#general
1 messages · Page 113 of 1
This gif game today is making my day thanks everyone!
There’s so many free resources to do whatever you want now days it’s kinda crazy. You can do anything.
It's never GIF game for me
I’m there too 
I’ve been meaning to ask you, does HTB have a marketing team ?
We do have
The design-ee part
Yeah
👀
Apply 
Or I will drag you to joeys date
Digital marketing and design
Imagine
Will be an adventure
It’s like watching a movie with subtitles
Just us crouched in the corner peaking over the tables
Yeah that would be fun
Lmao
And romantic 😂
I think he may be freaked out and never come over again 😂
I can bring candles
What
5hours to go...
Until what?
Oh I thought sate
Y’all want the hacking date app
hacking date app?
Like tinder or what?
yes
tinder likew?
Fun fact, a lot of AWS services are written in Java
every fucking time
not so fun for aws it seems
i gotta re enter my creds for htb
yes, with hack rizz
wtfff

stop it
are you https? because without you im just ://
use sso lil bro
Is this a joke cause of the downtime ?
are you https because without you im insecure
yes
no dipshit even then you log in next day you gotta re-auth
just sign in with google
no bug deal
big
no?
do you not have cred auto entering software like password managers?
and clicking remember me should remember u for some time
you're missing the point
i do
but
i got 2fa
and also
its annoying
I don't understand
I've never entered creds in htb login
i should be able to just not get logged out
or at least be able to assign myself trusted devices
actually that would be good feedback
There used to be a "remember me for a month" or something
ive submitted that 🙃
Unless im hallucinating
copy paste in dms so i can upvote
hackerone and bugcrowd kill the session every 3 hours 
ive done it in the forms they asked you to
when they wanted to improve the site
i remember that as well
They wrote the entire ec2 codebase in go
btw what do u think about academy 2.0
go is nice
to make malware with
ruby is a forgotten gem
sucks
i liked the old one more
meh looks different sure, doesn't feel snappy nor slow, heard some people are upset about it not being copy pastable in markdown format again so im being a parakeet and repeating it 
i just feel like the ui is so different from labs and academy and although i get that they're 2 completely different products, there could be more unity between designs
so, tinder like with hack rizz
Im gonna pretend this pun was on purpose and giggle
it was 💪
gem install j*b
Why does everything begin with web
yes
Why cant it just be a vulnerable file server or something
because web is the gui for normal people
wait

or whatever
well but it isn't
U just change it on the new HTB account manager
we have the most mutual frens
how many
we do?
9
I can't change it, but it changes when the htb name changes
me and melon have 32
i mean i have more in common with vader 

how many
59
goalm has mod privelges
thats a lotta friends

friends with ery'body
i had many friends before mod as well
I WILL BE ON VC GEN IN 30 MIN.
💪
smh :(
krill issue
did u run pwsh
i do
must be why
oh wait no i run oh-my-posh
so takes long to load
with pwsh takes half of that
mine takes 3 sec
cause i run in google cloud
re writing stuff in rust actually makes some stuff slower
rust is rusty
specially the things that are written in C
Im on VC
I'm too busy scoring thicc bounties like this:
good job❤️
bro found a p5 in starbucks
Context: FR-016 states "System MUST allow users to upload multiple profile photos [NEEDS CLARIFICATION: maximum
photo limit - 5, 6, 9 like Tinder?]"
What we need to know: What is the maximum number of photos users can upload to their profile?
Suggested Answers:
| Option | Answer | Implications
|
|--------|-------------------------|------------------------------------------------------------------------------
---------------------------------|
| A | 6 photos maximum | Standard for most dating apps; good balance between variety and simplicity;
easier to display in grid layouts |
| B | 9 photos maximum | Tinder's current limit; allows more self-expression; requires more storage
and bandwidth |
| C | 5 photos maximum | Simpler, less storage required; might feel limiting for users who want
variety |
| Custom | Provide your own answer | Specify a different number if you have specific requirements
|```
pls no spam
$25 wouldnt even cover my coffee for a week
i will have to report you to golam
IM ON VC
i think it wouldn't cover my coffee for a day
since you just drink it before 10AM
Sat her down and said figure it out 😆
That’s what I had to do when I was a kid
yeah lets vibecode later with @rustic carbon in vc
HELL YEHH
I’m down
vibecode how to ldap inject 😩
I have actually done this before haha, once you get a true/false response discrepency you just paste the req into AI and say "script plz"
its joever
@native plume Chess?
I feel lonely working so....Im just here on VC
Alright
Maybe I join in a bit but I'm doing something rn
Send link 
yayyyyyyy
Join the challenge or watch the game here.
Why I'm white again 😭
i have 2 monitors. pluz my work laptop and my personal one
lemem finish the game round
I joined vc but I can’t talk
i'm growing my beard out for winter
Only pro hacker is worth linkedin
I'll join when I finish work
bro lives in the past
Vc in Spanish

Big time
cursed
@rustic carbon join VC
plz stop, u r scaring me
Clearly I do
U dont understand
Im saying
When u hack something
Do u have any clue whats happening
oh not at all
the horror only gets started
i just keep pressing random buttons until I get a flag
I just did an SSRF in a URL aparemeter for GCP when it is strictly supposed to be prevvented due to the security header that they made a requirement
So how the hell did that happen
GG
Gg
hackerr
It’s fine, don’t worry about it! 
Vc went from frendly nice meetup to clogged in a second
We even had it in Spanish 
I rather be in general in silence

Wow there's a lot of people in VC
A question, did the erratum channel just disappear for you? I don't find it anymore here
Too many
May be an erratum
Jesus there’s 20+ people in VC
Do you see the channel?
Wuuuuuuuaaahhh gotta join vc tf are they doing there?
Maybe better to split into AFK
@subtle plover
Hey guys
Is it true burp intruder is on free burp now
I need an endpoint with SSL
Its always been on free burp, just at a limited capacity
bro delete i didn't consent to this image using my information
@scenic maple
i have not consent to this
so delete

caught
bingbong caught
Cry
but its public
I have previously given your organization explicit consent to use my
personal data, but I hereby withdraw that consent.
Your organization is processing my personal data unlawfully.
[If you choose this reason, you must provide further justification. For example, you can indicate that the
organization is processing your data without a legal basis].
The legal period for storing my personal data has expired.
You are processing my child's personal data collected via an app or website, even though my
child is under 16 years of age.
[If necessary, you can further explain the reason for your request here.]
I base my request on Articles 12 and 17 of the General Data Protection Regulation.
What am I asking of you?
I would like to receive a written response from you within one month. In this response, please let me know whether you will comply with my
request. If so, please indicate whether you will comply with my request in full or in part.
Have you passed on my personal data to other organizations in the past year? If so, you must also notify these organizations of the
deletion(s) as soon as possible. They must delete every copy of or
link to my personal data.
If you do not comply with my request, or only partially comply, I would like to know why.
Translated with DeepL.com (free version)
Coming a little strong there buddy 😭 too big text
hi
In the vc 😂
my english is bad
Wsssapsss
Wsssapsss
Only say hello
hello
It is important to note that each penetration test or security assessment must be performed from a freshly installed VM to avoid including security-relevant details from another client environment in our reports by accident or retaining client-sensitive data for significant lengths of time. For this reason, we must have the ability to quickly stand up a new pentest machine and have processes in place (automation, scripts, detailed procedures, etc.) for quickly setting up our distro(s) of choice for each assessment we perform. - https://academy.hackthebox.com/module/77/section/722
I'm a bit skeptical about this, and I don't think that most people spin up a fresh VM for every single engagement. I imagine configuring environment takes time, i.e. downloading wordlists, custom tools etc.
Zaps! 
Oh you left
Zaps! 
Hahah
Zaps! 
Zaps! 
Zaps! 
Zaps! 
Zaps! 
Wsszzzzzzzzaps

Wsszzzzzzzzaps

That's why people have "golden images"
A fresh vm, in this case, refers to a vm that doesnt have data from a client on it, not that it has no tools
And its not like youre gonna jump into a pentest with zero warning, youll have plenty of time to prep
Yeah, makes sense, thank you. Does using snapshots to create client specific instances works too? How is data handled when cleaning up between engagements?
Having a base snapshot is pretty common, as mentioned. Some firms consider copy/pasting between reports a fireable offense (or any sort of client data cross over)
Cleaning up heavily depends on the contract, ive heard cases where a company requests the hard drive or copy of the vm that was used
there are 42 million kangaroos in Australia and only 3 million people in Jamaica. Which means if the kangaroos were to invade Jamaica, each person would have to fight 14 kangaroos.
kbai
How many protocols are there 😭
How many can be misconfigured/vulnerable
Like ssh and https can’t be vulnerable I think
I put latest nginx in a docker container 😄
Now I don't have to worry about old distro packages
1.28
Okay ash obviously can be culnerable if u have an ass password
HTTPS and certificate authorities seems like if it’s configured properly u can’t break through it
Guys
Whats the easiest way to get an SSL endpoint
- Dont want to buy a domain
- Cannot use ngrok
I mean an endpoint with HTTPS
Because there is a lab where ur injection output must reach an SSL endpoint
Its a service on GCP and it only sends to locations using SSL not HTTP
So why not use ngrok?
I think I have to use money or else i cant do the lab
It supports https
Is this a quote from kennys book?
Because ngrok is blocked by my service provider
Who is gonna tell him
What about localtunnel @hardy frigate
Whst about localhost
localtunnel supports https
localtunnel.app
localtunnel has https on the free tier
@austere sigil u didn't sound like ur 30 or more sir
dont insult him like that 😡
lol.
This server requires members with moderation....blah blah blah I didn't ask for that
go away notification 💀
@melons voice he sounds 9
the new academy ui seems cool
Do i?
okay bingbong thats okay
i know change is scary
do it
No u
I wish
wowie he got you there
Its the best email address ever
fr
this you bingbong
ts got me confused for a solid 30 seconds
i shall be redissapearing now
do i?
hey
hi
I have a question
ok
i have an answer
that's too long a question
I can only answer questions under 150 char
I purchased the vip subscription for htb but i cant access luke the vip machines and it says like me to upgrade to vip+ like. What is the vip for i think i made the wrong purchase in hurry. Please if you could clarify my doubt about the difference between a vip and vip+ subs
- Delete Facebook
- Hit the gym
- Lawyer up
Bro
Need to speak to a person? Learn how to reach our support via HTB Labs.
Contact support
Ok so
The vip+ sub
Has a plus
So uhhh idk
It’s fancy
Demure
n8n
a few months ago there was this random domain that started providing free labs
Bro, do you any difference between the two plans
Does anyone remember what it was
no
I think it got deleted
Surely Support knows
vip is pronounced “Vee Eye Pee”
WHEARAS(stay with me here)
Vip+ is pronounced “Vee Eye Pee PLUS”
Boom difference
I should just become htb staff already
I think you're onto something
Definitely
Eye Pee?
are you ok bro?

Seems a bit obsessive of you
I found you a Reddit comment enjoy
I see a finger
Doing sus movements
thanks for complimenting my curves

Hey guys
Ok now time for ippsec and then sleep
s/c/x
I dont speak regex
this is not regex
Im up all night to get some
she's up all night to get some
we are up all night til the sun
You know there's a magical tunes channel right?
TO the staaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
Segmentation Fault (core dumped)
Lil Sis is watchy
bro imagine that song with someone and star gazing
Equally sized non-binary sibling is peering
Me and the boys coming up with some bromance
gotta fill that equality quota yk ✌️
also im stealing dat
get your uh
text thingy
stolen
ha
_._ _,-'""`-._ (,-.`._,'( |\`-/| `-.-' \ )-`( , o o) What? `- \`_`"'-
it's a lemur
i have accepted i will only take and give that for the rest of my life
Zoo boo maa foo?
^^^
🤯
😄
Im done
NO BRO
Listen bro im not gonna die
glutem-free cake even
I just wanted to say im done with this
the cake is a lie!!!!
Im done with all of this
Just hug someone you care
Im gonna make a C2 framework using cloud services
Or fap it helps too
Thats all im done about bro
same man i wanna be a farmer
No one is gonna die about it
AWS?
Good good
goat farmer?
@scenic maple Goat farming got mentioned
😭 not specifically goat but in general uk different type of animals and aint touching computer ever again
Yeah the puter can be evil
wdym
Ur a hacker, technology all day, ur face glued to the computer screen, u DONT MILK A COW
yo guys hello
Hello
yeah thats why i wanna change it, dont wanna stay glued to screen when im old

2025: AI girlfriends
I found it
The earth self destruction button
Bro u could have given her a SECOND chance
guys i wonna ask about a cybersecurity certif for beginners colled "Fortinet Certified Fundamentals cybersecurity" do any one know it ?
Yeah I heard of it before, are the labs practical
must i use cvss 4.0 in cwee report exam ?
it's like courses than u have to pass at least 80% of the exams
Just do HTB Academy -> Demonstrate your skills -> Provide services to local companies
Thats what I did
Then I got a job Alhamdullillah
is HTB certf free ? id think so
U can get a Student subscription
Like 10 dollars a month
Gives u the CBBH and CPTS and CDSA pathways
Which is all u need
htb cert not free, u need to pay. or have your company pay for it
hmmmm so i have to freelance for 10 bucks than i'll get it
What if I told u it can be free? But I still havent gotten around to reporting how
No bro u just dont buy a cup of coffee for 2 days and then u purchase the most valuable subscription in ur life
Yappin here?
DID YOU DOCUMENT THE FIRST OF THE 36 DAYS OF PENTESTER PATH?
the problem that in my country we don't have any international payment that's why so i have to freelance
if you are enrolled at an academic institution, then you can get the student sub for 8 USD/mo
DM me about this I will give u my advice -- Im gonna go to bed now
I'll take it as a no
Bro there is no way in hell that u can do those modules in 36 days
Impossible if you don't even start
I did most of them already
But the thing with CAPE u have to redo the modules with AV on
So u pretty much redo the modules with your modified sliver
Which makes it take a lot longer because u have to modify your payloads to evade static and dynamic detection
So i.e. u do the certificates module now u have to make certify evasive
So u want me to build an entire suite of evasive exploits and modify sliver and everything in between in 36 days
Maybe thats how black hats learn how to hack
okay, enough about drugs
Gtg good luck accusing the stuff of using cocain
Goodnight for me as well
this feels wrong
The only thing thats truly wrong are french pokemon sounds like starmine
Huh?
Okay i listened to french starmie
Why is it straight up moaning
AHHHH 🤤 ⭐
@patent elbow
Attack
U deleter link ((
Don't sleep
GGRRRRR
Gn bot

@frosty thistle
No busy ping very

That's how i look at you for not completing cyclone

I still look at you the same way

Post about it bitch
I wanna be the first liker
Post about cpts?
Damn i didn't like

Now i did
Someone’s letting off fireworks
AI is a tool and nothing more
It helps me most in tedious task
yes
@frosty thistle this was
kinda
scary
i mean i saw nahamsec comment "chat am i cooked"
no idea if its serious or just a joke BUT DAM BRO TOP 1
I’m not having another cookie this week
Three fiddy
Look at that gif
I might go out next week
Out out
To a bar or something
Typeshit
it's not even good at being that 
Wow
e
Yes you are mod
Exactly
never back down never what
Chat frozen?

Clead
Happy birthday
Thank you
Bruh Cheeto keeps going in my room. He's such a weirdo
Morning
evening
do u wake up so early everyday?
hehehe
most times
i will sleep after having breakfast
u soon gonna die
no so around 12 am we were messing around mickhat and others were vibe coding a dating app for hackers lol so was there
then work then gym then some watched some shit and here im now
doing my brain dead tasks
wait what? gym is open mid night?
bro imma see if i can come to pune
4 am
here they only open by 5
watched some shit
I bet ik
same but they have given the gym keys and shit to people who wanna work out early
but why?
apparently its easier to date there
I thought you were dating someone already
Ik for sure that I'm not one.
i used to, not anymore
Hello 👋
🙏
where you at?
rn? punjab
Who lives in pune
I have been there alot of times
lol no one im just trying to see the dating culture in pune everyone is trash talking about it
Broskis... I am cracking my first wpa2 (my own wifi) for the first time with my multi-gpu rig... It's working now
Set it for 10 alpha-numeric
My password is less than that
Arg... Need to add special characters
I applied for a position with HTB! Anyone here willing to answer a few of my questions?
what role was it?
Business Development Representative
Ik very little about them, I don't think I can answer
No worries, thanks anyway! How long typically before you get a response on an application here?
You should get them in a week or two, I believe the delay is because the team had been to a meetup and they were occupied.
Sounds great! Thanks!
@mint raptor IF PIZZA IS A CIRCLE WHY IS THE BOX A RECTANGLE
you shapist
why do we drive on parkways and park on driveways
Because all shapes go in: the square hole
My original "Square Hole" duet and the redemption in one video! Enjoy!
Check me out! - https://linktr.ee/AlisonBurke
/cat need this btw
wait is @mint raptor going on a date?
not yet
Wanna give tips my Sensei?
Bro has all the ranks... 
I was just thinking the same
I'm just good at begging
mate ask @sterile violet
You can use that on your date 
Now I'm curious I will
That's always the plan
@sharp ether please dont send unsolicited friend requests
hi
brr brr patapim tralalero tralala
u missed the chance to interview both of them
wdym
DM
DM me please
BROOOO
I had this last night too
u got tea huh
I have all the tea in the world
your mate got me hooked on smash cars
or whatever the game is on the bus ride
lmao u still playing it
Do you have to ask to send friend requests. Beats me I've been sending everyone a friend request LOL
yea
bro stfu
HAHAHA
now you make me look like shit at temu mario cart version
Legit IT IS A TEMU VERSION of mario cart
temu ?
smashkarts?
yea, that game
i love that one
it's car racing game
I just found out I've been pronouncing pwn wrong
I've been saying the adult industry name
When it's p-own
lol
I'm gunna tell people I porn for a living
im a penetration tester
i swear
the amount of trolling i got
irl and online
from saying that
I used to put that on dating apps
LOL
astagfurallah my brother wdym u are a penetration tester 🤨
i wouldn't trust
those apps
everyone online is either a murderer or a psycho
I'm good at pwn
Yeah I constantly do catfish experiments
just say binary exploitation 
or binex
thats not nice
people r not rats
I get some super good looking dude and turn his personality into exactly what women are looking for
It's nice do it
yup
its nice do it
Let them learn a lesson
And then after 3 days I unmatch
catfish @mint raptor
U don't have to catfish me
After learning their life history. These women will tell you anything If you're hot
I say yes to everything and anything
will you marry me
if ur a girl and rich yes
I'm in my 20s I have 0 brain cells and endless trust
if ur a girl and cute yes
Yes papi
oh well ~ahem yes I am
????
bro stop she is mine
true love trust
I told u I say yes to everything and anything
do you hate @ornate ibex
this is a hacking discord server
not a
I MEAN IM FINE With the convo
but ur too cool i dont want u to get banned
I'll delete it
Yes because why I can't be as cool as him
the staff didnt see it
Clown is right here

Idc I'm sleepy
is it you in the pfp?
LOL
Yes
Yes
you look kind of like me
Idk who u asked we all said yes
yes
xclow3n I mean 
Clown is a chad
🫦
Why you and your wife taking turns to shine?
she is cute
Ngl looking back I was being a bit mean
During experiment?
I'd intentionally talk to like uglier women
Cuz they had better convo skills
Yes. Will I give it up, no. Do I feel bad sometimes yes
I mean it's not mean it's more of a choice u prefer people who know how to communicate
No cuz they thought they found prince charming who is very charismatic wise and really ideal, plus hot
Everything is subjective all that matters is intentions
But they found me
Iphishpromax
Sometimes if I get really attached to the convo I'll send a voice note. Then they're like OMG SERIOUSLY I knew you were ideal of a man
i never knew girls existed until i became 20 i was like oh shoot i remembered
i need to keep my bloodline alive
some how
But their ego would be big bruised and they'd unmatch
I love today's chat ngl
Hahaha yeah that's my nickname though
There's this song don't know if you know it
Its from the 90s
Love you raja
My ex was called rajat
So I'd blast this song from time to time
How do you have all the ranks?
SLEEP @mint raptor
😭 yes ik
Hes member of staff
I begged emma
Yeah I took my medicine
Will sleep eventually 🤝
Is it only for staff or I can beg also
staff
Is it fancier to write offensive security consultant or penetration tester on your linkedin
Damn it
Ok so I went on HTB glassdoor and one dude posted how he's an Ethical Hacker at HTB
Why are there ethical hackers being hired by HTB
htb is not a consultancy
Because you dont want to hire twerps
Who don't know anything and just say the arbitrary passion word
you dont a hire a person who is good/bad you hire a person who is going to be a good employee in the future
I mean, if I was HR, i'd rather hire a passionate twerp than an arrogant APT

Sup peeps
Can't do that when you're a boutique consultancy agency with 10 members in it. Then you're forced to hire the arrogant sme. And don't you think that if you were passionate you'd get up, go learn, grind a cert, grind a rank, write posts, do something, build a tool even. That's actual passion. Words mean nothing
Interview difficulty weeds those wordy salesman out
Well yeah, that's what I'd define as passionate. Just because they're a twerp doesn't mean they don't know shit 
I've found out the bigger the organisation the more mediocre people there are.
I ain't gonna take your word for passionate you gotta show it of course.
In it
Those no show for it are what I'm talking about. The people who just say they're a passionate individual while they spend their Friday and weekends doing nothing infosec related
The interview with higher difficulty weeds them out
Well that's what I'm saying, interviews shouldn't be difficult, you can do a skill challenge if you really feel like it, but IMO interviews are meant to get the sense of what kind of person the applicant is
I do agree though but I felt really dumb and stupid when I couldn't answer how a blind sqli works. Because I realise in the pursuit of gitting gud I forgot to actually learn what each vuln does behind the scenes instead of sucking up roots like a vacuum cleaner. Made me reflect
Plus making the interview more difficult would just make the applicant more nervous than they already would be, idk bout you but I think it's a dick move to make an already stressful situation more stressful
8 Years of Experience, 20 years in AI development, 6 years as a GRC and 1 year in being a CEO.
Yes this position is an entry position 🚀
We hope you'll join our team today!
Yeah in my previous one, I was describing the diff between recursion and iteration. Mentioned stack overflow and how iteration prevents that. Then the interview took a bend and asked if I knew the diff between head and thread
I was like you think I'm a dev and an encyclopaedia???? I don't give a fuck
wym head and thread 
yeah idk the difference between a head and a thread 
What is head?
head is on top of your neck
see you got everyone asking
Ayo Jo
easy
I wish I said that
Freaky time as per usual in HTB
I gave a very mediocre answer and it completely tanked my confidence which was high cuz I had just done subnetting for them in my head and they clapped
keep it R-13... 
stack and thread can't even be compared on the same level
You haven't seen the chat at 4am EST
yes papi
Well... I'm probably asleep at that time
Imo they should stop hiring encyclopaedias and should just develop a ctf and give it to short-listed candidates then you can do a cultural fit interview later with a few basic tech questions
I've seen the horrors of gooning 1337 haxors
Bro's got that meterpreter payload and opened their cameras 
You should go be a pentester for the military. 
He was being dense. In the same interview when I was describing SQL he asked what port postgresql was on. I was so done at that point, he was trolling me with 5432
Interview questions:
- What happens when you type google.com in the browser?
- What's the difference between symmetric and asymmetric encryption?
- Are you free Saturday night?
Last question only applicable to female candidates
why does intervier wanna know if u are free sat night?

Hold on I'm asking chatGPT
DNS things
one is selfish
Yes papi
- idk
- idc
- yessss
I nominate this as the best answer
On the hiring couch
male candidates also eligible

tomorrow isn't saturday 
Higher executives always seem very fruity to me
I had to google fruity to understand what you meant
Ain't no way 💀
Get with the gen z
Have you seen Mr robot
The white dude who ended up murdering a chick, wanted to be VP of Ecorp did fruity things
I stopped watching when it became less about hacking and more about how skitso Elliot is
What's that
I always figured it would be something like this:
I've hacked the mainframe and got root on the web server
runs sudo apt update && sudo apt upgrade
No they hired a very smart team of red team operators to increase realness





