#general

1 messages ยท Page 166 of 1

molten bobcat
#

by.. cleaning and purifying the wastewater of the duplicants

#

heya pwning

#

โค๏ธ

tough oyster
#

<3

eternal mango
#

I don't remember the first games storyline tbh

#

so

#

SPOILERS MUCH

#

๐Ÿคฃ

molten bobcat
#

i am talking about Oxygen not included โค๏ธ

eternal mango
#

I blasted through the first so quick after release, kinda regret going so fast

#

Took my time with the second

molten bobcat
#

I'm still struggling to understand.. gas pressures

eternal mango
#

Am I thinking of another game then... I was thinking of a game on a sub?

molten bobcat
#

on a sub..?

#

Barotrauma.

eternal mango
#

Like, underwater

molten bobcat
#

bad colors because HDR but this

eternal mango
#

Yrsh yhsy'd yhr onr

#

Uhhh... fingers, move one to the left

#

Yeah that's the one

molten bobcat
#

I was gonna say, fuckin, c'thulu pthagn alright

#

HE LIES IN ETERNAL SLEEP SIR

#

honestly me too

eternal mango
#

Ok yeah I've not played Barotrauma, so I must just be getting confused

#

๐Ÿ’ฏ I was thinking of Oxygen Not Included as the one I played

molten bobcat
#

do you enjoy the large Pit of Waste I have

eternal mango
#

I try not to judge

molten bobcat
#

we call that "Future Drinking Water"

eternal mango
#

Everything has a use if you try hard enough

#

or something like that

molten bobcat
#

my plan is

#

the water is polluted water

#

polluted water can be turned into normal water with a sieve

#

this solves only one problem though

#

its potable now sure, but it still has food poisoning germs

#

the solution? You boil it ๐Ÿ™‚

#

So I have to transfer the filtered water into a vat, boil it, bring it back to temp, return to water resevoir.

eternal mango
#

Massive drip

molten bobcat
#

far from a perfect loop

eternal mango
#

Damn it now I can't remember the name of another game from that time... something like "try not to do", or "please don't die"

#

Isometric cartoony graphics survivalish game

#

Robot n shit

#

I'll remember it at 6 am, don't worry

molten bobcat
#

hmm

eternal mango
#

Don't Starve

#

Damn it, yes that's it

molten bobcat
#

โค๏ธ

#

my infinite reaction time cursed technique is why im a good blue teamer lol

#

but yeh they're both made by Klei

eternal mango
#

Ahhhh, well that makes a lot of sense

molten bobcat
#

I feel like

#

streaming some final fantasy

eternal mango
#

Have fun ๐Ÿ™‚ I need to go to bed. First time I've kept myself up doing random crap past 11PM in ages

#

and I need to keep being a good boy

#

Nice to see you back dude

#

Gotta catch up properly some time ๐Ÿ™‚

molten bobcat
#

likewise sir, we'll catch up ๐Ÿ˜„

terse dirge
#

Yo cloud, do you have any tips on finding IOCs?

#

Or good threat Intel feeds?

molten bobcat
#

I mean

#

Personally I haven't really utilized an intel feed

#

as most of my investigations are lead driven

static pasture
#

@molten bobcat DM?

terse dirge
molten bobcat
terse dirge
terse dirge
#

Nice

remote bolt
#

hi h4ck3rs

molten bobcat
#

does someone wanna explain to me how i misplaced a greatsword..

terse dirge
#

Do you have any tips on finding IOCs or anything? I've just been using shodan a bunch lol for this current investigation I've been doing.

molten bobcat
#

IOCs of what?

terse dirge
alpine pumice
#

windows event logs, you're welcome

molten bobcat
#

thats a bit of a vague thing id be happy to explain over vc

terse dirge
alpine pumice
#

process explorer + autoruns

remote bolt
#

how R u guysz

terse dirge
molten bobcat
alpine pumice
terse dirge
#

it's kinda hard to explain without showing my current findings Kappa

worthy cargo
#

I have an .ru domain ๐Ÿ™‚

molten bobcat
#

sure

worthy cargo
#

I bought it with fake russian address

meager kernel
worthy cargo
#

In soviet russia...

placid apex
#

Gm chat

terse dirge
muted olive
#

.cn site

#

.nk site

muted olive
#

your blog is unresponsive, btw

placid apex
#

Yeah i turn it down for some reason kek

worthy narwhal
vivid flower
#

Hey why did xreous leave?

alpine pumice
vivid flower
#

Oh i thought he left he never talks

alpine pumice
#

he did leave for a bit but came back a while ago

worthy narwhal
#

i just got a new business idea hmmpepe

#

hmm pepe_notes

warm dome
#

any recommendations for github alternatives? thinking of moving to gitea atm, trying to move away from anything with telemetry/data collection

warm dome
# worthy narwhal run your own git server

was thinking about it, which was why was looking into a local gitea simply for that extra comfort for lack of words, havnt done a git only server before tho, do you just use the daemon with a vm?

worthy narwhal
#

personally i have a raspberry pi that runs 24/7 and i maintain my main git repo on there (with multiple backup drives). choose a distro, setup the server, and remote into that, push changes to that remote, nothing too crazy

#

on my pi i just use ubuntu server LTS, then install the server, and its on my local network at all times

warm dome
eternal mango
#

AWS free tier

warm dome
#

been slowly reducing amount of data given out moving things over to more privacy focus'd stuff, but ideally i'm not liking how githubs going since microsoft ownership, same thing with things like vscode to much enforced telemetry

worthy narwhal
#

you can use a VPS too i guess, like a $5 / month Linode/Akamai node is more than enough

muted olive
worthy narwhal
#

yeah or AWS free, i guess GCP too

warm dome
worthy narwhal
#

just make sure you keep a backup of it, somewhere, often, because if your VPS goes down you are rekt out of everything

eternal mango
#

Free tier has plenty of resource to run a personal git server

worthy narwhal
#

you can use a second server somewhere else thats free and setup a script to auto-send a copy over scp once every day or so

warm dome
#

yeah ill setup an aws free tier for a git server, alternative was to use proton drive and backup local version control that way

eternal mango
#

Encrypt daily and push to a free GitHub LFS storage

#

Down the power

#

๐Ÿคฃ

warm dome
#

since i pay for proton, same reasoning really haha

molten bobcat
#

oh torn i am on what to do

warm dome
worthy narwhal
eternal mango
#

Yeah I get it, but your backups would be encrypted

#

Just throwing silly ideas, so don't take me too seriously

muted olive
#

I generally stay away from stuff starting with "i" ๐Ÿคฃ

worthy narwhal
#

run the server on US east 1, and run your backups on US east 1 as well ๐Ÿ™‚

warm dome
eternal mango
#

You get 2gb LFS for free on Github

#

Depending on retention and history, as you obviously couldn't do diff updates as it's encrypted, it could suit you fine for some time

#

Anyway, end of stupid ideas, for now

warm dome
#

yeah haha ill either go with aws or just backup the files with proton drive and setit up to a git diirectory

muted olive
#

Regex search is my favourite feature on Github. Last week I rediscovered 3 old CVEs from 2015 lol

#

I was like oh look, new vuln, but then found out all of them are already registered a decade ago

warm dome
#

people can be lazy when it comes to dependencies

worthy narwhal
#

damn i really want a new vape rn but itโ€™s mad late ahhh ill just suffer with the dying vape and hurt my lungs for 1 night

muted olive
#

Although what I usually do is search for vulnerable code patterns

#

Like unserialize($COOKIE[session_data]) or whatever

warped plank
static pasture
#

Heyo

eternal mango
#

It worked very well

eternal mango
static pasture
#

Hi

eternal mango
#

Hey

#

All good? ๐Ÿ˜„

static pasture
#

Yea im good. Are you good?

eternal mango
#

I'm ok thanks. Been doing better with sleep, but today I've ended up down a rabbit hole of a stupid personal project

#

so couldn't sleep for thinking of what to do next, and now I'm doing it next

#

wups

static pasture
#

I noticed ๐Ÿ˜‚

#

Hopefully you figure it out!

eternal mango
#

Oh I have

#

and it's so dumb

#

but so fun

#

I was trying to find a configurable ticker that supports currencies and tokens across a number of common trackers for Windows, that I could just have in the taskbar to keep an eye on

#

None of the ones out there were m aintained, and th ose that were maintained sucked

#

So I made my own... and then for SOME reason the memory of those old desktop pet apps from the 90s came to mind, Dogz, Catz, Oddballz... I thought it'd be fun to show some sort of interaction on transactions, but I wasn't about to go do some pixel art

#

so instead it now shows the ticker in the taskbar, and shoots off desktop fireworks styled and sized based upon the buy / sell transaction values

#

So stupid.. but it's been fun

static pasture
#

Should have some Tomagotchi like functionality doge_finger_guns

eternal mango
#

So....

#

You feed it, you buy?

#

You slap it, you sell?

static pasture
#

That works lol

eternal mango
#

Ok this is going off the rails, again.

#

All I wanted was a freakin market cap ticker in the task bar ๐Ÿคฃ

warped plank
#

when the market is bullish it should have $ for eyes and when it's bearish it looks depressed kek

eternal mango
#

I don't even trade ๐Ÿคฃ

#

I just saw the news on an old coin I got a drop on over a decade ago and got interested again

warped plank
ornate ibex
#

Good Morning

devout sail
#

Good morning

#

I just reached Bangalore and i really wanna go back home xD

silver forge
#

lol

worthy narwhal
ornate ibex
devout sail
ornate ibex
#

Relative's house

devout sail
#

Same ๐Ÿ’€

#

I'm gonna sneak out and smoke

devout sail
#

Gae

meager kernel
#

Nothing to see there or do there

devout sail
#

Grils

devout sail
#

uhh i read AV as in AV not that AV

meager kernel
devout sail
#

I have good friends
I'm just lazy

meager kernel
devout sail
#

๐Ÿ˜

#

Share

meager kernel
#

I have to go to college for project submission

devout sail
#

Open sauce Gun

meager kernel
#

@devout sail today was that cultural society trip I told you about.
I missed it.

devout sail
#

Yes

#

Hehe what do u do instead

meager kernel
meager kernel
devout sail
devout sail
meager kernel
#

Academy modules

devout sail
#

Woah

meager kernel
devout sail
#

Breh you travel for 30m

#

And changed states 2 time

meager kernel
#

I have to use metro

#

Cause too much traffic

devout sail
#

I'm talking about metro

#

But traveling in Delhi's metro is always fun

#

You always get to see drama

meager kernel
#

I would prefer to drive

devout sail
#

In that traffic ๐Ÿ’€

meager kernel
#

Traffic is the reason why I take metro sometimes

devout sail
#

Go to some other city

meager kernel
#

After btech

#

Preferably foreign country

devout sail
#

Russia ๐Ÿ‘๐Ÿป

#

Why not ๐Ÿ’€

meager kernel
#

Some good country in europe

meager kernel
devout sail
#

Then goto the desert region

scenic maple
#

estonia is best in cyber

devout sail
#

(idk the places names)

severe stream
#

evening gents

devout sail
#

Evening michele

severe stream
#

close lol

devout sail
#

Michale

#

Someday

severe stream
#

some day lol

meager kernel
#

Moderate climate preferable

devout sail
#

Yeah just stay at home

severe stream
#

been working on my own lately as well

#

only get a couple hours a night lol. ruff life

#

mine takes you back to 2000 aol days haha

devout sail
severe stream
#

thanks ๐Ÿ™‚

warped plank
#

you should put an epilepsy warning kek

devout sail
#

Nah

warped plank
#

but damn that's nice

severe stream
#

much appreciated! been working on it for a few months

devout sail
#

But thecloud is back

severe stream
#

wym?

devout sail
#

@molten bobcat

#

-# idk the real reference xD

severe stream
#

nah thecloud is a reference to obviously the cloud but transmuted to a memorial

molten bobcat
#

?

severe stream
#

oh look at that, you got your own directory on my site lol

severe stream
#

gots to go but i shall leave you with a tune.

hoary nebula
#

@bingbong9

muted olive
eternal mango
#

So polled for updates and analysed the changes as they came in

muted olive
#

That's efficient

#

and fast in terms of finding new stuff

eternal mango
#

Yup, got a load of CVEs from it, not many with high impact / high usage, but some

#

Gave me good experience in responsible disclosure and the CVE issuance / verification process

muted olive
#

I've been meaning to try out this method where you scrape a lot of plugins and use AI to recurse through each of them and search for vulns. You'd need an MCP server, typically I'd setup Gemini since it's free, or I'd go for Claude Code if I'm willing to invest.

eternal mango
#

Claude using their Agent Skills feature would be best for that right now imho

#

It's very powerful

keen pilot
#

How can I use cURL to download a file please I need guide

muted olive
#

So I've heard

eternal mango
#

Like, what have you tried, did it work, if not what happened?

eternal mango
#

Plenty of no auth rce, file inclusion, sqli etc yes

muted olive
#

I've gotten just one CVE so far, but it took so long that I'm kind of lethargic to get into the whole process of finding another ๐Ÿคฃ

eternal mango
#

They're all documented on the blog ๐Ÿ˜‰

muted olive
#

Submitted it to MITRE and they got back in 4 months

eternal mango
#

Poor old ancient no love blog

#

4 months?! ๐Ÿ˜ฎ Damn

#

Was quite some time ago I last had to submit one, didn't usually take more than a few days for a placeholder

#

Things no doubt have changed, busy times and not enough hands

muted olive
eternal mango
#

๐Ÿ™ that's sad

#

I only had a few times where the vendor / author didn't reply along my responsible disclosure policy

#

But I count my WP research as pretty soft

#

No way indicative of general research or disclosure process imho

#

Other work I've done that isn't documented has gone much, much worse.. stretching to over a year in one case

#

That was so painful, but as it was a bank, and the bank I actually used, I had to stick at it ๐Ÿคฃ

#

Ended up getting lucky and someone had a contact that knew the person to speak to

#

...follow 6 more months of back and forth lol

muted olive
#

I mean, reaching out to the vendor was also challenging in my case. They had almost zero info on contact etc. I found their email through the patch notes of a really old repo and sent a disclosure request to that email... no reply till date. kek

#

I've heard WP is better at response times etc

eternal mango
#

Yup, feel that one

#

WP were pretty decent in my experience yes

#

Still gutted to this day the null byte injection thing I found in cURL wasn't considered CVE worthy

#

Not salty at all

#

๐Ÿ˜ 

#

It was very edge case though

eternal mango
#

Honestly I can't remember

keen pilot
#

Please no disrespect

I don't understand this question:

To get the flag, start the about exercise, then use cURL to download the file return by '/download.php' in the server shown above

eternal mango
muted olive
livid narwhal
#

...

eternal mango
#

Hah yeah.. use AI to help discover issues, fine. But VALIDATE and DEMONSTRATE

#

Blip blap blop the slop helps nobody

muted olive
#

Or just copy paste straight out of ChatGPT ๐Ÿคฃ

lusty storm
#

is this a finding on a pen test, that PMF is possible to be enabled but its not enabled?

muted olive
#

(Trying to understand what the security risk is, I'm new to null byte injections)

eternal mango
#

IIRC it was more regarding an edge case where a plugin was performing filtering based upon schema

#

It wouldn't have accepted just file:///etc/passwd, but it would accept a string with http in

#

The issue was that you could terminate the file path in the file: schema early when passed to cURL using a null byte

#

so file:///etc/passwd was the same as file:///etc/passwd%00http, and they both were evaluated as file:///etc/passwd and hence /etc/passwd when passed from PHP to cURL

muted olive
#

I see, interesting

eternal mango
#

So yeah.. very edge case to bypass a very basic input filter on a plugin in order to use the file: schema to access a local file, while bypassing the filter looking for the string http in the path

muted olive
#

I think this is very similar to some other kind of vuln

#

CRLF injection?

#

Something like that

eternal mango
#

Not quite, it's more the string was being decoded and parsed as is, and the null byte when processed in PHP before being passed to cURL meant the string was being terminated prior to http

muted olive
#

Ahh, got it

eternal mango
#

Technically it could've probably have been taken further to some memory corruption or sorts, but I wasn't very skilled in that area at that point, so didn't try

#

It was an issue with libcurl IIRC, so not really PHPs fault

#

Anyway, that bug report above links off to the suggested and eventual patch in the cURL interface, along with a preventative change in PHP

muted olive
#

iirc curl can do other things as well right? such as transferring data

eternal mango
#

Yup

muted olive
#

you could leverage the null byte injection to read files, and transfer them to an attacker server

eternal mango
#

It suppots many methods and protocols

muted olive
#

you could essentially clone the victim's filesystem... maybe ๐Ÿค”

eternal mango
#

Honestly I don't think there was any real danger past the edge case above

muted olive
#

of course, it takes time and is bound to be noisy, but in theory you could

eternal mango
#

Memory corruption wasn't really an option as cURL parsed the information correctly, it was that they were not ensuring the provided path was not equal to the end path

#

The logic before was to parse over the whole input string and decode it until it hit a null byte

#

The updated code changed it to parse over the full path string, breaking out if it ran in to a null byte with an error

muted olive
#

Yeah so, if you could read the file by inserting the null byte, could you transfer it in a similar manner? Make an http request to read file:///etc/passwd to a webhook with the null byte niserted

eternal mango
#

Uhhhhm, I don't know, I don't think so tbh

muted olive
#

My line of thought is that if its able to successfully retrieve the file contents, it might be able to also save those file contents somewhere (say, in a variable or something) and transfer it to a webhook

eternal mango
#

but if I were to find that issue today I would've definitely dug further

#

Ok ok, so

#

It's not about fetching the file contents

#

That was part of the app with the weak checking

#
  1. Does the input have http or https in? Then it's a valid URL
  2. Pass it to cURL to fetch the content
  3. cURL terminated the string at the encoded nullbyte
  4. cURL correctly fetched the file:// path
#

The TLDR is that the plugin was using a filter of http existing in the input path as proof of a valid URL, but through this bug we could remove the http string from the path through the premature null byte injection, meaning we could cause cURL to fetch a valid file path and have it returned to the app

#

I know, it's weird

muted olive
#

Ohh okay. Then redirecting that output would have to be part of the app's functionalities for any real danger, I'd imagine

eternal mango
#

Yes exactly, the app only made the request, or rather passed the URL to cURL to make the request and then processed the results

#

I suppose in theory you could have done some funky shit with a samba share URL

#

but that's a massive assumption

meager kernel
eternal mango
#

especially as the issue was only present in the file processor lib in cURL

muted olive
#

This brings up an interesting vector I hadn't tested with another bug I found

eternal mango
#

I didn't think to check the other protocol libs to see if the issue existed there at the time

muted olive
#

the file part

eternal mango
#

Spill the beans ๐Ÿ˜„

#

Damn, I wanna run cURL lib through this workflow now to see if it finds any weirdness

#

๐Ÿคฃ

muted olive
muted olive
#

That was happening because of the fragment and the javascript handler after it

brazen crown
meager kernel
#

Vibe coders should grow some balls and do real coding

eternal mango
#

lol

#

Use the tools available to you, but never trust them if you can't understand what they do

muted olive
#

but technically, after the # in something.htm, you could insert an arbitrary protocol like http followed by a url, and it would load it into the presentation frame itself

#

you could deliver malware that way

eternal mango
#

I've coded for decades, but have found integrating AI in to some workflows very beneficial

muted olive
#

imagine, a victim clicks on a presentation link and is prompted for a place to save the file (the file being malware)

meager kernel
eternal mango
#

Well yes

#

if they don't use the tools right

#

as in just trust what is given

#

You still have to understand what you have, how it works, audit and test

#

Shipping something vibe coded without those steps, ew

brazen crown
meager kernel
eternal mango
#

Not always.. but yes, possible

muted olive
meager kernel
#

Vibe coding is not a good concept

eternal mango
#

That's why you need to integrate it in to your workflow

#

Not let it REPLACE your workflow

meager kernel
#

"oh yea let me just play some songs and tell this fucking AI clanker to do everything for me so I can be a lazy fuck"

eternal mango
#

lol

#

There's a difference between just saying "hey do this", and actually putting together a decent statement of work, paying attention to what the result is, testing it, auditing

#

There is nothing wrong with vibe coding, if using AI to aid in coding is done correctly

meager kernel
eternal mango
#

Most

scenic maple
eternal mango
#

That's exactly it

#

MOST

#

Saying people who use AI in coding are lazy and wrong is just a blanket statement that is incorrect

#

Sure, someone could just make an app in 10 minutes and ship it

muted olive
meager kernel
#

Personally, I like rawdogging my code

eternal mango
#

but someone who actually cares about what they are working on, and using AI to help them achieve will spend time understanding and correcting provided

#

Rawdogging

#

Bruh

scenic maple
#

altho we cant disagree that people who learned to code without ai are a different breed than people who had ai

muted olive
#

That's also probably why corporates ban chatgpt from employee systems lol

brazen crown
#

i litterally 20 minutes ago got claude to critique my code

meager kernel
eternal mango
#

I know

scenic maple
meager kernel
#

Rawdog seemed like a suitable word

brazen crown
eternal mango
#

But seriously, you should take some time to learn how you can effectively and safely integrate these tools in to your workflow

brazen crown
muted olive
#

Claude gives you the least shit imho
"You're absolutely right!" โŒ
"Your code sucks, fix it!" โœ…

eternal mango
#

I'm not saying ship to production 10 minutes after you commit to git from GPT or Claude or whatever

scenic maple
eternal mango
#

But it's POWERFUL, and not just for coding

meager kernel
#

AI is an assistant
Not a master

eternal mango
#

Agent Skills, the feature Anthropic shipped a while ago is freakin massive

eternal mango
muted olive
#

master senpai AI daddy UwU~

eternal mango
#

Used correctly to accelerate, and enable rapid development under correct supervision and critique is massive

#

And Agent Skill, that feature

#

I've said it three times now, but if you haven't read up on it, do so

brazen crown
muted olive
#

To be honest, I'd love to see more AI being used in other sectors, prominently on non-tech sectors

eternal mango
#

It's SO much fun to work with

#

and so powerful

meager kernel
# eternal mango Exactly

Honestly I feel LLMs have taken away people's critical thinking skills
I think there was a study from Harvard or some big Ivy league uni which said that people who regularly used GPT had much lower critical thinking skills than those who did not

scenic maple
brazen crown
# brazen crown 4.5/10 ๐Ÿ’”

`Why Not Higher?

โŒ Data leakage makes all results unreliable (biggest issue)
โŒ Misapplies scaling to tree models
โŒ No way to actually compare which model is best
โŒ Would perform worse in production than in testing
โŒ Inefficient pandas operations`

eternal mango
#

Use what you have to help you work faster and think better, not to replace your freakin brain

eternal mango
#

Challenge what you see

#

Never accept truth without testing it as truth

muted olive
#

Recently someone came up with an AI system to detect students carrying guns. Which is a very good way to use it. It did have a lot of FPs (like picking up a bag of Doritos as a gun), but honestly training it the right way and using it the right way can solve a lot of problems like this one.

brazen crown
eternal mango
#

otherwise we may as well just throw shit and git commit

meager kernel
#

Earlier, if you had some question, you had to search for it on Google, learn about the concepts to better understand the problem, which gave you a wider view of knowledge
Now, just plug the exact problem in AI, solution given, no challenge

I preferred the time when you had to search for the solution, learnt better that way

eternal mango
#

lol

#

What about before search engines

#

when you had to go and read books

meager kernel
eternal mango
#

What about before books

cursive nymph
#

Any hackers going to see tron ares ๐Ÿ‘€

meager kernel
eternal mango
#

Technology and what we have available to persue knowledge and skills will always change

meager kernel
eternal mango
#

bullshit, of course you would have knowledge

brazen crown
eternal mango
#

How do you think we got where we are now

scenic maple
meager kernel
brazen crown
meager kernel
#

Lmao

eternal mango
#

lol

scenic maple
#

usually used by js developers

muted olive
#

Stack overflow is dead, long live chatgpt kek

eternal mango
#

Collaboration and sharing of experience, and as such laying the groundwork of collective knowledge is the whole premise of human evolution and growth

meager kernel
#

GTA 6 is delayed
November 2026
Another whole year

eternal mango
#

Use what you can, because others will

meager kernel
#

I feel I would have a girlfriend and kids by the time GTA 6 comes out

scenic maple
eternal mango
#

haahahah

brazen crown
muted olive
eternal mango
#

Well ok a fourth time, Agent Skills, tuning and enabling models through known datasets and programmatic interfaces to said data. When it was first released, Anthropic's Sonnet model didn't know how to work with the Agent Skill APIs

#

So I developed an Agent Skill dataset that taught it how to work with the Agent Skill APIs

scenic maple
#

i think in mu lifetime i have only got to the 2nd page of google a few times

eternal mango
#

Then used that Agent Skill workflow to work with the Agent Skill APIs to improve a workflow utilising Agent Skills

#

๐Ÿคฃ

frail viper
#

Good morning guys

muted olive
#

you'll be scrolling through 20 google pages

#

for same result

eternal mango
scenic maple
#

RPOGGERS but more links == better seo

eternal mango
#

I used something else

muted olive
#

Google is the best hacker tool

eternal mango
#

And NASA is an awesome target for practice

#

But yes, Google is great

muted olive
#

btw I got my third NASA letter yesterday

#

XSS again

eternal mango
#

Noice, I got a couple and one from some other gov org, can't remember which

scenic maple
#

yall hacking governments

#

that has to be illegal

eternal mango
#

The other gov org was an RCE

muted olive
#

I got one on SSA but I think it was either fixed, or I forgot to report it and too lazy

eternal mango
#

Nah

#

Many US gov orgs are under a wide VDP program

scenic maple
#

thats what cinzinga said

muted olive
scenic maple
#

i am just repeating

muted olive
#

the now-shutdown US government kek

eternal mango
#

Wait

#

It's still shut down?

muted olive
#

which is why I'm not expecting fast responses atm

muted olive
eternal mango
#

Wow

muted olive
#

36 days and counting, its the longest one

scenic maple
#

iirc frosto had issues cause of it

eternal mango
#

yup, crazy

scenic maple
#

usually in my place when govt websites go down they neevr come back

muted olive
#

It's just a staring contest atp. Either dems will blink first or Trump will

eternal mango
#

Did you ever land on the gitlab repos across those gov VDPs 0xcnJo?

terse dirge
#

crazy? I was crazy once

#

they locked me in a room

#

a rubber room

scenic maple
#

room full of rats?

terse dirge
#

a rubber room with rats

vague minnow
#

hi

muted olive
#

And yeah, I've seen those Gitlab repos

eternal mango
#

The repos was where I found the RCE ๐Ÿคฃ

muted olive
#

Gitlab and Bitbucket are the most common ones they use

eternal mango
#

NFI how it was still there after so long

scenic maple
#

why dont they use github

eternal mango
#

I've got some custom tooling for osint on domains which helped too, helped to connect the dots

muted olive
eternal mango
#

Oh man, some of their APIs.. WEIRD right

#

But yeah, very good practice

#

..and legal

muted olive
#

I found credentials for a service account actually

#

It was crazy

eternal mango
#

Haaahah oh man wiat

#

I hope I noted this down

#

There were some docs I found, with a guy leaving hints for himself for his password

#

One was something like... "that funny russian word nobody knows"

muted olive
#

Thing is that file wasn't really there! But it was there at some point of time, and while it was there, Google indexed it. So the search result returned the base64-encoded password in the blurb. ๐Ÿคฃ

muted olive
eternal mango
#

๐Ÿ˜„

rustic carbon
#

Guys,why I donโ€™t get cubes from my referrals

scenic maple
#

dang didnt have the full meme

#

sadge

scenic maple
rustic carbon
#

They have done "Intro to academy"

scenic maple
#

well if all that is done please wait some time and if you still havent gotten them contact support

eternal mango
#

They must also complete the onboarding questionnaire

eternal mango
#

When they have registered?

#

It's like, the first thing they see

rustic carbon
eternal mango
#

Then be patient I suppose, or reach out to support

obtuse fern
#

requires at least 2 friends to recieve rewards

rustic carbon
#

Okay

rose onyx
#

two friends? pepehands

gaunt gale
#

Had job interview today but they are gonna invite me to another one which will be the last interview phase

obtuse fern
#

rewards are at 2;5;15 and whenever a friend you refer completes a tier 2 or higher module

rustic carbon
obtuse fern
#

the t2 one though doesn't apply if they're using the student sub

eternal mango
#

Yup, don't worry though

#

They know that already, they read about it

gaunt gale
#

Iโ€™m hopefully gonna have an entry level job in e commerce soon, which can lead into other jobs like IT ones

eternal mango
gaunt gale
#

Probably full time weโ€™ll see

eternal mango
#

oooo cool, good luck!

scenic maple
#

but who is the 2nd one

rose onyx
meager kernel
#

@eternal mango wanted to ask
What's your role in HTB rn

alpine pumice
eternal mango
#

mmm

eternal mango
#

special projects.. involving mops

#

My role was CTO, but I'm moving away from that role while still being involved with the departments I managed to focus on other tasks that contribute to HTB, and allowing for some mental health recovery.

#

Co-founder, also

#

and yes, janitor

rose onyx
#

egasp, moving away from cto?!

eternal mango
#

In tital, but I'm still involved mostly in what I did before

#

Just changing reporting lines and focusing on what I can best provide as benefit to the company, and as I said, allowing for some mental health recovery after a personally difficult few years (not due to HTB)

meager kernel
obtuse fern
#

yes

alpine pumice
#

g0bs is a legend

obtuse fern
#

him and d4rk combined beards and made htb

meager kernel
#

Crazy, did not know that

rose onyx
#

combined beards pika

meager kernel
#

@eternal mango you are Nikos Fountas?

#

Or am I confusing you with someone else

supple plume
#

Doxxed

meager kernel
#

I just googled founders of HTB

eternal mango
#

lol no

#

I'm James

rose onyx
#

I'm hungry

eternal mango
#

I'm that too

meager kernel
obtuse fern
#

"gee i wonder where HTB started"
googles names
"It's all greek to me"

eternal mango
meager kernel
eternal mango
#

๐Ÿ™‚ Pleasure is mine

meager kernel
#

Sorry I did not know before that you were one of the cofounders

supple plume
#

We would have said less grotesque stuff

eternal mango
#

It's fine, like I said earlier, here I'm just me

#

Don't care about titles, I'm here to hang

obtuse fern
#

g0b is a chill guy

meager kernel
eternal mango
#

๐Ÿ™ˆ

obtuse fern
#

can confirm

#

mod chat leak when Kappa

meager kernel
#

I was using terms like "rawdogging my code" ๐Ÿ˜ญ๐Ÿ˜ญ

supple plume
#

Dang that reminded me of taking my pills somehow

meager kernel
#

Well I wanted to apply to HTB in the future some time, there goes my chance

meager kernel
obtuse fern
#

ยฏ_(ใƒ„)_/ยฏ

meager kernel
worthy narwhal
obtuse fern
#

you've seen how some staff members chat in here sometimes... it doesn't hurt you

meager kernel
#

Imagine if they check your discord chats when you apply

obtuse fern
supple plume
rose onyx
#

I hear ry4n was a top yapper, he got hired, so should be fine raw dogging every now and then

worthy narwhal
#

heyyy marcie i got parrot 6.4 installed WITHOUT any LUKS issues excitedpepe 6.4 is working amazingly well!

supple plume
hoary nebula
#

@exotic pendant friday

worthy narwhal
meager kernel
obtuse fern
supple plume
rose onyx
meager kernel
#

Arch users are like the swifties of Linux community

obtuse fern
#

but idk why you @ me about it RainbowDumb

worthy narwhal
obtuse fern
hoary nebula
obtuse fern
#

and then reinstall ALL the tools again

worthy narwhal
#

i will never forget my super sekrit password which is the first license plate i ever had pepeUwU + the make of my dream car excitedpepe

ivory burrow
#

Off topic the Internet been around since arcade era ... That weird info is helpful with online security oddly

#

Idk either something about tokens

hoary nebula
#

bankai tenkai oppai

meager kernel
supple plume
#

Ive seen a password recently

hoary nebula
#

get hacked buddy

supple plume
#

Interesting

ivory burrow
#

What's in front of me that's unbelievable

#

Bag that says unicorns on it yup password that

supple plume
#

******

#

that is the password

hoary nebula
#

bigtittiedgothgirl123

worthy narwhal
supple plume
#

seriously

#

that symbol

hoary nebula
ivory burrow
supple plume
#

even if you see it in plain text you wouldn't think it's a password

hoary nebula
supple plume
hoary nebula
supple plume
#

I 've also seen this

ivory burrow
#

I can't stand prompts like tht

supple plume
#

****OrD123

#

or

worthy narwhal
#

my favourite thing to use in my passwords is @_@ after everything kekevil

hoary nebula
ivory burrow
#

That's dedication

hoary nebula
ivory burrow
#

Ehh ig it's easier to do than I thought @_@ kek

hoary nebula
#

dead

ivory burrow
#

Lol

#

Did I say something weird chat got quiet fast

green kite
#

sup Yannick

ivory burrow
supple plume
#

so appartenly hex can bypass is_numeric in php

supple plume
#

the problem is that the url get parameters are always type string

hoary nebula
#

Sup Sparkling

supple plume
frail turtle
#

I am now cheating on my girlfriend with a girl who is cheating on her boyfriend

supple plume
#

and raised many hecker questions

supple plume
#

this

frail turtle
#

kek I am ao fuckrd

hoary nebula
#

both break up

supple plume
#

the problem is this

meager kernel
supple plume
frail turtle
#

Relationship problems

meager kernel
frail turtle
#

I havent seen my girlfriend in almost 30 days

meager kernel
#

Brother.

supple plume
meager kernel
frail turtle
#

I am on the latest kernel of arch

ivory burrow
#

Yeah you can declare this twice with if is_numeric<= sing
Then sing = parts in idfk fix this gpt

#

I think right

cerulean bloom
worthy narwhal
obtuse fern
frail turtle
#

Were not taking time apart

obtuse fern
#

also not seeing != not communicating

frail turtle
#

Thats correct we still communicate

#

Daily actually

obtuse fern
#

like you way overread what Hall said

ivory burrow
#

I can't code that good but I try

worthy narwhal
#

my gf would end me if i didnt see her after days kekPlode

supple plume
#

cheap discord therapists are not going to uncheat his relationship

frail turtle
#

Due to albeit almost unbelievable reasons... i cant see her. kek like my whole mess is fucked it's honestly hard to talk about

obtuse fern
#

but eh

#

Cheating is never right to do

green kite
#

Unless you're playing wiezen, right @hoary nebula

obtuse fern
#

and you should just break up with your girlfriend @frail turtle instead of cheating on her

frail turtle
#

I am not endorsing it at all. But i need intimacy like Im in here in my apartment alone every god damn night

obtuse fern
green kite
#

yeah I agree with Marcie

worthy narwhal
hoary nebula
#

secs

#

bro just say sex

frail turtle
#

Me too man i spent two years without getting laid

obtuse fern
#

like... your needs don't override the feelings of your girlfriend

obtuse fern
supple plume
#

you can't say some words bc automod

green kite
#

get a few kids, then wait and see how much intimacy you get

frail turtle
#

No by intimacy i mean an actual fucking connection

obtuse fern
hoary nebula
#

women โ˜•

frail turtle
#

We barely talk but the loyalty is there for some reason

green kite
#

When we talk nowadays its usally avbout the kids

frail turtle
#

She wont let me go i wont let go

green kite
#

like your first role becomes mom/dad

obtuse fern
#

just because you speak every day, doesn't mean you're actually communicating

green kite
#

not boyfriend/girlfriend

hoary nebula
#

vro is keeping her as a backup

frail turtle
#

Sigh

green kite
#

but yeah

#

try to have a chat with her hallicon ๐Ÿ™‚

#

if the ship is sinking anyways, better to know and get out in time

obtuse fern
#

have you actually communicated any of your needs to her, or are you just assuming that she knows what you want

frail turtle
#

I did twice already i told her exactly how hurt i felt and all

#

And she tells me i have to understand her situation, and I do but im the one putting any effort

obtuse fern
#

then break up

#

point blank

#

break up

hoary nebula
#

point blank

obtuse fern
#

it's gonna suck

hoary nebula
#

๐Ÿ”ซ

obtuse fern
#

but like

gaunt gale
#

I was reading this and about to recommend breaking up

obtuse fern
#

@worthy narwhal that passed the line

hoary nebula
#

what did he say

#

I missed it

green kite
green kite
#

now marry me

rustic carbon
#

u know, ive been the cheater before, but at least i admitted i was a douche ๐Ÿ’

gaunt gale
#

Lmao

scenic maple
#

very sad to inform you guys sparkling and qeuemark are no longer dating

obtuse fern
#

but seriously Hall, if neither of you are able to move forward positively in the relationship -- then it's time to break up and move on instead of cheating on her. because ultimately that will make it 100000000000x worse in the long run

meager kernel
green kite
#

is she the same girl you were talking about a while ago when she went clubbing with her friends?

worthy narwhal
frail turtle
#

Yes and it wasnt her friends

terse dirge
#

I step away for like 30 minutes to find cooking videos to post. Wtf happened??

frail turtle
#

It was her family

hoary nebula
#

@terse dirge yamete

meager kernel
scenic maple
hoary nebula
#

rule 5

#

get him boys

meager kernel
worthy narwhal
hoary nebula
#

okay

#

fix

scenic maple
#

how do people eat em everyday and not die

#

i want to be like that

ivory burrow
#

Ey it turned out that was indeed correct call tho

green kite
#

eggzy typing

hoary nebula
#

dead

worthy cargo
#

I just went through an ordeal with trying to reinstall my OS. I installed it to a diff partition on the same disk and it overwrote my /boot/efi entries, so my old OS was not showing up anymore. Holy hell. Plus, X11 is going away and I'm not changing my WM from Xmonad to anything else.

I had to reinstall grub from a live usb image. Just hell.

green kite
#

just get a mac

#

no issues

scenic maple
#

if you are dropped into grub shell you know it went horribly wrong

worthy cargo
#

I'm back on 22.04 Ubuntu

#

I was in a grub shell.

hoary nebula
#

uwubuntu

worthy narwhal
#

grub's hell*

worthy cargo
#

I was thinking, I'll install new ubuntu to a separate partition, but it overwrote /boot/efi which I thought would be commonly used among the two. but no, both use /efi/EFI/ubuntu namespace, that's why.

scenic maple
#

man i just cant find the actual gif

hoary nebula
#

which one

worthy cargo
#

I got my system back. I'm not fscking with it anymore. I'm fine on 22.04 until 32.04. That's how long ubuntu provides extended security support

#

via ubuntu pro free for 5 devices personally

supple plume
#

Vro

#

I don't even need to say it

worthy cargo
#

I'll have to migrate my ZFS volumes

#

I'm also on BTRFS

#

/ is on btrfs and /home is ZFS

worthy narwhal
#

why did you not just upgrade your original ubuntu instance? o_O

worthy cargo
#

Because it can't be upgraded, too many custom/package depends problems. I've tried like hell.

scenic maple
#

bro is not fscking around anymore

worthy narwhal
#

ohhhhhhh okay

supple plume
worthy cargo
#

It's okay. Eventually I'll get around to reinstalling everything. np

supple plume
#

that's all?

worthy cargo
#

Its a COW system copy on write, meaning instant snapshots

supple plume
#

ah

scenic maple
#

thats what sold it for me

worthy cargo
#

That's how I was always able to get back to my original system using snapshots

supple plume
#

good

scenic maple
#

echo you use arch right?

worthy cargo
#

I try an upgrade, it fails, broken package, so I restore from snapshot

supple plume
worthy cargo
#

it's instant too

scenic maple
worthy cargo
#

literally takes seconds, because you just switch to antoher btrfs subvolume

supple plume
scenic maple
#

this will make compressing huge packages lot faster

#

hence package installs a lot faster

#

also you could run pacman in parallel so it would download 5 packages at once or so

terse dirge
supple plume
#

interesting

green kite
#

@worthy cargo did you remove the french language pack?

supple plume
worthy cargo
#

i have no french lang pack

#

what are you on about

hoary nebula
#

rm rf

hoary nebula
#

stop posting gifs of me

green kite
hoary nebula
#

never

terse dirge
hoary nebula
scenic maple
scenic maple
hoary nebula
#

oh nauurrr

scenic maple
#

also some dev stuff breaks in void

terse dirge
scenic maple
#

playwright latest breaks on arch

green kite
#

Hello moon

scenic maple
terse dirge
scenic maple
#

nice dance ceald

hoary nebula
scenic maple
#

never knew you originally from asia

worthy narwhal
# supple plume that's all?

how i remember it is that btrfs keeps track of the original volume and then keeps track of the changes sort of like a git tree, but ext4 is journaling and keeps track of file by file changes. yes btrfs is faster for instant snapshots, but, if the system grows a lot i guess theoretically keeping track of all those changes could become slower at some point. btrfs is more complicated to resolve errors in though... unless you really know what you were doing on your system.

#

i use btrfs cuz im constantly at risk of bricking my shit, and ext4 is just slower

scenic maple
green kite
#

@hoary nebula Fluvius was gonna come at 8 to mine to change my power meter

supple plume
green kite
#

Nobody to be seen yet. Can I send them a no show invoice?

#

If Iโ€™d not be here theyโ€™d send me one

hoary nebula
worthy narwhal
green kite
#

Yes. Theyโ€™d make me pay like >100 euros if Iโ€™d not be here

hoary nebula
#

damn wtf

scenic maple
#

send your stunt double

supple plume
scenic maple
#

comparison is thief of leisure time

supple plume
#

comparison is king of learning time

worthy narwhal
scenic maple
worthy narwhal
#

its only beneficial if you absolutely cannot just reflash lol

supple plume
worthy narwhal
hoary nebula
#

fuck nvidia drivers

scenic maple
supple plume
supple plume
hoary nebula
#

Arch has problems with multiple monitors where one is vertical

supple plume
#

also nowadays I don't have to reinstall the os very often luckily

scenic maple
#

old days were different

#

there was chaos

burnt mauve
#

Didn't realise it was arch as a whole

scenic maple
#

it probably is that

hoary nebula
burnt mauve
#

la loyd

worthy narwhal
supple plume
obtuse fern
hoary nebula
burnt mauve
obtuse fern
burnt mauve
#

I've only seen the shorts of it, never watched it

obtuse fern
#

it's honestly really fun

#

beyond it being a lego show, it's actually well written with good serious moments that aren't undercut by the goofy moments

burnt mauve
#

Nice

burnt mauve
obtuse fern
#

"L-L-O-Y-D I named you"

muted olive
#

its interesting to start typing random stuff and watch the suggestions lmao

hoary nebula
#

lol

unreal lotus
obtuse fern
# muted olive

the first result is actually within the constitution; if a VP takes over for a period of 2 years then they can serve the 2 terms (8 years) after

muted olive
hoary nebula
muted olive
#

try in incognito

obtuse fern
#

even incog can take from your own history btw

hoary nebula
#

yeah

muted olive
#

oh

burnt mauve
#

Incog takes from the history file if it exists right?
Surprisingly mine doesn't, maybe just a librewolf moment

obtuse fern
muted olive
#

third one is more interesting kek

burnt mauve
muted olive
#

looks like lots search for that

brazen crown
hoary nebula
burnt mauve
#

that second one ๐Ÿ’€

hoary nebula
#

bro google just called me gay

brazen crown
obtuse fern
#

it's all algorithms, all the way down

supple plume
hoary nebula
#

nuh uh

muted olive
hoary nebula
#

damnit hitler

muted olive
hoary nebula
#

Ferglar, more like Burglar

muted olive
burnt mauve
hoary nebula
#

stop throwing fridges at me

supple plume
brazen crown
# brazen crown based on previous searches smh

mine was (i don't have image perms)

why do i always find myself distracted (real lmfao)
why is ai detector flagging my writing
<name of a supermarket>
why women kill
why not
why (Sabrina Carpenter song)

hoary nebula
#

L NO PERMS LOOOOOOOOOOOOL

muted olive
supple plume
#

vro my ggl is crazy

brazen crown
hoary nebula
burnt mauve
hoary nebula
#

hesus

meager kernel
supple plume
eternal mango
#

Damn, accidents happen