#general
1 messages · Page 244 of 1
check out him @lofty warren
Man
No
close ur eyes
Omw to the office 

Hey @austere sinew get pinged
slavery 
Daily freebies
u mean internship?
Shut up you spoiled kid
Because hi
I am not spoiled
i would have said hello instead
I am a good

LMAO THEY DID THIS TO ME TOO
you got unsolicted dm?
Yuh but tbf I do that a lot to people so I’d feel guilty
But also I yap with those people beforehand
Ehehehehe
ye
Chat, Imma install Garuda on all of the workstations at the cyber range 
oh oh
i saw that
do a /verifycertification with cwee to get that role
Indian scammers better
Btw golam how's your uni going
You must be pulling girls with those skills
"Tumi ki inasțāgrāma ayākā'unța hyāka karatē pārō?"
Why did you redeem
What is that
Do anyone go to blackhat mea?
issa linux distro
yer a linux distro harry
oh
yer a five year old Britain-based consumer electronics company, harry
Which makes it based
would be cooler if it was Darude linux
Arch also has out of the box rust kernel hacking
Debian doesn't because it's not sigma
*bad
Is debian considered stable?
depends on the OS tho
ubuntu is stable, kali is not
Isn't there like a base debian?
Like normal debian OS?
tbh, idk
yes
Is it stable?
yes
Yes but it's slow and its security model is weird
Also it's behind in packages when compared to nearly everything else
I've been analyzing phishing emails all morning, Zzzz
Skill issue
Which distro would you personally recommend?
FEDORA
Void Linux
Which is stable and doesn't require that much troubleshooting
I don't wanna troubleshooting 1-2 days all the time
It fast, niche, stable, and up to date
I did try Fedora
It was good
Sucks
Atleast on the surface, fedora was good
Works well with nvidia GPUs?
The way fedora releases new major versions like going from fedora 20 to 23 or whatever is weird
Does any Linux distro work well with Nvidia GPUs?
Windows
No
I am on windows
all of them do
🧍♂️
Windows >>>>>>>
News article: http://silicon-news.com/news/2012/06/17/linus-torvalds-nvidia-fuck-you/
Linus Torvalds reveals his true feelings for Nvidia.
Windows is better than what Linux fanboys say about it
we gon fight
It has some bad features but you can always disable them, and use things like CTT utility to debloat many things
cant use safari on a windows machine, but you can use edge on a mac
Apple just sucks
Apple has a good ecosystem thingy
And I like their iPads but iPhones and Mac?
Nah
because work gives you a macbook for dev stuff
That's when you leave the company and find a new one
What exactly do they give that windows or Linux doesn't?
Unless it's a decent one with a non arm chip
i mean do i really even need to attack windows
Nah I'm talking about windows vs Mac in development
How would mac be better?
its a unix system
punix
Windows is easier to centralize infrastructure for
mac sucks
to each their own, but i use a macbook
macbook with exegol is quite a functional enviroment for CTFs
I heard even HTB gives it staff macbooks for work
Also to learn ARM assembly
I love macbooks, like their physical features and all that. Only issue is that it has MacOS on it.
I like how sleek macbooks are
yes, that's why I don't use it 
I had a macbook couple years ago
I liked it's form factor
I used mac for one complete year
macos vs windows 11 is like the southpark giant douche vs shit sandwich
That's what she said
Man why do y'all hate windows so much?
It's definitely not a good OS and has problems, but it's not that shitty
I like windows because I've been using it since childhood 
didnt say i hated it lol
Apple laptops usually comes with better hardware unless u get a really high-end gaming laptop
Same pretty much
I've tried many times to move to Linux but I find it difficult sometimes
For cybersec, Kali Linux all the way
But as a daily driver, linux as a whole, nah
Unfortunately same 😭
same stack
They cost too much
if you want to do maldev, reversing, or anything like that, you almost always need a windows machine tho
But yea their hardware is pretty top tier
mm not really, I find it more effective to do that on linux
reversing etc
reversing windows binaries?
exactly
Compare with the type of laptops that give the same hardware specs
Yeah, apple sets a standard of premium hardware on their laptops and phones
That's their branding
yes, ghidra can do that
Another point towards windows is gaming
Most games are almost always targeted towards windows cause that's the most profitable
yeah you can disassemble the binaries, but tell me how you are going to run parts of it
Valve has something to say about that and I'm looking forward ngl
ex: RE .NET cannot useful at Linux distro btw
Developing malware would usually be focused on a windows playground simply because windows is the most used desktop os
Yea but it's about their OS
Steam OS is made immutable and made in such a way that games would run well on it
That's definitely good, I'll give it a try myself
But when you talk about other Linux distros that people use and customize on their own, each person uses their own DE, WM, own different things and then they might face issues according to it
I read on twitter about a game dev ranting about linux, he said that Linux users make up a fraction of the game audience, but make 90% of the support tickets, huge loss
Ofc they make the most support tickets
Gaming is so vendor locked to windows
Same with malware dev (unless your target isn't someone's desktop)
gaming isnt locked to windows... dont yall have phones?
Well you can't expect a game dev to cater to all kinds of Linux distros and different window managers and different desktop environments
Sorry, desktop gaming*

Steups
Im not blaming the gamedevs
Get it?
Yea yea
I got it
It's kind of an issue on both sides
Valve is trying to bridge the gap little by little
So that's good overall
Alr guys see ya later
Yea
Bro
I have mastered Linked In
I swear
I'm about to make a Linked In course
Whos buying
Why would anyone use windows?
I’ll sell you a LinkedIn course for $500 on how to make $500 quick on LinkedIn
What do you even teach in a LinkedIn course?
That everything is a teachable moment in b2b sales or something
Idk using LinkedIn hurts me inside
The course content: how to sell a $500 linkedin course to earn $500
doesnt linkedin learning also have htb lol
That’s a different thing
But yes
There was a book on Amazon that is essentially that
I always get follow request on LinkedIn from random people idek
I'm more famous on LinkedIn than instagram
The true life changing book is Doug Doug, a Doug Doug story though
Not for networking?
I use Cisco packet tracer for that
Lmao
Networking on linked in kinda sucks imo
It’s all very… fake
Please do not hinder your career by not liking LinkedIn. I will teach u how to use it
That's true yea
It’s just corposlop man
I just use it to flex
I have no interest in that
Most of the post on LinkedIn are AI slop
but i found a job i think you would be perfect for! can you just send me your updated resume and cover letter and let me know if you are interested?
I just network via discord and meeting people irl etc
It’s more genuine
Tru
And builds better connections
Thats facts Emma
Kubuntu ?
Once I get some time I'm gonna do a BSides where I am. Cause its pretty dead atm
Of course. Would you like to hear my story about how tripping on the sidewalk helped my b2b sales strategy too?
I network through connections
My father calls his friend, I talk through his friends to other people and get employment like that
Agree
They’re amazing
ARCH
There is sometimes city sec or defcon groups too
I have some local monthly groups that feel like a mini defcon lol
WE USE ARCH
How many times does it break in a week?
Arch is so 2020 man
All my homies use VibeOS now
It’s all vibes
Don't bring some low lvl junk
Never, if it breaks skill issue
Arch is for 15 year old Linux fangirboys
@lime trout is it true that HTB gives it staffs macbooks for work?
Yeah
I see
you should use arch btw
There is
What's the advantages
How many of those advantages have come in your use?
You can say
I USE ARCH BTW
Is take rock solid stability in exchange for whatever arch provides anyway
I mean steamOS is arch based
I can win argument
This is more accurate
I do broda
Show
Don't want waterfalls here
Aight

no x, no y, just z
sound familiar? 
Bro you can now add github projects onto your LinkedIn profile
Ik but it can be debian based and have all it's functionality still
cutting it real close there
Also I am pretty sure steamOS is immutable

It is
whats immutable in that?
That basically negates all the classic advantages of stock arch
Mickey mouse is a billionaire
You
you
Small operating systems like arch and alpine work well with the small constraints of embedded programming
DOL GULDUR
who is that
Your5Truly
bro types like a snail
no
But question..... if I wanna make an os on browser.... only support web assembly or also support js (for javascript slopware compatibility)
your5truly
No
I suck on phone but 90 wpm on laptop
you sucky sucky on phone
No to which one
Candy is spamming the reaction button
No to WHICH one
Lol
Where is Lady Of The Vail?
this is how you know this book finna be fire,
Day by day I get incentivised to stop talking to humans and start talking to llms /j
warum sind das 60 fps?
Why?
yes and so far so good
I hear they're more responsive @west venture
No to what?
yep
Bruh i asked a question, u pinged me and said no
No to "don't support js" or no to "only support webassembly"?
Oh okay
💀
yes
I don't really remember the details of things that happened more than like 40 seconds ago
9/10 ragebait guys
Or I'm very irritable rn
So I might have a reason to respond the way I did, but I mostly lose my chain of thought
have you done any research on this
Yes
WHOO
Joe mama
Mhm & some decent headway too
so a whole operating system inside your browser?
And not just a cross compiled linux
well good luck
i havent seen someone do it yet
let me know if you are the first one
Obviously I can skip over disk scheduling and process scheduling in terms of access to the cpu
But yeah process management, isolation, filesystem, interfaces, permissions, etc
I'm a few months in (well sorta I also havent touched it for 2 or 3 months) but whether to support js or intentionally not support it is my question as it would severely define how I move forward
starting today, gonna try aoc in rust :D
Supporting js means more work in sandboxing but I already started there and it's just to sandbox the css (crazy as that sounds)
i just know
fn main() {
println!("Goodbye world!");
}
But then should I intentionally say "nah no javascript use a real programming language"
if i were you i would do a canvas with web gpu and web assembly for running it
Cuz ppl can code apps on js possibly faster than using zig or c or rust
Yk the vscode fanboys.... it uses electron just to use browserjs to run, the entire electron bloatware gets avoided if js is supported (as it's already an os on a browser)
?
Huh
Brainfog
18yroldbaby living up to the name 👀
I was gonna say react also gets instantly supported but then.... idk if it would be nearly simple to implement react native
Long story short, should I forget about supporting js even tho it's already on a browser or not
Does anybody see advanced search in new htb UI for retired machines??
gubarz
htb with preworkout >
All the official regs still refer to it as DoD as does out local industry. However, I'm OK with the name change. At least they're calling it what it is. They've still conveniently forgotten the part where engaging in one take an act of Congress to declare and fund.
the rename also requires an act of congress
so it's really just glorified 'well it's on paper technically' but not in practice or law
good points as always Marcie
htb never disappoints
it's like the 'don't talk about your salary' thing, legally they can't stop you.

but the beta ui disappointed me
i've always found the American vs Japanese approach to this topic interesting
@warped plank
academy or labs
Is it just me or can the new UI on HTB not sort on machines according to User-Rated Difficulty anymore? I can click every other column in the machines tab to sort them.
I know you aren't asking me, but from what I know, CPTS is MUCH harder than eJPT
i feel like total ass
How's the value of CPTS in the industry
Not very good
It's okay. I don't like corporate much anyway
hi Donut
Uhh yeah
dawg, eJPT it really piece of cake tbh
but its too expensive 

any hacking today?
Niche certs like CPTS will carry more weight at consulting firms than on internal security teams
Polishing up some burp extensions this morning, then web pentest for the rest of the day
Experience > certs
are there any extensions that format the output of the request
i am currently looking for one
How would you like it formatted?
Burp has a "pretty" view option
I believe it goes off the content type, so because it sees text/html it is not formatting the JSON
Switch it to application/json and send again, it will pretty print
Do you know how to do that punycode account takeover bug?
so - GUID bruteforcing - whats your thoughts on that @heady sage @zealous charm
no auth other than a random guid
no ratelimiting
I dont know that i've seen that one, but is it just abusing similar characters in a email or something?
I think It's kind of anoying
valid bug? 😆
ill send you the freedium link in dms
I mean can you see other users info?
yes
Then it's a bug
ofc
tried 2000 combos - no hits yet , but the only identifier is guids
Without a UUID oracle it is difficult to acheive, but not impossible. UUID IDOR is a valid bug, although low severity. Tokens get logged in tons of places such as emails (URLscan.io), historic URLs (wayback machine), and search engine indexing
yeeah just found something that shows PII if you get a valid GUID
no auth needed, no ratelimiting
Fuck right off that's cool
I wish I could do that
found a bug last week in a government entity, could read all files on the server 
I cant even get a bug in synack
Might also be worth playing with the parameters to look for older specs, for example can you change ?guid= to ?id=1, etc or try test GUIDs like all zeros
one of my friends reported a critical bug on a gov server, they fixed it and never replied to his mail 
found a funny param
I've tried yeswehack, hackerone (which enforces a requirment for signal), bugcrowd ( which I have some success on) and synack
I feel like those are the best kind
But nothing intresting pops up
they invited me to a private program and I got a little bounty
Synack is pretty good for US-based hunters if you are on the federal platform
I applied to synack a few times
they said they had plenty of my profile 
but why would they not take you

Unless of course, anyone has otka misconfigs I can check
plenty of people like me 
Not even sparklingrecon is detecting anything anymore
Which btw I named the damn tool after you @green kite
I applied after I got CWEE, and again after CPTS

❤️ @heady sage
with CPTS
with CWEE after I saw they accept CBBH
and with CWEE after they started accepting it
you got in? 😅

thats crazy man
Fuck!
then what kind of people are they looking for
I was hoping to have people to hunt with
offsec certs ig
Anyone feel like Darknet Diaries fell off?
Im half way tempted to go back to NASA
CEH does not help
So I can farm letters
I also have CEH 
Listening to the past couple episodes and I’m just like eh this isn’t really that interesting
anyone with CEH would be too good to do bug bounty tho
the only certs you really need are the ones @exotic pendant has
exactly
It also didn't help that I listed "I know frostb1te_"

I was expecting a full ceremony
I put _ on my HackerOne because frostb1te was taken
I’ll do OSEE eventually once it gets funded
hellllo chat
release da files
yeah but you need osee too
OSED, oswe and osep
OSEE is the advanced exploration
yeah
i'll never pay them from my money lol
do you need that wireless cert for the osc3?
💋 💕
No just OSED, oswe and osep
Do you think OSED's the hardest out of those three?
tbh i already had osep and oswe, so i asked them for the osee, thought it would give me the osce3 but yeah whatever
feels like that to me just by looking at it
OSED < OSEE
Depends on what you’re good at
I see
OSED - pwn
Oswe - web
Osep - just OSCP but harder
OSEE?
& OSEE is like advanced pwn
OSEE is OSED on steroids
oh
windows pwn
no harder OSCP is just OSCP+, then OSEP
OSEE also requires you to go in person for training
but OSCP & OSCP+ are a scam to me
I’m taking OSCP+ for fun this weekend
I didn't know that 👀
Frosto is bored and is just retaking it
Aren't OSCP and OSCP+ the same exam? I thought Offsec gave you both because one would expire and the other wouldn't or something
dunno
Don't you have to pay or something
Yes
ngl i feel like certs like oscp are kinda a scam, they don't really bring much to the table, might as well just tryhard straight for the osep and it'll be way more worth it
I feel like OSCP is easy (in terms of exploitation etc) but... money 🥲 💸
Yeah I mean report writing for new people is decent for that
oh hm yeah
i guess that helps
My shadow21A is taken by some chinese guy on few platform
I put 21A as random still someone beat me to it

2B
2IA
I had to make my twitter with Shafow21A 😢
why not Shadow2IA
I didn't think of that at that time 💀
But yeah. 2<capital i>A
Oh?
Lowercase El then
Or get that other guy banned 
And get it
You should've used Shаdow21A


Let's try
u arabic?
yeah
is there a way to share HTB Academy profile link same as ctf profile??
algeria
I thought you were French 🤔
ah I see
do you live in algeria or france?
france
makes sense
im born in france but i can speak a bit arabic ahah
darija but i also understand fusha
ahahah
aircrack is french
😃
so many french tools
certipy
nxc (wait maybe it's german)
responder
^^'
even docker is from france iirc
ok wow I did not know that
nxc isn't french I think although their main contributors include french people
docker is from france yeah
yeah
lol
academy
did you get that new govt app? @devout sail
the app which is going to be preinstalled on phones
Oh i use 4yo phone
report fraud etc
so they paid 15k$ instead of 1.7k$
I'm gonna just disable it if I see it
👀
that would be for SANS
Tf 15k$ for a cert???
no need to
SANS certs go up to $10k
OSEE training takes place in France?
That's alot 
You could buy a car with that money
If someone buys SANS certs out of pocket without their company sponsoring them, they are likely clinically insane
Mhm i mean if someone is going for such certs
They are probably already at senior level in career and earning enough
there goes my plan for this weekend
jokes apart, my father was saying he could buy the SANS cert for me
though they are extremely valuable
@native plume sponsor my SANS certs
out of his own pocket
yep !
but the exam is online lmao
Yes just let me start my money printer for you
probably
I mean SANS certs are very valuable so if he can do that, go for it
Hope u got some experience with windbg then
same time as getting arrested for counterfeiting 
Long enough 💀
That's cyber's problem
yeahh i hope ill do good :p
oh you've got it scheduled already?
good luck
You'd be able to sponsor everyone here
Hey
^
print("k"*10000)

Apple of cybersec
put a SANS bro in front of a medium box and see how fast he shits his own pants
fucking play-pretend starbucks hackers
but their goal isnt to hack htb boxes their goal is to make money and they make more than us combined
you can't buy your way out of being a brainless clown though
sans certs get them an advantage
agreed 😩
dang thas crazy
maybe ur search wasnt right
SANS is just for linkedin boomers with a Macbook
a=4
b=10
c=b**a
for i in range(0,c):
print('k')
obfuscation 101
wat bro stop stealing my cookies
to make things complicated
Now do it in JS
🫦
Bro 😭 lmao
lol
bruh
you hacked his login
let num = 10;
let output = "";
for (let i = 0; i < num; i++){
output+= "k";
}
console.log(output);
anyone know how to decode otka flow takeover
Vro is enjoying December
this was quite the exercise not using any js libs
Sir keep it pg13
goal was to print it 10,000 times not 10 times
rejected
interview failed
please tell me i forgot alot of pass
Ranger of the north, the Dunedain
actually we could have done this
const output = "k".repeat(10);
console.log(output);
much simpler
I'd say maybe recent events would help js devs cut back, but I doubt anything will change.
done
goal is also to make it complicated or else you could just do console.log('k'*10000)
I aint slidding anywhere
nah npm has those daily and honestly they dgaf
you know what else is tingling
and this is how you stay employed
you should be the only one who knows how to debug
leave a backdoor in the app as well
lock it if you get fired
thats neat syntax i am gonna use this as a backdoor now
ty
-# for legal reasons its a joke. go home fbi.
solve a problem
BE A PROBLEM ✅
if your code is readable then you can be replaced
lets go
obfuscating it helps
♟️ ⭐
i actually have a js obsfucator
stop sending it My cookies are limited you got them alredy enjoy
wait let me show
turns one line code into million line code
send link senpai I have been waiting for you
Join the challenge or watch the game here.
I'm waiting 😩
nice
oooooooo, cool 🙂
I thought you gonna move it 😭
Experience the pinnacle of keyboard design with the LEOBOG Hi75. Crafted for the discerning user who demands both style and functionality, this keyboard kit is a game-changer in both aesthetics and performance. Revolutionary Mode-Switching and Enhanced Control The EPOMAKER x LEOBOG Hi75 introduces the innovative knob,
can it compete with an Apple keyboard though
I want a custom keyboard 
I know my stuff
@hoary nebula
but CPTS is more important
Yannick is doing cpts?
lol no
no, me lol (at least, gonna prepare for it soon)
cooool
@native plume vro go easy on me 😭
Alright 😭
210 dollars out of my bank account 
-# I thought you were talking to me for a sec LOL
I'll do botez gambit
Botez gambit accepted

tell more about this keyboard
You have to beat me someday senpai 😩
that's a Alice 75 dude
@mystic harbor Ggs senpai
I am so stupid
bor is jerking it

Practice more to beat me 😩
why is bro wanting to be beaten
In chess not somewhere else 💀
no
This man gets off on suffering, i guess💀
@devout sail post the whipping emote
you are learning game dev?
insta reel
no
ouch hurts
im sending on ur dms
ban this entire chat

!ban everyone
+1
i am already banned
+2
then me too
i think i got covid rn💀 too fkin headache
DAMN bro
thats a bit of an L
tell ur immune system to step up
its better tho but idk what happened
i feel like i got malaria
how is this
isnt it cool
@hoary nebula
ya
yea

@native plume get beaten
im not cough, but i think ill goin to buy a kit-test
he likes it
Senpai 😭
💀
gogo
@mystic harbor Bro that king took a tour
stop deleting
is /verifycert smart to do? Like you can never see the Labs rank color again haha
u can leave and join back to get rid of the cert
Then i dont got my original join date anymore at my profile
I wnna send some racist memes but the angel on my shoulder is telling me not to 💀
well you better listen
Yea haha, prolly will keep rank for now and in the future maybe if i got 2 certs will add them
More than just angels will be on your shoulders 💀
I loose
@mystic harbor enough for now senpai 😭
yea
Ggs 🔥
I play like shit
But you played well tbh
false
it's been long since i played that game
And you're good to go
hmm
Try practicing tactics
And also theory, i viewed your match
ahh i dont wanna compete

Say in the mirror
This word can only be said to you
HMM
I know many
Which one do you want 👀
trying to figure out if i want the lelit mara x v2 or lelit elizabeth
smh
Idk what either of those are
Hehe I’ll hop on VC on the other discord in a bit and teach you lol
coffee machines
the discord I'm in?
like the VC I'm in rn?
Ain't nobody know nothin
Yep
Ooooh coffeee!
noice
coffee is too bitter tbh
creemer, sugar, even green latte (or whatever its called) doesn't help
its still way too bitter
You’re too young donut, you’ll understand soon
I drink coffee the way it’s supposed, black
Hi guys, how are you? I was wondering if someone of you, had the certification of Comptia Security+
sec+? I've heard its really good
Woooow GG man!
How was it? I mean it was difficult as it seems or pretty easy?
I only studied 2 weeks and it was mid difficulty, some questions I had to guess
study the performence based questions
Yes that's what it seems to be in the world of HR selections ahahha
the labs count a lot Ive heard
Ummm interesting, for example?
2 weeks?!
There's some Youtubers in particular that u can suggest me?
Yeah straight after CCNA my employer wanted me to get my sec+ fast too
DAMN
That's very fast
I have some exp in SOC analyst tho
@elder inlet where you disappear off to 👀
Anyone know when will be HTB university ctf
@elder inlet @elder inlet @elder inlet where you at
Oh ok that's why for you was not that much difficult wasn't it?
professor Messer I think his name was
You’re gonna get muted by the bot lol
December 19th

For someone with no exp at all, it will be very difficult
Thx mate
My sec+ expired years ago kek
Ok I see...I have a bit of experience in that cybersec world but not sure that is enough to pass it rn
Why u didn't renew it?
I need to be a university student? sad, I'm not one yet 
Yes, you will need to select a university to join
Don't really need it
me too...I've lost five years of school and now I've should been out of University since 2 years... this is so embarassing...
I dropped out of college
I guess I'll join in 4 years
For my bachelor's
Ohh ok to me they said that is one of the most important sec to have years after years
I just didn't have the time. Perfect 4.0 gpa tho
Can somone select a university and he is not a student i mean ( graduated from this uni )
When you're new, yes
Once you've had your foot in the door, no
Oh ok that's fantastic
Nice gpa
You need active access to the .edu
I mean, less money to spend ahahah
Automating obsidian with my streamdeck
Agreed 😄
ah, nice 🙂
I didn't even join a VC.......
join it
Busy
comeon 
What is a VC
Ooh fancy
Voice channel














