#general
1 messages · Page 251 of 1
I get weird notifications 💀
hnnn good argument
I'm gonna go do prolabs
but prolabs want to be done by u?
consent
people
How much time you wasted listening to screams and signs
please
I dont have that Im using widsurf
use AIstudio or maybe open windsurf settings somewhere
there has to be the temperature setting somewhere
I asked do you mind? If you do, say so.
It didn't say anything, so yes ig
i am going to report you to ai overlords
Clankers are my friend
is not true
Google then
Its fine I ran out of tokens
Good
Good for you
Look at this shit
i totally understand lol
brotha
It decided that all the code is trash
maybe it is after all
It is but I haven't done it I just have to add something to it
@carmine pecan @austere sinew got another interview in 1.5 hours 🙂
In order to get paid
BOTONES FIJOS EN EL BOTTOM
I died bro
aw hell nah
tell windsurf to watch this https://www.youtube.com/shorts/SEVD2nI4Bis
Twitch : https://twitch.tv/ThePrimeagen
Discord: https://discord.gg/ThePrimeagen
Support me (by becoming a backend dev): https://boot.dev/prime
@austere sinew
BOTONES
just got to work. Time to slack! and by slack I mean "professional development"
hello chat
Our company wants us doing up to 4hrs/week. I have a couple of books I'm reading about personality/emotional IQ stuff that I can tangentially apply to the workplace 🙂
How lucky
I wish my job allowed me to study
Anyway im free for today 
minimum wage employer meets minimum doing employee 💪
Literally
It's funny because I feel like I do 5% of what I can do
And they are still fine with it
Specially now with the vibe coding thing
wait i have the perfec thing for you
some consider it unethical but as long as your employer is happy i dont care
Having multiple jobs at the same time
Isn't it like having multiple gfs at the same time?
I should consider it
i have nothing but respect for the people who work hard to meet the needs of 2 sides
- one for employer who needs his stuff done but cant pay him lots
- one for family and personal side who need money to stay good
Correct
Probably making htb boxes would he a good side project
While at my job
As long as the job is done at 3pm
Everything should be fine
sure whatever works for you
Maybe doing the job at the first 2 hours
And uploading the commits during the day
Setting up alarms on my phone
Wdym
what do u think that reddit is for
I wish I just had 1 job already
Ive seen people flexing about their stuff only
anyone looking for a remote programmer
no no never flex
reddit is a waste of time
thats how you get caught
I argue with stupid people on reddit and end up being the loser for both wasting my time and being beaten by experience
Christmas is about giving
I never used reddit
so I'm giving up
I don't find it useful either
everything has its uses tbh
Most things are a waste of time
Maybe
and its not illegal (unless you signed a contract)
It don't mattah, none of this mattahs
Vro what is going on with you today
I'm just goofing around lol
Unfortunately
I have a doctor's appointment today and then I'll be hitting the gym yeehaw
Where is the green stuff
its winter
That planet doesnt have land
Southern hemisphere
🍆 👊 💦 🪳
Vro it is just a vegetable relax
u know, I know. No one else to know that🌚
Right
Higher resolution mode
I'm actually blown away. The game looks incredible in both the 1080p 60fps mode and the 720p 120fps mode
this will never get old
Vro
well thats how they steal ur stuff via tufflehog
Or is the thought behind the cred stealing that it's way too late lmao
dawg @supple plume got trigged💀
like every other threat actor they dgaf
Oh, so they name the repo something easily searchable and stealable once it's public
Ive heard that using pnpm doesn't execute this worms code
Smash and grab technique still works, why add any complexity
I've been fighting this stupid worm for a few weeks now
let me send u my repo pls run it using pnpm
I don't hate my life or anything
Ok
Maybe I upload the worm to your repo
listen bro no matter what js framrwork or package manager you use
if its javascript there is 10x more chances you will get hacked than anything other
Seems like it these days
Dang
i stopped using node since a the incident
I like js...
i mean sure it has some perks
but i feel like it created more problems then it solved
Time to code C and make everything from scratch
have you ever heard haskell get backdoored?
functional programming is a way to peaceful life
I didn't, I never used haskell
thats the point if there are less users there are less threat actors for it
and thats why cobol is the greatest programming language of all time
WHO ARE YOU, I DONT CARE IM RUNNING MY FUCKING COMPILER 📞 ☎️
go backdoor npm
Frontdoor if possible
Backdoor is busy
Time to use my time wisely
Please no pings
Thank you
Thats a peachpuff without the xterm colors
Ugly
😄
tbh thats fair it doesnt say how to start typing
Easiest way to use vim is to close the terminal tab and use nano
But it says how to quit
Download/Stream: https://anyanami.lnk.to/bread
Follow Anya Nami:
Instagram: https://www.instagram.com/theanyanami/
TikTok: https://www.tiktok.com/@theanyanami
Lyrics:
All I, all I, all I all I wanted
Was a bit of bread
Mama called me disappointment,
Papa called me fat
I like it garlic, rye and brown
Banana, honey bun
Brioche, focaccia, naa...
Vim sucks
It doesn't
average discord ragebaiter
I only use vim when I have no choice inside the shell of some IOT device with literally nothing installed
Avg nano user
I like my text editor like I like my brain size, nano
i 100% use nano and dgaf
obviously necessity is the mother of invention. In my Linux class we were shown how to use VIM and Nano and told to use whichever we liked. Obvi if vim is all I have I'll use it and a cheat sheet just like the one I use for other asinine tasks that are necessary but not frequent enough for me to memorize. I'll pick up the skills in time with use but unless mandatory I don't do things for the sake of doing something difficult.
Any hacking today?
i use only nano:D
Just use cat and echo 
💯 nice! What was the LFI on?
Vro what
language change feature
development
Extend your explaination further
they blocked ../ but i used ....//
For advanced users 
so like ?=japanese.php
dont have the code but this is direct in url
Hmmm
All Unix Commands except “echo” and “cd” are useless bloat.
Who needs an “ls” command, when you’ve got:
echo *
Who needs “touch file.xyz” when you’ve got:
echo -n > file.xyz (or alternatively, type “> file.xyz”
Who needs an “cat” command, when you’ve got:
echo “$(<file.xyz)”
Who needs an IDE or Text Editor to save your files, when you’ve got:
echo “insert ascii text here.” > file.xyz
Unfortunately, echo doesn’t replace the functionalities of the “cd” command, so you’ll need the “cd” command installed alongside the “echo” command.
Therefore, I have concluded that, in fact, you only need two Unix Commands to use your computer, “echo”, and “cd”. All other commands are useless bloat.

What? How do you run ssh with echo
Sounds like bloat to me
no we infact do not need cd
we need gcc and echo
We should create a command cdecho
Time to solve issues with a computer that other people made with a computer
😄

I also had ice cream for dinner lastnight
how does it scale
was a strawberry upside down protein ice cream
Hell yeah, halo top?
fr
What type of content is not allowed to be made in regards to HTB? I know they are strict on not sharing revealing details on certain things. I assume making videos about retired/starting point machines is fine. What about academy modules? Thanks
only tier 0's are allowed
Correct
The rest is paid content and revealing paid content is big no no
wassssupppppppppppppppppp go green
go green
hello
where is Atreus dawg
in my nuts
beautiful day to have reading abilities
Im using yay @scenic maple the aur helper that you like
you wont look back at any other aur helper ever again
ew
I got tired of that shit
I use snapd
ew
Get out of here
💪
whats an email engineer
Here's the stuff they'll be asking me
how are you gonna grep data
who needs grep when you have eyes?? bloat
valid point
what about poweroff
the lion keeps unnessecery empty files
WAT
I know
HTB lost one of the most pervert user
I'll go ping him on other platform
Maybe after waiting for an year
That seems like a reasonable time
Finally
yeah manmn
pen tester use pen elope
yeah sometimes I customize my own stuff to much
pwncat or something was too much for me
and there are already good things out there
ill start with penelope
you didn't see my full arsenal because I had to format my computer
arse?
yeah
I don't want to
arse weaponry

What attack box
ATTACK
Non-subscribed user can only deploy the free AttackBox for 1 hour a day. Subscribe for unlimited access.

maybe the PWNBOX
So maybe it reset after 24h
maybe he lives in mars
oic
ty bro
it couldve been a timing reset thing
rather than 24 hours rolling
I wouldnt know
thanks for being an arse ig
I do, its just kinda late and I dont want to have to find my laptop
I just wanted to try booting it
or install arch baremetal
did someone say arch
no
some of us use arch so if you need help ask around here
gotcha
mb
nice
I made coffee!
That coffee has: Black Rifle Coffee, Coffee from a Louisiana Plantation, and the frothed milk is Canadian style, Maple Syrup with Half and Half.
@lime trout
I CRUSHED IT
my interview
@meager kernel
^
?
what was the job?
I thought 🥜

what?
you pinged me shadow
I asked what happened to your setup
as in my OS?
Yes
Arch or something
I tried installing Fedora, failed for some reason, tried Arch, failed again and then cried myself to sleep
vro
Come to debian
maybe im meant for windows
you never asked me for help
Maybe yeah try Microsoft Arch
i was tryna do it alone
and idk
i wanted to learn on my own
time to get a split keyboard 
where do you got stuck?
How much
trying dwm
time to spit on your keyboard ✅
@sturdy thistle has one iirc
Ngl those stenographer keyboards are fun
If u are willing to learn
im checking it out atm i will get bare bone kit cuz i already have key caps
I do yes
yeah and wizard too
it looked pretty cool
what's wrong with kde
do u recommed it?
yes
Are u 8?
vro high school is a place
nothing, i just kinda wanted to try a WM
Oh uh
this is pretty nice i have this but kinda got bored now
Parent permission where
it does
wut, parent permission form?
i have nvidia + hyprland
I completed it
vro delete that quick
Yeah no it isn't 💀
Oh nice
To be on htb
yeah
THEN WHY DOESNT IT WORK WITH MINE AAAAAAAAAAA
Do u like colors?
even without discrete i was using it on my cpu which only has nvidia
fine ill run an Arch VM rn
Im configuring my distro rn
not on desktop
Doing some maintenance and installatijng stuff
I thought the GPU with TI are expensive and not cost effective???
my fellow kitty terminal user 
Let me know id you need help
we cultured man
-# but why
In life?? 👁️👁️
I thought you didnt have parental consent
should i just stream the installation process?
ah lol
in VM
i dont like much colors in my room, i like decor tho
oh, yeah
For this he said
what should i choose in this
Okay, your pfp , keyboard and website says otherwise 💀
its for Arch
40 isn't much
thank you @scenic maple for letting me know about the parental consent
what are you going to do with it
Do 100 atleast
yeah that just goes with my name that i picked when i was 16 so
keeping that persona
just try installing shit and learning how to configure
I need to fix kitty for my arch
40 gb is good
idk why it terminates immediately after it starts
arch is about 1-2 gb if im not wrong
Not gonna use it for htb!?
You can space more storage
It's not like you lack it
lmk if i can help
maybe a bit more
I am running kitty is very weird way
I'll work on it tomorrow, will ping ya if I need help 🙂
I don't even know if that's how it should run
I'll try to troubleshoot tho
It has weird files in tmp for it to run
why would i use arch for HTB?
I have Kali already
Hi everyone 👋,
I need some help with a very specific situation involving Active Directory enumeration through proxychains.
I'm working inside a lab where my only pivot into the internal AD network is through a SOCKS proxy created with ssh -D, and everything that goes through this pivot must be TCP-only.
As you know, proxychains doesn't support UDP — so tools like kerbrute, ldap pings, and some user enumeration techniques don’t work because they rely on UDP (especially for Kerberos and RPC behaviors).
I’ve already tried alternatives like chisel, but since it also transports TCP only, I run into the same limitation.
i use pywal for all the colorscheme through out the setup including neovim
Thats what kitten do they steal a sponge and hide it under a couch... Why wouls digital kitty behave any other way?
which one do u have?
I use arch for htb it's cool if I have the tools installed
btw
Idk i didn't bother with it as it was just working
But kitty wouldn't start so fud some shenanigans and it keeps something running on tmp
Kubuntu + Xmonad 😄
i like the preinstalled nature of kali
I think you can force them to use tcp instead
Fair enough
and why does kerbrute exactly need to use a UDP port ? what are you using it for
i forgot the first few steps i need
in arch install
theres sudo pacman -Syu
what else
i completely forgot
it's writing a letter to parents that you'll disappear for free days
i rather just install it with archinstall rather than doing manually ngl

i used to do it manually before archinstall

how the fuck
Y'all make me wanna do it too just cuz why not 
Arch is overhyped
I think is the protocol, always using tcp, i dont know how to change it, and is because i can reach the machine with pivoting and to enum valid users with proxychains or chisel is like that :c
+1 nix is cool but too much for me
i rather use nix but im not man enough
I use Kubuntu + Xmonad. I like KDE but I don't like Kwin. I like Xmonad better
kerberos is always available over tcp
i like to have a life outside my PC so thats why i use windows
Hmm from what I know the proxy sends shit one by one and rpc and stuff needs some sort of parrellel connection
Totally pulling this shit out of my dead brain but i vaguely remember something like this happening
But I can confirm I have recently did machines with chisel and manually forward every port required to same port number and it worked (actually dif the same with proxychains too it was hit or miss but worked 70% of the time)
what's the error you are getting ?
did you created multiple partitions? maybe youre in the wrong one
What's the smallest size I can make for arch
Just for the sake of installing one
5?
It is not and error when i use impacket tools it can enum valid user to spraying credentials, cause it is through UDP and chisel and proxychains just use UDP
i did like 4 times the fking wreath room in THM and i can't find a hint :c
idk are you going to install anything else on top?
the smallest can be very small
Like what everything
The necessary stuff yes
Alright 10gb I'll do
it could work
@supple plume pulse audio or pipewire?
try adding the blackarch repos
I don't use audio drivers but I had pipewire before, painful stuff
not hard to install tho
usually
its installing
ok
@supple plume did you fix the BOTONES FIJOS
😄
nah I just shut that down
good
BOTONES FIJOS EN EL BOTTOM
BOTONES FIJOS EN EL BOTTOM
wh?
how do i exit the chroot environment
@supple plume how do i exit the chroot env
how do i make a VM in the cloud if i want to
pulse audio still works best for arch with steam games etc
vro
blackarch repos check them out
I guess after running the archinstall script
you can just reboot
ctrl d, exit just like any shell
maybe type 2 word so i can understand 
BlackArch Linux is a lightweight expansion to Arch Linux for penetration testers.
this is a distro that includes a lot of tools ok?
like kali
but for arch
these tools can get installed without pacman but if you don't have the mirrors in /etc/pacman.conf to fetch them (repos) you can't do it the easy way
my goal is different xD
im gonna get the minimalitic one under 10GB
ok
👁️ wsl --install archlinux
vro

bruh
Vro
Look into whonix, the entire OS is proxied
Change the upstream proxy from a tor gateway to an invisible burp proxy, then you can inspect all OS traffic 👀
i had absolutely 0 idea this exists lol https://portswigger.net/burp/documentation/desktop/tools/proxy/invisible
doesnt read the docs
gets mind blown by a guy who read the docs
I came here to hack, not read!!
Huge development
Can I get black arch on WSL
first install arch on wsl
then install black arch mirrors and then install a meta package
and its blackarch now
Downloads the netinstall or the live iso by torrent, http or ftp
windows subsystem TempleOS 
@cloud osprey https://github.com/Zeal-Operating-System/ZealOS 🇺🇸
to much work. I just want it to work out of the box
ew
false
it's so easy to install things on kali even I can do it
it's meant for fucking dumbasses like me
ok then
it depends, are you getting shot? Then no, sorry
no there's one more UBUNTU
Reaction for what
damn
reaction time sorry
Yeah reaction time for what
idk
What is the activity
for reacting
Lol
human test benchmark i guess
for boxing i guess it's pretty good
bruh
kick boxing better
unless you are fighting lomachenko, in that case no
who tf is that
Since apparently no one likes google
it's one of the best boxers ever
obviously
Average human reaction time for clicking a button upon visual stimulus is 0.15 to 0.25 seconds
why
please look up two messages
💀
okay :)
looks like ur skull
Yes, I infact have no lower jaw
So one millisecond is 0.001
so its good ?
it is godo
Average reaction time to hit a button on visual queue averages out to 0.15 to 0.25
godo
you could also look it up
why did you change stimulus with queue
oh
ok
a queue ahbahbhba
@exotic pendant when you read the k & r book did you read the appendix? if so did you find it useful or did you leave it at chapter 8?
sooooooooo
Haven't gotten to the gym in forever
55 ms is good ?
Feels good
It's just a number
is it a good number
thats the question
Whether or not you can do something useful with a quick reaction time
its the equivalent to a deer standing in the headlights of an 18-wheeler and getting hit
Is the question
i mean
i do kick boxing
so i guess it helps
still dk what your on about my guy
you're
There's a difference between when you can recognize visual stimulus vs coordinating complex body movements to compensate
I'm messing with you that's what I'm on about
brutal correction 🔥
Just because I got fast eyes don't mean I got fast hands, ya dig?
brutal messing 🗣️
i don't dig infact
I got somethign else that's brutal
but i understand u
That's about as simple as I can put it
Fast eyes don't mean fast feet
But it's step one 
ok
basically you see the punch -> you react -> you are not a good kickboxer so you don't protect in time -> you get punched
u fight ?
u fight ?
Guys how to fix the error permission denied
Kendo
most i ever fought is to get out of bed
Contact your local sytem admin
I had 1 lesson of kickboxing and aikido
But what if i am the lokal syadmin
special
uh-oh
you're fucked bingbong, you're fucked
Why is he fucked
poor bingbong
not deserved
@scenic maple @green kite @nova delta
Ban this user
lmaooo
I haven't done it since COVID unfortunately
Greater men than you have attempted to ban me
not special
Lmao
I do own a sword
special
So I do have that going for me
What kind of sword
get back to your prime
Wym you failed cpts you dont own a sword
what does cpts mean
:)
sir could the 3rd ahh sword
Nice sword. I read books about forging
❌ ❌ ❌
go forge then
Got it from an actual weaponsmith
for how much ?
Was about $300
is it sharp ?
No, I'd have to sharpen it myself
do you have SHARP SORD!
Guys a quick reminder
sharpen it and use it for self-defense
Master... i didn't sharp my sord...
There are tools for sharpening
I don't need a sharp sword to defend myself, it works the same blunt
Sharphound is great
get an ak then
better
👍
then make something happen
brutal
🥀

do more boxes, no need for fast reaction times i swear
Code at the speed you can type English sentences then come talk to me
i don't actually care
i was bored and went on human benchmark and tried the reaction time test and got 55ms
thought it was super cool
Yeah I don't believe you
i got the average
Genuinely over
55ms would put you at superhuman paranormal statistical outlier, you would be more than 5-6 standard deviations
which eh, i don't know man
goddamn
I was about to say, homie
LIKE I SWEAR I GOT IT I JUST CANT SEND THE PIC 😭
Web pages don't load that fuckin fast lmao
lol
Some of them at least lmao
Dm me I'll post
appericiate it 🙏
for example, if you can react to 55ms, you could dodge a bow arrow fired at 5 meters from you
damn
that good ?
Hugo didn't answer, I got some kind of director guy instead 
at least, you would see it coming let's put it that way
Remember, that's how fast you can make a muscle twitch in response to stimuli
how to actualy put an answer in the actual response i found the flag but it says its not good
Now make your whole body move that fast 
yeah 🤣
Don't fuckin post flags dude
Hello?
atleast better then ur 200ms

well time to train your bow dodging arc
do you have a medieval longbow?
and a lot of courage?
you don't need it

maybe cloud is like devil may cry Vergil and can move the sword faster than 55 ms
i did not mean to do that i just want to know what format is acceped by the platform
Copy properly maybe
i did
Contact support then
format of what?
JS can click it in 3ms 
Flag
pffftt...how about MY reaction time?
dev tools is illegal
hold up let me re-take the test real quick
yeah, this is my actual reaction time sorry
i saw green coming in the future
Lmaoo
my bad my bad
😄
suport told me to go to the discord and ask 😂
ask your question here 
flag format should be HTB{random_string}
ohh i found something called fetch/flag_theflag
i tought that was the answer
yeah nah you actually gotta read the flag via fetch or something
and get the HTB{...} value
can time have complex numbers?
it's Pi O'clock dear
both space and time are real numbers so far
and how can i use the flag to get the actual flag like the command?
dayum
i found this smart guy on the internet he explained it
golam be helpful here
that's a bunch of nonsense
cat flag.txt
find / -name "flag.txt" -type f 2>/dev/null -exec cat {} \; | xclip -selection clipboard
try that
i am sure the Hyper-V security team is thinking the same
good ol xclip -se c trick
such difficult commant

it's not
i have 15 min before meeting
honestly it is kinda simple yeah
its is difficult when u compare it to cat flag.txt and copy paste
which is why im in a good mood today
don't give frosto any more ideas
i mean given he hacked Hyper-V I guess he could actually do it
yeah that's what I thought lmaooo 🤣
but not in 15 min
what a legend
i know because i've done it in 5 mins
bro has a godly enumeration
you hack the nasa in the meeting

call meeting initializated ...
the master at work
"sir you have some vulneravilities"
"what ?"
"hacking in the meeting"
"no i dont have"
"you have now"

All the gov VDPs on bugcrowd are great for practice, large attack surface and easy to find bugs
Yep i tell everyone this
like DoD
Bugcrowd's bug bounty and vulnerability disclosure platform connects the global security researcher community with your business. Crowdsourced security testing, a better approach! Run your bug bounty programs with us.
do you atleast get points or thanks?
Thanks and im in multiple VDP reports
thats neat then
Yeah, the USDA program has a pretty massive scope that is hidden in an attached file, so people often overlook it
you get 



I was the reason they uploaded the CSV scope
bro flexing on peasants
found 40 bugs in the wide open and email USDA asking if they can add the scope since it's a LOT of SQLi, RCE and LFIs
dayun
but are they simple or complex

that Is I
go out and lay claim to those bugs
would you like to do coop in a bbh with me some day?
Thats wild
I can save during 6 months just to take a flight and be 3 hours with you @exotic pendant
https://www.cisa.gov/sites/default/files/2023-08/2023-8-21_VDP_Platform_Annual_Report_508c.pdf
check page 8 on this one also
fly with me and golam to chayna

🇨🇳
🇨🇳
CISA also gave me a bunch of swag
put the cat in the keyboard
but don't expect swag. that was just them thanking me for finding so many bugs
@scenic maple
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
first do the modules listen on this page
p3t3r is pretty talented, #6 all-time worldwide on BC
yeah and nice guy
is there any reason yall like bc over h1
i remember frost having issues with h1
H1 screwed me over many times
tirager
when I complete the academy path
and have YET tog et back to me after 3-4 years
I work on both, but mainly BC just because that is where I have put in the most time and have the most rep
giv voucher and ill do it
isnt the toxic exp same everywhere? or is it better in bc
lately frosto just does independnt instead of BC/H1
what voucher?
find bugs in software I use
CBBH voucher
if I get it done or you want the voucher for you?
Just kidding. You asked to coop with BBH and I said if you give the voucher
bc atleast replied back to any issue i had and fixed it
Almost SAME day for any issue i had
I've long toyed with the idea of trying to offer solo pentests, but doing BB/PTaaS for BC/H1 seems to be the sweet spot for now
It's easier to manage honestly
the programed ones
I'm on my own to contact these companies lol
Like this VMWare bug I found
They finally got back to me last week tho
Bro is in the game

My critical Electron bug is just a sitting duck atm
And since he’s famous, he ignores my DMs
who
you Kypanz
Frost 
you're famous
Coffee machine hasn’t been shipped yet
I still need to do my blog
Show off the Steam RCE
here is the voucher

all yours
Steam RCE
NVIDIA LPE
ASUS LPE
etc
Find 1 rXSS to pay for it













