#general
1 messages · Page 271 of 1
Nice (assuming it's true :D) - how did you get into cyber security?
Have you done the Portswigger Academy yet?
I was stuck with too much of academy and got tips to do more boxes and doing them have expanded my knowledge and toolset more
no
Though I didnt rly do active ones bc i dont care bout the rank
That could be your next step. Try to do as many labs as you can without looking at the solutions.
Im just messing with ya, there are no girls here
Pro tip, do the portswigger labs just with python 💀
Doing active boxes is good for it
I have a lot of fun doing that
Because you dont have official write ups
Shouldmt have 3rd party either due to the TOS, but well..
Learning how to script attacks is indeed a good thing
My favorite thing
My fav thing are busty asians
You can't automatize them yet
Soon
(Flame alert) Are you guys on Burp or Caido team?
I have pending to try caido
is there a market that people buy CJCA vouchers from other people that dont need em?
Didnt even know thats a thing

I dunno, I am just asking
I have both since the company pays for them anyway lol. I use Caido as primary, with Burp configured as upstream proxy for Caido, so all requests go through booth tools and I can seamlessly switch between them depending on the feature or plugin I need.
Only played with it a bit, not really used it yet. Caido also has some nice AI features
I think it can get expensive quickly with active usage because you can burn credits so fast.
Ah
Burp
Ah, earlier I was asking about your locations. Does any of you live in Amsterdam? I might have a chance to speak at the next KubeCon in March so I thought it would be nice to meet some of you in person
Have you tried Caido yet?
I’m based in Texas
A tad too far :p
Oh wow
I have but I didn’t quite like it
I'll move to texas
Oh, really? Why didn't you like it?
The interface felt a bit off
Hopefully in the next 2 years
I found a neat little gadget that might have security impact
Interesting. I think the UX is the best part of Caido, together with the ligthweightness and speed
First create two accounts test1 and test2
Then change the email of test 1 to test 2 and at the same time logout of your session before you change the email and forward your request
If you did it right you changed the email in your unauthenticated state
Not sure how that's relevant to Caido?
Oh I just wanted to post about something cool I found
Ah
4ospel called it a race condition
What's the coolest bug you've found so far? Mine was a race condition in a refund functionality. I could purchase a digital product, and then use the race condition to issue many refunds simultaneously since they have a no-questions-asked refund policy for 7 days. So I would buy a product and get back 20 to 30 times the amount. A cash machine. 😄
Oh bug bounty 
Cna you share more details?
Probably the sales force bugs I’ve found
Nope
Uhhh what do you want to know
Clouds gay?
Fair
In love with me
For example, normally apps enforce uniqueness of the email address, but you said you were able to set the email for account 1 to be the same as account 2? Did I under1stand that correctly?
You're so late to the party I've been cleaning up confetti for fuckin hours bro
It's in his profile last time I checked
This is true
Yes, sorry
Thats crazy
❤️
You’re able to set the email after you’ve already logged out to be email 2
Ich liebe dich
It was not the most complex I found, but the "funniest" one 🙂
Sounds like unauthenticated BAC. Definitley reportable
1.3k in total
Goodness gracious
My dad has a Breville also. They're very good.
Or in us slang a bit over 1 grand, or?
I have yet to find something serious, too noob for that rn. Only two things i found at my Corp were exposed passwords and exposed access to the 3rd most important persons onedrive for business with, lets say, plenty of information
Are you sure the email is actually persisted in account 1? It seems you are saying you end up with the same email for both accounts. And that sounds quite unlikely
I have already finished all my food. Good gravy that was delicious
I have the logs going from changed emails as soon as I change the email after I’m already logged out
That food needs like.. a beer
Wow. I wouldn't want to purchase any service from your company :p
The call to change the email is completely detached from the state of the website
When you then log in with that email address, which account are you logged into?
Me neither but thats bc of their very questionable marketing practices
The changed email but here’s the thing I never registered an account with that email
What you are describing is quite confusing. I thought you changed the email for account 1 to the same email as account 2. That's what seemed unlikely to me. So instead, you were able to change the email address for account 1 but the email address you used was not associated to any existing account?
Correct
Another cool little gadget I found was that I’m able to bypass the email verification by simply using oauth before verifying the account through a normal email
Ok. Are you absolutely sure that the request you sent to change the email address after logging out was actually unautheticated? Meaning, no session cookie or token auth header and such?
That's pretty common
There was a session cookie but it’s supposed to be invalidated after I logged out
Excuse you
Gotcha. Unfortunately that's often considered informational by most companies. Check the accepted vulns on the program details
I figured but it’s still a really cool thing to be able to do
Oh, passwords wwre not the customers
These were internal ones for saases and platforms we work with
Hey if i do cbbh is it comprehensive if i want to be good at bug bounty? I always figured people were doing portswigger labs but i never actually got into it
Even worse 🙂
Portswigger is better for bug bounty imo
Will i be able to actually find stuff
Yup, i reported it and guess if something was done about it
Spoiler: not a thing 
I learned more in the field by asking myself questions than I ever did from cbbh
If you are serious about bug bounty and you are interested mostly in web apps as targets, forget about hunting for a while a build a solid foundation in web application development. It will pay big dividends in the long run. If you already have built real world web apps, then forget about this advice
I ditto this advice
Do they have a BB program? If yes please DM the name 😄
Can I add you btw?
You’re pretty intresting
Add?
Friend request
Nah, they would end up being poor considering their awful developing practices, vibe coding our platform
I don't really do any kind of web development. You're talking to someone who knows python and a little bit of everything enough to have a pentest workflow and pass oscp
Like in the Nahamsec server where I saw you right?

I am serious about wanting to understand it though
Then, I recommend you follow my advice. If you want to be able to find meaningful bugs, you must know the ins and outs of how apps are built. If you don't, you will be guessing most of the time and hitting the head against the wall pretty often
OSCP is great and all, but hunting on real targets is quite different
Do you know whats involved with pentesting a mobile app?
Also :p
I don't do mobile testing much, but it depends on the app
What would you like to know about it? I am more experienced with regular web apps, but I have done some mobile testing too
About to get this tattoo in my sleeve. Filling the gaps. Just counting down the last minutes of a work day that's irritated me
I have never understood the appeal of tattoos to be honest
Whats a good way to learn about web app development?
😂 That's quite a rushed conclusion lol
yes it is
Some are kust cool
Who wouldnt want a hole on his chest like payton talbott

Im always changing so much i have rarely found something i would tattoo on myself
Im careful about the symbols i put out the most i have is a water bottle with techy stickers mostly because i want most people who see me to believe i think like them and leave me alone
If you have a solid foundation in how the web works (as in, what happens between when you enter an address in your browser and when you see the result), then you can pick a language and a framework and start building some real app. Scratch an itch you may have perhaps, but build some apps with a realistic feature set. Authentication, authorization with possibly different roles and permissions, and whatever features make sense for the type of app you are building. Build more than one app, and try using different languages, frameworks, and databases. Get familiar with all the components in the stack, including database servers, proxies, web and application servers, etc etc. There is a lot of stuff to learn before you can effectively hunt for bugs in real targets with lots of eyes on them.
Get timeless classic imagery. Tattoos don't have to mean shit
I guess thats true
I just feel like sometimes I can read a person's mind just by the symbols they cover themselves with
I have more respect for people that dont put meaning in it fr
didn't want to do a fresh Kubuntu install so put KDE on default ubuntu which is essentially same thing
missed Kubuntu is why
KDE > GNOME
change my mind
Some people put their whole lives on their shirts and it aint much
krashes
I still prefer xfce over everything
Maybe i will try parrot kde when 7 launches
It used to be really nice but architect edition kde was barf
If they rice it up all nice again i may bite
Gotta go to bed now. A long day is waiting for me tomorrow. Good night or enjoy the rest of your day depending on what time it is for you.
what do you guys do when you're in a crummy mood to cheer up?
Goodnight
The librarian never called back I guess
haven't given her my number yet. I went yesterday and she was really busy. I went today and it was her day off. Tomorrow.
tomorrow is the day
To cheer up, get little things done
Maybe some small labs or something
Achieving something even small helps
That is achieving something too
Thanks for letting me pick your brain
I eat some good food and take a nap
good food sounds good
maybe after my tattoo
noodles sound good
I gotta pick up MAP gas for my dad's flamethrower xmas present
Why not tho?
Gym
Get some food, watch old ufc fights
Oh yeah or i do bjj stuff with friends
We dig into some youtube video and we have a spreadsheet of all the moves all of us know
Had a bad day? Well, let me leg lock you 30 times in a row 
As long as i can do it back
You do gi or no gi?
Mostly no gi
Nice, casualy or u run comps too?
Nah im not confident enough for that
Fair, nogi is tough considering how some guys go heavy on leg locks
Nothing worse than getting your acl torn in a sport you do 4fun
Facing roided gorillas aint fun either 
My legs arent that long either i cant do that many leg locks
And im kinda short
I have a good kesa gatame and a few other things i can go for but i mostly do it because i have friends who are better at it than me
Could try to add more wrestling to your game
heel hookers R us
Maybe i should
Judo is fun if rolling on the the ground with half-naked men is not a requirement.
Bro i go for the cuddles
Helllloooooo
half naked men are the best part tho
im digi g
.
Hey I dont judge. Just enjoy the standing game and takedowns way more than armbars 😉
Where can i submit/report a bug?
chokes are the best 
hi dude
xup bro
where does the kids game of tag originate from
Chat, I'm so sick of wazuh that I'm switching everything to elastic security instead


? who is he ? what a riddle ? hm?
English is fucking weird
suppoooooooort
the more im forced to brute force the more often i walk away from my computer to grab a snack
im getting fat
😭
Sup nerds
hi glitch
You look pretty familiar
5x 1 year VIP+ giveaway going on in the giveaway channel if you never check it #giveaways message
niceee
They changed how discord links, so you have to re-do it.
It's via linking your htb account to discord on the htb website in settings
I need it
Can you poke htb support because i sent email like before 4 days and no one answer
For what, linking your Discord account? Just unlink/relink it on the site it should connect.
Also I'm not staff so I can't do anything special for you like that
Okay Thanks for help
Hey does anyone know if the order of arguments matter in nmap script?
nmap -Pn --disable-arp-ping -p53 -sU -sC 10.129.2.48 -v --packet-trace
nmap -Pn --disable-arp-ping -sU -sC -p53 10.129.2.80 --packet-trace…the first one is working, the second one fails, and its consistent
There shouldn't be a discrepancy but it's UDP scan so... 
Hiiii
Boots with the fur
Zabbix doing a ping sweep on the network:
yo guys im new here i joined yesterday and i feel like im in a room full of crazy idiots 😂
Youre an idiot
You mean like yourself?
uh not like me im a different kinda idiot
i dont just jump but these bros are wild start from the start
are you referring to the trojan?
Trojan.JS.YouAreAnIdiot
Why of course
not just one but few in account
More like a dozen
yup
i saw yesterday message here
No?
ooh mb
my timezone
has been changed
its showing am instead of pm
i just wokeup so
I mean if you're going to call people idiots then you should probably show off your ego along with name calling
Fuck I love the intro for bedlam by Whitechapel
i wanna john the team guys
Join what team?
Hallo Tejas
ctf
For what CTF?
How are you ceald?
hi bro
anyctf
im just wanna join u know
I'm alive, how about you?
Helloo 👋
Doing fine
That's good
I'm super excited for cactuscon, I still need to get tickets tho
And a hotel
hello how are you tejas
Fine, you?
i have taken the vaccine so ill be fine soon

Wait... No more Hackthebox battlegrounds? I was Afk for about 2 years. I just noticed that today. What happened?
It was completely scripted
It not being procedural killed it
start match
run mayhem.py
win
But machines were random right? Expect for practice games.
yep
the better clanker wins
its like THM's KOTH, you know all machines after playing them many times
therefore, you can root it in basically a few minutes
who? us?
the issue is everybody on this platform spams AI at ctf, boxes, and challenges, so why would it be any different on bg
i have no faith in the future cyber practitioners
I remember i hacking the registration in HTB doing a post Request, just to create an account.
Gone were the days.
It can be said to most fields
oh i agree
its bleak
I havent done an active machine in like 2 years and im still somehow top 1000
still*
I think we should start taking into account the abilitiy to do things with AI as an assistant as a plus point and not a one stop solution to replace us.
I would not bring bg back if i was htb
Atleast you are not cheating bro.
Thats an entire other issue
Learning > Cheating.
The writeup market is always hot for certs.
At any given time I assume 80% of people who have certs on this platform cheated
In fact I have no doubt
UPDATE leaderboard
SET rank = 1,
WHERE username = 'Brathadair'
Please no, make me the last rank
SQL
bro just leaked the schema
its been turned into a box called 2 million
yes thank you
you mean HTB certs? its definitely possible, yeah
100%, if i quiz a handful of you guys, you would crumble
thats why these folks cant get jobs
luckily I aint gonna cheat
And i respect the hell out of that
They we're posting a write up. Even on youtube lol.
do you think the people who passed honestly can get a job?
CPTS, yes
#1: no one I know will help me cheat or know enough to cheat
#2: I have more dignity than that 
hmmm but they would have to be from a specific location/background and know some people no?
CPTS is clearly more difficult than OSCP and teaches the big 4 firm lifecycle well
yup
they ain't this simple 
thats just how it is
i mean the core issue was a chicken and egg problem
no one played it, so we couldnt justify spending time to improve it, and thus no one played it
its an infinite cycle
its sad it was a nice way to ragebait other people
The amount of times one could play a month was awful
there wasnt that many machines to play
SO ITS REALLY SQL? HMMMMM.......
Turned me off from playing any more than I did
ofc I typed the SQL, but not as per the real schema.
you want bg? just go make your own platform. its technically a open market
good luck
VL did it, so go for it
||gets acquired||
Thats sorta the goal when you make something
Tyler Ramsbey did it
I assume xct tried to work you guys and got undercut so he simply undercut you
no?
If i make something big, I don't wanna be acquired
huh
He didnt try to make you guys pro labs?
i know exactly 0 of the history
mood
fuck shareholders
I am talking out my ass too
complete speculation
what drives someone to make their own platform
matter of fact, if I make something big. I want it to be bootstrapped
lol
thats already done!!!!
oh i know
i should make a vscode plugin that puts htb general in my ide
its fucking YC too
what the lmfao
i mean, next thing you know we'll see softbank sponsoring it
its not a question of if
How much does SoftBank have? I see its name pop up more than I expect it.
a number you cant even reasonably say
I just realized, you know those wired earphones you can use on your PC? it seems like I always had the cable not fully plugged in 🤣
too much.
I guess, one per cent of their too much would be enough for me.
Which one do you guys prefer, pro labs vs boxes on the main platform?
I’m a pro lab lover myself! ❤️
thank you 
Someone said people who study coding look like the nerdiest sticks that have no muscles, thats wrong isnt it??
if you exercise, then yes, it is wrong
Do the most people exercise in the IT
you can't calculate that
depends from person to person
Yes
honestly if you dont care for physical health, you are foolish
im a pentester and ive been boxing for 1.5 years along with strength training
its all about time management
Vro just 1 hr in the morning go gym enough
do gym early morning, keeps you active for rest of the day
yea, arch doesnt do that bro
😼

bro comes once in a day
with 2-3 message and gone
morning
I sometimes stick around and chat away
You keep track? I’m blushing
morning
gm
how r u?
Yall ever have tacos with cilantro
do it rn dude, combine it 2gether
Hello, i'm starting to do prolabs, i just want the subcription for one month, if i cancel right now, i keep the access until the next "renew" right ?
for?
weekend hehe
oh
notice how I sent 3 sentences with 3 words kek
no
Chats dead because the usual suspects are busy
ruined morning
lmao
Real (I'm too busy doing a bunch of nothing)
morning 🙂
How do you guys bypass openvpn connection if block by your institute ?
why not ask permission?
Bc he aint authorized 
Never had tacos
Hi , i want to ask what is the next step after networking linux web req courses
i lol'd out loud
thank you for laughing, I can keep my dream up of being a comedian
occams razor goes hard here
actually i guess it would be called reverse occams razor
surely there is a term for this
@rose onyx what should I add to the HTB TUI? I'll have more time to work on it soon
I just added a seasonal box option on the main menu
Wassup sparkling
I'm alive, how about you?
No, just finals
That's good
H E L P
you can pick whatever module you like or based on what your interests are
guy, you need to form a sense of independence, help yourself before you burden others
i say this with love, and if i have to say it again it will be with disgust
man I forgot how good oranges taste
I really liked the winter bananas lol
Agree ,as a newbie you need to do a lot of research kiddo.
not just as a newbie
you'll never be handed everything on a golden platter
there is no route to heaven
you need to do a lot of research whatever your skill level is
if you dont like to learn and research, dont come in IT
@austere sinew daily ppppppiiiiiiiinnnnnnnnggggg
at this point it aint even annoying lol
@austere sinew ping 2

@cerulean bloom @green kite ping
wolooooooooooooooooooo, how are you 🙂
I had a crazy day yesterday so I didn’t sleep the best but today is a new day how are you donut!!
oof
I'm doing good, interviews were okay yesterday
first one probably went quite well, the second one (for the school that "liked" me last year and I want to get into) was going good UNTIL I misunderstood the interviewer's question twice (same question, even after clarification). I was able to answer the question with the correct understanding, but the facial expression of the interview didn't look good 
its very likely it was nothing, since these interviewers know that people misunderstand stuff, especially when they are nervous (people aint perfect)
Hii
hello, may I ask if there is a place to ask questions regarding retired boxes here?
Ohhhh it’ll be fine, at least the first one went well!!
yeah, but I really like the school with the second interview lol, thats probably why I'm worried about it
I'm sure it was nothing, fingers crossed
Bingus bongus chongus amongus
What was the question?
its for high school, so basically, it was what I wanted to do in the future. I was assuming it was about chess (because that was what we were talking about just before the question), but it meant in general 
You’ll be fine
hopefully

I thought you said you got kicked out of that one
Why is Love is Blind the best trash television show ever
Because drama
consider: skibidi toilet

Hi everyone! Does someone work with MobSF? Or else tools for dynamic analysis apk? I need help for work with this! Thanks a lot
I mean... MobSF is a VA, why not just skip it and use Frida?
Im at work...
actually working? or just filling a seat?
Working really hard
Tomorrow is the deadline
Mob looks simpler, iam not good at this
good luck
Im getting a little break to make coffee
Mob is extremely surface level, teach yourself frida.
How youndoin
It’s in another one!!
Hi guys, what job titles do people list for purely internal pentesting / Active Directory testing / cloud infra? Struggling to find job listings for this it seems most are just looking for web testers, maybe my search term is wrong though, it seems most “pentester” listings are like that at least
Security Engineer
Hi
After we analyzed the pcap traffic, the Security Manager has come back and confirmed the user was smuggling data out of the network via the images. He is requesting that we now capture traffic to determine if anything else is going on from the user's host 172.16.10.2. We will need to start a capture, categorize and filter the data, and extract anything significant to the investigation.
Connectivity to Lab
Access to the lab environment to complete this part of the lab will be a bit different. We are using XfreeRDP to provide us desktop access to the lab virtual machine to utilize Wireshark from within the environment.
We will be connecting to the Academy lab like normal utilizing your own VM with a HTB Academy VPN key or the Pwnbox built into the module section. You can start the FreeRDP client on the Pwnbox by typing the following into your shell once the target spawns:
Code: bash
xfreerdp /v:<target IP> /u:htb-student /p:HTB_@cademy_stdnt!
You can find the target IP, Username, and Password needed below:
Click below in the Questions section to spawn the target host and obtain an IP address.
IP ==
Username == htb-student
Password == HTB_@cademy_stdnt!
I don't understand ts
ask a chatbot man..
what did i say that you did not understand?
Well. For instance. Is that I can't do what they tell me
I used the vpn file at my machine
VPN works fine
But then I tried using this xfreerdp and can't use to the target

Isn’t this more implementing security than testing it?
Yo gello guys!
hi guys
I've been having issue getting the number ofservices in a server on all interfaces, I've triedusing the command for all listening services only, it's not giving me the correct answer, I've been on this since last night, please help me
even chat gpt can't solve it
I'm actually looking for the number of listening services
yep, youll do both. Internal pentesting is pretty rare by itself.
What about in consultancies?
Then youll just be providing third party pentests.
I guess red team roles are gonna be mostly full time infra but they’re more senior positions as well
Internal red team is only for huge orgs
Id be happy to do this for purely internal testing but yea seems like most are looking for someone that will do everything and then again, specialisation is more for seniors
Yep, expect to do everything
Its pretty bullshit but thats where the industry is
I find security engineer very vague but I guess you just have to communicate well in interviews
Pentesting is QA and companies HATE paying for QA
It’s definitely an interesting issue
To get into this role requires you to first obviously be senior because actual red team engagements are hard and require a lot of experience, and second to be very good with Active Directory environments
The first happens naturally but the latter seems difficult
Outside of labs that is
Its actually just who you know
red teams are comprised of bros who are skilled
be skilled and make some bros
there is no career path into rto, you just gatta be a chill dude and make friends
That’s a good point yea, getting skilled is the hard part though, maybe security engineer really is the best path for it
You can learn in labs how to find and exploit vulns but that doesn’t prepare you much for the commercial side of it
Being able to understand and communicate about an organisation’s internal infrastructure and how it works etc, this comes from doing a lot of internal testing or internal work
I think Crowd strike red team is mostly AD actually but could be wrong
Most red teams are specialized in windows environments
yes
i aint no billionaire but i still want immortality 
puts you in a metal box and drops you to the bottom of the ocean
yeah, i guess next year GPUs will face the same fate
We are so cooked
and wait till AI datacenters milk the silicon resources so bad
Someone help🥲
EVERYTHING will be way more expensive
They are building a data center a mile from my house, my electric and water bill about to explode
whys it coming on your bill
not only that but it might affect your health as well
in america the tax payer suffers for the greed of our elite
so the company building the data centre wont pay for their water and electricity usage?
Yeah ill probably sell my house, they are arbitrarily raising the property taxes and insurance too. I dont think we hate our governments enough. They really told us that we will eat ze bugs and be happy, and I dont think it was a lie
also, I have labs VIP but it tells me i have ran out of pwnbox time, dont i have unlimited access?
yep, the AI bubble is tragic
VIP had a limited amount of time iirc
i tried to find info about the tiers but it shows in settings like only free/VIP+ is an option, i have regular VIP i think?
https://help.hackthebox.com/en/articles/7257535-htb-labs-subscriptions here only free and VIP+ are listed too
what does it say top right next to your username?
according to your role you have VIP 🙂
only VIP+ does
VIP normal was phased out in october, meaning only already subscribed people are on VIP+
seems like there might be a mistake on the stuff you get from VIP+, it says Unlimited Pwnbox twice
where you going to move to?
some quieter state?
ok, i thought regular VIP was left only for those who paid yearly, i always had the monthly
ill upgrade
its left in the sense their current plan will run its course
but no one new can buy it
🔥
"Unexpected error when changing the subscription - Please contact support." hmm, any known issues when upgrading?
any place that has great nature, mountains and rivers would work for me
please contact support lol
hello emma
hi
how it going
sorry to hear that
I am alright
attempting to fix an issue for a irregular customer
regretting life choices
yea... didnt know it would try to charge instantly, i havent transferred pln to usd yet, mb
..
Wyoming is very nice
Jackson hole
Or Monument CO, nice small town right up on the edge of the mountain range
i love the academy 2.0
idk who I should tell but pls keep it
much more neurodivergent friendly
great job UI/UX team

You brew homes?
yes sir
Brew some beer
For me
And @hoary nebula
@mystic harbor is too young dont give him any
Why am I not able to enter the Giveaway? it just shows I need a role in the server, but how do I get a role? HTB portal doesn't help.
You need to relink your account because they changed how verification works
Check #welcome
Hey, that worked!! Thanks much.
Can someone please give me a push with JET, I'm a bit stuck.
pushes laki towards jet
🍫 s
Num num
@zinc steppe - please no advertisement
You need to push a little harder)))
Kill La Kill seems interesting
wdym laki?
thats the user their name
wtf 🤣

Good find
The only bugs I'm finding is in my own software 
start paying yourself 
I'm going to RCE myself real quick 🔥
Top 1%

Sometimes I dream of saving the world
@austere sinew
@pearl spruce why did u stop typing mate
A real magician
second one joins
cat C:\Users\bss-9tr8h92\Desktop\root.txt
0xcnJo PWNED!
lol
how are u friend?
@sturdy thistle any fun bugs?
I got a new f* keyboard
Test
no 🙁
stop it
Great, wbu?
what if my golam sees that?!
I am waiting for a reponse on a few in the same program
now I am looking through code from an ios app
let me dance
great bud hows everything
who said that VGA cables are bad for the health
nothing will happen
Test
depends, if you wrap them around your neck or try to eat them, not very healthy
but if you leave a VGA cable alone, safe

reminds me of the Wii warnings
TIL 😩
sorry to be the bearer of bad news @rose onyx
finally got one CSRF, fuck vendor
nice
hello guys
tyyy
hi dude, hbu
i am new
me too
im a noob
lies
2nd XSS got approved
nice
"Im a noob"
wait..
his rank
I did not see something like that before
what rank
just a rank
Are you going to make a post about it?
I just did 90% of all HTB
if you don't want it - i take it 
nah you are not GOD enough
maybe you are I don't know
hey
ceiling
bro, I was learning IDOR, I need help pls
ok DM
or maybe him he is a half GOD
No I’m noob
Then what am I
Echo
guys
I did not pay for th e sub my account was empty but I still have access
it has been 5 days and still have access
frosto had a blog?
have u gotten a domain yet
Everyone who will see it be like “why didn’t I see that”
That's broken access authentication, try to exploit the xss on the images
I got domains but not for blogs
dude I mean I paid 8$ but I should pay now again but my account is empty it has been 5 days
and still have student sub
Download the website to extend access
Pro tip
I am asking why do I still have access
Idk
if you completed a module its yours forever
I am not a bad person
no but I still can see modules that I did not even start
Only bad guys download the html 👿
it is like I am still sub
you have access until your plan runs out
am not...🥺
Download inside your brain
it should run out 5 days ago
.
is it a problem that I should report 🥺 ? or maybe HTB want to give me free access
what module do you have access that you dont thkn you should have?
all TIER2
🤷♂️ contact support I guess
have a student account
but why🥺 .. what if I didn't?
am I going to jail?
Can Support reset a pwnbox (I mean change some files that are in the user_data)?
sparkling the apps you write uusally are they all related to ecom?
yes
🔥
do all of them have magento as base?
My customers? Yes
Yeah 🙂 I don’t take on clients on other platforms
Unless they wanna move towards Magento
ur probably the top dudes in the space
No lol. Far from
I’m good at what I do, but I’m not the best
ye but one of the best for sure
I just am lucky to be recognised by Adobe as a SME 
i feel like no matter where you go there is just better people
do they give you adovbe stuff for free?
No, unfortunately not
Say hello to my new neighbour
what a handsome fella
He likes to get attention
attention is rare these days
Is it?
lol
Be back in a bit. Gotta give my kid some attention at the playground
me
sad to see the epic downfall
You cannot ping 1000+ people in the server
Eighteen is anyone solve this machine
jo, u guys know how to get into school wifi? just asking for a friend yk
have you tried asking the teacher for password? or the lab admin?
Go to #boxes
i get a pass for admin in dashboard and now im stack
I was literally going to say the same thing
okay sorry
Sleepy
Sleep
I just woke up
nice challenge
Nah I have to be awake for work
whut time in ur region Cloud? morning?
Yeh it's morning
he dont know it eighter
then tell him to figure it out
its his job to know

all jokes aside if you both dont know and you are doing what you are supposed to
just ask him to reset
but dont do it on your own
u know what im trying to do...
Hi ab7v, my name is Allan. I have terminated your subscription. No further billing attempts will be made. Is there anything further I can assist you with today?
ok that was a bad idea
I hate working extra hours for no extra money
cold world
pet me
😩
please
good boy
reading a book from 1988 and they built gurdrails against attacks
and there are people who write nextjs
Hmm
Hmm
Hmm
That's still an OOB though if you use negative numbers
or if you can get an integer overflow there
So not a good guardrail
what can you expect from the guy who wrote C
Oh is this from K&R ?
yeah
Which one is the dead one and which one is alive one again?
Is K the dead?
or R the dead?
i think so
ah
richite is dead
Yeah R is a complicated initial
If your name starts with an R
you will die earlier than most
Don't know how it works in other alphabets though
alpha bet
By this rule if you don't have a name you won't die
Convert the letters to numbers
Wait until you meet ascii's younger yet more sucessful cousin
Booooo
I don't know the exact name of it but literally for every language there's a table of number to alphabet letter
Neeeeerd
i think i sound like a redditor
Exactly like one
meh i am fine with it
Me when UTF 🤯
Indeed
UTF-32
Working on my Plex server for a bit
Hope that goes well
i want to put base256 on a box just to see how they would react
Some seasons are duplicates of others for some reason so I'm having to sort through and find which seasons are screwed up
I've been planning a box whose privesc will be heap exploitation
just to see how everyone will react
LOL
Good good
feel free to use base256 if you can
You should seek help
We don’t say heap here
Guess the encoding is my least favorite mini game actually
Stack is already pushing it
boooo tcache poisoning after stashing
Tic-tac-toe for privesc
dang thats cool
boooo largebin attacks
up for a game?
woah nice pun
Boooooooo
I'd lose so bad
Thanks I thought it was clever
😛
Real
aight
This is about to be fucking legendary
Uhh wait let me just open CSP 💀
people will try to RCE this
Cyber can I take your place I'll be your champion
I'll mop the floor with this kid
Imma start moving your X
Just to random positions
❎
Oh to be a car snuggled under banana leaves
Your move
FUCK
race condition
At least we picked different colors
FOOL
HE GOT YOU


