#general
1 messages · Page 280 of 1
Bugcrowd
bc?
is my main
ayy noice
I'm already top % on BC
Have you ever tried criminal activity?
h1 needs to get their stuff togthere
From the album Body Wash:
http://stonesthrow.com/mndsgn | https://itun.es/us/YtvYy
Watch the “Cosmic Perspectives Intro” https://www.youtube.com/watch?v=Nj0MNNfXyZM
Video created by Ringgo Ancheta & Alima Jennings
Directed & edited by Eric Coleman
Cinematography by Eric Coleman & Mike Park
Produced by Shane Sakanoi, Ringgo Ancheta & Alima ...
I did
every now and then i see people move away
They outsource all their support
h1?
yeah
I can be
😔
alr get to work
It's Friday
witch one
@austere sinew daily ping
know your limits
not very motivational
Just fuzz until you find something
wolo answers more nicely 🙂
who is wolo
🤮
yea
this is not nice
so you gotta do 2 jobs that dont pay and study for 2 exams while also completeing HTB labs so what u choose
nice
I been coding for the past 12 hours straight
yes I like that
and I've been sleeping
@exotic pendant teach me finally
The jobs are different btw one is tech other is art
My blog will come soon
sleeping is for betas
then call me the betaist
teach in dm man
what is the second job then
😂
you aren't
Who is ab7v?
did you know them or should I art them for you
💀
ovulating
ha
where is echoes bro
i mean i blocked him
chat is not chat without him
and i hope he will not try to push me 🙂
you blocked echoes?
ofc not
hi
@supple plume hello
hello
hhmmm who is that
what did you do
When am I getting blocked mickhat
me?
thats bvecause youre a zatlap
agree
Idk 
Thanks for listening!! :)
long weekend ahead
It was more than just a UI overhaul, and yes there may still be things to do. What the team has achieved will allow them to go back into feature development mode in the new year.
Feel free to /feedback
chat who is good with pwn and rev
Heyyyyy g0bbo
long time no chat
Hey, how're things?
Doing well and yourself
but please provide good feedback and not just "It's Trash"
Not too shabby thanks
A weekend project oneshot I did turned into quite a project
season 9 had to take a backseat unf.
Oh yeah? Cool! Anything you can share?
yeah sec ill shoot you a dm
@austere sinew wakey wakey
Might have to dash as daughter arriving soon
But will check in 🙂
Speak of the devil
😄
😄
You should see her Halloween outfit from this year, it was great
i'm curious now 😄
@lilac cipher
Jesus why does everyone in the bbh community think im a guy
hey miss
Hey Micky
i thought it first too tbh
but actually, it does not matter at all
It really doesn’t
you have good and awesome knowledge
never crossed my mind
👋
red panda
Oh hey! What’s up?
better pretend to be a guy or else your DMs will be flooded
thats close enough to be called a cat
fight back golam
Oh nothing much just going through CWEE
red pandas are cute
good to see normal users here
nice
I’m on my path to catch up to you lmao
Almost there

My kid tried to catch the tooth fairy last night but the phone fell over during recording

Lmao
I'm about to gym
how did you find me?
So that's when he pinged the 4 of us? 💀
Mobile notifications are so handy
Now it's gone
So am I
Hi

admit it now
YOU
like my computer?
ha
Hi everyone! My name is Gh0stIsR00t.
I’m learning cybersecurity and currently focusing on pentesting & web security.
I use THM/HTB for practice and I want to improve my skills and connect with the community.
Happy to be here!
I am happy too
Thank you all of you guys to appreciate me I am currently preparing for junior pentester career
that's amazing
Hi everyone, I need some guidance.
I’m currently learning penetration testing, but I cannot afford a paid tutor or mentorship right now.
Can anyone please suggest high-quality FREE resources, roadmaps, labs, or communities that can help me learn effectively without spending money?
I'm specifically looking for:
• Pentesting learning resources
• Web security learning resources
• Practice labs (free or affordable)
• Any beginner to intermediate roadmap
• Communities where I can ask doubts
Any help or recommendations will be truly appreciated.
Thanks in advance!
hi
You're not active nowadays
Yup have pre boards going on
Damn how's it going?
Studied well?
Kind of on hold for now but it'll start again after the boards
pre boards I mean
I see
That's nice, do your best
At least the NCERT stuff will be solid then
ty
College life would be easy for you most probably
Since you already have alot of knowledge
Doubt it. Not in the first year anyway, I suck at things like physics and chem lol
Do you have any connections in cybersec industry?
Through family
Or any friend?
Nah, join a college with cybersec degree if you can
mmm not much tbh. Just one
Can you apply for internship or job through them?
Wont make much of a difference tbh, the syllabus is very shallow. Studying normal CS will be the same
Might consider it in the future
Fair point
Like I said I know just one person in the cybersec industry and that is a friend of a father's friend
I'll suggest that you take an internship in the first year itself
In cybersec
Yeah, I've been thinking about this and will mostly do that
It'll help alot in the future
You might get placed in that company itself
I did have a few people tell me that internships from first year raise a few red flags with recruiters but I think in security you need all the experience you can get lol
Why would it raise red flags though
You're a teenage prodigy in cyber and you're using those skills to get employed
So?
I guess because they dont believe that one would have enough knowledge/skills to take on internship
Huh 
You have the necessary skills
Need to speak to a person? Learn how to reach our support via HTB Labs.
Your work would be an evidence of that
Yeah I know I might but thats the general sentiment is what I heard
Might be different though
Yup. I most likely will
Anyway the people who told me about the red flags work in different industries lol
So things would probably differ
In my opinion, if you can skip college altogether, you should, IF you're okay with missing the college experience
Alright good enough
then there's also the societal expectation 😂
College is fun, but when exams come along, that's boring as hell
Oh yea that too
oh yeah for sure
If I could've dropped college, I would, but ofcourse family
just hope it isnt as hard as jee
masters is good actually
I don't wanna study more and more
But what will they teach me that HTB or any internship won't
they'll give you a shiny piece of paper 
It's a waste of money
Plus I dislike the exam system

Gand marwaye degree
I genuinely hate giving exams for multiple days at end
Other countries' entrance exams are easy tbh
Dude
They're way better than Indian ones
some people I know are going to hong kong/singapore for bachelors
u must be intelligent
India has this fuck ass JEE system which makes everyone study physics chemistry maths
no they're actually very easy
Plus side is that it produces smarter people than other countries, minus side is that it sucks and is one of the reasons for migration
I've been asking this for two years 😂
The degree is called engineering, and you study the foundation of engineering in the first year.
The smart people that it produces are exceptions
Look at the number of people it fails
I mean that even if people dont achieve what they want they come out of the experience smarter
So, if you call it quits later, you are still able to join a different engineering dept.
unlike America where 26% of the population believe the sun revolves around the earth
How is something I'm never going to use in my work, part of my engineering
I have no use of studying physics chem maths if I'm going in CS
In school I understand
But why for college entrance
You are wrong, MATH is CS.
CS is math yes
Alright fair maths
its not physics or chem
Let maths be there
those things are absolutely useless to me
But physics and chem
tbf everything is math so saying cs is math is kinda weird
math is unavoidable everywhere
I changed it. Math is CS.
I can explain it but you might call me boomer.
ai is stats
Go ahead 👀
@muted olive in first year, fuck college, just don't fail, get decent GPA, then rest of years it's mostly computers, do internships, hopefully you'll get placed early cause of your already existing skills.
interested in hearing opinions
boomer
and linear algebra and multivariable and vector calculus
Also make friends enjoy College
Please do
There’s definitely physics in CS
Physics how
So, the computers, devices that you use hardware and technology derived from physics and chemistry.
yeah. making friends etc, and fests. btw how are the fests in your college?
well yes but you don't involve them on a daily basis
My college is trash, but other colleges have good enjoyable fest. I often go with friends to have fun
You should too atleast once
Look at the width of wireless bands and how some can carry more than others and not penetrate certain materials as great as others
Alright physics is there but only certain amount
Not saying every single thing in physics is useful in CS, this is just one example in networking
@muted olive if going to clubs and concerts is your thing, you can do that too in college
I tried it once, but I personally didn't like that environment
I guess I'll find out whether I like it or not
True, you are studying to become an engineer. Engineer is a broad term, and sitting at the office and having to type some random ass code doesn't require an engineering degree. You are learning engineering to understand how the basic fundamental concepts work, how you can analyse a problem and devise a solution (not any random ass solution, but the best, efficient and effective one).
@meager kernel how much do you pay for college?
I do agree that a good portion of classes can be skipped. I remember my school had me take a class on how to study, which was required 💀
if you guys study hard and work hard you will have as much gold as tejas
Yes, which is zero.
Yea, in your first year, you'll most probably have something called "Freshers party"
You'll pay like 500-700₹ for it, you'll go to a club, and check it out
If you feel the environment is not for you, leave
the point
If you enjoy, stay
My college fees of 4 years is almost 3-4 times more than what HTB Labs + HTB Academy would cost for 4 years COMBINED
they must teach you about hacking satelites then
Also, I've never learnt anything useful in college
NOOOO
THEY HAVEN'T EVEN STARTED TEACHING USEFUL SHIT
they never will tbh
WOOOOO
Exactly, this is something my physics professor said when I argued why I need physics when I came to learn cybersec in the university.
She explained with a similar example, and then it felt conflicted and rebel. Now, I don't.
i am going to college just for a checkmark and nothing else
same
Mostly all my knowledge is from HTB
And I'm genuinely very grateful to this platform
strongest uni enjoyer vs weakest htb player

After my exams end, I'm gonna start my intern job and grind HTB for 6 months straight
Idec if I fail in college
whats the intern job
Internship
ye but abt what
Do yall realize the significance of this?
Jr Pentester
I think so
Meanwhile I get rejected by my top pick of job
I ain't working my ass for free
i dont care what the job is abt if my work life balance is good and pay is good
would rather be a figma designer sipping coffee then working my ass of as pantester tho

That's actually good news
@exotic pendant did you ever go to a university?
No college
None at all?
HUH!
0
he was navy
Considering where we live that’s probably for the best
Dude, all top hackers I know didn't even go to college 😭😭
A lot of us get jobs through experience and networking
Most companies in my country require a college degree
dont let them tell you otherwise
in this world nepotism is key
That's true
I got my internship through connections too
About time
Which country
India 
I’m hoping CWES gets that same treatment
yep, makes sense
There’s so many of you that it’s prob easier to separate by who has college
In India
All I care is HTB is getting the recognition it deserves
Cybersecurity is pretty rare though
Everyone in India is jumping on the AI bandwagon
you're supposed to network in university too
ahem ahem not true, since 2020 several unis have started offering cyber sec programs
not the AI bandwagon
I got a sr sysadmin job by just interviewing and no networking BUT I used that job to network to the parent company
I just studied math and didn't give a shit though
And I already had cves and bugbounty
phd in nmap 
yep
I probably won’t have much when I graduate
And is their course material good?
vader already has like 3 CVEs
Pump those numbers up
Come to the local meet and then I’ll help get bugs
2 are pending

1 CVE at the age of 17
Wow
You can get a decent job rn if you wanted
well technically 18 but I was 17 when I first found it
Well, even if it is good, most professors do not know anything.
Hack college website after admission (with permission ofc)
Report the vuln and ask for extra credit as reward
Besides CVES don’t matter much
They do not have industrial experience nor the hands on. They have experience in the core CS
that is it
hmmmmmm
True
good idea
probably wont be too hard either given how school sites are
Thats what I did too
yeah, I should
My college had an outdated Joomla CMS dashboard
I used an CVE to get admin creds
And got access to admin account and whole dashboard
Reported it next day
I don’t really talk about my uni
I thought you were in a job and not a uni
I’ll prob do college for fun
I thought it was both, no?
Nope. I can’t get a job to save my life
Maybe 2026
idk
It's not like pokemon
Collecting all certs and degrees for fun
My CVE was CVSS 10. Only flexing point lol

for him it is 
Send CVE number
Oh dang got me beat
I’ll have my first 10 soon
Hyperv and rdp escape
CVE-2025-50567
Tbf it was some niche software lol
Eh it’s easier than you might think
still
I’m only hitting big things unless it’s for work

I got a bunch of lab stuff cves
Lab equipment
How so
WHAT
and those WP plugins are easy
There’s a site that takes some wp bugs
Saurus CMS?
yep
I forgot the name of it but they pay for plugin bugs
yea i heard its like easy money
How'd you find it though
Yeah wordpress has their own CNA too
Wordfence @exotic pendant
it was open source, I read the code on github
should i say it
wordfence
😭
Wish I was that good
its wordfence
I’ll probably get some more once I finish CWEE
easy money
oooo, gl, gl
good luck 💪

once you start you'll realize that its easier than how it seems to be
Can always message me for help if you need to verify
JFH
one of the schools that I'm applying to uses wordpress 🤣
Or Just Fucking Hunt
@exotic pendant did you get a chance to poke that driver yet?
I found the register interface so I know its accessible through user mode now
can i add u and verify it
when i get it
get a math degree
Not yet I didn’t find a device by the company
I was going to just do the SANS college
@green kite i wanna know something Sparkling
do you think I should submit the report without POC?
what do you wanna know
Eh I would give it a few weeks
I have a POC but the global symbolic link is wrong
isnt it ticket
Get that working first
for mobile
as mto said when u reach 30 or higher u dont need much sleep to recover. he told like hes 30 so for charging up my energy the sleep doesnt work and dont need much sleep than 2 3 hours
it said email submissions are invalid
Yeah but it’s on its own site and I think just jira tickets over email
during summer I can agree , winter, no, I need sunlight lol
building a proof in mathematics is very much like hacking
I was just going to phd in cyber for fun
ooh damn .okay sir can i know ur age 
@exotic pendant
this was the thing I was referring to
Yeah I’m just saying it’s a hira system
Jira
You submit on their form
oh, its samsung lol
ah okay
And it just has the coms over email
yeah makes sense
man I need a jailbreaked ios device
Theres no platform like h1
Oooooohhh you wanna exploit the Jira instance….. @muted olive
Corellium
hey guys what is the most easiest to find bugs is it like android , web , ios , windows

I applied for a trial but no feedback yet
Only problem with corellium is the ipa needs to be compiled with debug
yeah
So most apps you can’t hit unless they have it compiled as such
Corellium is a sick app
which is why I still need a jailbreaked one 😄
Look at mobile hacking labs
hello anyone @exotic pendant @green kite 
I got 2 exam vouchers 😄
They use Corellium
i struggle just to read c and asm code 
The free course gives you free Corellium
does it? I thought they said to apply for an account
can i learn app hacking from there
for free
platform name please
Hmmm yes the floor here is made of floor
Mobile hacking labs
Web in my opinion
@heady sage i know u hate me but can u reply this
let me check frosto
The mobile hacking labs free course comes with Corelli free
i've seen that one, their certs seem cool
Corellium
CAPT and CIPT
Idc about the certs for it but the course gives you free corellium to use
I’m sure you’ll find your answer with the more experienced people here
they aint replying 
what is corellium if I may ask?
only kratos did
I think Web is the easiest to pentest and find bugs on
Web usually
But it’s depended on you
Not the bugs

Just do it lmao
are you in SRT? @exotic pendant
which resource
there is not just a resource on bug bounty lol
I haven’t tried the HTB bug bounty course (plz gib free voucher HTB so I can promote) but portswigger labs is good
Frost used to tell me the same thing
Learn to code web, write bad code and then fix it
And I hated him for it
tell you wut lol
just do it < this?
But now I realize he was right
@heady sage is this the best thing to do
Yes

Mobile hacking lab
i mean
ahhhhh, I see
Unless you wanna be the person to just spam payloads at stuff not knowing how it works
i mean frostb1te is the resident expert here 
pentesterlab is good for code review btw
oh no
its white box
mb
CODE REVIEW
hey
i replaced my pc case , and after i click the power button
the cpu cooler makes a huge noise and then stops
but it takes a lot to boot the bios, also my windows is not being seen , like it can't boot u[p
any reason why ? and if so , what did I do wrong ?
can it be because I made a mistake when the cpu cooler is active
@muted olive which language sir?
Can start with JavaScript since a lot of client side bugs from black box but you can also do java,php etc
@exotic pendant which web dev language
i think i should do javascript with html and css ig?
@neon zealot not sure what you're exactly hoping for, but there's no golden ticket to earn easy money
Don’t lead him down that path
Once you can read code, it tends to be easier for other langs
yea im not asking for that . i will go the hard way
Are you crazy @muted olive
I am currently reading C everyday 
I used to think this
@exotic pendant what is that server tag you got? Is that server like publicly accesible? lol
Just because Frosto finds bugs easy doesn’t mean it’s ezpz
FBI server
frosto is expert
I know a guy who’s gotten several bugs under his belt and he’s younger than any of us
click its its publicly accessible
I am good in vdp but bad in bb 🤣
got bug on ChatGPT which they still haven't replied to, that might be my first one
even younger than me?!
whoo can i talk to him 
Did you sandbox escape
shheeeeeeeeeeeeeeeesshhh
If not then it’s useless
kinda funny that fbi has a discord server
Not official 
nope its low-medium but interesting. want me to dm it?
Sure
bug b
@exotic pendant im not even able to complete this do u think i can learn bug b
its context
fortress

I don't think you understand what bug bounty is lol
i know man i understand it
I'm a bit confused what should I learn here
just searching for bugs
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
like any normal pentest
@charred harbor
Just start off small
Pick 1 goal
Beat it
Then move to the next
well, its not gonna be exactly like pentest
there will be tons of people trying to find bugs, and its public
but there are restrictions to how far people can find bugs
one goal is to learn portswigger
yes i know that
its in scope
my one goal for now is portswiggy
i mean there are
many vulns
hard to pick one

i know sqli and some
but the
Do them all
portswigger is different
Down the line
you just keep learning
I find pizza as reward helps
pays frosto pizza
why do they have that look

if i get my first bounty , i will treat u with 5 pizza

same

is this
okay frosto

i will pay for it then also

i will pay the xtra
myself
from my pocket
50€ = 5 pizzas no
but its 10 expensive pizzas
is this like

well that would be hard
yep
jk
but he said 5 didnt he

@exotic pendant can i add u and dm u sir?
so its ok
thats true
where is this from lol
Sure itl take me time to approve tho
vercel

the rich get richer
lol
I’m waiting for my $250k bug to be finalized
why sir

@unborn estuary hey
i think
i know u
They at least approved them

and tax
It’s pending the pay atm
i think i know u from somewhere
write the blog asap man
I only got one P1 so far, that was on NASA and it was a duplicate lol
This new method I found is insane also
It also helped me get a crucial electron bug
@exotic pendant sir why will it take time
Even discord is vuln
okay how are u chatting
are u on the treadmill
👀
Unauth 1Password
youre probably the only person on this planet who can do that 1password CTF lol
bros gaslighting me
I got accepted but honestly haven’t poked yet
i know u man
Been busy with other major bugs
I didn't know you have to apply for it
i let you who i am
write the blog man 
It’s just an email to get an account
Soon
ah
i told him so too man
does it involve kernel fuzzing? I think thats how you got the electron one unless I'm misremembering
you said it crashed etc
i know him bro hes gaslighting me

you might know him, but does he know you?!
Why hit the kernel for electron
he does
It’s userland app
oh
well, even if he knows you, doesn't mean he HAS to DM you
valid
i think ill leave the chat for now

who made this then
wait
one moment
give me a sec
that makes it even worse lol
@exotic pendant my microsoft xss got finally got fully fixed
funny thing was that the xss wasn't even in any microsoft managed domain 
ok dont tell me u didnt made this
@unborn estuary
oi oi oi Jungle Bells Day innit, bruv?!
@exotic pendant what all did you study from HTB specifically which helped you in your job?
@scenic maple sir golam the github name and his name isnt it same or am i blind?
bros gaslighting me
just cuz the usernames are the same doesn't mean they are the same person........
💀
funny how everyone is a sir Lol like a knight in the uk 
⬆️
also forgot to reply but that could be multiple plans 
im going for now
IM TAKING A TRAIN
ah, speaking of which
@static pasture
@austere sinew DDDDDDDDAAAAAAAAAAIIIIIIIILLLLLLLYYYYY PPPPPIIIIIIIINNNNNNNNNGGGGGG
Yessir
NO
SAT?
SSAT
what is there ssat also?
yes
SAT is ezpz
I meant HTB Labs VIP+ for an year
Combined with HTB Silver plan for an year
You’ve got this
bro imm gonna kill you it isnot i got 1350
lol
its not easy.
I mean, I got 97% percentile on the exam last year among 8th graders
I'm planning to retake
i hate geometry
bro is going to be a corporate slave soon
those classes marks dont even count , 11,12 bachelors ,
I mean if you have done JEE, SAT is like toddler stuff lol
regardless the last few questions are somewhat challenging
sybau
its for applications, not from school
14
ooh alright good
bros a good student
i feel like
but I HATE VOCABULARY
wut lol
what do you think a job is like
better than ssat imo
its like daily slavery
HAHAHAH
who got muted rn
ay lets not
So around $3000
for all 4
@meager kernel @muted olive heard this?
Hmmm nah should be way less
Nah, I don't listen to Indian songs
490x4 + 18x12x4 is what I did
ooh
I listen to indian songs but havent heard that one
Isn't VIP+ like 200$ rn?
@muted olive hear it then
I forgot
wait hold up
18 monthly when billed annually
25 when billed monthly
Hmmm
No no the silver other one
18$ per month silver
ah well idk
expensive
I have to pay $32,000 for my degree @meager kernel 
$250
Per Month, per user seat
Enterprise is for companies not individuals
its not cheap
It's for an whole company
Access for all modules
like 250 per member
💀💀
i thought you knew
My college fees is like 8000-9000$ for all 4 years @muted olive
Still way more expensive than HTB
will i get access to all modules
you cant, you're not a company
that is just for one year for me 
Which degree you getting bruh?
same, CS
Which college?
The uk is 14k a year….
My college fees are $0 thanks federal student aid
any nit, iiit
must be nice
14k $ ??
Yep
THAT EXPENSIVE?
yea
Oh that's even more 😭😭
Just study HTB for 4 years and get a job
So easy
It helps i already had my associates (same uni) so transferred credits
its fixed at 4000 dollars per semester
wait let me tell my fees , 2,60 lakh / 4" means
two lakh sixty thousand divided by four, which equals 65,000 in nepali rupees and
65k npr is 449.15 United States Dollar
which means my uni fees is almost 450 per year
credits reduce fees?
okay wait nvm you said associates
Yes, because less classes = less semesters
i tried international student visa for the states
i got rejected twice
my coa was 20k

technically I have a choice to pay same fees as everyone else and take what I get, or pay that amount and get anything
I feel sorry for all cybersec students who pay for a college fees
HTB is way more affordable and better
But companies obviously want college degree
only reason tbh
youre cooked if you rely on college to actually teach you stuff
Exactly
Most job listings I've seen want a bachelor's. Im also getting hit up by Binghamton university for a Masters lmao
i joined a uk affilated college man ,8,983.04 United States Dollar
it was hons degree in cybersecurity for bachelors almost 9k usd for 3 years man i left in 6 months i paid around 1500 usd which they didnt return @muted olive

I got an email from MIT (yes the actual MIT) for masters in cybersecurity
Pretty sure it was a scam
why did you leave
you were in UK or it was an online program?
Hell nahhhh
i would pay 20k per sem in the states rather than that trash hons degree @muted olive
i got my associates with honors, so I can probably get more leeway ¯_(ツ)_/¯
man , it was in nepal its managed by the uk
its called affilated
ah
yes
look
Marcie is it worth doing masters in cybersec?
Literally joined the National Honors Society 
I want to do that exact program in MIT but its hard :(
I dislike college system
literally i would earn in the states but not here @muted olive
i can do little bit in campus job there
I haven't taken the master's route. The uni im at only goes up to bachelor's in CyberSec
not here
Cause of the MIT tag or cause how good their course is?
both
Man why would you do that those unis are scams 
Are you sure their material isn't covered by HTB
eh no college material can cover HTB stuff lol
yea i heard after 6 months after the joining
as for business related stuff im unsure
i didnt knew
they might have more content
then i left
¯_(ツ)_/¯
Is it worth the cost?
maybe idk, if I can get a scholarship that would be kewl
If you dont have an ivy degree any other university generally wont matter
MIT fees is 72000 $ (I think it's for one year)
As in, most places arent gonna care about who gave you the degree
yeah... if no scholarship, then probably no MIT
is what im thinkign
🥱
UC is a very viable option and 99% gonna be my choice though




