#general

1 messages · Page 282 of 1

tame gust
#

yes milk gifs would get you banned/muted

undone fossil
#

am so tempted to try it but like

#

i only just got unbanned 😭

supple plume
#

Lets see if I get banned

tame gust
#

f around and find out

supple plume
supple plume
tame gust
#

lmaaao

tame gust
#

some guy i think got caught cheating or something and posted he got banned, and asking why

supple plume
#

Please

#

Oh

#

Genius

dense ruin
#

average htb user ... jk :P

tame gust
dense ruin
#

you would be surprised

undone fossil
#

look who it is

dense ruin
#

oh shit...

#

gotta go... getting raided kek

scenic maple
#

🔥

tame gust
scenic maple
#

peak prod code

supple plume
#

Watch the Official HD Video for "Insane In The Brain" by Cypress Hill
Listen to Cypress Hill: https://CypressHill.lnk.to/_listenYD

Subscribe to the official Cypress Hill YouTube channel: https://CypressHill.lnk.to/_subscribeYD

Watch more Cypress Hill videos: https://CypressHill.lnk.to/_listenYC/youtube

Follow Cypress Hill:
Facebook: https://C...

▶ Play video
tame gust
carmine pecan
molten bobcat
tame gust
#

also how does a sleep work

scenic maple
#

it was windows issue

molten bobcat
scenic maple
#

they didnt have sleep so they had to come up with absurd things

molten bobcat
#

It's a pause in execution measured in milliseconds yeah?

scenic maple
#

but this is latest

#

SECONDS is a special bash thing that increaments every second

tame gust
scenic maple
#

issue is during those x amount of seconds it would take up all ur cpu

undone fossil
# scenic maple peak prod code

ok but you could just do this (on windows)

SIZE_T GetTimestamp(void)
{
    const size_t UNIX_TIME_START = 0x019DB1DED53E8000;
    const size_t TICKS_PER_MILLISECOND = 10000;
    LARGE_INTEGER time;
    time.LowPart = *(DWORD*)(0x7FFE0000 + 0x14);
    time.HighPart = *(long*)(0x7FFE0000 + 0x1c);
    return (unsigned long long)((time.QuadPart - UNIX_TIME_START) / TICKS_PER_MILLISECOND);
}

void SleepMs(_In_ SIZE_T Ms)
{
    volatile size_t x = 0;
    size_t end_time = GetTimestamp() + Ms;
    while (GetTimestamp() < end_time) x += 1;
}
scenic maple
#

wow i feel ragebaited

molten bobcat
#

Lmaoo

tame gust
#

like does sleep() just changes the status of the process from running to something else ?

#

or what

molten bobcat
#

No it's still a running process

carmine pecan
#

but it's long

molten bobcat
#

It's just currently doing nothing

supple plume
scenic maple
#

it just sleeps so like bash sleep nothing extra

molten bobcat
#

Different from "backgrounding" a process

scenic maple
carmine pecan
tame gust
scenic maple
#

thats the point of sleep tho right

#

do nothing

undone fossil
tame gust
molten bobcat
undone fossil
#

yeah

molten bobcat
#

How is a sleep() doing nothing for a moment not accurate

undone fossil
#

its not technically doing nothing

#

but from usermode it appears as if it were to be the case

molten bobcat
#

Okay sure

supple plume
#

Im going to nohub myself &>/dev/bed

carmine pecan
#

because it is awaiting an actual hardware interrupt to go back to running

molten bobcat
#

Huh?

undone fossil
#

The windows equivalent would be a wrapper around NtDelayExecution

carmine pecan
molten bobcat
#

Is the hardware interrupt the "change in system time?"

tame gust
molten bobcat
#

Something about a cmos battery being delicious

carmine pecan
#

It quite literally stop existing to the scheduler

#

so it needs a hardware interrupt to wake it up

molten bobcat
#

So what's the hardware interrupt if the sleep is scheduled say, 5 seconds?

carmine pecan
#

the real timer is a hardware one, and it only works in a timescale named: 'jiffies' go figure

terse dirge
tame gust
carmine pecan
molten bobcat
#

Right

#

That's what I said

scenic maple
#

alarm clock

molten bobcat
#

A change in the system time is the trigger

#

Because how else would it measure time

#

When I say system I mean like

#

An on board clock

#

Not the OS time or something

undone fossil
#

you've got me decompiling the windows kernel rn to figure out how windows does it

carmine pecan
#

Yeah now I gotchya, I read system and I think OS

molten bobcat
#

My bad my bad

molten bobcat
undone fossil
carmine pecan
#

its in RAM, it's just not known to exist from the POV of the scheduler

tame gust
#

ooh yeaah makes sense

undone fossil
#

^^ virtual mem and the thread object(s) still exist

carmine pecan
#

Some clever guys abuse this to make OSes be able to have more than one scheduler at a time

#

it's nuts

molten bobcat
carmine pecan
#

a gaming-optimized scheduler for eh, ah games.

#

and another for everything else

molten bobcat
#

I'm currently running a leadless threat hunt

#

Help

carmine pecan
#

Honeypot and pray

molten bobcat
#

Not possible

undone fossil
#

too many unknowns gg

molten bobcat
#

Yeah I know lmaoo

carmine pecan
molten bobcat
#

Nah nah

#

I'm an investigator

#

I can uh

#

Find leads myself

#

Basically client says "hey we get hit every Christmas"

#

So I'm reviewing what has happened in the past

#

To see if I can't form a reasonable suspicion of what might occur next

#

I'm gonna need more coffee that's for damn sure though NotLikeThis

tame gust
#

they wont be hit again

#

life sometimes is that simple

molten bobcat
#

Ah yes, let's simply keep them working

#

Christmas is the reason they're being hit, I was so blind before LOGGERS

tame gust
molten bobcat
#

Yes

tame gust
#

how did the highups deal with that

undone fossil
#

ok so sparing many details - windows removes the thread's system work priority, ends cycle accumulation, and locks the thread

molten bobcat
#

Well they called the cops

tame gust
tame gust
molten bobcat
#

That would be wildly irresponsible of me to reveal

molten bobcat
tame gust
molten bobcat
#

TLDR "Using Machine For Crime"

sturdy thistle
#

That’s a no no

molten bobcat
#

Big no

carmine pecan
#

😮

molten bobcat
#

Super obvious too

tame gust
#

@carmine pecan uses prod servers to mine crypto

pearl spruce
molten bobcat
#

It is he's been preaching making espresso

sturdy thistle
#

What else?

molten bobcat
#

Preaching? Practicing

carmine pecan
pearl spruce
sturdy thistle
molten bobcat
#

And showing off his expensive machine pika

sturdy thistle
#

A barista visits me on Tuesday

tame gust
#

power's gone gg

sturdy thistle
#

Showing me stuff

#

@austere sinew health check

carmine pecan
pearl spruce
undone fossil
#

hello mr mickhat

tame gust
sturdy thistle
#

Hey dude

tame gust
#

i'd like you to keep it off for the next 2 weeks

sturdy thistle
#

Teach me all you know

tame gust
#

i got some books to fnish

sturdy thistle
#

How ru doing @undone fossil

tame gust
#

finish

molten bobcat
#

Oh

undone fossil
#

doing good :) busy week at work but good

molten bobcat
#

I know how to do this th now

undone fossil
#

how's things with yourself?

sturdy thistle
#

Gucci

#

Teach me what ya know kek

molten bobcat
#

It's obvious to me now

#

I have to pretend to hack them

agile thunder
undone fossil
#

im tired but how about i give you a kernel exploit poc instead

molten bobcat
#

Sorry froj I'm a pentester now

undone fossil
#

L

sturdy thistle
#

Works kek

undone fossil
tame gust
undone fossil
#

nah is a driver

tame gust
#

so no 0 day

undone fossil
#

to give a tl;dr. You could write 0x36080000 anywhere in kernel memory, so i overwrote my KTHREAD->PreviousMode to 0 (aka KernelMode), and from there any syscall you make is as the kernel so you can just overwrite your own token

#

as far as exploits go, very simple poc and wont work on latest windows versions due to more mitigations being in place but alas

tame gust
undone fossil
#

no shellcode needed

carmine pecan
#

very simple indeed but it's my first time reading a kernel exploit

tame gust
#

i've never done binary exploitation on windows before except basic bofs

carmine pecan
#

Recently I've been studying runtime linker pwn, as a contrast to heap pwn

#

Ever played with that? @undone fossil

undone fossil
#

Think can you give an example

sturdy thistle
#

One day you’ll be my mentor

#

And one day I drop this

carmine pecan
#

maybe in DMs?

undone fossil
#

sure

tame gust
#

this guy work for oracle

#

btw

undone fossil
#

dam dox wtf

#

shows a few methods and so long as you can figure out a KASLR leak, will work on win11

#

iirc there was some side-channel kaslr leak shown recently but i might be misremembering

tame gust
tame gust
molten bobcat
#

Luigi wins by doing nothing

tame gust
#

why is googling sad monkey, trigger safesearch ?

carmine pecan
#

Go figure

#

I am not interested into diving into the safesearch rabbit hole

tame gust
#

Petals

#

you need to chill out

carmine pecan
#

heathers

carmine pecan
#

I just said I am not interested

tame gust
carmine pecan
tame gust
#

petals no ...

carmine pecan
#

it's true I am trying to read a chinese heap pwn writeup

#

this is worse than gambling

tame gust
#

dont pwn a heap

#

pwn a stack

carmine pecan
#

can't it be both?

#

then we can also pwn file streams

#

and pwn the runtime linker too

tame gust
#

for your next task i want you to find a way to make .TEXT segment writable

tame gust
carmine pecan
carmine pecan
tame gust
#

i didnt know you can do anything with those

carmine pecan
raven rain
#

what does FSOP stand for

carmine pecan
#

File Stream Oriented Programming I guess

heady sage
carmine pecan
#

I don't usually memorize names

tame gust
#

Petals can you like start a blog or something

raven rain
#

great

undone fossil
#

hello prayge

tame gust
#

do both

carmine pecan
#

no

tame gust
#

pretty please

carmine pecan
#

It was usually allowed

tame gust
#

whaaat

#

he just joking he got no OF

eternal mango
#

Is OF PG13?

tame gust
#

if he did i would already be subbed

#

wellllllllll

eternal mango
#

Exactly

carmine pecan
#

back to pwn I guess

tame gust
#

Petals, you see you cant have that, now start a blog

cedar shell
tame gust
#

my macbook is dying

raven rain
#

well i have an onlybrans. the content is high in fiber

tame gust
#

time to install omarchy

austere sinew
#

Hru

feral jackal
#

hheeeelellooo

#

hheeellooopppp

#

heeellppp

#

helelppp memeeee!!!!!!!!

alpine pumice
eternal mango
#

Ok nvm then

#

Sorry @carmine pecan

carmine pecan
#

💪 No worries, I was ready to stop with the OF jokes though

alpine pumice
#

actually i take it back, despite content creators posting whatever content they want, the terms require 18+

dusky jacinth
#

Anyway

#

What’s yalls favorite colors

feral jackal
#

please help

#

am done

dusky jacinth
#

With?

cerulean bloom
feral jackal
#

the bad mods

#

it is a ctf

cerulean bloom
#

no

dusky jacinth
#

Is it an active machine?

#

Cause then we can’t help you

cerulean bloom
#

we are not helping u with an active CTF

dusky jacinth
#

It’s the rules man

feral jackal
#

please am gonna cry

cerulean bloom
#

its the rules

feral jackal
#

we are 14 people and I am the only one found flags and it is my first CTF

cerulean bloom
#

and for good reason, its probably part of the CTF rules too

sturdy thistle
feral jackal
#

am cooked

dusky jacinth
#

You gotta figure it out Brodie

#

Just like we all do

#

It comes with the territory

#

Sometimes you gotta read documentation

#

Like a lot

feral jackal
#

witch one dude

dusky jacinth
#

Whatever is relevant to your CTF

sturdy thistle
#

I only see blocked message sadglas

feral jackal
#

please am gonna cry

dusky jacinth
#

Sorry dude no can do

#

No one will help

feral jackal
#

please am gonna cry

sturdy thistle
cerulean bloom
dusky jacinth
#

I don’t really care tbh

eternal mango
#

Can you just drop the subject anyway, you've been asked multiple times

feral jackal
#

please am crying

eternal mango
#

Stop crying

#

Keep pwning

feral jackal
#

dude fr am crying

dusky jacinth
#

Dude fr stop asking us to help

#

No one cares

#

We’ve all cried plenty figuring it out

#

It’s part of the game

sturdy thistle
#

Cry me a river

#

Is a good song

dusky jacinth
#

It really is

#

One of my favorite standards

feral jackal
#

why the fuck they block sqlmap and ffuf

#

!!!!!!!!!!!!

eternal mango
#

Dude

#

You should be saying this to your team

feral jackal
#

this is not fair at alll

eternal mango
#

Not here

sturdy thistle
#

lol

feral jackal
eternal mango
#

Well

sturdy thistle
#

What a respectful way

terse dirge
eternal mango
#

By not working with them, you're not being a great team member

feral jackal
#

I have never played CTF but at least found some flags
the only flag they found was in discord

supple plume
eternal mango
#

By trying to get outside advice, you are risking the entire team being removed

#

Work with your team.

feral jackal
#

I don't care about the team dude I don't know them

sturdy thistle
#

What cft is this

eternal mango
#

Great

feral jackal
#

it is just a random ppl

eternal mango
#

Just stop speaking about it here

cerulean bloom
sturdy thistle
#

Like you

#

And now move on

tough abyss
#

can anyone recommend good guides on using chisel?

cerulean bloom
#

standardized testing in a few hours

#

wish me luck!

carmine pecan
#

gl

eternal mango
#

Good luck!

sturdy thistle
feral jackal
#

I mean box creator

eternal mango
supple plume
#

SUFFER CREATORRRRE

sturdy thistle
#

I hope

tough abyss
#

🤔

sturdy thistle
#

Let me get popcorn

tough abyss
#

so confused right now

eternal mango
#

Please respect the mods

tough abyss
#

seems like I've arrived at a bad time

sturdy thistle
eternal mango
#

Nah, this is calm

#

Relatively

sturdy thistle
#

Who r u lol

feral jackal
#

but you are a staff

tough abyss
sturdy thistle
tough abyss
sturdy thistle
#

Ye

tough abyss
#

just a nerd

sturdy thistle
#

Hey nerd

eternal mango
#

I wasn't speaking to you @tough abyss 🙂

tough abyss
#

I came here looking for some guides on chisel

#

I'm doing ad lab

sturdy thistle
#

I don’t have

eternal mango
#

I'm terrible at using that reply button

sturdy thistle
#

Check out ippsec maybe

tough abyss
#

🤔

eternal mango
#

Me lol

tough abyss
#

oh

sturdy thistle
#

Hahaha

tough abyss
#

I got chisel on the localhost

terse dirge
tough abyss
#

started a server

#

and then on other machine I connected to it with the client

tough abyss
feral jackal
tough abyss
#

no

sturdy thistle
#

No

tough abyss
#

why me?

tough abyss
#

I once told someone no

#

and i think they literally had a mental breakdown

#

it was honestly so confusing for me

sturdy thistle
#

Unfortunate

tough abyss
#

yeah well

#

I mean

sturdy thistle
#

For him

tough abyss
#

my landlord thinks he can do an inspection whenever he likes simply because I study online

#

somehow

eternal mango
#

😠

tough abyss
#

because I study online I have no responsibilities to attend to

eternal mango
#

Landlords that don't follow the rules or respect privacy

#

They are the worst

tough abyss
#

yeah

feral jackal
tough abyss
#

I've basically got him in checkmate though

sturdy thistle
#

1337 months

tough abyss
#

I caught him out on so many things he fcuked up so

#

now he just leaves me alone

#

I mean

#

how can he compete?

dusky jacinth
#

Lol

sturdy thistle
#

But he still lives or?

supple plume
tough abyss
#

I just feed all the legislation into chat gpt and tell chat gpt to write me an email

tough abyss
#

I mean

eternal mango
#

Ages ago, our landlord had their dad resurface the flat roof and tar. The house caught on fire. They tried to kick us out and take our deposit

tough abyss
#

I don't want him to die

eternal mango
#

They didn't protect it

feral jackal
eternal mango
#

They let a workman on the property without notice

#

They set the house ON FIRE

sick gate
sturdy thistle
#

I need to visit u one day

tough abyss
#

he has a job

eternal mango
#

Yeah, like asphalt and sealing

dusky jacinth
molten bobcat
#

That sounds awful, I'm sorry that happened

tough abyss
#

he's a landlord

sturdy thistle
#

Or a weekend

eternal mango
#

On a flat roof

sick gate
#

That's not a job

dusky jacinth
#

That sounds fucking awful Goblin

tough abyss
#

he also like to send illegal eviction notices in retaliation

molten bobcat
#

Correct, being a landlord is not a job

eternal mango
#

Yeah it wasn't fun, but that was ages ago

rapid badger
#

tbf have you seen the cost of roof repair ? \s

dusky jacinth
#

I’ve been in a house fire, so I get it man

eternal mango
#

She thought she was above the rules

tough abyss
#

I mean

#

he gets paid for it so

sturdy thistle
#

Can someone create some obs overlay?

eternal mango
#

nu-uh, we did nothing wrong

tough abyss
#

surely it's a job

vivid flower
dusky jacinth
molten bobcat
#

He himself has no job

eternal mango
sick gate
#

It's passive income from capital

dusky jacinth
#

^^

eternal mango
#

That's just silly

rapid badger
#

OFC

eternal mango
#

🤣

sick gate
#

It's like if being a shareholder was a job

austere sinew
#

HAHAHAHAHAHA

dusky jacinth
tough abyss
#

nah

#

he's the low ranking guy

#

he basically like

#

goes around

sturdy thistle
#

Like here

dusky jacinth
tough abyss
#

opening peoples doors whenever he wants

molten bobcat
#

Ah so he's a home intruder

sick gate
tough abyss
sturdy thistle
#

Not from you @austere sinew

dusky jacinth
#

In the states you’d get opened on

tough abyss
#

he said

naive nest
#

Let’s enter Facebook employment statuses on our tax forms like “bag chaser”

tough abyss
#

he was going to get a locksmith to unlock my door

dusky jacinth
#

Unbelievable

tough abyss
#

oh and

molten bobcat
#

You'll have to forgive me I am American and if someone opens my door without my consent it's the last action they perform

vivid flower
#

Fr though the whole situation we have rn with blackrock being given infinite money from the Fed to buy up properties and jack up rent is really messed up

tough abyss
#

I must provide copies of my identification for maintenance to occur

vivid flower
#

These days most landlords are hedge funds not people

tough abyss
#

fortunately for me I've kept a record of all of this

#

imagine like

#

I must surrender a copy of my id

#

just to get something fixed

#

so insane

#

hahaha

eternal mango
#

Wait what

tough abyss
#

certainly illeagl

molten bobcat
#

In a property he owns.

feral jackal
tough abyss
#

hahahaha

vivid flower
#

One day people will wake up with a bunch of money worth nothing and no home

tough abyss
#

the guy is an obvious lunatic

molten bobcat
#

Landlords own the property

tough abyss
#

he just makes up his own rules

#

no

#

landlord can be the property manager as well and not an owner

molten bobcat
#

So the property is his responsibility, whatever

#

That's not a job

#

And if it is, he's not performing it. But who's correcting his behavior?

tough abyss
#

yeah like

molten bobcat
#

There's nobody above it

tough abyss
#

no one

#

I sent an email to the chief operations officer

#

I found out who all the important people where on LinkedIn

#

🤣

#

anyone experienced with rack mount ups?

#

I'm trying to figure out if it's safe to mount mine with only the ears at the front

eternal mango
#

I know they're heavy A F

tough abyss
#

yeah

#

mine is way heavy

#

I've got a shelf for the server rack

vivid flower
#

Dang sub zero is that u? havent seen you in ages

tough abyss
#

except it too also can only be mounted from the front

tough abyss
vivid flower
#

Same tyche ive been

sturdy thistle
#

How is dinner

#

I do another coffee later

eternal mango
#

Couldn't say, I know those rails are surprisingly strong, but I also know UPS are chonkers

feral jackal
#

hey

tough abyss
#

do you got oscp now @vivid flower?

eternal mango
#

Never had to mount them in a rack on rails tbh

vivid flower
#

Yep!

tough abyss
eternal mango
#

ahhhh 😐

tough abyss
#

you're elite

#

haha

vivid flower
#

I passed it and now i do workshops at my uni where i teach ppl pentesting and soc stuff

tough abyss
#

there's this guy in my server pretending to be a Somalian pirate

#

🤔

#

wtf

#

hahahaha

eternal mango
#

Takes all types

vivid flower
#

Use ligolo-ng instead

tough abyss
#

after 8 hours on the computer my brain stops concentrating

#

why?

vivid flower
#

Same

tough abyss
#

oh

#

yeah

#

uhhh

#

but I don't want to change now

#

I already started the chisel

sick gate
tough abyss
#

I read that

sick gate
#

Hit the documentation then I guess

#

Set up a small lab and try it out

vivid flower
#

Because when you use chisel you have to use proxychains and the way proxychains encapsulates traffic makes certain impacket tools not work like the client for mssql

sick gate
#

I would honestly personally recommend ligolo

tough abyss
#

so I did

sick gate
#

I always go ligolo first

vivid flower
#

But if you use ligolo-ng it makes a new virtual network adapter that directly connects u to internal subnets

tough abyss
#

chisel server -p 8000 --reverse on my local machine
./chisel client 10.10.10.10:8000 R:socks on the other machine

#

now I can't figure out what to do

vivid flower
#

And it scales better bc you need two terminal windows for every hop u do with chisel

tough abyss
#

hahaha

#

so it's better

vivid flower
#

So double/triple pivots are less hassle

#

Yeah basically what Vege said

tough abyss
#

so like

#

after I master ligolo-ng

#

I can be like john hammond and pivot through networks like a mexican crack addict runs to his local crack dealer, right?

vivid flower
tough abyss
#

y0 @vivid flower, I sent you something

vivid flower
#

You can always just ask if theres something you dont understand

eternal mango
#

Maybe they wanted to swap other peoples brains with your aid

vivid flower
#

Once I am more confident at it I will start recording some of my workshops

#

I'm still getting used to public speaking and dealing with large groups of people, though. So it's a little hard for me

dusky jacinth
#

Like a lecture kinda

eternal mango
dusky jacinth
#

Idk that’s how I got iver my performance anxiety

eternal mango
#

But not put myself out for anything like that for a while.. I almost got towards enjoying it

dusky jacinth
#

Made me feel like I wasn’t talking at an audience but really being grounded in my space and connected with them

#

Idk if that makes sense

eternal mango
#

Finding those eyes that are engaged, and using them as your "safe space" lol

#

But interaction, like hands on?

#

No that sounds off

#

I mean practical?

dusky jacinth
#

Btw I was a semi-professional jazz musician and spoke at lots of events in my youth

#

So that’s my only credibility

eternal mango
#

Or simply being present in the space

dusky jacinth
#

Not like “hands on”

#

Idk it’s hard to explain

eternal mango
#

Yeah 🤣

#

Not being a player on a screen

vivid flower
#

My usual plan is to try to present something difficult and then walk around and try to work with individual people as they struggle

dusky jacinth
#

It’s a feeling of being connected for me like the more I feel involved w the audience the easier it is to be me

dusky jacinth
#

It’s why I hate online meetings and workshops

vivid flower
#

Last time I had two TA's that helped but I know a few people still got lost

dusky jacinth
#

Doesn’t feel real

eternal mango
#

The most public speaking I've had to do recently was to ask the checkout staff to fix the self checkout till

dusky jacinth
#

💀

#

Valid

gray wraith
dusky jacinth
#

@balmy basalt sorry to ping you but that book has already been great I’ve read like a quarter of it td and was OH SHIT SO THAAAATS HOW THAT WORKS

sturdy thistle
#

Which book

balmy basalt
dusky jacinth
#

Yeah it’s really cool

#

Hacking: the art of exploitation

#

@sturdy thistle

vivid flower
sturdy thistle
#

Ag thanks

dusky jacinth
feral jackal
#

hey bear

dusky jacinth
#

But I believe in you brodie

dusky jacinth
vivid flower
#

I'll figure it out, and I think teaching a lot of this stuff to my TA's first helps

eternal mango
#

I have no doubt

rapid badger
#

Teaching can be fun. Forces you to decompose things into their simplest form and some guy much smarter than me said that is true understanding.

dusky jacinth
#

Highest level of learning

winged ridge
#

is python the best programming languge for solving crypto CTF?

#

like which languge has the most useful libraries for cryptography challenges

dusky jacinth
#

Idk

unkempt cradle
#

hello

unkempt cradle
#

where tf should i actually start bug hunting from man i completed port swigger labs and rn i’m on the web penetration tester path from htb

#

how do i start bug hunting

orchid breach
#

On a platform

unkempt cradle
#

man i’m doing it but i just can’t find anything

#

i’m doing vdps

orchid breach
#

That’s the process

unkempt cradle
#

nah man i’m gonna kms now

eternal mango
#

You're going up against platforms that have had thousands of testers work on them for sometimes years

#

It's not impossible to start now in the field and find valid issues

#

But know a lot of low hanging fruit is likely to be gone

unkempt cradle
orchid breach
#

Even if you find one, prob be a dupe

unkempt cradle
unkempt cradle
eternal mango
#

There is still some out there, but generally you're going to want to approach targets in a much broader testing fashion, not just looking for quick wins

#

USE your target

#

Document endpoints and params

#

You gotta work not just on parameters, but deeper behaviour throughout the application logic

#

...but there are still some easy wins lol

#

They are just not as common

unkempt cradle
#

man wtf it’s so fucking hard

eternal mango
#

It really is

#

It's a very complex field

unkempt cradle
#

so basically it’s just over for now

#

bug hunting is dead?

eternal mango
#

Only if you decide it's over

#

No, it's not dead

unkempt cradle
eternal mango
#

Platforms change all the time

unkempt cradle
#

ong i’m gonna find the 0day

#

i promise

#

i’ll not report tho

tough abyss
#

hey y0

#

@vivid flower

eternal mango
unkempt cradle
vivid flower
#

Sup

tough abyss
#

I connected to my localmachine through the liblogo thing

undone fossil
tough abyss
#

can I just run commands from the proxy thing?

unkempt cradle
#

do you guys have any cves?

orchid breach
#

Bro just likes to crash out

undone fossil
#

ye

vivid flower
#

There are some commands for Ligolo Look at the man page

unkempt cradle
#

who has a cve??

undone fossil
#

my "ye" was to your question

orchid breach
#

I thought it was Kanye west

undone fossil
#

but im sure many people in the server do tbh

unkempt cradle
undone fossil
#

lmao

#

uhhhhhh just under 2 months ago maybe

unkempt cradle
#

i’m trying to find my own cve

heady sage
unkempt cradle
undone fossil
#

windows LPE

unkempt cradle
heady sage
#

Oh lord Vader made another one

undone fossil
unkempt cradle
orchid breach
undone fossil
#

duplicate

orchid breach
#

dupes are real

undone fossil
#

like 7.8 or something i forget, if you want i can just fire you the msrc page

unkempt cradle
undone fossil
#

best advice i can give is get familiar with a target you genuinely enjoy playing around with

#

e.g. pdf parsers -> pdf readers

orchid breach
#

Play around with you say

iron comet
undone fossil
#

Nah you can get like super crappy cves

iron comet
#

someone’s 2 star github repo

unkempt cradle
iron comet
#

lmao

undone fossil
#

ive been playing with windows exploitation for like 2 years now, not tryharding 24/7 or anything but

#

definitely should give some solid time investment

unkempt cradle
undone fossil
#

then look up some random php CMS and grep for sql queries Kek

undone fossil
#

dont want it, unless an employer pays for it

unkempt cradle
#

oh

undone fossil
#

then i'd do it

iron comet
#

interests are set straight kek

vivid flower
#

I have a forbes article

undone fossil
#

ayo?

vivid flower
#

No cves tho

undone fossil
#

if you dont mind sharing? 👀

vivid flower
iron comet
#

i’ll assume the burglar is you

vivid flower
#

I was working with a law firm at the time to find instances of gross negligence

#

We did a responsible disclosure and there was a lawsuit afterwards

#

First case ever tried under the CCPA

eternal mango
#

Nicely done

vivid flower
#

I'm trying to get into a pentest firm rn

undone fossil
#

yoo

vivid flower
#

I know it's not a good look to be bragging about something I did five+ years ago

undone fossil
#

nah that's awesome be proud of it prayge

#

oh shit wait i just looked it up and turns out i got a forbes article also? (shared with another cve)

eternal mango
#

haha

visual jolt
#

wsg my dawgs

vivid flower
#

Ayyy

eternal mango
#

Epic

visual jolt
#

A little about me ;3

#

I hate recon.

#

I love red-team.

#

thats about it

eternal mango
#

Welcome 👋

visual jolt
#

thank you!

undone fossil
#

I hate recon.
I love red-team.
based

visual jolt
#

soooo what yall talkin bout

undone fossil
#

just yappin honestly

visual jolt
#

coolio

vivid flower
#

Measuring our e peens

visual jolt
#

my dad is bringing home wendys :3

undone fossil
#

yooooo

visual jolt
#

pray he brings the nuggets and fries 🙏

#

I used to work for like, a little group of hackers

#

and then we started like, a teaching course'\

#

they were complete, misogynistic frauds

#

and liked crypto.

eternal mango
#

Ouch

visual jolt
#

Felt disgusting tbh

eternal mango
#

Unfortunately there are some disgusting people out there :/

visual jolt
#

YOOOO HE BROUGHT THE NUGGETS + FRIES AND SODA

#

WE ARE EATING 🔥🔥🔥🔥🔥🔥

vivid flower
#

Legend

eternal mango
#

Nuggies present?

visual jolt
#

Nuggies ARE present.

eternal mango
#

Nice

molten bobcat
#

I'm making dinner as my partner is picking up my Christmas present psyduck

visual jolt
#

quick start flerting

eternal mango
#

My daughter wants a treehouse

molten bobcat
#

I got a PlayStation portal

eternal mango
#

I haggled down to monkey bars

visual jolt
#

your daughter damn well deserves one

vivid flower
#

I want my gf to get that excited when I bring home wendys

visual jolt
#

unless shes being mean

eternal mango
#

Haha

visual jolt
#

wendys is so good

eternal mango
#

Maybe I'll get a bonsai tree

#

Build a treehouse in it

visual jolt
#

minature 😭

vivid flower
eternal mango
#

She'd find it funny I think

visual jolt
#

oh then ABSOLUTELY do it

eternal mango
#

Zoolander!

vivid flower
#

I think thats about the biggest home millenials can afford these days

eternal mango
#

Damn I've not watched that in ages

visual jolt
#

as a father of none and with a degree in "teenage", i diagnose you with "cool dad disease", cause you sound awesome

eternal mango
#

I try my best

visual jolt
#

You have 3 years left...

#

Only treatment is,

#

having an amazing child

eternal mango
#

3 years left?

#

Ok Mystic Meg

visual jolt
#

the operation cost 18 years of your life

eternal mango
#

😄

visual jolt
#

I forsee your future 🔮

#

I see riches!

eternal mango
#

There is no future but what we make

visual jolt
#

just not in your hands :D

eternal mango
#

You're not off to a good start, I'll be honest 🤣

visual jolt
#

lol

eternal mango
#

Anyway

#

You said you made a course?

#

You still involved at all?

#

I'd assume not by what you said with the people you described

visual jolt
#

nah

#

the course was a complete fraud

eternal mango
#

ahh ok

visual jolt
#

useless "networking" stuff

ocean cedar
#

Hi I'm new here nice to meet everyone

visual jolt
#

greetings!

visual jolt
ocean cedar
#

Thanks that was welcoming

visual jolt
#

Lol, my bad!

eternal mango
visual jolt
ocean cedar
#

Just exploring the server and understanding this ethical hacking stuff

visual jolt
#

thats cool

heady sage
#

You know monkey see monkey do

#

it feels weird being back on my puter

#

instead of my laptop

eternal mango
#

jfc.. a robust set of monkey bars aren't cheap

#

Like, something that'll last her more than a couple of years the way she's growing lol

#

Maybe cheaper to get the tree

#

🤣

visual jolt
#

Lol!

heady sage
#

I feel weird being back on the main setup though

visual jolt
#

Strong wood and some nails can be an alternative, just keep it low to the ground relative to her height

molten bobcat
eternal mango
#

Working off my laptop is weiiiird after moving from the superultrawide

visual jolt
eternal mango
#

She's tall.. and has more growing to do lol

molten bobcat
#

Adult monkey bars makes me think of Ninja Warrior

eternal mango
#

Plus if I can use them (yeah right), nice

molten bobcat
#

CLIMBING SUPAIDA

eternal mango
#

😄

visual jolt
#

Do you know how tall she is?

visual jolt
#

Holy crap

#

That guy is WORKING it

molten bobcat
#

I watched the original Japanese show on G4 :U

visual jolt
#

nice

eternal mango
#

Haven't measured her in a while

#

but she's taller than all of her previous teachers and her grandparents

visual jolt
#

maybe around 5'6"? or 6'?

#

oh

#

def like, 6' then?

eternal mango
#

I'm 6ft4, her mum is 5'9 or something

visual jolt
#

...

eternal mango
#

She's 12, so has some more to go

visual jolt
#

ah

#

ok so id assume shes about 5'8"

eternal mango
#

Bit less I think, she's not quite up to her mums height yet

visual jolt
#

get some wood thats like, 6'4" in length/height

#

these will be the height for where the monkey bars begin

molten bobcat
#

Gob why are you trying to be Ra's al Ghul

visual jolt
#

so youll need about 4

eternal mango
visual jolt
#

then you need 2 planks about 10' long

#

for the rails

#

and like, 10 small, rounded wood bars that fills those gaps

eternal mango
#

Daughter asked for a treehouse for xmas, I haggled her down to monkey bars

visual jolt
#

add a ladder on either ends

#

here lemme open paint rq

eternal mango
#

Nah it's fine

molten bobcat
#

No pls

eternal mango
#

I know what monkey bars look like

visual jolt
#

you got my cogs running

#

now im gonna work and exert myself

eternal mango
#

Thanks though

visual jolt
#

np

eternal mango
#

I don't think I have time to build them before xmas from scratch hahah

visual jolt
#

I like working (esp. red team)

eternal mango
#

Unless I give it to her, and say it's a DIY job

visual jolt
#

takes less than 2 hours it takes to build

molten bobcat
#

Merry Christmas this is your job now

visual jolt
#

i would estimate about 26 nails should do

#

thats like, $5

molten bobcat
#

If that

eternal mango
#

Appreciate the sentiment hahah

molten bobcat
#

Hello sir I would like 4 bolts 7 nails and 3 wood shavings

eternal mango
#

Local lumbar and diy yard closed last year

#

I'm sure there are others near by

molten bobcat
#

I stopped by my local pet store today

eternal mango
#

but I'll just go easy mode

molten bobcat
#

They have a cat that lives in the store

eternal mango
molten bobcat
#

I saw him behind the counter with a bag of treats he stole and broke into lol

eternal mango
#

Operating as intended

#

😄

visual jolt
#

port forwarding SUCKSSS

#

youre telling me I need to remember my router password and username?

warped plank
#

also most ISPs just use an app now

eternal mango
#

What're you forwarding?

visual jolt
warped plank
eternal mango
#

So long as they are 18+ it's fine

visual jolt
eternal mango
#

Oh

#

Uhhhhm

visual jolt
#

Its a VM

#

trust :)

warped plank
sick gate
#

You shouldn't do that

visual jolt
#

Holy crap its another person

#

Anyways

warped plank
#

that is in fact, quite dangerous, even if you're running it on a VM

visual jolt
warped plank
sick gate
#

Vpn or SSH tunnelling

visual jolt
#

Dawg im 14 I dont got a job 😭

eternal mango
#

Something throwaway, and not on your home network

#

Uhm..

#

Well there it is then

sick gate
#

External hosted and not exposing 445 for metasploitable to the public internet

visual jolt
#

The publix nearby is looking very interesting recently

eternal mango
#

You'll need to obtain a parental consent form @visual jolt

eternal mango
#

You obviously read the ToS, right?

eternal mango
#

For HTB

visual jolt
#

wait im confused

#

oh

#

ok where do I get one of them

warped plank
#

it is the weekend

visual jolt
#

cool

molten bobcat
eternal mango
#

What

molten bobcat
#

He said cloud

eternal mango
#

We all host our listeners on you

molten bobcat
#

I was summoned

eternal mango
#

Didn't you know?

molten bobcat
#

Oh

eternal mango
#

😄

molten bobcat
#

Yeah maybe someone should have asked me because I'm going offline now

#

Good luck everyone who hosted things in me psyduck

visual jolt
#

this feels...

#

highly

#

how do I word this

#

"get-a-round"able

molten bobcat
#

It's not

warped plank
molten bobcat
#

Sign the form or face erasure

visual jolt
pearl spruce
#

SAT is shi

visual jolt
#

i meant the form itself

tame gust
#

ok im actually finding stuff in IOT but its really not satisfactory or feels like a win

visual jolt
#

it just ask for an email and so

pearl spruce
visual jolt
#

no SSN or anything

tame gust
#

but this old routers i be having laying around

molten bobcat
#

You don't sign paperwork with your SSN...

visual jolt
#

I meant a form of verification to verify that you are 18+ (Such as an ID, or Drivers License)

eternal mango
#

You should probably stop talking until you have spoken to support

#

Because you're not helping yourself

visual jolt
#

sounds good

tame gust
#

gotta buy some new stuff

warped plank
#

that a POST request?

molten bobcat
#

Would you like an ibuprofen it has to be killer on the back to be digging your own grave like this.

tame gust
visual jolt
#

also, I dont have a printer can I email them a copy of the online document?

tame gust
#

]

#

but doesnt look like your standard ping binary

pearl spruce
molten bobcat
#

What

#

In the christ

warped plank
eternal mango
#

uhhh

warped plank
#

just executing code on yourself

visual jolt
tame gust
#

its not standard, and its restricted shell via telnet

visual jolt
#

TELNET?

molten bobcat
#

Ping most assuredly does not have a "host id" parameter

visual jolt
#

that ANCIENT service?

molten bobcat
#

Unless I'm about to learn something new about ping lol

tame gust
#

so gotta figure something out

carmine pecan
tame gust
warped plank
molten bobcat
#

Ping is just as old and we use it every day

visual jolt
tame gust
warped plank
#

you know you can do that with a serial cable and Putty

lofty warren
#

mornin fellas