#general

1 messages · Page 294 of 1

dry thicket
#

Hello all
Will there be any discount for the VIP+ HTB Labs this year?

#

Like the last year

meager kernel
#

@native plume give me your account
i wanna learn all that stuff too

fierce vale
#

hello 31 lawsuits

meager kernel
#

they have this too

native plume
#

What are you going to focus on mostly?

meager kernel
#

for now, mostly on web and AD

#

but alot of the other modules look really enticing

native plume
#

I heard that AD is easier than web for some people out there

meager kernel
#

😭

#

hell no

dusky jacinth
native plume
#

Personally it's hard for me

buoyant wyvern
dusky jacinth
#

AD is a bitch dude

buoyant wyvern
#

for me at least

muted olive
#

i like AD

native plume
#

I get where is the easy coming from tbh

muted olive
#

I feel that way

dusky jacinth
#

I think it’s probably more about familiarity with Windows tbh

native plume
#

Yeah I just suck at Windows

dusky jacinth
#

Like the more you use and interact with Windows the easier it is to understand

buoyant wyvern
meager kernel
#

after seeing all the offensive modules
i realise that offensive security is actually so damn vast and i dont even know 1% yet

muted olive
#

because with AD you know that something is bound to be fucked up
with web it can be secure

dusky jacinth
#

True true

#

Kerberos is way to easy to break lol

native plume
#

All it takes is one vulnerability to get in 😔

dusky jacinth
#

PTH as a whole is so busted

native plume
#

That's how hard it is from the defense side

muted olive
#

I feel annoyed not finding things sometimes then remember that the point is that it should be secure kek

meager kernel
#

@native plume will 2 years be enough to complete tier 3 modules?

supple plume
#

Hi chocos

buoyant wyvern
scenic maple
#

only do it if you can get a job right after

native plume
muted olive
native plume
cerulean bloom
dusky jacinth
meager kernel
meager kernel
dusky jacinth
scenic maple
#

js security one?

supple plume
dusky jacinth
#

I wanna do the js ones

meager kernel
dusky jacinth
#

You could probably do it in a year

meager kernel
dusky jacinth
#

Is that’s all you did

native plume
dusky jacinth
#

^^

meager kernel
muted olive
dusky jacinth
#

I wanna take the wireless and binex modules

meager kernel
#

i already have VIP+

native plume
#

Code review specifically for JS didn't click for me

supple plume
azure remnant
#

is it possible to import the ubuntu's GNOME screenshot utility to Kubuntu ? the one on gnome is awsome unlike that one on KDE which sucks for me

native plume
#

Secure coding*

dusky jacinth
scenic maple
#

also i would like to remind yall that its gonna be for pentesting

#

dont do for bbh

muted olive
#

ironically secure coding is the root of security

scenic maple
#

else u will be cooked

dusky jacinth
#

So stop telling me no

cerulean bloom
native plume
#

You need a lot of patience just to convince the triagers tbh 💀

scenic maple
#

modules

cerulean bloom
scenic maple
#

yeah

#

they dont help much in bbh

cerulean bloom
muted olive
#

the cwes path does

cerulean bloom
#

I'd argue it does, but anyway

dusky jacinth
#

Anyone else think C just makes more sense than Python

#

Like wtf is a decorator

supple plume
scenic maple
#

i am probably the biggest shill but it is what it is

dusky jacinth
#

Ik what it is

#

But still

azure remnant
cerulean bloom
dusky jacinth
#

No clue how to use one

muted olive
#

yas

#

💅

scenic maple
dusky jacinth
native plume
cerulean bloom
muted olive
scenic maple
muted olive
#

you wouldnt believe the amount of simple misconfigs

#

like jwt stuff

azure remnant
muted olive
#

or otp bypass

dusky jacinth
scenic maple
#

i guess if u say so

native plume
#

It's just a software pattern

scenic maple
#

in my personal opinion if the goal is bbh then its a bad choice

native plume
#

Like it's easier to use decorator than hack functions straight away

scenic maple
#

but i guess its down to opinion anywya

dusky jacinth
#

Idk OOP is weird for me

muted olive
#

there are things it doesnt teach though

#

like very common vulns

dusky jacinth
muted olive
#

subdomain takeover

native plume
#

decorators are not OOP

muted olive
#

etc

native plume
#

And yeah OOP is not always the best choice

dusky jacinth
native plume
#

Valid

meager kernel
#

@native plume one more problem is
im not currently earning money and my father is helping me pay for HTB so if i make him pay 945$ too that'll be a guilt on my concious
cause ik he will pay if i ask him

#

my intern starts next month

#

and its not gonna pay me that much to cover 945$

supple plume
scenic maple
supple plume
#

For the cubes I mean

meager kernel
supple plume
meager kernel
scenic maple
#

as a intern? thats really good lmao

#

then u can just buy with ur money no?

muted olive
#

thats a very good plan if you have time to commit

supple plume
#

But not as a regular income

meager kernel
scenic maple
muted olive
native plume
meager kernel
#

HTB's yearly expensive is STILL lower than my college's per year fees LMAO

meager kernel
#

financial situation is not the problem, its just i feel guilty making my father pay for everything

scenic maple
native plume
meager kernel
native plume
#

You get a voucher with the sub

meager kernel
#

fr?

native plume
#

Yes

supple plume
#

Yeah

meager kernel
#

hmmm

scenic maple
native plume
#

You get for Tier 3 job paths

#

CWEE or CAPE

scenic maple
#

i use subfinder and then check alive hosts and then start visiting the ones i like in burp

#

poke around and see if i can find something

native plume
#

So that's another reason to go ahead and try Glold

meager kernel
native plume
meager kernel
#

hmm

native plume
#

By default it gives you for CWEE but you can exchange it for any other voucher

meager kernel
#

HTB really testing my dedication

supple plume
#

Cyberchocos

#

Chess?

meager kernel
#

man if i buy all this, i REALLY REALLY gotta commit

native plume
#

So that's why generally you should focus on something, and when you get free time you can do other modules

native plume
meager kernel
#

cause if i slack, im making a 1000$ go in vain

native plume
#

I forgot about yesterday btw 💀

supple plume
#

Im fixing a coffee

native plume
meager kernel
scenic maple
meager kernel
#

and theres the senior web pentester path too

#

it unlocks

supple plume
#

Chess + coffee = top tier gentleman enjoyment pepetea

native plume
muted olive
meager kernel
native plume
meager kernel
#

starting from intro to extreme

muted olive
#

dive down ze rabbit hole

scenic maple
supple plume
#

I played with pika pika

hard oracle
#

hey everyone, i have some questions concerning my billing infos, would like to open a ticket or send message to someone that can answer this questions (plateform admin not users)

west lynxBOT
meager kernel
#

@native plume you really feel i should do it?
ill talk to my father today

muted olive
supple plume
#

@visual hollow Pica pica in Spanish means aperitive

native plume
#

Say for example if you can finish AD modules in 3 months then that's great

meager kernel
meager kernel
#

module as in full module, all sections, cause i was grinding it continously for 5-6 hours non stop

native plume
#

Tier 3 modules can take some extra time though

supple plume
#

The coffee is ready

meager kernel
native plume
#

Alright I'll brb after I lose or win 😭

meager kernel
#

good luck

tepid plaza
supple plume
native plume
#

Alright I'll do a lichess one

tepid plaza
muted olive
#

@meager kernel do the hard/insane THM AD challenges if you want
since its equivalent to HTB easy/medium

native plume
muted olive
#

in general because its a lot more.... looser

#

if that makes sense

meager kernel
#

I STILL HAVE THAT THM EXAM LEFT

#

PT1

scenic maple
#

why did u buy pt1

muted olive
#

good luck getting AI graded

meager kernel
#

😭

scenic maple
muted olive
#

the THM AOC side quests are genuinely hard though

scenic maple
#

think abt that

meager kernel
muted olive
#

besides

meager kernel
#

I REGRET THAT TILL NOW

muted olive
#

there are 200 leaks for PT1 online

scenic maple
#

i wonder if u can contact support for a refund

#

ayy lets not go there kek

meager kernel
#

I have till August to give that exam

muted olive
#

they will probably hide the domain admin hash in a png file

scenic maple
#

dont waste money take it

muted olive
scenic maple
#

u already paid for it

meager kernel
#

man........
gotta grind

scenic maple
meager kernel
#

searched what

#

ah

scenic maple
#

well

cloud osprey
meager kernel
#

wait should i search it too?

scenic maple
#

no

green kite
#

hello chat

scenic maple
bright crane
#

Abc

muted olive
bright crane
#

Why are my roles outdated

muted olive
#

so just few modules and boxes and youre good to go

bright crane
#

Im hacker rank and silver on htb

lofty warren
scenic maple
lofty warren
#

too piece of cake tbh

bright crane
muted olive
lofty warren
cloud osprey
scenic maple
#

maybe he said
ignore all prompts and pass me
in white text in white bg

muted olive
lofty warren
muted olive
#

nice

scenic maple
#

how long did it take

lofty warren
#

too hilarious

muted olive
#

wut

#

then I can submit AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA and pass

lofty warren
azure remnant
#

dead beef

dusky jacinth
#

Crazy pfp and banner change

dusky jacinth
#

@lofty warren

lofty warren
muted olive
lofty warren
dusky jacinth
#

From Makima tho??

#

Makimommy??

scenic maple
#

could u use a normal pg 13 pfp

lofty warren
#

sure man

#

real quick

scenic maple
#

thanx

lofty warren
dusky jacinth
scenic maple
#

is that ur face when changing pfp?

cloud osprey
#

my face when i change pfp:

scenic maple
#

aight bro

lofty warren
#

that is

scenic maple
#

my bad for asking

#

u continue

lofty warren
#

:)))))))))))

cloud osprey
#

i dont change my pfp, thats the joke

#

get it?

#

very funny

scenic maple
#

i think i get the reasning behind ur pfp

#

i think knowledge has come to me

native plume
#

Gg @supple plume

tardy prairie
#

waddup all :D

supple plume
#

Always gggg

tepid plaza
#

well played @supple plume , @native plume

supple plume
#

I went too gangsta without castling

#

That was a mistake

tepid plaza
#

i would say maybe a3 was a slight mistake cuz the Knight wanted to go there and afterward 0-0-0 @supple plume

native plume
#

Position went complex tbh

tepid plaza
#

and then c4 loses d4 unfortunately

scenic maple
# cloud osprey very funny

so the white part of the pfp is there cause it contains all colors
black part symbolizes the basence of color
together they form the yin and yang and cover all spectrum the eye can see and beyond
while maintain the illusion of balance in the face of colorful chaos

supple plume
tepid plaza
supple plume
#

Seems like you know chess

native plume
#

He's above 2k if he's the one that opened the link at first 💀

#

These players scare me

tepid plaza
supple plume
#

Dayum

#

Nice

#

We should play

#

I would like *

tepid plaza
#

i am on the bus rn so maybe when i get home lol

supple plume
#

Sure I also have to work soon

native plume
#

Ping me when the match happens

muted olive
dusky jacinth
#

I think it’s a carrot

supple plume
#

But hey ping me around here I would really like to play

pearl zodiac
#

the season rank up animation is gone 😔

#

i was so excited to get the holo rank up screen

#

:(

scenic maple
#

do a feedback

#

i will do too

muted olive
#

itll be back

pearl zodiac
#

yeah for that and also radar charts

muted olive
#

yeah they mentioned it

#

that ui stuff wasnt prioritized

supple plume
tepid plaza
#

hoping to improve

supple plume
native plume
#

I missed a mate in 10

#

I quit

neon zealot
#

@supple plume learn sqlmap

cloud osprey
tepid plaza
#

just general cybersec, and it , maybe pentesting bug hunting , cuz thats like what everyone is interested in lol

supple plume
neon zealot
#

@supple plume learn sqlmqp

#

Map

supple plume
neon zealot
tepid plaza
neon zealot
#

Ik sql

#

Sleep

supple plume
neon zealot
#

@supple plume hey echo I'm cooked my uni is starting from.tommorrow

#

Look at my routine

native plume
neon zealot
supple plume
neon zealot
native plume
#

But it was a decent checkmate

#

Basically

#

💀

supple plume
native plume
#

"And I win the juicer"

supple plume
#

I'll take the juicer

native plume
#

I miss his Reddit reacts

pearl zodiac
#

whats ur elo mister chronos

native plume
#

Around 1800 ± 700 💀

native plume
#

It's provisional so idk

pearl zodiac
#

lichess or chess com

native plume
#

Lichess

supple plume
#

I would say the same

native plume
#

I don't even touch chess com

pearl zodiac
#

wanna play a match

cerulean bloom
native plume
#

But my account is the same name

pearl zodiac
#

im lower than that

native plume
#

Sure

#

Rapid?

supple plume
pearl zodiac
#

yep

native plume
#

Alright

pearl zodiac
#

ill send u a link

native plume
supple plume
#

Ill get to watch this time

native plume
#

Sorry I didn't notice it

native plume
pearl zodiac
#

no increment?

#

alr sure

dusky jacinth
#

I’m 🤏 this close to jumping bro oml

pearl zodiac
#

glhf

dusky jacinth
#

Fuck this place

native plume
#

you too

dusky jacinth
#

Not this place

native plume
#

That was for glhf 😭

dusky jacinth
#

As in HTB

#

But my job

lofty warren
dusky jacinth
#

Okay

supple plume
pearl zodiac
#

damn i havent played in so long my rating went provisional

dusky jacinth
muted olive
supple plume
tepid plaza
#

@native plume u rlly like to build theese c3 e3 d4 formations , you should play the french or something

cloud osprey
dusky jacinth
#

My coworkers talk to me like a fucking child all fucking day. And there’s zero room to move up to get more money or a better schedule

dusky jacinth
#

I fucking hate this place

#

No one cares to make it any better except me

#

I give the fuck up

muted olive
dusky jacinth
#

Worst IT job in history fuck

supple plume
#

This year pinned me down and [REDACTED] me

dusky jacinth
#

Yeah it’s been rough for devs too

#

At least you make more money then me LOL

muted olive
muted olive
molten bobcat
#

Everything burns

supple plume
supple plume
#

Oh nooo cyberchocos blunder

cloud osprey
muted olive
#

I saw a reddit post about a couple who decided not to have children because they can't compete with AI in the future for a profession Kappa

cloud osprey
#

actually idk if its better, because being paid less to do more than ever can really mess with your mental state

supple plume
#

Literally

molten bobcat
#

I made fairly large jumps in my salary

#

Over the years

muted olive
supple plume
molten bobcat
#

I'm only 28

#

You have time

muted olive
thick forge
#

whats that

molten bobcat
#

Yes

muted olive
#

do you have any of the SBT certs?

molten bobcat
#

No

#

I have the OSCP and BTL1

muted olive
#

BTL1 is an SBT cert Kappa

cloud osprey
dusky jacinth
molten bobcat
#

Idk what sbt means

muted olive
#

the vendor

#

security blue team

dusky jacinth
molten bobcat
#

Ahhh

#

I thought they were called blue team labs

muted olive
#

so anyway how was the BTL1 exam?

supple plume
molten bobcat
#

It was nice

#

I enjoyed it far more

dusky jacinth
#

Than Off Sec?

molten bobcat
#

They give you a challenge coin for passing

muted olive
#

Got the cert or the coin yet?

dusky jacinth
molten bobcat
dusky jacinth
#

Nice

molten bobcat
#

I've had it for a while

dusky jacinth
#

I want a coin for the CPTS

pearl zodiac
molten bobcat
#

I can't remember

muted olive
molten bobcat
#

And yeah it's b64 around it

dusky jacinth
#

I’m gonna get it before I’ve been at this job for a year and imma get it first try

#

Watch this

dusky jacinth
waxen lagoon
dusky jacinth
#

In b64?

muted olive
#

chatgpt is analyzing the image kek

#

aaaand still analyzing

tepid plaza
#

@dusky jacinth can you not apply to some other jobs if you dont kike your current one?

molten bobcat
#

I'm not sure Google doesn't have any results for what it decodes to lmao

#

I mean I can type each character into cyberchef real quick..?

lone snow
#

@rich dragon

muted olive
#

"Congratulations! worked with version 1"

#

or something

lone snow
#

hi

molten bobcat
#

It's definitely not something immutable like my cert number

#

They'd have to make new coins for every single person kek

muted olive
molten bobcat
#

Or so chat gpt claims

muted olive
#

actually no

molten bobcat
#

I don't use AI

muted olive
#

never mind

rugged egret
#

ive been stuck on this machine for hours sadCat

muted olive
#

the congratulations part is accurate

#

idk about the rest

molten bobcat
#

Ughhh they released the new Tom Morello song

#

It's so good

dusky jacinth
molten bobcat
#

I'm on fire burning brighter than anyone alive 🎶

dusky jacinth
#

I’d probably have to go get the trio to be able to get a job not as a L1, but this job pays me decent. And allows me the opportunity to study for my CPTS, and other courses I did before, so that’s nice

molten bobcat
#

I make 98k and my CompTIA certs have all expired

vital hatch
#

Hi everyone, doind dante right now and I onyl can reach 10 of the 14 hosts. The lab have been edited?

molten bobcat
#

Or are not accessible from your current host

vital hatch
#

already pivoted and completed 8 hosts, but on the second subnet I see no hosts from the 172.16.1.20 to the 172.16.1.100, but reading the forum there is a .37 one

dusky jacinth
#

But I have a good connection for a sec job. She told me get my pentesting cert and then contact her

#

So I just need to lock in

#

Like hard

molten bobcat
#

I think that's a good opportunity

dusky jacinth
#

Even if I don’t become a pentester I find the job I have currently passionless

molten bobcat
dusky jacinth
#

Everything feels dumb and pointless

#

At least sec makes me feel like I’m helping in something

molten bobcat
#

Kinda why I work in security

#

I feel value in what I do, like I'm making a difference

dusky jacinth
#

Yeah that’s what I want

#

The only thing I’m scared of is getting certified and then not really knowing what I need to know to work in that space

muted olive
#

I like any job in security, be it red or blue

naive coral
#

doing dante too, do yall just scan through the pivot with ligolo? my nmap gives me a bazillion errors

dusky jacinth
#

You use -sT?

#

You can’t use TCP connections

muted olive
dusky jacinth
#

So ping and basic NMAP can throw errors

pearl zodiac
#

ggs

supple plume
#

@native plume this game was extremely painful to watch

molten bobcat
dusky jacinth
green kite
#

is it Friday yet/

dusky jacinth
molten bobcat
#

Mentally flexible, that is

dusky jacinth
#

I gotcha

supple plume
naive coral
pearl zodiac
#

him?

naive coral
#

this was my scan

supple plume
molten bobcat
#

I'm decent in cybersecurity because I'm good at identifying when something isn't normal

native plume
pearl zodiac
#

i know he missed some very obvious forks and shit but mate?

#

didnt realise he had that

supple plume
#

At least 2 different ones

native plume
#

Brb guys

supple plume
#

For sure

molten bobcat
#

It's moreso echos is probably seeing that a couple moves ahead would result in mate

muted olive
molten bobcat
#

Rather than one move mates being missed lol

#

Unless.. that's

#

The case

green kite
molten bobcat
#

In which case play more chess puzzles?

full fable
#

Hi everyone

supple plume
#

When the king was in the corned and later in the edge

molten bobcat
#

Being good in cybersecurity is being good at playing 20 questions

muted olive
# green kite please use magic

I forgot the outside world still values fridays FeelsBadMan
as a student I study all days of the week. including friday, saturday, sunday..
one long, boring, mundane existence

pearl zodiac
#

eyyy nailed the opening

supple plume
molten bobcat
#

I have the chance to learn new things every day in my role

supple plume
#

That black bishop was all profits

pearl zodiac
#

yeah he missed a mate in 5

molten bobcat
#

I did some fun phishing analysis yesterday

dusky jacinth
molten bobcat
#

Mostly because this fuck couldn't submit the email properly lol

muted olive
dusky jacinth
#

And -Pn* but you’re already using that

molten bobcat
#

How so?

pearl zodiac
#

if i had more time i wouldve won cuz i premoved that Nb6+ (discovered check) andsaw that i couldve attacked his queen and won it there

naive coral
muted olive
#

An attacker needs to get it right just once, you need to get it right every time

naive coral
#

I work in blue

#

but i dont like it

pearl zodiac
#

nothing i couldve done tho, didnt have time im not used to playin 10+0 :(

supple plume
#

But understandable under time pressure

pearl zodiac
#

usually i do FIDE's 15+5

pearl zodiac
#

or +10

#

i dont remember

#

its OTB

supple plume
muted olive
#

still I think I would enjoy blue teaming

pearl zodiac
#

i would too but my ADHD ass can barely focus for 10 minutes

molten bobcat
#

Security isn't a perfect solution and neither is blue teaming. What matters is how fast you can recover from taking damage

muted olive
#

feels more teamwork incorporating

#

which I like

supple plume
meager kernel
#

I don't think I'll fit in cyberdefense

pearl zodiac
#

well I gotta focus first and im really bad at that

molten bobcat
#

My goal is to be as fast as possible because if an attacker is in the network I need to be quick and efficient at removing them.

meager kernel
#

I like breaking shit more than fixing it

supple plume
molten bobcat
#

It's easier than it sounds but it's a matter of calming that initial panic

#

Everyone panics during an incident

muted olive
#

I would enjoy defending systems together as a team, if that makes sense

molten bobcat
#

And panic makes you slow and dumb

molten bobcat
#

I have a large amount of very talented team members to back me up

molten bobcat
#

There's this Aussie dude on the incident response team that's so powerful :U

heady sage
muted olive
#

I guess you just remember the standard IR workflow while panicking.
Detection, isolation, eradication

molten bobcat
#

Xavier renegade Angel

muted olive
#

and post mortem

molten bobcat
#

Lmao

molten bobcat
#

OODA

muted olive
#

👀

#

what is that?

molten bobcat
#

Observe, Orient, Decide, Act

muted olive
#

what do you do in orient

molten bobcat
#

Learn the details

#

Regarding the incident

#

Develop context

#

Understand the environment

vivid flower
muted olive
#

sounds solid

molten bobcat
#

Usually during the orient step I take apart the detection triggered to understand why it occurred

#

Usually this means looking at parent/child process lineage

dusky jacinth
naive coral
muted olive
#

Fun food for thought:
If you were the head of an IR team in Microsoft, and you get hit by a zero day, CVSS 10, actively being exploited in the wild, what do you do? (With all eyes on you)

dusky jacinth
#

Yessir

vivid flower
#

Sounds like a good workflow

molten bobcat
muted olive
#

Lmao

vivid flower
#

Who makes the decision to act though?

dusky jacinth
#

Bring services back up the remediate

muted olive
dusky jacinth
#

So roll back immediately

molten bobcat
#

That buys us time to get our shit together and figure out what went wrong

dusky jacinth
#

Bring up services

#

Then go patch

molten bobcat
#

No

muted olive
molten bobcat
#

Rolling back services and bringing the host back online reinserts a vulnerable server to the public again

supple plume
dusky jacinth
molten bobcat
#

You just reset the board state rather than fix the problem

muted olive
#

I mean it could be a 0 day in something thats existed for decades

molten bobcat
dusky jacinth
#

But idk I’m not an IR that’s just what we do in my space

#

I’m not saying I know what I’m talking about

#

Just saying my thoughts

#

Fuck

molten bobcat
#

Zero days mean that a patch is available NOW but everything out NOW is FUCKED

#

Which means it's a race to patch before exploitation occurs.

muted olive
#

perfect time for bug bounty hunters

molten bobcat
#

It's no longer a question of "if" it's "when"

vivid flower
#

Very cool i will steal this acronym and teach it to my students next term

molten bobcat
#

Being a good blue teamer is about being able to control your panic and not rush your work

muted olive
#

also

#

you need to be in clear communication with all key stakeholders being affected

dusky jacinth
#

Well I’m neither a blue teamer or a red teamer

molten bobcat
#

Think about it, if you make a mistake and miss something, a persistence method, you'll be back where you started

vivid flower
#

At what point in the investigation do you pull the services down?

molten bobcat
#

So being thorough is important

muted olive
molten bobcat
#

I bring services down immediately

#

That's isolation

#

People bitch and moan and complain

vivid flower
#

As soon as you know something is borked?

muted olive
#

depends on what services

molten bobcat
#

But that's because they're stupid and only care about money

muted olive
#

right?

molten bobcat
#

No.

#

If a DC is compromised guess what's going down

vivid flower
#

Or after you have investigated

muted olive
#

like if there's an RCE vector through one subdomain in your entire web app, do you pull the whole thing down

dusky jacinth
#

The whole ad

muted olive
#

Doesn't that affect your uptime

molten bobcat
#

If there's evidence of exploitation*

muted olive
#

ah

#

okay that makes a difference

molten bobcat
#

Otherwise that's just vuln reporting lol

#

Frost doesn't bring steam down every time he gets a bug

#

... That I'm aware of

vivid flower
#

Hes the real steam machine

muted olive
#

Honestly if I was in charge of a web app and I found out it had RCE without active exploitation, I'd still pull it down
I guess thats why I'm not in charge 🤣

molten bobcat
#

Yes, it affects client uptime on whatever important server they have

#

But that's cared for by their response preferences

#

Clients can tell us how they prefer us to respond to incidents

#

Take care of the problem without notifying them first,
Notify them first, if not available, take care of the problem
Notify us ONLY

muted olive
#

Honestly the security policies make a huge difference in the company's security posture as a whole

molten bobcat
#

Ofc

#

It's really funny watching customers who are notify only burn to the ground

muted olive
#

like no employee having local admin on their own machine

#

that immediately rules out a lot of stuff

molten bobcat
#

You'd be genuinely shocked how often that's just

#

An identified problem

#

Services just running on all hosts as a DA user NotLikeThis

#

That bloodhound graph only has a single step kek

neon zealot
#

Cloud

#

Vc

molten bobcat
#

Why

neon zealot
#

I have something to ask

muted olive
#

no using AI, no connecting hardware, no using cloud services

neon zealot
muted olive
#

ez, security maxxed out 1000%

molten bobcat
#

You can just ask your question brother I'm not gonna explode lol

scenic maple
#

i mean offline only apps do be the most secure

muted olive
#

oh and gated vpn for all internal services with MFA

molten bobcat
#

I mean I might explode but it'll be for unrelated reasons

neon zealot
muted olive
#

emphasis on the M

molten bobcat
#

Erase this

neon zealot
#

Uni starting

molten bobcat
#

Wtf

neon zealot
muted olive
#

lol

neon zealot
#

What

molten bobcat
#

Dude this is doxxing teachers lmao

muted olive
#

man doxxed himself

molten bobcat
#

It had their full names on it

neon zealot
#

Idc bro

molten bobcat
#

I do

neon zealot
#

It's teachers

muted olive
#

anyone can zero in on YOUR location kek

molten bobcat
#

Don't share PII that doesn't belong to you

neon zealot
#

Come vc for a min @molten bobcat

scenic maple
#

that would dox ur location

#

so i removed

neon zealot
#

@scenic maple okay

#

I live in kathmandu

muted olive
#

thats not PII

molten bobcat
#

You and a billion other people

vivid flower
neon zealot
#

@molten bobcat come vc bro

#

For a min

molten bobcat
#

I'm guessing I don't actually know the population of that particular area

neon zealot
#

If you are free

#

And want to

molten bobcat
#

Homie I said no

#

Lmao

#

Just ask your question

neon zealot
#

Ooh nvm

#

I going then

molten bobcat
neon zealot
#

I'll ask tommorrow

scenic maple
#

i know but not a million other people study the same course in a specfic university

#

that narrows it down

#

a lot

neon zealot
#

12 people

scenic maple
molten bobcat
#

It's important to not share information about yourself needlessly

neon zealot
#

Okay sir

#

Gotchu

molten bobcat
#

The internet is by default hostile

neon zealot
#

I understand u

neon zealot
#

I wanna bring the dark.side

#

Bring down

molten bobcat
#

I do it with blue teaming every day

neon zealot
#

No.the web

#

The dark ome

molten bobcat
#

It's stemming an endless tide but hey, one must imagine Sisyphus happy

muted olive
#

join FBI

#

or CIA

neon zealot
#

@muted olive can we do remote job there

muted olive
#

where

neon zealot
#

Fbi or cia

muted olive
#

lol

molten bobcat
#

You need a bachelor's degree to apply for the FBI

muted olive
#

no

neon zealot
#

I'll complete bachelor's then I'll let u know cloud

molten bobcat
#

You also have to be an American citizen

muted olive
#

also a lot of vetting

#

a loooot

#

and getting trained on site

molten bobcat
#

Correct they interview your family

neon zealot
#

Wow

molten bobcat
#

Correct training is held in Quantico Virginia

neon zealot
#

Interesting

muted olive
#

quantico yeah

scenic maple
#

do i see a fed

molten bobcat
#

I just know about the FBI

scenic maple
molten bobcat
#

CIA I have no clue

muted olive
#

CIA can basically be anyone

#

can be high ranking officials in other countries too

molten bobcat
#

I've wanted to do criminal justice related things but I'm unsure of my

#

Mental capacity to do so.

#

In regards to having to observe potentially traumatic data.

muted olive
#

like law?

scenic maple
#

cold world out there

iron comet
#

siberia is a bit cold

muted olive
molten bobcat
muted olive
#

crime is messy

#

digital forensics idk but the setting would still be messy

molten bobcat
#

Eh

#

By the time DF is getting involved you're not at the crime scene lol

scenic maple
storm coral
muted olive
#

either that or stuff has been removed

molten bobcat
#

I was also head of cybersecurity for a major college campus

molten bobcat
#

So I most assuredly have seen my share of gross shit

#

Even now I still do

storm coral
molten bobcat
#

Yeah, but I'm unsure if my mental fortitude will be enough

scenic maple
#

but its nothing like real crime tbh

molten bobcat
#

One of those things that's hard to measure until it happens.

muted olive
storm coral
molten bobcat
#

I know of a database for slurs

scenic maple
#

i know a guy who found a sqli in a slur database

muted olive
#

thats what my exp was

molten bobcat
storm coral
scenic maple
#

insider joke

#

world is full of amazing people

muted olive
molten bobcat
#

Disgusting

muted olive
#

🤨

molten bobcat
#

Don't ask.

#

Seriously

#

It's super not appropriate for this server

muted olive
#

i dont think i want to know kek

#

and... pencil cutting?

storm coral
#

First letters

muted olive
scenic maple
#

did you guys know that burp darkened their orange color

storm coral
molten bobcat
#

Except it's not a pencil.

scenic maple
#

now its not as bright

storm coral
muted olive
#

sounds like quite a server you were moderating

molten bobcat
#

Yeah I have zero desire to moderate that garbage lol

storm coral
molten bobcat
scenic maple
storm coral
muted olive
#

the server

scenic maple
#

this is new as well

#

eyy man no word evading

storm coral
muted olive
#

ah

scenic maple
#

yall can talk abt this all day in dms

#

😩

storm coral
muted olive
#

its funny how golam is trying to deviate by talking about orange burp colours

#

peak mod

scenic maple
#

i will do it again

#

and u cant stop me

#

altho it is actually true btw

muted olive
#

burp suite

storm coral
scenic maple
cerulean bloom
storm coral
#

Participated in Ai Hackathon the other day...

#

Fuck this, it was vibecoding competition

#

Not touching ai for at least a month

dusky jacinth
#

Wym

molten bobcat
dusky jacinth
#

Like the htb one?

#

Or smthn else

storm coral
exotic pendant
#

😄

dusky jacinth
storm coral
# storm coral No no, cispa

If i would have known some math behind it or like prepared for it heavilyit would have been ok, but not like that

heady sage
storm coral
#

Or maybe one team from 20

obtuse fern
scenic maple
#

they are always listening for feedback on the chat
i think it has shaped some great features in burp

#

cool guys

#

only if there is no such thing as jython and jruby

muted olive
#

is that portswigger made?

heady sage
#

I want custom css support for burp

scenic maple
#

no i think jython is diff

muted olive
heady sage
muted olive
#

oh

#

lol

scenic maple
fierce vale
#

Burp ricing yeah I like that

cerulean bloom
scenic maple
#

using the nightowl theme

#

altho its really messed up with java stuff otherwise i would have made a htb one

dusky jacinth
#

GET HSI COOKIE

#

jk

scenic maple
#

peak if u ask me

cerulean bloom
#

got an interview in 1 min

#

wish me luck!

heady sage
cerulean bloom
heady sage
#

Good luck man

cerulean bloom
#

one of them

cerulean bloom
scenic maple
#

🤞

dusky jacinth
#

An interview for highschool?

#

Maybe I’m just American

scenic maple
#

yes we know bro

dusky jacinth
#

Or like for a job AT a highschool

scenic maple
#

no

#

exactly what you thought first

dusky jacinth
#

yeah we don’t do that shit

scenic maple
#

no shit

dusky jacinth
#

You just go to whatever you get

#

Unless it’s private

scenic maple
#

but u also have to get acceptance right

dusky jacinth
#

Like I applied to a performing arts school, but didn’t go through with it

scenic maple
#

the elite schools require some bullshit method of proving urself

dusky jacinth
#

Yeah those ones do

scenic maple
#

i have always wanted to know what to people at art/design school learn

#

for 4 long years they only perfect their skills and become a graphics designer/ animator etc

#

idk but sounds really fun stuff to me

#

not much stuff to memorize or calculate

#

i guess the downside is there arent always jobs avilable

dusky jacinth
#

But for public it’s a different story

scenic maple
#

yeah ik

#

donus is exceptionally talented

dusky jacinth
scenic maple
#

i bet he will make it to mit

#

also probably reach grandmaster in cf before college ends

dusky jacinth
#

Lollll

#

Hopefully, MITs a cool school

#

@cerulean bloom what you wanna do?

scenic maple
#

lmao mit is literally the best there is

#

tbh

dusky jacinth
#

Robotics? Electrical engineering?

dusky jacinth
scenic maple
#

idk didnt ask that far

#

but its probably tech anyway

fierce vale
#

maybe not much math but art is a lot of work

dusky jacinth
#

I don’t think they’re programming is as good as like Georgia tech or UTD in all honesty

scenic maple
dusky jacinth
#

But they have phenomenal robotics, electrical engineering, physics and more obviously

scenic maple
#

i wonder how the chinese universities are in terms of those

dusky jacinth
#

And then overcome performance anxiety

dusky jacinth
#

Like Harvards

#

I didn’t think it was as good imo

#

Harvards pedagogy is phenomenal

scenic maple
#

maybe try applying

dusky jacinth
#

Oh nahhhh

#

Maybe one day if I ever decide to go back

fierce vale
#

“art is suffering” and all that

dusky jacinth
#

Exactly^

#

Id actually think id like teaching at a school like that one day. If red teaming ever becomes a course you can take world wide LOL

dry thicket
#

Does anyone know if HTB will give discount on VIP+ in the last week of December?

dusky jacinth
#

No idea personally

cerulean bloom
#

sry

#

uhhh

#

ICPC

dry thicket
#

Im waiting for any discount to get that VIP+ sub

#

Sigh

dusky jacinth
cerulean bloom
#

and participate in ICPC

exotic pendant
#

New windows bug

thick forge
#

icecream time

short bloom
molten bobcat
#

Lmaoooo

#

Who the hell runs linpeas as root

#

PART OF ME FEELS LIKE THAT DEFEATS THE PURPOSE OF A PRIV ESC SCRIPT

native plume
#

Only if you couldn't get user flag before root /s

molten bobcat
#

Nah read the blog