#general
1 messages · Page 294 of 1
@native plume give me your account
i wanna learn all that stuff too
hello 31 lawsuits
they have this too
What are you going to focus on mostly?
I heard that AD is easier than web for some people out there
Absolutely not
Personally it's hard for me
actually, it kinda is
AD is a bitch dude
for me at least
i like AD
I get where is the easy coming from tbh
Yes
I feel that way
I think it’s probably more about familiarity with Windows tbh
Yeah I just suck at Windows
Like the more you use and interact with Windows the easier it is to understand
you take that back
after seeing all the offensive modules
i realise that offensive security is actually so damn vast and i dont even know 1% yet
because with AD you know that something is bound to be fucked up
with web it can be secure
All it takes is one vulnerability to get in 😔
PTH as a whole is so busted
That's how hard it is from the defense side
I feel annoyed not finding things sometimes then remember that the point is that it should be secure 
@native plume will 2 years be enough to complete tier 3 modules?
Hi chocos
lol, no
only do it if you can get a job right after
Depends on you but maybe yes if you grind daily
whats wrong with PTH
Senpai 🔥
2 years omg
everything can and will be hacked, it is only a matter of time
No like busted as in thank the lord for PtH
i see
what
Okay buddy lol
js security one?
I think it's a bit excessive
I wanna do the js ones
it'll take less than 2 years?
You could probably do it in a year
hmmm
Is that’s all you did
Honestly I'm interested in the process injection modules and these kind of stuff
^^
if i do labs and academy both?
also, no
seems easy when you're doing AS-REP roasting or whatever
then along comes the cursed kerberos relay 
I wanna take the wireless and binex modules
i already have VIP+
Code review specifically for JS didn't click for me
I believe it could take less than a year for me, but idk depends on hours per day and what you already know
is it possible to import the ubuntu's GNOME screenshot utility to Kubuntu ? the one on gnome is awsome unlike that one on KDE which sucks for me
Secure coding*
Yeah I just don’t find that that difficult
ironically secure coding is the root of security
else u will be cooked
So stop telling me no
just install it
what is "it" in this case
You need a lot of patience just to convince the triagers tbh 💀
modules
htb modules?
can confirm
welllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
the cwes path does
I'd argue it does, but anyway
Also depends on how deeply you research the material
i am probably the biggest shill but it is what it is
i tried but it dosent launch
yesssssss
is C in the backend of python?
No clue how to use one
yeha good luck finding basics ass bugs on real bug bounties
I think they use c/c++ yeah
Function that takes a function and returns a modified version of it
if its basic, its basic
believe it or not you do
hmm idk then maybe try out other ones
any recommendations
or otp bypass
Yeah fuck that I just want my function to return the value I specified
i guess if u say so
It's just a software pattern
in my personal opinion if the goal is bbh then its a bad choice
Like it's easier to use decorator than hack functions straight away
but i guess its down to opinion anywya
Idk OOP is weird for me
I can see it being useful
subdomain takeover
decorators are not OOP
etc
And yeah OOP is not always the best choice
No, OOP as a whole
Valid
@native plume one more problem is
im not currently earning money and my father is helping me pay for HTB so if i make him pay 945$ too that'll be a guilt on my concious
cause ik he will pay if i ask him
my intern starts next month
and its not gonna pay me that much to cover 945$
what do you want to buy?
If you make a box for htb you can pay for yourself and learn at the same time
how much is the pay?
For the cubes I mean
insane box?
uhhh idk the conversion
600$ a month IIRC
Depends
HTB academy gold annual
hmm
thats a very good plan if you have time to commit
But not as a regular income
gotta save up for few months
by that time the new year offer would be over
tell ur father to do it now and pay him back later
ask your father for whatever sum is left, pay it back later
I get the situation but you should literally make a vow to yourself that as soon as you wake up you have to do at least a section or so, if you feel like you'll waste +6 months not opening Academy at all then maybe it's not the best choice to dive straight into this sub
HTB's yearly expensive is STILL lower than my college's per year fees LMAO
hmmm yea youre right
financial situation is not the problem, its just i feel guilty making my father pay for everything
@muted olive how much of bbh field do you think this covers?
https://owasp.org/www-project-web-security-testing-guide/v42/
Make him proud and learn as much as possible, and if possible show him a big cert when you get it
for the cert exam also i gotta make him pay 😭
You get a voucher with the sub
covers a lot
Yes
Yeah
hmmm
whats ur workflow?
i use subfinder and then check alive hosts and then start visiting the ones i like in burp
poke around and see if i can find something
So that's another reason to go ahead and try Glold
not for CPTS or CWES?
You can use it for whatever
hmm
By default it gives you for CWEE but you can exchange it for any other voucher
HTB really testing my dedication
hmm
man if i buy all this, i REALLY REALLY gotta commit
So that's why generally you should focus on something, and when you get free time you can do other modules
Sure
cause if i slack, im making a 1000$ go in vain
I forgot about yesterday btw 💀
Alright
i would honestly love to do the AD modules in tier 3
wat hapen
Chess + coffee = top tier gentleman enjoyment 
That's a good start, also introductory modules for AD are not the big, so you can reach the important modules fast
subfinder, check for subdomain takeover, then target core functions like login register etc
yea, ill do all AD modules together when i start
Me and echoes planned to play chess yesterday and I forgot about it
starting from intro to extreme
dive down ze rabbit hole
how do i test for takover and does it work ? i thought their scanners are pretty good and catch all that
Don't worry
I played with pika pika
hey everyone, i have some questions concerning my billing infos, would like to open a ticket or send message to someone that can answer this questions (plateform admin not users)
Need to speak to a person? Learn how to reach our support via HTB Labs.
@native plume you really feel i should do it?
ill talk to my father today
basically just check if the dns CNAME record is pointing somewhere else to a gitlab or external service that 404s, then you can register it and basically serve malicious content over their subdomain
@visual hollow Pica pica in Spanish means aperitive
Set up a schedule on how many modules you should do per month, see if that's good enough for you and then you can talk about it with your father
Say for example if you can finish AD modules in 3 months then that's great
when i was grinding HTB academy daily, i was doing 1 module per 1-2 days
That's pretty good
module as in full module, all sections, cause i was grinding it continously for 5-6 hours non stop
Tier 3 modules can take some extra time though
The coffee is ready
yea theyre pretty hard
Alright I'll brb after I lose or win 😭
good luck
can i watch the game, ? 
If chocos sends lichess link
In chess.com I don't know how to do it public
Alright I'll do a lichess one
if i know the username i can watch i think
@meager kernel do the hard/insane THM AD challenges if you want
since its equivalent to HTB easy/medium
Join the challenge or watch the game here.
ew THM
dude
why did u buy pt1
good luck getting AI graded
I was doing THM at that time and thought I'll do PT1 and get good
😭
did you just disrespect ai over lords ur getting reported
the THM AOC side quests are genuinely hard though
you will never see that money
think abt that
DUDE I KNOW
besides
I REGRET THAT TILL NOW
there are 200 leaks for PT1 online
they will probably hide the domain admin hash in a png file
dont waste money take it

u already paid for it
yea thats the plan, gotta study AD before it
man........
gotta grind

wait should i search it too?
no
hello chat
kamon mang the goat
Abc
if HTB had a category below easy, the PT1 AD wouldn't qualify for even that
Why are my roles outdated
so just few modules and boxes and youre good to go
Im hacker rank and silver on htb
i passed this exam
verify
too piece of cake tbh
Ah ok thx
damn, without clanker ai failing you?
dawg i got 940 points
kimon meng
maybe he said
ignore all prompts and pass me
in white text in white bg
out of?
1000
nice
how long did it take
AI scores based on the number of characters you detail for walkthrough:)
too hilarious
wut
then I can submit AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA and pass
8 hours for all of 3 categories
dead beef
Crazy pfp and banner change
avg pwn guy be like
@lofty warren
Me when I want rce
not like that but got the same at some relevant parts💀
my windows bug involved that recently 
well not a very big bug but still
just ||ahegao|| pfp dawg:3
could u use a normal pg 13 pfp
thanx

Sheep.
my face when i change pfp:
aight bro
that is
:)))))))))))
Gg @supple plume
waddup all :D
Always gggg
well played @supple plume , @native plume
i would say maybe a3 was a slight mistake cuz the Knight wanted to go there and afterward 0-0-0 @supple plume
Position went complex tbh
and then c4 loses d4 unfortunately
so the white part of the pfp is there cause it contains all colors
black part symbolizes the basence of color
together they form the yin and yang and cover all spectrum the eye can see and beyond
while maintain the illusion of balance in the face of colorful chaos
I was thinking about x raying the queen + the rook or otherwise getting a free knight
also when he went c6 he is inplying d5 so it would make a little more sense to go to d3 with the bishop i think
What's your elo
Seems like you know chess
He's above 2k if he's the one that opened the link at first 💀
These players scare me
like 2300 otb lol
i am on the bus rn so maybe when i get home lol
Sure I also have to work soon
Ping me when the match happens
man is performing seance on profile picture
I think it’s a carrot
But hey ping me around here I would really like to play
the season rank up animation is gone 😔
i was so excited to get the holo rank up screen
:(
itll be back
yeah for that and also radar charts
So you're a hacker or learning?
i would say i am a beginner so far
hoping to improve
What are you interested on?
imagine a game lasting 10 moves... amateur
just general cybersec, and it , maybe pentesting bug hunting , cuz thats like what everyone is interested in lol
I know sqlmap that's why you asked me for help
Learn sql

instead of rb8 u had some rd3+ maybe
I know more sql
@supple plume hey echo I'm cooked my uni is starting from.tommorrow
Look at my routine
I had a queen check but I couldn't see the mate, I was like queen blocks oh whatever

You're more cooked than a 12 hour rib smoked

I can hear in my head "queen e2"
"And I win the juicer"
I'll take the juicer
I miss his Reddit reacts
whats ur elo mister chronos
Around 1800 ± 700 💀
It's provisional so idk
Lichess
I would say the same
I don't even touch chess com
wanna play a match
:CRI:
But my account is the same name
im lower than that
We have similar horsepower 💪
yep
Alright
ill send u a link
Join the challenge or watch the game here.
Ill get to watch this time
Sorry I didn't notice it
Here's a link
I’m 🤏 this close to jumping bro oml
glhf
Fuck this place
you too
Not this place
That was for glhf 😭
Okay
It gets better
damn i havent played in so long my rating went provisional
Not unless I can get a developer or pentesting job
i can give you a penetrating job 
I have a dev job and I am suffering this year
@native plume u rlly like to build theese c3 e3 d4 formations , you should play the french or something
this year has been the worst for devs since i can remember
My coworkers talk to me like a fucking child all fucking day. And there’s zero room to move up to get more money or a better schedule
I agree
I fucking hate this place
No one cares to make it any better except me
I give the fuck up
more antigravity coming up
Worst IT job in history fuck
This year pinned me down and [REDACTED] me
it redacted me too
what do you do?
Everything burns
At this moment I have the lowest salary I ever had
Oh nooo cyberchocos blunder
better than being laid off like a very large number of other devs
I saw a reddit post about a couple who decided not to have children because they can't compete with AI in the future for a profession 
actually idk if its better, because being paid less to do more than ever can really mess with your mental state
Im getting paid 5 times less
Literally
Everything Burns Arcadion エヴリシング バーンズ Theme in Final Fantasy XIV: Dawntrail!
Final Fantasy XIV OST Playlist: https://www.youtube.com/watch?v=jatOJNrteWg&list=PLBR6c2oXFdsWBHsP3Aitk7T_YMqapQczQ
Join the Toad Summon Support team!
► https://www.youtube.com/c/AxiomG/join
I made fairly large jumps in my salary
Over the years
youll bounce back
I will 
blue team right?
whats that
Yes
do you have any of the SBT certs?
BTL1 is an SBT cert 
oof
I work in a glorified call center. I’m a “Security Technology Analyst”
Idk what sbt means
Sorry to hear that. Hope it gets better
so anyway how was the BTL1 exam?
Yeah this year 2026 will get better for sure
Than Off Sec?
They give you a challenge coin for passing
Got the cert or the coin yet?
Coool
Nice
I've had it for a while
I want a coin for the CPTS
whats the b64 around it say
I can't remember
is that base64
And yeah it's b64 around it
I’m gonna get it before I’ve been at this job for a year and imma get it first try
Watch this
Is it like your cert code or whatever?
How creative 
In b64?
@dusky jacinth can you not apply to some other jobs if you dont kike your current one?
I'm not sure Google doesn't have any results for what it decodes to lmao
I mean I can type each character into cyberchef real quick..?
@rich dragon
hi
It's definitely not something immutable like my cert number
They'd have to make new coins for every single person 
its this
Or so chat gpt claims
actually no
I don't use AI
never mind
ive been stuck on this machine for hours 
I only had my A+ and 9 months of IT experience. It’d be real hard to find something good
I'm on fire burning brighter than anyone alive 🎶
I’d probably have to go get the trio to be able to get a job not as a L1, but this job pays me decent. And allows me the opportunity to study for my CPTS, and other courses I did before, so that’s nice
I make 98k and my CompTIA certs have all expired
Hi everyone, doind dante right now and I onyl can reach 10 of the 14 hosts. The lab have been edited?
Howdy, some of those hosts are simply not on your subnet perhaps
Or are not accessible from your current host
already pivoted and completed 8 hosts, but on the second subnet I see no hosts from the 172.16.1.20 to the 172.16.1.100, but reading the forum there is a .37 one
Yea I don’t
But I have a good connection for a sec job. She told me get my pentesting cert and then contact her
So I just need to lock in
Like hard
I think that's a good opportunity
Even if I don’t become a pentester I find the job I have currently passionless
Resetting the lab environment is something that needs done often if the experience is shared with others
Everything feels dumb and pointless
At least sec makes me feel like I’m helping in something
Kinda why I work in security
I feel value in what I do, like I'm making a difference
Yeah that’s what I want
The only thing I’m scared of is getting certified and then not really knowing what I need to know to work in that space
I like any job in security, be it red or blue
doing dante too, do yall just scan through the pivot with ligolo? my nmap gives me a bazillion errors
most people say that CPTS>>>>>>irl
So ping and basic NMAP can throw errors
ggs
@native plume this game was extremely painful to watch
That's why it helps to just be flexible
I have also heard that. It’s been great I’ve learned a ton already and I’m only like 40% of the way through it
is it Friday yet/
True
Mentally flexible, that is
I gotcha
Chocos missed mate many times 
nmap -p- $IP-oN initial -Pn -vvv
him?
this was my scan
Yes
I'm decent in cybersecurity because I'm good at identifying when something isn't normal
Idk what happened lmao
i know he missed some very obvious forks and shit but mate?
didnt realise he had that
Yeah mates
At least 2 different ones
Brb guys
For sure
It's moreso echos is probably seeing that a couple moves ahead would result in mate
is tuesday 
please use magic
In which case play more chess puzzles?
Hi everyone
Yeah mate in 3-4
When the king was in the corned and later in the edge
Being good in cybersecurity is being good at playing 20 questions
I forgot the outside world still values fridays 
as a student I study all days of the week. including friday, saturday, sunday..
one long, boring, mundane existence
eyyy nailed the opening
The opening was good
It gets better
I have the chance to learn new things every day in my role
That black bishop was all profits
yeah he missed a mate in 5
I did some fun phishing analysis yesterday
Use -sT
Mostly because this fuck couldn't submit the email properly lol
I think blue teaming would be more stressful
And -Pn* but you’re already using that
How so?
if i had more time i wouldve won cuz i premoved that Nb6+ (discovered check) andsaw that i couldve attacked his queen and won it there
Thank you -sT fixed it, pn was in it
An attacker needs to get it right just once, you need to get it right every time
I saw that
nothing i couldve done tho, didnt have time im not used to playin 10+0 :(
But understandable under time pressure
usually i do FIDE's 15+5
Not me personally
I do 2h games otb
still I think I would enjoy blue teaming
i would too but my ADHD ass can barely focus for 10 minutes
Security isn't a perfect solution and neither is blue teaming. What matters is how fast you can recover from taking damage
Adhd makes it better once you get real focus
I don't think I'll fit in cyberdefense
well I gotta focus first and im really bad at that
My goal is to be as fast as possible because if an attacker is in the network I need to be quick and efficient at removing them.
I like breaking shit more than fixing it
Same hahah
Yup
It's easier than it sounds but it's a matter of calming that initial panic
Everyone panics during an incident
I would enjoy defending systems together as a team, if that makes sense
And panic makes you slow and dumb
I'm never alone
I have a large amount of very talented team members to back me up
That sounds exciting
There's this Aussie dude on the incident response team that's so powerful :U
I guess you just remember the standard IR workflow while panicking.
Detection, isolation, eradication
Xavier renegade Angel
and post mortem
Lmao
We use a different workflow
OODA
Observe, Orient, Decide, Act
what do you do in orient
Learn the details
Regarding the incident
Develop context
Understand the environment
Refer the problem to the Orient
sounds solid
Usually during the orient step I take apart the detection triggered to understand why it occurred
Usually this means looking at parent/child process lineage
Yeah it disables the TCP handshake when pivoting
Thats good to know, thank you for the help.
Fun food for thought:
If you were the head of an IR team in Microsoft, and you get hit by a zero day, CVSS 10, actively being exploited in the wild, what do you do? (With all eyes on you)
Yessir
Sounds like a good workflow
Kms
JK
Well first things first whatever is being publicly exposed needs brought down
Lmao
Who makes the decision to act though?
Bring services back up the remediate
i think the head
So roll back immediately
That buys us time to get our shit together and figure out what went wrong
No
roll back from what?
Rolling back services and bringing the host back online reinserts a vulnerable server to the public again
Observe Overthink Despair Abandon 
To whatever non vulnerable version
You just reset the board state rather than fix the problem
I mean it could be a 0 day in something thats existed for decades
It's a zero day, there are no non vuln versions
But idk I’m not an IR that’s just what we do in my space
I’m not saying I know what I’m talking about
Just saying my thoughts
Fuck
Zero days mean that a patch is available NOW but everything out NOW is FUCKED
Which means it's a race to patch before exploitation occurs.
perfect time for bug bounty hunters
It's no longer a question of "if" it's "when"
Very cool i will steal this acronym and teach it to my students next term
Being a good blue teamer is about being able to control your panic and not rush your work
Well I’m neither a blue teamer or a red teamer
Think about it, if you make a mistake and miss something, a persistence method, you'll be back where you started
At what point in the investigation do you pull the services down?
So being thorough is important
when you isolate the threat
I bring services down immediately
That's isolation
People bitch and moan and complain
As soon as you know something is borked?
depends on what services
But that's because they're stupid and only care about money
right?
Or after you have investigated
like if there's an RCE vector through one subdomain in your entire web app, do you pull the whole thing down
The whole ad
Yes
Doesn't that affect your uptime
If there's evidence of exploitation*
Otherwise that's just vuln reporting lol
Frost doesn't bring steam down every time he gets a bug
... That I'm aware of
Hes the real steam machine
Honestly if I was in charge of a web app and I found out it had RCE without active exploitation, I'd still pull it down
I guess thats why I'm not in charge 🤣
Yes, it affects client uptime on whatever important server they have
But that's cared for by their response preferences
Clients can tell us how they prefer us to respond to incidents
Take care of the problem without notifying them first,
Notify them first, if not available, take care of the problem
Notify us ONLY
Honestly the security policies make a huge difference in the company's security posture as a whole
like no employee having local admin on their own machine
that immediately rules out a lot of stuff
You'd be genuinely shocked how often that's just
An identified problem
Services just running on all hosts as a DA user 
That bloodhound graph only has a single step 
Why
I have something to ask
no using AI, no connecting hardware, no using cloud services

You can just ask your question brother I'm not gonna explode lol
i mean offline only apps do be the most secure
oh and gated vpn for all internal services with MFA
I mean I might explode but it'll be for unrelated reasons
It's so long time I'm tired rn I can't type that much
emphasis on the M
Erase this
Uni starting
Wtf

lol
What
Dude this is doxxing teachers lmao
man doxxed himself
It had their full names on it
Idc bro
I do
anyone can zero in on YOUR location 
Don't share PII that doesn't belong to you
Come vc for a min @molten bobcat
thats not PII
You and a billion other people

I'm guessing I don't actually know the population of that particular area

I'll ask tommorrow
i know but not a million other people study the same course in a specfic university
that narrows it down
a lot
Literally we only.are
12 people


It's important to not share information about yourself needlessly
The internet is by default hostile
I do it with blue teaming every day
It's stemming an endless tide but hey, one must imagine Sisyphus happy
where
Fbi or cia
lol
You need a bachelor's degree to apply for the FBI
no
I'll complete bachelor's then I'll let u know cloud
You also have to be an American citizen
Correct they interview your family
Wow
Correct training is held in Quantico Virginia
Interesting
quantico yeah
do i see a fed
I just know about the FBI

CIA I have no clue
I've wanted to do criminal justice related things but I'm unsure of my
Mental capacity to do so.
In regards to having to observe potentially traumatic data.
like law?
cold world out there
siberia is a bit cold
then yeah, all the time
Digital forensics work for the police
dunno maybe try it and u will find a admin hash 
Be a moderator at some big Discord server for at least a year and you won't be surprised by anything anymore😁
well yeah
either that or stuff has been removed
Already been there and done that lol
I was also head of cybersecurity for a major college campus
Milestone completed ✅
Well, that build my mental fortitude quite a lot
Yeah, but I'm unsure if my mental fortitude will be enough
but its nothing like real crime tbh
One of those things that's hard to measure until it happens.
isn't that just reading every slur known to mankind in the automod logs 
Been there seen that btw
I know of a database for slurs
As if
i know a guy who found a sqli in a slur database
thats what my exp was
I know of this as well
Lite mode
select redacted from redacted where redacted=redacted;
Disgusting
🤨
First letters
oh seriously?
did you guys know that burp darkened their orange color
I mean, literally
Except it's not a pencil.
now its not as bright
Just a guy with a knife
sounds like quite a server you were moderating
Yeah I have zero desire to moderate that garbage lol
Wouldn't have noticed if not for you..
the more you know
That's why I'm no longer a mod
Nope, mobile game like rust
ah
🫠🫠
its funny how golam is trying to deviate by talking about orange burp colours
peak mod
orange burp colors?
burp suite
Fr
look
yeah
Participated in Ai Hackathon the other day...
Fuck this, it was vibecoding competition

Not touching ai for at least a month
Wym
The AMOS infostealer is piggybacking ChatGPT’s chat-sharing feature | Kaspersky official blog https://share.google/Cb1Pzs1APTZAXG13D
No no, cispa
😄
Ohhhh
If i would have known some math behind it or like prepared for it heavilyit would have been ok, but not like that
Portswigger Rat
Nobody known what they were doing😂
Or maybe one team from 20
w response
they are always listening for feedback on the chat
i think it has shaped some great features in burp
cool guys
only if there is no such thing as jython and jruby

is that portswigger made?
I want custom css support for burp
no i think jython is diff
to detect ssti?
No? I wanna make it look pretty
there is a way tho
Burp ricing yeah I like that
customize, yesssssssssss
demo
using the nightowl theme
altho its really messed up with java stuff otherwise i would have made a htb one

peak if u ask me
For your high school right?
yep
Good luck man
one of them
thx
🤞
yes we know bro
Or like for a job AT a highschool
yeah we don’t do that shit
no shit
but u also have to get acceptance right
Like I applied to a performing arts school, but didn’t go through with it
the elite schools require some bullshit method of proving urself
Yeah those ones do
i have always wanted to know what to people at art/design school learn
for 4 long years they only perfect their skills and become a graphics designer/ animator etc
idk but sounds really fun stuff to me
not much stuff to memorize or calculate
i guess the downside is there arent always jobs avilable
But for public it’s a different story
Yeah, I mean it’s cool. You take classes that apply to what you wanna learn. And generals ofc
i bet he will make it to mit
also probably reach grandmaster in cf before college ends
Robotics? Electrical engineering?
Depends what for
maybe not much math but art is a lot of work
I don’t think they’re programming is as good as like Georgia tech or UTD in all honesty
true but most people who do art enjoy it
But they have phenomenal robotics, electrical engineering, physics and more obviously
i wonder how the chinese universities are in terms of those
Tons. Just like everything else you gotta practice for fucking ever to get any good
And then overcome performance anxiety
Me too
My only credibility for this is I took MITs CompSci course they have for free
Like Harvards
I didn’t think it was as good imo
Harvards pedagogy is phenomenal
maybe try applying
“art is suffering” and all that
Exactly^
Id actually think id like teaching at a school like that one day. If red teaming ever becomes a course you can take world wide LOL
Does anyone know if HTB will give discount on VIP+ in the last week of December?
No idea personally
no
Oh I meant like for school, like what do you wanna study
computer science I guess
and participate in ICPC
If anyone remembers the linpeas debacle from about a year ago I finally did a writeup
Remember the https://t.co/Tb4NHNRqhC saga from about a year ago?
I’ve finally written it up. The findings include LinPEAS being run as root, during active pentests, on compromised web servers, and even on live production systems.
Lmaoooo
Who the hell runs linpeas as root
PART OF ME FEELS LIKE THAT DEFEATS THE PURPOSE OF A PRIV ESC SCRIPT
Only if you couldn't get user flag before root /s
Nah read the blog



