#general

1 messages · Page 297 of 1

civic lance
#

I'm up at 1AM accepting my fate

sharp shuttle
#

frickin epic memories dood!

vivid flower
#

I show brathisms to students at club in hopes they won't be like that

sick gate
#

just ask him

#

he'll tell you

pearl spruce
vivid flower
civic lance
#

9AM for u?

pearl spruce
civic lance
vivid flower
civic lance
#

I'm just saying shit

#

Griffith is something else mannn

sharp shuttle
#

how college-educated of you

civic lance
pearl spruce
#

brathadair, why I feel that you are hopeless or angry?

sharp shuttle
#

brother i dropped out of high school

civic lance
#

?

sharp shuttle
#

i saw the sham when i was in fucking middle school

sick gate
#

statistically speaking not a great move

civic lance
#

I feel like u should actually complete highschool ngl

vivid flower
#

Thats pretty badass

sharp shuttle
#

yes statistically, i am an outlier

#

dont be like me unless you are profoundly stupid

vivid flower
#

Bandors dropped also

#

He was doing hf stuff in class

civic lance
#

he prob trolling ngl

sharp shuttle
#

im serious, i wouldnt lie about this

#

in fact im prideful of it

#

i did it the hard way, and im better off for it

vivid flower
#

Bro would literally run an ewhore pack on his computer during class in high school

sharp shuttle
#

lmfao

sharp shuttle
#

😉

pearl spruce
vivid flower
#

I met him right when he turned 18 you will get to meet him sometime

sharp shuttle
#

im excited to meet bandor

#

sounds like a stand up guy

civic lance
#

Im really a failure

sharp shuttle
#

only if you think you are

pearl spruce
civic lance
#

I'm just going to get this calc exam out the wya

#

so I can go play minecraft over my winter break

sharp shuttle
#

whats the slope intercept formula

#

you have 7 seconds

civic lance
#

y = mx + b

sharp shuttle
#

good job

#

youll be fine

civic lance
#

Thats alegbra....

sharp shuttle
#

thats also calculus.

civic lance
#

bitch

pearl spruce
visual hollow
civic lance
#

SAT?

pearl spruce
#

I love algebra, but hate gemetry.

sharp shuttle
#

standardized academic testing

civic lance
#

ik what that is

#

but why he said it

sharp shuttle
#

who knows

#

lets fight about it

pearl spruce
visual hollow
#

I want a McFlurry

civic lance
#

thats what calc is?

sharp shuttle
civic lance
#

I just try and memorize shit

sharp shuttle
#

hope that helps

#

talk to me when you start doing digital signal processing

#

you are basically a baby

civic lance
#

u right

vivid flower
sharp shuttle
#

yes, analog conversions

#

fourier transforms

#

FFT's

pearl spruce
sharp shuttle
#

the list goes on

vivid flower
#

I passed a calculus class and still dont even know what it is

sharp shuttle
#

its moreso differential equations

pearl spruce
sharp shuttle
#

when i studied quaternions when i was developing in game engines, it all made sense

#

it is extremely useful

remote iris
#

hackthebox gotta stop blocking mullvad nodes entering site, i love my mullvad vpn

#

i need to visit their store

sharp shuttle
#

why... would you use a vpn to connect to a vpn?

remote iris
#

im not

#

im on a vpn

vivid flower
#

This guy hacks

sharp shuttle
#

mullvad vpn -> openvpn?

#

what?

remote iris
#

no

sharp shuttle
#

you mean mullvad browser then?

remote iris
#

no..

#

mullvad on top

remote iris
sharp shuttle
#

alright...

remote iris
#

i feel comfy using mullvad

#

everywhere i go

vivid flower
#

Hey is there a better way to encapsulate vpn traffic than vms these days

pearl spruce
remote iris
#

mullvad

sharp shuttle
#

imagine using a vpn with a company logo when you can roll your own vps

civic lance
#

No matter what measures u take for privacy, u are still known.....

sharp shuttle
#

insane

remote iris
sharp shuttle
#

consider how mullvad makes money please

remote iris
#

by providing anonymity it serves

#

and their trust

civic lance
remote iris
#

mullvad on top

heady sage
#

flex tape

vivid flower
#

Does mullvad allow packet forwarding?

remote iris
#

this is what they offer

vivid flower
#

I guess not

sharp shuttle
#

it doesnt support port forwarding no

pearl spruce
#

Free ad

remote iris
#

FREE THE INTERNET

#

bro i cannot do any bug bounties im such a fucking skid

sharp shuttle
#

we dont need to free the internet we need a new internet with giant firewalls blocking entire countries

vivid flower
#

Yes

remote iris
pearl spruce
sharp shuttle
#

bug bounties are for indians and cyber slaves

#

unless its private ofc

remote iris
#

LOL

#

LOL

sharp shuttle
#

👌

vivid flower
#

Let frostbite hear that

remote iris
sharp shuttle
#

yeah...

rustic carbon
#

hello

sharp shuttle
#

bug bounty is simply fuzzing unless its private, and AI is just going to dominate it

heady sage
#

i have drunk beer

vivid flower
#

This whole corporate bugman shit makes me depressed

sharp shuttle
#

not worth your time

heady sage
#

and i feel like god

remote iris
#

if i wanna secure a job

sharp shuttle
#

lol what

pearl spruce
remote iris
#

yeah bro i got rejected

heady sage
#

Bug bounty will not get you a job twin

sharp shuttle
#

you think submitting a CVE is going to get you a job?

remote iris
#

i literally dont have irl experience

civic lance
remote iris
#

i need irl experience

sharp shuttle
#

you dont put your fucking name on a CVE if you are smart

remote iris
#

🗿

#

ofc not

heady sage
sharp shuttle
#

-.-

remote iris
#

just can say "subbmited bounty for"

remote iris
vivid flower
#

Damn how high is the ladder

remote iris
#

i got the IG info disclosure kept private still

#

good for osint

vivid flower
#

Yall keep pulling it up

heady sage
#

mmm delicous hacker snitch kinishes

sharp shuttle
#

have you considered lying? thats just social engineering, thats just pentesting, thats red teaming - are you really living in bad faith if you can secure a job without invoking izzat?

pearl spruce
#

What else he can do if no CVE or registered findings?

remote iris
#

can just be like anything thats bug

#

IDOR for example

sharp shuttle
#

your efforts are profoundly misplaced skidzz.

#

i hope you one day realize that

remote iris
#

im so tired bruh been tryna find a bug bounty all day got no where

#

what does that mean

vivid flower
#

I think i can pass an interview with bpm but im learning ghostwriter first

pearl spruce
remote iris
#

profoundly

heady sage
remote iris
#

and where can i actually get actual skills from

subtle plover
remote iris
#

im down

#

i need to get better i feel like im bad still

vivid flower
heady sage
pearl spruce
# remote iris what does that mean

I think maybe you are searching in the wrong places, me and my friend entered the same programs and learned together and he recently found one without too much time since he entered the field.

sharp shuttle
remote iris
#

i always feel like im just not actually good enough

sharp shuttle
#

its okay to r-wordmaxx

subtle plover
vivid flower
#

I feel that way too sometimes but i go back and talk to people and i realize ive grown

subtle plover
#

Its gonna always feel like that

remote iris
#

like even going for certs man

vivid flower
#

Do the crto with me man

remote iris
#

it doesnt feel anything special for me

remote iris
sharp shuttle
#

dont go for certs, just learn

#

pick a niche

pearl spruce
vivid flower
#

Im like 1/3 through

remote iris
#

thats what im tryna do i rly want IRL experience

sharp shuttle
#

ffs guys we have this convo every single fucking day

pearl spruce
remote iris
#

if i can be do offensive security all day in a real environment and have good feedback then i know im fit for it

#

fully

subtle plover
vivid flower
#

I might not even finish the cdsa after i realized i can hold a good convo about blue team stuff now

pearl spruce
remote iris
subtle plover
#

@austere sinew ping

pearl spruce
heady sage
#

LMAO

sharp shuttle
#

half the time you cant even find

remote iris
sharp shuttle
#

you want to find?

remote iris
#

for me ngl

sharp shuttle
#

be a threat hunter.

heady sage
subtle plover
#

Skids hunter

vivid flower
remote iris
#

LOL

subtle plover
#

Im an apt hunter

civic lance
vivid flower
#

Yes

sharp shuttle
civic lance
#

who made these names?

pearl spruce
remote iris
sharp shuttle
#

oh lord

remote iris
sharp shuttle
#

promise me you didnt buy a writeup for CPTS, skidzz

pearl spruce
pearl spruce
remote iris
#

LOL

remote iris
sharp shuttle
remote iris
#

i didnt even know that was a thing

subtle plover
pearl spruce
sharp shuttle
#

i do hope you are not lying to me

#

youd just be lying to yourself

remote iris
remote iris
pearl spruce
subtle plover
#

Hes a skid and a snitch

remote iris
#

LOL

subtle plover
#

Gtg

sharp shuttle
#

see skidzz, the thing im keen on here is we have no mutual friends

#

nobody knows who the fuck you are

#

how do you expect to get a job

subtle plover
remote iris
#

¯_(ツ)_/¯

sharp shuttle
#

start there

subtle plover
#

Pray for job

sharp shuttle
#

networking is truly the only way nowadays

#

you have linkedin skidzz?

remote iris
#

nope

#

i dont own any socials except for snapchat

pearl spruce
#

@remote iris I believe in you, just be motivated. Everyone’s provision is already destined for them.

sharp shuttle
#

go make one. osint me, and ill be your first friend

vivid flower
#

Ill add u homie

remote iris
pearl spruce
sharp shuttle
#

add me on linkedin when you are successful

pearl spruce
sharp shuttle
#

in what way?

subtle plover
remote iris
#

LOL

pearl spruce
remote iris
#

is that for realz

subtle plover
heady sage
pearl spruce
#

DDoS him.

remote iris
sharp shuttle
#

its arrogant? i know he wont do it, but if he does, I encouraged him to connect with me.

#

if you truly feel that way, L

subtle plover
remote iris
#

didnt get baited, just verified the source

heady sage
#

im a burp suite monkey rn

pearl spruce
remote iris
sharp shuttle
#

im public and if you want to take a step towards solving your stupid imposter syndrome woes, youll take up my offer

pearl spruce
sharp shuttle
#

but if you dont, i do not care

remote iris
#

good to know

sharp shuttle
#

the bounty is trying to help him build a network.

heady sage
#

hes not gonna do it brath

#

bro is uncofident even though he has a cert

remote iris
#

i've retired from doing it years ago

sharp shuttle
#

olive branch is extended, when you are done gooning to valorant or whatever thing you waste your time on, take me up on the offer

heady sage
#

no amount of osint will help him gain that confidence

pearl spruce
#

Be right back.
Sorry if bothered anyone by mistake. Good luck skidzz

remote iris
#

im gonna just get CRTO

#

im bored

heady sage
#

LMAO

remote iris
#

im just demotivated cause i aint find a single bug bounty to do today it probs just takes hella time

heady sage
#

HUH

sharp shuttle
#

i just verfiied you can osint me in 4 steps

remote iris
#

tbf it is my first time doing bug bounties

remote iris
terse dirge
sharp shuttle
sharp shuttle
#

yes it is

heady sage
#

LMAO

remote iris
#

cap

sharp shuttle
#

dont cope with zoomer ebonics, take accountability for your situation and change it

remote iris
#

im no cope, im just upset i couldnt get a bug bounty today to find for the first time

#

it's ok tomorrow is a new day

#

im gonna go sleep

cerulean bloom
remote iris
#

in the end

terse dirge
#

I just remembered I forgot to buy a Powerball ticket

remote iris
#

theres like 100k reports on bounties so far

cerulean bloom
remote iris
#

cause i thoight it was like different bugs

heady sage
remote iris
#

bros bullying me

visual hollow
#

Literally

remote iris
#

how many boxes do u have to do to get hacker rank

half lantern
#

i feel like crying

remote iris
#

cause i think i done like 20 in total

half lantern
#

you should be at pro

remote iris
half lantern
#

if theyre all active

remote iris
#

probs not active

cerulean bloom
remote iris
#

ohh

half lantern
#

yeah so 8 active should get you beyond hacker

remote iris
#

deadass?

#

im a go grind then

half lantern
#

yep

#

i did it in a week

remote iris
#

damn

vivid flower
half lantern
#

Guys i think im gonna cry

remote iris
half lantern
#

I genuinely think I KNOW ABSOLUTELY NOTHING

remote iris
sharp shuttle
vivid flower
remote iris
#

@vivid flower btw dms

sharp shuttle
vivid flower
remote iris
#

grapheneOS is cool

#

i need to put it on my pixel

sharp shuttle
#

but you wont

#

cause you lazy

remote iris
#

but i will

half lantern
#

So i did this interview, they had me do this fucking web app test for free, then write them an enterprise pen test report

vivid flower
#

Now i have a good ban evasion setup i can make a new profile ez if it happens again

half lantern
#

Then they invited me to interview

#

They started the one hour interview by grilling me

sharp shuttle
#

nice

#

why though

half lantern
#

they were like we will grill you on everything until you say IDK

sharp shuttle
#

imagine grilling over a web app pentest, did you apply to a place with amateurs

#

thats some real shitty behavior

half lantern
#

Yeah that was genuinely disgusting

#

no humour no nothing

#

it was a terrible experience

sharp shuttle
#

nobody who knows what they are doing would gatekeep over a web app pentest technical

#

if they thought you did poorly they wouldnt even entertain your application

half lantern
#

They were like trying to get me to change my mind that if they set their cookies to HTTPonly, to prevent session cookie stealing, that would prevent their stored XSS vuln from being exploitable

#

I was like BRUH

sharp shuttle
#

oh lord

#

consider it a bullet dodged

half lantern
#

XSS means arbitrary javascript execution

#

it does not mean cookie stealing

#

i just wrote that in there to show proof of impact

sharp shuttle
#

you should DM where you applied so i can ace their shitty technical and grill them

half lantern
#

Orro Grou

#

Group

#

Penetration Tester

#

they have a 2.8 rating on glassdoor

cerulean bloom
#

huh, I didn't get accepted to my AI competition

half lantern
#

then they were like you missed a CSRF vuln

sharp shuttle
#

i promise you, these people have no idea what the fuck they are doing

#

look at this offering page LOL

#

ganna check employees on linkedin

half lantern
#

chris kent

#

he is only oscp qualified

sharp shuttle
#

yeah their employees hardly know anybody in the industry

#

i have almost no mutuals with anybody

#

dont sweat it, they were amateurs

half lantern
#

A jobs a job, i need a job, I can't be picky, istg if I dont get through

sharp shuttle
#

i get it, but that is not how you do technicals

#

if they suck you give respectful feedback over email and move on

#

they must not be busy

half lantern
#

They had me do a free pen test and then they grilled me on my report, ok if it was dogshit why interview me

#

HOLY FUCK

#

i had it at 5pm

#

so maybe not

sharp shuttle
#

out of curiosity was everybody indian?

half lantern
#

no white as fuck

sharp shuttle
#

fascinating

heady sage
sharp shuttle
#

ah i see the issue

#

their pentesters are from deloitte

heady sage
#

Oh that makes sense

sharp shuttle
#

it makes perfect sense

half lantern
#

what does this mean

sharp shuttle
#

it means they are dumb as hell

heady sage
#

Deilotte is famous for having low quality employees

#

Like it’s their thing

sharp shuttle
#

yup

half lantern
#

Guys the point is

#

I felt dumber than them

sharp shuttle
#

they made you feel that way

#

you might be sure

heady sage
#

You shouldn’t

sharp shuttle
#

but they shouldnt make you feel that way

heady sage
#

You’re clearly more knowledgeable than they are

#

So don’t feel bad

sharp shuttle
#

well, thats also not the point vader

#

you dont gatekeep in a technical

#

its unprofessional

half lantern
#

i was like, ok is there a csrf vuln if i missed it and they said, "based on our conversation what do you think"

#

Bruh

#

BRUH

#

that is so impolite

sharp shuttle
#

they didnt even show you...

#

lmfao i cant

half lantern
#

I said, I tried testing it, but i didn't get a password change

sharp shuttle
#

let me tell you something iphish

#

okay

half lantern
#

yes

sharp shuttle
#

you know who my favorite hires have been?

#

people who get FUCKED the first time around and came back to spite us

#

i love that shit

#

consider this an opportunity

#

❤️

half lantern
#

to fuck them up?

sharp shuttle
#

no, prove them wrong

#

dont be malicious

half lantern
#

by? coming back?

sturdy thistle
#

Morning

sharp shuttle
#

yeah, then you surpass them

sturdy thistle
#

What did I miss

half lantern
#

their standard was, first 8 months, want to be oscp qualified

#

why grill me like im a senior then

#

HOLY SHIT BALLS

sharp shuttle
#

oscp is the new ceh

#

its not hard

half lantern
#

I feel like a total dumb c

half lantern
sharp shuttle
#

dont alright, just try to take something from this experience

#

its certianly rare

#

dont be discouraged

#

in fact you should feel motivated

remote iris
#

isnt CEH really ass

half lantern
#

i thought id like this style of interview. Make a report, then they will ask me about it

sharp shuttle
#

yes, its a multiple choice exam

half lantern
#

turns out

#

i prefer

#

question answer question answer

sharp shuttle
#

well most technicals dont require a report, just you to pentest live to a panel

half lantern
sharp shuttle
#

so that alone was kinda stupid

half lantern
#

CRT is also similar

#

if youre in the UK

#

well Ill know by friday

#

so atleast its quick

vivid flower
#

Apparenly the company im trying to get into requires a good report

#

So im trying to get better at that now

green kite
#

morning

half lantern
sharp shuttle
#

the first thing id do is automate report writing, ghostwriter is a great choice

half lantern
#

I need to study up how cookie stealing and all that works

vivid flower
#

Yeah! Learning ghostwriter rn

sharp shuttle
#

just, take my word for it

half lantern
sharp shuttle
#

if thats true, then yeah, keep your head up

half lantern
#

im ready to be kicked in the butt, I even told them that, I like it when im wrong

sharp shuttle
#

youll do fine in the industry

gaunt spear
#

yo

half lantern
#

youre a real g

#

please kick this user guys

gaunt spear
sharp shuttle
#

sure, i dont wanna see you give up because you had an interview with OSCP elitists

#

they are basically redditors

cerulean bloom
#

<@&861185840277487616>

green kite
#

that doesn't sound "educational"

gaunt spear
cerulean bloom
#

I think thats the right ping

half lantern
sharp shuttle
#

im sure he did

#

but hes a terrible mentor

gaunt spear
green kite
half lantern
#

Unkind and stiff, felt like im talking to trunchbull

sharp shuttle
#

being a good leader in cybersecurity is really important

green kite
#

morning brath

#

donut

tough oyster
#

hmmm

sharp shuttle
#

morning sparkling

scenic maple
#

why would you need a mentor tho

cerulean bloom
gaunt spear
half lantern
cerulean bloom
green kite
#

If you are being threatened, best to go to law enforcement

sharp shuttle
scenic maple
#

i can sure help people but mentoring is diff and fifficult

green kite
#

but yeah, your question did not make it look like you were being threatened but you wanted to RAT someone's pc

half lantern
sharp shuttle
#

being in a mod position is an opportunity to mentor

scenic maple
half lantern
sharp shuttle
#

my employees seem to like me

gaunt spear
#

isnt that what u guys do in this server

green kite
#

no

scenic maple
#

no bro

green kite
#

this is not a hacker for hire / we hack illegally

sharp shuttle
scenic maple
#

A white hat (or a white-hat hacker, a whitehat) is an ethical security hacker. Ethical hacking is a term meant to imply a broader category than just penetration testing. Under the owner's consent, white-hat hackers aim to identify any vulnerabilities or security issues the current system has. The white hat is contrasted with the black hat, a mal...

gaunt spear
scenic maple
#

he has cpts lmao

remote iris
half lantern
#

starting an interview with methodology is great, but then going into grilling every decision I made is holy fuck, frightening, it was a black box assessment, i could only assume what was happening in the backend

scenic maple
#

hmm he could be colorblind with cyan color

#

but i dont jusge

remote iris
cerulean bloom
green kite
scenic maple
#

come on dude atleast should have started with grey first 😩

green kite
#

I meant to add "server" after that

gaunt spear
sharp shuttle
cerulean bloom
sharp shuttle
scenic maple
#

we usually make money in a legal way
and they make money in a illegal way and often times they make less and end up in jail

remote iris
scenic maple
#

but top people of both fields make the same ish tho

meager kernel
#

Ahh

gaunt spear
#

quit replying g

remote iris
#

u want help g u get help by asking

#

im not your "g" bud

gaunt spear
#

ur a script kiddie though

half lantern
west lynxBOT
half lantern
cerulean bloom
scenic maple
#

why dont you read this to find out what hacking is all about

remote iris
half lantern
#

doesnt matter if he did active boxes or no

green kite
#

Look @gaunt spear if you're gonna be rude to people who've been here for al ong time, you might as well leave. No place for rude/toxic people

sturdy thistle
#

don't start to be a dick thanks

sharp shuttle
meager kernel
gaunt spear
#

u run me man

meager kernel
#

There's like a whole CPTS track in Labs

remote iris
half lantern
#

@meager kernel I was wrong, i had the worst int in my life

sharp shuttle
#

is joe, joey?

half lantern
meager kernel
sharp shuttle
#

oh okay, just making sure

sharp shuttle
#

i like joey alot, so it woulda been interesting if that was the case

half lantern
#

when i left the call

#

i collapsed

meager kernel
half lantern
meager kernel
#

You know how you can get back at them? Hack them. (Jk)

sharp shuttle
#

i have a meeting in the morning, goodnight/goodday yall

half lantern
#

I should do grc

meager kernel
meager kernel
half lantern
half lantern
heady sage
#

Anyone know how to go to sleep whenever you’re wound up

half lantern
#

so i can prove them wrong

#

i love toxic work places

meager kernel
half lantern
#

its where you grow

remote iris
cerulean bloom
sharp shuttle
green kite
remote iris
meager kernel
sharp shuttle
#

well i do it in mine, with a gun

#

but i get it

meager kernel
#

I have decided that I'll buy the Academy Gold Annual

#

For 495$

sharp shuttle
#

very nice, get a cert brother

cerulean bloom
#

thats sooo cheap

#

how

meager kernel
sharp shuttle
#

yep, use it wisely

meager kernel
#

Not 495

sharp shuttle
#

you also get cjsa

cerulean bloom
sharp shuttle
#

start there i guess

cerulean bloom
#

I was thinking of silver annual, but I don't need CJCA, so

meager kernel
# sharp shuttle yep, use it wisely

You were saying earlier in the chat that getting certs and pentesting like how people do in HTB is not worth it, cause vulns irl are often quite small.
Am I misunderstanding that Convo?

If that's the case, should I get certs?

sharp shuttle
#

INE security really fucked up by messing up eLearnSecurity

meager kernel
#

*not

sharp shuttle
#

there are too many

meager kernel
sharp shuttle
#

and HR is not a good reason to have a cert

cerulean bloom
#

don't catch certs like pokemon

meager kernel
sharp shuttle
#

HR is not part of the equation if you network

meager kernel
#

Yea

sharp shuttle
#

i promise.

meager kernel
cerulean bloom
sharp shuttle
#

perfect

meager kernel
sharp shuttle
cerulean bloom
rustic carbon
#

gg

cerulean bloom
#

thats ez

meager kernel
#

All through referrals

cerulean bloom
meager kernel
cerulean bloom
#

I have people willing to refer me

meager kernel
#

Feels like nepotism 😭

sharp shuttle
#

the world runs on it

meager kernel
sharp shuttle
#

as a hacker, you should LOVE nepotism

#

its an easy system to hack

meager kernel
#

I have an option of joining an Indian tech service company
Or a multinational SaaS company

I should pick the multinational one right? @sharp shuttle

half lantern
meager kernel
#

In both I'll have role of pentester

remote iris
#

i love SEing

sharp shuttle
remote iris
#

i did it to go to the bathroom in school, it's called LYING!

meager kernel
half lantern
remote iris
cerulean bloom
#

you really have family connections

#

I'm jealous

sharp shuttle
meager kernel
#

Most people in my family are either in tech or medical

#

So it's very easy to get connections

cerulean bloom
meager kernel
#

My sister in law's brother in law is the vice president in the multinational SaaS company, and he was a penetration tester too when he was young so he understands my field

naive coral
#

Morning

half lantern
#

The “we keep going until you say you don’t know” line

That line is not said to weak candidates.
It’s said when interviewers believe:
you can go further
they’re curious where the boundary is
they trust you not to bullshit
They are testing epistemic honesty, not knowledge volume.
One uncomfortable truth
Security interviews at higher levels feel impolite because:
reassurance hides signal
politeness reduces pressure
pressure reveals reasoning quality
They weren’t trying to be kind.
They were trying to be accurate.

Ok chat gpt is a wonderful cushiony best friend

meager kernel
#

Do you not switch off your PC?

naive coral
#

honestly didnt wanna do all the pivoting again

meager kernel
half lantern
#

aur mujhe bhi dilaade

meager kernel
half lantern
#

i'll move to india

meager kernel
remote iris
#

whats a good way to write writeups

meager kernel
#

Not worth it IMO

remote iris
#

like as in writing it what app

#

im tryna build a portfolio for myself

meager kernel
#

Australia is better than India by a million miles

half lantern
naive coral
meager kernel
half lantern
#

I feel like im a restarted toddler who knows nothing

remote iris
#

i just need to build stuff for myself

half lantern
#

i should go into grc

cerulean bloom
#

I need to work on writeups

remote iris
#

tryna get a github going so i can prove my worth aswell

naive coral
cerulean bloom
#

gotta write more writeups

remote iris
#

o really

meager kernel
remote iris
#

is obsidian that good?

naive coral
#

its in markdown + you can use templating to make ur life easier

half lantern
remote iris
#

i used microsoft onenote for my entire writeups for the exam prep

naive coral
#

I think Obsidian is that good, pretty sure a lot of people would agree

meager kernel
cerulean bloom
#

but here's my approach: I ONLY write walkthroughs for active machines (of course, I release them after they are retired)

remote iris
#

in case i lose my account

#

or smth

remote iris
remote iris
#

i will look into it

remote iris
#

yeah

#

looks clea

#

clean

#

i lost my writeup for the prolabs on dante and i raged and left the machine 😂

naive coral
#

haha

#

well im making one as we co

remote iris
#

onenote did not sync it

naive coral
#

im 6 flags in

remote iris
#

yeah thaats what i do

#

im 50% in it

#

i think

#

it's not even difficult to do

#

someone said to me it felt like OSCP

naive coral
#

can I ask you smth in dm? Dw i dont want a solution

remote iris
#

yeah sure

naive coral
#

Thats why I am doing this rn haha, OSCP exam is 18th january for me

remote iris
#

oooh

#

sure sure dm me

naive coral
#

Dante for prep atm and then Zephyr

#

perfect ty

remote iris
#

yeah i wanna do OSCP but i dont have 2k to spend for it

#

so i might aswell do CRTO

#

would be fun playing with C2

naive coral
#

My job is paying for all this thankfuklly

remote iris
#

yeah jobs pay 4 it

naive coral
#

i also convinced them to get me htb enterprise

#

they'll do it in new year

#

but i couldnt wait so i just bought dante myself yesterday

meager kernel
#

Well well well....
I was waiting for times like this

#

It was bound to happen

green kite
#

sticky situation

meager kernel
#

Honestly I'm not even sad this happened

green kite
#

imagine having reported a bug on h1 - that was now abused to breach

meager kernel
#

It was already waiting to happen

#

Lmao

#

It will definitely be used for blackmail, 100% sure

exotic pendant
#

😄

meager kernel
#

Hahaha if they just release the data on dark web, you can actually find info like that

exotic pendant
#

kidding

meager kernel
exotic pendant
#

😄

meager kernel
#

I don't think frost is kidding

#

@exotic pendant how much did you study HTB to get where you are

exotic pendant
#

HTB wasnt arround when i was learning

#

We had Hackthissite

muted olive
#

hello chat

#

oh I remember hackthissite

warped plank
cerulean bloom
muted olive
#

thought it was shady at first because of how retro it looked

muted olive
#

plus I found it by accident

#

when hunting on something else

meager kernel
#

You're caught

muted olive
#

I think it was on shodan, not sure

meager kernel
muted olive
#

bugs

meager kernel
#

Definitely not man

muted olive
#

There was even a page on Bugcrowd to report vulns

mystic harbor
#

I reached ur heart

meager kernel
muted olive
#

I'm not reporting anything there kek

#

not that I have found anything

meager kernel
#

Imagine having to explain that to your parents

muted olive
#

ikr

meager kernel
#

"no dad I wasn't watching any of that, just research stuff"

#

Yea even I wouldn't report that shit

muted olive
#

I bet I can think of most attack vectors there

#

click HERE for (redacted)

#

ez phishing

meager kernel
#

Definitely

meager kernel
hearty copper
#

hackthissite goated

exotic pendant
#

Dang one of the RCE didnt like but the others did

dusty gazelle
#

Reading - to make myself smarter

#

I have a iq of a pingpong ball when it comes to this stuff

proud moth
#

when i grow up i want to be like papa frosto

exotic pendant
#

I've shown i can pop calc.exe and other stuff lol

proud moth
#

bro popped a calculator 💀

dusty gazelle
#

Popped?

exotic pendant
#

I'll blog post this finding if he doesnt approve it

proud moth
dusty gazelle
#

Whats redteam again - sorry checked out your prof

#

Ngl scared me

#

🤣

exotic pendant
#

I need some pizza

green kite
dusty gazelle
#

I need a laptop

#

Because ig i like the linux coding (python 3)

cerulean bloom
dusty gazelle
#

Havent learned much yet

cerulean bloom
#

which I guess is linux python? idk

dusty gazelle
cerulean bloom
dusty gazelle
#

I got into this by accident by watching scammers get infected

dusty gazelle
#

I get so many scam emails

#

Its like bruh i see you

green kite
#

just remember, stealing from a thief is also stealing/illegal

exotic pendant
dusty gazelle
green kite
#

illegal

dusty gazelle
lime trout
green kite
#

Robin Hood was also a criminal

lime trout
#

2 wrongs don't make a right

dusty gazelle
lime trout
#

morally you can be wherever you want; but legally its still a crime

green kite
#

exactly

warped plank
#

Stealing everything from a thief doesn't make one less thief

dusty gazelle
#

Ngl i just thought this stuff was fun and wanted to learn but ngl

terse dirge
hearty copper
#

depends if you believe in moral objectivity or not

dusty gazelle
#

Sitting in a room full of you guys scares the fuck out of me

green kite
#

the law doesn't care about the morallity of things

warped plank
terse dirge
#

yo Emma, I had to install k3s again because k0s kept crashing its konnectivity agent and core-dns Kappa

dusty gazelle
lime trout
warped plank
dusty gazelle
lime trout
warped plank
#

but malware reversing & research is actually a really kewl field, you just have to learn C, Windows Internals, computing architecture and maybe some assembly

lime trout
#

if you use them as part of an engagement you have permission for its fine

#

but if you use them to do crimes its not

dusty gazelle
#

They explained that

warped plank
dusty gazelle
#

And it was a duck

agile bluff
dusty gazelle
#

Virus but

warped plank
dusty gazelle
#

Entertaining

terse dirge
warped plank
dusty gazelle
warped plank
#

*ehem* PhantomRaven *ehem*

dusty gazelle
#

¿

terse dirge
dusty gazelle
#

It was pre 2010

dusty gazelle
#

After 2010 i havent seen anything tbh

warped plank
#

well not exactly injecting into memory straight away but uses a post-compile script to fetch and inject malware into binaries

exotic pendant
#

Frosto fighting with the triagers

warped plank
terse dirge
#

the KongTuke ones I was looking at were a bunch of heavily obfuscated powershell scripts that run a bunch of others in memory. I was always a bit too slow to get the third script in the infection chain because it'd get taken down or move

exotic pendant
hearty copper
exotic pendant
#

on Riot

terse dirge
warped plank
dusty gazelle
#

Actually i lied

#

My ex got hit with a 3rd party cookie attack?

#

Whatever thats called

terse dirge
#

l33t soc alerts

warped plank
dusty gazelle
#

Triage?

exotic pendant
warped plank
terse dirge
# terse dirge l33t soc alerts

I get alerts and stuff every 20 minutes from the n8n script and I'm storing the IPs from the alerts in redis to do more research on them 😄

exotic pendant
#

SkeletonDance it';s 2 am

cerulean bloom
warped plank
# dusty gazelle Triage?

According to whatever AI google feeds me nowadays:

Bug bounty triage is like being a
doctor in a special bug hospital. When someone finds a "bug" (a security problem) in a company's website or app, they send a report to this hospital.
The job of the triage doctor (the "triager") is to check out the bug report and decide how sick the bug is and what to do about it

cerulean bloom
#

stay up more kek /j

exotic pendant
#

I'll just make a blog post of the Riot finding

nimble parcel
#

What is the Channel for HTB academy support?

west lynxBOT
cerulean bloom
warped plank
green kite
#

If you need help witha module #modules - if you really need support , visit the link above

cerulean bloom
#

btw, I have a quick question

cerulean bloom
#

one sec

warped plank
#

HURRY UP kek

dusty gazelle
#

My brain

cerulean bloom
#

anyway

warped plank
dusty gazelle
#

Sometimes i feel like i need a old crtv to lick the screen and maybe thatll help me

cerulean bloom
#

for CVEs, does it HAVE to be connected to your full legal name if you found it?

warped plank
exotic pendant
#

I have some under frost

warped plank
#

heck pretty sure you can even just be anonymous

exotic pendant
#

you can even put CVEs under other peoples name

#

Like Frostb1te

warped plank
#

iirc just do all Active Easy boxes and you should get to hacker rank

exotic pendant
#

plz gib

cerulean bloom
#

there must be some sort of proof

warped plank
warped plank
#

CVEs are just records of vulnerabilities, either you take the credit or dont

cerulean bloom
exotic pendant
dusty gazelle
#

I mean if they pay i would xD

cerulean bloom
supple plume
#

Wsp turboheckers

cerulean bloom
#

so if I put DonutMaster
I guess they have to say it was me

warped plank
#

I think some platforms do provide a letter of authenticity or something idk

exotic pendant
#

yes if you put donutmaster

#

donutmaster is on it

supple plume
cerulean bloom
muted olive
warped plank
meager kernel
#

@exotic pendant adopt me

supple plume
exotic pendant
supple plume
#

DonutMaster is dope already

muted olive
#

might get something good though

cerulean bloom
#

would a company be embarrassed cuz "DonutMaster" found a big vuln on there company kek

muted olive
#

few CVEs

warped plank
exotic pendant
#

I might take a break from bug hunting

terse dirge
#

bruh there's no interesting malwares on malware bazaar sadge_business

exotic pendant
#

after this riot one

muted olive
#

perhaps money

muted olive
#

gotta study

meager kernel
warped plank
#

HUNTING TAKES LONGER

exotic pendant
cerulean bloom
exotic pendant
#

CVE-2024-11233

muted olive
exotic pendant
warped plank
dusty gazelle
terse dirge
#

too much mirai malware

warped plank
exotic pendant
warped plank
dusty gazelle
muted olive
#

you can zero in on vulns quickly, or vuln code patterns. validating is the hard part

#

and testing

meager kernel
dusty gazelle
#

Ooo

cerulean bloom
dusty gazelle
#

I cant wait to get home and code

#

Or learn i mean

warped plank
cerulean bloom
#

it can be from $0 to $500,000

cerulean bloom
ornate ibex
#

Heloooo

dusty gazelle
#

Id be happy with enough for a snack