#general
1 messages · Page 298 of 1
😄
@exotic pendant do you get an email confirmation for a CVE?
General Tsos chicken ugghhh
or anything like that ?
depends on vendor
I might code some project for myself
The ones I submitted to Mitre yeah. The other tims the vendor submitted for me and they also had let me know
Let's see if I get time
I am going to ask microsoft and nvidia for CVEs though
I see, I see
so those emails could be kinda confirmation
Words
Check with the vendor to see if they have a program/vdp first
they can submit it ezpz
Still waiting on a reply from MITRE 
for what 👀
I just wanna work from home ngl
That's what I say
is joke, I had one before but it was dupe
Ngl i think the most iconic was the cupholder code
Or whatever made your disc drive pop back then
yeah they take forever to process submissions
ezpz
I have time, luckily
hunting for driver bugs is like going shopping without knowing what to buy
next year, I'm grinding for CPTS
or trying to choose from 50 different ice cream flavors
I'd like Tier III module access, but idk if my dad will have the money for it
I'll prob force myself to play video games
then next year make $1m
in bugbounty
All of them obvi
use your bounty money to travel
nahhhhh
use your bounty money to invest in a 401K 
I feel like bughunting you dont need to work as much?
no
I already put in a lot
its not a stable income for most
No as in?
most bug hunters dont make any money
its very hard to find vulnerabilities
Oooooo okay
Frostb1te is just 500 steps ahead
go to iceland
Again apologies if i sound dumb
no need to apologize 🙂
Antartica
I'll goto flavor town
Frostb1te is so far ahead in the bug bounty scene, what you do manually he probably has an automation for
You can automate it?
he runs on pizza
Anything you can do on a computer can be automated
I actually hardly use automation
i just hand jam it all
@sharp shuttle what do you mean by gatekeeping
I give up i keep learning more and more
Can someone clarify
huh? heh? hah?
meanwhile I'm out here learning to automate web exploitation in Rust cos apparently I'm a massochist
Heh?
figured out half my errors were caused by sending requests through a proxy cos I wanted to look at em 

I've searched about it in the specific cateries, but I didn't found nothing. Someone know if the Dante lab have been changed in the last months? I'm trying different things that I've already doed in past, but they are not working and the services exposed on some host are not runnin anymore
I literally just commented the line that put the client in a proxy and it worked 100% of the time without dropping requests
lol
figured out how to make it reliable through proxies though, thank god
Worried
if you're writing exploits and malware then yes, yeet everything on a virtual machine
Yea but would it be safer on my pc or a laptop?
actually even if you're just developing normally yeet it on a virtual machine, these days supply chain attacks are rampant
doesn't matter if it's in a VM
Supply chain attacks?
no
use VM
depends on what youre doing though
who's joe
They got her through cookies/link
bro's ex getting hid with every virus
not exactly a supply chain attack
She pissed off a writing community all ik
supply chain attacks more so target developers of applications through the packages they use
Sorry i mustve misread
I don't think they know to even show that....
In a supply chain attack, an attacker might target a cybersecurity vendor and add malicious code (or ‘malware’) to their software, which is then sent out in a system update to that vendor’s clients.
Guys, to take CPTS. should I take the "penetration tester" job role path?
just to make sure it is the right path.
for example:
- Hacker hacks discord developer,
- hacker changes discord code and pushes an update,
- hacker now controls anyone who uses discord.
yep
Thank you 🌹
:(
It was under the browser based attacks a lil bit down
I wanna take part of the CJCA learning path as well just so that I learn stuff many I didn't know in the basic stuff
🤔 okay again i apologize im a sponge
That section just mentions that a lot of websites depend on other people's software, if that software gets compromised it affects all those websites
Thats the simplest explanation for such a definition. Thanks.
I have 3 hrs of work then training yayyyy
Gotcha okay that makes sense
For context i take care of the mentally ill
90% of the job is chilling
So i needed some reading lmao
oooooo, thats nice
time to learn ethical hacking 
Literally
you know, just learn ethical hacking, chill, have some rest time, perfect
There are some free books out there like Bug Bounty Bootcamp or The Hacker Playbook
unfortunately my work doesn't have that kind of chill time 🥲
Even if I rest for a couple mins my manager finds something for me to do 
Tysm for these
This dude will do anything but seasonal boxes

I dont want to go through the pain and struggle of starting an HTB box and not being able to stop till it gets rooted 
I'll have time for that after exams are done
so for now.. hack drivers
ez
bro at least you don't have to write the automation for it, we have several different versions for it 
is bery interesting trust, wouldn't recommend doing the automation the way I did it though, just use opcode's one 😅
I know, you'd probably use rust 
it works ok...
still cursed
100% agree
anyway chat
but it's completely memory safe 
-# useless in an exploit cos I will never have to run this again
does anyone want to see how layer 3 of the OSI model looks under the hood
its fascinating
as in with 5000 different components so its impossible to read
but still fascinating
Why is cybersec so rare in my country?
And why is it so underpaid 😭😭😭😭
Software engineers are earning so much
isn't it just encapsulated 2nd layer with a bunch of layer 3 information?
because software engineering is valued a lot more
india is the land of software engineers
have you checked: The defensive side? 
idk why though
@muted olive when you get an internship, get a remote one
Preferably in a company which appreciates cybersec ESPECIALLY where pentesters are appreciated
as a software engineer thinking about moving into appsec, way more fun
nah cysec jobs in general are rare
Most of them are mediocre
oh definitely lol
Fuck no
damn, crazy
it's still cybersec, arguably the more important side
well.. at least they contribute to the coding landscape 😛
thats one thing im happy about
Pentesting just as important
heck not arguably, it just is the more important side
Pentesting wouldn't exist if it weren't for the defenders there to patch the holes
If you don't have pentesters, no one would point out mistakes of defensive side
but you can still defend without pentesters
It wouldn't be called "pentesting"
It would just straight up be hacking
look at it this way
it'd be much more risky cos you'll be patching live but it's still defending 
you need both the sun and the moon
cant have only either
I like both though ngl
im better at offensive but wouldnt mind learning defensive for a while
later on
im just wondering why pentesters in india are paid like shit
I honestly prefer offensive, but I concede that defensive is the more important and more in-demand of the two
the salary is so fucking low
because no one cares about security
It's India, the salary was gonna be low anyway 
being able to code it properly in itself is an achievement
imagine building a wonderful house but forgetting the door locks
software engineering gets paid a lot
true
that's why pentesters are paid so low... cos a person on the side walk can open the door cos it has no locks
oh one more thing, BECAUSE cybersec is paid so low, the cybersec infrastructure of india is also very shit
govt websites get hit many times
yeah govt websites are pretty bad
y'all need a massive cyberattack to push efforts in the right direction...
we need a new government
man i wish i get a good company
to work in
I like the government here, I don't notice them, which means they doing their job pretty well.
im willing work till death as a pentester, as long as the company pays me well and appreciates me effort
you know just make a competition to have Gen Z refactor the entire govt codebase
that way itll be better
no vulns
or rather lesser vulns
better design
which new policy?
i havent seen
vibe code it
I meant itll be good if they have one
Ohh look another supply chain attack brewing 
@lime trout is HTB recognised by companies like Cisco?
introducing more vulns 
more opportunity for pentesters
you can still try to hack govt websites btw
less catually if it's also vulnerable enough for script kiddies to attack
I know someone who hacked modi's website, and got commended for it
pretty sure they dont have a VDP
I think it was a critical
Did they scream about it on the news?
they must have a note somewhere
i think
nah
even if its not a formal vdp
like a security.txt somewhere
or a number to report anything
even if its not explicitly a vuln its a general contact number
my neighbour works for govt in cybersec division, he said i can report vulns to him if i ever find one
might give it a try, who knows
hey thats good then
certainly not hard finding a vuln
reporting is tricky but theyll appreciate it all the same
definitely not
ill just give my neighbor uncle a call
tell him i found something
show it to him at his house
and he'll make 1-2 calls and done
there is actually a competition where you hack a custom OS, govt run @meager kernel
the winners get commended by the chief of army staff
I would love to do that one day
that too its an in person thing
i reported a malicious app to him i found somewhere
that app was displaying people's information when you input their phone numbers
basically a leak database sort of thing
he made a call and reported it

i was commended for it
yeah PSIRT is actually very quick at responding
at this point bro ain't gonna sleep 
or CERT-IN or whatever
just that their security isnt great
which is ironic
I think its more focused on actual cybercrime
than vulns
ill talk to my neighbor
if i get official permission soon, ill try hitting few govt websites
I’ve been up since 1am
they stop the person after the crime is done lmao

@exotic pendant ever found a vuln in govt website?
idk about how they handle cybercrimes and stuff
hundreds iirc 
i could tell you a cybercrime story about a college friend of mine
but hes in this server too
and if he sees it, he wont appreciate it
dm? 👀
Plenty
did they appreciate it?
NASA gives you letters
CISA gave rewards but it was because I’ve submitted over 300
yea NASA would appreciate
other ones idk
what the fuck
dutch govt? that tshirt
and that trophy from tax admin?
CISA is us gov
no I mean did you try dutch gov
that is hilarious
@exotic pendant
MOD the uk gov gives a coin
will try that
@exotic pendant p sure I found a vuln in an old Intel RAID driver, but apparently vbox and my host both use standard AHCI SATA driver for that, so I cant force load it to test at all

try on host
different driver again
cant load it
plus itll corrupt memory on host
buy new PC?
The mod coin I had an RCE
And the tax auth trophy I did my own 0day for an app they use

I do but honestly I do a lot of testing on my host lmao
download a VM on new PC
is it not unsafe
how do you debug kernel then
Kernel is in vm
ah
Hyper v with windbg over com
For like my riot bug I just test on my pc
VMware gave too many issues
you dont use VMware or Vbox?
I thought of installing league of legends to hunt bugs on it, but the installation alone is like 25 gb
Hyper v and windbg works like butter
VMware
Hyper v just for kernel debugging
for serial port connection?
is VMware better than Hyper V or vice versa?
Yeah the VMware drivers hate windbg
lol then im not using vmware
Caused too many unnecessary crashes
I like VMware because vm tools is superior
Hyper v only if using windbg
Hyper v is just enhanced RDP instead of vmtools
Maybe I’ll beat kingdom hearts
Haven’t played in years
Frosto too bored, need new things to do
play league of legends
Her mom didn’t want the name pepperoni

So we settled on the league name
you can still call her your little pepperoni
Smash Karts is a free io Multiplayer Kart Battle Arena game. Drive fast. Fire rockets. Make big explosions.
ez game, you just smash karts
i would actually call my son Boy! and then Atraeus when he's old
and if i have a daughter, she would be called Calliope
Frost whats your favourite game of all time
game of thrones ❎
game of bugs ✅
Almost got a KH tattoo in middle school
i need to earn some money so i can buy video games
Get a sugar mommy
When you know he is the one who found the veigo anivia bug on veigo release but you can't prove it
They need to make more than me tho
To find one who does would be hard

lemme guess what you make
you know youre getting old when you have lots of video games to play but no motivation or time to play any
~250k
$10
ig it's more about having more freedom as an adult to play any game you want
if I had to guess id say your senior RTO job pays around 180k and the 250k is with your bounty money included
3 things
Money
Time
Energy
so the list of games that actually interest you is narrowed down
You only get 2
real
💔
I have energy
im 19 and im still out of energy to play games
no time or money
Wait until you’re my age
I thought you were like 22 or something
30 is rough I can’t imagine 40
uhhh. honestly yes 
yeah you have a kratos pfp
fair
i guess the kratos pfp is part of why
I have Kratos's beard, now I just need the physique
no, lots of hair, Im Sikh
hence, the beard
ohh. yeah right
still best game
Provided to YouTube by DistroKid
hold me · Pearlblade · pearlblade · pearlblade
hold me
℗ chaoscore records
Released on: 2025-02-13
Auto-generated by YouTube.
disney characters
It’s all Disney universe shoved into final fantasy
@exotic pendant go to disneyland. no more boredom 
infact go every week or something
to some theme park
I love theme parks

I’m teaching my kid how to cook
lots of theme parks
I’ve been to Dubai
pizza?
Like 12 times
o
any yakuza players ? : - )
go to china
She made French toast
yum
4yo here can make her own pancakes
nice
meanwhile: I cant make anything 
ive never cooked anything in my life
except myself
new gen
my dudes. I have an issue with my openvpn. I have delted the files from my downloads, but for some reason I am still connected on HTB.
very annoying
kill the process
sudo killall -9 ovpn
I have also killed the process I will try again 2secs might have done it wrong
says openvpn no process found
Yummy
I also dont have a tun0 interface running
can you see your tun0 in ifconfig? because sometimes the HTB interface claism you are still connected, but you are not
no tun0
I agree but I am trying to play around with the Convertor machine, but my connection does not work to it.
so tried to re-download a VPN connection then notied it said im connected to both starting point and labs
VPN issues? Slow connections? Can't reach machines? Start here!
did you download the right VPN file? ie. for the labs and not starting point
as they have separate files
this is doing me a hecking STRESS. Yeah downloaded the correct vpn file
jus dont know why it says im connected when I am not
if the issue persists, reach out to support 🙂
Need to speak to a person? Learn how to reach our support via HTB Labs.
thank you!!!!
good luck and let us know 🙂
reboot?
I do indeed and I have rebooted twice
and error when launching sudo openvpn file
no errors runs well
frost doing support
I'm heading to the gym 😄
Nice
ParrotOS decided to shit itself for me. RIP 
Kali > D:
hello
Come to arch
Hi
bruh is promoting arch again 😂
I’d die
You would reborn and grow wings
you would lose all aspects of a social life if you use arch
It’s weird, it worked before I changed brightness and poof
I could try to help if you want
Also
Fancy some chess?
I’ll figure it out
Later
It’s weird it works in recovery mode if I do stuff but when I stop poof
get out my way i am here to flex my card
i got mega blastoise ex
lets facking goooo
:evilcat:
Are you guys know about a free article website cause medium so expensive 😔
so ur here for a little bit longer today wow
i keep tracking ya

only ur messages ( im not a creep)
i see some people rarely

😂
Greetings
@unborn estuary i thought u were someone i know i shared there country code and last two digits
and he unfriended me

i sent u the country code and the last two digits here do u remember?
it was kind of same so
the name
nvm its fine tho
yea delete
he will block me
🤣
if he sees this again
💀
🙏
+977
I might climb Everest soon
yea nvm sorry bruv
Nigesh

i will show u the beauties of nepal
Golam is intrested
im not talking about ladies.
im talking about the natural beauties
the nature
I didn't talk about ladies
No no no
@lofty warren
gal
@cerulean bloom
yes, gal, not guy
girl
wut
women
Wut
you pinged me
Wrong emoji
Outside
alright
same

Vro
not a joke man. pickle rick i did its so easy and that agent sudo also
why are you represting those trash cans here
dont joke around
stop trolling 
no lol
u can
Vro coaching classes
hello frosto u said after gym you will accept my friend request
I am still at the gym
bro attacking network entrprise aint picklerick

Gotta workout hard to eat this pizza
The riot battle makes me need to fuel up
Got RCE on riot and it got some kick back buttttt my other rces got approved

Bro cooked riot steam rog damn

broo ,
no hints, no nothin?
Did someone say donut?
ok then fair
I'm about to go buy some of those
i did nudge
so u can say anything
@spare tulip nice i have a factory of mine i can send u
my dads
factory
I'll take it. Is it same day delivery?
It's a donut

im from nepal depends where u live
East coast USA
I love mommi
im from nepal
mb
you can use
bro it donesnt look sarcasm
/cheater
the nerd emoji
Golam We going to see Nepal baddie
but if it has images and stuff u could dm me
where they at
without the mountains nepal is mid honestly
no hate tho
facts
u can call me golam btw
Ask @neon zealot
most nepalis dont look like that
i mean she has 20kg of makeup
Golam down to earth 😂
and prob bleached before
it is what it is
bro u tweaking , mid ? wdym
Bleached what

thanks dear
AYO
okay ur tweaking
that is my opinion yes
i generally recommend people to not come to this subcontinent in geenral
give me nitro
nothing personal
bro it is personal
cool country
some of their architecture is not seen anywhere else
I don't have Nitro
😩
ayo
ok this is getting political
maybe i am chinese you neevr know
you would not understand the gif
but i am always closer to yalls heart
nor delete it lol
lulz
Brother gets CWES one time and feels invincible
let me come over @unborn estuary
sa7a
cant you only get it once bozo
Does it expire, bozo
Yikes
XI JIN PING
hostias
@scenic maple PIIIIIIINGGGGG
Hahah
Hello! i am new here
does anyone know how to link their hack the box account to lets defend. Is it possible if I don't have a lets defend account? Also, does that mean we need a lets defend subscription now, in addition to HTB subscription?
I thought we were all getting more Chinese this year
Did anyone else play the game called Hacknet? 😄
😄
😄
😄
did i start some bot sequence or something lol
nah, you ruined it
IT’S OLIVE OIL
@austere sinew I can't keep up with daily pings anymore 
@cerulean bloom GIVE UP THEN BROTHER
our tradition...........

This image is missing bateman and joker
IT SHALL ALWAYS REMAIN IN OUR HEARTS
i guess yall could join a server and add a bot

🫂 🫂
NOT THE SAME
NOT THE SAME DAMMIT
@austere sinew ello
@austere sinew ping pong
Go to sleep
Ik Brodie I’m being facetious
Yoo
yoooo
How are we?
good, good
awwww, doing better now
Ehh
thats the only cat doakes gif
golam is a cat so yeah
Golam is a cat hmmmmmm

ya seriously
weird question
i think thats what he was trying
I am doing some SQL practice for college homework around 4 pm est today . Is anyone available to help at that time ?
Html, css and js
@scenic maple 🔥
which is webgl right 
check this out he updated his portfolio https://bruno-simon.com/
for best performance you would need webgpu tho

Actually this stuff is very well paid.... if you sell it to the client directly
i want to be rich but i dont want to scam people or sell courses
but idk how to
maybe i will figure it out along the way
Hahah
Yeah
but still i have made a vow no selling courses
But remote work is not bad if you get a good company to hire you
for me its good enough
i cant even work remote for the jobs that are in my country
i wish it was possible
It's hard to get a good remote job
i have to work out of my place
Even with experience
altho i kinda disagree on that cause in some countries any job in home country would be better than outer ones
i guess if u know people
i am starting to think i should post cool shit on twitter
Hahahahha
who is nigesh
Me
He invented the terms
it would be very difficult for someone who hasnt been to this chat to understand whats going on
It means nice person from a country where you can't get a decent wage
Yes
We speak in code 
dang tf
we are all nigesh
@native plume you are nigesh
😭 😭 😭
but hacking is illegal
Could be
true
nigesh
Hahaha
You're late for that convo
vro
He is the original one
okay then I leave
too late
@mystic harbor 
u aint ready for what i am going to do next either
Find the full, uncensored versions of my essays and more at: https://horses.land/
IG: https://www.instagram.com/horses.ig/
music:
Beyond Words - Many Moons Ago
La Vuelta a Lerida - Vendla
It Goes On - Peace Reels
Torn Apart - Infinity Ripple
Synethesia (Scaled Down Version) - Peter Sandberg
Photography: Lisa Fotios, Skylar Kang, Inga Selivers...

This only proves you to be a lier
yes you are in a hacking server
Hackernaan
who could have guessed
I just own a overpriced pc that's all

you could sell that ram and be gold man of india
If u break the walls they have paper
actually the walls are made of
Hahah
Maklubah pizza
how bro looks like
Dollar bills?
Burnt rice
Wait is it burnt or burned

with or without the gold?
I am broke man
It's both, some of these verbs/adjectives now are accepted both ways
i mean in all honesty without the gold u will be naked cause thats all you wear
bro be like
do you have gold?
Not Xerxes 💀
hello chat

I have silver for killing monsters
he is the persian version of gold man of india

@ornate ibex this man has 5kg of gold can we transfer your title to him? as gold man of india?
why tf u act broke lmao

I am poor 
WHERE DO YOU HAVE THE GOLDEN NUGGETS
IN the 🍑
real gold men are in UAE
Its crazy there
land is one of the best ways of having wealth
average shops in dubai are like this
Average dubai sheikh be driving a bugatti
I drove around in Teslas there lol
@scenic maple Land can always be taken away from you by your government
they are taxis btw*
We have tesla taxies in jordan here
vro city land prices costs are so high like for 20x50 also u gotta pay 1.5cr
just for land
😔
house later
then spend a few millions searching the sea
then after few years hackerman unlock them
get poor quick scheme
Real storage of wealth is something that is high in demand regardless of current state of the world, and it needs to be in a size small enough that you personally can handle it easily, it also needs preferable to be stored physically in a location that only you could possibly know about.
Ik that
The orange site
I own it
costs you money to buy land, costs you money to buy a house, ROI from renting will be due in 20 years
and then you start profiting slowly
haha
Valid
double buzziness
both reacted at same time 
nigesh
did bro just buy css with real money?
Oml
ez spend
in other news
im bug hunting with qwen
which may be questionable but in some ways its better
ez 
yes do it
china number 1
Lets not pretend that any of us in here has any wealth worth storing tho.... xD







@cerulean bloom




