#general
1 messages · Page 307 of 1
machines seemed a bit boring so yeah... i tried the prolabs
2 were free
so i just picked the one which sounded good 💀
That's nice methodology
lmao
Better than my "Start this box and hopes it won't skill-issue me into an early death" methodology
lol
@static pasture did you see the new splitgate update?
There's a few ways of purchasing the CPTS path + voucher right?
😄
how's your friday been frost?
nice
not really
i certainly prefer candidates who have used hack the box, but rank means nothing to me
id be more impressed if you could talk about your experiences on hack the box, ie did an insane machine and learned x that was relevant to the position
Its just a cherry on top thing
if i get 2 resumes the exact same info but one has an extra "HTB"
then atleast it'll put a step forwards
it won't make or break the ice cream
I don't think my HTB rank made much of a difference tbh
I do think my networking/writing/CTF's/volunteer work may have helped, but yea - Never had anyone ask me what my rank was in an interview.
not yet amirigght
My old boss liked my write-ups
I mean they did ask me about it, but not rank - it was more process, how I viewed things like you mentioned. How do I solve problems basically.
I use academy way more atm anyway -.-
is there an official cert physical for the active directory one?
CAPE
The HTB Certified Active Directory Pentesting Expert (HTB CAPE) certification evaluates the candidates’ knowledge of the following:
Advanced Active Directory Enumeration
Advanced Active Directory Attacks
Abusing AD Protocols
Abusing AD Trusts
Abusing AD Misconfigurations
Abusing Common Active Directory Components
Command and Control (C2) Operations
Windows Evasion
Pivoting & Lateral Movement
Advanced Post-exploitation Tactics
lowkey seems fun
holy moly gamers
we're cooking with beef tallow now
it's coming together quite well
Got some sprite and gonna have the rest of that watermelon liquor with it 😄
After some pizza
not yet
oh ok
soon™
how much is the entire thing
that sounds almost cloyingly sweet

@terse dirge I just bought 1 powerball ticket. buying you 3 dinners if i win.
3 dinners!
okay now my eyes hurt like crazy
I've been ricing this literally all day
but I'm really happy with how it's turned out so far. still need to tweak my swaylock config, try to get GDK customization to work, make all waybar modules open up as floating windows instead of static ones, and then I think that'll pretty much be it, but I think I need to be done today
I'm loving my terminal rn though
a little embarassing for how long it took me to get my Wi-Fi working, but now it work
forgetting to install networkmanager in a manual arch install is a canon event for all
hello'
Yeahhhhhh
I can’t get the GUI to work rn though I have to use the TUI if I want an interactive session
I’ll get it to work tomorrow probably but I’m fried
I don't wanna sound like a conspiracy theorist but I'm just learning about intel management engine and it's wild
@sharp shuttle
No need to feel like a conspiracy theorist friend
It is Infact very very weird
idk the rules so I don't wanna get ban for saying the wrong things I really like HTB
well seems like everyone is doing the same thing tho
Brath loves talking about this
amd and ios too
I do too on my laptop
And a ultra 9
was thinking about getting one for my desktop computer
because of shortage of ram I wanted to keep using my ddr4
but yeah with all the politics involve around intel and now I'm learning about this idk what to think about
Don’t stress
You’re never not gonna be spied on
Someone always wants more info on you to better profile you and make more accurate decisions on how to make money off you
So just accept it and move on
Is what it is
its a hardware weapon, that works in tandem with windows, a cyber weapon, yeah.
is it theoretically possible to remove it ?
need i remind you that the xbox kinect had dhs hardware in them?
There are people scraping these chats and throwing them into LLM'S
you can get a old 2 line lenovo laptop that uses a celeron and effectively disable the me's ability to spy, but thats it
It’s the curse of being online
Poison the data
You can try but why waste your efforts
With pictures of Saddam Hussein
stop worrying about being spied on, its so much worse now than just computer hardware lol, just have duality of identity, easy
You could just learn how to be less appealing to those people and organizations, be better at saying no and automating the removal of all advertisements and spam
you are in the system, embrace it,
But even that’s over kill and another waste of time
If they already know about me then so what
They chose to look into my private life. Sucks to suck if they saw something they didn’t like
What’s up goober
wym have duality identity
use tech as you would normally, do all your private shit away from that. Be both public and private.
so you can't do private stuff on tech ?
not really.
Your system cant be on the "grid"
if wifi signals touch you, you are on the grid
even if your chip is off
"off"
You need help
I can help you
really need help fellas
take a fat rip off a fum
calm...
I took a fat rip off something I’ll tell you what
oh yeah?

Me
Yall
That’s how it’s going rn if ya catch my drift
Well C1oud might also be where I’m at but idk I haven’t seen him
@sharp shuttle ever heard of system76 ?
Brother what 👁️👄👁️
their laptops are fire tbh
Are they actually
they look super cool
I was looking at em
ya
one of the greatest tv shows ever made
how come it's playing safe ?
just as a warning, the cooling isn't the best so don't do any gaming or super intensive tasks
It’s like the Toyota of laptops
yeah of course it's a laptop
no but come on bro give more thoughts than just that
I mean like, I would even advise against running hashcat 
Dude it’s a Lenovo, it’s literally ol reliable
ol ?
I mean lenovo nowadays are getting worse and worse
soldered ram
Yeah like the shortening of old
That’s why I didn’t get the slim one
of course if you get a t480 then you good
Good thing I though about all that huh
I mean idk what's the higest cpu you can have with a t480
I agree
I have a new gen
well if you have a new gen how is this reliable
when your ram is soldered
if you have an issue you can't fix it
It’s notsoldered but okay
my english is not that good to understand that word
I mean no one told me that I just looked at new gen thinkpad
and all the one I saw had soldered ram
I looked it up and it’s not true
my mistake then
Lol
holy blast from the past
You either buy a subscription or cubes
i think you can win cubes sometimes in seasonal stuff, but i am not sure
i have student sub rn
but i'd love to keep my offensive security on the AD side
right now there's a 25% off deal for the annual plans
can people gift cubes?
Idk, I had the same question
no
🙁
Yeaa you can get cubes as reward in htb season
could also probably get hired by htb, then it'd be cheap for you
LOL
well 700 is nuts...
im gonna get CRTO then
it's still cheaper than most other industry certs ¯_(ツ)_/¯
also i generally don't recommend buying the cubes outright
yeah
you straight up scam yourself that way
whats the best way to even get it then
cause CRTO is teaching the same stuff for 400usd
Plat monthly is best if you can't spring for the annual
ah
but is the cert itself included in that $400 😉
deadass???
so u get exam attempt included too?
oh 😔
i'm just saying usually those cheaper prices don't include a cert
CRTO it is.... maybe next time when they release the physical copy i'll do CAPE
or you have to sell your firstborn to afford it
Jesus I can’t seem to improve no matter what I do
What should I do now
I can’t improve no matter how much I study no matter how much I try
What’s your fucking problem?
I mean, you are already a lot better 😭
Then most of us here
i luv my life
Good Morning folks
Guys im now starting the htb starting point please teach me some stuff to upgrade myself
Good Morning!
Do crto with me and skidzz
Right now im learning ghostwriter and mythic integrations
Thats the direction you can level up in
The edr evasion stuff is icing on the cake
How do you need help?
like where can i start bro
crto?
Red team ops
hey. i did it
Cool stuff
let's talk here #starting-point
but the old scenario exam, not newest
Study new things 
I sleep now
Wasn't aware it had changed
FINNALLLLY After an hour of trying to get this damn program to work to save my Skyrim save from bad scripts.... my save is saved.
TLDR, I use Fedora BTW. Couldn't install Java in bottles, Tried adding it in env variable in bottles, I had to run the, what I thought was just an .exe but it's a .jar in my console and save my save
Holy crap I need a beer
mornin' Tejas
Do you know a c2 or ghostwriter? @remote iris
Its not part of the crto requirements but it seems to be something one ought to learn as a red teamer
Either mythic or sliver
i dont
i wanna learn about c2
i know what it is and it's purpose
but never used one
Learn mythic and ghostwriter with me
im down
Ive been setting it up on braths suggestion
So mythic sends usage logs to ghostwriter to generate reports
Cobalt strike does this too and crto is all cobalt strike
Would people be interested in a crto study group or something
For those of us on the struggle bus
hi
guys i have one questions
hi guys
my just a simple question that Computer Networking A Top-Down Approach
EIGHTH EDITION
James F. Kurose • Keith W. Ross
IS THIS BOOK GOOD
FOR BEGINNERS
u livin' at US?
Gemini capping as usual
ans my question hi guys
my just a simple question that Computer Networking A Top-Down Approach
EIGHTH EDITION
James F. Kurose • Keith W. Ross
IS THIS BOOK GOOD
FOR BEGINNERS
does it have good reviews?
I just completed the first ctf in the university challenge
took most of the day, was not "very easy"
great job
😮

First you would need to find the cable
I guess it is in a predictable location though
This could be like that competitive kite game in India
Tabula Rasa
your grandfather was a coward then
drones are just drivable artillery shells
Assuming your grandfather fought in a world war, he likely used artillery or ordinance to kill
its akin to calling a drone operator a coward
50-66% of all casulaties were from fragmentation artillery
just that one weapon
its the same with drones
Ah yes, the modern goon cave, very different from the one from WW2
what is this supposed to illustate ?
its the same thing
firing from protected positions
warfare only changed in the technology, the strategem is unchanged
defending?...
im a drone operator.
yes, my father operated quad copters during the cold war
imagine thinking im defending it
im pointing out how little you know about warfare
when you get conscripted (high chance) you will jump at the opportunity to sit in the goon cave
built different huh?
your bravery will be filmed for the world to see
do you think nation states care if anyone thinks their tactics are cowardly
or is the point of war to win
it's way cheaper to equip a drone with weapons and do massive damage than send troops in
idk not risking your soldiers lives kinda smart
rather than putting your foot in your mouth, understand nobody likes war, so there is no defending it
but when war happens, you will be a coward
i dont want to be right, i would never defend wars
they are always brother wars that reward those who do not send their own sons to war
the convo was not pointless, you are now informed that drone warfare is simply evolved artillery warfare
they even use the shells.
you did? you knew that over half of all deaths during the world wars were with goon caves?
i got what i wanted
im only messing with you, but i can understand sheer ambivalence to what i just did
anyways, i was triggeredTM by the fact you called someone using drones a coward, that word is rude to associate with people unfortunate enough to be duped or forced to fight for their countries elites
then we can agree on that and put this to rest
Yo I'm from THM and i was new here can anyone tell me where should i start what cube they callled sorry for this dumb question. id like to know more about HTB
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
@rustic carbon use the docs above ^
Tnx donut
you can see the stars, luckyyyyyy
we can't even see stars 
a
Yeah. But the blanket was cozy and warm
colder weather is better. when it's cold enough there will be no clouds
Yeah, exactly
I love the cold
wind usually stops at around -30C and the humidity drops too so no new clouds forming
Ill need to get my merino wool underwear out then
Check out highlights from the heavyweight clash between Jake Paul and Anthony Joshua in Miami, Florida.
Jake vs. Joshua is now available to watch globally only on Netflix.
✔️ Subscribe to ESPN Unlimited: https://plus.espn.com/
#ESPN
Im watching rn
Jake's currently in the hospital for possible broken jaw
Ah so a real fight this time
he keeps going for takedowns for some reason??? LMAO
Not possible broken jaw, he DOES have a broken jaw
Gtg. Swim class for kid
he forget to slip the bribe money in the locker room?
goodness
unless odds were for him then it'd make sense why he'd take a losing fight
he got clobbered pretty hard at the end
judging by the reaction it isnt as bad as what it could've been
oh yeah for sure, there's a moment right before the final punch where it could have been way harder
I think the guy took it easy on him at the end despite the hit
defo some restraint there
stuff like this isnt even entertaining the golden age of boxings already passed long ago
Morning chat the box
yo what it do famalam
Hello
Hi
I have a quick question, the season ends today, but does the next season start immediately after (tomorrow/later today)?
you have about 60 seconds to do the whole season 
wdym
No there is a 2-3 month break iirc
You can't just shit out boxes 24/7 lol
I might have a medical condition that makes it hard for me to advance intellectually at my full potential. However, it might be treatable. I have to get tested. It would explain my autism and other mental health issues. I don’t want to say what the condition is (that’s private info). What I will say is if I can get it treated (I have a mild case of it if I have it at all) then I think I might excel at hack the box much more quickly once I treat it.
I mean I have high intellect but this condition might impact how quickly I learn certain skills
It also impacts balance
I have a hard time on balance beams
Etc
I’m gonna get tested this week.
I think I may not be able to get a job or do school until I get tested and know for sure
I’m worried about it. The good news is it may be easily treatable.
Which would be huge.
But we’ll see
Its just then I have to wait to get the treatment
Etc
must be ligma 
No
Something else
But its ok
I am hopefully gonna be better soon.
I just gotta confirm this condition really is what I have
time to cook, hmm which wine would be the best for the sauce
red
anyone know, what's the support id of hackthebox store?
I'm thinking about making that same thing today
Def wanna give Silver C2 a whirl soon
you will enjoy it
I've been on MSF for a while and I figured Silent Trinity was the next best step but Silver C2 + python seems OP
ironically
its OP but sometimes 💀
you will want to smash your head on the wall
Well it can't be worse than Powershell Empire
bro doxxed me
why not mythic?
partially because i am doing the puppet prolab
as long as you understand sliver is siggied to hell, im not ganna be pedantic
it is signatured as hell, therefore not viable in real engagements, hence not worth learning
can agree on that
am just browsing the docs while using it
i don't remember half the stuff 💀
thanks
You're too lazy to even self diagnose an excuse
@scenic maple quit putting your fingerprints in my .50 cal
Que hostias
wouldn't evasion be enough to circumvent this?
Me la pelas
Me chupa un huevo
mythic is slow as hell and more clunky imo
I like sliver
absolute botones moment right here
I would personally take the necessary measures to prevent sliver from being detected than use mythic 
💀
Let's play a chess match while the liter of black coffee kicks in
Join the challenge or watch the game here.
Bro went from forcing stalemate to forcing mate 
Ggggg
I saw that, it was great
thanks sir
my king was shitting his pants

do you want to be hikaru
Hey great game
That's how I like it
Last game you said, I would have appreciate more aggressive
So I thought about that
let's gooo kill everything yess
LMAOOO
didn't see that coming
Hahahah
morning
cats
I HATE VIM
Nano > vim
People that pretend to love VIM are the ones that spend hours configuring Arch but never actually end up pwning anything lol
The only cool thing about VIM is neovim but I'm too lazy to customize it
Yeah, I tried to test out VIM again. Never again. But Tmux + nano equals 1 window to rule them all
Spent an hour getting the best pizza neovim theme and it never came out how i wanted it

Hi, trying to get myself into soc field but stuck in the loop of which platform should I go with as a start
Try hack me or letsdefend
The worste. I want to customize my Kali desktop but honestly don't wanna break anything on a bare metal build
Letsdefend is recently also joining with HTB https://letsdefend.io/blog/letsdefend-joining-hack-the-box
Well... As a student i'm limited in money so i have to start with one
And we don't say the "T" word around here partner. We hardly even say the word "try" lol
My bad
I mean I didn't like the platform nearly as much as I did HTB, but why the hate 
So i don't have to pay separate subscription for both?
THM is free for a lot of it, idk about letsdefend
I'm sure HTB also has some free soc (esp with them joining letsdefend) stuff but I've never checked
Mostly Sherlocks (I could be wrong though)
Yep
So did they change the content? Compine the subscription of both platforms together or what I've never understood this
I think they're still seperate but HTB has been adding more SOC content lately
Best case, register, see what each platform offers for free and then chose the best one you like
Okay thx mate
It's a joke. I actually got my start at THM. But HTB is where the real h4x0rs are
Lets defend belongs to hackthebox
Also it has decent content
I'm gonna say the biggest difference I see is THM is a learning platform whereas HTB is a CTF platform that created Academy for learners
Something like that, yeah
THM holds your hand too much though imo
Fine to learn but practical exp is far more superior with HTB
I lost all motivation to do hacking
why
It’s just not working out for me. No matter what I do I can’t get better and I know I don’t know things
For now not much has changed
For now…
Sounds like either burnout or you struggle to measure progress
Knowing you imma take a guess at burnout
Hacking takes time. I can understand your point. I also have moments where I feel like I don't know anything and go through stuff. But practice makes the master. You just have to keep grinding and take your notes :), so when something becomes familiar, you can search for it and easily find that topic. Don't overwhelm yourself. breaks doesn't hurt
So you feel like there are patches in your knowledge? You got the CPTS so you know something
I’ve been doing this everyday for 6 months straight
You need to let the brain rest just like everything else
No grass tho that’s scary
Def burn out. Maybe change the medium and try messign around with puzzles or lockpicking
My parents won’t let me. The moment I play any sort of video game they’re like “Oh you have time to play video games, you have time to study”
Mate of mine is in a similar spot (in that sense). It’s difficult :(
chinese parenting pattern 37.2
What’s weird is that none of my parrents are Asian
ngl its common anyways that parents bash you for having a good time
My dad’s African American and my mom is European (German)
I'm fully korean 
ok then post a picture of yourself eating a live squid
Even when I’m tired I still find a way to do this
nyo
my dad and mom does tho
its just so interesting tbh
I legit completed a portswigger lab when I was drunk last time
pull away from working?
Yes and studying
I see
Wait, how old are you?
23
welcome to the "getting better hell"
i've been stuck here for 2 years, take a seat
getting past this point will require either an ENORMOUS amount of effort, or just being an alien like Frosto
So either I become a god or give up
Well, we don't give up here so get ready to ascend
i mean, giving up hacking altogether might be too harsh
but hey, look at the positive side, the majority of people do not even end up in this situation
so you are way better than you think probably
If I just lock in and finish CWEE and try to get pentesterlab
inb4 you become a kpop star
damn, ur like from the 2000's
I'll be a god in the next decade
atleast its not the late 1900's
you can also like, you know, getting a senior pentester job or something
I can’t even get a junior pentesting job

why do you put it like that -_-
i mean it is factually correct
did you try europe? i am a junior pentester and it wasn't too hard, and I am definitely less good than you
In case you didn’t know, I’m still in college and Crowdstrike rejected me because I wasn’t a junior yet
you couldnt get an EU visa as a Jr Pentester
unless you have EU family
plz hire me, here's my skills
- I launch nmap
- I google
- i hak service (sometimes)
I love you all
I for some reason attract European women. But I don’t think I’m getting a Visa that way.
i mean, you could
- kick my ass in chess
its how im getting a greencard lmao
people y'all need to come to europe
all part of emmas masterplan to pivot to POTUS
i never can
US-Born folk only
i could become an american cit in like, 3-4 years if i wanted
but 🤷 idk
later me problem
American likes to tax you and have alot of compliance globally
could come in handy during WW3 lol jk
the US market must be completely broken for you not to find a job, it's definitely not your fault
Play the University CTF 2025: Tinsel Trouble event on the Hack The Box CTF Platform. <div><strong>🎄 Grand Legend — </strong><strong><em>The Tinsel Trouble of Tinselwick<br></em></strong><br></div><div><strong>In the snow-glittered village of Tinselwick</strong>, where peppermint chimneys puff cinnamon steam and toy trains zip between roofto...
THE INCEL CTF
i mean, Canadian & US Passport are effectively the same
haha
you are already goddamn good in hacking vader
for going most places
hello 
TURBOMAX
TURBOTONES
I love the turbo prefix
its the best
i want to go into a 0% capital gains tax place
i mean, the only places i need a VISA for are places i wouldnt really wanna go anyway tbh
there are several
alias turbo='sudo'
my ETF is not going so bad, i can now afford two kepabs per month instead of one
turbo nmap -sC -sV 0.0.0.0
(same)^-1
I would go to India but uhh it’s kind of dangerous there plus foreigners aren’t really welcome
they only work if your not a US Citizen though
I've been looking at taking a trip to India
i wanna visit Aureville in india
come to south korea 
already in the plans
wanna do a Singapore-SK-JP trip
oooo, niceeeeeee
Singapore's like N°2 in my fav places I would want to go to
Silk trader emma
behind malaysia lol
mostly just wanna try the Singapore Airlines A380 suites
My trip plan is North Korea-Iran and recently I added Venezuela to the list
then its cheap to goto SK/JP once ur in asia
vro just swimm to antartica
discover the world
What
How is that the desired thing
welp into the pit I go
I want to swim with the U.S. navy surrounding Venezuela
Plane Autism
dang it Im getting distracted
Hahahah
closing this 💋 cya
Ok thats just banging
I would sacrifice my studies for this 🤣

eh theyre pretty easy to get
whaaaaaaaaaaaaaaaaaaaa
Walk back into Academy
See Xpath Injection is up next
Walk back out
this view was so dazzling even the chat went silent from its beauty 
😄
comrades
Hii
waking up...actually got several hours of sleep last night so that's nice
I say that as though I didn't have whole days I slept this past week lol
but regardless night before last I only got like 2hr
I am from Singapore. Yes, our tech infrastructure are quite resilient!
so last night was needed
- Their cybersecurity training not bad! They had some CTF challenges if am not wrong.
yeah I know a community there
I hope it can get installed in an hour.
no need for ads but honestly I think singapore and indonesia will grow massively in cybersecurity
Game not good
if it doesn't it'll go "out of control" 
I have played it earlier and then uninstalled.
Now, I'm like holiday season will play this 🫠
Ik but I did not like the characters
This is my collection in Epic, completed WD, and RDR2
It says 2 hours 
Ghostrunner? 🧻
Valorant = game of frustration
It was free
so I claimed
Only WD2 and RDR2 I have purchased
rest all were free
Nah, trash is free but you leave it on the street
too many toxic ppl
I never had any in a lobby 
All were players who seem to be kids who curse words for no reason
no machine for this week?
no machine no cube talks
They gave grass time
I mean as a kid when your parents aren't around you do exactly what you shouldn't lol
hell nah
I never cursed in front of them when I was a kid. I do sometimes but too quite.
bro
who tf deleted all the beacons and sessions from the Puppet prolab
[*] No beacons 🙁
sliver > sessions
[*] No sessions 🙁
💀
Anyone know how to hack wifi?
Forgot your password?
Bro, nice try, I’m not falling for a phishing link
I hacked the Italians (Joey) and stole their food. 
Is that samsung
Nice try kiddo
I'm stuffed.
im slow
ping @scenic maple . and report me for sending phishing links
Search the world's information, including webpages, images, videos and more. Google has many special features to help you find exactly what you're looking for.

its only a phishing link if you get caught
not a phishing link
UwU, it's you agwain!
I've been good, just busy learning chemistry! How've you been brother?
You got tricked and clicked on my fake GIF link. Now you will feel real fear
I haven't even opened it bud xD
@mystic harbor let's not post gifs like that -_-
Don't lie bro, i have your IP
Oh? Anything on your mind bro?
Vro test my phising link 🙏🏻
nothing mjuch
thought i would bursh up web dev skills after i got cooked in bbh
xD
Oh I see! You got this man! Goodluck to you!! 🫂
lol
I tested your link, bro. I used to create that type of malware in 5th grade.
i have one
They wouldn't take you 
Cause of somthing
can you get root for me on puppet please?
How can u work and text 🤔
bro already started, before I even him asked
gib me ur IP and transfer 10K USD, will send a shell. listen on port 9999
my team mates probably left a golam_was_here,txt
sounds perfect
its how they troll me 😩 😩
can you change the port to 1337. it looks & sounds cooler
that is how uk that u got good friends
I saw it now. Thank you and your teammates
Kitten gets trolled 😩
custom port costs another 2K USD if you will
port 0 or nothing
they are no where near me when it comes to trolling
port number too small my guy
Even netcat is angry
for everything to exist there must be nothing
for every other port to exist there must be no ports
0 is wildcard; it actually binds to the nearest possible available port :)
good to know
dang bro actually read the man pages
i got curious a while ago
:caught:
there is no jackfruit emoji 
Yes I got money for one
The others are waiting for after Christmas
- @SERIOUSRULEBRAK
There's no passion fruit emoji either 

any hacking today?
I was expecting that question

if I expect the unexpected doesn't it make it expected?
bro is the reason we have a "0 days used in the wild" checkmark

but it wont work for me i am using a browser and i am on linux 😩
Frost keeping everyone on their holiday end of year soc readiness
Wouldn’t make a difference for my electron bug
i might look at some today, but probably not seriously. Had my 2 XXE paid out yesterday so that is a nice way to end the year
Electron bug works on Linux
https://kibty.town/blog/mintlify/
i read this today some bugs are so simple i feel like i could have found it
how to hack discord, vercel and more with one easy trick
but then again payout is huge
Every bug you see online, everyone says “I would’ve seen that”
You’d be surprised how simple a lot of bugs are out there 
is it the classic hit the xml endpoint with entity or anything cooler?
i think i should be asking how i manage to not find them 
@exotic pendant in gym?
Ye
i think they win cause of trying out things no has tried before
One was basic, literally a /xml endpoint. The other took a base64 encoded zip file full of XML (proprietary file type import). For both I had to use error based XXE because it was a java app, so with OOB XXE on java you can only usually get the first line of the file, even via FTP exfil
@exotic pendant reply when ur free I texted u
I just pop stuff into Ida, see how it works and thing of funky stuff that can work with it
shi 2nd one cool
previously i found a base64 post request endpoint where u would hit it as xml for oauth 2 and it will take u to a login page on a govt website
didnt manage to do anything with it tho
it was either "something went wrong" or it would redirect
thats what everyone says man
so what will you do when u take a break
Force my self to game
I bought cyber punk
My $250k bug is still pending
Because holidays
Pending payment, not approval. It was already approved
hope they pay u full
Yeah, thankfully there were verbose error messages so that helped figure out the format it required. But otherwise pretty straightforward


bro even left a comment saying base64
I always hit my oastift just incase it’s blind
They had collab blocked
man just pick a static site generator
Yeah, use a custom collab (you can find these on shodan 🙂 ) or just a web server with tail
akshually u could also use vercel or whatever
they have ip logs with is pretty fast
aye its The Weekend
pizza time
why can u not deny
I was told it’s a party just for the kids
i see
Then I agreed, then it turned out “ok we invited a few more people”
No family
party of pepe sounds better
They intentionally told me it’s a SMALL Party
Then lied

I got the kid gifts and then I was told 19 people are coming last min
sounds brutal
This one is clever <pingbackmetrics.com>
Otherwise hello consulting firms: <burp.eh.orangecyberdefense.com>
<collab.redsiege.com>

Also what’s sexy about collab is the smtp
I use it for emails
Register with collab for a quick temp email
but u cant use them right?
cause the companies own them?


Kind of want to find another hyper v bug

But break
Maybe I’ll take a break next month

:))
ngl shit like that is always motivational
do you use ida for this as well?
I wanted to do that as well
Yes
how does the thing even fit inside ida
ida just decompiles it
Individual comps
its broken into multiple drivers btw
owww
Window Fundamentals? What is that!
i see now
Its not a single exe 
hello cinzo golam , frosto . everyone . hello sir
its fundamentals of using windows and basics
its related to windows
Ooh interesting, I will try it today!
if u dont know basics of windows
@exotic pendant the ipv6 one did turn out to be a cve 
ran the public poc and got it too
although its interesting how that driver is still vuln
Nope it’s not the same
The one I showed you
should i ping three people

Is not the exact same
👀
but....
I got the poc which means... im running an outdated driver?
ok its possible
weird but
But I got a few vuln for hyper v that I need to hit and that’s better atm

More $250k
hyper v has like 50 different drivers with 200 different functions each. how do you even zero in?
its incredible
Prob because they wouldn’t get a cve on something that wasn’t patched
Microsoft does patch first
hello cinzo
hello golam
hi
hello frosto
how r u
hi
Be quick like sanic and don’t focus on stuff that sounds useless
Sup sup




