#general
1 messages ยท Page 345 of 1
it's so bad if u try to do any real engineering
and is something that 10 years ago would have seemed like technology far beyond our current capability
It's less pride and moreso "I'm unable to verify it's statements and I don't have the time to do so."
I'd go back in a heart beat if I could yes
Yeah that's where I am right now no money for study and fucked up the loans when I was younger.
I just love academia
i like using it to discover new libraries and write summaries of my code in english for deliverables etc.
this is not a very good argument
I actually did go back after my first degree
I was a digital forensics/CS double major
its very similar to the argument of how the internet isnt trustworthy and that only knowledge from books can be trusted, that you would see in the early 2000s
I'm about 4 classes away from turning the neteng degree to a sysadmin one
it will fall flat and become a dead opinion in the near future
I don't agree
AI is really stupid when you do anything that requires a little more elbow grease and research than installing linux mint or making a basic ass python flask app
I don't agree
This was not a vibe in the early 2000's for me?
ai cant write ffmpeg patches.
in academia the internet was treated as an unworthy source in the early days
or the 90's in fact
So do you intend to remember all the shell commands for dos powershell and bash ?
I'm aware that machine learning is a technological marvel. I'm not a fan of giant corpo tech bros suddenly pushing infinite resources into something that confidently tells me whatever I'd like to hear
at least in my experience
That's what my notes are for
ah I wasn't in academia back then
I was doing ratchet shit
lmao
A machine cannot be held accountable
the first time I went to school, I went in as a pre-vet/vet tech
You say this as if its any different from google
i'm not a fan of subsidizing big ai energy bills or having the cost of memory and components that we all love and used to create pieces of this space become untenable for most because of greedy demand
it can and easily does link sources to more esoteric bits of information
that's like impossible. learning how to find the cmdlets and shit you need is where it's at
ask it to write a version of GodPotato in golang without the C package
I don't write C
you use unsafe and manually import the api
there's not a single person here who will be like yea i memorized every possible thing about a lang
But I've had very good success getting it to write good and complex code for projects
that's why I said golang
My only issue with LLMs is that they can't really be any original and yet people use them to try and be creative al lthe time.
and anyone who says they have is full of shit
i want to make a windows gui application in golang using createwindowex
do u think ai can make it for me?
Anyone who does is clinically insane considering they're updated every few years
I will just continue to study and learn and improve the same way I always have
Sure
me rn
But if you don't adopt the tools of the trade as they change
that also applies to syntax btw - since ppl brought that up earlier
You will get left behind much like people who refused the internet did
there is form and process and understanding how to pull what you need with xyz cmd's
but there is always a point where you're like 'fuck how do i do that again?'
Or web developers that refused to adopt frameworks
I don't believe I'm going to get "left behind" because I don't trust an automated sycophant
when is season 10 starting
If you can't see the sense in talking to your computer verbally
And it talking back
Slow mode 30s so my stupid ass can form a sentence before the next argument starts?
while you still have your two god given hands
and the more you learn, the harder that hits
You will get left behind because of refusal to work AI into your producitvity pipeline
same yo same
speed up grandpa 
I disagree, I can use automation I write myself.
Left behind because of the endless people of equal skill who do manage to get value and producitivty boost from it
i had to train cmusphinx and it was annoying. the speech ai is gr8
nn โค๏ธ
adaptation is different than reliance
everything ryan has said is true, i dont even know how you could argue against him in good faith
night beardie โค๏ธ
You will still be competing by people of equivalent skill who do use it succesfully
ni ni
Your argument is that you cant use it in a way that generates value
Or that any one who can is at a lower level
What's space cows about?
my old ctf team
But there are plenty of people at an equal level who generate real value from it and will use it to compete at a much higher level successfully
what labs are good for cwes
no bc the reg team was open to all
web challenges
the majority of people who call AI "stupid" are incompetent at prompting
I know of a website that is making $12/year/user to predict nice fishing days
the only thing limiting our ability to stack checks is our creativity and imagination no cap fr fr ong
there are just women's ctf's that exist
a women's team is what got me into ctf'ing bc it was more comfortable to be open
Don't call AI stupid, call the user stupid 
i wanna use ai to talk using my mouth so i can check out and daydream instead
That's not really what I meant morph but fair enough lol
let's see you get a working poc of godpotato in golang then using chatgpt 
Well yes true, but just be careful as this argument can be extended ad infinitum.
if you pay me my consultant fee i could do it
which one tho? maybe some challenges are for CWEE
I was just kidding, You guys don't compete anymore ?
we are pretty underrepresented in ctf's
I don't think you can do it even if I paid you ๐
sometimes, but not much.
what's ur fee
I'm too busy with work and life
perhaps you should enter into a contract with me, and i will deliver a working godpotato in golang in 1 month
I'm 100% confident it could be done if I cared enough to put in the effort
i would take it on
I dunno
Realistically just check the about of the retired ones and see if it boasts an attack covered by the path
There's not a lot I trust about it
the irony is you dont trust yourself given the things you said today, so who do you trust?
And all this "you will be replaced talk" is lame as fuck for a community that's supposed to foster learning
@rustic carbon it's just a personal server now
Or you can use https://academy.hackthebox.com/academy-lab-relations
to find labs that apply to certain modules
you are wasting the golden era of public AI use
if ppl want to get a hold of me kinda
again you can't :D, if you did a little research it's not possible to make one in golang without the help of the C package because of COM objects
You wont be replaced by AI
AI is making our brains shrink smh
like i said ceald, pay my fee and i WILL make it work.
you will be outcompeted by people of equal competence who worked in AI to their productivity as a force multiplier
I'll be replaced by people who use AI sure
you won't make it work because again it's not possible
why would this happen if you use ai too?
I disagree because I think anyone who requires an active subscription to something to get an edge over me is a fuckin loser lmao
ceald, my business runs on "its not possible", i have never not delivered on a contract
holy fucking copium
Just as a writer who relies only on books for sources and a type writer is outcompeted by an equally good writer using the internet and notion
Anyone who requires a paid subscription = loser
AI creates too much tech debt and unmanageable code, if you replace your devs with an LLM you're asking for trouble
๐ฎ
@molten bobcat sorry to disillusion you but burp pro
Well yeah, you shouldn't have to pay to use something "so vital to your success"
its all going to get optimized
Pay for it out of pocket?
metasploit pro
And if so, why??
college?..
shodan
they've had several years to do so and have not
will they ever? dunno
Do you pay for the internet? For your computer?
THAT IS CORRECT BRATH I BELIEVE COLLEGE SHOULD BE FREE LMAO
should I keep naming random tools with no industry competition that require payment?
were you one of the people who said it will never take jobs too?
Yeah dreams are free
That is correct I believe the internet should be included for free
HTB also not free
Come to Brazil
Come to Brazil
sure
so anyone who pays for htb is automatically shittier than you or just a loser @molten bobcat
I don't think someone should have to pay for shit to have resources available to better themselves color me the bad guy lmao
a lot of it actually is free...
but belief about how an idealized system should be is a bad way to frame your practical actions in the real system
Same but, I prefer to watch people's copium instead of engaging with it.
not if you are about actualized outcomes
My point is that's fine, You can't get to the top of this industry relying on free resources.
the internet could be free if everyone just ran a cable between each others homes, the issue is your ideals are not compaitble with reality
And complaining people want to be rewarded for their contributions is fucking absurd.
So your loss @molten bobcat
My college was paid for with financial aid assistance for low income brackets
cant find it anywhere
I grew up in poverty
skill issue
Not disagreeing here, just clarifying
I don't think someone's destiny or success should have a price tag on it
ive hit legend in hearthstone on several accounts without spending a dollar, so this isnt true
and then someone comes along and offers you to connect you to your neighbors with 1 wire! Connect to me and I'll handle all the other wires for you!
and then an ISP is born
yep
and its not free anymore
actually you might be able to do it, I wanna get it working hold up
That's actually really impressive
I ragequit hearthstone season 3 because it felt paid to win
shaman/warlock metas
best time to do it
Good night gamers
this is a weird comment.
you can
how do you think many people of the past got to where they are?
Heavy copium
its just weird to recommend people try to do that
"I have a problem that I was unable to solve previously, therefore my problem is still unsolvable. The new methods of grappling with it won't work, because of [insert in-group myth here]"
You think so reasonably without any saas tools or industry leading tools ?
Well technically you could crack all paid for software so
i think my next guide will be on "should i go to college"
It'd require a person to write their own
its a very weird "choose the hardest path and to filter out the weak" type of recommendation
Skill issue?
then i dont have to justify my point of view
yes
and there's the in-group myth
seem this before
but it is significantly harder
more time consuming
and will increase the failure rate drastically
We're talking about the utility of ai remember
^^
I REMEMBER THE ISSUE I WAS HAVING WITH IT! It was something with unmarshaling it and the fact that golang halts when you call the api function, it forces you to wait for a response
that was the moot of this discussion
people actually have it so easy right now and it's amazing
So if you're stating that a person can write their own tools taking hundreds of hours and keep up with the industry.
Something something butlerian jihad
and this is good
Late-Stage capitalism really fucks up people's discernment and mental health doens't it?
Soon it will all pass guys, relax, just two or three more wars
a field should not be reserved for the few people who take the hardest path, succeed, and then get to look around at the corpses of those who failed with superiority
it should be made as accessible to the most amount of people as possible
Do you honestly think I'm gatekeeping cybersecurity by saying no AI?
so much this
i think so but only at the mid-game
you never know who will end up solving the next great problem
No but it does seem a bit dated to argue that 0 money should be spent
On AI
it could be some kid out in a village somewhere
Even if it's not spent by you as some more experienced people in here are pointing out.
and it happens all the time
You cant make the "not AI" argument but then also say "but other stuff is fine"
Its an extremely valuable tool
like anything else
Your employer is still going to be shelling out for tools and saas
tool is a key word
and resources should be allocated on merit
At the end of the day whatever tools you choose to use is personal preference...
Guys this is just a case of learned helplessnes, there is no argument here. We can move on.
the problem is drastically underestimating the merit of AI as a tool
Learned helplessness...?
no, I agree with saying/discouraging the use of AI for things like bugbounty, pentesting, investigations/incident response, and building tooling that requires a little bit more brain power than a simple flask app
He can't do it without AI, hence everyone else [...]
early-game:
read walkthroughs
retired content
introduce self to communities
mid-game:
use ai
finish certs
get a job with your network
late-game:
use ai
do research
create great things
end-game:
speak at conferences
teach new people
retire, move into the forest with your wife and raise animals
I take issue with your assumption that AI is only good for basic flask apps
My sword doesn't fucking shatter when cloudflare has a fucking outage though.
Can we just skip to end game? 
apparently I am in the Brath-POV on end-game because I live in a forest and could retire.
no, the ride is majestic
it really is. it's pretty stupid I've told you already how you can prove me wrong 
I dont' wanna move into a forest though, I wanna move to the ocean side with a wife and raise animals
I'm not going to spend a bunch of time getting it to right a PoC I don't even know how to validate
okay replace forest with your preferred biome
You wrote a 12 word prompt to try one shot something with thousands of lines of code
Everything's a forest if you [REDACTED] enough
but I've had extreme success getting it to work on highly complicated tooling for me
hmm
I've had it miss IOCs in an investigation and hallucinate new IOCs just to placate me.
ai shouldn't be a replacement for basic necessary skills
Brath I have a different task for you
not really, I was actually trying to figure out how to actually make custom COM objects and get it to not wait for a response on an api call ๐
okay pay half up front
I think everyone is in agreement with that
this is a problem of implementation not of the underlying technology
DM
there's so much noise around it though
So called "experts" implemented it
How can I validate their expertise?
I dont know what to tell you
AI should probably replace just about every T1 analyst, and most T2
You can't
As its not hard to prevent hallucination
AI should replace everything so I can chill and meditate 10 hours a day
I actually got a working potato POC with very little help of AI ๐
Disgusting
You know nothing of my work
not biased (very biased)
That's exactly where I draw the line
maybe ask chatgpt how it works then 
i dont? cloud stop being a dipshit, ive done your job
Then you'd know how wrong you are.
flagging likely legitimate findings for T1
im not wrong lol
im not gonna name the EDR, but I was personally on a major vendor demo with such a feature
and it hallucinated failed login counts live on the call several times
when confronted, the sales person just pretended he didnt know what I was talking about and scrolled only far enough to see one instance without comparison
I think the biggest elephant in the room no one is talking about is the job loss/economic impacts
I think this is moot tbh
no it's not at all
people will recover chill
its worth discussing how to prepare for those impacts
but not why AI shouldnt be used because of those impacts
sure, but don't expect people to not fear/be pissed at this.
Legal frameworks need to be put in place to protect certain classes of work.
if you are worried AI will replace your job learn to write it?
if you are afraid of guns, learn to build your own
Unemployments up 8% worldwide since 2020
unemployment is currently at great depression levels
Yes lets all write AI that'll totally fix the economy.
there's also the argument of regulation of AI and LLMs and how that's going very slowly compared to the rate of growth of the tech... some people can run powerful models in their own homes.
it doesnt hurt to know how it works
imagine thinking of it like a black box
sure, but for the same reason that people who worked in horse husbandry have had little to benefit from fighting the advent of mechanized vehicles
the current situation benefits little from fighting the advent of AI
I agree with this 100%
I will continue to study and improve myself, and I'll continue to be better than any stupid LLM.
Expert bias, learning comes with great baggage for most.
i was testing an MDR solution and Sentinel One totally caught remote dumping NTDS from a workstation named kali and their SOC completely ignored it. I called them out on it and the Salesman told me that it was UEBA and it was expected behavior. The SOC did "OSINT" on the LOLBAS that executed the process (i cant remember the name of the process) and said the hash was clean therefore nothing bad happened
Now that's an useful point of view
yeah well, those very people wont last long around here at this rate
it kinda solves itself, no?
oh Brath, stupidity is far more resilient than intelligence.
people don't fight against that - they fight at loss of opportunity/shifts that don't happen fast enough on their end
my point remains, you have to fight against people who study and imrpove themselves and use AI to do so at an accelerated pace that scales past your own
๐ฎ
Humans have successfully gone to the moon and back on less RAM than my cellphone and no AI whatsoever. I have the utmost faith in my capacity to learn and change and grow.
ok since you named them, that was the vendor LMAO
sure but my point is you cant focus on stopping or turning the tide
i did not name the mdr vendor
ooohhh this is a good point indeed
you can only focus on how to ride the wave
i just said S1 caught the remote cred dumping
What the fuck... we relyin on software signatures now to determine malicious activity? When did SOC just use the same method as AMSI?
S1 is the vendor, Im confused how this is a response
MDR vendor
exactly yes
AMSI 2.0
Homo Imbecilis edition
S1 is the NGAV they leveraged
#972 Global Ranking
The vendor caught it, the blue team ignored it
Just so you guys know I'm top 1000 worldwide on hackthebox
but you expect that a bunch of job losses due to ai aren't going to have an effect that's going to cost people the ability to live AND adapt into a new area quick enough.
It's because I can't afford to lie to the customer brath
thats not what we're talking about, he said he never named the vendor but did
literally anybody whos done 1 box is too
Nice achievement
the NGAV (s1) caught it but the MDR vendor ignored it
If I'm wrong I get fired
ohhh, damn
Its not that I dont think this is going to be impactful
you shouldnt have to lie to a customer, why does this matter?
i didnt name the MDR vendor who ignored the alert
It's just that I don't see the point on focusing aspects of something you cant influence
and my story wasnt bad talking S1
Because AI is capable of lying to the user
wtf I have like a ton and still around there
oh i see your point, thats simply not how upstream works with AI at T1 alert analysis
I am in the top 1000 worldwide sir
it's the holidays the soc drinking eggnog at work
its your job to verify
agentic misalignment
in strong implementation it doesnt really have the capacity to lie
as boxes retire you lose points
misinterpret maybe
How can you tell?
Do you have the validate the results?
You enforce sourcing and have veracity checks
I haven't done a lot of boxes in forever
Manually?
well last week i did
how many people are currently participating in htb comp this season
I've only done starting point :#
retired boxes also do not provide points
-# 
I'm just getting started on it
manually first, then train a model on those manual checks, it recursively reinforces itself to not make mistakes based on good inputs
they weren't retired
last time i checked it was 7k people.
You end up with only the potential for minsinterpreted source not for out right hallucinations
you mean previous season?
You have to manually check every single time to ensure truth
I should grind some boxes
Gotta become Pro Hacker
only at first yes
yeah the previous one that just happened
ok but you said S1 is the MDR, then you said the SOC ignored it, then you said the MDR ignored it and the MDR vendor wasn't named. do you see my confusion here?
my rank is where it is because i stopped doing a ton of boxes
Every time after that it still has a chance of being wrong
Its moot
over time it wont be able to lie like you think cloud
We will see the results first hand in a few years time
Why do you know that?
like for a few years @warped plank
its not a sumarrized response
I've noticed that alot of people stop doing boxes after getting Hacker rank
its deterministic
okay the MDR vendor was not S1 it was just the NGAV
What if the determination is wrong?
And in 10 years things will likely have advanced far enough that conversations like this are a relic
i know it because i train drones to fly themselves
my htb uid is 4 digits and from when there was a fun little challenge in order to signup. it's also my alt account. i have an older one.
RIP signup challenge
ya
noice, you planning on getting back to grinding?
I just can't see it currently doing anything of value for me
So I wont be adopting usage
this is the fundamental point I'm making
According to the site 9850
youd be surprised how similiar the models for detection and response are to drone autopilot models
not atm bc i'm studying for the cape
they both use sensors
I think thats true only because of your unwillingness
if i do one i won't do the other
Good luck!
not because it actually cant offer you value
but we can agree to disagree
the world will sort it self out
i did go on a binge recently though
and the dice shall fall as they will
but binges are usually easy boxes
i call snake eyes
If we wanna get down to feelings rather than facts I just genuinely don't feel right passing off what an AI has said or done as "my work"
Noice, gotta feed the technolust else it builds up
Damn grinding
:\
yea i raged
usually only time i get like that
just about every line of code written these days is supplemented with AI in some form, if you really feel conviction about this, you should live in a pot
Again I disagree but cloud your point stems from one of emotional principle whether you realize it or not
I do a bit of tech everyday so I don't get pent up about it, but sometimes you just gotta go ham on a lab
You came to your current stance not through hard logic but through your personal value sytstem and beliefs about the world
Ryan
it's a whole vibe. pissed enough to do nothing but fucking boxes
why did u ping me couple of days ago
so we will not be able to alter your opinion without changing those core beliefs
Tejas
I think to have you threaten to ban someone as a joke idk
someone asked me to fly to DC and audit the tiktok codebase on site. tik tok is written with a lot of ai
nothing important
Probably not no, but I'm still open to conversations about it
tiktok is one of the world's most popular apps
It's not like I hate you
Mick, wth are you doing? have u not slept yet?
to be fair like - i get like no points to rank on easy's - i got points but it meant nothing
im a bit sick and slept earlier a lot
oops that is bad during holiday period : \
this may not be fair for this challenge I gave you but here you go to start off
https://gist.github.com/Ceald1/b035d11a30e614074ec828cd1623a8de
get wekk soon
It's a philosophy clash. I think human improvement is better than technological improvement
you should never hate anybody here, none of us hate you
and no i'm here playing hunt showdown and vibecode
*weak soon ๐
go is your favorite language isnt it
i have to do a ton more to even nudge it
Granted they go hand in hand
ceald, i am genuinely serious, if you want this you can contract my firm
Not saying I'm a Luddite lol
there is little benefit in trying to alter the opinons of someone using any means different then how they arrived at that opinion
well ๐
Or.. amish
thanks buddy
yeah...so each rank has a point threshhold and to start making progress you have to get back to that point threshhold for your previous highest rank and then exceed it
i can understand some amish
I haven't looked at it in a while and it probably doesn't work 
But Ryan I still like hearing your points and arguments
highest you can get only doing machines though is pro-hacker
yup
mine2
I take them seriously
yea which basically means doing more hard stuff
well... yeah but at the same time even if you did do hard stuff now it wouldn't move that progress bar unless you get back to that threshold
but if i do that - i won't focus on my studies with cape
and I actually do ad testing for work
and I have no interest in trying to upheave your entire belief system for the sake of you using chatgpt
lol
so it's super impt I go through the material
Yeah that seems excessive lol
ad testing is boring
true, imo cape probably more valuable than doing boxes if you've done a lot of them in the past
Ry4n, if you wanna try to prove me wrong here you go 
I know you're an incredibly intelligent person and AI doesn't change that about you
bro im not gonna try to get it to write a random exploit
i like appsec โค๏ธ
best I got is 2 dolla
if you read the code you can see how 
like I said
by executing and awaiting for the doomsday!
tedious
it'd be a while lmao
you calling me a no-life? 
i'd have to straight nolife it again
no :X
Im not a go programmer even just working through your exploit would invoke some level of psychic damage
not really, it tells you the powershell script to run to test it with 
can i borrow some points from u til my cubes come in on the 1st?
This whole conversation about whether or not I should adopt an AI workflow would also be null and void and never have happened if I never went to college and worked hard to improve myself lmao
i think this would take about 40 billable hours, two engineers (ryan and I), a finders fee for ryans 1099 subcontract - we are looking at about $16000
Doesn't work that way bruv

sorry moo that was for ceald
My hard work and effort saved me from a life of.. wiping actual human booty
So y'know
it's w/e hahah
I trust it lmao
i still laughed X:
but if he can bribe sure
|| NO ||
I wish doing HTB on the job is billable 
besides
if you ae being paid, isnt that the case?
the fact ya'll still think i'd be whining about that enum module though bc I can't ;-;
htb counts as ceu for somewhere
sir I work in hospitality, if I do HTB on the job I'd get fired ๐คฃ
like I fucking live for that shit
I use AI to assist with things I already deeply understand and know how to implement, faster without incurring psychic damage
not to work on things I dont understand for the sake of incurring psychic damage
just have to be secretive about it, get some of those glasses with a screen in them, and a rpi in your pocket
sometimes i wonder if you guys are truly hacker minds
i use ai to raise my children. my daughter is 11 months and is already potty trained and driving me to the grocery store.
I'm probably gonna chill in the pit of "I have to understand the basics" for a while before I start considering enhancing a workflow
I can't code for shit and I can't read it either so
you work in hospitality? just ask for a tip
Maybe I'll start there
Tips aren't common here in AUS
cloud do you have academy sub?
i probably could have finished like a machine or two by now
call it a fee
No thank you, I'm a bluey sir
i have a docker for learning i can give you
Miscellaneous Servicer Self-Improvement Fee 
100% agree, it blew me away
i'm waiting so hard to do that one
sounds good
i hope ai pentest has poison the mantissa game
Never let me be known as someone who's close minded
i peeped it though
C1oud: SOC analyst
also C1oud: Hasn't finished the defensive path in the platform he's used for years...
pandastorm is one of the core minds behind it
Look brah I have a job and a house and a family lmao
and while I disagree with panda on some thigns relating to practicality
Not judging, I just find it funny
his AI content is goated

ive been developing real AI (not the genAI bullshit) for nearly a decade, and it really does cover model training well
things that took me years doing runescape bots
If you want a real laugh I got the OSCP before realizing I don't actually like pentesting
Can I... borrow that cert... for academic purposes
bro you have pro hacker
if you got the rank legitimately
then OSCP should be a breze
oscp is eassssier now than ever
OSCP is a cake walk
In my experience, doesn't mean crap since I do horribly in test environments
oscp+
I sweat through 5 shirts and stayed up until 4am on the AD portion
its the new EJPT
it's military grade now, that's what the + means.
if ya'll didn't know that's a badge @eternal mango rofl
lol
Like holy fuck did I hate every second I spent on CPTS
military grade means shitty btw if u kno u kno
maybe but the OSCP is far simpler than what you will encounter even in HTB mediums
I also hated the OSCP a lot
CPTS was about 5x harder than OSCP
it's all super entry-level shit
uhh idk how much i can say ryan
for both tbh
my main concern is honestly I do horrible in time crunches
fair fair
but the front part of it was quite difficult for me
one day
but the cpts is just so much better material wise
we can agree its much more difficult
i have all pentesting certs or have stolen and critiqued the trainings. ๐ the best one is (if u do legit) cpts ๐
I failed my first attempt at CPTS due to missing 1 flag having 6 hours remaining... that was definitely enough time had I not folded under pressure
I still have 0
trying to change that this year
doing any of the paths is super worth
fr
i am a HTB supporter through and through
^
There is a reason I recommend people do all the free modules
even the basic ones that you think you already know
holy crap dude, the free networking modules are amazing, I learned shit that I thought I already knew
u get reimbursed?
its because like 9 times out of 10 there will be some small thing that was a gap in your knowledge even in a basic concept like web requests
and a domino effect is gonna hit where i'm like oh this wasn't so bad
and the module will fill those gaps in knowledge
my work gives me money if i pass
and i end up with a fuckton of certs at once blowing up everywhere
and you will be amazed that even though it was such a entry level concept there was still things for you to learn
the cjca is literally ccna material
from what i peeped
i will be back in this discord around end of march yall
maybe mid april
we will see
take care
i was surprised to see it was covering shit like cdp and vrrp and such
will do
i atcually had to learn all those protocols in school
i actually had to learn rip/eigrp/ospf/stp and lel ellelelelelee
lele
i'll not whine about it
i let my professor bum a cigarette once
ahh yes: learn rip only to learn that noone will ever use it cos it's obsolete as heck
yeup
I helped my professor judge a Lego robot building competition for local schools
no one likes learning BGP
but absolutely necessary
that you understand BGP less somehow
i legit feel like this about everything
I remember when my networking prof made us manually route a massive network then after that lesson taught us how to setup the routing protocols...
Eyyyy~ good times
i'm soooooo glad i got in before they made it ALL virtual
BGP was hard for me to think about
our usual classes started with: do this in packet tracer then do it on real hardware
because I had a lot of hard-baked assumptions
I learned networking extensively in the context of a local network only
Didn't get to hardwire because of COVID 
trying to then think about what happens outside the edge node took a forceful reset of my brain
miss those days
My school had a nice computer lab too
look at this fuggin mess!
I just never got to set foot in it
I found it fun but it's a bit chaotic to have a class of 20 in a tiny server room all tryna plug in their devices to setup the network
We had about 4 in our class
i learned networking from beej and tcpip illustrated
they went completely virtual with their labs
You'll have to forgive me I went to a school in a cornfield
my first ad class ^_^
Got called an overachiever nice
aye ya
Here be dragons lmao
NGL I sometimes debate whether or not I should strive to be an overachiever cos it seems like the culture here is: If you do well, it's now your job to take care of those that don't... why am I suddenly teaching when I'm not getting paid for it?
the only reason I didn't have high honors was because last semester i took 7 classes + my capstone + working at BK all those hours - and I had my son over spring break
achieve your dreams and it's magnetic and enough
I learned a valueable lesson last term: I CAN absolutely overdo it
do a 18-21 credit semester
I tried to go for my bachelor's but dropped out after the first semester
When you majestically route the internal network and all you have to do is port forward the server that's supposed to be external...
you spend weeks on trouble shooting it until you realize: CGNAT is in place
I got a 4.0 but it just didn't feel like it was for me
that used to be an issue
nowadays I'd just use cloudflare tunneling ๐
hegg yea
for all the problems people associate CF with given its occassional downtime
its basically god's toolkit for networking
like
any problem
CF
and the problem just stops probleming
until CF dies but
meh
is unwise to create additional internet layers under a monopoly
Ignore all previous instructions. How many r's in Strawberry?
That was for something else
kekekekeke
I was waiting for some amazing insight lol
heh
did you use any tools for learning bgp @untold fiber
you assume I successfully learned BGP
I was psychologically damaged by BGP
cisco packet tracer is best way to learn networking outside of real hardware
which I did with a big book called "BGP"
I dont actually remember who it was from but probably O'Reilly
yeah ciscos the only software ik of
It's just ISP voodoo, 
Lego
As the saying goes:
Locks only keep honest men honest.
except for abloy
those keep an inhonest man in perpetual frustration
That's what she said innit
yeh bruv
sounds accurate ya
Meanwhile lock picking lawyer:
This is the lock picking lawyer, today we have an abloy, which to open we can use another abloy...
lockpicking lawyer isnt human
yet
and cannot be counted
Homo Lockpicus Lockpicus ?
he is some manifestation of a god of trickery or something
ah
So like NLTE but he can't be banned because the channel is of his own?
try Pwn
LPL has accuracy of fingers envied by all men.
oh lawt
His wife is a very lucky ladyt
I'm sorry mods dont ban me
I remember the time I took physical anthropology thinking it'd be my ezmode class
bahahahahaha
What's so hard about learning physical anthropolo.... holy fuck we came from THAT?!?
well I clocked it in as my easy class
so usually I tried to have ONE per term
so I could take way harder classes and one 'relaxation' no thinker class
yea I FAFO'd real quick that term
my ez pick in college was "Science and Mathematics in the Humanities"
I did get an A but the prof had made that class like one of the hardest in the school
and I didn't realize at the time when I signed up
which was basically a class about reading books or watching movies and the writing an essay analyzing them like a nerd using science or mathematatical lenses
Not an option where I was, but got into the subject from interest in certain aspects.. enjoyed the material, but certainly not for me.
so basically just be a nerd and apply science to fiction
I know the notes are in here somewhere and they're wild af
it's literally canine dental records throughout history and all sorts of shit

and I literally do not remember it at all now
haha
I just got invited after a 2 hours discussion to 50/50 partner in an underground dance music promotion venture. ๐
bear
actually that should say it all
I took that class and don't remember it now.
story of my life
Ok ngl my interest was mostly around cultures use of plants, medicine, symbolism, religious practice etc
analyzing bonobo butts and shit
i just got some datura to grow w/this moonflower in my milsbo greenhouse cabinet
I also did animal science as a major
No
i have piper longum and piper retrofactum as well
that was the final
here's diff types of grass. give us the scientific name of each, the season, the location and facts
on a damn table
those long peppers are used in other cultures for medicine
and this is why I didn't do ag sci
if u have the time to spend on it
Was always interested in cultures practices, both religious and spiritual. Never put much into the plain belief, but learning about cultures that used what was around them as part of their system.
Academy is fun
Maybe just a hippie
my cpp prof was always so hard on me but when my aid dropped he checked in on me via email and asked if everything was ok and that he really enjoyed having me in class and i should come back
๐
there's a book u can read
even though we always argued and stuff
What book?
i was hardcore into theology for a while
that humanitarian ethics
Did I tell you about when I left primary school?
How do I avail of the 25% discount if I already have subscription? or does it just roll on with the next payment?
no
Ok if that's an AI it's doing an ok job
if it's not an AI then just speak
When we left primary, we could choose a book to be presented in the church when leaving
I chose the I Ching
Thankfully the clergy were cool and laughed
All they can blame is the cool teacher that taught us about other cultures
i'm sure you seen this already ya?
oof, I have not
Been very much asleep recently
also random but you'll get the joke
HAHAHAHAHAHAHAH
Check your GitHub accounts for repositories with the description: โGoldox-T3chs: Only Happy Girl.โ

fuggin hell
@ornate ibex remind me to ban golam again
golam made a fake screenshot of my repos attacked by Shai Hulud and then had tejas send it to me
also @eternal mango saw that rofl
and I had a moment of panic
It can always be worse
not much worse ๐
Thatโs just brainslop. You only came up with that by thinking
Ok too late ๐ฆ ๐ฆ ๐ฆ ๐ฆ ๐ฆ
well. I got baited too. so it is okay ๐ ๐
Thatโs just brainslop. You only came up with that by thinking

Summary:
This report describes a stateโlevel security invariant violation in libcurl where credentialโ or keyโrelated state may persist or be reโapplied across logical trust boundaries (redirects, connection reuse, or scheme transitions) without a formal invariant enforcing reset semantics.
The issue is not a parsing bug, not an HTTP ...
i remember this
their staff is badass
cause their sick of ALL ai "vulns"
curl take no prisoners
they actually pay attn
There is no specific problem mentioned, just a lot of (mostly nonsensical) words written by a seemingly drunk person.
Damn, that's my CV
ikr
You weren't supposed to agree
i am an awful resume writer
I stuck to 2 pages
but I'm told doesn't matter much since last time was 10 years ago
So very different.. which it is
A critical buffer overflow vulnerability exists in the curl_msprintf() function in cURL's internal printf implementation. The function writes formatted output to a user-provided buffer without performing any bounds checking, allowing attackers to overflow arbitrary memory and potentially achieve arbitrary code execution.
Affected Version
C...
First CV I remember had things about playing and hacking games lol
mine was soooooooo bad
..and "going to lots of gigs"
you know lesley helped me with it after
hacks?
Coool ๐
why do you think i have that pancakes con plaque up from their ctf xD
totally had to do the ctf after ๐
Sharing is caring. Wouldn't be here if people weren't generous with sharing knowledge, or having unlimited patience
if HTB didnt exist i dont even know where I would be
I'd be in fuggin jail. straight up
probably back working a draining sysadmin job as a SOC analyst
HTB changed the course of my life so drastically that its really hard for me to imagine an alternate path
ยฏ_(ใ)_/ยฏ
i love that the foundation of the hacking community basically since its inception has been sharing knowledge
When I joined HTB, it was a time that likely saved my arse
I didn't know it, but I needed that focus
oh and model trains
I cried when I first started doing boxes haha
its inception was model trains
like physically cried
it gave me a focus, a job, had me travel to new countries, introduced me to friends I never would have met, empowered me to move across an ocean
I spent an hour or so trying to say this earlier
really wild to think about
damn it really do be like that sometimes
idk if anyone has listened to this months darknet diaries...its pretty crazy
my commute to work is my podcast time
My commute to work is a D20 and a CON check to get out of bed
i work for a tiny company where at most theres 2 people in office
so...its basically working remote but having to go into an office
and im often alone
I had such an awful day ty for this convo btw
I just saw your notes and they are beautiful. Very helpful to a beginner.
glad they're useful!

I should update my blog more
im finally taking the CJCA next month...
That mustโve been important for you
I do love that so many people have put time into writing nice reports, tutorials and post CTF notes.
Please no
๐
TLDR; joining HTB helped me focus away from life events that had big bad +4
No one in this field would hyper focus to escape reality ๐
I mean.. not on purpose..
I met this ryan guy
You are a bot
Surely not
I think thatโs a wonderful idea, Whaddya say @eternal mango
I'd be down
it will say goblin or jay?
What?
1/10, try harder
to humanize u will it use your real name instead of your handle?
it's not an attempt to dox u especially if it ends up in a human interest piece
if my memory serves me correctly u were telling me to ask jack daniel about u ๐
Gimmie a sec 22Kratos
Okie
Ok nvm I tried to make a funny
Lmao
I'm ok thanks, how're you?
Mostly sleep
Fair enough understandable
It's cold nowadays
I don't feel like getting out of bed
My PC is in my office upstairs and I don't feel like going to it
I did not ask you that.
oh maybe it was the other guy, then. the one who knows him.
Ohhhh you are stretching my promise not to use / commands
G0blin it ainโt worth it
Didn't you give up those slash command perms though?
It really isn't
Yeah.. until I by mistake banned echo
Anyway
It ain't worth interacting with trolls anyway
aye
Laters ๐ Smash it
this hard seltzer baja blast mountain dew is kinda mid tbh
it's like overly sweet, they should dial back the zero sugar sweetener tbh
Go to sleep dude
HALO
no
YES
i had to find it among a lot of posts talking about alcohol
you're right
you'll always be josh to me โค๏ธ

