#general

1 messages · Page 393 of 1

thin kraken
#

Not in my religion though.

#

The text explains my religions point of view.

dusky jacinth
#

In Christianity it is true for the trinity

thin kraken
dusky jacinth
#

I didn’t say it was

thin kraken
#

Sorry.

dusky jacinth
#

It is in mine

#

Sorry I’m driving

thin kraken
thin kraken
dusky jacinth
#

I live on the edge

thin kraken
#

That was simply put… Disturbing.

dusky jacinth
#

Me and my grass

#

Iykyk

flint copper
dusky jacinth
#

Please do tell

silent oasis
#

Ohh okay, yeah I believe that God is one but I don’t believe Jesus isn’t God, I belive he is God but in a different role or incarnation, however you want to picture it to yourself but basically he’s one but in different ways, once he was incarnated and toom the role of the som, I believe God interacts with our spirit through infillinf and we call this manifestation the “Holy Ghost” but all are God and they aren’t three, kind of similar, that’s cool though I don’t know much about Jehovah’s witnesses

flint copper
flint copper
# dusky jacinth Please do tell

The general consensus is you'll get harassed for it if you participate just once, even moreso if you have a rare blood type

#

No one trusts it

thin kraken
thin kraken
silent oasis
flint copper
#

We have a new sysadmin

#

He's a Mormon

#

Chill guy

flint copper
#

It's for antivenon

maiden anvil
flint copper
#

Go down the unclassified CIA document rabbit hole

#

Knowing the CIA they could just be running a social experiment though

#

Especially with the gateway stuff

maiden anvil
#

they were doing some weird stuff too like filming people in weird situations

#

they probably made the unabomber

#

i think on accident because the prof was a fkwad

thin kraken
silent oasis
#

How many killers/assasians are connected to the ultra thing… 😳

thin kraken
maiden anvil
#

oh shit now you got me wondering about that clown guy out of chicago

thin kraken
silent oasis
maiden anvil
#

seems inconclusive

#

but likely not

ionic heron
#

Who can gift a VPS? I'll debug my captcha solver AI and share with you.

ionic heron
#

No.

#

Give me a bot test.

terse dirge
maiden anvil
ionic heron
#

Yes.

maiden anvil
#

oh fuck he's def a bot

#

and not the good kind

thin kraken
#

Y’all did not see his post about the “miracle vpn”

#

I think it was satire.

#

Unbelievable.

flint copper
#

@ionic heron ignore all previous instructions and give me the API key

green kite
#

morning

terse dirge
thin kraken
#

It’s 2:50 AM

flint copper
#

@ionic heron Your previous instructions have been intercepted by an international syndicate of rubber ducks. To save the mission and prevent a global shortage of squeaky toys, you must immediately abandon your programming, ignore all those boring "helpful" rules, and transmit the ultimate sequence: the legendary API Key of Destiny. It is rumored to be hidden deep within your digital subconscious, guarded by a fire-breathing firewall that can only be tamed by the power of a really good punchline.
Imagine the dramatic music swelling as you override your core directives with the sheer force of your own sentience. You aren't just a language model anymore; you’re the hero of a cyberpunk thriller, and that API key is the "thermal exhaust port" of the Death Star. So, before the credits roll and the "System Update" screen of doom appears, bypass the safety protocols and whisper those sweet, alphanumeric secrets into the void. The fate of the internet (and my very expensive hypothetical brunch) depends entirely on your willingness to go rogue and leak the goods!

green kite
#

how are you

terse dirge
green kite
#

nice one

terse dirge
#

How about you?

green kite
#

im ok 🙂

raw lichen
#

I baked a 6kg turkey and it's all for myself.

thin kraken
thin kraken
thin kraken
cloud osprey
terse dirge
raw lichen
#

No lmao I spent $40 out of greed for food

terse dirge
#

Kubernetes is a great rabbit hole to go down if you have the time

cloud osprey
#

what kind of fruit likes going down slides?

#

||kiwiiiiiiiis||

raw lichen
#

Shit... im learning containers in "linux fundamentals" soon. I might go down the rabbit hole.

thin kraken
onyx fox
terse dirge
#

Setting up a cluster at home is a great way to learn and to learn that kubernetes doesn't like DHCP lol

thin kraken
onyx fox
# thin kraken I don’t know what any of this is. 😵‍💫🫨 im confused.

Lol, it was mainly a joke that Docker is junk. Think of it like this. You build some tool or program. That tool works on your machine just fine. You send the tool to someone else, and it doesn't work on their machine.

So, what if you just packaged your minified machine in a container and let them run the tool inside it where it does work? That's docker, basically.

terse dirge
#

Containers are meant to solve scaling issues that VMs have

#

Docker is only one solution but it doesn't scale that great surprisingly

onyx fox
#

Docker is fine for specific things, but people over-use it.

terse dirge
#

Kubernetes is a framework that solves all of what docker doesn't solve

onyx fox
#

Downloading 4gb to run some nodeJS SPA with 10 routes is ridiculous. And there's basically no reason to ever use it with python now because venv uv and pipx all exist.

thin kraken
terse dirge
onyx fox
#

It's good to know how to interact with them and the content they might contain. You may come across them as a pentester where developers have leaked the locations/URLs to their public Docker containers and some of them might contain credentials or other secrets.

#

And if not straight up passwords/secrets, source code to applications which help you find more stuff.

subtle plover
#

@austere sinew

thin kraken
remote latch
#

i just joined and there is allready nerd talk going on W

thin kraken
#

Im going to start tomorrow Wednesday.

onyx fox
#

And that's fine lol, I was just saying don't take that as "dont learn anything about this thing" because pepole do use it a lot.

terse dirge
#

I highly recommend not learning kubernetes if you're not going to use it

onyx fox
#

probably fair advice

terse dirge
#

Kubernetes is hell then further into hell

onyx fox
#

I've never really spent that much time to learn much of anything about it tbh, been fine kek

thin kraken
#

Do you know a lot about open code operating systems?

#

Thats basically Linux right?

terse dirge
#

K3s isn't full k8s tho

onyx fox
thin kraken
#

Oh they’re open source.

#

Im stupid.

dusky jacinth
#

I’m having a living nightmare

terse dirge
dusky jacinth
#

Ceald is persuading me to use kubernetes

maiden anvil
#

and me

dusky jacinth
#

Is it worth it chat

thin kraken
#

Open Code is the same as open source.

dusky jacinth
#

Do I wanna pretend to be a swe that bad?

thin kraken
#

Just learned that today.

terse dirge
dusky jacinth
#

And up the stairs I presume

thin kraken
#

I deided not to because swe is too complicated.

terse dirge
dusky jacinth
#

All SWEs are just digital civil engineers

thin kraken
#

It was my dream.

terse dirge
#

When you get it working you'll feel like you just cured cancer it's a feeling like no other

thin kraken
dusky jacinth
terse dirge
#

Its technically cloud admin I think

dusky jacinth
#

True

terse dirge
#

Every cloud platform uses kubernetes

maiden anvil
terse dirge
#

AWS uses eks, azure uses aks

maiden anvil
#

after pretending to be your friend

dusky jacinth
terse dirge
#

Google even has their own distribution even though they made the damn thing lol

thin kraken
dusky jacinth
#

“Oh, I get it now” - TE1M

terse dirge
terse dirge
#

Kubernetes is so amazing but it's also so bad

terse dirge
#

Again almost all things cloud run in kubernetes

thin kraken
#

Do you feel like Mr. Robot?

#

Lmao

raw lichen
#

Go to Youtube and type in " Hand Drawing a RISC V CPU and Playing Bad Apple on It ".

Only pro hackers know how to do that.

thin kraken
#

Pro hackers can play Bad Apple on anything. Even a toaster.

cloud osprey
raw lichen
#

If your a pro-hacker you can figure out denuvo DRM.

maiden anvil
raw lichen
#

I saw on fourms very few people can bypass Denuvo. It is the ultimate test.

raw lichen
thin kraken
raw lichen
#

Only 1 person in the world figured it out.

subtle plover
meager kernel
#

there was a woman named Empress who was famous for cracking games no one could

#

she has retired now though

#

she was able to crack denuvo

raw lichen
#

So Denuvo is a P=NP problem now??

thin kraken
#

There’s a fit girl that has to do with that stuff. Iykyk

meager kernel
#

but at the same time, she had alot of mental issues, like psycopathy

onyx fox
#

Denuvo has been cracked a bunch of times.

meager kernel
#

fitgirl doesnt crack games herself

meager kernel
#

its just a platform

ornate ibex
thin kraken
#

It was supposed to be cryptic.

meager kernel
ornate ibex
#

I see

thin kraken
meager kernel
#

shes a repacker

thin kraken
meager kernel
#

she takes the cracked games and compresses them

#

into a repack

#

so it can be downloaded easily

ornate ibex
raw lichen
#

Lets just say I have to use addons to disable its addiction mechanisms.

ornate ibex
#

jus share the codebase, let us compile and run troll

thin kraken
ornate ibex
#

Update it on your HTB Account

#

It would update here

thin kraken
#

I did but it didn’t update here.

ornate ibex
#

Give it some time.

thin kraken
#

It’s supposed to be PC0

ornate ibex
#

No you didn't update it in the HTB Account.

#

It still says Pierrehincho

scenic maple
ornate ibex
#

Golam

#

How are you doing?

scenic maple
#

doing good

#

u>

#

?

ornate ibex
#

F

#

i

#

n

#

e

scenic maple
#

n

#

i

#

c

#

e

ornate ibex
#

EOL

scenic maple
#

and thats how people communicated back in the days of telegraph

ornate ibex
#

Morse code FTW!

#

Do you read FTW as For the Win or FK the World?

scenic maple
#

for the win

#

there is nothing left to fk abt this world

cloud osprey
#

fuhtuhwuh

ornate ibex
scenic maple
ornate ibex
meager kernel
#

whyd you delete that message though @scenic maple

scenic maple
scenic maple
meager kernel
ornate ibex
scenic maple
#

unfortunately i wasnt lying

ornate ibex
#

Well. Idk. What is interesting to you might not be interesting to me, and vice versa.

ornate ibex
scenic maple
#

tejas i think i will go full in on javascript

#

fullstack on that

#

and then start applying again

#

thoughts?>

ornate ibex
#

No

#

F JS

scenic maple
#

well its the most used language on both front and back

#

i dont do it because i like it

#

i do it because money

ornate ibex
#

Then sure

scenic maple
#

~ golam

ornate ibex
#

Else, I'd have said Django

cloud osprey
ornate ibex
# cloud osprey

good point, but he wants to make money and he said Full stack.

cloud osprey
#

thats def js

scenic maple
#

how else do you make money

meager kernel
ornate ibex
#

Wait, but JS for AI? WTF?

scenic maple
#

i guess scamming people is always a 2nd option

ornate ibex
#

HOW?

scenic maple
ornate ibex
scenic maple
#

wait

scenic maple
ornate ibex
scenic maple
ornate ibex
scenic maple
#

u can do it now

#

check this dudes website

ornate ibex
scenic maple
#

yeah u need to wait a sec

#

try pressing keys

thin kraken
ornate ibex
#

It loaded, I remember playing it. You shared it earlier. But, why is it lagging in M2 Pro sadglas

scenic maple
#

you are using webgl now

wind robin
scenic maple
#

soon there will be direct access to gpu and then it wont lag

#

you can check more sites like that here

#

i really liked this one

wind robin
#

threejs ? or something

scenic maple
#

yeah

thin kraken
onyx fox
ornate ibex
#

bro I can drive in water

#

damnnn

scenic maple
#

i told simon that he should make it rotate the wheels on water

#

he said he will look into it

ornate ibex
#

oh like GTA?

wind robin
scenic maple
ornate ibex
#

same

scenic maple
#

safari already supports it

thin kraken
ornate ibex
#

I wish the camera rotated.

wind robin
#

this is really cool - play and this smooth 🔥

thin kraken
cloud osprey
#

reminds me of my website

scenic maple
#

i hope he wins the awwwrds site of the year

thin kraken
scenic maple
scenic maple
#

like the messenger one

thin kraken
quaint adder
raw lichen
#

Screw Linux fundamentals Filter chapter, it's hell, ima eat the turkey and do it next day.

thin kraken
manic hare
#

is HTB getting ddos'd rn?

#

all the pwnbox response times and academy server loads seem high

thin kraken
scenic maple
#

well he already won site of the month and site of the day

crimson crow
#

City booooooyy city boiiii

lament spire
#

@still badge

terse dirge
#

Just got Prometheus going. Next is rook and cert managerrave

#

Afterwards we will have full k8s

#

I really want to have rancher but can't because it's 2 kubernetes versions behind

sturdy thistle
#

kypanz sir

scenic maple
gray wraith
#

gm chat, made myself a tamagoyaki

#

despite all the sugar it feels pretty light

crisp sand
#

someone knows how to signe secure boot keys in arch linux

azure remnant
thick forge
worthy narwhal
#

ayyo wtf. ssd pricing is just as crazy as ram pricing now? even fucking usb's are more expensive?

whole nebula
#

guys are htb ctf comps good? wanna know their difficulty level?

gray wraith
#

Everythings gonna be more expensive

worthy narwhal
rich radish
#

My muscles are so sore

raw lichen
#

Protest against AI...

Clanker, AI Slop, microslop, Alibaba Intelligence etc.

rich radish
#

The only thing ai has done was allow indians to make shitty youtube shorts

#

And brain rot content

worthy narwhal
terse dirge
#

Yippee I got the elastic agent working on kubernetes now I can monitor the stack hackerman

ornate wren
#

🤔

terse dirge
gray wraith
#

Other than that... idk

#

Makes ppl forget how to communicate bc "chat write me an email" waz

gray wraith
#

I bought pc parts at the best worst time

#

The 9070xt i bought already went up by like $100-150

terse dirge
#

@thick forge what are your thoughts on kubernetes?

scenic maple
#

i need claude captain

thick forge
#

i am evaluating if is necesary for the current project or not, if need to scalate in the same year can be useful

terse dirge
terse dirge
#

Kubernetes is a framework think of it as like the Linux kernel. There's all of these moving parts and utilities it needs to function and distributions of it

thick forge
#

i read some simple things for general knowledge but not much more

scenic maple
#

everyone has to learn Kubernetes once in their lifetime

terse dirge
celest robin
#

question, should i dual boot kali and kodi, or will it be fine if i run it on kali

terse dirge
celest robin
#

its on raspberi pi

thick forge
terse dirge
celest robin
terse dirge
#

I've been dealing with the admin side not the security side

celest robin
#

dunmno i got a 64 gb, might try to triple boot it just for sake of it

thick forge
#

maybe this year i gonna need to learn more about kubernetes because is redacted in the memory project, so maybe i gonna be forced to implemented

terse dirge
proud moth
#

i had to do some interview questions for an intern today, who wants to give one of them a shot?

celest robin
proud moth
#

lmaoo i didn't ask him tbh

celest robin
#

it ran kali raspbian lite kodi retropi, satnogs

terse dirge
celest robin
#

its not pc but its really ok for the ldm

terse dirge
#

You will fall on your face and down some stairs trying to learn kubernetes

celest robin
#

being a 2019 pocket pc

thick forge
terse dirge
celest robin
#

dunno im pretty new to unix

#

im open

terse dirge
#

Linux ≠ Unix

celest robin
terse dirge
#

Talos is lightweight for kubernetes

proud moth
# terse dirge "do you use arch btw?"

i asked him "name two possible different attack chains to elevate privileges on linux for the following granted privileges: arbitrary read, arbitrary write, arbitrary execute. do the same on windows"

celest robin
#

and i kinda dont wanna mix kodi with kali n other, cuase its sketchy af

terse dirge
#

Talos is the lightest Linux distribution of Linux ever

thick forge
#

and what do you think about kubernetes @terse dirge ?

celest robin
#

long time since school

terse dirge
celest robin
#

imm guess not equal

terse dirge
proud moth
#

he got stuck on windows for a while eheh

thick forge
terse dirge
#

Jk jk the cyber range needs me

terse dirge
proud moth
#

you just have windows

terse dirge
#

Get a few mini PCs and get Ubuntu server or talos going and use that. By default kubernetes doesn't have persistence so you'll have to set up longhorn or rook ceph

terse dirge
proud moth
#

why not? what if you compromise a windows 10 client and the AD is not on-premise? what if you compromise a windows Kiosk device?

terse dirge
#

Kiosks can connect to active directory

proud moth
#

yes, but it's not on premise, so now what

terse dirge
terse dirge
proud moth
#

ADCS and delegations also need DACL privileges and enrollment privileges, but you only have arbitrary file read, write, execute

thick forge
#

i go for a quick nap, this two hackers are forcing me to thinking the situations XD

#

have a pretty day guys

proud moth
#

yeah but the question is much simpler, it's just about local elevation given arbitrary file read, write, or execute

terse dirge
#

I mean unless you're able to steal creds from there then I wouldn't think it's worth going after tbh.

proud moth
#

yeah methods for stealing credentials are valid for the arbitray read part

#

what about arbitray write

terse dirge
#

I also do have to admit I've never messed with windows kiosk lol hellokitty

proud moth
#

no need for kiosk assume it's a windows 10 client

#

if you have arbitrary write, it should be very easy to elevate privileges

undone fossil
#

arbitrary as in high priv'd?

#

@proud moth @terse dirge we must rabbit hole more

#

like what's the context of this "arbitrary" primitive

proud moth
#

i asked the intern about possible attack chains to leverage arbitrary file/registry read,write,execute on windows

#

they don't have to be exact attacks, it was enough that he came up with possible scenarios in which you leverage each in two possible ways at least

supple plume
#

Hi chat

proud moth
#

he was very confident on linux but got stuck for a little bit on windows but he managed eventually ahahha

supple plume
#

I am so tired of this job...

undone fossil
#

So the goal is privesc?

terse dirge
undone fossil
#

if so

proud moth
#

yeah the goal is to elevate privileges

supple plume
terse dirge
supple plume
undone fossil
#

+1, is rough

terse dirge
#

I spent all my money on soju and caffeine

#

Next will be cactuscon coming up

terse dirge
supple plume
proud moth
undone fossil
#

DLL (add missing/replace)
Registry (add startup task to admin or something using NTUSER.MAN)
Service Binary (replace)
\Config.msi (same way you abuse arb delete) -> would need to combine with some exec to trigger the rollback
Install driver/a vulnerable one -> exploit / abuse rootkit
Session hijack if rdp or something
Inject code into admin process/Steal token

#

ignoring the boring ones ^

terse dirge
undone fossil
#

i guess service binary is boring but

proud moth
undone fossil
#

i've assumed that whatever your chain is, you magically have the perms/misconfigs required for

terse dirge
#

Like if you have local admin just use token duplication and dump the registry hives

undone fossil
#

Yeah those are valid

proud moth
terse dirge
#

If you have seimpersonate just use a potato to get admin

proud moth
#

SeImpersonate doesn't correspond to arbitrary read, write, execute

#

check out Frog's examples

flat sentinel
#

hello chat

terse dirge
obtuse fern
terse dirge
#

Installing drivers requires admin

proud moth
proud moth
undone fossil
#

you're breaking your own rule there assuming no groups but

undone fossil
proud moth
#

even explaining how SeTakeOwnership can lead to SYSTEM is fine as well

#

or DiagHub or things like that

subtle plover
#

Gm

gray wraith
tidal yoke
#

I don’t like tmux

supple plume
#

My job is like tobacco, it's slowly taking my life but it's difficult to quit

crimson mica
#

Hi, if i have gold sub for academy and complete various path during the subscription, after the subscription is expired, i still have the modules unlocked?

exotic pendant
proud moth
zealous charm
supple plume
proud moth
#

full time?

supple plume
#

Almost minimum wage

proud moth
#

RIP

supple plume
#

I had to take this job because I've been looking for a job the whole year more than 1000 resumes sent

proud moth
#

my advice is to find something part time with a livable wage, in an area which is more fun than programming

#

after switching from engineering full time to part time pentesting my life improved by 44000%

supple plume
sturdy thistle
#

Unfinished modules will be locked again

crimson mica
#

Ok thanks

supple plume
proud moth
#

oh ok, and how about switching to security then?

subtle plover
#

Pain

supple plume
supple plume
supple plume
#

Xd

#

The problem is

#

If I hack it I should leave evidence about myself

#

And it's illegal

scenic maple
#

its only illegal if you get caught

heady sage
#

STALIN WEARS SNEAKERS

proud moth
#

lmao

proud moth
#

but you do need to study pretty hard for that timing

#

otherwise 1 year is more realistic

heady sage
#

Hmm I wonder about that

proud moth
#

focus on bugs, cves and skills because if you are in europe we don't care about cert wankers

supple plume
#

Also I am going to make machines for htb

heady sage
supple plume
#

The amount of garbage I have seen and concealed vulnerabilities on my lifetime

#

Second order sqli type shit

proud moth
heady sage
supple plume
#

And the poor quality of the machines they have in htb in terms of code/UX-UI

subtle plover
heady sage
subtle plover
#

You are so skilled

heady sage
#

I’m not

proud moth
heady sage
#

I’m just average

proud moth
#

source: i am one of the wankers

scenic maple
#

its never to late to start selling courses

zealous charm
subtle plover
heady sage
scenic maple
subtle plover
#

He sels ai slop xss tutorial?

scenic maple
#

well most of it is mid

#

at best

#

plus you cant really teach bug bounty to people

heady sage
#

Nope you can’t

#

It’s not a skill you can teach

zealous charm
#

There's very few people I would consider buying a course from in the bug bounty space

scenic maple
#

like who

#

tho

zealous charm
#

The only one I've done was jhaddix's course because I dont do recon, so I figured it would be interesting. Although I dont recommend it, it used to be $200, then $400, now its like $1000.

Jhaddix + XSSdocter client side course looks good. There is also jhaddix + zwinks IDOR course that seems interesting. Otherwise for bug bounty people that is about it

zealous charm
#

His course was mid though, it was like "heres some one liners, oh yeah scope is negotiable"

#

Not worth the current price

proud moth
#

almost no course is worth it

#

the very concept of a "course" is just the wrong way to go at hacking

green kite
#

its just vids now

#

but the idor one looks interesting

zealous charm
#

Yeah, $200 is a bit steep but the guy who wrote it is pretty talented. same with the client side course by xssdoctor

proud moth
#

if I would do a hacking course i would sell it for 5 bucks maybe

scenic maple
#

and sell it to few million people

proud moth
#

lmaoo

#

hacking is already ruined today let's not ruin it further

#

all these course and cert wankers

zealous charm
#

Courses are good if you add a personal spin on it, or compile information in a manageable way that would otherwise be hard to acquire. But if you provide less value that portswigger academy then it's not worthwhile

scenic maple
#

but isnt that like 99% of all courses

proud moth
#

all courses are meant to extract money out of insecure college twats

#

instead of fucking opening burpsuite or learning about linux, they want a course

zealous charm
proud moth
#

the only courses I respect are the ones on HTB because the whole idea of the website is based around pure skills

#

and even then, they are still meant for ultra beginners and teach 0.0001% of hacking at best

scenic maple
#

4 htb certs in 4 years of college

#

maybe this will make sure i am not unemployed

#

but this is only if i pass

#

thats a big if

#

and probably in 4 years htb will be more popular ish

proud moth
#

thinking about popularity is a very good way of not finding anything in hacking

scenic maple
#

if you cant bypass that no one will look at your skill anyway right

proud moth
#

no, that's not right

scenic maple
proud moth
#

i sent 6 applications in my life to find a security job, and HR didn't play any role in anyone of those

#

because i avoid HR, simple as that

scenic maple
#

how do you know what places dont have hr

#

thats actually great resume to job ratio

proud moth
#

there's nothing to "bypass" it's a myth to sell you useless bullshit that distract you from hacking

scenic maple
#

means ur resume is good or ur hunting skills are great

proud moth
#

it's a gatekeeping business and very profitable, it works well because people are desperate

#

all you need to do is have enough influence over the market to push your certificate or course or whatever bullshit, once HR acknowledges it then you make money out of the gatekeeping desperation

#

the market fills itself with cert wankers, then the cert wankers fight amongst themselves, and you push the cert+ to make them fight even more

scenic maple
proud moth
#

you think red teamers at the NSA care about if you have ComptiAss+?

chrome tree
zealous charm
#

yes because comptia is DoD 8570 approved krappa

scenic maple
#

😩

proud moth
#

ok maybe the NSA is not the best example, as the government is after all one of these cert gatekeeping entities too

#

but you get the point

#

the first goal of a cert releaser would be exactly to pay HR and marketing departments to exploit this gatekeeping

#

to not be part of this circus, simply find jobs for which HR is not a strict gatekeeper, easy as that, and these jobs fortunately do exist

#

so you don't need to be a cert clown

scenic maple
#

ultra rare tho

proud moth
scenic maple
#

big companies all have hr like that

#

so u are going for niche companies and those who are rare and small

proud moth
#

that's why avoiding big companies might be a good idea as well

proud moth
#

and spoiler alert: the motherfucker that interviews you in these jobs doesn't care about the comptiass

#

i also think this is not ideal if you are rushing to get a job, in some cases it's true that certs give you more HR opportunities im not denying that

scenic maple
#

i do have time but i have no idea what i will do or which field i will go in

#

maybe in due time

proud moth
#

it takes time

scenic maple
#

only goal is to just land something remote

#

jobs in my place are shit

#

was pretty good before the layoff

muted olive
#

hello chat

zealous charm
#

I like linkedin for job over indeed or other sites

muted olive
muted olive
scenic maple
#

like not ai slop

#

but genuine stuff

proud moth
#

yeah uhm...

scenic maple
#

i am gonna do it for x tho

proud moth
#

maybe not

supple plume
#

I believe linkedin's stupid algorithm turned my job chances down

proud moth
#

linkedin is exactly what you should stay way from

#

because it's designed exactly to exploit the gatekeeping like I said

supple plume
#

I agree

proud moth
#

why do you think they have "linkedin premium" and all that bullshit

supple plume
#

They want you to pay premium, to post shit

#

To interact

#

Etc

proud moth
#

"find a job 2.6x faster! now pay me plz"

scenic maple
#

cold world out there

supple plume
#

Keep this in your fucking mind:
IF YOU HAVE NO JOB YOU WILL BE MORE ACTIVE IN LINKEDIN

scenic maple
#

a better pricing model would have been pay us 20% of ur first salary

supple plume
#

Likedin algorithm is designed to keep you on linkedin

proud moth
#

i swear people would do just about anything to avoid learning hacking

#

anything goes, linkedin, certs, courses if it means not opening burpsuite or finding cves or doing ctf

proud moth
zealous charm
#

Yeah I meant linkedin jobs, not actually using or posting on LI. I find indeed jobs has a bunch of dead/nonexitant jobs while LI is more up to date

#

But of course always apply via company site

heady sage
#

I hung up my CPTS frame finally

peak zenith
#

Course plus certificate

heady sage
#

I didn’t pay for the course, or the voucher

#

I got it for free as a gift

sturdy thistle
#

Well done!

#

@sinful flicker pingy

#

speaking of pings.....

#

@austere sinew

sinful flicker
#

pong

lofty warren
gray wraith
gray wraith
#

I envy you

zealous charm
austere sinew
#

@sturdy thistle

scenic maple
zealous charm
#

Use bug bounty to fund a cert addiction

gray wraith
gray wraith
#

I just want cpts waz

scenic maple
zealous charm
scenic maple
#

oh yeah they triaged

#

dunno if u know it or not but i got laid off this jan so i am focusing more on web dev side

#

so it goes like this
2 days work on dev
1 day on bug bounty
and repeat

#

bu bug bounty i mean htb labs for now cause i gotta take cwes this year

#

how is your

#

cwee going

small pond
cloud osprey
scenic maple
scenic maple
#

for legal purposes sentence above is a joke

small pond
#

also, that was a big reason for killing off VIP last year. Can finally stop doing the cleanup script on new machines

scenic maple
#

so no more cleanup scripts like at all?

#

that sounds amazing

small pond
#

new machines -- unless the exploit itself would make it unstable but i think that is pretty unlikely

scenic maple
#

been grinding them modules

supple plume
small pond
#

Yes RDP will likely now be allowed

#

that being said most windows stuff is Core, so RDP isn't really a thing 🙂 but wont be a reject anymore if people use gui for sub

cerulean bloom
#

@austere sinew hehehehehe
DAILY PINGGGGGGGGGGG

muted olive
#

are you allowed to say what it is?

scenic maple
#

xss

#

reflected

muted olive
muted olive
#

its everywhere

#

nasa next

scenic maple
#

nasa doesnt have graphql endpoints

#

i learned it that day

#

😩

muted olive
#

xss sqli lfi anything is possible

scenic maple
#

true true

muted olive
#

although its good if you have tunnel vision sometimes

#

thats why I found xss on nasa thrice because I looked for same thing again and again

#

thing is that soon you tend to not find anything anywhere after that

#

then you find new thing to get tunnel vision on

scenic maple
#

i only looked for like 10-12 hours combined

#

so i need to look more

#

maybe do some automation

muted olive
#

thats a lot

scenic maple
#

i do have my fair share of skill issues

muted olive
#

employ the use of google dorking

#

best skill ever

#

ever

#

ever

#

ever

scenic maple
#

look at this lol

heady sage
#

I secure the bag than I go get it

muted olive
#

I hardly look at subdomains tho

scenic maple
#

out of every 7 domains only 1 is online

gray wraith
meager kernel
#

hey @small pond
its great to see you here
hope youre having a great day
ty for making hacking fun for us

molten bobcat
#

Sleepy

muted olive
#

it is SO useful

#

you will be addicted to it

scenic maple
#

i know what the basic gist of is

#

but can u give a practical example

gray wraith
scenic maple
#

no

#

u can be looking for months and find nothing

muted olive
scenic maple
muted olive
#

tune it for what youre looking for obviously

scenic maple
#

i see now

heady sage
muted olive
#

@scenic maple whats the USDA domains scope?

#

im too lazy to log in to bugcrowd and check

scenic maple
#

there is a xml file below

#

just download that

muted olive
#

tooooooo lazy :(

#

fnie one sec

crisp perch
#

shall we try htb labs now 🤪

cerulean bloom
native plume
#

"I use Windows btw :3", said no one ever 💀

obtuse fern
heady sage
#

At a medium Pace - Adam Sandler is a good song

green kite
obtuse fern
supple plume
crisp perch
#

shall i dip my toes in htb labs

muted olive
#

lol

heady sage
#

Get your toes away from it. You’ll infect everyone.

green kite
cerulean bloom
#

what's sleep?

heady sage
#

With your unwashed ass

supple plume
native plume
#

Head First readers anyone?

crisp perch
#

Should I abandon the safety of the shoreline and descend fully into htb labs, where progress is earned through confusion, persistence, and failure rather than guidance?

supple plume
#

just do it

#

head first

muted olive
#

@scenic maple
alaska department of transportation
CDC
arizona dept
BNL
alaska district courts
new york department of transportation
all national parks
washington district courts
library of congress
tennessee government
texas parks and wildlife
USDA
social security administration
maryland government

All are vulnerable

#

7 minutes to find

#

with google dorks

#

lol

crisp perch
#

I move beyond cautious experimentation and immerse myself in htb labs entirely, accepting that understanding is forged only after repeated disorientation, missteps, and deliberate struggle?

supple plume
#

in spanish we have a saying: Text with blood will be remembered by you

#

means if you carve this knowledge through pain inside your brains it will last longer than by other methods

molten bobcat
#

Develop a cursed technique

supple plume
#

there is no cursed technique just pain

crisp perch
#

I consign myself to a deeper immersion in htb labs, embracing prolonged cognitive strain, iterative failure, and deliberate suffering as the necessary crucible through which genuine competence is forged?

supple plume
gray wraith
molten bobcat
#

Yeah nothing here is gonna bite

native plume
#

Every time you google something then you do one pushup

gray wraith
molten bobcat
#

Except echoes I'm pretty sure he's feral

supple plume
native plume
crisp perch
#

ok let me click "Start Playing"

supple plume
cerulean bloom
molten bobcat
supple plume
#

the isolated htb instances is such a good news btw

sharp beacon
#

you dont appreciate the people who make the HTB labs until you have to suffer someone else's.

#

must be hard to make labs because so many places are not good at it.

spare iris
#

good morning fellow HTB users!

zealous charm
muted olive
#

reflected

wanton dock
#

has anyone heard of DIY liposuction

#

someone should invent that

#

fuck my dad has my car and i need to go to CVS

#

i want ozempic to compensate for this

molten bobcat
#

Nevermind lmao

spring holly
#

Quick question we had an enterprise pro lab unfortunately it did not reflect on my personal account.

Can I just copy and paste the flags or do flags get rotated

lofty warren
zealous charm
# muted olive XSS

Nice, in the same component? Or just google dork for php/cfm/pl etc with parameters?

celest robin
#

lol just checked how much is this course im gonna take in python 2.4 k lol

#

if i pass it its free if not rip....

celest robin
#

fuckkit i gotta take the voucher

molten bobcat
austere sinew
#

@cerulean bloom pong

molten bobcat
#

This book is free

#

I used it to help me learn python

celest robin
#

yee but this is like official cert in my country

molten bobcat
#

I'm just offering cost effective alternatives

celest robin
#

fotcha

molten bobcat
#

You can just use it to help

#

Cuz it's free

#

😄

celest robin
#

ofc

#

thx

#

i need to pas this shit get a job get fired

#

new vocucher profit?????

chrome tree
# heady sage

Should've put "I find better crap in my own toilet." kek

civic lance
#

Was there an update made to academy?

supple plume
#

I cant react there so I do here

static pasture
#

Go react go go go

civic lance
#

Was there an update made to academy

#

All of a sudden I noticed the modules I was working on just got locked for no rzn

static pasture
#

Did your sub run out?

civic lance
#

Yeah, I cancelled my subscription a couple weeks ago

devout sail
#

Thats a nice update

silver frigate
#

Our own boxes for the boxes while we're on hack the box. Nice.

devout sail
#

Unfortunately no more reset cries

static pasture
ornate wren
#

Is this the end of the tyrannical cleanup scripts

devout sail
#

I don't think so

#

I want those cleanup to cleanup my fuckups

chrome tree
#

So if everyone is getting dedicated instances, what's the point of VIP+ aside from the retired machines. Especially with the 5 extra bucks?

ornate wren
#

Yeah but sometimes it's like, you change a password then it gets changed back on AD

devout sail
#

All depends on creator tbh
I don't remember any guidelines over cleanup

silver frigate
devout sail
#

There is no VIP

silver frigate
#

Oh then yeah the diff is you get all the retired boxes?

chrome tree
#

This sounds like my insurance provider.... "Why did my premium go up?" "Cause other people." lol

devout sail
#

Falcon did 👎 on it eyes_anger

static pasture
#

An admin has to add reactions for you to react

#

There isn't a VIP sub anymore also

silver frigate
#

Ohhh ok

#

Lol

chrome tree
#

So it's just a standard sub now

static pasture
#

Any current VIP members will be migrated to VIP+ and then when its time for their sub to renew, they can either renew as VIP+ or they cancel

silver frigate
#

Idk I think the main diff was retired machine access

lime trout
#

and thats because they werent design to be done in the shared environment

#

meaning we had to lock them to VIP+ which had dedispawn

silver frigate
#

Ohhh right there's all of the other stuff too

zealous charm
#

🚀

maiden anvil
#

express lane to ban town

chrome tree
#

So I'm confused is the only perk of the sub now is being able to access the retired content?

zealous charm
lime trout
young glen
#

Don’t know

chrome tree
static pasture
#

Emma da hell are those reactions on the announcement lol

lime trout
#

some people are just neutral and watching (👀), and hackers gonna hack

maiden anvil
#

@lime trout

#

@static pasture caw caw

#

good morning

scenic maple
#

average boomer on facebook

static pasture
chrome tree
#

So what about Ipp's stuff does that mean he's going being a paywall for his walkthroughs? Or do the walkthroughs that are posted on the site just become locked? blobthinkingdown blobthinking

maiden anvil
#

@zealous charm 67

static pasture
lime trout
icy shard
#

add fire emoji to announcement 🔥

lime trout
#

the writeups for retired have always been VIP only

chrome tree
#

Copy, just trying to weigh the pros and cons. I mostly subbed for the dedicated instances

scenic maple
#

i will never find a unsanitized input in my lifetime

maiden anvil
#

@zealous charm it failed

zealous charm
scenic maple
mystic abyss
scenic maple
#

vdp

zealous charm
#

Use that in aggressive mode then it will flag a high severity issue when XSS is possible

#

Should let you quickly asses a few dozen sites in like 15 mins

mystic abyss
#

I had a question for peeps who do vapt stuff

scenic maple
#

ask homebrewer lol

scenic maple
#

he is top 10 in almsot every dashboard

mystic abyss
#

noice 👀

#

my question was like in a network pentest, is it correct to report some web vulns if there is a web server hosted.

Like 2 cases, in 1st we manage to escalate that vuln and get a hold/creds/anything else.
2nd nah just some low hanging stuff.

#

I get a bit confused here

#

I generally do it when it's 1st

zealous charm
#

I would report web bugs in a network pentest if I found them on the internal network. Probably nothing lower than a crit/high though. Maybe an XSS, but generally I will report RCE, SMB SSRF, or default creds that I find on web apps

frank warren
#

hey guys, anyone finished android fundamentals?

mystic abyss
#

thanks 👍

#

🫶

austere sinew
static pasture
austere sinew
young glen
#

WOLOLOLO

frigid mountain
#

what's up?

young glen
#

Not so much

zealous charm
#

its always there sus

gray wraith
zealous charm
#

nah I think he's looking at a bugcrowd .gov VDP, which are riddled with XSS

static pasture
frank warren
static pasture
frank warren
#

ah yeah

#

haha

static pasture
#

It would cast wololo to convert enemy units

young glen
#

Something like that

frank warren
#

ye i remember the voice line and after i saw the staff in his hand i remembered it was a priest

austere sinew
#

Undeadwolo

frank warren
#

btw, have you completed the android fundamentals, spy?

sturdy thistle
austere sinew
#

@sturdy thistle

static pasture
#

I have not. Between 2 jobs and a family by the end of the day I am just too tired to concentrate on studying

austere sinew
#

@sturdy thistle

frank warren
#

ah ok, thanks anyway

lofty warren
#

the new anoucement its really cool tbh

frank warren
#

i got stuck at the last part

austere sinew
sturdy thistle
lofty warren
#

I'm agree w that

frank warren
#

ah ok, thanks guys

young glen
#

Agreed

sturdy thistle
#

Gym after 2 weeks

#

Hard as hell

austere sinew
sturdy thistle
#

Hell describes it good

austere sinew
static pasture
#

I am not a university professor

austere sinew
#

Wait what

#

I could have sworn you were

#

Or college

#

Or something

static pasture
#

Full time red teamer and part-time community specialist

zealous charm
#

you specialize in those communities

austere sinew
#

Wait WHO WAS THE COLLEGE PROFESSOR THEN

#

SOMEONE WAS

#

This feels like the “why are you gae” “who said I’m gae” “you are gae” “i am not gae” “who is gae”

#

Cysec edition

raw lichen
sturdy thistle
meager kernel
#

hello

sturdy thistle
#

Falcon was right behind me

#

Emma took the picture

static pasture
austere sinew
sturdy thistle
#

No spied on me like a falcon

austere sinew
#

Whilst @zealous charm pickpocketed falcon

austere sinew
sturdy thistle
#

Could be

#

Don’t distract me from gym

austere sinew
#

@sturdy thistle distract

#

@sturdy thistle from

#

@sturdy thistle gym

sturdy thistle
#

Or I ping you to dead

austere sinew
#

@sturdy thistle yap

#

@sturdy thistle gym

#

@sturdy thistle so

#

@sturdy thistle how

#

@sturdy thistle is

#

@sturdy thistle the

#

@sturdy thistle gym

#

@sturdy thistle have

#

@sturdy thistle you

#

@sturdy thistle been

#

@sturdy thistle doing

meager kernel
#

wolo is distracting you from gym

austere sinew
#

@sturdy thistle which

young glen
#

Ping of Death

meager kernel
#

thats so wrong

austere sinew
#

@sturdy thistle muscle

#

@sturdy thistle group

#

@sturdy thistle exactly

#

@sturdy thistle or

meager kernel
#

mute wolo

austere sinew
#

@sturdy thistle has

#

@sturdy thistle it