#general

1 messages · Page 411 of 1

muted olive
#

live action roleplay?

novel oriole
#

let me finish this 80 tons of networking theory first ig sadglas

woven blaze
#

hiii

stable tiger
#

red teaming for example is mostly Active Directory, which needs extensive Kerberos knowledge etc windows internals

muted olive
icy viper
#

i agree, the bouncer needs to kick out the chef for cooking steak well done

stable tiger
novel oriole
muted olive
#

even on non domain joined machines

#

which is mostly what I do

novel oriole
muted olive
#

I need to setup an AD lab tbh

stable tiger
woven blaze
#

hi, im new. rn we arre 2 doing offlinea challenge htb
can u someone help us how to start? we do 3 very easy challenge before and this is hard for us

muted olive
# novel oriole how much exactly then? can you specify?

So you need to learn how packets travel through a network, how they're segmented, how a network is structured, how data travels across two networks, OSI model etc. You don't need to learn OSPF, BGP and things like that

stable tiger
#

and that’s okay

#

some people find the easy boxes harder than medium or hard tho cos of the topic used but whatever

novel oriole
stable tiger
#

Strong understanding of how networks and computer work makes it very easy to see when something is vulnerable

novel oriole
stable tiger
#

“oh wait they’re not validating user input and this thing directly queries the database?”

sqli in a nutshell

#

for example

stable tiger
novel oriole
#

i thought of completing network foundations section and making a complete map of it on a paper how everything works and all protocols etc evbery single thing involved in whats happening rn like how im accesing the internet.. whats happening under the hood etc

#

what do u say about this?

#

making a mental map of this structure once and for all

stable tiger
novel oriole
stable tiger
novel oriole
#

u also had to do all this?

#

when u were a beginner?\

stable tiger
#

yup

novel oriole
#

daamnnn

icy viper
#

@stable tiger How do I make notes ionside of ntoes on Joplin?

stable tiger
#

can’t write malware without knowing how windows works

can’t know how windows works if I don’t know how computers work

stable tiger
woven blaze
#

what challenge do u recommend for new users?

novel oriole
#

alll this info just to be a beginner sounds brutal bro

stable tiger
#

There’s a reason it pays well

novel oriole
#

tbh cybersec feels like toughest field of Computer Science

stable tiger
#

bcos it is

novel oriole
#

my friends busy in web/mobile app dev and its super easy compared to this.. whereas im stuck nhere in theory feeling useless

stable tiger
#

write a HTTP server in C

#

you’ll understand C and a protocol

novel oriole
#

should i really do this? am i on that level rn?

stable tiger
#

If you struggle with theory try project based learning

stable tiger
#

which is what htb is built around really

novel oriole
#

i see

stable tiger
#

practical labs to learn new techniques

icy viper
#

is linux from scratch good?

novel oriole
#

btw one last question before i go back to my theory learning

stable tiger
#

do you have motivation issues

icy viper
#

Not really, I love learning

stable tiger
novel oriole
#

will AI kill this field? is this field saturated? i often see very very less views on yt videos related to cyber sec

icy viper
#

Especially with stuff I'm interested in

stable tiger
muted olive
#

is it saturated yes

#

will AI kill it no

icy viper
#

I think AI will help people in the field, not kill it

muted olive
#

its saturated everywhere

novel oriole
muted olive
#

but, the trick is just: being better than everyone else

#

lol

muted olive
#

high level as in, medium-senior roles are less saturated

novel oriole
#

so

#

cjca = saturated skill level?
cpts = less saturated?

muted olive
#

you can say that

#

one thing though is that specializations are not saturated

#

thats if you choose to commit and go deep enough

novel oriole
#

well..
do u recommend me to take cjca exam after learning all modules or go directly to pentest path and get cpts cert only?

muted olive
icy viper
#

ibraheem, I'm not in the field but I wouldn't try learn everthing even though you said no compromise. Specialise and prosper

novel oriole
exotic pendant
muted olive
#

internships etc depends on your country

#

what they look for and such

novel oriole
muted olive
#

you can transition

#

thats not a problem

novel oriole
#

i have searched the whole web and i found out that rn cjca path is the best one out there.. nothing is better than this

#

for a beginner

stable tiger
muted olive
#

I mean

crimson elbow
#

how do i discover a zero day in the windows hypervisor?

muted olive
#

its fairly new so

exotic pendant
#

Don’t read above but if you’re wanting a job certs are only 10-20% of the battle

stable tiger
#

exploit dev is not new

exotic pendant
muted olive
muted olive
crimson elbow
#

like that's really insane

stable tiger
novel oriole
exotic pendant
#

I can feel my motivation coming back so I might hit back at hyper v

stable tiger
#

HYPERCALLS pepeTweaks
HYPERCALLS pepeTweaks
HYPERCALLS pepeTweaks
HYPERCALLS pepeTweaks
HYPERCALLS pepeTweaks

stable tiger
crimson elbow
exotic pendant
crimson elbow
#

im just looking at MSRC's website

muted olive
stable tiger
exotic pendant
#

If you have 80% of what they’re looking for like experience

novel oriole
#

i see

exotic pendant
#

Then certs Arnt as needed

crimson elbow
exotic pendant
#

I got a lot of my professional experience from being a sysadmin and bug bounty

crimson elbow
#

did they pay you the 6-figure bounty?

exotic pendant
crimson elbow
#

damn that's like 250k

exotic pendant
#

Plus it works as a rdp escape

#

Rdp host -> connecting host

crimson elbow
exotic pendant
#

No user

stable tiger
crimson elbow
exotic pendant
#

Doesn’t mean it can’t be chained with another bug

#

So it’s still sexy

stable tiger
exotic pendant
#

Time for the gym

stable tiger
#

usermode rce -> privesc is easy to chain if you have them both

muted olive
crimson elbow
crimson elbow
#

ah i see then

muted olive
crimson elbow
#

yeah i meant what vulnerability did they leverage

stable tiger
#

uaf

#

cloud driver for the privesc

crimson elbow
#

ooh that's cool

muted olive
#

drivers yum

#

@stable tiger do you have any CVEs?

crimson elbow
#

that's the million dollar question

sturdy thistle
#

I have one

crimson elbow
#

critical?

muted olive
crimson elbow
#

if so can you reference the CVE?

stable tiger
#

that werent already currently reported

muted olive
#

I thought you had like ten kek

stable tiger
#

theyre a cve if you report them to the vendor

crimson elbow
#

so you aren't a zero day hunter then welp that's frustrating but also cool to see some experienced people here

stable tiger
#

zero day markets pay a lot better

sturdy thistle
#

CVE-2024-35203

muted olive
#

having cve != not being hunter

sturdy thistle
#

Together with @austere sigil

crimson elbow
stable tiger
exotic pendant
exotic pendant
crimson elbow
muted olive
sturdy thistle
#

Thanks

exotic pendant
#

I wish I was a hunter

crimson elbow
exotic pendant
sturdy thistle
#

With a bow?

exotic pendant
#

Sword plz

sturdy thistle
#

Put sword in bow

#

I slept 1 hour

#

For whatever reason

exotic pendant
#

Shooting dagger from bow would be sick

muted olive
stable tiger
muted olive
#

yes getting you arrow and bow now

muted olive
crimson elbow
#

has anybody here achieved OSEE?

stable tiger
#

osee isnt that difficult

crimson elbow
#

that's like top tier shit

sturdy thistle
#

Probably some

stable tiger
#

sans sec760 is top tier

crimson elbow
#

isn't that a kind of more niche

stable tiger
#

no?

muted olive
#

no

stable tiger
#

sec760 is 0day hunting

muted olive
#

sans is THE top

stable tiger
#

osee is entry kernel exploitation

muted olive
#

it is?!?!?!??!

stable tiger
#

offsec just glazes it

muted olive
#

how much does the course cost?

crimson elbow
#

oh wow never heard of it

stable tiger
#

sans or offsec

sturdy thistle
#

Much much

stable tiger
#

offsec u can only take irl

muted olive
#

sans

stable tiger
#

oh

#

sans is like 9k usd

#

its fucked

#

stephens a great guy tho

sturdy thistle
#

Yeah pricey

muted olive
#

:P

stable tiger
#

so youd learn a lot from him

muted olive
#

thats my yearly college fees

#

lol

sturdy thistle
#

Damn

muted olive
#

Choice between

#

Bachelors degree

#

or 4 SANS certs

stable tiger
#

the OSEE has so few holders because it's only done irl

crimson elbow
#

ahh i thought you could take it remotely

muted olive
#

nope

stable tiger
crimson elbow
#

thanks for clarifying

muted olive
#

even remote exams have intense proctoring

stable tiger
#

sans sec 660 and 760 is the best way to exp dev

muted olive
#

I wanna :(

#

but no $

stable tiger
#

if you want to learn free id say start from what people used to do in the 90s, reading shit like shellcodes handbook, art of exp, smashing the stack for fun and profit etc and then moving into more modern shit like mitigations, bypasses, heap spraying for eg etc

stable tiger
#

they cover v8 exploitation

#

meesa wanna learn chrome sandbox escapes

muted olive
#

sandbox escape is easy

#

jk.

stable tiger
#

xsalsa giving fed

#

WHO HERE CAN FIND 0DAYS.

muted olive
#

it is interesting tho

#

electron apps are juicy

#

for sandbox escapes

stable tiger
#

yeah but thats electron

muted olive
#

also: windows

#

no linux for exploit dev

exotic pendant
#

Girl at the gym said I look bigger prayge

crimson elbow
#

didnt they patch like 114 security vulnerabilities in the last patch tuesday

exotic pendant
#

Hopefully she didn’t mean fatter

stable tiger
exotic pendant
#

Not the girl who I wanted it to say but still w

stable tiger
#

they removed two things in the caller functions and they didnt fix the root issue of the UAF lmao

muted olive
crimson elbow
#

holy shit that's what they get from incorporating ai into their windows source

stable tiger
#

yup

crimson elbow
#

winbloat

muted olive
#

you meet anatoly

stable tiger
#

you can find it with one patchdiff

muted olive
#

and*, I havent found it

#

I havent even searched for it kek

#

is it a win11 thing?

stable tiger
muted olive
#

if so, no way

stable tiger
#

ye

muted olive
crimson elbow
#

honestly when i first switched to linux i never thought i'd not see low ram usage

stable tiger
muted olive
#

ah

stable tiger
#

usually done to find the original vuln and write an n day

#

but in this case its just not a good patch

muted olive
#

how do you reverse a patch though?

#

they just drop an updated dll (or whatever the affected component was) right?

stable tiger
#

most windows applications have debugging symbols

muted olive
crimson elbow
#

you just pull the fresh binary and provide it to windbg to generate psuedo-assembly code, also grab the kernel symbols

muted olive
#

they had to patch a web vuln I found THRICE

#

because I broke it the first two times

stable tiger
crimson elbow
#

and you use the website referenced to notice the previous patch

stable tiger
#

and just use winbindex to get the two diff file versions

crimson elbow
#

yeah that's a reliable way too, but doesn't IDA Pro cost like a thousand bucks?

stable tiger
#

ghidra

crimson elbow
#

you also mentioned ida

stable tiger
#

i did say or

crimson elbow
#

i wouldn't bother asking then

muted olive
#

I want to get another CVE tbh

crimson elbow
#

it's very time consuming though

muted olive
#

lazy and tired so far and NOT willing to talk to mitre ever again

#

my last one (also my first one) took 3.5 months

crimson elbow
#

can you provide the cve here

#

i kinda want to see it

#

also is it included on CISA KEV?

muted olive
#

uhh never checked tbh

#

CVE-2025-50567

#

its CVSS 10

#

:3

stable tiger
#

is there a reason

crimson elbow
muted olive
#

ty

#

oh its on CISA-ADP

stable tiger
#

fuck me i need to reconfigure burpsuite now

crimson elbow
stable tiger
crimson elbow
stable tiger
muted olive
#

what you got so far?

stable tiger
#

me and the gang leaving vulnerable rdp on a box just to use frosts rce

#

honeypotting!!

muted olive
#

did you confirm statically?

#

im saying this because I made this mistake multiple times

crimson elbow
#

for now actually? yes

muted olive
#

oh thats cool then

#

is it deterministic?

crimson elbow
#

you really nailed it, yes.

muted olive
#

if you can manage to trigger it, report

crimson elbow
#

i'm actually talking seriously lol

#

i'll see, thanks

#

there are no documentations for it or any CVE record at all

muted olive
#

that is mostly expected

stable tiger
#

alright ive got kali setup guys

#

no need to gloat but i had too

granite shadow
#

Hello everyone! New member Suraj here, passionate about HTB labs and cybersecurity. Excited to learn from you all!

stable tiger
#

arkham goon

stable tiger
#

🔥

zealous charm
warped plank
stable tiger
exotic pendant
#

Frosto ready for the weekend

#

Soon

warped plank
#

😭

muted olive
#

oh yeah

stable tiger
muted olive
#

yes

granite shadow
meager kernel
#

do not use Kali baremetal

#

use it in VM

stable tiger
exotic pendant
granite shadow
stable tiger
exotic pendant
#

Frosto just uses windows but for the few times I need linux I have a windows 95 theme on it

stable tiger
#

i was using windows till yesterday

#

till i ragequit

exotic pendant
#

Linux has me rage quitting ngl

meager kernel
stable tiger
muted olive
#

I mean all linux tools mostly have windows equivalents

exotic pendant
#

Plz install dependency on dependency on dependency

meager kernel
stable tiger
meager kernel
stable tiger
exotic pendant
#

If you find one let me know

stable tiger
#

or endeavour

exotic pendant
#

I’ll tell you what I can do in windows for it

muted olive
#

@exotic pendant lee-nux or lie-nux?

meager kernel
#

lee nux

exotic pendant
#

Lin ux

muted olive
stable tiger
#

dont say WSL2

exotic pendant
stable tiger
#

wsl 1 doesnt count thats pico processes

muted olive
#

im probably the only one here who says lie-nux

stable tiger
#

wsl 2 is just a vm

#

so that doesnt count

exotic pendant
#

What would I need the kernel for

#

If I’m fuzzing I’ll use qemu

#

Damn this auto correct

meager kernel
#

qemu works in windows?

exotic pendant
#

Yes

meager kernel
#

i thought it was linux only

stable tiger
#

ofc

#

lmao

#

no

#

people dont use windows 11 because windows 11 is shit

#

10 was great

meager kernel
#

i use 11, im used to it

stable tiger
#

12 wont work till natya sadella steps down

meager kernel
#

my linux crashed and i just stopped using it for now

stable tiger
meager kernel
#

unfortunately it is deprecated

stable tiger
#

it is nice to not have to hunt down drivers

muted olive
#

I still use 10

exotic pendant
#

I use 11 but make it look like 10

muted olive
#

for testing

stable tiger
exotic pendant
#

Only because I was forced to use 11 sadglas

stable tiger
#

oh real

exotic pendant
stable tiger
#

in a vm

meager kernel
#

frost can i have your linked btw? 🥺

#

*linkedin

stable tiger
exotic pendant
#

You’ll have to find me but I don’t like associating my personal with online

meager kernel
#

fair enough

exotic pendant
#

I’m not hard to find

#

I got my certs listed

meager kernel
#

wait can you send your twitter again

stable tiger
#

he's from Pizzatown

stable tiger
#

go use it

meager kernel
#

shut up

stable tiger
#

google his username dawg 😭

meager kernel
#

he has a slighty different username bruh

#

pls shut up, no offence

exotic pendant
stable tiger
#

spot the twitter

meager kernel
exotic pendant
#

Best lang

stable tiger
muted olive
#

when you gonna accept

signal mica
#

can some spotify enjoyer visit https://developer.spotify.com/dashboard and tell me if creating an app is disabled for them. its been like 4 weeks now since they disabled this and idk if its because i have free or whatsup

exotic pendant
#

I have no pending

muted olive
#

uh

#

i'll resend sec

stable tiger
#

ur being used as an example of why rust is bad but you love rust

#

so funny

exotic pendant
#

That was because I made the poc public

stable tiger
#

reply to him and say you love rust

exotic pendant
#

Low level also gave me a shoutout

warped plank
meager kernel
exotic pendant
stable tiger
#

RUST IS OVERHYPED and its a winapi issue

exotic pendant
#

Rust was the only one who said it’s not a feature

stable tiger
#

@exotic pendant can you write up a list of exploit dev 0-hero resourcs so i dont need to keep explaining it to people who join

#

thanks xx

scenic maple
#

2016 was 10 years ago

stable tiger
#

no shit

#

thats why 2026 has a 2 in it

#

(i am joking)

muted olive
#

@exotic pendant kek

stable tiger
#

dont murk me

muted olive
#

I think mine is still there somewhere

#

apparently I sent it 3 months ago lol

exotic pendant
#

Dm your acc

#

Dang it was one of the pending ones kek

warped plank
stable tiger
#

they need a beginners guide or they shit themselves

gray wraith
#

Bro was jealous they didnt find it smh

stable tiger
#

also tbf apts are usually just writing bootkits

warped plank
stable tiger
#

for example

#

Join me in the next Off By One Security stream where we feature Alejandro Vazquez as our guest with some amazing content!

Bootkits and Rootkits represent some of the most complex and stealthy forms of malware, capable of achieving full system control before and after the OS is loaded. While often discussed in theory, their actual construction,...

▶ Play video

When we talk about truly advanced malware, the kind that only state-level or highly resourced APTs are capable of developing and deploying end-to-end, we're referring to what are known as bootkits and rootkits.

In the first session we did on the Off-By-One Security YouTube channel (https://www.youtube.com/watch?v=oa2i7JsGOHo), we introduced how...

▶ Play video
#

stephen my king

warped plank
stable tiger
#

@crimson elbow

#

seems up your ally

exotic pendant
#

Frost lifting so heavy my whoop though I was powerlifting

exotic pendant
#

365 bench today

stable tiger
#

frost what you squat

#

i need to train actually

exotic pendant
#

Lately just 495

stable tiger
#

my sleep schedules so fucked im noncturnal and hitting rpe 9 squats with no spot

#

😭

#

guys im so 1337 i sleep during the day so the #feds and the #glowies think im in #china wow 1337

muted olive
muted olive
#

I can find.... anyone

#

-# because im with the NSA

#

-# /j

stable tiger
stable tiger
#

their pay is crazy

muted olive
stable tiger
#

also being a government apt sounds fun

#

writing exploits and bootkits all day

muted olive
#

gg

#

#doxed

stable tiger
exotic pendant
stable tiger
#

people finding my identity isnt an issue i care if they see my open powerlifting

stable tiger
warped plank
#

IF you sleep during the day in australia technically you're awake during US daytime 6111zerothinking

stable tiger
#

thats the main reason i used a whoop pre apple awatch

muted olive
exotic pendant
#

It’s faceless

#

But I have an Apple Watch on also

muted olive
#

oh interesting

stable tiger
exotic pendant
#

Whoop is just a band, no face

muted olive
zealous charm
#

kinda sucks they made whoop a subscription

warped plank
muted olive
undone fossil
muted olive
#

but I forgot the brand

#

fitbit?

stable tiger
muted olive
#

maybe

undone fossil
#

he can actually write the language and uses it for reasonable things

stable tiger
#

takes being a 0day hunter to write rust

#

live love laugh

muted olive
#

/j

#

(this is a joke from an insta reel kek )

stable tiger
exotic pendant
#

Gork plz write me hello world in Rust

undone fossil
muted olive
exotic pendant
#

Prob why the psych gave it to him

#

And not him buying it at the store

muted olive
#

I mean one which is trafficked

#

those are the controlled controlled substances

stable tiger
#

adderall is illegal in aus

muted olive
#

oh 👀

stable tiger
#

you can get straight actual meth perscribed for ADHD here but not adderall

muted olive
#

wtf

#

isnt that uh

#

kind of mixed up

stable tiger
#

am i 1337 now #edrbypass with that #signeddllonly

#

#rustdev #0day #blackhat #clumsylulz

stable tiger
#

you can be walter white but not medicated

exotic pendant
stable tiger
#

you know your shit

#

rust devs dont

muted olive
#

*insane

stable tiger
#

rust devs when claude code pops out the unsafe keyword and they dont know what it is

warped plank
stable tiger
#

ur spitting

#

'claude write me a python to rust compiler please'

novel oriole
#

python or rust? best one for cyber sec issS???

stable tiger
#

wait no youre new

#

learn python first

warped plank
#

please don't learn rust first

half vine
#

Hyy

stable tiger
warped plank
#

actually I change my mind: Do... dive head first into: smart pointers for async, and the wonderful world of generics and traits

novel oriole
#

though not deep but i do have some assembly knowledge

stable tiger
#

youre a computer science student but you just asked if rust or python is better as a first lang?

warped plank
#

If you're a CS student you don't go into Rust or Python, you dive into C and winapi bugs for cybersec

stable tiger
#

custom winapi functions !

#

live love laugh

novel oriole
stable tiger
#

depends on usecase

#

as with

#

all things

#

ever

stable tiger
#

ur gonna summon froj bro

novel oriole
#

hmmm

#

btw

#

the entry level of which field is more saturated? what do u think? web dev or cyber?

warped plank
#

at this point cyber is as saturated as web dev ngl

novel oriole
#

literally every other guy around me is dwelling into web

muted olive
novel oriole
#

only me and 2 others in my class are into cyber stuff

muted olive
#

its lesser saturated at medium and high

#

I think its like a pyramid

warped plank
# muted olive at entry level

exactly, you know how many skeeds are watching a this one xss payload video and then proceed to complain on hackerone

muted olive
#

cringe

stable tiger
muted olive
#

right?

stable tiger
#

Shits unsaturated here

#

Life’s good

novel oriole
#

and also i heard many people quit cyber

muted olive
#

I mean maybe

stable tiger
frozen zinc
muted olive
#

I got three offers from US companies so idk

#

for internships*

#

two of those and one for a part time job

warped plank
muted olive
#

okay thats also mostly because of connections so

#

I guess I dont count

novel oriole
#

either ill become good at it or ill die trying thats all i can say now after so much junk fed into my brain by people

#

who say cs majors are cooked

stable tiger
warped plank
novel oriole
stable tiger
warped plank
novel oriole
#

job is the thing thats left

muted olive
#

my philosophy is

#

everyone is your competition. so your job is to be better than everyone else in one way or another

#

maybe slowly but surely

gray wraith
stable tiger
warped plank
stable tiger
#

go join the NSO group

novel oriole
#

so thats why i decided to pick cybersec and drill into it

stable tiger
novel oriole
#

of it

muted olive
#

Because those can be invaluable

novel oriole
muted olive
#

Any CS related placements?

#

even coding or whatever

novel oriole
#

people dont give a shit about security here unless they are hit like a truck by a hacker

muted olive
#

lol

#

which country?

novel oriole
warped plank
novel oriole
warped plank
#

unless it's a compliance thing they don't care about security

muted olive
#

like w1ld said

lofty warren
muted olive
#

still, if you can get a placement, go for it

novel oriole
#

now.. the cyber scene is top notch in the capital city and some other major cities

muted olive
#

because you need experience

novel oriole
#

but in my city no one gives a shit about it

#

and guess what?

#

i live in the city

#

where

#

Bin LAden was captured

muted olive
#

lol

stable tiger
#

you mean when he got headshot and that wasn’t in a city

warped plank
muted olive
#

cant stand up to 🇺🇸

#

as venezuela learnt the hard way

stable tiger
#

We love orange man!!!

novel oriole
muted olive
#

@novel oriole are you planning to do a masters?

stable tiger
#

@novel oriole you’re cooked

novel oriole
#

who knows what reality was.. nobody saw his body and multiple different agents have their own story in interviews of how they were the ones who caught him

stable tiger
#

they literally shot him

muted olive
#

yeah

stable tiger
#

why would they not shoot him

novel oriole
muted olive
#

maybe UK

novel oriole
#

ill do master only after CPTS completion

stable tiger
#

I promise you a masters degree looks better than the cpts

novel oriole
#

otherwise ill be useless .. or atleast ill be useless in my own eyes

muted olive
#

well if you have determination its fine

novel oriole
muted olive
#

just be sure to really nail in the academic stuff in order

novel oriole
#

either UK or Germany

#

i really wanted it to be the US but US guys are onto something, the ICE are kicking their own native citizens lol.. what would a foreigner do

muted olive
#

I think the student visas for UK got tighter too but its doable

novel oriole
muted olive
#

what UK?

novel oriole
#

yaa job market there

muted olive
#

Yeah I mean that is sort of true but

#

never mind

novel oriole
#

i prefer Germany ig or maybe finland

muted olive
#

just dont do masters in your current country prayge

novel oriole
#

language is a barrier which im willing to learn

muted olive
#

oh for sure

#

germany is cool in that regard

#

you know, you learn the language and you dont need to pay

signal mica
#

german language is ugly

muted olive
#

or you get scholarships

muted olive
novel oriole
#

rn i have holaidays like till late march and i wanna get CJCA or atleast finish the junior path modules if not the cert before i start uni again

novel oriole
warped plank
muted olive
#

Germans are organized as fuck though tbf

novel oriole
#

and some words are spelled like a kid spammed a keyboard

muted olive
#

Very very very punctual

novel oriole
#

but do i have any other choice? am i going to give up? am i not worthy? i dont think so

#

well yes i can transition to web dev.. i have a very very strong foundation in JAVA but i dont want to do that im fascinated w cyber stuff

novel oriole
warped plank
signal mica
novel oriole
#

it is...

warped plank
muted olive
#

It is, but not in recent times

#

its mostly used in legacy stuff

#

which cant be replaced with anything else

novel oriole
#

alot of legacy systems are on java

#

ALOT

zealous charm
#

Any hacking today?

signal mica
muted olive
#

yas

novel oriole
#

JAVA is still going strong.. still among top 10 languages

muted olive
#

discord hacking prayge

frozen zinc
signal mica
#

its impossible to migrate out of it wild

#

java is like crack cocaine

novel oriole
stable tiger
#

💀

frozen zinc
stable tiger
warped plank
muted olive
#

this is what I've heard more experienced people say

novel oriole
stable tiger
#

this you twin

warped plank
#

Most people I know are in cyber

deep ferry
novel oriole
warped plank
#

Being surrounded by like minded people is a gift, not a burden

muted olive
#

lol

zealous charm
novel oriole
#

hmmmm

muted olive
#

but yeah

#

here I am

stable tiger
#

if you strive to be different you should be unemployed

muted olive
#

so thats good

meager kernel
frozen zinc
#

and try Arch

muted olive
#

irl, no one gets cyber lol

deep ferry
muted olive
#

I know one guy who is great at programming and is great at AI stuff

#

thats about it

warped plank
signal mica
meager kernel
frozen zinc
muted olive
#

I know 0

zealous charm
warped plank
stable tiger
signal mica
#

i know 2 but tmk they are just running nessus

warped plank
#

security engineering that is

muted olive
#

I mean my family know a bit of cyber now because I yap a lot

#

lol

deep ferry
warped plank
zealous charm
meager kernel
#

im actually happy cyber is not as common as dev, less competition for me evil_cat

muted olive
deep ferry
meager kernel
deep ferry
#

and cybersec youtubers hyping it up

muted olive
#

I dont think cyber is heavily competed in India

#

dev? yes unimaginably

signal mica
#

@usama0 @brathadair @nlte @devout sail

meager kernel
meager kernel
muted olive
#

tbf I'm happy that dev is competed in India

#

Its a good thing

mystic harbor
#

Yeyyyu

frozen zinc
mystic harbor
muted olive
#

good thing unless you're a dev*

muted olive
deep ferry
#

dev in the big 26 🥀

mystic harbor
stable tiger
#

you need to build applications

muted olive
#

lack of a degree for one thing

#

as im finding out now

mystic harbor
#

I have no degree sadge_business

warped plank
deep ferry
meager kernel
deep ferry
#

lie that you know all languages and frameworks

stable tiger
#

skill issue

warped plank
meager kernel
stable tiger
deep ferry
muted olive
#

ah I want a degree lol

warped plank
novel oriole
#

is it possible to never find a bug when ur participating in a bug bounty event?

stable tiger
#

bars

signal mica
muted olive
#

do I understand everything now

deep ferry
#

I invented a scalable, industry-agnostic frameworking templating engine for JavaScript with microprofiling of multiprocess-archiecture

stable tiger
signal mica
#

the job is yours jo

novel oriole
signal mica
meager kernel
stable tiger
muted olive
#

so

meager kernel
#

you do

deep ferry
muted olive
#

welp

#

its annoying

#

no one replies

meager kernel
stable tiger
muted olive
meager kernel
lofty warren
#

wife material

muted olive
#

might as well start trying

deep ferry
meager kernel
#

💔

muted olive
#

microsoft and mozilla havent replied

#

neither has the other 3 on bugcrowd

#

neither has openai

deep ferry
#

I guess

muted olive
#

no one replies anymore

stable tiger
#

for all of them

#

if they dont reply its on them

muted olive
#

nah its been a week since the last reply lol

muted olive
zealous charm
muted olive
#

or, more accurately, the abiilty to filter out noise

deep ferry
muted olive
#

mozilla's security team is basically a bunch of devs lol

zealous charm
#

worst is when the customer accepts but doesnt pay right away CISO_j3rry I've got 5 accepted pending payment, 3 triaged, 3 awaiting triage

muted olive
muted olive
#

I dont think they're primarily security oriented despite being the security team

deep ferry
muted olive
#

which isnt a bad thing but

#

takes more explanation

zealous charm
#

Yeah, just makes me nervous because they can always scam up until the bug is paid out. An unpaid bug is worth $0

muted olive
#

and convincing

deep ferry
muted olive
deep ferry
#

Security team which is not oriented towards security

muted olive
#

they understand how the code works and how the infra works

#

they just dont understand the security impact

#

once I explain it, it makes patching easier

zealous charm
muted olive
#

because they know exactly what they have to fix and how

muted olive
#

lol

deep ferry
gray wraith
#

Trying to understand offensive sec sometimes feel like battlingvagainst shitty genetics

muted olive
#

Where do you hunt? @zealous charm

#

h1 or bc?

#

and what programs?

muted olive
#

because thats the hardest part for me

#

choosing

deep ferry
muted olive
#

yes and its very ineffective

#

most of them dont have BBPs

deep ferry
#

Alright

muted olive
#

I did get a few that way though

#

but mostly not worth it

#

or youll run into random german/chinese ec2 instances

zealous charm
# muted olive h1 or bc?

I like BC. I looked a bit at a public gov program earlier this month and shut it down after sending a bunch of crits haha. Now I've moved onto a private web program and a private desktop app

muted olive
#

I'm on one private program but not really found much

#

its very hardened

#

its electron based so there is a lot of holes but no way to reach :(

zealous charm
#

I sent 2 command injections bugs on this desktop app. Like file import -> click -> RCE and they were both downgraded to P2 by triage. idk what they expect for a desktop app, I feel like thats about as critical as it gets

muted olive
#

they want you to take over the internet

#

thats P1

deep ferry
#

Yeah

muted olive
#

nice hardening

deep ferry
zealous charm
#

Hopefully the customer is cool and accepts it higher. For their threat model (and no exposed network services) this is about as good as it will get

zealous charm
muted olive
#

I'll dm

mystic harbor
devout sail
novel oriole
#

guys

#

i need some help

#

im done w network foundations section and im finally on skill assesment page

#

im not starting it yet .. after a revision ill do

but i dont understand one thing.. my htb labs access is denied and it says my account is sanctioned.. since day 1

i wanna know whyy is my account sanctioned????

#

and also does this assesment have to do anything w labs?

molten bobcat
#

No

#

Skill assessments are part of academy

novel oriole
#

can perform tasks on my own linux instead of the pwn box..? pwn box is slow as a sloth

molten bobcat
#

Yes you can

muted olive
#

and, you can

novel oriole
molten bobcat
#

I use my own Kali

molten bobcat
muted olive
novel oriole
#

and what if i provide my national id card and university student card.. would that be enough?

molten bobcat
#

Htb is EU based

muted olive
molten bobcat
meager kernel
#

finally completed a machine prayge

muted olive
#

airtouch?

meager kernel
#

monitorsfour

novel oriole
#

Oops!
We’ve spotted a compliance issue with your account.

Your HTB account has been sanctioned.

You can’t access HTB because compliance requirements haven’t been met based on our
User Agreement policy
.

If this seems incorrect, review the required
documents
and send them to HTB.

muted olive
#

Ohkay

molten bobcat
#

Wild

muted olive
#

I think thats potentially a conflict with your student status that you need verified

novel oriole
#

but they gave me subscription based off my std account and i also verified it

lime trout
novel oriole
#

nvm ill just send what they need for confirmation... student id card and national id card that should be enough

muted olive
lime trout
#

This is legal requirements by goverments to make sure we're not serving terrorists etc

muted olive
#

Ah

muted olive
#

Okay

lime trout
#

if you have the same name as someone nasty, we gotta make sure your not them

novel oriole
#

what to do ????

lime trout
#

Reach out to support, send them what they need

#

and we'll get you sorted

#

im not overly familar with the process tbh, beyond that it may take a minute as its handled by a very limited group of ppl internally due to the sensitivity

novel oriole
#

well tbh im annoyed asf .. but i cant blame htb.. its a fair action from their side if u consider the broader spectrum

lime trout
#

let me poke around and see if there is anything i can do

#

no guarantees, touchy process but ill see

novel oriole
#

this one right?

lime trout
#

Yes, correct

novel oriole
#

ill send national id card and student id card

a live selfie would help or no need of that???

lime trout
#

doubt a selfie is needed

novel oriole
#

ok let me prepare a formal mail then ig and ty for help

meager kernel
#

has it happened before?

lime trout
#

to my knowledge, we've never had any terrorists using our platform lol

novel oriole
#

am i gonna be jailed even before the start of my hacking career LOLLLLLLL?

meager kernel
lime trout
#

but being a company operating in the EU/US, we are required to follow US & EU sanctions, which have liability laws that scare me.

meager kernel
#

not terrorist like actual big ass terrorist
just criminals

novel oriole
#

this has to be normal for people in my region i literally cant access labs since the account creation day

opaque flume
#

hey hello there

opaque flume
lime trout
#

It'll block you from using VISA/MC as an example

#

issued by any bank

devout sail
#

😔

lime trout
#

even just sharing a name with someone on it creates headaches

devout sail
#

Okk, i was joking, if anyone here is hunting bug on that site
DO NOT use my name to test

#

Golam would edit the source to troll i guess

sturdy thistle
#

NAP time

devout sail
obtuse fern
#

This sounds like a #modules question, it also helps to provide module name and section name

lime trout
novel oriole
#

i have sent the images to prove my identity to the support's mail

#

is it enough or do i have to consult someone else as well?

dull meteor
#

I can't spawn pwnbox anyone knows why?

There are no instances available. Please try again later

obtuse fern
molten bobcat
#

Nomnom

obtuse fern
#

Cloud

#

My framework comes today

#

:3

#

It said delayed, but those bastards lied