#general
1 messages · Page 453 of 1
@austere sinew id
What kind of talk in cube today
You haven't seen him?
He got a nice lady on call tho
have
@supple plume can I send you bald ass head here
Echos is swole
which picture
Oh cube talks going on
make sure I am wearing clothes
That's echo

i learn da wey of python
say
make sure to keep it tame
I was almost eaten by a python
this shi is my head
0 bald
I finished planning my new machine
vro lets go to the cubetalks
Nah
that sounds really hard
Breh he's sending your pics in general
they are going to answer my question on cubetalks
I'm shy
golden ratio
With that unique aah constellation on your bald head, it's literally doxxing
he asked nicely on dm
only 50% of my head
White version of the rock
.
I guess but if I grow hair it diesapperas
xd
i haven't listened to cube talks in a while because ....I don't have any questions about hacking yet
But i can find people shave their head and find you
I lost interest cuz, "how do I get into it"
" How do hack "
yeah that seems like the overall theme in cube talks
aright
I think his chin might be a tumor.
Might want to advise your buddy echo to go to the docs post haste.
Waymo time again
would it be a nightmare if i just started coding gentoo linux LFS
vro gentoo linux is not a programing language
i meant compiling and stuff
LFS
Hey guys 👦 I'm new to hacking world, gttin better with Linux, does anyone has video courses of hacking maybe on mega or drive, sorry for bothering I'm just a noob trying to get better ebooks is not my type so I love watching videos courses. Thank you 🙂
theres plenty of websites to use, like tryhack me and hackthebox, i recommend as a newbie myself to use kali linux or parrot security os
Have tried both
any other like ubuntu arent for hacking, or either advanced (black arch), then comes the privacy and security ones that arent completely for hacking
wow
it asked me to find the version of ftp
and i acctually knew what nmap command to use to scan it
i remembereddd
Looks like a goiter
nvm
so black arch is not for hacking?
Black arch is for very specific hacking tooling which realistically you wont use as a learner
I did
Arch in general is good for rigs where you need like one or two tools and you want them to run well: for example it would be a good choice for a cracking rig
I could see blackarch as a good choice for a threadripper rig you ssh into if you want to make sure all the relevant tools can run on it
Does that make sense
fucck
Its not durable enough to daily drive
i forget how to do this
There are people that do but arch systems will bork when you have deadlines and thats bad
well I have been running it for 2 years what can I say
sorry for the wall of text but
Password for [WORKGROUP\kali]:
Sharename Type Comment
--------- ---- -------
ADMIN$ Disk Remote Admin
C$ Disk Default share
IPC$ IPC Remote IPC
WorkShares Disk
Reconnecting with SMB1 for workgroup listing.
do_connect: Connection to 10.129.144.206 failed (Error NT_STATUS_RESOURCE_NAME_NOT_FOUND)
Unable to connect with SMB1 -- no workgroup available
this came up after smbclient -L (ip)
good luck 👑
Okay so say you need to install a new tool last minute for an engagement and it breaks a bunch of packages. Now you have to unfuck your system when you should have been responsible enough to keep on task all day
Its not that you cant do this, but choosing your tools better is a way of controlling the outcome
there are many strategies to not get rekt using arch and many others to unreckt
Yeah one strat is using a setup designed to not bork
Its good for simple setups or simple servers that do one or two things requiring little management
the thing is, Arch can be used to hack but it's an aqcuired taste. I just wanted to ask to the guy above if he said blackarch is not for hacking
kali is enough for hacking tho
The more complex you make it the more you have to think about when u come back to it
im stuck on facts , the season 10 machine , can somebody help
am i allowed to speak a little details?
I really believe kali is the best for most people
yeah
Today is
smb1 so checked for eternal blue
they lie🥹
Also, please erase comments that spoil boxes brah
Other folks aren't supposed to know what the path is
he is doing no spoiler belive me
Kek
so can you help me out if you read it
im new on discord just joined
and new to all
Howdy!
Run!
I'm eating nuggies rn
||how to find the user of facts , tried all from comments but it wont work , cracked the ssh key passphrase||
ahh some1 plz
How do I contribute to the community so I can become blue?
huh
Leave two bags filled with plain unmarked bills behind the lamp post next to the bridge at midnight
You also have to sacrifice a goat
Yes
It doesn't say how, so sacrificing a goat token in a game of Magic works too?
Why don't we do sacrifices anymore?
It's been automated
It has to be on a full moon night
Raining too much? BOOM kill a random person - > rains stops
oil too high ? boom kill a not-so-random person -> oil drops
saw something in the news today
a guy died because of balloons
he carried 20 balloons into a lift, all exploded at once
boom
So if you guys have never seen a lunar eclipse I guess look up on.. March 3rd
Humans apparently used blood magick to mix blood with dogs and horses...
Which is why we're bonded to them
Hello!
low
It is not a lie. It is known.
I was in a voice call and it just glitched me to cube talks this is cursed
the reverse shell is not reverse shelling
Is it stable
I never stabilise my shells
it was but I lost it and now the same paylaod doesnt work 
I didn't know you hack too
Ew no
Who does that lmao
Im here purely as a shitposter
you tricked me
me 
Why?
So based tbh
I use penelope it does automatically
Okay but seriously has anyone else been having an issue where they join a voice call and it teleports them to another one entirely
This is the second time it’s happened now for me
Sometimes I don't even use reverse shells if I get command execution directly on the browser, I just rock with it. I'm that lazy
I have to do many things in the server here
should I take soc analystic or pre requsite soc analystic
also good morning
huge: it depends
I mean what is even your goal
that's not even interactive
That's a well documented phenomenan called, parrelel phone call teleportation or PPCT
Yeah
Too. Much. Work.
I wanna run linpeas? I detach season, run command in the background and go back while it scans
Hey everyone! I’ve been building practical AI automations for web apps, think assistants that draft, classify, and trigger actions across tools. I’m big on guardrails, cost control, and measuring quality. Curious what AI use-cases are working for you.
The absolute max I'll go is a netcat shell
Have you heard out from brathadare any time soon
This dude have disappeared
he rejoined days ago
this is my bash
very customized
is this linux?
I even customized my cat comand
heck yeah, arch linux btw
nop
oh wow cause I thought getting VM is safer
it is
My shell is the default gnome shell 😭
Customers be like bruteforcing my ears
I literally CANNOT be bothered
can bruteforce the phone numbers ending digits till the pfp matches
do you like mine?

Nah work stuff
Yeah it's cool
you can have it
babysit?
I made a oneline install
Go ahead, you know what I can give you the nb in dm 
if you end up installing it run echoeshelp to know what aliases you can use
Ohh
Wtf of course no
Alright
mb i didnt get whole context

hey
jk
whats up?
I quit my job and I'll be getting my first pentesting as a freelancer next month
any advice?
curious what are you going to use for that info?
Well I guess do a good job and make sure the client likes you and hopefully hooks up more contracts with you in the future and recommends you to others. I have done zero freelance pentesting so I'm not sure what other advice to give really.
Oh and dont sell yourself short
It's echoes email address, once you mail him you'll win 100 bucks
Advertise yourself as the best they can get (to a reasonable degree)
hacking NASA
he is a former client (when I was a freelancer dev) so I know he will make it fair
Lol okay
Sounds good then, he already knows you
all about connections 
also was it hard to find anyone's email?
not really
I'll be impressed if you can find my email
it's this hard
I have 16 assignments overdue again and it's probably your fault
nice try: failed basic social engineering
isntalled my bash customization?
HTB Teams are for learning only?
No, I'm about to pass out, I'll install it tho and Def let you know
i am script kiddie on hackthebox and its because im new , how many labs to solve to become atleast hacker 🥹
cool
it depends what path you wanna take
Like literally haven't slept in 24 hours exactly
im not cool enough to understand what you said
Where can I go to get some nudges on Season Machines? I am stuck and need some guidance.
And I have a presentation in 2 days
Bout 20 active machines
That's not true at all
Easy ones
thanks i will surely do
also I think @muted olive is trying to find my email now
will i get banned if i answer this or help others or at what extent can i hell
or not
Is there that much of free machines?
bro what is What is the name of the share
then thats more easy right?
There's just fewer of them to do
Cloud 20% of 100 is 20.
Ah noted sorry for misunderstanding
I am not looking for cheats. I just need a sounding board. I feel lost in the dark
Are there currently 100 active machines?
Yes
I solved fuckin 5 and got hacker rank wym
0_o
lets see , i will check for myself now
I don't know stop yelling at me
I'm not lol
All active machines are free
Indeederino
I know
Yoo
I haven't slept in 24 hours give me a break
Go sleep lol
So they retire and new machines get created?
How often that happens
Every few weeks or so I think
Been goin on for years
if i
Welcome aboard
if i solve all boxes
i will reach holo , no matter how late i solve right?
just in the week when its active and giving points?
I believe so?
that means i will get 50% off htb swag
I don't do the boxes these days
i have to solve then
fair enough
I love your enthusiasm, but if you're a beginner, you must go into this with some realistic expectations because you aren't going to get Holo in a week
Ye
i know
i meant that , the boxes comes every new week or so right
Yaya
so as long as i solve the that single box in a week i will get points
or do i just need flags to reach holo?
Yaya
i need htb hoodie , im grinding for 50% off coupon Lol
I mean flags are how you solve boxes
Ah nice haha
I don't think I have any cybersecurity hoodies outside of uhh
The vx underground bitphomet hoodie
i like the vxundergound hoodie
Huh, they don't sell mine anymore?
You can get coupon by being active or what
by being holo they say they give
Holo is?
holo is a rank , by solving seasonal machines
Got it
got it
Dope hoodie cloud
Is there anyway I could convince someone to give me a hand in getting into my tablet that I forgot the password too?
factory reset it
I would prefer not to delete everything
maybe contact the manufacturer, highly unlikely they can help though
I was thinking I might use it to learn how to do a brute force attack but I also think that I put some crazy password on it and that is why I can't remember it.
The problem is it may not be yours, just because you say it is doesn't mean it is, and no one here is going to help you with something that could be illegal.
I realize that, that's why I asked it the way I did
There's no way to validate that, you just joined and aren't really part of the community, your first question was asking for help breaking into a device
contact the OEM
Understand your position
so do I have to email support about a question about academy?
One question if I can. Would a brute force attack work if the drive is encrypted?
I do data recovery for electronics for a living and tbh you're pretty SoL if you want to preserve data unless the device is ancient
every remotely modern tablet from the past 15 years is going to have lockout timers that will stop a bruteforce attempt
Depends on the question
most devices will perma lock around 10~ failed attempts
So like even ethics aside, youre out of luck
I think I bought it back in 2020 or so. I thought I saved the password on my proton pass but I aparently did not
its just about subscription, like basically if I buy student one, start pentest path and midway through my student expired I lose access to the rest of the modules right
even if I have 18 a month
then your options are to either remember the password or wipe the device
Yes, if your sub expires you lose access to modules you didnt complete 100%
is the 18 a month just for cubes
ye ik thats 8 a month
Meaning it grants access while subscribed
but the 18 month plan for non students is cubes only right
on the page it does not say anything for the most part thats why I was confused
Thanks for the info, I guess it will just take up space on the desk. Maybe one day the spark will ignite and I will remember. I doubt it though I have a HDD that has been setting around for about 5 years that I have the same issue lol.
It says everything it gives you, not sure where you're not seeing info
amusingly encrypted hdds have a better odds of getting into it lol but theres a lot of scenario specific circumstances to make it possible.
And better odds doesnt mean realistic odds
where's this at?
but since I have student rn I can't see what I would get without it
2.0 upgrade page
also it says from bc there's different tiers
Ive gotten data from some bitlocker and firevault drives, but only a handful out of the number that cross my desk
It has Linux Mint on it and I know I encryped it but it has a fairly short password. Just a couple words, I just cant rember exactly what it is and have tried several things
no, it's telling you exactly what it gives you
it's not saying anything different...
well see how I see the other plans
in the other screenshot
yeah...
you can see other plans in this screenshot yeah
))
That probably has a better than 0 odds but I havnt tackled any luks/common linux encrypted drives before.
ye just go ahead and time me out for 10 min I derserve that one ngl
reading is fundamental
It just has some service manuals and things of that nature on it. Maybe a few invoices.
I am suprised htb does not just have a tier-based access subscription for non students for monthly plan tho
it is silly
but
value
like, there's not much value in having a cheap access-based sub... since that would tank the value of the cube monthly
generally if I suspect that a drive has a short password(common for firevault), I try to get a few guesses from the customer of what they think the password mightve been and then I feed them through various hashcat rules to try to crack the drive.
Usually its something like person tried guessing rose1972 and the actual password was rose1985 or something along those lines.
I mean I guess but like ppl doing the job role paths then also have to pay for the cert exam
@austere sinew
correct; the annual subs come with 2 vouchers; silver includes CJCA AND CPTS/CDSA/CWES
Yeah I think it was like name of business and year established but I can't seem to guess correctly. It was a thing i tried for a couple of years
buying cubes and voucher is cheaper for cpts
200 for the 2000 cubes, 210 for the exam = 410
yes
Yeah if your curiousity strikes you again you should find out what type of encryption it is and see if hashcat supports it. You might surprise yourself with the rule variant method I described.
but the value of the annual subs is access to ALL modules (tier2 below)
for the voucher its 2 attempts still right?
yes; with the stipulation for the attempt being submitting a report/something otherwise you forfeit the second attempt on the voucher
I really don't know where to start with it, as far as the "hacking" side. I will keep that in mind though. I wan't to learn about the process but I don't want to read for hours or pay for it and that seems to be what is required due to the fact that I don't know anyone in person that can assist. Half the people I know can't figure out normal dir navigation.
@sturdy thistle
thats not bad at all 2 vouchers 4 exam attempts in total
yeah hacking (un) fortunately requires effort lol
def cheapest with student tier tho so I need to hurry up then 😅
being a lawyer is a very dangerous job
talk about high risk high reward
that's lawyer
can you see how much longer your student verification will last for or is it when your school email expires
True, and I wouldn't mind a little effort but not the amount it would take me starting from 0. I don't know enough about the concept.
so are most roles in cybersec

Hi guys, I am new here, can anyone tell me how should I maneuver this server?
turn right
30km
then go back and turn right in the roundabout again but twice counterclockwise
Well now I can see White House
aright if you make a more specific question I'll answer seriously
if you rank up in htb you'll be able to see other channels
Yeah I am just coming from those
if youre in the academy try asking questions for your track on the HTB academy dropdown
lol
if not just go to the other drop downs, it's pretty intuitive
kidn of an odd question
are you trolling?
No, I am seriously new here and wanted to know, how to go about it
road to 250
I enrolled for Penetration Testing Process, do you think it is a good module for beginners? I mean it says Fundamental there
yeah but I would also recommend you to try the starting point on htb labs
to get some hands on taste
oh also check deez
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
Thanks I'll go through this
Hello chat
hello sweet
How’s it going
What did you do to it
Why does it wanna kill you?
lick it 
How can one lick their own eyeball
My tongue can’t even reach my nose
i have a few suggestions
Ew ew ew
nothing, woke up today and its been irrittated all day
thankfully my nose isnt as stuffed as it was yday
Sucks man. Hope it feels better soon
hate being sick
thanks, i should be good by tmrw/sunday, gotta be. i want to go climb some more
i couldnt even blow it, it was so stuffed lol
i sounded like i was holding my nose
Damn
I have
Pro gamer tip
For helping clear stuffy nose
When blowing your nose, don't just full blast blow air through your nose, blow a little air out and ramp up the speed towards the end of the breath
For some reason it works better?
Hello guys
Can anyone help me
I’m beginner in cybersecurity
And I don’t know from where I should start
Any suggestions? 🥲
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
I think there's a module literally called Linux fundamentals
Should I write everything I learned it in some notebook or something?
Correct
Any suggestions for beginner?
Most of use note taking software like obsidian
Is free
I’m confused and lost🥲
Das normal
Should I download it?
Up to you
How many months I want to start solve medium ctf challenges
Remember I’m 0 in everything
Care less about the time invested
And more about just starting
There's no definitive answer
If you do a box a day you can do mediums in a month
By week two you will understand the boilerplate approach
if you alternate os each day
welp
hi, sorry to talk here but idk where to ask, i keep getting machine ips out of the vpn range today, even when i switch vpn. Does someone know how to fix it please ? I have vpn europe 6 for example which gives me ip 10.10.15.191 (in /23) and the box spawns at 10.129.11.53
yeah and it doesnt make the nose swell inside
did you tried to ping the box?
I dont get why people use claude, all its doing is running terraform and ansible to wire infra up. You can do it yourself in 8x more time but free
yes it does not work
Google chrome free model will tell you how to write malware, but chatgpt needs to be convinced
Its so funny
which box you've tried
Soulmate
aight, new jjk ep watched, time to go back to cpts studying
and which vpn server you're on?
theres new jjk?
europe 6 (same behaviour with eu4)
this?
yes exactly
yeah episode 6 of the newest season dropped yday
and i choose udp vpn
and tun0 is the only interface you're seeing?
and you see the initialzion completed?
Thats great, ill need to check it out
no but the machine ip is not in the ip scope
yes
lets go lets go momentum over fear 😄
i tried with other machine and get another ip in 10.129 while the vpn gives me the ip 10.10.15.191
yeah that's normal
oh okay so my interfaces must be overlapping thanks for your help
Good Luck Mr Robot
yea do, both are amazing, gege doesnt miss
fixed it thank you very much for your help
I need to watch!
I still have a bunch of stickers lmao
It's a curse.
From me, to you.
Making your own friends is not a curse
I would make like 8 squishmallow friends that have different elemental abilities imbued, and wed go live at the north pole
pridem
It takes the soul information of a real person to perform
Although stuffed animals you control with a CT sounds a lot like fuzzy shikigami
Which is kinda what I thought the principles CT was anyway
in a way it does but it's like a mix of curse manipulation and shikagami
So what season of Naruto 2 is out now? like the new episodes?
im pretty sure they had like a prequel season i havent seen yet too
naruto 2 🤣
jjk is literally naruto 2
yea true
you can parallel every single episode
and characters
its naruto for the modern generation
bro has the 9 tailed fox in him
at least jjk is a better "cheap copy of naruto" than boruto is
boruto is actually very original now (after time skip) and I think its well written
even tho the manga of boruto is kinda cooking, the same can be said about jjk's sequel
but yes, boruto is pretty terrible
Hello👋
howdy pardner
hellow
How is the day so far?
It's midnight, tryna catch some sleep
Anyone know how to hack into accounts
How tho
know your password is a way
and then it's called Login
That's not hacking
Yes: the way to do it is kinda complex but the jargon people use is hacking. That's how you get into accounts. 
Buddy said to know your password
Congrats on cpts

Congrats on @warped plank
I have the voucher but im scared for planning the exam

Well thats one way to do it. Real answer is: There's so many ways to do it: everything from ASCII brute force to Exploiting the application's server/network logic.
Time is tickicking
Huh? Wha?
bro said 'accounts' like there is only one auth mechanism thats universally used across all devices and environments
I did 90% of daddy tjnulls
It's all just usernames and passwords...*MFA, oauth, and passkeys peaking from the window*
kerberos laughing from a distance
Yes it's just: ASREQ ASREP TGS TGT SAM MIT... wait what were we talking about again?
How many people did @austere sinew get into a ping war with?!? 
im also amused that 'knowing the password' isnt hacking.
All the apt's that utilize scouring infostealer logs need to pack it up and go home.
@subtle plover
Well... it is a form of hacking
Like 30 different people I lost count beyond that point
Idk how many but @austere sinew will never be as popular as @seadris
I am a victim
so i bought a gift card and used it to get the gold annual sub, where can i find invoices for this

You're only a victim so long as you entertain the pingerz
I tried ignoring it for days
Failed
Exactly
It’s across multiple servers
There's a discord feature for that
I am a VICTIM
Typical male discord audience reaction to female on discord 
This is why you lie and say you a dude
I think this is just wolo targeting tbh
They just sense the bully potential
Sybau
If this is how you react to bullying then yeah I'd bully you too 
This is targeted
OH COME ON


Need something to be happy about, cos a very popular holiday is coming up that makes half the world happy and the other half at risk
That’s my brother’s birthday as well
Your brother was born on Chinese New Year?
Oh no
LMAO
I thought you were referencing valentines
That's the holiday that makes the entire world at risk...
LMAO
At least I always have an excuse to not celebrate it “haha uh my brother’s birthday hahahah…”
Even people in relationships at risk of getting assaulted by a disgruntled Ex or an STD
Or being assaulted by current partner
I was on the bus yesterday and this guy was scared shitless of his gf
Who lives in another country
And he has to navigate getting flowers for her
And he was like
WHY DO YOU WOMEN LOVE FLOWERS SO MUCH
and I was like it’s the concept they’re pretty and you were willing to spend time on getting us something pretty even if it doesn’t last and is functional
It’s a standard
Nick if you’re out there good luck buddy
By that logic I should get girls flash paper. It's pretty, not very functional, and by design doesn't last long.
Okay but unironically you should
Every woman loves a bit of mild arson
Nu uh yall are just jealous you cant reach our levels of goated
It’s why we collect candles
Ohhh yeah I see that now. At work my manager and co-worker always be playing with the candles... I have to remind em to put it out before we close.
Ehehehehehehehehe
Legitimately they left a candle on one time... next to one of the plants. Thank god that didnt burn.
What a shame…
hello everyone, the academy.hackthebox subdomain seems to be down ?
And so we moved all the plants away from the bar area where they play with candles... now just gotta figure out a way to get them to play with candles away from the alcohol
Do htb offer student discounts on htb labs/pro labs
Best device for hacking
- Gaming PC
Works fine for me
Nope
VPS
- Cheap
- fast
- Upgradable
Sorry cheap?!? Have you seen the price of memory?
@warped plank that sucks then i wish they had
can anyone help me
Memory these days are expensive cuz they are focusing on ai
weird, i've a 500 error
There's only student sub for academy which does make sense
yes ?
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
How can any of us
I had already bought the silver plan a couple of months back and didn't know about the student discount. After spending so much money there i kind of broke right now
in the cybersecurity community we don't teach how to hack instagram account or something, it's not the point of it
idk
bruv
Other people are not responsible for teaching you how to commit crimes
Bc this is a public community, it breaking discord rules.
Asking people to teach you how to commit crimes is very, very dumb
exactly

but if you want to learn cybersecurity you're welcome 🙂
anyway xD
why i've a 500 error code 
yeah i know
that's why i asked if the subdomain was down
but apparently it works for other
that's why i don't understand tho
Could be an isp issue
should i use a vpn then ?
The ISP would not force that error
The web server is reachable, it's just responding with a server side error
Maybe waf/proxy issue?
or maybe i just have to wait a bit
It's not based around how you're connecting unless the way you're connecting is actually screwing up something on the host
Someone should be made aware of which endpoint is giving 500 errors
Cuz that means something brokie
that someone should be me
Bro looking to cash in on a bug
I would say the best way to learn hacking I can think of is to join a group of people that do the same thing in real life. college is a good place. lol
I miss my academy gold sub from the last one
Find experience people that can actually help you though everything you need
In real life
That you can always talk to
idk, i don't consider myself as a hacker, i just like doing ctf and exploiting vulnerabilites (legally ofc)
is there any live support here?
i mean i'm not enough skilled for considering myself as a hacker lol
Not on discord
The site has a live support option
Need to speak to a person? Learn how to reach our support via HTB Labs.
Speaking from experience: only a few people in college actually wanna learn stuff, the other half just there for the degree and nowadays just cheese everything with LLMs
If you don’t consider yourself as hacker you are not a hacker. You have to think you are already a hacker. This way you have motivation.
But also, be advised it might be end of business day on a Friday
i feel the same tho
i did that and i gotta wait until monday...
Yeh, sorry
Well it is the weekend...
Support needs time off too
Support is always limited on weekends
Is college useless now?
Ive subscribed to the old school notion that you dont really get to call yourself a hacker until another hacker identifies you as one
but thats not nearly popular anymore
Lol
It's currently only good for networking... with your professors and the people they know in the industry
Kind of a "real recognizes real" thing
Maybe... for now i'm just a baby hacker then, i'm still learning the basics sooooo
No. you are a hacker
Caveat is they have to be someone anonymous to you
noob hacker but hacker
You cant just call your friend a hacker and they do the same with you

A hacker not any other hacker, not noob, not pro
It certainly makes it more memorable.
I remember for me it was after I posted an article about identifying exploit protection mechanisms in Linux back on the SecurityOverride forums.
I don't think I'll ever have that moment
ok
well if you dont subscribe to that ideology you wouldnt remember it
ethical hacker ?
Bro's a defender why would he wanna be recognized as a hacker? 
but thered def people that consider you a capable hacker @molten bobcat ❤️
There are no legit rules say that
And what happen if I break it
I appreciate it thank you
Well your friends might consider you a hacker but the community will still consider you a skid
Doesn’t matter
depends, if your friend is absolutely cracked it could count anyways
for me i'm still a skid
Same
Why I need to listen or look at other people letting them decide who I am
I decided who I am
that's ok tho, i'm still learning and i don't pretend anything
and i'm trying to improve myself
If that didnt matter to you in the first place then why join the conversation about people considering other people hackers
i'm living in a region of france full of geek, i should improve myself xD that's a must
like I said, my view is from a more old school of thought.
Call yourself whatever you want tbh, it ultimately comes down to whether or not youre actually doing shit or not.
I consider Lylias a hacker lol

you don't know my skills, how you can say that ?
what's a hacker for you then ?
hackers hack

And they consider themselves a skid. You can't change a person's perception of themselves just by saying they're something they think they're not
Oh ok
good definition

idk if i'm a skid but i'm still a beginner at least
ill take a skid thats striving to learn over a proclaimed hacker that just shitposts on discord any day
For instance I've always been a skid and that'll never change
ok be my mentor 
Skid? You never learn programming before?
@rancid snow taking students? Count me in!
whens the first class???
Sure. Step 1. Read the entire tcp/ip illustrated vol 1 and 2
Depends on what you consider a SKID I guess. I still use a ton of other people's scripts and don't completely understand how they work under the hood. Take something like impacket scripts I only understand a high level abstraction of what it's doing and dont know what's going on on the packet level. Which is why I think I'm a skid
But other people script are the best to use
Programming takes long time
decided to restart my soc training from scratch since the last time i used it my notes sucked ass
took a break to train firewall management stuff
Basic all powerful tools are coded by a team and contributer
Yes and no... what you gonna do when the script doesnt work and you cant fix it cos you dont understand it
if I want people to just check my pfp on HTB, do I HAVE To turn on public mode?
It useful when you want to understand how your target works
Like the client side
Meanwhile: mimikatz (solo writer)
I think palo alto defines a skid very well
But he takes long time
"novice attackers who use publicly available tools without fully realizing the implications of their actions"
6 reports are in triage for WP plugins...
No, your profile is public anyways
what does "private" mode do?
Just requires people to sign in before. Viewing your account
guys
in other words, they dont actually know hacking fundamentals and rely entirely on other people's work to do stuff for them
why is there a limited amount of instances lmao
Find another script
why would you need more than one instance
cant start my pwnbox zzz
im assuming that would affect me if im applying for intern/job and employer may wanna check to prove I did lot of stuff in HTB?
Cos money
Programming is a tool too. What if the language doesn’t work? You make your own language or you just find another one that works?
Mate noone who's employing you gonna be checking your HTB profile other than HTB themselves
oh good
Say that's the only script anyone has ever used cos it's what has worked, even nxc relies on impacket
This on academy or labs?
nvm im just dumb
I know someone whose writing his own impacket lul
Wym
What if for example the environment doesnt seem to work with impacket scripts and you dont have shell access on it. NXC? Also won't work cos behind the scenes it's impacket.
Depends on the situation some required you to write your own script
When I was doing file upload & sql by pass I was writing a lot of php
Exactly, which I'll never do, thus I'm a skid
do you get rank rewards when you reach a rank or by the end of season?
its funny how much you can learn by just staring at code
End of season

Ikr I learned how stupid I am after tryna read C
The secret is that most code bases look incomprehensible when you first look at them. You gotta give yourself a little time to get used to how the project devs write things before you decide you dont understand
go read the sys utils source go for stuff like chfn and su
a little confusing at first and then its shockingly simple code once you get it
Meanwhile Rust:
// Taken from Sylvain Kerkour's Black Hat Rust
struct Haha<'y, 'o, L, O>
where for<'oO> L: FnOnce(&'oO O) -> &'o O,
O: Trait<L, 'o, L>,
O::Item : Clone + Debug + 'static {
x: L,
}
Mission almost complete I think I might still have HTB employees to give stickers to
C is only hard by the memory management, and the system library. I used in my MacOSX before and the memory keep breaking, I used both strcpy and strncpy still breaking. Btw that MacBook have 32GB ram
Sometime it works
Sometime it breaks
I was doing fuzzing with that
Okay rust is actually incomprehensible even if you know rust without spending an exorbitant amount of time understanding each line
Also didnt realize they made a Black Hat Rust book already, Ill have to pick it up
I know rust but HRTB and lifetime annotations scares me 
I wrote a small project in Rust and felt like some of the most beautiful code Ive ever written and then the next day I didn't understand any of it
Fuzzing using curl library
What I hate the most is the lack of interopability of the async libraries. Everyone just uses tokio but if I want to interface with an embedded system I now have to refactor everything to async-std
Even used free
The syntax
thats one thing go does right, being designed for parallelism of all sorts from the beginning.
if rust had async features as part of the design itd be godly
Ive been really liking zig but the documentation is laughable. Doing anything beyond a toy example has you off pioneering your own shit
Rust has really nice parallelism just not async runtimes really nice cos it does preemptive scheduling which the ways the libraries handle it aren't compatible with each other. Go's parallelism might be easier to write but it's still all runtime voodoo due to cooperative scheduling
go syntax is just python with braces
And if err!=nil
Yeah but at least Python uses : before type
True but parallelism feels useless without async support. But maybe thats just me
So does rust
yeah, that comes up so often I feel like go really should just have a native shorthand for it
Don't get me wrong Rust's async is a god send, it's just annoying that the most used library for async isn't compatible with embedded systems
But rust have no many weird syntax that can be used
I went a search and identified a bit Rust kinda like C++
Rust is easier to read than Java...
fn Main() {
println!("hello world");
}
V.S.
public static void main(String args) {
std.System.out.println("hello world");
}
Does std required in Java? I never used one
java is just so verbose it becomes more nonesense than terser languages
Rust is hybrid of C++ & Python
& JS
Gladly my situation doesn’t need to use rust
java and c# are straight up a whole ass iliad
Why is madf0x angy
Some function syntax in Java is lowest first letter in C# is upper case lol
yeah my biggest issue with Rust is that for anything I need to write Rust is just overkill lul but diff languages for diff problems
im always mad
Why is angyBirb angy
their parents beat them as a child
Ditch rust and write something new in Nim
Know what's easier than that
python
lol
print("Hello World!")
I might actually. I like to try out different languages just to experiment
W this is the best one
They have a nice ffi for glfw
Printf is better than std::cout
It's the most readable. Not the most optimized and quick though. Plus compiler.
I like the way it writes thouhg. Almost stupid proof
Yes but python doesn't have true parallelism
cin.get() vs cin >>
But scanf is not better than std::cin
python is best when I need something written faster than I need it to run
Python isnt even a language its a program
lol
Oh yeah i finished that part
if I just need to make a web request to scrape a little data real quick I aint busting out c
Btw
Scanf I think it need use reference
Imagine everytime you write code it has to run a program to run a program, can't be me
I'm aiming to learn go next
go is honestly my favorite language to actually write in
Get out bro
We Python here only
If I making a quick web request I aint busting out programming I'm opening caido/burp
Even we do know some other language but Python is mainly loved
its one language where I can write 100+ lines and then actually expect it to run how I think it should
Hey man we dont discriminate for language preference here.
Except php

My friend actually beat me to lvl 45
But he doesnt have a job
Thats why
Php is like C++ even the the class constructor uses this.
this->variable
He also taking the go path im doing the typescript one
I was gonna say he's most likely just hammering away at it.
But good for you two for getting through it so quick
it's a really wonderful website
I've learned a ton
Dude im steuggling with functional programming
I was gunna give an example and realized that I had actually used go for that project instead of python lol
(scraping wordpress.org themes+plugins for mass static analysis)
Not in a bad way though
Do some challenges. Like ask Boots to craft you some practice on concepts you're still not understanding
That's what I did
helps out a lot
Ill try it
Go use OOP. So many things you can do than functional
whats Boots
You won't regret it. Ask it for varying levels too.
The AI on the boot.dev platform that assists you with hints and questions on certain problems. It recently got the ability to craft challenges for users as well
oh neat
You just tell it what you want and the difficulty level and it spits out a practice challenge with directions
I can’t think of child coding Rblox games in lua without true OOP as object instead using functional as objects
I havnt checked out boot.dev yet
Or use Rust and get the best of both
Python do both easy too
Do it. It's super great if you want to learn backend development or just have some fun learning coding
Even have super to access the child class constructor
It has a very HTB structure. Concept, material, and then little quizzes
Very hands on
Yes but you also always running 2 programs just for a simple hello world
Thats def neat. I unfortunately have my schedule packed out for quite some time. Esp since stuff has gotten pushed back for being sick
i hate google that's why i dont wanna learn go; there was a time when i was using it, but then i hated google after using it
They need to make Python compiled one day
...you can
You can compile python
But their bug bounty program is so sweet
It's just stupid to do so...
That’s not truly compiled it just combine the cpython and ur code into one
PyInstaller doesn’t support every os lol
they have a bb program? interesting I thought their bounties were outsourced.
It large company any bug you find you get pay good. It very hard but you know
When you find one you will be happy
I have heard good things about googles bb
$5,000 for some XSS instead of $50
if its that serious
Not if you compile with RustPython
Yea


