#general

1 messages Β· Page 463 of 1

frozen zinc
#

Its the first reverse shell... there is when everything starts

devout sail
#

oh do u know why i have 21A?

#

prev one ot banned :D

#

i even lost 22A

frozen zinc
#

lol

devout sail
#

all i did was test discord API

cerulean bloom
devout sail
#

and they be like go away

frozen zinc
#

wow

azure remnant
#

evil

devout sail
#

@thick forge hacking?

thick forge
full aurora
#

you are a genius mate, its working after I change to US. ❀️

thick forge
#

7 min left

#

then hacking

#

tell me some easy box to start hacking

#

machinges

molten bobcat
#

I'm awake

molten bobcat
#

It's now everyone else's problem

frozen zinc
molten bobcat
#

Nah I had

#

A breakfast biscuit

#

And I've got my tea

exotic pendant
muted olive
#

how you doin

wicked iris
#

hey I recieved some code from a random number

#

can anyone tell what does it do >?

silver sinew
molten bobcat
#

Er, MFA code not token

wicked iris
#

this is it

molten bobcat
#

That's malware

wicked iris
#

what it is used for?

molten bobcat
#

Please do not enter this into your terminal

#

Well let's read the command

#

It's powershell and it's using Invoke Expression to run "IRM" against a remote IP on port 5506 for a file called zz.txt

#

Irm is "Invoke Rest Method"

#

So he's fetching content via irm

#

The content of zz.txt probably contains more malicious powershell commands

muted olive
#

its malware

molten bobcat
#

This is a phishing exploit designed to compromise whoever runs this in their terminal

muted olive
molten bobcat
#

I deal with this exact lame shit all day long at work

#

I've seen it a thousand times lmao

wicked iris
#

damm

#

cant we track it without opening that so called file?

warm ravine
#

Throw bricks at the user who send that thing

warm ravine
warm ravine
molten bobcat
#

The best way to analyze what this does is to run the command or grab the file from a sandbox

brittle quail
#

bro i asked ai to help me with pterodactyl and it js gave me the answers it dont know how to give hints

molten bobcat
warm ravine
molten bobcat
#

That's normally how I get the next stage of shit like this, I open a sandbox and start playing with it to see if I can't get the content of the file in question

devout sail
#

Just normal curl on host wouldn't hurt tho?

molten bobcat
wicked iris
#

do we have a program or somekind of software that detects this kind of sus codes and blocks them ?

molten bobcat
#

It's better to do so in a VM always

brittle quail
#

why tf did u recieve this from a random number

warm ravine
#

I use it most of the time

warm ravine
#

But

#

It only detects

devout sail
#

Just to see the file content πŸ’€
Why would it execute just from getting it

molten bobcat
#

But this is also "on your phone" I presume?

brittle quail
#

can i run that command

#

in a vm

molten bobcat
#

Do not fuck with malicious indicators unless you're trained

wicked iris
#

are they free to download or else somekind of subscriptions?

molten bobcat
#

Please

brittle quail
#

k ima ask ai what it does exactly

molten bobcat
molten bobcat
#

I can read powershell

wicked iris
#

laptop lenovo LOQ

molten bobcat
#

Earlier you made it sound like this was texted to you

#

Like via a cell phone

#

HEY

#

UNLINK THAT MORON

brittle quail
#

my bad

zealous charm
#

Pipe to bash to check

warm ravine
#

Hey, make sure to log off from internet when you're gonna activate that malware.
It'll spread like a worm and kaboom. You're done for, spread to the whole wi-fi network

molten bobcat
#

YOU JUST PROVIDED A HYPERLINK TO MALWARE IN CHAT

brittle quail
#

is that the virus tho?

molten bobcat
#

YES

brittle quail
#

so

#

can i click it

molten bobcat
#

What the fuck do you think I'm trying to say lmao

#

NO MORON

#

LEAVE IT ALONE

wicked iris
#

via whatsapp

molten bobcat
#

ITS DESIGNED TO STEAL YOUR SHIT

warm ravine
brittle quail
#

but i wanna see the malware

warm ravine
#

Holy shit dude

brittle quail
#

I WANT TO SEE IT

warm ravine
molten bobcat
warm ravine
molten bobcat
#

You about put this whole server in danger for no reason dude

brittle quail
#

no? im putting myself in danger

warm ravine
#

Why bother infecting our computers with that unknown file bruv

molten bobcat
#

YOU SENT THE LINK IN THE FUCKIN PUBLIC CHAT BRAH

#

UNREDACTED, HYPERLINKED, READY TO GO

brittle quail
warm ravine
wind plank
#

πŸ”’ Message has been redacted.
-# You will only see it if you are a VIP+ member of HackTheBox.

brittle quail
#

i can understand u just as well not screaming

wicked iris
molten bobcat
#

Because you're not under the gravity of the fuckin situation lmao

molten bobcat
warm ravine
molten bobcat
#

Are you in South America?

warm ravine
#

And infect their computa

brittle quail
#

this is is a hacking server no? people know more than well not to click random links

wicked iris
brittle quail
molten bobcat
#

There's been a large amount of this shit affecting countries in South America from Whatsapp

wicked iris
brittle quail
#

@wicked iris can you dm me the number that sent it

molten bobcat
#

Dude

#

You're not qualified

#

Knock it off lmao

brittle quail
molten bobcat
#

Anyway, this looks like ClickFix campaign to me

#

This normally looks like this

#

But it has a bunch of mutations and variants obviously

brittle quail
molten bobcat
#

Effectively the goal is to coerce the user into copy pasting malicious powershell

silver forge
#

not bad

molten bobcat
#

And run it via the windows run dialog box, win R

brittle quail
#

thats the site?

molten bobcat
#

No

brittle quail
#

is that a different virus or phishing link

molten bobcat
#

This is an ongoing malware campaign that shares indicators with what was shared from etsos

brittle quail
#

oh

wicked iris
#

+7(8443).... got from this numb.. not pasting whole number since pmdev is so cooked

waxen lagoon
brittle quail
#

yea i was gonna say, cloudlfare just makes u click once

molten bobcat
#

Doesnt super matter where it come from because phone numbers are easily faked

wicked iris
brittle quail
wicked iris
#

why you want it

molten bobcat
#

Anyway did the message contain anything else or is it just

#

The powershell command

brittle quail
wicked iris
#

nothing else

molten bobcat
#

Damn they're getting lazy as shit huh?

brittle quail
#

is there any way to inspect the link without opening it

molten bobcat
#

Threat actors suck

wicked iris
molten bobcat
#

No

#

Do not share scammer info please

warm ravine
#

Why this chat feels so dead rn

brittle quail
#

why would i want that

warm ravine
#

And with idiots except @molten bobcat

molten bobcat
#

I mean I woke up like 45 minutes ago

#

Y'all making me do my job before my shift starts damn

warm ravine
#

Get yourself a cup o' coffee

molten bobcat
#

I got some tea I'm vibin

warm ravine
#

And please, turn on Do Not Disturb

wicked iris
brittle quail
#

πŸ‡ΊπŸ‡Έ rsa 2022-08-25 13:20:38
(3 years ago)
web spam ddos

molten bobcat
#

It's incredibly dangerous to attempt to do malware analysis if you don't have knowledge beforehand and an environment set up to safely handle things

#

Because you'll just infect yourself

#

Like, I can teach you how to do this analysis if you want

warm ravine
#

Always check before going dawg

molten bobcat
#

But you HAVE to do shit safely

brittle quail
#

it's a web spam ddos

molten bobcat
#

No it's not.

#

Read the powershell. That's not what it does.

brittle quail
#

not the command

molten bobcat
#

The command is all that matters.

brittle quail
#

the IP is reported as a web spam ddos

molten bobcat
#

Because IP addresses can change.

supple plume
molten bobcat
#

Lmao

wicked iris
#

btw is turbo vpn really safe or just something

brittle quail
molten bobcat
#

Most VPNs accomplish the same thing

wicked iris
#

I used it while logging to dark web PepeProtecc

west venture
#

I can't with Huawei drivers bro. Like Why the fuck would you need to load 6 different drivers to the kernel, in the right sequence, then load some obscure firmware loader and load the firmware to the wifi chip, then load another initialization binary, and then echo a very specific code to > the wifi chip, for it to wake up and show the WLAN interface for 10 FUCKIN seconds and then dissapear again.

brittle quail
#

PS.Agent.bx!crit

warm ravine
west venture
supple plume
wicked iris
warm ravine
warm ravine
brittle quail
warm ravine
#

Ts really easy

west venture
supple plume
warm ravine
#

Nah

wicked iris
warm ravine
#

I'm watching tutorial on YouTube
But that one is a bit different than others

supple plume
#

try NOT to use it to write code at the beginning

#

and build something

molten bobcat
#

I don't use it at all

#

Because I don't care

supple plume
warm ravine
#

That's all

supple plume
#

xd

#

aright

warm ravine
#

I'm gonna start from the beginning

brittle quail
west venture
#

Cloud don't you work for china?

cerulean bloom
wicked iris
supple plume
#

donuts master you like donuts right?

brittle quail
west venture
#

Tor doesn't have search engines

wicked iris
cerulean bloom
molten bobcat
#

Not even 10 minutes into my shift and there's impacket lateral movement

#

Classic.

brittle quail
wicked iris
#

bruh a chinese or japanese man sent me frnd req

warm ravine
#

I use Vivaldi

wicked iris
warm ravine
#

Chrome suck ass

zealous charm
warm ravine
brittle quail
molten bobcat
#

Bragging about dark web access is stupid as hell

wicked iris
#

wang_chuanfu7531 <--- wtf is this

brittle quail
west venture
#

Tor has link directories or things like Ahmia which basically have manually submitted links to websites

wicked iris
west venture
#

They're most definitely scams lol

wicked iris
#

@jovial sapphire are you even real?

supple plume
brittle quail
#

what about torch and etc i thought they were called search engines

supple plume
wicked iris
brittle quail
wicked iris
brittle quail
wicked iris
wicked iris
brittle quail
west venture
# brittle quail its a search engine but i guess not

If it's a "dark web" one then no. Because search engines by design work by crawling the web and onion sites, by design prevent this behavior, so people have to literally submit the onion links to these, "search engines" which is why searching something in a dark web search engine only gives you results from like 0.05% of the entire database.

brittle quail
#

why would you

wicked iris
west venture
#

So is the normal internet

wicked iris
#

its just hidden links

west venture
#

Just a collection of regular website

wicked iris
#

but there''s illegal stuff tho

brittle quail
#

theres illegal stuff on the regular internet too

wicked iris
#

I am thinking to order YOU from dark web XD

brittle quail
#

my infos probably on there somewhere

#

i wonder, how can you remove all your information from the internet

wicked iris
#

@west venture are you free at the moment?

west venture
#

I'm free for like 10 minutes why lol

#

Then I go sleep

#

@wicked iris

wicked iris
west venture
#

What's that

wicked iris
#

just my clg stuff

#

kindof homework

west venture
#

You want me to do your homework?

wicked iris
tawdry sorrel
#

echo 'surrender on Faraday for @supple plume ' 2>/dev/null
cat cur_progress.txt
1/7
cat reason.txt
user is so dumb

supple plume
#

this fortrss is very cool

tawdry sorrel
#

echo 'd3v is motivated by @supple plume ' 2>/dev/null

west venture
supple plume
tawdry sorrel
supple plume
#

talking in pseudolinux?

west venture
#

Why you echoing shit to dev/null?

supple plume
#

because is fun!!!

wicked iris
#

btw dc is safe right? I wont get hcked just by accepting a friend req

supple plume
#

Im echoes and he is dev/null

#

xd

west venture
tidal musk
supple plume
#

mv /dev/urandom /Candy29

devout sail
#

/deez/bowl

wicked iris
west venture
#

echo "lmao" > /dev/null
✨ Nothing ✨

tidal musk
wicked iris
#

your server's chinese guy sent me frnd req and dn what to do'

supple plume
#

SELECT * FROM DEEZ_NUTS;

tawdry sorrel
west venture
devout sail
chrome tree
supple plume
molten bobcat
wicked iris
tawdry sorrel
#

sudo mv @west venture /tmp
sudo reboot

west venture
cerulean knoll
devout sail
muted olive
wicked iris
tawdry sorrel
#

bash war πŸͺ–

west venture
tidal musk
#

rm -f /usr/bin/sudo

west venture
supple plume
#

alias wrap='rm -rf' && wrap Candy29 && echo 'Deez nuts' > Candy.exe

silver sinew
devout sail
#

cd /proc
sudo kill -9 *
will this give flag?

chrome tree
wicked iris
#

import time
import random

def generate_melancholy(depth):
"""Recursively generates a lonely, fragmented story."""
fragments = [
"the silence", "a cold wind", "fading light",
"empty chairs", "forgotten letters", "dust"
]

if depth <= 0:
    return "..."


scenes = [f"{random.choice(fragments)} in {room}" 
          for room in ["the room", "the hallway", "the mind"]]


return f"{random.choice(scenes)} {generate_melancholy(depth-1)}"

def emotional_engine(stages):
"""Simulates a slow, emotional breakdown."""
echoes = []

for i, stage in enumerate(range(stages)):
  
    thought = f"{generate_melancholy(2)} "
    echoes.append(thought.upper() if i % 2 == 0 else thought.lower())
    
 
    time.sleep(0.3)
  
return "".join(echoes)

sadness_output = emotional_engine(4)
print("--- LOGGING EMOTIONAL STATE ---")
print(f"Memory Log: {sadness_output}")
print("--- END OF LOG ---")

supple plume
#

no vibecoded shi

tawdry sorrel
wicked iris
tidal musk
signal mica
tawdry sorrel
#

sudo pacman -Rns @silver sinew

zealous charm
wicked iris
west venture
wicked iris
#

Dont ask full form of CRT pls

supple plume
meager kernel
molten bobcat
#

Gmorning azo

wicked iris
meager kernel
wicked iris
#

its campus recrument training

ornate ibex
#

Helooo

west venture
meager kernel
#

Back in my day, CRT was cathode ray tube

devout sail
#

its texas

molten bobcat
#

I learned a wtfbin today

devout sail
#

J

meager kernel
west venture
#

/dev/ass sounds so rad

devout sail
#

Not allowed

#

Mods gonna beat u

supple plume
#

NO PERVERSER ROOT evil_cat

tawdry sorrel
#

chat gpt write me a funny bash command so I can be cool in htb general channel

meager kernel
devout sail
#

Hi kraton

tidal musk
#

why doesnt my shell warn me about no preserve root

devout sail
#

Long time no see

meager kernel
#

You said my name

#

Incorrectly said but still

cerulean knoll
devout sail
#

I called out 0x one

meager kernel
#

Oh

#

Ok

devout sail
#

I don't call u that

cerulean knoll
meager kernel
#

Unlucky

devout sail
#

You are kreatone

meager kernel
#

Anyway gonna sleep

meager kernel
#

Gn

#

Cya

west venture
#

pip install yourmum -break-system-binaries

devout sail
cerulean knoll
west venture
devout sail
devout sail
muted olive
cerulean knoll
tawdry sorrel
wicked iris
molten bobcat
#

I just want my exam results

devout sail
#

Chatgpt wouldn't give u anything dangerous tho

wicked iris
#

any cmd to delete useless files?

devout sail
tawdry sorrel
molten bobcat
#

Yeah

devout sail
wicked iris
muted olive
devout sail
#

Damn i thought the one you did might give instant results

molten bobcat
#

I turned my exam in on January 29th

tawdry sorrel
cerulean knoll
molten bobcat
wicked iris
west venture
cloud rampart
#

is that only me or htb's vpn is very tired lately ?

muted olive
cerulean knoll
wicked iris
west venture
wicked iris
#

still storage is missing ;-;

tawdry sorrel
#

why new comers lies a lot and say no sense shit

devout sail
#

Just go do pterodactyl

wicked iris
west venture
#

Oh

wicked iris
#

2Gb filled again for no reason -_0

west venture
#

@austere sinew

tawdry sorrel
wicked iris
#

oi is there any way to get paid apps for free?

devout sail
#

As long as u don't pay it's free

#

Take your mom's CC

valid thicket
#

bruh

west venture
cerulean knoll
wicked iris
devout sail
#

Nah my mom doesn't even have CC
I'm pretty sure no one in the family does πŸ’€

#

Did u get a job?

wicked iris
#

where to type it tho?

west venture
silver sinew
devout sail
#

3YOE of CTFs
And that specialist is your profile i assume

#

Fair enough, which team are u in nowadays

#

Namw

wicked iris
#

@vestal nimbus can you find the app solidworks ? like free download?

devout sail
#

Oh ? No one checks that in team lmao

#

Trol

wicked iris
#

have to use it for designing

devout sail
#

Yeah we are kinda active
Very busy life so we do it like in 2-3days

#

Not as active as used to be

wicked iris
devout sail
#

Not really we have work
So priorities

#

All i care about rn isnto het out team back to #69

#

It was stuck there for long time

scenic maple
#

@cerulean bloom what do you think full set of cses covers like if you complete it what can you expect ur cf ranking to be?

devout sail
#

Hehe some did tried prolabs
I gave up, C2 aren't my thing

tidal musk
#

echo 0 | sudo tee /proc/sys/kernel/randomize_va_space

devout sail
#

Hmm might do that

#

Nowadays I am busy 7 days at work
Sometimes even upto 12h
Very hard to find time to do random stuff

#

Probably

#

I been doing weird stuff πŸ’€
Too many stuff

wicked iris
#

damm 60 usd for the app ;-;

#

You sleep

tidal musk
#

@supple plume another game?

wicked iris
#

Go to sleep

devout sail
#

Sysadmin, lone soc (have yet to understand it and setup properly), dc infra support, etc

supple plume
west venture
#

Another what?

devout sail
#

Not kraton πŸ’€πŸ’€

tidal musk
wicked iris
#

this is unfair sadglas

devout sail
wicked iris
tidal musk
devout sail
#

Hmm not really
And that's not what I do
I said lone cuz there's not really anything properly setup, so i just look at siem , find those VMs / computers, check around for stuff and fix it needed to
Watching tickets /incidents is just the part of L1 soc

devout sail
tidal musk
#

😠

west venture
#

insmod yourmum.ko
insmod: error out of memory

lofty marsh
#

When does cube talks happen?

devout sail
lofty marsh
#

Time?

devout sail
#

It's on Friday

#

Find the time there

lofty marsh
devout sail
#

Yeah uhh aren't u Egyptian or greek people (idk what to call it)

#

Rome maybe

west venture
#

Tutankhamen

#

Have you seen Egyptian mommies

tidal musk
# devout sail Hehe i haven't had anything annoying to get it Fortunately the whole project is ...
[  42.771983] Kernel panic - not syncing: Fatal exception
[  42.772104] CPU: 3 PID: 1876 Comm: kworker/u16:7 Tainted: G        W  OE     6.7.4
[  42.772268] Hardware name: Generic x86_64 (BIOS 1.16.0 12/01/2025)
[  42.772412] RIP: 0010:do_page_fault+0x2af/0x4e0
[  42.772533] Code: 48 8b 3c 24 e8 91 6a ff ff 48 85 c0 74 09 <0f> 0b 48 83 c4 28 5b 41 5c 41 5d
[  42.772811] RSP: 0018:ffffb90003c03d98 EFLAGS: 00010246
[  42.772939] RAX: 0000000000000000 RBX: ffff88810c3a4000 RCX: 0000000000000001
[  42.773112] RDX: dead000000000122 RSI: ffff88810c3a4000 RDI: ffff88810c3a4000
[  42.773319] RBP: ffffb90003c03dc8 R08: 0000000000000000 R09: 0000000000000000
[  42.773538] R10: ffff888100000000 R11: 0000000000000000 R12: ffff88810c3a4000
[  42.773765] R13: 0000000000000000 R14: ffff88810c3a4000 R15: ffff88810c3a4000
[  42.774008] FS:  0000000000000000(0000) GS:ffff88817fc00000(0000) knlGS:0000000000000000
[  42.774288] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[  42.774521] CR2: 0000000000000008 CR3: 000000010c21a000 CR4: 0000000000770ee0
[  42.774795] Call Trace:
[  42.774912]  <TASK>
[  42.775028]  handle_mm_fault+0x1c7/0x3a0
[  42.775168]  exc_page_fault+0x94/0x1b0
[  42.775303]  asm_exc_page_fault+0x26/0x30
[  42.775447]  </TASK>
[  42.775578] Kernel Offset: disabled
[  42.775702] ---[ end Kernel panic - not syncing: Fatal exception ]---

nice wow amazing

devout sail
#

Fat exception indeed

tidal musk
#

why is kernel panicking at me

#

*cries*

devout sail
#

Easy yes , but time consuming

lofty marsh
#

It doesnt say time anywhere

devout sail
devout sail
#

When it was sent?

#

It would be the same next week

#

For me it's 9.28pm

tidal musk
lofty marsh
#

Ok perfect

west venture
devout sail
tidal musk
#

intel SDM said there is no ring 0

#

???

#

did they lie to me again

devout sail
#

See it's even trying to handle it's own fault
And is too nervous so making typos

west venture
#

Whenever a kernal panic happens, you should delete your init script and rewrite it from scratch

tidal musk
#

i blame the ram

#

im very angry at the ram now

#

it fed bullshit into the cpu

lofty marsh
#

Fellas

#

Is there any youtube video you recommend for pentesting? sadglas

#

||@supple plume fuck u ❀️ ||

scenic maple
#

if not walkthroughs then no

#

check ippsec

lofty marsh
#

Like how to think and what to do..

scenic maple
#

do academy

rancid snow
#

I feel like videos on the subject can be good entertainment but its extremely rare for it to actually be a useful learning aid

lofty marsh
rancid snow
#

hacking is a pretty text heavy field, best to get used to text heavy sources

lofty marsh
#

Bro what is this emoji πŸ’€

tidal musk
#

”Access granted” πŸ₯€πŸ₯€πŸ₯€ @supple plume

rancid snow
#

good book

tidal musk
lofty marsh
#

Because I cant quite explain

frozen zinc
#

The facs that people say "its not possible to do this in Arch use a kali Vm" and they dont even think about the existence of docker is sad

scenic maple
#

but i am pretty sure a 15 min vid wont cover how hackers get in kek

tidal musk
#

|| ||

scenic maple
#

|

lofty marsh
#

bro πŸ’€

scenic maple
#

i just dont recommend yt videos for pemtesting

lofty marsh
#

What do you recommend?

scenic maple
#

text

#

and labs

lofty marsh
#

Because me personally months ago I even struggled with the very easy boxes sadglas

#

I had to drop them to finish cjca first

lament shadow
#

uh

#

sup

#

i just started using htb

supple plume
#

hi

supple plume
#

@tidal musk we can play now

lament shadow
#

that's how a easy ctf goes

lofty marsh
#

Fucking finally stuffy replied to my dm πŸ’€

lament shadow
#

so who's stuffy?

lofty marsh
#

How come he isnt in this server this dude is my messiah in hackthebox sadglas

supple plume
tidal musk
#

||​||||​||||​||||​||||​||||​||||​||||​||||​||||​||||​||||​||||​||||​||||​||||​||||​||||​||||​||||​||

#

||​||||​||||​||||​||||​||||​||||​||||​||||​||||​||||​||||​||||​||||​||||​||||​||||​||||​||||​||||​||

supple plume
#

empty

rancid snow
#

@lofty marsh you keep throwing YouTube links at us like were actually gunna watch that shit

lament shadow
#

@devout sail

#

can u check dm's?

tidal musk
brittle quail
#

man i cant do it

#

fuck

devout sail
lofty marsh
molten bobcat
lofty marsh
#

I cant explain who stuffy is he has to see him πŸ’€

molten bobcat
#

@lament shadow delete your message

#

You're not supposed to post flags from challenges

scenic maple
#

@lament shadow what cloud said

#

i deleted

rancid snow
lament shadow
#

....

#

it's a made up one

#

😭

lofty marsh
lament shadow
#

im saying how the easy CTF's goes

lofty marsh
#

And second of all why did you get pressed? πŸ’€

lament shadow
brittle quail
#

anyone able to help me with the pterodactyl box

molten bobcat
heady field
#

Hey guys hope your doing well what labs should I focus on when I completed the Linux fundamentals module

#

Any response would be much appreciated

rancid snow
lofty marsh
rancid snow
#

I hate youtube πŸ‘Ώ

lofty marsh
#

Yeah anyway no hard feelings tho

rancid snow
#

Im just giving you some shit, dont take it hard lol

molten bobcat
molten bobcat
supple plume
#

xd

tidal musk
#

i got confused

supple plume
#

blunder psy4

tidal musk
#

thank god

#

i was running out of time

supple plume
#

xd

tidal musk
#

πŸ₯€

supple plume
#

gg

tidal musk
#

gg

supple plume
#

any hacking today?

tidal musk
#

bipolar game

scenic maple
#

yall analyze chess like it will solve world hunger

lofty marsh
#

Do u in any chances love toilet papers? wazwaz

tidal musk
supple plume
tidal musk
supple plume
#

I wrote a fake report about a box and finished the Faraday fortress

tidal musk
#

i mostly only do bug bounty on weekends

supple plume
tidal musk
supple plume
#

dange really?

#

that one pays good

supple plume
#

πŸ”₯

tidal musk
#

but still no severity change or bounty

lofty marsh
#

Does ippsec help you guys in labs?

supple plume
#

I can't hear you with all this grudge

tidal musk
#

at least i dont think its duplicate anymore

scenic maple
#

incerdible itch to ask what it is

#

but i know you cant share

tidal musk
#

didnt even need burp suite to find it

#

πŸ₯€

rancid snow
#

πŸ’€

scenic maple
#

lol same

#

i have had days like that

rancid snow
#

tbf my nasa find didnt use burp either

tidal musk
supple plume
#

nasa = never eat salad again πŸ«ƒ πŸ”

rancid snow
#

ye, nothing crazy cool but I wanted a letter

tidal musk
rancid snow
#

yup

scenic maple
#

what was it

rancid snow
#

leaked creds on one of their gitlab instances

tidal musk
#

@rancid snow twin <333

rancid snow
#

so found just by good ole reading code

scenic maple
#

i only have 3 xss and one of them is out of scope so didnt report (all combined)

rancid snow
tidal musk
#

whats rad

molten bobcat
#

I don't have any offensive accomplishments

scenic maple
molten bobcat
scenic maple
#

rad means cool

rancid snow
#

I was chasing down some other interesting leads but moved onto other things

tidal musk
rancid snow
rancid snow
tidal musk
#

omg

#

it was the git auth bypass report

#

i remember seeing it somewhere?

rancid snow
#

http basic auth hardcored password.

rancid snow
scenic maple
tidal musk
rancid snow
#

idr let me check. I didnt even notice when it was accepted because I was ghosted gor 3 months

molten bobcat
#

HTB STOP SENDING ME EMAILS THAT ARENT MY EXAM

tidal musk
molten bobcat
#

It appears I have solved

#

Or at least performed investigative work

#

On 556 cases so far

tidal musk
molten bobcat
#

I'm a defensive specialist

tidal musk
molten bobcat
#

The company doesn't get ransomwared basically

tidal musk
#

LOL

#

but is there like any badges or whatever

molten bobcat
#

But uh, as far as achievements I guess I've caught a criminal before

rancid snow
scenic maple
tidal musk
#

how long did it take u to find

rancid snow
#

I aint complaining. It was totally possible the creds were invalid too. I didnt check because they belonged to a specific employee and that was out of scope

brittle quail
rancid snow
#

poking around nasas 50k+ subdomains randomly lmao

tidal musk
#

infinity subdomains

tidal musk
rancid snow
#

Its why its a good program for real world practice

iron depot
#

hi guys

rancid snow
#

the search space is so vast youre bound to find something if you actually try

tidal musk
rancid snow
#

I dont really do much bug bounty at all tbh lol

#

I just specifically wanted a nasa letter for reasons

tidal musk
tidal musk
#

then u tell people u got it and they think ur lying

#

πŸ₯€

rancid snow
#

Just share the letter lol

#

thats what I did

scenic maple
#

h1 in 2026?

tidal musk
rancid snow
#

Sent to my family lmao

scenic maple
tidal musk
molten bobcat
#

I'm cold

iron depot
#

I already reported it in the OBB; I have two bugs there.

scenic maple
rancid snow
#

I do want a cooler bug though so I might go back for another letter. But I have toi many other projects first

tidal musk
tidal musk
#

or cia

rancid snow
#

Doing a low key pentest for a friend this week for a homelab hes running

molten bobcat
#

I think once I have my CDSA I'll just collapse for a while

rancid snow
#

I dont expect to find anything for him but mainly acting as sanity check

scenic maple
iron depot
tidal musk
#

😭

molten bobcat
#

Lmao

rancid snow
molten bobcat
#

Unsolicited means no one asked for it

rancid snow
#

Yeah he approached me about it

brittle quail
#

so i went to the domain for pterodactyl box but its not connecting?

tidal musk
molten bobcat
#

Hey mad how long did it take you to get results on your exam

#

Do you recall

rancid snow
#

The interesting part isnthe proxy into the lab is on some AI forward hosting service that has an open but bounty. So If I find anything Im expecting it to be platform related lul

molten bobcat
rancid snow
molten bobcat
tidal musk
molten bobcat
ornate ibex
#

Which exam?

molten bobcat
#

CDSA sir

rancid snow
ornate ibex
#

I'll tell them to fail you, so relax

molten bobcat
#

I turned it in January 29th, still waiting for results

scenic maple
#

20 business days means pretty much a month

ornate ibex
scenic maple
#

but feb 29th comes years later

molten bobcat
#

Honestly if I get a failing grade y'all need your heads examined lmao

rancid snow
#

they have way more exams to grade nowadays

rancid snow
molten bobcat
#

I don't have any risk riding on this exam it's fine

iron depot
rancid snow
#

Ive also never collabed on anything hacking before lmao

molten bobcat
#

I already have a job in cybersecurity

ornate ibex
#

that is what she said

iron depot
molten bobcat
#

I especially love working with lav, she's wicked Smaht

ornate ibex
#

I hope I didn't go overboard with the joke/sarcam/trolling

rancid snow
#

Ive like asked for advice but thats been it

ornate ibex
#

Good luck man, hopefully you ace it

#

Good Night

molten bobcat
scenic maple
#

tejas

#

progress

molten bobcat
#

I know I nailed it haha

rancid snow
#

collabing just for team experience might be good though

iron depot
#

I'm almost finished with CWES and CPTS.

ornate ibex
iron depot
#

lol

scenic maple
tidal musk
#

oops

ornate ibex
molten bobcat
#

I'm a defensive fella so it's probably the only one I'll really focus on or spend resources on

ornate ibex
molten bobcat
#

The content was great, I learned a lot

ornate ibex
#

SA exercise

scenic maple
molten bobcat
#

Although someone needs to be telling people the CDSA exam requires your eyes to be.. at the top of their game

scenic maple
#

or was it hmmmHug

ornate ibex
scenic maple
#

i remember there being one assesment where you literally have to know php

#

or ur fked

tidal musk
#

my cwes was 100 how come its 76% now did they change it?

iron depot
#

I wanted to learn wireless network penetration testing and hardware penetration testing. It's a shame I don't have the money.

molten bobcat
#

Understand how windows processes and process hollowing/injecting work or you're fucked lmao

molten bobcat
#

That's usually what happens

iron depot
scenic maple
#

its in the blog above

iron depot
tidal musk
#

now its 76% tho

tidal musk
#

cwee looks even better ngl im more interested in those modules

scenic maple
#

?

#

i have mixed opinions

tidal musk
#

its like the only thing i did for bb

#

rest was all practical 😭

iron depot
scenic maple
#

i see

#

checkout portswigger labs too

tidal musk
#

oh i forgot lol

#

portswigger too oops

#

long time ago now smh

scenic maple
#

peak shit

tidal musk
scenic maple
#

they added new labs check em out

tidal musk
tidal musk
scenic maple
#

thats disappointing

tidal musk
#

u got the exam?

#

is it worth it

inner void
#

Are there probs spawning machines?

#

Pterodactyl wanβ€˜t Start πŸ€·πŸΌβ€β™‚οΈ

zealous charm
scenic maple
zealous charm
scenic maple
#

how do i have more than u

tidal musk
#

its over twin

scenic maple
scenic maple
tidal musk
#

honestly real life is many times easier like fr

scenic maple
#

if u find the initial bug yeah

#

i suck at recon tho

zealous charm
#

light mode or dark mode NotLikeThis

scenic maple
#

dunno what can i do abt it

zealous charm
#

do the hacky hacky

scenic maple
#

i forgot how to change at this point

zealous charm
tidal musk
rancid snow
# scenic maple if u find the initial bug yeah

that is always the kicker. I think just about every bug Ive ever found on a website, hackthebox itself included, would be like an htb easy box vuln at best if not some starting point shit.

This issue is always finding the needle in the haystack

molten bobcat
#

My sister got her rn license

zealous charm
scenic maple
zealous charm
tidal musk
#

i want it

frail turtle
#

My autozone be like

iron depot
lofty marsh
#

Fellas..

#

For cybersecurity is it better to first be a backend dev or a sysadmin/IT?

alpine pumice
#

neither

tidal musk
#

backend

lofty marsh
tidal musk
alpine pumice
#

cybersecurity is a huge field my guy

#

it depends on what you want to focus on

lofty marsh
#

I want to eventually become a red teamer

#

But I have the degree to either become a sysadmin or backend dev

#

and I'm halfway done with CJCA

tidal musk
#

sysadmin wont get you good programming skills

alpine pumice
#

then being a sysadmin will help more imo because you need to know general foundational level IT concepts which being a sysadmin would facilitate, dev isn't gonna help you with anything like that except malware development later

tidal musk
#

all vulnerabilities are just lines of code in the end

lofty marsh
young glen
#

I want to learn Python

alpine pumice
#

the only thing backend will do is help you learn code, you need to know how to code to create malware and such so yeah

lofty marsh
#

Is there a cybersec role in htb where you can combine backend with something?

#

Either CPTS or CWES?

tidal musk
#

logic bugs and source code analysis

terse dirge
#

Why do people want so much organization/roadmaps?? Just do whatever it's not that difficult lmao.

lofty marsh
#

It is actually because if you do backend and it is useless for you in cybersecurity later on..?

terse dirge
#

If you want to learn malware either make malware or reverse engineer it.

supple plume
terse dirge
#

I really need a cig or something as well I'm not awake enough for this lmao

lofty marsh
#

I deleted my prev acc to not be distracted

supple plume
lofty marsh
terse dirge
#

If you're "well rounded" you're good at nothing but average at most of it is my understanding

lofty marsh
#

I keep getting different answers from everyone with this question... πŸ’€

#

One very good pentester I've been watching for a while replied to me
"you should be getting real world experience. Getting help desk jobs, sysad, do free assessments for companies, going to meetups, shadowing, interning, etc etc. If your only skill is shown in certs your sort of useless to a company."

terse dirge
#

If you wanna be a web dev learn web dev, if you wanna be a sysadmin learn sysadmin shit

supple plume
molten bobcat
supple plume
molten bobcat
#

"the best way to do something" changes person to person

terse dirge
#

I wanna get a trashy hotdog right now

molten bobcat
#

Absolute slop dog

supple plume
#

I am eating 2 big pizzas one for each buttcheek

supple plume
lofty marsh
supple plume
molten bobcat
#

I need to

#

Sleep more

#

I think

supple plume
#

Sleep more then

molten bobcat
#

I can't as much as I want to cuz I've got the job

#

To contend with

#

And apparently management is paying close attention to work output for the moment

supple plume
#

Regular cycles are important

molten bobcat
#

So I'm attempting to ✨ dazzle them

supple plume
#

For sleep

mystic harbor
#

Alone

supple plume
#

Bro wth you send in dm

#

Nasty

mystic harbor
#

You send worse

supple plume
#

I'll answer when I finish my dinner

#

But I still feel betrayed

lofty marsh
#

Let me make it up to you

#

I'll delete this one too in friday after cube talks kek

#

Btw

#

I'll send you what subjects I learned in college so you can have an idea

supple plume
#

do you also throw the pocket change in the trash cans when you buy something?

lofty marsh
#

nah jk jokes aside I was using discord only for cybersecurity shit.. not for fun

#

so when it became a distraction I deleted it

supple plume
#

aright

#

so how many time do you want to spend on one of these jobs'

lofty marsh
#

before you start

#

Let me send you my subjects on dm

supple plume
#

ok

lofty marsh
#

And now tell me if I can even become a sysadmin from those πŸ’€

supple plume
#

and half that shit is trash

lofty marsh
#

Alright then kek

#

Backend it is

supple plume
#

really is not that I am being rude for no reason

lofty marsh
#

It's only practical

supple plume
#

it's at least 50% of time waste

lofty marsh
#

It's a practical college..

#

Anyway

#

Backend it is

supple plume
#

mmm

#

I believe sysadmin would be better

#

to pivot to cyber

#

also if you study all this software development related stuff

#

think about it

#

sysadmin would give you more perspective

molten bobcat
#

Ughhhhhh

supple plume
molten bobcat
#

What does a guy have to do to not be on the priority queue two days in a row

supple plume
#

he sent me a message on dm that you're not seing

molten bobcat
#

They're killing me

#

Oh I'm just complaining about work no worries

lofty marsh
#

real

supple plume
lofty marsh
#

But you said I can't be a sysadmin with those.. sadglas

supple plume
#

well you can be whatever the fuck you want I didnt finish highscool and whoever told me I cant be a dev can suck my ass

molten bobcat
#

I was told I was too stupid to touch the computer.

lofty marsh
#

@molten bobcat since you're a community contributor your opinion will help me a lot too..

#

I can send you my subjects in college and tell me if I can become a sysadmin πŸ₯€

supple plume
#

cloud is rm -rfing mfs on log files

#

btw mr holmes

lofty marsh
#

ye

supple plume
lofty marsh
#

Oooo lesgooo

supple plume
#

cloud is blue teamer btw

lofty marsh
#

I havent touched any labs for months now.. I'll first finish CJCA and then I'll dedicate to labs

supple plume
#

I have been developing a lot of tools for it

gray wraith
supple plume
#

a lot evil_cat

supple plume