#general

1 messages Β· Page 467 of 1

devout sail
#

Ik

frozen zinc
#

So is very interesting, it can be use with C2s so the port is "close" (application layer) and then the interface wait for a specific sequence to open the port

#

so you hide the server

molten bobcat
#

I'm tired

frozen zinc
#

like knocking a door in a specific way and then it open

molten bobcat
#

Yelling read the Bible and then linking the mitre framework is funny to me lol

brittle quail
#

it seems like my connection to the box is rlly unstable. it keeps flashing from "connected" to "connect"

frozen zinc
#

it can be also use to hide port 22 for example

molten bobcat
frozen zinc
#

so when you do the initial nmap scan port 22 is not there

molten bobcat
#

You don't connect to machines directly

#

You're connected to the network the machine is on

devout sail
molten bobcat
#

Your network connection is what is unstable, not the target

frozen zinc
#

do the box Nineveh if you can

devout sail
#

No vip

frozen zinc
#

oh

brittle quail
devout sail
#

Hmm my seasonal rewards are rotting
But I'm lazy to use it cuz I know I won't be using it much

molten bobcat
#

Have you done any network tests lately?

devout sail
#

No cloud, currently many people are having such issues

molten bobcat
#

Awee

devout sail
molten bobcat
#

Nevermind then

devout sail
#

Especially EU

brittle quail
#

i run the vpn and it keeps saying
2026-02-11 14:22:25 Restart pause, 2 second(s

molten bobcat
#

It seems that HTB servers are having issues

#

So don't worry about it, nothing you've done πŸ‘πŸ»

brittle quail
#

thast why?

molten bobcat
#

Ya ya

brittle quail
#

wowwww

#

ok

molten bobcat
#

How fun

devout sail
brittle quail
#

this whole time i thought i was doing something

molten bobcat
#

I mean

#

It could be a coincidence

brittle quail
#

i probably still am 😭

molten bobcat
#

Exactly lol

frozen zinc
#

i pay you cookies

brittle quail
#

it js keeps disconnecting

devout sail
devout sail
#

Go for US or SG

brittle quail
devout sail
#

Ok don't download any which says 0 beside name

#

Idk if that's latency or user count
But those doesn't work

brittle quail
#

yea i just think the severs are lagging

#

im just gonna try every server

devout sail
#

Hehe i can't evenr recommend vpn now

#

All i remember is I used vpn 267

#

The ID not name

molten bobcat
#

At this point just

#

Give it some time

#

They'll resolve it

frozen zinc
brittle quail
#

whats the command to disconnect from openvpn vpn

molten bobcat
frozen zinc
#

I dont need to study more cyber sec i will just open that panel and look at it

devout sail
#

sudo pkill openvpn just to be sure

molten bobcat
#

Ctrl C is "stop" when something is running in the command line btw

brittle quail
#

ima js reset vm

devout sail
molten bobcat
#

Sudo pkill openvpn does this

#

All that does is kill all processes with the name openvpn

brittle quail
#

im trying us machines 4

frozen zinc
#

you can scroll up still

#

sometimes is annoy

devout sail
#

Doesn't really matter lmao
They just wanna clear screen

frozen zinc
#

xD

molten bobcat
#

It's cls

#

Tyvm

frozen zinc
#

export TERM=xterm

#

clear

brittle quail
#

now im running the vpn file and now it says my certi not valid

#

wonderful

frozen zinc
#

wonderful world wonderful people

brittle quail
#

why did pterodactyl get 2.7 stars πŸ’€

iron hollow
brittle quail
#

im gonna do a different machine all the other ones have like 4+ stars

frozen zinc
#

Do Hercules

brittle quail
#

im doin

#

browsed

#

its medium

#

i can only do medium or easy

frozen zinc
#

Are you doing academy?

#

Super Easy challenges are fun also

molten bobcat
green kite
#

hello chat

cerulean knoll
#

Yoo wassup

green kite
#

Not much. You?

cerulean knoll
#

Normal vibes

green kite
#

Nice

cerulean knoll
#

Yep

#

Any hacking today

green kite
#

No, hacked too much already

#

Gotta leave some for other people

cerulean knoll
#

πŸ˜‚okay. I see I'm talking to a legend 🫑

thick forge
green kite
#

Hahaha

cerulean knoll
#

Respect 😌

green kite
#

Bro I got your ip

#

127.0.0.1

#

πŸ˜†

cerulean knoll
#

Omg I'm super scared 😳

#

😭

green kite
#

Hahaha

cerulean knoll
#

I got a question

green kite
#

Sure

cerulean knoll
#

I'm trying to pass a username and password through burp repeater. I'm still finding it difficult to pass the values

green kite
#

What do you mean? It’s just entering the values?

velvet root
#

What is the way to contact hack the box store. I tried sending mail to their email. But no one responded.

green kite
west lynxBOT
cerulean knoll
#

It's a portswigger lab btw

green kite
#

Trying to hack Carlos eh

cerulean knoll
green kite
#

Poor Carlos. Being cyberbullied

cerulean knoll
#

Justice for Carlos πŸ˜‚πŸ«‘

rancid snow
#

Carlos knows what he did

upbeat frigate
#

Can two people have the same username on the HTB labs platform?

upbeat frigate
# molten bobcat No

So if someone posted a screenshot claiming they pwned a specific machine, but my friend couldn't find that username, and created his account under that username, that means that someone was capping? lol

molten bobcat
#

Yep

cerulean knoll
upbeat frigate
#

Dam, that's crazy

molten bobcat
#

Every account is searchable complete with a history of boxes solved

upbeat frigate
#

I've just completed SSRF, and poor Carlos

cerulean knoll
#

And I'm finding it difficult to login through burp. I've intercepted the request, I have the creds but I can't pass them through repeater to gain access

rancid snow
upbeat frigate
cerulean knoll
rancid snow
#

sure

cerulean knoll
#

Thanks

signal mica
rancid snow
#

I havnt done the lab itself but might be able to spot if theres a syntax issue

molten bobcat
signal mica
#

ts loads for u and displays my profile?

#

@molten bobcat

molten bobcat
#

I'm on mobile and am workin atm

#

I can't check I am sorry πŸ˜”

signal mica
#

i swear on hood if htb changes ts while im writing a cv

#

im deleting my acc

#

and destroying the whole htb infra from g0blins account

rapid badger
green kite
#

I just retested a flaw I reported that was supposedly fixed

#

Yes, I can’t send th parameter anymore that I paid the full amount. But I can still send negative qty πŸ˜†

rancid snow
#

partial fixes are fun

green kite
#

Yeah

gray wraith
#

Yes, it does show your profile

green kite
#

But obviously I’m a good guy and I reported it responsibly, again

gray wraith
#

And there is a graph showing boxes solved

#

As wellnas activity

rancid snow
#

I report the same htb issue like once every year

signal mica
gray wraith
#

Np prayge

supple plume
#

Im back

green kite
supple plume
signal mica
# supple plume

whats with all the redirects and shit man who tf is writing this backend

signal mica
supple plume
#

this is what happens when htb doesn't offer me a job

devout sail
green kite
devout sail
#

I thought he just meows here and there

signal mica
#

😾

supple plume
devout sail
#

That 97.95% is annoying
Make it 100

#

How many challenges for 100

supple plume
#

400

signal mica
#

all

supple plume
#

xd

devout sail
#

Like all active content should be completed?

signal mica
#

ya

#

for omni

devout sail
#

Machines and challenges only i assume

green kite
#

@austere sinew wake up

supple plume
#

ea despierta

#

@austere sinew

signal mica
#

ME GUSTA LO MEJOR

#

WOLO

#

VAMONOS

devout sail
#

I gotta steal laptop

#

And get all challenges

green kite
#

Get me a coffee wolo

#

And some Cadbury

devout sail
#

So stealing a skull

devout sail
#

would work as an ashtray after i become omni

signal mica
#

id probably hit some chinese mountain and master wushu

#

bodhi after that

devout sail
#

Hit some 😏

signal mica
#

shie forgor to dm shawty today

devout sail
#

Issok

#

I'll take care

#

@native plume he forgot to dm you, so fuck you
Don't bother him anymore

gray wraith
molten bobcat
#

I just want my exam results

gray wraith
molten bobcat
#

It was nice to have a fresh challenge that required

#

Thought

devout sail
molten bobcat
#

Even if I'm still exhausted from it lmao

green kite
#

What’s your next endeavour cloud?

supple plume
#

Cover the sun

molten bobcat
#

I'll decide after I get my results lmao

#

For now I'm BIG CHILLIN

green kite
supple plume
#

I have documented a lot today huge documentation task

molten bobcat
#

Maybe I'll just emulate frost and go to the gym and start studying web lol

supple plume
#

Unless you replace the cheese tho

green kite
molten bobcat
#

I'm a "one thing at a time" kinda guy

#

But ty ty

frail turtle
#

the nypd are a bunch of scumbags, I left my final email to them as Evil people deserve evil people around them.

supple plume
#

@frail turtle PizzaGoose

frail turtle
#

because they couldn't get in touch with my place of work from 2021 they wouldn't hire me after a long beaurocratic process.

warm ravine
#

@supple plume I'm starting to get into the basics of HTTP

frail turtle
#

I was like how tf is that my fault

supple plume
#

That is fundamentals to understand web

warm ravine
heady sage
#

HMMMMM

green kite
supple plume
frail turtle
#

whatver most nypd get sent to the depths of hell, they deserve it, all those neighborhoods full of gangs

signal mica
lime trout
warm ravine
warm ravine
supple plume
#

There is a lot in the frontend

west venture
lime trout
frail turtle
#

discord had their users IDs leaked via the third party they outsourced their verification to

#

it happened I think in 2024

#

and now they are doing it again

lime trout
#

i suggest clicking the button

warm ravine
#

Holy hell

#

No way

frail turtle
#

I'm not clikcing that

warm ravine
west venture
#

Also discord is going to block all accounts by default unless they verify age via 3d face scan or ID

lime trout
#

its a rickroll

#

lol

frail turtle
#

lol

west venture
#

Oh I didn't fall for it

warm ravine
frail turtle
#

lol

warm ravine
supple plume
frail turtle
#

nahh emma is trustworthy

warm ravine
#

Nothing but every single anti-virus says its safe

frail turtle
#

but discord is not

lime trout
jaunty pulsar
warm ravine
frail turtle
#

lol

jaunty pulsar
#

some weird ideas are coming out of my mind rn

frail turtle
#

dont do it

warm ravine
#

I wonder how many blackhat hackers gonna hack discord after this update comes out

frail turtle
#

and dont worry guys i will invent the new websocket based web chatting site we will all migrate to

warm ravine
#

Every single person's personal data

#

Gone to dust

jaunty pulsar
supple plume
#

Dust

frail turtle
#

i think discord uses websockets

#

-.o

warm ravine
west venture
#

I haven't slept in over 20 hours again

jaunty pulsar
supple plume
jaunty pulsar
#

happens a lot

west venture
#

I wanna play chess

supple plume
warm ravine
west venture
#

But I also don't want to

frail turtle
#

yeah discord uses websockets

jaunty pulsar
warm ravine
supple plume
warm ravine
west venture
#

Mine is 30+

frail turtle
#

dude it's just the phone number verification is enough

#

discord is just being hostile

warm ravine
frail turtle
#

why would they need more

warm ravine
#

Including us

jaunty pulsar
warm ravine
#

Ok so which chatting platform we have than this one

wind marlin
#

yo

warm ravine
#

Tell me

west venture
frail turtle
#

.........there's so many out there

west venture
#

Let's start a telegram channel

supple plume
warm ravine
#

@supple plume Coming to Back End

warm ravine
jaunty pulsar
warm ravine
#

Almost same as Discord

frail turtle
#

do not ......DO NOT lose sleep

jaunty pulsar
#

and that night when I slept I had a cramp

frail turtle
#

;c

supple plume
supple plume
#

Sleeping bad is terrible

supple plume
warm ravine
#

So dying is

west venture
#

Yeah tbh

warm ravine
#

I mean

#

Why

#

Living is optional tell me

frozen zinc
frail turtle
#

not getting enough sleep promotes aging, and a bunch of absolutely terrible things

#

use a blue light filter

frail turtle
#

on your desktop environment

#

if you spend a lot of hours on pc

signal mica
#

we are the sultans of swing

supple plume
signal mica
#

convertible roof open

#

smoking a marlboro gold 100s

supple plume
#

Turbo

west venture
#

It's so hard to sleep when you have ADHD bc your brain won't shut up

supple plume
#

I really want to smoke tho

frail turtle
west venture
#

When you don't sleep for so long you start tasting blood in your mouth πŸ’€

molten bobcat
#

I'm working a threat hunt

signal mica
#

i solve boxes sometime

molten bobcat
#

Rogue network device

supple plume
#

The brain will stfu if you exercise hard

signal mica
#

it wont

#

haha

supple plume
warm ravine
#

Should throw bricks at myself

frail turtle
warm ravine
west venture
#

The only way is to take a daily intake oh glutathione it make me go to sleep VERY fast

signal mica
#

c1oud slept with a lot lizard waz

supple plume
west venture
#

But glutathione only come in beauty pills so like

signal mica
#

doesnt work on the mind

#

i tried

supple plume
signal mica
#

i can smoke za and my mind will shut up but then i stop dreaming and thats the terry davis road

frail turtle
#

i dont know that sounds like alife of suffering if you gotta tire yourself out physically to get sleep

west venture
#

People are just so lucky that they can lie down and then just fall asleep

frail turtle
#

im...about to do that right now

supple plume
signal mica
#

it best advice i can give to a fellow adhd

supple plume
#

Best is

#

Play a video about someone narrating a story

frail turtle
supple plume
#

Background and auto turn off

gray wraith
supple plume
#

You'll get to dream it while awake

gray wraith
supple plume
#

And the. Fall asleep

gray wraith
#

Maybe read a book instead or smth

frail turtle
#

i mean the blue light filter works pretty well for me

signal mica
frail turtle
#

i need ajob ;c

gray wraith
#

Rn

west venture
supple plume
frail turtle
#

I need a job working more on hacking isnt gonna het me a job

signal mica
frail turtle
#

i passed it i almost died doing that obstacle course

signal mica
#

love how shit like this IS PERMAENGRAVED IN MY BRAIN

supple plume
signal mica
#

SAVE ME

#

I WANT TO BE ONE OF CHIEF KEEFS STUPID COUSING DRINKING LEAN ALL DAY LOOKING STUPID

frail turtle
#

they had me do 20 push ups at the end with a weighted vest and two weights at the end of the obstacle course

#

only me

#

nobody else

supple plume
warm ravine
#

On the military training?

#

That would be my dream

frail turtle
#

and just two days ago they denied my application because they couldnt get in touch with some company i worked with 4 years ago

warm ravine
#

I love when a drill instructors shouts on my face

frail turtle
#

police

#

I told them that evil people only deserve to be around evil people

deep ferry
frail turtle
#

i keep seeing these ads

#

about people building apps with AI

#

like you just describe it and suddenly an app is made

deep ferry
#

that's how htb labs are made

frail turtle
#

don't say that

deep ferry
#

The front end is definitely vibecoded on most of them

frail turtle
#

you're looking to get shot by people who worked their asses off to make some of them

deep ferry
#

I'm behind 1337 proxies

deep ferry
molten bobcat
#

Note to self

#

Do not forget about your septum piercing

signal mica
#

no way a vaultie like urself would have a piercing

molten bobcat
#

I do indeed have a septum piercing and 3 tattoos

rancid snow
#

c1oud is gay, the piercing and tats were mandatory and scheduled as soon as he left the closet

stable tiger
#

parrot 7.1 has a watchdogs reference on boot

#

neat

molten bobcat
#

I think the best way to describe me is "former vaultie"

rancid snow
#

came out of the vault

deep ferry
#

fallout gifs check out

supple plume
molten bobcat
#

I fell asleep after eating my tacos and didn't properly store my leftovers

#

Rip

supple plume
#

Air fryer does the job

deep ferry
#

I'd like to thank Cobson

#

incomprehensible

rancid snow
#

I had it before you

undone fossil
#

lmao what a crazy message to reply to for that

frail turtle
#

oh

rancid snow
#

jk idk when you got yours, but I got cpts like 2+ years ago lol

frail turtle
#

i got mine last year

supple plume
#

I keep thinking if cpts will make a difference

#

Or not

rancid snow
#

its a fun cert, learned a lot, but the label doesnt help with interviews much

#

so depends on what kind of difference youre looking for

supple plume
#

Interviews

rancid snow
#

then its unlikely to make much of a difference, work on public projects you can showcase more

#

tooling, writeups, bug bounties, cves, etc

supple plume
#

Hmmm

#

Ok

rancid snow
#

but if you still need skills to go from newbie->high beginner/Icanseeintermediatearoundthecorner then cpts is good for learning

supple plume
#

I'm more interested on CWES

#

I wouldn't like to be pentesting AD stuff

#

Tbh

#

But I guess cpts and cwes is similar regards the job market

rapid badger
#

they share lots of modules

hybrid galleon
#

would you guys say HTB is to cybersecurity what the Odin project is to web developers?

#

bad comparison? lol

warm dome
rancid snow
#

I will say that unfortunately cpts is missing a couple of areas with AD pentesting that employers are super keen on.

They really want you to know about delegation attacks, relay attacks, and adcs. Which only gets mentions in cpts

supple plume
warm dome
supple plume
frozen zinc
#

Should I take notes about the Insomnia Attack? Is that still relevant nowdays?

#

(jokes about sleeping coming)

supple plume
#

I'm not googlin atm

frozen zinc
#

but very legacy

supple plume
supple plume
#

Made of the ugliest code ever

#

Every line of code was a vulnerability

frozen zinc
#

but spain is different

rancid snow
#

idk I think wete entering an era where old code is far more reliable than new code πŸ˜‚

frozen zinc
#

same with my last job they were doing the send email feature in the client...

supple plume
#

It was more of a poem about misery than software

supple plume
supple plume
#

Even without modifying the code

#

Lucky I quit that job already I hated every moment

rancid snow
#

plus idors, client side captcha checks, client side auth in general, shared user storage, private source code on public directory, sqli, and rce

azure remnant
#

gpt write me a code make sure it dosent break later

supple plume
azure remnant
#

Ah sry

#

I once made hilarous mistake in whatsapp where i took screenshots of chat 1 and instead of sending it to chat 2 to make fun of him i sent it to chat 1 by mistake

timber garnet
#

Anybody unable to spawn pwnbox instances atm ?

azure remnant
#

How im gonna sleep now

gray wraith
rancid snow
gray wraith
#

My guess is, adding them to cpts would be too expensive

flint rain
#

Are we allowed to publish writeups on mini prolabs, the ones with an official writeup available to download?

warm ravine
#

@supple plume yo

supple plume
#

Wsp

lofty marsh
#

What's cooking?

supple plume
warm ravine
lofty marsh
#

What echo I'm one of your hoes now ignoring me like that? sadglassadglassadglas

#

/j

mint ledge
#

he got sorcery user flag

frozen zinc
mint ledge
#

hes now a different man..

warm ravine
#

So.. fellas
I tried the Meow challenge, wanted to test smth
It wanted me to download VPN, every single time I tried downloading it, the terminal says it cant find the file

flint rain
mint ledge
lofty marsh
flint rain
#

for Hades xen rpg and others

#

the old ones

frozen zinc
supple plume
warm ravine
lofty marsh
frozen zinc
#

I didnt knew it

flint rain
#

np

warm ravine
lofty marsh
supple plume
#

that command creates the file

#

Fr

lofty marsh
#

AND HOW CAN YOU SHOVE A TEXT ON A JPG pikasadglas

warm ravine
lofty marsh
lofty marsh
warm ravine
mint ledge
#

bro forfeited for the day

lofty marsh
warm ravine
#

Had to use the last minutes for this

molten bobcat
#

Hacker bed time sleepoCat

warm ravine
#

Turns out its just a waste

mint ledge
lofty marsh
#

You guys sleep?

supple plume
warm ravine
#

I mean

mint ledge
#

das it

rancid snow
# lofty marsh Oh fr?

you can shove php into a jpg and if you manage to get a php application to include it the PHP code will run despite all the jpg file structure stuff

warm ravine
lofty marsh
warm ravine
#

Lemme try it

mint ledge
#

try that aswell

#

for vpn connection

#

(dont)

supple plume
#

NO PERVERSER ROOT evil_cat

lofty marsh
#

delete it ur gonn get muted πŸ’€

#

Speaking from past experience

mint ledge
#

hes not typing anymore

#

did he do it

#

im scared to know

rancid snow
#

Yeah theres enough absolute newbs that come in that dont get the joke and will run it

molten bobcat
#

Yehh

lofty marsh
#

but you didnt put sudo so ur good

mint ledge
frozen zinc
#

I remenber a guy who actually did the rm command in a spanish hacking server....

molten bobcat
mint ledge
#

so its good

molten bobcat
#

Kneel

frozen zinc
#

poor dude

rancid snow
molten bobcat
#

I hate clickfix a lot

#

Cloudflare turnstile bullshit

mint ledge
#

@warm ravine u good bro RatBeg

rancid snow
#

its kinda genius tbh

supple plume
frozen zinc
molten bobcat
molten bobcat
mint ledge
molten bobcat
#

R28gZnVjayB5b3Vyc2VsZiBsbWFv

warm ravine
#

@lofty marsh Can I DM

rancid snow
mint ledge
#

HES HERE

#

THANK GOD

supple plume
rancid snow
#

lotttta wiped drives back then

lofty marsh
west venture
molten bobcat
#

Cloudflare?

#

No

#

Lmao

supple plume
#

@@west venture @west venture @west venture sleep already

west venture
#

Oh

molten bobcat
#

That's a clickfix phishing page

supple plume
#

-# dogkek

west venture
#

I would've fallen for that tbh

rancid snow
#

ofc, thats why its genius

#

it doesnt have to outsmart people, it just has to level the right balance of tedious to trick regular people

#

everyone has seen annoying captchas and completely random cloudflare checks that if you dont know anything about computers it looks like just yet another new stupid captcha system

supple plume
#

Time sleep hopefully

potent gull
#

o/

supple plume
# potent gull o/

Zero dumb means that the zero is dumb or you are zero units of dumb? Maybe ZeroDumb is Dumb number 0 or some Zero named character that is dumb so the name is an insult against someone called Zero. Or is it that you're Zeroing the dumbness

potent gull
#

lol

#

I am one with 0, and anti dumb.

#

do zero dumb things = ZeroDumb

#

or, maybe it's all just a meme from AI

azure remnant
#

Or maybe

#

M****D is involved

potent gull
#

what is more likely is that I had a grand idea one day to start a blog, and t-shirt, super secret club for antihackery and it landed on ZeroDumb, and after that, I already had the domain and email so it stuck

warm dome
#

so im kinda curious why lets defend was brought when academy has so much blue team stuff

#

has it got something academy doesnt? havnt touched the lets defend platform yet

tawdry thorn
#

Hi guys, i just joint today and completed my first box Meow

potent gull
#

congrats on the first box

#

now just 999 more to go

sharp shuttle
#

All good marketing is funnel-shaped

potent gull
warm dome
sharp shuttle
#

There is no such thing as momentum anymore, the players are set, there will be no new platforms, so platforms cannabalize each other

supple plume
#

Time to become a relatively successful competitor and get cannibalized badmashInvictus

rapid badger
#

A red team platform buying up a blue team platform makes perfect sense. For example boot.dev which has tons of back-end only courses bought some large front-end platform.

sharp shuttle
#

What VulnLabs did only happened because HTB ignored pro labs and XCT was highly respected

#

We call that market cornering, at this point in the game, OffSec is all that HTB has to kill

#

and we all know offsec content is dogshit, so just by the nature of education, CPTS will surpass OSCP

#

HTB just needs to get one giant enterprise account that wants to standardize their testers education on it

#

HR will follow

frozen zinc
#

HTB will never kill offsec if they dont develop projects imo

warm dome
supple plume
exotic pendant
#

πŸ˜„

sharp shuttle
frozen zinc
#

and exploitdb also

sharp shuttle
#

Exploitdb is really just metasploit

exotic pendant
#

I wish I could go back in time and give myself an air fryer and the ninja creami when I was doing bodybuilding

lofty marsh
exotic pendant
#

wouldve been a game changer

rapid badger
exotic pendant
frozen zinc
#

Would be nice to see HTB release a community big project

exotic pendant
warm dome
warm dome
exotic pendant
#

I got it on black friday

warm dome
exotic pendant
sharp shuttle
#

shit frost had that ready

exotic pendant
#

or you can just dump fruit + fruit juice in a container, freeze and then you have a sherbert

warm dome
sharp shuttle
#

i also use the creami and frosts recipe

warm dome
#

might looko into one

sharp shuttle
#

it is a game changer

potent gull
#

guru speak, we listen. healthy ice cream is where it's at

sharp shuttle
#

You will never buy ice cream again

exotic pendant
#

The protein I used atm tastes like hot chocolate

supple plume
#

I stored strategically pizza crust in the fridge to toast it and eat it with fried eggs. Now these thoughts are haunting me while being hungry and trying to sleep.

warm dome
#

actually taste like melted ice cream

#

would go hard in that

exotic pendant
#

Ninja pizza oven would be nice

west venture
#

I like to eat chocolate frozen

exotic pendant
potent gull
#

that looks amazing

exotic pendant
#

9/10 ninja creami tho, would get again

frozen zinc
potent gull
#

I want a pizza oven. idk why, I have an oven. but a pizza oven seems nice

exotic pendant
#

I'll prob still go ooni

warm dome
supple plume
exotic pendant
#

I have this soft serve one but i dont make soft serve that much

#

the kid loves it

sharp shuttle
#

i just feel like there are better uses of time

exotic pendant
warm dome
exotic pendant
#

I only wanted orange name to match my pfp

potent gull
#

makes sense

sharp shuttle
west venture
exotic pendant
#

my pint of ice cream today was only 180 calories

sharp shuttle
#

I like making fruity pebble ice cream

#

220 a pint

exotic pendant
warm dome
supple plume
#

Time to indulge midnight pizza crusts

exotic pendant
lofty marsh
#

Fellasssss

warm dome
#

so trying to smash out as many as i can

supple plume
exotic pendant
#

Instead of meal 6, i just made ice cream

sharp shuttle
#

I actually let it sit in the milk then i strain out the wet cereal so i can get the essence, and sometimes l mix in the crunchy versions

exotic pendant
#

ah yeah I've seen that. Make cereal milk

west venture
#

You guys make ice cream? I just buy it

warm dome
rapid badger
#

Cereal Milk Ice cream

lofty marsh
#

Should I keep going with pentesting labs and keep practicing while preparing for devsecops, or should I take a break from it and dedicate to devsecops and THEN dedicate to pentest?

sharp shuttle
#

the fuck

lofty marsh
#

What do you guys recommend

sharp shuttle
#

thats so cursed

supple plume
frozen zinc
#

aahaha

exotic pendant
lofty marsh
exotic pendant
#

and you wont ever again

sharp shuttle
lofty marsh
#

plus coding with pentesting?

sharp shuttle
#

Pentesting cloud lol

lofty marsh
#

lethal

sharp shuttle
#

Cloud is mostly patched, the only exposure is keys

west venture
exotic pendant
#

got 3 more companies that i'm waiting on money for

lofty marsh
#

thats what I heard πŸ’€

warm dome
sharp shuttle
exotic pendant
#

but it's doing me good atm

sharp shuttle
#

Cloud is silly expensive

warm dome
west venture
lofty marsh
exotic pendant
#

kidding I pay my taxes

west venture
#

Is it easy or do you have to do hard work?

sharp shuttle
exotic pendant
#

knowing where and how to look

lofty marsh
#

Anyway enough for today I'm peacing out

#

Cya dudes

exotic pendant
#

after taxes

lofty marsh
#

probably this friday again

west venture
#

The reason I don't like doing it is writing reports. Like here the PoC take it or leave it I'm not going to babysit you ,😭

supple plume
west venture
#

Are the things you test mostly secure or do they have pretty easy vulnerabilities on average

sharp shuttle
#

What did you find?
2 criticals
Cool. Take those out of the report.

#

average real world pentest

#

"We do not accept them"

#

Rubberstamping is tough work

exotic pendant
#

like Hyper-V, RDP, PHP, etc

west venture
exotic pendant
#

I also got a few RCEs on steam

#

and riot

west venture
#

That's probably hardened aaf

exotic pendant
#

Ye a hyper-v escape

sharp shuttle
supple plume
#

What am I even reading

sharp shuttle
#

Real life

frozen zinc
#

And I thought toxic positivity was bad

sharp shuttle
#

I secretly judge yall who make cyber weapons

#

You are just fucking yourself

supple plume
#

I just make sucker bash aliases I am safe

sharp shuttle
#

Unless you have nested brokers, you are a loose end when a 0day is sold

supple plume
#

I don't even know what a nested broker is πŸ₯€

frozen zinc
#

@sharp shuttle what do you think about people like Chris Rock (the mercenary)

sharp shuttle
#

It means many middle men

supple plume
sharp shuttle
west venture
# exotic pendant and riot

I got a RCE in the boot rom of the MediaTek MT6739 chipset, after working on it for days, just so I can unlock it's carrier lock but since it cannot be patched it's not considered as a CVE

sharp shuttle
#

You found a 0day?

west venture
#

Idk

frozen zinc
#

ths is the last talk he did in defcon:
https://www.youtube.com/watch?v=ICjSXak50uo&feature=youtu.be

Governments and the private sector around the world spend billions of dollars on Electronic Counter Measures (ECMs) which include jamming technologies. These jammers are used by police departments to disrupt criminal communication operations as well as in prisons to disrupt prisoners using smuggled in cell phones. The military use jammers to dis...

β–Ά Play video
signal mica
#

full day of

west venture
#

Idk if it's 0day bc mediatek CPUs are notorious for having hardware exploits

signal mica
#

another one?

frozen zinc
#

He got famous when he did the one about creating and killing people

supple plume
warm ravine
#

I did it

sharp shuttle
#

Didnt know of him but will watch his talk

supple plume
#

You can say it now

warm ravine
frozen zinc
warm ravine
#

I finished my first challenge

supple plume
warm ravine
west venture
#

whoami is just an echo

#

echo $USER

sharp shuttle
#

whoami exists for easy skid identification

#

if you alias whoami/who you can catch skids in seconds

supple plume
#

πŸ”₯

sharp shuttle
#

skridpting

west venture
#

What do you use instead?

supple plume
#

"Who the fuck you think you are"

sharp shuttle
#

stat -c "%U" $(tty)

#

thats how real g's do it

west venture
#

You can also echo $USER

sharp shuttle
#

thats still obvious

supple plume
#

That's not very handy for scripting tho

misty hamlet
#

Hey everyone don’t get on much to chat I really should

So Iv been on htb for a little bit now just on a year or so and Iv been plucking away in the academy it’s great and all that but I feel like I’m not learning because I’m not putting anything in to actual practice I’m not doing boxes just the training
I’m currently doing a level 2 in intro to cyber security in college (not at all practical all the legal stuff)

But I’m going to start an boxes and was wondering if there’s anyone out there a few days a week just working on them so we could practically learn? Instead of just checking boxes and never using it the knowledge

Sorry for the long ass message

sharp shuttle
#

you can go through them with him

fathom pawn
sharp shuttle
rancid snow
fathom pawn
# sharp shuttle yes

but i feel like watching walkthroughs won't help me learn, or is that the wrong mentality

sharp shuttle
#

No its moreso when a user gets on, they run who/whoami, its an easy alias to kill the session and lock the computer

#

or just log it

#

honeypot 101

supple plume
rancid snow
#

sure, but im saying if youre the attacker and worried that it could be a honeypot tracking whoami, you should be employing different tactics entirely rather than trying to evade it with something like stat blah blah

west venture
#

alias whoami to "your mom"

supple plume
#

Everytime I run who I can see the face of Eminem asking "wH0o?

sharp shuttle
#

I gotcha, im just making a suggestion

supple plume
rancid snow
sharp shuttle
#

noted

rancid snow
#

make sure you snag id too

sharp shuttle
#

yeah i would just only allow one form of user id to work

supple plume
#

It would be hilarious to alias id to some ass function that finds the process of the rev shell and kills it

rancid snow
#

ez

#

just alias it to exit

rapid badger
#

alias id='vim' gg

sharp shuttle
supple plume
frigid belfry
#

Is this server migrating because of Discord age verification coming?

supple plume
#

Maybe with some function that checks time like 1 month ahead to activate

sharp shuttle
molten bobcat
#

No, this server will be unaffected

supple plume
rancid snow
west venture
#

If you have a honeypot can you make money by snitching on hackers?

rancid snow
#

no

west venture
#

Then why have one

sharp shuttle
#

no you will actually lose money

#

millions of bots will connect every day

frigid belfry
#

This is actually a global implementation for age verification

sharp shuttle
rancid snow
#

nothings stopping you from setting up a honeypot right now. Its mostly just for research purposes. Youll never catch someone interesting unless you work for an interesting place that allows you to set one up

#

nobody is blasting a ssh 0day across the internet for your rando ssh honeypot to catch

west venture
rancid snow
#

The Equation Group isnt guessing root/root just to see whats on your box either

rancid snow
#

Nah, being a criminal is work

sharp shuttle
#

Just so you know those research jobs are just selling 0days

rancid snow
#

its a harder job than a legitimate 40hr work week

sharp shuttle
#

Even if you are ethical you are harming people

#

Keep that in mind

west venture
#

Like do pen testing on public bug bounties, when you find 0days, sell them on the dark web no writing reports, nothing, just easy money

rancid snow
#

a week of blackhat hacking for $$ is backed up by months/years worth of money laundering to actually enjoy your gains

sharp shuttle
#

Whats your life worth?

west venture
#

Like 100

supple plume
#

Chat quit persuading about becoming black hat

#

Or I will ping cloud

sharp shuttle
#

The only hat you should be is gray

rancid snow
#

c1oud aint even a mod

west venture
#

Also I literally live in a cave in tnr middle of the woods ain't nobody catching me

sharp shuttle
rancid snow
#

Im just saying anyone who thinks blackhat is easy money has either not put the effort into actually reasoning out the logisitics and amount of work involved, or theyre begging to get caught immediately

west venture
sharp shuttle
#

Now we are talking

#

But how will you have an authorized xAI approved neuralink climax if your brain is protected from starlink?

rapid badger
#

Jerk it in a maylar blanket. Candy29: 1 Elon : 0

sharp shuttle
#

you spoke too soon

west venture
#

Lmao

sharp shuttle
#

Elon: 1

west venture
#

How did this chat come to this

sharp shuttle
#

i woke up

west venture
#

It's like 4 am

sharp shuttle
#

you are chinese?

#

its about 4pm for me

west venture
#

I am asian yes

sharp shuttle
#

I will dig a hole to you

rancid snow
#

haha fool. youve narrowed down your hemisphere

west venture
#

That's the minimum I'll ever go

sharp shuttle
#

whats your address if thats the case

wanton dock
#

do we have to use parrot for the cpts?

sharp shuttle
wanton dock
#

ty

west venture
#

Also I live on a remote uninhabited Island in the middle of the specific ocean

sharp shuttle
#

i used macOS

stable tiger
#

parrot 7.1 is so fucking slow bro

#

every vm i try it in it shits itself, no matter the specs i give the vm

cerulean knoll
#

True

#

😭

stable tiger
#

genuinely ragebaiting me

#

i even swapped my hypervisor from virtualbox to vmware to see if that was the issue

#

changed my processor affinity to ensure it was using my p cores

#

no

#

its just shit

#

ragebait.

sharp shuttle
#

If its slow you need more cpu

#

thats like the simple and the big of it

stable tiger
#

And gave it gpu acceleration

sharp shuttle
#

gpu?

#

in a vm

#

i wouldnt do that

rancid snow
stable tiger
#

i tried with both

#

on and off

west venture
#

Just use khali

sharp shuttle
#

took two attempts

stable tiger
#

ragebaited me too hard

rancid snow
#

I wonder how hard itd be for me now, but no way to find out

west venture
#

Even that's too bloated. Real hackers use a lightweight debian base and install tools manually

sharp shuttle
#

In any case there is no doubt its better than OSCP

rancid snow
#

yup

stable tiger
obtuse fern
wanton dock
sharp shuttle
#

yall not real hackers

rancid snow
stable tiger
#

here anyway

obtuse fern
#

Real hackers are in the wires

rancid snow
#

custom setup means custom metadata signature

sharp shuttle
#

no they dont bro

#

HR doesnt even read your resume anymore

#

Its all AI bots

#

they look for the keyword, OSCP

obtuse fern
sharp shuttle
#

thats it

west venture
stable tiger
sharp shuttle
#

and i just told you how to do it

#

and it works

sharp shuttle
#

and its true

obtuse fern
stable tiger
#

ah alr

sharp shuttle
#
  • HTB CPTS (OSCP Equivalent)
#

and do that with any other certs on the jd

obtuse fern
raven rain
#

HTB CPTS (CompTIA A+ equivalent)

sharp shuttle
#

It would work lol

wanton dock
rancid snow
#

cpts is like a 10 day exam. it can be extremely difficult to get the time off for it if youre paycheck to paycheck

raven rain
#

it's only a 10 day exam?

sharp shuttle
#

I failed my first CPTS, make sure you dedicate the full 10 days

raven rain
#

only 10 days

sharp shuttle
#

Its not that long if you have responsibilities

obtuse fern
obtuse fern
raven rain
#

yes it's not long if you don't dedicate every breath taking it, but i haven't seen any other exams give you 10 days to finish

#

not even college gave me that much time