#general
1 messages Β· Page 467 of 1
So is very interesting, it can be use with C2s so the port is "close" (application layer) and then the interface wait for a specific sequence to open the port
so you hide the server
I'm tired
like knocking a door in a specific way and then it open
Yelling read the Bible and then linking the mitre framework is funny to me lol
it seems like my connection to the box is rlly unstable. it keeps flashing from "connected" to "connect"
it can be also use to hide port 22 for example
I would love to clarify something for you
so when you do the initial nmap scan port 22 is not there
You don't connect to machines directly
You're connected to the network the machine is on
Was reading it, might study in details later
do the box Nineveh if you can
No vip
oh
so the wifi im on is trash?
Hmm my seasonal rewards are rotting
But I'm lazy to use it cuz I know I won't be using it much
I mean that's what it seems like
Have you done any network tests lately?
No cloud, currently many people are having such issues
Awee
Check #1469754264372117698
Nevermind then
Especially EU
i run the vpn and it keeps saying
2026-02-11 14:22:25 Restart pause, 2 second(s
It seems that HTB servers are having issues
So don't worry about it, nothing you've done ππ»
thast why?
Ya ya
How fun
Download new VPN file for different server (TCP) and connect, if it connects
Spawn the machine on that network
this whole time i thought i was doing something
i probably still am π
give it ot me
Exactly lol
i pay you cookies
i alr got a new file
it js keeps disconnecting
Can't transfer or there will be HTB black market
us machines 7
Ok don't download any which says 0 beside name
Idk if that's latency or user count
But those doesn't work
Hehe i can't evenr recommend vpn now
All i remember is I used vpn 267
The ID not name
people this is cool as fuck
https://worldmonitor.app/
whats the command to disconnect from openvpn vpn
You Ctrl C the terminal running the command
I dont need to study more cyber sec i will just open that panel and look at it
sudo pkill openvpn just to be sure
Ctrl C is "stop" when something is running in the command line btw
ik but i did this im still connected
ima js reset vm
I hate it when people at work type "clear" instead of Ctrl+L
I keep telling them and they don't want to use it
Sudo pkill openvpn does this
All that does is kill all processes with the name openvpn
im trying us machines 4
well is not the same Ctrl+L does not really clear
you can scroll up still
sometimes is annoy
Doesn't really matter lmao
They just wanna clear screen
xD
wonderful world wonderful people
why did pterodactyl get 2.7 stars π
maybe b/c some of the path kept failing unless you reset the machine and/or changed release arenas?
im gonna do a different machine all the other ones have like 4+ stars
Do Hercules
hello chat
Yoo wassup
Not much. You?
Normal vibes
Nice
πokay. I see I'm talking to a legend π«‘
Hahaha
Respect π
Hahaha
I got a question
Sure
I'm trying to pass a username and password through burp repeater. I'm still finding it difficult to pass the values
What do you mean? Itβs just entering the values?
What is the way to contact hack the box store. I tried sending mail to their email. But no one responded.
Might just be best contacting support
Need to speak to a person? Learn how to reach our support via HTB Labs.
If I use the form on the site, it logs in as a standard user but I can change the cookie to that of an admin.
So I intercepted the request and want to login via burp as the user and change the cookie
It's a portswigger lab btw
Trying to hack Carlos eh
Naa I have to delete him. I know don't what problem portswigger has with him π
Poor Carlos. Being cyberbullied
Justice for Carlos ππ«‘
Carlos knows what he did
Can two people have the same username on the HTB labs platform?
So if someone posted a screenshot claiming they pwned a specific machine, but my friend couldn't find that username, and created his account under that username, that means that someone was capping? lol
Yep
C'mon I've seen 2 users always. Wiener and Carlos.
Why does it always have to be Carlos who gets deleted π
Dam, that's crazy
Every account is searchable complete with a history of boxes solved
BRO ISTG, I was thinking the same today
I've just completed SSRF, and poor Carlos
Congrats π₯³
I'm still on the basics
And I'm finding it difficult to login through burp. I've intercepted the request, I have the creds but I can't pass them through repeater to gain access
screenshot of what your repeater screen looks like
I did CRTP, and penetration Tester path, but forgot to do Portswigger first, so im back to basics :')
(I was suffering from getting initial access to machines)
U cool if I dm u
sure
Thanks
where is tfucking export url profile htb labs
I havnt done the lab itself but might be able to spot if theres a syntax issue
I've no clue
i swear on hood if htb changes ts while im writing a cv
im deleting my acc
and destroying the whole htb infra from g0blins account
I just retested a flaw I reported that was supposedly fixed
Yes, I canβt send th parameter anymore that I paid the full amount. But I can still send negative qty π
partial fixes are fun
Yeah
@signal mica if you sre curious
Yes, it does show your profile
But obviously Iβm a good guy and I reported it responsibly, again
I report the same htb issue like once every year
thanks man
Np 
Im back
No

whats with all the redirects and shit man who tf is writing this backend
ChatGPT-1
not me
this is what happens when htb doesn't offer me a job
Didn't know azomax was actually a hacker
At least they saved themselves from a DROP DATABASE
I thought he just meows here and there
πΎ
why all the beef 
400
all
xd
Like all active content should be completed?
Machines and challenges only i assume
@austere sinew wake up
So stealing a skull
would work as an ashtray after i become omni
Hit some π
Issok
I'll take care

@native plume he forgot to dm you, so fuck you
Don't bother him anymore
U dont want to do the pro Labs?
100% passed
They are probably busy in this love week
Even if I'm still exhausted from it lmao
Whatβs your next endeavour cloud?
Cover the sun
The struggle is real
I have documented a lot today huge documentation task
Maybe I'll just emulate frost and go to the gym and start studying web lol
You can't eat that much pizza π₯
Unless you replace the cheese tho
Lmk if you have CWES struggles, I know a thing or two
the nypd are a bunch of scumbags, I left my final email to them as Evil people deserve evil people around them.
@frail turtle 
because they couldn't get in touch with my place of work from 2021 they wouldn't hire me after a long beaurocratic process.
@supple plume I'm starting to get into the basics of HTTP
I was like how tf is that my fault
That is fundamentals to understand web
Just learned the vulnerabilities of Front End area
You know a thing or two?
HMMMMM
Maybe three
All of them?
whatver most nypd get sent to the depths of hell, they deserve it, all those neighborhoods full of gangs
thats too much, brain explode
Start climbing 
Its epic
Almost finished, moving to components of back end after that
WHAT
Hard to believe tho
There is a lot in the frontend
What is this?

discord had their users IDs leaked via the third party they outsourced their verification to
it happened I think in 2024
and now they are doing it again
i suggest clicking the button
I'm not clikcing that
Heck no
Also discord is going to block all accounts by default unless they verify age via 3d face scan or ID
lol
Oh I didn't fall for it
That's a simple phishing thing
Just harmless
lol
I scanned it
I was about to start sending dubious pics
nahh emma is trustworthy
Nothing but every single anti-virus says its safe
but discord is not
i'd never post anything that'd actually get censored here π
what rickroll requires age verification? 
Throw bricks at discord
lol
some weird ideas are coming out of my mind rn
dont do it
I wonder how many blackhat hackers gonna hack discord after this update comes out
and dont worry guys i will invent the new websocket based web chatting site we will all migrate to
the better question is: how many groups will "claim" they compromised their db?
Dust
Do they really get it or fake it?
I haven't slept in over 20 hours again
some groups just try to threaten and others actually have solid proof that they have hacked the company
Skill issue
happens a lot
I wanna play chess
Let's do it
Well I trust the people who actually hacked it so they can show how Discord cant protect their pathetic platform
But I also don't want to
yeah discord uses websockets
what's your record big boy? π
Wantn't
Wdym

Mine is 30+
dude it's just the phone number verification is enough
discord is just being hostile
Lmao
To their customers
why would they need more
Including us
what's your record in terms of hours awake without sleep?
Ok so which chatting platform we have than this one
yo
Tell me
We have telegram
.........there's so many out there
Let's start a telegram channel
I guess 2 nights but that's just brain damaging, skill issue is not sleeping good regularly
@supple plume Coming to Back End
How about TeamSpeak
yea I also lasted two full days without sleep for a hackathon
Almost same as Discord
do not ......DO NOT lose sleep
and that night when I slept I had a cramp
;c
Good, let me know the progress
It's not good
Nah sleep is optional
Sleeping bad is terrible
Sure, living is optional too
So dying is
Yeah tbh
not getting enough sleep promotes aging, and a bunch of absolutely terrible things
use a blue light filter
I'm a night owl
we are the sultans of swing
Because there is a checkbox that says optional
Turbo
It's so hard to sleep when you have ADHD bc your brain won't shut up
I really want to smoke tho
leverage this
Skill issue again
tell your adhd to be quiet
When you don't sleep for so long you start tasting blood in your mouth π
I'm working a threat hunt
i solve boxes sometime
Rogue network device
The brain will stfu if you exercise hard
Exercise harder
Should throw bricks at myself
did you find it?

The only way is to take a daily intake oh glutathione it make me go to sleep VERY fast
c1oud slept with a lot lizard 
180kg leg bench
Melatonine pills
But glutathione only come in beauty pills so like
thats physical exhaustion friend
doesnt work on the mind
i tried
Now we're talking
i can smoke za and my mind will shut up but then i stop dreaming and thats the terry davis road
i dont know that sounds like alife of suffering if you gotta tire yourself out physically to get sleep
Yeah
People are just so lucky that they can lie down and then just fall asleep
im...about to do that right now
I had to work on the fields for free today just so I can sleep
i envy them. you should try concentrating on sleep OR meditate before bed with a singular thought. works for me sometimes
it best advice i can give to a fellow adhd
you know what I envy? I envy not having that orange colored name because reasons
Background and auto turn off
And not frying eyes with blue light before sleep
You'll get to dream it while awake

And the. Fall asleep
Maybe read a book instead or smth
i mean the blue light filter works pretty well for me
how tf u have cpts but skid rank. why not solve like 8 boxes and you are like hacker rank
because I dont wanna be a hacker yet
i need ajob ;c
I get too anxious of falling asleep with the phone on
So after you get a job you will come back and get hacker badge
I need a job working more on hacking isnt gonna het me a job
you have a job you said you failed that jump over fence on physical test months ago?
i passed it i almost died doing that obstacle course
love how shit like this IS PERMAENGRAVED IN MY BRAIN
That is why it should be set to turn everything off automatically after the video ends
SAVE ME
I WANT TO BE ONE OF CHIEF KEEFS STUPID COUSING DRINKING LEAN ALL DAY LOOKING STUPID
they had me do 20 push ups at the end with a weighted vest and two weights at the end of the obstacle course
only me
nobody else
I like it, I can remember the image of his worn shoes too
Where
On the military training?
That would be my dream
and just two days ago they denied my application because they couldnt get in touch with some company i worked with 4 years ago
I love when a drill instructors shouts on my face
ATTENTIOOO
i keep seeing these ads
about people building apps with AI
like you just describe it and suddenly an app is made
that's how htb labs are made
don't say that
The front end is definitely vibecoded on most of them
you're looking to get shot by people who worked their asses off to make some of them
I'm behind 1337 proxies
I mean that the websites the labs run usually have AI images
no way a vaultie like urself would have a piercing
I do indeed have a septum piercing and 3 tattoos
c1oud is gay, the piercing and tats were mandatory and scheduled as soon as he left the closet
I think the best way to describe me is "former vaultie"
came out of the vault
fallout gifs check out
β
Doesn't matter
Air fryer does the job
congrats on the cpts
I had it before you
lmao what a crazy message to reply to for that
oh
jk idk when you got yours, but I got cpts like 2+ years ago lol
i got mine last year
its a fun cert, learned a lot, but the label doesnt help with interviews much
so depends on what kind of difference youre looking for
Interviews
then its unlikely to make much of a difference, work on public projects you can showcase more
tooling, writeups, bug bounties, cves, etc
but if you still need skills to go from newbie->high beginner/Icanseeintermediatearoundthecorner then cpts is good for learning
I'm more interested on CWES
I wouldn't like to be pentesting AD stuff
Tbh
But I guess cpts and cwes is similar regards the job market
they share lots of modules
would you guys say HTB is to cybersecurity what the Odin project is to web developers?
bad comparison? lol
you end up finishing sorcery root?
I will say that unfortunately cpts is missing a couple of areas with AD pentesting that employers are super keen on.
They really want you to know about delegation attacks, relay attacks, and adcs. Which only gets mentions in cpts
Not today
ohh okay
I went through most of it tho
Should I take notes about the Insomnia Attack? Is that still relevant nowdays?
(jokes about sleeping coming)
What's that
I'm not googlin atm
is a race condition on phpinfo() that allow you to get RCI from LFI
but very legacy
I've seen wild legacy apps running in production as a dev
Actually the last I worked on was a 15year old php monster
Made of the ugliest code ever
Every line of code was a vulnerability
but spain is different
idk I think wete entering an era where old code is far more reliable than new code π
same with my last job they were doing the send email feature in the client...
It was more of a poem about misery than software
Reliable my ass every 2 weeks some feature disappears and nobody knows how or why
ahaha
yeah okay that happens to the PoS system we use at work too lul
plus idors, client side captcha checks, client side auth in general, shared user storage, private source code on public directory, sqli, and rce
gpt write me a code make sure it dosent break later
Wrong chat buddy
Ah sry
I once made hilarous mistake in whatsapp where i took screenshots of chat 1 and instead of sending it to chat 2 to make fun of him i sent it to chat 1 by mistake
Anybody unable to spawn pwnbox instances atm ?
How im gonna sleep now
Maybe u can make a /suggestion iirc, unless this is explored more in different AD paths
academy covers those but theyre tier 4 modules
I am
Oof...
My guess is, adding them to cpts would be too expensive
Are we allowed to publish writeups on mini prolabs, the ones with an official writeup available to download?
@supple plume yo
Wsp
What's cooking?
π
Check dms
he got sorcery user flag
official writeups for mini pro labs? Are you sure about that?
hes now a different man..
So.. fellas
I tried the Meow challenge, wanted to test smth
It wanted me to download VPN, every single time I tried downloading it, the terminal says it cant find the file
I do see few of these
you're probably in the wrong directory
because you didnt cd to the correct directory
oh
π£οΈ π’ π₯
rm -rf @lofty marsh && echo 'DEEZ NUTS' > @lofty marsh.JPG
I mean.. cant I do it on my own VM?
he DEFINITELY didnt π₯
I didnt knew it
np
I'm trying something new bro
Bro u already deleted me how tf u gonn shove deez nuts at the jpg 
>will create new file
AND HOW CAN YOU SHOVE A TEXT ON A JPG 

That is part of the plan 
Wdym by that btw
cd to Downloads
Stego
jpgs can also hold arb text
and do sudo openvpn startingpointsomething.ovpn
I mean..
Like lemme do this tmmrw
bro forfeited for the day
Oh fr?
Cuz its night time
Had to use the last minutes for this
Hacker bed time 
Turns out its just a waste
my clock corrupts my os if i touch it so i can't tell
I have developed a set of tools that do that but with elegance
What should I do before that?
I mean
you can shove php into a jpg and if you manage to get a php application to include it the PHP code will run despite all the jpg file structure stuff
Ok uh
sudo openvpn startingpoint.ovpn```
Lemme try it
NO PERVERSER ROOT 
Yeah theres enough absolute newbs that come in that dont get the joke and will run it
Yehh
just add a tiny dot in front of the /
I remenber a guy who actually did the rm command in a spanish hacking server....
so its good
Kneel
poor dude
its crazy how effective this is
@warm ravine u good bro 
its kinda genius tbh
Someone asked me for someth8ng stupid like how to steal a bank account and I gave them the no perverser root and told them to add the website address after the # parameter, they vanished
He may be fighting against the VPN it got harder nowadays
I mean ya gave the brother the command to run
Base 64 encoded btw

hes still online i have faith 
R28gZnVjayB5b3Vyc2VsZiBsbWFv
@lofty marsh Can I DM
Not surprised.
I remember the days before --no-preserve-root was even required lul
@lofty marsh get pinged
lotttta wiped drives back then
Yee ofc
Is that your company?
@@west venture @west venture @west venture sleep already
Oh
That's a clickfix phishing page
-# 
I would've fallen for that tbh
ofc, thats why its genius
it doesnt have to outsmart people, it just has to level the right balance of tedious to trick regular people
everyone has seen annoying captchas and completely random cloudflare checks that if you dont know anything about computers it looks like just yet another new stupid captcha system
Time sleep hopefully
o/
Zero dumb means that the zero is dumb or you are zero units of dumb? Maybe ZeroDumb is Dumb number 0 or some Zero named character that is dumb so the name is an insult against someone called Zero. Or is it that you're Zeroing the dumbness
lol
I am one with 0, and anti dumb.
do zero dumb things = ZeroDumb
or, maybe it's all just a meme from AI
what is more likely is that I had a grand idea one day to start a blog, and t-shirt, super secret club for antihackery and it landed on ZeroDumb, and after that, I already had the domain and email so it stuck
so im kinda curious why lets defend was brought when academy has so much blue team stuff
has it got something academy doesnt? havnt touched the lets defend platform yet
Hi guys, i just joint today and completed my first box Meow
you live in a capitalistic market and can't identify the technique called "buying your competition"?
All good marketing is funnel-shaped
seems like a waste when htb has so much more momentum then they did tho
There is no such thing as momentum anymore, the players are set, there will be no new platforms, so platforms cannabalize each other
Time to become a relatively successful competitor and get cannibalized 
A red team platform buying up a blue team platform makes perfect sense. For example boot.dev which has tons of back-end only courses bought some large front-end platform.
What VulnLabs did only happened because HTB ignored pro labs and XCT was highly respected
We call that market cornering, at this point in the game, OffSec is all that HTB has to kill
and we all know offsec content is dogshit, so just by the nature of education, CPTS will surpass OSCP
HTB just needs to get one giant enterprise account that wants to standardize their testers education on it
HR will follow
HTB will never kill offsec if they dont develop projects imo
doesnt make sense when they have so much blue team content tho
What matters here is how do I begin making loads of cash legally, give me fastest path for an idiot like me
π
Metasploit is the only good product by OffSec, why would you use kali linux after you graduate their kindergarten oscp cert?
kali is shit im agree but metasploit is big
and exploitdb also
Exploitdb is really just metasploit
I wish I could go back in time and give myself an air fryer and the ninja creami when I was doing bodybuilding
It's not shit but its disposable..
wouldve been a game changer
Do they ? There is one blu cert and everything else is red. At least what it looks like to a newbie like me.
ninja creami?
Ice cream maker
Would be nice to see HTB release a community big project
and it's super easy to make healthy ice cream
sherlocks,challenges, that 1 blue team cert has alot in it, also a load of other blue team modules
bruh i need this
does it come with recipes for healthy icecream? or hows it turn out to be healthy
I usually do
1 scoop protein, milk under the fill line or almond milk for lower cal, dash of xanthan gum, and monk fruit
shit frost had that ready
or you can just dump fruit + fruit juice in a container, freeze and then you have a sherbert
i think i need to try this haha
i also use the creami and frosts recipe
might looko into one
it is a game changer
guru speak, we listen. healthy ice cream is where it's at
You will never buy ice cream again
The protein I used atm tastes like hot chocolate
I stored strategically pizza crust in the fridge to toast it and eat it with fried eggs. Now these thoughts are haunting me while being hungry and trying to sleep.
you should try the rule1 vanilla ice cream one
actually taste like melted ice cream
would go hard in that
I like to eat chocolate frozen
Ye that vanilla is good
that looks amazing
9/10 ninja creami tho, would get again
oh wow thats cheaper than ooni
I want a pizza oven. idk why, I have an oven. but a pizza oven seems nice
I'll prob still go ooni
btw these challenges are slow for guru feels like im just rapid firing them going through easy ones to tick em off
Gooning?
why do you want guru?
i just feel like there are better uses of time
Everytime I did a box, a new box kept coming out
just for sake of doing it
I only wanted orange name to match my pfp
makes sense
fair
I can't eat ice cream from a cone like that and enjoy it bc you have to be quick before It melts and starts to make a mess
Yeah i just eat it out of the container
my pint of ice cream today was only 180 calories
I was tempted to mix some in since I can eat rice cereal on my diet in the morning
yeah that was my issue before, but i wanna focus ono just weekly releases without other stuff sitting thhere
Time to indulge midnight pizza crusts
Fellasssss
so trying to smash out as many as i can
Wsp
Instead of meal 6, i just made ice cream
I actually let it sit in the milk then i strain out the wet cereal so i can get the essence, and sometimes l mix in the crunchy versions
ah yeah I've seen that. Make cereal milk
You guys make ice cream? I just buy it
its healthy tho one he makes
Cereal Milk Ice cream
maybe i'll try this
Should I keep going with pentesting labs and keep practicing while preparing for devsecops, or should I take a break from it and dedicate to devsecops and THEN dedicate to pentest?
the fuck
What do you guys recommend
thats so cursed
Bro again !?!?
aahaha
Get a creami



and you wont ever again
those roles are completely unrelated, one is dev one is puzzles
nah focus 1 area fr
Pentesting nowdays dedicate a lot in cloud and it is a good launchpad
plus coding with pentesting?
Pentesting cloud lol
lethal
Cloud is mostly patched, the only exposure is keys
@molten bobcat
I heard companies use cloud a lot and it's crucial in modern cybersec
thats what I heard π
everytime i see you makes me wanna start doing bounties
There is actually a huge push to go back on prem
I dont even care about the money
but it's doing me good atm
Cloud is silly expensive
yeah thats why im doing so many labs now its just fun, i might try them out once i climb a bit more
How much to you make on it?
I dont think they will regardless..
Is it easy or do you have to do hard work?
Then why do they force all the employees back to their office buildings?
I mean it's hit or miss a lot of the times
knowing where and how to look
I never knew they did that.. 
Anyway enough for today I'm peacing out
Cya dudes
I boought a new car, paid off debt and got money for a nice downpayment on a home
after taxes
probably this friday again
The reason I don't like doing it is writing reports. Like here the PoC take it or leave it I'm not going to babysit you ,π
Damnnm
Imagine someone pays you to do a pentest and then they ask:
Did you find something?
Yes
What did you find?
Who tf knows I'm not babysitting here I used python
Are the things you test mostly secure or do they have pretty easy vulnerabilities on average
What did you find?
2 criticals
Cool. Take those out of the report.
average real world pentest
"We do not accept them"
Rubberstamping is tough work
I try to hit stuff that's popular
like Hyper-V, RDP, PHP, etc
straight on sale on the dark web
Hyper V hypervisor?
That's probably hardened aaf
Ye a hyper-v escape
Domain was a honeypot, domain seized, jailed for 40 years, 0-day stolen, used to bomb middle eastern kids, life ruined, blood on hands, gg no re
What am I even reading
Real life
And I thought toxic positivity was bad
I just make sucker bash aliases I am safe
Unless you have nested brokers, you are a loose end when a 0day is sold
I don't even know what a nested broker is π₯
@sharp shuttle what do you think about people like Chris Rock (the mercenary)
It means many middle men
Sounds nasty
I have no idea what you are talking about
I got a RCE in the boot rom of the MediaTek MT6739 chipset, after working on it for days, just so I can unlock it's carrier lock but since it cannot be patched it's not considered as a CVE
You found a 0day?
Idk
oh he is big on radio now, maybe you know his research, let me link
ths is the last talk he did in defcon:
https://www.youtube.com/watch?v=ICjSXak50uo&feature=youtu.be
Governments and the private sector around the world spend billions of dollars on Electronic Counter Measures (ECMs) which include jamming technologies. These jammers are used by police departments to disrupt criminal communication operations as well as in prisons to disrupt prisoners using smuggled in cell phones. The military use jammers to dis...

full day of
Idk if it's 0day bc mediatek CPUs are notorious for having hardware exploits
He got famous when he did the one about creating and killing people

Didnt know of him but will watch his talk

oh wow, you remind me to him when i read you talk
Congrats, now do 600 more and you're good
Damn right
whoami exists for easy skid identification
if you alias whoami/who you can catch skids in seconds
Whoami exists for scripting 
π₯
skridpting
What do you use instead?
He yells to the computer directly
"Who the fuck you think you are"
You can also echo $USER
thats still obvious
That's not very handy for scripting tho
Hey everyone donβt get on much to chat I really should
So Iv been on htb for a little bit now just on a year or so and Iv been plucking away in the academy itβs great and all that but I feel like Iβm not learning because Iβm not putting anything in to actual practice Iβm not doing boxes just the training
Iβm currently doing a level 2 in intro to cyber security in college (not at all practical all the legal stuff)
But Iβm going to start an boxes and was wondering if thereβs anyone out there a few days a week just working on them so we could practically learn? Instead of just checking boxes and never using it the knowledge
Sorry for the long ass message
Just watch ippsec videos broski
you can go through them with him
are they walkthroughs?
yes
I feel like if youre already concerned about them detecting your terminal activities youre already doing it wrong and shouldnt be using a terminal for that op
but i feel like watching walkthroughs won't help me learn, or is that the wrong mentality
No its moreso when a user gets on, they run who/whoami, its an easy alias to kill the session and lock the computer
or just log it
honeypot 101
Aliasing it to rm -rf no perverser root
sure, but im saying if youre the attacker and worried that it could be a honeypot tracking whoami, you should be employing different tactics entirely rather than trying to evade it with something like stat blah blah
alias whoami to "your mom"
Everytime I run who I can see the face of Eminem asking "wH0o?
I gotcha, im just making a suggestion
alias whoami='echo'
itd make for a hilarious htb box gotcha
make sure you snag id too
yeah i would just only allow one form of user id to work
It would be hilarious to alias id to some ass function that finds the process of the rev shell and kills it
alias id='vim' gg
yes thats how i usually write it
Easy but how to smugle it to bypass the htb submission review
Is this server migrating because of Discord age verification coming?
Maybe with some function that checks time like 1 month ahead to activate
submissions are just automated scripts
No, this server will be unaffected
Bre
I will affect it
If you have a honeypot can you make money by snitching on hackers?
no
Then why have one
This is actually a global implementation for age verification
you put them in your corporate infra near beachhead machines
nothings stopping you from setting up a honeypot right now. Its mostly just for research purposes. Youll never catch someone interesting unless you work for an interesting place that allows you to set one up
nobody is blasting a ssh 0day across the internet for your rando ssh honeypot to catch
Every day, more and more things tell me that being ethical is not the way forward
The Equation Group isnt guessing root/root just to see whats on your box either
Yeah..
Its hard.
Nah, being a criminal is work
Just so you know those research jobs are just selling 0days
its a harder job than a legitimate 40hr work week
Like do pen testing on public bug bounties, when you find 0days, sell them on the dark web no writing reports, nothing, just easy money
Easy money lol
a week of blackhat hacking for $$ is backed up by months/years worth of money laundering to actually enjoy your gains
Whats your life worth?
Like 100
The only hat you should be is gray
c1oud aint even a mod
Also I literally live in a cave in tnr middle of the woods ain't nobody catching me
Starlink lidar scans you jerkin it in your cave whenever the azimuth aligns
Im just saying anyone who thinks blackhat is easy money has either not put the effort into actually reasoning out the logisitics and amount of work involved, or theyre begging to get caught immediately
Starts jerking with a aluminum hat
Now we are talking
But how will you have an authorized xAI approved neuralink climax if your brain is protected from starlink?
Jerk it in a maylar blanket. Candy29: 1 Elon : 0
you spoke too soon
Lmao
Elon: 1
How did this chat come to this
i woke up
It's like 4 am
I am asian yes
I will dig a hole to you
haha fool. youve narrowed down your hemisphere
That's the minimum I'll ever go
whats your address if thats the case
do we have to use parrot for the cpts?
no
ty
Also I live on a remote uninhabited Island in the middle of the specific ocean
i used macOS
parrot 7.1 is so fucking slow bro
every vm i try it in it shits itself, no matter the specs i give the vm
genuinely ragebaiting me
i even swapped my hypervisor from virtualbox to vmware to see if that was the issue
changed my processor affinity to ensure it was using my p cores
no
its just shit
ragebait.
I gave it all of my performance cores
And gave it gpu acceleration
oh you finally did it at some point? what did you think of it?
Hard as shit
Just use khali
took two attempts
same. I think I could have done it in one attempt had I taken the full week off from work
I wonder how hard itd be for me now, but no way to find out
do u have cpts?
Even that's too bloated. Real hackers use a lightweight debian base and install tools manually
In any case there is no doubt its better than OSCP
yup
shame its the gatekept cert
Not yet, im debating on doing it before I finish my bach
why do you offer coaching for it
Its not you just put your CPTS (OSCP equivalent) on resume
yall not real hackers
real hackers still use kali so that way if their VM is sigged the metadata just looks like everyone else using kali as well
hr filters for it
here anyway
Real hackers are in the wires
custom setup means custom metadata signature
no they dont bro
HR doesnt even read your resume anymore
Its all AI bots
they look for the keyword, OSCP
Because Ive completed the course and have, generally, provided good guidance and help for modules.
thats it
Marcie, just FYI, I am in your walls
thats my point
why dont you take the exam
and its true
Im not worried, im in other peoples walls
this line
ah alr
Time commitment. Im prioritizing my time:
- job hunt
- degree
- other stuff
HTB CPTS (CompTIA A+ equivalent)
It would work lol
its only a 10 day exam. did you fail?
cpts is like a 10 day exam. it can be extremely difficult to get the time off for it if youre paycheck to paycheck
it's only a 10 day exam?
I failed my first CPTS, make sure you dedicate the full 10 days
Its not that long if you have responsibilities
It's a 10 day exam yes, but I'd rather not be stressing about other stuff while also taking the exam. Been there, done that, wasnt fun
did you fail?
I was in a state of heavy burnout for a while




