#general
1 messages Β· Page 474 of 1
Where

With who
invite me
DO NOT REPORT ME PLS
You're stuck here
They don't have time to hate you either
Dude 
I stayed 2 extra days to do cube talks I knew falcon was going to cancel it last minute-
AI is gonna take over our jobs
They are doing secret cube talk
Everyone is invited except you
Imagine π
They don't want to answer the same thing again
Maybe go to Spotify and find old ones
They aint the same ones tho 
Never asked those
It's literally same in every cubetalk first 30m
Some heavy back like a car?? π
Ask no questions and I'll tell you no lies
Wait it's actually correct

You need to go pick up the car
So walk makes sense
The original version was
I want to take my car to wash, it's 100 yards away, do i drive or walk
I modified it
How will u bring 2 cars (or 1 car , 1 whatever)
exactly lol
sad
Clankers gonna hit you on back when they take over for this trolling
Skynet is looking for you vro π₯

You won't be able to do anything else than being glued to this chat
I may leave tomorrow then vro π₯
Aright well be discussing advanced exploitation techniques as soon as you leave
π
urmom
Can I join
<script>alert()</script>
helloworld("print")
helloworld π΄
HELLOOOOOOOOOOOOOOOOOO
maybe they heard me talking ... " Niantic Labs, the developer of PokΓ©mon GO, removed a PokΓ©Stop located on Jeffrey Epsteinβs island, Little Saint James, in the Caribbean Sea, which had been part of the game for 5 years."
You already joined this server
i feel like i am not making progress
I see
Break time then
I had that random motivation for new machine, worked in it for few days for hours and lost motivation π
Back to resting for few months
we burnout everyday
so we can start another day
yes
Hm?
.
Yeah making new machine for htb
i love the matrixwizards memes
But i wasn't satisfied with some part so I'm taking a break for some good shit
if i study using hackthebox will my methodology grow or is that still dependent on how much research i do on the side?
Both
hey so I started learning pen testing like 3 days ago i dont know how to learn so im just doing the starter point machines. I just completed every machine up to crocodile (excluding the vip ones) am i learning the right way?
i do do that
Ironic!
why dont you get a pixel and use graphene ?
what's stopping you
Echonic
should I get a new better username ?
I have better things to do
security matters
I am happy with my current setup
yk fuck this shit imma level up
I am tied of not being able to post good memes so I will grind
Yeah, advice afterwards
you have two phones?
sry ur right
What's your os btw
Yea, one phone i use for talking to my friends, school and all the other personal stuff, and then i have my pixel phone which is for private use
Im curious
What is private stuff?
thats the hackers way to do it as suggested by my friend chatgpt
Just anything i'd like to separate
research, fbi and epstien files yet to be revealed, trump files, steam acc passwords, feet pics
Aright
I use my chinese controlled phone to Google hacking stuff
They should know about me and hire me
its too bad bro
i dont know why these things keep popping up in a fricking cybersecurity discord server
We all start somewhere
its oxygen os with ads on
It's obligatory weekend Convo
Your os comes with ads? 
almost every chinese os
bro ad id its google integrated unfortunately, if I toggle with it the camera goes broke, its ai camera shit
my apps stop working if I kill the os
I was asking about the computer tho
what things
ohh windows, plus I will get my own computer when I go to college
i value my time.
I see
I will make two seperate drives, one for research and other work
π¦Ύ
thnx gl good night sweetie boy π
new CTF
LOL
Which one
That's one way to put it lol
Dude don't get me started π
TryHeartMe or smth
Don't
π
Na bro Im gonna do it π
you gonna get it trouble again
Again? 
yes
Again
When did I ever get in trouble?
not trouble
but be warned by mod
When was I warned by mods? ππ
Dude u schizo?
we were told not to talk about other servers
kinda is lol
its kinda like


"you do it again, me punish you hehe"
They never said that π
They just asked for respect
who wants some punishment?
@mods make them fear you
anyway
I'm done with my challenge
after 2 days LOL
Which one
3 technically, but anyway
Nicee
coding challenge
lmc
Meh
I'll probably look at some ippsec later
insane one
the Cap one
-# you talking to me, or
yes
Nothing?
#1: its much easier to create HTB challenges than I thought
oh you made one
yes
π
pack it up dude
ye
cool. i wanna play when it comes out
I don't wanna play challs
Do machine
Wait btw @devout sail how tf did u make a box?
he's good
so he created box
simple
LOL
Get lot of logical gate chips
and if it gets accepted, you get some amount of money
And assemble them
and gets released to HTB
I'm tired
i'm on the hunt for challenge creators for phrack but it has to be from a text fiile and no vm.
and .. hard for the audience.
phrack? lemme google that rq
lol
some technical journal?
I mean
the only challenge I can make as of right now based on my skills is...... sadly coding
cuz....... thats what I'm good at lol
competitive programming
na bro don't fret
same
lol
thats cheating
booooooooooo
What if she's my waif
still
yeah some technical journal
gotcha
I once asked my colleague for some input while solving machine
He said idk
lol
here's the thing
Damnnnnnnnnnnn
the difference is
Actually?
Mine was quick 2mo
do you have leverage
Na bro that's too much
2mo is not that much lol
1 year bro? 
if u make a challenge u can get a silver one of these coins
Difficulty
1 year is, but they got a lot of submissions lol
in HTB? or Phrack lol
oh
Phrack
duh
me dumb
Let's do cubetalk now
yes
If it's insane it will take time
Low release frequency
Ghost ping
that ghost ping
I'm tired
That's worse than ping
when I wrote it out
Where your plan now then
Laze around?
man
I have work today
FalconSpy, my dearest apologies for ghost pinging you
So I'll just finish my shift
U get mail with submission queue
So u can assume how much it will take
check spam, or maybe you didn't submit properly
Oh wait some time more ig
or that
Can't do anything else π
Still waiting
I'm nervous if they'll even understand it lol
oof
They busy for valentines
if this happens, what happens lol
do they just reject, or do they request.... more explanation lol
And take credits
Should have read T&C properly
Actual
He has to sign contract ig
Cuz name should match
Submitted?
nyo
I proofread π
Hmm
you dare trick me
smh
me know the rules
I actually read all the documents slowly and carefully
Fun fact: Experts have observed rare occurrences of penguins waddling away from their colonies never to return. They theorize the behavior could stem from navigational disorientation, a neurological disorder, or extreme stress. π»πΆπ§
At least you know how to lie on your resume to score a job
wat
but I actuallyr ead it
Suuuure, me too 
Why dont you?
shush
me not lie
me tell truth
Work
Had any good ones lately?
Not really
None that come to mind at least
@upbeat tangle nice rank upgrade!
bro thm ctfs for beginners are crazy π
dev left a comment saying theres a lfi on a endpoint π€£
"But why?"
i went on there to see their latest ctf
Goblin has asked us to stop shitting on THM
π€£
its not the competetive one so i didnt expect much but dam
passwords in robots.txt lmaoo
You are smart yes
shit mb, ill keep that in mind
cant sleep for some reason so decided to fuck around
hows everyone's day going
Good about to get another shot of antibiotics for an infection that is getting much better
Hby HappyMan
tryna sleep so my day technically hasnt started
@ htb staff, are we getting hackthelove this year? I need a girldfriend.
HackTheLove?
Thatβs a thing?
@compact wave will you be my valentine?
Its the best
Hey @maiden anvil got any grapes? π¦
Lol i havent use the LLMs in github a single ever in my entire life xD
You go to work, to buy a car, to drive to work, to pay for the car.
The irony of society
I might get a car with 300 months EMI
And everytime you score a salary increase its only an illusion of increased rewards for your efforts, because alonside those salary increases comes price increases on rent, food, energy. So at the end of the day, the only ones getting your salary increases are those who already have alot of money.
π
no and I need to get dialed in. hbu?
Lock in big boy
I found myself watching a professor messser livestream 
Lez goooo π₯π₯π«‘
kypanz sir
every day is hacking day
Target(s) are spawning...

time to do some brute force login attacks
for educational propouses

Does NLTE have a youtube channel?
who wants to see smth funny
π
I'm scared
Iβve always thought women are better at hacking menβs brains than the other way around
thats good too
π
hi guys.. got a little embarassing problem. I did not end my subscription for labs but really also dont have money xD
I agree with you on that
I disagree with the βonlyβ
They are also better at other thibgs
No they are much better at cyber stalking and SE
Bruh
Hi Cloud
is there a support mail where i can ask somebody what i can do?
Need to speak to a person? Learn how to reach our support via HTB Labs.
soup
you have still two kidneys 
i mean you can always buy it back later
the only retired one i see is Faculty;
https://ippsec.rocks/?# I searched 'Process Inject'
Search utility for IppSec's YouTube videos
@obtuse fern

Hood
urmom
Bro is obsessed with mom
I'm also obsessed with your mom 
oh
am flattered
Gesh
someone has been blocked 
yoo
got a question
whats the basic checks a server might do for md5 collision check
let them run around in a box
for example whats the common ways it detects a repeat rather than a different file when both file's md5 sums are identical
ive never seen someone bother to check for a md5 collision
same
the answer is they dont use md5 if theyre worried
they use an algo thats more resistant
its on a ctf π
oh....interesting.
so like you have an md5 collision but its checking anyways?
Someone should be put in a rocket and sent into the center of the sun
if their sums match and their content matches it jsut says repeated
but if the content is different and the md5sums match the css triggers and the flag is shown lmao
So whats the actual goal here? They could literally be doing a byte match check for the contents
ohhhh
Mad, can I rant for a second.
ye i know and i looked into that, but that wouldnt be the case
they just want to see if you CAN do a md5 collision
I think you're one of the only smart folks who will understand my anger
so just like do one
Only uppercase
do it
that sounds pretty hard trying to produce an md5 collision; my guess is you would edit the thing that does the collision check
A customer is currently angry with me because their SSL VPN is talking to their domain controller for authentication
I-
isn't that what it's supposed to do?
A file based md5 collision where you add random data aint that hard
YOU DENSE FUCK YEAH THATS HOW THAT FUCKING WORKS
"Technical Administrator" my fucking ass
lmao
i dont have access or can edit the server files bruh
I'm so tired of people who don't have any idea what they're doing earning stupid titles
"the firewall isn't rejecting them, the server is, how are they making it past the firewall"
theres some standard tools for generating md5 collisions
i already tried most of them
"Dense fuck" extended my life expectancy for 5 minutes
Thanks
tried that too
Thank you tho
youll be surprised on what i didnt try
and you verified you had a successful md5 collision?
no thats the whole point if i wouldve had one i wouldve seen the flag
but i didnt
me too 

We need to pin this
Some mod please
hello
YAY! I can play Dead Island on Linux!
He faked it, until he made it
The problem is that he's not making it
This firewall is correctly configured to the gills and I am willing to bet money he's not the one who did it lmao
...thats what the vpn is for
If you can impersonate an accepted connection
ye this md5 collision seriously needs some thought, nothing normal is working
dont punch me im just trolling 
3rd CVE confirmed
can one of yall actually take a look at this md5
and lmk
bruh it aint just me
the whole leaderboard is lost
you smell like garbage
wtf ?
bruh youre missing context, might wanna scroll up
@molten bobcat you lack patience
Yah?
You're talking to a blue teamer
cant say Im better
He is better
https://hackerone.com/reports/3183046
howβs an keyed cache is a vulnerable?
Cache pollution
Eviction of legitimate cached entries (such as popular pages)
Increased load on origin servers (reduced cache hit rate)
Potential denial of service (DoS-like scenario) at the cache level
This becomes a serious resource exhaustion issue on public-facing endpoints.
you know what else is Cache polution?
Hush
a well known Cache Polution is Call of Duty Black Ops 7
A keyed param cause cache pollution?
you cause Cache Polution
Unkeyed, not keyed
So thatβs cache pollution
No need for reflected params?
Read the lab carefully
You still reflect
It's just that the method by which you reflect needs to be checked by examining cache responses
It's specifically Step 5 of the solution here
But the write up didnβt reflect anything
Iβm talking abt the HackerOne writeup
I guess they couldn't get it to reflect
5- Observe that this too gets cached independently.
Supporting Material/References:
/en/contact-sales?test=123
/en/contact-sales?abc=456
/en/contact-sales?polluted_param=
Each receives a separate CF-Cache-Status: HIT and a new Age.
Howβs that a vulnerability
Itβs not similar to ps lab
@molten bobcat I have some things to say
you may be the most boring person I know but you are pretty cool and smart
sorry @supple plume I dont say lies
is that renoir pfp? goated
i am not french. i enjoy the game
Bro you need another brain 
I am soo smart I need at least another brain
to be able to hold all of my knowledge
@supple plume you sure love nuts
the real question is. which ending did you choose
I'm not put on this Earth to entertain you
Verso
yess.
who said that you have to entertain me?
Life keeps forcing cruel choices
like taxes
You did, by telling me that I'm boring
My rebuttal is that it's not my job to entertain you
nah it only means you are boring
I don't think you're capable of thinking more than a single move ahead
boring to 1 may be interesting to another
its like saying somebody`s trash is someones treasure
but Cloud aint trash
so I dunno
next weeks episode is gonna be so good
When old people start tapping the button, its time to put them down
(thats them gambling away your money)
alemamu ali belasad
is that a soraka spell from league of lengends
im looking forward to his fight
Ah yes the fight
ambushed by villian
dialogue
counter attack
big blow
memory from past
activate hidden shonen power
woop villians ass
Power level increased
next iteration new character
JJK is just naruto season 1 but with beautiful art
Do man in the middle attacks work on big enterprises and corporate firms
Yep
Most enterprises and corps do not have on-site SOCs
It's - a - me
Just about everybody but fortune 500 uses MSSP's or software exclusively for detection / response
well if it is the fight im thinking of next week. that is surprisingly wrong π but yea thats 99% of them
But have insane amount of users.
Do the attackers really go through each and every communication between the users and the business
Bro JJK up to this point has followed naruto season 1 progression to a T
there aint no surprises
No, its all about path of least resistance
just wait for it. talk no justu will be brought in next
talk no jutsu was a shippuden thing
havent watched much of shippuden. i think ive seen 15 eps or so
The main villian in JJK is basically orichimaru
That's why phishing works best
So they find a point that's easy to intercept and boom. We have a man in the middle. Is that it
There's technically two
Are you talking about radio waves?
they let you in voluntarily
except orichimaru didnt give birth to naruto π only difference
he kinda did
No the hell he did not lmao
How u comparing Sukuna to Orochimaru
kenjaku
Body hopping into a younger, more suitable vessel?
He literally does this twice lmao
seems so π
Nope. I want to understand the concepts of this attack. Cuz what I read was an attacker sits between the conversation of an end user and a website and intercepts the traffic
orichimaru is the de facto villian in naruto, and hopefully boruto. i want to see him win
Its called a tap
Thats all you need to know
That's the main villian π€¨
is he in boruto too? lol that dude just doesnt end
Fair enough
well if you think about it. without kenjaku none of what is happening would happen with out them
I disagree
I believe that
Kenjaku's plan
Was to include Sukuna, the King of Curses, into his plan (as he is often described as a force of nature, not a person)
By edging things along to where Sukuna could have a suitable vessel and cause as many problems as possible for his ultimate obstacle, Satoru
kenjaku made the vessel tho?
Correct
You guys need to realize JJK will have a sequel so keep that in mind..
with sukunas brother
But he didn't seal away Sukuna when he died
yea i seen a bit of it
Wait its out? i was just speculating
Bro's on to something π€
That was jujutsu society that did this
Techno tonight with a dope dancefloor
He included sukunas resurrection on purpose
Because he thought Sukuna would enjoy fighting gojo
Da na
Have fun azo
Appears he was correct.
Also helps his plan that
Sukuna resurrected directly in front of gojo
And was immediately slammed by him
but we know his plan
Ey fellas
Yep, the culling games
yea
whats up xXquiKsc0perXx
But what's in the way of tengen?
bros got those aryan eyes TM
Is that jjk
Yep
No thats kakashi
he also needed sukuna for his CE, to make all people gain even more through when tengen evolves
you guys ganna feel real stupid when the principle returns and is the main villian
ppfft
I always figured it was just a "bonus" that he had a stupid amount of CE
I have terrible news.
Lmaooo
nah. he became cursed objects 1000 years ago which maintained his CE.
Even pandas cry.
DOMAIN EXPANSION: BELLY BUTTON ABYSS

but i must say the funnies thing in jjk is. since twins are considered the same person in sorcerer society. kenjaku had to get pegged by sukuna
relatable
The fact that he had to do any of that in the first place was wild enough
"I'm your mom"
Yeah that's
hey you gotta do what you gotta do to make the best vessel
hang on we got femdom in JJK now?
yea didnt you know
no idea man
Nanami π₯π₯
π its really bizzare
sorry man youll have to read if you wanna know these details atm
No wonder I'm getting confused 
i did not enjoy last season of GoT. i dropped it on last 3 eps
yea man π things get interesting
Not to revive the dead horse but GoT was really really good until season 5
so i just dont care to remember anything past
It got SJW'd once the source material ended
U enjoy spoilers?
Wow
i enjoy deep dives into topics i find interesting
and jjk is one of them
and is it really a spoiler if i read the manga?
Oh so a professional way of saying spoilers π
I've researched a bit
So u don't read manga
π
Turns out If I put my ass in the chair and lock in, I might become like @supple plume
He reads anime
π€¨
(moving manga)
Made some cinnamon roll ice cream
sounds peak. share
Yooo
i dont need it... i dont need it... im already to large
Wait.. Coffee and Ice Cream Maker? ON ONE SINGLE MACHINE
actually it helps lose weight
Okay, I'm sold. Give me that
you can make super good healthy ice cream
nah just ice cream
Well as long as you took the milk from goat that has been taken care in Turkiye
@exotic pendant you're pumping it with protein right?
all I put in mine was almond milk, monk fruit, xanthan gum and protein powder
MaraΕ Ice Cream hehe
I knew it
This is like cheating on dieting
why the gum though?
only issue is the 24hr time in the freezer no?
thats ideal
sometimes we do 2 at a time
shoot you can do 7
if you want since its frozen
Frosto only got his cheap because he's sponsored and getting people to buy them on here
kidding
enter code FROSTO20 for 20% off
Thought you had a break from dieting etc
Protein: ~246g
Carbs: ~247g
Fat: ~61g
Calories: ~2,540 kcal
Damn thats a LOT of protein
Im going 2300-400 with ~130-160g of prots, need to cut bc excesive fat is killing my climbing skillz
how much do you weigh
I might be getting sick
Kids teacher goddaughter had a "fever" but she said she wasnt sick
Bruh
TF does she think a fever happens for 
Yeah hopefully not covid and then i get back heart issues
It sure isn't when you're healthy 
@molten bobcat I also have 1 more thing to tell you
I'm sure it'll be grand
hmm good luck
Which is probably gonna be portswigger labs stuff so I can do frost stuff
Saving up for the ice cream machine
I play magic so I'm already cooked
I was 87 few months back
And it felt great, but yea... need to be lighter
Had i done legs weight wouldve prolly capped at 90ish
i know there's somebaaaaaaaaaaaaaaaaaaadeeeeeeeeeeeeeeeeeeeeeeeeeeeeee who loves
and that's all i aaaaa ia aa aaaaaa neeeeehhd yeaaaaaaa h
I LOVE MY my parents
If only my chest genetics werent awful
Have terrible middle insertions
But tbf it doesnt bother me as long as i have healthy tendons Nd good grip 
Bad and illegal
k
why tho, if someone did something bad to u, shouldn't it be self defense?
also
yall use virtualbox?
No
k
self defense can only be in the immediate when escape is not an option.
hacking takes time and effort to accomplish, any scenario where hacking could be used against someone thats harmed you has passed the point where self-defense qualifies.
idk i had this in mind alot, and i js wanted to ask
-# im not gonna do it, i js wanted to get an idea from actual experienced hackers
ok
I think there can be morally justified scenarios, but it still wouldnt be self defense
Depends on the state for the first one
yeah some places have stand your ground, but generally what I said is true
esp when were trying to define what self defense would mean in hacking terms(which we cant)
Happy birthday Emma.
This for you
https://www.sbnation.com/a/17776-football

Huh
Stand your ground / castle doc is spook
Gonna be moving to a state with it lmao
Open ze link π₯Ίππ
honestly Im for it. I hate the idea that someone breaks into your home and youre supposed to guess whether or not theyre there to rob or kill you
I mean, insurance
huh
And if you have the option to just leave
Not taking it is kinda ehhh
Especially outside of your home
thatβs why I shoot first ask questions later
And as I understand, in some states itβs just trespassing alone, not breaking in
insurance doesnt help me if me or my family are dead. No amount of money replaces that
My point was more stuff gets taken
Cause yeah if your life is at risk thatβs a different ball game
Requires being an FFL
Yeah, like I said I dont like the idea of having to guess
donβt care make ur own
ATF scary
I cant read minds, I dont know if the person bashing down my door just wants my tv or not
most ppl robbing houses arenβt there to kill you
they need money
or something
Anthropic announced a new AI that is insanely good at finding and fixing security flaws and vulnerabilities with βvery little promptingβ
theyβll probably shoot u or act rationally if you like lunge at them
People who have tested the tool say βit is very goodβ
ppl gonna stop learning how to do stuff
We're so cooked
very
the last jobs that are gonna be fully replaced are probably going to be service jobs like real estate agents, tech support, etc
not a day goes by I donβt see someone using ai to do the easiest task of all time
hm
tech support?
and research shows that using ai to replace learning hinders your ability to learn the subject. Even if you stop using the ai for the task
Why not? Everyone uses it and skills don't matter anymore. Might as well get it to do everything for you
ai tech support SUCKS dude π
Ai would have a meltdown at Kathrine from accounting doubling down on the fact that its her monitor thatβs locked, not her pc
βah ok ms. kathrine. I see that it is your monitor that is locked. Try turning it off and back onβ
repeats that 3 times
Itβs pretty good but to review a large codebase you will burn through your tokens, but itβs definitely capable of scoring bounties for you
More news about anthropic. The head of AI at anthropic just resigned and said βthe world is in perilβ
π
Anthropicβs head of AI said he wanted to βmove back to the UK and βbecome invisibleβ while practicing poetry and becoming an authorβ
Good for him
He said the world is in peril because society is essentially crumbling with the streamline of dopamine and excessive reliance on ai
thatβs a summary of why
You wonβt be replaced by AI soon, but you will be replaced by the IT/cyber professionals who adopt AI as a tool in their arsenal
chat are we cooked
Based
Reject computer, start farm
reject modernity return to monkey
thatβs always the end goal isnt it
its what alot of old people do
If I had a choice, there are 2 options for how I would die
Iβd either vanquish like master oogway while talking to my grandson or something with a cornball line like βmy time has comeβ after living a long fulfilling life
or Iβd perish while doing something redbull would want to sponsor
Instructions unclear: took a homemade submersible down to the titanic
the only nutrients I have consumed today besides water has been a quart of chocolate milk
for all my metric folks. 4 quarts makes a gallon and a gallon is about 3.7 liters
Was about 1,000 calories
Iβm ready to conquer agartha
Imagine not even doing GOMAD
Unfortunately I do not wish to marry or make love to my bathroom
wait till they run outta tokens, duh!
Shit be banging
so you let it crust?
bro @rancid snow the code was broken, thats the reason my shit wasnt working π , they fixed it later and it worked flawlessly first try, cause i was surprised too that it shouldnt be this complex
appreciate the help tho
interesting
Not sure how it was their code broken when you werent even able to make a hash collision at all
so it was kinda like a duplication check
i did make it
wym
Earlier when I asked you said no
oh i get it now i thougth you were referring to the whole hash collision attack, not the payload
Yeah like just a hash collision at all you could verify yourself, not the challenge lol
oh ye that was easyu bruh
lmao
oh lmaoo
but yeah, broken challenge makes sense then
i thought you meant the whole chain where i make the payload and upload it
all good, glad it got resolved
bro thm honestly for beginners is just ass
they got python scripts being executed in profile pic upload
like zero sense
and pure ctf shit
It still exists in htb, and is still realistic
i know but not in a freakin profile pic
Though usually its .php not .py scripts
You dont execute it, you load it and it executes a payload
they literally had a exec() inside a Flask request handler
ye ye but you get my point
usually I see something more like a system command for image conversion and you can do something like command injection in the file name.
Or like marcie said.
But yeah just straight up executing a pfp is wild
I mean sometimes you wanna snag the image
thats some "developer was creating a malicious backdoor for their client on purpose" shit
just unrealistic thats my point








