#general

1 messages Β· Page 475 of 1

jolly snow
#

fr

#

even the llm started laughing

obtuse fern
#

It is realistic, misconfigurations are the leading causes of breaches

jolly snow
#

it goes

rancid snow
#

Marcie I think youre misunderstanding

obtuse fern
#

Perhaps

jolly snow
#

ye marcie

#

im not hating

#

im just saying theres a limit to where you can teach the ways

obtuse fern
#

Exec() in a profile picture is brain dead

jolly snow
#

theyre beginners and if they teach them this shit then imagine what would happen

#

later on

#

lmaooo

obtuse fern
#

Im just referring to file upload exploitation in general being realistic

rancid snow
#

not saying a misconfiguration or anything. Hes saying literally the code is

system('python3 account_pfp.py')
jolly snow
#

they trying to upload python shells on a static site

#

lmaooo

jolly snow
#

or not even that a literal image my man

obtuse fern
rancid snow
#

usually theres a step 2 at least

jolly snow
#

and funny thing was they were not even python pfp, literal images

#

jpegs lmaoo

rancid snow
#

idk if thats as bad an an endpoint that is literally just executeSQL?sql=

#

which Ive seen in a real application

jolly snow
#

nah the executesql one is wild, they go, ayyo you want a mssql shell, i gotchu

rancid snow
#

wasnt mssql but yeah

jolly snow
#

in theory

#

not literally

thick forge
rancid snow
#

it was pretty funny though. Still unfixed:/

jolly snow
#

dam

#

devs are pretty interesting these days

rancid snow
#

I did some research and the devs were literally some college graduates that made the app before they got any actual software dev jobs and got lucky enough that it makes enough money they havnt needed to

#

same place that has a capt cha that is purely client side

#

as in no parameters ever gets requested to any server. its entirely self contained javascript

jolly snow
#

wow

rancid snow
#

the only captcha Ive seen that is mathematically proven to waste peoples time without a single once of bot protection

jolly snow
#

very interesting

rancid snow
jolly snow
#

oh you talking about captca , when u said capt cha i didnt get it so i thought you were talking about something else

rancid snow
#

I have a tamper monkey script that just clobbers it so I dont have to do it at all

jolly snow
#

i read a article the other day about captchas, most of the time they just check your time to complete or your mouse movement to prove youre human lmaooo

#

they got no real way to verify you actually doing shit right, the good ones prob do

rancid snow
#

yeah captchas are generally pretty bypassable. I was just stunned by this one doing utterly nothing

#

theres a number of other issues Ive found too

jolly snow
#

fuckin 7 times

rancid snow
#

lots of 'only an admin can do this function -> inspect element delete disabled tag hit submit -> action successful!'

jolly snow
#

the worst one for me was when i was a kid and that stupid ass rob*** captcha

#

dam server banning robl**

#

lmaoo

rancid snow
#

thousands of users 😭

jolly snow
#

ye its pretty wild what we can do with just js

#

and what it can also do to fingerprint a lot of browsers to later identify

#

i dont know much about forensics but read stuff about it

rancid snow
#

I think theres also some deserialization->rce in said app but the context seemed risky to test for so I never bothered.

jolly snow
#

wait u talking about the react one

rancid snow
#

no

#

the db stores some php serialized objects. Normally you cant just add an object directly but refer to the executesql endpoint above.

Test and prod share the same env though so if I fucked up the payload itd bring down prod and I didnt want to risk that

jolly snow
#

ohhh

#

i seee what u mean

#

ye ye def, cause the wrong thing gets deserialized and executed, and next thign you know

#

the whole thing crashes

rancid snow
#

yup

#

and since the payload lives in the database....

jolly snow
#

it gets deserialized on any query ?

#

not sure if thats how it works but idk

rancid snow
#

presumably yeah, wasnt risking finding out

jolly snow
#

oh

#

i mean usually its not necessary unless the object is needed or referenced

#

but ye

rancid snow
#

yeah there was high likelihood thatd be a frequent occurrence

jolly snow
#

so youre a senior dev right ? or a soc analyst or some

rancid snow
#

nope I do data recovery

#

Im trying to transition roles though

#

id like to do more pentesting or appsec work

jolly snow
#

see what i mean when i said if beginners are taught this way what would happen πŸ˜‚

jolly snow
#

dude said iguess, bro himself doesnt know why to do that lmao

rancid snow
#

my weeks project has been testing my friends homelab setup. Unfortunately(for me, not for him) his setup is extremely solid so Ive now devolved into checking some of the more obscure applications he uses and seeing if I can find a cve for it lmao

keen elm
#

guys is the academy working for you?

#

i am getting 504

jolly snow
keen elm
lyric oasis
#

Same^^

#

Back now

#

Must've been the wind

fiery copper
#

@obtuse fern dont let the haters own you, be the happiest person you can be

#

and this can be said for anyone here

#

Also dont hurt people emotionally I think

fiery copper
#

@alpine pumice go nuts and revive the chat

mystic harbor
#

Remove the s

fiery copper
frigid mountain
#

πŸ˜€

#

I've been busy

muted olive
rancid snow
#

new

#

youll never find bugs without trying to look for em

gray terrace
#

Feed me your hate

#

It’ll replenish my tanks

quasi zephyr
#

hey how do i start, i am a free user and i just signed up

west lynxBOT
quasi zephyr
#

doing this completely free is possible?
or at some point there is a requirement to purchase

cerulean bloom
quasi zephyr
#

So is it still worth to spend time on this as a free user?

#

or should i think of at least spending in the future

cerulean bloom
#

if u are starting out, continue with what you can with free content (in academy, they use cubes as a currency, and free content would mean content that give back all the cubes u spent to get access to the content after u complete it)

cerulean bloom
#

but, if u want to unlock more advanced stuff in HTB, you will at some point need to spend money

quasi zephyr
#

But basics can be done for free right?

cerulean bloom
#

the Tier 0 ones

#

are all free

quasi zephyr
#

alright then i will first stick to basics, then explore what i am really interested in before paying.

quasi zephyr
#

to be honest i thought there would be a way to farm cubes by giving tests or something

cerulean bloom
#

if there were, HTB would be out of business lol

quasi zephyr
#

true true

#

thx for the help ;D

cerulean bloom
spare horizon
#

@sharp shuttle if u ever became a millionaire can i live in ur mansion

#

ill be that one random dude who is fun to hangout with

maiden anvil
#

24/7

#

365 days per calendar year

#

but even more insane looking

#

like this

#

at all hours of the day

#

just imagine my face like this while I'm shrieking "ROTFL!!!"

meager kernel
#

Time to hack

feral jackal
#

omggggg

#

that's really bad

#

when I open my account it tell me

#

πŸ’˜ Swipe Right on OnlyHacks
Valentine's XSS Special

#

what is only hacks???!!!

#

is it like onlyfans but for HTB?

rustic carbon
maiden anvil
#

omg CJ

#

where you been buddy?

#

all we had to do was follow the damn train

silver forge
west venture
#

Bro chess.com fuckin sucks. I was beating this guy and he was almost lost literally like -3 eval, then he stops playing for 5 minutes straight and proceeds to play the top stockfish moves 10-20 times in a row. Like if you cheat at chess you're literally an inferior human being and you absolutely suck at everything you do.

rustic carbon
supple plume
silver forge
west venture
rustic carbon
#

guys i have figured it out

west venture
silver forge
rustic carbon
#

do you guys like jobs ?

silver forge
#

I liked Steve Jobs prayge

rustic carbon
#

if i offer a job with a reasonable payment will you like it vs a job thats fun, interesting, has equal payments and fair for all according to their work, pays decent not very high and provides good life

#

bascially a job that doesnt feel likr job it feels like doing something good and worth it

rustic carbon
supple plume
#

It can be enjoyable

quasi zephyr
#

getting caught after cheating is the most embarassing

supple plume
#

Yeah cheating is trash

silver forge
supple plume
#

Retro left

west venture
supple plume
#

Appreciate your weaknesses and fix yourself

west venture
#

How do you appreciate a weakness

supple plume
west venture
#

"sorry I lost to stockfish yeah I will use that as a motivation to become better at chess than an engine"

supple plume
west venture
#

Playing absolutely ass, then pausing for 5 minutes, then playing the best moves in a row till winning is not natural

supple plume
#

Well just report it and move on

#

If they find is cheating you get the elo back

#

Why do you spend time thinking about it psy4

#

Mental energy flushed down the toilet

west venture
#

Bro I'm not as evolved as you to be all matured and shit sush

supple plume
#

That's the cutest thing I've seen today

west venture
#

Welp that's no more chess for another 3 - 4 months again

silver forge
#

perhaps you should play blitz, because it's harder to cheat (effectively) there

west venture
#

I'm too slow for that kek

west venture
#

I be making moves with zero deapth

terse dirge
supple plume
terse dirge
#

I'm so happy and proud I configured and set up a VPN server with wireguard

west venture
terse dirge
#

Network engineering is the bane of my existence

supple plume
west venture
#

Aws

terse dirge
west venture
terse dirge
#

I have it on a completely different IP range than the local network and I'm so happy I got it working

#

VPN clients are on 172.16.1.0/24 and the local network is 10.0.0.0/8 (yes the local network is flat, we love dns and think vlans are socialist propaganda)

west venture
terse dirge
west venture
#

Oh okay

muted olive
#

the earth

terse dirge
west venture
#

Yeah I set up an entire wireguard server on aws so I can get better routing while playing online games kek pika

terse dirge
muted olive
#

using vpns to play games is just making it slower kek

terse dirge
west venture
west venture
#

Free teir

#

When it expires imma make a new account and get another free teir

silver forge
#

oracle cloud has free tier that does not expire. probably has a site in the asia as well

west venture
#

I tried 4 times and lost $8

silver forge
#

oracle may be technically inept, but I seriously doubt their intent is to scam. just saying.

elder lichen
#

hi

silver forge
#

ok, today 3 prompts to claude and context is full kek ah well

terse dirge
#

I always forget that Oracle exists same with IBM.

silver forge
terse dirge
#

What do they do anyways?

#

Like Amazon is online shopping and server hosting, Netflix is streaming, apple is phones. What does IBM do?

elder lichen
silver forge
#

seriously talking, they do cyber, custom hardware/software solutions, and consult the enterprise sector

#

if you need a private could they are one of the actually potential vendors

supple plume
meager kernel
#

i think i learn better from HTB Labs than I do from Academy

silver forge
#

I think they also have superb AI accelerators and innovation centers, which you can use as a client

supple plume
silver forge
#

... and we are not even at noon, and I'm out of claude code credits pepecoffee

west venture
#

You know you can use Gemini 3 pro for free on google IA studio?

silver forge
#

what's the quota for the free like?

west venture
#

I don't think there is one

#

I haven't reached it personally

terse dirge
#

Instead of messing with ai we could be learning kubernetes and oauth for rancher

west venture
#

Who is rancher

silver forge
#

doesn't look that good of a match for developing python code that has to run in my network...

#

does look pretty nice otherwise however

terse dirge
#

It's a management ui for kubernetes

cerulean bloom
#

I HAVE DONEIT

terse dirge
#

It's like portainer but better and free

vestal trench
#

Some one did oscp recently..?

terse dirge
cerulean bloom
#

submitted my own coding challenge

west venture
#

Now why would I need kubernetes

terse dirge
#

Faster than they already are

#

Better

#

Stronger

west venture
#

I use docker. I am simple

terse dirge
#

And better?

west venture
#

πŸ™‚β€β†”οΈ

terse dirge
#

Don't you want to be able to customize it?

#

Kubernetes!

west venture
#

customization is overwhelming

terse dirge
#

Or don't add any

#

Speaking of kubernetes I need to make a home lab with kubernetes

cerulean bloom
#

@eternal mango @obtuse fern @scenic maple I submitted my coding challenge 😁

terse dirge
#

I need to buy raspberry pis!

west venture
#

Pis

idle mauve
#

gm

idle mauve
west venture
#

Speaking of raspberry pis I turned a Huawei smartphone into a DIY raspberry pis

idle mauve
#

raspbery piss

pine topaz
west venture
#

What

idle mauve
#

How did u use GPIOs

west venture
#

Installed Linux bare metal and used the flashlight connection and the power and vol buttons as direct connections, for everything else, I attached an Arduino nano and wrote a bridge so that the Arduino becomes an extension of the phone

supple plume
cerulean bloom
idle mauve
#

Have u just installed linux?

west venture
#

Not just installed Linux, It does everything a raspberry pi does

supple plume
west venture
#

Not the kernel

idle mauve
#

So it doesnt

west venture
#

I mean...

idle mauve
#

But its cool

west venture
#

Is it that big of a deal

idle mauve
#

if you have know how to do it, can you suggest me a way?

cerulean bloom
#

heh

#

good luck

#

thats all I'll say

supple plume
#

It's math spray

cerulean bloom
supple plume
west venture
#

And of course extract and get the drivers working

idle mauve
cerulean bloom
supple plume
#

I'm going to eat a donut rn, well see when I get to the challenge

cerulean bloom
west venture
#

Is it available for the Huawei y5 lite 2018 (MediaTek MT6739 SoC)

#

Because you cannot even use the stock android kernel (even though you technically should bc this phone is compatible with treble) proprietary Huawei drivers won't work

supple plume
west venture
#

So you have to unpack the boot image extract the Kernel and build a user space and get the init system working.

cerulean bloom
supple plume
raven rain
#

i finally got my letsencrypt cert to work in my cluster

#

holy ares

#

so nice to see my longhorn dashboard on https

cerulean bloom
torn cedar
oak timber
meager kernel
#

AD is hard to do without any prior knowledge on it

idle mauve
west venture
#

So can I use it for phones that aren't officially supported?

idle mauve
#

Actually there is no team that messing up with devices

#

Everyone port their own machines

#

my phone doesnt support it due to locked BLs and lack of drivers

west venture
#

Oh

west venture
#

Drives are in /system/vendor and /vendor partitions

#

Get them and insmod them manually

idle mauve
#

it's quite tricky

#

because

#

i bricked my tablet/phone

west venture
#

Ohh

idle mauve
#

I just have access into bl

west venture
#

Yeah well I have BROM access so I practically cannot brick mine.

idle mauve
#

and searching for an exploit

west venture
#

Yeah

idle mauve
#

but i need a perm access

#

still researching at my weekends

west venture
#

Cool

#

Try and find a Boot Rom exploit

idle mauve
#

tbh i think it's quite pathetic

#

I have to exploit my own device to take fully access

manic anvil
#

waz cant wait for the new machine

#

sadglas did half of the old machine but got stuck but learned new things

warm ravine
#

Hey uh, fellas. I need some help to connect the VPN server to my VM

manic anvil
warm ravine
#

I'm on the Linux section

#

I mean

#

At the system information section

manic anvil
# warm ravine I mean, I dont know how actually

oh its pretty easy
download the vpn file that suit your location and copy it to your vm
on your linux distro type this one by one
"sudo apt update"
"sudo apt install openvpn"
"sudo openvpn /here type the path to your vpn file you downloaded"
on the top right your IP should change

warm ravine
#

Like

#

Am I gonna write commands like cd/Downloads or smth?

manic anvil
warm ravine
#

Downloads?

manic anvil
warm ravine
manic anvil
#

sure

supple plume
#

@warm ravine I'm glad you didn't give up yet. You may become a hacker at some point

warm ravine
#

If I have something that I really wanna do

#

I wont leave from it

supple plume
#

We'll see in a couple of years

sturdy thistle
#

Hey

turbid bloom
#

Can anyone give me tips on how to reverse engineer a rust file?

sturdy thistle
#

Read it backwards

supple plume
manic anvil
muted olive
manic anvil
terse dirge
#

I LOVE SPENDING 2 HOURS FIXING INGRESS CONTROLLERS AND DEPLOYING A SINGLE APP!!!

#

absolute peak kubernetes experience

feral jackal
warm ravine
#

Uh... @warped plank Yo someone just send a friend request to me, the account looks really new

fiery copper
warm ravine
#

@bronze goblet thats the person who send it

warm ravine
#

Wait

#

Same person?

#

I mean

#

Did this Sally person send it to you too?

feral jackal
#

yeah

manic anvil
warm ravine
#

Ok yeah throw bricks at sally

#

Yo we got a bot in this server aye

feral jackal
manic anvil
feral jackal
#

people who DM you and ask you to hack ig?

feral jackal
manic anvil
#

the problem they choose the wrong places lol

#

a server that literally teach ethical hacking and anti scamming lol

warm ravine
feral jackal
#

btw my account is new because am new

#

into life

slim harbor
#

Hi guys, in the cybercafΓ© there's a system that tracks the games and applications on the device, as well as the user's account, time spent, and money spent. How can I run Kali Linux and Tor Browser on this without exiting this system?
BTW I pay money for cybercafΓ© not illegal
And chrome is available in this

manic anvil
feral jackal
#

i want to know why there is some challenges labeled hard but they are actually easy

manic anvil
slim harbor
manic anvil
slim harbor
manic anvil
slim harbor
manic anvil
devout sail
#

mods'

slim harbor
manic anvil
slim harbor
manic anvil
manic anvil
slim harbor
manic anvil
slim harbor
devout sail
#

@scenic maple

#

ID 931439814920765460

manic anvil
manic anvil
muted olive
devout sail
#

i cant count them

#

so no point

manic anvil
#

dude what the fuck is purple kali

devout sail
#

cooler one

manic anvil
#

i just scrolled down in the images page and found alot of things

#

what you mean offline installation

terse dirge
#

SSL sucks chat

devout sail
#

😼

west venture
#

Closest I am ever going to get to "I hacked the fbi"

supple plume
keen trench
#

Hey guys, in the profile section of HTB, I can't seem to add any certification from companies other than offsec, GIAC, and EC-Council

rustic carbon
#

happy valentines day @supple plume πŸ’‹

#

wil you be my valentine sadglas

zealous charm
devout sail
meager kernel
#

@austere sinew

ocean marsh
#

happy valentines day @subtle plover

fiery copper
#

PUSH PUSH PUSH

elder inlet
#

@austere sinew WOLOOOOOOOOOOOO

fiery copper
elder inlet
subtle plover
zealous charm
#

any hacking today?

simple monolith
#

sure new box new

cerulean bloom
elder inlet
#

@austere sinew WOOLOO

#

@austere sinew WOLO WOLO WOLO WOLO WOLO

west venture
#

Bro the new HAL AI or whatever in HackerOne is straight up asking me to download exposed .SQLite files I was trying to report so I can confirm they have sensitive info. I am pretty sure that's illegal right?

#

Don't really do this often just wanna confirm

signal mica
turbid bloom
#

I'm stuck on an OSINT level now lol.

supple plume
#

good luck

dry blade
#

do we already have physical cert for CAPE?

terse dirge
#

Lmao it's 7am. Gn chat

#

Too much kubernetes

#

I got gitea and working ldap auth with authentik going and I fixed our ingress controller

#

Too much kubernetes makes ceald a tired pod

turbid bloom
#

It has an mp3 file as an attachment πŸ’€

frigid mountain
#

good morning

exotic pendant
upbeat tangle
#

So whos ready for new machine release? POGGERS

sonic blaze
#

I need to get back into hack the box

#

I always start for a few days and give up 😀

upbeat tangle
upbeat tangle
manic anvil
#

does onion websites work the same as normal websites?

scenic maple
#

pretty much

manic anvil
#

the enumeration part tho you need to edit the tool script or most tools know how to deal with them?

scenic maple
#

you have to tone it down tho cause of bandwith

scenic maple
#

ffuf stuff?

manic anvil
scenic maple
#

well first of all you obv should be running it without permission
but even if you have it those sites arent able to take lot of bandwidth as i said
but if you want to do it anyway you can do it by proxying your request via tor

#

like install and setup tor on local and then pipe it through the proxy locally

#

but it is highly likely that the tor nodes will ban you

#

so i would advice agaisnt it

#

also it sounds very illegal now that i think about it

manic anvil
#

i see

scenic maple
#

-x is ued for proxy same for curl

manic anvil
#

thanks for letting me know

idle mauve
#

I'm getting ready for tonight's machine

#

my cancer cycle is going to release

scenic maple
#

A man who runs with aggression walks without dignity ~ Smaurai Jack

manic anvil
#

dude leaks groups are silly a group put on their site that they hacked a company and have alot of their info , just for the company to come out and show them that they hacked the wrong company that just happen to have the same name but its based in india

scenic maple
#

very cringe

manic anvil
#

funny thing they put the thing on their leak website then took it down like nothing happened

#

btw guys are rainbow tables any better than waiting for john or hashcat to try everything in rockyou file?

neat cipher
manic anvil
#

waz make sense

supple plume
#

Let me check

#

Oh method is -X seems like proxy is -x lowercase gaddayum

upbeat drift
#

Hi everyone,

I’m a bit confused about the difference between Labs and Challenges on Academy x HTB. Labs seem to be topic-based (e.g., XSS), while the OWASP 2025 Path contains Challenges. What’s the actual difference between the two? Also, for CWES preparation, should I focus more on Labs or Challenges? I know there’s a dedicated CPTS prep path β€” is there something similar for CWES?

Thanks!

frigid mountain
#

A challenge gives you a direct question or problem while a machine is more open-ended

wary wind
#

Hello, i know this question are being asked alot and repeatable but may i know the roadmap for cybersecurity where i can expand myself on later on

upbeat drift
young glen
#

I prefer machines

median karma
#

sup

young glen
#

Hi

bronze crow
#

hey guys
i kinda wanna make the transition from thm to htb but i heard that htb is not really the best option for begginers
whats yall thoughts about that?

supple plume
#

there is free tier stuff on both places

signal mica
supple plume
meager kernel
signal mica
#

@sharp shuttle can you pick me up n drive me to the bus station

#

On hood?

bronze crow
silver forge
#

played a bit more of that Infinite Arena Breakout game pepecoffee earned 5 millions

pure jasper
#

Hey fam.
I'm new Here, just joined in, I'm a beginner in computing and I really want to make it pretty well in this category.

#

Can someone be my guide please πŸ₯Ί

thick forge
#

moooveeee

#

is hacking timeeee

silver forge
#

developing stuff pepecoffee

thick forge
#

y remember me i need to vibe coding

#

to spend less time

#
kypanz activate second core to do parallel tasks
tidal musk
#

Happy valentine day

silver forge
#

or, Melissa

thick forge
#

my new vps is under attack

silver forge
#

good, attacking makes services stronger FeelsGoodMan

thick forge
#

time to activate default passwords to see what the hacker does

silver forge
#

"What is this talk of 'release'? Klingons do not make software 'releases'! Our software 'escapes', leaving a bloody trail of designers and quality assurance people in its wake!"

manic anvil
#

HTB profile is a portfolio right ?

silver forge
#

Bugs are there only to build the character of the user!

toxic sandal
#

Anyone running ParrotOS ARM in Parallels?

devout sail
thick forge
devout sail
thick forge
#

the noob revelation

devout sail
thick forge
#

πŸƒ πŸƒβ€βž‘οΈ

devout sail
thick forge
thick forge
mystic patio
#

I wonder if I could have trouble with HTB if I develop and publish POC of CVEs of active boxes

#

Any mod can help me with this?

#

Like i dont find decent POCs for CVEs when Im doing an active box and I want to develop one

alpine pumice
#

Mods can only help with Discord server related problems.

mystic patio
#

Who should i talk to?

alpine pumice
#

It's against ToS to post writeups for active boxes.

mystic patio
#

I know

#

But im not sure if a POC of a CVE is allowed

#

I mean it must be allowed

#

Its not a writeup

#

But

#

I want to be sure

alpine pumice
#

That would reveal the attack path on an active box, against the ToS to provide writeups/attack paths/etc. for active boxes

#

Providing the way to solve a machine and trying to not call it a writeup is still a writeup

mystic patio
#

I understand

#

Ill wait when the box is retired then

ornate wren
#

if you mean develop POCs that happen to exploit something on a box that's fine though just don't do like

#

"here is the POC for thsi box"

#

if it's poc for cve whatever

alpine pumice
#

If you have questions like this it's best to reach out to HTB directly on the website. Their support can answer the questions better than anyone here.

undone fossil
thick forge
#

cofeee time

simple monolith
#

ready for the machine

rancid snow
fiery copper
tame plaza
supple plume
idle mauve
#

May I connect release arena via machines vpn

thick forge
potent gull
#

sup

#

o/

#

\o/

#

oi

tame plaza
supple plume
#

zero units of dumb

potent gull
#

I need a new hobby

#

side quest perhaps

tame plaza
potent gull
#

unlikely

supple plume
potent gull
#

LMAO nope

supple plume
#

it's not that bad

potent gull
#

I like mine

silver forge
#

why doesn't report cpu

supple plume
#

wdy do you said nope xd

potent gull
#

because I turned all the none your business off

tame plaza
supple plume
potent gull
#

LMAO

silver forge
supple plume
supple plume
tame plaza
supple plume
#

I wanted to see that 100 uptime days

supple plume
tame plaza
silver forge
supple plume
#

with zsh

potent gull
supple plume
potent gull
#

yes

tame plaza
potent gull
#

with zsh, to answer

tame plaza
#

usable

supple plume
tame plaza
#

can u send it to me ?

supple plume
supple plume
potent gull
supple plume
#

it has hacking scripts too

supple plume
#

like this shit is so impractical

potent gull
#

I have three configs. common, bashrc, zshrc so just in case I need to swap around. most everything lives in common, very little is zsh

bitter wasp
#

Hello, I am creating a firm in Slovakia that focuses on penetration testing. We are doing a deep research into methodics and tactics to use while doing these tests. Can someone here tell me more about their own procedure or reference some links, where I can find these things?

supple plume
#

I update it often, I have not set any versioning tho, but to update is like the same oneliner that's used to install

green kite
#

Hello chat

supple plume
#

leave me some gh star if you like it

green kite
supple plume
green kite
#

Ill leave two

supple plume
potent gull
#

super

green kite
potent gull
#

whatcha bloggin

supple plume
green kite
#

Nice

devout sail
#

I gotta raise an issue on it

supple plume
potent gull
#

issue and PR, instantly. gotta get that contribution badge

bitter wasp
#

No I want to create a business based on penetration testing. In my country, it's not common and I think this gives me a perfect opportunity on market

devout sail
#

Like farming.?

supple plume
tame plaza
supple plume
#

I'ma run sqlmap through websockets evil_cat brb

tame plaza
potent gull
tame plaza
supple plume
silver forge
#

The Toilet Paper

green kite
silver forge
green kite
#

No bbp. But the company is considering it

green kite
green kite
#

Watching kingsmen with the wife

#

This cutie is keeping me company too

bitter wasp
cerulean bloom
green kite
#

He’s snoring

cerulean bloom
green kite
#

This one’s recovering from class

#

How’s everyone’s Saturday

potent gull
#

super! yours?

green kite
#

Yeah it’s been good, thank you.

cerulean bloom
graceful pendant
#

happy valentines

green kite
#

You too πŸ’š

rose onyx
green kite
graceful pendant
#

I got a 404 there

green kite
#

But might be able to make it a 418

#

Valentines is overrated

graceful pendant
#

im tryna make it a 500

green kite
#

Then a 201

#

Then in a few years 429

gaunt gale
green kite
gaunt gale
#

Ok

#

Gotcha

green kite
#

She knows I love her by the little things πŸ˜‰

gaunt gale
#

Ya that’s a good philosophy

green kite
#

Pre-heat her car when she’s gotta go to work for example

gaunt gale
#

Ok agreed

#

Ya

green kite
#

Load the dishwasher wrong so she can yap about it kek

gaunt gale
#

Ya ok

#

Wonderful

green kite
#

How’re you birdie?

gaunt gale
#

Good I did half a CWES module a couple days ago. Yesterday had severe anxiety and wasn’t able to focus

#

Today I’ll finish the module

#

I’m celebrating my birthday today and tomorrow

green kite
#

Oh I am sorry to hear that. Did you get your appointment with that doc you were talking about?

gaunt gale
#

Tomorrow is my actual birthday

#

Yes

green kite
#

OMG !!

#

Happy birthday in advance

gaunt gale
#

Thanks

#

I really appreciate it

#

Anyway, my doctor prescribed zoloft more than two, soon to be three weeks ago

gaunt gale
#

Thank you

#

I appreciate it

green kite
#

I hope it’ll help you

supple plume
gaunt gale
#

It probably will but I’m on a low enough dose that the therapeutic effects haven’t kicked in

gaunt gale
green kite
gaunt gale
green kite
gaunt gale
#

Anyway I’m off to a concert with a friend

green kite
#

Enjoy!!

gaunt gale
#

Thanks guys

#

Ttyl

green kite
#

See ya

supple plume
#

Getting ready for the seasonal

#

I hope all my team gets in vc

cerulean bloom
#

uhh

#

I might not LOL

crimson crypt
#

@fossil sequoia can I send you a DM?

supple plume
cerulean bloom
#

its like

#

4 AM

#

I'll join ig

supple plume
#

Oh yeah

cerulean bloom
#

worst timing tbh

#

you guys can help me tomorrow if possible

#

I'll try, but me getting sleepy

supple plume
#

Yeah these nasty machines get released always at the same time

supple plume
#

Have you checked my blog btw?

cerulean bloom
#

no

supple plume
celest meteor
#

Why is it not allowed to screenshare in the channels? (i am new here, just switched over from THM)

supple plume
celest meteor
#

Ahh, okay xD

supple plume
#

Yeah it works like this with embedding

celest meteor
#

THM has become so bad lately, the VMs are unresponsive, latency blows and rooms are just basic questions with almost no effort to find the flags

supple plume
#

I have heard that

supple plume
#

Huh

#

What about the chat

celest meteor
supple plume
#

Hahaha

#

I would say here is 1.7/10

celest meteor
#

There are so many randoms in there like femboys, people joining vc and meowing etc

supple plume
#

Hmm

#

There is femboys here too

celest meteor
#

FUC...

supple plume
#

What's wrong with femboys?

silver forge
#

it's the femboy apocalypse

warm ravine
celest meteor
#

Yes like we can respect LGBTBBQ but just dont shove it into peoples faces if they dont want to (No hate)

sharp beacon
#

wut

supple plume
#

I have one in my team and I am proud of him y'all can suck my ass

sharp beacon
#

hell ya

thick forge
crisp sand
#

i completed the jet fortress challenge and i got only 12 points for all flags is that normal ??? (on my profile points )

thick forge
supple plume
thick forge
#

i never win points because i am noob

supple plume
supple plume
crisp sand
#

🀣

supple plume
#

we are learning a lot here

thick forge
#

spanish team ?

#

i wanna participate en ctf time

supple plume
thick forge
#

but i dont have much time to spend

#

lot of work

supple plume
#

hehe

tame plaza
thick forge
#

🀣

supple plume
#

it's dificult to find spanish speakers

tame plaza
#

nice pwnboxes on web

supple plume
thick forge
#

i dont know, decrypt

#

🀣

#

read it fast

supple plume
sonic wharf
#

lol the webpage said it can't find the machine

tame plaza
naive coral
#

i started machine but nmap scan shows not a single port open lol

tame plaza
naive coral
#

nvm it works

silver forge
#

or apply more force

thick forge
silver forge
#

I have now been trying to find a bug for almost 3 hours... sigh

rare spoke
#

user blood taken before i can even spawn box lol

woeful osprey
#

same lol

thick forge
sonic wharf
silver forge
#

once upon a time I had the blood for user for one box, but decided to take a nap. after waking up I realized what I had done kek

#

I had the hash there, but didn't submit

#

but was good nap

tame plaza
potent gull
#

yesterday my domain email was spoofed. weird getting an email from myself, saying note to self, and also saying suspicious activity, user may be impersonating sender. First time this had happened in all the years of me managing my own domains.

#

anyways, be vigilant

#

also, naps are good

silver forge
#

spoofing email addresses, if your domain is properly configured, is nearly impossible

potent gull
#

anyways, I swapped it and should be fine again. it wasn't a primary address, I use it for testing mostly, but, my fault is my fault.

#

kinda funny though. failed all checks, and still landed in inbox. my primary email gets filtered sometimes. but some rando sending me an email saying "hello" from my own domain= straight to priority 🀣

tame plaza
#

who's using omarchy ?

potent gull
#

nope

#

but, because no opportunity wasted. I use arch

#

btw

#

well if it's "basically Arch"... do you have a question or are we just asking to ask?

#

oh, then nope. I will let you whisper into the void

azure remnant
#

to do is to be

#
  • gigachad8520 rahimahullah
young glen
#

Any openSUSE users?

silver forge
#

hopefully not

dusky pebble
#

what's the point of streaks, it pops up once a week but I can't review it anywhere on the platform???

thick forge
#

is from the academy

dusky pebble
#

okay, maybe I understand some of the points - why can't you see the streak data anywhere beyond a simple streak goal on the dashboard or when you complete an item required for the streak or are about to "miss" a streak... there's no historical view??

thick forge
#

when you have the possibility to miss a streak you receive an email notification

#

about the historical view, not sure, thats gonna depends of how the streak are stored in the htb database

dim lagoon
#

I'm in the files

thick forge
#

could be just a strike counter of 3/3 or can be store all the streaks that do you do in the academy

#

but what i think maybe is just a counter that reset the sate when the week ends

#

now i am curious about it

dusky pebble
#

ha, sorry catHiss

dim lagoon
thick forge
#

but is a interesting question, all depends of how htb is handle it in the db

thick forge
#

emotional or economic

tame gust
#

it does not depend

thick forge
#

well

#

so it does not depend

#

is eating time

#

i generate auto dubbed with ai

dim lagoon
#

veiny ahh dih

azure remnant
dim lagoon
#

Yo whatPepeProtecc

#

veiny ahh dihveiny ahh dihveiny ahh dihveiny ahh dihveiny ahh dih

azure remnant
#

You should be lucky if ur not in

dim lagoon
#

ALLAH UKBAR!

manic anvil
#

bro wtf

azure remnant
#

bro is on religion generator πŸ₯€

silver forge
#

now I have prompts in my prompts in my prompts

manic anvil
silver forge
#

I have claude designing a system how to design a prompt to design prompts.

manic anvil
#

this is like writing prompts to ai so it write you prompts for it to generate something

silver forge
#

the issue is, my prompts have become so complex I have to start using multi-level templating

#

so I have a prompt template skeleton, which gets populated by sub-prompts. and I'm using a prompt to manage them.

rapid badger
silver forge
#

... and again claude launched 18 sub-claudes, and there went my quota. ah well

thick forge
#

i not try it yet

supple plume
thick forge
#

but can works

supple plume
#

It's kinda slow for free models and dumb models...

#

But the idea is cool

#

Also you can add your api keys

silver forge
rapid badger
thick forge
supple plume
#

big pickle

silver forge
supple plume
#

look how dumb it is

supple plume
rapid badger
exotic pendant
#

πŸ˜„

silver forge
thick forge
tawdry sorrel
#

Hey there

loud solar
#

hello guys

tawdry sorrel
#

Wsp

alpine pumice
#

Your account is verified though

#

How are you here talking then?

#

Unlink and re-link the account

#

try another browser if you're having browser issues, or private mode, extensions disabled

loud solar
#

ive got that issue

#

have you tried /verify

west lynxBOT
#

Whoops! I cannot DM you after all due to your privacy settings. Please allow DMs from other server members and try again in 1 minute.

hollow prism
#

guys, could someone help me? i'm strungling when its a good time to start with the labs, if it is when i finished the modules or smt, what do u guys think?

obtuse fern
#

Sometimes it can take a little while, make sure you're also not signed in on another discord

torpid root
#

yoo anyone form SantΓ© QuΓ©bec? I have some questions for you !

sturdy thistle
#

Hello guys

west lynxBOT
#

Whoops! I cannot DM you after all due to your privacy settings. Please allow DMs from other server members and try again in 1 minute.

magic blade
#

it is very cubic

azure remnant
#

Hi htb can i have lifetime sub

#

How much watt hours would i spend by mentioning all

terse dirge
#

Mfw when I spend 5+ hours setting something up and fixing stuff just to be told that it's not right because a different system should be used:

obtuse fern
#

If you dont change it youll be forced to leave

#

Its literally the htb logo, which can mislead people into thinking you're staff.

zenith pine
#

change color

#

red, evil htb

toxic sandal
#

Am I wrong in feeling like Parrot is more stable than Kali? I feel like I've gone full circle back to the "Kali vs. Parrot linux" question everyone asks at first

warm ravine
obtuse fern
toxic sandal
obtuse fern
warm ravine
obtuse fern
toxic sandal
toxic sandal
# zenith pine vm

Wild, I had a bad experience with that with performance. MacOS M4 in ARM kali via Parallels. Maybe it was a me issue

obtuse fern
#

Its ok

toxic sandal
#

I've run into a lot of ARM issues but mostly with compiling super old POCs, but not enough that it hasn't been useful

#

Parallels is super smooth (this isn't an ad) compared to Virtualbox on a gaming pc

warm ravine
#

Hey yo @supple plume
I'm starting to get into the hands on how to connect into a machine

toxic sandal
warm ravine
#

But I'm curious why VPN needed for it

west lynxBOT
toxic sandal
supple plume
warm ravine
#

Yknow that that's actually so clever

#

I never thought that

warm ravine
supple plume
#

I also believe they assign a vpn ip internally linked via backend to your account so they can check if you cheated doing machines

supple plume
#

too late brath

sharp shuttle
#

Are you in Oregon?

supple plume
#

he is next to Oregon in Slovenia

obtuse fern