#general

1 messages · Page 488 of 1

cedar fable
#

And so

austere sinew
#

BECAUSE IT IS SHIT

cedar fable
#

Posh

eternal mango
#

loool

scenic maple
#

Petition for Scotland english to be called scottish cause that aint english

cedar fable
austere sinew
#

@wooden python

lime trout
#

better then the american-alternative

cedar fable
#

You’re blind

eternal mango
#

Lots of DFLs here

cedar fable
#

Have you been to Peak District

#

There’s so much people down south

eternal mango
#

Little further East and price goes down some

ocean marsh
#

getting stabbed in london or getting in a car accident in egypt, choose your fate

eternal mango
#

...until you hit Rye

cedar fable
scenic maple
#

Going to uk and joining a gang would be a side quest

eternal mango
#

Then you're in old person territory and high rent again

cedar fable
#

Bought a house over here on east

#

And fking hell

lime trout
cedar fable
#

It’s like double the price

austere sinew
scenic maple
cedar fable
#

You’re blind

austere sinew
#

They’re unemployment final bosses

scenic maple
#

Thats why its not a quest

jolly snow
mystic harbor
eternal mango
austere sinew
#

Hang outside houses

scenic maple
austere sinew
#

WDYM CLOSE

scenic maple
#

So you are from which gang

heady sage
lime trout
scenic maple
austere sinew
#

In the same spot….

ocean marsh
#

wolo what about oscp

austere sinew
cedar fable
eternal mango
#

So lightning DOES strike twice

jolly snow
#

I wanna try and see whats that hype about jacket potatoes in UK

austere sinew
eternal mango
#

That makes no sense

#

but I'm sticking with it

cedar fable
#

If you come UK get yourselves a nandos

split patio
#

Anyone planning to become a bug hunter here?

ocean marsh
jolly snow
#

Looks pretty good on vids

cedar fable
#

They ain’t cheaper no more

ocean marsh
#

STOP YAPPING

lime trout
austere sinew
eternal mango
#

We had a Nandos for like... 2 months

austere sinew
#

You see

cedar fable
#

But nandos is good

eternal mango
#

Then it closed because it was crap

austere sinew
#

We’re cold

#

And

cedar fable
austere sinew
#

Then there is something warm

lime trout
#

ngl, best chicken is jolibee

austere sinew
#

And starchy

heady sage
scenic maple
cedar fable
austere sinew
#

And buttery

lime trout
cedar fable
#

Well nvm

#

Come here to get Greggs

eternal mango
#

...but they didn't

jolly snow
#

So the taste is mid according to you ?

cedar fable
#

And a chance to get stabbed 🤠

split patio
#

no tag

jolly snow
#

But the environment influences it a lot

cedar fable
#

If you’re lucky even robbed

cedar fable
lime trout
austere sinew
cedar fable
#

We should delete London

heady sage
cedar fable
#

And brum

heady sage
#

Or have you met

scenic maple
#

Such vast empire and still no spices

lime trout
austere sinew
lime trout
#

london, or city of london

cedar fable
#

He’s helped me out to get a job

austere sinew
#

I am not from that cesspool

jolly snow
ocean marsh
cedar fable
austere sinew
#

I am a southerner

#

Who moved up north

scenic maple
#

Dont troll

austere sinew
#

And now wants to go back down south

cedar fable
green plover
scenic maple
#

Yeah dont troll literally

austere sinew
cedar fable
#

Only good thing down here is: you could sell your house for a higher price

jolly snow
#

I found out about those potatoes from that one brother yt channel

heady sage
#

And this is Golam. @scenic maple, JavaScript nut and web dev extrodianare

cedar fable
#

Which is sort off good

austere sinew
#

IT TAKES ME FOUR HOURS

#

TO GET TO LONDON

jolly snow
#

That garlic butter was good ngl

cedar fable
austere sinew
#

UNO DOS TRES FOURRRRR

cedar fable
#

Do you

lime trout
green plover
lime trout
#

just drive

cedar fable
#

You doing uni or something

austere sinew
scenic maple
austere sinew
#

The train back

austere sinew
#

Twice

ocean marsh
lime trout
#

imagine having trains

austere sinew
lime trout
#

just drive

scenic maple
lime trout
#

get a pickup truck

cedar fable
jolly snow
#

Trains are lifesavers

scenic maple
green plover
ocean marsh
#

Some people distro hop, wolo cert hop

heady sage
#

Golam is actually better at web than me! But he doesn’t like to admit it.

cedar fable
austere sinew
eternal mango
green plover
jolly snow
lime trout
#

Get Nebula for 40% off at http://nebula.tv/jetlag

Buy the Hide and Seek Home Game: https://store.nebula.tv/collections/recently-added-1/products/hideandseek

Get $20 off an annual Nebula subscription by signing up at http://go.nebula.tv/jetlag
Listen to the Nebula-exclusive Layover podcast now: https://nebula.tv/thelayover
Buy a Jet Lag hat at:...

▶ Play video
austere sinew
#

That one hurt my soul a little piece of me died when you said that.

scenic maple
green plover
lime trout
supple plume
scenic maple
#

Cause its illegal

lime trout
#

we dont do crimes

scenic maple
austere sinew
#

Die

ocean marsh
#

what the hellie

green plover
scenic maple
#

No

lime trout
eternal mango
lime trout
#

or atleast someone elses ISP

scenic maple
#

Back in my days trolls used be creative

cedar fable
scenic maple
#

#agent47

ocean marsh
#

they deleted my message, they're trying to censor me

green plover
lime trout
austere sinew
#

Like

ocean marsh
green plover
austere sinew
#

Do you think youre the only person coming in

#

Asking that

supple plume
austere sinew
#

Pretending it’s someone you know

green plover
austere sinew
#

We dont like illegal stuff

#

So just shoo

heady sage
eternal mango
#

Man it's not even Friday

green plover
ocean marsh
#

can someone teach me how to hack wolo

cedar fable
#

Gosh that was a phase of mine

#

Embarrassing moment 💔💔

green plover
scenic maple
# supple plume

Fact that this was related to agent shows how creative he was

austere sinew
ocean marsh
scenic maple
#

Doesnt wolo fall for phishing links

ocean marsh
austere sinew
heady sage
austere sinew
#

When I had an interview with someone recently

#

They spoke about phishing links

green plover
austere sinew
#

And then like 5 mins

#

After

scenic maple
#

Uh huh

austere sinew
#

That interview

ocean marsh
#

wolo and interviews, biggest lie ever

austere sinew
#

I got an email offering me 200 dollars to talk if I had an interview with

ocean marsh
scenic maple
#

Bro had an interview with agent47

austere sinew
#

And I hovered over the link was dodgy af no less

green plover
austere sinew
scenic maple
#

Its def agent47

lime trout
heady sage
#

Day 23 of asking Golam if I should take a Node js class

jolly snow
#

Lmao

supple plume
green plover
#

Is c better than python?

lime trout
green plover
lime trout
#

They both have a purpose and a place and different advantages

zealous charm
#

any yappin' today?

scenic maple
ocean marsh
eternal mango
scenic maple
#

I wouls say php first

heady sage
lime trout
supple plume
ocean marsh
#

rust for mentally ill people

green plover
eternal mango
#

Node for that rush every time you install deps as to whether you get owned or not

lime trout
#

Doing stuff in C takes way longer, so python is better when you don’t need the benefits of it

supple plume
jolly snow
#

Bro just skip everything and do dart

ocean marsh
#

book

green plover
ocean marsh
#

bruh

eternal mango
#

(jk I love node, but lool did you see the compromise that shipped that ai agent with some package recently)

jolly snow
#

Dart on top

scenic maple
green plover
lime trout
scenic maple
#

Thats the book name

#

Search on google

green plover
ocean marsh
green plover
#

My

#

God

eternal mango
scenic maple
green plover
#

Thx bro/sis

scenic maple
#

Ow that bot

ocean marsh
scenic maple
#

Everywhere i gp

#

Go

#

I see his face

eternal mango
#

Yup, someone added as an install dep for cline after obtaining a token for the repo

ocean marsh
#

is the blackhat python book any good?

scenic maple
supple plume
green plover
ocean marsh
green plover
supple plume
#

htb academy + portswigger labs + developing some projects to learn code

ocean marsh
supple plume
#

I would say is amazing for web stuff

ocean marsh
#

I did cbbh and cwee path

#

its amazing

supple plume
eternal mango
#

Man I so need to actually start one of the paths, keep saying I will, then just.. not

green plover
#

Guys you know when i was a newbie in puthon ,i used crypto instead of pycryptodome and i always kept getting errors so i dont know how much time it took for me to relize that pycryptodome existed

ocean marsh
#

same

green plover
supple plume
#

I couldn't make it work

supple plume
#

heck yeah

scenic maple
supple plume
#

I remember using /feedback

scenic maple
#

If u dont know php in lfi/file upload module ur cooked

supple plume
#

xd

scenic maple
#

Learn php for cwes guys

ocean marsh
#

dont tell me what to do bro

#

😾

zealous charm
scenic maple
#

😼

scenic maple
ocean marsh
#

any php enjoyers in the chat

scenic maple
#

Dont look at me

supple plume
ocean marsh
#

this is a safe space

scenic maple
#

No i dont like

#

But i used to hate it

#

Not anymore tho

signal mica
supple plume
#

turbo

opal lark
#

I shall soon be going to a career fair and an interview later today

devout sail
#

I remember i used todo crazy math
Now I need calculator if addition isn't multiple of 10s 💀

devout sail
#

I skipped integration and differentiation
Cuz i skipped 1st year of graduation, got into 2nd year directly and they teach that shit in 1st yeat

#

They also do it in junior college, which i skipped too
So i had to learn less about math and stuff
More about technical stuff (electronics)

signal mica
#

here you can skip 1 subject per year and carry it into next year

devout sail
#

If u do diploma, you can skip a year in graduation

signal mica
devout sail
#

Automatic S (9+ grade) in 1st year

signal mica
#

oh thats whatsup

devout sail
#

Cuz i just have to do like 2 exams?
C and some stupid thing

signal mica
#

so you dodged a wholeahh math class??'

devout sail
#

Yep

signal mica
#

amazing

devout sail
#

My highest level math is from 10th class

#

Matrix ig

signal mica
#

bro barely knows addition

devout sail
#

Well guess how much i suffer from it

signal mica
devout sail
#

I was good in electronics labs cuz

#

Other spent time on math and physics chem etc
When i was fw electronicz

signal mica
#

and i barely know jack shit in electronics, but i wish i knew more

#

i know how to tinker around arduino and such

#

but dont ask me how current works in some circuit

devout sail
#

You forget about it if u don't touch it for half decade tho

zealous charm
#

@supple plume time to lock in

#

Let’s get out there and lay claim to those bugs

supple plume
#

you know what

#

I'll do that now

supple plume
zealous charm
#

Otherwise there are executable programs, like Epic Game's fornite you could probably reverse and read

#

Or look outside of BB platforms like google/apple/microsoft, I think each of those has OSS in scope

scenic maple
#

I should probably work on that htmli

zealous charm
zealous charm
scenic maple
#

It still takes a click
I am trying to find out if i can leak the cookies in GET with img tag

scenic maple
#

They accepted 2nd xss

#

Not in scope cause release was delayd but a bug is a bug they marked it no applicable so that it doesnt harm my profile

scenic maple
zealous charm
#

Just HTMLi with no JS?

scenic maple
#

I have to look for programs that have that domain list things thats super helpful than just bruting all domains

scenic maple
#

Can do all other things

#

Except js

#

Probs something todo with execution window

willow storm
#

any htb staff here i can DM?

west lynxBOT
willow storm
willow storm
scenic maple
#

Dunno then

willow storm
#

its complicated kek

zealous charm
# scenic maple Except js

Yeah then it wont be able to access document.cookie, maybe if there is a token in the URL it could be leaked via referer, but otherwise not having JS limits you

scenic maple
#

Tbh

scenic maple
devout sail
willow storm
zealous charm
supple plume
eternal mango
#

If you need to speak to someone from HTB, then honestly support is your best place to start. If it's not support, can you just ask here? If you can't ask here, then again.. I'd recommend support tbh @willow storm

zealous charm
supple plume
zealous charm
#

I personally like bugcrowd, although I have heard that H1 has better triage. Synack used to be good but has gone downhill in the last few years. Otherwise those are the only 3 I have worked on

#

At the end of the day most platforms function the same

#

A lot of people think "oh I havent had success on H1/BC, I should apply to SRT", but if you havent had success on one platform, switching wont immediately change that. That is to say the platform is less important, your time/dedication is more important

supple plume
#

thanks for the advices and info

exotic pendant
#

😄

#

Ask Claude code to find a bug in a repo
It says it found a flaw, It creates poc.js, False positive
It says it found another flaw.... in poc.js

#

Such advanced

exotic pendant
#

Decided to give it a go to see how claude handles it

zealous charm
#

Nice, I read over the apple scope yesterday

balmy basalt
exotic pendant
balmy basalt
#

lol. That checks out.

exotic pendant
#

wasnt a vuln but didnt properly call a function right

eternal mango
exotic pendant
#

I'll prob reread the webkit code

#

manually

#

but pain

signal mica
#

oh yeah doing things manual is pain in 2026

#

thats what we have becometh

exotic pendant
#

It's how I found most of my bugs, ai hasnt been much help

zealous charm
#

Is your goal bugs in iOS or safari?

exotic pendant
exotic pendant
#

so i can add it to my roster

signal mica
#

bro is collecting bugs like pokemons

exotic pendant
#

reviewing jsc so safari would be likely target

zealous charm
#

Chrome's baseline starts higher, but doesnt go as high for code exec

west venture
exotic pendant
#

Yeah i got a chrome CVE

#

only paid $5k

#

and was a high CVE

#

was able to use an image to steal NTLM hashes from the browser

zealous charm
#

Oh nice

exotic pendant
#

let me see if i can find the video

zealous charm
#

Did they just call it info disclosure?

west venture
#

How do you find them that easily?

#

When I struggle to exploit a program that I know is vulnerable to buffer overflow

cerulean bloom
exotic pendant
#

this one was specifically in the file system api

west venture
#

You have the source code for that?

exotic pendant
#

Chrome is open source

west venture
#

Oh

eternal mango
#

And fat

zealous charm
#

"claude pls find me a browser exploit, make no mistakes"

eternal mango
#

Like.. PHat

#

At least if you are building it haha

#

Kernel is easy mode compared

signal mica
cerulean bloom
signal mica
#

🙂

west venture
#

I think he means chrome has a high PH

cerulean bloom
#

OHHHHHHHHHHHHHH

#

I get it

exotic pendant
#

😄

eternal mango
#

No

#

Trolls

cerulean bloom
#

oh lol

eternal mango
exotic pendant
#

I kind of want to poke at smart contracts

#

I heard web3 pays well

#

I need to get a GF and break up to start my arc

cerulean bloom
west venture
#

I mean I always thought of chrome as being acidic, no basic, but I suppose it could have a high PH

eternal mango
#

Hahah

cerulean bloom
#

I thought that at first when you said it lol

zealous charm
exotic pendant
#

I gotta get my $1m goal for this year

#

but i also downloaded WoW

west venture
#

Bro

#

Stop

cerulean bloom
young glen
#

I play WoW as well

west venture
#

Frospite is Korean?

young glen
#

Waiting for Midnight

cerulean bloom
#

part korean

exotic pendant
eternal mango
west venture
signal mica
cerulean bloom
cerulean bloom
exotic pendant
signal mica
#

rookie

#

you gotta be #number in region

exotic pendant
#

shaming my korean side with top 2% on season 5

signal mica
#

😼

west venture
graceful pendant
cerulean bloom
west venture
#

North

cerulean bloom
#

nyo

exotic pendant
#

for pve

west venture
#

Ohhhhh

#

South?

cerulean bloom
#

yes

graceful pendant
west venture
#

Lmao I guessed it in 2 tries

graceful pendant
#

and played arena tournament 3.3.5 against hydra and kalimist

exotic pendant
#

The new wow xpac Midnight comes out next month

#

supposed to be huge

cerulean bloom
#

unlikely to find a south korean hacker that speaks english, speaks in discord, and is a teen lol

graceful pendant
graceful pendant
exotic pendant
#

March 2nd

eternal mango
#

I know I'm talking to myself, but wonder if I could take a more complex model and do some sort of decimation to reduce it to something that could be rendered in the terminal..

cerulean bloom
#

I do indeed

west venture
#

Oh

graceful pendant
#

I just finished a beta build ❤️

eternal mango
#

How're you?

graceful pendant
#

all good im getting married tomorrow

#

lol

eternal mango
#

WOOOO

cerulean bloom
graceful pendant
#

thanks. 😄

eternal mango
#

Because one is nice, and the other is a challenge

eternal mango
#

Ok

#

Well, I should've worded that better

rose onyx
west venture
eternal mango
#

Just a stupid little play thing, but fun

west venture
#

You're not vulnerable

brittle quail
#

yall play mc?

silver forge
#

oh g0blin is still here, have you been yapping the whole day hmmmHug

eternal mango
#

I don't need to explain myself, I did that already

silver forge
#

nah it's ok, I've been irl yapping the whole day pepecoffee

eternal mango
#

Gotta get those yaps in

silver forge
#

lost our supreme leader today, was his farewell party (the driest party ever, but anyways)

bronze lion
silver forge
#

his title actually roughly translates to supreme leader

eternal mango
#

I hesitate to ask but.. retired, or?

bronze lion
#

U might need it

silver forge
#

he kind of levitated upwards, closer to where politics happens

eternal mango
#

Aha ok

silver forge
#

personally I try usually to avoid politicians, but my track record on that is not spotless anymore FeelsBadMan

eternal mango
bronze lion
signal mica
eternal mango
#

It's just a little script I'm playing with, isn't anywhere atm

silver forge
eternal mango
#

Could chuck it in a repo if you really want

silver forge
#

I'd make a nice tech bro ceo prayge

bronze lion
silver forge
#

first I need lasers. and rockets. and a huge AI farm.

bronze lion
silver forge
#

the rest will come together, trust me

bronze lion
#

💀

silver forge
#

it's one of the cheapest investments available

bronze lion
silver forge
silver forge
#

noice

bronze lion
#

Won't u?

devout sail
#

What if someone fails

bronze lion
#

If no then it's just a skill issue

silver forge
#

I have already passed, all 3 levels FeelsGoodMan

silver forge
eternal mango
#

Was mostly a workout for this 4bit quant of the MiniMax M2.5 model locally, to see how it performs

#

and it's done pretty nicely tbh

bronze lion
silver forge
#

Nice, I also tested some 4bit quants lately, but more for language tasks.

eternal mango
#

Nemotron fp16 is quite nice also

#

but m2.5 is a bit heavier, hence 4bit

silver forge
#

Was funny running 30B parameter llm on pure CPU with okayish performance, without any real accelerator.

#

Advancements advance. Couple years from now things will look crazy

eternal mango
#

for sure

#

We've come a long way from Will Smith slurping his spaghetti

silver forge
#

And the Indiana Jones movie where every scene with AI youngened Indy looked uncanny

rose onyx
silver forge
#

Now I think it's time for some video games catlul

eternal mango
#

Full vibe coded for fun, but learned quite a bit and reminded me of coding silly game engines ages ago 😄

#

(back then WITHOUT AI haha)

#

I'll add the prompt history later when I get back

austere sigil
#

@rose onyx thanks for letting us know. you know what 😉

austere sigil
rose onyx
#

I gathered

mossy smelt
#

hello

exotic pendant
#

😄

exotic pendant
#

dang now i'm craving Korean food

frozen zinc
sour gulch
west venture
heady sage
#

FUCKING FINALLY

bronze lion
cerulean bloom
cerulean bloom
bronze lion
#

Ye

wet hornet
#

Can anyone pls help me make a group in telegram. It gives a message "Sorry, you are not allowed to do this."

#

?

cerulean bloom
#

I don't think anyone will help with that tbh

bronze lion
wet hornet
bronze lion
#

Lol

wet hornet
bronze lion
#

Just so u know, ur making it worse

#

You are telling me that you are not asking your so close 'homies' to make a channel but a complete stranger from a discord server to make it.

eternal mango
wet hornet
eternal mango
#

I wish more tools made with AI would include their prompt history and such a statement tbh

#

Helps everyone learn

eternal mango
#

Suppose I could add the script which parsed the raw prompt history markdowns in to that end file too

wet hornet
eternal mango
#

If it says you're not allowed to create a group, then for some reason you are not allowed. Google for why that might be.

#

Otherwise reach out to Telegram support (good luck)

wet hornet
eternal mango
#

We can't help you, sorry.

molten bobcat
#

Goooood mornin

wet hornet
wet hornet
molten bobcat
#

Timezones ✨

wet hornet
bronze lion
#

But what type of learning did u use?

#

Supervised?

eternal mango
#

The local model was out of the box, 4 bit quant from the minimax-m2.5

cerulean bloom
eternal mango
#

Some was done with opus 4.6

#

It says that in the readme

#

😉

molten bobcat
#

😄

eternal mango
#

I use Kilo Code currently for the prompting personas

cerulean bloom
molten bobcat
#

Ya

bronze lion
#

Oh ok

cerulean bloom
bronze lion
cerulean bloom
#

you'll crush it

bronze lion
#

How are u

molten bobcat
#

Hallo I'm good

#

I'm watching tv and trying to wake up

bronze lion
#

What's up with tht pfp? Where's the majestic cat ?

molten bobcat
#

I like fallout

eternal mango
#

I've added the script used to extract prompt information and generate the prompt history markdown file too now @bronze lion 🙂

bronze lion
molten bobcat
#

Is a man not allowed to like things without ranking them lol

cerulean bloom
eternal mango
#

It needs updating if you use it as it has some static sections but yeah

#

can't update it from my phone 🤣 🤣

molten bobcat
cerulean bloom
#

can a person not like two things at once lol

bronze lion
lime trout
#

hi chat

molten bobcat
#

I feel like I'd find a way to get family guy episodes on my pipboy

#

Y'all got games on your pipboy?

eternal mango
bronze lion
#

What

#

Oh ok

eternal mango
#

I'm terrible at using the reply feature..

bronze lion
#

U deleted it suddenly lol

molten bobcat
#

He replied to the wrong person

#

So he fixed it

eternal mango
#

I didn't reply to anyone

#

so I fixed it

molten bobcat
#

Ohh

eternal mango
#

😄

west venture
#

I'm enjoying C++ more then go

cerulean bloom
lime trout
#

Still decently early, but alright so far

eternal mango
bronze lion
#

Easier than I thought

#

Thnks

molten bobcat
#

I laid in bed last night

#

Slightly not sober

#

And my last thought before I drifted off to sleep

#

Was

lime trout
#

Taco Bell

molten bobcat
#

Man, I'd kill for some raisin bran rn

bronze lion
#

Was..

#

💀

molten bobcat
#

I like cereal

bronze lion
#

There is no need to kill someone for ht

molten bobcat
#

Where's the fun in that?

bronze lion
#

True lol

sturdy thistle
#

Found a 2FA bypass in a plugin

molten bobcat
#

It's storming

cerulean bloom
molten bobcat
#

Why rain dance it's already raining

devout sail
zealous charm
devout sail
#

Cuz odd number

molten bobcat
#

Because this implies 2fa is used properly

#

Reeeee

cerulean bloom
#

@scenic maple what are you typing lol

bronze lion
scenic maple
devout sail
zealous charm
bronze lion
#

The anime entirely is peak

edgy jetty
#

ramadan mubarak for all muslim hacker :3

scenic maple
bronze lion
edgy jetty
scenic maple
#

Best i can do is a link or other html

bronze lion
#

Ramadhan mubarak to Everyone

molten bobcat
zealous charm
scenic maple
#

I should try iframe ig

scenic maple
median sundial
cerulean bloom
zealous charm
scenic maple
#

I found out the math formula bruteforce wont help with O(n) since it becomes 1x10^18

bronze lion
#

What's the problem

bronze lion
#

I wanna try it too

molten bobcat
#

10 with 18 zeroes

#

Is how that is read

#

Btw

cerulean bloom
#

yes

#

1000000000000000000

molten bobcat
#

I'm bad at math

median sundial
#

Do Challenges progress towards ur Rank too or is it only machines?

cerulean bloom
#

active machines and challenges

#

so yes

bronze lion
molten bobcat
median sundial
scenic maple
scenic maple
molten bobcat
#

I have to join my boss on a client call today

zealous charm
cerulean bloom
#

its simple maths ig

scenic maple
cerulean bloom
#

want me to tell you the solution, give a hint, or tell nothing

scenic maple
#

Tell nothing

cerulean bloom
#

cool

#

gl

scenic maple
#

Cause intruder only sends http right

#

Without a console how do i see js being run

zealous charm
#

Right now you are only in the HTML context, so this is just building out your payload to see if you can get any JS. But the XSS payload will fully appear in the HTTP response

#

General XSS fuzzing is like:

  1. find allowed HTML tag with portswiggers tag list
  2. find allowed event handler with portswiggers event list
  3. build out JS payload (alert() or similar)
scenic maple
#

This is Very interesting

rancid snow
#

Saving that to my notes to dig deeper later

#

xss is such a memed vulnerability class but then you look at people who are good at xss and they pull out some ninja shit

scenic maple
#

The payload gets cleaned by client side js

#

So if intruder can help here my mind willbe blown

#

I am digging into this next thing tomorrow morning

scenic maple
#

Bro wrote the math formula

eternal mango
#

It was C1ouds idea

#

I think?

#

Or he gave me the idea

#

I dunno

median sundial
cerulean bloom
eternal mango
scenic maple
cerulean bloom
#

LOL

#

he really did

scenic maple
supple plume
#

hi brewer I got fumbled by the BBs

zealous charm
#

Nice blog, a fun interview question is "what is the impact of XSS with the httponly flag set" (or unauthenticated XSS)

austere sigil
#

Wordpress is developed in PHP so there’s no bigger insult than that

scenic maple
#

the answer is waz

eternal mango
#

PHP with Octane as the interpreter is fast as fuck boiiiii

scenic maple
#

technucally speaking you should still be able to make actions the user does from the console

#

very impact

austere sigil
#

Much impact

scenic maple
#

and out of scope

zealous charm
austere sigil
#

Not replicable

scenic maple
#

well if its unauth you could still run js on the users browser and mine crypto

#

or phish them ig

#

but its not real impact

#

p5

#

what would you have answered?

zealous charm
scenic maple
#

what why

#

oh i see now

#

cause it impacts everyone(not just loggedin)?

azure remnant
#

Big show

#

Miss him

exotic pendant
#

😄

molten bobcat
#

Heya frost

azure remnant
zealous charm
# scenic maple what would you have answered?

its just a good question to see how people think. Basic thinking is like "steal cookie", but thats why the question specifies httponly or unauth. Mid level answer is "xss can perform any action in the users browser", but again people focus on authenticated xss. So anything from fake login page, driveby download, etc show a little creativity

azure remnant
#

Hes fbi look

scenic maple
#

i guess i passed this one

zealous charm
#

ur hired

exotic pendant
molten bobcat
#

Just relaxing before work. I'm on a customer call today

azure remnant
sturdy thistle
azure remnant
#

My bro worked there until corona kicked in

molten bobcat
#

I'm being asked to sit in on a client call, I'm a security analyst

azure remnant
#

O ok

molten bobcat
#

I used to work helpdesk tho

azure remnant
#

It all starts small

#

Me in 10 years: water searching analyst 🗣️

frozen zinc
zealous charm
frozen zinc
exotic pendant
#

whoops acidently found a chrome bug

bronze lion
#

Accidentally

#

Ye bro lol

exotic pendant
#

😄

young glen
zealous charm
jolly snow
#

they finally talkin now

exotic pendant
zealous charm
#

MiraclePtr status?

supple plume
exotic pendant
#

DOS maybe at most with that

#

was playing with somehting else and acidently loaded it into my browser and boom crashed, which caused me to investigate

zealous charm
#

Still probably 0-10k for memory corruption. Although I think MiraclePtr: protected caps at $2k

exotic pendant
#

yeah still easy money

sturdy thistle
#

the 2fa bypass is dupe

sturdy thistle
zealous charm
#

Yeah looks like $1000-2000 for mitigated UAF

jolly snow
#

but that blurred stuff isnt too necessary

jolly snow
supple plume
#

I just said

#

for the refresh token

zealous charm
#

A triager would ask: what does the bcrypt hash do? What is the impact?

jolly snow
#

oh mb didnt read the full thing

#

ye i mean u dont even know if its a password hash

supple plume
#

it's not a password hash

jolly snow
#

alr so how important do you think it is

supple plume
#

if it could be craked... I would need to try if I could authenticate with another user or steal someone's session using it

#

probably not worth to keep digging

alpine latch
#

Hello everyone

brittle quail
#

can someone help me with metasploit

#

nevermind

mystic harbor
zealous charm
#

Gemini 3.1 pro released frostypausetime

brittle quail
#

why do files disappear everytime i extract with 7z

thick forge
eternal mango
#

If it's used in a server side flow, you would need to obtain the client secret also

#

but not all oauths are made the same, some implement additional checks when tasked with issuing a new short lived token from a refresh token

#

You don't need to crack it, either

#

It's meant as a secret for the client to use in order to refresh short lived oauth tokens when they expire

#

I think what I've said is accurate, anyway

rapid badger
#

Sounds about right

mystic harbor
#

@cerulean bloom how's the challenge?

bronze lion
#

⁨@austere sinew⁩

austere sinew
bronze lion
#

Nothing

#

😶

wind robin
#

Hello Chat

#

I bought a new laptop today a ThinkPad with 16GB RAM, 512GB SSD, and i7.

#

I want to install Kali Linux on it directly as the main OS. I also have Kali and Parrot installed in VMs. If I install kali-linux-everything on the main OS, could there be any issues?

sturdy thistle
#

send it straight to me kek

wind robin
mystic harbor
#

The full name of it

eternal mango
#

I mean, you could face compatibility issues (Google your laptop model and compatibility / drivers / etc). If you then start using it as your main OS with the intention of playing in labs or whatever with it, you are then taking your primary OS in to potentially hostile environments.

#

Whereas.. if you stick with VMs, you can isolate them to a degree, take snapshots, revert to a clean state, control their resource usage, all while having a (usually) isolated host to work on.

sturdy thistle
#

i think my cpu from x230 is an i3 m3210 or something - i forgot

eternal mango
#

End of the day, the question you should be asking is.. what do you stand to gain from installing it as your main OS

sturdy thistle
#

i was awarded with $36 bounty for 1 vuln kek

eternal mango
#

With 16gb ram and an i7, ok not a super power house, but plenty to run Windows and a guest VM without trouble

#

If you're more comfortable with Linux as a daily driver, then do it, but be very aware of using it directly in VPN environments on platforms like HTB, that it is your host.. not a VM. It is not isolated.

#

That said.. if you want to daily Linux, there's nothing stopping you from running VMs on there too

#

but if I were to daily linux, I probably wouldn't daily Kali or Parrot

#

but something more lightweight

mystic harbor
#

Arc linoxarchthink

austere sinew
#

you know when i watch people fighting about which distro is better it reminds me of the kids in school who argued that their shoes can make them run faster because they have lights built in

#

but i stand on my hatred for arch

wind robin
eternal mango
#

What do you want to use out of interest?

eternal mango
#

Windows 11 with 16gb can comfortably run a VM with 4gb RAM

#

...but it will get cramped with heavy daily use of course

austere sinew
#

a stiletto just going off blinding everyone seems so cool

austere sinew
eternal mango
#

One alternative could be WSL for your testing environment on Windows, which you can spin up a Kali image on, but you're forfeiting isolation by default with that, although you can harden it to an extent

supple plume
molten bobcat
#

I have taken the tummy potion

mystic harbor
wind robin
#

What I want is to use Kali Linux, Parrot OS, Ubuntu (server version), and Red Hat on VMs — and I want to run them all at the same time. So I'm thinking it might be better to just build a PC. :3

molten bobcat
austere sinew
#

turn the heels into jets

eternal mango
#

Yeaaah that might be a bit much all at the same time with 16gb RAM tbh

mystic harbor
#

Yahhhh

mystic harbor
molten bobcat
#

Guys look I glued my drill to my chainsaw to my screwdriver to my car to my house to my toaster

eternal mango
#

Kali 2-4gb, Parrot 2-4gb, Ubuntu, could get away with 512, same with Red Hat I guess

#

but those would be very slim instances

#

If you don't need UI on Kali or Parrot, you could reduce that number a bit

#

but that'd be a hell of a squeeze

molten bobcat
#

Gob I have a funny client call

eternal mango
#

Can I join?

molten bobcat
#

God yes

eternal mango
#

(NO JOKING)

molten bobcat
#

I need someone

#

To like

austere sinew
#

i do want a degree in mechatronics but the options in england mean i'd stay in manchester and i'd rather.... not...

austere sinew
#

JOIN THE CALL

molten bobcat
#

Adequately express to these people that yes, making the DC a public RDP server

#

Is the dumbest fucking thing since condos

austere sinew
#

hoi morph

wind robin
maiden anvil
#

people used to think they were communicating with aliens or a higher power, but actually they had dental fillings that were picking up AM radio

molten bobcat
#

Ruh row indeed

molten bobcat
#

They're calling us to complain about the lack of care regarding RDP bruteforcing

#

Fat kek

mystic harbor
molten bobcat
mystic harbor
austere sinew
#

not far from what china did.........

#

remember when they hired cosplayers to pretend to be robots kek

mystic harbor
#

DIY robot

eternal mango
mystic harbor
eternal mango
#

Also what the dumbshit

#

It's public

#

Sure you can limit exposure

#

...but if it's public

#

first

#

WHY IS IT PUBLIC

#

Second

#

WHY. IS. IT. PUBLIC

austere sinew
eternal mango
#

lol

austere sinew
#

😔

mystic harbor
#

Correct

wind robin
eternal mango
#

RDP is vulnerable to Frostb1te

#

Everything is vulnerable to Frostb1te

austere sinew
#

i am vulnerable to my own stupidity

mystic harbor
#

I read Fortnitesadglas

eternal mango
iron galleon
#

i can download it rn

#

once im out of the restroom

mystic harbor
#

Sleep time

iron galleon
#

alr

wind robin
#

By the way, I don't really like the new desktop style of the latest Parrot OS release. If I go back to version 6.1 or ? and then add the repositories, would I still be able to use the latest tools?

mystic harbor
#

Maybe Tommorow

iron galleon
#

just lmk

#

ill be on

eternal mango
#

You could build / install them yourself from source

#

but yeah, from the parrot deb repo, that'll be pain

#

I assume..

wind robin
#

yes

eternal mango
#

Just from trying to get a deb package installed the other day, just one.. so many cross deps that it screamed about

bronze lion
eternal mango
#

(then someone gave me a one liner which worked)

meager kernel
#

when will HTB make new HTB edition parrot?

eternal mango
#

Soon ™

austere sinew
wind robin
#

realliy like old htb edition :p

eternal mango
#

Did the desktop manager change in 7?

#

window manager*

#

KDE Plasma 6