#general
1 messages Β· Page 494 of 1
You have the opposite relationship that I have with her
@austere sinew
i agree
Oooh sounds like fun
its not lol
hop in
IM ALWAYS KIND JUST IN DIFFERENT WAYS
damn all caps for me
Do you brew coffee
Please ping Mick
Okay but like r and I have a diff type of friendship where we bully each other the more we care. And donut is 14 and precious so like protecc at all costs
Exactly
Exactly!
@west venture
14 π
I never win these ping wars
He's 14?! Bro borderline can't use discord
@austere sigil

Heβs 14 and a hacker and very impressive
Imagine doing this stuff at his age
Damn that's nice donut
Genuinely goated
π
have u seen his work?
@sturdy thistle
π
Yeah
Fr
I was destroying ppl on fortnite when I was 14
nowadays Im a bad hacker and washed fortnite player
I do that at my grandma's
which is the only place I can play games
i was still doing calisthenics that time, and guess what im doing now? same shit
why is tht?
Baby keem dropped an album guys
rule by my father
I cannot remember what I was doing when I was 14
arab?
korean
damn
Kim Jong donut?
ye i mean im asian too
nyo
damn im old
What's 7294*8842
Based
i agree with tht statement of urs
Frospite how old are you?
Been eating it daily
Older than the internet
u woke up and chose to be an racist bro/?
is that how he can find bugs that easily
I go back to sleep
now it makes sense
Made soft serve cinnamon roll ice cream
I tried Claude to find a bug for me, it found 4 Fps and nothing else
I'm gonna make u do my homework then
My goal is to be able to collect bugs as fast as frost does and be a millionaire by 30
Fps?
which subj
Obviously math
False positives
Oh
chap?
Frames per second
Well you can hunt bugs faster than AI lmao
Idk man, it's been like 5y last i studied to remember
and better. I had it go over a RCE i found and both claude and chatgpt didnt see it
Yeah
And try pointing towards it
And they'll still skip or refuse

I gave it every function from input -> vuln code and chatgpt found a bug that didnt exist and claude said nothing
oh i didnt know we use the acronym In general too. i have seen those acronym in the filed of AI like TP,TN,FP,FN
Did you try Gemini?
i am fighting with a dragon in black desert online

Oh do u target everything when hunting?
I never heard u talking about web related ones
Breh just hit the reverse scale
And one shot it
@thick forge
I got a few web bugs also
I've been using claude for src code review, definitely mixed results and requires lots of prompting
I've been just targeting high value targets lately
yeah i do like it for simplifying functions for me
Whenever I hear about bug bounties
I think of those big catchers in Pokemon games
but it's still years away from spot the bug with accuracy

Yup, you have to have a narrow csope
i think i got a link which might help
let me check
i will send the likk in DM if i find it
Sad day, I'm out of ice cream
Where do you normally look when you hunt? Bc this is what's confusing me the most. Ironically, I think doing boxes a lot made it worse here bc in boxes I know where to look most of the time, but when doing a real website, it's super overwhelming.
google VRP awarded one of my issues this week. About two weeks between fix and payout
Sometimes its me just looking through the entire code base
or
i bought some tday
sometimes I just say "This would be a cool theory if its true"
and read the code in that area
like yesterday I was thinking about a function within enhanced RDP
Like for example?
and decided to read the code for it
^ I thought enhanced RDP would be a good area to look at and had theories of things the guest -> host share
i have send a link in ur DM frost, check if it will thts gonna help u more than grok
Beat the dragon and finish hacking
Ye feel free to send bugs to me if you need help with confirmation also

Frosto always willing to help with bugs
i dont know why i always remember VPS Hijacking when i hear "RDP"
So you always look at the source code of stuff? I'm mostly talking about web too
I did have one cool area I was looking at that it loooooked vuln but i wasnt able to hit it
doing that, i finish the dragon and now i gonna abuse the write vuln to override some code to get RCE

might poke at it again today
i mean
if no source, I usually find params, poke and see how they responds
Uh no not bugs , i heard u saying tht u tried using grok,chatgpt tday for the looking for bugs
so i just shared a link which might have something useful in tht case
i personally havent tried it tho
I bought some rainbow sherbet protein. Going to make a dope ice cream
damnn
I made apple pancakes
So good
Because its difficult lol
Ah okay. So imagine you are testing a real website, what would be the first thing you do? Is it the standard stuff like standard enumeration, testing, etc?
Prolly one of the most difficult branches
can any one explain Certificate-Based Authentication (CBA) how it works
im sure u could have just typed this as a prompt in chatgpt and he would have explained it well and also clear ur doubts
He?
damn bro am i gonna get into trouble for misgendering a machine?
Yeah enumerate stuff like params, read js code and seeing how they react
a lot of the times I find a lot of good info in the js code
like in steam I got 4 XSS this way
Ohh okay
π
Yes chatgpt is a she
how do u know tht 
Because
chatgipiti
wht did u do bro
How do you know it's a he?
No it's a she
no
Yes
steam is on my to-do list as well. Once I'm done with google I might look at MSFT, steam, or fortnite
look behind u then
No
Yeah I got a few RCEs, and XSS s
Do they pay well?
I do have a few more areas saved to look at
Nope
7500 per RCE and 750 per XSS
then how did u read tht msg broskie
damn
I was looking down at the phone not forward
Riot paid $25k for an RCE
Not bad. Epic games seems to pay pretty well, they might be worth looking at. I see a lot of 10k bugs in fortnite
I have a LPE for epic but they dont take LPE
so I'm just holding it
Mw too
frost mind sending me some bugs which are below 20 dol for me ? im broke lol

mexicano
Imma copy paste code to you and you find the bugs for me >
LOL
lol
@exotic pendant btw do u check bugcrowd and hackerone for finding the targets or do u just look for bugs in for example google and report to them directly?
Both
oh nice
u can use dorks also
My dork isn't coming online nowadays

Whats popin general?
Sup
book a demo π«¦
Idk if u got hacked or that was random aah message
hacked definitely
Alright lemme book a demo then
I want to book a demo too
π¬
Been 3h already for me
Maan where do u live
Same planet ig
don't know about you guys but my sole motivation of pwning the active boxes is to get rid of the Script Kiddie title
guys what do u recommend first niche to learn if I wanna learn bug bounty
With that name?
Eww
web security?
portswigger labs too
I mean, like specific niches like XSS, race condition, SQL attack, etc.
All
but I want to master one at atime
I'd be noob but not script kiddie
Ahhh cant wait to finish academy
So u know all, wanna master 1 by 1 now?
@glad sage ask here
yeah I guess
Life
worth living
Do whichever seems interesting to u
Dinner time then


idk all seems cool; but I know ull probably say then do all since I think all r cool
Nop
where are you in the course
hey @devout sail
Yo
@glad sage

Im very worried because he said he located me via gps
so I feel like we should send him some ping overflow atack
to counterattack the python
@glad sage
Oh no, not the dreaded ping overflow attack!!
idk steve could perfectly be this one @glad sage
@austere sinew pspspsp
cyber people are crazy was watching a guy explaining SSRF bugs and for that he set up a server and tailed his logs to show us during that the guy logs showed that someone was already scanning his server lol
Logs be cray cray fr
like does bug bounty hunters have automated bots or something that 24/7 scanning the web for new websites and such?
Its not just b hunters. Tons of companies scrape the entire net
How do you think google search works ?
crawlers ?
bro thats just a bot
cant a person just setup a server in peace
yes
dont put it on the internet
Do it on personal network
my friend want to setup his own storage server i said i will do it for him
time to make lolcat command run every two hours on that server
Hi
Hy guys, I wanna know (for the good ones) when doing a nmap scan, for a regular scan do u use the regular commands like sV sC Pn, or do you always try do be the less noisy possible? Like including direclty certain ids/ips evasion?
why evade on an htb box
sorry i was sleeping
whats that
look at the signature column
for good practice
this is how you approach an htb box
Should I report exposed hard coded IP ranges as information disclosure?
still not getting it
not like this
its an ips

would you lose anything if you do?
If you're doing irl testing yeah but doing it for HTB boxes is just wasting time
i am noob i dont know
Well well well
i know but like what is this thing ? a bot that scan the internet or what?
What type of chat do we have today?
Sounds like a spider bot if it scans the internet
what do yuo mean a bot that scans the internet. its my ips
Oh then I won't
Yes, time
If you scan slowly it's going to be slow

NOOT NOOT
an ips doesnt scan things it just blocks inbound traffic
Theres no point in doing it for HTB lol
or alerts
For HTB just scan as noisily and fast as you want
hopefully 15% femboys 
at least
time to learn some vim grade martial arts 
hello
nvChad
echoesofwhoami... you didnt tell me you were into femboys
Isn't that the best way?
i caught you lacking now
I used to like lunarvim
but I am learing basic keybindings while developing something
the only way
real
tha shi is too advance for you to know
i know though
i finish my food, time to see how to get root access
i think i can help you, i just completed that after my 4-5 tasks
π€£
lol
you can't help anyone lil vro

nope
MickChad

mickchad
Yeah I know but maybe you have a default scan that u use that potentially include evasion, because even if its htb maybe a certain box use some kind of ids/ips
lol i got the user flag but i forgot to send it
Some of those IPs are up and very very juicy stuff is running π
I haven't encountered anything like that personally

how do you know its up if they are internal IPs
you have SSRF or something?
They aren't
They map to actual public servers
Public IPs
if juicy stuff is running, which you could exploit, thats a stronger finding on its own
Hopefully
pop shells, get paid
We don't do THAT in Germany
Gonna have breakfast and take care of groceries me thinks
Hy guys , HTB machine release at 1:30 am late night here , u don't think other people also have same issue to do new season machine ,
probably we should do a poll on discord , so probably get good timing people really like. @gentle tulip @obtuse fern
/feedback
It is impossible to please everyone
Because of timezones.
huh?
nvm. had to read it a second time. kinda gives an unfair advantage
Ez
The HTB machine will be released at 1:30 AM tonight. Do you think others might have the same issue with the new season machine? It might be a good idea to conduct a poll on Discord to find out what timing works best for everyone.
Only solution is fly everyone to same location
Hey, at 1:30 at night it's 12:30pm on the opposite side of the world or so
Hey guys, how u doing
True, but that might not be feasible. Letβs focus on finding a time that works for most of us.
I don't think you're understanding
He's telling you no
Type shi
dropped some barsπ₯
trying to set up two monitors on a virtualized kali without getting crazy
"might not"? 
but yeah.. no perfect solution
they release at 12:30 am for me
There is no time that works for most of everyone...
Another solution is to admit that the flat earthers were right
In all honestly, it releases for 1pm for me. Which for me, is inconvenient. I would prefer 1/130am
Β―_(γ)_/Β―
Do you never sleep? Haha
I was about to ask that π
id prob go to sleep around 2 lol. But at least at 1/130 I could at least do some of the box
Ahhh
I went to bed around 3am last night
Got focused on fixing my report that I lost track of time
sup everyone
CDSA report?
Ye
gl next time
I got this it'll be alright π
^_^
Any of you use NotebookLM?
i did for college
I don't think I know what that is
for uni and other studies
Ahhh
@gentle tulip
But I dont like using it for cysec tbh
Broski I am waiting for cubetalks to be released on spotify 
me too
Dude
@burnt bloom
Be patient man
Bruh I am waiting for Hack The Box the movie
And couldnt hear cubetalks
So u do the boxes too
when is the release date
1h
This aint no fnaf bro ππ₯
can i get permission to dm people to join a discord server of ours
maybe its a winnie the pooh
get deez nuts in the meantime https://github.com/silofy/hackthebox/
To spam people without having their permission to dm them? No
oh hell na 
not spam, just ask them if they want to join only one time
Randomly DMβing people is against the rules
can i ask someone to join here then?
EverydaySparkling
Spoil us
The cube talks
release date
on spotify
plssssss
No π
but in here its not against the rules
watch this: https://www.imdb.com/title/tt15474916/
Canβt help you there. Itβll be released when itβs ready. Not sure who recorded it, sorry
Advertising is?
Aw man...
Who knows?
it is soooooooooooooo good
something else is advertising
top 5for sure
advertising is, our server can do this has this and that, asking is different
first scene is kinda π¬
Bro I watched the silence of the lambs recently
And it was goatedd
highly recommended
Dude wtf is even Hannibal about π₯
@lofty marsh winnie the pooh style scene 
After witnessing a bizarre, traumatic incident involving a patient, Dr. Rose Cotter starts experiencing frightening occurrences that she can't explain. As an overwhelming terror begins taking over her life, Rose must confront her troubling past in order to survive and escape her horrifying new reality.
lives rent free in your head once you see it
Dude π
I saw it on halloween
I mean I saw the mf terrifier long before that
Actually nevermind nothing surpasses the terrifier π
I had 3 plastic bags next to me
ye
watch the video i sent
or actually just forward to last 2 mins
dude wtf 

3 plastic bags huh?! @frigid mountain
best horror scene
π₯
the bags are left to the imagination, suffice to say: there are 3.
Bro
Don't watch the terrifier
I beg you π
haha
when is fnaf x htb collab
looks meh
I used to. havent had time for a few years
How do you like it? Trying to decide if I wanna convert my cert notes to NotebookLM
Ye dude it looks meh
But its so graphic bro 
I've seen graphic shit but that goes beyond the scale 
Way worse π
defo watching
good luck bro π
π«‘
Menace π
i thought it was fucking cool honestly
like 9 y/o me thinking its the coolest movie ever
One of them was funny af right??
The guy who loses his hand
And time travels
Idk what that was
I vaguely remember watching something on my friends bday
any problem spawning lab machines?
Or really thinks heβs speaking for HTB community or gonna get HTB to reschedule around a time that works for him. Wat. I canβt tell if trolling or not.
Just refresh the page if it's stuck at spawning
ok, thanks
yep, worked
Enjoy
Listen vros Iβm gonna need HTB to reschedule the box. This time doesnβt really work for me.
K thx.
π
and i literally need it for root

Do last resort at the end
Tbh as long as u don't care about rankings (or blooding tbh) it doesn't matter
-# i know you are just being sarcastic, I just don't wanna scroll up to reply to him.
You still get a week to clear and get rewards
Just code it in pwnbox 
The whole thing

Indeed.
But I do feel for the people that do care about these things
I get where they are coming from truly jokes aside
It sucks for them
But like someone said above canβt please everybody
Awww cool
Iβve been waiting for them to drop that patch
Punch the monkey out here correcting the timeline
Yep they gonna flatten the eart to perfect 1d square
And change the sun to eco friendly version on lights
Does this harm the human?
No more human
I like to use it when I'm focusing on a specific topic
I feed notebook the information
and chat with it about it
cant even get source codes
jfc
how is this box a thing
I dont have all my notes there or something, I just use it on specific scenarios
Cuz no one really uses pwnbox to do it
Use your own VM?
that is just not true
Ask anyone who regularly does machines
The only time they use pwnbox is when you need to generate a weird ahh payload which only works on specific os and all
Sorry I only rent compute. Im a trailblazer...
brath can i borrow your claude cli
or codex
how so
i was under impression you were like gpt pro user scaling everything?
I dropped chatgpt, has too many guardrails
I learned everything i needed from it already
yeah thats very true
now I can query deepseek perfectly
I hit a .cn domain recently but I cant remember why
and I was pleasantly impressed with the UX
hmm so better than using gemini straight?
Claude is just bullshit because they knowingly waste your tokens and its not impressive
Its just doing cicd under the hood
Hello, I want to prepare for OSCP, what modules or learning path would you all recommend for me?
CPTS path and ippsecs cpts machine prep
Thank you!
anyone able to help troubleshoot an issue with nxc and bloodhound?
yes

I wonder what the blood hound tastes like 
it doesnt cover netexec/nxc integrations
im sorry ;w;
whatup everyone. long time no speak :x
eh hey
skill issue
so around this time last year robl_x was a filtered word, is 67 also filtered by chance?
that would be funny.
Was it?
i believe so, someone correct me if im wrong
it was around the time of the robl_x / discord fallout, like when that dude did the yt expose and both companies stock prices tanked
yes rowblawx is still filtered lol
type it
67 seems safe for now.
It's common for phishing scams targeting that particular game to hit large discord servers
That's why it's a banned term
prob cause that ones more annoying to hear in person than online i guess
it makes you smart
thats for sure
sounds like you might be a lil young. you'll realize once you get out of highschool or college or whatever that there is no boomer, millenial, zoomer, etc. its just smart people and dumb people simple as. oh and kids.
but kids arent people (as far as this conversation is concerned) thats why they're kids.
hey thats cool when did HTB get crowd sourced walkthroughs? or has that always been a thing?
oh yeah that wasnt a dig at you personally or anything just a bit of caffeinated commentary from me about society in general, who seeks to distract and discriminate groups of people on arbitrary metrics so as do keep us in a state of separation and conflict
/name 0x67
i wish this was irc >_<
Any of you have cleared cpts?
root
root@meow:~#``` 

neeeext
Hello people
Hi all
Viktor
hey guys im having a senior moment here... when we want to do a quick vibe check on a login panel and think a password fuzz is the right move, we can use fuzz for that right?
ffuf is in my comfort zone and i dont want to start trying hydra and a bunch of other shit. alternatively i might break out burp
but i just want to make sure im not forgetting something painfully obvious
Are you positive the username you'll be using is correct, or are you trying both usernames and passwords?
just passwords
im looking for admin and its a htb box so ill prob only be trying admin or administrator. ill wing that part
i think hytdra is the move here though
as much as i dont want to use it, i think its the move, no?
Brute forcing a login is usually the last step I'd take on a login form
But you can use ffuf, hydra, you could use burp suite's copy-as-python-requests extension and make a quick script, or you could use burp suite's turbo intruder extension. Definitely lots of ways
When we run out of time on the Pwnbox in the free tier, can we still solve the challenges via the same OpenVPN connection, or does running out of Pwnbox time prevent logging in via OpenVPN?
If its HTB and the answer is actually to brute the login, I believe it'd either be default credentials or it'll be near the top of rockyou
Yeah, yoink the OpenVPN config and run openvpn on a vm to continue. No issue
must be on a vm?
I literally just switched to Pop!_OS right now and I don't have anything set up here yet, but yeah, VMware was supposed to be here already, lol. Thanks
lol how does that work did this person just root within 20 seconds on a medium
you need 3 letter nickname
I wouldn't connect your host machine to the HTB network, I'd advise using a VM
LOL
Is it the more you chat it changes the color of your name?
Okies lol
Yep, handling the VMware install now
What's your gamers
No, the color of your name is dictated by roles you have. You can rank up in the HTB labs to get different colors.
Ahh ok makes sense
Is anyone open to bringing on a dev to build AI features (summarization, search, copilots) into your product?
#programming probably a better place to ask
error mounding /dev/sda1
what the hell? its my backup hd
Its 2 diff people ....
why are you mounding it
Yes but you'd have to get the user password to get the root. If the root guy got the password earlier he would put it in to get the score no?
not everything needs ai
Imo, yes
I think that the "memory" is better
and it avoids the hallucination problems
I had a sonoran dog last night and I was too drunk and cold to taste anything 
but I do highly recommend them
Error mounting /dev/sda1 at /media/alienware/A41CEB151CEAE172: wrong fs type, bad option, bad superblock on /dev/sda1, missing codepage or helper program, or other error```
wtf is this
was working great on zorin
swithched to Pop_os and now gives this error
bad format. what format is it?
Mr. @molten bobcat sir, may I borrow your attention sir
Oh sweet. I wanna upload some notes to it, but i dont want google to take/use them
is it exfat, ntfs, ext4, btrfs?
ntfs requires a package to be installed for you to mount it
ntfs i think
I think exfat needs it too
make sence
format it to ext4
What's up?
oh it says right there. My bad
where are the vuln labs located?
Mr. Community Contributor, sir
Might I make a humble request for a contribution of a measly 1300 cubes?
π π
they're the retired labs and a few prolabs
can confirm
If I want help about Uni teams on labs where do I go
Thanks, I don't see vuln lab 'Trusted' anywhere, it's an AD chain (2 boxes)
the problem is formating i loose the files
if you're using it for gaming it needs to be either btrfs or ext4 btw
hackers
ntfs-3g fuse
``` are what you need to install to mount ntfs
Cubes are non transferrable
I accept PayPal
where can I get a nice color pallet generator for variants I have the hex of the main color
I'm not giving you money lol
How come community contributor
I also accept free money
you would have to first donate your organs
via javascript
where are the artists here
I hope that you may reconsider, sir
this is where Im at
Dude wtf is this ide?
Im doing a theme for my syntax highliglight
What are u using?
bro
my bad
Some of you are fucking aliens bro istg 
just help me with this "where can I get a nice color pallet generator for variants I have the hex of the main color
"
like I need to rice my cat comand
because otherwise all this why look
see how it looks
imagine cat printing white
fuck no
just your terminal colors
I mean bro that looks normal to me
But coding in your terminal? π
First time
see way better
alienware@pop-os:~$ sudo mount -t ntfs-3g /dev/sda1 /mnt/backup
alienware@pop-os:~$ cd /mnt/backup
alienware@pop-os:/mnt/backup$ ls
'$RECYCLE.BIN' Filmes 'Pen Sandisk'
Aether-v.1 Hacks Software
'Alienware wallpapers' Outros 'System Volume Information'
desktop.ini pavilion6 User
alienware@pop-os:/mnt/backup$``` looks like is working now
neovim is very based
Oh no
not the hacks folder
if it's good enough maybe I move to nvim
U can code in neovim?
I can just code everywhere
π₯
"where can I get a nice color pallet generator for variants I have the hex of the main color"
I will VERY MUCH prefer to write code with a pencil and paper bro π
Its super inconvenient tho..
why would u do that? 
you would realize the power of vim when you discover this: .
just use notepad++ like a true hacker
Bro I scrape the code on my motherboard with a toothpic what u talking bout
mr brewer do you know the answer to this: "where can I get a nice color pallet generator for variants I have the hex of the main color"
Yes. Become based. I'm sure there's a neoemacs or whatever for emacs
We talking engineering type shit
I think it's called helix or something
π¬
we talking shit type shit
Not sure, what is your goal?
I am not sure, there is probably some color/image editing websites you can play around with online
yeah but I tried some already
no bueno
this terminal is so based
I worked a lot on it
word
But it looks empty tho...
Emotionless

Real
it lets me see what I'm looking for
Time spent editing terminal β€΄οΈ time spent finding bugs ‡οΈ
Time for the yearly vim config maintennance
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
i believe, mine is vibecoded with claude, sometimes cant copy or cant paste, but its nice haha
How the fuck is this linus bro...
@river adder
That looks more like ryan than linus π
I am ready to take over the world chat
you mean to deploy kubernetes
I am half atheist
Back to the k8s mines @terse dirge
Yes maybe
Noooo
which side
What does half atheist even mean? π
U trust god in half?
Lemme get high before I do more kubernetes
probably half bottom of the body is atheist
I believe in something big but no the creation of people
Never thought about a bro having less context than chatgpt π₯
bre

Not totally, like i believe something more big exist but no in the other stories
Your phone surely got created by a random explosion
Yes but who started the big bang
I think "agnostic" is the term for this
A giant cosmic enthity maybe
I big banged in ur mom and started ppl true story
we'll never know
Yee that's called being Agnostic
What is even the big bang

why is this guy yappping here, instead of yelling no ping im busy?
found et
90% of people when they see an advanced tech or something unique like the pyramids first question be like "who created it"
I like this person π
I only like half of it
He acted fast ngl
HAHAHAHAHAHAHASUDJBASKDNASD
Bro is secretly a good roaster
i use only pwnbox but can't use the final file
BROOOOOOO i want spam gif aswell
perfect
You can use half pwnbox π₯
no
wdym secretly
pass the hash
I roasted half the server here
U probably roasted many guys but nobody noticed

Na bro only half
BRO IM OUT
50/50
hahaha
vre
Ayy make a bot for this
ty for the assistance shadow

Shadow being those translators bruv
im just felxing my image perms
Why do you even have that bro +
Ty shadow 
Im half out
Im halfways
call me halfredo
call me 1/2
π

capybara grilling lmao
You got it half inch
The terminal I mean...


kypans do #1474825970652545024
whats that
new machine
not enough difference I think
please htb staff gift me a silver annual
but i do one today
I nly have half
6 months too is ok
Yee still looks the same

Im trying to get something good here on the yellow syntax
the types
but idk...
suggestions
Echoes wanna play 1 5+0?
aright
bre π₯

do I send link dm?
Please yes
where
you could share your .conf with us 
echo
read this
@supple plume
breh the dark mode is cool on that site
Dark mode ahh toggle
Did I just see you give a compliment? π
Historical moment
pin this shit 
must be my screen glitching







