#general

1 messages · Page 504 of 1

ocean marsh
#

ofc bro

sharp shuttle
#

Thats cool but its better to have a palantir profile that is transparent

#

the more "dirt" feds have on you, the easier your life will be

#

and said dirt is just lies

#

i search up shit im not interested in at all

#

duality of identity is the new opsec

#

you have to give up your "proximal" identity

alpine pumice
#

Making excuses for your furrycon searches?

sharp shuttle
alpine pumice
#

you just admitted you randomly searched though so now they know

sharp shuttle
#

broo why you gatta doxx me like that

alpine pumice
#

you're in oregon it's assumed most of oregonians have a duck fetish

#

i see them wearing it all the time

sharp shuttle
#

my fetish is very easy to find here in oregon

#

(trees)

alpine pumice
#

what kind of wood do you like?

sharp shuttle
#

dawg that birch messes with me

#

an man some treated cedar

#

fuuuuuu

alpine pumice
#

birch is good for sure

#

a nice strong hard wood

dense turtle
#

vac laughing at the corner

sharp shuttle
#

That shit arbors my vida

warm dome
#

ngl its crazy looking at my old notes and how bad some where compared to the ones i do now

ocean marsh
#

I cringed

#

ngl

warm dome
ocean marsh
#

never cringed so hard

warm dome
#

like i've been rewriting them similar to hacktricks for references but just process ones on boxes has changed so much

#

gone from this okay could replicate it roughly to a i could give them to someone and they could follow

ocean marsh
#

But I think that's totally normal because the first time you learn something

#

you have different eyes for that

#

notes are meant to be changed

warm dome
#

yeah i learned alot of it outside htb without notes or mostly having word for word notes, so was due for improvement for a long time coming

ocean marsh
#

works for me though

#

same

#

I did a whole mental map

civic lance
#

take is a keyword python?

cerulean bloom
#

ayyyy

cerulean bloom
civic lance
#

Does any1 ici own a homelab?

hushed frigate
#

Because that requires an IQ above room temperature

maiden anvil
#

relatable

ocean marsh
#

ngl bro, my first attempt on cert exam got me depressed

#

never felt worse

#

I felt dumb af

ocean marsh
#

I'll be doing cpts next month

#

ty

civic lance
#

true story?

#

Ur tuff

#

I cant focus when emotions is disturbed

#

Sitting down laying around feels better

#

Nahhh that’s tuff

#

Cuz how da hell you retain information😭

#

Then u wanna go and take an exam😭😭

#

I never taken an CPTS exam but I heard it’s multiple days

#

And then you have to give a report that’s reproducable

#

What the machine?

#

😭😭

#

7 hours is insane

#

You finna have to research

#

I heard ppl make directories for their boxes

#

And work from their

#

With their research n stuff

#

Really?

#

Isn’t that encouraged tho?

#

Like when I say researching, is googling and figuring it out

#

So no Google?

#

So why da hell……

muted olive
#

thats lesser than average for an insane machine

#

it takes entire days for me

warped plank
#

Good box ngl, forced me to learn a lot about a certain authentication method as well as learned a lot making a PoC in Rust 9263zerotwoveryhappy (my team already had PoCs in python and I just wanted to be different)

civic lance
#

Wth is a PoC

warped plank
civic lance
#

Wait yall have to write your own programs for some of the boxes?

#

nahhhh ur not a reel hacker

#

Reel hacker make their own programs

#

Like men

#

Reel hackers say fuck dat toool

#

Imma make a better tool

cloud osprey
#

i remember i had the choice to buy an engagement ring for my ex, or a laptop which i was going to bare metal kali on

#

and the rest is history

maiden anvil
#

you never heard of a group called milw0rm

muted olive
#

gotten too acquainted with them now

maiden anvil
#

definitely before your time

civic lance
#

Yo

maiden anvil
#

they hacked a power plant

civic lance
cloud osprey
#

installing the nvidia drivers for that kali machine was a pain

maiden anvil
#

I cant remember exactly

#

I want to say maybe Israel or something like that

warped plank
civic lance
#

Yo where tf rust came from

maiden anvil
#

ah Mumbai

#

thats where they hacked a power plant

muted olive
muted olive
civic lance
maiden anvil
civic lance
#

A power plant has open ports?

iron galleon
#

gl0wrm

civic lance
maiden anvil
#

we like 0ur 0's dont we

muted olive
#

PLCs and HMIs be having open ports

civic lance
#

Acronyms

#

Amazing

iron galleon
civic lance
#

Oooo

#

I heard of that word before

#

It’s like using other computers to attack

maiden anvil
civic lance
#

I learned about it in highschool

civic lance
#

A lil

maiden anvil
civic lance
#

I would tell everyone the earth was flat

civic lance
#

Cuz Kyrie Irving said so

terse dirge
#

Kubernetes is container orchestration not botnet c&c

civic lance
#

Oooo

maiden anvil
civic lance
#

Does HTB boxes have hornets?

#

Bot nets*

#

Too expensive maybe

maiden anvil
#

cobaltstrike all hail cobalt strike cobaltstrike

maiden anvil
civic lance
terse dirge
#

Yo Emma, I got kubevirt and kubevirt manager up in the cyber range

maiden anvil
#

before htb

#

before even offsec

#

actually maybe offsec was around then

#

yeah that kinda checks out cuz that woulda been circa bt3

civic lance
#

Damn ur a old head

maiden anvil
#

yeah, ive been studying this stuff over half my life now

#

fun times

#

like if you took my time alive so far in half, more time would be spent learning hacking than not

civic lance
#

That’s crazy and scary

#

Damn

#

Have u landed a job?

maiden anvil
#

yeah

civic lance
#

Sysadmin?

maiden anvil
#

I was a network engineer for a long time, then a red teamer, now a pentester

silver forge
civic lance
maiden anvil
#

yeah but for like normal stuff

#

cuz tbh i dont really have all day to have writer's block

#

trynna get an exec summary going

#

when I can just have some chatbot get it going for me and it's company-specific and written really nice

civic lance
#

Wait

#

Most of ur time is just writing reports?

maiden anvil
#

yeah most of the job is doing stuff other than hacking in a funny way

civic lance
#

😭

#

Writing

maiden anvil
#

oh bro

#

you're in for a really big surprise

#

you know all those diagrams and stuff in books that nobody reads?

civic lance
#

……….

maiden anvil
#

they actually mean stuff

#

check this out

civic lance
#

Bro😭

maiden anvil
civic lance
#

Ewwwwww

maiden anvil
#

this is basically the entire job in a nutshell

civic lance
#

Actually

#

This is what HTB Boxes reinforces subconsciously

meager kernel
#

🥀🥀

maiden anvil
#

Im guessing that would fall under number 4

civic lance
#

So it’s like a loop?

#

Over and over

maiden anvil
#

yeah from test to test, project to project, client to client

#

etc

civic lance
#

Damn, I wonder

#

They’ll prob try to make an AI do this

meager kernel
# maiden anvil

I just landed a pentesting internship, like yesterday, any tips and advice you can give?

civic lance
#

Enumeration is key

maiden anvil
#

good way to blow up everything

meager kernel
#

Pentesting itself is not what Im scared of
Im scared of corporate environments

civic lance
#

You never been in a corporate work setting?

meager kernel
maiden anvil
#

I think as long as you test what you're doing before you do it live you're generally fine

meager kernel
#

This new internship will be in office

civic lance
#

Idk

#

Ion think there is much to be worried about being in a corporate work setting

maiden anvil
#

yeah best of luck to you kratos

meager kernel
#

Thanks

#

Hopefully it goes well

civic lance
#

Like u landed an internship😭

#

Cmon now

maiden anvil
#

good chance they'll have you shadow someone for a couple weeks

meager kernel
#

Im already appointed a mentor

maiden anvil
#

i dont think they'll just put you into some strange situation without any heads up

civic lance
#

I thought it was only for healthcare workers😭

#

Where they have the newbie follow the vet all over the building

meager kernel
#

Im supposed to shadow a senior who will be doing pentest on pre-production AD environments

#

And I'll be given assignments

#

And projects

#

To do

civic lance
#

Wooooah

meager kernel
#

Hopefully in a team

civic lance
#

What type projects

meager kernel
#

I cant do shit alone

civic lance
#

Do they do

meager kernel
#

What else

civic lance
#

I wanna knowwwwwwe

#

The detail

meager kernel
#

Depends on what projects and clients the company recieves

meager kernel
#

Im just telling what usually happens in companies

#

Who do pentest

civic lance
#

You finna have hella fun

meager kernel
#

They make stuff for clients, and before the environment is released, you do either white box pentesting or black box pentesting on it

#

I think im roughly correct

maiden anvil
#

i think maybe one thing to consider is growing as an engineer through pentesting

#

like for example at some point having 10 criticals on a report kinda stops being fun in a way

meager kernel
maiden anvil
#

yeah basically

meager kernel
#

Ive only done pentest on pre-production environments
Cause they aint letting an intern near a production environment lmao

maiden anvil
#

well after who knows how many reports you write eventually the magic kinda wears off

#

so then you start thinking differently about the types of stuff you find

meager kernel
#

Report writing is the most boring part

civic lance
#

Jesus, I don’t wanna write essays

maiden anvil
#

like for example cranking out one policy update as a result of a test is worth over 9000 criticals

#

because if you find an issue that scales across the business, the business has to rethink how it operates

civic lance
#

Just let AI write the report✌️

meager kernel
#

NEVER

#

DUDE

maiden anvil
#

so then these type of high value output artifacts from your tests start defining what kind of portfolio you're building for yourself

civic lance
#

😂😂

meager kernel
#

You never EVER leak data to a LLM

#

It violates the NDA

maiden anvil
#

then instead when you move jobs you're not bragging about "hey look I find 100 criticals"

meager kernel
#

I just had to sign like 3-4 NDAs for this intern

maiden anvil
#

now you're saying "hey look at these 8 new policies as a result of my testing and high scale remediation"

civic lance
#

4 NDAs?

#

Tf?

meager kernel
civic lance
#

FAANG company?

meager kernel
#

They go to different branches of the company

meager kernel
civic lance
#

Oh okay

maiden anvil
#

then you stop getting offers for junior positions and start looking at senior and higher titles

#

anyway tldr im kinda rambling

meager kernel
#

They also give like 3-4 Criminal Disclosure Forms

maiden anvil
#

sorry

meager kernel
#

If you've ever had criminal record

#

There's forms regarding not giving insider trading information

civic lance
#

Oooooo

#

It’s a public company that have stocks

meager kernel
#

Bro is gonna try dox me

civic lance
#

STONKSSS

#

Nah

maiden anvil
#

im trynna work for the lizard people

#

hit me up

civic lance
#

Those that shit down something that stopped consoles?

#

Shut*

maiden anvil
#

idk the interdimensional lizard people that control everything

#

thats who i wanna work for

civic lance
#

Ooooo

#

Rothschild

maiden anvil
#

imagine hacking the mothership

civic lance
#

Or black rock

meager kernel
#

@maiden anvil you cannot tell your current clients too right?

maiden anvil
#

I prefer not to

#

Im certain I cant disclose clients

civic lance
meager kernel
#

Alot of restrictions, which is fair

maiden anvil
#

anything that goes on a report is NDA

civic lance
#

Do u guys own homelabs?

meager kernel
#

Pentesting in itself is very fun

maiden anvil
civic lance
meager kernel
#

Thats pretty much it

civic lance
#

I was thinking bout starting one, but idk

maiden anvil
civic lance
#

Like the use cases don’t really

#

Seem of use

maiden anvil
#

my lil proxmox cluster

civic lance
maiden anvil
#

oh no this is 3 NUCs clustered together

civic lance
#

wtf is that

maiden anvil
#

cute lil beefy PCs

civic lance
#

NUCs?

opal saddle
maiden anvil
civic lance
#

NDA go crazy

#

Do yall stay up doing boxes on a school night?

maiden anvil
#

I did before I started doing this for work kek

#

now not so much, once in a while on weekends maybe

civic lance
#

Bro finna write 10+ pages of reports

maiden anvil
#

you gotta encourage a culture of sharing documents at work

#

so even random bullshit ideas get written down and passed around

#

reading is the real pain

#

I couldnt tell you what ungodly amount of content I read in a day but it's unreasonable beyond all logic

civic lance
#

Damn, you should take those ideas and write a fiction book

#

Nah that’s stupid😂

civic lance
maiden anvil
#

if you dont like reading and writing, pentesting might not be it

civic lance
#

I actually own a book shelf

maiden anvil
#

red teaming even more so if you wanna be on the cutting edge of maldev

civic lance
#

With books on it

#

I have manga and fictions

warped plank
maiden anvil
civic lance
#

I think he means sharing

maiden anvil
#

I cant even remember the difference between hell's gate, halos gate, tartarus gate

#

i'd have to check my notes kek

warped plank
civic lance
#

I learned how to use burpsuite today

#

Brute forcing is a long procress

#

Gawd damn

meager kernel
#

Why is this field so hard

warped plank
civic lance
#

Ooooooh

#

No way burpsuite cost money…..😭

#

I didn’t know that

meager kernel
civic lance
#

Fuck no😭😭😭

meager kernel
#

Theres a whole way of burpsuite app validating your license
You input the licence key, the portswigger website grants you another key, you input that particular long key, it gives you an even longer key for the response, you input that response key again in burpsuite, and it grants you the access to professional @civic lance

civic lance
#

Oh okay

meager kernel
#

There's like a whole 3 factor authentication

civic lance
#

But I don’t think ppl will even pay for burpsuite

#

When there’s alternative

meager kernel
#

Companies do

#

For their employees

#

One company shares the licence to all employees

civic lance
#

Companies are different

#

They have cash to burn

meager kernel
#

Individuals normally dont, unless there's someone who REALLY wants it

maiden anvil
#

bug bounty hunters too, some private programs dont want you leaking stuff to public collaborator servers as an example

meager kernel
#

Yea but you dont discuss that in public

humble wyvern
#

dont dm me for it then

meager kernel
#

First rule of fight club
You dont talk about fight club

#

Same is in the piracy community

civic lance
humble wyvern
meager kernel
gaunt gale
#

Ya you can only get into the piracy community if you know where to look

humble wyvern
civic lance
meager kernel
gaunt gale
gaunt gale
meager kernel
civic lance
#

In terms of profit

humble wyvern
meager kernel
humble wyvern
#

u pay for it?

#

"pay"

meager kernel
#

No

#

Had it in my old company

civic lance
#

$499 for a license

#

How much do bug bounty pay?

#

$2?

meager kernel
#

Depends on the vulnerability you found

civic lance
#

Oh so they can scam

#

Gaslight u into thinking a severe vulnerability was a minor

#

And pay u less

meager kernel
#

Also, bug bounty hunters and companies are often bound by contracts, so its hard to scam, but it does happen sometimes

maiden anvil
#

there are some cases of triagers claiming findings and telling the researchers they had dupes

civic lance
#

Ahhhh bet bet

#

I have a digital forensic class

#

The labs are pretty annoying

#

I learned delete files just get sent to unallocated space

warped plank
rancid snow
warped plank
rancid snow
#

nah browse r/bugbounty youll see what I mean lmao

warped plank
#

In the end it's all about saving the most money vs making the most money

rancid snow
#

people will genuinely report shit like 'if I log into account A and then log into account B but then take account B's cookie and plug it into A's browser, Im logged in as B! broken auth! critical!!!!'

#

you can then explain to them how cookies work and theyll just argue for hours

#

I know because I've argued for hours while bored lmao

warped plank
fiery ice
#

How can I start learning malware development
What's the best language for that

rancid snow
#

maldev acadmey, c and asm

#

good luck maldev is a brutal field

warped plank
#

Hear me out: learn Rust so you solve the memory problems of working with C but now you have 2 problems.

rancid snow
warped plank
rancid snow
rancid snow
warped plank
rancid snow
warped plank
rancid snow
#

nope

#

r/bugbounty is a treat if youre bored

#

this is like 90% of posts

#

the other 10% are people writing manifestos on how they hate triagers and that every platform are just scammers and then when you ask for details it turns out to be the same shit as the other 90% of posts

torn cedar
#

What did I just read

rancid snow
#

the reason why Im always skeptical about someones bug bounty complaints without context/knowing the person

meager kernel
#

I once found this typo squatting domains with reddit too

rancid snow
#

yeah

#

its a 'no shit sherlock, you really think someones going to pay you a bug bounty for reporting a typosquat???'

meager kernel
#

Lmao

rancid snow
#

not even one trying to steal credentials or pretend to be the target even

meager kernel
#

Its kind of a shitty thing to do tbh
Typo squatting
Like someone mistakenly types a website name wrong, and now they're on an adult Website infested with malware

meager kernel
rancid snow
#

yes, again its a no shit sherlock moment

#

my 80 year old customers asking for Facebook assistance understands this

meager kernel
#

I remember I once fell for a trojan horse website which copied discord
A friend of mine got his account hacked, the attacker sent me a message from my friend's account, and his way of talking genuinely convinced me that he was my friend.
He redirected me to some other discord-type website which required a discord login, I entered my credentials and saw the URL of the website later.
Luckily I noticed it right after entering my credentials and I changed my email and password before anything happened to my account

rancid snow
#

you couldnt torture that info out of me

meager kernel
#

Ehh its not an embarrasing info tbh

#

I fell for a scam, I recognised it right after falling for it and didn't face any damage

#

It was an old account too, I have created like 3 more discord accounts after that which I deleted

dawn frigate
#

sherlock or poirot? sadglas

manic anvil
#

i have question for bug bounty hunters , do you guys use auto scanners like i see that scopes say no auto scanners allowed but by that do they mean just the result or the auto scanner as whole , like you can use it to detect a bug then you go test it yourself as a PoC and submit it?

manic anvil
warped plank
manic anvil
#

sadglas in most videos i see people use burpe scanner and such but i guess will just go manual

warped plank
#

either way best course of action is one where you don't end up behind bars or not allowed to touch a computer 9263zerotwoveryhappy

warped plank
warped plank
muted olive
#

That response can be forged and you get a cracked version of pro

rapid swallow
#

Well hoping soon

#

Bro these badges

#

For academy

#

They need a way to showcase them

rapid swallow
#

And show them off

meager kernel
meager kernel
#

Classic

scenic maple
rapid swallow
#

Life be hard

scenic maple
#

waz but u are now expecting tomorrow so not tomorrow

rapid swallow
#

Sometimes I feel like im way behind cause I cant do a certain box

warped plank
dense turtle
rapid swallow
#

I need to build a CTF team

#

Lol

#

Issue is majority of the time im learning

#

So im always doing retired boxes

scenic maple
#

Good luck

warped plank
scenic maple
#

Well we used to take everyone

#

Too many people nowadays

#

So it went up to some machines / challa from no activity

#

Tbh if you think abt it

#

China is the most populous

#

But i have only met like 3 chinese people in htb

#

Hmm

dense turtle
#

math isnt mathing

#

lmao

manic anvil
scenic maple
#

Just work there

manic anvil
#

pepecoffee what is the requirment to be staff

#

sus i am all ears

scenic maple
#

Apply for a position

#

Pass the interviews

#

Thats it

torn cedar
safe jacinth
#

anyone wanna study while playing game

warped plank
#

What kind of studying involves playing games? sus

safe jacinth
#

all of it

warped plank
#

You mean like studying academy and playing games by doing labs right? RIGHT?

safe jacinth
#

ya

#

its always blue vs red

#

anyone?

warped plank
#

You mean you're looking for someone to play as red team against your blue team? With what labs though? battlegrounds no longer exist and attack vs defense labs aren't really that common.

safe jacinth
#

😅

#

i dint mean that lets game same team as blue and fight the red

manic anvil
warped plank
safe jacinth
#

can i install steam on liunux

warped plank
manic anvil
safe jacinth
#

i answered that too

manic anvil
#

also holy OSINT module is 1000 cube

uneven beacon
safe jacinth
warped plank
# safe jacinth i answered that too

Yes you can install steam on linux...

but what did you mean by you're looking for someone to study while playing game

& it's always blue vs red?

manic anvil
safe jacinth
warped plank
safe jacinth
#

i play for blue

warped plank
# safe jacinth i play for blue

So do sherlocks and CDSA... but if you're looking for a red teamer to study with you're out of luck because you'd be studying the complete opposite things and there isn't exactly a lab where you can defend from their attacks in HTB.

safe jacinth
#

can i play finals on it

warped plank
safe jacinth
#

eac?

warped plank
#

Easy Anti Cheat

safe jacinth
#

how did u study

manic anvil
#

waz 0xW1LD ate the books about cybersecurity

dense turtle
#

vac - valve allow cheating 😂

warped plank
#

bro's jumping around topics and it's getting harder to keep up kek

safe jacinth
#

u game?

warped plank
#

bro jumps from studying to gaming in less than a minute...

scenic maple
#

What can i say tech is unstable waz

safe jacinth
warped plank
dense turtle
#

i just started interpreter , but anyone to hvh cs2? FeelsGoodMan

warped plank
#

-# at least you're still on topic with hvh

safe jacinth
#

😴

dense turtle
#

i mean,. my cooldown already passed .. kek

safe jacinth
#

why dont guys game

dense turtle
#

boxes are our game

safe jacinth
#

but creating a GUI like interface to solve those boxes are way easy

dense turtle
#

i used to play fortnite tbf, but no longer windows user

warped plank
meager kernel
torn cedar
warped plank
torn cedar
safe jacinth
meager kernel
warped plank
safe jacinth
meager kernel
#

If a GUI requires a user to go into the terminal then its not a GUI anymore

warped plank
#

I feel like this convo is essentially one about metasploitGUI vs manual exploitation...

safe jacinth
#

?

#

its about playing game

warped plank
#

What do games have to do with boxes?!?

#

I'm so confused now...

safe jacinth
torn cedar
#

I believe he wants to turn the learning element of hacking into a game where instead of just reading walls of text, you play a game and absorb the information that way.

warped plank
torn cedar
warped plank
#

Well fair enough but you aint gonna get good at hacking by playing a game cos 90% of hacking is learning and you can't have time to make a game out of everything you have to learn

torn cedar
#

True, but now we know what he was trying to say, at least I the assume handshake emoji means correct hahaha

warped plank
#

@safe jacinth best to do boxes on labs and treat it as a puzzle game I guess.

safe jacinth
#

i don't know what to type now

warped plank
#

Probably that puzzles are boring and not filled with dopamine moments like action games...

torn cedar
#

I remember Greyhack being a thing on steam, but I doubt any of that knowledge can truly carry over to real life.

safe jacinth
#

thank you guys

muted olive
#

Chat, I think I found a bug in Rust

manic anvil
muted olive
#

the programming language

#

-# there's a game called rust?

safe jacinth
#

cool

manic anvil
manic anvil
#

like whats considered a bug?

signal mica
#

End me

manic anvil
safe jacinth
#

I just wanted to talk while I learn. It creeps me out to ask my doubts to an AI

muted olive
#

memory safety bugs, logic bugs

#

programming langs are also coded by another lang

manic anvil
safe jacinth
cerulean bloom
#

@lofty marsh cube talks in spotify now

safe jacinth
#

channel?

scenic maple
torn cedar
cerulean bloom
cerulean bloom
#

6:30

torn cedar
#

You're in the future

cerulean bloom
safe jacinth
#

what do them talk about

cerulean bloom
dense turtle
#
    The user requested packaging>=24.0
    pwncat-cs 0.5.4 depends on packaging<21.0 and >=20.9```
ok , changed requirements to packaging>=20.9,<21.0
pip install
```The conflict is caused by:
    The user requested rich==13.7.1
    pwncat-cs 0.5.4 depends on rich<11.0.0 and >=10.4.0```
AAAAAAAAAAAAAAA
frozen zinc
#

Just unistall and install again

#

will be more easier than go dependency after dependency

#

i recommend you to use virtual env with python also

scenic maple
#

use venv 😭

dense turtle
#

i am in venv 😭

#

but installed

mystic harbor
#

Run linux in docker psyduck

dense turtle
#

just needed to setup this rich rich>=10.4.0,<11.0.0

ornate ibex
#

use uv

frozen zinc
#

it will be something else probably after rich

dense turtle
#

i think we fine now, lemme try run it 👀

ornate ibex
# terse dirge I use go btw

I used go only once at work. I wrote code with python and asked cursor to convert it to go and it worked well kek

warped plank
sharp shuttle
#

0xBrath has entered the chat

#

its 0xChat now

dense turtle
dense turtle
ornate ibex
muted olive
muted olive
ornate ibex
muted olive
#

yeah will do

#

been meaning to but keep forgetting

scenic maple
#

rust keeps helping other programming languages and dev ex

muted olive
#

I'm traumatized by rust

#

will never heal

#

and will never forgive

ornate ibex
#

meh

#

had rust programming briefly in uni

muted olive
#

my condolences kek

ornate ibex
#

In secure coding subject iirc

scenic maple
#

sings of a good uni

#

and furries 😩 😩

ornate ibex
#

I guess, we had c as well

muted olive
#

if they taught you rust

ornate ibex
#

they didn't teach rust, they thought us secure coding

#

use after free, double free etc etc shit in c

#

I can't tell now, been ages

austere sinew
#

@sturdy thistle

muted olive
terse dirge
#

@sharp shuttle you should learn kubevirt and VM orchestration in kubernetes

muted olive
#

because if so

#

my view of it just changed

#

slightly

glossy hollow
#

Hi guys

#

I need help please

scenic maple
#

i see

glossy hollow
#

I'm stuck in an academy module where I can't answer all the questions because I can't spawn target IP
Is this a general issue or what could be the fix?

west lynxBOT
spare horizon
lofty marsh
#

FINALLY

#

GAH DAYUM

dawn frigate
lofty marsh
#

IT'S BEEN A DECADE sadglas

spare horizon
#

man we trollin

#

i prefer not to talk about it

odd abyss
#

Hello guys! I'm new here... Hope to get along with you all!

dawn frigate
#

i must delete my messages before i got muted by mods sadglas

lofty marsh
#

Dude fucking finally I listen to cubetalks 💀

#

I've been waiting for 1.5 weeks sadglassadglassadglas

#

I got answered all my question 😭prayge

tidal musk
#

immunefi on top

green kite
carmine fulcrum
#

why I cannot see the firstblood anymore here?

mystic harbor
#

in activity

carmine fulcrum
#

yh but I don't see how much time has taken to complete the chall

silk pasture
#

can i enroll in 2 paths at the same time

zealous charm
green kite
#

no, but you can change between them

zealous charm
#

Rise and grind gents, let’s get this bread

heady sage
#

Dude I spent all day making a challenge

zealous charm
heady sage
#

Yesterday

muted olive
#

@zealous charm 👋

#

any hacking?

heady sage
#

@zealous charm @muted olive yall wanna try your luck at it?

muted olive
#

i've already made around a dozen or so

zealous charm
muted olive
#

basic stuff though

#

I think 1 web challenge, 3 pwn challenges, and a lot of other stuff in crypto and forensics and OSINT etc. Basically every category

#

It was intended to be a beginner CTF so most of it was easy, with the exception of a few

dawn frigate
heady sage
fiery ice
#

Is c++ good for malware development

static bloom
#

yes

void sapphire
#

Anyone got problems spawning targets (shell & payloads if it matters) ? Not working for like 1-2 hours now

zealous charm
#

@muted olive any update on your bugs?

tidal musk
zealous charm
#

Nice, best of luck!

tidal musk
#

one report can change ur life with the rewards they have 😭

zealous charm
#

I’ve only worked on web2 bug bounty but it is always fun to follow the web3 writeups and see the payouts

heady sage
zealous charm
#

Still on my first coffee, my bad

tidal musk
dawn frigate
fiery ice
#

So I should learn c++

dawn frigate
#

btw c++ is good for bypassing antiviruses

cerulean bloom
#

LETS GOOOOOOO

fiery ice
#

Thanks

austere sigil
dawn frigate
heady sage
dawn frigate
#

@fiery ice btw, it's better to learn C before C++

cerulean bloom
# heady sage Without AI?

except for errors that occurred (normally I can figure out what they are, but sometimes, it just doesn't show exactly what happens nor can I debug in that space), yes

zealous charm
heady sage
#

I’m so proud of you

odd abyss
heady sage
#

No bugs yet @zealous charm still upskilling and making my own challenges

heady sage
cerulean bloom
odd abyss
heady sage
#

Yeah everything’s cool, just making Ctf challenges and chilling

odd abyss
#

cool!! that's nice!

heady sage
#

Finally hung my letter from nasa on my wall

odd abyss
heady sage
#

I keep getting private invites on YesWeHack

odd abyss
#

🔥

#

good stuff gurl!

heady sage
#

Preciate it

odd abyss
#

😁 👍

heady sage
#

I’m gonna make a challenge for OSI today

muted olive
# zealous charm <@814024685389217792> any update on your bugs?

On google, microsoft and meta, no. I found a vuln in Python yesterday which they are investigating. Found a vuln in Rust stdlib today, just sent it in :3
Also found a vuln in some random crypto funds transfer app, got closed as duplicate. Found another in the same app and submitted, expecting to hear back in a couple of hours

muted olive
muted olive
#

I haven't hung mine on the wall yet 🤣

#

I should though

muted olive
cerulean bloom
zealous charm
cerulean bloom
#

I saw you pinged me a few days ago

zealous charm
muted olive
muted olive
manic anvil
#

dude it seems like yahoo is the most platform filled with bugs

exotic pendant
zealous charm
#

Yahoo was one of the first big programs, at one point they would pay $3k for every SSRF

exotic pendant
#

Goal is to get a home from bugbounty this year

manic anvil
#

waz the regret that i didnt born earlier to be part of that

muted olive
muted olive
#

ez

zealous charm
zealous charm
meager kernel
#

They're searching for a new IppSec

manic anvil
manic anvil
exotic pendant
#

$2m might get me a 100sq ft closet

#

In Malibu

muted olive
manic anvil
meager kernel
manic anvil
muted olive
#

3.43 million

heady sage
#

Alrighty, Time to read HackerOne reports or bother hades for challenge inspiration

manic anvil
heady sage
exotic pendant
manic anvil
heady sage
muted olive
#

unless they misplaced the decimal point kek

exotic pendant
#

Frosto will get a 500k house in Texas and a custom made pizza oven

#

I’ll be set

#

Plus I’ll have a big back yard with room to grow food for self sustainment

cerulean bloom
#

500K????????

#

I mean

#

you do make thousands and millions from bug bounties lol

#

but

#

wow

manic anvil
muted olive
zealous charm
#

in some states that is the price of a starter-home lol

manic anvil
muted olive
heady sage
#

Frosto needs to do my challenge so I can make improvements to make it harder

muted olive
exotic pendant
exotic pendant
muted olive
muted olive
#

chocolate ice cream

muted olive
exotic pendant
#

Only customer is me

#

But it’s all business expenses

#

Frosto is already set to retire at 45

cerulean bloom
#

cuz I know how much money my parent's make LOL

#

and uhhhhh

manic anvil
muted olive
# cerulean bloom really????

yes... depending on the state
500k will get you a small condo in California but a large ass home in North Carolina

manic anvil
#

a studio ?

muted olive
#

depends on whether its upstate or not

half sedge
#

Beef chezzilla

supple plume
#

Hi chat

manic anvil
#

waz time to hunt bugs with no experience but portswigger labs and a dream

scenic maple
#

man i want to post a political meme so bad

half sedge
scenic maple
#

its so relevant to the discussion

supple plume
manic anvil
scenic maple
#

us citizens feel free to dm me to get the meme

supple plume
#

Dang I have to become a us citizen firstc🥀

manic anvil
scenic maple
#

i mean its for all of us but its very relating to them

zealous charm
scenic maple
signal mica
heady sage
zealous charm
#

plenty of src code review programs out there. Or pick one with an executable in scope and reverse it

heady sage
#

Bug bounty is kind of secondary to that

manic anvil
manic anvil
#

is there linux tools that are AI based so far?

#

like they relay on you for work ?

scenic maple
#

you see in linux you dont really use gui tools

#

you would use cli and pass in and pass out output via piping

#

i only do cybersec for fun my main area is web dev frontend to be specific but the major ai tools will work everywhere

manic anvil
#

i feel dumb lol an AI based tool would need a database or a server to go back too which linux tools dont

scenic maple
#

at the end of the day they just hit a http post anyway

zealous charm
#

It's definitely good to have exposure to them. In the beginning you wont be replaced by AI, but you will be replaced by the workers embracing AI as a tool

heady sage
scenic maple
heady sage
#

Which order should I do the portswigger labs in?

#

@scenic maple @zealous charm

zealous charm
#

Idk I’ve only done like 7 of them, but I think they have paths now?

scenic maple
#

been a long time i should get back and finish some more

heady sage
#

I’m yelling one, two,three, four, five I am the most stubborn hacker Al-ive!

clever goblet
#

Can we expect to have an Android cert from HTB anytime soon?

scenic maple
#

we will have it but how soon we dont know

clever goblet
#

hmmm. So, I believe there is still some content to be added.

zealous charm
heady sage
manic anvil
# scenic maple

guys look we got golam to give us a free bug hunting course

scenic maple
#

had to open source it cause no one buying waz

manic anvil
zealous charm
scenic maple
civic lance
#

Yooo

zealous charm
civic lance
#

Why this chat still talking about bug bounty😭

manic anvil
scenic maple
#

negative rep is peak lmfao kek

manic anvil
scenic maple
#

it takes true dedication to get there

zealous charm
civic lance
#

The domino effect is real, there was a convo about bug bounty at like 1-2AM

#

And it trickled down all the way to 7AM

#

Crazy😭

manic anvil
#

waz i can change the subject

zealous charm
#

Any (non-bug bounty) hacking today?

manic anvil
#

so whats the chances that one of kali tools have a backdoor waz

muted olive
#

@zealous charm you should try out the 1password CTF

zealous charm
#

Netexex just patched a bug in their tool, so probably very likely

scenic maple
#

npm do be getting most backlash

muted olive
#

everything is fully hardened and kept up to date

#

so only way is by finding a 0 day in the depedencies

#

bounty is 1 million dollars

manic anvil
scenic maple
#

which one is it

muted olive
scenic maple
#

owww its not a ctf

#

lol

muted olive
#

also 1st one

#

yeah its basically bug bounty

#

but not prod systems

#

no user data

zealous charm
idle birch
#

or its just ctf

muted olive
idle birch
#

oh bro

#

i see

#

i thought u were trolling lmao

muted olive
#

nah, they've had it for a while

scenic maple
manic anvil
scenic maple
#

some ctfs do be like that

scenic maple
#

in vdp you dont get paid for submitting bugs

#

but you do get recognition

muted olive
#

tfw when you find a bug in claude all models but dont get paid waz

manic anvil
scenic maple
muted olive
#

have to do through anthropic vdp

manic anvil
#

like that guy who leaked all of patreon databse after they refused to pay anything for the bug he found

muted olive
#

reward: $0 🔥

#

I mean if you're hacking foundational internet software you're likely gonna get nothing

manic anvil
#

man pentesters are funny , its like pay me or i do evil

scenic maple
#

no most of them have morals and ethics

meager kernel
#

Thats me

scenic maple
#

thats also why most of them are poor

#

but it is what it is

meager kernel
#

Pay me or I do crime

#

Jk

#

Dont ban me Golam

muted olive
#

If VDPs give me something cool other than money, I would do it

#

like NASA

muted olive
#

@scenic maple when you gonna hack NASA? waz

manic anvil
meager kernel
#

@scenic maple is running nmap on someone's website illegal?

manic anvil
zealous charm
muted olive
scenic maple
muted olive
#

you get a tshirt

meager kernel
#

Golam ignored me

muted olive
#

I got Cloudflare swag but that was because I won a giveaway lol

zealous charm
manic anvil
muted olive
meager kernel
#

Genuinely

manic anvil
meager kernel
#

Is running enumeration tools on someone's website illegal??

muted olive
scenic maple
#

no way to tell for sure

meager kernel
manic anvil
muted olive
#

It says on it "I hacked the dutch government and all I got was this lousy tshirt"

meager kernel
muted olive
meager kernel
#

Haven't been arrested yet

muted olive
#

*unless you have permission

manic anvil
muted olive
#

or unless they have a bug bounty with safe harbor which would exempt you from most anti hacking laws which would otherwise apply

muted olive
manic anvil
zealous charm
#

did you see curl is going back to H1 lol

muted olive
muted olive
manic anvil
#

in the report write "weak CEO body build get gud"

muted olive
#

because of AI slop?

zealous charm
#

Yeah they closed due to AI slop, made a big stink about it online and all the "infosec influencers" talked about it. now back to H1

muted olive
muted olive
#

it was genuinely better without it kek

manic anvil