#general

1 messages Ā· Page 522 of 1

sharp shuttle
#

its become ubiquitous, and thats why software engineering is dead

clear anvil
#

Ohh too much caffeine

molten bobcat
#

Because that's a pretty immediately in demand skillset?

muted olive
#

Thats concerning kek

civic lance
#

Broooo I hate seeing those tweets saying AI is writing 90% of code

#

Like šŸ’€

molten bobcat
#

Guess 90% of code fucking sucks lol

clear anvil
#

Is there anyone still down to collaborate or is it too late to ask..

rancid snow
#

if you include ai-assistance and shitty code its correct

molten bobcat
#

Shamelessly stolen

rancid snow
#

yw

sharp shuttle
#

lolol

#

i love that

civic lance
#

$2509?!!!

sharp shuttle
#

i hope it happens more often

molten bobcat
#

Ai is gonna take your jobs tho

gaunt gale
#

Hi guys

sharp shuttle
#

Hello robin

molten bobcat
#

Not if you're like.. any sort of bar above completely worthless sure..

muted olive
#

TNG, Season 3, Episode 16, "The Offspring"
You send a star trek TNG gif, chances are I can identify it kek

rancid snow
#

look Im dead serious when I say every vibe coded application thats more than a toy/script Ive examined Ive found vulns in

civic lance
azure wasp
#

AI is bad

molten bobcat
#

I hope it all burns to the god damn ground and people are forced back into swords and shields

rancid snow
#

AI is tool, users are bad

civic lance
#

One more LLM update

dense turtle
#

hoo lee sheet

rancid snow
#

and that includes(especially) ai bros

gaunt gale
#

Is it bad to be depressed over being sick? I’m mad at myself because its very difficult to get anything done today. My back aches I have throat issues and a lot of mucus tho I took something to suppress that and it works mostly.

molten bobcat
#

I wish them all a very lose all your money

molten bobcat
civic lance
rancid snow
#

im convinced that proper way to utilize AI successfully involves a healthy amount of skepticism

#

treat it like demon summoning

molten bobcat
dense turtle
#

i just discovered that my mysql sintaxes dont work in sqlite šŸ’€ NotLikeThis

rancid snow
#

you perform a ritual to summon forth an entity to perform tasks or exchange knowledge, but must be done with care because itll slip in little bits here and there to fuck with you

muted olive
molten bobcat
#

It's hardly a force multiplier for me

rancid snow
molten bobcat
#

I am burdened every moment I have to waste fact checking it

muted olive
#

It speeds up a lot of stuff for me but is also a huge pain to deal with it

#

Trade-off I guess

molten bobcat
#

I just don't bother

muted olive
#

And yeah fact checking takes up time

rancid snow
#

Ive found great usage with it speeding up reverse engineering segments for me

muted olive
#

Plus whenever its logic is fucked, or when it loses context

rancid snow
#

with the caveat that I know enough on my own to steer it in the direction I want

molten bobcat
#

People have told me constantly that they're waiting for my job to get replaced by ai but holy shit trusting my role to AI would be devastatingly stupid

muted olive
#

And I believe people who vibe code lose their model's context frequently and it forgets why it coded something a certain way, and you get spaghetti in the end šŸ˜‚

molten bobcat
#

I call people to tell them they have to arrest an employee bro

civic lance
#

like asking questions about why this piece of code was used

rancid snow
#

for programming specifically, AI is best for templating and short snippets

civic lance
#

Or explaining a piece of code

muted olive
#

for RE specifically

molten bobcat
#

I raised a no action required case for Proton on Linux Mint today lmao

molten bobcat
#

No

#

Im a security analyst

civic lance
#

Oooo

#

Nice

rancid snow
# muted olive for RE specifically

giving it snippets to explain to get a rough overview of whats going on. Helps for quickly deciding if its something I want to spend more time on or skip over

molten bobcat
#

I'm a tier 2 shooting for a promotion this summer

civic lance
#

Tier 3

molten bobcat
#

Ye

rancid snow
#

the sort of thing where if it gets a few details wrong I dont care

#

because ill be handling the details myself if it ends up important

muted olive
#

Not figured out how yet, something like OpenClaw could I'm sure but I'm not touching that shit ever lmao

rancid snow
#

theres a ghidra plugin but Ive not played with it because AI integrations give me the ick

#

if I did Id probably spin up a dedicated VM just for that

dusky smelt
#

hello yall

muted olive
#

I'd want to hook up specific models too

sharp shuttle
#

ghdira, ida, and binja all have api's...

#

what?

muted olive
dusky smelt
#

I just wanted to ask if there's any specific place where the modules for CJCA or some other role path is stored in which I can automatically start doing or I have to find them 1 by one or however it goes

muted olive
#

I did not know that

sharp shuttle
#

dude how do you think plugins work

rancid snow
#

Ive seen it for ghidra, Ive not looked for ida or binja for AI integrations specifically. Id be shocked if they didnt exist though

muted olive
#

I mean I've never touched plugins in IDA so I dont know

sharp shuttle
#

You plug in a python middleman

#

its that simple

rancid snow
#

yeah pretty much

#

I think my concern for AI integration for that would be having the AI attempt to do TOO much and it getting lost in the sauce

#

I like my current approach

muted olive
#

So, apparently you get access to IDAPython with a premium plan, whereas Ghidra and Radare2 have it on their free plans

lime trout
sharp shuttle
#

oh they paywalled it

#

jesus

#

IDA is scummy

muted olive
#

they paywall everything in IDA

rancid snow
#

yeah theres a reason I don't use IDA

muted olive
#

but its a good product so... still using the free plan for now

sharp shuttle
#

I think binja is better at this point

muted olive
#

they dont allow you to jump to global xrefs and its annoying as fuck kek

#

you need premium for that

sharp shuttle
#

the debugger is cool i guess but binja is as powerful now

rancid snow
#

if I was to pay for a dissembler/decompiler rn itd be binja

#

but im brokie

molten bobcat
#

That shows all the paths

muted olive
rancid snow
dusky smelt
rancid snow
#

Im still in boring repair and data recovery atm

muted olive
#

You dont have a training budget for certs and stuff?

#

Oh

rancid snow
#

no lmao

#

Ive self paid for cpts and oscp

#

even if I never got a job in the field I aint letting that stop me from progressing

#

ill keep learning till the stars align and then some

muted olive
#

well youve already got the necessary qualifications so start advertising yourself more atp

#

not that im speaking from xp but ive seen it with others

rancid snow
#

yeah Ive been getting the occasional interview

#

im a bad interview though apparently, need to work on that

random aurora
#

docker for web

#

right ?

rancid snow
#

I have to do a video recorded questionnaire for an application process tonight though

#

I also have a project Ive been avoiding to collect some CVEs because the idea felt 'too easy' and thats been dummy dumbo head thinking on my behalf

rancid snow
#

yeah its a no shit sherlock idea, but tbf I have been working and learning on other stuff as well since Ive had the idea

#

so Ive not been wasting my time either

#

Ive just been chasing sexy bugs instead of settling for unsexy bugs

muted olive
#

which reminds me of a few more CVEs I have to submit which i've been putting off. MITRE sucks

muted olive
rancid snow
#

unlikely for this project specifically, but we shall see

#

but Ive seen someone thats been cashing in on a worse version of my idea sooo

muted olive
#

is it a bug bounty?

rancid snow
#

sorta

#

but not web based but kinda

muted olive
#

contracted?

civic lance
#

Why da hell I see Ubuntu announcing their plans for age verification

#

This shit is sooo stupidšŸ’€

rancid snow
muted olive
#

nice

rancid snow
#

and my idea involves automation

muted olive
#

I tried bug bounty recently but apparently people are using claude to cherry pick the surface level bugs LOL

#

got like 2 duplicates

#

then im like fuck it back to hacking OSS projects

rancid snow
muted olive
#

funny thing is, for those specific dupes I got, I found someone on r/bugbounty posting "look guys I found bugs on this shit with claude"

civic lance
muted olive
#

they didnt get paid for it anyway because that company sucks, apparently kek

muted olive
#

its google's scanner

muted olive
rancid snow
#

yup, Ive been looking at projects where oss-fuzz has failed to work

civic lance
muted olive
#

I recently found a bug on one of Google's flagship OSS projects and it was such a beautiful logic bug. No fuzzer or AI on the earth can pick up on it lol

#

Only humans could

rancid snow
#

nice

#

gtg cya

muted olive
#

And I pointed that specific code at Claude, and it couldnt identify the bug

civic lance
#

Now it’s in Claude database

civic lance
muted olive
clear anvil
#

Should I re-post what I said about the C2 project?

muted olive
#

I mean

#

it still cant pick up on it is my bet

civic lance
#

Sure……

muted olive
#

You need to trace the entire flow across like 20 files, and it just gets confused and going in circles

#

this is what I've seen so far

civic lance
#

I want the AI bubble to crash

#

But it probably won’t……

#

That sounds too good to be true

muted olive
#

it will

#

at some point

civic lance
#

But when it crashes

#

What happens…

#

Discord having network issues I see

muted olive
#

people start using AI like normal

civic lance
#

…..

#

😭😭

muted olive
civic lance
#

ā€œpeople start using AI like normalā€

muted olive
#

that was bad wording, my bad kek

#

its like a calculator

#

feels miraculous when its invented but over time becomes an unextraordinary everyday tool

civic lance
#

Instead of scrolling on Google for hours

#

Like what’s the difference between googling for a code snippet for your specific issue Vs asking AI for it?

muted olive
#

Nothing

#

asking AI is effectively equivalent to googling

#

more personalized responses etc

#

but you still got to do the work yourself

civic lance
#

AI legit surf the web for you

#

So it’s a good tool for that

#

It’s like hitting Ctrl + F

#

But for the entire internet

muted olive
#

like my calculator analogy. if you want to calc the sum of 20 numbers, you COULD do it manually or you could use a calculator depending on how fast you need the answer

#

same for AI

civic lance
#

I agree

muted olive
#

and tbf I like AI search mode a lot so far

civic lance
#

On your browser?

muted olive
#

yeah

civic lance
#

Eww

muted olive
#

I mean the "AI mode" in google

#

I hate AI-based browsers

civic lance
#

Cuz u still gotta think

#

U just lose the skill to do mental math as quickly tho

#

AI has no restraints on it

#

Only the safeguards the companies put on it

muted olive
#

im saying that because when you're vibe coding anything, its almost basically guaranteed that your app wont work unless youre using it the smart way

civic lance
#

I see

muted olive
#

so if you just say "okay build this app and dont make mistakes", it will start building it, then fixing errors, then losing context, then wondering why it implemented something in a certain way, then change it which introduces another bug, repeat

#

I pity everyone trying to build complex apps just by asking AI

civic lance
#

Yeah when I build something, I start building. When I get stuck along the way I turn to Google

#

Sometimes I feel like I’m cheating myself when I use AI, cuz I’m like ppl back in the day didn’t had it

#

And they still built amazing things😭

muted olive
civic lance
#

They just had Documentation + Google

muted olive
#

Asking AI to do all the work for you is the wrong way

#

asking it to debug something along the way is equivalent to posting a question on stack overflow or googling it, imo

civic lance
#

Mmmm

#

You should also ask it to explain to you

#

When debugging

#

I be asking the chatbot questions

#

Until I understand it

muted olive
#

idk, I think AI did significantly lower the bar for coding but now that its here and you cant change the fact that its here, you adapt yourself to it and become way better while people with no understanding who use it as a crutch get swept away and replaced

civic lance
#

It did lower the bar

#

It allowed ppl to cut corners

muted olive
#

increased job security for security people kek

civic lance
#

Nah they will also flood security roles

#

I heard kali Linux integrated AI into their VM

muted olive
#

I encourage people to vibe code apps with chinese models so I get more bugs to find

muted olive
civic lance
#

Nah I heard someone say, now they can just write plain English

#

And they’ll be effective

#

Just as effective

muted olive
#

correct, and wrong

#

writing plain english correct

#

being just as effective, wrong

#

unless you're building some toy scripts

#

a great example for this scenario is daniel stenberg

#

(the hackerone triager)

#

I love reading the reports he receives from AI skids kek

civic lance
#

Who is that

muted olive
#

He has like... what, 34 years of experience in coding

civic lance
#

Reports from AI skids?

muted olive
#

he absolutely destroys AI in it

muted olive
civic lance
#

Oh wow

muted olive
#

runs the curl bug bounty, or used to

civic lance
#

I use curl

muted olive
#

and yeah, gets AI skid reports all the time

#

like all the fucking time

#

and its hilarious to read

#

he calls out each of them and makes the reports public

civic lance
#

It’s kinda annoying now, cuz ppl that actually wanna contribute to OS projects

#

Won’t be able to soon

#

Cuz everything is just getting flooded with AI reports

#

Drive by AI reports basically

muted olive
#

You just submit genuine reports

#

AI reports are insta closed

maiden anvil
#

I remember growing up and watching Terminator

#

thinking "this is it, this is the greatest action movie ever made"

#

never expected it to become real life haaaha

#

hopefully we can course correct and AI just makes fun memes

azure wasp
#

HM

ornate ibex
#

Morning

wind fractal
#

morning

civic lance
#

we not correcting course anytime soon😭

#

Imagine a robot deciding your fatešŸ’€

#

Becuz of a foolish bug

azure wasp
#

Morning

frail turtle
#

da california age verification trash

graceful pendant
sharp shuttle
#

You guys wanna see something cool

#

chekc this out

wind fractal
graceful pendant
#

those of you have done oscp, if oscp machines were a htb box, what difficulty would it be?

graceful pendant
sharp shuttle
#

yes.

#

i am not messing with you

wind fractal
#

do i have to purchase htb and lets defend separately?

graceful pendant
#

and oscp+ and oswe?

#

same shit?

sharp shuttle
#

oscp

#

oswe is even easier

graceful pendant
#

oswe is AD right?

sharp shuttle
#

no, its web

graceful pendant
#

whats the AD one

sharp shuttle
#

osed

#

oscp has AD too

graceful pendant
#

osee is hard?

sharp shuttle
#

osee is the hardest cert they offer

maiden anvil
#

I have brought peace, freedom, justice, and security
to MY new wasteland! evil_patrick

sage epoch
#

Sam Altman expects people to believe his ā€œtrust me broā€ statements about how openai wont be used to do the exact things anthropic got rejected for not wanting to do

sharp shuttle
#

you guys should stop caring about things out of your control

#

if you arent going to be a martyr, keep playing fortnite and chill

rancid snow
#

the harder oscp boxes cap out at medium

#

but most would qualify as easy for sure

#

but like low end of medium

#

@graceful pendant

uneven turtle
#

Sayian walk X Subaru climbing stairs

graceful pendant
#

@rancid snow its 24 hours for how many boxs?

sharp shuttle
#

bro go read jesus christ

rancid snow
#

idr exactly, its in the exam format info

graceful pendant
meager kernel
rancid snow
#

I hate offsec for many reasons but they legit have the most indepth answers on anything exam related you could have in regards to the format

sharp shuttle
graceful pendant
#

I dont want any certs lol...

sharp shuttle
#

you are the one asking 20 questions..

graceful pendant
#

where does it say questions arent allowed

#

i must have missed that

#

dont make me unfriend you on linkedin

meager kernel
graceful pendant
rancid snow
#

this is a weirdly fragile ego

graceful pendant
#

im kidding

rancid snow
#

like theres normal fragile egos and then theres whatever this is

#

me too

graceful pendant
#

its called joking

#

okay good

#

now we are all on the same page, so how many boxes is it in 24 hours?

rancid snow
graceful pendant
#

but its okay I already googled it

#

seems chill beans

rancid snow
#

yeah oscp doesnt exist anymore

#

cause offsec sucks ass

graceful pendant
#

huh wat

#

realy?

#

TIL

#

I thought the oscp+ was like some harder cert

#

I dont get it (╯°▔°)╯︵ ┻━┻

#

oh they time gated it?

#

thats definitely not just for extra money

rancid snow
#

yeah theyre ending lifetime cert and marketing it as new oscp+

graceful pendant
#

I mean the landscape does change but... thats obvious cash grab

rancid snow
#

so you basically have to be grandfathered in or enjoy paying $2k~ every however long the cert lasts

graceful pendant
#

3 years it says

#

thats funny

#

best pentesters I know have like 0 certs lmao

rancid snow
#

certs are a poor reflection of skill

#

a cert might prove some competency in some area but a lack of cert doesnt mean anything at all

graceful pendant
#

I think all of its funny

#

I talked to a guy with a MASTERS in cybersec

#

who didnt know what SSH was

#

?!??!?!?!!?!?!?!!?!?!?

#

wtf they teaching you over there brody

civic lance
#

OpenAI swooped in for that defense contract 😭

graceful pendant
#

Im sure the military has some deep underground LLMS that are completely untethererd and fucking insane

civic lance
#

AI being in the decision making for kill chains?

#

That what they wanted to use anthropic AI for

graceful pendant
civic lance
graceful pendant
#

you have un jammable ordinance that uses onboard compute to finish its journey to target

#

with AI/mesh systems to calculate Angle of traverse and shit

graceful pendant
#

cus yeah since a while tbh

civic lance
#

AI's

graceful pendant
#

ye thats old news

civic lance
#

If that was the case then, why are defense contracts for AI is used.

#

needed*

graceful pendant
#

cus the private sector LLMs are quite advanced right now

#

and have access to compute that rivals even government capacities

civic lance
#

ooo

#

so antrhopic standing on its morals was useless?

#

Like just improving the capacity for its job, thats been around.

#

?

graceful pendant
#

also idk if you know but after claude was "banned" for use by the DoD and state

#

it was immediately used after by them to carry out strikes in iran

civic lance
#

šŸ’€

#

........

#

Can claude sue them?

west venture
#

Shut it

graceful pendant
cerulean bloom
civic lance
west venture
civic lance
#

šŸ’€

#

That removes the entire file system

west venture
#

It does not

civic lance
#

They should've just stayed with the defense contract

#

Either they pay you and use it, or they use it.

graceful pendant
#

yeah the whole thing is stupid I guess IDK

rancid snow
#

theres drones now with onboard systems specifically for autonomous AI models

civic lance
#

mannn

#

how tf yall know bout all this military tech

#

😭

rancid snow
#

It was at brath's bsides talk last weekend

civic lance
#

who tf is that

rancid snow
#

Brathadair, hes in this server

#

his specialty is drones

civic lance
#

@sharp shuttle

#

Oh wow

#

I think I've seen his Setup before

rancid snow
#

he did a talk and a workshop about drones. It was rad

cerulean bloom
rancid snow
#

one of the talking points was about autonomous drones

#

iirc hes getting his hands on one soon to take apart

civic lance
#

What is braths credibility?

cerulean bloom
civic lance
#

or that just his hobby

cerulean bloom
rancid snow
civic lance
#

under*

#

šŸ’€

rancid snow
cerulean bloom
rancid snow
#

whenever bsides seattle starts uploading things

civic lance
#

so yeah

#

this AI shit isnt going anywhere

#

Drones controlled AI

#

šŸ’€

#

Shiiii

#

When we getting a real life iron man suit

rancid snow
#

theres a couple engineer youtubers working on it

civic lance
#

LAMEEEEEEEEE

muted olive
#

am currently trying to get a bsides talk accepted

west venture
civic lance
#

Idk if I can say the word

#

But it has something to do with splitting atoms, I think.

west venture
#

You mean nuclear war?

#

Nuclear bomba

civic lance
#

yeah pretty much

west venture
#

Nuclear

civic lance
#

Mhm

west venture
#

You can say that

#

Also mods aren't here so you can say anything related

civic lance
#

Nah they are lurkers

#

and will read chat history

#

but ion think its that serious

west venture
#

@civic lance

civic lance
#

yo

#

checking my roles?

west venture
#

But why

civic lance
#

?

west venture
#

Yes osmondeus

civic lance
#

your random

west venture
#

But why

civic lance
west venture
#

No

civic lance
#

damn

west venture
#

I only speak a little English

civic lance
#

STOP BEING USELESSSSSSSSSSSSSSS

cyan charm
#

hey there, why is the vpn so shit today😭

#

at first it connects, rdp works

#

then after 10 seconds rdp closes, and then the vpn stops working

#

have changed vpn 3 times already 😭

terse dirge
terse dirge
#

Tcp tends to work better in my experience

cyan charm
#

i think udp is the default recommended by htb so udp

#

ok i'll try tcp once

west venture
west venture
#

Also why would you ever use that?

#

Who invented it?

#

Why is there so many of it

terse dirge
terse dirge
west venture
#

YouTube also uses it

#

Because apparently dropping a few packets is better than ensuring absolute data integrity

#

Which is just not true

cyan charm
#

nothing works 😭

#

maybe its a way of telling me to chill out today

silver forge
cyan charm
#

changed vpn to tcp, then to udp, then changed regions to us regular 5 and 6

silver forge
cyan charm
#

oh it worked once, and then it stopped working again

devout sail
#

just

cyan charm
#

like when in windows, it asks i i want to make my device visible(recommended in home device, not in public wifi) or smth like that. and then i click no, then everything stops working

west venture
sick gate
west venture
#

I am

sick gate
#

Why would you prefer a tcp vpn

west venture
#

Because of Zelda dark souls

sick gate
#

Interesting

west venture
sick gate
#

It's all good man just keep on with those paint fumes

devout sail
#

udp will give u random issues

sick gate
rose onyx
devout sail
#

hmmm, many people get such issues

#

and after recommending TCP to them, thye just vanish

#

so it must be working

west venture
#

In reality, it's only charging

sick gate
#

Probably because they have a strict firewall or other connection issues

frigid mountain
#

šŸ˜„

sick gate
#

Yeah

#

Wanna avoid tcp meltdown

devout sail
#

hmm haha wanna avoind UDP mood swings
what do u mean by tcp meltdown?

#

now i know the UDP works tho xD

rose onyx
devout sail
#

i quit UDP cuz i remember not being able to load sites or do ssh

#

and TCP just worked

cyan charm
#

equally

sick gate
#

Google can probably explain tcp meltdown better than I can but it's an issue with tcp in tcp tunnelling

devout sail
#

i cant remember if i was at work or at home

devout sail
#

drive to nearby HTB DC

cyan charm
#

ya, all i need is a plane ticket

devout sail
#

walk

cyan charm
#

thats a good idea to set a world record tbh

devout sail
#

nah nowadays its hard to set world record

#

someone already did shit

#

or its considered too dangerous to be recorded or something

tawdry sorrel
muted olive
#

Thats not why its used at all kek

#

UDP is used for things like livestreaming, where you NEED to be receiving packets in real time every single second

#

So if you received ALL the packets like TCP, it would be slow as fuck + you'd be lagging minutes behind and a lot more freezing/buffering

#

so with UDP you just receive whatever packets you can and leave the ones you cant

#

Thats why livestreams break or pixellate in the middle if you have a bad connection

#

em dash detected, AI response mode powering up

#

yes, I saw it the first time

#

try asking bugcrowd to mediate. open a support ticket

warped plank
#

Bro you dont gotta re-send the message, waz

mellow fractal
#

sorry ...

rustic carbon
static pasture
#

hi paint im bird

ornate ibex
ornate ibex
static pasture
ornate ibex
ornate ibex
#

Yes. It is a CIA program.

cloud osprey
#

i wish i was a CIA program so they would funnel billions of dollars into my shenanigans

tulip heron
#

damn

cerulean bloom
tulip heron
#

hi paint, i'm soldier

cerulean bloom
sturdy thistle
cerulean bloom
sturdy thistle
#

this drone was uncovered

ornate ibex
pulsar basin
#

hey guys. offsec now also uses CPE points for OSCP+ exam to keep. can anybody tell me if and how I can submit HTB boxes/courses like I can for ISC2?

ornate ibex
#

Just add your ISC2 ID in the HTB account and rest the platform will take care

austere sigil
cerulean bloom
pulsar basin
ornate ibex
#

No, we only support ISC2 atm

pulsar basin
# ornate ibex No, we only support ISC2 atm

ok. do you know if HTB boxes are accepted by offsec? somehow I cannot find any information about this. on offsec website they say I am eligible for CPE for online activities / webinars / presentations etc but no real example

ornate ibex
sturdy thistle
#

how about ask their support?

#

oh lol

pulsar basin
ornate ibex
supple plume
muted olive
ornate ibex
#

which one of the many eagles?

tulip heron
#

the one with the cameras

muted olive
#

this one

ornate ibex
muted olive
terse dirge
#

did a complete rework of the color palette, too much purple and pink in the old one

ornate ibex
cloud osprey
#

i dont have a YT

naive cosmos
#

does anyone know what time HTB support start work

sturdy thistle
#

i think they already sstarted

naive cosmos
#

whats the SLA for website support responses?

sturdy thistle
#

what is your request?

naive cosmos
#

i jus put smth in a while ago about prolab machine being down

muted olive
sturdy thistle
#

they should reply soon

naive cosmos
#

thanks

sturdy thistle
#

maybe a bunch of tickets idk

scenic maple
#

Them mosquitos be big

frozen zinc
#

Hey thats interesting, I'm also doing a C2 so I cant really commit to your project but Im open to talk about ideas. Im curious, you said you are using python. I only using python on mine to generate the shellcode with a script. Of course you know python needs a interpreter right? So Im curious about how do you face issues like multi threading or memory manipulation...

Also the syscalls arent native which is a mandatory in order to properly allocate memory and so. Also the fingerprint is quite obvious as you just need monitor Ctypes, subprocess and os.system() which is pretty basic.

has you consider this challenges?

muted olive
scenic maple
#

I stole from online sadge_business

#

One day tho

muted olive
#

get cat

scenic maple
#

Homeless people just get jouse typa energy

scenic maple
#

😩

mystic harbor
sturdy thistle
mystic harbor
sturdy thistle
#

oh u stole pic

scenic maple
sturdy thistle
#

i would say the same

upbeat tangle
#

Whats up HTB

mystic harbor
#

WhatsApp HTB

sturdy thistle
#

working

scenic maple
#

Altho we can tell based on the knuckle tatoo

sturdy thistle
#

that says 1337?

scenic maple
#

Ye

sturdy thistle
#

based

scenic maple
#

Very leet

sturdy thistle
#

yeah

#

awesome guy

#

i've heard

upbeat tangle
#

Im getting inspired to make that tatoo

sturdy thistle
#

the 1337?

mystic harbor
upbeat tangle
sturdy thistle
#

this year i will refresh the tattoo

mystic harbor
#

@austere sinew

sturdy thistle
#

@austere sinew

#

time for a new tea

#

my damn throat šŸ™

mystic harbor
#

Spill the tea here..

muted olive
#

@austere sinew

supple plume
#

@mystic harbor ghost ping is for cowards

#

A bit better but you still a goofy

austere sigil
#

@sturdy thistle please sir

upbeat tangle
sturdy thistle
#

so yeah, i now own a dji neo

upbeat tangle
#

You need to make the most legendary pentest report ever in your life for that job @supple plume

supple plume
austere sigil
mystic harbor
sturdy thistle
supple plume
supple plume
upbeat tangle
sturdy thistle
#

but you got it?

austere sigil
sturdy thistle
#

lol

mystic harbor
sturdy thistle
#

one day i might own a FPV drone

supple plume
austere sigil
sturdy thistle
#

but the goggles are so expensive

supple plume
#

@mystic harbor spray

#

Pichay

#

Vinay

upbeat tangle
supple plume
mystic harbor
#

Wrong direction

supple plume
supple plume
#

Oh nvm

#

Sudo does not affect >>

austere sinew
#

@mystic harbor @sturdy thistle @muted olive

supple plume
#

I have a function to do it in 1 command

supple plume
austere sinew
austere sinew
supple plume
#

Too bad there is not a gif like unwelcome to egypt 🐫 🐪

austere sinew
#

mb bro 😭

sturdy thistle
#

thanks

#

the most thing that sucked is that i started with gym again and boom sick

mystic harbor
supple plume
sturdy thistle
#

i have to

#

need to loose the 8 kilos at least again

supple plume
#

To be 100

sturdy thistle
#

so 130?

supple plume
#

Yep...

sturdy thistle
#

i started there too and lost 20

austere sinew
#

the easiest thing yall could do is replace your big meals with a salad

#

vegetablemaxxin

#

that n soup

muted olive
#

never šŸ”„

supple plume
austere sinew
#

smfh

muted olive
#

Did yesterday though

upbeat tangle
sturdy thistle
#

proteins important

supple plume
sturdy thistle
#

and also calories

#

but i used to got 6 times a week to gym last year

upbeat tangle
scenic maple
#

ah crap wrong reply

austere sinew
#

Wdym - powered by gemini

sturdy thistle
#

DN - powered by gemini

scenic maple
#

they be catching strays everywhere tho

supple plume
#

Macroslop

austere sinew
#

m1c705l0p - powered by gemini

sturdy thistle
#

m1c705l0p - powered by DN

#

ok back to work

muted olive
#

microslop - powered by gemini

#

loud and proud

muted olive
warped plank
#

Check out my coffee before my shift today

muted olive
#

I knew you were gonna send a coffee pic before you sent it

warped plank
runic forge
#

hello

frozen zinc
terse dirge
warped plank
#

What's even funnier is sometimes in the cafe my manager would have to leave to but stuff and that's when everyone comes at the same time.

west venture
#

@austere sinew I will safely ignore you

frozen zinc
west venture
sturdy thistle
#

looks good

fierce vale
sturdy thistle
#

someone has a z.ai sub?

terse dirge
warped plank
#

By the end of the night we served 12 people, might not seem like a lot but Im the only one at the front and only 1 chef at the back.

west venture
frozen zinc
warped plank
frozen zinc
#

and you see the customers looking at you like they can hear the bell too lol

sturdy thistle
#

i just had tea for now

warped plank
austere sigil
#

noted.

warped plank
#

Legally I can't kick people out but damn take a hint...

austere sigil
#

they do not care

warped plank
#

Honestly my Cafe shift made my day but then my restaurant shift ruined it 9263zerotwoveryhappy

austere sigil
#

usually the ones that feel like they are being treated as crap

sturdy thistle
#

just spil "accidentally" hot water over them

#

they leave on their own

warped plank
austere sigil
#

people are people

#

and slipknot said it best šŸ˜‰

warped plank
#

The nicer guests were those that walked in without reservations.

sturdy thistle
#

people = shit

#

i like that song

austere sigil
frozen zinc
warped plank
#

Done venting, now story time of the regular who made my day.

I'm the sub-barista at the cafe so I only make coffees when the barista's out or busy. But one of the regulars came in as I was leaving and said "I'm glad you're still here, I like the way you make coffees"

Made my whole day for sure.

sturdy thistle
#

nice

austere sigil
#

Small things usually have great impact

sturdy thistle
#

that's what @austere sinew said

frozen zinc
austere sigil
#

@sturdy thistle get back to work sir

sturdy thistle
#

don't force me

austere sigil
#

I need to work on my powerpoint presentation on why we need to validate threat and exposure to architects and ISOs

#

it was nice knowing you all

sturdy thistle
#

GO TO WORK

#

stop yapping

austere sigil
sturdy thistle
#

uno reverse

austere sigil
#

🤣

warped plank
#

Both y'all go to work

austere sigil
#

woah

scenic maple
#

he said dont force him
he didnt say not to stop him from forcing you waz

scenic maple
austere sigil
#

stop using truth against me, golam

sturdy thistle
#

friendly reminder

#

so go to work

warped plank
warped plank
#

I dont always double up shifts but when I do, my manager owes me kek

scenic maple
#

which one

warped plank
heady sage
scenic maple
#

i have no idea

heady sage
scenic maple
#

u mean grok?

austere sigil
#

Got deserialization at work blaze

#

yay I guess

heady sage
#

You know what I meant

scenic maple
#

no waz

warped plank
scenic maple
#

like a wise man

sturdy thistle
narrow mirage
#

yooo sister and brother how are youss

zealous charm
austere sigil
#

it's homebrewer!

narrow mirage
#

guys how can i activate gif

austere sigil
#

you need to rank up to hacker on the platform

sturdy thistle
#

monthly subscription kek

austere sigil
#

you can pay mickhat with pickles, onions, and mustard

sturdy thistle
#

coffee beans

narrow mirage
#

now im learing linux he write basic but its long

austere sigil
#

no, pickles, onions, and mustard

warped plank
austere sigil
sturdy thistle
#

bro

#

go to work

austere sigil
#

🤣

sturdy thistle
#

i put pickles and onion and mustard in your closets

narrow mirage
#

Who fasts

austere sigil
#

thanks mick

ornate ibex
#

šŸ˜›

sturdy thistle
#

Lunch

zealous charm
#

it is wednesday my dudes

scenic maple
#

whoever made this is really smart
prolly saved millions in storage costs

gray wraith
#

Gm

heady sage
scenic maple
#

just do it

heady sage
#

:T

scenic maple
#

skill issue

#

šŸ˜”

heady sage
scenic maple
frozen zinc
#

muahahaaha

river jasper
#

anyone know what’s up with localhost.run?
can’t seem to be able to connect through ssh and the website is down

scenic maple
#

maybe its offline

#

use something else ig

heady sage
scenic maple
dawn aspen
#

Hey, may I ask why you’d prefer taking notes in obsidian? šŸ™‚

We are just curious on what the advantages there are and how we could improve note taking in SysReptor.

Feedback is much appreciated šŸ™ŒšŸ˜Š

green kite
#

(I promise I come in peace)

zealous charm
zealous charm
native plume
#

Ship more bugs to production šŸ—£ļøšŸ“¢šŸšØ

scenic maple
#

šŸ—£ļø šŸ”„ 🚨

sturdy thistle
umbral bone
austere sigil
sturdy thistle
odd abyss
#

hello beautiful people!

#

how are you all?

green kite
fierce vale
#

chillmaxxing today

signal mica
supple plume
#

When do we do some chessing... @native plume

meager kernel
#

i see

supple plume
meager kernel
#

i wanted to change my color

supple plume
ornate ibex
#

I wish I heard songs from Tame Impala earlier in my life

meager kernel
#

hopefully soon

supple plume
#

When do we hack some trashy AD retired

#

I still have 3 days vip

meager kernel
#

studying for college exams nowadays

#

unfortunate

meager kernel
supple plume
#

No try

#

Do or do not

meager kernel
sharp shuttle
#

never apologize

native plume
sharp shuttle
#

gas light, debate, and psyop

meager kernel
#

alright

signal mica
scenic maple
#

bro has a thing for being chinese

signal mica
#

Ah there he is, my favourite mod that was pivotal for my htb growth

sharp shuttle
#

I wanna be IN (A) China (based) non-male (identifying) person, if you feel me

signal mica
#

Good day golam

scenic maple
#

everyday where i meet you is a good day

sharp shuttle
#

golam when are you going to send the evangelions to resolve the conflict in the middle east

meager kernel
#

@supple plume im gonna attempt Pirate today

meager kernel
#

after an hour or so

supple plume
#

Do message me

#

We can do vc

scenic maple
meager kernel
scenic maple
#

its better to avoid that place

signal mica
#

This ones?

supple plume
scenic maple
#

very cold

meager kernel
meager kernel
signal mica
supple plume
signal mica
#

Thats the goal

#

Bodhi

scenic maple
#

bodhi is a linux distro

#

a horrible one tho

signal mica
#

Ofcourse it is

supple plume
#

Hey chat

#

I want to install a turbo minimal arch distro in my raspberry pi, someone knows of some good desktop environment?

#

Not the ugly xfce

supple plume
#

My bad for asking

signal mica
#

😹

#

Welcome to general

azure remnant
#

Can i export all client javascript from the inspector tab in the browser ?

vast mango
#

Lets protest so the pwnboxes get free forever XD

meager kernel
#

i bought HTB VIP+
i WANT there to be a difference between paid and unpaid

sharp shuttle
#

Classism

meager kernel
signal mica
devout sail
sharp shuttle
#

I believe it

#

Gas prices will stop going up tomorrow guys

#

And therefore food prices will stop going up to

rose onyx
# signal mica Bodhi

I always think of the character from payday 2. You might want to be more specific šŸ˜›

sharp shuttle
#

You got a nice Bodhi, Gubarz

#

you work out?

rose onyx
#

All natural

sharp shuttle
#

Thats the right answer

signal mica
clear anvil
# frozen zinc Hey thats interesting, I'm also doing a C2 so I cant really commit to your proje...

I'm not sure if I did mention I was making a nim agent and/or a C agent. Since python OBVIOUSLY needs an interpreter and if I somehow found a way to package it into an agent it would be extremely heavy and would take hours for an agent to generate.

So for all what you've mentioned I'm definitely going to use NIM for the agent, but I did build a simple prototype in python just to test out the stability of the server and the overall C2.

I am definitely open to discussing ideas since I am pretty new to building red team tools/malware.

austere sigil
#

Chat, hey chat, I need your attention

azure wasp
#

Ok

austere sigil
#

Thank you for your attention.

azure wasp
#

Yes

#

How many machines do I need to complete to rank

austere sigil
#

yes

azure wasp
#

Yed

sharp shuttle
scenic maple
#

Who is jack and why is he doing his shit

sharp shuttle
#

Jack is my uncle, hes riding a horse

#

I need to help my uncle jack off the horse now

scenic maple
#

I see interesting person uncle jack

austere sigil
#

I am almost finished with my presentation that I will give to architects and isos

#

I will celebrate with kfc

scenic maple
#

Dont do it on friday

#

Congrats

austere sigil
#

next week

frozen zinc
heady sage
#

Finna apply for my CVE today

frozen zinc
#

Im also developing a first enumeration "suite" with modules, basically im rewritting linpeas in asm and calling in RottenPeas to test the C2, once i made it open source I want to come with that

clear anvil
frozen zinc
#

I will rework the UI

#

once i finish the decoupling so the only tabs so far will be Console, Builder and Modules

#

with the module tab working as library with like "Enumeration"

#

and then when you click there you will see rottenpeas

#

and inside rottenpeas you will the modules with a description

clear anvil
frozen zinc
clear anvil
signal mica
frozen zinc
#

The idea is to make super modular and send it with a plugin system

#

so far it only work with simple XOR

safe vessel
#

I need a job

knotty thorn
#

does htb have anything related to re?

frozen zinc
#

but the idea is to also support more encryptions

clear anvil
# frozen zinc So is all C++ with Qt tools for the GUI, then I have Python only for the shellco...

Well.. that might be a future project for me but I don't think I'm really ready to be coding with ASM and C++ (C sure). I would say I'm still a beginner and the reason I'm working on this project is because it's a learning journey and it will help me learn more in detail about C2 infrastructure. And the reason I said production ready is because I want it to be the best thing possible in python and nim. (Kind of similar to nimplant)

sharp shuttle
river adder
#

Hello everyone

safe vessel
clear anvil
#

@frozen zinc would you wanna talk in the DMs?