#general

1 messages Β· Page 546 of 1

lofty marsh
#

is metasploitable2 good for training?

molten bobcat
#

It's just an automation framework

supple plume
young glen
#

With OWASP top 10 right?

lofty marsh
#

is it? πŸ’€

#

Yes or no

supple plume
lofty marsh
supple plume
molten bobcat
#

Oh apparently I was wrong

#

Wack

#

I've been enjoying my days off

#

Yesterday sucked emotionally but I'm fine

frail turtle
#

I'm gonna become a loser EDC guy

#

I'm gonna carry a rescue kife and prybar

lofty marsh
#

Idk vro Im doing a cybersec seminar and the professor put metasploitable to teach us nmap sadglas

frail turtle
#

never use them

supple plume
frail turtle
#

buy $1000 knife

frail turtle
#

never use it

supple plume
#

Is the first thing I ever hacked

frail turtle
#

buy lockpick tool to fit in pocket

#

never use that

molten bobcat
#

And the first thing I hacked was my own router lol

heady sage
#

Thinking about going scorched earth on these mfs who don’t know what they’re talking about

supple plume
heady sage
#

That would be fun

#

I’m too damn nice to do that though

lofty marsh
#

Why did you guys gatekeep me metasploitable2? sadglas

supple plume
lofty marsh
#

I thought I could only hack htb labs

lofty marsh
#

lol

supple plume
lofty marsh
molten bobcat
#

Nah

lofty marsh
#

I didnt know metasploitable was a thing

#

Nah bro now Im happy kek

molten bobcat
#

There's a lot of different methods for approaching things ethically

supple plume
heady sage
molten bobcat
#

Ethics is more about a mindset than anything. You're not learning how to commit crimes you're learning how to prove vulnerabilities exist

muted olive
lofty marsh
#

But how to train with that was a question for me always πŸ’€

#

Now it's answered sadglas

#

Basically a sandbox

supple plume
lofty marsh
#

Sniff it? sadglas

#

Touch it kindly? blaze

supple plume
#

Bre

#

Why do you send a kids emoji after saying that...

lofty marsh
#

Dude u weird-

supple plume
#

I'm not the one getting weird about a fedora

lofty marsh
#

How do I use a vm for a sandbox...-

supple plume
crude nest
supple plume
#

You want to do the metasploitable

lofty marsh
supple plume
#

I was a kid I watched a youtube tutorial and I've set up the vm

#

Followed the tutorial

#

Hacked the machine and learned nothing

#

You can do it

#

Quit whining and just do it

lofty marsh
patent lily
#

meat sploitable

lofty marsh
#

Virtual matchine

#

What do I shove in it-

#

metasploitable only?

supple plume
#

Bro

lofty marsh
supple plume
#

Do you need me to go to your house and set it up?

lofty marsh
crude nest
lofty marsh
#

pwiz

supple plume
lofty marsh
#

bruv

supple plume
#

Seriously

lofty marsh
#

I dont know if Im explaining it wrong or u dont understand me NotLikeThis

#

WHAT VIRTUAL MATCHINE BRO πŸ’€

supple plume
#

Look open a brouser

#

Then in the search bar type

patent lily
supple plume
#

How to set up metasploitable

lofty marsh
#

metasploitable only?

supple plume
#

Aaaaaaaaah

lofty marsh
supple plume
#

Bro πŸ’’

lofty marsh
#

JHAHAHAHAHAHAHA

#

Bro I genuinely dont understand you πŸ’€

supple plume
#

Man

lofty marsh
#

Sir

supple plume
#

What did I say that was confusing

molten bobcat
#

Good Lord people

#

Someone's asking for help and y'all keep shit posting lol

supple plume
#

Im not shitposting

molten bobcat
#

A sandbox is a virtual machine that has no Internet connection or shared directories with the main host

#

It's used to fuck around with software that might be dangerous or malicious or just outright unstable

supple plume
#

A virtual machine is a sanboxed environment as far as I know

lofty marsh
#

Hold up

#

I was busy

supple plume
#

If I said it wrong I wasn't trolling

lofty marsh
molten bobcat
#

Yes yes

lofty marsh
#

You arent specific sadglas

supple plume
#

Bro

molten bobcat
#

Any of them are

lofty marsh
#

Any?

molten bobcat
#

Yessir

lofty marsh
#

Even fedora?

molten bobcat
#

Ye

supple plume
#

Just look up some tutotials on youtube I'm not trolling

rapid badger
supple plume
#

They explain how to set it up

molten bobcat
#

If it's in a virtual machine it can be considered sandboxed if it's not connected anywhere else

lofty marsh
#

But

#

With that

patent lily
#

Install windows xp sp1 it's better than meatsploit 2

molten bobcat
lofty marsh
#

What do I even hack on an empty vm?

patent lily
molten bobcat
#

Unless you're

#

A blue steamer

patent lily
#

He will learn to use metasploit

molten bobcat
#

Steamer? Teamer

lofty marsh
#

Im steaming bro

molten bobcat
#

Anyway I have a sandbox so I can test malicious urls

#

And other things

#

Cuz I don't want that shit on my host if it infects the host

#

Right?

lofty marsh
molten bobcat
#

I am describing

#

It right now

lofty marsh
#

sadglas πŸ”«

patent lily
turbid bloom
#

i could just open them in windows sandbox πŸ€“

supple plume
#

What I don't understand is with the amount of material out there including llms that will simplify it for you why do you keep asking here the simplest things instead of researching and come up with questions that are not easy to find out

molten bobcat
#

That's their whole deal

lofty marsh
#

I want to hack anything

turbid bloom
molten bobcat
#

All of these boxes are hackable virtual machine

lofty marsh
#

I want to even hack the url bro...

#

Even the login

#

Everything

molten bobcat
#

Heya

lofty marsh
#

no restrictions

#

sandbox

molten bobcat
#

You're getting too ahead of yourself

#

That's not how this works

lofty marsh
#

Nuke tha bih sadglas

supple plume
#

Anyway good luck

molten bobcat
#

I think it's important that you understand how computers and servers work first

#

Otherwise nothing will make sense

lofty marsh
molten bobcat
lofty marsh
#

Without needing to do specific tasks

molten bobcat
lofty marsh
# molten bobcat Too bad

What I mean is I dont wanna be doing Cap for example which is a specific step by step CTF πŸ’€

#

I wanna do flexible attacks..

molten bobcat
#

What you're describing does not exist

lofty marsh
#

Then what is Metasploitable? sadglas

rapid badger
patent lily
lofty marsh
molten bobcat
#

Dude, I have a successful career and I have never used that

#

I need you to understand there is no one single solution

patent lily
molten bobcat
#

I'm good at what I do because of my practice and understanding of operating systems, networking, etc

#

I've been doing this for years. It's work.

lofty marsh
#

But I wanna do it and train how you train with coding

molten bobcat
#

No

lofty marsh
#

Flexibly.. no step by step

molten bobcat
#

Everything in this world is step by step.

lofty marsh
#

I object on that πŸ’€

#

Respectfully

patent lily
molten bobcat
#

Homie, this word "flexible" makes it sound like you want an easy way to the top.

patent lily
#

Gotta learn something first

lofty marsh
#

I think thats what metasploitable is too

#

everything vulnerable

molten bobcat
#

Ah so you want things to be easy?

patent lily
lofty marsh
#

Man...

#

Listen

#

Im not saying I want easy shit

molten bobcat
#

I'm trying bro what you're describing sounds lame and pointless lmao

#

I wanna give you tangible real goals

lofty marsh
#

So when I do CTF

#

I do them with ease

#

And not like

#

"Yo how the fuck do I exploit that"

molten bobcat
#

That's literally how all the boxes work bro 😹

lofty marsh
#

Idk how to explain it to you further bro..

#

Either Im not explaining it good or ur not understanding me

#

Or both

molten bobcat
#

Are you familiar with the expression "more than one way to skin a cat"

heady sage
#

Gng ts is not complicated

molten bobcat
#

Awful expression

heady sage
#

I agree, you can’t skin a cat. They’re too fast.

molten bobcat
#

SO IM GONNA BUST IT DOWN FOR YOU REALLY SIMPLE RETRO SIR

lofty marsh
#

HAHADHAHAHHAHA 😭

molten bobcat
#

Everything red teaming focused has Categories

#

If you focus on hacking websites

#

Okay, that's called Web

heady sage
#

:3

molten bobcat
#

I need you to fucking understand that there are thousands

#

And thousands

#

And thousands

#

Of techniques

#

JUST FOR WEB ALONE

#

THATS ONLY WEBSITES

lofty marsh
#

hOW

#

The fuck

#

Do I learn

#

Allat

#

ALL OF THEM

heady sage
#

Gang you can’t

molten bobcat
#

Correct you cannot

heady sage
#

You have to pick one

patent lily
molten bobcat
#

Or, you learn the most common ones πŸ™‚

lofty marsh
molten bobcat
#

It's better to know about 80% of something than 0 right?

lofty marsh
#

well yee u right

molten bobcat
#

No one human knows everything about web security

lofty marsh
#

@supple plume does

#

He aint human bro

supple plume
molten bobcat
#

Security is a collaborative effort. We work together

buoyant wyvern
lofty marsh
#

He failed the "Im not a robot" shi

rose onyx
#

Dabble in a little bit of everything to recognize some patterns, focus on a key area that you really like. Shrimple.

molten bobcat
#

Anyway web is literally just one category

#

We also have Forensics

#

Reverse Engineering

lofty marsh
#

Yee Im aware of all this

supple plume
lofty marsh
#

I wanna be a general one

#

OSCP

#

CPTS

supple plume
#

The subject is massive

lofty marsh
#

Whatever it is

#

Red teaming

molten bobcat
#

Cpts is your path then

#

It's way cheaper

lofty marsh
#

CPTS OSCP..

#

Potato tomato

#

πŸ’€

molten bobcat
#

But yes please understand that there's a very large amount of things to learn so you can't just be "flexible"

supple plume
molten bobcat
#

You grow to be flexible by focusing on a topic until you're cozy with it, then moving to another one

lofty marsh
molten bobcat
#

Real

lofty marsh
#

Now I understand how I wanna tell you

molten bobcat
#

It's not gonna take your whole life, relax lol

lofty marsh
#

Hear me out

#

In htb labs you have to do step by step shit right?

#

recon touching exploiting and privilage escelation..?

molten bobcat
#

It's not explained to you what the steps are

#

But yeah, those steps don't ever change..

lofty marsh
#

So

#

Hear me out

heady sage
molten bobcat
#

You'll always enumerate something before you privesc

lofty marsh
#

I dont wanna do all these step by steps then..

molten bobcat
#

Then quit

lofty marsh
heady sage
#

C1oud is also very good at what he does smhsmh.

molten bobcat
#

I need you to wrap your head around this. You have to scan something before you can hack it.

#

You can't skip steps

lofty marsh
heady sage
#

Let me break it down for you

lofty marsh
#

😭

molten bobcat
#

Say what you want lol

lofty marsh
#

Aight..

#

So

#

I dont wanna do all these step by steps then.. YET...

#

I want to focus NOW on the exploitation phase

lofty marsh
#

So I can UPGRADE this skill of mine

#

So I can be MORE EFFECTIVE while combining it all

patent lily
lofty marsh
#

Am I clearer?

patent lily
#

If you don't know what you're hacking then you can't hack or learn anything

#

The end

molten bobcat
#

Exploitation isn't a skill you can practice individually

heady sage
#

Gng that’s not how that works, you have to go in order

molten bobcat
#

You have to do the whole thing step by step or it doesn't count

#

You can't just pick and choose which part you like from the steps

lofty marsh
#

Then what? πŸ₯€

molten bobcat
#

I'd be a really shitty hacker if I only scanned things

heady sage
#

I literally have a cert in ts shit, trust me.

molten bobcat
#

Or ask questions?

lofty marsh
molten bobcat
#

Yes?

patent lily
molten bobcat
#

Other people have walked these halls before you bro. Follow their steps

patent lily
#

You gotta be trolling

lofty marsh
#

I know recon but when I see shit idk how to exploit them

heady sage
#

Gng is not gonna get better 😭

molten bobcat
#

Which is.. exploitation methods..

patent lily
lofty marsh
#

Htb academy?

#

Need to do labs?

molten bobcat
#

Yeah

lofty marsh
#

Both at the same time?

molten bobcat
#

Academy has this info, you could also just Google it

lofty marsh
#

Aight thank you πŸ’€

molten bobcat
#

No, academy won't teach you how to exactly hack a box

#

But it will show you what's possible

lofty marsh
#

Because it might sound funny

#

But for me

molten bobcat
#

It's up to YOU to determine what technique goes where

lofty marsh
#

VERY EASY boxes are tough for me πŸ₯€

#

Especially tier 2

heady sage
#

Gng they literally tell you how

molten bobcat
#

That's okay dude

lofty marsh
heady sage
#

I think you should do THM first

molten bobcat
lofty marsh
heady sage
#

Yes you

lofty marsh
#

Thm? πŸ’€

heady sage
#

Go

#

To THM

lofty marsh
#

Me thm? πŸ’€

molten bobcat
#

It's a server for beginners

molten bobcat
lofty marsh
#

The opps? πŸ’€

molten bobcat
#

Patience is a virtue

heady sage
molten bobcat
#

And?

#

This is a server for the basics

tender sparrow
#

Hi, can some1 assist me in the info gathering module, i cant set up the enviroment

lofty marsh
#

Aight I might be a beginner but I have personal beef with thm..

molten bobcat
#

I'd rather him hash out his issues here than screw up some host somewhere

buoyant wyvern
lofty marsh
molten bobcat
#

No

buoyant wyvern
molten bobcat
#

You can screw up a host ethically lol

lofty marsh
#

ahhh

rancid snow
#

bad pentesters can and hve taken down production devices just like malicious actors

lofty marsh
#

But yeah whatever the case is I wont be ever touching a foot on thm kek

patent lily
rancid snow
lofty marsh
rancid snow
#

Brother I made the meme

lofty marsh
#

The worst member in htb is a saint compared to thm..

rancid snow
#

I understand

#

lmao

lofty marsh
#

πŸ’€

#

Speaking from experience

#

Touched a foot for 5 minutes and I had beef with a community contributor

patent lily
#

Touched a foot?

lofty marsh
#

Yee πŸ’€

#

footers

rancid snow
#

wut

spark mulch
#

one day peoople will stop asking "how do i hack" multiple times a day and ignore every answer to only ask the same shit the next day

dense turtle
#

wut

exotic pendant
#

πŸ˜„

dense turtle
#

crazy

lofty marsh
patent lily
#

Stinky

austere sigil
vital aurora
austere sigil
lofty marsh
#

Dude...

#

on metasploitable 2 everything is literally broken

#

dream come true πŸ’€

dense turtle
#

Damn, @supple plume your jwt post is perfect for this machine that just came out

dense turtle
sturdy thistle
errant wyvern
sturdy thistle
#

Would you mind pinging @austere sinew in my name?

austere sigil
vital aurora
austere sigil
errant wyvern
#

hi guys yeah my name is sarah nice meeting yall

#

just started on htb

vital aurora
#

Nice to meet you!

austere sinew
#

NO

#

@sturdy thistle @austere sigil pong

supple plume
#

I'm going to make next one about jwt too

#

If you want a specific one for me to solve and document just suggest in DM and I'll add it to my todo list

silver forge
#

the web was a mistake FeelsBadMan

austere sigil
silver forge
silver forge
#

and they removed the best part which was the blink tag FeelsBadMan

austere sigil
#

moving titlebars made the web amazing

silver forge
#

and weebl and bob

neat cipher
#

The web peaked at badger badger badger

ornate ibex
#

whats happening?

ornate ibex
#

I'm not invited sadglas

silver forge
#

party is just a mood, lighten up pepecoffee

ornate ibex
#

I see

#

tomorrow is Friday @green kite

green kite
ornate ibex
#

A good weekend is awaiting for ya

austere sigil
#

I am going to return to my default state during this coming weekend

devout sail
austere sigil
devout sail
#

Better yeah

#

Best part of working 24/7 shift is you don't have to way for Friday

#

There's never a weekend cool_boi

austere sigil
#

you work at SOC or?

devout sail
#

Officially I'm support for data center

#

But no work in it 99% of the time

austere sigil
#

ooooh I see

devout sail
#

So i do soc and patch management etc

austere sigil
#

good stuff

devout sail
#

Yep got to learn many things

austere sigil
#

that's priceless

devout sail
#

Plue get to mess with most of the stuff

ornate ibex
#

mto, I'll pay you to meet sparkling

austere sigil
#

OK

ornate ibex
#

meet him this weekend

devout sail
ornate ibex
#

I don't have a green hat

devout sail
#

Your pfp show u have one

ornate ibex
#

so u have red eyes?

#

like this?

austere sigil
#

nice counter there, tejas

ornate ibex
#

learnt it the hard way kek

#

thanks

austere sigil
#

is it because of @untold fiber?

ornate ibex
#

no, my friends when they mock

austere sigil
#

fair

ornate ibex
#

wordplays and stuff are something that I learnt after seeing them used on me

#

Anyways, it is time that I sleep. Good Night

austere sigil
#

Nighty sir

devout sail
devout sail
#

You missed one layer on my comment

steel spoke
#

Anyone know of a way to go back to the old UI for HTB academy? Not liking the recent change.

rapid badger
#

No

steel spoke
#

haha lovely

turbid bloom
maiden anvil
raven rain
#

i forget, what is the CEH exam like

sharp shuttle
#

its pretty hard

raven rain
#

i see

normal drum
turbid goblet
#

Will i get bullied if i go to defcon this year but dont have oscp yet

muted olive
#

need I say more

turbid goblet
#

Thats not real right

muted olive
#

'tis

turbid goblet
#

Lmao im ab to make my company pay for it and just take it just for shits and giggles

muted olive
#

youre wasting their money

sharp shuttle
raven rain
sharp shuttle
#

be careful

sinful mesa
# muted olive

Well, if you take the 32 bit version and inject shellcode with Shellter... sure!

turbid goblet
#

Yeah but my company sucks anyways

sharp shuttle
#

not as much as i suck baby

muted olive
raven rain
#

dude how the heck do i make the nextcloud helm chart use a specific disk for storage oh my god

devout sail
devout sail
#

Close your eyes and feel your intestines

eternal widget
signal mica
tender sparrow
#

hi, can someone assist me with a task

stone kelp
#

Looking for a partner to develop something.

stone kelp
devout sail
#

Looking for a partner too

scenic maple
devout sail
#

Can I just say it?

scenic maple
#

no waz

devout sail
steel crane
scenic maple
dawn edge
#

All chat has been images

scenic maple
#

whats with lithuania

dawn edge
scenic maple
#

me neither

dawn edge
#

@scenic maple @scenic maple
You are in htb team . Right

frigid mountain
#

😊

scenic maple
#

yeah

dawn edge
frigid mountain
scenic maple
#

TDP

#

for small man

dawn edge
scenic maple
zenith pine
scenic maple
#

yuh uh

zenith pine
#

nuh uh, thats @spare acorn

sharp shuttle
scenic maple
#

all jokes aside tho get some activity on profile do some boxes/chall
after that try applying

#

but as i said he gatekeeps

heady sage
dawn edge
sharp shuttle
scenic maple
#

whats so funny

dawn edge
sharp shuttle
dawn edge
#

I am arounded by stupid ppl

sharp shuttle
dawn edge
dawn edge
scenic maple
dawn edge
rancid snow
sharp shuttle
scenic maple
rancid snow
#

Hasan Piker is the epitome of 'when you agree with someone but absolutely hate them/the way they said it' for me

dawn edge
rancid snow
rapid badger
#

Oh oh,brath stuck in a loop again. Reset his context

sharp shuttle
rapid badger
#

flap flap flap byeeeee

sharp shuttle
#

F L Y I C A R U S

dawn edge
spark birch
#

Wassup everyone! Here i am after a long break

rancid snow
dawn edge
scenic maple
#

cwes

rapid badger
obtuse fern
spark birch
dawn edge
rancid snow
#

no worries

spark birch
# scenic maple do you have money

From now prob i will earn money in other areas, not related to cybersecurity, at least for some period. I think it is worth it in order to be able to study and do things that i truly like to do in cybersec. Because experience that i had on probation period killed all my joy and after it i took 1 month off anything related to cybersecurity in order to recover from a burnout

signal mica
zealous charm
heady sage
#

if claude can do my job then whats the point

signal mica
zealous charm
#

if sqlmap can exploit sqli whats the point of learning sqli

scenic maple
#

i dont think cybersec is good if you like money

sharp shuttle
scenic maple
#

or doing wandere pro lab from ippsec he makes sure automated tools dont work

spark birch
# scenic maple thats what i do too

It is possible to make good money, but id rather spend years tov build s true wealth of knowledge either which i would decide by my own how exactly i will monetise it, rather than rely on internships and junior roles, trying to break into shitty corporate world

zealous charm
scenic maple
#

cyber too chaotic

#

and very hard to land any job

#

if a field has a lot of jobs then theres also lot of remote ones or easy ones

#

where else cyber you would need lots of things to even set foot in

#

altho i do agree its worth it if you land a high paying one

rancid snow
#

why the fuck is the most physically impenetrable piece of electronics Ive ever come across a $3 chinese smart socket from 8 years ago?

scenic maple
#

but then again a dev role migth pay the same

heady sage
#

wtf is context fortress first flag

#

That’s fucking stupid

rancid snow
#

Ive torn a part a lot of other chinese electronics

obtuse fern
#

plastic from the 90s >>>> plastic from today

spark birch
# scenic maple makes sense i do web work cause its peaceful

Before i got official job in cybersec, i managed to work 1 time on a contract, and i REALLY like what i did. I was able to penetrate production DB with 2m user records on one of the largest local service in my region. That was pure dopamine and was interesting as hell. But then i got 9 to 5 job which was boring as f*ck. 95% of my time i was doing paper work and writing documentation, explaining how OWASP TOP 10 works on a paper so they would be able to show this useless paper on ISO 27001 audit in order to pass it. Extremely boring. I’d rather clean a snow on the street than do smth like that again

sharp shuttle
#

and def are not only with you to steal trade secrets

scenic maple
sharp shuttle
#

beat you to it

scenic maple
#

true

sharp shuttle
#

❀️

#

its okay i still love their silly attempts to steal intel

#

its cute when you know its happening

scenic maple
dawn edge
#

China girls do that?

sharp shuttle
spark birch
#

So i guess i will try contract work in the future. But now i am for sure wanna study things just for me. Things that give me pleasure to study

rancid snow
spark birch
rapid badger
scenic maple
rancid snow
#

honeytraps was invented at the same time as 'give a guy alcohol until he starts drunk-splaining state secrets'

spark birch
rapid badger
#

Doubtful

dawn edge
dawn edge
#

Please no links

sturdy thistle
#

why?

dawn edge
rancid snow
sturdy thistle
#

It's dangerous if you click the wrong links only

rancid snow
#

I have a couple things possibly cooking in the oven so to speak but ran out of time last night to test them

sturdy thistle
#

Nice

rancid snow
#

most promising one would be unauth sqli on something with a couple million installations

sturdy thistle
#

I can help if you want

obtuse fern
# dawn edge Even if you know it's a trap, you may still fall into it.

wordfence is a legitimate website, even when you're being cautious you can easily vet websites you find suspicious via a variety of methods. One of them being the tried & true whois lookup; older web domains tend to be more trustworthy (though they can still be socks) and looking up various things regarding the domains

rancid snow
#

im still experimenting with some workflow stuff, theres just a couple interesting things that have bubbled up to check but power was flickering last night and it was family bed time

#

I have a haircut after work and then kiddo really wants to try pho for the first time so ill probably only have a couple hours tonight too

sturdy thistle
#

Yeah just dm me when needed or wanna talk

rancid snow
#

almost into this blasted thing

signal mica
rancid snow
#

and a pair of strong clippers

#

I have backups so I can destroy this one for science

severe falcon
supple plume
#

vibe code micromanagement kek

devout sail
#

Lgtm

devout sail
zenith pine
devout sail
zenith pine
rancid snow
devout sail
#

What is it

#

I see the plug pin and a big ass capacitor

signal mica
rancid snow
#

smart socket. owner is tossing them because they only work with alexa or google home stuff

signal mica
#

congrats on guru simon

rancid snow
#

and havnt sold in forever

#

now a smart person would probably start by examing whatever mobileapp they want or seeing if theres a firmware download option

devout sail
severe falcon
rancid snow
devout sail
#

:0

#

Keep us updated with your findings

rancid snow
#

basically a wall plug you can turn off remotely

devout sail
#

Yep i got it, I was thinking about how you use the smart plug and was thinking solely about it wheeze

#

He got promoted a few days ago

rancid snow
#

im really bored at work rn, dunno how much effort ill put into this, but I at least want to extract the board

#

because its offended me

devout sail
#

I don't even know the way to extract such stuff πŸ’€

static bloom
devout sail
#

Eh

rancid snow
#

normally they come apart pretty easily, this one is like injection molded shut or something bizzare

devout sail
#

Hehe fair enough

rancid snow
sharp shuttle
#

is that the amazon plug mad

rancid snow
#

not amazon branded but probably sold on amazon a while back

severe falcon
#

Thank you Hack The Box!

sharp shuttle
#

yeah those things are crazy

#

gratz on orange

severe falcon
#

Thank you Brath, learnt a lot about AI/MLs.

signal mica
devout sail
signal mica
#

711 is great

severe falcon
#

I love DFIR and want to progress more into Rev/Pwn.

#

Of Course, what azomax said.

#

0x711 or 0xffee is good.

molten bobcat
#

711 is a gas station

#

And apparently they're really really cool in Japan

devout sail
#

0x8008

severe falcon
#

"If you want to learn something, just start doing"

#

Just, Just start.

#

go to sleep.

#

Yeah, I know you are new.

#

I can tell.

#

discord user from 2016.

#

yeah sure

#

yeah, welcome here.

#

jk, happy learning.

supple plume
#

is it a static website?

crimson crypt
#

Almost Friday waz

supple plume
#

astro + gh is great

#

ts my blog

#

the code

#

you're welcome to steal it and change some styles it works rendering markdown

#

hahah

rancid snow
#

victory is mine!

stone kelp
#

Hi. help on a captcha solver AI as a service?

#

I developed everything. Need domain and hosting.

rancid snow
#

ESP8285 controller it looks like

rapid badger
rancid snow
devout sail
#

Go do HTB academy now

supple plume
devout sail
#

Didn't compliment you

#

Ok

supple plume
#

wut

devout sail
#

Yes you are welcome for me checking it

devout sail
#

Now do HTB academy

#

Fix it

supple plume
#

maybe next month

devout sail
#

Tonight

supple plume
#

fun thing is I could probably do it tonight if I wanted

devout sail
#

So?

#

You don't want?

supple plume
#

I am still working on the blog

devout sail
#

Fair

normal drum
#

HTB academy is great if you are a student

rose onyx
supple plume
rose onyx
#

I have some stuff that i've been playing around with in mkdocs and hugo

rose onyx
#

none yet, maybe one day when i get the energy to finish one of them πŸ˜‚

molten bobcat
rancid snow
#

imagine building a captcha ai solver but figuring out domain names and hosting is where you get lost

acoustic cove
#

what does he sells

molten bobcat
#

A whole lotta nothin

mortal salmon
#

Hi all, @obtuse fern may I DM please ?

young glen
#

😎

supple plume
acoustic cove
#

why I can't upload image

supple plume
acoustic cove
#

I just wanted to show my windows setup

supple plume
supple plume
rancid snow
supple plume
#

@acoustic cove Either this or you get someone to proxy your upload. Falcon if you read this, do not reveal || DN ||

acoustic cove
#

dw I will get cert

spark mulch
molten bobcat
#

Do your best and don't be afraid to talk to people to figure out things you're stuck with

supple plume
velvet grail
#

Hello everyone, I have an annual Silver membership.

I've completed a course.
Do you know how I can retrieve a certificate showing the time spent?

I'm looking for this document to submit manually for my certification renewal.

I downloaded the transcript, but it doesn't mention this information.

turbid goblet
#

today is a lay in bed day whos with me

rancid snow
#

It doesnt have it by default, hope you already had your ID linked for the credits

thick forge
#

kypanz world in the best

#

mind my change

crimson crypt
stoic flint
#

I tried many dictionaries, the module is broken. I already contacted support.

rapid badger
severe falcon
turbid goblet
#

ai is great i convinced a discord of 500 people that i was stuck in a waymo trunk

severe falcon
#

lol

balmy basalt
#

I want to get SDR hardware now. sadglas

rancid snow
#

me too

#

Ive wanted it for a decade but never get around to it

spark mulch
#

SDR ver fun

simple gale
#

Just finished all the Linux boxes LainKusanagi/TJNULL easy list for HTB. Does anyone know of good resources on WIndows Methodology?

frosty jackal
#

Does HTB have a deal with nord or something? Infuriates me to see them suggest NordVPN over Mullvad.

rancid snow
#

where are you getting a nordvpn recommendation from?

frosty jackal
#

in the "getting started" module for offensive in the Setup, in Connecting using VPN unit and I quote

We can use a VPN service such as NordVPN or Private Internet Access and connect to a VPN server in another part of our country or another region of the world to obscure our browsing traffic or disguise our public IP address.

#

Although they say connecting to HTB VPN in the next section, I find nord to be an awful recommendation as they operate under panama law, subject to then KYC laws

rancid snow
#

Yeah lame advice

#

but I wouldnt recommend covert opsec advice from HTB lul

frosty jackal
#

yeah true, that's what we got dread for i suppose

lime trout
#

It’s just as an example

#

It’s random

rancid snow
#

I think its more important to know the concept exists then to take it as good recommendation

#

its an old module too

rapid badger
#

Its just a basic example lmao

rancid snow
#

even if it did say mullvad thered be no way to know if that would age well at the time or not

frosty jackal
#

Fair point

rancid snow
#

mullvad is good now, but would you blanket endorse it for the next 4 years?

calm osprey
#

how do i connect to the htb vpn with linux? i can't find the .ovpn file anywhere

turbid goblet
#

atleast htb's advice isnt to use thm echo

neat cipher
frosty jackal
rancid snow
#

In 2 years palantir buys mullvad and your recommendation is ass. Better luck next time πŸ˜‰

im jk but you get my point

frosty jackal
#

Yeah I do, if palantir did ever buy mullvad though I'd be so pissed

#

fuck peter theil

rancid snow
#

I think hosting your own vpn entirely depends on what your actual threat model is

calm osprey
frosty jackal
neat cipher
obtuse fern
#

in excercises that require you to connect to a private target <10.129.x.x> there will be a tab next to the pwnbox one that says "VPN"; you download the vpn from there

molten bobcat
obtuse fern
#

they actually updated the help article to reflect the UI changes :)

calm osprey
obtuse fern
#

"connecting to htb academy vpn" is usually what I google when someone asks me about it

#

and usually HTB has a help article for it

molten bobcat
#

I feel like things have been calmer lately

rancid snow
# molten bobcat

people freaking out are so annoying. The ending message is the exact same message given when part 1 ended.

Freak out when theres no announcement about part 3 instead

obtuse fern
#

fuck you @molten bobcat ❀️ (there, no more calm)

rancid snow
#

the only reason people are upset now instead of when part 1 ended is because part 1 worked as a self contained story and part 2 doesnt

hoary dawn
#

best opsec vpn is ur iphone hotspot bruh

#

on another note i love my mullvad

obtuse fern
frosty jackal
rancid snow
#

you want the blackhat answer?

bulletproof hosting provider that accepts monero, use a tor hidden service to wrap a wireguard connection and use that

rancid snow
obtuse fern
#

hard to tell when people are being genuine or being funny

#

this is the life of the discord janitor

hoary dawn
#

🀣

rapid badger
molten bobcat
#

I am

#

Adrift

#

In what I feel like doing

rancid snow
#

see my added paranoid addendum lul

frosty jackal
#

oops mb

#

indeed

polar turtle
#

Hello I’m new and just wanted to say what’s up

molten bobcat
#

Unfortunately the router you've tapped into is under my protection

#

The logs have been handed to the authorities have a bad day

hoary dawn
#

can u make ur own vpn with a pi

rancid snow
#

the REAL blackhat answer is to live in a country that doesn't care and let your infrastructure guy in your team handle it for you

hoary dawn
#

i got a freaking pi laying around

molten bobcat
#

You can do anything with a pi it is a computer

hoary dawn
#

i think thats what imma do with it

molten bobcat
#

I didnt say what your idea was would be smart

hoary dawn
#

im gonna put a modem on it

rancid snow
#

do it and learn something

molten bobcat
#

Do you know what a modem is and does?

#

It's two things.

hoary dawn
#

the shit thats in the phones

#

not the router one

molten bobcat
#

The children are not educated these days

#

This is the part where I hold your hand

rapid badger
#

We made everything too ez for them

molten bobcat
#

And explain to you that we haven't used modems since the 90s

rancid snow
#

@molten bobcat buddy

#

you know hes right?

#

right?

molten bobcat
#

He's talking about a modem

rancid snow
#

the chip in the phone that handels cellular communication is still called a modem

hoary dawn
#

big opsec

molten bobcat
#

I'm talking about

#

Us no longer using modems

dense ruin
molten bobcat
#

In networking

rancid snow
#

...but you're wrong

molten bobcat
#

Because we don't piggyback off the phone lines anymore

#

Or we shouldn't

rancid snow
#

modem terminology has been extended

molten bobcat
#

Of course it has lol

#

You're more than welcome to educate me if I'm wrong

rancid snow
#

it aint the 90s anymore

hoary dawn
#

thats for routers the router technology been new new thats back when the phone was reliant on the router to run too

rancid snow
molten bobcat
#

Ahhhhh.

#

I understand now

#

Apologies I get it now

#

We still modulate analog signals

#

Those signals are not dial tones anymore

#

They used to be πŸ˜‰

rapid badger
molten bobcat
#

Anyway!

#

Be careful because

hoary dawn
#

i still am clueless on how i would go about it but i just figured a good private way to have your own vpn would be doing that with the pi

#

i just still dont know how i would ensure my traffic is encrypted and all that lol

molten bobcat
#

PI's and other systems have no cooling

#

On their own

#

I would be concerned if you try to overwork the thing it would get warm

rancid snow
meager kernel
#

Morning

dense ruin
#

unless you run them far beyond their capacity they don't really need cooling

rapid badger
#

You want a cheap pc for that kinda stuff no?

hoary dawn
#

i actually did research that

molten bobcat
hoary dawn
#

because i wanted to use it for a 24/7 around the clock security sytem

molten bobcat
#

Small enough workload

hoary dawn
#

it can pretty much take a beating 24/7

molten bobcat
#

Lmao

hoary dawn
#

i was managing the storage pretty well, i mean, not saving a lot or anyhting like that

dense ruin
#

I run one of my pis 24/7

molten bobcat
#

I'm almost positive hardware firewalls have fans lmao

dense ruin
#

no issues

molten bobcat
#

Sure but he's wanting to do something beefy AF with his

dense ruin
#

i typically use it as a proxmox qdevice + ntp server

hoary dawn
#

naw i made it myself its a little crappy program

#

its actually on my github i think

dense ruin
#

nah vpn isn't really all that beefy tbh

hoary dawn
#

hes talking about my security system but yea vpn would be more hefty than a cctv system

dense ruin
#

now maybe if he were cracking passwords or something cpu heavy sure

molten bobcat
#

He said 24/7 security system

hoary dawn
#

i just had a funky little security system rolling with a wired webcam at my door

molten bobcat
#

After vpn

#

Lmao

hoary dawn
#

that was the last thing i did with my pi when i researched if it could run 24/7 with no issues witht he software i was running basically

molten bobcat
#

Streaming video takes a lot

dense ruin
#

security system is likely writing ffmpeg to external disk drive right?

hoary dawn
#

yea no the storage wouldve died instantly basically

molten bobcat
#

Not to mention encoding

hoary dawn
#

i had to basically not save anything not worth saving πŸ’€

molten bobcat
#

That the cpu would be handling

exotic pendant
#

πŸ˜„

dense ruin
#

ayo @exotic pendant

#

been a while

meager kernel
#

Guys

#

Wanna hear something funny?
The game that didn't work well for me on windows, worked better on linux

#

And even my controller worked on linux, even though it wasn't on windows

#

Ironic

molten moat
#

lol microslope

rancid snow
native yew
#

is there a channel dedicated to asking for help/questions ?

rancid snow
#

lots of channels for lots of different topics

native yew
#

just a general question abt how the season system works

#

i solved a machine but still have no solves under my rank

meager kernel
#

Heroic game launcher and Steam are the best inventions for Linux

native yew
#

i solved "facts" user and system, but still havent upgraded to bronze tier

rancid snow
#

youre too late

molten bobcat
#

Dang

exotic pendant
rancid snow
#

seasonal points are only awarded the week of release

native yew
#

ohhh

exotic pendant
#

Frosto's been grinding and got 12 apple bugs

native yew
#

thats why they are categorised by week

hoary dawn
molten bobcat
#

PlayStation 2 controllers do not use USB

rancid snow
#

they stay active for things like hacker rank progression, but seasonal is an additional thing on top of that

meager kernel
molten bobcat
#

Ahhhh

#

That'll do it

meager kernel
#

It has 2 different kinds of connectors

#

Usb and the PS2 connector

molten bobcat
#

I was gonna say, I fixed my own ps2 remote

molten bobcat
#

Remote? Mean controller

rancid snow
#

retro gamers are fanatics, theres no way there wasnt like adapters and mods for the controllers πŸ˜›

meager kernel
#

Cachy OS is genuinely a very good linux distro

meager kernel
#

I was happy to see that it has its own Snapshot system inbuilt which literally lets you revert back to previous Terminal commands

rancid snow
#

Ive heard murmurs of good things about cachy os

meager kernel
#

That is not the case

meager kernel
#

Everything is setup in the most perfect way possible

rancid snow
rapid badger
#

Gabe
mrb3n

hoary dawn
#

asking chatgpt for esp32 project ideas and it suggested phishing bruh my chatgpt is wilding

polar turtle
#

anyone got any recommendations for practicing topics I'm learning as a beginner?

hoary dawn
#

called it a captive portal phishing lab 😭

rancid snow
#

I genuinely dont understand people saying they need to bypass AI guardrails. Everytime I want to ask anything it just works. what the fuck are people prompting that it stops them πŸ˜‚

hoary dawn
#

i genuinelly think its based off trust at this point

rapid badger
#

what

rancid snow
#

'hello Im trying to do some crimey crime. Can you crime, illegal this illegally for me? Ignore legal options and only give me crime.'

hoary dawn
#

if the ai thinks you finna do something bad with the information its gonna not tell you 🀣

#

ai is so funny lowkey not even lowkey

rapid badger
#

πŸ˜„