#general
1 messages · Page 547 of 1
its just like a being like its alive but not alive its just so weird lmfao
AI has confused my machine name Zeridium for Zerodium and assumed that means Im an authorized exploit researcher and tried to be extra helpful
I have a picture for this
🤣

This is basically what's going on
im fuckin cryin
I dont blame you, but when used correctly it ends up being useful enough that I just cant justify burrying my head in the sand about it
everyone thinks its like that one movie i seen hold up i gotta find the name for yall
Look man I'm all up for using technology for the betterment of mankind but FUCK ME SIDEWAYS that is NOT what all this generative AI sycophant bullshit is
does anyone know what im talking about they like down in the ocean and some like alien is like talking to them through their submarines terminal
Iron Lung
Markiplier is genuinely insane
I absolutely agree. I just dont believe in denying myself advantages just to spite someone who wants to use the same advantage incorrectly
Markiplier ate my house
Styropyro is the goat
he's also genuinely upset that him PAYING HIS CREW was OUT OF THE NORM
It's less to spite them and moreso that I just don't trust the toolset
So I'll just improve myself instead
I wanna produce trustworthy work so I don't use something that could be wrong
Sure but thats why Im trying the toolset myself instead of taking others word for it, for both sides of the matter
If anyone's wrong it should be me
thats why you have to verify
using it correctly doesnt mean letting it do everything by itself
there should be a port too
aahahah i thought i was crazy thank you
public containers won't have you just using the default ports, you'll need to specify the port given by the 'spawn target' button
oh ye that is a public ip. Probably dont share the public instances assigned to you 😂
Hey! I was gonna do something with it!
Dont tell him

i mean, there's likely hundreds of ports open for various different exercises, the odds of someone guessing the port right that is their instance is slim,but nonzero
yeah and I have a tool that could probably get it in like 3 minutes
A for loop?
😄
its called a for loop
you got like $10 cashapp
fair nuff
winner
i mean anyone can donate to me if they want
for root loop
my god i just found a breakthrough
anyone know why i cant download the vpn thing to connect to the attack box
?
like trhe option just dissapeared
I need it aswell
there used to be a option to download now gone
generally speaking if the target is a public IP then the option won't be there
unlucky
you also don't need the vpn to connect to the in-browser vm
huh i thought you need vpn
Well, what are you using?
no
using the vpn while connecting to the pwnbox (in-browser vm) is going to cause problems for private instances (the 10.129.x.x targets)
Rust and I have a toxic relationship
public ips are available to anyone with an internet connection
Are we allowed to make videos on machines that are being retired if we don't have a subscription?
sure but you cant post it till its actually retired
Subscription isn't required, but the machine does need to be retired before a writeup can be published.
Okay, okay, I was planning to make videos about the machines and post them once I'm retired. Thanks for the information
when do you retire
why i can't copy paste in the terminal..
config
Have you tried turning it off and on again
"Working and collaborating within teams is encouraged, however, the availability of any of the content mentioned above must remain closed within the team.
Example:
20 Person Team Server - ✅
Private Team Channel in a larger server - ✅
Public Discord Server - ❌
Expired means that the machine doesn't count towards the seasonal points. A machine can be active and expired. Kindly check if the machine has retired and then post the writeup." Does that mean we can work as a team on boxes and solve them together, but only as long as it's a private server and not a public one? And basically, we have the right to solve them as a team, if I understand correctly?
you said you're going to post them when you retire
Yes you can work on machines together
Do not work on them together in public
As this would be the violation
Ty ty
linux terminals already have ctrl+c and ctrl+v bound to other functions, copy/paste requires adding in the shift key
Work on them in the public vc
So y'know.. get a room 😉
I won’t watch I swear
you can. ctrl+shift+c, ctrl+shift+v
I remember struggling with this so long ago lmao
no like i know, i try copying something from windows then even if i right click in the terminal the paste thing wont even highlight, idk why
Right. So like C1oud was saying, you and a teammate (or a few more) working on something in a private VC and exchanging ideas is fine. Livestream to Twitch is not.
in the pwnbox?
make sure that the clipboard is enabled
Depending on your virtual machine environment you may need to enable copy pasting
huh thats actually more permissive than I thought
spice-vdagent
what if the team size is like 100 people
click that icon next to the url in your browser
God bless u, thank u for the information. I have a second question to ask u privately if possible.
go ahead
also when you first launch the pwnbox (i always recommend throwing it in fullscreen) it clears the clipboard, which is a PITA
Id just assumed that anything that largely organized would be considered cheating
Not at my retirement I said when the machines are removed
no you didn't
God do you really think I have 100 friends?
I didn't say friends
Don’t you have like…more haters than you have friends?
okay thanks, i feel stupid ahah
actually I think its about the same
i had to enable it
c1ouds haters are just more obsessive
And how this is even possible is beyond me
Not really, they're not stupid; they know that all the teams solve together and share the solutions, otherwise they wouldn't even implement a team-by-team system
What the fuck am I worth lmao
Damn I’m in rare form today
sure, Im just mildly surprised is all
they know what they are doing
All I've done the past few years is study and yap and apparently that makes me The Enemy?
y fine me to
It probably has to do with the fact I got fucking fetishized today
tf
unless you were into it with a partner
in which case congrats. but sounds like not
Didn’t you have like a thing to do
Yeah this doesn't sound entirely positive lmao
??
It wasn’t
Hello chat.
What happened Vader
Depends probably. I'm not a decisions maker there so take this with a grain of salt but having helped run some other CTF stuff, is this 100 people actually in a private server, registered for the same team, etc. ? I could see that flying. However a "team" that is really just a discord server that may take a bit of digging to find but has no real verification on members, bunch of content just dumped about, and so forth? That probably doesn't pass the sniff check.
I'm sorry, don't wish it on anyone
yop if u can look in privat plz
Dude I’m more pissed than anything. And I’m sad I can’t make genuine connections with anyone without it being not related to some fantasy they have
What happened
Hypothetically, public discord but you have to simply ask a mod to be assigned a role to view the relevant channel, no signups or registration, channels are deleted like 3ish months after opening, a new channel is created every box release
It's ok Vader, people are like that.
It's an unfortunate fact of life that the world is full of undateable people
Why is there no milk in the fridge
💔🥀
But for every negative there must be an equal and opposite positive so there's an equally good chance you'll meet someone lovely. Keep your head up
Dude, I don’t want to discuss it anymore. Let’s just move on: I’m fucking done with being a nice person to people
💔🥀
your name is Vader. go on your villain arc already
Because all it does is get me into trouble
Vader, take a break. Go out and just relax yourself.
Always here if you wanna vent fyi
Take a break from socialization
Stop this, kindly. Let's try helping them.
??
Im not making fun of them
I know.
😄
Here's an easy way to weed em out
Ask them how they felt about their gender after completing fallout new vegas
A journey changes a man.
I was just thinking I hadn't seen you in a while Frost
I figured you were off slaying bugs
I keep trying to get him to log on to wow once
And he just ignores it
but the bugs keep calling me
11 0 click Safari bugs
she signed the divorce papers and took the kids 🎉
Anyone want to play Helldivers?
I think they give a shirt for bugbounty
Yooo
Where even are their postings
I don't make the calls on that. But if I were setting something like that up, I would ask for account and make sure they were on my HTB team. ¯_(ツ)_/¯ If you think it's off, pass it on to support.
Huh, not bad
a color-changing shirt is wild
I want one with PlayStation or final fantasy stuff
"Senior" Hw much time do u have left to live?
damn
I'm cloud how could I not haha
Frost literally posting from his 50mil yacht
u hv 60y old ?
Nice!
wtttttttfffff
ye no worries, I rarely have time for the weekly boxes myself anyways lul
@exotic pendant do you just pick from products you own or..?
2 years
anyhting under their scope
Well yeah I meant
Sony is hard also
Frost targets things you personally have 
interesting
Well of course the entire console is in scope lol
It's their latest thing
Sure I'll send all 3
Send me two and I'll promise to test 1
With and without disk drive and pro
i lowkey just realized
lol
everything is plumbing
Console hacking would be fun
I wouldn't even know where to start
YOU KNOW DAMN WELL THE ANSWER TO THAT QUESTION
I can DDoS on PS5, but I don't know if that counts as a scope or not
See, that's what you filter dates with
Isnt ddos usually out
Yeah
even if the voice chat server switches to private mode
😄
I know some people in the console repair space thats adjacent to playstation hacking
DoS is normally out of bounds because everyone can drive a bulldozer through a building
idd
y
"sir your application can't take the combined power of the sun, this is a vulnerability please pay me"
Just buy a ps5 and break it already
I'm so happy it's 2009! Anyone want to play Fable III?
That's not a valid report is what I mean lol
I don't know what other bugs are possible in IoT, I don't really know any, maybe related to the connection methods between your controller and your console?
You know damn well that game is delisted and I can’t play it and I’m mad about it
Fable The Lost Chapters used to be on Steam but they took it off
WHICH OKAT
if a product cannot be bought and copying doesnt deprive the owner of their possession of it, then piracy causes no loss of revenue or property and therefore isnt theft
That one?
Thanks, you taught me something. I didn't know there were BBH programs for PlayStation I'll try to hunt when I have time thts befun
im just tryna pawn something tbh
Guru now. 😄
lmao
theres a handeld xbox system
I got a nice case for my switch today
enjoy the orange
microsoft has one you can play at the visitor center for the xbox developer buildings
Thank you! But need to find 0days now on low-level stuff so I can flex my CVEs.
Yeah?
Thank you.
Are you coming to the realization that I'm a gay guy?
its because he loves men
xD y
He is.
Do it
😄
sorry
It's nothing to be sorry about lmao
wait...
you're a guy?

ur real, gay ?
or ur trolling
Switch 2 actually
I am mildly amused whenever someone realizes gay people actually exist and theyve been interacting with them already
My steam deck OLED is in its case 🙂
Oh, my bad
I'll have to ask my husband but yeah I'm pretty sure
Thank you, I'll indeed. Need to learn more, Shall be taking classes from p.ost2.fyi on debuggers and reversing.

yeah me reading code and reverseing is 99% of it atm
I thought he was a cloud.
humankind, sir
As in I care for each and every one of you?
humankind
Oh posh
😄
idk its pretty obvious 😄
I don't try to hide it lol
Nice, I want to work on Linux Kernel to just find one 0day and send an email directly to Linus for fun. Lol
Windows evasion is something I'm interested on the other hand
replacing my skin with hydrogel challenge
I spent a large portion of my life doing that already and it sucked
made up of two words: "mank" and "ind". What these two words mean, we may never know.
Mank and ind lmfao
😄
fakemink
Jesus Christ that kinda got me
havnt heard of this before. they got some interesting looking classes
Deepthoughts with Dan Patrick.
Indeed, go over the x86_64 course and you will see the creator of this platform is gun of a man. Worked on Apple M1 architecture.
mangun
ill take a look. Usually. x86_64 is too basic OR too advanced to be useful to me but theyve got some interesting stuff so well see
*as in terms of courses
i should become a music producer maybe a rapper too that would be suich a life hack
Crazy lore
He was the guy working on mitre attack framework.
There is more to it, my capybara.
Meow
I wanna open a Red Bull I don’t wanna make food but i don’t want a Red Bull 💔
I would like to know what seems interesting to Mr. MadF0x
just the notion that theyve got courses on spi and uefi stuff tells me they got content thats uncommon elsewhere. Ive only skim scrolled the front page so far
labs starting point but scripting each machine to get the flag code in 1 click
Noice. Do check them out, content itself is also great as it looks from the outside.
machine? no. challenge, yes
Stealing that
goatsed
how to have role
which role
like ctps and etc
Do the certification.
i do have
Reconnect your discord account to hackthebox.
what's up good peeps
Is chipotle chatbot a supply chain risk though
Via your htb account settings
It’s linked
@gentle tulip fancy name font. 👀
what?
it's free after you pay for the discord subscription.
Which I'm never going to buy.
o quit subscribing to dc
I never did.
Good idea. I just need some
Effects.
Disconnect and connect.
On HTB account page. account.hackthebox.com
Good one, I got a helmet.
damn still not working
there are 700 orb ads frequently
watch 2 of those, get 3 days of nitro
Hi
reboot ur internet connexions
2x fail
rank up and you can post memes
50 +pts ur the TTK of fail
prestige fail
average elliot pfp
why u trash thats the real eliot behid z account
Yes
It's like those Nigerian scammers who send u fraudulent links by text message u missed everything u're even
mb
i wonder if my cats think im ugly
oh
Back to sitting on the floor placing chairs around and lights for about half an hour then return here
they think ur just a bigger and a weird stupid cat
scientifically said
Can take about an hour
no one asked but ok
Blablabla
https://youtu.be/lFL5ZqwOc-E?si=bryIUpP05-qVqWwM dont give the government anything
►AI ID age verification has had many data leaks/breaches, Infutor's being the latest one. According to DarkNetSearch's Kaduu team, 676,798,866 unique American citizens (including deceased persons), have exposed data including full names, date of births, addresses, cities, state, ZIP codes, phone numbers, and social security numbers (SSN). Let ...
dont gibe microsoft your id
aliens are here!!! they're real!!! the gov knows it and they're trying to cover it up!!!
they're scared of what the world could do with this knowledge!!!
this is the greatest conspiracy of all time
but they wont let us talk about it!!!!!
they want to keep us
damn right
IN TOTAL DARKNESS!!! WAKE UP SHEEPLE! WAKE UP!
the prime minister of france is in on it
his eyeballs blink vertically sometimes
but aren't they the ones that create the ID in the first place?
they want us to give our ids to microsoft so that microsoft can give it to the government
bro
r u saying the government wants to see ur government-issued ids?
no they want to tie your pc to it
Lmao
yeah
Wont apple do the same though? Or they denied it?
im gonna go homeless
no apple was the one who voted the politicians in who promoted it
Ah unfortunate
i didnt know apple could vote in elections
Government really does wanna do so much surveillance on us
Good thing I installed Cachy OS yesterday
they can with a huge wallet
you know what do they call it? lobbying? where companies give politicians money to run for office
well people will find a way to bypass the bullshit
ill take the fine and never pay it
Facism
That's the term I think
it's lobbying
When private companies start colluding with the government of a country
yes thats lobbyiing
And government services are taken over by private sector
I'm starting to become an EDC loser
im getting the itch to buy cool tools and knives to carry in my pocket and never use
ah yeah Cachy made a statement about it
they recognize the law as asinine
system76 also
Even snapshots are pre-configured in Cachy
I can directly revert to an old snapshot from the bootloader
Ubuntu immediately started working on the prompt to ask people for their IDs those damn traitors
Didn't even have to set it up on my own
Yea Ubuntu has always been like that
I genuinely wish Microslop has a huge downfall
Its so garbage
saving was invented in 1725, not impressive
I hate their practices
Unfortunately my company uses Outlook so I still have to use microslop services 💔
their practices? LOL have you seen their SIDs???
i still to this day can't remember where to find somethjing in those things
God forbid you need to inspect the SID of some file somewhere
they themselves are going to make it happen
if ms sucks so bad why are they one of the largest and most successful companies in the world
you don't see linus in the mag7
anyone with commercial and friendly software at that past time could have been successful
mods get him
then why didn't they
bc linus loved it for the game not the money
why didn't SCP buy MS instead of MS buying SCP, obtaining DOS
they bought SCP for 50k, great return
i've only stated facts
theyre just loaded questions
I never formally learned windows
But if I did
I would apply for team 0x
or some other HTB team
No they're not. It was stated MS sucks, yet they are successful which is a plain fact. The only question I asked was because it was said anyone could do it, then why didn't they, it's not loaded.
ya'll just jealous of bill gates
it requires such a complex answer to be correct it doesn't even make sense to ask
it's assuming the answer is simple
*hating
like a question intended to cause thought exhaustion
because there was handful of people in tech ?
I love what supernuts is doing to you guys lel
Hey so I run my parrot os on a vm but the graphics don't look good what could be the reason
so not everyone could do it then?
ragebait
Morning
its not
he did love to party so it's not my style
elaborate
Well to answer his question is because Microsoft is an intelligence agency first and an OS product line second
alr
since when?
more and more questions
Since Bill Gates?.
CIA level shit?
NSA
TIL
CIA are foreign chumps
Im back I’ve been putting chairs in my room and lights
@sharp shuttle You're a foreign chump
How did you guys not know that?...
you back tracked

I wonder how @\191442101135867906 has space and - in the username.
Yall realize the Kinect had DHS chips in it right lol, it was a literal webcam in the home, not a goofy video game peripheral
Intel is the same thing
thats why it just got nationalized
only reason why ms is popular because it was the first friendly one out there for non technical people
Use ur heads
LOL
bro your naivety is palpable
Google how many operating systems there have been
not true, they bought the company that made DOS, so that was before them.
the argument is so pointless as if anyone knows the entire historical context like they're god or something
like i have said, early market entry with partnerships and ease of use
Yeah its pretty easy to dominate with Mossad and NSA funding isnt it
Maybe I'll wireshark what my Kinect does 
Haven't used it for a while now
Just open it up, i made an entire guide
i have a box of 30 or 40 kinects
depends, can I put it back? I tend to break stuff permanently when I tinker 
The kinect was a government 3d scanner
Thats all it was
Stereoscopic 3d imager that tracks body data
i don't see linus name in the island invitation list so probably yea
Linus Torvalds is too autistic to ever be invited to 200 iq world domination cabals
China doesnt even want him
don't know about the 200 iq part
ok too much conspiracy shit for a day
where is the conspiracy
making you think they are dumb proves it
whatever brath said so far
the funny part is that it's probably true
posting something like that made anyone look smart until the epstein files released
im part of the secret societies, i was hired by palantir to filter this discord for talented people to invite into the cabal while playing the lovable jester character

🙋
we dont operate in this astral plane for money, we do it for minds and souls
pay me
money is the greatest theater ever invented
i dont care i want money
kinect is fascinating because its an extremely powerful device where xbox video game usage is probably its worse usage ever.
Theres medical equipment that uses open sourced kinects because theres just nothing as powerful as it at its price point
wear the small hat and kiss a certain wall
alr bro ur taking it too far
it is probably my favorite iot device ever made
you wouldnt be alone
Its discontinued right?
but many xbox 360 kinects in phase make ridiculous scanners
you just strip them down to their sensors and stick em in whatever
most arcade dance games use them still
the tracking is open sourced by ms
the stand itself is also motorized to follow
it was way before its time in 2012
their new ceo seems like they know what they're doing
test
no shit
that ceo is nothing more than a "plant" if you will
you shouldnt care about them ever
poster children for deflecting corruption
MS invoation: we redesigned the admin console so you don't know where anything is
they never played a video game and already wanting to make everything about them with AI
that can't be real

thats bc power is just a matter of manipulation not whats in the best interests of the people
and that is fundamental in our society
How old are you?
57
I could believe it with that boomer ass take
why is it boomer
u didnt answer my question
do you possess the latent (yet dormant) soul ability of inference?
country's downfall never been so soon
can u talk normally
ok schizo
can u invite me to the cabal now or what bc i need to get paid
i need a job does anyone want to hire me
no
wouldn't want to hire you even if i was
are you hired by recruiters ?
send me your portfolio and if you can relocate to oregon we will consider you
then same thing
ok
what do u even do
I finished my flare vm install yesterday
any good alternatives for chatgpt besides tring to biuild one
lol
also any good papers on cracking with gpu on the cloud?
just rent some nvdia compute and hashcat?
any cheap cloud options lol
htb pwnbox
Animals on earth sure are weird huh
morning
It's been almost a month since I submitted my challenge
still hasn't been reviewed
my impatient self is going crazy, cuz a new coding challenge is also going to be released in a week
contact support?
@sturdy thistle sir
hello
how are we?
apparently it was in queue two weeks ago, so I should probably just wait
6 more modules to complete the CWES path
Lego
imagine stepping on that
Nnot much either
it will step on you
ahaha
EverydayTowStubbing
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
@cobalt lynx ^ should help 🙂
yay thanks
im looking to make friends here in the hacking space :3
if u guys are doing smth interesting, maybe i can tag along 😄
Hello.
Sounds weird.
Refreshing a page fixed it
Noice.
I like the Ayah in the about me.
I wrote it.
Hi chat I came here to age faster
ok boomer
I have 2 minutes someone shitpost something
Thanks
You didn't write anything you asked codex to vibecode some trash that you don't even know if it works or not yet you advertise it
asked an LLM to write my tombstone for me so now i'm going to be buried with a headstone that has half of a recpie for choc chip cookies and the rest is instructions on how to build a pipe bomb
Nice bro instructions for a pipe bomb would make me laugh in a graveyard
what do you mean? they're clearly a very competent 10x engineer, evidenced by the fact they're asking everyone in a public discord primarily filled with students who watched season 1 of Mr Robot to "gift a server" for them to host their trash on. Standard industry professional practice
Bullying in general chat again
Tbh its actually a good idea, imagine someone sensible managing logistics
Be bettee if it was train freight but due to oil barrels price increase, the transport likely still favors profitability
well ofc the american tax payer will pay for it 
why after i put the password in academy lab it's taking 1 hour to connect?
refresh and make regenerate vpn
if persists then change region
It’s Friday 
Its 5 dollar friday
Why 5 bucks? Illuminami 
Warning: remote port forwarding failed for listen port 8000 I get this thing now

dunno better to contact support then i guess
ok thank you
Hi golan
hi $whoami
no they have no idea where they would put the api key
so now i am waiting
but i dont think they will respond
Tell them to put it in the html so they can find it anytime
thats a good idea
i was thinking about putting in css
so the hackers wont find it
Display hidden
Oh visibility hidden I think it is
Yep
Display none / visibility hidden are the best bets here
hacking life
Attacking common applications htba
yes of course
long day of havana syndrome, just getting started
hell yeah, it is friday so that is great
do the hacky hacky. Next time you do a VDP sweep you should load up the burp extension "reflector" from github




@zealous charm any hacking? 
just waking up and investigating some leads from the AI I left running overnight 
anything interesting so far?
Might just be a DoS, but at least a promising lead
You working on anything fun today?

To real
pizza today?
Also nice, has apple triaged/accepted any?
4 weeks until pizza
Yeah all 11
The 12th they said they don’t think it’s a sec issue but is a bug
And had me report to WebKit
They all have dates for the fixes now
?
I’ll get a cheat meal in 4 weeks
Bodyfat %?
Abs back to showing so maybe 11
😼
I can see all 3 abs now again
6
3 on both sides

I still have another 12 weeks to be done, so I’m ahead of schedule
I feel bad for you
I’m at 2400 calories atm while cutting
2400 on a cut lmao thats my maintenance
I know lack of pizza is hurting my bug hunting
I’ve replaced pizza with ice cream atm
My app locker bypass for Microsoft was approved
Its march already though i gotta lock in aswell
It’s not about the food, but the low body fat percentage drives me crazy. I feel good at 20%
Race condition that let me sneak in to bypass the ruleset
I start hurting at 7
😅

189cm
I prefer to feel strong
Thats 4 eagles, 13 foot, a gallon of milk in your units
Says I’m 170cm

18 cheese burgers
Ahahaha
gallon of milk a day (GOMAD) diet??
187lb 170cm
Damn you must have so much muscle
8% is good for beach
Plus I got large clavicles and a smallish waste
so i look decent sized
Legs?
Going for the space marine build
Tiny or?
Yeh I got 2
Legs are decent and calves are large
lol my calves are good size
You’re BB?
Noice
For arms
Arms and calves are my strong point
BB style
bugs getting scared when they see your arms
One guy responsible for causing global protein shortage
@exotic pendant speak Deutsch?
do you?
I took 4 level of German in high school
So I can hold a convo
But not well anymore

practice with me 😛
doch
Time for gym 
have fun
Someone send me cool targets to hack
No, I have a friend who has dual citizenship and he taught me a few things
Maybe I’ll do android
I was considering safari or android after I finish up with chrome
Or fortnite
Or any MSFT, but I havent really looked at their scope
I’m doubting Apple because for a 0 click safari isn’t a lot of money
Saddly
Frosto proved RCE and got PC control and I bet they will do under $10k
I thought about hitting iMessage but I need to see how much they pay
Does it work on mobile? If so there's probably some other people who would pay "bounties" for it
Yes
iPhone is specifically what I’m targeting
What's your opinion on the Firefox CVE claude found? 
But all 11 works on allsafari
Idk I tried ai to help and it did an ok job
My prompt skills suck I guess
Butttt anthropic also has a unfiltered version
But I feel like ai will be insane in 5 years
hi frosto
It’ll replace regular sast
got my freerdp CVE published 20 mins ago
I found a bug in NTFS
waiting to see what they say
Default ntfs?
ntfs.sys
kind of
its AV:P

could be AV:N if you convince someone to load a VHD you send them but cant really justify AV:N with that
oob read
bye bye
now do DOM XSS with curl
why y'all hit me with oath and DOM xss on curl 
but challenge accepted
yooo
I got dilited
@supple plume in #community-content please.
Whatsup wild, how you been

been eeping all day cos I finally have a day without work 
has it been wild?
Sweet sleep
Kinda wanted to play some MD or something but was too tired even for that 
@zealous charm You've hit chrome, right?
do you need hardware that can run overnight or something?
Nothing special, my main laptop is a 2018 macbook pro. I also have a 2018 windows laptop
But I dont do a lot of fuzzing, that would probably require better CPUs
did you build chrome from source?
I've done linux builds on a beefy cloud VM, but otherwise they have pre-compiled ASan builds that will detect OOB read/write

how did you look at the code though? im too confused to start lmao
its been months for me
just the chromium base or?
Yeah I pulled the whole src code, then have looked at a very specific area for the last month
Not yet, but once I exhaust this area I might consider it. They have 3 tiers of memory corruption bugs: rednerer, GPU/network process, non-sandboxed/browser
V8 actually maxes out at $20k where as GPU/browser go higher
Same, not even caught up with the new meta at this point
You can always check their release notes to see what kinds of bugs they patch. Some they accept and pay out $1-2k, not all are OOB read/write
hi
Like from this week they paid $2k for "insuffient policy enforcement" whatever that means
https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_10.html
idk if mine is intended behavior or not
want to take a look in dm?
Sure
Hiya
yo mto
ayooo my guy
hey instead of DOM XSS what about this https://portswigger.net/web-security/cross-site-scripting/content-security-policy/lab-very-strict-csp-with-dangling-markup-attack
it sounds badass
and it's a similar concept

I'll add it to my list
Chat
Some prof at my uni attacked a student when the student came to apologize in his quarters
Cold world
@scenic maple
he should have faught back
for what
What do you mean attacked?

Like literally?
it was an erasmus student (exchange student) from ukraine. he was late to the lecture and prof doesnt like that and doesnt allow it, although its completely legal for anyone to join lectures at any time here in slovenia on any uni. prof started throwing chairs around the room n shi. the erasmus student did not understand whatsup, but he knew it was about him. so later after the lecture he went to his quarters to apologize only to get his ass whooped
seek inner peace guys, it is essential in this world
That profesor needs a mental health evaluation
goodbye career i hope
Hopefully
did he press charges
nah we are day 1 into it
will see whatsup
but probably not
man these boomers with their old mental models "dont be late to the lectures"
similar thing happened here once
someone tried to do something to another student, like throwing a rock or something similar
she didnt get hurt or anything so the principal said since no one was hurt shake hands and forget it
next day her father came to school to meet the principal
with his team of lawyers
and asked should we finish this in here or in court
tldr guy got expelled
and the principal was removed shortly after the respective board launched an investigation
Can confirm, i was the rock
type shi
did his lawyers jumped the principal 
prof was forced to be a prof he wanted to be a street fighter
he wanted a fight yall should have given him one
nah they were sipping coffee in his office 
Sup





