#general

1 messages Β· Page 562 of 1

sharp shuttle
#

yes

craggy ferry
sharp shuttle
#

pls hacker help me out we need someone

spark mulch
#

how're the cats today brath

craggy ferry
sharp shuttle
patent lily
#
#include <windows.h>

int WinMain() {
 for(int i = 0; i < 6; i++) {
   MessageBoxA("Are you an idiot", "System Alert", 4+16);
   MessageBoxA("Wrong answer try again", "System Alert", 0+48");
 }
 MessageBoxA("Hahaha I knew it", "System Alert", 0+64);
}
#

Coompile that

crimson elbow
#

this wouldnt compile into an exe, save it into a text file and change the extension to vbs, or use the C++ snippet provided

craggy ferry
patent lily
#

Yeah I think it's missing an argument for messagebox

craggy ferry
#

int WINAPI WinMain(HINSTANCE hInstance, HINSTANCE hPrevInstance, LPSTR lpCmdLine, int nCmdShow) {
    for(int i = 0; i < 6; i++) {
        MessageBoxA(NULL, "Are you an idiot?", "System Alert", MB_YESNO | MB_ICONQUESTION);
        MessageBoxA(NULL, "Wrong answer, try again!", "System Alert", MB_OK | MB_ICONWARNING);
    }
    MessageBoxA(NULL, "Hahaha, I knew it!", "System Alert", MB_OK | MB_ICONINFORMATION);
    return 0;
}```
#

this is fixed

spark mulch
#

lol

patent lily
craggy ferry
molten bobcat
#

Congrats now it's the worst malware ever

craggy ferry
#

πŸ˜„

glass ibex
molten bobcat
#

One mans prank is another company's million dollar reported quarterly losses

patent lily
molten bobcat
#

If you make it do anything in a loop

craggy ferry
molten bobcat
#

Like say

#

Something resource intensive

#

Like opening a chrome tab

#

Ad infinitum

patent lily
#

make it a bof

molten bobcat
#

Uh

#

This just crashes the host lol

glass ibex
molten bobcat
craggy ferry
molten bobcat
#

Malware does quite a bit more

#

I'm not saying it's not safe

craggy ferry
molten bobcat
#

I'm saying adding a loop to infinitely open a chrome tab would make the os unstable until it needs a forced reboot lmao

rancid snow
#

linux resource limits go brrrrr

craggy ferry
raven rain
#

you should make the payload melt the screen like that windows 95 virus

molten bobcat
#

Trust, windows does not give a fuck about whether or not your running code contains an infinite loop

rancid snow
#

not the gui, the screen

raven rain
#

yeap. your monitor melts

molten bobcat
#

I have a memory of a certain frog opening thousands of calculators on my host.

glass ibex
patent lily
raven rain
rancid snow
#

batch fork bombing my friends computer in the early 2000s lul

raven rain
#

but there was a virus that made the gui melt

turbid goblet
#

Work work

molten bobcat
#

Froj just closed his shell rather than stopping his program

turbid goblet
#

Work complete

molten bobcat
#

35 thousand calculator.exe processes later and my host was slowed to a crawl lmao

glass ibex
raven rain
#

what you could also do is make desktop icons and windows run from your cursor

raven rain
turbid goblet
#

I wish i was a peon in warcraft 3

#

Life would be so fun

molten bobcat
#

ZUG ZUG

spark mulch
silver forge
#

wat. wat WAHAHAAAAT STOP POKING ME

molten bobcat
#

SOMETHING NEED DOING?

#

JOBS DONE!

turbid goblet
patent lily
turbid goblet
#

When is warcraft related box coming out

rancid snow
#

dma access the display to rapidly write to a single pixel every single color shifting to opposit hues over and over until it burns out the pixel in their display

#

as a prank

patent lily
#

That would be amazing

turbid goblet
#

My current prank is reregistering user’s i dont like MFA everyday

molten bobcat
#

Granted this is solved by turning the monitor off

turbid goblet
#

Cant stop workflow. Its only ethical to just slow it down

molten bobcat
#

I bet lol

rancid snow
molten bobcat
#

Fair

spark mulch
#

if you want to subtly fuck their display

#

ok i'm not going to tell you how

#

but I will say

#

learn how hdmi works

turbid goblet
#

Just have ur rmm taskkill their main browser they are using at a random time everyday

molten bobcat
rancid snow
molten bobcat
#

Btw the PlayStation portal got an update

turbid goblet
#

Is that a real thing

spark mulch
turbid goblet
#

Yeah wtf

molten bobcat
#

It's a handheld for my PlayStation

turbid goblet
#

That shit wont fit in ur pocket

molten bobcat
#

It's not meant to

craggy ferry
#

omg i did it

crimson elbow
# molten bobcat

whats the actual purpose from this? Can't you just use the remote PS5 app control and pair your phone with a controller

raven rain
#

neither does a steam deck

craggy ferry
#

i made it an .exe

#

lets gooooooooo

turbid goblet
#

I put my steamdeck in my back pocket

molten bobcat
zealous charm
#

touch test.exe waz

craggy ferry
#

what should i add to the troll

raven rain
#

your back pocket must be ginormous

maiden anvil
#

@zealous charm do have that hockey player boot with the thicc buns I can confirm fr ong

molten bobcat
#

This lets me play my PlayStation while someone else uses the tv.

#

πŸ˜„

rancid snow
crimson elbow
#

ahh I see

rancid snow
#

I did that for a prank for my friend

molten bobcat
#

It also has all the bells and whistles of the ps5 controller

maiden anvil
#

drop a byod driver and overwrite eprocess so explorer's pid equals -1

patent lily
molten bobcat
#

I should mention I love collecting handhelds

spark mulch
#

what is a sigbus male
and is it better than alpha/

maiden anvil
zealous charm
#

ship it

maiden anvil
#

bonds

molten bobcat
maiden anvil
#

straight cheddar

zealous charm
#

CREAM

raven rain
maiden anvil
zealous charm
#

4eva

maiden anvil
molten bobcat
#

It ain't nothin to fuck with that's for sure

maiden anvil
#

and drop more cool exploits

raven rain
#

it's taking all the power in the world not to buy an AYN Thor

zealous charm
#

let's quit our day jobs and drop exploots on twitter

craggy ferry
#

guys to test my cpp code do i use a virtual machine

molten bobcat
#

I'm working with a friend on bug bounty stuff

#

I promised I would after I passed my exam

craggy ferry
#

can someone help me why is oracle virtual shwoing black screen

spark mulch
#

lol

crimson elbow
molten bobcat
#

Web

#

But I do like source code review

zealous charm
#

Get dem bounties

crimson elbow
#

neat

molten bobcat
#

It'll be a starting from zero thing for both of us anyway so

#

My first goal is to get a thank you letter lol

zealous charm
#

NASA VDP?

molten bobcat
#

Small achievable goals LETSFUCKINGGOOOOO

random aurora
#

Request my friendd

craggy ferry
#

does anyone use oracle virtualbox

raven rain
#

yes

#

plenty of people do

craggy ferry
#

when i turn it on

rancid snow
zealous charm
raven rain
#

does it say anything

rancid snow
#

I genuinely think its a great one for intro bug bounty

zealous charm
#

USDA is pretty good as well

rancid snow
#

theres literally thousands of subdomains to poke at

zealous charm
#

Most .gov is easy mode hacking

craggy ferry
# raven rain does it say anything

uh now it just says aborted with this:

Unresolved (unknown) host platform error. (VERR_UNRESOLVED_ERROR). Result Code: E_FAIL (0x80004005) Component: ConsoleWrap Interface: IConsole {6ac83d89-6ee7-4e33-8ae6-b257b2e81be8}

rancid snow
#

plus you get to learn about neat things you didnt know nasa was in charge of or provided tool for

#

like nasa maintains a global map of wildfires

umbral bone
raven rain
#

very unresolved error

maiden anvil
raven rain
#

i have no idea what this means

crimson elbow
craggy ferry
rancid snow
craggy ferry
raven rain
#

microsoft's virtualization platform hyper-v

silver forge
#

ew

crimson elbow
#

the hypervisor thats integrated into windows

#

basically the backbone of azure

craggy ferry
crimson elbow
#

have you tried running bcdedit /set hypervisorlaunchtype off

#

and restarting after?

craggy ferry
#

The boot configuration data store could not be opened.
Access is denied.

crimson elbow
#

run command prompt as an administrator

craggy ferry
#

yersyes

#

mb i realised

#

do i restart now

#

or try to turn it on again

crimson elbow
#

Yeah restart

molten bobcat
#

I've known him since long before I touched IT

rancid snow
#

nice. good luck. And Im very serious about recommending nasa as a target

zealous charm
#

imagine having people to hack with IRL sadglas

#

other than at defcon/LHEs

rancid snow
#

lil jelly

craggy ferry
#

@crimson elbow i did it and its still black

molten bobcat
#

It's still over the internet

#

But I know him in person at least lol

#

I'm getting drinks tonight to celebrate my victory yay

pallid zenith
#

Full ride scholarship btw

crimson elbow
#

if options are unchecked then you might have to boot into BIOS/UEFI and check whether Intel VT-x or AMD-V is enabled

#

Or right click on the VM and look for an option thats related to clearing the old state

devout sail
rancid snow
#

he failed πŸ˜”

rancid snow
#

im inspired by customers

jagged storm
rancid snow
#

had one last weak that was neighbors with zuckerberg and elon musk

#

and obama gave elon his first loan to start a business

#

she totally was the one that told elon tonget a degree from Stanford too

mystic harbor
#

Finished CPTS

rancid snow
#

did you pass

mystic harbor
#

I have 4 more days left

#

Before it ends

rancid snow
#

thats a good sign

silver forge
#

it is the end

craggy ferry
molten bobcat
#

Oh cool the

#

Certification package comes with a shirt?

#

That's dope as fuck actually it has the giant shield golem on it

sharp shuttle
#

he is he

jagged storm
molten bobcat
jagged storm
#

In case you're worried that only one shows up

molten bobcat
#

Actually baller shirt

molten bobcat
mystic harbor
hoary dawn
#

Just finished linux fundamentals, now I have 'Getting Started' bookmarked and 'Introduction to Pentesting' bookmarked

#

Dont really need windows/macos/android fundamentals so urgently, but will definitely go back to do em eventually 🀣

#

I just kind of want to push myself towards doing some machines, cant do much with just Linux Fundamentals being the only module ive completed so far, im sure ill have to do another 3-4 modules at least before most machines start making more sense

merry oar
#

i agree

jagged storm
#

Probably more than that lol

hoary dawn
#

yea i figured lmao

jagged storm
#

Most of the first modules are about theory

#

With some really simple basics

#

One of them will essentially walk you through nibbles, though

#

Actually wait, which path are you doing lol

hoary dawn
#

yeaa im just gonna keep reading the getting started and intro to pentesting i think after i do those 2 modules ill have a much better understanding of things than linux fundamentals given me so far, then with those 3 combined, ill bust out a few more modules

#

was just on the os fundamental path, but i just finished linux so trying to figure out which module i wanna do next is all, i dont really wanna pick up android/mac/win fundamentals right now

#

i use linux heavy so i just had to do linux ofc

jagged storm
#

Yeah, if you're a Windows power user, you're fine

#

You have some powershell experience?

hoary dawn
#

no not at all

#

well

#

is that the terminal, another word for it?

jagged storm
#

There is the old cmd terminal, but powershell is different

#

I forget if the windows fundamentals module covers it

hoary dawn
#

im good af in the terminal, like finding stuff, movin around, etc, gotta work on moving stuff, saving stuff, backing stuff up, etc little iffy on those stuff, its really just the giant ass commands

patent lily
#

powershell the only scripts that look more like black magic ancient runes than perl

hoary dawn
#

thats like the win+r command or whatever? that opens up that little box to run a command? or is that just some else

patent lily
hoary dawn
#

ah 🀦

#

lol

jagged storm
hoary dawn
#

ok yea regular terminal sucks for scripts it seems like

jagged storm
#

If you haven't touched it at all, I'd check if there's a section in the windows fundamentals module, and learn the basics

hoary dawn
#

idk though im like noob to all this, just trying to figure out where to go first from finishing linux fundamentals, so that i can actually understand all these words and actions 🀣

#

i was gonna say i dont think i seen anything todo with it in the linux fundamentals

jagged storm
#

You will definitely be using it a lot, going forward

hoary dawn
#

im gonna have to view windows fundamentals

jagged storm
#

Treat it as important as learning bash

hoary dawn
#

im understanding

#

same concept just one is default usage for one another system basically

#

so yeaaaaa ill view windows fundamentals, but i wanna do a different darn module besides android/mac after this one haha

#

im sure theyre just as important though 😭

jagged storm
#

Yeah, they're both useful for scripting, but bash is very linear, while powershell is all object-oriented

#

You can use powershell on Linux, but other than some rare tool situations, it's not really useful

ocean marsh
patent lily
#

Better to learn both

hoary dawn
#

1 liners i would be fine for me but anything i see longer than 1 line be like having me stressed bruh im like yea ok ima have to read this 10 more times to actually memorize this if i really am gonna be using this like that 😭

patent lily
#

You're trying to memorize one liners?

jagged storm
#

It's easier than it looks

patent lily
#

Just make a file with all commands you usually use (the one liners) so you don't need to memorize and focus on learning the scripting language itself than memorizing stuff

#

That will save you a lot of brain power

hoary dawn
#

thats actually smart i will have to do that, i actually do try to do text documents here and there for quick access cheat sheets but never seem to be able to keep them managed neatly enough to keep them around long enough, but ill have to change that if i wanna learn this stuff properly because man its a lot haha

#

i just wanna climb the ladder the most legitimate way possible, i dont wanna move onto anything i shouldnt be moving onto basically

#

so well, linux fundamentals is complete, now onto windows fundamentals trumpsalute

patent lily
jagged storm
patent lily
hoary dawn
#

do you guys strongly advise to continue to finishing mac/android fundamentals before moving onto other modules, Like before moving onto the intro to pentesting module or the getting started (offensive) module?

#

oh well obsidian got double whammy mentioned, imma have to use it now

jagged storm
#

Mac/Android can be ignored, unless you have something specific in mind

hoary dawn
#

ok ok i thought so

green kite
#

Mac will need you to own one

hoary dawn
#

makes sense tbh

patent lily
#

But the hard part will be separating in a way that you can find it quickly like if you have just one massive note with all commands it's not good gotta separate it for example for enumeration commands make one file for credential stuff make another file for different subjects in active directory make different files for c2 commands another file

jagged storm
#

If the CPTS path is your goal, windows/Linux are the only ones covered

hoary dawn
#

ok thats actually great insight

hoary dawn
#

im gonna restructure my entire laptop around this educational journey, trust me haha, its got no other usage besides this really

patent lily
#

What do you want to learn

hoary dawn
#

just gotta hit it with a clean reset then start fresh, got all my notes on my github page as it is so nothing would be lost πŸ˜„

#

offensive i guess it would be called?

#

thats what im interested in like the offensive side of this stuff

#

bug bounty one day πŸ™‚

jagged storm
hoary dawn
#

oof, how do i know what material cant be shared? just like anything thats in the modules basically? i didnt even think about that actually

rancid snow
hoary dawn
#

ill make it private honestly, that didnt even cross my mind

jagged storm
patent lily
# hoary dawn bug bounty one day πŸ™‚

Focus more on web stuff and windows and linux then no need to go deep into OSes for now if your goal is bug bounties learn the commands and fundamentals not going full deep dive into active directory and such you need to learn linux command line windows command line (maybe optional if you just use linux for stuff)

rancid snow
#

HTB cant claim specific knowledge, but if youre pasting any text blocks or commands with lab info its gunna be a no no

jagged storm
rancid snow
hoary dawn
#

ok ok makes sense, ill make sure to go over it when i have a chance to make sure nothing was uploaded that shouldnt be

raven rain
#

heya rat

jagged storm
rancid snow
#

I have but not dipped my toes yet.

My current project can earn me money if it works lul

jagged storm
hoary dawn
#

gonna bring my girl to work then come back to a full 6-7 hours of HTB

#

off i go

jagged storm
rancid snow
#

Ill dip in eventually, rn Ive been fixated on vuln research though

green kite
#

I hate IDOR

#

Found too many. Want to find rce now

jagged storm
raven rain
#

but IDOR creates job opportunities

green kite
raven rain
#

lol

patent lily
rancid snow
green kite
#

Or make their salary go to your bank account

jagged storm
#

If it fails in red team, I might still be able to pivot to blue team as a detection engineer

rancid snow
#

that could be neat

jagged storm
#

I would rather be writing it than defending against it, but I'll take what I can get.

rancid snow
#

the nice thing about vuln research is that if Im successful I can get paid even without getting employed for it yet.

with maldev thats called a felony lul

rugged dune
jagged storm
#

So seeing those calcs pop is an even better rush

green kite
rancid snow
#

like the intentionally vulnerable stuff might be okay for just examining a vuln class as an example, but for actually learning it the best is to go against n-days or just try your hand against real software

#

My project workflow has been testing against a mass of targets, sorting and triageing them, finding new opportunities to reduce false positive rates, and then Ill run it against some n-days to fix up any missed True Positive gaps and then just cycling back and forth as I tune things

rancid snow
#

My test comparison success rate is currently hovering around 50% detection for true positives, but hasnt found anything meaningful against my current corpus, but I also only have really hardened targets in the corpus either so 0 there could just be my stubbornness lol

#

its only been a couple weeks too. hoping to put some more time this weekend.

#

Also Im only focusing on crits/highs, anything medium severity or design weaknesses Im ignoring

jagged storm
craggy ferry
#

can i benefit from anything related to hacking (tools, softwares...) i have $36

rancid snow
rancid snow
#

any tool worth buying is at least $100 and has a free version you can use while learning.

getting the pro version of stuff before youre ready is just wasted cash

craggy ferry
craggy ferry
jagged storm
#

Academy currency, to unlock modules to learn from

craggy ferry
warm ravine
#

Hey there fellas

#

How y'all doin?

short hollow
#

yo

rancid snow
#

hows bailey doing

sharp shuttle
#

h-h-how did you.. know about.. bailey

#

screams internally

#

notices itchiness betwixt buttimous maximus

#

digs

spark mulch
#

find anything good in there?

sharp shuttle
#

nothing that a febreeze air freshener wouldnt fix

spark mulch
#

maybe some arse maggots?

sharp shuttle
#

what do you take me for, the nurgle king?

supple plume
#

I freking hate cloudflare waf

sharp shuttle
#

we all do

supple plume
#

It's designed to make what I do more difficult

spark mulch
#

cloudflare waf solely exists for cloudflare's sake

#

noone else's

supple plume
#

That's probably right

rugged dune
#

i love you man @sharp shuttle just like that 🫢

sharp shuttle
#

i love you too tarfouse

#

❀️

rugged dune
#

you are the best man

sharp shuttle
#

bro that means so much, you too brother

latent oak
#

What is up, fellow hackers

lime trout
#

wazzup

latent oak
#

Stuck in YYZ since noon

#

Won’t get home until 4:30am tomorrow it would seem

lime trout
#

oh fun

latent oak
#

Original flight delayed 3 hours, then cancelled

lime trout
#

wx?

latent oak
#

Rebooked for another that was supposed to leave at 8, but it is also delayed until 1:15

#

Hurray!

lime trout
#

weather im guessing?

latent oak
#

Yerp

lime trout
#

lovely

latent oak
#

Freezing rain from this morning delayed everything, the chaos ripples outward

lime trout
#

could always try to get into CYHZ then via or rent a car?

latent oak
#

Flights are full

lime trout
#

AC620 at 940

#

PD211 at 910

#

guessing AC1986 was tried

#

AC8230 might be another option

#

but yeah not many options

zenith pine
lime trout
#

fly to Montreal, then take Via "The Ocean"

#

its only a 17 hour train ride!

#

and cell service only exists 1/4 of the time

#

(ive done it, never again)

latent oak
#

Fuck that

lime trout
latent oak
#

I travelled that way in 1995

#

It sucked then, and you could still smoke on the train back then

rancid snow
turbid goblet
#

guys i need help who can help

#

how to gget girlfriend

rancid snow
#

you missed yesterday's session with brath on the topic

turbid goblet
#

damn

#

guess im cooked

pseudo bluff
turbid goblet
#

surely if i stay in and hack on a friday ill find one

#

i chose and AD machine πŸ™

rancid snow
#

its always easiest to find someone when youre not looking

turbid goblet
#

surely

rancid snow
#

systemd is adding age verification

obtuse fern
#

it's an optional field

potent gull
#

according to their horribly public spat about sandboxing and why strings in json and not editable by user, blah blah, it's already merged and self authenitcating

#

reading commits and comments are better than social media some day

rancid snow
rancid snow
potent gull
#

I read one the other day that said something like, "you're stupid why would you push this" reply was, because claude said so

rancid snow
#

"I know I haven't contributed in years but as the founder Ive decided to monitize all your free work for myself, you have my thanks."

"uhh well just fork it and continue open sourcing our work then."

"wait no come back...."

potent gull
#

lmao

rancid snow
#

it might actually be the fastest Ive ever seen a community migrate from an active popular tool to its replacement

#

shit was overnight

potent gull
#

pretty sure some rule was made about that now. idk, maybe it's old news but I heard a ruling how once OSS, if adopted by N or used downstream, it must remain OSS.

rancid snow
#

well that just depends on licensing

supple plume
potent gull
#

yeah, idk. I use what I can, I hate subscriptions. I would rather burn 100 hours learning how to use it, than pay another $30/m to use someone elses

supple plume
iron galleon
#

We need to add political alignment verification to operating systems

#

freedom of speech must be eradicated

#
  • anyone who criticizes me
#

It's an optional field

iron galleon
sharp shuttle
#

my views are my employers, and my politics is whatever keeps me employed

molten bobcat
turbid goblet
#

is bloodhound like necessary for AD

#

like it looks convenient, i havent used it much but i dont feel like using it if i dont need

molten bobcat
#

It's not necessary

#

But it's helpful

turbid goblet
#

eh fuck it im stuck ill just use it

iron galleon
#

soystemd

sharp shuttle
#

but you dont need to use it

#

have fun enumerating everything (:

undone fossil
#

Bloodhound is just a visualizing tool

gaunt parcel
#

@static pasture Message me πŸ™‚

turbid goblet
#

but i guess im too noob to find my next path of attack

undone fossil
#

like everything it's a tool. Use what you like Β―_(ツ)_/Β―

#

It does the job I need, and is pretty powerful with custom queries and such

iron galleon
#

Guys should I use a network enumeration tool like Nmap or write my own C2?

static pasture
lavish hull
#

@static pasturegood to see you are still alive. Hope life is treating you well man emoji_10

gaunt parcel
broken flame
#

Who trynna act like falconspy? NotLikeThis

lethal warren
#

Gosh it's bold joining a server full of hackers and trying to social engineer them....

rancid snow
#

nah

iron galleon
#

and a lot of overcompensation

rancid snow
#

so many skids are gullible as fuck

#

its actually an excellent hunting ground

turbid goblet
#

ok trying to run bloodhound crashed my computer lmao

#

oh i didnt even know that was a thing

#

TIL

sick gate
latent oak
#

Use bloodhound gang?

lethal warren
sick gate
lethal warren
#

Runs in CPU mode but ungodly slow compared to what a 5070 will do

molten bobcat
#

I use the windows Binary for hashcat

obtuse fern
#

eveerything bloodhound can do you can either do with built-in AD commands/LDAP queries or PowerView

molten bobcat
#

On my main host

uneven turtle
#

Imagine having so much aura you have to make a announcement because people are trying to be you 😭😭😭😭😭

molten bobcat
#

Cuz I have a nice gpu lol

obtuse fern
#

You know what else is nice about you cloud? your inviting personality

molten bobcat
#

Meh

rancid snow
lethal warren
rancid snow
#

and while I don't use windows host anymore I can confirm the windows hashcat version is good

molten bobcat
#

@undone fossil I passed my cert sir

spark mulch
#

i'm doing some truly magnificent farts right now. Life changing

maiden anvil
spark mulch
#

sometimes I do a fart and I think

lethal warren
spark mulch
#

G-d has given me a unique and divine gift

rancid snow
# lethal warren Okay you have convinced me 🀣

also also, serious groups that need to do big time hashcat stuff usually have dedicated crackstations. Entire machines dedicated solely to cracking that you submit your hashes to.

its definitely running native on those machines lul

latent oak
#

Sometimes, i think i might be dying

spark mulch
rancid snow
molten bobcat
#

I use it for Windows event viewer because I am a disgusting blue teamer

rancid snow
#

steamdeck is linux. If it runs in steamdeck itll probably run on your distro too

lethal warren
#

Amazon*

rancid snow
#

that gets pricey for hash cracking purposes but some people do it

rancid snow
molten bobcat
rancid snow
#

commando even has a victim installation mode for testing malware

lethal warren
#

I mean my home PC has a 5070 it's basically already optimised for hashcat

#

At least, enough for anything you are likely to see in labs and certs

spark mulch
#

i mean

rancid snow
spark mulch
#

in labs and certs you aren't often going to see anything outside of rockyou anyway

molten bobcat
undone fossil
molten bobcat
#

πŸ˜„

latent oak
#

I recently moved to AppSec

lethal warren
spark mulch
rancid snow
latent oak
#

I’m having a blast

spark mulch
#

i'm having a blast too (out of my butt hole!)

latent oak
#

Writing an AI sast, dast, and fuzzing tool

rancid snow
#

Nice. I have a similar but more focused project

molten bobcat
latent oak
#

@rancid snow say more?

lethal warren
latent oak
lethal warren
#

My goals to do an OSCP, just started HTB I tried another service a few years ago but work got busy and I ended up in a management role but I'm ... Sick of the place now I'm studying again 🀣

tardy compass
latent oak
#

@tardy compass that’s why I’m building it… i think most companies are just overlaying semgrep with claude or cursor

rancid snow
# latent oak <@277851449147392000> say more?

mostly just building a processing pipeline to offload the difficult/computationally expensive parts for AI, and then prioritizing findings, then letting AI find bugs from there.

semgrep with custom rules is doing the heavy sast portion. Ive not expanded into any dast or automated fuzzing portions yet though and im also tuning it for a particular target ecosystem.

elder hawk
#

People fall for this in 2026?πŸ’” prayge

latent oak
#

I just want to prove that the hype is bull

tardy compass
#

holy ai slop

#

no wonder curl closed their vdp lmao

rancid snow
sharp shuttle
#

the future is bleak for corpos

latent oak
#

@rancid snow I think the best value right now is that you can run traditional scanning tools, and have AI attempt to dedupe

#

Reduce the noise

lethal warren
#

Thoughts on new hacking AI automation tool being developed by THM ? Using their users for training data ...

rancid snow
# tardy compass holy ai slop

whole reason I started this project is because I wanted to form an opinion with my own experience instead of trusting what ai bros or anti ai people say about it Β―_(ツ)_/Β―

latent oak
#

Exactly

#

Same here

lethal warren
#

Seems like a bold strategy to sell someone training, to then have them train back your ai ....

tardy compass
#

not anti ai, im anti ai slop

latent oak
#

Likewise!

rancid snow
# latent oak Reduce the noise

thats like 90% of what my pipeline is doing right now. Eliminating FPs and prioritizing more likely hits for further review

latent oak
#

Same

lethal warren
#

I kinda hate the AI slop, but also the ram prices are insane now

#

And storage media pricing is next I think

rancid snow
#

Im in a cycle atm of testing it against very recent CVEs and seeing if it correctly finds the flaw and then aiming at my corpus to build up FP patterns to eliminate

tardy compass
#

plato gps have this weird connection reset built in through their load balancer for any time of host header bypass its really annoying, and other stuff. asked ai if theres any way to try a desync attack to bypass this and it said if i point my host header to 127.0.0.1 itlll work.

like bro....

rancid snow
#

it correctly finds the cve and prioritizes it about 50%~ of the time so far

lethal warren
#

🀣

latent oak
#

I’ve just built my sandbox to start fuzzing c libraries, ran it a few times and it β€œworked” in that it found some results, but it wasn’t mapping things correctly, so I had 75% false positives on the first runs… it’s a work in progress…

tardy compass
#

like ai is useful for doc hunting when im lazy and im on an api engagement with a swagger page with 500 plus endpoints but beyond that its very mediocre with anything specific or technical

latent oak
#

I literally started it on Wednesday though and been working on it here and there outside of work hours

tardy compass
#

what do you guys work as currently

latent oak
#

Skill issue

tardy compass
#

maybe

iron galleon
latent oak
#

I’m a sanitation engineer

tardy compass
tardy compass
rancid snow
molten bobcat
#

Me blue

latent oak
#

I work for a large company doing purple team stuff

rancid snow
#

yeah

tardy compass
#

good luck bro god bless

iron galleon
lethal warren
rancid snow
latent oak
tardy compass
latent oak
#

More of a passion project

iron galleon
#

ah yes

molten bobcat
#

I work for a SOC

tardy compass
molten bobcat
latent oak
#

We protect and try to break our stuff

molten bobcat
#

πŸ™

latent oak
#

Before someone else does (ideally)

tardy compass
lethal warren
tardy compass
#

not sure if i can swear here

iron galleon
#

no fucking swearing

tardy compass
#

also maybe i shouldnt say that with dv clearance

latent oak
#

Sounds like shit

lethal warren
sharp shuttle
#

all while promising vestation

#

never take a job promising shares folks

tardy compass
#

if it helps my boss takes bribes for promotions

latent oak
#

@sharp shuttle speaks truth

tardy compass
#

legit saw someone go into his office and leave with white stuff on his lips

latent oak
#

Been burned on this

sharp shuttle
#

happened to me twice now

latent oak
#

Laid off with worthless options

molten bobcat
sharp shuttle
#

they never intended to pay the options out

#

its sick

lethal warren
#

New management are taking in people from 3rd world countries on a vissa so they can pay then shit wages - they are grossly unqualified and it's my job to clean up their mess now

latent oak
#

Show me cash money

rancid snow
#

only take shares if its a startup, you get it right away, and youre willing to gamble

iron galleon
#

πŸ˜‚

latent oak
#

It was a startup, I took shares in lieu of what I should have been paid, and it all went to shit

tardy compass
#

tell you wnat i knew a lady, got a management degree in cyber. always the management mfers and she knew nothing about what she was doing. ended up getting fired after she punched one of my colleagues in the face

rancid snow
lethal warren
latent oak
#

We went tits up before the first vestment period ended

tardy compass
#

its ok guys if youre under 30 you still have a chance

latent oak
#

lol, too late for me

rancid snow
#

πŸ’€

tardy compass
#

haha no but youre fine at any age

#

well unless you live in usa

#

then youre cooked

latent oak
#

Canada πŸ™‚

rancid snow
#

as long as Im learning I can clinge to copium

latent oak
#

… america’s hat

lethal warren
#

I'm 30 but not that big a stretch to go from tech to .... Different tech

sharp shuttle
#

we're 30, we are new 50

#

nobody hires us mang

iron galleon
tardy compass
#

cananda is chill i have a client with a canadian manager and an indian dev team and the time zone difference is sooo annoying. illsend an email to her and shell contact the indian team which will only get back the next day so one email takes like 2 days to get a proper response

#

also their accents are so thick

#

i thought a guy was choking on gasoline

#

but he was trying to pronounce cookie

lethal warren
latent oak
#

The Indians or the Canadians

sharp shuttle
latent oak
#

It’s the maple syrup

iron galleon
tardy compass
#

ive never heard a canadian with a thick accent

latent oak
#

Gives us the smooth voices

tardy compass
#

legit have the softest voices

sharp shuttle
#

go north or west

latent oak
#

North! Beyond the wall

#

You will find us

tardy compass
#

guys become penetration tester is good fun

#

two thumbs up

tame gust
#

Isnt canada just india with extra steps !?

tame gust
#

No

iron galleon
rancid snow
#

I submit apps and get occasional interviews but market rough for entry pentest

tardy compass
latent oak
#

Uhm… extra steps?

tardy compass
#

usa you wont find anything

#

uk is good

tame gust
rancid snow
#

too brokie to move

#

but im def open to relocation for jobs

tardy compass
#

just had someone dm me asking me to basically commit terrorism lol what

latent oak
#

Literally no idea what you’re talking about, sounds like shit is coming out of your mouth

lethal warren
#

Just... Discord in general 🀣

tardy compass
#

whats your skills like, do you have any experience

rancid snow
#

ive been stubborn about applying to them but I might have to bite the bullet and suffer

tardy compass
#

i should delete that actually

tardy compass
rancid snow
#

good enough for cpts and oscp, but 0 employed pentesting experience.

got a nasa thank you letter but I dont really do bug bounty stuff which has hurt me in interviews

latent oak
#

Fastest way to be ignored, be a fucking moron

west venture
rancid snow
#

honestly I think one of my biggest issues is I get interview deer in a headlight syndrome and I drop 50 iq points

turbid goblet
#

who excited for kobold

#

i love easy boxes

rancid snow
#

ye

latent oak
#

@rancid snow the struggle is real

tardy compass
#

bro quit bitching and get job already

#

with oscp is easy

rancid snow
#

lol trying

sharp shuttle
tardy compass
#

bro i thought you were barebones

alpine pumice
#

job market blows right now, has blown for a while now

meager kernel
#

Hi

tardy compass
#

bro job market is booming what you guys talking about

#

so many americans

rancid snow
#

gtg cya everyone

latent oak
#

I researched all my interviewers. Read any social media I could find, blog posts, linked in, etc… prepped for the questions I figured they might ask…

tardy compass
tame gust
#

if you dont understand what someons saying, does it means you the moron or the other person

tardy compass
#

if they asked something you dont know. just think out loud of how you would research it to find out

west venture
lethal warren
#

You know your shit, I know I am shit we are not the same

alpine pumice
latent oak
#

lol

molten bobcat
#

Chats getting philosophical today

west venture
#

That's what I agreed to

#

Bc they won't hire

tame gust
lethal warren
molten bobcat
#

I like to change it up sometimes

tardy compass
molten bobcat
#

Vault Boy the mascot for VaultTek

#

Yes

tame gust
#

imagine this, you hire a firm for an audit to find their engineer using burp with mcp to hook an llm

#

how pissed would you be

tardy compass
#

oh theyre not here

sharp shuttle
tardy compass
#

AI red teamer?

#

whattt the john

west venture
#

It's module

tardy compass
#

no way bro

sharp shuttle
#

its an industry term now

tardy compass
#

im going to call myself AI red teamer that sounds like im robotic bro thats so sick

tame gust
#

lmao

#

yo my grandma died but her wish was always to find an RCE on this repo

#

do your thing

tardy compass
#

grandma was techy

tame gust
#

she always sang HTB root flags to us before sleep

west venture
#

I keep finding 0days in old ass phone's specially the bootROM, but even though they can be used for RCE at the highest possible privilege level. Non of them are accepted. Huawei just keeps ignoring all my emails.

tardy compass
#

i wonder why

#

bro should report to blackberry next

west venture
#

The one they did respond to they said bc the boot rom is not patchable they aren't gonna pay me and said thanks anyway

tame gust
#

you'd be supprised how many routers i opened and got an RCE one

#

to find out you can just do basic command injection

west venture
#

Oh yeah same

tame gust
#

and i gave up

tardy compass
#

zyxel ones are pretty good

west venture
#

I have RCE on all my ISP routers

#

At home

tame gust
west venture
#

If you find their firmware you're basically in lol

tame gust
#

like i would like to fking plug it directly to my firewall and not be limited to a 1GB port

#

thank you

west venture
#

Also look for UART pins. That's an automatic root shell

tame gust
#

its like either pay up 8k a month or you cannot have that

tame gust
tardy compass
#

something sounds wrong about allthat but im toodrunk to call it out haha good night guys its been fun

tame gust
#

so imma just dump the nand pages

tame gust
#

and translate it to something binwalk can understand

west venture
#

I recently found hardcoded admin creds in a firmware file and used that to log into an admin page which had a command injection vulnerability and used that to escalate privileges, change the root password and log in through telnet lol.

molten bobcat
#

I'm making tacos

tame gust
west venture
#

Loll

tame gust
#

the modul was C1N

#

its pricy for a shitty software but the hardware was good

west venture
#

Huawei routers have the most unhinged shit

sick gate
#

Tell me more

tame gust
molten bobcat
#

That's it, I'm having a smoke and cooking dinner lol

west venture
#

If you look through the source code for their web interfaces like JS and HTML in their firmware file, and translate the Chinese comments to English, you'll find the most unhinged shit ever.

tame gust
#

best thing about cave diving is you dont do it

sick gate
tame gust
#

bro imagine

heady sage
#

hi :3

sick gate
#

I've done some decent swim-throughs but caves are ridiculous

tame gust
#

imagine waking up and say lemme squeeze my self in

sick gate
#

Same

tame gust
#

there's something worst

#

they call it "hobby horsing"

molten bobcat
#

Da prep

tame gust
molten bobcat
#

Cookin

sharp shuttle
#

cloud is a vegetarian now

#

he sustains off limes

west venture
tame gust
#

Cloud if there'snt much seasoning on that meat, we finna ban you

warped plank
# tame gust

To be fair: nothing calmer than feeling weightless in a dark place that nobody's ever lived to tell stories about

tame gust
west venture
#

Maybe...

sharp shuttle
#

cloud is vegan is now canon

sick gate
molten bobcat
#

I cook better than a lot of people lol

ocean marsh
#

ok I answered to the wrong message

#

ban me

sick gate
sharp shuttle
turbid goblet
#

its the first time im watching netflix on my tv in like 2 years and apparently netflix has ads?

tame gust
# molten bobcat

that look dry, and not enough seasoning ... also the papers finna be a bit raw ...

warped plank
molten bobcat
tame gust
tame gust
molten bobcat
#

Quite literally, hold up let me cook

west venture
#

I used to be vegan for like 7 days bc of the suffering of the animals, but I could not resist the urge and accepted that I am a bad person and went back to meat.

tame gust
ocean marsh
molten bobcat
sick gate
ocean marsh
#

same kek

tame gust
ocean marsh
#

I like climbing and I already think that climbing is crazy

#

but cave diving

#

what the hell

molten bobcat
#

SO YEAH, GOOD EYE

sick gate
#

Onions first

tame gust
#

cloud thorw onions first and peppers then add the meat

ocean marsh
#

These dudes are so obsessed with opsec that they go cave diving so people dont even find them dead

tame gust
#

and use some olive oil

#

a lot of it

molten bobcat
#

I did

obtuse fern
#

I throw onions at cloud

#

they keep falling back down

west venture
#

Cloud uses water instead of oil

molten bobcat
#

Y'all ain't about to trash talk my cooking when y'all don't know how to deglaze a pan

ashen plume
#

Hi, how are you? How is everyone? I'm a beginner passionate about cybersecurity.

sick gate
#

If I go under I hope it's one of these guys fault!!

sick gate
west venture
tame gust
obtuse fern
tame gust
tame gust
sick gate
#

If a shark attacked me I would simply rotate it

tame gust
#

the juices from the meat will be enough

sharp shuttle
west venture
obtuse fern
#

also shark noses are extremely sensitive

sick gate
#

Any more from the peanut gallery?

sick gate
west venture
#

Once they smell blood you're finished

tame gust
#

damn fish can smell semll ?

#

crazy

west venture
#

A great white will fit a whole human in its mouth lol

tame gust
#

what next they see color ?

sick gate
#

Anyway here's some clownfish and a decorator crab I saw a few years ago

molten bobcat
west venture
molten bobcat
#

Notice how after cooking the onions aren't raw anymore

west venture
#

Notice deez

tame gust
#

onions still raw, that beef is still dry

#

and the pepers are still NOT COOKED ENOUGH

molten bobcat
#

Cope

tame gust
#

you gotta roast your pepers

sick gate
#

Cloud is baiting

tame gust
#

Cloud cant cook

molten bobcat
#

I'm not, there's nothing wrong with my food lmao

sick gate
west venture
#

Cloud if you are discord smart you'd know by now that you're being trolled by them

#

Yeah but it's a scale

sick gate
#

Cloud makes bread by putting all of the ingredients in the oven separately then combining them

west venture
#

They can smell a person bleeding from very far away

molten bobcat
#

True

sick gate
tame gust
west venture
sick gate
#

There is far more that goes into a shark attack than smelling blood

west venture
molten bobcat
#

Sharks more often than not think we're seals due to our shadows in the water

tame gust
#

silm shady once said dont do drugs, so i can have more

molten bobcat
#

Either that or we panic and move like injured fish

west venture
#

If you present yourself as food a shark will attack you

molten bobcat
#

Which make for quick bites

west venture
#

Also crocodiles will attack you regardless of how you present yourself

molten bobcat
#

Yeah they don't give a shit

#

Theyve spent the past few thousand years not giving a shit

sick gate
#

Not freshwater crocs

west venture
heady sage
west venture
#

Gustavo Fring?

heady sage
#

What is this shit Arkham?

west venture
#

I swear bottom left is Gustavo Fring

sick gate
#

I think it's al sharpton

ocean marsh
sick gate
heady sage
ocean marsh
#

thanks vader

latent oak
#

I’ve been in this fucking airport for 11 hours… but it’s okay because I got a $30 voucher so I could buy a goddamn sandwich and tap water

#

The airline is so considerate

terse dirge
#

@terse dirge

latent oak
#

Did you summon yourself?

terse dirge
latent oak
#

Power move

ocean marsh
#

@terse dirge

terse dirge
latent oak
#

Deb!

terse dirge
ocean marsh
#

yayyy

#

AD is so goated

#

having a jolly time in AD

#

always

latent oak
#

lol… nearly 30 years old now

#

Came out in 2000

obtuse fern
turbid goblet
#

idk ive been thinking about it recently guys. i think i might just go to valhalla

ocean marsh
#

Yeah I also had to search that

#

bro has cpts

#

never heard about that, hackthebox should probably make 2 mini modules about it

#

@lusty forum

#

skid

lusty forum
ocean marsh
#

he just called me a ho

#

wtf

lusty forum
#

same

ocean marsh
#

where's golam

#

golam

#

get a load of this guy

#

@lusty forum cpts when

#

cybersecurity 2026 biggest loss

#

so much potential πŸ’”

#

1 minute of silence in the chat

#

@lusty forum its okay being a gigolo, but you can part time cyber if you want to

#

just saying

sharp shuttle
#

bro broke his own moment of silence

ocean marsh
sharp shuttle
#

we were respecting it

ocean marsh
#

I'm sorry guys

raw prism
#

How Can I Earn Money?

ocean marsh
#

I'm just a yapper

ocean marsh
#

mods remove this guy's badge

raw prism
ocean marsh
#

you do you my man

raw prism
#

most earning a man can make in OF?

#

solo*

sharp shuttle
west venture
turbid goblet
#

send me those

sharp shuttle
#

idk the meta is going back to artists who draw lmfao

west venture
#

Meta on OF? Brath how do you know that? sus

ocean marsh
#

I dont think so

raw prism
ocean marsh
#

LMFAO

sharp shuttle
ocean marsh
#

I just wanted to prove that you are wrong

#

I always feared CPTS more than CAPE

lusty forum
ocean marsh
#

CPTS is scary

#

CPTS has web

#

web scary

#

me dont like web

lusty forum
#

i love web

west venture
#

web boring

lusty forum
#

web fun

ocean marsh
#

cape has ad

#

ad cool

#

ad jolly

#

good time on ad

lusty forum
#

ad sucks

ocean marsh
#

stfu wyv

#

never say anything again

#

but yeah I really fear cpts more than cape

sharp shuttle
#

idk man, i think AD is basically evil incarnate, i absolutely hate it

west venture
#

Just wait for another month I will be getting all the certs HTB offers and if I still don't get a job it's on this platform.

ocean marsh
#

not even a joke

raw prism
#

hey answer this you are in a park watching a child talking to his Dad and telling him that I am trans but when u watch him u say him talking to no one . WHY?

ocean marsh
#

dude YOU ARE CALLING ME UNHINGED, YOU'RE THE ONE WHO INTRODUCED ME TO AD

#

That's YOUR fault

#

shame on you

#

I used to hate AD

raw prism
ocean marsh
#

nevah

#

nevah evah