#general

1 messages · Page 582 of 1

west venture
#

A week? My guy I solve a box in 2 hours

hardy frigate
#

What I've done in the past / what I've trained in

west venture
#

If it's easy

meager kernel
turbid goblet
#

i do it in 3minutes if its easy

west venture
#

Alone

meager kernel
#

I wish for a day when I'm better at this

turbid goblet
#

alone

alpine pumice
#

depends on the box really

hardy frigate
cerulean bloom
meager kernel
meager kernel
#

Just wanna be as good as him someday

molten bobcat
#

I'm just okay at defensive stuff

alpine pumice
#

the more i learn the more i realize i'm just bad or mediocre at everything

warm dome
alpine pumice
#

i know stuff, but i know i don't know a lot more

#

so i'm a noob

west venture
#

I don't even know stuff

turbid goblet
#

COME TO BRASIL

sick gate
alpine pumice
#

You can never know it all

sick gate
#

Exactly

rose onyx
west venture
#

The government is logging our messages btw

ocean marsh
turbid goblet
#

fixing the economy

ocean marsh
#

Are you brazilian kami?

turbid goblet
#

im not

#

i just love sayng come to brazil

ocean marsh
#

Dont come to brazil

turbid goblet
#

why

ocean marsh
#

I mean dont come here to live

#

To visit

#

Sure

turbid goblet
#

oh yeah definitely not live sorry lol

ocean marsh
#

@meager kernel

#

Dont give up

meager kernel
#

Not to

ocean marsh
#

We still have a long way to go

#

And boxes are hard

broken flame
#

Do a kickflip

ocean marsh
#

Dont measure yourself on boxes

#

Dont compare yourself with your teammates

#

You got this

cerulean bloom
#

yeah, echoes has years of experience

ocean marsh
#

I still feel like shit when I do boxes

#

So true

#

Boxes are cool to learn new things

#

And you shouldn’t expect to know how to solve all of them

#

Im sure you learn a fuckton specially when it takes you a lot of time

#

Approach them as a learning resource and don’t worry if it takes you a lot of time to solve them

#

Most of them indeed

#

I agree

#

That’s why I like to follow the tracks

#

Like AD one

#

Bc they are picked to be there

#

If its a seasonal box its worth the time just to have a cooler badge here

#

Im joking

#

Bitch

#

Lmfaooo

#

But yeah, dw overall

#

Meoware time

#

Jesus

#

Idk how that translates to kg

#

But ik thata a lot

#

Fucking hell bro

glad crystal
#

I just ate some chicken and mashed potatoes.

ocean marsh
#

I forget we are on different timezones

#

10:30pm here

glad crystal
ocean marsh
#

Sure bro

#

Whatever

gaunt gale
#

I just ate a tsunami combo

ocean marsh
#

This is how zumi treats his day ones

frail turtle
#

I haven't brushed my teeth in like 2 weeks

ocean marsh
#

I love you

#

Pookie bear

ocean marsh
meager kernel
#

Thnx man, im just trying

ocean marsh
#

Lets go get itt kratooooos

#

What is that

sick gate
#

First world problems: can't have two enterprise subs on one account

ocean marsh
#

You can give me one

#

Dw

sick gate
#

Okay I just need your entire identity

#

Thank you for attending my humblebrag

west venture
#

Guys even 1000+ years from now, in spacecrafts, they still use sql btw

ocean marsh
#

They will use glorpql

sick gate
#

Wow that's not very nice

ocean marsh
#

Bogos pinted

#

Interesting, i am a student

glad crystal
#

One is for my college's National Cyber League team.

ocean marsh
eternal mango
#

Don't advertise

ocean marsh
#

Should i go evil again?

sick gate
#

Result of an ugly soul!!!!

glad crystal
eternal mango
#

Real the #rules, remove the message

sick gate
#

Its okay

#

We all learn and grow

ocean marsh
#

Only good souls have cape

#

Boooo

eternal mango
#

Thank you.

turbid goblet
#

1

glad crystal
sick gate
#

🙌

ocean marsh
#

Damn both

west venture
#

Goblin constantly reminds me of the Vikings

ocean marsh
glad crystal
#

Wasn't trying to steal anyone from HTB. That league is seasonal I'm pretty sure and it's only for students and minors.

ocean marsh
#

Are you a cs student?

glad crystal
#

Yes

ocean marsh
#

Nice which semester

glad crystal
ocean marsh
#

Calling me a kid is wild

ocean marsh
#

Sounds cool

glad crystal
#

It's really not. I can audit an entire company lol

sick gate
#

I did a master's and it sucked but it instantly netted me a 35k pay rise so that was nice

ocean marsh
#

I’m a cs student

#

College sucks

ocean marsh
sick gate
#

A lot of my cohort didn't get anything though

#

Yeah

glad crystal
#

College taught me how to do full lifecycle audits using the RMF and other benchmarks like the ISO/IEC benchmark (which the NIST maps to).

turbid goblet
#

college taught me how to body 40 natty lights a day

ocean marsh
#

College taught me I should skip classes to hack

glad crystal
#

Certs aren't super hard to get if you have the knowledge. Just have to pay for the tests.

sick gate
#

I wouldn't advocate for a cyber degree unless it's tied to a job requirement and you already at least work in IT

glad crystal
#

That would be relative to your expertise, I guess.

turbid goblet
#

yeah zumi u suck

#

get good

glad crystal
eternal mango
glad crystal
eternal mango
#

I'm not a moderator

#

Last time I tried to ban someone

#

I banned someone else

sick gate
eternal mango
rancid snow
sick gate
#

Friendly fire

glad crystal
eternal mango
#

I mean technically I could

#

but I don't want to risk it

#

so I am not touching the / key ever again

rancid snow
#

werent they like a mod too or something you banned lol?

eternal mango
#

Unless it's to flex my yap

#

No it was echoes I think

glad crystal
#

@eternal mango I would be happy to DM you the page that has the NCL on it.

eternal mango
#

I went to ban someone else, and it auto corrected to echoes

#

NCL 2026, $45?

glad crystal
#

Yes

eternal mango
#

Ask a mod please

glad crystal
#

Again, it's restricted to students and minors.

#

Up to 1 year post-graduation.

ocean marsh
#

My goat

#

So humble

glad crystal
#

They outline who is eligible on the page.

ocean marsh
#

So humble

turbid goblet
#

are minors even allowed to have discord anymore

#

or windows

glad crystal
#

And the rules on sharing league challenges are strict just like HTB active machines.

rancid snow
#

arrogant and yumi

eternal mango
#

Right, but please ask a mod

glad crystal
#

Fair.

cerulean bloom
eternal mango
#

It's still promoting another platform, and a paid platform at that

cerulean bloom
#

hru

ocean marsh
#

Barbecue beer sauce 🔥

eternal mango
#

Hey DonutMaster 🙂 All good thank you, just in bed with Rick and Morty on for a bit before bed. How're you

turbid goblet
#

ur in bed with a rick and morty?

#

nice goblin

eternal mango
#

Double trouble

west venture
cerulean bloom
#

no ping

ocean marsh
#

Not my goat, so rude

#

Zumi

#

Barbecue beer sauce

rose onyx
#

Y no yumizumi?

cerulean bloom
#

whyyy

ocean marsh
#

I’m not a kid lil bro

#

Watch your mouth

eternal mango
ocean marsh
#

Dont even joke

glad crystal
#

I finally decided on my next laptop purchase. Instead of Framework Laptop 16, I am going for System76 Serval WS.

snow wraith
#

YumiZumi the army man

cerulean bloom
#

this isn’t a ping

glad crystal
#

ping 8.8.8.8

tough oyster
#

that can't be the real payload hahahaha

rose onyx
#

But y? Who said?

snow wraith
#

I hv read tht article bruhh

#

The podcast one

ocean marsh
#

After the podcast he lost the humble spirit

glad crystal
ocean marsh
#

Lmfaoooooo

#

Old people these days are pissing me off

cerulean bloom
#

wat

glad crystal
#

tracert, what?

rose onyx
tough oyster
broken flame
#

I wish i had a thinkpad

cerulean bloom
#

hmm

ocean marsh
cerulean bloom
#

yes sir

rose onyx
#

Okay boomer

ocean marsh
#

Good for you

#

I am

#

Jk

cerulean bloom
#

we all balding

ocean marsh
#

True

cerulean bloom
#

thats why I’ll stop at cpts /j

ocean marsh
#

Never doing cpts

#

That will stress the shit out of me

#

Web😭😭

ocean marsh
#

I feel dumb overall

turbid goblet
#

yeah web cooks me

cerulean bloom
turbid goblet
#

is a web cert first like viable

cerulean bloom
#

we must learn from @supple plume

ocean marsh
#

Fuck

#

Wront message

cerulean bloom
turbid goblet
#

👀

ocean marsh
#

Lets do it together baby girl

cerulean bloom
snow wraith
cerulean bloom
ocean marsh
#

I want to do osep too

cerulean bloom
#

echoes the web goat

ocean marsh
#

Im so jealous

#

Stooooop bro

#

I need to catch up

cerulean bloom
#

noice

ocean marsh
#

Jfc

turbid goblet
#

one day ill have read all of academ

ocean marsh
#

Take a year break or so

#

Retire idk

eternal mango
#

heap is evil

#

I never got my head around it

turbid goblet
#

i think ima just learn astral projecting and do academy in my dreams or something

cerulean bloom
snow wraith
#

Introduction to Cyber Security

#

Back to basics

cerulean bloom
ocean marsh
#

Skid

turbid goblet
#

i need to learn networking

ocean marsh
#

Bruh

#

The boy who cried niche hacking

#

Wtf is that

#

Damn

#

There are levels to this

eternal mango
ocean marsh
#

That’s why im retiring, too many sweats

#

Im getting mad

#

Not even joking

snow wraith
#

Fault Injection is also under Physical hacking ryt? not sure

ocean marsh
#

Skipping oscp and going straight for osep bc its much cooler

#

Jk

#

Thank god

snow wraith
turbid goblet
#

im skipping to nationstate level

ocean marsh
#

Employers dont exist

#

They are a myth

#

I cant even do oscp rn

#

So nothing to worry

#

Dont bruh me

#

Pipsqueak

rose onyx
#

Bruh has cape not cpts

ocean marsh
#

Yeah

#

Web is scary

#

I dont joke

#

When i say cpts is more scary

#

Than cape

#

For me

eternal mango
#

Face your fears

#

Smash it

rose onyx
#

Cape way harder than cpts

ocean marsh
#

I will do, I’m just having a lot to do regards college

turbid goblet
#

drop out

ocean marsh
#

Pandas with python💔 💔

#

Just let me hack

eternal mango
#

Snakes and Pandas are not good bed fellows

#

God damn it

#

You beat me to it

ocean marsh
#

Lmfaoooo

#

He’s always faster

eternal mango
#

That's what she said

ocean marsh
#

Old man still has some speed

#

I’m not mentioning why we call you yummy😫😫

glad crystal
ocean marsh
#

You should be proud of that

ocean marsh
#

Dont mention that

#

In my presence

eternal mango
#

..where did Python hurt you

glad crystal
# ocean marsh Sybau

I am LITERALLY taking applied statistics in STEM right now. I just wrote up 2 scripts for auditing using data science lol.

rose onyx
eternal mango
#

Yes

#

Yes

#

Yes

rose onyx
#

Yes

ocean marsh
#

I only think about hacking

#

Thats all

glad crystal
ocean marsh
#

Bruh

#

Yeah for sure i guess

#

Im too old for that👴

eternal mango
#

Python is not Ruby

#

That's my argument

glad crystal
ocean marsh
#

Thats for sure a fact

#

Python is indeed not ruby

glad crystal
#

.rb ftw

ornate ibex
#

Morning

eternal mango
# glad crystal .rb ftw

I had a bad experience with Ruby, it confused the shit out of me.. I still got the job done, but I swore never to let it touch me again

ocean marsh
#

Where is the caveman code

eternal mango
#

..so the next time, I was the aggressor, and regretted it all the same

#

It just feels weird to me for some reason

glad crystal
rose onyx
ocean marsh
#

Omfg

#

The take base64

#

will always get me

turbid goblet
#

i code in brainfuck

ocean marsh
#

I believe you

eternal mango
#

I'm so sorry to hear that, are you ok?

#

Excellent

glad crystal
#

import pandas as pd
import numpy as np
import matplotlib.pyplot as plt
import seaborn as sns
from scipy import stats

def run_single_audit(file_path, label, target_col, baseline, comparison_type):
# ---PHASE 1: Data Ingestion---
column_names = [target_col, 'group'] # Adjust these to match your file's structure
df = pd.read_csv(file_path, header=None, names=column_names)
data = df[target_col].dropna()
df['Source_File'] = label

# ---PHASE 2: The "A to Z" Math Engine---
n = len(data)
compliance_rate = (df[target_col] < baseline).mean() if comparison_type == 'less' else (df[target_col] >= baseline).mean()

stats_results = {
    "Mean": np.mean(data),
    "Median": np.median(data),
    "Mode": stats.mode(data, keepdims=True).mode[0],
    "Variance": np.var(data, ddof=1),
    "Std_Dev": np.std(data, ddof=1),
    "Range": np.ptp(data),
    "Std_Error": stats.sem(data),
    "CI_95": stats.t.interval(0.95, n-1, loc=np.mean(data), scale=stats.sem(data))
}

# ---PHASE 3: Individual Graph---
plt.figure(figsize=(8,4))
sns.histplot(data, kde=True, color="skyblue")
plt.axvline(baseline, color='red', linestyle='--', label=f'Baseline: {baseline}')
plt.title(f"Distribution: {label} ({target_col}")
plt.legend()
plt.show()

# ---PHASE 4: Individual Printout---
ci_low, ci_high = stats_results['CI_95']
margin_of_error = (ci_high - ci_low) / 2

print(f"\n" + "="*80)
print(f"\n--- INDIVIDUAL AUDIT: {label} ---")
print(f"-"*80)
print(f"Samples Examined:       {n}")
print(f"Control Compliance:     {compliance_rate*100:.2f}%")
print(f"\n" + "-"*80)
print(f"Mean:       {stats_results['Mean']:.4f}")
print(f"Median:     {stats_results['Median']:.4f}")
print(f"Mode:       {stats_results['Mode']:.4f}")
print(f"Variance:   {stats_results['Variance']:.6f}")
print(f"Std_Dev:    {stats_results['Std_Dev']:.6f}")
print(f"Range:      {stats_results['Range']:.4f}")
print(f"Std_Error:  {stats_results['Std_Error']:.6f}")
print(f"\n")
print(f"CI_95:               ({ci_low:.4f}, {ci_high:.4f})")
print(f"CI_95 (ROUNDED):     ({ci_low:.2f}, {ci_high:.2f})")
print(f"margin_of_error:      +/- {margin_of_error:.4f}")
print("="*80)


return df, stats_results

def master_comparator(file1, file2, target_col='latency', baseline=2.0, comp_type='less'):
# 1. Audit File 1
df1, stats1 = run_single_audit(file1, "FILE A", target_col, baseline, comp_type)

# 2. Audit File 2
df2, stats2 = run_single_audit(file2, "FILE B", target_col, baseline, comp_type)

# 3. Master Comparison
combined_df = pd.concat([df1, df2], ignore_index=True)

# Stats: Independent T-Test (Is there a significant difference?)
t_stat, p_val = stats.ttest_ind(df1[target_col], df2[target_col], equal_var=False)

# 4. Comparison Graph (Box Plot)
plt.figure(figsize=(10, 6))
sns.boxplot(x='Source_File', y=target_col, data=combined_df, hue='Source_File', palette="Set2", legend=False)
plt.axhline(baseline, color='red', linestyle='--', label=f'Baseline: {baseline}')
plt.title(f"Master Comparison: File A vs File B")
plt.legend()
plt.show()

# 5. Final Verdict
print("\n" + "="*80)
print("     MASTER COMPARISON VERDICT      ")
print("-"*80)
diff = stats1['Mean'] - stats2['Mean']
print(f"Mean Difference: {diff:.4f}")
print(f"P-Value: {p_val:.4f}")
if p_val < 0.05:
    print("VERDICT: Statistically Signficant Difference Detected.")
else:
    print("VERDICT: No Signficant Difference Between Files Detected.")
print("="*80)

Execute

master_comparator('MassiveAudit.csv', 'MassiveAudit2.csv', baseline=2.0)

eternal mango
#

Holyfudge

glad crystal
#

LOL

eternal mango
#

Damn give us some warning

glad crystal
#

I can't share pics 🙁

ocean marsh
#

Wrong tab

eternal mango
#

lol

ocean marsh
#

Cealddd

terse dirge
#

Hallo

terse dirge
ocean marsh
#

the kubernetes guy

glad crystal
#

I don't use claud and that's a fully functioning script.

eternal mango
#

If you were trying to get people to love Python, I don't think you're turning many heads there

glad crystal
#

It creates graphs and everything.

rose onyx
#

Use code blocks

glad crystal
#

It looks cleaner in my PyCharm IDE lol

terse dirge
ocean marsh
#

Lmfao

terse dirge
#

Somethin to do with PVC volumes

eternal mango
ocean marsh
#

Based64

terse dirge
#

You could do it. Learn golang vro

rose onyx
ocean marsh
#

Omg bro same

terse dirge
#

15 minutes isn't anywhere near enough time 🥀

ocean marsh
#

So hard

terse dirge
ocean marsh
#

15m is way too much

#

Imp

#

Imo

rose onyx
terse dirge
#

This is a full tutorial on learning Golang! From start to finish in less than an hour, including a full demo of how to build an api in Go. No fluff, just what you need to know.

0:00 Introduction to Golang
6:25 Constants Variables and Basic Data Types
13:14 Functions and Control Structures
19:30 Arrays, Slices, Maps and Loops
26:36 Strings, Rune...

▶ Play video
ocean marsh
#

1hour?

#

Too much

#

I cant do that

rose onyx
eternal mango
#

Working with data structures is just nice in Python, and surprisingly (nobody will believe me) if you know how to put the introspection helpers together, in Java too. Excluding lower level languages, best two in my experience.

terse dirge
ocean marsh
#

Give me a tiktok or something

#

15s or less

glad crystal
#

Anyone here ever messed with Firebase?

ocean marsh
#

No, that guy is dangerous

terse dirge
#

Not with that attitude

eternal mango
ocean marsh
#

Dont mess with him

glad crystal
rancid snow
#

I mentally associate firebase with vibecoders that have no business vibecoding and leaking all their user data

ornate ibex
eternal mango
#

Well, they should've reviewed their code

terse dirge
#

It's really a mentality thing that you learn the more you do it tbh.

eternal mango
#

Firebase is awesome, the og pubsub

glad crystal
#

Poor sanitization.

terse dirge
#

Start with python then go 🔥

rancid snow
rapid badger
#

not everybody puts the time to learn painting. People dont just wake up and know how to do it .

rancid snow
#

that and supabase

glad crystal
#

The good news is, once you learn one language... recognizing syntax differences and structures comes pretty easy.

terse dirge
#

Python allows for unoptimized and hackier code than go, once you have an idea of how to structure your projects and solutions then you can learn go to write fault tolerant and type strict code

eternal mango
#

Messed with PartyKit recently.. completely painless

warped plank
terse dirge
#

The type strictness of go is both a blessing and a curse

#

That's why you keep doing it vro

ocean marsh
#

I only code because college forces me to

#

But I'm enjoying malware code

glad crystal
#

It takes practice. You should probably read about data types, variables, boolean logic, loops, etc.

eternal mango
#

That's where the adaptability comes in clutch.. like you said, the patterns are (more or less) the same

glad crystal
#

Lot of topics to get a decent grasp of it. But it's essential for pen testing bro.

rancid snow
eternal mango
#

Doesn't take long to drop in from one language to another if you're experienced enough

ocean marsh
#

i "learned" c as my first lang

glad crystal
#

Coding is puzzle solving 🙂

terse dirge
glad crystal
terse dirge
#

Not always. You can always look at the docs and stack overflow

eternal mango
#

..you can still have artistic flair too though.. sure, it's logic, but you can always leave your mark

warped plank
eternal mango
#

..like, making it completely weird and messed up, to curse the person after you

terse dirge
#

Trail and error

eternal mango
#

or so elegant that you cannot comprehend how you even achieved the task

rancid snow
ocean marsh
#

is

#

C is still one my favorites

#

if not my favorite

#

i think it is the perfect language to start

glad crystal
ocean marsh
#

you learn a fuckton from C

warped plank
#

C Isn't annoying to learn, it's annoying to master

terse dirge
ocean marsh
#

true

#

exactly

#

I dont get anything

#

everything is hard

#

nothing sticks

terse dirge
glad crystal
#

Probably one of the best piece of information I learned is how the IDEs read the code. Left to right, and anything indented is part of a block.

torn cedar
#

I fell asleep on my phone and skulled yah Hmmmm

ocean marsh
#

cupidcupid

#

hru

glad crystal
#

It just helps you start to learn it better when you know how it parses the code. But, you should really dig in and learn a language tbh.

ocean marsh
#

wtf you are hacker rank and ruby, since when

warped plank
torn cedar
ocean marsh
ocean marsh
torn cedar
ocean marsh
#

congrats for the rank

terse dirge
ocean marsh
#

keep up

warped plank
terse dirge
#

There's also size limits on arrays

rapid badger
#

error handling is one of the best things about Go

torn cedar
west venture
#

Microsoft Discord Server?

eternal mango
terse dirge
#

It's the unofficial community server for Microsoft

warped plank
#

Go learn about Rust's error handling and come back to it.

#

or Haskell

muted olive
#

To whoever says AI will take over hacking, I dare you to ask Opus 4.6 to help you bypass either semi-strong path traversal or SQL parameterization and see how long it goes around in circles

ocean marsh
glad crystal
glad crystal
#

and even then, it is not good at making secure programs.

terse dirge
#

I like the error handling but the problem I have is nil pointers but I get why they don't allow them and why it's that way

ocean marsh
#

zumi is either typing a fucking book or he died on the keyboard

glad crystal
#

Pick a language or two and master them. You're trying to diversify too much.

warped plank
muted olive
glad crystal
ocean marsh
#

ok bro

#

like

warped plank
ocean marsh
#

cmon

glad crystal
warped plank
#

It's not like you understand all the systems you pentest right off the bat waz

#

DW Zumi, noone does

west venture
glad crystal
#

Just takes time. It's muscle memory.

eternal mango
#

Can't remember, but you can still follow the logic right?

eternal mango
#

Point is you're not trying to be a coder, you're auditing

#

llol

#

Right

glad crystal
#

Then I think it makes more sense to you then you're giving yourself credit for. That's probably the gap in my understanding of where you are in your journey lol.

hardy frigate
#

Hey g0blin can u run something by in the next big boss round table meeting

#

Make a compliance cert

ocean marsh
#

i'm going to rewrite some notes, wish me a good time or I quit cysec right now

warped plank
muted olive
#

I hate Anthropic, the Claude free tier is now 3 prompts and then a 5 hour break

glad crystal
#

I have to decrypt some RSA really quick

eternal mango
#

Ok nice, you got this

warped plank
#

there's tonnes of them and each one has their own certs for a reason...

rose onyx
ocean marsh
#

thank you man, that's so kind of you

sick gate
#

JSIG

#

Do JSIG

glad crystal
#

compliance evolves but the baseline is still relatively the same.

muted olive
warped plank
ocean marsh
west venture
hardy frigate
glad crystal
#

That's true, but the underlying fundementals of compliance stay relatively the same. That's where the CIA triad comes in.

rose onyx
ocean marsh
muted olive
warped plank
eternal mango
#

A compliance cert would not only require that we teach the full subject of the established compliance framework, but also build upon them with practical exercises which in themselves would likely just feel like a box ticking exercise I think?

glad crystal
#

Governance, Risk, and Compliance is literally what CAE-CD programs tailor towards.

muted olive
#

the compliance cert would have to be compliant to another compliant cert, and so on

sick gate
#

Now open the spreadsheet in pwnbox

ocean marsh
#

any paint dry watching enjoyers?

muted olive
#

hack my frisbee

glad crystal
#

And that's why I am going to be a unicorn in this field. Not only do I have a very solid foundation of GRC, I will be among the few with the actual technical skills.

hardy frigate
#

Just comply to my idea and make the cert

muted olive
warped plank
glad crystal
#

Trust me, I am. Everyone hates "that's not in our budget."

tough oyster
rose onyx
glad crystal
#

Communicating technical risks to c-suite execs is an art form.

eternal mango
#

Imagine the negotiations with the compliance officers of the compliance assurance officer to ensure our certificate is appropriately compliant to the compliance requirements of the compliance definitions

tough oyster
#

Ayy yooo congrats @molten bobcat 😄

glad crystal
warped plank
eternal mango
#

It does

#

How it should be

tough oyster
warped plank
#

Hello Homie CEO,

Found a bug in yar network

That'll be 50,000$

molten bobcat
glad crystal
#

Yeah, but what I was getting at is explaining technical problems to people that are tech-illiterate. They are still just people.

cloud osprey
warped plank
#

I'd do it for 50,000 kek

eternal mango
cloud osprey
#

not if you have a fancy bidet

glad crystal
ocean marsh
glad crystal
#

Might even be nice enough to top it off with a BIA.

rose onyx
#

That's a long poop

glad crystal
#

Business Impact Analysis.

eternal mango
#

They had the gun loaded

#

Ready to post

glad crystal
#

Literally.

ocean marsh
#

"please rewrite this as professional but not overly formal"

glad crystal
#

You're speaking the language of c-suite execs 🙂

warped plank
#

I learned hacking to break the rules not follow them damn it 9263zerotwoveryhappy

runic cliff
#

will doing starting point machines increase my rank?

warped plank
ocean marsh
#

yeah

#

more aura points

warped plank
#

I only did the free ones, am I still handsome?

rose onyx
#

No u zumiyumi

ocean marsh
#

you two are handsome for me

warped plank
runic cliff
#

it's ok am dumber than u anyway

muted olive
#

son, you need to finish starting point or youre gonna end up like him
points

warped plank
#

You? Dumb? Cap

#

if you're dumb wtf am I?

maiden anvil
ocean marsh
#

zumi just a lil stupid

#

but he fine

warped plank
#

Nahh but you did CPTS in 1 attempt, I needed 2

ocean marsh
eternal mango
#

🙊

warped plank
#

And even now I don't understand wtf I did

ocean marsh
#

maybe you had a luck thought process

warped plank
#

Still pissed though, I was 1 flag short on first attempt and I had it in the palm of my hand I just didn't realize it

hardy frigate
#

Smart new guys know this too. I see it all the time

warped plank
#

My iterative process: Try it once, no work, ok move on to the next thing 9263zerotwoveryhappy

ocean marsh
#

I submitted my CAPE report with 40m left because I was re-reading the report for a whole day

#

without sleep

#

only coffee

#

and anxiety

warped plank
#

idek how to do one thing 10 different ways... waz

eternal mango
#

Too late to give you a proper answer now without people thinking it was from AI now hey @maiden anvil

ocean marsh
#

4/5 days to write a report and then 1 day to re-read it over and over

#

gemini, claude, chatgpt, certipy

#

that's 4

warped plank
#

probably check if web enrollment is a thing

#

2nd way is just: if it does, go try it 9263zerotwoveryhappy

#

can't recall if it's one of the ESCs certipy can check for

terse dirge
#

Lemme check certipy real quick

warped plank
#

I know there's a few that certipy can't check

ocean marsh
#

guys no one actually knows hacking, it's just magic

warped plank
#

relay time baby

ocean marsh
#

you call it a day

ocean marsh
#

good question

warped plank
#

certipy find

#

idk check existing certs?

ocean marsh
#

you want some clairvoyance atp

#

ask the domain admin personally

warped plank
#

He wants something to do with the cards or something

terse dirge
#

Group policy I'd assume

ocean marsh
#

OU?

#

idk if that could be a thing

warped plank
#

honestly if I only have kiosk access which is hardened, last thing I'm checking for is ESC8 9263zerotwoveryhappy

ocean marsh
#

W1ld has a zero two emoji for everything

ocean marsh
#

or a korean girl gif

terse dirge
#

Then you probably can't access anything ad cs since you probably also can't get access ldap

warped plank
ocean marsh
#

this is absolutely nuts

#

damn

#

fastest star in my whole life

#

10y old repo

#

fahh

hardy frigate
#

Hey guys

#

Does any one here can teach me how to setup and use an advanced hacker AI that works with me

#

Or can recommend a resource

ocean marsh
#

I recommended not trying to set up an advanced hacker AI

eternal mango
#

[ruNTiME.IntEROPSeRVICEs.mARSHAl]::PtRtOstRInGAuto( [rUNt my eyes gave up

warped plank
#

If you need a tutorial for one, you don't need one, you gotta prioritize other things

ocean marsh
#

jfc

#

ok I give up

hardy frigate
#

Idk I feel like if there are gaps in my knowledge during boxes then the AI could help

ocean marsh
#

But how do you even arrive at such a conclusion

warped plank
#

ffs

ocean marsh
#

bruh

#

never talk to me ever again

warped plank
#

next thing I know it's no evasion and I'll just run a claude agent

meager kernel
ocean marsh
#

I'm still dumb

meager kernel
#

I have to learn how to use impacket scripts for a machine

warped plank
#

my means of doing ESC8: certipy, I'll forward ADCS if I have to

ocean marsh
#

I need to get smarter

meager kernel
#

@ocean marsh what modules should I use for learning impacket scripts for a machine

#

Academy modules

ocean marsh
#

documentation

#

yeah

#

lol

warped plank
#

literally just read

meager kernel
ocean marsh
#

btw the modules that are tool related are a joke imo

#

nxc module

#

just read the docs

#

and do the exercises

warped plank
#

or pick an AD ldap/kerberos attack and do it, pretty sure impacket doesn't have any ADCS or ADFS tools though

ocean marsh
#

the exercises are good ofc

meager kernel
#

There was a machine I was stuck on last night and couldn't get past a point cause I didn't know how to use impacket mssqlclient

meager kernel
#

Bro wtf is impersonate

#

In mssqlclient

ocean marsh
#

impersonate a user

meager kernel
#

Huhhhhh?????

ocean marsh
#

booo

#

You need to learn how to self teach yourself

#

modules are good to introduce yourself to topics

#

then you go research on your own

#

should I use this instead of the impacket thingie

#

using that on cptswaz

prime heron
#

i will still be using impacket-mssqlclient

#

😼

ocean marsh
#

I wish I was a computer

warped plank
#

y'all use mssqlclient? 9263zerotwoveryhappy

#

nxc mssql

ocean marsh
#

nah

warped plank
#

I hate entering interactive shell sessions

meager kernel
#

What?

warped plank
#

for anything really

ocean marsh
#

not as good afaik

prime heron
frail turtle
#

I is Angy

ocean marsh
#

@warped plank how long have you been hacking for?

warped plank
eternal mango
#

I could've saved so much time by reading the README, instead of reading through the whole thing to figure out what that MSBuildShell you posted did..

meager kernel
manic hare
eternal mango
#

..well, learning is learning I guess 🤷‍♂️

warped plank
ocean marsh
#

nice

warped plank
#

so just over a year

eternal mango
#

Stubs, supers, nops and emulation 😅

ocean marsh
#

that's wild

#

good progress w1ld

meager kernel
#

Like it was guest@[machine].htb even though I used the creds of the guy I was given @ocean marsh
Why is that

eternal mango
#

yup

prime heron
#

ive seen people use that general method to bypass av as well

frail turtle
#

xp_cmdshell in 2026???

eternal mango
prime heron
warped plank
terse dirge
ocean marsh
warped plank
#

that's why you sometimes need the --local-auth flag smth or other

frail turtle
ocean marsh
#

we started together

prime heron
ocean marsh
#

@meager kernel sql can have a different context

#

I'm dead tired I'm going to sleep

prime heron
#

same here, march 22nd 2024, i remember lol

meager kernel
ocean marsh
#

I'm mad

frail turtle
#

nah but like in 2026 how is a sysadmin just gonna leave their account with a weak password seems like a 5% chance of working

ocean marsh
#

💀

eternal mango
#

sa:sa is fine right

prime heron
#

on my last pentest the sysadmins password was like John12 or something like that

ocean marsh
#

that is something

prime heron
warped plank
prime heron
#

industry standard

meager kernel
#

How much time did you dedicate to hacking in a day

barren sundial
#

yo

prime heron
#

yo

meager kernel
#

Oh my nitro expired

ocean marsh
meager kernel
#

Unlucky

ocean marsh
#

discord nitro 💔

warped plank
unkempt beacon
ocean marsh
#

I did the same but overall 6-8 hours a day

ocean marsh
#

during vacations I would push that to 10 hours depending on the day

prime heron
ocean marsh
#

then take a break (burn out)

meager kernel
ocean marsh
#

and come back

prime heron
#

when you start doing 10 boxes a day thats how you know you're locked

ocean marsh
#

sheesh

ocean marsh
meager kernel
#

I tried doing one easy module a day along with a machine

prime heron
meager kernel
#

But schedule kinda cramped rn

warped plank
prime heron
frail turtle
#

See I never worked in the industry but it's my belief that in 2026 people would at least become conscious that stronger passwords are a must. If a password attack works it's the company's fault for not having stronger policies

prime heron
#

nowadays its like 2-3 boxes a day (when i care to do them)

meager kernel
#

@ocean marsh I have to travel one hour to my office today just to be there for 3 hours so I can come back home with another 1 hour trip
W

#

What a fun day

ocean marsh
prime heron
ocean marsh
#

dont pmo

meager kernel
prime heron
#

human error will never change really

meager kernel
#

My college is 1.5 hours away

ocean marsh
meager kernel
ocean marsh
#

oh that's for sure

warped plank
ocean marsh
#

but I also study cysec during classes

meager kernel
#

I've never gained knowledge from college, I only gained knowledge from college friends

ocean marsh
#

???

prime heron
#

in AD

frail turtle
#

I kept thinking you know...oh the kinds of attacks left: privesc via some unbeknownst object in some software....or something

terse dirge
#

ceald slop 🔥 I didn't salt the pasta water enough before microwaving it

#

it's very bland kek

warped plank
ocean marsh
#

I've been studying hard but I still feel dead stupid when I talk to zumi

prime heron
#

ntlm reflection, web client coercion, mitm6, adcs misconfigurations are the most reliable ive seen so far

frail turtle
#

man this is so fucked, I need to sit down and find a way to destress from yet another disappointment produced by humanity

ocean marsh
#

idk how you make so much progress and learn that fast bro

#

that's fucking crazy

prime heron
ocean marsh
#

I think I'm not trying hard enough

ocean marsh
prime heron
terse dirge
prime heron
#

wpad abuse

#

whatever it is it ends up in you having http auth and you can relay that to ldap

warped plank
ocean marsh
#

i feel dumb man, like real dumb

prime heron
#

because its http auth

#

i really wanna do another internal now

eternal mango
#

ntlm reflection is just fun, plain and simple

warped plank
prime heron
#

im sure by default mitm6 should work

#

me 2

frail turtle
prime heron
#

i remember on this one test after i ran secretsdump i put all the nt hashes in a list and like 50 cracked in 3 seconds

frail turtle
#

It should be impossible i mean we got fiber gigabit internet speeds in our own house

ornate ibex
prime heron
#

one interesting thing was some of them were in the format of the date the password was changed

warped plank
#

when you forget to use the --only-ad-user flag in secretsdump

prime heron
#

so with that i looked in AD at when these other accounts last changed their password and i got a few of them that way, it was the most htb shit ive ever seen on a test

#

i just dump the whole god damn dc

ornate ibex
#

Yeah FTW

eternal mango
ornate ibex
ocean marsh
prime heron
#

i dont do pentests on companies that care enough to even have a blue team lmao, they wont care.

#

well i only dump all because i like to do a "password assessment" afterwards

#

ive seen many testers do that so i just take after them

frail turtle
#

at that point you're just asking for people to rob your business and livelihood it's like an invitation; or a storekeeper leaving the door unlocked and the shiny jewel unguarded

ocean marsh
#

too much pressure

#

I would pass out

prime heron
#

August08072023

cerulean bloom
frail turtle
#

not even a salt

#

that's embarrassing

ocean marsh
#

imagine working in soc watch someone pwn your whole network waz

frail turtle
#

Give me the $200k a year job I'll fix that in 10 min

prime heron
#

oh yea lmao

ocean marsh
#

smarties!!!

prime heron
#

KGFOkpoKVFQO_PKFF_)!KTFG_)!KIGF)!<LK_F)!LK+LE+)K!I)RRFI!)(FK!)(@IK$)($I!)(%I!)FGVK)!K@T)_

warped plank
#

They just abuse 0 day after 0 day

prime heron
#

funny passwords ive cracked, 1. Fordranger1

ocean marsh
#

why is :3 inside a cauldron here

prime heron
#
  1. Obiwan2024!
#

shi mb

frail turtle
prime heron
cerulean bloom
warped plank
ocean marsh
#

same

cerulean bloom
#

sleep tight

ocean marsh
#

I can't control the yap

cerulean bloom
warped plank
ocean marsh
cerulean bloom
warped plank
pliant pumice
#

i suck at bug bounties

#

cant find a damn bug, been months

warped plank
#

then hunt there

eternal mango
#

or something like that lol

warped plank
#

bb also no pay

#

sad

mystic harbor
#

@ocean marsh

frail turtle
#

jhaddix vids are worth it?

cerulean bloom
#

I’m joking ofc

mystic harbor
#

False

pliant pumice
#

anyone got bug bounty tips?

warped plank
pliant pumice
#

lowkey

warped plank
#

It takes a damn long time, the triagers are either burn't out or don't care and the payout isn't worth the effort most of the time

#

Also unless you find an interesting vuln in a common app that isn't discovered yet you probably ain't gonna find much.

pliant pumice
#

what can i do then

#

for money

#

without applying to work for a job

warped plank
#

Find a job waz

pliant pumice
#

ugh jobs r so boring

#

i just wanna sit at home and do it

warped plank
#

Jobs are how 99% of people make money waz

pliant pumice
#

true

warped plank
mystic harbor
#

J*b

pliant pumice
#

1% are the millionaires

#

dw i will be the 1%

ocean marsh
sick gate
pliant pumice
#

U RIGHT

#

ok 1 sec

mystic harbor
warped plank
#

literally be a chat support agent, boom work from home, ez money

ocean marsh
#

took me 21 to receive my results

pliant pumice
#

actually not a bad idea

ocean marsh
#

I almost DIED

#

of anxiety

warped plank
ocean marsh
#

not fair at all

warped plank
ocean marsh
#

exactly

#

I had plenty of time between my first and my second attemt

#

attempt

#

I hope I receive my cpts results fast

warped plank
#

I had 2 weeks... NotLikeThis

warped plank
elder lichen
#

we can't add more time to instance ? what

#

we can't add more time to instance ? what

ocean marsh
warped plank
#

tf you mean found this sequence mate unless it's HTB related we can't help you cos we don't know if you're breaking CTF rules or the law for that matter

ocean marsh
#

found that in the wild

#

just around

#

yk

ocean marsh
warped plank
elder lichen
mystic harbor
glad crystal
frail turtle
#

What are some more secure alternatives to nginx and apache

glad crystal
warped plank
glad crystal
warped plank
glad crystal
warped plank
glad crystal
warped plank
sharp shuttle
#

did you guys catch the new jon hamm& video?

frail turtle
#

lighthttpd

#

I feel like I would go with that

#

for a website

glad crystal
sharp shuttle
#

Erm

glad crystal
#

Bro literally accused me of trying to break the law over RSA raw 😂

sharp shuttle
#

If it was indeed a nuclear code leak, my good sir, you would be found guilty of high treason!

#

and therefore, obliterated!

ocean marsh
#

is the game good?

#

i only heard bad things about it

sharp shuttle
#

erm

ocean marsh
#

@glad crystal

alpine pumice
#

the nuclear codes used to be 000000

prime heron
#

I played the old ones

ocean marsh
#

same

glad crystal
alpine pumice
#

00000000*

ocean marsh
#

I played only 2 and 3 tbh

#

2 is perfect

sharp shuttle
#

Borderlands. Heh. More like BOREder lands... and yes.. I barely know her

frail turtle
#

good games are hard to come by these times

glad crystal
#

Password1234

alpine pumice
#

i have unopened board games and i want to buy some more

#

do i have a problem

cerulean bloom
frail turtle
#

There are some good point and click games i like

sharp shuttle
#

erm depends on the games

#

i am a level 900 dungeon master in arkham horror

alpine pumice
#

was looking to pick up arc