#general
1 messages · Page 584 of 1
Don't body shame me man
if you say so bro
Bro watch those cs go videos russians saying we hit our kids in weekend bases
kids as in @mystic harbor
Oreo cake tf 😂
not as actual ones
I am just a baby
Eat all the chocolates normally
how do you abnormally eat tho
Inside a cake
now he eats all
i wil take it
I am not
cake it up, sister.
Can someone motivate me to complete the box I started?
Do that box or ill throw candy at you
That'll do it 👍
no. it's you vs you, lol
Guys you're scaring me
Fail me and you will not live to regret it
Yes sir
just complete the box man. that's all we want.
so we don't Mr. Robot you
Be nice
im nice
I am better than Mr Robot
ask @devout sail
Hello I just started in cybersecurity, I would like to join a small study group or a partner to study and share knowledge etc., if anyone interested dm me ! Thank you !
i wish my friends would study with me
hang out long enough, and maybe someone will bite. in my experience, those types of connections usually come from voice chats. people are seldom comfortable to link up via text chat. but it does happen possibly on occasion. like, there's a room in this discord server for "Join a Team" or something like that.
@mystic harbor what total percentage should you complete out of HTB to get to Guru? I am at like 10% completion idek how I am hacker rank
I don't have friends
90
find some! they are very important in life
Alr thanks
Pro hacker?
I can't , cuz I'm mostly at home
discord is great. i'm the same way. and i'm guessing most of us are. very similar. hang out on discords and join voice chats on here. you'll meet people for sure.
then go out
I can't
disabled?
Alr
45 i guess
💀🙏
I have nothing to do by going out
Breachforums telegram channel 🫵
yeah then dont tell again that "you have none"
thanks. i'm good. sounds interesting though.
great dumps, from what i've heard.
there for labs or labs + academy ?
It wasn't really a request
Labs active
ty
oh, you gave the uncle Sam finger pointing at me like you wanted me to join, haha. sorry, misunderstood, lol
I mean , its complicated
lol
🫵
Like you loose points every week so keep it going or else
u can do shit, u just chose not to
even @mystic harbor has friend
so anyone can have it
How many?
I do had some friends in past but they aren't real only used me for money so left them, then I didnt had any opportunity to make friends after that
2 - 3 boxes per week enough?
Depends on machine and challanges that are retiring that week
damn i missed my chance to loot u
Yea if You wanna go above elite do challenges and machines
False
so the only way beside getting hacker rank that doesn’t dissapear to get image perms is to get a cert
the progress falls to 0%
nicee
@scenic maple
Date 
would be lit 🔥
Ewww
No

@..... @austere sinew
They should pay me for marketing here
why is everyone pinging @austere sinew
?
i dont like these stuff much
Because....
I dont know why everyone is pinging @austere sinew
What You like
but theres this smol shop (idk if its famous but its smol near my place) called smoke shaq
@austere sinew
they give expensive but yum burgers
@austere sinew
seems like im missing some context

nothing

Hello, I can't spawn any VM ? Is it just me or do you guys have the same issue ?
Here u go
You joined in Feb 2026... Fresh meat
error?
or it just say "wont spawn"?
Error
Failed to spawn machine on the Dedicated server. Please try again.
change server
Too much fat in chat
Me too
Can't download any VPN lol
show screnshot of the page where u spawning it
happening to everyone
dont worry
ah broken htb or something xD
nothing we can do
WhAts A vPn?
lets see if we have an announcement soon
So I cannot complete my box after all?
what module/box are you doing?
i was tryna do boxes today and they weren’t working like AT ALL so that makes a lot of sense
is htb down , not able to spawn any machine
is anyone else getting the "Server error" error message?
Was trying to spawn Forest
That's a fun box, I hope you can complete it soon
Ist is retired?
Yes
I almost completed the Intro to AD track, but people were telling me that this box was really good and missing in the track
is there any notice ? when it will be up ?
Idk. Machines aren't spawning
it’s not fun when i have to configure it as a practical task on the server and i only have an hour ✌️😭
this just happened
Someone hacked HTB 💀
ig wait for an hour or two and try again
Is it better to focus on a single sub and doing machines of that or going through random boxes?
i see i'm not the only one with the issue
@versed wadi wassup? you need something man?
I found it so much more fun that Linux machines most of the time
I prefer to focus on a single sub
Alright will do that after starting point
You worked for Diddy?
send you a Dm please
Who
Patrick Bateman
Mohammed Lee
@dense yacht yep it's the same for everyone
I got my machine to spawn!
Wait this is not the one
nvm
😄
Bro how
Wym
He is penetrating the street no ?
Hey everyone, I just received a pretty suspicious message from a random user asking me to help them make a “411 call” in the US. This seems really unusual and potentially a scam attempt (possibly trying to get me to call a paid number or act as a relay). Has anyone seen something like this before? Also, should I share the username here so it can be reported or checked by the mods?
Many did
Report and forget
This is what my town looked like a few weeks ago, some lost their houses
Search 411 in this chat, there was some screenshots xD
💀
😂
411 calls are for ensuring there's no buried wire or pipes where you intend to dig 
This person has no idea about the US at all and likely isn't even a resident lmao
It used to be for directory completion
Hence the phrase "what's the 411?"
I'm thinking of 811
For digging
Rip
nah dude, 411 is an oldschool number to lookup business phone numbers and addresses.
i used it all the time back in the day.
Yeh, directory completion
yeah
The emergency line for the police in the US is "911" btw
Well, not for the police but for all emergencies
I'm okie
Really strange, and also pointless since I’m not in the US 😅
nice
Yep he mentions bengal or something in. His message
..
Nepal xD
Same person!
wth is a darkweb injection protocol 😭
They send people from dark web with sussy injection which they poke you in your butt
Let's see what happens
Sending 2 to you
Hi
Click here: https://boot.dev/?promo=PROFESSORDAVE and use my code PROFESSORDAVE to get 25% off your first payment for boot.dev!
Remember when Bill Nye debated Ken Ham about evolution vs. creationism? I remember it too, but I didn't watch it when it happened, I was busy touring in a rock band and not being a science communicator. Want to watch m...
hello i participating in ctf and i struggling with tihs task for a long time i only takze control of machine with metsploit exploit but then i dont know what to do the objective is to find secret.txt where is flag
The administrator has deployed a CMS web application.
We know it's not bug-free, and you can verify this using the metasploit framework.
Your first step is to conduct reconnaissance and find a vulnerability that will allow you to "get in" and gain a shell in the context of the user running the service.
However, this is only half the battle. The real goal is to take full control of the system. We know the administrator is using a popular permissions delegation tool. If you manage to exploit it correctly, you'll have access to the root user's home directory and the secret.txt file hidden there.
PS. One of the available local modules should handle this task, but rumors are circulating that it requires a minor tweak to work in this specific environment.
Server address: 10.35.45.129
if somone is intersted in i would pass openvpn file and password to connect
I would be very grateful if someone could help.
Sorry mate, we can't help with that/outside competitions. Hate to slap you with this but it might be time to
hey yall im new but are the eu 7 machines down cuz i cant connect to any of them
people had issues with the machines this morning
I would be happy to solve it, but I won't give you the secret.txt 🥰
ok so you will tell me how to do it then
ah shit, its so confusing to me because it tells me its under maintenace yet people completed a lab 3 minutes ago
Maybe very very VERY very slight nudges
@glossy hare https://hacktricks.wiki/en/generic-methodologies-and-resources/pentesting-methodology.html This might help you a bit. Go back and enumerate. Look at everything and take good notes. Other than that, welcome to the struggle bus. Everyone is riding and has to muscle through.
Learn & practice AWS Hacking: HackTricks Training AWS Red Team Expert (ARTE) Learn & practice GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE)...
if i can't spawn pwnbox in next 30min i will cry
go ahead
Miaw

bad
do it now
wht is?
it won't help
so lost tht i dont even knew wht the it is tday
you already have an active pwnbox instance error
i don't have one running though
Then figure out something that will. Half this path is doing your own research and figuring it out. Enumerate the functionality and the stack. Then go and research that. This is a cyclical process. Enumerate, find something interesting, research, possibly exploit. Rinse and repeat.
If you don't know how something works you can't break it or fuxk with the logic. So you'll have to go learn.
What is cube talk
PentAGI goated this
What you guys think about thm using our data to make an AI can we sue them
Yes sir
😼
Where is ur cpts tag?
so wht abt pokemon go using all the info they collected from the camera of their million sof users to create a 3d map?
Revoked?
What
I meant u like my bike ? 🐈
Didn't use it so idc 
Pfp looks cool
well i did 
can i have urs?
Ahahah it's my friend's bike i went to the event to do wheelies 
so can i have ur friends bike?
Yes
🫶
hello I would like 500 cigarettes.
mmmmmmm, water
Hi.

ayo why is it taking so long for a full port scan with nmap on a htb target machine 😭
That's normal friend
Nmap is doing tons of stuff for ya, gotta be patient while it runs
its been over 10 mins 😭
If you tap an arrow key what's the progress at and what's the ETA
normal port scan at 99.9% sigh
Can you copy paste the command you used?
nmap -p- -sS <ip> -T4
used the timing template to make it faster
i just wanted number of open tcp ports
T1000
time to wait 12 mins ;-;
what does it give?
-sV services
-p- all ports
--Min-rate is a "minimum packet transfer speed"
Iirc
So it's like setting a minimum speed limit
ohh
what's the difference between the T flags and the min rate?
Sigh well
--min-rate <number>; --max-rate <number> (Directly control the scanning rate)
Nmap's dynamic timing does a good job of finding an appropriate speed at which to scan. Sometimes, however, you may happen to know an appropriate scanning rate for a network, or you may have to guarantee that a scan will be finished by a certain time. Or perhaps you must keep Nmap from scanning too quickly. The --min-rate and --max-rate options are designed for these situations.
When the --min-rate option is given Nmap will do its best to send packets as fast as or faster than the given rate. The argument is a positive real number representing a packet rate in packets per second. For example, specifying --min-rate 300 means that Nmap will try to keep the sending rate at or above 300 packets per second. Specifying a minimum rate does not keep Nmap from going faster if conditions warrant.
Likewise, --max-rate limits a scan's sending rate to a given maximum. Use --max-rate 100, for example, to limit sending to 100 packets per second on a fast network. Use --max-rate 0.1 for a slow scan of one packet every ten seconds. Use --min-rate and --max-rate together to keep the rate inside a certain range.
Does this make sense? Copied straight from nmaps doccs
I wrapped it so it wouldn't be super bad to look at
It's explaining the --min-rate flag
hm yea it does
Reading the docs is the first step to truly understanding a tool
i did go through it but somehow missed this part 😅
The nmap people are smart, they have their whole documentation on their website
yea that's true
Ctrl F is your friend
that's also true
is there a way to turn off seeing what OS the box is
i dont wanna know the OS before i start my machine
might've slacked in reading the docs when i was reading timing templates
Ive looked at it a few times when trying to figure out why I get different results with only a single flag change; -sT, -sS, -sS
rip
friendly reminder that warnings about getting blocked of flagged for fraud for performing card chargebacks are a psyop by companies to convince people getting back their money is more hassle than its worth but you are 100% within your rights to demand money back for goods or services not received or only partially recieved.
and no it doesnt matter if the company has terms listed somewhere or made you sign something up front or if their internal refund policies deny you
You don't know how hard it can be to randomly read docs for the sake of reading docs when you have sevear adhd
Im not saying you have to
Uh yeah? Just don't add the -O flag?
i do that too XD
That wasnt the question
but im used to reading through long docs
i've been reading long python package docs since i was 15
the trick is to loop reading docs into your hyperfixation loop
I do read a specific part of docs when I'm using a new tool in the middle of doing something I am hyper fixated on. Which makes reading that specific part of the docs in that specific context fun.
Yeah, expanding your special fixation to include related boring stuff is unfortunately a lot easier than trying to do that for dishes 😭
God I love clever uses of old technology
I'm currently using the fuckin ARP cache
As an investigation point
It's like when a cpu executes code but the code uses imports and you put an exploit in one of those imports so the cpu executes something it won't normally execute 😭
ARP deez
Nuts
cats eat rats
after watching zootopia i realized rabbits can also be sexy
for millennials that was space jam
Rabbit are just big rats
They r tasty though
Happy Robot
Happy Robot
Happy Robot
Happy Robot
Happy Robot
Robot
Happy Robot
Robot
Happy Robot
Robot
Happy Robot
Robot
Happy Robot
Robot
Robot
Robot
…
some websites have lot of content related to judy hopps
this song fucks
this is the song they roll you up with after you get arrested for too many pretty rabbit pictures, lmfao
"but i'm on ecstasy!" "tell that to the judge pal" lol
after that, it's all sad robot from there lol
dude, this looks lit! lmfao "recommended". we'll see if it's good...
https://www.youtube.com/watch?v=mVvGvxWdEXI
Immerse yourself in Brutal Minimal Techno with Boris Brejcha's signature High-Tech Minimal style.
A cool, dark, hypnotic audio journey where minimalist grooves repeat relentlessly, bass is solid, kick is dry, and the rhythm is precise down to the smallest detail.
This mix is curated for:
Minimalist Techno / High-Tech Minimal listeners
...
you also like ducks? looks like that one likes to get down, lmfao
ducks are tasty 
don't know if i've ever tried em
sounds alright. i had a duck fat in a jar once. didn't really like it.
what are some duck dishes?
i recall there being Chinese duck dishes.
Yah but nothing beats chicken 🐔 for me
Download the remix free: https://hypeddit.com/ramesesb/lumiereremix
I absolutely loved this game so I had to remix it. We need more games like this, story, gameplay, presentation. It's a masterpiece. (I also tried to get the track length to 3:33 but this will have to do. Enjoy!
🚀 Rameses B:
All Links: https://linktr.ee/RamesesB
● Spotify -...
love some dnb
Does anyone knows how to create unlimited gmail? Not temp mail 🚫
loading it up now cloud
No
This isn't the server to ask for this
Sorry am new here. Where do I ask?
Also you cant even create unlimited gmail accounts without unlimited phone numbers
@molten bobcat i really like this artist:
https://www.youtube.com/watch?v=mrPir5H-EMI
» Follow our Drum & Bass Playlist: http://ukf.io/DNBPlaylist 🎵
» Download/Stream: http://hyperurl.co/sporanachronic 🔊
Taken from Spor's Anachronic EP, out now via Sotto Voce. Visuals by Spor.
» Shop UKF Merchandise 👕
→ http://store.ukf.com/
» Subscribe to UKF Drum & Bass
→ https://ukf.io/subscribednb
& enable notifications ...
so even if this was the right place itd still be a dumb question
just gotta RE gmail and add some NOPs, lol jk
I have like 5 gmail accounts and they didn't require phone numbers to sign up
Their phone number requirement can be pretty arbitrary. Sometimes they ask, sometimes they don't.
C1oud can i borrow fiddy bucks
tree fiddy
nice! yeah, i remember this song! good one.
i also really like the whole album, "Breathe In, Scream Out"
boo this man/woman
lol
god i'm so sick of rice. but it's the cheapest. i think i have some pasta in the cabinet. hopefully...
can't go out now though....
rice racism
ricism?
I love white rice, my favorite thing
White rice causes blood sugar spikes and can actually cause diabetes lol
that's an edible offense
tell that to the continent of Asia...
If you don't exercise immediately after eating to absorb that glucose
damn its a shame all of asia is diabetic
I am from there and we eat rice
oh whoops. i thought you meant white rice.
is diabetes a huge problem in traditional Asian households??
It really is. Diabetes is a leading disease even among the young generation here. Bc all we do is eat a bunch of rice and be on screens
Consider its probably not the rice
wo xi huan mi fan. how's my Chinese? 🙂
anyone can help me with broxsed ?
What is it?
with that much wisdom you will either disappear or become a higher being
#startups
If you gave me a million dollars to make a bet, I would bet on the energy drinks
I'm working my way up to type 8 diabetes
the adoption of things like American fast food.
or just soda.
This has never been an issue in the past, I think it is purely correlation, and I think it's the drinks
all countries are having spikes in diabetes
its not the rice
Japan is a blue zone country. lots of white rice, from what i understand.
Do you know why? Because in the past people here munched on rice but also worked there asses off so all that glucose was actually used up by the muscles. Now we eat as much and don't do nearly as much work, causing a massive glucose spike bc muscles don't need that fuel.
(blue zone = most centenials from what i recall)
😊
yay eugenics 
that tracks. it has to be proportional to your caloric needs.
Yeah
I am aware of the sedentary lifestyles, i too am guilty of sitting at a desk for 12 hours a day very often. I still blame, almost exclusively, the random kool-aid products people drink nonstop
yeah, my money's on that too
that's like saying can any carb cause diabetes
like, yes? but in excess of your TDEE
and for a sustained period of time
speaking of carbs. i need some... brb. gonna cook ze pasta
Also we don't drink as much energy drinks lol. I don't think I've drank one in the past 2 months
when i say energy drinks, i mean anything flavored, not water
at least in america, nearly all products have caffeine in them
i am speaking biasly
but i know japan, china, korea, etc drink tons of non-water products
That too not with sugar for the most part
i think those drinks cause organ failure that leads to the diabetes you are associating with rice
rice could be the catalyst but the drinks cause the issue
You mean tea causes diabetes? No
lifestyle is completely irrelevant as long as you are under TDEE and not storing excess glucose that isn't used in exercise, any carb would do this
Uh....I do bc I work in a tea factory 
food choice is irrelevant
Tea is our #1 export here
some foods may have higher thermic effect but subtracting 100 calories from the 2000 calories of pure dogshit slop you shove in your body without moving is the issue, not the food
Heavy Metals: Studies have found lead, arsenic, and aluminum in brewed tea, largely absorbed by the plants from the soil.
Pesticides: Some teas contain traces of pesticides, though often within regulated limits.
Tea Bag Quality: Some tea bags (especially nylon or plastic ones) can release plasticizers or microplastics, though this is considered a minor source of exposure compared to food.
Mitigation: Purchasing high-quality brands, opting for organic, and limiting consumption of very high-volume, low-cost bagged tea can reduce exposure. ```
ie; 99% of olympic athletes eat high carb, sugary diets to meet their massive requirement of caloric intake; however, they're also doing like 6 hours of cardio and then strength training following this
You cant know whats in the tea packets, even if its marginal
it's like being a cig addict
a pack of day = cancer
a dart a month = ur prolly fine
Yk factories grow tea in extremely controlled environmentss right?
I am american, who has worked many ICS/OT facilities, and I know the shit they get up to
i highly doubt its different just because you live in a different country
you have a much more likely chance to find heavy metals in your diet from everything else you eat as opposed to tea tbh
ie; if you take a multi vitamin good chances are you're ingesting metals
Its not the point, but yes I agree - my point is simply i think drinks are causing issues
food, if you are american
anyone here completed the entire CJCA path?
Again too much of anything is bad, including tea, but Rice specifically is turned into pure glucose rapidly. Eating white rice is like eating a plate of sugar. You cannot tell me eating a plate of sugar daily won't increase the risk of diabetes lol
but drinks universally
or atleast pentesting in a nutshell module?
i think our bigger issue is the overglorification of sugar as a sweet alternative, no sugar coke and regular coke are very similar yet most people buy the full sugar version just cos it is
furthermore, most people live dogshit lifestyles bcos life is easy
absolutely
If you're american, sure it's probably the drinks
if you're american it's your culture
your small coke at maccas is our large
unironically
overconsumpation and underactivity is much more likely to be the health issue causer as opposed to the outlier of trace doses of dangerous ingredients
Yup
All that sugar needs to go somewhere
It hangs around in the blood stream if it's not absorbed by the muscles
Which causes the body to dump insulin to reabsorb the gluecose
Which repeated over years causes insulin resistance where the release of insulin no longer effectively re absorbs the glucose
Which causes damage to the kidneys
And eventually kidney faliure
all that sugar is fine as long as its within your maintenance range of caloric intake
or yk
just exercise
^
Yeah
jus go for a run lowk
yeah like when you look into your crush's windows n shi?
been there done that
pause
that ill do on my own
that's a victim
like when you sent her her entire extended families names and addresses and wondered why she ghosted you paul
stop
🤣
yeah like computertrash said it's what i did too except i found her with tyrone and used hammer on the window to get in. Tyrone said "shes busy lil bro"
better that than sending ... pictures
This is the question
💀
fuzz it
check after -ComputerName vro
how do you know about that
if its in the script
my fault
it aint
did you know computertrash used to piss himself cos he didnt wanna get up from his xbox
💀
alr
that's true XD
i have DID and see my dead father ahh pfp
he actually walked in on his dead father
this is true i did do this
vro
tryna send me sm like 25 dollars
Send me

Time to wardrive and report all my neighbors
Seriously if they opened a bounty system for fox hunting, i would have a fleet of drones wardroning entire swaths of my state triangulating banned mac addresses
Iran-linked hackers have breached FBI Director Kash Patel’s personal email
I saw a headline
Don't know if it's true
i need to ask you all a question. if someone is running windows 10, but has a good antivirus, and is just a regular user, are they relatively safe? my answer to the person was "yes". i just told him to watch his browsing late at night, etc.
The answer is no
why?
Even having a windows logo anywhere near makes you vulnerable
For a regular person? Id say yeah
ah, cop out. ok. i see, lmfao
Tbh it depends
Id probably toss in an ad block though
yeah, same. it's funny, because he was just a boomer at the bar, and immediately bypassed my ingrained IT mantras chanting "update".
If they have windows 10 but they download any suspicious app and install it they are cooked
most consumers are getting pwned from bs ads
maybe, depending on if it gets detected.
like, scareware scams, right?
what did they post
Does it go to 100c? I believe it cant because gpu gets damaged above 90
it's true
Also water is supposed to cool the gpu -
In this week's episode we're in Schenectady, NY at a place called Wagon Train BBQ...taking a swing at their 'Graveyard Burger'...
Intrepid meat lovers get just 30 minutes in which to finish a burger chocked full of beef, pulled pork, bacon, mac and cheese, bacon, jalapeños, brisket and coleslaw, accompanied by shoestring fries and onion rings....
thats the number 1 thing for consumers rn yeah. Scare and then get them to download some teamviewer clone that doesnt trip AV because its technically legitimate
eggzy was hired by palantir to make me hungry
😄
well it worked
wo xi huan zhongwen cai. (i like Chinese food.)
and a crab rangoon
dude, those are the best!
those are some crazy names for sexy time, but im on board
fix my door, fix my door
stop stealing my dough, stop stealing my dough
stop disconnecting my video
Randy Walters is a son of a bitch, whoah oh
that's why i fucked his wife and got filthy rich, whoah oh
US chinese food has too many calories
Check out ALL the SHCA subwoofer series here 👉https://skyhighcaraudio.com/shca-subwoofers/
Good googa mooga
Good googly moogly
That BASS is fucking insane
they only posted old images of him which is funny
he remind me of hollywood comedians
they always have that look on them
yeah that short loud guy that talks normally for a second and then gets very loud for a second
skinny indian guy
I can't remember his name
i searched , guess the name
his name is Ravi Patel
No
Not him
This dude I'm thinking of is short, skinny, very loud and obnoxious but also talks normally but gets loud all of a sudden like that's funny or something
he looks like kash patel
in general falling i wonder if it was chained attack or kash was just dumb
oh yeah he does lol
imagine him falling for a phishing email "hey i am an iranian citizen here is a location of some underground bases click this link : obviously-a-scam.com"
Visiting The Beefy Boys in Bath, England to take on their "Phat Boy" Burger Platter Challenge! Brave diners have just 30 minutes to finish a 6lb tray loaded with 2 double cheeseburgers, 2 massive servings of loaded fries, 6 chicken tenders, 6 chicken wings, 10 mac n' cheese balls, and a big scoop of coleslaw! Winners earn their meal for free and...
broo.. is literally kindahomless 🥀
she actually ate all of that.
yup
Does she look like a ballon after
human garbage disposal
that's impressive af. I'd have vomited not even a quarter way through
Getting a quarter the way through is impressive
ya but even then I'm probably exaggerating lol
I know professional eaters do all sorts of things to prep though.
Like what seeing how much can be Inhaled in half an hour
In this week's episode we're back on home soil, albeit briefly, down in Yeovil at a restaurant called Texas Rocks...
Fearless carnivores get one hour in which to consume a 75oz steak, accompanied by three double sides; chilli cheese fries, mac & cheese and creamy garlic mushrooms. If successful, not only is the £80 meal FREE but you get a litt...
75oz steak and 6 large sides
holy shit
that shit would feed me for a week
lol
Took a trip to Nottingham, England to take on Red Dog's £1,000 Cheeseburger Challenge! Brave (and fast) eaters have just 10 minutes to finish 10 cheeseburgers in order to win £1,000 (~$1,400 USD)!! Signing up for the challenge guarantees a groovy hat, BUT finish 5 burgers (and get them swallowed in a 30 second buffer) and win 50% FOR LIFE! In ...
Man
I want some steak and boorgers
congrats
Shabat shalom
hi guys I am gonna ace my electronics midterm
I think I really am learning this stuff extremely well
have a week to study and its going good
how are you guys?
good luck dude
ya its good
then after the midterm I'm gonna finish web proxies htb module and then work on the next module but take notes this time. I may take a few days to take notes on web proxies module before moving onto next one (because I should have taken notes while I was doing it)
anyway, how are you guys?
I'll chat for a few minutes while on break and then gotta get back to work
hi guys I am gonna fail my PNPT exam
I think I really am not understand hacking well
have a month to study and its going horribly
how are you guys?
Does htb have any module about WAFs?
Best of luck with it. Knuckle down. Try and spend more time practicing, getting your notes in order, and doing the exercises
yes they do
Where
its in CWES or CWEE learning path I think
I forget which which is kind of silly since I am doing CWES
appreciate u big bro. i was kinda trolling tho lol
❌
hold on let me see if I can find it
I guarantee is not in CWEE/CWES
I think there was some section of a module
there's no module dedicated to WAFs specifically, but they do mention WAFs from time to time
maybe that's what I was thinking of maybe its embedded in other modules
ok in which modules
IIRC the SQLmap module mentions bypassing WAFs
with some specific sqlmap flags that you can use
I need to learn about waf bypass specifically
buying the sqlmap module won't help me much
maybe that's more of a pro lab thing
which is more advanced
I don't think so
ok I thought the pro labs include more stealth, etc.
and phishing related topics like go phish
compared to academy
not saying that's all pro labs are
either way I need to study it
ya ok well, maybe bypassing WAFs is advanced and they don't want to immediately introduce it
like maybe its just not beginner level
or whatever
it's not beginner level but I thought they would have it
I thought so too
it may be included within other modules
like weaved in here and there
as opposed to being in a dedicated module
thm has a module but no way I am going to use thm for anything
I agree with this
the problem is waf bypassing is an ever evolving field. Any course about it is immediately outdated at time of release
You can look at general strategies of whats worked in the past to develop your own, but youre not likely to find something that promises to teach bypasses and have it be effective
Same is true for maldev, but building the general skillset (even on outdated information) can help you to understand the mindset.
how we all doing
yea same
yeah but at least the basics would help
but yeah i will have to figure it out myself
I'm actually surprised it isn't in CWEE. I would have expected it to be.
i've a question is it legit legal for someone doing academy modules on stream ?
prob not the ones that cost like a subscription
FWIW I dont work for or represent HTB but generally paid content is a no go
if ur blur game is on point
it flies over lotta peoples heads im sure
it's also kinda weird because THM doesnt really care, basically free advertising for them anyway
yo do people even bother doing manual windows local enumeration
like idk if i should be good at it or just winpeas and call it a day
nvm its a Tier0 module
haven't done a windows box in a minute. but yeah. i would browse the filesystem prior to running scripts/modules to enumerate exploits. sometimes something obvious stands out.
I have had to do it in a job interview for red team before
usually start with whoami /all
worth to learn it just for that IMO
i do manual enum first, while running some automated script in the background
that's actually way smarter, lol
cyberops2025 knows whats up
yeah whoami /priv is all i do and if i dont see anything i just drop winpeas but i feel like im not really getting it lol
I dont think it's a flex to use Cachy OS right now
i try to see if there's an AV first, or some logger, outside of CTF's ofc
for sure. that makes a ton of sense.
omarchy is a linux distro, right?
yeah arch based
the completions plugin is pretty neat on zsh terminal
was looking at Devuan, but everything in regular Debian just works. no real reason for me to switch aside from complaining about systemd, which hasn't screwed me yet...
if I have rdp I like opening about pc to see if some av or edr is installed because it's normal user behavior`
driverquery is bad opsec
learning all a million commands brb
that's really smart, haha, vs. registry, etc.
i mean if i had the pations to rice something and make it look that pretty and techy i would, but mostly just runs whatever would just get the job done with no problems
Devuan is becoming popular
it's really cool. but i disable it so i'm forced to type the commands. also, better for opsec. but when you're starting out, i think it's fantastic for memory. eventually, you want to practice "cold" typing them though. even if you have to peek at your command history.
yeah, it's been around since i think 2017 ish. but i'd rather stick with Debian unless something (in the black swan event) blows up.
was thinking about switching to BSD, but my current learning objectives can't justify that.
isnt that the auto suggestions plugin
it's in your .zshrc file in /home/<user>/
there's a part mentioning "auto" or "complet" or something.
maybe "history"
i dont get the "Systemd-Free" part tho
or like what SysVinit is bringing to the table ?
i gotta look into that
yeah, i know. but my current goal is to learn unix sys internals. which seems like a good fit, but i want to analyze the data structs / architecture and code it. so i'll just stick with debian, qemu, and C
a tiny spider crawled into my laptop keyboard
rip lol (rip spider)
okay i need more noob windows boxes to practicec zzzzzzzzzzzzzz
it's like super mario world down there, lol. dungeon level.
thats nice, but trying to read strucs from header files was always a pain for me lol
@hoary dawn did u win devel
yea tahts the autosuggestion plugin the completion plugin just is a legend of commands based off what you got typed in the autosuggestion is what lets you use right arrow to complete commands without typing based on history
yeah, it can get messy for sure.
Hey yall, ive been struggling with physical labor jobs for a long time now and my physical and mental health are suffering for it.
So, given that im familiar enough with computers that I was able to build my own from scratch multiple times, and im decent at troubleshooting, where would a totally beginner cybsec begin learning employable skills? I am literally breaking my back with what I do rn, so im exploring many options, lol.
Thanks! Peace &love ✌️
it always seems like a pain sloppy slop for me, but i guess im still bad at it
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
nah my girlfriend got home like 10 minutes into it and she had just got back from a funeral so i had to accompany
start with IT. apply for help desk jobs. that's your starting point based on what you've mentioned.
damn
work your way up
i saw a pretty obvious approach though
man im just trynna get money for cwee modules and exam lol
HTB sponsore me i'll doo all the certs
in 1 year
nah, i mean, C is often sloppy and large, regardless. long bits of code. header craziness, etc. but i want to break that pattern if possible...
i mean you'll always struggle but you get better at "struggling"
also gotta get a poppy for unlimited motivation
oh dude, you said "where do i learn". sorry. Start with TryHackMe or Hack the Box Academy. my bad. yeah. start with THM in my opinion. pay for a sub. $15/month last i checked. tons of content for beginners.
too much work
also, catch up on the latest CompTIA A+, Network+, and Security+ knowledge. but don't pay for the certs, unless it's Security+.
i check 1 box. i wear a black t-shirt, lol.
how many boxes do you check?
i guess i check 0.5 boxes. t-shirt = half body lol.
you might have me beat...

damn i want cheese now +_+
@turbid goblet you in NYC?
nah philly
Ah, so not a cheesesteak?
i gotta go to NY to get the real chopped cheese
i eat cheese steaks once a week lmao
Nice! I don’t live anywhere near those cities, but I’ve been to NY a few times
Agreed
My friends live in the Bronx
They almost never go into Manhattan, takes an hour on the train each way
red teaming in new york actually sounds cool af now that i think ab it
I went to HOPE a couple of times… I’ve probably spent more time in NY hacking than any other activity
🧘♂️
It’s true. From a New Yorker
just did devel flowed right through
@thick forge cat emoji pls

yea 16 mins once i seen ftp i was like okie dokie
couldve been quicker if i knew how to use msfconsole better but that was really good practice
hacker when
gimme like 10 yrs
You could never be as unemployed as I am
Gl trying to be like me

hell yeah
||E||
bologna
Braken broin
@obtuse fern @south zenith asked me to call a number and read a script. i'm probably not his first or last victim. please take any appropriate action. attached are my receipts.
nah. they know exactly what they're doing. it's crime for sure dude.
they need anonymous dox on someone.
Blackhat skids are the best
i dont get it
Just DM any admin/mod with concerns
Blood is when someone is the first to get user or root in a released machine
thanks. i wanted to share the actual TTPs because i figured the chat could learn from them.
ahh. cool
Does anybody know a reliable way to disable the time from automatically updating in kali on Virtualbox. I am tired of fighting with Clock skew?
i can't remember, but if you search online for which packages control that in Kali, and how to disable it, that'd be a good start. sorry i don't remember off the top of my head.
ophcrack is trash on wsl
spent 2 hours messing with it just to find out I can just use John the Ripper. FML
i dont think itd be a package that fixes that if its todo with time
A legacy NTLM password cracking tool
old tech goated fr
hashcat was fighting me on this one.
John the Ripper seems to be moving a little faster while doing the same job as ophcrack
Im aware but have you tried doing NTLM passwords on hashcat?
I switched to my kali on bare metal. And still had the problem.
I know the command lol
but who has 6 hours to blow waiting to crack 8 passwords?
I got shit to do lol
yeah, so kali has a built-in thing to keep the clock the same. OHHHH SHITBALLS!!!! WAIT! do you use VirtualBox? there's a setting in there too to disable that syncs your host BIOS/UEFI clock to the VM. disable that if that applies...
oh wait, you just said baremetal
disable systemd-timesyncd on the vm then do the setting on the actual virtualbox there prob is one
yeah, it's the package/config in Kali.
uninstall the one that keeps it the same, install the one that lets you set it.
if it does im not doing it
The crack isn't time-based. You need VRAM to crack passwords lol
I did the box in a VM and bare metal I saw the switch that I needed to turn off in the VM.
I only use john when its an encrypted file tbh
Because hashcat was trying to parse a shit ton of combinations?
Tried best64 and dive.
they both exhausted.
Something makes me doubt this so much
How’s that in a ctf brother
good lord lmao
Yeah, I'm just making this shit up. 😂
Why would I fucking make this up? lol

im being ragebaited
U mad bro?
gl
Im taking about zero
Talk about zero trust in wraith
No, your comment was just dumb lol
I could never say such a thing about you my dear
Has nothing to do with brains at this point. You doubted that I am doing an NTLM password cracking challenge lol
Will eat junk and watch something
im 1 week sober
It's a league, bro. These are the concepts for practice challenges before the league starts.
Hi guys
do u guys do the htb challenges
Hey
No
do they typically take less than an hour? i might do them on my lunch work break
Some can take days
I wish I could do boxes all day
Prolabs
They are interesting
Not requiring SDR would be complicated right?
I dont have any cool ideas for chall or boxes
Me dumb
No creativity
do jjk s3 box
S3 is sooooo good
This reminds me of someone who’s over 9000
Is dragon ball worth watching?
I never got into
Even as a child
do u have a few thousand hours to waste on entertainment? then yes
I was never an anime watcher
Gohan in High School could have been its own anime
I wasted a lot on one piece
they ruined gohan my boy
I havent seen beyond Buu arc so he's still cool to me 
but I heard they nerfed him
Trunks in the future arc was pretty good too
DONT YOU DUCK ME @winged aurora I KNOW WHO YOU ARE




but why would u inject it


