#general

1 messages · Page 626 of 1

supple plume
#

Also he made ssh 0day

glad crystal
#

HackTheBox is irrelevant

remote bolt
#

in real world this isnt possibru

glad crystal
#

You think your HTB accomplishments Trump a CAE-CD university program?

proper dragon
#

dangerous levels of copium after a troublesome easy box?

glad crystal
#

RCE refers to the exploitation of vulnerabilities, not legitimate logins.

supple plume
glad crystal
#

Good game. Sorry you're not winners.

supple plume
remote bolt
#

rce is only possibru if u can run commands

glad crystal
#

You might be able to work a computer but you lack some brain cells.

patent elbow
#

wait

#

I HAVE RCE IN BASH

supple plume
proper dragon
remote bolt
glad crystal
#

Imagine arguing with cloudfare, MITRE, and every verified definition of RCE with the argument "but, I'm an HTB pro." 😂

remote bolt
#

xD

proper dragon
#

even don quixote was ultimately aware he was fighting windmills

supple plume
glad crystal
#

It's not even my definition you're arguing against, so I won't take it personally.

glad crystal
#

Imagine being high ranking, loud, and wrong.

obtuse fern
#

Imagine thinking he's being serious

high cobalt
#

If the password is weak and you log in the vulnerability ist weak password, not RCE ...

prime heron
#

Why are you so mad zero

proper dragon
obtuse fern
#

It was fairly obvious it was a joke lmao

glad crystal
#

Nah, they all really believe it. Too late to backtrack.

obtuse fern
supple plume
patent elbow
#

all explained here

glad crystal
#

Executing code remotely doesn't automatically qualify as RCE

proper dragon
#

can you guys add more intense kek emojis

obtuse fern
#

Yall are reading way too deep into him being silly

remote bolt
proper dragon
#

the present set no longer convey the depth of lels and keks

remote bolt
#

/no-hint

#

/no-hints

obtuse fern
#

Like... learn to not take everything so serious... especially in htb gen chat

west lynxBOT
#

No hints are allowed for the duration of the event. Once the event is over, feel free to share solutions.

#

No hints are allowed for the duration of the event. Once the event is over, feel free to share solutions.

patent elbow
remote bolt
#

/yes_hints

hardy frigate
#

Guys

#

I have like 5 different scans going

obtuse fern
hardy frigate
#

Feel like a fricking hacker

remote bolt
#

/please-no-i-am-scared

#

/i-have-very-high-rank

obtuse fern
supple plume
#

/DN

remote bolt
#

/xD

hardy frigate
#

Marci duel him in htb battlgrounds

faint slate
#

are we cooked with claude mythos?

prime heron
proper dragon
eternal mango
#

/ban—me—harder

remote bolt
#

hackthebox calls me a noob

eternal mango
#

Evening all 👋

remote bolt
#

but i know htb uses laravel 😉

eternal mango
remote bolt
#

hahahahahahaha

obtuse fern
remote bolt
#

i saw it on the 500 error page, which is typically laravel

high cobalt
#

Ew PHP

west lynxBOT
#

No hints are allowed for the duration of the event. Once the event is over, feel free to share solutions.

#

No hints are allowed for the duration of the event. Once the event is over, feel free to share solutions.

supple plume
remote bolt
#

/yes_hints

hardy frigate
#

Bro

supple plume
supple plume
remote bolt
#

kick hackster

#

dm is not allowed

eternal mango
#

Please don't remind me

supple plume
#

It's fun to remember now

prime heron
daring bane
#

Can someone hide their activity and started reports on GitHub from me ?

raven rain
#

@eternal mango do you have any suggestions for what to host in homelab

supple plume
#

When is my machine going to be accepted why

raven rain
#

besides Home Assistant

prime heron
#

dont tell me its a medium linux

raven rain
#

it's an arch linux

prime heron
#

shit

supple plume
prime heron
#

god DAMNIT

remote bolt
supple plume
#

But at least is something different than what's out there

worthy cargo
#

Pasta is done. It's a bit al dente

prime heron
#

i always get hard skill issued on medium linux machines

#

ive done plenty hard ones that were easier

worthy cargo
#

Nom nom

eternal mango
#

Honeypots are fun..

raven rain
#

i don't have the money to afford a RAID setup..

eternal mango
#

If you do software, the only cost is the disks

raven rain
#

best i can do is two 4 tb drives

remote bolt
#

<i>test</i>

proper dragon
raven rain
#

and those are already being used for something else

supple plume
eternal mango
#

but not something you'd want to virtualize, unless the virtualization is itself fault tolerant

remote bolt
#

how..

raven rain
#

hmm

remote bolt
#

<b>test</b>

raven rain
#

is it worth to set up wazuh

eternal mango
#

Suppose technically you could have the VM image etc held under the raid partition the controller itself is managing lol

#

But that sounds messy

#

..and probably stupid

raven rain
#

yea..

eternal mango
#

The con troller would need to be running to access the VM etc so yeah, stupid

supple plume
eternal mango
#

I'm sure it's possible though if you create physical partitions for the controller to manage

remote bolt
#

how..

supple plume
eternal mango
#

but still stupid easily 🤣

raven rain
#

at some point i want to get some 10 inch wide NAS and set up RAID on it

remote bolt
#

<u>test</u>

eternal mango
#

Unless you backed up the base image, and had snapshots backed up to the RAID every so often or something

#

The UGreen NAS are pretty nice for an easy to setup solution, but not the cheapest (£299 for a two bay)

supple plume
eternal mango
#

You could achieve the same with some cheap NUC and some USB3 drive bays

remote bolt
#

i give u 10dollars if u tell me how

raven rain
prime heron
raven rain
#

how comparable are they to SATA

eternal mango
#

USB3 is still 5gbs, if possible you could get one with Thunderbolt for speed

remote bolt
#

<h1>test</h1>

eternal mango
#

but for large transfers 5gbps would be a bottleneck for certain

iron galleon
remote bolt
#

markdown

#

markdowntestmarkdown

eternal mango
#

USB4 goes up to 40gbps which would be fine

quaint sun
#

Do you know what markdown is? awkward

remote bolt
#

no

supple plume
eternal mango
#

..but for SATA 5gbps would be enough probably

remote bolt
#

#test

#

#b test

quaint sun
#

This is good entertainment

iron galleon
#

u have to add a space after the hashtag

raven rain
#

i see

remote bolt
#

test

prime heron
#

test

remote bolt
#

#B test

#

##B test

prime heron
#

-# test

eternal mango
#

..and you honestly want actual platter drives for NAS anyway, as NVMs are more likely to fail over long term use with high read/write, so unless you plan on dropping your NAS..

remote bolt
#

-#b test

#

-#B test

iron galleon
#

-# pistola

high cobalt
#

USB? For RAID? Why even bother with RAId if it's an external driver over USB? Sounds overkill and not helpfull tbh

raven rain
#

yea i want HDDs

quaint sun
#

I've been meaning to setup a NAS for so long

raven rain
#

they hold the most storage anyway

eternal mango
remote bolt
#

what is markdown

#

and how to <b> here

jagged storm
#

You could also go LTO for backups

eternal mango
#

If you get enough for one of those ugreen ones, they are super simple to use

remote bolt
#

*****
message was auto censored by discord

glad crystal
#

wow, you're so cool.

quaint sun
iron galleon
#

for some reason my spotify isn't working with discord

#

nvm

remote bolt
#

*****
yes

eternal mango
supple plume
remote bolt
#

xD

#
-RCE=SSL
prime heron
#
-RCE=JINJA2SSTI
glad crystal
# supple plume ```diff -RCE=SSH ```

RCE is determined by unauthorized access. A legitimate, authorized SSH login isn't an RCE. If you reported an authorized SSH login as an RCE to SOC, they would laugh at you.

prime heron
#

he's back kekw

remote bolt
#

time2go4 M3

1T'5 12:30am h3r3

C14000

iron galleon
raven rain
jagged storm
#

Imagine being so wrong, you have to fight on discord about it 3 times in one day kek

supple plume
glad crystal
#

This is why people have become skeptical of hiring HTB "experts."

remote bolt
#

xD

#

how can i apply for htb

turbid goblet
#

hi guys i am done work but i am not finished ruining my day. anyone wanna fight in gen chat with me

raven rain
remote bolt
#

i know how to sql

supple plume
remote bolt
#

yes i can do via terminal

remote bolt
#

and also i can see if a website has /robots.txt

supple plume
turbid goblet
prime heron
#

to get top 100

raven rain
#

i think guts from berserk is lame and dumb

turbid goblet
#

oh my god

glad crystal
obtuse fern
prime heron
#

lmfaooo

remote bolt
#

i forgot the command but maybe i can try sql with curl

jagged storm
supple plume
proper dragon
#

dude is in the corner taking swigs of gatorade between arguments lol

obtuse fern
remote bolt
#

rce is the same as ssh and ssh is the same as rce

zealous charm
jagged storm
supple plume
obtuse fern
#

By all technicalities: you're executing code on a remote machine

remote bolt
#

i can control my remote controle remote

supple plume
raven rain
#

mfw XSS is technically RCE (the code is executed remotely on the victim's browser)

prime heron
glad crystal
remote bolt
#

xross site scripkiddieng

obtuse fern
#

it would be really funny if I came in here, put it on 1 minute slow mode, then left

obtuse fern
glad crystal
#

There's a difference between using "remote code execution" in a general manner and security terminology. Your discord profile tells me all I need to know about you.

obtuse fern
#

congrats you found the joke

#

LOL

obtuse fern
#

like

patent elbow
glad crystal
obtuse fern
#

buddy

supple plume
#

YOU'RE NOT REAL MARCIE

remote bolt
#

i can talk with myself in terminal with nc command

supple plume
#

You dont exist

rancid snow
#

who has rce in their bio

supple plume
#

Youre a discord bot

rancid snow
#

who we clowning on

glad crystal
#

Imagine jumping into a conversation you weren't initially part of to defend people's honor.

obtuse fern
#

it can be a serious thing and a joke; as in it seriously is RCE (you're executing commands remotely); but it's not RCE as in the security terminology

gray hamlet
#

can anyone please give me good source for costom dorking for blind xss like lostsec has created (shown in yt vid but can't access it)

obtuse fern
#

two things can be true, words don't just have binary definitions

rancid snow
prime heron
obtuse fern
#

like for instance if there was a server running vnc instead of RDP but you said you rdped into it, the point still comes across

supple plume
remote bolt
#

script alert(1)

gray hamlet
#

ok just give me good google dorking sources plz

prime heron
rancid snow
#

skids need to stop watching security youtubers, theyre all either entertainment or scams

glad crystal
remote bolt
#

ecr

obtuse fern
#

brother you're the one that was insulting them

proper dragon
#

when you change a channel on a television isnt that technically RCE

obtuse fern
#

they have every right to throw the proverbial clown pie back in your face

remote bolt
#

apash just leaked he is from europe

lusty swallow
high cobalt
# eternal mango Cost, read the rest. Is it ideal? No.. is it an option? Yes

Imo a second drive would be better suited as a proper backup instead of a RAID array. As far as I know USB drives aren't recommended to be used in an array because they could randomly disconnect and kinda defeat the redundancy purpose. And the redundancy probably doesn't really matter anyway in such a homelab setup (except if it is just for the sake of learning the concept)

glad crystal
rancid snow
supple plume
#

Everything is getting remote af at this point

glad crystal
#

Let me know and I'll take you seriously.

obtuse fern
jagged storm
#

Ban incoming

glad crystal
proper dragon
#

ridiculous clownworld escapades

raven rain
#

bro

obtuse fern
#

that's not how that works at all

sharp shuttle
#

never a bad time to come to general

terse dirge
sharp shuttle
glad crystal
eternal mango
supple plume
glad crystal
#

This discord server is a joke.

obtuse fern
patent elbow
#

not you

obtuse fern
#

there's also multiple dictionaries

sharp shuttle
#

id rather not get involved on this specific topic

glad crystal
remote bolt
#

xD

obtuse fern
#

you know what fuck it

#

staff can shout at me about it later

glad crystal
#

Yeah, do it.

terse dirge
proper dragon
heady sage
#

Son

jagged storm
#

Yeah, probably time for the ban lol

patent elbow
#

He's a server booster, paying for VIP+

#

😂

supple plume
#

pokeball attack

raven rain
#

don't worry i won't yell at you

glad crystal
#

Do me the favor because I already cant stand you dumb asses.

faint slate
#

lol

patent elbow
#

don't worry

turbid goblet
patent elbow
#

i'll never forget you

remote bolt
#

zerotrust, take a deep breath and lets talk about something else

patent elbow
supple plume
turbid goblet
#

this is my favorite day

patent elbow
faint slate
#

lmao why did he take the hard way

patent elbow
#

he was fun

proper dragon
#

i enjoy the chaos
i don't think I had a stake either way

turbid goblet
#

typical GRC

patent elbow
#

i was thinking about ragebait but he was real 😭

rapid badger
#

real bozo

prime heron
#

thats 2 bans i witnessed

proper dragon
#

bet everytime he sees RCE in the future he'll be overcome with rage

prime heron
#

he's gonna get a flashback

obtuse fern
#

like... it was pretty fuckin obvious

faint slate
#

buddy got shipped to /dev/null

eternal mango
#

It was all obviously a joke..

prime heron
#

rm -rf zerotrustwraith

eternal mango
#

Apart from the last bits (from them)

prime heron
#

bro was a server booster too

#

tragic

jagged storm
faint slate
#

we lost server funding

prime heron
#

no more server tag

iron galleon
#

LMAO

sharp shuttle
#

the hills are always exciting

jagged storm
#

Like, this was just a matter of time lol

faint slate
obtuse fern
#

and?

faint slate
#

who will fund the server now?

proper dragon
#

hopefully the goy learns to focus his knowledge and his efforts more judiciously in the future

obtuse fern
#

@supple plume needs to buy double the boosts to make up for it Prayge

jagged storm
patent elbow
# obtuse fern like, i'm not high in thinking that you were mostly just fucking around, even wi...

it was 100% trolling, like an old troll from a few months ago, someone pinged me and this guy legit made me laugh, i thought it was ragebait at first but when i realized he was dead serious i just lost it and told him i had an ssh rce... i mean yeah, he's technically right, it's not a security related RCE, but he was saying it in such a serious way i couldnrt not send him my famous ssh rce..

iron galleon
#

conserve

eternal mango
#

I just boosted twice, the lights will stay on, phew

prime heron
supple plume
proper dragon
prime heron
#

was gonna show him this

patent elbow
obtuse fern
#

my cubes are locally sourced

faint slate
#

close one we would've had to host our staff in the street

obtuse fern
#

anyway

jagged storm
obtuse fern
#

Grass fed

prime heron
#
<command>whoami</command>
root
raven rain
#

my qberts lay cubes

obtuse fern
#

qbert is a real one

supple plume
rancid snow
supple plume
#

I can spawn any stupid comment from months ago

jagged storm
obtuse fern
remote bolt
#

remove access trojan

supple plume
#

.

turbid goblet
#

34 btw

obtuse fern
jagged storm
#

rat access trojan 🐀

obtuse fern
supple plume
remote bolt
#

via crypto

supple plume
#

It lives in my head rent free

obtuse fern
#

you know what's funny

rancid snow
obtuse fern
#

it's probably not even a contender for one of the dumbest things i've said

rancid snow
#

true

remote bolt
#

because some ppl dont care about discord

jagged storm
obtuse fern
#

idk man i say about a dozen dumb things a day

jagged storm
#

So he must be from the alternate good universe where that is true

rancid snow
#

¯_(ツ)_/¯

obtuse fern
#

Kali... stable? huh???

remote bolt
#

debian is based on kali

sharp shuttle
#

i identified him as abrasive and opinionated, but i like that type of person. i just think its important to self regulate and wear the right mask among whatever ilk you are hanging out with. Very dumb hills to die on.

obtuse fern
#

It's like one of the MOST notorious distros to break on update

supple plume
rancid snow
#

its okay hes been studying cybersecurity for 7 years and is the top 5% of the industry kek

prime heron
# rancid snow its okay hes been studying cybersecurity for 7 years and is the top 5% of the in...

he was struggling on this:

Cap provided a chance to exploit two simple yet interesting capabilities. First, there’s a website with an insecure direct object reference (IDOR) vulnerability, where the site will collect a PCAP for me, but I can also access other user’s PCAPs, to include one from the user of the box with their FTP credentials, which also provides SSH access as that user. With a shell, I’ll find that in order for the site to collect pcaps, it needs some privileges, which are provided via Linux capabilities, including one that I’ll abuse to get a shell as root.

im dead bro lmaoo

turbid goblet
#

i like his picture of himself with the hood and knife

prime heron
#

7 years?

turbid goblet
#

i felt scared

rancid snow
obtuse fern
#

imagine getting triggered though because someone's bio says "they/them"

jagged storm
#

Bro said it was insulting to suggest he do academy instead of boxes even though he was struggling on starting point while using a writeup

obtuse fern
#

no shot

high cobalt
rancid snow
prime heron
#

with no writeup most people can prob do that box in maybe 30 mins

#

if you are 7 years deep in cyber sec that like 5 - 10 mins

obtuse fern
#

I do get that SOME of the boxes are so old that you just breathe in their direction they break, or you gotta summon greg from IT to install an old version of a tool that works

#

I think that the starting-point boxes could use a bit of a tuneup (not like a full update, but bring them more in-line with modern tools)

sharp shuttle
#

oh last night?

turbid goblet
#

i only cried twice on starting point

sharp shuttle
#

yeah he had the ssh priv key and didnt know to use it for privesc

prime heron
#

my biggest thing is people using that smbclient \\\\ip\\share

obtuse fern
#

breh

proper dragon
prime heron
#

like just use impacket-smbclient user@ip

rancid snow
#

I aint gunna fault anyone whos struggling on a box but you do have to be humble about it if you are

sharp shuttle
prime heron
proper dragon
sharp shuttle
#

jesus christo

obtuse fern
prime heron
#

but lots of people use that tool instead of impacket's smbclient

#

they prefer the other one

obtuse fern
#

smbclient also accepts // instead of \\\\

turbid goblet
jagged storm
proper dragon
obtuse fern
#

fuckin

#

lmao

turbid goblet
#

i need to go through a full course on impacket some day

sharp shuttle
#

how else can RCE be interpreted? it is in the OWASP

#

its globally defined

eternal mango
#

...u wot bruv

rancid snow
#

arguing with froj is a key indicator in stupidity, because froj is always right

jagged storm
prime heron
jagged storm
#

I got receipts

sharp shuttle
#

wow he was calling jord stupid

#

yikes as the redditors say

supple plume
molten bobcat
rancid snow
supple plume
#

RCE certification

prime heron
#

he is the rce genius

sharp shuttle
#

i think jord has taught me more than anybody ive ever met in cybersecurity

faint slate
supple plume
prime heron
jagged storm
obtuse fern
#

maybe just maybe he was thinking CWE

prime heron
#

similar to how you would get rce via ssh

faint slate
#

ssh confirmed

jagged storm
#

They tried to explain

obtuse fern
#

i'd prefer not to, in fact, i don't know how to read, i'm just typing off vibes

rancid snow
supple plume
obtuse fern
eternal mango
#

Missdris

obtuse fern
#

no one will beat out seadris's legendary coin status though

#

o7

supple plume
#

I never knew seadris

eternal mango
#

Anyone still in touch?

sharp shuttle
#

i talk to him monthly

#

hes fine

eternal mango
prime heron
eternal mango
prime heron
#

he's one of those people who leaves htb server for a few months comes back leaves again

obtuse fern
proper dragon
#

zero showed me that my r*tardmaxxing strat needs work

prime heron
#

idk why people do that

obtuse fern
# obtuse fern

i requested this image to be made into a sticker, this was my contribution to the server

sharp shuttle
sharp shuttle
#

leave and come back better

proper dragon
obtuse fern
#

i mean... no no i won't be toxic

sharp shuttle
#

im also a subscriber to the rwordmaxxing lifestyle

#

only approach to modernity that works

jagged storm
undone fossil
#

hello chatters

sharp shuttle
#

hello dumbass

rancid snow
obtuse fern
sharp shuttle
#

you dont know shit jord you think RCE means Remote Code Execution

#

dumbass

#

ffs

jagged storm
#

froj we were just talking about you

undone fossil
#

wonderful

obtuse fern
#

Hey froj

rancid snow
#

you missed the ban

sharp shuttle
#

that frog guy

#

thinks hes special

#

(he is)

#

but

#

the audacity

undone fossil
#

oh he got banned

#

the arch guy?

supple plume
undone fossil
#

based

sharp shuttle
#

i still dont quite know why

#

but i was reading you trying to help him last night

#

and he was combative

turbid goblet
#

sorry froj we know he was ur friend

jagged storm
sharp shuttle
#

was funny befoe sleepy

prime heron
#

i feel like kali or even parrot is enough

undone fossil
#

no?

#

as in not good

proper dragon
sharp shuttle
prime heron
#

white arch when arch enters the room

undone fossil
#

minimal os w/bloat

supple plume
obtuse fern
supple plume
#

Cold temperature level iq type shi

rancid snow
prime heron
#

took me only a day to switch back

proper dragon
#

i cant imagine having the low knowledge low self awareness combo
i'd just gravity myself from a cliff

remote bolt
#

~ $ whoami
whoareyou

sharp shuttle
#

you guys hack with os's? lmfao.. i only need systemd

supple plume
rancid snow
#

the best part of blackarch is just stealing the repo to install tools easier if youre doing your own arch setup

prime heron
#

kali + i3 + pimpmykali 👑

remote bolt
#

xD

prime heron
sharp shuttle
#

no, i do not need the osi stack, just straight bare metal. i use dip switches for my binary input

remote bolt
#

~ $ whoami
idontknow

supple plume
sharp shuttle
#

cat echoesofwhoami | grep balls

remote bolt
#

xD

undone fossil
#

Bare metal cloud specialist peepSelfie

obtuse fern
#

TIL how older rotary phones worked, and that you could dial using the hangup latch

sharp shuttle
#

thats a good idea holy shit

remote bolt
#

~ $ echoesofwhoami
echoesofwhoami: command not found

sharp shuttle
#

that brings me from binary to decinary

remote bolt
#

sudo apt install echoesofwhoami

sharp shuttle
#

elliot mrrobot enters the cafe holding an analogue phone, you know you fucked up

supple plume
high cobalt
#

The best distro ist the one you learn to customize to your liking 😌 change my mind

eternal mango
undone fossil
proper dragon
remote bolt
#

xD

supple plume
swift pond
#

Has anyone see mythos doing ROP chains on FreeBSD? Is offensive security over?? lmao

undone fossil
#

For a uni student they're pretty well educated

obtuse fern
undone fossil
obtuse fern
#

it's really phreaking cool

eternal mango
#

Goes into phreaking nicely

#

Hahah

remote bolt
#

i did:
echo "alias sai="sudo apt install" >> .bashrc

now i can sudo apt install everything by just typing sai

proper dragon
undone fossil
#

yeah p much

sharp shuttle
#

opkg snap conda apt install seclists

undone fossil
#

but also a case of their environment being students

obtuse fern
#

theoritically i have a degree in physics

undone fossil
#

most of them likely dont give a shit, so someone like that is likely higher up in their class

#

etc. etc.

#

who knows, either way dont dump on them too hard ¯_(ツ)_/¯

rancid snow
faint slate
#

ssh is theoretically a RCE if you think about it

remote bolt
#

nice

supple plume
#

Ssh is not rce

remote bolt
sharp shuttle
#

my student:teacher relationship with jord is sassy senpai

rancid snow
undone fossil
#

my teacher:student relationship with brath

remote bolt
#

owhh

sharp shuttle
#

jesus lolol

undone fossil
#

oh wait i forgot that gif gets very nsfw

sharp shuttle
#

was that george droid?

proper dragon
keen knot
#

Guys, I want to see my modem's traffic from my Mac with Wireshark. Will any Ethernet adapter work for that?

rancid snow
#

ive had autoremove accidentally remove shit I was using because it was installed as a dependency for something when I did in fact also need it on its own

eternal mango
#

Read about the phreaking scene, blue/red/black boxes Brath? Equally cool to learn about how they worked

undone fossil
remote bolt
#

yes better manually

sharp shuttle
#

all i saw was systemd and HP lovecrafts cat name

undone fossil
keen knot
proper dragon
remote bolt
#

i also got alias for uptime -p

sharp shuttle
#

what is it

turbid goblet
eternal mango
#

I remember the terms being mentioned when I was learning as a kid, but was way too late for that

supple plume
#

upptime

sharp shuttle
remote bolt
#

upt

rancid snow
sharp shuttle
#

the wire hilt

#

omg im in love

faint slate
sharp shuttle
#

thats some ork shit

proper dragon
#

RAM - randomly accessing musculature

sharp shuttle
#

i would put rainbow leds on it so when you go for the juggular you get a light show in the open mouth of the victim

#

😮

undone fossil
#

holy based

eternal mango
#

Oh god damn, Marcie..

#

..Those messages were all meant for you

#

Somehow I thought Brath sent the message about rotary phones 🤣 They did not.

hoary dawn
#

I’m almost ready to be active again on HTB i probably shouldn’t have taken such a long break in the beginning of my education im gonna have to refresh the hell outta myself lol

sharp shuttle
#

i was only suggesting to use a rotary phone for hacking

#

instead of a terminal

eternal mango
#

I know

#

I just read back and saw you didn't make the post I was replying to

sharp shuttle
#

oh yeah

supple plume
turbid goblet
#

time to play warcraft 3

hoary dawn
#

I’m gonna play some Xbox for a little yall I just booted up watch dogs 2 and I put it on realistic difficulty so let’s see what’s different with it

remote bolt
#

decimal = 0-9
hexadecimal = 0-9 + A-F

proper dragon
worthy cargo
#

<-- Diablo II

rancid snow
sharp shuttle
#

im just waiting for someone to actually list a good game

#

yawn

hoary dawn
#

Yea well it was for good reason I cleaned my setup and made it much more HTB friendly lol like I was saying yesterday or the day before I put parrot os security edition on one of my systems

jagged storm
proper dragon
worthy cargo
#

But nostalgia!

#

And modding

sharp shuttle
remote bolt
#

power over ethernet

sharp shuttle
#

im but a humble phisherman

jagged storm
#

All the mods just make it more like poe lol

#

Like median

worthy cargo
#

I never enjoyed median

#

I like Brother Laz

#

I played his older mods

#

Demon Trip

molten bobcat
#

Frojs teaching style is pulling out Microsoft paint

sharp shuttle
#

we all agree that the best game ever made is hit 2024 game, chained together

hoary dawn
#

Speaking of Ethernet my setup now has Ethernet capabilities as well ayyyy I should go plug it up

proper dragon
hoary dawn
#

My wifi slow as heck by the water

sharp shuttle
turbid goblet
#

if ur trying to edate just play valorant

jagged storm
proper dragon
#

and you can see the character model's accentuated and evocative breathing so you know the gameplay will be top notch

sharp shuttle
turbid goblet
#

☠️

sharp shuttle
#

"you play val?"

proper dragon
#

valorant sage mains are perfect wife material if you're planning on getting stabbed in your sleep

rancid snow
turbid goblet
#

it could be worse

#

edating on vrchat

sharp shuttle
sharp shuttle
#

heres my venmo

rancid snow
#

she was also running a hacked animal crossing twitch stream where people could pay to come to one of her 12 islands to get whatever item/money they wanted

sharp shuttle
#

now that i support fully

#

thats good busines

rancid snow
#

made a couple grand from it before nintendo locked shit down more

sharp shuttle
#

i remember helping my wife out by spending an entire weekend doing the...

#

garlic?

#

whatever the stock exchange is

#

and making her filthy rich

rancid snow
#

turnips

sharp shuttle
#

oh right

warm ravine
#

I can hack

rancid snow
#

prove it

sharp shuttle
#

you can hack? okay. what does coercer do

prime heron
#

coercer coerces

undone fossil
#

coerce deez

prime heron
#

ntlmv2 or http auth

#

it uses like named pipes and shit

sharp shuttle
#

coercer? i barely know her

proper dragon
sharp shuttle
#

responder? I barely know her!

molten bobcat
prime heron
#

mitm6 when linked up with ntlm relayx

rancid snow
proper dragon
rancid snow
#

she has better opsec than I do

proper dragon
#

quick, which categories does this fall under

sharp shuttle
#

what part?

#

this is pentesting

proper dragon
#

yea

supple plume
sharp shuttle
#

quintessentially bri ish

eternal mango
#

Had to use /gif because the default Discord GIF search doesn't keep the good stuff

prime heron
proper dragon
sharp shuttle
#

oh is that the cheat code? i am always dissapointed with the discord gif filtered stuff

supple plume
sharp shuttle
#

sick til

rancid snow
#

/gif

#

Ive been bamboozled

rustic pulsar
#

Yo

prime heron
#

yoo

quaint sun
turbid goblet
#

my privesc is so poopy man

rancid snow
#

...cant use vms anymore?

proper dragon
#

im noticing a criminal amount of youtube videos written by AI
the "it's not X, it's Y." and the other short form rhetorical devices are exhausting and unnatural to sit through

rancid snow
#

I remember when youtube was actually a legimate source for learning things

prime heron
quaint sun
proper dragon
jagged storm
prime heron
#

after linpeas kernel exploits internal ports pspy64 and internal network interfaces im done

quaint sun
turbid goblet
#

is kernel exploits very common?

rancid snow
proper dragon
#

I got introduced to HTB when I found xct's channel and thought the dude was a wizard

turbid goblet
#

i ran linpeas but linpeas didnt flag it so i missed it until i copy and pasted the results into claude lol

prime heron
#

linpeas should say like more probable

turbid goblet
#

it didnt say anything about it

#

wait is my linpeas out of date or someshit

#

fk

jagged storm
rancid snow
#

linpeas is good but itpl throw out a bunch of extra shit because its a maybe and itll look just as important as the actual super obvious path forward

quaint sun
#

I was using linpeas today and, it's probably skill issue on my part, but none of the "95% PE" flags seemed useful

rancid snow
#

if im running linpeas its because Im really struggling and scrolling is a good passtime to think about the issue but never actually gets me the answer itself

turbid goblet
#

yeah idk ig im just not comfortable yet of what is normal vs what isnt

#

how many boxes i gotta do to get to that poitn

#

im 41 boxes down rn

molten bobcat
#

A customer is angry with me

turbid goblet
#

so never

#

damn

molten bobcat
#

They experienced an incident more than 7 days ago and their logs on their firewall only retain for 7

rancid snow
molten bobcat
#

And now they're mad the logs are gone by the time they were ready to work on the issue

tight path
#

sounds like a policy issue for log retention

#

$$$

prime heron
#

am*

eternal mango
#

Sounds like a successful test of log retention policy

rancid snow
eternal mango
#

If there is a policy...

#

🤣

tight path
#

unlucky

eternal mango
#

Sucks they think that it's your fault if they dragged their heels..

rancid snow
# turbid goblet rip

if it makes you feel better privesc in the real world is usually either 1. completely unnecessary or 2. completely trivial

#

I think one of the biggest mistakes in HTB box guidelines is requiring a priv esc path to root

tight path
#

we get hounded over cost for 6 months log retention, and then have an incident that goes back 2 years, and it takes forever to pull anything out fo cold storage (and costs)

molten bobcat
rancid snow
#

it warps thinking and creates a ctf style mindset that had poor translation to real world adversaries

molten bobcat
#

"we're disappointed in you."

#

Okay?

#

Bro I don't care

#

My job is to stop attackers

molten bobcat
#

I don't give a fuck if you are retained as a client

tight path
#

orgs will do anything to shift blame

molten bobcat
#

It's not my job!

eternal mango
molten bobcat
eternal mango
#

RIP

molten bobcat
#

Same email thread

#

These people are dense as fucking osmium its marvelous

proper dragon
rancid snow
molten bobcat
#

Yes lmao

rancid snow
#

lmao

molten bobcat
#

THE VERY SAME

rancid snow
#

the irony

jagged storm
molten bobcat
#

People will scramble and scrape

#

To blame everyone but themselves

#

When things go badge

rancid snow
#

meanwhile their adversary is like:

tight path
#

thats it, keep fighting each other

molten bobcat
#

There's just no logs to examine

tight path
#

they seem like the kind of org who would only log denied logs anyway

molten bobcat
#

Logging? What's that?

tight path
#

thats just unnecessary opex

sharp shuttle
#

do i look like a blue collar man...

tight path
#

cut

rancid snow
#

theyre almost certainly actively compromised and their detection stuff probably caught it too and nobody did anything

rapid badger
#

if 90% of your cloud costs arent logs are you even trying ?

sharp shuttle
#

^^^^

#

REAL

tight path
#

dont forget to log your logs

#

otherwise how will you know you're logging

rancid snow
#

remember that the NSA team lead of Tailored Access Operations held a talk about nation state actors and admitted that the number 1 thing they hate to deal with is an org that is actively printing their logs because it means they have to send an agent in person if they want to cover tracks and thats riskier

high cobalt
#

I wish the university I work for had money to keep logs for longer than 14 days 🫠

rancid snow
#

oh interesting, I can no longer find that talk on YouTube 🙂

tight path
#

the funniest part for me about logging was how sysadmins found operational use cases to better monitor their network with splunk than the NMS they paid for, finding stuff that was effectively invisible otherwise

rancid snow
#

found it but had to use gemini to find the video:

https://youtu.be/bDJb8WOJYdA?si=7TQhoLb05jzmdoXX

Rob Joyce, Chief, Tailored Access Operations, National Security Agency

From his role as the Chief of NSA's Tailored Access Operation, home of the hackers at NSA, Mr. Joyce will talk about the security practices and capabilities that most effectively frustrate people seeking to exploit networks.

A transcript of this talk is available:
https://w...

▶ Play video
tight path
#

link flaps happening too fast for snmp traps to capture? good thing syslog sends it every time it happens

#

when they wanted to reduce log spend, the ops teams complained more than security because they would loose visibility of the network

spice copper
#

which is the best virtual machine to use linux on?

tight path
#

there isnt really a "best" one, everyone has different opinions of their preference and use cases

#

try a few out and pick the one you find suits you best

spice copper
tight path
#

some people only use vmware, some hate broadcom enough to only ever use vritualbox, others prefer bare metal like proxmox

eternal mango
tight path
#

not to mention the fuckery of putting their software behind an account creation requirement for free software, the price model proposal was insanity lol

rancid snow
#

virtualbox, VMware, and proxmox are probably the most popular

sharp shuttle
#

im a parallels user

#

vmware can suck it

rancid snow
#

yeah if youre on mac parallels is the only real answer

remote bolt
eternal mango
#

My kid is going to see another re-imagining of Romeo and Juliet soon, apparently it involves BMXs doing sick jumps and other antics..

tight path
sharp shuttle
#

i remember watching leonardo di caprio in a roneo and juliet with guns lol

high cobalt
#

VSpere is so good, its the only software I know where localizing into another language does totally mess up numbers 💀 A folder with 5 VMs using 100GB disk space each? That's definitely 20TB used disk space, isn't it?

eternal mango
#

Thing is, they had already changed the root password a couple of years back after they included it in the Android app to support upgrading older firmware models

#

So they messed up twice

tight path
eternal mango
#

(amongst the rest of the issues found like.. being able to flash a device with a backdoor from a webpage..)

#

Still waiting for them to fix their update flow to not just.. you know.. TRUST EVERYTHING

tight path
#

Its evidence that they use cookie cutter firmware builds across eveything too.
This device is used for GSM networks but had gpon configuration

eternal mango
#

2 months left until the generous 6 month disclosure window is up, blog is ready

tight path
#

Make sure you share it here

eternal mango
#

This was a smart telescope. They totally updated the API without documenting it, which broke a load of community run projects

tight path
#

Lol

eternal mango
#

So I figured out how to downgrade it to a version that did 😅

#

They say they have an "open initiative" to publish the new API docs at some point.. we'll see

tight path
#

They always get pissy when you list a finding as "undocumented"

#

They know its there

eternal mango
#

They had an nginx config that let you just traverse to read any file on the device due to a weak alias definition (they've fixed that one)

tight path
#

They just dont want anyone else too

latent oak
#

Lo

#

How are peeps

#

?

rancid snow
#

so when they grab for their 'longsword' its just a shotgun with longsword written on it

eternal mango
rancid snow
#

idk what titus is

latent oak
#

Shakepeare is the bees knees

eternal mango
#

Titus Andronicus

latent oak
#

That’s what the kids are saying

eternal mango
#

Another Shakespeare play

#

Freaking fire

latent oak
#

I was in a couple of those plays…

hardy frigate
#

Bro I should have been a preacher

sharp shuttle
#

you still could be

latent oak
#

I was the sergeant and murder #2 in Macbeth

turbid goblet
#

im fish #212 in finding nemo

latent oak
#

I was Snout the Tinker in A Midsummer Night’s Dream

#

Clutch roles

eternal mango
#

I was a tree in some primary school play about some kid born in a barn

#

One and only play I ever took part in

#

I like to think I really captured what it is to tree

latent oak
#

lol

#

The last play I was in was written by a friend of mine

#

“A New Brunswicker’s Guide to Alien Abduction (Abridged)”

frigid mountain
#

been troubleshooting for 2 hours an intermittent audio and video stutter in my DJ rig. 😭

latent oak
#

DJ Stutter would be a great name

frigid mountain
#

it would

glad mauve
#

so i'm coming back to htb after like 6 months or so. Is it me, or did the way boxes are spawned / run change?

prime heron
#

independant instances i think

glad mauve
#

spawning seems to take a really long time

latent oak
#

They seem the same to me…

glad mauve
#

and they don't stay up 24 hours anymore

#

and have dynamic IPs like Release Arena

latent oak
#

But I’m on free tier atm

turbid goblet
#

bing chilling

glad mauve
#

i was working on cctv last night, came back just now, it was off. Starging it now, its still going after like 5 minutes

#

also took a while yesterday too

prime heron
glad mauve
prime heron
glad mauve
#

ah. i never knew that part

prime heron
#

yea

#

RA boxes spawn a bit before the box comes out

#

and stay up until all players leave the box probably

glad mauve
#

ugh. ok. i think the web app just never got the message the machine was spawned. I refreshed the page and it was ready.

heady sage
#

Oy vey

frigid mountain
#

i think I squashed my audio playback bug

lyric token
#

yo

#

What is going on with the UI update?

#

Can this be reverted?

alpine pumice
#

No

alpine pumice
lyric token
#

It is horrible. Makes way less sense, less intuitive. Based on how it looks im sure a LOT of people have complained about it so dont mean to go off on you

#

thanks man

heady sage
#

pack it up guys

#

pentesting is over

#

Claude Mythos is here

alpine pumice
#

they said the same thing about computers when computers were invented

#

they said the same thing abour horses when the car was invented

prime heron
hardy frigate
lyric token
#

jfc, what are we doing here people? The lines are too long??? Are we catering to the worst kind of end user?

hardy frigate
#

Because for when I have to "pack it up guys"

lyric token
#

wth smh

lyric token
#

this is like a meme

#

the lines are too long so people skip over them

#

well those people dont want to learn

#

you should take their subscription money and ignore them

turbid goblet
#

but whats ur wc3 ladder rank

lyric token
#

I imagine a lot of revenue is driven by those entry level people with no technical or professional experience so it makes sense from a business perspective to cater to them

alpine pumice
turbid goblet
#

cap

alpine pumice
#

no cap

prime heron
#

cap

alpine pumice
#

i was a wc3 god

lyric token
#

:p

#

u play cg at all

#

or just ladder?

alpine pumice
#

i used to be a professional gamer

#

ladder and tournaments

turbid goblet
#

i used to play some cgs

#

post tourney wins

alpine pumice
#

never won a tourny

turbid goblet
#

island defense was best custom game

alpine pumice
#

went against real pros and lost

#

ladder was ez though

#

my best game was cs

#

won tournaments in that, cal-m

#

undead/orc pwn

#

all my homies hate night elf and humans

turbid goblet
#

u played two races are was num 1?

alpine pumice
#

i could play all races, but not high level like that

#

undead was my best

#

and i just liked orc

lyric token
#

god academy is such garbage now, i dont even want to use it 😭

#

pce

#

it is what it is

#

ima bitch here until im banned or its reverted tho

#

bye for now

alpine pumice
#

just use /feedback

rancid snow
#

no bitching is more fun and less productive

west venture
#

GIVE ME CVE

lyric token
#

ok I take it back on the long line thing, that makes sense for the reasons they listed. Why change the actual UI though? It just does not make sense, the reasons they outlined don't explain the massive changes

#

these people are up to something, probably someones cousin is a webdev that had a great idea and needed work, or they needed to generate some sort of KPI and came up with a UI overhaul to make it "modern"

#

prolly some damn manager trying to keep his worthless job

#

:|

iron galleon
#

lmfao

#

someones cousin is a webdev

#

thats funny as shit

lilac portal
#

sadly things are bound to change man, I used to hate steam's UI as well

lyric token
#

@north laurel yo I saw u thumbs down the UI change announcement

#

im trying to start a small grassroots collective aimed at actualizing policy change, and I think you could be what im looking for

alpine pumice
#

you prob on win 7 still

lyric token
#

It is stable.

#

and it works with my mine sweeper

iron galleon
#

what if someone made a browser extension to restore the previous ui

worthy cargo
#

Come on guys

#

Be like the Borg

#

Adapt to the new UI

lyric token
worthy cargo
#

Windows 10 isn't bad.

lyric token
#

agree

#

we are talking enterprise domain environments

#

fuck microsoft otherwise

alpine pumice
#

ms owns

#

they mog you bro

worthy cargo
#

Bro

alpine pumice
#

part of the mag 7

#

critical tech for usa

worthy cargo
#

Visual Studio is the best IDE mankind has ever created.

lyric token
#

bro they be changing the azure dashboard and 0365 dashboard UI too

#

smh

#

u all in cahoots

alpine pumice
#

they also disrupted that bully sony with xbox