#general
1 messages ยท Page 641 of 1
Good good, learning AD nowadays
so real bro
how are you finding it?
I'm always stuck and crying
Fun, but very information dense
finished the first DC, theres some web services but I cant figure out what to do
๐ฅฒ
daag lasagne ur hobby puts ram prices to shame
Yeah ofc we dont know what to do in a web service
golammm
Golam sounds alot like Golang
you cant talk about golang without pinging ceald
@austere sinew health check
Golang is the best
you should all learn Go! instead https://en.wikipedia.org/wiki/Go!_(programming_language)
Dive computers are just fancy dive watches btw, dive suits and scuba gear also get very expensive very quickly
altho i suppose once u buy them it cheaper from then on right

Add to that having to rent scuba tanks and paying for their refills 
bro?
Whose this
what an image lol. I think from that I kind of see what you're getting at
Then you also have specialized air mixes for different types of diving
chase mulligan
And whose that
specifically around the eyes more than anyhting
the facial shape is the same
nah the face in the pfp flares out a lot more in the midsection
nice jumpscare
hes a freak
In 2026, you can just loosely write the entire logic of the program you want, and then integrate AI into the compilation pipeline.
So Pseudocode -> AI compiler -> Go -> go compiler -> assembly -> binary.
hes a groomer
but i guess I also can't unsee it now
lol
Just tell the LLM to write ASM
drew this little guy as a backup yesterday
@sharp shuttle my company isn't giving me actual pentester work as an intern ๐๐
They gave me a report to write on SDLC
sorry bro
Waiting for a UDP top 1000 scan to finish. 12 min remaining.
it's ok
I want actual work ๐ญ
And good pay
I added min rate but it misses ports
shadow wizard money gang
If it's too low level, it could fuck up the logic without the provided libraries in a higher level language
brother you have a job already ๐ญ
Intern
I slept for like 4 hours and woke up. Finished/rooted a box just now and working on another.
I got it through nepotism
that's something man
the best way
Im a fucking nepo baby
Yes but it'd skip a bunch of steps 
Brathadair why aren't you doing a box
Why aren't you? 
Who says I don't
me too brother, me too
I say you aren't cos you're here
Well I've BEEN doing
Oh
i drank 3 100 proofs
And the proof is my silver badge
wooweee
Should be ruby by now
And the absence of one for brath
Should be holo forver
Every time I solve an active machine, it gets retired in few days ๐ญ๐ญ
1 more flag and Im platinum
Which is why I only like to do seasonal ones
Speak boy!
but they're the most fun to sweat
I am going to testify against you in court tomorrow
Breh it's 40ยฐC here
Everything's sweaty
33 where I am
im going to repeatedly yell "objection"
@spark mulch why do you have that Tryhackme's AI bot pfp
Ig smog helps sometimes ๐
I don't want my online image to be represented by something that is (or strongly resembles) a fucking pdf
damn
idk what that is, I drew this
Based
thats valid
Bro is using THM AI's bots pfp
im sorry coco i was just being autistic and noticing
i wasnt trying to ruin it
A pdf?
it's ok, pfps are transient, more will come and more will go
Not for me ๐
I'm just a psychedelic alien.
Ive been using the same pfp for 3 years
a map, a nambla enjoyer, a roblocks player
I don't get what that actually means
Pedophile
Oh
minor attracted person, national association of man boy love something
'pdf file'
Docx file
this one will be a placeholder I think, since it's already been misidentified twice as pre-existing things in the 5 minutes since i swapped to it lol
North park
Use this
no
Weird sounds are coming out of my chest bc of this
๐
you should Photoshop your own pfp
can i pick your next pfp cocochan
It might be a tumor
I drew this one
Broo
i will accept suggestions but I will be the selector
use this @spark mulch
lol
dark souls mentioned
Hi chat
This?
lol
use deez
chudden
Billions must pet
Hoi donut! Uhhh I was hospitalised again recently but should be getting better now 
Hru!!
stop dying bruh
I know whoami is me
Of course. I have your home network remember
Fr this is just tiring
Nice you missed all the bolocs I sais in your server 
my homegirl wolo is in the hospital again, fam what can we do to help her
not again 
get better soooooooooooooooooooooooooooooon
Mfer
I was discharged but it was once again a moment where all the doctors were looking at me like โhow are you still aliveโ
I messed up and took double the dosage of my heart medication
What happened?
And Iโm already on a high dose
Wolo's heart might not be normal, but it is unbeatable
No beats?
Yeah, it was not fun
it defies all laws of science, medicine, and nature
What do you need to get better? I can get you @meager kernel s heart
๐
how did the hospital respond?
Wee woo wee woo ig
did they tmake you smoke a pack of 20 cigs to counteract the meds?
They were scared shitless
Patreon - https://www.patreon.com/jadenwilliams
Merch - https://www.jadenw.com
Socials -
โค Website - https://www.jadenw.com
โค Main Channel - https://www.youtube.com/@Officialjadenwilliams
โค Gaming Channel - https://www.youtube.com/@GamingJadenWilliams
โค Tiktok - https://www.tiktok.com/@officialjadenwilliams
โค Instagram ...
i volunteer clouds heart for wolo, he would understand
I nearly gave a consultant a panic attack
??
that's what you want out of a senior doctor
inability to function under pressure
ideal quality
fair
Tbf it was a crazy situation
I can help you with that
sarcasm
good thing you're alive
I donโt blame them
So your heart was beating too slow bc of the overdose?
I have yet to sing you happy birthday 
It was beating way too slow then way too fast for some reason
Just super unstable
you like mathrock?
Never heard of it
Awh ๐ญ
Dw donut
Itโll take a lot more to take me out
So uh guys
Its actually crazy wolo, things escalated so fast
It is holiday
either way wishing you ืจืคืืื ืฉืืื ( "refuah sh'lemah" - means "a complete recovery")
Dont rely on your meds in the regular box
Fr
When it isn't for u ๐
I have been to the emergency room like 4 times in the last few weeks
In India you know right we get lots of public holidays
I got too
Iโm getting tired of it they better gimme my damn surgery
But idk for what
Animals as leaders, Polyphia, Beyond Creation, Archspire
Tamil New Year
math rock
math rock is so goatedd
Happy birthday ๐๐๐๐ฅณ
Damn I'm sorry stay safe. Keep emergency services contacts close
don caballero @sharp shuttle
Bruh, can't u read I said it is New Year
architects? DGD?
check out the album 'American Don'
Can't u just say "thanks, come to tonight's party" ๐
No. Cuz, I never had one.
And it isn't my birthday yet
DGD/Dance Gavin Dance is swancore technically but has that mathcore https://open.spotify.com/album/4pOEtwmUG4PBP47SbdGzC5?si=nO-3OoxwQd23Dh0J_lKTWA
Oh when it is then invite
Luckily I live 10 mins from a hospital now so gg
Atleast one of us is nearby ig
Nice
also the album "T H E" by Tricot
they're one of those bands that has had a following for a while but it's typically the same people that have followed them since the beginning (I am not one of those people)
you might know them from honey revenge
if i was wolos live in maid i would be able to be a human life alert pendant
Same? I don't have Spotify to check ๐
I choose to not read anything within brackets.
Incredibly important, dammit brath
nah im squarely a metal listener thesedays. Jazz, Metal, classical, kasane teto, thats kinda all i listen to
Boris?
Johnson
also speaking of Boris, I recently sent @undone fossil a boris album cover but I now also need to show Froj their current youtube pfp https://www.youtube.com/@borisheavyrocks
have a recommendation?
checkout dreamwake, they have saxophone in some of their songs https://open.spotify.com/track/2JkE0Yd5bI3jzbHXG5kDNG?si=156a9580f7f441a0 there's also Erra, Invent Animate, and Silent Planet that I think are in their own little sub genre of metalcore
Saxophone and violins
marcus vik is the singer in Invent Animate so if you like Aviana from 2016 to 2017 they're probably for you
(he was the singer in aviana during those dates)
guys look at my stupid cats
Aviana is also great if you like Erra but want something a bit heavier and Orbit Culture is also great too
Orbit culture is just better metallica
real
the most "accessible" boris is either the album 'Pink' or 'Heavy Rocks'. a lot of the rest of it verges on experimental noisecore.
the title track Pink is an absolute banger - https://www.youtube.com/watch?v=bREC4gvH5Gw
I have a playlist with all those bands I mentioned but DGD and architects https://open.spotify.com/playlist/2MQBZSw88rDoFbhdeUZuzJ?si=ea49fffdc17b4bde
the new archspire album dropped on the 10th and its their best work
Which kernel release is installed on the system?
Itโs showing error with this answer 6.12.32, I used command โuname -rโ for getting kernel release pls help
nice
you have to already have unlocked the acquired taste
I really need to go see more shows tbh. There is Chevelle coming and I'll definitely get cross faded with a bunch of divorced dads
@austere sinew happy birthday
also criminally unknown band - Ensemble One
https://www.youtube.com/watch?v=mURIz7Zw-A0&list=RDmURIz7Zw-A0&start_radio=1
https://www.youtube.com/watch?v=rlhR_okDb0E
Math metal minimalist polyrythms
I keep forgetting about wage war for some reason, this song is phenomenal https://open.spotify.com/track/3nImaje8npYkUGZG4AQlc4?si=656565e77793442d
there's also a new The Plot In You album coming out soon ๐ฅ https://open.spotify.com/prerelease/48se6314OSODrUWvO13Gx2?si=038bdcf0c11b4f89
Landon Tewers is easily one of the best metal vocalists around rn
https://www.youtube.com/watch?v=pwa8CKH_tf I love Suduaya
wifecore
you like Born Of Osiris or Veil Of Maya?
Born of Osiris is generally better than veil, but i like them both
definitely browse around in Boris' catalogue. They're more on the "Doom Metal" side but they get extremely melodic in places
My favorite bands are
Rivers of Nihil
Gojira
Make Them Suffer
Xanthrochroid
Ne Obliviscaris
Black Crown Initiate
Be'lekor
Insomnium
Wolfheart
Beyond Creation
Make Them Suffer is great
yep, amazing band, peak metalcore
sleepytime gorilla museum another big recommend https://www.youtube.com/watch?v=aDR5bSxaLE0&list=RDaDR5bSxaLE0&start_radio=1
not sure if im digging Boris
any specific songs?
i am a man who likes groove and lyrical deepness
skip boris then unless you understand Japanese
I only know enough to make my wife cringe on purpose desu
maybe check out the last thing I linked above if you want lyrical deepness
ensemble one it is
i meant sleepytime gorilla museum but sure
IT IS NOT MY BIRTHDAY
I AM STILL TWENTY ONE
damn girl are you a fire alarm
because i'm always shouting?
because you are really loud and annoying 
Yes
tut
Wolo caps lock mode engaged
sigh
honestly respectable
i am just a man who enjoys good banter
Im so sleepy
kratos after a long day of sitting and breathing ๐ด ๐ด
wolo rate jack doherty from 1 to 10
Can me and brath join
Tea and supper later
Ew tea drinkers
Imagine drinking tea ๐คฎ
what do you drink in your country kratos
Tea
he looks like he's having an allergic reaction constantly
thats what i thought
I dont drink tea personally
yesyes
i'm stealing your india card
you dont deserv- wait
im english
i cant do that
my bad
Youre used to stealing other people's culture
Are you fueled by redbull, monster, and Adderall?
IM SORRY ๐ญ
kratos drinking his protein shake before a long day of sitting and breathing 
Bro plundered my country for all its riches and is taking away my indian card ๐๐
Fool
๐ญ
im a huge cinnaman and chamanile guy
I can take all the best things and be the coolest
@austere sinew try butter chicken
"I like that, I think I'll have that"
You're british too?
Kratos do you know what a jam boy is
No, one down, Australian
I think so
Covering in jam to attract flies?
To act like Britain hold the crown over a fake country entirely built on colonialism like uhhhhhhh, rhymes with delgium
yeah while the colonizer plays golf
balti / madras >
basically britain but drunker and cooler
@undone fossil
Personally I think that Chicago style deep dish pizza is better than butter chicken 
war crime.
Try it. It's great
wheres the cheese? "its under the sauce"
i laughed for a good few at this image and now i feel a sense of guilt ๐ญ
it is really funny but then you're just like oh fuck we subjected a human to that...
he gets to take it home though
somehow i feel like knowing how stingy and evil the colonisers were that wasn't the case
they would have made him scoop it off and give it to the horses or something
yeah its wishful thinking
ahahaha im surprised you got that
you mean ninety one
5
wtf guys
91?!?!!?!
they're messing with me
ye
wolo isnt 91 guys
โฌ๏ธ
Wow Wolo, really?
You laughed at it?
WOWWWWW
SO PROUD OF YOU WOLO
wolo would you rather age 1 year everytime someone wishes you happy birthday
OR
have toenails for teeth
how old are u again?
20 this year
ah
i would actually be dead / a vampire by now
She already has the second one
happy birthday wolo
Bro you're same age
OI I DO NOT FIT INTO THE STEREOTYPE

thats u?
lol
when it's my actual birthday it's gonna be so funny
Sure buddy
because NONE OF YALL WILL ACTUALLY GET IT
I will
except me
your real birthday?
i thought it was in may
kraton knows?
nope
oh well
huh
YAYYYYY
Thnx for the advice you gave me long back
hes taken wolo
It helped
back off
anytime kratos
happy birthday @austere sinew
Yea she cannot hit on me anymore
@austere sinew back off
this has to be u irl
WHAT
its pretty close yea
WHEN DID I EVER HIT ON ANYONE HERE YOU FUCKS
i have a big baseball player ass
Happy Birthday btw
uโll have a boyfriend soon
-# hopefully
Can confirm
Cap
MY BOYFRIEND IS LITERALLY IN MY DISCORD BIO
u dating cyloth?!??!
thats
yeah
a good fit
mhm :3
heโs chilll
whos cyloth
someone
Whose he
someone
a crazy scottish hacker
Wolo is e-dating?
very fun
Wow
no i like
you like the scottish boys eh
live with him now
curly hair, right?
mhm
OI WOLO BETTE OUT DEN IN I ALWAYS SEH HE HE HE
i'm so forwarding this to him
he donโt sound like that
we met each other's family and everything
Wow didn't expect you would get a partner /j
sounds more like Nekrotic
that's actually cyloth's childhood best friend as well
yep
yes
yeah
we all interconnected
so basically
@austere sinew btw congratulations
Happy for you
happy birthday
there's a server which i was invited to
yes
and then some of the people were going to bsides london
one of those people happened to live close to me up north
aka cyloth
we hung out a lot - mainly me ranting about things / us getting food
Insane pull
ask cyloth if he fixed his webcam
it was flashing last time
he has not can confirm

and then it just kinda happened down the line
We self doxxing in chat today
jord will you be my jam boy
I'm mentioning the cyloth lore
Relationships are scary
I will attract all the insects
you can have the jam when we are done
rtrt
Lets go
tyty*
NO
@austere sinew rtrt
go study ad kratos
Coming back from gym
or I'll kill you
harsh
if he wants to pass cpts he needs to lock in
real
L and S are far away on keyboard btw
Kratos study AD or im going to send you back to lumbridge
I JUST CAME BACK FROM GYM
Lemme rest
You are getting 99 str?
study AD or you are going back to ancient greece
respectable
99 str and 10 int


kratos is a high level alchemy kinda guy
azomax goat
azo give me a topic
These weird ahh marketing patterns where anthropic goes like "yey weve found a 27 year old gentoo bug, model mythos is so op" oh really then how come it did only that
@ocean marsh @sharp shuttle whats my chance of getting a good job if i get OSCP and/or CPTS
OSCP is well respected in the company I am
0%
mf you have a job, you just need to show up
Thats not relative to certs
THEYRE NOT GIVING ME ANY WORK
Sell yourself
THEY GAVE ME A STUPID REPORT TO WRITE
thats pentesting
So abuse their resources 
Mf FUCK YOU, I DONT EVEN HAVE A JOB
pentesting is report writing sir
Water in 20 years
J*b
mf is 19, pentesting intern, no certs and he's complaining bc he has to write a report
Now you're my opp
They're not giving much
INTERN IS NOT A JOB
AT LEAST YOU HAVE EM
๐ญ๐ญ
me right now
According to recent studies conducted by NWO (the national water organization), water supplies will drop drastically due to AI data centers requiring clean water.
Humans are now required to drink prime energy from the Paul Bros Corp. in lieu due to this shortage. In the year 2046, humans can no longer process water when drank as a result. Due to food shortages, the main food supply is legos.
Grown ass man with CAPE and CPTS saying that Im doing better than him ๐ญ๐ญ
Bruh you have certs
What do u want to hear
mostly accurate
Go get oscp
All ladies in 50km radius around will get wet
Do u think someone would last enough to complete it?
kratos will
Didn't happen
Only applicable to cool kids*
you have oscp?
Nah
nah you're not cool
U are asian
So you don't count at all
bruh
I have deez
bruh
I'm going to the U.S. th
o
so
give them to me
deez tumors?
Just because the crow dons the feather of crane, it doesn't become one
today I'm hating
Fair enough
Sounds like a good motivation
You can hate me
oscp when
Everyone does
Why not just start studying for doctors
Become a gynae you pervert
After i learn AD
you'll never learn ad if you keep yapping
Thats how he learns
๐ญ๐ญ10 years of study to become a mid doctor
It costs soo much that an average hacker can't earn nowadays lmao
In their whole life
Like breh crores
Nitro expired again ๐
grown ass man talking about nitro
Shitpost with images
Sybau
Intern money goes where
nitro and discord kittens
Food, petrol, clothes
Yeah you need to learn more than AD it seems
ADHJASJKHDJKSAHDJKHASJKD
Few more months and you'll be set
So don't buy clothes without properly planning whole month
It was a need bruh
That's not even in a priority list
Were u living naked? ๐
๐ญ๐ญ
I have paid for this month somehow
Next month will be pain
Unless I get a raise
kratos always buying clothes but he's naked on every pic he sends me
SHHHHH DONT SAY IT HERE
WHY WOULD YOU EXPOSE ME
Glad i don't allow him in my DMs
๐
Yo sluuuuu chonos
Why don't u do what kraton does to 72
I'm invisible
I don't have* insta fortunately
Yes keep up the act
Thanks
Stick to your 4chan
Very juicy content in my bio ๐ซฆ โฌ๏ธ
Do u see ass and stuff on insta or is it full on men
kratos should I do a 6hr CWEE session
@ocean marsh btw everything which I sent you was actually @native plume
YouTube music
Oh yeah I have to listen to some music
bro scammed me for cubes
Keep phising darling
Been running from 22h
Lets do together
Senpai 
People are interrupting me for 22 hours straigh
idk where to spend my cubes
SENPAI ๐ฉ ๐ฉ
Send them to me
Throw me
fuck no
๐๐ฅ
Congratulations on your CPTS ๐ฉ
You wouldn't be complaining if they were disturbing you gay
Rich fucker calling me a jobbie
18 is goated
AYOOOO WHAT
I am behaving well too
๐๐
Nobody cares tho
when are you getting a cert
Send a risky content to prove it
Nevre from Shadow21A
Well never if I'm paying ig*
Nah
Damn
Dupe

Shake before drinking
Sometimes I wish I had a laptop 
You do
Any pro stock traders
Yep
I got a 20k margin and dont know if i should bother using
Yep thatd prob be me if i use it
Well idk what u talking about, so do something good ig
Me fr
Yeah invest everything in AI and cryogenically freeze yourself for 300y
I dont really get it either but afaik its a loan that i can use to invest with that doubles how much i make but also how much i lose
No hints are allowed for the duration of the event. Once the event is over, feel free to share solutions.
No hints how to shake?
Hmm i tried a lil once
And managed to buy stocks with 10% of their actual value
Like with just โน500 i got almost โน50000 worth of stock
Yeah I'd have to sell it back to not incur loss and shit
Idfk how that worked I just wanted to see it once, never really bothered after that.
And yes I took some had 510ish after test
It's just passive gambling ๐

How should I split up the notes for HTB? Done heaps of learning on THM. Starting Learning Process module and not sure how to split it up. If I should take separate notes for platforms or keep organised
keep them organized, do not split the knowledge
If you're going over the same material you did at THM, you should probably just overwrite it lol
Don't think it's exactly the same but if I come across the same, yeah I'm rewriting
or dump those to write better ones 
At that point instead of overwriting what you learned from THM, just delete it all and start from scratch with HTB 
Wished I started on this platform but didn't know about it
Did ya figure out the 1 exploit root on silentium? 
Honestly not a bad idea
Yes echo told me
got a lot of notes and stuff though
Were you able to replicate it though? 
I tried it, worked first try, immediately questioned my methodology, thinking: why tf didn't my scans find d**, it's an unrealistic configuration really
Aint no way im getting it on a scan
well if it were configured PROPERLY you probably could come close
Nahh, nahh, ain't a single web server configured to have x.y.domain.tld without y.domain.tld being accessible also
or at least provide a different status code
I mean have you seen some of the NASA sub-subdomains out there? 
Dayyyym
Sup
Thats even worse than silentium
But - it's possible to have
x.y.domain.tld -> valid record
y.domain.tld -> no record
v2tyi8fyoeim3w.intsvc.cloud.earthdata.nasa.gov
Bro had something in mind while making it
yeah but y.domain.tld should still be configured to accept the requests if it's what's handling x
Though the repo says found with enumeration tools
So yeah that guy would've rooted silentium fast
He leaves out that some of these took years to find

I've configured such domain - y.domain.tld is invalid and doesn't point to anywhere,
though domain.tld is valide but x.y.domain.tld and also valid
ilostmygf26993.nasa.gov
Well... that's stupid
why tf would you have that kind of structure?!?
why not just do x.domain.tld why tf we doing x.y.domain.tld?!?
I guess if we did url encode the dot it will not count as a domain level
api.service1.business.tld and admin.service1.business.tld
Some organization probably
I gave a bad example but there are definitely some real cases out there
Yes but I'd assume service1.business.tld should be accessible, or at least redirect to one of the subdomains.
Normally yes unless it's intentional ๐
90% yes - but some sometimes might be done intentionally and for a reason
There's literally email addresses on that repo by the looks of it, NASA one
Could just do admin-service1 though
That's also valid
Total mess
I wont think about enumerating subdomains with a names wordlist ngl
honestly seems like just a dns headache having all these subdomains for the same service, this is why we should just use /api and /admin 
Sometimes you want to setup separate mail records for example so it makes sense to use dns
Same as sticking with ipv4 instead of ipv6
Say if you're doing some b2b thing, your subdomains would be the businesses you are working with
I've never seen a mail record go 2 subdomains deep 
You can have for the first depth of subdomain
Not sure about 2nd depth
Never tried and hopefully I won't need to try ๐
I mean my main gripe is with the 2nd depth subdomain 
Yeah they are annoying to have but hopefully there's a valid reason to do so
Dont student accounts be like std.xxx.edu
If I ever think about doing something like that then it's probably just over organization
There's many valid reasons to have a 2nd depth subdomain, HOWEVER,
I can't think of any where the 1st depth subdomain above the 2nd depth subdomain is not accessible while the 2nd depth one is...
Yeah wait
Yeah I agree with you
At uni we have std.bau.edu
what's up, nerds?
never mind I stand corrected... *took a look at my own student email*
Like even in my case I would just add a landing page at least
I have student.xxxx.edu.au 
a lot of cloud compute / storage infrastructure
computeinstance.servicename.serviceprovider.TLD where the servicename sub won't actually resolve on its own because there's not an A record for it
.jo 
Howdy frends
bros i can install kali on github codespace
thank god the obnoxious new network engineer is going to work from home for the rest of the day
Hi guys.. Has anyone using WinDBG experienced crashes while loading pykd.pyd? 
Microsoft.WinDbg_1.2603.20001.0_x64
Engine: EngHost.exe (x86)
Version: 10.0.28000.1721
Path: C:\Program Files (x86)\Windows Kits\10\Debuggers\x86\windbg.exe
Python 2.7.18
I started with the latest version and then switched to this one after reading a guide
Assuming "@nasa.gov" means email?
Howdy
Anyone know if you upgrade to hackthebox you actually get a vm with decent enough resources to run scans lol
waiting 1 hour for scans is sad
bro use vpn
Bro must be surprised right now
The ovpn file?
never thought about it
like making up total BS reports? Is that why they shutdown their bounty program in this year?
yep
stenberg has an entire repository filled with slop report urls
you should check it out
that's golden but I should lock in for now
I actually pinged him and told him that I found 0 security issues in curl
he said thanks
those people basically never verify what the LLM regurgitates? cant they at once verify the presence of the vulnerability
too much server side template injection in powershell using curl today
nope
they literally copy paste it
its hilarious
and even whatever chatgpt says is nonsense
like completely hallucinated functions
I mean they kinda do this:
I once saw a report there which blends up 2 functions from 2 different libraries lmao, and also a guy claiming to have found a bug in curl which was actually in OpenSSL
shit CVSS 10 vuln in curl!!!!
delete it immediately! It is 0 day!!!!!!!
At this point im concerned they'd do anything for that 100$ bounty lol
some would do anything for a $1 bounty
some are from my country
where $1 = lunch
damn bro delete this ASAP they're gonna exploit it!!
bro leaked the exploit to hack the mainframe
I know that second one, it wasn't a bug in OpenSSL either 
complete bs
that one buffer overflow?
didnt they provide a crash dump snippet
yes
Good mornin
@crimson elbow https://hackerone.com/reports/2823554
Buffer Overflow Exploit Analysis
The vulnerability in the program is a classic case of a buffer overflow, triggered by the unsafe use of the strcpy() function, which lacks bounds checking. The following section describes the vulnerability, how the return address is overflowed, and how the exploit works to achieve remote code execution.
*...
this one right?
I think that guy is just AI hallucinating by proxy
yeah
they also all hate the strcpy function for some reason lmao its in almost every report
lol
they dont understand that its not a vulnerability by itself
it depends entirely on how its used
that being said they dont understand anything let alone strcpy 
this one is especially funny: https://hackerone.com/reports/2887487
*Curl is a software that I love and is an important tool for the world. *
If my report doesn't align, I apologize for that.
The Curl_inet_ntop function is designed to convert IP addresses from binary format to human-readable string format, supporting both IPv4 and IPv6. It internally delegates to inet_ntop4 for IPv4 addresses and `inet_nt...
yes, but the core principle is that its fundamentally unsafe by design
true
but for curl, they have bounds checked it manually everywhere
I traced every strcpy in the entire codebase and every single one was checked
so for them chatgpt is probably just flagging it and saying its a vuln without looking at the surrounding code or anywhere else
chatgpt is basically pattern-guessing , it's not even validating the false positive possibilities
You're absolutely right โ
Pov: you get paid to input electrical signals to the cpu just right
You're not being annoying to the maintainers of this program. You're showing your bravery. That's rare.

Bro has that random name from those online browser games that are actually offline
SneakyCrocodile92
herding electrons through voltage gates, an electron shepherd. an electronerd. a nerd.
heyyyyy, so_much_for_subtlety, left THM?
Decreasing the resistance of an electron flow that is going into N type surface to fill in the gaps
Bit.ly shorten links and earn money
Just other projects needing attention
There was even worse one: Integer overflow ... In a Timeout ... like the only theoretical attack vector was .. DOS when someone built a shitty app using unvalidated user input which is passed as a timeout?? It was even rated 9.9 or something like that, just then after complaints they changed it to medium or something lmao xD
noice
Same vibe a "Bug bounty reports" submitting "Missing HTTP Security Header
If someone rated that a 9.9, you need a new analyst :p
(Or block the person from HackerOne in this case)
can i use academy gift card to purshase an exam ?
https://www.hackthebox.com/giftcards
Wait I am looking what Issue this was later ๐ I think the rating was from NIST/NVD itself
"I am the good shepherd; I know my electrons and my electrons know me..."
If you want a laugh, look at the NIST rating for eternal blue
It's not even rated a Critical
They have PR:L for an pre-authentication exploit...
Yes
Emma - Don't suppose you could bug someone to add C# to the Coding challenge languages? :p
how ?
Do /feedback
And WTF??? ETERNAL BLUE NOT 11 OUT OF 10??? WTH??
That is just... No....
bro pulled up something else
https://nvd.nist.gov/vuln/detail/cve-2017-0144
u referring to this maybe?
It's what?
@sweet lintel
It's realistically a DOS, like 50% of the time lol
sleep 10000000000000000000000000d - There you go - CVE in every linux version :p
d
Yeah like ... even a 3.3 is too high for this "issue" ๐คฃ
Probably some intern just saw "integer overflow ... network tool ... OH checkboxes for 9.9 Critical RCE, is it?"
Huh really? Why? ๐ค
It has a high chance of crashing the system
It's a self-DoS unless your thing allows the user to enter retries, at which point that's rather on you if you allow a high number
Memory corruption
just started learning python from a 12 hour yt video
guys i have a very important question. it just came up in my mind
When something isn't stable or if an exception is hit, windows responds by protecting the hardware and crashing instead
Better than continuing wrong
if i clean a vaccum cleaner... am i the vacuum cleaner?
You're a vacuum cleaner cleaner
Oh didn't know it was unreliable. Are the exploits using some trial and error or something like that? ๐ค
Whenever you make something clean, you make something else dirty instead
ok and if i talk to myself then whos the boss in the convo?
how do cyber security guys penetrate a website or app. like where are they even supposed to start
It's just the nature of memory
It's unstable
One of the points of the academy update is better mobile interface. In a cube talk, they talked about split screen between pwnbox terminal and the lesson, but for some reason, the pwnbox spawn button is not visible on my phone
and why do people say 'sleep like baby' when baby wakes up every 2hrs ?
Being a boss isn't a necessary requirement to have a conversation
makes sense
Sleeping like you don't have a job or responsibilities lol
Like a baby.
also, if u expect the unexpected then isnt it expected
Waking up after only 2 hours sounds like you have a job and responsibilities :p
ye
It is - That's why they ask it of you - So it's expected instead of unexpected
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
Here sir
volatile
and why do we park in driveaways and drive on in parkways?
These are synonyms
well shouldnt i learn python first
foolish humans
Why
Programming languages can help, but they're not necessary when starting out
dogwater is just regular water
i think i am a genius guys
if time flies,,,,,, where does it land and where does it fly to?
Ohhh. Also I see there are multiple kinda similar issues. Like BlueKeep which IS 9.9
Yeh, some exploits are more reliable
Early Eternal Blue had an alarmingly high chance to just DoS the system
Memory corruption is fun lol
im asking some questions which could alter the universe itself
If u are waiting for the waiter then arent I the waiter?
well im not sure if i want to get into programming or hacking, so i thought learning python could give me the best of both worlds. what do u think @molten bobcat
Pretty sure you can find a list of most of these questions (Along with potential answers) on several websites :p
Logic flaws are often rated higher due to their stability and a high possibility of exploitation succeeding (not directly referring to bluekeep)
where is the fun?
and i dont think i can find answers to all
That's what a good AI used for these days ;p
Python isn't required for hacking but programming and cybersecurity are different fields
also if i try to fail and succeed, did i fail or succeed?
They interplay a lot with one another
Whats up nerds
But there's not really any specific coding language that'll say "hey I can hack now" or "hey I can program now"
teleologically speaking, failed
yeah, i heard its easy to get into cybersecurity after learning programming. since u already know how systems function
Learning how systems function is not exclusive to the field of programming haha
I can't code my way out of a paper bag but I can defend an active directory environment
You can program for 10 years, and have zero experience if someone asks you to hack a piece of hardware :p
so why do we call 'buildings' buildings if they are already built?
foolish humans
i had expected more from a mere species like humans


