#general

1 messages ยท Page 642 of 1

proper dragon
#

they require consistant maintenance troll

molten bobcat
#

Cell posting

main halo
#

typically, do ppl learn both when getting into cs as a career

molten bobcat
#

Computer science isn't a job title

#

It's a big field

bronze lion
molten bobcat
#

Gotta find a role that speaks to you

sweet lintel
high cobalt
#

Yeah. I can do Web Stuff and Web Hacking, but low level things are like "WTF?" for me haha xD

main halo
sweet lintel
bronze lion
sweet lintel
#

"Oh - If we wobble the electricity enough when it's booting, it skips that function" - Like... WTF

bronze lion
#

i mean flipping the bit is not hard

#

but to know the exact outcome

#

shouldnt he be a nerd who speaks and eats binary?

high cobalt
molten bobcat
#

Instead of just going after what people tell you

remote bolt
#

this chat is 24/7

main halo
#

i see

sweet lintel
proper dragon
proper dragon
#

thx m8

sweet lintel
remote bolt
#

xD

molten bobcat
#

I like blue teaming and DFIR work a lot. Other folks hate it with a passion

main halo
remote bolt
#

its 5:30 pm here

molten bobcat
#

It's all about finding what you like the best

bronze lion
sweet lintel
bronze lion
#

same

molten bobcat
#

Someone's gotta do it

rare monolith
main halo
sweet lintel
#

When your remaining boxes start to look like this ._.

molten bobcat
bronze lion
main halo
#

im so inexperienced on this topic. i feel like every question i ask is dumb

molten bobcat
#

It's okay

sweet lintel
rare monolith
molten bobcat
#

I was dumb and clueless years ago

bronze lion
molten bobcat
#

Now I'm just dumb

high cobalt
molten bobcat
#

Why them, I'm the blue teamer lol

sweet lintel
bronze lion
#

he is the professional blue teamer here

#

lol

molten bobcat
#

It's me hi catwave

high cobalt
molten bobcat
main halo
#

why do ppl say โ€œmuh cs jobs are being taken over by aiโ€

#

are they coping

sweet lintel
#

Yup

molten bobcat
#

Cuz people like to complain yeh

rare monolith
worthy cargo
#

I'm finishing up the Linux boxes first.

sweet lintel
#

AI can help - It's very bad at doing complete jobs.

molten bobcat
#

Every single use I've seen of AI in my own cybersecurity workspace is meh at best lol

sweet lintel
main halo
molten bobcat
#

My coworkers themselves produce art

#

By comparison

worthy cargo
bronze lion
#

also depends on ur current skill

sweet lintel
#

Somewhere between several days and never :p

molten bobcat
#

I don't hack at all haha

#

I just know how to

rare monolith
main halo
#

whats more valued, cybersecurity or programming

bronze lion
worthy cargo
#

I just do pentesting to be able to think like an attacker. I actually do enjoy cybersecurity engineering, and architecting/building secure systems/solutions.

molten bobcat
worthy cargo
#

I love forensics and DFIR

bronze lion
molten bobcat
#

Those two are just intertwined lol

worthy cargo
#

but I haven't been able to get into the forensics field yet

sweet lintel
bronze lion
#

a very good way to put is honestly

rare monolith
main halo
molten bobcat
#

I like forensics

warm ravine
#

If yes

molten bobcat
warm ravine
west lynxBOT
bronze lion
molten bobcat
#

Like I said I've been doing this for years I didn't start until I was 24 or so

warm ravine
worthy cargo
#

I'm gonna go get some bbq chicken tenders, some corn on the cob, and some potato salad.

sweet lintel
# main halo does it even matter which i start with first

Programming may help to start with, but not necessary. Think of it like driving. You can drive really far without knowing how an engine works, but it may cause a problem if the car breaks down. The trick is to drive along, and deal with it when it happens ๐Ÿ™‚

main halo
bronze lion
#

as far as i can recall

#

lol

molten bobcat
#

Just take your time to understand things and follow what you have passion for

rare monolith
molten bobcat
#

People who care about their work produce immaculate quality work

#

Or at the very least better than most

sweet lintel
high cobalt
# molten bobcat It's me hi <a:catwave:881909807190269973>

Got a tipp on how to learn a bit more about blue teaming topics? My workplace is currently in the dilemma of building at least a basic SOC which would be able to detect when our most critical systems get attacked/ransomwared (again). Not sure where I could start and help out as a Linux sysadmin with detections bc. we know a bit of Theory behind MITRE ATTACK etc. but applying it practically and building Use Cases feels a lot more overwhelming and harder. Do you know any good learning resources? Would you recommend digging deeper into red teaming to learn more?

molten bobcat
#

Hi!

#

Sherlocks are great practice

#

The DFIR challenges remind me of my actual work

rare monolith
main halo
molten bobcat
#

It's only boring because of how it was explained to you

sweet lintel
#

Well, I managed to finish the Overwatch box today, and made some changes to my script, so that's enough for one day :p

molten bobcat
#

I find that a lot of education in the field is unfortunately.. real dry

#

So if you're expecting it to be a thrill ride I'm very sorry lmao

sweet lintel
#

Programming theory is ass :p

jagged storm
molten bobcat
#

This is true as well

high cobalt
warm ravine
#

Hacking is something that I love

#

As a hobby

molten bobcat
warm ravine
#

As a job

#

Everything

molten bobcat
#

You never really know what'll end up being useful until.. the moment it occurs

high cobalt
main halo
worthy cargo
#

30 years ago i was the best hacker. Everything was in clear text. There was assumed trust. there wasn't a lot of security. then I got into different things in life and 30 years later the whole landscape is different.

#

I did my MCSE in NT4

sweet lintel
rare monolith
#

imagine that you are hacking insane boxes at night and then working as a farmer at day

worthy cargo
#

Back then active directory didn't exist

molten bobcat
#

I know about common methods for piracy, and I can spot them in use in real life environments and it's really funny removing malware from a host because someone wanted to play Sniper Elite: Resistance on their work pc

high cobalt
#

Haha

molten bobcat
#

I've also seen people making local firewall exclusions for StarCraft 2 lmao

warm ravine
#

Or smth

sweet lintel
#

When you get things like this

warm ravine
#

Time to hax machinas

#

But first

high cobalt
#

Well me and my colleagues already told the higher ups that it would be better to get consulting for our SIEM use cases ... xD Well money is a problem though ...

warm ravine
#

Get teh etherned adapter

#

When I get my first bank card, I'll buy myself a cool hacking laptop

molten bobcat
#

I can use both elastic and slack and I hate both

warm ravine
#

With some good statistics and other things

high cobalt
scenic maple
sweet lintel
molten bobcat
#

I just dislike it lol

rare monolith
sweet lintel
warm ravine
high cobalt
#

Kss. We honestly love it

scenic maple
#

idk what that means

#

2017 was 8 years ago

rare monolith
molten bobcat
#

It was 9 years

#

Not 8

sweet lintel
#

And I've been in this Discord server since 2019 ;D

scenic maple
#

u r an og

#

tbh i draw the line when gatekeeping was a thing

sweet lintel
#

I miss the old hack an invite :p

#

I suppose it kept out super new people

rare monolith
#

if im gonna be running 30 enumeration tools at once should i get active cooling on my pi 5 thinkpad

scenic maple
#

maybe rude

sweet lintel
#

;D

scenic maple
#

but its not a hard gatekeep it would point you to academy if u couldnt

#

it wasnt like u cant get in haha get lost here is a rickroll

sweet lintel
scenic maple
#

so i am all for gatekeeping

#

but like every other company they need revenue

warm ravine
#

Hey uh, what is gatekeeping if I may ask

rose onyx
sweet lintel
jagged storm
molten bobcat
#

Oh I don't believe in gatekeeping

high cobalt
molten bobcat
#

The only time it should be gatekept is when someone wants to use the knowledge for stupid/illegal shit

scenic maple
rare monolith
molten bobcat
#

Gatekeeping is the concept of "you can't sit with us"

#

You're not allowed in the special club, gates closed

sweet lintel
scenic maple
#

it works like this
hey u wanna know x study y and u will find out instead of spoonfeeding or how i see it i guess

rare monolith
sweet lintel
jagged storm
#

golam can't sit with the gatekeepers

high cobalt
#

Oh lol I couldn't even write a fake hacking request ...

rose onyx
scenic maple
scenic maple
rose onyx
jagged storm
#

no true gatekeeper

scenic maple
#

we gotta invent a new word cause gatekeeping toxic

#

how abt spoonblocking

rose onyx
scenic maple
#

hmmmHug abt wat

warm ravine
#

Im curious

#

Learning things

scenic maple
warm ravine
#

Sure

jagged storm
#

You're already out of the circle of trust, golam

pearl kernel
#

missing her snores

iron galleon
scenic maple
#

maybe now we 2 sit outside kek

sweet lintel
#

When you follow an LDAP side escalation path 4 levels deep and wonder if it actually helped...

jagged storm
#

You are now the last to be picked at flag football

warm ravine
#

Man

#

I feel like a peasant over here

#

Look at me, very little knowledge

rose onyx
high cobalt
#

You guys know what's weird and a dilemma about gatekeeping and making fun of cringe stuff? You know r/Masterhacker and r/FakeDisorderCringe? The thing is, every time someone is starting to make fun of such things it kinda becomes "50% really is cringe ... but the other 50% is probably legit and really someone learning hacking and having a real disorder and making self ironic jokes about it"

sweet lintel
crimson elbow
#

memory isnt inherently unstable, though, it just needs continous power to hold data. its not a nature of memory

warm ravine
jagged storm
high cobalt
#

I suck at everything except IT kek kek kek kek

warm ravine
high cobalt
iron galleon
#

bring back Vine

sweet lintel
warm ravine
#

So uh

#

I dont think it'll be a problem for me to learn hacking

west venture
#

โš ๏ธโš ๏ธSTEP BACK THIS IS A CRIME SCENE โš ๏ธโš ๏ธ

warm ravine
#

Just gonna take some guts and time

sweet lintel
#

A little bit a day and you'll be good in no time ๐Ÿ™‚

rose onyx
warm ravine
#

Without it, I cant do hacking

#

And hacking with wifi is too slow

rose onyx
#

๐Ÿค”

warm ravine
#

And I need speed

west venture
warm ravine
candid drum
#

how do yall deal with being burnt out? or preventing it?

sweet lintel
jagged storm
high cobalt
west venture
# warm ravine Me

You just made a very big mistake and there will be an appropriate response

warm ravine
candid drum
sweet lintel
sweet oak
#

anyone here ever faces issue with the vpn , espacially the MTU of the vpn , what's the perfect value for this

warm ravine
#

But look, I feel like I can do this

warm ravine
#

I literally can do hacking

molten bobcat
#

I've never once touched my VPN settings

warm ravine
#

I have guts

#

I HAVE RESOURCES

#

I HAVE EVERYTHING

#

Kind of

rose onyx
limber arch
sweet lintel
west venture
high cobalt
warm ravine
jagged storm
warm ravine
sweet oak
molten bobcat
west venture
candid drum
jagged storm
west venture
#

I ended up in the ER for some reason

quasi ridge
#

or tequila

warm ravine
west venture
#

Mmmmmm

warm ravine
#

I hate beer

high cobalt
# warm ravine Hell fucking yeah

Personally I think, even if you decide you don't want to do it as a day to day job, you can still learn it if you want. Like I am more of a DevOps Engineer and really a script kiddie compared to professionals. But I feel like it is still good for my career to know about hacking and doing it on a side :)

warm ravine
#

๐Ÿฅ€

jagged storm
west venture
warm ravine
west venture
#

But no, it's bc I punched through glass

#

For some reason

austere lynx
#

hi guys, i saw that some time ago you could see any country in leaderboard, but now only top100, can i still see a country outside top100?

west venture
#

Yes

warm ravine
sweet oak
warm ravine
#

But well.. no

#

I havent tried it

west venture
#

Why

warm ravine
#

Is it something like 2 hackers trying to find a flag on a machine?

#

Or smth

warm ravine
worthy cargo
#

BRUTAL JUNGLE RITUAL โ€” a dark, hypnotic, primal ritual in the heart of the night jungle.

150 BPM of pure destructive drive:
โ€ข Massive pounding kick
โ€ข Deep rolling sub bass
โ€ข Fast psychedelic groove
โ€ข Tribal percussion, jungle drums, shakers, bongos, toms & ritual hand drums
โ€ข Organic wooden percussion fused with hard psy-techno powe...

โ–ถ Play video
#

/me Dances

west venture
#

Also we are not hackers

worthy cargo
#

High octane hacking music

#

high octane coding music

warm ravine
worthy cargo
#

it goes with everything

candid drum
west venture
#

@jagged storm

high cobalt
# warm ravine I havent tried it

Do you habe some basic IT knowledge? Linux? Windows? Programming? I mean like how programming and operating systems work? :) even if its basic understanding about Filesystems etc

azure remnant
#

The most fun ive had is back when

#

I was creating hacking scripts

#

For Roblo*

#

Good times

warm ravine
#

Like I'm still a beginner

west venture
#

Have you ever tried to hack activisions anticheat system?

sweet lintel
jagged storm
#

casual discussion of felonies

west venture
worthy cargo
#

I'm a tumor, I'm a tumor, I'm a tumor. Oh oh oh

quasi ridge
#

I'm late but still on it

#

๐Ÿ˜‰

worthy cargo
#

Peter Griffin

jagged storm
#

God, it's like nobody has seen the movie

quasi ridge
worthy cargo
azure remnant
west venture
limber arch
#

Have the boxes the past few seasons been any good?

sweet lintel
#

Mostly - I'd say so

limber arch
#

thats good

#

I want to get back into the seasons lol

high cobalt
# warm ravine I have some info about programming but.. dont know much about how OS works

Hm, I mean I don't know where you are from so I can't really give a good advice on how you might get a bit of education about it. Really depends on the country. I am from germany so I had the luck to get an apprenticeship as an application developer. Here it is basically 3 years working with going to a school if you don't want to study it. Sadly other countries only have colleges/universities or self learning :/

rose onyx
sweet lintel
limber arch
#

I did part of Garfield and I liked it

#

Have to finish that out

sweet lintel
#

I got lost in the realms of the Garfield privesc...

limber arch
#

yeah after user I got a bit lost lol

west venture
sweet lintel
#

That silly box - There's like a dozen paths you can go down, and at the end you wonder if you've accomplished anything at all :p

#

And silly Bloodhound doesn't detect the thing you need >_>

west venture
#

Eww AD

#

I always get overwhelmed by AD

sweet lintel
#

Bloodhound: You can't do a thing - Not one thing - Not at all.
bloodyAD: Yea - You have full access to these things.
Me: ._.

austere lynx
#

how can i earn general points?

worthy cargo
#

Use bloodhound-ce instead

molten bobcat
#

Active boxes and challenges

austere lynx
#

not seasonal ones

limber arch
#

bloodhound is so dumb

high cobalt
sweet lintel
limber arch
#

I've never had it fully ingest all ACEs that I actually care about

austere lynx
#

are these points 4ever with you?

#

or only as long as the machines are active

sweet lintel
austere lynx
#

oh ok got it

sweet lintel
#

It's possible to drop all the way back down to 0 if you're away long enough

#

It's why I've had this color name on Discord for years ;D

#

Do box - Do challenge - Box retires - Challenge retires - Loop :p

#

The thing with seasonal boxes is that they're the boxes that will stay active the longest, so will give you points for the longest time

devout sail
#

Yappers

austere lynx
#

so, if it some point i complete all active labs ill get the highest rank?

mystic harbor
vocal fog
random aurora
devout sail
#

Have to do the challenges too

random aurora
#

Okay good luck everyone๐Ÿค

devout sail
sweet lintel
#

Well, "Labs" do rather include challenges - It's all active everything :p

#

But as long as you can complete them faster than they retire, you'll eventually hit Omni

devout sail
#

But challenges are hard and boring

mystic harbor
austere lynx
#

what if i have 64 points, but i did only seasonal machines and 1 active chal for 20 points, how i got other 44?

molten bobcat
#

Don't worry about the points

devout sail
#

Eh nah i think the current logic on HTB rank is like this
If they didn't release new content and retire active, and have only 1 machine
It's insta peak

molten bobcat
#

Rank is determined by percentage of the platform completed

austere lynx
stable tiger
#

@obtuse fern whered yo mod go

sweet lintel
#

That Pirate box and that post-shell Garfield knocked me down ๐Ÿ™

devout sail
#

Do it tonight

limber arch
#

that points thing is new right

devout sail
devout sail
limber arch
#

I don't recall seeing that a few months ago

#

mhm, maybe it wasn't displayed in the column or smth

devout sail
#

But seasonal ranking is broken too

limber arch
#

so i didnt notice

sweet lintel
devout sail
#

Not that

sweet lintel
#

2/7 into plat at the end is weird ._.

devout sail
#

Like how I'm always holo

sweet lintel
#

It's on the site as well.

I need 5 more seasonal flags to hit Ruby, I've missed 3 flags this entire season, and there are 2 boxes left.

devout sail
#

Oh well

sweet lintel
#

Wait...

#

Oh wait....

devout sail
#

:")

sweet lintel
#

I've just realized

#

Plat is ABOVE Ruby ._.

devout sail
#

Isn't platinum more expensive than ruby?

austere lynx
#

i am ruby and i got much less than you bro

sweet lintel
#

Saw my Silver icon and thought it was plat - Lol - My bad :p

#

Let me reverify ;D

past acorn
#

hello

devout sail
#

They starred with mats like silver gold ruby plat
Then put random holo?

#

Why not holmium

#

๐Ÿ˜”

sweet lintel
#

Wooo

#

Weird purple icon! \o/

#

My highest one yet ๐Ÿ˜›

devout sail
#

This season was very easy for holo tbh

#

Plus increased rewards

sweet lintel
#

I may have pushed Holo harder if it wasn't for that stupid Pirate box that knocked me down hard

devout sail
#

Ahaha next season

austere lynx
#

no insane machines?

nova summit
#

Can someone explain to me how the season thingy works

devout sail
past acorn
#

@burnt bloom youre getting opal twmrr, nice

devout sail
burnt bloom
devout sail
#

U do seasonal machine within week
Get points, seasonal rank, seasonal rewards

sweet lintel
nova summit
#

im trying to save up for the yearly subscription

sweet lintel
#

I posted my seasonal reward discount code in this Discord once since I wasn't planning on using it - Mods were not happy with me ._.

devout sail
#

But credits can't be shared

sinful mesa
sweet lintel
#

Fellow Purple! How's your progress going?

summer urchin
#

purpel

devout sail
#

I realised they didn't give me orev season rewards

#

Atleast credits I'm still at 25$

#

Even tho I've been holo for 2 seasons

sweet lintel
#

You get credits?

devout sail
#

Obviously that's the best part

#

Idc about cubes

glad needle
#

Didnt they only give a discount code last season and not credit?

sweet lintel
#

At what rank? :p

sinful mesa
devout sail
#

This time holo gives 45 iirc

#

S8 I got 25

#

S9 idk how much it was supposed to give

sweet lintel
#

You sure about that? I got cubes in the past - Never credits

devout sail
#

Just check season page

#

Rewards

#

And send screenshot while u are at it

#

See if u find s9 rewards too

sweet lintel
#

Yea - Only cubes and discount codes

devout sail
#

Oh they changed it to codes

#

That's weird

#

Can't stack ig

sweet lintel
#

People spend credits - They don't spend discount codes

devout sail
#

Yeah shitty

#

I must have s9 ones in mail then

signal mica
#

Instagram Reelix

devout sail
#

But credits were nice

sweet lintel
#

I suppose it was also an anti-RMT thing - People getting holo on 100k accounts and so on

devout sail
sweet lintel
devout sail
devout sail
#

Stupid pokemon

mystic harbor
signal mica
austere sigil
#

biznis

devout sail
#

I wanted to stack for 10y and have alot of fake money ๐Ÿ˜”

#

Well as long as we can stack it
It's good
Otherwise gotta just use it once per subs

#

Pretty sure the stacking is no no ๐Ÿ’€

sweet lintel
# devout sail The joke was reel

There was an ongoing thing a few years back where some fishing company released the 9th brand of their fishing reel, used roman numerals, and it ended off as Reelix half the time which got me spammed to death :p

meager kernel
#

wassup

devout sail
#

Change your name to reel 10

#

Reelx

#

Stay 1 point ahead

sweet lintel
#

And there was some theme person who used a placeholder gmail address on their "Reel-IX" site which got scraped and I got spammed, so that was fun

signal mica
#

Haha get reeled in

sweet lintel
#

And now there's some random Spanish thing using Reelix to promote their image-based AI, so I'm getting spammed for that as well.

The wonders of a 6 character alias :p

scenic maple
#

thats why u add random shit at the end of ur username

devout sail
#

I once joined a server with sado as invite
It was random russian server
Funny to find random stuff on your name

sweet lintel
devout sail
#

He could have been 20A but nah

scenic maple
#

40 years ago the first letter of year was 1

#

thas kinda old

sweet lintel
#

Ya young whippersnappers...

scenic maple
devout sail
#

I just hope he gets banned from X
So i can take it

sweet lintel
devout sail
#

How were they doing it

#

Were there any green skinned people?

sweet lintel
#

Rolling blocks of stone on sticks

signal mica
#

Rolling blocks

devout sail
#

Sounds like rolbox

signal mica
devout sail
#

waz

sweet lintel
#

That reminds me - Watch that movie The Man from Earth - Fascinating movie. There's a sequel, but it's not that great - Original is very thought provoking

devout sail
#

Hmmm can it be converted into short

#

Can't focus for 3h

sweet lintel
#

It's about a guy from earth :p

devout sail
#

Ah so mirror

sweet lintel
#

And it's less than 90 minutes long

scenic maple
devout sail
#

Well you underestimated me
But sure I'll keep it in mind

devout sail
#

Rells

#

Reelix

scenic maple
#

some lifeless guy has already done it

sweet lintel
scenic maple
#

it doesnt take much

devout sail
#

Add unique subway surfers gameplay on each reel

#

And a greenscreen guy who does nothing

scenic maple
#

i saw a guys pipeline who makes 10k from shorts

sweet lintel
devout sail
#

10k per year? Day?

sweet lintel
#

Eh - Many people using AI to pump out shorts on a hundred different channels earning fortunes

signal mica
devout sail
scenic maple
#

he gets it transcribed as in the whole movie
timestapms based on text and speech and feeds into ai and asks for timestamps
then he splits using ffmpeg and uses code to put subtitiles and based on color and stuff uses ai to apply color grading to pop up
and releases to shorts using yt api

proper dragon
scenic maple
devout sail
#

I want 10k per week

scenic maple
#

he has a factory

devout sail
#

๐ŸŽ‚

sweet lintel
# devout sail Make him me

Run a local LLM - Set up a script to generate a 15 second short - Upload it to 75 channels under 75 different names - Repeat

Now, spin up a hundred of those LLM's.

scenic maple
devout sail
#

Like Peter Griffin and Donald trump

#

Oh btw

scenic maple
#

i would say some words rn

#

but i would have to ban myself

devout sail
#

I saw some guy selling course
Which is slop but for competitive exams

signal mica
scenic maple
#

exytemely low tier ragebait

devout sail
#

And it's actually selling lmao

sweet lintel
#

There are people "selling" HTB flags for boxes half a week before the box releases :p

devout sail
#

Like u guys must have seen the ones with cats ?
Similar but with elements or history ๐Ÿ’€

proper dragon
#

does every mod have an inner troll struggling to break free

scenic maple
devout sail
scenic maple
#

you could see me from space back in the days

devout sail
#

Now look at golam

#

Can't say shit cuz he's a ๐Ÿ˜บ

scenic maple
#

[redacted]

#

and you are poor

#

now speak

proper dragon
#

gonna go discover the esoteric ritual to help all mods' inner trolls escape and wreak havoc

signal mica
scenic maple
#

access to everything htb has to offer in simple terms

sweet lintel
devout sail
#

Golam has 4 girlfriends
He just said that

devout sail
scenic maple
#

well i guess works out for u

sweet lintel
#

Mass trolling many a year ago

scenic maple
#

i wonder what i did lol must have been peak

devout sail
proper dragon
#

id have sent you a friend request

scenic maple
#

you see the thing with trolling is

#

as long as it doesnt harm anyone and its not bullying

#

its not that bad

heady sage
#

Who blocks Golam? Honestly kind of weird behavior if you ask me.

scenic maple
#

i had quite the mastery of it

devout sail
scenic maple
#

but things change

#

we grow

signal mica
devout sail
scenic maple
sweet lintel
scenic maple
#

i never support bullying

#

now that i remember the old times

proper dragon
#

so long as i use the internet, I will troll pepetea

scenic maple
#

it kinda brings back memeories of seadris actuaL and agent47

#

and golgo

devout sail
#

I remember at every point of my discord time
I hated atleast 1 mod ๐Ÿ’€

scenic maple
#

from what server

devout sail
#

I started with solo leveling server

heady sage
#

I didnโ€™t hate any of the mods here

proper dragon
#

htb mods are super chill

scenic maple
#

like whats the end

devout sail
#

My fault tbh
I exploited their bot and generated too much coins

scenic maple
#

tbh i want to know every animes end and the whole lore without spending too much time

devout sail
scenic maple
#

and its too cringe to watch recap vids

heady sage
scenic maple
#

i do use it sometimes

heady sage
#

@Grokinator

scenic maple
#

but not every anime has plot listed

proper dragon
signal mica
heady sage
#

Huh

scenic maple
#

tbh at that point in time you could watch the series

heady sage
#

Guess they left

devout sail
heady sage
#

@Gronkulator

scenic maple
#

massive larp specialist

heady sage
devout sail
devout sail
scenic maple
#

nah thats a dawg

quasi ridge
heady sage
jagged storm
devout sail
#

Look at the lamp pole

heady sage
#

He doesnโ€™t do hacking

heady sage
#

Heโ€™s a nursing assistant

scenic maple
#

so larp means belly?

sweet lintel
quasi ridge
devout sail
#

And his kid does stuff

proper dragon
quasi ridge
#

aka D&D but you swing your foam or wood sword around

devout sail
#

The only thing i like from solo leveling is

high cobalt
scenic maple
devout sail
#

Cha hae in

warm ravine
devout sail
proper dragon
#

isnt solo leveling a bit different than t.o.g.

sweet lintel
devout sail
#

Ah i haven't finished tog

#

I dropped almost all of them
I only read skeleton knight couldn't protect the dungeon

#

But slow release

proper dragon
#

tog fell off so hard

devout sail
#

Might have to pick up ln

sweet lintel
#

I've watched so many Isekai's, I think my brain has been hit by Truck-kun.

devout sail
#

And most dies by 30

#

I have probably read almost all Isekai (started 10 chaps) 3y ago

sweet lintel
#

It's why you stick to the Anime and binge the entire season / series in a day :p

devout sail
#

Just for seeing how they die and what they get

devout sail
sweet lintel
#

You saw the recent one where the guy got temporarily reincarnated as the hero who saves the day with a massive harem....'s rib?

devout sail
#

I've been trying to finish all of ergen novels
From last 1.5y

devout sail
proper dragon
#

have you guys read dark gathering

devout sail
sweet lintel
devout sail
#

Funny name
I'll check it out rn

#

You should check this out
It's nice

#

If u enjoy this type of genre

#

Pretty unique too

#

Im saying unique on this status

#

Haven't seen many doing such stuff

#

Anyways time to check this rib reincarnation

sweet lintel
#

You were warned :p

muted olive
#

Yeah this was assigned CVE-2020-something right?

#

I think they disputed this and tried to have it remove but to no effect :p

high cobalt
scenic maple
#

turns out reelix is a weeb

muted olive
#

curl http://evil.com look, I just found a 10.0 CVE

#

give CVE when

scenic maple
high cobalt
#

Look, I found a critical SQLi in PHP. If I pass an arbitrary Text to PDO::exec I get SQLi

sweet lintel
scenic maple
devout sail
#

While trying to find it
Graphql broke ๐Ÿ’€

sweet lintel
devout sail
#

Nice to find random errors tho

sweet lintel
#

Fix fix ๐Ÿ™‚

#

Reminds me - What's that anime where the episode titles are effectively a synopsis for the entire episode...

high cobalt
scenic maple
#

i am doing worse things waz

#

so back in the days i was making a discord bot so i thought dang my bot has so many features

#

what wold be a unique feature

scenic maple
#

so i added code execution like literally passing it to os.system lol

high cobalt
#

๐Ÿ˜ญ๐Ÿ˜ญ๐Ÿ˜ญ

scenic maple
#

i thought man its just replit server whats the worse that could happen

#

cause its not my server idgaf if it gets hacked

#

so it turns out

#

you could leak the token when you get rce

#

and then its basically the attackers bot

#

with access to the servers its inside

sweet lintel
#

I did one in C# awhile back. Added a tonne of protections.

I stopped when some guy in a programming channel used like 5 layers of reflection to execute the code, and it took me the rest of the week trying to figure out what the code actually did

high cobalt
scenic maple
#

remember guys its called best practices because you should follow them

high cobalt
#

Server went rogue after this

scenic maple
#

bad things happen when you dont

undone fossil
molten bobcat
#

Yooo

scenic maple
muted olive
#

The funny thing is even by NVD's logic, CVE-2020-19909 would not lead to even a DoS because a DoS implies that there's an asymmetric amplification of otherwise normal traffic in a way that overloads the server's bandwidth / available memory. 0 secs between retries and calling it a DoS on a single threaded client is insane.

Therefore my theory is that the reporter was high on ketamine, and so was NVD when they assigned the CVE.

scenic maple
#

i wasnt bad enough

sweet lintel
frigid mountain
#

i can't run code using my program

scenic maple
#

now that i am mega big brain cause i learned from my mistakes the legit way to do it is to spin up a container and run it there and return
also make sure it doesnt have internet access

#

or it could dos

high cobalt
scenic maple
devout sail
sweet lintel
devout sail
high cobalt
edgy jetty
#

golam

scenic maple
#

if you are hitting those very rare edge cases then you are doing things wrong

edgy jetty
#

selem akhy u can check ur dms ?

scenic maple
#

and you should do it differently

scenic maple
sweet lintel
devout sail
muted olive
scenic maple
high cobalt
#

While I did an epprenticeship I should program a test runner so a prof could run submissions from his students. Tried to secure it with a second process and user, firewall etc though

scenic maple
#

ok now i have

west venture
high cobalt
#

Still not 100% comfortable if this was a good idea but not my responsibility any more kek I mean to be fair it does not get library and Java patches anyways so thats probably a bigger issue lmao ...

devout sail
#

What's gonna happen on Feb 6 2036

azure remnant
#

A lot

sweet lintel
#

You sure it wasn't the 19th of Jan 2038?

high cobalt
sweet lintel
#

The year 2038 problem (also known as Y2038, Y2K38, Y2K38 superbug, or the Epochalypse) is a time computing problem that leaves some computer systems unable to represent times after 03:14:07 UTC on 19 January 2038.
The problem exists in systems which measure Unix timeโ€”the number of seconds elapsed since the Unix epoch (00:00:00 UTC on 1 January...

muted olive
azure remnant
#

Im still on 4 bits minecraft computer

muted olive
#

its like the y2k thnig

#

except everyone uses 64 bit anyway

#

so no panic this time

high cobalt
#

Although, I still wonder what stuff will break then ... probably more than people now worry and think about ...

azure remnant
sweet lintel
muted olive
azure remnant
#

Its all games and fun until 32 bits aint enough ๐Ÿ—ฃ๏ธ ๐Ÿ—ฃ๏ธ ๐Ÿ”ฅ ๐Ÿ”ฅ ๐Ÿ”ฅ

quasi ridge
#

the thing is..you can just push the bits to mean something else...the starting point for time stuff is 1970 iirc

high cobalt
#

Just 10 years guys ... 10 years until IT is in "Oh shit we didn't think about that until now" mode ... again

quasi ridge
#

so bumping it to 2000 buys at least 30+ years

edgy jetty
#

yo Have any guys already hunted on Bugcrowd?

sweet lintel
#

Or in this case - 10

high cobalt
#

Seems like every IT Generation needs to experience a global scale fuck up once

muted olive
muted olive
#

why a generation when you can have one every year

sweet lintel
#

When you're at this stage and haven't even gotten User

muted olive
high cobalt
# muted olive crowdstriiike

Nah not everyone uses them so not that big (even though big enough). Well I just have trauma from a near ransomware attack.

rancid snow
azure remnant
silver forge
azure remnant
#

"i can do it in seconds" ahh moment ๐Ÿฅ€

#

@supple plume can root it for ya with 1 move

muted olive
#

plus the claude code thing

high cobalt
muted olive
#

Axios and something else were compromised in the last month

#

LiteLLM, thats the one

sweet lintel
#

The amount of NPM compromises that have made major news that were literally "Email dev a phishing page - Dev goes to phishing page - Steal creds - Dev has no 2FA" is too damn high

high cobalt
muted olive
sweet lintel
edgy jetty
# rancid snow also yes

Those we've already hunted on Bugcrowd are still being sought. I'm considering picking up some programs again, so if you're smart, please send me a private message

high cobalt
worthy cargo
high cobalt
sweet lintel
high cobalt
sweet lintel
muted olive
high cobalt
molten bobcat
#

Had to tell a client today to narrow down their request because they have over 50 firewalls husk

#

"please provide firewall data for this timeframe"

#

Sure here's your 4 terabyte.csv

high cobalt
#

50 ... firewalls??? That sounds wild

molten bobcat
sweet lintel
#

Like you know BlueSky? Major social media platform? They allow the literal word password as your actual password! They have ZERO checks!

high cobalt
hoary dawn
#

Wassup peepz ๐Ÿฅ Gonna grind some HTB today been inactive af on there

rancid snow
molten bobcat
#

They were all labeled like they have different locations lol

hoary dawn
#

The knowledge is remembered though prayge

molten bobcat
#

Ty ty

worthy cargo
#

Hey it's Sparkles

#

What's up dude

green kite
#

Heya eggzy

worthy cargo
#

Where you been?

high cobalt
molten bobcat
#

Sure but

green kite
#

Iโ€™ve been busy with work, had an upgrade I needed to do. Took a hit mentally

molten bobcat
#

It's a weak password still

green kite
#

Howโ€™re you?

sweet lintel
molten bobcat
#

Cuz commonly used phrases are a no go

#

Like password, or the current season and the year.

#

Winter2022

sweet lintel
molten bobcat
#

I'm aware

zealous charm
#

hunter2 is safe tho

molten bobcat
#

You've said this already

sweet lintel
#

No capital P - No 123 - No exclamation mark - No checks at all ._.

high cobalt
#

Yes but ... how do you keep user experience while forcing customers/students/employees to use strong password ...

green kite
zealous charm
#

I set all my passwords to P@ssword1

sweet lintel
green kite
high cobalt
#

I wanted to implement at least a visual indicator for entropy ... the other devs didn't like it sadglas

zealous charm
#

Weak passwords donโ€™t really matter if you have MFA waz

sweet lintel
#

At least NIST eventually updated their guidelines from 8 to 15

green kite
#

I wanted to change my password somewhere recently, threw an error because it was longer than 12 char

hoary dawn
#

I just opened my laptop and I freaking noticed I have a Beats by Dre collab laptop

sweet lintel
#

Reminds me of those "Your password cannot contain the following characters:...."

green kite
hoary dawn
#

Got the lil b on it ๐Ÿ˜‚

hoary dawn
#

Thrift store cop for $30 ๐Ÿ˜Žโ˜๏ธ

hoary dawn
#

Thought it was a sticker tho tbh had to search it up then found out hp did collab with Beats by Dre ๐Ÿ˜‚

sweet lintel
#

Huh - Offsec just implemented account XP / levels

icy viper
#

Very random question but once I move to IT, how important is a smartphone?

zealous charm
limber arch
green kite
green kite
#

The phone canโ€™t really make you smarter

molten bobcat
#

Most workplaces will need you to have MFA

molten bobcat
#

And this is accomplished most commonly

high cobalt
#

You guys know how many Tickets we have to answer where applicants for a university place need to get their password reset ... guess what, half of them already even has a new mail adress ... a few weeks later ... xD

molten bobcat
#

Through an app

sweet lintel
icy viper
#

Thinking of buying a button phone instead of using smartphone

green kite
zealous charm
#

Show them how serious you are and use hardware tokens

limber arch
#

I mean if your in gov they might not allow a phone in the office lol

frigid mountain
#

lol "button phone"

molten bobcat
icy viper
green kite
frigid mountain
#

oh I know what you mean just never in my life heard button phone

sweet lintel
frigid mountain
#

I use MMS for security

icy viper
molten bobcat
high cobalt
sweet lintel
molten bobcat
green kite
#

I once had a customer share me one of their recovery codes so I could log in under their account t when they were on a holiday. As their account had MFA and it cost them money to give me a separate account

icy viper
#

So button/dumb phone for personal and smartphone for work?

sweet lintel
#

If you want

frigid mountain
sweet lintel
green kite
#

True story. I needed them to change something for me. But they were on a holiday, so thatโ€™s the way we did it

icy viper
#

Got a smartphone for personal use now in fact using discord on it now. Just want less distractions in personal life.

molten bobcat
#

I don't have multiple phones and I've been a successful cybersecurity person for years

molten bobcat
#

If you want less distractions it's a discipline thing

#

I use my phone for music a lot so it helps me focus lol

frigid mountain
#

I've been struggling to transition to using a flip phone more but so far...it just sits on charging cradle. I've used it to text loved ones the number kek

icy viper
molten bobcat
#

It sure ain't. The future be here brother

sweet lintel
icy viper
obtuse fern
icy viper
#

I miss the dumb phones though

molten bobcat
#

One of the fun thoughts I've been having lately about cybersecurity is thinking about the context behind it all

frigid mountain
#

sorry C1oud. you're #2

obtuse fern
#

i'm not joking btw, that's the stated reason as to why they stripped mod -- I was too mean

sweet lintel
#

Gotta switch your courses to THM now - RIP

frigid mountain
#

y u so mean marcie?

molten bobcat
#

Ya big meanie

worthy cargo
#

You are too mean.

obtuse fern
icy viper
frigid mountain
molten bobcat
#

Emma herself is trans

icy viper
#

But people have different opinions

molten bobcat
#

And she works for the place

worthy cargo
#

Did you merely just ban the transphobe or did you say something mean to them?

sweet lintel
obtuse fern
frigid mountain
obtuse fern
worthy cargo
#

Opinions are like assholes. Everyone's got one.

obtuse fern
#

i.e. liking waffles or liking pancakes. the difference of opinion does not make it political

molten bobcat
worthy cargo
#

Facts on the other hand...

icy viper
#

Maybe not politics but if someone gets banned because of their opinion where does it end

obtuse fern
obtuse fern
#

per the rules

#

if you want me to get technical

icy viper
high cobalt
molten bobcat
#

This server and htb by extension is available for all and cybersecurity is not limited to straight people or people more comfortable with their gender. It's very silly lmao.

sweet lintel
worthy cargo
#

I made a joke about Israel and I got a warning, level 0.

molten bobcat
#

As much as I'd love to hold my hand up and stop the wars I can't

obtuse fern
#

point is it shouldn't be political

icy viper
#

I'm religious will I get attacked?

sweet lintel
#

Just saying - Almost anything is political these days

molten bobcat
obtuse fern
molten bobcat
#

Your faith is your own and no one can take this from you. And it's not going to be a matter of much importance here lol

worthy cargo
#

Knowledge is the cure for ignorance.

high cobalt
rancid snow
icy viper
worthy cargo
#

Faith is believing without evidence.

obtuse fern
frigid mountain
molten bobcat
#

Which is big fat Okay with me

rancid snow
#

it just looks dope af

icy viper
rancid snow
#

but its also dirty and faded, I need a new one

high cobalt
frigid mountain
# rancid snow I wish

is it the old school velvet one? I know Church of Satan used to have them like that.

worthy cargo
#

Believing things without evidence is still ignorant. You don't have evidence, so that's a lack of knowledge, meaning ignorance.

icy viper
frigid mountain
#

I use my ignorance to excuse my religion

icy viper
#

I work retail and a trans woman comes into my work as a half regular customer.

rancid snow
#

its VERY faded

#

Ive had it for quite a few years

acoustic wagon
#

What websites do you guys use to stay update to date on the different exploits and infected software

rancid snow
#

the tenets on the back

worthy cargo
#

I have trans people in my family. I grew up with them. I know this space intimately. I support and love trans people so long as they're not individually assholes. I don't like assholes of any kind.

sweet lintel
icy viper
#

I mean I believe trans is the gender they were born as not as they identify as but I won't treat them any different if that makes sense?

rancid snow
#

I mean that just means you dont understand what gender is

worthy cargo
#

Treat people how you want to be treated. Treat people how they treat you. Which one to go with?

icy viper
#

I fully understand ones biological and ones social.

high cobalt
rancid snow
#

gender is the social construct of roles we assign to people. Sex is the biological assignment

worthy cargo
#

It doesn't cost anything to smile. ๐Ÿ™‚

#

So love and respect people

#

PLUR

#

Peace. Love. Unity. Respect

rancid snow
#

and even the biological bit gets pretty wonky once you go beyond biology 101