#general
1 messages ยท Page 642 of 1
Cell posting
typically, do ppl learn both when getting into cs as a career
most of them dont require consistent maintenance and tht doesnt mean they are re-building it
Gotta find a role that speaks to you
Depends on what branch of CS they want to go into
Yeah. I can do Web Stuff and Web Hacking, but low level things are like "WTF?" for me haha xD
what do u recomend @molten bobcat
You think you're semi decent, then you see someone use something to flip a bit in a circuit to just change how stuff works , and you're like o_O
will the outcome be predictable tho?
"Oh - If we wobble the electricity enough when it's booting, it skips that function" - Like... WTF
i mean flipping the bit is not hard
but to know the exact outcome
shouldnt he be a nerd who speaks and eats binary?
Hahaha, electrical wizardry. Like I even forgot how elecricity works because as an admin and webdev I don't care too much to keep knowledge about the magic behind the hardware we are programming ๐คฃ
I recommend finding your own passion
Instead of just going after what people tell you
this chat is 24/7
i see
That's when you're dealing with oscilloscopes and altering in millivolts
today I learned about denominalization and nominalozation
great
thx m8
Timezones combined with varying activity levels
xD
I like blue teaming and DFIR work a lot. Other folks hate it with a passion
i find hacking cool, but i also like to build shit from scratch
its 5:30 pm here
It's all about finding what you like the best
sounds interesting, first time hearing abt oscilloscopes
I would be one of those folks who hate it with a passion. If I had a Blue teaming job, I'd be bored to death
same
Someone's gotta do it
the more you fuck around the more you find out
which takes longer to โmasterโ and get decent at
When your remaining boxes start to look like this ._.
This is a life long journey homie
ez ones. i could do these in like 5 sec
im so inexperienced on this topic. i feel like every question i ask is dumb
It's okay
The more you know, the more you realise you don't - You can do it for 50 years and still not consider yourself a master :p
when you are geniuelly cooked
I was dumb and clueless years ago
humans are dumb, dont wry
Now I'm just dumb
May I ask you for a tipp about learning blue teaming?
ask C1oud
Why them, I'm the blue teamer lol
You're very much asking the wrong person
It's me hi 
Oh shit marked the wrong message ahahaha ๐

Yup
Cuz people like to complain yeh
here we go again
I'm finishing up the Linux boxes first.
AI can help - It's very bad at doing complete jobs.
Every single use I've seen of AI in my own cybersecurity workspace is meh at best lol
The Burp AI has a drop table fetish :p
how long does it take for you to complete a decently hard box
I take my time, many breaks, so it depends.
also depends on ur current skill
Somewhere between several days and never :p
1 minute work 2 hour break & repeat
whats more valued, cybersecurity or programming
can u help me hack my dishwasher plssss
I just do pentesting to be able to think like an attacker. I actually do enjoy cybersecurity engineering, and architecting/building secure systems/solutions.
They're both important?
I love forensics and DFIR
i see
nerd
Those two are just intertwined lol
but I haven't been able to get into the forensics field yet
To be very good at cybersecurity you need to learn how to program, and to be very good at programming you need to learn cybersecurity - So - Both.
a very good way to put is honestly

does it even matter which i start with first
I like forensics
Is this how ppl get roles with hacking these
If yes
The important thing is just to start homie

ONG
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
u do more active boxes/challenges to rank up
Like I said I've been doing this for years I didn't start until I was 24 or so
Yeah right uh.. how can I find the active boxes if I may ask
I'm gonna go get some bbq chicken tenders, some corn on the cob, and some potato salad.
Programming may help to start with, but not necessary. Think of it like driving. You can drive really far without knowing how an engine works, but it may cause a problem if the car breaks down. The trick is to drive along, and deal with it when it happens ๐
yummy
๐คค
That's called problem solving
oh yeah? im 17 rn. i hope i can get consistent with this
go to htb labs and do the boxes (filter out the retired ones which u dont have to wry cuz all shown when u press machines tab is active)
as far as i can recall
lol
Alright thanks
You have plenty of time
Just take your time to understand things and follow what you have passion for
and then you realize in 10 years that gardening is your passion
People who care about their work produce immaculate quality work
Or at the very least better than most

good point
I've heard of people leaving cyber and going into farming. Like - Going into farming would be a nightmare for me :p
Got a tipp on how to learn a bit more about blue teaming topics? My workplace is currently in the dilemma of building at least a basic SOC which would be able to detect when our most critical systems get attacked/ransomwared (again). Not sure where I could start and help out as a Linux sysadmin with detections bc. we know a bit of Theory behind MITRE ATTACK etc. but applying it practically and building Use Cases feels a lot more overwhelming and harder. Do you know any good learning resources? Would you recommend digging deeper into red teaming to learn more?
Hi!
Sherlocks are great practice
The DFIR challenges remind me of my actual work
i cant imagine doing that ๐ but some people might want a break from all the computering around
i learned about strings,bolean, integrrs last night. whyd that shit feel boring. ig everything boring at first, ill keep at it for a while
It's only boring because of how it was explained to you
Well, I managed to finish the Overwatch box today, and made some changes to my script, so that's enough for one day :p
I find that a lot of education in the field is unfortunately.. real dry
So if you're expecting it to be a thrill ride I'm very sorry lmao
Programming theory is ass :p
It could also just end up being boring to them. Some people like the 'idea' of programming/hacking/etc more than they like actually doing it.
This is true as well
How do you decide what is actually usefull in real life? Or is it just experience you get with real world incidents and patterns you see in threat actors?
It's a combination of experience and things I've seen before
You never really know what'll end up being useful until.. the moment it occurs
Ah I see ... thanks though for the Tipp ๐
did u learn from hackthebox beginners guide when starting out
30 years ago i was the best hacker. Everything was in clear text. There was assumed trust. there wasn't a lot of security. then I got into different things in life and 30 years later the whole landscape is different.
I did my MCSE in NT4
I started long before HackTheBox existed ๐
imagine that you are hacking insane boxes at night and then working as a farmer at day
Back then active directory didn't exist
I know about common methods for piracy, and I can spot them in use in real life environments and it's really funny removing malware from a host because someone wanted to play Sniper Elite: Resistance on their work pc
lol
Haha
I've also seen people making local firewall exclusions for StarCraft 2 lmao
Literally antivirus'ing a torrent
Or smth
When you get things like this
Well me and my colleagues already told the higher ups that it would be better to get consulting for our SIEM use cases ... xD Well money is a problem though ...
Get teh etherned adapter
When I get my first bank card, I'll buy myself a cool hacking laptop
I can use both elastic and slack and I hate both
With some good statistics and other things
Why do you hate Elastic?
since new ui rework?
ELK stack - Nightmare 101
I just dislike it lol
make your own laptop ๐ฅ ๐ฅ

Damn, 8 years of hacking
Kss. We honestly love it
i think you should make a small raspberry pi project with a little keyboard, screens and stuff for the fun of it lol
And I've been in this Discord server since 2019 ;D
if im gonna be running 30 enumeration tools at once should i get active cooling on my pi 5 
how i see it is that it kept people out who didnt try
maybe rude
;D
but its not a hard gatekeep it would point you to academy if u couldnt
it wasnt like u cant get in haha get lost here is a rickroll
At once? Sounds like you need to upgrade to a new system :p
Hey uh, what is gatekeeping if I may ask
Don't tell him
"I won't talk to you because you're not good enough"
gatekeeping inception
Oh I don't believe in gatekeeping
Prime example lmao
The only time it should be gatekept is when someone wants to use the knowledge for stupid/illegal shit
thats not how it works lol
lol prolly , but the fact that i can have a mini computer with a 1% keyboard , wifi card and every port imaginable for a portable mini pentester is so god damn cool
Nah it is
Gatekeeping is the concept of "you can't sit with us"
You're not allowed in the special club, gates closed
I do also question why you're running 30 simultaenously :p
it works like this
hey u wanna know x study y and u will find out instead of spoonfeeding or how i see it i guess
im toolmaxing
Pi5 Local DoS - CVE-2026-1338 - Run 30 tools at once
golam can't sit with the gatekeepers
Oh lol I couldn't even write a fake hacking request ...
Yeah who else is going to gatekeep the gatekeepers?
they kicked me out 
@vocal fog is this u bro
He's bad at it
no true gatekeeper
Uhm... About that one...
abt wat
Oh why man

Im curious
Learning things

u r ok we will sit with u
what is this 'we' nonsense
You're already out of the circle of trust, golam
missing her snores
maybe now we 2 sit outside 
When you follow an LDAP side escalation path 4 levels deep and wonder if it actually helped...
You are now the last to be picked at flag football
Why?
You guys know what's weird and a dilemma about gatekeeping and making fun of cringe stuff? You know r/Masterhacker and r/FakeDisorderCringe? The thing is, every time someone is starting to make fun of such things it kinda becomes "50% really is cringe ... but the other 50% is probably legit and really someone learning hacking and having a real disorder and making self ironic jokes about it"
We all have very little knowledge in some aspect or another ๐
memory isnt inherently unstable, though, it just needs continous power to hold data. its not a nature of memory
I mean I usually get shy when I talk with people that knows much better than me

No, places like that are now 90% fake content, made for upvotes/etc..
I suck at everything except IT

They're people too
ยฏ_(ใ)_/ยฏ
Okay yeah karma farming is also a problem ...
bring back Vine
For every challenge on HTB you've done, there are a milllion people who have no idea how to do it :p
I mean, I love hacking and naturally.. I'm a fast learner
So uh
I dont think it'll be a problem for me to learn hacking
โ ๏ธโ ๏ธSTEP BACK THIS IS A CRIME SCENE โ ๏ธโ ๏ธ
Just gonna take some guts and time
Youre not the police

A little bit a day and you'll be good in no time ๐
Well what are you waiting for, permission?
Well
My ethernet adapter got broken
Without it, I cant do hacking
And hacking with wifi is too slow
๐ค
And I need speed
Says who...?
Me
how do yall deal with being burnt out? or preventing it?
Spin up a free Oracle box, SSH to it, and hack from there - 2,000Mbps Up / Down :p
take breaks
I think you don't even have to be the best hacker. You can even find fulfillment and get and advantage if you are just a bit better and more passionate at it than most of your coworkers even if you are a noob compared to a chad hackerman ;)
You just made a very big mistake and there will be an appropriate response
But like, doing nmapping with wifi takes hours
thats what i do, but i end up taking longer and longer breaks. maybe im just lazy
Sleep for 7 hours a night
anyone here ever faces issue with the vpn , espacially the MTU of the vpn , what's the perfect value for this
But look, I feel like I can do this
Oracle stole my money
I literally can do hacking
I've never once touched my VPN settings
Have related adjacent projects that pull up back in
if your stuck on something for awhile dont continue to burn your brain trying to figure it out, take a step outside for a bit and come back to it
Need to look into the specs of their AlwaysFree tier. I switched off of GCP since they charged me $0.02 for some international traffic :p
ยกWhat are you on!
Thats the right spirit
Hell fucking yeah
If you have to force yourself to do content, maybe the subject matter isn't for you. You need to consider if you like doing this, or if you just like the idea of doing it.

same neve, but am having an issue i can't get a server response it just hangs , and when i changed the MTU it workked
When troubleshooting it's best to change one thing at a time, could it be that your old VPN file just needed changed out?
No I mean to register for free teir. They said they need to charge $1 and they will refund it back, but they said the registration failed, and never refunded my $1 either
wow, never really thought of it like that. i dont really force myself, but rather when i get stuck, i force myself to stay until i figure it out
RIP
It's okay if it's not for you, but if you're struggling with growing burnout, you should wonder if there's a real passion there. Try to find what makes you passionate about the subject, if anything does.
I ended up in the ER for some reason
Ugh
Mmmmmm
I hate beer
Personally I think, even if you decide you don't want to do it as a day to day job, you can still learn it if you want. Like I am more of a DevOps Engineer and really a script kiddie compared to professionals. But I feel like it is still good for my career to know about hacking and doing it on a side :)
๐ฅ
it might be a tumor
You need to chill with diagnosing me with cancer
I mean, I'm naturally onto hacking and coding
I'm a technologist guy. I'll learn when I have the time
Have you done CTFs?
hi guys, i saw that some time ago you could see any country in leaderboard, but now only top100, can i still see a country outside top100?
Yes
I'm gonna learn it one day
idk , i lost interest in troubleshooting ,i just switched to TCP , i think it works fine now with no tweaking
Why
https://www.youtube.com/watch?v=x3SWlCSwt8g BRUTAL JUNGLE RITUAL DROP!
BRUTAL JUNGLE RITUAL โ a dark, hypnotic, primal ritual in the heart of the night jungle.
150 BPM of pure destructive drive:
โข Massive pounding kick
โข Deep rolling sub bass
โข Fast psychedelic groove
โข Tribal percussion, jungle drums, shakers, bongos, toms & ritual hand drums
โข Organic wooden percussion fused with hard psy-techno powe...
/me Dances
One
Also we are not hackers
Oh hm
it goes with everything
i see, thank you for the insight. i do have passion for programming, but there is so much stuff u can do its almost overwhelming.
Do you habe some basic IT knowledge? Linux? Windows? Programming? I mean like how programming and operating systems work? :) even if its basic understanding about Filesystems etc
The most fun ive had is back when
I was creating hacking scripts
For Roblo*
Good times
I have some info about programming but.. dont know much about how OS works
Like I'm still a beginner

Have you ever tried to hack activisions anticheat system?
https://app.hackthebox.com/challenges?tab=active - There's a GamePwn section there :p
What's the felony?
THANK you
I'm a tumor, I'm a tumor, I'm a tumor. Oh oh oh
Peter Griffin
God, it's like nobody has seen the movie
or we're old
Season 04, episode 06 - Petarded
#familyguy #petergriffin
Hmm cant see it maybe cuz im on mobile
Bro bypassing Activision's anticheat isn't a felony
Have the boxes the past few seasons been any good?
Mostly - I'd say so
Hm, I mean I don't know where you are from so I can't really give a good advice on how you might get a bit of education about it. Really depends on the country. I am from germany so I had the luck to get an apprenticeship as an application developer. Here it is basically 3 years working with going to a school if you don't want to study it. Sadly other countries only have colleges/universities or self learning :/
Past few seasons, some of the hard and insane were okay. There were a couple medium/easy worth checking out too.
mmh ok good to know
It's 1 box a week - Keeps you fresh ๐
I got lost in the realms of the Garfield privesc...
yeah after user I got a bit lost lol
Just install Linux and windows in VMs and mess around with them. Ask anything questions you get from chatgpt
That silly box - There's like a dozen paths you can go down, and at the end you wonder if you've accomplished anything at all :p
And silly Bloodhound doesn't detect the thing you need >_>
Bloodhound: You can't do a thing - Not one thing - Not at all.
bloodyAD: Yea - You have full access to these things.
Me: ._.
how can i earn general points?
Use bloodhound-ce instead
Active boxes and challenges
not seasonal ones
bloodhound is so dumb
Yeah playing around is reall good advice! Always!
I'm from eh..
Turkiye
https://app.hackthebox.com/machines / https://app.hackthebox.com/challenges
Finish the ones marked "Active"
I've never had it fully ingest all ACEs that I actually care about
got it thx
are these points 4ever with you?
or only as long as the machines are active
Until the box / challenge retires.
oh ok got it
It's possible to drop all the way back down to 0 if you're away long enough
It's why I've had this color name on Discord for years ;D
Do box - Do challenge - Box retires - Challenge retires - Loop :p
The thing with seasonal boxes is that they're the boxes that will stay active the longest, so will give you points for the longest time
Yappers
so, if it some point i complete all active labs ill get the highest rank?

Omni - Yes
Go to machines retired one
Nop
Have to do the challenges too
Okay good luck everyone๐ค
Shhhhhhhhtfu
Well, "Labs" do rather include challenges - It's all active everything :p
But as long as you can complete them faster than they retire, you'll eventually hit Omni
But challenges are hard and boring
They aren't
what if i have 64 points, but i did only seasonal machines and 1 active chal for 20 points, how i got other 44?
Don't worry about the points
Eh nah i think the current logic on HTB rank is like this
If they didn't release new content and retire active, and have only 1 machine
It's insta peak
Rank is determined by percentage of the platform completed
im not worried, im just curious how they work
@obtuse fern whered yo mod go
That Pirate box and that post-shell Garfield knocked me down ๐
Do it tonight
that points thing is new right
I was hungry
Nah
I don't recall seeing that a few months ago
mhm, maybe it wasn't displayed in the column or smth
But seasonal ranking is broken too
so i didnt notice
Yea - I'm sure I should be Ruby by now...
Not that
2/7 into plat at the end is weird ._.
This is discord bot issue
Just reverify
Like how I'm always holo
It's on the site as well.
I need 5 more seasonal flags to hit Ruby, I've missed 3 flags this entire season, and there are 2 boxes left.
Oh well
:")
Isn't platinum more expensive than ruby?
i am ruby and i got much less than you bro
hello
They starred with mats like silver gold ruby plat
Then put random holo?
Why not holmium
๐
I may have pushed Holo harder if it wasn't for that stupid Pirate box that knocked me down hard
Ahaha next season
no insane machines?
Can someone explain to me how the season thingy works
Final one will be
@burnt bloom youre getting opal twmrr, nice
Vague question

U do seasonal machine within week
Get points, seasonal rank, seasonal rewards
There's a bunch of boxes every now and then that you get a ranking for :p
ic ic tysm!
im trying to save up for the yearly subscription
I posted my seasonal reward discount code in this Discord once since I wasn't planning on using it - Mods were not happy with me ._.
But credits can't be shared
You pwn the weekly seasonal box and you get points. With enough points you increase your rank.
Fellow Purple! How's your progress going?
purpel
I realised they didn't give me orev season rewards
Atleast credits I'm still at 25$
Even tho I've been holo for 2 seasons
You get credits?
Didnt they only give a discount code last season and not credit?
At what rank? :p
It's going pretty well. I'm learning a lot.
Every rank
This time holo gives 45 iirc
S8 I got 25
S9 idk how much it was supposed to give
You sure about that? I got cubes in the past - Never credits
Just check season page
Rewards
And send screenshot while u are at it
See if u find s9 rewards too
Yea - Only cubes and discount codes
People spend credits - They don't spend discount codes
Instagram Reelix
But credits were nice
I suppose it was also an anti-RMT thing - People getting holo on 100k accounts and so on
So what, can't share it
Tied to account
I don't use Instagram so someone else snagged my alias there
I don't think we even got 100k active players lmao ๐
The joke was reel
Stupid pokemon
no more stacking HTB's money 
We dont, the new biznis model is not working
biznis
I wanted to stack for 10y and have alot of fake money ๐
Well as long as we can stack it
It's good
Otherwise gotta just use it once per subs
Pretty sure the stacking is no no ๐
There was an ongoing thing a few years back where some fishing company released the 9th brand of their fishing reel, used roman numerals, and it ended off as Reelix half the time which got me spammed to death :p
wassup
And there was some theme person who used a placeholder gmail address on their "Reel-IX" site which got scraped and I got spammed, so that was fun
Haha get reeled in
And now there's some random Spanish thing using Reelix to promote their image-based AI, so I'm getting spammed for that as well.
The wonders of a 6 character alias :p
thats why u add random shit at the end of ur username
I once joined a server with sado as invite
It was random russian server
Funny to find random stuff on your name
I created this username almost 40 years ago - There were 0 search results for it at the time :p
And yet there's a Chinese guy with my exact name
He could have been 20A but nah
Ya young whippersnappers...
what if his 21A actually means something
Y'all ride dinosaur 40y ago?
It could
I just hope he gets banned from X
So i can take it
I watched them build the pyramids when I walked over to Egypt the one day, so that was nice :p
Rolling blocks of stone on sticks
Rolling blocks
Sounds like rolbox

waz
That reminds me - Watch that movie The Man from Earth - Fascinating movie. There's a sequel, but it's not that great - Original is very thought provoking
It's about a guy from earth :p
And it's less than 90 minutes long
just watch 7 hour of reels and duplicate shorts to watch a 3 hour moive its that easy
Well you underestimated me
But sure I'll keep it in mind
Make it into feels
Rells
Reelix
some lifeless guy has already done it
Until you've chained all 3 LotR Extended editions in a row ;D
it doesnt take much
Add unique subway surfers gameplay on each reel
And a greenscreen guy who does nothing
i saw a guys pipeline who makes 10k from shorts
I do wonder how that became the defacto alternate-stream slop game...
10k per year? Day?
Eh - Many people using AI to pump out shorts on a hundred different channels earning fortunes
Dont do this to me
Idk but it kinda works
he gets it transcribed as in the whole movie
timestapms based on text and speech and feeds into ai and asks for timestamps
then he splits using ffmpeg and uses code to put subtitiles and based on color and stuff uses ai to apply color grading to pop up
and releases to shorts using yt api
is this the guy who has phones pointed at monitors
per week
no thats rookie
he has a factory
๐
Run a local LLM - Set up a script to generate a 15 second short - Upload it to 75 channels under 75 different names - Repeat
Now, spin up a hundred of those LLM's.
#learnToCode
Any channel which teaches this in reel?
Like Peter Griffin and Donald trump
Oh btw
I saw some guy selling course
Which is slop but for competitive exams
Allow me
exytemely low tier ragebait
And it's actually selling lmao
There are people "selling" HTB flags for boxes half a week before the box releases :p
Like u guys must have seen the ones with cats ?
Similar but with elements or history ๐
does every mod have an inner troll struggling to break free
i dont speak for all the mods but i was indeed a big troll back in the days
Perks of being a member is you can say whatever shit u want
you could see me from space back in the days
gonna go discover the esoteric ritual to help all mods' inner trolls escape and wreak havoc
I saw
access to everything htb has to offer in simple terms
In the 10 years I've been on Discord, I think you were one of the <10 people I had blocked who was actually active
Golam has 4 girlfriends
He just said that
what did i do
Who tf blocks golam
Well tbh the only thing I care about is active machines
Maybe retired sometimes
Not missing out much
well i guess works out for u
Mass trolling many a year ago
i wonder what i did lol must have been peak
Alright I'm kicking you too
It works for me
id have sent you a friend request
you see the thing with trolling is
as long as it doesnt harm anyone and its not bullying
its not that bad
Who blocks Golam? Honestly kind of weird behavior if you ask me.
i had quite the mastery of it
This comment hurt me in my heart
You said it
And this image hurts my eyes
should have posted the anime one but u would have posted something weird like feet
If you find someone who rides the line between bullying and not bullying day in and day out for months on end, that's probably someone you want to distance yourself from :p
absolutely agree
i never support bullying
now that i remember the old times
so long as i use the internet, I will troll 
I remember at every point of my discord time
I hated atleast 1 mod ๐
from what server
I started with solo leveling server
I didnโt hate any of the mods here
htb mods are super chill
i want to know what happens with that anime
like whats the end
My fault tbh
I exploited their bot and generated too much coins
tbh i want to know every animes end and the whole lore without spending too much time
Well he does time magic and fix everything and shit
and its too cringe to watch recap vids
@Grokinator
but not every anime has plot listed
make an llm do this
turn it into a youtube series
Gitara
Huh
tbh at that point in time you could watch the series
Guess they left
Get weeb gf and let her yap
@Gronkulator
massive larp specialist
Gng I am not a weeb ๐ญ
I thought that was real sloth ๐
Are u his gf ๐๏ธ๐๏ธ
nah thats a dawg
one way of reading this is physically large larp specialist...
No! I have a boyfriend
Look at the lamp pole
He doesnโt do hacking
Heโs a nursing assistant
so larp means belly?
Spoiler: ||Nm - I need more sleep.||
Live Action Role Play. L.A.R.P
And his kid does stuff
wait wut
aka D&D but you swing your foam or wood sword around
The only thing i like from solo leveling is
Oh okay. As 0daykitty said, playing around with VMs etc is a good start though. And there are a few good resources online. Even free ones.
average anime with a good animation budget
Cha hae in
I love messin around and learning anyway
That plus lockdown
Perfect timing
isnt solo leveling a bit different than t.o.g.
Oh wait... Nevermind :p
Ah i haven't finished tog
I dropped almost all of them
I only read skeleton knight couldn't protect the dungeon
But slow release
tog fell off so hard
Might have to pick up ln
I've watched so many Isekai's, I think my brain has been hit by Truck-kun.
Only fun for first 10 chapters tbh
And most dies by 30
I have probably read almost all Isekai (started 10 chaps) 3y ago
It's why you stick to the Anime and binge the entire season / series in a day :p
Just for seeing how they die and what they get
I like reading light novels now
You saw the recent one where the guy got temporarily reincarnated as the hero who saves the day with a massive harem....'s rib?
I've been trying to finish all of ergen novels
From last 1.5y
Haven't after that time period xD
have you guys read dark gathering
None to invalidate
https://en.wikipedia.org/wiki/My_Ribdiculous_Reincarnation - One of the stranger things I've seen :p
Funny name
I'll check it out rn
You should check this out
It's nice
If u enjoy this type of genre
Pretty unique too
Im saying unique on this status
Haven't seen many doing such stuff
Anyways time to check this rib reincarnation
You were warned :p
Yeah this was assigned CVE-2020-something right?
I think they disputed this and tried to have it remove but to no effect :p
Yeah linked it later. CVE 2020 19909
turns out reelix is a weeb
p1 wont fix
Look, I found a critical SQLi in PHP. If I pass an arbitrary Text to PDO::exec I get SQLi
Always have been :p
this is exactly how i keep finding 0 days in my code
While trying to find it
Graphql broke ๐
You were warned :p
Nice to find random errors tho
Fix fix ๐
Reminds me - What's that anime where the episode titles are effectively a synopsis for the entire episode...
How? are you doing exec($_GET["query"]) 
i am doing worse things 
so back in the days i was making a discord bot so i thought dang my bot has so many features
what wold be a unique feature
so i added code execution like literally passing it to os.system lol
๐ญ๐ญ๐ญ
i thought man its just replit server whats the worse that could happen
cause its not my server idgaf if it gets hacked
so it turns out
you could leak the token when you get rce
and then its basically the attackers bot
with access to the servers its inside
I did one in C# awhile back. Added a tonne of protections.
I stopped when some guy in a programming channel used like 5 layers of reflection to execute the code, and it took me the rest of the week trying to figure out what the code actually did
Lemme guess ...
remember guys its called best practices because you should follow them
Server went rogue after this
bad things happen when you dont
Yooo
thanfully enough i was the bad guy who found it
The funny thing is even by NVD's logic, CVE-2020-19909 would not lead to even a DoS because a DoS implies that there's an asymmetric amplification of otherwise normal traffic in a way that overloads the server's bandwidth / available memory. 0 secs between retries and calling it a DoS on a single threaded client is insane.
Therefore my theory is that the reporter was high on ketamine, and so was NVD when they assigned the CVE.
i wasnt bad enough
If people can run code using your program, they can run bad code - No exceptions.
i can't run code using my program
now that i am mega big brain cause i learned from my mistakes the legit way to do it is to spin up a container and run it there and return
also make sure it doesnt have internet access
or it could dos
My theory is om NVD side it was just an intern checking checkboxes or something 
feel free to use mine 
So it doesn't have manga, either anime or ln
I was looking for manga lmao
Might just watch it
Looks fun from description
Reminds me of when I was bored and used the Github runner to get a temporary shell on the builder box. Not much there, and it shut down after 30 seconds :p
Yeah Goddess: โWhat Do You Want to Turn Into When Youโre Reincarnated in Another World?โ Me: โInto a Heroโs Ribโ
I mean in very rare cases you need exec.
golam
if you are hitting those very rare edge cases then you are doing things wrong
selem akhy u can check ur dms ?
and you should do it differently
aight
It's the way it's described though is hilarious.
"I want to be turned into A hero who goes on amazing adventures, and has a massive harem who constantly swoons over him and he does awesome stuff's rib."
You can make it last longer no?
Im pretty sure it's easy to make it last for 10m
now for a real 10 CVE: all of earth's 32 bit systems will overflow on February 7, 2036 at 06:28:16 UTC
there is nothing there?
While I did an epprenticeship I should program a test runner so a prof could run submissions from his students. Tried to secure it with a second process and user, firewall etc though
ok now i have
But we'll all be dead by then
Still not 100% comfortable if this was a good idea but not my responsibility any more
I mean to be fair it does not get library and Java patches anyways so thats probably a bigger issue lmao ...
What's gonna happen on Feb 6 2036
2036?
A lot
You sure it wasn't the 19th of Jan 2038?
Didn't they change some impls to use 64 bit or more though?
The year 2038 problem (also known as Y2038, Y2K38, Y2K38 superbug, or the Epochalypse) is a time computing problem that leaves some computer systems unable to represent times after 03:14:07 UTC on 19 January 2038.
The problem exists in systems which measure Unix timeโthe number of seconds elapsed since the Unix epoch (00:00:00 UTC on 1 January...
Nope
Im still on 4 bits minecraft computer
Although, I still wonder what stuff will break then ... probably more than people now worry and think about ...
Bruh this is real
If only :p
well.. yes
Its all games and fun until 32 bits aint enough ๐ฃ๏ธ ๐ฃ๏ธ ๐ฅ ๐ฅ ๐ฅ
the thing is..you can just push the bits to mean something else...the starting point for time stuff is 1970 iirc
Just 10 years guys ... 10 years until IT is in "Oh shit we didn't think about that until now" mode ... again
so bumping it to 2000 buys at least 30+ years
yo Have any guys already hunted on Bugcrowd?
Or in this case - 10
Seems like every IT Generation needs to experience a global scale fuck up once
yes, itll reset to jan 1st 1970
crowdstriiike
why a generation when you can have one every year
When you're at this stage and haven't even gotten User
yes
Nah not everyone uses them so not that big (even though big enough). Well I just have trauma from a near ransomware attack.
also yes
Shouts skill issue ๐ฃ๏ธ ๐ฃ๏ธ ๐ฅ ๐ฅ ๐ฅ
looks like extremely easy task to me
"i can do it in seconds" ahh moment ๐ฅ
@supple plume can root it for ya with 1 move
TeamPCP have been providing everyone with enough to go around with
plus the claude code thing
Who or what is TeamPCP?
A threat actor who has been indulging in supply chain attacks
Axios and something else were compromised in the last month
LiteLLM, thats the one
The amount of NPM compromises that have made major news that were literally "Email dev a phishing page - Dev goes to phishing page - Steal creds - Dev has no 2FA" is too damn high
Oh goood, okay Supply Chain attacks really scare me. I kinda guess the next big incodent at work will be Supply Chain related ...
Was really big too. Those packages were very popular. So just update your dependencies or install anything which uses them and boom, you're compromised.
Don't they force 2FA now?
You'd freaking think...
Those we've already hunted on Bugcrowd are still being sought. I'm considering picking up some programs again, so if you're smart, please send me a private message
Yeah I know. Was hunting for IoCs ... and scaring the Security Officer because my Laptop did logs to the C2 IP ... sorry I was just dumb and didn't think other people will look at it a day later and tried out if the firewall blocks the C2 IP already ๐คฃ
Bruh. That's scary, bc at least GitHub does now ... remembered getting an EMail
Yea - Github are secure - That's why all the compromises are all npm
Weird thing is ... ITS MICROSOFT, WHYYY MICROSOFT ARE YOU LIKE THIS?!
That's the thing - It's "minimal effort" secure.
AND THAT'S ALL YOU NEED!
They couldve hidden behind their Copilot shield
Another thing I don't know haha
Had to tell a client today to narrow down their request because they have over 50 firewalls 
"please provide firewall data for this timeframe"
Sure here's your 4 terabyte.csv
50 ... firewalls??? That sounds wild

huh
Like you know BlueSky? Major social media platform? They allow the literal word password as your actual password! They have ZERO checks!
Like are they running firewalls for different regions or how do you get 50?
Wassup peepz ๐ฅ Gonna grind some HTB today been inactive af on there
I dont think your message translated well
They were all labeled like they have different locations lol
The knowledge is remembered though 
Congrats on cdsa
Ty ty
Heya eggzy
Where you been?
I mean technically Password123! is a strong password per policy ...
Sure but
Iโve been busy with work, had an upgrade I needed to do. Took a hit mentally
It's a weak password still
Howโre you?
Yes - Sure - But the literal word password ?
Cuz commonly used phrases are a no go
Like password, or the current season and the year.
Winter2022
The social media platform Bluesky quite literally allows you to change your password to password
I'm aware
hunter2 is safe tho
You've said this already
No capital P - No 123 - No exclamation mark - No checks at all ._.
Yes but ... how do you keep user experience while forcing customers/students/employees to use strong password ...
Please donโt share my discord password
I set all my passwords to P@ssword1
All I see is ******** - You're good.
That my bank account password
I wanted to implement at least a visual indicator for entropy ... the other devs didn't like it 
Weak passwords donโt really matter if you have MFA 
At least NIST eventually updated their guidelines from 8 to 15
I wanted to change my password somewhere recently, threw an error because it was longer than 12 char
I just opened my laptop and I freaking noticed I have a Beats by Dre collab laptop
Reminds me of those "Your password cannot contain the following characters:...."
Oh yes, that was an issue too
Got the lil b on it ๐
I'm sorry for your loss.
Thrift store cop for $30 ๐โ๏ธ
Thought it was a sticker tho tbh had to search it up then found out hp did collab with Beats by Dre ๐
Huh - Offsec just implemented account XP / levels
rip beats
Very random question but once I move to IT, how important is a smartphone?
You cannot set your password to โP@ssword1โ as a other user already has this password
i bet they start selling xp multiplers
As long as the user is smart, youโre good
Uhh
The phone canโt really make you smarter
Most workplaces will need you to have MFA
MFA
And this is accomplished most commonly
You guys know how many Tickets we have to answer where applicants for a university place need to get their password reset ... guess what, half of them already even has a new mail adress ... a few weeks later ... xD
Through an app
Needs to be able to use 2FA apps - Okta and Microsoft / Google Auth and so on.
Thinking of buying a button phone instead of using smartphone
Thatโs what recovery codes are for
Show them how serious you are and use hardware tokens
I mean if your in gov they might not allow a phone in the office lol
lol "button phone"
Sms methods aren't as safe
Yes an old school phone
Iโm talking about a randomised word list generated that the website wants you to save somewhere
oh I know what you mean just never in my life heard button phone
Not many people use SMS (The term - Not the format) :p
I use MMS for security
What else do you call it? Dumb phone?
This is a cybersecurity discord
Oh boy ... do I have stories about trying to push recovery codes ...
Most use text / text message
I'm aware
I once had a customer share me one of their recovery codes so I could log in under their account t when they were on a holiday. As their account had MFA and it cost them money to give me a separate account
So button/dumb phone for personal and smartphone for work?
If you want
bro I swear I'm from IT. just this one time bro
If your work needs you to have a smart phone, your work can provide you with a smart phone - But that's strictly for work. What your own phone is is up to you.
True story. I needed them to change something for me. But they were on a holiday, so thatโs the way we did it
Got a smartphone for personal use now in fact using discord on it now. Just want less distractions in personal life.
I don't have multiple phones and I've been a successful cybersecurity person for years
iPhone with eSIM ftw
If you want less distractions it's a discipline thing
I use my phone for music a lot so it helps me focus lol
I've been struggling to transition to using a flip phone more but so far...it just sits on charging cradle. I've used it to text loved ones the number 
If I could use button phone for both I'd be happy lol but I also know modern world isn't equipped for button phones
It sure ain't. The future be here brother
Mobile Firefox + uBlock Origin + Spotify Website \o/
Yeah I understand that lol
i was too mean; conveniently it was after i banned a transphobe
I miss the dumb phones though
One of the fun thoughts I've been having lately about cybersecurity is thinking about the context behind it all
you'll always be my favorite mod
sorry C1oud. you're #2
i'm not joking btw, that's the stated reason as to why they stripped mod -- I was too mean
Gotta switch your courses to THM now - RIP
y u so mean marcie?
Ya big meanie
You are too mean.
your mother
Doesn't that make it political tho

Trans people are not politics haha
Emma herself is trans
But people have different opinions
And she works for the place
Did you merely just ban the transphobe or did you say something mean to them?
5 years ago I'd have agreed with you. These days? I'm not so sure.
coincidence, allegedly, Khaotic was on vacay and it happened after he came back
that makes literally anything political
different opinions doesn't make it political
Opinions are like assholes. Everyone's got one.
i.e. liking waffles or liking pancakes. the difference of opinion does not make it political
What I mostly mean is that if you think someone's right to live and breathe on this planet is a "political argument" I need you to sniff the bottom of the nearest trash can until you think differently
Facts on the other hand...
Maybe not politics but if someone gets banned because of their opinion where does it end
they were banned because they weren't being respectful
Okay I understand my bad
It does because I will go to a holy war for one of them
(/j)
This server and htb by extension is available for all and cybersecurity is not limited to straight people or people more comfortable with their gender. It's very silly lmao.
Did you miss a recent large-scale attack? It seems that a hundred odd millions right to live and breathe on this planet WAS a political argument ._.
I made a joke about Israel and I got a warning, level 0.
which? 
I can't exactly influence geopolitics to be more friendly now can I?
As much as I'd love to hold my hand up and stop the wars I can't
point is it shouldn't be political
I'm religious will I get attacked?
Just saying - Almost anything is political these days
No
only if you try and use your religion to excuse your ignorance
Your faith is your own and no one can take this from you. And it's not going to be a matter of much importance here lol
Knowledge is the cure for ignorance.
Chokolate ... idk if I like pencakes or waffless more
me being a card carrying satanist almost never comes up
Is faith ignorance?
Faith is believing without evidence.
and when it does, it's usually REALLY funny
Does the card get you into Satanic Blockbuster?
Because it only has relevance to you and your own spiritual journey
Which is big fat Okay with me
I wish
it just looks dope af
Sure but it's still something
but its also dirty and faded, I need a new one
You sir ... I like your thinking
is it the old school velvet one? I know Church of Satan used to have them like that.
Believing things without evidence is still ignorant. You don't have evidence, so that's a lack of knowledge, meaning ignorance.
I know LGBT all exist and I respect them as long as they respect me.
I use my ignorance to excuse my religion
I work retail and a trans woman comes into my work as a half regular customer.
its VERY faded
Ive had it for quite a few years
What websites do you guys use to stay update to date on the different exploits and infected software
the tenets on the back
discord /s
I have trans people in my family. I grew up with them. I know this space intimately. I support and love trans people so long as they're not individually assholes. I don't like assholes of any kind.
None?
There were a fascinating amount of typo's in that single short sentence
I mean I believe trans is the gender they were born as not as they identify as but I won't treat them any different if that makes sense?
I mean that just means you dont understand what gender is
Treat people how you want to be treated. Treat people how they treat you. Which one to go with?
I fully understand ones biological and ones social.
Urgh being non native english speaker plus typos are the worst ...
Literally both.
gender is the social construct of roles we assign to people. Sex is the biological assignment
It doesn't cost anything to smile. ๐
So love and respect people
PLUR
Peace. Love. Unity. Respect
and even the biological bit gets pretty wonky once you go beyond biology 101



