#general
1 messages · Page 655 of 1
Funny thing that in this server I learn every single computer stuff except tools 
It's still useful
Keep it up broskis
Downloading the executable locally and running it through the command line, it seems like it does not run or it runs something hidden.
famous last words
Tools are for noobs. U build what u want.
No body shaming in general pls
What am I? 
they are also known as fat clients / rich clients
A sandwich
i guess poor people cant be fat
I hate the thick clients academy session
ye i have to refuse
'night man
Tejas going to sleep after drinking 14L of water again
No. I did the math wrong.
Clarified this morn
It was 6 bottles and each of a litter
Thank god
that's barely enough vodka
Vodka alone?
berry kompot is peak
beer is the only best answer
Kompot is the true nectar of the gods
u are the true nectar of the gods

smooth 
i gotta get gif perms
😬
ye im thinking of reaching hacker rank too
better start doing some machines and boxes now
Same 💔
why?
noob rank to hacker rank is easier than hacker to pro hacker
too busy being chatty cathies
I see that Mr. T picked up another weird hobby
But I gotta stop planning and start acting
yup
trying to reverse psychology get you to do it out of spite
shrimple as
just finished up amedium lv challenge i wanna try out another machine or challenge before going to bed
@ornate ibex first vacations, now being drunk with water and sleeping all the time
haha 
Heart breakm?
tomorrow doesnt exist
Drunk with water? 
Yeah
I'm pissed cuz all of the shops are closed cuz police been raiding them
im guessing the exploit would take me longer than 45 minutes to understand
wtf?
ah the retired one
Only had 3 ciggie
Shadow is from the block
whts happening?
Fortunately i found the nico gums
didnt see any news
Diff?
So kids were smoking and got caught
And police raiding all shops cuz why not
medium windows
Still got 40m
I'll do it ig
a very valid reason imo
Go beat their parents
Why bother the shop
If I can make rules
I would implement that
If u make kids, control them
Don't throw the responsibility on others
I mean man not that easy...
After puberty they go rogue lmao
Dont worry Kratos I'll finish that box in 5 minutes
Well ..
easy
sure
I'll try to finish it in 6h
if it takes longer than 5 minutes, im blocking you
alright?
I was being sarcastic bro 
i wasnt
So? Don't make kids
Why do I have to suffer
thts not reasonable , they might go out of thier house saying they are gonna hang out with friends or doing this shit after school hours their parents literally wont know anything
thts how it usually goes
I mean yee everyone got their choices
If they don't have money to fuck around
They wouldn't be getting into these
If you make kids you have to have the parenting responsibility but its not guaranteed that they will end up good
he doesnt give a fuck abt the life of others
, he is just sad tht he got no ciggies tday
^
im sorry for being a bad father @lofty marsh
how much does 1 even cost bruh
its literally a pocket change
Who's you bro ippsec is my dad 🥀
Well yeah, but still Im pissed
BETRAYALLL
valid
Just so everyone knows, I run Burp proxy on 9191, so 8080 doesn't cause a problem with other things like bloodhound-ce
im realising this now if u click with ur middle mouse in an input field u will get a magic charachter.
No way 💀
Try clicking on any gif on discord
It takes u to the site without any confirmation
Used for scams few months ago
Idk if they removed it
gad
Shadow

Dont embarrass me in front of ipp 💔
?
i heard he never came back with the milk tho
sad
¯_(ツ)_/¯
same i like them too

I was messing around with Kratos
@undone fossil
frogs don’t drink through their mouths,
they absorb water through a belly area called the pelvic patch
I wont even pass nmap on that box forsho 💀
maybe humans and frogs arent so different afterall
ciaoo
Very good frog fact. 9/10
Froj is actually spelled as frog
big fan of facts about their daily life which are unexpected
frog = for real on god
froj = for real on jord
froj backward = jorf
gorfing around
tf do u mean
He meant what he said
also humans can ingest alcohol if you rub it in your head. skin is thin, it will go straight to blood. just use > 80% stuff, or jello
i should also try making a challenge soon,
i hope tht i can
frog in binary =
01100110 01110010 01101111 01100111
for more ape facts, contact me
red eyed tree frogs eggs can detect vibrations from predators
their egg laying routine is called plop hatching, which allows hachlings to fall from a leaf or branch they egg was laid on into an underlying body of water
Predator vibrations cause a plop event
@silver forge tell me how human can skip sleep forver
Neat, not looked into red eyed tree frogs too much so that’s a good one
But is xss any good other than trolling?
you can't but you can prolong being awake periods slightly
Ye
stealing sessions cookies
red eyed tree frogs have been frenning for millons of years
Hi I have a question is there a good course I can take in hack the box for pentest +
But with proper security settings on them it can be avoided and it's most basic things to do?
ayoo thas me
Especially nowadays with AI. Their “support bot” is an attack surface
What's pentest plus?
Bad
Comptia pentest +
guess i have a serious question to ask
when getting certs is it recommends to take it in our real names ?
Yeah go sleep
im luckly not sleepy yet
htb will help on practical exams
Your name and username aren't much different
You're not applying to jobs with your handle.
so real name is better
But i wouldn't get any cert on this username 💀
got it
Mr Rat, Senior Pentester, CPTS
Yes unless you don’t want an employer to see it
i heard u need to put mic+webcam on when doing exam or u go to testcenter
Idk why you wouldn’t want that, but yeah
Mr Froj, Programmer, Frog lover
My linkedin is all professional, but my github will never be
github is where all the malware goes
Red eyes? I play pot of greed and draw 3 cards
caan some one help me in triding to get in to this but i cant fine a way
3?
try
Its a long running meme about the anime
Get into what?
Cybersecurity in general?
No one can help you with vague requests
trying to get in to website

and find
I love that you didnt answer my question.
?|
XDD
Does the website have a bug bounty program or vdp?
If you dont know then you likely shouldnt be poking around on it unless you want legal problems
no no im trying to do it legal
Get into a website legal: sign up
Out of curiosity, how do bug bountie RoE work? Do I need to contact someone before trying things so I dont deal with the law?
If you don't know how to do it legal, you don't know how to do it at all.
calm down cuz, whats the problem tho
i do but i dont know how to do it
Then first look into if they have a disclosure policy, either on a bug bounty website or if they have a security.txt file that would direct you on who to send the information to
Then you don't know how to do it legally.
ok
Try shutting down the PC/laptop and sleeping
yes be legal 
Generally speaking though, if you dont know what you're doing, then youll likely end up doing harm (like accidental DoSing) rather than helping
idk for to do a dos
how
.
Doesn't mean you cant accidentally cause one
Like for example using a fuzzer with too many threads
That's why most web bounties have a rate limit of like 10
learn
more threads = more bugs. that’s why I always run burp with at least 1000
dude, you know the basics?
More threads means youre hitting the server more, and if you hit it with too many requests you might cause it to crash
I suggest the cwes path on academy
hehe do u know about 1001? its more than 1000
you should learn first
?
dont u get gatekept at like 300 anyway no matter what u do
Nah, CJCA doesnt really cover web vulns too much
dont ask me how i know this btw
for web, CWES
I meant looking at the info I have, start with CJCA
Which is what I suggested lol
yes
They're looking for web stuff, not system testing
ah
I thought CJCA might be a better start, idk
for web, yeah
what Marcie said, CWES is a good idea
for web not
Theres also the cracking into htb skill path on academy
cjca is like intro to cwes,cdsa,cpts
Don’t let your dreams just be dreams, edit the limit in the src code
so whta so i do on hack the box
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
We're telling you lol
where do i get burps source code 😩
dont tell me u loaded it on ida
ok mb
Genuinely how old are you lol, this shouldnt be a hard thing to understand that we're trying to steer you in the right direction
ok ty
Unless stated otherwise im gonna assume you're a child
maybe you shoud look for some easier labs tho
Nah, web challenges
how old do you think i am?
16/17 judging off behavior
a bunch of ones like that i aint gon name them there
around there
@scenic maple get him
epic fail
?
oof
what
Yeah yeah ik, embed failure
I got you
what?
Htb ToS, you should read it
nah whgat?
oh ok so im gonna get bannd
pretty much and there is nothing we can do about it sorry
alg
https://resources.hackthebox.com/hubfs/Legal/UA.pdf section 4: eligibility
well
its cause of the eu laws and stuff with htb
you have to
but dont worry tho
please know that we get no joy out of banning people
The shame of falling for bait is eternal
but i did no get bannd\
what happen to kot
can't their parents signa document?
I did. Every time.
Anyone know how to send Ctrl+Z into a Pwnbox terminal via Firefox browser? It omits the Ctrl and just writes a z into the console
ha
Youll get hit with the account ban once staff get around to it if you dont get the form submitted
oh well
so can you give me what i so do first in hack the box
i think u might need to overwride ffox shortcuts
tell
yall funny as hell fr
you have to sign a document, well your parents have to sign it
We've told you what to do and where to go. You just have the attention span of a squirrel on crack
Make sure to show them the squidward lean pfp
ok ty
i will
it depends on what u want to do
cjca is a general start
cdsa is blue/defence
cwes is web attack/red
cpts is web+ad aattack/red
dw
Theres also the information Security Foundations path
All this effort for someone we will never see again lol
for the people who come after
i gonna come back
Honestly though, it was too easy
so how
We. Told. You
The squirrel crack epidemic is a serious issue tbqh
their networks are incredibly sophisticated. Law enforcement are finidng crackpipes buried with acorns every 30 feet
Years.
ok
Is it possible this is a scenario where using OpenVPN is better than Pwnbox?
Dont listen to rat, he was born with that knowledge
There is almost no situation where pwnbox is better, unless your connection is REALLY bad.
No he wasn’t
Interesting, is Pwnbox not very reputed? I've used it fine, pretty impressive with what it can do for a VNC browser session
Your attention span and how willing you are to forego instant gratification for delayed
How about you leave the server and don’t come back. You’re wasting everyone’s time.
There's nothing wrong with it per se, but it's just that your own image will always be faster/better.
bro
well yeah cause when using openvpn u are using a terminal hence no issues for doint ctrl z
if it works on ur terminal it will work on vpn
You want to hack a website, its not as shrimple as just running a command and getting feedback
Unless your PC is just too slow to run a VM
i wanna learn tho
never ask people the "best" roadway, just find ur own way and enjoy it
$hack google.com
ez
idc what you say
Thanks rat and golam71, I'll get the OpenVPN setup. The HTB website just seems to imply this is like a "deprecated" / not recommended method
I ran mine on 4GB of RAM and hopes and dreams
i know
hi chat'
Hi echo
bye chat'
I mean, you should do it in a VM, but it's definitely the better way.
Fresh skid on the boat
No you don’t, you want people to spoonfeed you information. You’re the worst kind of person. Get out of my sight and never speak to me again.
the noob knows where it is because it knows where it isnt

bru i asking for help if they what
gaddayum
You gotta learn as well to be self sufficient, and to take what people give you and explore
ok bet
dawn
your so full of your self
You have the benefit of having a lot of thr knowledge written down for you in a few easy google searches
Marice has been dropping gold on you this entire time
i would write all that stuff down and really sit with it if I were you
yall cooking without me
i am tho
How dare
never ask the "best" roadway, find ur own and enjoy it,
some people don't accidentally "start" in cybersec.
they came from web development, software engineer, helpdesk, tech support etc
Every technique now was once novel and had to be discovered
no i enjoy it thats why i asked
alr, i take my words back.. aint no staying chill here
it's cyclical
sometimes it gets extra spicy in here
no milk either
Main point is. All the information you need is a Google search away. And learning to Google can be half the battle, the other half is understanding your problem
@balmy owl tell me the difference between tcp and udp
?
TCP prioritizes reliabilit
TCP prioritizes reliabilit
nice copy+paste
Its cuz i wasnt here
i know im try ? no
Gonna be fire in minutes 🗣️ 🔥 🔥 🔥
aight then, thats dope
TCP uses sequencing packets in order to ensure that if packets arrive out of order, they are assembled in order before being given to you
😆
ok
Stay tuned for an upcoming ban 🗣️
UDP just gives you packets in the order they arrive in
Don’t flash card the stupid they’ll use Google everytime
just like voice/video calls
no way plz bro
Type of shii they tell us in uni
Which is why UDP is used for things where speed trumps reliability
UDP throws shit at the wall and TCP is a trained marksman
i learned it from comptia tech+
Udp is pissing blind
The fuck is tech+
Dive deeper into how the actual packets are structured
Oop wrong reply
I think that's the new sub-A+ cert lol
ok ty man
It's like the A+ of the A+
No fuckin way
They made the dual exam cert even dumber?
it replaces the comptia itf
General hardware and software things
heyy there I have connected my dicord in htb but still I cant able to see any role changes like rank or anything
should I need to do anythign other ?
Stuff you can easily Google
image 1-1: Computer Parts.
What rank are you on the website
comptia tech+
Image 1-2: Mechanical Keyboard
script kiddie and bronze 
It shows here you're skid rank
I just found out that sqlmap has this parameter --second-url= 
comptia like 'how can we scam even more money with an even more useless cert than the A+'
What is it for
Sometimes it can take up to an hour
a+ with small letter
doesn't our seasons rank gets displayed here ?
if the payload is reflected somewhere else in another request
Yes*
Like a raw socket ?
Oy vey
actually i misspoke myself, i learned it from professor messor comptia A+
Its been days since i done silentium and no bronze for me
Didn’t you get banned?
lets say you are attacking site.com/set_profile
where you set profile data via params or whatever
now the output/errors of that sqli run wont show up in that it might show up in site.com/profile8273
so then u pass the 2nd url as that so sqlmap can look at the place
Why?
the first payload is sent by -u to an endpoint, then a the --second-url param is to point where the reflected output of the first request lands to help sqlmap analizing responses
@balmy owl https://www.youtube.com/watch?v=YIaF4cJRB4g
Ahaaaa
Reverify your account then
Youre a G golam 🔥
Will u get ur mod role back?
Maybe
Acknowledged 🗣️ 🫡
Ill have to reconsider being mean though
I think ur actions are pretty valid especially when dealing with some guys in general chat
Just saying
Nah, I can admit that there have been times where I crossed a line, or cultural barrier caused misconception
Humans
¯_(ツ)_/¯
I want a diff one, i don't like taking baths together
normalized bullying a 15 year old 💀
💀
we sit in the bean water
Still

Hey
i am doing some of the challenges in the challenges section of HTB
where would the progress of that be tracked ?
On your account
Theres a challenges tracker on your profile
Says #/824
ok would that contribute in my rank ?
Only active machines and challenges count
Bruh some blogs have graphical ui
When i visit them my laptop fan starts spinning hard
Pls, no fancy frameworks
but fancier + more compute needed = more skill of dev
Yes
What is an ai resesrcher
Although not me
do you have advice where to start
Haha u got me too
Is it u who said that xor can bypass amsi
sorry for the bait I had to. But honestly, try looking into other papers and architectures
i have a bayesian analysis book but i dont understand the math or anything 💀 would assume that i should start with advanced mathematics or something
#ai-ml-llms cough cough
See what people did, see what’s interesting
There is a server called ' gray swan arena' tht would be the best place to ask those questions and I m pretty sure u will find that server very helpful if u are turning into tht field
Well it depends on what’s ingesting from AMSI but in some cases yeah simple obfuscation will do the job
classical ML
send
in dm
Although XOR isn’t really gonna be practical because AMSI would scan at execution time (post decryption)
unless you patch / hook / unload AMSI and then decrypt stage 2
Search it up in the discovery tab
ah alr
long winded way of saying it depends ¯_(ツ)_/¯
Nvm i will send
cough its cooler here cough
Thats what i thought too
I saw someone loading powerview by just changing function names
@iron galleon
i'm not an ai reseacher but work in healthcare AI
feel free to DM me with questions you may have and I'll lyk if I can help
appreciate it thanks
For the most part your typical AV engines usage of AMSI can be thought of like a fancy grep
XDRs have the justification to go a little more in depth and will correlate with other sources etc
Good news because during the AD module i always thought "but nobody turns off real time protection on production", so i was curious
Ye don’t do that lol
Unless it’s a dedicated test box, much better adding a temporary exclusion if you really have to
Or even simpler - if their AV/XDR in place isn’t important for the test goals, ask the client to give you a pass
But but they said that if I turn it off I will be able to install Fortnite with inf coins ( I forgot its name)
No point testing a paper towel in knights armour
Should happen
Yeah but sadly the real world is rarely perfect
U mean if it was important right
yeah like, if your goal is just to assess AD config, then XDR isn't really important there, and is just a barrier to testing
¯_(ツ)_/¯
Makes sense
its like having a cloudflare WAF on a vulnerable ctf-esque php site
the site could be horribly written, but the WAF might save them within the testing window, as you're limited on time
however you have to assume that an adversary can bypass heuristic-based defences given enough time
*****
message was auto censored by discord
Paper towel in knight armour 🗣️
As frog said no point in dealing with edr while its a test for ad configs
So yh dpnds
fun fact:
*****
message was auto censored by discord
😆
*****
message was auto-censored by Discord // US Federal Law Enforcement Protocol (18 U.S.C. § 1030)
Anyone else feel that even if you don't become some pro hacker from HTB, it's a brilliant way to get all-rounder systems knowledge?
Learning about everything from Redis to MongoDB to LDAP
no i feel like my knowledge is worth nothing and when i learn something new i try to forget it immediately
because i want to live like a cow
at the end of the day that's what it's all about
the rank is rather trivial in terms of your worth
in an educational context, at least
They’re releasing htb movie next week
i remember saying some shit about that a long time ago lmao
hack the box the movie
i was prolly faded asl
lmaoo
If you remember you were not faded enough
Za so good its fixing your sleep schedule
Thats crazy bro
😭
Insane work
UDP scanning

user datagram protocol
I still have yet to work in a place that uses a completely closed off physical network that uses UDP, literally the only time I’ve ever used it has been in uni labs lmao
It cuts off bruh 😭
2morrow
Wait no it doesn’t
Oh my god I’m an idiot lmao, I’ve had this same thing for like years
😆
How has nobody mentioned it lmao 😭
a semicolon is actually a better choice than a comma in this sentence

Omg soul of cinder
Average discord pfp, I alone am the risen one 🙌
my pfp is priceless
Nah but did thm do some funky updates? My role got nerfed back to noob from hacker
Its peak
thm ?
Tryhackme
but this is htb
Oop wrong discord lmao
no, this is Patrick
😆
Man ignore me I’m too tired from work lmao, my buddies got me onto hackthebox after I was on tryhackme for a while, I’m liking it so far
A lot more in-depth, but tryhackme was a good start for my SOC career.
*****
message was auto-censored by Discord // US Federal Law Enforcement Protocol (18 U.S.C. § 1030)
Any US people here see that Mountain Dew is doing a rebrand lmao, can’t wait to drink me some “Freedom Dew”
the brand logo changes the taste
ask your question. instead of asking to ask
i wanna hack three snapchat account but idk how

thug it out man
$sudo hack snapchat-account
read rules before asking
you signed up for HTB, a platform dedicating to learning ethical hacking and cybersecurity, and you come in this discord asking how to perform an illegal activity
Saying that with your full name on spotify account linked to your profile is crazy
FBI tip sent, bounty collected
dear lord
yes, my child?
please give me the strength to survive this 12 hour flight
enough time to hack snapchat
it was worth a try
alright cool thanks
did you bring your steamdeck?
i was considering buying one.. either the steam deck or the ayn thor
im gonna make a discord server claiming doing hacking services to let people yap and train an AI model from yapping
I swear 99% of time it wont use capital letters
Has anyone heard of modernsecurity AI security course?
Not me
Got 3rd in a CTF at bssides and got a $600 voucher for their course
🤑
sick
Do mods get paid
They get paid in love and attention
Take love and attention and gimme the money
wot dis
I was fighting
Chatgpt
Because theres no definite cause for Amyloidoisis.
And now im slightly mad
@rancid snow
What tools / software / cloud solutions do people use for notes and info when doing OffSec?
There isnt one per se, but everyone around these parts uses obsidian
what the hell is this bro how can I edit a message twice
obsidian, trilium
bro what are you typing
I personally use Notion because it provides students more offers.
or VS Code simply does the job
Notion 🥀
I wanted to blame running as a cause. Bevause the guy i know who got it ran like 13 miles often non stop.
Yeah I know sorry
Now why would anyone run for 13 fucking miles I dont know. People are lunatics
I've been using Trilium lately, I see Obsidian is basically the same but centralised / costs per month. Am I missing something with Obsidian?
I would only run that much if i were paid to do it.
I used obsidian for a year and a half and I changed to trilium for the past month
I dont regret
but I like both
I just wanted a change
Obsidian is free bro. You only pay if you want to backup your notes
Yeah exactly, so there's no sync for free?
No.. but then again why would you put sensitive testing notes anywhere remote
Instead of your own pocket, just saying not the best choice.
Yeah like a personal git repo would be good. Not github or anything like that but one you made yourself
I dont think most notes would be sensitive enough to not put them on remote services
unless its job related
or personal
Yeah just keep em on your own personal laptop that has an encrypted hard drive like a sensible person
Go to starbucks and pretend youre normal afterwards
🥀
I push all my obsidian notes to a private git repo
@terse dirge hey man how did you handle packages you had to handle manually in void? Like discord the app its not in the package manager but does that mean if you had to upsate you went to github and built it?
Dude today i learned a lot of shit
Like you can have 3 different file names for the same file.
My mind is totally warped about how computers work since ive started messing with kernel hacking
I thought i had it. I dont. I dont got anything.
All i got is some lint and a paper clip...(small snippets of code to work with)
google and looking in https://github.com/void-linux/void-packages
Alright
Hello
Does anyone know how I can get the annual student subscription for the academy?
hello. is it possible to get a platinum academy membership refunded? i literally jus paid it this now for a miss click
Reach out to support on the website
I wrote to Fischer, he's the one I spoke to the last time something happened to me. but he hasn't been online for hours, and I can't send another message
hell yeah
Support has less staff on weekends
okay thanku, I said that just in case that specific person could answer me
i saved up enough of my tears to fit in a shot glass. any recommendations of a good occasion i should drink it?
Yeah you have to go through the website, chat bot. It's also the weekend so support is very limited, I wouldn't expect an answer until next week. You can also email them customerops@hackthebox.com
When you are at your highest
Can you take me hiiiiigh enough 🎶
How goes the meoware
couch eat kot
is kot ok
Meoware only after cpts
He ok
Oh, are you back in the exam now?
Or just waiting until later
pio pio pio poco pio
Y scan taek so long 
Im in my parents city for the weekend
So im just chilling with my cat
udp?
no 
@worthy cargo have u done in person CTFs? is picoCTF more tailored around that theme?
interesting thats exactly how my CTF today was categorized lol
well mostly
nice ty
im far from that
i'm doing some SQL injection boxes now
so wonky, these things
People dont actually let users run SQL, right? 
huh
I just did an easy box with a login page that spits a flag out if you put a sql condition in the user and pass fields
wild to think this could exist in nature
i killed chat 
it does but practically will never see it
only seen it once in a gig in a cookie header
Maybe learn to write code vro 🥀
AI makes you worse at programming 🥀
ok
Umm you wanna check my git lab repos?
Shit dates back way before gen AI was a thing
I'm already a developer man. And that's not what I'm using claude for anyway
What’s up homies
Generally we don’t want to let users run random sql… but databases be databases
Best practice is to use stored procs
I’ve seen this happen in the wild
Or local credit union “upgraded” their online banking system. On day 1, it was discovered that you could just change the querystring to see the account of another customer
Unforgivable for an institution people are supposed to trust with their money
I've been breezing through the very easy machines
Did like 4 modules and rawdogged a few chapters of the nmap book. This is neat
i liek
in 2026 theres no excuse anymore for this kind of buffoonery
the pain for me right now is the writeups
i dont know the lingo at all so doing a writeup for every machine is like pulling teeth
(Don’t tell anyone I said that)
Yo @dusky jacinth welcome back homie tbf I been afk for a week so idk when you came back but good to see ya again
wildest sql vuln Ive seen in a real world application was a /get_row.php?row= endpoint and then just a full ass hand crafted sql query
Only a few days ago. Good to see you too Brodie 😎
i know about ADD
waffles are good too
Holy shit
You’ll pick it up as you go too, use other write-ups as reference. Use 0xdf and other official write ups
the app has a few other vulns thatd be pretty bad as well but the arbitrary sql query was the worst
I've been cross referening the cure53 writeups (which to be honest are way over my head) and using AI to nail down the concepts so far
It needed user creds but guess what? the demo environment used the same db as production:)
That’s pretty good, yeah cure53 does some legit research
Real high level stuff
my bran hurt
It’s definitely hard to digest all that if you’re newer to it
@rancid snow my little project hit paydirt
But you’ll get it

hell yeah
I'm just starting to get into the machines that have multiple steps now
I'm excited, but a little intimidated. I've looked at the solve rates for these boxes and they fall off dramatically lol
Full production RCE, default config
nice
Ive been swamped lately and not been spending the hours Ive wanted even though it still consumes every waking free time I have. I want some of my paired metrics to be a bit better than they currently are before I start pointing it at some real targets again
"Oh thats just test data"
i could use a quick 6 figures if anyone is feeling generous
dunno how many times Ive heard that nonsense
I hear you
replied to wrong message

nw I knew what you were responding to
one time I saw "test data" on a mssql injection for 13k+ "test customers"
like yeah sure buddy Im sure you generated 13k+ records with some script and it's not real
Well this one I was able to use my test account to see my real account's data lul
hard to explain that away 
The psychotic part was that they were using that endpoint to pull user info for a page and I when I was looking at requests I was just like 'huh why is my password hash there? Why are all the other users for the org's password hashes here?? Wdym this endpoint is called get_row.php ??? Why do I see SELECT ??????'
Same place also had backup.zip with half the source code sitting in the root of the public upload directory...along with subfolders for every org+user file uploads ever
Ridiculous
congratulations
Congrats
I found myself in cybersecurity specially pentesting not game devopler
I try do game with ai s
it was hard to me
game dev is challenging
even for simple shit
gamers are also not very accepting of AI produced games either
cybersecurity is better then game deveopler
what u mean by that did I say something wrong
I Know its hard to get job in this field at least u know something and u have some skills
If AI wasn't a thing, Id have multiple jobs by now
you basically have to get really lucky, or produce projects of undeniable benefit that people have to respect and acknowledge you
and u solved many machines and u have get many certs for example cpts and bughunting that is better
but gain u skills
yup all that and its only moved the needle to the occasional job interview and thats it lol
Skills that cannot get you hired
I dont want to be hired I want to prove myself in bughunting
soon if we got oscp I will get be hired inshallah
mashallah
Bug bounty is completely over saturated with AI.
this is every industry atm
even welders cant find work easily lol
thank the bankers
Technological development is to blame
Machines being able to do what humans should have done
thats wrong here thing claude now they are creating the ai for finding zero day and malware in the compaines so still we dont know other ai release that do bughunting
Any normal huge AI model can find bugs better than a human doing this for like 10 years
Thats area dependent. I know some extreme high demand welder locations lol
Thank you sir
It doesn't even have to be claud mythos
Thank you sir
and its not the correct way that they doing many mistakes for example there is many compaines that have ai doing blue teaming stuff it must have trained well by the blue teamers so we should know how to use ai for bug hunting
I'm on the east coast and hiring is quite slow aside from like one or two places despite cited "increased demand"
Thats just not true yet lol
It's just for the simple fact that you can run them 24/7
So in the same amount of time, they'd eventually find something
ask literally anyone thats been developing workflows for using AI in vuln hunting
like me, or backspace lol
theres actually a significant amount of work involved to get AI to find proper bugs and not just spam thousands of false positives
so we dont know if ai doing bug hunting in good way or not because it will give you the genreal way not the vulnerability how to work and explaining it many stuffs are missing here
AI models need to be constantly upkept
thats its own skillset
AI will create loads of new jobs. Shatter your traditional heuristic of tech. Best start believin in paradigm shift stories; you're in one
That's the fucking point. I don't want change
my project to-do list is easily 6 more months of work minimum
Didn't study cyber security to just change feilds lol
so we will understand we will get we will have we exploit we will find the bug
the market will regulate after the recession
Most traditional roles arent going anywhere
but as u know I'm still burnout I have stopped right now thank you everyone have good day everyone
salam alkeem
Most AI at corporate level is for show, and only a few shops actually put out meaningful and impactful implemntations
And I think the jobs of teachers would basically disappear
Bc like you can get AI to explain something to you way better than a teacher
nobody wants to teach modern children anyways
These kids are so cooked
Valve's newest Proton update has quietly removed one of Linux gaming's biggest hassles. Through Wine 11 integration and major optimizations, Proton 11 brings Linux to Windows-level playability.
Anyone tried Proton 11?
down with Windows
Nope.
Winblows
well actually I will say that AI is much more capable of exploit building than it is vuln finding rn lol Ive learned this as a side effect of my project.
Its not hard to give an AI a cve entry and the source and let it derive the exploit
I still can't play valorant on linux
Ive done most of that already just for building my validation metrics
Oh yeah. Basically supercharges scripting for me lol
By being salty
You can be as toxic as you heart desires
Great way to release stress
I'm in a weird mood
No way that game stresses me out
Right now I don't care if I offend people
I play sage tho
there should be a game but for roasting people
Imagine giving Tencent kernel level access
2008 cod4 called
It misses you

Try cod mobile
We all do
Cod mobile vc is basically out of a dark web chat room
Script Kiddo - interesting
qemu being used to mess with Windows? 
Should I do another box?
Do you wanna get better?
I shed sweat tears bloods writing this first bash script for file in *; do (stat --format=%y $file) && (echo $file) done is it overkill just because i used it to get the last modified file?
@worthy cargo I see you're still at it on xssy
You too
too much hacking today I think
eyeballshurt
need to build tolerance
to hacking
Huh
I know how to solve the impossible length limit one, but im not paying for the domain lol
¯_(ツ)_/¯
What lab is it, link?
This site helps you learn about cross-site scripting (XSS) attacks.
hidden
I'll dm you my sample payload, if it works for you i'll be mad lol
How come I don't see that lab listed anywhere on the all labs page?
What type of UI design is this.
Looks old as fuck
I like it
I just would like for the site to be more responsive
It's slow as turtles
Right
Yeah but it doesnt take 300 years to load so like
W in my books
-# bring back old htb UI 😭
you can call it brutalist by todays standard
👀
Brutalist architecture is an architectural style that emerged during the 1950s in the United Kingdom, among the reconstruction projects of the post-war era. Brutalist buildings are known for minimalist construction showcasing the bare building materials and structural elements over decorative design. The style commonly makes use of exposed, unpa...
Both are good. But I became used to with the previous UI
Yes, that summarises me.
@undone fossil
The wood frog survives winter by letting its body freeze on purpose.
As temperatures drop, ice forms outside its cells while its liver releases huge amounts of glucose (a natural antifreeze).
This keeps the inside of cells from freezing and prevents damage.
Its heart stops, it doesn’t breathe, and it appears completely dead.
When spring arrives, it slowly thaws, its heart restarts, and within hours it’s alive and hopping again.
🐸
what's the pasted thing I am seeing
he does the exact same thing
have u seen froj in winter?
yeah i thought so
😆
I used to do this too


