#general

1 messages · Page 655 of 1

scenic maple
#

fr fr

#

pwnbox it is

lofty marsh
#

Funny thing that in this server I learn every single computer stuff except tools sadglas

#

It's still useful

#

Keep it up broskis

scenic maple
#

Downloading the executable locally and running it through the command line, it seems like it does not run or it runs something hidden.
famous last words

ornate ibex
ocean marsh
#

No body shaming in general pls

lofty marsh
scenic maple
ornate ibex
scenic maple
#

i guess poor people cant be fat

ocean marsh
#

I hate the thick clients academy session

bronze lion
lofty marsh
#

'night man

ocean marsh
#

Tejas going to sleep after drinking 14L of water again

ornate ibex
#

No. I did the math wrong.

#

Clarified this morn

#

It was 6 bottles and each of a litter

ocean marsh
#

Thank godkek

silver forge
#

that's barely enough vodka

lofty marsh
#

Vodka alone?

silver forge
#

preferably with friends

#

and some kompot

lofty marsh
#

Na I mean not with anything else?

#

Vodka is bitter alone sadglas

#

just like wiskey

silver forge
#

that's why grandpas make kompot

#

and granmas

proper dragon
#

berry kompot is peak

lofty marsh
#

beer is the only best answer

austere sigil
#

Kompot is the true nectar of the gods

bronze lion
lofty marsh
#

smooth kek

proper dragon
#

i gotta get gif perms

austere sigil
#

😬

bronze lion
#

better start doing some machines and boxes now

cloud osprey
#

you wont

lofty marsh
#

Same 💔

bronze lion
meager kernel
#

noob rank to hacker rank is easier than hacker to pro hacker

proper dragon
devout sail
#

I see that Mr. T picked up another weird hobby

lofty marsh
#

But I gotta stop planning and start acting

undone fossil
#

yup

cloud osprey
undone fossil
#

just like

#

do shit

proper dragon
#

shrimple as

bronze lion
#

just finished up amedium lv challenge i wanna try out another machine or challenge before going to bed

devout sail
lofty marsh
#

I'll try man I promise sadglas

#

Tomorrow I lock in

devout sail
#

Heart breakm?

proper dragon
lofty marsh
#

Drunk with water? sadglas

meager kernel
#

@devout sail i forgot to root silentium

#

💔

devout sail
#

Yeah

proper dragon
devout sail
#

I'm pissed cuz all of the shops are closed cuz police been raiding them

meager kernel
#

im guessing the exploit would take me longer than 45 minutes to understand

bronze lion
devout sail
#

Only had 3 ciggie

lofty marsh
#

Shadow is from the block

devout sail
#

Fortunately i found the nico gums

meager kernel
#

@devout sail are you gonna try the new machine

#

logging

bronze lion
#

didnt see any news

lofty marsh
devout sail
meager kernel
devout sail
lofty marsh
#

If it was easy I would've streamed it

devout sail
#

I'll do it ig

devout sail
#

Why bother the shop

#

If I can make rules
I would implement that

#

If u make kids, control them

#

Don't throw the responsibility on others

lofty marsh
#

After puberty they go rogue lmao

meager kernel
#

@devout sail should i try Logging

#

or let it be

#

and learn more AD first

devout sail
#

It's medium

#

Should be easy

meager kernel
#

i dont have much confidence on myself

lofty marsh
#

Dont worry Kratos I'll finish that box in 5 minutes

devout sail
#

Well ..

lofty marsh
#

easy

lofty marsh
#

no sweat

#

easy peasy

devout sail
#

I'll try to finish it in 6h

meager kernel
#

alright?

lofty marsh
#

I was being sarcastic bro sadglas

meager kernel
#

i wasnt

devout sail
bronze lion
# devout sail Go beat their parents

thts not reasonable , they might go out of thier house saying they are gonna hang out with friends or doing this shit after school hours their parents literally wont know anything

#

thts how it usually goes

lofty marsh
devout sail
lofty marsh
#

If you make kids you have to have the parenting responsibility but its not guaranteed that they will end up good

bronze lion
devout sail
#

^

meager kernel
bronze lion
bronze lion
lofty marsh
devout sail
#

Well yeah, but still Im pissed

bronze lion
bronze lion
lofty marsh
worthy cargo
#

Just so everyone knows, I run Burp proxy on 9191, so 8080 doesn't cause a problem with other things like bloodhound-ce

prime zinc
#

im realising this now if u click with ur middle mouse in an input field u will get a magic charachter.

lofty marsh
devout sail
#

It takes u to the site without any confirmation
Used for scams few months ago
Idk if they removed it

devout sail
#

Now try middle clicking and show what it does

prime zinc
#

is it good bad

devout sail
#

gad

lofty marsh
#

Shadow

bronze lion
lofty marsh
#

Dont embarrass me in front of ipp 💔

devout sail
#

Too late

#

You can be illegitimate if u want

remote bolt
bronze lion
#

i heard he never came back with the milk tho

lofty marsh
#

sad

bronze lion
#

¯_(ツ)_/¯

undone fossil
lofty marsh
#

I dont remember saying that tho...

#

It might've been long ago

bronze lion
proper dragon
lofty marsh
#

Oh it was a day before kek

#

damn I dont remember that

lofty marsh
remote bolt
#

@undone fossil
frogs don’t drink through their mouths,
they absorb water through a belly area called the pelvic patch

lofty marsh
#

I wont even pass nmap on that box forsho 💀

proper dragon
remote bolt
#

xD

#

i am w8ing for froj to rate it cuz thats in his bio

lofty marsh
#

Aight broskis enough today

#

Imma go study tomorrow

#

Have a good one legendsss

remote bolt
#

ciaoo

hoary dawn
#

Gotta find a new monitor today

#

For me raspberry pi 🕵️

devout sail
undone fossil
#

big fan of facts about their daily life which are unexpected

#

frog = for real on god
froj = for real on jord
froj backward = jorf

devout sail
#

gorfing around

bronze lion
#

tf do u mean

devout sail
#

He meant what he said

silver forge
#

also humans can ingest alcohol if you rub it in your head. skin is thin, it will go straight to blood. just use > 80% stuff, or jello

bronze lion
#

i should also try making a challenge soon,
i hope tht i can

remote bolt
silver forge
#

for more ape facts, contact me

proper dragon
devout sail
#

@silver forge tell me how human can skip sleep forver

undone fossil
#

Neat, not looked into red eyed tree frogs too much so that’s a good one

worthy cargo
#

Two sections done

#

Moving to Adept difficulty

devout sail
#

But is xss any good other than trolling?

silver forge
undone fossil
worthy cargo
proper dragon
viscid crow
#

Hi I have a question is there a good course I can take in hack the box for pentest +

devout sail
scenic maple
undone fossil
#

Especially nowadays with AI. Their “support bot” is an attack surface

undone fossil
#

Bad

viscid crow
bronze lion
#

guess i have a serious question to ask

#

when getting certs is it recommends to take it in our real names ?

devout sail
scenic maple
#

its a mcq exam

#

just study the guides

bronze lion
scenic maple
#

htb will help on practical exams

devout sail
jagged storm
bronze lion
devout sail
#

But i wouldn't get any cert on this username 💀

bronze lion
#

got it

scenic maple
undone fossil
remote bolt
#

i heard u need to put mic+webcam on when doing exam or u go to testcenter

undone fossil
#

Idk why you wouldn’t want that, but yeah

scenic maple
#

Mr Froj, Programmer, Frog lover

jagged storm
scenic maple
#

github is where all the malware goes

obtuse fern
#

Red eyes? I play pot of greed and draw 3 cards

balmy owl
#

caan some one help me in triding to get in to this but i cant fine a way

proper dragon
#

3?

balmy owl
#

try

obtuse fern
obtuse fern
#

Cybersecurity in general?

balmy owl
#

but more like

obtuse fern
balmy owl
#

trying to get in to website

proper dragon
balmy owl
#

and find

obtuse fern
warm jacinth
#

XDD

obtuse fern
#

Does the website have a bug bounty program or vdp?

balmy owl
#

i think

obtuse fern
#

If you dont know then you likely shouldnt be poking around on it unless you want legal problems

azure remnant
#

Get into a website legal: sign up

proper dragon
#

Out of curiosity, how do bug bountie RoE work? Do I need to contact someone before trying things so I dont deal with the law?

jagged storm
warm jacinth
#

calm down cuz, whats the problem tho

balmy owl
obtuse fern
#

Then first look into if they have a disclosure policy, either on a bug bounty website or if they have a security.txt file that would direct you on who to send the information to

jagged storm
obtuse fern
devout sail
silver forge
#

yes be legal prayge

obtuse fern
#

Generally speaking though, if you dont know what you're doing, then youll likely end up doing harm (like accidental DoSing) rather than helping

obtuse fern
#

Doesn't mean you cant accidentally cause one

obtuse fern
#

Like for example using a fuzzer with too many threads

balmy owl
#

that why im trying to lean it

#

lerng

obtuse fern
#

That's why most web bounties have a rate limit of like 10

balmy owl
#

learn

zealous charm
#

more threads = more bugs. that’s why I always run burp with at least 1000

warm jacinth
#

dude, you know the basics?

obtuse fern
# balmy owl ?

More threads means youre hitting the server more, and if you hit it with too many requests you might cause it to crash

balmy owl
#

but do i grind hackthe box

#

?

obtuse fern
#

I suggest the cwes path on academy

devout sail
summer urchin
#

you should learn first

balmy owl
summer urchin
#

I would do DJCA first

#

CJCA*

scenic maple
obtuse fern
scenic maple
#

dont ask me how i know this btw

summer urchin
#

I meant looking at the info I have, start with CJCA

obtuse fern
summer urchin
obtuse fern
#

They're looking for web stuff, not system testing

summer urchin
#

ah

#

I thought CJCA might be a better start, idk

#

for web, yeah

#

what Marcie said, CWES is a good idea

warm jacinth
#

for web not

obtuse fern
#

Theres also the cracking into htb skill path on academy

scenic maple
#

cjca is like intro to cwes,cdsa,cpts

zealous charm
balmy owl
#

so whta so i do on hack the box

west lynxBOT
summer urchin
#

@balmy owl

#

read the above

obtuse fern
scenic maple
#

dont tell me u loaded it on ida

balmy owl
obtuse fern
obtuse fern
#

Unless stated otherwise im gonna assume you're a child

warm jacinth
#

maybe you shoud look for some easier labs tho

obtuse fern
balmy owl
obtuse fern
warm jacinth
balmy owl
#

around there

obtuse fern
#

@scenic maple get him

scenic maple
#

epic fail

balmy owl
#

?

balmy owl
#

what

obtuse fern
#

Yeah yeah ik, embed failure

summer urchin
#

I got you

balmy owl
#

what?

obtuse fern
balmy owl
#

nah whgat?

obtuse fern
#

Specifically regarding users under 18

balmy owl
scenic maple
#

pretty much and there is nothing we can do about it sorry

balmy owl
#

alg

obtuse fern
summer urchin
#

well

scenic maple
#

its cause of the eu laws and stuff with htb

summer urchin
#

you have to

scenic maple
#

but dont worry tho

summer urchin
#

well

#

your parents have to sign a document

#

yeah

scenic maple
#

once u sign the forum u will be back

#

the ban is temporary

scenic maple
#

please know that we get no joy out of banning people

obtuse fern
#

The shame of falling for bait is eternal

balmy owl
#

but i did no get bannd\

summer urchin
#

can't their parents signa document?

scenic maple
#

well u will get banned

#

eventually

jagged storm
wanton kayak
#

Anyone know how to send Ctrl+Z into a Pwnbox terminal via Firefox browser? It omits the Ctrl and just writes a z into the console

balmy owl
#

ha

obtuse fern
balmy owl
scenic maple
balmy owl
#

tell

warm jacinth
#

yall funny as hell fr

obtuse fern
molten bobcat
#

Make sure to show them the squidward lean pfp

scenic maple
#

it depends on what u want to do
cjca is a general start
cdsa is blue/defence
cwes is web attack/red
cpts is web+ad aattack/red

balmy owl
#

dw

obtuse fern
#

Theres also the information Security Foundations path

jagged storm
#

All this effort for someone we will never see again lol

scenic maple
#

for the people who come after

balmy owl
#

i gonna come back

obtuse fern
#

Honestly though, it was too easy

balmy owl
#

so how

obtuse fern
proper dragon
obtuse fern
balmy owl
#

ho long did i take you guys to learn this?

#

oh

#

how

jagged storm
#

Years.

balmy owl
#

ok

wanton kayak
proper dragon
#

Dont listen to rat, he was born with that knowledge

obtuse fern
jagged storm
balmy owl
#

how hard you wark

#

o

heady sage
wanton kayak
obtuse fern
# balmy owl on ?

Your attention span and how willing you are to forego instant gratification for delayed

heady sage
jagged storm
scenic maple
#

if it works on ur terminal it will work on vpn

obtuse fern
#

You want to hack a website, its not as shrimple as just running a command and getting feedback

jagged storm
#

Unless your PC is just too slow to run a VM

remote bolt
#

never ask people the "best" roadway, just find ur own way and enjoy it

wanton kayak
#

Thanks rat and golam71, I'll get the OpenVPN setup. The HTB website just seems to imply this is like a "deprecated" / not recommended method

obtuse fern
supple plume
#

hi chat'

obtuse fern
#

Hi echo

remote bolt
#

bye chat'

jagged storm
obtuse fern
#

Fresh skid on the boat

heady sage
# balmy owl i wanna learn tho

No you don’t, you want people to spoonfeed you information. You’re the worst kind of person. Get out of my sight and never speak to me again.

proper dragon
#

the noob knows where it is because it knows where it isnt

remote bolt
balmy owl
obtuse fern
warm jacinth
#

dawn

obtuse fern
#

You have the benefit of having a lot of thr knowledge written down for you in a few easy google searches

proper dragon
# balmy owl ok bet

Marice has been dropping gold on you this entire time
i would write all that stuff down and really sit with it if I were you

azure remnant
#

yall cooking without me

azure remnant
#

How dare

remote bolt
obtuse fern
#

Every technique now was once novel and had to be discovered

balmy owl
warm jacinth
#

alr, i take my words back.. aint no staying chill here

proper dragon
obtuse fern
#

Main point is. All the information you need is a Google search away. And learning to Google can be half the battle, the other half is understanding your problem

remote bolt
#

@balmy owl tell me the difference between tcp and udp

balmy owl
obtuse fern
balmy owl
remote bolt
#

nice copy+paste

azure remnant
balmy owl
azure remnant
#

Gonna be fire in minutes 🗣️ 🔥 🔥 🔥

warm jacinth
obtuse fern
#

TCP uses sequencing packets in order to ensure that if packets arrive out of order, they are assembled in order before being given to you

remote bolt
#

😆

balmy owl
#

ok

azure remnant
obtuse fern
#

UDP just gives you packets in the order they arrive in

heady sage
remote bolt
warm jacinth
azure remnant
obtuse fern
#

Which is why UDP is used for things where speed trumps reliability

heady sage
#

UDP throws shit at the wall and TCP is a trained marksman

remote bolt
#

i learned it from comptia tech+

azure remnant
#

Udp is pissing blind

obtuse fern
proper dragon
obtuse fern
#

Oop wrong reply

jagged storm
#

I think that's the new sub-A+ cert lol

jagged storm
#

It's like the A+ of the A+

obtuse fern
#

No fuckin way

azure remnant
#

Is A+ still a thing

#

What does it teach literally

obtuse fern
#

They made the dual exam cert even dumber?

remote bolt
obtuse fern
vale sorrel
#

heyy there I have connected my dicord in htb but still I cant able to see any role changes like rank or anything

should I need to do anythign other ?

obtuse fern
#

Stuff you can easily Google

azure remnant
obtuse fern
remote bolt
azure remnant
#

Image 1-2: Mechanical Keyboard

vale sorrel
#

script kiddie and bronze sadglas

obtuse fern
#

It shows here you're skid rank

supple plume
#

I just found out that sqlmap has this parameter --second-url= psy4

jagged storm
#

comptia like 'how can we scam even more money with an even more useless cert than the A+'

obtuse fern
vale sorrel
supple plume
azure remnant
vale sorrel
#

Thanks

heady sage
#

Oy vey

remote bolt
azure remnant
heady sage
#

Didn’t you get banned?

scenic maple
bronze lion
supple plume
# azure remnant Like a raw socket ?

the first payload is sent by -u to an endpoint, then a the --second-url param is to point where the reflected output of the first request lands to help sqlmap analizing responses

remote bolt
obtuse fern
azure remnant
#

Youre a G golam 🔥

bronze lion
obtuse fern
#

Maybe

obtuse fern
#

Ill have to reconsider being mean though

bronze lion
#

Just saying

obtuse fern
#

Nah, I can admit that there have been times where I crossed a line, or cultural barrier caused misconception

proper dragon
#

we all boil in pot together

iron galleon
#

the zeitgeist of this channel feels hostile 75% of the time

#

needs work

bronze lion
iron galleon
#

normalized bullying a 15 year old 💀

bronze lion
proper dragon
bronze lion
proper dragon
exotic zealot
#

Hey
i am doing some of the challenges in the challenges section of HTB
where would the progress of that be tracked ?

obtuse fern
#

On your account

proper dragon
#

Says #/824

exotic zealot
#

ok would that contribute in my rank ?

obtuse fern
exotic zealot
#

ok ok

#

thanks for the help

azure remnant
#

Bruh some blogs have graphical ui

#

When i visit them my laptop fan starts spinning hard

#

Pls, no fancy frameworks

proper dragon
#

but fancier + more compute needed = more skill of dev

azure remnant
#

the noob 👆

#

The pro: make a fancy/performance toggle

iron galleon
#

is anyone here an ai researcher

#

in uni imma try to become one

undone fossil
#

Yes

azure remnant
#

What is an ai resesrcher

undone fossil
#

Although not me

iron galleon
#

do you have advice where to start

bronze lion
azure remnant
undone fossil
#

sorry for the bait I had to. But honestly, try looking into other papers and architectures

iron galleon
#

i have a bayesian analysis book but i dont understand the math or anything 💀 would assume that i should start with advanced mathematics or something

obtuse fern
undone fossil
#

See what people did, see what’s interesting

bronze lion
undone fossil
proper dragon
undone fossil
#

Although XOR isn’t really gonna be practical because AMSI would scan at execution time (post decryption)

#

unless you patch / hook / unload AMSI and then decrypt stage 2

bronze lion
iron galleon
#

ah alr

undone fossil
#

long winded way of saying it depends ¯_(ツ)_/¯

bronze lion
#

Nvm i will send

azure remnant
azure remnant
#

I saw someone loading powerview by just changing function names

proper dragon
#

@iron galleon
i'm not an ai reseacher but work in healthcare AI
feel free to DM me with questions you may have and I'll lyk if I can help

undone fossil
#

For the most part your typical AV engines usage of AMSI can be thought of like a fancy grep

#

XDRs have the justification to go a little more in depth and will correlate with other sources etc

azure remnant
#

Good news because during the AD module i always thought "but nobody turns off real time protection on production", so i was curious

undone fossil
#

Ye don’t do that lol

#

Unless it’s a dedicated test box, much better adding a temporary exclusion if you really have to

#

Or even simpler - if their AV/XDR in place isn’t important for the test goals, ask the client to give you a pass

bronze lion
undone fossil
#

No point testing a paper towel in knights armour

undone fossil
#

Yeah but sadly the real world is rarely perfect

azure remnant
undone fossil
#

yeah like, if your goal is just to assess AD config, then XDR isn't really important there, and is just a barrier to testing

remote bolt
#

¯_(ツ)_/¯

azure remnant
#

Makes sense

undone fossil
#

its like having a cloudflare WAF on a vulnerable ctf-esque php site

#

the site could be horribly written, but the WAF might save them within the testing window, as you're limited on time

#

however you have to assume that an adversary can bypass heuristic-based defences given enough time

remote bolt
#

*****
message was auto censored by discord

azure remnant
#

Paper towel in knight armour 🗣️

#

As frog said no point in dealing with edr while its a test for ad configs

#

So yh dpnds

remote bolt
#

fun fact:
*****
message was auto censored by discord

remote bolt
#

😆

rancid totem
remote bolt
#

*****
message was auto-censored by Discord // US Federal Law Enforcement Protocol (18 U.S.C. § 1030)

wanton kayak
#

Anyone else feel that even if you don't become some pro hacker from HTB, it's a brilliant way to get all-rounder systems knowledge?

#

Learning about everything from Redis to MongoDB to LDAP

remote bolt
#

no i feel like my knowledge is worth nothing and when i learn something new i try to forget it immediately
because i want to live like a cow

iron galleon
#

the rank is rather trivial in terms of your worth

#

in an educational context, at least

ocean marsh
#

They’re releasing htb movie next week

iron galleon
#

i remember saying some shit about that a long time ago lmao

#

hack the box the movie

#

i was prolly faded asl

ocean marsh
#

@mystic harbor is the mc

#

.

iron galleon
#

lmaoo

ocean marsh
iron galleon
#

thats true

#

i been getting litty too much

#

i went to sleep earlier today bc

ocean marsh
#

Za so good its fixing your sleep schedule

iron galleon
#

LMAO yeah

#

it actually is

#

i woke up at 8 am today

ocean marsh
#

Thats crazy bro

iron galleon
#

😭

ocean marsh
#

Insane work

proper dragon
#

UDP scanning pepegun_hand toomuchtroll

remote bolt
#

user datagram protocol

timid lichen
#

I still have yet to work in a place that uses a completely closed off physical network that uses UDP, literally the only time I’ve ever used it has been in uni labs lmao

remote bolt
#

@timid lichen in ur bio "tomorrow" is misspelled

timid lichen
remote bolt
#

2morrow

timid lichen
#

Wait no it doesn’t

#

Oh my god I’m an idiot lmao, I’ve had this same thing for like years

remote bolt
#

😆

timid lichen
#

How has nobody mentioned it lmao 😭

proper dragon
remote bolt
ocean marsh
timid lichen
#

Average discord pfp, I alone am the risen one 🙌

remote bolt
#

my pfp is priceless

timid lichen
#

Nah but did thm do some funky updates? My role got nerfed back to noob from hacker

ocean marsh
timid lichen
remote bolt
#

but this is htb

timid lichen
#

Oop wrong discord lmao

remote bolt
#

bruvv

proper dragon
#

no, this is Patrick

remote bolt
#

😆

timid lichen
#

Man ignore me I’m too tired from work lmao, my buddies got me onto hackthebox after I was on tryhackme for a while, I’m liking it so far

#

A lot more in-depth, but tryhackme was a good start for my SOC career.

remote bolt
#

*****
message was auto-censored by Discord // US Federal Law Enforcement Protocol (18 U.S.C. § 1030)

timid lichen
#

Any US people here see that Mountain Dew is doing a rebrand lmao, can’t wait to drink me some “Freedom Dew” 🫩

fiery raft
#

yo guys

#

can someone help me pls

proper dragon
raven rain
fiery raft
proper dragon
ocean marsh
proper dragon
#

$sudo hack snapchat-account

sturdy thistle
#

read rules before asking

raven rain
ocean marsh
jagged storm
raven rain
#

dear lord

cloud osprey
raven rain
#

please give me the strength to survive this 12 hour flight

cloud osprey
#

no

sturdy thistle
#

enough time to hack snapchat

raven rain
#

it was worth a try

cloud osprey
#

kidding, you can have 2x strength if you fight another passenger

#

i promise

raven rain
#

alright cool thanks

alpine pumice
raven rain
#

i was considering buying one.. either the steam deck or the ayn thor

azure remnant
#

im gonna make a discord server claiming doing hacking services to let people yap and train an AI model from yapping

#

I swear 99% of time it wont use capital letters

turbid goblet
#

Has anyone heard of modernsecurity AI security course?

azure remnant
#

Not me

turbid goblet
#

Got 3rd in a CTF at bssides and got a $600 voucher for their course

azure remnant
#

🤑

alpine pumice
#

sick

azure remnant
#

Do mods get paid

turbid goblet
#

They get paid in love and attention

azure remnant
#

Take love and attention and gimme the money

supple plume
undone fossil
supple plume
#

really cool ctf

frail turtle
#

I was fighting

#

Chatgpt

#

Because theres no definite cause for Amyloidoisis.

#

And now im slightly mad

supple plume
#

@rancid snow

wanton kayak
#

What tools / software / cloud solutions do people use for notes and info when doing OffSec?

rancid totem
#

.x

#

sorry

#

wth

#

my dc got bugged

#

I think it's because of the internet

frail turtle
rancid totem
#

what the hell is this bro how can I edit a message twice

ocean marsh
rancid totem
#

or VS Code simply does the job

ocean marsh
#

Notion 🥀

frail turtle
#

I wanted to blame running as a cause. Bevause the guy i know who got it ran like 13 miles often non stop.

rancid totem
frail turtle
#

Now why would anyone run for 13 fucking miles I dont know. People are lunatics

wanton kayak
#

I've been using Trilium lately, I see Obsidian is basically the same but centralised / costs per month. Am I missing something with Obsidian?

frail turtle
#

I would only run that much if i were paid to do it.

ocean marsh
#

I used obsidian for a year and a half and I changed to trilium for the past month

#

I dont regret

#

but I like both

#

I just wanted a change

frail turtle
wanton kayak
#

Yeah exactly, so there's no sync for free?

ocean marsh
#

you can back them up with git

#

git does the job well

frail turtle
#

No.. but then again why would you put sensitive testing notes anywhere remote

#

Instead of your own pocket, just saying not the best choice.

#

Yeah like a personal git repo would be good. Not github or anything like that but one you made yourself

ocean marsh
#

I dont think most notes would be sensitive enough to not put them on remote services

#

unless its job related

#

or personal

frail turtle
#

Yeah just keep em on your own personal laptop that has an encrypted hard drive like a sensible person

#

Go to starbucks and pretend youre normal afterwards

ocean marsh
#

🥀

worthy cargo
frail turtle
#

@terse dirge hey man how did you handle packages you had to handle manually in void? Like discord the app its not in the package manager but does that mean if you had to upsate you went to github and built it?

#

Dude today i learned a lot of shit

#

Like you can have 3 different file names for the same file.

#

My mind is totally warped about how computers work since ive started messing with kernel hacking

#

I thought i had it. I dont. I dont got anything.

#

All i got is some lint and a paper clip...(small snippets of code to work with)

terse dirge
sleek zephyr
#

Hello

#

Does anyone know how I can get the annual student subscription for the academy?

rugged crest
#

hello. is it possible to get a platinum academy membership refunded? i literally jus paid it this now for a miss click

undone fossil
#

@supple plume coming 4 u

#

length limit was a funny one

alpine pumice
rugged crest
supple plume
ocean marsh
rugged crest
turbid goblet
#

i saved up enough of my tears to fit in a shot glass. any recommendations of a good occasion i should drink it?

alpine pumice
molten bobcat
jagged storm
proper dragon
ocean marsh
ocean marsh
jagged storm
#

Or just waiting until later

turbid goblet
#

pio pio pio poco pio

proper dragon
#

Y scan taek so long pepehands

ocean marsh
#

So im just chilling with my cat

proper dragon
turbid goblet
#

@worthy cargo have u done in person CTFs? is picoCTF more tailored around that theme?

worthy cargo
#

I have not done any in person CTFs

#

Here's my current progress on PicoCTF

turbid goblet
#

ah rip

#

will pico isnt like boxes right its just like challenges?

worthy cargo
#

No boxes no

#

Check 'em out. they have a variety of categories

turbid goblet
#

word yeah ill have to grind em

#

CTF today was rough

worthy cargo
turbid goblet
#

interesting thats exactly how my CTF today was categorized lol

#

well mostly

#

nice ty

proper dragon
#

i want to try down that route

worthy cargo
#

those are easily solvable with AI

#

Lots of math rquried

#

I don't like maths

#

!

proper dragon
#

im far from that
i'm doing some SQL injection boxes now

#

so wonky, these things

#

People dont actually let users run SQL, right? monkaS

turbid goblet
#

huh

proper dragon
#

I just did an easy box with a login page that spits a flag out if you put a sql condition in the user and pass fields

#

wild to think this could exist in nature

#

i killed chat FeelsBadMan

worthy cargo
#

You are out of free messages until 10:00 PM

#

Gimme !

tardy compass
#

only seen it once in a gig in a cookie header

terse dirge
#

AI makes you worse at programming 🥀

tardy compass
#

ok

worthy cargo
#

Umm you wanna check my git lab repos?

#

Shit dates back way before gen AI was a thing

#

I'm already a developer man. And that's not what I'm using claude for anyway

tardy compass
#

brother

#

he is just messing with you

latent oak
#

What’s up homies

#

Generally we don’t want to let users run random sql… but databases be databases

#

Best practice is to use stored procs

#

I’ve seen this happen in the wild

#

Or local credit union “upgraded” their online banking system. On day 1, it was discovered that you could just change the querystring to see the account of another customer

#

Unforgivable for an institution people are supposed to trust with their money

random aurora
#

I try do the game with AI

#

and its stupid

#

so much

proper dragon
#

I've been breezing through the very easy machines
Did like 4 modules and rawdogged a few chapters of the nmap book. This is neat

#

i liek

maiden anvil
dusky jacinth
#

Jk AD is fun

proper dragon
#

the pain for me right now is the writeups
i dont know the lingo at all so doing a writeup for every machine is like pulling teeth

dusky jacinth
#

(Don’t tell anyone I said that)

maiden anvil
#

Yo @dusky jacinth welcome back homie tbf I been afk for a week so idk when you came back but good to see ya again

rancid snow
dusky jacinth
proper dragon
latent oak
#

Holy shit

dusky jacinth
rancid snow
#

the app has a few other vulns thatd be pretty bad as well but the arbitrary sql query was the worst

proper dragon
rancid snow
#

It needed user creds but guess what? the demo environment used the same db as production:)

dusky jacinth
#

Real high level stuff

proper dragon
dusky jacinth
#

It’s definitely hard to digest all that if you’re newer to it

latent oak
#

@rancid snow my little project hit paydirt

dusky jacinth
#

But you’ll get it

proper dragon
rancid snow
proper dragon
#

I'm just starting to get into the machines that have multiple steps now
I'm excited, but a little intimidated. I've looked at the solve rates for these boxes and they fall off dramatically lol

latent oak
#

Full production RCE, default config

rancid snow
#

nice

#

Ive been swamped lately and not been spending the hours Ive wanted even though it still consumes every waking free time I have. I want some of my paired metrics to be a bit better than they currently are before I start pointing it at some real targets again

iron galleon
#

i could use a quick 6 figures if anyone is feeling generous

maiden anvil
#

dunno how many times Ive heard that nonsense

maiden anvil
#

replied to wrong message waz sadglas

rancid snow
#

nw I knew what you were responding to

maiden anvil
#

like yeah sure buddy Im sure you generated 13k+ records with some script and it's not real

iron galleon
#

wheres this guy when you need him

rancid snow
#

Well this one I was able to use my test account to see my real account's data lul

maiden anvil
#

hard to explain that away access_denied

rancid snow
#

The psychotic part was that they were using that endpoint to pull user info for a page and I when I was looking at requests I was just like 'huh why is my password hash there? Why are all the other users for the org's password hashes here?? Wdym this endpoint is called get_row.php ??? Why do I see SELECT ??????'

#

Same place also had backup.zip with half the source code sitting in the root of the public upload directory...along with subfolders for every org+user file uploads ever

latent oak
#

Ridiculous

random aurora
#

I found myself in cybersecurity specially pentesting not game devopler

#

I try do game with ai s

#

it was hard to me

rancid snow
#

game dev is challenging

#

even for simple shit

#

gamers are also not very accepting of AI produced games either

random aurora
#

cybersecurity is better then game deveopler

west venture
#

Lmao

#

Cyber security is cooked

random aurora
#

what u mean by that did I say something wrong

rancid snow
#

no, theres just a lot of doomers in the industry rn

#

its never been harder to get in

random aurora
west venture
#

If AI wasn't a thing, Id have multiple jobs by now

rancid snow
#

you basically have to get really lucky, or produce projects of undeniable benefit that people have to respect and acknowledge you

random aurora
#

and u solved many machines and u have get many certs for example cpts and bughunting that is better

west venture
#

Doing machines won't help you get a job

#

Maybe if you have 10 years of experience

random aurora
rancid snow
west venture
random aurora
#

soon if we got oscp I will get be hired inshallah

iron galleon
#

mashallah

west venture
proper dragon
#

thank the bankers

west venture
#

Technological development is to blame

#

Machines being able to do what humans should have done

random aurora
west venture
#

Any normal huge AI model can find bugs better than a human doing this for like 10 years

rancid snow
weary lantern
west venture
#

It doesn't even have to be claud mythos

weary lantern
random aurora
#

and its not the correct way that they doing many mistakes for example there is many compaines that have ai doing blue teaming stuff it must have trained well by the blue teamers so we should know how to use ai for bug hunting

proper dragon
west venture
#

So in the same amount of time, they'd eventually find something

rancid snow
#

ask literally anyone thats been developing workflows for using AI in vuln hunting

#

like me, or backspace lol

#

theres actually a significant amount of work involved to get AI to find proper bugs and not just spam thousands of false positives

random aurora
proper dragon
#

AI models need to be constantly upkept
thats its own skillset
AI will create loads of new jobs. Shatter your traditional heuristic of tech. Best start believin in paradigm shift stories; you're in one

west venture
#

That's the fucking point. I don't want change

rancid snow
#

my project to-do list is easily 6 more months of work minimum

west venture
#

Didn't study cyber security to just change feilds lol

random aurora
proper dragon
random aurora
#

but as u know I'm still burnout I have stopped right now thank you everyone have good day everyone

#

salam alkeem

proper dragon
#

Most AI at corporate level is for show, and only a few shops actually put out meaningful and impactful implemntations

west venture
#

And I think the jobs of teachers would basically disappear

iron galleon
#

Thank god

#

😂

west venture
#

Bc like you can get AI to explain something to you way better than a teacher

proper dragon
#

nobody wants to teach modern children anyways
These kids are so cooked

worthy cargo
#

Valve's newest Proton update has quietly removed one of Linux gaming's biggest hassles. Through Wine 11 integration and major optimizations, Proton 11 brings Linux to Windows-level playability.

#

Anyone tried Proton 11?

proper dragon
#

down with Windows

iron galleon
#

Winblows

rancid snow
west venture
#

I still can't play valorant on linux

rancid snow
#

Ive done most of that already just for building my validation metrics

west venture
proper dragon
#

valorant is the biggest saltfest ever

#

how do you deal with it

west venture
#

By being salty

#

You can be as toxic as you heart desires

#

Great way to release stress

worthy cargo
#

I'm in a weird mood

proper dragon
#

No way that game stresses me out

worthy cargo
#

Right now I don't care if I offend people

proper dragon
#

I play sage tho

worthy cargo
#

But I know that's not right

#

:/

#

Why do I feel weird?

iron galleon
#

there should be a game but for roasting people

rapid badger
#

Imagine giving Tencent kernel level access

rancid snow
#

jk (unless)

proper dragon
#

It misses you

iron galleon
#

i know it does

#

i miss it too

proper dragon
west venture
#

Try cod mobile

proper dragon
#

We all do

west venture
#

Cod mobile vc is basically out of a dark web chat room

proper dragon
#

alright I have one more machine and write up in me

#

i killed chat NotLikeThis

dusky jacinth
#

I remember going through the starting point ones

#

took a fat minute

analog perch
#

blaze Script Kiddo - interesting

proper dragon
#

qemu being used to mess with Windows? pika

west venture
#

Should I do another box?

tough oyster
west venture
#

Better at?

#

Doing boxes?

#

Maybe

runic marlin
#

I shed sweat tears bloods writing this first bash script for file in *; do (stat --format=%y $file) && (echo $file) done is it overkill just because i used it to get the last modified file?

undone fossil
#

@worthy cargo I see you're still at it on xssy

worthy cargo
#

You too

dusky jacinth
#

too much hacking today I think

#

eyeballshurt

#

need to build tolerance

#

to hacking

dusky jacinth
#

no more boxes today

heady sage
#

Huh

undone fossil
bronze lion
#

¯_(ツ)_/¯

undone fossil
#

hidden

#

I'll dm you my sample payload, if it works for you i'll be mad lol

worthy cargo
#

How come I don't see that lab listed anywhere on the all labs page?

undone fossil
#

filter by tag

#

they only show then for some reason

tough oyster
#

Looks old as fuck

worthy cargo
#

I like it

#

I just would like for the site to be more responsive

#

It's slow as turtles

karmic elk
undone fossil
#

Yeah but it doesnt take 300 years to load so like

#

W in my books

#

-# bring back old htb UI 😭

scenic maple
#

you can call it brutalist by todays standard

eager gust
scenic maple
#

Brutalist architecture is an architectural style that emerged during the 1950s in the United Kingdom, among the reconstruction projects of the post-war era. Brutalist buildings are known for minimalist construction showcasing the bare building materials and structural elements over decorative design. The style commonly makes use of exposed, unpa...

eager gust
#

Both are good. But I became used to with the previous UI

remote bolt
#

@undone fossil
The wood frog survives winter by letting its body freeze on purpose.

As temperatures drop, ice forms outside its cells while its liver releases huge amounts of glucose (a natural antifreeze).
This keeps the inside of cells from freezing and prevents damage.

Its heart stops, it doesn’t breathe, and it appears completely dead.

When spring arrives, it slowly thaws, its heart restarts, and within hours it’s alive and hopping again.

rapid badger
#

🐸

eager gust
#

what's the pasted thing I am seeing

scenic maple
#

have u seen froj in winter?

#

yeah i thought so

remote bolt
#

😆