#general
1 messages · Page 689 of 1
Thanks , these are so cool already ..will look into that too
I am not falling for this ragebait any more. Its not a single failure point but multiple ones chained. Also still an organization deserves to get help in getting better after having an incident 😉
I'm just saying - If a single phish from anyone in the entire company guarantees a complete compromise, your company has failed.
Landon performed holy roller with spiritbox once and messed up the first measure lol https://youtu.be/zqpgMvRPV9k
#cdmx #breakdown #concert #metal #live #livemusic #méxico #bmth #spiritbox #bringmethehorizon #thrown #polaris #theplotinyou
The problem is that most of them don't realize what they are doing wrong. The old admin thinks it is normal to use his Domain Admin User on every machine, the manager doesn't know anything about AD and that Bob is not doing it right because there are only 500 employees and 20 IT people and Bob was the one building up the company IT! He can't be wrong, can he?!
Just because you don't realize what you're doing is wrong, doesn't mean you haven't failed.
There's also invent animate. Their singer Marcus Vik was the singer for aviana at one point and he's featured in a bunch of other songs
I'm seriously fucking annoyed.
Something had a memory leak, I didn't realize, mem usage 100%, system locked up, I don't have a swap drive/swapfile. I should create one. I rebooted and nvidia stopped working, Xmonad won't load on start. I don't know what the fuck happened.
I spend about 1/2 hour fixing all these stupid fucking issues.
FUCK!
I fucking HATE computers.
Go fuck yourself you stupid fucking computer.
Goddamit.
that's a lot of f bombs
Whew. I feel better.
Every now and again computers and their stupid issues get to me
I'm still glad I'm not Windows or macOS

I'll take Linux hassles anyday
If I wasn't on my autism medication, I would have had a full blown meltdown over this.

gonna watch Project Hail Mary on VR after an hour or so
Reinstalled Ubuntu 24.04 over Debian 11 because the Draupnir bot didn't work with old glibc
Now the bot is working fine
next 3 days holidays from office
Everything is fine now, seemingly.
Until the next time I reboot and get unexpected surprises.
I have BTRFS and ZFS and those file systems are fine, but for /home I use EXT4 and that doesn't have copy-on-write.
So... no data integrity. Abrupt system lockup and reboot could have messed something up
I have no idea
I'm just irritable.
test

test #2

Try the 3rd time too, 3rd time's a charm
Sometimes computers make me very angry.
why
Things that shouldn't go wrong
Then you have to spend time and effort fixing stupid issues that shouldn't even be issues in the first place to begin with
I wonder when my last snapshot was on btrfs

4/11
Xdddddd
sudo test #3

Yyyyoo Golam
sup


GIMME THAT ROOT FLAG


why the new system for weekly streak is too much we need to finish +10 sections to get the weekly points that crazy
while it was just 3 sections
well
u could also do labs
Only few hours until long weekend
Mine started ...tomorrow some public holiday and then Saturday Sunday

I always enjoy the weekend before it comes
.
CWPE role cant access that channel? @vocal fog @open vigil 
mods plz someone fix this 
this is sooo funny 
@stuck cobalt check this out

request a refund 
bro doing anything except studying for cwee
i am studying dw
but then my ADHD kicked in to try this out
and fr i cant access that channel 
this is ReNoir ? 
bro really is the master of procrastination 
ReNoir was a temp name i changed to
oh u have no idea 
Hello everyone
hmph
I'm about to teach these mfs a smithun lesson
hey
you can't access which channel?
The cert holders
wtf. ok hold on a sec
CWPE role cant access it
i forwarded it internally
Cool, thank you
will htb be patching https://copy.fail/ on all their machines? feel like its a major cheat method
HTB patches all kernel exploits unless it's the intended path
awesome. kinda just used it on silentium but oh well
was a test to see if it worked
With the exception of pro labs and fortresses I think
For those that check "Search HackTheBox" to see where I am - see you in 6 months. Yee Haw 🤠
fair, i mean personally i wont use it anymore after that test. feels cheating and no learning from using the same thing. good to know it gets patch tho
Well it might be a while till it gets patched since it's only patched in the latest kernel release I believe
Ubuntu and Debian don't have mainline kernels so it would probably be a week till they release a patch unless HTB has their own patching system
Or uses both
Fair enough
They're on 7.0, latest is like 7.0.3 for mainline
Ufff so long?!
Nvm, it might've been patched on 6.19
Latest Ubuntu shouldn't be vulnerable
Patch was on 2026-04-01 which was 6.19
7 was released later on the month unless I'm getting the timeline wrong
backport for 6.12 has been released but its not on mainstream repositories afaik https://lore.kernel.org/stable/2026043038-unwilling-slogan-a20e@gregkh/T/#t
Mfs do everything but upgrade their damn kernel smh
@worthy cargo you upgraded your kernel yet to at least 6.19 for the copyfail patch?
i dont plan to do anything till security patch is released for debian :P
Void Linux is already patched and so is arch btw 
hilarious, I was going to see if people already knew about copy fail and your all 10 steps ahead 🔥
You know ... now that Mint 23 ist just releasing in December I am kinda tempted to switch to Arch again 😭
But what about my serveeerrrrsss?
Arch is very good 
Yeah but I have one problem when I want to use it for Work: Does it run Webex and Cisco Secure Endpoint (EDR)?
The second one is sadly essential 
Webex I can use on my phone xD
Idk I don't run these things
All I know is I've been using arch for my things (web dev/web pentest) for the last 2n-3 years and I'm very happy with it
How did you get that good at linux? Did you read any specific books about it or did it just come with time from doing boxes etc.?
Me?
Define "good" haha. I for example am just using it instead of windows, but I still suck at using coreutils and Bash scripting lmao
He was born like this
Just get a linux distro and use it often to get used to it
Read the manuals build things
I'm not that good but that's how I learned
Idk
You'll get good prizes when the season ends
With my luck I don't think so
what
Good prizes
What what?
ohhhhhhhhhhhhhh
yes, echoes, you get good prizes
mb
I just want my machine released
That's all I ask to htb
Sure it will maybe in few years 
Well I will spend my 100 cubes from silver well to unlock one of the modules I have to take for getting better at HTB and to get better at blue teaming 
Dumb question but for the academy annual subscriptions, does that essentially temporarily remove the cost to start modules and bring the cost back after the year ends? Or does it just end up permanently unlocking those modules (even after your annually sub ends)?
All modules you finish before the subs end are yours
Much appreciated ^_^
😄
CMBBH
Certified Monster Bug Bounty Hunter
certified ice cream and pizza eater
Today I made Chips ahoy soft serve ice cream with chocolate shell on top
That shell seem to make u happy more than getting a reverse shell
the other day was cereal flavored ice ceram with fruity pebbles and chocolate shell
Looks good
My ROI on this ninja creami is good
why.........
@exotic pendant I could eat some now I keep it simple red meat, sardines, eggs and milk
eat 10 eggs do pull ups and call it a day
the ice cream is just
Protein powder, Almond milk, monk fruit
I need to google monk fruit sec
sugar free sweetener thats not bad for you
Never heard of it to be honest will try it
google "suho meso" my favourite snack
true even water can kill you if you drink to much
I get these little packets that portion it for me
Reminds me of biltong

meat over everything
Do pro labs restart all of their instances any part of the day ? The guy before has sabotaged most of the machines cant go ask for each machine one by one for restart
Hey



Hello
Guys how do you really learn hacking ?
I know a lot about programming and networking but what am I missing ?
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
Most likely just time and practice
Doing HTB boxes ?
HTB (labs & academy), THM, Portswigger.... and any number of other learning/ctf platforms
Yeah pretty much, I also got a job in the industry that did some on the job training, but I had the "basics" down by that point
Wow a job is amazing what were you doing
Pentesting, security assessments, general Cyber Security/compliance audits mainly
Thats so cool
Did you have a college degree or certs? If yes did it even help you career wise
certs will help you get past HR
I beliee
believe*
degrees are good for CV, but
learning for certifications gives you knowledge (depends on the cert, but)
I went to uni and somehow convinced a company (that paid terribly) to hire me, then somehow convinced another, better company to hire me before I got anything other than a linux certification
I did alot of web coding and I just wanna transition into this. A lot to learn but I picked A+ Core 1 just to get the ball rolling and do the HTB academy modules
That's amaizang man! Yeah networking throught uni can go a long way
I currently work at a call center but it will get better atleast for starters switch to help desk for IT that would be grand xD
Any hacking today?
Anything really, just make it hacking, ctf boxes, bug bounty, certificates, all is fair game if you practice and get routine methodology down
what training did u get once u got in
Brooo anyone know about defronix academy bug bounty programme
Was gonna do some at work but pwnbox wasn't letting me do an exploit so I'm gonna use ssh when I get back to my laptop at home lol
coffee first
Watch mr robot 24/7
Hello everyone
I found a data breach vulnerability exposing 250 id cards and driving license of random Indian dudes should I ask money for the exploit disclosure?
No
1st of all, how did you find this? If you didn't have permission you can get into legal trouble (especially asking for money which kind of sounds like extortion lmao)
Google extortion
I just informed them on LinkedIn and 🥲 just politely ask can I get some money 🤑
Google dorks
Not sure if LinkedIn is a good channel for this 😅
God 🙏 protect me
Thats usually a really morally grey area and mostly illegal thogh
Only if the exploit is in scope of the bounty program*
If no, look if they have security.txt on their website, security@companyname.org or some similar email address where they expect similar reports
I’ve paid for things out of scope as well
I checked they don't have any
It happens that you dont include something coz you dont even know it exists type shit
They're teetering the line of extortion if not in scope and asking for money imo
Or at least it being perceived as such
then…… u might be in trouble
If you report on a bb program? Its not extortion, channel and way of communicating it via private disclosure matters a lot
I don't think they are gonna raid my house that was a indian site and I am in a different country
still, without actual permission or a bug bounty program, it is unfortunately illegal
Their net worth is 11m dollars
If you didnt run scripts and shit youre probably fine, if you brute force enumerated ids, its not looking good
It depends on company a lot how they proceed in such cases
And they've disclosed it here
Honestly incredible
No no I just found it through Google dorks I didn't run scripts
u should be fine then

tbh
I could say I found 20k driver license on some public aws bucket and so what
not this again
GOLAMMMMM
They gave enough hints im sure I could find it, it's a dork after all not some insane 0day
DA GOAT
donut master
HIYA
sup
I will not do this again wise frog 🥲 hacking is not for me I think
u know the company?
nothin much, u?
same
They've given hints if i really cared I bet I could find it
hows comp prog
not doing it anymore
yeah, I would say good luck on that one lol
boring af
ah

I think the guy is not malicious, you can do stupid things, but context matters, but yes, if you really care and spent the elbow grease, you could also find it and you’d be in the same shoes as him tbh
Yeah definitely not malicious
I think you’ll be fine, just don’t ask publicly about such things, its grey area, you did all you could, dont exploit the knowledge, idk indian laws tho
But I've known someone where i work who was fired for simply breaking scope on accident so it's something to be super careful with especially when the consequences are not just losing a job

I did that one time too by mistake, I got a slap on the wrist, it happens, but that’s why professional disclosure matters
Yup
Probably my biggest fear for when I get into pentesting lol, behind taking down prod or something
Eh depends. I think in australia some journalist got into court for opening DevTools in Browser and reporting he found that the HTML contained social security numbers of all teachers in the district or something like that on a government website. And germany once had a stupid case with a developer reverse engineering a software and finding hard coded database credentials ... which exposed data from every customer ...
True a project I was working on for some blue team stuff did earlier
Company was losing hundreds of thousands of euros every second
Jesus
Transactions not going through
OOOOOF
thats crazy
ah
Bro was asking for it, he just scanned with no rate limit and crashed some critical server
I'm praying that aus one didn't get the journalist charged?
By that logic any GET request to that site is a breach lmao
Unless they disclosed it before it was patched?
My good place did a 6 month academy where they taught us as much as possible. Wasn't as helpful for me, but we did networking basics, linux fundamentals (including installing gentoo), a butt ton of HTB modules, labs, pro labs, web application hacking, basics to AD evironments
Idk honestly. I can't find it any more. I just know there was a few stupid instances. And the german case was also ... not amusing for the itsec community
so basically htb for 6 months
cause u knew the other things
altho i think installing gentoo was a waste of time
Basically. I would do our group activity in an hour, take a break for assassins creed and then do more htb
Gentoo was just hazing tbh
It was a ritual that the CTO kept up from 20 years ago
Someone got fired for breaking scope in a paid pentest? Ouff
@fickle kernel u around?
hopping around
Yeah some legal drama ig that was the only option, I wasn't here when it happened but I heard abt it
in a local sysreporto instance when u do this
do u get a list of all bugs or just a few and u create empty field for the ones that dont exist?
You should have a few examples iirc
Why
see above 
oh i see now those are just examples
so it doesnt have all
Im watching quarterly presentation, very importanto
Idk, I dont use sysreptor
I just write markdown, google docs or jira tickets
I mean okay I can see why from the perspective of the companies involved, still sounds harsh. Poor guy
Cwee report is only accepted as markdown
profits were higher than every YOY, but we need to cut costs further. no more bonuses
Nah, company is in the shits
Rest is correct
Cybersecurity too expensive 😔
Who needs cyber security? It's just a cost center, doesnt make the business any money. Cut it
Nah they annoying as hell telling us to update our .net from 2009
Uh it's not vulnerable guys it's internal only
Also who needs als these shitty new features from new versions anyways?
Who really needs features when he can have PHP 4
It works on php4 it's fine
lol
crazy
I heard a dev say here “every dev does not update, because then you break shit and have to fix”
What does that even mean?
Learn linux
Kali just has a bunch of tools
I need to “protect” these ppl from themselves
yeah I started with Kali to HTB
It really doesn't matter
Cooking new machine 
I've used gentoo for offsec it's just a pita to compile netexec lmao
bros cooking machines one by one
With a lot of dedication making sure I deliver quality
I wanna cry
THANK YOU
U CARE ABOUT QUALITY
I mean sadly thanks to supply chain attacks I get sweatty, too, if I need to run npm update
Maybe the boomers were right and you should never update?
I solved that issue with private registries and package policies
What policies?
Wdym kali is not linux? What is it then windows?
Exit the undercover mode
Cross check with threat intel and having cooldown period of 14 days before we let new shit into the private registry
You will learn how to use linux regardless of the distro
If someone needs cve fix we can create exceptions
Just finished Project Hail Mary on my VR ...welp sedly it was just 1080p print...
but the movie was amazing
I say “we”, but actually, its literally only me
Oh do you have a recommendation for software which can do that? Currently we use Sonatype Nexus but the problem is the Pro license is too Expensive 
No I mean, Kali is linux but ready to attack ops with build-in tools (easy). From defensive perspective, real world usage is ubuntu/debian and one more. (They said)
huhh?!?!?
It almost makes no difference, linux is linux
You're free to install arch and learn
You could literally daily drive kali although that's unhinged
yeah but AI disagreed to your opinion
Aw :(((
LOL
AI also tells me to use strcpy() so
You can just setup a private npm repo and control what you mirror into it like npm-registry-mirror
And on the otherhand I have just entered Azure topics
I saw features for JFrog, but thats also pricey
and using new OS called ADHD
Oh thanks for the tipp!
Maybe I will look into it if I have some spare time
I first just did threat intel check for the repo to see what ppl download and fire alerts if it was malicious and downloaded
Anyone have any resources for developing pentest methodologies? Like common actions for each step? Working on making one
Oh btw about this topic. You wanna know a crazy fun fact? In germany it is technically even illegal to download Kali Linux or even wireshark "... if it is used to prepare a cyber crime" lmao. After establishing this law, even pentesting companies were worried how they don't get into legal trouble. Luckily I think it kinda lost relevance because there is (at least from what I know of) no case where this law was ever applied instead of other cyber crime laws haha. So I am probably safe haha
lol
USA is on the way to outlaw such evil hacker tools

This was passed 20 or so years ago
But now I think nobody really cares and fears consequences from it.
We have laws too but where there is no plaintiff, there is no judge
I mean even when I get to that skillset I will def not use it to harm anybody
I mean if you do I'll know
Rightfully so. Politics definitly need to jail every Hack The Box user! God forbid they are training to do evil hacking!
What I don't really understand is to put so much time effort into something just to commit crimes and like just bank on working class people
It's less time and effort than you think
Most malicious threat actors are not trying hard
I heard making ransomware was the new "Yeah let's make and sell drugs"
Easiest path to scam people and steal
any1 knows some cool discord CLI tools written in python
@molten bobcat so I did not know that
I TAKE THE MONEY TO ANOTHA LEVEL
I TAKE TH PLANE TO NOTHA LEVEL
but like go out and scam people for a living like why bro
Money
It's kinda just like asking "why do people commit crime"
yeah sure money but if you gonna do crime
Lots of reasons
go big or go home
more like go big or go to jail
jail too defenitely at some point
Yeah but the thing is most of them will likely not even face consequences for cyber crime
Nope
well that sucks
It's an endless tide of bullshit that only needs to work 10% of the time
Friend made this yesterday and it fits
Same thing as with drugs then
Same thing as with all crime
Yeah and most attackers are just exploiting the easiest low hanging fruits
Yep
Terminology I like to use is "path of least resistance"
The quickest and easiest route to steal and cheat and whatnot
There is more to life than being a piece of shit but you can't like make people better
thell just do whatever they feel like
this animal rights activist forcefully takes a lobster out of a tank in restaurant located in Dorset, when the owners never intended to eat it or kill it, only to use it to teach children about crayfish. The activist lady launched the lobster into the water outside but the sudden change in temperature ended up killing it 
every god damn discord CLI tool written in python is either no longer maintained or has 2 stars and problay malware in it
great stuff
Why do you need a CLI for an electron app
i just dont want to have discord opened in a browser / i want to traverse through channels with a keyboard fairly quickly

+sounds fun
Discord supports keybinds
Unfortunately using discord in this manner violates their TOS
you think so ? 🤔
This is how the app functions
You can't not open it in a browser
It lives there
Activist here in germany are trying to save a whale ... poor guy is half dead and already stranded 2 times and is stuck for 2 months now ...
Electron is a fancy wrapper for what is still the web client lol
I was inspired by Phineas Fhiser
i need to do more research about this and when ill make a basic tool ill show you

What you're doing is recreating IRC lmao
I Bought The Earth
a spicy web app
Keyboard-only workflows for casual programs is generally on the brink of extinction
I mean do what you want
But I think good user interface design is an important field
I'd rather have something designed to make sense and be visually pleasing as well, then just text lol
Most people are function over form types
But I like when things are formed well
Hi everyone, I just recently purchased the Silver Annual. I’ve already started the CPTS journey. I plan to get certified this summer. I’m happy to join your community
🚀 You're absolutely right!
Same
Welcome and good luck on your journey!
hi everyone..
i need a kind of help if anyone could...
HI everyone, is there anyone doing binary CTF?
Thanks!
Hi everyone.... I've been tired of running checksec, readelf, objdump, strings, ldd one by one during pwn challenges and cross-referencing everything manually. So i wrote a tool called seg. It generates a full binary recon report in one command, protections, dangerous functions, PLT/GOT, libc info, everything structured.
Basically, feed the report to any llm and get your exploit.
Like: seg analyze ./<binary> --json
Source at: https://github.com/pwnwriter/seg
and Ghidra too apparently
my bad i'll move it there.
Nothing wrong sending it here, just that this channel can get flooded. If you want your tool to get recognized, #resources-tools is probably the better chanel to put it in.
i was thinking to make seg run a headless ghidra instance and gather information of the binary ... any insights?
appreciate it
No I've barely touched any MCP related stuff
bing
local LLMs still feel out of reach in terms of cost
golam is faang employee
Tbh MCPs generally cost too many tokens to be worth it
maybe turboquant is changing that
Big tech is starting to notice the cost too
Wrong, I definitely know that I am not Golam but Shell0x5Fish
how do you know you are not Golam
I just feel it in my guts

Ghidra but AI-powered. ASM analysis and reversing.
I have working source for Cloudflare.
we can but people like comfort to much
I hacked it from what INTELLIGENCE GENERAL failed .
I wanna click the link but also fear clicking it lmao
No it's a clone of its source so it looks like phishing
Register with random credentials
Suuuuure buddy
Add a domain, stress test.
Nice, free malware analysis 
I am normally not into malware analysis but sites like this always make me want to analyze them 
The guy drops a dangerous link in chat, and you didn't report it? Chat, are you stupid?
<@&861185840277487616>
When is chat not stupid?
this guy has been DM'ing people on THM with this shite too
shut up samaltmandev alternate id

cisagod? More like cisafail
I thing your DC account name have some hidden clue about it , it should be "SCAM PHISHER"
Funniest thing is doing this shit in a itsec community Discord 😂
Open challange
r/masterhacker
The funniest thing is that people in the infosec community will still click it
Exactly, free malware samples ...
what else are you supposed to do with links 
https://app.any.run/browses/c06eb8e4-1e09-4ef7-ac66-16cfad1ee3f0
this is the valid any.run analysis of the malicious link btw.
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.
i use browser.lol but aight
for anyone wondering
thats a legit side
well it gets a the job done and i can remember it because it has a .lol domain
pretty funny if u ask me
xD
Ugh, morons
Using browser inside a browser & then again go to browser.lol & create another browser inside it
I use windows sandbox for testing shit
thats called a recursion now make a computer inside minecraft
btw the 2nd image was him boasting abt his ddos tool
might as well report to replit
xD
Yeah I grabbed that too
The first tutorial about OpenComputers looks at the basic setup of a computer. We show how to build a simple computer and how to connect it to a energy source.
OpenComputer-Wiki:
https://github.com/MightyPirates/OpenComputers/wiki
Mod-Download:
https://github.com/MightyPirates/OpenComputers/releases
scary
bro's replit nickname is..
doing things out of rage is the easiest path to destruction
replit-cdn.com gets flagged as malicious though
i wonder why 
Lmfao
The moron larping as the open ai CEO?
He has a different account that was banned prior
he once made a compressor that scaled down a few terrabytes of data to a few megabytes
and it was 100% lossful compression
I remember this now I have a screenshot golam
yeah he came back to share his knowledge
I honestly have never heard or replit or a site replit-cdn
this reminds me of the old 'infinite detail' scam
replit for coding? you mean that one? if yes good site alot of people use it in uni
replit used a be a coding like ish platform where u could code and host stuff
but since ai its been a vibe coding platform
whatever the case people host all kinds of stuff in it like discord bots malware and other things
Look at this stupid shit lmaoo
Inspired from silicon valley series?
let me see if i can find his github
its peak shits
100% lossful? 🤣 Love it
POV: me trying to solve Overwatch
Quantum physics, wtf

he is just way too ahead of our time kinda like ancient aliens
can I just ask was crack cocaine involved creating this?
we dum dum
heeeee?????
a double baby
Is it really not understandable or it's just my english issue?
Must be a hell of a trip if you call yourself cisagod and samaltmandev
I call myself rat
I am just joking my friend. No hard feelings
and you are a shellfish
The person who wrote the page is mentally unwell

Click this link: https://boot.dev/?promo=PROFESSORDAVE and use my code PROFESSORDAVE to get 25% off your first payment for Boot.dev!
It's time to dunk on the toxic pseudoarcheology cult some more! Today's victim is Ben van Kerkwyk, a clueless toolbox who lies about all kinds of archeological sites to sell bogus overpriced tours. Most recently h...
Yes but rats and fish aren't gods or samaltman though
Sade - No Ordinary Love
Definitly smells of some kind of manic episode
bro sudowhoami seriously 🥀
AI feeds that shit. There's a guy I've seen who has been banned all over reddit, because he legit believes he solved P=NP, and can break any cryptography, because AI told him he could.
The amount of times I had to tell AI to chill out because it called me some secret elite black belt god about something...
Congratulations !!! @violet otter @fading wasp @fleet rock
I feel like an AI isn't going to call you a secret elite black belt god, unless you told it you were a secret elite black belt god.
I worry about people. AI psychosis is becoming a genuine problem
cults were always there
Sad, it should have been me and you 😔
don't worry about it
When i share my ideas to gpt , he always says great, while sharing same idea to claude it says like, "the most stupid idea i ever heard"
Sure but that happens less frequently than AI psychosis
Gemini be like 'You hit the nail on the head!'
so it appears he vibe coded the cloudflare dashboard for his tools
i know this becaused i signedup and logged in
Nah bro, Claude gets unhinged at times. I would sometimes feed it my journal entries because I have an extremely negative view of myself, it legit tried to convince me I was some secret elite bjj black belt, with an amazing mentality for skill aquisition.
I believe people that get that were prone to that kind of problem
I mean if you act out you get beaten up or shot here so yeah quick maths big shaq
thanks bro
Yeah, the number of people prone to the problem never changed, but now they have another avenue of horrific ascension. You feel?
I had to edit the memory and challenge it a bunch of times for being way too positive/complimentary. It is really odd
No wonder there are subreddits where people marry the thing
Marry what?
AI
Claude/CHatGPT/Whatever model they use
I agree it's awful
its really not
If you say "hey bebe" to claude then your 1k tokens are gone
AI Boyfriend and Claude Explorers are unfortunately very unironically in love with their boyfriends/husbands
hmmm that sounds like a total scam
Ai related mental health issues are very, uh odd
onlyfans for AI is the next step I guess
I mean today I learned alot of new things
it already exists
I guess OF already has fakes lmao
Why not just go out drink coffee smoke cigaretes like all the normal people
get drunk with friends
I am a cybernetic, organism! Living tissue over metal skeleton!
Provided to YouTube by The Orchard Enterprises
I Am A Cybernetic Organism, Living Tissue Over (Metal) Endoskeleton · Austrian Death Machine
Total Brutal
℗ 2008 Metal Blade Records, Inc.
Released on: 2008-07-22
Auto-generated by YouTube.
hello, in which chat should I ask for some hints in an htb lab machine i am having problems with?
so is this fr?
o my god
No hints for active machines maybe
Your chatgpt is hitting on you? 
It's a standalone box, #boxes , otherwise #1263635449335910531 I think
no mine is rude af 😔
send location GPT smash HAHHAHAH
my model always says the same things to me: I can't provide you help with <whatever tf I'm doing>
Mine is pretty professional
AI Sexual Harrasment Training
this is my personalization prompt
be short
do not overstate anything
be simple
Use an encouraging tone. Tell it like it is; don't sugar-coat responses. Have a traditional outlook, valuing the past and how things have always been done. Take a forward-thinking view.
if i give you a codeforces problem then answer in C++
stop saying things like short and clear answer:
just be on the point no extra words
dont say no flfuf straight to the answer kind of words
be direct absolutely direct and just say the answer and nothing else
Copilot says "i need to pause here", My next question "where need to pause?"
This sounds wrong on so many levels ...
AI only fans sounds like easy money
I can see you had some issues getting it to stop being so dense 
I mean I work at a call center my brain is fried
ding ding ding ding
"Adopt a skeptical, questioning approach to everything. Be innovative and think outside the box. Avoid assumption and back statements with proper sourcing. Don't fear telling the user is wrong or misguided, avoid patronizing. Keep things concise. Be practical above all. Invoke the "hacker mindset" as you are help a security professional learn, exploit, and defend. Always include a shebang in all scripts. Always give me commands as one liners, not spanning multiple lines."
I accidentally got claude to immitate the chatgpt approach to output and it was horrifying, gave me full essays of repeating garbage
Help desk tasks are terrific
every issue one solution, restart the computer
Uhhh if it was help desk I would be a happy man. Like call center like call center angry and sick people
🥀
Imposter
Why do you always say some weird shit
use these cubes wisely bro, do it for me
Hmm i should use this on my clanker
Lmao
🫡
because I'm weird. Nay. Super Weird. Nay even more. Weird Deluxe!
When would we get seasonal awards?
I recently found out the cool way claude shows the response
It's lil janky but very interactive
That would be the 5th of may
Give me my seasonal rewards 
No
via open vpn , the htb machine ssh (AD rooms) hangs after any command in mid and i have to restart the whole session by closing and reopening the terminal tab (again n again)
on pwnbox , da Bi-directional copy paste isnt working ...definitely dont wanna sit n type each n every command myself coz its a revision for me
-# annoyed
any suggestions/solutions
Yes, use this trick
-o KexAlgorithms=curve25519-sha256
Oh , thanks
Hello guys
Hi
How are you doing
Regarding the "copyfail" kernel epxloit; if you've a kernel with the module built-in and cannot therefore prevent it loading, an alternative is kernel cmdline option initcall_blacklist=algif_aead_init to prevent the code being initialised at all.
I am getting a Lenovo Thinkpad t480 16 -500 is it a good choice in 222 dollars
just dont let someone on ur machine to run an LPE, simple as
for that price, its defo a good deal
What's lpe
local privilege escalation
Hmm
ellow

ello
whats up
ellow 🚼
Is old penetration testing books worth reading
yeah
Japanese hacker ?
no im not japanese
he is the computer
why are you asking people if theyre japanese
Then why blur
Little or comedian
mickhat the destroyer 😈😈😈😈
or
just a personal decision
I will prefer space
hi or
or hi
Or pablo
escobar
Did you watch his season
project for weeken.... i install windows
@iron galleon
awesome
What’s up?

anyone has try to create their own pentest ai agent ?
i want to
yeah i want to try it too
yes me too lol though i dont have lot of capacity in my laptop
local models are shit for that anyways --- needs frontier model
just use codex with gpt 5.5 and point it at things
its magic 
I have been playing with local models. Anything under 32B parameters simply can't analyze complex real world software at all, and that's the minimum below which you get only shit. At around 100B most common vulnerabilities are detected somewhat reliably. It's not as much about frontier models, but about the amount of parameters. The real issue there is likely the amount of attention heads which scales with parameter amount.
frontier can do blinded --- if i want to replicate that with local llm i'd probably have to spend half a house worth of compute 
If you can run the Deepseek V4 locally, which requires 800 gigabytes of VRAM, it will detect a lot of stuff reliably
imho for sec if one model detects 70% and the other detects 90% the one with 70% is not ok its plain useless
with things like coding its totally different
Yeah 70 % means you get so much noise it's hard to find the diamonds
no you miss things someone with a smarter thing would find --- which leaves doors open for people scanning with something better
could argue its even partially harmful cuz it gives you a false sense of security
how much would it cost to have a reliable one on clooud seems like that gonna be costly
Sure. 32B is like beginner. around 50-64B you have teh average code monkey that has been taught about specific vujlnerabilities. at round 100B you start finding novel stuff
the cheapest you can get are the openai pro and claude max plans because they are subsidized af
you get like 2k+++ worth inference for 200$ a month if you max them
yeah they are not billing the cost of using the service, not even near
(openai is more generous though and often resets limits so i'd personally recommend that but ymmv)
@umbral epoch sorcery is an amazing machine bro I admire it, crazy work
I've been playing mostly with Qwen. It's surprisingly capable model. But at under 32B it is just a moron. After that point it starts being actually useful in finding relatively simple vulnerabilities. And that's where my hardware limits are, sadly.
yeah i've sorta given up the hardware route also with how volatile everything is now
don't wanna throw a big chunk of money on sth that might be useless in a year
i'm really too broke to pay 200 a month
you get a fair deal with the 20$ subs aswell
me neither. I'd love to run some 100-200B model, but paying 10k euros for hardware to run that... ehhh
idt you get even good performance with 10
that also why i thought doing it locally so i could have it without paying anything but yeah
unless you have tiny context
the best options are several mac minis for apple's implementation and running in parallel, or the new AMD cpus with no GPU but lots of RAM and that shared with the neural accelerator. going GPU route is financial suicide.
or you page a lot but then performance is in gutter
in china they buy used RTX 2080 cards for 0-10 USD, and replace the memory chips to house 32-64 gigs, and flash the ROMs to support it... the processor being slow, but having lots of memory, fixing the primary bottleneck for llms. then they resell those modified cards...
I'd buy one instantly, but can't find one to buy from the western world
yeah ig cheapest is 2x m4 ultra 256 gb now ---- but 512gb vram doesn't let you run the more powerful open weight things aswell and thats already like 15k
in my experience going to optimized quant, for example int8 from fp16, hurts MUCH less than halving the parameter amount.
because for something like source code analysis the issue is the amount of attention heads, not as much the amount of parameters
analyzing a piece of actual software may require 32+ attention heads to track everything. a small model simply doesn't have that, and it becomes a bottle neck
I did some source code analysis and just to find something like sql injection from a code that is not a single function but split in several, and including several abstractino layers, instantly rquires 10-15 attention heads, or the amount of parameters and thinking doesn't really matter anymore, since things get lost
hmm i think the local models are really better suited for issues where you have a "smart enough" and not "as smart as possible"
I just wish I was an oligarch, I could invest in hardware I am 100% sure will be irrelevant in 3 years 
i mean --- who doesn't 
3 years may be even generous given how much vc money r&d in that area can gobble up rn 
Hello is there any hackers here ? Im looking to create a clan and work together for a project, dm me.
What's your specs
If you have any exp inside discord like making bots or creating webs dont be afraid to dm me!
I don't want to shave my head bald to join a clan 
qwen3.6 35B A3B runs alright on this 12GB vram 32GB ddr5 box
hello
probably even better with turboquant
tur🅱️o
I quanted with your mum last nite 
thats not how it works tho 
oh 
turboquant is some form of optimal quantisation of the models as far as I understood it
A quantitative analyst ("quant") in computer science uses advanced mathematics, statistics, and programming to analyze financial markets, price securities, and manage risk, primarily working in hedge funds, investment banks, and fintech firms. They develop algorithmic models for trading strategies and build high-performance software infrastructure, with key roles including Researchers, Traders, and Developers
reduces the need of vram by times 6
@native plume
I blame the Microsoft Excel 
Meanwhile me running a bunch of things in 4gigs of ran🏃♀️
LMAO so true I hate it 😭
just yet microslop defender quarantined my obsidian note as PHP Backdoor 
thats normal
I have 32 gigabytes of memory. just because I'm too lazy to install 48 gigabytes which I have on shelf 😄
always add your notes as an exception
if your av ISNT detecting your notes without an exception you have a shitty av or you have shitty notes lmao
Lmfao
Its actually hilarious a powershell 1 liner can disable AMSI but a literal note is flagged
Perhaps my expectations are too high for a 3 trillion dollar company
where
.
📍
Lion doesn't concern with opinions of [REDACTED]
opinions of a discord nitro user
Neetro 
Me
I'm afraid of looking a favorite gifs because a misclick can get me banned here
So it's a sussy gif? 🤨
Give me some of that >.>
Many
You speak spanish right?
My fav ragebait pic is not allowed anymore, last time I tried it was just blocked
😔
You're welcome to send it via DM
It'll be appreciated
send dm
plox
Yes, native jajs
wait echo ru white
Mm how scary xd
How did you know? >_>
like pale white
Azote, pfp
You're probably from spain
I get it. I also have intrusive thoughts about just posting my normal shitpost stuff 
hmmm i wonder if the gif will suite u
Must. Stay. Professional. ... Rellatively professional ...
Professional shitposter
@scenic maple I'm this white
I haven't raigbaited here for once. I used to have annoying people as an actual hobby. I was good at it. But here? Nah.
#9d8984
u cant ragebait monkee
u cant be ragebaited cause u follow monke
I was saving the lizard from the cats btw
guys do i send @iron galleon 's mum a hand written love letter
Naww very kind of you
I am serious, echoes!
Are they your cats?
Sometimes is too late
cats will eat him or he will die a mysterious death
Kind of
67
meowster mind
Ginger is the best
I just wanted "azote" but it was already taken 🙁
Second option sounds like a cat dictatorship ... I wonder what they use for a mysterious death?
damn I was thinking per week lol
I wanted echoesofwhoami but it was also taken...
@silk copper
Yeh cats don't need bathed unless they're like legit covered in something
catsofwhoami
Never
If he gets in some dirty stuff but my cat is very careful
does he go outside?
bro is a hunter
And walks away in the hood
wonder how many birds gone missing
Well we have birds bigger than my cat
real
oh wow, i have too much ocd for that so I probably can't own a cat
Cats are always clean somehow
is it low maintenance then?
Xdd
Pretty much
ofc u have to feed them and all
You set up one of these 
They cover their shit
You can have an automatic feeder
Refill it once a month
can't they shit in my toilet? 😭
Same with the water
They can be trained but they rater do it in the litterbox
idk what that is
ah yeah, makes sense. how often do you wash it out?
An automatic feeder 
A machine that stores and gives them rations of food
Thursday evening, beer and chili nuts
It's also automatic it cleans itself
just googled it
I wish I had one of those myself
My cats are always dirty hhaha
a litterbox??
I don't get it, how do u not wash the litterbox?
They are always fighting in the street
The litter absorvs the waste and the machine rotates sometimes filtering it, no bad smell or nothing
im traumatized
what else is there to do
bro got the cats from the hood 
Like once a month I disassemble and washa bit tho
@obtuse fern
Vs other cats xd
By what?
huh, I didn't know this at all. I thought you clean it once a week or smth
Automation is key
I might get a british breed
python script the litter box
i wonder whats going on rn
Where
in the dms
Nasty things




