#general
1 messages · Page 698 of 1
NOOOOO
let it live and release ut
We're starting a bug bounty program to look like we care about security. The plan is to screw over anyone who actually finds anything by calling every single report a "duplicate" so we don't have to pay them a dime.
it*
Just don’t submit dupes, ez
ITS A LIVING CREATURE
a living creature trying to end my life
I submitted a sensitive secret disclosure to atlassian through bug crowd, fairly high impact though it required a certain permission level to abuse
eat it for protien
@iron galleon be glad you don't live where I do lol
oof
SEE!! i knew i was right
why where
i need to improve the size of my tinfoil hat now
i thought ur pfp was a spider for a sec
Just part of the game, use the time waiting for bug 1 triage to find bugs 2,3,4 and 5
Az
oh hell no
are you high
why not now

7000 dollars notification
israeli baddies wya
noticing....
have yall seen that video of netanyahu playing with his toys
jetanyahu
No politics on gen chat
golam71 the destroyer
ZAP > burp
worst take i've seen in the last month
That's way worse than the politics discussion
What worst take did u see before lmao
you right we chill
me
Zap is unstable
It will not only lie to you but mislead you
I can fix her
Everyone knows burp suite is backdoored by James kettle to steal bugs. Hence why you only get DUPES
somebody once told me that AES-CBC is a vulnerability because you can MITM it
And their zap HUD has never worked once for me
i don't know what that means but yeah
Then use caido

So is https a vulnerabilitiy?
apparently kekw
Caido is only for non-professionals 
P1 for sure
Spoken like someone who has never submitted a P0
P5 > P1 cause 5 > 1
Don’t work on security technology folks
Fact.
5 > 1?
Yeah 5 is bigger than 1
No.
We can have difference of opinion
P5 are actually better than getting a bounty
Bounty -> subject to inflation
kudos points -> always worth the same amount
Ahhhh, feels so good to have finished 2 modules. Never knew I could learn so much from Windows and file transfers. And ironically I am kinda starting to like PowerShell from the few snippets the modules have 😂
i wonder what happened to all the people that used to watch teen titans
im here
hi also here
we're here
ok so raven or starfire
@turbid goblet hi
Oh lord my eyes
tf
"invite more goblins"
LOL
you're cooked sir
Holy hell that's to much chaos
LGTM 👍
My brain has an overload from this
let's go to mars?
Calm down there, Elon
Beat me to it
woah woah take that back
hi
Did anyone actually experience the goblins in GPT before they reduced the number of goblins?
🤨
it appears I'm missing important lore
Yeah 🤣
In a blog post on Thursday, the company said it spotted increased mentions of the mythological creatures, as well as gremlins, in metaphors used by ChatGPT and other tools powered by its latest flagship model, GPT-5.
After users and employees flagged problems being described as "little goblins", OpenAI said it took steps to mitigate the issue - including telling its coding agent Codex not to refer to them unless relevant.
It discovered that a "nerdy personality" it developed for ChatGPT had unwittingly been incentivised to reward goblin mentions.
What else don’t they want us to know 
Works as intended
When did you join a cult
it's particularly confusing when I ask it to describe something ad related
When the doctor pronounced "IT'S GINGER!!!!"
lol
It’s mildly concerning that I know two insane ginger cyber people now
Is the cult limited to being ginger or is it ginger cyber or is it ginger cyber and chaotic
We may not be born with a soul, and instead have to earn it, and are more mental than usual.. but the mix seems to work well
Intel or amd in a laptop
No soul so computer soul yesyes
I’m immediately forwarding this to my lady ginger best friend
Thank you for this bullying fuel
hahahaha
🤣
Heya grx
Bully ping @austere sinew
it's more of a mixed bag yk
Only known a couple of ginger women
@sturdy thistle no u
Yes I
One gave me a concussion by throwing a chair at my head in secondary school
LMAO WHAT
hey there ☁️
I called a girl the C word and she cried
The other one rocked out with me to Iron Maiden at Wacken
Then I lost her in the crowd!!!
Next year camp @eternal mango
I'd like that
U come this time?
Will have to see closer to the time
spicy redheads are the best😍
Life is chaos right now
Noooooo
August or so
oh my
that's hilarious
She made fun of the british accent earlier this is justice
fair game 
guys im debating if I have 6k hours on a video game do I put it on my resume
if its minecraft and ur not a pvper larper then yes
Depends on how good you are
its ARK survival evolved pvp
or if its osrs and u play the market
top world
oh
Good to go then
top virgin*
eSports cv
Better than bottom one
does it count then
whats wrong with bottoms
Yes
nothing wrong solider
They don't see the sky as clearly
I just feel like if its 6k hours they shouldn't go to waste yk
but than what would they think of me
Yeah if wasting time on something might as well be good at it
eSports player
words to live by
this is why I left one of my social circles
they dont believe in this sentence
I'll just leave it out they better not know
it's also true one can't be good at everything they have to invest time on, it's probably about picking your battles so to speak
So why do we waste time on hacking 
finally got my Intel core ultra 9 275 HX, 96 GB DDR 5 and rtx5090 Mobile
wait you guys are hacking?
get got
I find most people aren't as hard on themselves as people in this field
Only LARPing for me
you won't survive if you aren't its cold facts
same
job market too competitive to dilly daddle
So that we can be good at it 
true, I'm just saying most of the rest of the population doesn't seem to have to
yeah u right
its a lot of effort not fit for most
i do things even if i dont feel like doing it, i get the job done
you also got to have some passion for it not do it for the money
Passion gets you in money keeps you there
I'm only in it for the fun of it tbh
if you're not early, u are late!
Same kinda a break for me
alwaysz be there 10minutes early
Then as soon as you get in all you dream about is getting out and never looking at a computer
Olares
Caught u
Goose farmer
xD
is it really that stressful?
Congratulations
Yeah
It’s fun
R u talking bout me
Bald_golam
I started balding at the speed of sound when I turned 25 lmao
Bald at 30
pick the right tech for you and the stress won't be that bad i
I was grey at mid 20s
just a lot going on
I prefer the term “aerodynamic”
actually i already got an island on my head
Hey all my og hackers. Anyone got a good introduction into Pentesting with Windows. I finally have to touch this filth
But u have great hair 
doxxed
on the bright side you'll rarely have to deal with the gui
I hear academy is good
Imagine doing pentesting and have to click away ads for candy crush
kek
adblock 4 the win
only if the site admin is a goof
i cant live without adblock
you can get rid of those long before the first user ever logs in
This for sure, but I still rather want to do the pentesting than the administration. So I guess Acadamy is the way to go. Or Any introduction yt vids to recommend?
honestly https://ippsec.rocks is good but you won't find the structure of academy
Search utility for IppSec's YouTube videos
i already feel like a hacker when using protonvpn
As far as yt itself I only know "mattifestation"
This is not convincing me yet
xD
The Cyber Mentor has some good videos about some topics. Even Active Directory
ippsec will cure your problem just binge ez machines at start and take notes study deep
I am now his 263th viewer
That actually sounds like the best way to go! ❤️
Is Master considered a good rank in HTB?
meow
we all know u can fake ranks, but skill/experience u cant fake
ranks mean nothing there is writeups change my mind
i agree
@eternal mango man you are super in cybersecurity
thats why htb calls me noob
Bro I stopped cybersecurity I'm playing
xD
I wouldn't say super
Bro you are my hero
But I took actual notes and learned
u took notes writing with pen+paper or taking notes on pc
In PC obviously
Bro please really tired from cybersecurity and feel burnout I dont know when I will return
that doesnt work for me, i like writing it on paper so i remember better
Burnout sucks so hard
just study every topic deep take good notes and you will progress 10x faster
All you can do is try to move on slowly
..or disconnect entirely, or risk despising what you once loved
..and then return once rested and refreshed
Not always easy to do with that thing called life and rent of course
Sometimes we all need a reset
if u read a book for 5minutes a day, u can finish it within 1 year
what im trying to say is, constitency is important
what im trying to say is, consistency is important
Did u got it today?
no
Since when
Hackthebox is best course
i just copied ur text from the past to look cool
So u just faked it
yes im sorry i am a faky
Then bye
🙁
Kids these days
can i connect my discord with ur htb account to look cool
*skids
Yep
😄
Just to have an orange role that does absolutely nothing? 😭
yes so ppl think i am hacker but actually i am still at the linux modules
Well, it does, you get pic perms n shit
yes now its cli only for me
Go study
text only i mean
does guru get a guru-lounge
I don't know, do they?
yes they do
idk im not guru lol
It’s a secret
cool kids only
kamigold remember when i told u i got new job tech support
bottom soliders rule
yes
Hacker-lounge should be renamed to skid-free-zone
im still there its almost 4weeks now
but im there
Exactly.
Lol
Chat less, hack more
u are absolutely right !
Just get hacker rank and you can post images and access a secret chat
w0000t easter eggs
Go hack and stop larping
Though the new system will eliminate the old ranking system
Cert holders get a secret decoder ring
Whenever it gets implemented
my hacking skill is 99 and i got my skillCAPE
Still… there will likely be a cutoff for access to a chat for sensible folk
Yup
MarcieLee [HTB],
Role icon, HTB Seasons: Bronze
—
5:04 PM
Yup

tvsr
—
5:08 PM

sigh, go ask your mom to help with dinner or something
some moms already died
It's another troll that takes way too long to get banned

i already got banned like 5 times but came back
And welcome to my ignored list… 100% of people who end up there end up leaving the server
\
🙂 fixed
Admitting ban evasion is kinda crazy
Wait no
@alpine pumice @austere sigil
@snitch
Lol, these kids
i already got banned like 5 times with this account but came back after ban was over
Waste of air
Do mods usually look the chat anymore?
yo anyone remember Happy Wars on xbox
what is your goal wasting time on here
that shit was fire
There was a mod here 10 mins ago
It's a troll. They have no purpose. Block it.
lol
The red white and blue monster is very good
Im getting banned here?
No lol
Yeah dude
We r lurking
No it was shit
Made me laugh at the end
That's what she said 🙁
Hahahahaha
Blueberry cigarettes
I’m a patient person, and I yak quite a bit too… but seriously, that guy was being a little shit yesterday as well
I'm sure mods will do the needful
Look through their history. They never contribute. Trolling all the time
Been doing it for weeks
For weeks? Holy shit, he must be really bored then
(that is not a challenge)
Look I learned little like before yestrady learning process how to do reporting in pentesting it should be structed and organized and highlight syntax what u did for the system and using tools
Like fireshot
And treecherry
.. stops typing
@austere sinew giga hydro turbo ping
Sigh
You can have a little block, as a treat
The important thing is the audit
They are low calorie
Diet blocks
I miss my block list 
I have blocked 700 people in LinkedIn
You can still ban people on IRC today!
You should
It’s a ghost town
HTB should get an IRC going in case discord goes to shit
Irc days
Well the server where I used to hang is. irc.2600.net
@eternal mango
irssi my beloved
Good Ole mIRC days
I still use the mIRC font for everything
There's a modern version called fixedsys excelsior
Really ?
What?
A/s/l ?
I use it absolutely everywhere
You can't have one without the other
95/not anymore/anglish
And the old 18/F/UK U?
Ole the fun days lolol
Haha
Fuck man im old haha
Me too
Ask jeeves died yesterday
I remember gopher
Lol using Netscape as a browser
Yel
i thought u were trolling when u said this yesterday
Using pine to check email
sad times
Getting that 56k dial up speed son
Winsock
I never troll
jeeves was the first websever box i hacked
22400 I think was one I had in Uni
Hayes optima
No hints are allowed for the duration of the event. Once the event is over, feel free to share solutions.
Oh lort
I had a 400 baud vic modem, but I could not get it to work
sec how old are u
I had a 300!
Old lol
Can probably type faster than it can transmit
I understand that you are contacting us from a sanctioned region and experiencing a block on our services. I apologize for any inconvenience this may have caused. Please know that our company is committed to complying with all international laws and regulations, including sanctions. As a result, we must restrict access to our services in certain regions. We can't provide you with any assistance on this matter. Thank you for your understanding and cooperation.
Major unc status @turbid goblet

I wonder if I can still remember the model. It was a grey block
We are expericing heavy load on our Login Service, we are working on it and will update when we can. Please wait a few minutes and try again
Oh wow
Micronet 🧓
Compuserve
Jfc I member
Now I dont feel so old hahaha
80s?
I’m a child of the 70s
Same
Best decade to be born in around there.. we got to play outside until it was dark, and experience the explosion of tech
(and letdown of y2k)
Yeah
Yes
-#

It was “come home when the street lights come on”
Uncs, assemble!
Lol
Now, go outside and play
"It's 10pm - do you know where your children are?"
Drinking water from the hose lol
I have children?
When playing manhunt didn't involve an automatic rifle
It’s 3:30 and your kid is home alone
Sorry, poor taste
Heating up a swanson gourmet
Lol!!
Salisbury steak
I feel like chicken tonight
Lol
Still got my dads zx spectrum somewhere. Somehow none of the 312 Commodore 64's survived
I wish I still had one
You could grab them from boot fairs for 50p
"NOT ANOTHER ONE"
My first computer was a apple 2ec
First one at home I recall was one of those cube apples, will never forget the rainbow logo
Tons of games
and BBC Micro at primary
I started on an IBM 80286 with 20mb hard drive
All sorts of stuff from the BBS
Those were the days. Shareware
That leap from 286 to 486dx2 was mega
And playing LORD on a BBS
and don't tell me about the AMD K62!
Even 8-bit pr0n
where
Took up a whole floppy disk labelled “jane fonda”
for science
MUDs were so great
If you squinted just right, you could make out the details
That's the one! ❤️ Unsure on the model, but the shape is unforgettable.. and the rainbow like I said 😄
Those IBM keyboards
Dual purpose, as a weapon and an input device
Will never have the same thrill as picking up an Amiga magazine with £50,000 worth of software on it on loan from the library
..and then the let down when it was all crappy garden design software
oh man these old garbage boxes, i had one of those
gargantuan floppy disks
First game I remember was some spelling game with a train..
Back when floppies were floppy
boomers gonna boom you know
boom boom boom
reminiscing about the past
Yeah, not quite that old..
Anyone who had any form of programming skills back then were eating good
Oh my god Zork
funny that the train is named 1984 xD
it was a prophecy
The train straight into the future of big brother
Ok every message is making me feel older and older
I both do and don't like this
omg i just read what dysentery means xD
thats a horrible way to die
Space
does anyone use the framework desktop as a daily driver?
I'm just so sick of nvidia
use case: host amd 2 vms on at all times with gpu acceleration
MarcieLee does
Oh
No, not desktop
Laptop, nvm
gotcha, ty anyway
for some reason my brain registered that / as *
Were should I start at htb
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
watch ippsec vids for ez boxes https://www.youtube.com/@ippsec
but i wanna do the boxes
are you also a complete beginner kami
Man, I just went down a rabbit hole… trying to find the title of an old c64 game that I played
Describe it 😮
ChatGPT said it didn’t exist
pfft
But I found it
Wich vid would you recommend
Are you an 18 year old baby?
Don't remember that one
The music is the thing
start with the easy ones that have the highest ratings (got to htb and filter by easy and highest rating) and move up
I did find the collection of RPGs my primary school had though 😅 https://bbcmicro.co.uk/index.php?search=ESM+(Educational+Software+For+Microcomputers)&on_P=on
RPG compared to what that means today is a very loose definition haha
also take good notes and hack it yourself after you watch the video
..not sure what that last game listed is all about though.. Podd..
Okay im gonna try tomorrow
Ty
ure welcome feel free to ask questions in DM if u need help good luck
@mystic harbor
Youre looking for this person
Longplay from the C64 game "Master Of Magic"
This video is downloadable at Archive.org
http://www.archive.org/details/C64GVA247-MasterOfMagic
😄 cutting edge audio then
Sure was
True wizards
C64 had a great 4-voice sound card
Borrowed an Amiga 500 from the game / computer shop for a bit (free swapsies to lend my copy of Mortal Kombat for rent, as they'd run out)
Honestly then I didn't know what to do with it, apart from use demo disks with random software from magazines
lol, in my day the magazines came with pages of code in the back… you had to manually enter it in and save it to tape
yup yup
Compute!
Then next month’s issue would print the errata
Even if you meticulously typed in the code… it might not work
My dad made me an easel that would hold the mag open and it had a sliding ruler so I could keep track of what line i was on
I forgot all about that until just now…
i love the new tech of when people say something they learned and source is tiktok
Remember pulling these out the back of the RM thin clients at secondary for a laugh.. but just once..
Got such a bollocking
Guys will the old ranks on HTB Labs disappear?
First network I ever set up was coax
Oh gorsh flashbacks. Secondary school was not fun for the most part
1995… I worked for the local symphony and networked 4 computers together so we could share the printer
..but I made what I could fun 😄
I built their web site in notepad
😄
All tables baby
First website I did, I thought I was amazing, copying all the cheats from a cheat book and putting it into a website
What a boring task that was
Back when Patrick Moore was still the Games Master
FML this docker image pull has been on "almost there" for the past hour, I just wanna check it's done before I go to bed
Still pulling a couple of layers, just didn't expect them to be that big..
looks like two coax to bnc
Token ring network connector that was used in the IT lab at secondary yonks ago
If you pulled one out, it all shat the bed
guys first time seeing port 79 open and im using a tool called finger-user-enum
nice
bro I dont know why I like batman I have batman rang
Token-ring!
youve never fingered a port before?
thats a great protocol
Get consent
well with pentesting you should always have consent
nope just fingering users
Before you go fingering anything… consent is necessary
Finger goes all the way back to 1991 ||not just the things on our hands||
Yep
This memo describes the Finger user information protocol.This is a simple protocol which provides an interface to a remote user information program. [STANDARDS-TRACK]
Old school stuff is fun, I made a thing I call reverse phreaking it uses morse code over frequencies to issue shell commands
-# checks rules of engagement
Being sick sucks my throats killin me..to think i have to force myself to eat a dilicious steak 💀
I trust my intuition and pray
whats worst that can happen
need bro to finish the manga 😭
What manga?
berserk
this is my hero academia
Ohhh og berserk was amazing i never read the manga
original writer passed away and new guy taking forever to finish it
I bet..lots of pressure and u know it will get criticized either way
Id hate ending a dead guys story
Oh i didnt know about all of this or i forgot...well thats a diff story finishing t in his memory then
would recommend reading the manga tho if u enjoyed the anime and have time to kill
Ye i havent read any manga in so long berserk would be a solid one
a
a question for support
test
fail
for the last season there was 9 days between the release of the final box and the season rewards email
yeah test has failed lmao
test has failed successfully
still green tho
exactly
did y'all get a chance to check Linkin Park's new singer out?
S tier pick imo
also Poppy went metal, what a timeline lol
Got pulled pork and wheat pasta Mac and cheese for the next 3 days 🔥
each meal is 780 calories, 34 grams of protein, 30 grams of fat, and 74 grams carbs 🔥
I need to make my own pickled onions, they're amazing
Picked onion madras pizza.. sounds disgusting, no idea what came over us to try it (was like 20 years ago), but god damn it worked
Just.. don't eat it before an interview, or a date..
..or any sort of public interaction..
My node package supply chain monitor thingy just found keys that have access to a companies entire platform repos :/ I keep reporting them by email, but just get ignored
Should I automate and forget (as in automate the email notifications), or just forget
(only validated with a non-intrusive API call.. grey area, but if I caught it no doubt someone else will)
pickled vegetables work in a surprising amount of things because of the acidity, often a missing ingredient on pizza
hello guys is there are anyone here who worked as a pentester before i need to ask him about something
i have worked only as a pentaster but i can try
can i dm you if you dont mind?
i admire your humility
prepare for bait
i miss 2012
you can still watch it for $9.99 on your favorite platform ™
what does it say?
Remilia's Capricious Cooking
spray tan is cheaper
i'd say she cooks people based on the succubus look
Wasn't it like free comic book day on the 2nd?
could be wrong
i dunno
Well damn idk I kinda remember because Kevin Smith came up here awhile ago I saw comic book men he did a podcast about it.
Sweet looking find you got there.
still not done buying yet
Buy a bunch of spray paints and use an exact-o knife to make stencils of your favorite characters.
Become the
hood-honcho
anyone have any idea on a good way to start building your own ai ? like learning about the topic
LLM? Or just a.i in general?
LLM ig, kinda like an ai that u can use to js expand and do other things like if u prompt it and create an ai agency that performs tasks automaically, kinda like openclawed ig
Give your idea to something like gemini, tell it to break it down in as many small steps as it's needed, then ask it to design a prompt for each task. Get a trial sub for a paid ai, finish before the week. Profit
Well I'm not going to say I know much to waste your time. I imagine that openAI SDK might be a good start.
Okay, serious answer: 3blue1brown has some of the best educational content i'v ever seen. Some of it is about the math of LLMs
That could help.
okay ty, yeah i was considering claude AI, but im js tryna build my own personalized good ai ifkykwim
Ohh yeah the visual math guy.
Building your own model, as in something that is comparable to the open source or hosted models out there is a mammoth task. You're likely better off either diving in with a paid provider like GPT, Anthropic, Gemini etc and looking at the numerous orchestration projects out there, or if you want to go further and have the resources, taking an existing open source / weights model and fine tuning it. Both are not straight forward tasks if you're just getting in to the field. One has cost, but is efficient, while the other requires hardware able to host a capable enough model to achieve what you're looking to do, and then has the overhead of fine tuning it (as in creating your datasets or curating them from a combination of open source ones) to have it bend more towards your desired behaviour.
It's a massive field.. I'd honestly recommend the first option if you can pay for a subscription at any of the above providers, or can get away with what you can get from openrouter
There are many orchestration and workflow frameworks out there, and more popping up all the time
First thing you need to do is to tightly define what you want your AI to do
Then determine if you really need something custom
Out of interest how do you go about this. Do you just monitor X number of highly used packages?
Then presumably feed patches into some sort of pipeline
what would u say is the correct pathway if i wanted to create/use my own ai agency to perform tasks
(If you dont mind sharing ofc)
like ghost employees
npmjs provide a read only replica of their couchdb that backs the registry
You can poll that frequently for updates being pushed, then perform tasks to flag risks or behaviour that is abnormal on like, commit history, static analysis, secret discovery, github hook misconfigurations etc etc
Honestly very surprised the monitoring services out there are not doing what I'm doing already, and being proactive about it
You'd think there'd be a race to market honestly
It's such a simple problem to solve
is openclawed sum to look into, or maybe SDK, for building an ai agency that performs tasks based on instruction
I don't know why it's not been jumped on already
but I suppose that whole step of verifying is a grey area on permission
Its a harness iirc. Look into harness development if you're interested in that
But my thinking is.. if I can do it, bad actors are doing it
Yup I imagine so, even pre-AI just spamming trufflehog etc.
Nail. Head.
I use a number of other tools for static analysis etc too
But trufflehog yus

Many "verified" are false positives
mmm
But enough are valid to cause a lot of damage
Got a backlog of emails to send out now 
suffering from success
haha
I have the whole email authoring task automated
I just am concerned about actually pulling the trigger on sending them
Honestly though these are the problems that frustrate me quite a lot in the industry. Effective solutions are possible however I find it's more about "perceived value" than actual security
Emails don't contain any details, just an overview and a link back to a platform which requires verification by proving ownership of the linked repo through github oauth
Then you get full details after auth
You just reminded me of a hilarious phishing technique
A detailed guide to emulating advanced phishing attacks on GitHub for Red Team operations, leveraging fake issues and notifications to exploit a TOCTOU race condition, tricking developers into authorizing malicious OAuth apps for initial access while bypassing MFA and using only trusted infrastructure.
Here's the demo, just downloading it
That's funny
Dang haha
That is a neat way to do it
You're already playing on their "fixitfixitfixit"
We asked 100 married men what they wouldn't want their spouse to walk in on them playing.
Meet 'nd Fuck kingdom Steve!
"H'what!?
If they click it they'll likely just run through if they aren't paying attention
brb making a pipeline like yours, but every alert email has a 1/750 chance of being a malicious oauth
Evil and brilliant
"a fine line between malice and incompetence" 
I'll chuck a screen recording over another day if you want, it's nothing that special
But the numbers don't lie
there's a certain reason why there's such a difference
Sure :) Threat intel is an area I've been trying to read into, I think it's a very under-explored area
Been slowly building my own small pipeline in my free time
Just playing the data science game atm to figure out what I'd want to enrich, and how to standardise things properly etc.
ohshit its 5am. Gonna head to sleep but was good chatting as always 🐸
Get some sleep
(or dont)
haha I feel that
rickroll was uncalled for 😭 😭
Where is ricoroll

Gday
why do I know so many city names from the USA than from India 🫠
never been to USA 🫠
so goblin didn't sleep early
nice AI
Walking is healthy
Yes, but not where I live. If you wanna be alive.
Celsiusmaxxing
Tigers and snakes roam freely?
Lovely
+public holiday in the UK today
Got a load done over the night, so winning
- No footpath
- The road is uneven because, post-construction, they have not laid the road.
- Dust due to point 2.
- Chances of vehicles hitting you is high.
hi
Hi
will the new experience ranking things transfer to discord
PG-13 people
Yes, that too. Summer. Now it is 31 C
hopefully your new actor guy does better 
Yikes
if u are winning, sure
only if he wins
yeah, I think 117 is the mark
and survives long enough from assasination attempts.
currrently at 90 or something I believe
in TN? no way
he'd have to survive people worshipping him
do u think the other two parties who have been alternating their CM roles will give up so easily?
they been pulling that shit for more than 2 decades
I didnt know that lol
I am so ready for the weekend
a hung gov would be fun to watch in this case
but also more time consuming and icky in general

whatcha guys talking bout
politics
in my state
someone calculated this 🤣 🤣
your state is doing better than kerala for sure lol
wikipedia has all shit
I’m confused about number 5
he's christian, hence the name
what is the confusion?
The name
^
I want me some Indian food
paneer butter masala
Something that tastes of something
I have no idea why his father decided to name him after the soviet leader
🤷♂️
So your project deals with heuristics of what's deemed bad right? How do you verify this?
Is this a heftier project with using supply chain LLM
thats a rare case though. with those kind of names, its almost always because they're christians
Weird but ok
No LLM involved. It's all metrics and trends from observed historic behaviour.
I can't verify anything for certain, I can only use the metrics to come to a figure representative of what I think constitutes a risk
That's what I imagined
Well done
https://www.snnewswatch.com/amp/local-news/mto-says-highway-11-concerns-are-being-addressed-12096739
I did not
Fun little project, but I wanted to take it further with more in depth analysis, testing diffs from previous to current commit, but pulling down all those repos when many are large set the machine it was running on on fire
as in, stopped responding until I hard reset it lol
Doable, but not right now
thanks for ensuring that the concerns are being addressed, MTO
No problem
It's a really cool project. I'm curious on how to fine tune it. See where common pitfalls would appear. There's gotta be nuances such as vendor specific keys or findings from incidents.
refining the heuristics has to be the most valuable thing about it.
The secret detection is straight forward enough
I did have a workflow to analyse diffs through an LLM to highlight any concerning changes
But yeah, I ditched the git fetch and diff mechanism as resolving that many git repos async just was hell, and not all have git repos
But I've another option I'm working on
Due to the volume the review step was going through a locally hosted model, otherwise I'd burn all my credits in a day 🤣
LMAO
Gemma 4 was working pretty well, but I've not worked on that side of inspection for a bit
Got a plan as I said 😄
Did something similar ages ago with the WordPress plugin / theme ecosystem
Got a load of findings / CVEs / etc by implementing similar methodology
Didn't have the tooling available now that makes detecting sensitive data as easy as a command though, so it wasn't quite as complete
I feel like this would be some sort of tabular classification problem.
you'd have to have it vote on the actual risk that's involved. hmmm even if it wasn't used for cyber it could be used for different types of trackers.
It's more than that, and I've helped ensure a number of packages secure leaked secrets that would've allowed for any bad actor to publish a version with whatever changes they wanted
along with securing github accounts, cloud infra, amongst others
It's simple, sure
but the combination of all the simple things seems to have resulted in something useful
If it's finding this much, obviously nobody else with good intent is doing it to this extent yet
..which means those with ill intent probably are
imho
It's wild the impact it can have on the world.
My whole stance on it from an objective point of view is how the hell do you "rice" tf outta this. SSC attacks have humongous impacts because you disrupt the whole supply chain. In my opinion it's about data ingestion and classification. I think it's a really good idea for risk assessment from a defensive posture.
idk the first thing that caught my eye was random forest classification. I feel like the toolset and classification gives you enough of an operational playbook for kinda anything. My personal use case would just be looking at geopolitical events and seeing how it can relate to certain stocks or indices.
that gas station Zaza and loud pack 
good night everybody
Good night
vmware 
neither, containers and kubevirt 🔥

for what purpose
Malware analysis
nah WSL too good 

@warped timber You here? Your one box (CCTV) has an unintended solution that may need to be patched 🙂
any.run is good for that, if you need something for reverse engineering just don't analyze malware on the same OS it targets
Like don't analyze windows malware on windows.
I'd agree but changing extensions on file names literally solves the problem
Fr fr
unless you hit run in ida
then it's on you lol
then again you can remove it from the toolbar
I've been forcing myself to use radare2 for reversing lol
Yo
Just for the elitism of "no I don't use a GUI" 
Sup
it's ok we don't kink shame here, even if you like pain like that
Hru yall
Radare2 is good for scripting and the ollama stuff is neat
I don't doubt it. Just making a dumb joke lel
yeah but the type system is genuinely ass
binja handles custom type definitions way better imo
and it's 1/10 the price
But I just don’t wanna pay at all
I had issues getting rev shell
who says I'm paying
Why learn to reverse if I gotta pay for the reversing software
I didn’t say that
No one saying anything and that’s all I’m gonna say

ida free, ghidra, cutter-re and binja cloud all work well enough for x86 tbh
Womp womp
I NEEEEEED that x64 baby
I don’t believe in x86
X64 and ARM and that’s it
RISC and MIPS aren’t real
I want my architecture to be named fuckshit
And I want it to do everything you wish assembly did
Using the free version of ida to crack ida pro
I want invincible VS

