#general
1 messages Β· Page 724 of 1
I mean for people who cannot afford api key then here it is:
Here is gemini api key:
URL: https://deck-munchkin-giddily.ngrok-free.dev/v1
API: AIzaSyNova1234567890AlphaBetaGammaDelta
im helping my community
Yoink
as wel as esc queries:
ESC_QUERIES = {
"ESC1 β Enrollee Supplies Subject + Client Auth": esc1_vulnerable,
"ESC2 β No EKU + Enrollee Supplies Subject": esc2_vulnerable,
"ESC3 β Enrollment Agent + Enrollee Supplies Subject": esc3_vulnerable,
"ESC4 β WritePKI Flags": esc4_vulnerable,
"ESC5 β Overly Permissive CA Access": esc5_vulnerable,
"ESC6 β CA with SAN Editing Enabled": esc6_vulnerable,
"ESC7 β ManageCA / ManageCertificates": esc7_vulnerable,
"ESC9 β No security extension + Auth EKU": esc9_vulnerable,
"ESC10 β Weak Certificate Mapping": esc10_vulnerable,
"ESC11 β CA with Request Extension": esc11_vulnerable,
"ESC13 β OID GroupβLinking Abuse": esc13_vulnerable,
"ESC15 β Application Policy Abuse": esc15_vulnerable,
}
I mean I could just not verify my cert
nice
Another yoink
You can easily search for misconfigurations
scam
Fair enough, get it soon
Then you can be back to shitposting from job
Certs > other roles
Is it just me or recent bloodhound update gives a lot of errors in terminal and is very slow?
wow thats crazy. did you try it?
Never used BH in console. What's this then?
It needs to establish the C2 agent and stuff and yeah takes time
Nice
@rough mirage
Sigh
Thanks
app-db-1 | 2026-05-12 16:29:29.857 UTC [2433] ERROR: type "nodecomposite" does not exist
app-db-1 | 2026-05-12 16:29:29.857 UTC [2433] STATEMENT: select $1::text::regtype::oid;
I meant a lot of these
Hey, don't share fucking API keys in a public chat..
nah, im just being annoying 
Its regular BH but I am looking at the console log
but im assuming it is
Ohh. I gotcha
no such thing as a free lunch
Don't interact with urls you don't recognize
don't tell me what to do
I run gemma model on my H100 gpus for free and im not paying a penny on it. So I want to share the api that I created
whats wrong with that?
i need to get to the hacker role
yall dont deserve to be nice to
π
one day...
Why
just take like two weeks and do all the easy and then start going through mediums
not too hard
The entire concept of a Trojan
Just ignored
Honey pot
man 2 weeks? that's time wasted not listening to tung tung tung sahur ai brainrot phonk
π«΅
fuck you for real
I hate you made me read that
Well yeah, why would he interact with you calling out the scam? 
Stop saying cyber security buzz words noob(s)
My bloodhound is eating memory and cpu wtf
yall can test it on website likes https://www.aiapicheck.com/ if you dont trust me
A developer tool for testing whether different AI provider APIs work correctly
oh im sorry mb π π
that's the point hehe
how many easies do you need? because i've been trying to get that back
@frail turtle so this is how the TUI Graph and Tree format looks like
opens and loads everything instantly , no extrac setup required
these are few days old pics tho , newer ones also include ACEs with details
all of them plus some
you can use the api key online if yall want, no need to connect it to your computer
What API key?
Bro wants to farm your usage, to train his model.
lol
@west venture
my bad, stupid question. let me rephrase that, how many roots do you need nowadays?
Oh thanks
Or he is just waiting for people to give him blackmail/sensitive material
all of the easy machines plus I think I got user on like three mediums last season
bro your just being wierd as hell
but not while they were the seasonal active machine
yes thugnasty
Zeeshan!
How much money do you have? Bc I might run an AI agent on that key for hours
brain rot can be fun at times
go ahead, and you can check it on https://www.aiapicheck.com/ if you think it wont work
A developer tool for testing whether different AI provider APIs work correctly
Now we just chatting about crimes
I use gemini cli for free and it eats up tokens. I use claude code for free using a localhost proxy
You literally said you were, in this chat, just a few days back 
i'd never commit a crime
well that leaves me with a weekend's worth of fun
you know how it be
ANTHROPIC_AUTH_TOKEN="freecc" ANTHROPIC_BASE_URL="http://localhost:8082" claude
π€·ββοΈ
Probably a stolen API key, too
qwen/qwen3-coder-480b-a35b-instruct I use this model
thx for the help @dusky jacinth
It's pretty badass
Keep it topped up
good advice
thank you man β€οΈ
how do i stop interacting with myself?
How don't I know when their moron
first you said it's a trojan and then you said it's stolen. Please stop lying on my tounge man
mirror
idk what that is
u think
He knows I'm rage baiting him like crazy with that one
what u are saying is a bit sus thi
tho*
No one can lie on your tongue
and frankly I don't want to
I'm not gay
you sound weak
Yall dont need to install an .exe file lol you can just connect that api key on the web if yall want
Literally just about to pull that one out π
If something looks too good to be true (= free), it most probably isn't true or isn't good 
There's nothing wrong with being gay
Fuckin idiots lmao
There is something wrong with being a name-calling rude person though
Same people who genuinely believe MacOS malware doesn't occur
it doesn't that's a myth
notavirus.bat
I'm literally working a case where curl executed maliciously due to the user executing it. Clickfix spread to MacOS a few months ago.
Y'all ain't safe nowhere.
Open/Free/Net BSDs are awesome
Hey guys, I have 10.000$ for free, which of your bank accounts should I transfer this to? (/j)
mine
MEMEMEMEME
Scammers are fun
i was first tien
heelo
Feed a hungry homeless person with your $10
I actually replied
convert it to BTC HAHAHAHAAH
That's a good use
bitcoin dropped a dollar today π
It dropped by 2k in the past day
And rise #10 tommorrow
most likely yup
Okay, just give me your bank account and I will launder ... ehm I mean gift you the money
send to me in crypto hahahahaa
Good scammers a fucking menace, its awesome
Listened to a talk about north korean deep fake scams, was pretty cool
The curl thing sounds absolutely wild
If you wanna launder money, start a carwash
gotta launder my karma
Got a revolution behind my eyes
We got to get up and organize
Come on baby tell me
Yes we aim to please
I have learned about networks: TCP, UDP, IP, MAC, DCHP, DNS, router, NAT, LAN, switch, and layers. Should I delve deeper into networks or move on to Kali Linux commands?
Why a carwash? lol
Why did you say it twice?
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
Also you can do whatever you want!
I have learned about networks: TCP, UDP, IP, MAC, DCHP, DNS, router, NAT, LAN, switch, and layers. Should I delve deeper into networks or move on to Kali Linux commands?
I think he is stuck in a loop 
Quantum Loop
?
loneliness
i made friends inside computers
you mean friends online right ?
I do hope you don't have little people inside your pc
We don't talk about the motherboard dwarves here
they were inside computers and then inside my head
isnt that a boomer reference
Too bad Jared Leto is an industry plant fuck
The only saving grace of Tron ares is the visuals and the soundtrack by nine inch nails
not daft punk ; not listening to it
I've learned about IP, MAC, DNS, DCHP, TCP, UDP, NAT, LAN, and OSI. Should I learn Kali Linux commands or delve deeper into networking?
My friends, why aren't you answering my questions?
Hey
We're real people and we're not a fucking search engine
You can't just pop in questions and get answers immediately
This is an incomplete knowledge set
We already answered you broski
You've just learned a couple acronyms. That's not the same as understanding the technologies and how they work
β
π
But someone has to wash his car with the money then π€
DCHP 
You can do whatever you want pal. Play around with Routing Protocols like OSPF or BGP ...
Or learn hacking lol
Doesn't matter
Okay this meme looks too aggressive but I hope you get the spirit 
it's a troll or bot lol
How do you know?
Their server tag
Oh π Well my OSINT skills again 
I'm a detective for a living lmao
You detect what?
but can you see why kids love cinnamon toast crunch?
Malicious intent
What is this soutcery
Detective Cloudeau
I just spent an hour writing up a full timeline for a user getting clickfixed
Well, I shouldn't say I spent the whole hour writing
Half of that was me trying to get their damn domain controller to respond lmao
Hello everyone, I am new to hacking and looking for someone who can help me with that, preferably in Dutch.
Hallo, this is English focused server unfortunately
But there's lots of folks from around your area too π
Hello everyone, I am new to hacking and looking for someone who can help me with that, preferably in spain
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
I know that and I can speak English too, but is there anyone from the Netherlands who can send me a private message so we can talk a bit more?
or in inglish
You might have better luck in #1318239802931286066 just be sure to follow the guidelines for posts there
OkΓ© thx
hello
Good morning
Could you write me privately I need help I'm new
Why
@trail prism read this on getting started
okey
bro is gonna get pinged
if you can teach me a little
and there it is
Can someone explain this to me #red-team message
okey
I wish I had an answer but I also want to know the answer bc. this is a good question
arp/routing table - ezpz
Yeah because I guess this is a real world scenario, because their is a lot of vlan configuration in enterprises
Pretty sure the pivoting module covers this.
Yeah but arp is only for same network, and why routing table? If you have a gateway who tells you it is to access other vlans and even if it is the case if you always do a ping sweep on the entire network it take a while no?
Nope ^^ it talk about multi nic interfaces nothing about vlan
VLAN is transparent to you, on the network. You can only infer by what you can reach out to.
Idk anything about network engineering tbh
hi
Hi
What do you mean with that? Take a look at the architecture https://cdn.discordapp.com/attachments/704070821496487956/1503795575408037948/content.png?ex=6a04a644&is=6a0354c4&hm=880c3ddb5151fc62b7fcfa52b7d544d64b6a060d1ec9c06c554a2f6cc4c695eb&
hows it going ceald
The orchestration layer
Same old same old. Parents yelling at about how I'm not trying hard enough to apply for a job
Oh
Kubernetes???!!
Rich kid
just apply
It's a meme now.
I guess you can just scan the whole subnet to find live targets
i cant sleep for some reason
i shouldnt have slept in the afternoon
I'm just rendering his image
i regret it now
Yeah but it take a whileπ
AI CEOs.
Interview with a AI CEO vs AI Engineer with Josh Doe and Jackson Jineer - aired on Β© The AI.
Programmer humor
programmer jokes
AI humor
Next gen AI
Cloud Computing
AI news
Oracle ceo news
AI Layoffs
Tech industry
AI progress
Work humor
Manager talk
GPT5
software development
β¦
I deployed my first application cluster to ECS using a proper CI/CD pipeline today 
Well, that's a bit aggressive. ARP for the start, pings if need be.
The thing is I need an idea to get a hint that their is potential vlan routing
You just need to know the subnets though. I guess if you don't see active connections you have to "brute force" it with Nmap?
Well i can't really think of any easier way?
And as rat said arp, but I was assuming if for whatever reasons that doesn't work
Yeah I guess to that it kind of luck by discovering them
Omg this reminds me of someone that kept calling bash the cli and it drove me insane cause I had no idea what he was talking about when he kept saying "the cli"
It's transparent at your level of the model.
Who's lol
THE ICE CREAM VAN IS HERE
Spritzou
But again arp is for the same network
"The CLI"
If you arp on 10.5.30.0/24 you will see potential hosts on this network not on those like 10.5.20.0/24
The dude supposedly worked as a networking engineer, not sure what networks he engineered but very worried
I donβt really understand why you mean haha what do you mean with transparent at my model
Yeah i don't really know too much about it
I have made some labs with multiple vlans and shit
So from top view
All i can think of the options we have discussed
Actually I'll look for it tomorrow, I have been mindlessly making huge labs and not thinking about these stuff lmao
Btw I made a note these days for a nice alternative for Nmap if you just want to discover hosts, fping. It's just ping but also works with whole networks
VLANs are layer 2. You're at layer 3.
Maybe try accessing the router and hope it's not locked?
Then try to find switch and hope that's not locked too then show all interfaces π
Ah like this, but I need to take a look at the lab then because since their is only 1 host on vlan 30 (kali) he donβt make connections with other vlans manually
Guys, vlans aren't real! Flat networks forever to confuse attackers π₯
I will take a look at my lab in the evening and keep you guys up to date with a witeshark check
So I guess intercept traffic and wait
Well, you could check the routing table.
It might point you to other networks
Who needs micro segmentation if you can just throw everything into 10.0.0.0/8?
Routing says:
default via 10.5.30.254
I mean Iβm not in front of my lab but nothing about the other networks
I unironically manage a network like that at the cyber range
Very big us vs them mentality and "everything is there for a reason" without any good reasoning
This is why responder will never stop being useful
may i present to you
Who configures routing tables manually on machines though?
We have servers that are older than me there just for the novelty of having them 
Depends on the machine, and if there is some specific reason something should normally not be in a specific place.
Yeah I asked clanker
And it said the same
You'll have to ping and find in other L2 network
π
Or make it worse and keep each device in its own cozy vlan with just itself
Someone said they got ice cream van nearby
Was it you
Stacked VLANs, all the way down
Micro(managed) segmentation lmao
b1issfu1
Yeah but like I told to my colleague what if the target has icmp disabled
We can hop soo many time
We should use all of those ttl
I got a new Windows CVE published today
On the same subnet, that doesn't necessarily matter, depending on how they reply.
Wifi proximity RCE
Yeah the place i work has this
Then you just have to hope that all of those pc has atleast one common port open lmao
But like I said I will take a look this evening and ping you @jagged storm @devout sail @high cobalt in red team group
I think there is no way around port scanning then ...
Yep, goodluck

Oh njce
Why do u not post any x post or blogs yet
the cve just published today and I got the blog post ready to post
Where
I think i follow u on twiffer
there's a reason I don't touch Windows 
Exploitability isnt easy but easy to DoS
I can walk outside your house and knock all the devices off on your street
using windows
if i spend the extra time, pop RCE
π
Ehehe do it when u see some kid playing LOL of something
Evil
I can make it targeted or just spam every wifi in range
Where are u gonna post your stuff
I'll keep an eye on it
we'll see
Hmm pls not on OF
I mean Linux got a 0-Day LPE every week so ...
thts a bit of an exaggeration dude
linux getting hit with the AI train atm
every week
LPE != RCE
reasonably talking, every single system has LPE somewhere
So many linux/windows LPEs now that 0day brokers are rejecting them
yep lol
What if we got an RCE this friday though?!
Glad I'm taking my break
Just saying
that is sick, congrats!
ZDI stopped taking pwn2own entries
Soon we will have 0day HTB solves like it's as normal as unintended
yeah, I also saw some other brokers tweeting about the flood of LPEs
next box idea, target Integrity with nothing listening on network 
i tried to get cluade to find this wifi bug i had and it wasnt finding it
after I had found it
I just wanted to see if it would even
"Nah bro looks clean to me!"
Imagine if they release one completely updated machine as insane and watch player interaction for 0day
I know ... I am exaggerating 
Nice
Oooooh you wanna play Inscryption and Ultrakill :3
kernelCTF is all about finding 0day
I havent played any games :(
If you wanna see CTF players exploiting zero days ...https://youtu.be/yrCXamnX9No?is=RLa2s6-MozgwqtAl
In this video we perform a code audit of Api6 and discover a default configuration that can be escalated to remote code execution.
CVE-2022-24112: https://seclists.org/oss-sec/2022/q1/133
GitLab: https://liveoverflow.com/gitlab-11-4-7-remote-code-execution-real-world-ctf-2018/
Challenge files: https://github.com/chaitin/Real-World-CTF-4th-Chal...
Dude, you need to change that
love kernelCTF then
need to get a new laptop first with a graphics card that would actually support games lol
sometime next month

Dude stop teasing us this much!
Deauth is to help groom
What? Another windows 0day??
Grass is green, sky is blue, Frost gets a 0 day or two
bro is preparing his repos before releasing it xd

and the TeamPCP released open source code for Mini Shai-Hulud, wtf is going on today
hey
yeah and one more there
soon
Fuck patch Tuesday ig
uh oh
how do i fix when i wanna download smth and itβs higher than my ios how do i download older versions
thank yβall
Thank god I am not a Windows admin but because I am still an admin and have responsibilities ... OH COME ON MAN
they really leveled up didn't they use to make shitty shell scripts to install xmrig or something or am I confusing them with someone else
dependency issues
wdym
they're using AI, so they're learning how to use it xd
he had the yellow one also
bypass bitlocker
I should just post my pocs to github
amirite
how do i fix when i wanna download smth and itβs higher than my ios how do i download older versions
..
yep
No need to repeat yourself @gusty saddle
I meant you can't unless it matches required dependencies
#1024429874246590575 might be better to ask
the libraries won't write themselves
personally I prefer developing stuff that can not be patched
again not going to spoil
and what are they please
Get more clout by uploading poc than get paid $1k for a 0 click RCE or LPE 
ok
1k?? lmao
are you serious?
I actually got 5k for my RCE
Holy shit
damn
no wonder people are just posting shit on github
Doesn't sound like that much for probably a ton amount of work tbh
if someone took my poc and walked around a hospital ,they could knock off devices
or if they work on it, get a RCE and pop on all devices in area
It's extremely low
One reason I actually didnt want to post the PoC until people patch lmao
severe implications
Yeah
hey
please can someone help with my problem
how do i fix when i wanna download smth and itβs higher than my ios how do i download older versions
Is there an archive of the app you're trying to install?
i dont think u can using apple's ios app store
archive?
had real tacos for lunch
u'd prolly have to jailbreak
Yeah like an archive of older versions?
like "street tacos" or as they call them in Mexico "tacos"
youtube
i wanna install yt and spotify
why don't you update ios
he probably needs to jailbreak but it's so unsecure
where can i get them archives
why don't you go to the website?
iphone 7 π
ah rip
I use Iphone SE
what website
my office TV spotify app is being weird
YouTube
SE is aiit
research jailbreaking, that's the only way because App Store apps are officially signed by the Apple
i donβt wanna use them on web
you could also, you know, not use an iphone
jailbreaking ?
google it
aiit
Doesn't android also want to lock down side loading though?
π€¦ββοΈπ€¦ββοΈπ
can use grapheneos
can't stop it.
Be advised that Google is stopping services for people who do this
Googles recaptcha now uses whether or not your mobile device is running the Google play service
ok
How so? I think they want to enforce so that APKs need to be signed or simething
Urgh, another day where greedy companies enforce their policies onto the user and don't make us own our software and hardware ...
Technically, Google could completely block sideloading if they wanted to, but they don't because Androidβs identity, market position, and architectural roots are built entirely on allowing it. Sideloading isn't a loophole they forgot to patch; itβs a core design feature.
The reasons Android hasn't flat-out banned sideloading come down to open-source foundations, corporate utility, and legal self-defense.
u can run a sandboxed google play services
i just read the article
thats why it still works for me
Oh, okay I just read the article ... seems like the headlines were just a bit doomsdaying again
just found an api endpoint on a shitty claude airdrop site, and the tweet has 4k+ likes, oh god..
I mean
I only use my phone to talk to people mostly and watch youtube videos
that's it
dont see the point in degoogleing unless....
I want more battery life
fuck I feel a fever coming
It might be a tumor
that'c
The torment nexus we built is tormenting users 
π»
Does anyone know How to participate in private CTF events?
you need an invite and you need to be invited
once those 2 are done and you have signed up you will get an email
Yes, but some descriptions say you just need to contact the event host to get the key
that is the invite
the event host is usually supposed to send the key/invite to the people who are supposed to be in the ctf
in a scenario where that isnt the case the people who are supposed to be sent the key just go and ask the host for the invite
lets say ABC school creates a ctf for its student so the teacher of that school is supposed to giveout the invites one per student
if the teacher does not that the students may be asked to reach out to their teacher and get a key
But where? For example, in the PepsiCo event section, the host creator is a redirect to their website, and theres no information there about the ctf event. The same thing happens at hunter cyber collector 2026, city of Newcastle.
if it does redirect to a site and you think you should have received an invite you should find contact information / support information on that site and ask for your invite,
or the CTF is to bypass the invite authentication 
man old htb was something else
Xd
Thanks im going to do it
now da graph looks neat af @worthy cargo
u can mode da nodes around as u like as well , ACEs Included for each nodes with details
u can search nodes with realtime indexing, Find shortest path between two nodes and render node amounts accordingly to save performance as well
Very nice and impressive!
sup chat
Gotta go make pasta in a bit. Not much
this is so real
Are you making a Bloodhound alternative?
kinda but its a full toolkit not just bloodhound features , graph is just one of the features
What does your tool add?
Hello all
https://github.com/Karmanya03/Overthrone
a lot of things , hard for me to type here xP
@rancid swallow hiii
Niiice, sound fun (and like a lot of work haha) developing it.
ya been 7 months so far , i still have so much to test and debug a lot of things and create a PoC so that i can release it properly
Damn, the longest side project I did was building a simple raycasting engine and then rebuilding it in Rust π


don't mind if slap a nice little git star on that one
Arigatou
It was just a really simple demo built with Raylib π was maybe working on it for a week or so in my vacation time
its been exactly around 1 year, my GPU is ded , So after office hrs i just do this , coz me bored , nothing to do
otherwise would either do game dev stuff or just play sum games with friends
Err... No.
Did you try to bake it
My condolences on the dead gpu π
no oven sedly lol
It looks like something out of one of those old hacking games on steam where you buy computer parts and install them in the data centre to get the leet skills
Laptop GPU btw
This is the HTB Academy
i had the motherboard replacement but the replacement was the only one remaining piece in my region and SOMEHOW i found out it has a Defected GPU hardware with Code43
Well clearly they weren't supposed to tell newbies about the secret internet that you didn't hear about, and this conversation never happened...
I don't think it's possible, the question was ironic
It's it a newer module? This seems like the kind of mistake AI would make
Nah, it's pretty old actually
Network Foundations Section 6 / 12
Nobody reported it I guess 
Any comment about it in #1234357888114364508 ?

I helped fix an issue with the cdsa content when I was doing my exam
One of the questions for one of the modules was completely unrelated to the content it just showed you lmao
Nah, modules for the cdsa path
Ah
The exam had no issues
At least HTB has fewer typos than LetsDefend xD
You know they bought them right lol
I knew it, it looks so unrelated to HTB 
It was a recent ish acquisition
Oh, they bought it? Gonna absorb like the last one did?
Slorp
Yeah HTB is buying up all the cool toys. Vulnlab too getting integrated
I wish their modules were just im the normal HTB academy ...
I can't tell if this is tbone or ribs
HTB needs to buy maldev academy
Very nice! Had similar earlier
If only
Chicken
You know what the /feedback thing is for...
Choron chicken I think it is
eating chicken ribs is wild



Always
What is that
"Happening" refers to an occurrence, event, or an artistic performance involving audience participation
hello
That's funny, you are funny guy
I like you
No, just chatting without purpose and now preparing for sleep 
Thank you, I like you too

Roses are red, I am back, there's a flipper zero right here in my bag. 
do you get any benefits for boosting server
other than aura
what does that mean
can you pay for my cpts
That means you get a lot of features.
like?
Try to send a GIF
exam voucher
nuh uh ive been laughed at
Ive played these games before
















No. Fuck off.
yea I couldve guessed
grrr
Pfff, just level up for sending Gifs
I did on my personal account but this is a new account and I dont wannd do the same labs twice
















mine?
yes
ah thanks
(Just joking)
It looks funky on my phone.
And now it's a billboard ad.
yea here you just look autistic
Yeah I also wanted to say the mention looks even funnier π
oh
in a good way
you are that youtuber who talks about how to RAT people
I am autistic, tf you mean just look?
May ur dreams project in 8k w dolby ur wildest hopes
I've seen your videos
Haha lmao, thank you π
AI text gen is too slow. We need thousands of tokens per second speed!
500 ai generators.
What?
π
:pp
Can't they just scale the models horizontally bruh?
It's not just pee, it's "The great release"
God The Orville was such a nice homage to Star Trek
cool!!!
It's time for American Dad to do a sci fi special... or something...
I never watched american dad. Just Family Guy
Family guy writing falls off hard around season 9/10
American dad is consistently pretty funny
They don't just say shocking gross things or just hate each other or show gore for humor
Okay this is pretty funny
Still, the animated show which has a special place in my heart is the Simpsons
Same, watched it every night with the family for dinner
The Jalojha

Yeah it's perfect for dinner. Just watching it in the background haha
I have a couple animated shows I put on in the background while I'm working
Lol, nah at work this would just distract me
Like dora the explorer?
Oh
But what shows are you talking about?
Doing the drywall at the new McDonald's gotta wake my ass up at 6am
have you tried not sleeping at McDonalds?
In this economy?!
fuck economy
It's a quote from office space from rats gif
capitalist emperors are sucking bloods
dang, nightmare eclipse dropping more bombs. another windows privesc and a bitlocker bypass.
like look at this, a magnet flying on the air
I used to buy these from street markets
no it's from 2023
but it's total distraction xD
somone needs to make some money on kalshi and plantir
Archer, Bob's Burgers, Brooklyn 99, Reno 911, Solar Opposites
comforting people is really hard when you're so emotionally detached
Oh Solar Opposites is from Rick and Morty creators ... now I wanna watch it, too
Hello
How can I get the CDSA certification label?
I just feel awkward in these situations, you too?
same
idk what to do gng
Good question, sadly I have no answer to this
get the certification
if you have it then just /verify-certification
yoh how do yall deal with the slow pings shiih has me on edge nd i want beautiful colours quick
What beautiful colors?
1435 ms
I mean yeah it's tough, but like I just deal with it
Now I have two tabs, one for details, and one for explore relationships and impacket commands.
i want every single role on me
ill surpass you son
ffuf runs better on Ubuntu than in a Kali VM lmao
I'm using it for web fuzzing and it works much better
I'm serious
bruh that's just host vs guest os
ya I know
so on host OS it works better?
I didn't know that
why not just install the tools on Ubuntu and use that
What do you mean by 'better'?
I mean your guest OS doesn't have as many resources on it
so like it simply cannot perform at the same capacity
It depends on your hardware too
yeah
First what is better?
^^
Thx
What do you mean by better?
like just faster?
the same command runs on ubuntu and not kali, its faster. I mean it runs sometimes on kali but there's not as much troubleshooting as with a VM.
I mean is there anything wrong with me using my host OS for hack the box?
I have a pretty powerful system, so for me kali vm runs just fine.
what is the downside to using a host OS for hacking? I have excellent hardware (ubuntu with KDE installed on it) and like I actually think I prefer it
Not really no, but you'd just have to set all your tools on your up hardware. It's not always recommended, but you do you
Nothing wrong with it but if you connect a VPN to your host system, you open yourself up to possibility of attack from another nefarious user maybe?
I'm not doing that
I mean will it screw up my OS somehow?
i have surpassed you sonion
I really don't see how it would screw up Ubuntu by having ffuf or hashcat on it
or nmap
Bro's in the "Wall street Bets" discord
dont diss my fellow regards brev
I mean is it possible to ruin my device this way? I don't see how that's possible. I mean I see how with malware development how I could screw up my system with that
too late
come up with better regards
but like even if I was doing that I'd get a Windows VM
or prove it
I have rockyou.txt on my host, and hash cat, and I just copy the hash I want to crack from kali to host and voila, GPU acceleration works
yoh bs aside you blue or red ?
ya unless someone can show me how it will screw up my host box to install hacking tools on it or something I may just install the tools on Ubuntu and use that
I mean the tools run perfectly
Td i saw a ubuntu runinng on a bus
red
Most impressive thing i say td
if i open a shai-hulud file without running the bin file am fked arent i ?
that's called static analysis
there's a difference between reading code and the program having been executed, or compiled and executed
but like just use a sandbox if you have any worries
still knew to the stuff but i can analyze the .text/.rdata strings to an extent then i get stuck 
for the first time ever ai just said no to me
tag me cuh
I'm not a reverse engineer or malware analyst, so I wouldn't be able to help you there
But, get good at reading dissassembly
probably start with some older "easier" stuff. VX-underground has tons of stuff you could poke with a stick
also i have these question that has been bugging me for a while saw a post for a while a guy claimed proxxies are far gone in this day and age does it also apply to TOR proxies are their anonymity rating a lie ?
yeah i have like 10 malwares from him good guy
But they could probably help you obfuscate yourself from a corporation
if a 5-eyes govt wanted to find you? They could do it no problem
then what other ways do the bad guys use ?
say i was chasing them
good try
nah genuinely curious not bsing'
Here's a little secret of the trade. Only people who know how to do that teach people they want to know how to do that. And for the most part? Using the tools you've already mentioned can help you evade your local law enorcement for sometime likely, but not forever.
people have patterns
and patterns can be predicted
all it takes is one autist to see your schedule and pinpoint exactly where you'll be and when
also there is a place called OTX alienvault you can check them out for like exploit news and stuff
You don't need to be avoiding the govt. But if your interested in "hunting bad guys" as you've said you could check out Threat Intel/ Threat Hunting
GIF
L Theme
my vpn is all kinds of jank today
There's some courses that go over that stuff
thanks
There's a reason why people use kali vms
lots of problems you'll have with dependencies trying to install some tools on ubuntu and such
but you can use docker for those
i have REMnux and it ticks me off unlike kali
npnp
I haven't found this to be an issue
but we'll see
you have a good point
@spare horizon to?
If all the tools you need work I don't see a problem with it but depends on how paranoid you are too and what is on your machine?
I wouldn't install a bunch of stuff in host os I do banking from or whatever
ah ok
I see
well, you have a good point
how will web hacking tools get in the way of banking?
I'm curious
I mean banking is something you do via browser no? just log into your bank account
Same issue as installing any other stuff there may be malware especially now that supply chain attacks on devs are more popular and also some stuff you install may make your system more insecure in general
ah ok
Like as an example if you installed npcap on windows
That cool burp plugin, yeah really an info stealer, gg
Now anyone has access to raw packets
Without needing to be admin depending how you installed it
Just an example but that kind of stuff will happen
what if you know its not malware? I mean ya but if you can tell the difference between malware and not malware it is arguably better no?
I mean I see the point you are trying to make
Like I said depends how paranoid you are and what important stuff you have on your host os
You can't ever be 100% sure
ah ok
gotcha
don't OffSec have a list of the places they get their tools from?
why not go to that list and cherry pick
there you go no malware
No not "no malware" you are trusting their judgement
ok
It all depends on your threat model
ah ok
what threat model requires a separate VM?
I guess if your doing something illegal?
@dusky jacinth remember hack the robot when elliot caught the p0rn0 guy who he caught he was routing his traffic to Tor thoughts and ideas ? 
wdym thoughts and ideas
"Mr.Robot" takes place in 2015
a guy who's supposedly a savant getting access to the local TOR nodes that this dude is routing too isn't that wild for 2015 ig
No it has nothing to do with that it's what do you actually have on your host OS do you have credit cards saved on your browser? Do you use web bank on it? If you're just using facebook on it or whatever then I don't see an issue
but I wasn't a hacker in 2015
How it will be supply chain atttack like for devices hacked in series way right?
I was 12
You could also use like a separate laptop if you have one
and I was in band lmao
no I don't tend to save credit cards in my browser I use a free open-source password manager with encryption for storing passwords
I don't understand your question can you use google translate to translate from your language?
sometimes I use Chrome for like netflix but for anything private I use mullvad browser (including for banking normally)
Lol
I only use chrome if its necessary
So those things don't matter at all
The communication is encrypted because it is HTTPS
Regardless of browser choice.
ok but we're talking about whether installing hacking tools on Ubuntu is a good choice for opsec
He's asking whether he should use host OS for htb instead of a vm
Supply chain attack you mean the devices will attacked one by one or mitre attack steps?
If you're studying cybersecurity what the fuck do you care about opsec for
If you write the word "crime" in a book do the cops come and get you bro?
It means someone who supplies software to you got hacked basically
Which a info stealer can possibly slurp up
ATEOTD? Using a separate VM for pentesting instead of having all that junk on your host OS is just nice from a organizational perspective
don't need to have all your eggs in one basket
Give me example I didnt get it
You downloaded a important program
that program came from a trusted developer
Okay ?
Okay you're using discord right now imagine discord got hacked they added malware to the app now you install discord and you also get hacked
but a hacker implemented malware into this program you are downloading
say he caught him right i want as to draw a map in our brains just a min
- he got phished
2.he got SEd
3.maybe did a physical typa investigation to map him leading to some typa data collected then ransomed him for something names passwords that typa thing
with this thoughts you could say he got head tapped from differnt angles not just bruteforcing his passwords right ? 
So yeah I got it the program hacked and u have hacked
Supply chain is further up the chain
that's the most simple way I can explain that, but it's more intricate than that
Yeah got it
It's moreso like a component discord uses is compromised
Thus discord is also compromised
ya but I also have 2FA on like everything and I don't tend to fall for SE attacks (I used to but not anymore its been a long time since I learned to spot those easily)
He says how he did it in the show btw
even my discord has 2FA
Opsec is how to hiding your data from hackers that do osint stuff I think
No
2FA doesn't do anything when your token has been leaked
He sniffed the network traffic found suspicious activity, investigated and found that site he's takling about. Pretty simple movie level stuff
Operational security is the practice not talking about what you do at work in public
ya but they would only happen if I got socially engineered which is unlikely to happen
No
We already went over this
dang memory is hazy lol aight
all good. I'm like an elephant don't fret
it's apretty small part of the show tbf
saw an exploit for this no ?
Wrong, you don't eat where you shit. You don't install potentially dangerous tools where you have sensitive information.
ok gotcha
Okay got it means organzation that know who the attacker and anaylsis the attacks
this is the best finalizer i've heard this entire time
but like then why not just get a separate device and put kali on that?
been looking for something that simple
No
Its like blue team
cause kali is a rolling release
ok
why is a rolling release a problem?
You can but then you have kali on your internal network
I've heard some news that AI Data Centers are draining gallons of waters. 
Better separate it in a vm
What is opsec thinking like an adversary to protect, information.
prolllem is he isnt taking a second to preocess the various thing hes been told 
@molten bobcat
it's more thatn that, but we won't get into it
It's up to you bro we're just saying why it's not a good idea but it's your choice of course
ok
I'll have to research this then
but whatever
yeah letting the guy be might be better atp
Uh can u fix ur grammar, I didnt understand ur question
What is your home language
i get smarter everyday reading this channel
Okay I will make it clear
It's just tough to translate.
This server is filled with degenerate ppl trust

Nah nah
Operations Security (OPSEC) is a systematic, five-step analytical process designed to prevent adversaries from exploiting critical, often unclassified, information about missions or activities. It involves identifying, controlling, and protecting indicators of, or data related to, planning and operations to mitigate risk.
Yep
i have a dark humour joke wanna hear it (fun and games btw)
arabic to english is a pretty hard translation, so don't beat yourself up to bad on it
What is opsec ?
Oh right
Thats the answer
Its just "Keep urself or ur team anonymous"
thank u google
Okay if I found the vulnerability in web thats kind of opsec
what was that LMAO
Tf did I just saw btw
Okay if I found the vulnerability in web thats kind of opsec?
What was that
Thats OWASP





