#general

1 messages Β· Page 724 of 1

devout sail
#

Never now πŸ˜”
You'll be stuck with cpts

winged ridge
#

im helping my community

devout sail
#

Yoink

worthy cargo
#

as wel as esc queries:

ESC_QUERIES = {
    "ESC1  – Enrollee Supplies Subject + Client Auth": esc1_vulnerable,
    "ESC2  – No EKU + Enrollee Supplies Subject": esc2_vulnerable,
    "ESC3  – Enrollment Agent + Enrollee Supplies Subject": esc3_vulnerable,
    "ESC4  – WritePKI Flags": esc4_vulnerable,
    "ESC5  – Overly Permissive CA Access": esc5_vulnerable,
    "ESC6  – CA with SAN Editing Enabled": esc6_vulnerable,
    "ESC7  – ManageCA / ManageCertificates": esc7_vulnerable,
    "ESC9  – No security extension + Auth EKU": esc9_vulnerable,
    "ESC10 – Weak Certificate Mapping": esc10_vulnerable,
    "ESC11 – CA with Request Extension": esc11_vulnerable,
    "ESC13 – OID Group‑Linking Abuse": esc13_vulnerable,
    "ESC15 – Application Policy Abuse": esc15_vulnerable,
}
dusky jacinth
#

I mean I could just not verify my cert

rancid swallow
#

nice

devout sail
#

Another yoink

worthy cargo
#

You can easily search for misconfigurations

devout sail
stone marsh
haughty meadow
#

Is it just me or recent bloodhound update gives a lot of errors in terminal and is very slow?

winged ridge
worthy cargo
winged ridge
devout sail
winged ridge
#

@rough mirage

molten bobcat
#

Sigh

worthy cargo
haughty meadow
#

app-db-1 | 2026-05-12 16:29:29.857 UTC [2433] ERROR: type "nodecomposite" does not exist
app-db-1 | 2026-05-12 16:29:29.857 UTC [2433] STATEMENT: select $1::text::regtype::oid;

I meant a lot of these

molten bobcat
#

Hey, don't share fucking API keys in a public chat..

rough mirage
haughty meadow
rough mirage
#

but im assuming it is

worthy cargo
rough mirage
#

no such thing as a free lunch

molten bobcat
#

Don't interact with urls you don't recognize

dusky jacinth
#

don't tell me what to do

winged ridge
#

I run gemma model on my H100 gpus for free and im not paying a penny on it. So I want to share the api that I created

winged ridge
#

whats wrong with that?

rough mirage
#

i need to get to the hacker role

winged ridge
#

yall dont deserve to be nice to

rough mirage
#

πŸ˜”

tired kettle
#

one day...

gilded fern
dusky jacinth
#

not too hard

molten bobcat
#

Just ignored

dusky jacinth
#

Honey pot

rough mirage
dusky jacinth
#

🫡

dusky jacinth
#

I hate you made me read that

stone marsh
west venture
haughty meadow
#

My bloodhound is eating memory and cpu wtf

winged ridge
rough mirage
dusky jacinth
tired kettle
rancid swallow
#

@frail turtle so this is how the TUI Graph and Tree format looks like
opens and loads everything instantly , no extrac setup required

these are few days old pics tho , newer ones also include ACEs with details

dusky jacinth
winged ridge
#

you can use the api key online if yall want, no need to connect it to your computer

jagged storm
#

Bro wants to farm your usage, to train his model.

winged ridge
#

@west venture

dusky jacinth
#

witewawy

#

he's witewawy fawming you

tired kettle
west venture
#

Oh thanks

stone marsh
dusky jacinth
winged ridge
dusky jacinth
#

but not while they were the seasonal active machine

lavish sage
#

chat

#

bomboclat

dusky jacinth
#

yes thugnasty

worthy cargo
#

Zeeshan!

west venture
#

How much money do you have? Bc I might run an AI agent on that key for hours

lavish sage
#

brain rot can be fun at times

winged ridge
stone marsh
#

Now we just chatting about crimes

worthy cargo
#

I use gemini cli for free and it eats up tokens. I use claude code for free using a localhost proxy

jagged storm
lavish sage
#

i'd never commit a crime

tired kettle
dusky jacinth
worthy cargo
#

ANTHROPIC_AUTH_TOKEN="freecc" ANTHROPIC_BASE_URL="http://localhost:8082" claude

dusky jacinth
high cobalt
worthy cargo
#

qwen/qwen3-coder-480b-a35b-instruct I use this model

tired kettle
#

thx for the help @dusky jacinth

worthy cargo
#

It's pretty badass

molten bobcat
#

Don't interact with morons

#

It helps a lot

summer urchin
winged ridge
tired kettle
lavish sage
#

sleep

#

ez

dusky jacinth
winged ridge
lavish sage
#

mirror

tired kettle
summer urchin
frigid mountain
dusky jacinth
#

He knows I'm rage baiting him like crazy with that one

summer urchin
#

tho*

dusky jacinth
#

and frankly I don't want to

#

I'm not gay

lavish sage
#

you sound weak

winged ridge
#

Yall dont need to install an .exe file lol you can just connect that api key on the web if yall want

dusky jacinth
high cobalt
molten bobcat
#

Hehe malware only exists as .exe files guys!

#

It's safe!

worthy cargo
#

There's nothing wrong with being gay

molten bobcat
#

Fuckin idiots lmao

worthy cargo
#

There is something wrong with being a name-calling rude person though

molten bobcat
#

Same people who genuinely believe MacOS malware doesn't occur

dusky jacinth
#

it doesn't that's a myth

frigid mountain
dusky jacinth
#

MacOS is a myth by big tech

#

it's always been BSD

#

always.

molten bobcat
#

I'm literally working a case where curl executed maliciously due to the user executing it. Clickfix spread to MacOS a few months ago.

#

Y'all ain't safe nowhere.

worthy cargo
#

Open/Free/Net BSDs are awesome

high cobalt
#

Hey guys, I have 10.000$ for free, which of your bank accounts should I transfer this to? (/j)

lavish sage
#

mine

molten bobcat
#

Scammers are fun

lavish sage
#

i was first tien

tardy surge
#

heelo

worthy cargo
#

Feed a hungry homeless person with your $10

dusky jacinth
#

I actually replied

fading cape
#

convert it to BTC HAHAHAHAAH

worthy cargo
#

That's a good use

dusky jacinth
worthy cargo
#

It dropped by 2k in the past day

fading cape
worthy cargo
#

was 82 yesterday

#

80 today

dusky jacinth
#

most likely yup

high cobalt
fading cape
stone marsh
#

Listened to a talk about north korean deep fake scams, was pretty cool

high cobalt
west venture
worthy cargo
#

gotta launder my karma

#

Got a revolution behind my eyes
We got to get up and organize

#

Come on baby tell me
Yes we aim to please

tardy surge
#

I have learned about networks: TCP, UDP, IP, MAC, DCHP, DNS, router, NAT, LAN, switch, and layers. Should I delve deeper into networks or move on to Kali Linux commands?

vague terrace
west lynxBOT
worthy cargo
#

Also you can do whatever you want!

tardy surge
#

I have learned about networks: TCP, UDP, IP, MAC, DCHP, DNS, router, NAT, LAN, switch, and layers. Should I delve deeper into networks or move on to Kali Linux commands?

worthy cargo
#

Learn what you're interested in

#

Bro is a bot?

rapid badger
#

I think he is stuck in a loop kek

worthy cargo
#

Quantum Loop

lavish sage
#

i made friends inside computers

wooden thunder
#

you mean friends online right ?

#

I do hope you don't have little people inside your pc

patent lily
#

We don't talk about the motherboard dwarves here

lavish sage
#

they were inside computers and then inside my head

lavish sage
#

isnt that a boomer reference

worthy cargo
#

Older than boomer I think

#

But Tron Legacy and new movies are current gen

molten bobcat
#

Too bad Jared Leto is an industry plant fuck

worthy cargo
#

I hated Jared Leto as the Joker

#

"You don't want no beef?"

#

LOL

molten bobcat
#

The only saving grace of Tron ares is the visuals and the soundtrack by nine inch nails

jagged storm
tardy surge
#

I've learned about IP, MAC, DNS, DCHP, TCP, UDP, NAT, LAN, and OSI. Should I learn Kali Linux commands or delve deeper into networking?

worthy cargo
#

Is this bro serious?

#

Come on man, break the loop!

tardy surge
#

My friends, why aren't you answering my questions?

molten bobcat
#

Hey

molten bobcat
#

We're real people and we're not a fucking search engine

#

You can't just pop in questions and get answers immediately

molten bobcat
worthy cargo
molten bobcat
#

You've just learned a couple acronyms. That's not the same as understanding the technologies and how they work

high cobalt
high cobalt
#

Or learn hacking lol

#

Doesn't matter

#

Okay this meme looks too aggressive but I hope you get the spirit kek

jagged storm
#

it's a troll or bot lol

molten bobcat
#

Nah

#

It's just some kid

#

They're on a gta5 rp server lmao

high cobalt
#

How do you know?

molten bobcat
#

Their server tag

high cobalt
#

Oh πŸ˜‚ Well my OSINT skills again NotLikeThis

molten bobcat
#

I'm a detective for a living lmao

green kite
jagged storm
molten bobcat
green kite
green kite
molten bobcat
#

I just spent an hour writing up a full timeline for a user getting clickfixed

#

Well, I shouldn't say I spent the whole hour writing

#

Half of that was me trying to get their damn domain controller to respond lmao

zenith urchin
#

Hello everyone, I am new to hacking and looking for someone who can help me with that, preferably in Dutch.

molten bobcat
#

Hallo, this is English focused server unfortunately

#

But there's lots of folks from around your area too πŸ™‚

trail prism
#

Hello everyone, I am new to hacking and looking for someone who can help me with that, preferably in spain

west lynxBOT
zenith urchin
#

I know that and I can speak English too, but is there anyone from the Netherlands who can send me a private message so we can talk a bit more?

trail prism
#

or in inglish

molten bobcat
green kite
#

I live like 15 min away from Netherlands

#

Be back in 20

zenith urchin
#

OkΓ© thx

trail prism
#

hello

terse dirge
#

Good morning

trail prism
#

Could you write me privately I need help I'm new

molten bobcat
#

Why

terse dirge
trail prism
#

okey

jagged storm
#

bro is gonna get pinged

trail prism
green kite
jagged storm
#

and there it is

wicked dagger
stone marsh
#

Contact epic support

#

That is all the help we can offer

terse dirge
trail prism
#

okey

silver forge
#

I played a bit of that Arena Breakout Infinite game hmmmHug got some nice loot

high cobalt
wicked dagger
jagged storm
#

Pretty sure the pivoting module covers this.

wicked dagger
# jagged storm arp/routing table - ezpz

Yeah but arp is only for same network, and why routing table? If you have a gateway who tells you it is to access other vlans and even if it is the case if you always do a ping sweep on the entire network it take a while no?

wicked dagger
jagged storm
terse dirge
#

Idk anything about network engineering tbh

meager kernel
#

hi

terse dirge
meager kernel
severe falcon
terse dirge
devout sail
#

Oh

terse dirge
severe falcon
terse dirge
devout sail
meager kernel
#

i cant sleep for some reason
i shouldnt have slept in the afternoon

devout sail
meager kernel
#

i regret it now

wicked dagger
severe falcon
silver forge
#

I deployed my first application cluster to ECS using a proper CI/CD pipeline today pepecoffee

jagged storm
wicked dagger
high cobalt
devout sail
wicked dagger
terse dirge
jagged storm
severe falcon
rough mirage
#

THE ICE CREAM VAN IS HERE

devout sail
#

Spritzou

wicked dagger
wicked dagger
#

If you arp on 10.5.30.0/24 you will see potential hosts on this network not on those like 10.5.20.0/24

terse dirge
terse dirge
#

The dude supposedly worked as a networking engineer, not sure what networks he engineered but very worried

wicked dagger
devout sail
# wicked dagger But again arp is for the same network

Yeah i don't really know too much about it
I have made some labs with multiple vlans and shit
So from top view
All i can think of the options we have discussed
Actually I'll look for it tomorrow, I have been mindlessly making huge labs and not thinking about these stuff lmao

high cobalt
jagged storm
devout sail
wicked dagger
terse dirge
#

Guys, vlans aren't real! Flat networks forever to confuse attackers πŸ”₯

wicked dagger
wicked dagger
jagged storm
#

It might point you to other networks

high cobalt
wicked dagger
#

I mean I’m not in front of my lab but nothing about the other networks

terse dirge
#

Very big us vs them mentality and "everything is there for a reason" without any good reasoning

jagged storm
undone fossil
#

may i present to you

high cobalt
undone fossil
#

the llmnrpoisonerdetector9000

#

.py

terse dirge
#

We have servers that are older than me there just for the novelty of having them hellokitty

jagged storm
devout sail
exotic pendant
#

πŸ˜„

devout sail
devout sail
jagged storm
high cobalt
exotic pendant
wicked dagger
devout sail
exotic pendant
#

I got a new Windows CVE published today

jagged storm
exotic pendant
#

Wifi proximity RCE

devout sail
wicked dagger
#

But like I said I will take a look this evening and ping you @jagged storm @devout sail @high cobalt in red team group

high cobalt
devout sail
#

Yep, goodluck

jagged storm
devout sail
exotic pendant
#

so plz update

devout sail
exotic pendant
devout sail
#

I think i follow u on twiffer

silver forge
#

there's a reason I don't touch Windows pepecoffee

exotic pendant
#

Exploitability isnt easy but easy to DoS

I can walk outside your house and knock all the devices off on your street

#

using windows

#

if i spend the extra time, pop RCE

#

πŸ˜„

devout sail
#

Ehehe do it when u see some kid playing LOL of something

high cobalt
#

Evil

exotic pendant
#

I can make it targeted or just spam every wifi in range

devout sail
#

Where are u gonna post your stuff
I'll keep an eye on it

exotic pendant
devout sail
#

Hmm pls not on OF

exotic pendant
devout sail
#

32161

#

Ic

high cobalt
bronze lion
#

thts a bit of an exaggeration dude

exotic pendant
#

linux getting hit with the AI train atm

bronze lion
#

every week

silver forge
#

reasonably talking, every single system has LPE somewhere

zealous charm
high cobalt
#

What if we got an RCE this friday though?!

exotic pendant
#

Glad I'm taking my break

high cobalt
#

Just saying

obsidian tartan
exotic pendant
#

ZDI stopped taking pwn2own entries

devout sail
#

Soon we will have 0day HTB solves like it's as normal as unintended

zealous charm
silver forge
#

next box idea, target Integrity with nothing listening on network NootLikeThis

exotic pendant
#

i tried to get cluade to find this wifi bug i had and it wasnt finding it

#

after I had found it

#

I just wanted to see if it would even

#

"Nah bro looks clean to me!"

devout sail
high cobalt
muted olive
heady sage
zealous charm
muted olive
heady sage
muted olive
muted olive
#

sometime next month

exotic pendant
toxic rock
high cobalt
#

Dude stop teasing us this much!

exotic pendant
#

Deauth is to help groom

rancid totem
#

nightmare eclipse is back

#

oh hell nah

high cobalt
#

What? Another windows 0day??

rancid totem
#

another 2 0-days

#

actually

#

not 1

gray wraith
rancid totem
#

bro is preparing his repos before releasing it xd

exotic pendant
#

fail

rancid totem
exotic pendant
#

Rookie move

high cobalt
rancid totem
#

and the TeamPCP released open source code for Mini Shai-Hulud, wtf is going on today

gusty saddle
#

hey

rancid totem
#

soon

molten bobcat
#

Fuck patch Tuesday ig

patent lily
gusty saddle
#

how do i fix when i wanna download smth and it’s higher than my ios how do i download older versions

#

thank y’all

high cobalt
#

Thank god I am not a Windows admin but because I am still an admin and have responsibilities ... OH COME ON MAN

patent lily
gusty saddle
rancid totem
exotic pendant
#

bypass bitlocker

#

I should just post my pocs to github

exotic pendant
#

amirite

gusty saddle
#

how do i fix when i wanna download smth and it’s higher than my ios how do i download older versions

gusty saddle
rancid totem
green kite
#

No need to repeat yourself @gusty saddle

rancid totem
green kite
rancid totem
#

the libraries won't write themselves

silver forge
#

personally I prefer developing stuff that can not be patched hmmmHug again not going to spoil

gusty saddle
exotic pendant
#

Get more clout by uploading poc than get paid $1k for a 0 click RCE or LPE kek

exotic pendant
patent lily
gusty saddle
patent lily
#

no wonder people are just posting shit on github

high cobalt
#

Doesn't sound like that much for probably a ton amount of work tbh

exotic pendant
#

if someone took my poc and walked around a hospital ,they could knock off devices

#

or if they work on it, get a RCE and pop on all devices in area

patent lily
exotic pendant
#

One reason I actually didnt want to post the PoC until people patch lmao

#

severe implications

high cobalt
gusty saddle
#

hey

#

please can someone help with my problem

#

how do i fix when i wanna download smth and it’s higher than my ios how do i download older versions

high cobalt
#

What do you even mean? What is higher than your iOS?

#

Older versions from what?

patent lily
iron galleon
frigid mountain
#

had real tacos for lunch

iron galleon
#

u'd prolly have to jailbreak

patent lily
frigid mountain
#

like "street tacos" or as they call them in Mexico "tacos"

gusty saddle
iron galleon
rancid totem
gusty saddle
#

where can i get them archives

frigid mountain
#

why don't you go to the website?

gusty saddle
iron galleon
#

ah rip

rancid totem
gusty saddle
frigid mountain
#

my office TV spotify app is being weird

high cobalt
frigid mountain
gusty saddle
rancid totem
gusty saddle
frigid mountain
#

you could also, you know, not use an iphone

rancid totem
gusty saddle
high cobalt
gusty saddle
iron galleon
frigid mountain
molten bobcat
frigid mountain
#

I'm waiting on a Framework phone πŸ˜‚

#

that would be sick

molten bobcat
#

Googles recaptcha now uses whether or not your mobile device is running the Google play service

iron galleon
#

it still works for me

#

i use grapheneos

gusty saddle
high cobalt
high cobalt
frigid mountain
# high cobalt How so? I think they want to enforce so that APKs need to be signed or simething

Technically, Google could completely block sideloading if they wanted to, but they don't because Android’s identity, market position, and architectural roots are built entirely on allowing it. Sideloading isn't a loophole they forgot to patch; it’s a core design feature.

The reasons Android hasn't flat-out banned sideloading come down to open-source foundations, corporate utility, and legal self-defense.

iron galleon
#

i just read the article

#

thats why it still works for me

high cobalt
rancid totem
#

just found an api endpoint on a shitty claude airdrop site, and the tweet has 4k+ likes, oh god..

frail turtle
#

I mean

#

I only use my phone to talk to people mostly and watch youtube videos

#

that's it

#

dont see the point in degoogleing unless....

#

I want more battery life

#

fuck I feel a fever coming

jagged storm
frail turtle
#

tumors cause fevers?

#

;c

#

oh god don't say that'c

#

scary

raven rain
#

that'c

jagged storm
raven rain
#

πŸ‘»

potent pagoda
#

Does anyone know How to participate in private CTF events?

scenic maple
#

you need an invite and you need to be invited

#

once those 2 are done and you have signed up you will get an email

potent pagoda
#

Yes, but some descriptions say you just need to contact the event host to get the key

scenic maple
#

that is the invite

#

the event host is usually supposed to send the key/invite to the people who are supposed to be in the ctf

#

in a scenario where that isnt the case the people who are supposed to be sent the key just go and ask the host for the invite

#

lets say ABC school creates a ctf for its student so the teacher of that school is supposed to giveout the invites one per student
if the teacher does not that the students may be asked to reach out to their teacher and get a key

potent pagoda
#

But where? For example, in the PepsiCo event section, the host creator is a redirect to their website, and theres no information there about the ctf event. The same thing happens at hunter cyber collector 2026, city of Newcastle.

scenic maple
zealous charm
#

or the CTF is to bypass the invite authentication sus

scenic maple
#

man old htb was something else

potent pagoda
#

Xd

rancid swallow
#

now da graph looks neat af @worthy cargo

u can mode da nodes around as u like as well , ACEs Included for each nodes with details
u can search nodes with realtime indexing, Find shortest path between two nodes and render node amounts accordingly to save performance as well

floral galleon
#

sup chat

worthy cargo
rancid totem
#

this is so real

high cobalt
rancid swallow
crude island
#

Hello all

rancid swallow
crude island
#

@rancid swallow hiii

rancid swallow
high cobalt
rancid swallow
high cobalt
#

Damn, the longest side project I did was building a simple raycasting engine and then rebuilding it in Rust 😭

analog notch
#

don't mind if slap a nice little git star on that one

rancid swallow
rancid totem
#

is this even possible ?

#

I thought it was ranged from 0 to 255

high cobalt
rancid swallow
jagged storm
high cobalt
rancid swallow
neat cipher
# rancid totem is this even possible ?

It looks like something out of one of those old hacking games on steam where you buy computer parts and install them in the data centre to get the leet skills

rancid swallow
#

Laptop GPU btw

rancid swallow
#

i had the motherboard replacement but the replacement was the only one remaining piece in my region and SOMEHOW i found out it has a Defected GPU hardware with Code43

neat cipher
rancid totem
#

I don't think it's possible, the question was ironic

jagged storm
rancid totem
#

Network Foundations Section 6 / 12

#

Nobody reported it I guess Kekw

jagged storm
rancid totem
#

That's great

#

But it's from August 5, 2025

#

xD

rose onyx
molten bobcat
#

I helped fix an issue with the cdsa content when I was doing my exam

#

One of the questions for one of the modules was completely unrelated to the content it just showed you lmao

rancid totem
#

In the exam?

#

That's bad

molten bobcat
#

Nah, modules for the cdsa path

rancid totem
#

Ah

molten bobcat
#

The exam had no issues

rancid totem
#

At least HTB has fewer typos than LetsDefend xD

molten bobcat
#

You know they bought them right lol

rancid totem
#

I knew it, it looks so unrelated to HTB neuroGiggle

molten bobcat
#

It was a recent ish acquisition

jagged storm
#

Oh, they bought it? Gonna absorb like the last one did?

molten bobcat
#

Slorp

terse dirge
neat cipher
#

Yeah HTB is buying up all the cool toys. Vulnlab too getting integrated

high cobalt
#

I wish their modules were just im the normal HTB academy ...

molten bobcat
jagged storm
#

HTB needs to buy maldev academy

neat cipher
stone marsh
terse dirge
neat cipher
terse dirge
#

Choron chicken I think it is

frigid mountain
minor flower
misty citrus
crude island
wooden thunder
#

Hey

#

Any hacking hapening ?

crude island
#

Always

rancid totem
wooden thunder
#

"Happening" refers to an occurrence, event, or an artistic performance involving audience participation

past acorn
#

hello

rancid totem
#

I like you

high cobalt
wooden thunder
#

Thank you, I like you too

rancid totem
boreal pike
#

Roses are red, I am back, there's a flipper zero right here in my bag. Kappa

past acorn
#

other than aura

past acorn
#

what does that mean

jagged storm
rancid totem
past acorn
rancid totem
past acorn
rancid totem
#

Try to send a GIF

past acorn
#

exam voucher

rancid totem
#

Lol

#

Hell nah

past acorn
rancid totem
#

You won't get vouchers for free

#

ofc

past acorn
boreal pike
jagged storm
past acorn
past acorn
high cobalt
#

Pfff, just level up for sending Gifs

rancid totem
#

ok

wooden thunder
#

Hey cool website

#

I like the design

past acorn
boreal pike
past acorn
wooden thunder
#

yes

past acorn
high cobalt
#

(Just joking)

boreal pike
#

And now it's a billboard ad.

past acorn
high cobalt
#

Yeah I also wanted to say the mention looks even funnier πŸ˜‚

rancid totem
#

oh

past acorn
rancid totem
#

you are that youtuber who talks about how to RAT people

boreal pike
rancid totem
#

xDD

#

You are a cool guy

wooden thunder
rancid totem
#

I've seen your videos

high cobalt
worthy cargo
#

AI text gen is too slow. We need thousands of tokens per second speed!

worthy cargo
#

What?

past acorn
#

πŸ˜†

worthy cargo
#

Oh hah

#

I remember that episode

boreal pike
#

:pp

worthy cargo
#

Bortus was the shit

#

Moclans only pee once a year

high cobalt
#

Can't they just scale the models horizontally bruh?

boreal pike
wooden thunder
high cobalt
#

God The Orville was such a nice homage to Star Trek

frosty thistle
neat cipher
molten bobcat
#

I've seen every episode

#

They have several lol

high cobalt
#

I never watched american dad. Just Family Guy

molten bobcat
#

Family guy writing falls off hard around season 9/10

#

American dad is consistently pretty funny

#

They don't just say shocking gross things or just hate each other or show gore for humor

molten bobcat
#

Francine I haven't been entirely truthful with you.

high cobalt
#

Okay this is pretty funny

#

Still, the animated show which has a special place in my heart is the Simpsons

molten bobcat
#

Same, watched it every night with the family for dinner

worthy cargo
wooden thunder
high cobalt
molten bobcat
#

I have a couple animated shows I put on in the background while I'm working

high cobalt
#

Lol, nah at work this would just distract me

turbid goblet
#

Like dora the explorer?

turbid goblet
#

Oh

high cobalt
rose onyx
#

Doing the drywall at the new McDonald's gotta wake my ass up at 6am

zealous charm
jagged storm
rancid totem
#

fuck economy

rose onyx
rancid totem
#

capitalist emperors are sucking bloods

alpine pumice
#

dang, nightmare eclipse dropping more bombs. another windows privesc and a bitlocker bypass.

rancid totem
#

and what's that bullshit with UFO docs

#

media distraction

rancid totem
#

like look at this, a magnet flying on the air

#

I used to buy these from street markets

wooden thunder
#

1900's^ ?

#

the image

rancid totem
#

no it's from 2023

wooden thunder
#

or recent

#

lol

rancid totem
#

but it's total distraction xD

wooden thunder
#

somone needs to make some money on kalshi and plantir

boreal pike
molten bobcat
rough mirage
#

comforting people is really hard when you're so emotionally detached

high cobalt
strong canopy
#

mods

#

any mod

brave matrix
#

Hello
How can I get the CDSA certification label?

high cobalt
rough mirage
#

idk what to do gng

high cobalt
#

Good question, sadly I have no answer to this

dusky jacinth
#

if you have it then just /verify-certification

strong canopy
#

yoh how do yall deal with the slow pings shiih has me on edge nd i want beautiful colours quick

dusky jacinth
#

wym

#

like against a target rn?

high cobalt
#

What beautiful colors?

strong canopy
worthy cargo
dusky jacinth
#

I mean yeah it's tough, but like I just deal with it

worthy cargo
#

Now I have two tabs, one for details, and one for explore relationships and impacket commands.

strong canopy
dusky jacinth
#

Less talk more action

#

do it. Don't say you will , cause idgaf

gaunt gale
#

ffuf runs better on Ubuntu than in a Kali VM lmao

#

I'm using it for web fuzzing and it works much better

#

I'm serious

dusky jacinth
#

bruh that's just host vs guest os

gaunt gale
#

ya I know

#

so on host OS it works better?

#

I didn't know that

#

why not just install the tools on Ubuntu and use that

worthy cargo
#

What do you mean by 'better'?

dusky jacinth
#

I mean your guest OS doesn't have as many resources on it

#

so like it simply cannot perform at the same capacity

worthy cargo
#

It depends on your hardware too

dusky jacinth
#

yeah

worthy cargo
#

First what is better?

dusky jacinth
#

^^

brave matrix
worthy cargo
#

What do you mean by better?

dusky jacinth
#

like just faster?

worthy cargo
#

So you mean faster? I think it runs fine in my kali vm

#

How did you time it?

gaunt gale
#

I mean is there anything wrong with me using my host OS for hack the box?

worthy cargo
#

I have a pretty powerful system, so for me kali vm runs just fine.

gaunt gale
#

what is the downside to using a host OS for hacking? I have excellent hardware (ubuntu with KDE installed on it) and like I actually think I prefer it

dusky jacinth
worthy cargo
gaunt gale
#

I mean will it screw up my OS somehow?

strong canopy
gaunt gale
#

I really don't see how it would screw up Ubuntu by having ffuf or hashcat on it

#

or nmap

dusky jacinth
worthy cargo
#

I run hashcat etc. on my host system so it can use the GPU

#

Sure

strong canopy
gaunt gale
#

I mean is it possible to ruin my device this way? I don't see how that's possible. I mean I see how with malware development how I could screw up my system with that

dusky jacinth
#

come up with better regards

gaunt gale
#

but like even if I was doing that I'd get a Windows VM

dusky jacinth
#

or prove it

worthy cargo
#

I have rockyou.txt on my host, and hash cat, and I just copy the hash I want to crack from kali to host and voila, GPU acceleration works

strong canopy
gaunt gale
#

ya unless someone can show me how it will screw up my host box to install hacking tools on it or something I may just install the tools on Ubuntu and use that

#

I mean the tools run perfectly

lone sleet
#

Td i saw a ubuntu runinng on a bus

dusky jacinth
#

red

lone sleet
#

Most impressive thing i say td

strong canopy
dusky jacinth
#

that's called static analysis

#

there's a difference between reading code and the program having been executed, or compiled and executed

#

but like just use a sandbox if you have any worries

strong canopy
misty citrus
#

for the first time ever ai just said no to me

strong canopy
#

tag me cuh

dusky jacinth
#

But, get good at reading dissassembly

#

probably start with some older "easier" stuff. VX-underground has tons of stuff you could poke with a stick

strong canopy
dusky jacinth
#

Depends who you're trying to hide from

#

TOR and VPNs don't make you invisible

strong canopy
dusky jacinth
#

But they could probably help you obfuscate yourself from a corporation

#

if a 5-eyes govt wanted to find you? They could do it no problem

strong canopy
#

say i was chasing them

dusky jacinth
#

good try

strong canopy
dusky jacinth
#

Here's a little secret of the trade. Only people who know how to do that teach people they want to know how to do that. And for the most part? Using the tools you've already mentioned can help you evade your local law enorcement for sometime likely, but not forever.

#

people have patterns

#

and patterns can be predicted

#

all it takes is one autist to see your schedule and pinpoint exactly where you'll be and when

strong canopy
# dusky jacinth good try

also there is a place called OTX alienvault you can check them out for like exploit news and stuff

dusky jacinth
#

You don't need to be avoiding the govt. But if your interested in "hunting bad guys" as you've said you could check out Threat Intel/ Threat Hunting

slender fern
#

my vpn is all kinds of jank today

dusky jacinth
#

There's some courses that go over that stuff

patent lily
#

lots of problems you'll have with dependencies trying to install some tools on ubuntu and such

wicked dagger
#

hey @slender fern wanna do a quick lab overview with me in the #red-team channel?

patent lily
#

but you can use docker for those

strong canopy
dusky jacinth
gaunt gale
#

but we'll see

#

you have a good point

patent lily
#

I wouldn't install a bunch of stuff in host os I do banking from or whatever

gaunt gale
#

ah ok

#

I see

#

well, you have a good point

#

how will web hacking tools get in the way of banking?

#

I'm curious

#

I mean banking is something you do via browser no? just log into your bank account

patent lily
patent lily
#

Like as an example if you installed npcap on windows

rose onyx
patent lily
#

Without needing to be admin depending how you installed it

#

Just an example but that kind of stuff will happen

gaunt gale
#

I mean I see the point you are trying to make

patent lily
#

You can't ever be 100% sure

gaunt gale
#

gotcha

#

don't OffSec have a list of the places they get their tools from?

#

why not go to that list and cherry pick

#

there you go no malware

patent lily
#

No not "no malware" you are trusting their judgement

gaunt gale
#

ok

patent lily
#

It all depends on your threat model

gaunt gale
#

ah ok

#

what threat model requires a separate VM?

#

I guess if your doing something illegal?

strong canopy
#

@dusky jacinth remember hack the robot when elliot caught the p0rn0 guy who he caught he was routing his traffic to Tor thoughts and ideas ? prayge

dusky jacinth
#

"Mr.Robot" takes place in 2015

gaunt gale
#

ya it came out in 2015

#

that's episode 1 of season 1

dusky jacinth
#

a guy who's supposedly a savant getting access to the local TOR nodes that this dude is routing too isn't that wild for 2015 ig

patent lily
# gaunt gale I guess if your doing something illegal?

No it has nothing to do with that it's what do you actually have on your host OS do you have credit cards saved on your browser? Do you use web bank on it? If you're just using facebook on it or whatever then I don't see an issue

dusky jacinth
#

but I wasn't a hacker in 2015

random aurora
dusky jacinth
#

I was 12

patent lily
#

You could also use like a separate laptop if you have one

dusky jacinth
#

and I was in band lmao

gaunt gale
patent lily
gaunt gale
#

sometimes I use Chrome for like netflix but for anything private I use mullvad browser (including for banking normally)

molten bobcat
#

Lol

gaunt gale
#

I only use chrome if its necessary

molten bobcat
#

So those things don't matter at all

#

The communication is encrypted because it is HTTPS

#

Regardless of browser choice.

gaunt gale
#

ok but we're talking about whether installing hacking tools on Ubuntu is a good choice for opsec

patent lily
random aurora
molten bobcat
#

If you're studying cybersecurity what the fuck do you care about opsec for

#

If you write the word "crime" in a book do the cops come and get you bro?

patent lily
rose onyx
dusky jacinth
#

ATEOTD? Using a separate VM for pentesting instead of having all that junk on your host OS is just nice from a organizational perspective

#

don't need to have all your eggs in one basket

random aurora
dusky jacinth
#

that program came from a trusted developer

random aurora
#

Okay ?

patent lily
dusky jacinth
#

but a hacker implemented malware into this program you are downloading

strong canopy
# dusky jacinth wdym thoughts and ideas

say he caught him right i want as to draw a map in our brains just a min

  1. he got phished
    2.he got SEd
    3.maybe did a physical typa investigation to map him leading to some typa data collected then ransomed him for something names passwords that typa thing

with this thoughts you could say he got head tapped from differnt angles not just bruteforcing his passwords right ? prayge

random aurora
molten bobcat
dusky jacinth
#

that's the most simple way I can explain that, but it's more intricate than that

random aurora
#

Yeah got it

molten bobcat
#

It's moreso like a component discord uses is compromised

#

Thus discord is also compromised

gaunt gale
dusky jacinth
gaunt gale
#

even my discord has 2FA

random aurora
rose onyx
dusky jacinth
#

He sniffed the network traffic found suspicious activity, investigated and found that site he's takling about. Pretty simple movie level stuff

molten bobcat
#

Operational security is the practice not talking about what you do at work in public

gaunt gale
strong canopy
gaunt gale
#

when?

dusky jacinth
#

it's apretty small part of the show tbf

strong canopy
rose onyx
random aurora
dusky jacinth
gaunt gale
#

but like then why not just get a separate device and put kali on that?

dusky jacinth
#

been looking for something that simple

random aurora
#

Its like blue team

dusky jacinth
gaunt gale
molten bobcat
#

Gonna be honest chief

#

This language barrier

#

Pretty tough

gaunt gale
#

why is a rolling release a problem?

patent lily
warm ravine
#

I've heard some news that AI Data Centers are draining gallons of waters. waz

patent lily
#

Better separate it in a vm

random aurora
#

What is opsec thinking like an adversary to protect, information.

gaunt gale
#

ok

#

whatever

strong canopy
dusky jacinth
patent lily
# gaunt gale whatever

It's up to you bro we're just saying why it's not a good idea but it's your choice of course

gaunt gale
#

I'll have to research this then

#

but whatever

strong canopy
warm ravine
molten bobcat
turbid goblet
#

i get smarter everyday reading this channel

random aurora
#

Okay I will make it clear

molten bobcat
#

It's just tough to translate.

warm ravine
warm ravine
random aurora
#

Operations Security (OPSEC) is a systematic, five-step analytical process designed to prevent adversaries from exploiting critical, often unclassified, information about missions or activities. It involves identifying, controlling, and protecting indicators of, or data related to, planning and operations to mitigate risk.

molten bobcat
#

Yep

strong canopy
warm ravine
#

Sooo

#

What was the question again

dusky jacinth
random aurora
warm ravine
warm ravine
#

Its just "Keep urself or ur team anonymous"

turbid goblet
#

thank u google

random aurora
#

Okay if I found the vulnerability in web thats kind of opsec

warm ravine
#

Like if u send a pic on instagram

#

Or smth

#

Ur done for

molten bobcat
#

Jesus Christ why

#

I did not copy that fuckin info lmao

dusky jacinth
#

what was that LMAO

warm ravine
#

Tf did I just saw btw

random aurora
#

Okay if I found the vulnerability in web thats kind of opsec?

warm ravine