#general
1 messages Ā· Page 727 of 1
š u dont wannt them to get rich?
ph
oh
yes
they should get medium
amounts
Unfortunately that won't happen
Yeah only rich ones say that
Just be rich
i mean ngl idk its worth it? i dont want that much land etc just basic? while im connected with nature + and still doing security research on side
my dad aint rich
we quite poor, yet he is quite happy
Just buy the money
bro said buy the money
Poor isn't the correct word tbh
Poor people are those who don't have any guarantee of next day food
Or own home and stuff
Money doesn't buy happiness, but it sure solves a lot of problems. It creates problems too though. So 50/50 I guess.
oh
then poorer than medium sized incomes
doenst that mean we are poor
For poor it does create happiness
For middle class and above what u said might be applicable
and you arent?
i am poor buddy golam
I remember being like that
then its a we buddy zeeshan
yes buddy golam
its paradoxical? people who have money they dont have much problem in life so they feel empty? and people without money are fixated on money like it will make them happy? but idk its not about money?
it does buy happiness depends where u put it
it 100% brings happiness
I'll goto maid cafe if I have lot of money
just need some context
Happiest
well happiness itself is temporary so is thee sad state
happiness != peace
if your peace depends on everything going right idk if its peace
tung tung tung sahur
Disappear
U too
patapim š£ļø š„
bomboclat
YO less go new blog UI, (this is a marketing post) (wait a shit no promotion allowed?)
https://xclow3n.github.io/
Looking good
Wooow, cool design š®
thanks dawg 
you can post in #community-content too if u want
yes master
will do when i publish next blog
/fill ~-16 ~ ~-16 ~15 ~31 ~15 minecraft:tnt
hey htb
i love the platform i really do
fix your fucking website it sucks from ios it is literally unusable i cant move
yours truly
Damn, crazy stuff bro
it also changes color per refesh
š man
yes sir there is reload button on top navbar for color
politeness overloaded
Now I feel like my blog is going to be too basic 
share link
Hahahahhahahahahhahahahahhahzhahz
I'll share it once it is done. Still working on the SQL statements and reactivity elements in Rust/Leptos
It's starting to look pretty good and functional as well. No dependency on bloodhound-ce and it's a standalone bloodhound json dataset parser in python
Finally, the explore tab, where you can see relationships and impacket command suggestions
The spice extends life
The spice expands consciousness
The spice is vital to space travel
Travel, without moving.
Ok sooo welp I have finally migrated da graph's code after whole day's work
Good time of day
throw ur device
How are group of persons
sincerely, with regards
it is a joke
Hey cupcake š
Dude, u got some monei? we go somewhere š« ?
š u know about my money situations right

I broke prod today, how was your day guys? 
Did u tell them that their prod is not strong?
I broke my back trying to debug something..
https://www.youtube.com/watch?v=1k7xltokSZ0 I'm doing great. Listening to this right now on repeat. I love this remix.
Buy it at: http://btprt.dj/1OKwy8J
Release Date: 03-08-2015
DigiCult: https://www.facebook.com/digicultmusic
DigiCult comes with a very first single track EP, a remix of the Astral Projection classic Dancing Galaxy. DigiCult found the right kind of spice to twist this iconic track into a progressive stomper, and although the bpm rate is a-typica...
How you doin'?
Welcome to the club
@mint raptor bro do some bb, u are a legend hacker save some money
lets go
somewhere
No, we all know already 
maybe to SL and meet @west lichen
The shitty identity management did stuck up while we wanted to delete something ... well, it also stuck up auth ...
What did you do to break stuff?
lesgoo, come to SL, food on me 
I tend to just use burp automation too freely not realising that some prod websites are toilet paper 
Luckily I normally just get the company IP banned
Active scan 1000 threads = 1000 bugs
From D3.js to Three.js
and TUIs are on max performance using CSR, Enhanced, viewport Culling on 
https://github.com/mandiant/commando-vm I found this on github. Windows as an attack/redteaming platform
Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@mandiant.com - mandiant/commando-vm
@worthy cargo now my ears hurt
Why?
ur music
Not my music. Just what I was listening to. You don't dig psychedelic trance music?
It's okay. It's not everyone's cup of tea š
a rite of passage for bug bounty hunting is getting your home IP banned from every site using akamai
Ahaha, our website was once DoSed by someone running ffuf on it ... š¬
not mine as well
Well if you ever get hit by someone you paid, and he is using feroxbuster...
Our work address was on a Cloudfront blocklist for awhile, that was fun to debug on a kickoff call
I got a website, and I see someone's IP from Ukraine testing daily the same wordlist 
And I was like wtf is CF even doing
He wasn't paid though xD Dude got blocked. I still don't get why the PHP code runs so badly though š
later figured WAF is paid
Take pity and just give him a morsel, give him a sandbox
Bro testing for /.env
U set the rate limit on CF, itās not necessarily going to block random requests to random endpoints with WAF
Free pen test bruh
What version of PHP? Sounds old if it was actually causing resource exhaustion
Idk if rate limit is part of their WAF though
until serrver doesn't die cuz of their shit i'm fine ig
Nah so this was before I got the guns out. Our IP apparently was just on some sort of default IP deny list they were using
Gday
I was meaning about the other point someone testing on the same wordlist each day
Tejas
Ooooh fair dues
Man lots of shields in chat today. People checking they have access before they have to do support?
I don't see an option to set on in free CF acc
Even 8.2 with symfony on an NFS Share likes to eat 100% CPU on all 4 cores with with just 50req/s o.O no database calls or something like that (or at least it shouldn't), just generated content. Maybe I am just missing some magic configuration flag, but I never got to increase the performance for more requests o.O
Guys, I have a question
Configuration sounds a bit funky, but PHP do what PHP dooos.
One of the reasons I am making my web app in Rust and setting a very disgusting rate limit
Yeah I tested the Java apps we have ... night and day man
lets say u have a office chair like this, over a period after reclining, u find that the backrest doesn't give enough forward resistance and moves back easily
is there a way to fix it?
not the exact type, but something like that
Pillow I dunno
Right now I keep a pillow so it covers that gap
But I don't like it
Heat in weather is killing me
I dont think those are easy to fix unfortunately
Those cheap amazon chairs are meant to last 6m-1y and buy a new one
I got it from a retail furniture store offline
https://blog.cloudflare.com/unmetered-ratelimiting/ according to this its free, but I dont mess with CF too much, so idk
You can set 1 Rate limit rule
I'll just turn on under attack mode and call it a day ig lol
IT is the only field where people fight against speed
I constantly see various Asian countries and European countries scanning my sites for php stuff, but I use hugo static site generator š
same here, mine is a JS and they been testing PHP
I guess they backpedaled out of free waf
Probably
I just return 200 on everything
and forgot abt the blog
I run Wazuh and ingest nginx logs. I see in the console right now South Korea scanning one of my sites
I wish I can fix my chair š«
Iām afraid we are too deep into Ikea way of doing things so I think you might have to get a new one
I should check my caddy logs and see what people are doing
patch it with some fishing net 
How old is your chair?
not even a year
Ouch
Good chair is essential so spend some money on something really good
I honestly donāt know anyone that can afford cheap stuff
I wrote a script to connect my bluetooth earbuds, and aptly named it 'btconnect.sh', before realizing that every time I type it out now, I hear the bitconnect guy
Man, I guess this chair costs 7K INR
hey guys is anyone else experiencing some htb web slowness ?
Labs or machines or academy or what?
labs
Not starting?
Is that the bitconnect guy?
Ye
bit connnnneeeeeeccccttt
not loading
loads but slowly
seems to have gotten better rn
still not much responsive
I should have it play a wav when it connects
Work
Breach and Attack Simulations and RBVM in CTEM for a very large bank
thats amazing bro
Itās fun
Most of the time

you can always give yourself a raise by working less hours for the same salary
I just hate interviewing people cause I would just hire them, I know how itās like so ye
Sir Please share more
How do I do that without getting fired
Youād be surprised how little you have to do to not get fired
Def not 15 hours
Yeah some people I genuinely wonder how they still have jobs
Depends on where u work, but I work 8 hrs max, unless thereās a high incident just when leaving
Cloooouuuud
If there's a high incident when I'm about to leave I just pass it on to the oncoming shift
Or if overtime is paid
We just need more people
Well, Iām the SOC, thereās no upcoming shift buddy
Yup
Beeeyond your deaths construction š¶
Buddy Iām a single security engineer within an 800 employee org
Ouch
There's only so much one dude can do lol
Ill get more work in on the weekend if I have time or work extra early morning, but I clock out at 5 unless something incredible happens
We are army of 300 people in infosec alone
Itās setting me up for failure, but idc tbh, Iāve sort of accepted it is how it is, and Iām freelancing
based
not my problem pilled pass-it-on-maxxer
Itās a chill org, Iām always saying I need more hands on deck, but company has no monez, etc, etc
Thatās always the thing
They'd somehow get the money for five if you quit though
What could I do other than pick up my paycheck, itās not my company, I do what I can, but in the end, itās just a job
they have enough money to pay the gd lazy shareholders who do nothing
Exactly how the world works
you mean pay their creditors back their low interest loan
Around 10 ppl told me to pls donāt resign coz then weād be in the shit, Iām supporting every security implementation as a tech lead basically at this point and ad-hoc support
hi guys. I'm starting with AD pentesting next month, and was wondering what would be the general path to take. I take it the Active Directory Penetration Tester path is to begin with. I also looked at ProLabs such as Dante. I'm a bit confused how to begin with.
edit: please let me know which channel would be the right one if spammed the incorrect one.
resign and then demand a pay bump then
heh
Nah, get them to pay you as a consultant
Nah, Iām just focusing on my freelancing projects
even better idea
One message removed from a suspended account.
Install AD in your own environment and experiment so you can really learn and have fun
@maiden anvil what's crack-a-lackin
But yeah, thatās the plan to eventually move freelancer here as well and get myself a 50% raise
more power too you
Waiting it out
hello
Imagine costing 1200 euro per dayā¦
what are we discussing'
I dunno
I need to waste time cuz nmap
I think at this stage, I am just going to try to get a job at a high end consultancy/bank, quit after a year with a bunch of money and find a really chill job.
It's a 24/7 service I work on
Just be happy and healthy
There's always gonna be another shift
just give up sleep and make caffeine infused eyedrops
And it's moreso "this can't be my problem" if there's 15 minutes left of my shift I can't pick up an incident lmao
I wish tbh, maybe 10 years from now
Youāll get there
I was looking for sec+ PBQ study guides, and this one guy came up on youtube, who wrote his own study platform, and it has this question:
I've been pounding away chapters of Rosen's discrete math with appications and I fear I am actually the one being pounded
I have always been the black sheep in the family so you can do it
Literally only one correct answer lmao
I mean, 1200 euros per day is what you pay for a big firm for 1 guy, but as a solo freelancer, I donāt think that price is justified at all
He claims that there are 2!
Unless -p- works after the ip
Nice, discrete math is fun
Itās how it is up here
That's the only one I ain't sure of
-p- does work after
But the 4th answer is incorrect, realistically speakig
It only scans top ports, which doesn't satisfy the question
-p- in UDP if you are paid by the hour
I'm enjoying it. Havent done rigorous math study since grad school though and I feel so rusty
If you only scan top ports, you can't say that you know all open ports.
This just feels like a gotcha question to see if you have used nmap before lmao
I heard swiss ppl asking for 1.2 CHF/day for a dev, but basically no one wants to hire them, outside of switzerlandš¤·āāļø Not my market
It's his own study platform, so it's not actually from comptia, and I just think he did a shit job at making a question/answer
Goated book
I can make do with 2 projects and 700/day each 
Companies do that if they are in deep trouble
I recently finished this excellent series on discrete math on youtube
Initially signed up for a university program cuz why not but ended up hating it and switched back to yt
Thatās decent
My linear algebra class used friedberg's book and this reminds me alot of that same kind of rigor. Really a breath of fresh air
link?
https://www.youtube.com/watch?v=zfwxSmL4n6w&list=PLUkY1OVVHzVljGOe8WAkKGc4GT8ZAKaav&index=1 this is the full playlist, and I'm wondering if I should find a better one
Currently studying stochastic calc
Thank you
when I have free time that is
I guess if you had a ransomware and you need forensics to salvage ur shit youād pay that
What is free time
time that is not paid for
hi
If we get that then itās probably over for us
I went through Stochastic Calculus with Fianancial Applications by Steele a few years ago. Incredible if your fundamentals in calc and stats are strong
verry high level though and I suffered greatly
Calc sparks joy
We are gonna be best friends
Read some snipptes from steele and others
Math is painful and pain is bad for health
Steele is fantastic and highly rigorous and gives me splitting headaches sometimes
Latest book I read was earnest chan on quantitative trading
if you ever feel useless
Excellent book to get you working on applying models
Hard agree; I can't stick at it too long unless I'm applying what I learn
i will never understand the math these theoretical physicists can do lol
I try to stay away from the quant math rabbit holes tbh
My computing skills are far from good enough to make actually useful financial modeling software
It's on my list of priorities though
what are you going to do with quant math in the private sector? besides day trading lol?
doing the math is one thing, making code the does the math is another
educated and informed cry sessions about how little I understand arbitrage
qants are horoscopes for economists
I think you mean discretionary traders
Cause quants are more similar to Astrophysicists
those hedge firm quants are freaks of nature
^
I should do some trading but I'm just lazy 
My money doesnt touch the market at my discretion aside from my 401k contributions
These algos are getting real good
I have over 100k liquid, which is not very smart, but I should spend a few hours figuring the trades out and ehhh
nah trading is for losers
Buy income generating assets and talk to a good CPA. Or throw it at a few index funds and don't touch it
day trading is esp stupid
I do mostly DRIP and value investing, which means I have to actually do my research
all in $GME
diamond hands
I also have too many REITs already tbh
lately I've just lended money for interest, but even that is kind of tricky at this moment since company investments are not looking healthy
Ever look into forex? (or even just investing in foreign companies which is far safer)
not many companies are willing to invest, and the ones that do are mostly YOLO this and that
Hype economy is real bad for quality investments, but other countries are looking alot more stable and growth oriented
I guess I could recalibrate my approach but it would take 5-10 hours of actual work
reading quarterly reports, analyst opinions and whatnot
also I should sell the companies that have no further potential, and have risen too much already, but that creates tricky situation with the taxes
I already owe 10k to the taxman 
wut
you profit they want their share 
I owe the taxman a whopping $125
My goal each tax season is to owe them nothing and have them pay me nothing
Theyre like a toxic ex
the less interaction the better
that's simply impossible for me. even after the deductions I make up I just make too much money

I have been lately thinking about buying or building a submarine though, it would be a fun side project
feds activated
tax evasion is always possible š
I'd like to build a sonar, that would be a fun project. then a small submarine to work it with.
I'd like to be able to track fish
tiny torpedoes for fishing
post it on youtube and then await job offers from a defense contractor lol
dont let your dreams be memes
everything is possible if you dont know social boundaries
literally me
go hard or go home
i do both
zeeshan you catch flis and feelings
im sensitive
aigh convincing someone that we should be using OSPF rather than static routes was a hustle chat
static routes are fun until you screw up and your network is down
INS Computer Networking Nerds spoof on the YMCA song
this guy suggested we do 0.0.0.0/0 -> everything to frontal firewall. via static
YOU FKING LEGEND
Hello all
hi
Hello karma my buddy
Great song eh
now i've a proof holy shit

and the thing is we got 4 companies 4 -> 4 VDOMs, and you want me to use static routes ???
i dont get paid enough
ok I made up some deductions, and they will have to recalculate how much I owe to the taxman 
My taxman took away my bounty monies
Damn you taxman
Alive?
time to check the investments, but I'm too drunk to actually do any changes so viewing only... last time I was drunk and tried investing I lost 5k euros 
imagine owning 5k euros in this economy

imagine affording groceries
I feel symphatetic, but I'm doing fine
Sir please you are hurting me right in the hurts
Q2 estimated taxes due 
Taxes are great and I am so pleased I can contribute
well enough off to pay lots of taxes, no well enough off to pay no taxes
ok two of my loans to companies have defaulted it seems. ah well. 
I don't mind taxes as long as it helps people I care about survive this life
Amen to that
US spends their tax money on mostly military stuff. We don't see anything, no universal healthcare, just ... it's crap.
Two of my working mates have had cancer. All their care was paid by the society. They are still alive, working, and not bankrupt.
Maybe in EU where tax money actually funds the public good and not bailouts resulting from corruption and fraud
Well, AmeriCAN'Ts are a different tale. They deserve the system they made.
We made?
is getting a pizza oven worth it
People are leaving the US in record numbers
It's an investment.
@lavish sage where you at this people talking about tax fraud
pizza oven -> š«
Taxes are my version of āI do my partā
but wait
Thereās more?
if your gov knows how much taxes you should pay, why dont they just send you the fkin number
They do
Thatās on me cause I donāt even claim to pretended like how to deal with that. I made that mistake once and I learned how to deal with it properly.
Ok ye
okay so from what i understood there's some bad consequences if you underpay
5 stars aah tax fraud
Then you have to pay what youāre owed
why not just tell me what i've to pay from the start
AI ATS and Resumes
Ohio State sent the same resume to an AI hiring tool twice. Same qualifications. Same experience. Same skills. One version was written by a real human.
The other was secretly rewritten by ChatGPT.
A team from the University of Maryland, the National University of Singapore, and Ohio State just published the receipt. They took 2,245 real human-written resumes pulled from a professional resume site from before ChatGPT existed, so the human writing was actually human. Then they had seven of the most-used AI models in the world rewrite each one. GPT-4o. GPT-4o-mini. GPT-4-turbo. LLaMA 3.3-70B. Qwen 2.5-72B. DeepSeek-V3. Mistral-7B.
Then they asked each AI to pick the better resume. Every model picked itself.
GPT-4o hit 97.6%. LLaMA-3.3-70B hit 96.3%. Qwen-2.5-72B hit 95.9%. DeepSeek-V3 hit 95.5%. The real human almost never won.
Then the researchers tried the obvious objection. Maybe the AI is just better at writing. So they had real humans grade the resumes for actual quality and ran the experiment again, controlling for it. The result was worse. Each AI kept picking itself even when human judges rated the human-written version as clearer, more coherent, and more effective.
It gets worse. The AIs do not just prefer AI over humans. They prefer themselves over other AIs. DeepSeek-V3 picked its own resumes 69% more often than LLaMA's. GPT-4o picked its own 45% more often than LLaMA's. Each model can recognize and reward its own dialect.
Then the researchers ran the simulation that ends careers. Same job. 24 occupations. Same qualifications. The only variable was whether the candidate used the same AI as the screening tool. Candidates using that AI were 23% to 60% more likely to be shortlisted. Worst gap was in sales, accounting, and finance.
99% of large companies now run AI on incoming resumes. Most of them use GPT-4o. The paper just proved GPT-4o picks GPT-4o 97.6% of the time.
vote me president 2027
If you wrote your own cover letter this week, you did not lose to a better candidate. You lost to a worse candidate who paid OpenAI 20 dollars.
You did not lose to a more qualified human. You lost to a machine that grades its own homework.
Cause taxes are magic
@tame gust I went to cane's yesterday, and I saw a guy give away his cane's sauce to his friend. The most illegal thing I've ever seen.
there is a reason the AI ACT actually limits the use of AI in recruiting
What is homebrewer brewing at home?
this is disgusting
I know right?
currently brewing a german light lager or "leichtbier"
Woah I respect that a lot
the AI act defines AI used for evaluating job applicant as a high risk use case, requiring registration to the officials for extra supervision, risk evaluation and management practices, etc. the requirements are actually pretty nasty, nasty enough that it's actually much easier just not to use AI in recruiting. or risk the penalties of tune of millions of euros.
Im researching DOM trees and HTML parsers today
hbu @zealous charm what it do homie
I don't think USA has any such law/act. Does it?
Seems like every country BUT the US has these regs in place
well, it's 3rd world 
So I see you are into sinks eh
trynna understand the mystery and wonder of mxss šŖ
Link for that study?
even more than your mum? 

i'll clober ur dom
dont you dare mess with my tree
Someone just posted a screenshot of it, no link. I'm sure I could find it.
Nothing fun for me, making some AI stuff at work. Still between new bug bounty targets for now
knowing intimately how llms work it actually makes much sense. they do prefer their own output as the input.
Found it
As artificial intelligence (AI) tools become widely adopted, large language models (LLMs) are increasingly involved on both sides of decision-making processes, ranging from hiring to content moderation. This dual adoption raises a critical question: do LLMs systematically favor content that resembles their own outputs? Prior research in computer...
Im on the lookout for a parallel computation book for subagent orchestration so if you know of a good one send it my way
I doubt such material exists specifically for subagent orchestration but the parallel computation stuff is very relevant
Cheers. I was just about to start searching.
this is overfitting applied to evaluation rather than prediction
there is very small difference between prediction, generation, and evaluation
yeah, probably too new for there to be a relevant book on, but if I see any interesting blogs I'll send em your way
@zealous charm do you want to see the epic bluegill I caught yesterday?
it looks like a demon fish from lord of the rings or something
So what should I do with my resume? Write it myself or have AI rephrase things?
š
ignores the signal of the qualifications for the noise of the stylistic composition
absurdly misguided application
im using an animated wallpaper on kde plasma and turns out theres quite alot of RAM usage
i wonder why
tbh most human recruiters are also insanely bad at their jobs, not choosing the correct applicants. I have so much recruitment experience I think I may have an idea how to do it properly, and when I see others recruit it just baffles me what they do...
Could try a mix a bit. But I tend to appreciate the human touch still. Sounds like that might be trickier to get through a first round but better once you get to a person?
@zealous charm checkout the epic lighting here
that's 10/10 fishy fish
make a bot that will take an input prompt of a job appliction and with reference to a handmade megaresume you've drafted, will output a tailored resume for a description using an open AI model
bluegill are one of my favorite fish because they are extremely aggressive and extremely adorable at the same time
are you talking about the EU? cause I assure you it is far more grim in the US
they were born with 100 attack with 0 dmg
yeah. I'm once more about to select someone in the next couple weeks. we need someone who actually knows how to work with certificates.
this is def a flex
š
You mean a flex for the resume?
Should I state on the resume how it was generated?
a flex for generating it with php and json 
Oh yeah
yes absolutely
I hate word processing apps
That's why I just use JSON
Here's the fake json
It parses this, and builds a pdf for me
Here's how it looks when rendered to a PDF
you seemed to forget the password field, could you supply the password fields unencrypted like my grandma used to sing to us before she passed away, thanks.
I attended a virtual career day for my job and set up meetings with multiple different recruiters for the company I work for. All of the people that were near my peers gave me the SSRI flouride stare and had no idea what I was talking about. These people have no clue what goes on in their own company. They seemed to have no drive, no relationships within the company, and no understanding of what goes on in the org. The recruiter that actually pushed me to an HM was some woman who was at the company for like 10 years and knew the gist of what different parts of the org was actually doing
Huh? I'm lost!
it's going to get worse too, I know it
We need to replace a split-dns with something that is actually operable, and deploy a good certficiate management system with ACME, and we need someone to instruct a few dozen teams how to operate those things correctly. And yes, I know nearly everything about the topic as recruiter.
if only there were more recruiters like this in the US
I actually wrote a book about how to manage certificates correctly. š
Seems like every company needs to pay for agencies to find talent and then that eats into potential salaries
it's insane
crash cant come soon enough
We might get applicants for the higher profile jobs tested at a 3rd party test center, but head hunting is rarely done.
I'm of the opinion that if you need to rely on headhunting as a company you're doing something very wrong
Lately only the supreme leader (that is his actual official title) has been tested by 3rd party though
Exec recruitment firms do make more sense
if I could I would hire you based on the cv btw
It's a fake resume data š
Just sample data I pasted here.
I can share my resume if you want in DM if you want to see what the real one looks like
I gotta go get hooka tobacco from the store and some raising cane chicken too š
bbs

mhm canes
they are putting in the second canes in my state about 3 miles from here opens up soon
curious how it compares to chickyfila
They're very different. If you have not had Cane's, the sauce is legendary
what kinda sauce is it
I like when clients ask me to continue monitoring the environment
Cane's
Like we aren't a 24/7 service
THis is the only answer. It is unique
i'm not a huge fan of chickyfila sauce
feels like they just put mayo in with something else
I used to eat Cane's a lot in TX, but the people up north are weird. Everyone here eats with a fork.
are the sides good at cane's? i hear mixed opinions
The toast is amazing
but it's mainly a vehicle to dip in the sauce
The whole reason you go is for the sauce
THAT's INSNANE
This goes str8 into my "why ai is big bad" list
Ah
I hate this job market
Canes is mid fight me lol
Canes is delicious.
But everyone has different tastes
So if you think it's mid, that's okay too
Good evening everyone
Any tips for someone who wants to learn cybersec? I have finished a course on fundamentals but now want some hands on
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
Start here ^
Get an academy subscription and follow the path you want and do modules etc. to learn
you cant drive toast
somebody tell rat he can't drive toast
I deleted all my ricing and everything and moved back to normal KDE plasma, I think I made the right decision
It feels like Im on the bottom of the bell curve
And I've crossed the top
This thing
I do unriced i3
we got a pop eyes here but the place is dead at night so it can't be very good
patrician taste
I don't even have a wallpaper
Psychopath
or filthy i3 gaps
I use to use Niri
psychopath
Coming of age

distro hopping is a mental illness
we all battle it
Im 19, not that old š
Tysm
Bruh ive been on cachy os for quite some time, no plans on hopping off
But its just my desktop environment and stuff
I riced a full Niri setup for myself which I was using
But idk why I just felt today morning that I dont wanna use a riced system anymore
As you get older, you start to derice, and get rid of RGB
I just want stock Plasma
do you plan on doing away with your mouse and just using your keyboard as an interface?
Nah
Looks cool, I personally don't enjoy kde since my current setup is productive for me but more power to you
I quickly changed my greeter, deleted Niri and quickshell, switched to Plasma
All I did on plasma is change my wallpaper and icons
Rest is same
Ricing is just to make pretty colors make your brain go like bling bling, me happy or idk
At some point, you accept multi-user.target, instead of graphical.target
And added 2 widgets for monitoring system usage
I never did ricing
then do whatever is most pleasant and familiar and let it drift into the background
I say this as someone who has spent way too much time trying to piece together my desktop experience while I ignored what I wanted out of it
Yea exactly
Like just keyboard usage
But i felt tired of it
It didn't feel worth it anymore
Proceeds to accidentaly break the whole system
šš
I feel im pretty happy now
With plasma
It works really well
I dont keep fastfetching to look at my system anymore
Imagine if people just learned hacking instead of ricing their env they gonna discard few months later at best coz you cant stay on a single distro smh
Me just use Ubuntu
I keep ricing in the lowest of my priorities tbh but I am faithful to my distro!!!
[responder intensifies]
All networks should be flat just like the earth!
32 loopbacks for everyone!! š„š„
Imma make a pci dss network without network zones and fail all my audits
@terse dirge look
istfg if bro tells me to switch to void
at least he doesn't shill arch anymore
void is respectable
Ive met some of the biggest arch glazers in this server
I use cachyos but I made it look like arch so I can larp as one of them
That's very cursed sir
wait what
Still using x11 alone is cursed let alone i3 and the default one
its like u are the kid who wears short in winters
no offense good sir
Im not able to sleep
Insomnia haunts me again
excellent battery life
Laptops in 2026 šš„
Build a custom gaming desktop
I will, just as soon as I'm not sitting in a homeless shelter lol
Fair enough
Btw rat, eBpfs on windows make you convert them into drivers or dlls to run them because running an elf file is too easy and they want you to use their shitty C++ toolchains to convert them 
The way Microsoft implements them makes zero sense because they're running in a virtual machine there's no reason why you'd have to convert them to drivers or dlls
Yeah, and that's not happening without the EDR watching lol
Oh yeah, I was thinking about writing a shellcode library - kinda like msfvenom, but you could hot drop any asm into it, with just a minor edit, and then it could generate whichever you wanted.
Maybe but depending on how it's pushed into new windows versions they might just let you pass the elf file anyways (which is the right thing to do) and eBpfs on windows right now is just bpfs
You'd have to write your own extensions to hook into kernel functions and libraries I think unless if you're able to use whatever windows has for tracing for it
It'd be sick af if you can hook into dlls or functions out of the box cause then you can extract credentials 
Im wearing my arch shirt today :)
Cultured man right here guys 
What is OS?
Old school
orange slurp
Ah, I an old, but not in school
osrs
š Message hidden
-# Discord now requires facial verification in order to see certain messages.
wow boy u sure got me!
Idk even know what that wouldāve gotten out of me
Are you interaction farming in HTB general?
Next level tbh
Ok the final version I think.
Loaded up real data from Puppy.htb machine
Looking and functioning well.
fam....I did a box for the first time in like 3 years go me
How did it go?
It was fine lol. I work in the field as a red team operator but just havent had the time to do boxes ever
Usually too busy hacking the company
@crude island I added a few more featues to bhtui. Check it out: https://gitlab.com/Eggzy/bloodhound-tui
Which one ya do?
Which box
Cap..
Trying to start working through the retired backlog and it was the first on the list
Prolly since it was recently retired
Okies
this basically put bloodhound data into a tui?
I think ive heard of that tool before
Cap is real old but it's the first on the list as staff pick
I assume because it's a good bridge between Starting Point difficulty and Easy box difficulty
Shows how out of touch I am with the platform 
Yup. I wanted a standalone bloodhound/sharphound JSON parser, without having to use bloodhound.
Imagine
yeah im assuming its because bloodhound is heavy and uses up ram so u made this?
Yeah. Basically. And also for fun.
That's okay
I am a nerd, and it's totally okay
š
It is totally innocent! </fonejacker>
im a nerd too we are twinning 
fonejacker
I didnt know u americans watched british comedy
its pretty bland š
all active Easy boxes will be linux let's go 
can you do all the easy boxes and get image perms without the subscription?
im considering getting the subscription but idk if im just gonna spend a month on it and leave
Yeah fonejacker was pretty funny back in the day
which won't make it worth it
If image perms are Hacker rank, then like all Easy + one Medium should get you there
ofc. you ever seen the it crowd?
When we move to the new ranks in Discord, you'll need Skilled (replaces hacker) or seasonal silver still
I thought I was getting Hacker today but maybe I wrote this wrong?
Peepshow was also good
all easy ones, im too lazy for this ong
that show made such great memes lmao
How to evolve to a ānerdāā¦
maybe my favourite peep show bit, just for Jez's dumb grin
https://www.youtube.com/watch?v=b8ZujxHpz8I
don't think ive watched that one too much ngl, I remember it was funny though
nah don't think so haha
will do lol, I think ive watched the one about nazis in MAW
Are we the baddies?
Haha
I mean we've got skulls on our caps!
yeah that one
they do?? huh, don't think ive seen
these guys were like the original south park
"hans, are we the baddies?"
south park is old as shit dude
I thought it would be like 2009
Oh no
because I started watching them when I was like 10
bruh
I was already like 16/17 years old when south park came out
I'm in my mid 40s right now
I wasn't even in my dad's balls back then
Funny releasing this box two weeks after Helix
HTB is two weeks away from getting nuclear weapons?
We need to go to war?
HTB can't have nukes. It's as simple as that. My plan, is very simple, folks.
The simplest plan, beautiful plan
It's very simple. HTB can't have a nuclear weapon.
htb world domination
</parody>

does anyone have that flow chart of routers meme where it's like, cisco to prevent us backdoor -> mikrotik to prevent russia backdoor, etc...
nevermind, found it
6 + (7 .....
rest in peace my granny she got hit by a bazooka
What is up peeps?
Found a new album that's so fantastic I can't even.
Well here it is guys! Our third full length album "Terraforming" is now available for your streaming pleasure!
Order your copy today at wideeyesofficial.bandcamp.com
- Evacuation 0:00
- Renaissance 0:51
- The Launch of Kasper 5:21
- Escape Velocity 10:04
- Titan 14:45
- Electrolysis 20:46
- Traversing the Oort Cloud 25:55
- Voy...
Instrumental progressive metal/djent style
Guitar work is amazing
Wide Eyes
creed
Nickelback
Eggzy!
Artist name
I was experimenting with ACE Step 1.5, self hosted Suno alternative
It's not as good as the Suno models
Still, it produced some not so bad tunes
i hope i wake up tmr in the backrooms
life would be way more exciting instead of just getting fucked by work everyday
Another one?
#1 cause of Grandma death worldwide
Mine was lucky, thrown into incinerator
I don't know I never lose sight of #1
Provided to YouTube by Miami XO under exclusive license to RUN Inc.
Bazooka Ā· Miami XO
Bazooka
ā 2025 Miami XO under exclusive license to RUN Inc.
Released on: 2025-12-31
Main Artist: Miami XO
Producer: Slxwly
Lyricist: Miami XO
Composer: Miami XO
Auto-generated by YouTube.
oh no
I can't dig this type of music, not my cup of tea but word
home slice
I guess it's funny
yeah its just a meme i dont unironically listen to it lmao
ima say fuck it this weekend and drop 3k on a new laptop
my current laptop is so dogshit its not even running feroxbuster now
3k⦠macbook?
If you fit USB-C, then Iām sorry
lmfaooo
Gaming laptop is an oxymoron š
Kidding man⦠you get what makes you happy
Even if a MacBook is superior
i mean fair
i just need a really good laptop thatll last me and can actuallly hack
currently my terminal crashes if i use hashcat
ah shit this looks fire actually
Which terminal do you use?
zsh
Get a system76 laptop
Not your shell
Or framework
Try John instead
john crashes too
Are you using Kali in a VM or bare metal?
bare metal
I don't have to mess with tmux or split GNU screen sessions
its a 4gb laptop
Tilix is awesome
That's your problem then. You need more ram
Tilix is an advanced GTK3 tiling terminal for Linux based on the Gnome Human Interface Guidelines (HIG).
You are honestly the only one I know that will use screen
I been using screen for years
Just used to it I guess
Don't wanna spend time learning tmux
I would use something that's not meant to be expendable like using Manjaro instead, arch Linux, or void
And then use Kali in a VM if you get more resources for your laptop
Tmux flow does not jive with me, that's why I use zellij
Plus screen and TMUX have a problem
Any single terminal emualtor window split by cli window manager causes problem when copying text with mouse
and using xclip is not very feasible all the time.
So I use tilix
screen gang
I can split the terminal any which way and they are all individual terminal, I can copy text and other split windows don't mess with it
Mouse copy is the main problem in GNU screen or tmux.
That's skill issue and tmux because that's something that can be done
It's not a skill issue if you want to make your life easier.
Computers were meant to make life easy, not harder.
No because you can split and copy just what's in the one pane
Not have to come up with workarounds for things that shouldn't even be a problem to begin wth
Not with a mouse. Mouse select the whole line from the terminal, so if it's split vertically, you copy from both splits.
You can pipe it to xclip sure, but who wants to do that.
i mean is it that life changing? i enjoy kali and never had any issues so far
does php 8.2.27 have any exploitable vulnerabilities ?
We are not a search engine buddy
i would hate having to install all the tools, that part of hacking is boring
Even the search engine failed me gng T-T
I mean it shows 4 but I don't know how to replicate them
Why you're asking?
group project ?
which one
a good one ?
so you're not honest
š
searchsploit? exploit-db?
It's not even a lie. It's just he is concealing the truth for some reason, and if he is hiding, then it's probably not for a good cause
google?
I'm new to this kind of sorcery kind sir
Well if you aren't even sure where to look for existing vulns, how do you even intend to exploit them
I'm not exploiting I just wanted to learn š
You want to learn specifically how to exploit php 8.2.27?
Because some site you don't like is running it?
ah no
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
tweak some of the settings >_< or use a vps
i have a vps i pay only like $10 every couple months for
for hashcat?
there's vps with gpus
wat settings
you'll have better luck finding something in the web app itself than exploiting php no matter what version tbh
-O use a wordlist run it on your host os instead of vm...
4gb is enough
Ye I just got hit by that , I mean the web had Five open ports on shodan so I thought I might have a chance

Yes learn first so you can actually go to jail later cuz right now I don't think you're gonna have any luck
Bro what is your pfp lmao
Gary coleman between 2 postal babes
Blast from the past
nah I'm better than going to jail+I ain't into being a bad guy or smth cringy like dat
this is illegal what you're doing
you're trying to pop random boxes on shodan
dw I can't do shi to begin with
yess hehe
stop it
ok T-T
as said it's illegal
Youāll end up getting into trouble⦠you likely havenāt got a clue what youāre doing and leaving a log trail back to your Momās basement
I live alone but....thx ???
and mom's spaghetti
now that i can talk, you are a brave soul LOL
Reminds me of that kid in Hackers that got caught at the beginning
Fine line between bravery and stupidity
meow
Lol
LOL true, im too paranoid to even attempt it
mb for existing yall
its not existing were ribbing you for its being careless, we dont want you to get in trouble
lol, you are allowed to exist, of course, and even staying and learning
^
But hacking something you have no permission to do is universally stupid
HTB is a great place to learn
I thought it's cool to find something in a website and tell em what's wrong, turned out that's also a crime
lmao
We all probably did zumi
he said he lives alone
those seem hard ngl, lotta people do it
Well, fortunately you can learn a lot of the skills here
You did it tho! you found vulnerabilities and if you were in that program you can safetly report them
And get paid instead of charged
and get my appartment swatted by local police 
better hunt on allowed program than hacking a site illegally
I did stupid things as a child, but the internet didnāt really exist
š
Not if you joined an actual bug bounty program
thats what were saying
but i mean hey if you like doing illegal things by all means, i cant stop you
but we have rules on this server
I assure you I'm a law respecting person
I got kinda arrested when I was 15⦠driving without a license
more like don't wanna end up in jail but works both ways
i dont think your getting what were talking about
same
I do guys , I respect that yall didn't straight up kick me and talked some sense instead
Got pulled over for a traffic violation⦠when I couldnāt produce a license, they decided I should come with them
anyone plan on watching the 24h Nürburgring this weekend?
not me
I liek monster trucks
somebody died on the track in the prequal I think
Nürburgring is top danger
very sad though
Oh yeah I was actually just testing the locks on the doors and the code to the safe don't mind me
imma
cat is this real
Literally me rn
Youāre a furry?
He is
this is Discord, after all
This is a safe space
For the moment
the archons and loosh harvesters are preoccupied
Hmmm I don't think I am but furries are good at hacking and cyber
Thatās my secret to success
