#general
1 messages Β· Page 737 of 1
As Firefox is open source, find the patch, read the code before, and see if you can figure out the issue.
true. will do
art is hard
Hello everyone.
Iβm new to HTB and i would like make career in CyberSec.
Can you help me with which to to start an how to learn β¦?
Art is easy. Just gotta know your techniques
I made this painting from spray paint and acrylics
And this one
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
read this
This is pure spray paint
Thank you!
This is my best painting so far
But lately I enjoy making AI art.
But people shit on me for using AI
They call it slop
Thanks man
damnnn
I'm equally good at the guitar
π₯
But I like making AI music too
veri nice
AI music?
talented af
AI-generated music
never seen good ones but yeah cool
How about this one
im trying to get into nudist art 
This came out real nice


wow that was very helpful ,
pls accept a upper cut as reward for helping me out
Lolmao, Elbow placed above your Uppercut , good luck
Here's some digital art too
Google's Lyra , Suno , etc are the platforms to generate
I did this in Gimp
that's because the whole point of art is that it is human expression. when an AI generates it for you, the human connection is lost
I don't feel that. As an artist, I don't feel that. I love AI art.
I don't think AI takes away from human art at all.
cool now ur ribs are open while youre busy posing with that elbow
Here's another digital piece in Gimp
sadly i dont have embed perms
Hi guys sup
some year right now gimp will reach feature parity with photoshop 4.0 
Literally what was your actual question then , from
"Ai Music?"
lol
Gimp is already fucking amazing
ye lol
yesss this one and the one you sent before is way better
looks banging
Thanks
I do digital art and canvas art with spray and acrylics
But I also enjoy making AI art
oh I see, nice
It's very therapeutic
at least for me, others like me, and artists who draw, we can see what others create and appreciate not only the emotions behind what artists create but also the skill and effort it takes to do what they do. AI strips that away. AI artwork does not carry the same weight that human art does since humans cannot relate to AI. there was no skill involved in creating the piece, and we cannot interpret the emotions behind it either
To each their own
its just personal preference ig
People have different opinions about AI
Some support it and some don't
Both are okay
You're articulating something a lot of people feel deeply, and there's real substance to it. A few threads worth pulling on:
I hate how AI sounds like some HR lady
drawing is easy. drawing well is very hard, and i have immense respect for artists since they spend nearly every day honing their craft
and most people will take it for granted
the sad thing is, the ones opposed will not adapt their skills, and they will end up like dinosaurs... it's going to be really brutal for them, but I guess they can make acorn soup and dumpster dive
Painting isn't easy either. First you have to draw, then you have to paint it in.
i fucking hate translating emails
idk bro i just wanna draw naked men π
AI isn't replacing any artists anytime soon, but AI art is fantastic. It's not just prompting, but in-painting,
*no comment
A lot of effort goes into AI art as well, with prompting just right, then post processing with in-painting, replacing parts here and there
Phenomenal non existent comment
fr
i mean its great
alright chat
24H of Nurburgring starts at 9am est
do I binge redbull or coffee
if you're a driver binge redbull, otherwise go to sleep
how abt u drink some water and doze off
But it's 6am. That's morning
Yall ever hate when bug bites wake you up at 5 am
bite back
It's almost morning and I have not had any sleep
tf dude, i cant even recall that happening
We got bugs out here homie
it's important to assert dominance when a bug bites you otherwise it sets a bad precedent for other bugs to follow
They bite
yes pee on the bugs
clean ur bed and house ? hello!
Homie the bugs are outside
You get bit when you go outside
Ouff
odomos can help
even tho its primarly for mosquitoes
Is this live? You got a stream?
It donβt matter tbh
It's not being broadcast yet
I'll send it over when it's up
damn are u in australia or something dude?
they have bugs all around the world
Jk

respectfully, what you just described takes significantly less skill and effort than drawing (painting) from scratch
but its still an art tho, it doesnt make it less of an art bcz the effort u put into is less compared to the others
Β―_(γ)_/Β―
To get something just right, it still takes a lot of time and work and effort and skills in GIMP or photoshop
(im not a big fan of AI art myself but i just wanted to point that out)
This for example, is purely digital art. Do you have any idea how long it takes, how much skill and effort is required.
This is Salvia Droid from Canada
Digital artist
a photoshop edit is not the same as a drawing
Like I said, to each their own
I support all forms of art, digital, AI, canvas, etc. etc.
I don't discriminate and I'm glad I don't hold such opinions.
that's much better than the AI slop
He is just saying that it's a photoshop edit. Do you know how many hours of work it is, how much it takes to hone your skills in digital frameworks.
but art is a broad term, its not only'drawing'
yea, because someone took the time to actually plan out the composition and actually create the artwork using their knowledge and skill
lol i did not say the image you posted was a photoshop edit.
i am saying generating an AI image and doing post-processing is not any different from photoshopping an image
it is the same skillset
Skill... set.
Not unskilled set.
Still it requires skill, talent, imagination, etc. etc.
i also did not say that photoshop edits were unskilled
It's like how the argument was 20 years ago when digital painting tablets came on the scence
i am saying that there is significantly less skill involved in a photoshop edit
Everyone was like, oh tablet art isn't art.
It's the same dumb argument again.
Did you see the painting I posted? Of Salvia Droids art?
people who said tablet art isn't art are fools because the artist still needed create the composition from scratch
yeah, it's an amazing work
I'm not nearly as good or skilled as him
I wish I could make art like that digitally.
That guy knows his tools and has a killer imagination
No different from a real artist.
Here's another Salvia Droid piece
As you can see, it's not 100% digital.
It's a mix media piece
I do the same. I take my art and digitize it sometimes.
Then add layers upon layers upon layers of effects etc.
If only I knew how to use the tools the way he does, I would be unstoppable!
I like the upper part, but the lower part is too simple
u still can
I think he uses photoshop and knows intimately. I use GIMP and I barely know it.
I absolutely love Salvia Droid
I would like to meet him one day
this is actually fire
Seriously this dude is so badass
How does he do it!? OMG
Anyway
I think I should get some sleep
It's almost about to be sunlight soon
or binge redbull
Ew
and yolo
yolo
I don't want to poison my body with that stuff!
technically redbull is just herbal tea with lots of added sugar
Pinged
@signal mica previous one isn't doing it. This one is, but you need to use a VPN
https://www.youtube.com/watch?v=oFBUkzV0vFs
his art would be rlly good to enjoy if you're mid trip 









@signal mica get pi 3.14159265358979323846
lul I managed to run out of claude max quota for today
the work it is doing is actually pretty hard
what big rock do you have your agentic slave breaking into smaller rocks
translating a book that is extremely hard language wise
I can't identify it on public chat for reasons
send me a messenger pigeon
wait
it's probably some degen stuff
just learn Russia? It's a pretty cool language
They have many words that English needs entire sentences to explain
Would unlock a lot of rich literature and other media as well
And you could talk to russian hackers on various sites I need not name
amazing\
Yo
Ill be writing a report for cpts prep for the unofficial list
Ill need someone to take a look at it
@vestal tinsel been playing this a bit on controller this morning, it damn good, an impressive play test (pre early access)
Highly recommend giving it a go while the play test is open!
Factorio has my soul π
Who said I was resisting?
let the efficiency flow through you
i can hear this
if the lanes ain't full it ain't right
π
Now do a zero signal train setup
no! π
The factory must grow
it can grow with signals.

did you see the get on factorio one
Weak
Bruh
I wanna make a mod that makes the biters behave more like tryanids
and instead of just rampant attacks, as you begin to expand your territory, they begin to attempt to dismantle it more strategically
I.E. taking out supply lines (oil pipes, railways, space stations) and then just dipping
I've always loved the idea of an adaptive game enemy
Biters are too easy, so I just disable them entirely
love a good orbital strike
They end up just being a chore
it adds diversity imo
it's why I like it more than satisfactory
but that's just personal preference
You just need a harder mod, like space exploration. It will take you 400 hours to finish lol
hey is there a basic list / general tool list for htb what you need to download from github / gerals pass user list/ i rollback my Kali to clean my disks and frogott to write down the tools i installed if not
if found this but i think this isnt everything https://github.com/kmahyyg/my-htb-tools.git
Yeah I saw martincitoopants play it
Just get what you need as you need it. Trying to keep a Kali alive is an effort in futility lol
Looks way cooler then the base spage age expansion tbh
yooooooo
CS2 anyone?
For sure, and it even makes the start a lot more involved. It's not as easy to just make a bus for everything
ok thanks
its less characters than localhost
it's just wrong
You can change the name in your hosts file lol
bro hates without reason
get those disgusting colons out of my address space
I use lb for loopback
Guys?
(I refuse to adapt to IPv6)
IDK if anyone plays CS2
Cool
wait i have to use hexadeciaml?
Vro just learned the reason lol
Just wait until you see ipv6 subnets
yuck
Now do ipv6 vlsm, for even more efficiency!
subnetting nromal ips is hard enough lmfao i aint doing this 128 bit bullshit
Do y'all think we'll see the full takeover of IPv6 in our lifetimes?
not while i am alive
I know it's used commonly and enabled on most modern devices
but like do you think it'll make a full takeover?
Probably never, actually. It's really only needed at the ISP level.
NAT exists
See this is my assumption too because of NAT
Man I love watching videos by Ryan Montgomery. great guy
Mods, we got another bot
so u just follow the poor guy around?
you know who'd say that
how long do u watch him
a bot
Literally today a week haha
generate me a react component saying hello world
Enters the server and immediately advertises
Can i use chat gpt?
I ain't advertising. I legit just signed up to HTB today lol
no bro do something original
Seen like 6 accounts do this in the last few weeks
soon
you can do a few boxes rank up and prove rat wrong
btw
imagine if this was "golam net/http server"
Ay be nice, they're talking about someone in cysec who they like
I want to...But I kind of did a small doodoo. I closed the vm so now i need ot wait a day
i dunno bro but i cant see myself typing hexa decimal or subnetting that π
LMAO
mad respect to the guys who do networking
hey im new to HTB
welcome to Earth!

Sadness touching skys.
Did we get another lpe this morning yet
Yes
There was the one yesterday, but I mean today
yo if i did insanes but just followed the writeup the whole time would i learn stuff n is that frowned upon
No I think
worse exp ngl
word lol
If you follow a recipe, you can make food, but that doesn't teach you why you used the ingredients
i used the curry powder because it tastes good, duh
show image
but the cheesecake is fucked
the official writeups kinda tell u why tho
start the box, have a go, and see how far you can get, build a list of suspicions and then validate with the writeup, once you get past that bit, do the same with the next step
It's not the same. You aren't identifying the why. You aren't understanding the vulnerability.
There are no shortcuts here lol
You either stay a skid, or learn the material
well i still feel like a skid just grinding easys and mediums 
ill stick to what im doin for now
Grind the academy
i do(ish)
You'll learn more crushing easy and mediums than you will followng insane tutorials
Insane machines are just funky amalgamations of lesser machines
guys im new but i cant really do anything in HTB because i need premuim
that kind of sucks yk
?
ohhh
Guys
I am thinking or need something i could be doing to earn some money for survival
What can you suggest me please ?
ah that sucks
darn free things!
Job

if ur just trying to survive idk if its a great time for cyber lmao
this; this applies to any high tier work
ippsec writing about ipsec
well cyber job market is especially fucked rn
Are you learning about networking
unless the job market in general is but idk
Rule #1: blame the far end
dns

Pick one
blame dns it is

whole economy is in shambles
blame golam
i will do it again
it's golam's fault the economy is in such rough shape

idk bro i made $1400 last month from stocks goin up
which all
hey I'm not complaining about my portfolio either but that's pretty outside the average
wdym
Did you sell them
which all stocks
hwello people
SPY, VOO, QQQ, VXUS, VEA, BND, IJR, VNQ, DBC, SCHD
ETF's mostly hm
wise
Mine have been going up $2k a day recently
low risk
It's nice
tru
im too stupid too stay up to date
note:- hantavirus gives a good opportunity to investors if it were to get serious. just saying
how much have u invested intotal?
i did hop on the covid investments and got out with 200x
ye thts why i said 'if it get serious'
Technically 0 since they're all RSUs
i was literally only wise enough to play rblx and watch pokemon and naruto at tht time
nice
golam71 the networker
Invested just before COVID hit.. got out a couple of years later breaking even because the investment firm were shite
0xqn the chatter
Monzo on medium has done pretty well through all the turmoil. Wouldn't trust myself to do shares lol
First message here this week βοΈπ«©


was it a good return overall?
No, I broke even then escaped the shitty firm

They were terrible, recommended by the bank of course..
Schroders they were called
g0blin invests in hantavirus
I invest in your mum
40 years old by the way π«©
she's that kind of bank
Dish crap get crap
that's a pretty big investment... not much potential there as seen by her product....
ok and
who is cycloth
ty for bringing my bio out i love it β€οΈ
Sorry for partyrocking β€οΈ
my boyfriend
@wooden python
hi
he's half scottish
no offence
is the other half chinese?
other half is jewish
lmao
Why you looking for chinese people?
cause i want to have friends all over the world
china / japan / south korea is usually my blind spot
can yall stop doing this lol
Hey man, no politics
Jew = politics?
i forgot his specific group that he's from
Not yet
no politics is what u mean by the gif π©
that's not even politics it's just straight up anti semitism
hi

why am i being so tired nowadays
anti semitismπ€£
yeah you could say that tbh
Now that you say it, you are right, especially because chine has good Hackers.
Oh yeah he's half buddhist
i slept like 7 hours last night, why am i still tired whole day
Anyway, can we talk about how my boss signed us up for the global CTF and then just didn't show up? 
Oops
anti septic
he realized that he cant win against you
victim card declined
it's also an ethnicity
lets just move on its nothing crazy
there is a lot of jewish people all over the world
At least he would have had enough AI tokens to compete with some of the other teams
is his ai bigger than other companies ai?
be like me
sleeps 4-6hrs at max and be productive

Golam71 I'm not aggressive as others want you to believe, I'm just here to talk and joke with others, I have nothing personal with anyone 
No, I just know that he pays big money for his AI usage, while I pay like Β£20
Is he Ethiopian Jewish?
yea i know all good but many people get offended
Even if I wanted to compete with team 55 bloods, we had no chance
Whats your secret fuel man?
is that why he is the CEO 
i got 8 hours of sleep few weeks before, i was unstoppable then, had a banger gym session where i got a deadlift PR, played like an esports pro in video games AND completed my subject easily
i'm actually not sure if he's comfortable mentioning what type of jew so i just tend to say jewish
given the whole marginalisation thing

there are different types of jewish?
he's a hacker
yeah
he works too ig?
I just think half Scottish half Jewish is a very funny way to describe someone
lol ok
well today i learned
All I am going to say is that his reports suddenly had a lot of em dashes around the time chatgpt started becoming more popular
wut about rubbish?
he does vulnerability research
i see
who we talking bout
<@&861185840277487616> can someone deal with 0xqn being antisemitic pls it's getting tiring
cyloth
antisemitic?
Bro what
ahhhhh
cyloth
plenty of people identify as jewish, there are ethnic subdivisions as well but it's easier to just say jewish
Its like saying I'm half italian and half christian
Haha ew
But that means you have some great seasoned food at least
vro i literally told u not to do it 3 messages ago π
which is also unhealthy since its filled with carbs and fried in fuck ass amounts of oil
i do have a banger beard tho
let's maybe not erase the existence of jewish people, whether they follow judaism or not... i'd like to think we learned from world war 2
lets not erase anyone's existence?
Yeah that is true, we had to edit our recipes as we went through them to lower down things like salt, oil etc. One recipe wanted like 5 ladels of mustard oil for a small portion
that's a good idea... but right now specifically there's anti semitism in the chat.
Wait can yall erase my existence tho
where is it
slow mode til y'all calm down and move away from this topic...
And for whatever reason like half of the garam masala that we had
oh slowmo 30 SECONDS HOLY FUCK
just asking cause i just came (damn 30 sec slowmo)
man one of these days i gotta make the limit to 5 minutes
the jokes about jews with the money thing, the trash vs garbage, victim card, saying they're not a people, etc from 0xqn


30s is just a tease, make it longer W1LD
This must be a joke...
put ||1 hr||
6 hours plz π«¦
Make it five minutes, erase the existence of general chat
ah ok, no yeah jews are ofc human beings β€οΈ and we must not say that
BUT THEN WHERE WILL I YAP???
The void always listens
nice
i know religion and ethnicity might sound weird but if someone doesnt feel good abt it just avoid it
you dont need to engage with that person
Can you explain to me what I'm doing wrong? How can you be antisemitic by just sending random images?
that is what the ignore button is for 
I just don't understand describing someone as half Scottish half Jewish, like Ashkenazi? Arab? Ethiopian?
Still have avoided blocking anyone since that whoopsie last year π
You will have to state your case wisely, and thoughtfully. When you press enter matters most.
not saying ur banned or anything just saying avoid heated discussions
LMAO
Don't mention it again or you'll become antisemitic
What oopsie? π
Just me throwing toys out the pram and announcing blocking someone
arab jew, but it's just easier to say jewish - and dont even start with your bs 0xqn, you know those gifs were out of line
Does that still count if you accidentally mute people?
It all got out of hand
wild
π€£ haaahaha, no idea why I had them muted tbh
He probably deserved it at the time 
Must've been audio feedback on a call in the past or something I guess π€·ββοΈ
where are u from
if its comes to juice then you're always 100% the problem, otherwise you can do whatever you want
i'm half english half egyptian
you server mooted them instead of just client mooting them didn't you? 
No just muted for myself
Everyone else could hear them, and I was apparently talking over them until I realised
nice interesting
You couldn't have explained it better
@eternal mango when you gonna stream games here again like you used to do
with moderation comes drama
LOTS of it
yeah that's the issue with muting someone
Hahhaa rude as hell
I could try streaming that game I linked earlier, but not very good at it, only got a few hours in
nah, don't start that nonsense. reacting to somebody's existence with rude stereotypes is racism but it seems that you're just another extremist
pls do
My voice is buggered too, so won't speak
much easier in text chat when you ignore someone you don't gotta read their messages, until everyone replies to them and you don't have enough context
and that is why you're best mod
but yeah I could stream some of it if you want
stream with story times again
slayy π
i guess that makes me a drama queen
Sometimes I say "Man, I miss being a mod on discord" but then stuff like this happens. And I am happy to just walk away and grab a coffee
now give me 6 hour slow mode plox
i might be, i actually hate everyone equally so dont worry about that part
judaism is a race?
30 seconds is the limit based on hackster
hackster is a chump, make pr plox
Am in general chit chat, but yeah no mic atm, throat is killing me
get better soooooooon
oh thank god. it's just that ever since the genocide in palestine everyone's decided to go all ww2 on jewish people and it's an absolute joke. it makes a lot of jewish people who are against the genocide terrified for simply existing
Golam, bubbla, you could make the slowmode go away
i could but this will raise more problems
no, i lieks it
for the time being its good
back in my days we used to block people and move on but its 2026
yes yes always the victim, dont worry about that part we get it
Youβre the boss ( well technically g0blin is, but you get it)
Jews mentioned --> slowmode
i feel soo bad now that i'll go get a cold drink, and finish this project.
Block and move on is still a sound approach, but maybe slightly difficult when you are representing a fairly large organisation
how DO they do it
Hey, let's stop arguing. Long live the legitimate state of Israel, long live Judaism. I hope your relationship with your boyfriend lasts forever. β€οΈβ€οΈβ€οΈ
its not that when they are mntioned its more like the statements that come along with it
any political discussion that doesn't get too heated really...
you'd think so
anyone crosses a line and we start throwing out mutes and bans
any way i got eyes only for @scenic maple, and he got some kissable cheecks irl
what bro does instead of doing cwes
what the fuck is this nonsense lmfao
you don't think lines have been crossed already?
they watching g0b play games instead 
building a portal for client, but i got my storage on two NAS and one's cache is failling right now, its been a hustle.
i hope you're joking in the two first parts.
replace what happened with any other race and it would've been a ban for 0xqn
gatekept by hackster
bro has the code to hackster
its open source
I'm using the same strategy as you, but let's really stop it, we're all friends here
wise decision
nothing seems overly offensive, just trolly, if you have a specific grievance you can bring it up with us and explain why it's so offensive, otherwise just seems like semantic discussion over religion vs ethnicity + some troll / ragebait gifs
time to get opus out and find some hackster CVE
we're not all friends here lol, i could count on my fingers the cool people here.
"Strategy" i mentioned my boyfriend is jewish and you started using so many rude gifs and expressions
would have been nicer if we became friends a few mins earlier
The conflation of Zionism and being Jewish has confused and angered the simple Italian racist brain.
Local Scottish man plays rougelike
@warped plank this for starters
it always does
From the country that brought you fascism, we now have this moron
anyone worked with openZFS and Pacemaker before ?
now it starts again...
i've expressed my thoughts on this ages ago, that shitheads love to dig up to try and prove something.
You guys didn't even last for one run π€£
just a trolly gif, the ignore button exists for a reason.
Thanks for sticking it out for 3 whole minutes Vader to see me fail
it's racist, not trolly
π
A fricking credit card isn't racism pal
if you're hurt by everything you see online, its better not to stay online.
Imagine not using the block feature. Can't relate.
Oh, okay, yeah this is ... yikes
close the damn laptop and your problem is solved. imagine someone online ruining your day.
please elaborate, I don't see anything specific to the jewish community about it...
i am Palestinian, born and raised there, and have been personally affected by everything happening, but i still don't hate jews cause there is a big difference between judiasim as a religion and zionism as a political stance
this isnt 4chan this is a regular area, i'd expect there to not be the rubbish i'd see as a part of the usual rubbish
people when nuance exists and genuinely don't understand the difference
it's a stereotype, loads of caricatures have jewish people going after money etc
You're reaching.
naaah sometimes you'll see shit you dont like, and its fine so just let it be and move on. if you argue with everyone you'd never finish
Itβs alright mate, Iβm kind of having a rough go at it with a game Iβm playing
i mean not to mention yesterday someone literally capitalized the word "COIN" in coincidence
exactly, yet some people seem to not understand that for some reason
You can't be realπππ
Keep at it! Only given this an hour so far, it's fun
can we all just chill
block, ignore, move on
Hit him with a stereotype back "I cooka da pizza"
been telling this for ages man no one litsens
zionism has a lot to do with evangelical christianity too lets not forget
i'm not gonna stoop to his level, it's disgusting behaviour
I mean that's one of my main issues with the server; the neutrality of moderation just opens the pit
@eternal mango do you recommend ZFS with Pacemaker ?. for someone with no money and 2 workstations laying around right now
He eata da meatball
The difference is that I don't get offended by words that are said online, I accept any kind of irony, I don't have a stick in my ass 
message deleted, but since it's a one-off there's really no reason to tack a ban/mute on the dude, even I have em ignored cos they are a known troll.
No one asked nor cares
let me bring up all the others that he used then
holy shit man shut the fuck up
this chat is just getting long for no reason lol, could there be some timeouts ?
Italians on their way to have their 20th child (their economy will collapse in a few years)
make this a pr, logic looks correct to me.
The fact that this is surviving slow mode is impressive
Moderation? On the HTB discord? Aren't you asking for too much?
bro thinks i dont know what this is π
moderation doesn't happen anymore /hj
im still mutted on THM untill this day
@warped plank this was another one, when i was pointing out the marginalisation he had some very interesting responses
Iβm banned from there for being a βtroublemakerβ
the people that gave a shit are long gone
@gilded fernthis seems like you
Were you being a troublemaker?
watching internet arguments are my guilty pleasure for sure
me and kyand where banned for asking there for what ASLR is for, and we kept getting wrong answers until they perma-mute us for correcting them
thats actually accurate damm
Vader your existence causes trouble, obviously (i cannot go further into this without turning political, unfortunately)
Ha! Nice one!
did you see the newsβ’? if not i can dm you the article that talks about it
Iβd like to see it.
Ok I get your point, I've slapped em with a temporary mute but the Ignore button is right there 
i'm glad you understood that, thank you β€οΈ
address space layout randomization!
slowmode stays tho
Ignoring bigotry doesn't solve the problem, but yk, not my problem anymore
i think everyone's over it now that the main offending party's been dealt with
Bro I can't complain on this with slowmode here π₯
it eill eventually be removed dw
Address space layout randomizarion is a topic for lower level hacking though, you cant really expect a bug bounty hacker or a pentester to know about it enough.
bro is running out of storage and time and still wont give up on mac
exploitation wise :c
The slow mode was added cos the topic wasn't being let go... I know there's a ton of trolls on the internet but it ain't healthy to keep the topic going when you can simply ignore em and stop feeding em, they wanna get a rise out of ya and when you respond they keep going... even they were tryna stop the topic tbh
Aight, back to the rust grind. Got to rewrite all of my SQL statements
Yall need to listen to some lil wayne and chill
Defeating ASLR is still a mystery to me. People say oh just add the difference in address and im like I wish it worked that way
not using an ORM in 2026?
Thanks Mr W1ld, you truly are a pro gamer.
bruh that's for js
wait wait wait, sir sir sir, lets brute force 64bit addresses
i can ignore / have fun with trolls, but with marginalised groups i tend to not stand for it because you never know who's who and who's lurking, i wouldn't want anyone to come in and feel uncomfortable because of things they can't control or even end up avoiding this space altogether
wait fr lmao? orms are language speicific?
There are orms for rust though
Technically rust does have some ORM crates I could use. SQLx is just better
I spent a good month trying to defeat it, i couldnt do it in 2018. But then again i was dumb too.
no but you js hipsters will install anything
it would have been the same even if it was any other ethnicity pls trust
I understand but it's not your job to deescalate (heck you were even escalating) or take a stand, report it, move on. (also helps to be specific cos like this instance we don't immediately see the issue)
my reaction would have been the same for any other ethnicity too, i just don't stand for it
if there'snt like a printf() i dunno what to do legit xD
See that's your problem Wolo, you give a shit - the time for giving a shit is long gone
Why we timing out again?
big drama
Bc of a troll
Always
I came here to talk about the canvas hack
"BC of trolls" and rule 1. "Don't be a troll"
I came here cos I saw 2 ICS machines in 1 month 
cant find the fight, too much text, you guys gotta start a new one
When?
i kinda started diving more and more into devOps and NOC, and sometimes do ofsec
your mother
Spy from Team Fortress 2 be like
Well. Im just surprised that after more than 10 years of ransomware attacks there still isnt a solution to it at a kernel level
I hate this meme so much omg
is there a better system than the serious rule break then? e.g. ticketing? it would probably have been better to give it like that
Damn, thought my twin stick game was getting better, but just turns out there's some light aim assist in this game π€£
most mod's DMs are open for rule breaks if you don't wanna do it out in the open
I would usually just DM a mod
although a ticket system should probs be created
I think blocking him would have been the best option tbh
it did take some time for them to do it, but i think that was my fault for assuming the stereotypes are common knowledge but after explaining what happened they did punish the person so i'd say i'm happy with the result
my status is also very accurate cos I only really change it to DND if I'm very busy.
Great Job Mr Mod!
Call fuckwit - block - move on
But canvas actually paying hackers to get students data back is hilarious i will admit
how else do you get data back?
backups π
What was the Hack?
If they lost it they should start by looking in places they might have left it
Theres tools people make for specific ransomware to decrypt.
yeah... my lil-bro both hates and loves it, hates cos he can't get required work done, loves cos now he has an excuse and is given a ton more time
If one doesnt exist then you have to wait until someone makes one. Or hire someone to make one for you
They still fghting over whatever they were debating upon?
If no solution works just accept the data is gone
or just register a domain that the ransomware some reason checks and decrypt everyone's data
You'd still need the keys
oh yeah... what'd the domain do? stop the spreading?
Unless they do a static key, but that's unlikely lol
I mean... how else they gonna decrypt when you pay... oh... I see
Inshallah
Wannacry checked to see if it could reach a domain before encrypting to avoid sandbox analysis so people just blocked the domain
Are you maybe thinking of that
Didn't it check if it could reach a domain and only encrypt if the domain was not alive
Backups with snapshots id say are the best solution, not with daily ones but something like hourly
I imagine they would reach out to get a dynamic key, too. Like, if you hard code a key, any reverse engineer can get it back
No, only if the domain was alive
if it only checked if the domain was alive then how come when the dude registered it did he stop the spread? wouldn't it need to be the other way around?
Fuck maybe it's all blurry to me
Btrfs has a snapshot feature my friend kept using it over and over again because he kept touching files on his install
ewww file toucher!!
introduce him to nixOS
can't touch the files even if you wanted to cos they're all linked to a single config file that you can modularize and get all those files back...
a horrible way to die
Maybe i should just shove him to an immutable
but hey, at least it's in a different consistent configuration language 
Im jk ofc
Yeah I think it was this way around, too
#magical-tunes message whats' this about? Anyone know? It's not a magical tune.
Theres actual you know like
Programming techniques you can use
To avoid a lot of attacks
Cat needs a firmware update
Like Go for example has ways you can implement backends to avoid CSRF and SQLi attacks
backend: "I'm not the cybersecurity guy"
You can also hire people who are not stupid you know keep your organization small so that your vulnerabilities stay minimal
How are there Go specific thing? The techniques for security are basically the same
I tried to write a CTF for work once using like Django I think and it actually made it annoying difficult to do the attacks that I wanted, because the common utilities all had protections.
While Laravel just has like a secondary template type that instantly allows for XSS
They have libraries and API that....its a lot to explain
My friend did it he can say more about it
Key word is avoid not prevent
Yes Django makes it very hard to do a lot of attacks
It is more so imo, that a lot of newer programming languages actively implement fixes and prevention techniques at a lower level, while say PHP, just goes YOLO and lets you do LFI, DoS, XSS etc with ease
what if you get hired then realize you work with a bunch of idiots
I got like 3-4 hours of sleep
@molten bobcat can say more about this 
That's it
to him, anyone who disagrees with him on anything is an idiot.
So not a good benchmark there of idiocy
Sql Iniection is prevented with prepared statements, which as I remember are even mostly implemented in the database if i understand them correctly
This is just life
Fyi, I recommend everyone watch the docs/listen to the darknet diaries on this. It was incredibly fucked up how everything went down
True PHP is like ... really bad design
Doesn't even have to be prepared statements, just don't blindly accept input without checking it. Don't accept user input directly into queries. That's the key.
But nah like what i mean is if a company or organization cares about security you.... wouldnt outsource it all, youd have a team inside that is concious and touches your files. And then have an external entity act as a red team or purple team
The problem is developers don't really learn about vulnerabilities enough. For example template injection, if you ask a developer how a template editor could hack your app ... this makes me remember I have to ask a colleague if he considered implementing a sandbox mode in the one app he is working on, oopsie ...
I think a system design book i once read talked about it
If someone tried to SQL inject my app I would simply disarm them
just use an orm
Developers have a lot of blind spots, and it is easy to do. You find a function call or an inbuilt utility that magically makes your code work, you may even try to harden it abit and you just don't notice or think about how an idiot would use your app. And then suddenly your database has dropped the user table because a script kiddie went "jee whiz, wouldn't that be funny?"
ORM deploy slow patterns like active record or data/table gateway and other
But yah, for noobs ORM can be a blessing
the question is IF it works does it scale
we first have to get to 20,000 users to start worrying about 20,001 users but thats maybe just my startup hustle mentality
A simple query builder engine is good enough. Generate safe sql queries via your programming langauge.
Im not a fan of shortcutting anything. The only thing i would say is using like no more than 1-2 frameworks
While here I am trying to optimise my code when likely 50 people at most will visit my website at once 
ORM defeats the purpose of relational engines and their features. DBAL comes into play and the ORM treats every engine like it's the same w/o optimizations
Then building scalable solutions becomes the next big deal youd need a guy who wont mess up your wire racks
I haven't come across a single ORM that does it right.
but again thats if you have that many users to care for it
Added stress and more people high on caffeine required
A lot of experienced engineers avoid heavy ORMs for the same reason: abstraction leaks, poor query visibility, and losing control over database-specific features.
DROP TABLE general;
The nice thing about ORMs is imp the automatic mapping from tables to objects though. So you don't have to write 1000 SQL queries
For everything
yeah it has its drawbacks its just makes things a bit faster
not in terms of speed in terms of dev
its the same as everyone shoving react without needing it
A decent query builder + selective raw SQL is usually the best engineering tradeoff for someone who wants control and performance.
Yeah, and I think like a lot. Also ORMs like hibernate still allow to write custom queries so ...
For noobs, ORM is great.
This reminds me actually, I asked claude to fill in a file so that I could try a bunch of CSV injection attacks at once. The bitch literally chucked this in there
Claude trying to get me fired
Loll
Did you remember that one time when a person had an SQL injection payload printed out in their license plate and when the OCR of the speed cameras scanned the plate and matched the license number against the database, it dropped the entire table instead
Hach developers and security 
No schema SQL ORMs are even faster at the tradeoff of control.
Checkout RedBean ORM for PHP for example

building malls is hard π«©
I love Eloquent (ORM used by Laravel), and the Laravel ecosystem as a whole. You've never seen PHP run so fast than when running with Laravels Octane PHP interpreter (instead of php-fpm)
That's the one framework I haven't yet gotten into!
Their "serverless" deployment stack is pretty cool too.
I got out of php development years ago and I haven't touched it since
It's what we use π
And I didn't need something as heavy as laravel to do some projects I needed
So I use Redbean ORM
Whatever gets the job done!
You just php, and it creates the table/schema for you
$post = R::dispense( 'post' );
$post->title = 'My holiday';
$id = R::store( $post );
RedBeanPHP will create a table called post for you in the database and add a column called title, big enough to hold your text.
You never touch sql or db or have to pre create your schema
It auto detects
Yup yup, Laravel as a whole have a great history for maintaining, improving and shipping new parts for their ecosystem
Ewww, PHP
Then why does HTB grind to a halt every machine release 
β€οΈ
what up, cuz?
not enough but yeah it's something
I got another 4 hours after we talked last
so maybe 7.5 for the night
An ex colleague of mine always said I have stockholm syndrom from PHP every time I said "I kinda like it now" lmao
with a 2 hr break in the middle
We don't use Octane as the PHP backend currently AFAIK
We almost did when I was working on a project to ship the platform to k8s, but that fell by the wayside unfortunately
should be shrimple to implement? do it now before next release, lets see the powah
Might bring it up with the engineering / infra vps to discuss, it'd be interesting to do a performance a/b test
I'll just ship it and run
On Friday
π
Also one thing I don't like about PHP is that it has wayyy worse performance than anything else
in all honestly plz some speed/db perf would be lovely on a saturday
anyone know much about phone chargers? Like how do they power things? For example, my phone's original charget block, USB-C will charge at "Super Fast Charging" speed. Where as when I use my 65W laptop charger it only charges at "Fast Speed". I'd think the bigger block from my laptop would charge just as fast but it don't yo?
Doesn't HAVE to be though
Except python maybe, didn't test
PHP has great performance, better than python
Python is the worst.
I have a massive urge to drop the entire database schema of my workplace
bruh this is cyber security discord wtf do you think the root cause is?
GPT but you get it
PHP-FPM is the standard, safer way to host PHP/Laravel: each request is handled by a worker with a mostly fresh lifecycle, so it is predictable and easy to operate, but a typical Laravel app may only handle roughly 50β300 requests/sec per server depending on code, database use, and caching. Laravel Octane keeps the Laravel app booted in memory using servers like Swoole, RoadRunner, or FrankenPHP, so it can often deliver 2Γβ10Γ higher throughput and noticeably lower latency, sometimes pushing simple Laravel endpoints into the hundreds or thousands of requests/sec range. The tradeoff is that Octane needs more care around memory leaks, shared state, worker restarts, and package compatibility, while PHP-FPM is usually the better default unless you have measured performance pressure.
I suck so much at coding. I only passed my Python class with chatgpt even during my final exam π
and I've seen this kind of performance boost personally
I use php fpm with nginx.
-# inserts language war
have you tried go?
Yes, I understand the value of coding. But that doesn't make me like it anymore. I appreciate Chemical Engineering but I also don't like chemistry.
Yeah, love go
the worst is mod-php for Apache
Let me just rewrite HTB in go, brb
That's the absolute worst for performance
LFG!
Every time I benchmark even simple PHP apps, I get like 100req/s at max, without using a DB or something which is blocking
Joking aside, years ago we did briefly consider a rewrite away from PHP, but yeah.. that didn't happen
I understand the value of auto mechanics. But I hate working on cars. Doesn't mean I don't appreciate those who do.
obviously didnt happen π
IN fact, I value you them more because they have a skill I'm willing to pay for them doing.
There's SO much optimization you can do, even just with php-fpm, and obviously with DB queries and appropriate indicies, cache policies, shared views, etc etc etc
If you're truly interested, do check out Octane
If not, then well you're welcome to your opinion π
its okay danny i hate coding too
Sadly I can't rewrite our legacy PHP app ... again π€£
hahah
Oh man.. one place I worked a while ago.. it was still sitting running PHP5.4 or something
..because updating it was "not an option"
I hope that system is dead by now
I still remember php 3 and php 4
-# narrator: its still alive
My thoughts on capitalism every day
Bet the backbone of that place that ran in BASIC is still going too
..because it still works
if it aint broke dont fix it
We had ONE guy in the company who still coded on that platform


