#general
1 messages ยท Page 749 of 1
I am currently building a blog web app in Rust+WASM, but I basically just gave claude my "brand" and got it to create a professional CSS design system for me
I dunno
I used Claude once and felt immediately guilty and disgusted, but I was quite impressed at the speed to churn out a neopets style click an image to proceed to the next 'area' website (to connect my digital illustrations in an adventure style)
All my years working with it got me second place in a competitive CSS thing at HTB a few years ago
Worth it
๐คฃ
2 TBs linux only ๐
xD
i feel happy
What was this about? Designing something for HTB or was it hacking related?
Nah was at an engineering meetup
Glad you genocided the Windows virus
We had a CTF, and this competitive CSS thing where you had to match the source image as close as you can, just with CSS
g0blin what is your job at HTB now?
im suprised how Cachy OS always survives everything
it JUST NEVER BREAKS FOR ME
being old
People were debating on what you are currently the other day lol
Has anyone else been getting what appears to be pug butchering scams from here by accounts saying they're new to cyber and asking for help?
Didn't you literally break your install yesterday? 
Role changed to Chief Architect some time last year
Oh
no actually
I THOUGHT I did but somehow it survived
Something I am curious, maybe the wrong place to ask, but what are some ideas to mix art and cybersecurity together? I know youtube tutorials or similar learning resources might be the easiest, but I wonder if you have other ideas.
(Other people feel free to contribute)
i rebooted and it was back working
like nothing happened
i love the drive mounting thing in linux
Visualization of data is something I really enjoy
for now
im confident in my ability to maintain this system
๐ธ
Use librewolf ^^
Not if I steal ur entire pc
Find where I live
Already done
612 Wharf Avenue
10 bucks
india
What
Be more specific
10 dollars and I will tell where u live
uhhhhhhhhhhhhhhhh gujrat
If I tell you where I live can you give me 10 dollars?
Are u from Japan btw
guys can anyone provide me some useful blogs to hearn hacking
Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.
No.
How does CISA not have DLP for this lol
I live nowhere near Gujrat
I sent you my doxx
idk then tamil nadu?
im sick chat do i do a machine
Wtf
Nowhere near
Ye
no you might give it a virus.
i might have the hantavirus bro
been having those symptoms they keep talking about in the videos
you spelled gujarat wrong
that doesn't fit my narrative so i dont believe you
It's just a morbid fact that if you want to become batman you have to accept that you will have a broken back. Im sorry but it's the truth.
time to wear a mask, no, 2 masks, and take this vaccine, wait not that one, this one, also stay home, but come to work when boss needs to use his building
Herniated discs
aw hell nah
Batman broken backs are 1 and 1
and get your parents killed
Did anyone say 'batman'
badman
I feel bad for people who workout and have backpain but will continue to tell themselves their back is shit and then. Continue to destroy their backs harder to get a "stronger" back
lucky for me i dont workout
im 94 lbs man ill die if i workout
positive role model ๐โโ๏ธ
I got new monitor arm units, got a new KVM switch and a new monitor to use in horizontal mode coming tomorrow. With my work laptop, going to have a nice little three monitor set up
Like ive seen so many youtubers who are fitness influencers
morining folk
Straight up tell people their backs are shit. Im like well if you stop trying to set it on fire none of this would happen .
literally me
90% of those fitness influencers are scammers trying to sell you their "ultra ever lasting optimal health" course
Dude will tennyson is my age and he looks like a serial killer now.
From how much he works out
And focuses on health
bruh i just googled him, he does ๐ญ
does he look 31?
sounds like you were a bad guy as a kid
is that the "i used to be fat but watch me now" guy?
I....dont know but i used to watch him a lot when i was younger
Or just poor. Batman is classist af
You need to watch Griffith then
He does have a kind of thinness in the face that you used to only really see in very old and skinny people
Lets not go there
Yes sirrr
hm? whos that?
No dont dont
?
The real batman
what
Bro never watched berserk?
griffith sounds like a british name
Dont just ignore the griffith stuff you dont need that in your life
no?
Even heard about it
tf is berserk
He was a well written character
i mean ive watched some anime, yeah, but idk about this
Let me guess demon slayer and Jjk?
You are asking for trouble man dont do it
nah, naruto
Is there any website for bug hunting other than H1 or bc
and death note
be honest, is it weird porn? ๐ญ
No
No
Try searching it up
i feel like i shouldn't
what level is hacker level?
level 34
Trust me
Wdym
Yeah dont. It's not worth the mental cost.
Ignore our words
thank you
do i watch this or no?? ๐ญ
No
It will fuck your health
ok ignorance is bliss
The anime is good, the characters are well written, the story behind it is good.
It's a bit dark and not suitable for every viewers
ive been fooled by way too many people to look up horrible stuff on the internet, i aint falling for this one

It gets more dark in manga
I have read it
Maybe when youre an older guy and have experience with life, but not as a young man
Guts trauma in the recent manga panels ahhhh
but the guy said it was manga?
Just let. Him a happy guy
im 16 i think i have exp in life
We are talking Abt the anime
Hallicon wht have u done
what gets the most XPs?
I didnt know he was 16
Boxes
thank you
Insane machine
Watch Dexter xD
wtv man the best anime is naruto
U could have guessed from him being scared to search an anime name on Google
See Vinland saga
Bleach >
@rough mirage
never watched
The big 3 of peace ahh
But yeah if you want to be batman just be prepared for broken backs
seems cool, will check out
True, but Naruto has a special place in my heart cuz it was among one of the first anime I have seen
It legit will make u a better human
Yep my 4th anime
Vinland saga is peak
lol, how so?
You will understand
Btw pokemon and beyblade are anime too
...okay 
Why would I give u spoilers lol
You will have no enemies
i don't like surprises
especially if its scary
Bro u are weird
I don't agree with 'all' of their ideas
If you are upto manga read climber, vagabond
nah jk
'The Climber' was soo good
If you havnt watched it check out full metal alchemist thats a classic
Literally this survived me
@bronze lion where can I watch it in uk?
A guy breaking into your home is automatically an enemy.
@frail turtle nah maybe he is just hungry
Crunchyoll
Reallll
I did like uzumaki too( only the manga)
๐ช๐ป
Always watch stuff legally
No comment
or sail the seas rawrr ๐ดโโ ๏ธ ๐
i never pirated anything tho 
me neither ๐

anyway ill watch this saga one tmrw
i had another anime in mind
"devilman crybaby"
my friends keep telling me to watch it
Thats peak
Ive pirated many things. Software mostly but ill be honest i didnt like to do it.
yeah its on netflix so im gonna watch it
idek how to pirate
I will however put a pass on nintendo games for pirating.
like i was being fr when i said i never pirated
no you didnt
this never happened
Bro is self-snitching
they aint gonna come to his house and arrest him for it
I like the fight scenes
May we move away from the pirating conversation please?
ok mod
Ok
๐
It's against Discords ToS and while I know we aren't discussing HOW TO I'd rather not land us in hot water
will check out fs
Can u buy me an ice cream?
( Never asked u this year)
so can we talk politics? 
Going to DefCon?
jk
Nah
No
wish there was a british defcon
If you go to Defcon ill get you some ice cream
i wanna meet all the femboys
There's a Defcon Singapore and Behrain now. Maybe there will be others
Make sure to keep that promise for the next 4-5 yrs too โค๏ธ
My distro still hasnt updated its package for the linux kernel
england is too dumb for defcon 
jk
hi I have a issue on a non-retired machine, where to ask for help?
"oi m8s come one comeall, ann get 'ya beans and bread whilst we gab bouttem malwares. den weee outta 'av some tea annn crumpets"
#boxes or if the machine has its own channel since its one of the newly released you can see it under the HTB: Platform section
Damnnn
"oi bruv its chewsday innit?"
Also GNOME is really dumb for wanting to take away middle click to paste
Imagine using windows
3 years using linux
"we go' uh sly roadman oere eer innit"
Same timeline
2 years on vms
GNOME is just dumb in general
Windows doesnt deserve all of the hate! im a microsoft investor btw
I don't think they have ever made a popular decision in the last 10 years
6 months
You don't use right click putty style paste?
"u got a bo-ol uh wa-a?"
ik someone thats microsoft shareholder and he hates windows ๐ญ
hey guys
I use winders btw

like the sweet?
i wanted to share a walkthrough for a challenge but i see no information
Like Windows 11
yall ever seen those dudes with windows tattoos?
Although Bazzite looks like its on the up and up so may switch to that in the future since I only have Windows personally for gaming
thankyou
If it's for retired content, you're fine, but have a read over that article
You're welcome!
the challenge doesent say if its retied or not
unlike machines
its pretty obvious
when its retired u get the official walkthrough and the option to submit/view others walkthroughs
You should see a toggle for active, retired etc. You can use that to see what challenges are retired or not
There's a tab for active/inactive
If it says "Writeup Available" in the top right, it's retired
And yeah, check the tabs
Theres something in my ass ๐ต
Agree that could be better shown in the content card
can i dm ?
there is a fat batman meme
thats what he sings and then he falls down
Feel free to ask here, I may not respond right away as I'm with my daughter
If you tell me the challenge, I can tell you if it's retired or not
but I see what you see on the challenge page ๐
man why do i gotta do this tutor counselling
Survival of the fittest
it released in 2023
It is not retired
yet i dont see any " walkthrough" tab
dang
in 2 years?
It's in a category that probably does not get many submissions, so the retirement is not as fast
๐คทโโ๏ธ feel free to give us /feedback ๐
how do you determine if a machine should be retired or not?
What we need is more Insane releases so Hercules and Eloquia can go bye-bye.
That'd be a question for the content team, not something I'm involved in really
Stuff only gets retired usually when something new is submitted/published of the sams type and difficulty
ah right, got you.
Sitting at the raising canes drive through
How long does it take from beginner to able to might take the OSCP how many months?
oh so the new boxes basically replace the older ones?
If something has super negative feedback it gets replaced earlier but it varies
...but I imagine stuff is retired when a machine of similar difficulty is released, and then possibly picked by any sort of related subcategory
months? bro its gonna be years
I thought it was obvious or am I getting it wrong?
The retiring machine has to be in the same category as the releasing machine, then the dates are looked at for current machines for that category. The oldest gets retired?
id say 1.5 years
Yup! It is a great system
@sonic blaze 3 months good luck
LMAO 
Likely that is the case yes, but there many be other factors taken in to account as above
I am thinking 7 to 8 months
I don't know the specific workflow for picking the machine to be retired tbh
I am new to all of this
probably 1 year
You could do it in 3 months if you have enough time, and ability to drive yourself through the content and subject certainly
and i will do it again
But it's a big field to get in to
Not saying it's impossible, but it would be tough from zero
if you learn and practice for literally 5 hours a day, maybe
Exactly
but no ones doing that realistically
Me ?
I did
With a full time job and a little one
ur dedicated asf then
It was tough, but I enjoyed it which helped keep me going.
It depends how much general IT stuff you know beforehand
Actually, I have a question about vuln types when it comes to boxes/challenge submissions, should I get in touch with the team to ask?
How old was you
oh yes, enjoying the process would help tons
I am 23
im 32 trust
Check this out https://app.hackthebox.com/machines/submission, there are some reference links to articles also
Uhhh I think maybe 29, 30?
Fair enough
Cheers for the link! Will give it a look
there was computers back then? /j
Itโs something I really wanna do I have been traveling a lot the last few years
But have been in the field of tech and had an interest in security for my whole adult life and before
Go for it! You got this ๐
I work in retail at the moment
Sales
i rlly gotta step up my game if you guys are scoring oscp in 3 months
oscp would help in degree apprenticeships
I stocked shelves before getting my first tech job ๐ I see people pivoting from all kinds of fields
J do it after CPTS
Then itโll be easy peasy
The job market is tough, but people do enter the field from all over
@eternal mango you got any good recommendations where to start or what models and places to learn as much as I need thank you ๐
yeah ive heard ur advice before
never what
yo @eternal mango make this random guy mod
Not really, I'm self taught mostly, just keep yourself interested, shift areas if you are getting run down and bored, keep good notes, take advantage of platforms like HTB and others to supplement working on the OSCP stuff
Iโm gonna hit you in your British face
Read, learn, reproduce, adapt
i have an indian face 
I understand ๐๐ป
True only platform I wonโt use is tryhackme
Sorry ๐คฃ
yes we hate tryhackme
right guys
Right, back later
I could care less
its so much different than htb
sets the bars too low
Use whatever works for you. There is value everywhere if you can find it.
They trying to use a training bot the users are feeding it ๐
What does it matter which platform you use if it helps you grow
Itโs definitely suited for absolute beginners
Imagine you did some hard grind just to see a random east Asians beating you score triple in 1 day
Itโs like scratch but for hacking
frfr
Thm does have some good content to help get people at a lower level into cyber sec imo. Even some HTB academy stuff can be a bit too advanced for certain people
I hate that leaderboard shit, all stupid just get spam flags on THM, so it's all crap
Thatโs why I am with Htb
Which is also a good argument, especially for security I would say. But there isnโt much substance to it
Leaderboards wont get you a job! Uni will !
just the intro to academy on linux fundementals got me through otw bandit levels
We canโt get more able bodies if the bar is too high for people to skill transfer
Imo, tribalism for any content provider is overrated. Just use whatever is best for a particular piece of content that is the most accessible for yourself.
Need to get the fundamentals first
i had only completed the module till half point
Whether that is THM, HTB, Portswigger, Off Sec, MalDev etc etc.
They all have their own uses
Ye ssirr and they don't even know what is the basics, last few weeks ago a guy said to me that he is top 9k in TryHackMe and he doesn't even know Pentesting basics
๐๐
More training providers than original topics
Ive seen people argue the opposite
about the uni part
Different ways of learning fit different people
Itโs a different day and age tbh
Certs can help you get more technical theory
College can do that too but can also open the door to lots of networking opportunities
I would say UNI is good if you are not paying for it or it is really cheap def worth it opens many doors
(As an American I mean college as in university)
In this day and age without uni your chances are really low.
Im going to uni next year and doing so willingly, i think it will help me establish the right fundamental knowledge to get into cyber
even tho ppl say its not needed
i think its not something bad to have
Good choice lad you need it. It is really important
they fr be clowning a lot on cs majors nowadays
You donโt need to be good at everything in Uni, you just gotta pass the shit you need to pass. And lock in for the stuff you wanna pursue
Open source โ
Agreed, I'd comment on my history but as you said, it's so very different now.. and I was a lucky SoB I think lol
Cuz those cs majors expect to be spoon fed. Which is sad you should see the cs majors sub Reddit
fr ive done that already on the side
skipping out on highschool work just to do what i enjoyed
CS degrees have no quality control if you just use AI to pass everything you will be cooked
i think unis gonna be a good fit for me
It's over for me ๐ฅ
Itโs just a weird argument I feel. Cause thereโs guys who have been in the industry and remember what it was like to get in. And not so much that theyโre out of touch with what it was like, but I just feel the world has changed so rapidly over that period of time
I see
If you are going to school in US take advantage of collegiate CTF competitions
nahh im far from US
located in eastern europe
they dont rlly do that stuff here
The skills needed are way more technically profound then they once were
Even if they donโt wanna say that on paper

Idk about eu collegiate CTF but pretty sure you can find some take advantage of them
A modern day junior needs to have way more skill and knowledge then they think
Never said it was impossible ๐ญ just low
Your piece of paper simply isnโt just enough, but itโs a start. Projects, competitions, and internships are like mandatory for younger people I feel
ye i take every chance i get
Unless you can network really well and even then I donโt think you can have the former without the latter :/
Yes the people who just do the bare minimum in CS are getting cooked
Itโs a game of favor and genius atp
Need to SOFTSKILL MAX + HARDSKILL MAX + LUCK MAX
Yeah dude I was dating this girl for like three weeks and she was a CS major, but dude this girl was struggling in her ASM class
Im talking year one ASM
Sheโs on her sixth year now?
Isnt year one asm like jmp
And โwhatโs at this addressโ
Assemble this
^^
Donโt American universities curriculum just slam asm inside computer architecture class
Not this one, this one was more โassembly 101โ
There would also be asm in a computer arch class though, yes
And I guy I know in his final year is taking a โscriptingโ class. Where there learning exploit dev 101
So itโs all over the place lol
Yo ass better drop some fresh memes today i aint seen none
let me see if i have anything for you
Never heard of a pure asm class in any uni that is new
Hey Guys working on a project, anyone of you have good sources based on network segmentation ?
When i have children im not giving them an arduino. That's insulting.
when i have children im not giving them a father
When I have children I will not give them Active Directory machines
when i have children im not giving them any htb machines
No I am going to give em dante lab as their first toys
yo why did i just figure out tracks are a thing
Paid
Any recommendations to start from beginner to OSCP ?
I use free version open source
Hydrogen baby vs coughing bomb
yo btw do you need a vip + version to get the hacker rank ?
or jsut helps to have it ?
do all the retired content, follow all the walkthroughs until you feel like you can skip steps in the walkthroughs because you start to figure out what the next steps should be, then start trying to do retired content without walkthroughs as much as you can, then do the active content, and if you can do that you will pass OSCP no problem
Skill issue you need 8-9 active machines
thats it ?
You cant get hacker rank anymore
only 8-9 ??
actually if you just complete all the active content you get hacker rank much easier
what do you mean
stops working for 2 days
le js
It was replaced by new ranking system
discord ranks are not updated to reflect the new system yet
Yes 8-9 active machines
As others said, the old ranking system was replaced, and I imagine Discord will catch up in the near future, buuut
Got hacker rank cuz I wanted gif perms in like a week and never played machines again. Just do active boxes pretty sure by the time you reach your 10th box you unlock it
Ur own mixture
yall already took my top 10 badge away... what will be left of me
Nice
but ive done more than 4 machines
Noice
Elite hacker?
I see only 3 in your activity
I did 26 machines active
yo im not understanding this so this analysis was made on my account ?
And 5/6 fortress
Yes
Just a silly little script that was vibe coded a while ago
I shared the URL above for it
You just enter your Labs user ID
(the numeric ID)
Damn you are crazy
i think some i did werent active
that might be right
or wrong
idk
Bro just do 9 machines
Definitely you will get hacker
And after 19 machines pro hacker
yeye ok imma tryjust that
Could be something is messed up in the script then if it's counting the retired as owns instead of active lol
..because it shoul dbe showing CCTV
but it's not
It was working, so maybe the API has changed a bit ๐คทโโ๏ธ nfi
how do yk ive completed cctv ?
By looking at your activity on Labs in your profile
Anyone can look at it
Gng my old account was banned by htb due to writeups ๐๐
Because that time I was stupid. Asf
Error 403
Ya know what is just as stupid? Admiting to ban evasion within the official discord 
or just machines orverall
Lmao
Been there same. Got my whole YouTube account taken down
Damn i have to do again 11 machines(also thanks my medium, I already privated those Writeups ) so it was easy. To recover and repwn machines
The only best thing when you do Writeups ๐๐ฅ
My wordpressed and medium got banned too
I was doing walk throughs for challenges in academy and live machines pretty much.
Was pulling in nice views
But now everything goes well
Damn my broke I get roughly 20 views a day
Then one day I woke up copy right strike like 37
And YouTube just banned my account
Pretty much
Miss Writeups of fortress allowed??
look at the guidelines
I didn't find anything related to writing fortress
I didnโt even know they had a TOS back then I wasnโt even on the discord was doing it for the love of the game
Same
xD
yeee
You are only permitted to upload, stream videos, and publish solutions in any format for Retired Content of Hack The Box or Free Academy Courses. In detail, this includes the following Hack The Box Content:
- Retired Machines
- Retired Challenges
- Retired Sherlocks
- Starting Point Machines
- Tier 0 Academy Modules
Any streaming or publication of Hack The Box Content solutions not mentioned in the list above violates our TOS. Legal actions will be taken against the content and the owner of this material if the content is deemed to violate the TOS.
Oh
also don't need to be on the discord to know about the guidelines
you can always do prior research before doing things
If you can publicly register with a service it has a ToS
Hell, if you can buy a product, it probably has a ToS of some kind
first time i found this i googled "Streaming guidelines HTB"
Maybe that's why
Also nice website ๐
Permanent usually. And lots of different ways depending on how the HTB team are feeling at a given time
being a dickhead in the dc server will get u banned from this dc server
@eternal mango
def lookup_user_id(username: str) -> Optional[int]:
search_url = f"https://labs.hackthebox.com/api/v4/search/fetch"
params = {"query": username}
try:
r = requests.get(search_url, headers=get_headers(), params=params)
r.raise_for_status()
data = r.json()
users = data.get('users', [])
if users:
for user in users:
if user.get('value', '').lower() == username.lower():
return user.get('id')
return users[0].get('id')
return None
except Exception as e:
print(f"Error: {e}")
return None
plox add support for username as well
Cheating I guess on active machines
Is this something for gubarz API tool?
Oh boy, I had fun doing that a month ago too ๐
I hate math -.-'
we have bsides........
bet?
hoi gubarz how ya doin
Fixed now @native yew, looks better.
holy general active
Alive just waking up, bout to get some coffee
i love math
lemme see brother @eternal mango
Right?
yummy
I think imma watch S2 of daredevil today
so my items increased ?
The new one
no his stuff is extra extra advanced
this is mine
Yes because it wasn't associating the owned content correctly due to the cache not refreshing
Now it's showing correctly the owned content and the updated calc
thats great
hiya @eternal mango hru
what's that @eternal mango ?
Hey, ok thank you ๐ Bit of a case of the sniffles, but fine. How're you?
morning btw
some of those machines require vip access
huuh..
this a smart idea fr fr how did you come up with it?
They are active machines, so they shouldn't
im bookmarking that one
I dunno, I gotta go finish dinner anyway
@austere sinew
nooo get better soon, i'm tired but alright, going down to london tomorrow gonna see some friends then see some people at a meetup, then on friday have that consultant. I cannot be arsed to go to london i should move down there faster
damn trains
@meager kernel WHAT
Because someone asked how to get the rank most efficiently, so I slapped that together with Claude for shits and giggles
hi
how are you
@meager kernel im good
helloooooooo
@meager kernel how are you
nice nice
im fine too
my eyes burn
sorry??
good to hear @meager kernel
what the fuck
the ones from the first analysis actually showed some vip ones like eighteen etc u can check them out, but this patch might have fixed the problem
im bored kinda
exams coming, dont wanna study
i caught cold and have sore throat
we dont have defcon but people meet up at bsides
Yeah the machine suggestions are different and correct now
0xDiablos still being active is crazy
if you dont study im gonna
uhhhh
insert comical threat
yeah it seems
I hate studying for college
fuck college
fuck exams
dropout
fuck my degree
fuckin mood
i live near basingstoke so this is weird seeing my location mentioned ๐ญ ๐ญ ๐ญ
htb profile was giving me a 404 for a minute. maybe its a htb issue not a you issue @eternal mango
there are plenty of bsides across the country :)
Lmao
That was me while I applied a patch and restarted the service if it was on that link I shared, if it was HTB then... I dunno lol
I thought it was a basingstoke specific thing, which one do u go to?
BSides
Imagining meeting up
BSides is good
r u good tho
I am
it depends on which ones my friends are going to!
At what?
Reverse engineering
i wanna meet up with @molten bobcat and give him a crisp high-five
Nice
Love BSides, they are hosted all over the place, not just UK
oh hey, ive been there lmao
bweeee bwee bweeee bweeeeeeee bweeeeeeeeeeEEEEEE ๐๏ธ
BSides LV โค๏ธ
ur a brit too? eww

oh
so uh
arent canadians ex british
idk anything against canadians
๐ญ
Aren't canadians french?
technically americans are ex british i guess
maple syrup and leaf flag
dunno whats the context
hahah, being screwed on rail prices is default for the UK ๐
i thought it was basingstoke specific because the name just matches, like bb ya know?
It's so out of hand
@austere sinew coffee >>> tea
no
they're that bad?
getting screwed on rail prices is a sentence if I've ever head one
i thought uk was small and u could just walk around
๐
doesnt seem to be the case
its the UK, out of london
Tea sucks btw
what do you expect
Absolutely hate tea
tea is not bad
what do u drink
Monster
'tis a small world
huh? it was only like 30 last time i checked
sadly, not in my country
chat is this real
no mum thats ai
Yes its a pic of me
is it a capybara or a hamster
but at least the htb group has some meetups once in a while
there's also bsides london as well
capy
Though this had a 50% off railcard iirc
cheapest possible railcard ticket
yeah thats like 20 quid, not bad. but even 30 is not bad.
it was more like 40 quid at the time
start walking there its free
exchange rates have changed since
You think that is bad, don't look up London to Newport Wales. I was paying almost ยฃ100 at one point
back in '71
they changed that much in 3 yrs?
u gotta be rich if u pay that per ride
what doin
or poor i guess
im curious to look up how many times basingstoke has been mentioned in this server
At one point I was upgrading to VIP or whatever they call it because it was like an extra ยฃ20 but I got a free coffee 
the UK is small, compared to Texas
Itโs allowed to use AI to help solve active machines and challenges, right?
The UK is much more dense though..
...population wise
(lol)
True
currently no rules against it
inb4 driving for 16 hours and ending up in the same state
But I still think Dallas alone has more residents
Whatโs the pop of UK as a whole?
The UK is small but you wouldn't think that watching the Last Kingdom
nice
No, I looked it up on Google then made up a number
count me in 
@lime trout ever been to festival place?
i think so?
Get divided
yea
Britainia
thats the biscuits
Britemalange
digestive biscuits with tea and no milk
actually tell a lie it comes from the term Britannia, meaning "the painted ones" or "the tattooed folk," referring to the indigenous Celtic folk
Oh shit I was almost right
oh I see
you mean cookies
well, I bought claude
aint cookies like the ones with chocolate
This is biscuits
Negative

๐คฃ
correct
do u guys say sweets or candy
9/10 for effort
looks like bread
Sorry Iโm not actually about to do this in HTB general
Hahahah
Bruh I'm a nervous mess rn 
bro those are crumpets fym
Let the biscuit wars, begin..
what docker does to a mf
Whatโd you call me??

Yeah I'm at jury duty rn lmao and waiting on bailiffs to call people back
yes ur a donut
british insults are so funny
like what is a muppet bro ๐ญ
how dare i not enjoy a delicious treat?
no pls have mercy on me ๐
Good thing I moved to Caddy a month or two back
I have 0 context
But boo hoo for not doing whatever u were saying
another one? didnt nginx get a critical like 4 days ago?
Oh it was just a โbiscuitsโ debate
Would need an already vulnerable configuration that CVE, but that's not that uncommon unfortunately due to how easy it is to make such a misconfiguration
Wouldn't that be better for him?
Free donuts and he don't even have to move
wicked
quicj someone submit a box
Wait for some bri'ish to call it crackers
Yeah I have 0 trust in that old config
It's not even a misconfiguration, or is it?
do brits still call cigarettes fags?
Just set after rewrite
All it takes is missing a / to allow for dir traversal
I thought that was old stuff for nginx??
Off by one or something
then he gets tummy ache
I know that vuln above requires a file read primitive, and so I may be talking out of my butt
Gonna do some real reading later to find out
Wait huh, is this another cve?
Oh, no I was right
The bug enables unauthenticated remote code execution against servers using rewrite and set directives.
It's awesome, always makes orgs decide to reinvest some money into pen tests
Oh no it's the same I meant
why cant I hold all these limes
oof
thats a big one
It only needs the file read to hit up the proc directory
So even a php lfi would work
Hi
hi
how are we?
Already exploited in the wild as well, fun stuff
good, u?
somehow alive but good
buys nessus scans
๐ช
Youโre deadly alive?
Do you mean the ASLR bypassing version? Or the original exploit?
Patched in 1.31 / 1.30.1 which was published in this April just gone
yes sir
If I had the capital for the insurance, burp suite, nessus and claude max....
crazy
ggs
noice
i hate this machine
lol

The exploit has been there for 18 years, was patched in April, and now someone figured out how to exploit it with ASLR enabled
When it was first dropped it required ASLR to be disabled
btw @eternal mango how come we are able to use these types of exploits
Copy fail is only for shit boxes 
its always regex's fault
they have to edit the machines basically
i wanted to use it just to prove i could
not thaaat easy
a hack is a hack
If it was a current season machine, it'd be patched no doubt
I know discussions have been had internally
I don't know what work they are doing though
i'm curious if this affects any of the exams (Ik you can't say this)
No idea, I'm certain sensitive things like that would be patched quick sharp.
yeaforsure cant wait for new season
they probably wonโt give u a pass
and give u a retry maybe?
if you think patching HTB boxes is hard, imagine how hard it must be for banks where applying patches and rebooting is not as easy as it might costs you millions
btw whats all the hype for joining a squad every season ?
Iirc it was announced that no box released at the time of copy fail etc would ever be patched
apes together strong
Its not like you cannot find help
But now that we have like 12 LPE vectors, that may change if it can be
What if all the apes are stupid in group
Hewwo :]
yeah but team help is often 10x faster than asking in a channel for help and praying someone helps you
Seeing how much people prioritized it had me thinking i was missing something, for example winning prizes or idk
a million monkeys hammering at the keyboard could write an exploit
most teams are there for people to help each other improve
Poor monke v.v
thats great
Or just to cause unnecessary drama
What if theyre all really annoying and abrasive and talk about "mr. robot" non stop? :[
i'm not keyed into the highschool drama of teams

You shush. You are on one of the best teams
Huh, okay, I am honestly still a bit confused, I thought CVE-2026-42945 was published just 6 days ago? The description says "with ASLR disabled code execution is possible". What does LFI/File Read have to do with the CVE? o.O What did I miss?
Which, btw, that show kinda sucks >.>
Lmao
then you'd need a different monkee group that suits you better
Last team I was on had major drama the week after I joined. Was so stupid
They are larping
๐ฅบ
Phasmophobia peak
please let me know how it is
I thought there is some new machine,
and please make sure to keep Gotham safe
Ive been playing zomboid with my BF lately:3
bro i had to do some wizardy to make steam actually unpack
shit was 5 mins late. pmo.
why's that?
cos the steam reporter process didnt die when i killed every other task
and it made it not unpack
The file read primitive is required to read from the /proc dir in order to fetch information allowing the exploit to be triggered
no clue why
And some dwarf fortress on occasion ^_^
The github repo linked on the post above is pretty good for an explanation
its always the people with default github pfp
nginx supposed to be secure
@high cobalt

