#general
1 messages · Page 757 of 1
he's said he doesn't want to afaik


yup, he better where he is.
He is way beyond the league. he is the league
I might leave again; haven't been having good
that's an understatement
he's the legend of the league
he cared and dedicated his time. Value time and it will value you;.
I might as well
Moderation is just too low lol
^
then; I don't see any point of you or people really good at what they do being here. OTHER then just helping others.
I haven't messaged in #cpts once since I came back. After I got my brain injury healed, I came back thinking it wouldn't be a problem anymore
But now the server is a wasteland lol
The prior wave of yappers took off too
yeah, i'm only here for #challenges. might leave it today or tmrw. just here for some updates and chat out with frens.
am I counted in that one?
i shouldn't have been too mean 
No
You just answered your own question here I think 😅
(hey btw)
Hiii
No, you were in the right
yeah, I did. I do some challenges every friday.
You know what I meant 
why the heck do you have a <@&516951058623496243> role? @eternal mango can I have the role? I qualify 
lol
that's sad; I'm not counted...
I can't grant roles sorry
You have to ask for it lol
oh yeah, lol. I forgor
oh you actually can't damn, I'll ask emma if I ever see her then
only if you are sebstianPC
naaaah
miss the APT role.
tbf
You still show up every now and then
i blame khaotic
APT role was a silly role
Stop showing up and I'll count you on that list
APT role was based
Beard role was too short lived 🙁
Oh yeah gubarz, I gotta disappear for a while and comeback. kinda became my nature.
I'm bipolar ig
I still have the AI generated wallpaper of yours "Bread Simon" one. or maybe I think @elder inlet created it.
also if <@&516951058623496243> actually has ping permissions, I just realised that I might have annoyed quite a few people 
Honestly can't remember tbh
I'm safe since I didn't ask for the role lol
Longer list than I expected
anyways, gotta go guys. hab a good ones
General question for general chat: how on earth people Crack some of these boxes in under 7 minutes
Experience and automation generally
Hacks
Not necessarily even ai, people have been beating the average long before ai became accessible as it is now
..or an unintended solution, which can happen from time to time
Ilr
I have seen some experience, but even with that. The box i did today took over an hour and first blood was 6.5 minutes
Ikr*
Like ipv6 that used to happen all the time
What was that, like services binding to the ipv6 interface unintentionally when they were supposed to be local only?
Or missing fw rules or something
Yeah, firewall rules that only applied for ipv4, and no implicit deny
Gotcha
Htb allow ai on labs now?
There is no official statement on that currently
you're only hurting yourself if you're using AI unironically
I think it has been stated that just pointing AI at a live box to go ham is against ToS. But what you do in your chat is your chat 🤷♂️
like I know it's funny to flag a ctf chall with AI but in the end it's the same as just not doing the challenge
Oh, yeah just checked the acceptable use policy, it is mentioned in there now
naaah no way, I send nessus after boxes all the time
AI or not. 6.5 minutes on a medium box is fast.
..but not for working with content I don't think
Gamification will always draw in some number of people who think rank matters more than skill
(as in using AI to try and solve content)
I've used it on retired boxes. I just didn't think it was OK for live
Well, there's like a million players now? The chance that someone finds the exact right thing on the first try isn't that unlikely
Yeah. Perhaps they had experience with that specific cve before
unless the box is knife and you need to know chinese to solve it on release, and 24h later the exploit was weirdly translated to english everywhere
yeah I'm still mad about spending my saturday night on it
Lol
who are you
What about my new Auto-hack github project… just point it at the box and it’ll solve it for you… educational, no?
Read the aup if you want, it covers the current stance on AI usage
..as I said, nothing covering using it against labs atm
Zero learning needed… what fun
But, maybe we have to build AI resistant challenge boxes
New wave of super hackers all rank to expert in a week
Yep!
'months of grinding'
It's going to ruin CTFs, too
Some sort of proctor
We'll add a test to require the user to spell "Strawberry" prior to submission of flags
Simples
Gonna need live CTFs again
Mitmproxy monitor
“Which days of the week contain the letter D”
none of them!
No matter what, someone will find a way to bypass
Case sensitive answer? 🤣
Jumping the gun again
Every day is raturday, if you try hard, and believe in yourself
🙂 and are a rat
Or an octopus, I’m always getting those two confused
I hate science
damn i cant believe they made a game after me guys
damn i was gonna say lego batman but the lesuire suit larry looks right
Guys, which HTB machines that have reverse engineering?
There’s an entire challenge category for this
cheat detection of chess.com are not as good as before in every 3 games 1 of them i play against a cheater
hans nieman cheated in a world tournament but i am talking about the app
oww didint know that
proctologist is the next step for Neimann?
but they have to find a solution for chess cheaters bc i am stuck in 1600 elo bc of them
It upset him so much he ended up dying of an OD
Seriously, the guy was very fucked up by being accused of cheating and online bullying… he was one of the best chess instructors on youtube
Very sad story
he cheated so thats on him
Danya did not cheat
i thought you talking about hans
amphetiminies are basically PEDs in chess
Hans is still with us, unfortunately
but danya its a sad story ofc may he rest in peace i learned so much from watching him his death is so sad ngl
Agreed, but it’s not clear that the amphetamines use started before or after the depression and the bullying happened… still a sad story
it's unfortunately all too typical. Where people cant build themselves they'll tear others down
Yeah, kramnik can eat a dick
♟️
I never got to 1600… I think my max is about 1400 rapid
1300 blitz
I’m 1700 puzzles or so
oh i thought you are 2000 or more lol
wtf hod do we check elo for puzzles
ive never reach that in puzzles
If you do puzzles it gives you an ELO
oh
You gain like 3-5 points for solving one, and lose 6-8 for getting one wrong
Each puzzle is rated, and I think the points won or lost is weighted by the puzzle difficulty
you play daily mode ??!!
Sometimes
Not often
A friend of mine likes to play daily… 7 days per move
It took like a year to finish the game
yeaaa lol
Killed it
subtl3 tell us something fun
im not a cool kid
Me neither
im founding certcism
guys it would be funny if someone out there started a click-fix attack on skids 
you are as green as me
I was told in a peer-feedback that my “heart is full of mischief”
yeah talk to us when you are orange greeno
wait is that orange or gold but there is no server boost to make the shine animation ?
isnt that teal tho
i mean just a shade of green?
It’s not easy being green
yeah but then again HTB is green
Yep
funny thing there is another website called draw a box for learning drawing
Think it’s easy for @eternal mango to put up with this nonsense?
When nonsense mode is enabled I generally close Discord, unless it's me posting the nonsense..
Hello 👋
goblin is like that mischief laughing frog gif
Hey
Goblin is misbehaving today ?.
I don't think so?
I was kidding
Hahhaa
I am up to no good
FREE DOWNLOAD: https://venjent.bandcamp.com/track/wub-wizard
FOLLOW ME:
TikTok 🎵 https://www.tiktok.com/@venjent
Instagram 📸 https://www.instagram.com/venjent/
Spotify 🟢 https://spoti.fi/35PhYRV
Bandcamp ⛺️ https://venjent.bandcamp.com/
YouTube 🎥 https://youtube.com/venjent
LOVE IS THE ANSWER ❤️
V xxx
#harrypotter #dnb ...
lol
Thats usual for you though
S’true
My boss told me I should “pop” an engineering team that keeps avoiding security work
I was like, yeah, I’ll just start running nmap on their production infra?
what is nmap
Secret
damn
Nmap.exe
Some groups just don’t want to do what they need to do… they seem to think security is a bunch of tinfoil hat wearers
i started sitting on as security in discovery tasks with the engineers on new client onboards and they are doing so much better with security stuff
Daaaamn gg Drupal
https://slcyber.io/research-center/keys-to-the-kingdom-anonymous-sql-injection-in-drupal-core-cve-2026-9082/
Inside SA-Core2026-004 On the 20th of May, the Drupal Security Team released SA-CORE-2026-004 (CVE-2026-9082), a Highly critical (20/25) SQL injection in Drupal core. The issue is reachable by fully anonymous users on any deployment that backs Drupal with PostgreSQL. It was reported upstream by Michael Maturi and a fix shipped across every suppo...
want someone who can run nmap scans?
instead of resetting network equipment to companyname2026! they are actually using complex passwords now
Small victories
Hello Good Morning
I see so much stupid stuff… oh yeah, it’s just easier to expose our stuff to the public internet so our “partners” can use it
Still won’t fix known CVEs
Hot out?
83 here
If you held a piece of the sun to get that hot it'd be about .5 mm radius and 1mm across, according to chatgpt
The AGIBOT Expedition A3 humanoid robot in Shenzhen, China tried dancing to Michael Jackson’s “Billie Jean” in May 2026. It pulled off the moonwalk, but the routine went wrong when the robot tripped on the steps and got dragged off stage in front of the crowd
Source: Shenzhen robot event
- Copyright Disclaimer Under Section 107 of the Co...
guys. which module i can find WAF exploit?
😉
Lol we exploit tomatoes
Just turned on tailscale on my android phone, desktop pc, and my proxmox PVE, with proxying to 192.168.1.4 (nextcloud)
Unpaid internships?
i told you
it's ez and awesome
Thanks man
@latent oak who
I appreciate you 🙂
For the tomatoes
Oh haha
@alpine pumice Did you see my domain? https://howstoned.ru
can i scan it
Yo kami
It's behind cloudflare. It's a tunnel
hi astro
Hru
Yes
guess ill do that this weekend
Someone got mad at me earlier
For what eggz
The subject is covered a little in this module, but you're not about to find bypass techniques for WAF's like Cloudflare in there https://academy.hackthebox.com/course/preview/http-attacks ..
@alpine pumice I got someone mad at me an left my matrix room b/c I have a Russian domain.
facepam agree
I had to install tailscale on proxmox and then └─▶ tailscale serve --bg http://192.168.1.4:80
I tried installing tailscale in the container, but ran into routing problems.
Tried for an hour and coulnd't figure out it wasn't connecting to the domain. Finally figured out you have to proxy if you're behind NAT
lmao
that guy you were tlaking to is ukranian
he just sadge
I don't get into politics or anything like that
I am against war and genocide and all the moral things sure
then why r u a terroist bro
But I don't let the mix with work/technology
discussing politics on matrix sounds like one of the most schizophrenic things one can do
He raged and quit
BTW, what do you mean by 'green role'?
Why a Russian domain?
Look at the domain name.
My nickname on IRC used to be stoned
Someone in 2014 suggested I get howstoned.ru
Like how stoned are you
So I got it
I've had this domain since 2014. Never did anything with it.
So yesterday I setup a cloudflare tunnel for it to my home desktop
once the russian government finds out you made up a fake russian address you're going to fall out a window
So I can self host some stuff
once the russian government finds out I'm God they're not gonna know what to do
Well it wasn't fake really. I used a friend's address
He was okay with it
I think
I can't remember it was 12 years ago
they aint gonna check if it's a real address
Either it was a fake addy or a real one.
But somehow it was accepted and I got me a russian tld
I would like to believe that all the window deaths are actual accidents, and when the news comes out, the KGB are just like 'damn it all, they're going to blame us again'
this is the ragest of all ragebaits I have ever witnessed
it happens too often
i remember when those billionaires literally fell out of windows
one in spain
they were teaching them how to fly
I'm God
hlo god
Hello
god of what?
I just am
I swear to dog
im a god of sleeping
Talk to a hippy mctrippy psychedelic spiritual person and you'll get, 'wer're all gods'
Mr. Hippy McTrippy
A process starts by first having its address space allocated virtually
How much does an electron weight?
then the program is loaded onto that space
5 kilos
If you take a storage device, and then it's empty right, but the you fill it with data, does it gain more weight?
So if we had sensitive enough measuring hardware, we could weigh it and find the difference
I wonder what is the whole weight of the Internet
Depends on the storage medium
that would mean SSD get heavier as you put data on them
For ssds iirc technically the act of storing data does change the weight by a teeny tiny amount
There was a video on this ages ago I recall watching, and had to double take on that claim..
Maybe from veritasium or someone like that
Oh Vsauce https://youtu.be/WaUzu-iksi8
Thanks to @lakefield83 and @zconsortium for these facts!
all music by Jake Chudnow: http://soundcloud.com/jakechudnow
READ MORE:
Weight gained from e-books: http://www.nytimes.com/2011/10/25/science/25qna.html?_r=1&adxnnl=1&src=tp&adxnnlx=1319904165-PvwPMwuILjGNEh8dgt7zAA
Gadsby: http://www.amazon.com/gp/product/1466216735/ref=pd_lpo_k2_dp_s...
well it would have to because electrons have mass
at least from what I understand data is just stored charge
Ig I'll go hit the bed again
Damn how did it get so late, I should too, nn!
No, I woke up early, 4:30ish AM as I couldn't sleep
now its 7 AM and it feels exhausting already
Could be charge, magnetism,light etc btw
good night to you tho, it is time already 
Exactly, and as when a 1 is stored is by removing the charge from that gate, a full disk weighs less than an empty one
Why?
I woke up just now cuz the room got very cold
idk, sleep got disturbed
is it becasue of a ghost?
Oh so we faced the same issue ig
There is a very high possibility
I most of the time forget to turn off the AC usually
i prefer sleeping in cold
use sleep timer
even when it's 20F out I'll sleep with my back door to my bedroom open to the deck outside
Same, but my body has a limit
I cant pinpoint the time I need my ac to be on.
I usually when I feel cold turn it off
So the time differs a lot eachtime
doesn't your AC have a thermostat that automatically regulates the temps?
during 3-4am or few hours after you go to sleep, the body temperature drops
naturally
this is the 21st century sir
Uh I haven't play d with my ac a lot but I don't think so,
The ac is afterall abt 3-4 urs old
Danny, did you see my domain? http://howstoned.ru 😄
Oh
sick site bruh
already hecked u
thanks
I never got into runescape
where's @brathadair\
Only online game I ever played really was Diablo 2 back in the day
Lol
I like openarena, quake 3 open source port with free graphics and levels
day one of asking if we will get a light theme for HTB
I want to play a video game
He isn't even in the server?
about a woman plummeting into psychosis
he needed a break from this madness we call general chat
just plummet into psychosis in real life youll have so much more fun
the point of the game is to and buy some milk
he comes and goes
I installed monument valled 3 in my mobile, cuz it there was an offer and it was free

all we have to do
is walk to the store
and buy some milk
come back home should be easy
the game though like the soundtrack was made by a hacktivist
they made a whole website where you have to break into it
try https://hacky.uk
The Hacky Playground teaches you to hack using Cross-Site Scripting and SQL injection.
Back done onto arms now
But most of them don't come back home after buying milk
Or that's what I have heard
please dont say that
I will make it home
I doubt it
I did look i to the leaderboard yesterday
gubarz typing
The team made a user script for academy, bunch of features, one of them is light mode. But academy only.

are you ok?
what kind of mental restrain and power you have to withstand lightmod
light mode would suck
so much
that nothing else has ever sucked in the history of sucking
darkmode > *
Some people actually need light mode for accessibility reasons, I will not taut that the light mode we put together is accessible, but it's probably better than nothing.
True.
I didn't consider accessibility
actually considering it when did lightmode staring being annoying like everything was on lightmode back then adn now one complained
People complained that dark mode didn't exist
why there is no green mode
Your name is green, thus green role
Yum
I only eat chickens and dead cows
some times mutton/goat/etc.
but mostly chicken and beef
Never do pork
Venison, and rattle are tasty too
What about bison?
Not alive cows?
I don't really like bison that much tbh. Very gamey same with some turkey
If my steak ain't kickin then it's overcooked
I don't like like turkey much. too gamey for me
I like my steak medium rare to medium
I should try blue rare steak I don't think I've ever had it that way
I like rare steak tho cause it tastes the best especially if you can get a quick crust on the outside
A little too chewy, need to let the fat render
Try steak tare tare sometime
It's minced steak meat, seasoned, with a raw egg on top
Yall eat poke?
What's poke?
I'm too scared of getting worms to try that lol
Raw fish
I also don't like eggs cause they upset my stomach
I can't spell worth a dick.
I'm going to make beef carpaccio later he'll yeah
🆗
Pro hacker
I thought those ranks went away
I'm probably going to make a microwave meal for dinner then have a protein shake later
Need to get back onto healthy habits again.
U didn't have to explicitly say 'dead cow' u know
then whats the script kiddie role color?
A type of green
They presented at cactuscon 2 years ago
Idk
Nice

Wht Abt fish?
I don't eat any seafood
W pfp
At all
Not even crab?
I can't stand the smell, taste or texture of seafood.
Damn u missing out on some tasty food
I see
Ohhhh chilli soft shell crab
Can't stand the smell. That's the worst.
I might every now and again have a tuna fish sandwitch at Subway
It's been 20 years since I had a tuna fish sandwich
I also have had a mcdonalds fish filet sandwich
I can confidently say I don't like seafood
of any kind
U have ever eaten crab tho?
Maybe fried fish, battered, if it doesn't taste fishy
No Ihave not had crab
but I have had crawfish
You ate the two worst seafood things of all time and claim you don't like seafood lmao
Macca's fish burger and subway tuna sandwich
It has a uniquely taste, and most ppl actually like it
💪🏻
I would like to try some beluga caviar one day
Yeah I ate a burger I found in the bin turns out I fucking hate burgers
I Never had caviar
ty ty
I suggest you give seafood another chance
Such as?
I had the most amazing ice cream with beluga caviar on it in Denmark
Pipis in xo sauce YUM
I'll give crab a shot maybe sometime, maybe.
U don't like fried clam?
Lobster Crab Shrimp octopus ...
Haha
No thanks
lol
Lobster I might try one day
All of them don't have the 'fishy' taste u are talking abt tho
but not crab or fish or seahorse or what have you
Never had seahorse
I didn't even know ppl eat them
Man will never eat abelone
hahahahaha they dont ate seahorses
Seahorses are super bony
did you eat one before?
And they usually just hold onto something in the reef
No but I've seen a lot of them
And sea dragons just look like bits of seaweed floating around
Good for you!

I'm going to start an illegal Marron farm and just eat Marron for the rest of my life
REASONS TO EAT THE SHELL
what is the point of glazing over a lobster shell and not eat it
at that point you have to
i dont know maybe make it look more delicious
Appearance matters to many ppl
exactly
Most chefs try to decorate their food( 4 or 5stars ones) to give it a good look even tho some foods taste like shit pr flavourless
Afterall there are some ppl who pay 10-20 or even 50 dollars etc for a bland food to be only put into a closed plate with some dry ice and see another guy open it
Yeah. If it has a fishy taste it's probably gone bad
Actually, fresh salmon really doesn't have a fishy taste, one of the only fish I'll eat but needs to be still flopping before cooking
I only eat fried fish , and salmon is one of the best fried 'fish' I have had
My typos are so shit dude, literally typed friend instead of fried
Yall still taking abt fish
😭

Good Morning again
Waddle doo
good morning
ill not wake up tomorrow so say it in advance to me
oh no
don't take any bad step
go to sleep
Properly sick of my brains response to not being able to sleep to decide that hyperfocusing on a subject or project that has no real value is the right thing to do instead of just laying there, hoping that sleep will come
Stupid brain
nahhh
thats me every day
my brain doesn’t sleep quick
I knew I should be up to go to a thing today to meet someone, but instead my brain chose to sabotage itself
Now I don't feel safe to drive
EXACTLY
that's the adhd superpower tho
that's how I learned to make cheese.
Doesn't feel like a super power tbh, but sometimes yes that hyperfocus kicks ass
but not like this

now i have a brined halloumi in the fridge, and bags under my eyes
I've never had much success when it kicks in when I should be sleeping, then the gf asks at 6am, "you still up?"
Not diagnosed, but it's fairly obvious. It'd take months or years to get diagnosed on the NHS
but I'm about fed up with them after they said it'll take 3 weeks to have a call with my GP to review my anxiety/depression meds the other day
Makes me feel great...
Pls take a uber then
I hate having to go private because it feels like that's exactly what the toffs want people to do by killing the NHS
I'm not either, but my friends lovingly describe the random pictures I send them as "your fun adhd hobbies" so I just accept it
but I need a freaking appointment
Nah no point going now, I would be the walking dead
I'll order stuff on Amazon, hyperfocus on it for 72 hours, then lose interest before the package even arrives
Ah not going would be the best then
and it'll go into the closet unopened for years
Can I have them then?
yeah, just a shame, as daughter was expecting me to be there as well
Ah well
no, because the desire comes back eventually and I open them
Its not like u can go even if u wanted to
She got me a Fuggler for my birthday present 🤣
there's an arduino and various sensors somewhere in this house. I'll find them one day
I will send it back to u when tht so called 'desire' comes back
This one
Damnn tht looks cool
i dont like the teeth
Just admit the fact tht u love it
it's cute without the teeth
Of course I do!
I bought a Gollum one a while ago that's just amazing
..and a Gizmo one..
They're just so freaking derpy
Yeee
There was a Care Bears one we saw the other day, but my daughter said I wasn't allowed to buy it 🤣
(she finds them disturbing)
..but come on, isn't that just glorious ?!
🤣 fair enough
( personally I don't blame her)
anyone have a good workflow for after getting an initial rev shell? I always feel overwhelmed by the amount of information available and end up running in circles
It happens to the best of ppl
I usually find what needs to be done, but it ends up being a tedious crawl through the entire filesystem
I usually look at stuff based on the context of the machine I have a shell on
Wdym?
For instance if I'm a shell on an SQL server I'll look for post-exploitation stuff related to SQL, is there an old database somewhere? are there service accounts? etc.
I'm basically:
> env
> sudo -l
> find suids
> find guids
> anxiety attack
Check processes running as the user, look for services bound to localhost, bash history sometimes
Oh ok, and it works most of the time?
you can add:
check logs
check backups
check kernel version
check networks
check services
I've been ignoring kernel version recently because everything is dirty fraggable
I mean, servers are built for specific reasons and usually those privilege escalation vectors are based on those reasons.
Wht if the user is not in the sudoers list?
Everything is also vulnerable to copyfail
I see
Log files readable ordered by date descending can yield interesting bits sometimes
suid bins are not that common these days in boxes I suppose, but a good check, so long as you recognise the usual suid bins that are meant to be there
My recent personal favorite is python packages
😃
i've been out of the game for a while. it used to be bread-n-butter
simply find one where you can write where it imports and make a pth file 
Can I have some too?
😃

Man that's triggered some memory about unusual file folder perms that allow you to rename but not to write to files or something
A massive TIL when I foudn that out, but I can't quite remember it
Something like exec on the parent directory allows for renaming of children of the directory
Ok I gotta go find that out now fml
i think there was an OSCP lab box that tied my up for hours because the exec perms were weird in the fstab
so I just coulnd't figure out why nothign was working
and i just had to move to a different directory 
Oh ok not so weird then, for a directory that you do not have read perms on but do have write perms, you are able to rename files in that dir, and then you can move a file you own into that dir and edit it.
Feels like I found that on a HTB or Vulnhub VM but honestly can't remember
Now that I read it again it makes sense, but I suppose the lack of read perms and yet still being able to do that made it feel a bit weird at the time
Where even is that kind of directories used?
it always makes sense after the fact
Thanks
Really dirs shouldn't have perms like that ever lol, but yeah, was part of a vulnhub challenge
Ye
It just confused the hell out of me that I could move a file owned by another user with no world perms on it because I had write perms to the contaning folder
..but you couldn't just overwrite the content in that file
You had to move it then write your own file to the dir
well, www-data owns the folder, so even if it was standard 775 it wouldn't matter right?
Like I said, the thing that confused me was that you could rename files in the folder due to the weak parent folder permissions, but couldn't just overwrite the file directly, you had to rename it first
It's fairly obvious now why it's like that, but yeah
It confused the hell out of me back then
oh yeah no I'm just trying to make sure i understand
If the perms were 775 thus lacking write perms the commands in that blog wouldn't have worked
oh okay
so it's the 777 that allows it to work
what a goofy set up. i would have missed that
yes, even though you do not have permissions on the file you're renaming, because a rename action changes the directory entry, not the file itself, it is allowed
But yes, very goofy setup, but that was vulnhub back then 😄
actually, it works with 775 too
Weird, it shouldn't, if you're not part of the group owning the directory
because that's just giving read and exec perms global right?
┌─[user@parrot]─[/tmp/tmp/testing]
└──╼ $ls -la
total 0
drwxrwxr-x 2 user user 60 May 22 01:37 .
drwxrwxr-x 3 user user 60 May 22 01:36 ..
-rw-r--r-- 1 root root 0 May 22 01:36 testfile
┌─[user@parrot]─[/tmp/tmp/testing]
└──╼ $mv testfile testfile2
┌─[user@parrot]─[/tmp/tmp/testing]
└──╼ $echo "asdf" > testfile2
bash: testfile2: Permission denied
┌─[✗]─[user@parrot]─[/tmp/tmp/testing]
└──╼ $
Well yeah
Sudo sudo sudoru!
user:user owns that directory
So you can rename files within it due to user/group write perms
yeah that's the same as the test-case you were looking at, right? with www-data owning the dir
Basically yeah
Same thing, just what I had above was global write perms on a folder owned by another user/group
But it's the same thing
😄
honestly I've seen cases like that before and never thought I could just move the file and replace it
pretty neat
Glad to have shared the crazy 😄
all i know is tung tung tung sahoor
when did you become a mod golam? i feel like you were just a memer a couple years ago
Mozilla
professional memer*
i dunno tho been like an year or so
mozilla is a joke company
congrats m8
but its the best we got
thnx mate
we have to replace mozilla
why are we hating browsers tonight?
it's just me
which do you recommend
i love firefox
i just want browsers to stop forcing tabs to sleep so they need to reload when I open them again. I have plenty of RAM -- just stop.
if you had seen the war crimes brave has commited u wouldt say that
they literally stole peoples money lmao
in this world its not about who is the best its about who is the least bad
but it's basically "chromium based browser" or firefox
Saw this earlier RE Chromium https://arstechnica.com/security/2026/05/google-publishes-exploit-code-threatening-millions-of-chromium-users/
Google publishes exploit code before patch, reported 42 months earlier, is fixed.
🤷♂️
@obtuse fern This is why I would just hold any exploit for ransom
that's what I did for razer synapse after they offered kudos for a privesc 0day
what the hell is chrome written in anyway
Christ the number of dependencies it pulls in
it'd be easier to say which language it isn't written in
Takes longer to build Chromium than kernel
🤣
bingus
Meow zumi
meow
the exploit is said to put users in a botnet
i want to be netted by a bot
the botnet god i wish that were me is a wierd fetish
I like fishnet stockings
I don't know all the details, but from that limited article it reads like something using the fetch api for large files resulting in a long running fetch task in the background, maybe that's being used to keep a webworker process alive past its supposed expiry when the page context is closed?
But that's a massive stab in the dark
Gonna read up more now, curious
essentially x3
oh I see
How's it going y'all
Good just had an amazing dinner
wasting time
Gnochhi baked brussel sprouts then lemon cheesecake
I like sheep and cows n stuff like every other human
basically the download feature if you download a large file the mechanism that keeps it going
Too late to delete, I already saw the image 😂
oooo that sounds good
it was fire
Yep exactly in the background, which then keeps the service worker alive beyond its intended lifetime
Neat
sorry for blurry pics
back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member
in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser
today, almost 4 years later, the bug is finally public:
issues.chromium.org/issues/400…
386
526
why does that matter?
i dont think most people think about sheep or cows ngl
I don't even know wht tht is
Oh what should I think about since I'm a human

never said its bad, i just dont think most people live in an area where they even see them
Because the web service worker should not outlive the context of the page, and by keeping it alive it can act as an implant, performing any actions the browser can in that context
yeah though I've......like yeah I can see now how you could have a large pool like 42 million affected people
How learn hacking I am a beginner are there any educational resources
but that's gotta take like a lot of hackers
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
Chromium made the bug issue post private 😢
and a popular website
i like, never see farm animals unless i fly somewhere that known for them 😂
i have a million cats outside of my home in california
Oh...
Which bug?
like first you need to have a popular website and then have people visit the website and download a file using your malicious JS
i mean, my father in law has cows 'n donkeys n shit

The one we've been discussing above
they always doing the nasty at night and yowling
Ohk
zero click as the fetch api doesn't require user interaction
Married?
Damn
So just a stored xss would do
yuh
so like visit the link. no need to trigger the download
Given that Drupal anonymous sqli from the other day recently dropped too lol
nifty
yikes yeah that's major
i was married 
i e ven touch grass
rohrow (if anyone even still uses Drupal..)
Drupal? People still use drupal?
🤣
Impossible!
me too
Sure buddy...
lots of government departments here use drupal
What's grass?
people use dotnetnuke they havent updated in 10 years
Really?
yea for ten years not no moreee
Picking up non computer hobbies is great for mental health 🙂
What's this thing called "outside" and "without computer" other people are talking about?
I hope that u aren't lying
get an RV
why would I lie
Soo true
how do you get notifications of these things? is it all social media?
Hahaha
0 interest in that
Idk 
we finally got ours at the beginning of the month
i mean my FIL has one i could yoink if i really wanted
Generally yeah, I just follow people on Twitter, some blogs, etc etc
but i got no interest
CVE feeds
I don't watch it all as close now, but when something big comes up it is all over the place
i dont even have a drivers license(yet) lmao
I want that expliot
Woah
now
can you DM me some pages to follow? I haven't had social media since 2010, and I'm thinking of setting one up so I'm not such an online ghost
ive been driving since i was 15
yeah need one for an RV 😅
i never saw the point until looking at moving somewhere else
i needed to cuz i grew up in rural area
LinkedIn?
0 point having one in the downtown of a big city
we aint got buses an shit
Emma drives a space ship. No need for a license lol
literally nothing
no i just live places with decent public transit 😭
U are missing up on some cursed posts , I see....
The Chromium one? I can imagine how it'd work, fetch api call to long lived request within a web service worker causing service worker to stay alive beyond it's intended lifespan
oh which one i might have tested it
but surely it's not that simple
cars are kinda cheap though
Must not be in the US lol
which sketches me out
Lucky u
when all the dealers are offering 0-1% APR that market aint doing well
Honestly I just spent years following people that I found post interesting stuff on Twitter, but many have now left
moving to the US so getting a license lol
For the rich maybe
the APR difference makes buying new the same price as used on financing
Exactly
which is weird
Oh boy lol east coast or west coast?
midwest
when you are rich everything is cheap
Very nice
i should see if i can refinance... my auto loan is at like 6.2%
maybe wes coast after a bit
Moon?
alot of makers are offering 0-1% APR when i checked recently
seattle is nice im there rn and lived here for many years
Yea zumi is rich
Portland if i went to west coast
have my gripes with Washington & Cali
no i spend all my money on programming socks
nerd
oh nooo, i like owning 3d printers n stuff
oregon is dangerous outside of portland
Ellow
@sturdy thistle hi
U hate using ur money on something useful?
people say that stuff about everywhere
You know what im talking about
idk it doesnt really bother me
Hey Emma
Mhm
Thats good ^^
Don't move to AZ if you dont like heat
i know how to protect myself if i need to lol
ive only been to AZ in the winter
Good 😌
phoenix is cursed as a city
I hate the summers here lol
Pepper spray won't be much of a use of he has glasses on ( nerd)
Summers in california kill me
Oh yea phx is ass lol
so fucking hot
i dont carry that
Oh so u do martial arts ttoo
Pew pew
Oh shit I forgot
i decline to answer what i do
Got it
Emma is a gangster
U made it sound illegal now
i open up inspect element and delete them 
like me
Gender?
Real god?
yea
I see
it's fine california thinks metal lathes are 3d printers
anything that uses additive or subtractive manufacturing apparently
(joke) .
😞
injection molding banned too?
damn
only if you don't add programming to ensure it's not a gun

