#general

1 messages · Page 757 of 1

severe falcon
#

Indeed, if froj can come back; he will too. but idt he will ever come back to this brainrotted land.

#

cursed emoji of the day

obtuse fern
#

he's said he doesn't want to afaik

silver bronze
silver bronze
severe falcon
#

He is way beyond the league. he is the league

#

I might leave again; haven't been having good

silver bronze
obtuse fern
#

he's the legend of the league

severe falcon
jagged storm
#

Moderation is just too low lol

obtuse fern
#

^

severe falcon
#

then; I don't see any point of you or people really good at what they do being here. OTHER then just helping others.

jagged storm
#

I haven't messaged in #cpts once since I came back. After I got my brain injury healed, I came back thinking it wouldn't be a problem anymore

#

But now the server is a wasteland lol

rose onyx
#

The prior wave of yappers took off too

severe falcon
#

yeah, i'm only here for #challenges. might leave it today or tmrw. just here for some updates and chat out with frens.

severe falcon
obtuse fern
#

i shouldn't have been too mean sadG

rose onyx
eternal mango
#

(hey btw)

severe falcon
#

Hiii

jagged storm
severe falcon
#

yeah, I did. I do some challenges every friday.

eternal mango
silver bronze
eternal mango
#

lol

severe falcon
severe falcon
silver bronze
silver bronze
severe falcon
#

ahahahaha

#

I knew

rose onyx
silver bronze
#

APT role was a silly role

rose onyx
#

Stop showing up and I'll count you on that list

undone fossil
#

APT role was based

eternal mango
#

Beard role was too short lived 🙁

severe falcon
#

Oh yeah gubarz, I gotta disappear for a while and comeback. kinda became my nature.

#

I'm bipolar ig

severe falcon
silver bronze
severe falcon
#

it was long long ago.

jagged storm
severe falcon
#

anyways, gotta go guys. hab a good ones

potent gull
#

General question for general chat: how on earth people Crack some of these boxes in under 7 minutes

eternal mango
#

Experience and automation generally

eternal mango
#

Not necessarily even ai, people have been beating the average long before ai became accessible as it is now

silver bronze
#

0days

#

we all burn 0days on htb bloods

eternal mango
#

..or an unintended solution, which can happen from time to time

tough oyster
potent gull
#

I have seen some experience, but even with that. The box i did today took over an hour and first blood was 6.5 minutes

tough oyster
#

Ikr*

jagged storm
eternal mango
#

Or missing fw rules or something

jagged storm
#

Yeah, firewall rules that only applied for ipv4, and no implicit deny

eternal mango
#

Gotcha

eternal mango
silver bronze
#

you're only hurting yourself if you're using AI unironically

stone marsh
#

I think it has been stated that just pointing AI at a live box to go ham is against ToS. But what you do in your chat is your chat 🤷‍♂️

silver bronze
#

like I know it's funny to flag a ctf chall with AI but in the end it's the same as just not doing the challenge

eternal mango
silver bronze
potent gull
#

AI or not. 6.5 minutes on a medium box is fast.

eternal mango
#

..but not for working with content I don't think

jagged storm
#

Gamification will always draw in some number of people who think rank matters more than skill

eternal mango
#

(as in using AI to try and solve content)

potent gull
#

I've used it on retired boxes. I just didn't think it was OK for live

molten bobcat
#

I've been here for years

#

😄

jagged storm
potent gull
#

Yeah. Perhaps they had experience with that specific cve before

silver bronze
#

unless the box is knife and you need to know chinese to solve it on release, and 24h later the exploit was weirdly translated to english everywhere

#

yeah I'm still mad about spending my saturday night on it

potent gull
#

Lol

silver bronze
latent oak
#

What about my new Auto-hack github project… just point it at the box and it’ll solve it for you… educational, no?

eternal mango
#

Read the aup if you want, it covers the current stance on AI usage

#

..as I said, nothing covering using it against labs atm

latent oak
#

Zero learning needed… what fun

#

But, maybe we have to build AI resistant challenge boxes

potent gull
#

New wave of super hackers all rank to expert in a week

latent oak
#

Yep!

jagged storm
#

'months of grinding'

latent oak
#

I don’t know how they will stop it from happening…

jagged storm
#

It's going to ruin CTFs, too

latent oak
#

Some sort of proctor

eternal mango
#

We'll add a test to require the user to spell "Strawberry" prior to submission of flags

#

Simples

jagged storm
#

Gonna need live CTFs again

latent oak
#

Yes

#

Click all of the motorcycles

potent gull
#

Mitmproxy monitor

undone fossil
#

“Which days of the week contain the letter D”

silver bronze
latent oak
#

No matter what, someone will find a way to bypass

eternal mango
latent oak
#

Jumping the gun again

jagged storm
latent oak
#

🙂 and are a rat

latent oak
#

Not a rat

#

That sir, is a platypus

#

😉

latent oak
#

Or an octopus, I’m always getting those two confused

latent oak
#

I hate science

turbid goblet
#

damn i cant believe they made a game after me guys

latent oak
#

Leisure Suit Larry?

#

Or space invaders

turbid goblet
#

damn i was gonna say lego batman but the lesuire suit larry looks right

scenic tapir
#

Guys, which HTB machines that have reverse engineering?

limber arch
toxic rock
latent oak
#

They have a system called proctor that they made Hans Niemann use

#

And Danya

toxic rock
latent oak
#

He cheated online

#

As well

toxic rock
latent oak
#

Danya was accused

#

Multiple times

proper dragon
toxic rock
#

but they have to find a solution for chess cheaters bc i am stuck in 1600 elo bc of them

latent oak
#

It upset him so much he ended up dying of an OD

#

Seriously, the guy was very fucked up by being accused of cheating and online bullying… he was one of the best chess instructors on youtube

#

Very sad story

toxic rock
#

he cheated so thats on him

latent oak
#

Danya did not cheat

toxic rock
proper dragon
latent oak
#

Hans is still with us, unfortunately

toxic rock
#

but danya its a sad story ofc may he rest in peace i learned so much from watching him his death is so sad ngl

latent oak
proper dragon
latent oak
#

Yeah, kramnik can eat a dick

toxic rock
#

may he rest in peace he was a chess freak

#

and aslo he was soo good

#

in the game

latent oak
#

♟️

#

I never got to 1600… I think my max is about 1400 rapid

#

1300 blitz

#

I’m 1700 puzzles or so

toxic rock
latent oak
#

Ha!

#

No sir

unkempt cradle
toxic rock
latent oak
#

If you do puzzles it gives you an ELO

unkempt cradle
#

oh

latent oak
#

You gain like 3-5 points for solving one, and lose 6-8 for getting one wrong

#

Each puzzle is rated, and I think the points won or lost is weighted by the puzzle difficulty

toxic rock
#

you play daily mode ??!!

latent oak
#

Sometimes

#

Not often

#

A friend of mine likes to play daily… 7 days per move

#

It took like a year to finish the game

toxic rock
#

yeaaa lol

latent oak
#

Killed it

turbid goblet
#

subtl3 tell us something fun

zenith pine
turbid goblet
#

im not a cool kid

latent oak
#

Me neither

zenith pine
#

im founding certcism

manic anvil
#

guys it would be funny if someone out there started a click-fix attack on skids waz

latent oak
#

Know yours

#

😉

#

My role is mischief maker

latent oak
#

I was told in a peer-feedback that my “heart is full of mischief”

manic anvil
#

yeah talk to us when you are orange greeno

#

wait is that orange or gold but there is no server boost to make the shine animation ?

turbid goblet
#

isnt that teal tho

manic anvil
latent oak
#

It’s not easy being green

manic anvil
#

waz yeah but then again HTB is green

latent oak
#

Yep

manic anvil
#

funny thing there is another website called draw a box for learning drawing

latent oak
#

Think it’s easy for @eternal mango to put up with this nonsense?

eternal mango
crude island
#

Hello 👋

manic anvil
latent oak
#

Hey

crude island
#

Goblin is misbehaving today ?.

eternal mango
latent oak
#

Not to my knowledge

#

But who knows

crude island
#

I was kidding

eternal mango
#

So was I

#

resumes mischief

latent oak
#

And me too

#

Maybe

crude island
#

Hahhaa

latent oak
#

I am up to no good

latent oak
#

lol

crude island
#

Thats usual for you though

latent oak
#

S’true

#

My boss told me I should “pop” an engineering team that keeps avoiding security work

turbid goblet
#

so positions opening up>

#

im here

latent oak
#

I was like, yeah, I’ll just start running nmap on their production infra?

turbid goblet
#

what is nmap

latent oak
#

Secret

turbid goblet
#

damn

latent oak
#

Nmap.exe

latent oak
#

Some groups just don’t want to do what they need to do… they seem to think security is a bunch of tinfoil hat wearers

turbid goblet
#

i started sitting on as security in discovery tasks with the engineers on new client onboards and they are doing so much better with security stuff

eternal mango
#

Inside SA-Core2026-004 On the 20th of May, the Drupal Security Team released SA-CORE-2026-004 (CVE-2026-9082), a Highly critical (20/25) SQL injection in Drupal core. The issue is reachable by fully anonymous users on any deployment that backs Drupal with PostgreSQL. It was reported upstream by Michael Maturi and a fix shipped across every suppo...

manic anvil
turbid goblet
#

instead of resetting network equipment to companyname2026! they are actually using complex passwords now

ornate ibex
#

Hello Good Morning

latent oak
#

I see so much stupid stuff… oh yeah, it’s just easier to expose our stuff to the public internet so our “partners” can use it

#

Still won’t fix known CVEs

latent oak
#

Hot out?

alpine pumice
#

83 here

latent oak
#

What is that in science?

#

28?

alpine pumice
#

If you held a piece of the sun to get that hot it'd be about .5 mm radius and 1mm across, according to chatgpt

frail turtle
#

The AGIBOT Expedition A3 humanoid robot in Shenzhen, China tried dancing to Michael Jackson’s “Billie Jean” in May 2026. It pulled off the moonwalk, but the routine went wrong when the robot tripped on the steps and got dragged off stage in front of the crowd

Source: Shenzhen robot event

  • Copyright Disclaimer Under Section 107 of the Co...
▶ Play video
zenith pine
hexed flare
#

guys. which module i can find WAF exploit?

latent oak
#

No exploits here

#

This is a gardening discord

hexed flare
#

sorry

#

i mean, the module

latent oak
#

😉

crude island
#

Lol we exploit tomatoes

worthy cargo
#

Just turned on tailscale on my android phone, desktop pc, and my proxmox PVE, with proxying to 192.168.1.4 (nextcloud)

latent oak
#

Unpaid internships?

worthy cargo
#

Now nextcloud is only accessible to me

#

Finally learned tailscale

#

Somewhat

alpine pumice
#

it's ez and awesome

worthy cargo
#

Thanks man

crude island
#

@latent oak who

worthy cargo
#

I appreciate you 🙂

latent oak
#

For the tomatoes

crude island
#

Oh haha

worthy cargo
turbid goblet
#

can i scan it

alpine pumice
#

haha

#

russia tld

crude island
#

Yo kami

worthy cargo
#

It's behind cloudflare. It's a tunnel

turbid goblet
#

hi astro

crude island
#

Hru

turbid goblet
#

damn i gotta pit my site on cloudflare soon

#

its free right

worthy cargo
#

Yes

turbid goblet
#

guess ill do that this weekend

worthy cargo
crude island
#

For what eggz

eternal mango
worthy cargo
#

@alpine pumice I got someone mad at me an left my matrix room b/c I have a Russian domain.

#

facepam agree

#

I had to install tailscale on proxmox and then └─▶ tailscale serve --bg http://192.168.1.4:80

#

I tried installing tailscale in the container, but ran into routing problems.

#

Tried for an hour and coulnd't figure out it wasn't connecting to the domain. Finally figured out you have to proxy if you're behind NAT

frail turtle
#

he just sadge

worthy cargo
#

I don't get into politics or anything like that

#

I am against war and genocide and all the moral things sure

slender fern
#

then why r u a terroist bro

worthy cargo
#

But I don't let the mix with work/technology

patent lily
#

discussing politics on matrix sounds like one of the most schizophrenic things one can do

worthy cargo
#

Exactly

#

That's why I politely informed him that this is a politics free zone

worthy cargo
#

He raged and quit

worthy cargo
#

anyway

#

😄

worthy cargo
#

BTW, what do you mean by 'green role'?

terse dirge
worthy cargo
#

Look at the domain name.

#

My nickname on IRC used to be stoned

#

Like how stoned are you

#

So I got it

#

I've had this domain since 2014. Never did anything with it.

worthy cargo
#

So yesterday I setup a cloudflare tunnel for it to my home desktop

alpine pumice
#

once the russian government finds out you made up a fake russian address you're going to fall out a window

worthy cargo
#

So I can self host some stuff

iron galleon
#

once the russian government finds out I'm God they're not gonna know what to do

worthy cargo
#

Well it wasn't fake really. I used a friend's address

#

He was okay with it

#

I think

#

I can't remember it was 12 years ago

patent lily
#

they aint gonna check if it's a real address

worthy cargo
#

Either it was a fake addy or a real one.

#

But somehow it was accepted and I got me a russian tld

jagged storm
frail turtle
iron galleon
#

i remember when those billionaires literally fell out of windows

#

one in spain

patent lily
#

they were teaching them how to fly

iron galleon
#

I'm God

ornate ibex
iron galleon
#

Hello

worthy cargo
#

god of what?

iron galleon
#

I just am

worthy cargo
#

I swear to dog

turbid goblet
#

im a god of sleeping

worthy cargo
#

Talk to a hippy mctrippy psychedelic spiritual person and you'll get, 'wer're all gods'

#

Mr. Hippy McTrippy

iron galleon
#

I pledge allegiance to Anthropic

#

Claude kill them

frail turtle
#

A process starts by first having its address space allocated virtually

worthy cargo
#

How much does an electron weight?

frail turtle
#

then the program is loaded onto that space

iron galleon
#

5 kilos

worthy cargo
#

If you take a storage device, and then it's empty right, but the you fill it with data, does it gain more weight?

#

So if we had sensitive enough measuring hardware, we could weigh it and find the difference

#

I wonder what is the whole weight of the Internet

iron galleon
#

My computer is powered by light

#

when i said

#

Let There Be Light

eternal mango
worthy cargo
#

I am waiting for opticla cpus

#

brb, gonna get something to eat

frail turtle
eternal mango
#

For ssds iirc technically the act of storing data does change the weight by a teeny tiny amount

#

There was a video on this ages ago I recall watching, and had to double take on that claim..

#

Maybe from veritasium or someone like that

frail turtle
#

well it would have to because electrons have mass

#

at least from what I understand data is just stored charge

ornate ibex
#

Ig I'll go hit the bed again

eternal mango
ornate ibex
#

now its 7 AM and it feels exhausting already

bronze lion
ornate ibex
#

good night to you tho, it is time already kek

eternal mango
bronze lion
ornate ibex
frigid mountain
bronze lion
bronze lion
bronze lion
#

I most of the time forget to turn off the AC usually

frigid mountain
#

i prefer sleeping in cold

ornate ibex
frigid mountain
#

even when it's 20F out I'll sleep with my back door to my bedroom open to the deck outside

bronze lion
bronze lion
#

I usually when I feel cold turn it off

#

So the time differs a lot eachtime

frigid mountain
#

doesn't your AC have a thermostat that automatically regulates the temps?

worthy cargo
#

during 3-4am or few hours after you go to sleep, the body temperature drops

#

naturally

frigid mountain
#

this is the 21st century sir

bronze lion
worthy cargo
frigid mountain
zenith pine
#

already hecked u

worthy cargo
#

thanks

frigid mountain
worthy cargo
#

I never got into runescape

frigid mountain
#

where's @brathadair\

worthy cargo
#

Only online game I ever played really was Diablo 2 back in the day

frigid mountain
#

ah he must be on hiatus

#

Unreal Tournament 2

bronze lion
worthy cargo
#

I like openarena, quake 3 open source port with free graphics and levels

somber oasis
#

day one of asking if we will get a light theme for HTB

frail turtle
#

I want to play a video game

bronze lion
frail turtle
#

about a woman plummeting into psychosis

worthy cargo
#

he needed a break from this madness we call general chat

iron galleon
#

just plummet into psychosis in real life youll have so much more fun

frail turtle
#

the point of the game is to and buy some milk

frigid mountain
bronze lion
bronze lion
#

Nvm

frail turtle
worthy cargo
#

chama chama cham chmeloeon

#

comes and goes

#

come and goes

frail turtle
#

all we have to do

#

is walk to the store

#

and buy some milk

#

come back home should be easy

#

the game though like the soundtrack was made by a hacktivist

#

they made a whole website where you have to break into it

worthy cargo
#
terse dirge
#

Back done onto arms now

bronze lion
#

Or that's what I have heard

frail turtle
#

I will make it home

bronze lion
#

I doubt it

bronze lion
zenith pine
#

gubarz typing

rose onyx
bronze lion
manic anvil
#

what kind of mental restrain and power you have to withstand lightmod

worthy cargo
#

light mode would suck

#

so much

#

that nothing else has ever sucked in the history of sucking

#

darkmode > *

rose onyx
# worthy cargo light mode would suck

Some people actually need light mode for accessibility reasons, I will not taut that the light mode we put together is accessible, but it's probably better than nothing.

worthy cargo
#

I didn't consider accessibility

manic anvil
#

actually considering it when did lightmode staring being annoying like everything was on lightmode back then adn now one complained

rose onyx
#

People complained that dark mode didn't exist

manic anvil
#

waz why there is no green mode

worthy cargo
#

What is a green role?

#

My back hurts.

#

Ow

#

Getting old

rose onyx
#

Your name is green, thus green role

worthy cargo
#

Name is Eggzy

#

Green Eggzy and Ham

#

😄

rose onyx
#

Yum

worthy cargo
#

I only eat chickens and dead cows

#

some times mutton/goat/etc.

#

but mostly chicken and beef

#

Never do pork

rose onyx
#

Venison, and rattle are tasty too

terse dirge
limber arch
terse dirge
#

I don't really like bison that much tbh. Very gamey same with some turkey

worthy cargo
#

I get bison meat too

#

cow family

terse dirge
worthy cargo
#

I like my steak medium rare to medium

terse dirge
#

I should try blue rare steak I don't think I've ever had it that way

#

I like rare steak tho cause it tastes the best especially if you can get a quick crust on the outside

rose onyx
#

A little too chewy, need to let the fat render

worthy cargo
#

Try steak tare tare sometime

#

It's minced steak meat, seasoned, with a raw egg on top

limber arch
#

Yall eat poke?

worthy cargo
#

What's poke?

terse dirge
sick gate
#

It's just tartare

#

And it's fine to eat

limber arch
worthy cargo
#

ah yes

#

tartare

terse dirge
#

I also don't like eggs cause they upset my stomach

worthy cargo
#

I can't spell worth a dick.

sick gate
#

I'm going to make beef carpaccio later he'll yeah

worthy cargo
#

But you're Vege Lesagne

#

how can you eat meat?!

sick gate
#

🆗

bronze lion
worthy cargo
#

I thought those ranks went away

terse dirge
#

I'm probably going to make a microwave meal for dinner then have a protein shake later

#

Need to get back onto healthy habits again.

bronze lion
toxic rock
worthy cargo
#

The Cult of the Dead Cow

#

Hacker group

#

Were they lovers of steak?

#

Who knows

bronze lion
terse dirge
bronze lion
worthy cargo
#

Nice

frosty thistle
bronze lion
worthy cargo
#

I don't eat any seafood

bronze lion
worthy cargo
#

At all

bronze lion
worthy cargo
#

I can't stand the smell, taste or texture of seafood.

bronze lion
#

Damn u missing out on some tasty food

worthy cargo
#

Not my cup of tea

#

No I'm not.

bronze lion
#

I see

worthy cargo
#

I'm good.

#

🙂

sick gate
#

Ohhhh chilli soft shell crab

worthy cargo
#

Can't stand the smell. That's the worst.

sick gate
worthy cargo
#

I might every now and again have a tuna fish sandwitch at Subway

#

It's been 20 years since I had a tuna fish sandwich

#

I also have had a mcdonalds fish filet sandwich

#

I can confidently say I don't like seafood

#

of any kind

bronze lion
#

U have ever eaten crab tho?

worthy cargo
#

Maybe fried fish, battered, if it doesn't taste fishy

#

No Ihave not had crab

#

but I have had crawfish

sick gate
#

You ate the two worst seafood things of all time and claim you don't like seafood lmao

sick gate
#

Macca's fish burger and subway tuna sandwich

bronze lion
worthy cargo
#

hmm

#

maybe one day

bronze lion
worthy cargo
#

I would like to try some beluga caviar one day

sick gate
#

Yeah I ate a burger I found in the bin turns out I fucking hate burgers

bronze lion
#

I Never had caviar

frosty thistle
toxic rock
sick gate
#

Nah dont

#

More for me

bronze lion
#

I only like abt 2 fishes

#

But I love crab

worthy cargo
sick gate
#

I had the most amazing ice cream with beluga caviar on it in Denmark

bronze lion
#

Both of which I like

worthy cargo
#

Oh hell no.

#

No clam.

sick gate
#

Pipis in xo sauce YUM

worthy cargo
#

I'll give crab a shot maybe sometime, maybe.

bronze lion
#

U don't like fried clam?

worthy cargo
#

bro.

#

No.

#

ew.

toxic rock
bronze lion
#

Haha

worthy cargo
#

No thanks

toxic rock
worthy cargo
#

Lobster I might try one day

bronze lion
#

All of them don't have the 'fishy' taste u are talking abt tho

worthy cargo
#

but not crab or fish or seahorse or what have you

bronze lion
#

I didn't even know ppl eat them

sick gate
#

Man will never eat abelone

worthy cargo
#

I'm just sayin'

#

a belogna

toxic rock
sick gate
#

Seahorses are super bony

toxic rock
sick gate
#

And they usually just hold onto something in the reef

sick gate
bronze lion
#

U made me not wanna try it

#

Thnks

sick gate
#

And sea dragons just look like bits of seaweed floating around

worthy cargo
#

Good for you!

toxic rock
sick gate
#

I'm going to start an illegal Marron farm and just eat Marron for the rest of my life

frail turtle
#

what is the point of glazing over a lobster shell and not eat it

#

at that point you have to

toxic rock
bronze lion
#

Appearance matters to many ppl

toxic rock
bronze lion
#

Most chefs try to decorate their food( 4 or 5stars ones) to give it a good look even tho some foods taste like shit pr flavourless

#

Afterall there are some ppl who pay 10-20 or even 50 dollars etc for a bland food to be only put into a closed plate with some dry ice and see another guy open it

terse dirge
rose onyx
#

Actually, fresh salmon really doesn't have a fishy taste, one of the only fish I'll eat but needs to be still flopping before cooking

bronze lion
#

I only eat fried fish , and salmon is one of the best fried 'fish' I have had

#

My typos are so shit dude, literally typed friend instead of fried

limber arch
#

Yall still taking abt fish

mystic harbor
#

😭

summer urchin
#

hru

elder inlet
#

Chilling. Waiting for my tablet to charge before going to bed

bronze lion
#

Weird

#

Just turn on the smart charging and go to sleep

ornate ibex
#

Good Morning again

bleak palm
#

Waddle doo

devout sail
devout sail
#

ill not wake up tomorrow so say it in advance to me

ornate ibex
#

don't take any bad step

summer urchin
#

if they can predict
then you’re screwed

eternal mango
#

Properly sick of my brains response to not being able to sleep to decide that hyperfocusing on a subject or project that has no real value is the right thing to do instead of just laying there, hoping that sleep will come

#

Stupid brain

summer urchin
summer urchin
#

my brain doesn’t sleep quick

eternal mango
#

I knew I should be up to go to a thing today to meet someone, but instead my brain chose to sabotage itself

#

Now I don't feel safe to drive

slender fern
#

that's how I learned to make cheese.

eternal mango
#

Doesn't feel like a super power tbh, but sometimes yes that hyperfocus kicks ass

#

but not like this

slender fern
#

now i have a brined halloumi in the fridge, and bags under my eyes

rose onyx
#

I've never had much success when it kicks in when I should be sleeping, then the gf asks at 6am, "you still up?"

eternal mango
#

Not diagnosed, but it's fairly obvious. It'd take months or years to get diagnosed on the NHS

#

but I'm about fed up with them after they said it'll take 3 weeks to have a call with my GP to review my anxiety/depression meds the other day

rose onyx
#

Makes me feel great...

bronze lion
eternal mango
#

I hate having to go private because it feels like that's exactly what the toffs want people to do by killing the NHS

slender fern
#

I'm not either, but my friends lovingly describe the random pictures I send them as "your fun adhd hobbies" so I just accept it

eternal mango
#

but I need a freaking appointment

eternal mango
slender fern
#

I'll order stuff on Amazon, hyperfocus on it for 72 hours, then lose interest before the package even arrives

bronze lion
#

Ah not going would be the best then

slender fern
#

and it'll go into the closet unopened for years

bronze lion
eternal mango
#

Ah well

slender fern
bronze lion
eternal mango
#

She got me a Fuggler for my birthday present 🤣

slender fern
#

there's an arduino and various sensors somewhere in this house. I'll find them one day

bronze lion
eternal mango
#

This one

bronze lion
slender fern
#

i dont like the teeth

bronze lion
slender fern
#

it's cute without the teeth

eternal mango
#

Of course I do!

#

I bought a Gollum one a while ago that's just amazing

#

..and a Gizmo one..

#

They're just so freaking derpy

bronze lion
eternal mango
#

There was a Care Bears one we saw the other day, but my daughter said I wasn't allowed to buy it 🤣

#

(she finds them disturbing)

#

..but come on, isn't that just glorious ?!

bronze lion
eternal mango
#

🤣 fair enough

bronze lion
slender fern
#

anyone have a good workflow for after getting an initial rev shell? I always feel overwhelmed by the amount of information available and end up running in circles

bronze lion
#

It happens to the best of ppl

slender fern
#

I usually find what needs to be done, but it ends up being a tedious crawl through the entire filesystem

warped plank
#

I usually look at stuff based on the context of the machine I have a shell on

warped plank
# bronze lion Wdym?

For instance if I'm a shell on an SQL server I'll look for post-exploitation stuff related to SQL, is there an old database somewhere? are there service accounts? etc.

slender fern
#

I'm basically:
> env
> sudo -l
> find suids
> find guids
> anxiety attack

eternal mango
#

Check processes running as the user, look for services bound to localhost, bash history sometimes

bronze lion
warped plank
slender fern
warped plank
bronze lion
warped plank
eternal mango
#

Log files readable ordered by date descending can yield interesting bits sometimes

#

suid bins are not that common these days in boxes I suppose, but a good check, so long as you recognise the usual suid bins that are meant to be there

warped plank
bronze lion
#

😃

slender fern
warped plank
#

simply find one where you can write where it imports and make a pth file kek

bronze lion
#

😃

slender fern
eternal mango
#

A massive TIL when I foudn that out, but I can't quite remember it

#

Something like exec on the parent directory allows for renaming of children of the directory

#

Ok I gotta go find that out now fml

slender fern
#

so I just coulnd't figure out why nothign was working

#

and i just had to move to a different directory Sadge

eternal mango
#

Oh ok not so weird then, for a directory that you do not have read perms on but do have write perms, you are able to rename files in that dir, and then you can move a file you own into that dir and edit it.

#

Feels like I found that on a HTB or Vulnhub VM but honestly can't remember

#

Now that I read it again it makes sense, but I suppose the lack of read perms and yet still being able to do that made it feel a bit weird at the time

bronze lion
slender fern
#

it always makes sense after the fact

bronze lion
#

Thanks

eternal mango
eternal mango
#

It just confused the hell out of me that I could move a file owned by another user with no world perms on it because I had write perms to the contaning folder

#

..but you couldn't just overwrite the content in that file

#

You had to move it then write your own file to the dir

slender fern
#

well, www-data owns the folder, so even if it was standard 775 it wouldn't matter right?

eternal mango
#

Like I said, the thing that confused me was that you could rename files in the folder due to the weak parent folder permissions, but couldn't just overwrite the file directly, you had to rename it first

#

It's fairly obvious now why it's like that, but yeah

#

It confused the hell out of me back then

slender fern
#

oh yeah no I'm just trying to make sure i understand

eternal mango
slender fern
#

oh okay

#

so it's the 777 that allows it to work

#

what a goofy set up. i would have missed that

eternal mango
#

yes, even though you do not have permissions on the file you're renaming, because a rename action changes the directory entry, not the file itself, it is allowed

#

But yes, very goofy setup, but that was vulnhub back then 😄

slender fern
#

actually, it works with 775 too

eternal mango
#

Weird, it shouldn't, if you're not part of the group owning the directory

#

because that's just giving read and exec perms global right?

slender fern
#
┌─[user@parrot]─[/tmp/tmp/testing]
└──╼ $ls -la
total 0
drwxrwxr-x 2 user user 60 May 22 01:37 .
drwxrwxr-x 3 user user 60 May 22 01:36 ..
-rw-r--r-- 1 root root  0 May 22 01:36 testfile
┌─[user@parrot]─[/tmp/tmp/testing]
└──╼ $mv testfile testfile2
┌─[user@parrot]─[/tmp/tmp/testing]
└──╼ $echo "asdf" > testfile2
bash: testfile2: Permission denied
┌─[✗]─[user@parrot]─[/tmp/tmp/testing]
└──╼ $
eternal mango
#

Well yeah

frail turtle
#

Sudo sudo sudoru!

eternal mango
#

user:user owns that directory

#

So you can rename files within it due to user/group write perms

slender fern
#

yeah that's the same as the test-case you were looking at, right? with www-data owning the dir

eternal mango
#

Basically yeah

#

Same thing, just what I had above was global write perms on a folder owned by another user/group

#

But it's the same thing

slender fern
#

i didnt know these things. i learned a new

eternal mango
#

😄

slender fern
#

honestly I've seen cases like that before and never thought I could just move the file and replace it

#

pretty neat

eternal mango
#

Glad to have shared the crazy 😄

scenic maple
#

all i know is tung tung tung sahoor

slender fern
#

when did you become a mod golam? i feel like you were just a memer a couple years ago

frail turtle
#

Mozilla

scenic maple
#

i dunno tho been like an year or so

frail turtle
#

mozilla is a joke company

slender fern
scenic maple
scenic maple
frail turtle
#

we have to replace mozilla

slender fern
#

why are we hating browsers tonight?

frail turtle
#

it's just me

slender fern
#

which do you recommend

frail turtle
#

I only suggest Brave

#

or if you're paranoid Mullvad

static burrow
slender fern
#

i just want browsers to stop forcing tabs to sleep so they need to reload when I open them again. I have plenty of RAM -- just stop.

scenic maple
#

they literally stole peoples money lmao

#

in this world its not about who is the best its about who is the least bad

slender fern
#

but it's basically "chromium based browser" or firefox

eternal mango
#

Google publishes exploit code before patch, reported 42 months earlier, is fixed.

#

🤷‍♂️

frail turtle
#

42 months

#

lmfao

eternal mango
#

Just seemed relatable as you were talking of Brave

#

No shade thrown ofc 😅

frail turtle
#

@obtuse fern This is why I would just hold any exploit for ransom

eternal mango
#

I just accept that my data is not my own and use Chrome still

#

ripperoni

slender fern
#

that's what I did for razer synapse after they offered kudos for a privesc 0day

frail turtle
#

what the hell is chrome written in anyway

slender fern
#

at the end-of-the-day it's all C

#

the mother lang

eternal mango
#

Christ the number of dependencies it pulls in

#

it'd be easier to say which language it isn't written in

#

Takes longer to build Chromium than kernel

#

🤣

frosty thistle
cursive bough
#

Meow zumi

frosty thistle
#

meow

frail turtle
#

the exploit is said to put users in a botnet

frosty thistle
#

i want to be netted by a bot

cursive bough
#

Botnets were promised

#

3000 years ago

frosty thistle
#

I dont remember that

#

But maybe i fell off my dinosaur

slender fern
#

the botnet god i wish that were me is a wierd fetish

frosty thistle
#

I like fishnet stockings

cursive bough
#

I like programming socis

#

Socks

frosty thistle
#

I wear programming socks

#

Id share a pic but its not suitable for htb

eternal mango
#

I don't know all the details, but from that limited article it reads like something using the fetch api for large files resulting in a long running fetch task in the background, maybe that's being used to keep a webworker process alive past its supposed expiry when the page context is closed?

#

But that's a massive stab in the dark

eternal mango
#

Gonna read up more now, curious

frail turtle
#

oh I see

lime trout
#

How's it going y'all

frosty thistle
#

Good just had an amazing dinner

slender fern
#

wasting time

frosty thistle
#

Gnochhi baked brussel sprouts then lemon cheesecake

eternal mango
#

Oh yeah that's it

#

web service worker

cursive bough
#

I like sheep and cows n stuff like every other human

frail turtle
high cobalt
#

Too late to delete, I already saw the image 😂

lime trout
frosty thistle
#

it was fire

eternal mango
#

Neat

frosty thistle
#

sorry for blurry pics

eternal mango
#

back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

today, almost 4 years later, the bug is finally public:
issues.chromium.org/issues/400…

Reblogs

386

Favorites

526

▶ Play video
lime trout
bronze lion
cursive bough
lime trout
#

never said its bad, i just dont think most people live in an area where they even see them

eternal mango
# slender fern why does that matter?

Because the web service worker should not outlive the context of the page, and by keeping it alive it can act as an implant, performing any actions the browser can in that context

frail turtle
#

yeah though I've......like yeah I can see now how you could have a large pool like 42 million affected people

worn nova
#

How learn hacking I am a beginner are there any educational resources

frail turtle
#

but that's gotta take like a lot of hackers

west lynxBOT
frosty thistle
eternal mango
#

Chromium made the bug issue post private 😢

frail turtle
#

and a popular website

lime trout
frosty thistle
#

i have a million cats outside of my home in california

eternal mango
bronze lion
frail turtle
#

like first you need to have a popular website and then have people visit the website and download a file using your malicious JS

lime trout
#

i mean, my father in law has cows 'n donkeys n shit

eternal mango
eternal mango
frosty thistle
#

they always doing the nasty at night and yowling

bronze lion
#

Ohk

frosty thistle
#

silly aaaaaaaa cats

eternal mango
bronze lion
eternal mango
#

So just a stored xss would do

lime trout
frail turtle
#

so like visit the link. no need to trigger the download

eternal mango
#

Given that Drupal anonymous sqli from the other day recently dropped too lol

frail turtle
#

yikes yeah that's major

frosty thistle
#

i was married Sad_Squidward_Pepe

lime trout
#

i e ven touch grass

eternal mango
#

rohrow (if anyone even still uses Drupal..)

frail turtle
#

Drupal? People still use drupal?

eternal mango
#

🤣

high cobalt
frosty thistle
bronze lion
green kite
#

lots of government departments here use drupal

crude island
#

What's grass?

sick gate
frosty thistle
lime trout
high cobalt
bronze lion
frosty thistle
slender fern
lime trout
bronze lion
green kite
#

we finally got ours at the beginning of the month

lime trout
#

i mean my FIL has one i could yoink if i really wanted

eternal mango
lime trout
#

but i got no interest

eternal mango
#

CVE feeds

#

I don't watch it all as close now, but when something big comes up it is all over the place

lime trout
#

i dont even have a drivers license(yet) lmao

frail turtle
#

I want that expliot

crude island
#

Woah

frail turtle
#

now

slender fern
frosty thistle
#

ive been driving since i was 15

green kite
lime trout
frosty thistle
#

i needed to cuz i grew up in rural area

lime trout
#

0 point having one in the downtown of a big city

frosty thistle
#

we aint got buses an shit

crude island
#

Emma drives a space ship. No need for a license lol

slender fern
lime trout
bronze lion
eternal mango
# frail turtle I want that expliot

The Chromium one? I can imagine how it'd work, fetch api call to long lived request within a web service worker causing service worker to stay alive beyond it's intended lifespan

frosty thistle
eternal mango
#

but surely it's not that simple

lime trout
#

cars are kinda cheap though

crude island
lime trout
#

which sketches me out

bronze lion
lime trout
#

when all the dealers are offering 0-1% APR that market aint doing well

eternal mango
lime trout
bronze lion
frosty thistle
#

cars arent cheap lol

#

maybe beaters are

lime trout
bronze lion
#

Exactly

lime trout
#

which is weird

crude island
lime trout
frosty thistle
#

when you are rich everything is cheap

crude island
slender fern
#

i should see if i can refinance... my auto loan is at like 6.2%

lime trout
#

maybe wes coast after a bit

bronze lion
lime trout
frosty thistle
#

seattle is nice im there rn and lived here for many years

crude island
#

Yea zumi is rich

lime trout
#

have my gripes with Washington & Cali

frosty thistle
#

no i spend all my money on programming socks

frosty thistle
lime trout
frosty thistle
#

oregon is dangerous outside of portland

sturdy thistle
#

Ellow

crude island
#

@sturdy thistle hi

bronze lion
lime trout
frosty thistle
#

You know what im talking about

lime trout
#

idk it doesnt really bother me

sturdy thistle
#

Hey Emma

bronze lion
#

Mhm

frosty thistle
#

Thats good ^^

crude island
#

Don't move to AZ if you dont like heat

lime trout
#

i know how to protect myself if i need to lol

lime trout
frosty thistle
#

Good 😌

lime trout
#

phoenix is cursed as a city

crude island
bronze lion
frosty thistle
#

Summers in california kill me

crude island
#

Oh yea phx is ass lol

frosty thistle
#

so fucking hot

frosty thistle
#

carry gat Levi

#

we carry gats

bronze lion
crude island
#

Pew pew

bronze lion
lime trout
bronze lion
crude island
#

Emma is a gangster

bronze lion
#

U made it sound illegal now

frosty thistle
#

Its dangerous here

#

For certain peoplez

lime trout
frosty thistle
#

like me

bronze lion
lime trout
#

yes, and inspect element big crime

#

atleast according to Missouri

frosty thistle
bronze lion
#

I see

slender fern
#

it's fine california thinks metal lathes are 3d printers

bronze lion
#

Aren't they

slender fern
#

anything that uses additive or subtractive manufacturing apparently

bronze lion
#

(joke) .
😞

lime trout
#

damn

slender fern