#general
1 messages Β· Page 761 of 1
it's an attack very specific to US military networks
and hardened ad envs
PtTGT
yes
SCptTGT
if u wanna read more about it and my very bad code
medium article and github
send
I believe in changing states
@frosty thistle send me your stuff. I'd like to mold it into something powershell based for an exercise
since im AD and have admin creds
Question about medium blogs
As a noob to this realm, is there even a point to making box writeups for boxes everyone has already written up
if you're looking for a job, yes
tf?
you disagree?
heavily
why?
i didnt do any writeups for my current job but i was talking about cve and cert stuff publicly
i never done a box writeup outside of certs actually
and work reports
but i see why u think that asylum
is having an online persona on social media with writeups not useful?
naw was just my thoughts on someone new, asking if it was worth the time
I don't bust balls
I think yes, it's worth the time
I think it can be helpful
it can also hurt u
if you dont know how to do good writeups
so if it looks like shiitaki mushroom
and full of spelling mistakes

HR is gonna look you up though. If you don't already have an "in" to the industry, your online pressence is all you have
might as well have something to look up
lmao
@molten bobcat am I crazy?
i kinda want to know the opinion of you guys though. I didn't expect to get "lmao" responses
idk why he isnt saying anything
Ok so I still dont know

I've been lucky in just knowing people. so it's been a non-issue
Put house alarm to every ping

Bachelors Degree in Cybersecurity
OSCP
OSWA
Grind Htb machines
Work at AWS as a support contractor doing vuln remediation for nearly two years
Sec+
Write one article on a CVE i found
Get good at AD
Fail a bunch of Pentesting Interviews and security engineer interviews
Bitch on Discord which is when my boss asked me to DM him
Interviewed with them
Did well enough to start as senior tester
thats everything in a nutshell i did to lead to my first pentest role
nice
TL;DR bitch on discord
just don't know how the OP asking about doing writeups, and me saying yes it's a good idea, being responded with "lmao" makes sense
theres a few other random jobs i worked where i helped train AIs
just got the ejpt, cpts THOOOOOOOOOOOOOOON
IT DOES WORK SOEMTIMES
congrats
i can explain gimme minuto
ty ty i remember u
noted, maybe i'll try it one day
ahhh once i finish the THM things, ill be here again 
people have been getting their medium accounts banned for simply having htb content
i meant to turn my coffee maker off, i accidentally made another cup instead
you can self host or put somehwere else
substack? selfhost is easiest, just run a damn jekyll blog lmfao
what i would also like to say is that you're putting too much weight into a blog
use github pages
no fear zumi, i will drink it
its nice but its not what they're after mainly
what are "they" after mainly
crazy aaaaaaaa i wouldn't be able to sleep
"they" are the people who are hiring infosec roles
A strong handshake and eye contact
and what are they after?
i'll probably pass out before finishing the second
and what "they" are after are passionate people with credentials and experience
all a blog does is prove "this person is passionate"
the efficacy of this is a YMMV thing
do not put all eggs into one basket
crazyyyyyyyy π
if feels like you agree with me then
thats the approach i took
Just as a noob I will have a friends recommendation coming up, but i dont want to lean solely on that is why id want to write a blog or make something art related
i just did many things
being able to prove you have a tangible passion is nice
but like
its werid
most of my employers straight up ignored my OSCP
i think taking many approaches is good
to include writing
why not
you have people straight up asking how to get a job in this career field. what the fuck do you recommend
your tone sucks
you're being so vague and evasive
i am not attacking you
I was commenting on the nuance and weirdness in the hiring situation
what do you recommend @molten bobcat
how the fuck you interpreted this as a tone is beyond me
literally what do you recommend
which certs do you particularly think are useful for employment
whatever it is, it's 100% not this deep
How this guy is a community contributor with this shit attitude is beyond me.
Every time I see him talk, he's insulting people.
@molten bobcat you are useless.
LMAO
gang
See what I mean?
Claude is useless
this really tickling my pickle
y'all are fucked up in the head to take anything any of you fuck heads say in this chat seriously

π
HEY
Certified human trafficker awareness or whatever
i say useful things 1 out of 100 times
im CPR certified
im that bitch
Good music always puts me in a good mood! π
https://www.youtube.com/watch?v=0dg-fUN7aXI this is sick. Been on repeat since I discovered it hours ago.
βΊ Subscribe: http://bit.ly/SubscribeNeogoa
Triglav is the new conceptual release from the Croatian duo Lunar Dawn featuring three new tracks and four bonus remixes, including collaboration work with Amir John Haddad (a touring member of Juno Reactor). Since the release of their debut album Kolovrat back in 2015, Lunar Dawn wanted to make some...
Man. I can't even how good this track is.
How do you get a community contributer role
y'all need to check out post sex nachos
yea how about we keep it pg13 thanks
Someone hasn't had his nachos
Nachos are explicit?
I will say sometimes people are condescending here, but if you separate the tone from advice its helpful
sorry about the mixup there anno
I found out there's a company that makes turkey day gravy for post dinner activities
Oh not your fault
You weren't lol
it's an actual band
I was also busy and just returned to read
prima/vera is their most recent album
my bad bro
Just the topic on rude people reminded me of some of my previous interactions here
no it's all good
I also like different opinions to the topic of blogging
I have one π
For me, as a noob in cybersec, yeah a blog not gonna make some employer shit their pants, but maybe could show passion at least
My resume itself can lead to my character especially if I can talk to them
Despite lack of it experience
I just need qualifications and the knowledge
To break in
Doesn't have to be specifically about machines you've completed, can be anything you want it to be. light bulb moments, tools you just discovered that you think are really cool, a cve you thought was novel and did a deeper dive into the why.
I need to incorporate my art into these writeups too
Could separate my blogs from others
At keast add some ZEST
I love zest
Writeups not box related sound interesting too
Just hard to find a topic people already haven't done a million times
So ill either need to revolutionize an approach to an already established topic or git gud and find something novel
I can read Japanese so maybe there are things in their outdated infra I can read up on
Then translate to english
If someone is interested in you outside of the regular job application process they will probably look at your blog and advocate for you
Makes sense.
Or if you go further into the process
but more depth
I have looked at applicants projects
Anything stand out?
I personally dont like doing box writeups, i just write about random things i find interesting
It doesn't have to be unique but made with love a write up is a write up after all
I've not done it for cybersec roles but I've seen people going for sysadmin roles who had developed automation tools etc
Yo zumi π
Yo hru
its me Zumi!!!
I see
great to hear
fische
glub glub
fimsh
funny fish
@open lava stalker
Im just messing with him
No maybe i just left th chat open to do something else π
Your fullness killed the server
Good
Hi how do i get the symbol thing after my name?
He ate the people π
Multiple servers actually
U gotta earn certs for that
Or complete seasonal boxes
morrow
blazingly fast Code optimizations while risking every sense of security known to man!
This is how I will use my pc from now on
As god intended
more work opportunities for the rest of us
job security

today
indeed

MY FAVORITE MOD! You're late 
Yes. I had to put pH and chlorides in the pool
It needs to be ready in a few hours
that takes like 5 minutes
Yes. Iβm only 5 minutes late sir
no sir, you are 1 hour late
I don't have a pool, I have to swim in the lake like a poor people 
Itβs only a simple Intex pool
No biggy
omg even easier
ceald is drunk
might go to a night market tomorrow π
Howβs it going @rose onyx
no sadly
Finally legal drinking age
i is going
dming link
i'm eating hummus and pita chips and olive oil
I love hummus
wanna see the show I was just at?
Sure
humans and olive oil? π€
uh oh too many embeds at once
Oh no bro got muted
It happened to me too a few days ago
Talk to a mod they'll reverse it
SPARKLES FIX IT PLOX!
Wow pinging @green kite for nothing
ok four at a time
Thank you nuts
Well how was I supposed to know SuperNuts was gonna do it
For unmuting
I don't have magical knowledge powers
Adam Sandler: They're all gonna laugh at you: Buddy
hummas and olive oil so good together
Provided to YouTube by Warner Records
Buddy Β· Adam Sandler
They're All Gonna Laugh at You!
β 1993 Warner Records Inc.
Lead Vocals: Adam Sandler
Writer: A. Sandler
Writer: R. Schneider
Auto-generated by YouTube.
i can eat as much as I want because theyre super foods
that album was epic when i was 15-16
Same
humans are not super foods
adam sandler distrack?
peak 90s humor
comedy album
my older sister had it
i remember listening to it in her apartment when she was like 21 and I was 15

do a git pull and check out bhtui again π
ok, will do in a while
Hwllo
Hwllo
Hmm. There seems to be quiet a bit confusion about PQC. Many people seem to think they have time to migrate until 2030, and they can use all that time. No. That's the cutoff when non-PQC will be disabled.
damn pizza is soo good
Whats the topings?
spaghetti as topping
@rose onyx probably like pineapple strawberry pizza

Honestly it doesn't look bad
It's like spaghetti with bread sticks

A more inhumane unethical combo would be pinapple

ss13 pizza hands
Fish will swim up your...you know
Ss13 is based
35,000 SK Hynix employees in Korea will receive 500M Won ($350K) ~ 700M Won ($450K) Bonus a year for at least the next three years, a period during which the semiconductor sector is expected to keep growing. Next year the bonus is expected to reach to 1.3 Billion Won($900K) because of more profits.
Hello,I am new to the cyber- world. I wanna do offensive, but first for that I wanna start understanding defensive, I know the basics , can anyone suggest the starter module for start of Defensive security
?
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
@novel hornet
h
Good morning general
This is a forked epiphany browser with ML-DSA support, connecting to web server using only post-quantum cryptography. No mainstream browser supports this stuff. Chomium will in late 2027, and most browser vendors will release the support in 2028. 
MLKEM+ML-DSA π
My home lab is now officially in 2028 
the adam sandler cd's that he used to release 20 years ago were fucking epic
toll booth willie
Why didn't you bring home the jackpot numbers instead of Post Quantum Encryption?
But jokes aside, how did you set up post quantum enc on the server?
I'm just doing some background research and oh boy everything related to certificates in real world will change because the way they are signed and produced will be completely transformed
Oh I have a obsidian note 
47 days maximum lifespan waiting room β°
it's more than that. you have to actually update your software as well, as the quorom signing thing will have markers that come with installed software packages, not via the certificates itself
so if you for example skip a monthly browser update, your users will not be able to connect all new services π
standalone certificate carries the inclusion proof plus a quorum of cosignatures over the containing subtree, sufficient for any conformant relying party. A landmark-relative certificate carries only the inclusion proof and no signatures at all, on the assumption that the relying party has already fetched, out of band, the hash of the landmark subtree the proof terminates in. Standalone works with any client; landmark-relative only works with up-to-date clients that maintain a current set of landmark hashes.
yeah i know i was oversimplifying the thing
im just thinking about companies whos still updating everything manually lol
its gonna be funny
they will be effectively disconnected from the internet
how does this work will other sites support it
you need those landmark hash updates
Sounds like ... an awfull user experience π΅βπ«
what do you mean? every single web site will be forced to switch before 2030, because in 2030 the pre-pqc algorihtms will be disabled globally from all software
yeah but how will it run now
oh outside the lab since I have the only actually working browser that can connect my web server, the user experience is slightly poor 
the user experience is good in about 1 in 8 billion
The algorithms are not hard, they are in libraries. The real issue seems to be that the shortening of the certificate lifespans and the fact that PQC certificates are huge forces them to re-implement most of how CAs work from the scratch. And since there are interoperability issues, not even the RFC is approved yet.
that how many donuts you have eaten?
uhhhhhhhhhh
sure
AKA codeforces rating
but
yk
thats better
morning
mornin mick π
hows your day goin
gucci
Wait what???
just restarted CJCA to get the report done lol
πͺ
.
Well only Report and Blue part needs to be done
That's in just 4 years, in 2026 People are still running Software with TLS < 1.2. Do you mean its forced via Certificate Authorities? How is that gonna supposed to work?!
hello mickhat, i havent forgotten the middle finger emoji you sent me on 3/12/2022 at 8:37 pm
but how are you
donut always asks how people are doing, but do people ask how donut is doing? 
YOOOOOOOOOOOOOO
just like that
amazing thank you
YOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO
satuday is fucking amazing
i found this laying on my floor
take it
β₯οΈ
its not dirty dont worry
Thank you!
my pleasure ! happy saturday !
good sir/ma'am
saturday & happy do NOT go in the same sentence
why
cuz i said so
why would i believe you you dont like peanut butter
ok, thank you good cat
not when they're together, nuh uh
MODS
ok, back to CJCA
gl sir
i'm gonna pretend i understand what the first C means
hiyaa everyoneee
for you it means crazy
peanut butter is peak and people who dont like it are fundamentally untrustworthy
Peanut butter π β€οΈ
you an opp gng
π«π«π«
Peanut butter WITH any cholocate cream π β€οΈ β€οΈ β€οΈ β€οΈ β€οΈ β€οΈ
Wdym, mixing these two tastes like Snickers
I hope you beat @tough oyster to it 
Need to speak to a person? Learn how to reach our support via HTB Labs.
i got 100 points in the red part
I think you are the one who is crazy ...
Who doesn't like Snickers?!
i plead nuh uh
present ma'am ππ»ββοΈ
Where R ya with your reporting. I'm also at 100 points but only going to submit 80 cus I can't be fucked writing the full report for all machines
no, DO IT
nah. been doing this ALL DAY today and yesterday
red part is ready - i took 2 voucher for everything
I dont block people but this guy is getting close
i'm starting to think y'all are autobots
analysis of Nvidia pivoting away from personal computing:
https://youtu.be/SUqQrlLV0tU?si=my_o7sOsqlT12qhG
good luck bro
What's everyone's thoughts on black licorice?
fucking love it
yes
Itβs not as bad as people say it is.
Based
Lol
No, I am an advanced AI
A member here called me out a few days ago π
Ikr it's just like red vines but they taste herbal and have that crisp/freshness like mint
it's because of the plant family, same ones as star anise, and fennel
I wonder if I can make star anise and fennel into licorice flavors
That'd be interesting
the gpu smuggling business is thriving
"yo you got the compute?" "yea I got the compute, wachu need?"
anethole look it up, crazy shit
Hi guys
Ayo I can give u 100 tokens as sample for da compute prompt yo sox off kid
anise is made into booze, and it tastes very nice
like sambuca?
Who dat?
Nice
let me google that for you
wait what you guys drink non-alcoholic drinks, too 
yoo man that compute was some good stuff... but I need more tokens... can't finish this program without some tokens
Yeah only when I'm not drinking
π€
Ooo nice.
It's a liquor
Jagermiester and orange soda sounds good rn
Maybe I'll try to get some Jager at the night market tomorrow
If I remember correctly it reminded myself of a fancier coca-cola
I kind of feel like hacking, but I have headache so I guess it's video games instead 
will video games help with headache?
What can i do (legally) with a diy flipper (esp32 with Bruce) guys? Im making one but dont know what to do with it instead of turning on/off tvπ
legally you can do very few things tho
Ahh, imma just turning on/off tv then
π
Change tvs in bars to cartoons
π
FCC notified
Wait... Im not old enough for bars
Bruh
is anyone else excited for Toy Story 5
how old are you?
14

wth how do I pop a shell on this
@scenic maple
π©
You need to be 18+ to make an account on HTB or get your parents to sign the permission form
Dang
golam is 14 yr old
you are missing a few zeros
1400 yr
bro is more ancient than @supple plume
and you're an 18 yr old baby 
I had some double chocolate chip cookies and they were great
Damn I also got leg day on Saturday
every saturday?
The verdict was || not guilty because of a lack of evidence that the defendant was in possession of drugs and that they were theirs all we had was a cell phone recording of security camera footage and it was really shitty ||
Oof. Yeah listen to your body man
I gotta skip leg day because I got a small hamstring injury at bjj 
Yeah and first time I was selected to be a juror and sit through the whole trial
It was very boring and I got a drink afterwards on both days cause why not yk
Oof
First day was a shot of tequila at a taco place and second day was a gin tonic at a local place
Will do, want to hit up a competition in like two months, so it better heal quick 
Oh shit I should probably get cash tomorrow for the night market but idk maybe I shouldn't buy anything lol kinda poor rn have only around $100 left in my account including jury duty payment
I'll spend my jury duty money at the market cause then fees will start applying and stuff
when u get money?
From old job and jury duty
and when u get new one?
I got paid like $40 a day I think
Idk. Still waiting on their hr now after I filled out more forms
yoink
Biweekly
how does US work 
It truly is a mystery
It's different for every job I believe
Why i meet u again hereπ
see, i get it once a month
lel
I probably won't even need to pay taxes cause I'll be making $15 an hour for 19 hours a week
Bro is in every chat im in

From my previous job I got like $300 back from a tax refund
At previous job I was making $19 an hour for 19.5 hours a week
It was ok pay but there was a lack of communication with management and I wasn't really sure who all I worked with lmao
the stupid Big Small 4s of my nation asks for 70-90hrs a week
on a paygrade of 3000-5000$ at max per year
Oof. Mines only a part time job
If I was renting then I'd not be making enough at all
top tier job to slip into the darkness and get paid for nothing
well stuff are cheap in my country so less pay as well
my monthly rent+food costs like not more than 200$
UwU.
Yeah I probably could've gotten away with that lmao but I decided not to because I didn't know what my coworker was doing and that's also how I became the sysadmin for the cyber range
19/hr for sysadmin work on legacy systems π
One time I deployed a domain controller and a secondary one to make a forest with ad cs and mssql
It wasn't great when I was getting paid and it's not any better now that I do it without pay but I've distanced myself more now

At some work places it is odd how little you can get away with. I had one co-worker that would fall asleep at his desk, and he was only let go after he asked for a reference for a new job that he got 

My coworker did stuff. I trusted them that they were actually doing their part
I still sometimes talk with them, they're pretty cool
Ouff I can't devide between playing video games and continue learning hacking right now ...
New job will be a soc analyst apprenticeship so I'll be doing real cyber now
Do the hacking, I am sure there is an easy box that you could do 
Oooh, good luck!
I mean the easy box I def. wanna do is released in a few hours ... but that's in the evening here 
just 1 more game of war thunder
gaming π΄
Word? Congrats
Ty still haven't gotten it yet tho
Yeah I always hate the release times for boxes. Like sure it is a saturday, but I am often having my meal and watching TV with my girlfriend, bit awkward to just grab the laptop and start muttering about nmap scans
Good luck on the job
job
No its not awkward at all, thats standard practice
pls dont say those offense words
congrats mate!
Yeah, maybe I will do it tomorrow, in the winter it is okay with 8pm, but 9pm is a bit too late :D
which platforms are you using to apply
There's only really LinkedIn, for IT 
π
Irl. My new boss will end up being my boss from my previous job
dang that internship came in clutch
The whole lack of communication was after my old boss left for the last like 4 months of that internship
Unfortunately I cannot talk too much about the new job lol
imagine being in Belgium
Just imagine....
I got to go walk the dogs before I can get root, but the silentium box is super fun
Belgium sounds awesome
it's nice
Arizona is kinda nice just not during summer 
Planning a day trip in 2 weeks to Lowell Arizona
Hello, good afternoon
How was helix 
Maybe even hit up one of the retro diners in Arizona afterwards too
/opt its like storing data from any file right
Same as tmp
Right?
If I was local user I will be using bin
If I'm root I will use sbin the
Tools inside sbin for root
No, /tmp is for temporary files, /opt is for installing third party software
No
Got it now thirdparty that I download it from other source right?
Finally I'm getting great in linux file hierarchy
Not really. Local users it's preferred to use /usr/local/bin or /usr/bin while system users/accounts would use /bin and sbin are things only root can run like updating grub
I'm probably wrong but 
Sbin only for roots
This reminds me why I prefer BSD
Bin only for the local users
No root can use anything in /bin and /usr/local/bin and /usr/bin
/sbin This directory contains executables used for system administration (binary system files).
You can run echo $PATH to see what your user paths are
Its like pwd right?c
No it shows you what directories you have added to your path
What the point of path ,
To show where your user's executable files are without having to type the absolute path
Okay like inside the sbin where the files okay I got u
Like /bin would be in your path
Not system accounts. Service accounts
Service accounts are things like www-data
Okay the bin its for commands ls cat to work right?
It's the directory for where those binaries are located
But the sbin it will give us the files root and how to access right ?
No
The binaries is ls cat to deal with shell for kernel
yes ls and cat are compiled binaries they exist at /bin/ls and /bin/cat
Sbin is for stuff like containing binaries for updating grub.. there may be system links for those higher level binaries but sbin contains uniquely stuff that like updating grub.
Yes
Okay okay got it or shutdown u should to be root to access these commands by the sbin I got u or configure hardisk
Confuse
Iβve never seen an env where PATH was unmodifiable 
Man I really feel linux file hierachy Feel it hard little
You can restart and shutdown your system through the init system depending on how it's configured you can do it without root
the path variable indicates where to look for binaries, if you empty it and call ls or cat it will say "ls not found"
Uhh no. You can change it
oh damn you're right
morning
the only time i did this attack was on pwn college and in the next exercice i did they had path unwritable, my mistake
Haven't done it yet, but it is on the list once I finish the bare bones of the write up for Silentium. Doing one final push to rank up before the legacy ranks disappear
Got any hints? 
is silentium a good box?
Yeah I have had a lot of fun with it so far. User had a few more steps than I had expected, but the issues it has are fun to do
I'm starting out my cybersecurity path in htb, is it normal for me to take longer than the time expected for the module
absolutely
each person has diff pace
What part r u at, u can dm if need i can see if its a part i understand wel
I just didn't understand how someone can zoom past a module in 6 hours I've been at for like 3 days now π€£
It's all good just keep going at it
Take as long as you need to actually understand it
will do sire
I plus 1 that but i also recommend absolutely taking notes regardless
Yes
Oh no I was just being silly since tarfouss is the creator of Helix, so was seeing if he would give me anything 
Oooooh lmao didnt notice that
I'm new to cybersecurity (actually saw some of it in college but the minimum of theory and cryptography, nothing practical), do you guys recommend the junior cybersecurity associate course or should I complement it with some other module that it doesn't include?

Junior course is really good, gives you a good breakdown of offensive and defensive techniques which can set you up well for general SOC/Security work. Thing is that no one course will give you everything you need, so it all comes down to interests and where you may think the jobs in cyber sec are going.
Okok, thanks
I'll do the course and if I feel I'm missing on somthing I'll do extra modules
In theory, Junior course, CPTS course and the web pentester course is probably around all of the content you may need to be a valuable member of an offensive pentesting team at a junior level.
btw @austere sigil
Which is a lot of content, and YMMV depending on a whole lot of factors.
CPTS junior ?
Yeah, in my experience, if you don't have a lot of that knowledge progression at corpos is super painful
All that knowledge applies well even at senior level, but even trying to get junior pentester roles in the UK basically requires you to have good inf knowledge, without it, interviews are brutal
u just answered ur self
Will take into account
Look at my second reply 
a lot of that knowledge progression at corpos is super painful

Can i use same vpn hackthebox provide in my local and docker machine in same time.
I assume you are taking it as progression to senior? My point is that even to get into pentesting roles or progress into more valuable positions as a junior you need that inf knowledge
I get what you mean but if you have CPTS you already prove you know what you doing for a mid junior ( 2 months to become senior)
alot of seniors can't do half cpts
Yes, but that's pain in the ass
jst forward
jfyi cpts is x10 harder than oscp
That may be true for some orgs! Unfortunately it is not quite accurate at my current org.
try docker run -it ubuntu bash
ik ik
Crazy
whatever your docker cont is, fix the line
I have done like 90% of CPTS and I am not even considered "capable" of doing inf assessments 
Ok i fix it
I am warred if htb team see i use 2 machine my vpn they ban me.That's why i am not trying it.
Though I am also in an odd position because I am just about to sit a web app exam that would make me a senior in that specialism. It is what it is π€·ββοΈ
in ur point of view what is the cert that is senior level then lol ..
cape is though
Well, I am basing my opinion on what is considered desirable or required within the UK cyber security scene
so, basically you aren't a senior unless you have CCT Inf, App or CSTL Inf or App.
But yeah, CPTS would be about junior level in an inf pentesting role
CEH
CHTAP
my dream cert man
SYBAU
Certified Human Trafficking Awareness Professional?
Yes that one
i will never obtain it π
after cape its osed time
hello, I'm new too, CPTS is worth it? Do enterprises consider it very good? Or should I do smaller modules first
Yup CPTS is worth it, but it's rlly hard
u need to type -embedallow man
Try cjca or cwee ar first
crackmapexec -h
are u calling me out
im stupid and about a week ago i found out nxc is a replacement of crack map kek
tbf i learned that through the netexec module
i liked it, pretty cool module
you gotta ignore all commands they give and use nxc instead(most commands apply)
its that one, but its the same shit
btw how do I get the Verified tag inside Discord?
Most enterprises accept that the exam is good, but I don't often see many that have it listed as a desired/required cert. So it really depends on what you are personally seeing in your country/local job market. The knowledge in it is great, and will help you get further certs even if your local job market don't seem to recognise it as much.
If you go to your HTB profile, you should see an option to link it to your discord. If you do that you get the tag.
Specifically on this page: https://account.hackthebox.com/security-settings
i dont see any cyber jobs in my country 
come to america golam
Thanks, it worked!
but u can make more money here bc capitalism
can i get help on the selentium box?
You guys see that drupal has an active SQL exploit?
i think all that ice shit fizzled out
nah not at all
dm
sure
I'd say come to the UK, but I don't even know if you would get security clearance 
whats the requirements for getting one
yes?
i thought golam was american
let's say I built an automated pipeline that does due diligence scans of ransomware executable across a massive library of collected ransomware. What are the odds that something crawls out of my VM if I were to let this run? Any advice on how to do this without worrying about nuking my host?
i forgot ngl 
remote?
CPTS π₯
remote is difficult
I was afk so I couldn't respond earlier
A job
and also a whole bunch of things related to your immigration status, country of birth, any potential criminal or financial history issues etc.
the chance is pretty low tbh unless its high end malware but i would say do the basic stuff like disconnecting it from the network etc
easier than remote ngl
Depending where you are based, I have no idea if the UK government would even allow it. I have heard some people having issues just for being the wrong kind of irish due to family history.
I already planned on this
yall still beefing ?
still going
I guess I'll just make a snapshot of my system and hope for the best
Not really beefing, but more so, if your uncle is a member of a known "terrorist" group, getting clearance is unsurprisingly problematic 
idk they just gave it to me man
yeah

just like that , 
i mean, im indian in the uk and i didn't have any issues coming here
golam isnt from india tho
Oh this is specifically about getting government clearance, not an immigration thing. The UK has gone out of its way many times to bring over people from India
oh I see
how did you get visa
germany?
not me
classified
nah
my dad did
that explains it
my fam moved here a while back
My partner is from India as well. Her visa process is kind of annoying at the minute.
she has to do some dumb test about british history/culture
All I could offer her was a musical about the order in which Henry's wife got beheaded and some random fact about the battle of hastings
haha
Oh no, I would be deported unless it was pub facts
i cant even read
british people loved blowing up copenhagen
you came here to hack not read
wach azumanga daioh
WE LOVE AZUMANAGA DAIOH
good suggestion

americayaa
hru levi
im waiting for hotel breakfast to open hueheuhue
never been better
hiii kami
went abroad for work?
good to hear me brain broken
nooooo im in a different state
oh
for pentest
i see
zumi i tried making fun of u but u ignored me
can anyone help me with setting up ovpn inside a virtual machine using kali? when I try to connect the the target machine it keeps saying "port 22: No route to host" halp plz
THAT WAS MAKING FUN OF ME???
no earlier
Well, have you connected to the VPN?
whats the command u used btw?
are you using the right ovpn? are you running sudo openvpn filename
"zumi the type of guy to type out netexec"
II like the progression in those questions.
one fucking time i couldnt figure out why i couldnt connect to a htb machine
i was using an offsec vpn

WHAT
youre not wrong tho

but i just use commandmgr.com
unless im in a airgap environment then i do manually type it 
or alias it to n
cuz im lazy
p is penelope
n is nxc
rnc is sudo rlwrap nc -nvlp
thats right i know python
can you DDOS and SWAT π₯· ?
no 
is this tuff gng?
why is australia the ip pinger nation

you dont wanna know
so tuff
solving real bug bounty machines, interested people can come and watch
oh yeah its 100% connected and I downloaded the file
chat is this real
yeah its the right file, I delete old ones right after I use them
try udp or tcp
try different region
big chungus sends his regards
Im doing tcp to avoid packet loss since I thought that was the problem but its still messed up idk wtf to do
congrats spiderman 2
try udp or diff region
Pingpong
which machine you connecting to and what's the name of your openvpn file
Maybe because the have high latency to the rest of the world? 
strong suspicion it's something stupid like tryna use the starting-point vpn for machines
it aint that. maybe my firewall on my machine is blocking the vpn connection from connecting on the vm? because I noticed I couldnt load any webpages after connecting to the vpn
check what wild said
if u think its firewall just turn off firewall
that would confirm or deny
"academy-regular.ovpn" and im using kali
what machine
can you even curse here
which module and section?
anyone wanna help me with the silentium box?
nah
linux, legit the first starting module
against the rules
dern
ask in #boxes 
you do realize there's a lot of linux modules
gotta be more specific
linux fundamentals i would guess
for all you know he's doing the Getting Started one 
lol
Hi guys! Beginner here, do I need to install supplementary tools on my kali Linux vm ? I plan to work through openvpn
@left hornet this one?
YE
not really
atleast not for now i would say
ok, you running openvpn and ssh in separate terminal sessions? also openvpn running as sudo?
no but you do need to uninstall cadaver
you will never use it
Gotcha
i havent ever used it nor heard of it tbh
Now I'mma make a box that forces you to use it 
WebDav stuff
NOOOOO
π«©
i have an interesting idea for a box but when the hell will i ever have time to make it
link?
Why uninstall it even of you never use it?
basically like smb or ftp but noone uses it
it was a joke
who tryna fish with me in stardew valley
thats like asking someone to date
clint flirting
Qemu supports PCIe passthrough 
doing this means potential DEATH 
fastest way to brick not only your VM but also your host 
clint got rejected too many times. looksmaxx in the next update
Is it for real dangerous?
ngl i overthought that i thought u were talking ab someone else lmao
I mean... you are dealing with giving up kernel level control of PCI drivers to your VM which can fudge up a lot of stuff
damn i like sql injected or something idk is that a funny hacker joke
better not knowing i think
yea not going anywhere near that with my current project
Bro my privesc is so shit

I bought some nice herbal tea instead
turmeric, ginger, and something else
something else eh π΅οΈ
cardemom i think the name is
There does seem a lot of little ends to check
I know a lot of people are using WinPEAS and LinPEAS for this. But I think I want to learn what it checks first
In case I ever had to do it manually or at least understand everything it looks for
Yeah i do both for practice
Even with peas sometimes i miss things bc im still so nooby
Linpeas does often just spam you with bs as well. So it can be easy to miss real things
When the new season starts does the first machine drop at the very start or do we have to wait ?
?
Could take ya 10seconds to find that answer lol
Something went wrong
Cannot log in user because it's already linked with another HTB Account
Please disable any browser extensions or use an incognito tab
and retry the operation. If the problem persists,
you can always contact our support team.
I think I may have deleted my account a while ago accidentaly and now when I create a user with the same email I get the above error. Is there a way I can recover my old account?
Contact support
Need to speak to a person? Learn how to reach our support via HTB Labs.
@warped plank thanks
passed cysa yesterday as a high schooler! score: 791
Nice job
-h i want to install a specific list for directory fuzzig for ffuz module guide me .....
in my wsl
you write dirs locations, one per line, in a txt file




