#general
1 messages · Page 2392 of 1
ask for mr robot
okay thanks
Gave +1 Rep to @cursive bone (current: #319 - 32)
yes
thats one of the most common beginner web vulns. its just when a web app exposes a reference to an internal object like a db record or file or user ac
like https://site.com/invoice?id=1042
you change 1042 to 1041 and suddenly your viewing someone elses invoice. its when devs fail to check who owns what
its rare
well i know basic dude i am here to find some Friends i can work and grow together like a team
It still shows up pretty consistently on smaller apps that do bug bounties
didnt you ask abt idor 😭
simple idor not work but some tech works tho
yeah i do but not basic
This is a decent live demo of information disclosure 😭
path enumeration recon phase complete
how u engage with target can i know ?
On my website i have admin portal and i have under the login box the password written
So i dont forget it
I send them a box of chocolates and a heartfelt letter (penpal)
default credentials 🥹
really ?
maybe
send them a handwritten letter of your undying allegiance towards their corporation
so u find any bugs yet ? or any certification ?
The biggest attack vector is always social engineering. MOST systems are not hacked, they are talked into. humans are always the weakest link, always.
yes 75 % around i think
yeah its like 65-75% its been cited in quite a few places
is there any one want to work together ?
Holy security webpage
I smell claude
No
i can sniff out claude design UI from a mile away
Its Gemini
...so u added a whole backend
So what
Hi everyone. Has anyone else had their league progress reset? I was in the Gold League, but today it dropped me to Silver. Was there some kind of bug?
but didnt secure it?
Its easier than ope the file every time i add something new
ok
Its a portfolio not a company webpage

and exactly what u did opposite
i wanna see ur potfolio tho , do share link thx
Gave +1 Rep to @quasi dome (current: #368 - 25)
I want to add a project or cert or course or experience i dont have to edit my html for that just do that in 1 minute instead with that portal
i think they are implying they can add to the portfolio using front end UI instead of putting it into the backend
Sure i will share it as soon as i finish it
even by mistake if someone yoinks the Admin login, Its GG for his whole site
Mmm good question
Its sucks
yeah it adds a lot of complexity

J hate editing
lock in
what did u even use for backend then?
Cmon guys what ever it is it doesnt have to be secured
i yoinked my money on the domain rather than a VPS and Backend hosting
Not if they used something like vercel
Cloudflare
i use cloudflare tunnel w my domain
yes
I will go home and show u guys its sec9asf

did you mean secure asf and if so what are you even using in your stack
Gemini did it for him lol
😭 HELP
LxZY youre getting eaten rn
what db i will use it for
Then what does the Admin portal leads to after login
Hardcoded right into the html
oh god
what the use for backend
im not overkilling
the creds is only a password
Pushing .env to repo as we speak
it update the file
now im just more curious , if he didnt use any DB how its admin login even working with? hard coding or something even more epic
ya lol
its on vercel
uses math.random for password

idc there nothing for me there
a cyber sec based discord is the last place you wanna admit this stuff 😭
youre gonna get absolutely fried for it everytime
i told u its not a company website

its not
it doesnt need to be a company website, my personal homelab is locked behind cloudflare zero trust, aUthelia and proper password portals.
why i have toscroll through the 2k lines to edit stuff when i just fill the form and push
nice
for a portfolio there is nothing else needed at all
Mine i wont say
and most importantly, able to be filtered by ai models 

companies being all lazy and not reading resumes anymore, they just feed them all into an LLM
pmo
yes
like what
Prompt inject the company
wll this help me pass the ai check
Portfolio websites i dont think will fall subject to that like resumes that get uploaded in .doc or md do

could be wrong there tho


I need to speak with 0day or a mod.
Break rules and modes will come to u 🤣 jk..✌🥀
hey
Hi
Hi

Hi
fineee , you?
hyy
hy
hyy
fine what about u ?
Surviving
are u interested in bug bounty?
Na, waste of time
For me
what are u doing then job somethings? or study ?
sorry i didn't understand
same but opposite , gotta finish work , coz thursday-Sunday long weekend again
Hey guys. I'm trying to switch career to Cybersecurity. I'm 30% on the Cybersecurity101 path. Do you recommend just completing the path or jumping in to either modules or walk through?
study + bug bounty
completed and also explore more
can u be helpful a bit or u want to make fun ?
University
ooh okay
I don't have the confidence yet but I'll update my resume ASAP. Thanks!
Gave +1 Rep to @warped blade (current: #374 - 24)
Cool, you made some cheese
he just st how he got job can u explain pls
sorry but no one smart like u
anyway what are u doing ? job or study ?
lol
anyone want to work together in bug bounty ?
yeah i dont know what to ans 😅
Tough crowd, takes a lot of time, earning is tough, people automate a lot of shit, the ones who make bank and get invited to private bbs have been doing it for a long time, so I don't see potential that convinces me enough
-# plus if i found a bug, I'm the person who won't report it
So this is y me no do bb

i accept i am facing it too but i like challenges

yup but i am looking for duo or a team to do it

Oh lol
U there already
that's way i think i learn fast

what u mean ?
ooh i got it now
radhe radhe
Doing work while watching anime lel
Huh
yup see ya later
my way to say bye
Cool
what u watching
Shangri-La Frontier
what's this
hey does someone know what are http header
a piece of extra information send by browser as request header and send back by server to browser as response header
now what is request and response header
a request header like this user-agent, authorization, etc all header have different purpose and response header like content-security-policy,set-cookie, etc u can see and learn fron youtube and try to ask gemini it's explain better then me
A data structure resembling a set of key:value pairs that contains details about the nature of interactions between two devices. Contains information about the identity of the respective device, how it wants to connect, and if it's authenticated to the server it's communicating to via some secure cryptographic secret such as a token/cookie of sorts.
very nice explanation thanks its help me too
Gave +1 Rep to @glacial cove (current: #818 - 9)
what u want to hack ?
All good, you've got a good explanation as well 👍 just a bit on the technical side
hmm
Suspiciously little context

what is that
no
i just saw it now

Npm is the gift of supply chain attacks that keep giving ❤️
well seems like it will just score based on how many rooms you have done or sum shit
I wonder what mine is.
Lol i see
Well let's see mine
65
Interesting
we know ur 10 no need to tell
sounds very inaccurate , since its PROBABLY based on the shit just like leage , the more points u get , the better score , no matter how u do it
10/10 bbg
Oh lol
Then it's useless

PROBABLY
That gives me more questions than it answers.

so basically Donut would be having Senior role score for sure tho he kid
Ya basically
I see
Indeed
Are you insinuating that Donut has a brown nose?
thats what i have personally observed
ya he is covered in chocoloate all the time
Breakfast time, duh.

happy international transgender visibility day
Let's gooooo



Hey! Anyone encountered situations where points from normal rooms are added at an instant but scenarios take a while?
Where do i see this
I'm staring
Omg🥀
a

hey guys
hyy
how long you’re in cybersecurity?
My professor requested 1500 words for our pen test report but I reached 6400, am I cooked
3+ years
omg i just started
words for bruteforcing or what? i don’t get it
What do u mean
sorry my bad, didn’t read your previous message till the ebd
end*
Oh no worries
thx 
no worry if u need nay help feel free to ask i help as much as i can
oh, really? thanks for your help:)
Gave +1 Rep to @muted dagger (current: #3703 - 1)
my pleasure
i don't think so 🙄

Still junior?
What's there 😲
Dm if youre arab
yeah u can tell it because i dont have pc i learn all things in moblie termux? but not juniour i have some exp tho
Its hard tho
I dont want to start till i get a laptop at least
It would be easier with a desk/laptop.
Did you call me just to bother me?😕 @meager pollen
yes but it's my passion and i love to do it i just do it
but u know its help a lot when i got pc i learn 10x faster
get old thinkpad x230i for ~$65
i’ve got mine with cachyos linux installed on it, works MORE THAN SHOULD BE
can i increase both depth and versatility at the same time in the new capability score?
i got mine pc with window i delete it and install kali then after one month i install arch
which makes sense
Which is hilarious, as I'm blue team.
kali is not for normal using, you could just install it on virtualbox and use it only for pentest
how does it compare to the real world?
I don't even know what they base this on. ¯_(ツ)_/¯
The best defence is a good offence, my friend
is there somewhere you can see the different colours and meanings?
The API, I'd imagine.
yeah makes sense
Bro are you arab
Iam too


i use kali net hunter for 2 year in my termux 😅 so i am not normal user
Yes I'm Arabic
how to open it?
termux users are goated
👀
بخير اذا انت بخير
This is an english only server please.
English only please 🙂
K sorry
Yooo how u been
Not too bad I guess? 😅
Damn lol
Why does shadow not get warned then
Nobody was warned.
Well not a warning warning
No mods are scary.
Nah.
I once got banned for saying someone should’ve not been banned
You will be alright
What do I do with these hashes
what is AXIOS
a new malware?
Use them to verify files.
New NPM supply chain attack.
Alright
great
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer malware. axios
it affected almost every npm install use within the time frame
big L

Does that have to do with the IOS thing I heard on TikTok? I’ve been told to update the latest IOS version because opening a website can get my data stolen
nope thats DarkSword
and its a real issue for ios 18 especially but not the same situation
yes it was publicly released on github and made accessible for everyone to use
I used to own an android but switching to IOS is so much better😼
Are you not updating so you're not forced to verify your age?
Ah great
I didnt update till the 2 Major Vaulns happened because ios pushes junk updates
Well I heard I need to do this but idc about that. I don’t have space on my phone, it says I need 18gb
Pegasus and DarkSword are both major threats to older IOS versions along with one other i forgot the name of
Mine is stuck on 18.2.6
Sorry 18.6.2
Pretty sure thats one of the versions thats most vaulnerable lemme check
18.4-18.7 so you would be in the range
Why
you dont have to lol its not my data
they corrected.
Not if ur 6
look at their second msg mate
Than that's on me for not reading 😂
Classic
Its okay 😭 i figured you missed it
Unless you take down an important server with a simple nmap scan.
Then you're fucked.
Hello TryHackMe Support,
I am trying to purchase a subscription, but I am facing issues completing the payment through my bank.
Could you please guide me on alternative payment methods available for users in India?
Thank you.
How would nmap scan take down a server?😅

It depends on the env,
You could be in an ICS where all the equipment etc are legacy because they can't update to newer hardware.
👍
You'll find some airports etc still run Windows XP.
Shouldn’t airports be the most secure
Sometimes their infrastructure can't be updated for reasons such as the software can't run on newer OS.
Technically using -T5 can flood old hardware causing exhausting and using -sV sometimes has things hit bugs due to unexpected bugged payloads triggering a crash i think -O can also send malformed packets
just fragile targets
That doesn’t seem very safe…
Most medical equipment is ran on window 95 - XP
Well if it’s old yeah
It's the same as when you get cyber attacked.
Instead of rebooting etc.
You have to think.
"What are the consequences of rebooting this server"
What are you going to potentially knock offline, is it critical or not.
Is that like very bad? 95?
Well I understand why but im surprised they’re not getting hacked easily
A lot of extremely important stuff was developed during that period and a lot of places go by the philosophy if its not broken do not fix it. aka keep using it
No need to reinvent the wheel hence why things stay on older operating systems. they work
Why wait until it’s broken tho. They should keep updating it so nothing gets broken
Why would i get broken? What variable is changing to destroy a closed loop system? They dont need to continually update industrial software that works
What do you do if a new OS pushes an update out, that no longer supports function X, and function X is crucial for application Y to run.
Like for my work im locked to windows XP
Fair yeah
Find an alternative?
Would it be easier to find an alternative, or harden what you already have?
Would is be cheaper?
Ggs
But like there’s a reason it’s updated and a reason that application is left behind. It just means they aren’t good enough no?
i saw that
Did actually though, or was it @strong scaffold pushing their aegis? lol
Not always.
Is that guy still in the server?
I reported him
Nah.
The US government was 100% behind this LMAOOOO
they were like watch this
He dm’ed me about some very fishy stuff🤐
LOL yikes
Wtf us government have to do with that bro 😭☠️
They refuse to give up their models for Government use

they have refused to work with the US government a lot lately

Something similar happened to VMware on Linux mint😭
VMware? Havent heard that in a while.. try using qemu and virt manager lol
i love qemu
basically feels baremetal w the correct setup
Virtualbox worked fine for me after
But thanks
too many options and customisations lol
I have to look into this now lol
i thought it was slow lol,isnt it?
might as well give it a shot
I mean not really tbh
I just disable 3d acceleration
i dont feel that w qemu at all
Yes yes, peak combo
thats enough to make a grown man cry
Hello Ladies and Gents
Im kinda embarrassed for anthropic
how do you accidentally ship source maps in an npm package.
Hello
Buy the cert.
its free?
Top 10 ways to shit your money down the drain.
i literally just downloaded it
No?
lol
Certificate is free.
Certification isn't.
@bold rover Thoughts on recent axios compromise? 😄
It wasn't me lol

or you meant certification exam thingy
Yes.
Exam
Lol.
nah
Btw, how's my score
id rather go big name ISC2 CC or Comptia
Who the fuck put YOU in that range LOL.

lol scrubs shilling the THM papers
What even is this?
Link?
Near streak
Dashboard
Looks cringe..
Your atleast a 90
Clearly...
Blue teamer.
Si.
I'll allow it.
Id just like to say, Maltego is expensive asf.
That moment when you wait a few months before you do a red team and one of the CVE's you found that company was vulnerable to changed from a DOS to an unauth RCE
Or keep booking a demo as a new guy

Peak
Maltego is crazy powerful but damn does it cost a lot
Why do the Easter Sale for Certificates feels a little scammy? The price for Sec0 was literally the same for me - 58$ before and during the sale? So no price movement here. Now, when the cert launched or some time after, I remember I saw it was 33 Euros. So considering that, still paying 17 euros above, and especially, during a sale, just not worth it. Again the same issue is with Sec1. It costs the same 15% less for premium subscribers like it was prior to the Easter Sale. So once again, there is absolutelly no sale for these two certificates! How come you woun't do a sale for them?
Absolutelly, the price is fucking the same for these two certs! Why do you advertice them as part of Easter Sale?
Stupidity...
Yeah, if you go on the main page, there is "supposedly" an Easter sale for the certs
Do yourself a favor and don't buy any of those certs.
😄
Treat yourself to a nice dinner instead.
Yeah right, I would previously buy them but at a bigger and REAL discount
Hmm, let's see
I have the voucher till December, so I have to take PT1 by then
Oh lol
U already bought it
Ouch..
haha, I know it can't be compared to CPTS but still, I got it at a good price back in December
I got PT1 for free.
You passed it?
I'm going to stop yapping so much and get hacker so I can spam my top tier gif memes in here
Haha, same with my CWES and CJCA from HTB which I have till August to take, and I am still on the CJCA path
Should not have bought PT1..
I sat it and failed because I forgot to submit a flag to the web pen.
I will take PT1 after them
Yeah, that's the plan

Damn
Nice nickname
Bleu the glue sniffer
Was my favourite
Man genuinely hates my team. </3

what to get for dinner, what to get for dinner 
i dont hate , i dont even know about the team why would i care about that, name is funny
SAME FUCKIN QUESTION I HAVE NOT BEEN ABLE TO DECIDE.
OH MY GOD.
IT'S BEEN AN HOUR AND I STILL DO NOT KNOW.
WHAT I WANT.
there is a steak house close by
IT'S PISSING ME OFF.
so might go try it out
well hopefully my steak is too juicy and my lobster too buttery
Make sure you ask for extra butter
gojo cat

you should see the dinner I had in italy
Was it too juicy and buttery? 😄
yes, 7 course tasting dinner, with 5 different wines to taste
Last Friday's dinner wasn't bad for me either.
Genuinely don't understand how people pay hundreds of $ for it...but hey at least it looks nice. 😄
How's any of it supposed to fill you up!
Food is meant to be yummy and there's supposed to be a lot of it!
is that meant to be a beach
cause it was really tasty, it did fill me up, and the way they made each thing on the dish compliment another was sooo good
@fervent delta Please slow down. Further spam will result in a short timeout.
Interesting...
There's only meant to be one half it looks like...
is this possible
Vision
Phone that doesn’t need charging
Related Ideas
Self-charging chip
Free internet via device
I was being sarcastic
No.

why no
yes, coconut and mango ice cream, with pistachio bushes, apple crumble and I can't remember the blue thing
IT WAS DESSERT?
yeah
Man I cannot tell when/if these things are sweet or spicy.
Do yall listen to music while doing pen testing or stuff?
Vision - Your eyes
Phone that doesn't need charging - yes, powerbank with solar power
related ideas - you're not getting mine.
self-sharking chip - no, chips are for eating.
free internet via device - Starbucks coffee.
how would that look spicy
I don't know chefs come up with the weirdest things.
I wanna go eat an apple tart now...
None of us. We're all idiots.
Meeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
eeeeeeeeeeeeeeee
eeeeeeeeeee
eee
e
not me
I thought you were bleu.
Bleu
HEY...
Nah we are not hackers
Well it depends.
We are just normal people role playing as hackers
only thing I can do is make systems go down
Larping
Yes yes
I'm an employed blue teamer.
no, only databases
𓂋𓅂𓄿𓂧 𓏏𓉔𓇋𓋴
I can do anything.
Read this

Can u give me a 16gb ram stick?

yo hello
Me too, i am an expert, i am an expert
hmmmm
No. Fuck you. I need one too. Desperately. Now I'm angry again. I run 2 VMs and computationally intensive scripts at the same time and my 16 GB DDR5 is SCREAMING.
I think the 2nd one seems nice.
Oh, i have 24gb of ram😈
I will find you.
yeah, possibly
I can run 2 vms and still can open 3 firefox tabs😈
might maybe go with a tenderloin instead
I can do that too...
Dude what do you want.
hello!
Awww, I get access to servers, one of many perks

You can go to tiktok.com/register and make one for yourself.
Please.
Stop.
Flexing.

uhm, are u using a iphone and didnt update in a long time?
you need us to take down a tiktok acc?
I also have access to a server. @elder marsh is nice enough to let me use it. 😄
Who is "us"?
Oh lol that clanker

He's no clanker...
excuse you, clanker user
Yes Bleu da Leakage da best hekar
are you using an iphone and didnt update by any chance?
Looks like one
here

This is coming from a RTO btw.........??
I told him
😭
RTO? ...am an engineer
Sign up for an account or log back into TikTok. Create an account to discover real people and real videos that will make your day.
just answer
You can sign up there.
yea bruh
Bro busy with minecraft
did he got ban?
Let him chill

this the place wherer i can meet real cyber security experts
Well, define experts...


welp maybe, btw, what is a router
Are you asking because you don't know?
😄
And looking for help on your homework?
Hey, anyone who has been part of any security or infosec compliance programs? Implemented/Audited for any organization?
Yes why
wait, wdym😭
Cyber Security expert with a little bit shitpost
Which security compliance have you worked on? or have experience with?
yes yes
i gonna make a window vm to try out damon's tools
DEFCON
Can't be,
Matt attends.
indeed
@tranquil swan i don't accept friend requests with people i don't interact with, if you wanna get added, meet me

It's not for ordinary hackers.
is for all
personally I'll never go to defcon
Same
well... not every person here is doing CTF/hack for military/army 🙂
not rich, just comfortable
Meeting some people would be pretty cool, but $2k is seriously a lot
What is rich?
tbh, you can meet better people anywhere else
Ya lol, get few rams, that's better
well, defcon is still boring in the sense of it being a convention
Like online or on other conferences?
both
I think very few people have what you are describing.
Lol did someone get automodded?
Any conventions/conferences you recommend?
personally, I have expenses that are 40% of my income
True
CCC
Depends on before or after taxes
yes, I am 22, have my own apartment
after taxes
Chaos ?
yup
I don’t think 22 qualifies as adult but yes, it is good
been living on my own for the last 4 years?
been paying taxes for the last 4 years
having a stable job for the last 6
Frontal cortex doesn’t stop developing until 25+
According to me, almost everyone here is smart.
and I am still the youngest person in a room of investors everywhere I go? so what's the issue with that?
Ahhhehhahehheahheaheha
1 + 1 =
3
There’s no issue, you’re doing great
AHEHEHHAHEHAHHEHAE
Do you live in a different country than your parents' home country?
no, I live 65km away from my parents

i live 170 km away from my parents.
For me it's 985
for me its 2K KM
maybe me too.
I think some stats say approx 50% paycheck to paycheck
claude code just got leaked and someone made a copy on github https://github.com/instructkr/claude-code
So next conference you go to, every other person you see teetering on the edge of disaster
Yeah, we are saying the same thing
I get 4000 Euro after tax, and have an expense amount of 1800-2200 a month
I have been living away from my family since class 6th.
I'll be getting around $1000-1200 per month
whole month's RENT+FOOD = $120-160 at max for me
imagine
Lives on Neptune
uranus is pretty nice
Very hard to get expenses below 50% of post tax income … I think I’m at like 60%
Add up over 2 years and then divide by 24 easy
Averages rule.
(On average) (mostly)
Is that a meme coin?
nah i bought sum bread with that moni
How does that collorate
Going to guess $50 000
me: "help im stuck: From which Windows DLL is the API SuspendThread being called?"
Echo: "The API SuspendThread is being called from 'Kernel32.dll'."
me: "can u give me the answer for that question?"
Echo: "I'm here to help you with learning, but I can't provide direct answers to questions. However, I can assist you in understanding the concepts or guide you through the task. How would you like to proceed?"
yes, echo is following his guardrails
in my country that can make you under Top 1%
its a chatbot.. what did u expect
??
why did he just give me the answer and when i ask for the asnwer again he denied to give it?
what does that mean cuh
nvm
i still can abuse this to get answer
clanka
I’m just doing binary search, starting with the 1st world average income
hello hackers over the world 😉
kuberneeeeeeeeeetes are the solution
Hi mr bebot
Thanks Mr Wang Kung Fu 😀
Gave +1 Rep to @signal ingot (current: #245 - 45)
I like this trend, I’m in
are u in usa
Step one to riches, do not have car, have bike
australia
how do u get around
You copied my naaaame
ehh got no word i just hate usa
Use public transport
Expensive hobby
didn expect that
what type of car u got
Capital intensive investment strategy
honda civic with laptop
hi guys
Damon only Lambo owner here, praise be
Nissan GTR
Exhaust mods are illegal in lots of places
Need to meet noise and emissions requirements
shrug
I don’t make the rules and government rules are many times, not smart
FAKE MALWARE
Better.
Don't click on the video 😄
It's fake.
You have to guess xD
It's not real ransomware.
Good news haha
No problem, anything I know I can share 😄
Tell me about C2 beacons

-# jk, mods don't ban me


Here is it , he told you
You're 0XB you must be pro
We still learning
Nah i quit cyber security i'm working as food delivery now.
I practice cyber security while delivering food, sometimes I do a man in the middle when I eat peoples food
Can you delivery for me 100 pizzas for free? It is for the homeless 🤓🎥
but just for practice not stealing ofc
Don't expose me
🤯
Man in the middle attack
Collecting customer location and phone number is illegal
hey bro ,im currently stay at China, and i use two vpn,one to acess try hack me website ,and one to acess target room, but in the most of time ,they got conflict ,only one of them work normally,i only able to access one of them,anyone got perfect way to solve this,gratefully appreciate ur help
Use the attackbox.
it is quite slow to deploy
Use the patience
Doubling up on VPN's is a bad idea, as you're finding out.
that why i prefer vpn,my computer performance was really bad

i saw person called wanglin ,are u also a chinese ,may i ask for ur contact as well
No
alright ....
💀💀
Oh, hangman, I love this game.
it is quite tough to access both website and target room
You can do anything @dense mantle
Give me your contact info , phone, adress
....
how about my bank info also
No
Your qq app or wexie
i gonna get mad of this , i really need some solution🥹
Do you know why it won't work?
i knew ,china goverment did a great firewall.....
Aura farm?
is there any available way to solve this
Yes, do you see the issue with sending encypted traffic to something that doesn't need to be encrypted?
Don’t encrypt it then

....
...Duh?
Yeah so what’s the issue
VPN in china is illegal
Man, read the conversation.
I thought this stuff was propaganda set by USA

Why
How are they even gona stop you from downloading a VPN









