#quiet-conversation

1 messages · Page 52 of 1

vocal ridge
#

ah. nice.

rose axle
#

I wanna be 0x1

mossy island
#

Why isn't it icalcs instead of icacls

ripe haven
#

This is really random, but I found a bug and don’t know what it is, I’m way too invested now, any recognition will be helpful.

full tapir
#

Also if you have a dog keep it away from them as if they sniff them the dog could have some serious problems.

ripe haven
full tapir
# ripe haven I don’t think it is, it’s entirely grey and it’s alone, no other moths around.

The oak processionary (Thaumetopoea processionea) is a moth whose caterpillars can be found in oak forests, where they feed on oak leaves, causing significant damage. They travel in nose-to-tail processions (hence their name), often arrow-headed, with a leader followed by rows of several caterpillars abreast. They are a human irritant because of...

#

They are not always in group

#

Might still be wrong tho

ripe haven
full tapir
#

My bug knowledge stops here, I tried 🙂

ripe haven
#

Haha

#

+rep @full tapir

hoary nymphBOT
#

Gave +1 Rep to @full tapir

full tapir
#

I guess you should start a bug bounty program 😆

ripe haven
#

Asked a zoologist friend, identified!

full tapir
#

May I ask what country you found the bug? @ripe haven

full tapir
#

I wonder what is the zoologist approach to identify this things. So many looks so similar

serene trench
#

Heck yeaaaa

ripe haven
serene trench
#

🥺

calm hedge
serene trench
#

Also lots of pretty pretty flower displays

mossy island
south inlet
# ripe haven

It's a hairy caterpillar, I can't tell you which species it is as the picture is too blurry.

ripe haven
#

And no, it’s a moth larva

south inlet
#

Moth Larae are the young stage?

#

Before a caterpillar... ?

ripe haven
half shadow
winged rain
# ripe haven

That's a caterpillar, rule of thumb is the shinier and more colourful they are the more dangerous

twin ridge
#

the hairy bois aren't very pleasant either

rotund moss
twin ridge
#

caterpillars

rotund moss
#

Ohh my bad

timid umbra
#

is anyone familiar with proxys that can help me out?

#

what are sock5 proxys?

#

ok thanks

hoary nymphBOT
#

Gave +1 Rep to @twilit nacelle

calm hedge
maiden pulsar
astral valley
honest elm
#

Hello there, can someone try to help me track a scammer, a friend of mine lost a lot of money because of him and i have not much of info on the person

serene trench
honest elm
#

ok thanks, he has but doesn't think it will do much. Maybe they catch him in a few years.

serene trench
#

Hopefully sooner

calm hedge
pine iron
#

kinda like how we identify different breeds of dog, just a more careful eye about it

honest elm
calm hedge
ripe haven
#

@primal steppe they are following me…

ripe haven
unique bolt
#

Please make it stop

radiant jacinth
frail beacon
#

Armageddon lol

magic niche
#

Hey, I've got no clue where to ask this.. but is it possible for a router's firewall to not store logs anywhere? I'm looking at my config and I see no options to view logs.

For some reason I have "Port Scan Detection", but no way to see it in the logs?

frail beacon
#

@magic niche Have you scanned all the ports?

vocal ridge
magic niche
#

Oh, I'm scanning them currently, it's just that there's no "button" in localhost to actually see any logs...

#

@frail beacon Like, visiting 192.168.0.1 and logging in, looking through all the options, there's just no button that leads to logs

frail beacon
#

@vocal ridge I hope not

vocal ridge
frail beacon
#

@vocal ridge I feel the exact same way. We will be okay 👍

vocal ridge
#

imagine, a worldwide 0day

#

quite literally

midnight minnow
silent tapir
#

hey community

magic niche
#

Hey everyone animewave
I've been doing an nmap scan on my other machine, just to see if I'd be able to attack it with my current, very limited knowledge, and I found I have a non-standard port open (near port 50000). It's supper weird lol, since I've only seen similar used as "SKIDY'S BACKDOOR" in one of the lessons.

I'll continue investigating this, but is this any reason for concern?

#

Yes

#

So, it's a "Randomly allocated high TCP port"... I don't see why it would be open on my personal PC though?

#

Is there any way for me to find out what this port is being used for?

magic niche
#

I started the nmap with -A. It's still working, but it displayed that port as open before it finished

rancid apex
#

Is the ESP8266 V3 WiFi Deauther worth it?

odd acorn
rancid apex
odd acorn
#

I'm sorry but I don't believe that

rancid apex
magic niche
odd acorn
magic niche
odd acorn
#

Something that isn't ethical is something that isn't morally correct.
Some places, deauthing might be legal, but it doesn't mean that it is morally correct; meaning just because you can, doesn't mean you should.

#

Especially as deauthing can be used to get WAP keys or to kick people off WiFi, it's not really the most ethical practice.

#

Mhm, it can be, but you can show that with a cheap wireless adapter, don't need to purchase a specific tool to do that.

spark sun
odd acorn
#

It's just strange buying something that's branded to be unethical.

spark sun
#

You can do that demo without deauthing the cameras.

#

Simulation would be just as effective a demo with 0% risk

#

Not for this. It's the equivalent of saying 'we want to revoke everyone's access cards to the building'. It doesn't serve any constructive purpose, it just prevents actual work from being done in the best case

#

And, there isnt' a defense that works against deauth.

#

It's inherent in how wifi works, period

magic niche
spark sun
#

That would definitely be a finding, but deauth itself would have to have extra permissions to do as it does disrupt a production system. A client may give a go ahead, but extra care would be needed for the SoW and contract to ensure that it is a permitted action and in scope.

vocal ridge
#

talk about a power move

#

"gtf off my wifi"

odd acorn
#

¯_(ツ)_/¯

spark sun
#

But even with client permission, it is still breaking US law. A pentester utilizing that technique is more likely than not to be liable for breaking the cybersecurity act that covers it. I don't remember the specific Act offhand, but it was relatively early in cybersecurity as a governance thing.

odd acorn
#

Also become a problem if you deauth the wrong device or unintentionally hit a wider scope

burnt night
#

Like $1

spark sun
#

I don't think you can target a specific device to deauth; IIRC it affects everything connected to that WAP

burnt night
#

ESP super cheap

vocal ridge
#

ahh, that's interesting

odd acorn
#

Just listen on your interface, grab the Mac address and deauth

odd acorn
#

Mhm, juun didn't say "the law", they said "US law"

spark sun
#

IIRC it's also applicable to the UK, and I think the EU as a whole? It's not just the US.
When people think deauthing attacks, I'm thinking things like unethical use of pwnagotchi and flipper

spark sun
# burnt night Huh?

Network stack typically requires admin privs to mess with packet crafting? Or have I misunderstood what this tool does?

burnt night
#

It's an ESP, it doesn't have the concept of privileges

#

Microcontroller

spark sun
#

Ok, crossed wires. I thought the context of the ESP chip was that it was a specific adapter that takes instructions from a management app

vocal ridge
#

pretty sure any over the air signal is within radio range. don't quote me.

#

oh no, wifi's within microwave...

radiant jacinth
#

Shhh

ripe haven
#

@vestal swan may I DM?

vestal swan
frail rapids
#

Is there a reason why SQLMAP doesn't have an option to bruteforce words in table names?

#

I'm currently trying to extract table names but its timebased and likebased so it's 1 char / s

frail rapids
#

personally I feel like there's a lot of optimization to be done like repeating characters and going to hexonly when a hash is detected

mighty echo
#

@odd acorn hey may I DM?

normal lynx
#

I got my first interview! happyCat

rapid barn
#

For what position/job

odd acorn
plain moth
normal lynx
hoary nymphBOT
#

Gave +1 Rep to @plain moth

rapid barn
#

Haha good luck!

mighty echo
hoary nymphBOT
#

Gave +1 Rep to @odd acorn

median moth
#

!docs verify

deft fossilBOT
idle venture
#

hey @serene trench can i suggest a song for you'r playlist Portugal. The Man - Evil Friends (Jake One Remix Ft. Danny Brown)

serene trench
#

I'll have a listen(:

idle venture
#

and? is it ok?

serene trench
#

I'll need to look at the BPM, but I'm sure I can fit that in a playlist somewhere

#

140 mhm sure if I can get it on beatport

#

I say that I've been mixing 170-180 for most of the day KEKW

idle venture
#

yep, maybe it's good for endings

ashen cradle
#

22

next junco
#

a

maiden steeple
#

Okay

frail rapids
#

How can I crack the pepper of an MD5 hash?

#

I know the unhashed value(s) and the hashed value(s)

#

I'm doing bug testing for a comp and want to check if their pepper is secure by bruteforcing it

serene harness
#

blobknife quiet

frail beacon
#

@serene harness Hey Acid Burn 😀

serene harness
#

Hi crash👋

frail beacon
#

lol

#

Only 4 people in here tonight oh well

serene harness
#

skidy where are u guys from?

soft pier
#

sweden the majestic north

frail beacon
#

UK

serene harness
frail beacon
#

@serene harness Where are you.

serene harness
#

India

soft pier
#

when does night start??

#

when it end???

frail beacon
#

@serene harness So far away how come you are still up

serene harness
#

I’m currently on vacations, Just onto late sleep routine.

frail beacon
#

I know that routine very well 😀

#

@soft pier Yeah true i am a bit of a night owl

#

@serene harness where are you from

serene harness
serene harness
# frail beacon I know that routine very well 😀

You kinda get into that habit once you enroll into engineering here. Complete assignments or study for exams the whole night and then later sleep through all the classes(huh I can't pay attention anyways). The real day starts after the classes.
Its kinda fun though

frail beacon
#

That’s cool how long you been studying engineering for

serene harness
normal lynx
serene harness
frail beacon
#

😂😂

soft pier
#

obviously the have only studied for 2 ms

twin ridge
serene harness
twin ridge
#

cool, not quite the same ECE I did 😛

forest cypress
#

Hey, I know there are a lot of videos of THM room walkthroughs on youtube and other social networks but is it actually allowed by your terms and conditions? I'm thinking about doing some videos in my native language for LinkedIn but don't want to get into trouble.

burnt night
#

Preferably link to the room in your post

gilded pasture
#

Are there any good places to learn? I'm quite new and would like to.

spare cave
#

Which modules in Metasploit tool help us in identifying version of some
services which we couldn’t identify using Nmap? does anyone knows answer to this

spare cave
#

its from the assignment i am solving

#

bit confusing for me actually so thought of asking advice

#

dont want to ask

#

or the answer is search module ?

warm peak
#

Plus he knows your syllabus, we don't

spare cave
#

its out of box question btw

tawdry dove
spare cave
#

are i already got the ansswer

frail rapids
#

What's the point of that?

radiant jacinth
#

lmao I'm like wait really that's a thing

frail rapids
#

ohhh lmao

#

yeahh

burnt night
#

-ban @radiant jacinth -ddays 1 spam

hoary nymphBOT
#

🔨 Banned greenlandbase#4368 indefinitely

radiant jacinth
#

AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA

mighty echo
#

@burnt night Trolling ^

twin ridge
#

¯_(ツ)_/¯

mighty echo
twin ridge
#

I mean they're trying to speedrun a ban...

#

-mute 661865932863569940 1d Lay off the low effort trolling and come back when you want to be mature

hoary nymphBOT
#

🔇 Muted Literally An Axolotl#0001 for 1 day

white cloak
#

I probably would have practiced analysis using whatever malware they could come up with

frail rapids
#

life pro tip: apparently it's possible to attach GDB in pwntools

#

litterally just inserting gdb.attach(proc) into the exploit

#

this saved me so much time today (still took me 3 hrs but hey)

mystic cliff
#

I was just wondering what is the hardest room on THM?

normal lynx
#

Could I please get the CySA+ role when a mod has a moment?

olive frost
wintry birch
#
  1. what is better to take first, cyber-defense or jr penetration/offensive security
  2. what is better to take first, jr penetration or offensive security
radiant jacinth
#

if theres someone good in python and some other stuff and know a lot about ethical hacking can message me only if he wants ofc

radiant jacinth
#

so i can learn myself some stuff i dont understand

burnt night
#

Why can't you ask it here?

radiant jacinth
#

i dont really learn that good from youtube and github

serene harness
cloud jacinth
#

why do u need someone to DM u?

still maple
torn fog
marsh surge
#

The actor's name is "Benedict Cumberbatch", it's a jab at weird names

normal lynx
cosmic cobalt
#

Benerdict Cumber Lad

south inlet
#

Benjamin Crumpystitch

normal lynx
#

Bolognese cannelloni

south inlet
#

Bridgerton Cabbagepatch.

normal lynx
cosmic cobalt
#

Butterict Cabbagefires

burnt night
#

Brisket Caramelfat

ripe haven
#

+rep @steel tulip

hoary nymphBOT
#

Gave +1 Rep to @steel tulip

magic niche
#

Does anyone here use any of those commercial VPNs? I'll be traveling this summer and I'm thinking of picking up Surfshark. Now, I don't know much about VPNs. I know the basics of how they work, but that's pretty much it. I'd like to avoid any complex VPN setups at this time so I'm going with a easy-to-use solution that can be shared between family members with low tech experience.

What kind of privacy/security can I expect from such a commercial solution? I usually go completely offline in foreign country (as I'm very skeptical when connecting to hotel WiFi or similar). Does VPN provide any security when using public VPNs?

burnt night
ripe haven
#

@wary cradle || CONGRATS YOURE ON WORDLE||

still maple
#

What do they mean by if the certificate is "present". The wording is throwing me off

#

I'm reading up on S/MIME.......and the sender sends their digital certificate and signs the message using their private key...... so does "present" mean a certificate thats clearly not signed?

tawdry dove
hoary nymphBOT
#

Gave +1 Rep to @tawdry dove

ripe haven
#

Hey! Did anyone manage to download glibc 2.34 on kali?

#

I'm completely stumped tbh

narrow field
vocal ridge
#

Mr. Robot SE 2 EP 6 😂 😂

tired anchor
vocal ridge
#

you'd have to see it

vocal ridge
#

words don't describe it

hot hamlet
#

can anyone help me with windows privelige escalation section of Jr.pentester pathway? For challenge - abusing vulnerable software?

olive frost
mighty echo
#

Why?

burnt night
#

There's about 2 machines where you need to care.

stable iris
#

can someone help me with this problem am facing on terminal while running byob "unable to locate directory containing user-installed packages"

tawdry dove
next nest
#

where can i report a user who just sent me a scam?

vocal ridge
#

that's a good question...

definitely report it to discord, but not sure on THM.

tawdry dove
odd acorn
jade jungle
#

I got same message

shrewd garden
#

Hello, oh, I m new and I wanted to have some experience in the field of hacking, is there anyone to help me?

steel tulip
frail rapids
#

I work as a security engineer for a business which uses Google cloud. If I would scan/attack a machine (e.g. port scanning) would that be attacking property of the business or attacking property of Google?

#

Or should I ask my supervisor

radiant jacinth
#

that sounds like a shower thought for some reason
just ask your supervisor and make sure the legal team has ur back

twin ridge
#

And legal

stray pilot
steel tulip
# frail rapids I work as a security engineer for a business which uses Google cloud. If I would...

Most Acceptable Usage Policy (AUPs) of most organisations and universities prohibit this type of behaviour and would be considered a fireable/dismissable offense. It would be something along this line:

Network Activities

The following activities are strictly prohibited, with no exceptions:
* Port scanning or security scanning is expressly prohibited unless it is an approved activity to detect weaknesses in the organisations’s environment, and after prior notification to the CISO office.
* Effecting security breaches or disruptions of network communication.
* Executing any form of network monitoring which will intercept data not intended for the employee’s host, unless this activity is a part of the employee’s normal job/duty.
* Circumventing user authentication or security of any host, network or account.
* Introducing honeypots, honeynets, or similar technology on the network.
* Interfering with, or denying service to any organisational information or technology asset.

So yeah, don't do this even if you have supervisor approval. For any security testing you need approval from the Security Team, which is mandated usually by the CISO.

twin ridge
steel tulip
twin ridge
#

Fair

frail rapids
#

It's an online business with over 800000 registered users but 30 employees

steel tulip
# frail rapids I **am** the security team <:kekwsanta:783452266379476993>

Then get approval from your manager or exco and you should be good to go.

In terms of testing the Google product, usually, this is acceptable as long as your approach is to test your configuration of the product, and not the product itself. Like AD from Microsoft. If you are looking for vulnerabilities in the product itself, you should adhere to their bug bounty and responsible disclosure policies.

twin ridge
#

Aye

frail rapids
#

Alrightt

simple pumice
#

I have two laptops, I need a higher processing power to do some task.

#

Can I combine both laptops?

#

I mean combine the CPU of both.

burnt night
#

You can spread the load over two

#

By distributing different tasks

simple pumice
burnt night
simple pumice
#

What is botnet btw?

burnt night
frail rapids
#

Am I the only one who truly hates enumeration focused boxes

#

I love web exploitation but the enumeration is just a c- funblock

#

like it's literally just hoping you have a good scanner

burnt night
#

Happy Path Enum > scanner

gray jetty
#

yep, can confirm, never used a vuln scanner other than the ocassional nikto

frail rapids
#

meh it's HTB I'm so pissed about

#

I literally cannot get a shell on most boxes

#

and then I do retired machines and look at a little bit of the writeup and I'm like

#

"oh wow, how didn't I think about that"

candid tartan
#

There is more than just 1 type of enumeration. nmap for ports/services and so. gobuste, dirb, FFUF, for folders/files enumeration...

#

if you don't have bwapp and/or owasp juice shop in VMs try it. 🙂

burnt night
#

That's... that's not the issue here

candid tartan
#

oh =/

frail rapids
#

everything besides port scanning

supple mauve
mellow silo
#

hello peeps!

flat yarrow
#

Hey Good Evening

frail rapids
#

I'm doing a challenge with LFI where /proc/self/stat returns properly, but /proc/PID/stat doesn't, does anyone know what's up?

#

I'm using the pid from /proc/self/stat

#

I've been playing with it for a couple of hours now, but I can't figure it out

frail rapids
south inlet
#

Is it an active challenge?

frail rapids
#

oh shoot it might be, mb

#

okay I found the issue!

frail rapids
#

@olive frost ^

#

I can't ping the mod role directly for some reason

gray jetty
#

@mods

#

hmm, that worked some time ago iirc

olive frost
#

Guess it's solved ?

twin ridge
#

They're not generally pingable after some abuse a while ago

south inlet
#

Can CM's still do it?

radiant jacinth
#

Hi, I have problem!

#

I don't have Internet connections on StartBox.

cloud cloud
#

AttackBox? I don't think anyone does

radiant jacinth
#

Jest AttackBox

#

In the content, he writes to use it to perform tasks!

cloud cloud
#

well, you should be able to access the machines that are in the same network with the Attackbox at least

radiant jacinth
#

I had an IP assigned - it said at the top, so I think I was on the same subnet after all....

cloud cloud
#

try terminating and launching the machine again. Maybe it didn't start up after all

radiant jacinth
#

I did so, when I turned it off I lost the access I had left i.e. 20 minutes and I can run it tomorrow...!! :((

cloud cloud
#

Welp. If you want to continue the room, you can connect via vpn and then perform the tasks on the machine

radiant jacinth
#

All I have is the Start AttackBox window!

cloud cloud
#

What OS do you use?

radiant jacinth
#

Arch!

cloud cloud
#

Oh. Idk how to connect to VPN in an Arch environment

radiant jacinth
#

ok :((

cloud cloud
#

just do this I guess

radiant jacinth
#

I just do it

#

Using a VPN will I be doing this on my Desktop?

#

I've never used it!

cloud cloud
#

yeah

cloud cloud
radiant jacinth
#

ohh OK!

frail rapids
#

I learned a really neat trick today with regards to binexp

#

if you leak a library's address you can use it for ropgadgets

#

I hadn't really thought about library's like that

gray jetty
#

if you're leaking it's base address then you can rebase your libc with

libc.address = leak - libc.symbols.<leaked_func_name>
frail rapids
#

yeah

#

and then you can just do libc.symbols.<func> for actual addresses

#

it made my pwntools "exploits" a lot cleaner

shadow acorn
#

Hey, it would be great if someone could help me with this problem: So i am trying to host a simple htp server. I have a raspberry pi and a PC, both on the same LAN. On the raaspberry pi 4 (debian) (in terminal) I type "python3 -m http.server 8000 --bind 0.0.0.0"
and on the PC (ubuntu)(which I want to download a file from the pi onto) I type "wget http://(raspbery pi's ip:8000/file being downloaded)". I get the output Connecting to (the IP):8000. It is stuck in this connecting state untill i get the timeout error. I can connect to teh server on raspberry pi using 0.0.0.0:8000. Has anyone else ever encountered this problem? What do you think I could be doing wrong?

#

I am not sure, not that I have deliberately installed. How would i check? I can ping the pi's ip from the computer.

#

@twilit nacelle shall I send you a dm of the result?

spark sun
deft fossilBOT
shadow acorn
#

! docs verify

#

Yes it is active, shall I disable it?

shadow acorn
#

OK great thanks for the help. I'll tell you if it works.

shadow acorn
#

Hey, it worked thanks you are so helpful. And you saved me another hour browsing tack overflow and getting nowhere. 😂

hoary nymphBOT
#

Gave +1 Rep to @twilit nacelle

verbal yoke
#

i need video steganography tool

#

can you suggest a tool

astral flicker
#

anyone tried running samsung dex and attack box together? does it work?

topaz oasis
#

hi?

warm peak
verbal yoke
verbal yoke
#

not on tryhackme

warm peak
#

what ctf then?

verbal yoke
#

a normal stegonography question

warm peak
#

from where?

verbal yoke
#

will you know?

warm peak
#

yes, I want to know from where

verbal yoke
#

hackkaradeniz

warm peak
#

is this a ctf that is going on right now?

verbal yoke
#

yes

warm peak
#

we will not help you then

#

cause that's cheating

verbal yoke
#

no problem

#

thanks anyway bro

radiant jacinth
#

algien habla español y es haker

tawdry dove
spark sun
tawdry dove
#

Nvm lol

still maple
#

Anyone know of any resources that I can skim through regarding vulnerability assessment report writing? Or maybe some good case examples I can skim through?

frail rapids
#

I know people are going to hate me for this, but what arguments are there against using passwords like ppppppppppppppppppppppppppppppppppppppppppppppppppppppppppp

#

because if attackers assume that you're using [a-Z0-9_-+,] etc in their cracking app its as secure as a complicated password of the same length with capitals, weird symbols, digits, etc

ripe haven
#

Also, do you know how Enigma was initially cracked? A German commander accidently sent a bunch of As (I'm pretty sure it was As) and they managed to learn a lot about it by that, so it could probably be a problem if you're attacked by MiTM.

candid tartan
warm peak
ripe haven
vocal ridge
#

№1234567890

short elk
#

password = service_name[0].lower() * 30 😎

plush hamlet
# vocal ridge `№1234567890`

I realized that our password manager let me paste in emojis for the password field. I then copied/pasted into the password prompt. It worked.
It was fun on a conference call with a vendor and I said “the service password is <stuff> airplane emoji. No, I’m not kidding. Just copy it from the field”

candid tartan
frail rapids
#

Yeah but the only way you could find out is if a plaintext password is leaked

autumn trout
#

lil bit of social engineering

#

oh my god im immune to the slowmode here, this is great. when i left modship i wasnt immune and now i am

#

i love this

remote echo
soft pier
#

if someone does not break it with simple rules and wordlists it would work as a decent password when brute force is the only option left

frail rapids
#

Which is a powerful condition because if they know chars in your password, they might aswell just know the entire pass

remote echo
#

Probably is. I didn’t think about it much

serene trench
#

squirtleVibe no think only vibe

quasi vessel
#

good like

topaz oasis
#

hi?

mighty echo
warm peak
warm peak
#

or getting PoC scripts for different CVE's (saw you had something with payload generation and using Ryans payload generator)

mighty echo
warm peak
#

why use crackstation when there's ciphey

mighty echo
mighty echo
warm peak
#

oh yeah

fathom panther
mighty echo
#

Ciphey doesn't support hashes but that why we got STH

fathom panther
#

Whats STH

warm peak
#

then make ciphey support hashes 😄 😛

warm peak
mighty echo
warm peak
fathom panther
#

Base64 encode decode

mighty echo
#

Encoding sounds neat

#

Oo wait exif data!

fathom panther
#

Yess

mighty echo
#

Or image reverse lookup

#

Or steno (messages in images)

fathom panther
#

OSINT

mighty echo
#

Running pywhat on differnt files

warm peak
#

@mighty echo good luck with exif data over discord 😄

#

discord strips all exif data

mighty echo
#

iirc it dosen't actually strip videos but yeah for images ill find a workaround

dawn dove
#

i am able to access a website with this site map _next/static/css/b929835218decd64.css does it mean anything?

frail rapids
#

What's the best way to store secrets?

#

.env seems okay until you realise that LFI kan leak /proc/self/environ

fathom panther
topaz oasis
#

hey?

short elk
weak dove
#

I am having issues using openvpn because of the UDP block in my country.
Is there any method to bypass this block? Its really annoying I can't use the platform because of it..

gray jetty
#

use the attackbox?

weak dove
#

Its too slow

#

I prefer using my machine

gray jetty
#

that's still the best option as bypassing country blocks is going to be a no no, anyway

weak dove
#

sad.. Alright then thanks

smoky mortar
weak dove
weak dove
#

I will check it out then inform you, thanks.

smoky mortar
weak dove
#

Didn't work either TLS Error: TLS handshake failed

#

HTB tcp .ovpn works for me tho..

#

Thanks for your help anyway

vocal ridge
#

that's terribly sad and wrong. censorship is unethical

#

blocking an entire protocol is absurd

#

it really upsets me hearing that.

smoky mortar
vocal ridge
#

ik, it disgusts me

#

that's only my opinion

woeful pecan
#

Hej staff (Ben) pls add closing bracket to the Task 13 xd Its killing me and I cant ignore it :DD

woeful pecan
#

Well I dodnt post it there cuz its really not "bug" yk

#

but sure, why not

twin ridge
#

more likely to get seen there though

late timber
#

Might come in the rework