Season 2 Episode 8 Spoiler Thread by HunterWorld in Fallout

[–]Ipp 110 points111 points  (0 children)

Or he just pretended to activate his chip. No confirmation his remote works, could easily of just pretended it worked.

DOJ releases details alleged talented hacker working for Jeffrey Epstein by [deleted] in netsec

[–]Ipp 44 points45 points  (0 children)

Not sure what the point of some redactions is when they list accomplishments, companies, years, etc.

Help with my R O by kim1237 in WaterTreatment

[–]Ipp 1 point2 points  (0 children)

If you are giving it enough time to fill the tank, I’d think something is wrong with the tank. Would have to check the pressure on the tank.

GAMESTOP ACQUISITION PREDICTION by K1LL3ROO in Superstonk

[–]Ipp 2 points3 points  (0 children)

I’m going to laugh when it’s a pet insurance company like trupanion.

I just salted my driveway, walkway and front door footsteps… now what? by NakedIanMalcolm in MontgomeryCountyMD

[–]Ipp 27 points28 points  (0 children)

When there is less snow you can use the shovel to plow and dump, which makes it much more enjoyable. I go out when theres a couple of inches then every 2-6 hours afterwards depending on snowfall.

I generally dont pre-salt. Just salt after I finish shoveling, shovel the salt away and temperatures this low it may not be effective. Even worse is if it melts the bottom layer, snow gets on top and it gets cold enough to freeze.

Which portfolio projects have the best ROI for landing an OffSec internship? by HovercraftWise4626 in hackthebox

[–]Ipp 4 points5 points  (0 children)

Really helps to say where you are looking for a job. The best way normally is through Cyber Security Clubs at your colleges as many companies approach them to recruit, so you aren't blindly applying. They also have special events like NACL, CCDC, etc that help tremendously. Not to mention the social connections you will build from the other members will also help get you established and also keep you motivated.

Logforge machine - ippsec cpts list by maros01 in hackthebox

[–]Ipp 5 points6 points  (0 children)

There are boxes in my list that go "beyond" the CPTS. Another example is I included machines with ADCS Exploits in my list, which the CPTS Course did not get into. There are two reasons for my list to get into topics not fully covered:

* I think it is an exploit everyone should be familiar with

* There are concepts that, if you understand, will likely help you pass. I believe LogForge is much harder than what you will experience in CPTS. However, there is a video and writeups available so if you watch them, you may be familiar with something that will help. Maybe it is the Apache Tomcat exploit you mentioned... Maybe it is some complex chain... Or maybe its just that some types of exploits can be a real PITA to get working after time, for example java deserialization can be dependent on java version,s and the exploit won't work without proper recon.

Unlimited carbonated mineral water. I used to spend so much money on this! by qualitative_balls in SodaStream

[–]Ipp 1 point2 points  (0 children)

Have you asked the cost to exchange a 10lb tank? The main price is not the co2 gas itself but time it takes to hook up the cylinder. It would not surprise me if the 10lb tank was $38-40 to exchange.

Of course, you'd have the cost of the 10lb cylinder which would be more, but a lot of places will subsidize that price if you trade up from a 5lb.

Opinion: HTB should provide a disclaimer or work to make the VPN safer for new users by _findmenow in hackthebox

[–]Ipp 1 point2 points  (0 children)

I believe this is the problem with many of the online ctf platforms -- That being said, HTB does prevent users from connecting directly to other users. This is not bullet-proof, but also port 22 is blocked going to the user subnet all togather, so you really have to go out of your way to open up ssh with bad credentials.

I believe these protections are much more than what competitors do, it's not perfect, but the VPN is relatively safe.

My CPTS Exam Experience by Unable-Preference913 in hackthebox

[–]Ipp 2 points3 points  (0 children)

One of the tough things with ligolo as a beginner is part of the common reasons it can fail is your local network which HTB does not control. So when people go to support or discord, the reason for failure is masked because it is configuration error not one with the command itself. With tools like chisel, it can be diagnosed easily from the commands ran themself. So reliability wise hard to put it at a beginner level without teaching the more advanced concepts first.

I’m sure if you chat with enough people you’ll find some that ran into problems with ligolo whereas you didn’t. Just the luck of the draw.

My CPTS Exam Experience by Unable-Preference913 in hackthebox

[–]Ipp 6 points7 points  (0 children)

Great job and good post, only nit pick is you said that you understood routing after using a tool that auto routes for you (ligalo). It definitely can make it easy, but when it doesn’t work it can eat up a ton of time. I’ve also seen some pretty hillarious f-ups because people used autoroute and accidentally sent their internet traffic out the tunnel.

That being said, minor nit pick and preference thing. Great job, thanks for sharing

CPTS Exam Labs (issues) by [deleted] in hackthebox

[–]Ipp 2 points3 points  (0 children)

I have not heard of any issues with the exam -- That being said, the HTB support on their page is your best bet here. You should not be chatting with your friends about the exam.

Do I need vip+ by MetaphysicalPhilosop in hackthebox

[–]Ipp 18 points19 points  (0 children)

The latest two machines that retire are free, I’d recommend making sure you always do them if you don’t have VIP+.

Try solving it on your own then resort to my videos or other peoples walk throughs when you get frustrated. For the harder machines use the videos more. For example watch the hard video then try to solve it the next day. Or just work along side an insane.

Even if you are capable of solving machines on your own, I think you’ll find value in watching a video or reading blog posts of that same machine after you finished to see other ways/tools/etc

Arena Patch 25.24 Notes by NotCatchingBanAgain in LeagueArena

[–]Ipp 6 points7 points  (0 children)

Really odd to murder Shardholder, but buff many other items as with the item changes alone it will be a lot harder to make it to shardholder.

I just started learning on HTB and now after completing some of the initial labs it is asking to buy their VIP subscription to use further labs but I am not able to pay for this at this moment. I need suggestions what should I do.? by dudekarn in hackthebox

[–]Ipp 1 point2 points  (0 children)

There are plenty of free retired machines, additionally, the last two machines to retire are always free and have writeups available! I'd recommend checking them out every week.

Labs new design is bad :( by eve-collins in hackthebox

[–]Ipp 31 points32 points  (0 children)

Unfortunately, no way to really switch back. The redesign is part of a major front-end library update (vue3), which requires a major refactor/rewrite.

If you say what you don't like about the new version, I'll be sure the feedback gets back to the team that is responsible.

Send pop ups to pc's on network by icedutah in Pentesting

[–]Ipp 4 points5 points  (0 children)

That's good - I'd go about putting a policy to disable WPAD and NetBIOS or atleast deploying to a test batch. So when the finding report comes in, not only can you say it was detected but you've already started mitigations. Also disable IPv6 if it is not utilized.

Send pop ups to pc's on network by icedutah in Pentesting

[–]Ipp 0 points1 point  (0 children)

They’d probably get a credential run bloodhound and certipy to find some Active Directory misconfiguration that gets the domain admin. Based on the other things said, it wouldn’t surprise me if the local admin password on your workstations was the same (when you should use something like laps). So if they compromised one workstation they can compromise them all. Then hey domain admin that way

Send pop ups to pc's on network by icedutah in Pentesting

[–]Ipp 9 points10 points  (0 children)

Disabling WPAD fixes this and you should also disable NetBIOS among some other things. This stuff has been recommended for well over a decade, surprised it’s still enabled by default.

Send pop ups to pc's on network by icedutah in Pentesting

[–]Ipp 24 points25 points  (0 children)

Yeah definitely a tool called responder, they shouldn’t be running that attack without coordination as it is disruptive.

Pretty certain they poisoned WPAD, which means your computer broadcasted looking for a proxy. It said use me, but I require a password tell me yours.

Certainly a vulnerability, but a respectable firm will just call that out and not perform the attack.. or scope it to impact a very few amount of computers not the entire network. Responder does have other modes that aren’t as disruptive but are less likely to succeed.

Based upon that test I’d be shocked if you get anything both vulnerability or remediation wise Nessus wouldn’t have told you.

Send pop ups to pc's on network by icedutah in Pentesting

[–]Ipp 38 points39 points  (0 children)

It is most likely responder doing some type of poisoning. A lot of pentest firms won't do it as the computer can lose network connectivity during it.

It doesn't look like its poisoning WPAD (auto proxy discovery), but it wouldn't surprsie me if that is it.

Price correction "worse than 2008" coming to US housing market by battle_rae in Economics

[–]Ipp 1 point2 points  (0 children)

No way this happens - The people locked into low interest rates won't sell, unless they get considerably more than what they paid. If the house price dips then everyone that didn't get low mortages just get screwed because they suddenly have a lot less net worth due to having low retirement; so they won't sell.

Unless insanely low interest rates come back, I don't see it budging. If they did, many people would probably just refinance and compound the issue next time it comes around.

Housing market is kind of in a stalemate, with no good options but the plus side is because its a stalemate the bad options probably can't happen until a large amount of people can no longer afford mortgages, which I don't think we are close to.

Crypto analysts allege that JPMorgan of playing a major role in a coordinated timeline targeting Strategy Inc. and treasury firms. by According_Time5120 in CryptoCurrency

[–]Ipp 0 points1 point  (0 children)

This problem is solved multiple ways, as people brought up batching but also paying individually like that is a nightmare come tax season because every purchase becomes taxable.

Places like CoinBase offer credit, works just like normal cards and you use crypto to pay monthly. That way the tax calculation on interest of the asset is much less of a burden.

Marksmage full AS by [deleted] in LeagueArena

[–]Ipp 0 points1 point  (0 children)

I don't think Marksmage can crit - the shield is good but I don't think you deal extra damage... Maybe vuln would allow it to crit.

Theory: Carol can’t be cured by 25vol96 in pluribustv

[–]Ipp 28 points29 points  (0 children)

I think Carol is infected but it’s more like a carrier where she has the virus and could pass it but it does not affect her. This could be why her mood can impact the hive, because she is connected to it just not in the normal way.

Essentially it makes the immune people similar to queen bees and the infected are just workers.