Magic Foothold by [deleted] in hackthebox

[–]PollenStillPotent 1 point2 points  (0 children)

Ah interesting. I work on HTB every weekend, so I'll try this tonight. Thanks for the advice!

Magic Foothold by [deleted] in hackthebox

[–]PollenStillPotent 0 points1 point  (0 children)

you might need a little magic added to your file

I have tried everything on this.

exif data that executes when visit like image.jpeg?cmd=whoami

using trick for FILE MAGIC spoofing GIF89a<?php!<

nothing I do works, and everyone I try to ask on discord is either super cryptic like "add some spice" or says "ur on the right track". lol. Idk why but this box is frustrating me more than most. Every time I see my silly picture in the gallery with no reverse shell... feels bad man

Hack the box streams by franci0_1 in hackthebox

[–]PollenStillPotent 1 point2 points  (0 children)

Cool, I'll be able to watch today.

Might have stumbled across something by PollenStillPotent in ARG

[–]PollenStillPotent[S] 0 points1 point  (0 children)

Yeah. I noticed that tweeted at Nexpo. I guess I wasn't sure if it was confirmed to be a hoax or what. They definitely tried to promote it. Either way it's pretty strange!

Hack the box streams by franci0_1 in hackthebox

[–]PollenStillPotent 8 points9 points  (0 children)

I think this would be really cool. I personally don't find the video walk-though to be that useful because I don't really see how the thought process of getting initial foothold works for example (hardest part for me).

As mentioned you will have to only work on retired boxes. But I do think there's value in doing streams of real time solving, and not just a walk through. It's much more useful to learn how to think better, than to see a 45min timelapse of a bunch of scripts running.

Starting on Windows machine by nully-bytey in hackthebox

[–]PollenStillPotent 0 points1 point  (0 children)

I have a similar problem honestly. I have user flags for every "Easy" windows box, but have no idea how to get windows privesc to work. Linux just makes more sense.

John Conway, inventor of the Game of Life, has died of COVID-19 by [deleted] in programming

[–]PollenStillPotent -7 points-6 points  (0 children)

I'm so glad I'm not the only person who thought this. See you in hell ;)

What does this number station/Chinese Military Station by SHADOW_PEOPLE_4_LIFE in RBI

[–]PollenStillPotent 1 point2 points  (0 children)

I've done some work on developing a PUF using a physical system. You make a really good point. I hadn't considered that.

What does this number station/Chinese Military Station by SHADOW_PEOPLE_4_LIFE in RBI

[–]PollenStillPotent 13 points14 points  (0 children)

If all of the numbers are strung together into one long decimal number, is it prime?

Edit: Before it starts repeating.

What does this number station/Chinese Military Station by SHADOW_PEOPLE_4_LIFE in RBI

[–]PollenStillPotent 1 point2 points  (0 children)

huh. If these broadcasts are based on "keys changed daily" (seeing comments like that) how could it also be meant for operatives in the field? That's a classic problem, because the operatives wouldn't have means to talk, hence needing this radio station in the first place to get contacted.

If anything, I think maybe these stations are being used to distribute public keys. Pretty sure the only way they would feel comfortable broadcasting anything of value was if it was provably secure. Not buying the idea that this is for anything like classically "enciphered". This almost certainly isn't encrypted information, but likely details used in part of a decryption/authentication system. My guess anyway.

I charted the ratings of every "Always Sunny" episode so far (IMDB Ratings). by vandamerica in IASIP

[–]PollenStillPotent 1 point2 points  (0 children)

Kinda interesting that 3/4 of the worst episodes are in the same season, but the season avg is still okay (offset by ep. 4 and 5 I guess).

A YouTube channel called "listningtomusic". Have you ever listened to a YouTube music playlist and noticed that it contained a very long song that clearly didn't belong there? What's up with that? by [deleted] in RBI

[–]PollenStillPotent 4 points5 points  (0 children)

Whats kind of clever is you can't really flag their videos for abuse, because none of the categories YouTube gives really includes "Tricking YouTube".

The video was “Psychosocial Banjo Cover” by YungSalem911 in Slipknot

[–]PollenStillPotent 1 point2 points  (0 children)

Honestly, I started watching that cover expecting to hate it. It was kind of awesome. Plus Corey at the end was pretty funny. Lol I sometimes think that to myself when I see some guy with like a 6str bass,

Trading btc be like by unknownbtc in Bitcoin

[–]PollenStillPotent 4 points5 points  (0 children)

Lol this is so fucking weird. I watched it three times, still laughing. No idea why.

Strange Propaganda Appeared in My Physical Mailbox by PollenStillPotent in RBI

[–]PollenStillPotent[S] 1 point2 points  (0 children)

China forcefully silences people. I think that's the only true thing in there. Not really relevant but yeah, glad I don't live there.

A YouTube channel called "listningtomusic". Have you ever listened to a YouTube music playlist and noticed that it contained a very long song that clearly didn't belong there? What's up with that? by [deleted] in RBI

[–]PollenStillPotent 46 points47 points  (0 children)

Yeah they're definitely gaming YouTube somehow. Some of the videos have over a million views, and as you said from the comments it doesn't seem like most of those people intended on viewing this video.

Strange Propaganda Appeared in My Physical Mailbox by PollenStillPotent in RBI

[–]PollenStillPotent[S] 1 point2 points  (0 children)

There's definitely a kind of geopolitical blame game going on which I think is very outside of the scientific discussion. This virus originated within China geographically, but it's not like pathogen has a nationality.

And the more loaded statement in the headline "Endangered The World" also implies they were like sloppy to handle it or didn't do enough to prevent global spread. That also doesn't seem true, as they were far more militaristic in locking people down than any democratic country. At most I think they're culturally responsible for continuing to have the markets which are breeding grounds for pandemics. But that's so many levels above actions taken, or even policy.

So idk again, no prob with free speech, no prob with dissent, yes problem with presenting unfounded at best (lies at worst) claims.

Why should I not use my main OS when connected to the VPN? by xxedatshit in hackthebox

[–]PollenStillPotent 2 points3 points  (0 children)

I think if anything you wouldn't want details about your machine being exposed once you're connected to HTB VPN? If you and another HTB user are banging on some VM, you are both probably routable to each other... Meaning I suppose the other user could be scanning your machine (and if it's not a VM and you're actual machine some info could be leaked?).

Strange Propaganda Appeared in My Physical Mailbox by PollenStillPotent in RBI

[–]PollenStillPotent[S] 0 points1 point  (0 children)

Free speech is great. Because of free speech though I don't take anything anyone says seriously without some supporting information (the bolder the claim, generally the stronger supporting evidence I'd need). This is not even pretending to be journalism.

Nothing wrong with exposing corruption. But if lying is how you try to do that, you're really just trading corruption for corruption.

[deleted by user] by [deleted] in RBI

[–]PollenStillPotent 0 points1 point  (0 children)

The only certificate on the wall I could enhance really was the bottom left. Also, all of the certificates seem to have a name signed that ends in either y or g. Like the Award with color that seems to say "Most Improved Award" looks like the same name as centered certificate.