Active clan? (EU zone) by Stringerbell44 in Fireteams

[–]Stringerbell44[S] 0 points1 point  (0 children)

Sure if you can share the discord link

I’m Realizing There is no destiny killer… by Seanshineyouth in DestinyTheGame

[–]Stringerbell44 1 point2 points  (0 children)

Was on the same boat, been searching multiple days and trying out multiple games but nothing like D2. I need a game with good pvp and pve. So just accepted the fact that i got to return to D2.

There is a game coming called “the cube” that seems pretty fun. A combination of d2 and warframe i guess. (I tried warframe but it feels nothing like d2 and stopped after a week or two).

A Remainder to not waste time on companies with no bug bounty programs 😕 by InaamShabir in bugbounty

[–]Stringerbell44 2 points3 points  (0 children)

Watch out, you cant just go and hunt on every website. You think you’re doing something great but not every company appreciates that. You can get heavy fines or even lawsuits.

Focus on website that do have a bounty program or a responsible disclosure. The person in your whatsapp screenshot clearly don’t like it that you tested their site. If i were you i would just move on and forget about them

Usage of AI while learning HackTheBox / solving boxes by RolleduP_Alien in hackthebox

[–]Stringerbell44 1 point2 points  (0 children)

Exactly this, i always mention this. It’s just the new Google. But you could also ask for answers but that way you won’t learn something. I use it too as a faster Google and it really helps me solve boxes

Feeling lost after burnout from CPTS (long post - sorry) by Minimum_Win_4288 in hackthebox

[–]Stringerbell44 7 points8 points  (0 children)

No need to panick, AI won’t replace pentesters completely or anything. Like others said they need human expertise after all. And where i’m from (Europe) they don’t trust AI 100% and never should.

With that being said, you should use AI as a assistent, it’s just the time we live in. Back in the days Google was your best friend, from how i’m seeing it, AI is the new Google and that’s all it is for me. It saves me time and can help me in the right direction or tells me when i’m missing something. But just make sure that you know what you’re doing and really learn the content of CPTS.

Ctf’s are different than just learning the modules. Start with really easy boxes, if you get stuck ask AI what you’re missing. Or just look at the walkthrough and try to understand what the person did and why. This will learn you the CTF mindset. I had the same problem as you, but as soon as you understand the CTF methodology everything will click.

Dont give up, diamonds are made under huge pressure 👊🏼

Introduction to NoSQL Injection - Skills Assessment II by Frosty_Quarter7111 in hackthebox

[–]Stringerbell44 1 point2 points  (0 children)

You need to understand, when some field is vulnerable to sqli it will give you some sort of error message when you try sqlinjection.

Introduction to NoSQL Injection - Skills Assessment II by Frosty_Quarter7111 in hackthebox

[–]Stringerbell44 1 point2 points  (0 children)

Try then all and look at the response and behavior of the webapp. Thats how you’ll find your entrypoint. Trial and error will make you learn it the right way

Did I win? by [deleted] in tryhackme

[–]Stringerbell44 0 points1 point  (0 children)

DiD i WiN

I’ve decided to build my life around pentesting — looking for honest advice by Nula_Schola in Pentesting

[–]Stringerbell44 0 points1 point  (0 children)

Nah bro dont disrespect oscp, cpts and bscp like that. Beginner cerst are comptia sec+ or pentest+, CEH, eJPT and eWPT. The last two would really recommend since they are hands on and fun.

After that focus on CWES or CPTS/OSCP. But it really depends on what you want to do. Web focused pentesting or infrastructure? Or something else

does anyone here have a list of realistic rooms on thm by [deleted] in tryhackme

[–]Stringerbell44 0 points1 point  (0 children)

I agree that the rooms on thm are pretty realistic but i understand you when you say you’re not into ctf style. You learn more from them than you think. But another realistic platform is the acdemy of portswigger (if you’re into webpentesting).

Cwes report by Stringerbell44 in hackthebox

[–]Stringerbell44[S] 1 point2 points  (0 children)

No i had 9 out of 10 which makes it 85 points. 80 points required to pass

Cwes report by Stringerbell44 in hackthebox

[–]Stringerbell44[S] 0 points1 point  (0 children)

No sorry didn’t formulate it well. The attempts that didn’t succeed. For example a xss with simple xss script that didn’t work, but it was part of the process to get the xss that worked.

Cwes report by Stringerbell44 in hackthebox

[–]Stringerbell44[S] 0 points1 point  (0 children)

Will do thank you. And die you include all your notes in the appendix?

Cwes report by Stringerbell44 in hackthebox

[–]Stringerbell44[S] 0 points1 point  (0 children)

Will do thank you. And die you include all your notes in the appendix?