@xyantix Hey.
I am a programmer who hacked your device's operating system.
I have been observing you for a few months already.
The point is that you have been infected with my virus through the adult website that you visited.
If you are not familiar with this, I will explain.
Trojan vi
@TracketPacer Not whole network, but also managed to uninstall iptables on a colo host (different country) after resetting all the rules, so no egress or ingress allowed at all
@TracketPacer Was poking at a login page on a pentest, thought it was weird that special characters in the username made the response longer sometimes. Thought I could enum user accounts with it. Turns out it was ldap injection, so I was locking out all accounts starting with A… B…
@mcohmi Make sure you check out master for extension stuff - recent changes use bof arg parsing which opens up the ability to send files as arguments etc
@nnwakelam if its the groove you like, there is a bunch of female vox gogo inspired tracks around - obvious ones that come to mind:
jlo-get right
amerie-1 thing
beyonce-greenlight
pretty much every backyard band cover of R&B/pop tunes
otherwise 00's pop all sounded pretty similar lol
@Ne0nd0g I wonder if there is anywhere in the runtime that exposes go functions as callbacks to OS routines - might be a good place to figure out the least painful way of doing it.
@Ne0nd0g I think you may be able to set up functions with a different ABI if you use asm, though I’m not sure I’d wish that on anyone even if it worked
@techspence Fun answer: RE exe, figure out crypto ctf
Fast answer: put exe and password file in a sandbox and listen on the relevant db ports for incoming connections
@lpha3ch0 Disagree. Cater it to the audience, but usually you are prioritising coverage during the engagement. If there is a question about what can be done with xss, there is plenty of reading material already around. If they want a poc, it should be considered extra.
@mcohmi@jrozner Caddy is great, but it’s bitten me a few times with not supporting old TLS stacks - HAProxy has been consistently good once you unlock the config logic in your brain
@ImposeCost I thought it was a pretty lame way to advertise your ‘swag’, but I’m not the target market so was gonna give it a pass. I was very disappointed to discover you use guessy challenges for technical interviews.
I don’t disagree with you on the value, I disagree with the execution.
@ImposeCost BaseN ‘matryoshka doll’ is bad chaldev, sorry. Doubly so in an interview. If the point is to see someone triage the file, just give the file and ask if they have heard of base32 or something.