On the quality of recent boxes...

@delo said:
if you want to do OSCP like boxes, fork out for VIP and do the retired machines created by ch4p - though maybe exclude brainfuck (which is still one of my favourites)

Realistic does not mean mirroring the OSCP environment. Nobody has said or asked for any such thing. Several people have said they’re here preparing for OSCP, but not one person has said, “I want a copy of the lab environment I already have access to!”

@delo said:
“Real world” external engagements generally have ‘slim pickens’ and if you are lucky enough to gain access, it is usually via default creds / password attacks against users i.e. boring - and you don’t learn a thing.

See:

re-al-ism
noun
the quality or fact of representing a person, thing, or situation accurately or in a way that is true to life.

As in, not having to go searching for critical files hidden in l33t_d1r_7h47_w0u1d_n3v3r_3x1s7 and other CTF elements that you would only ever see in CTFs. You don’t learn anything from that, either. There needs to be a healthy balance. It’s really not a difficult concept to grasp.

@delo said:
Want full real world webapp simulation? Go play bounties.

Yet another thing that nobody has alluded to. Not only that, but you can teach people web app vulnerabilities beyond LFI/RFI and SQLi (99% of what we see on this platform) without having to write a full-blown, custom CMS or being lazy and tossing up a vulnerable WordPress plugin.

@delo said:
It helps to look at each machine as a jigsaw puzzle rather than just searching software versions and banners looking for edb exploits.

“Everyone who’s complaining is just looking to pop easy shells with public exploits”.

First: Yeah, no. Try again.

Second: There are jigsaw puzzles and then there are jump-through-idiotic-nonsensical-hoops-just-because puzzles. Can you guess which of these two things people in this thread are complaining about?

@3mrgnc3 said:
Dear HTB Community

For the record everyone,

Anyone can feel free to DM me with constructive feedback (no abusive profanity filled rants please though) on ANY boxes I author once they complete them. Some people already have many times.

I will listen to your point of view. I will listen to you, and hope you allow me to put accross my thinking behind what I was trying to achieve. We can discuss it in a positive frame of mind, I want to improve and go on creating boxes for the benefit of the community purely because I enjoy and learn from it.

I don’t publish boxes to try to be 1337 (I’m so so not).

I love you all :wink:
:heart:

3mrgnc3

Look mate I know someone made the mistake of saying this thread is about you? It really isn’t. And nobody should be sending anybody abuse profanity ridden or otherwise, privately or otherwise.

Just point at the problem. Suggest a solution. Don’t get mad when you don’t get your little way. Work hard. Be kind.

I don’t know where all this ‘no foruming in the forum’ is coming from? The community belongs to everyone regardless of rank, experience, ability, longevity.

Hello everyone, I have been following this conversation, I really liked @3mrgnc3 suggestion, basically, I loved it because I love graphs and I believe that indeed the user should know what to expect before trying a machine (without giving away part of the solution).

Its already half-way coded, sample below, @3mrgnc3 I hope it meets your expectations :slight_smile:

@ch4p said:
Hello everyone, I have been following this conversation, I really liked @3mrgnc3 suggestion, basically, I loved it because I love graphs and I believe that indeed the user should know what to expect before trying a machine (without giving away part of the solution).

Its already half-way coded, sample below, @3mrgnc3 I hope it meets your expectations :slight_smile:

Pasteboard - Uploaded Image

I must’ve missed @3mrgnc3’s suggestion on this, but I just went back and saw it. I like it too. It’s pretty spiffy. Nice visualization.

However, I don’t think it addresses the core issue that this thread is based around; that of having too many “heavily” CTF boxes being submitted/approved. It gives people some forewarning before jumping into a box, sure, but that’s about it.

Note that I’m not trying to detract from new features being added. I honestly like the looks of this one.

@ch4p said:
Hello everyone, I have been following this conversation, I really liked @3mrgnc3 suggestion, basically, I loved it because I love graphs and I believe that indeed the user should know what to expect before trying a machine (without giving away part of the solution).

Its already half-way coded, sample below, @3mrgnc3 I hope it meets your expectations :slight_smile:

Pasteboard - Uploaded Image

Thank you ch4p. I think it’s a welcome addition and it fits nicely with the feedback throughout the discussions in the thread. I appreciate you taking the time to implement this kind of change which will add further value to the platform as a whole.

I get your point @opt1kz , my aim is also towards realistic scenarios (as you can see from my boxes excluding brainfuck).

All I can say is that we will try to enforce more strict guidelines and requirements for releasing boxes and stick the CTF-ish things for the Challenges section that is opening up in January for weekly releases and bloods aswell.

We could even split two tracks, HoF on Machines and HoF on Challenges (just a thought, would need feedback on this before we proceed in such a major change in rankings)

Have fun!

@ch4p said:
Hello everyone, I have been following this conversation, I really liked @3mrgnc3 suggestion, basically, I loved it because I love graphs and I believe that indeed the user should know what to expect before trying a machine (without giving away part of the solution).

Its already half-way coded, sample below, @3mrgnc3 I hope it meets your expectations :slight_smile:

Pasteboard - Uploaded Image

Looks exactly as I first envisaged it. :wink:

Thanks to for taking the time to implement it.

:love:

@ch4p said:
Hello everyone, I have been following this conversation, I really liked @3mrgnc3 suggestion, basically, I loved it because I love graphs and I believe that indeed the user should know what to expect before trying a machine (without giving away part of the solution).

Its already half-way coded, sample below, @3mrgnc3 I hope it meets your expectations :slight_smile:

Pasteboard - Uploaded Image

@ch4p Thanks for this. One of the reasons I like this community is that the mods and admins are active and listen to our ideas and criticisms.

One thing I could say that we might like a little more of is maybe a little more frequent updates. For instance, y’all have used the announcements page to address common issues such as concerns over machines like Vault and Ypuffy. Would it be possible to release maybe a weekly or bi-weekly (or even monthly perhaps) general announcement about what you guys are working on and what we can expect for the future? I know you guys are probably extremely busy, but I think this would help users realize just how much work y’all do to make this thing run as well as it does.

@ch4p said:
I get your point @opt1kz , my aim is also towards realistic scenarios (as you can see from my boxes excluding brainfuck).

All I can say is that we will try to enforce more strict guidelines and requirements for releasing boxes and stick the CTF-ish things for the Challenges section that is opening up in January for weekly releases and bloods aswell.

We could even split two tracks, HoF on Machines and HoF on Challenges (just a thought, would need feedback on this before we proceed in such a major change in rankings)

Have fun!

This is probably one of the best ideas. In this case, you can still accept the CTF like machines but you’ll put them with the challenges points & have a different section for “real world” machines.

The visualization looks great btw!

Keep up the good work & we support you fully!

.

Hi everyone! I’m glad to read all of your comments, I have been here for merely 80 days, and it has been a great experience so far that I have pushed other friends to join this great community.

And as @opt1kz, I begun to have the same feeling, when I first did Frolic that event though it started very CTF at the end I learned and did my first Ret2Lib exploit, so maybe it is just a matter of balance, and I know that my “just” it is not easy to accomplish it.

I have the feeling (and it is just that) that almost everyone wants a balance between real-world machines, and the ones for the lulz, so thanks @ch4p for understand it, and great work, it look promising the dimensional graphic for each machine, more than I already expected, a simple real-ctf flag.

So, as you can see, all of us as a community can make this HTB a better one, and why not “the best one”, we just need to be open minded, discuss about what we think should be the best, because at the end it will benefit all of us!

We are just in a great time to discuss about every aspect of the experience we want, but also it is difficult to understand the amount of duty that the HTB stuff do for keep this flawlessly.

My 2cents would be regarding the stability of some machines, I know that probably most of them fails for the excess of brute forcing (another topic, put a huge sign that states “NO BRUTE FORCING NEEDED!” on every single machine), but there has been some very annoying unstable ones though (teacher was one of them, even on the VIP env).

So guys, keep the good work!, everyone deserves to be heard (or actually read) as we ARE a community, and that is always welcomed.

Kudos to @ch4p, @3mrgnc3 , @opt1kz for the discussion and moving forward with the already stated suggestions.

Greetz to all

@gudj4qu3r said:
Hi everyone! I’m glad to read all of your comments, I have been here for merely 80 days, and it has been a great experience so far that I have pushed other friends to join this great community.

And as @opt1kz, I begun to have the same feeling, when I first did Frolic that event though it started very CTF at the end I learned and did my first Ret2Lib exploit, so maybe it is just a matter of balance, and I know that my “just” it is not easy to accomplish it.

I have the feeling (and it is just that) that almost everyone wants a balance between real-world machines, and the ones for the lulz, so thanks @ch4p for understand it, and great work, it look promising the dimensional graphic for each machine, more than I already expected, a simple real-ctf flag.

So, as you can see, all of us as a community can make this HTB a better one, and why not “the best one”, we just need to be open minded, discuss about what we think should be the best, because at the end it will benefit all of us!

We are just in a great time to discuss about every aspect of the experience we want, but also it is difficult to understand the amount of duty that the HTB stuff do for keep this flawlessly.

My 2cents would be regarding the stability of some machines, I know that probably most of them fails for the excess of brute forcing (another topic, put a huge sign that states “NO BRUTE FORCING NEEDED!” on every single machine), but there has been some very annoying unstable ones though (teacher was one of them, even on the VIP env).

So guys, keep the good work!, everyone deserves to be heard (or actually read) as we ARE a community, and that is always welcomed.

Kudos to @ch4p, @3mrgnc3 , @opt1kz for the discussion and moving forward with the already stated suggestions.

Greetz to all

Well articulated feedback. :+1:

I personally really appreciate reading everyone’s viewpoint in this thread. I will keep all of the stuff talked about throughout in mind when I get around to building a new box after FluJab gets released.

Thanks and Merry Christmas to all those who celebrate it.
and to anyone who doesn’t, I still wish you the same love.

We are all HTB :heart:

I dunno, I’m getting something out of most of them, although some of the CTF-style stuff gets a little tedious to me. I don’t really know why “most” people are here, whether to learn or do something entertaining that is not xbox or facebook. I’m sort of split down the middle. Ook and brainf*** made me smile, although I’ll never see them at work. On the other hand, if the forums indicate that a box is very CTF-ey AND the difficulty is high, and people have downvoted it a bunch, I will probably skip it (e.g. Bighead).

I do prefer the “realistic” boxes – it would be cool if more people who are doing counterthreat work would throw some boxes on here based on that. I’d also like more Windows, OSX, and IOT or other platforms for variety and breadth of experience.

PS I have a paid subscription and feel it’s a net value for me.

I am just too OCD to be able to skip boxes. If I could skip Bighead I would.

@izzie lol, I’m not quite that bad, but if I start a box it is very painful for me to let go… which is why I’m not even going to start in on Bighead !

I’d suggest that if the customer feedback on this product (ie, complaints in the forum) suggests that the type of box submissions should change, perhaps HTB could provide some incentives to submitters to create the kinds of boxes you’re looking for. Not sure what the incentive would be…

… People seem to like internet points and cred a whole lot (that’s me! ) so maybe submitters should get some kind of Creator points and rankings based on the qualities of the boxes. Or maybe that exists already and I’m missing it.

@LegendarySpork said:
I’d suggest that if the customer feedback on this product (ie, complaints in the forum) suggests that the type of box submissions should change, perhaps HTB could provide some incentives to submitters to create the kinds of boxes you’re looking for. Not sure what the incentive would be…

… People seem to like internet points and cred a whole lot (that’s me! ) so maybe submitters should get some kind of Creator points and rankings based on the qualities of the boxes. Or maybe that exists already and I’m missing it.

Makers do get though: the points for the box as soon as first blood is registered, just saying.

And LOL internet points. If you skip a box it really hurts your table rank/progress. I should get over it really. Probably will soon.

Heh, I have to take long breaks, so I tend to pick boxes from the bottom so that the points will stick around as long as possible. I love points almost as much as I love coffee.

But back to the topic – when I mentioned incentive I was suggesting that box creators get cred that is more tied to the type of attributes the community wants to see … maybe aligning with 3mrgnc3’s graph. (as opposed to discounts or monetary incentives, or other material whatnot)

@izzie said:
I am just too OCD to be able to skip boxes. If I could skip Bighead I would.

Of course you say that now ??