#red-teaming-path

1 messages Β· Page 1 of 1 (latest)

frigid forum
#

πŸ₯³

pseudo mist
frigid forum
#

For Ticket Event related inquiries, please use the #1017019049181450291 channel (in the Support section). thm

lethal creek
#

Hey! I need some help with setting up the page at Gophish. I cant get the html code to work 😦

potent crest
#

Hi all . Im at Red Team Fundamentals, Red Team OPSEC Room.

I quite lost/confused even after reading the hint for task 7. What do they mean four question ? Arent there 5 ?

#

okay, i geddit πŸ˜‚ now i know why there's 4 question.

obtuse bone
royal void
#

oh wow they now include some network rooms on paths.....

white wharf
#

Wtf are "White Cards"

#

Can't find a reference anywhere or I'm just a bad googler

white prairie
potent crest
#

because i was so lost at the question. and yeah i think that task question have to re-structure abit

brisk path
white wharf
thin irisBOT
#

Gave +1 Rep to @brisk path

royal void
#

white team red cards not so much

frigid forum
# white wharf Wtf are "White Cards"

A good example of a white card is in the case a threat simulation calls for the use of 0day vulnerabilities. In most cases there are none available to a red team, so the use of it is simulated (as if it was used) in a particular attack scenario.

marble knot
thick pelican
#

In the Intro to C2 room on Task 6 I am only able to get the NTLM hash of the Administrator user and not Ted

#

Any ideas as to why this is happening

#

I'm in a Meterpreter shell and can get the other hash and flags fine

#

I used the 'Registry Method' to get it to work

#

Using 'hashdump' in a meterpreter shell like normal didn't work for me

thick pelican
#

This is the only question that I need to complete the room 😒

rose cedar
#

can someone help me at this quesstion?

#

is not |||spear phisinh|||

#

?

thick pelican
#

heres some proof i guess

royal void
royal void
royal void
# thick pelican

have you opened a shell as ted and then ran hashdump??? or using meterpreter and kiwi

celest vessel
#

also, make sure to scroll enough! everything related is highlighted so it should be doable to find it πŸ™‚

languid surge
#

am i the only one having trouble on Task 7 in "Red Team Threat Intel"? I cant seem to find the correct answers/order

sly ibex
#

am i doing something wrong or is there a bug in Post Compromise - Enumeration task 3

#

it says the version number is incorrect

#

nvm i forgot to do ssh lmao

languid surge
#

na sadly not

celest vessel
#

It is pretty "simple"

#

Use the Att&ck navigator

#

Search for APT41

#

And then match the TTPs to the chain

#

if that's the one where you are stuck at least

languid surge
#

Yeah im already on the "map" of APT41 on Att&ack and tried to search for the Words in the Hint but i only managed to find 3 of them in APT41 and if i just fill out the other 2 it says something is wrong

celest vessel
#

in the top bar you see the different categories

#

those categories match the table

languid surge
#

yes exactly thats how i found the 3 words but i cant find the others

celest vessel
#

If you have all APT41 highlighted you should have multiple options to be honest

celest vessel
#

You got it @languid surge :p

languid surge
#

not yet ...5/6 now and the lolbas thing is missing ... Hope i got more luck tomorrow πŸ₯²

celest vessel
#

can I DM you?

languid surge
#

sure

peak prism
#

Hi, I'm trying out this new path and I can't understand what's wrong with this crunch 5 5 -t 'THM@!' -o tryhackme.txtas an answer to the password attack room in task 4

#

I ran it locally and it does what is expected

royal void
hollow knoll
#
To use the ATT&CK Navigator: navigate to the groups summary page, next to "Techniques Used," navigate to "ATT&CK Navigator Layers," from the dropdown navigate to "view." An ATT&CK Navigator layer should have opened with the selected group's TTPs highlighted in a new tab.
royal void
hollow knoll
#

Where do I find the "groups summary page"?

royal void
#

then you click groups

#

then search for the group name using ctrl + f

#

then check a bit down the page under the box and there is a button for opening navigator

hollow knoll
royal void
#

no problem.... hopefully you can answer the questions now

hollow knoll
#

Yup I am unstuck now πŸ™‚

peak prism
manic shadow
#

Hello

#

Can I get some help :)

#

My last final question and yes I did Google but πŸ˜…

nimble seal
#

It is in the text above πŸ˜‰

manic shadow
#

AhhBlack_Movie_42

#

Still not found

nimble seal
#

Have you tried ctrl+f to search the answer ?
I cannot give a better hint than suggesting you to read the paragraphs above once again

pseudo mist
manic shadow
snow lantern
#

should be a fun weekend ahead with this new path πŸ™‚ but its kinda double edge sword by having some of these rooms done already in regards to the getting the tickets

manic shadow
snow lantern
#

def aint resetting all the AD rooms haha

manic shadow
#

i should of used the number 3 insted of three

#

oh my dayysss

#

i love u Robert

snow lantern
#

the asterisks are there πŸ™‚

pseudo mist
manic shadow
#

thanks so much

pseudo mist
snow lantern
formal yoke
#

Anyone having a difficult time finding the answer to the LOLBAS question in Task 7 - Creating a threat intel driven campaign?

formal yoke
pseudo mist
nimble seal
formal yoke
formal yoke
pseudo mist
#

(very useful website)

formal yoke
thin irisBOT
#

Gave +1 Rep to @pseudo mist

jade flume
#

Hey friends I have been battling with this for hours I’m not really sure what they ask us to do, can someone please give me some sort of idea

#

Number 1

final lotus
#

I can't enter the room at the moment but I think you need to enter the technique names as per the table in the top of the screen shot

#

try using those and put them in the correct order

jade flume
#

Thanks friends I figured it out

final lotus
#

great πŸ˜„

glossy sandal
jade flume
#

Hello friends please can someone take a second to explain what we are suppose to be doing here ? Just find it so hard to understand what the question is

#

Would appreciate as much hint I could get thanks

nimble seal
thorny marlin
#

Typo on OPSEC page @elder olive

rough owl
#

Anyone else having issues with GoPhish constantly spinning?

muted rapids
rough owl
muted rapids
rough owl
potent crest
# jade flume Hello friends please can someone take a second to explain what we are suppose to...

forget about the hint, the hint was quite confusing.

look at the answer field , the first 2 number they give u is the right answer. so 1st bullet falls under RISK (4) and 2nd bullet falls under COUNTERMEASURE (5).

so you are left with Critical Information - (1), Threats - (2) and Vulnerabilities - (3).

So when reading the bullet point number 3, which number (1,2 or 3) do you think it falls to ?

something like that .

potent crest
agile yoke
#

Can someone help me with this question in Room Enumeration Task 5- DNS question 1 , I use Dig to carry out a domain transfer, but it not return the flag ? any hint for this task, Tks all.

wide parcel
#

Hello, hope all are enjoying it

agile yoke
#

learning path Red-Teaming - Post Compromise - Room Enumeration- task 5- DNS

robust skiff
#

if you stuck, just read the task again

fickle halo
#

Just started the red teaming path

gray hawk
#

Trying to understand this, if armitage does not listen on loopback, then why does the example bind the port to the loopback address?

#

Intro to C2 room

elfin saffron
#

Can i get hint for these questions?

potent crest
# gray hawk Trying to understand this, if armitage does not listen on loopback, then why doe...

Say you already set up teamserver on port 55553 on your C2 server, which is on 192.168.0.44. You can now use another unix machine (lets say 192.168.0.100) to access that armitage server that you set up by port forwarding.

The full command is 'ssh -L 55553:127.0.0.1:55553 root@192.168.0.44'

  • Means: I want to Port forward port 55553 from 192.168.0.44 to my localhost which is 127.0.0.1 on port 55553.

So now, when you open another terminal in 192.168.0.100 and run ss -tulpn, you see that now u have access to your armitage server on your localhost 55553.

#

Feel free to correct me if im wrong. im always open to improve myself πŸ₯³

potent crest
tropic ginkgo
#

Guys, I've been stuck on this question. Evading logging and monitoring lab for the past two hours.Please help me.

gray hawk
#

@potent crest I think I get it: the admin sets up the command shown in the example, but another team member would use the syntax you wrote in your example.

potent crest
pseudo mist
pseudo mist
void cedar
#

Hey guys, I am following along the "Intro to C2" room and i am trying to run armitage on my own laptop. I've started the teamserver and I've connected successfully, but when i try to start a listener in the armitage I am given an error in the console that says "Timed out while executing 'use exploit/multi/handler' last read = {data=, busy=false, prompt msf6 > }; current prompt msf6' " After that i am presented with two or three errors of the same kind. Does anybody have an idea how can i fix this. Thank you in advance.

pseudo mist
void cedar
pseudo mist
void cedar
twilit quail
#

Hello guys, maybe someone can explain about John the Ripper "Single-Extra rule", how to use it? Password Attacks room

void cedar
forest cradle
#

need some help with runtime detection task 6

#

I keep getting error

sand arch
#

In the Password Attacks section, part 4, question 2. I ran the crunch command in terminal to generate the list to produce what it wants, but it's not accepting it as the answer. Am I doing something wrong?

sand arch
twilit quail
lean heron
#

im stuck (not in a washing machine) but at the obfuscating challenge-8.exe

#

obfuscation principles

pseudo mist
lean heron
#

getting the flag

#

like getting rid of meaningfull identifiers

#

i dont understand maybe my brain is broken

pseudo mist
# lean heron getting the flag

Walk me through what you're doing, how you've obfuscated, what you do to compile and anything you do after compilation (hint hint)

lean heron
#

so

#

i took the snip like they tell to do

#

i look and i think removed MFID

#

compile with mingw

#

to challenge-8.cpp to challenge-8.exe

#

nm + strip

#

and send it

#

wrong as it seems to be

#

so i retake the snip

#

and im lost

#

i dont know wtf im a doing

pseudo mist
lean heron
#

NO

#

OK THANKS

#

I KNEW IT

#

no i didnt know

#

mayber im not obfuscating enough

#

@pseudo mist can you explain to me in a voice chat ?

pseudo mist
jade flume
#

Hello friends I’m trying to solve the C2 room task 4 but each time I try to set up the machine using the preparing our environment instruction provided after the first start that have to do with starting postgresql…

When I try to run msfdb β€”use-defaults delete

#

I get an error is there anything I’m missing help mate

potent crest
#

@jade flume are u using ur kali or tryhackme ?

#

try to run sudo teamserver <your ip> <secret>

jade flume
#

I try to use my machine but have problems with the installation so I switch back

#

To attack box

#

I have to try this and see if it worlds thanks my man

lean heron
#

im stuck on downloading the file because WD delete it

#

and i cannot download it from the web it said access denied

#

🀣

pseudo mist
lean heron
#

sorry i just woke up im fucked up

#

i didnt thought about that

royal void
# sand arch

you almost have the correct command.... just 1 letter/character is wrong.... and it is in the ||THM^!|| part

sand arch
night tinsel
royal void
pseudo mist
royal void
#

or google/duckduckgo kung fu powers

#

searching for APT41 lolbas gives a few results

pseudo mist
royal void
#

yeah understood what the first 2 was based on the hint and that the answer box kinda states it

#

just all the other combos after seem to not work even when shadow thinks they are right

#

so they just left and decided to do command and control instead

#

after watching a video about cheese to calm down

pseudo mist
royal void
#

+rep @pseudo mist

thin irisBOT
#

Gave +1 Rep to @pseudo mist

lusty galleon
#

When you do the --rules in john and run it what is the syntax to out put that to a file?

pseudo mist
lusty galleon
#

I am not seeing it in either one

royal void
#

then | tee blah.password.list.txt

lusty galleon
# royal void `--stdout`

Thank you! I totally forgot about | tee, but I just used > list.txt and it worked also. Thanks again.

thin irisBOT
#

Gave +1 Rep to @royal void

royal void
#

no problem

#

and yeah remembering the stdout parameter/option/flag to output is kinda tricky

#

though you can grep for it

lusty galleon
#

Well, I read that and was trying it but I was obviously using it wrong lol.

thin irisBOT
#

Gave +1 Rep to @pseudo mist

dense trellis
#

I see, so many guys got red teamer titles

tulip igloo
#

anyone had any issues so far in the "Phishing" room with the GoPhish machine just getting hung with a loading animation? (not nginx error) have already tried clearing cache/history and multiple web browsers as well as re-deploy of the machine. loading animation is on every page

rustic dock
#

on the obfuscation task 7 Arbitrary Control Flow Patterns, the sample code doesn't compile because of a syntax error with case.
The line is
" for y in case_1:
match swVar: <<--
case 1:"
"
and the error basically says invalid syntax. I tried other versions but it didn't work.

I ended up changing to an if elif and got the flag but IDK if there is something obviously wrong

agile yoke
rustic dock
tropic ginkgo
lusty galleon
#

can I dm someone about password attacks task 9? I don't want to post any spoilers.

opaque iron
#

What am I even supposed to do here? I have no clue

#

The hint is also very confusing to me

lusty galleon
#

They want you to put them in order. They give you the first 2 numbers so you have to figure out which number comes next. Make sure you put spaces in between each number.

muted rapids
#

been stuck on the DIY sandbox evasion challenge for about 4 hours lmao... Everytime I run my c++ script it does this, can't seem to figure out why

marble knot
royal void
#

or will you just brute force it like everyone else???

muted rapids
crude burrow
dry snow
agile yoke
tropic ginkgo
#

Anyone already finished on Win10Office2016-Installed under Weaponization? I would like to know if you guys used the rdp to run the scripts? and where did you input the code?

-- answered my own questions

marble knot
#

I have had this VM running for about 15 minutes but it's just stuck on the spinning wheel of death. If I click "New Profile" or anything else - nothing happens. I have closed and re-opened as well as signed out and back in. Is this a common issue? I'll just try to reboot the VM in a little bit if it doesn't start working.

agile yoke
open reef
#

what happens after the 3 day access on the Breaching Active Directory room, do i just lose access to it forever?

white prairie
thin irisBOT
#

Gave +1 Rep to @white prairie

winged isle
pseudo mist
winged isle
thin irisBOT
#

Gave +1 Rep to @pseudo mist

tropic ginkgo
celest vessel
#

I believe I sometimes struggle understanding the question correctly πŸ˜…

#

like this one: "What is the crunch command to generate a list containing THM@! and output to a filed named tryhackme.txt?" πŸ˜‚

#

I literally spent half an hour on this question, the learning curve is present

pseudo mist
tropic ginkgo
celest vessel
#

How can I fix this issue on a Kali Linux machine?

#

this is for the dictionary attack on the hashfile

#

and where to run it then? :/

#

I am running Kali inside Virtualbox

#

the solution seems to be more simple by just assigning more RAM to the Kali machine

#

it takes a couple of seconds when you assign 8GB RAM to the VM πŸ˜„

tight granite
#

Hello fam, just started my red teaming path ! Any tip or suggestion for someone starting from almost 0

pseudo mist
tight granite
#

Gonna def check that

celest vessel
#

I would personally also recommend the complete beginner path

#

it contains lots of interesting basic concepts

iron saffron
#

true

celest vessel
#

because I am personally a bit surprised by the No prior knowledge for the read teaming path

#

if you dont know Linux commands it will be a difficult one

#

as well as understanding other basics

#

but again, this is my personal opinion

primal basin
#

It is recommended to complete the jr penetration tester path before red teaming

feral sage
thin irisBOT
#

Gave +1 Rep to @feral sage

#

Gave +1 Rep to @tight granite

celest vessel
#

I didnt get a rep 😒

primal basin
#

Into to c2 room, need help with armitage, I can't get meterpreter shell, i used metasploit for the same exercise and it was flawless, but the task says to use armitage.
I can use exploits i get direct shell , and can't run commands like hashdump, i tried using the post/windows/gather/hashdump module , i get incompatible shell type

ornate hull
#

What is the crunch command to generate a list containing THM@! and output to a filed named tryhackme.txt? can help me out

potent crest
#

@ornate hull the option is "3 letter word + special characters"

ornate hull
thin irisBOT
#

Gave +1 Rep to @potent crest

potent crest
ornate hull
#

i am doing it wrong

#

crunch 5 5 -t TMH^! -o tryhackme.txt

pseudo mist
potent crest
#

@ornate hull very close, replace the exclamation mark with something similar there

ornate hull
#

crunch 5 5 -t "TMH"^ -o tryhackme.txt

pseudo mist
# potent crest ^

yeah, there's some flexibility on the answer as there's a regex to check if it's "right", but 3 characters out will defo be over πŸ™‚

pseudo mist
#

so crunch 5 5 -t ||"THM^^"|| -o tryhackme.txt

ornate hull
#

thank you

potent crest
#

it was a rollercoaster ride for awhile πŸ˜‚

ornate hull
#

sorry i was trying with TMH not THM

potent crest
#

trymehack doesnt work bro πŸ˜‚ but honest mistake down there haha

tulip pulsar
pseudo mist
celest vessel
#

aaah man, I am gonna be so mad if the password crack is wrong πŸ˜‚

#

128 tries/min and there are 50k passwords to be tested

celest vessel
#

it is the online password room

potent crest
#

which task ?

celest vessel
#

or I am making an mistake πŸ˜…

potent crest
#

ahh im 4 task away from it

#

hahahah

celest vessel
#

task 8, the one where you need to make a rule-based dictionary

pseudo mist
celest vessel
#

tbh I followed the steps, made a list clinic.lst as said, make the dictonary adding 2 numbers + a symbol

pseudo mist
celest vessel
#

well .. I did use like 6 different symbols since the symbol itself wasn't shown

pseudo mist
celest vessel
#

it still gives you a lot of options I believe πŸ˜›

pseudo mist
#

Hmmm, i see the hint is pointing you at john rules, so i may be wrong with crunch, but i'd probs stick to just the 4 used in the demo in Task 6

celest vessel
#

yes

#

I narrowed it down a bit to 20k options

#

ok, got it πŸ˜„

pseudo mist
celest vessel
#

cool exercise to be honest πŸ˜„

brave sinew
#

stuck at this point as well πŸ˜„ Did you manage the smtp password? I always get "[ERROR] SMTP LOGIN AUTH, either this auth is disabled or server is not using auth: 454 4.7.0 Temporary authentication failure: Connection lost to authentication server" This is not normal, right?

celest vessel
#

yes I got it

#

well it is normal

#

because you don't have the password yet

#

maybe your list is not well populated

#

Did you make a rule-based dictionary changing the john.conf @brave sinew

brave sinew
#

ah, this is basically the message for "wrong password"? for me the message sounded more like " hey your AUTH method will not work at all"

#

Then we have to wait some more decades. this is slow. (i used mentalist to generate a wordlist)

celest vessel
#

well to be fair

#

if you have the right dictionary

#

you should have it in less than a minute

lusty galleon
#

^agreed. Once you have the right dictionary it takes about .03 seconds to crack

pseudo mist
lean heron
#

how can i encode manually to set my host my port and the runshell

brave sinew
pseudo mist
#

If you're Trying to post a screenshot, you'll need to verify

#

!docs verify

wind boneBOT
buoyant fog
#

ahah ye

#

I'll do it

#

ty

lusty galleon
#

I don't know how much of a hint or bump you want or I am aloud to give on here.

buoyant fog
#

So, as I said, I’m doing Active Directory Basics, at Task 4 where we have to found the flag on Sophie’s desktop. When I’m trying to Connect to sophie account I get this :

brave sinew
#

ahh wait. I think I missunderstood the task. Thanks, will try a bit more πŸ™‚

buoyant fog
#

Have I done something wrong ? ^^

pseudo mist
buoyant fog
#

windows machine

unique quiver
#

First exit out of Phillip rdp^

buoyant fog
pseudo mist
buoyant fog
#

ty πŸ™‚

#

it works, thx

#

Have a nice day all !

feral sage
#

I'm currently in the Network Evasion -> Firewalls room. Stuck at task 7. I'm not pretty sure how to setup the port tunnel, someone has some hint? (pm also possible)

valid flax
#

in "Introduction to Windows API", Task 7 q "What type of method is used to reference the API call to obtain a struct?"
I can't find answer to this? Is the answer available in the Task 4 content or I have to read MS docs to find the answer.

pseudo mist
thin irisBOT
#

Gave +1 Rep to @tulip pulsar

vernal jetty
#

Not all rooms are free right?

pseudo mist
brave sinew
# celest vessel did it work already?

YES :). Just wanted to say I reduced the wordlist to likely passwords and it didn't help, but my larger WL finally suceeded. Didn't expect this password to be the solution πŸ˜„

#

2 more passwords to go in this room

celest vessel
#

yes I am working on the last one πŸ˜„

potent crest
#

Task 9 for Password Attacks Room.

Any hint for the year and special characters ? πŸ˜‚ I already tried 2021 and 2022 with !@#$ as special character. Am i missing something here ?

celest vessel
#

I need to start task9 πŸ˜‚

#

πŸ₯³

potent crest
#

@celest vessel lets go

celest vessel
#

you found it?

potent crest
#

still trying

#

ahh i actually got, just that it didnt stop when found the password

#

i fixed it

#

hahahaha

long robin
#

yall im in sandbox evasion room and unable to compile cpp files, all it displays is "attach". how are we supposed to compile it? im trying to compile a sleeper file into exe

celest vessel
#

did you make a list then @potent crest ?

potent crest
#

yes

#

i make a list as the hint suggested

#
  • manage to play with some rules i learn in that room too.
celest vessel
#

hmm 500 tries, no hits

potent crest
#

shdnt be more than 200

#

How u craft ur password list ?

celest vessel
#

with john

potent crest
#

okayokay

#

just share u problem here later if u are still stuck

celest vessel
#

got it, something with capital and non capital letters πŸ˜‚

potent crest
#

yes

#

πŸ˜‚

celest vessel
#

going to take a break πŸ˜„

ornate hull
#

i need help or a hint in rule based the last one

#

"S[Word]NN

potent crest
#

@ornate hull - @pseudo mist assist you by giving the spoilers already

ornate hull
#

@potent crest I will figure it out

signal warren
#

does any one completed sand box room
dm me plse

#

plse helpppppppppppppppppppppppppppppppppppppp

potent crest
#

Task 5 - Phishing Room, is the website lagging ?

iron saffron
#

More people are getting on so could be the case

tropic ginkgo
#

I require help with task 7, flag 14. Can anyone assist me?

echo ore
grizzled viper
#

Hi, i need help in understanding what i need to do in a Task, dont whant any answer but my english is not the best and i have not figured out what i need to answer in the web page.

Its in Red Team Threat intel - Task 7, the web site

grizzled viper
thin irisBOT
#

Gave +1 Rep to @wanton nacelle

wanton nacelle
#

Happy to help!

manic shadow
#

I just saw this and can u help me with those 3 questions, the picture is kinda blurry

ornate hull
manic shadow
ornate hull
#

@manic shadow it in APT 41 software table

ornate hull
manic shadow
#

I seem to not be able to figure it out

ornate hull
#

@manic shadow it the ||ASPXSpy||

manic shadow
thin irisBOT
#

Gave +1 Rep to @ornate hull

ornate hull
#

@manic shadow Anytime mate

brave sinew
#

still missing the two http-form password attacks πŸ˜„ 😦 So many options what rules to apply.

celest vessel
#

haha

#

are you still working on that one? πŸ˜„

#

I found the http to be a bit more simple

brave sinew
#

had a break with other things to do, but basically, yes 😦

celest vessel
#

I get you, I also took a break πŸ˜„

brave sinew
#

is the password format given in smtp task valid for the website = all passwords or just for this specific smtp password?

lean heron
#

even with the walkthrough it says false i dont understand

lean heron
#

22 WSAConnect 22WSAConnect False 58 WSASocketA 58WSASocketA False True 5A WSAStartup 5AWSAStartup False True A5 htons A5htons False

dreamy glacier
#

Hi, can anyone assist pls to explain an answer in the Red Team Threat Intel Room Task 5 TTP Mapping question "How many Command and Control techniques are employed by Carbanak?" I got the answer by a process of elimination but in the mitre-attack data there are 16 C2 techniques listed - can't work out how the answer is determined. Many thanks

native berry
royal void
dreamy glacier
thin irisBOT
#

Gave +1 Rep to @native berry

royal void
#

ooh nice you figured out how it works

dreamy glacier
royal void
#

only 1 rep point giveaway every 5 mins... but yeah no problem

native berry
#
  • @royal void
thin irisBOT
#

Gave +1 Rep to @royal void

native berry
#

Always worried about the rep πŸ˜„

royal void
#

Β―_(ツ)_/Β―

obsidian patrol
#

Evening all

molten summit
#

Dropping something for people to find when searching. The GoPhish task in Phishing will spin. However, on your VPN system, go to the site https[://]YOUR.LAB.IP:443. It should load.

#

Doing the above will allow for completion of the task just fine. Happy hunting!

obsidian patrol
#

Thx answered my question before I even asked. Lol

fresh harness
#

Red Team Theat Intel --> Creating a Threat Intel Driven Campaign --> Kill chain site has 6 answer options instead of 7

#

Did anyone else answer those answer those questions?

obsidian patrol
#

@fresh harness start with weaponization

molten summit
#

I'm sure I did. Is that the one with the flow chart that you fill in the blanks for?

obsidian patrol
#

2-7 in kill chain

molten summit
#

The iconography is infuriating.

fresh harness
#

I did but it says, At least one of your answers is incorrect.

#

But thanks

molten summit
fresh harness
obsidian patrol
#

@fresh harness That question drove me crazy

molten summit
# fresh harness

Ahh, you're supposed to look at the APT in the question and put down a technique they use into the correct blank.

obsidian patrol
#

@fresh harness hit hint tab

molten summit
#

So, if they use Scheduled Tasks for persistence, the answer would be Scheduled Tasks.

thin irisBOT
#

Gave +1 Rep to @molten summit

jade flume
#

Hello mate, I’m having problem with weaponization room, task 5 I have been able to make the calculator pop up but I’m trying to chain it with a reverse shell like it was instructed so I generated a payload with msfvenom but the issue is after getting the output and Saving it in Microsoft I could not open it I get an error, so I have few questions that I could appreciate anyone that could help me with it, do I have to save the file as document1 or doc to make it work and again do I have to include the extra payload in the document or just output of msfvenom only

molten summit
jade flume
#

Just the output starting the #EndIf statement right ?

#

From ***

molten summit
#

From #If Vba7 Then
.....to....
End Sub

#

The last End Sub

jade flume
#

I get compile error mate

#

That’s from me trying to run it

#

To make sure it’s working from saving tho

#

Does that matter atall ?

#

Or do I just save and see if it works

molten summit
#

I'd say put what you get from msfvenom into the macro, nothing else in there. Save and re-open the doc.

jade flume
#

Thanks man

molten summit
#

Feel free to make multiple docs for each of those steps, like one that just starts cmd, and another doc that starts calc, and another with your reverse shell.

jade flume
#

Bingoooo

#

We are innn

#

Respect @molten summit

molten summit
#

And I think as a bonus, once you get meterpreter to connect and get a session, look up how to download files from c:\users\...page, and save your docs to your local system! πŸ˜„

#

Just note that you need two slashes for that command....Discord doesn't like that, though. C:\ \users\ ....

jade flume
#

Yes right I get the point you the man respect

molten summit
#

good luck!

jade flume
#

It work already thanks man

obsidian patrol
#

Doesn't work on port 443

jade flume
#

Weaponization room is one of the sleekest room I have ever done in my life

#

😍😩

molten summit
#

Be sure to use https.

jade flume
molten summit
#

Well, I mean yeah it's generally good advice, I suppose.

ornate hull
#

can any help me in password attacks on task 8 rule based event

jade flume
jade flume
ornate hull
#

@jade flume done mate

jade flume
#

find this article it should be useful for others so I thought I could share…

lusty galleon
#

Anyone available for help on Windows Local Persistence Flag 17?

jade flume
#

I’m yet to get to that mate would have love to help

lusty galleon
#

No worries man it is kicking my a$$ right now.

jade flume
#

I need help mate password attack, task 4 I inputted, crunch 5 5 -t THM@! -o tryhackme.txt as the answer but it won’t allow so I change it to 7 7 THM@!%% but the problem persist is there anything I’m missing here

jade flume
hot drum
#

I had the same issue

lusty galleon
#

Sorry trying to give help without spoilers is not my strongest ability lol.

ornate hull
#

Task 9 in password attack season + year + special characters I am doing anything wrong

winged briar
#

Oooof

celest vessel
#

Otherwise I might give a small tip

winged isle
#

Cannot get armitage running in room INtro to C2 Task 4. I am getting following error message when launching armitage:
Exception in thread "main" java.awt.AWTError: Can't connect to X11 window server using ':0.0' as the value of the DISPLAY variable.

#

I am running kali 2022.1 on a VMware Fusion on a mac m1

queen badge
#

Can sb helps me in the "Windows Local Persistence" Room flag13? Tried everything but didn't work

charred vortex
#

Hello, anyone having trouble with the Phishing room? I cannot get the GoPhishing to load properly. In dashboard the loading animation keeps on playing and I can't create any new profile/campaign

ripe basin
#

Hi,
I am stuck at Task 8 (Using MSSQL as a Backdoor) of Windows Local Persistence.
Does anyone know where should "evilscript.ps1" be located? At attacker or active machine? Thanks

jade flume
#

I think it should be the active machine

#

Hey mate I’m having problem understanding task 8 question, password attack room, what word list were they referring too when they said clinic.lst

#

Someone help

ripe basin
thin irisBOT
#

Gave +1 Rep to @jade flume

naive lily
jade flume
thin irisBOT
#

Gave +1 Rep to @naive lily

naive lily
#

Did you get the hydra one done? Or stuck on smtp?

jade flume
#

I’m having issue generating the word list but I’m use too using hydra for brute forcing all sort of network services that should not be a probs on its own atall

naive lily
#

Task 7 gives you the exact command to generate the base wordlist. Task 6 answer is how you should modify that base wordlist to answer Task 8

#

Task 7 + Task 6 = Task 8

tropic ginkgo
#

I need help with task 2 on Signature Evasion lab. How can I split DD or split because Windows doesn't support these commands?
Port 22 is closed. How can I scp the shell.exe?

jade flume
#

Maybe setup a web server then you use powershell -c wget β€œhttp://yourIP:port/file_to_get

tropic ginkgo
#

how can I start a web-server on windows machine?

primal basin
#

Im on the phishing room, and the gophish website just skips spinning, not responding

jade flume
primal basin
tough basin
#

.

crystal sandal
#

Maybe I'm missing something about how this documentation is written, but why is the date range labelled "engagement dates" not the answer for "engagement end", preferring instead the date listed for "post exploitation and persistence" (also why does this phase fall outside the engagement period?)

#

Red Team Engagements, task 7

nocturne stump
celest vessel
#

Did you open the file with sudo?

#

@nocturne stump

nocturne stump
celest vessel
#

Thats weird, is the file existing?

#

You def need root access to edit that file

nocturne stump
#

the folder does not exist /etc/john

celest vessel
#

Then you have found the issue

#

Try to reinstall john?

nocturne stump
#

tried to reinstall john now

#

trying

celest vessel
#

Ok πŸ‘

nocturne stump
#

Thanks pope

celest vessel
#

No problem!

nocturne stump
#

thanks @celest vessel

thin irisBOT
#

Gave +1 Rep to @celest vessel

jade flume
#

Sorry for the late response

nocturne stump
#

am i doing this wrong?

nocturne stump
#

i sorted it

crystal sandal
molten summit
#

Oh man, those questions were awful.

#

Just awful.

celest vessel
#

yes a lot of people struggled on those πŸ˜†

crystal sandal
#

It's not even clear what exactly it's asking

#

I would also like someone to acknowledge my previous question, if it is indeed an error

celest vessel
#

you have to match each response to one of those topics

#

each number is only to be used once

molten summit
#

It's probably a typo.

#

I mean, assumed it was.

tropic ginkgo
molten summit
#

Those questions could be slightly useful if it would pause after you get the right answer, so you can try to decipher wtf it's the right answer.

#

But as they are, that was a step back, learning-wise.

crystal sandal
#

Or make some kind of matching interface

molten summit
#

or just do each one at a time

crystal sandal
#

Instead of typing in a string to match statements together with no feedback, with poorly worded instructions

crystal sandal
celest vessel
#

I believe a lot of people bruteforced the answers

#

to be fair, I also found it to be a very weird thing πŸ€”

molten summit
#

The first one or two I did, because I had no idea what was going on. Then when I tuned in, it still made no sense.

#

So yeah, I bruteforced them all and moved on.

crystal sandal
#

people who bruteforce are still going to find the answer, or a guide

celest vessel
#

I am not sure what you mean but given that the first two digits are already shown, filling in the last three wasn't a hard thing to do

#

and a lot of people already posted comments about that section

vast quest
#

It's being redisgned.

crystal sandal
#

Scratching my head over this bit, didn't even realise it says "Coutermeasures"

#

*Covenant by Ryan Cobb is the last free C2 Framework we will be covering *
The section about sliver is after the section on Covenant, which is also free unless it's in the wrong section

primal basin
#

Has anyone completed the phishing room

molten summit
#

I am positive someone has, yeah

celest vessel
#

I am working on that one as we speak

royal void
primal basin
molten summit
royal void
royal void
molten summit
#

You have the patience of a creature of the night. πŸ™‚

royal void
#

heh yeah that is a skill shadow developed when downloading games in their kid years..... steam game downloads on old dsl modems were slow as molases

thin irisBOT
#

Gave +1 Rep to @molten summit

primal basin
royal void
#

okay then.... guess it might be slow or buggy

celest vessel
#

I didn't encounter any issue with the website (opened in Kali while being connected over the VPN)

molten summit
#

I sort of suspect it the js may be referencing something on a private address, and if you stay fully remote it just spins until a possible timeout. I didn't bother to check too hard since I'm not THM QA. πŸ™‚

royal void
#

oh yeah.... shadow had to disable some firefox extensions for it to work correctly

molten summit
#

ahh that's an even better idea probably.

royal void
#

mainly dark reader as everything else shadow has disabled for tryhackme domains by default

devout kernel
#

I am having trouble with this question been over the task and don't see the answer in there (What setting name that allows you to modify the Host header in a Meterpreter payload?)

molten summit
royal void
pure thorn
#

am I the only one that ran into a brick wall in password attacks > online password attacks?

#

prolly took like 2 hours to get the http flag

#

still got nothing on the other 3

#

is the dictionary built with the "rule" [symbol][dictionary word][0-9][0-9] supposed to be ~500K words?

mortal sparrow
#

if anyone could help out that would be awesome, I'm not understanding where to find the Access Types?

lean heron
#

read it

#

just read and you will find

mortal sparrow
#

oh damn, I see it. I've been doing this too long today haha

naive lily
pure thorn
#

Was all of them

#

Had multiple sessions running for hours against burgess and pittman

#

Wound up finding the other with a lateral move from another task

#

Ftp was just available in browser, don’t think that was intended

molten summit
#

or something like that.

solar coral
#

Anyone run into the issue of the Weaponization - Visual Basic for Application where the document is closing when attempting to reverse shell?

#

When doing all the other listed steps it works for loading Calc, opening the popups, etc, but copying and pasting the VBA script from msfvenom it closes before a reverse shell can open

molten summit
solar coral
#

I thought it was just a bad script made a new macro and it still loads, then crashes

molten summit
#

Only the msfvenom output is in the macro, yeah?

#

If so, you could maybe try to regenerate that, though I bet you already did.

solar coral
#

yeah I even attempted it in attackbox instead of my kali VM and it still crashed

solar coral
molten summit
#

boo πŸ™‚

#

beyond that maybe recheck ports and IP addresses, but, even a bad connection shouldn't close the doc.

solar coral
#

I get a semi connection using nc -lvp 4444 and it connects but doesn't connect to meterpeter

molten summit
#

you're in metasploit to upgrade to meterpreter, correct?

solar coral
#

yeah

molten summit
#

or rather catch it and do the dance that is. hmmm

solar coral
#

it doesn't crash word when I use nc to listen but when I use MSFConsole after verifying a connection using NC and manually start the exploit it crashes word/excel

molten summit
#

does it crash pretty quickly or does it take a few minutes?

solar coral
#

It takes about 1-2 minutes before it crashes

molten summit
#

but not enough to get a meterpreter through and do any commands?

solar coral
#

nope, going to try the kali optomized to see if it is an issue as I recently updated my metasploit framework

#

but if it works in the kali instance on THM but not attackbox that is strange

molten summit
#

I wish you luck, I have no other ideas. Mine worked pretty well with kali 2022.03 defaults. I think the only thing that deviated from the instructions would be after successful connection and doing a run post/windows/manage/migrate to keep it up.

winged apex
#

@molten summithave you finished the active directory basics redteam room?

winged apex
#

im stuck on https://tryhackme.com/room/winadbasics task 6 . i cant find the network share used to distribute GPOs to domain machines.
ive done all the gpo configuration and updated it and rdped like it asked. ive checked all over the gpo settings for it

molten summit
molten summit
solar coral
#

also no idea why/how? but it still crashes word as well even with msf5 but I'm actually able to get a connection but not to meterpeter in msfconsole unlike before

winged apex
#

i overcomplicated it @molten summit

molten summit
solar coral
#

So I'm able to get a command shell session but after running any command it kills word πŸ™ƒ

#

I had to respawn the machine to fix it, guessing it was a bad connection or something

ornate hull
celest vessel
ornate hull
celest vessel
#

what do you want to know

winged isle
#

I need another hint for room Password Attacks, Task 4:
This is my solution, but it's wrong:
crunch 5 5 -t "THM@!" -o tryhackme.txt

celest vessel
#

There is a special characther you can use to generalize symbols

#

@winged isle

zinc atlas
#

Exploiting Active Directory
Task 5 Exploiting AD Users

I recommend introducing some script that automatically picks up the process we need to migrate to.
Someone messed up that process and I can't go any further.
In the list of processes it does not exist, and this is the only process that allows you to perform the task, that is, to use the keylogger.

CANNOT COMPLETE TASK without resetting machine

winged isle
thin irisBOT
#

Gave +1 Rep to @celest vessel

zinc atlas
#

In the instructions we have written to take over the process C:Windows\explorer.exe, which is running with the permissions of THMSERVER1.local.
In the attached window, you can see that there is no process running as this user

zinc quiver
#

Red Team Threat Intel Task 7:

Open the provided ATT&CK Navigator layer and identify matched TTPs to the cyber kill chain. Once TTPs are identified, map them to the cyber kill chain in the static site. To complete the challenge, you must submit one technique name per kill chain section.

a bit ambiguous, I can't really solved without checking the hint as a tried with other technique combinations and didn't work ... could someone explain bit further? Thanks in advance!

royal void
#

anyone else having this kinda error on the windows local presistence room???

royal void
warped lion
#

Can anyone help me with the passwords attack room? task 8 and 9 are kicking my butt and i am having trouble creating a username list and getting the attack to actually work

celest vessel
#

Can you tell us where exactly you are stuck?

obtuse bone
#

no one did! LOL - they want you to order the steps and give you the first two. then another scenario pops up. very confusing wording

royal void
#

and for task 8 it is kinda straight forward if you know how to use hydra.... and the first question on that is as simple as remembering that some people forget to disable a default account on ftp

#

if you need more specific answers then that you would need to provide some more info

zealous wind
#

Something doesn't add up in the Password Attacks room in task 4. The crunch answer input expects crunch 5 5 -t "7 chars" -o tryhackme.txt but the min-max values for the generated passwords in limited to 5

#

must say its confusing

royal void
zealous wind
#

Quotes? where? generate a list containing THM@! i read it as THM[a-z]!

#

which is 5 chars, am i missing anything?

royal void
#

you surround the "thm@!" with quotes as what you are generating is going to include spaces and therefor be bleghg for terminal stuffs

#

also that was just an example the real answer uses only symbols and not the a-z thingy

zealous wind
#

if THM@! is just an example and the answer is only symbols, then the only thing i can come up with is crunch 5 5 -t ,,,^^ -o tryhackme.txt, which will give you three upper case chars and two symbols combination, but that also gives me a wrong answer.

zealous wind
#

also tried crunch 5 5 -t ",,,^^" and also "THM^^" not the right answers

#

any nudge to the right direction would be appreciated, i must be missing something simple here

#

HA! got it πŸ™‚

royal void
zealous wind
#

yeah, i figured it out! thx πŸ™‚

royal void
#

No problem

warped lion
#

@royal void i got the first task just fine lol. It's mainly the other questions in task 8. i am confused on the hydra syntax, and having trouble brute forcing that login-get webpage

royal void
#

small hint: ||hydra -l phillips -P clinic.lst 10.10.48.200 http-get-form||

#

@warped lion ⬆️

#

if you missed the hint

manic shadow
#

Keep it up guys , if I get stuck in any room ,hopefully I'll find it here without asking : )

warped lion
#

so i figured out the syntax and got that question, thanks

#

but when i try to brute force smtp, this is what i get: "[ERROR] SMTP LOGIN AUTH, either this auth is disabled or server is not using auth: 454 4.7.0 Temporary authentication failure: Connection lost to authentication server"

#

and this is my syntax: hydra -l pittman -P clinic.lst 10.10.30.14 smtp

#

and ive tried other ways besides that syntax and still get the same error. Has anyone ran into a similar issue?

#

@royal void Thank you

thin irisBOT
#

Gave +1 Rep to @royal void

royal void
#

the tickets are then rewarded... just check your tickets in the profile page and you will see what you got

#

you can get duplicates when you already have 3 of the same type

royal void
warped lion
#

@royal void how did u go about generating the rule based dictionary for that pittman question?

#

ive been trying john and will generate like 8000 words but i cant get it to save/overwrite the wordlist

royal void
#

john blah blah wordlist and rule --stdout | tee newwordlistthingy

warped lion
royal void
#

well you are getting there slowly but surely

#

it is also okay to take a break and come back later

warped lion
#

lol, ive tried doing it but the file crashes and gets locked in john.rec

royal void
#

huh

#

!docs verify

wind boneBOT
royal void
#

can you follow the instructions in that link and post a screenshot of the error

warped lion
royal void
# warped lion

if you run just john what does it tell you its version is???

warped lion
#

1.9.0

royal void
#

nothing about jumbo???

warped lion
#

1.9.0-jumbo-1+bleeding-51f7f3dcd

royal void
#

huh

#

weird then

#

just do a rm /opt/john/john.rec and try the command again... maybe

#

be careful with the rm command though

#

as it can and will sometimes delete files you need

#

if your path is wrong for example

thin irisBOT
#

Gave +1 Rep to @royal void

royal void
devout kernel
warped lion
#

@royal void is my syntax pretty on point?

royal void
#

but don't think that should affect it a lot

celest vessel
#

shadow, sometimes I wonder if you are some AI speaking for shadow herself πŸ˜„

royal void
warped lion
#

well thanks @royal void for oyur help, i guess ill just wait and see if anyone else can figure it out and try again a different time

thin irisBOT
#

Gave +1 Rep to @royal void

royal void
#

that is what it generated for shadow as the wordlist using the best64 rule

lusty galleon
#

Can someone help with Lateral Movement and Pivoting? I've tried connecting through my own vm and the attackbox and cannot get access.

royal void
#

not done that yet so sadly shadow can't help

devout kernel
#

Trying to break the hashes but get this error Hash '/root/Desktop/Tools/wordlists/hashes.hash': Token length exception. This is the command I am running hashcat --force -a 0 -m 0 /root/Desktop/Tools/wordlists/hashes.hash /root/Desktop/Tools/wordlists/rockyou.txt -r /root/Desktop/combinator.rule

royal void
devout kernel
#

do I need the ::: at the end

royal void
#

yeah probably

red tangle
#

tell me did we all can get all the prizes or who get first it's his?

devout kernel
#

Hashdump gave me the answer and I didn't even see it

#

all that is left is getting the flags

red tangle
#

go for it

#

you can do it

royal void
#

better explained in the tickets room

red tangle
#

i see then no point to go forward pineapple already taken

#

thanks

elfin tulip
#

!docs verify

wind boneBOT
elfin tulip
#

will the tickets no longer be useful if the voucher is already redeemed by someone

#

?

royal void
elfin tulip
#

😒 okay!

ripe basin
#

Hi,
I am at Performing an LDAP Pass-back & connected with my Kali VPN connected, while setup LDAP server, there's no selection on LDAP database (MDB) but it go next options ie "ensure the database is not removed when purged"
And I am unable to connect to LDAP server.

What could be the issue here?

worthy shuttle
#

Anyone want join to solve a room together ? Signature Evasion

zealous wind
#

hmmmm.......in Task 8 im running the brute force attack against the HTTP server and i get the User Pass pair from hydra, but when i use it in the login page in the browser i get login failed error

zealous wind
#

if I'm taking the -f switch, I'm getting the same 16 passwords for both users. I tried it with the custom list generated from the custom rule and the "clean" list, and both provide the same 16 passwords for both users. non of them work

#

what am i missing here?

primal basin
zealous wind
#

hydra -l [user] -P [path to password list] 10.10.131.145 http-get "/login-get/index.php:username:^USER^&password=^PASS^:S=logout.php" -f

#

that is the syntax im using

primal basin
celest vessel
#

how can you get 16 user passwords when you need to brute force only one account?

zealous wind
#

exactly

celest vessel
#

should it not be http-get-form instead of http-get

zealous wind
#

well, when you try the wrong creds you get Login Failed! message may using F=Login Failed! ?

zealous wind
primal basin
primal basin
zealous wind
#

how can a user has 16 working passwords?

mystic sage
#

they dont, your syntax is likely wrong

celest vessel
#

ah yes, I also see the mistake in the synthax

zealous wind
#

any pointer on what part of the syntax?

celest vessel
#

have a look at where you specify username

primal basin
mystic sage
#

i suspect S=logout.php is what's wrong here

#

but not sure

primal basin
mystic sage
#

google is also your friend, hydra can take a bunch of different things for success/failure

celest vessel
#

Did you found it already @zealous wind ?

spiral forge
#

Someone help please, I can't complete this task it keeps loading for a very very long time πŸ˜ͺπŸ˜ͺ

primal basin
#

The website is broken

#

Sorry port 443

spiral forge
potent crest
#

try typing : https://10.10.15.223

primal basin
#

Https://

spiral forge
#

Thanks

celest vessel
#

We wanted to let him search for it :p

zealous wind
#

i also tired hardcoding the user instead of ^USER^ didnt work either. but i keep looking πŸ™‚

mystic sage
#

if you setup proxychains you can make the request go to burp & inspect it to make sure it's doing exactly what you want

#

really handy for troubleshooting tools

celest vessel
#

ah he changed his comment πŸ˜„

#

you should not hardcode the ^USER^ part

#

it is something with username: which is not correct

zealous wind
#

ok

#

ill have another look

zealous lark
#

In the "Windows Privilege Escalation" room, the section about abusing SeBackup/SeRestore privileges is a little bit confusing (at least for me). It says that in order for the exploit to work the user must have the SeBackup/SeRestore privileges...then it shows a screenshot with a result of "whoami /priv" that clearly shows that the current user does NOT have these privileges...

#

I checked on the machine and despite the user THMBackup being part of the "Backup Operators" group, it does not have these privileges...but the exploit works anyway

wind boneBOT
zealous lark
#

This is the screenshot in the topic. "SeBackupPrivilege" and "SeRestorePrivilege" are both set to "Disabled"

#

what does it mean?

#

Ok, got it: if it's listed, the user has that privilege, the "State" column is relevant to the current process only

#

A little bit of explanation in the topic itself could be useful, in my opinion

#

will do. I agree, it's not a bug, just a little bit counterintuitive

zealous wind
#

so for the first user i got the following command: hydra -l phillips -P ./pass.txt 10.10.156.124 http-get-form "/login-get/index.php:username=^USER^&password=^PASS^:S=logout.php" -f which works, i got the right pass word.
for the 2nd user burgess u changes the method to http-post-form and the url to "/login-post/index.php" and using the custom list with the custom john rule which is Az"[0-9][0-9]"^[!@#$%^&*()/]

#

hydra comes up empty here 😀

#

should be the same other then changing the HTTP method and the uri

marsh birch
#

Hi! I've started this path and I'm having problems in the room https://tryhackme.com/room/redteamthreatintel with this question: "What signed binary did Carbanak use for defense evasion?"

I've used the ATTACK Navigator and I've also read the Kaspersky report about this APT but the answer I think is, it isn't. Someone could help me?

zealous wind
marsh birch
#

Thanks for your help @zealous wind. As the ATTACK shows, I've only have one option with this hint but It isn't correct... I don't know if I can tell you my answer

thin irisBOT
#

Gave +1 Rep to @zealous wind

marsh birch
#

I've tried with .exe and without it

zealous wind
#

think of what windows binaries in C:\Windows\System32 you have that can be used to execute malicious code

marsh birch
#

I also saw that this APT injects code in another built-in binary, but this isn't the answer neither

marsh birch
zealous wind
#

The answer is not in the carbank att&ck page

#

not in the software part anyways

calm gyro
#

Can I dm someone to explain me the crunch command task?πŸ˜…

native berry
calm gyro
zealous wind
#

omit the -o to see how the output looks like that will also help you out

calm gyro
#

First of all I did not understand from the task, how the output should look like? Which characters should be in the final output and which are special characters

zealous wind
#

THM something something

native berry
opaque iron
#

I'm setting up armitage in my local machine using the instructions in "Intro to C2" module under section "Setting up a C2 framework"

#

Lastly, we must initialize the Database so that Metasploit can use it. It's important to note that you cannot be the root user when attempting to initialize the Metasploit Database. On the AttackBox, you must use the Ubuntu user.

This instruction is given in THM but I am unable to start msfdb as normal user as you can see above

#

What do I do?

primal basin
#

Sudo msfdb init

zealous wind
#

If anyone can DM me about the last part of task 8 I'd appreciate it!

native berry
zealous wind
#

Password attacks.....sorry about that

native berry
potent crest
#

@zealous wind what problem are u facing for that task ?

zealous wind
#

so for the first user i got the following command: hydra -l phillips -P ./pass.txt 10.10.156.124 http-get-form "/login-get/index.php:username=^USER^&password=^PASS^:S=logout.php" -f which works, i got the right pass word.
for the 2nd user burgess u changes the method to http-post-form and the url to "/login-post/index.php" and using the custom list with the custom john rule which is Az"[0-9][0-9]"^[!@#$%^&*()/]

#

hydra comes back empty

potent crest
#

task 8 last question is not using custom rule

#

u must use single-extra rule from john

zealous wind
#

sorry but i thought the custom rule == single-extra

#

what is single-extra rule then>

potent crest
#

so task 6 u learn on how to craft ur own rule

#

if u run the command to see all the rules, like this:

#

so when the hint tell me to use "John's Single-Extra Rule", i take it as use john in built rule, not the custom rule which i created.

#

i also have the habit to double press my tab key to see if i miss out anything and for auto completion, doing so i stumble upon the rules like this

#

first tab after typing "sin" to see if the rules is valid. If it autocomplete, means its valid.

#

double tap the tab button and it tells me that i have 2 option to use.

#

so from there u play around with it and look at the stdout or the file (if u save all ur output to a file) and see what the rules does ! πŸ™‚

calm gyro
#

Or should contain this one: "THM@!". Because is confusing to say what is the command to generate a list of one string. If we say a list that means we have more words.

potent crest
#

@calm gyro what task are u doing again on password attacks ?

#

task 4 is it ?

latent grotto
#

Getting a PostgreSQL error when trying to run teamserver on Armitage

potent crest
latent grotto
#

yea, i ran everything with root privileges

#

db works fine on msfconsole but it wont connect with teamserver

zealous wind
potent crest
#

whats the command u running on ? @latent grotto

zealous wind
#

now im using list.txt in hydra

zealous wind
#

see what happens πŸ™‚

calm gyro
# potent crest task 4 is it ?

Looking through old discussions here on the channel, I found the answer. And is still unclear for me.
||The answer how is in the task is not correct because you need 6 characters, not 5. And why do you need 2 '^' to get the symbol '@' ? Because the ^^ will add 2 symbols for you.||
The whole problem is that I did not understand what should be the final output?

latent grotto
zealous wind
#

pehwww.....finally worked πŸ™‚

#

thanks for anyone who helped out!

potent crest
#

@calm gyro the final output should be THM@!

THM@! = 5 characters

^ = means it will run special characters including space

if u include 2 of these ^, means 2 special character will run

THM@! = 3 letters + 2 special characters = 5 characters

Does that make sense to you ?

zealous wind
#

but the input expects 7 chars that what threw me into a loop initially

calm gyro
potent crest
#

@calm gyro hm im curious, why the exclaimation mark at the end ?

calm gyro
potent crest
#

if u include the exclamation mark means is 6 characters

calm gyro
#

Ok... I have no more words🫠 Anyway, thank you for the help, it really helped me to understand πŸ˜„

thin irisBOT
#

Gave +1 Rep to @weak ice

potent crest
thin irisBOT
#

Gave +1 Rep to @potent crest

potent crest
#

thanks @weak ice πŸ’―

thin irisBOT
#

Gave +1 Rep to @weak ice

calm gyro
#

What is that?

twin dagger
#

what is rep btw

#

new here

potent crest
#

i remember someone say all the answers to the question have some like regex checking or sort of, now that u mention that way

twin dagger
#

haven't used reddit lol

calm gyro
#

So is not counted somewhere?

twin dagger
#

is it something like more you active the more points you get?

#

ok! get it!

latent grotto
twin dagger
#

thanks! @weak ice and @calm gyro

thin irisBOT
#

Gave +1 Rep to @weak ice

potent crest
latent grotto
#

did u use this command apt install -y default-jdk

potent crest
#

no i didnt

#

oh i think i how i did it was install armitage thru apt

#

i didnt clone anyhting

#

so i didnt clone anything or run any script, just install armitage straight from apt and run it

latent grotto
#

i see

formal dew
#

"What would the syntax you would use to create a rule to produce the following: "S[Word]NN where N is Number and S is a symbol of !@?" passowrd attacks room task 6

#

i couldn't find the answer

copper talon
#

I've been waiting around 20 minutes for the gophish emails to be opened in the Phishing section of red team learning. would you say i probably put something in incorrectly, or has anyone else waited quite a while on it?

potent crest
#

@copper talon do this: https://<targetIP>

zenith sonnet
copper talon
#

thanks for the replies, i'll recheck my configurations

zenith sonnet
#

maybe you weren't convincing enough πŸ˜„

celest vessel
#

I also had data in less than 2minutes

#

I think it even took 1 minute or so πŸ˜„

copper talon
thin irisBOT
#

Gave +1 Rep to @zenith sonnet

sand arch
#

Anyone here able to give me a little help using Detect it Easy in the Windows Internals room?

sand arch
formal yoke
#

Is it normal to get multiples of "red teamer" tickets after you redeem it?

celest vessel
#

I believe so, also had this yesterday

sand arch
#

Yeah it's random what tickets you get, i appears, I've gotten multiples of the Red Teamer ones after unlocking it

unkempt hemlock
#

Room: Password Attacks
Task: 8
Question: How do I get the flag in the first question?

Upon running hydra -l ftp -P list.txt ftp://10.10.166.77 I have the output as shown. What should I do next?

#

Assuming it's talking about using some sort of default credentials, I'm lost.

#

ftp
open
IP

#

Yeah, but I require a "Name" and a "Password"... that is where I'm lost on.

#

the question said no brute forcing... so i seem to be missing something in plain sight?

shadow quartz
#

@unkempt hemlock are you familiar with anonymous login for ftp?

celest vessel
#

now you have given the ultimate tip πŸ˜„

celest vessel
#

I remember on one of the first trainings on Tryhackme, they said google is your friend

shadow quartz
#

Give that a google

unkempt hemlock
celest vessel
#

A lot of times you need to do some additional research as well, also you would be surprised by the amount of stuf you can find on google

#

like default user and pass for cctv systems (it is just one example)

#

the same goes for ftp servers, that's why the question is "without brute-forcing", to enforce you to search for it - on google πŸ˜„

unkempt hemlock
thin irisBOT
#

Gave +1 Rep to @shadow quartz

unkempt hemlock
#

Thank you so much for the help.

celest vessel
#

well, we all have to learn, the same counts for me

unkempt hemlock
#

I'll try and get better at researching. :)

celest vessel
#

did you do the basic cybersecurity training? It is really good

#

and I have spent more than the hours they say on this training πŸ™ˆ

unkempt hemlock
celest vessel
#

you can always pick it up again πŸ˜„

unique rain
#

Hello pips !
I don't understand the first question in the signature room evasion :

To the nearest kibibyte, what is the first detected byte?

#

which value do I need to put ?
It is in byte or kibibyte ?

#

as I understand the question i need to give the value that I found in byte in kibibytes

calm gyro
#

Hello, how can I save the output from the custom rule made by John, in a file?

royal void
calm gyro
thin irisBOT
#

Gave +1 Rep to @royal void

royal void
#

tees manpage ==

NAME
tee - read from standard input and write to standard output and files

#

i.e its intended purpose is just for this

calm gyro
#

Hello, me againπŸ˜… Can somebody help me with this one?

zealous wind
#

add the :S=logout.php at the end of the linw

#

i think that will fix it for you

calm gyro
#

Ah, so hydra will check the correct credentials by response. Yeah, make sense, let me try

royal void
#

yeah for the http hydra methods it needs something to check for on success or failure to know if it got in or not

zealous wind
#

@calm gyro don't forget to add the -f after that to tell hydra to stop processing once a user pass pair was found

tropic ginkgo
#

All my tickets was deleted ☹️

vast quest
tropic ginkgo
#

Oh! o_o

calm gyro
tropic ginkgo
#

I got my 3rd ticket to get the $20 swag and then everything was deleted πŸ˜”

royal void
tropic ginkgo
#

But I got the t shirt before coolguy

royal void
tropic ginkgo
#

@royal void niceeee

royal void
#

the hat is somewhere in sweden right now so yeah it is getting closer

calm gyro
#

Still doesn't work

#

I tried either with: :F F= :F=

royal void
# calm gyro Still doesn't work

hydra -l phillips -P clinic.lst 10.10.48.200 http-get-form "/login-get/index.php:username=^USER^&password=^PASS^:S=logout.php" -f

#

worked for shadow

#

of course change the ip