#tryhack3m-special-module

1 messages ยท Page 1 of 1 (latest)

merry quest
#

๐Ÿฅณ

hearty storm
#

๐Ÿฅณ

cold star
#

Wasnโ€™t expecting these to drop early ๐Ÿ˜€

bold badger
ivory hornet
#

Yeaaa

#

๐Ÿฅณ

tired moss
#

๐Ÿ˜ฎ

#

oh, the colours got fixed too

ivory hornet
#

Breaking: Timtaylor is not the first!

lilac knot
#

๐Ÿฅณ

cold star
ivory hornet
#

hehehe

narrow onyx
hollow sparrow
#

Have fun everyone ๐Ÿฅณ

thorn vapor
#

nice release and fun that this is a new one without any answers out there ๐Ÿ™‚

light temple
#

๐Ÿฅณ

hollow sparrow
#

Which of the 5 challenge rooms has the coolest name? ๐Ÿค” Please post here. ๐Ÿฅณ

hazy jungle
#

Are we allowed to talk about solving the module in this channel?

hollow sparrow
hollow sparrow
stoic crescentBOT
#

Gave +1 Rep to @hazy jungle (current: #2059 - 1)

hazy jungle
crisp ledge
lyric temple
#

Man Challenge 1 question 4 is pain

crisp ledge
#

i startet with question 4 now

reef yarrow
#

I didn't understand task 5 from room sch3mad3mon very well, can anyone shed some light?

narrow onyx
#

Im stuck on the last 2 question in Exploitation in Subscribe hopefully I can break through it soon

crisp ledge
#

1 lab down

spare nova
#

sch3mad3mon task 4 is making me feel fully stupid lmao

#

Figured out what I was doing wrong lmao

hollow sparrow
knotty spoke
#

0 labs down
infinitely more to go

raven estuary
#

took me a minute but i finally got a shell on the first one โค๏ธ

grim brook
grim brook
#

going nuts on the last flag of sch3mad3mon

red dagger
#

Nice Firework simulation when you finish TryHack3M: Subscribe room and restore the sign up page, nice room thanks to all creators for this room @tardy sail @hallow crescent @covert bobcat and TryHackMe

stoic crescentBOT
#

Gave +1 Rep to @tardy sail (current: #158 - 41)

hallow crescent
#

Goodluck everyone ๐Ÿ™‚ cant wait to see you all crossing the winning line ๐ŸŽ‰

spare nova
#

I'm hard stuck on sch3ma task 5 lmao ahhhhhh

sleek prism
narrow onyx
#

Hard stuck at Subscribe Task 2 Question 3

grim brook
ivory hornet
#

Anybody has a hint for "What is the name of the suspicious process?"

spare nova
nova siren
spare nova
#

(I did not, in fact, figure it out lmao)

narrow onyx
charred yarrow
gloomy jacinth
#

So I'm in task one and trying to find hidden txt with ffuf and gobuster but after 10000 requests I don't get response from server and search gets stuck??? What to do now

mortal egret
gloomy jacinth
#

Ok

quiet sedge
#

Subscribe was a nice one ๐Ÿ‘ I really enjoyed it

floral umbra
#

I've compiled the script with nim, but I don't get the flag

#

i've installed the nimcrypto and winim but no chance ๐Ÿ˜ฆ

magic sand
#

What day are people going to be able to ask for hints? is that today?

floral umbra
#

This is not how to solve the challenge. I've done the entire room all by myself. I have errors with script while compiling it

#

is not necessary to be mean..

magic sand
#

I am not sure who you are talking to rave, I was asking to ask for help for myself

#

up top of the channel it said 72 hours until hints but I wanted to verify heh

floral umbra
#

Ah sorry, when you replied to the chat, I thought it was addressed to me

floral umbra
#

I've managed to solve almost the entire room and I'm blocked at the last task with compiling a .nim file (which is the first time i'm doing it) and it feels frustrating because I'm not doing it right

wooden rivet
narrow onyx
floral umbra
#

Thanks mate. I hope you can compile the code and get the flag. Iโ€™ve installed the required dependencies, but wonโ€™t work. Tbh? I think I have to see if it is nim installed on the machine and try to compile it from there ๐Ÿ˜…

floral umbra
#

I was overthinking it too much. I tried to compile the script locally instead of compiling it on the machine ๐Ÿคฃ

narrow onyx
#

lol

#

Yeah I am stuck on the last question

hearty storm
#

No hints please.

23 hours.

floral umbra
#

Sorry.

narrow onyx
#

Finally after 3 hours of thinking I solved the last question to TryHack3M: Sch3Ma D3Mon and have a writeup ready

red dagger
#

me too, finally I got TryHack3M: Sch3Ma D3Mon, compiling the script was not an issue when I arrived to that step, I got stuck on reverse shell did not want to work for me and it was my mistake!! nice room @dusk crypt @MaxRobertson @arebel and TryHackMe

floral umbra
grim brook
narrow onyx
#

Currently stuck at subscribe question about secure token to admin panel, I feel I'm getting close to the answer but overlooking it

spare nova
#

Finally got past the point I was stuck on for sch3mad3mon and I'm not even sure how lmaooooooo, must've been something silly that I won't theorize about until the embargo is lifted

timid vault
#

Iโ€™ve found the secure token, but I canโ€™t figure out what to do with it to get access to the admin panel ๐Ÿ˜ฆ

#

For subscribe

spare nova
#

I just apparently broke my target machine lmao

#

Or the web server at least, time to terminate and start from the beginning coolguy

#

Oh now I'm hitting an extremely annoying problem, I think there's a workaround though

hollow sparrow
spare nova
hollow sparrow
spare nova
#

Okay now I'm stuck on something that I feel like shouldn't be an issue lmao aaaaahhhhhhhhh

fickle dragon
placid spear
hollow sparrow
nova siren
#

Second place is still up for grabs on Burg3r Bytes

#

Third place is also up for grabs on TriCipher Summit

red dagger
shut idol
#

I can't seem to find the hidden path in the unlisted task in sch3mad3mon room, any hints?

solemn wadi
#

Hey,
I think this is the right channel to reach out to the TryHackMe Staff. I would like to thank you very much for the e-mail I received on Monday. It really made my day. What a great appreciation :)!
This is a great event. I think the Burger Bytes Challenge will be my favorite, even though I haven't found everything and come to a solution yet. I am looking forward to the writeups of the ones who are able to solve the room. There's a lot to learn here!

ripe violet
#

A couple of days with gastroenteritis is quite funny (now) but no excuse for not getting anything at all with burger challenge. Definitely need hint or writeup ๐Ÿ˜…

floral umbra
#

I didnโ€™t do that room, but that would be my wild guess when I get a session token.

floral umbra
timid vault
#

Tried adding a cookie with name as session and value as the token.. no luck. Same with the name set as PHPSESSID

nova siren
#

I am assuming you are both staring at a ||forbidden page||?

spare nova
nova siren
spare nova
#

Oh actually I think it's lifting right this minute quite literally

#

In that case ||why tf is gpg failing to decode with a bad session key error no matter how I try it on or off the target system|| (for sch3mad3mon task 5)

nova siren
# timid vault Yes I am

I got stumped there too for a sec but had to take a step back and ||ask myself, just because I canโ€™t see that page, doesnโ€™t mean I wouldnโ€™t be able to see other pages inside that directory. Just got to find them.||

stoic crescentBOT
#

Gave +1 Rep to @nova siren (current: #61 - 112)

placid spear
#

Any hints on the ||security toke, or where is the admin page (is it the phpmyadmin?) || on the subscribe ?

hollow sparrow
#

The only hint I have for burgerbytes is ||๐Ÿ”||

timid vault
floral umbra
spare nova
knotty spoke
#

shadow feels to burnt out to try these and just gonna have fun reading writeups later

floral umbra
#

reverse shell won't work. at least for me

#

i've used only sql injections

#

but here is a thing,|| curl has its magic ways of working ||

spare nova
#

It shoooould be possible with the batch option if I've understood the stackoverflow answers correctly. Would copying the file contents not work either? Because I did try that too, complete file with header and footer. I guess I'll try another exfiltration method when I get home

floral umbra
#

you can tranfer the files from the system. check with my suggestion above

narrow onyx
#

Didn't do the gpg decrypt lol

spare nova
narrow onyx
#

But I'll wait for a writeup to see if others have done it

floral umbra
spare nova
#

Interesting that it seems popping a shell wasn't necessary, I ended up spending a lot of time getting that to work lmao

floral umbra
#

yea it was the same for me, maybe the've limited some things from the docker, so I had to find other simpler ways

spare nova
#

Seems like most standard routes were blocked in some way but I didn't bother trying to redirect stderr or anything to get detailed info

narrow onyx
#

Still stuck on secure token, and the 2nd question of brick lol (didn't have much time to explore this one)

placid spear
placid spear
spare nova
ripe violet
lost cloak
#

Question regarding 3M room Sch3Ma D3Mon task 5:
||I'm unable to use lannister's credentials from users table to ssh into the machine, even tried password from task 1 but neither of them work. I even got bitcoin addresses for decrypting receipts as well as a portion of task 5's answer (/home/products/malware/4sale/) but can't figure out how to complete the rest. Tried to use mysql since it has /bin/sh as its shell but password was incorrect again, any hints on what I'm missing to log in?||

narrow onyx
spare nova
#

@placid spear Stabilizing the shell was the move, got everything working nicely ||also I was trying the wrong address lmao||

#

Aaaand that's sch3mad3mon completed, really got hung up on that decryption step and it was just me shooting myself in the foot lmao

spare nova
#

||Did you defang it first? Always read the readme!||

lost cloak
stoic crescentBOT
#

Gave 1 Rep to overseer92 (current: #2062 - 1)

placid spear
#

Only the hard ones left now NotLikeThis

floral umbra
placid spear
floral umbra
#

the cipher one you've finished it ?

terse zodiac
#

Are we supposed to get a rev shell on Sch3Ma D3Mon? I have tried several times and it has opened a few times but immediately closes...

floral umbra
terse zodiac
#

Alright cool. I was having issues and couldn't figure out how to do the gpg stuff without it lol.

floral umbra
#

for the GPG i've used ||curl for exfiltration along with nc||

terse zodiac
#

I'll give that a go.

placid spear
acoustic knot
#

this secure token is kicking my tail

#

Are the drop downs supposed to work? Just curious, cause they aren't for me

red dagger
acoustic knot
red dagger
#

If remember when you login you see 2 courses one free and one premium, are you at that point

red dagger
#

can you access premium course? if so easy way just check ||source code and look for strange named file|| so you can understand how the code work. as button for me too did not work

acoustic knot
red dagger
#

in my understanding you are looking for secure token

acoustic knot
#

yup

red dagger
#

what I propose is how you get it

acoustic knot
#

the buttons are not in the premium course, your suggestion seemed to indicate that I should look at the premium course for the button thing.

#

sounded like you were mixing them up

#

ive been looking at the source for an hour now

red dagger
#

which course you are looking at? free or premium?

acoustic knot
#

all 4 pages

red dagger
#

there are only 2 courses

narrow onyx
acoustic knot
#

yes I know that. I am looking at the source for all of the pages is what I meant

red dagger
red dagger
acoustic knot
#

okay, maybe thats my issue as I am not using the VM

narrow onyx
#

||ah I click on it after modifying a value, and gave me alert saying i have no access to it||

red dagger
red dagger
acoustic knot
red dagger
acoustic knot
#

I see this, I have had access to this for a while, but you say have access. I am not sure if we mean the same thing

#

if you mean clicking on it, then anyone can do that

#

but not sure if you mean something else

#

|||such as the actual url not existing and instead redirecting to the subscribe page, cause I have looked both pages up and down and do not see the token|||

red dagger
#

if redirecting to the subscribe page so it mean you do not have access to it, so first find a way to have access to it

placid spear
acoustic knot
narrow onyx
#

Kind stuck on the last question of the task 2

red dagger
narrow onyx
placid spear
terse zodiac
stoic crescentBOT
#

Gave +1 Rep to @floral umbra (current: #2062 - 1)

narrow onyx
#

@red dagger Thanks for the wisdom and hints ๐Ÿฅณ it help me narrow down what I was overlooking

stoic crescentBOT
#

Gave +1 Rep to @red dagger (current: #264 - 19)

acoustic knot
#

ugh this admin privesc is a pita

knotty spoke
acoustic knot
#

but for real, I think my machine is broken

acoustic knot
#

holy hell how did I miss that...

floral umbra
floral umbra
#

or is it a rabithole ?

acoustic knot
floral umbra
#

on the burger bytes

#

i thought you're doing that ๐Ÿ˜…

acoustic knot
#

not there yet

#

nope I found out how to move forward with the secure token. I overlooked something small

#

but I think i broke something or I am accessing it in a way I am not supposed to... so theres that

floral umbra
#

I took a break from burger bytes. found te console which is blocked by the pin and there is a secret and I don't know what do with it. because i need to use the secret without pin I guess

acoustic knot
placid spear
acoustic knot
#

Did you get the admin page?

floral umbra
placid spear
floral umbra
acoustic knot
#

Apparently this room has been removed...

red dagger
floral umbra
supple wedge
placid spear
solemn wadi
floral umbra
supple wedge
solemn wadi
supple wedge
#

and i think i need some rest ๐Ÿ˜…

supple wedge
#

after a few cigarettes

supple wedge
#

Got the First Flag....

#

But why it's error on revshell ?

supple wedge
#

I was able to create dodol.sh with nc mkififo to my ip why it's cannot run?

supple wedge
#

Need help to escape from docker please some1 give me some hint i was trying with ||mounting|| and there is no progress angrycooctus

supple wedge
#

Hi , @solemn wadi or @red dagger can you guide me please.. Sorry for tagging you guys

red dagger
red dagger
supple wedge
red dagger
#

I will try the room again later

supple wedge
supple wedge
#

Need more rest for learn about python script

red dagger
supple wedge
red dagger
#

I am not sure on that root container port 81 there is server, may be send the shell /var/www/html (add path on the python script) then call it on port 81, I am not sure it will work

supple wedge
placid spear
placid spear
supple wedge
red dagger
supple wedge
red dagger
#

as that python script is like an ftp you can put / get files, you can think of classic way of ssh to linux without a need to enter password, there is 2 well knows ways, one of them will work

supple wedge
red dagger
#

You can get the pin too

supple wedge
red dagger
#

you can using it to get reverse shell, its another way to get reverse shell for initial access

supple wedge
red dagger
#

initial access, user flag

supple wedge
#

Still stuck for a few days ... and don't know what to do with the python script

supple wedge
#

Thank you for guiding me @red dagger i am so idiot not to think about that. Acctually the hard one look like easy after you know the right path

stoic crescentBOT
#

Gave +1 Rep to @red dagger (current: #252 - 20)

red dagger
sick stratus
stoic crescentBOT
#

Gave +1 Rep to @spare nova (current: #313 - 15)

placid spear
red dagger
#

you can guess it or look for the links when you add to cart

placid spear
supple wedge
placid spear
supple wedge
placid spear
supple wedge
placid spear
stoic crescentBOT
#

Gave +1 Rep to @supple wedge (current: #191 - 31)

placid spear
# supple wedge Keep spirits

Man I tried using || hashcat rules to make a list with every possible combination of the links only to see that the answer was the simplest one || Thanks a lot!

stoic crescentBOT
#

Gave +1 Rep to @supple wedge (current: #188 - 32)

placid spear
#

Wow this really was a machine out of my league, but with all the help I finally could get at the end, reeeally learned a lot with this one, really enjoyed it, thanks to everyone who helped!

floral umbra
#

Finished too the burger bytes too. Nice chain of exploits for the web part. And interesting method of making privesc.

scenic kayak
#

glad you enjoyed :3 was fun to make with me and my two teammates ๐Ÿ˜„

woeful kite
#

I have only solved subscribe but I can say that I quite enjoyed it. It was original and good.

empty birch
floral umbra
#

If youโ€™ve found the script it means you are in the right direction. Just donโ€™t do it locally, i remember that there was a readme file which was telling you something about debug. Check that as well. And for compile. Check the syntax for nim compile. The nim is on the docker

empty birch
#

What about the tools?
Need to install nim, nimcryptoand winim, maybe something else?
I am confused by incomprehensible compilation errors.๐Ÿ˜•

empty birch
floral umbra
#

You should compile the script on the victim machine. Nimโ€™s compiler is there ๐Ÿ˜„

empty birch
stoic crescentBOT
#

Gave +1 Rep to @floral umbra (current: #1383 - 2)

floral umbra
#

hehe no worries mate, I'm glad that I've helped. I was in the same rabbit hole. Never had experience with nim scripts before and I was doing it on my machine

small moss
#

The 3M Subscribe room VMs contain license error of Splunk because the trial date is expired. Can this be fixed?

small moss
stoic crescentBOT
#

Gave +1 Rep to @hearty storm (current: #1 - 2421)

small moss
hearty storm
merry quest
#

Working on it as we speak, should be done by Monday at the latest, if not sooner

merry quest
hearty storm
merry quest
hearty storm
merry quest
jade turret
#

Hi everyone
I am currently stuck in the TryHack3M:Subscribe room, is this right place to ask questions?

jade turret
#

No the DB records from my Admin portal dump don't make sense

#

And the Admin credentials aren't working

#

@drifting phoenix can I DM screenshots of what I am talking about?

drifting phoenix
jade turret
#

Thank you very much for the prompt response though๐Ÿ™

#

I just got it, thank you very much for the help ๐Ÿ™

#

Awesome room, shout out to the creators ๐Ÿ™Œ

empty birch
#

TryHack3M: Burg3r Bytes
Hello everyone, there is no way I can get the application to reply to me POST (Status code 302), where I should see the redirect.
What am I doing wrong?
I'm ready to post screenshots, but there are a lot of spoilers.

empty birch
#

NM
I found a workaround.
Which worked. (although I've tried 3 different ways before)

willow whale
#

hi

torn sandal
#

@shell crescent

#

@celest knot

#

Can you update my role

celest knot
torn sandal
#

O Okay

opal pivot
orchid swallow
#

salut tout le monde

hollow granite
#

hi y'all good morning from here

urban sierra
#

Can someone mentor me to be a ethical hacker?

vapid slate
nocturne abyss
vapid slate
nocturne abyss
#

the next course after linux fundamental 1 is the 2, with a link to take me thr...

i guess its not for free plan..... and i was waiting to have it unlocked for me

vapid slate
ashen bronze
#

Why the certificates so expensive?

violet rose
ashen bronze
ashen bronze
violet rose
ashen bronze
# violet rose Bout to

I wanna take too but I'm lacking behind the payment gateway, anyways if you want to discuss pt1, I would like to hear I am new too ; )
Anyways Good luck

honest knoll
#

I donโ€™t understand what Iโ€™m doing wrong here. I know I have the command correct

gray oasis
honest knoll
#

Thank you

latent herald
#

Hello, I would need help on this topic. I don't want the asnwer but may be mored etails on how to get the answer ? thanks in advance : Content Discovery, Task 3
Manual Discovery - Favicon

#

Practical Exercise:

On the AttackBox, open firefox and enter the url https://static-labs.tryhackme.cloud/sites/favicon/ here you'll see a basic website with a note saying "Website coming soon...", if you look at your tabs you'll notice an icon that confirms this site is using a favicon.

Viewing the page source you'll see line six contains a link to the images/favicon.ico file.

If you run the following command on the AttackBox, it will download the favicon and get its md5 hash value which you can then lookup on the
https://wiki.owasp.org/index.php/OWASP_favicon_database.

curl
user@machine$ curl https://static-labs.tryhackme.cloud/sites/favicon/images/favicon.ico | md5sum
Note: This curl will fail on the AttackBox if you are a free user, in which case you should use a VM for this. If your hash ends with 427e then your curl failed, and you may need to try it again. You could also run this on Windows in Powershell as shown below.

PowerShell
PS C:> curl https://static-labs.tryhackme.cloud/sites/favicon/images/favicon.ico -UseBasicParsing -o favicon.ico

PS C:> Get-FileHash .\favicon.ico -Algorithm MD5
Answer the questions below
What framework did the favicon belong to?


Submit
Hint
Task 4
Manual Discovery - Sitemap.xml

ashen bronze
stuck barn
#

Pls am looking for a cyber security mentor,am in need of someone to work with,help while growing myself

proud surge
#

I need a hacker to hack my account back for me

obtuse kernel
#

ive just started doing the oentester junior and am having trouble with the viewing the page source when it asks to view the website in the comments. there is no website in the comments. am i missing simething

static marlin
#

It's not allowed in here and can get you in jail.

mystic pollen
#

Need to learn more about hacking

glass cairn
tropic igloo