#voice-chat
1 messages ยท Page 6 of 1
yah i found monitor
JFC learn how to name variables
nope this is just to tilt you lmfao
Borders on rule 4 there
@plucky vault learn how to use curl
@plucky vault Also remember I can ban you from the room
So super rule 4
then learn to use curl
@plucky vault ip a s
No sudo required
Try harder
Run less code as root
Don't abuse sudo
okay
@plucky vault That's literally the easiest thing to fix
Applies to 90% of rev shells on THM
90-100%
@plucky vault You really don't need to other than patching it
That go is just the source code for the webserver
It's uh
not compileable on the box
yah yah hang on
yeah im doing that rn
im sur you are
wdym only 1 screen
No
Just some basic research
omg
@plucky vault learn how to google
I literally told you what to search
Uh, yeah, yelling at Google ain't gonna help xD
yes yes google help me
You know
Googling what I told you to google might help
Learning what a reverse shell is isn't likely to
okay i stop trol
@plucky vault
reverse shell use sudointo google
@forest python
James, relax. It's funnier without him knowing he's not looking at the right thing
ikr
its not easy at all
It's something you should instinctively know how to fix
Those quotes aren't real quotes
They're fancy format quotes
Welcome to ubuntu 1804
The fix is really really obvious from what you're being told
You don't have a real shell
You need a real shell
There's a bunch of ways
The python one is one of them
i know
You just skipped it when python2 wasn't installed
There is python
It tells you python is installed
You just need to actually try
Think about it
be smarter

It worked
Now keep working
I gotta eat in a bit
@plucky vault You upgraded your shell already
You're not spawning nested shells within shells
try actually using the shell you have
@plucky vault You don't have the password, so running commands as sudo aint gonna work
ooo
If you can run any commands with sudo without a password, sudo -l won't require a password
then i have to get sudo without being sudo
*root
superuser ๐
*root
*root
administrator xD
yeah i just discovered that
It says abusing sudo rights
Read the title
@plucky vault You need to understand that before you attempt to use it
root 725 0.0 2.0 185948 20204 ? Ssl 19:20 0:00 /usr/bin/python3 /usr/share/unattended-upgrades/unattended-upgrade-shutdown --wait-for-signal```
bingo
No
Not at all
You found something that runs by default on ubuntu as root
Well done.
@plucky vault You need to understand what you're doing
And I can promise you, you don't
If you just throw commands at it with no logical process and no thought, that's what makes a skiddy
Skiddies don't try to understand
hackers understand.
No, you don't understand
it should give me root
I keep posting privesc cheatsheets
didn't you say thats skidy?
exactly
smh im bad at privesc idk what do you expect
Then don't say either box is easy
for the record i didn't play food like seriously ever and that /monitor is like lucky hit
hackers is easy box ok ?
Don't say something's easy without actually knowing
Hackers isn't easy
You haven't completed it
okay i won't give up actually
i will complete both
hang on
like 5 sec
let me just get an idea
okay
@plucky vault aaaaaaaaa
@plucky vault You can generate SSH keys and use those to get a better shell btw
Nice trick
But it won't help you there
@plucky vault https://tryhackme.com/room/thefindcommand
Learn what you're doing reee
finding anything that ends with .sh in the folder
You're just throwing stuff into find
find . -iname ".sh" will find files called exactly .sh
A backslash?
cuz idk where its located i had to switch to other keyboard accedently spilled booster on it
yah well James im not made of money yk
If you weren't in serbia, I'd post you one smh
well noone is made of money
no tnx lol ๐
can someone give me that key
/ but reversed
like its looking at oposite side
2 late
i found it
\
import strings
print(strings.symbols)```
You know
"*.sh" works
But you're not looking strategically
You can search from /
lol
it might not
Whatever you're doing, whatever it's being interpreted as, there's no results
Doesn't matter
@plucky vault Cheater.
its hurting my heart that i can't look at it rn lmfao
aa give me little hint ; (
tiny tiny hint
The little hint is stop just runnign every single command you know
Have a strategy
A method
Use your brain

All the Best Elf ๐ฅฐ
i hate privesc
i liturally feel like world's dumbest guy rn
Now stop saying that either box is easy
you can do it Elf!
what box is this?
food
Food CTF
@plucky vault No. You haven't privesc'd either
You got a shell really fast, in the hardest way on FoodCTF
wdym hardest way
its liturally easyest way ever
it says : ping:
liturally the name it self is saying that you can use that to get reverse shell
SMH
Not for reverse shells
It was designed to be hacked that way
That was the hardest access route on that box
All of the others are crazy easy in comparison
If that's the hardest way then what are the others 
how is that hardest access root idk
I need to check these koth boxes
Waht
smh even szymex understands me
it's not root
i highly doubt its easy
You're running random commands
no im not
smh even szymex understands me
@plucky vault wat
You don't have any method
wdym method
๐
@plucky vault No, there are logical things to do when looking for a privesc
@plucky vault now you're just wasting time 
u tried scripts? like linpeas? it will MAY speed up
You haven't completed it
yah well im doing it rn
You can't root either

For both of them, it's hard for you
first proof
The proof is you're failing right now.
Hard stuck.
thats not a fail
Without a strategy
yeah something like that
No idea of what to try
but not a fail
also why are you using vscode as your terminal 
cuz i can't do full screen share idk why
like when i want to share full screen
look
im gonna be swtiching to windows 7 soon tho
it had a problem with full-screen screensharing on linux
Windows 7 is EoL
Mind DMing me the IP? I'm curious if I can get root before you do 
never did food so it's new to me :)
there i sent you
got it ๐
wait i forgot i alredy have reverse shell
oof dark
why do i have you dark on 50% 
idk can i ask this but can this be a little bit simpler
aaaa about that
sry i didn't know
yes yes i know i wasn't aware im sorry
i was warned by 3 mods about that
i deleted it 2
when james explain it to me
okay it won't happen again
ree i give up
james can i look at writeup ๐
@plucky vault If you admit you lied
Hackers is not easier
And you shouldn't make statements like that without having actually done the box.
You don't have to talk bull
so i will admit but i will complete hackers just to try
i think its the same method
What is?
hang on
You're saying words with no meaning
@plucky vault Privescs are different by user.
Try to understand the process for finding the privescs
Otherwise you're just being a skiddy and copy/pasting from the writeup
so basicly i needed a script
oh
And you'd need to find the thing you exploit first
MHM
And then research that program
yah yah whatever i backoff my word cuz i thought its some geniues way but turns out it was just a cve and its just bad... and then im skid. ๐คฏ
There's more methods
also involving scripts
But you skipped all the enumeration in the writeup
All of the "looking for ways to root the box"
enumeration doesn't stop when you get a shell
You immediately should be starting to look for ways to get more privs
Read the writeup, work out how I found each vuln
wait you were actually playing ?
bruh this is like dissapointment for me and learned new stuff
yeah
The privescs section @plucky vault
Read
looking for suid etc is what you should be doing
I did like 3 koth games before two of which were with my friend and we both didn't get too far 
Suid, sudo -l, look for passwords, use that resource
foodctf room sub only
im reading
thx :)
can you explain this line ? find / -uid 0 -perm -4000 -type f 2>/dev/null
@tame ether it's not sub only
manpage @plucky vault
yah good point
yeah i just noted that
Part of the process of enumeration
Scripts like linpeas do it for you
Once you learn how to do it manually, then you can start using scripts
Then you understand what you're doing, and you're just using tools to speed up the process
can this one be done thorught browser
yeah i understand that part
but can you like first download a file and then make a shell
@plucky vault wat
hang on let me start hackers
Have fun
let me test does this stuff work there
yah well let it be today i learned something new from you smh
@plucky vault If you post the link, don't be surprised when people join
i alredy did
Yeah
well i need people to join so i can play
It's competitive now
sounds good to me ๐
also do you like my new pfp on thm ๐?
giving enemies that scary look
anyway brb i go make cigarete and go to wc
cuz this will be good
okay im back and ready
found one privesc on food :)
@tame ether Unintended?
nah, I'm doing it for the first time 
Bro. Food privsec done!
That was super easy bro๐
yeah lul
i hate privesc xD
It was literally sooo easy, and can be done in multiple ways
one of them was literally the whole theme of another room
and james is alredy king
Which room bro? I'll play that too๐
Box hardened
wdym
@plucky vault I patched the vulnerabilities
kek
wdym
I can see those POSTs
well stop looking at them
thats like evil
no no thats like next level of evil
im gonna draw graph level of evil just for you
yes ๐
Basic blue team
bruh for this 41 days i never saw you not being serious ๐
You shit-talk my box, you get whooped
I made food and hackers
ooh it's midnight already :))))
well this conv just lost it's point i guess
It's the best
HAHAHAHA\
ik that it "redirects" me lol
Whatever you're gobusting for
imma go do very secure protocol from hackback2
@plucky vault You can't gain access now
Unless you're me.
Passwords were changed, backdoor was patched
it's not completely blocked as he said it's possible to get in if you're him
you said i can't get access
which means
You're allowed to change passwords
you'd need to somehow impersonate gim
I haven't stopped services
that's what I got from it 
@tame ether You'd just need to know my password
optionalFTW 
thank god james evil level is raising
@plucky vault So again, what rule did I break?
it apears you didn't
๐
๐
@forest python do you like logs ?
every 1.5 btw
All you're doing is spamming one of several root shells that I have open
And your own
@plucky vault there's no point in you streaming this
yah good idea
but it says : explore apk
what makes you think r2 will help you with that
apk is not a binary like exe/elf files are
@livid crag Hi, everyone's asleep so I'm being quiet
No worries :)
google?
apk reverse engineering into your favourite search engine
got any good stories?
@livid crag A wonderful bird is the pelican; His beak can hold more than his belican. He can hold in his beak Enough food for a week, Though Iโm damned if I know how the helican! โDixon Lanier Merritt (often incorrectly ascribed to Ogden Nash)
Lovely.
I'm aware, thanks
that room can point you in the right direction
at least for the apk part
you can omit that and do it afterwards
;-;
maybe leave the apk alone and focus on the other flags

Goodness, it's a party in chat
well the fact you're addicted to smoking is most likely your fault 
lol

i don't know
don't think so
rip voice chat
AHHAAHHAA
Come on, let's watch it and talk about how wrong he is
ima like 70% done with initializing nessus
bruh its crashing
why.
@livid crag are you watching ?
smh no point on streaming to guys who are afk xD
holy $&@! thats still going?
hey can you help me?
SUID you vegetable
@plucky vault ||Vim was a glitch when they were trying to make the actual SUID exploit, it doesn't work even if you got an interactive shell||
elf
Mon May 18 07:57:19 2020 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
help me
openvpn error
messages me first and then says *im gonna block you


No I just came into this channel to see what is going on
me too
Very! LOL
LMAO
...


is try harder for me
Duh
Very much so @hot sparrow
the KOTH page tells that your username should be in the file
and i have placed my username in that file
but king doesn't seems to change
how you do that though
I'd rather not for the sake of competition
Are there any characters at the end of the entry in the file? E.g. white spaces, new lines?
no
Another user might be overwriting the file then.
no i was testing the same in with no user or a user who was offline
doesn't seems to work in OFFLINE Machine
while i play with other players they somehow managed theri username in that file
Dont Know Whats Happening
Right - so then you know it's working if other users can put their usernames into it
yeah other players do
Exactly
but why i can't


That's a very broad statement
Not necessarily tournaments as of yet, but we have a few popular livestreamers who host a private lobby
Koth is free to play
๐
Machines for koth are made from people in the creators programme
get into that and you can pitch your idea ๐
where is creators programme
Submit / publish a few rooms that go down well with the community and you'll be selected by the admins
๐
Bahahah I love the lolcat
huh let's see
Man, it's party in there
took me whole hour too ๐ธ
maybe helpful for elf: I watched John's Pingu room video today and found assembly, cyclic, binary things maybe... those value mean something related to that ๐ค
use nc on 7321
๐คฆโโ๏ธ
@tawny oak that's not useful if he didn't get the prev part
๐ sry! but it may be helpful!
unless someone got prev steps it's just misleading
yah im confused
wait i alredy know cirilic
i saw these alredy somewhere xD
i think im dumb?
U R DOING GREAT!
I'm here to cheer u up ๐ป
U can do it Elf! U can do it
am i atleast in the right way o.O
(STILL MAYBE MISLEADING)
elf, I think (10% sure) i got clue,
someone gave hint to check discription of room, there is a PICKLE png image, and there is also a python module named pickle
was that helpful?
yes
i think
?
hehe
i know i can use that command but like sudo ifconfig tun0 seems easyer
idk why
@plucky vault Are you... trying to interact with a non-http service using requests?
@naive nacelle I gave you the twitch streamer role. Do you do YouTube as well?
is stream down?
edit: I think Yes!
okie! but keep going bro โค๏ธ
Any hints or tricks u can recall from his video that he used completing it or anything that can be helpful (mislead + maybe time waste)
I think... It's all in our front, we just can't see them yet. There is no way John didn't just used Pickel for making this room. Something phishy is there... I'm also checking all related things right now.
What happened now Elf?๐
Aaa my pc crashed
....
I cant stream tonight 2 many technical issues smh...
Lmfao
Nothing's in here
Yeah im in bed just started watching ๐ thanks for hints you are really awsome
@tawny oaknoted lol ๐
Kitten @wise mortar
@tawny oak xD
really sry elf, I was gone for lunch! but I recorded everything to watch later
and now.... I'm back!
so... did u tried passing whole 01010101 raw file for unpickling?
(most suspecious)
did u tried raw hex converted file to unpickle
maybe? we should try evreything na?
yah im doing that xD
@plucky vault try re-decoding the 0/1 to the pickle file with this, I think you might have some bad chars inside:
cat creds | perl -lpe '$_=pack"B*",$_'>creds.pickle
this one works tho
told ya :)
๐น hmmm... that was simple!
im eating lol xD
lol, then eat, don't stream! and peacefully go school!
noice!
fun fact: im eating pickles
๐น lol, don't eat them! they r extremely difficult (in a way ๐ )
can't think (i do remember 1 thing, but let me find)
@Dark Thank you! No youtube :)
https://tryhackme.com/room/25daysofchristmas
Task 14 [Day 9]
maybe something similar
maybe
nope
my class starts in 6 minutes guys
i will see you in like 1 hour or maybe 1 and a half
go to class :)
yes i go to class xD
@plucky vault pls automate that, it'll be a good python excercise :)
eh
i mean... it kinda works
xD
it just needs a little bit
of you know
fixing
xD
ooo i came up with a great idea
@tame ether ๐
what did I missed? ๐
xD
high quality pickles :))
yes
who where
@plucky vault Netcat -e VERY VERY VERY rarely works
Don't trust it
@plucky vault nc -e only works for a certain version of netcat
On ubuntu, you will practically never have that version installed.
๐ฆ
@plucky vault Learn how to use SSH keys.
They make upgrading the shell super easy if SSH is installed
Yes, SSH keys.
@plucky vault Don't copy paste commands reee
Learn how to use.
man ssh-keygen @plucky vault on your host
I mean I have 3 commands saved that get you a better shell
/home/dill i think
Mind: I need a better thing than ls -la ๐ค. I should Google it.
Elf: ls -la but BETTER.
im not in dill
@plucky vault Why sudo ssh?
That's a terrible idea
Stop running code as root when you don't need to
i forgot the command ๐
you also forgot something
wait i think i got it
I wonder what failed to decode base64 could mean
u nice giving hints Ninja 
Just saying... :smh:
OMG! ๐น
carrots don't grow on hills
i think?
oo i got something
@west sphinx wow you are typing really fast ๐
@plucky vault Read the room description
@plucky vault ls -lah in the folder of the exe and tell me what the file type is
also file is a great command
It's not a bash script, I'll tell you that
You didn't do that in the folder
Still going with Peak Hill?
@tawny oak Yea, it sucks
I think john intentionally made it harder
๐
yeah
Honestly, it's the only non hidden file in the dir
Quick way to cat it
use bash stuff
:)
๐ธ okay!
@plucky vault SEE, even I got root! u can also do it!
ps: u actually taught me python and pickle little little bit to solve this room! and yeah BASE64 does work!
is there a stupid (blank space) before the file?
I think using / / / / / something can access it?
or is there something different? @forest python
@tawny oak If you understand
There's not a blank space
I tried cat " root.txt"
I think zero width chars
u can do it ELF!
wow well thats nice to know ๐
keep up
but im still stuck lol
You were looking at the right things
hm
ninja, can i scp whole folder to my local system and just open it with gui
i don't remember what i was looking at ๐
lol ELF!
and now i forgot how to use tmux xD
I don't use tmux very often
Good afternoon
gm @tardy beacon
Shows us the creds @plucky vault ๐
wdym
Your login creds to THM๐
i didn't block anybody?
Your screen shows you blocked Horshark
Straight in with the tag
no fr i didn't know i blocked hem
Lmao no worries
sry again xD


:D
See y'all later folks :)
well gl ๐
@west sphinx plz mute your mic if you're not talking
i liturally still don't understand
not yet :jo:
@plucky vault that looks promising
Although
print "something" might indicate something to you
@forest python room completed!
i just cat-ed whole folder
cat /*
๐
It was in my mind whole time, I just didn't tried it
thankz ELF! ninja, szymex, etc!!!
โค๏ธ
I'm still watching u elf! ๐
@tawny oak cat * is what I did
this is riveting
sudo /opt/....that stupid file
send commands in base64
that's all bro, u already reached there!
legit is your monitor like 144p
no here let me show you my monitor
fair enough
omg
i think ELF is exuasted and can't think straight!
relax for min or two



are u going to play KOTH?

@robust zinc