#voice-chat

1 messages ยท Page 7 of 1

tawny oak
#

and get back again!

plucky vault
#

i mean a little rest works i guess

tawny oak
#

3min break will be good

tame ether
#

@plucky vault leave the box, do something else to clear you head and attempt again in few hours

plucky vault
#

noo if i give up then i lose

tame ether
#

??

plucky vault
#

i go get more coffee

tame ether
#

is there a bet that i don't know about?

#

๐Ÿ˜

plucky vault
#

yeah im playing vs my self btw

tawny oak
#

u never lose! that's beauty of Try Hack ME!

u always learn!

forest python
#

@azure moss plz mute if you aint gonna talk

#

If that's you talking, you're real quiet

azure moss
#

Opps! Sorry!!

forest python
#

@lean musk Neeee nawwww actually

#

Elf

#

Have you given up?

tawny oak
#

No! he cannot

#

I WILL NOT LET HIM!

#

He can do it!

#

๐Ÿ”ฅ

plucky vault
#

ok im back

#

aa no give up

#

now im ready

drowsy pollen
#

you should have done the room yesterday, it was easier before the program was moved ๐Ÿ™‚

plucky vault
#

wdym moved]

drowsy pollen
#

it used to be in the user's dir, so you could just replace and get root that way

forest python
#

@lean musk I can only speak for the first year lmao

tame ether
#

there were two ways to bypass it

drowsy pollen
#

really? what was the second one?

tame ether
#

you could just remove/replace the file

#

but when the folder had root perms

#

you were still able to rename it

#

and make a dir with the original name and a scriptof your choice

plucky vault
#

im so confused

#

jesus can pls look at writeups...

full sapphire
#

Where's the fun in that?

plucky vault
#

okay no writeups

tame ether
#

you said it yourself you don't want to look at them

plucky vault
#

yah i don't

#

but i feel the fire rn

forest python
#

@lean musk I have to be quiet, my dad's working on a conference call on the room over

#

So I can't talk properly

#

@real orbit reee you said RSA not EC crypto

tame ether
#

there are two live but you'll have to make a deep dive into the internet abyss to find them because iirc they're still not approved

forest python
#

Most of the stuff is EC Crypto now I think

plucky vault
#

yes

#

i forgot username ๐Ÿ˜‚

#

im gonna look at the writeup...

#

i can't this is going nowhere

#

well nwm there is nothing to look at ๐Ÿ˜‚

tame ether
#

wdym "nothing to look ap" thonk

plucky vault
#

see

tame ether
#

John hasn't accepted them and I don't expect them to be accepted ver ysoon

plucky vault
#

well then i have a full day ๐Ÿ˜„

forest python
#

@plucky vault ||you found stuff about pickle vulns when you deserialise user data||

plucky vault
#

ty

#

smh

#

smh

#

im gonna go to play other room

tawny oak
#

goobye @plucky vault going for rest! done a lot today with U! ๐Ÿ˜˜

plucky vault
#

i can't even deploy other room

#

@tawny oak bye ๐Ÿ˜„

#

well i can't even deploy other room

#

so i guess no giving up

#

smh

#

im starting to question my self

forest python
tame ether
forest python
#

Big Red Box

tame ether
#

i do that everyday

tawny oak
#

RIP

#

F

#

See U Elf!

plucky vault
#

Man this is so bad.
.

#

Hope my pc doesnt catch on fire

#

ooo wait

#

so i have to pickle to code

#

@forest python i think it buged out

#

oh nwm

forest python
#

wat

plucky vault
#

sry for ping

#

omg it works

#

thank you โค๏ธ

#

thanks alot

#

so basicly

#

i was doing it wrong the whole time

forest python
#

yes

#

pickle deserialisation vuln ezpz google

plucky vault
#

i feel unstopable now

tame ether
#

try inoculation Kappa

plucky vault
#

aaa im doing it

#

what do i have to do here

tame ether
#

no helping here

#

this is a hard room for big boys :)

plucky vault
#

aaa okey

weary grove
#

Do anthem i wanna see ya struggle kekw

plucky vault
#

so from what i understand

#

i need to give it webhook

#

idk what to do ๐Ÿ˜‚

tame ether
#

but you were unstoppable ๐Ÿ˜Ÿ

plucky vault
#

ah yes and now i will do some research on that webhook thing

#

to see how i can exploit it

#

not gonna give up ๐Ÿ™…โ€โ™‚๏ธ

#

hang on i go put coffee

azure moss
#

Isn't that from a tool album?

plucky vault
#

i dunno

#

๐Ÿ˜‚

forest python
#

@west sphinx Unless you join voice, we can't unmute you

crude void
#

but elf are you using a VM or linux bare metal on the pc

plucky vault
#

@crude void linux bare metal

crude void
#

ah ok

civic wedge
#

nice wii

crude void
#

yes

#

epic wii

plucky vault
#

this doesn't want to change

#

SMH

crude void
#

hmm strange

plucky vault
#

now there is a bigger problem

#

i can't minimse stuff

#

smh i go restart

#

aaa some ifixing yk

#

even rooms can't load

#

oh nwm

#

this is so bad..

#

i thought its good tho

#

this Desktop is legit so wierd

plucky vault
#

smh im liturally stuck

tame ether
#

it hurts me so much that you're overcomplicating this script FeelsBadMan

plucky vault
#

even more hurts me when i see that i forgot how _thread module works

#

it works

#

uh wait

#

how do i ctrl + v in terminal

tame ether
#

check the keybind section in settings

plucky vault
#

this is..

#

idk how to do this..

tame ether
#

make a script

#

duh

fast wind
#

i cant even tell if you are trolling at this level

tame ether
#

he's not, that's the worst part

plucky vault
#

aaa

#

what is trol

#

im elf sry

fast wind
#

you need socks

plucky vault
#

no no no

fast wind
#

please your role says GURU, pls don't do this

tame ether
#

i have no idea how he got this high tbh

fast wind
#

unless both of you are trolling me now lol

full sapphire
#

Good grief, sort your variable names man

tame ether
#

@fast wind if you tuned in to his every stream it's like that non stop

fast wind
#

its my first time discovering my eCrying abilities

full sapphire
#

Unfortunately, ranks are decided by points alone...

fast wind
#

atleast he can type fast.

#

(JK)

tame ether
#

well, at least the contributor/bug hunter ranks aren't kekw

fast wind
#

lol

plucky vault
#

elf.

fast wind
#

oh boi oh boi oh boi

plucky vault
#

elf.

#

it works

fervent marsh
#

beautiful code

plucky vault
#

yes yes

#

thank you xD

fervent marsh
#

variables couldnt have been named better

plucky vault
#

nope they are getting best they can rn

tame ether
#

i can't watch this anymore

plucky vault
#

why no

tame ether
#

my eyes hurt

#

overcomplicating, the variable names

fresh solar
#

What room is he doing?

fast wind
#

create a while loop to receive data, (variable.decode('UTF-thingy) then copy it to a variable, use negetive indexes to decide what to send,

#

FFS

#

What room is he doing?
@fresh solar no idea

plucky vault
#

aaa

full sapphire
#

Now that is worrying

plucky vault
#

thats called

#

talent

fresh solar
#

@plucky vault What room are you doing?

tame ether
#

webgramming

#

task 2

fresh solar
#

Ah

full sapphire
#

Jesus Christ fix those variable names

fresh solar
#

That room has quite a few broken tasks

plucky vault
#

i can agree

fresh solar
#

Task 2 is not broken ๐Ÿ˜›

plucky vault
#

ok just watch

#

now i will finish it

#

with eeasy

fast wind
#

dont connect again!

#

ln no. 10, 11 dont

plucky vault
#

im elf

#

i legit think im dumb

modest spruce
#

what is your elo @weary grove

#

?

weary grove
#

g2 i think this season

modest spruce
#

good, in US server?

weary grove
#

nah eune

#

had this account since s1

#

any champs you want to see me playing kekw

modest spruce
#

hmmm ezreal

plucky vault
#

ooo eune ? ??

weary grove
#

ye

modest spruce
#

Europe

plucky vault
#

i play on eune 2

#

and played

weary grove
#

i'll go for a cigarette

plucky vault
#

lol

weary grove
#

?

modest spruce
#

nice skin bro

weary grove
#

Got like 426 i think

modest spruce
#

426 rp?

#

or in hextec chest?

weary grove
#

skins in total ๐Ÿ˜„

plucky vault
#

what rank

modest spruce
#

nice

plucky vault
#

ooo he is going ap ezrael

#

thats op

modest spruce
#

yes, so broken

#

soraka saved u

plucky vault
#

oof

#

2/2/1

modest spruce
#

i go to sleep bros, bye

plucky vault
#

lol they are diving so much

weary grove
#

he's playing ap lee

#

he's shields are busted

plucky vault
#

lee it self is broken in urf

#

0 suprise...

#

lol randomly rolling who to honor ๐Ÿ˜‚

weary grove
#

shitty game haha

#

yeah, the ones that fed less

#

408 not 426

plucky vault
#

xD

#

still so many skins lol

weary grove
#

i'm playing since s1

plucky vault
#

you bouth eternals 2 ?

weary grove
#

nah just 1

#

i might buy the whole pack

plucky vault
#

oof. its better to buy whole pack tho buying 1 per 1 is really not worth it

weary grove
#

5.8 k rp for all it's not bad

#

well you got 5.8k for all

plucky vault
#

yeah

#

and i think 1 costs 500 rp ?

weary grove
#

600

#

it says there

plucky vault
#

yeah i see

weary grove
#

so after you buy 10 characters you are spending more on eternals

plucky vault
#

better buy full pack ๐Ÿคทโ€โ™‚๏ธ

weary grove
#

yeah

#

cheaper

#

i got all the league games, so i do play runeterra and valorant

plucky vault
#

ooo valorant

weary grove
#

yea

plucky vault
#

wait legends of runeterra?

weary grove
#

yeah

#

the cards game

plucky vault
#

yeah ik

#

not really into that type of games but its good ig ๐Ÿ˜† can't wait for wild rift tho

weary grove
#

you can sign up for beta

#

but i wasn't lucky for any of them

#

neither TFT or runeterra

plucky vault
#

me neither i signed in when i heard about it

weary grove
#

I also play warframe

plucky vault
#

wow

#

i played that when it appeared on steam store ๐Ÿ˜‚

#

but i was having so bad fps .... so i delted it

#

cuz my pc is potato smh

#

not sure what year was it when it came out... i think it was 2016 or 2017

weary grove
#

It got 10x better now

plucky vault
#

i mean if i can get better fps i will certanly play it ๐Ÿ˜‚

#

i also remember it has a story about some aliens and stuff

#

it reminded me alot of destiny

plucky vault
#

its quite confusing...

#

what os are you using

#

distro*

#

pop os

#

o

#

but not gnome

#

i don't remember what is the thing exactly

#

i have gnome

#

and other theme instaleld as well

#

so i can just switch in login ...

#

ah ok

forest python
#

@plucky vault apt install neofetch and show us a neofetch

#

LXQt @plucky vault

plucky vault
#

ah

#

let me guess

#

i have to use burpsuite for this one?

#

aaaa

forest python
#

Elf

#

This is painful to watch

#

@plucky vault What about directories inside the directories?

#

Randomly installing software aint gonna help

#

Image data often gets detected as ZLIB data

#

You're going to get nonsense out @plucky vault

#

You're actually causing me pain

plucky vault
#

okay i stop

#

lol

forest python
#

@plucky vault I wouldn't be that blatant with a hint

plucky vault
#

aaa

#

okay

#

hang on

forest python
#

You fall down rabbit holes that aren't even there

plucky vault
#

xD

#

im preety lost

forest python
#

You found a dir

plucky vault
#

yeah

forest python
#

maybe there's more

#

/dir/moreStuff

#

Learn what a placeholder is

#

JFC

plucky vault
#

i alredy tried that

forest python
#

@plucky vault A placeholder is an example value

#

Like I'm not going to tell you the name of the dir

plucky vault
#

wait that exists

forest python
#

@plucky vault What

#

It's a general concept

#

Not for the CTF

full sapphire
#

You fall down rabbit holes that aren't even there
Impressive...

forest python
#

@full sapphire It hurts

#

So bad

#

Please send help

full sapphire
#

I think I'mma go back to my dev work...

plucky vault
#

๐Ÿ˜ญ

forest python
#

@plucky vault Why did you stop as soon as you found the directory?

#

Explain to me that.

full sapphire
#

What in God's name are you doing?

forest python
plucky vault
#

wdym as soon as i found directory

#

oo

#

nwm im still lost

forest python
#

@plucky vault You found a folder

#

The folder renders a page

#

There can be more things there

#

@plucky vault Wow.

#

You can move on

#

You know a placeholder is an example

full sapphire
#

Why are we looking at the definition of a placeholder?...

forest python
#

@full sapphire because I said the word and he thinks it's a hint

full sapphire
#

๐Ÿคฆโ€โ™‚๏ธ

forest python
#

You found a folder @plucky vault

full sapphire
#

Right, with that, I'm out ๐Ÿ˜

lyric horizon
#

lol an Arrow based box

forest python
#

There can be things inside the folder.

plucky vault
#

so i found a folder

lyric horizon
#

is this like a puzzle where different html pages go to different things?

plucky vault
#

and i don't even know where ๐Ÿ˜‚

forest python
#

A directory

#

Maybe look for more things inside the directory

#

@lyric horizon This is a SUPER basic CTF style box. That Elf is massively overcomplicating

lyric horizon
#

o

forest python
#

@plucky vault How did you find the first directory?

plucky vault
#

aa gobuster

forest python
#

@lyric horizon Elf ain't the person to watch

#

@plucky vault So, so what does gobuster do?

plucky vault
#

find directories

forest python
#

Ok, so what if you have a directory inside a directory? How'd you find that?

plucky vault
#

gobuster -w big.txt -u <ip>/first_directory/

#

i did

forest python
#

You did a shitty job

#

dirbuster 2.3 medium

#

Use that wordlist

plucky vault
#

i don't have it ๐Ÿ˜‚

#

this is suposed to be medium ?

#

smh 220k

#

that won't load till tommarow

#

nwm

forest python
#

@plucky vault Check the question page

plucky vault
#

xD

forest python
#

Ok, now look at it

#

Ignore the moving pictures @plucky vault

plucky vault
#

yeah this is what i like to call

#

progress ๐Ÿ‘

forest python
#

@plucky vault PLEASE learn how to use gobuster

#

Otherwise this room will be hard for you

#

Very hard

plucky vault
#

ah jeez again ...

forest python
#

@plucky vault When you have .something with computers, there's normally two meanings

plucky vault
#

ooo

#

i didn't think about that

forest python
#

@plucky vault You didn't think.

plucky vault
#

wdym xD

forest python
#

Like at all

#

That was close

plucky vault
#

so this is good?

#

hang on i go put water for coffee and make cigarete

forest python
plucky vault
#

ok im back

#

damn @silk tiger

#

@silk tiger i enjoj everything i can learn

forest python
#

@plucky vault Start again

#

Remove the recipe bits

#

@plucky vault Drag the magic elements back to the blue bit

#

No

#

No

#

No

#

BAD

plucky vault
#

@silk tiger CEH worth it? I have no prior experience and want to get a cert worthwhile

#

this is so confusing

#

yeah

forest python
#

@plucky vault You had the username

#

You skipped some chars in the password

#

@plucky vault You skipped the chars again

#

JFC

#

@plucky vault .other_user looks interesting

silk tiger
#

@plucky vault CEHv10 is certainly worth it. Its great on resume

plucky vault
#

yes im doing that

#

i think

forest python
#

@plucky vault Skim read

plucky vault
#

@silk tiger is it entry level? or should I do stuff like eJPT

forest python
#

You look for names etc

#

Names, passwords etc

plucky vault
#

im looking for that but also reading ๐Ÿคทโ€โ™‚๏ธ

forest python
#

Skim reading is a general term

plucky vault
#

@silk tiger

silk tiger
#

@plucky vault

plucky vault
#

is CEH entry level or should I do stuff like eJPT @silk tiger

forest python
#

@plucky vault You downloaded images

#

Look at the images?

plucky vault
#

oh

#

didn't think of that

forest python
#

@plucky vault it's an image

plucky vault
#

okay

#

steghide

forest python
#

Like. Damn.

plucky vault
#

ty

#

yah first thing that comes to mind is strings binwalk

#

exiftool

forest python
#

Bless or ghex are hex editors

#

You can edit the files in hex

plucky vault
forest python
#

IQ? Under 5.

plucky vault
#

Big Brain Time

#

whats the name of the box?

forest python
#

@plucky vault Extract.

#

@plucky vault Lian yu

plucky vault
#

I will try too

plucky vault
#

aa i will go afk for like 5 mins in the meantime can someone explain me how to download an image if its corupted?

tame ether
#

what tools does terminal have to download files?

plucky vault
#

curl

#

python

#

python and curl

#

xD

tame ether
#

๐Ÿคฆโ€โ™‚๏ธ

full sapphire
#

Uh...

plucky vault
#

can u try steghide --extract --sf thm.jpg and use that pass, it seems there is a hidden file

#

hello

#

my username on thm should be renamed to team work kekw

#

the image on task 1 of challange has another hidden file

#

see you ๐Ÿ˜„

silk urchin
full sapphire
#

@silk urchin that'll only work with pwfeedback enabled -- which isn't by default, and isn't on Madness, if that's what you're referring to ๐Ÿ™‚

#

Madness privesc is an easy one

silk urchin
#

@silk urchin that'll only work with pwfeedback enabled -- which isn't by default, and isn't on Madness, if that's what you're referring to ๐Ÿ™‚
@full sapphire yep

tame ether
#

you just need to know what you're looking at though kekw

plucky vault
#

im legit stuck

#

in priv esc

#

again.

#

brb i go find cup for coffee

silk urchin
#

check for binaries that calling others with non-absolute paths

#

the screen.old seems interesting, has suid too

plucky vault
#

im back

#

yeah it does

#

idk what to do with it

#

xD

#

ty for help guys ๐Ÿ˜„

#

im gonna go in bed for like some time to chill since i have to go to work in 1 hour lol ๐Ÿ˜‚

#

this was fun tho :jo:

#

nice session ! thanks

#

thanks for help ๐Ÿ˜„

#

see you guys tommarow i guess ๐Ÿ˜„

serene veldt
#

hi

tame ether
#

@plucky vault what room are you doing this time?

plucky vault
#

idk still thinking of what to play

#

@tame ether im doing willov

full sapphire
#

Oh God

#

This should be good ๐Ÿ˜

plucky vault
#

lol

full sapphire
#

Why would that be Base64?...

plucky vault
#

cuz idk what is it ๐Ÿ˜‚

full sapphire
#

Not Base64...

#

I mean, it's technically a base?

#

Oh my God -- how the hell did that work?

plucky vault
#

i don't know ๐Ÿ˜‚

#

google is my friend ๐Ÿ˜„

full sapphire
#

"google help me please find cyber something has magic github"

#

Google is incredibly tolerant

plucky vault
#

yeah he is smart guy

quiet needle
#

google's a dork

plucky vault
#

xD

quiet needle
#

aah discord video makes laptop fans go brrRRRR

full sapphire
#

You know I screenshot that every time you say it Elf?

plucky vault
#

say what ?

#

๐Ÿ˜‚

quiet needle
#

we've got a channel for it

plucky vault
#

@plucky vault whats up

#

really bad

#

im kinda stuck with these wierd numbers

weary grove
#

there's something wrong with your left phalange @plucky vault

#

you need to fix it asap

plucky vault
#

i don't even know what that means ๐Ÿ˜‚

full sapphire
#

Right

#

So, we have a winning strategy here

#

Use big words, he'll go Google 'em for ten minutes

plucky vault
#

basicly yah

weary grove
plucky vault
#

clearly working

#

reee

#

Look for the excessively long videos

weary grove
#

pink fluffy unicorns dancing on rainbows

plucky vault
#

i legit don't know what is that

fervent marsh
#

you got too many viewers elf, better dont choke now

plucky vault
#

the pressure is on

#

its some machine

#

jesus

#

thats alot of people watching me blame

weary grove
plucky vault
#

xD

drowsy pollen
#

hmmm, maybe i should be starting my google searches with hey google tell me

plucky vault
#

@drowsy pollen desi brate ๐Ÿ˜›

drowsy pollen
#

sorry, i don't speak elf

plucky vault
#

lol

weary grove
#

check the video i sent you it will help you @plucky vault .

full sapphire
#

Heh, he's got somewhere

plucky vault
#

hang on xD

full sapphire
#

Now for the Crypto...

#

YES!!!!

weary grove
#

you sir. go back in your box

full sapphire
#

Also, Chev

weary grove
#

both of you

full sapphire
#

Did you really rickroll the poor sod?

weary grove
#

as you can see

full sapphire
#

Vim > Nano

weary grove
#

nano > vim

#

it was the easiest way to do it

full sapphire
#

sudo Vim > * && sudo passwd

weary grove
#

sudo apt uninstall vim

#

cry me a river, lol

#

i'm a simple man

full sapphire
#

Better yet: sudo Vim > * && $pass=$(head /dev/urandom | sha256sum | base64 | head -c 32) && (echo $pass; echo $pass) | sudo passwd && unset $pass

plucky vault
#

d2FubmFfYmVfZnJpZW5kcz8=

full sapphire
#

Beat that Chev

#

Also, No using sudo without the password ๐Ÿ˜›

#

Elf for the love of God use proper variable names

#

Eh, keep it PG13 -- point is valid though ๐Ÿ˜†

plucky vault
#

aaa help me ๐Ÿ˜ฆ

full sapphire
#

Np ๐Ÿ˜„

#

And not a chance -- this is hilarious ๐Ÿ˜

plucky vault
#

it really isn't ๐Ÿ˜ฆ

full sapphire
#

Your choice to take on Willow

plucky vault
#

but heey i got a full night ๐Ÿ˜‚

full sapphire
#

She's a strong personality

#

inb4 I make the writeups private...

plucky vault
#

hes already looking

full sapphire
#

That explains a lot...

plucky vault
#

cXVpdF9zbW9raW5nXw==

full sapphire
#

Why base64 encode it?..

#

I mean, if the FBI can't decode base64...

plucky vault
#

ok im back

full sapphire
#

Which, uh, no one can decode...

#

Elf, if you start coding properly, I might give you a hint

#

Also tmux

drowsy pollen
#

looks like he has a general idea of what python code looks like ๐Ÿ™‚

plucky vault
#

no

#

@full sapphire no code properly imma give you pain haha

full sapphire
#

Have you seen those variable names??

#

Try it, kiddo ๐Ÿ˜

plucky vault
#

mfw muirland has a writeup

full sapphire
#

Muirland made the room

drowsy pollen
#

strimmer noticed me

plucky vault
#

muirland thus you are disqualified

full sapphire
#

๐Ÿ˜

plucky vault
#

wait thats all in one ?

full sapphire
#

Why d'you think I'm watching

#

This is hilarious

plucky vault
#

its even more funny with the writeup up

full sapphire
#

Heh

#

I really should be getting on with this tutorial...

#

This is so funny though

plucky vault
#

this is a question of habit

#

am i dumb?

full sapphire
#

You said you were ten minutes ago

#

So, given that came from the source

#

Probably

plucky vault
#

aaa explains aalot

#

oh this looks like it will take maybe a slight bit based on where you are

#

okay so thats solved

#

what to do now with that string

full sapphire
#

Uh

#

Did you just re-encode that?

plucky vault
#

LOL

full sapphire
#

There yah go

plucky vault
#

muirland about to remove all of them

full sapphire
#

I don't need to pwn it ๐Ÿ˜†

drowsy pollen
#

how tf do those searches keep working...

plucky vault
#

@drowsy pollen me and google love each other

#

aaa facebook yes

#

i did

#

idk how to convert it ..

#

im legit lost

#

in

#

numbers

#

wdym multiply

#

SMH

drowsy pollen
#

nice, he finally figured out it's chinese

rough flax
#

What the heck is happening

plucky vault
#

@drowsy pollen omg stop trolling me

drowsy pollen
#

but this is so much fun

fervent marsh
#

this is hilarious

plucky vault
#

i legit don't know what to do

full sapphire
#

I can promise you

#

It ain't Chinese

plucky vault
#

i trust you

#

xD

drowsy pollen
#

spoilers ๐Ÿ˜ฆ

full sapphire
#

I made the damn thing!

rough flax
#

lmao

plucky vault
#

cuz

#

when you decode the hex

#

its clearly saying its rsa key

#

which is not chinese?

fervent marsh
#

you never know

#

new rsa key standard

plucky vault
#

yah

#

bruh

#

this is 2 much 2 read

#

i was reading it

#

and then i forgot where i left off

#

so just left that thing

#

xD

#

ppl don't need to know that btw

#

omg coffe

#

i forgot

#

brb

#

ok im back

#

and we saved coffe

#

jeeez this is hard

fervent marsh
#

@plucky vault gl with your sanity man

plucky vault
#

oof

#

๐Ÿ˜ฆ

#

gn ๐Ÿ™‚

fervent marsh
#

ill give the room a try myself tmrrw, although based on how you're dealing with it im not looking forward to it

plucky vault
#

xD

#

i don't love ciphers

#

or privesc

fervent marsh
#

i know nothing about ciphers really, so gonna be a lot of reading

plucky vault
#

what ever it is

#

i don't know

plucky vault
#

smh im gonna look at writeup

#

im streaming for 2 hours and this is going nowehere..

#

@full sapphire you are evil.

full sapphire
#

I am

plucky vault
#

smh i wasted 2 hours on something i don't have..

#

im just gonna leave that room since i checked the write up smh

fervent marsh
#

oof

rough flax
#

Aww muir is all alone in the general voice

full sapphire
#

Muri ain't watching

torpid hollow
#

check now pls

rough flax
#

can @plucky vault check this out possibly looks like spam itโ€™s been in multiple channels

plucky vault
#

@rough flax what's up

rough flax
#

mouadjg keeps posting whatever that is in multiple channels I donโ€™t want someone to go to it more than likely malicious

plucky vault
#

@torpid hollow please stop posting suspicious links

#

im gonna check it for the good of compunity

rough flax
#

thatโ€™s not smart

plucky vault
#

yeah well i just did

#

its some sport shoe shop

rough flax
#

thanks pars

plucky vault
#

it has a nice design tho

gaunt thunder
#

i thought it was vigenere too but it may have multiple steps of decoding

wise mortar
#

my internal guess is vigenere

midnight fern
#

smh

#

maybe I'll do something thats not ciphers

#

I'm not the biggest fan of them.

wise mortar
#

yeah same

gaunt thunder
#

^

wise mortar
#

yikes

gaunt thunder
#

its really annoying lol

wise mortar
#

you know, just tryharder

#

@midnight fern replace all the repeated lines with nothing and see whats left

#

wooo

gaunt thunder
#

maybe try sonic visualizer if its an audio

wise mortar
#

^

midnight fern
#

I don't have it

#

I have another tool, just need to find it.

gaunt thunder
#

you should give it a try sometime

pure swallow
#

audacity should work fine too

midnight fern
#

I'll install it

wise mortar
#

i tend to use audacity more often

pure swallow
#

spelled it right, almost ๐Ÿ™‚

gaunt thunder
#

im out guys take care

fervent marsh
#

that beeping scared the hell out of me

pure swallow
#

i expected something that went through minimodem

#

wow those were easy

midnight fern
#

Yeah so far

plucky vault
#

@midnight fern type png wikipedia and there is the magic hex

midnight fern
#

I got it

#

Thank you

pure swallow
#

ocr ftw

#

true, but no manual typing x)

plucky vault
#

i think radare2 ?

#

xD

wise mortar
#

ha

plucky vault
#

i think thats hex

midnight fern
#

Yeah not my thing

#

Not doing that either

plucky vault
#

im on my alt about to replay advent of cyber

#

im gonna go gl 0day ๐Ÿ˜„

valid night
plucky vault
#

echo "base64 thing" | base64 -d

#

@marble cape im making assembly room 2 ๐Ÿ˜‚

#

but but its still just an idea

#

also i was doing some research and found that there is no room about sqlmap

#

so yeah maybe gonna make that 1 first cuz atleast i know a little of usage for sqlmap

real orbit
#

lmao James

#

@marble cape neither is formatting RSA private keys, but you still did it kekw

#

James, you don't always have to follow the rules

plucky vault
#

im doing great

#

it is 18pm and i haven't eaten since 9pm yaster

#

i did drink tons of cool stuff like coffee,coca cola,coffee,energy drinks... and much more stuff like that

#

@marble cape can i play with you guys ?

#

does it need credit card?

#

when im buying off paypal

lofty moat
real orbit
#

my twitch prime sub goes to lilypichu

plucky vault
#

if i start youtube i steal all the views

#

lets say im recording a video and upload it do flags need to be removed?

#

im gonna go record a video.

lyric geode
#

does this help?

silk tiger
#
$ cat jwt.john 
eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJ1c2VyIjoiYXNkZiJ9.GwJ7_ZrnpRLXXSBYzB9VkM4n7j2iSJEkdjhckeaXQ-U
$ john jwt.john
# Wait a few hours, then:
$ john --show jwt.john
plucky vault
#

nwm i give up

#

making vidio is hard... im 2 dumb to make a good video alone

barren wave
#

what is a good flight simulator for PC ?

#

@silk tiger any suggestions?

waxen cave
#

Microsoft Flight Simulator, but honestly the new one is going to drop any day now.

#

So if you're looking for one, may just hold off a bit longer until it's released.

lean musk
#

P3D is decent, but also hella expensive

waxen cave
#

X-Plane is evidently good too, but expensive from my understanding.

plucky vault
#

hey mayor that game you are playing seems nice is it free?

lean musk
#

583311337

waxen cave
#

It's not free. But not super expensive either. Nite Team 4.

plucky vault
#

does it teach anything ?

waxen cave
#

Importance of enumeration. A lot of OSINT stuff.

barren wave
#

can you export http objects to find the flags?

plucky vault
#

does it have campaing

waxen cave
#

It has a campaign, yes

silk tiger
#

@barren wave im not sure exactly what you are working on but yes you can many ways. wireshark, tshark, pcap, etc..

barren wave
#

watching 0day's stream.

lean musk
#

tshark -r nssal-capture-1.pcap -T fields -e ip.src -e dns.qry.name -R "dns.flags.response eq 0 and dns.qry.name contains google.com"

barren wave
#

tshark | sed -e 's/.tryhackme.com//'

plucky vault
#

@wise mortar yes site is down ๐Ÿ˜ญ

#

can i complete jack ?

mellow frigate
#

it's so quiet in this voice chat....

#

it can be better to sleep in order to stay productive

#

oh, so i'm not hacked, it's discord feature

#

why?

#

sure, stream it

#

CMesS

lofty moat
#

use search wordpress user role in metasploit?

mellow frigate
#

hi

lofty moat
#

Hello from the other side

mellow frigate
#

gj

zenith cradle
#

@hot cloud

mellow frigate
#

why do you have all theese folders with thm tasks?

#

sort -u?

zenith cradle
#

smb://

#

@hot cloud enum4linux

lofty moat
#

0day was doing the same room earlier.. btw hello too

#

0day have you tried SixSiege?

midnight fern
lofty moat
#

Looking at writeup doesn't count

marble cape
#

Now I haven't seen that name in quite a while @quartz birch

midnight fern
#

Looking at writeup doesn't count
@lofty moat Who?

#

0day have you tried SixSiege?
@lofty moat No I have not.

buoyant lichen
#

keep your language civil, please

forest python
#

@silk tiger Hey, keep it legal.

#

Pretty damn fraudulent, not paying your AWS invoice

azure moss
#

That is very dodgy

#

They'll catch up eventually im sure

mellow frigate
midnight fern
#

He uses it for Pentests

#

he said this in Voicechat.

lyric horizon
#

What's goin on?

#

What are we doin

wise mortar
#

having a party, your not invited

mellow frigate
#

alright, i'll go to sleep, cya, gl

drowsy pollen
#

wow, writing actual classes to get code execution with pickle

lyric horizon
#

Rude

drowsy pollen
#

gonna suck when this fails fue to missing newline

silk tiger
#

@forest python I have kept it legal, I was mentioning that there are people who do fully abuse the aws stuff and leave without paying, etc.. not me my friend ๐Ÿ™‚

quiet needle
#

Wait what

#

m5dn.24xlarge??

#

Isn't that like ยฃ2k plus monthly ๐Ÿ˜‚

#

Dude that's insane amounts of money @silk tiger

silk tiger
#

Ehh, something kinda sorta. I frequently adjust the server plan as I mainly use AWS for alot of dev and experimental based stuff

quiet needle
#

But you're installing Kali on it?

#
  • MSF and nexpose on the windows one
silk tiger
#

I cant tell you how many times a week that I stand up and down VMs with every OS lol. That Kali instance will be for shits and giggles but will host a Metasploit Pro environment and the windows box will host the Nexpose environment for some 'stuff' you could say.

#

I always do all my work on VMs vs locally. Significantly faster. Maybe 5% of what I do is locally.

tame ether
#

runescape kekw

alpine ember
#

crab genocide anyone

#

got two whips earlier so have to train up to use it

rapid shore
#

Has anyone written a PenTest Report in here that can answer a question for me?

buoyant lichen
#

you can just ask your question

zenith cradle
#

@edgy musk aye

edgy musk
#

WHats up

fast wind
#

๐Ÿ˜†

plucky vault
#

?

midnight fern
#

@tame ether What is wrong here?

#

Do I have to reinstall PowerView

tame ether
#

uhm i have no idea tbh, powershell isn't my thing

void fable
#

is it ok to join the stream here?

midnight fern
#

yes

rare pollen
#

@midnight fern whatโ€™s your problem?

midnight fern
#

What problem would I be having at 3:06am

#

@rare pollen

buoyant lichen
#

0day's problem is that he is too perfect

lofty moat
#

too perfect to exist

weary grove
#

What problem would I be having at 3:06am
@midnight fern life is meaningless yet we try to make it count and have a purpose. let that sink in..

white vessel
#

hi

pastel grove
#

Hey Guys

fast wind
#

Sup?

fiery bolt
#

How can I join the voicechat?

tame ether
#

double click the general

fiery bolt
#

ho lol ...

#

my discord ui is all bugged

#

Yes

#

discord very secure yesyes

limpid badger
#

hello everyone

keen salmon
#

what am I looking at?

#

can't talk, sorry ๐Ÿ˜ฆ

#

short lived ๐Ÿ˜†

tardy anvil
#

hey?

plucky vault
#

cj

tardy anvil
#

What do I do with that

#

Fk

full sapphire
#

(Be aware it's a public server -- we can all see that)

plucky vault
#

smh

#

its not giving me shell!!

#

ooo got something yaya @tame ether

#

etc/passwd ๐Ÿ˜›

#

gonna use hydra now ๐Ÿ˜ (i just love that tool so much)

#

yeah ik

#

but im gonna try bruteforce

#

im so lost rn

#

im legit bruteforcing every user with rockyoushort

tame ether
#

I don't think it's the way to go Kappa

#

explore ports 80-83

plucky vault
#

im doing it

#

i can't upload .php

tame ether
#

yes you can ๐Ÿ˜Ž

plucky vault
#

eh.... ig but i think of doing some more enumiration at the same time

#

@tame ether why do you know stego so much?

tame ether
#

stego?

plucky vault
#

stegography

tame ether
#

there's no stego here afaik

plucky vault
#

how did you

#

do it then ๐Ÿ˜ญ

tame ether
#

๐Ÿ˜Ž

plucky vault
#

going back to look at the pic you uploaded ๐Ÿ˜ฎ

tame ether
#

i can't get king tho

#

I don't have a static chattr and i think it's chattr'd by default kekw

plucky vault
#

oof

#

xD

#

eh it ends in 6 min

#

gg

#

another one ?

tame ether
#

not now

plucky vault
#

oof okay

#

im gonna go and play some rooms ๐Ÿ˜‚

dark grail
#

this server dont have the music channel ?

cursive herald
#

we dont have a music bot

dark grail
#

can we ?

cursive herald
#

this is supposed to be a professional discord other than #general , i can't see how a music bot could professionally advance people's careers or skillset? But anyway, it's not down to me. Ask a @mod ?

dark grail
#

lol

#

let itbe

cursive herald
#

@forest python will likely answer you

dark grail
#

ill listen it on spotify

ripe flare
#

say something

azure moss
#

u ok there @ripe flare

ripe flare
#

i want to listen void of somebody

#

im first time here

#

voice*

azure moss
#

Ur wish is done

plucky vault
#

someone stream koft or skmething

lofty moat
#

umm i already won this one, so no point streaming it as no one is in the box

plucky vault
#

The next one

glad apex
#

Can we ask doubt in this group

#

? About machines ?

livid crag
#

You're deafened you vegetable, I can hear you

plucky vault
#

ok im here

#
``` @plucky vault
south elk
#

hi

#

i like to watch

zenith cradle
#

join KOTH-1

#

voicd chat

plucky vault
#

@livid crag ready to play ???

livid crag
#

as ready as you

#

(not at all)

tame ether
#

๐Ÿ‘€

plucky vault
#

ahhahaahah

#

tru tru

#

@livid crag whats up ๐Ÿ˜‚

#

why restart the machine ?

#

wow someone running autopwn

cursive herald
plucky vault
#

@limpid badger it took me 15 minutes to install zorin os again.

#

armitrage is a good tool

#

i liturally love it

#

yah

cursive herald
#

@plucky vault whats your github? You had a repo for a THM leaderboard tracker and i wanted to check it out ๐Ÿ™‚

tame ether
plucky vault
#

i alredy installed operating system

#

just yk apt update apt upgrade

rapid imp
#

get kali-linux-full I guess?

#

The whole package

plucky vault
#

y

rapid imp
#

Forgot it was ZorinOS, nvrmind

plucky vault
#

can someone send me big.txt?

cursive herald
#

i think this is it?

plucky vault
#

@forest python should i do this ?

#

the liter the faster install

#

i avoid windows

full sapphire
#

Think of it as attack and defence @limpid badger

#

Once you get in, you have to defend against everyone else

#

Kinda like Red/Blue team

serene veldt
#

guys hey

lofty moat
#

hye

serene veldt
#

is there any way that i can use the compromised website as the shell

#

what i am trying to achieve is to get a reverse shell on the machine,not a webshell that has a hosted website on it.the machine is behind a waf so i tcp are blocked only port 80 is allowed.is there any tool out there that can make a php intermediate page between my uploaded reverse tcp shell in the website and my local listener

#

target machine netcat<==>php intermediate webpage<====>attacker netcat

lofty moat
serene veldt
#

this is a doubt๐Ÿ˜†

lofty moat
#

i would rather not answer that

full sapphire
#

@serene veldt I've seen it done, but you may need to program it yourself

#

I hope this is for a THM room as well...

languid wing
#

hello guys!! im new here. Can i ask some doubts about the tryhackme website??

tame ether
#

@languid wing sure, if you want help with a room head to #room-help, for most other things #general is a place to go

languid wing
#

@tame ether thankyou!! a help is that now im recently sign up to tryhackme web. so im now struggling to connect openvpn with tryhackme from win10. it says connected in openvpn but not showing in te tryhackme website!!

tame ether
#

ah, ignore the /access page, it's buggy
try deploying a machine and connecting to it

#

also for any other problems with a VPN #site-support is the place to ask in

languid wing
#

@tame ether yeh ive made a deploy and it said connected

#

@tame ether thank you so much for your support!

tame ether
#

๐Ÿ‘

lofty moat
#

@languid wing if you need help regrading rooms try to ask in #room-help and if have any vpn or techinical difficulties ask in #site-support . Have Fun Hacking ๐Ÿ™‚

tame ether
#

I literally told that few messages back kekw

languid wing
#

@lofty moat ok thankyou again!!

lofty moat
#

I literally told that few messages back kekw
@tame ether I look for ways to jump in into everyhing

zenith cradle
#

someone up for KOTH ?

plucky vault
#

@zenith cradle Yes xD

serene veldt
#

ys

cursive herald
#

pls fix

#

my headset died

#

๐Ÿ˜ฆ

stoic root
#

what room do you guys recommend to do after zthlinux?
?

buoyant lichen
#

Blue

stoic root
#

ok

lofty moat
#

what room do you guys recommend to do after zthlinux?
?
@stoic root i would suggest to do RP: Metasploit before doing blue

stoic root
#

ok

#

i will also do RP: nmap

lofty moat
#

GL

wooden locust
#

let's see ...

ruby drift
#

@plucky vault what room is this?

plucky vault
#

its koth

ruby drift
#

nice

plucky vault
#

only @plucky vault is pro here XD

#

why does it show your name @plucky vault ?

#

Because I'm the king.

#

oh

#

dunno what to do:/

#

i'll ask ya after this compi

#

got it theres a exploit for abyss port 9999

tame ether
#

no?

quiet needle
#

Don't attack 9999