#voice-chat

1 messages ยท Page 8 of 1

plucky vault
#

no?

tame ether
#

you should leave port 9999 alone

plucky vault
#

Can't

#

Not allowed to attack 9999

#

oh

#

okay

#

dont knw what im doin lol

#

is brute forcing allowed. i doubt it'd work

#

or completely wont work

#

so is it port 3000

#

I patched access to root so good luck.

ripe rover
#

I see what you did there ๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚

#

Ppp

plucky vault
#

Yeah

quiet needle
#

@plucky vault No.

plucky vault
#

You want to know how I patched some things @ripe rover?

ripe rover
#

Yes sir

plucky vault
#

What method were you trying?

tame ether
#

@full sapphire hey we have @plucky vault being very toxic in vc :)

quiet needle
#

Muted.

#

Ahmed

tame ether
#

oh you're in vc cmn

ripe rover
#

@plucky vault i spawned a reverse shell using nodejs but i don't know much about patching side

plucky vault
#

I killed node and started blocking incoming connections besides SSH, and then I prevented access to root.

fresh solar
#

Ooh, Elf is streaming ๐Ÿ™‚

plucky vault
#

After writing to the king file and doing "chattr +i king.txt"

#

Annnnnd removing access : )

#

lol

#

why are u playing dude

#

we are no match for you XD

#

It's fun : )

#

i'll pratice hard af from right now

#

Haha, well pick up some books then, complete some beginner boxes.

#

im gonna beat ya next time @plucky vault

ripe rover
#

Can you tell more about blocking the incoming connections thing?

quiet needle
#

I have just banned Ahmed-al-Hammad @tame ether. Thanks for letting us know

plucky vault
#

Haha, well pick up some books then, complete some beginner boxes.
@plucky vault i've already done it

#

will do more

#

@ripe rover iptables

#

e.e

ripe rover
#

Ah shit ,obviously i still have a lot to learn . Thanks for sharing the info tho ^^

plucky vault
#

No problem.

#

after the challenge is finished will ya tell me how did u do it @plucky vault

#

?

#

There's a lot to learn, and the whole point is for you to understand it, not just get the answers.

ripe rover
#

True

plucky vault
#

I exploited a vulnerability in curl to get on faster, and then changed passwords and dropped a backdoor shell

#

okay

ripe rover
#

Up for another game ? xD

plucky vault
#

what topics do you suggest to learn before i become eligible for koth?

#

Sure @ripe rover

real orbit
#

"Elf McSkidy hacked the FBI?! No way. He's a fokin knob"

plucky vault
#

@plucky vault Do all the basic rooms, things that teach the beginners level of things, like the RP series.

#

ok

real orbit
#

@plucky vault apt install bless

azure moss
#

Can we keep the voice to being helpful and constructive please. We're all here to learn

full sapphire
#

Keep it civil guys

lyric horizon
#

Oh my god

#

What is going on here

#

@real orbit what's Bless?

real orbit
#

hex editor

lyric horizon
#

Adding to list of things I never knew about but need

#

What would you use a hex editor for anywho?

plucky vault
#

yes

forest python
#

ghex is nice too

lyric horizon
#

If you have GDB

forest python
#

Editing binary files EG headers

lyric horizon
#

And like radare2

forest python
#

GDB is a debugger

lyric horizon
#

Ahhhhh

forest python
#

Radare is RE software

lyric horizon
#

Not sure where it would come in handy but I'll look into it

forest python
#

Binary != executable in this case

#

Image files in CTFs with bad headers, changing bytes, it comes up

lyric horizon
#

I'm sure it does

#

I just don't know what any of that means

#

Or the implications of being able to change them

#

I'm working so can't join the party. What room is he doing

tame ether
#

cherryblossom

plucky vault
#

@real orbit what is bless thing

tame ether
#

it's a hex editor

real orbit
#

thank you

muted sand
#

Radare is RE software
@forest python that also has a debugger

forest python
#

A hex editor is separate, that's the point I'm making

tame ether
#

damn, i never saw this many people in vc at one time

snow kelp
#

Seems like Elf McSkidy is doint something nice ๐Ÿ˜ฎ

weary grove
#

coming in hot

#

nice hair you got there kekw

#

show your feet @midnight fern

marble cape
#

Fun fact, people in voice chat are weird. Justsayin ;P

tame ether
#

Even funnier fact, people generally are weird

lyric horizon
#

Wish I could stay

#

I just like hearing Dark talk

#

I feel I gain brain cells when he talks about pentesting

#

And methods

#

Smart kid lol

#

@marble cape how did you get to where you are but you're so young?

tame ether
#

wait till' you see one of his famous infosec twitch streams :)

marble cape
#

oi

lyric horizon
#

Are you just one of those genius kids that started playing with computers when they were 2?

#

Like you hear on Darknet Diaries

marble cape
#

I've been playing with and building computers for years

lyric horizon
#

"Joe was just a normal kid. He made his own computer when he was 5"

marble cape
#

Infosec has only been a recent thing though, like three years tops

tame ether
#

midlife crisis

lyric horizon
#

But I assume you live and breathe it to know as much as you do

marble cape
#

Just read a lot, albeit it doesn't come off super well on stream because I'm not one to enjoy being up on stage when I'm the main focus

lyric horizon
#

He's too young to have a midlife crisis

#

What do you read

forest python
#

@plucky vault - not ~

marble cape
#

I'm going to start posting what I read on my website

lyric horizon
#

Just articles from Google searches on topics you're interested in?

marble cape
#

I'll post the two books I read last week here in a moment

lyric horizon
#

Cuz my life goal is to get where you are lol

#

In a position like that

#

Hell, I'd even love to do physical pentests

#

That would be awesome

marble cape
#

I also say yes to a lot of things that I may not 100% understand from the get go and I'll learn either before or as I do them

modest spruce
#

what is your website?

marble cape
#

Throwing yourself in the deep end is fun as long as you're prepared to try and swim

#

I'm working on the blog part now, I just mostly have all of my VMs and resources up there

#

Along with links to talks I've given

plucky vault
#

@forest python ooo ๐Ÿ˜‚

forest python
#

reeee

livid crag
lyric horizon
#

@marble cape I do that too. It's a good attitude to have

lyric horizon
#

Added to Wishlist

#

Thanks man

#

And let me bookmark the site

#

Looks good. Built it yourself?

marble cape
#

Yeah, it's simpler than it looks though lol

#

There's a github repo for it that you can see the entire thing in

lyric horizon
#

Oh nice. So in addition to red teaming, you know how to make a good looking, custom website lol

#

What languages did you use or frameworks

marble cape
#

Standard web with bootstrap haha

lyric horizon
#

Excellent

#

Yeah I guess you wouldn't need any server side

modest spruce
#

@marble cape what do you think of the book "Black hat python"? I starting reading this week

marble cape
#

Haven't read that one yet but I've heard good things

lyric horizon
#

Same

marble cape
#

Python is mostly practiced based so tbh, as long as you're doing the exercises you should be set

lyric horizon
#

Friend from work started it and said it taught a lot of cool things

#

Yeah that too

tame ether
#

It's one of the no starch press books right? yes it is, checked that

modest spruce
#

i think yes

lyric horizon
#

Usually their books are free no?

marble cape
#

Nah, they just do a lot with Humble Bundle

lyric horizon
#

Ah gatcha

marble cape
lyric horizon
#

Would concepts here apply to other RE software?

#

Or is it just teaching Ghidrs

#

Ah looks to be most only Ghidra

quiet needle
#

oooo Ghidra

lyric horizon
#

Where's a Cutter book :(

real orbit
#

there

lyric horizon
#

Lolol

lofty bison
#

which room is this

quiet needle
#

Cherryblossom

livid crag
cinder mirage
#

hey look my profile ๐Ÿ™‚ ๐Ÿ‘

quiet needle
#

NotLikeThis literally vc

tame ether
#

the cat is watching

#

๐Ÿ‘€

quiet needle
#

he has blessed us

cinder mirage
#

:c

tame ether
#

i'll give a can of coke to everyone in vc
DISCLAIMER: I won't actually give any coke cans

forest python
plucky vault
#

ty

quiet needle
#

I dockerised it too

#

with Muirl for the box

#

wait no wrong box mb

livid crag
#

where do you come from where do you go

#

where do you come from scp file

forest python
#

@plucky vault scp sourcefile destinationfile

#

scp exploit DESTINATION

plucky vault
#

YES

azure moss
#

Elf may appear to be silly, but he's got the whole of this discord teaching him. That's some next level straegy

plucky vault
#

o.o

forest python
#

Back to terminal

#

NOW

tame ether
full sapphire
#

Very successfully, it appears...

quiet needle
#

Making leaps and bounds Muirl

azure moss
#

It slightly reminds me of "twitch plays"

tame ether
#

twitchdoeshacking

full sapphire
#

You lot are not gonna like the next two...

#

No one is noticing my nice message?...

#

I didn't even bother with my notes -- I just hacked it myself while he was figuring out SCP...

livid crag
#

my head still hurts

full sapphire
#

Wait

#

Wait wait way

#

He shredded his own

#

AGAIN?!?!

azure moss
#

why did he shred again...?

full sapphire
#

Can't even blame Pars this time...

#

Did he mean to do it to the box?...

tame ether
#

no idea

#

don't think anyone told him to

quiet needle
#

Nah

full sapphire
#

No one told him to this time...

livid crag
azure moss
#

Every new room requires a new distro

full sapphire
#

Well, naturally

livid crag
#

This time we're doing Parrot

lofty bison
#

that was fun ๐Ÿ‘ ๐Ÿ‘

tame ether
full sapphire
#

Ey, let's be civil here. Be nice

azure moss
#

Elf has the thickest skin here, he doesn't stop, legend

#
  • I'm pretty sure he was on an advert for "CompareTheMarket"
full sapphire
#

@livid crag if this is illegal, I would suggest not doing it...
Either way, please don't stream it if it ain't THM

#

Oh, on which note, if someone pastes a room IP in a chat, please don't mess with it

plucky vault
#

It's not illegal, he had permission.

livid crag
#

yeah it was a bug bounty

full sapphire
#

If

#

If it's not illegal than carry on ๐Ÿคทโ€โ™‚๏ธ
Either way, please keep it THM related here though

azure moss
#

This is THM we stream THM stuff not random Bug Bounties. You could lie about having permission.

#

imo

livid crag
#

โ˜•

#

Noted.

azure moss
#

We need to get Elf to try out Temple OS in a VM

quiet needle
#

We don't do that thing around here @sacred relic

#

Rule 9.

sacred relic
#

ok

#

guys what is 0x1 or 0x8

#

is that rank or something like that

#

?

quiet needle
#

Yes

#

It correlates to your TryHackMe level

lofty moat
#

Oh you are live, lemme just turn on my pc

quiet needle
#

gotta call - muted

marble cape
plucky vault
#

it thought me alot

#

brb i have to switch to phone

tame ether
#

@plucky vault mind passing me the koth invite?

plucky vault
plucky vault
#

@tame ether Did you kill sshd or iptables me?

tame ether
#

nope

plucky vault
#

Huh

#

Well, gg.

tame ether
#

only stopped the backdoors

plucky vault
#

Nice patching.

tame ether
#

what was that program? kekw

plucky vault
#

Why?

tame ether
#

yCfAx thonk

#

only one with the connection to another IP

#

so that was you

plucky vault
#

Yeah haha

tame ether
#

and I can't find it D:

plucky vault
#

Haha well good luck ๐Ÿ˜„ you're smart

#

I can't even ssh haha

tame ether
#

๐Ÿ˜Ž

plucky vault
#

Do you mind telling me how you patched it :p

tame ether
#

kekw aside from stopping the shells i removed sudo perms and moved ssh

plucky vault
#

I saw that lmao

#

I saw the removal of sudo, at least

tame ether
#

saw? ThonkRubTP

plucky vault
#

Logs

tame ether
#

ah

plucky vault
#

It logged every file change, at least

#

e.e

tame ether
#

That program is interesting, is it still on the box? kekw

plucky vault
#

It's not, no.

#

I'm still improving on it.

tame ether
#

if you want the flag DM me the one you got and i can pass to you the working one

plucky vault
#

Alright

#

Clicking "Join Random Room" for 10 minutes straight is fun :p

tame ether
#

automate it

plucky vault
#

Wish I had nitro for an emoji right now, but no e.e

tame ether
#

:(

plucky vault
#

@marble cape I can agree to that. Nights in the NOC and weekends in the SOC, and being in the CSIRT is very fast, but it's fun.

#

(lagged sorry)

marble cape
#

all good and yeah absolutely

plucky vault
#

@marble cape Good night, tell Kris I say bye, szymex gg, and off to the NOC I go : )

marble cape
#

peace man โค๏ธ

tame ether
#

gn :)

marble cape
rough flax
tame ether
livid crag
#

byee

rough flax
marble cape
livid crag
marble cape
#

?

tawdry tangle
plucky vault
#

Can you share the twitch link?

marble cape
#

Oh my twitch link?

rough flax
plucky vault
#

yes

marble cape
tame ether
livid crag
livid crag
tawdry tangle
#

Implementation of the USB 2.0 controller not found!
Because the USB 2.0 controller state is part of the saved VM state, the VM cannot be started. To fix this problem, either install the 'Oracle VM VirtualBox Extension Pack' or disable USB 2.0 support in the VM settings.
Note! This error could also mean that an incompatible version of the 'Oracle VM VirtualBox Extension Pack' is installed (VERR_NOT_FOUND).

tawdry tangle
#

Not in a hypervisor partition (HVP=0) (VERR_NEM_NOT_AVAILABLE).
AMD-V is disabled in the BIOS (or by the host OS) (VERR_SVM_DISABLED).

tawdry tangle
#

@fierce laurel

fierce laurel
#

oh

#

ok one sec

#

task 5?

#

and the payload is correct?

weary grove
#

no need to ping mods

fierce laurel
#

@tawdry tangle are you sure of the payload

#

yea yea it's correct

#

umm

#

try changing the port to 135

#

Rport

weary grove
#

type check

fierce laurel
#

remove the j

#

like

#

-j

#

are you sure the host is still up?

#

idk I've done this a looong time

#

I don't think it'll respond to ICMP

#

you should try the tmux tutorial

#

oh ok

#

yea 8000

#

wait

#

I think your LHOST is the target

weary grove
#

nmap -sV -p- -T 5 -Pn IP

fierce laurel
#

and RHOST is you

#

wait

#

run

#

ifconfig tun0

#

ifconfig tun0

#

@tawdry tangle try running ifconfig tun0

#

waaait

#

are you connected?

#

openvpn?

#

F

#

just do

#

yea it is installed

#

sudo openvpn <file.ovpn>

#

yea I was confused

#

lol

#

are you good with reverse engineering?

#

:(

#

I've been stuck on this since yesterday

#

I couldn't even find any writeups

#

it's supposed to be a walkthrough, but it's been mentally abusing me

#

I'm stuck at the last crackme

#

Connection to 10.10.31.99 closed.

#

F

#

you don't have to do that

#

just terminate the machine and relaunch it

#

yea I was about to say that

#

rename it

#

or do it like this \(\)

#

@tawdry tangle just terminate the machine and start it again

#

you won't lose any progress

#

oh wait

#

\just change the LHOST

#

no

#

LHOST]

#

not RHOST

#

sometimes tun0 doesn't work, so make sure you put the actual IP

#

@tawdry tangle your IP

#

LHOST

#

make sure you put the actual IP

#

he put ton0

#

not tun0

#

@weary grove

#

I can't talk just tell him

#

he put ton0 and not tun0

plucky vault
#

nano /etc/network/interfaces

#

service network restart

#

ip link remove wlan0

weary grove
#

missclick lol

plucky vault
#

Hello there.

#

asdf jkl;

#

?

thin schooner
#

@plucky vault

plucky vault
#

kali on WSL. Not working for me at the moment.

#

Soo yeah.

weary grove
#

You need wsl2

#

So windows 10 v 2004

plucky vault
#

Yeah, it is WSL2.

#

It's just that I can't deploy the VPN at the same time.

#

For some reason....

#

Anyway, I'

#

Anyway, I'm downloading kali linux 2020 iso now.

#

I'll install it directly on my hardware just like before.\

#

๐Ÿ™‚

polar raven
#

< file < anotherfile Could someone link me to what that is??
Less writing :D

plucky vault
vague crescent
#

u can use pspy to see what is being runing

livid crag
#

thats my namee

plucky vault
#

@livid crag try to find lfi

gaunt thunder
#

which box is this

plucky vault
#

what ?

#

@livid crag im gonna go to store

#

gonna be back in like

#

20 minutes

#

can you wait for me ?

#

ok brb 20 min

vague crescent
#

my mike isnt on

livid crag
#

damnit mike

visual wyvern
#

I cant hear you @plucky vault

plucky vault
#

Let me see if I can troubleshooti.

visual wyvern
#

ok

plucky vault
#

How do you want to do the private call?

#

Google?

#

Still?

#

Ah ok

#

hmmmm.

#

yeah.

#

Is there any sound at all?

#

Yeah, it is.

#

I thought I solved it for a second.

#

Oh no, I didn't do that website you sent.

#

I tested it with Discord.

#

The joys of lnux

#

linux

#

Yeah.

#

Yeah.

#

Just overnight.

#

Do you mean the sound settings?

#

Does he mean?

#

input device microphone - blue snowball.

#

Um, wdym?

#

ah one moment.

lofty moat
#

like this ^

plucky vault
#

Oh ok.

lofty moat
#

just woke up.

plucky vault
#

Ah I can't do that.

#

Default and Snowball.

lofty moat
#

oh wait

#

i got it

#

see you have push to talk on

#

but no key set for push to talk

#

Try changing that to Voice Activity or set a key in No Key Bind Set

plucky vault
#

Hmmmmmmmmmmmmmmmmmmmmmmmmmmmmm..........

lofty moat
#

whats the other game except grey hack ?

#

Can you spell it in here?

#

i didnt get it ๐Ÿ˜ฆ

raw walrus
#

nite team 4

lofty moat
#

thanks

raw walrus
#

no problem

lofty moat
#

which box in koth?

#

Stream it @livid crag

#

i dont think james will mind

#

wait, why he will mind for streaming a game?

plucky vault
#

Yeah, I'm still working on it.

#

What version of Linux do you have?

#

It seems to be working on yours.

livid crag
#

You should really make a rule for that

plucky vault
#

20.04

full sapphire
#

Y'don't think it's common sense?...

#

Kinda falls under Rule 14

lofty moat
#

umm i thought streaming some games wasnt against the rules

plucky vault
#

Yeahh, it above.

#

It's still on voice activity.

livid crag
raw walrus
#

lsusb

plucky vault
#

Bus 004 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub
Bus 003 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub
Bus 002 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub
Bus 001 Device 004: ID 1532:005c Razer USA, Ltd Razer DeathAdder Elite
Bus 001 Device 003: ID 1532:0209 Razer USA, Ltd BlackWidow Tournament Edition Chroma
Bus 001 Device 005: ID 0d8c:0005 C-Media Electronics, Inc. Blue Snowball
Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub

raw walrus
#

arecord -l

plucky vault
#

oddrabbit@Wild-Dog-Pro:~/.config/pulse$ arecord -l 5
**** List of CAPTURE Hardware Devices ****
card 0: PCH [HDA Intel PCH], device 0: ALC1220 Analog [ALC1220 Analog]
Subdevices: 1/1
Subdevice #0: subdevice #0
card 0: PCH [HDA Intel PCH], device 2: ALC1220 Alt Analog [ALC1220 Alt Analog]
Subdevices: 1/1
Subdevice #0: subdevice #0
card 1: Snowball [Blue Snowball], device 0: USB Audio [USB Audio]
Subdevices: 0/1
Subdevice #0: subdevice #0

tawdry tangle
#
                     |  _____________ ____      ____ __________________     |
                     | /____    ____//   /\    /   //                  \    |
                     | \___/   /\___/   /_/___/   //    ___    ___     /\   |
                     |    /   / /  /   ______/   //    /\_/   /\_/    / /   |
                     |   /   / /  /   /\____/   //    / //   / //    / /    |
                     |  /___/ /  /___/ /   /___//____/ //___/ //____/ /     |
                     |  \___\/   \___\/    \___\\____\/ \___\/ \____\/      |
                                           "Try Harder"```
plucky vault
#

System76. ๐Ÿ™‚

lofty moat
#

Add me @livid crag ?

livid crag
#

no

plucky vault
#

I've accepted the friend reqeust.

#

Where to now?

raw walrus
#

he is about to add you

plucky vault
#

OK, awesome. Thanks.

plucky vault
#

I finally did the mr robot machine

#

Hi D4SuCE.

#

I don't have a microphone.

#

What's that

#

?

#

Do you want to do a KOTH?

waxen cave
#

8gb model or none.

muted sand
#

8gb model or none.
@waxen cave Theres an 8gb model? Aww everywhere is out off stock ๐Ÿ˜ฆ

dusky zodiac
#

Did you check adafruit?

tawdry tangle
#

I'm not made of money

#

Its already almost $200

undone willow
#

nmap -T4 -A -p- -PN

lyric horizon
#

@rough flax Whatcha streaming?

rough flax
plucky vault
#

so i guess im streaming wonderland now .

full sapphire
#

Have you asked James about that @plucky vault?

#

It's a new box

plucky vault
#

i think he said i can?

#

gonna ask hem again tho

plucky vault
#

wait you modified the dirs 2 ?

#

oiooo

#

i got something

#

kekw

#

๐Ÿ˜ญ

tame ether
#

@plucky vault what are you trying to do

plucky vault
#

trying to upload file to my pc

tame ether
#

use scp

pulsar smelt
#

^^

forest python
#

*trying to copy a file off the box

waxen cave
#

netcat file transfer?

forest python
#

Which you can do with a single HTTP server with python and a single WGET

#

I've given him a dozen options

pulsar smelt
#

scp is easier tho

tame ether
#

scp is the easiest as it doesn't require setting up any servers or listeners

pulsar smelt
#

^^

forest python
#

@plucky vault Don't install php

#

0 reason to install php

plucky vault
#

okay

tame ether
#

why are you installing an ssh server

pulsar smelt
#

because you need it for scp

#

iirc

tame ether
#

you don't

pulsar smelt
#

o really?

tame ether
#

you need a ssh client

forest python
#

No

#

He needs to recieve the file

pulsar smelt
#

server

tame ether
forest python
#

He doesn't have a password for the user on the box

#

Elf, other way round

#

Serve the file from the box

tame ether
#

ssh key

forest python
#

WGET it from your PC

pulsar smelt
#

no

#

password

plucky vault
#

yes thats what im doing

#

oh no

forest python
#

He doesn't have the password

plucky vault
#

im not doing that

forest python
#

You're trying to send the file

pulsar smelt
#

from box do scp to pc

forest python
#

You want to serve the file

pulsar smelt
#

no?

forest python
#

He can't

#

Because he needs an SSH server

#

@plucky vault You know HTTP

#

It's HTTP

pulsar smelt
#

on box you need ssh client

forest python
#

And on his machine he needs something to receive the SCP connection

#

So an ssh server

pulsar smelt
#

or that

#

there

forest python
#

That's all it took, elf

tame ether
#

why not just add the ssh pubkey to the box and use scp from his pc

plucky vault
#

yes i get it now

#

its done

#

@forest python 2 very simple commands

#

๐Ÿ˜‚

tame ether
#

simple

#

but look how long it took you ๐Ÿ˜Ÿ

plucky vault
#

ikr hahahaha

#

now im going to be doing something i have no idea what im doing pls help me

#

lol

pulsar smelt
#

what do you need to do

plucky vault
#

avoid segmentation fault

pulsar smelt
#

XD

#

ok

plucky vault
#

so uh

#

im stuck

forest python
#

@plucky vault Chuck a decompiler at it

plucky vault
#

its made in c

#

hang on

forest python
#

Something like Ghidra has a decompiler. Or cutter which is a nice gui for r2

#

Or that one, which cutter uses

#

Turns assembly into C

plucky vault
#

ooo

#

im gonna check that out rn

forest python
#

You can do it straight from r2 if you know what you're looking for

#

Elf it had installation instructions

#

@plucky vault Don't clone it

#

You don't need to

#

Under the Install in the readme

#

No elf

#

It tells you exactly what to do

#

You don't want to build programs

#

Elf

#

In your terminal

plucky vault
#

its not working

forest python
#

It tells you what to do to fix it

#

It is

#

You made a franken debian

#

And I warned you

plucky vault
#

xD

forest python
#

This is why I warned you

#

Yes you can

plucky vault
#

but i can't install gobuster if i don't have it

forest python
#

You need to take like, a minute to understand how go programs work

#

Or download the binaries and add it to path

plucky vault
#

or twinkle with sources ๐Ÿ˜‚

forest python
#

When someone emphatically tells you something is a bad idea, and gives you reliable sources to back up why something is a bad idea, you probably shouldn't do it

plucky vault
#

yeah thats a good point

forest python
#

Something that isn't useful

#

You can RE the program using incredibly simple techniques

#

And that gives you enough to exploit it

plucky vault
#

am i going the right way?

forest python
#

You're not going any way

plucky vault
#

am i going the right way now?

forest python
#

I thought you said you weren't going to ask for help

plucky vault
#

okay okay

#

no help

#

this is 2 much stress for me

forest python
#

@plucky vault grab the appimage for cutter and use that

#

@plucky vault Radare 2 releases on github

#

Cutter

#

Releases.

plucky vault
#

omg what is this

forest python
#

You know where releases are

#

It's a gui for radare2

#

Scroll up

#

It's the same place as regular github releases

#

@plucky vault No, that's the repo files

#

Top bar

#

releases

#

Yes there

plucky vault
#

yes i found it ๐Ÿ˜‚

forest python
#

You'll need to chmod it

plucky vault
#

ooo its an app image

#

like runelite

#

i know how to run those

forest python
#

@plucky vault Elf

#

I said you need to chmod it

#

Set it to dark

#

midnight

#

you need to enable the decompiler

plucky vault
#

how do i do that

forest python
#

Windows > Decompiler

#

Click on main

#

That's basically exactly the source code

#

You should know the library calls

plucky vault
#

and this is even more confusing

forest python
#

You have the source code of the program

#

Find the vuln

#

It's in main

#

Elf, you said you know C. You should know puts, system and getchar as library functions

plucky vault
#

i know

#

i liturally sent you the file of what i learned

#

i didn't learn puts or any libary

#

i think?

forest python
#

If you don't know the very basics of stdio, you don't know c

#

google the functions

plucky vault
#

ok

#

ok

#

so i read it

forest python
#

it's basically print

plucky vault
#

puts is print

forest python
#

Yes

plucky vault
#

getchar is scanf basicly

forest python
#

no

#

it gets a single character

plucky vault
#

wdym no its looking for user input right?

#

YES

forest python
#

So

plucky vault
#

sry for caps

#

lol

forest python
#

it prints segmentation fault

#

You can see that

#

You can see exactly what the code is doing now

tame ether
#

๐Ÿ˜Ÿ

forest python
#

@tame ether You rooted it yet?

tame ether
#

ye

#

i was blind

#

saved the steps, might make a writeup later and publish it in few days

forest python
#

you fell for it

plucky vault
#

yes i don't understand now

#

so what ever i input

forest python
#

yes

plucky vault
#

its prints seg fault

forest python
#

Yes

#

it's not erroring

#

It's just printing it

plucky vault
#

thats evil

#

wait what am i looking for then

forest python
#

I mean the exploit is really easy

tame ether
#

look closer at the generated code

forest python
#

If you've actually done boxes on THM and learned

#

You should only care about main here

plucky vault
#

its a buffer overflow?

forest python
#

Elf

#

It prints Segmentation Fault

tame ether
#

read the code

#

๐Ÿ˜Ÿ

forest python
#

There are no buffers

#

It gets a single character

plucky vault
#

yes

#

okay just gonna bruteforceit

forest python
#

You can't BoF with no variables and a single character that is never stored

#

Elf

tame ether
forest python
#

You can see the code

plucky vault
#

yes

forest python
#

You know it's not checking the input

#

It's discarding it

tame ether
#

elf, not every function there is a print/getchar

forest python
#

The input doesn't matter at all

#

You said no help

tame ether
#

thinkDerp now i want to get back on the box and check that tryhackme user out, forgot to do it before

forest python
#

@tame ether I can tell you if you want. There's nothing there

tame ether
#

:C

forest python
#

It's just the user I use to create the challenges

#

Bash history wiped

#

Runs the webserver

tame ether
#

noticed that, it's the first non-root, non-system user

forest python
#

It has all all sudo

#

But you don't have a password

plucky vault
#

so i was correct

#

it involves time ?

#

i mean date

forest python
#

Not really

#

Only trivially

tame ether
#

well technically it does

plucky vault
#

kekw

#

i give up on this one ๐Ÿ˜ญ

forest python
#

No

plucky vault
#

james help mee !! ๐Ÿ˜ฆ

forest python
#

Go do some THM walkthroughs

#

Learn2hack

plucky vault
#

no i want to complete this one so hard lol

forest python
#

Part of learning is knowing when to give up

#

And come back later

tame ether
#

^

plucky vault
#

but :

#

this room is so nice

#

and i wasted 5 hours on it btw

forest python
#

You need to learn how to exploit things

#

You should have been keeping notes so you can come back to it

tame ether
#

and i wasted many more hours on other rooms. it's part of the process elf

forest python
#

It's a challenge room

#

Don't be surprised when it challenges you

plucky vault
#

the point is there is no room for giving up and leaving the room rn

#

kekw

forest python
#

No

#

You need to learn what how to do things

#

There's a reason walkthrough rooms exist

tame ether
#

@plucky vault do you take notes on rooms at all?

forest python
#

you set super weird permissions

#

permissions are normally 3 digits

plucky vault
#

james i broke something

forest python
#

Yes elf

#

Don't blindly chmod stuff

plucky vault
#

nwm i fixed it

tame ether
#

@plucky vault do you take notes on rooms at all?

plucky vault
#

no

#

kekw

tame ether
#

๐Ÿ˜Ÿ

plucky vault
#

i put stuff only in my head

#

hang on i need a cigarete lol

tame ether
#

well, good luck when you forget something

plucky vault
#

im back

#

i don't do forget ๐Ÿ™‚

forest python
#

I mean

tame ether
forest python
#

I doubt that, if you've completed more than 10 rooms on thm

#

Go do some walkthroughs

#

Learn more techniques

#

Understand them

plucky vault
#

or

tame ether
#

and take notes

forest python
#

You need to understand in order to apply things to other rooms

plucky vault
#

learn them by streaming for 5 hours

forest python
#

Bashing your head against the wall isn't a healthy learning strategy

plucky vault
#

i do that some times when i get really mad

#

or really bored

#

xD

forest python
#

Go learn some stuff

tame ether
#

this is for a reason

forest python
#

Stop using the headbash method

#

Learn what you're doing, and it goes much smoother

tame ether
#

it really helps to revisit stuff, you don't waste time

plucky vault
#

i mean sure

#

but this way is good 2

forest python
#

It's not

plucky vault
#

you know learn the hard way

forest python
#

For everyone else involved

plucky vault
#

tru tru

forest python
#

Why learn the hard way when you can learn the easy way?

plucky vault
#

cuz the easy way is bully ๐Ÿ˜‚

forest python
#

bully?

#

I don't think you know what that means

tame ether
#

tbh this way is "bully" as you say it

plucky vault
#

it was a joke ๐Ÿ˜ฆ

forest python
#

It doesn't make any sense

plucky vault
#

@forest python google how to troll pls

forest python
#

Elf

#

You used a word that doesn't make any sense in the context

#

That's not a troll

plucky vault
#

yes

forest python
#

That's just using the wrong word

forest python
#

Kale is a vegetable

plucky vault
#

he is a youtuber

#

this is some stuff i will never understand lol

tame ether
plucky vault
#

@plucky vault not cool

#

i don't know what to do

forest python
#

Elf

#

I've said it before

#

And I'll say it again

plucky vault
#

no i mean with this

forest python
#

Walkthroughs are to teach you

#

Go do walkthroughs

plucky vault
#

which one

forest python
#

A bunch of them

#

Maybe start with some easy linux ones

plucky vault
#

but i alredy know how to do linux stuff

#

here

forest python
#

No

#

you know how to use a terminal

#

There's a lot more to hacking linux than that

plucky vault
#

yes

forest python
#

Do some linux based walkthrough rooms

#

You're never done learning

plucky vault
#

okay but first i finish this thing

forest python
#

Elf

#

You won't be able to

#

You need to learn skills

tame ether
#

leave wonderland alone elf

forest python
#

Come back to it

plucky vault
#

i don't want to

#

its part of me

forest python
#

You prefer to beg me for help than actually put the work in yourself?

plucky vault
#

both kekw

tame ether
#

๐Ÿ˜Ÿ

forest python
#

I'm being serious here

#

Go do some walkthroughs

tame ether
#

how are you 0xD with this mindset :(

plucky vault
forest python
#

I mean it's not binexp

#

No point misleading him

tame ether
#

it's something 100x easier

forest python
#

It fakes being binexp just to mess with you

#

Because it's a CTF

#

@plucky vault I said linux walkthrough rooms

#

Not malware analysis

plucky vault
#

okay

forest python
#

Do rooms like kenobi

plucky vault
#

.

#

i don't want to use metasploit

forest python
#

Walked through challenges

#

Elf

#

Stop assuming it has metasploit

#

Have you looked?

plucky vault
#

yes

#

i think

forest python
#

It doesn't use metasploit

plucky vault
#

@plucky vault youtube.com/watch?v=dQw4w9WgXcQ

forest python
#

I know that URL

plucky vault
#

shhh

forest python
#

You can wrap URLs in angle brackets to keep them clickable but not embed

plucky vault
#

woah cool

pulsar smelt
#

XD

forest python
#

Now go start kenobi from the beginning

plucky vault
#

@plucky vault me is not that dumb

#

you tried to copy it haha

forest python
#

DOn't skip over questions because you answered them

#

That's not what starting from the beginning means

plucky vault
#

im not skiping them im gonna do that again just gonna wait a few moments

forest python
#

I'm leaving

plucky vault
#

why ๐Ÿ˜ฆ

#

don't leave me james!! ๐Ÿ˜ฆ

forest python
#

It's 4:44am?

plucky vault
#

its almost 6 am here hahaha

#

don't leave me james!! ๐Ÿ˜ฆ
@plucky vault that sounds like its straight from a romantic movie

#

lol

forest python
#

The story of an elf who keeps stalking a man

plucky vault
#

thats me

#

pubg is free to play rn

#

@plucky vault

#

wait idk can i run it

#

yah i can't

#

im gonna go get washed and go in the bed watch tv and play liveoverflow

#

brb in like 2-3 hours @tame ether

tame ether
#

play liveoverflow
pandawtf

plucky vault
#

Kekw

pastel wave
#

kekw

quiet needle
#

Please try to keep the streaming to THM-related content only @gaunt thunder (:

gaunt thunder
#

sry @quiet needle

quiet needle
#

All good - thanks!

gaunt thunder
#

yup

plucky vault
#

and im back to doing it

muted sand
#

...

plucky vault
#

and im quite liturally stuck

muted sand
#

Have you ran linpeas ?

forest python
#

I mean you skipped over half the doc

muted sand
#

xD

forest python
#

The doc will tell you exactly what you need

#

But you've missed something in your current folder

#

Log in as the current user

#

Because your gid is wrong

#

Elf, you're running a random program

#

A random program isn't going to help you

plucky vault
#

wait what program

forest python
#

the ask password

plucky vault
#

oh

#

i forgot its not sudo ask password

#

but now i just realised

#

im making no sense

#

wow

#

did you see that james ?

#

i learned something from you

forest python
#

I was tabbed out

muted sand
#

those tabs ๐Ÿ˜ฉ

plucky vault
#

๐Ÿ˜ฆ

gaunt thunder
#

did you check out the thing i told u elf?

#

the capabilities thing?

forest python
#

You're not meant to be helping him

plucky vault
#

im still confused

#

this is not wokring

gaunt thunder
#

:/

forest python
#

It does work

plucky vault
#

this linpeas

forest python
#

But you're skipping stuff

#

And focussing on the wrong stuff

plucky vault
#

its cuz i don't know what im looking for

forest python
#

The CVE needs ptrace enabled

#

So you can skip that

#

Because it won't be

plucky vault
#

okay

#

but im hatter

#

and now i need to do

#

this last privesc

forest python
#

Yes

#

So read the output and look for stuff that's actually going to help

plucky vault
#

brb gonna go make cigarete while this is doing its thing

marble cape
muted sand
#

kekw DARKCHAMP DARK MODE

plucky vault
#

pls no ban @forest python

tame ether
#

dark mode soonโ„ข

muted sand
#

Wait, Is elf still not root

plucky vault
#

nope

#

im still hatter

marble cape
muted sand
tame ether
#

B)

muted sand
#

fail kekw

tame ether
#

on purpose

muted sand
#

xD

plucky vault
#

@forest python its done

muted sand
#

Woooo elf rooted

plucky vault
forest python
#

ez
@plucky vault

gaunt thunder
#

LoL eZ

plucky vault
forest python
tame ether
#

that took you only few days

forest python
#

I hope you learned something

spare jay
#

grats Elf!

forest python
#

Otherwise you failed

plucky vault
#

3 days to be specific @tame ether

#

yes i learned alot

#

2 more ways for suid

#

and 1 perl cep

tame ether
#

did you take notes elf?

plucky vault
#

no

#

kekw

tame ether
plucky vault
#

now im gonna do the python one

muted sand
#

good luck elf, I'm doing it now kekw

plucky vault
#

reee ๐Ÿ˜„

#

good luck ๐Ÿ˜‚

muted sand
#

My box has like 4 upvotes already and it hasn't even been released??? kekw

plucky vault
#

lol

#

omg i forgot to upvote the room

#

idk what i have to do

#

xD

tame ether
#

did you finish kenobi?

plucky vault
#

uh

#

no ๐Ÿ˜‚