#voice-chat

1 messages · Page 13 of 1

hardy spoke
#

about smb or what

solid anvil
#

no wait

hardy spoke
#

what happend?

solid anvil
#

okay so i used the dirbuster tool

#

and i found the website 10.10.35.203/upload/

#

but i don't know how to upload the payload on the website

#

you see what i mean ?

hardy spoke
#

there are two upload one on that dir and other on port 5000

solid anvil
#

alright

hardy spoke
#

did you check?

solid anvil
#

yeah

#

i found something else

hardy spoke
#

if you find a exploit of that service wont work

solid anvil
#

no i found the login page

#

on port 8080

hardy spoke
#

yes i know they have funny writing

solid anvil
#

😂

hardy spoke
#

men its a docker container

#

did you get to log in

solid anvil
#

found it

hardy spoke
#

its depressing

solid anvil
#

how about the port 3306 ?

hardy spoke
#

i know its a DB but look this

solid anvil
#

🤣

hardy spoke
#

i did go there you have to upload a image with reverse shell since is php the webpage

solid anvil
#

yeah

#

you were using msfvenom right ?

hardy spoke
#

you have two way one with msfvenom and one with exif

solid anvil
#

never used exif before

hardy spoke
#

exif is for extracting info of pictures but also you can put some stuff on pictures

#

for me is great doing both but with msfvenom did you change the file name to get there

solid anvil
#

damn

#

my wifi crashed

#

i'll finish later

hardy spoke
#

for real that is bad

#

my exiftool method doesnt work here

#

i am gonna leave, need to eat.

#

@solid anvil my reverse shell not working

solid anvil
#

same

hardy spoke
#

i think we need to attack smb

#

since 5000 port is not vuln

#

@solid anvil 🤣

solid anvil
#

😂

hardy spoke
#

another one?

#

@solid anvil Are you gonna do another one?

solid anvil
#

later

hardy spoke
#

okay let me know

plucky vault
#

brb

#

2

#

ssl on

plucky vault
#

@fervent maple ayyy startcraft 2

fervent maple
#

yep

plucky vault
#

@plucky vault try wpscan

#

idk :/

#

@plucky vault yes

#

@plucky vault use wpscan

#

oof

#

smh

#

how do i use that thiing

#

try to find the usernames and bruteforce them

#

billy

#

use wpscan to find the users

#

how do i do that smh

#

wpscan -h

#

good point

#

did you just see this?

#

use --

#

i forgot i can't copy from vm

#

to the thing

#

F

#

--enumerate u

#

don't copy it, type it

#

how what why

#

and its giving me same output

#

only blog.thm

#

not the php

#

YES

#

now brute force them

#

with wpscan

#

huh

#

this is so

#

idk

#

sudo gunzip rockyou

#

lets go

#

im using rockyou

#

👍

#

this will take eternity

#

how long will this take o.o

#

few hours

#

haha no

#

couple minutes

#

o.O

#

i saw we cirlce it around 1 hou

#

add -t 100 at the command

#

nice it crashed

#

SMH

fervent maple
#

100 threads to?

plucky vault
#

the brute force

#

nah the machine crashed

#

i mean the vm

#

im on

#

no point in trying this

#

but don't worry

#

actually

#

idk

#

nwm

#

eh im gonna play a game or somethign

#

@plucky vault thank you for helping 😄

#

i can stream how im trying to find drivers for my usb tho

#

@plucky vault ok have fun

#

ty u 2 😄

cloud fox
#

yo

#

I'm new here

unique harbor
#

what u tryna do @plucky vault

plucky vault
#

dual boot ubuntu

unique harbor
#

u did the new partition?

plucky vault
#

yes

#

yesterday

unique harbor
#

give it a unique name and at least 150GB

#

and it's just as simple as windows installer

plucky vault
#

hhh

#

i know

#

but im still scared

#

kinda

unique harbor
#

i recommend sticking with virtual machines

#

but for more optimization dual boot would be good

plucky vault
#

i cant do virtual machines

#

i think its something with my laptop

unique harbor
#

what software did u use

plucky vault
#

vmware

#

virtual box

#

hyper-v manager

unique harbor
#

have u heard about wsl?

plucky vault
#

yes

unique harbor
#

try it see if it works

plucky vault
#

i cant get wsl 2 because i need build 2004

#

which is not compatible

#

for some reason

unique harbor
#

what kind of error do u get when you install virtual machines

#

hi

plucky vault
#

lemme show u

unique harbor
#

okay

#

did u install the right version

plucky vault
#

yes

unique harbor
#

that goes with the system build

plucky vault
#

no

solid anvil
#

nope

unique harbor
#

well thats weird

#

lmao

solid anvil
#

he didn't put the right settings

#

that's all

unique harbor
#

maybe yah

solid anvil
#

...

#

@plucky vault go to the settings of unbutu

#

turn off the 3d thing

#

then press ok

#

and try

unique harbor
#

that bitch is annoying

#

keep flashing

#

update to 2004

solid anvil
#

do the windows 10 version 2004 update @plucky vault

unique harbor
#

ye

#

p

#

it could take some time

#

depends on ur internet

solid anvil
#

yeah

#

you have an i3 right ? @plucky vault

plucky vault
#

yes

solid anvil
#

damn

#

you have to change that 🤣

unique harbor
#

i think he nees to dualboot cause virtual machines won't be compataible

solid anvil
#

that will takes a lot of space

plucky vault
#

gfdsrdgf

#

aaqaaaserfad;kf;klsdfg;poklsdklo;[g

solid anvil
#

i think they 'll ask you to restart your computer

#

so just restart it

#

if they ask you to

#

i think you should download kali linux or parrot

solid anvil
#

tell us when you're done

plucky vault
#

ok

unique harbor
#

"elevator music"

solid anvil
#

😂

plucky vault
#

its at 100%

#

and its stuck there

#

and i hate it

solid anvil
#

have to wait

plucky vault
#

nvm

#

its at 0% installing

#

dkl;s;jkafsde;kljdfaj;kladgf;kjladfej;kldafg;jksdg

#

the video is almost over

#

brugh

plucky vault
#

i want this update to be doen alreadyyyyyyyyyyyyyyyyyyyy

#

52% installing

solid anvil
#

alright

plucky vault
#

how long does this usually take

solid anvil
#

idk

warm atlas
#

needy

#

joined?

solid anvil
#

yeah

warm atlas
#

ok

plucky vault
#

What machine did you pick @warm atlas

#

?

warm atlas
#

production easy one

#

@plucky vault

solid anvil
#

how many times we did that 🤣

warm atlas
#

then we will move to space jam

#

is that ok?

solid anvil
#

what's that ?

#

is that hard ?

plucky vault
#

Is space jam the SQL one?

warm atlas
#

or lets do food machine

#

thats easy i think

plucky vault
#

That's too easy as well

solid anvil
#

everything is easy for you 😂 @plucky vault

warm atlas
#

smh

plucky vault
#

No, because they are the easiest machines!

warm atlas
#

ye ur right

solid anvil
#

let's do a hard one

warm atlas
#

or lets do

#

shrek

#

seems hard when john hammond do it

plucky vault
#

OK let's do shrek then;

solid anvil
#

ok

#

fine

warm atlas
#

remember to ftp!!

solid anvil
#

^^

plucky vault
#

Who will send the link?

#

I can make a private game if you want.

warm atlas
#

i think me

solid anvil
#

idk

warm atlas
#

either me or rabbit

plucky vault
#

scissor paper rock

warm atlas
#

cuz we have subscription

plucky vault
#

paper

warm atlas
#

u will do it rabbit

#

next round

plucky vault
#

did you choose rock?

warm atlas
#

@solid anvil why u leave

solid anvil
#

miss click

plucky vault
#

Wait do I choose this round?

warm atlas
#

oh kk

plucky vault
#

OK I'll send it.

warm atlas
#

ok ready

#

set

solid anvil
#

wait

plucky vault
#

I have my commands ready

#

All my folders ready

#

bam

warm atlas
#

me too lol

solid anvil
#

which one are we doing right now ?

plucky vault
#

Shrek

solid anvil
#

ok ok

warm atlas
#

huh

#

its production

solid anvil
#

🤣

plucky vault
#

What the hell?

#

??????

warm atlas
#

glhf

plucky vault
#

We just agreed to Shrek.

solid anvil
#

fine let's do the production first

warm atlas
#

next we do shrek

#

@plucky vault

solid anvil
#

😢

plucky vault
#

I just sent the link you ungrateful *******

#

It's starting in 15 seconds.

#

Are you playing @warm atlas

warm atlas
#

ok

#

lets quit

#

and do shrek

#

ok?

solid anvil
#

ok

#

@warm atlas how you que 3 one ?

warm atlas
#

wait

#

@plucky vault why it have passwd

solid anvil
#

the ftp ? @warm atlas

warm atlas
#

no

#

shrek ssh

solid anvil
#

of course 😂

warm atlas
#

huh

solid anvil
#

try to find the private key

warm atlas
#

ahhh

#

cant find it

#

smh

solid anvil
#

gobuster

#

use it

warm atlas
#

i dont think the shrek user have password

plucky vault
#

You don't need the password if you have the id_rsa key guys.

warm atlas
#

huh

#

i do the ssh

#

and i have id_rsa

#

shrek@10.10.246.213's password:

#

@plucky vault

#

watch the stream

#

the hell is that

#

imma go

#

bai

#

maybe after i will play with you

plucky vault
#

-----BEGIN RSA PRIVATE KEY-----
MIIEogIBAAKCAQEAsKHyvIOqmETYwUvLDAWg4ZXHb/oTgk7A4vkUY1AZC0S6fzNE
JmewL2ZJ6ioyCXhFmvlA7GC9iMJp13L5a6qeRiQEVwp6M5AYYsm/fTWXZuA2Qf4z
8o+cnnD+nswE9iLe5xPl9NvvyLANWNkn6cHkEOfQ1HYFMFP+85rmJ2o1upHkgcUI
ONDAnRigLz2IwJHeZAvllB5cszvmrLmgJWQg2DIvL/2s+J//rSEKyISmGVBxDdRm
T5ogSbSeJ9e+CfHtfOnUShWVaa2xIO49sKtu+s5LAgURtyX0MiB88NfXcUWC7uO0
Z1hd/W/rzlzKhvYlKPZON+J9ViJLNg36HqoLcwIDAQABAoIBABaM5n+Y07vS9lVf
RtIHGe4TAD5UkA8P3OJdaHPxcvEUWjcJJYc9r6mthnxF3NOGrmRFtDs5cpk2MOsX
u646PzC3QnKWXNmeaO6b0T28DNNOhr7QJHOwUA+OX4OIio2eEBUyXiZvueJGT73r
I4Rdg6+A2RF269yqrJ8PRJj9n1RtO4FPLsQ/5d6qxaHp543BMVFqYEWvrsdNU2Jl
VUAB652BcXpBuJALUV0iBsDxbqIKFl5wIsrTNWh+hkUTwo9HroQEVd4svCN+Jr5B
Npr81WG2jbKqOx2kJVFW/yCivmr/f/XokyOLBi4N/5Wqq+JuHD0zSPTtY5K04SUd
63TWQ5kCgYEA32IwfmDwGZBhqs3+QAH7y46ByIOa632DnZnFu2IqKySpTDk6chmh
ONSfc4coKwRq5T0zofHIKLYwO8vVpJq4iQ31r+oe7fAHh08w/mBC3ciCSi6EQdm5
RMxW0i4usAuneJ04rVmWWHepADB0BqYiByWtWFYAY9Kpks/ks9yWHn8CgYEAymxD
q3xvaWFycawJ+I/P5gW8+Wr1L3VrGbBRj1uPhNF0yQcA03ZjyyViDKeT/uBfCCxX
LPoLmoLYGmisl/MGq3T0g0TtrgvkFU6qZ3sjYJ+O/yrT06HYapJLv6Ns/+98uNvi
3VEQodZNII8P6WLk3RPp1NzDVcFDLmD9C40UAQ0CgYBokPgOUKZT8Sgm4mJ/5+3M
LZtHF4PvdEOmBJNw0dTXeUPesHNRcfnsNmulksEU0e6P/IQs7Jc7p30QoKwTb3Gu
hmBZxohP7So5BrLygHEMjI2g2AGFKbv2HokNvhyQwAPXDBG549Pi+bCcrBHEAwSu
v85TKX7pO3WxiauPHlUPVQKBgFmIF0ozKKgIpPDoMiTRnxfTc+kxyK6sFanwFbL9
wXXymuALi+78D1mb+Ek2mbwDC6V2zzwigJ1fwCu2Hpi6sjmF6lxhUWtI8SIHgFFy
4ovrJvlvvO9/R1SjzoM9yolNKPIut6JCJ8QdIFIFVPlad3XdR/CRkIhOieNqnKHO
TYnFAoGAbRrJYVZaJhVzgg7H22UM+sAuL6TR6hDLqD2wA1vnQvGk8qh95Mg9+M/X
6Zmia1R6Wfm2gIGirxK6s+XOpfqKncFmdjEqO+PHr4vaKSONKB0GzLI7ZlOPPU5V
Q2FZnCyRqaHlYUKWwZBt2UYbC46sfCWapormgwo3xA8Ix/jrBBI=
-----END RSA PRIVATE KEY-----

warm atlas
#

ye thats wat i found

solid anvil
#

same for me

#

but it's not working

plucky vault
#

This is what I got from the .ssh directory

#

Let's reset?

solid anvil
#

idk

warm atlas
#

here use this command to do privellage escallation gdb -nx -ex 'python import os; os.execl("/bin/sh", "sh", "-p")' -ex quit

solid anvil
#

i think i'm gonna sleep

warm atlas
#

@plucky vault

#

me too lol

solid anvil
#

i'm out 😪

#

see ya

plucky vault
#

I'm already root

#

But is GDB setuid?

warm atlas
#

ye

plucky vault
#

Oh wow it is.

warm atlas
#

i will tell u when i am free later

#

about 30 mins or more

#

bai

#

cya!

plucky vault
#

Probably a better way than doing a reverse shell through that check.sh file in shrek's home directory.

#

Yeah, see ya later.=

warm atlas
#

ready

#

set

#

sapce jam?

#

same one?

#

gtg enjoy the game! i need to go

lofty moat
#

@plucky vault you guys playing?

plucky vault
#

dsflksdlfksdkjlgkljsdglkjsdg

#

YESSSSSSSSSSSSSSSSSS

#

@solid anvil

plucky vault
#

dual boot

full jewel
plucky vault
#

this is my pc

polar raven
#

And your monitor? c:

plucky vault
polar raven
#

putty for windows

plucky vault
#

;w;

polar raven
#

The highly difficult ones yeah

plucky vault
#

hh

#

i wanna dual boot

#

but im scared

polar raven
#

You'll download them when needed

safe plover
#

sudo apt-get install gobuster

plucky vault
#

bvnvbnfghnbvhnfgjm

lofty moat
#

If you are using latest version of kali you don't need to use -get

plucky vault
#

:(

#

i'm starting to give up aaaaaaaaaaaaaaaaaaaaaaaaa

plucky vault
#

im getting very demotivated

#

WAIT WGHAT

#

WHAT

slender kayak
#

7 minutes and I’m there

junior raft
quiet needle
#

@plucky vault people were talking over but let's avoid the homophobia and streaming videos like that

#

PG-13 as well

plucky vault
tardy beacon
#

Sup boomers

cloud fox
#

yo

tardy beacon
#

Is that a french accent I hear?

#

There is some german somewhere, too

tame ether
#

hey hors

tardy beacon
#

Oy

#

I was just passing by ahah, see ya guys
Have fun :)

cloud fox
full sapphire
#

@cloud fox I think 0day may have already warned you, but here's the last one: enough with the excessive swearing, no racism. and I have a sneaky suspicion there may have been a little homophobia earlier.
Last warning

solid anvil
#

cool @plucky vault

cursive herald
#

In this house we use Ciphey angrycooctus

#

oh wait they were banned

#

rip sozzy

rough flax
#

Nope cyber chef only

tribal flicker
#

.

lofty moat
#

you guys playing KoTH?

#

@slender kayak i am always up for a koth match

#

and i don't talk 😄

#

sure

#

should i make a private game? @slender kayak which machine you wanna play?

#

i know every box. almost every way in.. asking you

plucky vault
#

can attest my pc is also a potato

lofty moat
#

lets go random

plucky vault
#

You know every way in? 👀

lofty moat
#

You know every way in? 👀
@plucky vault Almost

plucky vault
#

teach me senpai uwu

lofty moat
#

i started THM 3months ago.. i used kali 4 years ago for a year or two.

#

also i am a Computer Science student. Last year in uni

plucky vault
#

I'm in software engineering lol 2nd year now

#

but I didn't use kali for anything :/

lofty moat
#

i just used it as a hobby

plucky vault
#

I just started using when I joined THM 3 weeks ago lol

lofty moat
#

for trojans and phishing stuff mostly at that time. learnt to use metasploit and few other tools at that time

#

hackers can be rooted in 1 minute

plucky vault
#

That's rather interesting, if I didn't have so much coding stuff to do meh

lofty moat
#

but with brute force ^

#

I didn't saw

#

btw showing real name is not that much of a security breach

junior raft
#

yo guys does any one know how to install league of legends in parrot (sorry for th3 question out of context )

lofty moat
#

i use rockyou with -t 64

#

Holmes spying in

fast wind
#

LoL

lofty moat
#

increase the threads

#

to -t 64 @slender kayak

#

wait you are doing it wrong

#

plague is not an ftp user @slender kayak

fast wind
#

That's what I was thinking lol

lofty moat
#

you logged into ftp using the credentials you found?

#

what are you doing rn?

#

before that try looking for sudo -l ?

#

@slender kayak ^^^

#

oh you are rcampbell i thought you logged in through gcrawford

#

@slender kayak dont brute force ftp but ssh now

#

yeah you will get your key from there

#

meanwhile look for privesc from other shell you got

#

if you want there is a writeup for Hackers

#

search for Hackers in hacktivites

#

yeah python

#

password is different everytime @slender kayak

#

new password every time

#

so old ones wont work

#

yeah you can use that to privesc

#

@slender kayak

#

@slender kayak read that page again.. at the end of the page just use last line of it

#

python3

#

now the most difficult part starts in KoTH

#

fighting for king

#

@slender kayak

ancient olive
#

i wondered how many message did u send @lofty moat

lofty moat
#

aloot

#

i dont talk

#

😄

#

yeah

#

renamed actually

#

so i can use it and other can't

#

well you rooted it soo GG

#

i m there

#

refresh

slender kayak
#

are you patching?

lofty moat
#

in carnage?

#

@slender kayak

slender kayak
#

yep, but you weren't

lofty moat
#

i just patched all of the privescs

#

if you can privesc let me know

slender kayak
#

i'm trying to dump web.db

#

i think that duku is a bit useless

lofty moat
#

i patched all of the methods to get root

#

for every user

slender kayak
#

oh

#

well i'm out hahah

#

is the bobba password actually the flag?

vernal tide
#

.

plucky vault
#

i'll be right back

#

@plucky vault

#

all good.

plucky vault
#

potato pc

solid anvil
#

i'm coming later

tame ether
#

@plucky vault join me pls

midnight fern
#

@plucky vault

#

I thought we were closer than that.

plucky vault
tame ether
#

try harderererererererererererererererererererererererererererererererererererererererererererererererererererererererererererererererererererererererererer

midnight fern
#

try harderererererererererererererererererererererererererererererererererererererererererererererererererererererererererererererererererererererererererer
@tame ether nope

#

That’s an odd number

tame ether
#

do it

#

try hardererererererererererererererererererererererererererererererererererererererererererererererererererererererer

midnight fern
real orbit
#

crackheads.

rustic mica
#

@midnight fern Can Elf get mod?

tame ether
#

Elf for admin 2020

fathom coyote
#

Elf for server owner. He will do a shredding good job!

midnight fern
#

Elf has my vote for sure

real orbit
#

"Will Hack 4 Crack" -Unknown

midnight fern
lapis furnace
#

get your ass in the god damn ...

lofty estuary
#

lucky guy

real orbit
#

0Day's Florida Man birthday ^^

midnight fern
#

5 Kudos to Cophe

tame ether
#

pin dat

lapis furnace
#

sweet sweet kudos

rustic mica
#

@midnight fern I got some Zero Cool stickers with your name on them.

lapis furnace
#

"Florida Man Arrested For Allegedly Assaulting Girlfriend While Dressed As Dinosaur"

fossil estuary
tame ether
#

that looks cool @rustic mica

sweet vapor
visual wyvern
tame ether
#

is there a link to buy them?

fathom coyote
sweet vapor
fathom coyote
rustic mica
#

@tame ether I am building the store still but I am happy to post them out to THM boiis before the store goes up.

fathom coyote
#

Ultimate picture that embodies Florida man ^

tame ether
sweet vapor
rustic mica
#

DM me if you want some and we can figure it out there @tame ether

tame ether
#

:)

real orbit
#

cat-amine

marble cape
midnight fern
#

Go to #streaming

fathom coyote
#

@marble cape This is THM-chan

tame ether
#
,@,_,--------_,,,,,,_---------------
|©©©%%%%%%,;;;;;;;;;;;;;!!!!!!!!!!!|
/©%#####/;;;;;;;;;;;;;;;;},!!!!!!!!|
|#####c/;;;'  "`'''''``'';;\!!!!!!!|
|###<?(;;;    """"        \},!!!!!!|
|###C/;;;    """""""      ";\!!!!!!|
|####|;;;    ___ """"      ;;!!!!!!|
|####|;;;,  `___'-   -;;'= ;/!!!!!!|
|####\;;;   <****>``;<**>  ;)!!!!!!|
|##_,,\;     """"/   \``   |!!!!!!!|
|#//   \  ,""",`/,   )\,   |%!!!!!!|
|`)`'-''\ """/,_______,)   /#%,!!!!|
| |######\""""`\;;;::;`/  /##%%%,!!|
| \#######},""" ``''` /"'/######%*`;
| |%%%####) \"""",_,""",{######    #
| `-_%-¿`{   `-,___ _-` |¿¿`-/_    #
|,`¿¿¿¿¿¿¿\        `    /¿¿¿¿¿¿¿'-,#
|¿¿¿¿¿¿¿¿¿`\         ,-'¿¿¿¿¿¿¿¿¿¿¿|
''''''''''''''''''''''''''''''''''''
#

@marble cape :)

forest python
midnight fern
#

Goodnight VC Gang

#

@fathom coyote I love it!

fathom coyote
#

Night 0D

plucky vault
#

/

lofty moat
lofty moat
#

see ya guys i'm going to a friend's place @plucky vault see you guys at night

#

Attackers exploit buffer overflow issues by overwriting the memory of an application. This changes the execution path of the program, triggering a response that damages files or exposes private information. For example, an attacker may introduce extra code, sending new instructions to the application to gain access to IT systems.

#

@plucky vault

plucky vault
#

@plucky vault my mic is broken lmao hf

#

its fine

#

lol

#

you can join if you want

#

Nah I was just taking a look 😛

lost current
#

hi

#

i don't

plucky vault
#

why do people always mute and or deafen them selfs when they join?

ancient olive
#

because they dont want to speak or hear something

#

i must to go

#

bye

oak bridge
plucky vault
#

idk

#

do you guys see stream?

fast wind
#

Hey @lofty moat

lofty moat
#

Yo

fast wind
#

@raven verge which room is that?

raven verge
#

set

#

new room

lofty moat
#

Windows room

#

Came out last night

raven verge
#

yea hard af xD

fast wind
#

Ooo

raven verge
#

icmp is blocked already with not many ports open lol

fast wind
#

Windows, ah, m out xD

#

I hate windows more than I hate pineapple pizzas

full sapphire
#

Set is an incredible piece of work

fast wind
#

No hatred on box..

I just hate windows boxes..

.. Cuz I can't solve them.

raven verge
#

its really hard :((

full sapphire
#

I'm not giving any hints until 4ndr34z or theart42 allow it 🤷‍♂️

raven verge
#

is llmnr on right track at least? xD

raven verge
muted sand
#

I hate windows more than I hate pineapple pizzas
@Mr.Holmes#0980 you take that back right now

worthy bronze
#

I hate windows more than I hate pineapple pizzas
@fast wind pineapple on pizzas >

fast wind
#

@fast wind you take that back right now
@muted sand 😂😂😂

worthy bronze
#

what room are u doing @raven verge ?

austere viper
#

/set

raven verge
austere viper
#

PORT STATE SERVICE VERSION
135/tcp open msrpc Microsoft Windows RPC
443/tcp open ssl/http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
| ssl-cert: Subject: commonName=set.windcorp.thm
| Subject Alternative Name: DNS:set.windcorp.thm, DNS:seth.windcorp.thm
| Not valid before: 2020-06-07T15:00:22
|_Not valid after: 2036-10-07T15:10:21
|ssl-date: 2020-07-25T17:56:58+00:00; 0s from scanner time.
| tls-alpn:
|
http/1.1
445/tcp open microsoft-ds?
5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
49666/tcp open msrpc Microsoft Windows RPC
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: specialized
Running (JUST GUESSING): AVtech embedded (87%)
Aggressive OS guesses: AVtech Room Alert 26W environmental monitor (87%)
No exact OS matches for host (test conditions non-ideal).
Network Distance: 2 hops
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb2-security-mode:
| 2.02:
|_ Message signing enabled but not required
| smb2-time:
| date: 2020-07-25T17:56:18
|_ start_date: N/A

TRACEROUTE (using port 443/tcp)
HOP RTT ADDRESS
1 107.46 ms 10.8.0.1
2 108.12 ms 10.10.96.194

OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 2

buoyant lichen
#

ayoo

wispy path
#

lul

buoyant lichen
tame ether
#

wtf

#

@wispy path you alright mate?

#

i think you want to get banned

wispy path
#

lol

trim cloudBOT
#

Rule 16 does not exist.

tame ether
#

not accepted yet kekw

buoyant lichen
#

tl;dr - no spamming

raven verge
worthy bronze
#

135/tcp open msrpc Microsoft Windows RPC
443/tcp open ssl/http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
445/tcp open microsoft-ds?
5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
49666/tcp open msrpc Microsoft Windows RPC

lofty moat
worthy bronze
#

kano

full sapphire
#

Would you prefer they were dead? 🤔

fresh solar
#

👀

worthy bronze
#

why is everyone live?
@lofty moat ¬¬

lofty moat
#

??

raven verge
#

we are playing the SET box

austere viper
raven verge
polar raven
#

Why is dirb searching for people names??

austere viper
lofty moat
#

voice gang is here 👀

tame ether
#

we moved for few minutes

lofty moat
#

Imagine not using tmux in 2020

tame ether
#

excuse me?

lofty moat
#

stream

tame ether
#

i am not using tmux GWcorbinANGERY

lofty moat
#

thats sad

#

really

#

oh i forgot.

#

tmux for 18+

#

my bad

tame ether
#

lmao

lofty moat
#

adult tools 🤣

tame ether
#

you missed something naughty lmao

lofty moat
#

👀

#

wat

tame ether
#

I'm already an adult sunglas

#

i just don't like tmux kekw

lofty moat
#

I'm already an adult :sunglas:
@tame ether waiiiit what

#

nooo

#

you lying

#

naaah

#

i dont believe ya

tame ether
#

lmao

scenic sky
#

what's going on here?

full sapphire
#

!rule3 please 🙂

#

!rule 3

trim cloudBOT
#

Rule 3: No excessive self promotion. Linking to another discord server is strictly prohibited, just don't turn it into advertising.

full sapphire
#

That's the one

austere viper
#

apologies, lesson learned.

plucky vault
#

u guys are awesome. i wish i could learn all this. such a great community

full sapphire
#

@austere viper No problem 😄

west sphinx
#

idk why I got muted in the server

full sapphire
#

Lemme check if there was a reason 🙂

west sphinx
austere viper
worthy bronze
autumn quest
#

RustScan

raven verge
merry valve
#

shooting bazooka with -A

merry valve
#

is that some type of buffer overflow

#

?

fossil estuary
warm atlas
#

another skidy

#

👀

fossil estuary
austere viper
#

thanks guys! 4am, I'm out. See you tomorrow.

polar raven
#

Szy, any difference in command netcat and nc??

#

Noted!

lethal nimbus
#

no

lofty moat
#

i'm able to see it

#

@slender kayak it isn't your issue

#

i can watch the stream

#

@plucky vault leave and rejoin

#

brb

plucky vault
#

Thank you.

lofty moat
#

@slender kayak share game invite? or you are doing hackers room?

#

from which user?

#

linEnum / linpeas would be enough

#

run tmux or add the output of linpeas in a file

#

oh in tmux you can with Ctrl+B + [

#

Ctrl+b is your prefix

#

what is your prefix?

#

prefix for tmux

#

like what you use to make a new window

#

aah ok

#

oh in tmux you can with Ctrl+B + [
this enables copy mode

#

then you can scroll

#

and press Q to exit

supple trellis
#

prefix + : type set mouse on

lofty moat
#

if anyone wants to play KoTH just ping me..

#

@slender kayak show me the linpeas output

#

ok @slender kayak

#

you saw that capabilities

#

look for capabilities

#

sure

#

starting in 6 minutes

#

public random

#

sure

#

do whatever you want

#

i can join

#

@summer cloud if you ever plan to play KoTH ping me i want to see you in action

#

also got some a few things/questions for that "backdoor"..

#

@slender kayak you making a private lobby? or you guys just gonna play on your own?

slender kayak
#

we are in a private call on discord rn

summer cloud
#

@summer cloud if you ever plan to play KoTH ping me i want to see you in action
@lofty moat Will do my dude

slender kayak
#

we are going to make a koth later because we are doing a room now

lofty moat
#

ohk

mellow frigate
#

hi

#

just don't want to turn mic on now

supple trellis
#

@sweet vapor find /home -ls

keen perch
#

Can someone please tell me what a KOTH is? Please!!!

tame ether
#
King of the Hill (KoTH) is a competitive hacking game, where you play against 10 other hackers to compromise a machine and then patch its vulnerabilities to stop other players from also gaining 
access. The longer you maintain your access, the more points you get.```
keen perch
#

Ah got it now.

#

Ok ok.

#

Thank you

#

Can you do it in group or alone?

tame ether
#

there have to be at least two users in a lobby for the game to start

keen perch
#

That’s great.

#

I liked it.

#

Another question, is anyone doing live for KoTH anytime soon?

#

So I could follow how that process works

plucky vault
#

yo

supple trellis
#

gtfobins

tame ether
#

what's happening in VC? 👀

supple trellis
#

nothing 👓

fresh solar
#

👀

tame ether
#

you better not be doing crack again AngryThonk

fossil estuary
raven verge
#

active directory

fossil estuary
lofty moat
#

@fossil estuary you teaching something? 👀

raven verge
#

we talking

#

vc

lofty moat
#

aah but i don't talk

fossil estuary
#

@lofty moat always 😄

#

i think ive heard you talk twice @lofty moat lol

raven verge
#

@lofty moat I heard your a pro at KOTH xD

lofty moat
#

saying "Hello" isn't really talking xD

#

@lofty moat I heard your a pro at KOTH xD
@raven verge you heard it wrong. someone must have lied to you

fossil estuary
worthy bronze
lofty moat
#

which room you guys talking about?

remote arrow
eternal crane
#

hi

remote arrow
#

hi

austere viper
#

hi

south elk
#

hellllllooooooo

austere viper
#

hey matt

lofty moat
#

hi

austere viper
#

welcome Naughty!

weak escarp
#

hi

austere viper
#

👋🏼

lofty moat
#

Bye

plucky vault
#

.

lofty moat
#

@worthy bronze which room you guys talking about?

worthy bronze
#

@worthy bronze which room you guys talking about?
@lofty moat set man

royal gust
cursive herald
#

@royal gust Have you tried the VPN script at all? 🙂

#

!vpnscript

trim cloudBOT
royal gust
cursive herald
#

dpkg -i

#

to install a .deb file

real orbit
#

or apt install ./package.deb 👀

cursive herald
#

or apt install ./package.deb 👀
@real orbit is there a difference? interested since i suggest to use dpkg for my packages 🙂

real orbit
#

nop, Just throwing out alternatives 👀

cursive herald
#

@remote arrow what country?

royal gust
#

It was a lot of fun guys. ty for the assistance earlier.

plucky vault
#

Are we allow to stream KOTH in General?

real orbit
#

@plucky vault ye blobfingerguns

plucky vault
#

@real orbit Thank you for the quick reply XD

real orbit
fast wind
#

Oi @rustic mica wyd?

rustic mica
#

Making wallpapers for THM :)

fast wind
#

noicee (jake mimic)

#

GIMP/ADOBE classes by @rustic mica 101

rustic mica
#

Adobe all the way <3

#

I need pars' one.

fast wind
#

xD

rustic mica
lofty moat
fast wind
#

lmao

lofty moat
#

Totally not stolen

fast wind
#

I made in GIMP

#

@rustic mica is an artist!

rustic mica
#

<3

lofty moat
#

They look awesome 💙

ripe rover
lofty moat
fast wind
#

Man this is some high level photoshopping skills.

#

That pink block in b/w images was to maintain same distance, I just realised that! @lofty moat (atleast I think so)

lofty moat
#

lol

rustic mica
#

Hahaha, yeah it's a sneaky easy trick in web ui design.

lofty moat
#

thats really some high level stuff

#

yeah it was to maintain equal distance

rustic mica
#

Now it is just finding the correct filters to make it pop.

#

What do you think of the sand?

#

I'll take it over to photoshop to finish it off.

fast wind
#

Dope, it is giving a feel of water 🤔

lofty moat
#

its awesome

#

Do whatever you think will be better

#

without cookie green one?

fast wind
#

You sure you are sharing right window?

#

I was like, mouse is moving, he is saying stuff, but it doesn't make sense

#

LOL

#

Ah, that sneaky one on taskbar now makes sense that I can see it

rustic mica
#

@plucky vault You wanna pop in and see the thing? :)

fast wind
#

Thanks for the Photoshopping class 😂

#

sure cya!

raven verge
real orbit
#

Hey @jovial escarp, I'm gonna have to ask you to stop DMing The Mayor about things related to other servers. Continuing to do so will lead to you being removed from the server again. He asked several times for you to stop, so please stop. Thanks.

jovial escarp
#

I was talking about his server not this, this server has nothing to do, no need to ping me tho, already talked with Darkstar

#

I stopped anyway

#

I think this is what I should do as a former member of HIS server, let's not bring this here tho, you could DM me instead

real orbit
#

The point is, he asked you to stop, so please stop.

digital light
#

hi

jovial escarp
#

So I did

digital light
#

feel me in too

jovial escarp
#

I'd block instead

real orbit
#

Good, and I might also mention -- he doesn't owe you anything. That attitude is gearing towards entitled individuals and we don't welcome that here.

jovial escarp
#

No problem, he clearly has his own rules and I should respect them because it's his own community

#

I'd recommend anyone who is against a server's rules leave it

raven verge
raven verge
#

import-module .\filename.ps1

#

powershell import-module .\filename.ps1; Invoke-AllChecks

#

get-service

raven verge
#

windows/powershell_reverse_tcp

plucky vault
#

wot u guys doin

raven verge
#

SET

plucky vault
versed granite
#

@raven verge just wondering -- did you ask the room creator before streaming this? You're effectively creating a live walkthrough of a brand new room

raven verge
#

@versed granite The room creator joined the stream few times and didn't say anything

#

Also I'm new here so if this is against the rules etc I will stop streaming

#

I can see it being a problem tho

versed granite
#

i'm not a moderator or anything, so I was just asking. It might be best to ask the room creator first. I think there's a restriction on sharing that content so early

full sapphire
#

I'd consider it a group collaboration myself -- as long as it's not getting recorded.
If 4ndr34z and theart are happy with it then it should be Ok 🙂

#

The restriction on writeups is up to the room creator as well

raven verge
#

I was not recording.. yes it was a group collaboration many people gave ideas on the way to solve parts of the challenge

#

I do see it being an issue if people just watch stream to copy flags/creds etc

full sapphire
#

How's it going anyway?

raven verge
#

I found exploit for privesc 😄

full sapphire
#

Ey

plucky vault
#

@fervent maple should i stream in other server?

fervent maple
#

everybody went to bed

plucky vault
#

yes

#

i just woke up

fervent maple
#

just trying to fix my script

plucky vault
#

nice 😂

tame ether
#

what are ya streaming elf?

warm atlas
#

Just finish that room tho

plucky vault
#

.

buoyant lichen
#

\

abstract raft
#

U guys doin hacktivitycon?

austere viper
#

what is that?

plucky vault
#

bruh

tough lake
#

gobuster dir --url -w /usr/share/wordlists/dirbirectory-list-2.3-medium.txt

woven coyote
#

vampire

#

ls -la

#

.flag

#

cat ./.flag

clever parcel
#

hey @zealous leaf

#

hey @worn shore

#

I'm watching stream

#

try sudo su

#

sudo su

#

then you will not want to write sudo everytime

#

hey @worn shore do you still have that bootable pendrive wtih you?

#

you can re install kali with it

#

with all the resources

#

so you don't have to everytime install the requirements everytime you do something

#

leave domain name for now

#

well can you help me with ssh ?? @zealous leaf

#

ok thanks

#

well the problem is that

#

I don't know how to ssh

#

😅

#

not even hydra😅

#

parenthesis

#

()

worn shore
#

<>

zealous leaf
#

ssh <username>@<IP> -p

clever parcel
#

well I don't know how to identify the elements

#

ohh ok

zealous leaf
#

ssh user@ip

clever parcel
#

for the passwords??

#

ohk thanks

#

ohk

#

well I'll stream in a min

#

will you be there??

#

ok thanks

#

me??

#

oh ok

rough flax
#

@marble cape just use rainbow tables like a true alpha

real orbit
#

@rough flax im probably gonna install python on the box and do it in that lol

rough flax
#

yes python on a production web server...

#

why isnt powershell working?

real orbit
#

it runs too fast

#

executing tasks individually - too slow

rough flax
#

put a sleep on it

real orbit
#

multi processing - too fast, literally breaks

rough flax
#

dont multi process ree

real orbit
#

ive tried delays

#

it still go brrr

rough flax
#

why?

real orbit
#

still too fast

#

it needs to delay the spawning of the procees, but that clearly doesn't work

rough flax
#

DelAY

#

I swear I'm actually going to kill you spooks

real orbit
#

powershell isnt as robust as literally anything else

rough flax
#

if you need to put python on it do it

#

no powershell is bae

real orbit
#

its good for sys admin

#

but not for hacking :L

rough flax
#

True

#

its helpful for working with AD

visual wyvern
#
marble cape
visual wyvern
plucky vault
#

Good mornings guys

clever parcel
#

hey @zealous leaf I'm not able to ssh into my home PC

#

I'm doing the

zealous leaf
#

w8

clever parcel
#

ssh <username>@<IP>

#

ok

plucky vault
#

Hey!

#

No TTS here? 😄

tough lake
#

hi

sonic pebble
#

hi

#

xD

tough lake
#

hi

tough lake
#

hello @ancient olive

ancient olive
#

hello @tough lake

tough lake
#

wanna play?

#

ok u already in

#

but take it easy cause im a beginner

ancient olive
#

@tough lake wat is ur name in THM

tough lake
#

UM240

ancient olive
#

ok

#

@tough lake do u want to learn??

tough lake
#

of course

#

yes please

ancient olive
#

ok

tough lake
#

i got to the ftp

ancient olive
#

lets do one together

#

join @tough lake

tough lake
#

i did

ancient olive
#

ok

tough lake
#

so what machine are going to learn

#

can speak on the voice chat?

ancient olive
#

LOL

#

its windows machine

tough lake
#

oohh bro

#

ok

ancient olive
#

can speak on the voice chat?
@tough lake i have guest

tough lake
#

ok

ancient olive
#

ok i will learn u how to exploit that

tough lake
#

got it

ancient olive
#

but in PrivEsc side u most to run winpeas on it

#

sudo nmap -sS -sV -sC -Pn <machine_ip>

#

try this on all of the boxes

#

it will show u open ports

tough lake
#

ok

ancient olive
#

-sS -> doing syn scan

tough lake
#

i did

ancient olive
#

-sV -> doing service scan

tough lake
#

what syn

ancient olive
#

-sC -> will scan for default scripts

#

what syn
@tough lake its related to Network+ course

tough lake
#

ok

ancient olive
#

but will tell u

tough lake
#

good

ancient olive
#

when u are scanning for ports

#

u will send them a message (SYN)

tough lake
#

aaaa

#

yes

#

i do remeber

#

now

#

its called check hands

ancient olive
#

if they recieved that they reply (SYN ACK)

#

else they will send another thing

tough lake
#

and the -Pn

ancient olive
#

-Pn its just for filtering

tough lake
#

ok

ancient olive
#

my country is filtering scan

#

so in my country we must use -Pn

tough lake
#

ok

ancient olive
#

u dont really need to do that

#

but i must use that

fresh solar
#

No

ancient olive
#

yes

#

it is

fresh solar
#

-Pn is for machines that do not respond to icmp echo requests

tough lake
#

i got the results from the nmap scan

#

now

#

?

fresh solar
#

Check your sources, before misleading others.

ancient olive
#

ok

#

but people in here say its because filtering

#

dont sure about it

fresh solar
#

Then they're wrong.

ancient olive
#

maybe

tough lake
#

it is not what we are talking about

#

we can continue

ancient olive
#

ok

#

and --script will use the nmap script (NSE)

#

NSE mean nmap script engine