#voice-chat

1 messages · Page 24 of 1

earnest sail
#

and how can i enter?

hot snow
#

!docs verify

trim cloudBOT
hot snow
#

@earnest sail You have to verify

earnest sail
#

ah, okay

#

done

#

thank you

mighty junco
#

@plucky vault use -T4

plucky vault
quiet needle
#

hey!

#

sorry, text chat only atm

#

What's up? (:

#

@limpid badger 👋

limpid badger
#

hello bro

quiet needle
#

hey! (:

#

I can give it a try -- bare with

#

Ah okay. That's probably a result as how the rooms were split up

#

I'll take a look (: thanks!

#

Hehehehe if only 😛

#

I'd of had it a long time ago!

#

you get my thanks (:

limpid badger
#

btw could you find the binary "shiba4"?

quiet needle
#

Aye, I'm just deploying & having a look at it now

limpid badger
#

ok, maybe i am to stupid for that XD

quiet needle
#

I'm pretty sure that's been removed on purpose as it was a bit too challenging for the purpose of the room

#

but I'll double-check (:

limpid badger
#

ok, but then i cant finish the room

#

i need the password from the binary

#

@quiet needle thx for your time

plucky vault
#

anybody can help with this?!

muted bridge
#

😆

quiet needle
plucky vault
#

@quiet needle go on bro , Nmap room

quiet needle
#

The box is offline

plucky vault
#

offline?

#

how!?

quiet needle
#

I think that's one I've gotta apply a licensing fix too

plucky vault
quiet needle
#

Windows VM's will terminate after an hour if I haven't applied the licensing fix

#

Terminate and redeploy, I can't start those vulnerable instances from the back-end

#

The attackbox won't make a difference in this case @muted bridge

limpid badger
#

ls -al /usr/share/nmap/scripts/ | grep -e "ftp"

quiet needle
#

Yeah I have (: l know the issues. I'll have to make changes to the box which I've put on my to-do for early next week @limpid badger

full sapphire
quiet needle
#

Yeah it is (: I don't have total control over instances the VPC that vulnerable instances deploy in for users

full sapphire
#

Ah, fair

limpid badger
#

guzs

#

guy

#

can i get the password then from you?

#

i did the room before

#

but got resetted

quiet needle
#

It'll be the same as it is for zthlinux

#

but other than that you'll have to wait until I get the time to sort it out over the next few days I'm afraid

limpid badger
#

ok

#

i will just google it >D

#

😄

quiet needle
#

Unless I'm understanding you wrong? 😅

limpid badger
#

i could not find it xD

#

and the test directory was there right? and the file inside the directory right?

#

test1234

quiet needle
#

yup (: I'm pretty sure that's on purpose

limpid badger
#

ok

quiet needle
#

You've just gotta find the binary (:

limpid badger
#

wuahhah

#

dont take my honor bro 😄

quiet needle
#

😄 thanks for asking though -- I can see how it isn't so clear so I'll see if I can make it a bit clearer in the task

#

You'd be very surprised at how well that works. Look like you know what you're doing and that you're supposed to be there...you're 95% of the way done @plucky vault

#

People assume you're in their best interest

plucky vault
#

😄

#

@quiet needle so are you interesting in Pentest?

muted bridge
quiet needle
#

I have a degree in cyber security & work at THM -- I think it's safe to say yes ahaha @plucky vault 😄

plucky vault
#

🤣 oh yeah

muted bridge
quiet needle
#

I work full time @limpid badger so yeah a salary

#

pretty cool place to work for I gotta say

#

Sure

#

I started making rooms for THM as a community member

#

after a couple of good ones (the malware stuff), they invited me into the comissioned creators programme (where you get paid on rooms that you make)

#

was active in the discord as a community mentor and then got to moderator

#

after graduating from Uni, got offered the role I'm in at THM (:

#

that's basically a TL;DR 😄 ^

#

Yeah -- it's a great opportunity!

muted bridge
#

nice

quiet needle
#

I applied for a couple of red team & blue team roles that I was in the interview processes for

#

Dropped them once the offer from THM was given to me

#

75%+ of the content is free (:

#

Who is having issues subscribing?

#

Ah I see

#

Can I PM you a month voucher?

#

ahahaha

#

Ruby, I'll PM you shortly (:

#

Hope you find the subscriber content fun!

#

The resource boost that instances that you deploy get (i.e. more RAM = faster boot times especially for windows) and multiple attackbox deploys are worth it in itself

#

Let me know how you get on with the content @plucky vault (:

#

Good luck with your exams too

plucky vault
#

@quiet needle sure thanks

quiet needle
#

Feel free to show using NMAP on any vulnerable THM instance @dawn pond

#

Moderators/staff have no way of proving that you have got their consent (:

#

(even if you actually have)

#

Yes (:

#

I think I get what you mean

#

Well a) applications mostly don't care if there's actual routing between computers/devices - that isn't the application's responsibility to worry about

b) There are many services & background tasks running in Windows that will have network connections that you're seeing

#

i.e. windows defender ruleset updates, windows updates. Services including DHCP, WINS & netbios

#

The application will do all of that (encrypting, etc) before it's sent over a network. If it's actually sent -- it's not the application to determine

#

If that makes sense?

plucky vault
quiet needle
#

That'd be at both layer 6 & 7. It's only until Layer 4 where actual networking protocols are used -- that's way past the responsibility of an application

plucky vault
#

@quiet needle yeah i understand

#

at lest thank you for conforming my question

quiet needle
#

It's all good 😄 hopefully I understood your question right

#

Even in English it's very hard to explain technical things so don't worry

#

Definitely @plucky vault

#

Now that you've got a THM sub, check out my malware rooms (:

full sapphire
#

!rule 3

trim cloudBOT
#

Rule 3: No excessive self promotion. Linking to another discord server is strictly prohibited, unless you have the infosec-developer role and the server is being linked as a resource to provide help with a specific tool (e.g. linking the Ciphey official Discord server for help with Ciphey). Don't turn it into advertising.

full sapphire
#

Yay, I got it right

quiet needle
plucky vault
#

🤣 🤣 🤣 🤣 🤣 🤣 🤣 🤣 🤣 🤣 🤣

quiet needle
#

Oh Muirl (':

full sapphire
#

What did I do now

quiet needle
#

I'll remember that

#

Anyway, you get the idea @plucky vault xD

plucky vault
#

hall to @full sapphire

#

LOLLLL

quiet needle
#

The worst he can do is ban me from here -- suddenly that makes my to-do list a bit smaller 😄

#

Haha nope! I think that's Disqus 😂

plucky vault
quiet needle
#

The little comments section I think is what the JS file is (I hope oof)

#

Hahahaaha 😂

#

social engineering 101 😉

#

jkjk ofc

#

just proves how easy it is though huh

#

very scary

#

My site's static HTML so nothing's been compromised dw

#

no PHP 😄

#

Here's the malware rooms though if you're still keen (most are subscriber only)

muted bridge
#

cherrytree

quiet needle
#

You analyse malicious PDF's, MS office macros & analyse the memory of a machine infected with the Jigsaw ransomware

#

but that's just my biast opinion 😄

plucky vault
#

i save it for forther study , sure

quiet needle
#

malremnux and the mal introductory are the most hands-on rooms so far

#

Ahaah! 😄

#

Lucky it didn't encrypt all!

#

Hehe -- not necessarily!

#

I studied malware analysis for two years at Uni but that doesn't mean I'm safe from it

#

I'm very sure you know a lot more about other things that I'd be jealous about so don't worry @muted bridge

#

Hehehe 😄 I don't use the roles I have as bragging points at all

#

Nah, it's just being mature & modest about what you know

#

But I see your point 😄

#

You'll see people who are just 0XD G0Ds and much better pentesters then I am

#

It's all about perspective

#

Exactly 😅

#

I value myself on what I can confidently talk about rather than what my roles/position suggests

#

Why would you need to DNS Spoof? @dense ledge

#

Yeah, we're not gonna help you with that

#

Mods/staff have no way of verifying the permission that your "friend" may or may not have given you

#

At the risk of myself mini-modding

#

Thanks @dawn pond @plucky vault (:

full sapphire
#

Eh, I'm gonna say ex-mods are gonna struggle to minimod, with few exceptions

plucky vault
#

i told you dude , i'm honest with myself and others 😄

#

yeah dont ban him

#

😦

#

i'm gonna crying..

#

😭

quiet needle
#

🤣

#

Don't we all...

plucky vault
#

dog0gy

quiet needle
#

Bug bounty seems like a lot of web app pentesting and oof

#

that's my worst topic 😂

#

Assembly 😄

limpid badger
#

@quiet needle bro in the linux fundamentals 3 on task task 12 there is text on the right side of the picture

#

but maybe it is only my resolution

#

do you have the same problem?

dense ledge
#

0101001

quiet needle
limpid badger
#

yes

quiet needle
#

Fixed (: give it a refresh

#

nice find

limpid badger
#

thx bro your the best of the west

quiet needle
#

lemme see if I can sort out my microphone

limpid badger
#

would be awesome >:D

#

😄

limpid badger
#

@quiet needle your discord badges 😄

night geode
#

Where can I get support for my streak?

quiet needle
night geode
#

Thanks!

quiet needle
#

include your THM username as well please @night geode (:

muted bridge
quiet needle
quiet needle
#

wait my mic has died

#

I've been muted for like the last 10 mins LMAO

#

bare with

limpid badger
#

Russia’s meddling in the United States’ elections is not a hoax. It’s the culmination of Moscow’s decades-long campaign to tear the West apart. “Operation InfeKtion” reveals the ways in which one of the Soviets’ central tactics — the promulgation of lies about America — continues today, from Pizzagate to George Soros conspiracies. Meet the KGB ...

▶ Play video
#

@quiet needle

quiet needle
#

Ah wicked! I'll give that a check

azure moss
opal ibex
#

nice

plucky vault
#

Copy that url and replace that digit with FUZZ and try wfuzz attack

#

@hidden marten

#

wfuzz -c -z file,/usr/share/wfuzz/wordlist/general/common.txt --hc 404 "http://" Your_Machine IP/and continue your url

#

@hidden marten

south glen
#

try sha1

plucky vault
#

wanna play koth?

lofty moat
bright wyvern
#

that should be better

plucky vault
#

sry we don't know

#

both anonymous

#

@lofty moat wonna vc later?

lofty moat
plucky vault
#

when i catch sleep

#

and then wake up

lofty moat
#

ok

plucky vault
#

idk time is wierd

#

today i think tho

#

🤔

lofty moat
#

the prizes are also good for the event. 1st prize is 500$ and 2nd 250 , 3rd 100$

#

also lots of other stuff with it

#

For details ^

#

@plucky vault ^

quiet needle
#

If you guys are still in VC in like an hour or so I'll hop in (:

plucky vault
#

yesir

opal ibex
#

hi

plucky vault
opal ibex
#

how to update tryhackme level on this server

#

@lofty moat nice rank

#

can you teach me

#

🙂

lofty moat
#

it is updated every 24hours but if you want to do it manually you can do it

opal ibex
opal ibex
#

?

lofty moat
#

!verify YourDiscordToken to @trim cloud bot

opal ibex
#

ok

lofty moat
#

so your level can be updated

opal ibex
#

thanks

#

and another thing

#

can you teach me

#

😦

#

about tools

lofty moat
opal ibex
lofty moat
opal ibex
#

and privilage escalaltion

#

especially

opal ibex
#

i was not knowing

opal ibex
#

free?

lofty moat
#

yeah

stuck juniper
#

hydra -l [user] -P [passwords] ssh://[IP] -t64

lofty moat
#

ssh ^

#

also -L if you are using users list

stuck juniper
#

/var/log/apache2/access.log

#

wait I think I just used rockyou for that machine @bright wyvern

#

find / -name rockyou* 2>/dev/null

#

so it will match the .txt or .txt.gz at the end

bright wyvern
#

thank you!

dawn pond
full sapphire
#

@dawn pond with?

#

@dawn pond Please read the server rules -- rule 1 specifically. Here is fine 🙂

glacial crater
#

how do I join general voice

lofty moat
trim cloudBOT
glacial crater
#

tks 🙂

bright wyvern
#

hellow @glacial crater @plucky vault

glacial crater
#

hi

#

1sec

#

on a call

bright wyvern
#

im gonna finish a box i started last night

glacial crater
#

okok

#

im very new

#

im doing linux findamentals pt3

#

fundamentals

bright wyvern
#

very nice!

#

can you stream?

#

if you cant you have to get verified

glacial crater
#

what did u say Bodiless

#

say again sry

#

Hi

worldly ivy
#

its as close as I could get it to 0 dB difference in the retrack so it should sound good with any headphones

quiet needle
#

@dawn pond Why are you looking up free proxy lists for proxychains?

#

doing good thanks @limpid badger and you?

#

hehe yeah! All you can ask for these days 😄

#

glad to hear it

#

Doesn't sound familiar no 😦

#

Ah good stuff @hasty dragon 👍

#

ty for letting me know

#

I'll catcha later @limpid badger keep well (:

quiet needle
#

hey hey (:

opal ibex
#

.

lofty peak
#

@plucky vault why are you so quiet 😆

#

KoTH 👀 👀

topaz ferry
#

Red Teaming is all about being quiet 😉

plucky vault
stuck juniper
plucky vault
#

yeah

karmic frost
#

.

plucky vault
#

SEECUL MAP

barren heart
#

SEAGULL MAP

plucky vault
#

seekool map

#

@stuck juniper press the button

stuck juniper
#

or what

plucky vault
#

press it

lofty moat
#

Just do it

stuck juniper
#

oh no

unkempt minnow
#

What was that, Merc?

stuck juniper
#

I'm sorry

#

I didn't mean it

#

whatever I've done

grim wagon
#

;-;

plucky vault
#

he did not press it

#

failed his speed run

barren heart
#

reset incoming

rustic mica
#

wat

#

@plucky vault 👋

bold raven
lofty peak
#

@plucky vault switch the damn lights on

bold raven
rustic mica
#

Please refrain from the swearing :)

#

Can't be doing that here, regardless of testosterone overflow.

bold raven
lofty peak
#

lol , a separate channel for you to swear 🤣

rustic mica
#

That'd be network chucks discord you can venture to then :)

rustic mica
#

Purely pg13 env unfortunately.

#

Darksec too. That place exists.

lofty peak
#

kekw i find this so funny lol

rustic mica
#

Sweet child. Please understand.

#

You must see things for what they are.

#

See past the flesh.

#

I appreciate the silver tongue :)

#

pg

#

13

#

mate

lofty peak
#

Nicholas , are you bored or something who is messing up for no reason kekw

rustic mica
#

It's highly suggestive. Cmon mate. Please prevent me from having to do my job.

#

Come visit Darksec.

lofty peak
#

lolllll

rustic mica
#

You know what you did!

#

That doesn't work here :)

lofty peak
rustic mica
#

I'll hire James.

#

ezpz

lofty peak
#

Nicholas hire me

#

i will fight with you

rustic mica
#

Get. In. Darksec.

lofty peak
#

😎

rustic mica
#

:D

#

Creativity lmao

lofty peak
rustic mica
#

Say it in base64

#

Wat

plucky vault
rustic mica
#

He has a memes channel.

lofty peak
#

varg , allowed to swear in base64 ? 🤣

rustic mica
#

:3

lofty peak
rustic mica
#

There

#

Bloody hell

#

lmao

#

HAHAHAHA

#

You know why I love you, nicholas?

#

Because you're too confident.

#

<3

#

oml

#

No

#

You cant

#

You cant have fun here dude.

lofty peak
#

your the craziest guy i ve seen in general voice bruh ,

rustic mica
#

Bold of you to assume you have to be "qualified" to get mod.

#

In any capacity.

#

No.

#

Just how to partially tie your shoes.

#

Do you use velcro?

#

No shame.

lofty peak
rustic mica
#

a little shame

#

You ought to be admin.

lofty peak
plucky vault
#

Yea feels like public speaking session

#

Am attending lecture rn

#

Yea..with my airpods on

#

You're definitely eligible for moderator role

#

Ya that definitely boosts

#

😂😂😂😂 damn...am gonna burst into laughter

#

Will you catch you later mate

real orbit
#

it baking night tonight

#

bee, where are the women at

plucky vault
#

on god

#

Well boys no more vc for me

manic canyon
#

curl -H "User-Agent: system($_GET['cmd']"

manic canyon
#

@brittle sinew I moved you to AFK as the study channels are for people studying.

worldly ivy
#

@manic canyon can you move me in pweez <3

manic canyon
#

Join a chat and I'll drag you in

plucky vault
worldly ivy
lyric halo
#

that is one big small study room kekw

manic canyon
#

Want me to pull you in?

lyric halo
#

yeye

#

plox

wicked bane
#

aw man.. the small study room seems comfy.. too bad I'm still working

sand glen
#

Pull me in too

fair wing
stuck juniper
#
WonderHowTo

The Operative Framework is a powerful Python-based open-source intelligence (OSINT) tool that can be used to find domains registered by the same email address, as well as many other investigative functions. This reconnaissance tool provides insight about your target through examining relationships in the domains they own.

#

that I believe

stuck juniper
#

redteamchallenge.eu

stuck juniper
#

owasp juice room

#

dvwa

limpid badger
#

@torpid badger we could not hear you bro

torpid badger
#

T-T

#

my mic is don't good

#

i don't have money forbuy one good

#

😦

limpid badger
#

😦

#

maybe try to join with your mobile phone 😉

#

@torpid badger

torpid badger
#

my phone don't is good to

#

it sh** hangs

#

😦

lofty moat
#

you can always mute and type

manic canyon
#

If you're going to censor your swear word, don't swear at all :)

lofty moat
stuck juniper
#

sudo apt update

#

apt-get is deprecated

#

wall

full sapphire
#

If you want to practice that one

stuck juniper
#

Ah thanks Muiri

#

we just had fun when we realised it worked on the Food koth room

steady umbra
#

What happened

#

Can I help u

stuck juniper
#

did you not see it

steady umbra
#

Laughing a lot man

steady umbra
tame ether
plucky vault
#

brb

shell spear
plucky vault
open ivy
#

Bruh

#

That font

fast wind
#

no coffee

#

barely alive

#

no coffee me gone

tame ether
azure moss
plucky vault
lofty peak
#

@unkempt minnow i realy like your voice man

#

your accent is british 🥺

#

😍

unkempt minnow
#

Merci 🙂

heady dew
#

@unkempt minnow May I DM?

unkempt minnow
#

Sure 🙂

royal knot
#

blackout seems to be getting better with his geography, must be studying

unkempt minnow
#

@heady dew Done 😄

heady dew
#

Thanks 🙂

lofty peak
#

@unkempt minnow whys general so hot 🙂

unkempt minnow
#

Cos we are all playing Geoguessr with Blackout

lofty peak
#

oh

unkempt minnow
#

I bought him Premium a couple weeks ago so we could play the Battle Royale mode

lofty peak
#

many people talking . cant understand anything 🤣

unkempt minnow
#

It's fun, Come join in

#

You just gotta guess the country

lofty peak
#

okay

plucky vault
#

country?

#

oh I played quess city

#

Saudi Arabia

#

or iran

open ivy
#

@unkempt minnow I keep getting disconnected

#

Slow connection

#

:/

unkempt minnow
#

Oh 😦

#

I don't know how to fix that

open ivy
#

Another time I guess

unkempt minnow
#

I hope so

safe idol
#

When was teh community meet

unkempt monolith
#

Is that look like a rabbit hole?

formal garnet
#

@unkempt monolith try running gobuster in the perm denied directories

formal garnet
unkempt monolith
#

@formal garnet Where to run gobuster?

formal garnet
#

try running in all web dirs

#

which tool is that @unkempt monolith

unkempt monolith
#

Its mine Im still working on it you want to try it?

formal garnet
#

yea sure

unkempt monolith
formal garnet
#

ty

unkempt monolith
#

Let me know if there is a problem or adding more stuff 😄

formal garnet
#

sure

formal garnet
unkempt monolith
formal garnet
#

ill tell in dm

unkempt monolith
#

Okay

formal garnet
#

mind if i ?

unkempt monolith
#

No sure

formal garnet
#

give 60 threads at least

unkempt monolith
#

How can I make it equal to 9

formal garnet
#

5+4=9 lmao

unkempt monolith
#

lol tryed that xD

formal garnet
#

tried that'

unkempt monolith
#

damit

#

I mean.. I dont see anything on the code that tells me that it will redirect me or something

formal garnet
#

exactly

unkempt monolith
#

Okay so I think the pattern is 1,2,3,4,5,6,7,8,9

#

something like that

plucky vault
#

which room are you solving?

unkempt monolith
#

new one enpass

#

what did you say?

plucky vault
#

your first word length is 2

unkempt monolith
#

yea

plucky vault
#

for 8th word is 3

formal garnet
#

21001123?

#

we tried it

unkempt monolith
#

but is it like a know word or I can make something up

plucky vault
#

ig you have to make it

unkempt monolith
#

Its two stages if we have val[0] and val[8] right we need the second phase

plucky vault
#

can you share the code like in dm or hold the screen for a minute

unkempt monolith
#

yeah

formal garnet
past sail
#

Is helping each other here considered giving hints?

formal garnet
#

not hints

#

we r figuring out ourselves lol

unkempt monolith
#

@plucky vault You got it?

plucky vault
formal garnet
past sail
unkempt monolith
#

If $sum == 9 the boolean is True

#

so we need to get there some how

formal garnet
#

20001123

#

this sum is 9

#

and follows the order

#

hmm

unkempt monolith
#

nope

#

It needs to be separated with ,

plucky vault
#

But how can we enter a character of length 0

formal garnet
#

try goin in tthe /zip n view the s

unkempt monolith
#

mm

formal garnet
plucky vault
formal garnet
#

hmm yea mybe

#

zip also try some guessy numbers and view them

unkempt monolith
#

ohhh

#

we have strings in hereeee

formal garnet
#

oh yea sadman was on the index.html as well

unkempt monolith
#

oh dame

formal garnet
#

if u open $ip:8001 u still see sadmna

#

try enternin sadman in reg.php

#

value of i = i+1

#

can that gib some help?

#

31112234

plucky vault
#

Enter a blank string ""

formal garnet
unkempt monolith
#

yeah

formal garnet
#

the sum is not 9

#

idk how bypass

unkempt monolith
#

oh so it has to be loop 9 times?

formal garnet
#

but hey the user flag hint says the ssh file u found

plucky vault
#

@@,$,$,*,$,!,$,!,@@@ can you try this?

unkempt monolith
#

nice man!!!

#

Ill back later

formal garnet
#

wut u stream?

#

@hidden marten

#

@plucky vault damn that worked can u tell me how?

plucky vault
#

!preg function stated that we don't have to give any alphabets or digits in the title

#

To get inside the if loop

#

And then I followed what if commands needs to bypass

#

Like on val[0] length of string should be 2

#

And so on

#

Thanks to @past sail on highlighting the "!" on preg function

formal garnet
#

ok thx didnt understand tho

#

@plucky vault and did u found the user?

#

need help neo in user

#

@plucky vault u there?

plucky vault
#

sandman is the user ig

formal garnet
#

sandman or sadman

plucky vault
#

Whatever was given in that zip files

formal garnet
#

i always get perm denied

plucky vault
#

That is the username

formal garnet
#

not working

#

its not workin

#

@past sail which ?

#

room

past sail
#

Im on En-Pass

formal garnet
#

yea im streaming that

#

can u help for the user

#

i got the passwd in /reg.php

past sail
#

Your stream doesn't show anything btw, and i would like to find out myself ^^

formal garnet
#

oh it doesnt

formal garnet
past sail
#

Wait for the 13th for hints

formal garnet
#

yup

#

lol

past sail
plucky vault
#

@lofty peak Can I ask why are you writing that sample code?

lofty peak
#

you understand this code ? please explain me once i write it completely

plucky vault
#

It's basic php...it's just accepting what you write as a input and execution is done

lofty peak
#

really ?

#

wait

#

wait

#

yea now tell

#

oh

#

whats meant by that stuff

#

oh

plucky vault
#

Yes...basic way of accepting inputs in get parameter

plucky vault
steady umbra
lofty peak
#

yo , whats meant by

What user is this app running as?

plucky vault
lofty peak
#

uh , no i found it

worldly ivy
plucky vault
lofty peak
#

@plucky vault you wanna play a koth ?

plucky vault
lofty peak
#

@limpid badger nothing much

#

wbu

#

tell us some good story

#

anything

#

experience

#

you done with your education ?

#

where you from

neon mirage
lofty peak
#

oh , cool

#

INDIA , yes 🙂

neon mirage
#

me?

lofty peak
#

you kind of sound like arabian 😄

neon mirage
#

Sri Lanka

#

😂 not arabian

lofty peak
#

your voice is very bold .

lofty peak
neon mirage
#

i am having coughf

#

corona 😆

#

oh sorry

#

lol

lofty peak
#

so how was corona time for you , @limpid badger

neon mirage
#

hi animo whats up?

lofty peak
#

oh , how a goood internet connection in a village

#

🤣

#

yea i am here

#

was busy koth

#

😉

#

yea so

#

village

#

you have a hint

#

what was it

#

hwos that possible

#

ohhh

#

is it cold at your place

#

😄

#

@earnest parrot you dont at all sound nepalian kekw

#

@stuck juniper what room are you doing 🙂

stuck juniper
#

the room Tetris

#

hardest one I've done so far

lofty peak
#

oh

#

i dont see the room

manic canyon
stuck juniper
#

oh I was just joking @lofty peak, me and Nox were just trying to speedrun the game Tetris

torpid badger
#

hello guys

plucky vault
#

The person who is streaming rn...can you share your wallpaper or provide me the name of that image @earnest parrot

stuck juniper
#

are you unavailable to talk? @echo badge

echo badge
#

Hmm, I don't really comfortable using vc 😂

stuck juniper
#

ah okay, man

echo badge
#

You can try it on the game, but I don't have enough batteries left

#

I've played it before

#

Only once though

#

Probably not a tty shell, that's why you can't see the process

#

I did see while loops process but idk if it's because the loops is background process

#

Oh, I don't use while loops because it's slowing down the box

#

Simple binary for write file

#

I think payloadallthethings is good

#

Okay then, that was fun

#

👍

plucky vault
#

Any plans for India?

hot snow
#

Yep THM is a UK company

fallow brook
#

I'm not british 😄

plucky vault
#

@plucky vault beard

urban cloud
#

@plucky vault glasses suit u 🙂

fallow brook
#

https://www.youtube.com/watch?v=XTaKWdIdg8g I always like to link to this presentation from DEFCON

Evan Anderson is the Director of Offense at Randori. He has over 15 years of experience in red teaming, vulnerability research and exploit development and is a founding member of the NCCDC Red Team. Prior to co-founding Randori, he worked at Kyrus Technologies supporting commercial and federal projects.

Grey Hat SSH: SShenanigans
The Secure She...

▶ Play video
#

should be useful for some wreathing 😛

rough flax
#

dialup noises

#

@quiet needle 👉 👈

quiet needle
#

@rough flax ❤️

rough flax
#

but

#

but

#

muted

quiet needle
fallow brook
#

afk, making dinner

stuck juniper
#

@echo badge you want to do a Koth?

stuck juniper
#

<?php echo system("ls") ?>

plucky vault
#

which room is this??

stuck juniper
#

Archangel

plucky vault
#

php://filter/convert.base64-encode/resource=/var/www/html/development_testing/test.php

#

try this

#

after view=

#

@barren heart

lost current
#

wtf

echo badge
stuck juniper
#

ahh very nice

#

I was just saying how you were my koth mentor

#

❤️

azure moss
manic canyon
#

@plucky vault Please do not post discord links.

stuck juniper
#

@echo badge psst

echo badge
stuck juniper
#

damn you were up late

#

I was wondering if you wanted to do a koth @echo badge :(

echo badge
#

Well, you're on the other side of the earth 😂

stuck juniper
#

that is a very good point

#

ping me if you wanna do one today 😂

#

@fallow brook we're voice suppressed :(

#

@manic canyon will we be able to ask questions or no?

fallow brook
#

I'll assist on minor questions if we get bogged down in too many 🙂

#

in text 🙂

#

Jabba is the voice god

#

oooh.. chuin is here

warm atlas
#

halo

remote ledge
#

howdy chun

fallow brook
#

When in doubt, enumerate. (thats why spy planes exist)

topaz ferry
#

Good morning. 🙂

fallow brook
#

It can be throttled down for pentesting...

#

💯 do things slow, automate and accelerate only after you fully understand why you're doing it.

#

understanding is key

stuck juniper
#

rustscan has the ability to cause DOS to a server as it's so freaking fast

#

so be careful with it, especially if you're going to use it in the real world

warm atlas
#

just use min-rate in nmap

#

rustscan can give u some false positives

stuck juniper
#

just like -T5 in nmap

#

generally, the faster the tool goes, the more likely the chance of false negatives/positives

late nebula
#

Since I'm new here, is this tutorial session conducted often? I feel like subscribing the premium now 😮

fallow brook
#

Welcome to the party Tatsuya 🙂

stuck juniper
#

apropos is a good tool for searching man pages as well @manic canyon, if they're offline 🤷‍♂️

late nebula
#

Thanks, I'm subbing within the next 24 hours after my card gets unblocked 😄 Feels damn good to be here

fallow brook
#

And it happens IRL too. A bug hunter friend of mine found an open anonymous login FTP with passports in it.

#

if it looks like a default lib, it's probably a default lib

#

feroxbuster!

#

Once again, when in doubt (nothing special in index), enumerate. This just iterates on that.

urban cloud
#

dirsearch>ffuf>wfuzz

fallow brook
#

dirbuster wordlists, you also have seclists which is amazing

stuck juniper
#

✨ directory-medium list is outdated ✨

urban cloud
stuck juniper
#

raft is better :L

#

has .git etc.

urban cloud
#

i prefer common.txt

fallow brook
#

🤷‍♂️ seclists, use them all untill you find it 😛

stuck juniper
#

you can specify threads with gobuster, default is 4 but I think it can go up to 64

#

although

#

webserver might die 🦀

#

good for blooding though

fallow brook
#

or you might start dropping connections..

urban cloud
fallow brook
safe niche
#

is this being recorded at all so i can watch it again later?

urban cloud
fallow brook
#

It was giving you a 301, because it says it's moved to the directory (/images becomes /images/)

fallow brook
full sapphire
manic canyon
#

(I’m recording)

full sapphire
#

We recorded the Event on Thursday night, but these aren't recorded unless Jabba is using OBS

#

Ok, it's recorded 😆

late nebula
#

Can I please have the youtube channel?

fallow brook
#

because Jabba is awesome 😄

full sapphire
manic canyon
#

I’m only recording my microphone and my screen, Did not think I needed a disclaimer

full sapphire
#

Yeah, should be good -- just for anyone who gets unmuted to ask a question 🙂

fallow brook
#

Jabba's Tutorials: Recorded in front of a live Discord audience

#

<insert clap soundbite>

late nebula
#

Me trying to find where Jabba uploads videos 😦 🌐

fallow brook
#

It allows you to mess with HTTP Requests

full sapphire
#

Web proxy 🙂

lucid dune
#

does this tutorials happen daily?

rustic mica
#

I nearly yelled "JABBA IN DA HIZZY" not realising I am not muted in there by default lmao

full sapphire
#

This seems to be going down well

fallow brook
#

I'll probably be doing a few in the future as well, following on jabbas footsteps 🙂 Probably have a few specific study topics.

azure moss
#

If happily do some :)

full sapphire
#

That's what this VC is for! 😁

rustic mica
#

Muir, I will paypal you $10 if you say "PANTS" loud enough that it is very clear to us all in here, with mic unmuted.

kindred laurel
#

will the tutorial then be uploaded on discord as well?

full sapphire
#

(Mods and mentors are not muted in there, so feel free to use at will)

full sapphire
warm atlas
#

i might do some binexp stream 👀

rustic mica
full sapphire
remote ledge
rustic mica
#

Yeah I am not offering more to just say a word lmao

azure moss
#

£20 and a lion bar

rustic mica
#

^

full sapphire
#

Right, I'm off to walk the dogs. Have fun!

rustic mica
#

<3

fallow brook
#

pentester-monkey shell?

safe niche
#

in a real world situation if the "upload file" screen came up, wouldn't the owners be notified of an attempted upload?

fallow brook
#

it depends on the service too, some services have so many uploads going on anyways that it could be missed because of noise-to-signal ratio

#

It'll depend on your scope, since we're all ethical hackers here 😄

#

lnvp > lvnp 😛

#

I'm lazy, I only half-stabilize

#

python method ftw

#

stty raw -echo; makes the special keys (Ctrl+C , Ctrl+Z) work 🙂

#

arrow keys too!

#

That and often we add custom headers to http requests to identify our trash so as not to pollute logs. IRL (one such example is the Verizon Media BBP)

#

reports are the final product after all

#

updog best dog

craggy mesa
fallow brook
#

No, their bug bounty program just requests that you use a very specific Header in all your traffic to avoid getting you in trouble, and so they can filter out their logs.

#

if you don't use it, you can get banned from the program.

remote ledge
#

./linpeas | tee linpeas.out so it can be stored for later use

fallow brook
#

And the Big PEA banner makes me happy...

craggy mesa
fallow brook
#

exactly Xia 🙂

#

Another useful script is pspy

azure moss
fallow brook
#

pspy logs executed processes, so you can identify hidden cronjobs (like root cronjobs)

fallow brook
azure moss
#

It's very handy, espically when u need to go over it again or the box dies

fallow brook
#

aye

#

and you can keep everything organized on your local folder

azure moss
#

Get all the info u can onto ur own machine. A lot easier to go over it

fallow brook
#

we see it

#

owner group all

#

suid allows you to temporarily set your uid to the owner of a file, so that's why you need -user root there. (in case there were other SUID files)

#

but it can be removed to search for SUID for all users

#

to gtfobins!

#

anyone else getting a bit of crackling from jabba's audio now? or is it just my discord?

#

(could be just me)

remote ledge
#

nah

fallow brook
#

move along, thanks 🙂

remote ledge
#

gd for me

fallow brook
#

And it focus on the vulnerability, not on exploitability

#

effective uid = root

craggy mesa
#

🎉

fallow brook
#

Great job jabba, you did a good job. kept it simple 🙂

plucky vault
#

Thank you for the great tutorial 😄

tawny sphinx
#

thanks for the tutorial. New to them

remote ledge
azure moss
#

U smashed it mate

tawny sphinx
#

Oh most def coming to more now

steady umbra
#

U are awesome tutor man @manic canyon

fallow brook
#

I'll add a question then: In the systemctl payload, why didn't you just execute "/bin/bash" there

remote ledge
#

/bin/bash -p to execute correctly

acoustic canopy
#

Thank you very much for the tutorial!

azure moss
#

there's many ways to skin a cat

remote ledge
#

yup

craggy mesa
#

@manic canyon When you take a note, what kind of troubles do you prepare for? I often overlook something...

fallow brook
#

or a pwncat

#

or a socat

#

or a... you get the point

fallow brook
#

if you take a step by step approach on everything you see from your enumeration, you wont miss too much.

late nebula
#

Thank you for the wonderful session @manic canyon, I'd like to know where the recording is hosted 🙂

fallow brook
#

if you are missing something, it usually means you need to enumerate more

#

services will inform what vulnerabilities to test for, etc...

craggy mesa
#

got it. Thanks for kindly advice!

manic canyon
#

The recording should be posted on YouTube and released soon :D

fallow brook
#

ofc, that's not always obvious, specially with web services.

late nebula
#

Channel plox, I'm new here!

fallow brook
#

and if you find an http you look for a CMS and if you find one you search for vulnerabilities in that. Otherwise you start testing OWASP top 10 etc..

#

Awesome job Jabba.

#

I'll gather some courage to do some too 🙂

#

I want to guide ppl to do some bofs 😄

hot snow
fallow brook
#

@manic canyon 👍 will do

late nebula
#

We need more of Jabba in here! Its lively!

fallow brook
#

seeya

remote ledge
stuck juniper
#

@manic canyon thank you sir blobheart

torpid badger
#

hi guys

#

🙂

lofty peak
#

@unkempt minnow its night . call some people and do a lecture 😄

fallow brook
#

brb.

#

trying to figure out how to get on voice with some crazy stuff going on with my music interface...

quiet knot
#

oscp

#

exam tips in 2021

fallow brook
quiet knot
#

ty

fallow brook
azure moss
azure moss
#

Zoija - Hackerista

limpid badger
unkempt minnow
#

@forest python Opinion on Chicken Burgers? ^^

forest python
#

lil dark but that could be the light. looks super crispy and craggly so yum

azure moss
unkempt minnow
#

Animo says it's the 'Best in the World'

limpid badger
#

with cornflakes

azure moss
#

It's covered in kellogs cornflakes

#

They're grrrreeeaattt

fallow brook
#

it's good 😄

#

chicken Saltimbocca

limpid badger
#

rouladen

azure moss
azure moss
coarse ridge
#

Hi

limpid badger
#

hi

coarse ridge
#

Why i can’t join the vc

azure moss
#

!docs verify

trim cloudBOT
coarse ridge
#

Ok tnx

azure moss
#

cat /etc/passwd | wc -l
cat -n /etc/passwd

rustic mica
#

port: "5900" authentication disabled

south glen
#

@fallow brook Opa

#

the names in polish look like hash

tame ether
rustic mica
#

Magna you alroit mate?

crisp sentinel
#

https://www.pdq.com/

^PDQ for remote deployment and monitoring. Good pricing IMO

rustic mica
#

@fallow brook I look away for 1 second :C

severe ice
#

szy ive never seen so many tabs in my life

crisp sentinel
tawny sphinx
#

Has someone been on tutorials since yesterday?

cedar hollow
#

-0-0

plucky vault
#

any room suggestions?

worldly ivy
limpid badger
lofty peak
#

@plucky vault PubgBOY

#

@plucky vault whats your THM bro ?

#

😚

plucky vault
#

привет

full sapphire
#

@plucky vault English please 🙂

plucky vault
#

ok

#

no russian

#

ты русски?

#

бот орошхо

#

ill stop

#

how are you today

#

good im guessing

#

im kind of bored

#

no russian whatsoever got it!

#

so how are you again

#

fine Im guessing

split raft
lofty peak
#

@plucky vault you can also do dir

#

dir works in ftp ig

#

@plucky vault ask him to try it once .

plucky vault
lofty peak
#

🙂

plucky vault
#

@lofty peak you're playing koth again?

lofty peak
#

yup 🙂

#

😆

plucky vault
#

you were about to teach me @lofty peak

lofty peak
#

ahh , 😆 . yea lets do it

#

he wont , patching

plucky vault
#

@lofty peak can i dm you if you dont mind?

lofty peak
#

yea sure 🙂

balmy nest
#

WHY GENERAL CHAT IS LOCKED ?

full sapphire
#

Because we don't want people being able to just join with no protective measures

#

!docs verify

trim cloudBOT
balmy nest
#

!docs verify