#room-hints

1 messages · Page 8 of 1

molten bay
#

the problem is i dont know which directory they are speaking about specifically

#

i get error 404 on certain ones but idk which one they want me to look at

tulip mural
#

you got this?

molten bay
#

thats what i get from there but it answers a different question:THM{NOT_A_SECRET_ANYMORE}

tulip mural
#

yeah thats okay

#

now read the next paragraph

#

how would you view other directories?

molten bay
#

I get that but inside the secr there is only one line and that is the flag theres no other css js files so thats why im confused

tulip mural
#

go back 1-2 directories then

molten bay
#

that takes me to the home page i looked at all the css, img, js files none of them seem to have any txt file attached

#

The only thing I could find was that other flag with not_so_hidden hidden inside some css file

tulip mural
#

oh sorry my fault

#

i just started machine myself

#

you need to go to the directory where all the js css files are stored

molten bay
#

like /assets/style.css?

tulip mural
#

kinda, style.css is the file. the directory is assets

molten bay
#

aah ok

#

i got u i didnt know why i didnt think of that

tulip mural
molten bay
#

i was just copying the full length paths i didnt think to look at the parent folder

tulip mural
#

read the task carefully

molten bay
#

to be fair i never found the 403 forbidden page

#

but i did find the txt

tulip mural
#

because it is misconfigured

#

when you access /assets, it should be forbidden in secured scenario but it is not in this case

molten bay
#

yeah i just tried it on an actual website and it returned a 404

#

thanks for your help

tulip mural
jade tangle
#

any tips for the "Lesson Learned?" room?

tropic garden
umbral umbra
#

@molten bay If you post flags in chat, please add the spoiler tag to them so that someone who hasn't gotten that far has the answer spoiled for them

molten bay
#

idek how to do that

umbral umbra
#

|| <text> || is made by || <text ||

jaunty elbow
#

10 time slower
Get-ChildItem -Path C:\ -Include *unattend.xml* -File -Recurse -ErrorAction SilentlyContinue

than

dir C:\ /b/s | findstr "unattend.xml"

improvements on powershell request?

clever seal
#

Task 5 on https://tryhackme.com/room/phishingyl after I initiate the campaign, the status of brian never changes to Submitted Data. I have double checked all the steps, but I have received the same result. I added a temp email to the campaign to see if the SMTP server works, but it never receives an email. I also tried to Send Test Email to the temp email, but did not receive test email either. I figure something is going on with the SMTP server, but maybe someone else might know what might be going on.

nimble snow
nimble snow
#

Can I list in here what I have found so far or will the spoil it for others?

lucid junco
#

You can use spoiler tags.

nimble snow
#

||I've identified that Apacher version running is 2.4.54 and that there are known HTTP Splitter vulnerabilies and after trying several I've had no luck||

lucid junco
#

All you have to do is get an RCE.

nimble snow
#

Yeah I looked at that and thought the CRLF was what they wanted but I can double back and check the RCE vulnerabilies.||

#

Thank you

lucid junco
#

There is a more simple one. 😉

nimble snow
#

Hmm

lucid junco
#

Have you identified what sort of website it is?

nimble snow
#

Yeah I have

lucid junco
#

That should help narrow it down.

nimble snow
#

I thought about that aswell just been focused on the Apache version first.

#

I am off for tonight but will come back with a fresh pair of eyes 🙂 Thank you @lucid junco

green minnowBOT
#

Gave +1 Rep to @lucid junco

vivid knot
#

Hello everyone,

I'm currently busy with the SQL Injection room on task 8 : Blind SQLi - Time Based.
So far I found the table_schema & table_name but I can't manage to get any column_name.

Does this error means the table is empty and doesn't have any columns ? Or am I missing something ?

vague pine
vivid knot
#

Oh right ! Thanks for the tip !

worldly flare
#

Doing year of the fox

#

||got the creds.txt and cipher.txt from smb||

#

but cant seem to find the correct cipher/encoding for them

#

been looking for hours now

#

i seems to me that they have multiple

#

but cant find the correct ones

alpine kestrel
#

blame muiri

worldly flare
#

@inland onyx i blame you

#

Now i could really use a hint 😂

alpine kestrel
#

hmmmm should shadow spoil themselves and look up a writeup to help here or should they hope someone else pipes in

lucid junco
#

Maybe it'd a rabbit hole...

alpine kestrel
#

considering it is muiri yeah definitely rabbit holes galore

#

muiri is the creator of the year of the rooms and has been known to do some tricky stuffs

worldly flare
#

Ok

lucid junco
#

What have you got?

worldly flare
#

Wdym?

#

2 smb users and their passwords

#

And 2 text files from one of the shares

#

Thats it

#

For now

alpine kestrel
#

hmmm smb gives shadow some fun potential exploit paths

#

though no clue if said things will work on this room

worldly flare
alpine kestrel
#

fair enoughs then

#

assuming you are refering to eternal blue

worldly flare
#

Yes

alpine kestrel
#

because that is what shadow thought of

lucid junco
#

Ever thought of bruteforcing the users you found?

worldly flare
#

Thats the first thing i thaught of

#

I did

#

And got their smb passwords

#

There is a http login page

#

By that i mean auth besfore u even see the page...no loaded html

#

Tried the creds there

#

Didnt work

#

Dried BF that...didnt work...the server isnt vulnerable and buster didnr find anything

worldly flare
#

been trying for hours now again. Cant seem to find a way in...can i get any more hints?

tropic shard
#

Is there any way of speeding up nmap scan, something more with just -T#

#

Scan going to take 48 minutes so far.

ebon jewel
#

there is no room on THM that require that amount of time for nmap =/

tulip mural
random sedge
#

I'm having trouble with the crack the hash room specifically the hmac-sha1 question. is the answer really in the rockyou.txt.gz list?

alpine kestrel
random sedge
#

really? hashcat says it ran through 14344385/14344385 (100.00%)

alpine kestrel
#

would not expect hashcat to unarchive a gunzip file but maybe it can

random sedge
#

I'll try and post back if it changes results thanks @tropic shard

green minnowBOT
#

Gave +1 Rep to @tropic shard

random sedge
#

@alpine kestrel I meant thanks to you. clicked the wrong name. I'm getting the same results can I post the results here?

#

@alpine kestrel thanks

green minnowBOT
#

Gave +1 Rep to @alpine kestrel

random sedge
#

hashcat -m 150 -a 0 hashcrack2 /usr/share/wordlists/rockyou.txt is the command I used

#

I also tried -m 110 because I saw that in my research

#

same results basically

#

also tried without the -a 0

alpine kestrel
#

Answers will be delayed as shadow is now gonna go sleep

tropic garden
chrome iron
chrome iron
valid widget
#

i am getting an error on day 8 of aoc 2022
TypeError: Member "toString" not unique after argument-dependent lookup in type(library Strings).
--> EtherStore.sol:8:26:
|
8 | string internal f8 = Strings.toString((((100 / 25) + 20 / 2) - 7) - 2);
| ^^^^^^^^^^^^^^^^

chrome iron
random sedge
#

@tropic garden yes exactly it runs through and status says exhausted.

tropic garden
#

Have you checked if there are excess spaces? Or can you add a screenshot of your hash?

coarse grotto
#

Hi I have a question in the Password Attacks of the red team walkthrough they talk about many protocols but how to bruteforce an authentification page that is included in the browser (like "Website asks you to connect :
Username :
Password :
)

random sedge
#

@tropic garden e5d8870e5bdd26602cab8dbe07a942c8669e56d6:tryhackme

worldly flare
#

hey guys, doing room "Jack", and we enumerated the users but the rockyou just isnt working

#

can anyone hint me to the right wordlist please?

#

I have gone through 5 different wordlists now haha

lucid junco
#

You're going to kick yourself when you get the password

worldly flare
#

And i want to burn the pc

hushed moon
#

Hey guys, I'm doing "Special Privileges and Security Descriptors" and when I try to run the c:\flags\flag2.exe after connecting as thmuser2 I receive this message "Sorry! You are still missing something. No flag for you yet. (4)".
Any idea?

hushed moon
tropic garden
#

Hi folks, anyone can give me a nudge on Gallery (https://tryhackme.com/room/gallery666 )? I'm on the privesc part specifically on the || /opt/rootkit.sh ||. I read that using unquoted variables are a vulnerability in bash, and I tried to exploit it, but can seem to get the correct 'payload'.

polar finch
gusty hill
#

@twin arch Which section you found confusing , mb i can help you

gusty hill
#

You managed to achieve the reverse shell section ?

twin arch
#

i finished it but i wanted more to understand it fully

#

because i cheated a lil bit when i got stuck

gusty hill
#

You are looking for information to understand better telnet or the way you got the flag out ?

twin arch
#

more info is there a vid about it or something

gusty hill
#

He's going through the room

twin arch
#

Thank you so much

tropic garden
green minnowBOT
#

Gave +1 Rep to @polar finch

jaunty elbow
#

but is there only Paula Januszkewicz explaining DPAPI?

distant plank
distant plank
upper anchor
#

I'm stuck on the second question in the Password Profiling #2 task in the Password Attacks module: "What is the crunch command to generate a list containing THM@% and output to a file named tryhackme.txt?" My answer crunch 5 5 -t THM@% -o tryhackme.txt or any of its variant was not accepted. Can someone give me a hint?

fallow venture
#

Look into placeholders for special characters to be replaced
Like this
, for all uppercase letters @ for all lowercase letters % for all numeric characters ^ for all special characters

alpine kestrel
#

shadow knows the solution and think wolk here kinda explained it good enough

coral fossil
#

Match all of the filenames of question 4, except "File7" (use the hat symbol) my = [fF]ile[1-9][^7] good = [fF]ile[^7] why ?

coral fossil
#

@alpine kestrel Regular expressions task 2, question 5

#

catregex

alpine kestrel
#

yeah the reason here is to go for the shortest option that still works as we intend

#

if it is matching all files with the name file/File with any characters after

#

sparing out any which have a 7 directly after the file part

elfin patrol
#

How do I post a picture so I can get some help ?

alpine kestrel
#

!docs verify

proud scarabBOT
alpine kestrel
#

then follow those instructions in the link and you can post pictures

elfin patrol
#

Thank you I think it worked

#

I can’t get past this stage

#

Am I not typing in the document correctly ?

fallow venture
#

You have a typo in comand

#

Check again

#

You ate a letter, guess you're hungry 🙂

elfin patrol
#

So it’s not the pdinfo that’s wrong

fallow venture
#

pdFinfo

elfin patrol
#

Thank you so much 😊

#

I was going crazy 😜

fallow venture
#

You're welcome

#

Good hint, always check the output of error

#

In 80% it can resolve your issue

#

Or you google it and find the solution

elfin patrol
#

Google gave me bad info for “pd” info 🤣

fallow venture
#

Sometimes it happens

#

Good luck with your starting

echo prism
#

can someone help me with grep?\

#

I'm supposed to find the flag in "THM"

green sedge
#

What task is this?

echo prism
#

6

#

searching for files

green sedge
#

ah I see, what is your question exactly? The hint provided for the question gives you the command to run, is it not working for you?

echo prism
#

nope

green sedge
#

Could you send a screenshot?

#

If I had to guess the issue is that you are not in the same directory as the file you are trying to grep

lucid junco
echo prism
#

@lucid junco it works now and no I wasn’t

lucid junco
lucid junco
#

What numbering system do you know that is base-16?

#

Yes.

What's the full name for hex?

ripe berry
#

I Was so stuck at this

#

and the answer doesn't make sense to me

#

can someone explain ?

#

Room "Red Team Intel" Last task before Conclusion

thorn frigate
#

Working on finishing Windows Local Persistence task 8 - Persisting Through Existing Service. I created the shell.aspx but I can't seem to cd to the Flag. cd /flags does nothing. What is the command I used to reveal the flag 16.

ivory meadow
valid widget
ivory meadow
#

You didn't have to ping a bunch of people

#

same thing happened to me

#

I suppose the script should be updated

hushed moon
#

Hey what payload do you use to get a meterpreter on "Modifying existing services" in order to reach flag8?

ripe hedge
#

Which room is that?

trim haven
random pond
#

room: unified kill chain
task 6

Q: Mimikatz is a attack tool discovered on IT Manager's computer, what is the mission of the tool?

I have tried: privilege escalation, lateral movement, credential access

the answer is 10 stars and 7 stars.

the docs for mimikatz say it is for credentials and find vulnerabilities, escalate privs

am I close ?

lucid junco
#

Yes.

#

Third answer is half correct.

random pond
#

hmm...

#

first time seeing and using the word || dump || for an answer

ripe hedge
#

Dump without permission

hushed moon
#

Hey guys,
I'ḿ doing Windows Local Persistence room and I can't get the flag8 after getting a meterpreter. Any idea?

spiral ginkgo
#

im on task 6 of subdomain enumeration. im running the commands and they dont seem to be producing a result

#

nvm it worked now

molten bay
#

anyone able to help me with flag 2 on the file inclusion lab?
i changed the cookies guest value to /etc/flag2

ivory meadow
#

It wants you to access files from includes/ Directory

molten bay
#

like file=../../includes/etc...

ivory meadow
#

yeah, count backwards

#

and don't forget to bypass ".php" also

molten bay
#

am i getting this right?

ivory meadow
#

Nope, you need to change the cookie

molten bay
#

change something in here?

ivory meadow
#

delete that cookie and refresh, It'll create a fresh one

#

then change the value, refresh

molten bay
#

just blank?

#

it gives a welcome page

ivory meadow
#

No. That's where It gets the file name

#

type "a" there and you will see Warning: include(includes/a.php)

molten bay
#

it previews that page

#

yeah i see that

ivory meadow
#

yeah so It's trying to access a.php file in includes/ directory

#

if you put ../a there you will see Warning: include(includes/../a.php) which is equal to a.php in current directory

#

Add ../ until It arrives the main directory / and then etc/flag2

molten bay
#

so ../../../a for example

#

until i get to a valid webpage?

ivory meadow
#

Your goal is to read /etc/flag2

molten bay
#

so instead of /a i put /etc/flag2

ivory meadow
#

yes, this is path traversal

#

It's like go to the includes directory, go back, go back, go back ...

molten bay
#

go back? do you mean keep adding the ../ until i find it?

ivory meadow
#

do you know what directory is?

molten bay
#

yeah like a folder

ivory meadow
#

yes, so basically web codes are trying to include a file and you have an input for it

#

In challenge 2, It adds "includes/" at the beginning and ".php" at the end of the input

#

Currently, I'm in the /var/www/html directory

#

so If I type a there, It'll go to the includes/ directory and find a**.php** thus be like /var/www/html/includes/a.php

molten bay
#

i see but instead of a.php im lookjing for exe/flag2.php

#

thing is ive added a lot of the ../ and cannot seem to find it

ivory meadow
#

so the flag is in /etc directory : /etc/flag2 flag2 is a file

#

you also need to remove .php there

molten bay
#

ah ok

#

need to delete the .php in cookies?

#

sorry what do you mean

ivory meadow
#

You need to make it ignore .php at the end

#

by placing null bytes

molten bay
#

oh the %00

#

eyy i found it

#

wow that was crazy

#

this challenge lab took me 2 days so far

#

got to question 3 now ahah

ivory meadow
#

This is a medium-level room. I recommend you take a look at to the easy rooms first

molten bay
#

ive already done the easy ones prior in the jr pentester lab

#

thanks btw

ivory meadow
#

Did you start from that path?

molten bay
#

i started there yeah

ivory meadow
#

seems like you have background

molten bay
#

i got a comp sci degree

#

they didnt teach us much cybersecurity but i am interested in it so ik alot of the basics

ivory meadow
molten bay
#

ah im already 20% through junior

#

i feel that the prequsites may be a bit easy since this was the only room i struggled with a bit so far

ivory meadow
#

Regardless, It could be a nice refresher

main totem
#

Just saw this convo, I've done a bit of cyber sec in uni and college but starting from scratch after a while on thm def helped me. Lots of small things i forgot

harsh cipher
#

Does anyone know the answer "Where you have the option, which should you use as a second authentication factor between SMS based TOTPs or Authenticator App based TOTPs (SMS or App)?
"

harsh cipher
# ivory meadow Which room is this?

"One of the questions in this room

"Common Attacks With practical exercises see how common attacks occur, and improve your cyber hygiene to stay safer online."

umbral umbra
harsh cipher
harsh cipher
green minnowBOT
#

Gave +1 Rep to @umbral umbra

umbral umbra
#

Did you read the task info?

molten bay
#

Hey can i get some help on the file Inclusion Task 8: Challenge 3
http://10.10.221.62/challenges/chall3.php/index.php?file=../../etc/flag3%00

#

[Hint#1] Not everything is filtered! [Hint #2] The website uses $_REQUESTS to accept HTTP requests. Do research to understand it and what it accepts!

ivory meadow
#

use Burp Suite

#

and conduct research on $_REQUEST

hallow vessel
# spiral ginkgo nvm it worked now

I'm stuck on the same question, I find that if I expand the attack window I can make ffuf works, but when I try to filter size, it no longer work no matter what window size I try. How do you make it works?

spiral ginkgo
#

make sure you terminate the instance and close out. make sure it gives you a new IP and then start instance. let new IP show up and then launch attack box

hallow vessel
green minnowBOT
#

Gave +1 Rep to @spiral ginkgo

molten bay
lucid junco
molten bay
#

I see but could you help me with File Inclusion room?

#

Task 8 Challenge 3?

molten bay
#

is this the right approach because i cannot seem to find the flag in these

molten bay
#

anyone 🥲

open hare
open hare
#

Check what $_REQUEST does in PHP - Hint of flag3

molten bay
#

Ive looked at the hint it said that $_request is used to collect data after submitting a html form. but im not sure if im doing that burpsuite thing right

#

if not what kind of GET would I put instead?

ivory meadow
#

None, you don't have to use GET. That reveals it

molten bay
ivory meadow
#

What?

molten bay
#

"that reveals it" i want to reveal what the key is..

#

or what do you mean by reveal

ivory meadow
#

I meant my previous sentence

#

reveals it

molten bay
#

not sure what that means but im quite stuck on this one

ivory meadow
#

Forget it

#

Try something other than GET

#

If you have already conducted research on $_REQUEST

normal pilot
#

hint for Year of the Rabbit i have accessd the /sup3r_s3cret_fl4g/ and truned off the js and listen to the video but it tell me that i am looking at the wrong place so can anyone give me hint

molten bay
# ivory meadow Forget it

i just watched a walkthrough of the lab and they used burpsuite for the 3rd challenge. Burpsuite is not something that has been taught yet in intro to web hacking.

is it possible to complete that challenge without Burpsuite if not how come we are made to use it before even been shown it?

ivory meadow
#

It's just a simple request

molten bay
#

something like this:
curl -X POST "http://10.10.31.255/challenges/chall3.php" -d "file=../../../../etc/flag3%00"

#

or GET rather

#

it didnt return a key though

ivory meadow
#

curl -X POST "http://10.10.31.255/challenges/chall3.php" -d "method=POST&file=../../../../etc/flag3%00" --output -

molten bay
#

aah i see it brill

#

thanks

#

it seemed a lot easier in that burp tool unfortunatly it is taught after this room so i had no way of knowing how to use it

ripe hedge
#

Noone says you have to do things in order 🙂

compact surge
#

Hi

#

I'm struggling with crackmapexec issue

#

I tried password spraying on rdp

#

and it shows fails

#

while one of the users actually can rdp onto the box

#
crackmapexec rdp 10.10.120.247 -u users.txt -p passwords.txt --continue-on-success
clever heart
#

iirc it does, but outside of that remove the continue on scucess so it stops and check your ip

#

ping the target

compact surge
#

i even does not work when I supply arbitrary login and pass (valid) for rdp

#

I'm using the latest version of cme included in latest kali

#

even purged it and did clean install

#

no luck

lucid junco
#

try -P

#

-p just does the one password.

#

I think

compact surge
#

nope

#

as it works fine for smb

#

it's purely cme issue. There's even github issue opened on main repo, but guy who proposed solution, points to use a non-existing repo (lol)

clever heart
#

oh interesting

compact surge
#

indeed

#

plus, it's the latest version

#

could someone please check it on your side?

#

I'd appreciate as I'm going to create another github issue

young gulch
#

what room is this?

young gulch
compact surge
#

sure

compact surge
compact surge
young gulch
compact surge
#

well, at the end, it all boils down to the latest crackmapexec's version

#

just a lesson to don't rely soley on one tool

#

anyways, If someone could test it I'd appreciate

lucid junco
young gulch
grizzled estuary
#

Need help with Intro to C2. I needed to update the Metasploit Framework since it was 2 weeks old and I did that. When I tried to execute the program it says RHOST failed to validate. Is anyone else having this problem?

compact surge
compact surge
green minnowBOT
#

Gave +1 Rep to @young gulch

young gulch
#

hi @compact surge, can you try crowbar?

compact surge
#

Dunno it

fickle delta
#

I've been doing THM Basic Pentesting room, Task 1, What is the username? I can't make it to work, could somebody help? I've got this error: I don't know which file to use, is it rockyou.txt? But then you need to set up a password file, too

#

any hints, help, or anything? I've run myself into a wall

clever heart
#

finding the username is a massive part of it

fickle delta
#

hmm

#

but I can't seem to make it work anyway

clever heart
#

break it down one step at a time

#

Where are you at? Where are you going? What is the next step to get there?

fickle delta
#

I'm at smb_login, am I even at the right place? That's the only thing I will ask

#

just a hint

clever heart
#

What's the basic pentesting room say?

flat meteor
#

Something wrong with the Enumeration active directory ?

fickle delta
#

so I thought using smb_login module on metaspoit

#

but can't get it worked due to creds error

clever heart
#

what other smb plugins are there around enumeration

fickle delta
#

smb_enumusers

#

I've tried that, but didn't seem to work, either

clever heart
#

knowing if/why something isn't working is often more important than the what

fickle delta
#

it's not that it ins't working, it's that it gives me empty response

#

like scan complete, but no creds

clever heart
#

okay, trouble shoot it using the OSI model

#

you don't have control over layer 1 or really layer 2

#

can you touch the target machine? layer 3. is the port right? layer 4

fickle delta
#

I also have layer7, but how does this info helps?

fickle delta
#

bro, I had to just run one script and scroll a lot

#

it wasn't metasploit

#

it was written right there 😄

#

thx anyways for help @clever heart

green minnowBOT
#

Gave +1 Rep to @clever heart

clever heart
fickle delta
#

more like didn't scroll enough

#

I used a script, skimmed through it without paying attention, scrolled a bit, thought it wasn't it and moved on. So tried to find it with Metasploit, just to later get back and read it throughouly that the creds were in the script all along

clever heart
#

oof

#

Nothing like a good layer 0 attack (that's you)

fickle delta
#

😄

#

can't argue

clever heart
#

Well. I guess you could say... LessonLearned.....

ivory meadow
#

indeed

fickle delta
#

Damn

ivory meadow
#

Dr has a great humour today

fickle delta
#

now time to escalate privs somehow

#

that's the hardest part

fickle delta
#

just finished the room holy it was good

#

beat yesterday's me 😄

sinful dust
#

Hi,
i have a question about File Inclusion Task 8: Challenge 3 "get flag3":
I´ve figured out how to do it in the Terminal with the curl.
But I could not manage it to execute it within the browser.
Is that even possible?

What I tried:
-Cookie tampering within the dev tools
-dot-dot-slash in any variations

alpine kestrel
sinful dust
trim breach
#

What Burp suite is gonna do is allow you to intercept the request and view it, modify it and generally do what you want with it.

If you want to understand the method better, Burp suite will really help you because you can see exactly what is being sent to the server and exactly what it replies with

sinful dust
trim breach
#

Yeah - metasploit is definitely one of them, it pretty much handles/automates all the tech logic behind an exploit for you so that all you need to do is supply the ip addresses of the machine you are attacking and - if its vulnerable - it will work.

Probably won't help you if you are trying to learn the 'manual' way but once you understand what is happening it'll make your life easier.

In my experience, I'd say nmap is definitely up there because it allows you scan the target and gather information which is your main resource when penetration testing - and theres a room on it 🙂

fickle delta
#

also if you're going after Linux machines, a bunch of scripts like Enum4linux, LinEnum, etc, I guess??? But this was for web sites so idk

sinful dust
green minnowBOT
#

Gave +1 Rep to @trim breach

sinful dust
fickle delta
#

np

tropic garden
#

Still stuck on Gallery (https://tryhackme.com/room/gallery666). I'm at the privesc stage, but still can figure out how to exploit the || /opt/rootkit.sh || script. I tried all the options, but somehow the screen gets funky after running || export TERM=xterm || to read the report. When I explore the root directory using || /bin/nano ||, I can see the list of documents, but can't select the root.txt file.

fickle delta
#

In Simple ctf room, I found the CVE they were asking for, but then they're asking to crack a password using a wordlist. The thing they're asking to crack it with is old Python script that doesn't run on Python2 or Python3 :D. Any help?

tropic garden
#

I suppose you already have the username?

fickle delta
#

nope

#

The script I'm supposed to run should give me both username and pass

#

but I have neither

fallow venture
tropic garden
# fickle delta but I have neither

I remember I got the name via enumeration.

Using the script though, it did work until the username in my case. Had to update all the print "text" to print("text") but had errors in the password bruteforcing part.

fickle delta
#

I see

tropic garden
#

You can also bruteforce the username first and then the password

#

So you'll have to run your bruteforce command twice

fickle delta
#

which wordlist is used for the username?

#

cause if I try the one given, like 15 usernames with pass are given

#

"fixed the script" now it finds nothing

tropic garden
fallow venture
#

Yeah, got it

#

I remember the Privesc

#

Did you try Ctrl+T Ctrl+X method from GTFOBin?

fickle delta
tropic garden
fallow venture
#

And then reset; sh 1>&0 2>&0?

#

Or smth like this

tropic garden
fallow venture
#

you should get the root shell

#

with Hash sign

tropic garden
#

Yes

#

I followed the steps in GTFOBin

fallow venture
#

Gimme a sec; I'll check it now

tropic garden
#

I'll retry doing it when I get the chance.

fallow venture
#

Got the root

#

Ctrl+R Ctrl+X

#

Terminal looked stuck, but a clear fixed it

tropic garden
#

Oh.. didn't think of clearing the screen. Will check again. Thanks.

sharp furnace
#

Uhm, is this incorrect?

#

Oooh, I think I got it. You never really use your private key to encrypt the messages you are sending. Rather, you use the public key of the other person right?

ashen pendant
#

opa

umbral umbra
sharp furnace
#

that's... what I'm trying to do in that room lol

#

thanks anyways ❤️

brisk moat
#

Hello everyone! Currently working on Network Services 2/Task 4. I was able to find the id_rsa file, copy it to my /tmp/ folder and used the 'chmod 600 id_rsa' command, but I still cant ssh into the machine when I use the command 'ssh -i /tmp/id_rsa cappucino@[ip]' and i receive this error: The authenticity of host '10.10.91.80 (10.10.91.80)' can't be established.
ECDSA key fingerprint is SHA256:YZbI4MCk+BQgHK2gc4cdmXuPTzO6m8CtiVRkPalFhlU.
Are you sure you want to continue connecting (yes/no)?
Host key verification failed.

#

Is there something obvious im missing? Thanks for help in advance.

tropic garden
ripe hedge
#

The host is giving you their public key to secure the comms, and your client doesn't know about it yet

wispy birch
#

I am getting this error for Task 13 of the aoc 2022 challenge:

"TypeError: Member "toString" not unique after argument-dependent lookup in type(library Strings).
--> EtherStore.sol:8:26:
|
8 | string internal f8 = Strings.toString((((100 / 25) + 20 / 2) - 7) - 2);
| ^^^^^^^^^^^^^^^^

"https://tryhackme.com/room/adventofcyber4

warm flicker
brisk moat
green minnowBOT
#

Gave +1 Rep to @ripe hedge

ripe hedge
brisk moat
green minnowBOT
#

Gave +1 Rep to @ripe hedge

brisk moat
#

Ive hit another snag: Network Services 2 - Task 4

i have downloaded, copied the bash file, and moved to the mount. I ran the sudo chown root bash command as well as sudo chmod +s bash, however the permissions are not correct and is displaying the permissions for the bash file as -rwSr-Sr--.

Any hints are much appreciated. Thanks!

graceful breach
#

Room - RootMe CTF
I have located the uploads folder and the page topupload files.

I downloaded php-reverse-shell.php and modified with my IP address and port 4444

I could not upload as .php as the upload filter blocked it, so i uploaded as .php3

i opened a terminal and netcat listener for port 4444

The file uploaded , but when i click on it in the folder file list on the web pge it does not execute the reverse shell.

Any hints?

#

I also tried it with a file called shell-x64.php3 that i got from msvenom

ripe hedge
brisk moat
green minnowBOT
#

Gave +1 Rep to @ripe hedge

brisk moat
tropic garden
tropic garden
#

So the reason my Ctrl + R and Ctrl + X commands are not being sent to || /bin/nano || was I didn't complete the shell stabilisation process specifically the Ctrl + Z and stty raw -echo; fg step.

#

It took me almost 2 hrs to figure that out. pepehands

fallow venture
#

Usually a skip the part with backgrounding and disabling echo

#

Only spawn a shell through Python if it’s available

#

Always check for Python or Python3

#

And in rare cases through socat

#

Just make sure to Export TERM

maiden patrol
#

Can anyone help me with this one?
"Which section in Inspector is specific to POST requests?"
In Burp repeater room task 5

fallow venture
#

Difference between GET and POST, is that with GET you request something from server through Header Parameters

#

It’s the page you need, host, some other flags

#

But with POST request, you query is in the body

#

Hope you’ll get it

maiden patrol
#

Oh yeah, thank you

fallow venture
#

Got?

maiden patrol
#

Yes, thanks

#

I didn't understood the question properly

fallow venture
#

Good, keep studying.

maiden patrol
#

Thank you

tropic garden
young temple
#

Hey, I'm struggling with this question from vulnerabilities 101

#

It's asking who the author of Exploit-db is but I have been looking around for that info forever and haven't found anything

young temple
#

I have been!!

#

Still nothing

#

Looked on the exploit-db about page too

#

Nothing that fits

random bloom
young temple
#

Yeah that's what I thought too but the answer format is ********* ********

#

Lol it didn't work

#

It's like, 9 asterisks space 8 asterisks

#

So it can't be that

lucid junco
#

Which task?

#

Oh I found it.

lucid junco
young temple
#

Yeah, there's an about page and a history page and I couldn't find any names that fit in either of them

lucid junco
#

Normally. When I want to find out who owns a website, I check the footer.

young temple
#

Hmmm, I see

#

The footer says offsec services limited, doesn't fit the answer

#

I feel like the answer to this should be obvious

lucid junco
#

They recently changed their name.

As of March 2023. 😉

young temple
#

Hmmm

lucid junco
#

Got it now?

young temple
#

Nope :/

#

Can you point me in a direction?

lucid junco
#

What offsec short for?

young temple
#

Offensive security

#

HAH

lucid junco
#

There we go!

young temple
#

Man, thanks a lot

lucid junco
#

I've reported this to staff too.

young temple
#

Yeah it's a hard find

#

I appreciate it :)

steady stratus
#

Well...specifically the answer to the question 😄

bitter citrus
#

im so stupid
What do you need to access a web application?

ivory meadow
bitter citrus
#

like browser?

ivory meadow
#

precisely

bitter citrus
#

fuck, yeah, thx

graceful breach
#

Room = RootMe

I have a reverse shell and my notes to stabilize shell say use ;

python -c ‘import pty;pty.spawn(“/bin/bash”)’
Ctrl+Z
stty raw -echo
fg
export TERM=xterm

But when i enter the
python -c ‘import pty;pty.spawn(“/bin/bash”)’

I get "/bin/sh: 1: Syntax error: word unexpected (expecting ")")

neat plume
#

Try putting a space after ;?

graceful breach
#

Looks like that did it

#

Thanks

graceful breach
#

Actually, addingthe space didnot work. I had to type it in instead of cutting an pasting.

Thanks again

covert kiln
#

Hi folks, I'm stuck on the last question on STRIDE topic, room threat modeling. The last question asks about unpatched applications and STRIDE categories, I tried every possible answer. Any idea?

young temple
fallow venture
#

Hope you see the difference

#

“””” """

ripe hedge
#

Those are annoying

covert kiln
#

Hi folks, I'm stuck in the Secure Network Architecture room exercise Zone-Par Policies and Filtering, the time is too short I tried a bunch of times but can't move forward. Any idea how to solve the challenge?

green minnowBOT
#

Gave +1 Rep to @fallow venture

oak elk
uneven jetty
ivory meadow
#

You need to do them with this table

bleak wave
#

So this qustion here in the room Threat Modelling in task 2. I cant seem to find the awnser

fallow venture
#

A vulnerable target can be exploited

#

What a vulnerable target might have?

bleak wave
#

Hmm

#

Got it

torpid panther
#

I need a clue in practice Investigating Windows, What tool was used to get Windows passwords?

#

I'm in Task Scheduler but I don't know what else to put xd

random bloom
rose olive
#

"What command would be used to delete the deployment from question 5?"
My answer so far : kubectl delete <anything> hello-tryhackme
I am stuck.

fallow venture
#

Try to google it or Look in the manual

#

But îs a basic sentence

#

Kube please delete deployment with name hello-tryhackme

fallow venture
pure knot
#

I'm not understanding the SSRF exercise

umbral umbra
#

which task are you stuck on?

pure knot
#

on task 2

#

I see that changing server changes the beginning of the url and the hint is to append &x=

#

but I'm honestly clueless on this one

alpine kestrel
#

ah yes that

#

it is very confusing if you have not read the later tasks in the same room and even then it might be confusing at first

pure knot
#

should I continue on and go back then?

alpine kestrel
#

it might help so try it

#

if you want a small explaination you are gonna make the web server you are attack browse to its own url with the flag parameter thingy and end it with &x= to make it find the end of the query

#

@pure knot ⬆️

pure knot
#

using the server parameter right?

alpine kestrel
#

yeah...

#

don't have the room open so don't recall fully and heading for bed so

#

hopefully someone else can fill in more details

pure knot
#

yeah I think that's where I'm confused, because shouldn't &x= get rid of the rest of the url?

#

oh i got it

#

thanks for the help

silver pelican
#

Hi all! I'm kinda stuck in tryhackme's follina msdt room where I'm following the manual given but keep getting this error: "error detering http hosting address. Did you provide an ip or interface?". But the command doesn't have any info on providing interfaces. The command is to simply execute follina. I'm using attackbox. Any help on this?

karmic pivot
tulip mural
#

What does the hint in user flag says?

karmic pivot
#

"Everything is upside down here."

tulip mural
#

What is your current progress ?

#

I mean what are you doing on the box rn?

karmic pivot
#

can i pm ? i dont want to spoil

tulip mural
#

Sure go ahead

tropic garden
#

It was a fun room, though I overcomplicated the || teaParty || part.

karmic pivot
#

Its good i found a way ^^

white salmon
#

Any hints for the task2 of the cryptography room? This is what the question asks:

Decrypt the file quote01 encrypted (using AES256) with the key s!kR3T55 using gpg. What is the third word in the file?

ivory meadow
#

Try it with --secret-keyring 'key'

white salmon
green minnowBOT
#

Gave +1 Rep to @ivory meadow

white salmon
#

although, when i declared --passphrase in the command, shouldnt of it bypassed the need to type in the passphrase?

ivory meadow
#

Yeah perhaps

bold solar
#

Specifically, how do you get ale after safeguard?

tropic garden
median axle
median axle
#

Nevermind...

#

Don't know why I didn't pay attention to the title of the challenge

fading sentinel
#

Hey guys the updated burp module in the other modules room task 8 who has any idea

crisp jolt
#

hello im doing task 20 of owasp top 10. I've read the paper again and again i understand what i need to do but can't figure what to replace in the header.

soft basin
crisp jolt
#

nvm i found the answer but i dont get why i couldnt get it first as i did the same procedure

fathom grove
#

I think the "wild card" is needed because the file name is actually.. "interesting-file.txt.txt"... that extra extension can cause a few issues 🙂 Thanks for getting us there.

bitter citrus
#

What is the path to htb-student's home directory?
Linux FUNDAMENTALS
i cant understand like what path it needs?

lucid junco
bitter citrus
queen vapor
#

Does anyone know the answer to the hint in "Virtualization and Containers' Task 5? Something is wrong with the machine.

slow python
green minnowBOT
#

Gave +1 Rep to @slow python

outer yacht
#

Hi, guys, currently in room 'pyramidofpainax' and I feel like I'm missing something really obvious to answer the "redirected website for the shortened URL using a preview" question. I'm removing the SSL and adding the '+' to the preview, but I'm not sure if I need to find this in the any.run lab?? Not comfortable trying this on the browser.

unreal lynx
#

Can anyone help me with the hints in overpass 1 . haven't got intial access yet. if you are willing to help pls DM me .

young gulch
outer yacht
#

thank you, @young gulch !

green minnowBOT
#

Gave +1 Rep to @young gulch

unreal lynx
young gulch
unreal lynx
unreal lynx
young gulch
young gulch
# unreal lynx ||/api/login|| ?

Don’t think too hard about it. || There is a requirement that is checked before the user is allowed to access the restricted resource, but what are we able to do with it? ||

unreal lynx
unreal lynx
young gulch
#

Yes you are on the right track. It has something to do || not necessarily with cookie.js but with the cookies itself ||

unreal lynx
unreal lynx
young gulch
young gulch
unreal lynx
#

Yes. .i dont see any chances of getting the cookie here.

young gulch
unreal lynx
#

I mean can i extract something useful?

unreal lynx
young gulch
unreal lynx
young gulch
unreal lynx
young gulch
unreal lynx
#

But I don't have a cookie yet .

#

Shiiiiiiiiii i got logged in !!! @young gulch tyy broo
i figured it out !! Thank you so much for your time and patience..ahah ik i made you mad lol apologies.😂

green minnowBOT
#

Gave +1 Rep to @young gulch

compact surge
#

I'm doing Ra room and cant get spark to launcher. It requires jvm8, installed it from nvidia package, but spark still says it requires another Java package that is replaced by the one from nvidia. How did you overcome this guys? Should i leave it and run it from Windows?

unreal lynx
# young gulch Congrats!

Hey im now in the privesc part. . should i find the password of user ||tryhackme|| ? i believe its ||cron|| but the ||script|| is located in that user.

unreal lynx
young gulch
unreal lynx
young gulch
unreal lynx
tropic garden
unreal lynx
# young gulch yes!

i can modify ||/etc/hosts|| file . So i tried replicating the same on my machine. . .am i doing right?

unreal lynx
#

omg k . Edit: Thanks i found the flag.

compact surge
#

Could anyone give a nudge on Ra?

fluid peak
#

Would anyone be around to help with a room? Or rather, give a hint as to what I'm missing?

lucid junco
compact surge
#

I'm doing Ra room and cant get spark to launch. It requires jvm8, installed it from nvidia package, but spark still says it requires another Java package that is replaced by the one from nvidia. How did you overcome this guys? Should i leave it and run it from Windows?

#

Wine does not help either

grim crater
#

Hi, has anyone here successfully completed the WithYouWithMe Linux Privilege Escalation Capstone Rm1 assessment? I have got halfway through Task 4, the Depot machine. I managed an exploit which gave me a low level user shell, was able to find the D user's password (v*) and submitted it as the correct answer. I then tried to log on to the target machine as the D user with that password, but it now seems to need a public key as well as the password. I can't create or attach a pair from the low level user and am stuck. I suspect that the configuration of the machine has somehow changed as in all the training that we are supposed to be assessed on, this problem was never presented and there are no obvious routes out of the low level user shell. Anyone got any insight into this? Thanks...

young gulch
fluid peak
#

Hey, how do you get around "nc: address already in use" when trying to run a listen command for a reverse shell?

lucid junco
#

Is the address already in use?

fluid peak
#

Ermmm let meee figure out how to check

fluid peak
#

I also found out how to bypass the file upload restrictions and I've uploaded 2 different PHP shells, but they're not working

#

It just shows the code when I click on them in the web browser

lucid junco
#

Which room are you doing?

Attackbox or VM?

fluid peak
#

It's the simplest room there is lol

#

And it's through the attackbox

lucid junco
#

Ah. Port 80 is used by the VNC for the attackbox.

I'd suggest using something in the 9000 range.

fluid peak
#

Will the listener still work if it's not using the same port as the website?

lucid junco
#

Are you trying to get a rev shell?

fluid peak
#

Yeah

lucid junco
#

Then if the port number match on the rev shell and nc.

#

I assume you're using pentest monkey?

fluid peak
#

UIhhm

#

I am now

#

I had to restart the instance because my attackbox and room machine stopped responding to input

lucid junco
#

😄

Then yeah, as long as the IP matches your ENS5 or Tun0 if you're using a VM.

And the port matches what you're using to listen with

fluid peak
#

Oh okay, so it doesn't have to use the same port as the website? (80)

lucid junco
#

Nope 🙂

fluid peak
green minnowBOT
#

Gave +1 Rep to @lucid junco

fluid peak
#

Also... What do you do if it fails to daemonize and the connection is refused?

#

I've uploaded now... 4 different reverse shells

#

All have had connection refused

lucid junco
#

Which format?

fluid peak
#

PHP

lucid junco
#

I'm surprised you were allowed to upload a PHP 😉

fluid peak
#

Oh

#

I fudged the extension

#

So I'd do

#

filename.php.jpd (Which runs as php since the last file extension isn't a proper file extension

#

I've also uploaded it as .inc which runs as php

#

and I've run it is .phtml, which also runs as php

lucid junco
#

This challenge doesn't need as an extreme file type type bypass,

PHTML should have worked.

Have you changed port?

fluid peak
#

I have it set to 9000 and I've tried 9001

#

I also got the shell from the reverse shell localhost

#

Funnily enough, I wrote my own reverse shell in Python on my other laptop and got that to work in my own network but I can't seem to figure this out lol

lucid junco
#

What's your target IP?

fluid peak
#

10.10.150.98

lucid junco
fluid peak
#

I also had to restart my instance once so some of my trial and error logs are MIA, but I get back to where I left off

#

Just put that one in with the proper IP and port and it failed to daemonize

#

Connection refused

#

And yes, if you're seeing my file naming convention, it is horrible

lucid junco
#

That one is a neat one.

lucid junco
#

Just the part with the ip etc

fluid peak
#

Sure thing

lucid junco
#

Wrong ip 🙂

fluid peak
#

wot

lucid junco
#

Can you do ip a s

#

on a terminal

fluid peak
#

wait

#

Am I supposed to use my IP there?

lucid junco
#

Yeah.

#

That's the listening Ip

fluid peak
#

...

#

I can explain

lucid junco
#

So either ENS5 or Tun0

fluid peak
#

Even though I wear glasses I am still blind

lucid junco
#

It's the little things.

fluid peak
green minnowBOT
#

Gave +1 Rep to @lucid junco

fluid peak
#

And to re-affirm this

#

You should read the file name that actually ended up working

lucid junco
#

I'm touched.

But yeah, if you need a response from a Rev chell, Metasploit etc.

You need to use your own address. 🙂

fluid peak
#

This explains so much

#

Even why I was able to get my python reverse shell working on my own network... Because I input my IP, which I was also attacking

#

My brain
It is big
But
My brain
It is smooth

fluid peak
#

Oh boy..

#

[DATA] attacking ssh://10.10.150.98:22/
[STATUS] 192.00 tries/min, 192 tries in 00:01h, 14344209 to do in 1245:10h, 16 active

#

Maybe I don't use rockyou

#

Should I just let this run?

lucid junco
#

You don't need to attack the ssh?

fluid peak
#

To get the rootme password?

lucid junco
#

Priv esc. 🙂

fluid peak
#

wait a minute... I found a bunch of directories with gobuster

#

No, nevermind, those are different, I got this

grim crater
# young gulch Can you give the room link for this?

It is a room for those completing training, the Cyber Pathway, as provided by WithYouWithMe, and I suspect that it is private and as such I don't think I should give the link out - sorry. I was really looking for those who have done it as I suspect that I am on the right track but I think there may have been a configuration change which is preventing me logging in with a password that I obtained as one of the objectives.

compact surge
#

I'm doing Ra room and cant get spark to launch. It requires jvm8, installed it from nvidia package, but spark still says it requires another Java package that is replaced by the one from nvidia. How did you overcome this guys? Should i leave it and run it from Windows?

tropic garden
random bloom
rich dome
#

Hello guys im stuck on webenumerationv2, 1.3. Practical: Gobuster (Deploy #1). Last question. I´ve found the virtual hosts but no idea where the flag is. A little Help?

Nevermind. I was only looking for .php extensions

tepid creek
#

I think the "Brute Force" section in the Authentication Bypass part of Introduction to Web Hacking, may have some errors. I've checked my syntax over and over, and it's not giving the expected results... I should get back one entry that is not a 200 response code, according to the lab, but I'm not getting any entries. I have no returned errors, and I am getting 200 responses, so the ffuf command is working as it should, just not getting what I need back to complete the lab.'

lucid junco
tepid creek
green minnowBOT
#

Gave +1 Rep to @lucid junco

lucid junco
tepid creek
lucid junco
tepid creek
#

yes i did

lucid junco
#

Can you verify and show a screenshot please.

#

!docs verify

proud scarabBOT
lucid junco
#

I just done it on an attackbox.

#

And it also worked on my VM.

tepid creek
lucid junco
lucid junco
tepid creek
lucid junco
lucid junco
# tepid creek

Can you

nano valid_usernames.txt
admin
robert 
simon
steve```
#

And then try the ffuf command again

#

Working in my VM also.

tepid creek
lucid junco
tepid creek
#

Oops my ip was wrong after doing the nano valid_usernames.txt

#

why it didn't work at first.?
why needed to copy the usernames manually to valid_usernames.txt.?
it was there when I cat valid_usernames.txt right.?

lucid junco
#

Yeah, but how did you get the usernames?

Did you pipe the fluff output?

tepid creek
#

ffuf -w /usr/share/wordlists/SecLists/Usernames/Names/names.txt -X POST -d "username=FUZZ&email=x&password=x&cpassword=x" -H "Content-Type: application/x-www-form-urlencoded" -u http://10.10.234.12/customers/signup -mr "username already exists" > valid_usernames

#

using the above commnd

#

valid_usernames.txt*

lucid junco
#

Yeah. The room states If you pipe it out it won't work

tepid creek
green minnowBOT
#

Gave +1 Rep to @lucid junco

odd karma
#

Room: Sakura Room
Task: 5
URL of the picture don't capture the flag

lucid junco
odd karma
# tulip mural What?

Yes, but the page is down on the Dark Web and the link in the tips image is not capturing the flag

tulip mural
#

You can't open the image?

lucid junco
odd karma
odd karma
#

I got it thanks for the support

young gulch
#

Having a goal in mind helps

#

My main objective was to learn more about web application security and pentesting so I focused on that

green sedge
#

Not really a good way to speed through and still learn the material. Only things I can think of to help you move quicker is to take good notes so you don't have to re-read task material when stuck and make sure to utilize google when you are confused. Other that it kind of just takes as long as it takes, once you get better challenge rooms will go by faster, but the walkthroughs will kind of always take a while because there is a lot of reading material

upper mulch
#

Hello! I have a question regarding Annie's room. I've identified the exploit and successfully established a connection, but I'm encountering an issue with obtaining a reverse shell. It seems that I'm not able to acquire the shell. Can you provide some guidance or assistance in resolving this?

#

Oke I fixed it, thanks!

ruby path
#

so completing the threat intel tools room, something is not clear

#

Email2.eml from task 7

#

calculating the hash of the file is what you need to do i assume?

#

but i don't understand the question or what they are looking after ...

lucid junco
#

You need to get the sha256 hash of the email

ruby path
lucid junco
ruby path
#

ah ..

#

got it

#

thanks for the tip 🙂

white salmon
#

+rep @lucid junco

green minnowBOT
#

Gave +1 Rep to @lucid junco

graceful breach
#

Burpe Suit Repeater - Task 7 Challenge

Instructed to goto /products and modify requests to get a 500 internal server error.

I have changed several values and only get 404 error

alpine kestrel
#

and also it is using numerical systems

#

so what number could break stuffs

graceful breach
#

HTTP/1.1 being on the firstline is how Burp captured it.

If i put HTTP/1.1 on the next line i get no response

alpine kestrel
#

never mind that part about where http/1.1 is might be wrong by shadow

graceful breach
#

k

alpine kestrel
#

anyways that is a large number... what would think would happen if you send a very small number....

graceful breach
#

Well.. convention on site seems to be single integer (i.e 1,2,3,4,5)
I tired 0.5 (flaot) and still got a 404

alpine kestrel
graceful breach
#

traget site map shows /products/1 through products/5

#

there we go , -1

alpine kestrel
#

you are in #room-hints hence why shadow is not giving the answer outright but trying to hint you towards it

alpine kestrel
graceful breach
#

thank you fgor the help

alpine kestrel
#

no problem

graceful breach
#

+rep @alpine kestrel

green minnowBOT
#

Gave +1 Rep to @alpine kestrel

wispy grail
#

Hi !
Does rooms have status page ? I'm currently doing the Simple CTF (free) room, and when i use a particular tool to exploit a particular CVE (no spoil oc !) the server seems struggle to handle my requests and prematurely stop my tool with RemoteDisconnected('Remote end closed connection without response').

lucid junco
wispy grail
#

Just python with the appropriate CVE ||CVE-2019-9053|| script (||46635||), but I have broke it in several parts, find informations without crack part of the script then playing with hashcat after.

#

I restarted the machine a couple of time to get info I needed (||salt, user, hashed password||)

lethal bridge
#

Threat Intelligence Tools Room task 5 how do i move download the email to analyse it externally in phishtool as the default machine doesn't have internet access?

white salmon
unreal lynx
#

Guys i successfully rooted the Brooklyn Nine Nine . still..kinda curious why there's a ||nano.save|| file in the ||/home/holt/|| dir . when opens its a huge file and almost hungs up the machine..what was it meant for ?

modern lichen
#

hello
i need a help on Chronicle ctf
actually iam trying to do Master Password for profile 0ryxwn4c.default-release:
in some writeups it shows password1 as worked
iam tried but not working
can any one give some idea
how can i crack this password

lethal bridge
#

got the answer from viewing the source code

tropic garden
modern lichen
green minnowBOT
#

Gave +1 Rep to @tropic garden

ashen anchor
#

any hint on " Linux Privilege Escalation " Task 9 , i tried serval ways, i changed backup.sh with payload explained in task and then tried a similar one in the payloads of all things and i didn't get a shell ... ( also tried the same method with antivirus.sh in /home/karen ). also copied a payload for test.py at /temp. can anyone give a hint ?

tropic garden
ashen anchor
#

it's the one in The junior pentesting path

tropic garden
ashen anchor
#

it denied me presession

tropic garden
#

Can you do ls -lash on both scripts please?

ashen anchor
#

actually i'm not so sure, i think it didn't deny permission but i thought it was already processed.

ashen anchor
green minnowBOT
#

Gave +1 Rep to @tropic garden

ashen anchor
tropic garden
ashen anchor
green minnowBOT
#

Gave +1 Rep to @tropic garden

heavy mica
#

@proud scarab just a quick note, in the MITRE room (https://tryhackme.com/room/mitre) under the Task 7 - ATT&CK® Emulation Plans, there is a link to the Center of Threat-Informed Defense (https://mitre-engenuity.org/ctid/), this is no longer correct. I think the correct one should be https://mitre-engenuity.org/cybersecurity/center-for-threat-informed-defense/

MITRE Engenuity

The Center for Threat-Informed Defense is a collaborative R&D organization advancing state-of-the-art defenses against cyber adversaries.

flint parrot
green minnowBOT
#

Gave +1 Rep to @heavy mica

heavy mica
green minnowBOT
#

Gave +1 Rep to @flint parrot

white salmon
#

xv

pure thistle
#

in the Eradication & Remediation room where is the suspicious IP address located? i checked the Jenkins web site and grep'ed the entire drive but did not find any "suspicious" IP's

pure thistle
green minnowBOT
#

Gave +1 Rep to @ivory meadow

woven gorge
#

Wow, spend almost an hour figuring out why I'm not able to get any vhosts in Task 6 of webenumerationv2 room. Turns out, there are different version of gobuster in attackbox vs my Kali VM.
Attackbox has old 3.0.1, while Kali has latest 3.6 !!

Related: https://github.com/OJ/gobuster/issues/382
TL;DR; Use --append-domain option arg, when using gobuster version >3.0.1

GitHub

I stumbled across this example today. I was trying to figure out why one machine could enumerate the vhosts in https://tryhackme.com/room/webenumerationv2#task-6 but another could not. It turns out...

woeful hamlet
#

Good evening, I am working through THROWBACK, and am stuck trying to get the Empire Agent working on the PROD machine. I successfully uploaded the launcher.bat file, but when I run the file I get a command line error below:
admin-petersj@THROWBACK-PROD C:\Users\admin-petersj>Launcher.bat
'iex' is not recognized as an internal or external command,
operable program or batch file.

#

Here is the launcher.bat code - generated from Starkiller, http listner, windows_launcher_bat stager

#

I have followed the instructions to a "t" I believe, but cannot get this stager to work

green sedge
woeful hamlet
#

Thank you

unreal lynx
#

Can anybody help me with the hints of the ctf room Year of the rabbit . Im stuck with that ||web dir.||

tropic garden
unreal lynx
tropic garden
unreal lynx
#

oh damn got the lead . ty appreciate it. i'll ping if im stuck again . Im now blaming myself for not checking out this technique NotLikeThis 🥲

tropic garden
unreal lynx
unreal lynx
#

@tropic garden im at the privesc part...should i look for ||kernel exploits||? i think whats given in the ||sudoers file|| is not gonna help .

#

is there anyhting to do with the ||/home/eli/core|| file?

tropic garden
tropic garden
#

Have you run || linpeas, lse or any like || scripts?

unreal lynx
tropic garden
unreal lynx
#

oh .

tropic garden
#

It was in linpeas, you only need to dig a bit, but it was flagged in red.

unreal lynx
#

hm okay..i'll check again .

tropic garden
unreal lynx
#

i thought that is possible...i saved that for last resort..now you said that doesn't work..that hope is gone lol .

unreal lynx
astral mesa
#

Hello how do I verify my tyrhackme account

tropic garden
proud scarabBOT
unreal lynx
tropic garden
unreal lynx
tropic garden
unreal lynx
#

i mean are you referring to linenum by les .

unreal lynx
#

Ohh okay .

unreal lynx
unreal lynx
# tropic garden This is a || rabbit hole ||.

when you said this . i thought i never need to examine that file . but potentially that was the lead to privesc and also with the ||sudo version|| . i shouldnt have completely left out of my mind. . Anyway thanks for all the help @tropic garden its done . Have a beautiful day! 🌟

green minnowBOT
#

Gave +1 Rep to @tropic garden

tropic garden
tropic garden
tired badge
#

https://tryhackme.com/room/burpsuiteom Task 4: Decoder: Hashing - Last question: I know which PGP key is the correct one but I hash it in Decoder with MD5 and select "ASCII hex" but I never get the same hash as in the question...??? Does anybody has the same problem? This drives me crazy 😖
I always get the hash: 36f7f6e7aaa7cd1a8f202612e2a1e7f1 (and yes I saw the tip in the Hint)

formal copper
#

Hello guy, I am currently stuck at the Capture Flag3 at /etc/flag3 in the File Inclusion room. I've tried to modify the request to POST but it just doesn't work. Can someone give me a hint?

radiant moon
#

hi guys i currently stuck at find out the version of the application is running what are the name and version of application ?

mellow schooner
#

hello, i have problem from this https://tryhackme.com/room/fileinc

in task 8, Gain RCE in Lab #Playground /playground.php with RFI to execute the hostname command. What is the output?

i stuck

#

http://10.10.159.167/playground.php?file=http://127.0.0.1:9001/cmd.txt

Current Path
/var/www/html
File Content Preview of http://127.0.0.1:9001/cmd.txt

Warning: include() [function.include]: Couldn't connect to server in /var/www/html/playground.php on line 28

Warning: include(http://127.0.0.1:9001/cmd.txt) [function.include]: failed to open stream: operation failed in /var/www/html/playground.php on line 28

Warning: include() [function.include]: Failed opening 'http://127.0.0.1:9001/cmd.txt' for inclusion (include_path='.:/usr/lib/php5.2/lib/php') in /var/www/html/playground.php on line 28

tropic garden
tender seal
tropic garden
tender seal
#

yeah i checkedd too

#

trying to reach him on x

tropic garden
pale ridge
#

I had the same issue as you. After finally getting the answer I went back through the room content & "how the web works" module to see if anything like this was previously explained. I couldn't find anything.

I'd like to know if there is more content on this, because even though I got the answer, I don't really understand it!

worldly moss
#

In steel mountain room how should i replace the binary file with the legitimate one ? Do i have to escalate my privileges ? I tried to use migrate and getsystem but i don't have the permissions

tropic garden
worldly moss
tropic garden
#

You will leverage the || unquoted service path || vulnerability to escalate your privileges. Instead of the full path, you will create a .exe file containing your reverse shell payload and save it in the same directory as the || Advanced System Care || one.

nova dove
#

hERE HAVE ANYONE SOLVED "Inferno"?

#

Need some help 🙂

white salmon
#

~~Anybody finish "Source Code Security" https://tryhackme.com/room/sourcecodesecurity yet?

I completed everything, had no issues but have been unable to find the first flag for task 7. I've re-read, restarted the room server etc, followed back through carefully without luck.~~

Nevermind, I figured it out. I'd question my sanity with how long it takes me to do such simple things but I have none left.

trail thicket
#

I am stuck on Exploit Vulnerabilities task 5. Hints would be greatly appreciated 🙂

manic kettle
white salmon
molten void
#

Can someone give me a hint please? Currently doing vulnerability capstone machine and have got a payload but when I use the payload all I get back is the same piece of text no matter what I input for what I want executed

lucid junco
#

Do you have a reverse shell?

or are you trying to get the shell?

molten void
#

I'll stick with saying get the shell as I can connect with the reverse shell (networking wise) but see no signs of life coming when I attempt to input anything through the reverse shell

#

except from the same word being sent back everytime

lucid junco
#

What's the word?

molten void
#

system

lucid junco
#

Can you send a screenshot of what you're seeing?

molten void
#

Yes

#

2 clicks

#

Would sending the entire command I type out be more helpful for diagnosing?

lucid junco
#

more than likely.

molten void
lucid junco
#

try help

molten void
#

Attempting to use help within the "shell" that the exploit gives just outputs "system" again and using it as a variable with the exploit only gives the following:

optional arguments:
-h, --help show this help message and exit
-v, --version show the version of exploit
-u url, --url url Enter the url

EXAMPLE - python3 exploit.py -u http://10.10.21.74

lucid junco
molten void
#

Sure, and I will also try out that CMS script. Thanks

#

Thanks, that's me up and running now

trail thicket
molten void
#

Researching is your biggest friend when it comes to figuring out how to attack your target, look back on the other tasks and see if anything stood out for methods on identifying how to find a exploitation then apply it - doing recon on the target is also your biggest friend here

trail thicket
#

Thank you very much. Just completed it now 🙂

molten void
#

Glad to hear it, hope you enjoy the rest of the module 👍

zenith sonnet
#

Hi im in the metasploit module, at msfvenom. I got a shell on the machine but when i type hashdump or try to use the module i get this message The "hashdump" command requires the "priv" extension to be loaded (run: load priv)

hollow stump
#

Hello,

I don't know if I'm in the right section and the discord search didn't find anything.
In the room intended for Wireshark, chapter 7 ARP in the second question I had as indication of answer ..,..,..,..,..,.., which does not validate.
The expected answer was ":"

Regards

zenith sonnet
#

yes another error

odd karma
odd karma