#room-hints

1 messages ยท Page 17 of 1

glossy crane
#

do i need to escalate or something ?

boreal whale
#

which room is it?

#

@white salmon
I'm about to head to work, if you get stuck here are some spoilers
||find / -user USERHERE -type f 2>>/dev/null||

glossy crane
#

task 9

boreal whale
#

this user looks interesting ||shiba2||

white salmon
#

i finished listing shiba1 files

boreal whale
#

@glossy crane [0-9] is correct, but the {2} does not belong there

white salmon
#

will look into ||shiba2|| now

boreal whale
#

@white salmon ๐Ÿ˜‰

glossy crane
#

i tried on this

boreal whale
#

@glossy crane instead of ||{2}||, use ||{1,3}||

glossy crane
#

but my ip pattern should be ??.?.?.??

#

thats why

#

(i tried it, doesnt find anything aswell), they said in home folder but there is nothing in there

boreal whale
#

open if REALLY stuck
||grep -rn '[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}'||
sry I really gtg now hope this helps, running late

white salmon
#

hey @boreal whale I got it!! Thanks man!

inland onyx
#

Uh...

boreal whale
#

@white salmon np

inland onyx
#

Meh, if it works ๐Ÿคทโ€โ™‚๏ธ

boreal whale
#

ps..: \ infront and behind ||{1,3||

glossy crane
#

yea my machine must be glitched or something like that, i'll restart it a 3rd time ๐Ÿ˜ข

#

omg

#

why do we have to \ before { ?

inland onyx
#

You shouldn't?

#
grep -E "([0-9]{1.3}[\.]){3}[0-9]{1,3}"

That would be my suggestion

glossy crane
#

uh

#

no

#

wait

#

||[0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}||

#

this worked

inland onyx
#

No idea why you'd need to escape the curly braces

stuck fractal
#

Either you need to escape the curly brackets for bash

#

It's Bash

inland onyx
#

Ah, not a grep regex?

stuck fractal
#

Or you can put it in quotes

#

Nope, not a grep issue

#

It's a shell issue

#

Same with having $

inland onyx
#

That explains it ๐Ÿ˜† -- they were talking about grep until now

#

That's weird

gray cairn
#

Hi, i think i'm loosing it - Linux Challenges , flag 23 - Locate, read and reverse flag 23.

#

i'm trying to reverse it but this is what i got : || xxd -ps -r flag23
_๏ฟฝ%๏ฟฝ0๏ฟฝCz
OfPy%๏ฟฝ ||

pliant pagoda
#

Hackpark: Task 4 #2
What is the OS version of this windows machine?
I can't seem to see what it's looking. Noting in the box's systeminfo output fits.. Anyone have any ideas?

Answer format: XXXXXXX XXXX XX XX.X XXXXX XXXXX

stuck fractal
#

I'd advise using backticks for the answer format

pliant pagoda
#

workign on that

stuck fractal
#

otherwise discord will format it

#

`format`

pliant pagoda
#

pepehands if anyone can point me in the right direction please pm me. feels bad after rooting the box I'm missing one question

thin valley
#

can anyone help me with tomghost, I found skf**... but I feel like I'm in a rabit hole

gentle cobalt
#

I'm in the Metasploit room and can't get the reverse connection to work. https://tryhackme.com/room/metasploit
I'm on a Mac here at home and connecting this machine via VPN to the TryHackMe network. When I do "run -j" in the msfconsole, this happens:

msf5 exploit(multi/handler) > run -j

[-] Exploit failed: address family must be specified
[*] Exploit completed, but no session was created.

I set both options the exploit provided as described in the tutorial. Google isn't of help in this case.
I tried using a Linux machine. A cloud server connected directly to the Internet. I built my payload, uploaded it to the vulnerable Windows machine and executed it via accessing the file in the browser. But nothing happens. The port on the target machine is open, I checked with nmap. But even after several minutes no connection is being established. What am I doing wrong?
Oh, after a while the webserver is responding again, this is the content of the website:

/*

white salmon
#

Icecast?

#

If so, you have to connect to icecast, not just multi/handler

slim skiff
#

Can you help me with the zip password? Im stuck on it i did the zip2john 8702.zip > hash.txt, and then the john hash.txt gives this output:

Using default input encoding: UTF-8
Loaded 1 password hash (ZIP, WinZip [PBKDF2-SHA1 256/256 AVX2 8x])
No password hashes left to crack (see FAQ)
Im new to this sorry if the question is stupid,but i searched everywhere.

#

and it does not unhash anything

#

Agent sudo room

stuck fractal
#

try --show

slim skiff
#

and nothing has changed

#

ooooo

#

yeah i see it

#

the smily made it harder

#

thank you very much!

#

wow

#

thanks!

stuck fractal
#

imma delete that message as I think discord censored the password

solar dune
#

Hi everyone - I'm possibly being extremely thick here but could someone help me with the box "alfred" please?

inland onyx
#

Just ask mate ๐Ÿ˜„

solar dune
#

ok haha

#

thank-you . I'm really struggling with the first bit for some reason - it straight up asks me what the username and password is for the login page. Now I've tried enumerating everything, going to anything i found, viewing page source code - everything. + I can't find anything. I'm at the point now where I am fuzzing it with some enormous wordlist and I am certain it's wrong. PLEASE HELP! ๐Ÿ˜„

#

it's not default creds i've tried those

inland onyx
#

Pretty sure you're on the right lines

#

Just checking my notes to make sure I'm not mixing it up with Hackpark here..

#

But it should be default creds

solar dune
#

hmmm wat

#

let me retry

inland onyx
#

Can you post the default creds you're trying inside a spoiler(||<text-here>||)?

#

I'll check 'em and delete in a second

#

I'll check my notes

#

But from memory

solar dune
#

thank-you ๐Ÿ™‚

inland onyx
#

One of those combos is right

#

Yep

#

One of those is right

solar dune
#

ok that's very odd

inland onyx
#

Try again, and make sure there are no typos ๐Ÿ˜„

solar dune
#

so things got weird - i just entered them into the field in the room - accepted them fine - not on the box though

#

think maybe the box worth terminating and restarting?

inland onyx
#

Quite possibly, yes

#

Windows boxes can be, temperamental, although Alfred should be fairly stable

solar dune
#

yeah it's definitely buggered - just checked my wordlist for fuzzing and that combo absolutely is in there

#

restarting now ๐Ÿ˜„

#

thanks for your help

inland onyx
#

Np ๐Ÿ˜„

obsidian bridge
#

I have questions regarding metasploit smb eternalblue exploitation, yesterday I've done almost every tasks of blue room, I got meterpreter access to machine, just didn't done last 3 tasks which was to find a flag. Now I'm trying to exploit smb, exactly as I did it yesterday, and this happens:

#

||
`msf5 exploit(windows/smb/ms17_010_eternalblue) > run

[] Started reverse TCP handler on 192.168.1.10:4444
[
] 10.10.32.206:445 - Using auxiliary/scanner/smb/smb_ms17_010 as check
[] 10.10.32.206:445 - Scanned 1 of 1 hosts (100% complete)
[
] 10.10.32.206:445 - Connecting to target for exploitation.
[-] 10.10.32.206:445 - Rex::ConnectionTimeout: The connection timed out (10.10.32.206:445).
[*] Exploit completed, but no session was created.
`||

steady stratus
#

Your IP Address is wrong

#

You need to set the LHOST as your TryHackMe VPN IP Address (i.e. 10.8, 10.9)

#

you can usually set the interface instead (tun0) but setting LHOST to your THM IP Address would be best imho

obsidian bridge
#

hmmm... thanks in advance, I'll check it out, but I don't remember I did it last time

#

nvrmnd, I'll check it out, thank you ๐Ÿ™‚

steady stratus
#

"Started reverse TCP handler on 192.168.1.10:4444 " would be the IP address of the Kali VM / device you're on ๐Ÿ™‚

obsidian bridge
#

yeah

steady stratus
#

and as the instances don't reach the internet (nor is your router hopefully port forwarding 4444), you need the openvpn IP ๐Ÿ™‚

obsidian bridge
#

hmmm, allright

#

hmm lmao

#

is it ok?

steady stratus
#

That means you're not connected - but the tryhackme.com/access page isn't all that reliable. check ifconfig and you'll see something like 10.8 or 10.9

obsidian bridge
#

hmm, I've run openvpn with --daemon, and it can be the case blobhuh , it could not start at all

#

weird, but possible

steady stratus
#

check the output of ifconfig, if you don't get an IP address refer back to the documentation incl. troubleshooting. If that doesn't work, #site-support

obsidian bridge
#

thanks, it works now :), done thank you very much @steady stratus

steady stratus
#

Any time pal! Enjoy the content

signal perch
stuck fractal
#

@signal perch you're close. You personally will be able to cat it, but only editing from a different user.

signal perch
#

|| do I need to use LinEnum at that point || ?

stuck fractal
#

@signal perch that task was answers from linenum so yeah?

signal perch
#

well, im not sure to understand the relation there, but the tab says :Enumeration and that the beginning its talking about LinEnum

#

does that mean || i have to install it and try to launch then from the target computer ? ||

trail gulch
#

i'm so bad
I was ls in the wrong directory and was thinking why is there shiba1 but not shiba2, so I had to change to shiba2 directory to get the binary ;///
@boreal whale i think it's a not a very well written question (task 21 zthlinux)

white salmon
#

last task

vast hemlock
#

Can someone help me with the XSS room?

#

I have no idea what Task3 #4/#5 wants from me.

#

I've changed the page title, but I assume that;s not it

#

And I've posted the cookie stealer link, but jack never logins

#

Also, if I try to visit the page, I get automatically redirected to my cookie stealer

white salmon
#

@gray cairn Could you already solve Task 4 #4 of Linux Challenges?

thin valley
#

can anyone help me with tomghost, I found skyf**... in web.xml but I feel like I'm in a rabit hole

vast hemlock
#

@thin valley why don't you check with the writeup?

stuck fractal
#

is there a writeup for it yet?

thin valley
#

@stuck fractal @vast hemlock I was stuck last night, It had no writeups, but I just checked there's a writeup now

#

thank you guys!

stuck fractal
#

Weird, wouldn't have expected one so soon

thin valley
#

Yeah I know, I was planning into writing one, but got stuck

#

my brain was ducked

#

๐Ÿ˜†

#

wait, that's weird, I got the credentials and tried to ssh with it too but it didn't work yesterday, that's weird blobhuh

runic thistle
#

hi hackers am stuck at VulnUniversity room task 4 question 5 any hint

glossy basin
#

check the writeup

runic thistle
#

okey thanks

tranquil wing
#

anyone able to help, trying to get flag 3, have used metasploit on a wordpress to run admin shell upload but once in the shell i dont have any permissions to open the flag3.txt

glossy basin
#

which room is that?

stuck fractal
#

@tranquil wing If this is the coursework for UoP, we can't help

tranquil wing
#

for a university one, so i think it might be a private one

#

oh damn

stuck fractal
#

Other than escalate privileges if you can't read a file

#

Don't have permissions? Get permissions.

tranquil wing
#

alright

white salmon
#

Linux room, shiba3: how do I go about getting privileges to make a directory in the home directory?

boreal whale
#

what task are you trying to do?

white salmon
#

32

boreal whale
#

32 or 33?
because 32 does not say anything about creating a directory

white salmon
#

33 then

boreal whale
#

just go to your home directory cd ~ and mkdir test

white salmon
#

Everytime I get "permission denied"

#

I've used chmod and chown, same result. Tried doing a link, same result

stuck fractal
#

Your home directory, not THE home directory

boreal whale
#

``cd ~`

white salmon
#

Okay, thanks

#

Got a bit confused there

boreal whale
#

you got me a bit confused too, not being able to mkdir in your ~ directory ;dd

midnight swallow
#

hey room vulnuniversity, i have a reverse shell and it asks what user is running the webserver, how is the result of whoami not the answer?

#

nevermind lmao

#

got it

tawdry dove
#

In steelmountain I cannot write the running service. If I stop the service and rewrite it I get an error as start. Is this the right path I am on?

obsidian flicker
#

Hi, i'm currently doing the room called "ice" and am on the step using metasploit.
Using the exploit bypassuac_eventvwr i am supposed to set session, then get more options to set

#

but still only see the option to set session, nothing more

#

it seems to run just fine with just 1 option set

#

aah no, it didn't create a session

#

running it makes options appear

stuck fractal
#

@tawdry dove Does it stop after 30s or just not start?

tawdry dove
#

@stuck fractal It does not start. I tried another aproach without modifing the original service file and putting it closer to root but I get an error

ERROR:     + CategoryInfo          : OpenError: (System.ServiceProcess.ServiceController:ServiceController) [Restart-Service]
ERROR:    , ServiceCommandException
ERROR:     + FullyQualifiedErrorId : CouldNotStartService,Microsoft.PowerShell.Commands.RestartServiceCommand
ERROR: ```
#

Wait. Trying something else

#

Wierd. I ran the exe again with the correct format this time and possibly correct LHOST and I get the shell. But I still have an error in the powershell command

#

Ownd! Thanks James

past night
#

CaN sOmEoNe HeLp Me WiTh ThE rEsEaRcH rOoM

#

thanks

bitter crane
#

What's a research

stuck fractal
#

You put the reeeee in research @past night

past night
#

no, for real

#

i'm stuck at task 1 #2

#

my answer doesn't work

stuck fractal
#

@past night You troll, there's no task 1 question 2

past night
#

damn

#

i was meaning #6 from Task 2

inland onyx
#

Really?

#

You sure?

past night
#

very sure

inland onyx
#

Least we're being honest!

stuck fractal
#

Nickname checks out

past night
#

hehe

#

why did i give you guys ideas

#

TT_TT

#

;-;

inland onyx
#

You only have yourself to blame...

past night
#

it's not fair

#

i'll pull my secret french move

inland onyx
#

Not my fault you threatened one of the people who actually can change nicknames ๐Ÿคทโ€โ™‚๏ธ

stuck fractal
#

french

#

you're not french

past night
#

๐Ÿณ๏ธ

stuck fractal
#

๐Ÿ‡ท๐Ÿ‡ด

past night
#

i was asking how to

#

yeah, that's my home country

#

^

inland onyx
#

How to?

bitter crane
#

.. there's a research room now?

inland onyx
#

There is

#

It was released earlier

#

You're welcome

past night
bitter crane
#

oh, just released

past night
#

what the Boris is custer

bitter crane
#

General Custard

inland onyx
#

Research, Chev, research!

past night
#

you owe me a beer.

#

first of all

inland onyx
#

True...

past night
#

then we discuss

inland onyx
#

Get yourself up to Securi-Tay next year, I'll get you that beer ๐Ÿ‘

bitter crane
#

What is they keyword

past night
#

Boris

#

yeah, if i'm still in England sure

inland onyx
#

Any reason you wouldn't be?

past night
#

moving to NL

inland onyx
#

NL?

past night
#

or spain

#

netherlands

inland onyx
#

Ah, fair enough. This got something to do with Brexit?

past night
#

||with corona, i can at least buy a cheaper property||

inland onyx
#

True...

past night
#

nah, i got my presettled status

inland onyx
#

Fair enough

terse basin
#

Dont know if this is the more appropriate channel, but I need some help. I'm in the ice room and trying to get the escalation exploit to work but it will not take and start the second session. I have restarted the box and my root twice with the same results. I have set the session and the lhost to tun0 before running. I watched and followed the walkthroughs but it still didnt take. Can anyone help me with what I am missing?

boreal whale
#

@terse basin you still here?

#

make sure you have ||LPORT 4444||

#

PM me and I'll try to help you out ๐Ÿ™‚

white salmon
#

in privilege escalation of linux,task 6,challenge 2> is there any trick,i have read,overead,cant get the answer ๐Ÿ™‚

#

got it,thx

lavish solstice
#

Hey guys
Kinda stuck on the final task of the linux machine
getting access to root.txt to get the flag
can someone help please ?

boreal whale
#

@lavish solstice look through different users files

lavish solstice
#

I did !

#

Let me check again

#

Thanks ๐Ÿ˜„

boreal whale
#

to be more specific files that are own by those users

#

not in their home directory

#

you'll have to use a command to find ๐Ÿ˜‰ files that are owned by different users

lavish solstice
#

I kinda see where youre getting

#

Let me try

boreal whale
#

VERY SPOILER ALERT------------ @lavish solstice ONLY use if you get REALLY stuck!!!
||find|| ||/|| ||-user shiba2|| ||-type f|| ||2>/dev/null||

white salmon
#

O damn

#

That's like

#

Maximum spoiler

boreal whale
#

Yes! Indeed!

white salmon
#

I find your profile picture adorable

boreal whale
#

yours too ๐Ÿ™‚

white salmon
#

๐Ÿ˜

royal badger
#

hi im stuck in introtoresearch task 2 question 4. anyone have an idea where i should be looking?

lavish solstice
#

okay

#

so

#

it searches for files owned by shiba2 and showing only files ? not directories ?

#

and what is that part of the find command ? 2>/dev/null
@boreal whale

boreal whale
#

yes :)
2>/dev/null ignores errors

#

when it was looking for files, did you find some file that looked interesting?

#

cough cough ||top|| of the search

lavish solstice
#

haha still didnt white out the black part

#

let me check

#

that ignore error is amazing

#

I tried using find alot and all the permission denied really annoyed me

boreal whale
#

yea when i found out about it I was amazed ;d

#

@royal badger hang in there budd, im looking ;d

bitter crane
#

data-piping in general are amazing

boreal whale
#

give us an example of a data-pipe :?

bitter crane
#

find / -name "cake" 2> /dev/null

#

2> means "write the error data-stream to"

boreal whale
#

aaaaa

#

i only knew that 2>/dev/null ignores error and that is it lol

bitter crane
#

/dev/null is a special device that just ignores everything you tell it

royal badger
#

@boreal whale ill try looking harder, untill idk

boreal whale
#

I see

lavish solstice
#

Thats awesome to know !

#

Thanks a bunch

#

@boreal whale found the credentials to nootnoot

boreal whale
#

๐Ÿ˜‰

#

my man

lavish solstice
#

how did you know to run -user shiba2 ?

#

and not

#

shiba1,3,4?

white salmon
#

It's a spoiler

boreal whale
#

i've completed the room

white salmon
#

He knew that because he already found it

lavish solstice
#

I know

#

I mean

boreal whale
#

you just have to look around

#

and get hints from us here

white salmon
#

Actually there is an intended way of figuring it out

lavish solstice
#

I should;ve just done the find -user for every user ?

#

Thats what i ment @white salmon

#

wait so I still didnt finish

#

Im at user nootnoot

white salmon
#

Just do some thonking

boreal whale
#

ok

#

do sudo -l

#

what can you do?

white salmon
#

Well now come on @boreal whale

lavish solstice
#

Im done ๐Ÿ˜„

#

i've found out that noot is a sudo

#

sudoer

boreal whale
#

๐Ÿ˜‰

lavish solstice
#

cause of the . file

#

in his home directory

#

just didnt have his creds

#

thanks alot guys ๐Ÿ˜„

#

first room completed

royal badger
#

o i solved it @boreal whale

boreal whale
#

also sudo -l shows that you can do ALL

#

@royal badger you did ๐Ÿ˜ฎ

royal badger
#

i ended up guessing

#

alot

boreal whale
#

๐Ÿ˜„

#

hopefully you learned why that is the answer, ONLY then is okay to guess

royal badger
#

im looking into it now to see why thats the answer ๐Ÿ™‚

lavish solstice
#

hey @boreal whale

#

Question about the sudo -l

#

I saw that I got ALL

#

But what does that mean ? I first tried sudo cd root/

#

It didnt let me cd

#

only sudo cat root/root.txt

#

ALL means the commands I can run as sudo ?

boreal whale
#

to my understanding is that you can run sudo on commands without getting message like 'you are not a sudoer user', etc

#

you can still fail to run sudo on other things because you are not root yet

#

right now you are just priviledged user

bitter crane
#

though some commands don't make sense to sudo. Such as cd'ing into /root/ or sudo /bin/bash -- those you still can't do

lavish solstice
#

I see, but other than those I can do anything with sudo like im logged into root ?

boreal whale
#

hey @lavish solstice
do you want to become root?

lavish solstice
#

On the linux room machine ?

boreal whale
#

yes

lavish solstice
#

Yeah ๐Ÿ˜„

#

I downloaded with scp the script that someone told me

boreal whale
#

ok so you have nootnoot's credentials right

lavish solstice
#

linpeas

#

yeah

boreal whale
#

type
whoami
first

lavish solstice
#

I

#

AM

#

NOOTNOOT

bitter crane
#

24601

boreal whale
#

ok

#

type
sudo vi

#

are you there?

lavish solstice
#

Hold on

#

Lost connection to room

boreal whale
#

๐Ÿ˜ฎ

lavish solstice
#

yeah im there

#

connected to VPN again

boreal whale
#

it looks like a notepad thingy right?

#

where you would take notes

lavish solstice
#

yeah

#

I know how to use vi kinda

bitter crane
#

except for nerds

boreal whale
#

type ||:!sh||

#

and ENTER

#

now
whoami

lavish solstice
#

what the hell

#

xD

bitter crane
#

subshell

lavish solstice
#

Explain ?

boreal whale
#

i dont know how it works, I just know it works ๐Ÿ˜„

lavish solstice
#

do i have to run it through sudo vi ?

#

because i ran it as root ?

boreal whale
#

bread mind explaining :?

lavish solstice
#

so when I call shell as sudo vi it calls it as root ?

bitter crane
#

you're running vi with sudo, meaning that you're essencially running vi as root, except on your user. :sh tells vi, for whatever demented reason, to create a new shell -- not go back to the one you came from.

#

because vi was launched as root, that new subshell will be logged in as root

lavish solstice
#

So basically I can do it from any machine as a sudoer user ?

boreal whale
#

makes sense

bitter crane
#

I haven't actually tried it, but you should be able to, yes

#

there's not much you can do from root that you can't do with sudo - except for the odd stuff like cding into a folder only accessble by root -- mind you that you can still do stuff like sudo ls /root/ without actually being logged in as root

tawdry dove
#

I remember that I could not get list files I had not permission to as unprivileged user with sudo and globbing

#

Or because of dir x permission I can't remember

#
hydra.restore
kali@kali:~/TryHackMe/OSCP/alfred$ sudo ls /root/*
ls: cannot access '/root/*': No such file or directory
#

Not sure why this is

past night
#

you sure it's a linux box

#

@tawdry dove

glossy basin
#

it seems like they are doing it on their machine

#

because of the directory name ~/TryHackMe/OSCP/alfred

past night
#

yeah still

#

if i recall from all the weird convos

glossy basin
#

alfred is a ||w-box||

past night
#

that's why i am saying

#

so ls is not a command for listing directories

glossy basin
#

yup, but it's in kali@kali

tawdry dove
#
/root/hydra.restore
kali@kali:~$ sudo ls /root/*
ls: cannot access '/root/*': No such file or directory
kali@kali:~$ sudo ls "/root/*"
ls: cannot access '/root/*': No such file or directory
#

Anyway. It's a small quirk. I wouldn't dwell much on it

white salmon
#

can someone help me cc steganography key 3?

glossy basin
#

@white salmon what have you tried?

#

I have it completed by i don't remember the exact way

white salmon
#

the name is qrcode.png and i tried zsteg and stegoveritas and nothing

glossy basin
#

have you opened the file?

white salmon
#

what file? the png

glossy basin
#

yeah

white salmon
glossy basin
#

oh i rember it now

#

you have to scan it

#

stegoveritas automatically changes all the colors and puts them in "results" folder

#

so you can scan it

white salmon
#

thx!!

wheat hollow
#

Any nudge for rooting zthlinux please?

bitter crane
#

nudge nudge you're gonna have to be a bit more specific than that nudge nudge

#

what are you looking for?

wheat hollow
#

@bitter crane it's a pun, isn't it?

#

If so, I didn't quite get it lol

glossy basin
#

@wheat hollow check the writeup for guidance

bitter crane
#

It's a hint, but yes, quite vague :p

inland onyx
#

Yes, please check that writeup. I sacrificed my sanity writing up a tutorial room. Appreciate it if it didn't go in vain

bitter crane
#

do struggle a bit first, though ;D

wheat hollow
#

Is it a room @glossy basin ? I cannot find it.

glossy basin
#

!writeup zthlinux

proud scarabBOT
glossy basin
#

@wheat hollow ^^

wheat hollow
#

Lol it's not listed in the write ups section

#

But thanks!

stuck fractal
#

That push is coming

#

Currently "simple" rooms don't have a writeups tab

white salmon
#

any hints on what to do after accesing the webserver in task 15 Advent of Cyber room

#

because it is a docker image, i cannot do find or grep. how can i find the flag without them

inland onyx
#

@white salmon Would that be Day 10, Metasploit?

white salmon
#

@inland onyx Yess

inland onyx
#

Can you drop into a shell from metasploit?

#

shell?

white salmon
#

yeah i am currently in the shell and i think i am root

#

but its a docker image

inland onyx
#

Are you in meterpreter, or shell?

white salmon
#

meterpreter

inland onyx
#

Drop into a shell

white salmon
#

isn't that the shell of the target machine?

inland onyx
#

From memory you can use find from that

#

Meterpreter is a metasploit shell

#

It's usually more powerful, but sometimes you need to execute commands directly onto the target system

white salmon
#

how can i drop into a shell

inland onyx
#

shell

#

(From memory)

#

Ta @dusky vigil ๐Ÿ˜„

white salmon
#

ohh yeah now i can run normal programs

#

Thanks @inland onyx

inland onyx
#

๐Ÿ‘

boreal whale
#

what's a nice, nmap scan for a host that you know nothing about and the scan does not take 20 min ;/

stuck fractal
#

nmap -sV -v -p-

white salmon
#

He said that doesn't take about 20 min

#

@boreal whale you can try using --top-ports

#

Nmap by default uses the top 1000 ports iirc

#

If you want to try a bigger number you can use that flag

boreal whale
#

ok I'll try them out
i've been wait 17 mins for my nmap to finish scanning ;d

white salmon
#

But using -p- will pick up every port

#

So it's still worth doing

#

Just to.make sure you don't miss anything

stuck fractal
#

@white salmon Normally takes about a minute or something for me

white salmon
#

Lucky

white salmon
#

Mine average about 2 minutes

plush estuary
#

I think my fastest scan on THM was 5min

dusky vigil
#

hit it with that T5 --min-rate 2500

#

Soon find speeds faster than a ket dealer on a peppa pig bike

stuck fractal
#

Interesting mental image

white salmon
#

somebody saw hostclouds i've got questions

past night
#

usually i give it at least half an hour

#

jk

white salmon
#

can anyone help me with ccpentesting
task 4
question 14
or recommend any wordlists?

past night
bitter crane
#

try๐Ÿ—

white salmon
#

hints?

tawdry dove
#

Doing hackpark. A little hint on uploading a file to cmd? I have access to PowerShell but I could not get the file download via PS from cmd. I also tried to launch PS directly but it did not work

white salmon
#

I was doing RP:Nmap, and in the final question, I'm asked to find a dos vulnerability, so I ran nmap --script dos, but then I get that: https://puu.sh/FrgjY/39f366d97c.png
Do anyone know what is going on, or a better way to find what I'm asked to ? (even if the answer is in the hint)

bitter crane
#

Could you link the room? I don't recall anything about dos

tidal sedge
tawdry dove
#

Doing hackpark. A little hint on uploading a file to cmd? I have access to PowerShell but I could not get the file download via PS from cmd. I also tried to launch PS directly but it did not work
@tawdry dove try ftp

tidal sedge
#

@white salmon You're running the wrong script

white salmon
#

okay, that explains it then

bitter crane
#

Ah i see. I forgot that question :p

#

read the question again ;)

white salmon
#

I tried --script vuln just before, but it didn't find anything, so i tried dos

#

Oh i know

#

I ran vuln only on the 80th port

#

Okay, just ran vuln again and it found the dos vuln on the 80th port. I don't know why it didn't show up before, but now it worked. Issue solved!

bitter crane
#

nice!

#

also, be careful with dos scripts, even on THM.

#

it's a good way to get an angry email from your ISP

white salmon
#

ahah okay, thanks for the tip

echo thunder
#

hello all

#

i have a problem with a room

white salmon
#

What room are you in @echo thunder

echo thunder
#

now I am in XXE

#

XXE-2

white salmon
#

Can you link the room? And tell the task you're stucked on? It will be much easier for people willing to help you

echo thunder
#

I finished the room

#

now

white salmon
#

Allright, glad to hear it!

#

Cheers!

echo thunder
#

it was a problem with the key importing

tawdry dove
#

Doing hackpark. A little hint on uploading a file to cmd? I have access to PowerShell but I could not get the file download via PS from cmd. I also tried to launch PS directly but it did not work

I am still here. Can't get ftp to work (interactive is broken). Can't download via PowerShell (I don't get any errors back to term to see what's wrong). Any other hints?

#

I am still here. Can't get ftp to work (interactive is broken). Can't download via PowerShell (I don't get any errors back to term to see what's wrong). Any other hints?
@tawdry dove Try to see if you can write to a file then try redirecting stderr to a file to see if you get any errors.

white salmon
#

hey guys , any hint for flag 25 room Linux Challenges?

glossy basin
#

!writeup zthlinux

proud scarabBOT
stuck fractal
#

@glossy basin This is for hints, not writeups (please?)

glossy basin
#

yes, but..

#

hinting on this room is pretty hard, honestly

white salmon
#

yep I know about writeups that is cool but I would like to understand why

glossy basin
#

okay sure let me check

#

i'll hint

white salmon
#

ty ๐Ÿ˜„

glossy basin
#

so you mean task 25?

#

and what's the question?

white salmon
#

#7

Locate and retrieve flag 26.

inland onyx
#

@white salmon for the record, I deliberately wrote that writeup with as much explanation as possible

white salmon
#

sry was a mistype

inland onyx
#

Uh, wait a second

glossy basin
#

it's linux challenges

#

not learn linux

white salmon
#

yep linux challenge

glossy basin
#

my sub expired ๐Ÿ˜ฆ i can't check my previous answers

#

@inland onyx do you have a sub?)

inland onyx
#

I do, but I'm on the phone

ripe meteor
proven bridge
#

@ripe meteor Check the information above the task.

ripe meteor
#

im stuck

proven bridge
#

What have you tried?

ripe meteor
#

ya

#

i export $test1234=$USER

trim breach
#

what does it say when you run that command

ripe meteor
#

@trim breach nothing

trim breach
#

so what happens when you then view the value of test1234

ripe meteor
#

i types echo $test1234 and it shows shiba2

trim breach
#

Okay thats good so now what do you think you should do

proven bridge
#

^

tawdry dove
dense latch
#

Hello i'm struggling with the following sentence in the Room :" Introductory Researching"

#

Task 2 q4
What number base could you use as a shorthand for base 2 (binary)?

#

i'm not an english native

thin yew
#

What three letter abbreviation is the technical term for the "wifi code"?

#

can you point me in the right direction?

stuck fractal
#

Look at the standards and how wpa works @thin yew

smoky meadow
#

I need a quick hint on username listing I use getent passwd yet cannot list the users! who can log in

thin yew
#

@stuck fractal I think there may be an error with the wifi hacking 101 question or im just stupid

stuck fractal
#

@thin yew there's not.

#

People get stuck on it

thin yew
#

ahhhh

#

just one of thoes kina questions

stuck fractal
#

It's really simple

#

But you will overlook it

#

Look at how the WPA handshake works

thin yew
#

will do. thank you very much

#

is it case sensitive?

autumn ferry
#

This is interesting

#

What do they mean by 'code'?

#

Wifi code

#

Is it the encryption, passohrase, or something else?

thin yew
#

thats what ive been researching

calm prism
#

can someone help me on the christmas room day 10?
on metasploit i get exploit complete but no session was created

autumn ferry
#

What's the context? @thin yew

stuck fractal
#

Yes case sensitive

autumn ferry
#

@calm prism same thing. you have to select a payload

stuck fractal
#

Code/password/etc

calm prism
#

I selected everything and set up anything

autumn ferry
#

What's your payload?

#

Do show payload

#

It has to match the OS

#

Windows for windows, Linux for Linux

calm prism
#

ye its
linux/x86/meterpreter/reverse_tcp

#

and im on linux

stuck fractal
#

It's not your host, it's your target that matters for arch

autumn ferry
#

^

stuck fractal
#

And what's your LHOST set to?

#

Bet you it's not quite right

calm prism
#

I set this to the openvpn ip

#

is it the correct one?

autumn ferry
#

Yep

#

What's the targeturi?

calm prism
#

showcase.action

autumn ferry
#

/showcase.action

#

I mean I don't think it makes a difference

#

But try

calm prism
#

ok lemme try this

autumn ferry
#

Sure

#

I don't know if Metasploit appends the slash

calm prism
#

I think it is cause still no session created

autumn ferry
#

Hmm

calm prism
#

the RPORT and LPORT are the default one

autumn ferry
#

Could you screenshot the output of show options

calm prism
#

sure

autumn ferry
#

And the lport can stay default

#

It's the lhost that has to match

calm prism
#

can I send links here cause this is on my vm so I need to upload it to somewhere

autumn ferry
#

O

#

Hm

calm prism
#

do u mind if I send u this on dm?

autumn ferry
#

Sure

calm prism
#

sent you dm

thin yew
#

got it @stuck fractal thanks

dusty salmon
#

Anyone here can help me / hint me as per HackPark's bruteforce?

#

I've been bruteforcing for 1/2 an hour and no results.

autumn ferry
#

Did you try empty password?

#

Or defaults?

dusty salmon
#

@autumn ferry -- I'm using rockyou.txt, which takes forever to brute.

autumn ferry
#

Yes, but also try some default credentials

#

admin:admin, admin:password, etc

#

Blank password too

#

I was brute forcing a file once

#

For sooo long

#

Turned out to be an empty password

dusty salmon
#

@autumn ferry -- Did you root HackPark?

#

Okay, I'll try using a smaller wordlist.

autumn ferry
#

No no, I mean first try default passwords and also try an empty password

dusty salmon
#

Tried, empty password.

#

Rocking it with rockyou.txt but no luck.

#

The missions states to use Hydra.

autumn ferry
#

Just wait then I guess. While you're waiting though check for other things you've found in that challenge that might be the password

#

Hm

#

Usually there are hints in the supporting material

dusty salmon
#

Tried using a lesser dictionary, still no luck.

#

Anyone else can help?

bitter crane
#

Do you know the username(s) to use?

dusty salmon
#

Yes...I do.

bitter crane
#

please delete spoilers

#

thanks

dusty salmon
#

Any other hints?

bitter crane
#

Sadly not what I know. I haven't done HackPack yet -- just read a bit about it here and there

dusty salmon
#

I see. I see.

still parrot
#

Anyone around to help on steelmountain?

bitter crane
#

Ask the question, don't ask to ask :)

still parrot
#

Alright thanks ๐Ÿ™‚

#

Im doing the privesc and im trying to reboot the service but it says it wont respond in a reasonable time

#

is there any way around this?

bitter crane
#

Could you show me message where it says it won't respond in a reasonable time?

still parrot
#

i blanked out the service to avoid spoilers

stuck fractal
#

Yep so it dies after 30s right?

#

I got around this with prepend migrate with MSFVenom, basically migrates the shell to another process immediately so it doesn't matter when the original dies

bitter crane
#

I don't recall having this problem at all

stuck fractal
#

I did

#

I think it depends what you replace

bitter crane
#

Right.

still parrot
#

I didnt replace anything really I just dumped it into the writable folder

bitter crane
#

yeah, but you're replacing what gets launched :p

still parrot
#

True

#

How would I do the prepend migrate in MSFVenom then?

bitter crane
#

That's magic talk to me.

#

I'd just try to do the migration real quick once it connects -- well.. if it connects

still parrot
#

yeah it never does

bitter crane
#

Oh. So it doesn't just die

stuck fractal
#

google msfvenom prepend migrate

#

Oh weird

still parrot
#

My shell never opens

#

The service just won't start back up

bitter crane
#

you're listening to the right port with nc and all that, right?

#

just checking -- you never know

still parrot
#

Im using multi/handler but its on the right port

bitter crane
#

ah, right

still parrot
#

im a dumbass

bitter crane
#

I guess I just went for the simpler attack and made a reverse shell, no meterpreter

still parrot
#

:///

bitter crane
#

yeah? Listening to the wrong port?

still parrot
#

works just fine with nc

bitter crane
#

hehehe

#

I don't really know how the multihandler thing works

still parrot
#

I didnt use a meterpreter shell when I generated it using msfvenom

#

I dunno why I bothered with the handler I've never had any issues with nc before

#

But this time I thought yeah lets use handler for once

bitter crane
#

fancy ideas sneak into our heads all the time :p

tranquil hedge
#

Bit stuck early on which is worrying, but I'm at this stage of the "Learn Linux" room, I've created the text file but I'm struggling to find the binary to run? I've tried opening the text file and stuff which gets me permission denied. Sorry for being dumb

bitter crane
#

It's probably good to learn how it functions. but yea, at least some of the time, just keep it simple :D

#

Go to your home folder and run

#

file *

#

binaries look no different on linux. No exe or anything and .bin is optional

still parrot
#

I cant believe I wasted that much time :/

#

Done too many boxes today time for a break

bitter crane
#

sometimes you gotta stop and question the line of thinking you're on. "What am I really looking for" x)

#

but hey, you got the right stuff going -- it just didn't work

tranquil hedge
#

Got it that's embarrassing, thanks Bread, knew I was just being dumb

bitter crane
#

better being dumb than lost :p

#

and you're welcome

still parrot
#

thanks for your help anyway bread Im off now

bitter crane
#

no problemo!

brisk obsidian
#

I've read answers above in this chat but they didn't help me

forest token
#

Hey chat, question for anyone who's done Steelmountain room -- have you had any issues starting the "service" I'm hit with a 1053 error "The service did not respond to the start or control request in a timely fashion"??

forest token
#

got it sorted... give me a shout if anyone has issues I'd gladly help.

sand shuttle
#

Hey, has anyone got Flag 5 in the wordlists room?

#

I've followed all the steps and modified the special characters wordlist

#

We're just trying to crack the zip file

sand shuttle
#

Also struggling with flag 6 after following the instructions

hearty zodiac
#

any hint for HackPark "What is the name of the abnormal service running?"

white salmon
#

What real life example can "Sitemaps" be compared to?

#

question 2

#

task5

#

googledorks

#

hints?

stuck fractal
#

It's in the text

#

Read the task

#

It's more or less directly on the text

white salmon
#

lmao

#

thanks

#

didnt think of it that way

#

Name the keyword for the path taken for content on a website

#

hint?

#

@stuck fractal

#

index aint working

stuck fractal
#

Again, it's in the text

white salmon
#

i dont see it

#

name a keyword for the path taken

#

HA

#

SMART

#

the question not me

#

lmao

#

thanks

#

๐Ÿ’ฏ

white salmon
#

@stuck fractal ok

#

this one im def stuck on

#

What critical file has had its permissions changed to allow some users to write to it?

#

common linux privesc

stuck fractal
#

Stop tagging me every time you need help please

white salmon
#

lmao sorry

#

its cool i guess ill eventually figure it out

stuck fractal
#

The script picked it up

white salmon
#

?

stuck fractal
#

You were meant to run a script for enumeration

white salmon
#

i did

stuck fractal
#

Basically. Read harder.

storm imp
#

hi friends, im very new and working on the learn linux room. I have completed everything except for the bonus where you need to get access to the /root/ folder for the final password. If someone could give a small hint to fill in the dots for me that would be great blobfingerguns

inland onyx
#

Look for files belonging to each user @storm imp

storm imp
#

will do!

storm imp
#

thanks so much for the hint! completed my first room wooo! vent

inland onyx
#

WOO!!

boreal whale
#

test

white salmon
#

1234

boreal whale
#

Any helpers?
What is the name of the technique that "Search Engines" use to retrieve this information about websites?

#

What is an example of the type of contents that could be gathered from a website?

terse yew
#

Help on Node1

#

Again can anyone help on node..i am not able to download file ||backup||

#

Hello anyone there

still fulcrum
#

Hello, looking for a hint in "The True Ending" of the Learn Linux room because i am stuck right now

stuck fractal
#

@still fulcrum Look for files belonging to each user

#

Maybe with find

still fulcrum
#

Ok, i had a second look at it because i already had found two intriguing files but i haven't manage to find use for them

stuck fractal
#

There's more

still fulcrum
#

Alright, got it, thanks for the help!

white salmon
#

the ip of the vpn remains the same ?

#

regardless tp the new announcement ?

stuck fractal
#

I think unless you change servers

normal peak
#

^ Yes

past night
#

I think my vpn is not working, can someone help me please

glossy basin
#

@past night i think sending me $5 can help

past night
#

send me your address

stuck fractal
#

127.0.0.1 @past night

#

o wait

#

0x3a8Ad7bEAa73f29A32f21c732e658855c07E9Dd7

wheat hollow
#

Any writeups for juiceshop? I joined the room in order to learn about it but unfortunately it's not a walkthrough room.

inland onyx
#

@wheat hollow yeah, there's literally a book written on it

wheat hollow
#

The Web Application Hacker Handbook?

wheat hollow
inland onyx
#

Because it's not a write-up for the room

#

Juice Shop isn't something we made

serene tartan
#

Hi, I have a question on Steel Mountain. I've successfully rooted it, however I'm stuck at question 2.
Take a look at the other web server. What file server is running?
There are two http servers, one on it's deafult port 80 and one on 8080. The HTTP server on 8080 is HttpFileServer 2.3. However, that answer is wrong, any hint/help?

raw blade
#

google http file server

serene tartan
#

lol, im an idiot

#

thanks

raw blade
#

np

slim skiff
#

What SSH product does Google use? I'm stuck on this one i don't know what exactly to look for, and i can't search anymore on shodan i did to many searches.

#

and ofc on google

humble siren
#

Hello guys, i'm at Day13 of "25daysofchristmas" but i'm having some trouble.
I managed to find the admin credential for the wordpress panel and i find a way to inject my php code inside a webpage, but i can't manage to star a reverse php shell.
Every php_rev_shell i found are for linux and i still have no idea how to write them.

raw blade
#

for linux

muted cloak
#

could someone help me with the last step of the game zone room

humble siren
#

@raw blade but what about that ($shell = 'uname -a; w; id; /bin/sh -i';) at line 54

muted cloak
#

i have the last hash but i cant brutefors the hash

#

*bruteforce

humble siren
#

because i tried it a few times and it is giving me errors related to that command.

raven prism
#

whats ment with number?

glossy basin
#

@raven prism it's basically a CVE identifier

raven prism
#

where to find it in exploit db?

glossy basin
#

so every CVE has it's own number and you can distinguish between them

#

where to find it in exploit db?
@raven prism using 'search' button ๐Ÿ™‚

raw blade
#

@humble siren - ok - you are trying to exploit a windows server - you stated that you were looking for anything other than windows but I see you edited your comment ๐Ÿ™‚

raven prism
#

so thats CVE 2016-1240

#

what is number ? 1240?

raw blade
#

and you're right that script isn't platform independent so it won't work

#

uname is not a windows command

glossy basin
#

CVE-2016-1240 is the complete name @raven prism

raven prism
#

ohh okay thx

glossy basin
#

number is 1240 yeah

#

like it's said in the room

humble siren
#

@raw blade yeah, sorry I've switched them, i only found them for linux based platforms and not for windows.

#

This is the only one i've found but it's not workinghttps://github.com/Dhayalanb/windows-php-reverse-shell

raw blade
#

no problem...makes sense now

slim skiff
#

What SSH product does Google use?

#

sorry to interrupt

#

but i cant figur it out

glossy basin
#

SSH Open Server i suppose

#

better ask google for that

slim skiff
#

7 letters

glossy basin
#

yup, go ask google

slim skiff
#

i did

glossy basin
#

we do not give answers here directly

slim skiff
#

tell me what to look for

glossy basin
#

i can't help you with a room which is basically based on personal research

slim skiff
#

i know,sorry but i hit the limit with shodan.in for today

#

im gone finish it tomorrow

#

ty

glossy basin
#

you can create a new account with a 10-minute mail

slim skiff
#

I'm gone do it now,thank you.

stable comet
#

Hi all I was wondering if anybody could explain or hint in room Common Linux Privesc task #9 Step #4. its the one for creating an imitation executable. I keep trying different things but I guess I am not sure what its actually looking for. If anybody has any tips that could lead me in the right direction I would greatly appreciate it. Thank you.

restive cobalt
#

If anyone could help me, I'm, on the last part on vulnversity. I have no idea what to do to escalate my privileges' to root

stuck fractal
#

@restive cobalt It gives you the binary to escalate with right?

restive cobalt
#

I've identified the unique SUID, unsure how to proceed

inland onyx
#

Single most useful tool for linux privesc you're ever going to find

stuck fractal
#

(And the correct one here)

#

You need to try and understand the exploit though

restive cobalt
#

I know im using the SUID to invoke temp privileges' that i can use to use root, is that accurate?

stuck fractal
#

@restive cobalt So GTFOBins will help you get a shell or other things using the binary that you're given

#

suid means the binary runs as the owner

past night
#

Lol its the first time i actually know what suid means

#

I feel kinda stupid now hahaha

restive cobalt
#

I still feel stupid

past night
#

Nah dude

#

You're cool. Everyone starts somewhere

#

Just invest your time researching what you do

#

It will come in handy one day or another

muted tree
#

uper new to this... looking for some help with Linux Functionality Flag 16 lies within another system mount. I can see all the mounts but anyone want to nudge what I should do here? I'm such a lamer windows guy.

inland onyx
#

@muted tree If you can see them, look at what they contain

muted tree
#

Actually has nothing to do with mounts.. but something else. Thinking too much like tech and not enough like CTF.

#

got it thanks

gaunt goblet
#

I'm doing the custom wordlists room and am stuck on flag 5 which states the password requirement of 1 special character. Now I'm supposed to use sed to modify rockyou.txt but I can't figure out how to save my life. Any nudge in the right direction would be greatly appreciated

spice harness
#

can someone give me hint about key 2 in cc stegnography box.

tardy drum
#

@spice harness have you tried using the tool from task 6?

worthy ferry
#

what Unix/Linux config files that i might want to hid from crawlers?
google dorking task 4 question 5

tardy drum
#

@worthy ferry well, what is the extension of a config file for unix?

worthy ferry
#

brub

#

im dumb

steady stratus
#

:^

tardy drum
#

have you tried googling it?

worthy ferry
#

ya

steady stratus
#

I guarantee you will find the answer by googling just a lil bit better

#

As the creator

worthy ferry
#

its 3am for me chief, just a bit tired

#

also really like the room so far, good job

steady stratus
#

Hehe it get that - itโ€™s pretty easy to overlook. Youโ€™ll kick yourself. Perhaps get some kip and come back to it late? ๐Ÿ™‚

#

And thanks!!

#

Iโ€™m glad to hear of it

white salmon
#

<3 @steady stratus

#

Turns out

worthy ferry
#

dog person, same

white salmon
#

Android phones have an ultra dark mode

#

For discord

worthy ferry
#

what???

white salmon
worthy ferry
#

that is very nice, only if it was on desktop

white salmon
#

You can use better discord

worthy ferry
#

@steady stratus Ok that was really cool, and as you said could be dangerous

steady stratus
#

What could be O.o

worthy ferry
#

google dorking

steady stratus
#

Ah! Yes! ๐Ÿ˜‡

#

could be dangerous aye

past night
#

Android phones have an ultra dark mode
@white salmon how u do that

odd void
#

spam press dark in themes

past night
#

OMG

#

thank you so much!

sullen seal
#

Hey all, having a bit of downtime and doing the metasploit intro room, im stuck on one of the questions

Last but not least, which module is used with buffer overflow and ROP attacks?

been googling for my life and cant seem to find it

past night
#

you'll see it when you open up metasploit

#

unless you do -q then you won't see it

sullen seal
#

still dont see it, all I see is the banner then this

   =[ metasploit v5.0.81-dev-11da08a                  ]
  • -- --=[ 1987 exploits - 1088 auxiliary - 339 post ]
  • -- --=[ 559 payloads - 45 encoders - 10 nops ]
  • -- --=[ 7 evasion
past night
#

it is there

#

i can't tell you more than that

white salmon
#

It is even in the presentation of metasploit architecture/modules in the room

sullen seal
#

im probably overthinking it

#

got it.......holy crap cant believe I missed that

#

I was looking for the actual name of an exploit rather than that

white salmon
#

anyone succeeded with LFI ?

#

@white salmon The one from AoC ?

#

the basic one ,room

final smelt
#

hey yall. Im trying to solve the toolsrus room but on task 8 it asks for the server version. I couldnt find the answer for this myself so i looked at the writeup and found out that the /manager/html/WorkArea/version.xml has the version. However the directory is locked under 403. Can anyone guide me in the right direction to get through this

white salmon
#

how have you checked ?

white salmon
#

dear fellow hackers ๐Ÿ™‚ i need some help with Common Linux Privsec Task 9 #4 ! i am stuck at what commands they want me to write

#

This is a good one

#

think simple

white salmon
#

i did it ๐Ÿ˜› i forgot the "

proven bridge
#

Make sure to use spoiler tags for answers

white salmon
#

ah doh

proven bridge
#

๐Ÿ˜›

white salmon
#

linux and me are slowly becoming friends

slate scarab
#

Learn Linux room = pwned

#

Very well put together for beginner content. I enjoyed it

inland onyx
#

@white salmon โ™ฅ๏ธ ^^

pure plaza
#

Need help with Brainstorm
When I run the exe file, Immunity debugger is paused automatically

white salmon
#

@slate scarab <3

slate scarab
#

๐Ÿ˜‹

white salmon
#

could someone help me see where i might be going wrong? im working on learn linux room challenge 21, trying to set two environment variables then run a binary, and even though the variables should be set the binary isnt running

stuck fractal
#

It's not set 2 variables

#

It's set one variable to the value of the other variable

white salmon
#

well im setting them equal to each other

stuck fractal
#

Make sure it's the right way round

#

And then you need to run the correct binary

mellow vale
#

Hi guys!

white salmon
#

thanks for the tip

mellow vale
#

I'm doing room CCpentesting

#

Task 18, in final task of sqlmap

#

"what is the value of the flag?"

#

I don't know what flag is

stuck fractal
#

You have to find the flag

#

Capture the flag

raw blade
#

it'll jump out at you when you correctly invoke sqlmap

mellow vale
#

I dump all tables and nothing

raw blade
#

review your sqlmap command, the url you are testing against, etc

white salmon
#

guys any hint on how to get a shell in LIF basic ?

#

i tried everything

white salmon
#

You mean Inclusion @white salmon

royal cave
#

@white salmon hey i cant access artic forum challenge site

white salmon
#

Huh? @royal cave

keen lintel
#

I am stuck on privileges escalation of ghostcat
I got the first user but cannot identify the privilege esclatiaon vector

glossy basin
#

@keen lintel check what commands you can run as root without the password

#

and escalate from there

past night
#

i think he just has the entry point in the system

humble siren
#

Hello guys, what about the task3 of day13 in 25daysofchristmas?

#

I found about the file you're supposed to use, and the bug in w server 2016 but i can't manage to fix it

#

i tried setting both browser as default (one at a time ofc) for every single file/extention but i can't manage to get it work

white salmon
#

Haha, exactly where I was confused too, couldn't get it to work either, but it just worked on the 15th try

past night
humble siren
past night
#

i got it on my 4th attempt i think

humble siren
#

It literally worked for the first time right now

#

but i think i reached ~15 attemps and a few reboots

past night
#

hehe kekw

#

it's a @minor bough challenge

#

so expect this kind of clunky behaviour

minor bough
past night
#

I'm just appreciating your challenges @minor bough ^^

uncut crypt
#

I am currently doing the Wifi Hacking 101 Activity and I am stuck at the 3rd question:

#

What three letter abbreviation is the technical term for the "wifi code"?

#

Maybe I am just dumb but I tried everything

tidal sedge
#

Google

stuck fractal
#

@uncut crypt Have a look at the types of WPA2

uncut crypt
#

Ok

stuck fractal
#

And what the technical term for the password etc is

uncut crypt
#

Well I found it maybe the question is made a little bit weird or I am incompetent

merry sonnet
#

can someone give me a nudge on "Jack" ? initial access I have located the WP login page, enumerated some usernames and have been brute forcing with rockyou.txt in hopes of finding good credentials.

uncut crypt
#

Thanks

stuck fractal
#

@uncut crypt If you can find a better way of wording it without spoiling it, I'm open to suggestions

uncut crypt
#

Ok I will think about it ๐Ÿ‘

white salmon
#

Any hint on task 3,ch 6 ? from LFi basic?

uncut crypt
#

@stuck fractal I think you should add a hint like the one you gave me. So something like: "Search for different types of WPA2". Or: "Look up how Encryption works in a small private Networks"

stuck fractal
#

@uncut crypt Different types of WPA2 gives it away too easily IMO, and small private networks can be wired etc

uncut crypt
#

@stuck fractal I mean you gave me a hint and the hint function is for hints. So yes it would give away too much when embeded in the question but not as a hint.

stuck fractal
#

It's still meant to challenge your research skills

uncut crypt
#

@stuck fractal Maybe just change the word "code" to password, key or something else not too obvious

stuck fractal
#

If you google WPA2 password, it's in the google suggestions

uncut crypt
#

Well I am based in Europe, Germany to be exactly and if i try googling wifi code I am not getting the results I need to find the answer. But if I try it with wifi key or wifi password I can find the answer not instantly but still fast. So maybe thats the problem I had. I know most users should be based in the USA

stuck fractal
#

I'm in the UK, it's just a part of research

glossy basin
#

Duckduckgo allows you to specify country for your search!

past night
#

google does the same

#

as long as you specify the .co.uk, .com, etc

solar onyx
#

Hi, Im doing the 25daysofchristmas day12 #3 and I am unable to brute force note2. What I have tried is using ssh2john with the private.key and then using john with a shortened version of rockyou (that contain the actual passphrase) but it never find the passphrase. Any hints?

stuck fractal
#

@solar onyx Read the hint, you can't really brute force it

#

It's not an SSH private key, is it?

solar onyx
#

No, just seemed like one ๐Ÿ˜ฆ

#

I've been reading and seems like you can't actually bruteforce rsa since there is no way to know if the resulted plaintext is what you where actually looking for

#

But openssl rsautl -decrypt give me an error when I enter a wrong passphrase

inland onyx
#

Not strictly true. You can bruteforce RSA, if the numbers used to generate it are low enough

#

An openssh key?

#

No chance

solar onyx
#

So there was no chance of solving that without the hint... All right thanks!

thin valley
#

can anybody help me with one question in toolboxvim

stuck fractal
#

@thin valley What's the question?

thin valley
#

@stuck fractal Task2 question 2, I answered all of them, I feel like an idiot stuck with this only one ๐Ÿ˜ฉ

stuck fractal
#

Which one is that?

thin valley
#

How do we start entering text into our new Vim document?

#

and the answer contain 6 char

stuck fractal
#

It's a really dumb clever question

#

Think as simply as you can

thin valley
#

I tried insert

stuck fractal
#

Once you're in insert mode, how do you enter text?

thin valley
#

it feels weird

#

that is weird

#

keyboard

stuck fractal
#

verb

thin valley
#

damn I feel dumb

#

thank you @stuck fractal