#room-hints

1 messages · Page 22 of 1

sand glen
#

anyone for help #Advent of Cyber room

stuck fractal
#

Grep.

sand glen
#

I checked all the files
they're encoded but I don't know how to decode them
I tried base64 -d and redirecting the output to a file
but when I use the file command with the newly created file
I get : file : data

stuck fractal
#

You don't need to decode them

sand glen
#

i already used grep and got only encoded output

stuck fractal
#

The information you're looking for is in there, in amongst the text

#

You just gotta grep with some nice regex

sand glen
#

oh, I'm really bad at regex xD

stuck fractal
#

digit digit dot digit dot digit match exact

#

Might need another dot digit

sand glen
#

got it

#

[0-9]\.[0-9]

stuck fractal
#

\d

#

If you have it in the right mode.

sand glen
#

thanks alot for the help

patent token
#

Is the buffer overflow room borked?

stuck fractal
#

I think there was some talk of a fix for one of the tasks @patent token

patent token
#

Task 8 I believe. I got excited when I saw some folks had finished it, but I've for the life of me not been able to. And I'm usually pretty good at BoF

sick sun
#

anyone done NAX room ?

dull frost
#

@sick sun I am, just need to finish 1 question. But I used a different exploit so I just have to find the one asked in the question lol

sick sun
#

Can i PM you ?

solid patrol
#

there is msf module with cve in that room

sick sun
#

@solid patrol can i pm you ?

solid patrol
#

go for it

normal totem
#

Hello, i try finding this answer but i cannot find it on goole:
What are automated tasks called in Linux?

#

i found a thing such corntabs but it doesnt work

#

the structure is **** ****

#

2 words made of 4 letters

white salmon
#

what room? @normal totem

normal totem
#

Introductory Researching

white salmon
#

oh then, you're in the good way

#

something about you said

normal totem
#

i will look further now

white salmon
#

have you looked at the hint? @normal totem

normal totem
#

yes..

#

but i found the same page

white salmon
#

i heard linuxtechi is a good page

normal totem
#

okay, i look now 🙂

#

oh i got it 😄

#

thanks for the help

white salmon
#

np ^^

dull frost
#

@sick sun yes of course

white salmon
#

In corp 3#3 I can't make hashcat work, keeps saying "Status exhausted"

glossy basin
#

@white salmon check that your mode is set correctly

white salmon
#

hm wdym @glossy basin ?

dull frost
#

anyone wanna help me out with identifiying and cracking a hash?

white salmon
glossy basin
#

okay it's cracked

white salmon
#

had spaces and fixed, tried doing again and says that with candidates huh

solid patrol
#

u cracked that hash

glossy basin
#

you are supposed to see the password then

#

no it's not in candidates

solid patrol
#

it should be above info of that picture u send in format hash:cracke

white salmon
#

oh yeah sry

glossy basin
#

yeah

white salmon
#

ty

normal totem
#

I still need some help finishing this task to finish the room

#

but i still cannot find 2 answers

glossy basin
#

which one

#

room

normal totem
#

on the Introductory Researching

glossy basin
#

ohh

normal totem
#

the second topic

glossy basin
#

that's only on you

normal totem
#

okay..

#

it is so confusing

sick sun
#

Nvm i got it

white salmon
#

@normal totem what do you need

normal totem
#

i got it 🙂

#

took me just 30 min 😄

white salmon
#

oh

wintry crown
#

Hi guys, meed help for this. Accessed blogengine website and tried to login but showing error. Password is breaked, but when entering it is showing something like ‘oops, developer caused this issue, appolgies, 20lashes to him vlah blah’

lime needle
#

Anyone doin nax

past night
#

what's up with nax?

grand pivot
#

Hi everyone!

white salmon
#

hi

static rampart
#

need help with nax

grand pivot
#

I was at 4am yesterday, starting with x86 crackme and i was so confused xD im going to watch it again now that i am awake

past night
#

if you can be more specific about what you need help with

#

@static rampart

static rampart
#

at foothold

past night
#

revise your chemistry

nocturne vault
#

also stuck there..

#

smtp pmpl?

static rampart
#

can any one know about .zlib extension

past night
#

i don't think you are doing it right ^^

#

use the information you got from the other tasks

crude swan
#

Hey there!

#

I need help with Nax too lol

#

What's up with the spoilers here?

#

I'm assuming that I can't share my findings so far... 😛

white salmon
#

we are discussing in -help

#

few of us are stuck

crude swan
#

how do I go to -help?

#

I'm new in discord, sorry

white salmon
#

its the other room, community-help under "Rooms"

crude swan
#

Found it! Ty!

white salmon
#

In hackpart my meterpreter session doesn't seem to work, I've uploaded the shell into the machine but nothing

quaint star
#

anyone any help for Nax ? stuck so bad 3 hrs deep

white salmon
#

people keep saying Chemistry, periodic table of elements and this referring to the .html page

quaint star
#

yeah looking at the different elements, hard to come up with something

white salmon
#

same

#

i'm not for the ctf type stuff

quaint star
#

yeah

#

i feel yah

still elm
#

i can't solve Task 3 #7 in PS Empire. i can't find how to change the server appearence

wooden hollow
#

@lime needle yes what u need ?

proud scarabBOT
stuck fractal
odd belfry
#

oh sorry

stuck fractal
#

Especially in the hints channel, since it's a bit of a spoiler

odd belfry
#

i cannot delete it sorry

white salmon
#

NAX.

#

Should gobuster error on this box

white salmon
#

Uh may someone give me a hint in skynet? I cant ||smb||map into the machine, it says "Authentication error"

ruby junco
#

Should gobuster error on this box
@white salmon what error?

turbid bloom
#

wait a minute i want to ask about Linux Challenges

#

flag11 command found

turbid bloom
#

ah i got it i logged in the wrong user

remote gate
#

@white salmon i was getting errors in gobuster after a few minutes. ||ended up not needing gobuster.||

late hare
#

Anyone got a hint to point me in the right direction for OWASP juiceshop room resetting jim's password/finding more info about him

quaint star
#

anyone finished Nax ? stuck with exploit

stuck fractal
#

@late hare osint

#

More specifically, product reviews

remote gate
#

@quaint star i finished it. where are you stuck?

late hare
#

Thanks! Like reviews on the site? I looked through a few, found admin section for his email but that's it so far. Gonna call it tonight I'll try again tomorrow

stuck fractal
#

@late hare for products. Some juicy hints in those and some mild stalking and you'll get it.

quaint star
#

briskets can i dm, dont want to spoil for anyone

#

@remote gate

late hare
#

@stuck fractal ahh ok didn't see there are reviews listed in the individual products maybe i'll find it there

turbid bloom
#

i can't locate flag26 in Linux Challenges room

grand pivot
#

Hi everyone! Im doing the final exam in CC radare2 and im a little stuck when i try to follow the get_password function. Can you give me some advice?

white salmon
#

salve

#

I made the room, what's up @grand pivot

grand pivot
#

oooh hello!! Great, ok

shadow basin
#

Hi, has anyone made made a walkthrough to room 'Advent of Cyber'. I cant figure out how to encode the cookie. I have tried "base64 'cookie value'" and it still gives out some gibberish, which doesnt help me to figure out which part of cookie 'is fixed value'. Any advice is appreaciated.

glossy basin
#

do want a writeup or a hint?

shadow basin
#

@glossy basin anything is appreaciated.

glossy basin
past night
#

there is a write up i think

glossy basin
#

and decode also

#

there is a write up i think
@past night at least 4 writeups

past night
#

hehe

#

true

shadow basin
#

where can i find them?

glossy basin
#

cookies?

#

in inspection tools

past night
#

under the write ups

glossy basin
#

!writeup 25daysofchristmas

glossy basin
#

here ^

shadow basin
#

@glossy basin amazing thank you so much.

glossy basin
#

anytime

white salmon
#

@minor bough can I DM about blaster?

#

or anyone that might have had issues creating the exploit in msf?

shadow basin
#

Can someone explain why he has, blacked out information in writeup. Is it some kind of sensitive information?

normal peak
#

It stops people coping the flags

white salmon
#

there are few writeups that doesnt have that

normal peak
#

To just answer the question without actually doing the task

shadow basin
#

ok got it

white salmon
#

In Skynet I've looked into the db-exploit but still don't know how can I upload the file, any hint?

shadow basin
#

btw is it considered to be unetical to show the flag to others?

white salmon
#

try to spoil it with ||

#

@minor bough in Blaster, the steps to create the exploit need to have "set target" before "set payload" or you get error when "run -j" payload not compatible

inland onyx
#

@shadow basin yes. It's fine to help, but don't show people passwords, hashes, or anything else that lets them skip stuff

shadow basin
#

thanks @inland onyx there is no much i can spoil at the moment, but will keep it in mind for the future.

minor bough
#

@white salmon good call, I'll tweak the ordering there

minor bough
#

Adjusted now

white salmon
#

Great, nice room btw

minor bough
#

Thanks!

shadow basin
#

Does anyone know is there a chance to run two distributions at the same time.

#

besides vmware

inland onyx
#

@shadow basin As in, dual booting?

tidal sedge
#

I think they mean running two distributions simultaneously

inland onyx
#

Well, in that case, no. Not without containerisation, VM's, or two machines 🤷‍♂️

shadow basin
#

yes simultaneusly, similar to vmware, but would like to know if there is other option someone might know

#

yes with containerisation

tidal sedge
#

Docker

inland onyx
#

It'll have to be done either with another hypervisor, or through something like Docker, which does basically the same job

#

But without the resource heavy hypervisor

#

No GUIs if you use Docker

#

Although I would be very interested to see what happens if you try setting up an RDP server and connecting that way (having installed a DE)

shadow basin
#

but will it be compleatly seperate system

normal totem
#

Hey

#

can anyone help me with this question:
What is the value of the home environment variable

inland onyx
#

Nope, still just a container @shadow basin

tidal sedge
#

echo $HOME

normal totem
#

the format is /xxxx/xxxxxx

shadow basin
#

@inland onyx does it mean that two kernels will be running at the same time ?

inland onyx
#

I mean, in a sense -- only in the same way that they would be in a hypervisor though

white salmon
#

can someone possibly help with a ssh2john issue?

#

throwing errors

normal totem
#

@tidal sedge ?

tidal sedge
#

@normal totem What room are you doing?

shadow basin
#

@normal totem if you would 'echo $HOME' it would give you the output /xxxx/xxxxx

normal totem
#

learn linux

tidal sedge
#

@normal totem Use echo $HOME

normal totem
#

ah i got it

#

i was doing it wrong

#

Thanks 🙂

white salmon
#

:
anyone have issues with ssh2john throwing indexError: list index out of range when using?

#

hello on agent sudo what's the name of the accident, i'tried a lot of thing

minor bough
#

Google 'roswell new mexico alien crash'

white salmon
#

no idea ...

patent token
#

Hey! Blaster has my exploit chain in it now. Woot!

#

I'll take "alternatively" out of my guide I'm writing now. 😛

minor bough
#

Haha yeah, I just adjusted it as it was very consistent with the web delivery method

buoyant cairn
#

if anyone has done Polos privesc and would like to offer some assistance ❤️

patent token
long niche
#

Hi, am doing "CC: Pen Testing" am stacking in section 14 question 3 "How do you specify which rule to use?" ?? which i try "-rules"
but didn't work is it a bug ?

stuck fractal
#

@long niche No, your answer is wrong

#

@buoyant cairn Re-read how the imitation works

long niche
#

ok thank u

patent token
#

||or just disable the firewall from the command line :P||

#

I'm so naughty.

steady stratus
long niche
#

@buoyant cairn i should use brackets but should i define a rule here or something

buoyant cairn
#

@long niche ? say again

stuck fractal
#

@long niche man john or john --help

warm schooner
#

tldr is also a great helper function

naive peak
#

Can anyone hint me in the right direction regarding brainpan

#

I've managed to get a shell

#

but am unsure how to evscalate.

long niche
#

@stuck fractal i did 😄 but ..

stuck fractal
#

@long niche Then you didn't read the output. I just ran it and got the answer straight away

long niche
#

@stuck fractal ok i will search again

long niche
#

believe me i read and i try many answers

stuck fractal
#

@long niche Seriously, it's 100% right there in --help.

long niche
#

if ur talking about --single i tried it

stuck fractal
#

You're looking at specifying a rule. Don't bruteforce the answer field. @long niche

#

Read the output of --help.

civic schooner
#

Hi

long niche
#

hi

#

:/

#

i read it but i didn't get it

stuck fractal
#

@long niche There's like 4 sections to the help output. One of them looks relevant.

white salmon
#

Can I ask if Stego is required for NAX?

#

I have author but stuck on username

long niche
#

@stuck fractal the answer [6 chars], i even use john --help | grep rule but nothing

stuck fractal
#

@long niche There's no other way of saying this. It's there. tryharder

long niche
#

are u using kali ?

stuck fractal
#

It's right there on kali too

long niche
#

believe me a even try random words but nothing

past night
#

sudo john --help

stuck fractal
#

@long niche I don't believe you. It's 100% there on Kali and Windows.

#

@past night reeee

past night
#

yes?

stuck fractal
#

Throwing sudo at something is bad if you don't need it

past night
#

it doesn't work on 2020 without sudo

long niche
#

am using root user

#

so no need

stuck fractal
#

Which kali?

long niche
#

kali 4

past night
#

plz.

stuck fractal
#

It's there

past night
#

with sudo, yes

stuck fractal
#

@long niche No such thing.

#

@past night They're not on 2020

past night
#

okii

long niche
#

Linux kali 5.4.0-kali4-amd64Linux kali 5.4.0-kali4-amd64 i just upgrade it should be 2020

shadow basin
stuck fractal
#

@long niche It's there. DM me a screenshot of the output of john --help and I'll tell you that it's there

#

@shadow basin Page width

long niche
#

i had the same output

stuck fractal
#

Huh?

long niche
#

i try every word

stuck fractal
#

Then you're not doing it right

long niche
#

believe me i tried every syntax

stuck fractal
#

I don't believe you, because it worked for me here. DM me a screenshot of the output of john --help and I'll tell you if it's there.

shadow basin
stuck fractal
#

Page zoom then

shadow basin
#

It started to work much faster now, but there is no more register button and old login credentials doesnt work anymore.

stuck fractal
#

If you terminated it, it's a whole new instance the next time you deploy it

shadow basin
#

yes but when I try to register with the same email, it doesnt allow anymore. Thats not a big deal, I just use 10 minute mail to bypass it, however there is no "register" button anymore.

#

but used to be

shadow basin
#

@stuck fractal I found what is the issue, I did not realize that "Advent of Cyber" task 6 and task 7 are two different machines. I guess task 7 machine "register" button does not meant to be there.

dense marlin
#

hey there

tidal sedge
#

👋

dense marlin
#

can i get some hint for nax machine? tried to brute force the web directory with ffuf but still unable to find the hidden file

plucky echo
#

anyon?

dense marlin
#

trying to read the source code of login.php to find the hidden file but no luck man

tranquil dagger
#

You can PM me @dense marlin

dense marlin
#

cool

white salmon
#

FFUF @dense marlin

#

THANK YOU

#

I've been trying to figure out what that bloody tool was called for weeks

#

God it was driving me insane every few days

dense marlin
#

@white salmon ya FFUF, it's ok managed to solved the initial part. Thanks for the hint from @tranquil dagger

proven bridge
#

FFUF @dense marlin
@white salmon FFUFFFF

dense marlin
#

yea that's a great tool for web directory enum @white salmon

white salmon
#

Wfuzz has been my go to

#

But a buddy of mine said FFUF was better

#

So I meant to install it

#

But I could never remember the name

dense marlin
#

been using FFUF for months, i can say tht it's much faster than dirbuster

#

u should give tht tool a try

white salmon
#

Everyone using gobuster

#

Me an intellectual: uses dirsearch

#

I need to get on the gobuster train ;-;

white salmon
#

I’m 50% on the NAX box

#

I’ve tried harder. Can anyone help nudge me

#

I don’t want answers, just someone to point me in a direction to retrieve one final piece

still elm
#

@white salmon where are you stuck?

white salmon
#

Step 4

#

Steps 1-3 are completed. What a ride so far. I’ll be cruising easily once i complete step 4

still elm
#

@white salmon try googling about the name you found

white salmon
#

Ok thank you

#

May I DM?

long niche
white salmon
#

Indeed I am

long niche
#

😄 hello friend

#

it's great room

#

i stack in section 14 question 3, i did lot of try

#

i discuss with Ninjajc01 | james

#

about it

#

i think there's typo

#

:/

white salmon
#

Typo!

#

Impossible!

#

It's actually very probable

#

Where's the typo

#

I'll fix it up

long niche
#

How do you specify which rule to use?

#

question 3

#

in section 14

#

i use many answer to use rule based on john manual page

#

or --help

stuck fractal
#

@white salmon I told you about it earlier

#

@white salmon Pars no posting answers

white salmon
#

Haha @stuck fractal

#

Typo fixed

long niche
#

@white salmon thank you it was fixed !

nimble wedge
#

Stuck on #2 of Task 18 "What is the value of the home environment variable" for the $ operator

stuck fractal
#

It's case sensitive

nimble wedge
#

thought using "echo $HOME" would be the right but entering the output doesn't work

stuck fractal
#

Are you the right user?

#

You might not be

nimble wedge
#

ohhhhhhhhhhhhhhhhhhhhhhhhhh

#

Yup

#

Where does it say to switch to shiba2?

#

I missed that completely

stuck fractal
#

Task 11

#

The entire point is switching user

nimble wedge
#

dang

stuck fractal
#

Technically task 12

#

Don't skip parts

nimble wedge
#

I mean I got the password quickly too but didn't think to switch

#

yeah you're right

#

need to read more closely

#

thanks ya'll

drowsy needle
#

I am at Common Linux Privesc at this moment , Exploiting PATH Variable -> "echo "[whatever command we want to run]" > [name of the executable we're imitating]" afaik it is echo ./usr/local/ > ls

#

anyone have a hint ? 😦

echo thunder
#

anyone comleted the bookface challenge

#

?

peak girder
#

@drowsy needle ./usr/local/ isn't really the command...

north moat
peak girder
#

wireshark shows 5 pieces of data, one of these that links to the transport layer has a protocol specified, what is that protocol

#

(another hint: protocol is literally in the answer)

north moat
#

you mean i must enter protocol name ? @peak girder

peak girder
#

yeah.. the protocol they are searching for.. yeah 🙂

north moat
#

can i DM ?

peak girder
#

sure

white salmon
#

I mean, if you understand what says above, its easy to answer

echo thunder
#

anyone completed the jack challange

#

?

echo thunder
#

can anyone give a hint on the wordlist in order to crack the password for the jack challange

#

?

#

the hint could be the first 3 letters

white salmon
#

havent done it, doesnt work with rockyou?

echo thunder
#

no

shrewd skiff
#

@dark schooner Not sure why you want to add me but please ask your questions here if its HINTS you are looking for 🙂

white salmon
#

try to look for a writeup, as i said i havent done it sorry

echo thunder
#

there is no writeup

shrewd skiff
#

@echo thunder ok so I assume thats the room. So um... rockyou.txt is good for many cases, but not always. Try different wordlists... Try the short ones too 🙂

#

If that is not the room then just ignore what i said 🥳

echo thunder
#

@shrewd skiff it is the room with the personal blog

#

I've tried rockyou password list

shrewd skiff
#

Yea try another one

#

thats my hint.

echo thunder
#

in the seclists under password are a lot of them

shrewd skiff
#

Yea i know

echo thunder
#

it is in the short ones

#

?

shrewd skiff
#

um that i dont know

#

i would totally try a shorter wordlist with more common passwords

echo thunder
#

where can I ask something regarding kali linux

#

I have a glitch problem

shrewd skiff
echo thunder
#

when installed on the pc

shrewd skiff
#

try "general"

echo thunder
#

ok

drowsy needle
#

@peak girder when you try one thousand times with ./bin/bash instead of echo "/bin/bash" ... dear lord... some things need to cool off before retrying it again 😂

stuck fractal
#

That works if you're in / 😉

quartz dirge
#

Hi, I have just started on the SQLi lab basic challenge. I am click on the image with various challenges. Im unclear as to what is required of me. THere are no instructions. The first 10 challenges are just static pages with no input boxes to exploit. So what i mean to be doing? SQL injection inside URLs or intercepting the request with burp suite and then injecting SQL. Some guidance would be helpful please. Thank you.

glossy basin
#

@quartz dirge in first lessons you need to modify link to get the result

#

the room is just a port from github basically

#

proper SQLi room is being made now

peak girder
#

Yes

#

Basicly

#

And a tiny bit of c#... It uses the "Api" of windows against itself

#

@quartz dirge you'd have more luck looking into the repo of that room... It's in github by the user audi-1

#

He even has a blog where he explains on what to do (link is in the repo)

turbid veldt
#

Actually I shoul;d have posted here

#

repasting:

#

evening guys
doing "find room"
i am going mad here as I miss 2 search commands
can anyone help with this one:
Find all files with write permission for the group "others", regardless of any other permissions, with extension ".sh" (use symbolic format)
*
I am doing this:
find / -type f -group others -perm -g=w -name *.sh
not sure where I make the mistake

stuck fractal
#

@turbid veldt that's the owners group

#

UGO

#

Delete spoiler

#

This is hints

#

You probably misread a character or two.

restive basalt
#

I kinda tried all combinations.

stuck fractal
#

It worked for me

restive basalt
#

well I must be blind then lol. is the first letter upper or lower case

stuck fractal
#

No idea

restive basalt
#

ok it was upper. thanks anyways

summer snow
#

@fierce bramble go through the help for msfconsole again it's in there. Maybe you're misunderstanding what it means by null. All you need is to clear a value or set it back to nothing...

tight escarp
#

guys anyone who has done The Cod Caper and can give a hint about the hidden ssh password? I rooted the box but can't find that file. Im going insane

inland onyx
#

Look for files belonging to other users @tight escarp

#

Not necessarily "real" users

tight escarp
#

hmm okay

#

ty

tight escarp
#

I think I found a way to break the machine lmao

proven bridge
#

@tight escarp How so?

tight escarp
#

nvm, it was just a coincidence. my vpn would crash exactly when i tried to execute a command on the machine

#

like 3 times in a row

white salmon
#

lol

quartz dirge
#

@glossy basin, @peak girder thanks very much for the guidance.....really appreciate the quick response and pointing me to github.

glossy basin
#

Anytime, @quartz dirge :)

white salmon
#

May someone give me a hint in brainpan? I'm kinda lost where to start, ||have scanned with nmap and port 10000 is a SimpleHTTPServer and I see like "x20"||

upper socket
#

i need help in biohazrad room

limber flume
#

||try enumerating that server for directories, remember this is a buffer overflow box so you should ultimately be looking for an exe to debug @white salmon||

white salmon
#

finished it already, its almost as same as brainstorm :D

limber flume
#

yes very similar ports and everything 🙂 feeling confident on buffer overflows just in time for my exam later tonight :b

white salmon
#

which one?

limber flume
#

The big boy, OSCP

white salmon
#

ow

#

wish you good luck with it!

limber flume
#

appreciate it! gonna be studying hard all day

white salmon
#

also remember, gfuel is your friend

limber flume
#

that a snack? lol

white salmon
#

its an energy drink

#

some type of preworkout for gamers

limber flume
#

oh true

upper socket
#

i need help in biohazrad room who is leader of stars brove team

upper socket
echo thunder
#

hi all

#

i have a question regarding smbmap

#

can anyone pm me please

#

?

#

task 20 question 9

#

anyone

#

?

sick sun
#

anyone ?

patent token
#

What have you tried so far @vague reef ?

sick sun
#

know what is the answer of this question in || Lord Of The Root || || Hmmm, what method is used to reveal hidden ports? || ?

vague reef
#

@patent token Hmmm? Related to what?

patent token
#

Your question. What have you tried already?

#

The answer to that one is pretty simple @sick sun

sick sun
#

i'm stuck in this question || Hmmm, what method is used to reveal hidden ports?||

patent token
#

||Google nmap hidden ports||

sick sun
#

@patent token i was try asnwer from google but nothing work

patent token
#

||2nd link||

sick sun
#

@patent token no work

patent token
#

I know it works because I've never done that machine before, joined it when you asked your question, and it's where I got the answer from. 🙂

sick sun
#

@patent token oke man

patent token
#

I promise you the answer to your question is located

#

||in the second link||

white salmon
#

@sick sun literally the room tells you the answer

fresh walrus
#

How would I find php version?

white salmon
#

try with burp

fresh walrus
#

Oh... Got it! Thanks @white salmon

sick sun
#

@patent token oke man i try it

white salmon
#

@sick sun read the room well, the answer is on it

still lintel
#

@patent token can you help me with Buffer Overflow 1 please?

#

Buffer Overflow Room

patent token
#

Which task? When you get to Task 8 it seems to be borked currently.

still lintel
#

Task 8

#

😄

patent token
#

Yea, I don't think it currently works.

still lintel
#

im not too sure what to do...

echo thunder
#

did anyone complete biohazard room

#

?

#

I have a question

#

on task 4 question 3

sick sun
#

@white salmon oh man thanks i got it

jovial sundial
#

I need an hint with Bonus Challenge - The True Ending
||I tried searching through /opt/ , /home using grep or sudo but i just don't know how to access it||

stuck fractal
#

Look for files belonging to each and every user

tidal sedge
#

^

jovial sundial
#

thanks made it through

mellow vale
#

I get stuck in Ghidra room

#

Task 4 #2

#

I have this one, but I don't know anything about C, so I can't see where is the variable

glossy basin
#

@mellow vale I hope you understand this hint, but the answer should be translated from Hex to decimal (the first value is hex)

#

I had a hard time on this question also, but this hint saved me back in the days ^

mellow vale
#

damn, thanks mate, I got It

glossy basin
#

anytime 🙂

summer snow
#

how are you supposed to do that in cyberchef? I tried and it wasn't working. Did it separately in rapidtables and it was easy.

glossy basin
summer snow
#

oh wrong room thought it was the one that had a hint from dec to hex and from hex to ascii @glossy basin do you know what the recipe for that would look like?

glossy basin
#

I mean, something similar to that ^

#

just use the search bar on the left

#

dec -> hex
hex -> ascii

#

something like that

summer snow
#

oh think I know what I did wrong hold on going to experiment more, thanks

#

🤷 I can't get it to work aha it doesn't recognize the input as a decimal think it's because it exceeds the range of ints even unsigned_long_long so idk how i'm supposed to format it for the recipe but oh well just would've been cool as I've started to use cyberchef often

umbral storm
#

Maybe it's a simple answer, but a get stuck and I don't know what is refered this: "How do we start entering text into our new Vim document?", on the Vim box, can someone give me a hint?

inland onyx
#

Yeah, the question is a bit dim.
How do you normally enter text on a computer?

summer snow
#

thought you were trolling then went to the room and sure enough the hint helped a lot :p

umbral storm
#

Yeah, I got it, that was so unexpected 😂 , thanks

white salmon
#

That question is actually stupid

stuck fractal
#

I love that question

inland onyx
#

It definitely makes people take a reality check...

summer snow
#

don't know best channel to ask but my strategy has mainly been go through as many easy rooms as I can and then start working on medium and then eventually hard I did all the complete beginner and 80% of BP/RP paths but is this strategy sound or is it better to stay within particular areas instead of jumping around etc

white salmon
#

It's a hilarious question

#

It's not a good question

stuck fractal
#

Just because it shows how simple VIM is...

white salmon
#

simple
VIM

#

Pick one

inland onyx
#

Vim is simple

#

Vim is gorgeous

#

Vim is love

#

Vim is life

#

Deal with it

#

sudo vim > * && sudo passwd

tidal sedge
#

🇻 🇮 🇲

patent token
#

nano > all

summer snow
#

talking about vim can anyone give me a hint for "How do we save and quit, for all active tabs?" Tried all the ones I can think of and googled and nothing seems to work.

#

in task 3 of vim room

#

oh ignore me for some reason enter on keyboard wasn't working as an alternative to check for correct answer so I wasn't actually doing anything xD clicking it marked it correct

nocturne vault
#

hey, could I get a nudge with catdog?

#

got lfi working, not sure what files to look for..

white salmon
#

There are lots of things you can do with lfi @nocturne vault

#

There's a method available that requires some research to figure out

#

Just keep trying things

nocturne vault
#

if you're talking about php wrappers I've done that already

#

hmm, gonna keep looking into it

white salmon
#

Nope not that

nocturne vault
#

okay i think i got it thnx

graceful nacelle
#

This challenge is pretty simple. The binary is checking to see if the environment variable "test1234" exists, and if it's set equal to the current $USER environment variable.

stuck fractal
#

Create the variable, set it to the correct value, run the binary

patent token
#

Hey there. I'm trying to run through the ZAP room and having issues getting the Vulnerability GET:Brute login parameters to show so I can attempt to brute force them.

I've logged in to DVWA, grabbed my session cookie, set it as active, uploaded my directory list, and ran again, but I'm not getting anything that I can try to fuzz. Any ideas?

stuck fractal
#

Is it http basic auth?

patent token
#

I believe so

#

I don't have much experience with ZAP, and kinda stink at web app in general, so trying to follow the guide pretty closely. I've restarted ZAP a few times and gone back through my steps but been unsuccessful in grabbing what is shown so that I can fuzz it.

stuck fractal
#

Did you use a login form for it?

#

On page one, not a popup browser one

patent token
#

I logged in via DVWA's login portal, and snagged the PHPSession cookie that we needed.

#

On page, not popup correct.

stuck fractal
#

So that'll be POST

patent token
#

That's what I thought as well.

#

But the guide isn't written that way.

stuck fractal
#

Oh wait

glossy basin
#

Yeah, i also was curious about that one

patent token
#

Either way, I'm not pulling a POST either.

stuck fractal
#

This is a page on DVWA for brute

glossy basin
#

ended up with POST

stuck fractal
#

The post request for login is shown in the question

#

Lemme just take a look real quick

#

@white salmon ❤️ nice shoutout

summer snow
#

pretty sure it was a get and it worked for me problem for me was getting the hunt.py to load i cloned and it doesn't show up in scripts not sure if I was supposed to save somewhere in particular or not don't think guide mentioned that

stuck fractal
#

Ok I can confirm it should be a GET

#

Waiting for the server to stop dieing

patent token
#

So what did you do that I'm not I guess.

stuck fractal
#

Well first things first I need to turn the security down

patent token
#

I did that

stuck fractal
#

What's the issue?

#

Oh

#

You need to actually try to login in first

patent token
#

I'm not getting the GET parameters shown in the walkthrough.

stuck fractal
#

When you have the proxy set up

patent token
#

I have logged in

#

Every time.

stuck fractal
#

No, to that form

#

Not the DVWA login, the brute force params login

patent token
#

doh

#

I need to read better.

#

Thank you.

stuck fractal
#

Time to finish doing this room myself

patent token
#

My eyes start wandering when the words are so close to the pictures I suppose. Silly me. Thanks for the help.

#

🙂

flat kite
#

i found url by solving it.but it is not the 😩 key give me a hint

stuck fractal
#

Then go to the URL

flat kite
#

thanks bro @stuck fractal

stuck fractal
#

It's the next logical step

#

I'm not your bro btw

hidden sand
#

Lol

echo thunder
#

did anyone complete bookface challenge

#

?

mint turtle
#

Im trying with|| echo /bin/bash > ls||, can someone help me?

wooden mist
#

look at the task

#

specifically at the parameter to echo

mint turtle
#

I don't get it

wooden mist
#

in the task you have echo "command to run" > outputFile

#

maybe try to wrap /bin/bash in quotes?

echo thunder
#

anyone completed bookface?

mint turtle
#

@wooden mist Okey I did it, but why are the quotes necessary?

wooden mist
#

it's to keep the command intact in case you want to have spaces or any other special character in it

echo thunder
#

Who need help for jack personal website pm me and I will help you

graceful nacelle
#

@stuck fractal just wanna say i completely overthought the question and it was increcbly easy.

shadow basin
#

" it will be checking that there's a directory called test in your home directory, how you create that is up to you. " Room "Learn Linux" task 33. I dont have the permission to create anything at directory '/home'. I have to escaleta privileges?

inland onyx
#

Your home directory, not the home directory

shadow basin
#

ahhh thanks, I guess I got used to the fact that '/home' directory is 'My'.

graceful nacelle
#

task 25 What flag allows you to operate on every file in the directory at once? I dont see a single flag in the --help ls that would do this nor has he gone over that there is a flag that does this? wiki doesnt seem to have an amazing definion of flags either.

tidal sedge
#

@graceful nacelle Which room is this?

rapid iron
#

On RP: PS Empire, Task 3 Question 7, "In addition to changing our browser profile, we can change what our server appears as. What option can we set to change this?" the answer it appears it should be is not accepted. Can you DM me plz @minor bough

graceful nacelle
#

@tidal sedge learnig linux

tidal sedge
#

@graceful nacelle man chown

shadow basin
#

I have created the home directory||, have made directory '/home/shiba3/home/test' , file '/home/shiba3/home/test/test1234'. Found the binary 'shiba4' executing it, and I cant get the password what am I doing wrong?|| Room : Learning Linux

summer snow
#

@rapid iron what do you mean? re-read what it's asking for. I just checked and the correct answer is accepted just fine

rapid iron
#

@summer snow this "server appears as" seems to be the key words to me. If that is the case, then the option h*****s would be correct as what it currently shows is exactly that. As it would seem that is not the case, I am not sure what I am missing

#

I git cloned the exact repo and installed so should see the correct options for the listener. Here is a screenshot of my options for it

summer snow
#

odd I see why you are confused check the hint or try a different version. I'm running 2.3.0

#

@rapid iron

rapid iron
#

@summer snow so I have that rare issue mentioned in the hint

#

I am running 3.2.0

summer snow
#

indeed, seems like it may have been renamed in the latest version? if that's the case more info should be added to the room

rapid iron
#

@summer snow seems that may be the case, if H*****s is the new one, what was the old one? Cannot finish it and the changelogs for the git repo doesn't show it and could not find 2.3.0 info yet

summer snow
#

check history and you'll see it if you search far enough @rapid iron

rapid iron
#

Appreciate it @summer snow

still elm
#

I have created the home directory||, have made directory '/home/shiba3/home/test' , file '/home/shiba3/home/test/test1234'. Found the binary 'shiba4' executing it, and I cant get the password what am I doing wrong?|| Room : Learning Linux
@shadow basin ||to many home||

shadow basin
#

@still elm yeah but I dont have access to create anything at '/home'. Do I have to escalate privilages?

still elm
#

no, your home directory is shiba3 (full path: /home/shiba3), think about this and read again the task

shadow basin
#

@still elm thank you so much.

still elm
#

np

white salmon
#

Hey there 🙂 I am currently working on the linux challenges and try to get flag 29. Well, to be precise, i found it already, but I feel like not having properly solved step 3 "Split by comma and get the last element in the split." for that flag. I removed the spaces and new lines in the file but i don't know what command to use for the "splitting and displaying the last element"-part. Might someone point me in a direction for that? :3

still elm
#

@white salmon try searching a shell command that deals great with strings, replacements, etc... or if you know how to code in python, you can create your own script

white salmon
#

@still elm soooo, ||sed|| looks interesting?

shadow basin
#

Room Learn Linux, Task 43: || It asks to read the flag, "/root/root.txt", I have acess to 4 users and none of them are sudoers || no idea where to look, can someone please give a hint where to start?

stuck fractal
#

@shadow basin look for files belonging to each and every user.

patent jacinth
#

Hi people. A bit stuck on the reverse shell in the metasploit room. I'm getting this message and no sessions when I upload the file.
[] Exploit running as background job 0.
[
] Exploit completed, but no session was created.
msf5 exploit(multi/handler) >
[*] Started reverse TCP handler on 10.9.2.21:1337
sessions -l

Active sessions

No active sessions.

stuck fractal
#

Which task?

patent jacinth
#

task 5 in gaining access

#

in the beginner metaplot room

stuck fractal
#

I think you missed a step.

#

After uploading it.

patent jacinth
#

yeh

stuck fractal
#

It won't just run it, you have to get it to run.

patent jacinth
#

so I have to go to /shell.php

#

right

#

boom, we're in

#

thanks a lot @stuck fractal

sharp bolt
#

What is the logic behind flag26 of linux ctf, if someone can DM me an explanation. I looked at the solution but still i don't understand what's going on and how i woul have been supposed to guess

white salmon
#

Hi, new to this site - once connected to a room how do i know what the server IP is to complete the tutorials?

stuck fractal
#

@white salmon I don't understand your question

#

What do you mean by "connected to a room"?

white salmon
#

@stuck fractal DM?

stuck fractal
#

No.

#

No need.

white salmon
#

ok - im doing the Learn Linux Room - Task 11 references a challenge that requires i execute a binary to retrieve a pwd ?

stuck fractal
#

Yes.

white salmon
#

where do i get the binary from if i can connect to the server

#

cannot*

stuck fractal
#

Ok, so you didn't answer my question

#

You said "once connected to a room"

#

What did you mean?

white salmon
#

i see, once a room is deployed

stuck fractal
#

Ok, I'm going to correct some terminology so this is less confusing for everyone

#

A room is the web page, with the tasks

#

Tasks can have a VM or some resources attached to them

#

When you click deploy, you are deploying a VM.

white salmon
#

if i said joined ?

stuck fractal
#

Joining a room adds it to My Rooms and allows you to deploy VMs and answer questions.

white salmon
#

ok, have not found a room that has requested that yet.

stuck fractal
#

Huh?

white salmon
#

so i have joined a room and a task is referring to a binary i should execute - how do i gain access to this file

stuck fractal
#

You skipped over part of the room.

#

Start from the beginning.

white salmon
#

ok, will review the previous tasks.

stuck fractal
#

Start from task 1

white salmon
#

i have

#

hold that

#

i missed the deploy button on the side ... hand-palm-face

#

apologies

stuck fractal
#

Don't skip over parts of the room

white salmon
#

i did not - just didnt read the full task

stuck fractal
#

That's a part

white salmon
#

lol - ok then

shadow basin
#

Can someone rephraze the question for me please, I have no idea what is asked over here.

#

Task 11, room: "Advent of Cyber".

stuck fractal
#

Someone leaked data using DNS requests

#

What was that data?

shadow basin
#

omg I still dont get it

#

can you suggest wrong alternatives pls?

stuck fractal
#

DNS is a system that turns addresses like "tryhackme.com" into IP addresses

#

Look at the DNS requests

#

Find suspicious ones

shadow basin
#

all of them are suspicious for me. 😄

stuck fractal
#

Some are weird.

shadow basin
#

ok thanks will be keep digging

shadow basin
#

@stuck fractal i have found the data, recovered it cracked it. But I just dont get what sort of ansver can be expected in 5 words .

#

and in two writeups no any clues, I guess I am missing something

stuck fractal
#

DM me the data you retrieved

shadow basin
#

I done next two questions.

#

correct answers was accepted

shadow basin
#

@stuck fractal omg I did finaly found it. Thank you so much for a hint.

stuck fractal
#

Get familiar with wireshark

shadow basin
#

yeah will do

graceful nacelle
#

task 33 Learn Linux: Its telling me to run a binary on shiba4. Why run a binary when i dont have permison to any of the folders?

strange basin
#

try to find the binary 🙂

white salmon
#

asks you to find it

graceful nacelle
#

by finding it im supoose to create directories inside each other and that somehow gives me access to test files

strange basin
#

what's the task prompt again?

stuck fractal
#

huh?

white salmon
#

it asks you to find a file whose name is shiba4

#

@graceful nacelle

strange basin
#

have you found the file?

#

hint: maybe there are multiple files named shiba4

graceful nacelle
#

yeaaah no. i was thinking i make a binary leading the test1234 files run it and somehting will happen that leads to shiba4

strange basin
#

well that's the right approach yes

stuck fractal
#

You don't make a binary tho

white salmon
#

@graceful nacelle i gave you the hint, try to read it :)

summer snow
#

why'd you create a 'Home' directory when you were already in the home directory

graceful nacelle
#

wasnt paying attnetion and decided to roll with it

#

could that effect the results? that path lead the file

summer snow
#

yes... guessing the binary is a compiled program that is looking for the existence of a file with an absolute path leading to the file it wants. You can't just put it in a different directory and expect it to work. Someone correct me if i'm wrong or talking about a different room here.

willow isle
#

I'm in https://tryhackme.com/room/thecodcaper Task 5. LinEnum return an error message: '''Syntax error: newline unexpected''' from line 8, but when I check the "script it's a commented line. Any advise to give ?

stuck fractal
#

Did you download it right?

willow isle
#

Yup I think so, used wget to get it and chmod it, eveeything should be ok ...

stuck fractal
#

Did you wget from raw.github?

willow isle
#

Nope i don't think so, got it from regular github page not raw one

steady stratus
#

That'll be it 🙂

#

not to hijack

#

you need to wget the raw contents of the file

#

then copy that URL :^^

willow isle
#

All righ thx, gonna try. Yet, I don't get why it must be so

summer snow
#

upside to that rather than having it locally,spinning simple server and getting it that way?

steady stratus
#

:^

willow isle
#

I spawn a simple server on my side to get it after i downloaded it from github

#

That's what i did, didn't know i had to get raw one

stuck fractal
#

@willow isle If you wget the page, it doesn't give you the file. It gives you the HTML page that your browser would render.

willow isle
#

Aww yeah that's right ! Did not remember this

#

Am i right saying that curl would have done the job ?

#

Just to know

stuck fractal
#

@willow isle Curl would have given you the HTML too

#

That web address will serve you the HTML no matter how you access it

willow isle
#

Ok, thx.

#

Is there a difference between those tools ?

stuck fractal
#

Google it

willow isle
#

That's what i was about to say ^^ thx

graceful nacelle
#

is the website down for everyone else?

stuck fractal
#

Yes.

sick sun
#

anyone give me a hint privs esc on securitay ? thanks

inland onyx
#

Securitay?

#

That's a conference

stuck fractal
#

@inland onyx It's a room as well

#

I wonder, it might be yours

#

But seeing as we can't search for that room, we're kinda stuck @sick sun

inland onyx
#

Yeah, that's what I was thinking 😆

stuck fractal
#

I imagine JOAT

inland onyx
#

Mhm

sick sun
#

sorry man i mean Jack-of-All-Trades

#

😄

inland onyx
#

What are you stuck at @sick sun?

sick sun
#

privs esc

#

@inland onyx can i PM you

#

?

stuck fractal
#

We try to keep it out of DMs where we can here

sick sun
#

@stuck fractal oke man sorry

inland onyx
#

Mhm -- what James said, although you're welcome to ask here if you want a hint, or #room-help if you want help with it

sick sun
#

@inland onyx oke man

uncut bolt
#

I know I'm late to the game here but I'm stuck on Cyber Advent day 5 Question 4. I've searched through the hints here and it looks like others have figured it out. I've used the archive and found the correct number of time to go back but it still won't accept the date. Any advice?

stuck fractal
#

@uncut bolt So you went back that far, did you do the maths to work out the actual answer?

uncut bolt
#

@stuck fractal Yes, that's why I'm confused. I don't want to go and say what I've tried to not ruin it for anyone else

stuck fractal
#

DM me your answer

dense marlin
#

hey there

#

can i get some help for tmux room?

#22 Now that's we've finished out work, what can we type to close the session?

#

arent that we used tmux kill-session -t 0 to kill the session?

stuck fractal
#

From your own command line

#

And don't kill things, it's bad

dense marlin
#

omg my bad....

#

i thought it's one of the commands from tmux

stuck fractal
#

Don't post answers, please.

dense marlin
#

omg my bad

prisma blade
#

Hey everyone ,, can anyone give me hint with hacker note task3

stuck fractal
#

@prisma blade I don't know how anyone can give a hint for that.

#

Either write a script, use burp with an extension, or use the prewritten exploits

#

By using the python exploit, you waive the right to complain about the speed

#

Same with burp unless you have pro

prisma blade
#

Thanks I will try my best I saw the hint but I didn’t understand

stuck fractal
#

Which question number?

prisma blade
#

3

stuck fractal
#

I assume q1.

#

You said task 3

#

Do you mean task 3 question 3?

prisma blade
#

Yes

stuck fractal
#

If you wrote an exploit, run it

#

If you didn't. Write one, find one or use burp

prisma blade
#

I have seen the one on ninja github

stuck fractal
#

The golang exploit is the fastest

prisma blade
#

But how can I run it from my terminal I mean

stuck fractal
#

Google.

#

Read it, find what you need to change

#

If it's Go, you need to compile it.

prisma blade
#

Is it like python <name>

stuck fractal
#

how to run python code

prisma blade
#

Okay thanks

#

Got it

echo thunder
#

did anyone complete Cross-site Scripting challange

#

?

#

I have a question

#

on task 5 question 2 I've managed to change the background to red

#

but there is no flag

tawdry dove
#

Good morning. So I am at dogcat room last flag. I am root but I can see I am some kind of jail. Possibly docker. Do you know some good related materials? I don't know much on the subject

shrewd skiff
#

@tawdry dove https://gtfobins.github.io/ try look here. It might give you a clue or ideas. I dont know your room but i do know docker 🙂

tawdry dove
#

Thanks @shrewd skiff .

dense marlin
#

@tawdry dove try look out anything related to date

mental osprey
#

What's up peeps 🙂

Quick question... Anybody have some tips and tricks for locating difficult flags?
Common locations, searching methods, find ticks, grep tricks, etc...

I'd really appreciate it ❤️

still elm
dark schooner
#

@still elm Thanks for the info, I too was wondering how to locate flags easily 😀 😀 😀

#

@mental osprey Good question dude 🤩 🤩 🤩

mental osprey
#

@still elm I appreciate the advice but I've exhausted find commands :P
I did this room a while back

past night
#

that's cheeky and not nice ^^

rancid crystal
#

but it works, soo xD

past night
#

it defeats the point of the room ^^

rancid crystal
#

well even this not works 100% of the time

#

should i delete this then?

past night
#

up to you, i would say yes

shadow basin
#

.. possibilities enabled by "-exec" is beyond the scope of this tutorial. Can anyone suggest a good place where I can find more info about it?

#
  • related to privilege escalation
inland onyx
#

@shadow basin that's covered in the Advent of Cyber

shadow basin
#

@inland onyx Thanks, if you mean Task 13 then thats what I am doing now. But would love to have more in depth reed about "-exec" specially related to *escalation. Thought maybe someone can suggest a good read.

inland onyx
#

I doubt anyone's covered it in that much depth -- it's just one method. There's probably a gtfobins page on it. Realistically, all you need to bear in mind is that -exec lets you execute a command on the files that you find. Like, for example /bin/sh

shadow basin
#

why outcome is 'igor' if file is owned by 'holly'

past night
#

because you execute your command on that file

shadow basin
#

yeah but I am 'holly'

past night
#

yeah, have you heard of suid/guid

shadow basin
#

nop I am 'new' 😄

past night
#

yeah, do some reading on that. you will understand

shadow basin
#

thanks

past night
#

no problemo

white salmon
#

Anyone for Jack? Need a hint please

summer snow
#

wait I don't get it there are no suid/guid bits in the permission for the file though @past night

past night
#

is it not?

summer snow
#

would it not be something like -rws if that were the case? idk haven't done the room/task but I don't think it's suid related but then again not an expert aha

past night
#

if it managed to run the command under the context of a different user i would assume so

shadow basin
#

it is suid related

past night
#

hehe, i was right

shadow basin
#

I managed to run command as another user because /usr/bin/find was belonging to another user

#

if it wouldnt be so, that wouldnt be the case

#
  • hope it is not considered a spoiling
summer snow
#

oh that's because you're running find as igor not the file you could've created your own file as holly ran find <your-file> -exec whoami \; and gotten an output of igor

shadow basin
#

@summer snow note the "s" letter on '/usr/bin/find' , thats called sticky bit

#

it lets you run the file as the user i guess

summer snow
#

yea that's what I'm saying the file_owned_by_holly has nothing to do with it. It's just a random file with 664 permissions and could be replaced with any file to get the same effect.

shadow basin
#

yes

#

however i havent figured out how to run the bash of 'igor'

#

somehow on every command works this way

summer snow
#

gtfobins is my go to for finding more about stuff like this

shadow basin
#

what is 'gtfobins'

summer snow
#

google

shadow basin
#

thanks alot for the hint

warm sierra
#

can someone tell me whats the incident of the photo in agent sudo /

solid patrol
#

use reverse image search

warm sierra
#

i cant seem to find anything @solid patrol

solid patrol
#

i found it using yandex

warm sierra
#

@solid patrol just to be sure i need to search the green cute alien image right ?

solid patrol
#

i dont think that is the image

solid pollen
#

Hey can someone give me a hint to priv esc in Ignite?

glossy basin
#

i'll check and hint

solid pollen
#

Ok

glossy basin
#

On the main page check the Step 2 about database configuration

#

there's a hint on how to get some sensitive info

solid pollen
#

On the main page check the Step 2 about database configuration
@glossy basin Ok, thank u so much✌️

glossy basin
#

Anytime, if you have any further questions feel free to ask 😄

solid pollen
#

Ya sure😇

viral crane
#

Lmao, for the room BP: Volatility, if you just put the file in your windows computer, Win defender will give you the last answer (:

#

I got stuck searching and uploading thing.. and then windows told me I had a virus kek

nocturne vault
#

getting headache from privesc jackinthebox, nudge in the right direction pl0x

stuck fractal
#

That's not a room

#

I assume you mean Jack Of All Trades?

graceful nacelle
#

$ find / -type d -name 'exploits' whats going wrong th this?

stuck fractal
#

What are you trying to do?

#

And what's not happening?

graceful nacelle
#

im searching for all directorys whose name is direcotry

#

lol exploits

stuck fractal
#

So what's happening that makes you think it's going wrong?

graceful nacelle
#

im taking a find course and this is one of the questions

nocturne vault
#

yea i mean jack of all trades sry 🙂

graceful nacelle
#

"find"

stuck fractal
#

@graceful nacelle Maybe quote mark types

graceful nacelle
#

ive tried them all

#

Find all directories whose name contains the word "exploits"

stuck fractal
#

Ah

#

You're not quite doing that

#

@nocturne vault This channel is for hints

nocturne vault
#

woops

#

sorry, will remove

stuck fractal
#

also use backticks to get discord not to format

nocturne vault
#

ty 👍

stuck fractal
#

@graceful nacelle name = exploit isn't the same as name contains exploit

inland onyx
#

@nocturne vault What's up with JOAT?

nocturne vault
#

having trouble getting root "/

#

cant seem to find the entry point

inland onyx
#

I figured
(watch as I try to remember how you gain root in that one)

#

Oh, I remember

#

Should be fairly straightforward -- it's the second thing you should be looking for with Linux privesc

#

First being sudo permissions

nocturne vault
#

feels like i've checked everything i usually check for 🤔

#

and second being files with SUID bit..

inland onyx
#

Correct

nocturne vault
#

i did that like, 2 hours ago lmao

#

got nothing

inland onyx
#

Bear in mind that's an ex-conference box. I didn't want professional hackers with full root shells running around...

nocturne vault
#

I feel so freaking dumb right now

#

I always forget the freaking / after -perm ...

#

holy shit im mad, that's why taking breaks is important lol

#

cool thanks, nice box 🙂

#

@inland onyx

graceful nacelle
#

-name pattern
Base of file name (the path with the leading directories re‐
moved) matches shell pattern pattern. Because the leading di‐
rectories are removed, the file names considered for a match
with -name will never include a slash, so -name a/b' will never match anything (you probably need to use -path instead). A warning is issued if you try to do this, unless the environment variable POSIXLY_CORRECT is set. The metacharacters (*', ?', and []') match a `.' at the start of the base name (this is a
change in findutils-4.2.2; see section STANDARDS CONFORMANCE be‐
low). To ignore a directory and the files under it, use -prune
rather than checking every file in the tree; see an example in
the description of that action. Braces are not recognised as
being special, despite the fact that some shells including Bash
imbue braces with a special meaning in shell patterns. The
filename matching is performed with the use of the fnmatch(3)
library function. Don't forget to enclose the pattern in quotes
in order to protect it from expansion by the shell.
no where does it say put the astricksSsSs inside the quatations

stuck fractal
#

No, because you're not understanding the question

graceful nacelle
#

find / find <what> find <where> type directory name exploits

nocturne vault
#

@graceful nacelle look up wildcards

graceful nacelle
#

i have ./*. but why would i need that when that looks perfectly fight

#

nm

#

check this would what i typed work in any other enviroment

nocturne vault
#

you should have it in the -name parameter, it will match anything containing the word exploits

#

so for example, the directory named 123exploit will be matched, so will exploit1234 and asdexploitasd or simply just the name "exploit"

#

I have not done the room you are referencing, but I think this is what you are supposed to do if I've understood you correctly

stuck fractal
#

You were looking for a directory named exactly "exploits"

#

Which isn't what you were asked for

graceful nacelle
#

whew i feel better thanks now thanks guys

tight escarp
#

anyone who has done Cicada 3301 and can explain to me what means uuse negative integers to go backwards in the text? I have tried a lot of methods using that hint but couldn't figure out the correct link

inland onyx
#

||Use the line numbers||

tight escarp
#

can i actually pm you? im confused af

solid patrol
#

Links can have numbers in it

tight escarp
#

got it 😄

inland onyx
#

Better asking @solemn smelt for that @tight escarp.
I tested it, so I'm kinda limited in what I should be revealing 😆

tight escarp
#

had to put head to head your hints and found the key

#

thanks!

solemn smelt
#

Oh haha there is a hint as to how to use the negative integers at the top of the document

#

@tight escarp

tight escarp
#

yes i know, but i have interpreted that hint like I have to start from the end of the line and go back

solemn smelt
#

Basically|| If you use positive integers to go forward in the text starting at the first letter then using a negative integer you would go backwards from that first letter to the numbers.||

tight escarp
#

yep, i guess that hint can be interpreted in more ways than one

#

fun room anyway 😄

solemn smelt
#

It was very hard trying to find a good way to write that

tight escarp
#

yeah, i can imagine

wraith marsh
#

I initially thought that too, until I saw what they actually where 😩

shadow basin
#

can anyone give me a hint why it doesnt work?

white salmon
#

where are you using it?

shadow basin
#

at my pc, testing SUID escalation example

white salmon
#

but are you using ssh or something? or is it your terminal?

shadow basin
#

but I am not familiar much with python, do I need to install some library?

#

thats my terminal

#

i run linux as my OS

inland onyx
#

For a start

#

Use Python3

shadow basin
#

same result

inland onyx
#

sudo python3 -m http.server 80

shadow basin
#

@inland onyx amaizing thanks so much

stuck fractal
#

@shadow basin Thanks for moving.

white salmon
#

weird i dont need to use python3 to set it up

stuck fractal
#

Systems no longer come with python2 by default

#

At least ubuntu

#

so python won't do anything

inland onyx
#

@white salmon If you have both versions installed, you need to specify which one

#

Or change the symlink in /usr/bin

white salmon
#

hm i think my python2 doesnt work then

shadow basin
#

@white salmon " ls -ls /usr/bin/python* " might list all available 'python' versions

ornate narwhal
#

room XXE task 2 , question 5. I have done the rest of the room, seems like an easy room, but that question makes me wanna hit the wall.

#

can someone gimme a hint ?

last nova
#

I think this might have the answer

ornate narwhal
#

@last nova thank you man, i dont know why i was looking for my answer in this line : <?xml version="1.0" encoding="UTF-8"?>

last nova
#

lol I was sat looking at that for a minute or two as well

ornate narwhal
#

well that makes me a feel a lil bit good.. im not that stupid after all 😄

untold birch
#

on the last question of corp, can't connect or change the pw, I've tried it all, is the last question just not possible due to the expiration date? I've yet to find an rdp client that will let me log out and log back in. Could someone give me a nudge?

stuck fractal
#

Microsoft RDP will allow you to connect and update the password IIRC

untold birch
#

so do I need to spin up a vm or can i do it from the room's box

stuck fractal
#

RDP into itself?

#

Sounds iffy

untold birch
#

well the issue is when I try to log out from the provide box it disconnects me so I don't understna dhow I'd do it any other way because you need VPN to access the machine. and to my knowledge you can't be connected on two different computers can you?

#

connected to their vpn

stuck fractal
#

No, you can't

#

But