#room-hints

1 messages ยท Page 25 of 1

chilly lantern
#

thanks

untold birch
#

need some help on Tempus_Fugit_Durius specifically the initial foothold. any hints? (I've tried the burpsuite method and got filename too long, so I'm assuming I either need to encode it differently or it's not the intended path.

#

DM's are welcome

chilly lantern
#

@stuck fractal That worked - you guys are awesome

frail ferry
#

@untold birch: did you identify the vulnerability?

untold birch
#

@frail ferry no dice.

unique cypress
#

Hello, I am finding myself stuck at task 2, question 12 from RP: nmap.
The question says:
โ€œHow about if I want to scan every port?โ€
I thought the answer was somewhere along the line of -p0-65535 but I am wrong. The answer format is *** can anybody help a newbie out here?

steady stratus
#

the question is looking for 3 characters

#

you're providing

#

9 ๐Ÿ™‚

#

specifically: it's looking for the switch

unique cypress
#

Thank you for your help @steady stratus You mean there is a specific flag for nmap that makes it scan all ports?

inland onyx
#

An option for an existing switch, but yes

steady stratus
#

^

unique cypress
#

Found it! thank you.

steady stratus
#

nice one ๐Ÿ™‚

abstract apex
#

hey, any hints for task 7 (Geolocating Images) ?

solemn smelt
#

Well this is late @abstract apex however think about what direction youโ€™re facing as well as what landmarks are around to identify where you are

white salmon
#

I need help :3

#

Three picture, three hints: hide, comment and walk away

#

first is steghide, second is exiftool comment

#

what could be the third one

#

the information is stored in the picture, the hint is "walk away"

#

it was binwalk

patent token
#

Any suggestions on a password list for Jack? Rockyou is obviously too long. I have the user names already, and working through a 10,000 list from Github, but nothing yet.

stuck fractal
#

@patent token I used rockyou, ngl

abstract apex
#

@solemn smelt i used the plate of the taxi, i found that the vehicule belongs to London, Borehamwood (formerly Stanmore) but i can't recognize the crossroad

patent token
#

Okie doke Ninja. Thanks!

solemn smelt
#

@abstract apex thatโ€™s not task 7

#

Just look up the name of the crossroads youโ€™ll be able to find it

abstract apex
#

@solemn smelt you are talking about task 4, i'm stuck in task7 (4.png)

wraith marsh
#

Okie doke Ninja. Thanks!
@patent token Theres a fast er one thats quite small

patent token
#

oh?

wraith marsh
#

took 10seconds

#

Remove this if not allowed ^^ || fasttrack ||

solemn smelt
#

@abstract apex I honestly canโ€™t remember that one could you send the pic?

pallid bough
#

Hello. I'm new and just starting and I'm following the beginner pathway. I've completed the introduction to research and lean Linux rooms. I'm currently stuck in room Linux challenges task 2 #8. Decompress and get flag 8. I've found the file I need to decompress but I'm logged in as Garry. Any hint would be appreciated

cloud perch
#

okay so im doing blaster and right now im trying to do the exploit with the hhupd but in order to do it the machine needs to be able to surf the web is there another way of doing it offline

glossy basin
#

okay so im doing blaster and right now im trying to do the exploit with the hhupd but in order to do it the machine needs to be able to surf the web is there another way of doing it offline
@cloud perch no, there's no need for that

#

it's going to work without global internet connection

peak girder
#

@pallid bough you probs didn't read it but task 2 #2 says: Log into bob's account using the credentials shown in flag 1.

white salmon
#

Mayor what can i research and how if i wanted to start with a phone number

#

@TheMayor speaking about Open intelligence sources

summer vortex
#

Hi everyone

#

I wanna ask something

white salmon
#

Hi Darkstern

summer vortex
#

Is there a place where we can see the medals we won in a room we have already completed?

white salmon
#

I don't fuckin know DarkStern

#

To be honest with you

summer vortex
#

?

#

you don't have to

white salmon
#

I wanted to give you a straight answer

#

๐Ÿ˜„

#

Just kidding around

#

Sorry

steady stratus
#

There's better ways of phrasing it though @white salmon

#

(sorry for ping other user)

white salmon
#

Of course there are, i already said i'm sorry

steady stratus
#

Only certain rooms have badges when you complete them - you can see them on your TryHackMe profile @summer vortex ๐Ÿ™‚

#

Yeah I saw as I sent it, thanks for apologising.

wooden mist
#

in the badges tab

summer vortex
#

@steady stratus First of all, thank you so much for your answer

white salmon
#

So guys, what can i gather on the web and how and if there are with which tools

summer vortex
#

@wooden mist I already checked but i can not find even i already completed room

white salmon
#

If i wanted to research on my phone number for example

summer vortex
#

@wooden mist for example "Basic Pentesting" room's completed badge

wooden mist
#

basic pentesting doesn't have a badge thonk

summer vortex
#

hmm

#

well is there any kind of "completed" think

steady stratus
#

I'm not quite sure what the criteria for a room to have a badge exactly is

summer vortex
#

I'm started to penetration testing so recent and it was my first room which I completed

steady stratus
summer vortex
#

so I just wanted to share on linkedin

#

yes like these

#

when you completed a room generally it's shows automatically kind of badge if you want to share

steady stratus
#

I believe you can do that in the pop-up after you complete the room. But hindsight you don't get the pop-up again later on. Best you can do at the moment is use the "Share" button in the room

summer vortex
#

oh okay i got it

#

so it just shows 1 time

steady stratus
#

I believe that's the closest you'll get to a "I've completed this room" at the moment other then your profile. Maybe something for #544951750801752079 ? ๐Ÿ™‚

summer vortex
#

i mean this

steady stratus
#

Yeah

summer vortex
#

but i got the answer

#

thank you so much :)

steady stratus
#

That's the only time that will popup - you cant get that to display again when you come back to the room in say a month or so

#

but i got the answer
@summer vortex coolio blobfingerguns

summer vortex
#

hmm

#

thanks :)

steady stratus
#

^^

grizzled glacier
#

Hi there! Has anyone here done the 'The Impossible Challenge'?

#

I have decoded the text on that page and tried cracking the zip. But unsure where to go from here. Hint on the page is not very helpful (yet, I think)

inland onyx
#

@grizzled glacier you're looking for a very specific way to hide information.

grizzled glacier
#

interesting. even before i manage to extract the zip then?

echo thunder
#

any hints on how to identify what the encode was used for the text on impossible challenge

#

?

shy sinew
#

Network services room

glossy basin
#

@shy sinew can you please avoid posting answers

#

telling task and question number is enough for us to understand

shy sinew
#

Ohhhhk next time I'll take care of it

glossy basin
#

so, what was the question?

shy sinew
#

How to perform the ping on telnet session using .RUN

glossy basin
#

using the ping command after .RUN

#

itโ€™s given there

shy sinew
#

But it's not working

glossy basin
#

did you set a tcpdump listener on your machine?

#

question 5

shy sinew
#

Yess I do

#

No response is shown there

#

In listener

glossy basin
#

did you get your tun0 for the ping?

#

โ€œInternal Virtual Ip addressโ€

shy sinew
#

Yes I have mentioned the tun0 ip of mine

glossy basin
#

then you should be able to receive it

#

you are connected to vpn, right?

shy sinew
#

Can u pls tell me the ping command (using .RUN)so I'll know that I'm sending right command or not!!

glossy basin
#

it is stated in the question 6

#

bold text

shy sinew
#

A note is written after the ques that -you need to preface with .RUN what is the use of that??

glossy basin
#

that means you need to put .RUN before the ping command

#

.RUN ping [tun0] -c 1
tun0 replaced with your IP value

shy sinew
#

๐Ÿ‘

normal totem
#

Hey, i would like to get a hint in finding the Joomla version on the Daily Bugle room

past night
#

nmap?

normal totem
#

if i -A, i get only the apache version

past night
#

what other tools have you tried to use?

normal totem
#

gobuster

#

also gobuster on the /administrator

warped fox
#

did you google? lots of ways to find it out and a simple google I just did returned many things to check from the first few results of google

normal totem
#

on google, they said to go on the dashboard and i dont have access

warped fox
#

clearly didn't google enough, google without access..

past night
#

gobuster wouldn't tell you the version of joomla

#

that a directory bruteforce tool

warped fox
#

hint: even without admin access there might be files you can read that have the version. it may be several directories deep so fuzzing it may not work. also for other things if they're opensource you can check through github etc

past night
#

you need to find other tools that help with that or files on the system

#

information gathering. that's what you need to do

normal totem
#

i used gobuster to see if there is a kind of info page

warped fox
#

i'd recommend not using a tool and doing this manually but yes tools exist for stuff like this..

normal totem
#

ah, i didt know there are tools for this

#

ill search deeper now

#

got it :)

#

thanks @warped fox, found a script that finds it in a directory

#

i was close but didnt look into that directory

warped fox
#

nice but again I suggest getting comfortable googling stuff like that since while there's a tool for this there are hundreds of sites or cms that won't have automated ways and googling to find the right directory or cloning the repo and searching for it yourself will prove to be very handy ๐Ÿ‘

normal totem
#

okay :D

sullen seal
#

looking at the linux challenge room and stuck om flag 7 PS and top dont show any flags

echo thunder
#

a hint regarding question 3 task 1 in the Wifi Hacking 101 challenge

#

?

#

resolved

#

thanks

#

i did't think to much

sullen seal
#

figured it out missed a switch

spark monolith
#

Can anyone help me out to find the admin flag in pepega energy?

patent token
#

Please refer to my suggesting in the other channel.

#

You need to provide more information regarding your current position in the room/challenge.

spark monolith
#

@patent token channel name? I am new here so donโ€™t know much

patent token
#

You replied to my comment in #thm-community-media as you were posting in the wrong channel. I recommended that you provide information about your current situation in the room/machine. Doing this will help folks want to help you, as we don't have to dig for answers that way.

#

Can you please provide context/information about your current situation in Pepega, so that we might be able to provide you with appropriate help?

echo thunder
#

i want a hint for a challenge. The challenge is plethora. I need a hint for the flag on juice shop if someone can help me please.

stuck fractal
#

@echo thunder So, the RCE is broken for that as it runs in a docker container

echo thunder
#

ok

stuck fractal
#

You can root the host, and find the flag via the files for the container

#

That's the only way we've found unless there's LFI or something

echo thunder
#

ok tahks

#

@stuck fractal can I ping you

#

?

patent token
#

You just did...

tidal sedge
#

They are probably asking for permission to dm him.

echo thunder
#

can someone help me with a docker image please?

stuck fractal
#

@echo thunder find / -type f -name "*flag*" 2>/dev/null

echo thunder
#

Thanks @stuck fractal

shy sinew
#

Can anyone help in network services room task 6 ques. 6 ??

white salmon
#

can anyone help me, IM TRYING TO CONNECT MY SERVER WITH PUTTY BUT IT SAYS CONEXION REFUSED

inland onyx
#

Your server? That doesn't sound very THM related @white salmon

white salmon
#

is openvpn server

inland onyx
#

You are, uh, trying to connect to the Openvpn server with PuTTY?

white salmon
#

yes

inland onyx
#

How about connecting to the openvpn server with openvpn, then the target machine with PuTTY?

white salmon
#

i already connected to the server with openvpn, i want enter with putty

inland onyx
#

Have you deployed the target?

white salmon
#

deployed the target???

#

what is that

inland onyx
#

Big green deploy button

white salmon
#

ima try it

#

again

#

should i turn off firewalls?

inland onyx
#

Have you pressed the Deploy button?

white salmon
#

oh ok

#

thx

#

u fixed

#

thx u a lot, i was 2 hours trying fix this problem

#

๐Ÿ˜€

inland onyx
#

Did you go through the Tutorial room @white salmon?

white salmon
#

yes, the linux basics tutorial

#

i dont forget nothing of it yes? i said bcs im not paying

inland onyx
#

That

#

Have you completed that?

white salmon
#

yep ๐Ÿ™‚

inland onyx
#

That teaches you how to deploy machines and use the site

white salmon
#

i forgoted, principiants errors xd

inland onyx
#

Maybe go do it again to refresh your memory

white salmon
#

i will

#

thx

#

bye

timid pagoda
inland onyx
#

@burnt cosmos That is right -- please delete it ๐Ÿ˜

burnt cosmos
#

@inland onyx Website says otherwise!

inland onyx
#

Try it without caps

#

Oh, no, sorry

#

Try it without the -

#

The caps won't make a difference

#

Just checking the format I used ๐Ÿ˜†

burnt cosmos
#

Amazing! Ty

inland onyx
#

Np ๐Ÿ™‚

strange basin
#

can anyone give me a hint for room The Cod Caper task 4? I'm not getting anything with sqlmap, trying to exploit a login form.

#

im supposed to get an admin username/password

spark monolith
#

@patent token in pepega , i have found all the answers but not the admin flag , last what i did was change the password of zachary by using the password_change command and loggied via rdp, i then came to know that zachary is the admin itself but couldnโ€™t find any flag for the admin

patent token
#

Which # are you referring to having difficulty with?

spark monolith
odd void
#

@spark monolith (Creator here) If you managed to gain access to a friends computer, what is the first thing you would check? Think incognito mode...

stuck fractal
#

dogekek dan, did you really hide it there? Nice.

strange basin
#

how do i look for ssh password for my user?

stuck fractal
#

@strange basin SSH password is the system password

strange basin
#

oh welp

#

thank you

stuck fractal
#

@strange basin If you're doing cod caper, then say

strange basin
#

i am yes^

#

i said it 5 messages ago

spark monolith
#

@odd void I literally forgot that ,thanks
Will continue from there ! coolguy

odd void
#

np!

stuck fractal
#

@strange basin So, find might help you

#

But SSH password is the system password unless you have SSH keys set up

strange basin
#

alright, thank you

#

i found the .ssh directory? is that it?

#

a bit lost here

stuck fractal
#

.ssh is used to store ssh keys

#

But if you're looking for a password, a key isn't a password

strange basin
#

okay thanks

#

pwndbg is not running on gdb (The Cod Cape)

#

just default gdb for me

next glen
#

anybody here?

stuck fractal
#

Always

#

Just ask the question

next glen
#

Heya Ninja; I'm doing the advent christmas one and on task 11 I don't understand the first question

#

I've done the others, did everything I was supposed to

#

but I don't understand what the question is asking me..

stuck fractal
#

I'm gonna be honest

next glen
#

sure

stuck fractal
#

People are less likely to help you if we have to go and find the room and task and question

next glen
#

Yea was just thinking of that

stuck fractal
#

Make it as easy as possible for people to help you.

next glen
#

yea yea

#

"what data was exfiltrated via dns?"

#

what does it mean by data?

stuck fractal
#

Data is information

#

Filter the packet capture to just DNS

#

See the suspicious one(s)

#

See what you can do with that

next glen
#

I did that too but didn't find anything relevant. I'll try again ๐Ÿ™‚

#

thanks for the hint buddy

stuck fractal
next glen
#

lol that's literally the first one I had searched. Thanks, will read that

last nova
#

tbh that sounds really noisy

wary ocean
#

Kinda confused about the goal of JWT

#

Like what are you trying to do

stuck fractal
#

With JWT, or the challenge in the room?

wary ocean
#

Challenge in the ocscure web exp room

stuck fractal
#

Ah I haven't got there yet so I can't really help

wary ocean
#

Like I have the new signature, and the modified header, but I'm just confused as to what the goal is, and what to change the content to

#

And how that would help me get a flag anyways

stuck fractal
#

JWT are used for auth

#

So you're breaking the auth on whatever you're attacking

wary ocean
#

True, there's not like a visible user object in the body tho

stuck fractal
#

Hopefully to get a flag

wary ocean
#

I could just like

#

@white salmon

wooden mist
#

@wary ocean what part of JWT are you stuck on?

wary ocean
#

I just don't know what I need to change in the body of the token

#

Do I just change it in general?

wooden mist
#

section 3 or 3.5?

wary ocean
#

3's challenge

wooden mist
#

token's body contains a data portion

wary ocean
#

Right

wooden mist
#

there's one thing that imo is obvious you should change

wary ocean
#

Yeah I reread the question, I thought I had to change it to something specific

wooden mist
#

i changed it to the first thing that came up

white salmon
#

Never fear para is here

wooden mist
#

the first logical thing

white salmon
#

To destroy jwt and everything it holds dear

wooden mist
#

jwt DogKek

white salmon
#

I hate jwt so much

#

You don't know the pain that went into writing those sections

wooden mist
#

lmao

#

I finished the jwt section in like 3 minutes kekw

white salmon
#

I read the JWT RFC da*n it

wary ocean
#

Para you are my god, JWT is seriously the worst thing to exist ever

#

besides EternalBlue

white salmon
#

I hate it too

wooden mist
#

Para you are my god, JWT is seriously the worst thing to exist ever
@wary ocean you haven't seen bad codebases you need to somehow change without breaking stuff, that's the worst thing that exists on this world

stuck fractal
#

Agree

#

Random use of global variables when you don't need to

#

That affects the state of an internal function

wooden mist
#

static's everywhere Kappa

stuck fractal
#

Variables not accessed outside of the main() function

wary ocean
#

so like

#

i successfully didn't screw it over to the point it broke everything, but it didn't work

#

what do i need to set for the data?

stuck fractal
#

Somewhat reassuring?

#

I guess read the RFC

wooden mist
#

so if you have noot in the data section it gives you noots, maybe change the noot to something you want to recieve?

wary ocean
#

tbf i didn't run it beforehand to know what it did, that probably would have been a good idea

#

Changing it to flag or flags doesn't help

wooden mist
#

are you editing the key like the room shows?

wary ocean
#

Running the commands that are in PayloadsAllTheThings

wooden mist
#

try using the token editor auth0 has
http://jwt.io/

JSON Web Tokens are an open, industry standard RFC 7519 method for representing claims securely between two parties.

wary ocean
#

Has an error with header

#

Nevermind, I fixed it

#

Sending me an error about an invalid signature, is it alright if I dm you my procedure?

wooden mist
#

Sure

clear cargo
#

hello,

#

is the binary file the way to get root or just the ||job || (Racetrack Bank) :d

inland onyx
#

Both together

clear cargo
#

o:

echo thunder
#

the server deploy on task 6 in ZTH: Obscure Web Vulns is not working

#

the button is working

#

but I cannot access any page

white salmon
echo thunder
#

i posted here because maybe I am the only one that is having this issue

sharp bolt
echo thunder
#

can anyone ping me ? I need a little hint for the ZTH: Obscure Web Vulns

white salmon
#

it puts in putty

#

and i have one thing in putty when i conect the server, 11packages can be updated

steady stratus
#

Instances that you deploy don't have access to the internet @white salmon

#

there's no need to update apt ๐Ÿ™‚

white salmon
#

shiba1@nootnoot:~$ apt
apt 1.6.12 (amd64)
Usage: apt [options] command

apt is a commandline package manager and provides commands for
searching and managing as well as querying information about packages.
It provides the same functionality as the specialized APT tools,
like apt-get and apt-cache, but enables options more suitable for
interactive use by default.

Most used commands:
list - list packages based on package names
search - search in package descriptions
show - show package details
install - install packages
remove - remove packages
autoremove - Remove automatically all unused packages
update - update list of available packages
upgrade - upgrade the system by installing/upgrading packages
full-upgrade - upgrade the system by removing/installing/upgrading packages
edit-sources - edit the source information file

See apt(8) for more information about the available commands.
Configuration options and syntax is detailed in apt.conf(5).
Information about how to configure sources can be found in sources.list(5).
Package and version choices can be expressed via apt_preferences(5).
Security details are available in apt-secure(8).
This APT has Super Cow Powers.
shiba1@nootnoot:~$ install
install: missing file operand
Try 'install --help' for more information.
shiba1@nootnoot:~$

#

wtf is that

steady stratus
#

Like I said

#

there's no need to update apt ๐Ÿ™‚
@steady stratus

white salmon
#

and the conection failed?

steady stratus
#

please read above

#

Instances you deploy on THM do not have access to the internet

#

hence the failure to connect when you're trying to apt update (of which there is no need respective of whether or not it can connect )

white salmon
#

ok

#

now i can learn echo command

#

im noob in this xD

steady stratus
#

gl hf!

white salmon
#

im in linux basics, and i need help, im learning the man comand, so i put echo man and im in good way, but later
No previous regular expression (press RETURN)

#

and i need to get "

How would you output hello without a newline"

#

i dont understand nothing....

#

im a hacker

#

so is -n echo hello

#

but rlly i dont understand wtf is -n

gaunt herald
#

Then use the manual for echo or --help

white salmon
#

What flag outputs things in a "long list" format

#

i dont understand this

gaunt herald
#

[command] --help

white salmon
#

guys, how to add text to a .txt

#

like when i put cat b.txt

#

cmd can show me whats inside

#

so i want add text to .txt to test the command cat .txt

gaunt herald
#

Google it

white salmon
#

xD

steady stratus
#

Yeah, questions like that can be very quickly researched. It's an attitude we really encourage here.

gaunt herald
white salmon
#

is cat > sample.txt

steady stratus
#

that's one of many ways

sharp bolt
#

any idea how to achieve a buffer overflow like python -c "print 'A' * 64 + '\x24\x84\x04\x08'" | ./stack3 without using python., maybe with xxd? i tried but can't make it work

stuck fractal
#

@sharp bolt you need something to print your raw bytes

#

In theory, you should be able to use a file

white salmon
#

how to know in wich directory im saving the .txt files?

#

in home, currently directory of before directory

#

for put direferents path

#

or*

steady stratus
white salmon
#

im on it

steady stratus
#

It will teach you all the basic commands you need to know like that

white salmon
#

im on it but how to know in wich directory the files saves

#

is a curiosity

stuck fractal
#

Wherever you tell it to.

white salmon
#

when u write touch b.txt

stuck fractal
#

By default, your current directory

white salmon
#

how it is called

#

home?

stuck fractal
#

No

#

Current directory can be anywhere you move to

white salmon
#

okey thx

#

How do you specify which shell is used when you login?

#

it is $0 ???

stuck fractal
white salmon
#

im google

stuck fractal
#

It's specifically for su

#

And you're asking for more than a hint

white salmon
#

incorrect solution

stuck fractal
white salmon
#

bcs im noob

#

and im puting all things i find

stuck fractal
#

Stop. Research.

white salmon
#

i was a noob too

stuck fractal
#

Man pages. Help options. Use them.

#

@white salmon Please go and read rule 13 #rules

white salmon
stuck fractal
#

Some basic research will give you the answer. @white salmon

white salmon
#

isnt 0$

#

$0

#

im estressing

#

stressed

stuck fractal
#

It's specifically for su. Do some research.

#

@white salmon Google it.

white salmon
#

ok sry xdรง

stuck fractal
#

A really fundamental part of computing and hacking in general is research

white salmon
#

ok sry sry

stuck fractal
#

Don't ask to be spoonfed answers. That helps no one.

#

There's a reason we had to write it into the rules here

white salmon
#

@sharp bolt did you take a look at pwntools ?

sharp bolt
#

hi, no i havent

#

i'll look it up

white salmon
#

you can use the "pack" function for your shellcode

sweet relic
#

hey guys. i'm stuck on a noob question. anyone here to help?

stuck fractal
#

@sweet relic Just ask the question, don't ask to ask

#

There's almost always people here if you're patient

sweet relic
#

Of these addresses two are reserved, what is the first addresses typically reserved as?

i've tried everything that comes to my mind but nothing works

#

its about local ip addresses

stuck fractal
#

Not sure I can hint that

#

Look at your ipconfig/ifconfig/ip a s

sweet relic
#

the answer has 7 letters and it is not 255.255.255.255 ๐Ÿ˜‰

stuck fractal
#

That's not the first, is it.

sweet relic
#

no its not but its neither about gates nor loops

stuck fractal
#

@sweet relic Perhaps it's another word for it

#

The device

sweet relic
#

that would be six letters then

stuck fractal
#

Maybe you want the full name

#

Gate means nothing

sweet relic
#

i dont get it ๐Ÿ˜‚

#

i'm an idiot. i've tried countless things and the obvious one was correct. thank you ๐Ÿ™‚

echo thunder
#

did anyone complete ZTH: Obscure Web Vulns

#

?

stuck fractal
#

@echo thunder Again, just ask the question

#

Don't ask to ask

echo thunder
#

I need a clarification regarding task 9 on ZTH: Obscure Web Vulns

stuck fractal
#

Again

#

Ask.

echo thunder
#

what vulnerable site

#

There is no deploy button regarding CSRF

#

sorry section 2

stuck fractal
#

@echo thunder have you tried... reading?

echo thunder
#

What parameter allows us to generate a POC(actual exploit)

stuck fractal
#

Huh?

echo thunder
#

this is the question

#

on the task

#

and is asking for an answer

stuck fractal
#

That's a parameter for the program

#

Try harder.

echo thunder
#

ok

#

thanks

lone widget
#

for the The Caping of Cod machine can someone tell me what i shoul search for with the "find" command. i have a nc reverse shell but now im stuck

inland onyx
#

Interesting files belonging to each user

lone widget
#

ahhh this is hurting my head ive looked everywhere haha, what is a .pub file?

stuck fractal
#

public key maybe?

#

or a publisher file

#

Extensions are meaningless

lone widget
#

ok cause there are two files that look interesting to me its id_rsa and id_rsa.pub and idk the diffrence

stuck fractal
#

@lone widget RSA

#

Is a type of encryption

#

There's a public key and a private key

wooden lava
#

I'm on learn linux on task 33 logged in as shiba3 ; trying to find the shiba4 bin. I'm getting a lot of permission denied after running $sudo find / -type f -name "shiba4.bin"

lone widget
#

ohhhhh thank you @stuck fractal

stuck fractal
#

@wooden lava File extensions are meaningless on Linux

#

Why assume it's a .bin?

#

And also you don't have sudo

wooden lava
#

Even though it says "The first step is actually finding the binary, I'm not heartless though, so I'll give you the name of the binary. The name of the binary is shiba4." - If i run a search for shiba4 i thought it would come up with a load of directories and files ; I'll go back and see if i can work it out . Ty

stuck fractal
#

@wooden lava File extensions are meaningless really, .bin is completely optional when creating a binary file

#

No one includes it

#

Because it means nothing

hazy fable
#

Okay, in Steel Mountain, I had problems starting the service for AdvancedSystemCareService9 (would get error 1053). I did this workaround that got me to system, but I was wondering if there is an issue doing it this way. Instead of doing the multi/handler exploit, I just ended up doing a netcat listener, which caused it to work. Any issues doing it this way?

stuck fractal
#

You'll still get a 1053 error

#

1053 means the service didn't tell windows that it started

#

Because you replaced the exe with your own, it will always 1053

hazy fable
#

Yes, I did get that. But, the ncat listener pulled up a shell in system before it timed out.

#

So, I satisfied the box's requirement, but I am unsure if I am missing out on something by not doing it the other way.

stuck fractal
#

The system kills your shell still

#

Unless you prependmigrate

#

You didn't exploit ti right

#

You weren't meant to replace the binary

hazy fable
#

Hm. Okay thanks!

lone widget
#

please someone help me with the The Caping of Cod machine, i feel like im on the right track with using the rsa public/private key to log in, but i am strugling and i dont know how to do it. i have aready tried putting the privat key in my .ssh file and using ssh -i but nothing works. im trying to connect to pingu

stuck fractal
#

@lone widget I said earlier

#

You're looking for a password

#

Not a key

lone widget
#

ahhh ive spent so lonng doing something i didnt even need to do, thank you ill keep looking

lone widget
#

im sorry for asking so many questions but i cant find anything. i have used find / -type f -user ("user") on pingu papa and root and i have found nothing

inland onyx
#

Those aren't the only users on the box

stuck fractal
#

Also that's a really weird way of giving "find" the user

inland onyx
#

^^

lone widget
#

gasp

#

but i looked at /etc/passwd

inland onyx
#

Mhm, and it will be in there

#

The "real" users aren't the only ones who can own files

lone widget
#

how am i supposed to supply a user @stuck fractal

stuck fractal
#

find -user userNameGoesHere or find -user 'UserNameGoesHere'

white salmon
#

guys on the room "bpnetworking" im stuck on: "How many addresses make up a typical class C range? Specifically a /24". Can someone give me a hint?

patent token
#

I would recommend searching /24 subnet addresses

stuck fractal
#

ip address classes

viral crane
#

(i was about to answer before asking my question but you were quicker than me)
hm but Hello there, I am doing the uopeasy room, and got stuck on searching the spot for the blind injection.. like I know its an old room and there is nothing on it to give some hint, if anyone has a tiny hint on where to do this, I will be very grateful aWumpusHug Thanks ๐Ÿ˜„

white salmon
#

I would recommend searching /24 subnet addresses
@patent token thanks vent

sacred kayak
#

This is a screencap of my burpsuite. It looks the same as the example, but the XXE is not working. Any suggestions as to what I am missing?

solid patrol
#

@viral crane try searching for directoris with comon extension

viral crane
#

Yeah I just launched a gobuster on this, thanks ๐Ÿ˜‰

#

I figured it was the last thing to do

viral crane
#

Okay so.... I got nothing really interesting? what am I missing really

white salmon
#

in OWASP Juice Shop while trying to find the user data, is there a good way to enumerate column names (of user table) using the union injection in the rest search area?

frail ferry
#

task 3 of webgramming is broken? nobody ever solved it except room's author

slender sigil
#

Hi! In kenoby room I get 11 ports open but it refuses my answer

#

resolved)

velvet flint
#

Anyone got time for quick time for question related to Skynet :)?

stuck fractal
#

@velvet flint Ask the question, don't ask to ask

velvet flint
#

Know what to do for root, but need to escalate to second user

#

Ive got 3 different passwords and a password hash from database

tidal copper
#

Hi THM people! Just wanted to request for a kind advice regarding "CC: Steganography" room. I got stacked with flag 3 of the QR code. I have processed the image and obtained 50 files. Not sure what to do or how to proceed? Could someone help? Many thanks!

slender sigil
#

Can anyone help me with room/kenobi I really dont understand how thats works in task 3 from #3 can anyone give me hint?

sacred kayak
#

@tidal copper did you try scanning the QR code?

white salmon
#

Just doing the Network services room on task 4 question 4 where it asks if there is any interesting information from the smbclient session - I've found a document called ||working from home information.txt|| however I can't seem to access it nor can I get it - I keep getting a NT_Status_object_name_not_found message? is there something I'm missing?

remote gate
#

@white salmon did you download the file? eg mget *

white salmon
#

Yep, still get the same message.

stuck fractal
#

Wrong share name?

#

Wrong username?

white salmon
#

I've logged in as anonymous as it explains to do - when doing ls it shows the file there.

#

Is it the naming that is the issue - IE all the spaces in working from home information.txt

stuck fractal
#

Quote it

white salmon
#

Scrap that - I've done it.

#

Thanks anyway.

#

@remote gate was correct, I wasn't thinking literally - I figured the * was for the file name - not realising that it gives you the option to download everything in said folder.

remote gate
#

cool and like james said you can quote it if you're using more to read the contents. in the future you could prompt off recurse on mget * and that should download everything you have access to

white salmon
#

Thanks! ๐Ÿ™‚

tidal copper
#

I'll try to scan it. Shall I use a specific app @sacred kayak

stuck fractal
#

@tidal copper It needs to have contrast if it's a QR code

sacred kayak
#

@tidal copper I just used Google lens on my phone. If you used stegoveritas, one of the extracted images should work. I just used MS Paint to change the colors to black and white (ducks)

tidal copper
#

I am trying to use google lens but not getting anything ๐Ÿ˜’

#

what can I be doing wrong? I used stegoveritas before...

#

just solved it guys, I simply downloaded the QR scan app for iOS

tranquil rain
#

Hey all, in working on the vulnversity room and having trouble locating the web server user. Can someone DM so I can walk you through what Iโ€™ve done so far so I can get a hint?

inland onyx
#

@tranquil rain you're not looking for the user the server is running as -- you're looking for the user who must have started the webserver

#

I.e. the only real user on the machine

tranquil rain
#

So I need to do some research on the users on the machine......

naive umbra
#

hello good morning yall

#

so which wordlists should i use in gobuster

wary ocean
#

just use dirb

naive umbra
#

whys that๐Ÿค”

wary ocean
#

easier to use and less errors

naive umbra
#

do i have to select wordlist? in that as well?

wary ocean
#

nope

#

just the url

naive umbra
#

thats noice

#

aight thanks @wary ocean

blazing turtle
#

any hints for finding the last flag on food?

stuck fractal
#

@blazing turtle The flags aren't numbered, so there's no last flag. I know which one you probably didn't find, but IDK which you have and haven't

blazing turtle
#

@stuck fractal can i dm so as not to spoil?

stuck fractal
#

@blazing turtle Ye I made the box

normal nest
#

did anyone solve golden eye?

vague heart
#

Any hints on: "[Task 43] Bonus Challenge - The True Ending" of the "Learn Linux" rom?. I tried finding SUID executables but sadly I cannot find it.

The task is to read a .txt file in the root home directory." /root/root.txt" with a user not permitted to do so. It's a very basic room, but it should be possible with what we learned

stuck fractal
#

@vague heart it is possible. Look for files belonging to each and every user

#

SUID would be a little too advanced

#

Investigate suspicious files

vague heart
#

Yea that's what I thought... Investigating suspicious files is a good one thanks

#

It's just... I don't know what options I have left.

These are the directories with "root" in their name:

/snap/core/8689/root
/snap/core/8592/root
/root
/usr/src/linux-headers-4.15.0-88-generic/include/config/usb/ehci/root
/usr/src/linux-headers-4.15.0-76-generic/include/config/usb/ehci/root

The top 3 I don't have permission to read. The bottom 2 do not contain a root.txt file

#

find -name root -type f -perm u=r 2>/dev/null doesn't say much either

stuck fractal
#

@vague heart Each and every user. Who said you're just looking for root? Files named root? Nah.

#

You know where the file is

#

That aint the problem

vague heart
#

Yea I don't have the knowledge to understand that

stuck fractal
#

@vague heart Go back to the find task

vague heart
#

I did

stuck fractal
#

See if you can work out how to find by file owner

#

Not file name

#

You know the flag is in /root/root.txt

vague heart
#

Yes indeed. So why would I be interested in other files?

stuck fractal
#

@vague heart Because you can't get access to it yet

#

You need to do recon

#

Search, look around, investigate

vague heart
#

Okay thank you. I'll skip this for now as I don't know what to look for yet

stuck fractal
#

@vague heart Look for files belonging to each and every user. Look at the results. Go from there.

vague heart
#

๐Ÿคทโ€โ™‚๏ธ

#

Thank you so much for trying to help me though

stuck fractal
#

Don't just skip it because you don't know

#

That's the opposite of learning

#
vague heart
#

Nice article, thanks!

stuck fractal
#

I told you what to look for as a hint

#

All you gotta do is look for it

vague heart
#

For someone with fundamental knowledge of pentesting things may seem easy, even basic. But I just learned how to echo "hello world" and pipe the output to a file and find that file again. There's a lot of information needed to go from that point to solving a pen testing puzzle with privilege escalation. You climb a mountain with training and step for step. Not with jumping as high as you can in the hope to reach the top. AKA: the task requires knowledge not yet obtained

stuck fractal
#

There's nothing you haven't learned

#

You're skipping it because you think there is.

tidal sedge
#

@vague heart You already have the knowledge, you just need to apply it.

warm schooner
#

Any pointers for The Impossible Challenge? Not too sure what steg-tools to use

vague heart
#

Thank you @stuck fractal & @tidal sedge I found the answer! It was indeed possible with what we learned in the room, but I have to admit it's pretty far fetched... But I guess that's the definition pentesting ๐Ÿ˜›

stuck fractal
#

It's not that farfetched

vague heart
#

For me as a beginner it looks like it's farfetched, but I hope I'll one day agree with you.

inland onyx
#

@warm schooner I've only seen one steg tool online that does it

desert bramble
#

Could anyone give me a tip for this question on the poloprivescfinal box? i dont even know where to start searching for this info

inland onyx
#

Look at some standard system files @desert bramble

#

Specifically, one that could store data about user accounts

desert bramble
#

hmm ok ill have a look, thank you

desert bramble
#

damn i was trying to hard, i was looking within that file to see if something had changed

#

got it now though

burnt cosmos
#

Currently on task 21 of zthlinux and feel like i keep reading the question incorrectly. Are you asked to set the $test1234 variable to equal $USER then check shiba2? Or have i misunderstood something

stuck fractal
#

@burnt cosmos Yes, but if you did >> $USER or > $USER then you broke it

#

And you'll need to redeploy

burnt cosmos
#

Damn

stuck fractal
#

You wrote to the binary if you did that

#

As soon as you write to it, it breaks

burnt cosmos
#

@stuck fractal Am i okay to PM you?

stuck fractal
#

@burnt cosmos Why?

burnt cosmos
#

Was gonna ask for some help, but I just figured it out! Thanks anyway

stuck fractal
#

We try to keep it out of DMs unless it's something excessively spoilery

wooden lava
#

I'm on linux challenges ; stuck on task 4. It says the flag is where cron jobs are created ; i've run "crontab -e" and theres no flag there.

#

Am I looking in the wrong area ?

peak girder
#

maybe another user?

burnt cosmos
#

@wooden lava Look more into where cron scripts are ran

delicate plaza
#

I feel really stupid to ask about hint for Learn Linux last task about privilege escalation

#

I think im overthinking it

#

can someone tell me little nudge ?

stuck fractal
#

Look for files belonging to each and every user

#

Investigate those

delicate plaza
#

aaa

#

thx u rememered me one thing

#

which i didnt wroted down

#

k found

peak girder
#

๐ŸŽ‰

delicate plaza
#

i checked for last two users ๐Ÿ˜„

stuck fractal
#

@delicate plaza All of them, not just the last two

delicate plaza
#

k found
@delicate plaza

#

I mean that last time and now i was checking for only last two

#

but i found it

#

thx

grizzled glacier
#

@warm schooner did you get any further on the impossible challenge? i've been stuck for a while

white salmon
#

learn linux room-task 18- question #2

#

what si that

#

is*

inland onyx
#

??

white salmon
#

the 2 question of learn linux room

#

task 18

inland onyx
#

Mhm, what about it

white salmon
#

what is that

#

im confused

inland onyx
#

Variables and Environment variables

white salmon
#

....

inland onyx
white salmon
#

the answer

inland onyx
#

Yeah, we don't give out answers here -- keep reading

white salmon
#

i dont want the answer, i want answer for understand what is that

#

....

#

o_o

inland onyx
#

That's a Google question

white salmon
#

thx

white salmon
#

Hi, i have a little problem with room /rptmux and #task3 - "All tmux commands start with a keyboard button combination. What is the first key in this combination?". standard answer like "default command key" (not literally ๐Ÿ˜› ) doesn't work, I use tmux every day so it gives me a headache..

stuck fractal
#

@white salmon Full name on an english/american keyboard

white salmon
#

@stuck fractal Try to not be angry and talk to me slowly ๐Ÿ˜‹ what you mean by "full name"

stuck fractal
#

@white salmon The full, unshortened name of the key

#

Unabbreviated

white salmon
#

thank you veryy much ๐Ÿ˜„ Now i'm done with this and i can go sleep

thin canyon
#

I'm on task 5 question 4 on linux challenges where I used an FTP client to download flag32.mp3

#

So I've done that and I've transferred it to my virtual computer provided

#

how do i listen to it lol the audio doesnt work oops

#

is there a way I can configure audio in this browser embedded machine?

steady stratus
#

you can upload the file to an online text to speech ๐Ÿ™‚

thin canyon
#

true!

abstract glen
#

Anyone able to give me a hint on how to find the third flag in Jurassic Park room?

thin canyon
#

LOL!

#

@steady stratus Thanks for the hint, I'll try to find some better website tho lol

stuck fractal
#

@proven bridge ๐Ÿ‘€

proven bridge
#

Didn't mean to paste that lol

#

You're so quick

stuck fractal
#

I'm not allowed to make a comment there

proven bridge
#

Was going to say, if anyone is struggling with the "The Impossible Challenge". Big hint, The answer is literally on the room page and requires no bruteforcing.

#

If you need further help, just ping me. I'd like others to learn this.

vivid scaffold
#

hi i'm doing the wirehsark CTF's room and i'm stuck at the last question Extract the RTP stream. What is the audio file from? I extracted an audio file with a boy yelling but i don't know what to answer

wary ocean
#

Haven't solved that yet, could be something with steganography?

#

Could be sstv

stuck fractal
#

Unlikely if it's a voice ๐Ÿ˜‰

wary ocean
#

Fair

#

You could try checking the spectogram

vivid scaffold
#

forget about that

#

thnx

#

it's not stego it's wireshark task

deep girder
#

i just need some sort of small hint

wooden mist
#

try including the dog/cat in a different place

dusky vigil
wary ocean
#

Unfortunately due to the nature of the Kali Machine, bookmarking would be completely pointless

odd void
#

The kali machine that you need a web browser to access?

#

That one?

wary ocean
#

When I have the chance I want to write a bash script to send post requests in a loop with a delay to keep the box alive and just have that running in the background forever

deep girder
#

@dusky vigil did yoiu try every method on the link?

#

and if not how did you pinpoint the right one to use

wary ocean
#

gtfobins is also pretty nice

#

Check sudo -l and find / -perm /4000 2>/dev/null for it

deep girder
#

i watched the start of your video writeup cause i was so stuck and there is no way in hell i wouldve done that /cat/../

#

and you did it so easily

peak girder
#

@wary ocean why... just get a 2nd hand laptop/desktop... set kali on it and you're done, it doesn't need to be THAT heavy/expensive or a VM

desert bramble
#

Can anyone see what is wrong with this /etc/passwd entry? i got the previous question right where i had to type out the entry and i just pasted it in and it says no password for user new. The hint is to escape the $ so i removed them and nothing happened

inland onyx
#

@desert bramble it won't be helping that you've not set a home directory, or gid, by the looks of things

echo thunder
#

anyone can give a hint for Ironcorp challenge?

azure nova
#

How do I transfer a file from local machine to a windows machine that I have a shell of?

true sundial
#

scp or ftp maybe?

next glen
#

hey guys, can I get help for christmas cyber advent, the one where I have to do privilege escalation. Whatever I do, when I run "whoami" all I get is "igor" and never "root"

#

although the suid bit is set as root

#

if the command/file is owned by root, why do I get igor instead??

#

I'm going crazy over here..

#

I was able to cat the first flag, since it is owned by igor

echo thunder
#

any hint on tempus fugit durius. I get the first shell when trying to upload file

echo thunder
#

anyone completed tempus fugit durius?

patent token
#

There's no need to ask multiple times, especially when your first request was also the last comment posted.

If someone is around that has done it and is willing to help, they will. ๐Ÿ™‚

wise basalt
#

Can anyone help for the Innoculation Room ?

dusky vigil
#

Ask your question not for help

wise basalt
#

alright sorry where can i ask for hints or any nudge when I am stuck in any room?

dusky vigil
#

Youโ€™re in the right channel but just say what you need help with

wise basalt
#

I need help on how to abuse the webhook I researched on data exfiltration using webhook but nothing worked. So am i missing something

sand grotto
#

hhi

glossy basin
#

hello

#

do you have any questions?

sand grotto
#

yes

#

how can i hide payload

#

@glossy basin

glossy basin
#

where?

#

on the target machine?

sand grotto
#

me ?

glossy basin
#

yeah

#

where do you want to hide the payload

zinc plume
#

can i get a hint where i can get the password for shiba3 in the learn linux room?

stuck fractal
#

from the binary

#

Solve the challenge that the binary is checking for

#

Then run it

#

Then you get the password

final lark
#

The Impossible Challenge Hint?

#

I dont know what those abcd's mean which are above the question

#

Please mention me while answering

zinc plume
#

Then run it
@stuck fractal cant im getting this "segmentation fault (core dumped)"

mild apex
#

Hi... I got stuck for a while i the learn linux room... the room was explaining su command, and after that came question: How do you specify which shell is used when you login?... Could someone help me where to look for this? Thank you

zinc plume
#

Hi... I got stuck for a while i the learn linux room... the room was explaining su command, and after that came question: How do you specify which shell is used when you login?... Could someone help me where to look for this? Thank you
@mild apex google it

stuck fractal
#

@zinc plume then you haven't satisfied the condition

mild apex
#

@mild apex google it
@zinc plume Hi... thanks for answer, I'm trying to but i'm not sure if I don't get the question... I try to look up how to change default shell none of the commands have two characters

zinc plume
#

do you want the solution to the question?

mild apex
#

do you want the solution to the question?
@zinc plume I found only ps and $0 ... I guess I could use the answer since this is coming to a dead end for me

thin bison
#

you can enclose an answer in || so you can put it in a spoiler

#

fixed

mild apex
#

oh so it was a part of su command ... thank you

stuck fractal
#

@zinc plume don't post answers.

brittle kite
#

Guys, I'm stuck on flag11 for Linux Challenges. I've found the place where aliases are stored, but when I cat .bashrc in the /home/garry directory there's no flag11 alias nor is it in the cat bash.bashrc in the /etc/ directory... Am I missing something?

neon zenith
#

any hints for impossible room

inland onyx
#

@brittle kite Try a different user

brittle kite
#

Nevermind, I had a brainfart that worked out for me ๐Ÿ˜„

inland onyx
#

@neon zenith Try decoding the hint?

brittle kite
#

I've been stuck on it for days, and now it suddenly came to me

neon zenith
#

@inland onyx yea being trying figure out what that thing

#

the room said it's crypto

inland onyx
#

It is

#

Nothing unusual -- just some common techniques needing applied in a particular order

neon zenith
#

alright, thanks for info. i try googling for that

white salmon
#

I'm currently on 'Cod Caper' task 3 where it asks you to run gobuster - which I am doing but all I get back is pages and pages of what look like links to things. It doesn't matter what extension I use .php, .txt, .html it all comes back the same? Is this correct or am I doing something wrong. If it's the latter any hints?

#

**sorry I meant to put the pic as 'mark as spoiler'

patent token
#

Anyone who's finished Anthem have a hint? I've successfully RDP'd to the machine, done what the hint suggests, however I cannot see the object necessary. Am I blind?

past night
#

@patent token very likely

patent token
#

I don't see how honestly. ๐Ÿ˜

past night
#

what does the hint suggest

patent token
#

I've unhidden everything i can find.

stuck fractal
#

๐Ÿ‘“

past night
#

what locations did you check

patent token
#

I mean, I ran unhide on the entire machine

past night
#

o.o it's a tickbox

patent token
#

Yea, I've been doing that too.

past night
#

it's in the most obvious location

patent token
#

This be why I dont CTF

steady stratus
#

You will truly kick yourself

past night
#

you'll facepalm

patent token
#

Yea, not getting it unfortunately.

past night
#

just look at the most obvious location

#

it's easier in the file explorer

patent token
#

I've been in the file explorer for two hours.

past night
#

i think you are definitely looking in the wrong place

#

if you need more dm me

patent token
#

I'm not sure how. I've gone through no less than 10 different directories now looking for whatever it is I'm supposed to find.

#

I'm manually unhidden everything. Tried changing perms. All of it.

past night
#

it's easier to just message me, i can give you a better nudge

white salmon
#

On anthem: I feel this is right in front of me but do we || use solomon/jane's login to the box or bruteforce the password?||

stuck fractal
#

@white salmon If you have creds, try them

#

You should always try before asking

white salmon
#

True. Just a sanity check while I was resetting my vm

woven pumice
#

About[Room:HackBack 2019,[Task 4] [Web Exploitation] [Medium] Jurassic Park,
#5 Locate and get the first flag contents.]

I log in as dennis and find "flag1.txt".
submit "b89**********************f",but dennied

Does anoone know how to solve it?

upbeat elk
#

I'm on the last question of bpvolatility. Uploading the files to hybrid analysis and virustotal isn't much help to answer that last question, I've gone through it like 5 times. I see the malicious files, but nothing comes up that fits the 6 digit requirement for the question. Any help?

upbeat elk
#

Nvm, I found it. Hybrid and VT were pretty useless.

restive kestrel
#

can i pm anyone on where to look for the hidden file/folder in the anthem room?

#

been digging around for 1 hour already :/

wary ocean
#

Sorry I haven't done it yet

final lark
#

@restive kestrel Same here

tidal sedge
#

@woven pumice I've already reported this bug, I believe Dark is working on fixing it.

shy sinew
#

Need help in Anthem room task 1 ques no. 7 ??

wanton shuttle
#

@shy sinew look at the poem and hints

shy sinew
#

And ques 8 ??

wanton shuttle
#

try to find clues look at hints

shy sinew
#

Thanks buddy

shy sinew
#

I'm unable to get the initial acces to the machine TASK 3 ques 2?

past night
#

reminna or whatever rd you use

shy sinew
#

Username password didn't working?

past night
#

it does?

shy sinew
#

Username password is same as for cms login ?

past night
#

have you tried?

final lark
shy sinew
#

Yes I tried

past night
#

read the tasks carefully

#

otherwise you'll complicate stuff you shouldn't

shy sinew
#

I have given the usrname the email of admin and password found in the TASK 1??

past night
#

read the task, you are complicating it

shy sinew
#

Can u pls give hint

#

??

past night
#

i already gave you a pointer. read the task carefully

viral mason
#

@past night any nudges on this hidden file??

past night
#

i think you might be overlooking it

#

it's in the most obvious locaiton

viral mason
#

Most obvious.. let me see

warm schooner
#

For anthem?

past night
#

yes

warm schooner
#

Look at hidden files in Windows if you haven't already then the flag will be obvious ๐Ÿ™‚

viral mason
#

Look at hidden files in Windows if you haven't already then the flag will be obvious ๐Ÿ™‚
@warm schooner i'm looking at the hidden files since the beginning

#

but couldnt find anything

past night
#

as i mentioned before. it's easy to overlook as it might resemble something else

warm schooner
#

@past night, did you have to change the files ownership when getting the flag?

past night
#

the flags have permissions by the user

#

but he's stuck between user and admin where there is a catch to it

unborn spade
#

Just finished that room, and all I can tell you @viral mason is do a little research

past night
#

what makes you think it's not it?

unborn spade
#

improvise, adapt, overcome

viral mason
#

@past night clearly i didnt think changing them perms would work lol

#

i got it thanks

past night
#

hehe loool

final lark
#

@viral mason Can i DM you?

#

@warm schooner I also see a file but i dont have permission to open it. I dont know what to do

warm schooner
#

@final lark open the properties and go from there

final lark
#

Yes i did but....

#

Can I DM you If I get stuck?

warm schooner
#

@unkempt surge don't just DM please, ask here first

#

@final lark go for it ๐Ÿ™‚

final lark
#

Okay

viral mason
#

@final lark sure

burnt cosmos
#

When you say "hidden", do you mean with the hidden property? Or hidden in another file?

#

I've been wracking my brain over which it could be for the past 20 minutes

warm schooner
#

It's not visible

viral mason
#

I've been wracking my brain over which it could be for the past 20 minutes
@burnt cosmos think simple, it's just hidden

#

what does hidden mean to you

burnt cosmos
#

Not visible

viral mason
#

yeah

#

so, how do you see files which are not visible

burnt cosmos
#

By ticking "hidden items"

viral mason
#

there you go buddy

round fog
burnt cosmos
#

@round fog My scans for that box were super weird, i ended up running it with just one parameter, try it without the T5

round fog
warm schooner
#

@round fog what room?

round fog
#

I've tried a lot of different scans and still no information

#

Network Services

#

^ room name

burnt cosmos
#

@viral mason Yeah the answer was staring me square in the face! Thanks for the help

#

Try running, just an aggressive scan

warm schooner
#

@round fog, which task as you can deploy multiple VM's

#

Task 6?

burnt cosmos
#

He's doing telnet enum atm

round fog
#

Yes Task 6 @warm schooner

viral mason
#

@burnt cosmos np bud

white salmon
#

@round fog the answer isn't in the NMAP scan.

#

It's asking what you think you could use the port for - when people look for ways into systems they find something..

warm schooner
#

Your nmap results are correct ๐Ÿ™‚

#

It's just the 1 port

white salmon
#

It got me for a bit until it clicked.

round fog
#

Ok thank you @white salmon and @warm schooner !

white salmon
#

Have you got it?

round fog
#

not yet ๐Ÿ˜„

wanton shuttle
#

guys any help regarding anthem finding admin password

white salmon
#

Ok - want a clue? @round fog

wanton shuttle
#

i have been searching for a long time

round fog
#

Sure @white salmon ๐Ÿ˜„

white salmon
#

So as I said above, you are looking for a way into the system, admins & creators sometimes leave them these things in so they can get back in anytime. It's something that you have on your house.

#

๐Ÿ˜‰

#

It's a bit of an obscure question as it stumped me a little.

#

But I kicked myself when I got it

round fog
#

Thanks @white salmon I've got it. No idea how I would've figured it out without your hint.

white salmon
#

I was the same.

#

Like I say it's a little obscure.

round fog
#

yeah

shy sinew
#

@round fog u got the answer for what that port is used for ??

round fog
#

Yes @shy sinew

shy sinew
#

Actually I didn't find it

round fog
#

@shy sinew Check the DarkFighter's hint

#

So as I said above, you are looking for a way into the system, admins & creators sometimes leave them these things in so they can get back in anytime. It's something that you have on your house.
@white salmon This one!

shy sinew
#

Got it

fresh kelp
#

Iโ€™m on the same question and finally got the answer

#

Thanks for the help guys

#

Also do you not think they *s are a little off putting

#

Since they say the format is like โ€œ* ******โ€

round fog
#

It depends on your answer actually

#

because i've used all the *

fresh kelp
#

My answer was only 8 letters long though

#

And it asked for 1 letter then space then 9 letters

round fog
#

but i've noticed that sometimes if a miss spell something the answer is still correct

white salmon
#

@shy sinew Do not DM me unless you ask my permission first - I think you need to check the rules.

#

@shy sinew What is the issue you are having?

shy sinew
#

Ohkk

white salmon
#

What exactly is the problem that you are struggling with?

shy sinew
#

help me ROOM Network services TASK 4 ques 4

white salmon
#

Have you connected through smbclient to the box?

shy sinew
#

Yup

white salmon
#

So what do you see that might help you?

#

There should be something that stands out?

#

See it?

shy sinew
#

A .TXT file

#

And few Directories

white salmon
#

Ok so the name of the txt file should be shouting to you, so what do we need to do in order to view the file?

#

If your stuck I'd suggest using the help command in smbclient - the answer is in there.

spark monolith
#

Can anyone help me to find Q3 in uopleasy CTF ? , I am not able to understand the question

white salmon
#

Got it yet @shy sinew

shy sinew
#

Not yet

white salmon
#

We need to put the file on our local system so we need to use a command that would do that - think about downloading - there is a command.

#

It's not put.

#

It's the other...

steady stratus
#

^

fresh kelp
#

@round fog by any chance have you got to the question about the ping command?

shy sinew
#

Ya I tried it but error is coming file not exists

steady stratus
#

a bit of googling will help out wonders ๐Ÿ™‚

white salmon
#

^^

shy sinew
#

Object name not found opening r.......

white salmon
#

Ok, so there is something that we can add to the command to select all files rather than the one that you want.

round fog
#

@fresh kelp Make sure you've read the whole question

white salmon
#

^^^^ I got stuck on that - you need to READ the whole question.

fresh kelp
#

I thought I did but Iโ€™ll give it another once over

white salmon
#

How are you getting on @shy sinew

shy sinew
#

Ya got it

#

Thanks a lot

white salmon
#

Glad to hear it

steady stratus
#

Good job :^^

fresh kelp
#

Unfortunately Iโ€™m still not sure what Iโ€™m doing wrong

#

Since I think I have the correct syntax for everything

white salmon
#

You're adding the .run to your ping command right? Think about where it needs to be?

steady stratus
#

Whatโ€™s the syntax that youโ€™re trying

white salmon
#

*preface it..

fresh kelp
#

Yeah Iโ€™ve got the .run

white salmon
#

But where have you put it in your command?

fresh kelp
#

At the start of the ping command

#

Does the ping command need to be in quotes?

white salmon
#

No.

#

so .RUN ping <blah blah> if you have that command then you need to check your netcat session?

round fog
#

try running .HELP

fresh kelp
#

I was using quotes...

#

So I got the answer

white salmon
#

Congrats

fresh kelp
#

Thanks for the hints guys

white salmon
#

No worries.

fresh kelp
#

Much appreciated

white salmon
#

If you get stuck give us a shout

#

brb need to sort something.

jagged raft
#

Hey bois, was wondering if someone could nudge me in the right direction on the flag task in linux walkthrough, very final one

steady stratus
#

All you need to solve it is within the task ๐Ÿ™‚ thereโ€™s a certain use that owns an interesting file. How do you search for files by who owns them? (rhetorical) ๐Ÿ™‚

jagged raft
#

Thanks, I'll keep lurking โค๏ธ

steady stratus
#

Itโ€™s not exactly a traditional privilege escalation ๐Ÿ™‚

vague moat
#

Hello, I am stuck at the ccradare2 final challenge

#

Any hints to guide me?

white salmon
#

@steady stratus have you done Cod Caper?

steady stratus
#

Yess! @white salmon

white salmon
#

Mind if I DM you a sec, just need advice on one answer?

steady stratus
#

Go ahead ๐Ÿ™‚ I might take a minute or so to reply but sure!

night cave
#

@vague moat What's up?

zinc plume
#

Hi guys i need a hint for the Hydra Challenge, where do i get the RockYou.txt?

past night
#

/usr/share/wordlists/rockyou.txt

zinc plume
#

thank you

forest token
#

Stuck real hard on this struggle bus for Anthem searching for admin password (unhid files within explorer...) searched all folders within the user I'm logged in as.... a nudge would be greatly appreciated - DMs are open to all

past night
#

it's in the most obvious location

forest token
#

hmm can I DM you Chevalier

zinc plume
#

"What flag deletes every file in a directory?" im stuck i thought it would be "rm *"

stuck fractal
#

@zinc plume That's the current directory, and not a flag

zinc plume
#

ohh yeah thx

stuck fractal
#

man rm

past night
#

@forest token sure

white salmon
#

can I have a hint for for the new Anthem box? ||I dir'd all hidden files but nothing shows up||

past night
#

it's in the most obvious location

patent token
#

I disagree. ๐Ÿ˜›

past night
#

hahaha, that's not true

stuck fractal
#

You're the creator

#

I think there's some bias there

past night
#

yeah, i know. it's easily overlooked, that's why i am saying

ashen plover
#

if you have not found it maybe your over looking something and should take a step back up

dusky vigil
#

it's in the most obvious location
@past night I can back this up

#

It's very obvious, it may seem like you can't do anything with in there but you can