#room-hints

1 messages · Page 26 of 1

ashen plover
#

^^

white salmon
#

haha found it 🙂

blazing turtle
#

that box annoyed me so much with the admin name... i was googleing anthem, the cms, post authors...

#

and then when i saw the thing, i didn't even need google 😦

past night
#

haha, i'm sorry

dusky vigil
#

Was a nice little thing to have in there. If I hadn't watched Gotham I wouldn't of got that at all

blazing turtle
#

it was fun when it wasn't annoying, so you did a good job

#

i knew it from a movie

past night
#

the accountant @blazing turtle

blazing turtle
#

yeah, great movie

past night
#

^^

white salmon
#

I found the name in || a config file on the box ||

pine ermine
#

It's very obvious, it may seem like you can't do anything with in there but you can
@dusky vigil Soooo even though I can see a hidden dir with file, I can't open it. But you say you can somehow view the content of that file?

steady stratus
#

Indeed you can 🙂

pine ermine
#

Hmmm, okay 🙂

white salmon
#

I'm still trying Tempus Fugit Durius, got on the box

steady stratus
#

Once you find the file it’ll be fairly intuitive as to what you need to do to open it @pine ermine

dusky vigil
#

@dusky vigil Soooo even though I can see a hidden dir with file, I can't open it. But you say you can somehow view the content of that file?
@pine ermine think of misconfigurations

white salmon
#

do I do a docker thing?

#

i got the first flag

spring ember
#

I've rooted Anthem but cannot for the life of me find flag 4. I might be blind

#

^ Scratch that, got it. Very sneaky

dusky vigil
#

ah yes flag four

#

you probably over looked it, it's similar to one of the previous

spring ember
#

I definitely did. just found it 🙂 Fun room!

marble dagger
#

anyone wanna hint me with anthem task 3.3? I'm tunnelvisioned it seems. I'm looking for hidden, but still can't see it ...

dusky vigil
#

You've likely overlooked it

#

You'll see something that sticks out which may have a misconfiguration

marble dagger
#

I looked at so many dirs and files. I just can't see it. maybe I just don't get the "most obvious location" thing 😦

spring ember
#

It definitely stands out, you'll know when you see

pine ermine
#

Thanks also, @dusky vigil @steady stratus - I really should brush up on Windows. Somehow I keep skipping those boxes

steady stratus
#

It’s very easy to skip to Z rather then going through A->B->C for sure 🙂

dusky vigil
#

I looked at so many dirs and files. I just can't see it. maybe I just don't get the "most obvious location" thing 😦
@marble dagger remember it's hidden

marble dagger
#

@dusky vigil yeah I ricked that option. and looked into those dirs. but maybe not hard enough

steady stratus
#

You might be looking too hard

dusky vigil
#

Try avoid over complicating it

marble dagger
#

yeah I tend to overcomplicate things 😄

dusky vigil
#

It's easily done

past night
#

like you've done it on stream

#

you can't imagine how much fun i had

zinc plume
#

wich wordlist should i use for gobuster (vulvuniversity)

dusky vigil
#

I've been known to overcomplicate boxes

stuck fractal
#

@zinc plume dirb common, dirb big, dirbuster lists

#

Try a few

#

Shorter first

zinc plume
#

aight was going straight to rockyou

stuck fractal
#

@zinc plume Rockyou is not a directory wordlist

#

It's a password wordlist

#

passwords are very different to directory names

dusky vigil
#

SecLists/Discovery/Web-Content/big.txt is also really good

zinc plume
#

man it hurts how much time i wasted

stuck fractal
#

SecLists is also really good
FTFY

steady stratus
#

Time learning isn’t time wasted

zinc plume
#

Well thats true

steady stratus
#

🙂

zinc plume
#

i just wished i knew this site earlier

steady stratus
#

Aye hehe. Glad you’re enjoying the content!

zinc plume
#

hell yeah i joined yesterday

steady stratus
#

Sweet - welcome! There’s plenty of free content to keep you busy at the very least 🙂

marsh violet
#

Regarding Anthem box. On Task 1 - #8 it's asking for email address of the admin. I have one address but doesn't work. I've tried also using other things to find it but can't seem to find the right one

#

there is only one address that is on the blog for the CV

#

could I get some hints from you peeps to find it?

short sphinx
#

@marsh violet check the hint button

white salmon
#

i didn;t find it either so I hydra it with a custom wordlist

marble dagger
#

and i'm also ashamed bc I'm still stuck on finding that "hidden" file on anthem. only a small hint maybe? I know it maybe hard without giving too much away

white salmon
#

you can search discord history

spring ember
#

@marble dagger start from the top

steady stratus
#

Start from the top ^ and take the given hint from the room quite literally :>

marsh violet
#

@short sphinx I don't really like doing that

marble dagger
#

@spring ember @steady stratus searching history here was the first thing I did actually 🙂 but well I'm slow. and yes I did start from the top. but one "obvious" thing I can't seem to be able to access

spring ember
#

@marsh violet What's the pattern for the address?

steady stratus
#

Well try and get access to it @marble dagger 🙂

marsh violet
#

forget what I said. I'm a f*cking idiot

spring ember
#

🙂

#

@marble dagger can you let yourself in?

marsh violet
#

it was right in front of me this hole time. Just saying, question #7

marble dagger
#

@spring ember with the password i don't have yet ... I just not used to windows boxes ... maybe I should try tomorrow again

spring ember
#

@marble dagger might be super easy when you come back with fresh eyes but you can do what you need with your current account

#

Think about why you might not be able to access that file?

marble dagger
#

@spring ember well I think I can't access it because it is owned by admin ... oh and now the vm died on me ... again. maybe thats a sign I should stop 😄

#

WOW ... I got it ... should have looked at the permissions earlier ... damn 😄

spring ember
#

ayyyy

#

Congrats! 🥳

quiet musk
#

Was going to say, if anyone is struggling with the "The Impossible Challenge". Big hint, The answer is literally on the room page and requires no bruteforcing.
@proven bridge

Can I DM you with a question?

inland onyx
#

@quiet musk What's the question?

quiet musk
#

Is the room graphic part of the challenge?

light galleon
#

ok @white salmon may i get one hint thats gonna point me in a right direction 😄

stuck fractal
#

Look for files belonging to each and every user

#

One of them has something suspicious

#

Use find

light galleon
#

just did that hahahah

#

ok thanks

arctic kiln
#

how can i find the first flag

#

of Anthem VM

short sphinx
#

@arctic kiln must be there, somewhere in the website

#

do you find the others?

proven bridge
#

@proven bridge

Can I DM you with a question?
@quiet musk Of course

light galleon
#

@stuck fractal numbers from 1-1000? 😄

stuck fractal
#

Not that one

light galleon
#

kk

#

its irelevant?

stuck fractal
#

I think so

light galleon
#

@stuck fractal i made this it will maybe help me find it 🤷‍♂️

#

its better now

arctic kiln
#

@short sphinx yes i find the others expect the first flag

zinc plume
stuck fractal
#

@zinc plume You put an asterisk for the login name

zinc plume
#

i thought it is the username

#

for /login

stuck fractal
#

user-agent is a browser thing

zinc plume
#

ohh i thought its a username

#

okay thx

short sphinx
#

@arctic kiln you will find it in the same way, maybe check for THM while loking for it

zinc plume
#

but what am i supposed to do with the file fsocity.txt? Isnt it a passwordlist?

stuck fractal
#

It could be

#

but you'd need a username or list of usernames

zinc plume
#

okay

light galleon
#

@stuck fractal Update : i got the password for the noot account but i think thats a false update 😄

stuck fractal
#

Maybe the new users have more power

light galleon
#

hmm yes

#

nope

#

sadly

stuck fractal
#

Hmm, what about listing sudo permissions?

#

sudo -l

#

Good command to learn

light galleon
#

yea did that

#

i like just typed su noot

#

and like guessed the password to be noot

stuck fractal
#

Well, maybe there's other users

light galleon
#

ill try to find the password for the nootnoot acount

stuck fractal
#

Keep looking for files

light galleon
#

on it chief 😄

#

im on the right track

zinc plume
#

i have found ||ZWxsaW900kVSMjgtMDY1mgo=|| thats not a key tho, is it decrypted or what am i should i do?

steady stratus
#

It’s encoded @zinc plume

#

Investigate what that = at the end could mean 🙂

cloud perch
#

Has anyone done the new room anthem

inland onyx
#

Plenty of people -- best just asking

cloud perch
#

I'm stuck on task 7 what's the administrator name can you give me a hint besides Google

inland onyx
#

There are three tasks?

#

Oh

#

Task 1

#

Question 7

cloud perch
#

Yup

inland onyx
#

Yeah, use what you're given on the site. It's a "social engineering" style one. You've got to extrapolate from the data you've been given

cloud perch
#

I'm so confused sorry I've been up all night working and once I got home I decided to study up on this

zinc plume
#

Investigate what that = at the end could mean 🙂
@steady stratus i have no idea i only found Base64

inland onyx
#

@cloud perch The administrator's name is not on the website. You've got to use what you've been given to guess what it might be -- same with the email

#

You know that he's got a poem dedicated to him -- there's a name related to that poem

sinful garden
#

It's not directly on the website

steady stratus
#

That’s right - whether or not it’s of any value you’ll have to figure out @zinc plume

zinc plume
#

aight

steady stratus
#

The = or == is padding and is a really good way of identifying base64 (although not all base64 encoded strings have padding)

cloud perch
#

Got it thanks poem I new something was funny about that poem

steady stratus
#

Nice one!

past night
#

hehe

#

i love to see people struggle

cloud perch
#

It's funny cause I checked everything I spent an hour trying to figure it out. The funny thing about it is when I first started on this room and saw that poem. I said to my self that this poem might come in handy but totally forgot about it.

#

@past night it's the only way we learn right?

#

Lol

zinc plume
#

does it matter if im using Hydra and the text "Username" isnt in the usernamebox , or do i have to use user_login?

#

bc when i run hydra i get like 20 pws

stuck fractal
#

I don't understand what you're asking and hydra is like second nature to me

#

You're probably getting 16

#

And that means it can't detect the failures correctly

zinc plume
#

yeah i kinda tought so too but i put F (for false) as F=incorrect so it should work

stuck fractal
#

That doesn't mean it can pick up that it's wrong

zinc plume
#

also im getting the error that the pw is incorrect

#

oh okay

zinc plume
#

okay thank you

wooden mist
#

anyone here did the very secure protocol chall on hackback2? not sure if I understand the task well
The hashed PSK is 32 bytes. No password file has strings this long. If you find a password file(rockyou.txt), make sure the minimum length is 32 bytes(do this by copying the same string until it is 32 bytes).
this tells me that the PSK hash is 32 bytes but not sure if i need to repeat the string until it's 32 bytes too thonk

light galleon
#

@stuck fractal you here 😄

stuck fractal
#

👋

light galleon
#

ok im stuck like i went thru every file

#

cant find it

#

hint

#

pls

stuck fractal
#

One of the users has a file that should have interesting content

#

username:password is a defacto standard in infosec

light galleon
#

ok but its not in the /proc files right?

#

username:password is a defacto standard in infosec
@stuck fractal ^^

stuck fractal
#

/proc is for internal stuff

light galleon
#

so its not there right?

stuck fractal
#

find / -user userNameGoesHere 2>/dev/null

light galleon
#

ok so i am trying to find a file thats owned by someone and that file has username:password

stuck fractal
#

All files are owned by someone

#

even if that someone is nobody

light galleon
#

yea but by someone i mean like one of the users

#

what does 2>/dev/null do

#

wait how do you do that other kind of formating

#

on discord

stuck fractal
#

backticks

#

2 is standard error

#

> is a redirection operator

#

/dev/null is THE VOID

#

Basically, send all error messages to the void

upper solar
#

Hello everyone

light galleon
#

oh ok tnx

cloud perch
#

Damn stuck again on anthom

#

I've never messed with this type of cms

inland onyx
#

You don't need to touch the CMS

final lark
#

@cloud perch What happened?

#

@inland onyx Yea

past night
#

nah, only if you want to see how it feels using that CMS

#

but you got nothing hidden behind it

cloud perch
#

@final lark trying to figure out how to get into the server. I try doing rdesktop with the same creds as the admin. No luck.

final lark
#

@cloud perch You can DM me & we can discuss more

viral mason
#

any tips on racetrack bank on transacting an huge amount of golds? i've been trying to manipulate the request as ||?success=Success!|| , at the end i get ||Success!|| but nothing happens. am i in correct way?

inland onyx
#

No

#

Clue is in the title

viral mason
#

So does it related with directly purchasing the gold?

inland onyx
#

Nope

viral mason
#

Ok i guess i need to enumerate more, thx Muirland ❤️

wraith marsh
#

it’s probably more about knowing the attack, like Muir said the title is a big clue.

viral mason
#

@inland onyx @wraith marsh ||race condition|| maybe 👀

wraith marsh
#

If you get stuck, owasp is your friend.

viral mason
#

thanks @wraith marsh

stuck fractal
#

No spoilers

light galleon
#

i tagged it as a spoiler

#

didnt i?

stuck fractal
#

Still

#

Don't post passwords etc

cloud perch
#

Done with athem thanks for the hint guys

viral mason
#

i think getting shell could be harder along with this frustrating gold step.. @wraith marsh

vestal igloo
#

With Daily Bugle I got a reverse shell as ||apache|| is there something I can do with that or should I find another way in?

inland onyx
#

Yeah, keep enumerating @vestal igloo -- that shell is the way forward

vestal igloo
#

thanks

cloud perch
#

@vestal igloo yeah that box was a little hard for me at first

#

@vestal igloo if you need a hint I'll give you one

wicked sluice
#

hi can i get a hint on task 3 for the anthem box im having issues figureing out what the username and password to login into the remote desktop can anyone point me in the right direction i think i over looked something but for the life of me i dont know what it is

short sphinx
#

@wicked sluice use the info you get so far

wicked sluice
#

ok i must be over thinking it lol

short sphinx
#

try some logins with the info you get from the other task

wicked sluice
#

ok ty @short sphinx

short sphinx
#

it help thinking what credentials someone will assign for these people

tribal ginkgo
#

stuck at anthem flag 4

#

i think i inspected all the pages

obtuse charm
#

@tribal ginkgo Did you look at pages which aren't for humans? If you know what i mean.

#

Can anyone give me a nudge on flag 7(name of admin) of Anthem? i crawled the website, but couldn't find anything, Using dirbuster gives me false positives,

tribal ginkgo
#

read the blogs

obtuse charm
#

did read them, tried both author names

shy sinew
tribal ginkgo
#

@obtuse charm content of the blog

shy sinew
#

What can be the username for ssh login ??

obtuse charm
#

@tribal ginkgo thanks, got it

shy sinew
#

Network services room

#

Anyone upthere ??

vestal cedar
#

hi any hints for this for hackpark

#

i tried running ps on meterpreter but seems i dont get an answer

shy sinew
#

Run PS command

tribal ginkgo
#

anthem spot the flag-> flag4 any hints

#

don't know which file i missed

shy sinew
#

See source code of all the pages

#

I have the key file but I'm not able to login through ssh ??
@shy sinew anyone help ??

tribal ginkgo
#

thanks don't know how i missed it before

#

anthem - rdp , I am using the credentials used to login to cms, but not working

obtuse charm
#

cms is hosted on a domain, rdp is not, does that make sense?

burnt cosmos
#

@tribal ginkgo Flag4 is similar to another flag you already have, and you already have the RDP login, just don't over-complicate it

obtuse charm
#

I have user.txt of anthem, but unable to find anything that could help me go further

#

Any hints , I've enumerated pretty much all interesting folders including the hidden files and folders

blazing turtle
#

the thing you're looking for is located in a very obviously named folder

obtuse charm
#

Should i limit myself to inetpub or search other parts of disk?

tardy beacon
#

Hey guys.

#

I am solving SSTI challenge from zthobscurewebvulns, I got root but there isn't any flag.🤔

burnt cosmos
#

@obtuse charm What you are looking for is hidden

obtuse charm
#

@burnt cosmos I'm looking for hidden files and folders as well, but nothing till now,

#

Maybe I'm enumerating the wrong directory

#

Currently enumerating the entire sg user folder

sweet relic
#

hey guys. is there a python module like exiftool?

glossy basin
sweet relic
#

thanks. i got it

vast moth
#

Check the meta data of webpages

anthem spot the flag-> flag4 any hints
@tribal ginkgo

#

search for poems "Born on a Monday,
Christened on Tuesday,
Married on Wednesday,
Took ill on Thursday,
Grew worse on Friday,
Died on Saturday,
Buried on Sunday." on the internet
Can anyone give me a nudge on flag 7(name of admin) of Anthem? i crawled the website, but couldn't find anything, Using dirbuster gives me false positives,
@obtuse charm

burnt cosmos
#

@obtuse charm What you're looking for is in plain sight, when you find the file you may have to do something else with it

burnt garden
#

On 25 Days of Christmas, Day 8 -~~ Privesc~~ hacking is super new to me, ||I managed to get a bash shell worked out that 'find' is controlled by igor using the assist doc. But I'm not really sure where to go from here, actually interacting with shadow is still denied||

#

Scratch that, got it, I should've just ||skipped gaining user and just opening the .txt||

white salmon
#

Good morning everyone. When I try to execute the Rejetto exploit on Steel Mountain room, it says "Exploit completed, but no session was created".

white salmon
#

Hey guys. I am new in this field and started going pratical. And i tried to do the cmess machine. So everything was going well. Discovered the admin password and tried a upload a reverse php shell from pentest monkey. But whenever I started listening connection in my Hacker machine. It couldn't connect i am stuck here

#

I put the correct lhost and lport

#

But netcat listening on other side doesn't get incoming connections

#

I think something is wrong with my netcat. I don't know the correct settings. I guess vm is blocking my incoming connection. I run in Bridge mode. Can someone please help me regarding this

#

I couldn't figure out

limpid vine
burnt cosmos
#

@limpid vine Have a look on the file system you end up in

#

You should find the remaining answer there

limpid vine
#

you just end up in / dir

#

and I think I have the username but I don't know the correct way to format the answer.

shy sinew
#

@limpid vine can u pls help me in ques no. 8 ssh login I'm unable to login using -ssh -i key file username@ip

#

But I don't knkw the usrname

#

*know

patent token
#

I'd refer back to question #4 if I were you.

shy sinew
#

I tried the same but it's asking password and @limpid vine managed to get the ques 8 without the ques. 4

fresh kelp
#

Hi would anyone be able to help me with the Tony the Tiger room?

#

In particular trying to get the shell

tidal sedge
#

@fresh kelp Just ask the question, don't ask to ask

glossy basin
#

@fresh kelp just use the exploit given in the materials

#

read about the CVE also

#

so you get the usage idea

#
  • you can always check the writeup to see how it's done
fresh kelp
#

I’ve had issue with the exploit in the task so I decided to use the jexboss.git repo

#

When running it I get the message “successfully deployed code”

#

But then it error outs and I get a attribute error

#

“None type” object has no attribute “groups”

tidal sedge
#

@fresh kelp What issues did you have with the first exploit?

glossy basin
#

can you also screenshot? i can't reproduce any error

steady stratus
#

the jexboss issue sounds like a python version issue - not totally sure with that exploit technique

#

But aye a screenshot would be useful 🙂

fresh kelp
tidal sedge
#

@fresh kelp A screenshot would be helpful...

fresh kelp
#

One sec I’m on my phone trying to log in into my laptop

steady stratus
#

The output of that tells you what’s wrong

fresh kelp
steady stratus
#

Look at the syntax it’s expecting

glossy basin
#

^

sinful plaza
#

Hello can any one give hint on the anthem room rdp username

inland onyx
#

@sinful plaza Lateral thinking. Use the stuff on the website to piece it together

sinful plaza
#

ok @inland onyx thanks

fresh kelp
#

Thanks for the help guys, I guess I was just looking at it all wrong. Took a break and saw my mistake

patent token
#

Is this Tony the Tiger?

tidal sedge
#

Looks like it

patent token
#

I don't remember using all of that extra stuff in my command.

zinc plume
#

(MrRobot)Im insite the Wordpress account as elliot, whats the next step do i have to interact with the pictures or switch to the other account bound to alliots account? (mich05654 her bio is another key?)

dusty pebble
#

Try to get a shell from there

wooden plover
#

check for wordpress exploits

#

Don't go for OSINT! It will be a rabbit hole

#

Mr.robot was an easy room

#

don't wander a lot

white salmon
#

# script.sh count port delay 

function main()
{   
   if [[ -z "$1" || -z "$2" ]]; then
      echo "Not all parameters specified"
      exit 1
   fi

   count=$1; shift
   port=$1; shift
   delay=

   if [[ -z "$1" ]]; then
      delay=$1
      shift
   fi

   for i in $(seq 1 $count); do
      echo "Iter: $i"

      nc -lvp $port &
      pid=$!
      sleep $delay
      kill $pid

      if [[ $i -eq $count-1 ]]; then
         nc -lvp $port
      fi
   done
}

main $@ ```
stuck fractal
#

#room-help since you're not asking for a hint please.

white salmon
#

Anonymous: I have all the files from 2 services but still can't find any user specific information. Any hint as to what to do from here?

proven bridge
#

Anonymous: I have all the files from 2 services but still can't find any user specific information. Any hint as to what to do from here?
@white salmon In one of those services there's a bash script that runs, it appears to be on a cron.

#

What should you do?

white salmon
#

I've tried now to edit the script, configure how it affects the log file, and still the same result. Any chance you can link a resource that could help?

verbal wedge
#

Why would you configure how it affects the log file?

#

It's a shell script that's running off a Cron job.

white salmon
#

@verbal wedge i tried overwriting the script but it doesn't seem to be running

verbal wedge
#

You can do whatever you want to it

#

What did you replace it with

#

Like what's the script

white salmon
#

nc connecting back to me

verbal wedge
#

Yeah there's a reason for that

#

There's another shell that will work

#

And it's not nc

white salmon
#

hm ok thanks

verbal wedge
#

Good luck!

white salmon
#

Hello community ! 🙂 I have a question. I am at the challenge in the "Intro to Python" room. Challenge gave me a text file named "encodedflag.txt". This is a multiple encoded file with base64, base32, and base16. I decoded the first time with base64 the given file. It gives me an output like this ->

b'\xdf}\xf7\xdf}\xf7\xdf}\xf7\xdf}\xf8\xdf}\xf7\xdf}\xf8\xdf}\xf7\xdf.......'

But I cannot decode this string by base64. How can i do that ? Anybody could you give me a hint ?

stuck fractal
#

Those are raw bytes. Implies you're doing something wrong

viral mason
#

so neither ||nc|| nor|| python rev-shells|| are working on this script @verbal wedge

stuck fractal
#

@viral mason Remember, python won't be installed on most ubuntu 1804 boxes

#

It'll be python3

#

And nc -e rarely works

viral mason
#

shit i didnt think of python3

stuck fractal
#

In summary

verbal wedge
#

There's others you haven't tried too

viral mason
#

let me try and i'll hit you in 5 mins because of the cron ¯_(ツ)_/¯

verbal wedge
#

Lol I should change that haha

viral mason
#

please man

#

please change it

white salmon
#

Those are raw bytes. Implies you're doing something wrong
@stuck fractal
I got what i am doing wrong 🙂 Thank you 🙂

wraith marsh
#

shit i didnt think of python3
@viral mason did you try bash ? 🧐 worked for me

viral mason
#

tried but i guess i did something wrong @wraith marsh

#

i guess i have to try another bash

south apex
#

I'm doing VulnUniversity but I'm a little confuse towards the end.
So, first, why should /bin/systemctl have stood out? Looking at the permissions on the other files around it look similar, is it simply because it's known to be able to be exploited for priv escalation?
Second, I'm pretty unsure what to do from here. I've never done a priv escalation before, so I don't really know what I should be doing. Do I use gtfobins? Usually to make a script on a remote session I'd use nano but that seems to be blocked, so I'm as little unsure what I should be doing

stuck fractal
#

@south apex You don't have nano because you're in a reverse shell

#

nano needs a proper shell, you can't even use the arrow keys

south apex
#

I see, I'd noticed the lack of bash history but didn't attribute it to that.

white salmon
#

systemctl runs with higher privilieges and it can be used to run arbitrary commands in a way

south apex
#

Okay so it is just something I need to know is easier to use to run arbitrary commands.

#

Thank you

stuck fractal
#

@south apex Yes use GTFOBins

south apex
#

Thank you

viral mason
#

i really was a dumbass, i got the shell @verbal wedge

hasty cobalt
#

unsure if this is the right room for this. Has anyone done the Shodan.io box? I have 2 tasks that I am unable to complete and im convinced its due to a change on shodan

south apex
#

I'm pretty lost still. How do I Get the exploit onto the box using a reverse shell?

stuck fractal
#

@south apex The exploit is a systemd service file, you can create a file.

#

And put content into it

south apex
#

I have a modifed systemd service that should give me a reversed shell with root, just unsure how to write the file without access to nano. Thank you for the direction to check. I'll follow through that since I'm not seeing how to make the file

stuck fractal
#

@south apex You can echo into a file

#

echo "string \> with \> multiple \> lines"

#

The shell will add the > when you don't close the quotes

south apex
#

I see thank you

quiet musk
#

@stuck fractal Can I DM you?

stuck fractal
#

@quiet musk Why?

novel topaz
#

Hey guys

#

I was an doing anonymous room

#

Is their any hints to get user.txt ?

south apex
#

I managed to get root. Thank you @stuck fractal
That's an awesome feeling.

viral mason
#

@wraith marsh is pe related with vim.basic?

#

or should i go for that ||cron which is executed by root||

wraith marsh
#

@wraith marsh is pe related with vim.basic?
@viral mason I found 3 ways to priv esc. there’s a much simpler way. Which happens to be the intended way

viral mason
#

hmm

verbal wedge
#

It's about to be only 2

#

Jb had a very unintended way lol

#

So I'm patching it haha

#

There isn't a Cron executed by root that im aware of

#

The Cron that's running the clean.sh is executed by namelessone

#

Root privesc is much simpler

#

No

#

Good on you for finding that

wraith marsh
#

Removed just in case, 😂

verbal wedge
#

Do you have an article for they other method?

#

I don't get it

viral mason
#

There isn't a Cron executed by root that im aware of
@verbal wedge i saw in pspy lol

#

uid was 0

wraith marsh
#

Yes, give me a minutes I’ll grab it and DM you if that’s okay?

verbal wedge
#

Aye

viral mason
#

Jb had a very unintended way lol
@verbal wedge free pentesting service lol

#

Root privesc is much simpler
@verbal wedge yea took a break i'll look on it

cloud perch
#

my new thumbnail for the new video coming what ya guys think yay or nah

viral mason
#

Seems nice dude

stuck fractal
#

@cloud perch Wrong chat?

viral mason
#

@verbal wedge can i pm?

verbal wedge
#

Aye but response may be delayed

#

trying to work out dinner

viral mason
#

okk

white salmon
#

hey 0x you got root?

woeful tide
#

Now I'm curious what the unintended way is

ashen plover
#

^^

viral mason
#

Now I'm curious what the unintended way is
@woeful tide its.. a little bit tricky

white salmon
#

do I really need to wait an hour in Anonymous?

stuck fractal
#

Probably not

#

||The thing is every 5mins||

restive kestrel
#

to anyone who has done the room anonymous

#

does privesc have to do with ||f||

viral mason
#

do I really need to wait an hour in Anonymous?
@white salmon its on ||each x5s and x0s||

white salmon
#

yeah I see it now

viral mason
#

does privesc have to do with ||f||
@restive kestrel what's f?

restive kestrel
#

ok nvm then if you don't recall f HAHA

viral mason
#

😄

#

yeah I see it now
@white salmon its a bit painful to wait that one

white salmon
#

it lost its +x somehow, fixed it

final lark
#

Whoever solved the box "Anonymous". How much would you rate it outta 10?

viral mason
#

@final lark 9/10 fun, 4.5-5/10 difficulty

final lark
#

Okay great !

#

I'll also solve it today

restive kestrel
#

ooh just finished the room, i think it's relatively easy

viral mason
#

good luck with that!

white salmon
#

as nike says, just do it

sharp mason
#

I'm doing the first lvl buffer overflow room(bof1). I'm trying to see what's happening in the code execution using gdb. The guide talks about looking at the values of registers like esp and ebp but when I look at the registers in gdb using the 'inspect registers' command all I see are registers that start with 'r'. Anyone know how I can view the esp edp registers?

viral mason
#

@restive kestrel yeah easy for a guy who is relatively experienced but medium for general as it stated in the box itself

restive kestrel
#

well if i can finish it i'd say it's easy HAHA

stuck fractal
#

@sharp mason ...you're not on ARM are you?

#

Oh, you're only seeing the general purpose registers

sharp mason
#

@stuck fractal thanks, I guess I need to specify the eax or esp etc registers I want to see. for whatever reason, all the guides I've found are showing the 'e*' registers by default when they run inspect registers

stuck fractal
#

@sharp mason those are the common ones

sharp mason
#

I need to read up on general vs common register types

stuck fractal
#

Common isn't a special word here

#

Common just means frequently used

sharp mason
#

gotcha

#

so I found there's also a gdb command info all-registers

#

surprised that the output still doesn't include any of the 'e*' registers that I'm looking for

stuck fractal
#

@sharp mason Hang on, you know x86 prefixes right?

sharp mason
#

the stack pointer and stack frame seem important, I think I'm missing something

#

I do not

stuck fractal
#

Is it showing you RSP?

sharp mason
#

yes

stuck fractal
sharp mason
#

is that equivalent to esp?

stuck fractal
#

RSP is 64bit ESP

#

RAX is 64bit EAX

sharp mason
#

ohhhhh

stuck fractal
#

AX is 16bit EAX/RAX

sharp mason
#

that's what I'm missing! Thanks @stuck fractal

stuck fractal
#

x86 is a mess.

sharp mason
#

lol, understood

white salmon
#

On anonymous room, ||idk what rev shell should i use, if i put like 3-4 line after line, one should execute and others should interupt anything, right? ||

late patio
#

@white salmon If you find the correct reverse shell it will work.

white salmon
#

as i thought, thanks

late patio
#

No problem.

white salmon
#

finally got anonymous, took me way to long

#

didn't even got root shell

patent token
#

I'm stuck on Root on Anonymous if anyone can lend a hand. I have a shell and the user flag. I've been looking at linpeas and other things, including the crontab. Not seeing anything specific.

ashen plover
#

@patent token for anonymous?

patent token
#

Yea, just realized I missed saying the room.

ashen plover
#

in your linpeas you should see something that will show you what you need to do

patent token
#

Ok. I'll take another look. I know I poked at it earlier and what I saw then doesn't exist now due to a patch I think.

stuck fractal
#

vim suid was fixed

#

That was an unintended

ashen plover
#

Yea but some other things should stand out

final lark
#

@ashen plover Hey, Can I DM you?

ashen plover
#

@final lark sure

patent token
#

||for instance, I see I'm in the sudo group, but naturally can't do much due to not knowing the user password.

I've tried /usr/bin/env, but again, no sudo no bueno.||

stuck fractal
#

I'm gonna have to try this box

patent token
#

I'm not a fan of CTF's, so the struggle is very much real.

inland onyx
#

@patent token You're in the right place there

#

With the command you tried

ashen plover
#

@patent token take a look at what you have and i would take look at GTFObins if your unsure of something

inland onyx
#

^^

patent token
#

I just keep getting requests for passwords.

#

¯_(ツ)_/¯

inland onyx
#

Don't sudo it then 😆

patent token
#

I just get the same user

#

I've tried this

inland onyx
#

What command are you trying?

#

||/usr/bin/env /bin/sh||?

patent token
#

That one as well

#

Thought I clicked spoiler.

inland onyx
#

Ah, yep. You're missing a switch

#

That will work

patent token
#

Ok one sec

ashen plover
patent token
#

I'm there.

ashen plover
#

type in what you wanna look up and see what they have done

patent token
#

||Just tried -p with no luck. I've tried -i as well.||

restive kestrel
#

skip the first line

patent token
#

I'm not sure what that means. I'm only using one line commands

restive kestrel
#

r u looking at sudo or suid?

patent token
#

lame. I can view the file with the command but can't escalate.

restive kestrel
#

worked for me tho

inland onyx
#

@patent token ||REDACTED -- NO ANSWERS ||

#

Try that

patent token
#

That gives me the same user

#

||Using env cat/root/root.txt gave me the hash.||

restive kestrel
#

u could always try to escalate another way via the lxd group

patent token
#

Seems like I should be able to do more than just that.

inland onyx
#

Curious. I just tried it on my own computer with the same conditions set

#

Worked for me

#

I know other people have managed it on that box

ashen plover
#

i had same issue once i reset my box it worked

#

but i was getting some major lag on that box so could have just not taken the command?

patent token
#

Guess I need to pay better attention

inland onyx
#

Hehe, that looks like a root shell to me 😁

patent token
#

Been sitting here root for 5 minutes. 😐

#

L2lookpassedthefirstUID

inland onyx
#

🤣

patent token
#

I don't CTF

inland onyx
#

whoami, then id

#

Best combination

ashen plover
#

lmao

patent token
#

I've been root since before I asked for help.

inland onyx
#

Followed by python -c 'import pty;pty.spawn("/bin/bash")

patent token
#

...

inland onyx
#

As an added bonus

patent token
#

Community Mentor too.

#

😐

#

Fired!

#

Thanks for the help everyone. ❤️

ashen plover
#

i usually go with whoami, upgrade shell then sudo -l as my first three but id is also a good one

patent token
#

I'm gonna get smoked on Linux when I take OSCP I guess.

#

¯_(ツ)_/¯

ashen plover
#

nah

#

its not bad

patent token
#

I'm an eCPPT. So I already have an actual pentesting certification. Just need to git gud at CTF

ashen plover
#

OSCP is not really CTF

#

it is in the sense of your gathering flags

stuck fractal
#

I've heard the opposite

ashen plover
#

they updated this year

stuck fractal
#

I've heard from people who've taken it recently that it's very CTF

patent token
#

Yea me too. I've never heard anything about it being anything close to lifelike.

ashen plover
#

actually have AD stuff in it now

stuck fractal
#

@ashen plover Nope

#

PWK has AD stuff

patent token
#

I have the materials. They completely lack context because it doesn't directly relate to labs.

stuck fractal
#

The exam does not.

ashen plover
#

well yea im not talking about the exam

patent token
#

It's just 800 pages of examples you can't practice.

stuck fractal
#

Then you're talking about PWK

patent token
#

Yea, PWK is not OSCP.

#

Or so I'm told.

#

¯_(ツ)_/¯

ashen plover
#

semantics.

#

the exam is slightly more CTF with certain things for sure. The course itself is okay

#

but I mean i dont take cert to take an exam so thats why I say OSCP is also PWK but sure you could argue both ways

#

The worst part about the exam is the proctors IMO they love bugging you during the test 😛 ruined my flow so many times

patent token
#

Anyways. Prolly should keep this channel for #room-hints. I've hijacked it enough. 🙂

summer wave
#

Any hint for Anthem username for connecting through RDP

patent token
#

You have the username already. 🙂

summer wave
#

but it doesn't work 😫

patent token
#

Need a bit more information about than what you've offered honestly. But if you are on Task 3 and answered ALL of the questions before that, I promise you that you have the username and password already.

summer wave
#

got it 😋

warm schooner
#

Any initial access hints for anonymous? on the ftp server, can edit and upload files but can't figure out how to get a rev shell

unborn spade
#

Ah yes. Love bash scripting.

echo thunder
#

anthem

#

sorry

humble mountain
#

how i can find the name of the Administrator on anthem chall :/? i got no idea

final lark
#

@humble mountain What was the thing mentioned about admin on the website?

tribal ginkgo
#

@humble mountain read the blogs

humble mountain
#

i found it, thanks @tribal ginkgo @final lark

desert bramble
#

Hi sorry to be a bother, but im struggling on this question a bit. Could anyone give me a hint on where to look.

#

this is common linux priv esc *

#

This is what i think it is based on the question but its doesnt match the amount of chars Echo /bin/bash > ls

#

But then the name of the executable is script so i must be well wrong

dusty pebble
#

you have two "chars" missing

final lark
#

@humble mountain That's Great!

desert bramble
#

you have two "chars" missing
@dusty pebble thank you so much! i thought those were just in the example i didnt know i needed them for the command!!!

dusty pebble
#

You're welcome, you will have to use quotes in a lot of commands

burnt cosmos
#

Working my way through the Shodan room and it's asking for the 3rd most popular country for MySQL servers in Google's ASN. A quick search reveals it should be ||Hong Kong (HK)|| but it doesn't seem to work. Any ideas?

past night
#

the room needs updating i think

echo thunder
#

anyone can give me a hint on how to find first flag on anthem challenge

#

?

woven pumice
#

@echo thunder you need to check the html source code

echo thunder
#

I have checked

#

I saw the flag

#

also on the other page get it

#

if looked on all the pages

#

tags,search, etc

burnt cosmos
#

Look through the website

#

You'll find all of them just by inspect the website

dusty pebble
#

i'm probably blind but i can't find it too, i have all the others flags except the first one

woven pumice
#

/archive/-------------/
check meta tag

summer wave
#

Any hint for admin password on Anthem

final lark
#

Hint says it is hidden. Therefore, see the hidden files. @summer wave

#

Don't go deep. It's easily accessible. Most obvious location & name.

summer wave
#

@final lark its been a day, i tried everything

dusty pebble
#

@woven pumice this is the 4th right ? Or i'm really missing something

#

@summer wave What have you done yet ? (spoil your response)

summer wave
#

@dusty pebble run gobuster and try to visit every page flag is in meta tag.

tribal ginkgo
#

@dusty pebble which one exactly are you stuck on

dusty pebble
#

@tribal ginkgo Just the first flag, i've done the rest of the box. I'm probably blind, i'll take a rest will gob is running as suggested and it should be good after 😁

tribal ginkgo
#

😆 its in meta tags

dusty pebble
#

Yup, it's probably in front of me x)

summer wave
#

@dusty pebble i m stuck on admin password i tried every hidden files stuff

tribal ginkgo
#

@dusty pebble search for pattern in source i

#

@summer wave that's a good one

#

😅

dusty pebble
#

@summer wave not every obviously, you're on the right way, you've probably found the file, just search how to read it

final lark
#

@umbral flint Try going to properties.

past night
#

i am still curious why people overcomplicate it

steady stratus
#

^

#

It's unintentionally a hard box ahah

dusty pebble
#

I feel so dumb, i've seen it 50 times, i was sure i already used it

steady stratus
#

I mean it's still good irrespective don't get me wrong

#

people just make it harder :^)

past night
#

should i put a disclaimer @steady stratus ? Like, do not overcomplicate it?

dusty pebble
#

Yup, right, i've spend few hours on this box, and now that i've finished it, i just make it a lot harder than it was, good box btw !

past night
#

thank you ❤️

#

much appreciated

dusty pebble
#

@past night Definitely x)

past night
#

i mean

tribal ginkgo
#

@dusty pebble right about that

steady stratus
#

Mhm I'm not sure, it seems like people get it eventually. Not quite sure how you can word it without spoling

past night
#

yeah, that folder name kekw

#

also

#

why do people look on linux for backups folders

#

but not on windows

steady stratus
#

I think they're taking the other meaning of "hidden" rather then the technical term for it

past night
#

looooool

steady stratus
#

But you can't really rewrite that other then using hidden 😛

steady stratus
#

Ahahaahahah!

signal needle
#

Quick question on Anthem, is the foothold obtained via Umbraco LFI? Or is a password attack required?

past night
#

none

wraith marsh
#

Neither

signal needle
#

:/

wraith marsh
#

Take a closer look at the open ports

#

one will stand out

signal needle
#

Will do, thanks

past night
#

i've read about the umbraco lfi, but didn't get how to actually make it work

signal needle
#

Yeah I wasnt having any luck with it, put it that way 😂

past night
#

it's a diffeent version though

#

i think the current website is running on 7.xx latest version at the time the room was created

#

which is defo nowhere close the 7.15 lfi

white salmon
#

how do u get the admin name? there's a real anthem.com site is it related?

final lark
#

@white salmon No it is not related to that.

#

Just see what is mentioned about admin on the target machine.

white salmon
#

lol ok got it

#

can't find the first flag even tho i got the others...

final lark
#

@white salmon Hint says to see the source code. Simple. Just search in the source code of every page.

#

I really mean it. "Every Page"

dusty pebble
#

Aha, same as me, just pay attention 😁

final lark
#

@white salmon Attention. That's it

white salmon
#

do i need to fuzz it?

final lark
#

@white salmon No no, Just search for the flag in the Source Code.

steady stratus
#

^

final lark
#

Look INTO Source Code!

white salmon
#

i read it whole lol

steady stratus
#

Read it again

white salmon
#

lol wtf

final lark
#

@white salmon What is the format of Flag?

white salmon
#

it's the same as others THM{

#

found it

final lark
#

Then just search for it.

#

😉

#

Suppose you are searching for a word in Notepad. How can you find a specific word?

warm schooner
white salmon
#

well now i gotta guess the credentials for the box, i guess

dusty pebble
#

@white salmon Nope, don't guess, it's in plaintext somewhere

summer wave
#

@past night Finally done the Anthem, seriously that hidden thing got me confused. Nice box BTW.

steady stratus
#

Nice one!

tribal ginkgo
#

@summer wave that hidden thing was good

final lark
#

@summer wave Great Work! 🙂

echo thunder
#

can anyone give me a hint on how to get root on Anonymous challenge

#

?

white salmon
#

check what has high privilieges?

#

Still web or rdp?

echo thunder
#

I've done it thru nc

dusty pebble
#

enum scripts will give you a good hint

echo thunder
#

I use linepeas but I don't know exactly where to look

dusty pebble
#

i think i used linpeas too, and linpeas is telling you that is interesting, then just search for this and u will be good

echo thunder
#

it is regarding that CVE

#

?

dusty pebble
#

No CVE

echo thunder
#

it is on pkexec

white salmon
#

you gotta try them out i guess

dusty pebble
#

gtfobins 👍

white salmon
#

on anthem tho is it through web or rdp?

dusty pebble
#

rdp

white salmon
#

hm ok thanks

#

cuz i got the web admin to login

#

oh i got it

final lark
#

Great @white salmon

white salmon
#

now need to find them hidden files

final lark
#

Good Luck

white salmon
#

hm access denied

final lark
#

@white salmon Keep Trying!

white salmon
#

do we need to escalate privileges before finding the password?

final lark
#

@white salmon You cannot escalate privileges until, you find the password

signal needle
#

Finished Anthem @past night. Fun box!

white salmon
#

what am i looking for tho? i found a txt file which might be interesting and although the file owner is the current user i cant open it

stuck fractal
#

Play with it until you can

past night
#

cheers @signal needle ❤️

signal needle
#

You got any more Windows boxes in progress? 😊

past night
#

3 currently. 2 are part of a walkthrough

left birch
#

hey guys, im stuck on anonymous. Enumerated all the shares, found the interesting script, but dont rly know what to do with it from here on out. Any1 finished it already and could give me a push in the right direction? 😄

signal needle
#

@past night Awesome, definitely need more Windows boxes. I’d like to see more AD related as well with the latest attacks etc.

austere aspen
#

dont give hints

signal needle
#

There’s a applocker box on THM which is quite interesting. More of those type of boxes would be good.

white salmon
#

@austere aspen this is literally a hints channel

steady stratus
stuck fractal
#

@left birch there's some logs there, have a look.

past night
#

yeah, there is stuff going on but i got some priorities in life for now @signal needle ( UNI ASSIGNMENT IS A HECK) to be done in the next few days, after that i'll crack on

left birch
#

yeee I salvaged this 1 log on the share, but i either dont know what i can do with them or idk haha

stuck fractal
#

The logs give you some info about the script

white salmon
#

so i need some hints on how to read a file which the user is owner but access is denied on anthem, or am i looking in the wrong place?

#

tried to get more permission on powershell but no luck

left birch
#

yee i went through the ||clean.sh|| script but ther isnt too much i can do with it or im missing smth

dusty pebble
#

@white salmon dont over complicate it, you're on the right way

stuck fractal
#

@left birch find out what's happening.

white salmon
#

wym overcomplicating?

left birch
#

i did haha but how can i use a script which i cant rly execute on demand to my advantage

dusty pebble
#

You can open it without powershell or some weird stuff

final lark
#

@white salmon You dont need anything special. Just browse in and out of directories

#

Find the right file. Done!

dusty pebble
#

@left birch Actually, you can, it's the goal 😁

unborn spade
#

nice room @verbal wedge Enjoyed it.

white salmon
#

i really can't tried already with notepad, type, cat, path traversal..

verbal wedge
#

Thank you!

dusty pebble
#

@white salmon It's over complicate too ^^

final lark
#

@white salmon DM me for more help if you are stressed out.

stuck fractal
#

@left birch the log files have entries every 5mins. That implies is being automatically ran right?

left birch
#

the log does not change with me

#

like "last edited"

dry pelican
#

im in the last part of ANTHEM any hints how to finde the admin username.

solemn smelt
#

@signal needle the problem is a lot of ad attacks require networks so that limits us a bit until networks come out and then ad hasn’t changed a whole lot in terms of attacks because sys admins still don’t know how to secure their dcs so the same attacks work there should be plenty of windows content getting pushed out soon though

white salmon
#

check for hidden secrets @dry pelican

dry pelican
#

@white salmon hmm im trying for like 45 minutes first parts are quit easy but this one im kindda clueless, still thank you for the help

white salmon
#

try to find hidden stuff with the command prompt, you can try dumping them all or going one by one

dry pelican
#

u mean on the remote machine or main cause i have not yet connected the machine

stuck fractal
#

Get a shell!

dry pelican
#

yes so i tried that and i got an error. im sorry im being quite annoying now thank you so much for the help ill just keep trying.

white salmon
#

if you have user credentials try to login

humble mountain
#

anyone doing anonymous chall? im stuck at the number 5 :/, what should i do? already tried the smb share but only found some cutty pics

final lark
#

Anonymous room? @humble mountain

humble mountain
#

@final lark yes

austere aspen
#

Use pipe

stuck fractal
#

@humble mountain You fell down the rabbit hole

humble mountain
#

what is that means :/ @stuck fractal

final lark
#

@humble mountain You are not going the correct way

stuck fractal
#

A rabbit hole is something you will spend time looking at, and it won't get you anywhere

humble mountain
#

ahhh okay, thats why haha

stuck fractal
#

From Alice in wonderland, ||when she falls down the rabbit hole into wonderland||

#

Spoiling a book that's over 100 years old there

final lark
#

😭

spark monolith
#

I am currently solving Anthem , though I have completed the first two tasks but i am not able to find the password for the admin to rdp on the machine. can anyone help?

white salmon
#

try rdp with other passwords

spark monolith
#

as in the other flags that have been collected? @white salmon

white salmon
#

maybe you can login with a lower privilege user other than admin

final lark
#

😉

#

@spark monolith Try the possible password you found.

spark monolith
#

okay thanks @final lark @white salmon

humble mountain
#

@final lark i found 3 files, what should i do next with that files :/

stuck fractal
#

Work out what they are

#

Why they're there

final lark
#

@humble mountain Figure out what's going on with them.

humble mountain
#

okay lemme try

humble mountain
#

@final lark @stuck fractal straight into privesc by putting some revshell?

stuck fractal
#

wat

#

||Cron doesn't always run tasks as root|| @humble mountain

#

Try things before you ask. @humble mountain

night rivet
#

is 4th question in xss room task 3 bugged? cant seem to get it

#

nvm, I got it lol

zinc plume
#

need some help with RP: Nmap. "What about 'very verbose' (A personal favorite)" where can i find the solution in nmap -h?

stuck fractal
#

man nmap

zinc plume
#

what is the difference between nmap -h and man nmap?

tidal sedge
#

@zinc plume man nmap contains a lot more detail.

stuck fractal
#

man is a seperate program

zinc plume
#

alright thanks

night rivet
#

man = short for manual

white salmon
#

any hints for pentesting crash course ctf?

#

been running ffuf on /secret/ but nothing comes out

night rivet
#

not sure if I remember right, but try extensions also

#

and dont focus on a single wordlist and go with that always, try different ones

white salmon
#

.php .php3 .php5 .php7 .html .xhtml .json .asp .aspx are these anough?

stuck fractal
#

txt?

white salmon
#

right...

#

it's gonna be a txt for sure

#

maybe i should deploy the machine again after it expired right

stuck fractal
#

That'd help

quiet musk
#

Just finished Anonymous. Was way overthinking it. Got down what I though was an obvious path but was just a rabbit hole. Fun room.

simple schooner
#

can somebody give me a hint for priv esc on tomghost ?

inland onyx
#

Read up on PGP keys

simple schooner
#

tnx ... so im looking in the right direction

#

tried john ... but no sucess so far

inland onyx
#

John will do it

simple schooner
#

tried another wordlist ... et voila

#

thanks

stuck fractal
#

@simple schooner rockyou > others for most of THM

#

Especially if you're cracking a hash

simple schooner
#

thats the one that worked for me 😉

white salmon
#

rockyou for ssh as well?

stuck fractal
#

@white salmon Only if you're meant to brute your way in

#

Isn't very common

white salmon
#

yea

white salmon
#

any hint on anonymous privesc task? Im out of ideas, where should I look?

inland onyx
#

GTFO

vestal igloo
#

bins

#

any hints for UltraTech's database task I'm lost even with the hint

arctic frigate
#

Hey guys, doing the nessus room.
Completed all questions except the directory containing example documents. There is nothing related to this on nessus scan output. Also used dirbuster, no success.
Need a hint please

crimson helm
#

Need some help on lfi basics task 3 question 5, I don't know where to put commands

verbal wedge
#

@quiet musk glad you liked it!

solemn smelt
#

@arctic frigate web app scan I believe?

#

@crimson helm whatever you put in quotations to get command output put that after your directory traversal then an equal sign your command goes there

marble dagger
#

anyone here that already got ctf collection vol2? I'm stuck at easter 15. the hash is the same, but I still can't see the answer. any hints?

high hamlet
#

anyone able to do day 11 of Advent of Cyber? Having issues getting my FTP connection to server to work. Getting issue when issuing commands. Tried to research issue and fix but no luck. Errors im getting are: 500 Illegal Port command and ftp: bind: Address already in use

signal needle
#

@verbal wedge Just finished Anonymous, really good box especially the privesc.

final lark
#

@signal needle Well Done!

arctic frigate
#

@arctic frigate web app scan I believe?
@solemn smelt

Yeah I did that using nessus, didn't find anything related to this question

humble mountain
#

@final lark @stuck fractal thanks for your help, finally figured it out :>

final lark
#

@humble mountain Glad I was able to help 🙂

verbal wedge
#

@signal needle thank you!!

spark monolith
#

Is rockyou.txt the correct wordlist for bruteforcing wordpress login in Jack CTF ?

#

or there is any other recommended wordlist which is more compact?

tidal sedge
#

@spark monolith Rockyou is not the correct wordlist 🙂

spark monolith
#

any hints? @tidal sedge

tidal sedge
#

The wordlist that you need is installed by default on Kali

spark monolith
#

got it thanks @tidal sedge

vapid crown
#

Any hint anthem root please?

dusty pebble
#

Did you found the hidden directory ?

dry pelican
#

@dusty pebble hey im trying since yesterday to find the admin username but got nothing

dusty pebble
#

@dry pelican It's on the website, you will need the help of google 😉

dry pelican
#

on the web app what i closed that and started using maltigo and im so close to using social engineering lol.

dusty pebble
#

Don't overcomplicate it, there is a post for the admin, just pay attention to it and ask to google 😉

spark monolith
#

@vapid crown search for the hidden directory

dry pelican
#

thats the username i have it since yesterday i think can i send it to u in private please

dusty pebble
#

Yup 😉

indigo ridge
#

Daily Buggle room. How to escalate priviledge to root wiith gitfobins.. I can't understand. please help me.

patent token
#

Did you search for the appropriate one?

white salmon
#

can anyone help with sqlmap for the OWASP Juice Shop i really want to understand how to use sqlmap to solve this puzzle..

sharp mason
#

I'm stuck on the bof1 Buffer Overflow room, task 8. This is the task where you are supposed to successfully get a shell by overflowing the buffer. I've tried running the example code they have provided but running it just gets a segmentation fault. I'm thinking maybe I need to provide a different memory address than the one that they have provided. I have the program attached inside gdb and I've been testing with different fuzzing strings etc but I can't seem to figure out what address that I'm looking for. The info I'm reading all references EIP as the instruction pointer that I'm trying to overwrite but the closest thing I see in gdb is RIP which is maybe the x86_64 equivalent?

stuck fractal
#

@sharp mason Yeah, this is the prefixes again

#

E is 32bit, R is 64bit

#

You can access 32bit registers from a 64bit program, it's the same register

sharp mason
#

right, so the odd thing is that I can't get the value of RIP to change

stuck fractal
#

Task 8 is a HUGE step up in difficulty

sharp mason
#

so, even if I feed 5k "A" chars as input, I can't get the value of RIP to change gdb --args buffer-overflow $(python -c "print('A' * 5000)")

stuck fractal
#

I'm not a BoF guy, I just know some x86 assembly

#

People have a lot of trouble with it

sharp mason
#

I think maybe I'm missing something, this is supposed to be the easiest bof room

stuck fractal
#

Not task 8 and 9

sharp mason
#

any hints on what I'm missing regarding how to control RIP?

#

in all the other examples I've seen for entry lvl bof, the teqnique is to fuzz until you can find the offset required to get data into the EIP/RIP

#

something is keeping the RIP from being overwritten

stuck fractal
#

I haven't learnt BoF yet so I got nothing

sick sun
#

Anyone done anonymous rooms ? Need hint privs esc

stuck fractal
#

gtfobins

solemn smelt
#

@sharp mason I don’t have a subscription so I haven’t done the room/ look at it however you’re right in saying you should find the offset maybe look for bad characters?

sick sun
#

But i didnt got creds user

sharp mason
#

@solemn smelt the part I'm stuck on is that I can't find the offset b/c I can't overwrite the RIP

#

seems like no matter how many chars I throw at the program, RIP never changes. I've tried up to 50k 'A' chars

solemn smelt
#

Ohhhh that’s your problem I’m not sure how the room has you do it but I always use a pattern create as the offset

sick sun
#

@stuck fractal if i run gtfo without sudo i just got user again

stuck fractal
#

You need to understand the vuln @sick sun

sharp mason
#

@solemn smelt same, but you can't find the part of the pattern to find the offset unless the EIP/RIP gets overwritten

solemn smelt
#

no you overwrite the eip after you find the offset unless the room has you do it some other way I’ve never heard of

#

How are you going to know where to overwrite the eip if you don’t know where the eip even is? That what finding the offset is doing

sharp mason
#

true, but if you can't overwrite the EIP, you don't know where the offset it is

wraith marsh
#

Are you doing Bof1? If so, RIP wont overwrite with just A's

sharp mason
#

yes, I'm doing Bof1

wraith marsh
#

Okay,so to overwrite RIP, the address needs to be in a specific range

sharp mason
#

why won't A's overwrite, are they bad chars here?

wraith marsh
#

Because for 64bit the address of RIP needs to be in a specific range

#

google: "x64 buffer overflow"

#

theres a good article on medium that explains it

sharp mason
#

willdo

#

thx

wraith marsh
#

np

sick sun
#

@stuck fractal im stuck on priva esc

stuck fractal
#

Yes.

#

You need to understand the vuln

#

And understand how to use it

#

Do some research

acoustic glen
#

Hey, I could use some help with the anthem box.
I just can't find the name of the administrator and I have no idea what the hint is trying to tell me

inland onyx
#

Use the information on the site to piece it together @acoustic glen

#

That question (and the next one) are all about lateral thinking

sick sun
#

@stuck fractal easy man hahahha

stuck fractal
#

huh?

echo thunder
#

any hint on how to find the password for the admin on anthem. I found a hidden directory in C:\ but the file can be opened only by the administrator

wraith marsh
#

but the file can be opened only by the administrator
@echo thunder You sure?

fleet flume
#

Hey! I'm pretty beginner to InfoSec and am having a little trouble with the Blue room.

I've got the explot set up to run, i'm setting the RHOSTS value to be the target IP, but I am getting "exploit success, but no session started" error message. I've tried resetting the room a few times with no luck. I've even followed a guide to see where I'm going wrong, but can't seem to find anything. Any help is appreciated 🙂

echo thunder
#

yes

#

can I PM you

#

?

wraith marsh
#

I'd prefer not. My hint was enough.

steady stratus
#

I fully agree ^^

fleet flume
#

Also, RE me, im brand new to the discord so not sure if this is the right place to post the above message cause it's not quite a hint I'm asking for, so if there's a better channel please let me know

echo thunder
#

the txt file is readable only by admin and the ||.dat ||one is readeable also by me

solemn smelt
#

@fleet flume that’s just eternal blue being eternal blue you just gotta do it a couple time

fleet flume
#

Thanks, @solemn smelt , ill bombard it a few more times and if I'm not successful ill come back 😂

solemn smelt
#

If that doesn’t work some things that will prevent an exploit from working are the target you have set the default may not always work, and changing between a staged and non staged payload however I don’t believe any of those need to be change for it to work on blue

fleet flume
#

I noticed there are a few variants of eternal blue within metasploit, will others also work on this machine and should I try them if the first one asked for by the room isnt working?

stuck fractal
#

Nope.

solemn smelt
#

there’s only really two

#

But no the one that the room says to use should work just fine

fleet flume
#

hmmm, okay. will keep digging. thanks both

echo thunder
#

finally figure it out for antehm

#

anthem

#

it was the most stupid thing

steady stratus
#

Very easy to overcomplicate

final lark
#

Anyone solving New box "Gatekeeper"?

patent token
#

One person has made it beyond the first task which just requires starting the machine up.

marsh violet
#

I'm stuck and have no where to go....

#

Any hints for Gatekeeper?

patent token
#

🙂

sinful garden
#

Might be a lil soon for hints

patent token
#

The gate is only half the battle.

dense marlin
#

hi there can i get some hint for THM: anthem task 1: #4, i tried to crawl the pages with burpsuite, but i cant managed to find the .txt file

stuck fractal
#

@dense marlin Burp spidering etc is only going to pick up stuff that's linked

dense marlin
#

so it's not linked you mean?

stuck fractal
#

I don't know

dense marlin
#

the question did mentioned possible password in one of the pages web crawlers check for

#

i thought it might be linked

stuck fractal
#

Nah

#

There are files that exist

#

That Google etc checks for when crawling

tidal sedge
#

@dense marlin Robots are nice don't you agree?

dense marlin
#

i do checked the robots too @tidal sedge

tidal sedge
#

It's there if I remember correctly

dense marlin
#

@stuck fractal so you mean the file might be out of the scope? like it might be outside of the machine ip?

#

like google github those link?

stuck fractal
#

@dense marlin No

#

Spidering etc only looks at pages that are linked somewhere

dense marlin
#

ok i tried to perform fuzzing on the robots

stuck fractal
#

what no

tidal sedge
#

🤦

stuck fractal
#

||robots.txt|| is a file that real crawlers will look for to tell them what they can and can't crawl

dense marlin
#

yea i mean the directories in robtos

#

*robots

#

fuzzing for files that might be potential contain in the directories that specified in robots

stuck fractal
#

what

#

fuzzing for files that might be potential contain in the directories that specified in robots
@dense marlin This makes no sense.

dense marlin
#

sometimes some user might store their file in those directory like /config/password.txt or something else that's why they dont want you to crawl these directory?

#

ok my bad

#

i cant believe that im watching the exact answer for 2 hrs

#

i've overthink the whole thing

#

@stuck fractal @tidal sedge thanks for the hint

upper solar
#

hey everyone can anybody help me in Anthem room task 1-7

dense marlin
#

hey there can anyone give me some nudge for anthem rdp login? i've tried different format of username for the first and last name that gathered with the password that found. the credential works when i login into the CMS but it seems that the credential for the rdp is different so i tried several type of username format for with the credential found. Im kinda lost right now

past night
#

read the task

#

i can't put stuff in BOLD otherwise i would ruin the fun

dense marlin
#

actually i've read it
sorry bout it but i dont really understand it

torn mural
#

Gatekeeper, am I on the right track?

patent token
#

Not sure what you mean

#

Should definitely ask your question more specifically please.

torn mural
#

Being the Cryptic keeper since it is such a new room

patent token
#

Not at all

#

Happy to help being as I created it

#

But I would expect me to gatekeep it a bit. 🙂

torn mural
#

Oh cool, mind if I pm you?

#

anywho, I noticed how leet this challenge was and wondered if a buffer overflow was in order

patent token
#

So, I recommend poking at it a bit and see what you get. If you've enumerated you may find something that you can use and test.

dense marlin
#

@past night my bad, i've literally overthink lots of stuff in ur room. Found the credential for rdp

tender bluff
#

I have a question that I want to check with you uys
guys*
I've just started the "Common Linux Privesc" room and it mentions downloading the Linenum shell which I did. the questions in the sections doesn't say anything about actually transferring it and using it on the machine so I just want to confirm that That is what I am supposed to do in order to answer the questions or if it's not something I'm supposed to do?
the instructions aren't terribly cleat
clear*

#

woops, wrong room 😦

#

apologies

vapid zenith
#

how to find admin of anthem room in web site analysis task

echo thunder
#

Hi @vapid zenith

#

PM me

#

and I will be glad to help you

past night
#

@dense marlin yup, we know. i told this at least 20 times about not complicating stuff

vapid zenith
#

@echo thunder come in inbox bro

#

I found a restore file in anthem room but cant access it

#

how to check that

past night
#

Google Windows file permissions

echo thunder
#

anyone finished the gatekeeper room

#

?