#room-hints

1 messages ยท Page 27 of 1

humble mountain
#

stuck at the privesc to root

spark monolith
#

Is anybody facing an issue in getting a reverse shell in Anonymous v6 CTF?

#

the commands are taking alot of time to work

#

please help if anyone has a better way to do it

tidal sedge
#

@spark monolith I didn't face any issue

#

@spark monolith Don't pm me again without permission.

spark monolith
#

@tidal sedge sure

steady stratus
#

If you look at the log file, you'll see an entry for every 5 minutes

#

You should infer from it that something happens every 5 minutes ๐Ÿ™‚

spark monolith
#

i have got the reverse shell but it's taking a lot of time to respond this is due to the cleaning of log files every 5 mins?

steady stratus
#

If the reverse shell has executed then it will persist

#

Any input lag will be your connection

spark monolith
#

oh okay thanks @steady stratus

steady stratus
#

You can always ping the machine to verify any drastic latency

tardy python
#

any hints on root of Anonymous?

humble mountain
#

@tardy python what cron jobs do?

tardy python
#

i dont see any crons of root

signal needle
#

Have you ran automated scripts yet? Linenum,LinPEAS?

#

They pretty much tell you the answer

dense marlin
#

any hints on root of Anonymous?
@tardy python linEnum can tell you something interesting for the escalation.

viscid mason
#

any hints on root of Anonymous?
@tardy python

check for some "ID" i think u can easily "SU" that VM. that was an easy room. just basic PrivEsc knowledge needed!

echo thunder
#

anyone can give a hint for lord of the root task 2 question 6?

atomic ether
#

Hi all, I'm on task 7 of the Ice room. They say that you should be able to to use the c code from exploit-db to do the same thing but no matter what i run or install i can't seem to get it to compile successfully. Has anyone else achieved this? Can you let me know if there is an issue with the code i need to correct or if it's an issue with my compiler configuration? I don't have any c background so trying to avoid debugging the script itself unless i know for certain that's the issue. Many thanks.

white salmon
#

aaa any hints on unreadable thing in peak hill the ||encoded thing or whatever||

wooden mist
#

the task description is a bit of a hint ;)

white salmon
#

okay good sir thank you very muchy

potent quail
#

Iโ€™m also on that room. I worked out what to do but it didnโ€™t work so o feel I did it wrong somehow. I get an error suggesting about a MARK but I couldnโ€™t fix it. Unsure what I need to do

#

@wooden mist mind if I shoot you a quick message please to see if Iโ€™m on the right track?

frail ferry
#

are you sure the word was mark? if yes, please explain what you did in DM

potent quail
#

@frail ferry that was an error I got. Not a clue or anything.

frail ferry
#

but doing what? (DM to avoid spoils)

white salmon
#

Any hints for Anthem room, rdp credentials ?

frail ferry
#

you will have every information you need if you replied to #1 -> #7

white salmon
#

Hello, I dont want to spoil anything but if someone can help with gatekeeper that would be great, i have a shell and working on root yet i have a question on it. Thanks

primal linden
#

anthem room i need 1-7

stuck fractal
#

...that's all of it

primal linden
#

what

scenic harness
#

Hi, Im working through the Intro to x86-64. I'm stuck on the task 4. I was able to see the variable on memory but it does not match the answer. I got all the other flags except for the first one.

primal linden
#

@stuck fractal is that for me?

stuck fractal
#

@primal linden 1 to 7 is like either all or most of the room

primal linden
#

i dont get it

#

anthem room

stuck fractal
#

@primal linden There's 8 questions in task 1

#

You asked for help with questions 1 through 7

primal linden
#

i ened 7

#

need*

#

hint to get administrator

#

name

stuck fractal
#

There's a famous poem that's incomplete.

#

T1Q7 would be a much clearer way of asking

primal linden
#

i got his first name

white salmon
#

@primal linden for admin name, google the poem.

primal linden
#

ty guys

#

got it

patent token
#

Hey VV. I'm the creator. My recommendation is to enumerate harder. ๐Ÿ™‚

white salmon
#

Thanks i will try winPEAS again

patent token
#

I would enumerate a different way.

#

The challenge is meant to make you look passed your typical enumeration tools.

#

I'm streaming it in 8 minutes if you're interested. No pressure if you want to try on your own. Check out #thm-community-media for more info.

white salmon
#

Rooted Anthem Room โค๏ธ

#

hints for getting user/pass for anthem room? (i logged into umbraco but i dont think thats where i'm supposed to be >_>)

frail ferry
#

rdp credentials?

viscid mason
#

actually, that's exactly where u suppose to be, but there is nothing much about what u trying to find.

and... since now, everything u found is the ANSWER of what u looking for

white salmon
#

Alright, I figured it out. Thx for the help ๐Ÿ˜„

viscid mason
#

Elf, why not use "internet" and a cute "cat" on peak hill

white salmon
#

I alredy did use both multiple times

viscid mason
#

nc?

wooden mist
#

@viscid mason using it is only useful when you got through the first part, not sure if elf got through it yet

viscid mason
#

๐Ÿค” YEah! ๐Ÿ˜› any hints from ur side szymex73?

white salmon
#

nope im stuck in decoding the wierd stuff

viscid mason
#

try harder Elf! ๐Ÿ˜›

white salmon
#

im doing it

wooden mist
#

look at the image in the description Kappa

elfin owl
#

Any hints on the first part? I am pretty certain about what to do with the weird part, but I am stuck enumerating things... well I am currently looking for things I have not enumerated yet.

wooden mist
#

there's one obvious thing that you should've picked up on a portscan

white salmon
#

Any hints on (what I'm assuming is) the last part? Is there a specific thing I should look up? I'm regretting skipping python classes at college

gilded badge
#

I think I'm on the same part that you are @white salmon. You ever figure it out?

white salmon
#

Yea it's the same idea that is used earlier in the room. Don't wanna go to deep into details

gilded badge
#

Gotcha

wanton sonnet
#

Hey for peak_hill it asks me to grow something any hints on that?

jade bolt
#

||total guess but look at the first 3 letters of the room?||

#

Hi, in anthem Taks 1 question 7, the hint says consult the oracle. but i can't seem to find the answer to the question, can anybody point me in a direction?

normal totem
#

Hey guys

#

i need some help at the network service room

#

at the last question form task 10, where i need to get the ftp.txt file, i get the error that i have no permission to get it

#

although i logged in the ftp as mike

glossy basin
#

Hi, in anthem Taks 1 question 7, the hint says consult the oracle. but i can't seem to find the answer to the question, can anybody point me in a direction?
oracle means google in this case :)

jade bolt
#

yeah i got that far haha

normal totem
#

anyone did that room?

#

network services

stuck fractal
#

@normal totem Permission denied locally

glossy basin
#

exit /wordlists directory

#

and ftp from somewhere else

jade bolt
#

@glossy basin can you guide me a lietel biet in the direction you pointed me :S

normal totem
#

Thank you guys

#

didnt realize the pwd influences this

tidal sedge
#

didnt realize the pwd influences this
@normal totem You do know that pwd stands for print working directory?

normal totem
#

wow

#

i thought its present

#

my bad

stuck fractal
normal totem
#

yup

white salmon
#

does nc require sudo for reverse shell ๐Ÿค”

tidal sedge
#

@white salmon Depends on the port you're using

white salmon
#

how so?

tidal sedge
#

The first 1024 ports require sudo

white salmon
#

huh. thx for the info

jaunty ember
#

do I need to specifically look at the one port in Peak Hill for a way in?

austere aspen
#

||ssh_pass||

blazing turtle
#

@jaunty ember at some point, yes

digital iris
#

anyone available for a little nudge on peakhill ? ||i have the all the ssh_user and ssh_pass things and i tried a bruteforce with all of this and also with a username i found (on ssh), but feel like i'm missing something - probably to do with that other port asking for a username/password||

#

i meant to put that in spoiler tags not that hahaha

sweet relic
#

can someone help my with anonymous v6? I edited ||clean.sh|| on the ||ftp-server|| but either i did something wrong or ||the script doesn't get executed by a cronjob||. am i missing something?

solid sphinx
#

@sweet relic What did you add to the script?

wooden mist
#

@digital iris in what form do you have ssh_user/pass?

sweet relic
#

cat whoami > whoami
i wanted to test for execution firs

#

correction: whoami > whoami

digital iris
#

@wooden mist so it had like ssh_userRandomCharacters and ssh_passRandomCharacters so i tried them like that and i also tried stripping the ssh_user and ssh_pass off it but that didn't work either

stuck fractal
#

@sweet relic You did something wrong.

#

Did it the lose execute bit?

wooden mist
#

but in what form do you have it? do you have it as a file or a ||deserialized array||?

solid sphinx
#

Would he need to put the full filepath?

sweet relic
#

@stuck fractal Ooooh...of course it did ๐Ÿคฆโ€โ™‚๏ธ

stuck fractal
#

@solid sphinx For what?

#

@sweet relic Don't delete the file. put with the same name

digital iris
#

as a file

sweet relic
#

@stuck fractal thank you ๐Ÿ™‚

solid sphinx
#

nevermind

compact locust
#

can i have a hint lmao

steady stratus
#

Dude

compact locust
#

oh sorry

steady stratus
#

I literally just asked you not to post answers

compact locust
#

had the asnwer

#

yeah sorry

#

hint?

stuck fractal
#

man ls

steady stratus
#

man is really really wonderful

compact locust
#

i cant find it

stuck fractal
#

Also, a google search would have worked

#

ls long list format flag

#

Learn to do some research, rule 13

compact locust
#

what kinda shell?

sinful garden
#

Have you tried googling it before asking here?

compact locust
#

idk exactly what to google

sinful garden
#

There is no point in doing the room if youre asking us all of the questions

compact locust
#

kk

stuck fractal
#

@compact locust It's specifically for su

compact locust
#

what is?

#

the shell?

stuck fractal
#

The question

#

It's talking about su

compact locust
#

yeah

stuck fractal
#

man su

#

learn to use the man pages

compact locust
#

yeah i saw that

#

but like

#

whats a shell

#

that was my question

inland onyx
#

That

#

Is also a google question

verbal wedge
#

@compact locust sup

compact locust
#

What is the value of the home environment variable

#

ive googled

#

ive lookd

#

i cant find it

verbal wedge
#

Dolla sign

compact locust
#

no like

verbal wedge
#

I think

compact locust
#

/----/------

#

this is the format

stuck fractal
#

Read the $ Task

verbal wedge
#

Ahhh

stuck fractal
#

Learn how to view variables

compact locust
#

i have

verbal wedge
#

Oh lol yeah

#

I got it

compact locust
#

im 100% certain of the answer

#

but it says its incorrect

stuck fractal
#

@compact locust You haven't if you can't find the value of that thing

compact locust
#

let me dm it to you

stuck fractal
#

Did you switch user when you were told to?

#

No

#

Don't DM me

compact locust
#

ok i found it

verbal wedge
#

There ya go

white salmon
#

Just checked myself and found it on the first page that was highlighted by Google.

#

Oh wait, you found it.

#

Nvm

verbal wedge
#

Yeah I did too

sweet relic
#

@verbal wedge your new machine is cracking my head ๐Ÿ˜„

verbal wedge
#

You got this

#

I'm an idiot and made it so you got it

white salmon
#

What's your box @verbal wedge

verbal wedge
#

Anon

austere aspen
#

Easy box

verbal wedge
#

Yeah relatively

cunning cloud
#

Nudge? getting cve for simple ctf?

white salmon
#

I'll give it a bash when a get a free sec.

#

Might be a little too much for my level at the minute.

sharp mason
#

anyone know what this is doing in python? myvar = "A" * 0xA00 If I print it, it's a bunch of "A" chars, not sure what it's doing. I'm used to seeing lines like "A" * 100 to quickly create a var w/ 100 'A' chars but haven't seen the like of the first one before

glacial ember
#

hey anyone has a hint for me I'm stuck in flag75 "ctf 100"

stark pelican
#

@sharp mason 0xA00 is hexadecimal for 2560, so myvar would be equal to 2560 "A"s

sharp mason
#

ahh, thanks @stark pelican

graceful sun
#

am i on the right track ? i got into the panel for umbraco on the ANTHEM box am i sopposed to look around there for creds for R** or do i need to somehow spawn a shell then get creds that way??

remote gate
#

@graceful sun look at your nmap scan again and see where you can use those creds

graceful sun
#

i got it already lol my bad guys

remote gate
#

No worries

graceful sun
#

thank you!

tardy python
#

any hints on The Impossible Challenge ?

viscid bramble
#

Any hints on Peak Hill? I'm stuck at a string with a bunch of ssh_pass/ssh_user

pine orbit
#

^ ditto

viscid bramble
#

I feel like there is more hidden in there

pine orbit
#

join vc, were discussing it

pine orbit
#

anyone awake that could provide a hint for pickhill?

blazing turtle
#

only if you mean peakhill

pine orbit
#

^

#

yes

#

i blame it on being tired :/

blazing turtle
#

where are you stuck at?

pine orbit
#

|| have found the .creds file in ftp and know it is pickled, unsure if i should decode it from binary first before trying to unpickle it, and either way, cant figure the right command to unpickle it correctly, guessing it involves setting the protocol.. been at this for 3 hours now ||

wooden mist
#

not really a command, it's better if you write a script to decode it :)

stuck fractal
#

@pine orbit I haven't done the box, but I can tell you that ||pickle reads/writes in binary data rather than plaintext||

pine orbit
#

thats what i meant ๐Ÿ™‚

viscid mason
#

that's also I was thinking Ninja! ๐Ÿ˜ธ

wooden mist
#

if you're not sure if you should decode the 1/0 before passing it to the decoder then why not try it with/without decoding the 1/0 prior to decoding the data itself

#

it will tell you if there's something wrong :)

pine orbit
#

i have tried it both ways, @wooden mist mind if i dm you about it so were not flooding this channel (ill send you some of the decoding things ive tried)

wooden mist
#

flooding the channel isn't a problem but this would probably go to #room-help though

sinful garden
#

Can anyone give me a hint on peak hill ||i've unpickled the data, and ordered the user and pass in the right order, but what am i supposed to do now. I've tried the creds on ftp ssh and the 7321 port but they dont work||

wooden mist
#

ssh

#

if they don't work then you did something wrong

sinful garden
#

๐Ÿค”

sinful garden
#

Ah i found the bug in my python script

#

Thannks ๐Ÿ˜„

stuck fractal
#

Peak hill, I have a password but I don't got a username

#

wait nvm

#

am dumb

#

cancel

glacial ember
#

hey anyone has any hint for me I'm stuck on flag75 "ctf 100"

glossy basin
#

I had to do it ๐Ÿ˜„

white salmon
#

hello im in need of help once again i did get creds and now i don't know what to do with them

glossy basin
#

use them for ssh

white salmon
#

i did

#

come watch stream

glossy basin
#

i can't

white salmon
#

okay

glossy basin
#

this might help

stark pelican
#

pickhill is reallly one hell of a room, isnt it?

white salmon
#

it truly is

glossy basin
#

nah

#

it's a great room

#

just takes time

white salmon
#

wdym decompile

wanton gate
#

@tardy python

check for some "ID" i think u can easily "SU" that VM. that was an easy room. just basic PrivEsc knowledge needed!
@viscid mason how do you exploit somthing without sudo password.

stuck fractal
#

There are privilege escalations that don't involve sudo.

wanton gate
#

i ran linpeas and got somthing seem exploitable. try with SUID env but no success...

#

any hint?

stuck fractal
#

@wanton gate There's caveats for GTFOBins

viscid mason
#

@viscid mason how do you exploit somthing without sudo password.
@wanton gate

that's the main role of PRIVILAGE Escalation. when u don't have password or anything, and u just go on wild and figure out things, I already gave u hint for this specific thing, u just need to figure out!

tardy python
#

how do you exploit somthing without sudo password.
@wanton gate just test your things without sudo

wanton gate
#

thanks for your help. โค๏ธ

white salmon
#

any hints on privesc?

blazing turtle
#

for peak hill? it's a pickle farm, grow some pickles obviously

viscid mason
#

base64

blazing turtle
#

base64 pickles best pickles

wooden mist
#

pickled base64 Keepo

viscid mason
#

try gib farm a base64

white salmon
#

what is that xD

tardy python
#

base64 a thingy xD

viscid mason
#

try to give base64 input to that python file

#

OMG!

#

why u search words that r not "..."

#

what is he doing ๐Ÿ˜น

white salmon
#

xD

#

i don't know

#

yah i tried

viscid mason
#

think bro think

white salmon
#

see

#

i tried xD

wooden mist
#

:|

viscid mason
#

๐Ÿ˜

stark pelican
#

;-;

white salmon
#

i legit don't have control over this

viscid mason
#

python + pickle + base64 + os + /bin/bash = root!

white salmon
#

smh

wooden mist
#

python + pickle + base64 + magic = root

white salmon
#

iii still don't understand

#

what am i missing ๐Ÿ˜ฆ

stuck fractal
#

@white salmon Get a nice shell first

#

Makes it easier

white salmon
#

yah im trying to do that now

#

cuz this is really bad

viscid mason
#

+1

stark pelican
#

step 1: get user flag
step 2: get root flag

it isnt that hard

#

XD

white salmon
#

x D

#

@stark pelican it took me almost 1 day to get that user ๐Ÿ˜„

stark pelican
#

yikes

wispy verge
#

hello, i have question about owasp juice shop

#

i read an article about it and writer solved broken auth part %50 guess

faint trail
#

Finally done Peak Hill, I was making so many little mistakes

wispy verge
#

%50 techincal

faint trail
#

Always trying to overcomplicate things

white salmon
#

aaaa hint pls

tidal sedge
faint trail
#

Feel free to PM, I wont give too much away though!

hollow gazelle
#

can anyone please help me with flag 1 and 4 of anthem

blazing turtle
#

use the source, luke

faint trail
wooden mist
#

hard decision to make

#

at least we have proof it was achieved DogKek

faint trail
#

I can't live with being the one to ruin it, so I've chose another box :p

tranquil dagger
#

Now join, @faint trail

stuck fractal
#

Someone needs to.

cyan token
#

@hollow gazelle Try writing a Python script that finds the flags for you. Atleast that's what I did. Regex + beautiful soup.

#

Or just CTRL+F your way through lol

north moat
#

@faint trail should i decode-something in Peak Hill

sick sun
#

anyone done Peak rooms

#

need hint for decode some creds

blazing turtle
#

@sick sun the first ones?

sick sun
#

@blazing turtle ?

blazing turtle
#

are you asking about decoding the first set of creds you can get?

sick sun
#

@blazing turtle yes right man

#

can i DM you ?

blazing turtle
#

sure

viscid bramble
#

Any hints on Peak Hill? ||I've broken out of the CMD shell and have access as dill on the box, not sure how to interact or reverse this binary in /opt||

stuck fractal
#

@viscid bramble ls -lah in the dir, see what's up with it

#

Maybe try... running it?

viscid bramble
#

I have done both, I don't know how to grow

sick sun
#

Anyone give me a hint how to decode from binary string

#

Peak hill room

tidal sedge
#

@sick sun You're going to have to provide more information, is this for a THM room? If so which one? Which task and question?

stuck fractal
#

Before initial shell, Peak Hill

tidal sedge
#

Ah, I haven't done that one, through I've heard good things about the box

stuck fractal
#

@sick sun The room page is full of hints

nocturne vault
#

nice room this pickleboi was, but frustrating at times

white salmon
#

hi could someone help me with the admin hidden password for Anthem room?

dusky vigil
#

You've likely already overlooked it

#

Think how systems may have misconfigured permissions

white salmon
#

@dusky vigil i found it thanks for your help

velvet flint
#

Anyone able to give nudge on how to escalate from www-data to jjamesonon Daily Bugle ?

patent token
#

Sure. Check the directory you initially land in in your shell for www-data. Investigate those files.

velvet flint
#

ty

patent token
#

Welcome.

velvet flint
#

Got root now ^^

white salmon
#

hello can i have a hint on inoculation

#

aa yk small lil hint

wooden mist
#

no

white salmon
#

๐Ÿ˜ฆ

wooden mist
#

it's a hard room for a reason

white salmon
#

ok no hints

stuck fractal
white salmon
#

but small

#

litlle

#

๐Ÿ˜ฆ

wooden mist
#

there is one hint from the room's creator hidden deeeeeeep in one of the channels history on this discord

#

it can help but idk if you're on that stage yet Keepo

white salmon
#

aaa no hints

frozen osprey
#

What critical file has had its permissions changed to allow some users to write to it?

#

how to check?

#

i was already in etC/passwd

stuck fractal
#

wat

onyx wadi
#

i

#

don't understand

stuck fractal
#

@onyx wadi ?

old root
#

Hi all!

frozen osprey
stuck fractal
#

i was already in etC/passwd
@frozen osprey wat

old root
#

Can anyone give me a hint at task 43 of 'Learn Linux' room?

frozen osprey
#

i did

onyx wadi
#

don't mind me james

frozen osprey
#

thanks got the resolution

onyx wadi
#

priv esc

stuck fractal
#

@old root Look for files belonging to each and every user.

old root
#

Thank you!

old root
#

any other hint? I think i'm stuck

cinder bluff
#

anyone help for blogengine ?

stuck fractal
#

@cinder bluff What room?

#

@cinder bluff Please respect Rule 1. Don't DM people without making sure it's OK first.

#

Additionally, this is for help with THM rooms.

patent token
#

HackPark uses blogengine right?

stuck fractal
#

@patent token They DM'd me unsolicited, then told me it wasn't a THM room, got angry at me for asking them to please follow rule 1, and then left.

patent token
#

Oh ok. Understood.

graceful sun
#

hey so where do i find the admin password do i wanna be looking into RDP for it ? like in files maybe? i did a winpeas didnt get much still looking lol any hints

patent token
#

Can you please share a good deal more information about that please?

#

What room, task, etc.

hollow bay
#

Ok, I feel sorta stupid but I can't figure out the last question in the Linux room (task 43)

#

I think I'm on the right track for what the vulnerability is

#

but I'm not sure how to escalate with it

stuck fractal
#

@hollow bay It's not really a vulnerability

#

This isn't a traditional box

old root
#

Hey @hollow bay try to look for files belong to each and every user

hollow bay
#

Am I correct in noticing the || files with the SUID bit ||?

#

And somehow changing one of those since I can write to them?

#

Or am I way overcomplicating this

old root
#

It's way more simple than that

stuck fractal
#

@hollow bay For reference, if you write to a SUID file then it loses it's SUID bit

hollow bay
#

@stuck fractal Yeah I learned that the hard way by trying to cat a shell script and > into the file

stuck fractal
#

Look for files belonging to each and every user

#

Investigate suspicious ones

graceful sun
#

it is the anthem room task 3 Q 3 looking for the admin PW

graceful sun
#

nvm found the file

cloud perch
#

yo i need help with Obscure Web Vulns has anyone completed it?

glossy basin
#

@cloud perch don't ask to ask, just ask

cloud perch
#

im stuck on task 9. "what parameter allows us to generate a poc(acttual exploit)" for csrf

glossy basin
#

have you read the tool's help page?

#

type xsrfprobe -h and you'll find it

cloud perch
#

thanks

indigo ridge
glossy basin
#

read this ^

#

i hope you get the idea

indigo ridge
#

last second task in the room

glossy basin
#

oh

#

you better specify the task next time

indigo ridge
#

sure

glossy basin
#

so, did you do anything about the hint in the task?

#

'it is hidden'

indigo ridge
#

yeah.. I tried show all the folders and files with folder options

glossy basin
#

great

indigo ridge
#

I found some backup folder but I cant's access them

glossy basin
#

you can access the folder, but i guess you couldn't read the file

#

right?

indigo ridge
#

yes

glossy basin
#

my hint would be to look into file permissions :)

#

I guess you'll find your way around now

indigo ridge
#

okay thanks!

cloud perch
#

did you check the robots.txt

#

@indigo ridge the hint is in the poem

#

@indigo ridge pm me

indigo ridge
#

okay thanks!
@indigo ridge
@indigo ridge the hint is in the poem
@cloud perch I got it.. Thankyou very much

#

It was permissionsskidy

white salmon
#

aaa small little hint

#

for Inoculation

past night
#

no

north moat
#

Room Network Services TASK 7 # 11 still not receive ping respond

quiet musk
#

For Gatekeeper, is digging into ||gatekeeper.exe via strings|| worth my time or am I missing another way in? I've tried ||uploading my own executables via SMB on the User share|| but am not getting a hit on my listener...

north moat
#

is it bug ?

vernal ridge
#

I have some doubts on authenticating the RDB in Anthem box, can i get some help?

patent token
#

M3talhead, there is only one way on to that machine. Uploading to the SMB isn't it unfortunately. It's a nice try though. ๐Ÿ˜Š

past night
#

@vernal ridge if you've done the previous tasks you should already have the credentials, read the questions carefully

vernal ridge
#

yeah i did , but the creds didnt work!

past night
#

they do

#

you just didn't read the first question from task 3

vernal ridge
#

i did read, but dint get it , can i pm, i dont wana be a spoiler

past night
#

feel free to say it over here between ||

oblique shuttle
#

hi all.. any chance of a clue for "Linux Challenges 5.4" - Using SCP, FileZilla or another FTP client download flag32.mp3 to reveal flag 32.?? I've SCP'd the file locally but now stuck!

past night
#

what does .mp3 imply

vernal ridge
#

||i used umbraco exploit to access the machine, but i couldnt find any creds to enumerate, but everyone said abt RDP to access the machine, but the creds i used to complete task 1, but i didnt got any access to RDP||

past night
#

there is no exploit for you to run

tidal sedge
#

Umbraco exploit?

#

^

#

Exactly

past night
#

you already have the credentials to access the machine

vernal ridge
#

Umbraco exploit?
@tidal sedge yeah!

tidal sedge
#

And did the exploit work?

oblique shuttle
#

what does .mp3 imply
@past night So I tried playing it but nothing...

vernal ridge
#

i got less prev shell using it

tidal sedge
#

@past night Fix ๐Ÿ™‚

past night
#

fix what lol

tidal sedge
#

Seems like they found an exploit

past night
#

what exploit

tidal sedge
#

๐Ÿคท

#

Ask them

past night
#

7.12 shouldn't work

vernal ridge
#

it gives only less prev shell

past night
#

mind sharing a link

#

you made me curious

vernal ridge
tidal sedge
#

That's an authenticated exploit

past night
#

hmm, that's unintended

#

it shouldn't be picking it up

tidal sedge
#

That means you already have the creds

vernal ridge
#

hmm, that's unintended
@past night ๐Ÿ˜ข

past night
#

it's nothing to do with exploiting a vulnerability

#

you are overcomplicating it

vernal ridge
#

That means you already have the creds
@tidal sedge yeah! for umbraco , not for RDP

past night
#

read this

tidal sedge
#

@vernal ridge Have you ever heard of ||password reuse ๐Ÿ™„||

vernal ridge
#

i dint type any domain name

past night
#

are you getting the ding ding ding?

vernal ridge
#

no dude!

past night
#

lol. read what malware said

vernal ridge
#

@vernal ridge Have you ever heard of ||password reuse ๐Ÿ™„||
@tidal sedge i know, also i am compelled to use the only creds i got

past night
#

what does domain mean to you

#

also, if it's after an hour the machine might've closed itself down (it's a bug)

vernal ridge
#

whenever i was asked to login using RDP, it asked a user , password and domain, i left the domain unfilled

#

also, if it's after an hour the machine might've closed itself down (it's a bug)
@past night ๐Ÿ‘€

past night
#

that's not what it means

vernal ridge
#

oh

#

OHH, got it buddies

#

please fix the exploit ||the exploit gives me a low privilege, and also gives me chance to look what is the user name,jzt now everything ring a bell on what i saw when i got a shell ||

steady stratus
#

Mhm it's pretty interesting you got an exploit - it's unintentional in the sense that I don't think it needs to be fixed?

#

However your thoughts are welcome @past night ^^

past night
#

i need to check that @steady stratus

#

i haven't completed my room yet kekw

quiet musk
#

M3talhead, there is only one way on to that machine. Uploading to the SMB isn't it unfortunately. It's a nice try though. ๐Ÿ˜Š
@patent token That being the case, is the vulnerable dialect the way in then? It was the first thing I thought of after I got a full enumeration. I'm familiar with ||the MS17_010 family of exploits||, but none are landing ||(even though NSE output indicated that SMBv1 is default)||. If this is a rabbit hole, it's a good one...

patent token
#

There are no kernel exploits. The executable you found is the answer. It associates with a port running on the machine.

#

That said, this portion is somewhat advanced and requires knowledge in that type of exploitation.

quiet musk
#

Right. The right enumeration returns a lot of information about that port. I can see in strings where the executable makes the call to that port as well. I'll dig deeper in the exe.

past night
vernal ridge
#

wait !

past night
#

the exploit it for 7.12.4 and the website is running 7.15.4

vernal ridge
#

actually the right execution made it work

patent token
#

M3talhead, you wonโ€™t glean much information from that outside of a link I didnโ€™t know existed.

#

The secret isnโ€™t inside the executable, itโ€™s what you do to it.

past night
#

oh shoot

#

yeah, just checked the services and it actually runs

vernal ridge
#

yeah it doess

#

and you can see the who are user(s)

quiet musk
#

M3talhead, you wonโ€™t glean much information from that outside of a link I didnโ€™t know existed.
@patent token Thanks! I just fired up the debugger and was about to deepdive. lol

past night
#

yeah i consider the impact is minimal so it should be fine @vernal ridge so i'll leave it as it is

vernal ridge
#

kinda yes!

past night
#

i'll let people struggle with it haha

vernal ridge
#

๐Ÿ˜†

quiet musk
#

@patent token ...when you say it's what you "do" to the file, you're not talking about modifying it offline and replacing it, right? Just asking for clarification since you mentioned in a previous reply that uploading isn't the way in. It's probably something stupid simple, I'm just overthinking it.

patent token
#

||itโ€™s a buffer overflow exploitation||

quiet musk
#

Nice rabbit hole! I noticed the ||\VBOXSVR\dostackbufferoverflowgood...|| in strings and the debugger but was going for the low hanging fruit first.

patent token
#

Not supposed to be a rabbit hole. ๐Ÿ˜› I didn't make the path completely obvious, but there is truly ONLY one way onto the machine, and one way to escalate privileges.

white salmon
#

Hi everyone, Room "Network Services" Task4/#8 "Now, use the information you have already gathered to work out the username of the account. Then, use the service and key to log-in to the server" > I have no clue on how to get John Cactus' password to ssh into the server.... any hints ? Did I miss something ?

stuck fractal
#

@white salmon Do you know about SSH keys?

white salmon
#

yes I got both of them

#

they are in .ssh

stuck fractal
#

Do you know what they do though?

white salmon
#

I think...i mean I tought

#

I have the id_rsa

stuck fractal
#

Explain to me what you think

white salmon
#

I have both John's public and private

#

I need the private to authenticate myself when I ssh

#

but I need a password right ?

stuck fractal
#

Ok, so why are you asking how to get the password?

#

No

#

The SSH key authenticates you.

white salmon
#

OK i have done something wrong then

stuck fractal
#

Yep.

white salmon
#

do you agree that sometimes you need a password to ssh no?

stuck fractal
#

SSH keys can be passphrase protected

#

And you don't always have keys

white salmon
#

right

stuck fractal
#

There's a lot of ways you can authenticate to SSH

#

Username and password is one
Username and RSA key is another

white salmon
#

I'm confused with the password vs passphrase

stuck fractal
#

passphrase is for the RSA key

#

This key doesn't have it

#

A passphrase is for the cryptography. They're meant to be longer than a password.

white salmon
#

right...and I always use RSA

#

that's why I am used to looking for a pass

stuck fractal
#

That doesn't make sense

white salmon
#

Ok I will rtfm. I think i am confused

#

thanks for your help

stuck fractal
#

@white salmon You don't need a password to authenticate with an id_rsa

#

If you're being asked for a password, you're doing something wrong

#

If there's a big box that says permissions too open, make sure to actually read that and fix it

white salmon
#

ok

#

@white salmon You don't need a password to authenticate with an id_rsa
@stuck fractal thanks to you I just discovered "ssh-add" > i was always asked for my passphrase when I was ssh-ing to my server, now I am not anymore ๐Ÿ‘

stuck fractal
#

@white salmon Passphrase is for the key

#

It just decrypts the key

#

Password is for the server

white salmon
#

Yeah I know, but I think i never really paid attention to the difference between passphrase and password, and now I do

white salmon
#

I think I have identified a potential issue : the "id_rsa.pub" file is understood as a Microsoft Publisher file

#

therefore it doesn't find the public key and asks for a password. It is what I understood from the verbose mide

#

mode

inland onyx
#

Ignore me, wrong channel, wrong topic ๐Ÿ˜†

white salmon
#

no probs

quiet musk
#

Not supposed to be a rabbit hole. ๐Ÿ˜› I didn't make the path completely obvious, but there is truly ONLY one way onto the machine, and one way to escalate privileges.
@patent token Good job regardless...๐Ÿ˜†... I've gotten to the point where I can abuse and connect to the exe when it's hosted on the local machine, but when I swap the local IP in the exploit for the target IP, the target doesn't connect. Have you had this happen before? Same exploit, same listener.

#

I can DM screenshots if that helps...

patent token
#

So, there's one tiny detail you're probably missing in your dump.

#

If you need help on that specific part.

#

You'll have to scroll forward to that point though.

quiet musk
#

God I'm an idiot...

stuck fractal
#

@white salmon Nope

#

id_rsa.pub is the public key

#

You authenticate to the server with the private key

night rivet
#

is binex broken?

wraith marsh
#

is binex broken?
@night rivet I done it 2 weeks ago with no issue.

stuck fractal
#

@wraith marsh Task 8 onwards is an excessive step

wraith marsh
#

@wraith marsh Task 8 onwards is an excessive step
@stuck fractal I thought he was talking about the room called binex, my bad

stuck fractal
#

Oh wait

#

@night rivet I might be wrong

wraith marsh
#

The room called โ€œbinexโ€ works perfectly fine if thatโ€™s what heโ€™s on about

tidal sedge
#

If I remember correctly bof1 is the one that's broken(still doable but not suitable for beginners) ๐Ÿค”

wraith marsh
#

Yeah, someone posted a write up for bof1. It looks like You have to rewrite the shell code.

silent wasp
#

Need help for this for order only for room ccpentesting task 20 subtask 9
I have all i need to create a command i tested command and command work but when i submit the flag its say is not good but i know its is. Anyone that can help me DM only. I will supply my command and i just wont to tell if i am missing anything or its parameter positioning

stuck fractal
#

Ask for help here.

#

Ask your question.

#

It doesn't sound like it needs to be DMs

tidal sedge
#

@silent wasp No one is going to dm, if you want help from the community then ask here.

silent wasp
#

OK

#

Given the username "admin", the password "password", and the ip "10.10.10.10", how would you run ipconfig on that machine
this is my answer and its not good but it is.
smbmap -u 'admin' -p 'password' -H 10.10.10.10 -x ipconfig

stuck fractal
#

Change your quote type.

#

Question uses double quotes

#

So you should too

silent wasp
#

omg

tribal ginkgo
#

guys stuck at unix varient with $6$ , any hints

inland onyx
#

@tribal ginkgo Those questions are specifically designed to be easily Google-able, so Rule 13: Keep trying ๐Ÿ™‚

#

(If you get really stuck, try looking for example hashes for hash crackers)

tribal ginkgo
#

i get that $6$ is for sha512 kind , that we can configure

#

do i need to find the varient that comes with this default

#

@inland onyx thanks

quiet musk
#

@patent token Wow...that was a brutal room. I admit that I broke down and had to follow your spoiler to get past the BOF detail I missed. Was chugging right along with normal privec stuff too...right up until I needed to use the last tool to get creds (I was staring at the objects I received, not knowing what I'm supposed to do next with them). Back to the video and it all clicked.

Thanks for a great room!

patent token
#

Thanks for the words! Glad you got it done. ๐Ÿ™‚

#

Was it that one tiny detail that got it fixed for you M3talhead?

quiet musk
#

To get the callback, yes. I forgot about the payload path that was being used during testing. Was still using it when I was ready to hit the target.

After that, it was relatively smooth sailing until it came time to extract the final creds from the 4 loot artifacts. Might have gotten through it on my own with a little more time researching tools, but I was getting antsy and running out of time.

patent token
#

Hehe. Well, it doesn't matter if it's pretty or not. You got it done. Congratulations!

#

If you did it using the automated process, try doing it manually this time. ๐Ÿ˜‰

#

If you want more of a challenge with those creds.

#

There's another way to collect them.

quiet musk
#

I was starting down the ||NT.dat|| rabbit hole and spent a good hour trying to pull out usable info before I saw your note about going back to the exe. It definitely got me out of my comfort zone and forced me to A) fix things that I'd been avoiding {Wine .dll errors} on Kali, B) re-introducing myself to ruby, and C) getting "outside" native Kali tools.

patent token
#

Not actually meant to be any rabbit holes on the machine honestly.

quiet musk
#

I actually started my callback attempts using raw methods before it became apparent that my conversations were not going to go anywhere.

#

Though when that wasn't working, I did jump back into MSF and run the usuals for that target.

#

It was around that time you mentioned that creating uploads was not the ECP.

patent token
#

Here's the most important question. Were you able to learn anything from it?

quiet musk
#

Without a doubt.

patent token
#

๐Ÿ™‚

light dew
#

Hey any hints about flag1 and flag4 in the anthem box?

white salmon
#

@light dew Funny you ask as I've just completed that box.

light dew
#

It's so f******** slow

white salmon
#

Have you inspected the page in through detail?

#

As that's what I'd be doing.

#

๐Ÿ˜‰

light dew
#

I am doing the final part

white salmon
#

Oh I thought you said you were doing flags?

light dew
#

got a headache opening everything

#

that's why I am here for!

white salmon
#

The final part isn't the flags? Do you need assistance with the flags or the getting into the box?

light dew
#

Flags

#

i am in the box

#

looking for things

white salmon
#

Well user should be easy enough if your inside the box.

warm hemlock
#

Guys any help on the Peak Hill machine, im close to root flag I think
I just need a nudge on the right way
im enumerating the file in opt

stuck fractal
#

Find out what it does

warm hemlock
#

what it does is it requires an input in base64

#

and I have supplied it with all the possbile input even making a python script, but I get that it can't be grown on the peak fill farm

#

I googled peak hill farm, and I dont want to travel there ๐Ÿ˜‚

stuck fractal
#

Peak hill is a pun on pickle

#

The box has a theme

warm hemlock
#

I know that its something related to the python module PICKLE, we have done it in the very first step

#

but this peak_hill_farm file isn't doing any good, idk what to do im lost at it

stuck fractal
#

You're in hints

#

Look at the python documentation for pickle

#

Like, the first page

ashen laurel
#

im doing linux challenges, and on flag 32 you're supposed to ftp a file but it keeps refusing to connect, any hints please? :/

sweet relic
#

I'm on HackPark right now. Got a shell, got System but I'm too stupid to find the abnormal service. Any hints, please? ๐Ÿ™‚

#

I don't want to be spoonfed
I ran ||ps and searched the output with regex [a-zA-Z0-9\\]{16}\.[a-zA-Z]{3} to match the answer pattern.|| But still no success ๐Ÿ˜ฆ

white salmon
#

can someone give me a hint about which wordlist to use on Lian_Yu i got the first two flags

warm hemlock
#

Ok so i am very close to the root

#

@stuck fractal thanks for the helps

#

but I have just one last thing

#

and i cannot figure it out at all

stuck fractal
#

Can't cat the flag?

warm hemlock
#

i figured out the pickle payload

#

i cant get the flag

stuck fractal
#

John made it hard.

warm hemlock
#

I tried running the netcat

stuck fractal
#

cat all files in the dir

warm hemlock
#

i did

stuck fractal
#

Wait do you have a root shell?

warm hemlock
#

i did cat thee root.txt

#

no

#

i dont have the rootshell

stuck fractal
#

Get a root shell.

warm hemlock
#

so what I did was instead of using netcat to get a reverse shell on my machine

#

what I did was, i just did ls -la /root/ in the payload

#

and i can see the contents of the root directory, but I cannot cat it out

stuck fractal
#

Get a root shell.

warm hemlock
#

and I have done so many things with netcat but I cannot get a connection back

stuck fractal
#

Don't use netcat

#

You're interacting with a command line program already

warm hemlock
#

so i just get the shell using the payload in python ?

#

maybe sudo su - ?

stuck fractal
#

No

#

It's running as root

warm hemlock
#

yes it is

#

and i also tried sudo su -

#

and im in the root shell

#

but i cannot cat the root.txt

#

its weird file

stuck fractal
#

You won't be able to cat it

warm hemlock
#

yes idk why

stuck fractal
#

John put dodgy characters in the filename

#

So you can't address the file name

warm hemlock
#

exactly ive been enumerating that

#

and im stuck like what should I do ?

stuck fractal
#

...

#

cat all the files

warm hemlock
#

OMG

#

im so stupid

#

@stuck fractal Thank you

#

I JUST COMPLETED

wispy verge
#

hello, may i take a help to solve python challenge?

inland onyx
#

Don't ask to ask, just ask ๐Ÿ™‚

stuck fractal
#

@wispy verge Are you looking for help or hints?

wispy verge
#

help

stuck fractal
wispy verge
#

oki doki sorry

stuck fractal
#

Lian yu, tried gobuster with dirb big and dirbuster medium and found a hidden page but nothing that matches what I'm looking for or gives me more info. And hints?

oblique dagger
#

I'm in the same boat James is in.. any little tid bit would be greatly appreciated

stuck fractal
#

ATM i'm just combining all the info I found

#

And getting nothing

oblique dagger
#

I'm in the same boat... I found the webpage and I believe I can post something to it but not sure if I'm on the right track..

stuck fractal
#

You're further along than me

#

I found the main page, and one other

#

I aint finding anything

graceful sun
#

im suck at a point in the new box Lian_Yu i have the ticket and i was forsure thinking it was a ||youtube|| ext but cant figure out wth to do with it i tried burp couldent find any fields that looked like it could be put im just really stuck lol

stuck fractal
#

I found something!

oblique dagger
#

Nice!

stuck fractal
#

I found the dir with the numbers

#

So

#

Let's continue forever

oblique dagger
#

That's where I'm at.

white salmon
#

@graceful sun pls a hint on how to get the .ticket

oblique dagger
#

How did you find the ticket?

#

I'm at that site

stuck fractal
#

I continued to gobust

#

Forever

#

Eternal gobusting

oblique dagger
#

Fair enough.. letting her run even longer lol

graceful sun
#

do same thing you did to get to the first page that was hidden but add something @white salmon

#

if someone wants to PM me they can also

white salmon
#

at this point i might download new wordlists

stuck fractal
#

@white salmon Dirbuster medium

white salmon
#

i dont have that

#

i have big and common

oblique dagger
#

Are you on Kali?

white salmon
#

i try now

#

no

oblique dagger
#

Ah

stuck fractal
#

Get the wordlists

white salmon
#

im on arch

#

i thought big contained all the medium ones

graceful sun
#

is it too early for me to be asking questions on Lian_Yu

stuck fractal
#

Dirb wordlists aren't the same as dirbuster wordlists

#

@graceful sun You can always ask, you just might not get an answer

graceful sun
#

im suck at a point in the new box Lian_Yu i have the ticket and i was forsure thinking it was a ||youtube|| ext but cant figure out wth to do with it i tried burp couldent find any fields that looked like it could be put im just really stuck

stuck fractal
#

You have the ticket?

#

You don't have to send anything to the server

white salmon
#

found the ticket with the medium list

stuck fractal
#

Again, IDK how people are finding tickets

#

I found the page with the vid

#

From there, I found the creds with some more gobuster

graceful sun
#

wait your working on the box right now as well?

#

yes i have the ticket

#

nvm i found some help , thanks yall

oblique dagger
#

I feel like I'm overlooking something so simple.

stuck fractal
#

@oblique dagger ||A . in front of something related to computers has two meanings. Either a hidden file, or a file extension. Gobuster can do extensions||

oblique dagger
#

Gosh dangit.. I knew i was overlooking something.. lol thank you

stuck fractal
#

Got user

#

Got root

robust nymph
#

I'm hitting a wall on Task 3 in anthem, I feel like I'm running out of places to look for the RDP login, could I get a nudge in the right direction? I don't want a spoiler by any means

ruby chasm
#

Anyone here tried the gatekeeper buffer overflow yet? I feel like I'm getting close but they have some memory protection stuff to work around

stuck fractal
#

ASLR?

ruby chasm
#

SEH i think

stuck fractal
#

I mean I found a few articles about bypassing SEH

ruby chasm
#

yeah same. i think i'll get it ๐Ÿ™‚ learning a lot

past night
#

@robust nymph you already have the details. Read task3 q1 carefully

oblique dagger
#

@stuck fractal I've ran the medium wordlist on all three directories you find in the beginning with the ext but I still haven't gotten anything. Am I allowed to post my command here if I put it in a spoiler?

stuck fractal
#

403 doesn't mean you got a folder

oblique dagger
#

..

#

thanks..

stuck fractal
#

HTTP 403 is a HTTP status code meaning access to the requested resource is forbidden for some reason. The server understood the request, but will not fulfill it due to client-related issues. IIS defines non standard "sub-status" error codes that provide a more specific reason ...

robust nymph
#

@past night Okay, so it's from the creds I have, maybe I just have to modify it to work as a username?

white salmon
#

@stuck fractal I've ran the medium wordlist on all three directories you find in the beginning with the ext but I still haven't gotten anything. Am I allowed to post my command here if I put it in a spoiler?
@oblique dagger dm if you need help with gobuster

stuck fractal
#

oof third hand ping

white salmon
#

i wasted 3 hours using the wrong wordlists

stuck fractal
#

Dirbuster 2.3 medium works fine

white salmon
#

yep

oblique dagger
#

Thanks, with that little hint I was able to find the file I needed for the password. Much appreciated

robust nymph
#

In Task3 q1 is it suggesting RDP is not the way to go? I'm thinking I just don't understand domains and RDP enough

stuck fractal
#

@robust nymph Ignore domains unless you're doing AD stuff

#

If you log in to a machine that is part of a domain, you need to use DomainNameHere\UserNameHere as your username

#

It's just saying don't worry about doing that

#

Username = username

robust nymph
#

Ahh okay that makes sense, but brings me back to my original wall now lol

inland onyx
#

For that question, it also means drop the domain from the email address

#

So rather than logging in with <user>@<domain>

#

You'd log in with <user>

robust nymph
#

Ohhhhh okay, so I'm probably just trying to login with the wrong user. Thank you both of you

scenic bolt
#

Hello, i'm new to this site. Currently on the Learn Linux room, i'm stuck on the true ending task where i have to access the root/root.txt where i dont have the permission to.

  1. I have tried to look for accessible file which has contains password as its name, find nothing useful here
  2. I have tried to look for file contains root, find nothing useful too.
  3. Tried to access the etc/shadow/ and etc/sudoers but apparently no permission to that too.
  4. Tried to chmod the root folder, but still no good (have no permission)

Anybody could give me a hint on what might be to do?

Thanks!

stuck fractal
#

@scenic bolt Look for files belonging to each and every user

scenic bolt
#

Got it! Let me try out that one

robust nymph
#

Man... Idk if I was trying it totally wrong before. But after a fresh reset of the box the creds I failed with before worked like a charm. Finally RDP'd into the box

#

Sorry if thats out of place, just happy to finally get it lol

jolly mantle
#

hey, i got the ticket on lian yu and i tried all the bases (even with rots) to decode it with no success.. any hint?

stuck fractal
#

@jolly mantle You didn't try all the bases then

grand pivot
#

hello everyone

#

can you give me a hint for the new box lian_yu?

#

i cant find the directory for the first flag

#

i found one directory but is not what the flag needs

oblique dagger
#

Hey James, I got the password, I'm in FTP and would I be on the right track if I needed to look at the files inside my users home folder? Am I on the right track?

viral mason
#

gobuster in luan_yi is a bit pain in the ass i guess

jolly mantle
#

@jolly mantle You didn't try all the bases then
@stuck fractal i will try again.. as far im concerned ive tried base[32,58,62,64,85] yell_cat

stuck fractal
#

@jolly mantle DM me

jolly mantle
#

ok

stuck fractal
#

@oblique dagger There's a few files, grab all the non default ones. Look for hidden as well

oblique dagger
#

Ok cool I did. So I jsut need to keep attempting. Thank you

grand pivot
#

@viral mason ok, so i keep enumerating with gobuster

#

i guess

stuck fractal
#

@grand pivot directories can have other directories inside them

viral mason
#

@stuck fractal @grand pivot got something from medium in reaaaaaal white

grand pivot
#

i find the code word if thats what you mea

#

n

viral mason
#

yeah

#

๐Ÿ˜„

grand pivot
#

but i guess is not useful yet

stuck fractal
#

It comes in very handy

grand pivot
#

i need the... numbers?

viral mason
#

yup, we need numbers

stuck fractal
#

gobust the things you found

viral mason
#

progress %44 on medium lol

stuck fractal
#

Don't stop at 1 level

grand pivot
#

ok

#

thaks!

viral mason
#

@stuck fractal what do you mean

grand pivot
#

that i have to be recursive

viral mason
#

im not sure what i should understand from here lol

stuck fractal
#

/games contains /koth

#

Gobuster would find games

viral mason
#

yeah i got that

#

oohhhhhh

stuck fractal
#

/koth would be a second command in gobuster

viral mason
#

now we are on track

#

yeah

#

thanks james let me try it

#

im a bit sleepy i didnt understand at first sorry lol

#

yup, found it @grand pivot

grand pivot
#

yeah! me too

robust nymph
#

So I'm on the machine now, I'm lost trying to find the Admin password, I found ||/backup/restore.txt|| but do not have access, I turned on hidden files. Is it a file I'm looking for? or more of a privesc route?

vernal ridge
#

Am stuck on the crackme2(task 7 of Intro To x86-64), any help would be appreciate

verbal wedge
#

@white salmon nootnoot

#

I need a hint for the flag

viral mason
stuck fractal
#

@white salmon ^

#

@verbal wedge What box?

verbal wedge
#

nootnoot not the password

#

can confirm

#

Learn Linux

stuck fractal
#

no tag creator

#

just try harder

verbal wedge
#

no tag creator?

#

oh

viral mason
#

@stuck fractal any nudge for ftp username?

stuck fractal
#

Don't tag the room creator because you're struggling

#

@viral mason Codeword should have been codename IMO

viral mason
#

let me search further

white salmon
#

What did para do

#

@stuck fractal

stuck fractal
#

@white salmon the YouTube link. Open it.

viral mason
#

LOL

#

everybody loves noot noot

verbal wedge
#
[*] ret020 Cron jobs....................................................... yes!                     
---                                                                                                               
/etc/crontab:SHELL=/bin/sh            
#

This looks suspicious

scenic bolt
#

@scenic bolt Look for files belonging to each and every user
@stuck fractal Thanks for the advice, solved it!

white salmon
#

I've watched that compilation too many times

stuck fractal
#

@verbal wedge you're not going to get root on learn linux with linenum or linpeas

white salmon
#

I mean

#

He theoretically could

verbal wedge
#

yeah im stuck

viral mason
#

@stuck fractal thx james got it

white salmon
#

hello pls hint at ||hiden|| in room madness

viral mason
#

@white salmon you mean the one with secret?

white salmon
#

yah

stuck fractal
#

@white salmon that was fast.

viral mason
#

um after ||checking the source code, you can see that it's between 0-99||

#

then, you can either do basic python scripting

#

or manually try it

vernal ridge
#

Can anyone help with the last task in INTRO TO x86-64

viral mason
#

but i suggest you to do the scripting, it can teach you something if you dont know it

#

even you know it, it would be a nice practice on get requests

verbal wedge
#

Yep I'm stuck on getting the flag here for Learn Linux

viral mason
#

optional really did a great job with madness btw

#

i really liked that room but by the same time i really said you crazy .... when the rot thing happened lol

#

@verbal wedge i want to help but i dont remember what i did on that one

verbal wedge
#

im really stuck

stuck fractal
#

@verbal wedge which part?

verbal wedge
#

getting the flag lol

viral mason
#

dude

#

check muir's writeup

#

there's a writeup for that one

stuck fractal
#

@verbal wedge look for files belonging to each and every user

white salmon
#

so uh im stuck... i got the thing and now idk what to do with it .. hint ?

stuck fractal
#

@white salmon ask questions better jeez

white salmon
#

its done ๐Ÿ˜‚

patent token
#

Saw a question a little bit ago about Gatekeeper. There are no ASLR memory protections in place on that machine/challenge.

#

If you're seeing that, you're doing something wrong.

stuck fractal
#

@ruby chasm

#

No. But wrong channel. @viral mason

viral mason
#

oh shoot i forgot i was on community-hints

#

sorry

inland onyx
#

He's not banned. Looks like he left though

viral mason
#

thanks @inland onyx

woven pumice
#

could you give me a hint for the box [Lian_yu]
I got password for ssh, but I can't find the username...

stuck fractal
#

@woven pumice there's a hidden file on FTP with a short story

#

A few potential usernames in there

#

ls -a to list hidden files works in FTP as well

woven pumice
#

@stuck fractal thanx! i didn't search hidden one

#

I'll try it!

stuck fractal
#

You should always look for hidden files

white salmon
#

Hi guys! What kind of hint could you give me for the room : Wgel CTF

#

I already have the ssh key

#

But can't connect to it. The ssh2john tell me there isn't any password

#

I'm sure I miss something else

solemn smelt
#

thats good that means the ssh key doesnt need one just use it to ssh into the machine now

white salmon
#

I tried

#

But it asks me for a password

#

I used the flag -i to specify the id_rsa file

#

As you can see on this capture

solemn smelt
#

I believe you may have to change the premissions of the id_rsa

white salmon
#

I did it too, set it to 600

solemn smelt
#

oh you have to specify the user youre trying to ssh as

#

if you dont know I would suggest further enumeration

white salmon
#

Ok, that's what I thought, I miss information

#

I'll continue to search for something like this

shut whale
#

help with a flag in learning linux, i swear i have the answer but its not accepting it.

#

task 12 im switching shells to shiba2 but the password that was correct in task11 will not work.

left salmon
#

"environment variable"

#

su automatically connects you to su (with the password)

#

try typing ls

#

and you'll see shiba2

#

@shut whale

shut whale
#

but im doing su -s shiba2

#

and it asks for shiba2 pass

regal vessel
#

hello everyone,can you give me a hint for the new box lian_yu?
i cant find the file name with SSH password.

shut whale
#

i got the pass from ./shiba2 but it says its wrong

north moat
#

@regal vessel did you do stegh to find SSH ?

spice harness
#

any hints on "CC: Radare2" room on the_final_exam binery

marble dagger
#

need a hint on lian_yu for finding the SSH password. I can see the hidden files and got the pictures but I can't seem to get anything out of it. tried steghide, but I don't have the passphrase. any hints?

neon acorn
#

@marble dagger maybe you can guess or brute that passphrase

indigo ridge
north moat
#

@neon acorn means Stegh not help to find ssh ?

indigo ridge
#

need a hint on lian_yu for finding the SSH password. I can see the hidden files and got the pictures but I can't seem to get anything out of it. tried steghide, but I don't have the passphrase. any hints?
@marble dagger hey.. if you are doing the same room can you tell me something about the 2nd task..

sinful plaza
glossy basin
#

it's not the tool problem

#

try different wordlists

sinful plaza
#

medium you know

north moat
#

@sinful plaza Stegh help us to find SSH ?

sinful plaza
#

@sinful plaza Stegh help us to find SSH ?
@north moat which task are u stuck??

north moat
#

#5

sinful plaza
#

it's not the tool problem
@glossy basin medium is the way forward lol

marble dagger
#

@indigo ridge did you try dirbuster or gobuster?

glossy basin
#

yeah, i know

sinful plaza
#

#5
@north moat found images already???

#

im also on LianYU - for some reason the ||Leave_me_alone.png doesnt open...|| i think that may have something in but binwalk doesnt find anything file magic number
@potent quail

past night
#

remove the spoilers

#

talking to @potent quail

sinful plaza
#

remove the spoilers
@past night sorry done

potent quail
#

ah sorry

past night
#

yeah, it's fully related to the answer

potent quail
#

ah ok

regal vessel
#

yeah, it's fully related to the answer
@past night I modified the file header of the image file, but only a little content is displayed, is this normal?

north moat
#

@sinful plaza i fix that file , its Mp4 but not play anything

sinful plaza
#

@sinful plaza i fix that file , its Mp4 but not play anything
@north moat not mp4 it a image

regal vessel
#

is png right?

@north moat not mp4 it a image
@sinful plaza

north moat
#

yes , but i mean inside that png .

sinful plaza
#

yes , but i mean inside that png .
@north moat ||go after jpg||

#

is png right?
@sinful plaza
@regal vessel ||go after jpg||

north moat
#

can i dm ?

sinful plaza
#

sure bro

potent quail
#

mind if i DM quick please?

north moat
#

sure Dm Me @potent quail

white salmon
grand pasture
#

I dont know any file extensions that have 6 characters

#

So im not sure what to search with the dirb

warm schooner
#

You don't need dirb to find the extension, simple enumeration of a webpage will help you find the filetype

grand pasture
#

Oh i tried that but it was taking ahes

#

So i found task 1 and 2

warm schooner
#

For the file type, you only need fuzzing and inspect element

grand pasture
#

Ahh ok thanks

#

And I'm not sure what the code word is helpful for yet, but maybe it will be later lol

warm schooner
#

That will come in later, I think for Q5

grand pasture
#

Ah ok thanks

#

First time doing a medium level room aswell

#

Abit of a challenge so i thought y not lol

north moat
#

im done Lian_Yu Room

grand pasture
#

Oh dam everyone too quick

viscid mason
#

yeah! โค๏ธ community!

warm schooner
#

First time doing a medium level room aswell
@grand pasture It's ranked as an easy room

grand pasture
#

Oh,? I thought the thingy was orange rather then green

#

Oh no if its supposed to be easy then I think im not supposed to be stuck lol

#

@warm schooner What wordlist should i use with dirbuster to find the file? Because it's been going for a while and its still not found it ๐Ÿ˜ฃ

warm schooner
#

I used 2.3 medium

grand pasture
#

Ok I was using small

warm schooner
#

The wordlist shouldn't matter too much as you're looking for numbers

grand pasture
#

Numbers?

#

Oh