#room-hints

1 messages ยท Page 45 of 1

wind fog
#

nope, still gave me 300 results

trim haven
#

No

#

find / -name '*release' 2>/dev/null

#

When using single quotes it's basically saying "only search for this string"

wind fog
#

nope, still gave me 300 results ๐Ÿ˜ญ

trim haven
#

Wut

wind fog
trim haven
#

Oh shoot

#

my b

stuck fractal
#

Escape the asterisk

wind fog
#

any advice ninja?

stuck fractal
#

Find treats it as a pattern

trim haven
#

I misseed the \

#

find / -name '\*release' 2>/dev/null

wind fog
#

so '\*release'?

trim haven
#

Sorry I pasted what was on clipboard and not what I was typing on my commandline

#

find / -name '\*release' 2>/dev/null
@trim haven cough

trim haven
#

Are you the wrong user

#

Let me check the room

#

You are not the correct user I believe.

wind fog
#

i only have two, bob and garry

#

at least I think

trim haven
#

HOld on

#

What task are you on

wind fog
#

task 3

#

question 5

trim haven
#

Switch to bob

#

And try again

oblique cliff
#

you rang?

trim haven
#

Wrong bob kekw

oblique cliff
#

๐Ÿค“

wind fog
#

๐Ÿ˜ฎ

#

nope, nothing for Bob either

trim haven
#

I'll boot up the machine 1 second

wind fog
#

gimme a sec

#

imma go take a dump

#

ill be back soon

trim haven
#

You didn't read the question

#

You do not need to use find

#

The question states:
Can you find information about the system, such as the kernel version etc.

rose root
#

Hi. Need some help with jack room. I foud credentials for one user, but this is low level one. He cant manage plugins or templates. Can you give me some hint what sould I do next?

trim haven
#

By literally copying and pasting that into my browser I found a directory, then I was able to go into the directory and find the *release file.

stuck fractal
#

Hi. Need some help with jack room. I foud credentials for one user, but this is low level one. He cant manage plugins or templates. Can you give me some hint what sould I do next?
@rose root Check the hints on the room, it points you at an exploit

trim haven
#

Obama I'd suggest you research more...

rose root
#

thanks

wind fog
#

Hey lads

#

im on Linux challenges, task 4, and have gotten stuck on a question

#

I've been researching C in linux for the past hour and still have no clue what I could do to find the flag

#

if someone could just give me a clue or a hint that would be great

stuck fractal
#

strings look into that instead

wind fog
#

thanks man, imma go research that now

#

cool got it, thanks for the hint man

rose jasper
#

Room: Linux challenges
Flag - 26
How do I solve?
I tried using this but it is returning nothing
find / -size 32c -name โ€œ4bceb*โ€ 2> /dev/null

oblique cliff
#

have you done the room thefindcommand?

#

the -name flag is looking for the name of a file

#

so youre looking for a file of the name 4bceb, which isnt what you wanna be looking for

rose jasper
#

Thanks
I havenโ€™t read the question properly

hardy matrix
#

im on the linux room and i don't have permission to use mkdir is there another command i could use?

stuck fractal
#

You're the wrong user

#

Or in the wrong dir

final mortar
#

You probably are logged in as the wrong user and dont have the permission to make a dir in that particular place

#

How are you so fast james NotLikeThis

stuck fractal
#

Expensive keyboard

hardy matrix
#

ill try on the other users

stuck fractal
#

Go home

final mortar
#

If you changed the user successfully, you may be in the old user's home directory which you dont have permission to access. cd ~ brings you to your home directory, or just cd

rocky forge
#

BP-networking room predominant addres reserved for router

stuck fractal
#

Google will find that

rocky forge
#

I tried but all answer where going incorrect

stuck fractal
#

Keep looking then

#

name for router ip in network that was easy

rocky forge
#

No third predominant address type reserved for router

#

A third predominant address type is typically reserved for the router, what is the name of this address type?

#

Question 10

rocky forge
#

Anybody know the answer of it

#

I have tried all possible answers

stuck fractal
#

I have tried all possible answers
@rocky forge You have not

#

We do not give out answers here.

#

I have you an exact google search query that would have got you an answer

rocky forge
#

Yeah itired exact query

stuck fractal
#

Then try changing it slightly

#

The answer is very easily found on google

rocky forge
#

Can share link where I can find it

final mortar
#
autumn rivet
#

For Overpass room. There's a golang code which seems to be the key but it's not loaded on opening any web page. Is there a way to run a go method in console

stuck fractal
#

For Overpass room. There's a golang code which seems to be the key but it's not loaded on opening any web page. Is there a way to run a go method in console
@autumn rivet Golang is a compiled language, so no

#

But that's a huge rabbit hole

rocky forge
#

I was not able find

random thunder
#

What encoding is used for cookies?

stuck fractal
dark salmon
#

Hi i was trying introtox8664 im completely new, i understood some basics and started with radar2 If-statement-Continue section have 4 questions all are at same positions, i mean value of 3 variable before pop and return, i ds before the pop up and entered the value all 3 got success but the value of var_8h is not accepting, the value which i was getting is 60, before pop but it shows wring answer, can anyone help me?

white salmon
#

Make sure you are reversing the correct file

#

It teaches you in file1 and asks you to reverse file2

dark salmon
#

yeah i did on file 2 only

frank dirge
#

Trying to complete the JVM Reverse Engineering room. Stuck with the Advanced String Obfuscation. Do I need to use virtually call the string functions from other code or I need to manually reverse engineer the code?

dark salmon
#

because all other values are accepted bro

white salmon
#

let me check 1 sec

#

60 is wrong answer try harder

#

Do you mind posting screenshot of the disassembly because I am not in my vm

dark salmon
#

i need to check the value of var_8h before pop right? i checked by px @jagged scaffoldp-0x8, while assigning value it was 63 after performing And operation when i check by px @jagged scaffoldp-0x8 the value at 0th offset is 60, after pop operation i check for the same now it was 00

#

where i went wrong

white salmon
#

bruh

#

its 60 in hex

#

it means its 96

dark salmon
#

oh this itself i dono, so what should i study for this?

stuck fractal
#

"what is hexadecimal"

white salmon
#

Its just how r2 displays it , actually its stored in binary

dark salmon
#

Thanks bros

#

My questions may be very low levels but just now im started thats y

stuck fractal
#

Not your bro.

trim haven
#

Uh oh

white salmon
#

@dark salmon You did good

trim haven
#

We all start somewhere!

dark salmon
#

๐Ÿ˜

gaunt herald
#

Since chat lest with room with introtox86_64
How to change the local variables? Or insert new lines of code? I remember someone in here gave the answer, but forgot ๐Ÿ˜

white salmon
#

You shouldn't need to change local variables or new lines of code in introtox86_64

#

Although if you're curious on how to do that, it's covered in the radare2 room

gaunt herald
#

Then I need to reread the crackme2 <_<
Ooohhh, yeah!! I remember about it! Thanks!!

white salmon
#

A big hint for crackme2 is that, the password is there, but the program does something to it

#

it only does one function to it if that helps

white salmon
#

help for mr robot CTF im new in this and i want to learn about it can someone help me please?

gaunt herald
#

https://tryhackme.com/room/zthlinux
Start somewhere low and then go on harder machines, if you got down a rabbit hole then use the hints, if no hints available on that task then look writeups

white salmon
#

but there is a litle problem

#

i have a windows on my notebook

gaunt herald
#

Okay

white salmon
#

so i dont have to learn of Linux when i have windows?

wraith tapir
#

The room you are trying to solve is linux based

white salmon
#

i know

#

oh you mean the Mr Robot CTF is linux based?

wraith tapir
#

yeah

white salmon
#

oh sorry my bad

#

thanks for information

#

do you know som windows based room?

#

easy room please

gaunt herald
#

Ice, blue

wraith tapir
#

good for starters

#

+=Blaster

gaunt herald
#

Well... you'll need to complete the 'rp: metasploit' room first to get a hand with it.

white salmon
#

ok thank ya

#

sooo metasploit is tool like an NC or something like this?

gaunt herald
#

Finish the metasploit room and you'll see :)

white salmon
#

ok

white salmon
#

ehhhhh i have a problems with the app

#

can someone help me please?

final mortar
oblique cliff
#

Can you be more specific please?

white salmon
#

yes sorry

oblique cliff
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
white salmon
#

ok sorry

#

i have problems with the ap Metalsploit in instaling proggres . The app instals but i cant see the app anywhere

trim haven
#

Type msfconsole into a terminal

final mortar
#

msfconsole -q blobknife

white salmon
#

nothing happens

trim haven
#

You havenโ€™t installed it..?

#

sudo apt install metasploit

#

What OS are you running actually?

white salmon
#

windows

trim haven
#

Oh

#

Well I canโ€™t help you there

white salmon
#

can i somehow change OS on laptop??

trim haven
#

You need to run the .bat executable

final mortar
#

Why sink deeper in the hole though

#

Get a vm running

white salmon
#

oh thanks

final mortar
#

can i somehow change OS on laptop??
are you familiar with the concept of virtual machines ? If not you can search for Vmware and how to use it

oblique cliff
#

@white salmon yea as they suggested Iโ€™d recommend using a kali vm at least to start ๐Ÿ™‚

white salmon
#

i have instaled kali

final mortar
#

Why did you answered with windows when jabba asked for your os

white salmon
#

bcs i dont using kali bcs i dont know how tothrow it back from kali to windows

final mortar
#

What do you mean I dont know how to throw kali back to windows

#

You installed kali in a virtual machine ? on windows host ?

oblique cliff
#

You can do all the exploiting on kali for now thereโ€™s no need to get anything back to your windows machine (for now)

white salmon
#

sooo

#

i have to change the OS of my computer to kali yeah?

final mortar
#

No one said that

#

I said to use a virtual machine, so you can use kali inside of your windows os

white salmon
#

ohhhh

#

sry my bad

#

my english is bad at this

#

sooo i have to run a virtual machine with kali yeah?

final mortar
#

Yes

white salmon
#

but that costs money

final mortar
#

Community version of VMware is free

#

VirtualBox, an alternative to VMware is free

white salmon
#

thanks

final mortar
#

Kali Linux is free

white salmon
#

thank ya

grave rain
#

Why do we have to install nessus in a vm

#

^just asking

#

Is it fine to install into an os like parrot?

#

Without the vm*

final mortar
#

Yes

grave rain
#

Thanks :)

#

So its just that windows isnt recommended right?

final mortar
#

you can install on windows, but what's the point of separating your tools b/w Linux and windows when you have to use Linux anyways

grave rain
#

Yaa obv wont do that

#

But in the room it said it was highly recommended in a vm and all

#

Anyways fine ๐Ÿ‘

white salmon
#

how i put kali in virtual box please?

trim haven
#

This is for rooms only.

white salmon
#

oh sorry

oblique cliff
#

@white salmon very googleable, lots of guides out there for that ๐Ÿ™‚

white salmon
#

im stuck in Metasploit Task 2 question 6

trim haven
#

That's not helpful

oblique cliff
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
trim haven
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
oblique cliff
#

hehe

white salmon
#

At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?

trim haven
#

Too fast for me, Sir tipsfedora I'll let you handle this.

white salmon
#

i typed the stage?

oblique cliff
#
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
white salmon
#

the Metasploit cant connect to data service and i dont know why

oblique cliff
#

so then youre stuck on question 5, not question 6, right?

white salmon
#

sorry

#

yeah question 5

oblique cliff
#

were you able to successfully complete all the questions before that?

white salmon
#

yeah

oblique cliff
#

so question 1, initialize the database, that worked?

white salmon
#

yeah

oblique cliff
#

can you show the output of when you do the db_status command please

white salmon
#

yeah no problem

#

postgresql selected, no connection

#

print screan not working

#

but that it types

oblique cliff
#

yea, thats all you need actually

white salmon
#

what??

#

i dont get it

#

soo

oblique cliff
#

the questions asked in the room

white salmon
#

oh

#

ok

#

so this is right?

oblique cliff
#

uh, im not sure what the connection status is supposed to be, but you can answer the questions in the room with what you see

#

@white salmon

white salmon
#

oh sorry for losing your time

final mortar
#

You can't loose his time, you can loose your time and you can waste him time

#

but you didn't wasted anyone's time ๐Ÿ™‚ Keep asking

trim haven
#

Learning is not wasting time :D

#

We're here by choice ask away ;)

final mortar
#

Jabba help stuck

#

need to hack google

trim haven
#

Uhh

#

Reverse the url then append it to a binary and hash it

tidal sedge
trim haven
#

Broke Malware's brain kekw

tidal sedge
#

No your statement doesn't make any sense, how can they hack google by appending the url to a binary and hashing it? tryharder ๐Ÿ˜€

trim haven
#

You tell me ๐Ÿ˜ญ

final mortar
#

๐Ÿง

oblique cliff
#

worked for me last night ๐Ÿค”

tidal sedge
#

Send proof blobknife

trim haven
#

Yeah here's your password-

oblique cliff
#

deleted all my traces ๐Ÿ‘€

final mortar
#

you are assuming he has a google account

trim haven
#

I'm not assuming, I know ๐Ÿ˜Ž

final mortar
#

( โ€ขฬ€ ฯ‰ โ€ขฬ )y

white salmon
#

If he sent you proof, then that'd be incriminating himself, duh

tidal sedge
#

He hasn't pleaded the fifth yet so ๐Ÿคท

oblique cliff
#

i plead the 50th

#

which is 10 times stronger than the 5th

final mortar
dark salmon
#

HI team i was newly working on reverse engineering, on this room i was trying to reverse the binary and to find the password, if you enter right password it prints some success message. but my problem is previous sections teaches me about the If conditions & Loops, initially i tried with general procedure of what they teaches but no luck for me, i dont need an answer, i need guidance can someone help me

#

Room: introtox8664

heavy anvil
#

you need to keep track of jump instructions

oblique cliff
#

@dark salmon which part is that?

sharp ether
#

Hey there

#

i am on toolsrus room

#

i m stucked in the part that is meant to be solved with nikto

trim haven
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
sharp ether
#

"Use Nikto with the credentials you have found and scan the /manager/html directory on the port found above.

How many documentation files did Nikto identify?"

#

and i get this output:
"- Nikto v2.1.5

  • Target IP: 10.10.28.208
  • Target Hostname: 10.10.28.208
  • Target Port: 80
  • Start Time: 2020-07-25 12:24:00 (GMT-3)

  • Server: Apache/2.4.18 (Ubuntu)
  • The anti-clickjacking X-Frame-Options header is not present.
  • No CGI Directories found (use '-C all' to force check all possible dirs)
  • Allowed HTTP Methods: OPTIONS, GET, HEAD, POST
  • 6544 items checked: 0 error(s) and 2 item(s) reported on remote host
  • End Time: 2020-07-25 12:51:33 (GMT-3) (1653 seconds)

  • 1 host(s) tested"
green prism
#

@dark salmon for RE i could help you out, tho if you want someone more experienced ask @oblique cliff

oblique cliff
#

If you want my master ask @white salmon but Iโ€™m always happy to help ๐Ÿ™‚

white salmon
#

๐Ÿ‘€

final mortar
#

Only I can send blobfingerguns ๐Ÿ˜ก

green prism
#

@white salmon wait smackhack you into RE?

final mortar
#

Dont tag anyone in a normal follow-up conversation ๐Ÿ™‚ Thanks

white salmon
#

yeah i did it maybe once or a lot

green prism
#

that's pretty ambiguous

#

lol

white salmon
green prism
#

maybe that one time you did it made you understand it completely ๐Ÿค”

#

quantum i'll keep that in mind

sharp ether
#

and i using the next cmd:
"nikto -id user:pass -h http://ipmachine/manager/html -p 1234"
It wasn't working because i have to put the port inside the URL, solved

white salmon
#

HI team i was newly working on reverse engineering, on this room i was trying to reverse the binary and to find the password, if you enter right password it prints some success message. but my problem is previous sections teaches me about the If conditions & Loops, initially i tried with general procedure of what they teaches but no luck for me, i dont need an answer, i need guidance can someone help me
@dark salmon
My biggest advice for RE if you're not comfortable reading static assembly code is to take advantage of the debugger and set breakpoints before critical points. You know it's a password check, so look for all the functions and parts of the code that seems to relate to "checking for a password". Identify the registers that contain your input, and identify the registers that also keep track of the password possibly

#

If you see a loop, that usually means some kind of function is being performed, possibly arithmetic or something, especially if it repeats more than once

#

it's good to inspect the registers before a loop, and after a loop to see what the difference is, and see if you can identify a pattern

green prism
#

this is exactly what i did to solve the final task of the radare2 room

hasty slate
#

@dark salmon
My biggest advice for RE if you're not comfortable reading static assembly code is to take advantage of the debugger and set breakpoints before critical points. You know it's a password check, so look for all the functions and parts of the code that seems to relate to "checking for a password". Identify the registers that contain your input, and identify the registers that also keep track of the password possibly
@white salmon i thought this was for the room RA, and was confused for quite a while.

white salmon
#

LMAO

lone scroll
#

hi, if i have a qustion about the room "learn linux"

#

where i can ask it?here?

green prism
#

sure

lone scroll
#

aehh ok..i`m new here and just want to know..

#

ok my qustion is about the task11

#

first, i don`t understant where i need the run the machine..how i need to run the shilba

#

i just make a TXT file in my machine and don`t get any password haha

stuck fractal
#

Task 1, click the deploy button

#

Task 4, walks you through connecting to that machine

green prism
#

usually tasks should be done in order

#

so you don't miss out on anything

lone scroll
#

ok thanks

carmine sphinx
#

hey, im at the "learn linux". i'm not understanding the consept of a file having a user and a group (i'm in the task 25). Like why would i change the user and not group, what would it change? Can someone explain it for me?

white salmon
#

There is only one user for a file, but a group can have several different users in it.

#

A good practical example would be if you wanted to let everybody work on a project at once, you would put them in the same group and every directory/file that they're working with can be interacted with by other members in the same group (depending on the perms on the file/directory)

carmine sphinx
#

hmmmm yeah makes sense, thanks alot ๐Ÿ™‚

white salmon
#

hey, im stuck at the task 5 question 1 in Metasploit can someone help me please?

stuck fractal
#

What have you tried?

#

There's no answer

#

So why are you stuck?

white salmon
#

because the comand does not working

stuck fractal
#

That's far too vague

white salmon
#

what?

stuck fractal
#

because the comand does not working
@white salmon Explain.

white salmon
#

oh

#

the comand output is Database not connected

#

but i have connected mi database

stuck fractal
#

Clearly not tho

white salmon
#

when i type db_stats output says

#

postgresql selected, no conection

stuck fractal
#

So you're not connected to the database

white salmon
#

but

#

i dont know how to repare it

stuck fractal
#

#general for fixing your metasploit. That's outside the scope of the help channels here

white salmon
#

ok

#

but in general is random chat

stuck fractal
#

It's also help outside the scope of the help channels

#

Which your issue is now.

crystal glade
#

@white salmon How about search on google it will help you solve the problem with metasploit

white salmon
#

i have searched. nothing helps me

crystal glade
#

btw you can use nmap

white salmon
#

when i type nmap and hit enter it types unkown command :nmap

crystal glade
#

check pm

#

@white salmon i texted you

robust nymph
#

Hey folks, I'm on the new Brooklyn 99 room, getting this error back. ||steghide: can not uncompress data. compressed data is corrupted.|| Is this intended? If so any hints on how to fix the ||corrupted data||? Google is mostly showing me windows applications to solve it

gusty ermine
#

@robust nymph try ||stegcracker||

robust nymph
#

Didn't expect that to be the way, thank you @gusty ermine

gusty ermine
#

no problem man

white salmon
#

uh that's the other way

remote yarrow
#

hello just with root that will is it the best idea to use GTOFBins

#

to get sudo

#

or there is other best website

stuck fractal
#

programName priv esc into google

#

Varies by room

robust nymph
#

Now I'm feeling really dumb, have creds to log in but I must be getting the username wrong? I've tried many variations of ||Holt, Holts, Jake, Amy|| Can't figure out where this password goes besides ||ssh||

white salmon
#

What variations did you try

remote yarrow
#

@stuck fractal thnx

robust nymph
#

||Holts, Amy, Holt, Ray, Jake, holts, jake||

white salmon
#

In that list one of them is right

robust nymph
#

I guess that's not as many tries as I thought lol

#

Hmm okay

#

I'll keep trying thank you

white salmon
#

Also it literally says which user has weak pass

robust nymph
#

@white salmon could I pm you a question?

white salmon
#

@white salmon could I pm you a question?
@robust nymph sure

carmine frigate
#

hey did any one complete the "Brooklyn Nine Nine" room?

gusty ermine
#

yep

carmine frigate
#

im stuck on the stego part can you give me a hint?

gusty ermine
#

||brooklin99.jpg||?

carmine frigate
#

yes

#

i cant seem to find any info in the image

gusty ermine
#

@robust nymph try ||stegcracker||

carmine frigate
#

thanks!!

remote yarrow
#

dm me for any question about brooklynninenine (rooted) Hints!!

rapid flower
#

Easy peasy room... It is... Brooklyn 99... initial foothold matters though ๐Ÿ˜…

white salmon
#

how do i access a directory that is locked?

#

i mean,without root account

rapid flower
#

@white salmon privEsc

white salmon
#

what's?

rapid flower
#

You need to escalate your current privileges to root level

white salmon
#

i cannot do nothing so access this directory without root

rapid flower
#

What challenge is that?

white salmon
#

learn linux

stuck fractal
#

Learn Linux task 43

white salmon
#

final quest

stuck fractal
#

You need to get root privileges

minor trellis
#

does anyone have any hints for SET box? I'm dying here ๐Ÿ˜…

hardy matrix
#

anyone have a hint for the last task in learn linux

trim haven
#

Look for who owns what files

#

Maybe you can come up with a find command to aid your discovery.

hardy matrix
#

thanks

#

thanks i got it

trim haven
arctic crystal
#

Hey can anyone help me with Brooklyn 99

#

I'm not able to escalate my privilege

#

I want some hint on how to escalate my privilege

trim haven
#

It is a new room, not many people have completed it. You might have to wait a while, whilst you're waiting keep trying!

scenic atlas
#

Privesc on Brooklin99 it's pretty straightforward. Just keep trying and you'll get there

arctic crystal
#

Yup got it

white salmon
#

could I get a hint for the last bonus question on the Agent Sudo room?

oblique cliff
#

Enumerate the machine more

#

Pretty sure you already saw it when you answered a previous question @white salmon

white salmon
#

ohhhhh, you're right. didn't make the connection lol thanks

#

lol i'm lying i just didn't bother to read the message xD

teal merlin
#

hi im new to this and trying to figure out how to find the answer this question "After accessing his account, what did the user mcinventory request?" i dont want the answer just some help on how to get to it. its on the 1st problem of the Christmas thing
thank you

stuck fractal
#

Log in as that user

#

then you see it

teal merlin
#

damn thats easy lol thank you

past edge
#

hey guys i need help cracking password

#

hashcat -a 0 -m 0 cc3a0280e4fc1415930899896574e118 /usr/share/wordlists/rockyou.txt.gz --force

#

and it says that i exhausted the keyspace

#

pls tell me what i do wrong

wooden mist
#

rockyou.txt.gz

#

the text file is compressed

#

uncompress it first

past edge
#

ah

#

okok

#

thankies

#

it doesn't seem to fix the issue

#

@wooden mist

wooden mist
#

don't use --force

#

it produces false-positives and false-negatives

#

if hashcat doesn't want to run without --force then use john

past edge
#

is there a problem with my hashcat

#

?

#

it runs --benchmark just fine

wooden mist
#

ยฏ_(ใƒ„)_/ยฏ

#

force is bad

red arch
#

just finished Brooklyn99 Final, does the brooklyn99.jpeg have any meaning? ||I tried using steghide but it told me the compressed data is corrupted, also used some online tool for it and it gave me some gibberish. Im pretty sure its the second way to get root access, could you give me a hint?||

latent jungle
#

Hi Team, I have a doubt in Basic Room called Goodle Dork Room -
What is an example of the type of contents that could be gathered from a website?

#

Any Hints can really Help me

#

Example of Type of Content - can be metadata or Any Text type or image or vedio

stuck fractal
#

I recommend reading back through the material

latent jungle
#

oh

stuck fractal
#

Because it answers all those questions and it's an assessment of your reading skills

latent jungle
#

I see Understood

#

Thank yoiu

crisp wigeon
#

@red arch you can read the above chats for the second way

indigo ridge
#

just finished Brooklyn99 Final, does the brooklyn99.jpeg have any meaning? ||I tried using steghide but it told me the compressed data is corrupted, also used some online tool for it and it gave me some gibberish. Im pretty sure its the second way to get root access, could you give me a hint?||
@red arch yes i just used that..

#

pretty simple

restive cloak
#

Morning all (at least over here it is ๐Ÿ™‚ ) I am just about to finish the Skynet piece but I would like a bit of advice. On the CMS login I found some commented out code that gives you the oportunity to reset password. I managed to get it to appear and added my skynet email address, but I never received an email. I tested the squirrel mail and it works fineas I can send and receive to myself. Should I continue try for practice or is this a bit of a rabbit hole?

latent jungle
#

Because it answers all those questions and it's an assessment of your reading skills
@stuck fractal Got it !!! Super thanks

white salmon
#

Have you guys had trouble with getting the Brainstorm exploit to work on the THM server but it works on a test machine?

oblique cliff
white salmon
#

@oblique cliff, Sorry that link is taking me to a different place Every time.

#

Can you give me a screenshot please.

#

?

oblique cliff
#

Brainstorm is unstable and/or broken

#

In bug submissions

white salmon
#

Is the bug submissions just all the bugs that are attempting to be fixed right now.

#

?

torn pine
#

It's bugs that are recognized and therefore submitted to the developers to be fixed in the near future

#

so they don't have to go through all the texts in these rooms to find what needs to be fixed

white salmon
#

Okay thank you.

torn pine
#

np

oblique cliff
#

It means you can do the room if you want but itโ€™s 50/50 if you get it working rn

white salmon
#

Is the bug the test binary and service on the actual machine not matching up in addresses?

oblique cliff
#

Brainstorm is unstable and/or broken

#

This is the bug

#

I donโ€™t have why more information than you

#

I just know people can get it working locally and not remotely sometimes

white salmon
#

Ok, that's all we have.

#

OK, thank you.

#

And also one of the qquestions ask how many ports are open.

#

I put in 3 but it says that it is wrong?

#

Is this known?

oblique cliff
#

Yep

#

To both

torn pine
#

Skip the room for now and return to it at a later time

white salmon
#

Yep, will do.

broken cloud
#

Anybody can help me what to use to view the web app souce code / I mean not the web page source code but that web app souce code any tool I can use!

white salmon
#

@broken cloud
Right click, view page source?

#

In Firefox?

torn pine
#

Anybody can help me what to use to view the web app souce code / I mean not the web page source code but that web app souce code any tool I can use!
@broken cloud I'm not sure what you mean.. Have you already got the source code downloaded? And just want to view it?

broken cloud
#

@white salmon thanks for response. But The room says web application souce code has the default username and password

I check the page source but there was nthg there

twin stratus
#

I was struggling a bit with bof1 caused by the different address spaces when launched in the debugger or shell as discussed in #room-help by @oblique cliff and @stuck fractal
So here's a litte rarun config to have the same environment in radare2 debugging mode, as if it would be if you start the program normally:

#!/usr/bin/rarun2

setenv=PATH=<PATH>
setenv=_=<file>
unsetenv=R2_BITS
unsetenv=TMPDIR
unsetenv=RABIN2_DEMANGLE
unsetenv=R2_ARCH
unsetenv=R2_IOVA
unsetenv=R2_XOFFSET
unsetenv=RABIN2_LANG
unsetenv=R2_FILE
unsetenv=RABIN2_PDBSERVER
unsetenv=R2_BSIZE
unsetenv=R2_ENDIAN
unsetenv=R2_COLOR
unsetenv=R2_SIZE
unsetenv=R2_DEBUG
unsetenv=R2_OFFSET

PATH has to be set to your user's current PATH variable and _ is set to the file you run (e.g. ./buffer-overflow-2)
save as <config>.rr2 and launch with
r2 -d <file> -r <config>.rr2

torn pine
#

@broken cloud What room, task, question?

broken cloud
#

Top 10 owsap--> task 20-->Q2

torn pine
#

@broken cloud And where does it say that the web application source code has the default username password?

#

The task description is just a teaching description, and has nothing directly to do with the question.. but gives a very good pointer on what do to, to answer the question

#

And if youre referring to the hint, it says find the app's source code, which is just rightclick -> view page source as said earlier

broken cloud
#

@torn pine thanks for the help . I didn't get anything from that I was doing that for a while so I thought I am doing something wrong so I thought to ask any if there is any chache here .
But as you said the hint refers to veiw page source than I think I should give it a one more try might I find the default username and password

gentle mural
#

@broken cloud normally you cannot view the source code on the backend, but maybe the application is open source?

broken cloud
#

If it is open source how can I view the source code@gentle mural

dapper iron
#

I'm stuck at room "common linux privesc" Task9 #4, I have what I'm pretty sure to be the answer, but it does't accept it. According to the answer format i need to add one symbol but all symbols that make sense to me don't work. The hint only reveals what i already knew and googling has not led to an answer

trim haven
#

Hm one second

dapper iron
#

my answer:

echo ./bin/bash > ls
trim haven
#

./bin/bash is trying to execute /bin/bash

dapper iron
#

Yeah i originally took the . out, but the format makes me thinks it needs it

trim haven
#

If you look at the hint, look at how /bin/bash is written

dapper iron
#

Ah, right

#

Thank you

trim haven
#

:D

dapper iron
#

๐Ÿ˜…

broken cloud
#

If it is open source how can I view the source code
Anyone who can help me with this!

trim haven
#

If it is open source

#

It means that it is somewhere on the internet

#

So if it is on the internet

#

Maybe get a company name and google it ๐Ÿค”

broken cloud
#

Okk๐ŸŒŸ

#

Btw is there anyone who has already solved this room?

trim haven
#

Yes

#

Many people including myself

broken cloud
#

So am I looking at the right place ๐Ÿ™„๐Ÿ˜…

trim haven
#

What are you searching

broken cloud
solemn smelt
#

Just google โ€˜how to look at web pages source codeโ€™ @broken cloud

broken cloud
#

i did and i always responce me with use ctrl+u or right cilck and select view page source

#

i refer different page but give me the same answer.

oblique cliff
#

And have you tried those?

broken cloud
#

use but didnt come accross anything that cout help me with default use and pass\

oblique cliff
#

What happened when you tried them?

open storm
#

@broken cloud owasp challenge ?

broken cloud
#

YES

#

task20

open storm
#

The source code is not necessary the one you can find by "ctrl+u".

#

for instance most cms have default passwords that you can find with a bit of OSINT

broken cloud
#

ok that means i have to guess !

#

i look into main file changepw and mynotes

#

i also came across a comment with a js script on it

open storm
#

No it means that you have to find it somewhere

broken cloud
#

also when ever i click mynotes it redirect me to the main page

#

why is that

#

also there is a list with txt null on it

stuck fractal
#

That's the page source

#

Not the webapp source

broken cloud
#

yes

#

any idea how to view web app source

stuck fractal
#

Have you tried looking on the internet for it?

broken cloud
#

yes

stuck fractal
#

Try again

#

You will find it

broken cloud
#

show the same use crtl +u

stuck fractal
#

False.

#

Keep looking on the internet. There's a common website used to share source code for open source apps. You can find it, I believe on you.

broken cloud
#

i know of soucre forge

#

did you have done that that room

stuck fractal
#

More than done that room

#

I created that challenge

cedar coral
#

any one did WebGramming Subscribe ?

severe bloom
trim haven
#

What have you tried?

tidal sedge
#

Yeah, that's a bug, I couldn't download it too

severe bloom
#

wow that is strange

#

design that way??

trim haven
#

No

#

A bug is usually unindented

tidal sedge
#

Yeah, from what I gather it's a bug ๐Ÿคท Try downloading it using wget or curl

severe bloom
#

ok i will

#

thanks

severe bloom
#

wget and curl can't download it

#

dsame error

trim haven
#

Hm it is strange

tacit owl
#

hello

#

need help gamezone room stuck at Task 5 question 2

oblique cliff
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
minor trellis
#

can anyone provide a hint for SET box I have question but don't want to post spoiler

tacit owl
#

as per question i follow step run ssh -L 10000:localhost:10000 <username>@<ip>

#

but its give me a output

oblique cliff
#

@tacit owl do you have something running on port 10000

tacit owl
#

yes

oblique cliff
#

You canโ€™t bind something to port 10000 if you have something running on it

tacit owl
#

i can curl that its give me a source code

oblique cliff
#

No, do you have something running on your kali machine port 10000

tacit owl
#

noo

#

even my remote macine give me a same error

oblique cliff
#

Are you running that on your attacker machine or the victim machine?

tacit owl
#

victim

#

oooh

oblique cliff
#

Which one does the room say to run it on

tacit owl
#

oppppps

#

local

oblique cliff
#

๐Ÿ™‚

tacit owl
#

thank you

median monolith
#

Hi, anyone for a little hint on Set?

worthy iris
#

is there a way to get rockyou.txt to work with the owasp zap fuzzer? i think the file size just creates an instant error

stuck fractal
#

is there a way to get rockyou.txt to work with the owasp zap fuzzer? i think the file size just creates an instant error
@worthy iris Try the first 50k lines, should work just fine

worthy iris
#

perfect thanks

sinful beacon
#

Can someone advise what is the question exactly at Metasploit 7? The command is 'use 6' but it didn't match...

white salmon
#

What's the name of the entire column?

sinful beacon
#

6 exploit/multi/handler

#

oO

#

lol... Thank you ๐Ÿ™‚

abstract apex
#

hey,
i guess there's a problem with sshing in the machine in overpass challenge

#

i cracked the key using ssh2john and john and still can't access the machine

#

Can someone help?

tawdry tangle
#

i've done it just fine, it's probably something with your method?

abstract apex
#

i've done it just fine, it's probably something with your method?
@tawdry tangle i have the passwords but it says Permission denied, please try again.Permission denied, please try again.

#

password*

tawdry tangle
#

i can't say with the limited info you've given me

white salmon
#

Could you give a screenshot?

abstract apex
tawdry tangle
#

you should fix what it says in the warning

white salmon
#

It actually kinda tells you why it's not working

abstract apex
#

didn't pay attention

#

thank you !

worthy iris
#

I've got an issue with the authenticate, there's no cookie being made in my browser and thus I can't edit it

gentle mural
#

Maybe there's a way to just create the cookie yourself?

worthy iris
#

cheers

carmine sphinx
#

hey everyone, im at the last task of "learn linux" room where i basically need to access a .txt file from /root but i dont have perms or something like that. I found already that "nootnoot as something called ".sudo_as_admin.successful", dont know if that's relevant. Can someone pls help or at least give me a hint?

wicked kettle
#

Not getting reverse shell in de-seriolization chall. can somebody provide hint?

#

I've already tried encoding(base64) several revserse shell from pentestmoneky

#

used python script for encoding

stuck fractal
#

I've already tried encoding(base64) several revserse shell from pentestmoneky
@wicked kettle That is not how the serialisation vuln is exploited, unless you mean using it in the python script provided

fresh quarry
#

hi all gonna repeat a question I had that I abandoned and am coming back to

#

i'm on the authentication room on the step "JSON web token" I've gotten the JWT captured in burp, decoded and changed it, and got the new token. however when i go to change the cookie value, Firefox is giving me the error "No data present for selected host"

#

I've tried to resolve this in numerous ways -- I found a Firefox forum detailing a possible fix by logging in a new profile and restarting the browser --> no dice. Does anyone have a hint on how I can fix this so that I can finish the room?

hardy matrix
#

I have this hex but dont know what to do with it (Blue/4/2)
aad3b435b51404eeaad3b435b51404ee:ffb43f0de35be4d9917ac0cc8ad57f8d

stuck fractal
#

Research where you found it

#

And the room tells you what to do with it

hardy matrix
#

okk

exotic canyon
#

OWASP JUICE BOX TASK 4 INJECTION -Log in with the administrator's user account using SQL Injection
I am a bit confused as to how to verify if I am doing the task correct.

If I am doing it correctly should it let me login or only return [objectObject]

grizzled lichen
#

U should get a response with a 200 status code

open storm
#

Hi hi everyone, Wireshark CTFs, final task: I got the audio file with the child speaking about pumpkins and everything but I can't understand all that he is saying (Im not good enough in english for that) so if someone could help that would be much appreciated. By the way I can send the file if required ๐Ÿ™‚ Thanks

trim haven
#

@open storm If you want to DM me the audio file I can listen to it :)

white salmon
#

You could also try finding if you can use google/amazon's auto-translate

gaunt herald
#

jb, you can do the sqli without any tool

slate swift
#

General question:
What sites do people use when checking is a service has known exploits that metaspoit can use.

Search from metaspoit is returning too many results and nothing really tells me what it is doing.

trim haven
#

Exploit.db

#

CVE.details

#

Searchsploit is created by exploit.db as an easier way to find exploits on your local machine.

white salmon
#

Also, enumeration tools help a lot

trim haven
#

^

#

Versions, Software names and looking for file paths if you're exploiting a webserver

#

(some exploits require certain paths to work)

slate swift
#

Yeah webserver. Maybe it's an upload exploit, I think I see one in the list. Thanks guys.

trim haven
#

:)

#

By the way, be aware. Searching on popular websites might not show up anything. Sometimes just searching the general idea of the webserver you're exploiting may bring up exploits. Depends on how popular the framework/template is

wind fog
#

Hello, please i need little hint for the nwebi challenge python :/ (manifold decoding)

trim haven
#

Is it the final task?

wind fog
#

yes, to intro python

trim haven
#

Okay

#

What do you need a hint with exactly? :D

wind fog
#

when i try to base32 decoded once base64 decoded i get the following error: raise binascii.Error ('Non-base32 digit found') from None
binascii.Error: Non-base32 digit found

trim haven
#

Okay are you able to send a little snippet of the code?

#

I think I know your issue but I want to be sure

wind fog
#

for i in range(5):
data = open("encodedflag.txt","r").read()
decoded64 = base64.b64decode(data)

for i in range (5):
decoded32 = base64.b32decode(decoded64)

print(decoded32)

trim haven
#

Okay so

#

You're decoding it backwords

#

It was encoded base64, then base32, then base16 right? So in order to decode it you have to start from the end and work your way up

white salmon
#

^

wind fog
#

ohh ok T.T

white salmon
#

If you look at your output, you should definitely notice that even though you followed the steps exactly, it still came out kinda weird

#

At that point, you should kinda think that "maybe it's in the wrong order"

#

Remember, usually real decoding isn't as black and white as this

trim haven
#

The way I did it was by encoding my own string and seeing if I get a similar looking string to the encoded one

#

Then seeing how I encoded it I then reversed what I did to decode it

#

Smack you should see my code for this task it was like 13 lines long kekw

white salmon
#

lmao

#

i wonder what my linecount was o.o

#

brb checking

trim haven
#

Bee taught me a trick with functions and libraries

#

Super smart

white salmon
#

oh nice

wind fog
#

thank i try now :p

trim haven
#

No worries

#

Any more issues come back, that task was a little tough

wind fog
#

i'm starting in prog :/

white salmon
#

Ah, I coded mines with readability more than linecount optimization

#

lmao

trim haven
#

for i in range(5):
data = open("encodedflag.txt","r").read()
decoded64 = base64.b64decode(data)

for i in range (5):
decoded32 = base64.b32decode(decoded64)

print(decoded32)
@wind fog I'd also like to mention that you're decoding the same string over and over rather than saving it to a new variable ๐Ÿ‘€

white salmon
#

this was mines o.o

trim haven
#

Send it in dms

#

Just in case ๐Ÿ‘€

white salmon
#

lmao

#

true

ashen matrix
#

Is there a quick way to decode bcrypt or is brute force the only way? In relation to the Crack The Hash room

wind fog
#

so would I have to implement a for loop in another directly?

white salmon
#

Is there a quick way to decode bcrypt or is brute force the only way? In relation to the Crack The Hash room
@ashen matrix As I understand it, it needs to be brute force only given it's complexity.

slate swift
#

Okay so I've looked up a walkthrough and I'm trying to understand how I was meant to figure out which exploit to use.

Room: Advent of Cyber
Day 10
Exploiting the webserver.

Everything I found from nnap pointed to upload exploit but there was no upload portal. Walkthrough points at struts exploit, but I have no idea how I was meant to figure that one out.

trim haven
#

Iโ€™m presuming there was a website name and or Versions which they put into google

slate swift
#

When I search tomcat/coyote jsp engine 1.1

Nothing points to struts

white salmon
#

Usually that means you didn't enumerate well enough

#

Checking for struts version is a common enumeration thing for apache webservers

slate swift
#

Hmmm, okay. Supporting doc suggests it should be far easier then doing any of that. Suggests it should be a simple launch metaspoit and search the service.

rapid flower
#

any hints on DNS exfiltration question from Advent of Cyber?

#

I got the file... ran ||steghide|| but can't understand the poem

white salmon
#

which task

rapid flower
#

task 11 day 4

#

sorry day 6

slate swift
#

I looked at the number of * and worked it out from that. But as for the actual thought pattern, I'm not sure if there actually is one. Hahaha

#

@rapid flower

white salmon
#

I don't remember it properly but it has everything try reading it a lil. For question #3 answer starts with || RFC|| work it out with this hint

rapid flower
#

ohkkk

slate swift
#

Yeah, if you workout the thought process let me know. Hahahah

rapid flower
#

is that poem of any use tho?

simple shoal
#

Hi, i'm in the OWASP Juice shop room TASK 7 on the administration page.
i have to access another user's basket, and followed the hint telling me to look into the local storage.
I found a token seperated into 3 arrays but I don't know what to do with it :/

I thought about the Sequencer in Burp as it deals with session tokens but I'm kinda blocked

Any hint for me, please ? ^^

gaunt herald
#

Sequncer? Maybe repeater

worthy iris
#

||on the XSS site, after I hijack Jacks cookie, I can no longer access the page (it just redirects me) ||

gaunt herald
#

Redeploy

worthy iris
#

how would that help me in 'real world' cases though? surely theres another way

gaunt herald
#

Wouldn't. Should've chosen a better payload in the first time.
Recommended for learning xss sure, but in a real life situation not so.

worthy iris
#

its the recommended payload ๐Ÿ˜’

#

I think I thought of sth

simple shoal
#

Thank you @gaunt herald for the help

worthy iris
#

|| so what I did was press Esc as soon as the page loads, before the script can redirect me, isn't clean but it worked atleast || @gaunt herald

gaunt herald
#

awesome :)

arctic crest
#

Hello all, can anybody give me hints with Common Linux PrivEsc room? I'm stuck at Task 8 #4...
I tried msfvenom on kali machine browser, but the result is command not found

final mortar
#

msfvenom is not installed on in-browser machine ?

#

Is that the issue

wraith tapir
#

It's installed ig

tough mirage
#

Hello all, can anybody give me hints with Common Linux PrivEsc room? I'm stuck at Task 8 #4...
I tried msfvenom on kali machine browser, but the result is command not found
@arctic crest Are you sure you are copying the command correctly?

final mortar
#

You should not be copying command tho

tough mirage
#

copy/replacing, same

arctic crest
#

@arctic crest Are you sure you are copying the command correctly?
@tough mirage I tried input the whole command, the result command not found, then type only msfvenom -h, results command not found

#

msfvenom is not installed on in-browser machine ?
@final mortar i tried apt-get install but no luck Hehehehe

final mortar
#

mefvenom comes preinstalled with metasploit

arctic crest
#

Yeah, that makes me wondering why it doesn't work

#

First time i try the command in PuTTY, but command not found, then i try on kali in browser machine, the result is the same

trim haven
#

Maybe the command is incorrect

final mortar
#

@arctic crest Are you sure you are copying the command correctly?
maybe

arctic crest
#

Maybe, i guess I'll try again later hehe

#

Thanks guys

green prism
#

"Can you find information about the system, such as the kernel version etc. Find flag 15" /room/linuxctf Task 3 #5

#

I used lsb_release -a

#

dmesg

#

cat /proc/version

#

uname -r

#

hostnamectl

#

i'm missing something

oblique cliff
#

did you look at the hint?

green prism
#

*release

#

yes i did

oblique cliff
#

did you look for a file called that?

green prism
#

isn't this referring to the lsb_release?

oblique cliff
#

no

green prism
#

i see

#

thanks

#

i couldn't find this thread searching with "linux kernel version release command"

white salmon
#

Hello everyone, I have a problem in the privesc room, I started Sharphound on the box and when I try to Invoke-Bloodhound it says "Invoke-Bloodhound : The term 'Invoke-Bloodhound' is not recognized as the name of a cmdlet etc etc. Someone can help me out? Thank you much.

#

o.o

#

It's invoke-Bloodhound

#

you typed in invoke-SharpHound

#

Right, right, I tried both infacrt

stuck fractal
#

Also you didn't load the script

white salmon
#

in fact

stuck fractal
#

You just ran it

#

If you want to run functions from the script, you have to specifically load it, which is . .\script

white salmon
#

Ok thanks I will try

stuck fractal
#

Show the line where you loaded the script

white salmon
stuck fractal
#

Again, not loading it

#

. .\script.ps1

#

Dot space dot

white salmon
#

It works ๐Ÿ˜„

#

Thank you. I never used PS in my life

tough mirage
#

His problema isn't msfvenom

#

It's the code itself generated

#

Hello everyone, I have a problem in the privesc room, I started Sharphound on the box and when I try to Invoke-Bloodhound it says "Invoke-Bloodhound : The term 'Invoke-Bloodhound' is not recognized as the name of a cmdlet etc etc. Someone can help me out? Thank you much.
@white salmon you can also try with the .exe

white salmon
#

@tough mirage ok, thank you !

stuck fractal
#

His problema isn't msfvenom
@tough mirage they were running it on the target machine, they needed to run it on their attacking kali

tough mirage
#

Ok, I didn't see that coming xD> @tough mirage they were running it on the target machine, they needed to run it on their attacking kali
@stuck fractal

sinful plaza
#
#

brute forcing not working

#

i have no idea how to extract file from a zip file any hint will help pls

#

โ˜น๏ธ

white salmon
#

i have no idea how to extract file from a zip file any hint will help pls
@sinful plaza Have you tried googling it

sinful plaza
#

yes but no luck

white salmon
#

What part of the extraction are you having trouble with?

#

Is the zip file encrypted with a passkey?

sinful plaza
#

yes

white salmon
#

Look up how to crack encrypted ZIP files with John the Ripper

sinful plaza
#

have try that already not working

#

i think the flag is hidden in the zip file just like hiding txt file in an image

green prism
#

Have a hard time interpreting this question: "Find flag 26 by searching the all files for a string that begins with 4bceb and is 32 characters long." /room/linuxctf task 4 #7
Is this asking for a filename starting with 4bceb that's 32 characters long or is there a file with a different name that CONTAINS a string with the same format?

#

Here's what I've tried
find / -name 4bceb* 2>/dev/null
find / -type f 2>/dev/null | grep 4bceb

oblique cliff
#

The first one youโ€™re trying to find a file of the name 4bceb

#

The second one youโ€™re doing the same thing (cuz youโ€™re grepping on the outputted file names)

#

What you want is to find files and then grep on the contents of the file

#

@green prism

green prism
#

find / -type f 2>/dev/null | xargs cat | grep 4bceb ?

oblique cliff
#

Uh. That looks like itโ€™d might work theoretically give it a try

#

Although 1 your find command is gonna try to go into mounts which it doesnโ€™t have permission to

#

So that part wonโ€™t work itโ€™s gonna hang forever.

#

And then you can feed the output of find directly into a grep. But your way looks like it may work

#

Give it a shot @green prism

stuck fractal
#

Is this asking for a filename starting with 4bceb that's 32 characters long or is there a file with a different name that CONTAINS a string with the same format?

#

A file that contains the string

rapid flower
stuck fractal
#

Base64 typically has lower case

#

Maybe there's another that looks similar but is only upper case

white salmon
#

Maybe there's another that looks similar but is only upper case
@stuck fractal Base64 but with uppercase letters

stuck fractal
#

Oh god that's a horrifying CTF "crypto" challenge idea

white salmon
#

LMAO

stuck fractal
#

Unknown case so you gotta brute force all the possible cases

white salmon
#

get people researching it for a long time until somebody just goes "have you ever tried just making it lowercase"

#

oh god

#

I just realized what you mean too

rapid flower
#

Maybe there's another that looks similar but is only upper case

#

wll look for that

lavish spire
#

Where's the ctf please?

rapid flower
lavish spire
#

Thank you!!

green prism
#

@oblique cliff is there a better to do this?

crystal glade
#

@sinful plaza Did you decode the letters and numbers below Download?

barren pike
#

Hello, when trying to use Metasploit when i run the exploit i get Exploit completed, but no session was created.

oblique cliff
#

@green prism the way youโ€™re doing is fine. But you can grep on the content of a file from one pipe out of a find. Itโ€™d just be a bit more efficient

trim haven
#

@barren pike Type options and screenshot the output please.

barren pike
trim haven
#

Don't use run -j just type run see if that works.

barren pike
#

Same output

tawdry tangle
#

reset box, worked for me

barren pike
#

I tried

trim haven
#

Update your metasploit, sudo apt update; sudo apt install metasploit-framework

barren pike
#

i am on mac

#

i will update

trim haven
#

Oh okay you do you

barren pike
#

Done

#

Same

tough mirage
#

I have a little question here

#

Room: Game zone

#

There is a task where we have to figured out that the port 10000 has a service and i have to forward, cool, but, next the creator said "we can see that is blocked by firewall, using iptables"

stuck fractal
#

Same
@barren pike Probably firewall

barren pike
#

I am using the ip in access page on the site

tough mirage
#

There is a task where we have to figured out that the port 10000 has a service and i have to forward, cool, but, next the creator said "we can see that is blocked by firewall, using iptables"
@tough mirage How ded he get to that if iptables only can be run by root, mmmm

stuck fractal
#

I am using the ip in access page on the site
@barren pike Still probably your firewall blocking the connections

#

@tough mirage Is the service accessible from outside the box? Yes/No
Is the service accessible from inside the box? Yes/No

#

If No and Yes, it's probably either firewalled, or only listening on loopback

tough mirage
#

In that case thats how he probably should explain no recommend a tools that can be only run by root

#

It's different the way you explain

crystal glade
#

@barren pike change the RPORT to 445

#

you are using wrong port

stuck fractal
#

@barren pike change the RPORT to 445
@crystal glade No

#

This is icecast, not blue

#

8000 is the correct port.

crystal glade
#

445/tcp open microsoft-ds Windows 7 Professional 7601 Service Pack 1 microsoft-ds (workgroup: WORKGROUP)

#

no 8000 port maybe i'm wrong

stuck fractal
#

Wat

#

445 is SMB

#

Icecast runs on port 8000, which means it's the correct RPORT here

barren pike
crystal glade
#

maybe expired?

white salmon
#

Hi,
sorry If I sound rude or neglecting but I feel like my self-esteem is taking a hit here and I feel really, really stupid :(
I'm stuck on one of the first basic questions and I just don't understand what the right answer is?

I know (like I know, know) that passwords hash encrypted with SHA-512 is shown as $6$... but that's the wrong answer according to "Tryhackme"
Am I using the wrong format or is it in fact not SHA-512 the right answer?
I've tried "SHA-512_crypt, sha-512_crypt, SHA-512_Crypto, sha512_crypt" and so on... but still... always the wrong answer =/

The question?
If a password hash starts with $6$, what format is it (Unix variant)?

I'm not asking for the correct answer but rather some advise on how to proceed?
Any tips would be greatly appreciated <3

I'm scared that if I get stuck on one of these first basic questions, maybe Tryhackme is not for me? But I hope to be proved wrong.

stuck fractal
#

If you check the answer format, it has a certain number of chars

dull palm
#

Hey all, I am on intro to x8664, at the point [task 4] where you run PC @rbp-0x4, and then do. When I type ds, nothing happens, just returned to the same prompt

#

Px * autocorrect error

oblique cliff
#

can you show a screenshot of all the commands youre running please

white salmon
#

Actually, something did happen when you typed in ds

dull palm
#

Sure, coming from photo from phone

white salmon
#

ds advances your debugger to the next instruction

#

you have to type pdf @main to see where you are now at

dull palm
white salmon
#

ds doesn't really give you any output to tell you that it did something

#

you'll notice that your instruction marker has moved down a notch though

#

if you check @main again

oblique cliff
#

leaving this to you @white salmon ๐Ÿ‘€

white salmon
#

don't you know i have a monopoly on all RE help blobknife

dull palm
#

Okay, sorry I thought the prompt would change.

white salmon
#

Also actually wait

dull palm
#

This is all newtonian me. Thanks

white salmon
#

did you set up any breakpoints before you typed dc?

oblique cliff
#

my bad ๐Ÿ˜Š

white salmon
#

you have to use dc first before ds will work

dull palm
#

New to me* yes followed it twice

white salmon
#

but if you don't set up any breakpoints with db, then the program will just advance to the end

dull palm
#

Jge, jmp

#

Okay I think I figured it out, I did a pdf @main and got the same output as on the page. I just assumed that the prompt would change. I see now that it does not.

white salmon
#

Yeah lmao

broken cloud
#

hii guys still stuck in top 10 owsap task 20 any specific guide to look for

rapid flower
#

hii guys still stuck in top 10 owsap task 20 any specific guide to look for
look for places where people store source-codes... documentation and stuff

stuck fractal
#

There's a HUGE website for it

broken cloud
#

i search for git hub with different query on opensouce project with login and so on

rapid flower
#

i search for git hub with different query on opensouce project with login and so on
maybe you are not searching for the right thing

#

the thing you need to search is right there in front of you

broken cloud
stuck fractal
#

Titles are better than descriptions

broken cloud
#

i also seached adding swaptheme featue of login feature

#

or* login feature

stuck fractal
#

Titles are better than descriptions

#

You're trying subtle things

#

Try really obvious things

broken cloud
#

kk thank a lot working on it๐Ÿ˜‡

cloud wagon
#

Hello guys... I am solving blue machine ...but I am unable to exploit that machine..?? Can anybody help me

oblique cliff
#

@cloud wagon

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
cloud wagon
oblique cliff
#

screenshot, not phone picture please

stuck fractal
#

Also, from the start

cloud wagon
#

Ohk... I am solving blue room....
And I am stuck on exploiting the machine

stuck fractal
#

You've said that

oblique cliff
#

yep, we've established that. Please show a screenshot of your options and the outcome

cloud wagon
oblique cliff
#

set your lhost to your tun0 ip address

#

right now its your local IP address, not you VPN IP address

#

also, update your metasploit your payload is defaulting to the wrong thing because your metasploit is outdated

cloud wagon
#

@oblique cliff what is tun0 ip address..??

oblique cliff
#

!multivpn

proud scarabBOT
#
TryHackMe
Learn how to look for duplicate instance of your OpenVPN connection.
โ€ข Step 1

Make sure you have setup your VPN connection correctly https://tryhackme.com/room/openvpn

โ€ข Step 2

Type ps aux | grep openvpn into your terminal and press enter

โ€ข Step 3

If there's more than one line (that don't start with "grep" or sudo), do the following steps

โ€ข Step 4

Type sudo killall openvpn into your terminal and press enter

โ€ข Step 5

Start the VPN with sudo openvpn <path-to-config>

oblique cliff
#

oops

#

!openvpn

#

ahhhhh whats the command

#

@stuck fractal halp

stuck fractal
#

just vpn

oblique cliff
#

!vpn

proud scarabBOT
oblique cliff
#

@cloud wagon

#

thank you

cloud wagon
#

Still I not got solution @oblique cliff

#

what I have to make change in ..??

oblique cliff
#

click on the link the bot just sent

#

and follow the prompts

#

you need to connect to the VPN

#

and then you will have a tun0 IP address

cloud wagon
#

yes ... I am connected to my vpn

stuck fractal
#

To the VPN?

#

It needs to be the tryhackme VPN

cloud wagon
stuck fractal
#

set your LHOST then

cloud wagon
#

It already set to my ip address

stuck fractal
#

It's set to a LAN IP

#

The target machine can't talk to that IP

#

It's not on that network

#

It has no way of talking to that IP

#

ip a s tun0

oblique cliff
#

or do that

broken cloud
#

am i looking for a tool that will help me pass the credential or a soucre code of an webapp like the one in machine ?

stuck fractal
#

am i looking for a tool that will help me pass the credential or a soucre code of an webapp like the one in machine ?
@broken cloud You are looking for the source code of the exact webapp

cloud wagon
#

Now I replaced my lhost ip with tun0 ip ,,,,,but still the problem is sameblobhuh ... It get fails

stuck fractal
#

Screenshot!

cloud wagon
stuck fractal
#

Of all of it

#

The start in particular

#

Update your mestasploit, it's out of date

cloud wagon
#

hmmmm ..........If I try to use non-staged payload ..??? Will it solve my problem

stuck fractal
#

Update. Your. Metasploit.

broken cloud
stuck fractal
#

Yes

#

Much much simpler

#

Titles are better than descriptions
@stuck fractal

#

Try really obvious things

brave bloom
#

about that blue room, I was also just on it, and even though I solved it I feel I've missed something important.. I've selected the exploit for eternalblue basically because the box was named "blue".. is there a more structured approach to finding the most adequate exploit based on the nmap results...?

stuck fractal
#

vuln scans

white salmon
#

There's also a metasploit scanner for windows machine, and specifically, a scanner for eternalblue.

#

Another key factor is just checking versions- a lot of Microsoft Windows SMB machines are vulnerable to it

#

Usually looking up any sort of key terms with version numbers into exploit-db or something can bring up something useful, including EternalBlue

odd panther
#

Update your mestasploit, it's out of date
@stuck fractal Literally came into ask about this, seems my answer is resolved lol. Thank you! (Fail on Blue) I'll update... ๐Ÿ™‚

stuck fractal
#

MSF decided reverse_https was a good default choice

#

Except it never works on THM for some reason, IDK about off THM

odd panther
#

oh, good info ๐Ÿ˜›

odd panther
#

Blue room, Updated and using the ||windows/x64/meterpreter/reverse_tcp|| Is this correct to check (have done room before, just being a pain)

fresh quarry
#

Still having problems: Authenticate-2 room, Task 4, Question 1: I still can't get to the cookies on the practice page. It looks like I am now able to access other sites' cookies, but not on the practice site. Any hints?

stuck fractal
#

@odd panther yep

quiet yarrow
white salmon
#

That's the correct module/library, yeah

#

Do you know how to program in Python?

quiet yarrow
#

nope

odd panther
#

I can help if you need

#

I'll wip you up an example

quiet yarrow
#

first time ever touching it

white salmon
#

You should definitely look up a more thorough and fleshed out Python guide

#

like an actual class or something

#

It's pretty easy to learn tbh

#

codeacademy has Python classes, Google also has one too

quiet yarrow
#

it is i have writen a few simple scritps i just think the decoding is a bit out of my scope right now

white salmon
#

It isn't out of your scope

#

It's a lot easier than you think

quiet yarrow
#

so i am on the right path i just need to start by learing the code first ?

white salmon
#

Here's a hint on what you need to do : You need to know how to use a loop

quiet yarrow
#

ohhhhhh ok

white salmon
#

Also, how a method/function works

quiet yarrow
#

i think i get it now

white salmon
#

๐Ÿ‘

#

Don't worry about making the code super optimized or anything

#

Just get the job done ;)

quiet yarrow
#

ok thanks alot i think that just helped me out alot

white salmon
#

@odd panther Please don't write out the code/answer for him- this room is for hints only.

odd panther
#

@white salmon Very good point ๐Ÿ™‚ thanks

white salmon
#

Yeah, don't worry, @quiet yarrow if you need any more help don't be afraid to ask!

odd panther
#

I get so excited to be able to help, but must remember better help is to teach!

craggy pulsar
#

@white salmon Very good point ๐Ÿ™‚ thanks
@odd panther Thank u!!!! ๐Ÿ™‚ its good that you're excited to teach!!! ๐Ÿ˜„

white salmon
#

Yeah don't worry, you had good intentions

#

your code didn't actually give out the answer too so that was good

odd panther
#

Yes I won't give answers but your right he's better off to learn the fundamental's, will serve much better in the long run

craggy pulsar
#

Yes I won't give answers but your right he's better off to learn the fundamental's, will server much better in the long run
@odd panther U can give answers if the user is like "I have smashed my head against my keyboard 500 times i have been trying for weeks someone please just help me"

white salmon
#

have you seen a doctor for your head injury from smashing into the keyboard 500 times

odd panther
#

I just like to help but need to help in a more structured way haha.

white salmon
#

It's infinitely more satisfying when you teach somebody How to find the answer, and they end up finding it for themselves and figuring out the rest

odd panther
#

Yeah, I work on a support desk, its my sole job to give answers as fast as possible I have to reign it in a bit, here at least for this lol

#

Also what language's do you know to code in?

white salmon
#

I'm not particularly an expert at any language, but I know how to work with C, C++, Python, Java, Assembly, JS, and I guess Rust now lol

#

Oh and C#

odd panther
#

I know c# the most started on it (8 year ago) stopped for a while, getting back into it now, but more python, powershell and I'm having to pick up some of the others for various tasks. python is fun ๐Ÿ™‚

white salmon
#

But Python and C++ are probably my most familiar languages

odd panther
#

nice

fleet pike
#

Is there some sort of etiquitte /acceptable activities list for practice room boxes?

stuck fractal
#

You don't share your VMs with anyone else

#

When you click deploy, that instance is yours and only yours