#room-hints

1 messages Β· Page 61 of 1

lean crag
wintry yarrow
#

Can you try to do it manually by backgrounding the current session and choosing module?

midnight spindle
#

Hey guys , I'm stuck on Task 11 of ZTHWEB2 , any hint ?

#

I found the api but is doesn't work 😦

#

NVM ! GOT IT ! πŸ˜„

cobalt gate
#

hi can i ask for some help on room ZTH: Obscure Web Vulns / [Section 4 - XXE]: Challenge i tried putting the xxe code example in the request and tryied whit xxe examples from https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/XXE Injection also but i getnothing in burpsuite only reply with "sorry, abc is already registered" any suggestions are appreciated

GitHub

A list of useful payloads and bypass for Web Application Security and Pentest/CTF - swisskyrepo/PayloadsAllTheThings

#

found it nvm

cold plover
#

need a nudge for lazyadmin

wintry yarrow
#

Sure. Where are you stuck?

cold plover
#

nmap scan shows port 80 and ssh, i gobuster'd port 80 but no intersting finds

wintry yarrow
#

Gobuster should show something interesting. Which wordlist did you use?

cold plover
#

raft-large-words

cobalt gate
#

use the rockyou wordlist

wintry yarrow
#

No, rockyou please. Its not for web dir bust.

cold plover
#

was about to say that

cobalt gate
#

ups

cold plover
#

lol

#

will try the classic directory-2.3-medium

wintry yarrow
#

It'll show something interesting, I'm sure. πŸ™‚

cold plover
#

been switching to raft lately tbh and it was decent

#

but some rooms depend on the classic one probably

#

oh gotcha

#

ty

#

actually

#

raft showd that directory

#

but i have a bad habit of grep'ing for 200 in my gobuster results

wintry yarrow
#

Sometimes medium list can't find anything so I try to stick with large one.

onyx atlas
cold plover
#

run that on the box

#

and put the answer there

#

i guess

#

@onyx atlas

white salmon
#

@onyx atlas it doesn't ask for the command but just for the variable

onyx atlas
#

Yes, Thank you

weary quarry
#

i have completed all , except this

white salmon
#

it is between the users

weary quarry
#

can i PM u to avoid spoilers @white salmon

white salmon
#

yes

cold plover
#

recovery nudge pls

lofty goblet
#

Hi all - May I ask for some assistance please? I'm a bit stuck on one of the Vulnuniversity questions

woven mirage
#

Ask your question

lofty goblet
#

I've been following step by step, also looked at some videos - however I can not seem to get intruder query to accept any of the file types in this question

stuck fractal
#

How are you determining accept/reject?

woven mirage
#

Send screenshot of your burp intruder request

lofty goblet
#

In DM Termack?

woven mirage
#

Here

lofty goblet
stuck fractal
#

How are you determining accept/reject?

lofty goblet
#

Sorry ninja - It's good question - as the subject doesnt actrually tell you where to look - I've gone by this

stuck fractal
#

You're looking at the response

#

Whatever the URL encoding setting is, flip it

lofty goblet
#

Apologies I'm going to be dumb here - what and where sorry 😦

stuck fractal
#

There's a setting for intruder

#

For URL encoding specific characters

#

If it's on, turn it off

#

If it's off, turn it on

lofty goblet
#

Cool - Just looking through the options now

#

aah

#

(just unticked it)

stuck fractal
#

Yea that one

lofty goblet
#

wow... saying I feel stupid is an understatement - that makes sense too 😦

#

Thanks a bunch Ninja - much appreciated. I was pulling my hair out

cobalt gate
#

hi can i ask a hint for room zthweb2 last task 11 ,i tried to fuzz different parameters with no luck

#

any suggestions are appreciated

cobalt gate
#

found it nvm

broken quail
#

I was completing shodan room, but couldn't solve Task 4 number 5 question, top operating system. Any other way to solve this question? Also, hint wasn't that helpful for me.

#

Okay, I just solved it. No worries!

halcyon bison
#

hi, i am trying the motunui room and i have wrote a script to bruteforce. But it's running for 2 hours now. Can somone tell me if i am wasting time or not? (the script is based on curl and rockyou.txt wordlist). If i am not clear enought tell me (sorry for the bad eng)

#

btw i am sure at 80% the script is right, cause i have made some testing before running it

stuck fractal
#

Any brute force on tryhackme will take 5 minutes or less.

halcyon bison
#

i see.. ahahah tnx

#

can i ask you t review my code (is like 6 line of bash)

stuck fractal
#

I can't as I haven't done the box

halcyon bison
#

uh kk

#

tnx

white salmon
#

Hi all, can someone assist with the crypto1a || layouts ||aspect, I tried to think using crypto mindset and out of the box mindset but still stuck, ||I tried all I have single and thrice as indicated in lowercase||. Thx

stuck fractal
#

What room?

white salmon
#

CCT2019

#

First question of Last task

stuck fractal
#

Rip ok there's not so many people that can help there

white salmon
#

I see that @proven bridge has finished it. If you are around 😊

#

Waiting some help going back to it

proven bridge
#

Sure, make sure you pay attention to the word ||thrice||

#

and layout means ⌨️

proven bridge
#

@white salmon

elfin flume
#

Someone can tell me one hint to Psycho Break, task 2, question 2 ?

stuck fractal
#

No, because that's a brand new room

elfin flume
#

Humm

stuck fractal
#

Please wait 72 hours after release

elfin flume
#

Okay, Thx πŸ˜„

lean crag
#

either I've drank too much or something seems odd. working on blaster

stuck fractal
#

If it's the history, check the pins in #room-help for the CVE

lean crag
#

run nmap, see a number of ports open. answer is NOT what I found with an -sT scna

#

it's lower than what I get with the sT scan

#

second, nav to the IP address in my browser and only getting the IIS landing page

#

there is no other port that has web service running (NMAP to check)

stuck fractal
#

Yeah so 1. Windows is weird with open port numbers

#
  1. What about directory bruteforcing?
lean crag
#

ran dirb

#

nada

stuck fractal
#

Try harder

#

Different wordlist

#

Bigger one

lean crag
#

k

#

one of the questions is asking the name of the main web page, though

#

there isn't one

#

wait

#

hang on

#

LOLZ

#

never mind

#

k, off to user a bigger wordlist and lick my wounds for my stupid web title page question

#

so why is Windows weird on open port numbers? I've not heard that before

stuck fractal
#

It just isℒ️

steady elm
#

Hello, i have been solving Psycho Break room and got stuck on Safeheaven, there are 4 images i did extensive stego upto my knowledge and check src files in source too only i got this on page source Search through me and find it. But i am not able to move forward. Any hints are highly appreciated

wintry yarrow
#

Its a new room, so no hints or help is allowed till 72 hours passes.

white salmon
#

Finally got the crypto1a and crypto1b flags, working on te last one crypto1c, thx @proven bridge for ||⌨️||

rough helm
#

Hello, i don't understand this sentence "Split by comma and get the last element in the split"

#

can just somebody help me

oblique cliff
#

split the text in the file by ,

#

and then the last thing in the split will be the flag

shut lion
#

Hey guys, I need a hint for the ccpentesting room. Anyone mind being DM'ed?

eternal brook
#

You can ask here someone will respond, anyways you can dm me:)

shut lion
#

So I'm stuck at task 24 of the ccpentesting room. I've done the directory scan and found the secret directory but the files I find are forbidden files like .htaccess and .htpasswd, plus an empty index.html file. Are these the ones or there are others to find? Which wordlists would be best to use in this case to find them?

eternal brook
#

Any standard wordlist would have found that directory.....you can try
/usr/share/wordlist/dirbuster/directory-list-2.3-medium.txt

#

@shut lion

shut lion
#

@eternal brook alright, let me try again.

#

thanks

native leaf
#

hello guys

#

i'm doing the owasp top 10

#

and i am trying to do the extra challenge of day 3

#

i found the email

#

and i got this

#

Hi,
Signups for the beta test of the senseandsensitivity program are now closed -- thank you to everyone who applied.
This also means that the subcode has unfortunately already been claimed.

#

does this mean that there is no more extra challenge

#

or should i try harder

stuck fractal
#

You can't get the code anymore.

native leaf
#

oh , okay

#

thank you very much

rigid fog
#

Room XSS Playgound, task 8, #4: Why does the following answer works, but yields no flag? ||<img src="abc" onmouseover=alert(String.fromCharCode(72,101,108,108,111))>||

wintry yarrow
#

No hints or helped allow for new rooms till 72 hours passes.

fathom mortar
#

Hello in XSS playground room task5 i got document cookie with alert also i changed background but i didnt get any flag should i do something different or its bugged any hint?

astral smelt
#

Try and look at inspect element

fathom mortar
#

tbh i dont know what i did different but i got flag at the first one

#

still can not get flag at the 2nd one im giving img src, and hover event i can change background colour to red

white salmon
#

in this channel only questions about tryhackme rooms. Try #general

stuck pendant
#

dont ask such things ,this is something which requires a concent letter and other formalities,one cant simply go to any sites and just attempt even if it is your own

fathom mortar
#

in this channel only questions about tryhackme rooms. Try #general
@white salmon its trykhackme room as i said at the top

white salmon
#

Wasn't directed at you

fathom mortar
#

oh sorry then

stuck pendant
#

it was for the person who just deleted his msg @fathom mortar

tepid solar
#

I am looking at room - Psycho Break - And i am currently stuck at decoding a piece of text to get the key to map , can anyone drop a hint which decoding method used.... I tried most of them - base64,rot13 rot 11 etc

#

Never mind got it

stuck fractal
#

@tepid solar Please wait 3 days after release before asking for help

weary quarry
#

easy root , i have not faced an issue like this

#

please ping me

stuck fractal
#

In the.... Perfect file?

weary quarry
#

sorry that will reveal the answer

#

can i PM u

final mortar
#

You can use the spoiler tags if you are worried about revealing answers

weary quarry
#

OH

#

okay

#

for the ||cronjob , i will check for the /etc/crontab , but here there is nothing shows in that but after running the PSPY i have came to know thereis an cronjob running|| @stuck fractal

stuck fractal
#

Yes

weary quarry
#

is this any BUG ?

stuck fractal
#

||System wide crontab is separate from individual users' crontabs. It's a security feature, not a bug. Root had their own private crontab.||

#

Not a bug.

weary quarry
#

oh nice thanks

#

u made a day

#

thanks again

flint lintel
#

I am feeling really stupid and having trouble clearing Learn Linux room

final mortar
#

and ...

#

Do you have a question ?

flint lintel
#

...

#

This is called room hints, is it not

stuck fractal
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
flint lintel
#

Thanks

#

I am at the last task trying to get the flag, I have tried chmods greps and finds for anything that looks like root, and tried creating links to the file I need to get to.

stuck fractal
#

You need to become root

#

You won't be able to get the flag unless you are root

flint lintel
#

Oh

#

The flow of the room was to get the pw for the next user, so I was assuming the PW was in root.txt. Thanks.

stuck fractal
#

The flag is in root.txt, which is what you need to put in to TryHackMe

flint lintel
#

Gotcha, now I feel dumber lol

stuck fractal
#

Don't beat yourself up over it

flint lintel
#

Thank you!

flint lintel
#

I got it thanks guys! (although not sure why the pw was in that file to begin with other than for learning purposes) haha

lavish wigeon
#

i got question

#

What term can we use to look for login pages?

#

google dorking btw

#

tried inline, inurl attributes, none seems to work

final mortar
#

Are you using the right parameter with the term

#

Also, it's none of the above

lavish wigeon
#

im using login

#

as parameter

#

im googling 15 min already o.o

trim haven
#

We usually don't help on research-based rooms

lavish wigeon
#

oh aight, didnt kno

#

w

#

i just solved it

#

nevermind

flint lintel
trim haven
#

Did the session just die randomly?

flint lintel
#

I am working on the metasploit room, and the steps say to run the commands sessions and jobs. Does that screenshot show the exploit works?

#

No it timed out, but I was trying to run the sessions and jobs command while it was running, but couldnt figure out what to do next (tried opening a new terminal and a new msfconsole but nothing was in sessions or jobs)

trim haven
#

If you type exploit -j it will run as a job but it will become a session when you get a connection, does that make sense?

#

And it says the session died so there will not be a session as it died.

flint lintel
#

Oh run -j

trim haven
#

the meterpreter > prompt means the session was opened correctly. You are able to type commands

flint lintel
#

Nice

#

So running the exploit command, I wouldn't be able to see jobs and sessions as they are run though

trim haven
#

You should be able to see the session

#

The job will be changed into a session

glad crag
#

Hey guys, Im new at this

#

And I've been stoped for almost 2 hours with and "easy" question

#

Can you give me a hint? hehe

stuck fractal
#

From the info you've given us? definitely not

glad crag
#

I was just asking if any one was here to help me xd

#

The worst of it

#

is that is not a CFT or something

stuck fractal
#

There are always people here, but you gotta directly ask your question

glad crag
#

Okay, sorry

stuck fractal
#

As long as it's a room on TryHackMe

glad crag
#

Is a question in a Section of the CC: Pen Testing

#

If i dont have to ask that here i'll leave it xD

stuck fractal
#

Just ask!

glad crag
#

Task 8 [Section 3- Metasploit] the #8

#

I'm stucked here because I can't find it

stuck fractal
#

It?

glad crag
#

I mean I read all the options of the payload, of the module

#

And I cant find it

#

Or maybe I just dont understand the question

stuck fractal
#

What option sets the payload to be sent to the target machine?

glad crag
#

YES

#

I just need a hint

stuck fractal
#

Something like EternalBlue is an exploit, it delivers a payload

#

There's an option to set what payload you deliver

#

It's a research question TBH

#

Do some googling

glad crag
#

I've done it trust me

#

So the question is about changing the payload?

stuck fractal
#

metasploit how to set payload

#

easy

#

It's literally "what option do you use to set the payload"

glad crag
#

Okay im dumb, I was searching in the options of the pΓ yload

#

Sorry, Im not english and there are some things that I can missunderstood

#

Thanks James! And sorry for wasting your time

stuck fractal
#

use google translate if you need to

#

It's not a waste of time if you learned something

glad crag
#

Forgive me for being a mess, I always complicate my life unnecessarily. I got it now

pine vale
#

Hello. New to this. I am working on Blue/Task 3 Escalate/Step #4 Run!
I continue to get a Post failed error. I have re-worked the room to this point and continue to get the same error.
I have read through many of the walkthrough guides and none address this. Thank you for any/all assistance!

stuck fractal
#

@pine vale You already had a meterpreter

#

You cannot convert a meterpreter into a meterpreter

pine vale
#

Hmmm. Thanks. I guess the status was not clear to me.

final mortar
#

msf has changed the default shell for that exploit since the room came out

pine vale
#

When I first saw meterpreter > I was confused. pwd showed C:\Windows\system32, so I thought I was on track. But if Task 2 gets you there, then what is the aim of Task 3?

stuck fractal
#

msf has changed the default shell for that exploit since the room came out
@final mortar

#

It used to give you a standard shell, it now gives you a meterpreter

pine vale
#

Ah. So the Task steps are out of synch with msf? That makes sense. I appreciate this forum and the help!

stuck fractal
#

No, the room just hasn't been updated

#

MSF isn't reliable, at all

#

Super unstable

pine vale
#

Thanks.

white salmon
#

damn year of the pig... no wonder there aren't anyone with initial flag. this will take more than 1 hour to even get into the dang thing

#

i mean... even writing a custom script to do this on the thm kali box and making it use all its threads possible... you sneaky sneaky devil you

#

@inland onyx can i send you a screen cap?

inland onyx
#

Yes, you can πŸ™‚

cedar notch
#

I've been bruteforcing it for 2h now...

#

@inland onyx If its not gonna be bruteforce I'm gonna whoop ur ass

inland onyx
#

Haha. That hint, for the record, means that if it takes more than two minutes then something has gone wrong

cedar notch
#

😠

#

it went thorul cewl and THE hint

#

and nothing 😒

inland onyx
#

Missing something still, perhaps then πŸ˜›

white salmon
#

On the learn linux room I can not ssh into the server using username shiba1. I have a macbook can not download putty so I tried through terminal. Anybody have this issue?

stuck fractal
#

@white salmon What happens when you try?

white salmon
#

it says permission denied

stuck fractal
#

What's the full error message?

white salmon
#

permission denied. please try again

stuck fractal
#

Permission denied (public key)?

#

Try 3 times.

#

Then screenshot the error message

white salmon
#

Permission denied (publickey,password).

stuck fractal
#

Ok, and you're typing the password shiba1 when prompted for a password?

white salmon
#

yes

stuck fractal
#

Where did you get the IP that you're using?

#

You need to deploy the machine in the room, not the attackbox

white salmon
#

under my machine

stuck fractal
#

The machine that you deploy in the room is separate from the attackbox

white salmon
#

oh

stuck fractal
#

The room emphasises this in 3 different places

white salmon
#

how do you deploy in the room? There is no button to deploy in this one

stuck fractal
#

There is

#

Make sure you're looking at the right task

white salmon
stuck fractal
#

Machines are attached to tasks

#

Not to rooms

#

Look at the tasks below the video.

white salmon
#

got it. I appreciate the help. I am new to this

#

@white salmon new is best... means you care and want to learn and have a passion or hunger to explore as opposed to oldschool grumpy assholes . (no offense to oldschool grumpy assholes present)

#

I find this very interesting but hard at the same time

white salmon
#

its a journey

#

i remember popping my first shell and being liek woh... what!?

flint lintel
#

On the VulnUniversity room, I can't seem to get the check to work

#

I have the right answer, but I am more concerned about wondering why it is showing the error "extension not accepted"

stuck fractal
#

Check payload encoding

#

If it's on, turn it off and vice versa

flint lintel
#

gasp

#

thankyouthankyouthankyou

stuck fractal
#

I can never remember which way it needs to be set

#

Just that one of them works and one of them doesn't

flint lintel
#

It throws me off that this is a free room but the pre-req room of burp suite is not

#

;_;

stuck fractal
#

There's portswigger academy. Don't limit yourself to just THM.

flint lintel
#

I will check it out! Prior to THM, I had only intercepted requests and just changed params- so this is really all fun in a whole new world

livid vault
#

guys

#

wrong password?

final mortar
#

You do get a free in-browser machine with this room, use that @livid vault

livid vault
#

haha

final mortar
#

Try Accessing in Browser @livid vault

livid vault
#

cant be used

#

same @final mortar

final mortar
#

Not Attack Box

#

Try This Green Access in Browser if isn't loading up properly

livid vault
#

same

final mortar
#

Same what

#

It comes pre logged in

prisma gull
#

i am stuck on psycho break room on the keeper key.....i did some stego tools but nothing came up ....can anyone give me some hints

alpine lantern
white salmon
#

It is in your enum4linux results

cedar coral
#

any one on Year of the Pig, just for a sanity check

pine ermine
#

Yes, @cedar coral

cedar coral
#

can i DM bro?

pine ermine
#

Yep, np

cold magnet
#

Hi, I got a question about Year of the Pig, anybody able to help?

trim haven
#

Rule 13 states we cannot help you for 72 hours unless instructed otherwise by the room creator

#

I haven’t checked the room but if it’s a challenge room we can’t help.

cold magnet
#

no problem,

white salmon
#

Hello guys!

For the room WWBuddy how do I properly add the passwords to change into pay load?

' or 1=1 -- a

paper sapphire
#

hey guy soo can someone tell me hint on agent sudo room

#

I discovered that the secret site is a user-agent but I have no idea how I can access it 😐

fleet pike
#

is YoTP a new version of yotf?

inland onyx
#

No. They're both part of the same series

fleet pike
#

yotf was crazy fun

inland onyx
#

There are lots of them -- some still private

#

Two more waiting for release. Three more planned

paper sapphire
#

I discovered that the secret site is a user-agent but I have no idea how I can access it 😐
@paper sapphire anyone help 😐

eternal brook
#

Try using different user agents according to the naming scheme you see on the webpage.....

fleet pike
#

Muirland: I thoroughly enjoyed yotf... You have a knack for good challenge rooms πŸ™‚

weary quarry
#

can anyone he,p me in this

stuck fractal
#

Show us what happens?

celest imp
#

i am really stuck on Psycho Break room at step that needed to decode text for map key. i already tried ceaser, rot or shift but none of them work. is there anybody can give me a hint

astral smelt
#

Intsall Ciphey

celest imp
#

thx a lot

ancient acorn
#

On the Learn Linux room i've tried everything I can think of to access /root/root.txt for the final task, I feel like I'm missing something obvious...any hints? Sorry I'm new

weary quarry
#

Show us what happens?
@stuck fractal i have got the Nt/authority

#

but i dont know , same user Y it is enabling the SeDebugPrivilege Debug programs Enabled

#

and in other it is telling like SeDebugPrivilege Debug programs disabled

stuck fractal
#

@celest imp Thats a brand new room so please don't ask for help yet. Give it 72 hours from release

weary quarry
#

i have got the shell as DARK , in windows i have tried to dump , sut i cant becasue SeDebugPrivilege is disabled

#

but i have used some msfmodule , that throws the same user with SeDebugPrivilege is ENABLED

#

i am confused here

stuck fractal
#

You need to be system

#

Then you need to migrate to a system process.

weary quarry
#

after using the ps also it is not showing the nt/authority process

#

i dont know how windows/local/bypassuac_eventvwr this enables the SeDebugPrivilege (so i can take the hash fromthe mimikatz)

tight skiff
#

Golden Eye Room: Task 2: 3rd Question: Inspect port 55007, what services is configured to use this port?
I have done nmap scan for this port and pop3 is running. But I'm not able to figure the answer.

loud flax
#

on the anonymous playground room, got the funky looking code and im guessing its some sort of cipher as the hint says 'zA' = 'a' but im not too sure what to do with it

astral smelt
#

You have to create a Python script for it to be decoded

loud flax
#

yeah but im not too sure how'd it work

#

i see the 'a's in it line up with the username magna so i might be able to get the hE and the m for example to figure out this

#

aight i figured it out

#

its a damn smart cipher tho ill say

astral smelt
#

Yea it is I got stuck on it for a long time

soft fulcrum
#

im stuck on Task 2 Question 4 Psycho Break Room, can someone give me an advice?

stuck fractal
#

Please wait a little longer

#

72 hours from release

soft fulcrum
#

ok

red minnow
#

Hi, i'm doing the "Psycho Break" room and i'm on the page where you have to escape Laura. Can someone give me a nudge?

stuck fractal
#

Please wait a little longer

true prairie
#

Hi, i'm doing the "Psycho Break" room and i'm on the page where you have to escape Laura. Can someone give me a nudge?
@red minnow oh man I'm stuck there too... Really don't know what to do..

hard raft
#

I'm stuck with that too

ivory plinth
#

lol seems to be a fun ride ahead .... i am stuck at the keepers key. Tried lots of stego stuff, but to no success, so really curious what i am missing πŸ˜†

true prairie
#

72 hours should be over now πŸ€”

steady stratus
#

Indeed it is

#

g,

#

Help/Hints about this room (in the respective channels) are okay now

true prairie
#

A hint for the keepers key from my side.. It's not about the picutes on the site

ivory plinth
#

@true prairie yeah I guesses so to, bc i tried everything on them. i was skimming through the JS files too :-/... can I DM u ?

true prairie
#

@true prairie yeah I guesses so to, bc i tried everything on them. i was skimming through the JS files too :-/... can I DM u ?
@ivory plinth yeah of course no problem :)

true prairie
#

Any hints for Psycho Break Task 2 Question 4? Can't escape Laura...

cerulean sky
#

Same here ... @true prairie since last night .. Lol..

#

Just not giving up on it. Trying and trying and trying. But no luck so far.

true prairie
#

Just not giving up on it. Trying and trying and trying. But no luck so far.
@cerulean sky yeah and I tried the weirdest things.. No success

#

Even looked up some gameplay videos on YouTube on what to do when encountering Laura

cerulean sky
#

Hahahaha I did too..

grave rain
#

Even looked up some gameplay videos on YouTube on what to do when encountering Laura
@true prairie i read the whole wiki πŸ˜†

true prairie
#

@true prairie i read the whole wiki πŸ˜†
@grave rain yeah I went to the Wiki link below and thought: hmm well maybe I'll find something useful in here...

cerulean sky
#

Same here guys.. I think I tried countless times to get past the task .. But it is kinda tricky... Yet i like the challenge.. The creator has made a quite a well-thought room..

#

I read the wiki page .. All of it ..

true prairie
#

Same here guys.. I think I tried countless times to get past the task .. But it is kinda tricky... Yet i like the challenge.. The creator has made a quite a well-thought room..
@cerulean sky oh yeah! Overall until now an awesome room and very dynamic

cerulean sky
#

Other than getting a clue I was more tempted to start playing the game on my PS.. I had it since 2017, never played but didn't know I will want to play the game due to a CTF machine I will get stuck in 2020.. Lol ..

grave rain
#

Theres really a blurred line between a very well thought room and a random room

steady stratus
#

Fo' sure

cerulean sky
#

True indeed. The harder we try the better the room actually is .. The motive is to keep trying and get the box done leaving you with learning something new.. I think it's all about the journey to being a good cyber/infosec guy

steady stratus
#

How do you think it falls? @grave rain between the "very well thought" and a "random room"?

grave rain
#

It depends on how you see it i guess

#

Right now im stuck

#

So for me its random for now

#

When an answer pops up.. ill be like damn it was well thought

#

Even blurrier line in judging lols

steady stratus
#

Okay - that makes sense

#

We're (i) debating on changing he difficulty rating so I'm just trying to collect communal thoughts

grave rain
#

It definitely not an 'easy walkthrough' room haha

cerulean sky
#

I am surprised that Psycho break is classified as easy ctf room .. I am sure it isn't easy box but definately medium..

steady stratus
#

Granted our new rules for room testing / review would clasify that room differently but

true prairie
#

When an answer pops up.. ill be like damn it was well thought
@grave rain Yeah but right now I don't know what to think. Maybe the answer is so simple yet so obvious. The room was a blast till this point. Now it's a bit of a bummer..

steady stratus
#

I'm using the "old" rules for when that was submitted and reviewed

#

Okay, thanks y'all

#

I'm stuck on task 3 btw πŸ˜‰

grave rain
#

You give us hope man

cerulean sky
#

Oh.. wow you went past task 2.. awesome.. keep going..

steady stratus
#

I want to gather a community view/opinion before changing the difficulty rating as it's very subjective so

grave rain
#

It looks easy if you know the solutions ngl

steady stratus
#

Very much ahaha

grave rain
#

Just directory bruteforcing and basic command injection

steady stratus
#

It's that little click in the brain y'know?

#

aaah it makes sense but it's stupid

#

xD

grave rain
#

But the little click makes all the difference

#

Hermit mode

steady stratus
#

For surea hehe

#

Good luck!

grave rain
#

You too luls

steady stratus
#

I'm just keeping my ears for how others find it alongside the rare time I get to try it

cerulean sky
#

May the force be with ya'all..BREAKING THE PSYCHO..

steady stratus
#

So it's good to hear for me especially (:

grave rain
#

When someone whos more pro in this field is stuck with you

#

Its better for us to hear haha

#

Makes us feel less nooby

steady stratus
#

LMAO I'm qualified in a different type of forensics but this is close enough xD

#

For sure

grave rain
#

Atleast not medical field hahaha

steady stratus
#

Keep on at it folks! I'm dragging on behind with you all ❀️

steady stratus
#

Atleast not medical field hahaha
@grave rain Ahaha well, saying that πŸ˜›

#

You'd be surprised

grave rain
#

Try me haha

#

Idk where antihypertensives fit in any of this

steady stratus
#

I'm a HCP in the UK

grave rain
#

Wuw

#

Im in india

steady stratus
#

That ain't a d*rk swing but

grave rain
#

Same profession technically

steady stratus
#

Infosec attracts a very wide personality πŸ˜›

cerulean sky
#

Im in UK too..

grave rain
#

Its one of those subjects which is 100 percent self learn yk

#

You cant learn stuff like medicine self learn

steady stratus
#

heheh somewhat πŸ˜›

#

I've been through plenty of exams for it

grave rain
#

I mean who would even self learn medicine hahaha

steady stratus
#

I only picked it up because my patience/knowlege of infosec was less at Uni lmao

red minnow
#

I don't think you will be taken serious if you say you learned medicine by yourself

grave rain
#

I didnt hear of infosec then

#

Kinda dumb

steady stratus
#

Not at all (:

#

Very different skillsets

#

Medical you take fact as fact

grave rain
#

I only picked it up because my patience/knowlege of infosec was less at Uni lmao
@steady stratus
This is weird haha

steady stratus
#

Infosec - you don't

grave rain
#

But medicine has its share of plot twists lol

steady stratus
#

Hehee ain't it just huh @grave rain

grave rain
#

@steady stratus id like to PM you something about nhs if thats fine by you

cerulean sky
#

gtg.. Nice talking to ya all.. First time on Discord and its indeed a lot of fun to be here among so many like-minded people.. The community is awesome.. We surely come back !! See ya' guy.. Break the psycho or become one ... Lol ..

steady stratus
#

Sure, go for it @grave rain (:

#

Thanks @cerulean sky! Best of luck with it all .... until the next time!

cerulean sky
#

Until next time.. Sure.. !! πŸ™‚

somber crag
#

Hi guyz

#

Can I get a hint about the FTP passwd? on the psychobreak room

glossy tendon
#

i think i might have overwritten the Learn Linux room Task 21 environment variable, any help getting back on track

woven mirage
#

Redeploy the machine

#

When you redeploy you get a fresh machine without the modifications you made

soft fulcrum
#

Hints already allowed for Psycho Room?

hollow holly
#

hey @white salmonyone!
I'm doing the SQL Injection room, on task 7, and I'm having a really bad time trying to find the database's name
Can someone give me a hint? there's no write up for this room yet ...

soft fulcrum
#

I just want to wonder what am i missing on Task 2 Quest 4 xd

hollow holly
#

anyone?

woven mirage
#

Search "query to select database name SQL"

#

Also, dont tag everyone, It doesnt work anyway and you Tagged poor ever instead :(

hollow holly
#

nervermind!

#

I got it!

#

@woven mirage im sorry

#

it was my mistake!

#

poor ever xd

woven mirage
#

No problem

hollow holly
#

can I share how I did solve it here?

woven mirage
#

Actually, this Channel is for hints so people are not supposed to post answers

hollow holly
#

I was not going to give the answer

#

but ok ..

soft fulcrum
#

Psycho Room Task 2 Question 4 (How to escape Laura), any hint?

hard raft
#

Can anyone give me a hint on Psycho Break task 2 question 4 (escape Laura)?

soft fulcrum
#

i think i know how to do it but miss something to complete it :/

hard raft
#

lol, at once xD

soft fulcrum
#

xd

hard raft
#

i think i know how to do it but miss something to complete it :/
@soft fulcrum I'm stuck at it for 2 days and I don't have a clue how to do it

soft fulcrum
#

yeah me too, i just have a thought but can be completely wrong

rugged sapphire
#

I'm also stuck on Psycho Break, Task 2 Q4..
I can view contents of actual dir but all other commands tried are blocked..

cerulean sky
#

Tried a lot to get past it. But no luck so far guys. Keep grinding. The hint is the keyword in the source code is the parameter and you can only run your most typed command , nothing else is permitted. Thats all so far.. Lol.. πŸ™‚

noble tinsel
#

has anyone done manual SQLi on uopeasy? trying to avoid sqlmap & need a nudge

noble locust
#

Room - Common Linux Privsec

#

query -

#

Task 4 : enumeration

#

How many available shells are there on the system?

#

I ran grep '^[^#]' /etc/shells

#

It gave me these

#
/bin/bash
/bin/rbash
/bin/dash
/usr/bin/tmux
/usr/bin/screen
/bin/zsh
/usr/bin/zsh
/usr/bin/pwsh
/opt/microsoft/powershell/7/pwsh
#

totals to 10 in count

#

but the answer format is of single integer input

#

πŸ˜•

stone oyster
#

Hey folks, working on the Advent room, and I feel like I should be able to actually find the page for the first box but it keeps timing out. My Openvpn is running. I have Burp Suite open and Intercept off. I can get to places like Hotmail....but not the machine that I deployed.

#

THoughts?

final mortar
#

!multivpn

proud scarabBOT
#
TryHackMe
Learn how to look for duplicate instance of your OpenVPN connection.
β€’ Step 1

Make sure you have setup your VPN connection correctly https://tryhackme.com/room/openvpn

β€’ Step 2

Type ps aux | grep openvpn into your terminal and press enter

β€’ Step 3

If there's more than one line (that don't start with "grep" or sudo), do the following steps

β€’ Step 4

Type sudo killall openvpn into your terminal and press enter

β€’ Step 5

Start the VPN with sudo openvpn <path-to-config>

final mortar
#

!vpnscript

proud scarabBOT
final mortar
#

@stone oyster

noble locust
#

chika..

stone oyster
#

thx

sturdy dock
#

can i get hint for pyschobreak room task2 question3?

true prairie
#

but the answer format is of single integer input
@noble locust If you're still stuck try reading out only the /etc/shells file

#

Can I get a hint about the FTP passwd? on the psychobreak room
@somber crag The FTP username and password should be in the same file...

maiden violet
#

Can anyone help me for Psycho Break Task 2 Question 3

stuck pendant
#

any hint for psycho break escape laura?

true prairie
#

Can anyone help me for Psycho Break Task 2 Question 3
@maiden violet Focus on enumerating the safe place :)

#

any hint for psycho break escape laura?
@stuck pendant I think a good hint is to imagine running away from her with the help of system known commands

white salmon
#

im stucked with keepers key in psychobreak room

#

any hints ??

past oxide
#

trying this lab
got stuck at what is the username of a logged on user?
i trided bruteforcing using dirsearch gobuster
but the username didnt came in the result
anyone?

clear creek
#

hello Guys,
I m stuck in the Psycho Break, where you have to decrypt a piece of text (task2.2)
I tried some bases, rot, ceasar, vigener,... I cant get it.
some hints? thx

red minnow
#

@clear creek Hint: cipher

clear creek
#

@red minnow thx I ll try some of them

white salmon
#

hello Guys,
I m stuck in the Psycho Break, where you have to decrypt a piece of text (task2.2)
I tried some bases, rot, ceasar, vigener,... I cant get it.
some hints? thx
@clear creek altbash cipher

clear creek
#

@white salmon yep found it. I never heard of it till now ^^

stuck pendant
#

@white salmon dont give the direct answer let people try thats where they learn

white salmon
#

Hello i'm in the linux challenge room task 4

#

"Analyse the flag 24 compiled C program. Find a command that might reveal human readable strings when looking in the source code."

#

and i don't know why it doesn't work

#

(i'm with the good user for this operation (garry))

#

Can somebody help me? Thanks

red minnow
#

try nano ?

white salmon
#

Nop it's a C program

#

can't read it like this*

red minnow
#

strings then

white salmon
#

Strings??*

red minnow
#

strings file.c

oblique cliff
#

Nop it's a C program
@white salmon for the record gedit wouldn’t have worked either it would’ve looked the same as that nano output

white salmon
#

Aw thanks

#

i'm try to used strings

#

but

sullen glen
white salmon
#

Thanks you @red minnow strings work

trail pebble
#

hey am doing psycho break and stuck on "i am having a terrible nightmare statement" can anyone give me a hint??

red minnow
#

@trail pebble sure, pm me

white salmon
#

sry

#

@trail pebble sure, pm me
@red minnow gimme hint too

sinful thicket
#

@sullen glen check your dm buddy

iron sapphire
#

can't wait to see the walkthroughs on 'Year of the Pig'

#

just wrote my first python script with concurrency

#

🀘

bleak gust
#

Can someone share some hint for crypto1c from cct2019? Im out of ideas 😭

spiral yew
#

On the Mr. Robot CTF box, for Key 2 there is a hint that says "white-colored font". I already got Key 2, but I did not understand the relevance of that hint since it did not involve white-font? I also checked the included write-ups with the box, and they all seemed to use a similar process I did. Would anyone be able to clarify what that meant?

echo salmon
#

can someone give a hint on 'i am having a terrible nightmare statement' in psycho break room

white salmon
#

can someone give a hint on 'i am having a terrible nightmare statement' in psycho break room
@echo salmon bruteforce

soft fulcrum
#

any help to Escape Laura? Psycho Break Room

slim narwhal
#

Need help to escape Laura also please :)

solar scroll
#

need help in Break Room (terrible nightmare)

trim haven
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
#

Are you able to type dir

stuck fractal
#

Please mark that as a spoiler or remove the passwords

white salmon
#

ow sorry

#

Will do it the next time

trim haven
#

You'll have to do it now

#

Just for the people who haven't completed the room

white salmon
#

Okey i will delete it

#

@trim haven I will try to dir

trim haven
#

You'll have to do it now
@trim haven Sorry I hope this didn't seem commanding, I meant it in a different way :(

white salmon
#

No problem, i understand your point πŸ™‚

soft fulcrum
#

Hint for Task 2 Quest 4 Psycho Break Room pls

white salmon
#

@trim haven dir also doesn't work

trim haven
#

It seems like there is something wrong with your smbclient

white salmon
#

I am getting these error message when i execute any command

#

NT_STATUS_INVALID_INFO_CLASS listing *

trail pebble
#

On the Mr. Robot CTF box, for Key 2 there is a hint that says "white-colored font". I already got Key 2, but I did not understand the relevance of that hint since it did not involve white-font? I also checked the included write-ups with the box, and they all seemed to use a similar process I did. Would anyone be able to clarify what that meant?
@spiral yew

yes the thing u should know is written on that web page but the trick is fontcolor is white and the background too so u can't see that

spiral yew
#

Hmm, I solved the whole box without that. I will go back and look around.

trail pebble
#

there are obv multiple ways to get same data

gray garden
#

Task 2 Quest 4 Psycho Break Room Escape Laura - is ||pkill|| a rabbit hole, spent all day on this and can only list the directory, no other commands seems to work - Would really welcome a hint on this one.

trail pebble
#

need a hint for psycho break
am at task 5 sshing the user found in previous task....
just want to know is the password in rockyou ??

solar scroll
#

@gray garden same for me

trail pebble
#

Task 2 Quest 4 Psycho Break Room Escape Laura - is ||pkill|| a rabbit hole, spent all day on this and can only list the directory, no other commands seems to work - Would really welcome a hint on this one.
@gray garden
do you get the web shell format ?

stuck fractal
#

need a hint for psycho break
am at task 5 sshing the user found in previous task....
just want to know is the password in rockyou ??
@trail pebble if you're brute forcing for more than 5 minutes, then you shouldn't be brute forcing

#

That's the rule here for box creators

gray garden
#

@gray garden
do you get the web shell format ?
@trail pebble yes

trail pebble
#

@trail pebble if you're brute forcing for more than 5 minutes, then you shouldn't be brute forcing
@stuck fractal
more than half an hour

#

@trail pebble yes
@gray garden
try listing contents of previous directory

stuck fractal
#

Then you probably shouldn't be brute forcing.

#

The rule is 5 minutes.

trail pebble
#

can you tell me the general limit for no of works coz my pc gets reqs like 200 tries/min

stuck fractal
#

There isn't one

#

It's based on time

#

30 minutes is definitely too long.

gray garden
#

@gray garden
try listing contents of previous directory
@trail pebble Thanks for the hint, but I must be missing a trick here somewhere:-)

trail pebble
#

@trail pebble Thanks for the hint, but I must be missing a trick here somewhere:-)
@gray garden
can u list current directory ??

gray garden
#

@gray garden
can u list current directory ??
@trail pebble Yes, no problem there

trail pebble
#

results will reflect in the same page

gray garden
#

results will reflect in the same page
@trail pebble As soon as I extend ls /[DIRECTORY], I get a 'Command not found'

trail pebble
#

you are very close my friend

#

just remember relative path can be useful too sometimes

gray garden
#

just remember relative path can be useful too sometimes
@trail pebble πŸ™‚ I have it, thank you for your help, that is one hell of a string I need to decode

trail pebble
#

the joy is the price for struggle blobheart

graceful valley
#

Stuck on Blue room, following the guide but I can't get past task 2. I've checked LHOST and RHOSTS to make sure they're set correctly, but the exploit completes without creating sessions

#

Previously have done the Nmap and Metasploit rooms, believe I have everything set properly

flint lintel
#

I am on blue room too, but I think I found an inconsistency rather than an issue

#

Stuck on Blue room, following the guide but I can't get past task 2. I've checked LHOST and RHOSTS to make sure they're set correctly, but the exploit completes without creating sessions
@graceful valley run the options command and see if you are missing anything

graceful valley
#

@flint lintel Double checked all my vars, they seem all to be set correctly. Was able to connect after several tries, I'm attributing my problems to "This can occasionally fail, try running it a couple times" - found in the writeup

flint lintel
#

I was also running into the same issues, but the PAYLOAD wasn't set right

final mortar
#

Blue exploit is not prefect. It can not work sometimes, It can auto bork after a couple failed tries

graceful valley
#

I don't even have a PAYLOAD option in my options list

flint lintel
#

it won't show there

#

you have to type get PAYLOAD

graceful valley
#

oh... well... that might be my next problem

flint lintel
#

I had to set it with meterpreter/reverse_tcp

final mortar
#

it won't show there
@flint lintel It will if it has failed atleast once

#

@graceful valley Screenshot your options please

graceful valley
#

I'm giving up on it for the day, my brain is cooked

flint lintel
#

My issue is that I immediately get a meterpreter shell, when the rest of the tasks guide me through upgrading a regular shell to meterpreter

graceful valley
#

I also got dumped right into the meterpreter shell

final mortar
#

Metasploit now gives you a meterepreter shell directly @flint lintel It's just how it is now. You can skip the shell_to_metrepreter part

flint lintel
#

Metasploit now gives you a meterepreter shell directly @flint lintel It's just how it is now. You can skip the shell_to_metrepreter part
@final mortar ah awesome, thanks

final mortar
#

I also got dumped right into the meterpreter shell
@graceful valley Which is all right πŸ™‚ Skip the conversion part in practical, but read through it

#

Screenshot of my options
@graceful valley So this works then. Right ?

graceful valley
#

It did work, at least twice, though I run out of time, my machine expires, IRL gets in the way, and when I come back to it the struggle starts over

#

I'm going to take a break from it for the night, maybe read the writeup over and try again tomorrow

flint lintel
#

It did work, at least twice, though I run out of time, my machine expires, IRL gets in the way, and when I come back to it the struggle starts over
@graceful valley once you repeat the process a few times, its pretty quick. I can get it down to sub-minute

graceful valley
#

@flint lintel Yeah, I was getting pretty quick at the metasploit room

#

@flint lintel @final mortar Thanks for the help πŸ™‚

flint lintel
#

@flint lintel @final mortar Thanks for the help πŸ™‚
@graceful valley all good!

vast wagon
#

I need help in psycho break room with task 2 q3 "The keeper's key" where I get 4 images. I tried a lot of stego techniques but none worked. Anyone pls throw some hint.

vast wagon
#

||"I think I'm having a terrible nightmare. Search through me and find it "|| help me in this

pale slate
#

need a little help in Year of the Pig room foothold?

final mortar
#

need a little help in Year of the Pig room foothold?
@pale slate New Room give it some time

#

Cap-L3v1 read the next question in the task for a hint maybe ?

drowsy sequoia
#

Need a hint for task 2 questions 3 in psycho break, i think i got the nightmare but how to make it usable.

vast wagon
#

Any hint for me @drowsy sequoia . I'm stuck on the same task.

drowsy sequoia
#

Any hint for me @drowsy sequoia . I'm stuck on the same task.
@vast wagon sometimes what looks is the way is not the way you'll have to do a bit of digging on the other. Sidee.

#

Hope my hint gives you a source to startπŸ‘

viscid void
#

Hey

drowsy sequoia
#

Any hints for the next step.please

fleet pike
#

So in YOTP. I have enumerated what appears to be a login page. embedded into that page is some strings .. ive had partial luck decoding this, I can get it back to plain english where i see things like "credentials" and a hell of an api fetch query. But I have found nothing on this site matches the constraints of what the page is asking for. What technique do i use from here, or Am i barking up the wrong tree.

#

Is this a "Feed it one pig, feed it two pigs, feed it -1 pigs" situation?

wintry yarrow
#

@fleet pike hints and help are allowed after 72 hours from release of the room.

drowsy sequoia
#

Need a hint for task 2 questions 3 in psycho break, i think i got the nightmare but how to make it usable.
@drowsy sequoia here pleaseπŸ˜‚

copper widget
#

I need help in psycho break room with task 2 q3 "The keeper's key" where I get 4 images. I tried a lot of stego techniques but none worked. Anyone pls throw some hint.
@vast wagon not about images

solar scroll
#

have someone time for Psycho Break help?

clear creek
#

depends where you re in ^^

solar scroll
#

Task 2 #4, Laura...

clear creek
#

look at the source code

solar scroll
#

i find ||"shell"||

clear creek
#

yep maybe you can use it some where you can write in it

weary quarry
ornate arrow
#

have someone time for Psycho Break help?
@solar scroll ahah I'm stuck at Task2 #3

weary quarry
solar scroll
#

some one on Psycho Break Task2 #4, if find somthing

wintry yarrow
#

@weary quarry if its saying wrong then your answer is wrong.

weary quarry
#

yes i have rooted

#

i know it is ||remote code exec||

wintry yarrow
#

Its wrong.

solar scroll
#

some one on Psycho Break Task2 #4, if find somthing
@solar scroll have it

ionic marsh
#

@weary quarry look harder.

#

@weary quarry search again.

weary quarry
#

Sure

#

I hope treid all combinations

#

Never mind I havr rooted

final mortar
#

Hey @weary quarry can you help me out then πŸ™‚

weary quarry
#

I have not done that machine @final mortar

final mortar
#

Ah my bad

wintry yarrow
#

72 hours are not passed since the release of room so no. You have to wait few more hours.

sick sun
#

oh oke thanks

thorny atlas
#

Anybody here done Revenge? I got root but can't seem to find the final flag
nvm got it

gilded pasture
#

is it possibile to find xss on thm machines?

stuck fractal
#

Yes

wise venture
#

Hello, a quick query, looking at day 10 of Advent of Cyber, how do you come to find that its running a vulnerable version of struts? I am using nmap and it just shows me Apache/Coyote, am I missing something?

stuck fractal
#

Tried nikto?

wise venture
#

no, will try that now, thanks

#

@stuck fractal boom, cheers

granite flame
#

Guys, i joined Smag Grotto room and i stucked in the middle. After that, i decided to look up some writeups and I had to put domain name into my /etc/hosts file. Why should i do that?

#

Can i just click it on my browser directly with the IP?

#

Guys, i joined Smag Grotto room and i stucked in the middle. After that, i decided to look up some writeups and I had to put domain name into my /etc/hosts file. Why should i do that?
@granite flame With the IP too

graceful dagger
#

I've been stuck at the admin login page for Year of the Pig since it came out. I don't think I'm able to exploit the obfuscated js file I found, so I have a feeling this is a password guessing situation. The password hint specifically states the password should be a memorable word, then 2 numbers, then a special character. I have not found any to work, unless this is just some cruel rabbit hole

wise valley
#

@plush estuary ^

plush estuary
#

I got past that bit ok Myles

#

@graceful dagger Take a look at what happening with the password before its sent to the server

#

The password is also not in any password list

oblique cliff
#

Can i just click it on my browser directly with the IP?
@granite flame you need to add it to your hosts file if it has virtual host routing like that box does

granite flame
#

I am sorry. But what is actually virtual host?

granite flame
#

Yeah, i have to google it first

#

Thankss..

opaque dagger
#

OWASP juiceShop task 7, q2 for the persistent XSS, I’ve done it many, many times and no flag ever comes up. What do I need to do as clearly there is a bug on this question to get the flag? Also tried changing the settings in Firefox config:about browser.urlbar.JavaScript boleen to false with no joy.

atomic shuttle
#

hi @plush estuary mind if i ask for some nudges on login page for yotp? been stuck there for quite a while now

#

yotpig room has passed 72 hours isnt it

astral smelt
#

Muir made YOTP

stuck fractal
#

Muir made YOTP
@astral smelt Yes, but cake was here with hints a little earlier

#

Like 8 hours ago lol

astral smelt
#

Oh right

plush estuary
#

@atomic shuttle You will need to make your own wordlist for this one :)

true prairie
#

OWASP juiceShop task 7, q2 for the persistent XSS, I’ve done it many, many times and no flag ever comes up. What do I need to do as clearly there is a bug on this question to get the flag? Also tried changing the settings in Firefox config:about browser.urlbar.JavaScript boleen to false with no joy.
@opaque dagger I did this room just some hours ago. Everything should work out fine following the instructions

plush estuary
#

Sometimes burp stops the flag from being shown, just disable it and you should see the flag

shut lion
oblique cliff
#

Can you show the output @shut lion

#

As well as how you’re running it

shut lion
oblique cliff
#

And the output?

wintry yarrow
#

Go make lunch I'm here.

oblique cliff
#

Thank you darky blobheart

shut lion
wintry yarrow
#

It takes some time.

oblique cliff
#

That’s wrong tho

trim haven
#

try changing it from http://10.10.40.185/simple/admin to http://10.10.40.185/simple/ ?

oblique cliff
#

Tell him how to fix

#

But also @wintry yarrow

wintry yarrow
#

Also, try to change timer to 5 or something on code.

oblique cliff
#

Ok grill is preheated. Byeeeee

trim haven
#

Bye Blob

wintry yarrow
#

Ty for the honor. blobheart

shut lion
#

@trim haven @wintry yarrow let me implement your suggestions

#

thanks in advance

shut lion
#

The advice has worked out for me πŸ‘

wintry yarrow
#

Great. πŸ™‚

rose cape
#

hey guys, im pushing through smaggrotto right now and im struggling with || getting a reverse shell from development.smag.thm/admin.php || ive tried || bash, python, perl, nc and even using curl to output writable directories to my localhost via requests|| no luck so far, im sure im missing something small and am being silly. a nudge would greatly be appreciated!

oblique cliff
#

@rose cape could you show your syntax?

stuck fractal
#

nc with mkfifo almost always works

oblique cliff
#

i know at least 2 of those work

rose cape
#

which method do you want me to show you

oblique cliff
#

netcat

rose cape
#

not popping anything

oblique cliff
#

nc with mkfifo almost always works

rose cape
#

omg

#

πŸ€¦β€β™‚οΈ

oblique cliff
rose cape
#

yo thanks sorry about that

#

i skimmed over what ninja said just reacting with the cat knife thing lol

oblique cliff
#

lmao

rose cape
#

i should know by now ninja is the enlightened one blobfingerguns

oblique cliff
#

its easy to skip over what @stuck fractal is saying and just react with blobknife

#

he gets that kinda reaction from people

rose cape
#

lol

stuck fractal
#

I'm correct weirdly often

tidal sedge
#

i skimmed over what ninja said just reacting with the cat knife thing lol
@rose cape It's a blobknife! angrycooctus

rose cape
#

omg my bad :(((((((((((

oblique cliff
#

how dare you

white salmon
#

what's a good way to priv esc from sudoedit?

stuck fractal
#

Room, task, question, have you done your research?

white salmon
#

hmm, I don't want to spoil anything so is it k if I dm instead?

stuck fractal
#

Not really

#

Mark it as a spoiler if you need to

white salmon
#

kk, the room's year of the pig. I've gotten pretty far and I'm on the last step of exploitation right now

#

I'm fairly certain it's to deal with ||environment variables|| but I'm uncertain about it

gilded pasture
#

can i ask a hint about Revenge?

ocean wind
#

Hi , curious if anyone faced this in Retro , after getting reverse shell , can't get output of any command !

wicked granite
#

Hi, im new to all this, how do i change options in metasploit, im doing eternal bule and i got stuck

white salmon
#

Hi, im new to all this, how do i change options in metasploit, im doing eternal bule and i got stuck
@wicked granite set variable value

wicked granite
#

sounds good

wicked granite
#

Im stuck on T3 Q6 of rpmetasploit

#

what does it mean by netcat like feature

stuck fractal
#

Do you know what netcat is?

wicked granite
#

no

stuck fractal
#

Well there's a great place to start then

wicked granite
#

is it like network wide cat function?

stuck fractal
#

Research it!

#

Research is a fundamental skill in cybersec

wicked granite
#

yea, im reading on it rn

#

Hey james ty, i found the answer while it was right in my face

white salmon
#

hey guys

stuck fractal
#

Just ask directly.

white salmon
#

i need a hint for Flag 3 is located where bob's bash history gets stored.

#

i tried diffrent command i googled it didn't work

stuck fractal
#

Look for a file.

white salmon
#

permission denied

#

sorry but which box are you doing right now?

wicked granite
#

On the metasploit box, T5 Q9 do i replace where it says payload

white salmon
#

yeah, otherwise it won't work

#

it's a meterpreter shell so if you tried catching it via nc it'll segfault iirc

#

set payload, not use payload

opaque monolith
#

task11 linux tutorial?

stuck fractal
#

What's up?

opaque monolith
#

i know a bit of linux but something doesnt work

stuck fractal
#

You're going to have to be MUCH less vague.

opaque monolith
#

when i try to run a binary it writes permission denied

stuck fractal
#

Show us.

#

Screenshot

opaque monolith
#

i do have ubuntu

#

i dual booted my pc

#

i had ubuntu first and then i downloaded win10

stuck fractal
#

That's not the binary

#

You still need to SSH into the machine

#

You have skipped over that part.

opaque monolith
#

oh

#

ok

stuck fractal
#

You need to SSH into the VM that you deploy int he room

#

Not the attackbox

opaque monolith
#

wdym

#

i downloaded putty rn

visual vessel
#

There is a DEPLOY button on the 1st question for the machine

opaque monolith
#

ik

visual vessel
#

ssh into it with putty

fathom ridge
#

instructions unclear

#

no wonder why everyone is stuck at the same place

stuck fractal
#

The instructions are clear.

fathom ridge
#

where does this /tmp/ stuff comes from then

#

it tells me no information about that

stuck fractal
#

It's an example.

fathom ridge
#

how am I supposed to know that lol

stuck fractal
#

You're expected to do your own research as well.

fathom ridge
#

then its like cheating

opaque monolith
#

so i need shiba1and my pc ip?

stuck fractal
#

They're literally screenshots to show examples of the command, how is that not an example?

fathom ridge
#

i thought it tells me to do the same way

stuck fractal
#

then its like cheating
@fathom ridge That's not how infosec works. Infosec is ALL about research

fathom ridge
#

as in the pictures

stuck fractal
#

i thought it tells me to do the same way
@fathom ridge It does not. Read the instructions.

opaque monolith
#

?

fathom ridge
#

Walah i quit bro

stuck fractal
#

Bye.

opaque monolith
#

so i need shiba1and my pc ip?
@opaque monolith is it k @stuck fractal

stuck fractal
#

No

visual vessel
#

Deploy the machine here, and get the Ip from there and put it into putty @opaque monolith

stuck fractal
#

You need to deploy the machine in the room

#

Get the IP from Active Machine Information

fathom ridge
#

i did that

opaque monolith
#

where is it?

#

activemachine info

stuck fractal
#

it comes up when you click the deploy button

opaque monolith
#

it worked!

#

i used the welcome machine

stuck fractal
#

It does explicitly warn you about that

opaque monolith
#

thx im dumb

#

is it arch?\

visual vessel
#

ubuntu 18

stuck fractal
#

is it arch?
@opaque monolith Never.

#

THM doesn't support uploading it, so you won't see an arch machine on THM ever.

#

it's possible but there's not much point

opaque monolith
#

oh

#

ok

#

i have ubuntu 18.04

fathom ridge
#

I just tried running the noot.txt

opaque monolith
#

i dual booted it

fathom ridge
#

it says permission denied

opaque monolith
#

bruh

stuck fractal
#

That's a blank text file

#

Why would that be executable as a binary?

#

You're told the name of the binary.

fathom ridge
#

this is too hard KEKSad

median reef
#

don't quit

#

try some time later

stuck fractal
#

There's no way to instantly become a master hacker

#

You need to learn, that takes work. And research.

opaque monolith
#

putty isnt connecting

#

connection timed out

median reef
#

screen shot

opaque monolith
#

sure

median reef
#

are you connected to openvpn?

stuck fractal
#

Are you connected to the VPN?

opaque monolith
#

no

stuck fractal
#

(You can SSH into the machine from the attackbox)

#

im fiber
@opaque monolith That's not related.

opaque monolith
#

yeah

#

im dumb

median reef
#

you need to connect to thm network (using openvpn) if you are using your own personal machine

opaque monolith
#

downloaded

#

how do i connect to thm?

stuck fractal
#

!vpn

proud scarabBOT
opaque monolith
#

k

#

what happend to eu2 servers

stuck fractal
#

Nothing

opaque monolith
#

page lost in matrix

median reef
#

refresh

stuck fractal
#

@tacit roost if you're around, EU2 seems to be 404ing again

#

refresh
@median reef Nope

#

Regenerate, and try again

opaque monolith
#

it does 04

stuck fractal
#

Otherwise it's something on THM's side

opaque monolith
#

404

#

ok

visual vessel
#

try eu1

opaque monolith
#

i did

#

it worked

#

ill just use ubuntu 18.04 next time

stuck fractal
#

ill just use ubuntu 18.04 next time
@opaque monolith That doesn't really relate at all here

opaque monolith
#

yay

#

ive done it

stuck fractal
#

Please don't post answers or passwords

opaque monolith
#

oh yeah

#

sry

#

wdym task12 by specify which shell?

stuck fractal
#

It's asking about su

#

Read the manual

opaque monolith
#

i did

stuck fractal
#

It's in there.

#

You can scroll in the manual

opaque monolith
#

this ?

#

ok

#

i did it

#

sry again

stuck fractal
#

Man pages are gold

#

Super useful

stuck fractal
#

Please don't show answers @barren tulip

#

But you didn't change user when you were told to

barren tulip
#

oopsies

#

oh hmm thanks

safe nova
#

Hi, I am doing the OWASP TOP 10 room, Day 9, task 30, I have to search in exploit-database, but I dont know what I have to search

#

the hint is:

You know its a bookstore application, you should check for recent unauthenticated bookstore app rce's.

hollow maple
#

@safe nova Well, if we know it`s a book store, try searchsploit something like "searchsploit book store", the description says it's a RCE, so it's easy, make sure you edit the exploit.
But, you need to find directory(ies) with gobuster or dirb or dirbuster ..., after that you will find more details about ..

white salmon
stuck fractal
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
    @white salmon
opaque monolith
#

linux task 18 .2

#

when i did echo $home didnt show anything

stuck fractal
#

Variables are case sensitive

opaque monolith
#

and $Home

#

oh ok

#

lol

#

u wrote "home" in the question and u didnt mention case sensitive

stuck fractal
#

I didn't write that

opaque monolith
#

ok

opaque monolith
#

can someone help with binary- shiba2?

stuck fractal
#

Yeah, it's best to just ask directly and someone will help.

opaque monolith
#

ok

#

so

#

i didnt find test1234

#

i tried ls -a |grep $test1234

stuck fractal
#

It's an environment variable

#

That you need to create

#

It's not a file

opaque monolith
#

ok

#

i created test1234

#

with export test1234=$USER

#

is it ok?

stuck fractal
#

Try it and see

opaque monolith
#

i tried to cat it

#

but it did something weird

stuck fractal
#

Yep, don't cat a compiled binary

#

Some of the bytes will be weird characters, because it's raw binary rather than text

opaque monolith
#

when i echoed it it wrote shiba2

stuck fractal
#

You need to set the variable

#

Then run the binary

#

The binary will check the value of the variable and if it's set right you'll be given the password

opaque monolith
#

wdym by setting it

stuck fractal
#

IDk if you've done programming before

#

But setting a variable, putting a value in there

opaque monolith
#

i did

stuck fractal
#

yea

#

So then run the binary

#

And you'll get the password

opaque monolith
#

i forgot to run

balmy crystal
#

hello, could somebody help me ? i posted my issue on #room-help fi somebody could, ill be thankful (hope that`s the word)

lunar sorrel
#

Someone around I can DM who has already completed Dave's Blog and has an understanding of ROP? I completed the room recently and I want to verify that I understand the exploit necessary for the final flag correctly.

thorny atlas
#

@lunar sorrel I might help

#

if you still need it

drowsy sequoia
#

Can i get any hints for revenge please

wicked granite
#

Im on room blue and i keep getting the message "exploit completed, but no session was created"

drowsy sequoia
#

Im on room blue and i keep getting the message "exploit completed, but no session was created"
@wicked granite have you checked your payload?

wicked granite
#

no, how do i do that again?