#room-hints

1 messages Β· Page 68 of 1

thorny drift
#

I have to run the binary not cat the output

#

apologies

thorny drift
#

So guys, one more question. im at task 33. Ive created a dir called test with a file called test1234, where do I start searching from the binary shiba4?

#

Apologies for the dumb questions

winged mist
#

Try switching directories/users

thorny drift
#

ok will do

#

thank you

winged mist
thorny drift
#

@winged mist Hi Nerdy Elf, I tried creating the dir test and the the file test4. even tried creating the binary shiba 4 and running cat on it, no joy πŸ™‚

#

Im I missing something here?

#

Thanks for the help

#

new to linux so learning as Im going along

winged mist
#

There’s a directory you are told you look at yeah?

thorny drift
#

Oh so shiba 4 already exists

#

Ill find it

#

thanks man

winged mist
#

||Find|| to your rescue

cedar axle
#

@lyric oasis you're actually really close, use a cyclic pattern, mona makes it easier, but it doesnt matter, you can search manually, just get what ends up in EIP and search your pattern for it

#

gonna write a program, thats the opposite to find, and call it lose, puts the file at a random location in your filesystem

lyric oasis
night fractal
#

||makes me think of HTML headers, but I don't know which port and which headers since they all seem to not matter||

white salmon
#

On WireShark 101 room task7 i don't get it " What 4 packets are Reply packets?" i found thos 4 packet but 😩 i'm stuck

median compass
#

it just wants the numbers of the packets, first column in the wireshark table

#

so e.g. 1, 2, 10, 99

white salmon
#

it's the Flags in DNS ?

median compass
#

no, you have wireshark open right?

white salmon
#

yes

median compass
#

and the main part of the screen is a big table, each row is a packet captured on the interface

#

and you have columns for destination IP, source IP, protocol etc

#

still with me?

white salmon
#

yes

median compass
#

ok, what's the left-most column called?

white salmon
#

info

median compass
#

LEFT-most

#

isn't info the right-most?

white salmon
#

oups πŸ™‚

#

No.

median compass
#

got the answer now?

white salmon
#

oh c'mon it's just those No. for "Reply packets" ?

#

You got them correct the format is wrong

#

i had the same problem

#

dm me if u want

median compass
#

yeah, it's asking can you identify the packets, and that's how they're identified, with a unique number

white salmon
#

yeah but the order of them has 2 be correct or it will say incorrect answer

#

😫 i been trying to find something else more complicate than this.

#

Thanks @median compass

#

hint on this question need to be made or ask the question on other form. Its hard when u don't get what is ask.

white salmon
#

i get those packet but still wrong in the answer

#

||76.400.459.520|| i still don't get it

median compass
#

the 'Answer format' that fills the box before you start typing shows you a pattern for the answer

#

it's commas, not full-stops, between the numbers

white salmon
#

yea he got it

#

he dmed me

knotty latch
#

Hi together,
i am doing wifi hacking 101 using aircrack-ng

#

first question on section 2 uses airmon-ng

#

but I somehow have only aircrack but not airmon on my kali machine

final mortar
#

aircrack-ng is a suite I believe. It you have one of them, you should have all of them

knotty latch
#

yes

#

Since aircrack-ng is installed, you already have airmon-ng, but it’s in /usr/sbin so it’s not on regular users’ PATH. You typically need to run it as root: sudo airmon-ng

#

found this

#

thanks\

final mortar
#

You did your own research while waiting for someone to answer. I like it

fallow sapphire
#

Yo all !!
Need some informations about Mr Robot chall

After how many iterations did you find right password to login ???
πŸ˜… πŸ˜… πŸ˜…

median compass
#

you should only need one to get the password as far as I remember @fallow sapphire

cedar axle
#

takes way more than 5 minutes

frozen scaffold
#

do all the machines use a password from rockyou?

median compass
#

isn't there a wordlist for the Mr. Robot room?

frozen scaffold
#

idk

median compass
#

if you have a room that needs a password to be cracked then it's usually in rockyou yes

frozen scaffold
#

ight thanks

median compass
#

some passwords are not meant to be cracked though

frozen scaffold
#

bc i have a passlist thats 14.5 gigs uncompressed

#

yea ik

stuck fractal
frozen scaffold
#

oh ight then

#

rockyou is kinda old tho isnt it

median compass
#

that's not really the point, the point is being able to crack, no one learns anything extra from spending 3 days running hydra, hence "should take 5 minutes maximum"

stuck fractal
#

See how many of the linkedin breach passwords can be cracked with rockyou

#

That sort of thing shows you that rockyou is not useless

frozen scaffold
#

oh ok then i get the point

cedar axle
#

meh, i recovered my bosses password with rockyou
because he asked

frozen scaffold
#

man i thought rockyou was outdated

cedar axle
#

it probably is

#

but stupidity isnt

frozen scaffold
#

yea weak passwords

stuck fractal
#

Ok, I'd need more context but the quote makes make it seem very very sketchy

#

If it was an online service etc, then consent from the user isn't enough. You're attacking facebook etcs infra which is illegal.

frozen scaffold
#

i will hack my own server

#

its so easy

stuck fractal
#

Yeah let's move the conversation either back on topic or to a different channel

frozen scaffold
#

tru

fallow sapphire
cedar axle
#

try rockyou in reverse

fallow sapphire
stuck fractal
#

I think you're meant to remove duplicates from the list

fallow sapphire
#

πŸ‘ πŸ‘

cedar axle
#

this one?

median compass
#

sorry, when you said iterations I thought you meant you were doing it repeatedly, my bad. My point was only that once you have the username the password is in the wordlist, you only have to run that once and I don't remember it taking all that long

#

if you're trying the wordlist and not getting the password then make sure you have the right username

white salmon
#

I'm also working on Mr Robot CTF (2nd flag). I thought... I obtained the username and password for the Wordpress site. But it's incorrect, I'm inputting what hydra provided. Any suggestions please?

stuck fractal
#

Try wpscan or wpenum or whatever it's called

#

It bruteforces WP much better

median compass
#

ok, I just went and checked, the password is in there, but towards the end, you could try reversing the file and running it then @fallow sapphire, that will speed you up

white salmon
#

@stuck fractal Thank you

cedar axle
#

@white salmon think about the TV series

median compass
#

there's no need to guess based on the show, you can extract both the username and password with tools

fallow sapphire
fallow sapphire
cedar axle
#

πŸ‘

white salmon
#

@cedar axle- Cheers for the tip! I haven't watch it yet, but think I will now.

fallow sapphire
#

Thanks @median compass and @cedar axle

cedar axle
#

πŸ‘

oak swallow
#

I'm stuck on the same problem. Did you figure out the answer?

oak swallow
#

@median compass I was totally banging my head against the wall looking at the CAR-2014-11-004 section...

median compass
#

got it now though?

oak swallow
#

@median compass Within seconds of looking at the correct article. Lol..

karmic sky
#

It's a great room and that was really the only confuzzled bit on it

tawny remnant
#

hey, so i'm doing the ignite room right now and am having troubles getting a reverse shell going

#

i found the payload and can use it, but for some reason when i run the payload with my netcat listening, i don't get the shell

pseudo wraith
#

@tawny remnant just check ip address and port again bro or try another method like meterpreter.

tawny remnant
#

i triple checked the ip addresses

#

i couldnt find anything for it on metasploit, only a payload on exploitdb

#

whats a website where i can submit text

#

so i can show the payload im using

pseudo wraith
#

@tawny remnant try another payload or other method . Can u give me room's name?

hard pebble
#

Seems like I've hit the same snag...

white salmon
#

good morning. Maybe somebody could help me with my question. I was wondering it there is a vnc server which could be run from a reverse-shell session on windows. My goal would be to get an entrypoint via gui even if remote desktop is disabled for the user. Any hints?

wintry yarrow
white salmon
#

yes its related to a room - but I don't want to spoil anything about it

night fractal
cerulean isle
#

hi

#

i was doing envizon but not getting idea what to do ?

all i see is login page and login page of admin

i tried some sqli payloads there but no use

#

can anyone guide me ?

white salmon
#

no hints for the first 72 hours

cerulean isle
#

ok

gusty hedge
#

Not sure if this is a hint, but read the task description...

cerulean isle
#

yeah i read description

gusty hedge
#

Any you read the part, that this box should be testet in a whitebox scenario?

cerulean isle
#

yeah

white salmon
#

this counts as hints

gusty hedge
exotic echo
#

Hi im stuck at Linux Challenge, flag 16 "Flag 16 lies within another system mount." I did findmnt to see all mounts but i cant really find the flag

final mortar
#

Have you checked for any mounted removable media @exotic echo

exotic echo
#

not sure what that is but will take a look into it

final mortar
#

:)

exotic echo
#

found it πŸ™‚

#

thanks dude

#

will still read it

thorny drift
#

Hi, im on the learn linux room, the last challenge is finding the hidden flag /root/root.txt. I tried the find function nothing showed up. Any hints?

#

I tried it on user shiba 1 to 4

#

it did say permission denied as well if thats of any help with the find results πŸ™‚

white salmon
#

you need another user

thorny drift
#

Ah I see

#

Thanks @white salmon ill try that

limber iron
#

can i ask about hints for You're in a cave ?

final mortar
#

It has passed the 72 hours new room period, so I guess you can

limber iron
#

Okay thanks

#

I got a user but i think brute forcing pass is rabbit hole right ?

exotic echo
#

grep -R -E '^4bceb.{28}$' /

#

Find flag 26 by searching the all files for a string that begins with 4bceb and is 32 characters long.

#

what am i doing wrong?

limber iron
#

Anyone ?

woven mirage
limber iron
tawny remnant
night fractal
#

it's ok, happens to all of us

white salmon
#

Anybody got a foothold on "inacave"

stuck fractal
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
median compass
#

it's better just to ask your question @white salmon, if someone is around who knows the answer and has time then they'll respond, and use spoiler tags (surrounding your message with ||) if necessary

white salmon
#

fellas , any hints how to bypass INVENTORY On "Inacave" (java app)

woven mirage
#

Bypass inventory?

#

Which part are you in?

visual jolt
#

holy hell elf binary debugging/analysis is crazy confusing 😦

#

im following a walkthrough and i am totally lost, is that normal?

astral smelt
#

Following writeups are great because it helps you learn where you go wrong and shows you new techniques you may have never seen before and you can apply them to other rooms, they help you find your strengths and weaknesses in the topic, it's completely normal to follow them there's nothing wrong with that

visual jolt
#

thanks, this is definitely a weak point for me at the moment

white salmon
#

There's no other way than putting serielized objects in www , either can control the environment path

#

whatelse ?

woven mirage
#

Oh I see

#

There is a way of controlling the input of the service so you can send an serialized object to it

#

Check out the hint of the first question

white salmon
#

which question ? i cannot find tt

woven mirage
#

The hint in the room

white salmon
#

wait 2 requests in one ?

woven mirage
#

No

white salmon
#

@woven mirage any more hints pls

#

@woven mirage i don't really get it

woven mirage
#

Okay, you found the vulnerability in action.php didn't you? It works with post, try to use the same vulnerability with get

white salmon
#

but that's a complitely different thing

woven mirage
#

Not if you take a good look at RPG.java

white salmon
#

i quite suck at java , but i do mybest trying

#

does it have to do with encoding ?

woven mirage
#

You don't need to understand much Java to understand most of the application

woven mirage
white salmon
#

yes

#

what's bothering me is , whether the input we give matters

#

hollycrap

#

i got it

#

@woven mirage Thankss for the idea , i appreciate it

timid sequoia
stuck fractal
#

Remove the dash?

#

Run select first

#

Then upload

#

Nah it's just this, those are bullet points

wicked rain
#

any hint on inacave upon entrance? I still struggling with POST. I got some valid actions via dir bust, checked the output, and tested on the application port, but still cannot get /action.php work for a single action. annoying 400...

stuck fractal
#

@timid sequoia Are you sorted now?

timid sequoia
#

yes sir got it thanks πŸ™‚ @stuck fractal

stuck fractal
#

Great, good to hear

woven mirage
pseudo wraith
#

hello physical security intro room
Task 5: padlock bypassing
question number 7
any help please... πŸ˜„

remote gate
#

@pseudo wraith the type of pick you a included in the sparrows orion set

winged mist
#

Look up Bosnianbill’s videos on YouTube

thorny drift
#

guys, total noob. I tried following @white salmon advice of adding a user in order to finish the last task of getting the flag for root/root.txt in the learn linux room. IT keeps saying I can use sudo to add a user and none of the shiba users have root access? I have tried the walkthroughs but prefer not to use them as doing it myself is better for actual learning.

#

cant use sudo

#

also, no idea where to find the root.txt file lol

#

used the find function but just lists all the files in the os

median compass
#

one of the things you should always do while enumerating a machine is do a find for each user you come across and look for files that seem out of place or otherwise interesting. Go back through all the users you found (i.e. become them) and try that

thorny drift
#

will do, thanks @median compass

thorny drift
#

@median compass one last question is how do I change the home directory to that of the user that I su into?

#

it seems to su into the proper user but doesnt change the home directory

median compass
#

there's a few ways, the easiest is to use su - <user> rather than just su <user>

thorny drift
#

ah that will help

median compass
#

or once in as that user you can cd ~ or just cd on it's own usually

thorny drift
#

thank you very much for the help

median compass
#

that can be messed up if some environment variables are not set correctly, so su - is probably the best way to go

#

welcome

royal mirage
#

Hey guys in Misguided ghosts, is there a sequence for the ports to knock?

final mortar
#

There always is

median compass
#

yup, that's knocking

royal mirage
#

so after getting ports from the pcap file, we have to write a script?

median compass
#

well if you know the sequence you can use knock <port>...

royal mirage
#

cool

median compass
#

if you install knockd (i think the package is)

royal mirage
#

no need to specify tcp or udp

#

?

median compass
#

you can specify that yes

#

man knock

royal mirage
#

thanks

#

yea it worked woho

normal olive
#

!rank

wintry yarrow
winged mist
#

Same reference kek

white salmon
#

fellas , "inacave" the root path is it with cave or skeleton

woven mirage
#

Skeleton

pseudo wraith
#

@frozen oasis this room is really difficult

#

currently stuck in Task 5 & Task 6

white salmon
#

@woven mirage i got in with unintended way , i never got cave user

woven mirage
#

Yeah, most people did unintended .-.

white salmon
#

@woven mirage the root way is pretty hard, i've been enumerating the whole day yet go nothing but /bin/kill 😦

#

and docke

#

r

woven mirage
#

Enumerate harder

#

Pretty sure linpeas finds one interesting thing

#

But I'm not 100 sure

white salmon
#

Hopefully i'll find something

royal mirage
#

any hint for getting root in Misguided ghosts?

wintry yarrow
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done.
stuck fractal
#

Have you ran linpeas?

oblique cliff
#

2 routes

#

1 found with linpeas, the other you already passed

#

Linpeas one is easier @royal mirage

royal mirage
#

I kinda found this /usr/sbin/visudo

royal mirage
oblique cliff
#

So try some stuff out if you’ve found something

royal mirage
#

I tried to play with visudo

oblique cliff
#

Well if nothing is working then run linpeas again and read the output closer

royal mirage
#

yeah cool

zinc dome
#

Just escaped "in a cave", insane headache xD ! thx @woven mirage

woven mirage
#

Glad you liked it hehe

zinc dome
#

at beginning i hated it. :p

#

but after all, you made a good one πŸ˜‰ ! all details count

woven mirage
#

i know that some parts are maddening πŸ‘€

white salmon
#

@zinc dome @woven mirage its a heck of a machine, the root part is insane I'm still stuck at it.
pls some help would be appreciated it.

woven mirage
#

you are skeleton right?

white salmon
#

Ye

#

Yes

woven mirage
#

look for an interesting file

white salmon
#

that's the issue, i've been looking all day for something and i can't notice anything interesting

median compass
#

how are your docker skills @white salmon? You might try pausing cave for a moment and doing the new docker room, armed with leet docker skillz you might have more joy rooting cave then

white salmon
#

@median compass Thanks For letting me know but i'm determined to finish this one first.

median compass
#

yeah, but the docker skills

#

you need to know docker, that's the hint

white salmon
#

Boy it was in front of my eyes the whole time

#

ps -ef is quite usefull

#

alot

white salmon
#

@woven mirage @median compass well it's quite a ride, i got root an hour ago in docker yet still enumerating for any interesting things that can lead me escalate to the host, am i missing something ?

median compass
#

just my last hint again i'm afraid, keep at it, you'll find it

stuck fractal
#

@ember gazelle That's still a brand new room, please wait 72 hours from room release before asking questions. As your question contains somewhat of a spoiler, I'm going to delete it.

ember gazelle
#

Oops sorry. I am new here so did not know about it 😬

stuck fractal
#

It's covered under Rule 13

marsh violet
#

Could I get a hint for what to do after getting a shell in room "Chill Hack"? I've done several things but I just can't get it

stuck fractal
#

@marsh violet As I said just above, that's a brand new room so please wait 72 hours before asking for help or hints.

pseudo wraith
#

Hello guys,
Physical security room
Task 6 Question no. 3 & 5.
I am stuck at this stage pepehands

bright steeple
#

need some hint on the mr robot ctf second question
I used hydra to crack the password, but its been like 15 min and still going

#

i use the file downloaded from the robot page

frail rain
#

can you tell us what you did? like the command

#

or your approach

bright steeple
#

hydra -l username -P file IP http-post-form "/wp-login.php:log=^USER^&pwd=^PASS^:The password you entered for the username" -t 30

wintry yarrow
#

Can you show screenshot?

bright steeple
wintry yarrow
#

Looks alright to me. It shouldn't take that long. Try redeploying the box.

bright steeple
#

ok ill try

#

maybe im doing it wrong

wintry yarrow
#

Try with wpscan.

#

wpscan --url http://10.10.133.101 --wordlist /location/of/wordlist/fsocitysortunique.dic --username elliot

white salmon
#

Any help on how to escalate privilege in CHILL HACK Room but anurodh?
I found out that /home/apaar/helpline.sh can be run by www-data but I don't know what to do
Any help?

next granite
#

I'm stuck there too right now but it's a brand new room so we need to wait 72 hours from release for things like hint

radiant hill
#

pleas help me any one (

In the Burp Suite Program that ships with Kali Linux, what mode would you use to manually send a request (often repeating a captured request numerous times)?
)tell me the answer of any easy way to reach the answer

white salmon
#

@next granite oh gotcha thanks ,if you get any idea please ping me

wintry yarrow
#

@white salmon @next granite its a new room. No hints or help are allowed till 72 hours passes. πŸ™‚

marsh violet
#

my bad @stuck fractal . Didn't realize it was new. I've been away for a couple of weeks

#

though I figure it out I believe

formal hawk
#

I also get stucked in this machine now πŸ˜„

orchid root
#

I m doing room Agent sudo
There he is asking to change the user agent to codename but after changing the user name I m still not getting anything.
I have tried reading writeups too but there is also no hint but they are getting some redirection after changing user agent

formal hawk
#

Or you can try with curl

orchid root
orchid root
formal hawk
#

Check User-Agent Switcher and Manager from Firefox Extensions

near shoal
#

morning

tardy gale
#

Okay, I need help, in order to get a flag in a room, i need to listen to a mp3 file, and i have trouble figuring out how to listen to a mp3 in the terminal in the room. i know this must be simple but it is breaking my brain atm

white salmon
#

what room what task

tardy gale
#

Linug Challenges - 32

#

task 5

#

cause nothing is installed on that "box" so i cant listen from there, or what, i dont get it 😦

white salmon
#

you need to download the file to your machine

tardy gale
#

Okay thanks.

#

My brain is so full even the simplest task become hard, I have succeded, thanks for the hint!

white salmon
#

you're welcome

dark schooner
#

Hey guys, have anyone tried chillhack room. Can I have a hint on the privesec part.

white salmon
#

no hints for the first 72 hours

dark schooner
#

Alright I understood. Thanks @white salmon

white salmon
stuck fractal
#

That's still a new room

#

Please wait 72 hours before asking for help on brand new rooms

pallid siren
#

Got a shell, but am now stuck lol

#

This is a good one

balmy verge
#

Yea im stuck on getting root as well

pallid siren
#

Yeah i feel i exhausted everything i know lol been researching past hour or 2

#

Pretty sure when i find it, ill feel dumb lol

balmy verge
#

Ikr

orchid root
#

I m doing room willow

#

Can anyone give me a hint for decrypting the random numbers given on website?

#

@pallid siren I just find out to Bypass the filter😐

median compass
#

do you mean the numbers you see on port 80?

orchid root
#

No@median compass

#

Something like this

median compass
#

those numbers you got by connecting your web browser to port 80 then?

#

try cyberchef

orchid root
stone oyster
#

Hey folks, just looking at the Kenobi room with Samba. Once I get the file, am I correct in thinking that I need to follow all of the instructions found within? Asking only because it's a lot

languid sentinel
#

Just looking for a hint on the cmd input for Upload Vulns Room - Task 8 please. Ive tried just about every cmd input (from "help") going to upload a file but keep getting "invalid command" no matter what. Not sure if im over complicating this at all but any help appreciated.

stone oyster
#

If you feel like you're over-complicating, you probably are. From the viewpoint of a recursive over-complicator

stuck fractal
#

The - are like bullet points

languid sentinel
median compass
#

@stone oyster, that's not instructions, it's a log file of some user actions, it's showing you the time the user made their ssh key and where it's stored and then it's showing you the contents of the ftp server config file

stone oyster
#

And then I search using that info.

#

rty

#

ty

white salmon
# stuck fractal That's still a new room

This is a free room, which means anyone can deploy virtual machines in the room (without being subscribed)! 504 users are in here and this room is 53 days old.

Created by Anurodh

stuck fractal
white salmon
#

It says the room is 53 days old

stuck fractal
#

it is still a newly released room

white salmon
#

Cool then! Lets wait πŸ™‚

stone oyster
#

I need someone to point me in the right direction.

#

In the Kenobi room, using netcat to scan port 111 for the version....once I get nc to work I tried running nmap from there and it just closed.

#

Did I miss a step?

stuck fractal
#

What just closed?

stone oyster
#

netcat

#

it said it succeeded, then sat there. Anything I try to input closes to a new prompt.

stuck fractal
#

-sV?

stone oyster
#

Are you asking if I've used -sV?

stuck fractal
#

You're trying to get the version

#

So use the flag for service version?

#

Not all services give you a version string when you connect

stone oyster
#

Yeah. Was looking and trying.

median compass
#

which task and question are you doing @stone oyster?

stone oyster
#

Kenobi 3-1

median compass
#

which port did nmap say was the FTP port? you put the answer for this into task 2 question 3

stone oyster
#

111

stuck fractal
#

Are you sure?

#

Screenshot your scan

median compass
#

task 2 q3 didn't accept 111

#

cause that's not the port

stone oyster
#

dang it...

#

the task is talking about 111 so much I didn't even think about that

#

sorry

#

ty

median compass
#

no need for sorry, good luck from there

white salmon
#

Hello everyone, I have a question about the machine Hardening Basics Part 1 (https://tryhackme.com/room/hardeningbasicspart1), Task 15 "What is the last rule that should be added to an access control list?" As I understand, the last thing to do is to block or delete everything. However, the format of the answer does not match. Can someone give me a nudge in the right direction?

astral smelt
#

Search the question up it will be the first result

white salmon
#

thx., i solve it

#

the question is strange ...

stone oyster
#

I'm trying to search thru and find the first low level room that had a hashcrack.

#

anybody recall which room that was?

oblique cliff
#

Could you be more specific?

#

A lot of rooms have hashes you need to crack

stone oyster
#

Sorry. I wish I could tell you, but then I would know the name of the room.

#

It had Bob, I think, as the user. We need to find the hash, crack it, use it.

#

I wanted to look at it as an example, but I can't find it.

oblique cliff
#

πŸ€”

#

@stuck fractal do you know which room he's talking about by chance

wintry yarrow
#

Looks like a new room. πŸ‘€

stuck fractal
#

There's dozens of Easy rooms with a basic hssh crack

oblique cliff
#

but what about with the username Bob

stuck fractal
#

I can only think of one room, Linux Challenges

dark schooner
#

Is it the The Blob Blog room πŸ€”

woven mirage
#

blob != bob

final mortar
#

Blob is here

#

Hmmm

oblique cliff
#

thank you for defending my honor @woven mirage

final mortar
#

Blob is not much here anymore pepeHands

oblique cliff
#

also henlo

#

boi

#

i was moving

#

@final mortar

#

I am back now

final mortar
#

So

#

you'll never go

stone oyster
#

If it is Linux Challenges I can't get in there anymore. need to pay to get in .

oblique cliff
#

i mean, im sure other stuff might happen in my life

stone oyster
#

So whatever I've done is inaccessible.

#

For right now I'm gonna' go use my hands for work and see about building a shed,

#

Ya'll have fun.

dark schooner
#

blob != bob
@woven mirage gotcha 😁

woven mirage
#

room is new, sadly no hints yet

final mortar
#

No one here will be able to help you out with a new challenge room within 72 hours of it's release

dark schooner
#

Yep

rough beacon
#

can i get a few hints on the chill hack room?

stuck fractal
#

Not yet, it's still a brand new room

#

Rule 13, please wait 72 hours from release

rough beacon
#

how new is it?

astral smelt
#

Only came out last night

shut lion
#

Hello. In https://tryhackme.com/room/smaggrotto, does the ||admin page|| on the ||development sub-domain|| actually bring back any ||command output|| or it's supposed to remain blank?

oblique cliff
#

iirc it remains blank

#

@digital iris are you alive

digital iris
#

no

#

blob hiiiiii

#

miss u love u

#

yes it remains blank, it’s a blind type of execution

oblique cliff
#

@digital iris luv luv

radiant pewter
#

I am having an issue with question 4 on "Investigating Windows"

#

Am I supposed to be looking at Amazon E2c Launch?

#

Amazon Ec2 Launch

red sandal
median compass
#

what room? I don't have a room "lfi walk"

red sandal
stuck fractal
#

Use the link to the room

median compass
#

ok, i'm not gonna hunt for the room, if you'd like help then post the link cause that might be the name that pops up when you deploy it but it doesn't help me find it

tribal olive
#

hey, i got the problem with owasp juice shop

#

task 5, #3

#

i downloaded the file, but i cant find the flag

red sandal
stuck fractal
#

No

#

Provide the link to the room

#

Or the room title

red sandal
median compass
#

do a cat id_rsa for me @red sandal please

#

hello? gone?

#

one thing you might check is if you copied the key directly from the web page or switched to the source view and copied it from there

red sandal
#

i capture the request with burp i have the key lol

pallid siren
#

Did u copy all of it? Sometimes when i click/drag to highlight, ends up only copying half lol

median compass
#

well i can't see what you've done so if you want to lol and not show me then i guess you're on your own, have fun @red sandal

red sandal
quick fern
#

Any hint for envizon?

median compass
#

where are you stuck sonym?

simple mountain
#

and Envision been live for long enough?

median compass
#

i think so...

#

yeah 96+ hours ish

blazing star
#

someone help me

#

im in chill hack room

#

i stay in the console i try upload shell in /tmp but i can't execute it

median compass
#

that room is too new still @blazing star, no hints for the first 72 hours

blazing star
#

aa ok so sorry, i dont know this rule

#

thanks

median compass
#

no worries, keep at it, I'm sure you'll get it

blazing star
#

TY bro

white salmon
#

i'm stuck at the begining of "Upload Vulnerabilities" room task4

#

i don't get it what website do i have to get on ?

#

Did you tried overwrite.uploadvulns.thm ?

median compass
#

did you hit the 'Deploy' button in task 1 and follow the instructions there?

white salmon
#

yep

median compass
#

if so then you have a machine running and the hostname overwrite.uploadvulns.thm in your /etc/hosts file

#

so that's the site to surf to

white salmon
#

ooohh

#

i gonna check

odd panther
#

Chill Room, Great Box thank you @torn zealot Please do more!!!! xD

white salmon
median compass
#

yes it does, have you connected to the VPN?

royal mirage
#

In Internal room, I got rev shell as ||jenkins| in docker env,|| what am I supposed to do after that..any idea?

median compass
#

careful with spoilers @royal mirage, you can surround text that gives part of the solution with || on either side

royal mirage
#

Sorry man xD

median compass
#

no need for sorry πŸ™‚

#

looking at my notes I think you just have to enumerate from there

#

do the usual hunt for 'interesting' things

royal mirage
#

To escape ||docker|| and get root right??

median compass
#

kinda, enumerate and you'll see

royal mirage
white salmon
#

i'm on thm-attack the box , do the instruction and still don't get nothin in etc/host or on a web overwrite.uploadvulns.thm

#

i'm redictect to google search

#

/etc/host__s__

#

Add it manually

median compass
#

so you're using the web browser based attack box yes?

white salmon
#

With your favourite text editor (vim/nano/emacs/...)

median compass
#

show me a screenshot of what happens when you execute the command cat /etc/hosts @white salmon

royal mirage
white salmon
#

not host

#

but hostπŸ˜†

#

ty @median compass

median compass
white salmon
#

so when i need to acess to the website overwrite.uploadvulns.thm

#

where i go ?

#

i stiil dont get it

median compass
white salmon
#

i don't understand how that work now but

#

i try this adress many times

#

i think i miss those "http://"

#

πŸ‘€

#

tx again

#

hanx again

#

thanks

tribal olive
#

Hey, can anyone help me with ToolsRus, when i try to bruteforce the password for ssh in hydra it pops up a message that this is an unknown service

white salmon
#

Your hydra command is wrong

tribal olive
#

what it should be like?

white salmon
#

First i don't think you can specify a username with -u

tribal olive
#

yeah i see

#

-l

#

nevermind

white salmon
#

About the protocol aswell

tribal olive
#

?

white salmon
#

Try to find how to specify the protocol with hydra

#

(ssh)

#

I might be wrong, i never tried this way.. but doesn't looks correct

tribal olive
#

i did that

white salmon
#

Don't put the protocol before the IP adress

eternal brook
#

Check hydra's man page

white salmon
#

man hydra | grep protocol

tribal olive
#

i tried something like this

#

it didnt work out as well

median compass
#

try it this way @tribal olive hydra -l/-L <user> -p/-P <pass> <IP> <service>

white salmon
#

This time your command worked properly, but tells you, you can't login with password so you need another way to identicate you

median compass
#

actually yes, didn't read it, it did work, well spotted kana

final mortar
#

SSH supports several different authentication mechanisms.
And as your error says target does not support password authentication your target probably supports keyboard-interactive and not password authentication.

#

Beat me to it @white salmon πŸ˜„

tribal olive
#

any tips what to do next then?

#

since i have no idea

median compass
#

more likely that the target wants a keyfile no chika?

white salmon
#

Try to find a id_rsa key

#

And login with

final mortar
median compass
#

yeah, but so does password

#

so that doesn't really separate them

final mortar
#

The password authentication mechanism has the client send the password to the server as a password. The more-common keyboard-interactive authentication mechanism opens a channel between the client and an authentication process on the server. The client allows the user to directly interact with the authentication process, which is usually just a password prompt

#

But is he's doing ToolRus room, I don't even think SSH is an entry point

median compass
#

from https://www.ssh.com/manuals/server-admin/44/User_Authentication_with_Keyboard-Interactive.html



Keyboard-Interactive is a generic authentication method that can be used to implement different types of authentication mechanisms. Any currently supported authentication method that requires only the user's input can be performed with Keyboard-Interactive.

Currently, the following methods are supported:

password
PAM (see note below)
RSA SecurID
RADIUS
Methods that require passing some binary information, such as public-key authentication, cannot be used as submethods of Keyboard-Interactive. But public-key authentication, for example, can be used as an additional method alongside Keyboard-Interactive authentication.


Note: PAM has support for binary messages and client-side agents, and those cannot be supported with Keyboard-Interactive. However, currently there are no implementations that take advantage of the binary messages in PAM, and the specification may not be cast in stone yet```
#

no, i think that's why it won't hydra

final mortar
tribal olive
#

also i got the problem with the question: What directory has basic authentication?. Since my gobuster didnt find any different directories than guidelines

final mortar
#

The snippet above your that I sent explains that

tribal olive
#

i used the directory-list-2.3-medium.txt

#

from dirbuster

final mortar
#

Well, the directory is in that wordlist

tribal olive
#

ill re-do then

final mortar
#

Also, when you find that directory

#

You will get to use Hydra πŸ₯³

tribal olive
#

just found /server-status

#

but thats not the case i think

night fractal
#

99% not

white salmon
#

Try gobuster from another directory

#

One you found previously

tribal olive
#

im doing that already

white salmon
#

Wait no you don't need, the directory you are looking for is in the home

#

Just found it in a sec with dirb/common.txt

limber iron
#

hey guys! yoto root part, any hints ?

median compass
#

enumerate everything, look everywhere

#

and dir -Force is your friend

limber iron
median compass
#

yup

limber iron
#

ok thanks buddy

noble locust
#

hi guys

#

how do you work with given salt and no. of rounds , while using hashcat

median compass
#

do you know the hash protocol, is it bcrypt?

stuck fractal
noble locust
#

-m 1800

#

yup
sha512crypt $6$, SHA512 (Unix)

stuck fractal
#

They are lying to you about the rounds

#

It's the default

noble locust
#

It returned a token length exception

#

I ran this command , very simple -

stuck fractal
#

Then you have specified it incorrectly.

noble locust
#

hashcat -m 1800 t4.txt /usr/share/wordlists/rockyou.txt --force

#

that t4.txt has that hash

stuck fractal
#

Do not use --force

#

And you have specified it incorrectly in the file if you're getting that error

noble locust
#

It worked fine everytime except this one

#

nope, I just copied who hash, and pasted it in the new file

stuck fractal
#

Ok, you can ignore what I'm saying or you can work with me

#

Is it working? No

#

So why not listen to me?

noble locust
#

I am listening to you,

stuck fractal
#

And you have specified it incorrectly in the file if you're getting that error

noble locust
#

I am actually doing that without --force

#

alright

stuck fractal
#

Nope I give up

#

I hate being ignored.

#

Asking for help and then ignoring and arguing about it is something I will not tolerate.

noble locust
#

... I was refreshing my THM , its web based attack machine

#

its session freezed, so i got there, now I made a new file and then gonna execute it without --force

median compass
#

can you do a cat t4.txt @noble locust?

noble locust
#

yup I can

median compass
#

well I meant can you show it to me...

noble locust
#

the new file is named q2.txt and here we go -

#

$6$aReallyHardSalt$6WKUTqzq.UQQmrm0p/T7MPpMbGNnzXPMAXi4bJMl9be.cfi3/qxIf.hsGpS41BqMhSrHVXgMpdjS6xeKZAs02

median compass
#

ok, the hash has a . at the end

#

that's not a full stop, it's part of the code

noble locust
#

I intentionally avoided that :/

median compass
#

yeah, don't do that πŸ™‚

#

be aware this one will take a long time

#

if you have a GPU on your host you should consider downloading hashcat for your host OS and running it there

#

it runs MUCH faster on a GPU

noble locust
#

I have poor 4GB RAM, no GPU ...

median compass
#

ok, well it'll get there in the end

white salmon
#

when i do the burpsuite room i never get the SET-Cookie

#

can somebody help

woven mirage
#

Are you looking for it in requests or responses?

median compass
#

That’s the one I meant πŸ™‚

solemn smelt
#

gpuhash.me is limited on word list, hash type, and syntax

median compass
#

πŸ‘ ty cry

green sorrel
#

can we ask for help with bookstore yet

stuck fractal
#

It just came out today

#

So no?

naive vortex
#

Hey guys,

Looking for some hint on this room (https://tryhackme.com/room/networkservices) task 4.

Last Task in 4, to get the flag.

I got the username, howerver, when I use smbclient to connect, any credentials are working.

So I currently have no idea where to connect to with that user and the key that I gathered before.

#

Ah wait I now have an idea

#

πŸ™‚

#

got it! finally... thought all the time I have to somehow connect over SMB. But in hindsight it makes no sense.

real lynx
#

Has anybody done year of the dog, I need a little nudge

jolly pulsar
#

hi

halcyon pumice
#

Hi everyone, can someone tell me how can I run shellbags in Volatility 3?

trim haven
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
remote gate
real lynx
deep agate
sick sun
#

are this is allowed to ask Bookstrore Room ?

astral smelt
waxen ridge
#

Please can I get a hint for owasp top 10 room task 19 (security misconfiguration)?
||i have looked through the application files and also after setting the session token cookie i was able to access the mynotes page.||

median compass
#

@waxen ridge, did you try googling for default credentials, always a good thing to try as lots of people don't think to change the defaults after installation

waxen ridge
#

Nope @median compass i will try this. The task hint seemed to indicate that the answer lies in the application source code so I was looking for clues there

median compass
#

well it kinda does, you might find the source code by googling

#

remember that the source code you see in the browser has often been interpreted and changed before being sent to you

#

for example, the designer didn't hardcode the date into a page, a piece of code gets interpreted when you request the page and inserts the current date

#

so there's source code in your browser and the original source code which includes the coding magic in php or similar, and that you need to hunt for

waxen ridge
#

Whoaa okay I didn't think of it that way at all. Thanks so much! I guess this is literally a thinking "out of the box" kind of question :D

median compass
#

research is a pretty massive part of infosec, every day there's a new thing and learning to google everything to hunt down answers is a big part of the process, enjoy! πŸ™‚

stuck fractal
waxen ridge
stuck fractal
#

You usually can't

#

At least you can't as an end user

#

Because it's running on the server

waxen ridge
crisp condor
#

hi guy!

#

dont know if this is the place but,.. anyways... I am trying to complete this room , and only 1 question left. https://tryhackme.com/room/hardeningbasicspart2 . Not looking for answers , just want to validate if there's any material I can read (beyond the book mentioned in Task#1) in order to anwser this question "This is a random, arbitrary number, used as the session key, that is used to encrypt GPG." Thanks!

night fractal
#

it's subscriber only, can you send a screenshot (||they're probably speaking about salt||)

stuck fractal
#

Probably not a salt seeing ss it's not a hash

crisp condor
stuck fractal
#

What task is it? @crisp condor

#

It's a standard cryptography term

#

Look into cryptography session keys

crisp condor
#

Is this --> Task 2 ~~~~~ Chapter 3 Quiz ~~~~~

median compass
#

the tasks are out of order in that room @crisp condor, do task 3 and go back to the quiz then

crisp condor
#

I'll take a look

#

ahhhhh! found it!.. thanks @median compass !

deep agate
#

Im on the google dorking room.

The question - Name the key term of what a "Crawler" is used to do has me stumpted.

Ive thought of a few words but all of them or over or under the 5 char answer format.

stuck fractal
#

It's in the text

median compass
#

read the text in task 1 and see if anything pops out

deep agate
#

Ight I got it. Thanks!

manic citrus
#

Having trouble with Physical Security Intro Task 5/7 "What type of pick takes advantage of lazy manufacturing practices by lifting all the key pins and driver pins above the shear line to bypass a lock?" pretty sure the answer is || r..e || or am I missing something as it wont accept it ?

median compass
#

i watched a lot of bosnianbill videos to find most of those answers @manic citrus

#

it's not rake i'm afraid

stuck fractal
#

oh I know this one

manic citrus
stuck fractal
#

It's a special tool for it, and it's named after what the tool looks like

median compass
#

there's still a couple I can't find tbh tony, and i watched a LOT of youtube

manic citrus
opaque vigil
#

@inland onyx I am trying your new room, "Further Nmap" and it is really great!

However, I am stuck at one question, for no apparent reason. Specifically, in Task 13, question "There is a reason given for this -- what is it?" i can give no right answer. Can you give me a nudge? Thanks!

inland onyx
#

(That room isn't meant to be released yet -- the scheduler messed up earlier πŸ˜›)

manic citrus
#

Just stuck on the adams rite one now....... lots of videos/writeups on how to use the tool but can not find the correct wordage to protect against it 😦

wind peak
#

goodnight everyone. im doing linux challenges task 3 find flag 15

#

i need a hint

#

thank you in advance

#

ive done uname -a

#

but i dont see the flag

#

also done uname -r to see the release like the hint says but no flag

#

any help would be appreciated

stuck fractal
#

The hint provided in the room is a glob

wind peak
#

forgive me i dont know that terminology. what is a glob? is it something meant to throw you off?

stuck fractal
spark owl
#

Does anyone know the answer to the β€œFurther Nmap” -> There is a reason for this β€” what is it” question in the β€œPratical” section? I cant figure it out and there is no hint or write-up! Thanks! @inland onyx i saw you responded earlier, anyway to help me finish? 😎

inland onyx
#

Apparently it is now meant to be released -- been a li'l bit of a mixup after the scheduling thing earlier and we've just decided to roll with it πŸ˜†

#

Did you try running the scan?

spark owl
#

Hello! Haha its been a fun deep dive. Yes i did, i have all questions but this one left. Did i miss some verbose i was supposed to see?

inland onyx
#

Lemme try it and make sure it is showing

#

Actually, what's your machine's IP?

#

Quicker than deploying one myself

spark owl
#

10.10.12.71

wind peak
#

Thank you ninja

inland onyx
#

What switches did you use?

wind peak
#

@stuck fractal thank you. you are a god send

spark owl
#

Nmap -sX 10.10.12.71 -p 1-999 -Pn

inland onyx
#

Ah, throw in -vv

#

I'll add that to the hint

spark owl
#

Ahh shouldve known better πŸ˜‚

inland onyx
#

Apologies -- it's my default go-to. Didn't realise that others wouldn't think to use it πŸ˜†

spark owl
#

No apology needed! Shouldve tried that first, running with extended verbose now

#

Got it! Thanks for the help! Fun room! @inland onyx

wind peak
#

Flag 16 lies within another system mount. Room linux challenges, task 3. i ran the df command and also cat /proc/mounts and /proc/self/mounts. still not 100% sure. Any hints?

stuck fractal
#

It's a little misleading. if you plugged a USB into an Ubuntu system, where would you want to look to find it?

wind peak
#

no idea Sir James. Im 100% linux noob. Ive never even done that

#

but ill check into what you said

stuck fractal
#

It was a rhetorical question

wind peak
#

i feel like im burnt out after 3 questions lmao

#

maybe i need a break

stuck fractal
#

Take a break then

#

No harm in taking a break

#

Burnout is a real risk

wind peak
#

last time this happened to me i left tryhackme for 48 hours

#

then it came to me lmao

#

i found it lmao

#

Thanks @stuck fractal

wind peak
#

im trying a command sed 2345 flag19 and its saying im missinga command

#

lmao i see my error now

#

ggwp

#

actually nope that wasnt the issue still stuck

#

okay i got it this time hopefully

#

got it

#

linux challenge task 3 Find the difference between two script files to find flag 13.

#

any hints please

stuck fractal
#

There's a specific command to find the difference between two files

wind peak
#

yeah i know that but will i find that flag comparing any 2 files?

#

its diff

#

what does a script file even look like

stuck fractal
#

The specific two files

#

I think they're in a folder called flag13?

wind peak
#

hmm

#

wow im definitely burnt out lmao

#

that was so simple

#

well im done with task 3

#

break time

#

Thank you again Ninja

left moon
#

Heya folks. Doing the Web OWASP starter course. I completed Task 29 but I didn't actually find a public exploit... I kinda worked my own way around it. Was curious if there was somewhere I can ask which vuln I was supposed to use for my own reference. Don't want to spoil anything by posting it all here.

stuck fractal
#

The OWASP top 10 room?

left moon
#

Or maybe I actually did it correctly... not sure.

left moon
stuck fractal
#

I found one fairly quickly by googling the exact words in the hint

#

Have you tried that one?

#

By fairly quickly, I mean it was the top result, and straight from exploitdb

left moon
#

Oh interesting. I looked up something else in exploit-db but this is essentially exactly what I did. But... a little less code involved πŸ˜„

#

Thanks!

runic iron
#

stuck on furthernmap task 8 question 2, Why are NULL, FIN and Xmas scans generally used?, I know the answer is because they are stealther than SYN scans but I can't figure out how to word it so it fits into the answer format.

stuck fractal
#

Xmas really isn't more stealthy

#

So that rules out your answer there

#

I can see the answer in the text

runic iron
#

got the answer thanks james

#

so Xmas really isn't more stealthy? so the statement "All three (Null, FIN and Xmas) are interlinked and are used primarily as they tend to be even stealthier, relatively speaking, than a SYN "stealth" scan. " is not true?

stuck fractal
#

Xmas scans derive their name from the set of flags that are turned on within a packet. These scans are designed to manipulate the PSH, URG and FIN flags of the TCP header. When viewed within Wireshark, we can see that alternating bits are enabled, or β€œBlinking,” much like you would light up a Christmas tree.

#

Not something that's going to be hard to detect

meager badge
#

I am doing room ZTH: Obscure Web Vulns, in this I am having shell but not able to find the flag

cedar palm
west sail
#

regex room Match the string in quotes (use the * sign): "2f0h@f0j0%! a)K!F49h!FFOK" << tried every combination, have created very unique solutions, to fit the 9 character answer, but nothing is working... this is the last one remaning

true widget
#

Can anyone give me a nudge for priv esc on Rootme?

wooden mist
broken quail
#

I'm stuck on this. ghostblobgib I cant understand how should I solve this. I tried using ||[Ff]ile[^68]|| ; any hints for this question? Problem number 04 from task 02.

west sail
junior sequoia
junior sequoia
wooden mist
#

I posted my response 20 minutes ago, if I found the answer I would've posted about it

#

seems it's the one single question people get stuck on since the completed user count didn't jump up since the room was released

west sail
#

I have to tap out, was stuck on it for hours ... need my sleep. 😦 I almost want to post the dozens of solutions that do work! πŸ˜‰

wooden mist
#

πŸ˜„ yeah i found few of those

west sail
#

I was looking for pattern repeats, but no {} in the answer portion.

junior sequoia
#

I have maybe 6 or 7 different combinations that all work so far. I should have taken a note of them cos I think I am just repeating them now.

west sail
#

I have it down to a meta & a space and I used β€œβ€ then thought maybe inside ... so many different combos

junior sequoia
thin bison
wooden mist
#

should we include quotes in the answer? πŸ€”

cedar axle
#

||
************.****
(\w+)@(\w+.\w+)||
missing a char, but matches no problem?
so whats missing?

wooden mist
#

[\S\s]* definitely matches the string but doesn't match the 9 character answer hence my question about the quotes πŸ˜„

#

@cedar axle the question was rephrased, refresh the page

cedar axle
#

||[\w\W\s]*||

wooden mist
#

oh wait you're doing the email one right?

cedar axle
#

yeah im going off the *'s

thin bison
#

yeah I'm going to answer this in a second

cedar axle
#

trying to make it fit

wooden mist
#

so with the email the TLD is static so don't make it a wildcard too

#

you're close to the answer for that one pood0g

thin bison
#

I might have to change more than the question in this one πŸ˜›

thin bison
cedar axle
#

so eitger ||[\d\s\D]* or [\w\s\W]*||

#

or the inverse

thin bison
#

you're using charsets where you should be using groups, like before

#

but you're not supposed to put the whole thing in a group anyway

#

try to specify the static parts and then add metacharacters for the parts that change

cedar axle
#

@thin bison omg im going to have nighmares about this tonigh

#

if i even sleep

thin bison
#

take a break and come back to it, I'm sure you'll do fine

junior sequoia
#

I am getting there slowly, just 3 more questions to go. It is difficult, but if you read the questions and don't think about it too complicatedly it is not too hard. One thing is for sure, I will not forget how to use regex for long time, and I guess that is the aim of the room.

cedar axle
#

|| (\s|\S)* || yet again a match but missing something still

fierce stratus
#

"[\S\s]*" just tried this but not working i think it might have to do something with the quotes since no other level before has the quotes

junior sequoia
fierce stratus
#

oh

#

sorry πŸ˜‚

cedar axle
#

|| 2[\s\S]*K|| can anyone give me another hint?

thin bison
#

uh, what is that

cedar axle
#

oh

#

right there

thin bison
#

A lot of the time you don't have to use charsets when using metacharacters

#

for example you can say \S*, this means, 0 or more non-whitespace characters

steady stratus
#

Hey, let’s not use that here @fierce stratus

fierce stratus
#

oks sorry

cedar axle
#

i knew about + and * is kind of like at least one and as many as you like

#

i thought id put the 2 and the K so that it doesnt match any arbitary string

thin bison
#

remember, the general hint is be specific but not too specific. and that string is literally gibberish, with a space in between.

fierce stratus
#

tbh i totally overlooked the space so far but finally got it now

thin bison
fierce stratus
#

just though about that maybe being a good idea ^__^ the spacing with the '!' next to it makes the space kind of dissappear

thin bison
#

yeah hopefully now it's more straightforward

cedar axle
#

thanks, i think i get it

#

maybe

fierce stratus
#

when creating a room can you actually specify more than one correct answer apart from the case insensitivity? i sometimes press enter too early and it still accepts as valid or is it only stringcomparing up to the needed length ?!

woven mirage
#

There's an answers tolerance

#

I don't know how's the regex for it but it's nice

#

Always gets even if you write one character wrong

#

It's nice for flags that need a hash or things like that

cedar axle
#

nope

#

try again

fierce stratus
cedar axle
#

oh yay bout frickin time

#

\s matches whitespace (any number of spaces, tabs, and line breaks) this kept tripping me up

#

in partiular any number of spaces

#

stupid details

#

i would have gotten it about 40 mins ago

thin bison
#

I'm also going to make the description more clear to reflect that metacharacters, while including large charsets, are used to match one character

#

for more, you have to use repetitions

cedar axle
#

thanks, deep down i probably knew that but i couldn't see past what was on my screen

#

bad habit

thin bison
#

remember, I also suggested that you use regexr.com. you can paste text in the big box and test your expressions in the small one.

#

there's always the chance of finding a correct expression that is not the correct answer, but there was no other way

cedar axle
#

all good

#

thanks for making the room

#

it was good

#

they should have a rating feature

#

for rooms

#

maybe thats a bad idea

feral anvil
#

I'm looking for a hint on the Physical Security Intro room please. Task 4 question 5. I have managed to get all the other answers in this room, and some have them have been quite obscure given the question, but I'm drawing a blank on this question. Any hints appreciated πŸ™‚

stuck fractal
#

What's the question, to save us going to the room?

feral anvil
#

In the "lock anatomy" section the question is "What is the piece that allows locking lugs to retract when the core is turned?"

stuck fractal
#

Oh ok I don't have that one yet

remote gate
#

@feral anvil they're kinda like deadbolts

junior sequoia
cedar palm
#

Damn regex is confusing

#

I've been looking at Task 4 Q4&5 for a long time and still dunno the answer

median compass
#

on Q4 you can have between 1 and 3 of a,b,c followed by 4 of 0,1

wintry yarrow
#

In room goldeneye, task 2 question 2, ||I've bruteforced login with natalya as user and got password bird but looks like its a wrong answer for this question. I can login with it fine using telnet.|| Need hint on this.

median compass
#

and on Q5 you can have F or f, followed by ife, followed by 1 or 2 of any digit

stuck fractal
#

Other users too I guess?

wintry yarrow
#

Yeah, I found ||xenia's password too which is RCP90rulez! but its wrong too.||

#

Got it. I didn't checked for ||boris user|| there. Thank you.

buoyant sapphire
#

Room : Yara Task 11:Question 5
It asks for another extension other than .PHP that is recorded for file2
There's only 1 file extension shown on VT and Valhalla
Am I looking in wrong place?

gusty turtle
glass fiber
#

In the OWASP room with command injections, why can’t we use all the CLI commands only some ?

median compass
#

what kind of commands work and which don't?

shrewd raven
#

hey guys can someone help me with "nmap" room?
here it is

stuck fractal
#

@shrewd raven please don't show answers

shrewd raven
#

srry

#

here it is

shrewd raven
#

got it

balmy wedge
#

Hey everyone, I am trying to finish up last year's advent calendar before tomorrow and I am hard stuck on day 19 of XSS. I have tried writes, followed documentation. everything and I cannot get the admin account to push it's authid.

#

any hints or help is super appreciated.

#

I have been at this 1 question for a day now.

stuck fractal
#

Make sure you reset your listener after every connection

#

Use a nc listener

balmy wedge
#

ahh

#

okay

#

I'll try

#

I did use -k earlier, would that help?

stuck fractal
#

No idea

#

But reset it every time to be sure

#

And once you've submitted the payload, do NOT touch the webpage. Do NOT reload it. Otherwise you'll get your own cookie.

balmy wedge
#

That was my issue was I kept getting my own cookie

#

lol

stuck fractal
#

Yeah, if you load the webpage then it'll run the JS

balmy wedge
#

perfect, thank you so much man!

#

I hate xss

#

lol

limber iron
#

room kiba, reverse shell part the payload doesn't seem to get executed properly

#

is there a something wrong with the box ?

stuck fractal
#

What reverse shell payload did you try?

#

Because I'm pretty sure I completed it recently and it worked just fine

limber iron
#
.props(label.__proto__.env.NODE_OPTIONS='--require /proc/self/environ')```
stuck fractal
#

it was a pain to do

limber iron
#

i think the payload is correct

stuck fractal
#

There's a couple on a github page

limber iron
#

yes

stuck fractal
#

Try a couple

limber iron
#

tried them both

stuck fractal
#

One worked for me, the other didn't seem to.

#

And make sure you follow the instructions super carefully

limber iron
#

Okay thanks buddy

stuck fractal
#

@limber iron is your site username the same?

#

if so, can I dm RE writeup?

limber iron
#

yes

stuck fractal
#

DM me please

white salmon
#

Hey, I have a beginner's question, is this the right place to ask?

stuck fractal
#

Are you asking for a hint with a specific room on tryhackme?

white salmon
#

yes well I don't know if it's exactly a hint, I have trouble trying to use putty in the very first linux room

#

it doesn't seem to connect to the virtual machine

stuck fractal
#

Are you connected to the VPN?

#

Can you provide a link to the room?

#

What IP address are you using? Where did you get it from?

white salmon
#

I connected to a vpn but not yours does it make a difference?

#

sure task 4 of this room

astral smelt
#

You need to be connected to Openvpn

stuck fractal
#

It doesn't touch your internet traffic

white salmon
#

ok that probably was the issue I'll give it a try

stuck fractal
#

The VPNs that companies like Nord provide only touch your internet traffic. They're different in concept

white salmon
#

Ok I think I understand thx

cedar axle
#

ThM VPN does'nt redirect all your traffic, it just adds the 10.*.*.*/17 network and route

cedar palm
#

Hey I'm still really stuck on the regex room on Task 4 Q4, I've tried ||[abc]{0,3}[01]{+}|| and it still won't work

remote gate
#

@cedar palm you're really close. just wanna be a little more specific on the times abc and 01 occur

junior sequoia
cedar palm
#

Okay, thanks a lot guys

#

Oh wait, found it

granite pelican
#

hello, looking for some assistance with running exploit in task 29 of owasp top 10 room

#

fixed the exploit code but still wont run

#

havent changed a thing other than commenting line 10

white salmon
#

hey, I'm doing the new regex room and honestly it's driving me crazy...

#

Task 3.2 I#ve tried this " [Cc]at? " but it won't accept, same with 3.4 and 3.6

#

could any1 pm me the correct solution?

winged mist
#

Also python 2 or 3

whole flare
#

3.2

thin bison
#

once you understand how to use the wildcards, you'll solve it

white salmon
#

oh

#

I got it now

#

thanks

jagged scaffold
cedar palm
# granite pelican

Personally, I didn't use that specific exploit and I don't think it would work. But in this case you need an IP, a port, and a command. Try adding -h or --help

median compass
#

what specifically do you want a hint on @jagged scaffold?

jagged scaffold
median compass
#

but where did you reach the dead end, did you get the ||ftp user & password|| for example? It is much easier to hint to you if I don't have to guess where you're stuck

jagged scaffold
#

there is ftp and ssh but dont know the credentials

jagged scaffold
median compass
#

well what did you find in that directory?

jagged scaffold
#

some text and a video

median compass
#

try using burpsuite to look at what happens when you request the directory

white salmon
#

Would appreciate a hint for the MITRE room. The question is "For the above analytic, what is the pseudocode a representation of?" Task4

median compass
#

did you read the CAR-2020-09-001 page you're pointed to @white salmon?

white salmon
#

@median compass Got it. Thanks πŸ‘