#room-hints

1 messages ยท Page 74 of 1

stuck fractal
#

@red sandal read through the source of the script

wide sleet
#

Read on the nmap website about this script, probalby easier

red sandal
#

Done ๐Ÿ™‚ thank you ๐Ÿ˜„

flint briar
#

Hello y'all, has anybody done the CC-Ghidra room? I have having trouble understanding what the last question is asking for. The question is "What outputs the good job message? " and the answer is 7 characters long. What type of answer is it looking for? A variable or address or something else? I think I understand how the function works, I just a little confused as to what the answer type is. Thanks, and Merry Christmas

#

Nvm, I got it. If anybody references this later, it is asking for what value is being compared, so that if local_1a is equal to it, it will print "good job!!!"

sleek hawk
#

Hey everyone, anyone who's done the 'cave' room know how to access the service on port 3333? I can connect to it in my browser but I can't interact with it. Is there a more interactive way of connecting to it?

woven mirage
#

You can use netcat

hollow condor
#

Hey guys, super noob here. im working on the beginner NMAP room, and have had to use the walk through for Task 3 on the last question. but even putting the walk through answer on there, still says ive got the wrong answer!
the switch should be --script vuln
i believe anyways, and thats what all of the walk throughs say, but its still showing as a wrong answer!

#

so i got an answer in tech support, saying the answer doesnt have a space in it, but every single walk through ive looked at, has the same answer! so i'm scratching my head here haha

neon ridge
hollow condor
#

did you end up finding a solution ?

neon ridge
#

yes

hollow condor
#

thanks!

neon ridge
#

np

#

For room NMAP task 14 > Wireshark, I don't have the premium version of thm, how would I go about doing it?

stuck fractal
#

Huh?

neon ridge
#

I did a tcp connect scan using highest verbose, and on wireshark set the ip.dst to the target ip, but I get no packets

stuck fractal
#

Why do you think you need a subscription?

neon ridge
#

?

neon ridge
#

For a walkthrough?

stuck fractal
#

Let me check the room

neon ridge
#

okay

stuck fractal
neon ridge
#

๐Ÿ˜ฒ thanks a lot it worked!

floral rock
#

hi guys! good afternoon, im very stuck in the room of network services, in task 7, it's about telnet, i cant stablish the net cat

stuck fractal
#

It's still running the ping command and not responding to other commands

#

There's a reason you were told to use -c 1

floral rock
#

it works!! thank so much!!!! kudo

#

s

old lava
#

@merry beacon whatcha stuck on?

merry beacon
#

tell me where I'm wrong

old lava
#

Okay, I'm looking at your answer. Doublecheck the command you're submitting, especially spelling.

merry beacon
#

directly copy pasted so I don't thing spelling mistake has any chance

old lava
#

I'm looking at your answer that you copy-pasted and there is a spelling mistake

merry beacon
#

ok got it

old lava
#

Good luck ๐Ÿ™‚

merry beacon
#

Updated ||smbmap -u 'admin' -p 'password' -h 10.10.10.10 -x 'ipconfig /all'|| still invalid answer

old lava
#

Okay, you're close. Remember that ' and " are two different characters.

merry beacon
#

got it thanks

#

one question

old lava
#

Sure

merry beacon
#

Its in smbmap -h

old lava
#

May I PM you?

merry beacon
#

yep

sleek hawk
little sable
#

struggling a bit in https://tryhackme.com/room/blaster i got into the box, but then it says to search the browser history and I only see IE and there is no history data. Am I missing something? ||I have started searching eventviewer now, but that is very slow on the windows box and I don't think it's the right answer||

white salmon
#

tryhackme internal -
i got to the stage where i made a ssh tunnel to access jenkins on my localhost after that i tried bruteforcing the login page
||
martin@martin-Blade:~/thm/wordlists$ hydra -l admin -P rockyou.txt localhost -s 6969 http-post-form "/j_acegi_security_check:j_username=^USER^&j_password=^PASS^&from=%2F&Submit=Sign+in:Invalid username or password"

[6969][http-post-form] host: localhost login: admin password: 1234567890
[6969][http-post-form] host: localhost login: admin password: hannah
[6969][http-post-form] host: localhost login: admin password: amanda
[6969][http-post-form] host: localhost login: admin password: loveyou
[6969][http-post-form] host: localhost login: admin password: pretty
[6969][http-post-form] host: localhost login: admin password: basketball
[6969][http-post-form] host: localhost login: admin password: angels
[6969][http-post-form] host: localhost login: admin password: playboy
[6969][http-post-form] host: localhost login: admin password: flower
[6969][http-post-form] host: localhost login: admin password: tweety
[6969][http-post-form] host: localhost login: admin password: hello
[6969][http-post-form] host: localhost login: admin password: elizabeth
[6969][http-post-form] host: localhost login: admin password: andrew

||
it detected all these password but when trying to login with them none of them work
i also tried changing the grep filter at the end but all it does is that it detects different passwords which also dont work.
what could be the issue?

trim haven
#

Your command is wrong

white salmon
#

what do you mean?

trim haven
#

Hydra is incorrectly detecting whether the username and password is wrong so you're getting false positives

white salmon
#

okay but what should i change it to? i already tried everything that was on the login page

cedar axle
#

@white salmon the 3rd section "stuff:stuff:here"

white salmon
cedar axle
#

i just used wfuzz and filtered by size

white salmon
#

in ZAP?

cedar axle
#

you could use that too

white salmon
#

okay ill give it a try thanks love

#

hello guys , im solving unbaked pie room , and i deleted the payload.png by accident , the PE part need that image ,any way to create something like this image work with the pytesseract lib

fossil cosmos
#

hey guys, i am currently doing the networks services room. Task 4, last question and i am facing a problem. I am really close of solving it but when i ssh into cactus i dont know the password and i have no clue how to find it. Can someone give me a hint

tawny stratus
#

hey guys i m stuck on the CCT2019 room any hints ???

white salmon
cedar axle
#

@white salmon๐Ÿ‘

floral rock
fossil cosmos
#

i solved it, thank you man for replying

#

i had to use id_rsa key

floral rock
floral rock
light dew
#

I remember doing a thm room, in which we have to do something with a tmux session in /tmp/tmux-* ... can someone point me to it or the exploit used there...

little sable
arctic compass
#

Hello everyone! Does anyone know how to crack a salted password? i have the salt hash and the password hash.

arctic compass
ionic brook
#

anyone else got stuck at binary - shiba2?

#

or do i just suck?

little sable
#

I struggled a bit with that one.

#

which task was that?

#

so task 18 from 25daysofchristmas is apparently the entire ||blaster room||. So the place I got stuck on the task is the same in the other bit. Has anyone done either and can give me some kind of hint?

stuck fractal
#

@little sable You need to say where you're stuck

#

Otherwise no one knows if thry can give you a hint

little sable
# stuck fractal <@233024690610765824> You need to say where you're stuck

I'm stuck on task 3, first question of ||blaster|| or task 18 third question of 25daysofchristmas. I checked for the ||browser history|| according to the hint, but that seems to be cleared and so I don't know where to look. I've started hunting through the ||event viewer|| but that seems like the wrong direction

stuck fractal
#

The history contains searches for 'how to patch CVE-whatever'

little sable
#

the history contains nothing that I can find...

#

it's blank

#

am I doing it wrong?

stuck fractal
#

No

#

It's a known issue with the room that's being fixed

little sable
#

oh thank you so much

#

I think the pin is gone.. I don't see it (read the pins 3 times)

stuck fractal
#

Ok it should be a hint on the blaster room?

little sable
#

there's a youtube vid a few questions past where i am as a hint

#

that was enough, thanks

fossil cosmos
#

hey guys, i need some help here. Wifi hacking 101 room, task 2. I must put and interface wlan0

#

i have a wireless adapter but kali machine from tryhackme doesnt recognise it

stuck fractal
#

Unless you have a wifi card on your kali machine, you won't have one.

#

The THM kali or attackbox isn't running on your machine

#

It can't have wifi adapters

#

It's a fully virtual AWS VM

fossil cosmos
#

ok, thanks man

#

that means i cant continue , right?

stuck fractal
#

You can't attack an actual wifi network using THM's attackbox or kali, no

#

You can complete the entire room though.

#

You were told the requirements at the start of the room

#

You will need a monitor mode NIC in order to capture the 4 way handshake. Many wireless cards support this, but it's important to note that not all of them do.```
fossil cosmos
#

ok, thanks man

blazing thorn
#

25daysofchristmas - Task 11 [Day 6] - What data was exfiltrated via DNS? < any hints on this. I have recovered the files via the pcap. I have cracked one of the file's passwords and answered Q2. I have extracted the hidden content for Q3. Just stuck a little on Q1. Perhaps overthinking it but a hint would be welcome.

stuck fractal
#

Filter to just DNS traffic@blazing thorn

#

You were told exfiltrated via DNS. That's not anything to do with files.

blazing thorn
#

@stuck fractal thanks, i did that for Q2/3.

#

I've read some writeups and have a hint

#

apologies for not looking at them first

stuck fractal
#

I gave you a hint

blazing thorn
#

ty โค๏ธ

#

got it ๐Ÿ™‚

cosmic skiff
#

Hey Hey. I'm in Room LinuxCTF. Having a hard time with this question:
Flag 16 lies within another system mount.
I can only find one file system mounted... any ideas?

stuck fractal
#

@cosmic skiff If you plugged a USB into an ubuntu machine, where would you look for it? Look there.

cosmic skiff
#

thanks much! Wouldn't have found that in like a million years

#

I'm running mount lol

snow crest
#

Hi some already did the Searchlight - IMINT

#

Im stuck

remote gate
snow crest
#

already done bro!

#

thanks anyway

remote gate
#

No problem

snow crest
#

of coffe shop

remote gate
#

Ahh gotcha

ionic brook
#

need help with binary - shiba2

stuck fractal
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
ionic brook
#

Gotchu

#

uuh

sinful kindle
#

hey gents, im currently working through the windows privesc room in the beginner track, task 9 - checking the registry to find autologon credentials. I've looked the output of both commands provided, and can't find any entry for the autologin password. anything obvious I'm missing?

serene stag
#

need help, doing OWASP-JuiceShop and i am on a part where you need to reset password for jim but i can't reset it, it doesnt allow me to input security question ?

zinc oyster
#

or something like that

#

I'm wondering a bit about the https://tryhackme.com/room/encryptioncrypto101, the question about what company the TryHackMe cert is issued to, but when I inspect the cert it has no owner information at all. Only the url it is valid for. The current cert is also fairly new so is there something I'm missing or is the question broken?

mortal belfry
#

Hi everyone I am trying this new room called onepiece where I have to use stegcracker to find the hidden username . I am using rockyou.txt but even after so many hrs I am not able to crack it . Can anyone suggest a shorter wordlist or hint ? It would be helpful

mortal belfry
#

Never mind got it

glad slate
#

Is there anyone who has completed ICE manual exploit recently

#

I have tried many times now and failed to get reverse shell. I did generate shell code correctly and it seems to execute without any errors but nc does not get any connection/reverse shell back.

night fractal
dense tree
#

Hi everybody. I am working in the Room "The Year of the Rabbit" and I have to listen to a video. But on the attack box, I dont'have any sound. Can somebody help me please ?

white salmon
#

Hello!
I'm trying to solve Room called: Basic Pentesting.
I'm trying to reach user j.. via ssh by this command:
ssh j..@IP_MACHINE
and I got a message after a while:
Connection closed by IP_MACHINE port 22.
SSH connection is needed in order to complete all tasks and to gain a password.
What am I doing wrong or how can I get connected?
I've tried ping, ping working nicely.
Can anybody help me with this, please?

zinc oyster
night fractal
#

It is there

#

It's just not the 'owner of the certificate'

#

It's the verifying company

zinc oyster
#

oh I must have entered an extra space or something. I tried that first a couple of variations/times but never got the green light

#

thanks

willow topaz
#

Hi!

I'm stuck on the room https://tryhackme.com/room/furthernmap (Nmap). On task 8 it says "Why are NULL, FIN and Xmas scans generally used?". I've read the information provided above the question, but I still can't figure it out. Anyone who would like to help out? ๐Ÿ˜„

stuck fractal
#

It's in the text above

willow topaz
#

I'm stupid, I only read the very top section........ Thanks ๐Ÿ™‚

zinc oyster
#

I've run into something that is probably again just me mistyping something but on the encryption101 there's a gpg key that should be cracked with john and so I supposed I needed to run gpg2john on the tryhackme.key file but with john 1.9 at least this only gives errors which seems to indicate that the file has more than one key and that this is not allowed. Then I re-read and thought that perhaps I was only supposed to use gpg on the message with the key doing something like ||gpg --keyring /mnt/d/Hacking/THM/encryption101/tryhackme.key --decrypt /mnt/d/Hacking/THM/encryption101/message.gpg || but that just causes core-dump.

vale stirrup
#

I'm stuck on the last question for Pickle Rick. Can someone help me out without spoilers?

zinc oyster
vale stirrup
stuck fractal
#

Yeah there's a bunch of linux privesc rooms

zinc oyster
#

Without giving it away, it is much simpler than you think probably, at least that confused me a while

vale stirrup
#

thanks for the help.

zinc oyster
#

I'm really stumped about gpg2john, I figured that perhaps it was a matter of this not wanting to work on windows so I transported the zipfile to the in browser attack box, but gpg2john only errors: ||# /opt/john/gpg2john tryhackme.key

File tryhackme.key
tryhackme.key contains plain RSA secret key packet!
tryhackme.key contains plain RSA secret key packet!
Error: No hash was generated for tryhackme.key, ensure that the input file contains a single private key only.||

stuck fractal
zinc oyster
stuck fractal
#

You have the private key and some encrypted data. Unless the key has a passphrase you don't need to use GPG2john. You can just decrypt it using the private key

zinc oyster
#

I tried that, though on ubuntu on windows and all I got was core dumped, but maybe I have better luck on the attack box

zinc oyster
#

||# gpg --keyring ./tryhackme.key --decrypt message.gpg
gpg: Ohhhh jeeee: Assertion "node->pkt->pkttype == PKT_PUBLIC_KEY | node->pkt->pkttype == PKT_PUBLIC_SUBKEY" in have_secret_key_with_kid failed (../../g10/getkey.c:4498)
Aborted (core dumped)||

#

(it did some weirdness to the spoiler tag there)

stuck fractal
#

Yikes

zinc oyster
#

I got the same locally (had to b64 encode the zip to get it to the attackbox), not sure what I'm doing wrong

topaz jasper
#

searchlight task 1 - do you understand the flag format? sl{yes} .... = wrong answer ?

astral smelt
#

Check the last bit of task 1

topaz jasper
#

ah, gosh

#

ty

#

so if im using the web based vm, and this room has local files ... theres no way for me to download these files to my machine and then analyize them on the vm ... right?

#

unless i log into my account inside the vm, which seems like not a great idea

sweet hound
#

Can anyone provide me a small hint for Wonderland? I found the page saying that i should open the door to enter wonderland, but I dont find anything with gobuster or in the source code. Thanks!

rigid galleon
rigid galleon
#

this isn't specified ? in the task anywhere ๐Ÿ˜ฎ

#

damn i didn't see it thanks !

#

@stuck fractal

stuck fractal
rigid galleon
#

yeah i found it thank you men !

glacial gust
#

what question

#

try to look for the file that has the info in it

tepid bane
glacial gust
#

did you do a verbose scan, the reason is before the port list

tepid bane
#

Yeah i have found it my nmap was buggy

wild pier
#

Doing the Linux Challenges. I've got everything finished except this one. "Flag 33 is located where your personal $PATH's are stored." I feel like I've looked everywhere a few times...

#

Does "PATH's" mean possessive or plural?

cedar axle
#

@wild pier where is $PATH stored?

#

@wild pier hint ||$PATH is a variable||

wild pier
#

hmm

#

I'm probably overthinking it, everything else was simple

cedar axle
#

yeah, you are

#

what kind of variable is all upper case, by convention?

wild pier
#

@cedar axle system set variables

cedar axle
#

@wild pier what file would you edit to set said $PATH on login

wild pier
#

am I on the wrong user maybe @cedar axle ?

cedar axle
#

check the others

wild pier
#

found it

#

swore i checked there, whatever lol, got it now thank you

cosmic skiff
#

I'm having issues on that one as well Sin and Pood

#

...question on Flag32. Do you need to listen to it?

cedar axle
#

@cosmic skiff yeah, its an audio one

cosmic skiff
#

any thoughts on how to listen to it on the attack box. or I need to VPN in for that one to pull the file down?

cosmic skiff
#

nevermind. Got the VPN and downloaded it :D. Now i'm left for my search for the beginning of one of the flags and the $Paths one still

#

and now i'm down to one

#

Find flag 26 by searching the all files for a string that begins with 4bceb and is 32 characters long. Any hints? Should I not be starting my search at /?

spice mica
twin heron
#

Hey im doing the room "Remux the tmux" and I cant find the answer for "How can you run the desired plugin after loading it?" can someone help me please? This is the last question I have left...

vapid dust
#

how do we specify which shell is used when we login?

stuck fractal
#

It's asking specifically for su

#

So read the su manual

chilly bane
#

@twin heron iirc, the command should be after the set -g command (look in the screenshot)

zinc bronze
#

When exploiting NFS with the root_squash share do I save the file on the VM or on my actual computer?

chilly bane
#

@twin heron below, sorry.

zinc bronze
stuck fractal
#

The suid bash needs to be on the NFS share.

zinc bronze
#

I guess Iโ€™m stuck trying to figure out how to download the file properly

twin heron
#

@chilly bane I still cant seem to find it..

zinc bronze
stuck fractal
#

Raw?

zinc bronze
#

I think so

stuck fractal
candid hazel
#

hey, anyone who has done the windows privesc's room? i have an issue with task 9

glacial gust
#

we need a bit more information

old salmon
#

Room: Network Services, Task 4
Issue: When trying to view the file Working from home.txt using more I get the error "NT_STATUS_OBJECT_NAME_NOT_FOUND opening remote file \Working". Trying to download the file using get I have the same issue.

#

Also side question. The lettering after each file, D,DH,N what are those? I tried looking it up in smbclient docs and couldn't find it

stuck fractal
#

@old salmon directory, hidden

#

Spaces are used to seperate arguments

#

The file name has spaces

#

Escape them or use quotes

old salmon
#

I got it! I forgot the slash at the end facepalm

candid hazel
candid hazel
glacial gust
pine ridge
#

OHsint room ...... question 3 ......can someone give me a hint .i dont want to see the writeups

zinc bronze
stuck fractal
#

What VM?

zinc bronze
main harness
#

guys i am doing Overpass room, i am using burpsuite for the login and i'm getting ||POST /api/login||. the problem is that if i try to go to ||IP/api/login|| it gives me 404

stuck fractal
#

Yes, download it to there. @zinc bronze

stuck fractal
#

/api/login only accepts POST requests

#

If you go there with your browser, that's a GET request

main harness
wet goblet
#

How do I report that a hint is wrong/provides a dead link to the resource?

wet goblet
#

Perfect thank you

gleaming grove
#

Hello ... What would be the best channel to get some help on THM Xmas challenge ?

zinc bronze
stuck fractal
#

@zinc bronze That button

gleaming grove
#

The upload one

stuck fractal
#

Click it

stuck fractal
gleaming grove
#

i mean last advent of cyber

#

2

stuck fractal
#

...last?

gleaming grove
#

ok thanks

zinc bronze
stuck fractal
#

Move it? Copy it?

#

It doesn't really matter where you save it, you're gonna move it after anyway

zinc bronze
stuck fractal
#

You need to provide screenshots.

zinc bronze
stuck fractal
#

What

#

What are you trying to do

#

Because a) it's in downloads already and b) that's most definitely not how you use the cp command.

woven mirage
# zinc bronze

you are trying to copy the file to the directory that the file is already but you're doing it wrong

zinc bronze
#

face palm I see what I did

pine ridge
#

hey

#

can i get a hint in mr robot room for key 2

stuck fractal
#

This channel is not for pointing people to writeups. If someone does that in this channel, they're in the wrong.

pine ridge
#

okay

white salmon
#

can someone help me?

trim haven
#

Go to their home directory

white salmon
#

i was there, i saw the shiba3 dir

#

there was to file( i think files, idk) test and test 1234

little loom
#

why am i here

trim haven
#

What user are you currently?

white salmon
#

shiba2

trim haven
#

Type in your terminal cd

white salmon
#

ok

trim haven
#

Then ls

#

cd on its own takes you back to your home directory

white salmon
#

yes after ls there is this shiba2

#

marked in red

trim haven
#

That's the binary

#

Now follow the steps on the task

white salmon
#

ok

#

you mean export?

#

now there is shiba2

#

what now?

trim haven
#

Follow the steps

#

then run the binary

analog fiber
#

stuck in lle playground task 6
Did you find a flag?
hint says its in .conf but cant seem to find it in the haystack of conf files

white salmon
remote gate
stuck fractal
#

Linux Local Enumeration

umbral hatch
#

I am stuck in task 11 of WIndows PrivEsc v1.0 room. I am trying to solve that with an alternative tool that I have found pre-installed in my Kali Linux. What's funny is that I see 6 different accounts but all the NTLM look exactly the same.

remote gate
stiff siren
#

Hello, I'm stuck in room Linux Strength training.. Final challenge.. I already found the password for the backup sql. My question is how to unzip the file 2020-08-13.zip.gpg of the sql database.. or am I missing a step? Thank you!

analog fiber
#

did grep -i thm{ test.txt

#

got the answer

#

i feel like for this particular task more hints should be given if needed

remote gate
#

nice, i was gonna say check out how to pipe find output to xargs or using the -exec flag for find ๐Ÿ™‚

analog fiber
#

the file name didnt have any thm{ inside

remote gate
#

really? i was just basing it off the answer for Did you find a flag?

analog fiber
#

the file did contain thm{flag value }

#

but not the filename itself

remote gate
#

ahh understood

analog fiber
#

the next step was gonna be -exec if i still didnt find the flag value

remote gate
analog fiber
#

sure

tropic garden
white salmon
#

hi, I'm stuck in room Linux Challenges... flag 3 is supposed to be where bob's bash history is stored, i.e. in his homedir

simple mountain
#

Is that where Bash history is stored?

white salmon
#

the file .bash_history is in ~bob

simple mountain
#

Is that a file?

white salmon
#

ah

simple mountain
#

There we go ๐Ÿ˜„

white salmon
#

I am enlightened ๐Ÿ™‚ many thanks

simple mountain
white salmon
#

I mean, in a sense... it IS a file... but it's only written to when logging out.. so yeah, I get it ๐Ÿ™‚

stiff siren
fickle pollen
#

Hi there!

Can someone please help me figure out what I'm missing..
I'm doing the Searchlight room, and in task5 (the coffee shop) I can not find the surname of the owners.... Please give me a little bit of help here.

hexed crescent
stuck fractal
#

Or at all

white salmon
#

can someone help me

stuck fractal
#

Make the variable and set it's value

#

Run the binary

jagged gust
#

@white salmon look up in the explanation above carefully

white salmon
#

Thanks for your help. I did

stiff siren
#

Oh the CC pen testing room task 4: and looking for the hidden file. My question is how do I know the path for the wordlist? I donยดt see any reference on the writeups. Can anyone help?

stuck fractal
#

@stiff siren use one that comes with kali

#

/usr/share/wordlists/

#

There's dirb and dirbuster lists

barren rapids
#

I'm working on Alfred. I created the payload. I have it uploaded. I have it executing. I'm getting a "Meterpreter session 1 opened" but then I can't type or do anything. I've already rebooted the AttackBox and the VM. Any ideas on why this happening?

stuck fractal
#

Screenshot please

barren rapids
stuck fractal
#

Yep

#

Stop the listener

#

Uh wait

#

It died

#

try sessions -i 3

barren rapids
#

I can't type anything until I ctrl+c. I'm probably doing something wrong but it's not obvious to me. To be honest, been playing with this all day and probably need a break!

#

Thanks for the help. Gonna try it again tomorrow for now.

#

@stuck fractal I figured it out. I had to try it last one time. It had to do with the way I was launching the meterpreter reverse shell.

umbral hatch
# umbral hatch I am stuck in task 11 of WIndows PrivEsc v1.0 room. I am trying to solve that wi...

The tool I have used is
||samdump2||, but I don't know if it is working or not...

||โ””โ”€$ cat hash.txt.orig *disabled* Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: *disabled* Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: *disabled* :503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: *disabled* :504:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: :1000:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: admin:1001:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::||

https://tryhackme.com/room/windows10privesc

cedar axle
#

@umbral hatch samdump2 doesnt work on newer windows 10 sam's, notice all the hashes are the same?

umbral hatch
spice mica
light phoenix
#

Hi! Does anyone here already did the NIS - Linux Part 1?

wintry yarrow
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done.
solemn folio
#

hi looking for a hint and an explanation of what im doing wrong if possible
Room: Nmap

#

Task: 14

#

the question that asks you to perform a tcp SYN scan on the first 5000 ports

#

i need to find how many ports are open on the ip

#

command im entering is sudo nmap -vv -Pn -p1-5000 <IP>

#

and it says all ports are filtered - no repsonse

frail rain
#

try -p- it will scan all of the ports (will take a bit time) instead of -p1-5000, (which is only scanning 5000 ports)

#

@solemn folio

solemn folio
#

Ty for the help potato!

#

I ended up restarting the machine and it ending up working

#

Not sure what happened but I prolly let it timeout and added an hour and didnt refresh

raven frigate
#

Have anyone completed 'Attacking Kerberos' room?

zinc oyster
static echo
#

can anyone help me with the windows privesc room

#

i was trying to dump hashes using SYSTEM and SAM files through creddump

#

and I'm getting this

#
File "/opt/creddump7/framework/win32/hashdump.py", line 117, in get_bootkey
    class_data = sysaddr.read(key.Class.value, key.ClassLength.value)
AttributeError: 'NoneType' object has no attribute 'Class'

tribal olive
#

Hey, I'm stuck in Mr.Robot room, since I'm not really sure how to bruteforce the credentials

stuck fractal
#

wpscan is usually easier than hydra for WordPress

#

Remove duplicates from the password list

midnight swallow
#

can anyone give me a hint on getting root on Internal

kind mauve
#

I'm trying the nmap room and I'm stuck on the Task 14 Practical question There is a reason given for this -- what is it? ** *******

#

Anyone that can help me out I feel like I'm in a need and a haystack

midnight swallow
#

the 2nd question?

kind mauve
#

3rd question

midnight swallow
#

did you do the Xmas scan?

kind mauve
#

sudo nmap -sX -vv 10.10.9.248

#

That is what I just ran

midnight swallow
#

so whats the reason theyre all coming back as open

kind mauve
#

Resets

midnight swallow
#

right so ur not getting a what from the ports

kind mauve
#

no reply?

#

Sheesh

midnight swallow
#

lol did u get it

kind mauve
#

I spent like 30 minutes on that lol

#

I think because I look at the stars I'm like no responses makes sense but there is a -

#

Thank you that was more just not reading mistake

midnight swallow
#

np

stuck fractal
#

Please don't post answers @kind mauve

midnight swallow
#

is anyone available for a hint on root on Internal

frail rain
#

@midnight swallow

  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
midnight swallow
#

I know the service running internally but no idea what to do with it

candid gulch
#

Did anyone try and solve the 'Binex' room? If yes, can you please help? With both ASLR and PIE enabled, predicting any address is impossible, and there's no usable gadgets.

What am I missing>?

stiff siren
#

Hello, does anyone know why I'm getting this weird output? I'm using web base kali linux.

stuck fractal
#

@stiff siren You didn't extract the wordlist

#

It's still compressed

#

You need to extract it

stiff siren
#

Oh my bad I see it now! thanks!

candid hazel
solemn folio
#

Is it possible to diff more than 2 files canโ€™t find an arg in man

#

Linux challenges task flag 13

solemn folio
#

Having more trouble with this one than I thought

#

In the question it references scripts Iโ€™m assuming itโ€™s the ones that are in the update-motd file

solemn folio
#

Solved

white salmon
#

anyone available to help me with attackive directory?

#

but for somereason its not working

#

im putting the right password too

stuck fractal
#

@white salmon did you add it to /etc/hosts?

white salmon
#

the .py?

stuck fractal
#

No

#

The domain

white salmon
#

why would i need to?

stuck fractal
#

Well, show me your command?

#

I can try explain @white salmon

white salmon
#

within that impacket directory

stuck fractal
#

@white salmon so how is your machine going to map that to an IP address?

#

It needs to use DNS because it's a name. It needs an IP.

white salmon
#

ah so use the machine ip after the '@'?

stuck fractal
#

So you either need to add the target as a DNS server (which is usual with DCs) or add it to /etc/hosts so it resolves.

white salmon
#

thanks so much

#

i had a feeling that was the issue

#

i tried the machine ip '.local'

#

but never thought to try just the ip

stuck fractal
#

Try it?

#

Cat that full path?

#

I'm gonna delete it as it's a huge spoiler for the room

zinc field
#

Okay sorry yeah I can delete it

zinc field
true zinc
#

Hello. I am doing "Windows privEsc Arena" room and there is no info about how we have to send files on windows. Is the "shared folders" from remmina the intended way? Or is there another way we can do it? (ssh port is closed)

cedar axle
#

@true zinc easiest is probably going to be python http.server, followed by smbclient

true zinc
cedar axle
#

@true zinc smbclient is probably the second most easy way to transfer a file

white salmon
#

Hi all I am new to tryhackme. I started with the fundamentals and am stuck in the linux fundamentals part 2, task 11 - shiba2. I don't really understand the question. "This challenge is pretty simple. The binary is checking to see if the environment variable "test1234" exists, and if it's set equal to the current $USER environment variable." I need shiba3's password

cedar axle
#

so you have to create an environment variable called test1234 which is equal to $USER

white salmon
#

ok, I did the export test1234=$USER

#

but I don't see how this can lead me to another user's password

cedar axle
#

noww run the binary

white salmon
#

yes! Got it heh. Thank you @cedar axle

cedar axle
#

๐Ÿ‘

fossil cosmos
#

hey guys, room OWASP Top 10, task 11:"Use the supporting material to access the sensitive data. What is the password hash of the admin user?"

#

i try to sqlite, but when i type the commands i get no answers

#

can someone help me

rocky charm
#

@fossil cosmos , man you are asking for the answer to previous task ...
That's not a good practice ...

#

Try redoing previous steps and retyping all commands

fossil cosmos
#

what do you mean man

#

i say that it doesnt work

#

i got the previous answers

rocky charm
#

if you get to same result redeploy the vm and try again

fossil cosmos
#

ok, thanks

rocky charm
#

the task works i did-it yesterday ๐Ÿ˜„

fossil cosmos
#

big room

#

still nothing works

#

idk why it's happening

rocky charm
#

@fossil cosmos

  • to open the db :sqlite3 <filename>
  • to list tables : .tables
  • to read value : SELECT * FROM <tablename>;
#

Mind the . and ;

fossil cosmos
#

i did that man, i am telling you it doesnt work for me

rocky charm
#

can you pm me with the file ?

hardy spire
#

can anyone help me? I am in a room and can't seem to get AD to work?

stuck fractal
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
hardy spire
#

ok ty

#

I am in intro to windows room

#

deploying active directory room

#

the machine deploys, but can not see the AD at all ?

#

hope this makes sense

#

terminated machine and then redeployed machine still see nothing

#

?

stuck fractal
#

...see nothing?

#

What are you expecting to see?

#

What do you mean here when you say AD?

hardy spire
#

Active Directory machine

stuck fractal
#

Be specific here

#

What are you expecting to see?

#

I cannot find that room

hardy spire
#

maybee I am confusing myself

stuck fractal
hardy spire
#

sorry

#

Intro to Windows

An introduction to Windows

stuck fractal
#

Be specific here What are you expecting to see?

hardy spire
#

task 6

stuck fractal
#

So you click deploy

#

What are you expecting?

#

There's a single question I'm asking.

hardy spire
#

does this take you too acitve directory room

#

or to machine?

stuck fractal
#

I'm giving up

#

You're refusing to answer that single question

#

And as such, I can't help you.

hardy spire
#

Users and Groups Management in Active Directory

Deploy the machine and authenticate using RDP (on Windows) or Remmina/Xfreerdp (on Linux) with the user: Administrator:tryhackme123!

#

when i deploy machine

stuck fractal
#

You get an IP

#

That's all you need.

hardy spire
#

ok makes sense now

#

i do appologize

#

for confusing you

stuck fractal
#

When someone asks a question to try to help you, it's best to answer it.

hardy spire
#

okie

stuck fractal
#

Being ignored tends to frustrate people, and remember we can't see your screen or read your mind.

#

You need to explain to us and/or show people what you're expecting and what's happening

hardy spire
#

ok

#

not trying to do that at all

#

ty for your help

balmy dock
#

Hi Guys

I keep getting [Error 110] Connection time out when i tried to use impacket for kerberoasting in the Attacking Kerberos room. any hint on what might be issue. I've googled nothing useful

white salmon
#

idk, but my problem was that I wasn't a sudo account

#

use sudo -i and then try to run that python script

#

**sudo python3 **etc didn't work for me

#

@balmy dock

balmy dock
white salmon
#

hmm

#

what command are u using

balmy dock
#

python3 GetUserSPNs.py CONTROLLER.local/Machine1:Password1 -dc-ip 10.10.191.100 -request

white salmon
#

I don't see any problem... wait for someone else to respond, I'm sorry sadcooctus

balmy dock
main harness
#

welp i need help on room Easy Peasy at task 2 question 2

#

i went on ||<ip>:65525/robots.txt|| and i see the ||user-agent is like a hash (?)|| but idk how to continue

stuck fractal
#

Maybe try crack the hash if it's a hash?

main harness
#

can i hide an image ||like this||?

stuck fractal
#

Yes

#

Mark it as a spoiler when you upload, or name it SPOILER_something

white salmon
main harness
#

k

white salmon
#

||rot||

main harness
#

what's that?

stuck fractal
#

Caesar

main harness
#

oh yeah i found out thx

supple forge
#

doing the splunk room and im stuck on the ip 8000.. it pulled up a cyberchef website

stuck fractal
#

Not your attackbox's IP

supple forge
#

in the attackbox correct?

stuck fractal
#

In the attackbox browser, or your own device if you're connected to the VPN

supple forge
#

Ok.. I was connected to the VPN and it pulled up the attckbrowser and had a desktop, but I was unsure of where to go from there.. I am just starting out and this was the first room I tried is there a different one that I should start with?

stuck fractal
#

The green one. In the room under an early task

supple forge
#

ok... I always skip that task.. I have been on this room for 3 days.. Pulling my hair out...

stuck fractal
supple forge
#

I had done that on a previous task and left when my hour was up and forget to go back..

jagged gust
#

Hey, i am on the dogcat room. I tried ||for the view-GET parameter the following command, that paremeter should be vulnerable to LFI or RCE i think: ../../../../etc/passwd dog %00, so i think i bypassed the filter for dog or cat, it only seems to look if in the string is dog or cat and there is no php at the end. But i cant open from here any file. So per dirbuster i saw there is a flag.php inside, but i cant even open that, with reverse travel or not. || Would appreciate a small hint, researched a lot but didnt find anything useful for me. It responses something like ||"Warning: include(): Failed opening '../../../../etc/passwd ' for inclusion (include_path='.:/usr/local/lib/php') in /var/www/html/index.php on line 24"||

jagged pollen
#

sometimes it just borkes, especially || if you have been screwing with the access log||

#

might have to re-deploy if the problem persists

#

hint:
||instead of null-terminating it, you could just include it at the start.||
||so something like cat/../../../../../../etc/passwd||
|| IIRC i used that||

#

@jagged gust

red sandal
#

Hello guys , i got a problem with BOF preparation in first task , i can't see the offset in the log debugger , some hints?

old lava
#

I'm having a hard time exploiting with a private RSA key. I feel like I might be missing a vital step here. I have the privkey, I know what the username is, and the SSH key doesn't have a passphrase on it.

stuck fractal
#

Room?

old lava
#

thecodcaper

stuck fractal
#

The key is a rabbit hole

#

It asks for an SSH password.

#

The key is a distraction

old lava
#

mf

#

fair enough

#

I even tried to add my pubkey in the authorized keys file but it was a no-go

#

Am I supposed to be able to complete this entire room in www-data? Because I was able to do so, with exception to finding pingu's pass

midnight swallow
#

why would sudo -l tell me I can run these 2 commands with no password and then why i try to it prompts for a password

old lava
#

Did you have to enter a pass to use sudo -l ?

stuck fractal
#

Sudo is incredibly strict on how closely you follow what you're allowed to do

midnight swallow
stuck fractal
#

And what are you running?

midnight swallow
#

||sudo perl -e 'exec "/bin/sh";'||

old lava
#

Correct me if I'm wrong, but don't you need the whole path to the binary ?

midnight swallow
#

even if i run it while in /usr/bin?

old lava
#

What happens when you run that command ?

midnight swallow
#

i get prompted for sudo password

stuck fractal
#

You're allowed to run, VERY specifically, that file with perl

#

Not perl as a whole

#

Just perl /home/itguy/backup.pl

#

Full path for perl is optional

midnight swallow
#

oh

stuck fractal
#

You do need the full path to the script tho

old lava
stuck fractal
#

LazyAdmin

midnight swallow
old lava
#

Nice job ๐Ÿ˜„

dire maple
#

Can I get hint for ccradare2 room..

#

I m stuck at this question

#

What character do you press to run normal Radare commands inside visual mode

#

Kindly tag me if u have a hint

thorny quest
#

Hello guys! I'm currently working on the "Windows PrivEsc" room, and I'm stuck on Task9, "Passwords - Registry". The Task needs me to find default login credentials, however for the admin autologin, there is no such key.

plain mango
#

Hello, Anyone knows how to fix error in configure of openvpn?

#

Sat Jan 2 17:53:02 2021 TLS: Initial packet from [AF_INET]54.193.240.194:1194, sid=e0e195d8 798cdcfe
Sat Jan 2 17:54:01 2021 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Sat Jan 2 17:54:01 2021 TLS Error: TLS handshake failed
Sat Jan 2 17:54:01 2021 SIGUSR1[soft,tls-error] received, process restarting
Sat Jan 2 17:54:01 2021 Restart pause, 5 second(s)

blazing thorn
slow lantern
#

room "DailyBugle" SQL injection
sqlmap takes long long time, is this normal (i used the sqlmap string from the joomla vulnerability - should be fine)
its testing and testing ... 15-30min now

#

normal?

#

ok looks normal, got the output now

zinc oyster
#

I'm a bit confused by task 7 on https://tryhackme.com/room/windows10privesc , the reverse shell I get upon login, I am the same user as I originally was on the remote desktop so it didn't seem like any privesc

white salmon
#

please help

solar needle
stuck fractal
#

Try double quotes.

rose cape
#

im on marketplace as user || michael|| and im having trouble owning root. i see interesting set of stuff to compose a docker container in ||/home/marketplace|| but im unsure if thats useful because it looks like it was possibly made to genuinely configure the box on startup. a nudge would be appreciated.

cold oracle
stuck fractal
#

-p-

#

And give it time to boot

cold oracle
#

rustscan didnt do that

cold oracle
maiden kite
#

I created the new user, got it on admins group but i just can't login with it

#

am I missing anything here?

exotic canyon
#

Looking for a hint on Linux challenges. Looking for flag 16 in the system mount. I have tried DF and gripping within the file systems I see with no luck

stuck fractal
#

When you plug a USB into an ubuntu system, where would you find it?

#

Look there.

white salmon
#

In the Splunk room the question "what is the website where you can find the Splunk forums at?" the answer is outdated. The current answer is 'answers.splunk.com' however the new website is ||community.splunk.com||

noble timber
#

Name of the room: mitre

little sable
#

struggling a bit with https://tryhackme.com/room/25daysofchristmas task 25 (day 20). I got in with ssh and the password but I can't figure out how to use the cronjob to do the privesc bit. I don't seem to have permissions to ||write files to the path directories or the cron.hourly directory||

opal hornet
#

Does anyone finish One Piece

stuck fractal
#

Just ask your question directly

little sable
#

in fact, according to the description, there should be a cron job that runs every minute, but there isn't one on the deployed vm...at least, not one that I can find

remote gate
#

did you try overwriting /usr/local/bin/overwrite.sh and see?

little sable
remote gate
stuck fractal
#

@little sable There's multiple crontabs

#

It's probably in root's personal crontab

#

I'd look around the system for a script, maybe even in your home dir

little sable
#

wait..how am I supposed to know that this thing is running every minute? (I did come across this script ages ago. But I even watched top and I had no idea it was being executed)

stuck fractal
#

You're told to escalate via cron job?

#

Or pspy, as suggested.

little sable
#

I know what script it's going to be

#

just no idea how to know that the script is running every minute

#

yeah, definitely triggered it

#

no idea how I would've found out

#

pspy I guess, but it's not installed so I would've had to scp it to the machine or something

fleet swan
#

Can someone please assist me with the Windows PrivSec room, task 9, I'm missing the PW and have searched the noted path manually as well.

zinc oyster
silk zenith
#

Hmm, im confused on https://tryhackme.com/room/scripting, i've tried sending bytedata 'add', number, etc but i wont get any proper resposne to the first port in the loop. Am i not supposed to send the starting number 0 to the first port? s.sendall(bytes([0])) ? And the first port is the port that is currently displaying on :3010

#

Nevermind...

#

Unclear instructions! ๐Ÿ™‚

distant tartan
#

i am on linux privsec task 3

white salmon
#

did you unpack you rockyou wordlist

distant tartan
#

i tried it

white salmon
#

but?

distant tartan
white salmon
#

you need to unpack it before you use it with john

distant tartan
distant tartan
#

do

white salmon
#

gzip -d rockyou.txt.gz
run this command in the folder containing rockyou.txt.gz

distant tartan
white salmon
#

you're welcome

distant tartan
white salmon
#

yes

#

large file

distant tartan
white salmon
#

if you run john with the unpacked wordlist yes

distant tartan
white salmon
#

the command mentioned in the description above the texrt

distant tartan
white salmon
#

cracking tool for passwords

distant tartan
white salmon
#

okay

signal plover
#

Hey all, I was doing owasp top 10 room. I have a doubt regarding broken authentication section where you could re register a username with slight changes like "admin" to " admin"(space at first). I didn't get what can coz this issue. Doesn't adding space at first will make the username unique coz the database(say mysql) and backend(say php) will consider "admin" and " admin" to be different?

#

Not posting any spoilers just saying what's written in the Introduction.

tidal heart
#

@mild silo

pine ridge
stuck fractal
#

Are you sure it's a suid escalation?

pine ridge
#

how do i make sure that

stuck fractal
#

Nothing stands out to me there so I'd keep looking for different vectors

pine ridge
stuck fractal
#

If you can't find a suid privesc, then it's probably not a suid privesc?

pine ridge
#

kay

white salmon
#

Anyone working on windowseventlogs room ? I think there is an error with answer for 5-4

#

I got the right command, that is the answer to 5-2 but if I copy&paste the part of the output requires I get wrong answer

#

ok, I just solved, there are some extra dots at the end of the output

balmy wedge
#

Room: Blaster ||I know I am supposed to be looking in the browser history but it is dead empty. I have restarted the machine and still have the issue. Any ideas?||

balmy wedge
#

Can i get pmed the answer?

#

and thanks for the response!

stuck fractal
quartz ruin
#

Hello everyone! i am stuck with mitre rooms Task 7

balmy wedge
balmy wedge
quartz ruin
#

Per the detection tip, what should you be detecting?

#

What platforms does this affect?

#

latest questions for this room

balmy wedge
#

they aren't as obvious as you would assume but they are there.

#

I had to dig for those too

quartz ruin
#

Oops ! GG

balmy wedge
#

got it?

quartz ruin
#

nope xD

balmy wedge
#

link the page you are searching on

#

dm me

quartz ruin
#

i need hints

#

for mitre room task 7 above questions

balmy wedge
#

@quartz ruin You ever get it? I asked for a link to the page you're looking for the answers on. Send it over.

rich shard
#

hello guys, I need help with the task 7 (Bypassing Client-Side Filtering ) of Upload Vulnerabilities. I am blocked there for hours. I am able to upload the shell.php and I can see the file in http://java.uploadvulns.thm/images/. However I am not able to reserve the shell with netcat. I am listining the port 1234. Someone can help me?

trim haven
#

Have you tried a different port

rich shard
#

it is the first time** sorry

stuck fractal
#

That's not a reverse shell payload

#

To use that payload, you'd go to /shell.php?cmd=ls for example

#

cmd is a parameter that PHP will take from the URL and run as a command

rich shard
#

Hmm ok, so if I use something like that <?php
echo system($_GET["ls /var/www/"]);
?> I will be able see the file then cat it ?

stuck fractal
#

$_GET["var"] is used to get a parameter from the URL in a GET request

#

You'd want to do something like curl ip/shell.php?cmd=ls%20/var/www/ and then curl ip/shell.php?cmd=cat%20/var/www/ThisIsASecretPasswordFile.txt

modest rover
#

Can anyone help me with the last step of retro?

#

when i open hhupd.exe and click on certificate it pops up with two options ... to use default or to choose an app.. but both can't be clicked

#

??

#

I tried web based rev shell too... but returned can't daemonize

quartz ruin
white salmon
#

hello guys any hint on this question : What MITRE ATT&CK technique is associated with powershell/trollsploit/voicetroll ?

azure pecan
#

How would I go back to meterpreter from powershell? I am on Steel Mountain task 3 if it helps

balmy wedge
maiden kite
#

hey guys, on windows privesc room on task 3 I tried as the instruction says and nothing... tried different ways with the "" and " but I really don't know what to do.. can you help me?

noble timber
fossil cosmos
#

hey guys, i am facing a small problem at OWASP-Juice-Shop-task4-Question #2: Reset Jim's password. Security question-Mother's maiden name

#

i put the name and nothing happens, i tried everything

winged mist
fossil cosmos
#

it doesnt ask me that

#

-Mother's maiden name

#

it's not Samuel

winged mist
#

Task 4 aka โ€œWho broke my lock?!โ€

fossil cosmos
#

yeah

winged mist
#

& question 2 is reset Jimโ€™s password

#

Right?

fossil cosmos
#

man, really now?

winged mist
#

Iโ€™m tryna confirm the room you doing cus mine says Jimโ€™s password

fossil cosmos
#

hey guys, i am facing a small problem at OWASP-Juice-Shop-task4-Question #2: Reset Jim's password. Security question-Mother's maiden name

winged mist
#

The Star Trek thing

fossil cosmos
cedar axle
#

@fossil cosmos read, all of jims posts and comments

winged mist
#

^^

#

~I donโ€™t think I did all that iirc~ I canโ€™t remember KEKW

#

Just did smol googling & got it

cedar axle
fossil cosmos
cedar axle
#

do some googling about james kirks mother

fossil cosmos
#

winona

#

i have tried that

#

doesnt work

winged mist
#

&

#

You got a middle name

cedar axle
#

keep looking

#

hint fandom.com

cedar axle
fossil cosmos
#

thanks for your help anyways

#

my fault was the e-mail

#

....

#

low iq problems

winged mist
#

You did it congrats GJ ๐ŸŽ‰

fossil cosmos
#

lol

white salmon
#

Hello, I have a question about the room https://tryhackme.com/room/windowseventlogs (Task 2, Question: What are the total number of events?) Is "Windows PowerShell log" identical to "Microsoft-Windows-PowerShell" (from Question 1)?

solemn smelt
#

@white salmon The Windows Powershell Log is the Log Name itself where as Microsoft-Windows-PowerShell is the provider name. When youre filtering with Powershell you can use either one to look through the events.

marble lily
#

Hi All!
The Attacking Kerberos room:
Question: What two services make up the KDC?

I know the answer but can't seem to work out the order or what the question is expecting to see. Can someone please help me ๐Ÿ˜†

glacial gust
#

use the acronyms with a comma between them

marble lily
rich gazelle
#

Can anyone please help me with BOF Prep Rm - TASK34 - OVERFLOW3?

#

I got the badchars but the system is not accepting them!

rich gazelle
#

Ignore my prev question about mona.. i figured it out.. took me only 3hrs... :/

shadow oar
#

got a question for linux fundamentals, for "What flag outputs all entries" thats just ls right?

stuck fractal
#

The command is ls

#

A flag is something you supply to the command usually after a -

shadow oar
primal mantle
#

Has anyone finished the "Windows Event Logs" room? In Question "Using Get-WinEvent and XPath, what is the query to find WLMS events with a System Time of 2020-12-15T01:09:08.940277500Z?" I already found 2 working queries, but they do not match the flag. Any hints?

cedar axle
#

*/table/key[@subkey=data]

fossil cosmos
#

guys, there's no -u option in gobuster when i want to run gobuster -u

#

what can i do

white salmon
#

what input do you have when you type " gobuster -h " in a terminal

frail rain
#

nothing

#

gobuster -h will show u basic help manual

#

and what you have to do if you have to read about something in a descriptive way, is present in the help man

white salmon
#

Yeah I know but it's weird that he doesn't have the basic -u command when running gobuster

frail rain
#

no because it depends on what you are doing

#

gobuster is not limited to directory enumeration

#

directory bruteforcing might be a better term, so it goes like "gobuster what you want to do parameters"

white salmon
#

Yeah it's true

primal mantle
#

@cedar axle thanks i queried the specified log via EventID +key/subkey and now i saw i had a typo in the timestamp๐Ÿคฆโ€โ™‚๏ธ

mental ivy
#

Did anyone ask question 6 of task 7 in the Windows Event Log room? The dates in the evtx file do not work as an answer to the question.

glad briar
oblique cliff
#

Increase the time in the exploit

#

Itโ€™s a time based sqli, so increase the time so it doesnโ€™t get false positives

#

@glad briar

glad briar
oblique cliff
#

Are you pointing it to the correct directory

glad briar
oblique cliff
#

That worked?

glad briar
#

oh yes, mispelled directory..noob mistake

oblique cliff
#

Awesome

barren rapids
barren rapids
barren rapids
glad briar
#

no worries, great!

zinc oyster
#

I'm a bit stuck on https://tryhackme.com/room/steelmountain task 4, doing the ||Rejetto|| exploit manually and doing it from either of the attack boxes. I haven't managed to figure out how to bind a webserver to port 80 on them (since it seems bound on various interfaces) so I hacked the exploit and added "%3A8080" after ip_addr in the vbs assignment. I can see that my 8080-server gets the correct requests for nc.exe, but nothing ever happens on my nc -lnvp 4444 (I updated local_port to match that port)

glacial gust
#

in investigating windows for the C&C IP where is the best place to look for it

odd edge
#

In room โ€œOWASP Juice Shopโ€œ Task7 question #2 โ€œPerform a persistent XSSโ€ Iโ€™m struggling to get the flag. Iโ€™m quite sure, I did everything right ๐Ÿ˜….
At least the xss alert occurs after logging in again. Iโ€™ve tried it several times ... with burp running and without but nothing.
Itโ€™s driving me crazy, since this is the only room left to close a path.

mild eagle
#

in room motunui I've got a shell but when trying to run a cmd ie. (id, or other) simply return kills the shell. I've looked at writeups and used the same route as them.

oblique cliff
#

@digital iris stop causing people pain^

digital iris
#

loooool

#

uh

#

i have no idea why thta is beyond my brain power

gusty kite
#

can anyone give a hint on the windows events log room? I am pretty sure I have the right answer for Task 5 question 1 but it will not accept it.

barren rapids
#

@gusty kite If it won't accept, it's wrong. Look at the format they are providing you and make sure your command matches.

gusty kite
#

@barren rapids it looks like it matches.

#

it gives me a sane output on the deployed machine

barren rapids
#

@gusty kite One more hint, there was more than once where I thought I had the format correct and I was using the wrong words even though they were the same length

gusty kite
#

have you finished this room?

barren rapids
#

Yes

gusty kite
#

could I maybe send you my answer and maybe you could hint me on where it is broken

barren rapids
#

Sure

gusty kite
#

ahh nevermind. the format had a bit more that was hidden as it is such a long command.

white salmon
#

I'm doing room Network Services, last question on task 4. I've downloaded the id_rsa file from the SMB share but can't figure out how to ssh in. I've tried ssh -i ./id_rsa [IP] which assumes I'm trying to access as root and asks for password. I've also tried ssh -i ./id_rsa john@[IP] and then it asks me for john's password. I thought the whole point of setting up ssh keys was to avoid using passwords for ssh. Am I just formatting it wrong?

white salmon
winged mist
#

I guess you didnโ€™t format the id_rsa file right. Or something else Iโ€™m missing cus missing ss

barren rapids
white salmon
winged mist
#

Ah right

white salmon
winged mist
#

I meant Screenshot kek

white salmon
half sandal
#

I have just found tryhackme-page.

#

I cannot really find how to login to the virtual machine. Is there a channel for this kind of questions or is it ok here?

woven mirage
white salmon
#

and now I'm running into another issue ๐Ÿ˜• same room, end of task 6. The question asks to which user could port 8012 (tcp - presumably about to use for telnet connection) belong. There's 5 stars as format hint, suggesting a username 5 characters long. The only username returned by enum4linux which is 5 long is guest, but the question rejects that answer. I tried all the other returned usernames (e.g. administrator, krbtgt, etc.) and none are accepted for answer. I also tried "admin" even though that's not a returned username

winged mist
white salmon
winged mist
white salmon
#

interestingly, the room doesn't prompt us to try connecting until the next task

winged mist
blazing thorn
blazing thorn
#

so I killed the original deployed box and redeployed

#

got the correct answers this time

#

first time aroud there were logs from today in the event viewer which I'm guessing is throwing the # of logs off

little sable
#

I have no idea what to do with the second question on task 29 (day 24) of https://tryhackme.com/room/25daysofchristmas I followed the hint and looked for kibana cves, but I can't figure out how to use them and I can't find any examples online

silver crater
#

Hey everyone!

#

I'm doing the windows10privesc room and can't get past task 9, the autologon credentials aren't listed. Am I missing something?

old lava
#

When I get the secret its much shorter than expected.

white salmon
#

Not sure if i am missing something or if it's a bug. But i am not sure what else to do. I am not filtering (as far as i know) but the room won't take my input.

SPOILER ALERT

trim haven
#

It would help if you put which room this is

white salmon
#

Yes offcourse, stupid me. This is Windows Event Logs.

zinc oyster
zinc oyster
vagrant ibex
white salmon
#

I have not been able to resolve the issue. I cleared all filters but i am not getting different results. From what i see from the the size of my logs is way more than the 68kb that is mentioned in the room. I think this could be the issue.

#

I suppose i'll move this to bugs i guess.

#

@vagrant ibex

vagrant ibex
#

I'm still stuck on task 7. Let me quickly go back and have a look to see what answer I get now.

barren rapids
orchid anvil
white salmon
#

I did try to unfilter and filter in multiple instances, but i suppose you have to get lucky ^_^

lone locust
#

I need HELP! I am working on a tryhckme room Windows Event Logs. I know the answer is correct, yet the I am getting incorrect

glacial gust
#

which question

lone locust
#

Task 2 - Q2 : What are the total number of events?

glacial gust
#

are you using the number listed at the top of the winevent window

lone locust
#

I did that. I correct incorrect when I submitted it

glacial gust
#

are you in the correct PowerShell logs?

lone locust
#

I believe so Operational

barren rapids
tough shoal
#

Hey guys. I'm pretty new here and I'm stuck on a task in the Linux Fundamentals room, in that I don't understand what the question is asking me to do

glacial gust
#

are you in that log

tough shoal
#

I"m stuck on Task 11. It tells me the function of a binary and then asks me to find a password

#

And I'm not sure how I'm supposed to start, or honestly that I even understand the question

white salmon
tough shoal
#

@winged mist I'm on Part 2, Task 11

winged mist
tough shoal
#

Ok I get it now

tough shoal
#

on to Part 3

lone locust
#

@barren rapids Thank I will

lone locust
onyx sparrow
#

I have everything until the domain, but i dont know what to put after /

glacial gust
onyx sparrow
#

thats what i dont know, i supposed api.phpFUZZ but its not

tired bough
#

Good eve. I managed to ssh and get inside the account in the NFS room, now I'm tryna exploit and it says I should download the bash executable! Where would I download that from? Thanks sm in advance

wanton epoch
#

pointers for https://tryhackme.com/room/mitre task 4 q1? I'm not sure which analytic it references and what it's specifically looking for

glacial gust
#

when you open the CAR link, it the last section

wanton epoch
#

@glacial gust thanks!

glacial gust
#

np

silver crater
#

@zinc oyster very cool, thanks for the feedback. Man I searched for two hours on that task. I learned a lot in the process, good to know I wasn't the only one scratching my head.

icy shard
#

Linux Fundamentals Part 1 task 9
i was told to come here for help i thinks its a simple question but I just started and am confused

glacial gust
#

if you do a touch <file> and do a ls does the file show up

icy shard
#

yes

silver crater
#

what's up @icy shard

icy shard
#

and then what i thought i do is /tmp/aa/noot.txt

icy shard
silver crater
#

What are you stuck on

icy shard
#

i just started this room and im supposed to make a file called noot.txt then open it to get a password

glacial gust
#

I think you need to have the file in the shiba1 folder not /tmp

icy shard
#

??

glacial gust
#

there should be binary in the home folder

silver crater
#

If I remember correctly you need to run the binary

icy shard
#

where is the home folder

icy shard
#

i reallly did

woven mirage
#

type ls and send screenshot of what appears

glacial gust
#

it is the folder you go to when you log in or you can do "cd ~"

icy shard
#

ill do it in 13 minutes

#

ive used my 1 hour room

#

today and its midnight in 13 mins

icy shard
glacial gust
#

if you type ls in the folder you should see a file that you can run

#

when it runs it will give you what you are looking for

icy shard
#

so i run it by typing /tmp/aa/noot.txt

#

??

stuck fractal
#

You need to run the binary

#

Not the empty text file that you created

icy shard
#

oh

#

so the binary is in cd ~

stuck fractal
#

cd ~ is a command

#

~ is a path, representing your current user's home directory

icy shard
#

so how do i find the binary??

#

to run it

stuck fractal
#

It's in the task

#

Note: the name of the binary is shiba1, as shown in the title

icy shard
#

Note: the name of the binary is shiba1, as shown in the title

#

oh

#

so i do

#

/tmp/aa/shiba1

stuck fractal
#

No

#

Why are you prefixing stuff with /tmp/aa?

#

You should be in your home directory still

#

Go home.

icy shard
#

huuuh

#

with cd ~

#

??

stuck fractal
#

You're missing a space but yes

#

Yep

icy shard
#

ok

stuck fractal
#

Create the file there

icy shard
#

thankyou very much

stuck fractal
#

Then run the binary, which is in that folder

icy shard
#

i was stuck on that for awhile

#

thankyou goodbye

icy shard
#

ye so that didnt work

#

any other waysi could do it

#

if i type cd ~

#

it does nothing

glacial gust
#

can you grab a screenshot

icy shard
#

of the question

#

ok