#room-hints

1 messages ยท Page 78 of 1

ashen scaffold
#

Im not a python pro...but

red arch
#

python has to think
"Oh you want me to use this string as the key"

ashen scaffold
#

String not variable

#

Thats what i ment

white salmon
#

i dont know

#

i don't understand anything

red arch
#

ok so

#

imagine you wanted to

ashen scaffold
white salmon
#

import string idk

red arch
#

print(test)

and it should print hello

white salmon
#

okay print

#

OH

#

print

red arch
#

no

#

xD

white salmon
#

frick

red arch
#

how would you define

#

test

#

to make it print

#

hello

white salmon
#

def

ashen scaffold
#

print("Hello, My name is Jovnn")

white salmon
#

okay and

abstract lotus
#

decode it by hand

red arch
#

xd

white salmon
#

u know I actually tried

ashen scaffold
red arch
#

xD

white salmon
#

so

#

i just need to make it print key?

abstract lotus
#

no

red arch
#

yo can you dm me

#

the script

#

I wanna try smth

ashen scaffold
#

Jovnn, cat that .py file and look at how the variable Enter Key is defined

white salmon
#

yeah

#

so it's key=input enter key

#

that doesn't seems sus to me

ashen scaffold
#

How is it written

white salmon
#

wdym

ashen scaffold
#

Is it like this "Enter key" or 'Enter Key' or Enter key

white salmon
#

"

red arch
#

:D

white salmon
#

it's just me lazy ass

#

dw

red arch
#

:D:D

ashen scaffold
#

Soo

red arch
#

can you pls copy paste the python script to me

white salmon
#

wait

ashen scaffold
#

It just doesnt understand your key

#

Understand

red arch
#

key=[key]

print(key)

ashen scaffold
#

And screams at you

red arch
#

what would you put in

#

[key]

white salmon
#

OH

red arch
#

what would you replace that with

#

to make that script work

white salmon
#

that make sense

abstract lotus
#

yes

white salmon
#

doesn't work

#

lol

red arch
#

send the script

#

over

white salmon
#

I'm on vbox

#

u gonna wait

red arch
#

on vbox?

#

oh ur working on windows

white salmon
#

yeah

ashen scaffold
#

Virtualbox

#

It doesnt like copy and paste from guest to host, not like vmware

red arch
#

just dual boot like I do ๐Ÿ˜Ž

ashen scaffold
#

Negative

red arch
#

you might have to reinstall

#

everything like 3 times

#

a month I think

ashen scaffold
#

๐Ÿ‘€

red arch
#

wait so

#

what now

#

if "" doesnt work

#

what python are you running it with?

white salmon
#

python

#

u cant with 3

ashen scaffold
#

Jovnn, you arent messing with the script itself are ya

red arch
#

wait a minute

white salmon
#

nope

abstract lotus
#

you copy the key correctly?

white salmon
#

yeah

red arch
#

oh

#

now

ashen scaffold
#

Send a ss

red arch
#

I know why that '

ashen scaffold
red arch
#

is on that key

#

thats why

#

the '

#

is there

#

but

#

wait

#

nvm

#

I think

#

u were messing with ur script

white salmon
#

i didn't

#

it's what I got

ashen scaffold
#

Send a ss of the screen

white salmon
red arch
#

then edit the script and add ' to the end

#

of the string

white salmon
#

which string

red arch
#

encrypted_mess

ashen scaffold
#

The only super long one

red arch
white salmon
#

see

#

just tell me

ashen scaffold
#

Whose ss is that?

white salmon
#

of him

red arch
#

mine

ashen scaffold
#

Dont need b

white salmon
#

i didn't set b

red arch
#

indicates its a python byte string no?

ashen scaffold
#

Dont need that

red arch
#

type error must be bytes

white salmon
#

see

red arch
#

ur script is broken then

#

idk

white salmon
#

u don't have yours rn so I can just copy and paste and do that way

#

tbh I don't wanna reset room

ashen scaffold
#

Wait nvm

#

Pioli, add the first thing in ""

red arch
#

same thing

white salmon
#

it's just broken

#

lemme se writeup to see

#

if it's the same

red arch
#

yea ok so

abstract lotus
#

no

#

do it by hand

red arch
#

I changed key="actual key"

#

and when running it same result

ashen scaffold
#

No editing of the script is neccesary

white salmon
#

yeah

#

script is fricked

ashen scaffold
#

But I do want to know what he did different

white salmon
#

write up says u just need to set ket

#

and that's it

#

key

#

no edit is necessary

abstract lotus
#

thats how i got the flag

ashen scaffold
#

Jovnn, soo what are you doing now?

red arch
#

yea same

white salmon
#

nothing

#

listening to music

ashen scaffold
#

I mean to get the flag

white salmon
#

pioli send me root flag at the least we found way

ashen scaffold
white salmon
#

oh nothing

ashen scaffold
#

Why not

white salmon
#

can't get a flag of a broken script

ashen scaffold
#

Dont give up

white salmon
#

i mean I can manually get it

red arch
#

or just

#

reset the box

#

you have creds for charlie ssh

#

and can easily get root again

white salmon
#

okay

#

if that script doesn't work

#

u will send me root

#

okay?

ashen scaffold
#

No

white salmon
#

or

#

i will do it manually

#

and it will take 100y

red arch
#

lets just

#

hope it works

#

ok?

white salmon
#

okay

ashen scaffold
#

Reach out to room creator if you think the script is broken...which it isnt

white salmon
#

we will see

red arch
#

imma switch back to arch and look again

#

brb

ashen scaffold
#

Get to root from scratch and enter key

abstract lotus
#

what encryption does the message use?

#

could just use an online tool

white salmon
#

I DID IT

#

FINALLY

#

fricking script

red arch
#

xd

#

knew it

#

could you send it again?

#

I wanna see what the difference was

white salmon
#

thank you guys

#

ofc

red arch
#

good job

#

sorry bot

#

lol

white salmon
#

check dms pioli

native grove
#

need help in room mr Robot ctf key2 i brut force the login page and i didnt find anything

red arch
#

my brain

native grove
stuck fractal
#

You're missing a ^

#

^USER^

white salmon
#

james

#

i had more trouble with script then how to get root

stuck fractal
#

I still haven't done it

white salmon
#

u would probably finish it in 15m

#

i needed 3h

#

imagine me doing osiris

red arch
#

im just

#

so confused

#

idk maybe you sent the script wrong

#

like theres a part missing

#

since it just cuts off with no ' at the end

white salmon
#

maybe

#

but we did it

#

thank you boys

#

i gain a lot of respect for you guys minecraftheart

red arch
#

ty

#

appreciate the thankfulness

vital spoke
#

holy moly this hash wont crack

wispy anvil
#

how can i find the password for shiba3. from linux fundamentals 2

stuck fractal
wispy anvil
stuck fractal
#

So create the variable and set it correctly

#

Run the binary

#

Then you get the password

#

Make sense?

wispy anvil
stuck fractal
#

Ok, so maybe show us what you're doing and ask for help?

wispy anvil
wispy anvil
stuck fractal
#

Ok I don't think you read the question thoroughly

#

or looked back at how to set variables

#

or how to run a binary

wispy anvil
#

uh okay

#

I've been trying export $USER=test1234 for 2 hours

#

I just was supposed to write the opposite like export test1234=$USER :P

stuck fractal
#

Yeah

drowsy sequoia
#

Trying nmap -T4 -p- -A <ip> on chocolate factory but service time scan takes forever, any solution or suggestions please

candid nimbus
#

Yeah, no-one's got time for -A -p- . First thing is use -Pn. A lot of THM boxes refuse pings and nmap will think they are dead and won't run the rest of the scan. If you just want to find what ports are open with -p- do it with a quicker scan first, then once you've found them you can bring out the big guns in a more targeted way.

drowsy sequoia
#

Okay will sure try that, thanks for your time ๐Ÿ‘.

white salmon
#

The Juice Shop room is a free room, but it requires you to have done the exercises int he Burp Suite room (for subscribers only)...so does this mean the Juice Shop room is impossible for those who are not subscribers or have not learned about Burp Suite elsewhere?

spring tartan
#

could someone please give me a hint on the new room John, I'm stuck on this one question to finish it, Task8 Custom rules question 2 :

#

What rule would we use to add all capital letters to the end of the word?

#

thanks

wicked bolt
#

well a john rule append is $ or Az so i'd start there

spring tartan
#

ok

#

thanks

mint copper
#

could someone help me out with Crack The Hash 2.. Task 6 advice n 1? I have created rules in john but the hash wont crack.. dont know if i am missing something..

wicked bolt
#

what rules do you have?

#

and can you show me the wordlist maybe dm

rustic sphinx
#

should be using rockyou

fossil cosmos
#

@wicked bolt can i dm you?

wicked bolt
#

send me what rules you have and i can advise

fossil cosmos
#

sure

ashen marsh
#

Hi,

I need a hint for the horizontal privilege escalation
(from ||www-data|| to ||aubreanna||) in "Internal" room (https://tryhackme.com/room/internal)

I've found some interesting things, such as:

||$cfg['blowfish_secret'] = '6wqoJ$mf_Wv($r?g$l4+#P#lAoCVVUM3';||

and I also found the password of the ||phpmyadmin||

median compass
ashen marsh
#

anyway, I'll repeat what I've done, maybe I missed something related to ||aubreanna||

median compass
gentle void
#

What rule would we use to add all capital letters to the end of the word ? for john the ripper ?

#

i can't figure this out

median compass
#

and at the end is append in john-speak

old pond
#

cc:crashcourse room.. working with nmap..even a port scan on a single machine ip taking more than an hour ....is it normal and the only way...to wait for a hour for scan completion..??

#

Cc: pentesting carsh course room

median compass
old pond
#

nmap -p- -T4 ip

gentle void
#

@median compass yeah but still can't figure this out

old pond
#

@median compass

barren pier
#

looking for some help on the Linux: Local Enumeration room on Unit 1 - tty, where is asks "
How would you execute /bin/bash with perl?
"

and its saying my answer of perl -e โ€˜exec โ€œ/bin/bashโ€;โ€™ is wrong so im lost. any help guys?

median compass
old pond
#

Yup @median compass

median compass
#

are you using the in-browser machine or your own VM/machine?

median compass
#

is your VPN active?

old pond
#

Hm...30 mbps

#

It's active

median compass
#

you can check with ip a you should see a tun0 interface and no other tunX mentioned

old pond
median compass
#

if you have long round trip times you could try increasing the nmap timeout parameters - -w <time> in seconds

#

check your connection health by running a ping against 10.10.10.10, you should see a ping time measured in <100ms, if you don't then try the timeout tip

old pond
median compass
median compass
pallid cedar
#

stuck on root flag in Chocolate Factory. Though i input correct key it shows error as "Fernet key must be 32 url-safe base64-encoded bytes"

#

need help!

wicked bolt
pallid cedar
#

nope flag is encoded

wicked bolt
#

Ahhh i might have to load up the box again to remember

novel bay
#

created a 100 mb file of mexico cities

wicked bolt
novel bay
#

i m trying all the rules

#

oh

#

..

wicked bolt
#

every possible iteration

novel bay
#

i found

#

a file

#

with most of the towns

pallid cedar
novel bay
#

that had some towns that your file didn't

wicked bolt
#

not the 30gb one

novel bay
#

ye

gusty kite
#

I am also struggling with the mex towns one

#

๐Ÿ˜•

candid nimbus
#

Guess what. Yup, still stuck on Mexico. Tried as many combinations as the mentalist provides as well as toggling cases, all the john and hashcat leet rules... currently I'm down to trying different lists, spellings or just random combinations of substitutions. It can't be that tricky can it!!? The first 2 were a bit painful but the rest was straightforward ๐Ÿ˜Ž

wicked bolt
#

same.

#

i used @vital spoke script to generate every possible character and iteration for every possible 14 digit place name i could find from lists.. so i must not have the place name right

#

or there's something sneaky like a 1 on the end

#

in which case i should be testing 13 char passwords and 12 with border mutation too, but thats not in the task

#

(is it cheating to use the input field of THM as a hint?)

pallid cedar
wicked bolt
#

i even tried places with spaces (heh) and iterated a _ instead of space

#

unless it's a placename with a space that has a different symbol instead

#

@white salmon is there a hint you may be able to provide ? ๐Ÿ™‚

wicked bolt
#

task 6 question 3 rather

white salmon
#

sure for crackthehash task 6 quesiton 3 || use wordlistctl to find a cities list and then on /usr/share/john/korelogic.conf look for a rule about l33t||

#

also remember to convert uppercase to lowercase on the wordlist, that I did it with a linux bash command, but it can be done also with a jtr rule

wicked bolt
#

@white salmon can i pm to show what i've tried

shadow hound
#

Hey guys, I got what I wanted but I'm looking to improve my output. Does anyone know how can I "grep" an output of

Get-ADUser -identity *********-properties *
#

I've tried

Get-ADUser -identity *********-properties * | Select-String -AllMatches "password"
#

There is no room for finding help with commands but I was hoping to see maybe someone has a clue?

white salmon
smoky star
#

@wicked bolt you can also dm me if you for task 6 question 3

rocky charm
#

Guys, i really can't figure this one ...
Finished all other questions but still can't figure this one ๐Ÿ˜
I know main use is to create dynamic passwords from wordlist considering the password complexity requirements and user tendency to append, perpend the required characters ...
Room : John The Ripper
Task : 8

stuck fractal
#

I think I can see the exact text that fits that format

#

Right there

rocky charm
#

Tried : password complexity requirements ...

#

didn't work ๐Ÿ˜

#

That was my first idea, even went to copy paste in fear of a typo ๐Ÿ˜

regal mantle
#

hi

#

i can't crack the etc shadow hash in that room, did you manage to do it?

#

and @rocky charm look for the word "exploit" to find the answer

rocky charm
#

THX man ...

#

๐Ÿ˜„

regal mantle
#

did you crack the shadow hash?

rocky charm
#

yes, managed to complete the shadow hash

#

did you split the downloaded file in 2 parts ?

regal mantle
#

how much did you have to wait?

#

i have the unshadowed.txt file and john has been trying to crack it for hours

rocky charm
#

almost instat ...

regal mantle
#

i split it and ran unshadow and i have the file and john is working on it but i get no result

rocky charm
#

pass me the content of unshadowed txt

#

and I'll give it a run

regal mantle
#

so does it look like yours?

frail rain
#

Use spoilers, also idk if its allowed to share things.

#

like root hash

rocky charm
#

the hashes are downloaded from the task as txt files

#

the decripting is a task ๐Ÿ™‚

regal mantle
#

this one worked

rocky charm
#

try redownloading the file, splitting to passwd and shadow - runing unshadow again , and after that john on the result

regal mantle
#

and windows and linux generated different outputs when i ran unshadow and both were wrong

stuck fractal
#

I recommend against unshadow

#

Just use username:hash

rocky charm
#

THX for the advice , i'll remember for future use ๐Ÿ˜„

gloomy estuary
#

Hello guys, I'm working on the steel mountain machine on THM. Do you know why I can't execute winpeas on the remote machine?

novel bay
#

the l33t rule

#

doesn't work

#

ive tried wordlistctl wordlist + lowercasing

#

i tried both with and without spaces

smoky star
novel bay
#

il dm u

feral juniper
#

nmap room help please. task 14. im supposed to deploy ftp-anon against the machine and tell if it is open for login in or not

stuck fractal
#

Terminate and redeploy the target

feral juniper
#

ok

stuck fractal
#

And/or check your VPN

feral juniper
#

ok

#

thanks

#

i did...but im still getting filtered..

stuck fractal
feral juniper
#

i restarted ovpn..

#

ok

hollow drum
#

I would recommend using the winPEAS.bat if you are unable to get the .exe to work. The .bat has always assisted me when the .exe would not work.

#

๐Ÿ‘€

candid nimbus
# novel bay il dm u

I just did the same as you with both the .conf rule and the 2010 one with no joy. Do shout out if you get any new ideas for what's missing!

candid nimbus
#

Thanks very much, I'm sorted now! Cheers.

vital spoke
#

if anyone could assist me with crack the hash advice 3, preferably thru dm, i would greatly appreciate it - thanks

wicked bolt
#

I think they need to update that room, its such a strange rabbit hole with that question

#

or update a certain wordlist with a certain city

ocean stump
#

I'm doing the upload vulnerabilities room: https://tryhackme.com/room/uploadvulns

I'm stuck on task 7, I've tried a bunch of different dirbuster scans with different wordlists but I'm only finding the /assets subdirectory and the ones it contains - however they don't contain the file uploads. The room says it should be at /uploads but that 404s. Anyone able to help?

lofty girder
#

can you provide screenshots/commands

ocean stump
#

oh nevermind i am just stupid. /images is different from /assets/images

meager turret
#

hi

pseudo wraith
meager turret
#

in crak the hash part 2 hi solved

#

soryy to distrub you

#

i have not researched before asking

pseudo wraith
pseudo wraith
meager turret
#

dont ban me

meager turret
pseudo wraith
# meager turret im stuck actually

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
meager turret
#

okay thanks for help
GOD bless you!

ocean stump
#

Having trouble finding the location of the 3rd image in the Geolocating Images room, is it a mosque?

#

I think I have identified the direction the image is looking but I'm stumped as to the actual location, or what that white building is

#

oo I think I found it but it's not labelled on google maps

#

goddamn that was difficult

old pond
#

cc pentesting room : while using gobuster what are the wordlists that i can use...is their specificity to use particular wordlists...is kali come with any built-in wordlists in its software package??..

stuck fractal
#

Yes

#

/usr/share/wordlists

cold bay
#

For Crack The Hash 2, Task 6, Advice 1, I'm having trouble with the rule set. ||I took the 10k usa male names and prepended numbers upto 4 digits and then I used this rule with hashcat. || ||hashcat -a 6 -m 0 hash.txt num-pre_a1.txt ?s || Can someone correct where I might be going wrong?

frail nacelle
old pond
frail nacelle
old pond
#

cc pentesting room task 4 gobuster dir -u http://10.10.173.33 -w /usr/share/wordlists/dirb/common.txt -t 64

Gobuster v3.0.1
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@FireFart)

[+] Url: http://10.10.173.33
[+] Threads: 64
[+] Wordlist: /usr/share/wordlists/dirb/common.txt
[+] Status codes: 200,204,301,302,307,401,403
[+] User Agent: gobuster/3.0.1
[+] Timeout: 10s

2021/01/22 12:46:51 Starting gobuster

/.hta (Status: 403)
/.htaccess (Status: 403)
/.htpasswd (Status: 403)
/index.html (Status: 200)
/secret (Status: 301)
/server-status (Status: 403)

2021/01/22 12:47:22 Finished how can i find which of the above is a hidden directory??

ripe hedge
ripe hedge
#

Also the others aren't accessible

old pond
#

After using the gobuster tool ..it's the output which i have came across ..but how can i find which of the following are hidden??

ripe hedge
#

It's not hidden on the Linux sense

old pond
#

The only fact that i know was that they are started with a dot in linux distros..

ripe hedge
#

It's hidden in the "I don't want you to find this" sense

old pond
#

But what if i have to find them for a webiste.... should i directly visit the website and inspect stuff??

ripe hedge
#

Why not try?

old pond
#

i gave it a try....but i can't find more than one directory while inspection in website
...from them

#

But the ans in the room is for a single directory..

ripe hedge
#

It's in your scan

old pond
#

I can't find both secret and .hta directories in the website directly which are in the scan ....then how can i confirm that which one is going to be an answer??

ripe hedge
#

.hta isnt accessible

#

Secret might not have a listing

candid nimbus
candid nimbus
# wicked bolt I think they need to update that room, its such a strange rabbit hole with that ...

I'm looking positive and saying there was merit in getting me to question the dataset I was using, but it was at the expense of trying everything else! Bit weird having the place that doesn't seem to show up elsewhere. I'm more concerned that, given the hint the idea was to demonstrate using a certain tool, which I doubt anyone has done to crack it and is certainly far from the best thing to use in this case.

prisma blade
#

Dear can I get a hint for windows event log room last task question 8 I have found the event is but when I answer ther group sec id it says wrong

median compass
#

have you ||looked at your sudo rights||?

ashen scaffold
#

@river path or run linPEAS

gilded latch
#

nevermind, got it

eager saffron
#

Can some one help me set METAsploit module for Game Zone room ?

#

Or hint maybe ?

spark abyss
#

Can anyone help me with the theseus room? I found the query string and the xss vulnerability but I don't know how to exploit it...

acoustic steppe
eager saffron
#

after run I get

#

[-] Exploit failed: An exploitation error occurred.
[*] Exploit completed, but no session was created.

acoustic steppe
#

Have u set all the options correctly then it should work

eager saffron
#

I set them as the pictures shows

#

or maybe I need to set Proxies http:localhost:10000

#

?/

#

I try with that and these didint work eather

acoustic steppe
#

I assumed that u have set ur LHOST and LPORT

eager saffron
#

nope

#

...

#

yaiks

acoustic steppe
#

I think it should be setup

eager saffron
#

but there is no options for that in that webmin module

mossy ermine
#

Hi everyone, I would really appreciate a quick hint on Looking-Glass. I am at the humptydumpty user, I have to further escalate. I tried some enumeration scripts such as LinEnum and Linpeas. I haven't been able to find any vulnerability or password exposure. Many Thanks

trim haven
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
mossy ermine
stiff jolt
frail nacelle
meager turret
#

need some help in

#

cth level 2

ripe hedge
#

which one?

frail nacelle
#

i need hint on the stuxctf room, i found in the ||robots.txt|| a directory but is not accessible, and in the code source of the page i found those numbers, i tried what the hints said, but i couldn't find any hidden directory, do i have to crack it in a certain way or what ?

prisma blade
#

Can someone help with windows event log

ashen scaffold
#

@eager saffron If you are still stuck, try looking at payloads

eager saffron
#

@ashen scaffold I will tommorow. Thanks for hints

urban tiger
#

Hello. I'm doing the daily bugle room. I have managed to get a reverse shell using joomla and running a custom php file. But I don't have a lot of access and can't even get the user flag. I'm a little bit lost of what to do now, I have looked at the cron files, checked for something unusual running, looked at files all over the system, and I still don't have any idea of what to do next. Tried running linpeas too but it gets stuck at installed compilers.

What can you do in this kind of situation ? Any tips?

onyx sparrow
#

may I know what do you get running linpeas?

urban tiger
onyx sparrow
#

It seems bit buggy, could i dm you to help?

urban tiger
#

Sure!

prisma gull
#

google where the passwords are stored in joomla

urban tiger
#

Alright. Thanks for the tip Anish. I have already finished the room.

#

Once again, thank you @onyx sparrow for your time

woven stump
#

hi. anyone know what is login creds for splunk OVA???

eager vale
#

Same here. On Advice 1 - Using the top1000 usa english male names list, I tried appending/prepending nums-symbols (1 to 3 times). Also a combination of appending and prepending 1-2 nums/symbols. I tried combining more than 3 num-symbols as well, however, I can't get any openCL version of MD5 working in either John or Hashcat on my osX machine to speed up the cracking process. Any ideas?

candid nimbus
#

You can --fork to share the workload providing you have suffi cient cpus allocated. You will need to try more variables than you have, though.

eager vale
#

Gotcha! Yep, I tried fork=16, but got discouraged when ETA was >1h and I thought I had to be doing something wrong if I did not crack it within 5 mins. Thank you!

ripe hedge
#

Generally use fork==number of cpus

karmic oasis
#

Oh ok, I know this sounds wier,d but on room 2, what ip am I supposed to ocpy

#

copy

silver otter
#

which room specifically is it called @karmic oasis? and what is the question

#

its not weird to need help when you are starting out by the way, no one is born with this knowledge

karmic oasis
#

Oh ok thanks

#

It's the second room

#

where you're supposed to copy and paste an ip

silver otter
#

can you screen shot what you are looking at maybe?

#

(I didn't follow any path or anything on try hack me so my second room might not be what you did, and searching for room 2 shows me a few options)

eager saffron
#

@ashen scaffold @acoustic steppe
Hey Just wanna let you know, that your hints helped me.
What I need to do, was to list available payloads, use one of them, and I need to set RHOST to my localhosts because of the firewall rule on the target. Thanks

slate turtle
#

Hello fellow hackers
John the ripper room task 8 question 2 I am stuck for some days now at 96% wondering if anyone could point me in the right direction
In my mind it's --rule=A-Z or a combination of but nothings working any hints appreciatedย  thankyou

candid nimbus
#

If you look in the text it explains how to format a rule for john. You need to use 2 letters which mean "put it at the end" and then format your regex using quotes and brackets like in the example

fossil cosmos
#

and forget about including "--rule" in the answer

slate turtle
#

Successful thankyou

#

I can now sleep soundly at night once more

fossil cosmos
#

guys. crack the hash level 2, task 6 ,n1 advice . I downloaded the male-names directory and added some custom rules, still cant find the password. I Am tired of trying, i have been trying for 3 days, still cant find the first question. What am i doing wrong? Custom rule: ||A0"[0-9]"Az"[0-9]"
A0"[0-9]"Az"[^&()+-={}|[];':,/<>?~*]" A0"[^&()+-={}|[]\;':,/<>?~*]"Az"[0-9]" A0"[^&()_+\-={}|\[\]\\;':,/\<\>?~]"Az"[^&()_+-={}|[]\;':,/<>?~]"
A0"[0-9][0-9]"Az"[0-9][0-9]"
A0"[0-9][0-9]"Az"[0-9][^&()+-={}|[];':,/<>?~*]" A0"[0-9][0-9]"Az"[^&()+-={}|[]\;':,/<>?~*][0-9]" A0"[0-9][0-9]"Az"[^&()_+\-={}|\[\]\\;':,/\<\>?~][^&()_+-={}|[]\;':,/<>?~]"
A0"[0-9][^&()+-={}|[];':,/<>?~*]"Az"[0-9][0-9]" A0"[0-9][^&()+-={}|[]\;':,/<>?~*]"Az"[0-9][^&()_+\-={}|\[\]\\;':,/\<\>?~]" A0"[0-9][^&()_+-={}|[]\;':,/<>?~][0-9]"Az"[^&()+-={}|[];':,/<>?~*][0-9][^&()+-={}|[]\;':,/<>?~*]"||. Do i need to add more options?

wintry yarrow
#

@fossil cosmos please ask in one channel only. ๐Ÿ™‚

fossil cosmos
#

if you ever answer, maybe i will

wintry yarrow
#

Be patient. Someone may help you when they can. So, please post in one channel only. :)

fossil cosmos
#

sure man, thanks for the reply. At least someone have replied

#

lol

candid nimbus
fossil cosmos
#

Thanks man, really appreciate it

zinc tinsel
vivid scaffold
#

hi guys, i'm doing the room "the market place" and i found a ||sqli i discovered it manually and wanted to exploit it quick with sqlmap but he can't find the vuln is there any options that will make the tool check better ?
i have a url like "<IP>/admin?user=2" then i use sqlmap
sqlmap -u "http://<IP>/admin?user=2"
but it says "GET parameter 'user' does not seem to be injectable"||

ripe hedge
#

Probably because it's not an sqli

#

Have you tried a different user id

woven mirage
#

but now that you found it yourself why not try to do it manually? It's a nice exercise to learn to do things without using tools ๐Ÿ˜‰

vivid scaffold
#

thnx for the hints guys

gusty kite
#

anyone had luck with sustah room yet

stuck fractal
#

@gusty kite that's still under hints embargo

#

72 hours from release, no help or hints until that passes

gusty kite
#

just curious about if people had luck with it.

stuck fractal
#

Don't.

#

Wait 72 hours from release.

gusty kite
#

I think you misunderstand my intentions but no problem.

astral mural
#

is this the room for stupid questions lie why is my progress not showing on the "complete beginner" page

quiet stump
#

It's for hints on rooms, so if you're stuck on a room an you need a hint or nudge ask in here.

astral lance
#

So I'm in webappsec 101 and I'm tryna find the name of a logged in user. I'm using burp suit and through in a wordlist as the payload, and using battering ram as the attack on intruder, however it says every single name on the list is correct or has worked indicated by a 200 code

#

I'm confused at what I'm doing wrong here

stuck fractal
#

Not application related

#

Wrong passwords etc aren't a HTTP error

astral lance
#

Ohh so 200 just means the webpage loaded successfully

stuck fractal
#

200 is just OK

#

200 doesn't mean anything loaded or whatever

#

It just means nothing HTTP errored out

astral lance
#

Oh. So any hint as to going about finding usernames? Keep learning burpsuite or start using hydra? @stuck fractal

stuck fractal
#

I don't remember how to do it

astral lance
#

well i would assume theres more than one way to do it

astral lance
#

can u mimick a burpsuite pitchfork attack on hydra?

white salmon
iron sapphire
#

For crack the hash, can anyone confirm whether I'm just using the wrong wordlist.....

#

i'm trying both the SecList 'malenames-usa-top1000.txt'

#

and the male-names wordlist using wordlistctl

#

but no joy after 2 days of trying across john and hashcat..... :/

onyx sparrow
#

what task?

iron sapphire
#

Advice 1, border mutation

#

I dont want a hint on the ruleset

#

I've generated a hashcat rule file that was 112gb

#

Just want to make sure its not a stupid move on the other end of the rule spectrum

iron sapphire
#

fyi here is my john-local.conf which is why i swapped to hashcat, it starts to get a bit heavy and hashcat is ALOT faster

#

||lAz"[0-9?!$@#%?.:^&()+-={}|[];',/<>~*]" lAz"[0-9?!$@#%?.:^&()+_-={}|\[\]\;',/<>~*][0-9?!$@#%?.:^&()+-={}|[];',/<>~*]" lA0"[0-9?!$@#%?.:^&()+_-={}|\[\]\;',/<>~]"
lA0"[0-9?!$@#%?.:^&()+_-={}|[];',/<>~*][0-9?!$@#%?.:^&()+_-={}|\[\]\;',/<>~
]"
lA0"[0-9?!$@#%?.:^&()+-={}|[];',/<>~*]"lAz"[0-9?!$@#%?.:^&()+_-={}|\[\]\;',/<>~*][0-9?!$@#%?.:^&()+-={}|[];',/<>~*][0-9?!$@#%?.:^&()+_-={}|\[\]\;',/<>~]"
lA0"[0-9?!$@#%?.:^&()+_-={}|[];',/<>~*][0-9?!$@#%?.:^&()+_-={}|\[\]\;',/<>~
]"lAz"[0-9?!$@#%?.:^&()+_-={}|[];',/<>~*][0-9?!$@#%?.:^&()+_-={}|\[\]\;',/<>~*]||

still fern
#

can i get a hint on sustah room for task one

wintry yarrow
still fern
#

ok

agile halo
#

in the ZTH: Web 2 Room Task 11, in Seciton 3 API Bypass. Is the solution really to ||fuzz for the flag.txt or is there another way to find it through, you know, an API bypass||?

candid nimbus
agile halo
white salmon
#

go for fuzzing

digital bolt
#

Hi Guys, Looking for hint for Crack the Hash 2 room. Task 6 Advice 3. Got the towns list from ||wordlistctl||, removed spaces,all lowercase, used the default jtr l33t rule,also used l33t rule from ||/usr/share/john/korelogic.conf||, still no luck. Anything else which i can try ?

candid nimbus
#

Another list? Seriously try ||cities|| or it will drive you nuts

digital bolt
digital bolt
#

And it worked! Thanks @candid nimbus . Only Advice 1 and 2 remaining. now. Also tried few things there also but no luck. Any hints there as well? Does the combination here means - for e.g. name is Ram, so possible combinations are 1%Ram,Ram1%,1%Ram1% ?

novel bay
#

Sorry guys i am having this problem

#

idk if it's a problem of john or what

white salmon
#

Heellooo, is there anyone who escalated to system in alfred room without using metasploit

opal vine
#

can i have a hint for break out of the cage room i literally didn't solve any flags
i have subdirectories and a file called dad_tasks
what should i be thinking of?

#

dad_tasks seems to be encrypted but i dont know what type of encryption is that

near shoal
#

did you do anything to dad_tasks yet?

opal vine
#

i think its base64, i tried to decode but nothing appears to be readable

near shoal
#

you're on the right path...

#

try harder

#

this might help you

opal vine
glacial gust
#

there are sites that will try to guess if you don't have the key

near shoal
#

how indeed. ... boxentriq kinda tries

glacial gust
old pond
#

cc pentesting room : while working on john the ripper...i referred the man page all the flags are documented as single dash(as Unix options) but the answers while completing the task are precceded with doubled dashed as gnu long options and while implementation too it's working as double dashed ....can i know what's wrong with the man page.??

midnight spindle
#

Hey guys, I'm on the sustah room and I try to find the number for the spin. I create a python script but the request is really long and the number can be|| 9999( if you see the * and the script code )|| , I'm on the good way and I have to be patient or I do something wrong ? ๐Ÿ™‚ thanks !!!

silver otter
#

no hints for that room yet I don't think, not until it's been out for 72 hours

midnight spindle
#

oh I though I can ask for hint and not for help ๐Ÿ™‚

hexed crescent
midnight spindle
#

ok ok or I will try harder ๐Ÿ˜‰

white salmon
undone hull
#

Hey, Im stuck on the Jenkins/Batman room - got everything working with the msf console reverse-shell - just can't get meterpreter to stabilize it keeps dropping any info on this?

hexed crescent
undone hull
#

c'mon man, i was waiting for a response. I didn't see anyone active.

hexed crescent
#

Just be patient. It's a virtue.

undone hull
#

Man, ive been trying this for 3 hours on THM - i'm very close and i'm not exactly sure whats going on?

digital bolt
# candid nimbus Spot on

Hello again: Tried these rules ||Az"[0-9]"Az"[!$@#%.^&()+-={}|[]\;':,/<>?~*]" Az"[!$@#%.^&()_+\-={}|\[\]\\;':,/\<\>?~*]"Az"[0-9]"
A0"[0-9]"A0"[!$@#%.^&()
+-={}|[]\;':,/<>?~*]" A0"[!$@#%.^&()_+\-={}|\[\]\\;':,/\<\>?~]"A0"[0-9]"
A0"[0-9][!$@#%.^&()_+-={}|[]\;':,/<>?~*]"AZ"[0-9][!$@#%.^&()_+\-={}|\[\]\\;':,/\<\>?~
]"
A0"[0-9][!$@#%.^&()+-={}|[]\;':,/<>?~*]"AZ"[!$@#%.^&()_+\-={}|\[\]\\;':,/\<\>?~*][0-9]"
A0"[!$@#%.^&()
+-={}|[]\;':,/<>?~*][0-9]"AZ"[0-9][!$@#%.^&()_+\-={}|\[\]\\;':,/\<\>?~]"
A0"[!$@#%.^&()_+-={}|[]\;':,/<>?~*][0-9]"AZ"[!$@#%.^&()_+\-={}|\[\]\\;':,/\<\>?~
][0-9]"|| . Still not able to get it. Not able to figure out what is missing. Any other suggestion ?

candid nimbus
#

Yup, you need to || app/pre pend 3-5 variables. Don't worry about having the numbers separate, just put 0-9 in with the special characters and use that as 1 variable. If that is eating up too much time, you can slim down on the special characters. The top row of a standard US/UK keyboard should be enough||

rose cape
#

could someone spare me a hint on owning root on overpass 3? having trouble finding my vector. a hint or kryptic nudge would be appreciated. im on ||james||

stuck fractal
#

Because if you got to James, you found something and LinPEAS should have shouted at you

rose cape
#

thanks james ill double check

opal vine
white salmon
#

you give it a known chunk and it will continue the work for you

stuck fractal
#

Huh, that's good to know seeing as I spoke to the creator about the theory behind that. That's awesome.

white salmon
#

at least it will make things easier

stuck fractal
#

Yeah, the specific example it was built around was SSH key headers which tend to have fixed starting characters in base64

white salmon
#

i tried that but used to use 10 chars to get my keyword

ripe hedge
#

it's a new room, so no

#

wait a few days

#

or keep trying

white salmon
#

No hints or help are allowed for new rooms till 72 hours passes.

winged ledge
#

Hello! Has anyone completed the NIS Linux part I room?

white salmon
winged ledge
ashen helm
#

Hi, any hint for Cyborg?

white salmon
ashen helm
white salmon
clear swift
#

hi, one question about gatekeeper room. When doing the bof I used my own machine (win 7 32 bits) to test it out but I have missing dll errors in there, did someone have the same problem?

trim haven
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

trim haven
#

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.
This statement ^

twin heron
#

it says the room is 24 days old

ripe hedge
#

it was released yesterday

trim haven
twin heron
#

Oh ok sorry

trim haven
ripe hedge
#

the room age is from creation and includes creation and review time

#

if it's on that list, it's off limits

twin heron
#

Oh I got it thank, sorry again

trim haven
ripe hedge
#

in any case, just try harder ๐Ÿ˜›

#

do some research based on what you find

clear swift
#

i did research trying to install those dll the whole morning

#

i just want to ask if im in the good path or wasting time

twin heron
clear swift
#

oh sorry then

#

i thought it was to me

ripe hedge
#

sorry, haven't done gatekeeper afair

pearl fractal
#

Room: owasptop10
Link: https://tryhackme.com/room/owasptop10
Task: 16
Exploiting and accessing the machine was out of the scope for the task. However, after doing so I found a user.txt file which contains a numeric value. Is it some kind of an easter egg and can that value mean anything?

dull depot
#

Can someone give me a hint for Overpass3, how do I get access over the james account as paradox?

trim haven
#

Have you tried ||linpeas||

dull depot
#

yeah

#

Maybe I overlooked something though

ripe hedge
#

probably, it'll be in bright red

inland marsh
#

hey can anyone give me a hint for Cyborg room
how to gain access to the machine, i tried to find but i cannot understand
i even got a hash and i crcked it but i dont know where to use it

glacial gust
inland marsh
#

ok

dull depot
#

I think I found the right PE vector, ||but I somehow can't just mount the nfs-share, is this my error?||
||I used:sudo mount -t nfs <machine_ip>:/home/james /tmp/pe||

stuck fractal
#

Look at the open ports on the machine

#

You can't talk to the service

#

Therefore you can't do that like that

dull depot
#

Ok thanks I didn't think abou that

ripe hedge
#

you're on the right track

slim pivot
#

Room: https://tryhackme.com/room/physicalsecurityintro
Task: Task 6 Hardware Bypassing
I can't find an answer for 2 questions in aforementioned videos. Any hints where can I find the answer?

The said questions:
An improperly hung door which opens away from you can be bypassed using this type of tool? (the second one)
Adams Rite hardware fixtures are susceptible to a bypass where a wire is snaked through the keyway and actuates the locking mechanism behind it, what could prevent this bypass?

stuck fractal
#

An improperly hung door which opens away from you can be bypassed using this type of tool? (the second one) is 100% answerable with google

#

The other is a pain to find

ripe hedge
#

it's in the video, but not quite by the same name

#

the other you can guess at it a bit if you think about it

coarse hornet
#

I need help with the tunnel in the unbaked foot machine, can someone help me?

trim haven
#

Which?

coarse hornet
#

Unbaked pie

#

I do the commands well with ||chisel|| and it doesn't work

slim pivot
#

The problem is there are so many answers that would be also possible, I cant find the proper one (the first question)
The answer to the second would be just welding a wall so noone can just get to the locking mechanism

livid birch
#

I am lost in my last answer in room Sysmon, Qustions: What C2 is the adversary utilizing in Investigation 4? - any idea?

ripe hedge
#

the first one is in Deviant's video

#

@slim pivot a wall, like maybe a shield?

slim pivot
#

ooooh, got it

#

thanks ๐Ÿ˜„

ripe hedge
#

you basically had it

#

the wording makes sense as an anglophone

#

but you have to be in that mindset

slim pivot
#

english is not my first language. It is sometimes hard for me to find synonyms

ripe hedge
#

yeah

#

it's not a super commonly used word

slim pivot
#

about the remaining question - is it conneccted to thin cards that you put between door and frame?

ripe hedge
#

that's one way

#

those are called shims

slim pivot
#

yeah, this one I got right

#

oh, so shim and cards is the same ๐Ÿ˜›

slim pivot
#

is it about this funny thumb-turn handle?

livid birch
#

:/ i am lost on my last case in Sysmon room :/

#

ah i found it

stuck fractal
#

Please don't ask the same question across multiple channels like that

glacial gust
#

please wait 72 hours from room release to ask for hints

stuck fractal
split steeple
#

Room Vulnversity, Task 5, Q1. "Search system for all SUID files. What file stands out?"

A pointer as to what I'm looking for here? Goal is to privesc

balmy wedge
#

@split steeple Did you run the command from the hint?

#

It's a find command that searches for suid files

split steeple
balmy wedge
#

a bunch of errors?

split steeple
#

Just permission denied.

balmy wedge
#

try adding "2>/dev/null" to the end of it and try again

#

should narrow it down

#

that is basically taking all errors and thorwing them in null uinstead of dumping them on screen.

split steeple
#

So permission denied counts as an error?

balmy wedge
#

yes

#

you tack that command on the end and it will not show those

#

they are garbage

#

@split steeple You get it?

split steeple
balmy wedge
#

@split steeple I'm glad it helped!

terse ginkgo
#

Im hella stuck on the last 2 questions of Windows Event Logs room. I don't understand xml queries well enough to find where "net1.exe" is in the "merged" event logs

#

They are litteraly the last 2 questions I have in the Cyber Defense path

gusty kite
neat cosmos
#

in blue right now and metapolit just worked before and now it says exploit completed but no sessions

#

what should i do??

stuck fractal
#

screenshot

neat cosmos
#

i used the exact same commands to set the hosts and i got it to work before

stuck fractal
#

show options and screenshot

#

Did you disable your firewall?

#

Or explicitly allow 4444?

neat cosmos
#

yeah i got rid of firewall

solid patrol
#

wrong LHOST ,LHOST = your vpn ip

neat cosmos
#

fixed that but still getting same issues

solemn smelt
#

show options and screenshot

neat cosmos
solemn smelt
#

Is it failing or is it saying no session created

#

You may also just need to reboot the box

neat cosmos
#

no session created only

#

i reboot box twice already

solemn smelt
#

I wonder if itโ€™s that shell

#

Try with the default shell it gives you when you select the exploit

neat cosmos
#

whats the default

#

i set it to the other one so many times its no longer default

steady stratus
#

I'm taking a look now at this (:

pearl fractal
#

Okay๐Ÿ˜ƒ

steady stratus
#

I can't see anything that would require the value of that file -- however it does make me question the reason as to why it's there to some degree

elfin ether
#

are thair any voice chat rooms?

steady stratus
#

I'd personally say you're safe unless the questions ask for it. However the OWASP 10 event is on my ever-growing list of things to revisit and fix a few minor bugs that we discovered during the event -- I suppose that could be one of them!

steady stratus
#

Yes -- quite a few @elfin ether but you have to synchronise your THM account with your Discord to access them

#

!docs verify

proud scarabBOT
steady stratus
#

weill get you started ^

pearl fractal
#

I was expecting it to be a THM subscription voucher๐Ÿคฃ

steady stratus
#

It's very possible it was whilst the event was running (: I know there's a few so apart of that "updating the room" will be removing the remnants of them as they're obviously claimed by now

#

But aye yeah -- I can't see anything that's asking for anything like a user flag -- but I guess keep a note of it just in case? ๐Ÿ˜„

pearl fractal
elfin ether
#

CMNatic arer you busy

pearl fractal
steady stratus
#

I'm about to head off for the night -- well day as it's 7AM but I'll be around for a few more minutes @elfin ether

steady stratus
#

I've jotted that down

#

All the more reason to bump that one up the list

#

Thanks for letting me know!

elfin ether
#

@steady stratus should i do the moduals befor doing the 25 day corse

steady stratus
#

25 day course? As in something such as Advent of Cyber?

elfin ether
#

idk where to start

#

should i do the 25 days of cyber security fist or do somthing else im new to this stuff but i wanna learn

steady stratus
#

Ah okies, I appreciate that. In my personal experience I've found events such as OWASP 10 and AoC2 to be incredibly useful if you're new to infosec (AoC2 was designed specifically just for that)

#

However, there's modules such as the linux fundamentals that I'd recommend checking out to cover the foundations of those (although they're quite over whelming)

#

we have this blog post to hopefully maybe get you pointed in the right direction

#

!docs free-path

proud scarabBOT
worn meteor
#

In Cyborg room.....I ran hashcat for the password which was obtained and its running for a really long time....i guess i went on wrong way of approach...there are no writeups for that room...so....any hints??

steady stratus
#

but imho AoC2 was purely built to be super introducable in getting you started in cyber security @elfin ether

elfin ether
#

AoC2 where is that

steady stratus
#

Teaches you enough to get you going -- but leaves you the opportunity to research further more on your own or look at other content on the site

steady stratus
#

Especially as every day has a full walkthrough video for the topic as well!

#

So you've got a lot of well detailed information in the tasks - and if you're stuck - an in-depth video to help you out (and then finally a great community here)

elfin ether
#

ok thank you

worn meteor
#

@proven bridge pls do writeup or any hints for Cyborg

trim haven
#

@worn meteor please respect rule 13

#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

kind bear
#

hey i am in room cyborg and i am user **** and i figured out that there is one file that can make me root but how do i edit that file ?

ripe hedge
#

see rule 13 just above

hollow arch
kind bear
#

i mean i own that file still i am not able to edit it ?

#

or it is also part of that box ?

elfin ether
#

how do i create a file called noot im confused on that how do i creat a file in genral so i can note it down

#

im on Linux Fundamentals Part 1 part 9

trim haven
kind bear
#

so it is the part of that box ?

trim haven
#

I donโ€™t like repeating myself.

#

No hints.

kind bear
#

lol no need

#

i got it

mossy ermine
#

Guys, in "The Marketplace" I am stuck at the sqli step. I 've ||found a way to gain access to the admin panel using xss to steal Michael's jwt, and also the sqli vulnerable point. However, using burp intruder or sqlmap, after some payload the cookie stops working and I get a 403(Forbidden) error. It also happens when I try to exploit it manually.|| Any little hint to solve this problem?

wary lark
#

Any nudges for sustah?

trim haven
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
ripe hedge
wary lark
#

Foothold. I know I need to write a script to fuzz the input, but I don't know enough scripting to be able to do that.

ripe hedge
#

which port, 8085?

wary lark
#

yes

ripe hedge
#

I've found the python requests library helpful

#

you could probably do it with curl though

#

gotta learn basic scripting though

wary lark
#

ok I'll read up on it, probably a good excuse to learn some python

ripe hedge
#

I mean the base will be a for loop

#

I had 27 lines of code, but I had an input for the target ip

#

and I used concurrency to go faster

eager saffron
#

Need a hint in Cyborg room, I found BORG files and crack hash for music archive, what should I do next ?

ripe hedge
#

I think rule 13 still applies

random gorge
#

@ripe hedge i ask @wicked bolt for help me and he report me!

ripe hedge
#

take it up with the mods

proven bridge
#

Ping me when you reply

balmy wedge
#

Writeups for Cyborg will be approved about a week after it's been out.

#

I have one personally submitted but the creator doesn't want them shown yet.

trim haven
#

Writeups have been accepted already..

balmy wedge
#

I'm just telling you what he messaged me after I submitted.

trim haven
#

Please do not send unofficial writeups :)

opal vine
#

can i ask for a hint for cyborg room?

cedar axle
#

has it been 72 hours?

opal vine
#

idk that's y im asking

astral smelt
#

72 hours is up tomorrow at 7PM GMT

pine sorrel
#

is there a way to tell when a room was released, the age of the room isn't necessarily relevant to release. Do we just go off the announcements channel?

spark prairie
#

Hello everyone, i am pretty stuck on a easy task that's driving me mad: Juice shop room, Question #2: Log into MC SafeSearch's account! the password is there to be seen and i am strugling to log in. It seems i am doing something wrong! i tried various combination but at this point i fear something is wrong with the account

#

can someone help?

hollow arch
trim haven
#

A minor update for the Cyborg room
As writeups have been accepted, hints are allowed to be given out (Muirland Approved).
Please do not ask for spoilers, only nudges, if you do see someone asking for spoilers rather than hints, please inform a moderator.

#

@opal vine Your question is allowed, go ahead :)

opal vine
random gorge
#

@trim haven can you give me spoiler for cyborg room?

stuck fractal
#

-mute @random gorge 20m You were explicitly told not to, after being warned for asking for answers.

green minnowBOT
#

๐Ÿ”‡ Muted ZimE#4506 for 20 minutes

stuck fractal
#

ยฏ\_(ใƒ„)_/ยฏ

trim haven
#

Thanks James

stuck fractal
#

There's an argument you're missing

#

One that is required for bash/sh to not drop suid permissions

#

Just... Kinda... Add them?

balmy wedge
#

Hey all, I have been stuck on Intro to x8664 for about 3 days. Task 4 Question 1 "What is the value of var_8h before the popq and ret instructions?" ||I have tried 63, 60 things related to c because of the hex conversion|| but nothing seems to work. I have been back through the previous tasks 5 times now and it's just not clicking for me.

#

I am using the ds, dr, dc, db, pdf @main, and px commands to search for it but it's not working so far.

umbral umbra
balmy wedge
#

I literally just got it after I posted lmao. it always works that way. Sometimes wording the question makes it click for me.

#

@umbral umbra Thanks a ton though!

#

It was also confusing because it doesn't change from ||63 to 60|| until right before the instructions.

umbral umbra
#

Yep. Usually when I get stuck, as soon as I tell my manager(s) that I'm stuck, I find the solution. Articulation seems to be the key to unlocking it

balmy wedge
#

Sounds good, again, thank you!

split steeple
#

Worked on this for a day now. Vulnversity room, final question. Privesc'ing by using ||systemctl||. I'm following some write-ups, but when I'm launching the very final command ||(/bin/systemctl enable โ€”now $myEnvVariable)|| I get Permission Denied. Why?

split steeple
scarlet drift
#

are there different versions of the Pickle Rick box? I noticed the write-ups show that you can immediately connect to a web page on port 80 and connect to the "Help Morty" page but my box only has a CyberChef page. Am I connecting to the wrong systems?

stuck fractal
#

You're using the IP of your AttackBox

#

The attackbox is the machine you control that you hack from

#

You need to use the IP of the machine under Active Machine Information. That's the target machine.

#

If you don't have that heading, you need to click the gree Deploy button with a cloud on it.

scarlet drift
#

ok I just hit the deploy button and that seems to fixed my issue. I'm waiting for an IP address to post

quaint vine
#

i try to scan 999 port of that ip address

#

but it doesn't work

#

=(((

#

Does anyone have any idea ? it's in the nmap class

neat cosmos
#

umm why is their a 0 in front of p

#

it needs to be -p- 999

fervent valley
#

Hi. I'm on the mr robot room, and the question is: why can't we spawn a valid tty shell with reverse shell with php, sh, etc. And ONLY with python?

#

I'm using the reverse shell cheatsheet

#

Sorry, not the reverse shell. Just spawning a shell, being already inside the machine

candid nimbus
spring tartan
#

could someone please give me a hint with the room Windows Event Logs Task 5 X-PATH queries

#

Task 5 Question 1

#

Get-WinEvent -LogName Application -FilterXPath '*/System/Provider[@Name="WLMS"]

#

i think is the first part but can't find the info about system time

#

Thanks

#

I know it needs to be concatenated with and , but i seem to be stuck on the next part about the system time

stuck fractal
ripe hedge
spring tartan
#

thanks

ripe hedge
#

cool

spring tartan
blazing thorn
#

Room: https://tryhackme.com/room/physicalsecurityintro
Task: 6
Question 5: An improperly hung door which opens away from you can be bypassed using this type of tool?
Any hints on this? Have been searching and searching but nothing. It's my last question on this room. Q4 is the same question but I have that answered.

pearl fractal
candid nimbus
blazing thorn
#

ty, got it ๐Ÿ‘

old pond
#

Web fundamentals room: Task 5 about curl.question 3 ...how can i get a cookie??...a little confusion with the flag ..need hint

stuck fractal
#

And the webserver will set a cookie for you.

old pond
stuck fractal
#

No.

#

You're getting given a cookie

#

You don't need to provide anything

fervent valley
hexed crescent
chilly wigeon
#

hello,everyone. the room SQL Injection Lab task 6 , my python script use string.printable test admin password ,but the third letter not found ,why?

midnight spindle
#

Hello guy , I'm on Jeff room and after gobuster the all dirs ! I found ||a zip file|| , I try with John but nothing at the moment. Any hint on that ? ๐Ÿ™‚

#

NVM^^

opal vine
#

hi
can someone help me pls ๐Ÿฅบ
im stuck at "year of the rabbit"

#

it just that rick rolled ๐Ÿ˜ซ

#

i turned off js but i dont know what to do next

white salmon
white salmon
tardy summit
#

has anyone tried hitman box.

#

linux agncy?

ripe hedge
#

no hints for 3 days

gusty kite
#

hmm I have a feeling that the real obstacles in this room are the hints and not the actual tasks at hand.

hexed crescent
#

The hints are definitely cryptic for sure. But that's okay.

gusty kite
#

well I am at one now that makes no sense to me so I think I am done for tonight.

opal vine
manic citrus
manic citrus
wicked bolt
white salmon
wicked bolt
#

I have figured it out anyway

white salmon
ripe hedge
#

I got to sean but I can't find his flag yet

#

passwords don't seem to be working for the named users

jaunty kite
wicked bolt
#

getting jordan was fun!

#

i feel like if i give up half way through i'll have to do all this again ๐Ÿ˜†

manic citrus
#

trying to get to penelope now...... the clues are still giving me more of a head ache than the tasks

wicked bolt
hexed crescent
manic citrus
hexed crescent
#

How do you like the progression of the challenges in Linux Agency?

manic citrus
#

flows quite well

hexed crescent
#

Yeah, I thought it was very well done. Took me two days to test it all.

wicked bolt
#

jeez found sean's flag at least

#

not sure if intended way or not but /shrug

white salmon
manic citrus
wicked bolt
#

i've been copying bash and giving it SUID in the home folder +777 just in case my shells crash

manic citrus
#

I am starting to think penelope is really obvious but I am just too tired to see it

wicked bolt
#

hahaha yes i just found it

#

but no hints sorry

#

i would love to give the tiniest little hint ๐Ÿ˜ข

manic citrus
sinful crag
#

Forgive me again... Total newb here. I finished my first room in the beginner's path and I'm now in introductory researching, I don't need my attack box to be running do I?I

hexed crescent
#

Not in case there is no deployable VM attached to the room.

sinful crag
#

That's what I thought, my split screen disconnected and I wasn't able to follow along with the youtube video

#

Is there a reason this would happen or how I can remedy it, when it happens?

hexed crescent
#

When it disconnects, refresh the page, when in split-page mode.

#

In case you're not a subscriber, you only get a limited time on the AttackBox, one hour per day. As a subscriber, this access to AttackBox is unlimited.

wicked bolt
#

got to get my brain in gear for the user flag now! ๐Ÿ˜ฎ

cyan sage
#

What means EVS

#

In linux

hexed crescent
#

What would Obi Wan Kenobi say?

#

Use the Force!

stuck fractal
#

Did you research SSH key fingerprints?

wicked bolt
#

Uh-oh! You have had your machine deployed for too long. oops!

silk crystal
#

Hey guys ! , im finished the goldeneye CTF , but i have no clue about this question , i know there is a pop3 server on that port , but i dont know about another service running on that . Some ideas ?

stuck fractal
#

Ok, the question is misleading and needs to be re-written

#

It's actualyl asking for what program you use to interact with the pop3 server

silk crystal
stuck fractal
#

I don't know why you're apologising

#

The room needs changing

#

Your question was fine

silk crystal
#

Oh the problem is the question of the room ๐Ÿ˜‚

#

hahaha thanks ! yep it was that thanks a lot !

leaden quail
light phoenix
#

Anybody already did LinuxAgency room? Does anyone know if the flags retrieved in the privilege escalation segment work as user passwords or not?

cedar axle
#

nope

feral juniper
cedar axle
gusty kite
feral juniper
#

it's a vm

#

does that effect it?

cedar axle
#

bcrypt is deliberately slow

feral juniper
#

oh ok thanksss

tawny latch
#

Anyone doing Linux Agency?

cedar axle
#

done it, but 72 hours for hints

distant tartan
#

hello i am on Mnemonic last task i founs root.txt

#

but when i converted it into md5 and pasted it on thm it says wrong answer can any one tell what i am doing wrong

distant tartan
distant tartan
distant tartan
cedar axle
#

make sure there isn't a newline at the end or something silly

cedar axle
#

ok

ripe hedge
gusty kite
ripe hedge
#

haha

#

oh dear

#

silvio is one of the simpler ones

gusty kite
#

I would imagine. The hint just do not make any sense to me.

ripe hedge
#

the hint is obtuse but when you see the answer it makes a bit of sense

gusty kite
#

rest has been really simple

ripe hedge
#

they're not called Postal Codes in the US...

gusty kite
#

ahh

ripe hedge
#

mods are asleep, can give small hints.... ๐Ÿ˜‰

gusty kite
#

๐Ÿ™‚

warm spire
#

hi in linux agency i have found the flag for the user dalia but i cant switch user

ripe hedge
#

probably not using the right vector

ripe hedge
#

they make sense in a twisted sort of way, usually after you find the exploit

ripe hedge
#

gl

opal vine
#

i don't know if i can ask for this
but in linux agency i was stuck at finding the mission25 flag but eventually i found it
but how can i know if that was the right way to do it or not
can someone help me with this pls?

ripe hedge
#

the bribe?

#

Though tbf, if you got the flag it was the right way

opal vine
#

hope so
amma check when its ok asking for hints

gusty kite
white salmon
#

Need help with mission23 in Linux agency

ripe hedge
#

snakes?