#room-hints

1 messages · Page 83 of 1

topaz jasper
#

tyty

simple mountain
#

Do not provide or ask for help or hints for magician room until 24th Feb, 7pm (GMT).

candid nimbus
#

Well there's a : followed by a choice of true or false.

hallow coral
#

Hi all! Anybody passed cct2019?

wet pollen
white salmon
#

I just wanted to mention that magician room does not feel like an easy one, maybe tomorrow after some sleep it feels different

ashen scaffold
#

The foothold is something that will take more time to accomplish Im sure

narrow kettle
#

Someone just did Yara room? got somequestions

idle pebble
#

What questions do you have?

cedar axle
indigo bear
#

I'm a bit stuck in my Nmap series, I'm at task 14 3rd question (maybe I'm just too tired).
Is there a friendly soul who can give a hint (in dm) to where I need to go with this 🙂

idle pebble
#

Did you read the hint?

indigo bear
idle pebble
#

did you run nmap with that flag?

indigo bear
#

yea

#

Think carefully about which switches to use - is in the description of the task

idle pebble
#

Hmm, one second

#

@indigo bear check your dms

stuck fractal
#

Is it an approved writeup on the room yet? @hardy thorn

#

They are not reviewed by admins. They're reviewed by the room creators.

#

If it's not approved on the room, DO NOT post it here. Especially not in the hints channel.

daring relic
#

any nudge on Magician -- privesc?

remote gate
daring relic
#

I was able to complete the room ... no nudge needed

candid nimbus
# wet pollen for both same 😫

@wet pollen ok so the format is / followed by the short version of the command ( beginning with l, not i ) a colon : then true or false (true)

short bobcat
#

hey guys, im stuck in the magician machine where i didnt upload any png file

#

and even i add the hostname to the host file

acoustic steppe
short bobcat
#

no i didnt ... I tried it copule of times

simple mountain
#

Guys, stop talking about that machine. Check the pins.

wet pollen
candid nimbus
#

No problems, we've all done it

slow slate
simple mountain
#

Middle icon, right there

slow slate
simple mountain
simple mountain
#

Oh thats a shame 😦 Don't give up on the first hurdle. Solving challenges is what makes us grow and become better

slow slate
simple mountain
#

a month? The challenge was only released 2 or 3 days ago

slow slate
simple mountain
#

It's great that you are sticking with the site! If you want to be alerted when an announcement happens, pop into #bot-commands and type !notifyme

slow slate
simple mountain
#

We all feel like that - Theres always more to learn!

slow slate
stuck fractal
#

@rich shard No. That room is under strict hints embargo as per the pins

rich shard
stuck fractal
#

You are not allowed

rich shard
iron shadow
#

Hello, I need some help please. I'm doing the inferno room. I was able to get a shell but after a while my shell gets disconnected, my shell gets an exit from somewhere. I tried to prevent it with alias and trap command but I didn't succeed

storm venture
#

I believe that's deliberate

#

try set up some form of persistence

distant tartan
#

ROOm WIFi HACKING WHAT IF THE PASSWORD IS TO STRONG TO BE cracked by aircrack

rose cape
#

Then rip

distant tartan
stuck fractal
#

You crack it with hashcat

#

Cracking the password is 100% independent of what wifi card you use.

#

If the password is too strong, then you don't crack it. Same as regular hashes.

distant tartan
undone quail
#

In Linux Agency I'm having an issue finding the 4th flag. Can anyone point me in the right direction? The hint seems like it's referencing cat but the flag.txt says that it was stolen... I have searched quite a bit and went back as previous users to no avail.

candid nimbus
#

Don't believe it. Try not using cat

undone quail
#

ooooooof I have spent way too long on that lol. The hint was more accurate than I thought. Thank you! I have the dumb today apparently...

hexed crescent
undone quail
#

Will do! I've been breezing through but for some reason that clue did not register.

neat cosmos
#

for linux agency im so confused on what the password for room one is

#

it is the the whole thing as in mission1{1234567890} or only the part inside the {}

#

i tried both and im having trouble logging in

glacial gust
#

you need to su to the next user i.e. mission1 using the flag/password you found for the first part

neat cosmos
#

anddd it worked

#

thanks for the help i tried sshing using the username and every combination of the password and it didnt really work

fervent valley
#

Hi, I'm at the "overpass 2" room, and I wonder, how can I retrieve a function's parameter from debugging it

#

I can't upload an image, but I'm debugging an SSH backdoor, and it is handling some hash, a salt (Both are known to me), to compare with a password. But my RIP pointer is right now inside a function that uses this password, (func somefunction(hash, salt, password))

#

but since it's not in memory I can't acess this "password" as if it were a variable

neat cosmos
#

can i get hint for linux agency mission 12 please

#

i googles evs and didnt get too far with it

half berry
#

Task 9 Binary - Shiba1 from the Linux Fundamentals relies on being in the AttackBox right?

#

its telling me to run shiba1, im guessing thats in the attackbox

idle pebble
#

no, on the box

half berry
#

Oh I see, it gives me a little environment

#

Thanks

idle pebble
#

mhm

#

no problem 🙂

slender dawn
#

I have accessed the machine but cannot find a way to get root

#

a sudo exploit might work but I don't even have access to the sudo password

#

I have upgrade from the basic shell

idle pebble
#

linpeas might help you

slender dawn
#

ok

#

let me try

stuck fractal
dusty sun
#

hi

#

is there any problem with code upload the backup file on ftp but not working can someone help me in[Day 9] Networking Anyone can be Santa!

pure thistle
#

you don't ssh you need to su to the new users you only ssh as agent47

pure thistle
#

did you use the whole flag as the password? ie.. mission1{longhashvalue}

median compass
#

can you screenshot this?

pure thistle
#

idk works for me

median compass
#

and you're using the full mission1{} flag as password, and it was accepted in the room as correct?

#

what's the IP of your box?

#

no, the target

#

it's definitely working

pure thistle
median compass
#

never bothered to look for where it was coming from

#

no bash history

#

work away

#

still, it works, 100%, will you try it again?

pure thistle
#

no i was just thinking if .bash_history was no redirected to /dev/null check and see if he was typing it in right?

median compass
#

oh, no, it is -> /dev/null

pure thistle
#

oh well

median compass
#

wait a min

#

exactly what are you typing in for the password?

#

that flag is a free one, so it doens't matter if you post it here

#

only the hash?

#

not the WHOLE flag text?

#

but I asked you that

#

you need the FULL flag

#

including the mission1 part

#

and the {}

#

yeah

#

try again to be sure?

#

good stuff, good luck with the rest of it

opal vine
#

hi
guys i'm solving skynet room and i'm literally stuck at the first question , i have the wordlist i know i need to use hydra but squirrel mail keeps redirecting me so i can't use the F=error or S=Location in hydra

#

what should i do?

median compass
opal vine
#

||hydra -l miles -P /home/enigma/thm/skynet/logs/log1.txt 10.10.163.188 http-post-form "/squirrelmail/src/login.php:login_username=^USER^&secretkey=^PASS^:F=redirect" -IV||

#

here's the full command

median compass
#

maybe think of a different service you might be able to hydra

opal vine
#

oh

median compass
#

what mission# is that?

#

sorry, scratch that lol

#

misread

#

i haven't done that one I don't think, at least I don't seem to have notes for it

#

actually I have done it, must've been before I got in the note-taking habit

#

you got a message when you connected right?

#

or use burpsuite to intercept the request and make changes

pure thistle
opal vine
#

hydra outputs all the passwordss and says 16 passwords found

median compass
opal vine
#

as the hint says you need to change your user-agent and this might not work in firefox
try changing it using curl

pure thistle
#

you don't really need to use hydra but i normally use Login=Login:[faild_response_message]

median compass
opal vine
median compass
opal vine
median compass
#

did you get the right username? it's not miles

opal vine
#

i tried milesdyson

#

doesn't work

pure thistle
#

im on my cellphone so i dont have access at the moment to the room

median compass
#

and don't use the login.php link, what's the page called that the error message comes back on? watch the process in burpsuite

pure thistle
#

so I don't know what the error response is

#

but like i said you don't really need to use hydra

#

all you need is to cat the log1.txt file

median compass
opal vine
#

no
i didn't get lucky 😔

opal vine
median compass
#

hydra is the way

dusky shoal
#

morning all

#

I am having some slight troubles on easyCTF

#

I found ssh running on port 2222

#

I also found a user mike in robots.txt

#

I tried cracking his pass with seclists as the hint says, but no luck. So my thought is maybe its a different user

median compass
#

ok, that's Simple CTF, a link is always good when asking for help as sometimes the names in the URL don't match the proper name of the room

dusky shoal
#

How can I enumerate potential ssh users on port 2222 without enum4linux? I can code this if needed but i imagine there is a tool? or maybe I am going about it the wrong way?

median compass
#

so have you enumerated the rest of the box?

dusky shoal
#

when you say enumerated, you mean the shares with enum4linux?

median compass
#

no, I mean gone through all the ports, looked at web pages etc.

#

tried to find out what's running

#

bruteforcing should be last

dusky shoal
#

oh well I think so, let me elaborate and maybe you could just give me a hint to dig more or something vague

#

I have ran/ am still running dirb

#

lots of stuff mostly looking emtpy so far but I did find that user name

#

I looked for ports with nmap

median compass
#

where did you say you got your user name?

dusky shoal
#

/robots.txt

median compass
#

what did that contain?

dusky shoal
#

saw something saaying mike and I tried ssh into that, asked for password so that means real user I believe

#

The whole string at the top is interesting but I figured that just formatting

median compass
#

can you show that here?

dusky shoal
#

I also saw on nmap that ftp is open on port 21

median compass
#

ok, did you enumerate that?

dusky shoal
#

no not yet, I should tho now that I think about it haha

median compass
#

yup

dusky shoal
#

ok let me take some time and get back to you lol the other trouble is idk what CVE they want me to attack with, so I have been hoping maybe there is a hint along the road

#

for now ill find some ftp pentesting software

median compass
#

you can just use ftp, should be on your box already

#

do the ftp, then check the results of dirb and you'll find something in one of those - google that

#

good luck

dusky shoal
#

appreciate that thanks

long birch
#

is anyone else having trouble with the magician room

#

I know what to do but I cant upload anything

#

I intercepted with burpsuite and im apparently sending an option request

#

I even looked at writeups 😦

median compass
#

from the pins above:
"Esqy02/21/2021
Do not provide or ask for help or hints for magician room until 24th Feb, 7pm (GMT)."

long birch
#

its not hints

#

its broke

median compass
#

that room is still too new for us to help

#

then first redeploy

long birch
#

ok fair enough

#

lol ....

median compass
#

but I don't think it is, it's just a pain

long birch
#

i figured it out just listen anyway dont worry about the error lol

#

2>/dev/null am i right LOL

median compass
#

yes, it's possible that you'll see errors, from a part you don't care about though so its ok

slow slate
#

It's a bloody nightmare!

#

Reading the Splunk manual is more satisfying.

#

The magician reminds me of a room in the Overlook Hotel.

#

Any moment Jack Torrance can come through the door.

long birch
#

lol @slow slate

hallow coral
#

Hi all! Anybody can help me with task3 CCT2019 room?

shrewd raven
#

hey everyone

#

task

#

it is not working for me

shrewd raven
#

?

hallow coral
#

I am stuck on task 3 CCT2019 room. Already exhausted. I found the password to the hidden archive, where there was a file with the words of a famous character, but I can’t go any further. Tell me where to look next?

woven mirage
shrewd raven
#

👍

#

my bad

woven mirage
#

no worries

neat kraken
stuck fractal
#

@neat kraken please don't post the question across multiple channels like that

ripe hedge
#

405 generally means that the HTTP method you're trying isn't supported by the endpoint

#

ie trying to GET when it expects a POST

#

for example

stuck fractal
runic ore
#

hey everyone! I've been doing HackPark lately and it's been a while that I'm stuck at it's priv esc part. I'm running winPEAS.bat where I should be getting the running processes but it's output isn't covering all info neither is it covering abnormal services. Can anyone help?

grizzled elbow
#

Hi I wanted a small hint for tomghost

#

I found that there is websocket there

#

But don't know what to do next

ripe hedge
#

Where are you at in the room?

#

Lookup the ghostcat vulnerability

cedar rivet
#

A year after I joined and tried "inoculation" and failed I'm back, but the room is gone. Is there an ISOsomewhere or a config script for whatever the hell that machine was about? I'd like to try it :(

serene stag
#

need a help on room Windows Event Logs

#

one of the questions is: What are the total number of events if you filter on Event ID 4104?

#

if i filter it on event id it shows 133 events but it doesn't accept as answer

#

what's the catch ?

#

i also see that events on the machine are increasing, so how can i put the correct answer ?

ripe hedge
#

try omitting the events that you created

serene stag
#

i have ommited the events from when i logged to the machine and it says 169 but still doesn't accept as answer

pine reef
#

Is it possibile to get some help on Hacker of the Hill room? I am not sure because it is an ongoing competition. I am stuck in the hard challenge. Thanks in advance

dusky vigil
pine reef
#

Understandable

dusky shoal
#

Im having troubles finding the CVE the want me to use against the webapp for privelege escalation

#

Any hints on where to find it? Im already ssh'd in as mitch, and I logged into the site admin page also

astral smelt
dusky shoal
#

@astral smelt was there a hint throughout the challenege that would have told me that, or just something i should have had tucked away in my knowledg?

astral smelt
#

It's just researching, it's a part of hacking

dusky shoal
#

Lmao i found other CVEs but they didnt ask me for one the wanted a specific one 😭

#

Thanks for that one lol

granite mantle
#

hey i'm on this : Hacker of the Hill #1

Can someone help me ? 🤓

granite mantle
#

ohh 27/02 ok ok sorry 🙂

dusky shoal
#

@astral smelt its not exploitdb lol im just gonna check the write up

astral smelt
#

It is on explitdb

dusky shoal
#

damn I see now,

#

the CVE is the specific bug?

#

exploitdb looks for the CVE?

stuck fractal
#

CVE is for the vulnerability

#

ExploitDB is a collection of exploits

#

Exploits will target a vulnerability (Or I believe sometimes a chain of seperate vulns)

dusky shoal
#

mmm ok that makes more sense. I was thinking at first that the CVE was the program itself lol appreciate that clear up

rare dust
#

explaining what the CVE is, exploit-db is.

dusky shoal
#

@rare dust sweet, ill do that one next

woven mirage
#

Take a look at html source

opal vine
#

hi
guys i'm doing the juice shop room
but i'm stuck in task 7 question number 2
when i use burp i don't have the parameter True-Client-IP
how can i edit the paramater?

stuck fractal
#

Add it?

opal vine
#

i did but it didn't work

stuck fractal
#

What did you add, exactly?

opal vine
#

True-Client-IP=<iframe src="javascript:alert(xss)">

stuck fractal
#

I thought it was X-True-Client-IP?

#

And you used backticks rather than single quotes

#

I'd use single quotes because you're not templating

opal vine
#

oh amma try now

opal vine
midnight swallow
#

can anyone help me with a question on cmess

#

why doesnt the reverse shell show up when i go to that directory? but when i go to the directory/myshell it works?

prisma gull
#

can anyone give me nudge on Lunizz CTF

soft fossil
#

Yes.
Lunizz CTF

prisma gull
#

can i dm you

daring relic
#

on the Lunizz CTF --- is it normal to get root before user?

prisma gull
#

that is a ||rabbit hole||

proud needle
#

stuck in Lunizz place, any hint?

daring relic
#

I am on that box but stuck on user

#

||got root.txt but no user||

ripe hedge
#

There's normally an embargo on hints for new rooms

normal tusk
#

I would like to have a sanity check on Lunizz - can someone DM me please?

still coral
#

@normal tusk hi

#

We have stuck on place questions answer. Any help here

#

Anyhint on rooting lanizz CTF?

normal tusk
still coral
#

Got shell as www data.any nudge on getting user and root

fading osprey
#

@still coral hi could you please provide any hint.

normal tusk
#

The room is still under embargo (too new). No hints.

still coral
astral raptor
#

Got a shell too

distant tartan
#

i am on wifi hacking 101 task 2 i am not able to find last 3 answers i tried seeing aircrack-ng --help but i didnt got anything or is it there and i am not able to find it can i get a hint

stuck fractal
stuck fractal
astral raptor
#

Ok sry

distant tartan
stuck fractal
#

Try things

still coral
#

Lanniz?

stuck fractal
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

distant tartan
gusty kite
#

for the guys asking for Lunizz room

proud needle
#

anidab finally

distant tartan
#

ohh ok thanks

still coral
gusty kite
#

same. no hints allowed during embargo

still coral
#

And the room is 79 days old more than a month

still coral
gusty kite
#

lunizz room less than a day old

astral smelt
still coral
simple mountain
#

Do not provide or ask for help or hints for Lunizz room until 27th Feb, 7pm (GMT).

rough helm
#

Hello, I cannot find the answer for question 2 task 8 of the "nmap" room. I know why these scans are used but I can't find the answer in the form requested, Thanks.

astral smelt
#

It's in the last paragraph of the text

rough helm
#

Thanks, i was writing bypass.

split nymph
#

Hi! need some help please with Task4 (Exploiting SMB) of the Network Services Room

So, I manage to smb the machine, I get the id_rsa file to my local, change the permissions to 600 but then I can't understand what exactly I am required to do

stuck fractal
#

Use the key to authenticate to the remote machine using SSH

split nymph
#

thanks a lot @stuck fractal . Now I will research how to do that☺️

green pebble
#

Can I ask someone about archangel task 2 please? I understand what I need to do but I can't pull it off

onyx crescent
white salmon
#

I can't run commands, there must be a mysql column that controls command executer? anyone know this?

ripe hedge
#

Can't help for that room yet

white salmon
#

Okie sorry

balmy verge
#

When can I submit my write up vid for the lunizz ctf room ?

normal tusk
#

See pins: Do not provide or ask for help or hints for Lunizz room until 27th Feb, 7pm (GMT).

#

Guess writeup can be provided then.

stuck fractal
#

But submit it whenever

#

It's not displayed until it's approved by the creator.

tranquil vault
#

TIL: hydra on the command line without verbose output is ca. 3 times faster than the hydra X GUI with verbose logging 🙃 still, seeing "to do in 1806:33h" is a bad feeling and I don't know whether I'm on the correct path and should wait a bit or totally wrong direction, break it and look for some other way

late patio
#

how's everyone doing?

dusky shoal
#

I have just a couple quiestions

#
  1. I found the admin dir.. ip/admin.. but it just continuously reloads. Bug or part of the ctf?
#
  1. In one of the video clips, it mentions whoismrrobot.com. Is this site actually part of the ctf? Ive been over there for hours messin around, but key one I found using dirb
stuck fractal
#

Don't attack that site

dusky shoal
#

lol ok cause once that site led me to ecoin I was like man I should stop 😆

#

do you know if the /admin/index.html should be constanly glitcing/reloading? or is that a bug?

stuck fractal
#

I don't remember

gusty kite
#

I have no recollection of that happening. sounds like a glitch

dusky shoal
#

the hints seem to not make any sense lol or maybe im dumb

#

Hint2: White coloured font.. well on main page hella font is white lol

ripe hedge
#

select all?

dusky shoal
#

Hint3: check nmap.. but the ssh port is closed

dusky shoal
ripe hedge
#

yes

dusky shoal
#

idk what you mean by select all? lol my bad

ripe hedge
#

for the white text on white background

dusky shoal
#

hmmm white background

#

im sorry I am trying to remember where i have even seen one on this ctf lol its all black

#

let me go through all the commands again

#

I cannot access the admin page tho so if anything is there that will be tough lol but if thats part of the challenge, cool

wide grove
#

yo room: lunizzctfnd question: "
a folder shouldn't be.." I dont get this question

#

any help?

#

you know what , I found the solution, answer was right in front of me for 20 mins, just couldnt see it cause of the output format

stuck fractal
oblique cedar
#

Room: LFI Task 2 -- found the user's id_rsa file, and it appends it to the end of the webpage. Tried to copy the text into a blank file, and then chmod to 0600

#

based on what I'm finding on Google, it might be something with trying to copy & paste the key text?

stuck fractal
#

That isn't an error really, it shouldn't stop you from logging in

oblique cedar
#

I don't have a password though. I'm trying to use that id_rsa file for the login. Am I doing something dumb?

stuck fractal
#

I'll clarify. It shouldn't stop you using the key to log in, seeing as you can get that error and succeed the login with the key.

white salmon
#

Maybe try to crack with ssh2john

stuck fractal
#

Therefore the key isn't passphrase protected.

white salmon
#

Oh my bad

white owl
#

That message is just a warning. Usually it still lets you in. But you can check if there's extra line feed characters or something it doesn't like

oblique cedar
#

sorry, was doing lunch... yeah, it's not letting me in with that. How do I know if there are characters it doesn't like?

white owl
#

That's what the invalid format means. Maybe you just need to clean it up. Check it with xxd command to see the details

rough helm
#

Hello, im in the Network Services room task4 exploiting smb, i am on the server (question 4) but i don't know how to open the ./profile?. Can somebody help me? Thanks

stuck fractal
rough helm
#

How i am supposed to know "Who can we assume this profile folder belongs to?" ?

clear coral
#

Hi I need a hint for the magician room i know the exploit which to use but it doesn't seem to work

rough helm
#

Ok, thanks.

rough helm
#

I don't know how open file, i trying and searching how to do, but i can't open it?

stuck fractal
rough helm
#

@stuck fractal i find a way to open the file but i don't know if it's the way that the room was waiting for?

stuck fractal
#

You know, I have no idea what you're doing

#

So I can't tell you if what you're doing is right or not.

rough helm
#

I just use "get" and open the file on my linux, i don't open it using the server command

stuck fractal
#

That's fine

rough helm
#

But is there another way to open the folder?

stuck fractal
#

There's lots of ways to interact with an smb share.

#

smbclient is the one you're taught in the room, is it not?

deft prism
#

I’m in the Linux challenges box and I’m haven’t trouble trying to find flag 12 I’ve tried using the find command to find where the MOTD’s are stored and going into the folder but I haven’t found flag12

simple mountain
#

Do not provide or ask for help or hints for REloaded room until 1st March, 7pm (GMT)

fervent valley
#

Anyone on "relevant" room? Stuck here, kind of hopelessly haha

stuck fractal
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
white salmon
#

Hello! I think I'm writting in the correct channel. I have an issue with the solution of a XSS room, can i have some help please? thanks.

fervent valley
#

Relevant room

stuck fractal
#

I haven't done the room but there's a glaringly obvious thing I'd do RN with IIS?

fervent valley
fervent valley
#

Ok ok, I'm barking at the wrong trees. Will try a different approach

buoyant grotto
#

excuse me, any one in group solved all task room hard HOTH ?

stuck fractal
#

So please do not ask for any help or hints

buoyant grotto
#

oh no i dont just ask hint, i had problem: server room sometime down, 3-5 min and i can access link or anything. My network is OK. anyone same problems

stuck fractal
#

!vpnscript

proud scarabBOT
buoyant grotto
stuck fractal
#

Please don't call me bro, it's uncomfortable because you don't know me.

buoyant grotto
#

tks 😄

real lynx
#

If anybody has done Linuzz CTF, I would like to discuss the way they got root, coz I know for sure I used the unintended way for root, feel free to DM me for discussing on the topic

upper osprey
#

is anybody solving simple ctf room

upper osprey
#

I don't understand how to find them using commands

winged mist
cunning quartz
#

Coz I got to root directly

real lynx
#

I couldn't figure out the thing on 8080 hence I decided to jump directly to root using the unintended way but I would like to know about that way as well

cunning quartz
astral smelt
#

If you did lunizz the unintended way, feel free to dm me and I will tell you what the intended way was

devout tangle
#

how long is going to take to brute force the basic auth in inferno box

#

??

devout tangle
#

anyone??

astral smelt
#

Sure

opal vine
#

guys im stuck at watcher room at task 3
the hint poins to a file upload but there's no directory where i can upload files
so how can i exploit the ||LFI||?

white salmon
#

i got a question for high level web pentesters

stuck fractal
white salmon
#

okay sorry

white salmon
#

It is already allow to ask hints for Lunizz ?

astral smelt
#

sure

sweet hound
#

Since we can ask for hints on Lunizz ctf since 4 minutes: I need one for the third question. I had a look at ||port 4444||, but it seems to be a rabbit hole. Then I found ||/whatever and /hidden||. The first one seems like a good way, but I can't figure out how to use it to get a shell or answer the question. I couldn't exploit the latter one so far... I also found the myqsl and used it to fully use ||/whatever||

white salmon
#

The answer for the 3rd question is in the shell..

#

A folder with a strange name that we never see usually

#

And for the mysql part....update query is needed to see a change in /whatever

sweet hound
white salmon
#

Ahh...my bad

#

which room?

#

Can you please elaborate?

#

You need to update the column value

#

You have to update the db column value to get that code execution working

sweet hound
gusty kite
#

the value in the table in the database is the lock that decides if you can use the website to run commands or not

#

you can see the website say somthing like mode:0 or similar.

#

you need that to be a 1 and that has to be changed in the db

ripe hedge
#

Pretty much that

flint breach
#

Heyyyyy about lunizz where should i focus on after getting shell of wwwdata

#

I did find find something on internally hosted but im not sure to proceed to mason or adam

#

I even tried completely the bcrypt script using the password as rockyou txt

#

But the salt gen function made the hash and salt new everytime so ....

#

Idk what to do next

#

Linpeas showed sudo version but im assuming thats not the intended way

white pike
#

In bcrypt you can use a hash to get the salt, which was used for encryption.

flint breach
#

There was salt and ... in the script

#

Ok lemme check

stuck fractal
#

Not encryption but ok

flint breach
#

There was only salt in the script but ...

white pike
#

The "salt" in the script may be more than just the salt

stuck fractal
#

I believe cyberchef has a parse bcrypt module that will extract the salt

flint breach
#

And then place that instead of gensalt ... ooh

#

And compare with the Salt

ripe hedge
#

There's a checkpwd function for the python module

#

Be aware that bcrypt is sloooooooooooow

flint breach
#

Can i dm you hydragyrum???

#

@ripe hedge

white owl
#

Is that bcrypt crackable? I tried rockyou, base64 of rockyou, and even including the b' that gets added to the b64 with python str

flint breach
#

Im running it

#

And ik its gonna crash because of some characters that can’t be converted to ascii 😂

white owl
#

Yeah i just skipped those

#

But the b64 ends up looking like b'abcd123' before being passed to bcrypt because it is converting bytes to str

stuck fractal
ripe hedge
flint breach
#

Nothing now😂

deft oriole
#

I got root on that box, seemingly a totally different way

#

I'm just stuck on "hi adam, do you remember our place?"

#

I just don't understand what it's asking.

ripe hedge
#

yeah it's in adam's home dir

slender wyvern
#

Lunizz, Salt from existing hash + rockyou.txt is the good way?

deft oriole
ripe hedge
#

there's a note in there

#

it's not so much a place though

deft oriole
#

i hate riddles

ripe hedge
#

there's a link to click

deft oriole
#

ffs

#

thanks

#

got it lol

ripe hedge
#

yeah...

green brook
#

Can someone elaborate on the bcrypt

#

Can't get any further than looking at the damn script and not getting any further 😆

ripe hedge
#

I dunno, I'm not getting anything after 100k passwords

flint breach
#

Mines still running 😞

uneven bane
#

Good to know I had the right script for this Lunizz box... but it has to run for a couple hours and errors out

flint breach
#

Errors out ... you mean the ascii conversation??

uneven bane
#

there is a string or two in rockyou that wont convert

#

so it runs for a bit and then cant go on

flint breach
#

Skip them

uneven bane
#

it was VERY frustrating

#

i went unintended route

flint breach
#

😂

uneven bane
#

it cracking bcrypt was the intent, it fell flat on that task

#

10 mins is about all the time I want to spend iterating through rockyou

flint breach
#

Its actually slooooow

uneven bane
#

yea, like 30H/s

flint breach
#

But im gonna wait tho

uneven bane
#

do it...

flint breach
#

Yup

uneven bane
#

I learned a ton about bcrypt and python

#

so, in that, I feel like it offered something

#

but I still dont know the PW

#

haha

flint breach
#

🤣

ripe hedge
#

I'm trying the top 100k rockyou passwords....it's slowwwwwwwwwwwwwwww

#

used iconv to strip out the bad characters so I hope it's not one of those

ashen scaffold
dusky shoal
#

Hey guys I am doing the Mr. Robot room and trying to crack the wp-login user name with hydra

#

can someone help me see whats wrong with this code?

#

hydra -L fsocity.dic -p test 10.10.103.0 -V http-form-post '/wp-login.php:log=^USER^&pwd=^PASS^&wp-submit=Log In&testcookie=1:F:Invalid username'

#

hydra runs, so I am guessing my issue is with the request

dusky shoal
#

I found it lol I needed the redirect I guess in the request also

gentle vector
sonic axle
#

currently in the linux challenges room. having trouble finding flag 4. the hint says "crontabs". i googled where cronjobs where created and everywhere says crontabs. i did try and check other directories but kept running into permission denied

stuck fractal
#

There are other ways to edit/read crontabs

#

There are several different crontabs

amber glacier
#

OWASP Top 10 | Challenge Broken Auth | Performed the " darren" user registration. Logged in with that user. All I see is "You need to login with specific account to be able to find the flag." Entered that as the flag and no luck. Went into dev tools posted the cookie value that was created into flag. No luck with that. This is a beginner challenge, so I am assuming I don't do a dirbuster or something to see if there are directories I should be going though. Any tips?

zenith owl
#

Can I get a nudge for question 1 on Investigating Windows 2.0?

stuck fractal
#

Did you register with the quotes or without the quotes? @amber glacier

amber glacier
#

WIth double quotes

stuck fractal
#

Do it without.

amber glacier
#

hahaha, I'm dumb

#

30 minutes I will never get back... Ha! Thank you for the assist.

deft oriole
cedar axle
candid nimbus
#

I've repurposed the script given as a fuzzer, tested it against passwords picked from rockyou and encoded using the script to check it works, run the hash against rockyou with and without/n, the song lyrics in many forms and a lyric pass wordlist from all the band's songs, and still nothing!

cedar axle
#

luckily this room has another vuln

storm venture
#

yeah I think a lot of us have rooted it, it's just trying to do it the intentional way 🤷‍♂️

cedar axle
#

has anyone asked the room creator?

pallid siren
#

Are we allowed to discuss Hacker of The Hill yet? Stuck on Task 5. Found flag for container 4, but absolutely no idea how to move foward from there to get the other flags

storm venture
#

don't think so @pallid siren, the prizes haven't been announced yet, so I presume hints will come after that

ashen marsh
#

Are we allowed to ask today?

simple mountain
#

I’m pretty sure the contest has been extended, so it’s still live. @steady stratus is that accurate?

ashen marsh
simple mountain
#

I think is you have to ask, it’s a hint. Sorry man.

#

Keep at it though, I know you can get it 🙂

gusty kite
# cedar axle has anyone asked the room creator?

Yes I discussed it with him. Correct way is to use python to get the salt for the password hash (disguised as "salt" in the script) and then use that salt as input for a modified version of the script that loops over rockyou, base64 encode and hash each word + compare it to the one in "salt" (matching one is the password).

uneven bane
storm venture
#

HOTH has ended, happy to talk anyone through the way I rooted all three of the machines if people are curious!

pine reef
near shoal
#

@steady stratus were we supposed to use that fake lfias an oracle?

#

asking because I did kekw .. and still messing with it

#

though I also have other ideas

#

including a sneaky sqli

storm venture
#

for medium?

near shoal
#

hard

#

medium I think I did an unintended

storm venture
#

ahh right

#

you wanna pm?

#

I can detail my method for both

split nymph
#

hey guys..need some please!

how long does usually a nmap take for all the ports on the machine at -T4 ?

near shoal
#

@storm venture not yet still trying hard 🙂

remote gate
#

@storm venture could I pm?

storm venture
#

of course you can mate

#

good luck with it @near shoal

ripe hedge
echo peak
ripe hedge
#

I'm assuming it's not the same user

sweet hound
split nymph
sweet hound
split nymph
stuck fractal
#

Shouldn't be.

split nymph
#

I used the -vv and stared at it. without a -vv the white pointer just frezees.

stuck fractal
#

It's busy doing stuff.

#

No news is good news usually when it comes to commands.

sweet hound
split nymph
distant tartan
#

i am on anonymous room i am stuck on question 4 i downloded the files from ftp server but i am not able to figure out how to continue any help would be appriated i tried login into smb by anonymous its asking for a password which i am not able to find

digital vector
distant tartan
#

can you explain a lil bit more

stuck fractal
digital vector
#

ah right . devil - in this box you can 🙂

digital vector
digital vector
#

just make sure you are in the same directory where the mal file is stored

distant tartan
#

thanks for your hint though

gentle vector
#

Hint : For those still working on Lunizz, YES, you can get ad**'s password from the bcrypt script and the popular wordlist. Here is what i did, i removed all special characters that did not convert to ISCII , all numbers only passwords (because who does that?), all 6 characters or less (as a start , because of the first mysql password length, thought others will be long as well). This still took a long time but not as others.(edited)
[9:52 AM]
Another Lunizz hint on that password: Its a plaintxt for a known sha256 hash, so maybe skip all the other words in the wordlist and run against known shar256 hashes. My writeup is coming soon

digital vector
#

what

gusty kite
echo peak
ripe hedge
storm venture
#

yeah of course

#

don't need to ask 😃

cedar axle
#

the password is like after 7.3 million in the list

#

thats gonna take a long time

cedar axle
oak swallow
#

Hi everyone. I'm working on the Windows Priv-Esc room by Tib3rius, and I'm stuck on Task 9. The walkthrough indicates that I could find a username and password from the command output, but I could only get a username.

gusty kite
#

sure

cedar axle
simple mountain
#

Do not provide or ask for help or hints for JPGChat room until 3rd March, 7pm (GMT)

lethal ravine
#

are we allowed to ask for hints for h1 hard box now? 🙂

trim haven
#

All hacker of the hill boxes are open for questions 🙂

lethal ravine
#

ok, if anyone would be willing to help out with the h1 hard box and helping me towards the right path it would be highly appreciated, I'm struggling with container 1 and 3

digital vector
#

@lethal ravine that suggests you have container2 flag ?

digital vector
#

so your left with the privsc part ?

#

you should have a foothold if you have 2nd flag .

lethal ravine
#

yeah, ooh, you can actually privesc on that one ? xD

#

I thought it was a dead end xD

#

thx then 😄

digital vector
#

@lethal ravine maybe i am wrong because i had to get a shell from one place , and from there i did not switch any containers , just privsc and then all flags

lethal ravine
digital vector
#

maybe You can Dm me and explain me how you the foothold for container2 , because as far as i know you can get only 2 foothold , one is container 4 and another is the rest , so container4 is a dead end

#

Maybe DM me , we can talk better

lethal ravine
#

sure, thx

pine reef
brisk pivot
#

I don't get where to find it

#

the hint was ____cry

astral smelt
#

Room?

brisk pivot
astral smelt
#

This was posted in general but use the find command in your browser to find $6$

brisk pivot
#

so by "find command" you mean to u find a specific word or phrase on a web page on your computer right?

astral smelt
#

Yes, if you press ctrl + f

brisk pivot
#

ok ty imma look into that

#

yeaaa

#

I got it

tough breach
#

looking for big chunk of hints of Hacker of the Hill

#

especially for the hard box. all feels so close but stuck there

cedar sluice
#

May i DM someone for JPGChat room?

digital iris
pure thistle
#

any hints on lunizz yet how do i install chisel on the remote without sudo perms?

ashen scaffold
#

@pure thistle wget to the box

#

I mean...you can use tar to get the files too

pure thistle
#

the same with socat

ashen scaffold
#

You dont install it on the remote box

#

You just copy it from local

pure thistle
#

or maybe i should be asking how do i port tunnel with out the common binaries

pure thistle
ashen scaffold
#

mark as as executable and ./chisel or whatever you name it

pure thistle
#
bash: ./chisel: No such file or directory
ashen scaffold
#

Did you download latest release?

#

Onto your local machine?

#

Follow the README

primal garden
#

Anyone completed webOSINT room?

#

I'm stuck on task 3

pure thistle
brisk pivot
#

What is the CVE for the 2020 Cross-Site Scripting (XSS) vulnerability found in WPForms?

#

I really don't know what to do here

stuck fractal
#

Google mainly

brisk pivot
#

mainly?

#

like search: mainly?

stuck fractal
#

No

#

Google it basically

brisk pivot
#

like what is a mainly

#

nvm

#

ohh so I search for the exact question

stuck fractal
#

You search for the keywords.

#

2020 Cross-Site Scripting (XSS) vulnerability found in WPForms can be shortened a whole lot, gets you better results

#

2020 xss WPForms

brisk pivot
#

ok ty for the help 🙂

#

oh so I had it I just forgot to put the cve at the start

white owl
#

Can we talk about hackerofthehill now?

stuck fractal
white owl
#

Excellent

neat cosmos
#

doing the year of rabbit room and just hit the rick roll section

#

any hints on what i can do?

white owl
#

Listen to the video

stuck fractal
#

Try burp with intercept on

neat cosmos
brisk pivot
#

Introductory researching task 3 question 3 I searched for it I put it in the quesiton slot put it does not work

white owl
#

So for the hard room, i found the login info in the api for one container. If i had root there, i could have rooted the host because the docker socket was exposed, but i only had davelarkin user. So I was trying to get in to the other sites. The one with the hills, i found the XML feed could list files in other directories, and i feel like i should have been able to get lfi somehow with the /view?image=... but i couldn't quite figure it out

neat cosmos
white owl
#

The shop page seemed to be requesting API endpoints with curl when you view products, so i thought maybe command injection, but it only accepted numbers for the product

#

Was i at least on the right track with some of these

brisk pivot
#

ok so I thought that I found the answer to the: What is the very first CVE found in the VLC media player? but it says no

#

idk why

#

I have this right now

stuck fractal
#

That aint the first

brisk pivot
#

no?

stuck fractal
#

I'm assuming that's the first in a list

brisk pivot
#

ah

stuck fractal
#

Go onto the site the room tells you about and look at CVEs for VLC

#

Sort by date/number

brisk pivot
#

oh one of the sites in the text?

#

😮

#

I got it right

stuck fractal
#

Try things. It's research. Keep looking until you find it.

#

That's how hacking works

#

Just keep trying stuff that seems like it'll take you in the right direction

brisk pivot
#

ah ok I follow you now

icy root
#

does anyone have problems getting the persistant xss flag from the owasp juice shop room? i got the xss window to appear but the flag is nowhere to be found 😦

sweet hound
lament notch
#

hey have you ever figured it out im currently stuck there as well

alpine gulch
#

any hints on room REloaded . I could not find the flag for the third task

ripe hedge
#

I found the flag but not the instruction modified

#

but I think the embargo is until tonight

white salmon
#

I just finished jpgchat room by myself, first room I completed 100% on my own 🙂

ripe hedge
simple mountain
#

No idea what you are talking about.....

#

(Merci 🙂 )

ripe hedge
#

😉

#

that was last year

#

I know last year didn`t happen, and that could be confusing

gusty kite
#

what debugger (preferebly free) would you recommend for windows for RE tasks like the REloaded room ? Right now I use x64dbg but it is not that good at representing the code for easy navigation. Often I have to open Ghidra to get an understanding of where something happens in the code and then find the address of the instruction and use that to set the breakpoint in x64dbg. patching functionality needed

cedar axle
gusty kite
#

ok but is there a way to run the app in ghidra ?

#

to get the output

cedar axle
#

i didnt even run the programs, which get detected by windows defender by the way

gusty kite
#

ok

cedar axle
#

i just read the decompiled code

gusty kite
#

I tried finding the flag for the one with xor (was it task 4 maybe) but could not get to a point where I could get to the place where the EAX value was inserted

cedar axle
#

only one question i made an educated guess, which was the one about which instruction did you patch

gusty kite
#

yeah that one I guessed too from the usual suspects

cedar axle
#

no 4 the programs encrypts the string, but it is stored unencrypted, just a little bit backwards but anyway

#

oh to answer your question you could use cutter which is a GUI for radare2

#

very powerful

gusty kite
#

cool will check that out. I do like radare but keep forgetting many of the commands when it starts to get a bit more technical than the initial investigation steps etc

ripe hedge
#

||but everything was in plaintext||

#

I'm pretty sure I did an unintended on task 3

cedar axle
#

what made it hard was the obfuscation, which wasn't so much obfuscation as it was clutter, just a heap of pointless functions

ripe hedge
#

yeah it was a mess

candid nimbus
echo peak
#

i used ghidra as well, as @cedar axle . started with searching for references to printf and then jumping around in calls.

gusty kite
#

usually finding the right spot where things happens is not the problem for me. it was getting back to where the initial string is located.

real lynx
#

when will the be writeups for HOTH be released?

storm venture
#

whenever people get around to making them

#

I'm in progress on one

waxen silo
real lynx
hexed crescent
white salmon
#

what's the best wordlist for cracking password on tryhackme? just to not using rockyou all the time..

ripe hedge
#

grats on the green @storm venture

worthy gust
storm venture
#

thanks sir ❤️ @ripe hedge

storm venture
hexed crescent
#

Lunizz CTF is being revised.

white salmon
worthy gust
ripe hedge
#

I dunno I think I'm doing the crack correctly, but the top 200k in rockyou is giving nothing

#

that took 4 hours so I'm not trying more

white owl
#

When i was testing stuff i noticed the script casts the base64 output, which is bytes, to a string, so it ends up looking like b'asdf1234' and that's what gets passed to bcrypt

marble hedge
#

I don't know where to ask these kind of questions, but are unintended ways a reason to reject writeups?

digital iris
stuck fractal
#

Personally I wouldn't reject an unintended unless I'd patched it by that point, or the write-up for it was low quality

marble hedge
marble hedge
stuck fractal
#

If the writeup doesn't reflect the current state of the box, I don't see much of a reason to accept it.

slender wyvern
#

for lunizz ctf,
script + rockyou -> use encode('ascii', errors='ignore') to avoid break process by non-convertable charts

white owl
#

I'm cracking now. Estimated 12 hours

#

Anyone with a video card want to team up to crack this bcrypt

crisp burrow
#

It is like ||7200000 +||

white owl
vivid spear
#

Anyone can give me a room hint for WireShark 101 - Task 7 - Question: What 4 packets are Reply packets?

vivid spear
#

Will have a relook

vivid spear
#

Isn't Reply packets an Arp

slate turtle
vivid spear
#

Thanks py120, I figured out.

slate turtle
white owl
#

hey i cracked the lunizz password!

white owl
#

That was way too much though. I feel like hashes shouldn't be that hard unless the room was like about hashcat or something and came with a disclaimer that you need a video card and several hours

stuck fractal
clear violet
#

hey can anyone help me with hacker of the hill easy machine

digital vector
#

did you do a nmap scan ? @clear violet

ashen scaffold
azure dock
#

@white owl did you use hashcat ? or you wrote a custom script ?

white owl
#

I used a script to convert rockyou to b64 lines, then ran that through hashcat

#

That would take 12 hours, but @crisp burrow recommended skipping a bunch

#

Also the base64 lines need to be surrounded by b' ... '

azure dock
#

hmmm it didn't work for me

#

the bcrypt generated by that script was not "cracked" by hashcat after 13h

crisp burrow
#

I would suggest another way to get the password. Get root via unintended way. Get the hash from shadow file then use hascat. It takes less time lol, then start again, go by intended way. I might sound silly tho.

azure dock
#

eheh

#

can I DM you guys? I'd like a sanity check.. if it is ok

crisp burrow
#

Check python bcrypt doc, you can figure out easily.

#

Yes you can

digital bolt
ripe hedge
#

I wasn't able to crack the shadow though either

#

unless the actual password is b'base64'

storm venture
#

apparently the password is halfway through rockyou @ripe hedge

#

it took 12 hours to crack

ripe hedge
#

...

storm venture
#

I presume that was threaded

ripe hedge
#

yeah that's not allowed

storm venture
#

yeah...

ripe hedge
#

halfway through rockyou is like 7M

#

that's 5 days on CPU

storm venture
#

well

ripe hedge
#

about 14 hours on my gpu...

storm venture
#

damn...

ripe hedge
#

that's just calculating

storm venture
#

about three weeks on my laptop

ripe hedge
#

GPU was about 140 H/s

#

CPU was getting about 14

#

yeah ok nearly 6 days on CPU

#

if you really want to bruteforce bcrypt with rockyou, you keep it in the top 1000

#

or bottom 1000 if you want to troll

storm venture
#

yeah

#

well

#

that was fun then

#

what next?

ripe hedge
#

glad that sudo was vulnerable then

cedar axle
#

how did that room get accepted, i thought there was a policy for brute forcing of 5 minutes

stuck fractal
#

There is. It's been discussed by the room testers.

gusty kite
#

if there was a question in the room about the actual password, then we would have had a hint on the length and this could strongly limit the length of the rockyou list

#

but it was fun (read: frustrating) to crack the password 😛

opal vine
#

guys can i get a hint on how to get root in watcher

ripe hedge
#

sec I need my notes

#

what have you tried?

opal vine
#

i ran linpeas and found nothing

ripe hedge
#

what user are you on?

opal vine
#

there's no SUID or cronjob obv

opal vine
ripe hedge
#

id might help

opal vine
#

he's in the admin group but i thiiiiiiiiink /var/log contains nothing

#

is it about lxd?

ripe hedge
#

ok, naw

#

you try to find everything?

opal vine
#

cuz lxd doesn't work on my laptop

stuck fractal
#

The lxd alpine privesc is kinda broken RN because of mirrors

ripe hedge
#

I don't think he has lxd access anyways?

#

but it's not lxd

#

but you can probably find a few things lying around outside the logs

opal vine
white owl
ripe hedge
#

yeah I was running it though with a subset

#

but I just base64'd using bash and tried hashcat on that

white owl
#

I learned how to parse text files with weird chars in them in python though, so it wasn't a wasted exercise

ripe hedge
#

heh I used iconv

#

though with b64 you don't really need to worry about those

opal vine
ripe hedge
#

told you you could find it!

opal vine
#

thx man

ripe hedge
#

(I hope you used find though)

#

I mean random directory trolling would have worked...

#

I always check /opt these days

#

bloody ctfs always hiding stuff in there

opal vine
white salmon
opal vine
#

thanks bro i just solved it

ripe hedge
#

little late

#

but yeah

#

leaving thing like that lying around. bad admin

opal vine
#

hahahahahah true

azure dock
#

still I didn't crack this pwd! LoL

ripe hedge
#

Lunizz?

azure dock
#

yeah

#

I spent 13h GPU lol and still didn't get it lol

#

enough 😦

ripe hedge
#

it's a bit broken

#

room creator has been notified from what I can tell

azure dock
#

1h max could be still ok .. but more than that I lose interest for a ctf

stuck fractal
#

The rules for THM are 5 minutes for brute force

#

Ideally tested on the attackbox

azure dock
#

and how would you explain 12h bcrypt ? 😄

stuck fractal
#

That it slipped past the tester?

azure dock
#

I think even the Crack the hash had something for bcrypt for 5h

stuck fractal
#

That was way before the rule was implemented, and you can cut the time down by a crazy amount because you know the length.

azure dock
#

ok it makes sense, I didn't know the rule was a new one 🙂

#

I thought it was always like that

stuck fractal
#

Crack the hash is one of the oldest rooms on the platform

azure dock
#

yes but I believe that whole scope is to learn how to use the tools or write a script to crack the hash not spending hours waiting for the execution.. I might be wrong of course. 🙂

brisk pivot
#

Netcat is a basic tool used to manually send and receive network requests.
What command would you use to start netcat in listen mode, using port 12345?

#

I type -l and it does not work

#

after: man netcat

stuck fractal
brisk pivot
#

ok so I type this first

#

so I need to enter that?

lime violet
#

Yes

brisk pivot
#

ok

#

ty

lime violet
#

I think lol

stuck fractal
#

@lime violet Please do not post answers

#

That 100% defeats the purpose of giving hints, and I'd count it as cheating.

brisk pivot
#

I did not had the time to write it lol

#

so it's ok

lime violet
#

Apologies didn't realize that was considered an answer

brisk pivot
#

it's good thumbs_up_cat

#

ok so I typed: man netcat

#

so I see -l for listen mode

lime violet
#

Ok so what's next?

stuck fractal
#

What command would you use to start netcat in listen mode, using port 12345? The full command for it

#

and you'll be using nc not netcat

brisk pivot
#

and do I write this here?

stuck fractal
#

Write what where?

brisk pivot
#

because I cannot write in this orange text

stuck fractal
#

I will repeat my question

#

Write what where?

brisk pivot
#

ok so you know that you so " man nc"?

#

and then it shows a bunch of things

#

do you write in this or do you write in a clear editor

stuck fractal
#

Why are you trying to write things?

brisk pivot
#

like the code

stuck fractal
#

What?

brisk pivot
#

I am so confused xDD

stuck fractal
#

What code?

#

There is no code?

lime violet
#

He means the command

brisk pivot
#

ok let's restart

#

so first I type " man nc"

#

and then it shows all the commands for nc

#

and it shows that " -l " is the command for it

#

and I know that the port is 12345

#

-l listen mode, for inbound connects

#

nc -l ** 12345

#

ok I am missing something in the answer

lime violet
#

Yes you are

#

Read the manual again

stuck fractal
#

It's the option or flag to use listen mode

brisk pivot
#

oh so it's not -l?

stuck fractal
#

I didn't say that

brisk pivot
#

ok so I need 2 switches

#

and I have one of them

stuck fractal
#

But using the right words is super super important in hacking

stuck fractal
brisk pivot
#

nc is netcat, -l is one switch and 12345 is the port

lime violet
#

You're so close lol

brisk pivot
#

lol

stuck fractal
#

So you need a flag that allows you to specify the port for listening

#

When you're connecting out (not listening) you don't specify a port

#

But when you're listening, you need to specify the port

brisk pivot
#

ok so I know that it is - and then a letter but I just need to find which one

lime violet
#

What does the manual say

brisk pivot
#

-c string specify shell commands to exec after connect (use with caution). The string is passed to /bin/sh -c for execution. See the -e op‐
tion if you don't have a working /bin/sh (Note that POSIX-conformant system must have one).

-e filename specify filename to exec after connect (use with caution). See the -c option for enhanced functionality.

   -g gateway   source-routing hop point[s], up to 8

   -G num       source-routing pointer: 4, 8, 12, ...

   -h           display help

   -i secs      delay interval for lines sent, ports scanned

   -l           listen mode, for inbound connects

   -n           numeric-only IP addresses, no DNS

   -o file      hex dump of traffic

   -p port      local port number (port numbers can be individual or ranges: lo-hi [inclusive])

   -q seconds   after EOF on stdin, wait the specified number of seconds and then quit. If seconds is negative, wait forever.

   -b           allow UDP broadcasts

   -r           randomize local and remote ports

   -s addr      local source address

   -t           enable telnet negotiation

   -u           UDP mode

   -v           verbose [use twice to be more verbose]

   -w secs      timeout for connects and final net reads

   -C           Send CRLF as line-ending

   -z           zero-I/O mode [used for scanning]

   -T type      set TOS flag (type may be one of "Minimize-Delay", "Maximize-Throughput", "Maximize-Re
#

it's not -i secs that I know

lime violet
#

Lol its there I see it

stuck fractal
#

I see it there.

brisk pivot
#

my eyes should be rly tired right now xD

#

😮

#

I got it

#

yay

#

ty 🙂

novel smelt
#

ok when trying to ssh to a room it doesn't give me a username or password but i do have the ip what do i do in order to connect to it?

slim axle
#

So, can we get any hints for Hacker of the Hill yet?

stuck fractal
serene flax
#

@steady stratus looks like the competition for hacker of the hill has ended. So will it be okay to publish the writeup for the room?

steady stratus
#

you can make writeups aye but we're very likely not to be accepting any that get submitted onto the room/site (as the boxes are in koth)

#

take that with a slight pinch of salt and I'd have to ask one of the owners about whether or not we accept them because of the fact it's also koth machines

#

I mean you can also make writeups for koth boxes thinking about it

#

I'll ask an owner tomorrow to get a better stance on approaching that one @serene flax

serene flax
#

So I can go ahead and publish my writeup, right? @steady stratus

steady stratus
#

You can write it up just follow the normal rules with writeups

#

I just can't guarantee it'll be accepted as a writeup on the room itself if you were to submit it on there is all atm (:

serene flax
#

sure. I will just post it on my website then

steady stratus
#

👍 ace I mean once a get the site owners stance I'll let you know but that won't be for a little while as it's 03:20 for them 😛

serene flax
#

okay thanks 🙂

#

will it be okay to leave a link here for the writeup? @steady stratus

steady stratus
#

Please share your writeups once they have been accepted to the room you're covering.
i.e. wait it out a little bit (:

serene flax
#

okay. will do that. thanks 🙂

gusty kite
#

nope the page is still there

#

you found the wrong one

stuck fractal
#

They are not allowed.

steady stratus
serene flax
steady stratus
#

I'll have a read (:

ripe hedge
#

tbf I'd like to know what the intended for Medium was

serene flax
#

||i think shell from command injection, find kerberoastable user and getting the hash for achilles user and cracking the hash|| @ripe hedge

ripe hedge
#

I brute forced rdp

#

with achilles

#

but was it intentional that achilles had admin rights?

#

because that made the box laughably easy

serene flax
#

that user was kerberostable and for us to crack that hash, the password must be on rockyou

#

it would be a little difficult if the password was at middle or end of the rockyou file

ripe hedge
#

not really, NTLM is stupidly easy to crack

serene flax
#

I also got the password by bruteforcing the smb

#

well you directly bruteforced the rdp, right? without having a shell

ripe hedge
#

yeah