#room-hints

1 messages ยท Page 86 of 1

worn otter
#

you must be a glutton for punishment ๐Ÿ™‚

#

I was doing a room a few days ago that had a website about trading in vim. Made me actually laugh out loud.

median reef
#

๐Ÿคฃ

worn otter
cloud perch
median reef
#

that is what i did

cloud perch
#

Nice

#

@median reef In the video I'm going to make for badbyte I'm going to show three ways of uploading the payload on I'm gonna show the Metasploit way,your script and how to manually do it. I'll give you credit for your script

median reef
#

โค๏ธ

median reef
cloud perch
#

electronforce and Raccooninja

median reef
cloud perch
#

i knw

median reef
#

ah i thought you missed

#

anyway dm me the feedback if you have any

fathom ibex
#

I GOTT ITTT, dude that room took me 5 hours

median reef
#

๐ŸŽ‰

worn otter
#

Yeah, I ran out of extensions on mine

#

wouldn't have gotten it without the hints

ionic cedar
#

hey guys what's up? coul you help me? I got stuck on task 4 from network services 2 as you can see I got the bash executable in my ssh but when i try to execute it, this doesn't show me any flag. could you help with a hint or something?

#

this are the permissions that I havr

stuck fractal
#

It needs to be root owned with suid

#

It's not root owned

ionic cedar
#

I used chmod +s for that

green cliff
#

Luis what are the permissions?

ionic cedar
#

-rwsr-sr-x

green cliff
#

Like Ninja said it needs to be owned by root
sudo chown root. Bash

ionic cedar
#

oh ok

#

man but i used this command line before as it says in task. Isn't right?

green cliff
#

Chmod changes permissions
Chown changes the owner

ionic cedar
#

oooooooh

green cliff
#

Chgrp changes the group

ionic cedar
#

man but here says chmod

green cliff
#

Task2 states to run
Sudo chown root bash

ionic cedar
#

ooooh yeah i got it

green cliff
#

Prior to running the chmod command

ionic cedar
#

yeah yeah i skip that step

#

skipped

#

now i got this

green cliff
#

Run it again

#

Then type:

whoami

stuck fractal
#

Or you were

green cliff
#

Ninja is correct....
I was trying to let Luis discover that....
You'll need to look around for the flag.

untold fulcrum
#

I rooted the badboy box

ionic cedar
untold fulcrum
#

I have two questions about badbyte what is the cve for the transversal directory (I can't find it) and for the curl command "curl -ks --max-time 5 --user-agent ..." ne not working and I do not understand why. a little hint would be welcome

novel hazel
#

Hello everyone! Hope u r doing great...!

I need help with a Nmap Question... I was doing EVERYTHING the task says but i'm not getting the answer (i think :v)

#

Command...

#

Response (1/2)

#

response(2/2)

#

and... Sad face. :'v

stuck fractal
#

The VM is not up

#

Redeploy it

ionic cedar
stuck fractal
#

Screenshot.

#

I cannot see your screen or what you did or what you're seeing RN

ionic cedar
stuck fractal
#

You exited the root shell

#

So you're not root anymore

novel hazel
stuck fractal
#

it dies after an hour

#

It needs a fix

ionic cedar
novel hazel
ionic cedar
stuck fractal
#

Now you're root, as it says

#

So you need to get the flag

ionic cedar
#

yeah I did it after several tries hahaha thanks

high beacon
#

In CC Pentesting Task 10 I Keep getting no session created. I've checked my ip several times. I'm using open VPN and a Parrot VM

stuck fractal
#

LHOST?

high beacon
#

That's what I was thinking i'm trying to grab a screen shot

high beacon
#

I can't seem to post a screenshot

stuck fractal
#

!docs verify

proud scarabBOT
stuck fractal
#

Follow those steps

high beacon
#

Thank you

stuck fractal
#

LHOST is wrong for sure

#

Needs to be your THM VPN IP

high beacon
#

Ok i though it was the VM IP

true widget
#

hey guys I am solving ARcHanG3l.I found the other hostname and also the test page but I could nt proceed forward.Tried a lot but couldnt find the lfi.Anyone wanna give a nudge?

modest swift
#

i tried for ages doing the LFI on that room, couldn't get it working

#

gave up

true widget
#

man I will refer the writeup now

#

It is meant to be an easy room.

#

I need to level up seriously

modest swift
#

lol why someone deleting my comment

weary flame
#

Did anybody here complete EnterPrize Room???

#

Need a hint on Reverse Shell Part

modest swift
#

need some help on foothold for broker please

misty bridge
#

Hi guys, I'm currently doing the Buffer Overflow Room, on task 8 I'm trying to pass as argument to the binary I'm exploiting the output of a python program, but I receive this error, does anyone have a hint to solve this issue?

weary flame
stark reef
#

There are POC's on github similar to metasploit that works

white salmon
#

Hey is the broker room buggy?

#

Cant connect via mqqt clients tried 3 different ones

modest swift
fickle bronze
white salmon
#

@modest swift ty! ๐Ÿ˜‰

slow slate
#

Just finished BadByte room. What a lovely challenge that was. Excellent work of electronforce & Raccooninja. Bit on the end of easy, I guess.

balmy verge
#

it was tagged as easy

acoustic steppe
slow slate
#

Love the way the passwords were hidden!!

acoustic steppe
balmy verge
#

I hurt my eyes looking through the || auth.log since the user was in the adm group lol ||

slow slate
slow slate
trail aspen
slow slate
trail aspen
slow slate
#

You guys deserve it!

acoustic steppe
merry sonnet
#

currently working on badbyte, I have managed to gain access through a CVE and now having some trouble searching for credentials. what are some common directories that you all have seen in a *nix host to be of interests for things like that?

#

other than config files and logs and whatever may be in their home directories

median reef
merry sonnet
#

@median reef damn totally missed that one lol thanks!

median reef
merry sonnet
#

that was a fun box

meager pagoda
#

Linux Fundamentals Part 1 I only can find the login credentials from the video and not on the page. Is there a reason behind ๐Ÿ™‚

stuck fractal
#

You're taught SSH in Linux2

meager pagoda
#

ahh ok ๐Ÿ™‚ thanks i connected through ssh with the credentials from the video makes sense for me thanks fro your help !

urban kernel
stuck fractal
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
urban kernel
#

@stuck fractal ok

#

i am in room
Badbyte
and in Port Forwarding i connect b ssh and t Forwarded the port 80 from 8080 using this commend ssh -i id_rsa -L 8080:127.0.0.1:80 ...

#

but i dont know this qutiotn What main TCP ports are listening on localhost?

#

@stuck fractal .

obsidian zenith
#

agh idk why its not working when i type in the pinguftw password

#

it worked yesterday

#

it just seems like today it isnt working

#

i did ssh shiba2@(my machine's ip)

#

that worked

#

except the password part

stuck fractal
#

Where did you get the IP from?

obsidian zenith
#

From the top of the website where it's green

#

Its next to the attackbox

stuck fractal
#

That's your attackbox's IP

#

Not the deploy in the room

#

Click deploy

obsidian zenith
#

i totally forgot about that

#

agh i feel so dumb

#

thank you

sleek obsidian
#

Could use a hint on Badbyte on the last section. Hunting for the old password.

#

Found it! Fun box, thanks to the creators of it. Had me stumped there for a second.

tiny hare
#

hey guys, I am looking for hint what can be wrong Common Linux Privesc room for "Exploiting Writeable /etc/passwd" I still getting Authentication failure when trying to log in with new user. New user line looks ok new:$1$new$p7ptkEKU1HnaHpRtzNizS1:0:0:root:/root:/bin/bash in /etc/passwd while it passed in task. Edited user7 which has root right to this file.

#

escaping $: new:\$1\$new\$p7ptkEKU1HnaHpRtzNizS1:0:0:root:/root:/bin/bash

stuck fractal
#

Honestly I'd use single quotes because it's easier to read

tiny hare
#

my failure, wrong password facepalm

verbal flume
#

Can we ask hints for Tokyo Ghoul yet?

astral smelt
#

Nope

#

Not til 17th 7PM GMT

proud aspen
#

guys can someone give me a hint about H1:Medium koth machine?

simple mountain
#

Do not provide or ask for help or hints for the Tokyo Ghoul room until 17th March, 7pm (GMT)

cloud perch
#

hey did anyone else have an issue with nmap running the script for finding the vulnerable plugins on badbyte

pure thistle
#

is the embargo on broker over with yet?

astral smelt
#

Yep

pure thistle
#

ok thanks I need a nudge i have a mqtt client running I've subscribed to the topic but not finding any info on how to retrieve the conversation from the broker what should I be googleing to find the command i need to use

pure thistle
hexed crescent
#

Research what wildcard can be used to subscribe to all topics in the broker.

pure thistle
white salmon
#

I dont rmemeber the client i've used but i remember that there was 5 messages looped s

stuck fractal
#

This channel is not for recommending that people read writeups

#

This channel is for hints, before looking at writeups.

white salmon
#

Then mqttfx is the way

hexed crescent
pure thistle
pure thistle
hexed crescent
#

You got the IP and port. The rest is fairly straightforward to figure out.

manic citrus
white salmon
pure thistle
worthy flame
#

Hi I am in introductory networking and have downloaded task files for Task 5. I haven't used Wireshark before and am having trouble loading these files. Any help appreciated.

stuck fractal
worthy flame
#

yes

#

It's on the attack machine

stuck fractal
#

Ok, so you need to get the files on the attackbox

#

Or download wireshark on your own machine

worthy flame
#

Yeah need to get them on attackbox

#

I have onot my machine and now need them on the box

high beacon
#

Ty @stuck fractal I got the CC Pentesting Task 10 completed. I had to use the attack box on the TryHackMe site. I couldn't get a shell with my Parrot VM. I could never get a LHOST address that worked.

stuck fractal
#

It needed to be your tryhackme VPN IP

#

tun0

high beacon
#

I use open VPN on my host and a Parrot VM. I tried ifconfig on both but neither of the ip addresses would work. the Tryhackmd vpn ip i got started with 10. but I couldnt get it yet.

stuck fractal
#

I mean you can run it on the host but then you need to port forward for the reverse shell port

#

And every other port you want to use.

#

Just run the VPN in the VM.

high beacon
#

ok i'll run the VPN on the VM. I guess the 172. address on the VM is just going to the host. I just started using VMPlayer

stuck fractal
#

I guess the 172. address on the VM is just going to the host That doesn't make much sense. The 172.16.x.x IP is probably from a NAT network in VMWare.

high beacon
#

does VMWare doen't conect directly to the internet does it? i was thinking it had to go trough the host OS to connect.

stuck fractal
#

It can be bridged to the network, but that isn't what I said

white salmon
#

For BadByte, are there any additional hints aside from "basic linux enumeration" for finding the users' old password?

short fox
white salmon
#

ah i found it. thanks @short fox !

cloud perch
# median reef what issues?

when ever i used the nmap --script http-wordpress-enum.nse --script-args search-limit=1500 -p 8080 127.0.0.1 -oA nmap/wpscanplugin it would take forever to scan but when i use nmap --script http-wordpress-enum.nse -p8080 127.0.0.1 -oA nmap/wpscanplugin it works fast

silver otter
#

do you get the same results?

#

I did a wp scrpt scan last night and it took a good 30 minutes to finish even with the script args

cloud perch
#

yeah i got the same results

median reef
#

by default the nmap scans less plugins

#

1500 is more then default so it can take long time

#

try using attackbox if you network connection is slow

#

it will help reducing the scan time

distant tartan
#

can i ask for the hints for the room hacked

stuck fractal
#

No

#

Well I guess writeups are approved but technically no

distant tartan
stuck fractal
#

Try harder

distant tartan
stuck fractal
#

Not what I meant but ok

distant tartan
#

i guess

#

i dont thiink he will give this advise

#

yes that what i meant when i said i'll find some thing

true widget
#

I need some help with privelege escalation to root in arcgangel.I found the binary also analysed it with ghidra.I have an idea but dont know how to implement it.Anyone wanna help?

cunning quartz
#

In how much time our writeup got verified?

trim haven
#

Depends on the room, creator, room age, write-up content etc.

#

Nobody can give an exact date.

stark owl
#

Hey guys, could anyone give me a little hint? I am stuck at question 16 from the Investigating Windows 3.0. The question is 'This is the default communication profile the agent used to connect to the attack machine. What attack framework was used? What is the name of the variable? (answer, answer)' Thanks!

true prairie
wise sundial
#

wut

true widget
candid nimbus
# stark owl Hey guys, could anyone give me a little hint? I am stuck at question 16 from the...

First thing is the two answers are the wrong way round from the question, so the framework is the second word. It's a well known tool which you should be able to identify with a bit of google. The variable refers to a value the attacker would have been asked to set when launching the attack, so you have to look at how the tool works (bit of an odd question since, as it says the attacker left it on the default setting but there you go)

stark owl
ionic cedar
#

hey guys could u help me here? task 6 from metasploit's room

stuck fractal
#

What do you see when you run ps?

ionic cedar
#

i use the ps command but doesn't show me any spool process

stuck fractal
#

You do not have a shell on the target

#

you need to run ps in a meterpreter

#

Because currently it's running ps on your local machine

#

On your kali.

ionic cedar
#

man but i did everything from task 5

stuck fractal
ionic cedar
#

But how do I know what I did wrong?

stuck fractal
#

You don't. That's why you ask for help.

ionic cedar
#

Ok

#

I noticed something weird

analog karma
#

hey, I'm on Skynet, got the user's password for smb share but as if it's not correct, I can't manage to log in

#

is there something else I'm missing here

proud scarabBOT
stuck fractal
#

Follow those instructions, screenshot what you're doing

mossy hazel
#

how can i open information.txt file

stuck fractal
#

Read up about smbclient

mossy hazel
#

i keep getting this message, any other hints??

stuck fractal
#

It has spaces

#

Spaces are used to seperate arguments for commands

mossy hazel
#

anything else to use beside escape character ""

wheat bison
#

Can anyone help me out from the last question of Task-6 of "REmux The Tmux"? I am stuck on this question from last few hours.

The question is: "How can you run the desired plugin after loading it?"

Thanks.

white salmon
#

Room badbyte

#

I am stuck on finding a CVE for RCE

#

Did nikto, wpscan, nmap

#

searched manually for it by wordpress version

#

still no clue what is the CVE

#

Can anybody help

candid nimbus
white salmon
#

Otherwise i really don't know what expanded nmap scan is

candid nimbus
white salmon
#

@candid nimbus oh damn i totally missed that even wondered what that parameter meant

#

thanks

#

found it finally tipsfedora

candid nimbus
ripe hedge
#

you can also try an aggressive plugin search with wp-scan but it takes a bit longer

#

nmap is probably better tbf

river fable
#

Hello all, Need some help. I am stuck in Pentest Task2 Nmap. in last there are around 4 questions, which answers i could not find on nmap chart and even not on google.

#

Can you please help me out ?

#

Question : How many ports are open on the machine?

analog karma
#

you need to scan the machine using nmap

#

check how many open ports from the scan results

tiny hare
#

I told the same in #room-help don't double post your question

river fable
#

Thank you Nick and Auger sir, i am doing it right now. Sorry as a new member , i did not know that where to post question.

tiny hare
#

Hey, maybe someone has idea why I can't see files downloaded with smb to my download folder:

#

server running in Downloads folder, but there is no subfolder kali

stuck fractal
#

You're in Kali.

#

They aren't the same filesystem

#

It's a VM. It has it's own filesystem.

#

Wait where are you looking?

tiny hare
#

I am expecting files in /home/kali/Downloads/kali

stuck fractal
#

Why?

#

The sharename is Kali

#

Not the local path.

tiny hare
#

aaaaa... thanks ๐Ÿ™‚

worn otter
#

So this isn't a specific room question, more of a generic rookie question. I've modified the php-reverse-shell.php with my tun0 IP and my listening port, and started nc -lvnp on that port. I upload the shell file to the ftp server, but it's not retaining the chmod I set it to before uploading (for a test, I tried chmod 777 before uploading, but it only has -rw--------- on the ftp server). When I open that page in the browser, nothing seems to happen, and my nc listener never connects. Am I missing something obvious?

worn otter
#

This was in the "h4cked" room. I completed it using a different method, so I don't need a hint for the room, just wondering if I'm missing a step with file permissions (or something else?) for reverse shells in general

cloud perch
sick sierra
#

You can upload your shell and modify its permissions afterwards. Chmod is a valid ftp command.

worn otter
#

hm. I thought I had tried that and it didn't work

#

maybe I used the wrong syntax

sick sierra
#

In that case I don't know, I did the room earlier today and could make it executable. I'm also pretty new at this. You could maybe try with +xmethod instead?

worn otter
#

I'll have to read up on that, I'm not familiar with it

#

As a general rule- what permissions need to be set for reverse shells? Does it depend on the type of shell? is read access enough, or is executable required?

cloud perch
worn otter
#

that must be the missing step. I didn't enter binary mode. I'm not familiar with that in ftp, so I'll have to do some reading

cloud perch
#

yeah i know i wasn't familiar with it as well i had to do some research the best part of learning

worn otter
#

Hence my name :). I've got a lot to learn

echo peak
ripe hedge
#

don't remember having to chmod the file

near torrent
#

https://tryhackme.com/room/vulnversity
In this room in Task 4 I have to use Burp to capture the request and then fuzzy the file formats. Even though I am using the formats specified in the task for fuzzing each of them are showing up as "Extension not supported". Then the checked the solution and found that the allowed extension is .phtml when I try that manually I can see that file of that extension is allowed but with Burp its showing "Not allowed"

#

Any idea what I could be doing wrong ? Or this an bug ?

#

When I try to fuzzy using repeater it seems to work but with intruder is seems to fail

stuck fractal
#

You don't want burp to encode the fullstop

near torrent
#

Ohh okay I will try that

unique lily
#

how much time does a machine takes to scan?

silver otter
#

well, using rustscan for me lately its been very fast

stuck fractal
#

Depends on the machine and scan type

silver otter
#

but yeah there are heaps of different types of 'scans' if you are nmapping all ports with default scripts it can take like 30-40 minutes

#

(maybe longer)

stark reef
#

For Inferno room, I can read here that the auto logout is intended behaviour. Is there a hint on how to go about this?

ripe hedge
#

try another shell

flint crescent
#

Hi!
Can someone help me out with

Hash: e5d8870e5bdd26602cab8dbe07a942c8669e56d6
Salt: tryhackme
I used this:
hashcat -m 110 e5d8870e5bdd26602cab8dbe07a942c8669e56d6:tryhackme /usr/share/wordlists/rockyou.txt
I don't know is it ok or not.

output:
Approaching final keyspace - workload adjusted.

Session..........: hashcat
Status...........: Exhausted
Hash.Name........: sha1($pass.$salt)
Hash.Target......: e5d8870e5bdd26602cab8dbe07a942c8669e56d6:tryhackme
Time.Started.....: Mon Mar 15 21:43:20 2021 (5 secs)
Time.Estimated...: Mon Mar 15 21:43:25 2021 (0 secs)
Guess.Base.......: File (/usr/share/wordlists/rockyou.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#1.........: 3246.5 kH/s (0.30ms) @ Accel:1024 Loops:1 Thr:1 Vec:8
Recovered........: 0/1 (0.00%) Digests
Progress.........: 14344385/14344385 (100.00%)
Rejected.........: 0/14344385 (0.00%)
Restore.Point....: 14344385/14344385 (100.00%)
Restore.Sub.#1...: Salt:0 Amplifier:0-1 Iteration:0-1
Candidates.#1....: $HEX[206b72697374656e616e6e65] -> $HEX[042a0337c2a156616d6f732103]

Started: Mon Mar 15 21:43:19 2021
Stopped: Mon Mar 15 21:43:26 2021

#

It's Crack the hash room

stuck fractal
#

If it's exhausted, then you probably need $salt.$pass here

#

exhausted means it ran through the whole wordlist and couldn't crack it

#

So either the wordlist doesn't container the password, or the pass/salt was the other way round in this case

flint crescent
#

so what will be the command

stuck fractal
#

I think you can work that out yourself.

livid reef
#

Hello

ripe hedge
livid reef
#

I'm just starting out with linux and I'm doing the challenges.

#

For the life of me, I cannot find where bob's history is being stored.

ripe hedge
#

history is generally stored in a particular file in the home directory, but it's usually hidden

livid reef
#

"HIDDEN" gotcha

#

thanks @ripe hedge

modest swift
#

ls -la

ripe hedge
#

it's a shy file ๐Ÿ™‚

flint crescent
#

after -m 160 it's work perfectly

ripe hedge
#

oh ok, it was an HMAC

coral summit
#

Hi
In lian yu rooms, i find the directory island/2100 and in this website source there is writing "you can avail your .ticket here but how? "

#

Can someone help?

livid reef
#

I found it can someone give me the quick answer "-la" is that list all?

ripe hedge
#

pretty much

ripe hedge
#

-l is long I think, -a is all

livid reef
#

makes sense

flint crescent
ripe hedge
#

-l use a long listing format

flint crescent
#

But i stuck with:

Hash: $6$aReallyHardSalt$6WKUTqzq.UQQmrm0p/T7MPpMbGNnzXPMAXi4bJMl9be.cfi3/qxIf.hsGpS41BqMhSrHVXgMpdjS6xeKZAs02.

Salt: aReallyHardSalt

Rounds: 5

stuck fractal
#

@steady stratus u at a PC RN?

steady stratus
#

Doing a bit of AWS stuff so I can get to w/e in a few mins

stuck fractal
#

On crack the hash, on that question, the number of rounds is wrong

ripe hedge
#

did you find the ticket?

coral summit
#

No

#

How can i find the ticket

ripe hedge
#

well it's a .ticket

#

probably want the rest of the filename

coral summit
#

But im still on the Web

ripe hedge
#

yup

#

how'd you find the 2100?

coral summit
#

Gobuster

ripe hedge
#

why not try that with the ticket?

coral summit
#

Okay

#

Update: i find it, thanks

ripe hedge
#

good hunting

flint crescent
#

?

stuck fractal
#

The default.

flint crescent
#

according to hashid it is sha512crypt

#

so should i add salt or not

flint crescent
livid reef
#

I would just like a hint if possible. I'm looking for where cron jobs are created. I see the location of where it's listed, not sure if it's the same place as it's being created

stuck fractal
#

Sha512 is salted out of the box

#

You just do not need to specify the salt separately because it is a part of the hash

flint crescent
#

I used
hashcat -a 0 -m 1800 '$6$aReallyHardSalt$6WKUTqzq.UQQmrm0p/T7MPpMbGNnzXPMAXi4bJMl9be.cfi3/qxIf.hsGpS41BqMhSrHVXgMpdjS6xeKZAs02.' /usr/share/wordlists/rockyou.txt

#

is it ok

stuck fractal
#

Did it work?

#

Stop asking if it's ok. If it worked, then it's OK. If it didn't work, then it's not OK.

#

This is a lab/learning environment

flint crescent
#

Its running .....

stuck fractal
#

Try things.

flint crescent
#

for the last 30 min it's running

ripe hedge
#

are you running hashcat in the VM?

worn otter
#

rookie question- I did an:
echo "$6$Tb/eum.......hash chars" > hash.txt
when I cat or subl that file, the $6$Tb/ is stripped off. Why is that? Those aren't escape chars, right?

stuck fractal
#

Used to access variables

ripe hedge
#

no but it's interpreting them as variables

#

use single quotes

flint crescent
#

VM

ripe hedge
flint crescent
#

I think that's why it is slow

worn otter
#

ah, I hadn't tried single quotes, or considered the vars injection. Thanks.

ripe hedge
#

run hashcat from the host, or use john in the VM

#

people say good things about collabcat

#

it took me 25 seconds with a GPU so...

flint crescent
ripe hedge
#

it's pretty deep in the wordlist

flint crescent
ripe hedge
#

yeah it's around the 3M mark

flint crescent
#

yeah

livid reef
#

Sorry to be a pest, did anyone get a chance glance at my question?

steady stratus
median reef
steady stratus
#

Do you know what the rounds should be by any curiosity? I'll take a look into it but I'm lazy w/ other things kekw

livid reef
median reef
#

๐Ÿคฃ

livid reef
#

Didn't want to spam the chat...

steady stratus
#

Appreciate you don't want to spam the chat -- but it's fast flowing in here and things get buried quick ๐Ÿ˜„

livid reef
#

I would just like a hint if possible. I'm looking for where cron jobs are created. I see the location of where it's listed, not sure if it's the same place as it's being created

trim haven
#

If you state your problem clearly, you will probably get the fastest response.

steady stratus
#

People aren't ignored intentionally

stuck fractal
#

The bare minimum of information you should give us when you're asking a question here is room, task, and question

steady stratus
#

I believe it's the same place as when you are creating them / writing them but as something like a .tmp

steady stratus
#

Ah, they're not in the same directory

#

but when writing they're stored temporarily

#

then when you save it, it'll be stored in the correct directory depending on the user you created it as

#

i.e. crontabs created as root will be stored separately to that created as say "cmnatic"

ripe hedge
#

there's also the crontab in /etc

livid reef
ripe hedge
#

flag probably won't be there directly

#

which room/task/question is this for?

#

We ask that you help us a bit so we can better help you ๐Ÿ™‚

livid reef
#

linux challenges flag 4

#

Flag 4 is located where cron jobs are created.

#

Thanks I'll list it the proper way, again, this literally my first day using the discord

pine reef
#

Hello i am trying to do LinuxAgency, i can not solve the question: What can you find on this service? I've rooted the machine and can prove it but it really bothers me that it shows that i have not completed the room

ripe hedge
pine reef
ripe hedge
#

LinuxAgency?

#

Because this is task 2

pine reef
#

Yeah you were right lol

#

I am sorry room name is GoldenEye

ripe hedge
#

ah, haven't done that one yet, sorry

stuck fractal
#

@pine reef if that's the question I think it is, it's a badly worded question

#

I don't know exactly what question you're asking about, but it might be the one that's actually asking 'what tool do you use to interact with this service'

#

Is it 6 characters?

slow slate
#

BTW, it is Q 5 of task 2.

pine reef
#

I'll take another look at it

#

Well you can find mails on that service, i am pretty sure that is the answer but it is not correct

slow slate
pine reef
#

Completed it, wth...

#

I am not even going to turning off my instance because i am so mad

#

๐Ÿ™‚

median reef
#

๐Ÿคฃ

opal vine
#

guys i'm stuck at golden eye room
i'm in the website as admin but i can't get a reverse shell

#

how can i do that?

worn otter
#

I haven't done that room, and I'm a rookie here myself. Are you able to upload files to a web server?

opal vine
worn otter
#

what's the file type? is this on a linux or windows machine? when you say 'click it', what program/window are you clicking in?

fickle bronze
glacial gust
#

you need to go to the page for the file

opal vine
fickle bronze
#

Yeah. There's no SSH but, there should be some other stuff...

#

Also.. If those creds donโ€™t seem to work, can you use another program to find other users and passwords? Maybe Hydra?

opal vine
fickle bronze
#

Which task are you on? You made it sound like you're still doing Task1?

opal vine
#

last question on task 3

#

i said im in as admin sorry if i wasn't clear

fickle bronze
#

Take a look into Aspell, the spell checker plugin.

#

And no, I think I just miss-understood ๐Ÿ˜›

opal vine
fickle bronze
#

|| what does the path look like... Maybe you can point it towards another program? ||

opal vine
#

i just have one question
in task 2 question 3 it says what service is runnning on port 55007 and it's pop3
i tried pop3 \ dovecot \ popt3d but none of these is the right answer

stuck fractal
#

On goldeneye?

#

It's asking for the program you use to access it.

#

I realise it shouldn't be

#

I reported it as a bug.

opal vine
#

yup thought so

cedar axle
#

@opal vine what does the service let you send?

#

or receive?

ripe hedge
#

I can't seem to get the reverse shell working on GoldenEye. not receiving any packets on the port I specified

cedar axle
#

try a different payload, maybe upload a binary

true widget
#

I am solving year of the rabbit room.But no able to get anything useful yet.NEED some help with initial enumeration.Anyone wanna give me a nudge?Thanks in advance๐Ÿ˜‰

wintry yarrow
#

Take a look with Burp.

ripe hedge
cedar axle
ripe hedge
#

I found the msf payload on exploitdb and then it clicked

#

reading through it

native mesa
#

anyone got OpenVAS to install on the attack box? I've tried pulling the docker image but it seems there is not sufficient space.

ripe hedge
#

it's a 7 GB image

steady stratus
#

copying a link of this: #room-bugs message

the attackbox is getting additional space as tools for the networks gets added but aye

#

I hope this clarifies things a bit better. I'll have a discussion with the owners on balancing the costs between making things accessible & the costs behind it

#

Obviously we wanna include as many tools as we can on the attackbox but it's not all that sustainable for both performance & costing esp. when things like OpenVAS is 7gb or something like that

native mesa
#

no probs, thanks for the clarification

steady stratus
#

I'm adding more storage space on the next push -- you might find that you can add the image okay

raw estuary
#

Hi, could someone help me? I'm doing the "Buffer Overflow Prep" room, in OVERFLOW5 when i run the command "!mona findmsp -distance 2400" it doesn't show the EIP offset, i tried to convert the address to obtain the offset with pattern_offset but it failed. In the writeups the command works ๐Ÿ˜ฆ

earnest plover
#

Happy St. Patrick's Day Everyone. I'm hoping someone can point me in the right direction here. Working on the Windows10privesc room and I'm getting stuck with Task 11 and dumping out the hashes from the SYSTEM and SAM files I copied onto my Kali Linux VM. The step tells me to use the creddump7.git repository but I'm not able to locate/install python-crypto and in turn not able to run the "python2 creddump7/pwdump.py STSTEM SAM" command. Is there an alternative way for me to dump these hashes?

stuck fractal
#

There's a python3 version, or you can use secretsdump from impacket @earnest plover

earnest plover
opal vine
#

i think you are talking about question 5 from task 2
but i'm talking about question 3 from the same task

simple mountain
#

Do not provide or ask for help or hints for the VulnNet room until 20th March, 7pm (GMT)

past cargo
#

Currently stuck on looking glass. I would really appreciate a gentle push in the right direction, as i am out of ideas and have basically been staring at the screen for two hours now.
I was able to obtain the user flag.
What I have so far:

||- Tweedledum and Tweedledee users can invoke bash shells under each others UIDs

  • Password for humptydumpty can be found in the tweedledum home directory
  • There are execution permissions on alice's home directory but no read permissions. I was thinking maybe one could try to bruteforce binaries in there but i dropped that idea
  • The onlty thing that seems to distinguish humptydumpty is the poetry.txt but I cannot make use of it
  • no further valuable sudo permissions , crontabs, SUIDs, ||
stuck fractal
past cargo
#

||you mean the one containing the password for humptydumpty? yes||

stuck fractal
#

Ok, check file permissions. Linpeas should catch something there.

stuck fractal
#

No

#

You can talk the creator, perhaps, but don't ask here

white salmon
#

@fierce stratus DM me if you have any questions

past cargo
stuck fractal
#

What do you mean?

#

it listens on 0.0.0.0:8000, running a HTTP server

#

You then need to GET the file from it

astral smelt
#

read the pins please

grizzled trench
#

oh ok

#

oh sorry my bad

patent scaffold
#

Got a question with the upload vulnerabilities room

#

Everything is going well but everytime I upload something I get a 500 error. Even when I just upload a legit, accepted image it's not accepted and I get a 500 error

#

Is it broken or is it supposed to be that way?

ripe hedge
cedar axle
opal vine
stuck fractal
#

It's not asking for the port

#

It's asking for the program you use to interact with it

#

It's a question that needs fixing

cedar axle
stuck fractal
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

cloud perch
#

hey has anyone done vulnnet yet

stuck fractal
proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

cloud perch
#

ive done my research dude

stuck fractal
# cloud perch ive done my research dude

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

cloud perch
#

awww i see my bad

opal vine
stuck fractal
#

I reported this as a bug a while back

twilit rampart
#

Hello, in "Brainstorm" machine, the answer to open ports is higher than the number that I'm getting.. I've checked a write up and he is getting the same port number. Am I missing something?

coral summit
#

Hello in basic pentesting, rooms asking me what is username how can i find it, i Just know these username first Letter is k and j

cold oracle
#

u gotta enum more

coral summit
#

The question is what is the username

cold oracle
#

try using a tool called enum4linux

#

it will show u some interesting users

coral summit
#

Okay im going to try, thanks

cold oracle
#

๐Ÿ˜„

coral summit
cloud perch
#

good dont be afraid of using the write ups remember its all about learning

lament tusk
#

Hello do you know if there is any writeup for room investigating windows 3 ?

silver otter
#

3, is that like 98?

astral smelt
lament tusk
#

Ah ok will keep struggling with it then

#

Just a few questions left unsolved

astral smelt
#

I tested the room, so if you need help lemme know ๐Ÿ™‚

lament tusk
#

There is one question regarding the attack framework and the variable used that I didnt get

#

As per my understanding it is empire that is used

#

But i tried many answers, without any woot woot

candid nimbus
lament tusk
#

Will try it asap. Thanks !

cloud perch
#

just finishing rooting VulnNet great room

#

im going to be posting a video on youtube on VulnNet on Monday if the creator is okay with the time line to post a walk through

austere mortar
#

Hey newbie here, doing the nmap room, at the praticle, i'm ask to do a TCP SYN scan of thye first 5000 ports. doing it with the switches -sS -Pn -p 0-4990 but still see 0 ports open. Is there something i did't understood with how to run a TCP SYN scan ?

stuck fractal
#

!docs verify

proud scarabBOT
stuck fractal
#

Follow those instructions, then you can send a screenshot

ionic cedar
#

hey guys I'm in task 9 from network services 2 and I got stuck here cause I don't know what is the username or password could you help me?

stuck fractal
#

You are given it in the task

#

Read back through the MySQL tasks.

ionic cedar
#

oh so the username is root and the password is "password" I thought that was an example lol. Sorry for that question haha

austere mortar
#

@stuck fractal here it is

stuck fractal
#

Checked your VPN?

austere mortar
#

looked like the open vpn command worked but apparently not ... gonna try to fix that thanks

austere mortar
#

checked and I have correctly set up the vpn but still have the same output

ionic cedar
#

hey guys I'm in the task 10 from network services 2. I usa trying to crack the password of carl from the hash but it has take more than an hour so I don't know if i did something wrong

glacial gust
#

you need to specify a wordlist or it will use a default list

cedar axle
#

incremental ASCII will crack any password, if you have a lifetime to wait for it

lament tusk
# candid nimbus The questions and answer are the wrong way round.

I tried my luck this morning with a few answers but still not able to get the correct one. Also stucked with one of the last question regarding the reg key being queried by attacker, I tested all the ones I could find in Procmon at 6:07 but no match โ˜น๏ธ

near torrent
#

https://tryhackme.com/room/kenobi
I have a doubt regarding the Kenobi room. So in Task 1 there is an question to find the open ports on the system did an scan and got 11 ports open but the correct answer is 7. Is this a bug or am I doing something wrong ?

lament tusk
#

I guess it's because it is asking a basic nmap scan (without the -p- switch)

true widget
#

how can I enumerate bolt cms version?

#

coudnt find the version.php filesadcooctus

candid nimbus
cedar axle
lament tusk
#

Thanks for the hints guys. Will look into that this evening.

#

Maybe I will do Empire room first.

cedar axle
#

probably not a bad idea

silver otter
#

I'm trying to do Brainstorm - I've got the file(s) from the host and transferred to a windows 7 VM, however it just quits instantly instead of running like I'd expect

#

I feel like this isn't supposed to be the challenge of the room kekwsanta

white salmon
#

You got the .dil file too?

#

Run that chatserver as administrator and on your machine do "nc {your windows machine IP} 9999"

#

I did this and it's working fine

#

@silver otter

silver otter
#

I got the dll file too, and when I run it, admin or not, it just quits straight away

#

re-downloaded it too and same issue hmm

white salmon
#

I ran that chatserver file as an administrator

#

And it works fine for me

#

Firewall and windows defender should be ๐Ÿ“ด

silver otter
#

yep both off, i'll try some more stuff later and maybe try on my main pc lol

rugged flame
#

can someone give me one more hint for "OWASP top 10" task 19
I watched all files, but didn't find anything helpful

stuck fractal
#

@rugged flame You need to do more than look at the files on the box. Search the internet, find the documentation and source code

rugged flame
#

for what do i need a documentation ?

stuck fractal
#

You'll know when you read it. ยฏ\_(ใƒ„)_/ยฏ

rugged flame
#

hah, ok=)

#

oh, it was so easy task(

rotund talon
#

can someone help?

quiet stump
loud ledge
#

yep

stuck fractal
#

Also, please state the room and task and question as basic info

loud ledge
#

its blue

quiet stump
#

... That too

stuck fractal
#

Seeing as we have no idea what the question is asking about without it

stuck fractal
rotund talon
#

rpwebscanning

#

its task 2 first question

loud ledge
stuck fractal
rotund talon
#

i have

#

legit looked everywhere

stuck fractal
#

Read the manuals

loud ledge
#

any hints for room blue im stuck at

[-] 10.10.162.126:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[-] 10.10.162.126:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=FAIL-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[-] 10.10.162.126:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
stuck fractal
#

You should verify with the bot

#

Then you can post screenshots

#

Then run show options and screenshot the output

#

Ok, did you see where I said screenshot?

loud ledge
#

ok ill do it

river musk
#

Room: Upload vulnerabilities
**Task: 9 **
you will need to access the shell directly using its URI. What does this mean? should I use the full file path??

trim haven
#

Yes, it does.

#

You need to access the file directly.

#

Just like in Linux when running a binary you type ./path/to/binary.extension

river musk
#

but its either asking to download or open the file

trim haven
#

Hm, did you follow the instructions correctly?

river musk
#

I did

trim haven
#

Would you be able to provide a screenshot that includes the pop-up please:)

river musk
trim haven
#

Magic as in ||Magic Bytes||?

#

Sorry it's a while since I completed the room.

storm venture
#

has anyone done Tokyo Ghoul?
just want to discuss privesc
I've done it
but really enjoyed it, want to see alternate methods

astral smelt
#

Sure you can dm me about it

trim haven
#

Hmm

#

I don't have any notes on this room and there are no write-ups.
Please make sure the file extension is correct and you are navigating to the correct URI.

#

Not only that but it says that the script is a php script, in the room magic seems to be magic bytes, if I am not mistaken.

#

Make sure the magic bytes are correctly setup on the file.

river musk
#

i got it

#

I mean , my payload is working . The mistake is, I've used ||4 characters(AAAA)|| instead ||6(AAAAAA)||

#

@trim haven thank you

trim haven
#

No problemo

candid nimbus
storm venture
candid nimbus
#

๐Ÿ‘

storm venture
#

I've had a little SSTI exploitation experience, in Flask/Jinja specifically

#

so that helped a little, but thanks

storm venture
#

ah

#

have you found

#

the interesting directory

#

in the ftp

#

@white salmon

storm venture
#

oh sure, lemme know if you want a pointer when you get back to it

steady elm
#

I am trying to root bad-byte room and stuck at finding users password, i tried enumerating for config files, history, linpeas, linenum, then opt dir or backup dir. But i am not able to figure it out any hint will be appreciated...

distant tartan
#

i am doing tokyo ghoul but after logging as anonymous in the ftp server i am not able to get the second file from need help dir

ivory kernel
#

room name : magician

#

y couldn;t i upload ??? it's not accepting it ? any help ?

acoustic steppe
distant tartan
#

thanks for your help

acoustic steppe
acoustic steppe
ivory kernel
#

yes i got link which led me to imagetricks vuln

acoustic steppe
ivory kernel
#

yea done .. applied and created file testv.png and trying to upload it's not getting uploaded

#

i tried normal png that's also not getting uploaded

acoustic steppe
acoustic steppe
ivory kernel
#

sure leemme do it

acoustic steppe
worthy flame
#

Introductory Networking/traceroute. When I enter traceroute into Attack Box it says traceroute command not found. Help

true widget
#

hi guys. I am solving startup.I got the initial foothold to the box and also found pcap file.But I m not very good with wireshark.Am I heading the correct way??

shrewd mortar
#

Hello, how can I find the path of that 404.php file?

white salmon
#

for wordpress i suggest to take an actual page that is on the site and add a random letter in the URI

shrewd mortar
storm venture
#

my go to is creating/editing a plugin which is malicious

#

that usually works

white salmon
#

Just add a php rev shell into 404 and ur goos

#

Good

#

U can also do /wp-themes/theme/404 if im not wrong

shrewd mortar
#

or /wp-content/theme/404.php

white salmon
#

How to execute an exe file provided for reverse engineering ?
I am trying REloaded challenge for reverse engineering in try hack me
I tried wine, but I can't able to run the file which I patched!!

#

Thanks

ripe hedge
#

Can you run it it windows?

white salmon
#

I mostly use linux. So I didn't tried

#

I want it to run in my parrot os

#

I can't get you bro

#

I patched but, I want to make it run to get flag

#

For the first two challenges it was done by string and ghidra decompiled code. So, I didn't faced any issue. But for the third one I need to patch and run

#

I patched but I feeling difficulty in executing

candid nimbus
# white salmon I mostly use linux. So I didn't tried

To be honest, in the great scheme of things, it may well be easier to set yourself up with a windows vm. It'll be useful for malware analysis and buffer overflow boxes as well. Or...you can actually find all the flags on that box without running anything.

white salmon
#

No bro

ripe hedge
#

Having a windows VM is always useful

short fox
solid radish
#

hello hello, i'm working on room "fuel". i've acquired a low level shell, can anyone give me a hint on the privesc?

#

i've tried linpeas and 2 kernel exploits so far which didnt work

storm venture
#

sure

#

@solid radish as in, the ignite room?

solid radish
storm venture
#

sure, pm

radiant saddle
#

what is rear!?

pure thistle
#

i need help with Golden Eye I only have one question left to complete the room its task2 question 3

Inspect port 55007, what services is configured to use this port?

what do they mean by services?

stuck fractal
radiant saddle
#

Ok thanksblobheart

opal vine
pure thistle
#

oh ok thanks

pure thistle
opal vine
#

happy to help

fast cave
#

How do I figure out "Based on the title returned to us, what do we think this port could be used for?" <- network services

#

nvm I figured it out, I had to use ||telnet ip port|| but if there is another solution I would greatly appreciate to know it :-)

near trench
#

heya, I'm on the wireshark 101 room, task 7 for ARP traffic. The question is "What 4 packets are Reply packets?" though I'm not exactly sure how to pinpoint reply packets specifically

edit: solved, so there isnt any way to filter specifically for ARP replies, if I just filtered normally for "arp" and looked at the info section its pretty self explanatory and the replies stand out.

pine reef
#

Can we ask hints for Enterprise?

wintry yarrow
#

Nope, 72 hours have not passed yet.

astral smelt
balmy verge
#

Oh so write ups are allowed ?

astral smelt
#

Not sure about writeups but you can submit an unlisted one to the room

#

Then it will get accepted or denied depending on if spooky wants writeups on ut or not

balmy verge
#

I would have to make the video public tho would that be ok ?!

astral smelt
#

Hmm not sure @last nova you ok with this? ^^

rose cove
#

Which layer of the TCP/IP model will traceroute run on by default (Windows)? please help me anyone

floral osprey
#

I'm on the linxbackdoors (https://tryhackme.com/room/linuxbackdoors) room i finished it but I can't find pam_unix.so on my machine other than "/usr/lib/x86_64-/usr/lib/x86_64-linux-gnu/security/pam_unix.so" that is not editable is this normal ?

last nova
#

cc @balmy verge including video

hexed crescent
#

It's Madness.

azure escarp
#

Hint for "The Impossible Challenge" room? I'm stuck at the start

mint cypress
#

hint plz: Yara room, one question left: Task 11: valhalla:
Besides .PHP, what other extension is recorded for this file?

#

tried txt, .js, not correct !

regal marten
#

Could I get from hint on Pickle Rick? I've found the login page and the username and right now I'm trying to do a brute force attack via burp and parsing the responses but no luck so far. I thought there maybe was some easy sqli to bypass the login and I've tried some variant of ' OR 1=1-- without success. Could I get a pointer? I'll give the brute force some more time. (beginner)

worn otter
#

did you look in /assets?

regal marten
#

yes but I missed the interesting info the first time I looked. thank you, a good hint. Will get on it! ๐Ÿ™‚

worn otter
#

my notes on this one aren't super detailed, that might not be helpful

#

I need a little help on the Magician room. I've created a png using metasploit (expolit/unix/fileformat/imagemagick_delegate) with my vpn ip and port. I upload that to the site (/etc/hosts is modified). But my nc listener isn't getting hit. Did I miss a step?

ripe hedge
#

haven't tried using that

#

I needed a 2 stage payload

worn otter
#

burp?

ripe hedge
#

no

#

downloaded the payload via wget

#

there should be an example in the research material

#

at least I never got it working properly with a single payload

worn otter
#

so I did just get my metasploit-generated png to call back and open a reverse shell, single payload

#

the only thing that I did differently was adding the msf option 'target = 1', which was not a visible option in msf, but was mentioned in a guide I read

worn otter
#

I've found the flag and cleared the room. I've noticed that the output format varies on each load of the page. I'm trying to find all decoding methods. binary/ascii, base64, but not sure about the other two.

pine marten
#

anyone got enterprise ? i got username and password but stuck

balmy verge
#

@last nova Hey, just submitted the write-up, sorry if i butchered a lot of stuff ๐Ÿ˜„

last nova
balmy verge
last nova
balmy verge
pine marten
#

wow didn't see that coming ๐Ÿ˜„ thanks for the videos

cedar axle
true widget
#

can I get a hint on brooklyn nine nine?Does it require stego?

white salmon
#

Can i get a hint for Year Of The Fox? I'm not getting anything. I tried ||to enumerate the smb and i found a share but is unnacessible with anonymous login, i found the username fox and i tried to brute the web and the smb with hydra. Then with wfuzz i tried to search some files or directories on the website but nothing.||

#

UPDATE: ||i found a new username named rascal and now trying to brute web||

twilit mantle
#

Hi there, just wanted to check about something in the "Introductory Networking" room.

In regards to Task 6 Ping, the final question asks "What switch would give you a more verbose output?". I've gone through 'ping man' and tried 'ping --help' and the only switch I can see (that seems to tick this box) is -v but TryHackMe states it is the wrong answer.

Am I blind and missing something or is it a bug?

last nova
twilit mantle
#

Thank you

last nova
#

haha, it's an anti-brute forcing technique

twilit mantle
pine reef
#

Is anyone having issues connecting over rdp on the room Enterprise? i've tried xfreerdp and remmina but both do not work, once xfreerdp worked but it was unusable. Now i am getting: Timeout waiting for activation, i've tried resetting the room but that has not helped

stuck fractal
#

@edgy inlet @pine reef It's looking like it's a lack of resources, fix will be coming soon

pine reef
#

Great, thank you for the fast reply

edgy inlet
#

Thank you .. Ok i thought the problem was with vpn. And i delete my favorite server ๐Ÿ˜ซ

pine marten
#

anyone got hint on virtual plant ?

stuck fractal
#

That's a brand new challenge room, so rule 13 applies here. No help/hints for 72hours after release

#

@simple mountain Wanna do your messages for it?

grim shard
#

Hi Hello! I'm working on jurassicpark and am having trouble finding the third flag.

#

I was hoping someone might be happy to nudge me in the right direction. I've found all the other flags with a simple find command

simple mountain
#

Do not provide or ask for help or hints for the Attacking ICS Plant #2 room until 24th March, 7pm (GMT)

sharp viper
#

hi

halcyon bison
#

hey guys can somone help me with linuzz room?

stuck fractal
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
halcyon bison
#

yeah k, if someone can help me with lunizz room priv esc to mason user would be fantastic.

lament tusk
candid nimbus
# lament tusk I finaly found it after doing Empire and What the shell rooms :) Do you have by ...

Good work digging that out! The only hint I can give you for that last is that I found it by identifying what had to be the value before the space (by size)and then filtering on that. Even then I had to scroll through a fair few entries until I found the right one. Apart from being the right length it didn't really leap out at me. Unsatisfactory and I'm sure there must be something more scientific but unless someone's prepared to explain I haven't a clue ๐Ÿ˜Ž๐Ÿคช

lament tusk
white salmon
halcyon bison
#

the intended one

#

i was checking the write up to be sure and the path is the right one

white salmon
#

Coz most of us did the other way with sudo vulnerability exploit...the reason the decrypt the the bcrypt was taking a longer time using rockyou

halcyon bison
#

nono i made that part

#

i would like not to use the sudo exploit

#

i hist have problem with the "lights" pssw

white salmon
halcyon bison
#

just*

white salmon
#

You got the Name of the place?

halcyon bison
#

yeah

white salmon
#

So that's the pass of mason

halcyon bison
#

yeah but also no ahahaha, i know thats it, but it does give me "auth error"

#

can i dm you?

coral summit
#

In bounty hacker, i cant being root. I did ssh connect

stuck fractal
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
coral summit
#

Im stuck in priv esc

stuck fractal
#

Ok. So what have you tried so far?

coral summit
#

I did connect the ssh and i upload linpeas, i try to crack id_rsa but not worked

#

Also there is the name of tar Vulnerability , i used gtfobins but not working Just shell

stuck fractal
#

So you know you're exploiting the right thing

#

So maybe screenshot what you're doing and what's going wrong?

coral summit
#

@stuck fractal

stuck fractal
#

||Sudo tar|| was the correct path

#

That is not.

coral summit
#

then its asking me what is sudo password

#

sudo tar -cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh

#

you mean this right ?

stuck fractal
#

Yes.

#

Don't you have the user's password?

coral summit
#

wait

#

oh gosh

#

im feeling dumb rn

coral summit
lament tusk
pine reef
worn otter
balmy verge
#

Hey, are hints allowed for the new OSINT room ?

astral smelt
#

Yep, it's a walkthroguh

uneven bane
#

I got a question on the OSINT one

worn otter
#

42

balmy verge
#

cool, im stuck on the ||pastebin || part would appreciate a little nudge ๐Ÿ™‚

uneven bane
#

same

#

hahah

worn otter
#

which room is this? I don't recall that off the top of my head. Don't have my notes in front of me, but I might be thinking of a different room

balmy verge
#

came out tonight

#

didn't get announced tho

worn otter
#

link?

astral smelt
worn otter
#

ah, okay. Thanks. Sorry, I haven't done that one, I was thinking of a different room

vague birch
balmy verge
#

@obsidian briar Hey, can we have a sanity check here ? seems like a few people are stuck on this part of your box, are we missing something ?!

vague birch
#

Thanks

rustic sphinx
#

Let me check the link

#

Yup it's invalid

#

I'll DM him

stuck fractal
#

Haha it's your friend OK

obsidian briar
#

It's funny because it was working a week ago when I demo'd it for some people , must've been unarchived really recently

balmy verge
steady stratus
#

But yeah -- gimmie a shout once you get this sorted and I'll post it somewhere more permanent in lieu of relying on pastebin/etc

obsidian briar
steady stratus
#

Awesome stuff

obsidian briar
steady stratus
#

Can I DM you real quick if you could spare the time please?

obsidian briar
#

Absolutely!

steady stratus
#

Gnarly ๐Ÿค™

#

Thanks for being so quick with this

obsidian briar
#

Of course!

obsidian briar
balmy verge
obsidian briar
worn otter
#

on the ccpentesting room, task 20, final question there, syntax for smbmap. I'm wondering if the question prompt is outdated for the answer format. Looking at the number of asterisks, it doesn't match what I think it should be. Nothing I've tried so far has been valid.

glacial gust
#

how many asterisks are you off

worn otter
#

2 on each of the larger blocks. I've also tried surrounding each arg with single quotes, no dice

glacial gust
#

try double

worn otter
#

yep, that's what it was. Thanks

glacial gust
#

np

vague birch
obsidian briar
junior walrus
#

anyone know why network services task 3 question on what sticks out is "Profiles"? Trying to understand why profiles is something that would stick out after performing a an nmap scan or enum4linux scan..

stuck fractal
junior walrus
#

is this determined under the share enumeration portion of the enum4linux scan?

stuck fractal
#

Is what determined?

#

The fact it's non default is not determined there, but that's where you're shown the share

junior walrus
#

so if you were familiar with default windows shares , you would then know that profiles share is not one of them?

stuck fractal
#

It doesn't end in a $, for one

#

Not default windows shares. Default SMB shares.

junior walrus
#

Roger. Thanks for pointing me in the right direction. much appreciated!

sand mesa
#

Check the shadowban API. What is the value of "search"?

I got stucked in the above question from KaffeeSec - SoMeSINT Room
any nudge would be much appreciated

stark reef
#

I'm not sure we're allowed to help with this room yet

#

If any mod can confirm or deny, then I can give you a hint

trim haven
#

Yup ^

#

@sand mesa Please respect rule 13 ๐Ÿ™‚

sand mesa
#

ok sorry... i thought it was a walkthrough..
np..

trim haven
#

If it is a walkthrough room, then my bad ๐Ÿ˜„

#

Lemme check

#

It is a walkthrough room, my bad. Hints are allowed.

sand mesa
#

thanks jabba

stark reef
#

@sand mesa did you use the tool that was hinted at in the description?

sand mesa
#

yeah but it is failing to search

stark reef
#

make sure you put quotes around

#

then it should search

sand mesa
#

thanks @stark reef
shall i dm?

stark reef
#

you're welcome

#

dm what?

silver meteor
#

i said except using onesixtyone or smbclient cuz u have to have a clue to use them while nmap shows nothing on that ports or maybe i'm wrong & u have to check everything (sure it is)

bold crow
#

In room SteelMountain - completed the exploit & privesc for the no-MSF section, but I can't figure out one of the questions to get 100%. Had some ideas, but none of them are accepted. Anyone willing to share via DM? Thanks! ๐Ÿ˜„
"What powershell -c command could we run to manually find out the service name? "

obsidian zenith
#

@opal vine Hey enigma, I'm at the final part of the rootme room. I managed to get the weird file, now I just need to get root.txt

#

I read from somewhere I need to exploit this SUID file, I tried looking around and got a python command, doesn't work though

opal vine
#

ok that's nice

#

search inside it for python
and do the commands in the SUID section

obsidian zenith
#

yeah i did that, idk why it didnt work

#

:/

opal vine
#

what was you full command

#

paste it here

obsidian zenith
#

python -c 'import os; os.execl("/bin/sh", "sh", "-p")'

opal vine
#

that seems right

#

what is the full path for the python SUID

#

are you sure you are not root rn?
by typing whomai

obsidian zenith
#

oh for fucks sake

#

it says im root LMAO ALL THIS TIME

#

finally finished the room

#

i think i should write notes on it

opal vine
#

yup that happened because the command gave you an sh shell instead of bash and you can't see the current user
that's why you need to check what user are you in as after running such commands

opal vine
#

happy hacking

obsidian zenith
#

thanks for the help

#

:)

opal vine
#

no worries, you can always hit me up

glossy solar
#

Hi!

#

Has anyone completed /easyctf ?

stark reef
#

@glossy solar Just ask your question instead. chances are most of us completed it

glossy solar
#

I managed to find out myself. Turned out i found correct exploit (SQL Injection) but for wrong service, so I couldn't get correct CVE

stark reef
#

Ah even better then ๐Ÿ™‚

storm venture
#

am I allowed to ask for a hint for pyLon here?

#

haven't seen anything in pinned

silver otter
#

if it's a CTF, as a general rule not for 72 hrs

#

ESQY does the pins but I guess he must sleep sometimes, the fiend!

white salmon
#

Where can I get the info?

silver otter
#

i dunno if i'm supposed to help you, but maybe read the Task from the beginning

white salmon
#

it was hiding in plain sight, guess I shouldn't skim anything

silver otter
#

not if you then go and ask for help ๐Ÿ˜„

#

a lot of the time no THM for questions like that, they are to prove you read and understood the text, if they require external answers they may say "research required"

#

(not a solid rule but fairly common)

simple mountain
#

Do not provide or ask for help or hints for the pyLon room until 27th March, 7pm (GMT)

storm venture
#

๐Ÿ˜…

silk zenith
#

New pyLon room was tricky, well back at it tomorrow i guess ๐Ÿ˜›

reef burrow
#

anyone up for a nudge on tokyo ghoul?

astral smelt
#

Which part are you at and what have you tried?

white salmon
obsidian briar
# white salmon i think it's broken again

How so?

Edit: The links are definitely woking, I think you're referring to the room. It's been temporarily taken down for reasons I'm not completely aware of and will be back up when that's resolved ๐Ÿ˜„

faint wasp
#

Loving pylon so far! TBC tomorrow...

short fox
worn otter
#

I'm working on the challenge in the uploadvulns room. I've made a small (<10kb) image file, when I attempt to upload it, I'm getting a 500 internal server error response back. Did I break the server, or is this expected behavior?

#

I've already intercepted the ||upload.js|| and removed the three checks there

#

I've also uploaded a txt file renamed as a jpg, and get back a 200 success, but so far, my manual and gobuster attempts to find it aren't revealing anything

#

hm, okay. Uploading a 2kb valid jpg gets a 200 back. still can't find it though

worn otter
#

okay, I'm an idiot. I was looking in the root path, not ||/content||. I haven't seen a way to make gobuster scan recursively. Does that feature exist?

naive tapir
#

I am finishing up the Crypto101 course and am stuck on the GPG challenge. I am trying to run - /opt/john/run/gpg2john tryhackme.key > hash,, but an error - Error: No hash was generated for tryhackme.key, ensure that the input file contains a single private key only.

#

Any hints please?

worn otter
#

sorry, faithsec, I don't know. Haven't done that room.

#

that's on my plan for tomorrow

hollow lynx
#

pyLon box moved private but still reach to it โฏ ping 10.10.189.173 PING 10.10.189.173 (10.10.189.173) 56(84) bytes of data. 64 bytes from 10.10.189.173: icmp_seq=1 ttl=63 time=223 ms 64 bytes from 10.10.189.173: icmp_seq=2 ttl=63 time=647 ms 64 bytes from 10.10.189.173: icmp_seq=3 ttl=63 time=466 ms ๐Ÿ˜‚ ๐Ÿ˜…

naive tapir
worn otter
#

Yeah, I do that too sometimes.

grim swan
#

Am i supposed to be psychic?

white salmon
#

In the room Brooklyn-99,

When I run steghide extract -sf brooklyn99.jpg on the image, it returns "could not uncompress data. Compressed data is corrupted" did I download the image wrong or is there something else I'm doing wrong here?

grim swan
#

Maybe you can try to re-download the image

white salmon
#

Yeah I tried using wget too, but gave same error

#

I downloaded it both by going to <Machine IP>/brooklyn99.jpg (where the source said it was being sourced from), and by doing wget http://<machine ip>/brooklyn99.jpg

digital iris
grim swan
digital iris
grim swan
#

Thanks for helping, but i still can't see what word it wants me to use.

The question is what rainbow tables are effective against, and as it says in the paragraph it says that it is effective when an attacker tries to crack a large number of passwords. In my head the answer then should've been "To crack a large number of passwords".

digital iris
grim swan
#

Omg..

#

lol

balmy verge
#

@obsidian briar Hey, just submitted my write-up ๐Ÿ™‚