#room-hints

1 messages · Page 89 of 1

lyric sierra
#

has anyone played the M4tr1x: Exit Denied room yet?

white salmon
#

Hello everyone, I was working in the Web Enumeration room and can't for the life of me discover and vhosts with gobuster. I tired nearly all the SecList DNS lists as well as the directory medium list. I also tied from within the attackbox. Any suggestions or tips would be appreciated

stuck fractal
proud scarabBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability and don't spam the chat if you don't get an answer to your question immediately. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

white salmon
#

Ah sorry too fresh

stuck fractal
#

It was a reply to D3f4ult

stark pebble
stuck fractal
#

Remember, no help or hints on that room yet

stark pebble
#

Yup..

solar topaz
white salmon
#

Maddingly frustrating. Fairly certain I have and nothing works.

civic jungle
#

Is there a message size limit in this chat? The message that I'm sending keeps disappearing after ~0.5 sec after (the message is a bit big, contains detailed explanation of what I'm stuck with)

wanton wharf
#

You can try splitting it in a couple messages

civic jungle
#

Hi everyone, I'm following Linux PrivEsc room and am currently stuck at task 7 in understanding what's exactly happening there. The question-message is a bit big and I think that's why I'm not able to directly send it here (links are restricted too). Can I please DM someone who's familiar with .so files and the way the are loaded?

solar topaz
white salmon
#

Hi. The Fortitude Intrusion Prevention prevents me from entering a correct answer to the Burp Intruder question in the OWASP Juice Shop room in the total beginner course. Any clues? The answer format clearly suggests I have the correct answer.

stuck fractal
coral crest
#

Having troubles with [Severity 8] Insecure Deserialization - Code Execution - don't know if its necat not listening to port 4444 but have tried using port 1234 no luck capturing the flag. I need help to complete the task.

white salmon
#

pls i need a hint from the gods on the Pickle Rick room ive been stuck for days but I really dont wanna look at the writeup

#

I've found the username for the ||/login/|| page, and ran multiple directory fuzzings on the IP address but I cannot for the life of me find anything

#

I know it's vulnerable to ||XSS|| but I'm not sure how that will really help me?

white salmon
#

REE i figured it out god damn that was simpler than I thought

distant tartan
#

why am i not able to change directory

stuck fractal
#

Because it has spaces in it

fringe zephyr
#

You need " around the name of the folder

distant tartan
fringe zephyr
#

don't worry 🙂

balmy crystal
#

Hi, emm, id like some hint for the room Upload Vulnerabilities, task 8. Im pretty stuck with extensions

#

Plzz

#

F

balmy crystal
#

Ok, already done that one

potent quail
#

I’ve worked most of the way through Different Ctf. I have a shell as WWW-data and pretty much know how to go from user to root, but unsure how to get to user. I have one idea to try tomorrow (||internal SSH brute force||) but if that doesn’t work then I’m stuck big time. Any nudges please?

normal vortex
#

For “Different CTF”, I got write access but I dont think it has to do with the site, so I cannot get a shell from there. Got access to the website admin panel, couldnt get anywhere tho. Have been stuck for a few days, feel like I’m missing something really stupid. Any help would be appreciated.

severe wave
#

Hi, any hints for web to user escalation for Different CTF? tried su and ssh bruteforcing, pspy, lse etc...

fossil python
#

Got web-flag in different ctf... very interesting room. I like it.

high onyx
#

For "Different CTF", can anyone give a little hint for finding the secret folder?

potent quail
potent quail
solar topaz
#

@potent quail any hint for getting a www-data shell? I tried a couple of methods but they haven't worked.

potent quail
#

||enumerate PHPmyadmin database and tables fully - don’t skip anything ||

solar topaz
#

Thanks!

potent quail
#

No worries

#

From there I’m stuck lol

white salmon
#

watchdog so am i

magic leaf
#

so, I don't necessarily need the answer but there is a three letter prefix in room "OWASP Top 10" on task 21. I have the name but that prefix is NOWHERE to be found.

severe wave
#

i have a suspicion

red minnow
potent quail
#

same here

split steeple
#

Currently on room Relevant in the pentesting path. Found and enumerated shares. Found passwords file. Decoded and found some credentials to something. Tried to remmina on with the credentials, but no luck. Tried accessing the other shares with the passwords, but nohing. I've run gobuster on the webserver, but only getting server error pages (can these be used for something?). Would love a hint.

true tusk
lyric lichen
#

in the different ctf room, i found the hidden directory and im pretty sure that i have to somehow gain access to the php my admin... I tried with Hydra and the wordlist that is given but couldnt find any passwords, do i have to try something else or am I just doing something wrong with hydra?? would love a hint

potent quail
#

you need to enumerate more @lyric lichen

#

the hidden directroy... ||why is there an image and a wordlist in there ? ||

lyric lichen
#

ok thanks i'll try a few things

simple mountain
#

thanks @distant grail

white salmon
severe wave
#

Hi Wim, I will DM you, still stuck though

white salmon
slate siren
#

Hey! Just stuck on Physical Security Intro room. Does anybody know the answer?

An improperly hung door which opens away from you can be bypassed using this type of tool?

distant grail
#

Go look at your door. When you shut it towards you, what way is the handle thing that goes into the door pointing?

slate siren
#

right way in my case

distant grail
slate siren
#

It is two words, first - 8 letters, 2nd - 4

distant grail
#

Should look like this

#

Now what do you think you could do to open that door if you can access the lock

slate siren
#

hm

#

just try to pick it

#

maybe insert some plastic

distant grail
#

Close

slate siren
#

twisted pair should also work

#

i don`t really know(

distant grail
#

It's a 4 letter word

sleek hawk
#

For different CTF - Stupid question - but once we have the phpmyadmin creds, how do we find the login? Just directory brute force or something else?

slate siren
distant grail
#

Unless it's changed your right

slate siren
distant grail
#

Ahhhh

#

This looks like a bug

slate siren
#

got it

white salmon
#

And Wam please make sure if you have more questions for different CTF please ask in #834061534639685643

sleek hawk
glacial gust
slate siren
#

Google says me nothing

glacial gust
#

lookup a Shrum Tool

slate siren
#

Ohhh

#

Finally

#

After 2 hours of searching

#

And there is one more question, that i have no idea what to answer.

#

Adams Rite hardware fixtures are susceptible to a bypass where a wire is snaked through the keyway and actuates the locking mechanism behind it, what could prevent this bypass?

#

It's 9 letter word

glacial gust
#

think of something that a knight carries to defend themselves

slate siren
#

Shield? Sword?

glacial gust
#

defense, and add an ing to the end

slate siren
#

That's not armor right?

stuck fractal
#

Please don't post answers by the way

slate siren
#

Sorry(

slate siren
glacial gust
#

something a knight carries for defense, and you will need to add "ing" to the end of the word

slate siren
#

Hm

glacial gust
#

Captain America also uses one

slate siren
#

You should have said it earlier))

#

Thank you so much!

worn otter
distant grail
#

Not the answer we needed but yeah sure I guess

worn otter
#

This is the hints channel. I didn't want to give what I thought the answer is 🙂

silk wedge
ripe hedge
#

Deviant talks about it in the video

fallow viper
#

Anyone did NFS task 3?

#

I keep getting access denied when trying to mount

#

sudo mount -t nfs 10.10.216.129:share /tmp/mount/ -nolock -vvvv

mount.nfs: timeout set for Wed Apr 21 03:02:26 2021
mount.nfs: trying text-based options 'lock,vers=4.2,addr=10.10.216.129,clientaddr=10.10.177.12'
mount.nfs: mount(2): No such file or directory
mount.nfs: trying text-based options 'lock,addr=10.10.216.129'
mount.nfs: prog 100003, trying vers=3, prot=6
mount.nfs: trying 10.10.216.129 prog 100003 vers 3 prot TCP port 2049
mount.nfs: prog 100005, trying vers=3, prot=17
mount.nfs: trying 10.10.216.129 prog 100005 vers 3 prot UDP port 36696
mount.nfs: mount(2): Permission denied
mount.nfs: access denied by server while mounting 10.10.216.129:share

stuck fractal
#

Make sure the VPN is running directly in your VM.
That's also not the correct export name, use the one you got from showmount

abstract bear
gusty kite
gusty kite
abstract bear
#

oh look like i missed those thing. will have alook

fallow brook
#

anyone on windowsctf

astral smelt
fallow brook
astral smelt
#

Yep

fallow brook
#

ok that's why that bruteforce is not working

fallow brook
green minnowBOT
#

Gave +1 Rep to @astral smelt

honest kiln
#

Hello

#

I'm new here 😀

silent narwhal
#

Hello, welcome to the tryhackme. How are you today?

honest kiln
#

Very well

silent narwhal
#

so do you need help?

honest kiln
#

I guessed you're fine too

#

Yes I do

silent narwhal
honest kiln
#

I could root overpass1

silent narwhal
honest kiln
#

I mean I couldn't root overpass1

green minnowBOT
#

Gave +1 Rep to @silent narwhal

silent narwhal
#

if you need any help about something, you can dm me freely!

honest kiln
#

Sure

dusk hemlock
#

Im trying to root the box in the vuneversity room using the script that abuses SUID from GTFObins, but the script doesnt seem to be working

#

after I execute it the /bin/bash program is supposed to have rws privileges, but it doesnt. Any ideas?

#

forget it

silver otter
clever charm
barren mesa
#

i was trying to run directory scan on specify directory and find extension file ... i ran gobuster command and used -x and used differnet wordlist still not getting any extension

halcyon flume
#

guys im at room DifferentCTF and i checked all attacking vectors i can use here to use the username and password i got but nothing works, maybe im in the wrong direction? Its task 2, flag 1

clever charm
halcyon flume
#

Yep forgot to enumerate files in the directory... was so focused on cracking the user with the wordlist i got

halcyon flume
#

is it suppose to be with an ordinary dir/file list

lyric ember
#

/room/bpsplunk:
Task 2 Can you dig it?

When viewing search results, it's often useful to rename fields using user-provided tables of values. What command do we include within a search to do this?
Answer Format: ******```
#

I'm not finding the desired answer for this.
Other than performing a function as defining the output 'AS' <newlabel> --- any hints?

white salmon
#

Th0rn ....check search examples

lyric ember
#

@white salmon thank you! That worked. I really don't think that should be the answer though... at all...

green minnowBOT
#

Gave +1 Rep to @rigid smelt

lyric ember
#

I also don't see how that's different from rename:
What command do we include within a search to do this?
Since the answer also requires a pipe and isn't inline with the search.

#

In fact I'm 99% certain that the author pasted the wrong answer and then defended it rather than change it.

white salmon
#

Ig the rename is causing problems there

#

rename should be replaced by locate?

lyric ember
#

the "correct" answer is used to reference an external source in order to "rename" a value...

#

and that's not that command's purpose

#

renaming isn't anyway... you could use it for that very roundaboutly... but it's a pretty bad question to check someone's knowledge of splunk commands.

#

goddamnit

#

I take it back

#

I didn't thoroughly read the question

#

i still think it could be worded better...

white salmon
#

This is what you want?

lyric ember
#

but I should've gotten it from "user-provided tables of values"

#

Yes

#

Yes please

white salmon
#

Go ahead and report this as a literature in #room-bugs

lyric ember
#

will do - and thank you again for the help!

white salmon
#

With room name task and question number with the error

quiet ginkgo
zinc gale
#

Anyone around who could help with OWASP Top 10?

worn otter
#

just ask, somebody might be able to help

zinc gale
#

I'm working on task 5. Machine deployed. It's asking for the version of Ubuntu. Answers format ..*. I am passing uname -v and get #102-Ubuntu SMP Mon May 11 10:07:26 UTC 2020 which clearly doesn't match the format. It looks like the kernel release but that is 4.15.0. Also tried 04.15.0 but it didn't work either. Any thoughts or iss this a bug?

#

answer format xx.xx.x

cedar axle
zinc gale
#

ok. I can pass ls so I'll look there. Thanks.

#

@cedar axle perfect. Thanks. I was focused on uname. Didn't know that file existed. Thanks again.

green minnowBOT
#

Gave +1 Rep to @cedar axle

hard karma
#

I'm stuck on https://tryhackme.com/room/introtonetworking section whois.
Microsoft has anonymized data via Markmonitor, and the Whois data for neither MS or Markmonitor publish location, technical contact, etc. that are the required answers.
Is this a bug, or do I need to find the information elsewhere other than Whois data (or am I not using whois right, but I've used it for years)

worn otter
silver otter
cedar axle
zinc gale
# worn otter There's also an nmap flag to scan for version info

I had already tried that. It hadn't been able to provide the details needed. But since I had command injection I was too focused on uname. cat /etc/os-release spat out just what I needed. But yeah, that nmap -O flag usually gives me what I need. It's just they crafted the room to force using command injection. And I learned something. So yay.

worn otter
#

I don't have my notes in front of me and don't recall how I did that part of the room (it was a lot of steps). But I don't recall doing the /etc/os-release route

#

I think the nmap flag is -V but I'd have to look it up

cedar axle
worn otter
#

Undoubtedly

zinc gale
#

I may have used the wrong nmap flag. But with help from @cedar axle I learned something new. Either way it's all good.

worn otter
#

Yep, I was just mentioning that in case you hadn't thought of it

zinc gale
#

I appreciate it. Believe me, I've got lots to learn.

worn otter
#

me too. Hence the name 🙂

zinc gale
#

lol

lofty sapphire
#

HI, I'm kind of newbie, kindly apologize if this question is dumb, I'm working on this Different CTF Room (Adana) in Tryhackme and I'm badly stuck after gaining access in the wordpress

#

On the room it says I need to create a reverse shell, but it says file is not writable in the plugin and the theme

#

I can do xss but even that isn't fruitful

#

kindly help me in telling where am I going wrong to create the shell

cedar axle
lofty sapphire
#

yeah, tried that too, but it didn't work out

#

I used the chmod u+s in the cli

#

and tried using the filezilla

cedar axle
lofty sapphire
#

you mean 755?

cedar axle
#

yeah

lofty sapphire
#

I tried the same too

#

but let me login to the room again to try it

cedar axle
lofty sapphire
#

no, I didn't

#

how to find the vhost?

#

using nmap?

#

I'm really sorry if it is a dumb question

#

I've just started my part on this side

cedar axle
#

notice there are 2 databases?

lofty sapphire
#

I'm really sorry for the late response

#

yes sir

#

there are 2 databases

#

let me check it now

mossy drift
#

I want help with retro room

#

The machine is disconnecting every other minute

stuck fractal
#

!vpnscript

proud scarabBOT
distant tartan
#

i am doing hackpack whle using hydra optional added cokkie also why is that so ??

stuck fractal
#

You need to match the format that the server expects

tribal mountain
green minnowBOT
#

Gave +1 Rep to @stuck fractal

stuck fractal
#

I have no idea what the context on this is, but I will happily accept your thanks

bold lichen
#

what does this mean

#

do i have to tell the golf name ?

nocturne arch
#

you need to research it

#

just find the place on maps and look at the near places

bold lichen
#

oh okay thanks

nocturne arch
#

i'm sure you'll find it, it isn't that hard at all

bold lichen
#

thats what i was wondering did it really ask me

#

golf club name near the place

#

ahha

#

nice

nocturne arch
#

yeah i was looking at it too :D

#

well power of research

bold lichen
#

yep

#

whois

#

is so strong i never knew

#

it gave literally a customer care number

nocturne arch
#

if you'd like to know more about researching try some google dorking rooms

bold lichen
#

for the sites

bold lichen
#

i did it last year and

#

i am starting back again

#

since i had no clue how ctf ever worked now

#

i am enjoying it

#

alot

nocturne arch
#

well good luck !

bold lichen
#

have been engaged

#

in couple of them

#

@nocturne arch thx for the help

green minnowBOT
#

Gave +1 Rep to @nocturne arch

nocturne arch
bold lichen
#

cool will do for sure

dawn isle
#
Task (3): Privilege Escalation
Question: Upload your binary and replace the legitimate one. Then restart the program to get a shell as root. 

Hello there, could you gimme some hint about it? I tried to delete the .exe in C:\Program Files (x86)\IObit\Advanced SystemCare\ but I don't have access to it, I also tried stopping the process killing the pid in meterpreter, but I can't do that either.

Reading this: Upload your binary and replace the legitimate one. Then restart the program to get a shell as root. I've assumed that maybe I could change the service's path, but not sure how to do it, any hints? Thanks!

dry briar
#

ok,so im in the introductory research room. the question is

What is the CVE for the 2020 Cross-Site Scripting (XSS) vulnerability found in WPForms?
my answer "2020-10385 "

#

oops i didnt mean to push enter yet😅 Anyway so i looked it up because i was confident in my answer and it still tells me im wrong. Is the format not correct or am i just wrong?

dawn isle
#

CVE-...

#

I mean, your answer is right be sure you put CVE- before

dry briar
green minnowBOT
#

Gave +1 Rep to @dawn isle

worn otter
#

Pro-tip: always look at the flag format- it gives you a hint as to the structure (dashes, periods, location of spaces, etc.)

dry briar
green minnowBOT
#

Gave +1 Rep to @worn otter

dawn isle
dry briar
green minnowBOT
#

Gave +1 Rep to @dawn isle

dawn isle
#

you can paste it with ctrl+v

dry briar
dry briar
dawn isle
#

You need to copy the picture at least

worn otter
#

you need to verify before you can post screenshots

#

!docs verify

proud scarabBOT
dawn isle
#

Oh

dawn isle
worn otter
dry briar
#

oh okay, ill get on that

storm robin
dawn isle
green minnowBOT
#

Gave +1 Rep to @storm robin

hard karma
#

@cedar axle and @silver otter the web version of Whois gives me what I need. So I need to research the cmdline version more. Thank you!

green minnowBOT
#

Gave +1 Rep to @cedar axle

silver otter
hard karma
#

can I paste the output in here?about 20 lines

silver otter
#

if you put it in tags it will make it look more readable but yeah you probably can

#

` tags

hard karma
#

` $ whois microsoft.com
Domain Name: MICROSOFT.COM
Registry Domain ID: 2724960_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.markmonitor.com
Registrar URL: http://www.markmonitor.com
Updated Date: 2021-03-12T23:25:32Z
Creation Date: 1991-05-02T04:00:00Z
Registry Expiry Date: 2022-05-03T04:00:00Z
Registrar: MarkMonitor Inc.
Registrar IANA ID: 292
Registrar Abuse Contact Email: abusecomplaints@markmonitor.com
Registrar Abuse Contact Phone: +1.2083895740
Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
Domain Status: serverDeleteProhibited https://icann.org/epp#serverDeleteProhibited
Domain Status: serverTransferProhibited https://icann.org/epp#serverTransferProhibited
Domain Status: serverUpdateProhibited https://icann.org/epp#serverUpdateProhibited
Name Server: NS1-205.AZURE-DNS.COM
Name Server: NS2-205.AZURE-DNS.NET
Name Server: NS3-205.AZURE-DNS.ORG
Name Server: NS4-205.AZURE-DNS.INFO
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/

Last update of whois database: 2021-04-24T00:53:16Z <<<

For more information on Whois status codes, please visit https://icann.org/epp
`

silver otter
#

hmm intersting, mine keeps going after that

#

what do you get if you do whois --version

hard karma
#

mine has a lot more after, but it is just NOTICE wanring and TERMS OF USE, etc

silver otter
#

it shouldn't be

hard karma
#

5.2.11

silver otter
#

after the "Terms of Use" section

#

The Registry database contains ONLY .COM, .NET, .EDU domains and Registrars. Domain Name: microsoft.com Registry Domain ID: 2724960_DOMAIN_COM-VRSN

#

this is what I get after "Terms of Use" section

#

and it leads into all the answers

#

my whois is Version 5.5.6.

hard karma
#

yeah my registry iID and stuff is at he top. let me try to update Whois. OR play with switches 🙂

silver otter
#

no

#

it has two sections with that

hard karma
#

ah - yep I definitely have just the 1 section

silver otter
#

ok yeah, try update whois I guess

#

can you paste me the entire output as a .txt file in dm?

#

I'd be curious to see

autumn relic
#

I have a question and hopefully someone can help

#

I'm currently in the Cracking a Zip hash section. The file that I downloaded from THM doesn't have a zip extension.

#

so when I use zip2john I'm not sure what the filename should be that I want to crack

#

the file is named zip. That is it

worn otter
#

Just a guess, I haven't done that room, but maybe you have to rename the file?

autumn relic
#

I don't know. I'm stuck.

worn otter
#

if it's a walkthrough room, re-read the instructions. You probably missed a step

autumn relic
#

ok. I just renamed it zip.zip. I will try that thx

stuck fractal
#

Yeah it's a bug with THM atm, with downloads being incorrectly named

autumn relic
#

renaming it .zip worked! Thx

#

there were some other rooms I could not finish because the file they wanted me to download literally doesn't exit

#

exist

severe crag
#

hy

feral parrot
#

Has anyone completed Windows Investgiations 3.0? I am Stuck at What was the path for the first image loaded for the process identified in Q's 19 & 20?

dry scroll
#

Is there any easier way to do wireshark101 task 11 regarding question 4: Looking at the data stream what is the full request URI from packet 18? I couldnt find a non trunceated version and have to build it out of the blocks I could see. Surely theres an option to show the full non shortened version?

high hinge
#

hey guys, can anyone do a code verify for me on my script for buffer overflow prep overflow1? I just really cannot figure out why the program is still crashing?

#

I have all the badchars just cannot figure out why its crashing

silver otter
#

I have like 3 mins if you can post ur exploit I can see if I can spot anything else dm me and I'll get back to you in 12hrs or so when I get back to my pc

acoustic mirage
#

can anybody help me with year of the jellyfish

#

@anyone

astral smelt
hard karma
#

@cedar axle and @silver otter thank you again, I found the issue.
Apparently now there are "thick" and "thin" whois requests. Clients are supposed to initially request the thin details (what I was seeing) and then contact the official Whois server for the registrar for more detailed info.
I am able to get the needed info by doing the initial whois query, getting the domain Whois server, then running 'whois -h" (whois host name).
Or by telnetting to it on port 43 and typing "microsoft.com" 🙂

green minnowBOT
#

Gave +1 Rep to @cedar axle

cedar axle
bold lichen
#

i need help with html injection

#

room

#

i am not understandin g

#

on what i am suppose to do

spring nacelle
#

hi people, anyone able to help on the mitre room ? having issues with task 6 question 3 big time lol

#

@steady stratus , @slim fractal @hexed crescent have any of you had problems come up about this before ?

spring nacelle
#

or @trim haven

trim haven
#

Hey please avoid pinging TryHackMe staff, we are all very busy

spring nacelle
#

sorry

#

my first time on here

#

thanks anyway

dry briar
#

ok so im in "Introductory Research Walkthrough" specifically task 4 "manual pages. The question is "

SCP is a tool used to copy files from one computer to another.
What switch would you use to copy an entire directory?" i dont see anything else in the man page so i chose "-3" but thats incorrect so is my problem syntax or is that simply not the ight answer?

#

this is the man page and my answer

stuck fractal
#

Yeah that definitely doesn't sound correct

#

You can scroll through the manual, use your arrow keys

dry briar
#

-3 Copies between two remote hosts are transferred through the local host. Without this option the data is copied directly
between the two remote hosts. Note that this option disables the progress meter.

dry briar
green minnowBOT
#

Gave +1 Rep to @stuck fractal

copper patrol
#

guys i am doing internal room and i am trying to bruteforce the jenkins form

#

so i used hydra and here is my command:

#

hydra -l admin -P /usr/share/wordlists/rockyou.txt -s 6767 localhost http-post-form "/j_acegi_security_check:j_username=admin&j_password=^PASS^&from=%2F&Submit=Sign+in:H=JSESSIONID.66f1d4a8=node0idaxpl7k62fw1mmhys0j7mqil0.node0:Invalid username or password" -V -t 4 -I

storm robin
#

Anyone know why ‘No service workers found’ is showing up in the Overpass website, I feel dumb

copper patrol
#

it just hangs after having tried once. if i do -t 64 after 64 tries, if -t 4 after 4 tris etc

stuck fractal
copper patrol
#

then i installed wfuzz, after disperetly looking at the internet and discovering that neither one guy that made a walkthrough about that room did function it with thm attack box

stuck fractal
#

If you're reading writeups already, please ask in #room-help because you're a little further than hints

copper patrol
#

"Note: Due to some weird reasons I couldn't able to crack using THM attacker machine. I deployed my on kali machine on vm and then it worked."

copper patrol
#

ok

storm robin
#

I curl’d to it and got what I was looking for

#

Now ssh2john don’t want to install 🐸

iron token
#

Hi! Can someone give me some hint how to find the "User flag" in the Django room?

desert sedge
#

Having an issue with HackPack room if anyone is available? Been at this for a couple hours....

bold lichen
green minnowBOT
#

Gave +1 Rep to @spring nacelle

plain sonnet
#

@limpid jolt

#

Whats the problem?

limpid jolt
#

got the answer buddy

#

will hàve to redeploy the machine

hard karma
cedar axle
green minnowBOT
#

Gave +1 Rep to @hard karma

kindred ore
#

any one Different CTF

last cipher
acoustic mirage
#

There is a problem in the box anthem I couldn't login with the credentials

#

on rdp and on /umbraco

#

anyone

#

@anyone

#

AAH GOTCHA!!!!!!!

white salmon
#

can someone help on vulnnet:dotjar?

opal vine
bold lichen
#

hey guys

#

this is off topic

#

related to cryptography

#

so i have two images

stuck fractal
#

If it's not for a tryhackme room, please do not use this channel

bold lichen
#

okay sorry about that , what room should i ask my doubt in ?

stuck fractal
dark otter
#

Hi all

#

I am new to try hack me

#

Can anyone help me to enumerate over machine to get the information ?

#

@here

wintry yarrow
#

~~Ask in #room-hints and ~~don't try to use @ here its disabled.

wintry yarrow
kindred ore
dry briar
#

im trying to run the binary and says permission denied, am i misunderstanding what i am supposed to do or am i giving the command incorrectly? TIA

stuck fractal
#

That is an empty text file that you just created

dry briar
#

i tried loacating the file "shiba1" and cant seemto find it.

stuck fractal
#

You are currently not using the target machine

#

You are currently on the attackbox

dry briar
#

ooooh... lol thanks I'll uh.. spin that sucker up 🤦‍♂️
thank you

dry briar
stuck fractal
#

For Linux Fundamentals 1, you have split screen access to the target machine

#

You might need to click "Show Split Screen" along the top

dry briar
#

no i know, i mean do i need both the attack machine and target running at the same time or just the target?

stuck fractal
#

You have split screen access, I don't see what you could need the attackbox for?

#

You can spin the attackbox up if you need it

dry briar
#

thats what i was asking, if i needed the attack box for anything. doesnt seem so.
thanks

dry scroll
#

I've installed john the ripper via
sudo apt-get install john -y

#

but the john command doesnt work

#

the room doesnt say any other commands, tried installing it other ways

stuck fractal
#

What distro? What room?

dry scroll
#

kali linux

#

networkservices 2

#

i used man john

#

and it comes up

#

oh nvm my machine just crashed I think

#

I should say its through THM kali box, ill try again

stuck fractal
#

Then it already has John the ripper installed

dry scroll
#

aye, but whenever I use john it says command not found. The man page said john -a would work but bash: command not found

#

ill retry it now the machine has restarted

stuck fractal
#

Screenshots.

dry scroll
#

sorry was restarting the kali machine

stuck fractal
#

sudo john

dry scroll
#

ahh

#

ofcourse

stuck fractal
#

It's not in your PATH, that's the issue

#

It doesn't need to run as root really

dry scroll
green minnowBOT
#

Gave +1 Rep to @stuck fractal

stuck fractal
#

No no no

#

Less sudo

dry scroll
#

I mean, try adn use it to see if it fixes small issues like this

#

no?

#

or be more wary of it?

stuck fractal
#

It's important to learn where you need it and where you don't

dry scroll
#

fair, ill pay more attention to that. I'll look up sudo and paths and stuff. Try and wrap my head around when and where the command is needed

wise ore
#

anyone completed agentsudoctf ?

stuck fractal
#

Just ask your question please

#

Always best to directly ask

wise ore
#

How you redirect yourself to a secret page? i don't know what is means

pure thistle
storm robin
#

What’s the problem xD, it’s asking what the file extensions are

white salmon
#

hey! I need some hints about physical penetration intro room, please 🙂 I am stuck on how to prevent attack on Adams-RIte, and with what to open wrongly hung door which open away (two words). I am googling and stuff, but I am not getting any closer, haha.

silver otter
green minnowBOT
#

Gave +1 Rep to @silver otter

silver otter
#

for the first one, honestly this could have 100 names and the one the room author chose is kinda 'ok'

white salmon
#

I know, haha, I found many already and no luck so far 😄 but I will check the video 🙂

silver otter
#

the other one I can give a wordplay hint if you want? I don't really know how to find a resource without giving away the answer

white salmon
silver otter
#

another plural/doing word for 'protecting' something, usually physically

white salmon
#

thank you!

silver otter
#

gl 🙂

white salmon
#

OMG, I got it! I would die and not find it by myself, haha. The Adams one was also kind of 'not standard'. But, cool. I learned a lot around. Thanks for help!

silver otter
#

glad to help

white salmon
#

My mistake was looking for more 'specialised', 'professional' names. Funny thing that there are many things which fit to both.

silver otter
#

yeah I had the same problem the door hanging one i tried a different name for like 100 times, exact same tool though

#

and the other one was just too obscure, if you search the internet for the actual answer i never even found it, even searching with the answer

white salmon
#

But, not bad, not bad. I like challenging things. These vids were awesome, and I learned many things during my research. 🙂

silver otter
#

yeah it was a great room overall, and great videos

pure thistle
pure thistle
#

and its the last question I have to answer to complete the room

glacial gust
pure thistle
green minnowBOT
#

Gave +1 Rep to @glacial gust

opal vine
#

hi guys i'm trying to solve this room https://tryhackme.com/room/musicalstego
i can't get the link from the audio like there's something but i can't read it i tried a lot of spectogram frequencies but i still can't tell what's in there

dusky plinth
#

Hey there, I am doing the NMAP Room of Networking Fundamentals in Complete Beginner. The task is to answer why the first 999 Ports are opend or filtered. My idea is that their is a firewall which answers with an ICMP unreachable packet. unfortunately i do not know what to fill in the field. It says the answer will be in my scan results, but i cant find it. Maybe because of my bad english. sry. I used the following to scan the machine. nmap -sX -vvv -f -p0-998 10.10.197.175

worn otter
#

look at the format of the answer field- the *** give an idea as to what it should look like

#

look for a similar structure in the scan results, if that's what the hint suggests

stuck fractal
#

Don't you also need -Pn there? I don't know if you're scanning from the attackbox

dusky plinth
#

yes i do

stuck fractal
#

Also, yeah, it's not because of ICMP Port Unreachable messages here

dusky plinth
#

the answer format is **....

#

oh ok then i think i will repeat the lesson

#

thx

silver otter
dusky plinth
#

There is a reason given for this -- what is it?

#

and the first one was this: Perform an Xmas scan on the first 999 ports of the target -- how many ports are shown to be open or filtered?

silver otter
#

did you answer the first one?

dusky plinth
#

yes its 999

silver otter
#

ok, I think the answer will be in your results you just might need to recognise it

dusky plinth
#

also in the correct format?

silver otter
#

I believe so, two letters then eight letters

dusky plinth
#

i will search _ 😄 thx

#

it was so obv. thank you so much

tawny lava
#

HELLO FRIENDS, THERE IS A NEW ROOM CALLED OSQUERY, I ONLY MISS ONE QUESTION TO FINISH THE CYBER DEFENSE CENTER COURSE, I'M STUCK 3 DAYS AGO ON A QUESTION HAHAHAH
Sorry for the capital letters xD
I have all the other answers in the room in case anyone needs them
😄

balmy crystal
#

hello

#

which question?

#

@tawny lava

tawny lava
#

I finished it, thank you very much 😄

#

in the same way I cannot obtain the certificate because mem say that we have to wait for the new rooms to be published 😰

balmy crystal
#

Ou

#

F

#

Congrats anyways! @tawny lava

tawny lava
#

thanks bro

white salmon
#

Any hints for finding flag 2 on Avengers Blog Room Task 3? (FOUND IT, man that was well hidden)

civic oar
#

I am stuck in safezone room. I did login as admin and tried to inject a php for RCE but nothing after cmd command runs and can not get a reverse shell. Any help would be appreciated.

civic oar
#

@distant tartan I’ll send the screen shot in a moment

gloomy jolt
#

YOTJF hint here ?

astral smelt
quartz moat
#

Hello i have a question about one of the questions on the java script task 3

last cipher
#

room?

tiny hare
#

Hey, how to download folder from windows machine? I uploaded nc.exe but it looks like it downloading only one by one. I need to download whole firefox profile.

white salmon
#

what room u doing?

tiny hare
white salmon
#

Yeah I haven't done that room cant help sorry lol

tiny hare
#

now I have files what sed is useful by WinPEAS

ripe hedge
#

that looks wrong

#

pretty sure it wants the whole profile

keen nova
#

I'm struggling so hard with the last flag on the Telnet section of the Network Services room. I feel really dumb right now. I need to get up and move around and maybe let my brain try to reset I think. I have no clue wtf I'm doing wrong.

white salmon
#

which part?

#

the exploiting is just based on you getting a shell from msfvenom so you cant get the flag unless u get the shell

keen nova
# white salmon which part?

I've had luck with everything up until the end. I run nc -lvp 4444 and then I copy/paste the msfvenom payloat in the telnet session after .RUN and it does nothing.

white salmon
#

u set the rport?

keen nova
#

No. I'm gonna just step away for a bit and start the Telnet lesson over I think.

#

I just realized I haven't eaten anything of any substance today. That may not be helping my brain to function lol

white salmon
#

I think you may be forgetting to put .RUN in the telnet session

#

or your msfvenom payload just has the wrong tun0 ip/you're listening on the wrong port

keen nova
#

Maybe. Thanks for those hints.

keen nova
#

Any ideas why the telnet welcome message isn't coming through? It came through when I went through this process last time...

white salmon
#

uh what fixed that for me was to terminate machine and re telnet

#

happens if u telnet to it to much i think

keen nova
#

Okay, thanks. Maybe this is related to why I wasn't having any luck before! I think I've extended this machine by an hour 3 times now, lol.

#

That fixed that problem! Thanks @white salmon!

green minnowBOT
#

Gave +1 Rep to @dull imp

white salmon
#

np

karmic atlas
#

Hi. Can someone help me get the password for shiba4? I know where the binary is and I have to create a directoy called "test". I tried mkdir and also ln but both don't work for me

white salmon
#

you know where the binary is so run it by doing ./

karmic atlas
#

okay thank you

white salmon
#

hello I am trying to do the zero logon room but i cannot install impacket from the kali attackbox :

#

root@kali:~# python3 -m pip install virtualenv
/usr/bin/python3: No module named pip

white salmon
#

of course, sorry!

#

thanks.

quartz moat
#

So my question is about the java script. It asks you to add your script to make it say “Hack the Planet” so i did that but what do i need to put in the answer box? I can’t seem to figure it out

last cipher
#

room?

ashen moon
quartz moat
#

After i put the script on the bottom the HTML title changes to Hack the planet as asked but nothing else shows up

ashen moon
quartz moat
#

Yes that is the room im on

ashen moon
#

you should get something like that

ashen moon
quartz moat
#

Ok I’ll try it now thanks

#

Thank i did it.

ripe hedge
#

gj!

cyan gyro
#

Im new to kali and cyber security and ethical hacking and i need help learning stuff

#

Can anyone help?

#

?

ashen moon
pale rampart
#

Hello

#

Please, help with hints for room ISO27001

#

I've completed everything, but 2 questions

#

Task 5 - Controls and domains

#
  1. If i talk about "A.9.2.4" Managment of secret authentication information of users" i talking about an...
  2. What is the name of the "Operations security" i talking about an...
pale rampart
#

Anyone plz

crystal delta
#

Anyone know how to terminate a machine if you don't have the terminate button?

brave vale
versed solstice
#

never mind

#

i got it

maiden rover
#

i am solving {{Buffer Overflow Prep
}} lab but i got stuck on task 10 i am putting right badchar but is showing my answer is wrong

ripe hedge
pale rampart
ripe hedge
#

so research 🙂

pale rampart
#

This is very weird research question, where you should find a "word"

ripe hedge
#

read the task then

pale rampart
#

Telling you as certified ISO27001 LA 🙂

pale rampart
ripe hedge
#

there are 3 categories mentioned

#

the whole room has issues, mind you

pale rampart
#

Ok, completed

ripe hedge
pale rampart
#

Thx

dry briar
#

can anyone tell me what i did wrong here?

stuck fractal
#

Yes. You cat'd the binary.

#

You also probably broke it because you wrote to the binary.

steep swift
#

stuck on mitre module
could someone help me out

steep swift
#

guys plz look into this bug

stuck fractal
#

Not a bug, please don't post answers in the #room-hints channel

#

@steep swift

steep swift
#

will keep in mind next time
meanwhile what should i do?
cause my whole room is stuck just cause of one question

stuck fractal
#

It's not meterpreter. Meterpreter is one component of a larger bit of software

white salmon
#

Anyone?

Peak Hill room

frail rain
#

pip install the module? Any results on Stackoverflow?

white salmon
#

No module found

#

Stack said pycrypto

#

But pip install is getting executed for python3 modules

versed solstice
#

"Using Get-WinEvent and XPath, what is the query to find WLMS events with a System Time of 2020-12-15T01:09:08.940277500Z?" i still havent found the right syntax, i've been searching all over

frail rain
white salmon
green minnowBOT
#

Gave +1 Rep to @frail rain

white salmon
#

It was just that last L in pass was giving syntax error

frail rain
#

Ur initial error was module not found...

#

Ah well.

versed solstice
#

"Using Get-WinEvent and XPath, what is the query to find WLMS events with a System Time of 2020-12-15T01:09:08.940277500Z?" could someone help me craft the right syntax ive been searching for a while and really want to quit...

#

never mind i found it

paper raft
#

Hello Guys, I am completely beginner is that ok to Start learning in the TRYHACKME ?

clever charm
#

yep

#

i suggest you to buy the subs cuz it will give you lots of path that teach you not only the basic but also something plus

paper raft
green minnowBOT
#

Gave +1 Rep to @clever charm

clever charm
paper raft
clever charm
#

Read writeups

#

Another website is picoctf

#

That has very benighted ctf

somber wave
#

hi guyz

clever charm
#

There is also htb academy

somber wave
#

can i get some hint about "Cyborg"?

paper raft
green minnowBOT
#

Gave +1 Rep to @clever charm

clever charm
#

Np

paper raft
#

I also took the 4 IBM cybersecurity courses

#

for fundamentals

paper raft
stuck fractal
#

It aint the same

#

For a start, htb academy is paid

paper raft
stuck fractal
#

TryHackMe and Hack The Box are totally seperate. They are competitors.

#

The content is not the same.

paper raft
#

oh cool

green minnowBOT
#

Gave +1 Rep to @stuck fractal

stuck fractal
#

Please don't ask the same question over multiple channels

paper raft
#

me ?

stuck fractal
#

They deleted their question

paper raft
#

ok

white salmon
#

What flag outputs things in a "long list" format

stuck fractal
#

@white salmon Did you check the manual for ls?

white salmon
stuck fractal
#

What

#

What's not working?

#

Roki, I recommend finding out what the problem is before suggesting things

white salmon
#

Might not work

white salmon
white salmon
white salmon
#

Hello,
Room: Web Enumeration (webenumeration2)
GoBuster: I can't find the flag in one of the subdomains (there are two)
I've used different wordlists to bruteforce folders and files and nothing useful...
Could anyone give me a hint with either specific command or maybe wordlist?

gusty kite
white salmon
#

Yes, and only css and js files are in there, I mean that are the folders and files that I was able to find...

gusty kite
#

thats how I found it

#

might not have found the right folder then

clever charm
#

try to add -x <extensions> cuz maybe is a simple file

eager umbra
#

Hi team,

Room: Investigating windows 3.x

q1

Need a hint to find out this event id in sysmon in faster way

white salmon
clever charm
#

do you intend to add .php, .html in each word in your wordlist?

white salmon
#

No but there is a list for all common extensions and I would like to pass that list to -x argument

clear violet
#

hey can anyone help me with htb scriptkiddie

ripe hedge
quiet stump
ripe hedge
#

also think about what the filename for flags are in other rooms

dapper sentinel
#

i need a hint to crack this hash $2a$06$7yoU3Ng8dHTXphAg913cyO6Bjs3K5lBnwq5FJyA6d01pMSrddr1ZG

stuck fractal
#

Room, task, question?

dapper sentinel
#

room - Hashing - Crypto 101
task - 5
question - 1

stuck fractal
#

Use hashcat/john and rockyou

dapper sentinel
#

ok

dapper sentinel
green minnowBOT
#

Gave +1 Rep to @stuck fractal

dapper sentinel
#

i was wondering around the internet and found nothing

tight fulcrum
dapper sentinel
#

thanks but i know its a bcrypt hash i am wondering around internet to crack the hash online

stuck fractal
#

You really can't

#

Online hash cracking uses rainbow tables

#

Bcrypt is always salted.

dapper sentinel
#

yeah i just rememberd its rainbow tables

#

yeah thats what i want to say i am a bad typo

gusty kite
#

you can use google colab for it

#

to get more resources and not put a pressure on your own machine

versed solstice
#

hhupd isnt on my retro machine, any ideas ?

stuck fractal
#

It is, just not where you think it is

versed solstice
stuck fractal
#

There's something on the desktop
If the user wanted to patch it, maybe they downloaded it then deleted it later

versed solstice
#

ik about the search history and the cve

#

ahhh nvm

#

thx @stuck fractal

green minnowBOT
#

Gave +1 Rep to @stuck fractal

versed solstice
#

so im trying to find cmd inside C:\Windows\System32\ but its all folders and no cmd.exe

stuck fractal
#

Change the filter

versed solstice
#

ok

#

srry james im not good w/ windows

#

thx for the help

stuck fractal
#

Change the "save as type"

versed solstice
boreal goblet
#

Hey. I need some help on Alfred please. I cannot understand what is the problem. I have also checked a few writeups and the step to download the shell.exe to the server simply doesn't work. I used a different exploit on the initial foothold as well because PowerShell commands simply don't work

#

Am I going crazy?

stuck fractal
#

I re-did alfred a little while back and there's a gotcha in there

#

You need to run the exe from the powershell reverse tcp, not as a job

boreal goblet
#

Yeah I wanted to do that. But I cannot get a reverse PowerShell TCP to download

stuck fractal
#

!docs verify

proud scarabBOT
stuck fractal
#

If you follow those steps, you'll be able to post images

boreal goblet
#

Cool I will get the box up a bit later and send it through. Thanks.

rigid spear
#

In burpsuite room task 6 which web application hosted on VM its talking about to complete the task?

stuck fractal
bold lichen
#

so i am doing http fundamentals ,, web fundamentals and i am stuck at the part of getting the cookies i did use the command curl -v http:machine_ip:port/ctf/getcookie and in output it told me to check my cookies now i did this using my terminal and i cant see where the cookies are i did use the hint and it told me to check firefox dev tool and there is no flag there

stuck fractal
#

The room covers this, your cookies are not shared between browsers

#

If you got the cookie with curl, it won't be in firefox

bold lichen
stuck fractal
#

You should have it in curl, seeing as you had verbose

#

Look at the headers.

#

http:machine_ip:port/ctf/getcookie this isn't quite right either

#

needs to be http://

bold lichen
#

Oh okay let me check , I directly went to the file I saved it

bold lichen
stuck fractal
#

Screenshots are generally better

bold lichen
#

Alright will post it , I dint post ss cause usually people say it spoils or reveals stuff so

stuck fractal
#

Mark it as a spoiler then

bold lichen
#

Idk how to do thag

stuck fractal
#

It's a checkbox when you post it to discord

bold lichen
#

@stuck fractal thanks I got the answer

green minnowBOT
#

Gave +1 Rep to @stuck fractal

idle bison
#

wifi hacking 101

"What three letter abbreviation is the technical term for the "wifi code/password/passphrase"?
i can't find the answer, last question for my completion of the room, Any tips would be nice

stuck fractal
#

Look at the different ways to authenticate with WPA2

idle bison
stuck fractal
#

I mean there's like 3

#

PEAP, EAP, and you want the other one

idle bison
#

i tried pmk, that didn't work

stuck fractal
#

The one that people tend to use

#

pmk aint right

idle bison
#

i also tried the eap so i must've not read something

#

i shall return, thanks

stuck fractal
#

https://en.wikipedia.org/wiki/Wi-Fi_Protected_Access#WPA2 Take a read of that, if you want a bit more of a hint

Wi-Fi Protected Access (WPA), Wi-Fi Protected Access II (WPA2), and Wi-Fi Protected Access 3 (WPA3) are the three security and security certification programs developed by the Wi-Fi Alliance to secure wireless computer networks. The Alliance defined these in response to serious weaknesses researchers had found in the previous system, Wired Equiv...

idle bison
#

found it, thank you @stuck fractal

green minnowBOT
#

Gave +1 Rep to @stuck fractal

jagged reef
#

Howdy, I'm doing the network services room, task 6, questions 6 and 7.
I'm doing the complete beginner collection and i'm stuck on this. Any hint would be great, thanks!

task 6, question 6: Based on the title returned to us, what do we think this port could be used for

task 7: who could it belong to? gathering possible usernames is an important step in enumeration

tight fulcrum
jagged reef
# tight fulcrum Heya, if you're still looking for hints: task 6: is a way to bypass the authetic...

hm :/
I can't seem to find any other info about a backdoor and the username

by executing the command
sudo nmap -A -p8012 -T5 10.10.88.57
i got the following output

Starting Nmap 7.91 ( https://nmap.org ) at 2021-04-29 17:44 EDT
Nmap scan report for 10.10.88.57
Host is up (0.00017s latency).

PORT     STATE    SERVICE VERSION
8012/tcp filtered unknown
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: WAP|general purpose
Running: Actiontec embedded, Linux 2.4.X|3.X
OS CPE: cpe:/h:actiontec:mi424wr-gen3i cpe:/o:linux:linux_kernel cpe:/o:linux:linux_kernel:2.4.37 cpe:/o:linux:linux_kernel:3.2 cpe:/o:linux:linux_kernel:4.4
OS details: Actiontec MI424WR-GEN3I WAP, DD-WRT v24-sp2 (Linux 2.4.37), Linux 3.2, Linux 4.4
Network Distance: 2 hops

TRACEROUTE (using port 80/tcp)
HOP RTT     ADDRESS
1   0.05 ms 192.168.130.2
2   0.06 ms 10.10.88.57

OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 1.58 seconds
tight fulcrum
#

did you try nmap -A -p- <IP> ?

#

Seems like some information is missing

jagged reef
#

i did, but its incredibly slow
i can execute it and let it run for a while and hopefully get a result

stuck fractal
jagged reef
#

i also tried the attackbox and got the same result

jagged reef
jagged reef
#

amazing, its fixed! changing VPNs was the solution. Thanks for the assistance, @stuck fractal and @tight fulcrum

green minnowBOT
#

Gave +1 Rep to @stuck fractal

arctic garnet
#

anyone about to answer some questions about relevant?

stuck fractal
#

It's always best to directly ask your questions

#

Then if someone can help, they will

arctic garnet
#

sorry, forgot the just ask rule

#

anyway, it seems to have sorted itself out - its responding as i would expect now

#

||the smb server on 445 found with nmap is non responsive - is this normal behaviour?||

#

^relevant room (maybe) spoiler

soft raven
#

Can anyone tell me how to read a file that is named with special characters ?
The name of the file is '-- -root.py'

stuck fractal
#

This is for peak hill, right?

soft raven
#

M4tr1x: Exit Denied

stuck fractal
soft raven
#

Got it, thanks !!

white salmon
#

hi

#

i have a problem with Burp Suite

#

at OwaspJuiceShop

#

Task 3

#

When i m trying to intercept the login

#

it s intercepting another

#

I know how to make SQL injection but i m stuck here at burp suite

#

because i can t intercep the right request

#

the request shoud look like this

#

the intercep is on

#

when i m pressing the login button

silver otter
#

it says rest/user/whoami in ur requset tho

brave vale
#

check the URL where you are doing the request

silver otter
#

and urs is a get request and the one they have is a post request

brave vale
#

that too

white salmon
#

is shoud make a post request

#

the url

#

is good i mean it s the login page

silver otter
brave vale
#

are you logged in by chance in that site?

white salmon
#

i m not logged

#

i m trying to type random credentials

#

and after that

#

intercepting the request with burpsuite

#

and after that making sql injection on the login page

#

to bypass the login

#

and get the flag

#

this task is simple but i got stuck at burpsuite

silver otter
#

what room are you doing

white salmon
#

owaspjuiceshop

#

Task 3

silver otter
#

i'll try it myself now and see

white salmon
#

k ty

silver otter
#

maybe clear your cache or restart the box or restart burp

#

I didn't do a single thing and it just gave me that when I clicked log in

#

might be related to that cookiconsent status thing too

#

if you have set your browser up non-default or something maybe

white salmon
#

yea sorry it s working to me right now

silver otter
#

nice, for reference I had not clicked this button yet

#

not sure if it's related but what did you change to fix it?

patent rune
#

OK, feeling dumb - I can't for the life of me see ISP/Organisation info using WHOIS to solve Task 5 in Sysinternals room. Any pointers please?

ripe hedge
#

hmm, the IP address may have changed

ripe hedge
patent rune
ripe hedge
#

eh, happens

#

in fairness, it WAS those IPs when the room came out

patent rune
#

That's what I thought............. maybe 🙂

green minnowBOT
#

Gave +1 Rep to @ripe hedge

ripe hedge
#

^_^

#

(you should also verify with the bot)

#

!docs verify

proud scarabBOT
sweet ferry
#

I am doing a room and i got a binary file and a dictionary file

#

the task says that i have to brute it to find the right key for binary

#

i dont know how to proceed further

#

contents of binary

stuck fractal
sweet ferry
#

Ok

#

Doing psycho break room

#

But nvm i opened a writeup

ripe hedge
#

Ok good hunting

novel rain
#

hey

low bone
#

anyone finish the osquery room that I can dm?

stuck fractal
#

It's always best to just directly ask your question. There's also a dedicated channel: #834161448934309948

low bone
#

Thanks

river mantle
#

Any tips on WWBUDDY?

wise ore
#

wgel ctf ? anyone

#

i need hint 😛 suid binary wget, im able to upload file to the server but php is not avialable

mighty stirrup
tribal wing
#

@mighty stirrup I'm on the same room so I'll tell you when I'll be there

mighty stirrup
tribal wing
white salmon
jagged reef
#

-T5 being the fastest for performance

white salmon
jagged reef
#

Hm, still try the syn scan on nmap with the -T5 thi

#

And grab a coffee while you're at it lmao, I went to do some stuff while it scan to pass the time

white salmon
white salmon
jagged reef
#

Loooool, it do be like that, still trying to get used to that as well

white salmon
#

yeah, musle memory is something not the best thing, so starting all over 😄

jagged reef
#

At least you weren't doing the 5 hours one :')

mighty stirrup
white salmon
grand linden
#

I believe i got the correct answer - b03f4b0ba8b458fa0acdc02cdb953bc8 but this is not accepted and I'm stuck with this question. please help.

spark prairie
#

@grand linden Let Me Check

#

@grand linden can you send me a link to the room?

#

i cannot find it

boreal goblet
#

Hi all. This is the error on Alfred i am talking about. Any clues as to what i am doing wrong. I have tried so many different things. Even the walkthroughs fail here when i attempt them.

upper wolf
#

I managed to finish Telnet Task(Network Services Room) with AttackBox, but when I try to do on my local machine I can't solve it

Why in the part "listening on" it shows [0.0.0.0]? I can't make the reverse shell

#

I tried other port, rather than the 4444 suggested by the exercice coz it was being used by my Linux

#

My telnet prompt

#

VPN Local IP

worn otter
#

If the port is in use, then you might have another nc listener using it. Also, I don't think you want to be running nc from within msf, but i might be wrong.

upper wolf
#

Y I agree with running nc from within msf
But I tried outside.. same error

worn otter
#

well, a port in use error is going to be the same across your machine

#

gotta find out what's using it and kill it

#

or use a different port. But if you use a different port, make sure you update that in the revshell and payload info

abstract flicker
#

Hey there! More of a im missing something obvious question than anything. Working through the MITRE room on the Cyber Defense Path and I'm stuck on last question of Task 6 . I cant for the life of me find any set of two words that answers the question and have been banging my head for at least an hour on this.

last cipher
#

Hint: what do you call a collection of weapons?

abstract flicker
abstract flicker
#

🙌🏻

dry briar
stuck fractal
#

Terminate and redeploy the box

dry briar
stuck fractal
#

You're not meant to cat the binary

#

When you ran the binary, you got the password

#

It's in the screenshot

dry briar
dry briar
#

ok so when looking for a flag what does it mean when there are seemingly 2 flags. for example -r and -R

worn otter
#

In that case, there are just multiple flags that do the same thing. That's not uncommon to have a shorthand with a single - and a full word with a double -.

dry briar
worn otter
#

correct

#

and most rooms and answer fields allow multiple answers, or might not be fully case sensitive. They allow a little "wiggle room" in the answers, often

green minnowBOT
#

Gave +1 Rep to @worn otter

worn otter
#

you're welcome

ripe hedge
#

I think the answer tolerance is that if ~90% of the answer is correct it'll give it to you

dry scroll
#

anyone done the "what the shell" room

#

I think im being thick

white salmon
#

yeah i have

dry scroll
#

when it says upload a webshell. Am I supposed to know what the fuck to do

#

xD

white salmon
#

yeah

#

the php line

#

one line

#

or the pentestmonkey reverse shell

dry scroll
#

yeah, I know the one line format. Where am I supposed to put that though

#

It does say see the Upload Vurnerabilities room but thats the room that sent me to this room

white salmon
#

is there somewhere you upload something right?

dry scroll
#

a URL yes

#

ip/uploads

#

oh

#

im dumb

white salmon
#

lol

dry scroll
#

theres literally a button

#

okay, lemme try

#

honestly, I may still be thick

white salmon
#

ur fine

wise ore
#
``` hints on how should i decrypt this ?
clever charm
#

i think base64

foggy cliff
ripe hedge
#

On Linux, you can echo '<b64 text here>' | base64 -d

wise ore
# ripe hedge Looks like base64

i think more than 1 encoding is used```Qapw Eekcl - Pvr RMKP...XZW VWUR... TTI XEF... LAA ZRGQRO!!!!
Sfw. Kajnmb xsi owuowge
Faz. Tml fkfr qgseik ag oqeibx
Eljwx. Xil bqi aiklbywqe
Rsfv. Zwel vvm imel sumebt lqwdsfk
Yejr. Tqenl Vsw svnt "urqsjetpwbn einyjamu" wf.

Iz glww A ykftef.... Qjhsvbouuoexcmvwkwwatfllxughhbbcmydizwlkbsidiuscwl

tight fulcrum
#

You're correct. There's 1 more

ripe hedge
#

Probably

tight fulcrum
#

hint: starts with V

wise ore
#

some kind of rotation

ripe hedge
#

Might be a transposition cipher

#

Caesar or the V

wise ore
#

how do you guys know which cipher is used

ripe hedge
#

Cyberchef can deal with it, or maybe ciphey

tight fulcrum
#

trial and error

ripe hedge
#

Pattern recognition

#

Decoded part looks like it could be words

tight fulcrum
#

V will need a key. There are websites which can brute force it

ripe hedge
#

A bit of guessing will be involved but yeah

#

That's code breaking

wise ore
#

it needs to key 😸

#

Vigenere

#

i should look more through the box

tight fulcrum
#

So you got the message?

kind blaze
#

Anyone who can help me with Sakura room, wigle does not show me the bssid

autumn yew
#

Hello, i'm actually stuck on "File Upload Vulns" room, task 9 (= magic numbers):
I succesfully upload a reverse shell after modifying the correct magic number but i don't find where the file has been uploaded to :c

I enumerated 2 directories w/ gobuster but can't list its content because of permissions denied (tried to launch the shell from thoses dir but didn't work either)
Added -x <ext1>,<ext2> to gobuster to test if it find the shell but still not working
actually manually "bruteforcing" to try to find the dir

Does someone has an hint please?

clever charm
#

gobuster can't list content

#

run a simple gobuster scan

#

like "gobuster dir -u <url> -w <path to wordlist>"

autumn yew
#

y, didn't express myself correctly
i've done that and find 2 dirs

kind blaze
autumn yew
#

by listing it content i meant manually, got a 403 error

clever charm
#

what are these dir?

autumn yew
#

y, probably add the upload timestamp in the name but didn't actually find the script doing it
or probably miss it 😅

autumn yew
clever charm
#

what wordlist did u used?

kind blaze
#

Use directory-list-2.3-medium

#

@autumn yew What directories did gobuster return to you?

autumn yew
#

dirbuster/directory-list-2.3-medium

clever charm
#

try to go assets/<shell>

autumn yew
#

tried

kind blaze
#

that's weird, I think I remember that there was more

clever charm
#

what is the room?

autumn yew
#

as UFO said the room indicated some serv modify filename so probably the case here but as i didn't find actually how

autumn yew
kind blaze
autumn yew
#

y

#

)

#

copied the title, sry :/

kind blaze
#

gobuster dir -t40 -u "url" -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium

#

And then you Fuzzing for extensions in the directories that you see in scan

autumn yew
#

yep, used:

#

gobuster dir -u <url> -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x <ext> -e -r

kind blaze
#

gobuster dir -t40 -u "url/pepe" -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium -x <ex>

kind blaze
autumn yew
green minnowBOT
#

Gave +1 Rep to @kind blaze

kind blaze
#

If I just realized that you are missing the / "pepe"

#

np

autumn yew
#

nah but as i didn't think about fuzzing sub dir i'll maybe have more result, will see