#room-hints

1 messages Β· Page 99 of 1

peak harness
#

it's in the same directory, and I can open the file too

silent narwhal
#

is this powershell?

peak harness
#

yup

silent narwhal
#

.\ means "execute"

#

so instead, try doing "8702.zip" instead

peak harness
silent narwhal
#

same output?

peak harness
#

yup

#

now I tried in cmd as well

#

same outpu

silent narwhal
#

did you change rockyou1.txt aswell?

peak harness
#

yup

#

with and without rockyo

silent narwhal
#

and remember to quote it aswell

#

hmm

#

is this file in hashcat-6.2.3 directory?

peak harness
#

yup

#

the same directory as hashcat.exe

umbral rock
#

Thanks, I am all set. I downloaded the sensitive file by typing the path in the browser. I assume you can't ssh to the machine?

green minnowBOT
#

Gave +1 Rep to @left thunder

left thunder
ashen scaffold
white salmon
#

I just finished room/uploadvulns, and I have a question about methodology (Task 10 item 3). We are asked: What's the naming scheme of the website? In the Task 11 ctf (jewel), the target tells us it wants a jpg. But the naming scheme is given to us in the gobuster wordlist. How would we find the file naming scheme in a real-world hack?

silent narwhal
#

if it wants a photo, then it should accept jpg files so, you can rename them to shell.jpg.php or if it doesn't work shell.jpg.phP or phP5, if it checks for magic bytes. Then add jpg magic bytes into the request using burp

white salmon
#

Thanks, but the problem is that the target renames the upload file using some naming scheme ending in jpg. How do we enumerate it without a wordlist?

silent narwhal
#

I don't have knowledge about that, sorry if i couldn't help you. I'm still learning

white salmon
#

Me too! I appreciate the effort.

white salmon
#

To address my own question: Maybe we can't solve the ctf without knowing that the upload file name is upper-case alphabetic three chars in length. I can accept that and move on.

pseudo tapir
#

It's all json and js, no python.

silent narwhal
#

Oh, i've been there too

#

sec ill drop it

#

@pseudo tapir

#

Dont forget to change the ip

dry gate
#

Currently doing the Inclusion CTF room. The gobuster brute-force attack seems to be taking ages. I was wondering if there was a way to increase the speed or if it's just like this.

#

I did read somewhere about increasing the amount threads but apparently that can decrease the accuracy.

#

This is the command I used btw :)

loud nebula
#

Use thread, iirc the command is -t 50 for 50 thread

pseudo tapir
green minnowBOT
#

Gave +1 Rep to @silent narwhal

white salmon
#

anyone able to assist with wget connection refused?

gleaming viper
white salmon
#

im typing in what the questions is asking me but everytime it comes back with connection refused...

#

I gotta go now, but ill revisit at some point soon

#

and hopefully either work it out or be back here

#

but thanks

misty orchid
#

Hello some hints for the pickle rick room dont give me the answer just give me some hints if posssible thnx in advance

misty orchid
#

Pickle Rick

#

ctf

#

the name of the room is Pickle Rick

loud nebula
#

yes, and which part you want to get the hint?

#

is it for root, recon, enumerate, etc

misty orchid
#

for the first part

gleaming viper
#

Do you have a foothold on the system?

loud nebula
#

can you tell us what attempt you have tried?

misty orchid
#

i tried gobuster first i find a login page and then i try to bruteforce login page(sniper attack burp suite) with the username that i found in the code but with no sucess

loud nebula
gleaming viper
#

Bruteforce is not usually the way to go. Consider that for future machines.

misty orchid
misty orchid
loud nebula
misty orchid
white salmon
#

Standing in front of each door is a robot guard. With no other way out of the room, you must choose a door to enter.

loud nebula
stable island
#

@misty orchid Cool gif?

stable island
#

If I connect to another system using an ssh key, will it still ask for a password before finishing the connection? I think I did this right, just wanna make sure.

ssh-keygen
place public key within /.ssh/authorized_keys
ssh -i keyfile user@host

#

I finished the connection, but I already knew the password, I was just testing if I understood the process

#

nvm, google is fren

misty orchid
stable island
misty orchid
fervent jasper
#

In Upload Vulnerabilities room Task 11 : Whenever I comment out or delete the Client Side Checks and forward the request in Burp , I no longer have the ability to upload any files the button doesnt work at all not sure why ..

stable island
misty orchid
misty orchid
stable island
#

@stuck fractal I think I am doing it right, I dont think I have permissions on this box to do what the crypto room is saying.

#

ooh maybe I can change permissions, i am root xD

#

Im not root...

stuck fractal
#

You don't need to change any config files

stable island
#

grrrr, why the hell is it still telling me to use a password. I have the authorized_keys in .ssh with 700 permissions on directory, 600 on its contents

#

THROWS HANDS IN AIR

#

lol

#

if I did what I think I did.. ima cry

#

I have atleast 40 derps a day

stuck fractal
stable island
#

I got that part, and it isnt the derp I thought it was

#

correct key within authorized_keys

#

Proper permissions?

#

end of key = so nightshade is the login name correct?

#

use my private key, and it wants a password

#

try with full path, but shouldnt need it since Im already in .ssh

#

Am I missing something? If so Ill come back to it later, or is something not workin right?

left thunder
stable island
#

i set a passphrase, but it doesnt work

#

i did not create that user on the other system.... If thats the problem..... ffs. attention to detail I lack..

left thunder
stable island
#

yes linux2, i tried linux2@ip and same thing tho

stable island
#

dont have permission to change the user

#

create**

#

oh ffs

#

I think I might no

#

again

#

i fixed it

left thunder
#

Wait, linux 2 user has already an ssh login set up, right? Did you remove that key ?

#

Oh okay, what was it?

stable island
#

the user is tryhackme the box is linux3

#

linux2

#

....

left thunder
#

Ah okay

stable island
#

welp that was a fun 3 hours. lmfao moving on

#

ty tho

left thunder
#

Not a problem πŸ™‚

stable island
#

prob why ninja went quite. thinking "FAhking idiot"

#

Thank you kindly, bot please rep @stuck fractal and @left thunder

green minnowBOT
#

Gave +1 Rep to @stuck fractal

misty orchid
silent narwhal
#

"sudo"

#

πŸ˜‘

stable island
# silent narwhal πŸ˜‘

I mean there could be situations where that would work tho. Current user is sudoer, but doesnt have access to a directory you need, and root does. I think? Dx

silent narwhal
#

then its not being "priv esc"

stable island
#

Why not, you are gaining privileges to access a directory you were previously unable to access

#

I mean I get the funnies, but still.

silent narwhal
#

You have access for it.

stable island
#

you didnt previously tho

silent narwhal
#

just add sudo before the command

stable island
#

can permissions not be set in a way that only one user can view them tho. Sometimes even sudo wont get you there. or am I wrong

#

nvm, a root user can change to any other user without the password. So, even though you can technically set permissions so that root cannot view them, nothing stops root from moving to the other account. >.<

#

I just wanted to give an unlikely, but possible situation, but I just ended up lookin like a dummy Dx

silent narwhal
#

then basically using the sudo giving you more privileges while you are in the user account, and the owner?

stable island
#

I dont follow. I mean kinda, not really. lol.

set a file so only the user can read. so like 600.

silent narwhal
#

That doesn't make sense

stable island
#

Only the user can read and write. So would root need to move to that account to see it?

silent narwhal
#

no?

stable island
#

ok

#

lmfao

silent narwhal
#

what to do with that about priv esc

stable island
#

ye, I get what you are saying.

#

priv deescalation is what I meant >.<

#

not really. Just dumb

sturdy hearth
#

@stuck fractal Scam link ↑ psyDuck

polar finch
#

is there a place to discuss completed rooms with spoilers? (for rooms older than the recent releases)

umbral rock
#

In the Owasp top 10 room, for task 29, 'Components with Known vulnerabilities - Lab', the instructions are: 'The following is a vulnerable application' What application are they referring to?

silent narwhal
#

It's the target machine you deploy

#

Has vulnerability, it wants you to find and exploit it

#

It's a bookstore

#

You need to search to the exploit for the version and name

#

For example : "A CMS" is name of a bookstore and its version is 1.4, then you need to search for "A CMS 1.4 exploit"

#

If you find a version 1.4 or 1.4+, you can exploit it

misty orchid
#

Any hints for pickle rick second ingredient?

gleaming viper
misty orchid
gleaming viper
#

You should be able to open it. Bear in mind spaces when opening a file with a space in the name.

misty orchid
misty orchid
gleaming viper
#

What did you try so far?

misty orchid
gleaming viper
#

You have a web shell that allows you to execute commands. You were able to find the second ingredient by doing enumeration on the target.

#

If after checking the filesystem with your current access you are unable to find it, maybe you should consider trying to move to another account.

#

You can move to accounts with your same privilege, or with higher privileges (privilege escalation).

misty orchid
gleaming viper
#

What you did was spawning a new bash session, but bear in mind you won't be able to interact with it since you are still on a web shell.

#

On the other side that trick "sudo -u#-1 /bin/bash" is used to exploit vulnerable versions of sudo, but it's not needed for this machine.

There's one command you should always run when getting access to a machine in order to list your sudo permissions. Then based on that, you might be able to execute certain or any commands.

misty orchid
gleaming viper
#

Sure no problem.

clever sparrow
gleaming viper
#

Some users reported the port would open after 15 minutes. Maybe try waiting a bit to see if it opens up . . .

clever sparrow
#

@gleaming viper thank you very much. Will try to wait a bit.

And check again

green minnowBOT
#

Gave +1 Rep to @gleaming viper

brave bluff
#

Wireshark 101, Task 7, ARP Traffic

Last question, I'm required to find IP address at specific MAC, i used eth.src == mac_address and arp, from that i get 5 different ip addresses, i can guess which one is correct by the template of the hidden answer but i dont understand how is there multiple ip addresses that i get?

#

I tried it and i got the correct one, but it still doesn't solve my problem

fickle crane
#

Hi guys, I'm onto Agent Sudo and i dont knw what task 3 is talking about
any help here?

loud nebula
fickle crane
#

That want me to change User-Agent

loud nebula
#

you mean task 2?

fickle crane
#

Task 2, question 3

loud nebula
#

to get the correct user agent, the hint provided is good enough iirc

fickle crane
#

sure, sure.... it is

#

Thanks.

#

Things got clear just now

loud nebula
#

good to hear

#

glhf

weary estuary
#

i am doing bolt and metasploit is saying target is not bolt application

#

I know i chose the right exploit

#

ends with this in metasploit bt_******

runic moat
#

still not understand yet why should we run use the bash -p to do for some privileges escalate, any one help please??

tulip mural
dry gate
#

I learnt about that yesterday while making a write-up for the skynet room haha

mental quarry
#

Hi. I was working on the Overpass 3 room, and was not able to upload a reverse shell. Every time I try to upload one, it says "553 Could not create file."

#

I was uploading the reverse shell from FTP

left thunder
# mental quarry

You sure the revshell is located at your specified path?Also maybe try to change into the folder where the revshell is located as I'm not sure if you can just specify paths to files within ftp, rather then just being in the same directory already, and then connect via ftp, so that you only have to use put revshell.php instead of with the path itself.

mental quarry
green minnowBOT
#

Gave +1 Rep to @left thunder

white salmon
#

guys I’m going tomghost room

#

Little stuck on privesc part

#

Can somebody help me

#

Any hints

wheat helm
#

Can you share what part you're stuck on?

white salmon
#

With the pgp thing. I tried to decrypt it but it ask for passphrase

timid ravine
#

Hi

timid ravine
#

Hlo

white salmon
#

i need help with hacker of the hill medium port 80

weary estuary
north stirrup
#

anyone available for a hint/sanity check for the CCT2019 room? Still attempting task1 but I feel stuck

inland sable
#

hey guys

#

has anyone done the lockdown lab?

#

I am confused, since I only see ssh and http installed

#

should I brute force the password, or do url scraping

waxen mica
#

Take what I say with a grain of salt cuz I'm still semi new to all this but it sounds like you should be using your browser for this one. At least in the beginning

prime willow
flat orchid
peak harness
#

can someone give me a hint about Lockdown room?

#

got a reverse shell as www-data

#

can't figure out how to escalate privs to user.

ripe hedge
#

What can you do as www-data

#

What info might you have access to?

peak harness
#

i have gone through the www/html found nothing interesting

#

or maybe it's sitting right there, but I can't see it lol
found a password hash, but I don't think it's on any use

#

tried cracking it, it's still running BTW

ripe hedge
#

It should be pretty quick

#

You may have misidentified it

peak harness
#

cracking the hash?

gleaming viper
# peak harness cracking the hash?

When you spend more time than usual trying to crack a hash, the reason might be you are using the wrong hash format in your cracking efforts. That's why you should run hashid -mj yourhash before, just in case.

peak harness
#

yea I know, it's just that I was trying to crack the wrong hash,

#

now I am on the right path

ashen scaffold
gleaming viper
green minnowBOT
#

Gave +1 Rep to @ashen scaffold

clear violet
#

can i get a nudge for year of the jelly fish

white salmon
#

i need help with Lockdown i have user but i need help with root

devout marlin
#

Linux fundamentals part 2

#

will not allow me to type any text for password

hushed rune
#

If it is the initial SSH into the machine, when you type in a password, you won't actually 'see' the characters (or *******) as you're typing

tame canyon
#

Hi, I'm doing the room : You're in a cave insane and I'm stuck in the moment of modifying the /etc/hosts to be able to access the /varr/www
What should I do?

devout marlin
#

Yes thank you! A Mod in another room helped me. TY for responding! And helping😊

hushed rune
devout marlin
#

TY CapOneCode!

#

I think that gets everyone who is hard-headed! After trying every key and wasting time I decided to ask for help

hushed rune
#

Hard-headed could also be called persistence or grit πŸ˜‰

devout marlin
#

That I am! Thx againπŸ‘

sacred pelican
#

Hello all! I am new to TryHackMe and I'm having a slight issue I'm hoping someone can help me with. I'm in the Linux Fundamentals room part 1. When I open the terminal it is opening as root, but in the video it shows it opening as user 'tryhackme' How to I get the terminal to open to the user and not root?

deep lion
#

on your local machine/vm ?

#

you dont need to specifically i would say

waxen mica
clear violet
#

can i get a nudge for year of the jelly fish

silent narwhal
grave blade
#

Hey guys, I'm trying to finish the Task 7 of Network Services room and connect connect back from victim telnet machine to my attacking box. What I'm doing wrong?
https://ibb.co/XWwPPcz

waxen mica
#

The telnet connection isn't working properly. When you connect, it should say ||SKIDYS BACKDOOR||

signal perch
#

Can I get a hint for "File Inclusion" part of the "introduction to web hacking" , I'm stuck at challenge #2 "capture the flag2 at /etc/flag2" . || I changed the cookie properly to get the page as admin rather than guest || . I therefore get the message || Welcome admin , this is a admin page! Get the flag! || I tried to apply from burp suite some GET or POST trying to get the flag2 but nothing happens , what can i do ?

waxen mica
#

I'm not sure what room/task you're doing, but from what your saying it sounds like you need to send a get request to that directory. Also, make sure it actually says /etc/flag because /etc likely can't can't requested cuz its above to root of the website, unless an etc dir was made specifically for that task

grave blade
#

Thank you @waxen mica ! It worked after target machine restart!

green minnowBOT
#

Gave +1 Rep to @waxen mica

slate siren
#

Hey guys. Really need help with Task8 "Capture Flag3 at /etc/flag3" question here. It looks like that there is '/' filtration that I can't bypass. I literally tried all lfi cheet sheets already, but no success. https://tryhackme.com/room/fileinc

grand idol
#

@slate siren Why not use an earlier LFI challenge and download the code for challenge 3 and look at what it is doing? πŸ™‚

shadow monolith
green minnowBOT
#

Gave +1 Rep to @grand idol

sacred pelican
#

could use some assistance please. I've been hard at it but cannot figure out what I'm doing wrong here. I am working on: Network Services 2 - Section 3 - Enumerating NFS.
https://tryhackme.com/room/networkservices2#

Active Machine IP: 10.10.115.132
Attack Machine IP: 10.10.194.19

I am on this part:

"Time to mount the share to our local machine!

First, use "mkdir /tmp/mount" to create a directory on your machine to mount the share to. This is in the /tmp directory- so be aware that it will be removed on restart.

Then, use the mount command we broke down earlier to mount the NFS share to your local machine."

root@kali:/tmp/mount# sudo mount -t nfs 10.10.194.19:share /tmp/mount/ -nolock

mount.nfs: requested NFS version or transport protocol is not supported

left thunder
wet cipher
#

Need push with "SQL Injection" room
https://tryhackme.com/room/sqlinjectionlm
Task 8 Blind SQLi - Time Based, got database name and stuck on tables querry... 😦

SQL Query
select * from analytics_referrers where domain='admin123' union select sleep(1),2 FROM information_schema.tables WHERE table_schema = '##########' and table_name like '%';--' LIMIT 1

oblique mantle
#

After typing dozens of verbs at it, later some emotive ones to, I found that 'format' is the obscure answer to this one. 'Formatting' probably more correct, but there you go.

prime willow
#

It is practically the same system like in the task before. Just with "admin123' UNION SELECT SLEEP(5),2 " at the beginning πŸ™‚

fathom drift
#

I have literally used intruder from 1 to 1000 with ascii decode, url encode and html encode

#

How can I find the flag ? I have even tried sql injection and xss payloads

alpine kestrel
#

are you making sure that you only send the data to the right field/part of the post request????

fathom drift
#

POST ?

#

It is using get request

#

http://<machine ip>/products/{payload}

alpine kestrel
#

???

fathom drift
#

it says use extreme inputs instead of integer here in this field

glossy perch
#

Same challenge here, do you have more insight?

shadow tangle
#

guys which is the last flag on Network Services 2 task 4 last question

#

i tried everything

#

and still not getting root

#

./bash: line 7: syntax error near unexpected token newline' ./bash: line 7: <!DOCTYPE html>'

#

only thing i get

#

@trim haven can you help me

#

?

trim haven
#

The bash file isn’t working

#

Try using the one on the box

#

Copy it to the place you need it and then execute the commands on it

shadow tangle
#

where is it located?

trim haven
#

/bin/bash ?

shadow tangle
#

ok

#

still not working

#

great

#

FINALLY

#

worked

fathom drift
modest timber
# fathom drift I still can't figure this out πŸ₯ΊπŸ₯ΊπŸ₯ΊπŸ₯Ί

this room is all about Repeater.
what does it have to do with intruder? I mean you don't need intruder to do this task.

pay more attention to this message:

See if you can get the server to error out with a "500 Internal Server Error" code by changing the number at the end of the request to extreme inputs.

try negative numbers (you should always consider unordinary numbers (such as big or negatives) when facing this situations).

fathom drift
#

thanks

alpine kestrel
#

what about imagineary numbers????

fathom drift
#

on it has already said integers

alpine kestrel
#

ah fairs

fathom drift
grand idol
#

This is priceless. Whomever built the Uranium CTF room, you are my hero today:

Broadcast message from root@uranium (somewhere) (Tue Oct  5 23:07:49 2021):    
                                                                               
That is not nano, sending the cops, bye!
#

Then it nuked the machine.

#

I can't stop laughing.

pure star
#

Anyone doing new Cross-Site Scripting room?

wide harbor
late patio
wide harbor
#

Sure thing

green minnowBOT
#

Gave +1 Rep to @prime willow

elder sapphire
#

Hey guys! I am using Kali-Linux and when i try to open the website the machine is connected to (for vulnriversity) it just gives me a "Cant connect" Error, yes i am connected to the openVPN

#

"Secure Connection failed"

elder sapphire
#

Fixed it!

random glen
#

Hi guys! I'm doing the OWASP juice shop. In the section about XSS I have to modify a header value in burp suite, but my burp suite version doesn't have the option to change the header. Do I need to change some option in burp?

waxen mica
#

It won't be an option. Headers are part of the request. If you intercept the request with burp you can change the headers

random glen
green minnowBOT
#

Gave +1 Rep to @waxen mica

near tiger
#

Hey guys, I'm doing IntroductionToHoneypots. I'm currently stuck on :

What application is being targetted in the first sample? (Tunnelling/Sample1.txt)

Any suggestions on how to read the file or where to learn to read the file?

modest timber
# near tiger Hey guys, I'm doing IntroductionToHoneypots. I'm currently stuck on : What app...
2021-03-17T10:09:51.052837Z [SSHChannel cowrie-discarded-direct-tcpip (62) on SSHService b'ssh-connection' on HoneyPotSSHTransport,118939,0.0.0.0] discarded direct-tcp forward request 62 to <A DOMAIN>:80 with data b'POST /xmlrpc.php HTTP/1.1\r\nAccept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8\r\nAccept-Encoding: gzip, deflate\r\nAccept-Language: en-US,en;q=0.9\r\nConnection: keep-alive\r\nContent-Length: 201\r\nContent-Type: application/x-www-form-urlencoded\r\nHost: <A DOMAIN>\r\nUpgrade-Insecure-Requests: 1\r\nUser-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.109 Safari/537.36\r\n\r\n<?xml version="1.0" encoding="UTF-8"?><methodCall><methodName>wp.getUsersBlogs</methodName><params><param><value>admin</value></param><param><value>password11\r</value></param></params></methodCall>'

so this is the log from Sample1.txt
you can see it contains a HTTP request inside. extract this request which looks like below:

POST /xmlrpc.php HTTP/1.1\r\nAccept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8\r\nAccept-Encoding: gzip, deflate\r\nAccept-Language: en-US,en;q=0.9\r\nConnection: keep-alive\r\nContent-Length: 201\r\nContent-Type: application/x-www-form-urlencoded\r\nHost: <A DOMAIN>\r\nUpgrade-Insecure-Requests: 1\r\nUser-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.109 Safari/537.36\r\n\r\n<?xml version="1.0" encoding="UTF-8"?><methodCall><methodName>wp.getUsersBlogs</methodName><params><param><value>admin</value></param><param><value>password11\r</value></param></params></methodCall>

#

in order to make it more human readable you can interpret those new lines using echo -e

POST /xmlrpc.php HTTP/1.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
Connection: keep-alive
Content-Length: 201
Content-Type: application/x-www-form-urlencoded
Host: <A DOMAIN>
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.109 Safari/537.36

</value></param></params></methodCall>hodCall><methodName>wp.getUsersBlogs</methodName><params><param><value>admin</value></param><param><value>password11

so what does it look like?

near tiger
green minnowBOT
#

Gave +1 Rep to @modest timber

modest timber
shy raptor
#

Any Help? Room Linux Agency root@ec96850005d6:/root# cat success.txt
47 you made it!!!

You have made it, Robert has been taught a lesson not to mess with ICA.
Now, Return to our Agency back with some safe route.
All the previous door's have been closed.

Good Luck Amigo!

wraith otter
#

NVM Got it.

odd token
#

Hi, i need help for the new SQL injection room, at the task 8 (blind sqli Time-Based).

I almost found the entire table but i can't find any extra characters and if i do a simple "=" on the name of the table i think i found, it doesn't work.

Can someone help me ?

naive roost
shy raptor
#

B0X Linux Agency Done, finally

wet cipher
odd token
wet cipher
velvet jackal
#

I am stuck on Introduction To Honeypots, Task 7 Q1.
"What brand of device is the bot in the first sample searching for? (BotCommands/Sample1.txt)".
Can someone please give me a hint?

dry gate
#

I'm stuck on the Agent Sudo CTF. I've enumerated as much as I can think of at the moment (which is hardly anything lol.) The ports for SSH, FTP and HTTP are open. I can't access the FTP server yet due to a lack of credentials but the web server yielded very useful information:

|| Dear agents, Use your own codename as user-agent to access the site. From, Agent R||

Gobuster didn't find anything so the only thing I can think of is a hidden directory. But I don't understand how to get to it with this information. I've tried things like adding "/user-agentr" and "/user-agent" to the end of the URL but to no avail. I can't think of anywhere else to try this. πŸ˜”

#

I also don't want to look at a write-up this time as it's not something that is beyond my ability as far as I'm aware :P

native atlas
shy raptor
#

If youre reading this, then know you too have been marked by the overlords...πŸ˜† accessdenied

pearl yew
#

In the question "Provide the amount of DNS connections made in total for this packet capture." of Masterminds room , I have tried several figures based on results but none of them work for me... I am left with this question -.-

torpid sphinx
#

Im a noob and very confused by the Burp Suite OWASP Juice Shop room. I am up to Task 8 and have added the target IP to the scope in BURP and disabled interceptor. I just get a blank page that asked me to accept a cookie, i did so and now its just blank. Task 8 starts by telling me to attempt to log in, showing me an image of an "account" button that doesnt seem to exist. Any hints are appreciated, even just telling me what i am seeing is expected would help lol

flat orchid
#

#masterminds hey guys, does anyone finished the Masterminds room?
if you have pls give me some hints where i want to start?

prime willow
# flat orchid #masterminds hey guys, does anyone finished the Masterminds room? if you have pl...

Maybe this will help πŸ™‚
https://www.youtube.com/watch?v=InT-7WZ5Y2Y

See how Brim's intuitive UI leverages the power of Zeek logs to provide insight about network traffic and quickly dive to the packet level in Wireshark when needed. To learn about features added since Brim's initial launch, see the Zeek From Home video at https://www.youtube.com/watch?v=ldrEadAQYTM.

β–Ά Play video
median violet
dapper nest
#

Ok, I think kali likely already has the .xxa filename I'm looking for on it but I'm trying to go about this as if I didn't already think it did.

#

Can someone point me to a place where can I find some good wordlists looking for 5 and 8 character .xxa filenames without all numbers

#

I just realized I need a 4 char filename not a 5 since the "." in .xxa counts as a character...

#

The room CC:Pentesting doesn't give any hint as to which wordlist I need to use to use gobuster to find an .xxa filename. It looks like by the eight grey * in the answer box that its either a four (including .xxa) or an 8 character so I'm trying to make one I think will work. I just tried all the 5 letter filenames in the gobuster file extensions. I guess I'll go back and try the four character ones

silver loom
dapper nest
#

okay I tried every four letter word in dirbuster wordlists folder i'm close to giving up. I even found the .htaccess.xxa type files but none of those are the right answer

dapper nest
#

cc:pentesting

oblique plank
#

The .xxa isn't in the answer

dapper nest
#

good enough hint. thank you

jolly crescent
#

Hello everyone, anyone doing the new Jason room?

green minnowBOT
#

Gave +1 Rep to @prime willow

true perch
drifting crest
#

Hi everyone! Running a Linux Agency task, went to the user robert, got the password id_rsa, but I can't connect through id_rsa, the error is like this

└─$ ssh robert@10.10.60.185 -i id_rsa
Enter passphrase for key 'id_rsa': 
Connection closed by 10.10.60.185 port 22

Who can tell me which way to go and what I did wrong?

fading robin
#

i think its closed by the server, maybe its the same as the ftp when you try to \\ip\user, you have to specify the user with the flag for it to let you acces it

waxen mica
white salmon
# jolly crescent Hello everyone, anyone doing the new Jason room?

i tried, but i stuck at payload step, if i send 'process.exit()' everything going as expected, but if i try smth with connection(send request to post.bin or connect to my netcat server) nothing work

And just checked that payload work with sleep function, that's mean smth wrong with socket/http functions, any hints?

wraith otter
timid ravine
#

Hai

white salmon
#

Hi guys in linux part 2 section i have an assignment to switch users

#

it says that my password is not assigned when i switch it to user2

dim minnow
unkempt jacinth
#

hello I am doing burp suite : Intruder room and I can't get past task 11, I set numbers 1-100 but I don't get any 200 results

#

just one

wide slate
#

Im doing the room agent sudo.
I've used stegoveritas on the 2 pictures that has hidden messages.
From one of the pictures I got a .txt file with a message in it saying :

#

However, the other file didnt give me anything of interest, as far as I understand. But I realise I might be missing something here.

#

THM is asking for the "steg password". And I'm not sure how to continue this room. Any hints?

fading robin
#

try to find out who WXJlYTUx is

radiant vigil
#

Hi, doing CC: Pen Testing room Section 4- John The Ripper. Been trying to crack the hash (md5) but can't seem to do so and keep getting 'using default input encoding: UTF-8 No password hashes loaded

flint falcon
#

Hi everyone, I'm in the room Metasploit can someone help me I'm trying to exploit but the message is " ip:8000 - exploit failed unreachable

waxen mica
white salmon
limpid sigil
#

im also stuck in the sql injection room, i've got the table names but i have tried a ton of different stuff and cant really find the answer

#

i'm taking a break from it now but any syntax advice would be appreciated πŸ™‚

unkempt jacinth
#

hello I am doing burp suite : Intruder room and I can't get past task 11, I set numbers 1-100 but I don't get any 200 results
just one

limpid sigil
flint falcon
#

Is there anyone who got the same problem and solved this

loud nebula
#

Care to elaborate?

loud nebula
#

Can you verify and then send screenshot of show options

#

!docs verify

proud scarabBOT
pseudo tapir
#

in the Alfred room -- for the initial foothold on the box, are we supposed to be brute forcing?

#

it mentions a nishang script, but I have been looking those over and I'm not really sure how I would gain initial access with it

unkempt jacinth
#

hello I am doing burp suite : Intruder room and I can't get past task 11, I set numbers 1-100 but I don't get any 200 results
just one

pseudo tapir
#

don't brute-force alfred, btw

waxen mica
#

Loool

analog orchid
#

hello discord friends, I am kinda of stuck on a question, well the command. i am watching a youtube video as well. something isn't quite right. This section i am on is Network services 'Exploiting Telnet' the command .... msfvenom -p cmd/unix/reverse_netcat lhost=(IP address) lport= (i have watched too different videos one with the port 4444 or 4545) .............. i am not getting the right reply back compared to the youtube videos

analog orchid
#

What words does the generated payload start with?'

mossy hazel
analog orchid
green minnowBOT
#

Gave +1 Rep to @mossy hazel

alpine kestrel
green minnowBOT
#

Gave +1 Rep to @alpine kestrel

alpine kestrel
#

no problem

drifting crest
#

Hi all, I'm working on the Daily Bugle, I can't get the user, who can give me a tip on how to get the user

vocal viper
#

Iv went waaaay down the rabbit hole with nmap in the netsec challenge who can reinf be back in the correct direction. I understand its to be stealthy lol

grizzled crane
#

hi i need a hint with one task in windows fundamentals part 2, task 3

#

At what time every day is the GoogleUpdateTaskMachineUA task configured to run?

#

i cant find the task in the task scheduler

#

what i found is a task called "GoogleUpdateTaskMachineCore" with run time at 6:15:30 am, but my answer is in this pattern "?:?? ??"

deep lion
#

hello, any hints on the net sec challenge, task 2, IDS evasion?

#

packet count goes up no matter if i am scanning or not

wheat helm
deep lion
#

oh, ive got it, thanks!

wheat helm
#

🍻

grand lintel
#

Hope to get a nug here

#

I am working on "File Inclusion Module" and I am at the last part.

#

Lab#challenge-1

#

It says I need to change my request to POST and use the file as a parameter. So I open up bur and I catch the request.

#

I send it to Repeater and change the GET to POST and add file=../etc/flag1

#

I took it to curl to see if I can do it like some thing like

#

I assume I am on the right track but as I keep failing maybe I am missing something or overlooking something any ideas would be great thanks jedis.

mossy hazel
#

or change the method using developer tool

grand lintel
#

You da man

#

After playing around Chrome as an option to re submit the request

#

Chanced sutff there got me to see the flag thank again

#

I did it threw the developer tool

wicked mica
#

Im working through the SMB tasks in the Network Services room of the Complete Beginner pathway. I downloaded an id_rsa private key file and changed the permissions chmod 600 id_rsa and the next task is to "use the service and key to log-in to the server". I'm lost as to how to do that. I've added the keys to my ssh folder but don't know how to use the keys for authentication into the target machine. Any hints?

modest flicker
#

do u know the user name?

amber shoal
#

hello

#

can someone explain what the protocol security negotiation error means

#

in xfreerdp

waxen mica
young lagoon
amber shoal
#

i couldn't understand the term protocol security negotiation

#

maybe it's related to certificates or something

young lagoon
#

Hmmm.. A quick google search shows tons of hits. You could go down the list and see if anything matches your problem.
Or fire up a fresh VM install RDP client of choice and see if a fresh install changes anything.

scarlet bone
#

hello im working on wreath room i downloaded the first key(id_rsa) from the first machine ( web server but when i try to ssh i get this permission error )

amber shoal
#

which error?

scarlet bone
#

ssh -i rsa root@<ip> 255 β¨―
Load key "rsa": invalid format
root@<ip>: Permission denied (publickey,gssapi-keyex,gssapi-with-mic).

amber shoal
#

hmm not sure but invalid format could mean something went wrong while copying the key

scarlet bone
#

i tired copy paste and meterpreter download both i get same error .

amber shoal
#

dont understand what you meant by meterpreter download

#

how did you receive the key?

amber shoal
#

evil-winrm works fine

young lagoon
bitter cliff
#

Could someone hint on the HackPark challenge?

wicked mica
untold robin
#

If someone has completed the Redline room that was just added today, can someone share how they set up the "Memory, Disk, System, Network, and Other" in the "View and Edit Your Script for Windows" for IOC Search Collector for Task 6? Given the hint for one of the question in Task 6, it says to look at "PE Info," but that is not even available to be viewed.

modest flicker
wicked mica
green minnowBOT
#

Gave +1 Rep to @modest flicker

simple forum
#

is this an error consistent with a permissions issue, or is the script is the BASH file I'm supposed to use creating the error on its own.

#

Thank you in advance for your insight.

modest flicker
noble yew
#

im stuck

#

._.

#

its uh with the metasploit room

modest flicker
waxen mica
#

That won't run for obvious reasons

simple forum
#

no sir, i simply ran the bash with ./bash -p as instructed.

#

@waxen mica

#

when i ran the bash through my VM natively, i got a similar 'redirect error'.

#

but it sounds like at least it's not an issue with the permissions.

#

so that's a plus.

#

Thank you for your reply.

#

that's the bash shell it's asking me to run.

left thunder
simple forum
#

i did not. i used curl -o

#

(slaps head)

#

that's a good idea, and i will try it later.

left thunder
simple forum
#

Thank you for that. i've re-downloaded the BASH and renamed it to BASH from BASH?raw=true

#

i'll re-run the course and report back if that solved the issue.

#

Thank you.

abstract sparrow
#

Hi fam, any hints on Netsec challenge on ftp nonstandard port

prime willow
abstract sparrow
green minnowBOT
#

Gave +1 Rep to @prime willow

brisk berry
#

I'm stuck at the 3rd flag in the blue room

#

please help

#

nvm got it

alpine kestrel
#

congratz on getting it

fathom ridge
#

so theres this task "
A very useful output format: how would you save results in a "grepable" format? "

#

i did nmap -H

#

theres no info about this

#

the answer was -oG

#

but i found this by googling

#

why isnt it on nmap manual or help

alpine kestrel
#

it is in the man nmap page

#

nmap -H is just a short introduction and not the full nmap manual that you get from the command man

#

if it is not maybe you have an old version..... or you were just unlucky and missed it

waxen mica
#

You will always need to be able to find answers on google

#

Even as a profesional

fallow badge
#

would anyone know why this pass is not working

stuck fractal
fallow badge
#

thats what i have done in my linux fundamentals

fathom ridge
#

no need on that task probably

stuck fractal
#

It's best not to assume what you're meant to do

fathom ridge
#

did so much research on google about this

#

" Known by many names, SYN-scanning, or Half Open scanning is where the full TCP connection is never made. SYN-scanning sends the first packet only, the one marked with the SYN flag. It waits for either a RST, ACK or SYN,ACK response. "

#

none of these options work

#

the answer format is too long for any of these to work

fallow badge
#

what could I be missing this time ?

#

nvm im connected

#

sorry

alpine kestrel
fathom ridge
#

the answer format is so weird

alpine kestrel
#

one is a very old name

ripe hedge
#

also read the task

pallid moss
fathom ridge
#

furthernmap

#

SYN scans can also be made to work by giving Nmap the CAP_NET_RAW, CAP_NET_ADMIN and CAP_NET_BIND_SERVICE capabilities; however, this may not allow many of the NSE scripts to run properly.

misty lynx
#

One of the answers is stealth scan iirc

fathom ridge
#

" syn scans can also be made to work "

pallid moss
fathom ridge
#

is this a reference to being other name for syn scan

#

the question is really hard

#

its just a puzzle at this point

pallid moss
misty lynx
#

It's really not

fathom ridge
#

look at the answer format

#

it has a " , "

#

in middle

#

like what

pallid moss
#

yeah

#

indicating that it wants two answers

#

answer1, answer2

misty lynx
#

Except no spaces

pallid moss
#

works with a space

fathom ridge
#

the other one is half open scan ?

pallid moss
alpine kestrel
#

half-open... no space

pallid moss
#

honestly, read through the text that is there, you'll have it in no time

fathom ridge
#

yeah the question was harder than the answer it self

#

got it now

alpine kestrel
#

good job getting it now

fathom ridge
#

took only like 50 minutes

pallid moss
fathom ridge
misty lynx
#

Some aren't immediately intuitive like privesc rooms

soft seal
#

Hey all, looking for some assistance. I am in the "Content Discovery" room on task 3. I have identified the favicon, got the hash, and cross-referenced it to the OWASP database. There is only 1 match that is "Zero byte favicon". However that answer is to long. I have tried all 3 words individually, with no luck. I ran the process again came up with the same result, and am stuck as I can not determine the stack framework. Any thoughts?

noble yew
#

so im doin the metasploit room rn but whenever i try to send it over it always ending up taking a long time or saying no session was created

noble yew
#

i do use another vpn whenever i use my vm but i doubt its the prob

#

but yall are smart so

flint falcon
# noble yew but yall are smart so

I did this room if this doesn't match u can reboot the target and then begin back... When it does the same the second time u must insist u can still add LHOST after RHOST if u didn't the first time

fading robin
prime willow
opal elbow
#

Hey guys! I'm somewhat stuck on the new IDE room. I've used an exploit to get a shell. So far so good. From a certain file I know that there's an image that might contain helpful information. I know where the user flag is but I cannot access it as I don't have the privileges. Any hints on what I should look out for?

prime willow
opal elbow
green minnowBOT
#

Gave +1 Rep to @prime willow

prime willow
fading robin
# prime willow Sure πŸ™‚ Request-Type/Cookie

huge thank you, i didnt even think about that. i was stuck in different types of URL encodings, then i was thinking that maybe its something related to the / added after each quiry i tried to add cause it looked suspicious xd

green minnowBOT
#

Gave +1 Rep to @prime willow

noble yew
#

it starts the reverse tcp handler then sends it, then theres just no response

thorny raptor
#

Good morning/afternoon/evening! Got a query about the KotH Hogwarts room. I am struggling the figure out the 7th (final?) flag. I found three deathly hallow clues ||(search file content for Invisibilty cloak:, Elder wand:, and Ressurection stone:)||, which I guess combine to the final flag. Anyone any thoughts/suggestions?

ripe hedge
#

don't think we usually offer help on active KOTH rooms

fallow badge
#

what am i Missing any clues ?

ripe hedge
thorn hollow
#

Hello! i'm learning about regular expressions and am stuck on Charsets. When excluding a number does the ^ go into the same charset as the group of files?

fallow badge
ripe hedge
#

might be a googlable question, eh?

#

found this

#

for example

fallow badge
#

ill look right into it

#

Guest ?

#

omg y did i speak so dumb.. it must be Guest. right ?

#

but doesnt it ask me to use "Anonymous"

noble yew
#

it does-

#

ion really remember that room too well but pretty sure the name "anonymous" is like a whole role in it self

#

like administrator blah blah

thorny raptor
ripe hedge
serene onyx
#

any hints on the IDE room? Tried working out with the unauthenticated public exploit without success. should there be anything on that ftp?

white salmon
#

I am on WebAppSec101 Room, Task 4, Question 4 What is the username of a logged on user?. The Hint suggested is to use Daniel Miessler's names.txt list to bruteforce the usename. There isn't any hint on what tools to use, so I tried using hydra and with this command: sudo hydra -l admin -P /home/kali/wordlists/names.txt IP http-post-form "admin/index/index.php?page=login:adminname=^USER^&password=^PASS^" to no avail. Anyone know what tool to use for this? i also thought about enum4linux but there is no smb

loud nebula
#

Have not complete the room yet nor familiar enough with hydra, but you use -P for password with wordlist, the wordlist you give is a names.txt for username. switch it with -l to -L /home/kali/wordlists/names.txt

white salmon
#

Shoooooooot

#

you right let me see if works

loud nebula
#

you have the password?

white salmon
#

but the question is asking for what the username is ?

#

i thought it was admin but it's not

#

shit dude

#

wrong post

#

my bad

loud nebula
#

glhf

white salmon
sharp talon
#

hi iam stuck in n map live host discovery, in TASK 7

snow birch
#

did you check the crontabs?

indigo ledge
sharp talon
snow birch
snow birch
sharp talon
#

Hi iam stuck in nmap live host discovery room TASK 7

indigo ledge
#

man im stuck at Privesc

sharp talon
snow birch
indigo ledge
#

IDE

sharp talon
snow birch
#

or the permissions of some bins

sharp talon
#

hey how can i get the roles

indigo ledge
#

yes im just going through them!

indigo ledge
snow birch
sharp talon
sharp talon
indigo ledge
snow birch
#

it is in your profile

sharp talon
sharp talon
indigo ledge
snow birch
indigo ledge
#

ur da made me think of that

sharp talon
#

yo iam verified

sharp talon
snow birch
snow birch
sharp talon
indigo ledge
#

dayum!

snow birch
#

Hard dox xD

sharp talon
indigo ledge
#

yes

sharp talon
#

coool

indigo ledge
#

Linkedin?

sharp talon
#

yeah

indigo ledge
#

gg

sharp talon
#

dont attach like that

#

@indigo ledge have u done nmap live host discovery room?

indigo ledge
#

no mate

#

i will do that next for sure

sharp talon
#

ohh, how are u playing VM ware

#

what u will do in that

indigo ledge
snow birch
#

only 3 people have it now

sharp talon
#

that*

snow birch
#

Its for an event, but it ends...
I've actually wanna get this role

sharp talon
#

now what s special about this role

snow birch
#

Da

sharp talon
#

DaDa

bitter whale
#

Could anyone give a hint for 'Task 8: Blind SQLi - Time Based' of SQL Injection room: https://tryhackme.com/room/sqlinjectionlm -> I have the table schema ||sqli_four ||, but the table name just doesn't seem to come correct. Currently, it is at ||analytics-referrer-% (assume - to be _ )||, I even tried || like 'analytics-referrer-' it works. But when I use = 'analytics-referrer-' it doesn't||
I seem to have tried every alphanumeric character, yet nothing comes to be correct.

prime willow
bitter whale
#

I think that the table named probably are different?

prime willow
bitter whale
# prime willow ||nope||

thanks happyPanda I fell into a rabbit hole and went onwards to trying everything on a new/different table in that database

green minnowBOT
#

Gave +1 Rep to @prime willow

lilac elk
#

Hi, guys. I'm stuck on a question on Network Services under the Complete Beginner path. Enumerating Telnet, question 6 to be exact. "
Based on the title returned to us, what do we think this port could be used for?" I've been entering flags to get more info on the port but to no avail. What should I be looking for when sifting through the nmap docs?

waxen mica
#

What flags are you using?

lilac elk
#

I tried sV, sC, A, sS, O and a couple others

waxen mica
#

A should give it to you

prime willow
lilac elk
#

@prime willow lol

#

I'll keep digging, thanks guys

drowsy gulch
#

Could someone give me a hint with python for cyber security please ? I'm stuck on the question "What is the function used to connect to the target website? "

#

When looking around online the most common functions used to connect to a website are ||requests.get|| and ||urllib.parse|| or ||urllib.request||. What other ones are there ?

drowsy gulch
#

Never mind. I realised I needed to include () in my answer

white salmon
#

Could anyone pass me a hint on enumeration of the Enterprize box?
Subdomain fuzzing, nmap, and gobuster only yield the /var and /public directory, without me being able to find any further files.
Only port 22 and 80 seem open, although nmap is taking forever to complete the scan.

white salmon
pliant abyss
#

has any one finished holo? i'm stuck on the first privesc

waxen mica
gritty crescent
#

Hi everyone. New to THM.
I'm working through Task 4 - Exploiting SMB
question: "...Download this file to your local machine, and change the permissions to "600" using "chmod 600 [file]"...
I don't see scp, but do see scopy. I can't figure out how to use scopy to get the id_rsa file off the target server to my local (attackbox) machine so I assume scopy isn't what I should be using. Can someone help point me at which tool I should use? (T.I.A!)

somber glacier
#

Can you show me the room?

native atlas
white salmon
white salmon
#

Didn't do the trick.

mental quarry
#

In the buffer overflow prep room, for overflow2 , my offset is coming ||633|| but seems the answer is ||634||. Is the problem same with everyone, or is it just me?

loud nebula
#

Scroll up there, you may find the hint you need

prime willow
white salmon
green minnowBOT
#

Gave +1 Rep to @prime willow

indigo sandal
#

NetworkServices Task-6 Q1 just we need to scan like this ryt?
nmap <ip>

glacial badge
#

Any hints for the new IDE room by Bluestorm and 403Exploit? I got a file on the anonymous ftp and found how to read it but I don';t understand what the password is and where i'm supposed to use it

left thunder
indigo sandal
#

ok i will try that

left thunder
fading robin
fading robin
gritty crescent
green minnowBOT
#

Gave +1 Rep to @native atlas

mental quarry
#

In the buffer overflow prep room, for overflow2 , my offset is coming ||633|| but seems the answer is ||634||. Is the problem same with everyone, or is it just me?

nova void
#

Hello i cant find right answer for Priv Escalation (linux ) Task 10 Q:1. I done all other questions but i cant find only this one . When i run echo $PATH there is nothing that fit as answer. Where i am going wrong ? Any hints ? Thank you in advance.

left thunder
nova void
#

this is the question " What is the odd path in PATH? "

left thunder
nova void
left thunder
nova void
#

Oo yes i saw it now. Thank you for the help

north saffron
nova void
hasty zodiac
#

Hey there! Would anyone have a hint for room oscommandinjection:
What popular network tool would I use to test for blind command injection on a Linux machine?

I've been trying all tools I could think of (I must not know of it).
Even tried looking it up but most searches ended up with Commix (also tried searching for Commix alternatives to no avail).

EDIT Got it.

heavy escarp
hasty zodiac
heavy escarp
#

Yeah, that's what I've been playing with. ||Cookies and HTTP Headers|| and not making any headway, sadly

heavy escarp
#

Hmm, okay thanks.

heavy escarp
# hasty zodiac ||That's not it||

Alright, Been trying for about another hour and still no luck on this. Now I'm trying to ||POST the request, but can't seem to use %00 to null the .php||, am I barking up the wrong tree again?

hasty zodiac
green jungle
heavy escarp
#

Hmm... yeah I went to ||curl|| and got it to work. couldn't get it to work in ||browser or burp||. Thanks for the tips.

wary ocean
#

Sad to say I'm having a bit of trouble with File Inclusion Challenge 3

#

Nevermind, found the solution

modest pagoda
#

yeah, I'm just stuck on nulling the php. can't seem to make it work any which way i try it

#

aaaaahhhh I GOT IT

timber plume
#

I was doing jr pen test stuck at lfi flag3 which doesn't accept any special char or number
A small hint please thanks

modest pagoda
#

read the convo just above

#

it really puts you on track

vale otter
#

Hello I'm doing the Network services part 2 room and I'm not sure which nmap flag i'm suppoed to use to find the open port

#

the question indicates there is 1 port open

#

I tried -sV and -sT

terse nova
vale otter
#

nope

#

thank you

terse nova
#

:))

vale otter
#

I'll try that

gilded flare
#

Any nudge on lfi chall3, pls? I read the convo above but still cant get it

modest pagoda
#

look through curl --help and see the different ways to send a file

gilded flare
#

Do I have to upload a file?

modest pagoda
#

no. just send a request for one

#

i chose my words xrong. Should have said integrate

gilded flare
#

Oh, ok, I'll try. Thanks!

#

Im just very dumb

#

Thank you, I got it!

#

Dunno why I didnt think of this in the first place

stiff oasis
#

hello i have question iam unable to crack hash through john Using default input encoding: UTF-8
No password hashes loaded (see FAQ)
the error i am getting is this Using default input encoding: UTF-8
No password hashes loaded (see FAQ)
the command i used is john id_rsa --wordlist=/usr/share/wordlists/rockyou.txt

terse nova
#

any hints for the linprivesc room task 9

dry gate
#

in order to post screenshots, you need to verify :P

#

!docs verify

proud scarabBOT
tulip mural
sturdy shadow
#

I'm struck with that blind sql Question in room

I got database and by doing like like statements but then struck going next.
link-https://tryhackme.com/room/sqlinjectionlm
Room - SQL Injection
Task - 8

I tried everything and got to know the table name but what to do.

idle basalt
#

hello can any one help with "Walking an Application " Pen testing course having a problem with finding 2 questions. One being "
What is the flag from the HTML comment"

left thunder
idle basalt
left thunder
idle basalt
#

yea i did that on both pages, im over looking both websites source code as we speak but there is only 1 comment at the top of the page and that's not the flag.

left thunder
idle basalt
#

wow... smh... that simple. i was thinking it would be links you could click on like number 2. so one last question any hints on 3 and 4. and then i'm done for today. Please and thank you.

idle basalt
green minnowBOT
#

Gave +1 Rep to @left thunder

left thunder
left thunder
idle basalt
left thunder
vale otter
#

This is asking about a title returned, but I don't see anything regarding a title.

left thunder
# vale otter

Try to scan with the -sV or -A flag instead of -sT on that port (so no need to scan all ports again)

vale otter
#

Does have to be a space between the flag and the port number?

vale otter
#

Gets stuck at 0.00 percent with either of those options

left thunder
vale otter
#

ok

#

thanks i'll try that

vale otter
#

got this returned

white salmon
#

in the 3rd challenge of fileinc, i could actually make it bypass the filtering but it doesn't interpret the null terminator, don't know what to do

left thunder
# vale otter

Alright, so that should give you the answer to your question πŸ™‚

vale otter
#

@left thunder ok i'll try to figure it out. it's just that the format in which the answer has to be is throwing me off

left thunder
# vale otter

Well it's basically just like that "A banana" or A car" πŸ˜„

vale otter
#

ok thank you for the help

vale otter
rustic surge
#

What is meant with "What is the odd path in PATH?"?

#

edit: got it, but it wasn't in path

blissful yoke
#

@left thunder for task 3 question 3 walking an application. From what I can read I am supposed to open a directory in the web browser to find the flag.txt file. How do you go about opening the directory

white salmon
#

Can i get a hint for Authentication Bypass task 4

#

I've read everything multiple times and done as it says, and been messing with the site to try get the support ticket

#

but either i cant find the link in the output, or I'm doing something incorrect

left thunder
rustic surge
#

task 6 q3, can someone lend me a hint?

blissful yoke
green minnowBOT
#

Gave +1 Rep to @left thunder

hasty zodiac
rustic surge
left thunder
hasty zodiac
#

ohhh....

#

uhhh.... that's an oversight on my part haha

left thunder
rustic surge
#

it should be unquotedpathservice.exe right?

hasty zodiac
green minnowBOT
#

Gave +1 Rep to @left thunder

left thunder
#

Nothing to feel dumb about, that happens to all of us πŸ˜„

quick jetty
#

Hey there

rustic surge
#

h

quick jetty
#

--help

rustic surge
#

sec

#

try using john

#

extract hashes of /etc/shadow

quick jetty
#

I'm unable to understand how should i escalate

#

can't

rustic surge
#

??

quick jetty
#

no perms

rustic surge
#

less suid/

#

wait nvm

#

uhh

quick jetty
#

i didn't get u

rustic surge
#

wait

#

nvm

#

lemme boot up the machine

quick jetty
#

i can't find anything useful in the suid files

rustic surge
#

attackbox is almost upp

quick jetty
rustic surge
#

have you taken a look at SGIDs as well?

quick jetty
#

jst a min

rustic surge
#

I described the 2nd stage of this privesc "accidentally", gl!

quick jetty
#

cool thanks!

hasty zodiac
#

well uhhh coming back with another request for a hint with the meterpreter room.
Task 5 Question 6

#

I found the answer but I can't input it

rustic surge
#

then it's not the answerℒ️

hasty zodiac
#

It is...

#

1000%

#

the next question asks the content of the file which I have correct

#

the sixth question asks for the path (and it wont accept the path I put in)

quick jetty
left thunder
hasty zodiac
#

with forward slashes

rustic surge
#

okay so this might sound weird but I think -4000 includes -2000 etc

#

and +4000 above 4000

quick jetty
#

ah! i got it

rustic surge
#

probably incorrect, but that follows the logic of the dates in the find cmd

left thunder
quick jetty
left thunder
#

Try it with backslash, as well as a backslash at the end.

hasty zodiac
#

oh.... man... the placeholder is showing a forward slash though haha

#

it works...

hasty zodiac
green minnowBOT
#

Gave +1 Rep to @left thunder

hasty zodiac
#

THM bamboozled me with the placeholder

quick jetty
#

@rustic surge i checked the sgid, still nothing useful

rustic surge
#

don't be based

quick jetty
rustic surge
#

yes

#

it's a good hint

#

in contrast to the one in the room

quick jetty
quick jetty
rustic surge
#

etc shadow

#

john with rockyou

quick jetty
rustic surge
#

with base64

waxen mica
quick jetty
quick jetty
viscid mist
#

Guys in the SQL Injection task 8 ... I am not getting an answere

waxen mica
#

Look at the first one

rustic surge
#

I figured einst3in already checked gtfobins

#

whoops

quick jetty
#

or maybe i think i need eye surgerycri

rustic surge
#

how about both

waxen mica
quick jetty
#

i don understand wht should i place on the./base64

#

the wordlist?

#

or the etc/pass

nimble prawn
#

why ./base64? can you not run it from path?

quick jetty
#

even that didn work

#

i specified the path

#

lol! i got it

#

nvm solved

#

this thing was kinda interesting

nimble prawn
#

oh good, i was trying to figure out which question you were on.

quick jetty
#

haha..nvm thanks

nimble prawn
#

i used base64 more than i should have on some of those linux privesc ones

#

burp suite basics - task 9 connecting through the proxy. Does anyone know what right click menu its talking about?

hasty zodiac
#

Hey guys... stuck once again on some stupid stuff..
Doing Burp Suite: Repeater T6Q3.
Added the header and sent the request successfully but I get an empty response.

nimble prawn
#

I feel like none of the responses that make sense match the answer format. Like "send to repeater" doesn't work

nimble prawn
hasty zodiac
quick jetty
quick jetty
sturdy hearth
#

I think, those are two CRLF as stated in HTTP Protocol

nimble prawn
#

lol im about to skip it but im halfway though it and i want my tickets

quick jetty
#

lol

white salmon
#

Can anyone help me with the file inclusion rooms last challenges?
I can't figure out how to use post to modify the form requests

#

Been banging my head on it for hours now

nimble prawn
#

flag 3 or the playground?

white salmon
#

Flag 1 itself πŸ˜…πŸ₯²

nimble prawn
#

ohhh yea that one was weird for me. In firefox open with inspector and stay in the inspector tab. Don't go to network

#

you have to modify the body line that says action=# and the method

#

then do your file inclusion on the bar like normal..if that makes sense..like on the actual web app

white salmon
#

So change the method from get to post, and then simply add the file extension on to the http link ryt?

nimble prawn
#

or you can use curl

#

the action is the entire url

quick jetty
nimble prawn
#

not file inclusion thoug

white salmon
nimble prawn
white salmon
#

Woah, alright, lemme see how this works, thanks for the help

nimble prawn
quick jetty
#

$6$m6VmzKTbzCD/.I10$cKOvZZ8/rsYwHd.pE099ZRwM686p/Ep13h7pFMBCG4t7IukRqc/fXlA1gHXh9F2CbwmD4Epi1Wgh.Cl.VV1mb/

#

this is wht i got

nimble prawn
#

lets see.. i didn't look at them all so maybe i did. I copied shadow to shadow.txt and passwd to passwd.txt
unshadow passwd.txt shadow.txt > unshadowed.txt
then i ran john against the unshadowed.txt file

#

i didn't do anything outside of that. One thing i did notice though is you have to be in the right VM for each challenge

#

sometimes i would keep using the same VM and it just woudln't work

quick jetty
#

ah ! okay lemme see!

white salmon
#

sorry if i seem clueless, am new to this😫

nimble prawn
#

the flag isn't at the bottom?

white salmon
#

nope, at the bottom, the only extra part is it mentions the file location of the link, and this
<h5>File Content Preview of <b>/etc/flag1</b></h5>
<code>F1x3d-iNpu7-f0rrn
</code>
</div> </body>
</html>

nimble prawn
#

LOL

#

its right there

quick jetty
white salmon
#

ffs, thats it?

#

i got that long ago, i was looking for the thm flag

quick jetty
#

hah

white salmon
#

i kms

nimble prawn
#

XD

quick jetty
#

to read the flag

#

okay! its confusing

delicate grotto
celest moth
#

Hey could someone give me a hint on flag3 for the FileInclusionVM?

celest moth
#

Task 8, capture flag3, sorry

#

My last wasn't very clear. I've gone through a lot of manual checks.

#

But I keep noticing a '.php' being added to my input. And it seems to be filtering on special characters and numbers.

#

Read through the W3 php filters and noted a few ways it might be doing some sanitation.

waxen mica
#

Have you tried methods other than GET?

celest moth
#

Yes. Been using repeater to test methods GET and POST

#

I've tested manually adding %00 and the hex escape also

#

For GET, Started using php:filter//convert.base64-encode/resource=welcome

To try and get the b64 out but it is heavily filtered

waxen mica
#

Don't do that

#

You don't need base64

#

Just try some other METHODS

celest moth
#

Hm ok so I should refocus on a something simpler.

waxen mica
#

Yes

celest moth
#

So going back through thr POST request I've sent they are all being filtered completely down to a blank '.php'

#

Is this one of the language examples?

waxen mica
#

No

#

Remember that post requests are you sending data to the server. You aren't necciserily asking for anything to be returned back to you

celest moth
#

Am I supposed to be trying to inject some php that effects the include_path function?