#junior-pentester-path

1 messages Β· Page 13 of 1

jade lodge
#

this SSRF example2 is killing me

modest arch
#

idek how I got through ssrf? I've never really done it before

#

ohhhh actually that was a super cool challenge

jade lodge
#

i see the mechanics of how it works.. but i'm not getting the answer. just a 404

polar cloak
#

Need some help im on LFI task 8 flag2 i send my curl command and get "this is a admin webpage! Get the flag! but see no flag

jade lodge
jade lodge
loud spire
#

ffuf -w valid_usernames.txt:W1,/usr/share/wordlists/SecLists/Passwords/Common-Credentials/10-million-password-list-top-100.txt:W2 -X POST -d "username=W1&password=W2" -H "Content-Type: application/x-www-form-urlencoded" -u http://MACHINE_IP/customers/login -fc 200

#

does the command contain any kind of error ?

#

because whenever i am trying to bruteforce, i get no results

lavish rose
#

can I DM you about lfi challenge

jade lodge
# lavish rose can I DM you about lfi challenge

you can hit me up tomorrow if you have issues still. going to sleep.
my primary caution about LFI is this

  1. inspect the response
  2. read the errors **very **carefully
  3. if you change the request and make progress.. do it again with changes. see what small changes do. ensure you really know whats happening. your assumption on the website is doing may be wrong
lavish rose
next lanceBOT
#

Gave +1 Rep to @jade lodge

modest arch
#

Hey guys, I need help with first challenge of LFI.

lavish rose
modest arch
lavish rose
dusky crescent
#

Finally got the first challenge of LFI

#

I was changing the request wrong πŸ˜…

lavish rose
#

is anyone up who has done lfi playground rce question?

modest arch
modest arch
#

In Lab #2, what is the directory specified in the include function?
I am trying to solve this from past one day...but I didn't get it
Can someone help in this

#

need help with first challenge

dusky crescent
#

Enter invalid input and look at how the function is being used

modest arch
#

@dusky crescent Sir, I did this but not understanding

lavish rose
dusky crescent
modest arch
dusky crescent
#

That's the directory

modest arch
modest arch
next lanceBOT
#

Gave +1 Rep to @lavish rose

slender pivot
#

Anyone done Metasploit exploitation Task 6, keep getting Segmentation fault (core dumped)
while running the payload

modest arch
#

What does.the directory say? Does it match anything you may have done so far? Does changing something in the cookie change the directory? @modest arch

modest arch
modest arch
young vault
#

@tardy grove Thank you sir! I appreciate your help on the SQL Injection πŸ™‚

next lanceBOT
#

Gave +1 Rep to @tardy grove

dusky crescent
modest arch
modest arch
#

As MonkeyBoi said, in the include() function

#

It will currently partially match something you have done to the cookie

modest arch
#

Wait

#

Have i said too much too soon ?

#

Have you got past the guest screen ?

#

Oh you must have in order to get the error message

dusky crescent
modest arch
#

I have my wires crossed ?

modest arch
#

Oh ignore me

#

Sorry i thought you meant challenge 2 , I should really learn to read

dusky crescent
#

Solette have you done challenge 3?

modest arch
#

I'm on it now. Just booting my machine to have another crack while the kids run circles around me screaming

#

Have you managed ?

dusky crescent
#

I'm still working on it

#

I finished the first and second ones

lavish rose
modest arch
#

Thank you all, I got answer

slender pivot
#

Anyone done the metasploit room yet?

#

damn thing is driving me insane, the msfvenom machine keeps throwing up segmentation fault

modest arch
lavish rose
modest arch
lavish rose
modest arch
#

That's encouraging. And you are right, curl is easier

#

Ugh this is frustrating

#

@lavish rose mind if I DM you rather than ask here? I just want to make sure I did something right

glacial hornet
#

This isnt the flag they are looking for. I found it as well, if you read included documentation you'll find the proper flag πŸ™‚

indigo lark
#

Anyone able to give me a nudge in the SQLI room? I'm stuck on task 8

balmy tinsel
#

I am stuck at challenge3 lfi room... Any nudges?

#

@lavish rose may I dm u for the chall?

#

I just need a little hint for the chall...I have completed the room except for this one chall

#

And now it just seems impossible to doπŸ₯²

lavish rose
indigo lark
coarse granite
glad anchor
balmy tinsel
glad anchor
#

Nice

#

Can i get a small hint how to get one flag i got last one

balmy tinsel
#

For chall 3

coarse granite
balmy tinsel
#

How did u made it work with burp?

coarse granite
glad anchor
#

For 2 i change Cookie to admin but nothing happened

balmy tinsel
balmy tinsel
coarse granite
#

I’ve PM’d it πŸ™‚

somber wolf
lusty bolt
somber wolf
#

lol burp tricked my with double encoding on the trailing %00 on challenge3... -> %2500...

winter canopy
#

anyone having problem accessing machine from content discovery room?

#

i cant access the link from task 2 which is http://{IP}/robots.txt

prime lava
tender ravine
glad anchor
tender ravine
glad anchor
#

Worked for me

lusty bolt
glad anchor
#

But i am still stuck on LIF challenge 8 don't know what to do

tender ravine
#

Was able to find the first flag, the second and third I have no idea

glad anchor
#

4th one was easy

#

For 2nd i changed cookies to Admin but then i don't know what to do next

tender ravine
#

Change the method to POST. I changed the request to POST /challenge... and removed the ?file... then I added Content-type: application\x-www-form-urlencoded. At the end I added file=../../../../etc/passwd.

#

This shows me the passwd file. You can change it to flag1 to find the flag

lusty bolt
#

at the end of where?

#

hmmm

#

I can't get it to work

tender ravine
lusty bolt
#

I just get no response if I do that

#

I have this
||POST /challenges/chall1.php HTTP/1.1
Host: 10.10.234.157
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.9
Accept-Encoding: gzip, deflate
Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
Connection: close
Content-Type: application/x-www-form-urlencoded
file: ../../../../etc/flag1||

#

did I miss something?

tender ravine
#

One moment will try it out

modest arch
#

Capture Flag1 at /etc/flag1

#

Can anyone help in this

remote estuary
#

chall2 : change the cookie with the file you look for and bypass it with the null byte

rocky thicket
#

please help in the Local File Inclusion - LFI #2 try to read /etc/passwd. What is the request look like?

modest arch
next lanceBOT
#

Gave +1 Rep to @remote estuary

glad anchor
#

On LIF? Task 8?

remote estuary
#

chall3 : change the request method to POST method, use the path traversal and with the null byte to bypass the filter

modest arch
plush widget
#

Is chall3 a binary?

twilit chasm
remote estuary
#

chall3 : ```
POST /challenges/chall3.php HTTP/1.1
Host: 10.10.151.115
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:93.0) Gecko/20100101 Firefox/93.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,/;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Connection: close
Referer: http://10.10.151.115/challenges/chall3.php
Cookie: THM=admin
Upgrade-Insecure-Requests: 1
Sec-GPC: 1
Content-Type: application/x-www-form-urlencoded
Content-Length: 35

file=../../../../../../etc/flag3%00

modest arch
rocky thicket
#

please help in the Local File Inclusion - LFI #2 try to read /etc/passwd. What is the request look like?

lusty bolt
#

Oh, I figured out flag1

tender ravine
lusty bolt
#

The file path was wrong, I needed another ../

timid dawn
remote estuary
lusty bolt
#

in burp any text I type overwrites the other text

#

what is happening

#

I try to put a space and it just deletes the character

#

it's like a block cursor instead of just a bar too

tender ravine
plush widget
#

Do we need to host a web server for the RCE part in File Inclusion?

tender ravine
lusty bolt
next lanceBOT
#

Gave +1 Rep to @tender ravine

rotund thorn
tender ravine
tender ravine
# lusty bolt I have this ||POST /challenges/chall1.php HTTP/1.1 Host: 10.10.234.157 Upgrade-I...

||POST /challenges/chall1.php HTTP/1.1
Host: 10.10.247.195
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:80.0) Gecko/20100101 Firefox/80.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,/;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Connection: close
Referer: http://10.10.247.195/challenges/chall1.php
Upgrade-Insecure-Requests: 1
Content-type: application/x-www-form-urlencoded

file=../../../../etc/flag1||

lusty bolt
next lanceBOT
#

Gave +1 Rep to @tender ravine

tender ravine
#

This should do the trick using Burp

modest arch
#

would be nice to explai nthe x part in this solution here again.

quick light
#

I need urgent help in sql injection task 8 blind sqli time based

#

I got the column names but got stuck after that

uneven niche
#

heuu guys i'm on the last question of Windows PrivEsc got root access and i'm looking for flagUSP where is this damn file X) i checked on admin/documents and Administrator/documents nothing is here

kindred lantern
#

i may lose my mind on skynets lfi lol its taking the file from my http server but not letting me run it to spawn a shell

hazy hinge
#

HeI ask a question with Local File Inclusion - LFI #2 try to read /etc/passwd have tried a bunch of things buts cant get it working.
things like:-

idle bison
kindred lantern
#

its a php rev shell

hazy hinge
#

/lang.php?file=/etc/passwd or something like that

modest arch
#

Gain RCE in Lab #Playground /playground.php with RFI to execute the hostname command. What is the output?

#

Please help in this

loud spire
#

hey, i can read the contents of /etc/passwd, but i am unable to take /etc/flag1

#

i have also changed request from GET to POST

slender pivot
quick light
slender pivot
#

task 7 yes, just starting it now

quick light
#

okay

modest arch
#

Don't think too hard. Where would they store x (where x = what they want)

modest arch
deft crater
#

Hello, I'm trying to complete the XSS room with the final flag. I've tried to steal staff-session cookie wtih the code and my IP address and port but it's not working. i'm sure iI'm connected o the vpn becuase i can ping the machine/access the website. Abnd I've put the IP given for interface tun0 on my machine If someone can help me it could be nice thk y

tender ravine
# loud spire hey, i can read the contents of /etc/passwd, but i am unable to take /etc/flag1

||POST /challenges/chall1.php HTTP/1.1
Host: 10.10.247.195
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:80.0) Gecko/20100101 Firefox/80.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,/;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Connection: close
Referer: http://10.10.247.195/challenges/chall1.php
Upgrade-Insecure-Requests: 1
Content-type: application/x-www-form-urlencoded

file=../../../../etc/flag1||

#

This should work

modest arch
quick light
loud spire
#

oh man i am doing so much of mistake from the past 2 days instead of doing change request using BURP i am changing it manually

tender ravine
modest arch
loud spire
#

it's not happening

subtle heron
tender ravine
modest arch
modest arch
modest arch
tender ravine
slender pivot
quick light
slender pivot
#

ah ok, im not that far yet

quick light
#

yeah it took a long time to reach there

loud spire
#

it was easy though

deft crater
slender pivot
next lanceBOT
#

Gave +1 Rep to @tender ravine

quick light
quick light
deft crater
lavish rose
#

has anyone completed Linux and/or Windows PrivEsc?

slender pivot
modest arch
lavish rose
quick light
#

so I think it's gonna be easy now

modest arch
lavish rose
modest arch
#

Sure

lavish rose
next lanceBOT
#

Gave +1 Rep to @fleet horizon

slender pivot
# quick light yeah and I just got the second table_name

I'm not even getting a delay now i'm trying to find the table_name, even with ||'%';--|| ||UNION SELECT SLEEP(5),2 FROM information_schema.tables WHERE table_schema = 'sql______' and table_name like '%';--|| Is that what you got?

drifting drum
#

No

#

You're schema is wrong

quick light
#

the schema

drifting drum
#

Yes

modest arch
slender pivot
#

ill go back to step 1 then, I was getting delays from ||sql______ ||though, thanks.

drifting drum
quick light
#

did anyone manage to get 3 oscp tickets?

modest arch
next lanceBOT
#

Gave +1 Rep to @drifting drum

drifting drum
slender pivot
#

think im on the way to the table name now

#

||analytics_(SOMETHINGHERE)|| right?

coarse marsh
slender pivot
#

fml

#

but the table schema is ||sqli_four ||right?

coarse marsh
#

yes

#

try other letters for the 1st string

slender pivot
#

bah just realised the table name that I was finding is already shown in the SQL query box...

coarse marsh
#

try SLEEP(2) for fast results

raw bolt
#

im on task 5 of File inclusion

#

Try out Lab #6 and read /etc/os-release. What is the VERSION_ID value?

#

im stuck on this question.

#

Nothing I'm inputting is working.

bitter plank
raw bolt
#

should I have file= in there?

lusty bolt
#

I'm trying to do this room, and I'm stuck on the last part of task 2, in the mock browser, it says the Server Requesting bar will show the url, but nothing shows there

nova mason
#

It was fun ! thanks thm

slender pivot
#

making progress now

#

found the columns in the table now

quick light
#

looks like you are going down the same rabbit hole as me

#

but keep going

quick light
#

try to figure out on your own

raw bolt
#

am I on the right track? I just keep adding ../

coarse marsh
coarse marsh
#

also bypass the filter

raw bolt
#

so double //?

coarse marsh
#

read carefully the explanation above

raw bolt
#

ah okay

#

monster hasnt kicked in yet

#

lol

wet silo
lusty bolt
drifting drum
#

No it means that your syntax is incorrect

lusty bolt
slender pivot
#

Got there in the end for the sqli time based injection

#

that was tough

#

thanks for the help

next lanceBOT
#

Gave +1 Rep to @wet silo

raw bolt
buoyant wind
#

LFI task8 chall2 any hint

#

i changed it from guest to admin using burp but didn't get the path

glad anchor
#

So should we directly enter path in cookies?

coarse marsh
#

trial and error is the key

lusty bolt
raw bolt
coarse marsh
#

try -sN

loud spire
#

there is not an input field in challenge2 of LFI

#

but how to change guest to something else in web dev. tools

#

when i click or double click on it, nothing happens

tender ravine
loud spire
#

ok

drifting drum
winged sparrow
#

Man, I love that you're adding new learning paths! Can't wait to get started on this bad boy after I'm done in Complete Beginner. πŸ˜„

lusty bolt
#

haha

loud spire
#

yeah

#

if you are talking about waling an application, then for your kind information, i have completed that module and that module doesn't show about editing cookies

#

@drifting drum

cobalt tundra
#

pretty sure he meant "task", not "module"

#

but thats not the issue

autumn crypt
#

i need help in Local File Inclusion - LFI#4 i don't know the request

loud spire
#

yes, that's not problem

#

i was doing that, but he mentioned like, you didn't pay attention

modest arch
#

Still can't get task 4 on Authentication Bypass working

#

I can't figure out what im doing wrong

loud spire
modest arch
#

I do all it asks, and can't get the creating an account curl request working

loud spire
#

check the command again

modest arch
#

I do it, but can't find anything from the output it sends

loud spire
#

you might be missing something

#

did u find valid usernames ?

modest arch
#

yes

tender ravine
modest arch
#

I got the 3

loud spire
#

are u sure that the file just contains, useranmes and nothing else

modest arch
#

it contains 4

loud spire
#

each line contains 1 username

modest arch
#

the 3 ones from the task and admin

#

yes

autumn crypt
#

Give Lab #1 a try to read /etc/passwd. What would the request URI be? - here is where i am stuck

modest arch
#

I can show you the file i have for it in dms

loud spire
loud spire
next lanceBOT
#

Gave +1 Rep to @tender ravine

tender ravine
loud spire
drifting drum
loud spire
#

i mean no cookies, but it's showinfg the cookie in network

autumn crypt
glad anchor
#

I am not getting LIF task 8
Flag 2 and 3

For 2 i know need to change THM to admin
I tried adding path also but not able to read flag

For 3 i only able to read welcome file

cobalt tundra
#

@autumn crypt what module/task is that?

autumn crypt
tender ravine
opal stirrup
cobalt tundra
#

youre talking about challenge #1/flag1, not the lab#1 from task4

opal stirrup
#

Ohhh

tender ravine
glad anchor
#

Yes but not able to understand

For task2 do i need to create more cookies? Or need to play with Only THM admin cookie?

loud spire
#

i changed the cookie from guest to admin

#

using burp

#

nothing happened

#

also, even after refreshing nothings happening

glad anchor
opal stirrup
#

You only need to use dev tools for LFI2

loud spire
#

ok, but in storage

opal stirrup
#

Right

loud spire
#

nothing is showing up

opal stirrup
#

After you change it to admin, play around with changing it to different values

next lanceBOT
#

Gave +1 Rep to @coarse marsh

modest arch
#

!rep @loud spire

#

uh

#

thanks @loud spire

next lanceBOT
#

Gave +1 Rep to @loud spire

glad anchor
#

Yes

loud spire
#

in storage it's showing NO DATA PRESENT FOR SELECTED HOST

#

for the file inclusion website

raw bolt
#

thanks @coarse marsh

next lanceBOT
#

Gave +1 Rep to @coarse marsh

wicked fulcrum
#

Hi all, can anyone give me an direction on room SQL Injection in Task8.

#

I couldn't figure out this.

weak bough
weak bough
loud spire
#

yes

#

more than 3 times

#

the cookie is showing up in the network section but it's not showing in storage section

drifting drum
#

Am I blind or does the windows PrivEsc room not tell you how to connect to the machine?

wicked fulcrum
# coarse marsh What did you try so far?
https://website.thm/analytics?referrer=referrer=admin123' UNION SELECT SLEEP(5),2 where database() like 'sql%';--
This confirms works.

https://website.thm/analytics?referrer=referrer=admin123' UNION SELECT SLEEP(5),2 where table_name like 'user%';--
This gave syntax error. 
drifting drum
#

Neither of those should work. You can't just copy paste the commands given to you

cobalt tundra
#

the first one should work?!

wicked fulcrum
drifting drum
#

That's not the dB name

#

And no the first one should not work

#

"referer=referer=admin123"

#

That won't work

wicked fulcrum
#

it is my type here.

#

typo

cobalt tundra
#

oh, wasnt even looking at the first part :(

drifting drum
#

Like I said, you can't just copy paste the commands

cobalt tundra
#

only looked at the part after union select

drifting drum
#

Yep

quick light
raw bolt
#

thanks @tender ravine \

next lanceBOT
#

Gave +1 Rep to @tender ravine

shadow echo
#

Well it's pretty straight forward, simply use telnet MACHINE_IP PORT ^^?

cobalt tundra
#

thanks @shadow echo

next lanceBOT
#

Gave +1 Rep to @shadow echo

cobalt tundra
#

but i just read something else in the question "What is the name of the running server?"

modest arch
cobalt tundra
#

i was entering the hostname and was confused why it just didnt work, "name of the server" refers to "what webserver is running"

shadow echo
tender ravine
#

Thanks, this put me on the right track. I was continuously focused on the admin user (flag found πŸ˜€ )

next lanceBOT
#

Gave +1 Rep to @steel nymph

viscid ice
#

ok so maybe I'm just ultra dumb

#

sitting here staring at the LFI module lab 1

#

Wondering why Im just chilling in the www directory and it wont let me out

#

even abusing the ../../

#

am I doin somethin incorrect here.

tender ravine
cobalt tundra
hoary crater
#

i'm having trouble with challenge1, i've tried modifying the request in burp suite and still not getting the flag to return

tender ravine
opal stirrup
loud spire
#

man how to bypass /

#

because in the third one it's filtering out /

#

ok

viscid ice
#

welp

#

thats enough for the day.

#

makin my head hurt.

#

If I followed those directions to the T that I did. This should operate how I want it to.

#

and its not

#

so.

remote estuary
#

ii have the cookie for the XSS Task 8 but doesn't work

viscid ice
#

Coffee break.

hoary crater
#

okay so its not super clear how to modify the request in the source page

viscid ice
#

I modified the request just fine through the network manager.

#

It didn't do as I wanted it to.

noble rose
#

Are you talking about LFI Challenge 1?

viscid ice
#

I did that .

#

doesnt move.

remote estuary
#

can i get help

viscid ice
#

files there.

#

@steel nymph

cobalt tundra
#

im pretty sure youre overthinking it somehow pepoThink

viscid ice
#

Im sure chilli

#

Thats what I get from going from a intermediate thm room

#

to lab1 in jrpentest

#

OVER THINKING

#

but thats why the gods created the miracle elixir called coffee.

#

Ill just come back to it later.

#

I might need to restart the machine or something maybe. IDK.

modest arch
#

good to know that task 8 needs a cookie, my head has been exploding trying to do it

#

manual sqli is so terrible

viscid ice
#

@steel nymph tats what i did.

viscid ice
#

file=

drifting drum
viscid ice
#

ye.

#

ik.

modest arch
#

it's bad when you're balancing school, relationships, prepping for 4 different competitions, and this πŸ˜‚

viscid ice
#

lol.

drifting drum
#

Loool

viscid ice
#

@steel nymph now you understand my head is exploiding

modest arch
#

sqli will be the end of me

viscid ice
#

when something should work.

noble rose
#

I should be working rn, but here i am on discord

viscid ice
#

tzu just use a tool.

#

I guess it would be cheating

modest arch
#

@noble rose tbh same πŸ˜‚

viscid ice
#

and you could do it manually.

#

but thats a lot of headache

modest arch
#

would it technically be cheating tho

noble rose
#

30 mins and i bounce fuck offices

modest arch
#

more like using resources

#

cheating would be look up a walkthrough

remote estuary
#

all LFI challenge, you can use curl to solve the problem

cobalt tundra
#

new content = no writeups/walkthroughs, cant be tempted to take the short path

viscid ice
#

@cobalt tundra we were talking if using a tool like sqlmap would be cheating instead of doing it manually.

noble rose
#

I just want that 3 months subscription

viscid ice
#

XP

#

@steel nymph DM me

modest arch
viscid ice
#

I wanna figure this out real quick.

modest arch
#

-X POST coming in clutch

cobalt tundra
#

if he doesnt answer, just dm me @viscid ice

noble rose
#

Im gonna go back in there in like 2 hours, i might need help as well

hoary crater
#

guess i'm not understanding how your supposed to modify your request into a post request for challenge 1, the LFI examples previously are not helping to wrap my head around it

remote estuary
#

any solve the XSS Task8 challenge? got the staff-session cookie but didn't work

hoary crater
#

well i already tried with burp, it didn't work

opal stirrup
#

After you decode with base64, it should just be the part after =

noble rose
#

Can i ask why do we need to change it from GET to POST? What's the reason behind it?

remote estuary
noble rose
#

I see, thanks man

next lanceBOT
#

Gave +1 Rep to @steel nymph

viscid ice
#

yea

#

that box can fuck itself.

sleek ledge
#

Burp Suite: The Basics machine is not loading in webpage

slender pivot
#

Has anyone completed the Linux PrivEsc task 5? Just want to check if the CVE i'm looking at is correct as I can't get the exploit to run correctly

lavish rose
#

anyone done task 7 from Linux PrivEsc? need help. in the follow along nano is used but on the lab machine suid is not set for nano

modest arch
#

just try doing a nano escape and see if it does anything?

hoary crater
#

i've modified the request using the dev tools and tried using the console to change the request as well, i'm not sure why it still gives a response of doing a get request

lavish rose
#

will look into it as well

slender pivot
#

Anyone on Linux PrivEsc Task 5, is ||37292.c|| correct?

slender pivot
#

fml im doing something wrong then

#

if I run it on the target I get loads of errors

lavish rose
short prairie
lavish rose
#

that is the exploit file for that CVE from exploit-db

slender pivot
next lanceBOT
#

Gave +1 Rep to @lavish rose

slender pivot
#

Compiling solved the issue

#

Thanks

wanton prism
#

I am on File Inclusion: "In Lab #2, what is the directory specified in the include function?" how do I find this? I tried 10.10.X.X//lab2.php?file=/etc/passwd is that not the correct syntax? It looks like I am getting an error but I'm not sure. Could anyone give me a nudge?

lavish rose
#

not able to find another binary which can be used. can you give any hint?

modest arch
#

bruh, hour 1 of pressing delete and 'abcdefghijklmnop_' OVER AND OVER

#

I'm gonna go insane from this bro

lavish rose
#

tried with it already, will keep digging more.

wanton prism
#

I'm just getting the warning: include(includes//etc/passwd) [function.include]: failed to open stream: No such file or directory in /var/www/html/lab2.php on line 26 is there somewhere else i should be looking?

modest arch
#

Hey could I pop a question off someone real quick for the last SQLi challenge

#

just to verify something

wanton prism
#

Thank you, I think i was expecting a different type of directory. Appreciate the help

next lanceBOT
#

Gave +1 Rep to @steel nymph

lavish rose
#

got it. instead of file read was trying other things.

short prairie
#

It works...

lavish rose
#

thanks

next lanceBOT
#

Gave +1 Rep to @steel nymph

short prairie
#

Investigate better the folders permissions

uneven niche
#

@steel nymph yeah i used an other way to do it, don't remember if it was SUID or not but it worked

next lanceBOT
#

Gave +1 Rep to @short prairie

uneven niche
#

||think i used suid on base64 and get the flag like that||

short prairie
#

Its normal, congrats!

proud bramble
#

Can i ask for help with a flag on the jr pentester im having trouble with here or is that more #room-help

#

Alright

#

I am having a bit of trouble on the directory flag on the walking an application task

#

i cant figure out where the txt file is

#

Yea task 3

#

Im not too sure what they should be looking like

#

Yup, i got it open

#

yeah i saw 6. clicking those sends me to some big lengthy code sites

modest arch
#

For the last SQLi challenge my payload is ||https://website.thm/analytics?referrer=admin123' UNION SELECT SLEEP(5),2 FROM information_schema.tables where table_schema = 'sqli_four' and table_name like 'analytic___________%';-- - (it wont show all of them but there's a bunch of _'s, I just kept adding them till it stopped sleeping)|| but it won't accept that table name, I've tried appending a-z, 1-0 on the end and it doesn't seem to accept any of those characters... what's up?

robust steeple
#

yeah, I thought it was ||analytic|| too, it went even further than you have there.

modest arch
#

is it more letters after the C? or a bunch of _'s then more letters @robust steeple

proud bramble
#

I'm not too sure. Sorry, but i keep getting a bit confused reading it more since im not too sure what a directory is

robust steeple
#

@modest arch I think you need to change it entirely

drifting drum
modest arch
#

no wayyyyyyy I spent so long on it πŸ˜‚ thanks guys

drifting drum
#

Np

drifting drum
proud bramble
#

Oh its that. I was just a bit confused for a second

#

Ohh i see now. Thanks for the help lassi

#

I just had a moment with my brain where i fail to notice the obvious

#

thanks again

lavish rose
#

for linux privEsc, task 7, i managed to crack the passwords. but from what i think nano is required with suid bit set to write our own user. am i right? any hints would be good

#

okay

#

okay, thanks for the heads up

next lanceBOT
#

Gave +1 Rep to @steel nymph

drifting drum
#

Can someone help me out for windows privesc task 5? I'm not entirely sure what I'm supposed to do here.

balmy tinsel
#

Kekw

cobalt tundra
spark wharf
#

yeah same

timid compass
#

Not the platform for that

modest arch
#

On LFI challenge 3, whenever pass a null byte to curl, it says something along the lines that using binary will mess up my output..... I'm starting to go mad

opal stirrup
#

Output it to your terminal anyways

#

It should work

modest arch
#

I'm not entirely sure how. Something about the --output flag, but it requires a filename? And when I did that it looks messed up

opal stirrup
#

It should tell you how

#

IIRC it's --o -

modest arch
#

Omg tell me I missed the space

loud spire
#

please can someone help me with 3 flag of LFI

#

i am unable to bypass /

modest arch
#

I'm stuck too, I'll see if I can do it after dinner when the kid is in bed

lunar yoke
#

hello, need help for lfi challenge 2

#

got challenge 1, 3

weak bough
modest arch
#

@opal stirrup @lavish rose I owe you both a beer

modest arch
sly fiber
#

hi guys i am stuck at the cronjob part at linux privesc can anyone give a hint about it

lunar yoke
#

only challenge 2 is left, I am stuck after cookie value change to admin

weak bough
sly fiber
#

i overwrote the backup.sh file but cannot get a shell

#

then about the wildcard i was going to creat --checkpoint=1 files but there was no directory such as admin

glad anchor
#

LIF task 8 Flag3 what to do need hint
able to read welcome file

opal stirrup
modest arch
glad anchor
#

like i know /etc/paswd convert into etcpasswd.php

sly fiber
#

omg dude yes same here

#

but this doesnt make any sense cronjob file should already been assigned as exec

modest arch
#

Some filtering going on, but you need to work out what is causing it

sly fiber
#

didnt delete it just overwrote it using vim

lunar yoke
opal stirrup
#

Tinker with the cookie value and see how it changes the page

modest arch
#

I did

#

It worked. Curl is king

#

Or queen

next lanceBOT
#

Gave +1 Rep to @opal stirrup

zealous plover
#

What

#

I'm stuck on this practical for the repeater room. Task 7 cuz I don't see where the damn validation is happening cuz it's not in the header and I feel so dumb lmao please help ;_;

left flicker
#

Good morning, I keep getting an error code on Subdomain Enumeration Task 6. After entering ffuf -w /usr/share/wordlists/SecLists/Discovery/DNS/namelist.txt -H "Host: FUZZ.acmeitsupport.thm" -u http://MACHINE_IP -fs {size}

zealous plover
left flicker
#

ecountered error report size filter or matcher invalid value

#

i looked above and the file size i saw the most was 472

#

from the line without the fs command

tawny flame
#

@left flicker how does the commandline look like?

left flicker
#

ffuf -w /usr/share/wordlists/SecLists/Discovery/DNS/namelist.txt -H "Host: FUZZ.acmeitsupport.thm" -u http://MACHINE_IP -fs {472}

#

with my machine ip plugged in

zealous plover
#

This you want to just enter 472

modest arch
#

Take away the curly braces

left flicker
#

oooo

zealous plover
#

^^

left flicker
#

thank you!

zealous plover
#

No prob!

tawny flame
#

welcome to the club πŸ˜„

modest arch
#

Is this pentester role temporary?

zealous plover
tawny flame
#

nonnumerical

zealous plover
#

I'm only getting 400 and 404. I'm glad to see I'm not crazy xD lemme try %00 or negative integers

#

Ty

noble rose
#

Hey guys!

#

I'm at LFI Challenge 2, i changed the cookie value from Guest to Admin, it worked, now what?

#

I have no clue what to do mext

#

On it

#

Thanks bro

#

Yeahhhh i see now

#

I think i know what to do

zealous plover
#

Also thank you for this I figured that was the case but headspace is broken today xD

next lanceBOT
#

Gave +1 Rep to @steel nymph

rare helm
#

I am stuck on Authentication Bypass task 3. Not seeing any return from the ffuf command. Any suggestions?

crimson lark
rare helm
#

I get output as like the ::METHOD and functions like that but cannot see the successful username/password combo anywhere

noble rose
#

Ok so i know that next the path in the cookie is the way to go am i right?

spark wharf
crimson lark
spark wharf
crimson lark
spark wharf
rare helm
#

In the output I get two : : Wordlist 's and they are correct paths. I copied and pasted command from instructions to attack box

noble rose
#

Can i dm you?

rare helm
#

valid_usernames.txt is in my current working directory

modest arch
#

What is the flag from the SSRF Examples site?

#

What file am I using in the RFI challenge ?

opal stirrup
#

You need to make your own

modest arch
#

Oh

modest arch
rare helm
#

No worries I will keep messing around with it thank you for helping so many of us

next lanceBOT
#

Gave +1 Rep to @steel nymph

modest arch
#

Please give some hint

#

Sure sir

modest arch
#

Sir, I didn't get, Please help

lavish rose
#

no, i'm still stuck on it.

#

awesome, thanks

next lanceBOT
#

Gave +1 Rep to @steel nymph

sly fiber
#

1 room left and the only thing a get is pentester title and 1 day freeze dammit so unlucky man

lavish rose
#

will try after dinner and if i still cant get it can I dm you if you dont mind?

tawny flame
#

@sly fiber Sounds unlucky man!

hollow river
#

you mean typed real quick?

slender pivot
#

Hi Guys, anyone done Task 6 on Linux PrivEsc? ||Am I meant to compile the LD_PRELOAD .so on the attack machine and wget it into the target?||

buoyant dagger
#

Try it

slender pivot
#

oh I see, it was an example only. I misread

kindred lantern
hollow river
#

I typed real quick too but it still says connection closed by foreign host. Like I am not even able to connect to any of the services on the targeted IP.

slender pivot
drifting drum
#

πŸ‘

kindred lantern
drifting drum
#

Anyone finish task 5 of windows privesc?

#

The DLL hijacking one

#

I don't understand what it wants me to do

hollow river
kindred lantern
late cloak
#

LFI challenge 2 - any hints? I htink i know what I need to do but not working

modest arch
#

thats your hint

late cloak
#

lol

tawny flame
#

haha.. good one @modest arch πŸ˜„

late cloak
#

i've changed the cookie and i'm trying my payload

#

but....no cigar

left flicker
#

On Authentication Bypass, Task 3 Brute force, I entered the string and got an error cause i didnt create a file from the username enumeration. do you need to create valid_usernames.txt with the valid usernames or is there a command to save the pull from the enumeration?

modest arch
wicked fulcrum
#

Need help in File Inclusion room.

a gentle hint. I am close. I have no idea what is wrong here. or if I am missing anything

subtle heron
#

I'm stuck on task 8 of SQLi, any hint?

late cloak
#

hmm ok

#

my cookie is wrong then

wicked fulcrum
modest arch
#

lol

wicked fulcrum
#

what is that.. πŸ˜…πŸ˜…πŸ˜‚

lusty bolt
remote estuary
#

any hint on SQLI task 8

quick light
remote estuary
quick light
vocal shadow
#

file inclusion challenge 8 last question - any hints?

modest arch
#

oh wait

#

man im dumb

vocal shadow
#

yes the RFI

#

thx i got it πŸ˜„

modest arch
#

omg RFI

#

done, phew

wind pollen
#

attackbox I should say

modest arch
#

@steel nymph I can't get simplehttpserver to work, how should I serve the file u think?

next lanceBOT
#

Gave +1 Rep to @steel nymph

modest arch
#

thanks

late cloak
#

there is a python3 version of the http.server

modest arch
#

aye

#

its what i used

late cloak
#

python3 -m http.server 80

modest arch
#

doesnt work for me on the attackbox

coarse granite
late cloak
#

port 80 is in use no doubt

coarse granite
#

Most of the time 80 will be in use

modest arch
#

lol

modest arch
coarse granite
#

πŸ™‚

verbal crypt
#

Anyone else have seriously unstable boxes all day?

late cloak
#

ive got no clue on this LFI challenge 2

opal stirrup
late cloak
#

ive set cookie

#

ive then tried a payload on end of url ?file=<path>/../../../../etc/flag2%00

opal stirrup
#

What did you set the cookie to?

late cloak
#

ive even repeated in BURP

#

admin

opal stirrup
#

Keep playing with the cookie value

modest arch
#

:p

opal stirrup
#

See what happens when you change it

modest arch
#

Any pointers on RFI last challenge?

late cloak
#

throws errors and thats where i determined path

#

ive done all others πŸ˜„

#

RFI was easier....

#

haha

modest arch
#

i agree

bold fossil
#

Not sure if I am completely missing the point. Answered all question except for #3. I've tried to give input on multiple ways but it keeps filtering all my special characters. even numbers. ascii encoded. url encoded different verbs such as post and get but no luck. What am I missing?

modest arch
#

I've read it enough lol

bold fossil
#

Hint says "Not everything is filtered!"

late cloak
#

@bold fossil think about httml method and filtering

bold fossil
#

tried all keys on my keyboard

#

filters all the special keys and numbers

modest arch
modest arch
#

did you set up what needed to be setup

#

kk

opal stirrup
modest arch
#

so you need to ||listen|| to that after you have delivered it

modest arch
opal stirrup
#

For #3?

modest arch
#

||

#

either side

#

that pipe thing

#

||lll||

#

voila

late cloak
#

@glad drumman ||think about the environment and type of file being hosted||

modest arch
#

i can only say how I did it, not what you should do

#

but i used curl

modest arch
wild sundial
#

listen to it after uploading the proper file with right extension

modest arch
late cloak
#

@bold fossil ill swap ya lol

coarse granite
#

@steel nymph cgcgcg

drifting drum
#

Can you help me with the dll hijacking task? I'm confused as to what I'm supposed to do

#

Whichever you preffer

fair summit
drifting drum
#

Haha

#

Yea

#

I just saw defender is turned on

#

Gonna try to get it to work anyway

#

Will confirm if it stops it from working in a minute

fair summit
drifting drum
idle bison
digital pendant
#

Anyone knows why this request doesn't work ?

shadow echo
digital pendant
#

ahh got it thanks

warm ledge
#

Anything in particular I need to do to get the Net Sec Challenge task 2, last flag to trigger? Consistently at 0% detection w/o a flag from my local machine as well as attack box.

fair summit
#

got it πŸ™‚

warm ledge
#

Lol alright, thanks. I’ll just send it some junk so it sorta detects me then start the scan

#

How long do I have to wait post scan before I should start spamming refresh again?

#

Ok, cool. Thanks

hearty quest
#

what trick was that

sly fiber
#

guys in the windows privesc task4 how do we learn version of the software

silk sentinel
#

Hello so i am on Authentification bypass task 2 and i wrote in the command to the terminal but i dont see any of the usernames, what did i do wrong? thank you....

#

I did put in the ip address yes and i am using the in browser attack box, it suppose to be predownloaded i think

#

am is there away to just share a screenshot or smth i think it would be easier

shadow echo
#

!docs verify

tiny bluffBOT
silk sentinel
#

thank you ill try to figure this out and come back, thanks i feel stupid, maybe this path is too much for me im like very new i dont know

shadow echo
shadow echo
shadow echo
silk sentinel
silk sentinel
next lanceBOT
#

Gave +1 Rep to @shadow echo

shadow echo
# silk sentinel Thank you so much. I feel like an idiot.

Well things like that can happen. I would go with copy/paste so you are more safe to make no typos. In case you didn't know, there is a small arrow between the splitscreens, you can paste stuff you copied from the left split screen into the clipboard and then you'll be able to paste it inside your attackbox.

modest arch
#

that's brand new information

#

ty

shadow echo
#

Not a problem πŸ˜„

noble rose
#

I gave up on LFI

#

Challenge #3 and the playground ended me

#

Im tired

modest arch
#

come back with fresh eyes and a clear head

noble rose
#

I think challenge 3 is bugging out on me

modest arch
#

what have you done so far?

silk sentinel
next lanceBOT
#

Gave +1 Rep to @shadow echo

sly fiber
#

guys can check the version out dunno how to check version from binary file in windows any suggestions
What version of FoxitReader is installed on the target system?

noble rose
#

And in the playground i just don't know how to do it

modest arch
noble rose
#

Normally the extension should go away

modest arch
#

user_ame

noble rose
#

I tried . \ as well same issue

modest arch
#

I know that happened to me and it was that I was on the wrong one facepalm

noble rose
#

I don't know how to use it still learning

modest arch
#

Gotcha

hollow pumice
#

Hello, is this the right place to report a potential typo for a tryhackme box?

#

It's just a typo in the question. Still bugs?

sly fiber
#

already done that no result but i found aanother way thx neverthless

next lanceBOT
#

Gave +1 Rep to @steel nymph

slender pivot
#

Anyone managed to complete Linux PrivEsc Task 7?

#

The example shows nano, but the user account doesnt have SUID set for that. Only option I can see is ||base64||. Am I looking at it wrong?

dusty iris
#

Check gtfobins

modest arch
#

For SQLi test, || for the password, I have the 2 numbers in the password, 4(something)6(something), should I be testing any special characters for the password? Kind of at a loss here ||

#

What is the value of the staff-session cookie?

modest arch
#

my fingers hurt from delete type one character delete, whoever made SQLmap deserves the best

#

just numbers???!?! what the freak, ok i'll try again but maybe it's broken

#

no way, I fat fingered it

#

and missed the right number πŸ˜‚

coarse marsh
drifting drum
#

As far as I can tell that's intended. The point is to give an example of what you can do with an SUID file, now show you how to finish he task

modest arch
#

I am not getting cookie in TryHackMe request catcher

drifting drum
hollow pumice
#

yes

modest arch
#

😒 FREAK, the user/pass I finally got are wrong πŸ˜‚

modest arch
drifting drum
#

Yea I couldn't launch bash either.

dusty iris
#

||try reading a file with base64||

drifting drum
modest arch
#

@drifting drum can you confirm for sqli, || admin : 4961 ||

#

is that right and the system is broke or wrong pass

drifting drum
modest arch
#

ok sick

#

thanks

#

Okay Sir, Thank you

next lanceBOT
#

Gave +1 Rep to @steel nymph

drifting drum
#

There's a way to execute commands with base64. I tried it out a bit but couldn't execute a shell

dusty iris
#

you dont need to execute commands

coarse marsh
#

i don't think you can launch a bash with it, people read /etc/shadow with it and crack passwords

drifting drum
#

Yes we know. But GTFO bins mentions that it's possible

#

So were just trying to figure out how

modest arch
drifting drum
#

Hmm. Try looking for the user again. I dont remember what it is off the top of my head

modest arch
#

Nah, I opened the attackbox in another window and it worked

#

idk what's up with it πŸ˜‚

drifting drum
#

Oh ok great!

#

Lmao

#

Yea

modest arch
#

Yeah. Thanks for your help man

drifting drum
#

It's a bit buggy

modest arch
#

That was a tough one

drifting drum
drifting drum
modest arch
#

Yeah, honestly was just hard cause of the brute forcing

#

I'm glad I didn't but it would've been so much easier to write a script or something

#

but now I understand how it works at a more fundamental level so that's sick

drifting drum
#

Haha. Facts

drifting drum
coarse marsh
#

Did anyone here try to solve sqli challenges using sqlmap?

modest arch
#

Thank you sir, I got this

next lanceBOT
#

Gave +1 Rep to @steel nymph

sly fiber
#

anyone to help dll hijacking part i am kind of confused

slender pivot
#

Reading the shadow + passwd on PrivEsc, i'm assuming i'd need to manually copy and paste the contents.

sly fiber
#

but when i say sc stop dllsvc it does not allow me to

opal stirrup
#

god that sqli one was annoying to do

drifting drum
#

I had that problem

sly fiber
#

The requested control is not valid for this service.

drifting drum
#

If you start the service too early you can't stop it

#

You only have start perms, not stop perms

#

So if you mess something up with either the payload or if you start the service to early you need to reset the room

sly fiber
#

then why on earth they wrote stop dllsvc god 😦

drifting drum
#

Good question lol

#

Ideally you'd have stop perms too if you're doing a dll hijack

sly fiber
#

yeah restarting the room

drifting drum
#

Ok. Lmk if it works

sly fiber
#

it is the last question on the path and i am so irretated by the part

drifting drum
#

Haha

#

Yea

#

It's annoying

#

Just follow what they do in the task exactly

#

With exact filenames and everything

#

All you have to do is modify to c code to change the user's password

sly fiber
#

yeah did that too i used net user jack password is it correct? because if there is smthn wrong with my payload and i fail it again i will throw myself out of the window xd cant afford it

#

okay got it right lol

slender pivot
#

Time to call it a night, brain overload

mighty plover
#

Wow thanks guys - was stuck at exactly the same tasks. This thread was a life saver πŸ˜„

wide crow
#

Hi

hexed coral
wide crow
#

Where are the creds of the machines in the last room Windows Privesc

sly fiber
#

drop it guys if u are solving it for the vouchers :/

hexed coral
wide crow
#

Thanks a ton

next lanceBOT
#

Gave +1 Rep to @steel nymph

sly fiber
hexed coral
#

As in the ticket progress

wide crow
pearl compass
#

Hello I was having trouble using the commands provided in the Authentication Bypass room the brute force section. I cant get the command to work and I've tried several ways and I've also tried using the repository in Github. Please help.

mighty plover
#

Could you post an error message ?

short prairie
#

File Inclusion Task 8 Flag3 anyone can help?

mighty plover
#

@short prairie there was some hint in the forum thread about that task. πŸ™‚

wide crow
#

method

#

try using curl

cobalt tundra
junior dome
#

^^

sly fiber
#

If we would have spent all the time that we have spent for the path to hack the ticket system we all would have awarded with a OSCP voucher hahahahahha

hearty quest
#

@short prairie did u figure it out, im also stuck on the flag3 of file inclusion

#

how many oscp vouchers are they giving out? or u guys most likely just gonna be stuck on 2 of 3?

glacial hornet
#

@hearty quest 2 OSCP Vouchers

hearty quest
#

so first 2 to get all 3 tickets then?

glacial hornet
#

I believe so

modest arch
#

Blind SQLi - Time Based: got the username and a four digit password but it won't take it is the username case sensitive ?

junior dome
#

3 rooms left. Gotta say, this has been a great pathway. Everyone involved did a damn fine job! Time for some dinner!

short prairie
next lanceBOT
#

Gave +1 Rep to @hearty quest

reef wave
modest arch
#

I got my first oscp voucher ticket today :)))

#

so happy

#

but also

#

use simple python server

#

need 2 more

reef wave
#

exactly what I've done

#

maybe i did something wrong

#

lemme check again

zealous crown
#

Has anyone won the wifi pineapple, OSCP or eJpt voucher yet?

short prairie
modest arch
drifting drum
reef wave
#

Not sure about how to do it since I copied the txt (just to see any output) however it doesn't seem to execute the php file

short prairie
#

what php shell are you using?

modest arch
#

There were some guys scripting it when it first came out

reef wave
#

yea I guess cause when I just entered some random text it returned an output

modest arch
#

so I don't doubt they've succeeded by now

reef wave
#

||I tried to write to a file and then read the file but it didn't seem to work too|| about the rfi

drifting drum
#

Also make sure u use real php code. Not a command that invokes php from cli. That won't work

rancid bone
short prairie
#

After restore the machine 3 times πŸ˜„

rancid bone
#

lol

reef wave
#

<php echo "something something"; ?>
seems good format for me right?

upbeat magnet
#

the commande needed is a "bit" more complicated

modest arch
#

@reef wave no

reef wave
#

yea ofc I meant about the php syntax

#

woops I forgot ? at the begining

modest arch
#

|| PHP reverse shell cough ||

upbeat magnet
#

cough

modest arch
#

cough cough

dusky crescent
#

cough

drifting drum
#

Cough cough cough

reef wave
modest arch
#

Oh ok, if you already know you can solve it that way, then have at it. I thought you were like actually stuck

drifting drum
reef wave
#

aren't RCE remote command exec?

drifting drum
#

Yes

reef wave
#

||like yea rev shell is the best way but I wanted something simpler||

#

yea I got an error now

modest arch
#

Just a little bit more burp suite then I get to the cool stuff 🀯

reef wave
#

but at least there is an output

modest arch
#

I'm excited for the privesc module

#

I've seen lots of people struggling on it πŸ˜‚

drifting drum
#

The windows one is a mess tbh

upbeat magnet
#

savin those two as the last things i do

modest arch
#

πŸ˜‚

#

yeahhhhh

#

windows privesc is kind of a mess always tho

drifting drum
#

True true

upbeat magnet
#

AD?

drifting drum
#

I just feel like the windows module was rushed