#recent-threats-module

1 messages ยท Page 1 of 1 (latest)

rugged sphinx
#

What is the flag that you obtained by following along?does anyone know the answer to this question?

serene comet
#

I don't know lol!

timber sluice
#

which one of the rooms???

rugged sphinx
#

its intro to defence system

#

i dont really know about the room

timber sluice
#

this channel is for the rooms in this module: https://tryhackme.com/module/recent-threats
so which one of those are you in @rugged sphinx ??? if not you will have better luck in #room-help

haughty vault
#

๐Ÿฅณ

crisp schooner
#
The PoC that we used has the capability to establish a reverse shell upon exploit - what binary is being used to accomplish this?```
#

what exactly does that mean

boreal tree
crisp schooner
#

for example a type of binary it can be base64?

#

my problem is that i dont understand the question to be able to respond

paper coyote
#

Binary being a compiled program

crisp schooner
#

ah ok

#

thx

supple lagoon
blissful frost
#

hello, i've got a question about room cve2022-26134 (Atlassian, CVE-2022-26134)
I couldn't find the log files on '/opt/atlassian/confluence/logs' using the attack box machine, there is not any file named atlassian in /opt folder. Could you please help?

#

i thought so but let me show you,

#

I just started the attack box again, there is a confluence platform which i can reach from http://IP:8090 but I couldn't see the log file

#

๐Ÿ˜ฆ I searched nearly all directories manually

#

I couldn't send screenshot

jaunty gorge
#

!docs verify

white sunBOT
blissful frost
#

@jaunty gorge thanks I verified ๐Ÿ™‚

elfin jungleBOT
#

Gave +1 Rep to @jaunty gorge

blissful frost
#

as you can see, there isn't any folder or directory named atlassian or jira ๐Ÿ˜ฆ

jaunty gorge
# blissful frost

Of course you are not finding it there, that's the attackbox, so if you are going to look for that log file, you would have to do it on the target machine, since Confluence is on that machine

#

I have not done that room, but Task 4 is only explaining how you could detect that vuln if you are looking for it on your own install of it, so it's just an explanation, so you doesn't actually have to go there

blissful frost
#

omg I'm such a dumb ๐Ÿ˜ฆ I just thought I could do everything through attackbox

#

thank you very much I'am trying to learn those things

jaunty gorge
#

Not an issue ๐Ÿ™‚

blissful frost
#

@jaunty gorge hope I can do it, thank you for your kind response

#

@jaunty gorge can I ask one more question please take it about my inexperience, I think I have to create a vm and install a vulnerable confluence on it to simulate this attack and then use attackbox to exploit the vulnerability, is it correct?

jaunty gorge
blissful frost
elfin jungleBOT
#

Gave +1 Rep to @jaunty gorge

alpine crystal
#

Hey, I'm having some trouble with the basic pentesting module. I'm at the step to crack the ssh passphrase but every time I try to crack the hash file after put in ssh2john, JtR tell me (no password hashes). Do you have any idea why isn't working ?
thx by advance for help

white sunBOT
alpine crystal
#

oh yes sorry I read wrong the title

solid breach
wicked pendant
languid chasm
#

hello
can anyone help me
i want to start ethical hacking

wicked pendant
#

Please don't spam the server, ask in one channel and wait, I sent a reply.

jaunty gorge
dusky gate
#

Hey,
on Burp Suite: The basics, I do not understand if it talk about FoxyProxy or BurpSuite? And which right click menu is?

wicked pendant
#

That's talking about burp.

dusky gate
#

If we must right click on the Options, I can't

wicked pendant
#

No, it's talking about the options in the right click.

#

Go to Intercept > Right click,

dusky gate
#

Oh okay! I just found it

#

Thank you

wicked pendant
warped moat
#

can someone help i don't know how to solve this part I have stuck here for a long time

timber sluice
#

which room and task???

warped moat
#

is in Jr penetration tester, Introduction to Web Hacking, Walking An Application, Viewing The Page Source

timber sluice
oblique kraken
#

i changed the full name to my actual name in my profile but the certificate won't change it. How can i get it with my name ?

untold zealot
timber sluice
timber sluice
#

that not paint.... that is just its successor

wicked pendant
wicked pendant
timber sluice
timber sluice
sand tusk
#

thats a new concept for me

timber sluice
daring drum
#

Hi, just downloaded ParrotOS Security to my VMware. and trying to run a vpn. but it says "could not find the commando run" how do i fix this? im pretty new to this

halcyon saffron
shrewd jewel
daring drum
#

Thanks! Worked with "sudo openvpn filename"

dawn junco
#

Do you have any sources for this? thats nuts

paper coyote
# dawn junco What in the flying fuck, thats insane
#

mspaint.exe section

timber sluice
dawn junco
#

Thank you! @paper coyote @timber sluice

grave hawk
#

Hello, I'm stuck on the question:

"Consider the desk in the photo above. In addition to the smartphone, camera, and SD cards, what would be interesting for digital forensics?"

which comes from "Intro to Digital Forensics"

I tried all the words
6 letters from all over the room and none of them work... can someone help me please?

timber sluice
silver tangle
silver tangle
wicked pendant
silver tangle
elfin jungleBOT
#

Gave +1 Rep to @timber sluice

silver tangle
timber sluice
toxic lynx
#

Heads up the atlassian room task git repo is no longer public

hasty helm
#

Hi

serene comet
#

well saw this module for 1st time here

sharp obsidian
#

please , has anyone here solved the great escape CTF practice ?

#

I've a problem concerning the first flag , I wanted to brute-force the /.well-known ; I tried ffuf , gobuster and dirb tools ; still couldn't find the .txt flag !! any help

rough pollen
#

hay, i have a question for the task 7 of module Burp Suite: Repeater ...It works well the ""500 Internal Server Error" ? because me he doesn't works..
ty for futur answer

timber sluice
#

well weird how this channel is just general support now and not just for the module that it is named after

timber sluice
#

aaaand we are back baby with new recent threats room

atomic pendant
#

Dear all, can u help me with the generation of new cert for a new computer that i added in to the system under section CVE-2022-26923

#

i keep getting this error

hasty pike
#

Hello

#

How is everyone

#

I am new here

#

And bored

serene comet
#

when i try to export a jpeg or smt as a packet byte in wireshark i cant save it

fading yacht
#

Was it an HTTP session? Fileโ†’Exportโ†’Objectsโ†’HTTP

thin valve
#

c

vestal meteor
elfin jungleBOT
#

Gave +1 Rep to @hasty pike

raw lodge
#

Can't seem to get the .rtf exploit to fire in https://tryhackme.com/room/follinamsdt.
Opening the .doc (or .docx), it's not editable (Word Activation error), so impossible to save-as .rtf to complete the zero*-click variant. (renaming the file/extension to .rtf doesn't work either)
(screenshots here: #room-help message)

Discord

Discord is the easiest way to communicate over voice, video, and text. Chat, hang out, and stay close with your friends and communities.

fallen shell
#

Walking An Application

Answer the questions below

What is the flag from the HTML comment?

What is the flag from the secret link?

What is the directory listing flag?

What is the framework flag?

jaunty gorge
desert zodiac
#

Hey everyone, I'm having trouble understanding a question, can someone help me out?

mellow echo
static robin
sly kelpBOT
#

@inland phoenix Please slow down โ€” spam isnโ€™t allowed.

sly kelpBOT
#

@unique tusk Please slow down โ€” spam isnโ€™t allowed.

#

@arctic zinc Please slow down โ€” spam isnโ€™t allowed.

haughty vault
#

๐Ÿฅณ

timber sluice
#

meep shadow has done nearly all the rooms in this module

vast mulch
#

Meep-meep

winged grove
#

PrintNightmare task6, anyone can help me with this task?

safe musk
#

hi team

#

can anyone help me with Task 7

grave holly
safe musk
#

this was fun

grave holly
burnt parrot
winged grove
burnt parrot
#

Sure, but if you ask here others can join in to help as well. ๐Ÿ™‚

winged grove
#

When i search for "Event ID" it return nothing

winged grove
#

PrintNightmare Task 6, I have tried searching in win Event Logs viewer, but i can't find anything. Please help me, thanks in advance.

torn urchin
#

hi in spring4log how do i get a reverse shell using the webshell?

burnt parrot
burnt parrot
torn urchin
#

i stuck in the optional one

#

i used bash in encoded url format and nothin

burnt parrot
elfin jungleBOT
#

Gave +1 Rep to @burnt parrot

burnt parrot
#

Ah, my bad. Didn't saw that.

timber sluice
#

spring4shell still does not seem to have been exploited a lot in the wild

sweet jay
winged grove
timber sluice
#

??????

#

that no look like english to shadow

mint rock
# winged grove

@winged grove Everything you need to get the answer is here in this image. Also question 1 (in task 6) was updated with a slight hint.

timber sluice
#

and module completed

#

took a while to type out the thingies from the event viewer logs

#

in the printnightmare room that is

haughty vault
#

New room added to the module: CVE-2022-26923 ๐Ÿฅณ

timber sluice
livid lynx
#

mmm that's interesting

ornate bough
#

guys

#

anyone else getting 500 interal server error in the west coast?

merry patio
cinder rampart
#

Hey all --
I am having some issues with the initial exploit for Print Nightmare. I am following the instructions exactly as they are written. What am I missing?

#

Here is a glimpse of the logs on the SMB Server I am hosting with impacket --

#

Ah. I figured it out. For those seeing this in the future -- I failed to modify my smb config file before doing the exploit

timber sluice
#

GG

winter nebula
#

Hi

cinder rampart
#

Hey all -- I did video walkthroughs & explanations on every threat/room in this module. If you get stuck or would like some extra learning, I hope you find these helpful ๐Ÿ™‚

CVE-2022-26923: https://www.youtube.com/watch?v=a-bCbIqGMCg
Spring4Shell: https://www.youtube.com/watch?v=iWdO9C5Aw_g
Log4J: https://www.youtube.com/watch?v=QDNPsupvAME&t
Dirty Pipe: https://www.youtube.com/watch?v=VfBTEpk2oz0&t
Pwnkit: https://www.youtube.com/watch?v=w5nBnvmYlf8&t
Print Nightmare: https://www.youtube.com/watch?v=FGivGdziLuA

timid dune
#

So I followed the directions exactly to a T with the Log4J / Solr room video and a connection is never received on the netcat terminal window

#

Session is still live, I closed everything out and terminated then created new sessions and new attack box session and get the same result following the instructions

sweet sun
#

why arent they marked with green things even though i completed them?

pastel mural
#

"green things" kekw

#

you're being redirected to the newer versions of those rooms and those old ones are just left not completed

sweet sun
sweet sun
elfin jungleBOT
#

Gave +1 Rep to @wicked pendant

pastel mural
#

that's... pretty much self-explanatory

sweet sun
#

bad english pays off

pastel mural
#

those rooms have been remade by the site itself

sweet sun
#

still dont understand

timber sluice
# sweet sun wdym?

there is an old room that is about metasploit and burp suite... but they have been made outdated and scrapped and therefor now redirect to newer rooms... the reason you are not getting the green checkmerks is because the pentesting tools series is looking for those old rooms being completed when you have just completed the new ones

timber sluice
#

and no there is nothing we or you can do to complete the old rooms sadly enough

#

gotta wait for thm staff to do something about it

sweet sun
#

oh

#

so icant do them

#

sedvargcooctus

timber sluice
#

no problem.... hope this helps

#

should be fixed sometime in the future

sweet sun
#

i does

sweet sun
#

wordlistctl doesnt work the right way for me i think?

sweet sun
#

fixed

blissful fox
#

Hello, I'm doing the machine 'Blue' ( easy ).
That machine is vulnerable to smb-ms17-010 and when i go to metasploit to run the exploit i get 'FAIL' messages. Tried few times. I gave up and went to the writeups and apparently it's mentioned that sometimes it might be needed to restart the machine but i did it already 3 times. Any ideas?

sweet sun
#

i had the same but it worked for me

#

did you look up on yt

blissful fox
#

in the 2 places i read, it says to restart the machine

#

i'll go ahead with the 4th ๐Ÿ˜„

sweet sun
#

try to watch a yt vid on it

wicked pendant
#

You need to set the LHOST.

sweet sun
#

and see if you did the same as the yt vid

blissful fox
wicked pendant
wicked pendant
blissful fox
wicked pendant
blissful fox
#

ohh sorry, LHOST, that did not touch it

#

let me check options in a sec

wicked pendant
#

set LHOST tun0

blissful fox
#

in the vid i watched, they don't do the 'set exploit windows/x64/shell/reverse_tcp

#

and works at the second

wicked pendant
#

What's your LHOST?

blissful fox
#

i have a LHOST option AFTER i set that exploit

#

and it points to my local IP address

#

192.168....

wicked pendant
#

Nah

#

Change it to your tun0.

blissful fox
#

ok, running now

#

ohh ohh works

#

niice! Thank you guys !

wicked pendant
#

RedZoop Happy Hacking.

wicked pendant