If you are running Kali Linux how do you have your terminal look like that at 14:08 at the bottom with the colors? Thank you.
@mayankchauhan47884 жыл бұрын
he is using tmux
@scully18564 жыл бұрын
@DarkSec I have been stuck on "WARNING: Failed to daemonise. This is quite common and not fatal. Connection refused (111)" Immediately after I try to run the script via the uploads page. On top of that, the port listener is not returning anything? I have changed the port number several times and re-uploaded the .php file and I consistently get this same error. Any ideas?
@LuisHernandez-yb4yd4 жыл бұрын
I am having the same issues. Did you find a way to fix it?
@scully18564 жыл бұрын
@@LuisHernandez-yb4yd unfortunately not. I e been busy with finals and haven't had much more time to look into it. When I figure it out I'll post back here though
@cybercowboy6424 жыл бұрын
Had the same issue. You are using the wrong IP address in the shell script upload file. Think about how traffic will get back to your local machine. HINT: need to run an ifconfig
@scully18564 жыл бұрын
@@cybercowboy642 thank you for the tip! I will check it out when I get back to my computer. I wish I could like your comment 100 times.
@Francois-B-Arthanas4 жыл бұрын
This was great! Thank you @Dark
@synack21654 жыл бұрын
I know I am a little behind. Playing catchup. I ran into a couple issues but I was able to fight my way through them and figured it out. Good stuff!! Really enjoying these lessons.
@austinthompson13144 жыл бұрын
Awesome video Dark! Sucks I had to do it at x0.25 speed due to tryhackme's slow machines haha
@ssh17hx0r4 жыл бұрын
These first two THM holiday rooms doesn't give me an indication that it's finished with the confetti and the "Congratulations" message, but it does say 100%. Since it matters for the prize drawings, is there a way to know that it's registering that the rooms have been completed? I couldn't find a place to make a ticket. So I'm posting here.
@DarkSec4 жыл бұрын
That's because you're not 100% done. To obtain completion, you have to do all of the days and you still have 23 more to go haha
@ssh17hx0r4 жыл бұрын
@@DarkSec That's what I was hoping! Thank you!
@KieCodes4 жыл бұрын
Very nice small hack-snack! Loved it! Maybe here's a little tip for mac users. On chrome on mac os you can't select a *.jpg.php file and there is no dropdown menu like on windows to select *.* (or I didn't find it), but a way to get through this is to upload a *.jpg file and repeat the request with burp suite in order to change the filename in the request to .jpg.php.
@audreymcnay35284 жыл бұрын
I just figured out there's a similar option on Mac OS. Click "Options" on the bottom left of the finder window, then there's a dropdown where you can select "All Files" :)
@KieCodes4 жыл бұрын
@@audreymcnay3528 Wow. never saw that. Thanks a lot!
@marcotheitguy4 жыл бұрын
Excellent video though website never uploaded forme tried at different times and different attack boxes and always got same error: 405 - Specified method is invalid for this resource
@JakeStPeter4 жыл бұрын
Thanks for the video Dark!
@boxclever80304 жыл бұрын
Cannot get netcat to find the connection, followed all these steps. Any ideas?
@Drusher103 жыл бұрын
had the same issue, i insert the ip that THM game me but couldnt connect :/
@carldavenport15834 ай бұрын
@@Drusher10 I think the issue is he has netcat already set to connect from "any" IP. My netcat isn't listening for connection. Gotta figure out to get it to listen for any IP connection like his is already set to do.
@sudarshanpatel89963 жыл бұрын
you have been really very helpfull....THANK YOU VERY MUCH !!!
@lommenthepocket35344 жыл бұрын
Thanks @Dark - as always a pleasure 😊
@cipher39662 жыл бұрын
Did this stop working? Trying to practice but this step will not nmap, page won't load and does not ping
@ssh17hx0r4 жыл бұрын
@DarkSec really fun room.
@crystalmorton95004 жыл бұрын
@DarkSec I'm subscribed to tryhackme, but when I deploy the VM it still only gives me an hour time limit.
@DarkSec4 жыл бұрын
Oh thats just the auto termination I think, you should be able to extend the time
@crystalmorton95004 жыл бұрын
@@DarkSec thanks!
@dalemanni244 жыл бұрын
So, two things. First, after doing everything you did, I can't upload it to the site. No idea why, just doesn't allow me to do so. Second, I tried removing the ".php" which then allowed me to upload. After doing that, I can't run the script due to an error. I assume because I removed the ".php". Edit: I am an idiot.
@DarkSec4 жыл бұрын
Bahaha didja find the drop down selector?
@dalemanni244 жыл бұрын
@@DarkSec Nope. Thought I had moved it from All Supported Types to All Files, but didn't.
@nithinchowdarygarapati16043 жыл бұрын
I really agree to your edit line.. :) Thats how I felt after seeing this video.. :(
@DarkSec3 жыл бұрын
Hey at least ya found it :)
@abdulhaqmohammed4 жыл бұрын
Hey How can i get a terminal like yours with the ip addresses in the bottom ??
@DarkSec4 жыл бұрын
Check out the project OhMyTmux on github
@abdulhaqmohammed4 жыл бұрын
@@DarkSec Does This work on kali linux?
@DarkSec4 жыл бұрын
Mhmm
@Nilicous4 жыл бұрын
I am greatful for this amazing video and these fun tasks. I've been given the opportunity to start a junior position at our security department this spring and I've made it my thing to complete this calendar and start learning more before then. I really appreciate the work that has been put into these starting assignments. They were easy to understand and felt engaging. They also left this aftertaste of wanting to know more. So yeah, really good!
@Drusher103 жыл бұрын
Have some questions on this: I have my own VB kali machine and i was inserting on my browser the IP of THM. Couldnt bring me the webpage you created therefore i couldnt complete the tanks. The copy .php file did it fairly easily. Any advice for the issuee?
@rubenramos28143 жыл бұрын
Hi, when i try to listen the port 1234 and i start the php shell in the website doesnt appear nothing, can u help me?
@dr.b32764 жыл бұрын
Please How do I copy into my current directory, I am using windows and kali in my VMware
@0xR1SKY4 жыл бұрын
I'm proud of myself. I did it myself. BTW all the work you all put on this is really useful and I think it will help everyone. Thanks :)
@Naigung3 жыл бұрын
I used the video because I couldnt figure out a question...my answer was plural. Whatever the video was great.
@KohzmikYT2 жыл бұрын
are you a master hacker now :)
@mohamedlourch4 жыл бұрын
hope you cover more stuffs in this channel .
@DarkSec4 жыл бұрын
I certainly hope to! I think my plan is to go on a schedule of one walkthrough a week release or so after AoC2
@aks34794 жыл бұрын
I tried running the script but i got WARNING: Failed to daemonise. This is quite common and not fatal. php_network_getaddresses: getaddrinfo failed: Name or service not known (0)
@samiul0084 жыл бұрын
Having same issue! Anybody found the workaround??
@samiul0084 жыл бұрын
WARNING: Failed to daemonise. This is quite common and not fatal. Connection refused (111)
@samiul0084 жыл бұрын
@Bergþór Olivert Thorstensen yes, i changed to correct port and ip address. Once executed,netcat shows listening but after clicking the script on the browser i get the same errorr in the browser. Could not get reverse shell by any means 😪
@samiul0084 жыл бұрын
@Bergþór Olivert Thorstensen Thanks a lot! I was putting the wrong ip address :P Banging my own skull :D
@Sokoto3124 жыл бұрын
hi all, i need your help. when i run the command to open netcat by nc -lvnp 443 nothing are going only its listenning on (0.0.0.0). i don't have the tunnel ip or vpn set on that THM only the THM IP and the docker ip are shown.
@brandonkilgore47263 жыл бұрын
it doesnt refresh to the upload page for me??????
@danpizzytm41574 жыл бұрын
thanks @dark
@jpersson87184 жыл бұрын
Hi! New to this and im trying to learn more, so this content is just awesome! But im so stuck on this one and after hours i cant understand why the site is just printing out my shell.jpg.php in text when im clicking on it and nothing show up in Nc? Maybe somebody can help me. Best regards!
@DarkSec4 жыл бұрын
Hey! Please hop in the tryhackme discord and ask this in the advent of cyber chat :)
@jpersson87184 жыл бұрын
@@DarkSec Well once again it was my stupid brain that was unreliable. I had forgotten "
@beebed14 жыл бұрын
Can someone tell me what to do? Is this step not available if I use openvpn? I am using openvpn on Mac, sudo nc -p 1234 This code doesn't work. nc: missing port with option -l I seem to get an error. php file, you can write the green part at the top of the try hack me website. $port = 1234; When I go to /uploads/ and click on shell.jpeg.php, I get the error WARNING: Failed to daemonise. This is quite common and not fatal. Connection timed out (110)
@camz_ridez45084 жыл бұрын
when i try putting the cp /usr/share/webshells/php/php/reverse-shell.php ./shell.jpeg.php it says cannot start cp /usr/share/webshells/php/php/reverse-shell.php ./shell.jpeg.php no such file or directory
@walterlensinas44044 жыл бұрын
Hi, try with cp /usr/share/webshells/php/php/reverse-shell.php . and then change mannually the file extension to .png.php or .jpg.php
@elizabethrasnick1361 Жыл бұрын
I'm hitting the same problem.
@mavericks.96384 жыл бұрын
hey Darksec, what laptop or computer do you recommend using a vm on because as soon as I open a web browser on my vm my main machine starts heating up and I hear the fan on loud af. im guessing its using too much ram, even though I've allocated 4gb of ram for the vm.
@curtishoughton93474 жыл бұрын
So I found if you just put ?id= without any id value after it, it will also let you access the uploads page. Not sure if it's an unintential bypass :)
@screencastlover45664 жыл бұрын
Hey mate, I found it as well (I didn't read the elf give code section :D) I think its not intentional, but they left it there, they did a huuge amount of work with everything, so yeah, why would they bother.
@DarkSec4 жыл бұрын
From an internal perspective, I think we just missed that bypass haha
@screencastlover45664 жыл бұрын
@@DarkSec It's a good lesson for us in any case :D Anyway, thank you for your contribution, it was fun!
@curtishoughton93474 жыл бұрын
@@screencastlover4566 Yep that's exactly what I did, went ahead without reading, then wondered how to answer the first question XD. Lesson learnt, either way enjoying the advent of cyber challenges! :)
@Sfhgscvg4 жыл бұрын
Uploads seem publicly accessible, no params needed. The param threw me off guard though, wrote a small script to brute force it and then proceeded reading the id in the assignment. - _- I actually thought of letting sqlmap loose too..
@netwizs30834 жыл бұрын
I tried executing the reverse shell script on the server, I got the following error:- PHP Warning: fsockopen(): unable to connect to (Connection refused).
@RahulKr514 жыл бұрын
nc -nvlp 4444
@thomasstern43364 жыл бұрын
Can you share your tmux script ? :)
@DarkSec4 жыл бұрын
I have a lightly customized version of this: github.com/gpakosz/.tmux
@dazman19734 жыл бұрын
Yay I worked through this challenge without watching the video and worked out some of the solution myself, just verifying I had the commands right in the text. Very chuffed with myself. Thanks for the effort you guys are putting in to teach an old dog like me new tricks. Merry Christmas 🎄
@BroodPitt4 жыл бұрын
.jpeg doesnt work as awnser :(
@lisabartlett52583 жыл бұрын
It's image
@BroodPitt3 жыл бұрын
@@lisabartlett5258 ah 🥺😂 danke!
@was34904 жыл бұрын
Love it
@aimetyuo5484 жыл бұрын
Please sir what is different between (A T) gmail.com and @gmail.com
@aimetyuo5484 жыл бұрын
I try to get my own email: (A T) gmail.com and gmail rejected my request.
@tekken-pakistan27184 жыл бұрын
bruh xD
@null_value894 жыл бұрын
B R U H
@chuckwoolson93394 жыл бұрын
@@aimetyuo548 you have to append {pretty please} then it should work.
@33minutes514 жыл бұрын
he speak so fast
@jaybell08194 жыл бұрын
Who is better? John or Dark We"ll have this answer.......................... Maybe
@DarkSec4 жыл бұрын
Fun fact, Jon is also my first name so its John versus Jon haha