TryHackMe Advent of Cyber 2: Day 2

  Рет қаралды 33,562

DarkSec

DarkSec

Күн бұрын

Пікірлер: 90
@pinglocalhost
@pinglocalhost 4 жыл бұрын
If you are running Kali Linux how do you have your terminal look like that at 14:08 at the bottom with the colors? Thank you.
@mayankchauhan4788
@mayankchauhan4788 4 жыл бұрын
he is using tmux
@scully1856
@scully1856 4 жыл бұрын
@DarkSec I have been stuck on "WARNING: Failed to daemonise. This is quite common and not fatal. Connection refused (111)" Immediately after I try to run the script via the uploads page. On top of that, the port listener is not returning anything? I have changed the port number several times and re-uploaded the .php file and I consistently get this same error. Any ideas?
@LuisHernandez-yb4yd
@LuisHernandez-yb4yd 4 жыл бұрын
I am having the same issues. Did you find a way to fix it?
@scully1856
@scully1856 4 жыл бұрын
@@LuisHernandez-yb4yd unfortunately not. I e been busy with finals and haven't had much more time to look into it. When I figure it out I'll post back here though
@cybercowboy642
@cybercowboy642 4 жыл бұрын
Had the same issue. You are using the wrong IP address in the shell script upload file. Think about how traffic will get back to your local machine. HINT: need to run an ifconfig
@scully1856
@scully1856 4 жыл бұрын
@@cybercowboy642 thank you for the tip! I will check it out when I get back to my computer. I wish I could like your comment 100 times.
@Francois-B-Arthanas
@Francois-B-Arthanas 4 жыл бұрын
This was great! Thank you @Dark
@synack2165
@synack2165 4 жыл бұрын
I know I am a little behind. Playing catchup. I ran into a couple issues but I was able to fight my way through them and figured it out. Good stuff!! Really enjoying these lessons.
@austinthompson1314
@austinthompson1314 4 жыл бұрын
Awesome video Dark! Sucks I had to do it at x0.25 speed due to tryhackme's slow machines haha
@ssh17hx0r
@ssh17hx0r 4 жыл бұрын
These first two THM holiday rooms doesn't give me an indication that it's finished with the confetti and the "Congratulations" message, but it does say 100%. Since it matters for the prize drawings, is there a way to know that it's registering that the rooms have been completed? I couldn't find a place to make a ticket. So I'm posting here.
@DarkSec
@DarkSec 4 жыл бұрын
That's because you're not 100% done. To obtain completion, you have to do all of the days and you still have 23 more to go haha
@ssh17hx0r
@ssh17hx0r 4 жыл бұрын
@@DarkSec That's what I was hoping! Thank you!
@KieCodes
@KieCodes 4 жыл бұрын
Very nice small hack-snack! Loved it! Maybe here's a little tip for mac users. On chrome on mac os you can't select a *.jpg.php file and there is no dropdown menu like on windows to select *.* (or I didn't find it), but a way to get through this is to upload a *.jpg file and repeat the request with burp suite in order to change the filename in the request to .jpg.php.
@audreymcnay3528
@audreymcnay3528 4 жыл бұрын
I just figured out there's a similar option on Mac OS. Click "Options" on the bottom left of the finder window, then there's a dropdown where you can select "All Files" :)
@KieCodes
@KieCodes 4 жыл бұрын
@@audreymcnay3528 Wow. never saw that. Thanks a lot!
@marcotheitguy
@marcotheitguy 4 жыл бұрын
Excellent video though website never uploaded forme tried at different times and different attack boxes and always got same error: 405 - Specified method is invalid for this resource
@JakeStPeter
@JakeStPeter 4 жыл бұрын
Thanks for the video Dark!
@boxclever8030
@boxclever8030 4 жыл бұрын
Cannot get netcat to find the connection, followed all these steps. Any ideas?
@Drusher10
@Drusher10 3 жыл бұрын
had the same issue, i insert the ip that THM game me but couldnt connect :/
@carldavenport1583
@carldavenport1583 4 ай бұрын
@@Drusher10 I think the issue is he has netcat already set to connect from "any" IP. My netcat isn't listening for connection. Gotta figure out to get it to listen for any IP connection like his is already set to do.
@sudarshanpatel8996
@sudarshanpatel8996 3 жыл бұрын
you have been really very helpfull....THANK YOU VERY MUCH !!!
@lommenthepocket3534
@lommenthepocket3534 4 жыл бұрын
Thanks @Dark - as always a pleasure 😊
@cipher3966
@cipher3966 2 жыл бұрын
Did this stop working? Trying to practice but this step will not nmap, page won't load and does not ping
@ssh17hx0r
@ssh17hx0r 4 жыл бұрын
@DarkSec really fun room.
@crystalmorton9500
@crystalmorton9500 4 жыл бұрын
@DarkSec I'm subscribed to tryhackme, but when I deploy the VM it still only gives me an hour time limit.
@DarkSec
@DarkSec 4 жыл бұрын
Oh thats just the auto termination I think, you should be able to extend the time
@crystalmorton9500
@crystalmorton9500 4 жыл бұрын
@@DarkSec thanks!
@dalemanni24
@dalemanni24 4 жыл бұрын
So, two things. First, after doing everything you did, I can't upload it to the site. No idea why, just doesn't allow me to do so. Second, I tried removing the ".php" which then allowed me to upload. After doing that, I can't run the script due to an error. I assume because I removed the ".php". Edit: I am an idiot.
@DarkSec
@DarkSec 4 жыл бұрын
Bahaha didja find the drop down selector?
@dalemanni24
@dalemanni24 4 жыл бұрын
@@DarkSec Nope. Thought I had moved it from All Supported Types to All Files, but didn't.
@nithinchowdarygarapati1604
@nithinchowdarygarapati1604 3 жыл бұрын
I really agree to your edit line.. :) Thats how I felt after seeing this video.. :(
@DarkSec
@DarkSec 3 жыл бұрын
Hey at least ya found it :)
@abdulhaqmohammed
@abdulhaqmohammed 4 жыл бұрын
Hey How can i get a terminal like yours with the ip addresses in the bottom ??
@DarkSec
@DarkSec 4 жыл бұрын
Check out the project OhMyTmux on github
@abdulhaqmohammed
@abdulhaqmohammed 4 жыл бұрын
@@DarkSec Does This work on kali linux?
@DarkSec
@DarkSec 4 жыл бұрын
Mhmm
@Nilicous
@Nilicous 4 жыл бұрын
I am greatful for this amazing video and these fun tasks. I've been given the opportunity to start a junior position at our security department this spring and I've made it my thing to complete this calendar and start learning more before then. I really appreciate the work that has been put into these starting assignments. They were easy to understand and felt engaging. They also left this aftertaste of wanting to know more. So yeah, really good!
@Drusher10
@Drusher10 3 жыл бұрын
Have some questions on this: I have my own VB kali machine and i was inserting on my browser the IP of THM. Couldnt bring me the webpage you created therefore i couldnt complete the tanks. The copy .php file did it fairly easily. Any advice for the issuee?
@rubenramos2814
@rubenramos2814 3 жыл бұрын
Hi, when i try to listen the port 1234 and i start the php shell in the website doesnt appear nothing, can u help me?
@dr.b3276
@dr.b3276 4 жыл бұрын
Please How do I copy into my current directory, I am using windows and kali in my VMware
@0xR1SKY
@0xR1SKY 4 жыл бұрын
I'm proud of myself. I did it myself. BTW all the work you all put on this is really useful and I think it will help everyone. Thanks :)
@Naigung
@Naigung 3 жыл бұрын
I used the video because I couldnt figure out a question...my answer was plural. Whatever the video was great.
@KohzmikYT
@KohzmikYT 2 жыл бұрын
are you a master hacker now :)
@mohamedlourch
@mohamedlourch 4 жыл бұрын
hope you cover more stuffs in this channel .
@DarkSec
@DarkSec 4 жыл бұрын
I certainly hope to! I think my plan is to go on a schedule of one walkthrough a week release or so after AoC2
@aks3479
@aks3479 4 жыл бұрын
I tried running the script but i got WARNING: Failed to daemonise. This is quite common and not fatal. php_network_getaddresses: getaddrinfo failed: Name or service not known (0)
@samiul008
@samiul008 4 жыл бұрын
Having same issue! Anybody found the workaround??
@samiul008
@samiul008 4 жыл бұрын
WARNING: Failed to daemonise. This is quite common and not fatal. Connection refused (111)
@samiul008
@samiul008 4 жыл бұрын
@Bergþór Olivert Thorstensen yes, i changed to correct port and ip address. Once executed,netcat shows listening but after clicking the script on the browser i get the same errorr in the browser. Could not get reverse shell by any means 😪
@samiul008
@samiul008 4 жыл бұрын
@Bergþór Olivert Thorstensen Thanks a lot! I was putting the wrong ip address :P Banging my own skull :D
@Sokoto312
@Sokoto312 4 жыл бұрын
hi all, i need your help. when i run the command to open netcat by nc -lvnp 443 nothing are going only its listenning on (0.0.0.0). i don't have the tunnel ip or vpn set on that THM only the THM IP and the docker ip are shown.
@brandonkilgore4726
@brandonkilgore4726 3 жыл бұрын
it doesnt refresh to the upload page for me??????
@danpizzytm4157
@danpizzytm4157 4 жыл бұрын
thanks @dark
@jpersson8718
@jpersson8718 4 жыл бұрын
Hi! New to this and im trying to learn more, so this content is just awesome! But im so stuck on this one and after hours i cant understand why the site is just printing out my shell.jpg.php in text when im clicking on it and nothing show up in Nc? Maybe somebody can help me. Best regards!
@DarkSec
@DarkSec 4 жыл бұрын
Hey! Please hop in the tryhackme discord and ask this in the advent of cyber chat :)
@jpersson8718
@jpersson8718 4 жыл бұрын
@@DarkSec Well once again it was my stupid brain that was unreliable. I had forgotten "
@beebed1
@beebed1 4 жыл бұрын
Can someone tell me what to do? Is this step not available if I use openvpn? I am using openvpn on Mac, sudo nc -p 1234 This code doesn't work. nc: missing port with option -l I seem to get an error. php file, you can write the green part at the top of the try hack me website. $port = 1234; When I go to /uploads/ and click on shell.jpeg.php, I get the error WARNING: Failed to daemonise. This is quite common and not fatal. Connection timed out (110)
@camz_ridez4508
@camz_ridez4508 4 жыл бұрын
when i try putting the cp /usr/share/webshells/php/php/reverse-shell.php ./shell.jpeg.php it says cannot start cp /usr/share/webshells/php/php/reverse-shell.php ./shell.jpeg.php no such file or directory
@walterlensinas4404
@walterlensinas4404 4 жыл бұрын
Hi, try with cp /usr/share/webshells/php/php/reverse-shell.php . and then change mannually the file extension to .png.php or .jpg.php
@elizabethrasnick1361
@elizabethrasnick1361 Жыл бұрын
I'm hitting the same problem.
@mavericks.9638
@mavericks.9638 4 жыл бұрын
hey Darksec, what laptop or computer do you recommend using a vm on because as soon as I open a web browser on my vm my main machine starts heating up and I hear the fan on loud af. im guessing its using too much ram, even though I've allocated 4gb of ram for the vm.
@curtishoughton9347
@curtishoughton9347 4 жыл бұрын
So I found if you just put ?id= without any id value after it, it will also let you access the uploads page. Not sure if it's an unintential bypass :)
@screencastlover4566
@screencastlover4566 4 жыл бұрын
Hey mate, I found it as well (I didn't read the elf give code section :D) I think its not intentional, but they left it there, they did a huuge amount of work with everything, so yeah, why would they bother.
@DarkSec
@DarkSec 4 жыл бұрын
From an internal perspective, I think we just missed that bypass haha
@screencastlover4566
@screencastlover4566 4 жыл бұрын
@@DarkSec It's a good lesson for us in any case :D Anyway, thank you for your contribution, it was fun!
@curtishoughton9347
@curtishoughton9347 4 жыл бұрын
@@screencastlover4566 Yep that's exactly what I did, went ahead without reading, then wondered how to answer the first question XD. Lesson learnt, either way enjoying the advent of cyber challenges! :)
@Sfhgscvg
@Sfhgscvg 4 жыл бұрын
Uploads seem publicly accessible, no params needed. The param threw me off guard though, wrote a small script to brute force it and then proceeded reading the id in the assignment. - _- I actually thought of letting sqlmap loose too..
@netwizs3083
@netwizs3083 4 жыл бұрын
I tried executing the reverse shell script on the server, I got the following error:- PHP Warning: fsockopen(): unable to connect to (Connection refused).
@RahulKr51
@RahulKr51 4 жыл бұрын
nc -nvlp 4444
@thomasstern4336
@thomasstern4336 4 жыл бұрын
Can you share your tmux script ? :)
@DarkSec
@DarkSec 4 жыл бұрын
I have a lightly customized version of this: github.com/gpakosz/.tmux
@dazman1973
@dazman1973 4 жыл бұрын
Yay I worked through this challenge without watching the video and worked out some of the solution myself, just verifying I had the commands right in the text. Very chuffed with myself. Thanks for the effort you guys are putting in to teach an old dog like me new tricks. Merry Christmas 🎄
@BroodPitt
@BroodPitt 4 жыл бұрын
.jpeg doesnt work as awnser :(
@lisabartlett5258
@lisabartlett5258 3 жыл бұрын
It's image
@BroodPitt
@BroodPitt 3 жыл бұрын
@@lisabartlett5258 ah 🥺😂 danke!
@was3490
@was3490 4 жыл бұрын
Love it
@aimetyuo548
@aimetyuo548 4 жыл бұрын
Please sir what is different between (A T) gmail.com and @gmail.com
@aimetyuo548
@aimetyuo548 4 жыл бұрын
I try to get my own email: (A T) gmail.com and gmail rejected my request.
@tekken-pakistan2718
@tekken-pakistan2718 4 жыл бұрын
bruh xD
@null_value89
@null_value89 4 жыл бұрын
B R U H
@chuckwoolson9339
@chuckwoolson9339 4 жыл бұрын
@@aimetyuo548 you have to append {pretty please} then it should work.
@33minutes51
@33minutes51 4 жыл бұрын
he speak so fast
@jaybell0819
@jaybell0819 4 жыл бұрын
Who is better? John or Dark We"ll have this answer.......................... Maybe
@DarkSec
@DarkSec 4 жыл бұрын
Fun fact, Jon is also my first name so its John versus Jon haha
@jaybell0819
@jaybell0819 4 жыл бұрын
@@DarkSec You guys are awesome btw.
TryHackMe Advent of Cyber 2: Day 3
20:33
DarkSec
Рет қаралды 16 М.
Google’s Quantum Chip: Did We Just Tap Into Parallel Universes?
9:34
How to treat Acne💉
00:31
ISSEI / いっせい
Рет қаралды 108 МЛН
The Best Band 😅 #toshleh #viralshort
00:11
Toshleh
Рет қаралды 22 МЛН
Une nouvelle voiture pour Noël 🥹
00:28
Nicocapone
Рет қаралды 9 МЛН
The First Amiga Virus - Something Wonderful Has Happened
17:05
Modern Vintage Gamer
Рет қаралды 101 М.
TryHackMe Advent of Cyber 2: Day 9
18:10
DarkSec
Рет қаралды 9 М.
TryHackMe's Day 11 of Advent of Cyber 2024
22:39
MBxCyberSec
Рет қаралды 116
TryHackMe Advent of Cyber 2: Day 6
17:45
DarkSec
Рет қаралды 13 М.
Reversing .NET Applications with ILSpy - TryHackMe AoC2 Day 18
24:40
The New Outlook is TERRIBLE
20:19
Chris Titus Tech
Рет қаралды 116 М.
TryHackMe Advent of Cyber 2: Day 17
35:30
DarkSec
Рет қаралды 11 М.
How to treat Acne💉
00:31
ISSEI / いっせい
Рет қаралды 108 МЛН