I just completed this level, and I would like to encourage everyone who is still looking for the solution.
Very important is to not give up on this one… I think this is the real beginning to learn what you want to learn.
My advise = to scan a several times if you don’t find the answer, yesterday I didn’t find the results with the same scan that I did today to give me the result to solve this level. Other threads on this forum will give you the hint so you will understand where I’m talking about.
Good luck !!!
did you try a wide range for your scan? maybe its not a known service used one you should be looking for….
I Hate Signatures.
I Hate Signatures.
I’m not sure if this is TMI or if it would help anyone (if so, apologies to the mods) but if you know the tool(s) you have to use, if you Google it with the words “command examples”, you can follow a tut (the very first link) on which ones you need to use to get the correct information. Then, using that information, you can use another tool commonly used in conjunction with the first to eavesdrop to get the answer you need.
That said, I think this book (a PDF copy is available online) might also help some not familiar with steps of a pentest which these two tools are usually the first you run. It came to mind when doing this one.
“The Basics of Hacking and Penetration Testing” by Patrick Engebretson
It is not exhaustive but it explains the steps (recon/exploit/post exploit) and what each means, common tools used and their functions and what you, the hacker/pentester is to get out of them. I mention this because challenge solving, at least for me, isn’t so much about getting the flag/glory but also understanding the concepts behind them and learning.
It’s one thing to copy a command and solve something and another to know immediately what command to use because you’ve learned the concept.
That’s my two cents. Good luck to everyone :)
Its already 6 weeks ago I started to encourage everyone and I’m still receiving private messages of people who don’t find the solution. Personally it doesn’t bother me, most of the people are even very close. It’s for this I just want to say before asking help try to be sure that the target is right ;-).
Hey there,
I know I am a little late to the party.
I have spotted the suspicious service and have deciphered the message.
What I do not understand is where to proceed further? I have the location/link and the port. I just cannot connect to it.
And thanks for the book recommendation @thetechnophile I will definitely read it.
Thanks in advance.
2 different ports, really ?
You should make a new thread in solution section and show us these two ! :)
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘\’‘ at line 1
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘\’‘ at line 1
I think he meant 5 days trying different scan types and repeating same scans over and over again :P
Thats what happened to me , had to scan the website like 5 times with the same scan type for it to finally show up.
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘\’‘ at line 1
nah i just replied to willywill’s comment!
i checked for the date and only looked for the last dates of posting btw, didn’t noticed the original post was opened way before hah my bad :P
WaRWolFz crew
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘\’‘ at line 1
Just read thread man
No pain ( actually I wouldn’t call it pain since you’re learning great stuff … ) no gain !
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘\’‘ at line 1
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘\’‘ at line 1
Wow, you want to do a electromagnetic bomb ? We have a good one here :o
@dloser any tutorial about this ? pls share
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘\’‘ at line 1
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘\’‘ at line 1
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘\’‘ at line 1
lol Nastyblood, someday you’ll not have to correct anything of me :p
Yeah 1337boy, I like doing this :)
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘\’‘ at line 1
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘\’‘ at line 1
I am still stuck at this level. I am just curious to know why do we need to do multiple scans to identify the suspicious service? Could it be because the service is not running at all time or it only runs on some of the multiple backend servers. I did not get any suspicious service when i scanned the default server 4 times but when I incremented the ip address i get something interesting in the scan.
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘\’‘ at line 1
With zennmap, I have scanned multiple times on www.hackthis.co.uk. I was expecting to get it right away with TCP all ports.
standard nmap
tcp all ports (1-65535)
udp
zenmaps “Slow comprehensive scan”
I have also tried scanning with the default options using sparta and it made no difference. I am finding ports, but nothing that looks odd. I can’t remember all of them, but i would say that I have found about 15 ports, some open, some closed.
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘\’‘ at line 1
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘\’‘ at line 1
I was stuck at this level for long. A couple of things that could help
1) Don’t just work with the default parameters of the scanner. Understand each and see if it can be expanded
2) Since people reported they had to scan multiple times I scheduled a script to run regularly and log the output. I still didn’t get the desired output. Maybe its because I was connecting from my office laptop/network and they have additional security.
Thanks to dimooz for guiding me to solve this.
Hello
Yes, don’t give up. It took me 6h, but most of the time, it was only my port scanner working.
Do not be impressed by all previous comments. Hackthis says they are running a service, so FIND IT!
See this exercise as an opportunity to read the manual of your port scanner software and learn more about port scanning and find the damn port.
When you found the service, well… Do with it what people usually do with a service.
I’ve been scanning the server (at defendtheweb.net, using TCP Connect scans on NMap) on and off for about a day now. Not seeing anything but SSH, HTTP and HTTPS.
Tried scanning the old server… worked on the first try.
Is the service blocked on defendtheweb.net, or does it only run once in a while here?
Or is the goal to map the domain, and related domains, then scan all those hosts? It’s possible to find it this way, just… seems like a change from the previous version of the challenge.
Just making sure I didn’t miss the point.
Got it !
Thanks for hints. I have to scan the old server to. Nothing on the actual one.
@Jeefbeef123 : Looking for “scan server” or “scan port” or else on google, you would find some tools to do it.
And after… try and read that thread and look for tuts about scanning.
Cheers
Ok so here is the major mistake I have been doing. Is trying to solve the problem. But the problem is only a sign that tells you ok so you have to learn this, that etc. So thanks @thetechnophile for the book. And others that try to teach us to learn the real reason behind these problems.
Beware of demons and beasts