challenges
32 TopicsTrick or Treat on Specter Street: Ghost of the SOC
I know it's one of the challenge labs but I'm fairly sure I'm missing something extremely straight forward, it's 100 point difficulty 4.... Someone help me please! I'm banging my head against a wall with this one! If anyone can point me in the right direction of the specific persistence mechanism I think that would be a start Q8. Use the service account to delete the spirit's persistence mechanism. The methods you employ to gain access to this account are up to you.207Views0likes10CommentsBurp Suite Basics: Intruder - Stuck on missing password.txt
Hello community, I'm stuck in lab https://mercedes-benz.immersivelabs.online/v2/labs/burp-basics-intruder/series/burp-suite. The attack to carry out is about a brute-force guess on mfogg1's password using the intruder. The briefing states: Brute force the login page using the password.txt list against the user mfogg1. I'm missing that password.txt file, where the heck is it? I carried out an intruder attack (Cluster bomb) using well known passwords from /usr/share/wordlists/metasploit/burnet_top_1024.txt without success. Even worse, testing those 200 attacks (there are only 200 passwords in that file), tooks quite a considerable time. I must have missed something about the location of that obscure password.txt file. I'm stuck. Perhaps someone can shed a light on this. Thanks in advance, Wolfgang14Views0likes1CommentServer-Side Request Forgery Web App Hacking
I've been banging my head against this for a few hours now and worked my way all the way through to step 7. I am not able to retrieve /tmp/token.txt. I've tried modifying the "url" param key and found it throws a 500 for anything I've tried other than "url". I've tried modifying the "url" value to use directory traversal and "///tmp/token.txt", "/tmp/token.txt". Still no luck. I've also tried using the original url paths and the bypass I used to view the config file for the bot and I get 404's back. I think the lab could have an issue? I have screenshots but didn't want to share them unless asked to not reveal any answers. Any help is appreciated.Solved48Views0likes2CommentsHalloween Labs - ideas, suggestions, wants ๐ป๐๐ฆ
What would you want to see from future Halloween labs? Did you really enjoy a particular aspect of previous years? Any technologies, themes, rewards you want to see? Want more Community content - webinars, events, media within the labs? ๐ป๐๐ฆ151Views3likes6CommentsNew Maze Challenge is now LIVE!
Do you have what it takes to escape The Maze? Put your offensive security skills to the ultimate test in eight of the most challenging OffSec labs ever assembled by the Immersive team. Whether youโre an experienced Red Teamer, or fancy yourself an offensive security superstar, this oneโs for you! Check out the new Community Challenges Area today to find out more about The Maze and how to take part: Mazeโ71Views2likes2CommentsMalicious Document Analysis: Visual Basic for Applications (VBA) Question 6
"Analyzing sample2.xls, what is the name of the function used to decode and save the Base64 encoded values?" I have zero idea on how to get this answer. There is a function Base64Decode() and a function SaveDocument(). I don't know if I am supposed to run a olevba command, look at the screenshots in the briefing, or run some question code. Thank you32Views0likes1CommentHelp with ELF file entry point in lab
Hi, I'm currently stumped on this lab in particular on the last question: https://us.immersivelabs.com/v2/labs/elf-execution-structure/series/computer-architecture It's asking for the "entry point", which I had assumed based on the image output was 0x4048c5 (it explicitly even says this in the image near the top!), but that's incorrect, as well as answers regarding the PhysAddr addresses. It had gotten to the point where I'm so stumped I tried putting in every other answer I could think of, like the type of program header or some of the names in the segment sections to no avail. The question itself is very vague (what else could be the 'entrypoint'?) and I've been stuck on this for quite some time. I'd appreciate any hints to point me in the right direction, because I don't know what else to put in for an answer now!Solved76Views1like2Comments๐ Episode 7 of Season 1 of The Human Connection Challenge is Closed! ๐
Hey everyone, We hope you enjoyed Lab 7 of The Human Connection Challenge: Season 1 our most difficult challenge yet! It's been fantastic to see the community collaborating and sharing your experiences, thanks to everyone who shared their hints, tips and support. 19 of you successfully completed this lab and over 300 of you have been entered into the prize draw to win some fantastic prizes: ๐ฅ Tickets, Flights & Accommodation to an Immersive Summit in NYC or London ๐ฅ 2 x PlayStationยฎ5 Consoles ๐ฅ 10 x Apple AirPods or JBL Headphones ๐ Much coveted Immersive swag and goodies! We will be drawing names out of the hat later today and will contact the winners directly. As per usual, the lab walkthrough will be shared shortly and we have a special webinar about the lab on Thursday. Join us to hear directly from lab author and evil genius StefanApostolโ. In the meantime, please drop a comment below and let us know how you got on with this challenge, and what you would like to see from Season 2...259Views4likes11Comments