help & support
236 Topics- Trick or Treat on Specter Street: Ghost of the SOCI know it's one of the challenge labs but I'm fairly sure I'm missing something extremely straight forward, it's 100 point difficulty 4.... Someone help me please! I'm banging my head against a wall with this one! If anyone can point me in the right direction of the specific persistence mechanism I think that would be a start Q8. Use the service account to delete the spirit's persistence mechanism. The methods you employ to gain access to this account are up to you.746Views0likes30Comments
- FIN7 Threat Hunting with Splunk: Ep.2 – Initial AccessQuestion 8: Extract the hex-encoded image from the RTF that starts on line 108. Decode and open the resulting image file. What is the first line of text that appears in the image? I facing difficulties answering this question, Please let me know how can I answer this?6Views0likes0Comments
- Trick or Treat on Specter Street: Widow's WebI am very stucked in Trick or Treat on Specter Street: Widow's Web I can't do none of the questions, but in any case I start by 4th that is the first answerable one Your first task is to simulate the loyal Crawlers. Run legitimate-crawler and inspect the output in Lab-Files to observe their behavior. To simulate the rogue Crawlers, you must discover the hidden paths on the website. Read the blog posts – they contain clues. Disallow these in Website-Files/robots.txt and run malicious-crawler. Inspect the output in Lab-Files. What is the token? I have created the robots.txt file since I understand that malicious-crawler goes expressedly there. My robots.txt contains all url's I can imagin Disallow: /secret Disallow: /treat Disallow: /hidden Disallow: /crypt Disallow: /warden Disallow: /rituals Disallow: /witch-secrets Disallow: /admin Disallow: /vault Disallow: /uncover Disallow: /post1 Disallow: /post2 Disallow: /post3 Disallow: /post4 Disallow: /contact Disallow: /drafts/rituals But the result of malicious-crawler.txt doesn't give me either a token nor a hint I have curl-ed all pages looking for words as token and nothing. I have found some key words in http://127.0.0.1:3000/witch-secrets as intercepted-incantations, decoded them and nothing. I have searched in spider-sigthings.log what hapened at 3.00 am but nothing Can someone gime me a hint?120Views0likes3Comments
- Trick or Treat on Specter Street: Ghost of the SOCHi there, Am I right as obvious that it may seem that for me to login to Kibana, I need to access this through the Elastic IP address that I have entered in my browser? If so I'm getting the error message on my screenshot. I tried this a few days ago as well and the problem persisted then as well.114Views0likes10Comments
- Digital Forensics: File CarvingHi there, I was just wondering if somebody could please direct me in the correct direction for Q3. The configuration files are stored on my home directory but when I input the command as on my screenshot nothing seems to happen...making me think there must be something incorrect in my command.15Views0likes3Comments
- Modern Encryption: Demonstrate Your SkillsHello, I am a little stuck on Q3 for this lab and would really appreciate any help I can get. So I have followed the steps as required by encrypting the file - plaintext_1.txt and set the password as per steps on the actual file itself - plaintext_1.txt. However after setting the password I am not getting token_1.txt appearing in the Lab-Files folder. What am I doing incorrectly?Solved143Views0likes10Comments
- Elastic Data Ingest: Ep.6 – WinlogbeatHello, I'm a little stumped by Q7 as I'm sure I have the correct values for 'application channel events' as being 5.0% and the question after, Q8 is asking for 'system channel events' and even that at 95.0% isn't correct? I also just tried 5% and 95% to no avail.30Views0likes4Comments
- help with A Christmas Catastrophe: A Letter to SantaI am in the scalation privileges part. Tried to create a symlink to /root/root.txt and to /root in /etc/letters/ waiting cron /etc/chmod.sh takes ownership with chmod 666 instruction and then extract token, but doesn't work Any help? Is there something missing?77Views0likes5Comments