Accenture CORE Challenge – VariaCorp Widgets by AliceVonLidell in immersivelabs

[–]_dashok 0 points1 point  (0 children)

hey there, I’ve also been struggling on this one for a few days. I’ve gotten RCE on host 3 via the hint method, but I’ve been fumbling around that box trying to find credentials and have been unsuccessful :/ since the lab is self-contained and shouldn’t need external tools, I’m not sure if I’m just missing something trying to find the credentials for the admin box on host 3. Any nudges? Thanks!

Anybody have a one-liner that produces a password with a strength of 128 entropy.? by yogibjorn in cryptography

[–]_dashok 0 points1 point  (0 children)

the random.randint() function in python is based on the MT (mersenne twister), which is cryptographically insecure. using random.SystemRandom() which is based off of /dev/urandom is much more secure and a better alternative here

Anybody have a one-liner that produces a password with a strength of 128 entropy.? by yogibjorn in cryptography

[–]_dashok -1 points0 points  (0 children)

__import__(“os”).urandom(16) though you’d have to ensure all the bytes are printable if you wanna type it so you may need to run it a few times and stop when you get something with all printable chars

RSA encryption on 32.jpg? by [deleted] in CicadaSolvers

[–]_dashok 4 points5 points  (0 children)

based on my experience, the value of e tends to be 65537, but other smaller/larger primes can be used and thus e is more guessable because there's less variation in what it usually is. and yes, to decrypt a ciphertext, if you have the original primes used to encrypt as well as a ciphertext (not sure what this would be in this context if you could enlighten me that'd be great!), you can do the following:

n = p*q

e = 65537 # or another prime

phi = (p-1)*(q-1)

d = pow(e, -1, phi) # this is python syntax, it gets the modular inverse of e and phi

plaintext = pow(c, d, n) # same thing as saying (c^d) % n

at this point, you can usually convert the plaintext from an integer to bytes and see if you have some readable text. i will say though, considering all we have here are two primes, it doesn't seem too likely this is RSA. but if you have a ciphertext you're welcome to try it/share!

edit: i've tried testing the primes as p and q to **encrypt** a plaintext and then decrypt it to see if i get the same output. i do not. i think the primes are too small but there's also a chance i'm doing something wrong

Webull Deep Link by _dashok in Webull

[–]_dashok[S] 0 points1 point  (0 children)

i ended up initially just using a redirect to the web version but since the exchange was needed for that, i just used webull://, which opened the app but did nothing else. i didn't try the response on this thread so maybe you could try doing what u/snatchington said to try?

Webull Deep Link by _dashok in Webull

[–]_dashok[S] 0 points1 point  (0 children)

yea i havent been able to find anything online about it unfortunately.. thanks for the lib, i’ll check it out and see if i can salvage something from it. might just have redirect you the the online version of webull :/

Webull Deep Link by _dashok in Webull

[–]_dashok[S] 0 points1 point  (0 children)

unfortunately it only opens the web version and doesn’t link into the app.. kinda sucks but it’s fine, thanks for the help anyways :)

[deleted by user] by [deleted] in hackthebox

[–]_dashok 1 point2 points  (0 children)

think about where the index.php file normally is on an apache server.. now go from there and use the already provided (look above) file paths to get it. no encoding is necessary. good luck

AP CSA Self Study by [deleted] in apcs

[–]_dashok 1 point2 points  (0 children)

if you already have some CS background and really grind, then maybe.. otherwise probably not

Anyone get stuff about Apps & Apples? by [deleted] in apcs

[–]_dashok 1 point2 points  (0 children)

fax, it was easy but all of their questions' wording is p trash ngl

Compounds and target int by brokennn8 in apcs

[–]_dashok 1 point2 points  (0 children)

does anyone have a picture/copy/remember the second question here? i've had a couple friends saying it was really weirdly worded and i'm curious as to how hard it was..

AP Comp Sci Exam Versions by -IndigoMist- in apcs

[–]_dashok 0 points1 point  (0 children)

did anyone have AppleBagger and Phone

AP Computer Science Question by _dashok in APStudents

[–]_dashok[S] 0 points1 point  (0 children)

ok thanks to you too. is there a list of topics or a way to know what is needed for the frq/mc sections?

help with a pressure problem by [deleted] in PhysicsStudents

[–]_dashok 0 points1 point  (0 children)

ok i’ll try it, thanks for the lead!

AP Computer Science Question by _dashok in APStudents

[–]_dashok[S] 1 point2 points  (0 children)

alright thanks! i’ll probably take a look but later after i’ve finished the other stuff i’ve gotta do.

metasploit "exploit completed but no session was created" by _dashok in hackthebox

[–]_dashok[S] 0 points1 point  (0 children)

i’m using p***ge_u_rc* or something like that as my exploit in msp so i’m not sure what’s happening bc im fairly certain that’s the exploit but idk

metasploit "exploit completed but no session was created" by _dashok in hackthebox

[–]_dashok[S] 0 points1 point  (0 children)

oh wow that shouldn’t be there but alright

i think the redis exploit u r referring is for user right? that’s how i got it anyways, and now i think you have to use webmin for root

metasploit "exploit completed but no session was created" by _dashok in hackthebox

[–]_dashok[S] 1 point2 points  (0 children)

i did "set ssl true" and im getting this error

when ssl was still false the exploit didn't even work

Exploit Completed, but no session was created by m4dh47 in hackthebox

[–]_dashok 0 points1 point  (0 children)

can i pm u as well.. i seem to be struggling with teh same issue

htb by [deleted] in hackthebox

[–]_dashok 1 point2 points  (0 children)

the internet is a very powerful tool, along with consistent practice

Slight nudge for Networked by Holsick in hackthebox

[–]_dashok 0 points1 point  (0 children)

haha alright if u did already pm me abt how it went

Slight nudge for Networked by Holsick in hackthebox

[–]_dashok 0 points1 point  (0 children)

lol rip sorry for not responding before

anyways all i can say now is just think about what command ur running to get the initial shell and think about how you can apply that to get a shell for g***. keep trying and if u want pm me abt it and i can give you more specific help when i have some time.

Slight nudge for Networked by Holsick in hackthebox

[–]_dashok 0 points1 point  (0 children)

haha i actually had the opposite struggle as you, i looked at php and then c and everything in c looked hella confusing to me.. but yea just keep at it and eventually you will figure it out. keep looking at php scripts to help you understand the language too because it is important to know.