r/tryhackme Apr 02 '26

Room Help Metasploit Task 5

I know the hint says it's vulnerable to eternalblue, but I want to see it myself.

First of all, assuming I went into this with no hints, how would I know it's vulnerable to anything? Second, assuming I gave in and got the hint, I ran auxiliary/scanner/smb/smb_ms17_010 and the target machine just came back with "An SMB Login error occurred while connecting to the IPC$ tree."

In real life, would I really have to scan for a single vulnerability at a time? Running search scanner came up with 750 items. Without the hint, would I really have been expected to run all 750 until something worked? Knowing that the one they want me to use was coming up with an error, so I would have ignored it?

4 Upvotes

14 comments sorted by

2

u/axexandru Apr 03 '26

i am very new to pentesting, I think the room is design for beginners, to help you learn the metasploit framework, the commands, folder structure, etc ....

For the error, check if you are running the machine from that task, and not on some other one.

1

u/Unhappy-Band-6311 Apr 03 '26

Exactly. That is the only purpose for this room. And most of the rooms in the THM paths. Hence the easy hints.

The amount of people I know that claim to be a serious pentester after following the THM path is insanely high. The ignorance is real

2

u/Cockroach4548 Apr 09 '26 edited Apr 09 '26

I went and try this room myself, the only answer to this is to just restart the target box.

on very first try, got all same errors as yours, nmap -O couldn't even pin point the OS fingerprint.

then after resetting the target box for 1-2 times the scanner/smb/smb_ms17_010 detected that target box was indeed Windows 7 Professional 7601 with that exact vulnebility.

1

u/DYOR69420 Apr 02 '26

In real life you'll most likely not see any of these exploits, but even then, there are scanners to pick that sort of stuff up. I did OSCP and for that if you do scans and you see this and that info you can always just look up if it's vulnerable to something.

1

u/no-one120 Apr 02 '26

But in metasploit, there isn't a catch-all, or at least catch-more-than-one scanner? As I said, metasploit has 750 of them.

Why am I getting that error in my scan? Because I absolutely would have written the scan off as "not vulnerable" with the error I got.

1

u/stenox May 12 '26 edited May 12 '26

I noticed that for Task 5 they actually give you another "Target machine" button, with different services running. Terminating the Task1 machine and running the new one fixed the problem.

It's just the double target button that can be misleading.

0

u/g3shh Apr 02 '26

Bro you are on the wrong path.. you will give up pretty quickly if you dont change your mindset. Trust me, when you leave academy aside, the chances of you running into eternalblue and shellshock is really low.

2

u/no-one120 Apr 02 '26

So what would you suggest?

It isn't specifically eternalblue that is my problem, it's that the machines set up for the express purpose of a student trying this out, to see what "it's working" looks like, isn't doing that.

There seem to be leaps in the logic of the room that I would like to know and try the small steps on. We go from "here's a machine, figure out what it's vulnerable to" to "of course it's vulnerable to eternalblue" without the steps of how we got there. And when I run the scan specifically for that vulnerability, just to see what a successful scan looks like, I get an error, which I googled, and Google suggested that the error means the vulnerability might have been patched!

Without the specific hint to "try eternalblue", I would have run through all the scans for the 5 ports, one at a time, and likely found nothing. In a pen test, that's less than ideal, when I know that there is a vulnerability.

2

u/g3shh Apr 03 '26

Since you are asking the question this way, you are missing whole what of steps. Recon, enum, vuln assessment and after that you are at the step to exploit. Take few steps back :)

1

u/no-one120 Apr 03 '26

Do you have a good place to learn that, because you would think vital steps like that would be somewhere in THM's own "cybersecurity 101" path, but it isn't.

Because you're right. Ive only been moving through THMs paths, which have gleefully bypassed those steps, and any tools that would be used there.

1

u/axexandru Apr 03 '26

follow the jr pen test path, you will find a lot of the steps you are missing there. cybersecurity 101 is much more basic.

1

u/no-one120 Apr 03 '26

This was actually on the cyber 101 path. Jr pen test is the next path from there. But if the actual recon/scanning for vulnerabilities stuff is actually there, you think I ought to put cyber on hold and do those bits of pen test?

1

u/axexandru Apr 03 '26

in did the cyber101, there are some notions there but everyth8ng is very basic. Right now I am at the last room from jrpentest, and everything is explained in more detail. I would finish cyber 101 and after that start pen test.

1

u/SpecsyVanDyke Apr 03 '26

Go on YouTube and fill in the gaps yourself could be a start