#modules

1 messages · Page 1 of 1 (latest)

bitter dawn
#

Hi I wanted to enroll htb academy student subscription but I have few things to ask, first of all does it give me a certification or something like this? And also I have logged in with my mail .edu.it that is the school certified email but i can’t access the plan, should I write to the support?

quiet prism
#

can't get the zip file to crack into the pwnbox... any advice?

ancient ivy
ancient ivy
ancient ivy
#

Thanks 👍

chilly slate
#

I'm at File Upload Skills Assessment, but guess doing something wrong - have created a list of allowed mime types and file extenstions, but using them ends with error 500. Anyone?

bitter dawn
ancient ivy
#

Maybe you need to verify it? Or you could contact support. As far as I can remember the process was as easy as changing the email

quiet prism
#

Either way this module is dumb 😂 don’t take it personally if the author of the module is here but I found the area of hacking I’m not interested in as much as others 😂

rustic sage
#

Things are dumb if you're not interested in it. Epic

shrewd bolt
#

Hi, i just started the Intro ti network traffic analysis module and I'm stuck at the second page (Networking primer - Layers 1-4). I answered all the questions but the 4th one, What addressing mechanism is used at the Link Layer of the TCP/IP model? (hint: Its not IP. Write it as singular not plural.): the module, under the section Addressing Mechanisms, states that the addressing mechanism used in the Link Layer is MAC-addressing but I'm having trouble finding the right answer.

#

Could someone tell me if I'm missing some information or it's just a format problem, thanks in advance.

chilly slate
devout vector
#

well there are other Address Resolution Protocols out there maybe you should search them up and see if that could work

shrewd bolt
#

Ok, I'll try, thanks for the help ʕ •ᴥ•ʔ

devout vector
#

no problem

cold marsh
#

i need help with web attacks skill assessment

vital adder
vital adder
quiet prism
#

when you're making a python http server on pwnbox it just says connected on http://0.0.0.0:80/ this is a problem... any help trouble shooting? trying to move a zip file over to crack

vapid grove
#

Hi, i'm stuck at module Using metasploit framework, Exploit the Apache Druid service and find the flag.txt file. Submit the contents of this file as the answer., i think i'm doing it correctly, setting RHOSTS and LHOST, but says target not exploitable and won't return the shell.

vital adder
quiet prism
#

now i'm trying to run the 7z2john.py script and it keeps saying syntax error xD

vapid grove
vital adder
vapid grove
#

It seems pretty straightforward but i keep getting that the target is not vulnerable

vital adder
quiet prism
vital adder
quiet prism
#

clearly user(me) error

#

any tips? (this is the 7z2john.py script, i downloaded it from github on my vm)

#

it's just not named that xD

vital adder
spice sundial
#

help me pls

#

about vpn

vital adder
quiet prism
#

i know what i need to do but some issue with pwnbox is stopping it working properly

#

derp... got that unzipped. getting same error now with the extracted file

polar widget
arctic acorn
spice sundial
#

ty

vital adder
clear bough
#

hi man, i'm stuck in "AD Enumeration & Attacks - Skills Assessment Part II" at the question "Use a common method to obtain weak credentials for another user. Submit the username for the user whose credentials you obtain." , i have a session on MS01 but when i use DomainPasswordSpray.ps1 it doesn't find anythink, it is stuck and don't run (i have already correct the powershell script)..... can anyone help me please??

quiet prism
rustic sage
#

Hi I'm the last part of Skills Assessment - File Inclusion

I'm struggling to|| execute the log poisoning on the admin panel, I'm able to inject my user agent and view it through the nginx logs, but once I inject the php shell I cant get it to execute commands like &cmd=id || Any tips?

tight mesa
#

hello everyone, anyone who had completed XSS room?

rapid pine
#

Any help on AD Enum and Attacks - Assessment Part II for how to get Administrator flag on MS01? I got into a rabbit hole of trying ||printnightmare|| but couldn't get it working.

spare maple
#

hello

#

i got error using waybackurls command

#

could anyone help me

#

bash: waybackurls: command not found

west canopy
#

@rapid pine i might be able to help

mystic pewter
#

Hey everyone, I'm looking for some direction on the xss phishing module.

Issue 1.
Payload: I use the provided JavaScript between <script> tabs.
Results in this: HTB phishing https://imgur.com/a/5YCkwbx
Which does not seem correct.

Do I need to find a different payload?

Also when running netcat on port 80, the workstation keeps telling me the port is already in use. Though I have not played around with it much due to wanting to get past the code issue first.
Any guidance would be appreciated

#

Tried another payload with similar results; JavaScript: document.write....

surreal marsh
#

Hey people I got an issue with the final skill assessment in Using Web Proxies Module. Last task. I've set up a proxy inside the Metasploit (set PROXIES HTTP:127.0.0.1:8080) and yet Burpsuite is not catching the requests send via auxiliary/scanner/http/coldfusion_locale_traversal. Can someone tell what am I missing?

mystic pewter
#

Try to Google settings up metasploit to proxy through burp. I forget exactly what I had to do but the answer wasn't in the module / didn't work. @surreal marsh

surreal marsh
opaque badger
#

Hello! I'm currently working on the privilege escalation problem in the "Getting Started Module". I'm. stuck on the second part where the prompt is " Once you gain access to 'user2', try to find a way to escalate your privileges to root, to get the flag in '/root/flag.txt'." Whenever I try the "chmod 600" command it says "Operation not permitted". I don't know how to get around it. Any help would be greatly appreciated.

twin stirrup
#

Anyone around that could help give me a nudge on the Footprinting Lab - Hard module. Always remember to scan UDP.

spare maple
#

does anyone know how to solve this error

#

downloaded vpn key from info gathering module then tried using openvpn academy.ovpn

rustic sage
#

Try sudo openvpn other.ovpn

spare maple
#

ok

#

tnx

rustic sage
#

np, glad it helped

west canopy
#

@opaque badger try running as sudo maybe

opaque badger
#

@west canopy Sudo requires the password for the user2 which I don’t have because I acquired shellthrough a vulnerability under user1. And user1 doesn’t have permission even with sudo

#

Thanks tho

west canopy
#

@opaque badger wait did you copy the id_rsa file to your own mahcine?

cloud ginkgo
#

hey
i just finished all the paths in thm
and i would like to know in what order i should take the paths in hackthebox to learn the most out of them

acoustic owl
cloud ginkgo
#

i want to do specifically pentesting

west canopy
#

start with Basic Toolset path imo

cloud ginkgo
west canopy
#

I'm not sure, i think there is some overlap between some of the paths

cloud ginkgo
#

ok ty

wheat garden
#

any one finish the academy module foot printing. On the last 2 questions of the IMAP/POP3 section. What is the admin email address? and Try to access the emails on the IMAP server and submit the flag as the answer. Not sure how to find the admin email and could use a tip on finding the flag.

slow ruin
#

Need a hint on Attacking Common Services - Attacking SQL Databases. Logged in to the mssql server with the given creds but running any command gives me no output
nvm figured it out

white crater
#

Need some hints for question Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host on final assessment 2 in the module Active Directory Enum and Attack .

west canopy
#

@white crater did you find the credentials for ||mssqlsvc?||

white crater
west canopy
#

sure

white crater
#

thanks

wheat garden
carmine hill
#

Hi! Can I dm someone for the blacklist filters section in the File Upload Attack? I’m running out of ideas, despite of having several not blacklisted extension, I haven’t found any that executes php code

vale salmon
#

So I could use a little help on the Network Traffic Analysis in Intro to Networking. I'm looking through the pcap file, but I am not finding anything even resembling an employee name.

radiant dagger
#

Thank you mate, I didn't even use hashcat after found this. hash.raw | cut -d ':' -f4 then crackstation

vital adder
vital adder
wind plaza
#

hi! I am working on the hashcat module, trying to pass first question in last section (Wireless cracking) . I used the ./cap2hccapx.bin to get the hash, it looks fine on output. However, I got error when I used hash cat to crack it. I think it somehow went wrong. can anyone help me? thanks !

#

�b...*1y�J�A�А�c��&O�"s^'��PvB��y): Separator unmatched => i got something like this

vital adder
vital adder
wind plaza
#

thank you for helping

#

i got it

vital adder
vital adder
#

i think he is the the Packet Inception, Dissecting Network Traffic With Wireshark section

vital adder
exotic tundra
#

Anyone else having VPN issues today? Mine keeps timing out, before anyone says, yes used openvpn before and the connection pack from here before and yes tried downloading a fresh connection pack.

carmine hill
wind plaza
stiff moon
#

on "Pivoting, Tunneling, and Port Forwarding" the part "Web Server Pivoting with Rpivot" im stuck on the last question "Using the concepts taught in this section, connect to the web server on the internal network. Submit the flag presented on the home page as the answer." i have done it but still cant see the web page i even scanned with nmap and its not open etc... any help?

#

i solved it

fleet magnet
#

hey guys, anyone manage to get dcsync to work for khartsfield on AD attacks module, probably doing something daft but can't get to work..

vale salmon
#

@wind plaza @vital adder Part of my issue is that I can't get NoMachine to connect, nor ssh. I keep getting 'No Route to Host' errors. I am connected to the Academy VPN, though. I'm assuming I need fresh packets, not the stuff in the lab resources.

slow ruin
#

Need a nudge for Attacking Common Services - Attacking SQL Databases. I am logged in as mssqlsvc. Tried impersonating existing users but do not get any users I can impersonate. Also, tried to find communicate with other databases but does not look like there is one to communicate with.

vital adder
vital adder
vale salmon
#

Hmm. Okay. I've tried refreshing my VPN several times, though. May be a ticket to support.

vital adder
#

oh btw can use check what openvpn version are you using

vale salmon
#

OpenVPN 2.5.7 x86_64-pc-linux-gnu

vital adder
worthy yoke
#

I need a little help at the File Upload Attack - Skills Assessment module, I found the upload location when I read the code, successfully uploaded the file, but I can't find the file I uploaded, the path is as I understand. then the files will be changed to YMD_filename.extension format and saved in ||/user_feedback_submissions/||
For example: ||http://IP/user_feedback_submissions/20220723_shell.phar.jpeg|| , am I missing something ?

livid iron
#

Hi i am new to HTB academy - i am facing problem with the CRACKING PASSWORDS WITH HASHCAT module.

I am having trouble with this question:
Identify the following hash: $S$D34783772bRXEx1aCsvY.bqgaaSu75XmVlKrW9Du8IQlvxHlmzLc.

I have tried Drupal7 but it just wont give me right.

vital adder
worthy yoke
vital adder
livid iron
spare maple
#

could anyone help me with this

#

module=information gathering

#

section=active subdomain enumeration

#

question number=4

quaint marsh
#

crackmapexec smb 10.129.32.8 --port 139 -u jason -p pws.list ???

vital adder
quaint marsh
#

on port 445 not work

vale salmon
#

@vital adder Okay, I finally got connected and was able to run Wireshark to capture. I found a HTTP Stream for forgot password, but still am struggling to find the employee name. Am I at least looking in the right spot?

shrewd bolt
vale salmon
#

Cool, thanks

shrewd bolt
#

np

final frigate
#

Hi, in the module Stack-Based Buffer Overflows on Windows x86, the section Finding a Return Instruction ask for searching a pattern

#

The address I found several times doesn't count as an answer, I'm missing something?

formal merlin
#

Hello

#

Hello

#

I need help

vital adder
quaint marsh
vital adder
shrewd bolt
vapid grove
#

Hi, i'm doing module "Password Attacks" in section password mutations, doing a mutation from the original wordlist with the rule they provide i get a 93000 password dictionary, i'm not getting any hit with hydra as it is so slow, any recommendation?

west canopy
#

@vapid grove i ended up just attacking ||ftp instead of ssh and cranked up the threads in Hydra||

vapid grove
#

you mean attacking the ftp service with the same user and so?

west canopy
#

yep

vapid grove
#

just because you can put more threads on it or?

west canopy
#

yea and i think natively it might be faster

#

to bruteforce

glacial blaze
#

Hello everyone,
I need some help on a question from Hacking Wordpress - Skills Assessment.
Got all answers, except one : "Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download."
Just saying "a file" seems too large for me.
Can someone who already did this module help me ?
Thanks.

sturdy agate
#

Would someone be able to help me with Footprinting Lab-easy? I am struggling to understand how I can find the username and password on my own without using the hint info.

acoustic owl
acoustic owl
acoustic owl
glacial blaze
spare maple
hollow oyster
#

Hey, could i DM somebody on SQLMap Essentials on Final Examination.
I have found an injection point but SQLMap is not returning the final_flag in a right format :S

devout cliff
#

general question about wpscan and wordpress. if you are enumerating a site and you find a readme.txt of a plugin but wpscan says it doesnt find the actual plugin, should you reach the conclusion that the plugin is actually present but the scan doesnt see it? would there be a situation where you would find a readme.txt of a plugin that is not present on the site?

west canopy
#

@devout cliff it would depend on if there is anything in the /wp-content/plugins or theme directories

#

i believe

devout cliff
#

im going to run the scan again but its very odd

west canopy
#

if there aren't any php files then i wouldn't think its active

devout cliff
#

present but not active on the website

lethal latch
#

Aside from the obvious ones in the CBBH path, what modules have you all done that seemed interesting from a bug bounty point of view?

summer lava
#

+ Try to access the emails on the IMAP server and submit the flag as the answer. (Format: HTB{...})
Please any help with this ? i openssl 'ed to the IMAP mail server but i can't login with the credentials HTB provided

acoustic owl
summer lava
#
└─$ telnet 10.129.166.252 143
Trying 10.129.166.252...
Connected to 10.129.166.252.
Escape character is '^]'.
* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ STARTTLS LOGINDISABLED] HTB{roncfbw7iszerd7shni7jr2343zhrj}
LOGIN robin robin
LOGIN BAD First parameter in line is IMAP's command tag, not the command name. Add that before the command, like: a login user pass
#

Do you understand this output

LOGIN BAD First parameter in line is IMAP's command tag, not the command name. Add that before the command, like: a login user pass```
west canopy
#

@summer lava try doing ||tag login robin robin||

summer lava
summer lava
west canopy
#

sec i will DM

quiet cape
#

Hello guys can someone help me on getting started module section public exploits
I used metasploit but keep saying completed without anything happened can someone help me?

unreal patio
#

What wordlist should I be using? it's taking forever

quiet cape
unreal patio
#

@quiet cape Do you have a listener set up?

#

I assume you're trying to get a shell

quiet cape
quasi wave
#

hi I need help with this module

#

Linux Fundamentals module 18 Section 1

quiet cape
#

Its a wordpress page with plugin 2.7.10

quasi wave
#

I get one config file to show up but the file is invalid

#

answer doesn't accept file

#

could someone hint me towards the right answer?

unreal patio
#

@quasi wave What are you trying to do with the file?

quasi wave
#

I need to find the right file so I can type its name in answer box

#

but I want to really learn and not just have someone give me the answer

#

thanks btw

#

I just wanted to clarify my inquiry

unreal patio
#

queuemark you already have your answer in that terminal window

quasi wave
#

yes I know but I type the name of the file in the answer box and it won't accept it

#

it will say incorrect

unreal patio
#

Are you typing the path or the file?

quasi wave
#

shit

#

I omitted the file path and it worked

#

lol I wasn't thinking

#

thank you

unreal patio
#

🙂

willow dust
quasi wave
#

I know

#

I know

#

brainfart

#

I mean this stuff is going well btw I just am doing TryHackMe and Hack the Box academy concurrently

#

I think as a combination it goes quite nicely

#

will the bug bounty learning path be enough for me to learn to make real money doing bug bounties?

#

I just thought I would ask

willow dust
#

That’s a complicated question, but I’d say yes and no.

quasi wave
#

ok

#

what do you mean?

#

does it depend on the person?

willow dust
#

Yes in that it gives you the tools for sure, but no in the sense that bug bounties, especially public ones, require quite a bit of time to find bugs, even for seasoned hunters. I don’t know everything, for sure, but I’ve got a few bounties and what worked for me was combining THM, HTB-Academy, and not cheating on boxes in the actual HTB.

quasi wave
#

ok

#

what's your largest bounty?

willow dust
#

It does depend on the person for sure. Not to discourage you, though, I think anyone could do it, just takes a lot of work.

quasi wave
#

is pentesterlab an ideal place to learn after I complete the bug bounty path?

#

or is it not necessary

willow dust
#

I’ve never tried it, but it’s worth a look for sure!

quasi wave
#

ok

#

once I complete THM and HTB Academy, aside from the real HTB, where else should I work on my skills?

#

thanks btw

#

would you say that doing HTB and Pentesterlab is practical at that point?

#

I'm looking for learn more advanced skills and get some repetition in

#

the idea is to get as good as possible in two or three years

#

etc

willow dust
#

You could try an actual public bounty board, like HackerOne or Bugcrowd.

I’d say yeah, that’s the practical stuff you’re looking for. Someone more experienced than me likely can also point you in some good directions too. That’s what I love abojt this stuff is that you’re always learning, and you can stay humble with the vast amount of stuff there is to know.

#

I would just be careful on real targets because they will definitely come after you if you accidentally bring a server down, so go nuts on HTB and pen tester lab and learn there. Also look up which tools can cause problems with servers, because that’s the last thing you want is to be on the line for stuff like that.

quasi wave
#

right

#

pentesterlab teaches web penetration testing without tools

#

it teaches basic through mega advanced

#

it teaches you to do everything manually

#

lol

willow dust
#

Oh that’s neat. Sounds super tedious but I’d be down to learn more about not being so tool reliant

quasi wave
#

ya

#

but I think getting through the bug bounty path will be the step I take before pentesterlab

#

I mean and getting through all the THM paths

#

because ideally I need to learn as much as possible

#

I'm just absorbing stuff

willow dust
#

It’s great training, for sure. Save the cheat sheets too bc they are good references. I keep them saved so that I don’t have to waste bandwidth trying to remember the ins and outs of every single tool.

quasi wave
#

I ideally want to be a good bug hunter and/or web penetration tester

#

but ya good idea

#

I think that going through multiple trainings is ideal in my case because I want to gain as much skills as possible before I graduate in 2 and a half years

willow dust
#

Yeah I feel you dude. You’re def in the right place for a goal like that!

quasi wave
#

maybe in the next three years ya

willow dust
#

Also another tip is don’t shy away from the blue team stuff. I did that starting out and my reports were horrible, but the more I’m learning now the better my reports are becoming. A good report can make the difference in how fast the bug gets fixed and how the interaction with the client goes.

quasi wave
#

I feel ya

#

ya I mean I definitely will take cyber defense learning path on THM when I get to it

#

I for sure should do some defensive security courses

#

its a good idea

#

what is a good amount of money to expect to make on a first bounty

#

let's say I'm starting off

#

like once I get through bug bounty learning path in HTB Academy

#

is it possible to complete all of THM learning paths and HTB Academy in 6 months?

#

if I focus hard on it?

#

and put in a lot of time and effort?

west canopy
#

well i have never used THM but you can definitely get thru the bug bounty path in 6 months

quasi wave
#

I want to get through bug bounty path and jr pentester path tho am right now I am doing Linux Fundamentals and I need to do prerequisite paths

#

when I get stuck on HTB Academy for a while I transition to THM and vice versa

#

so ya

#

then once I meet this goal I will decide next goal

willow dust
#

Oh you can def get through it in 6 months.

vital adder
quasi wave
#

Ok thanks

#

Awesome

#

So I guess this is a doable goal then

#

Ok

vital adder
#

but don't jump right into the offensive or defensive path do the beginner and fundamentals path first

quasi wave
quasi wave
#

People tell me I will get burnt out but I don’t think that’s the case

#

I’m aiming to build penetration testing skills quickly

#

So once I complete THM and HTB Academy I will move onto Pentesterlab and HTB VIP

#

In order to get more advanced skills

vital adder
crude kettle
#

My sincerest apology to you/mods/each and everyone of you who received the invite link or got spammed every section of this server, my account got hacked !
Idk what is happening....its literally getting spammed almost everywhere..i got phished!!
With the same server link , im trying my best to mitigate the issue...it just happened unknowingly.
I strongly suggest not to click join or verify yourself via any method , its a new kind of social engineering or phishing attack named token loggers . Im not the one who created this sh*t ! This is spreading everywhere!!! my friends account are also getting compromised.... I got this sent by one of my friends, if you click join n verify yourself your account will also get hacked n will start to spam everywhere...so Please don’t ! And be aware of it guys. .

summer lava
unreal patio
#

@summer lava Thanks for the reply I solved it a minute ago, the forum had good pointers

summer lava
#

Are you fellowing the JUnior Penetration Tester

unreal patio
#

Yeah, I did some lose modules before and now I'm following the path

rustic sage
#

hey

#

i wanted to hack an insta account

#

can someone help?

#

pls help

#

imma leave the server

#

its just useless

shrewd bolt
#

lol

rustic sage
#

bro

#

do u know how to hack?

#

wanna hack my teachers id

shrewd bolt
#

nah man

#

only hackthebox machines sry

rustic sage
#

okk

#

where u from tho?

shrewd bolt
#

i don't think we are supposed to be having this conversation in this channel

rustic sage
#

hmm

#

u are probably a middle schooler

shrewd bolt
#

yeah true

rustic sage
#

which class?

#

6th?

#

lol

shrewd bolt
#

i don't really understand why you are mad but imma just ignore you np

languid dawn
#

and do not start flame wars for no reasons.

acoustic owl
# unreal patio

You need to find all the zones.
If you are still stuck, feel free to DM me

summer lava
bitter dawn
#

where can i contact the support for htb accademy student subriscption?

#

I still can't get the student subrcription with my edu mail

uncut mirage
#

Hi, I'm stuck in the Weak Bruteforce Protections section of the Broken Authentication module. I've tried using the provided python script but I can't get it to run without errors. I've also tried fuzzing the login with Zap using the mentioned CIRT lists for username and password. Lastly, I also tried using Ffuf, similarly without any results. DM me please, thank you!

bitter dawn
quiet cape
vital adder
vital adder
vital adder
quiet cape
#

The l host is tun0 right?

vital adder
quiet cape
#

What do i need

vital adder
quiet cape
#

If u have a frre time look at the section is in module getting started section public exploits

quiet cape
vital adder
quiet cape
#

What do i type?

#

I keep coming accros rabid7

vital adder
#

@quiet cape no i was wrong metasploit make this way easier

#

you just need to set rhost and rport and the file path to the flag location

quiet cape
#

How to set file path?

#

What do i put in it

vital adder
quiet cape
#

Wait i'll try now

plush edge
#

Can completed modules be revised without paying for them again? Nor retaking them entirely?

willow dust
#

Yup!

vast geyser
#

Hi ,Could anyone give me some hint about "WEB ATTACKS- Mass IDOR Enumeration"?
I am stuck at regexp for ".txt" so I manual find the flag
How can I write the regexp for this ?
Thanks

west canopy
#

@vast geyser i solved it using ||burp repeater and just fuzzed for uid's 1-100||

ancient ivy
#

At that point you will have reached 500 cubes i believe

#

And you will be able to unlock only one tier 3

#

By purchasing with the cubes earned

#

Without having to pay those other subscriptions

#

Silver etc.

austere pendant
#

Hello good people is anyone working on the xss module

#

?

radiant dagger
#

I think the cheatsheet for that module is pretty weak. Especially most of users familiar with linux more

next tree
#

i know this is the wrong place to ask, but anyone know what gives with the openvpn issue ? data-ciphers-fallback(2.4.7)

#

is this an openssl issue ?

radiant dagger
grizzled cobalt
#

ANSWERED

Working through Getting Started: Public Exploits. I can exploit the plugin on the target website and pull back the backed up file (looks like it's a list of profiles and permissions), but I'm not sure what to do after that. I've tried running some other exploits with msf based on the filenames, but I'm not having any success. Any suggestions would be appreciated.

polar widget
radiant dagger
#

RDP and SOCKS Tunneling with SocksOverRDP super unstable even not practicable

#

something wrong with instances now? NVM, restart fixed it

rain marlin
#

Evening, having some issues with the WINDOWS FUNDAMENTALS module in the NTFS vs. Share Permissions section at the "Using smbclient to Connect to the Share" part where I need to use smbclient in which I have and included the Ip addy of the target. But I keep getting "failded (Error NT_STATU_IO_TIMEOUT) and not sure why, could someone help guide me to where I've gone wrong?#WINDOWS FUNDAMENTALS#modules

radiant dagger
radiant dagger
placid quest
#

@grizzled cobalt where are you stack

quiet cape
#

hello can someone help me im on module getting started section nibbles intial foothold i couldnt get a reverse shell what did i do wrong?

grizzled cobalt
upper vault
#

I'm doing a refresher of Info Gathering - Web edition :: Active Sub Enumeration, and I'm in the section Active sub enumeration, I remember I had trouble getting the FQDN of the nameservers before, been trying dig/nslookup/etc, but cant seem to get it to cooperate. Anyone available? --- edit: found a forum post, nvm 🙂

radiant dagger
full mica
#

Hello, I am currently stuck at ACTIVE DIRECTORY Skills Assessment 2: Getting access to Administrator Desktop on MS01. After obtaining an elevated shell on the SQL server, I pulled an INLANEFREIGHT/Administrator hash from the cache. However, any attempt to crack it or doing pass-the-hash was unsuccessful.

lament beacon
#

Hello, for the Footprinting: DNS module (final question), I'm trying to brute force (dnsenum) various subdomains to identify the host ending with .203 . I did find out a zone transfer on a subdomain but no help.

radiant dagger
radiant dagger
#

rdp .50 by using a plaintext credentials

full mica
#

I just received the NT-Hash for admin. No chance to crack it offline...

radiant dagger
#

I think I'm pretty clear about what can be done and what can not be done

full mica
#

Who is talking about not trusting? If you could just explain me what you mean by RDP .50? There is no need to be defensive about your advise.

radiant dagger
#

no offence, probably should go with netrual words "*believe"

uncut mirage
#

Hi, I'm stuck in the Bruteforcing Usernames section of the Broken Authentication module. I can't get wfuzz to detect any difference in the outputs, even though it is clearly visible upon manual inspection (I brute forced the answer). Using the timing script in order to solve question two likewise doesn't detect any difference. If you have managed to make it work, please DM me. Thank you!

vapid grove
#

Hi, im stuck at Password Attacks - Credential Hunting in Windows, I find Winscp creds with the method they provide, but in the module response says the credential is wrong..

Edit: solved, format things 😫

worthy yoke
#

I see in the section SERVER-SIDE ATTACKS - Blind SSRF Exploitation Example , the target machine does not seem to match the lesson content, the target machine is repeated with the SSRF Example which should be an example exercise about Blind-SSRF

pine cargo
#

Footprinting modules boxes were a tough one, though definitely fulfilling to have finished them without looking at any hints or the forum

quaint marsh
#

i find only ||ns, helpdesk, control, root, mail.pornhub, pornhub||

rustic sage
#

Hey

#

/rank

errant lava
#

./verify

vital adder
lament beacon
#

Anyone nudges on the Footprinting Easy module

acoustic owl
lament beacon
uncut mirage
#

Hi, I'm stuck in the Bruteforcing Usernames section of the Broken Authentication module. I can't get wfuzz to detect any difference in the outputs, even though it is clearly visible upon manual inspection (I brute forced the answer). Using the timing script in order to solve question two likewise doesn't detect any difference in the execution times. Please DM me

lament beacon
#

Footprinting medium challenge got some creds for smtp in tickets does that help?

red obsidianBOT
#

There is no flag here. Get back to hacking!

lament beacon
#

I have the sa credentials for the SQL service but, it doesn't seem to work for me

dim flame
#

hi guys, I'm little stuck on DNS attacking on common services module. Can someone help me? I red that there is some bug on that, but I don't know if it's me or the bug the problem...

frozen lark
#

why is the pwnbox so laggy? it's beyond usable for me

quiet cape
#

how ca i connect to htb vpn?

#

Options error: In [CMD-LINE]:1: Error opening configuration file: lab_lob0i.ovpn
Use --help for more information

#

it says this

lethal atlas
#

the error indicates you have an invalid option specified in your command.

rapid pine
#

has anybody been able to import powerview into powershell on the AD Enumeration and Attacks skills assessment part 2?

west canopy
#

@rapid pine i checked my notes and i used PowerView on part1 and not part2... but we should be able to just move over the .ps1 file and then import-module

rapid pine
agile meteor
#

hey guys can yall help resolve this "could not resolve host: github.com" its in kali btw

slow ruin
#

Need a nudge on Attacking Common Services - Easy. Still looking for any type of creds, tried brute forcing ftp and rdp with no luck

tight mesa
#

anyone who has competed SQLMAP module, to ask some..!!!

vital adder
tight mesa
#

I'm not able to read the content of a table "flag3" but @lethal atlas gave me a hint, thanks in advanced

vital adder
tight mesa
#

yep, I tried --cookie

vital adder
#

and the ||TESTPARAMETER (-p)||

tight mesa
#

no, i didn't use this argument

#

I'm give it a try

#

thank you

vital adder
#

@tight mesa if you still have some issue with that feel free to dm me

tight mesa
#

course, ty @vital adder

pine cargo
lethal atlas
#

although you can do it without -t flag3

drifting knoll
#

pls be careful with spoilers @karmic vigil

pine cargo
#

How is ffuf not able to find these files while gobuster is?

#

Is there a ffuf option that I'm missing, or is there something that gobuster does in the background that ffuf doesn't?

devout cliff
# pine cargo

pipe it through a proxy and compare the requests to see

unreal patio
#

I'm currently using mssqlclient in docker to access a database from the academy but I can't use any of the mysql commands like "show"

#

Could not find stored procedure 'SHOW'.

obtuse oak
#

I want you to guess Sony's hands. I have a special hand, meaning a small nickname

unreal patio
#

I ended up solving the exercise but not the way I hope was intended

storm lagoon
#

Hi gus, one question , i have a problem with the section "Network enumeration with nmap" in the module Firewall and IDS/IPS Evasion - Easy Lab
Our client wants to know if we can identify which operating system their provided machine is running on. Submit the OS name as the answer.
i run the command sudo nmap 10.129.140.142 -T2 -p10001 -A, and it detects the OS in linux, but it is not the answer, someone solved that section

wheat garden
#

could use nudge on the footprinting lab-easy. Have found ssh keys and downloaded them to my attack machine. Though when I try to connect to the target using ssh p 22 command- ssh -i ./id_rsa ceil@<target i.p> keeps saying Connection closed by <target i.P> port 22. I did modify the permissions too for the private key file to chmod 600.

west canopy
#

@storm lagoon it wants something a little more specific. Which distribution of linux specifically?

#

@wheat garden your path is correct, we should be able to ssh in as ceil. Maybe try to restart the target?

wheat garden
west canopy
#

yes

#

i am testing it right now and its hanging for me too

wheat garden
west canopy
#

maybe try from pwnbox?

slow ruin
#

Need a nudge on Attacking Common Services - Easy Lab found the username and password and I know the exploit. However, my exploit is not returning any output. Anyone available to help me out?

wheat garden
storm lagoon
west canopy
#

@slow ruin DM me 🙂

storm lagoon
west canopy
#

you're welcome 🙂

#

@wheat garden just tested and i can ssh as ceil from pwnbox but not my kali vm

wheat garden
unreal patio
#

Am I supposed to bruteforce the password of the local Administrator in Footprinting Lab - Medium?

#

I have gotten the rdp u/p and logged in but I'm stuck there

west canopy
#

@unreal patio did you find ||the credentials for the sa user?||

unreal patio
#

Not yet

#

I couldnt find acces to the smtp server

west canopy
#

what about ||smb?||

unreal patio
#

Guess I have to try that

#

important.txt retrieved

#

Thanks

mossy epoch
#

hi, in module "Using the Metasploit Framework: Sessions & Jobs" in the question about "old sudo" i don't find the "relevant" exploit maybe why i dont privileges. Can anyone give me a hint where togo from here? thx

placid quest
#

@mossy epoch which exploit did you use

mossy epoch
trail pendant
#

Is anyone able to give a little hint "AD Enumeration & Attacks - Skills Assessment Part II" - flag for admin on MS01. I got "DefaultPassword" from the SQL01 and have tried running it by my users list - no success. I tried cracking all the hashes I can get near with no luck. Anyone before I might give up.. :/

clear bough
trail pendant
clear bough
trail pendant
clear bough
#

i found the Administrator hash on SQL01 and test it with crackmapexec for winrm session on MS01 and it work

obsidian sonnet
#

Hi!
I am stuck for a few days now, and I’m don’t know what I’m doing wrong.
The question is:
Enumerate the target and find a vHost that contains flag No. 2. Submit the flag value as your answer (in the format HTB{DATA}).

When I’m doing FFUF on it, and want to go to for example blog.inlanefreight.htb than everything is the same webpage. The webpage from the Ubuntu Apache page.
When i go to HTTP://inlanefreight.htb 1 than I got a flag 1 and that is OK.

I added the findings from FFUF to /etc/hosts/ with the given target-ip.

Can anyone tell me what I’m doing wrong, please?

trail pendant
feral stump
#

Hi! Anyone can help on the last machine of the getting started module?

I got footprint already and trying now to gain privilege escalation to root but stuck a bit

#

Thanks!

placid quest
#

@feral stump did you use like sudo -l to see what happens

feral stump
#

Yup

rustic sage
#

Hello

#

i need hlp

#

help*

#

ATTACKING ENTERPRISE NETWORKS

#

Web Enumeration & Exploitation

shrewd bolt
#

did you add the ip address to your /etc/hosts?

clear bough
#

hi , i'm stucked at "AD Enumeration & Attacks - Skills Assessment Part II" on the question "Obtain credentials for a user who has GenericAll rights over the Domain Admins group. What this user's account name?" .... i've try all method but i can't obtain this credential ... can anyone help me please??

clear bough
#

solved

sage yew
#

Hey guys, Im stuck on attacking common services - SQL. I have tried using the commands and looking around for several hours, but im stuck tbh. Is there someone who can help?

stiff moon
#

hi in Pivoting, Tunneling, and Port Forwarding module i have a problem with chisel i uploaded it tried to run it and with sudo but it give this error "./chisel: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.32' not found (required by ./chisel)"

#

solved it thanks bros ❤️

final frigate
#

Hi, I'm with the cracking passwords with hashcat module and hashcat always reply that my command is a illegal hardware instruction, I just copy the commands from the module so I don't understand what I'm missing

polar widget
#

Damn

limpid crane
#

anyone got a hint for finding CT059 credentials in AD Enumeration and Attacks Skills assessment Part 2 ?

west canopy
#

@limpid crane try using ||inveigh|| 🙂

#

@final frigate maybe try it from the pwnbox?

raven cairn
#

I second what Jared says. Try it from pwnbox.

west canopy
#

i get a weird error whenever i try to run hashcat on my Kali 2019 image that i use for testing occassionally

limpid crane
#

@west canopy ths, i try

final frigate
#

I think is some kind of problem with drivers, I tried using hashcat locally and reply that needs some drivers from my cpu

#

But I thought that Kali come with all the necessary drivers

vapid grove
#

Hi, i'm stuck in Password attack - credential hunting in Linux, i've tried bruteforcing with the provided resource, not working for will / kira

west canopy
#

@vapid grove try using ||a mutated version of the password provided in the hint. It might already exist if you mutated the original password list :)||

errant lava
#

I'm stuck on Footprinting [NFS chapter] the /etc/exports directory isnt on my machine. I was able to use nmap but I can't use showmount
NVM I had to download nfs-common I guess catHiss

quiet otter
#

Is this place for learning how to use coding or for getting peoples IP cuz I kinda wanna know how to get Ip cuz some kid I know tried to get mine smh and he failed bad

#

So I wanna get his cuz he thinks I can’t

#

Lol

#

If this isn’t a server for that sort of stuff I will leave if the admins or the owner wants me to

lethal atlas
#

This is a place where we discuss academy related stuff. We DO NOT condone hacking without consent. What we learn here we learn for good, not evil.

quiet otter
#

Ok

#

If you think I should leave then that is fine I don’t hold a grudge but do you know any servers that does allow that sort of stuff do you mind letting me know

onyx dust
#

how long does it take to do all the modules?

#

i feel like it's been FOREVER

lethal atlas
#

Now that being said, if you want to learn skills that will help you get a career in cybersecurity, this IS the place

vapid grove
quiet otter
#

No I’m all good @lethal atlas

onyx dust
#

those of you with these meters full, how long did it take you?

quiet otter
#

Thanks for letting me know

#

I’ll be on my way now

#

Appreciate the info

lethal atlas
onyx dust
#

ty that's what i'm looking for

lethal atlas
#

It depends on how much time you can dedicate to it.

onyx dust
#

i try to do some every day and even at that for a couple months

lethal atlas
#

some days I can spend most of my day working on modules, the last month I have barely had time to touch it

#

I have completed the bug bounty path though. I need to tighten up my SSTI and XSS skills before I attempt the exam.

onyx dust
#

did u get the exam

lethal atlas
#

I havent paid for it yet but plan to.

onyx dust
#

i wonder if it's hard

lethal atlas
#

I know a couple of guys who have attempted it. Only one that passed.

#

I hear its challenging which is why I want to beef up my weak spots before I attempt it

raven cairn
#

I’ve been working on modules ~4 months and I would say I am 75% done from completing every module.

#

Pat yourself on the back. Some of the modules are BRUTAL. They can take some time.

#

Worry more about learning than speed.

west canopy
#

i dont get how the meters work

raven cairn
#

Also this is my best advice for Academy

raven cairn
west canopy
#

they really don't

lethal atlas
raven cairn
#

Could I get an honest answer. If I completed the BB/Pentest exam do you think employers would find that impressive??

#

Don’t want to ask staff cuz they might give a biased answer Lol

#

I want to get an IT job.

lethal atlas
#

I guess that depends on the job and employer. I work in IT for a college now but we don't handle anything like this. We farm all our testing to a 3rd party.

acoustic owl
vapid grove
#

thats why I think it's not a good idea to rush modules, instead go slow and learn as much as possible

west canopy
floral zodiac
#

Going through the Web Proxies module using Burp exclusively but now I'm trying to go back and use ZAP. I'm using the pwnbox but can't seem to turn intercept on in the HUD mode. I click it but nothing happens. I'm sure I'm missing something simple but am a bit sleep deprived 🤣

hardy anchor
#

Hey guys i have a problem finding the TXT in Information Gathering - Web Edition

#

I was able to find subdomains but i think i'm using the wrong query

#

Omg i just find the flag

#

It doesn't work lol

final frigate
hardy anchor
# hardy anchor It doesn't work lol

This is my query and the output but the flag doesn´t work

||`nslookup -type=TXT inlanefreight.com
;; Got SERVFAIL reply from 200.115.192.28, trying next server
;; Got SERVFAIL reply from 190.55.60.130, trying next server
Server: 181.47.248.145
Address: 181.47.248.145#53

Non-authoritative answer:
inlanefreight.com text = "HTB{XXXXXX}"`||

acoustic owl
hardy anchor
acoustic owl
hardy anchor
acoustic owl
#

You must specify the target machine as the DNS server.

|| dig TXT domain.tld @rustic sageIP ||

hardy anchor
#

My domain.tld is this:
curl -s https://sonar.omnisint.io/tlds/inlanefreight.htb
Output:
["inlanefreight.com"] right?

So if i do dig TXT inlanefreight.com 10.129.155.149

The output show spoiler ||300 IN TXT "HTB{5Fz6UPNUFFzqjdg0AzXyxCjMZ}"||

oblique gorge
#

if that flag doesn't work I would check if that's encoded

acoustic owl
wheat garden
#

done like 18 modules so far

acoustic owl
# wheat garden ive only been doing the academy modules for about 2 months now. and it already s...

🚨 500K #HTBAcademy members 🚨
Half a million aspiring #hackers have already started their #cybersecurity journey!
Modules for all skill levels, 2 job role paths, and a certification are waiting for you 👇
https://t.co/PS7OKA4szU

Likes

104

#

But how the ranking is created, I do not know. Number of modules? Number of sections? Number of answered questions?

echo zenith
#

Hello, I am in the File Transfers module and in the first question it asks me to download the flag.txt file with wget and to put the content. I download it but I do a cat flag.txt to read the content and I get a series of numbers and letters, I paste it in the response and it doesn't give it to me as valid. What is it that escapes me?

acoustic owl
echo zenith
raven cairn
#

The bug bounty path is like 20 modules I think?

raven cairn
wheat garden
acoustic owl
acoustic owl
fossil crescent
#

Depending on what type of job you're applying for, I genuinely question if CEH and/or CompTIA certs will help. Certainly DoD/contract jobs, where it's a checkbox requirement, yes, but aside from that, while many job postings may have CySA or CEH listed, it seems like a massive disconnect from HR to actual hiring manager. Yes, if going for say help desk, no doubt having A+ will help... And having the KNOWLEDGE will certainly help, but at $300+/cert (CompTIA), seemingly many better returns on investment. Even worse for CEH.
Edit: In full disclosure I have a # of CompTIA certs and CEH... live-and-learn.

radiant kettle
#

is there a recommended course guide for newbies?

raven cairn
quiet prism
#

quick question

#

i'm on the hashcat module skills assessment final question

#

says what's the most common password

#

how would i find the most common one?

#

looks like i've cracked the list

vital bough
#

Anyone help me on the Command Injection skills assesment, I have the injection point but something isn't working....

wind plaza
#

then crack the most common hash

quiet prism
#

i've got a list of cracked hashes anyway

#

nvm it's exhausted not cracked

wind plaza
quiet prism
#

the exhausted result suggests i need something else not a straight brute force wordlist

raven cairn
vital bough
radiant kettle
quiet prism
#

nvm got it lol

cobalt sky
#

has anyone run into an issue with starting point responder where you put in the site after starting responder to get the hash and it prompts you for a username and password? this wasn't in the walkthrough and its very confusing lol

tender shadow
#

Anyone help me find the flag in task 1 skill assessment Intro to Assambly language.

#

I stucked 2 weeks

shrewd bolt
#

Hello, I'm doing the Getting started module, page 23 Knowledge Check: I managed to exploit the machine and get a meterpreter shell, I also uploaded LinEnum.sh to the machine but I'm not able to run it because i don't have the right permissions. If you have any tips please feel free to DM me. Thanks

quiet prism
#

is there a good bash tutorial i should check? doing the bash scripting module and only have javascript and python experience so stuck at the first hurdle

shrewd bolt
rustic sage
#

Hi i'm doing the Password Attack module and i'm stucked in the password mutations section. I can't find the right creds even though i've created the mutated wordlist. this wordlist is 94000 passwords long and it would take 16 hours to complete the brute forcing attack through hydra. Any hints?

pine dagger
rustic sage
#

do i always try with hydra?

pine dagger
pine dagger
# rustic sage do i always try with hydra?

Yeah, but for some of the labs, you can use Hydra to scan with FTP rather than SSH, because SSH is slower. Sometimes the creds for FTP and SSH are the same. If you nmap the target, you can see if it has FTP open. 😉

raven cairn
rustic sage
pine dagger
rustic sage
pine dagger
vital adder
pine dagger
vital adder
shrewd bolt
#

im also top 1% but i dont feel like i've done nearly enough to be in the top 1%

#

lol

fossil crescent
# shrewd bolt im also top 1% but i dont feel like i've done nearly enough to be in the top 1%

Figure for every person that signs up for academy, some large percentage sign up but don't complete ANYTHING (because free to sign up)... From there, another large percentage may only do a module or 2, and another large percentage only do the truly free modules. So you quickly dwindle down to small percentage of folks doing a measurable amount of content... Just shows you are committed far more than most

shrewd bolt
#

yeah that makes sense

rustic sage
mortal charm
#

Hey all good morning from midwestern USA.

I have recently begun the HTB Academy: Web Requests and I notice that the Cheatsheet and Hint options do not work. When I click, the page size changes, however, no window for either pops up. I do have pop up blocker allowing HTB academy through. I have reloaded, closed out - reopened, etc. No avail. Is this normal?

pine dagger
pine dagger
vital adder
pine dagger
#

Ohhhhh

rustic sage
#

try using the files in the resources on the top-right part of the module

rustic sage
rancid holly
#

just saw that,came back to delete the text 😅
thank you

pine dagger
rustic sage
rustic sage
pine dagger
#

I have just tested with the same command and it cracked it in less than 5 minutes.

rustic sage
#

please can you sand me the command?

sage jackal
#

Pivoting, Tunneling and Port Forwarding Module - Skills Assessment Section; I got into the Windows host through the pivot Ubuntu server and I tried to Meterpreter Tunneling and port forwarding to be able to route nmap through windows internal network to enumerate but I dont get the connection back through multi/handler. Also I don’t get how to use the user vfrank. Any help/hint?

rustic sage
rustic sage
pine dagger
raven cairn
#

Really confused how they calculate that now LOL

pine dagger
#

Probably most people join and do the tier 0 stuff, or do a module or two for things they are really interested in

#

And then there's crazy people like me who are working through every module to see if there's anything I can learn 🤣

raven cairn
#

I think it is probably just sampling bias.

pine dagger
#

I'm hoping to finish all the modules by October, and then I'll go nuts on cracking boxes ^^

vapid grove
#

Hi, can i get a nudge on password attacks - lab hard ? I can't find anything on services 😦

rustic sage
#

Hi

vital adder
raven cairn
pine dagger
#

Sure, although I think you're a bit ahead of me. I'm currently finishing "Password Attacks" and "Shells & Payloads". But only time I get to work on them is during the weekend. 😦

rancid holly
pine dagger
rancid holly
#

not exactly a question, In password attacks Network services I got all the correct user and password, the deal is with SMB the user doesn't have read access so I am not sure how can I proceed with that as it says "NT_STATUS_ACCESS_DENIED"
and for rdp, the connection establishing using xfreerdp fails

quaint marsh
#

How do you request flag information? dig txt XXX.inlanefreight.htb @ip-addres?

pine dagger
quaint marsh
#

😁

vital adder
#

oh that one

#

@quaint marsh use the ||custom DNS server (-r)|| you are run gobuster

quaint marsh
vital adder
quaint marsh
grave dust
pine dagger
alpine vault
#

Hi All working on the Active Subdomain Enumeration lab under Information Gathering - Web Edition, I understand how to start a zone transfer but I am lost as to how to identify "zones". "identify how many zones exist on the nameserver" is one of the questions, and I guessed it right ||"2"||, but I have no idea why that is correct. Any help would be greatly appreciated.

pine dagger
frozen lark
#

why can't I connect? Did I miss something?

grave dust
acoustic owl
tulip plinth
#

Hi all, someone who finished the API skill assessment can help me out? I am sending the request and receiving an error, I fixed the error but I keep receiving the same message.

frozen lark
grave dust
#

On attacking common services, i can't bruteforce the smtp or pop3 server and can't exec any command, get the error 503: Bad sequence of commands do I need to authenticate ? If so do I need to use GUI tool like thunderbird ?

frozen lark
grave dust
frozen lark
#

wait what?

grave dust
#

ur tun0 isn't up

frozen lark
#

but I imported the academy.ovpn file and turned the button to "on"

#

what's tun0 if I may ask? I thought its just a different name for a internet access point

grave dust
#

u can use the command line : sudo openvpn urFile.ovpn

grave dust
frozen lark
#

do I need to mention the path aswell?

acoustic owl
frozen lark
#

what did I do wrong this time?

#

aah /home

#

sorry for my stupidity :D

grave dust
frozen lark
#

thank you guys for helping!

acoustic owl
grave dust
frozen lark
#

what's the matter this time?

grave dust
frozen lark
grave dust
acoustic owl
# grave dust yup

However, with this you should be able to bruteforce the access. Which list did you use?

grave dust
grave dust
frozen lark
#

like this?

grave dust
#

with rockyou i think it block the port bcs i get

grave dust
acoustic owl
frozen lark
#

not again

grave dust
frozen lark
#

allright

alpine vault
#

Hi all, Trying to identify other zones on the DNS server. need a nudge

frozen lark
#

do I need to redownload the .ovpn every time I want to connect to htb or do I only need to do that once?

frozen lark
#

okay, thanks!

rustic sage
autumn pilot
#

no need to download the vpn file every time

frozen lark
#

why do they even require connecting via vpn to access them?

grave dust
autumn pilot
#

as you might already know, some of the targets can either be reached through the VPN or without one

grave dust
autumn pilot
#

the button in the exercises is put for convenience

frozen lark
flint minnow
#

has anyone here been charged double the cubes for a module before? i.e. module is 20 cubes and you got hit with 40. Tried looking in FAQ but nothing there regarding this.

grave dust
#

not yet XD

languid dawn
#

open a ticket I guess?

flint minnow
#

bummer, gunna reach out to support then, thanks!

frozen lark
#

welp, it seems neither the cli nor the gui openvpn clients work, ill resort to google

grave dust
alpine vault
acoustic owl
alpine vault
#

i looked at the syntax on their forum but the example works

acoustic owl
alpine vault
#

even if its in hosts.txt? tried it anyway didnt work

#

if anyone has any ideas my DMs are open

acoustic owl
alpine vault
woven copper
#

if you look at the CheatSheets on the Footprinting Module , you will see that the share a command line for dnsenum ' dnsenum --dnsserver <nameserver> --enum -p 0 -s 0 -o found_subdomains.txt -f ~/subdomains.list <domain.tld>' , change namerserver, domain.tld and subdomains.list

alpine vault
#

whoops mistyped, its working.... kinda, doesnt give me any info on zones that I am looking for

#

also doesnt enumerate nearly as much as dig or nslookup has been

dry tundra
#

I have a question about a HackTheBox Academy module. For the "Introduction to Bash Scripting" module under Comparison Operators, I got the following answer: U2paTlJYTkxDZz09Cg==

Here is the following code that I used:


var="8dm7KsjU28B7v621Jls"
value="ERmFRMVZ0U2paTlJYTkxDZz09Cg"

for i in {1..40}
do

    var=$(echo $var | base64)
    length=$(echo $var | wc -c)
   
    if [[ "$var" == *"$value"* ]] && [[ $length -gt 113469 ]]
    then
echo ${var: -20}
       
    fi
   
done

I feel like this is the right answer, but for some reason, I am getting it marked as incorrect. Can anybody explain why?

sage yew
#

Hey guys
When attacking common services - DNS
-How long should I expect subbrute to take? 🙂

rustic sage
#

Hi I’m stuck at in the FOOTPRINTING module DNS... anyone can help me?

#

What is the FQDN of the host where the last octet ends with “x.x.x.203”?

vital adder
sage yew
vital adder
sage yew
shut owl
#

Could I get a nudge on the XSS Skills Assessment please?

lethal atlas
lethal atlas
lethal atlas
#

Question for all those who have completed the XSS module. I am going back thru and in the Phishing section I have never been able to get the code to clean up the page the way they say in the section. Even using the code they provide does not work. Has anyone been able to make the page ONLY show the username and password login boxes?

west canopy
#

I don't think i was able to. I recall the page looking all messed up

lethal atlas
#

yeah, I remember you and I talking about that when I first completed this

grave dust
#

is there someone for "Attacking common protocols" "Easy" i think i'm near the end but there is a little thing not working
EDIT: Finished Thx @west canopy

west canopy
#

@grave dust i might be able to help , feel free to DM me 🙂

acoustic owl
bitter dawn
#

I was doing the windows box but i can't use xfreerdp, i've also installed it with aptitude but still nohing

pearl island
#

I can't ping any of my target machines in HTB academy. My internet and VPN are both connected. I can't ping the target machine from the pwn box too!

#

Is there a problem with Academy machines?

pine vale
#

The target machine can only connect to either your pc or the pwn box iirc. close pwn box and reset target and connect will probably work

#

or only the pwn box and not vpn ofcourse

pearl island
#

Tried both. Couldn't connect through pwn box, then tried from my PC. No luck there too!

pearl island
pine vale
#

Maybe restarting pc? if you didnt already

pearl island
#

Let me try that too!

grizzled cobalt
#

Getting Started: Privilege Escalation

I can successfully ssh into the target system and I can see the first flag. I can also move laterally into user2's account. Also I can access root's id_rsa file and see the key within it, copy that key, and move it to user2's files. Where this one breaks down for me is in trying to use root's key to ssh into the system as user2. It times out every time I try.

#

Not sure what I'm doing wrong here. Any help would be appreciated.

trail wren
#

Hi all 👋 just joined and looking forward to discussing some of these modules with everyone 😄

west canopy
grizzled cobalt
#

I've tried that too, and it still times out on me

#

Does it matter where I execute the ssh command? Like, do I need to be in an entirely new window?

haughty furnace
#

can anyone help me make a virus using node.js

wheat garden
grizzled cobalt
#

The id_rsa file containing root's key doesn't exist on pwnbox

wheat garden
grizzled cobalt
#

I swear, I am constantly overthinking this stuff 🤦‍♂️

#

Let's hope that works.

#

That timed out as well

west canopy
#

are you specifying the port when SSHing?

urban sage
grizzled cobalt
west canopy
#

np nice work 🙂

wheat garden
unreal patio
#

I'm supposed to identify two zones from this

#

I only see inlanefreight and root.inlanefreight under SOA

#

But I'm missing a zone to query for the TXT record

#

Can someone give me a pointer?

west canopy
#

@unreal patio try doing a zone transfer against one of the subdomains you found

unreal patio
#

one or all?

west canopy
#

test them all until you get a zone transfer 🙂

unreal patio
#

Sigh

#

Thanks, solved it

modest token
#

Did you solve this? I have the same issue.

#

I'm stuck on USING THE METASPLOIT FRAMEWORK - Meterpreter. I'm supposed to Retrieve the NTLM password hash for the "htb-student" user, but even though I'm system user when I run the hashdump command in meterpreter I get this error: "[-] priv_passwd_get_sam_hashes: Operation failed: The parameter is incorrect." I've tried changing to just about every other running process and I still can't get it to work. Any ideas?

west canopy
#

@modest token yes hashdump does not work , i ended up ||using mimikatz :)||

modest token
vale salmon
#

I was wondering if anyone could give me a nudge on the Skills Assessment portion of the JavaScript Deobfuscation module. I'm stuck on the next to last question. Nvm. Figured it out.

radiant dagger
#

For windows privilege escalation DnsAdmins use multi/script/web_delivery to generate the cmd line for msfvenom to use. Others won't work, at least for me. And try to switch between cmd and ps if got stuck

sage yew
#

Hey guys, i'm doing the attacking common services - mail services
I got the user, but i don't know where to go now. Could someone give me a nudge please 🙂

summer lava
#

Please... to know how to use the FETCH command to read mail... i used it once but forgotten ...

#

IMAPs server

summer lava
#

how to i read that mail

sage yew
#

okay, thanks!

#

Do i need to get a password for the user first?

sage yew
vital adder
sage yew
#

okay, thanks!

fiery fossil
#

What is the name of one of the accessible SMB shares from the authenticated Windows scan? (One word)

grave dust
#

I'm on "Attacking common services" "Hard" adn I don't know why I can't impersonate the user I need to impersonate can I sand someone the command I'm using ?

grave dust
fiery fossil
#

Thanks i will try it

vital adder
bitter dawn
rustic sage
#

HI I'm having problems in the passwords attack module, in the Credential Hunting in Windows part (What is the default password of every newly created Inlanefreight Domain user account?). I've searched for the word password in almost all the pc but i can't find this password. any hints?

pine dagger
#

Can’t give you more specific advice atm as I’m on a train visiting a customer

mossy epoch
vital adder
mossy epoch
vital adder
mossy epoch
#

ok, thx

rustic sage
rustic sage
quiet prism
#

What am I missing? xD

#

Done every other question with no difficulty

#

"Intro to Network Traffic Analysis"

vital adder
quiet prism
final frigate
#

In the Linux Privileges Escalation module, the special permissions section in this question, I have the path to the file but it says that it is incorrect, I have done the next one, which is more or less the same, without errors, can I send the solution to someone to check if the format is correct?

#

Okay nevermind, there are more than one file, but the question only allow one

delicate drum
#

Anyone up to help me with IPS/IDS and firewall evasion using nmap

keen wave
#

Can anyone tell me how to answer the question in “Attacking DNS” question please !? :got it 😍

grave dust
#

just finished Command Injection can i dm someone to see if they got another answer ?

quaint marsh
rustic sage
#

hi I'm in the credential hunting in Linux(Password attacks) and I tried every wordlist possible to bruteforce the pw for Kira. I even made mutated passwords from LoveYou1 which is the password hint. can you tell me if i'm doing something wrong. Any hints?

slow ruin
rustic sage
#

i have the same problem can i dm you?

distant stream
night pier
#

ls

undone cypress
#

Hi guys!

Stuck on the 2-nd question of the task - *Predictable Reset Token *from the module - Broken Authentication
Tell me, please, what are my next steps, after I understood the coding algorithm for htbuser.
How to change the password for htbadmin if the token is sent to him by mail?)
I will be grateful for any hint.
Thanks.

quaint marsh
#

on the way to access the mail and perhaps find a hint there?

vital adder
remote holly
#

HI

errant moss
#

Hi!

I'm working on the skill check for the "Web Service & API Attacks" module. The question says "Please note that the service will respond successfully only after submitting the proper SQLi payload, otherwise it will hang or throw an error.". I'm submitting a login request with "admin:admin" for credentials just to have something to work with and I get no response from the server. Indeed it looks like it hung. But what's the point of that? How am I supposed to work out a wokring SQLi payload if I have to have one in order for the server not to hang? A server that hangs on login requests unless they're exploiting SQLi vulnerabilities... that's so broken... how's this realistic? I'm guessing that I'm supposed to work it out in another fashion but I'm still very confused by this setup. Can anyone clarify why this lab is set up this way?

oblique shale
#

What is a more realistic output to that input you would expect

errant moss
#

A failed login would result in a 403 and/or a message saying something like "invalid credentials" I'd expect, don't you agree?

oblique shale
#

If the login request has a back end to authenticate against sure

errant moss
#

You're saying it doesn't?

oblique shale
#

I am agreeing but that is not really the point of the learning module

errant moss
#

But there has to be a back-end receiving the login request in order for it to be vulnerable to SQLi?

#

Would I be right to assume that I'm supposed to exploit another flaw, figure out the SQL expression and craft the sought after SQLi payload that way you think?

oblique shale
#

Yes that more commonly would happen, I guess I am probably missing what is the point of you just logging in?

errant moss
#

My idea was to just get a login attempt working and then start doing SQLi tests for the username and password in order to (hopefully) find the SLQi vulnerability.

oblique shale
#

I mean imagine it is a company admin portal, unless you are a blue team how would you have those creds?

knotty summit
#

what is the root flag

#

submit

errant moss
#

No, the creds don't have to be valid, could be anything, "test:test", "admin:admin". If the function then turns out to be vulnerable to SQLi the validity of the creds typically wouldn't matter.

lethal atlas
errant moss
#

You mean command execution?

lethal atlas
#

yes

errant moss
#

I was just about to go work on that. Feeling even more motivated now that you said that 😉

lethal atlas
#

and be prepared to enumerate like noones business

errant moss
#

Awesome! Thanks for the input both of you!
I take it then as the author of the module wants you to work on more than just SQLi then.

oblique shale
#

Remember the point of modules is to teach that 10% -30%

#

Doing the practical is where the 50% of your learning comes from

errant moss
#

Yeah, I guess it would be a bit too easy if it was just a SQLi and done. Thanks for your input, much appreciated!

lethal atlas
#

how do I black out stuff? I forgot lol

#

I hate how long it takes to crack passwords on Password attacks. My target times out before hydra can even make it a fraction of the way thru a list.

pine dagger
lethal atlas
#

yes!!

pine dagger
#

Drop the first 17000 results from the mutated list and try

lethal atlas
#

right on.. I have been deleting the ones I have gone thru and starting over after a time out.

lethal atlas
pine dagger
#

🙂

#

I do think the time to complete the password attack module is WAY WAY WAY off

broken warren
#

Can someone help me with the payload for intro to server side attacks, SSTI Exploitation #2 they give an example of using a tornado a payload with a whoami command, but they don't actually show the user. And when I try the same payload with different command (like ls or cat flag.txt) I get the same result as the example but nothing else.

pine dagger
#

Yay! Finished password attacks. That hard lab was actually fun 😄

pine dagger
#

Thanks 🙂

hallow otter
#

I really need to go to sleep now but can someone help me with the Documentation & Reporting practice lab? This was supposed to be an easy lab!
I cannot find any path on how to do things or what I am supposed to do. On top of everything, hashcat always complains with "separator unmatched" when passing the tickets as per section "Components of a Report". I was able to find a certain lab user but I am stuck there since I cannot crack the hash due to the previous error. Uploading a command shell to tomcat lead me to nothing, even if I can execute some commands

errant moss
hallow otter
quaint cargo
#

Has anyone used CertReq.exe as a way to upload and catch with nc like in the Living on the Land lesson? I get the error that -Post is not a valid argument the the LOLBAS syntax
"CertReq.exe -Post -config"

west canopy
#

is that like certutil.exe?

quaint cargo
west canopy
#

interesting , I just tried running it now from windows command line

#

i have never seen this before

quaint cargo
#

Give you an error?
0x80070057

west canopy
#

opens a file explorer type window where i can select a file

quaint cargo
slow ruin
#

Need a nudge on Attacking Common Services - Hard lab. Know about the ||linked server|| but not sure if I am understanding how to send commands to it. Getting a Login failed error

Figured out the login issue

quiet prism
#

working on the analysing network traffic module and couldn't handle the command line readout of a capture file so jumped ahead to wireshark before actually starting the wireshark section xD

#

all that info in a command line without any organising is rough on the eyes

#

Tcpdump sux (joking)

tender meadow
#

looking for a lil advice. iv been using kali linux to do soem of the modules. some of the commands arnt working the same as they would in the workstation.

#

eg ssh dosnt let me log in remotly.

west canopy
#

ssh doesn't work on your vm? Is your vpn connected?

tender meadow
tender meadow
tender meadow
#

tried reconecting but it timed out. respawned isntence but getting the same issue.

quiet prism
#

on the wireshark module it gives me a target IP, do i have to connect to that nomachine still like the walkthrough lab does?

west canopy
#

i was able to finish the module just using the pcaps in the resources section at the top

west canopy
#

first question ||is exporting http objects from a pcap.||
second question ||ssh into the box and look for users in /home directory.||

quiet prism
#

yeah i get the first question, but where is the pcap?

west canopy
#

resources

quiet prism
#

oh is it that same wireshark-lab-2.zip?

west canopy
#

yep

quiet prism
#

ahhhh easy peasy then

#

ty

west canopy
#

np

quiet prism
west canopy
#

where are you seeing flag.jpeg?

quiet prism
#

there's three users. i'm assuming the image is the clue but i don't know how to view images through ssh as it's text

west canopy
#

ah i dont even remember that

quiet prism
#

there's three users

#

each of them has a flag.jpeg

west canopy
#

i just guessed 🙂

quiet prism
#

(me too but i was curious about the 'real' answer haha)

west canopy
#

could move the flag to your own machine and then view it

#

or could try running strings on it

quiet prism
west canopy
#

can u start a python web server?

keen wave
west canopy
#

could use netcat too

#

to transfer files

quiet prism
heady igloo
#

Hey is anyone here in local file inclusion or has done it?

quiet prism
west canopy
#

i couldnt solve it by sniffing packets 😦

quiet prism
#

kind of detracts from the focus of the module when you have to fiddle with other stuff, but whatever

quiet prism
#

yeah i just blazed through it with the included pcap file. They should say "HEY if you don't want to go through the hassle of a VM inside of a VM, here's the pcap file you need"

plain coral
#

Has anyone completed the OSINT: Corporate Recon - Business Records section? I feel as if I have the correct answer, but it's not allowing me to submit the flag.

west canopy
#

@plain coral i might be able to help

plain coral
polar widget
rustic sage
#

How do you find the root hash if there is no permission over the etc/shadow file?

languid dawn
#

if you're root you can read the file

#

or, root can read it for you

rustic sage
#

Yes but i’m a user

rustic sage
rustic sage
languid dawn
#

you might be able to get root to read the file for you without being root yourself is what I meant

rustic sage
sage yew
#

Hey guys
Im stuck on attacking common services - easy. I have a user on the system, but i dont know what to do now. I have tried different things. Please help 🙂

thin crypt
#

Oi

#

How to get htb role??

languid dawn
grave dust
quiet prism
#

Anyone help me out pre-configuring my browser for use with ZAP? having issues

pine dagger
solar zodiac
#

hi everyone :)

#

is htb academy releasing any new modules/

#

I tried to look on the website, but nothing was listed under upcoming modules

#

was looking forward to the pillaging and lateral movement modules

quiet prism
#

but i've got chrome

#

i'm a in a kali linux VM

hallow otter
#

I think by default it requires firefox

quiet prism
rustic sage
#

I need to talk to a real pentester about Active Directory.
First off, I have only little issue when reading stuffs like Networking concepts, security. Watching & taking notes for hours long YT videos on things like reconnaissance, web app pentest, & etc. However, I began to question myself in my pursuit of being a pentester.
Its the active directory. Almost all I saw in the beginner stuffs seem to be completely pointless. They are not hacking at all.
The fundamental to Active Directory module I attempted was so boring. It is nothing more than a dictionary, history lesson, and a manual book.
This can't be what people interested in hacking. I have no problem in being a nerd, hence why I can learn IT. But..... the active directory. HackTheBox. Where are they. When in the world will I ever create more than 1 active directory.