#modules

1 messages · Page 5 of 1

lethal atlas
#

DM me

#

DM me

grave dust
#

on password attack module, hard assessment can someone tells me why i can't use the password i found to connect as d*** ? bcs i can't use smb server to upload a file on my kali

pseudo kiln
#

Hey Jinn,
I've found the exploit in the end. Just thought it would show up with automated tools. But it did not.

boreal vine
#

I have some questions about the "ACL Enumeration" part of Active Directory Enumeration & Attacks, if anyone can help me ?

onyx eagle
#

hey guys

#

new here

grave dust
#

i just finished the brute force on "password attack" module, "Network Services" section. and no valid combination was found, i used :
crackmapexec winrm 10.129.212.194 -u username.list -p password.list

glass pecan
#

hey, any one doing footprinting lab hard?

#

i got an issue using tom credentials

#

i cant login using "a authenticate plain"

#

and then the hash

#

from telnet

woeful oxide
#

Hey guys, currently on File Upload Attacks - Blacklist Filters, the issue I'm having is that after finding the correct extension I'm not able to run the bashphp.ext file

sacred lance
#

oof

lethal atlas
lethal atlas
vital adder
raven grove
#

Enmm, I just scanned the entry network segment 10.10.110.0/24, why are ports 25 and 110NotLikeThis

cosmic helm
#

why or what

#

port 25 is going to be an SMTP, so mail service

#

then 110 - Post Office Protocol

#

also, googling helps

#

😄

raven grove
#

I see. It could be NMAP-PN

#

fuck me

compact compass
#

anyone know whats up with the Responder machine in tier 0?

#

when running evil-winrm theres a certificate failure...?

raven grove
#

No, just port 25, port 100

raven grove
compact compass
#

@raven grove I dont understand your Q. mind elaborating?

raven grove
#

sudo nmap -sS -A -sC -sV -Pn --open -p 1-65535 --min-rate 5000 -iL ip.txt -oX love.xml

#

then 25/tcp,110/tcp .............blabla

cosmic helm
#

what os

compact compass
#

the OpenSSL issue has been an issue? I'm running Kalio

#

Kali*

cosmic helm
#

ya

#

do a full upgrade

compact compass
#

"sudo apt update" ?

cosmic helm
#

that

compact compass
#

@cosmic helm -- im currently running a full update. i appreciate your help pal 🤞

cosmic helm
#

np

#

hopefully it solves it

eager flame
#

dont u guys feel that all these hacking tools are useless, in real cyber attack none of them are actually being used and this is just a companies marketing trend to sell there stupid softwares ?

west canopy
#

which tool specifically?

grave dust
finite gorge
#

I need some help because I managed to successfully login to the admin page but I can't see the flag value it is asking for

#

Feel free to DM me

radiant dagger
#

I heard some people don't bother to use kali or parrot. They built their own linux. In the end, it's up to people to decide what to learn, what to do and what hacker they might want to be.

feral stump
#

Trying to understand… what boxes/tools for example? I might get your point but there are a lot of open source resources used in general

radiant dagger
#

OSCP for example

feral stump
radiant dagger
#

literally wasting time on their exercises for 10 bonus points.

feral stump
dense ferry
feral stump
summer lava
vital adder
glass pecan
snow pond
#

Hey guys I am doing skill assesment of linux local privesc. And I got till the last part but I am not able to perform the gtfobin sudo exploit bcoz. the command isn't creating a page like less command.

#

I am thinking it might be bcoz of the shell?? Can someone help?

glass pecan
# snow pond

dont you have to add a | and then spawn a shell ?

#

like bash

snow pond
glass pecan
snow pond
glass pecan
snow pond
snow pond
snow pond
glass pecan
#

SUID from those services ?

#

maybe one of them can be use to escalate?

#

not sure just giving ideas 🙂

snow pond
glass pecan
#

maybe you can write the busctl file and add the shell there

glass pecan
#

there should be a space sudo busctl --show-machine | bash

#

are u sure u dont have permissions to write the file ?

#

show me

snow pond
glass pecan
#

XD

snow pond
glass pecan
#

have u tried using the less command as | less

#

to write the file

snow pond
#

I got the problem my shell isn't fully interactive I have to change the shell for commands like less to be effective

glass pecan
#

stty ? i guess

#

not sure then, more than i can handle for now

snow pond
glass pecan
#

oh i see

#

mind if u help me ?

#

got a problem with credentials

snow pond
glass pecan
#

doing the footprinting lab hard

snow pond
glass pecan
#

got this

snow pond
glass pecan
#

am supposed to encode the email and the pass

#

to do a plain authentication on telnet 143

snow pond
#

What pass did u try??

glass pecan
#

everything that i got from the snmpwalk tool

snow pond
#

Did u try sshing using it?

glass pecan
snow pond
#

||NMds732Js2761||

glass pecan
snow pond
#

Any webapp??

snow pond
glass pecan
#

i did but dont work

#

is says that authentication fail

snow pond
glass pecan
#

no wep app

snow pond
glass pecan
#

no port 80

snow pond
glass pecan
snow pond
glass pecan
#

yes

#

they return ok

snow pond
glass pecan
#

this error is what bothers me

glass pecan
#

i use this as reference

snow pond
glass pecan
#

yes

snow pond
#

ohh i see

glass pecan
#

i used port 993 too

#

but dindt work

snow pond
snow pond
glass pecan
#

yes

paper furnace
#

has anyone encountered this problem? the target machine ip address seems weird... and i can't ping to it.

paper furnace
#

yup, i've reset for several times, and it doesn't help.

feral stump
#

Let me dm you

acoustic owl
placid quest
#

@feral stump the ip is not weird

paper furnace
#

I'm in SQL INJECTION FUNDAMENTALS module

#

Oh, I can log into the DB directly, no need to ping it.

candid sandal
#

I've got a question when it comes to DNS enumeration. In this question (from the starting point), I am expected to find a specific subdomain. As there is no DNS server for my host, and that I have added the domain to my hosts file to be resolved, I cannot understand how different fuzzers will operate to test different subdomains as they will not be resolvable

languid dawn
#

If it's subdomain I would suggest using gobuster or something for vhost enumeration

#

As for how it'll work, just add the top domain and ip to your hosts file

#

It's all the same ip anyway as it's the same server

candid sandal
#

alright, i see

#

so am I supposed to be able to reach the subdomains with, let's say curl ?

quaint marsh
#

why after being added to the admin group I still can't read the file?

onyx dust
acoustic owl
fresh wedge
#

Hi need help with information gathering active subdomains enumeration

#

Not finding all the zones and A records

acoustic owl
fresh wedge
#

I’ve done that here I got the internal ones

#

But when I count them and the original ones my answer no right so I’m missing something

rustic sage
#

Who can I pm regarding sqlmap module?

#

About SQLMap + bypass CSRF

rustic sage
#

How can provide me a hint with SQLmap Essential Skill Assesment?

rustic sage
#

I have identified the vulnerable vector ||json|| but I am not able to get a valid SQL payload

woeful oxide
#

Fellow hackers, currently on the File Upload Attacks - Blacklist Filters, been trying to figure out what's the problem wit the file extension, found the ones that are not blacklisted using burp intruder and went ahead to check if this works but my php code doesn't show up

vital adder
rustic sage
tepid fjord
#

guys

#

i got a problem in File inclusion

#

section automated scanning

#

am Fuzzing the parameters and everything

#

but idk where to go next

#

am doing curl for the files shown after fuzzing

#

but nothing appears

vital adder
tepid fjord
#

i got a lot of parameters yes i did

#

one of them is language

#

which is the know for that website

vital adder
vital adder
tepid fjord
#

ofc i did yes

#

wait i will try again

vital adder
tepid fjord
#

this is the command for the parameters

#

is there any wrong with it?

vital adder
tepid fjord
#

hmmmmm let me see

#

am getting the same

#

😓

vital adder
tepid fjord
#

it worked

#

but

#

how

#

am missing some little gaps

cobalt holly
#

hey guys! i have.... i think so far an easy issue but iam really stupid to find the issue. iam connecting via VPN and can find via netstat -nv the IP network ip HTP 10.10.x.x but i cannot connect on http://10.10.10.121/private what do i wrong?

vital adder
# tepid fjord how

basically the request that have size ||2309|| appear too many time and most of it don't work so we can assume that most not all of the request have size is false so just filter it out

tepid fjord
#

it worked

#

i got the parameter

tepid fjord
#

now

#

idk where to go

#

i got the payloads

#

a lot of them, and am using them

#

no output

compact compass
#

has anyone been able to complete the Web Proxies on HTBA?

raven cairn
onyx dust
#

it's all a conspiracy perpetuated by BIG IDA

#

this is all to sell ida licenses

feral stump
#

🤣

naive ravine
compact compass
#

Doest technical support even work on HTBA? it says im using a pop-up blocker but I disabled all plugins and whitelisted in ff

grave dust
#

anyone had this problem on "Shell & payload", skill assessment "host 2" :

grave dust
thick python
#

hey dudes, kinda struggling with a question in the linux fundamentals module. " How many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only):
can curl gather that info or am I missing something basic?

knotty dove
#

have you used nmap? Think that should be able to tell you how many services are on open ports

#

havent done the course though

thick python
#

nmap hasn't been covered but that was gonna be my next move. was trying to stay within scope

knotty dove
#

you could curl every port I suppose?

thick python
#

what would that look like?

knotty dove
#

for i in {1..1000}; do curl <target>:$i | grep -v "Connection refused"; done

#

have you done much bash?

thick python
#

meh, not a ton

knotty dove
#

does the above all make sense I guess

#

not complex but

thick python
#

windows admin turning linux so theres that

knotty dove
#

lol fair

thick python
#

ya, i understand the concept

#

just struggling with syntax

knotty dove
#

fair
if you dont get the right answer by curl I would think to move to nmap

#

Not too much else springs to mind with what you've got 🤔

thick python
#

lol I appreciate it, gotta learn nmap anyways

#

thanks bud!

knotty dove
#

too easy

#

curl -s lol
gets noisy otherwise

modest sleet
#

hi

knotty dove
#

hello

gentle lion
#

@xp you active lad?

vale salmon
#

So I am working on Active Subdomain Enumeration and I am having trouble finding the total number of all "A" records. Anyone got a hint?

knotty dove
#

Did you perform checks on all the subdomains that intially popped up?

vale salmon
#

I tried using ||dig A|| on each one, kinda like with ||dig txt||, but I can't seem to find the right number

west canopy
#

we should be able to just add up all the A records from the ||two ||zones

#

have you done a zone transfer yet?

knotty dove
#

I think some records had A records and others
Did you try counting strict A and also not strict A?

vale salmon
#

@west canopy I did ||dig axfr inlanefreight.htb @ns.inlanefreight.htb|| at the beginning

vale salmon
quasi wave
#

it had been a while since I had worked on HTB Academy's Linux Fundamentals module so I decided to do Linux Journey. Now I've completed Linux Journey and I need help with this one Linux Fundamentals section. Can someone give me a hint? The question is that " How many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only)"

#

what do I do about this

west canopy
#

@vale salmon try doing ||dig axfr inlanefreight.htb @ipaddress (of the spawned target)||

quasi wave
#

hi would it be better for me to just redo Linux Fundamentals path?

west canopy
#

@quasi wave one sec let me check my notes

quasi wave
#

ok thanks @west canopy

west canopy
#

sec ill DM you 🙂

vale salmon
knotty dove
#

ok, its been a minute since I looked at it
are you counting ones that have only A in the record column or the ones that have A and other letters?

vale salmon
#

I was just counting the ones with A

knotty dove
#

did you miss ones that were out of the column?

vale salmon
#

No, I got those too. Problem is I'm only counting ||19|| and that isn't right.

knotty dove
#

definitely missed a few

#

looks like you only queried one of the servers

vale salmon
#

Yeah, I just got it. I came to the same conclusion at the same time. Lol. Thanks!

knotty dove
#

rip too easy

vale salmon
#

Yeah, I actually have a note, in my notes document, in all caps that says STOP OVERTHINKING!

quasi wave
#

I'm having a hard time determining which user is using a given ProFTPd service

#

I used ps aux | grep ProFTPd

#

and I got a result but

#

the user I listed is the wrong answer

#

can someone give me a hint

#

without giving me the answer necessarily

#

I say I ought to be able to make it work with

ps aux | grep ProFTPd
#

what am I leaving out?

west canopy
#

try doing grep -i ProFTPd

#

linux case sensitivity might be messing you up

west canopy
#

@fossil crescent my objectguid is different than yours

fossil crescent
west canopy
#

sec i will DM 🙂

woven copper
#

Please be careful with the spoilers

mighty bone
#

I didnt able to see #general

feral stump
#

@acoustic owl are you around? Can I dm you?

#

Thx

gusty zinc
#

Windows Privilege Escalation
Initial Enumeration
"What service is listening on port 8080 (service name not the executable)?"

I know whats listening, I can see it, I can visit it. I cant get the question to take the answer. What am I doing wrong here?

I've tried|| apache, http, tomcat, apache tomcat, etc ||

rustic sage
#

Can someone help me with the skill assessment of the AD Enumeration & Attack module

acoustic owl
rugged stag
trail spade
#

Hi everyone ! I need help on the module « password attacks » I’m blocked with the question « use the user’s credentials we found in the previous section and find out the credentials for MySQL ».
I tried many things but nothing worked, i don’t know what to do 😬

candid sandal
#

Is there a way to interupt a command when we are running a reverse shell, without ctrl+c (as it breaks everything) ?

rustic sage
#

hey can you tell me how you solved the problem?

kind turret
rustic sage
#

Hello I just started with hackthebox and I am answering the questions on the very first lesson.
It says to submit the root flag but I don't know what that means.
can somebody help me?

rustic sage
#

Who can provide me a nudge for Command Injection?

west canopy
#

@rustic sage I might be able to give you a little nudgey nudge

west canopy
tepid fjord
#

guys wanna ask

#

in file inclusion

#

automated scanning

#

after fuzzing the directories i got this

#

i will show the last two lines

#

||/nologin sshd : x :106:65534::/run/sshd:/usr/sbin/nologin barry : x :1000:1000::/home/barry:/bin/sh||

#

so as we see it is ssh

#

as i connect to ssh

#

they need password

#

how do i find it

west canopy
#

Use the same LFI payload you used to read /etc/passwd but use it to read /flag.txt

#

you will not be SSHing into any machines this module, it is purely web based

tepid fjord
#

i will give it a try

#

i have been using heavy command and it everything was in front of my eyes

#

@west canopy THX a lot

west canopy
#

nice work 🙂

#

np!

compact compass
#

@rugged stag May I dm you?

pure silo
#

Hey all I'm stuck on the IMAP/POP3 section of footprinting. I can't seem to find the admin email address or access emails on the IMAP server. Not 100% sure what I'm doing wrong here. Any help would be appreciated

rugged stag
rugged stag
rustic sage
little summit
#

hello

#

anyone can help me

compact apex
#

What’s your question ?

little summit
#

i am at foorprinting module

#

smb

#

What is the full system path of that specific share?

#

i tried every thing

#

/c/home/sambauser

#

nothing works

compact apex
#

I also have a question … does someone know how to get the flag in the web fuzer module ? Because I try with burp suite (not pro) and used the wordlist provided in the example but I took so many time that te target was shuttting down without finishing the fuzing 😅 maybe I’ m using the wrong word list ?

compact apex
rustic sage
#

Would someone like to provide me a nudge on Command Injection Skill Assessment?

west canopy
#

@little summit your answer|| is correct but there is a formatting problem,|| feel free to DM me

steel kite
#

When's the CPTS exam gonna be available thinkw

west canopy
#

@steel kite have you finished the path?

#

mine is stuck at 98.7% even though i've completed every module, curious if anyone else is experiencing this

steel kite
west canopy
#

well my path shows as 100% complete but the exam progress bar shows 98.7% 🤷‍♂️

warm needle
#

Firewall and IDS/IPS Evasion - Medium Lab
Oddly enough, I was able to get the hard module, but I can't get the medium module to nudge. I am trying to use the || dns-nsid || module, but It never outputs any results. When I do a tcpdump on the target IP, I see the || TXT CHAOS? version.bind. || keywords, but I keep getting || Refused- 0/0/0 (30) || Any nudges or advice?

west canopy
#

@warm needle DM me 🙂

twin gulch
#

Hey guys

#

I’m at vulnerability skill assessment at open as section. Trying to log into the Vpn but looks like it’s off. Is there anything bout it? Everything fine with my environment

west canopy
#

Lately a few of my vpn's were not connecting, i just had to download new ones for the main HTB site and for Fortresses

#

using Singapore and EU now haha

#

but they connect

#

this was literally like a few hours ago

hollow thunder
#

On password attacks lab -medium, and im just curious if anyone else has problems with the docx

#

nvm just tried harder

ancient prism
#

Hey

#

Someone help me

#

I am stuck at getting started module at the knowledge chek poit

#

I have the access of initial shell but i am failed to escalate privilege

#

I found this but i don't know how to use it

young vigil
#

Obtain a session cookie through a valid login, and then use the cookie with cURL to search for the flag through a JSON POST request to '/search.php'

#

curl -X POST http://ip:port/search.php -H 'Content-Type: application/json' -b "PHPSESSID=71kg4rbms08de6935hjk82kerd" -i

#

my payload

#

still dont get anything

young vigil
young vigil
#

i found it

#

im stupid lol

rustic sage
#

Who can help me with Command Injection Skill Assesment?

ancient prism
rustic sage
#

Anyone can give a nudge on Password Attacks Lab - Easy?
There is FTP and SSH services and nothing else, no initial info or hints. Tried some of the default credentials - no luck.

young vigil
acoustic owl
iron river
#

Hi there,

can someone help me out with web attack skill assessment?

I manage to figure out which user is the admin and ahve the token and uid. however i am unable to change the password

rugged stag
#

Thanks for pointing me to the solution. Would have never guessed that in my life. There are some exercises that I could never solve without the community help here because there is no way I would have guesses what they suppose you to do from the lesson. And sometimes the info you get is so vague that I'm like, "what they hell do they mean with that". Not all of them are that way, thank god. Some are excellent. But some are just totally confusing and I don't see what that has to do with learning. Since this is an academy they're supposed to challenge us with the exercises, but give us enough information that the challenge is solvable. Anyway, rant over. Thanks again.

knotty summit
#

somebody find for the question about HTB academy in the module learning progress

ancient prism
#

Tell the module name

rugged stag
#

Can somebody help me on sqlmap Attack Tuning Case6? I've wasted hours of my life (with no learning effect at all), and I just don't get what they want me to do.

  • I get that case 6 it's about changing the prefix. I did that.
  • I already tried a gazillion possibilities, including raising level and risk, randomizing user agent, focusing on the right table, ...

There must be something I'm missing. Any nudge in the right direction is greatly appreciated before I throw the computer out the window. Thanks.

rustic sage
#

Having trouble with the AD introduction labs. From my local Kali VM I keep getting recursive lock messages and a blank xfreerdp window then it disconnects after a few minutes. So I tried loading my free pwnbox and am mostly unable to connect there too. On both systems I can connect occasionally but I get disconnected after a very short time...

placid quest
#

@rustic sage try to use rdesktop

rustic sage
#

having trouble finding the correct website to download krnl, can someone send the link to me?

rustic sage
rustic sage
#

Anyone has most economic plan to finish everything in Academy, when I see amount of cubes required and prices I am kind of discouraged I would ever be able to afford it all

onyx dust
#

in that case buying the cubes through the highest subscription makes more sense.

#

the last 7 modules are at minimum 4400 cubes (deducting the amount returned upon completion), and for the last one the 200 cubes returned are worthless.

rustic sage
#

I have trouble with File Upload Attacks module: Blacklist Filters, I found a valid exentsion (with Burp Suite) but when I try to perform ?cmd=id I don't get a output

final frigate
#

Can someone helps me in the skills assesment 1 from Active Directory Enumeration & Attacks? I have the administrator hash but can't find a way to execute commands through pass the hash

tight mesa
#

hello everyone

#

anyone who has finished SSRF module?

sage yew
#

Hi, how did you solve the error? 🙂

onyx dust
final frigate
onyx dust
#

evil-winrm accepts hashes

final frigate
#

I tried using the same syntax for executing others command but doesn't give any output

final frigate
onyx dust
#

why not? u can use from the attack host if u make a tunnel on the windows host

worthy yoke
#

Hi im stuck with section Broken Authentication - Skill Assessment ,it seems i guessed the cookie encoding algorithm as ||md5 + base64 + urlencode|| , i also found the user can have admin rights as admin , but after i add a new cookie i just get the message "User cannot have requested role" ,
where am i wrong?

wicked gazelle
#

hi there, is anyone available to help me with Skills Assessment - File Upload Attacks? i fuzz the extention and can bypass the different filter and use ||xxe ||to disclosure the ||upload.php|| files an the other ||common-function.php||. I discover the Path where the file upload, ||/user_feedback_submissions/|| and finish i try to acces to my payload with the nomenclature ||220820_payload.xxx|| and i retrive not found, i dont can execute my malicious php code. the other hand, if i try redo the same process with a image without nothing, in this case i can see the image. At the moment I can't think of anything else to try, does anyone have any idea what I can try?

vital adder
boreal vine
#

I have some questions about the "ACL Enumeration" part of Active Directory Enumeration & Attacks, if anyone can help me ?

onyx dust
#

i used the names.txt list that comes with the tool subbrute which is recommended in the hint

vital adder
onyx dust
#

subbrute takes a long time and so far it only produces the same records as gobuster

vital adder
onyx dust
#

i ran gobuster and only got two subdoains, helpdesk and control.

#

is there another one i missed?

vital adder
#

did you use gobuster with the custom dns name?

onyx dust
#

gobuster dns -d inlanefreight.htb -w names.txt -r 10.129.126.251 -t 100

#

it did not find ns1

vital adder
onyx dust
#

🥲

#

no i didnt find that

dense ferry
#

Module 'Attacking Common Applications' section 'Attacking GitLab': I found 3 valid users for the GitLab instance however none are accepted as the answer. Is there some weird format you need to enter it as?

vital adder
#

also the pornhub part i'm not joking and there are also i think 2 more guy dm with this #modules message

final frigate
onyx dust
#

i think i read somewhere if the tooling for an exercise meant to be educational takes longer than 5 minutes it's shit and poorly written

#

with this i concur

final frigate
#

use the correct resolver.txt file, take in count which resolver are you using

#

I think with the right command doesn't take too long

onyx dust
onyx dust
#

should i just duplicate the entry 17 times?

final frigate
#

I think I only used the given wordlist by the tool (names.txt), the IP as resolver and only inlanefreight.htb

onyx dust
#

is it took you how long?

#

i've tried that but it didnt work by the time i stopped the process because no thanks around 15 minutes

final frigate
#

I don't think more than 5 minutes, I remember when I get the correct command the subbrute show some output

#

at first, when I launched It the output was completely blank

onyx dust
#

looks good? you're saying i should have useful output in ~5min?

final frigate
#

yeah seems good for me

onyx dust
#

in resolvers.txt is the ip spawned in the exercise

#

it's correct?

final frigate
#

yep, only that ip

#

or I think it will check all the ips

onyx dust
#

ok it's been about 5 minutes

#

same output as before

final frigate
#

I used this command, with only the ip in the resolvers.txt

final frigate
coarse dove
#

Hi, for Burp intruder use zapp and (directory-small-list-2.3-small.txt) from seclist. 😆

onyx dust
worthy yoke
#

grep '[[:upper:]]' /usr/share/wordlists/rockyou.txt | grep '[[:lower:]]' | grep '[[:punct:]]' | grep '[0-9]$' | grep -x '.{20}' , I use the following grep command to find the password that matches the password policy

vital adder
worthy yoke
vital adder
#

i'm trying your command on the pwnbox to see if the support user password is in there but it is given error but that command seem right and also which support username did you found? there is multiple support user but there is only one right

worthy yoke
vital adder
worthy yoke
#

username is *support *

#

I found out by sending messages

vital adder
#

the support have a country code (typo)

worthy yoke
#

i tried top-username-shortlist but didn't see any possible username

vital adder
worthy yoke
rugged stag
#

I'm also doing the Pentester Path. But I'm focusing on the Bug Bounty Hunter first (since a lot of modules are the same anyway and this will also help me with pentesting). I'm at 45% of the Bounty Hunter now. DM me if you're interested in interchanging information...

onyx dust
#

speaking of wastes of time

#

the dns part of attacking common services

worthy yoke
onyx dust
#

u get it now?

#

some of these 'gotchas' distract from technical application and serve no purpose other than to waste time "thinking outside the box"

#

the askhole of red herring

#

¯_(ツ)_/¯

#

but at least i get to think about modeling problems with nuance

worthy yoke
onyx dust
#

🙂 maybe

#

i just gotta tRy HaRdeR

raven cairn
#

Try smarter > Try harder

#

Screw OFFSEC man 🤣🤣🤣

worthy yoke
onyx dust
#

us.support

#

uk.support

#

looks like that

worthy yoke
#

ok 😦

vital adder
worthy yoke
worthy yoke
# onyx dust us.support

sudo grep '[[:upper:]]' /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou.txt | grep '[[:punct:]]' |grep '[[:lower:]]' | grep '[0-9]$' | grep -x '.{20}'

#

I think it's not possible to escalate by modifying cookies right?

onyx dust
#

idk what you are on

#

what's the link

#

to your module and section

worthy yoke
#

Broken Authentication - Skill Assessment

onyx dust
#

i remember there was only one i did which asked for country code and it ended up being concatenated with a . and us/uk

worthy yoke
#

yes, i saw the user a.us

onyx dust
#

i used ||support.us|| to crack the password

#

try that tell me if u find flag.

worthy yoke
#

my cookie ZTY1ODNjMWU1NTNiNDQ2NjAwYmI2MzNhYmMwMTkxNmU%3D

onyx dust
#
e6583c1e553b446600bb633abc01916e  -
#

is that how u made the cookie?

worthy yoke
onyx dust
#

try the command line cookie

#

for online one i like cyber chef it has a lot of easy to use features

worthy yoke
#

my md5 code and yours are the same

#

md5 > base64 and url encode last char

onyx dust
#

do u have to do that last two encoding?

#

i think i only used md5 output nothing else. i dont remember though

worthy yoke
#

i just url encode the last character as "="

#

i don't know either, but i tried to create 1 user and the algorithm for creating cookie for this user is same as above

compact apex
#

Does someone know why my zap browser is so slow when I type ip of target ? it never reach it

onyx dust
#

ok i got it

onyx dust
worthy yoke
#

😅

onyx dust
#

to get the input for cyberchef i did ||echo -n 'admin.us'|md5sum && echo -n 'admin'|md5sum|| and concatenated together with a :

#

then using that website i dragged the transformations over and clicked the box on the URLENCODE option to encode the special characters (takes care of the "=")

worthy yoke
#

r.i.p so hard 😦

onyx dust
#

using that output as a cookie while logged into the support account i refreshed the page n got a flag

#

did u get the flag?

#

cyberchef is so good 8-)

worthy yoke
#

This part is probably the hardest part of the CBBH module :)) , thank you so much

onyx dust
#

no the hardest one so far imo is the active directory one

#

i haven't done them all yet tho

worthy yoke
#

luckily I haven't learned that module yet :)) , previously on tryhackme I learned through bloodhound + kerberous

scarlet sapphire
#

hi i need some help AD Enumeration & Attacks - Skills Assessment Part II at Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 i cant find the flag i have list all the files thats end with txt but i cant find the flag

violet axle
#

The hint for "Generating Shellcode" in "Stack-Based Buffer Overflows on Linux x86" should be changed to this. The questions in the Linux Buffer Overflows aren't specific enough in general.

red obsidianBOT
plush yarrow
#

hello

scarlet sapphire
jade terrace
#

Why the search is working with curl and not with the browser

acoustic owl
#

Have you found a solution? I have the same problem

#

i can't catch the second shell

coarse dove
#

Hi, replace robots_txt with http_put and you need an ip and port from any website or question and use it, and have the burp open .

boreal vine
#

I have some questions about the "ACL Enumeration" part of Active Directory Enumeration & Attacks, if anyone can help me ?

distant stream
vast geyser
#

Hi ,Could anyone give me some hint about FILE UPLOAD ATTACKS-Whitelist Filters?
I use the Burp intruder to get this

#

But I curl this file get 404 not found

#

how can I request the web when the file name contain "\ " or "//"?

little summit
#

hello

#

can any body help me

#

footprinting>SNMP

#

Enumerate the custom script that is running on the system and submit its output as the answer

sharp cedar
#

Hi! I'm currently doing the Linux Fundamentals module and I stumbled upon this command:
find / -type f -name *.conf -user root -size +20k -newermt 2020-03-03 -exec ls -al {} ; 2>/dev/null

what's confusing me is the -exec ls -al {} ; part of it. Why would we use this instead of much shorter:
find / -type f -name *.conf -user root -size +20k -newermt 2020-03-03 -ls 2>/dev/null

The explanation in the module says:
This option executes the specified command, using the curly brackets as placeholders for each result. The backslash escapes the next character from being interpreted by the shell because otherwise, the semicolon would terminate the command and not reach the redirection.

This is all good but for noob like me it's not enough of an explanation. Why do we need a placeholder in the command? We need to escape semicolon but why it's there in the first place? 😄

raven cairn
#

Network Traffic Analysis: Interrogating Network Traffic With Capture and Display Filters

#

Could I have help with this?

grizzled cobalt
#

Is there a walkthrough for the knowledge check version of Nibbles?

final frigate
#

Hey, I need help in the AD Enumeration & Attacks - Skills Assessment Part II, on the question to pivot from SQL01 to MS01, I run the lazagne.exe in a system32 shell but it doesn't providing any clear password,

#

I also tried to use hashcat to the hashes I got or pass the hash, but anything of this seems to work

sage yew
#

How did you manage to get the second IP? I seem to be searching blindly :/

final frigate
tidal tinsel
#

Hi everyone, I am currently working on the ffuf module and now reached the skill assessment. One of the questions is to find the full page URL for a page that says "You don't have access!" I am 100% sure that I found the correct URL but my answer is not accepted. Can anyone help?

#

I am 100% sure because the two questions that follow require the URL and I was able to answer both of them.

vital adder
tidal tinsel
#

@vital adder that worked, thank you very much

tight mesa
#

hello, anyone who had completed the SSRF module, to ask some general questions..!!!

vapid veldt
#

For the Intro to Assembly module, it says that the command man -s 2 write shows the details of that syscall. Don't appear to have those docs installed on the Kali host, anyone know which packages provide that?

rustic sage
#

Hey everyone, can anyone give me a nudge for Password Attacks Lab - Hard? I've found all the services, trying to bruteforce them with provides password list for user Johanna but no luck.

vital adder
rustic sage
vital adder
west canopy
#

hello friends

woven sandal
#

Hello I'm new to HTB
I have problem in starting point module
Setting Up
I didn't understand the explanation is there any videos regarding to starting up in setting up ?

😫 sorry

acoustic owl
rustic sage
vital adder
# rustic sage I got the VHD but I can't mount it in Linux, spent an hour already 😦 How can I ...

use bitlocker with losetup

sudo apt-get update; sudo apt-get install dislocker -y
sudo mkdir -p /media/bitlocker
sudo mkdir -p /media/bitlockermount
sudo losetup -f -P Backup.vhd
sudo dislocker /dev/loop0p2 -u(password) -- /media/bitlocker
sudo mount -o loop /media/bitlocker/dislocker-file /media/bitlockermount

also here is the unmount command if you are doing this on your machine

umount /media/bitlockermount /media/bitlocker
losetup -d /dev/loop0
rustic sage
vital adder
rustic sage
rustic sage
hardy anchor
#

It's really impossible to connect with nomachine to the target at the Shell and payloads module

hollow thunder
#

Can I get a nudge for password attack lab - hard

#

I have J

oak summit
#

can someone help me with this Q Perform active infrastructure identification against the host https://i.imgur.com. What server name is returned for the host?

#

Module :Information Gathering - Web Edition

sudden oriole
#

Hi guys, I’m working on the module information gathering. Right now I’m at the active infrastructure identification. Here it give to me the key to connect to vpn and two urls:

  • app.inlanefreight.com and dev.inlanefreight.com. After I connect to the vpn I can’t access to this two urls but I can access to the the private ip of the target. When I open up the page it says “this is the inlanefreight.local default vhost”. How can I access to the two vhosts app and dev?
sudden oriole
oak summit
#

yes ofcource i wil PM you @sudden oriole

placid quest
#

@oak summit try to use curl

oak summit
placid quest
#

@sudden oriole add them in /etc/hosts file

west canopy
vital adder
#

oh wow so i'm not the only one who mount that vhd on a windows vm (but i use double click)

west canopy
#

i am too low IQ to understand the|| bitlocker / losetup|| method lol

vital adder
#

oh about the dislocker part me and i think most people found a blog about this but dislocker is for mounting bitlocker partition so that's what losetup is for

charred linden
#

Wassup guys!

west canopy
#

sup homie

woeful oxide
#

Hey guys, managed to upload the file but got this error, any ideas?

#

File Uploads Attacks - Type Filters

woeful oxide
manic ermine
# acoustic owl i can't catch the second shell

Don't follow the steps outlined on that page - they don't work (well not for many of us anyway). I would go back and look at the AD enum and attacks module where some info was added about the Kerberos double hop problem. I used a remote port forward (ssh -R) for the metasploit shell and then a local port forward (ssh -L) for the win rm and that worked for me

west canopy
#

I could not get the double hop to work using the steps either

west canopy
#

@woeful oxide i would try a much simpler php shell

hollow thunder
#

could anyone nudge me for password attacks lab hard?

charred linden
#

Anyone else get the response from crackmaspexec:
aardwolf librairy is missing, you need to install the submodule
run the command: ( nothings here )

#

ive looked online and tried installing it with pipx, apt-get, ive tried a bunch of different things to no avail.

blazing briar
radiant dagger
#

I love the "Miscellaneous Misconfigurations" from the AD module. AS-REP and others are most common ways to obtain a foothold

#

quite handy when doing the HTB AD track

acoustic owl
rustic sage
rustic sage
west canopy
#

ah nice

dire eagle
#

On Introduction to Active Directory. 95% sure the answer to this NTLM uses three messages to authenticate; Negotiate, Challenge, and <__>. What is the missing message? (fill in the blank) is authenticate or authentication. Basically the module said that, google searches say that, but the question doesn't accept it. What's the answer?

#

Is it broken or am I stupid?

#

(from module)It is a challenge-response authentication protocol and uses three messages to authenticate: a client first sends a NEGOTIATE_MESSAGE to the server, whose response is a CHALLENGE_MESSAGE to verify the client's identity. Lastly, the client responds with an AUTHENTICATE_MESSAGE.

hollow thunder
west canopy
#

@dire eagle it should be ||Authenticate||

dire eagle
#

........was it really just the capital A

west canopy
#

haha

dire eagle
#

ten minutes of searching and rage.......and it was a damn A

#

thanks

sullen siren
#

who want to help me?

placid quest
#

@sullen siren about what

sullen siren
#

can you help me bro?

placid quest
#

@sullen siren change the password

sullen siren
#

i can't log in

#

i need a good hacker

placid quest
#

@sullen siren I cannot help on that

sullen siren
#

yes

#

i know

sullen siren
dense ferry
#

🧐

sullen siren
#

I need a good hacker

sour python
sullen siren
vital adder
vital adder
rain agate
#

anyone here has a sub on HTB academy who can answer a question ?

sullen siren
vital adder
rain agate
# vital adder what's the issue?

I'm planning on doing the silver sub but it give you 200 cubes. Now my question is if i complete the module do i get the cubes back or are they just consumed ?

sour python
sage yew
sullen siren
vital adder
rain agate
rain agate
#

that really sucks

vital adder
#

for example this module will cost you 1000 cube and it will give you back 200 cube

#

the Unlocks For is the cost and the +200 is what you get back

sour python
vital adder
sour python
#

How are you supposed to get enough cubes ?

vital adder
sour python
sullen siren
#

who can hack a gmail?

sour python
rain agate
acoustic owl
sullen siren
#

he change a password and ph number

rain agate
#

MFA is a must

sullen siren
#

and Security is too strong

sullen siren
sour python
sullen siren
sour python
#

Why is ur email called that

vital adder
#

and that email is in 1 data breach

sullen siren
#

he stole that gmail

sour python
vital adder
sullen siren
#

bro

#

don't do it

sage yew
#

Hi guys,
I'm doing the skill assesment on the pivoting module, but I don't understand if you are capable of ennumerating the internal network from the webshell? '

vital adder
# sullen siren don't do it

pls stop being an idiot no one is going tell you how to hack gmail if you need help recover your email i already send you the resource and also i found your email in a data breach so change your password

sage yew
vital adder
sage yew
# vital adder nope nmap on your machine

Sorry, I'm a bit confused
The webshell has access to the internal network, and we don't have direct access from attackbox, right? (That's what I understood when looking at ifconfig)

vital adder
sage yew
vital adder
sage yew
#

Thanks!

vital adder
broken warren
#

I could use some assistance with broken authentication module weak brute force protections section, in question 2 I'm using the basic_bruteforce.py script they have us. I changed my target to http:// <target up>/question2/ and I can get my header to have the "X-Forwarded-For":"1.2.3.4" but I keep coming up short it seems so simple though idk what Im missing

vital adder
broken warren
#

I copied right from the example, this exactly how it sits within my script headers = {
"User-Agent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.96 Safari/537.36",
"X-Forwarded-For": "1.2.3.4"
} So is that all correct and the ip needs to be changed? to like anything or does it have to be like a 192.xx.xx.x?

vital adder
rain agate
#

did anyone here pass the PNPT with help from HTB academy ?

#

i'm hesistant to sub but i'm not sure about it

dire sentinel
vital adder
rain agate
maiden kraken
#

Hi everyone

#

Im new

rain agate
#

so i wanted to push in a different aproach to it like some of the stuff i got in the academy like stabilizing shells wasn't covered in the course

maiden kraken
#

How do i hack in windoes

vital adder
# maiden kraken How do i hack in windoes

Sponsor: https://go.intigriti.com/thecybermentor
Blog Post: https://tcm-sec.com/so-you-want-to-be-a-hacker-2022-edition/
Academy: https://academy.tcm-sec.com

Timestamps:
0:00 - Introduction
0:53 - Intigriti Sponsorship
1:55 - Building a Foundation
2:10 - Important Notes
5:37 - Basic IT Skills
8:28 - Networking Skills
12:38 - Linux Skills
17:04 ...

▶ Play video
vital adder
maiden kraken
#

thanks

rain agate
#

i just send the HTB team an email to request for them to unblock my academic email to get access to the student discount

vital adder
#

that is unnecessary there is a chat bubble click that and send them your academic email and info they will whitelist it

vital adder
#

if you have ads block on you can't see it

vital adder
rain agate
rain agate
vital adder
#

if you don't have ads block on i have no idea why it doesn't show

rain agate
onyx dust
#

¯_(ツ)_/¯

rare tide
#

The reverse shell is not working for Getting Started in the hack the box academy

west canopy
#

hello friends

shadow verge
#

Hi :3

oblique shale
#

for web requests : POST has anyone had the search just never fire off? I put it in the web interface and the search just spins, no Search.php ever fires

west canopy
#

@oblique shale sometimes with docker targets i have to respawn them a few times

oblique shale
#

Ok I will give that a try, I was like how am I screwing up by following the example

oblique shale
west canopy
#

Maybe try using curl instead of your browser? If you just navigate to the target you might not necessarily be sending a POST request

#

for example:

oblique shale
#

I was playing with browser so I could see the search request

#

I will skip it for curl

summer lava
#

using burpsuite.... what will be the content-type to bypass .WAR file ??

copper creek
#

whats the longest study/learning session in terms of hours you guys have done on academy? anyone above 12hrs? 😄

tight mesa
#

I'm stuck with Blind SSRF exploitation examples, anyone to whom ask some?

plush yarrow
#

Mr Tom I deadmr tom is dead

#

rip mrtom

west canopy
#

stop bullying mrtom FeelsBadMan

vital adder
#

about that....
i was bored, he was spamming, so i did a bit of trolling... and now he think i got killed by "the russian"

delicate glacier
vital adder
#

already tell him that

unreal timber
west canopy
#

@unreal timber DM me 🙂

shadow willow
#

can someone pls help me ?
Module: Broken Authentication -> Predictable Reset Token
I know the algorythm and the way how the hash is generated but everything i do is wrong
My code:

lyric echo
#

Hey! Could I get some help with Broken Authentication Assessment? I found the passord for the support user and see the cookie, but am having troubles with the next step to decode

dire sentinel
#

Password Attacks -> Password Reuse / Default Passwords: Found some useful files on the target, tried known credentials and bruteforce tools. Enumerated other services, dead ends. Think the key is in one of the files that are on the target, a bit stuck on reading/gaining access to them. Any help is appreciated!

vital adder
dire sentinel
#

Thanks!

woven hollow
#

Can anyone assist me in Password Attacks - Hard? I've hit a wall after finding the VHD file.

vital adder
woven hollow
vital adder
woven hollow
#

Thank you! I'll give that a shot

woven hollow
hollow thunder
#

did you use vdi2j to crack

night pier
#

got it....

woven hollow
hollow thunder
#

thank you

woven hollow
hollow thunder
#

Finally finished PW attack - lab hard

#

spent so much time on that one

west canopy
#

Nice work 🙂 The ||backup.vhd|| threw me for a loop !

raven cairn
#

Does anybody know how to change their profile picture for academy?

west canopy
#

I dont think you can

raven cairn
#

If I could find a stored XSS attack vector, I could change the website so I could change my profile picture. big_think

west canopy
#

i mean what the hell is even this???

raven cairn
#

So ugly

west canopy
#

its like a bomberman pez dispenser

raven cairn
west canopy
#

you're killing it bro

raven cairn
#

Now just need to complete the CBBH path. Only have 20 sections left.

west canopy
#

i have been getting spanked by this Secure Coding 101 module

raven cairn
#

The javascript one?

west canopy
#

yea

raven cairn
#

I wish I could help but no way in hell am I going to spend 1000 cubes on that 🤣

west canopy
#

i managed to get mrb3n to unlock it for me

#

turns out extortion is quite effective

raven cairn
#

lol

#

I got OSINT corporate recon for free because I fixed the hashcat module

west canopy
#

hell yea

raven cairn
#

@west canopy How many modules have you completed?

west canopy
#

all but two

raven cairn
#

Which ones?

west canopy
raven cairn
#

The flex haha

west canopy
#

i have OCD so i wont complete a section

#

until the entire module is done

raven cairn
#

Hackthebox really needs to fix the progress meters. It fucks with my mind

west canopy
#

lmao i know they make no sense

acoustic owl
west canopy
#

awww 🙂

echo zenith
#

Hello, I am in the module of the academy called vulnerability assessment. I connect to my virtual machine, Pwnbox, but I can't find Nessus within the programs. And from my VMware machine, when doing the scan, it does not find the vulnerabilities of the exercise or anything. Some help?

rocky thorn
#

Scan again...

echo zenith
#

I've done it several times and nothing. And with my nessus I only have 16 Ip's to scan, I've already spent 2

rocky thorn
#

It's being pushed through an advertisement session id;;ior::rn'musabr'

echo zenith
#

also, the exercise is supposed to scan a windows machine, but the ip it gives me is a linux machine

rocky thorn
#

Yes because I'm in one of those remote controlled drones r.dp (Direct.Point'Pontificure') Remote controlled pneumatics...

#

N+N Mk.Setup loc/soc 'm6H2'

#

N+N Mk.Setup loc/soc 'm6H2'

#

It broke into tiles using tulsa.blues icon.pkg

#

Okay you figure it out from here.

rocky thorn
#

../Runc.mk(d.d) [pnkdi] --sha1::t.Pastorea::d.h2'M6

--HMS(MS13)

feral stump
#

Hey @acoustic owl you around? I have a quick question on the easy lab footprinting

#

Thx!

rocky thorn
#

Huh?

feral stump
#

Not stuck solved it on my own but wanted to understand if the id_rsa and id_rsa.pub need to be on the local root folder under .ssh to make the connection to the remote ssh server successfully

#

Just because I see when ssh that it loads the keys from there so just wanted to make sure that is a rule

acoustic owl
#

You can basically store id_rsa (private key) wherever you want. You can specify it like this

ssh -i /path/to/your/key user@serverip

feral stump
#

Ok perfect wasn’t sure how to make that happen

Thx!

summer lava
#

I always get this error after i upload a crafted metasploit payload in .war format on Tomcat and listening...
please i need you're help
module: SHELL & PAYLOAD

jagged zenith
summer lava
#

the payload was uploaded successfully but when i try to execute.. tomcat raises an expection of metasploit payload

jagged zenith
summer lava
#

if so.. we need file restriction bypass

#

i tried that using burpsuite ... and tomcat insist it must be .war file

summer lava
#

spent so much hours finding solution.. all to no avail

#

can you give example of that pls

#

tomcat only accepts .war file

#

so can i upload .exe file using that methode ?

#

payload.exe%00.war

#

got it.. let me tried that out

copper creek
#

Password Attacks Module - Q: Examine the target using the credentials from the user Will and find out the password of the root. Then, submit the password as the answer.
Are we supposed to ||use rockyou wordlist on the unhashed file||?

#

nvm, got it

fiery pier
#

Using the Metasploit Framework Module / Introduction to Metasploit / Question 2: Which version of Metasploit is free and can be used only through a CLI?
Are we really expecting anything else than "Metasploit Framework"? This answer isn't accepted.

fiery pier
final frigate
#

Hi, I can't move in the Attacking Enterprise Network, Active Directory Compromise, in the first steps (getting the tgt hash) the socket is failing, I have just copy and paste the commands so I don't know what I'm doing bad

#

(the credentials are ok, if I wrote bad credentials the error message is different)

#

each time I launch the command (GetUserSPNs.py) a new line of error appears in the left, but I can connect with proxychains, nmap and others tools works fine

copper creek
#

Password Attacks Module Q: Use the cracked password of the user Kira, log in to the host, and read the Notes.zip file containing the flag. Then, submit the flag as the answer. Can I ask someone about that?

copper creek
# acoustic owl sure

I downloaded the Notes.zip file to my host, to get the password.
Am I using the wrong wordlist or what am I doing wrong exactly?

#

Can I send u the screen via dm? So I dont spoil

acoustic owl
final frigate
knotty crag
#

Guys is BeEF good for larrning to hack

#

Or we should use linux terminal to learn the commandes

#

Commands*

acoustic owl
copper creek
#

can someone give me a hint on how to gain ssh access on the password attack easy lab? i've tried bruteforcing ssh/ftp with username.list & password.list provided from the resources

hard lodge
#

Could i DM someone about Attacking Common Services - Attacking DNS? I'm stuck and idk what else to do :/

hard lodge
west canopy
#

@hard lodge i might be able to help 🙂

copper creek
copper creek
#

alright, i guess i will let it run in the background

#

thanks 🙂

hard lodge
shadow willow
#

Module: Skill Assessment - Broken Authentication
Can somebody pls help me ?

#

||I have The user admin.us..; support.us..; and a wordlist adapted to the rules but i just can't crack the password||

west canopy
#

@shadow willow DM me 🙂

fossil crescent
#

Anyone avail for a dm/nudge on WHITEBOX PENTESTING 101: COMMAND INJECTION -- Skills Assessment? Have looked at the code and virtually certain I know what's to be exploited, and ability to control it (at least alter it's default behavior), but aside from altering default behavior, can't figure out how to get command execution locally (let alone remote). Lost as to what I'm doing wrong. Thx. EDIT: Figured it out.

rustic sage
#

ca n anyone help with Find and submit the contents of the TXT record as the answer? can anyone help please?

rustic sage
hard lodge
#

yes DM

shadow willow
night pier
#

has anyone completed intro to assembly language? I need some help

west canopy
#

@night pier i can help on any questions except the first question in the skills assessment

tepid fjord
#

yo guys

#

wanna help

#

in file inclusion skills assessment

#

i FUZZed the directory and everything

#

it is the logic way to me, anyway, as am trying to put it in the URL

#

it shows nothing

#

what should i do

lethal atlas
#

SORRY @night pier im in the middle of that module

copper creek
#

password attacks medium lab felt quite difficult compared to all the previous modules in the path, but nice learning experience

tepid fjord
#

the command i did last as they want the flag inside root folder

#

ffuf -w /usr/share/seclists/Fuzzing/LFI/LFI-Jhaddix.txt:FUZZ -u 'http://134.209.31.118:30751/index.php?page=FUZZ' -fs 4521 | grep root

strange saddle
#

Having a little trouble signing in on my computer . Says I don’t have an account but yet I’m logged in , maybe another email verification or something ? Anyone had this issue ?

tepid fjord
#

skill assessment

#

in File inclusion

#

well yeah i tried still giving me nothing

#

in the questions itself they say that the flag inside /root

rustic sage
#

anyone free to DM about the getting started unguided end box? I completed it getting a foothold with metasploit but trying to find if I'm on the right track for doing it without...

quasi wave
#

can someone give me a hint as to this HTB challenge?

#

I want to find out which user is running proftpd server

#

wait

#

I found it

#

it is just proftpd

#

lol

acoustic owl
modest token
#

I was wondering if anyone knows about any training modules on htb that can help get you ready for hacking Microsoft Azure?

#

ty! this looks great!

onyx dust
#

😎

tepid fjord
quasi wave
#

could someone give me a hint for another challenge?

#

without giving me the answer?

#

I'm trying to figure out how to use curl to get a number of unique paths to a destination from a page's source code

#

I really don't want to look up the answer

#

I googled it and there are people asking for the actual answer which I don't want

quasi wave
#

I keep ending up at 48

copper creek
#

anyone for a nudge on password attacks - lab hard? got a foothold, but stuck now

rustic sage
quasi wave
#

I used both the uniq command and sort -u

#

as part of a larger command

#

curl https://www.inlanfreight.com | grep "https://www.inlanefreight.com" | uniq

or

curl https://www.inlanefreight.com | grep "https://www.inlanefreight.com" | sort -u```

I even tried adding in ``` | wc -l``` at the end and it gives 48 or another number besides the right answer
rustic sage
#

You're on the right track, you might just need to do a bit more work in the middle

west canopy
#

@quasi wave is this for linux fundamentals skill assessment?

rustic sage
#

iirc I had to put in some regex

lethal atlas
#

@quasi wave hey just so you know @rustic sage is exactly right, you have some work to do in the middle of your curl command. This one was tough imho.

rustic sage
#

Yeah, took a lot of work to figure out how to do this one

fossil crescent
quasi wave
#

am I just looking for regex?

#

I mean to specify a regex in the file and count that number of times it occurs non-recurring?

fossil crescent
#

Presuming as 10months old that you have long since solved, but just-in-case.. I just got this done. (Came across your post as was looking for a nudge myself until figured it out)

mystic fern
#

Hi new here glad to be here

#

I need help on a academy module called cracing

#

I dont need amswers just what i am doing wrong or misunderstanding

ashen dagger
#

bro, did you solve it? I have the same problem

mystic fern
#

No im still on first question i spend 4 hours on it yesterday

#

I am very sure i understood the question and i am also sure i am doing the rite command but every hash i get it tells me wrong answer

mystic fern
broken warren
#

@ashen dagger nah Im so close to being done too. Someone said to try on the pwnbox but I can't find the directory tplmap is in , and I can't install it. I've tried setting up a new VM, and setting up a server on Linode to install tplmap on. No dice. And I have no idea why the tornado payload won't work

lethal atlas
#

anyone give me some input on an error im getting in assembly language? NM figured it out on my own

woeful oxide
#

Hey guys

#

Anyone out there who can give me a hand on the skill assessment of file upload attacks?

#

I managed to read the upload.php

vital adder
mystic fern
#

In the cracking passwords words with hashcat module. The question is. ( Generate a md5 hash of the password HackTheBox1243! ). The problem is , i put in the command echo -n 'HackTheBox123! | md5sum
When i get the hash and submit the amswer it tells me it is wrong. Can any one please help me

west canopy
#

maybe try without -n ?

#

is it HackTheBox123 or 1243 ?

mystic fern
#

Its 123!

#

Ill try

#

Sorry miss type its 123!

mystic fern
rocky thorn
#

Because you might not own the user name space server's rights to claim it.

rocky thorn
#

I don't know that gets into federal law then

mystic fern
#

You just left me even more confused if you were talking to me

vital adder
#

i think he's just trolling that make no sense even in the module or not

#

also send me the command you run for the hash

rocky thorn
#

Oh my god...

#

Go fucking find your own pirated fbi codes...

#

bitch

vital adder
#

@rocky thorn
绝不会放弃你
永远不会让你失望
永远不会跑来跑去抛弃你
永远不会让你哭泣
永远不会说再见
永远不会说谎伤害你

west canopy
#

i'm only 12 what is this???

vital adder
#

secret CIA code

#

vault 7 was leak on wikileaks this is ||vault 69||

rocky thorn
#

Mhm. I hate you.

midnight basalt
#

Hi, currently going through broken authentication - predicatable reset token.
Looking for a nudge on question2.

Not sure on what is the right direction on approaching this question, i have decoded the temporary password for htbuser, and trying to forge a similar one for htbadmin and submitting it as a password.

Looking for a nudge or something to point me in the right direction!

vital adder
#

after you decode the cookie for htbuser change all of the ||htbuser|| to ||htbadmin|| and encode the cookie the same way it was decode and use that as ||the password||

midnight basalt
lethal atlas
#

@mystic fern I see your error

#

you said i put in the command echo -n 'HackTheBox123! | md5sum so you missed an quote. it should be echo -n 'HackTheBox123!' | md5sum

mystic fern
#

the issue was the md5 was incorrect no matter how many ways i wrote the command the md5 tool was giving false hash values

lethal atlas
#

ok if you say so

west canopy
#

his hash got hacked

#

zero day algorithm

lethal atlas
#

@west canopy have you done the assembly module?

west canopy
#

i shouldn't say

#

everyone knows too much already

lethal atlas
#

Im stuck on conditional branching

#

I changed the line of code and get the loop to stop but I cant for the life of me find the hex value they want

west canopy
#

one sec

rustic sage
#

can any 1 help me with ssh connecting issues?

dense ferry
#

RIP Gregg Harris😔🙏

rocky thorn
short flame
#

Hi. In the final assessment of WordPress module I get all the flags except the first LFI. Actually I got a shell on the machine, but what I suppose to search? With the LFI I got /etc/passwd which is related to the next flag, and the wp-config.php that contains the DB credentials..... It is not clear what I need to look for.
2 Flag files already catched.

(edited)
ok, got it, and completed the BB path. Some time the hardest part is understanding the questions..... and what the author really want from us.....

rustic sage
#

I am currently stuck at: Broken Authentication > Brute Forcing Passwords. Who can I dm?

rustic sage
#

I tried to use Burp Intruder but after some attempts it'a getting blocked

short flame
#

It's about filtering the password DB

rustic sage
#

I know, I used this command: grep '[[:upper:]]' rockyou-50.txt | grep '[[:digit:]]' | grep -E '^.{2,13}$'

short flame
#

Ok, it's better use ZAP FUZZ or mannually write a python script

rustic sage
#

||1 Uppercase
1 Number
Length Minium 2|| the password policy

short flame
#

Burp intruder slow down in the community edition.

rustic sage
#

I have Burp Suite pro ; )

short flame
#

ok.... I'm going to check. maybe there is a time out after fews attemps..... I'm not sure this is the case. In that case insert a pause for ech request

rustic sage
#

ahw lower the threads

#

that's clever 😁

#

Thanks, I will implement that

short flame
#

I remember ||30 or 25|| sec for each request.....

rustic sage
#

Okay, thanks ; )

rustic sage
#

hey, I am stuck at Broken Authentication > Preditable reset Token > Question 1, who can I pm regarding this?

rocky thorn
#

idk,.. bye again,

past quarry
#

Hello! I got to study at the academy. I don't understand the first question "What is the name of the first section of this module? If you are using a translation solution while studying, please temporarily disable it to enter the name of the first section in English." The prompt says "All answers are case-sensitive".Help me I'm a beginner.

autumn pilot
#

@rocky thorn stop with the nonsense

lethal atlas
languid dawn
#

please don't leak flags, even if incomplete/wrong

quiet prism
#

i'm on an SQL injection fundamentals. log into the mysql then do the 'SHOW DATABASES' command and nothing happens

#

any help would be appreciated please 🙂