#modules

1 messages ยท Page 6 of 1

quiet prism
#

added

copper creek
#

can someone give me a nudge on attacking common services - attacking smb? 'What is the password for the username "jason"?'

hard lodge
#

Could someone help me on Attacking Common Services - Easy? Thx ๐Ÿ™‚

vital adder
hard lodge
#

found a user but brute forcing with the give pass list doesn't return anything and i've been trying rockyou but the machine runs out of time in the process @vital adder

vital adder
#

what did you brute force and also use ||rockyou||

hard lodge
vital adder
#

yeah you are in the right path and if you use ||rockyou|| the password should be in the ||top 100|| and also for the username you need to use the ||full mail address||

spare condor
#

Can I dm someone about the **AD Enumeration & Attacks - Skills Assessment Part I **? (below error)

woeful oxide
#

Hey, working on server side attacks but I can't connect to the server, any ideas? I can tell that everything right

west canopy
#

There must be a problem with your nginx conf file

woeful oxide
#

I get response with 127.0.0.1:80

snow mirage
#

Im having a problem with the Using Metasploit Module. I've set up my target machine with the proper exploit they want me to use but it just doesnt want to connect. Ive tried both the pwnbox and my VM via the ovpn to hackthebox and it just doesn't want to connect, can anyone help me?

#

EternalRomance. I tested a similar MS17_010 exploit with one of my other boxes in my VM lab and i was was able to shell in just fine, idk why this is a problem on HackTheBox

vital adder
#

any hint for what word list to use on module Attacking Common Applications section Attacking GitLab i found the user but can't find the password

loud raft
#

hi there - i started HTB from scratch - and it seems that in the "Starting Point" Tier I the S3 bucket is not running. Is this going to be fixed?
obviously my hosts file is setup, but i get a 502 proxy error when attempting to use a browser to access that bucket

calm plaza
#

anyone know about cve-2022-31625 or cve-2022-31626 ?

swift ledge
#

Hello,
I got redirected to this channel.
I'm pretty new around here. I am currently going through the "Getting Started" module.
I'm stuck on the "Knowledge Check" section.
It is about ||GetSimple CMS v3.3.15|| and ||CVE-2019-11231||
I saw some conflicting statement in the Discord history so I'm wondering if the box tied to that section is still functional ?
I have the following error when running msf : Exploit aborted due to failure: unknown: IP:80 - Upload failed
Maybe I just missed something

copper creek
#

can someone assist on attacking common services easy lab?
||can upload files to webserver, but I can't get my reverse shell right||

rustic sage
#

can any one help with CROSS-SITE SCRIPTING (XSS) :Phishing: having issues removing the image url element on the page?

vital adder
copper creek
vital adder
vital adder
copper creek
#

My mistake was I put / instead of \ in the path... this actually cost me like 45minutes oh boy

#

๐Ÿ˜‚

stray grove
#

stuck on password attack hard lab, already found johanna creds and rdp to the machine.
found some .kdbx file, upload it on my attack machine and crack the pass to find the
masterkey...can't find anything else after that. any hint?

vital adder
stray grove
#

yessir

vital adder
# stray grove yessir

if you do a nmap scan you will find some service on that box and one of that service will accept that user cred

lethal atlas
vital adder
#

also this doesn't affect anything but for fun you can still add an icon

sturdy igloo
#

Hi Iโ€™m stuck at in the FOOTPRINTING module DNS... anyone can help me?What is the FQDN of the host where the last octet ends with โ€œx.x.x.203โ€? I did dnsenum --dnsserver 10.129.132.192 --enum -r -p 0 -s 0 -o subdomains.txt -f ~/htbAcademy/jpt/wordlist.txt inlanefreight.htb and ran the same on every ns a soa i found but no luck. wordlist is the one from seclist.

#

did `dig axfr inlanefreight.htb @10.129.132.192' and everything found after that like axfr mail., axfr dc1. etc

lethal atlas
copper creek
#

can someone give me a nudge on a foothold for common services - medium lab? can't find any username/creds

stray grove
vital adder
lethal atlas
#

I will go back and try to add '}; and see if that fixes it

vital adder
copper creek
#

thx ๐Ÿ™‚

stray grove
stray grove
#

yes i did, getting access denied

vital adder
#

so you use ||david|| cred on the in the ||smb|| and still get access denied and which share did you try to access

stray grove
vital adder
sturdy igloo
vital adder
#

htb give me brain damage

#

i'm on the last brain cell

stray grove
vital adder
#

Shoot me a DM with the command that you use

worthy yoke
#

HTB challenges my perseverance

copper creek
#

anyone for a nudge on common services - hard?|| impersonated the user but stuck now, getting an error when trying to communicate with the remote db||

vital adder
copper creek
#

can I dm you? not sure if i'm missing smth

lean bobcat
vital adder
tender marlin
#

can anyone help im trying to launch Parrot OS on a VM but its not in the options

vital adder
tender marlin
#

There is only an option for linux no parrot os, or iso. I have no idea how to download the parrot iso. I do have parrot OS installed and on a virtual disk somehow

vital adder
#

just search about this on youtube there video show you how to setup step by step

tender marlin
#

I think I installed it wrong because there is nothing in the virtual disk that says parrot OS,

#

followed a step by step guide on youtube and it still didnt find the OS

vital adder
vital adder
#

and also can i dm someone about this moudule cheat sheet my look like it missing some stuff

west canopy
#

You need help with attacking common services?

vital adder
#

nope Attacking Common Applications

west canopy
#

sec let me check my notes

#

try using ||cirt-default-usernames.txt||

vital adder
#

oh i found the user but can't find the password

west canopy
#

i dont have anything on bruteforcing the password

#

but its a simple password

vital adder
#

yeah i get that part but can't find a word list have that password

#

is that password in rockyou?

west canopy
#

it should be yes

#

if you run into issues DM me

tender marlin
#

So I was able to get Parrot OS onto it but now when I set it up and install it, instead of going to parrot OS when it restarts it goes to grub and disables the keyboard.

placid quest
#

@tender marlin Is it your first time using parrot os

hard lodge
copper creek
placid heron
#

So at the XSS module phishing part i keep getting the "Issue in sending URL!" like many others before, even with a payload posted earlier my own payload and the one posted earlier both work when i test them, however i can't send it to the "victim".. any ideas what could be the problem? Tried both url encoded and not url encoded and once again, works when i test it, probably would work if the "victim" would accept and use it but i guess the bot is finding smthn it doesn't like with it because it rejects it

#

hope this is not an issue with the exam later because that would be very frustrating ๐Ÿ™ƒ

worthy yoke
#

hi everyone , i am currently stuck at the module Web Attack - Bypassing Security Filters , I have tried quite a lot of different HTTP Verbs like POST,PATH,UPDATE,PUT,DELETE ,OPTIONS and using url encode but only get the message "Malicious Request Denied!" Can someone please suggest me ?

sage jackal
#

Hello, I need some help on the Attacking Common Applications module - Skills 1; On the tomcat application I canโ€™t find the manager or host-manager, also tried the ghost at exploit but didnโ€™t get something usefulโ€ฆwhat am I missing, any hints?

acoustic owl
sage jackal
broken warren
#

Has anyone had issue connecting to the VPN I can't get it to run and say initialization complete.

marble raft
#

Hi there guys! Could someone please give me a nudge on Credential Hunting in Linux? I may be doing something wrong

hard lodge
#

if so DM me

copper creek
#

can someone assist with remote/reverse port forwarding with ssh? pivoting module, my pivoted meterpreter session closes instantly

zealous fiber
#

Hello, I am stuck on the Stack-Based OVerflow Linux x86 Skill Assignment. I got a working shellcode in gdb but when I try it outside it not working ๐Ÿ˜ฆ

frigid summitBOT
#
Shibe#3359 has been warned

Reason: Mass mention

summer lava
#

can someone please give me full list of thing we can do with the file

/etc/passwd```
raven cairn
stray grove
tender marlin
#

@worthy yoke alright I finally figured it out and got Parrot OS running on my VM, and Thanks jnvk for helping me out

raven cairn
#

Could I have help with Linux Buffer Overflows Skills Assesment?

raven cairn
vale salmon
#

So I am having a bit of a struggle in the Password Attacks Module. I am using crackmapexec winrm on the target box, with the provided username.list and password.list, but when I hit enter it pauses for a second and then just returns me to the terminal prompt. No output or errors or anything.

dire sentinel
vale salmon
#

Heard, I'll check

vale salmon
#

@dire sentinel Seems to be happening with both 5.2.2 and 5.3.0

dire sentinel
zealous fiber
lethal atlas
#

Anyone who has done the web attacks module, did you use the curl method? or the bash script? if so what regex did you use? I have done this module using burp but I want to understand the other method as well.

vale salmon
#

So now I'm having problems with hydra and smb in Password Attacks. I keep getting Invalid Reply from Target

lethal atlas
#

DM me @vale salmon

lethal atlas
iron plaza
#

can anyone point out what am I missing: I start the nessus service with " systemctl start nessusd.service" then I am giving option to choose from multiple identities, I chose the htb-student and type the password. I do get the Authentication Complete followed by "Failed to start nessusd.service: Unit nessusd.service not found." (even tried "nessus.service")?

lethal atlas
iron plaza
lethal atlas
#

yes, nessus is a service provided by tennable. You have to sign up with them to use it on any system

iron plaza
lethal atlas
#

nope, doesnt quite work that way im afraid.

iron plaza
west canopy
#

hello friends

stray grove
tight mesa
#

hi, anyone who has completed the SSRF skill assessment can share a hint with me..!!!

#

I'm complete stuck

copper creek
#

can somone give me a nudge on the pivoting skills assesment? whats the best way ||to transfer the lsass dump to my host||?

vital adder
#

or did you try transfer ||mimikatz|| on the target machine

copper creek
#

omg I did not know I could do this but I just found about this..
if anyone wants an easy way to transfer files with xfreerdp just add /drive:SHARE,/home/kali as arguments when connecting. Maybe it was obvious but I didn't know this. This is lifechanging

copper creek
raven cairn
west canopy
#

i am taking it easy from modules

#

i am teaching a networking class next month so just going over the course work

#

and even though i troll compTIA hard i kind of want to get network+ for the lulz

west canopy
#

naw its just general networking'

#

we do stuff with packet tracer though

worthy yoke
#

I'm tired of the network at the company, sometimes it disappears for unknown reasons

lethal atlas
#

good evening

west canopy
#

hey bb

faint trellis
#

Hi everyone!
Who can help me with the "Windows Privilege Escalation - Vulnerable Services"?
I can't get a reverse shell on my netcat listener.
I saw a picture of @west canopy . I have the same one exepted the needed shell. The shell.ps1 seems to be edited correctly as well. The Scope in the Bypass state.

terse jackal
#

m

#

obanganga?

rustic sage
#

i am stuck at command injections module, Bypassing Other Blacklisted Characters, could someone give me some help on it please

#

i am not able to figure out the syntax needed

rustic sage
#

should I use URL-encoding?

faint trellis
rustic sage
#

so first ${LS_COLORS:10:1} for semicolon and then the encoded command or the whole thing encoded?

faint trellis
rustic sage
#

thanks for the help, I will continue

#

quick confirmation, is "127.0.01; ls /home" correct syntax for the task?

faint trellis
rustic sage
#

i mean that is in the raw format without any attempt to get it through the filters

#

just trying to make sure that I am not facing two issues simultaneously

rugged stag
#

File Upload - Skill Assessment: Could I ask someon a question?
I think I have almost everything (source code, naming convention, regex filtering, ...) but I can't seem to get the MIME type right and I don't see what I'm missing.

vital adder
rustic sage
fresh wedge
#

Shells and payloads live engagement last server can someone dm me I have a few questions

hard lodge
#

Coul someone help me on Attacking Common Services - Hard lab?

copper creek
dire sentinel
#

Password Attacks -> Credential Hunting in Linux: Pretty stuck. Tried brute-forcing multiple services with provided username and credentials from hint. Any help would be appreciated!

fresh wedge
#

Shells and payloads live engagement last server can someone dm me I have a few questions

fossil crescent
#

Secure Coding 101: Skills Assessment -- Managed to get thru the other sections of this, and managed to get the first question in the skills assessment, but absolutely, positively, utterly LOST on the rest of the skills assessment... Is there a Secure Coding 99 or 100 that someone can refer me to by chance so I can complete this? ๐Ÿ˜…

EDIT: Holy hell, I actually got the second, third, and now fourth questions in skills assessment solved as well... final one -- patching...

hazy grotto
#

Having trouble with this too.

native quarry
#

General question here:
When I run

gobuster dns -d http://whatever.url -w /usr/share/dnsenm/whatever-the-filename-is.txt

I seem to lose my VPN connection after a few minutes. Am I missing something here? Is HTB just shutting off that connection to protect against some kind of nefarious activity? I know that I could use ffuf or similar, it just seems weird that I don't have problems if I run a gobuster dir command, but do have problems if I run a gobuster dns command.

undone coyote
#

HI

umbral arch
#

someone knows how to scalate privileges in the Getting started | Knowledge Check? I tried a lot of things

gentle terrace
#

Hey everyone, I had a question. I got done with the *Service Scanning * section on Getting Started and we ended up using bob's credentials. I was curious as to how we got bob's credentials?

undone coyote
#

.......

gentle terrace
#

Like, I understand we used smbclient to see what types of shared folders were listed and that there was a non-workgroup labeled users. But after that the documentation just states to use bobs credentials..? I was just curious as to how they were able to actually view the creds and knew how to use them.

rustic sage
#

its always the anime profile pictures bro

#

always.

livid pier
delicate needle
#

jesus christ what are you feeding your arms man

wanton viper
#

can someone explain to me what is flag

#

find flag - what is it and how we can find with curl

west canopy
#

it will be a text file called "flag.txt" , you must find its location and read it's contents

#

hence "capturing the flag"

wanton viper
#

how can i find with curl

#

been stuck 2 days

west canopy
#

which module/section are you on?

wanton viper
#

http methods and cods

#

hack the box mudoles

wanton viper
west canopy
#

1 sec homie i got you

wanton viper
shy warren
#

Anyone have success in the IMAP/POP Footprinting module. Stuck on the last question. I'm able to login to the IMAP server, Select the "INBOX" and now I'm stuck with fetching the messages within this inbox. Any insight would be greatly appreciated

#

Every fetch command I get an error. I know my syntax is off but still have no idea what command to issue to retrieve the flag

dire sentinel
proud sparrow
#

hey guys, i need help, any one?

feral stump
proud sparrow
#

i just wanna know what machines should i go through when im done with some modules ?

feral stump
#

I guess it depends on the modules youโ€™ve gone through

#

But even though you can try easy machines

#

And use maybe guidance from YouTube

acoustic owl
proud sparrow
#

i dont see any suggestion for machine after im done with the module thats why im asking

#

all i can see is "Suggested Modules"

acoustic owl
#

Which modules have you solved so far?

proud sparrow
#

wait... i think you're right, i've been doing modules i didnt notice that it suggest for machine its like not every module has machines to do

#

thank you i need to go back for all what i did ๐Ÿ˜ฆ

quasi wave
#

I'm having trouble with this HTB challenge

#

can someone help me without giving me to answer

rustic heart
#

@everyone

rustic sage
fossil crescent
#

Could I solicit a nudge/DM from either yourself, @knotty hemlock , or anyone else who has completed the Secure Coding 101: Javascript -- Patching Skills assessment? I deciphered the code, and (I would argue successfully) have identified and patched 2 ||sanitization|| vulnerabilities in the script, but upon submitting, it always errors out. Depending on how I choose to modify it, either (a) that the function that needs to be run is not, (b) that parameter validation failed, or (c) error while running code ensure runs with node file.js [which it does just fine]. Going absolutely insane on this one...

west canopy
#

^ yes if anyone wants to carry me through the second half of Secure Coding, i am accepting volunteers ๐Ÿ™‚

fossil crescent
west canopy
#

Awww thanks bud! I might take you up on that in the future if thats ok

fossil crescent
# west canopy Awww thanks bud! I might take you up on that in the future if thats ok

No worries, sounds good. Will say that if you go back to re-read/re-review the appropriate section(s) with a fine-tooth comb, it starts to make sense (kinda). Enough at least that I again managed to solve everything (but that last question on skills assessment). NOT easy, had numerous windows open (thank goodness for dual large monitors).

west canopy
#

I think i am on custom decoder right now

#

but i have the javascript all unpacked and i have a bunch of variables renamed to something more human readable

#

so i am thinking it should be smooth moving forward

#

And i skipped ahead and did the first question of the Skill Assessment because it was low hanging fruit

hot raptor
#

Hola alguna habla espaรฑol? Reciรฉn estoy empezando:โ€™)

rustic sage
#

How to have a role

west canopy
mortal basin
floral crow
#

damn LFI skills assessment

low hinge
#

Hi. I'm stuck on "Attacking FTP". I've found a first user/password which give me access over FTP and SMB and then SSH. I have the name of the second user but was not able to bruteforce the password using the given list. Any hint ? Thanks,

floral crow
#

what format is the password hashed in ?

vale salmon
#

I'm a tad stuck on Password Attacks/Finding the Credentials for MySQL. Not sure where to start with the credentials I currently have. Maybe a nudge the right way?

velvet gulch
#

Hi all, have a question on the HTTP module. Question asks to use cURL to download a file from 'the server shown above'. Is that the server in the examples (inlanefreight.com) or a server in the terminal or something else? Thanks for the help.

velvet gulch
polar zodiac
#

Hello I'm pretty new here

vivid lance
languid dawn
copper creek
#

Is there a standard way to let kerbrute just output all enumerated users into a file One per line? Like valid_users.txt?

#

Maybe I'm just blind

vale salmon
#

Could anyone possibly nudge me in the right direction on Password Attacks - Default Credentials? I am not entirely sure how to use the previous credentials to snag the MySQL credentials, especially since MySQL seems to not be running.

low hinge
tight mesa
#

hello, I'm really stuck with SSRF skill assessment, anyone who can give me a hint..!!!

vale salmon
low hinge
vale salmon
low hinge
lethal atlas
#

What section in password attacks?

vale salmon
vale salmon
lethal atlas
#

Agreed

vale salmon
tight mesa
#

anyone who can share with me a SSRF skill assessment hint

rancid imp
#

Im still confused to what this even is

low hinge
#

Hi, did you manage eventually to find the flag ? I've managed to find the r user after getting the ssh access with the j user. No luck bruteforcing the password with the given passwords lists.

lethal atlas
#

Can anyone help with intro to assembly?

fossil crescent
low hinge
vital adder
#

i think before in the ftp there is a ssh key and you have to use that to login via ssh and get the flag and i just try the flag is in the r user ||ftp||

low hinge
#

and it's not working for the r user

vital adder
vital adder
copper creek
copper creek
#

In the AD Enumeration Module it says "Windows Defender (or Microsoft Defender after the Windows 10 May 2020 Update) has greatly improved over the years and, by default, will block tools such as PowerView. There are ways to bypass these protections. These ways will be covered in other modules."

Which module covers this? Or is that module not out yet?

west canopy
#

not covered yet

summer lava
#

OK

kind fjord
#

Hi! Iโ€™m new here and im a beginner. Iโ€™m stuck with the first lab in Sqlmap essentials, the Case4 (last question). Anyone know how to do it? if yes dm please ๐Ÿ™

raven cairn
#

I love it when the modules foreshadow

#

In the future we should be getting an OSINT staff investigation module

shell carbon
#

Anyone knows a machine without a webserver? then pls tag me. Thanks

west canopy
vale salmon
#

Okay, I'm struggling a bit on the Credential Hunting for Linux in Password Attacks. I can't login with the credentials for Kira via any service so far as I can tell, I can't seem to bruteforce credentials for will. Not sure what I'm not doing.

west canopy
#

@vale salmon try using a mutated version of|| LoveYou1||

vale salmon
dire sentinel
#

Lil stuck on Password Attacks Lab Easy. Able to ssh with a user, thats about it

#

A nudge would be appreciated ๐Ÿ™‚

copper creek
vale salmon
#

This module is kinda making me want to beat my head against the wall. How am I supposed to get access to /etc/shadow without root? (Password Attacks: Passwd, Shadow & Opasswd)

dire sentinel
vale salmon
#

๐Ÿคฆ

vale salmon
#

Is hashcat supposed to take like 40 minutes for one hash?

copper creek
#

Don't recall for it to take that long in that module

vale salmon
#

Hmm. Did you use rockyou.txt as your wordlist?

copper creek
#

Afair barely used rockyou, mostly the provided list or the mutated one

vale salmon
#

Specifically, I'm using hashcat on the unshadowed hashes. If I do the whole file, it tells me almost 4 hours

#

Just the hash I want is roughly an hour

limber hedge
#

I'm going through Windows fundamentals module again, and I noticed somewhat of an issue in 2nd part of it "Operating System Structure"... not sure if anyone else has ran into it, but the non-standard directory it asks for is non-existing, as there is one with different name than what is an accepted answer

#

the non-existing dir which exists there is ||75<REDACTED>02|| whilst the accepted answer is ||c8<REDACTED>75|| (not sure how much I'd be allowed to show here, so if it's too much I'll remove it)

hollow thunder
#

Attacking Common Services | Attacking SMB --> I've used the password list from the resources. Nothing.

#

used jason.. Do I have to mutate the password list. Im going to attempt capital J

hollow thunder
#

Resorted to using metasploit instead of crackmapexec. Not sure if that is intended or not, or even what the difference is

knotty crag
#

guys is signing in hackthebox website safe ?

#

cuz i have been scammed in the past a few times

west canopy
#

for what its worth I signed in earlier today and i'm ok

knotty crag
#

ok

#

one more thing is it necessary to have 16 or 8 gb ram if we are using hackthebox website hacking lab?

west canopy
#

ya u should be good

knotty crag
#

if i use 4g ram

#

is it good

west canopy
#

if you are running a vm that might be cutting it kind of close

#

but if you are using just the browser/pwnbox its probably ok

knotty crag
#

ok

#

thnx

vale salmon
#

Is there a better way to crack the unshadowed hashes from the Password Attacks: Passwd, Shadow, & Opasswd section than using hashcat or john? john says it'll take over an hour and hashcat gets exhausted no matter what password list I use.

west canopy
#

it takes forever

vale salmon
#

That's unfortunate

quasi wave
#

Is Python a good option for bug bounty hunting, exploit dev, wireless hacking, network hacking, SE pentesting, OSINT, etc?

#

Because I get conflicting reviews. I started this Python course and really like it

#

Would C/C++ be better? A lot of people say Python is best choice for cybersecurity but I hear some people say C/C++ is better

rustic sage
#

Can someone help me with the Active Directory skill assessment part II?

indigo marsh
#

@quasi wave I'd say you should start with Python since the learning curve is easier and then it will be easier to learn C++ if you end up needing it.

#

Python is considered the standard for cybersecurity imo

shadow orbit
#

Hi, I have problem with ATTACKING COMMON SERVICES -> Attacking SMB. I can get the credentials for jason, but I can not login to ssh, since I get jason@10.129.210.195: Permission denied (publickey).

idle egret
placid quest
#

@shadow orbit try to login smb

shadow orbit
tawny night
#

Hi guys.

rustic sage
#

should i just learn all the modules

#

from the first to the last tier in order

zealous fiber
#

Need help on windowx x86 buffer overflow - fuzzing parameter. I found the offset and tried everything and got also the length of A until it crashes

#

It ask for the smalest payload size. But when I enter the size of the smallest payload it dosent count? What am I missing?

raven cairn
barren oak
#

I am just starting out and i was wondering if you guys can give me some tips on where and how to start? i want to be a redhat hacker i have a problem knowing where to start

raven cairn
rustic sage
worthy yoke
#

I love this quote from the user data in the Web Attack section "A fool with a tool is still a fool. Always have a goal, a plan & the tool as the enabler." :3

placid quest
#

@barren oak what redhat?

hollow thunder
#

can i get a nudge for logging into mssql in attacking common services? Not working any which way i try it with the credentials given.

rustic sage
#

oath is so broken 2fa is the reason accounts get hacked

wary sky
#

I have a problem with the WEB REQUESTS module
under HyperText Transfer Protocol (HTTP)
in the first and only task I can not understand what I do wrong
I can download the right file, but what to do next I do not know
Please help me

vale salmon
#

Did anyone who did Password Attacks: Protected Archives have issues cracking the hash on the Zip Archive? I've tried zip2john, hashcat, and fcrackzip and had no luck.

vocal parcel
#

For Starting Point: Responder, I'm not getting a response when I run Responder. I'm running Kali on a virtual machine and have a eth0 address but no tun0 address

west canopy
#

@vale salmon i was able to crack it fine with john and ||mut_password.list||

vital adder
hollow thunder
west canopy
#

but think of how much you learned

hollow thunder
#

LOL

west canopy
#

๐Ÿ™‚

hollow thunder
#

I was doing this last night, and went right back after it this morning, and decided to stop and watch football before I drive myself insane, and i just now noticed

#

i guess the lesson learned is don't forget some breaks haha

west canopy
#

ya when i am tired i start overlooking simple stuff

vale salmon
arctic acorn
#

Could someone clarify the wordlist to use for Passwd, shadow & Opasswd for Password attacks for the shadow root hash? I've tried the obvious small ones with no results and rockyou is taking a while.

west canopy
#

@arctic acorn should be able to crack it with|| mut_password.list||

mystic fern
#

Haveing a bit of a issue on a hash word list combination attack

#

The module is combination attack

#

I see i am useing the wrong word list

livid pier
#

im trying to do the pivoting module, Double pivots section and it looks like the proxifier website is down, anyone have this problem and or solution?

arctic acorn
mystic fern
#

Can anone tell me what is wrong with the command i am typing. Its the mask attack section

west canopy
#

@mystic fern if u send me a screenshot i can take a look

twilit cipher
#

Anyone around here completed the File Upload assessment I can bounce some ideas off of?

twilit cipher
#

Seems like I'm not the only one getting stuck here. I have interrupted a valid POST request and modified it by inserting php code after the magic byte (I've done this for both PNG and JPG file types), I am bypassing all of the filters, including the MIME type actually. I can see the file on the remote server, but the php code is not being executed. I have tried many different php file extensions as well:
.pht, .phpt, .phtml, .php3, .php4, .php5, .php6, .php7, .phps, .phar
Nothing seems to work! And I absolutely know I am overlooking something very silly and stupid. Because that;s just how I roll....

twilit cipher
#

NVM, I tried harder......

#

That's 3 days of my life I'll never get back, and it was something stupid. ๐Ÿ™„

#

It's like when I finally break down and get outside my comfort zone and ask for help, the answer just appears.

vale salmon
#

Alright, so I'm working the Password Attacks Easy Lab. I'm trying to use hydra to get any credentials, but it takes forever and my target timer ends up expiring, even if I refresh the target.

#

What am I doing wrong?

#

I am using the username.list and password.list provided in Resources

west canopy
#

try attacking|| ftp|| and crank up the tasks so it runs faster ๐Ÿ™‚

vale salmon
#

Past ||16|| tasks?

west canopy
#

i think you can go up to 64 with no problems

vale salmon
#

Ah, word

#

I didn't realize I could bump the tasks that high. Thanks.

west canopy
#

np!

vale salmon
#

Also, is it just me or does the Time Left for the target speed up when using something like hydra?

west canopy
#

i dont recall that happening to me

#

how long have you been awake?

vale salmon
#

Lol, I just got home. I started with a fresh target at 90 minutes and in the span of 5 minutes it has dropped to 65 minutes.

#

I know my sense of time is a bit screwy, but it isn't that bad

west canopy
#

haha i remember being up all night on the medium lab

#

but it was great because i had so many ideas and my mind was racing

vale salmon
#

Oh yeah, I was up until 2am this morning getting through the rest of Password Attacks

tawny night
#

your mind was racing or it became a monkey mind like mine?

west canopy
#

its hard to say

#

because even a monkey can write shakespeare

#

given enough time and entropy in the universe

#

i managed to solve it though

vale salmon
#

I have ADHD so I hyperfocus anyway

west canopy
#

the hard lab had me stuck for a few days

tawny night
#

I doubt that. Shakespare miind still hass some kind of focus

#

in this info age, i beleive we all have ADHD. paradox of choices and endless distractions

vale salmon
#

To some degree, yes, but I got a diagnosis as a child, so around 30 years ago.

#

This period of time just gives me plenty of things to hyperfocus on

tawny night
#

You're lucky. In my society, mental illnesses are defined as possessions by some unhuman creatures. So we sort it out on our own.

vale salmon
#

Yeah, I feel very bad for everyone who grew up in a situation like that. I am exceptionally lucky, too, that ADHD is the only thing I have to cope with.

tawny night
#

yup. Transcendence is rare emotion to experience these days

mystic fern
vale salmon
#

In order to use id_rsa for login to SSH, it's permissions have to be set to 700, yes?

livid pier
#

i think 700 is for .ssh folder

vale salmon
#

Ah, excellent

raven cairn
raven cairn
mystic fern
raven cairn
#

Self discipline is rough man ๐Ÿ˜…

#

You have to have a lot of it if you like hacking

vale salmon
#

That's the damn truth

#

The problem with hyperfocus is that you constantly run the risk of burnout. That is where my struggle is.

tawny night
vale salmon
#

Could I pick someone's brain about the Password Attacks Medium Lab real quick?

raven cairn
#

Also for the password attacks module, are we given a certain wordlist???

vital adder
vital adder
raven cairn
vital adder
#

i think i use crackmapexec for winrm

raven cairn
#

@vital adder Did this happen to you?

west canopy
#

try installing with gem
Edit: Disregard

vital adder
#

or pip3

west canopy
#

derpp for some reason i was thinking evil-winrm

raven cairn
#

Installed with pip. Weird, I swear I am using this tool right...

vital adder
#

that's weird i try run the same command to test something out and it will not stop on success i don't know to make it do that

raven cairn
#

going to reset target. Maybe that will work

#

How long should I expect for crackmapexec to give me the password? The cracking on the hydra module was relatively quick

vital adder
#

i would about 5-7 minutes maybe or maybe longer but i have no idea how to make it stop on success so watch out for that

stray grove
vital adder
#

but i need verbose and | grep "Pwn3d!" is better

mystic fern
#

Im back

raven cairn
#

Ugg this password attacks module is kicking my ass

#

I don't know if I am approaching things from the wrong angle, or if I am being too impatient with my hydra scans

#

Under the password mutations section, am I doing this right?

#

It sucks cause I 100% understand the theory

vital adder
#

the password for that is over 17000 so...

raven cairn
vital adder
#

the password for that user is over 17000 word deep in the mutated wordlist

novel swan
#

hi

vital adder
#

if it is taking to long try to cut the first 17000 word

novel swan
#

I can do a botnet stress test to people who are interested in security

tender marlin
#

On the getting set up module and it wont accept the right answer, It says "what does linux PAM stand for" I put in both Pluggable authentication Modules and Privilege access management and they both didnt work

livid pier
#

There is a module that gives a recommendation for a program that can draw networks, does anyone remember what the mod or program is?

plain coral
zealous fiber
#

Can someone help me with this question: Try to fuzz the program with '.wav' files of increments of 1000 bytes '1000, 2000, 3000...', and find the smallest payload size that crashes the program and overwrites EIP with '41414141'. On the Windows Stack Based Buffer Overflow module

wary jetty
glossy maple
#

Hi Guys, im stuck at Credential hunting for linux. i have tried bruteforcing several ways, still no lucks. HELP!

arctic acorn
timber hatch
#

Hello together

I am currently on the Windows Fundamental course. In the section NTFS vs. Share Permissions I am supposed to mount to the share - with the following command:

sudo mount -t cifs -o username=htb-student,password=Academy_WinFun! //10.129.201.57/"Company Data" /home/user/Desktop/

But then I get the message
mount: /home/user/Desktop/: mount point does not exist

Next, I adjusted the path in the command:
sudo mount -t cifs -o username=htb-student,password=Academy_WinFun! //10.129.201.57/"Company Data" C:\Users\htb-student\Desktop

But the same message still comes up.

I have to add that if I get an error message I should install cifs utils with sudo apt-get install cifs-utils, but I also get an error message saying ackage cifs-utils is not available, but is referred to by another package.

Does anyone have an idea where I should start in order to get further?

pliant sage
#

could anybody help me figure out the medium lab from the enumeration with nmap module in academy?
i've tried every possible flag with nmap but I just can't get the version of the dns service running on the machine

west canopy
#

@pliant sage i had to use pwnbox to get the answer , i couldnt get it from my VM. feel free to DM if you need help ๐Ÿ™‚

acoustic owl
acoustic owl
rugged stag
#

(Login Form Attacks:) Have you been able to solve this by any chance? I have the same problem. Hydra finds the user:pass pair, but the login doesn't work. Am I missing something here?

woven hollow
#

Can anyone assist with the attacking FTP module? I've found user J and their password. I've also found user R but have been unable to bruteforce their password with provided/known wordlists. I can ssh with J but have been unable to find any clues for what R's password may be.

acoustic owl
woven hollow
acoustic owl
tender marlin
#

Yo how long would it take for someone to start earning money via bug bounties

fleet eagle
#

in the vulnerability assessment module I can't download the right tool

acoustic owl
fleet eagle
#

I do it from my host

acoustic owl
#

From here the page can be reached

fleet eagle
#

idk I get a "no access" message when I try to access any subdomain

#

All the more reason not to register

acoustic owl
#

What exactly are you trying to do?
When you enter the URL in your browser, the page is not loaded?

Which subdomain do you want to access and from where do you want to access it?

fleet eagle
#

I just want to open the site, preferably open the list of plugins, but I can't do either

#

even from under the console the site rejects requests

acoustic owl
#

Is a firewall in your network blocking access? DNS resolves correctly?

fleet eagle
#

yes, i check it

#

Could the problem be that I'm from Russia?

lethal latch
#

Anyone able to help me out with the medium footprinting lab? I'm hitting a wall

tender marlin
#

@plain coral I tried it for both and it didnt work, EDIT: I think there was a spelling or caps error cause it just worked

sturdy igloo
#

can anyone provide assistance. footprinting hard lab. found snmp is open and tried creating wordlists from NIXHARD and all seclists wordlists but no luck.

acoustic owl
fleet eagle
#

Yes, the site blocks any connection from Russia, cool
Anyway, thanks for your help.

sturdy igloo
mystic fern
#

I need help is anyone free to help me with the hybrid mode section of the cracking passwords with hashcat module

eternal violet
#

Can anybody help me please?

#

Im trying to change a meterpreter shell to a cmd shell using the "shell" command in the meterpreter session

#

but everytime it says |D-chain|-<>-127.0.0.1:9050-<><>-127.0.0.1:42893-<--denied

west canopy
eternal violet
west canopy
#

sure but i dont know if i have a solution for you haha

spark maple
#

hi every one i m new here and i want learn hacking , can you help me

rustic sage
#

Is privacy a myth? If system was meant to be secured, enigma wouldn't have broken.

acoustic owl
spark maple
#

ok tnx

spark maple
quaint fiber
#

That is the "Welcome to HTB Academy" Module, should help get you in the right direction.

acoustic owl
#

A few modules can be taken for free.

#

When you register you get 50 cubes and can unlock certain modules with them. When you have completed the module and answered all the questions, you get back a certain number of cubes. With this you can then complete further modules.

lapis pivot
#

Hi everyone ๐Ÿ˜œ๐Ÿ‘‹ ... Web proxies mod there is question saying try to look for other flag in other directory ... I have checked all that directory but only one flag I got

west canopy
lapis pivot
#

I will show you what dir I have got

#

No such dir found

west canopy
#

which directory is at the top of the linux file structure?

lapis pivot
#

Tnx you jarednexgent.. you solve my problem ๐Ÿต๏ธ๐ŸŒธ๐Ÿต๏ธ๐ŸŒธ

sturdy igloo
#

help. footprinting lab hard. i am logged in as tom. any advise on what should be my path or am i down the wrong path

west canopy
#

@sturdy igloo check and see ||what service(s) might be running locally on the machine... something like a database maybe?||

sturdy igloo
dire sentinel
#

curious... anyone in here passed OSCP after using HTB academy? With practicing in the pwk and HTB too of course.

dire sentinel
#

||Test ||

#

Password Attacks Lab - Medium: Have user ||jason|| and am able to ||dump keys and contents of one .tdb database||. Stuck past that, nudge would be appreciated ๐Ÿ™‚

acoustic owl
west canopy
#

i saw that

lethal latch
#

Could anyone help me out with the hard footprinting lab? ||I found creds to login to imaps but now im stuck||

unkempt flame
#

guys can i hack games?

rustic sage
#

If u have skill

unkempt flame
#

oh

rustic sage
#

Yes

unkempt flame
#

roblox?

rustic sage
#

Nah, I think it's too safe

#

But u can create exploit

unkempt flame
#

can u hack it for me?

#

idk how

west canopy
#

can u teach me to hack?

rustic sage
#

Youtube

unkempt flame
unkempt flame
autumn pilot
#

@unkempt flame please read the rules before engaging in any conversation #rules

unkempt flame
#

wha

#

oh

#

ok

#

anyone can hack roblox fr me?

autumn pilot
#

++kick @unkempt flame

little whaleBOT
#

๊งไน‚|Sฬดอ›ฬœaฬตฬ‰อ„pฬทอ’อ‚nฬตฬŽอŠaฬธฬ‚ฬpฬถอ›อ|ไน‚๊ง‚โ„ข got the boot!

unkempt flame
#

hi

#

no

#

dont

languid dawn
#

hello, please don't ask for anything illegal

autumn pilot
#

if you try to ask again to hack anything you will be banned

unkempt flame
#

what

#

this server should be illegal then

autumn pilot
#

changing your username won't change your identity

unkempt flame
#

u told to change ma name

languid dawn
unkempt flame
west canopy
#

i love everything about this

unkempt flame
#

ok

rustic sage
#

Ayo why is asking for help illegal and Hacking is not in this group?

unkempt flame
#

i need justice

languid dawn
#

asking for help hacking a game company is illegal

unkempt flame
#

then what are u doin?

rustic sage
#

And Hacking is not?

autumn pilot
#

you need the #rules and discord tos, and to not forget the service that you are going to use TOS

#

not justice

languid dawn
#

if you want to make game cheats I suggest going to UC, otherwise we only entertain technical questions

unkempt flame
#

whats UC?

languid dawn
#

or try out our gampwn challenges!

unkempt flame
#

what

unkempt flame
languid dawn
unkempt flame
#

k

#

this is complicated

#

ima leave

languid dawn
#

yes hacking is complicated...

#

that's why we have this platform, to learn progressively

#

and get help and guidance when we're stuck

rustic sage
#

DNS fail in HTB Academy Boxes ?

When trying to enumerate a domain behind a specific DNS/Name-Server , then this DNS-Server should have open port 53, right ??

hollow thunder
#

Need a Nudge for Attacking Common Services SQL. Got mssqlsrv creds but looking for a nudge. Dug into the flagDB but not getting any content from it.

vital adder
jovial viper
vital adder
#

did you try this command ||SELECT * FROM tb_flag|| ?

hollow thunder
#

while I have you here let me spin it up and DM u, but Iโ€™m almost certain I did

vital adder
#

sure

gloomy tangle
#

Hi. Having problem on STACK-BASED BUFFER OVERFLOWS ON WINDOWS X86 Final Assestment. Someone finished it? DM please

cerulean adder
#

Hello, I can't get past the privileged groups section, I grep the /var/log directories and I get a flag but it doesn't

timber hatch
#

Anybody know if there also is a modul for malware analysis?

rustic sage
#

I am stuck on file upload attacks modules skills assessment, got to point where I can upload file to server (and find it after the name modification) but I cannot give it any commands as it is .jpeg. how should I continue from here?

brave prawn
fiery berry
#

Hi, I'm stuck at the module "Attack Common Services - Skill Assessment Medium". Did a scan with nmap first on the top and then on all ports and I'm getting 4 services. However the enumeration did on them didn't get me anywhere. Any tip? Thanks

copper creek
#

looking for a nudge on how to find valid ad users in the ad skills assessment I

brave prawn
barren oak
#

yes sorry for replying late

frigid socket
#

hi everyone im stuck at Firewall and IDS/IPS Evasion - Medium Lab in the nmap academy module. The question requires the DNS version number. I found port 53 to be running the DNS service but the nmap script isn't returning output for some reason. What am I doing wrong? any help is super appreciated

copper creek
#

anyone available for a nudge on the first skills assessment of the ad enumeration module?

timber hatch
frigid socket
timber hatch
frigid socket
#

it won't work since

timber hatch
#

really? Stupid question you replaced the ip with yours? Than there should be a Flag at p53 as version number...starts with HTB{Go

rustic sage
#

hi there

#

i would like to ask something about search engine tracker

#

can anyone discuss it with me?

#

for some case, discord being a platform which search engine do their tracker abnormally. does anyone also face it?

#

thx in advance

brave prawn
#

Hey, can anyone help with Password Attacks Medium Lab?

west canopy
#

@brave prawn i might be able to help ๐Ÿ™‚

lapis pivot
#

Hi everyone ๐Ÿ˜€ question saying ... Try running 'auxiliary/scanner/http/http_put' in Metasploit on any website, while routing the traffic through Burp. Once you view the requests sent, what is the last line in the request

#

Last request line connection closed

west canopy
#

@lapis pivot if you can't get it to route through burp... you can actually find the solution ||in the exploit options in metasploit||

rocky pier
#

Can someone point me to correct direction with: Getting started - Knowledge check? I got reverse shell, but have hard time doing privilege escalation. I know with Sudo -l that /usr/bin/php can be run without password, but how can I get it to work? Edit: I get "Tee /usr/bin/php: permission denied"

spark maple
spark maple
#

is there someone who lives in Morocco

copper creek
#

anyone for a nudge on the last question of the ad enumeration skills assessment 1?

west canopy
#

@copper creek DM me ๐Ÿ™‚

lapis pivot
#

@west canopy .. I have checked the options I changed proxi option to 'yes' but still not working

west canopy
#

Look at the options... what three words do you see|| next to FILEDATA?||

lapis pivot
#

Am seeing many options like proxi, rhost ,vhost ,SSL ,path

quartz frost
#

hello i am new here is this channel chat channel?

lapis pivot
#

@west canopy I have set everything ..

#

I tired of this lap ๐Ÿฅบ.. please give me the big hint@west canopy

west canopy
#

one sec

vapid grove
#

hi, in module Linux privilege escalation , section special permissions, i find the file with SUID that is different from their output, but it won't count as correct (in the answer)

edit: found, there's one more in the output

opaque marlin
#

Hi Looking for some guidance on question "Find additional information about the specific share we found previously and submit the customized version of that specific share as the answer" hope someone can help

zealous wadi
#

Hi, I'm looking for some guidance on the Intro to Network Traffic Analysis module. Would anyone be able to assist?

#

Ah there we go nevermind :/

shadow willow
#

||i have the admin panel and know the /ilf_admin/index.php?log=../../../../../../../var/log/nginx/access.log path but ether it is buggy or i do something wrong..||

#

||GET /ilf_admin/index.php?log=../../../../../../../var/log/nginx/access.log&cmd=ls HTTP/1.1 Host: 206.189.113.19:31855 Upgrade-Insecure-Requests: 1 User-Agent: <?php system($_GET["cmd"]); ?> Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.9 Accept-Encoding: gzip, deflate Accept-Language: de-DE,de;q=0.9,en-US;q=0.8,en;q=0.7 Connection: close||

shadow willow
#

god damn wdym ๐Ÿ˜„

#

since I had changed the user-agent header, the log does not spit out anything new

#

no matter what i type in
the header log doesnt change anymore

lethal atlas
#

you may have to respawn and do it again

shadow willow
#

yeah that is the funny thing..
it doesnt work

#

again .. xD

lethal atlas
#

one sec

shadow willow
#

i had this bug a few times already..

#

i click on reset and it resets but the same IP:Port appears

cedar folio
#

can anyone give me a nudge on the assement for file upload attacks? I think im close, just cant seem to get anything thats "executable", i just get "images with errors" - not sure I understand what adding null will do to the filename

knotty dove
#

Keep trying different filenames, and dont worry so much about null bytes

vocal parcel
unreal timber
#

hey guys can we connect academy lab to my kali attackbox ?

#

I tried to connect to my kali using vpn config but it gives this error

west canopy
onyx dust
#

Hello. I am on the module "Using Web Proxies". I am on the Zap Scanner page. After running an active scan with Zap, I should get a hit on a high vulnerability alert. But all I get are medium and low alerts. (And one informational.) I have followed the instructions on the page. (Although I did not update the security certificate as explained earlier in the module, because I am using a Pwnbox and I thought it was pre-configured.)

Does anyone have any advice?

rough mirage
#

hello, my terminal in kali linux on VirtualBox respond by errors even i type the correct commands . hat should i do?

void temple
#

hi

#

where can i purchase voucher for academy hack the box

dire sentinel
dire sentinel
knotty dove
void temple
#

like is there sth like voucher

#

like thm does

dire sentinel
#

THM is a subscription based service. HTB Academy is similar but does an honestly overly confusing "cube" system. You'll need to look at that on your own to get an idea of how it works and what would be best for you

fresh wedge
#

Need help with the metasploit framework meterpreter skill

#

Anyone willing to dm so I can discuss my thoughts?

dire sentinel
rough mirage
rough mirage
knotty dove
#

when I went for a job interview, the technical test they had was simpler than the cbbh path
I'd give that a crack, make sure you understand whats going on, and then you can probably try to sign on with a company

vale salmon
#

Can I possibly get a hint or two on Attacking Common Services: DNS? I've tried everything. Fierce, subbrute, subfinder, dig, gobuster. If I get subdomains, I get a whole lot of them, or I get none at all and I'm trying not to chuck my laptop out the window.

stray grove
#

if you're doing attacking DNS section on Attacking common services, and subbrute or gobuster is taking too long,
there's a shortcut on how to find all available DNS records. ||if you did an nmap scan you'll find there's port 22 open
turns out to be the same box as attacking ftp service. ssh to the box using the same credential you found
for the user robin. ||On footprinting module there's a DNS section and it explains how to access local DNS configuration
||by doing > cat /etc/bind/named.conf.local ||| you'll find all available DNS zones and one of them has the flag.

vale salmon
#

Yeah, I did the DNS footprinting module. I didn't even think to use ||ftp||

solid wedge
#

Hello new here if I have lab questions can I post a snippet

strange silo
#

Thank you for sharing! This is the answer. Bloody typo...

vocal aspen
#

Please who can help email me please. I need to get remote connect on PWN-Box to windows to resolve quetion in windows fundamental.

vital solstice
#

Hi, can someone help me, I can't solve this question What is the FQDN of the host where the last octet ends in "x.x.x.x.203"?

autumn pilot
#

please don't leak your email

vital solstice
#

Please someone help me, I have spent many hours on this.

hollow hinge
vital solstice
#

Footprinting , DNS

feral stump
unreal timber
#

hey guys can anyone help me with the initial access to the AD Enumeration & Attacks - Skills Assessment Part 2

stuck plover
#

guys who can hack an email

languid dawn
#

++kick 969465931791233064 read the #rules next time, don't ask for anything illegal

ebon mural
#

hey

balmy moon
#

Good Morning! Can I get some help with Footprinting SMB. I'm on the last question which is "What is the full path to the SMB share". The hint says C:\ is for only Windows machines.

I've tried variations of:

/Devops/home/sambauser
/home/nobody/sambashare

I've scoured the internet for help, and my last hope is one of you good people.

surreal mortar
#

In the setting up module, I can't exactly follow up all the instructions that are given in it.

#

Because, most of the things that are present in the module and the screenshots with the commands don't work in my VM like it's in the module.

#

there's tool.list file and other files which are shown in the modules but they aren't present in the VM, so like we have to make the files then download the tools or am I missing something?

#

Also, in the Operating Systems category, in Windows, is it recommended to configure the bare metal host or make a VM for it?

copper creek
wintry gorge
#

has anyone completed the LDAP module? i need help on the final question ๐Ÿ˜›

rustic sage
#

what is fingerprinting in terms of browsing and surfing ?

#

@everyone

#

no one ? ๐Ÿ˜ถ

shadow orbit
#

Hi; I have problem with Attacking Common Services - Medium. I can not find a username. I tried with smtp-user-enum and DNS lookup, but no results.

feral stump
#

Fingerprinting in terms of browsing are the techniques used to gather information about a person or an organization (cookies, canvas fingerprint, WebRTC)

In cybersecurity fingerprinting are the techniques used to gather information about the configuration of a system/network or other infrastructure

Enumeration is listing connected device while fingerprinting deep dives further into ports, installed software and service /OS settings

brave prawn
#

could someone help with Password Attacks Hard Lab? I tried to crack masterkey of keepass file, but no success. Also tried crack the password of user D on winrm and smb services, but also no success. Mounting nfs is also unuseful. I am stucked and don't know what to do

vast geyser
#

Hi Could anyone help me about academy.ovpn?

brave prawn
vast geyser
#

@brave prawn Both desktop and Download folder

brave prawn
vast geyser
#

@brave prawn

#

the same error

brave prawn
feral stump
vital adder
shadow orbit
vital adder
#

nope higher

vast geyser
#

but got the same error

vital adder
vital adder
#

so you are using openvpn 2.5.6?

#

oh you are using openvpn 2.5.7

vast geyser
#

I use 2.5.7

vital adder
#

i don't think that is an issue

brave prawn
vital adder
#

the password for that should be a bit over 73000 word in the mutated wordlist

vast geyser
#

Thanks

dire sentinel
#

Happy Wednesday! Would appreciate a little help troubleshooting problems with guestfish - libguestfs

boreal marsh
#

.

mellow turtle
#

Hi i need help with File Inclusion module - PHP Wrappers. Im able to get the flag executing comands with data and input wrappers but i cant get it with expect. The extension is enabled (i search it in apaches php.ini). This is what i tried: curl -s "<IP>:<PORT>/index.php?language=expect://comand". What im doing wrong?

shadow orbit
#

Hi, I have problem with Attacking Common Services - Hard. I can do RDP login with F* ** * user, but I can not login to MSSQL

west canopy
#

@shadow orbit we should be able to connect with ||windows command line sqlcmd :)||

surreal marsh
#

Hi I got a problem with one of skill assessment every single deployed target was accessible through vpn and now when I'm on the assessment it's just "hanging" in the browser. When I tried curl it it shows me a redirection, when I follow redirection it "hanging" on the terminal. I've checked on two different browsers. When I've checked on pwnbox it works fine. Never had that issue before, is it possible that the problem is not on my side?

west canopy
#

@surreal marsh this might sound silly but i would restart your router and download a new vpn.

#

Reason i say this --- when I was going thru Windows Priv Esc, i simply could not move files over to the windows targets. Could not figure out if it was intended or not and it definitely wasn't , but restarting my router fixed it.

surreal marsh
west canopy
#

ah shoot ๐Ÿ˜ฆ

surreal marsh
#

i didn't restarted the router though...

#

I'll try

#

CU in few minutes ๐Ÿ™‚

west canopy
#

yes its worth a shot!

#

goood luck!

surreal marsh
#

thx

#

well that didnt help

#

weird

west canopy
#

what module r u on

#

if its a docker target we shouldn't need vpn connection i dont think

autumn elk
#

For the broken Auth skills assessment none of the passwords I use for login for (s.u) are not working my list was narrowed down to 96 lines. I donโ€™t know if itโ€™s my modified script or I donโ€™t have the right password

#

Can someone give me some help if theyโ€™re free?

surreal marsh
surreal marsh
shadow willow
#

||I have already found a XSS Vector but i cant get it||

#

||and i found a way to get a cookie with a XSS but how should i get the cookie from the admin ?|| ๐Ÿ˜„

west canopy
#

@shadow willow have you played around with ||the api endpoint? If you make a successful api call, which user is revealed? Maybe we can use the api to make that user visit our XSS page....||

west canopy
#

i have my moments ๐Ÿ™‚

copper creek
#

does anyone know the correct formatting for reporting module on the first tmux question?

fossil crescent
#

[Key] + [Key] + [Key] -- (etc) -- if you look at the part in the sentence that begins "Once in the session, type" you'll have a better understanding of what I'm saying -- @copper creek

west canopy
#

i need a tmux guru to teach me how to scroll while in copy mode

storm flower
west canopy
#

let me try this , thank you!

Edit: no dice ๐Ÿ˜ฆ thanks tho

mellow turtle
#

Do someone has pass the HTB Certified Bug Bounty Hunter?

storm flower
west canopy
#

Like if i wanted to copy everything , 1 through 100? I don't get why i can't figure this out. Also i dont know if it matters but i cant use my page up or page down keys on my laptop

storm flower
west canopy
#

or if i enable mouse scrolling in the conf file, then the copy/paste doesnt work haha

storm flower
#

maybe you need a specific config option

#

setw -g mode-keys vi in your tmux.conf

west canopy
#

EDIT: i think we might be gucci!

storm flower
#

nice

west canopy
#

so to copy i just press enter right?

#

is it normal for my ctrl-shift-v to not work when pasting?

storm flower
#

yes

#

i think

#

i don't know the default shortcut but i added this to my tmux.conf

bind -T copy-mode-vi v send -X begin-selection                                  
bind -T copy-mode-vi y send -X copy-selection-and-cancel
#

to copy with y

#

only works if vi mode is enabled

west canopy
#

gotcha

#

thanks for your help ๐Ÿ™‚

storm flower
#

np, hope you can copy as much as you want now

#

hehe

cunning oak
#

hello guys can someone help in this questions i am stuck on it in footprinting-SMB

#

What is the full system path of that specific share?

rustic sage
#

Hello everyone. As much as I hate to admit this, I am completely new at everything within HTB. I'm currently working in Linux Fundamentals and I am completely lost with the questions in section, "System Information". The first 2 questions I was able to solve. The rest, well for whatever reason I am completely stumped in how to figure out the answers. I have looked and looked and looked and I'm just lost at this point. Anyone with a little advice or suggestions would greatly be appreciated.

west canopy
#

@rustic sage i might be able to help, feel free to DM ๐Ÿ™‚

zenith osprey
#

I'm having a problem with http request module...

#

it says to look for a Flag request in devtools, but none come up, a 404 comes up as the last request

#

along with a bunch of pngs

#

404 get FaviconLoader.jsm is the last thing loaded, no file called flag

raven cairn
#

@west canopy Watch the ippsecc tmux video I sent you a while ago ๐Ÿคฃ

west canopy
#

it did not work yaoi

#

it just was not meant to be , and thats ok

#

i will slowly make new tabs in QTerminal , and somehow find a way to survive without nested SSH sessions

#

and i can scroll with my mouse while copy and pasting. I mean i get tmux is great, but this is basically a super power

#

imagine using a mouse in 2022

raven cairn
#

based

west canopy
#

its true bro they r trying 2 censor me

long plover
#

hello

#

i need help

#

LInux fundamentals

#

what is the path of the email ???

#

plss

west canopy
#

@long plover try running the|| env|| command and read the output carefully... it looks like|| there is a variable called MAIL...?||

long plover
#

tanks

#

thanks*

west canopy
#

np !

long plover
#

i will try it

#

work it

#

thanks a lot!!

half tiger
#

hey

vale salmon
#

Could someone DM me about Attacking Common Services: DNS? I'm still having issues and I don't still have credentials from previous sections, so I can't shortcut it. Nvm. I /finally/ found it

vale salmon
#

Okay so with Attacking Common Services: Email, I have the credentials, but how do I go about accessing the account?

stray grove
sage yew
earnest aspen
#

Hi I'm struggling with the Skills Assessment - File Inclusion. I already read here that there is an admin panel at|| /ilf_admin/ ||How did you find it though? I tried multiple wordlists. Thanks for your help!

earnest aspen
vital adder
earnest aspen
dawn fable
#

save

earnest aspen
vital adder
#

no the vulnerable parameter isn't contact.php and also i didn't fuzz anything i just found the vuln and read the file hint with ||base64||

idle juniper
#

Hi everyone. I'm stuck with SQLMAP ESSENTIALS - Skills Assessment. I've gone through a lot of hints and I'm pretty sure it is not much I'm missing, but I can't figure out the right sqlmap options to find a working sqli. I'm attacking action.php with an json payload and I am using the tamper script mentioned in this chatroom. DM appreciated

vital adder
earnest aspen
idle juniper
idle juniper
dire flint
#

How to solve the EXE program by angr

gloomy tangle
#

Hi guys. Anyone who finished Documentation & Reporting Practice Lab Section from Documentation & Reporting module? Cant solve second question on "After achieving Domain Admin, submit the NTLM hash of the KRBTGT account"

balmy moon
#

Good Morning! Will someone be as so kind to help me with the DNS module under FOOTPRINTING? Trying to find the FQDN name for the host ending in .203.

I have tried to run the discovery script with the firerce word list and it still doesn't give me the required IP.

rustic sage
languid dawn
#

Means it's probably in a very short and well known password list

#

That might be available in seclist

placid quest
#

@balmy moon try zone transfer

#

@languid dawn try welcome2

balmy moon
#

Thanks! @placid quest and a huge lift from @feral stump!

balmy moon
#

Okay here is a solid for someone in /Footprinting/SMTP section.

Start from the bottom of the list!!

so painful, lol, I can type VRFY pretty competently now.

surreal mortar
#

Hello, I wanted to ask that in the "Setting Up" module, the instructions are given to download windows 10 devVM but I have downloaded the windows 11 devVM which was available on the microsoft website. Will the instructions be followed up to windows 11 too or just windows 10?

#

Anyone?

hallow otter
#

Thank you for this. Keep in mind that ZAP seems NOT to add Content-Type when switching methods via DROPDOWN. I opened a feature request for this and I may even fix it myself, I consider this to be a huge bug https://github.com/zaproxy/zaproxy/issues/7440

GitHub

Is your feature request related to a problem? Please describe. Opening a GET request with the request editor and switching the method with the dropdown from GET to POST moves the query parameters t...

narrow sable
#

Find all TCP ports on your target. Submit the total number of found TCP ports as the answer. ___

nmap -Pn -p- 10.129.245.214

All 65535 scanned ports on 10.129.245.214 are in ignored states.
Not shown: 63725 filtered tcp ports (no-response), 1810 filtered tcp ports (host-unreach).

Put 65535. WRONG!
Put 1810. WRONG!
Put 63725. WRONG!

Help me...

onyx dust
#

Hello. Stuck on one question in "Using Web Proxies". The question is:
Run ZAP Scanner on the target above to identify directories and potential vulnerabilities. Once you find the high-level vulnerability, try to use it to read the flag at '/flag.txt'

I ran the ZAP Scanner, a spider, and an AJAX spider. Nothing is giving me a high level alert. Also, my ZAP HUD is viewable, but unresponsive. I'm using a Pwnbox. Does anyone have any suggestions on how to scan for the high level alert?

narrow sable
onyx dust
#

Yes indeed.

#

Using Web Proxies, Zap Scanner.

lethal atlas
lethal atlas
onyx dust
merry kestrel
#

Hi

snow mirage
#

Having trouble with the windows module section: NTFS vs. Share Permissions. Cannot connect to the smbclient I keep getting the same error. Is the SMBclient hackthebox uses outdated? if so that would explain why the syntax may not be working. If anyone knows what Im doing wrong please let me know

#

I cant post the screenshot here for some reason. :v

Im doing this : smbclient -L 10.129.148.11 -U htb-student
do_connect: Connection to 10.129.148.11 failed (Error NT_STATUS_IO_TIMEOUT)

lethal atlas
snow mirage
#

same error code

lethal atlas
#

sounds like an issue with the target. Respawn and try again

snow mirage
#

the new target gives the same error

#

smbclient -L 10.129.105.173 -U htb-student
do_connect: Connection to 10.129.105.173 failed (Error NT_STATUS_IO_TIMEOUT)

lethal atlas
#

is this pwnbox?

snow mirage
#

openvpn

lethal atlas
#

im not sure why you are using smbclient in this section. It calls for you to rdp to the server

snow mirage
#

It says in the section that they are doing to do SMBclient in the pwnbox so I was trying to follow along so I could see how everything works with one another

lethal atlas
#

did you create the share like they did?

snow mirage
#

I did create the share yeah

#

thats as far as I got

lethal atlas
#

hmm I just fired it up, created the share and sure enough cant reach it. Running nmap now to see if the ports are even open

#

yeah, no smb ports open on the server.

#

oh wait, the section tells you that windows defender is blocking smb connections.

snow mirage
#

Ah gotcha. I'll read things more carefully

#

Thank you for telling me that although my eyes should've caught that

lethal atlas
#

yep that was the issue. can connect now

paper crest
#

Hi all, who has passed Windows Privesc? Passing the module User Account Control , I downloaded the dll in the right path , then I run the tutorial SystemPropertiesAdvanced.exe , but nothing happens , who faced with this , tell me how you solve it ?

foggy stirrup
#

hi can someone help me with AD enum

#

I ran powerview

#

Get DomainAcls

#

results came back

#

no ACEs on the group in question

narrow sable
west canopy
#

@narrow sable working fine on my end

#

maybe try and reproduce my command and see if you get the same results

narrow sable
foggy stirrup
#

nvm got it working

#

thx @west canopy

west canopy
#

np ๐Ÿ™‚

rigid minnow
#

Hi im new to the hack the box academy and am stuck on the SMB section of Footprinting. Could someone walk me through how to do it?

west canopy
#

@rigid minnow which question specifically?

rigid minnow
#

@west canopy "Connect to the discovered share and find the flag.txt file. Submit the contents as the answer." Im not sure where to start for this

west canopy
#

try using ||smbclient or smbmap to discover and then connect to the available share||

narrow sable
west canopy
#

maybe its a pwnbox vs VM thing?

narrow sable
#

You're using pwnbox or VM?

west canopy
#

pwnbox

#

in the example i showed

narrow sable
#

Ah....

#

How to get strong arm?

west canopy
#

Superdrol

narrow sable
#

lol

west canopy
#

actually its genetic

#

my mom has 20 inch arms

narrow sable
#

I want arm of He-Man vhilst hacking criminalistically...

west canopy
#

thats always the end goal

#

imagine being a giga chad + vigilante hacker simultaneously

narrow sable
#

๐Ÿ˜„

#

nmap -sS -p- -Pn- -T5 10.129.246.19 -v
Starting Nmap 7.92 ( https://nmap.org ) at 2022-09-01 13:12 EDT
Happy 25th Birthday to Nmap, may it live to be 125!
Initiating Parallel DNS resolution of 1 host. at 13:12
Completed Parallel DNS resolution of 1 host. at 13:12, 0.02s elapsed
Initiating SYN Stealth Scan at 13:12
Scanning 10.129.246.19 [65535 ports]
SYN Stealth Scan Timing: About 0.91% done
Stats: 0:00:37 elapsed; 0 hosts completed (1 up), 1 undergoing SYN Stealth Scan
SYN Stealth Scan Timing: About 1.10% done; ETC: 14:08 (0:55:31 remaining)
SYN Stealth Scan Timing: About 4.73% done; ETC: 14:07 (0:52:41 remaining)
SYN Stealth Scan Timing: About 9.39% done; ETC: 14:07 (0:49:53 remaining)
SYN Stealth Scan Timing: About 14.31% done; ETC: 14:07 (0:47:06 remaining)
SYN Stealth Scan Timing: About 19.33% done; ETC: 14:06 (0:44:19 remaining)
SYN Stealth Scan Timing: About 24.35% done; ETC: 14:06 (0:41:32 remaining)
10.129.246.19 timed out during SYN Stealth Scan (0 hosts left)
Completed SYN Stealth Scan at 13:27, 900.09s elapsed (1 host timed out)
Nmap scan report for 10.129.246.19
Host is up.
Skipping host 10.129.246.19 due to host timeout
Read data files from: /usr/bin/../share/nmap
Nmap done: 1 IP address (1 host up) scanned in 900.25 seconds
Raw packets sent: 35830 (1.577MB) | Rcvd: 902 (64.944KB)

#

Don't think it worked well

west canopy
#

are you running as root/sudo?

narrow sable
#

HTB Academy gaslighting me again

#

root

west canopy
#

its just a next level IDS/IPS

#

all ports blocked , all the time

#

the target is literally just a brick plugged into a switch

narrow sable
#

lol

west canopy
#

FBI honeypot

#

you shouldn't go around port scanning computers without permission

#

that is the lesson Academy is here to teach you

narrow sable
#

It would be funny if HTB was a regime funded ruse just to frustrate beginner hackers into not going any further.

west canopy
#

you are on a vm right?

narrow sable
#

ye

west canopy
#

are you connected to the vpn?

narrow sable
#

na I turned it off earlier

west canopy
#

need to be connected to hack the box academy vpn

narrow sable
#

I mean

west canopy
#

in order to have network connection with their targets

narrow sable
#

ye I'm connected to that one

west canopy
#

you sure?

narrow sable
#

Ye I just double-checked it but the non-Pn scan gives same result

#

"Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn"

brave prawn
#

how did you figured it out?

west canopy
#

@narrow sable can you ping the target?

#

I am on my kali VM, connected to academy vpn, and I can ping the target

narrow sable
west canopy
#

yea your vpn is not connected i don't think

narrow sable
#

It's connected but I guess the VPN can't connect to the academy stuff... ๐Ÿ˜•

west canopy
#

i would restart your vm and download a new .ovpn file

#

maybe select one for a different region

#

also restart your router ๐Ÿ˜‰

narrow sable
#

thanks I think I'll try this on another day now

#

head is hurtsome

west canopy
#

also if you are running another vpn on your host OS it might mess things up , i need to keep my protonvpn turned off on my winodws host

zealous fiber
#

Hey does someone has time for helping me out on the Pivoting module on the Remote Reverse Port Forwarding with SSH section?

west canopy
#

@zealous fiber i can try, which question(s)?

brave prawn
#

Hey, can someone help with SQL Attacking? After I connect to mssql, there is blank output, whenever I type command

west canopy
#

@brave prawn which module/section? I can test on my end

brave prawn
west canopy
#

ohh now it works .

brave prawn
west canopy
#

logged in as ||mssqlsvc||

#

Are you on the first question?

brave prawn
west canopy
#

well commands are "working" haha

#

at least on my end

brave prawn
#

hm, ok i will reset machine and target, and try it again, thanks a lot

west canopy
#

np ๐Ÿ™‚

rigid minnow
#

I am on the Footprinting module in SMB and stuck on the question "What is the full system path of that specific share?" Ive tried "home/sambauser/sambashare" but it is not correct

west canopy
#

is that the last question of the section?

rigid minnow
#

@west canopy yes

west canopy
#

try using ||rpcclient $> netshareenumall||

rigid minnow
#

Update: I was able to find it! thank you @west canopy

west canopy
#

nice work mate ๐Ÿ™‚

rustic sage
#

Hi Iโ€™m facing a problem with the third question of the web proxy module. I deleted the cookie of the original request and set the cookie space as the position of the payload then i added the decoded cookie as prefix and forst i encoded the payload in base64 and then in ascii hex but I canโ€™t find anything. Can somebody give me a hint?

west canopy
#

@rustic sage DM me

foggy stirrup
#

wtf

#

this box makes rubeus crash

#

when it tries to kerberoast

west canopy
#

@foggy stirrup i think for rubeus kerberoasting we have to specify the domain as well as the user

foggy stirrup
#

but even running /stats breaks it

#

hmm

west canopy
#

for example:

foggy stirrup
#

oh lemme try

#

same error

west canopy
#

Maybe try using powerview to find out which accounts have SPN's and can be kerberoasted?

foggy stirrup
#

but how do i request it

#

if rubeus is broken

#

i know the acc that has it

#

I added the SPN

rustic sage
#

Anyone free to help with The Stack-base buffer overflows on windows x86 module - remote exploitation?
< is the new(/old) semicolon! it was working without it from the Windows VM but not remotely!

rigid minnow
#

how were you able to figure out the NFSW

balmy moon
#

Good Afternoon Good Hackers! May I discuss an issue I'm having with the Footprinting/IMAP/POP3 module?

iron basin
#

Can anyone help with Network Enumeration with Nmap Firewell and IPS/IDS evasion Medium Lab?

slow ruin
silver pagoda
#

What you guy think of having the possibility of adding your comments to the current page u at in a given module?

tight mesa
#

anyone has completed the Session Attacks Module?

cunning oak
#

anyone has completed the footprinting SMB part ?

vital adder