#modules

1 messages ยท Page 9 of 1

loud sapphire
#

so far people have helped me.

I just need to know what i am missing with adm group.

iron basin
#

I do nslookup -type=NS ns.inlanefreight.htb

#

doesnt work, but dig does. but I believe the issue is not mapping the IP address to the hostnames.

lethal atlas
iron basin
#

@lethal atlas still doesn't work

loud sapphire
lethal atlas
iron basin
#

@lethal atlas Yes, not sure why nslookup isn't.

#

I mapped the proper hosts to IPs in /etc/hosts

lethal atlas
#

the target ip

#

nslookup -type=NS inlanefreight.htb <targetip>

iron basin
#

@lethal atlas Thank you! I answered most of the questions already i just wanted to figured out why that tool wasn't working. I tried that earlier but did it with @rustic sageip and this time just tried it with the IP and it worked

iron basin
brave prawn
#

Hey, can someone help with this question in Active Directory Enumeration and Attacks module Assignment 2?

undone belfry
#

hi can u help me too, with this one?

bitter comet
#

I know the answer is in front of me but I'm past the point of overthinking it. I'm stuck on Login brute forcing, assessment - website question #2

rustic sage
#

I believe in you

bitter comet
#

I have the username, but the passlist doesn't turn up anything

vital adder
vital adder
bitter comet
#

I'm almost certain I have the fail string, because I was getting false pos originally, but I haven't gotten them since

vital adder
bitter comet
vital adder
#

oh wait the guy in that video use the same syntax as @bitter comet but his work

bitter comet
#

my fault, and thank you @vital adder @west canopy

cyan parrot
#

Anyone able to give a nudge on Web Service & API Attacks - Skills Assessment? created a custom soap request but script seems to just hang

bitter comet
#

I'm doing the labs in the VMs though, and foxyproxy isn't preinstalled. Guess it makes more sense to do them on my own

west canopy
#

pwnbox should have burp and foxyproxy ready to go

vital adder
bitter comet
little helm
#

So i am doing the "getting started module". I feel like a little kid that is learning all the chess pieces. Loads of fun.

bitter comet
vital adder
west canopy
vital adder
#

and try using the terminal it will spawn you in /root

cyan parrot
vital adder
#

sure

acoustic owl
outer vault
#

Any hints for Footprinting HARD lab? I can't access mysql db, couldn't figure out password(figured out user's group being mysql)

rugged stag
#

Can someone give me a hint in which directory I can find the flag of the Hacking Wordpress - Directory Indexing flag? I've been enumerating directories for 90 mins now and can't find it. Is it really in the /wp-includes/ directory?

maiden kraken
#

how do i hack a google account

#

????????????????????????????

autumn pilot
#

we don't do that here

vital adder
rugged stag
# vital adder "directory listing enabled" mean you can view all file in that directory so find...

Thanks for the hint. Another user here suggested that the flag indeed is in the ||/wp-includes/ ||, so I guess it's my bad to actually believe that. Apart from that, what is the sense in making an exercise that let's you easily go down a path where you waste 90 min with no learning effect at all. Now I'm really good at changing directories after having "practiced" it for 90min. I feel really prepared for the exam now, wohoooo. How would I know that they wouldn't hide the flag in some sub-sub-sub directory of ||wp-includes||? Just one more example of HTB not caring about stating the point of the exercises clearly enough and wasting my (as in "the paying client's") time and money. This is so utterly disrespectful.

I really enjoyed this academy in the beginning, but over time I realize that I've become so frustrated and disheartened about the way the exercises are designed. I don't care if it's hard. It's supposed to be hard, that's how you learn. But "hard" is not the same things as "having no clue about what you actually shoud do". And that problem cannot be solved by just saying "think outside the box" all the time. That's neither helpful nor funny (except for the ones who designed the exercises maybe, I don't know, maybe I just don't get their humor).

vital adder
#

i mean i still lost more brain cell on htb academy then tryhackme

pale oak
#

yeas hi is right

#

watch go ingon

rugged stag
# vital adder yeah some stuff on htb academy is a bit dumb especially the new pwnbox but in th...

You're one of the many nice people here who (thank god) help people like me when the exercises are not made well enough to understand them, so thank you. I'm not arguing against anything you say, and you're absolutely right, in this case, it was clearly stated what they want (not so in many other cases). The problem with this one is that there are just so many folders to look through, and that can take a lot of time with no learning effect at all. So, they should have reduced the amount of possible folders to manually sift through. What good does it do me to do the same (tedious) step 100 times instead of 10 times.

I guess this one was just the last bit that unleashed my rant, there are so many exercises that are either time wasting, or not explained well, or utterly confusing. So, I just couldn't hold it in anymore. It's super disrespectful from HTB's part.

pale oak
#

ARE ANY PEOPLE HEARE WHO CAN TEACH ME ABOUT SOME DENGARUS TOOL OF TERMUX

pale oak
vital adder
vital adder
#

sure

summer lava
#

Please can someone help me with CISCO IOS images..

timber hatch
#

Could somebody help me with the ATTACKING ENTERPRISE NETWORKS Service Enumeration & Exploitation

Question: Enumerate the accessible services and find a flag. Submit the flag value as your answer (flag format: HTB{ }).

I found with Gobuster the login page...tried to fuzz... that did not work... does anybody have a hint for me?

placid quest
#

@timber hatch maybe try sql injection or default passwords

vital adder
#

i would say far but not that far and i would not move on to college there is a lot of cyber security certifications out there i would go for that

robust drift
#

hi somaone that help me with a hit broken authentication bruteforce password please

timber hatch
acoustic owl
brave prawn
pure flint
#

Hello

warped cape
#

Hi, I am stuck on Bruteforcing Cookies in quesiton 2, I have my HTBPERSISTENT cookie decode it using URL and Base64 but after I don't know what I use to have it in plain text ? can someone help me ? ๐Ÿ™‚

timber hatch
#

and at the end the conclusion was, only the webserver is left...

acoustic owl
cyan parrot
#

If anyone was able to get a sqli work on Web Service & API Attacks - Skills Assessment send me a DM. I solved it but with sqli

cobalt meteor
#

hi

#

I need some hackers to help me.

#

I will pay 1-2btc as a thank you.

timber hatch
# acoustic owl The web server is still coming, but is not the right choice for this question

I tried

  1. ftp login with anonmyous; there you see al flag.txt; can't open
  2. trieh ssh connection with the following credentials: admin:admin, root:toor, admin:Welcome, admin:Pass123
  3. Trie to enumerate the smtp server with nmap -p25 --script smtp-enum-users --script-args smpt-enum-users.methods={VRFY} 10.129.68.4
    and nmap -p25 --script smtp-enum-users --script-args smpt-enum-users.methods={VRFY} 10.129.68.4 and nmap -p25 -Pn --script smtp-open-relay 10.129.68.4
  4. connected with telnet; verified with VRFY that the user root exits and also www-data
  5. made connection with telnet to 10.129.68.4 110; tried user www-data; that gives me -ERR [AUTH] Plaintext authentication disallowed on non-secure (SSL/TLS) connections.
  6. tired rpcinfo 10.129.68.4 and have consulted hacktrick but found nothing.

could you give me a hint which number i should further investigate?

storm dagger
cobalt meteor
#

ok

latent sage
#

hello evryone please need someone to help me on the metasploit module precisely on the session and jobs section i have precise question to ask

timber hatch
rustic sage
timber hatch
rustic sage
#

On your end

#

Make sure the folder you connect to ftp from you can write to without sudo

rustic sage
#

Yeah, made that mistake myself!

timber hatch
rustic sage
timber hatch
pliant panther
#

yo question!

#

ive been working on this animation for 4 years though quarter half of it is nearly finished know how to speed up the process?

storm dagger
#

Should probably be changed

#

I've seen like 3 people with this issue already

iron basin
#

Anyone have any advice on how to properly use ffuf? I am on the web information gathering module for HTB academy. Currently on the vhosts part but I am stuck on successfully using ffuf. The following command gives me output error โ€œffuf -w /opt/useful/SecLists/Discovery/DNS/namelist.txt -w www.inlanefreight.htb -H โ€œHost: FUZZโ€ -fs 612โ€

rustic sage
#

FUZZ.inlanefreight.htb

placid quest
#

@iron basin look for the content-length

rustic sage
iron basin
#

@rustic sage I tried that, am I suppose to put that with the -w flag or like this: -H โ€œHost: FUZZ.inlanefreight.htbโ€?

#

ye i have is filter 612 as the module said its the default response length

rustic sage
#

In the host header

placid quest
#

@rustic sage you need to have content-length to use -fs

iron basin
#

@placid quest Ye I am just not able to have it to operate properly

placid quest
#

@iron basin To get the content-length you need to use curl and grep the content-length

rustic sage
#

Or you just run it for a few seconds and see what is coming up most of the time!

#

Which can be useful for fuzzing attempts where the fuzzed input is included in the output and you may need to filter by word or line count

iron basin
#

Hmm, gonna have to keep working on this. @placid quest I am trying this now, Ill keep working on tryin. Thank yall for your help

rustic sage
iron basin
#

@rustic sage No, was working on the web information gathering module. Think ima go give it a gander cause I finally got ffuf to work but still a little confused.

worthy laurel
#

Hey Guys,

Going through the Priv Escalation Module. I am trying to follow this based on the description given. I was able to SSH in and after 1 hour transfer my linpeas.sh file over. But failed due to having no permissions. I managed to get access using chmod but it didn't seem to do anything when i run the file.

Looks like i run out of time and had to reset the box. Now i can't seem to scp it over. Once the command has bee run, nothing shows up on the victim's box like it did before. Am i doing this section correctly?

Just need a nudge in the correct direction.

https://academy.hackthebox.com/module/77/section/844#questionsDiv << Link to module

west canopy
worthy laurel
west canopy
#

we should be able complete the exercises using techniques shown in the section ๐Ÿ˜‰

worthy laurel
#

yeah it showing to use Enumeration Scripts, which is what i was attempting. But must be another way to do so

rustic sage
#

You should be able to upload the script using a simple webserver on your vm and wget it from the target

worthy laurel
#

yeah i tried that, but just get a returned connection error

rustic sage
#

I don't remember the exact process, have you tried using a common port like 80 for the webserver?

worthy laurel
#

Yeah just get a ``unable to resolve host address`

#

Normally i would just look via nmap but the IP doesn't show any ports. shows as offline

rustic sage
#

open ports is not the issue, you're connecting back from the target, so its about ports that are blocked by a firewall

worthy laurel
#

I'll have a dig around, thanks

rustic sage
#

Just loaded it up again, and jared is right. maybe look at how you can enumerate manually?

vague spire
#

hello, i'm new in htb communtiy
i try to do Academy\Windows Fundamentals but i'm stuck at this question :
What is the name of the group that is present in the Company Data Share Permissions ACL by default?
i got all other question, can someone help me ?

worthy laurel
#

Yeah i was looking at the now

west canopy
west canopy
vague spire
timber hatch
#

till now at the academy i always used the browser based workstation, is it also possible with the own kali?

west canopy
brave prawn
#

It was interesting for me and i am not sure that such themes are discussed in this channel. Does the Junior Penetration Tester Path make you real junior penetration tester?) And are here any people who got the job after finishing this course and making some machines? I mean this path seems to be kinda hard, but I haven't got experience in this field to know exactly what level it gives to you

placid quest
#

@brave prawn you need to practice more

sturdy igloo
#

how did you solve this?

#

Error running chisel on victim: ./chisel: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.32' not found (required by ./chisel)
anyone can help on how to fix this?

stiff moon
#

use a compiled one

#

i used socks4 i think

#

and use the right binary i took the wron one lmao

west canopy
sturdy igloo
sturdy igloo
stiff moon
sturdy igloo
#

RDP and SOCKS Tunneling with SocksOverRDP - RDP to host with proxifier is taking forever saying "Configuring Remote Session". I have even changed to "modem" under "experience". any suggestions? nevermind

high totem
#

Any nudge on the hard lab in nmap module, please? I think I established the port but I can't get past the firewall.

#

||I think the target port is 990 (ftps). I tried setting source port to 53, using decoys, setting a source ip to some ip which should be in the target's subnet (cannot establish the connection then) and different types of scans (SYN, ACK)||

rugged stag
#

I'm stuck with the Web Service & API skill assessment. I can do the ||SOAP Action spoof||, but I don't know how to go on from there. I tried|| fuzzing the parameters||, but no luck.

I'm confused about how I cut put the steps from the lessons together to solve this. Any help would be very appreciated.

meager solstice
#

Hi

vital adder
vital adder
rugged stag
vital adder
#

hi @cyan parrot @swift dune sorry for the ping but i think i found the intended way of exploiting the sql vuln in "Web Service & API Attacks - Skills Assessment " to get the flag and like the questions said you will need a "proper SQLi payload" mean if you send a request that doesn't have any kind of sql injection payload the server will hang so you can't test with normal cred and you also need to send it in a valid xml format

fair mesa
#

Hello everyone ! I need help on this :
Module (Shells & Payloads) Section
(The live engagement #host

#

the live engagement host#3.
I managed to get an aspx webshell on the target because on its HTTP port we can upload files and execute it.
But the user I land in has no rights at all, I can't move can't upload nothing

#

I tried Windows escalation privilege on Hacktricks but I don't manage to get it

fair mesa
acoustic owl
fair mesa
acoustic owl
fair mesa
#

Ok I will try thanks, coming back !

fair mesa
brave prawn
#

Hey, I have some troubles with Web Proxy Assessment. I am sure that payloads built corretly, but I am not getting even response codes or some bodies with error html. Can someone help me to solve the problem? The result cookies are exactly 88 characters long as they are needed to be

timber hatch
#

hello
i work on the module attacking enterprise network
currently i am at the section Web Application Enumeration and there I try to upload a reverse shell with the help of burp.
when you try to upload than it says php is not allowed, with the help uf burp you cahgne within the repeater the content type to image/png and than you should be able to upload the shell.
I mean the i get a response with 200 status ok...but with curl i am not able to interact with the shell.
so i think it did not work. anybody knows why?

#

when i curl i get the the response 404 not found, so i think the upload with the repeater did not work. but why...?

timber hatch
# acoustic owl Which question are you on?

Web Enumeration & Exploitation is the chapter and than HTTP verb tampering.
i suppose the second question should i be able to answer after i am able to upload a shell

acoustic owl
#

This Question?
Exploit the HTTP verb tampering vulnerability to find a flag. Submit the flag value as your answer (flag format: HTB{})

acoustic owl
#

If so, you can upload a WebShell exactly as explained in the module.
Do step by step exactly what the module shows.

west canopy
#

iirc for the entire web section in Enterprise Networks i was mostly able to just follow and recreate the steps

#

some of the later sections definitely threw me for a loop though

timber hatch
#

yeah i mean i thought i did...that's why i can't explain why it's not working.. ๐Ÿ˜‰
but i'll watch it again ๐Ÿ™‚

#

response:
HTTP/1.1 200 OK
Date: Sat, 17 Sep 2022 14:13:16 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 1
Content-Type: text/html; charset=UTF-8
Via: 1.1 dev.inlanefreight.local
Connection: close

that's the response from the repeater after sending the request with the shell, seems that to be okay?

sly nebula
#

Is there any schedule for upcoming Academy modules?

acoustic owl
west canopy
west canopy
acoustic owl
west canopy
#

let me make sure i wont get in trouble first lol

timber hatch
#

okei I give up. Does not work ๐Ÿ˜‰

west canopy
#

i was a bad boy and named the file shell.php instead of a random hash value

timber hatch
#

thank you...i see my mistake....
It has two Content-Type and I always changed the upper one, but at the bottom it also has one and that should be changed...
Annoying I should have seen...and tried....

west canopy
#

np ๐Ÿ™‚ hope this helps!

twilit cipher
#

Anyone able to help out with the Session Security Assessment. I am pretty sure I am doping the right thing at the provided endpoint. I have the admin browsing to my hosted payload and pick it up, but he's not being very nice and dropping off his cookie like I asked him to...

rugged stag
#

Hey, great advice! Thanks! But when I put the ||XSS payload on Julie Roger's profile|| and test the ||"cookie stealing" by clicking on "share"|| it works great, I see the ||auth-session cookie in the php server log||. But when I request her profile page via the API endpoint, the server log just says|| "GET /script.js"|| and shows nothing else. I must be missing something but I don't see what. Any advice?

west canopy
rugged stag
west canopy
#

maybe ||respawn the target, make the api endpoint visit her page prior to the XSS so it can generate a session cookie, and then try the attack again?||

west canopy
#

we can also do it without ||script.js|| i think , but exactly how to do it and what it looks like i couldnt tell you

rugged stag
shrewd wasp
#

Hello, can anyone help me with the "GET" module from "Web Request" section, I can't find the flag

brave prawn
#

Can I ask someone a question about Attacking Web Apps with Ffuf Assesment?

sturdy igloo
#

help needed if can. stuck on pivot, tunnel skills assessment 5th question "For your next hop enumerate the networks and then utilize a common remote access solution to pivot. Submit the C:\Flag.txt located on the workstation."

#

Transferred |lsass.exe| to my machine but cracking with rockyou provided nothing.

forest fulcrum
#

hey there, need a little nudge on Network Enumeration with Nmap, lab 11 (Firewall and IDS/IPS Evasion - Hard Lab)

#

I've tried all possible decoy combinations, no avail

west canopy
forest fulcrum
#

or am I missing something?

west canopy
#

DM me ๐Ÿ˜‰

forest fulcrum
#

sure

woeful oxide
#

Hey fellow hackers, im stuck at the IDOR enumeration, my bash script is not working and I donโ€™t really understand why, someone could give me a hand?

west canopy
woeful oxide
#

Thatโ€™s right

west canopy
woeful oxide
#

Got it, let me try that

west canopy
woeful oxide
#

It was really easy, thanks @west canopy

rustic sage
#

htb-student is not in the sudoers file. This incident will be reported.

#

why does it keep getting reported

shrewd wasp
#

@west canopy hey, thanks about the GET problem, but could you help me with the next one? "POST"

storm dagger
#

Usually just gets logged somewhere on the machine

rustic sage
rustic sage
#

fr

little helm
brave prawn
#

Is there anybody who have troubles with target machine? Can't ping machine almost 2 hours. Tried to restart hundreds of times, but nothing

placid quest
#

@brave prawn check your vpn

brave prawn
placid quest
#

Change the server of vpn@brave prawn

brave prawn
#

what? i am not using my local machine, but virtual environment by hackthebox

#

I don't understand wtf....

west canopy
brave prawn
novel matrix
#

Targets with port are able to access externally

#

Meaning vpn is not required

brave prawn
little helm
#

after banging my head, i got the root flag on the last section "getting started". that feeling tho

#

Seriously though, knowing what I needed to do, but then getting it to do what I want and get the exact subtle command right. I need a nap

brave prawn
lyric kettle
#

Is anyone able to help with "Active Directory Lab" - the "Credentialed LDAP Enumeration" section. The last question, is asking which userAccountControl bitmask for 2 specific properties. I have validated I have the right decimal values from 3 separate websites, including Microsoft, and no matter what I type, its not accepting the values.

lyric kettle
little helm
modest kraken
#

I think we're all idiots its just matter of being less of one as time goes on

#

or trying to lol

storm dagger
#

I just spent 10 minutes trying to figure out why I couldn't LFI /etc/passwd until I remembered I was on a windows box, so yeah always something silly :D

woven hollow
#

Can anyone assist with common services easy lab? I am having trouble figuring out how to upload my shell to the web server.

novel matrix
vital adder
#

i think that's the common services module skills assessment easy lab

vital adder
rustic sage
#

algum br ai?

rugged stag
#

I have a problem with wpscan (for Hacking Wordpress module, Skill Assessmnet). When I try to scan the target it says, "Scan Aborted: The remote website is up, but does not seem to be running WordPress." (on my VM)

On Pwnbox, I get a ton of error messages (see screenshot).

I researched the problem here, someone said, "it's DNS", but changing my DNS in the network settins didn't help.
Any ideas, anyone? ๐Ÿค”

acoustic owl
vital adder
#

oh wait didn't you already done this section? the last time you ||know that page isn't running wordpress||

rugged stag
rugged stag
vital adder
rugged stag
vital adder
#

ohh

rugged stag
#

Anyone knows where to report the constant crashes of the "File Inclusion" skill assessment machine? At least on my side it crashed every couple of minutes, which makes doing the assignment virtually impossible. I've complained about it in the past and did other assignments meanwhile, but it's still the same. Does anyone know who best to contact about these problems?

mellow turtle
#

Support

brave prawn
#

Hey, can someone test target machine on Attacking Web Application with FFUF Module Assesment? I think there are some technical problems with it...

mellow turtle
#

Skills assesment?

#

@brave prawn

mellow turtle
brave prawn
brave prawn
mellow turtle
#

time limit?

brave prawn
mellow turtle
#

Mine works

#

dm me how you are doing the curl

mellow wind
#

anyone can help me with this question "Crack the following hash: 978078e7845f2fb2e20399d9e80475bc1c275e06 using the mask ?d?s." I tried using hashid to fine the hashing mode but nothing works any hint ?

nimble ridge
#

can someone help me with this question: Enumerate the custom script that is running on the system and submit its output as the answer. It's under the snmp portion of footprinting

coarse dove
#

Hi, im at 'Skills Assessment - WordPress' . And i try to put in the /etc/hosts on my VM not on the HTB VM. I try : 10.129.2.37 blog.inlanefreight.local / 10.129.2.37 inlanefreight.local / 10.129.2.37 inlanefreight.HTB . The page not open โ˜น๏ธ the connection take to long to respond.

west canopy
coarse dove
brave prawn
west canopy
#

sure

west canopy
west canopy
west canopy
coarse dove
west canopy
#

just ip address and domain name

coarse dove
# west canopy

Samething block i do not know wath, i keep search. Tnx for the help. meby the firewall setings

nimble ridge
shrewd wasp
#

Hey, what should I do if the target ip's that HTB gave me are unreachable?

#

I am in the Getting started module, the "service scanning" challenge

placid quest
#

@shrewd wasp change the vpn server

shrewd wasp
#

Should I change from "Us" to "Eu"?

#

Still nmap cant scan it

rugged stag
#

OK, so I'm trying to do the "File Inclusion" skill assignment on the target machine that breaks down every couple of minutes. But I'm eager to get it done since it's the last skill assignment missing for the bounty hunter path.
Problem is, I've spent hours and days going through the stuff in the lesson, but I can't find the injection point or "hidden things" that other commentaries are talking about. Judging from other commentaries it can't be too hard, but I'm just not seeing it.
Any hint would be greatly appreciated. Thanks.

rugged stag
#

Hi, thanks for offering help. Am I right that either the โ€œ||page||โ€ or the โ€œ||message||โ€ parameter must be LFI vulnerable or am I looking in the wrong place? I know that โ€œ||pageโ€ filters commands that contain two โ€œ..โ€||.

vital adder
#

i know you already got help with this in the dm but if you or anyone esle need help with this part there is actually something in the cheat sheet that you can use for this part

#

also one of the parameter that you list are the right one so you may need to put spoiler tag on both

hollow hinge
hollow hinge
twilit cipher
#

I am working on the Hacking Wordpress Assessment, and I have all of the questions answered except for this super vague one:

Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download.

And the hint is a bit silly, can anyone help?

#

I have a stable reverse shell and ran find / -name "*flag*" 2>/dev/null which showed nothing...

#

Nothing I haven't already found, anyway.

twilit cipher
#

Doing grep -rn "HTB{" / 2>/dev/null but I feel as if I am missing something really obvious...

#

Also, I did run the scan with an API token...

#

I found it. ๐Ÿ™„

#

Took a little digging into the results for anyone looking back at this from the future....

ashen orbit
#

In the using web proxies module, setting up proxy chain sock4 with https 127.0.0.1 8080 throws an error even though the instructions say to use that set up?

west canopy
wary basalt
#

Hello happy to Start learning with you ๐Ÿ˜‡

nimble ridge
#

can I get help with this question in footprinting - ipmi: What is the account's cleartext password? I found the hash but I'm unsure how to get it into cleartext. I've tried using the hashcat command as it's given to us but I think I'm missing something

wheat garden
nimble ridge
wheat garden
#

Might want to use just straight worldist attack using switch -a 0 and the popular rockyou.txt wordlist

pine dagger
#

Indeed. Use a standard wordlist.

#

I cracked it with john

wheat garden
#

hashcat -m 7300 -a 0 ipmi.txt <wordlist file path> possibly something like this

nimble ridge
nimble ridge
wheat garden
#

hashcat -m 7300 -a 0 ipmi.txt /usr/share/wordlists/rockyou.txt

#

hashcat -m 7300 -a 0 ipmi.txt /usr/share/wordlists/rockyou.txt thats the default file path to rockyou.txt wordlist in kali

iron basin
#

Hey, is there a word list that parrot or the vm have that is a good word list for vhosts?

west canopy
iron basin
#

Thank you @west canopy

ashen orbit
#

Go pack Go

vale salmon
#

So I'm working on Active Directory Enumeration and Attacks and I'm in the ACL Enumeration section. Trying to figure out the last question, about the ObjectAceType that the forend user has over the GPO Management group. I'm trying to use Get-DomainObjectACL, but it keeps freezing on me. Can anyone give me a quick bit of help?

west canopy
vale salmon
#

Word. I'll look then. Thanks!

odd kayak
#

Heyy frnds ๐Ÿ™Œ๐Ÿป๐Ÿ™Œ๐Ÿป๐Ÿ™Œ๐Ÿป๐Ÿ™Œ๐Ÿป

#

I am new here

#

And I am trying to start my career in cybersecurity......so can anybody help me out to .......

#

How and when should I start my new career ๐Ÿ˜ฌ๐Ÿฅฒ๐Ÿฅฒ

#

Please some of this server suggest me about it๐Ÿฅฒ๐Ÿฅฒ๐Ÿฅฒ๐Ÿฅฒ

vital adder
odd kayak
#

Bruhhh I had already seen these type of stuffss

#

But I want suggest from a Hacker ๐Ÿ˜ฌ๐Ÿ˜ฌ๐Ÿ˜ฌ๐Ÿ˜ฌ

#

That how he /she had started his/her career

red obsidianBOT
languid dawn
#

alternatively, just do CTFs

burnt stone
#

This channel is for HTB Academy

little whaleBOT
#

Please see your DMs for instructions on how to verify your HTB account.

burnt stone
#

@mellow turtle

mellow turtle
#

Sorry ๐Ÿ™‚

sudden shore
#

Having issues with the broken auth module - bruteforcing passwds. I found the minimum policy needed, cant find the right passwd and keep getting rate limited. What am i doing wrong here? Thankss

muted hull
#

Hello, could i get some help please?
I'm trying to do the last question in the getting started module in the service scan section.
For some reason i can't seem to get the flag.txt file but i keep getting the "Error opening local file flag.txt"
Did i miss a step?

sudden shore
#

@muted hull try get * or get . Also maybe do a dir first to check for available files

muted hull
#

I end up with "get <filename> [localname]"

#

does that mean i must put the bob user?
i.e. "get flag.txt bob"
edit: didn't work either

#

woops forgot to include error section

#

well error still the same

sudden shore
#

@muted hull get flag.txt flag.txt

muted hull
#

no cigar

mellow turtle
#

Dm me

#

tropkal

sudden shore
#

I replied to my own post a few minutes ago @mellow turtle

#

I found the pwd but the challenge isnt working properly

mellow turtle
#

A*?

muted hull
#

Oh i see, so i'm not missing something very obvious

#

Cheers

rustic sage
mellow turtle
#

i dont know but ./flag.txt?

#

"get ./flag.txt"

muted hull
#

Not either, but tropkal did say the challenge isn't working properly

#

so it looks like we should give up

mellow turtle
#

i dont think so

muted hull
#

i did try your suggestion though

#

didn't work

mellow turtle
#

I think he said the exercise he was taking isnt working properly

#

try this "get flag.txt /home/{username}/Desktop/flag.txt"

#

maybe its trying to write a file in a folder without permissions

muted hull
#

Oh damn

#

you were correct

mellow turtle
#

Mohit's answer should be correct too

muted hull
#

Why didn't it have permission though

mellow turtle
#

idk, maybe u are trying to write a file in / without root privs

#

i didnt taked that module yet

muted hull
#

heh you certainly know more than me though

#

thanks again

pliant panther
#

i need help on finding someone's ip address

mellow turtle
#

For what @pliant panther

pliant panther
#

spamming accounts

mellow turtle
#

Call the police

pliant panther
#

okay

forest fulcrum
#

hi folks, need a little nudge with exercise 8 in the Footprinting module of the pentester path

#

What is the FQDN of the host where the last octet ends with "x.x.x.203"?

#

I tried all DNS seclist files on pwnbox but no luck

placid quest
#

@forest fulcrum do brute force on dev subdomain

forest fulcrum
#

-.-

#

that should have been in the challenge hints

#

thanks @placid quest

#

one more quick question: where is this list provided exactly?

placid quest
#

@forest fulcrum look on the resources

sudden shore
#

@mellow turtle @muted hull no i wasnt referring to your challenge, i was referring to my own which was pwd bruteforce because after finding out the pwd policy you get around 15 pwds to test and you almost immediately get banned because of โ€œtoo many triesโ€

#

And i dont think that works ok because the good pwd you need to find gets put at the end of the wordlist when you build it so 100% of the time right now youโ€™ll get banned b4 actually trying out the good pwd

#

You shouldnt be banned in a pwd bruteforce challenge after 5 automated requests in a list of 15 like come on

brave prawn
#

Hey, can someone give a hint on SQL Injection Fundamentals Assesment? This module's sections seemed to be easy, but here I can't even login with injection...

placid quest
#

@brave prawn what is the problem

brave prawn
placid quest
#

@brave prawn yeap

brave prawn
eager rivet
#

is anyone online that has completed the Skill Assessment - Broken Authentication? I've got the user and a pass list but must be missing something as nothing in my pass list is working

lethal atlas
#

๐Ÿ™‹โ€โ™‚๏ธ @eager rivet

lethal atlas
muted hull
#

i see

#

how would i do that?

#

i just opened bash and started smbclient

#

wait

#

unless i had to sudo?

mellow turtle
#

chmod or sudo @muted hull

lethal atlas
#

@muted hull before you connect to smb in terminal do cd ~/

#

then execute smbclient and try to get the flag

muted hull
#

i see

#

thank you for the info

hollow hinge
lethal atlas
#

I still need help with the first question of skills assessment in Intro to Assembly Language.

lethal atlas
#

yes

inland shoal
#

What's the question? ๐Ÿ™‚

lethal atlas
#

I have pulled the shellcode out of the data section, but I can decode it as 32 or 64 bit and the 32 bit has commands not discussed in the module.

inland shoal
inland shoal
latent sage
#

please is anyone online that has complete the metasploit module ??

placid quest
#

@latent sage what is the problem

maiden field
#

in the module footprinting in the smb section there's a question that ask to find out which domain the server belongs to. I've been searching and i don't find anything. Can I get a hint ?

brave prawn
placid quest
#

@maiden field use enum4linux

maiden field
latent sage
ripe musk
#

hi can someon help out?
I've been trying to "get" flag.txt from Bob, but it just never downloads. it's speed is 0 and i never get a confirmation for the completion of its download
also, how long does a nmap -p- scan take? it's been over 30mins.

ripe musk
#

yeah, i get that.

raven cairn
#

So it can take a long time. Really depends on what you are scanning

#

Usually you donโ€™t need to do a full port scan tho

ripe musk
#

what about flag.txt?

raven cairn
#

What module is this?

#

@ripe musk

ripe musk
raven cairn
#

In the Nmap module ?

ripe musk
#

yeah, thats what the hint says and thats what the question implies.

raven cairn
#

Dm

pastel isle
#

I'm getting a bit different pwn box

#

like it doesn't have useful repos and all

#

any idea how to get to the previous one

broken warren
#

I could use some assistance with foot printing easy lab (https://academy.hackthebox.com/module/112/section/1078) I've scanned for ports, found three open. scanned the first open one with all nmap scripts and logged onto the service but i can's list any files. I also tried using the given creds to ssh in but obviously that wont work lol.

raven cairn
#

I'm having problem with the ERC plugin in Windows Stack Based-Buffer Overflows 'Controlling EIp' section. I've done buffer overflows many times so I understand that I am supposed to do 'ERC --pattern o B5eB'.

#

However because the ERC plugin isn't working for me I can't get the flag.

arctic acorn
rugged stag
#

Can I DM?

forest fulcrum
#

is anyone having issues with the IMAP exercises?

#

server isnt responding to curl and not showing the correct results with nmap

broken warren
#

I ran "nmap -A <target ip> -p- " on my first scan I'll try running it again though

placid quest
#

@forest fulcrum can you ping the ip

forest fulcrum
#

I can

#

this is not how TLS response should look like

#

and this is curl curl: (35) OpenSSL SSL_connect: Connection reset by peer in connection to 10.129.193.197:993

placid quest
#

@forest fulcrum that looks like nmap results

forest fulcrum
#

shouls look something like this no?

110/tcp open  pop3     Dovecot pop3d
|_pop3-capabilities: AUTH-RESP-CODE SASL STLS TOP UIDL RESP-CODES CAPA PIPELINING
| ssl-cert: Subject: commonName=mail1.inlanefreight.htb/organizationName=Inlanefreight/stateOrProvinceName=California/countryName=US
| Not valid before: 2021-09-19T19:44:58
|_Not valid after:  2295-07-04T19:44:58
143/tcp open  imap     Dovecot imapd
|_imap-capabilities: more have post-login STARTTLS Pre-login capabilities LITERAL+ LOGIN-REFERRALS OK LOGINDISABLEDA0001 SASL-IR ENABLE listed IDLE ID IMAP4rev1
| ssl-cert: Subject: commonName=mail1.inlanefreight.htb/organizationName=Inlanefreight/stateOrProvinceName=California/countryName=US
| Not valid before: 2021-09-19T19:44:58
|_Not valid after:  2295-07-04T19:44:58
993/tcp open  ssl/imap Dovecot imapd
|_imap-capabilities: more have post-login OK capabilities LITERAL+ LOGIN-REFERRALS Pre-login AUTH=PLAINA0001 SASL-IR ENABLE listed IDLE ID IMAP4rev1
| ssl-cert: Subject: commonName=mail1.inlanefreight.htb/organizationName=Inlanefreight/stateOrProvinceName=California/countryName=US
| Not valid before: 2021-09-19T19:44:58
|_Not valid after:  2295-07-04T19:44:58
995/tcp open  ssl/pop3 Dovecot pop3d
|_pop3-capabilities: AUTH-RESP-CODE USER SASL(PLAIN) TOP UIDL RESP-CODES CAPA PIPELINING
| ssl-cert: Subject: commonName=mail1.inlanefreight.htb/organizationName=Inlanefreight/stateOrProvinceName=California/countryName=US
| Not valid before: 2021-09-19T19:44:58
|_Not valid after:  2295-07-04T19:44:58
MAC Address: 00:00:00:00:00:00 (VMware)```
#

cert details contains answers to some of the challenge questions

placid quest
#

Cert has no answers to the questions

forest fulcrum
#

can I DM you?

placid quest
#

Yeap

night pier
#

Need some help with whitebox pentesting syntax errors section. I have the right command connector and I have a successful ping but can't get any other system commands to execute

rustic sage
#

Can someone help me with a question from the web request module?

brazen dust
#

I for some reason can not get a DNS version for the medium module in the NMAP module, I have used multiple flags, scripts and the only version it will come up with the the NLnet Labs NSD as a version an that isn't the right answer

#

$sudo nmap -sSV -p 53 10.129.2.48 -D RND:50
Starting Nmap 7.92 ( https://nmap.org ) at 2022-09-19 15:59 EDT
Nmap scan report for 10.129.2.48
Host is up (0.045s latency).

PORT STATE SERVICE VERSION
53/tcp open domain NLnet Labs NSD

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 6.79 seconds

rustic sage
#

basically i'm running a curl get request on a web server but i'm not getting any output for some reason

placid quest
#

@rustic sage did you read the man page of curl

lethal atlas
shrewd wasp
#

Anyone know i can't connect or ping a machine in a specific challenge?

proud sparrow
#

anyone can help me with "nest" machine? im facing problem with smbclient ??

raven cairn
shrewd wasp
#

Yeap

#

The "Hivemind" bot is actually usefull

pearl island
#

Stuck on the skills assessment for "Shells and Payloads." I have solved 2 machines though. Just need to confirm if I'm on the right track. Any help is appreciated!

hallow osprey
#

Is there voice channels on this discord server?

#

Where people talk

raven cairn
#

What is the issue?

pearl island
# raven cairn What is the issue?

So I was stuck on the second machine. The one where metasploit module was always crashing on some split error. I tried assigning the vhost and it worked.

#

Thanks for offering help though @raven cairn !๐Ÿ˜„

pearl island
#

I have a question regarding machine 3 on "Shells and Payloads." There is an upload functionality on the webpage where you can upload files. I uploaded the Antak web shell and got a working web shell. However, the intended way was to exploit a known vulnerability. My question is, I was unable to view any files under the Administrator directory from the Antak webshell, but could see them very well in the meterpreter shell. How does that happen?

vale salmon
#

So I'm working on the Abusing ACLs section of the Active Directory Enumeration & Attacks and when I attempt to use Set-DomainUserPassword it tells me that it is unable to find user 'damundsen', which would make sense if it didn't seem to be necessary for this section.

livid pier
#

anyone around finish windows priv esc skills 1?

nimble ridge
wheat garden
wheat garden
#

can use a program called hash id using command "hashid -m <hash> "will show the hashcat mode of the hash if it can identify it

nimble ridge
wheat garden
strange silo
#

I've tried every tool, and even found one subdomain with elephants using the SecLists wordlists but it wasn't it. I've found it by using https://subdomainfinder.c99.nl. BUT it isn't at first sight, so I suggest reading all the page

flat silo
#

Hey can anyone help me out with finding the FQDN of an ip I've tried dig and can't get any kind if info

nimble ridge
wheat garden
#

hashcat -m 7300 -a 0 ||4af9ee3a82040000c70d59c758d07070f8805bc997c280c6eb48ba0868237f937bc6e631eed477e6a123456789abcdefa123456789abcdef140561646d696e:32b3335b435c8f8b13c0e23f200735606a654221|| /usr/share/wordlists/rockyou.txt this worked for me

lyric echo
#

Hey! Im stuck on Footprinting DNS last Question. Regarding finding the FQDN of the host the ends with x.x.x.203. Could someone please help? thanks.

covert yew
#

Whatโ€™s best setting up a server with Mac or Linux ?

sudden steppe
#

Can anyone help with Footprinting FTP, Cant get the flag.txt file for the second question. Keep getting 331 Password required. Dont know the pass and cant seem to login anonymously

lyric echo
#

Hey! Im stuck on Footprinting DNS last Question. Regarding finding the FQDN of the host the ends with x.x.x.203. Could someone please help? thanks.

pearl island
mellow wind
#

Hello, I am stuck with sqlmap essentials case#5 I managed to get the flag but when submitting it I get that it is wrong answer

placid quest
#

@lyric echo what is the problem

lyric echo
placid quest
#

@lyric echo you can brute force dev subdomain

warped phoenix
#

Hello, I am stuck with the Password Cracking Skills Assessment Hard. I have the password for the first user and can rdp into the machine. ||However, I am stuck trying to exfiltrate a .kdb file from the machine (blocked by GPO)|| Would anyone be able to point me in the right direction?

vital adder
brave prawn
#

Hey, can someone help with Sqlmap Essentials Skills Assesment? Can't find any POST or GET endpoints to run sqlmap on it(
EDIT: Someone who struggles with it, dm me)

warped cape
#

Hey, I am stuck with BROKEN AUTHENTICATION -> Predictable Reset Token, I added a script to check a token for the htbadmin within an interval of +-1 second (I check in milliseconds *1000) but it not works I also noticed that the timezone is not the same between the machine and the website I tried other timezones but it not works ๐Ÿ˜ฆ Someone can help ? I can show the script in DM

raven cairn
vital adder
crisp remnant
#

Need some help with the stability of the academy targets, where should i post ?

loud sapphire
#

and your timer still has plenty on it

crisp remnant
#

More or less... i am spawning a target and after around 2-3 mins i am starting to get connection refused... and the target is no longer working.

#

This is both with VPN from my own attack machine and the pwnbox...

surreal marsh
#

Yo I gotta say that I've just manually pwned Sqlmap essentials case6 instead of doing it through sqlmap. I've spent hours trying different prefixes etc...Somehow it was easier to exploit it that way which is kinda weird I've you've asked me. Now I'm kinda confused because I got the flag but didn't do it as intended.

loud sapphire
crisp remnant
loud sapphire
#

help someone. GTFOBins. busctl.

Doesnt give me much to work on for escalation...... or im just blind. can someone dm me pleasE?

vital adder
surreal marsh
vital adder
#

i have the ||suffix|| tag with the ||risk|| and ||level|| set to ||max|| in my note but i think i did test it without those tag and it's working fine so i think the tag you need is just prefix but i'm not 100% sure

surreal marsh
brave prawn
brave prawn
surreal marsh
brave prawn
south lark
#

anyone done the Info Gatering- Web Servers module for active subdmain enumeration?

surreal marsh
south lark
#

I'm a little confused if my resolving is messed up or if it's the design of the lab but if I try to query the domain with anything other than dig I get a timeout and there's no TXT records on any of the servers

lethal atlas
#

have you tried a transfer?

south lark
#

yeah that's kinda where the kicker is for me, because none of the subdomain bruteforcing tools resolve anything and the two/three that return with dig refuse a transfer

lethal atlas
#

did you put an entry for inlanefreight.htb in /etc/hosts?

south lark
#

yep!

lethal atlas
#

can you ping inlanefreight.htb?

south lark
#

yep!

proven brook
#

Good evening, i need help please. I'm on AD Enumeration & Attacks - Skills Assessment Part I Question 2. I already tried to bruteforce the open ports and i tried to upload powerview, mimikatz, rebeus, inveigh.ps1 and a few other things, but i can't get them to work on the webshell/remote box. I hope someone can dm me please with a big hint, because I'm stuck for about 2 days on question 2.

lethal atlas
#

then your command must be off. Feel free to dm me and we can look at what you have without spoiling it for others

south lark
#

yeah I will just a little odd because I'm using the same commands that I used to solve footprinting which imo is supposed to be harder lol

lethal atlas
#

I am still stuck on the skills assessment of intro to assembly. I am pretty sure I have the code right but I dont know how to get it to print out

brave prawn
warped phoenix
#

Hey everyone, I am still stuck on the password attacks - Skills Assessment Hard. I was wondering if I could reach out to someone to get a nudge?

vital adder
solemn jasper
#

Hello, in FILE INCLUSION module- Remote File Inclusion section (question), when I tried to gain remote code execution through RFI with http://<SERVER_IP>:<PORT>/index.php?language=http://<ip>:<port>/shell.php&cmd=id, with shell.php hosted on python http server, I get "connection time-out" error. Does anyone know what am I doing wrong ?

vital adder
solemn jasper
vital adder
#

i mean on your python server do you see any request from the target ip

solemn jasper
#

No

vital adder
#

that's weird

#

shoot me a dm i'll help troubleshoot

loud sapphire
#

was anyone able to help me with that elevation?
Linux Local Privilege Escalation - Skills Assessment
Flag 5
User can run b**ctl as root. but i cant seem to use it... im doign it wrong.

DM me?

acoustic owl
wide river
#

hi, im at footprinting LAB2, i cannot find the password of the username HTB, in fact i stuck right at beginning. anyway can give me a hint?

west canopy
vital adder
autumn elk
#

Hey can anyone give me help with the file inclusion skill assessment. I keep l breaking the server when I put the php in the User-Agent. I also for the ||/proc/|| I tried to poison that but broke it there too. If someoneโ€™s free can you walk me through?

wide river
#

you mean 111?

vital adder
wide river
#

im new here so idk about spoiler tag, how you do it?

warm kernel
#

Can anyone give me a clue for: nmap firewall and ids/ips evasion, the lab?

autumn elk
#

@wide river use the double โ€œ||โ€

wide river
#

||ok

autumn elk
#

Like quotes lol

#

Sorry

wide river
#

"oh"

autumn elk
#

So do that in the front and back

vital adder
#

for images use this

autumn elk
#

@vital adder did you finish the file inclusion?

vital adder
autumn elk
#

I found ||/access.log|| too but I break it there too

#

I tried curling it different headers

vital adder
autumn elk
#

Base64,URL

vital adder
autumn elk
#

Yup yeah

#

I will when I get back to my desk

vital adder
autumn elk
#

Ok I figured because my code came up as text

#

Then I got โ€˜-โ€˜ โ€œ

vital adder
#

i have no idea why you got that but about the payload that you use?

vital adder
# wide river you mean 111?

you still need to put spoiler tag on this also i haven't ask if anyone else also have this issue yet but in the hard lab when you get the ||ssh key|| and you can't use it there is a chance that the ||key|| is corrupted and you can fix it quickly with putty but if you don't have it install or don't know how to fix it shoot me a dm with that ||ssh key||

broken warren
#

For anyone interested humblebundle.com has a good deal on Linux material. They are ebooks (can be downloaded as .pdf)

loud sapphire
west canopy
#

what about python3 ๐Ÿ˜‰

loud sapphire
tepid hemlock
wide river
#

hi, its me again with the footprinting lab2 medium, this is where i am now but why it still say permission deny even when i use chmod? what should i do, tks

acoustic owl
wide river
#

hah XD?

brazen dust
#

Any help finding the DNS Version in the NMAP module - medium lab would be much appreciated

lethal atlas
# wide river

try sudo mount -t nfs 10.129.114.179:/ ./target-NFS/ -o nolock

wide river
#

i did

#

and then when i go inside target-NFS

#

and use tree .

#

permission denied

woeful oxide
#

hey guys

warm kernel
#

anyone here have done the hard lab on firewall ids/ips evasion? I need some help, and the hint button isn't working

woeful oxide
#

working on the skill assessment of web attacks module

lethal atlas
lethal atlas
woeful oxide
warm kernel
woeful oxide
wide river
# lethal atlas dm me

hey, i done you advice and this is what i got. is that the right answer? what should i do next

lethal atlas
#

use those creds now

wide river
#

is there any thing need to login?

lethal atlas
#

xfreerdp

wide river
#

oh yaya, im doing it rn

wide river
lethal atlas
#

xfreerdp /u:alex /p:'lol123!mD' /v:10.129.114.179

wide river
lethal atlas
#

google that error about the display environment

wide river
acoustic owl
wide river
#

Administrator?

tepid hemlock
#

Try it

wide river
acoustic owl
west canopy
#

i think xfreerdp might not work with root on PwnBox

raven cairn
#

Can I have help with the windows buffer overflows module

#

My machine can't download the ERC plugin

west canopy
#

@raven cairn ERC plugins are already set up on the RDP box

raven cairn
#

Awesome. Needed to attach it to a process, and configure it before running the tool

brazen dust
warm kernel
#

What other flags do you have? Feel free to PM me ๐Ÿ™‚

shrewd wasp
#

Hello, anyone knows the reason for that I can connect to a target with the browser but can't ping it?

near frigate
#

Just started the SQLi module. How to connect to the SQL terminal ?.. nothing is woking

warm kernel
#

does nmap detect the target?

shrewd wasp
warm kernel
#

http?

shrewd wasp
warm kernel
#

send us some screencaps

warm kernel
shrewd wasp
warm kernel
#

your commands that you are sending, the ping, and nmap scans

#

and another one with the browser, should give enough info to help you out hopefully

shrewd wasp
#

Ok, give me a min

#

that's fine?

#

@warm kernel

warm kernel
#

try nmap <ip> -p 30340

#

by default nmap isn't scanning that port

shrewd wasp
#

same response

warm kernel
#

tried -Pn?

shrewd wasp
#

ok, worked with Pn for that port

#

the 30340 one

warm kernel
#

perfect, now you can run you scans with that flag/port up

shrewd wasp
#

how?

warm kernel
#

ex: nmap <ip> -p 30340 --script vuln

#

for example

#

not sure, what you re looking to do next past this point

strange silo
#

It doesnยดt work for me, Iยดm losing my mind NootLikeThis

shrewd wasp
warm kernel
#

depends on what the lesson covered, pretty vague without more info

shrewd wasp
#

"public exploits" challenge in Getting Started module

#

I have to search for vulns in that target and exploit it to find the flag

#

the lesson covered "searchexploit" and "msf"

#

I guess I should search for more ports, in particular if it is ftp or ssh, right?

#

I can't scan any other port tho, it says that the ports are in "ignored states"

#

with or without -Pn

strange silo
warm kernel
shrewd wasp
frozen atlas
#

Can anyone teach me also some basic coding

#

I am 11 class student

#

@everyone

warm kernel
west canopy
wheat garden
final salmon
#

Ugh, stuck on last question of Footprinting module, IMAP/POP3. I am sure the answer is staring me in the face, but drawing blanks. Anybody able to assist?

crimson warren
#

Anyone here with azure pentest experience

rustic sage
#

Hi! I need help with Privilege Escalation. Im trying to Sign In to the ssh by using: ssh root@host -p xxxx -i id_rsa AND it says me "Load key "id_rsa": error in libcrypto". I did chmod 600 but still nothing. Can you help me pls?

timber light
#

Hi, can anyone help me with the whitelist filters for File Upload Attacks? I managed to upload the file with something like ||.php\x00.jpg|| but i cant seem to access the files

blazing socket
rustic sage
#

Can anyone help me to hack a email ID ?

acoustic owl
rustic sage
placid quest
#

@rustic sage do you want to hack someone's email

rustic sage
#

That person ruined my career

#

I wanna ruin his YouTube channel

granite plover
#

Im stuck on find the easy pass - I have little knowledge on debugging an exe in kali... this walkthrough I was trying to use, after searching for strings, the address values are missing. I assume this is because it's not actually running the exe, just looking into it - how do I get ghidra to run it? is that possible with the current version of ghidra?

#

(that screenshot is from the walkthru images)

#

my view of ghidr doesnt have those ref addresses

#

this is what I see

#

im thinking this is because its just static, not running... and that somehow I need to link ghidra to a debugger that can run it...

zealous flax
#

Hello, I just have started in learning more about Windows from the Windows fundamentals module, and I was wondering what is the Windows Build Number ? I searched about it, but all what I found from searching is some info about Windows versions. So, does this mean that the Windows build number is the same as the Windows version ?

unique valve
rustic sage
#

Hi! I need help with Privilege Escalation. Im trying to Sign In to the ssh by using: ssh root@host -p xxxx -i id_rsa AND it says me "Load key "id_rsa": error in libcrypto". I did chmod 600 but still nothing. Can you help me pls?

#

its on my local VM

shrewd wasp
#

I used searchsploits to search for exploits, (obviously) and found it, but don't know how to download or use it.
can someone explain me how to do it?

tidal compass
#

Morning folks. I find myself stuck again on a module. It's the cracking passwords with hashcat. I'm on the cracking common passwords section. The test question is : Crack the following hash: 7106812752615cdfe427e01b98cd4083 I've tried everything. Even looked at the hint which states "Use hashid to identify the hash, and then use one of the Hashcat built-in rule sets or hybrid mode to help you crack it.". I used hashid, and got a few possibilities as the type of hash but nothing specific. Even if I start at the top of them, I still wouldn't know which rule set to use. I'm missing something I'm sure. Any help would be appreciated. Feel free to pm me. Thanks so much.

placid quest
#

@shrewd wasp use searchsploit -m the exploit

shrewd wasp
#

[!] Could not find EDB-ID #

placid quest
#

@shrewd wasp what error

shrewd wasp
#

[!] Could not find EDB-ID #

#

it's a error, right?

placid quest
#

Read the man page of searchsploit

shrewd wasp
placid quest
#

Can i see the screen shot

shrewd wasp
#

that was the screenshot that you wanted?

#

@placid quest

vital adder
vital adder
drifting knoll
#

nope, it wouldn't

vital adder
maiden field
#

In the footprinting module in the dns section for the last question "What is the FQDN of the host where the last octet ends with "x.x.x.203"?" I've try a lot of things but i cant find this fqdn. Any tips ?

hollow basin
#

Hi guys. I'm new to htb challenges. I was trying to root the new shoppy machine but I got stuck somewhere, can I ask for any hint/ideas on how to proceed from there?

shrewd wasp
drifting knoll
vital adder
hollow basin
drifting knoll
#

be careful with spoilers trev0ck

hollow basin
frozen atlas
#

java.io.FileNotFoundException: C:\Users\meera\OneDrive\Desktop\MarsUltor (Access is denied)

#

how to resolve this exception

vital adder
vital adder
#

sure thanks

west canopy
#

i think i know what exploit it is ๐Ÿ˜‰

EDIT: i was wrong!!!!

brazen dust
#

Just a heads up to the ones that do not know yet, I had a lab that no matter what I did it wouldn't work with my VM but worked with the VM instance on the site.

brazen dust
#

the NMAP module medium lab when trying to find the DNS version

#

it was giving me a weird NLNet Lab NSD as I posted above but doing the same thing in the instance I got the flag

lethal atlas
naive ravine
zealous flax
shrewd wasp
#

every time I try to log with ssh to the server in Getting Started | privilege escalation it throws me "connection refused"
what should I do?

shrewd wasp
#

ssh user1@159.65.90.3 -p 31100

#

do you want a screenshot or you're ok with that?

west canopy
#

that looks right

#

maybe try respawning the target? just tested on my kali vm and i was able to ssh

shrewd wasp
#

fresh target

#

and nothing @west canopy

west canopy
#

i would try the PwnBox

#

or a different vpn key

shrewd wasp
#

ok, thanks for the help โค๏ธ

lament tartan
#

got a question about the Footprinting Lab - Easy, any staff free? n/m, i'm a n00b ๐Ÿ˜…

autumn pilot
#

you don't need a VPN for the docker targets

#

if your ISP is blocking somehow the outbound connection to the targets, then you should either use the workstation or a VPN to change your location and etc

west canopy
vapid grove
#

hi, i'm using bloodhound at Active directory module, and the upload of the files to the bloodhound program is freezed at 0%, it has happened before and i don't know how to fix it

#

the command i used was basically the one they give

warm kernel
#

anyone have time to help me with ftp lab in the module footprinting?

placid quest
#

@warm kernelwhat is the problem

warm kernel
#

hey thanks for reaching out! ๐Ÿ™‚ Current problem is that I don't have permissions to access the file, and I've tried countless combinations of creds with the hint to use full email address as the password

vital adder
warm kernel
#

host based enumeration: FTP

vital adder
#

and my note is a bit dumb for this part so give me a sec i need to check some stuff

#

oh yeah you can't get the flag for some reason

iron basin
#

Hey any help on NMAP module, hardlab question? I found the port and service, cant find the version. Been trying out the steps in the module and looking at hints online. I tried using netcat with the sourceport however the source port throws an error of saying its a binding issue.

vital adder
#

i have nothing in my note about this you should be able to just get the flag

vital adder
warm kernel
vital adder
#

oh wait

#

i hate the new pwnbox the terminal spawn you in /root but you aren't root

#

so if you use the get command in ftp it will download to flag to /root so the permission denied error is from the pwnbox not the target machine

vital adder
warm kernel
#

RIP, I just sudo'd it, and it worked...

vital adder
#

yep or that

warm kernel
#

sometimes.... just the stupidest little thing xD

#

thanks for the help

vital adder
warm kernel
#

I told myself yesterday I wasn't going to use the pwnbox anymore for other issues xD

#

and here I am being lazy again, and costing me an hour of nose bleeds

brazen dust
#

๐Ÿ˜†

nimble ridge
#

can someone help me with this question for intro to python3. "The type of foo from question 1 is <class 'set'>. What is the type of x_coordinate?" i've tried all the different python data types and i can't figure out what the question is asking for

normal spear
nimble ridge
brave prawn
#

hey, just was interesting to ask..about 6 modules left in jr penetration tester path. have made starting point machines and they are labeled as โ€œvery easyโ€, but personally it was not so easy) and my question is, is it okay overall? and can anybody who switched from academy to machines recommend the right way to do it and gain the level? is it real to find good machines without vip?

quiet trout
#

can someone help me udnerstand what the diff bw these two packets are? https://imgbox.com/thClf6jl -- beyond the basic that one is a tcp packet and the other an http packet, and that both are being sent on port 80, im having a hard time understand the true difference... as the data in the tcp packet contains the http request.

#

so is the host informing the server of an incoming http request, and the second packet is the request itself, or ... ?

brave prawn
quiet trout
#

so the host sends a tcp packet to inform the server of an incoming get (or other type of) request?

#

then sends the request? seems a little redunant?

brave prawn
#

canโ€™t tell exactly what is going on the lowest level, but i think, firstly it asks the host like โ€œdo you existโ€ and then request a resource from the webserver

quiet trout
#

ah, that makes sense.

#

im also noticing that for wireshark you can issue a tcp.stream == [0,...,n] but you cannot do that for udp.stream, its either udp.stream or nothing you cannot do udp.stream == [0,...,n] does that seem correct? a limitation of the software?

#

or does it have to do with udp being connectionless so theres no way to quantify a stream or conversation?

#

wireshark seems to be able to colorize the "conversation" (or perhaps what it believes to be the conversation) pretty reliably, so i figured you'd be able to filter by it as well, but i do notice that wireshark is also grouping all the packets, even tho "conversations" are colorized, as one stream group

quiet trout
#

is it possible using wireshark to figure out which subnet an ip address belongs to without having a packet that specifically transmits an ifconfig cmd?

plush cape
snow mirage
#

In tcpdump....I was wondering howcome the first 2 numbers are absolute sequence numbers? is that because the Client and Server are establishing a connection?

rich mulch
#

Hi guys, I am stuck these 2 questions at module "ATTACKING ENTERPRISE NETWORKS". Any hints ?

feral stump
rich mulch
#

yes I found a lot of sub-domain. But dont get any info about FQDNN

feral stump
#

Have you queried the ||A subdomain to see if there is a zone or not and try bruteforcing ||

rich mulch
#

you mean Zone Transfer can be inside sub-domain?

feral stump
pearl island
#

Hello all, working on Introduction to Metasploit Framework exercise on Sessions & Jobs. Got root on the machine. However, did the privesc manually, couldn't get the metasploit privesc module to work. Any hints are greatly appreciated.

rich mulch
feral stump
#

For all the A subdomains

rich mulch
#

you means I have to bruteforce sub-domain to find out the sub-domain in sub-domain?

placid quest
#

@pearl island what is the problem

pearl island
#

It says exploit was successful, but couldn't create a session. @placid quest

placid quest
#

@pearl island do you have shell

pearl island
feral stump
warped phoenix
#

ls

frozen atlas
#

How to resolve the errorjava.io.FileNotFoundException: C:\Users\meera\OneDrive\Desktop\MarsUltor (Access is denied)

fervent narwhal
proud kiln
#

Hello everyone. I am stuck on one question in "Using Web Proxies":
Run ZAP Scanner on the target above to identify directories and potential vulnerabilities. Once you find the high-level vulnerability, try to use it to read the flag at '/flag.txt'

I ran the ZAP Scanner and spider. Nothing is giving me a high level alert. Also, I can see the HUD on the included browser but I can't interact with it. I'm using a Pwnbox. Does anyone have any suggestions on how to scan fix these issues?

bleak prawn
#

Hi, when doing Bucket I got really frustrated as anything I uploaded to the bucket would disappear in a manner of seconds. Is it really necessary to wipe everything and reset every 30seconds? Is this by design? What would the purpose be?

vital adder
vital adder
vapid grove
#

Hi, anyone has done question What domain user is explicitly listed as a member of the local Administrators group on the target host? in Active Directory module? can't figure it out..

vapid grove
#

||found it, use net localgroup administrators||

real vortex
#

Hi, I haven't done python in a while, would anyone help me with this on Introduction to Python3. Q; "ย In "Code block 2" the blank should be filled with what, to output all numbers in a terminal?"

Code Block 2 is list_2 = [4, 3, 2, 1]
for num in list_2:
__________

real vortex
vapid grove
#

no worries ๐Ÿ™‚

graceful parrot
#

Hello, I need help with the type filters section. of course FILE UPLOAD ATTACKS
I find that the valid extension is ||php\x00.gif ||but when I try to rename my shell the \ disappears.
and when adding it in burpsuite the image_profile appears with the name of x00.gif
Even though I manage to load the file, searching for the path shows the following error "Cannot display the image โ€œhttp://104.248.162.85:31390/profile_images/x00.gifโ€ because it contains errors."

lament tartan
#

the instance timers in academy counting down wayyy quicker than they should for me, is this normal? spawned an instance like 30 mins ago it said 90 mins remaining, was down to 60 within 5-10 mins

#

just spawned a new one and its gone down 7 mins in about 2

#

gone down 10 mins now ๐Ÿ˜

vital adder
#

i don't think that's normal but i got the same issue

vital adder
lament tartan
#

driving me crazy because some scanning tools dont show when the instance is terminated

#

have to sit there pinging the box to make sure scan still working

mossy quarry
#

hi

west canopy
#

feel free to DM me ๐Ÿ˜‰

iron basin
#

Howdy, what is the proper way to enumerate SNMP? I have used nmap and its scripts. I am trying to answer the questions for the footprinting module which is asking to find email address, version, and find a custom script. I am just curious what tools I am suppose to be using. I am curious if snmpwalk is what I need to use

vital adder
#

yep snmpwalk is what you are supposed to use

iron basin
#

This SNMP part of the footprinting module is wild to me. In terms of just what it deals with and the ability of it lol.

rustic sage
#

Anyone free to DM about Linux Local Privilege Escalation - Skills Assessment final stage?

iron basin
#

I stumbled upon the usage of netcat for finding verisons of services via a command like this: echo "EXIT" | nc -nv 10.129.x.x (port number)

#

I can get versions of services like SSH with this. I tried this to find the version of snmp if possible: echo "EXIT" | nc -nuv 10.129.x.x 161

#

It connected but didn't respond with any version or response. Curious if anyone knows why or has advice.

onyx rapids
#

Can someone give me the command to pull the flag for module/54/section/490 -> Parameter Fuzzing - GET using FFUF
There is an issue with the machines, and the commands are no longer working, so I need to bypass everything

maiden field
vital adder
vital adder
onyx rapids
#

I've run the command in previous labs without issues, but for some reason, it won't work anymore. I've tried resetting the machine and all that, but no luck

vital adder
#

you can use the ||subdomain in the example|| and for the url tag in your command try with http://academy.htb:30350/

onyx rapids
#

I managed to run the FFUF on the directories and it ran for a while, but halfway through it just started throwing errors again. Something is definitely up with the servers. I contacted support, but I'm not hopeful

#

Since I'm already here, how can I paste commands into pwnbox browser session? I can copy stuff out, but can't paste inside. I keep having to reset the box, and retype the long ffuf commands, would be cool if I could at least paste them in

vital adder
vital adder
onyx rapids
vital adder
#

then use this to copy

#

click this and paste what ever you want to put into the pwnbox in here but if you copy something too long it could be buggy when you paste it

onyx rapids
#

Here is an image of what I'm talking about when I say errors

#

It works for a while and then at some point it throws errors, as if some sort of WAF protection kicks in from their cloud provider

vital adder
onyx rapids
# vital adder hint ||you found what you need||

I already have all those answers, but the problem is I can't run any of the commands I need because they throw errors as well. I just decided to start from the beginning to see if I was missing something

#
real vortex
#

Hello! Need help on Attacking Common Applications; Question: "Following the steps in this section, obtain code execution on the host and submit the contents of the flag.txt file in the webroot."

rigid minnow
#

^me too

onyx rapids
#

God this is so frustrating ๐Ÿ˜ฆ Paying nearly 100$ a month and I'm wasting the day away. I run curl, it works, run it again, same command: connection refused

I can manage to enumerate the correct id for my post request, but then running curl fails. If I switch to a new machine, the ID changes, so I can't use the same one to find the flag. Does anyone have a one liner in curl that will go through all IDs 1-1000. If I skip FFUF and just grep the curl command then I might be able to bypass this issue HTB is having

vital adder
vital adder
#

i did have 1 issue with that module but it's at the Skills Assessment but restart the target a few time fix it for me

lethal atlas
#

Im also NOT using pwnbox

onyx rapids
#

I will try without pwnbox

shell panther
#

How to hack someone heart ??

vital adder
#

we need a module / box on this

onyx rapids
#

If anyone ever comes here to search for the same issue, here is how you can bypass ffuf and get the flag in one go to avoid the server error.
||for i in {1..100}; do curl ip:port/admin/admin.php -X POST -H "Host: admin.academy.htb" -H "Content-type: application/x-www-form-urlencoded" -d "id=$i" -s | grep div.*HTB; done||

ancient oriole
#

Hey, I am stuck at ACTIVE DIRECTORY ENUMERATION & ATTACKS - ACL Enumeration, last question.
Q: What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word)
i tried the Get-DomainObjectAcl, but the command only outputs the first half and then hangs. I really don't know what to do now, could anyone give me a hint?

west canopy
lethal atlas
onyx rapids
lethal atlas
#

I just dont have any issues with ffuf on that section. I just re-ran my commands and got right thru it.

#

I would be interested in comparing ffuf commands

ancient oriole
lethal atlas
#

ill test it on there real fast

sturdy igloo
#

Anyone can help with this question? "Perform a DCSync attack and submit the NTLM hash for the khartsfield user as your answer." How to answer this? i performed dcsync and have the ntlm hash but it keeps saying incorrect answer

west canopy
onyx rapids
onyx rapids
# lethal atlas ill test it on there real fast

I'm on the skills assessment and not having anymore issues. Been waiting 3 hours for HTB support chat to respond, but I'll probably be done the module when they respond. It seems to be a known issue for a year now, so I doubt they will fix it

sturdy igloo
lethal atlas
onyx rapids
lethal atlas
grave lance
#

Having trouble with footprinting, imap/pop3 section, on question "enumerate imap service and submit flag"
I've used nmap to list the details of the service, and curl and openssl commands to interact with the service. Any advice appreciated

rustic sage
#

i lost a argument with someone can anyone pull their ip for me?

#

please

rustic sage
#

anyone

onyx rapids
#

Anyone know how I can make this XSS payload into something cleaner? ||0' onerror=alert(1)>|| I use it here : module/103/section/984 (XSS - Phishing)
It works, but it shows '> on the page and it doesn't look clean. Try my payload to see what I mean

quiet trout
#

does anyone know if there's plans to get "Authors suggested solution" on the exercises? some of the exercises i've completed i have felt i had performed in a way that may not have been 100% as the author intended and on some of the more stubborn exercises i've been quite curious what solution the author intended when they were coming up with the exercise.

quiet trout
#

@onyx rapids can you paste your xss payload in the clear, i dont want to click on it -_-

high totem
#

Hey, I'm doing footprinting module, DNS part and have problems with the last task (IP with last octet 203). I haven't found anything matching via zone transfers. I tried manual enumeration as shown in the module, but it takes very long (which I can understand) and returns only three results (which I don't understand - via dig I've found way more) and resolves name server of the target (so ns.givenDomain.htb) to my localhost - 127.0.0.1, which I SUPER don't understand. Can anyone give me a hint on what I'm doing wrong?

high totem
quiet trout
#

well it kinda does, if you're a little bit anal retentive like myself because there are multiple ways to get the answer and sometimes having the authors intended solution gives (people who desire it) a better insight into what the authors intentions were or thought process with the module. its not strictly necessary but is super helpful beyond just knowing what the intended solution is

rustic sage
#

on module, "getting started, service scanning" when i type in "get flag.txt" it tells me there's an error opening the local file. Can somebody help me?

high totem
rustic sage
high totem
rustic sage
bleak willow
#

I tried a lot of things including Ip, Internet Protocol, MAC, Media Access Control.. and nothing.. Any advice please? pepehands

feral stump
bleak willow
feral stump
bleak willow
#

Im in since one hour ๐Ÿ˜…

feral stump
#

I am looking for alternatives in google though ๐Ÿ˜…

bleak willow
#

I looked too and i been doing nosense brute forcing monkaS

#

I think that something is wrong with that question

feral stump
#

not sure if this will help but did you check on HTB forum just in case?

bleak willow
#

ill do it

feral stump
#

hope you can find it

storm dagger
#

it's been asked before ^^ and it seems like chronos was nearly correct

bleak willow
rustic sage
hollow hinge
#

Dm if you still need help

brave prawn
#

Hey, can anyone help me with File Inclusion Skills Assessment?

acoustic owl
#

Which section/question do you need help with?

acoustic owl
frozen atlas
#

How to solve the access is denied error

#

In json file reader

#

Is there any certain permissions for the folder to be read

#

And when folder is specified it shows cannot be cast from object to

#

?

tidal compass
#

For the love of all that is holy can someone help. lol. Cracking with hashcat module. Cracking common passwords section. Question is: Crack the following hash: 7106812752615cdfe427e01b98cd4083 . Hint says: "Use hashid to identify the hash, and then use one of the Hashcat built-in rule sets or hybrid mode to help you crack it.". I used hashid, compared that to hashcats online notes and determined it's an NTLM hash. I've tried everything and I'm getting nowhere. Can someone give me a hint? Or a walkthrough, or something lol. Thanks in advance

lethal atlas
vital adder
#

i think he didn't use the right rule

lethal atlas
#

i just used the one from the rules section

#

rando 1k

vital adder
#

oh i use a different one

lethal atlas
#

interesting

vital adder
#

the first time i did this module i didn't note anything so i still have no idea what i use the first time

lethal atlas
#

lol

tidal compass
lethal atlas
rustic sage
#

hashcat -m <hashid> <filename containing the hash> /usr/share/wordlists/rockyou.txt

#

is this how ur command looks?

frozen atlas
#

Someone tell my doubt also

rustic sage
vital adder
#

and your command are missing the rule

rustic sage
#

u can do so , by
ls -la

frozen atlas
#

In*

#

In windows

rustic sage
#

ohh..