#modules

1 messages · Page 10 of 1

frozen atlas
#

Is la will work In linux

#

Then??

rustic sage
#

are u using windows or linux? coz i just figured out the command for windows

#

for linux, ls -la

#

u can find who has permissions

#

if u dont have the permission

#

then u can change it by using chmod command

frozen atlas
#

Windows

rustic sage
#

u use icacls or somethin

queen hatch
#

If anyone has a sec, I'm stuck on SQLMap Essential case 6. (If I'm giving too many spoilers, let me know and I'll edit)

What I'm trying: ||sqlmap -r attackTuning2.txt --batch --dump --threads=10 -T flag6 --level=5 --risk=3 -v 3 --prefix='`)'||

Contents of attackTuning2.txt:

GET /case6.php?col=1 HTTP/1.1
Host: 178.128.173.79:32711
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:104.0) Gecko/20100101 Firefox/104.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Connection: keep-alive
Upgrade-Insecure-Requests: 1

I'm not sure if there's something I'm supposed to be looking for in the verbose output or not.

vital adder
#

the main thing for case 6 is the ||prefix|| tag you got it right you i don't know that didn't work

queen hatch
#

I'll try clearing the cache and starting fresh. The fact that the scan takes so long is a buzz kill

vital adder
#

yeah i think you need to restart your target i just try your command but with the url and it's working fine for me

queen hatch
#

Could ||--risk 3|| be messing it up?

lethal atlas
#

no

vital adder
#

and i can get the flag just fine on the pwnbox

onyx rapids
#

Can someone send me the full XSS command under the XSS - Phishing lab? The one provided doesn't work correctly. This gets reflected back instead of being run: ');document.getElementById('urlform').remove();

onyx rapids
vital adder
#

put it at the end of your payload like this: (your payload here)<!--');

frozen atlas
#

I just have to authenticate vs code?

vital adder
onyx rapids
vital adder
#

oh i don't think you can remove that but you can put an icon on that

vital adder
acoustic peak
#

I’m also having a SQL injection issue. In the section about “using comments” I end up injecting code so that the end code is

SELECT * FROM logins WHERE (username=“asd” OR id = 5)

Then the rest is commented, but it still doesn’t work. I think I’m missing a fundamental thing. I’m trying to get into the user who’s id is 5. What am I missing?

EDIT: Solved. It was as simple as putting a space at the end... Thanks to those who reached out.

real vortex
#

Attacking WordPress

vital adder
nova citrus
#

1

real vortex
vital adder
#

so the cred from question 1,2 don't work?

iron basin
#

Anyone have any advice on the IPMI section of the Footprinting module? The last question is what I am stuck on. Deals with password cracking after grabbing a hash.

#

Nvm lol, it solved it finally.

bitter comet
#

going through fuzzing, found this on a random port? ```
███ ███
â–ˆ â–ˆ â–ˆ â–ˆ
█ ◍ ◍ █ █ ◍ ◍ █
â–ˆ â–ˆ â–ˆ â–ˆ
█████████ █████████
███ ███


Welcome adventurer! Before we begin, please tell us your glorious name (max 20 chars):
Now, what is your class GET / HTTP/1.1
Host: admin.ac?

  1. Tank (increased Health)
    2. Mage (increased Dexterity)
    3. Assassin (increased Attack)

>>
[-] There is no demy. class! You will follow the Tank path..

[*] First levels of the game, every character will start with a Sword even though it's not class efficient!

Here is your first sword:

[+] You just obtained: Level 1 smol sword!

â–šâ–šâ–šâ–šâ–šâ–šâ–šâ–šâ–šâ–šâ–šâ–š
â–š â–š
â–š â–Ÿâ–:tm: â–š
â–š â–‘â–‘â–‘â–‘ â–š
â–š â–‘â–‘â–‘â–‘ â–š
â–š â–‘â–‘â–‘â–‘ â–š
▚ ██████ ▚
▚ ██ ▚
▚ ██ ▚
â–š â–š
â–šâ–šâ–šâ–šâ–šâ–šâ–šâ–šâ–šâ–šâ–šâ–š

Energy: [4]

What will you do now?

███████████████████████████████
â–ˆ â–ˆ
â–ˆ 1. Craft sword (1 energy) â–ˆ
â–ˆ 2. Show info (No cost) â–ˆ
â–ˆ 3. Show stats (No cost) â–ˆ
â–ˆ 4. Farm XP (1 energy) â–ˆ
â–ˆ 5. Change name (Only twice) â–ˆ
â–ˆ 6. Fight Boss (5 energy) â–ˆ
â–ˆ 7. Rest â–ˆ
â–ˆ â–ˆ
███████████████████████████████

Everyone needs some rest.. See you soon!```

onyx rapids
vital adder
#

yeah you can't make the box disappear but you can put an icon on it

ancient oriole
#

which part?

autumn elk
#

Has anyone had any problems connecting in security sessions to vhost? I keep getting “No Route to Host” but the IP address pops up in the forward request area.

#

Via Burpsuite

#

Firefox works

lethal atlas
woeful oxide
iron basin
#

@lethal atlas dunno, but interesting seeing a text based adventure game displayed like that lol

safe adder
#

Is there walkthroughs for the HTB academy module 67 (Windows Privilege Escalation)? Been searching but there's none. I wanted to check out the the different solutions.

lethal atlas
#

what a headache

brave prawn
#

i am on a module File Upload Attacks section Whitelisting, found needed extension, and burp tells me that file uploaded successfully, but i can't exec the code, because it tells me that file not found. can someone help me?

woeful oxide
#

Hey Guys

#

Its possible to remove a word from a file using terminal?

#

I wan to remove the word payload

brave prawn
#

i think yes, you can google it

brave prawn
#

idk how

#

just google

woeful oxide
#

I mean dm to help you with the whitelist exercise

gloomy sigil
#

I'm on module "Information Gathering - Web Edition" in the Active Subdomain Enumeration. I have to identify a FQDN from a IP address but neither nslookup or dig are working. I must be doing something stupid but I have tried every command as shown in the material.

placid quest
#

@gloomy sigil what is the problem

paper swan
#

hi all , my machine suddenly became unable to connect to the hackthebox openvpn

#

i need help

placid quest
#

@paper swan download another

vital adder
paper swan
placid quest
#

@paper swan use sudo maybe

vital adder
gloomy sigil
gloomy sigil
vital adder
onyx rapids
#

Can someoe PM me the XSS Payload for Session Hijacking in XSS section of the academy before I jump off my balcony. I'm also willing to accept hints, but make it a really good one because I've exhausted a lot of possibilities

vital adder
#

sure shoot me a dm and also you can just yeeted your pc out the windows if you can't find the answer

onyx rapids
broken warren
#

Can someone explain how tplmap works on the pwnbox for server side attacks? I can't even find it using "locate tplmap" and when I try to install on pwnbox it gives the same errors as I would get on my VM. I reallllly need a solution to this to finish the server side attacks module.

raven cairn
#

Going to see if I can finish it today

broken warren
# raven cairn How are you installing it?

I've tried installing verbatim from the module instructions. On my current machine, and even installed a fresh VM with Kali. I always get an error saying relating to 'Opera' and no mapping attribute. Ive seen a couple articles say try running with python 2 and that hasn't worked either. I'm only 9% from completing the bug bounty hunter path

raven cairn
#

I’ll check it out on my end

vital adder
#

update i just try on the new pwnbox no issue for me so far

broken warren
ember silo
#

anyone know the location of etc/hosts on the pwnbox VM?

vital adder
ember silo
vital adder
#

it's pwnbox hosts file

ruby elbow
#

Hi

#

Hi everyone, how you doing?

I am struggling with the Session Hijacking from the XSS module. I got my PHP server working, found the payload to use, and made the configurations as suggested in the course material, but I keep getting [200]: (null) /script.js

Any hint on that?

Thanks in advance!

ruby elbow
#

or your preferred text editor

hollow badger
#

Hi

#

I'm struggling to start my first instance in Starting Point

#

getting stuck here:

vital adder
hollow badger
#

"creating instance"

ember silo
hollow badger
#

It's been about 8 minutes

west canopy
storm dagger
#

else you probably won't see the channel

graceful parrot
broken warren
woeful oxide
#

Hey guys

#

quick question

#

I got everything alright but I don't understand how to curl it

#

like this

storm dagger
woeful oxide
#

like this: curl ||-s 'ip/var/ww/html/shell.php?cmd=id'|| ?

storm dagger
woeful oxide
#

using ||index.html?value=||

storm dagger
raven cairn
#

Can I have help with the windows buffer overflows skills assesment

#

I am super confused why my exploit isn't working haha

#

Normally I would post my code, but I don't want to spoil the badchars, the offset and the jump addresss

raven cairn
#

pls

#

😭

dreamy plume
#

@raven cairn

raven cairn
rustic sage
stray grove
#

this is interesting after getting the ||hash|| i used ||impacket-wmiexec inlanefreight/administrator@<DC_IP> -hashes "LM:NT"|| and landed straight to the DC

wide river
#

hi guys, its me again who stuck at lab2 footprinting. I got some progress now but idk what will be my next step to find the HTB username and its password

stray grove
stray grove
#

on the left pane you should be able to see all the dbs listed, the one you're looking is under ||WINMEDIUM.accounts - db0.devsacc||

wide river
#

nail it

#

thanks bro

little helm
#

Q: On a spawned machine within an exercise, if the time to live left is quickly dropping, 9 to 10 minutes every minute or so, is that something I am doing or causing?

#

Killed my vpn rebooted my machine fixed it

knotty crag
#

guys

#

i am new here

#

i just wanted to ask u guys

#

how to download proxychains on the linux app

#

on windows

rustic sage
warm lichen
little helm
#

Right?

knotty crag
#

yeah guys can we also use proxy on games

#

right

#

online website game

gritty crest
#

guys, need a bit of help on the web section in Attacking Enterprise Networks.
what's the flag location for attacks involving LFI? the SSRF and XXE ones.

warm lichen
#

Or try ~/flag.txt

gritty crest
#

nope

warm lichen
#

If it's SSRF / XXE maybe try poking around /var/www/html

#

else you can run find

gritty crest
#

that's what i first tried, /var/www/html/flag.txt

#

cant run commands, it's just LFI

warm lichen
#

Ah yeah that sounds really annoying. Maybe LFI some pages that you already know exists?

#

The flag could be hidden as a comment in index.php or something

knotty crag
#

guys we cant use proxychains when we are only using terminal right

little helm
#

On the NMap module, hard lab, anyone got time for a DM? Trying to do something maybe I need to adjust my thinking?

gritty crest
warm lichen
#

Of course 🙂 glad to hear it

hollow hinge
#

Dm

brave prawn
#

On module File Upload Attacks section Whitelisting I have all my files successfully uploaded, but they can't be found on webserver. Can i get a hint?

summer lava
#
Password Attacks Lab - Medium

I need help.. i already got the first user and the second user but still couldn't find the root

warm lichen
brave prawn
warm lichen
warm lichen
#

Sure

knotty crag
#

hello guys can i use vmvare

little helm
#

Nmap module hard lab exercise. need a final little nudge, dm?

knotty crag
#

for a vm

#

for linux

spice onyx
#

Morning All! I'm in the HTB academy module, footprinting IMAP and POP3; the very last two questions. "What is the admin email address, and Try to access the emails on the IMAP server." While I've been able to enumerate the servers, and the email cto.dev@dev.inlanefreight.htb, I'm not able to sucessfully figure out how to get in - I'm assuming I need to figure out the pw for the cto.dev account. Any suggestions, tips, hints to point me in the right direction? I've used the nmap imap-brute script, but it times out after 10 minutes...

rustic sage
#

hi all

spice onyx
#

@rustic sage ?

rustic sage
#

?

rustic sage
spice onyx
#

you responded with, "shut up". The question mark was in response to that

spice onyx
#

classy

rustic sage
#

fuck off\

#

niggqa

spice onyx
#

@umbral marlin are you 8 years old? Really.

#

@umbral marlin Go find something better to do than to harass others thanks

raven cairn
#

Cringe Af lol

granite plover
#

🤔 currently tryin to figure out why the exploit i found for Jerry (begiiner track) aint working... trying to use CVE-2020-9484 - am I barking up the right tree here?

raven cairn
#

Also there is the #boxes channel. Do some research on attacking Apache tomcat. If you get stuck you can watch the Ippsecc video. This channel is focused on Academy.

granite plover
#

oh shoot ok thanks

little helm
#

Hiya. On the last exercise of Nmap, I could use a bit of a nudge. Im at the very last of it, so dm is more appropriate if someone is floating around.

spice onyx
#

@little helm when I was going through it, I didn't wait long enough after connecting, to get the flag. After I connected and waited for 30 sec to 1min, it appeared...if I recall correctly

little helm
#

Perhaps that was the medium? But just to be sure I also ran a -d and a -w with 60 seconds on each

#

@spice onyx Plus, doe port 31337 have anything to do with it? I just connected to port 80 for giggles

spice onyx
#

@little helm I recall having to go back over the step by step of the section, to get the final flag. I believe another tool was mentioned, which you need to use to connect with, to get that last flag.

little helm
#

Is it ok I dm you? Im aware of both tools. Funnily enough....the connection to port 80 IS the second tool

spice onyx
#

@little helm certainly. Also, I'd suggest looking at the source port you're trying to connect from 🙂

little helm
#

yup got that too

spice onyx
#

and to scan TCP and UDP.

heady nymph
#

What am I doing wrong with this module: information gathering web edition - skill assessment section and this is the question, "Perform active infrastructure identification against the host https://i.imgur.com/. What server name is returned for the host?" I cannot seem to find the answer it is looking for

placid quest
#

@heady nymph use curl

heady nymph
#

I have used curl -I and still not seeing it

#

im sure I am staring right at it or something but....

#

I think ive pasted every line of the return n to the answer and none of them worked

#

Ill try again

lament tartan
#

the "OpenVAS Skills Assessment" tells you to launch an instance and connect to the openVAS interface but doesn't say which port.. Default is 8080 but that's not open, am I missing something? thought it would just be like the previous (Nessus) assessment n/m i didn't wait long enough for it to start

heady nymph
feral stump
brave prawn
#

can i dm someone about file upload attacks skills assessment?

brave prawn
jovial walrus
#

need a bit of help with intro to ad module

zenith apex
#

Hello

vale salmon
#

So in the Privileged Access section of Active Directory Enumeration & Attacks it asks what other user has the CanPSRemote privilege, but when I run SharpHound on the Windows box and then upload the data into Bloodhound, there seem to be no users with RDP execution privileges and I've checked all the domain entries. Can I get a nudge? Nvm. Got it

frail garden
#

DM if you need

jovial walrus
#

can someone tell me why the newly created OU is not visible in ADUC

ancient oriole
#

you have two quotation marks at the end of the command, remove one

inland shoal
jovial walrus
#

Thx 👍

ancient oriole
#

no problem, it happens

jovial walrus
#

The solution guide had two " needs to be corrected

inland shoal
# ancient oriole no problem, it happens

Same goes for the selection in PowerShell. If you select something in PowerShell like in the screenshot, it waits for you to enter. If you don't, it keeps waiting and you wonder why it doesn't continue. Also if you select something like in the screenshot, it's in your clipboard. This happend to me so many times that you can a single character in your clipboard when you wanted to paste code so you have to copy the code again 🤦‍♂️

jovial walrus
#

Using powershell seems to be more intriguing as compared to the ADUC gui

#

Just started with the into to ad module on htb academy

ancient oriole
inland shoal
jovial walrus
#

whats the meaning of this cmdlet?

inland shoal
jovial walrus
inland shoal
#

Yeah, or just ask. I'm happy to help with AD questions.

jovial walrus
inland shoal
ancient oriole
#

btw I believe you can use 1 instead of security in group caterory

#

and 0 for distribution

#

but that doesn't matter

jovial walrus
inland shoal
#

Pretty sure 99% of the time it's security though 😉

ancient oriole
#

I believe distribution is for regular users, while the security is used for managing stuff

jovial walrus
#

What does group scope mean and should it be set to domain local or global

ancient oriole
#

it decides how much does the group cover

#

if only the domain, the tree or the whole forest

jovial walrus
#

👍

inland shoal
ancient oriole
#

oh, thanks

vocal musk
#

any way to bypass the academy vpn openvpn error "OpenSSL: error:0A00018E:SSL routines::ca md too weak"? an openvpn CLI flag perhaps? seems the VPN key given by academy is too weak?

ancient oriole
#

happened to me too

#

i will tell you, I added one line to the ovpn file and then it worked

#

i will check what it was

#

@vocal musk open the ovpn file and after the key-direction 1 line add this line: tls-cipher "DEFAULT:@SECLEVEL=0", then save and it should work

#

I am not sure what it does but it works

#

you can google the error for yourself and you should find some website telling you this

jovial walrus
#

completely lost over this error

#

followed the steps

#

can someone help me FeelsBadMan

vital adder
#

hi so which section is this?

ruby elbow
#

Hi everyone, how you doing today?

Anyone can drop me a hint in the skill assessment of the XSS module? Been trying payloads without success for a while,

Any hint?

Thanks in advance!

sharp cedar
#

Can anyone see the error?

little helm
#

Hello Nmap hard exercise. Spoke with 2 people who state this and this are the final answers but not working. I waited for each of those to produce a result 10 minutes. also ran after establishing the connections in pic, I have tried to run 2 scripts associated with that service thru the appropriate channel. Would love to chat about it with someone

west canopy
vital adder
#

i hate that part in the new pwnbox

ancient oriole
little helm
#

Thank you so much for replying. i have learned more about nmap than this module was intended to teach

west canopy
#

also your netcat commands are off a little bit, if we are netcatting into another machine we need specify the port we are connecting to

little helm
#

I had tried the switch as well. I will attempt both your suggestions now

sharp cedar
#

Both failed...

ancient oriole
sharp cedar
#

got in the domain name is INLANEFREIGHT

#

not INLANEFREIGHT.LOCAL0 lol

#

although you have to figure this out first because it tries to log in to a DC by default

#

so confusing haha

ancient oriole
#

yeah sometimes these instructions on academy are unclear and require you do to some extra step you didn't expect

plush falcon
#

Hello in AD Enumeration and Attacks - Skills Ass part 2
Any hint for how to connect to MS01 as Administrator? Got some hashes on SQL01 but none of them seems to work

sharp cedar
little helm
west canopy
#

np nice work 😉

little helm
#

No really last night, I was reading about idle scans, and reading much deeper into tcp flags and zombie scans...

#

i ran the two db2 scan scripts

#

and how to read the packet trace socket programming...

#

turns out directory.

raven cairn
#

I've been working pretty hard on the windows buffer overflow skills assessment and I am still stuck. I am able to get the buffer overflow to work on locally, however when I do it remotely it doesn't work...

#

I am pretty confident I got the Bad chars, and offset correctly

#

My return instruction worked on my box. But I think this is what my be wrong

stuck elm
#

Can someone direct me to the channel for n00bs, if there is one? I'm an experienced analyst. Breezed through the preliminaries but am stuck on my first box ... I need some quick assistance. Found a hidden port using Nmap but I need to cut through it quick so I can bounce through subsequent boxes....

#

Hacked shit in the real world but this emulation shit isn't the same.

#

Yeah, like I hacked stuff as a kid ... along time ago and broke through ...

raven cairn
#

Also Ippsecc is just a god tier resource in genearl

stuck elm
#

I'm not getting more specific than that. I also broke a CTF for a screening in a job interview and I Have the screenshots to prove it

#

So before the shit-talking begins, if that's how it works, I have the screenshots from a Palo Alto interview

#

They rejected it because I circumvented their block

#

*bot

raven cairn
#

You can't say you are skilled and not be able to do a noob box tho buddy

stuck elm
#

The bot didn't pick it up because I literally built a server on their ec2

#

Yeah, yet, I have screenshots from an actual CTF in a job screening

stuck elm
#

I like how you size me up in 2 min, @raven cairn

#

I can see the CTO in you

#

You must be the stage hand that left Mr. Robot

fossil mountain
#

1

red obsidianBOT
stuck elm
#

So your shit talking or my screenshots from Palo Alto

raven cairn
#

NOt shit talking bro. Just being realistic haha

stuck elm
#

So let's do that. I'll post the screenshots so you can talk shit after that

red obsidianBOT
stuck elm
#

So, this is how it works: in the real world, you don't have walk through and cryptic "Star Wars" hints

#

There isn't a tutorial or VPN

#

*well the VPN is there

#

But it's not a hackthebox VPN

raven cairn
#

@stuck elm There are also box writeups you can look at on the site.

#

THere are only writeups for the retired machines. Those can help you out.

#

No writeups for active machines.

stuck elm
raven cairn
#

Browsing irc on weechat is nostalgic

#

rip freenode

stuck elm
#

On the surface it's much more user friendly but when I use nothing but the cli for work, it's halfway confusing

#

haha

#

*cli for weeks

#

Well, for work too

stuck elm
#

I'm an instructor and business owner

#

Yes, it is

raven cairn
#

Hard to do web browsing, burp suite or watch videos tho

stuck elm
#

I think if people never quit using stuff like DOS normal folks wouldn't be intimidated but they are taught to only understand the GUI so they just won't touch it

raven cairn
#

I would use only CLI for pentesting but i don't really see a good Web proxy for terminal haha. Other than that CLI tools for the win.

stuck elm
#

Yeah, I don't even know how to post the photos on here. "Use the slash command" which works on IRC but surely that's not it for photos ...

#

Are photos blocked on this channel for security purposes to avoid noobs getting trojans?

raven cairn
#

you can post photos

stuck elm
#

Well, for blackbox pentesting, someone should know how to script Python and BAsh from scratch

raven cairn
#

yes I am a light mode user. fuck dark mode haha

#

Finished the module

#

thanks for help @rustic sage

autumn elk
#

@raven cairn for the sessions security I for compromised ||input form|| but I don’t know what I’m missing. I have the submit-solution and it says the admin visits but I’m lost.

raven cairn
#

What section

#

This will make it easier for me to help

autumn elk
#

Skills Assessment sessions security

#

I see the ?url=<>

raven cairn
#

I'll take a look at it in a sec

raven cairn
#

I got stuck on this same problem haha

autumn elk
#

I have a feeling im over thinking it

raven cairn
#

Look at the image I just sent

#

/submit-solution?url=(payload)

autumn elk
#

I did. I’m just thinking of the payload

raven cairn
#

Once take over admin page you will find a pcap file

raven cairn
#

following the steps should be pretty similar

autumn elk
#

That’s what I’m looking at now

raven cairn
autumn elk
#

I have my notes but I feel like I missed something

#

Ok will do. Thank you!😁

wheat garden
#

Any one do shells and payloads module stuck on the Antak Webshell section last question. " Establish a web shell with the target using the concepts covered in this section. Submit the name of the user on the target that the commands are being issued as. In order to get the correct answer you must navigate to the web shell you upload using the vHost name. (Format: **, 1 space) "

#

I got webshell and exexcute whoami command and get ||iis apppool\defaultapppool|| not sure how this question is wanting me to format this answer.

lethal atlas
wide river
#

hi, im at footprinting hard lab, this is where im at right now, what should i do next

wheat garden
wheat garden
wheat garden
wide river
#

uhh

#

snmp?

#

i saw non of it in nmap

vital adder
velvet birch
#

We can use termux and GMT also

#

Termux is safe

#

Can anyone suggest me termux is safe

placid quest
#

@wide river scan udp

stiff stream
#

Attacking Common Service - Attacking SQL Databases section - Trying to connect to the SQL server just like in the example but recieving this:

#

Nmap finds the service open though so is it my connection or?

pearl island
#

Need some hint on Password Attacks-Mutations section. The password list after mutation is around 94k. Brute forcing is taking time. Is this the intended way?

stiff stream
#

@pearl island You can cut the password list much shorter, say first 5-10k passwords and see if that helps

faint trellis
#

Hey there! I have the same issue. How did you manage to fix it ?

pearl island
#

Alright, Let me try that rq. @stiff stream

stiff stream
#

I think I cutted them down to first 5k

worldly garden
#

hi

#

i am a newby

stiff stream
#

@worldly garden Welcome! I'd suggest you to start with academy and from there to htb 🙂

pearl island
#

@stiff stream Can I dm?

stiff stream
#

@pearl islandYes of course!

twin gulch
#

Hey guys

#

Can someone help me get rid of hashcats error about not enough memory for the attack?

#

Cannot make progress at password attacks module

faint trellis
#

Hey guys! Who knows how to fix the issue with the Bloodhound when it shows "Upload Completed" of a .zip file with 0% ?

frozen atlas
#

my program searches for ifsc codes and tells the details of all banks in my country so how will i upload this to the internet

#

with all the 200 + files that come with it for it to search

#

all are json files

#

is there a way without paying

twin gulch
stiff stream
#

@twin gulch Check if your vm needs more ram or what I did also was that I used my windows computer with hashcat so that made it was able to crack it

autumn elk
#

@raven cairn I did it, but the worse part of all I did this but I didn’t pay attention to see the difference in the cookie…smh

timber hatch
#

hey everybody
this command brute forces User RIDs:
for i in $(seq 500 1100);do rpcclient -N -U "" 10.129.14.128 -c "queryuser 0x$(printf '%x\n' $i)" | grep "User Name|user_rid|group_rid" && echo "";done

can someone break down and explain the command a little more?

shadow tiger
#

...

#

How the shit does anyone game or do anything with Discord given it's utter incompatibility with VPN hopping

#

I literally gave up on 2FA because the security is on fucking steroids ... It will not allow MFA from more than one region at a time regardless of meta-levels of authentication etc.

timber hatch
storm dagger
vapid grove
#

anyone can give me a nudge on active directory skills 1? i can kerberoast the spn but i can't seem to find the SQL01 machine?

surreal rain
#

@shadow tiger Keep your comments relevant to the channels you post in.

serene epoch
#

what encryption type do you think is $2y$10$PWeS5OrZJ96EKhTi30fsYes0vkQCXtCtNQGIExfSYXEuKCjua.BAS

hollow hinge
#

Dm

serene epoch
#

so can you solve it or can you tell me how i can solve it?

languid dawn
#

just throw rockyou.txt at it.

#

or one of the smaller password lists

#

as it is bcrypt and will take a long time

#

depending on your machine you might not even get 50 hashes per seconds.

ashen orbit
#

anyone know where the numbers.txt file is located? I can't seem to find it

placid quest
#

@ashen orbit use find command

ashen orbit
placid quest
#

@ashen orbit use readlink

flat silo
#

I'm trying to run sublist3r and I'm getting an error saying virustotal is probably blocking my requests anyone able to help me work around that

shadow tiger
#

Sorry - I've been MIA

#

I need to post my violative Palo Alto CTF photos

#

Breaking their damn CTF ...

#

Not just passing it but breaking it with my backdoor

atomic river
#

Hi guys, can I DM somebody for the broken authentication skills assessment? I am stuck...

sly shadow
#

Hello everyone! I'm struggling with the footprinting med lab. Here's what I've gotten so far:

Alex creds
Sa creds
Logged in through RDP with Alex creds
Now I'm unable to login to ssms with either of these creds. Please DM me with a nudge in the right direction

atomic river
#

I know which are the users, I know how the token is encoded but the token tampering is not working...

feral stump
faint trellis
flat silo
#

I'm on the last question for the information gathering module and I found a list of subdomains using gobuster I used go buster again to trying and go another level down I found two more sites but nothing else. I can't get sublist3r to run right as the hint suggests can someone help me with a nudge

acoustic owl
mystic perch
#

Hello, I started the Password Attacks module. Can anyone tell me a list of usernames for this module?

mystic perch
#

Thx mate

placid quest
#

@tough ibex enumerate smb

frozen atlas
#

I want to share a java program with my brother in new york without sending him all the files meaning he does not have to download all the files so I need like a vps server or anything else (the files are like 2.61 gb)

#

any ideas?

frosty wasp
#

you could use google drive

frozen atlas
#

then how will he run the code

#

he still would have to dowload it

frosty wasp
#

then you shall go with heroku

frozen atlas
#

what is heroku?

#

got it

frosty wasp
#

server

#

you have to create a File named Procfile

#

add it in your code base

#

and push it to heorku

frozen atlas
#

is it free

#

or paid?

frosty wasp
#

its's free till november

urban sage
#

Heroku axed their free tier iirc. Ah okay. So a little longer.

frozen atlas
#

so dont know how to do that

frosty wasp
#

me too

frozen atlas
#

age?

frosty wasp
#

17

frozen atlas
#

16

#

country?

frosty wasp
#

india

frozen atlas
#

same

#

where in india

frosty wasp
#

up

frozen atlas
#

gorakhpur

#

in up

#

u?

frosty wasp
#

me raptinagar

frozen atlas
#

arey bhai tum toh padosi ho

frosty wasp
#

holy god

frozen atlas
#

i live near fatima hospital

#

which school?

#

lfs dharampur

#

name?

#

sahaj

#

nice to meet another brother

frosty wasp
#

nice to meet you

#

too

frozen atlas
#

can u tell how to do that

#

or is there a tutorial

frosty wasp
#

sure

#

do you have experience reading documentation

autumn pilot
#

keep the channel on topic

frosty wasp
#

sorry for tat

frozen atlas
#

brother msg personally

placid quest
#

@tough ibex what is the problem

#

@tough ibex try login mysql

#

@tough ibex find the ssh key

#

@tough ibex it will be for root

wide river
#

hey, im at footprinting lab3, so far i got nmap of pop3, imap, and snmp. what step should i do next ?

jovial walrus
#

I need help with the intro to ad module

#

The support system is so bad on the website

plush falcon
#

Hello in AD Enumeration and Attacks - Skills Ass part 2
Any hint for how to connect to MS01 as Administrator? Got some hashes on SQL01 but none of them seems to work

jovial walrus
plush falcon
jovial walrus
real vortex
warm turret
#

hello, some one can give me the right wordlist to solve the default credentials section on the broken authentication module??

proven jay
#

Can anyone confirm that the final challenge for the information gathering - web edition is still doable?

#

the one where you have to find the subdomain of githubapp.com that has elephant in it

warm turret
#

i did it

#

use sublister

sly kelp
vital adder
sturdy igloo
#

Help with AD Enumeration & Attacks - Skills Assessment Part I ? (below error)

#

unable to run powerview for AD skills assessment part 1 question 2

proven jay
#

Honestly wondering if that subdomain got removed by github or something

#

@sly kelp if you could check and see if you are still able to find the right domain, I would be very appreciative 🙂

feral stump
#

Can’t say if it has change

proven jay
#

ctrl-F finds no elephant

warm turret
#

Use sublist3r and grep for elephant, you'll find it in 3 minutes

proven jay
#

I tried with|| sublist3r -d githubapp.com | grep -i 'elephant'||, got nothing

warm turret
#

I do not know about -i option of grep but the sublister command is how i got it

proven jay
#

-i just ignores case

warm turret
#

Try several times then, sometimes the sources of su lister does not respond at the 1st try

ashen orbit
#

Anyone having trouble connecting to the VPN with the keys, seemed to work fine yesterday and today nothing connects

vital adder
#

@proven jay i can't even get sublist3r to work for me right now so i can't say if that tool work or not but i did found the right subdomain with c99 before and now the same scan give me nothing but if you scroll down a bit after the scan you can find "More scans of" that's scan in the past and i was a able to find the right subdomain there

proven jay
vital adder
proven jay
#

https://github.com/AetherBreeze/Sublist3r.git

#

This has a working sublist3r, they are trying to get it merged into main @vital adder

vital adder
#

this is all i god if i try to scan something

proven jay
#

hmm, I was only getting the VirusTotal error

vital adder
#

but it give me nothing after that

#

oh wait i just try to scan pornhub and that's the only domain work for me 🤣

ashen orbit
vital adder
#

is your pwnbox on?

ashen orbit
#

Yeah, its on

vital adder
#

oh then that's the issue

ashen orbit
#

Hate using it though, so slow

vital adder
#

yep the new pwnbox is bad

brave prawn
vital adder
#

and that's still the only domain that work well for me so far

vital adder
ashen orbit
#

oohh, just rebooted but that is probably it

#

Packers killing it, woot

sturdy igloo
acoustic peak
#

I’m stuck on the SQLi “Reading Files” section

#

Not sure what I don’t know here

acoustic peak
#

Could someone point me in the right direction on that page? I’m sure it’s there I’m just not seeing it

#

Got it… I’m dumb

rustic sage
#

Guys help me please, I can't find this hidden "history" file.
NootLikeThis

dire sentinel
#

@rustic sage try to list hidden files

rustic sage
#

-a

rustic sage
#

It worked...

tired elk
#

Hello to everyone! I'm taking the Information Gathering - Web Edition, Active Subdomain Enumeration Section but I'm stuck in this question: Submit the number of all "A" records from all zones as the answer.. Any hints pleasee ?? 😦

rustic sage
meager plover
#

Hey i'm a few days into the modules wanted if theres anything special you have to do in order to use your own virtual machine instead of the instance or browser parrot supplied. Is there anything special you have to do and if so any walkthroughs for what to do?

split meadow
#

Hola

vital adder
meager plover
#

when i click the vpn button it just redirects me to a blank page

vital adder
#

did you click download?

sturdy igloo
#

help AD Skills Assessment I question submit the users cleartext password ||lazagne.exe just opens and closes,|| does not really work. any suggestions

meager plover
#

ok i downloaded the file but now what do i do with the file? I have nothing on my mac that will open it

vital adder
#

i don't use mac so i can't help you troubleshoot but try using openvpn and if you have kali it should be pre-install

vital adder
sturdy igloo
ancient oriole
#

could I get a hint on AD Enumeration & Attacks - Skills Assessment Part II first question? ( Obtain a password hash for a domain user account that can be leveraged to gain a foothold in the domain. What is the account name?)
i really don't know what to do, I am stuck there for like 2 hours now

onyx rapids
#

Has anyone ever used XSSStrike or Dalfox to succesfully trigger the blind XSS in the session hijacking exercise? Solving the problem is easy now, but can't for the life of me get a tool to automate this step. Both tools support blind xss, and I use the same blind payload that I used manually, but neither tool will trigger it. I refuse to believe both of these tools can't do a basic blind XSS on a form made to be vulnerable

acoustic peak
#

Ok, legit question, cuz I’m beyond stuck. Is there a prerequisite to the SQL Injection course? The assessment on “writing files” is blowing my mind and I just want to know if I need to know something before this module in order to do it. If not, I’m sure I’ll find it.

west canopy
dire sentinel
ancient oriole
wheat garden
vital adder
#

oh wait that's weird the first half is correct

wheat garden
acoustic peak
dire sentinel
vital adder
#

@acoustic peak the skills assessment did grab my dick and twist it so it's no way in hell easy but if you break each step down and learn how the Injection payload work it's still hell but at least now you have a sense of what to do, and as the dumb ass i am i didn't note down any thing i learn, just the stuff in the module

zenith apex
#

What is programming languages i need to learn for to be pro hacker ?

vital adder
#

learn linux

#

and python

zenith apex
vital adder
#

nope

acoustic peak
warm turret
#

Hello, anyone can give me a nudge for the wordlist to use in the default credentials module?

zenith apex
vital adder
warm turret
#

Yes plz

#

I have used every word in the seclists scada defaults and nothing

vital adder
#

hint view the web source code and google that page default cred

warm turret
#

I have tried many others wordlists but obviously not the right one 🙂

#

Yes it says admin/blank

#

But admin is not the answer

vital adder
#

nope not the right one

#

keep search it on google you should find the default cred for that page

warm turret
#

I'll do that then

vital adder
warm turret
#

Thx anyway MRtom

vital adder
#

and if you still can't find it like the hint said google the page ||title||

modest token
#

I was wondering if I could get some help with AD Enumeration & Attacks - Skills Assessment Part I. I'm inside of MS01 and the need to find "cleartext credentials" for another domain user... I've been looking around MS01 for a long time and I haven't been able to see any 'clear text' credentials anywhere. Maybe I'm just missing something obvious? could someone familiar with the module give me a hint? ty!

quasi wave
#

do all regular HTB boxes require programming knowledge? Would I be able to work on my skills for a while without learning programming? I do want to learn a dedicated programming language, like Python. The thing is, I'm wondering because I heard everything that can be done in Python for hacking, at least in terms of what most people can write for hacking tools, is already covered by existing tools and I am pressed for time to learn fundamentals. Would it be ok to go through HTB Academy and then merely practice real world without advanced programming knowledge at first until I really cement the fundamentals?

#

see what I mean?

#

I'm thinking of doing HTB Academy and then Pentester Academy maybe or HTB Academy, then real world practice for a while, then learn a few additional things on Pentester Academy to reinforce the material and build upon it, but then maybe when I have more time actually dedicating time to learning Python, in order to get to the next steps?

#

I like this Python course I have been taking but I have trouble spreading myself thin.

#

so ya

warm turret
#

@quasi wave There are some stuff you should learn. For me having knowledge of programming bases have helped me a lot. You do not care about know about every python library but at least you should learn the basics of programming (variables, types, functions, collections, loops, etc) all of that will help you on any field of cybersecurity. Once you will learn how to do it in one language, the rest like bash, ruby, php, js will be more clear to you.

glad orbit
#

Dear friends, I see that you have completed the module: "DOCUMENTAZION E REPORTING". I ask you information about the first question. I dont' undestand what is the way to get an answer
I found this password in one file on remote pc: HTB_@c****************
But i don't undestand how use it

mint torrent
#

anyone still online

inland shoal
mint torrent
inland shoal
mint torrent
quasi moth
#

Hello everyone. I'm on module web proxies, section Proxying Tools. There are a some kind of a problem with proxychains syntax, but I don't really get where

frigid ingot
#

Getting a little stuck and frustrated on mod 20 sec 226

#

Any nudge appreciated

loud sapphire
placid quest
#

@frigid ingot what is the problem

loud sapphire
#

lol... i got it. me just dumb.

frigid ingot
placid quest
#

@frigid ingot ok

frigid ingot
#

I following the example but I’m getting these errors when I’ve done everything the example has done

#

I’ve downloaded the pcap twice

placid quest
#

@frigid ingot The hash is not loaded

frigid ingot
#

I’m so confused

#

How is it not loaded

#

I’m following the example, where is the hash im supposed to load lol

placid quest
#

@frigid ingot on exercise down you will down the file

frigid ingot
#

Correct I downloaded the file and got pcap

placid quest
#

@frigid ingot fellow along how the example was

frigid ingot
#

Yes if you look at the screen shots, it’s doing the exact same thing the example did

#

On both sets matches exactly the example and still get the error

placid quest
#

Did you check the file which you are cracking if it has the hash

obtuse root
#

@frigid ingot try using this: https://hashcat.net/cap2hccapx/ helped for me idk why but mine cap2hccapx complied from source on my kali could successfully open only .pcap files

obtuse root
#

can anyone help me with Login Brute Forcing - Skills Assessment

Once you access the login page, you are tasked to brute force your way into this page as well. What is the flag hidden inside?

I don't know what dictionaries should i use? tried with -L bill.txt -P williams.txt from previous sections and got no result. Also tried -l user -P rockyou.txt but it take way too long. no luck with ftp-betterdefaultpasslist.txt either :/

#

my last try:
|| hydra -l b.gates -P william.txt 165.22.117.21 -s 31327 http-post-form "/admin_login.php:user=^USER^&pass=^PASS&:F=<form name='log-in'" ||

sudden shore
#

Hey. Anyone for broken auth, tampering with cookies? I feel that something is wrong here, pls dm me

warm kernel
#

Hey, does anyone know where I can find the provided resources on the pwn-box? Im doing the footprinting on SMTP, and they say there is a footprinting-wordlist somewhere, but the find doesn't find it...

warm kernel
#

lol, I just found it there now...

#

of course its after I complain, sorry for the distraction

acoustic owl
#

No problem, I also searched at that time

warm kernel
#

using the wordlist isn't giving me any results on the footprinting of the smtp server. Command im using, smtp-user-enum -M VRFY -U <PATH TO FILE> -t <IP>

#

also doing the same with msfconsole, and getting 0 hits... :S

paper gust
#

@obtuse root @frigid ingot FYI, hccapx is a deprecated format

frigid ingot
#

@paper gust when you look at my screenshots provided, I’m doing the same thing as the example, I’m using 22000 as the mode

paper gust
#

yes but you have loaded a hccapx file

#

which is the deprecated format and won't work with 22000

#

the module is out of date, we've made changes since it was released and it probably needs to be updated sooner rather than later

warm kernel
paper gust
blissful verge
paper gust
#

sure, its an easy fix

warm turret
#

hello, someone can point me to the right wordlist to use in the default credentials section of the broken authentication module. i can not find the hmi/scada default login needed to complete it after several days. plz 😫 i'm really frustrated

acoustic owl
sudden shore
#

Um anyone for what I said a few posts ago? Thanks

cosmic dock
#

If i purchased the $210 option for Academy, but want to upgrade to the 400 one, will it only cost the difference between the two or am i screwed out of the extra cash

fierce sparrow
cosmic dock
#

this is such a PITA

raven cairn
#

This is a little bit of a rant but the new pwnbox is garbage

#

Foxy proxy not installed by default?

#

Automatically dropping you into the root directory?

#

Wtf lol

meager plover
#

ok i'm still figuring this out. I have my own parrot virtual machine. Can I just run the excercises without using hackthebox's specific vpn? I'd like to use the key supplied by them but I don't know what to do with the file after I download it.

ebon vault
#

Hello
sorry for the question but is it possible to Writeup from the academy modules or is there any restriction in one case
could you help me with this question please
thanks

raven cairn
#

I'm a little stuck on this question from Broken Authentication -- Guessable Answers

#

Am I suppoed to OSINT?

acoustic owl
raven cairn
acoustic owl
storm dagger
#

I wonder if the typo is intentional

raven cairn
warm turret
#

@meager plover after download the open vpn file just use: openvpn filename and voila, you will be connected to the corresponding vpn. There are not the same vpn for the boxes, academy or beginners challenges

warm turret
cosmic dock
sharp cedar
#

Hi! I'm currently doing the "Getting Started" module and I got stuck at the last task in "Service Scanning" part. It's my first time using SMB and I'm getting this kind of response from the machine. Would anyone be so kind to give me a tip to find out what am I doing wrong? It looks like the server is kicking me out due to "no compatible protocol selected by server"? How can I fix it if it's the server selecting the protocol? And what about the last line "nor workgroup available"?

cosmic dock
#

My money tree can't grow that fast @warm turret

#

And just for my clarification - if you do the 400 (Silver annual) one, does that mean you can skip fulfilling the modules and just attempt the exam?

sharp cedar
sudden shore
#

hey @sterile hawk can i get some help here? broken authentication module - Cookie token tampering ? not working properly, would appreciate it, thanks

snow girder
sharp cedar
snow girder
#

yes

warm turret
#

it is the idea of -L (list) yes

sharp cedar
# snow girder yes

why is it screaming about these protocols and workgroups instead of just showing me the shares then? I'm probably overthinking xd

warm turret
#

🙂

snow girder
#

then you can enumerate those shares by providing the names one by one, and that way you can list the content of those shares

#

(if you have permission)

cosmic dock
#

@sharp cedar It did show you the shares. Are you talking about the contents of the shares?

sharp cedar
#

I expected to stay in the connection and be able to choose a share to enumerate

cosmic dock
#

Ah

warm turret
#

@red obsidian anyone can point me to the right wordlist to use in the Default Credentials Section of the Broken Authentication Module??

cosmic dock
#

Get rid of the -L then lol

sharp cedar
#

haha yes that's what solved the "problem" 😄

fast copper
#

the pwnbox is giving private key errors even after resetting and terminating it, is something down right now?

sudden shore
#

@warm turret that's just a bot, made that mistake myself

#

but apparently htb crew doesnt respond, been trying for the past few hours now

warm turret
#

@sudden shore it means??

cosmic dock
#

I've also been waiting in their contact queue for a while as well.

sudden shore
#

is there a contact queue? lol ?

cosmic dock
#

Yeah the help center thing

snow girder
#

I'm looking for a solution to raise the nr. of active connections with cloudflare rate limiting. By any chance do any of you know if they can help with that? (for a university the public WAN IP getting rate limited)

snow girder
#

thanks

near linden
#

How do I bypass "tcpwrapped"?

#

Is there like other vulnerability that I can use of?

carmine quail
nimble ridge
#

can someone help me with the password attacks module? i want to run this command crackmapexec winrm <ip> -u user.list -p password.list but i don't know what i should insert as the user.list or password.list

cosmic dock
#

Going on 3+ hours now waiting for a response in Help Center for academy... loving it

vital adder
#

mind if i ask what issue are you having? also you need to refresh the page for the staff message to show

vital adder
nimble ridge
cosmic dock
nimble ridge
vital adder
brave prawn
#

Can I dm someone about Web Attacks Assessment?

vital adder
normal spear
#

Need a hint for the Command Injections skill assessment; The injection point should be a POST request, right? Or is it possibly a GET request?

fervent veldt
#

i am losing my mind on the simple flag hunt for Wordpress Hacking - Directory Indexing. is the module broken? the flag is not in any WP directory and there are no solutions available, thanks for your help

fervent veldt
#

figured it out haha, i was way overthinking it

normal spear
#

I believe that would go under #858470491676737536 . You can look at the pinned message there to see how to format your feedback

prisma mason
#

anyone know how to upgrade privelages to root in Parrot OS?

pearl island
#

sudo su

prisma mason
#

oh wow thank you

ancient oriole
#

could I get some hint on AD Enumeration & Attacks - Skills Assessment Part II - Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host.?|| I found some ~110 characters password for username SQL01$, I tried to use that password with the mssql user, but it did not work. I am not sure but I feel like it's a rabbit hole.|| ||Edit: Now I found a password for user mssql in memory which seems a lot more human, but I still cannot RDP with it.||

vale salmon
#

Alright, I'm struggling with Active Directory Enumeration & Attacks: Child - Parent Trusts from Linux. I can't figure out how to get the NTLM hash for bross.

forest drum
#

Is anyone around that can help out with the "Getting Started" Knowledge Check? I have been struggling all evening. In the Forums people say to use metasploit but I cant get a shell. Edit: I got a shell finally!

wide river
#

hey, just curious, whats gonna happen if i click this button ?

lavish torrent
#

I can't use the 'sudo -l' command after using msf to get the reverse shell, but I saw on Youtube that others can use the 'sudo -l' command after using the 'Shell' command, what is the reason?

forest drum
#

There is a way with python to 'upgrade' the shell.

modest token
# acoustic owl Mimikatz is your friend

thanks for the advice @acoustic owl, I set up a network share on MS01 and uploaded mimikatz to it, ran it was admin, I know the user's name who is supposed to have cleartext credentials t*****, but in the output that's returned I've only got an unbreakable NTLM hash for that user. I grabbed a lsass minidump and ran mimikatz on it as well, no luck... Strangely enough it did give me the cleartext password for MS01 which is a ridiculously long string of random special characters, numbers and letters... I guess I'll try brute forcing the NTLM hash next.

lavish torrent
#

@forest drum thank you so much!

vale salmon
#

Okay, in the Cross-Forest Trust Abuse Section of the AD Enumeration Module, it wants you to log in toe the ACADEMY-EA-DC03.FREIGHTLOGISTICS.LOCAL Domain Controller. I am having a serious memory issue on how to connect to it.

modest token
vale salmon
#

Ahhh right! Thanks!

acoustic owl
carmine quail
#

In the Windows Fundamentals module Skills Assessment I completed all the questions except for the first. Who can help me answer: "What is the name of the group that is present in the Company Data Share Permissions ACL by default?"

carmine quail
#

I already tried all the options output by icacls

carmine quail
#

nm - figured it out.

trail anvil
#

can anyone help a noob out on the opensource machine?

#

im trying to find the mac address of the server running the app

warm lichen
#

Can anyone tell me if I'm missing something here?

The target for the exercise of the XXE portion of the Web Attacks module is just an IP. It doesn't resolve to a web app, which is what I would've expected

#

I feel like I'm missing something trivial here

storm dagger
warm lichen
#

Oh nvm, my VM must've disconnected from the VPN 🤡

#

It works now

placid quest
#

@warm lichen if it's xxe you will need to use brup

warm lichen
#

Layer 8 problem

placid quest
#

@warm lichen what is the problem

warm lichen
#

My connection to the VPN was just cut off for some reason, so I couldn't resolve the host

crisp remnant
#

Can someone ping, i have a question about the web attacks module

placid quest
#

@crisp remnant what question

vital adder
#

what's the issue?

#

sure

shrewd heath
#

I am having some issues with a module

#

Obtain a session cookie through a valid login, and then use the cookie with cURL to search for the flag through a JSON POST request to '/search.php'

#

this one was called web requests

#

I obtained the session cookie, and I used the JSON post request to try and get the flag, but all it returns me is: "A valid authentication cookie is required!"

#

curl: (6) Could not resolve host: application A valid authentication cookie is required!

warm lichen
warm lichen
shrewd heath
#

curl -X POST -d '{"search":"london"}' -b 'PHPSESSID=c1nsa6op7vtk7kdis7bcnbadf1' -H 'Content-Type: application/json' http://<SERVER_IP>:<PORT>/search.php

#

(also I changed the server IP to the correct stuff lol)

warm lichen
#

Oh sorry no that's correct, I just didn't fully read the error message. You're sure that the cookie you used is correct?

shrewd heath
#

I am pretty sure, I logged in with the correct creds, and looked in the network tab, and copied the session cookie

warm lichen
#

Hmm you're doing something wrong. You're absolutely sure you copied the correct cookie? I just tried it on my end and it was fine

#

You might have kept the cookie from the example and forgot to replace it with the valid cookie you got after logging in

shrewd heath
#

yknow, it might be that I am using windows

#

I was using my linux system earlier

#

and I did challenges fine

warm lichen
#

Nah that shouldn't matter for this exercise I don't think

shrewd heath
#

I will try again, hold on

warm lichen
#

Wait yeah it might be because of Windows. I think you might need to escape the double quotes with \

shrewd heath
#

ahh, I heard that somewhere

#

its proof OS based on the linux kernel is so much better XD

warm lichen
#

Sorry, to be more accurate I think that curl executed from cmd doesn't like ' (single quotes)

#

so it'll need to be something like

curl -X POST -d "{\"search\":\"flag\"}" -b "PHPSESSID=<your cookie>" -H "Content-Type: application/json" http://<your target>/search.php

shrewd heath
warm lichen
#

All good

shrewd heath
#

Received content contained invalid JSON!

#

lemme try something rq

warm lichen
#

paste your exact command here

shrewd heath
#

I forgot a "

#

I got the code, thanks for the help

#

I will remember the difference between curl on linux and windows now

#

👍

warm lichen
#

No worries

shrewd heath
#

I just cant believe I spent over an hour on that because of quotes where if I was on a linux system I would have done it in 5 minutes 😂

warm lichen
#

Happens to every one 🙂

clear bough
#

i guys, can anyone help me with Broken Authentication "password Bruteforce" module on question "Using rockyou-50.txt as password wordlist and htbuser as the username, find the policy and filter out strings that don't respect it. What is the valid password for the htbuser account?" ... i have found the password policy but have a problem on modify rockyou-50.txt with regex and it doesn't work

warm lichen
#

What's not working with it? Is your regex not correct

clear bough
#

i'm not really expert of regex and i can't make a working regex

orchid ingot
#

When will a new module be released?

warm lichen
# clear bough can i DM you?

I'm not really home right now so I can't help you. No one's good at regex man, you just struggle through it each time 🥲

silver zenith
#

I still need to complete 80% hahahaha

proven brook
#

Hello, may i dm some one for AD Enumeration & Attacks - Skills Assessment Part I Question about ||tpetty|| cleartext password.

brave prawn
#

Hey, can I get a hint on Attacking Common Application Wordpress Enumeration? I think it is an easy one, but i can't find other plugins instead of contact-form-7, wpdiscuz and mail-masta. Tried even with ffuf to find all pages and grep their plugins, but nothing.

sly reef
#

can someone help me out on hydra module?

chrome thistle
#

Hey, someone who can help me with the web attacks module?

brave prawn
chrome thistle
#

thanks for quick response

sly reef
#

can't seem to find a correct pair on bruteforce module. hydra has been running 30m what should i search for?¿

sly reef
brave prawn
sly reef
#

skill assessment - website second flag

brave prawn
sly reef
#

im running

#

S=HTB

#

as there will be a flag

brave prawn
# sly reef as there will be a flag

i didn't use S=, i was using F=, and specified string from login page source code, so that hydra can differ success login attemps from unsuccessful

rustic sage
#

Hi guys

sly reef
#

didnt get a working pair so i went with S

rustic sage
#

Sup boys

brave prawn
sly reef
#

np thanks 🙂

warm lichen
# sly reef S=HTB

I don't recall if successful log in returns a 302 HTTP response so the flag may not be there, so it's better to use F
I think I did F=<input name='user' according to my notes

brave prawn
sonic river
#

heyyy

warm lichen
sly reef
#

thats the last section

warm lichen
#

How do you know there's a user / admin user then?

sly reef
#

basic http auth creds are user:password

#

hint says to use the username u found so i assume it is user

#

have been running hydra 30+minutes which seems not ok for an academy simulation

warm lichen
#

Oh

#

Have you solved Q1?

#

It's the user you found for that

#

Nvm sorry I misread you entirely

#

Can I see your hydra command?

sly reef
#

one sec

#

hydra -l user -P /usr/share/wordlists/rockyou.txt -f -t 4 167.99.202.193 -s 32119 http-post-form "/login.php:username=^USER^&password=^PASS^:F=<input name='user'"

warm lichen
#

Lol I see where your mistake is

sly reef
#

no way

#

admin_

#

lemme retry

warm lichen
#

I was going to suggest you proxy hydra to burp and inspect the response 🙂

#

but you got it

sly reef
#

anyway this morning i was testing with admin_login and didnt get creds

sly reef
#

would appreciate a hint

warm lichen
#

Log in with a dummy user/pass on the website and then inspect the request on burp

sly reef
#

on it. thanks

warm lichen
#

If you get stuck, the mistake was:
||the variables for the username/password don't match up with what the webserver is expecting (i.e. user / pass)||

sly reef
#

works with S=HTB aswell

high totem
#

Hey, a question about Footprinting Lab - Easy. What's going on with the Entering Extended Passive Mode when connecting to ftp? It tells me that command (say ls) was successful, but there is no result. Am I doing something wrong, or is this intended?

high totem
# lethal atlas maybe dir?

Same thing. However I think I was able to connect via Filezilla, so let's say problem solved (managed to download some files 🙂 )

#

Ok, I finished that lab. What was the DNS part in the description about? || I did some enumeration of it, but I think it's just a dead end? Is there any useful information in that?||

west canopy
flat silo
#

I'm on the attacking web apps with ffuf in the value fuzzing section they want me to write a bash script to make a custom word list I wrote the commands they provided and got permission denied tried to add sudo to the front of the command and got an error within the command what do I do

flat silo
#

I'm already at root

brave prawn
#

not root

#

home

#

like cd ~

brave prawn
west canopy
bleak prawn
#

Hi, on the sqlmap fundementals module, I'm having some trouble solving flag6.... I think I've tried everything.... Do any of you have some additional hints that I can try?

exotic fox
#

Hi. In the CTF platform. Is there any option to change the name of my team?

muted hull
#

Hello, when i complete a module but a later date have another look at it do i have to do all the optional questions done again or re-spend cubes to open it?

arctic acorn
muted hull
#

Thank you!

naive ravine
#

Did anyone ever experience a scenario where you try to connect to a target that you just spawned, in web browser but you cannot connect to it

arctic acorn
lean atlas
raven cairn
#

Can I have help with “Username Injection” on the broken Authentication module?

naive ravine
twin gulch
#

Guys

#

I’m at password attacks module need some help at some point. Just made that mut passwords file and ran hydra against ‘sam’ at ssh but with no luck, nothing is wrong with my commands and the file also is fine

lethal atlas
south lark
#

just a heads up- in the module shells & payloads, on the 'anatomy of a shell' page the second question asks for the version of powershell deployed but powershell is not located in the panel of the pwnbox anymore (like shown in the module). I think this might create a lot of unnecessary confusion since powershell is ran with pwsh and not just powershell which is not intuitive and also not in the module! 😄

modest token
modest token
thick dune
#

I wanted to know what exploit was performed in python 3 to obtain root and user access to retrieve the flag of this user in machine bank

raven cairn
#

Jarednexgent pls help 😭😭😭

#

This module is no fun :/

west canopy
normal spear
raven cairn
vital adder
vale salmon
#

I'm on the first Skills Assessment for AD Enumeration and Attacks and I'm trying to gain a foothold from the webshell. I'm struggling a bit, but I want to figure it out, so could I just get a small nudge in the right direction. I've tried several things, but nothing I've tried so far has gotten me closer.

woeful oxide
#

Hey guys

#

Working on FL - Skill assessment

stray grove
woeful oxide
#

I have access to the ||admin panel|| and the ||logs || but when poisoning the ||user agent|| my code doesn't get executed

woeful oxide
#

guys?

vital adder
#

did you ||use double quotes|| for the payload? if you did then try using ||single quotes||

woeful oxide
#

no fucking clue whats wrong

vital adder
#

first you are using ||double quotes|| try with ||single quotes|| and in the user agent just put the payload and nothing else

woeful oxide
#

got it

#

nothing

#

same error

vital adder
#

send me a dm with the screenshot of that error

rustic sage
#

having issues getting the flag from the smb section of the footprinting module, keeps saying permission denied. Could anyone help me out with that?

vital adder
#

are you doing this on the pwnbox?

rustic sage
rustic sage
vital adder
#

the new pwnbox terminal spawn you in /root by default so you have to cd out every time if you didn't do that and try to get the flag from target machine it will give you permission denied

#

or you can use more flag.txt to read the flag without download it

rustic sage
#

man that was super simple lol thank you

forest drum
#

Is there anyone on that can help me out with the "Getting Started" module's "Knowledge check please"? I have the first flag, but an having a tough time with privesc. Nevermind, I found the solution.

vale salmon
frigid ingot
#

Hello all, trying to do mod 20 sec 226 when I download and install hcxtools it does not install hcxpcaptool, how are we able to extract the hash if we don’t have that tool

vital adder
#

you need to Compile it and pls give the module / section name next time

frigid ingot
#

I did give the mod and section

vital adder
#

the name not the number

frigid ingot
#

Cracking passwords with hashcat

#

So when I try to compile im getting an error

vital adder
#

did you run it as root?

frigid ingot
vital adder
#

nope you need to run it as root

#

with sudo

#

oh wait

#

you are on kali that tool is pre-install

frigid ingot
#

No lie?

vital adder
#

yep

frigid ingot
#

Then why did I have download the repo

vital adder
#

that's there for the one who need to install it

frigid ingot
#

I must be really stupid if I can’t find it

vital adder
#

oh and for the first question in that section the hint said to use the other tool but if that doesn't you can just use ||hcxpcaptool|| for both

vital adder
frigid ingot
#

I thought about that tool, but reading with the example that tool wouldn’t extract the hash from what I read

vital adder
#

i'm using kali 2022.1 and that tool is pre-install for me but i did saw some stuff change in some of the newer kali version so i'm 100% sure if that tool is pre-install for sure but it's to remove it from kali

vital adder
frigid ingot
#

Correct

vital adder
#

then yes that's the right tool

frigid ingot
#

I’m drawing a blank to find out which version I’m running

vital adder
#

for the version run cat /etc/os-release but you can just check if the tool is installed or not with hcxpcapngtool so run this first

#

if it's give you no option selected then the tool is installed but if it's give you command not found then it's not install for that you can Compile the tool with sudo make; sudo make install

frigid ingot
#

The hxcpcapngtool.c is there

vital adder
#

you have a typo the tool is hcxpcapngtool not the thing you use

frigid ingot
#

So yes it’s there

vital adder
#

oh good then you can just use it you don't need to Compile it

frigid ingot
#

Do I still need to find the hash of the file?

vital adder
#

yes

frigid ingot
#

I hope I’m on right track

vital adder
#

yeah you just extract the hash from 1 file so yes and you probably need to put some spoiler tag on that

frigid ingot
#

I think I’m getting it

vital adder
#

you also need to put a spoiler tag on that

frigid ingot
#

It finished and was able to solve it

rapid jewel
#

Nsn

#

Why i can send pic ...i need a help

#

😑😔

#

Cant

vital adder
trim yoke
#

—solved— running two openvpn connections from host and vmware is not good

#

.

#

.

loud sapphire
#

SQL Essentials. Bypassing Web Application Protections
Case 10. hint please?

#

DM always open

vital adder
loud sapphire
loud sapphire
#

all fixed. 🙂

gentle willow
#

I’m not sure if I’m being stupid or something. For someone who’s looking to come into this field is there a module that allows you to familiarise with the basic Linux commands or is that a Google thing off my own back? I’m having trouble even with the foundation modules currently

#

Apologies if this is in the wrong section

stray grove
gentle willow
#

Thanks, much appreciated! have a nice day

lime moth
#

Woooop! Got my first root shell on the Footprinting - Hard lab and finished excersise 1 minute before my target went offlineFeelsGoodMan

loud sapphire
pastel ginkgo
#

Ok I feel like an idiot for asking this, but I've been stuck on it since yesterday. I'm trying to do the Fingerpriting Module and im stuck on the first DNS question which says to get the FQDN

#

For the life of me I cant find what its looking for and I feel like a total idiot

vital adder
#

i don't really know how to give you a hint on this but check the ||DIG - NS Query|| part in that section

carmine quail
#

is anyone around who can answer a question on Attacking Common Applications - WordPress?