#modules

1 messages · Page 11 of 1

carmine quail
#

specifically, the skill section says to "Enumerate the host and find a flag.txt file in an accessible directory." I can't find it and I want to check my reading of the statement/question. Are they saying there's a folder location accessible without using an LFI vuln to see? Or are we expected to leverage the LFI? I looked through all the folders by downloading the website with wget and used tree to view the structure. I can't find the flag.txt

#

did you get help on that one? I have a hint on it. I need help on the first question in that section.

pastel ginkgo
#

I've done that and thats why I feel like an idiot as nothing I put in comes out as the right answer

#

I'm honestly at a total loss I was able to get the answers for the other questions and am working on the last one now which you look for the subdomain matching the right ip

frozen atlas
#

is ryzen 7 better or intel i7

#

?

vital adder
vital adder
carmine quail
west canopy
#

thanks, ill make a note of this

feral stump
high totem
#

Hey, any nudge for the footprinting hard lab? I must be missing something, but cannot find a foothold :/ Especially that before in the exercises there always was some kind of name available

drifting glacier
#

Question on the IMAP/Pop3 section in the Footprinting module. For question 4(What is the customized version of the pop3 server) I'm not sure what more of an answer this question is looking for. I found ||InFreight v9.188\x0d\x0a via metasploit||, but multiple variations of that answer is still not working as well. Any nudge in the right direction?

cosmic dock
#

I'm about to lose my mind on the IDS evasion: Hard module

drifting glacier
high totem
drifting glacier
high totem
high totem
cosmic dock
fierce sparrow
#

anyone can help me on ATTACKING ENTERPRISE NETWORKS ?

lethal atlas
#

can someone remind me how to do the spoiler thing

feral stump
feral stump
#

|| sjdbddj ||

#

Start with ||

#

Put the text in between and finish with ||

flat silo
#

I'm working on extension fuzzing for the assessment at the end of the ffuf module. I found the two extensions but it's telling me that wrong

#

Can anyone help

flat silo
#

Ok I'll figure out the third tonight then

#

Thanks is there a better word list then the web-extensions.txt from seclists

dense ferry
flat silo
#

Still only 2

runic nimbus
#

Can someone help me find the .ovpn file? The online instance keeps crashing.

mellow turtle
#

|| message ||

lethal atlas
lethal atlas
mellow turtle
#

👍

runic nimbus
#

yeah that doesn't show up for me.

#

ig I'll raise a request, thanks!

acoustic owl
runic nimbus
#

yoo lifesaving, thanks!

raven cairn
#

Can I have some help on the broken authentication module: Brute forcing cookies section question 2?

hazy minnow
#

@raven cairn what wordlist are you using?

#

Can anyone help with the "tamper the rememberme token" question for Broken Auth Module? Can get the decoding right..

raven cairn
austere cave
#

Day 3 Right Now - Day 4 2nite! Get an Urge, Call Anyone or Join a Discord Audio Video Group and Find more people to work with & talk to, Get Clubhouse, ETC Especially!!!

raven cairn
#

I'm just trying to work on my cyberskills. Don't distract me SMH.

polar crag
#

im not sure if i understood snmp right but i tried the commands given in the module, tried enemurating different community Strings using onesixtyone with different lists buti cant find that custom script
can anyone give me a hint?

#

Footprinting SNMP

mystic perch
#

Has anyone finished the password attacks module?

vapid grove
#

Hi guys, i'm stuck at AD Enumeration & Attacks - Skills Assessment Part I, i've solved the first 3 questions (found the flag and the spn and cracked it), but i can't reach the SQL01 or MS01 machine and get admin privs, could i get some hint on it? Thanks

pastel ginkgo
#

I'm having trouble with enumerating the smtp server for the footprint module. I'm able to telnet in but it hardly responds and constantly times out. I've been giving commands like || VRFY ryan || but I don't even get a response back at all. I've also tried using || metasplot and smtp-user-enum with the provided fille || but its not getting any response either. Is this a issue with the VM?

feral stump
iron basin
#

Anyone able to help on the last question of the Metasploit module, last question of the Sessions & Jobs section? Has to deal with escalating privileges on a box using metasploit.

raven cairn
iron basin
#

@raven cairn I am able to run the local exploit suggester module on the box. I then try to use the 3 exploits it shows to work/potentially work. I run the exploits, they complete yet not session is established. I make sure to switch the ports to not be the same as the original section. A bit stumped at the moment.

timber hatch
#

What is the FQDN of the host where the last octet ends with "x.x.x.203"?

...wow after 2h i found out that i have to be patient and wait till my big wordlist finds the result...

raven cairn
frail willow
devout cliff
#

is anyone skilled with sqlmap and some of the http error codes you can get when running it? i came across one im unfamiliar with and would like to know what it could indicate

raven cairn
raven cairn
devout cliff
#

its error code 510

frail willow
pastel ginkgo
wind gust
#

What interface do I listen on for rev shell using the hackthebox machine?

#

there are like 3 interfaces

wind gust
#

Thank you

stray grove
dense rock
#

Having trouble with the final question on Service Scanning in the Getting Started module. The hint says ||bob uses weak passwords||, but I've tried a bunch of them and I can't get in. Tried using metasploit's smb_login, but it doesn't want to connect. The anonymous ftp server has a file that I don't have the rights to. Not sure where to go from here.

teal helm
#

having some fun with burp intruder section of using web proxies, theres no indication what list should be used to fuzz, and with it beiing soooo slow with out professional any nudges to the right one?

raven cairn
teal helm
#

Thanks Yaoi

raven cairn
raven cairn
teal helm
cold oracle
#

are password reset emails not working?

dense rock
raven cairn
cold oracle
#

nothing there

#

tried resetting twice, i used it last night

raven cairn
dense rock
#

Ah wow

cold oracle
#

does anyone that can check if their password reset systems are bugging out

#

idle in discord?

raven cairn
#

Contact support

#

But honestly i doubt they are having issues on their end tbh

cold oracle
#

that is so weird

raven cairn
#

Can I have help with this

#

confused on the instructions

#

I have been able to decode the reset token pretty easily

#

but how am i supposed to "forge a valid temp password to login?"

slender sequoia
#

hello guys, im a new member, i need help for use a app in my virtual box

brazen dust
#

Hey everyone, I am trying to find the custom script on the server for the Footprinting - SNMP section, can someone give me a hint. I am not sure what I am looking for is the problem

brazen dust
#

I got some help, it was a dumb HTB flag not actually a script so....

#

but thanks @pearl island

pearl island
#

No worries!

#

Hey all, Need some direction on Password Attacks Easy Lab.

rustic sage
restive zephyr
#

Can someone help me with the Attacking Common Services Skills Assessment Hard? I can login in the RDP but i dont know what to do with the mssql.

jaunty vigil
#

100% sure there is a bug in skills assessment file upload

#

any admin available to talk?

rustic sage
#

Can anyone point me in the right direction on the footprinting/imap+pop3. Cant find the admin email address and the final flag

woeful oxide
pearl island
#

Anybody else getting the same error on pwnbox?

#

If yes, how did you circumvent it/ fix it?

vital adder
#

use pip3

brave prawn
#

hey, i am on module Attacking Common Applications section Tomcat Attacking. can't find the flag, tried find / -name tomcat_flag.txt and even manually, but nothing

vital adder
brave prawn
vital adder
#

that's weird mind if i send you a dm about that?

vital adder
#

which section?

tiny ledge
#

I am currently doing: Web Attacks - Skills Assessment | I already completed the first part few months back, where I changed the password of the admin account and logged in, however; now when I'm trying to do the same I'm getting Access Denied. Can someone remind me what am I missing to change the password again, so I can start working on the part where I left of to get the flag.txt from the backend servers, thanks!

vital adder
#

for that you need 2 main thing the ||uid|| and ||token||

tiny ledge
vital adder
#

oh then a hint for that ||request type||

tiny ledge
tiny ledge
vital adder
#

the flag is at /

tiny ledge
acoustic peak
#

Ok, I think this is the place to go with this question. If someone wanted to go from zero experience to “ready for the battlegrounds” the most efficiently, which path(s) would that person take?

rustic sage
#

You are dealing with MSSQL, right?... Just use the appropriate tools... 😉

short brook
#

heyy

cosmic dock
#

What is the FQDN of .203? tired of wasting time on it

craggy rapids
#

Hey guys can someone help me ? I'm stuck for about 1 day on this question I have upload the webshell to the target but I don't understand how to access the wp-user directory ?

I didn't find any infos on the forum or here.

MODULE : WORDPRESS

Thanks @west rampart @autumn pilot

west rampart
#

@craggy rapids No

craggy rapids
west rampart
#

Anytime

craggy rapids
#

this is not cool man I'm really stuck 😦

west rampart
#

random ping is also not cool

lethal atlas
craggy rapids
craggy rapids
lethal atlas
#

how would you access a directory on your vm?

vital adder
craggy rapids
tranquil sierra
#

guys can you help send me the python download link my browsers and cmd not working

cosmic dock
short brook
#

@tranquil sierra May I DM you the link?

tranquil sierra
brazen dust
#

Does anyone know of a good web hash cracker that will work for the IPMI hash that was dumped by metasploit for the IPMI module in Footprinting.....If i use hashcat it says like 7 days

brazen dust
#

ok let me check thanks

devout cliff
#

John is such a nice guy

stray grove
vital adder
brazen dust
#

yea using the rockyou.txt took like seconds lol, thanks all. I was trying to use what was in the example on the training

stiff stream
#

@rustic sage thanks managed to do IT!

meager pond
#

Not sure where to ask i cant ping my target machine it was working just fine recently i restarted openvpn couple times tried diferent config

#

I play through parrot os vm

brazen dust
#

you use sudo or root correct?

vapid grove
#

anyone can give a little help on Active Directory skills I?

meager pond
#

@brazen dust i used sufo openvpn pathtoconfig

#

Sudo

#

Yes i restarted it

brazen dust
#

Make sure your pwnbox is not on if you are using your own vm and sometimes ill just do a sudo su - and log in as root

meager pond
#

Ok thanks

stray grove
vast geyser
#

Hello , I'm stuck on question#1 of the Predictable Reset Token module, this is my script, coluld anyone give me some hint?

rustic sage
#

Hi

#

Speak spanish please?

raven cairn
#

I can send you the script I used, it is pretty similiar

flat silo
#

Does anyone know the word list needed for the ffuf assessment recursion scan ive tried a variety and am not getting any type of a hit

torn inlet
#

HELLO

dire sentinel
raven cairn
#

Having difficulty with the broken authentication skills assesment. This skills assesment is pretty huge haha.

#

Been able to decode cookies

#

Enumerated the password policy

#

I think I might have to brute force the password. Doing this requires filtering rockyou.txt with regex, and I suck at that

vital adder
#

if you was able to decode cookies you can just change it to the admin and skip the rest if you want you just need to find the admin user

flat silo
#

Third question in the assessment I used the syntex from the cheatsheet and followed the hint and keep getting nothing

vital adder
#

oh yeah i also have an issue with this question try restart the target a few time and try again

#

i did note down 4 time work for me

flat silo
#

Ok thank you I'll give it a try after work

raven cairn
vital adder
#

i mean you can but if you know the format you can just guess it

raven cairn
#

@vital adder Can i dm?

vital adder
#

sure

wind gust
#

the answer for HTB is very precise/picky

west canopy
#

can anyone let me know if they are able to use wireshark on pwnbox and successfully capture traffic on Tun0?

lethal atlas
#

sorry Jared, I can't say that I have tried

west canopy
#

all good just wondering if this is a pwnbox issue or personal issue lol

lethal atlas
#

I have just never had much luck with pwnbox.

cosmic dock
#

Ok... what am I missing in the Footprinting Easy lab

#

Nothing on port ||2121|| is allowing me to connect

timber hatch
#

Modul: Footprinting
Section: SMTP
HTB Question: Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer.

My tries:
perl smtp-user-enum.pl -M VRFY -U footprinting-wordlist.txt -t <IP>
sudo nmap <IP> -p25 --script smtp-enum-users -v
msfocnsole: smtp_enum

My Question: This did not bring any Results, any hints?

cosmic dock
cosmic dock
cosmic dock
solid wedge
#

Enumerate the hostname of your target and submit it as the answer. (case-sensitive) Can anyone help with this

fierce sparrow
#

anyone for the command injection module?

daring drift
#

Hello guys

#

I just installed the Linux 20.04 and I have some issues with sound

#

Can someone please help me with that 😃

solid wedge
#

Network enumeration with Nmap

vital adder
#

and the section name?

solid wedge
#

the second question

vital adder
#

yeah i'm double checking some stuff in my note i use -A and that's given issue right now but try that

solid wedge
#

sudo nmap 10.129.2.49 -A like so

solid wedge
vital adder
#

i use it on the ||highest port||

solid wedge
vital adder
#

it's a spoiler tag just click it

cosmic dock
#

Did anyone ever get an issue with the SQL server on Footprinting - Med?

vital adder
#

the hard lab?

solid wedge
lethal atlas
timber hatch
lethal atlas
#

right on

lethal atlas
cosmic dock
iron basin
#

Anyone mind assisting with the Special Permissions section of the Linux Privileges Escalation

lethal atlas
#

or think about what sa might stand for

vital adder
solid wedge
#

nothing

vital adder
#

ssh isn't going to show you the host name

#

use -A with some of the port you found

vital adder
gloomy tangle
iron basin
#

@vital adder Yeah the wording was messing with me. So just run the two commands and compare the output, got it.

solid wedge
vital adder
vital adder
#

yes

lethal atlas
iron basin
#

@vital adder May I DM you?

vital adder
#

sure

solid wedge
# vital adder yes

sudo nmap 10.129.2.49 -A -p 22 80 110 139 143 445 31337
ran this scan nothing

solid wedge
vital adder
#

sure

cosmic dock
#

Ok... What table is the HTB user in? Digging through all of this is ridiculous

#

nevermind.

timber hatch
#

Modul: Footprinting
Section: IMAP / POP3

I'm a little embarrassed, but I'm struggling with this question:
Figure out the exact organization name from the IMAP/POP3 service and submit it as the answer

i mean i did a nmap scan with -sC -sV, that gives me "organizationName=Inlanefreight".
but this doesn't work...

vital adder
#

hint an organization name need to have some stuff at the end of their name

pastel ginkgo
warm turret
#

hello, someone can give me a nudge on Guessable Answers. i can not find the right question/wordlist

lethal atlas
#

I just picked the question about favorite color and kept guessing

warm turret
#

just what i did but using seclists i can not find the answer

lethal atlas
#

never did get the script working

warm turret
#

mmm... ok, i'll try the hard way then

warm turret
#

@lethal atlas i got it. I can not make the script work though. Weird

#

thanks

raven cairn
#
#

I can't believe I actually finished this module!

#

Brutal haha

woeful oxide
#

cheers mate

#

struggled a lot with it but at the end saw the light

#

I really enjoyed it but damn, it has some tricky questions

heady nymph
#

need help sqlmap final_flag cannot find vulnerable page. I tend to overthink things...

sharp elm
#

I was completing a final part of a module and my target box crashed, every time i spawn a new target or local host i am getting a series of xfreerdp errors. Any ideas?

brave prawn
#

hey, can someone help with enumerating the users of gitlab on module Attacking Common Application? Im running script and that all i get

sharp elm
polar crag
#

finished the Footprinting Medium took me a while but it was really fun anyone who need some hints feel free to dm

mellow turtle
#

@polar crag The academy footprinting module?

mellow turtle
#

Can i dm u @polar crag ¿

polar crag
#

sure

rustic sage
#

how long to create an operating system

sharp elm
#

anyone know how to get around Error 32 Broken pipe when trying to make a connection with xfreerdp?

mellow turtle
#

@rustic sage 2 days

polar crag
#

@sharp elm i use remmina, got way to many issues with xfreerdp

sharp elm
polar crag
#

sudo apt-get install remmina

sharp elm
charred gyro
#

Having issues with the HTML Injection section of the "Introduction to web applications" module. The answer seems so obvious but it's apparently not correct. Anyone have advice?

crude drift
#

hi

wind gust
#

Hey for the for the nessus module it says to authenticate to an IP and gives username and password. Auth via what RDP? (didnt work)

nimble ridge
#

can someone please help me with the password attacks - network services. i'm running this command "sudo crackmapexec winrm 10.129.202.136 -u user.list -p password.list" and not getting a user output

#

i've also tried with taking sudo out, it doesn't make a difference

raven cairn
#

@charred gyro Can you post the question pls

charred gyro
raven cairn
#

lol not what I meant

#

Its fine tho

charred gyro
#

Oh sorry

#

The question:
What text would be displayed on the page if we use the following payload as our input: <a href="http://www.hackthebox.com">Click Me</a>

raven cairn
#

What section?

charred gyro
#

HTML Injection, in Module "Introduction to Web applications"

raven cairn
#

So as you do academy you will learn that it is very picky with answers

#

Make sure to include everything

#

Should be _______ Click Me

#

You need to put in the full answer

charred gyro
#

I see now lol. Thanks!

gusty zinc
#

Documentation and reporting: practice lab - question 1 ... this question is just out of left field and to even consider answering it seems out of place. Why is this included in the module?

#

Welcome to documentation and reporting ......

"complete the in-progress penetration test. Once you achieve Domain Admin level access, submit the contents of the flag.txt file on the Administrator Desktop on the DC01 host."

.... what?

rustic sage
#

Could use a little help with the Footprinting Lab - Medium. I have some credentials and have access to a service but not sure where to go next

austere cave
#

Day 5 Right Now - Day 6 2nite! Get an Urge, Call Anyone or Join a Discord Audio Video Group and Find more people to work with & talk to, Get Clubhouse, ETC Especially!!!

vale salmon
#

So I'm working on the Skills Assessment I for AD Enumeration and Attacks and I can get a ||reverse shell||. When I upload ||mimikatz.exe|| and try and run it, though, it hangs. Is that normal? Am I going down the wrong path for trying to Kerberoast the MSSQLSvc Account? Nvm. Found a better way

rustic sage
lethal atlas
gusty zinc
#

would appreciate some help on "docuement and reporting - Once you achieve Domain Admin level access, submit the contents of the flag.txt file on the Administrator Desktop on the DC01 host."

rustic sage
lethal atlas
#

yes

warm turret
#

@sharp elm try using the remina installation on the pwnbox. It worked for me

#

@wind gust try using the pwnbox, it worked for me too

#

@rustic sage it depends on the size of the team i guess. It is so difficult that anyone does it anymore, nowdays they just takes a linux core as a base and build it from there.

#

@heady nymph i explored the site with burp/zap first and i found a "hidden" post method somewhere in the shop

vital adder
vital adder
frosty tulip
#

can someone help me with this How many files exist on the system that have the ".log" file extension? i type: find / -type f -name *.log and it wont work

hollow thunder
vital adder
vital adder
frosty tulip
#

ok

#

ty

hollow thunder
#

nvm

zinc dew
#

Can I get some help on footprinting IMAP/POP3? Stuck on the flag for Try to access the emails on the IMAP server and submit the flag as the answer. (Format: HTB{...})

#

I opened the email, but it seems to be blank

light pond
#

Hi

vital adder
sudden shore
#

Anyone for the broken auth module in academy ? Think something”s wrong. Dm

brave prawn
vital adder
#

did you use ||49821.sh|| from exploit-db?

brave prawn
loud sapphire
vital adder
lusty silo
#

Bonjour

#

Je suis nouveau ici

lusty silo
#

@fierce sparrow bonjour je suis nouveau ici

vital adder
acoustic owl
#

Feel free to DM me

rustic sage
#

Attacking Common Services - Attacking email services . which dictionary for bruteforcing? I'm trying with userslist from module resources against smtp (smtp-user-enum) but no user.... thanks

acoustic owl
gusty zinc
#

would appreciate some help on "document and reporting - Once you achieve Domain Admin level access, submit the contents of the flag.txt file on the Administrator Desktop on the DC01 host."

rustic sage
cosmic dock
#

Anyone have a nudge for initial foothold on Footprint - Hard

placid quest
#

@cosmic dock what is the problem

gusty zinc
#

If anyone has completed the document and reporting module I’d be interested in talking. I’m stuck.

#

The last questions imo make no sense and are out of place.

cosmic dock
#

Looking for a nudge on the initial foothold on Footprinting - Hard

vital adder
#

dm me if you still need help with that

feral stump
vapid grove
#

hi, anyone can give a nudge, active directory skills II on question Locate a configuration file containing an MSSQL connection string. What is the password for the user listed in this file?, i have enumerted filesystem but can't find a mssql config file, thanks

acoustic owl
flint agate
#

Hi, I got the same problem 😬

lethal atlas
flint agate
#

Anybody free to give me some tips on web proxies module
the last part about metasploit

#

I find it really weird why we have to use metasploit in this module and without any training before 😐 .
I used it a bit in the past but forgot about it

flint agate
#

I found a medium article which helped me so problem is solved

pastel ginkgo
#

I was having issues with that module last night, for some reason all my nmap scans were coming back filtered. Tried again today and it scanned without issues and I got the answers in about two mins. 🤷‍♂️

grave lance
#

any tips on footprinting hard lab?
|| was able to scan udp using nmap and found snmp running, but having trouble getting a community string using crunch and onesixtyone tools. ||

grave lance
#

ugh, I figured it out. I appreciate offering to help though, thanks!

austere cave
#

Day 5 Right Now - Day 6 2nite! Get an Urge, Call Anyone or Join a Discord Audio Video Group and Find more people to work with & talk to, Get Clubhouse, ETC Especially!!!

proud sparrow
#

anyone here can help me?

#

in footprinting module SMB section ,the 3th question is to see inside the flag.txt witch located in share list, but i have no access to the share list i just can see the list, i've tried every possible way to enumerate the SMB , but i couldn't know how get that flag.txt, i need help

solid wedge
wind gust
#

im putting the password for the nomachine and it wont take it. Man WTF is this frustrating lab setups

wispy tiger
#

Hi
I'm very beginner in this field
How can I become pentester, please can you help me?

#

How can i start?

#

What should I study???

solid wedge
#

CEH is the Certified Ethical Hacker exam by EC Council and it has its own hacking labs

wispy tiger
#

I'm zero
I haven't studied the basics yet

#

What basics should i can start?

solid wedge
#

The Junior Pentester program here is entry level I am doing it to further understand Penetation testing

wispy tiger
#

Oh , I understand you

solid wedge
#

Start from the beginning learn the method then work the labs

#

yes it takes steps to become one

wispy tiger
#

Kkk thx , bro 🥰

solid wedge
#

yes sir thank you

#

I am 48 yrs old and trying to learn

wispy tiger
#

Long life for you

#

I'm 19 and trying to learn too

solid wedge
#

yeah considering the loss of my own family and friends

#

but I am not alone

wispy tiger
#

@solid wedge May the Lord protect you

#

I'm from Egypt
And trying to learn the language and learning this track

solid wedge
#

I believe the ones gone are now more guardine angels and are on my side

wispy tiger
#

Sure

solid wedge
#

I believe in there is a higher power

wispy tiger
#

I think that too

solid wedge
#

Yes I believe God does exist

#

or what ever name he is called but still there is something there

#

anyway hope this helps

west rampart
#

Please keep the conversations topic related.

wispy tiger
#

@west rampart
Ok , bro

solid wedge
rare abyss
#

19

solid wedge
solid wedge
#

Is the help with Nmap

#

sorry there help with Namp

raven cairn
solid wedge
#

No I mean a good tutroial for Nmap

raven cairn
#

https://youtu.be/5MTZdN9TEO4 Hackersploit has tons of videos on Nmap

Welcome to Nmap for beginners! Nmap ("Network Mapper") is a free and open source (license) utility for network discovery and security auditing.

Our Courses:
Python For Ethical Hacking - Develop Your Own Scripts: https://www.udemy.com/course/the-complete-python-3-developer-course/?couponCode=TCP3DC2019

The Complete Ethical Hacking Bootcamp: htt...

▶ Play video
#

And the Nmap module is really good also

wind gust
raven cairn
#

Watch out

#

127.0.0.1

wind gust
#

😮

#

so do you know the answer to my question lol

#

have you done it

raven cairn
#

I think so

#

What module what section?

wind gust
#

not even sure why this challenge is here. its just out of place lol

raven cairn
wind gust
raven cairn
#

Yeah that is the right vulnerability

#

Should have worked

wind gust
#

im currently www-data

raven cairn
#

Weird

#

Are you using metasploit for cve 2021-3156?

#

Are you backgrounding your session?

#

Promise you this is the CVE i used on the section

#

And I promise it worked for me

wind gust
#

waiy

#

wait

#

you are saying use Msf version of this cve?

raven cairn
#

Yes. Use metasploit

wind gust
#

OHHHH

#

this makes sense now

#

thx

raven cairn
#

Np

gusty zinc
#

would appreciate some help on "docuement and reporting - Once you achieve Domain Admin level access, submit the contents of the flag.txt file on the Administrator Desktop on the DC01 host."

wheat garden
#

Doing the shells and payload module skill assessment host #2 and having the exact same problem as you were. Working on host #2 cant get 50064 exploit to work. set RHOSTS and RHOST to target I.P set TARGET URI and VHOST to blogs url address. But not working for me. If theres anyone that done this module throw me a tip.

vital adder
#

did you set the vhost to subdomain?

wheat garden
vital adder
#

sure

jaunty vigil
#

anyone can help with Service Authentication Brute Forcing

#

not sure how long this should take but its taking a long time

hollow thunder
#

can anyone tell me the best one liner to ping sweep on windows

#

the ones im using are unreliable

vital adder
#

if you are in the Pivoting module i recommend a gui tool call wnetwatcher and ping sweep only work half of the time for me

vital adder
jaunty vigil
#

login brute force

jaunty vigil
vital adder
#

yeah that shouldn't take long for both question

#

oh and for the first question you need to use a custom wordlist make from the previous section

hollow thunder
#

idk if it scans both networks or just the one

#

nvm it scanned both

vital adder
#

and you are on the Skills Assessment right?

hollow thunder
#

yea i think i may have foudn it

#

testing now

vital adder
#

nice

hollow thunder
#

thank you

#

that took so long

verbal moth
#

Hello, everybody! I need some help, I just finished the first skill assessment on the Active directory attacks course, and I feel like I did it incorrectly and missed the point of some of the sections. Would anybody who has finished the course mind chatting about our solutions?

By "Incorrect," I mean that even though I was able to finish the module, I utilized a couple techniques that were not covered, and they were critical to my success.

vale salmon
#

On the AD Enumeration and Attacks Skills Assessment I, I'm not sure I'm understanding the next to last question, "What attack can this user perform?"

gusty zinc
#

I mean - this module is about nmap ... why is it diverting from the primary module purpose so much? Seems so strange.

kind turret
#

If anyone wants to use wpscan on Pwnbox and gets a missing gem issue, please run the following command:

sudo gem install nokogiri
wise swallow
#

Hey guys, I am stuck at Password Attacks - Credential Hunting in Windows. I found the first three password but now I couldn't find the default password of every newly created Inlanefreight Domain user account.

jagged zenith
#

Hello guys how are you

vital adder
#

I'm about to go to horny jail

vital adder
vital adder
wise swallow
vital adder
#

yep i think so all of the answer for this section is in 1 windows machine

rustic sage
#

Hi

#

Can someone hack 1 server and delete it for 5€

#

?

plain coral
rustic sage
#

No

#

What is this?

placid quest
#

@rustic sage FBI may help you with your work

rustic sage
#

Ok

#

How to communicate with FBI?

#

I can't deal with them😂

#

Is anyone here a hacker?

vital adder
#

🙋‍♂️

rustic sage
#

Ok

placid quest
#

@plain coral why not sudo jail

austere cave
#

Day 6 Right Now - Day 7 2nite! Get an Urge, Call Anyone or Join a Discord Audio Video Group and Find more people to work with & talk to, Get Clubhouse, ETC Especially!!!

autumn pilot
#

?

chrome thistle
#

My command for SQLmap essentials skills assessment, is running for 15 min now, should it be like this ?

placid quest
#

@chrome thistle patient

chrome thistle
#

@placid quest ok ...but not my strength 🙂

placid quest
#

@chrome thistle sometimes waiting is not useless

chrome thistle
#

@placid quest wise words.... properly im on the right track then.

placid quest
#

@chrome thistle yeap

chrome thistle
#

or just cancel sqlmap and have a look at the log file 🙂

vital adder
chrome thistle
#

took 30min, so i canceled it and looked at the log file

vital adder
#

yeah that's way too long

chrome thistle
#

nevertheless got the flag 🙂

flint agate
#

Hello can anyone help me with that Active Subdomain Enumeration module 🙂

#

I didn't know how to access the site
I put the ip and host in /etc/hosts

vital adder
#

if you mean the Information Gathering - Web Edition module and Active Subdomain Enumeration section then there is no site that's a dns server

flint agate
#

Yep that is the one

#

I saw this guy did it ?

#

I ran dig axfr inlanefreight.htb <ipadress> and it returned a bunch of dns and none of them is the answer

vital adder
#

first why are you pinging that guy? and what question are you on?

#

also most if all of the ip you found is dead

feral stump
#

Or as many zones you can find better said

flint agate
#

and then ?

feral stump
#

Which question are you in?

flint agate
#

The first one

feral stump
#

Then ||dig ns||

flint agate
#

is nslookup good ?

#

I looked at the cheat sheet

#

dig any $TARGET @<nameserver/IP>
for example here i put the nameserver as the $TARGET and the put it again in the command ?

vital adder
#

no idea if nslookup will work or not just use dig

flint agate
#

ok i did it

#

and now i do like dig ns with 2 subdomains ?

#

like here ?

vital adder
#

nope do a ||dns zone transfer||

flint agate
#

with nslookup i suppose

vital adder
#

if you can

#

or use dig

polar widget
vital adder
#

a bit confused but thanks

polar widget
#

I really mean it
You've been helping so many peeps out there

flint agate
#

I don't understand
After I do the dig
It gives me one answer a.root**** and so on
So now with what should i do the dig ?

polar widget
#

Unfortunately since my vacation ended, I am not getting much time to devote on Academy, but eventually

vital adder
feral stump
polar widget
flint agate
#

ok i will do the zone transfer cmd from the cheat sheet

timber hatch
#

Hii all together
Modul: Footprinting
Section: IMAP / POP3

Question:
What is the admin email address?
and
Try to access the emails on the IMAP server and submit the flag as the answer. (Format: HTB{...})

Currently i logged in to the pop3 servcie in tried some commands...
but at the moment i find nothing that really helps...any tips for a next step?

vital adder
flint agate
#

guys i did this with the inlanefreight.htb and it gave me that ninja domains

feral stump
feral stump
flint agate
#

it gives me a connection refused

vital adder
flint agate
#

and my ip expired so i need to change the etc hosts

feral stump
flint agate
#

well it expired now but i am stuck for hours now on this module

feral stump
#

I don’t think you need to edit your hosts file

#

Once the ip responds and using the domain you should be fine

flint agate
#

well everybody edited the hosts file

#

nothing works : )))

#

i will switch to the pwnbox

vital adder
#

yeah i just try a dns zone transfer work fine without putting anything in /etc/hosts but just for sure put it in anyway

feral stump
#

Right now I don’t remember doing it but try both options just in case

I believe the issue is more related to finding the zones

flint agate
vital adder
#

yeah.. without putting anything in /etc/hosts i can still get the all of the answer for that section

flint agate
#

now i am stuck

#

i really tried everything

#

how should i do a zone transfer ?

vital adder
#

nope

vital adder
placid quest
#

@vital adder hard to understand maybe share with him a screen shot or example using different domain

flint agate
#

ok i searched the internet and one guy had the same results

vital adder
#

so what did it give you when you try to do a zone transfer with dig?

flint agate
#

a bunch of subdomains

#

and i think none of them work

vital adder
#

that's right

vital adder
#

but the dns record is still there and that's the answer you need so try to dump that base on each question

flint agate
#

so you say all the answers are in here ?

vital adder
#

hint not all of is in there but you can get the rest with the same method

flint agate
#

ok i got a flag

#

got another one

#

omg I bloody did it

#

I don't know man
is this the best way to learn things ?

#

i submited the answer with that dot at the end and that is way i always got the wrong answer

#

Thank you for help 🙏 🤝

vital adder
#

nice and np

stiff stream
#

Can someone help me with Attacking Common Services - Easy, got credentials > found|| two files ||i||n ftp server ||> managed to upload the file but cant seem to to be able to launch it

full drum
#

Hey im doing the linux priv es module skills assessment, I managed to get flag 2,3,4,5 (including root flag) but can't get flag1 (supposedly the easiest one). ||When i do a find command as root for the flag. no such file named flag1.txt appears||. Any ideas here? I can see where I think it's supposed to be based on what we learn in the module. But it's just not there.
(Edited: added skills assessment, and more details)

vital adder
#

if you do update it through the ||ftp|| then it can't run normal and i end up have to use a php payload with powershell

#

hint that flag is in ||the given user home directory||

full drum
#

@vital adder is that hint in your last message to me?

vital adder
#

yep

full drum
#

So when i look at ||.bash_history|| it points to ||var/www/html/flag1.txt|| but no such file exists at that location. Can you confirm that this is not the correct hint?

vital adder
#

nope the flag is in somewhere in the ||home directory|| and yes it isn't ||.bash_history||

full drum
#

You are a legend. I am an absolute moron. TY

mystic perch
#

"Password Reuse / Default Passwords" in the password attacks module. I'm stuck at ". What exactly do I need to do here. Priv esc ?

timber hatch
#

I am still working on the last two questions in the Footprinting module IMAP /POP3.
I'm logged in and in the dev.department mailbox, but I can't get any further.
Can someone spoil the next step for me ;)?

feral stump
#

Now you just need to ||FETCH the content of the mail || to get the answers

#

Try using ||FETCH 1 RFC822|| if I remember well

#

But make sure in the mailbox you are, there are emails

devout cliff
#

in the Windows Fundamentals module there is a part which asks you to use smbclient to connect to a share you just made, im getting an error in smbclient - "Error NT_STATUS_IO_TIMEOUT", what am i doing wrong nevermind

vital adder
vital adder
#

the password for that is a bit over 17000 word in so if it's taking too long cut the first 1700 word off

lyric kettle
#

Is anyone able to help me out on the Active Directory Bloodhound - Skills Assessment. The last question is asking for the percentage of users with a path to Domain Admin. I have the query, but apparently, the Cypher query language for that function is deprecated, and I cannot for the life of me figure out how to solve the query.

Cypher Query from hausec.com2019/09/09/bloodhound-cypher-cheatsheet/

"MATCH (totalUsers:User {domain:'DOMAIN.GR'}) MATCH p=shortestPath((UsersWithPath:User {domain:'DOMAIN.GR'})-[r*1..]->(g:Group {name:'DOMAIN ADMINS@DOMAIN.GR'})) WITH COUNT(DISTINCT(totalUsers)) as totalUsers, COUNT(DISTINCT(UsersWithPath)) as UsersWithPath RETURN 100.0 * UsersWithPath / totalUsers AS percentUsersToDA"

Error message from Neo4j (see attached screenshot)

I have tried older versions of neo4j, tried running the queries inside of the provided pwnbox -- and nada -- any help would be greatly appreciated.

acoustic owl
lyric kettle
brave prawn
#

hey, can someone help me with Linux Privileges Escalation flag4?

acoustic owl
sturdy igloo
#

need some help with AD skills assessment I last question "Take over the domain and submit the contents of the flag.txt file on the Administrator Desktop on DC01"

stray grove
austere cave
#

Day 6 Right Now - Day 7 2nite! Get an Urge, Call Anyone or Join a Discord Audio Video Group and Find more people to work with & talk to, Get Clubhouse, ETC Especially!!!

pine dagger
#

^^^ Bot?

languid dawn
outer ledge
#

how come I am able to login on my brave browser but not on my chrome browser?

devout cliff
#

can someone point me in the direction where i can find out how to answer the first question in the Windows Fundamentals module section "Windows Security" its hinting that i should be using the get-wmiobject cmdlet to get the SID but i dont see how google is your friend

mellow atlas
#

hello

rustic sage
#

Hello, someone speak french, i need help for where i fail in the module "Started"

wind gust
#

why is crackmapexec not installed on the PWNBOX

#

omg

#

it wont even download it

#

smh

vital adder
#

use pip3

vital adder
rustic sage
#

my english isn't good for explain.. :/

vital adder
#

or you can send me a screenshot

#

and no worries my english are as bad too

rustic sage
#

ok so, i need to "grabbing banner" but when i write netcat ..

#

i don't have the grabbing

vital adder
#

first which section are you on? and you need to use netcat on linux use nc to get the banner

rustic sage
#

section : basic tool,

#

with the vm on the site, linux, i open the terminal and write netcat "ip"

stray grove
vital adder
wind gust
vital adder
#

yeah the new pwnbox is ass it work for me the last time

wind gust
#

sad

vital adder
stray grove
#

with the new one once you open a terminal make sure to move out of the /root with cd ~

flint agate
knotty crag
#

hello

#

guys how do i connect to vpn

#

to download stuffs on pwn box

flint agate
#

-fw <nr of words>

stiff stream
#

@knotty cragsudo openvpn (filename) , each section has this:

iron basin
#

anyone know how to access the nessus scan stuff for the Vulnerability Assessment module, nessus scan section of the JPT path?

vital adder
#

the nessus is on the target machine you can access it via port 8843 and https

iron basin
vital adder
#

oh that's weird i didn't do any port scan on that target machine so i'm not sure about the ssh thing but try restart the target machine

iron basin
vital adder
#

the only section that you can access nessus is the Nessus Skills Assessment section and in that section nessus is install on the target machine and you can access with just going there on port 8843

vital adder
iron basin
# vital adder oh wait you have a typo it's 8843 not 8443

That typo was here, i entered it correctly on the machine and no connection. Not sure why this is difficult for me to understand but I cant figure a way to access the machines scan data. everytime I try to connect says connect refused.

vital adder
iron basin
vital adder
#

the answer is in section Getting Started with Nessus

iron basin
#

@vital adder well, sorry for my blindness lol. If it was a snake it would've bit me. Thank you for your help!

rugged dagger
#

New problem: I can't seem to get the smbclient to connect to list the shares.
I'm using the academy vpn instead of pwnbox.
~~I can ping the server, ~~I can rdp into the server, and when I try to list the shares I get a connection that prompts for a password ... and then it just fails with a "Error NT_STATUS_NOT_FOUND"
I've been beating my head on this for hours now, and seemingly no permutation of the command seems to be doing anything.
the only difference being an attempting with -L gives me a timeout, an attempt with -L -I gives me the status not found
nevermind, i apparently cant ping the server, so that's a whole new issue lol

prisma mason
#

hello im stuck on this question "Use NSE and its scripts to find the flag that one of the services contain and submit it as the answer." ive tried to go to http://sourceip:port/robots.txt and it doesnt work any help please?

devout cliff
#

Doing the windows fundamentals module skills assessment, where in the module does it explain how to make security groups? Once again, google is your friend ._.

rugged dagger
#

So ... am I just not able to complete modules using the openvpn? Am I required to use a pwnbox?

severe wren
#

🙏

severe wren
devout cliff
#

itll be called like 'academy.opvn'

rugged dagger
#

Alright, well, I am connecting to it and it doesn't seem to be allowing me connect to the target machine.

devout cliff
#

which module

rugged dagger
#

Windows Fundamentals. lol

devout cliff
#

oh lol

#

alright which section are you on

rugged dagger
#

See above, I am able to rdp into the target no problem, but when try to list the shares I just get an error from smbclient.
Either TIMEOUT (obvious) or NO STATUS

devout cliff
#

ah, i was getting the same thing, you actually dont need to do so to complete the questions

rugged dagger
#

I need to be able to mount the drive tho, don't I?

devout cliff
#

is it the Shares and NTFS section?

rugged dagger
#

Yes

devout cliff
#

dont need to no

#

i didnt

#

the questions dont require you to do so

rustic sage
#

guys im stuck at file inclusions can someone help

devout cliff
#

i know they are talking you through how to do so but the actual questions at the end of that section dont require you to do it

rugged dagger
#

i s e e

devout cliff
#

--it may or may not be broken-- everything working as intended KAPPA

rugged dagger
#

LOL

#

Well, fortunately for me this isn't my first time using smbclient (it's, like, my second xDDD) so at least I'm not losing much.

devout cliff
#

yeah same, i think just do some homework or something by doing a box that has SMB involved with it

#

look into ippsec.rocks to find boxes that do so

rustic sage
rustic sage
#

file inclusion

#

php filters

devout cliff
#

ok

#

what are you stuck doing

rustic sage
#

Fuzz the web application for other php scripts, and then read one of the configuration files and submit the database password as the answer

#

this is the question

#

i just need

#

direction

rugged dagger
#

Alright, well, on to the next section then. xD

devout cliff
#

read through the entire section and pay close attention to the examples they provide and their methods for doing so

rugged dagger
#

Glad I was beating my head on this for a few hours for no reason. xDD

devout cliff
#

yeah i asked a similar question earlier and then read the questions

#

and was like 'oh nvm'

rustic sage
rustic sage
#

pm me as i cannot

#

its not letting me do so

devout cliff
#

ok

rustic sage
#

thanks bruv easier than i thought

#

lol

devout cliff
#

np

gleaming spindle
#

A really dumb question, in the module Shells & Payloads I can not write the @ symbol in the login prompt, any way around this? I've tried screen keyboard, nmap to verify ssh and only port 4000 seems to be open

solid wedge
#

Enumerate all ports and their services. One of the services contains the flag you have to submit as the answer. can anyone help with this Nmap lab

rugged dagger
solid wedge
#

Can someone help with the Nmap Service Enumeration lab

devout cliff
solid wedge
#

Network Enumeration with Nmap

devout cliff
#

ah i see it

#

which lab

solid wedge
#

I have tried so many scans but no luck getting the flag

devout cliff
#

which lab? easy/medium/hard?

solid wedge
#

Its in the section Host discovery and the Service enumeration box its that lab

devout cliff
#

Enumerate all ports and their services. One of the services contains the flag you have to submit as the answer.

#

this question?

solid wedge
#

yes

devout cliff
#

alright give me a moment to see what kind of output you get

#

let me pm you and ask you what youve tried

solid wedge
#

k

pearl island
#

Hey all, need some hint on the Password Attacks hard assessment. Just need to confirm something.

languid ginkgo
#

Hello all,
Can anyone help me on "File Upload Attacks"->Type Filters ?

rustic sage
#

how to become a hacker enjoy?

languid ginkgo
#

I pass the filters, but I can't execute my php code in the browser

languid ginkgo
#

That is my error message in the navigator:

The image “http://<IP>:<PORT>/profile_images/<IMG_NAME>||.phar.jpeg||?cmd=id” cannot be displayed because it contains errors.

raven cairn
#

Could I have some help with Web Attacks: Advanced File Disclosure. I followed the instructions exactly, yet I am confused on why I am not getting the flag.

#

I am trying to do the Advanced Exfiltration with CDATA method

rugged dagger
#

Alright. One down, ten million to go. lol

raven cairn
#

Just got the flag with error method.

languid ginkgo
#

I think you forget a '/' for
FILE:///

raven cairn
#

probably haha

languid ginkgo
raven cairn
languid ginkgo
raven cairn
#

My favorite module haha

#

File Upload attacks are fun and sneaky

#

Soooo many ways to bypass filtering lol

languid ginkgo
raven cairn
#

There are lots of filters on this question, so you gotta make sure you are properly bypassing each one

vale salmon
#

Would someone who finished the AD Enum and Attacks Skill Assessment I mind giving me a quick DM?

wind gust
#

What port is the FTP service running on?

#

but FTP aint even open

vital seal
#

Need help 🙂
**Path **: Penetration Tester
Module: ATTACKING COMMON SERVICES
Question: What is the password for the username "jason"?

Tried brute forcing SMB using crackmapexec and metasploit (smb_logon) via passwords.list (acquired from ftp server). No luck.

vale salmon
#

I am definitely struggling more with the AD Enum and Attacks Skills Assessment I than I expected. So I still am not sure how to identify what attack ||tpetty|| can perform. Also, I've managed to dump the hashes from ||172.16.6.3|| using ||proxychains secretsdump.py|| but Hashcat exhausts when trying to checking it against rockyou.txt and I'm not getting any cleartext passwords out of it, so I can't figure out how to get into DC01. Any help would be greatly appreciated.

languid ginkgo
vale salmon
west canopy
vale salmon
#

Hmm. Okay. I'll try it. Also, how am I supposed to figure out what attack the user can do? I've tried pretty much every answer I plausibly thought could be right, but with no luck.

west canopy
#

have you ran bloodhound?

vale salmon
#

I ran SharpHound on it, but I was struggling with getting the zip from MS01 back to my attack box.

west canopy
#

you can collect bloodhound data remotely with bloodhound-python

#

if you have a user you can authenticate with

vale salmon
#

Oh dang. I forgot about bloodhound-python. Thanks.

#

Will i run it through ||proxychains ||as well, I assume?

west canopy
#

not sure I haven't tested it

#

I ran bloodhound locally on the foothold machine

vale salmon
#

Ah okay.

#

Maybe I'll try that.

west canopy
#

and can just move the file into C:\inetpub\wwwroot

#

then download from the webserver

vale salmon
#

Right on

west canopy
#

same place its hosting the antak webshell

vale salmon
#

Thanks again. I've been struggling with this Assessment for a few days now. It's been driving me nuts

mystic pewter
#

Is anyone on that is willing to give me a hand with the command Injection skills assessment

knotty crag
#

guyds

#

guys

#

how do i connect to vpn

#

and use firefox

#

i am having trouble

#

using firefox for testing my proxychains that i had set up

teal helm
#

anyone familar with the Information Gathering - Web Edition module? just finshed the assessment and the last question I wasnt able to find the answer with the suggested tool, a google search did help me out but wondering if sublist3r needed a specific setting to find it or if question may need updating? dns has no record of the answer

knotty crag
#

anyone

#

?

#

i would find it helpful if anyone could help me with the open vpn stuff

#

anyone?

teal helm
feral stump
vast geyser
#

Hello , I'm stuck on question#1 of the Predictable Reset Token module, this is my script, coluld anyone give me some hint?
I have no idea.

teal helm
stray wind
#

use //

timber hatch
#

Modul: NETWORK ENUMERATION WITH NMAP
Section: Firewall and IDS/IPS Evasion - Hard Lab
Question: Now our client wants to know if it is possible to find out the version of the running services. Submit the version of the service our client was talking about as the answer.

isn't it ||ibm-db2||?

vital adder
#

oh no the version is the flag you need that not the service name

vital adder
wraith spoke
#

Module: windows fundamentals
section: NTFS vs. Share Permissions
question: I have to make a shared folder which i can connect to using a linux computer. I managed to setup windows defensder to allow the connection, I can connect to the SMB using SMBclient, however within 5 secs I get a disconnect with the message:Reconnecting with SMB1 for workgroup listing.
do_connect: Connection to 10.129.175.17 failed (Error NT_STATUS_IO_TIMEOUT)
Unable to connect with SMB1 -- no workgroup available
Which setting should i change to prevent this from happening?

vital adder
# teal helm anyone familar with the Information Gathering - Web Edition module? just finshed...

i assume you mean the github question and i'm not 100% sure on this but i think that subdomain is recently removed and i haven't got any luck with sublist3r yet but that tool maybe can still find it but me and some other people use a subdomain finding tool call c99 but if you use that tool too scan it now you properly won't find that right subdomain but after the scan scroll down a bit and you can find some scan history at "More scans of" and the answer should be in there

vital adder
surreal marsh
#

Hi, i got the flag for the final assesment of the sqlmap module, yet when i try to submit it incorrect answer appaears, there are no extra spaces or any other stuff did someone experienced something similiar?

teal helm
vital adder
wraith spoke
vital adder
#

first i don't thing you can connect smb share like that try "\\\\IP\\share name" and you can't mount a share drive on your desktop mount it somewhere like at /mnt/

knotty crag
#

how can we download kali linux on low end ps guys?

#

except pwn box of hackthebox

vital adder
knotty crag
#

ok

jagged zenith
#

Hello

wraith spoke
rustic sage
#

how long does it take for a programming language from scratch

charred pawn
#

Hi everybody

#

In the getting started module at this part: List the SMB shares available on the target host. Connect to the available share as the bob user. Once connected, access the folder called 'flag' and submit the contents of the flag.txt file.

#

I see the flag.txt but when I do get flag.txt it doesn’t work

stiff stream
#

Can anyone help me with Attacking Common Services - Hard? Found the ||linked server ||and been trying to get commands that way without success

rustic sage
#

Greetings! Having connectivity/login issues in Module 33: SQL INJECTION FUNDAMENTALS. I was able to log into the target via mysql a couple days ago in my studies but now it's not working. I went into earlier parts of the module to confirm the correct credentials were being used. I'm using format -h [ip address] -P [port #] but getting this error in output. I've attempted using multiple pwnbox instances and respun multiple target instances. Unsure how I should move forward. any assist?

#

^ issue occurs with personal VPN on or off

vital adder
# stiff stream Can anyone help me with Attacking Common Services - Hard? Found the ||linked ser...

hi this is pre-write thing so if you don't understand any shoot me a dm

for example the EXECUTE command if you run 1 command like EXECUTE('select @@servername') AT [LOCAL.TEST.LINKED.SRV] you only need to use 1 single quote but if you need to run 2 command (which is how you get the flag) like EXECUTE('xp_cmdshell ''dir''') AT [LOCAL.TEST.LINKED.SRV] you need to use 2 single quote
so EXECUTE('xp_cmdshell ''dir''') instead of EXECUTE('xp_cmdshell 'dir'')

vital adder
rustic sage
stiff stream
jaunty vigil
#

lfi module skill assessment hint? I already have the source code, struggling to bypass extension

opal vapor
#

I am right now at the USING THE METASPLOIT FRAMEWORK module on the module part, but I have some problems. I trying to exploit the target system on the pwnbox with the windows/smb/ms17_010_psexec module. I setted the RHOSTS with the target machine's IP and I entered run to start the exploit. This is my result:

vital adder
opal vapor
#

@vital adder Allright that worked thank you

rustic sage
vital adder
#

and also which section are you in?

rustic sage
#

Using Comments --- checking to see if it replicates in another session

vital adder
#

oh wait there are no login in this section

#

that's a web server

rustic sage
#

oh oop

rustic sage
#

hi I have "The connection was reset" error with target on academy htb

wraith spoke
#

Module: JAVASCRIPT DEOBFUSCATION
section: Decoding
Question: I have a solution to request however it is not accepted when I put it in the box at the bottom, can someone pls verify that I have found the right flag?

lament tartan
#

Shells & Payloads - Anatomy of a Shell tells you to use pwnbox to find powershell version and submit as answer but pwnbox doesn't match the screenshots

vital adder
lament tartan
#

ah yes, ty

#

it's telling me the version is incorrect though 🤔

vital adder
#

oh it's the ||PSEdition||

sturdy igloo
#

HELP - AD Skills Assessment II Question6 - Locate a configuration file containing an MSSQL connection string. What is the password for the user listed in this file?

rustic sage
#

Is there any way to turn the Academy background colour into white instead of black?

wheat garden
strong field
#

hey, I'm not sure where I need to write it but I need help.
I'm doing the Windows Fundamentals and after making the folder and giving the permissions, I couldn't connect to it with smbclient and can't install cifs-utils either.
there is anything I can do to solve it?

wraith spoke
#

did you setup windows defender?

stray grove
strong field
# wraith spoke did you setup windows defender?

Do you mean to deactivate it?
But still, I think I don't have a connection because I can't use apt install and the windows machine doesn't have an internet connection.
one more thing that I could not use the smbclient.

wraith spoke
#

When you setup de smb rules for public network in defender you can then use the smbclient to make a connection

strong field
wraith spoke
#

ah i don't know if they are installed on the htb machine, i use my own kali machine..

vale salmon
#

So I'm doing the AD Enum and Attacks Skills Assessment II and on the first question, Obtaining the password hash for a domain user account, I'm not having much luck. Additionally, using ||responder|| on the internal IP shows me the domain ||INLANEFRIGHT.LOCAL|| which seems odd since it is usually|| INLANEFREIGHT.LOCAL|| and I'm not sure how to proceed.

strong field
round eagle
#

Hello

wraith spoke
stray grove
vale salmon
strong field
mellow turtle
#

sudo openvpn file

#

?

stray grove
#

i just used the ||-I flag|| then checked ||/usr/share/responder/logs|| that's where the hashes captured are stored, after you got some hit

vale salmon
#

Ah awesome, thanks!

strong field
charred pawn
proven jay
#

Anyone available for a hint for the "Web Attacks" skill assessment?

raven cairn
charred pawn
#

i can see bobs flag but out of reach so long 😭

#

when i do get it says error opening local file

subtle ferry
#

I know everyone's IP, but itz a hacking server sooooooo...

#

jk lmao

#

hai! I'm new

#

I bet ur hungry

#

New* Not nu as in c/lambda

charred pawn
#

if i use a nord vpn does that make my ip safe from heckers? 🧐

subtle ferry
#

The world is sponsored by NORD VPN

#

brb

wind gust
#

I have to be honest the PWNBOX in hackthebox is not prepared at all for the student unlike tryhackme their attack box has everything you need installed

#

but i do like HTB content more

charred pawn
#

help question

#

List the SMB shares available on the target host. Connect to the available share as the bob user. Once connected, access the folder called 'flag' and submit the contents of the flag.txt file.

raven cairn
#

Foxyproxy not on by default

opal vapor
#

I am currently at the USING THE METASPLOIT FRAMEWORK on the payload part and I am trying to exploit the apache druid HTTP vulnerability, but it seems, that it dosent work. When I start the exploit and the meterpreter interface appears and I look around a bit I realise, that I am still on my local machine and not on the target machine. My log output from msfconsole looks like in the picture. The payload was preset and is a reverse_tcp for linux from meterpreter linux/x64/meterpreter/reverse_tcp. My settings are on the second picture .Has anyone any idea why I am still on my local machine when i launch the exploit?

charred pawn
#

im doing the smbclient but not work

wise nimbus
#

It won't work in what way?

wind gust
charred pawn
#

smb: \flag> get flag.txt
Error opening local file flag.txt

#

;-;

wise nimbus
#

Are you connected as user bob?

charred pawn
#

4062912 blocks of size 1024. 944764 blocks available
smb: \bob> get passwords.txt
Error opening local file passwords.txt
smb: \bob> cat passwords.txt
cat: command not found

#

i think so but maybe i didnt do it the right way

placid quest
#

@charred pawn @charred pawn what command did you use

wise nimbus
#

When you first connect with smbclient you can supply a username after --user I believe. You may be in a directory you can't write to if you're not running as sudo but I'm not sure that'd be the issue. It might help to give the get command a local name and see what happens.

charred pawn
placid quest
#

@charred pawn Use smbclient -U bob -L ip address

charred pawn
#

smbclient -U bob \\10.129.181.148\users
Enter WORKGROUP\bob's password:
Try "help" to get a list of possible commands.
smb: > ls

placid quest
#

@charred pawn the command is correct so what is the problem

charred pawn
wise nimbus
#

What says error?

charred pawn
#

it worked finally i wasnt in root privilages before

wheat garden
# raven cairn Foxyproxy not on by default

Ya though I think alot of inbuilt security features in firefox and many other browsers interefere with burp suite analysis or make it more cumbersome. Ive ran into this so started just using the inbuilt browser in burpsuite. It has no security over head allowing you to breeze through web browser and application testing with out interference.

raven cairn
#

interesting. Good to know

#

Can I have some help on the web attacks skills assessment? Know how to change user passwords but don't know what else to do.

brazen dust
#

I can't seem to find the user HTB in the database on the Footprinting - medium lab, anyone have any ideas

brazen dust
mystic perch
#

I am stuck Password Attacks - Hard Lab. How do I download the ||backup.vhd|| file to my machine. This is big.

placid quest
#

@mystic perch use smbmap

mystic perch
stray grove
mystic perch
placid quest
#

@mystic perch use smbmap -H ip adbdress -u name -p password--download directory/backup.vhd

mystic perch
#

dont work

quasi wave
#

Hi I'm starting the Information Security Fundamentals Path

rustic sage
#

With the annual payment does that mean you can get all the courses vip and non-vip for free?

#

You don’t have to pay cubes?

mellow turtle
#

Hi, im stuck in footprinting medium lab can someone give me a hint?

mellow turtle
#

I have sa credentials, i logged in at the server via rdp

#

but i cant login into the mssql

#

with sa credentials

stray grove
mellow turtle
#

can i dm u?

sweet lily
#

Hello everyone 💯

lament tartan
#

NoMachine software 👎

vale salmon
lament tartan
#

took me about 20 mins to get installed on VM and then 10 mins to get the password entered.. so laggy + password didn't match my keyboard language ("@")

raven cairn
#

So tedious

lament tartan
#

now just sitting with constant

#

and resolution terrible 😫

vale salmon
#

On the AD Enum and Attacks Skills Assessment II, I can connect to SQL01, but I can't figure out how to snag the flag file on the Admin Desktop.

#

Any nudge would be helpful

#

I think my real question is do I need to connect via mssqlclient.py or autoroute and RDP in?

stray grove
#

use ||mssqlclient over proxychains|| with the creds you got from previous question, then you can use|| enable_xp_cmdshell|| to be able to run commands and retrieve the flag, ||PrintSpoofer exploit|| will be useful for privesc.

subtle ferry
#

Microsoft or Apple or Google?

narrow ferry
#

Can someone help me about Nmap IDS evasion part

proud notch
#

Hi I was doing the IDS/IPS Evasion Lab - Easy I was not able to find the OS through Nmap but saw that ||port 80|| was open. When going to ||the webpage || I was able to see what the OS was. Can anyone show what the correct methodology was supposed to be through Nmap?

narrow ferry
#

Lol I did the same thing

narrow ferry
#

No one completed NMAP bypass ips/ids medium and easy one ?

wheat garden
wheat garden
inner cave
#

Hi I have a problem with attacking common apps/ attacking tomcat I was able to gain RCE but I have searched everywhere for tomcat_flag. Can please someone narrow the scope of where to look for. Really appreciated.

pearl island
vital adder
vital adder
inner cave
solar granite
#

Hi guys, I need some help with Hacking Wordpress: Submit the contents of the flag file in the directory with directory listing enabled.
I tried the following directories: ||/, /wp-includes/, /wp-content/||, but I can't find the flag file

Edit: working on skills assessment

Edit2: hint: ||make a list of the directories you want to search and skim through them manually||. The flag will be obvious if you have the right dir.

loud sapphire
#

Hello. Me again.

I am stuck with XSS Phishing as part of the XSS module.

I have my script to use with vulnerable parameter but i am doing something wrong.

I cant post it here without giving away too much....
Can I DM someone pelase?

vital adder
vital adder
loud sapphire
solar granite
vital adder
granite plover
#

working on 0xDiablos and I couldnt get anywhere without a walkthrough. In following a walkthrough, I dont understand how the return address from a function is found. I put a breakpoint in before the function executes, and a breakpoint after. Stopped at the first BP, the walkthrough uses the gdb cmd "x/60x $esp" which I think is the cmd to show the contents of 60 addresses from the current stack pointer. It then says "we can see the return address" of the function in these 60 addresses... I dont understand how they determine which of the 60 output is the return address... EDIT: it seems if I type "info frame" into gdb, it gives me the address the walkthrough says is the return address listed as "saved eip" relative to the functions name...

vital adder
solar granite
# vital adder ||yep||

Still can't find it. I even ||used a crawler|| on ||the plugins found by wpscan: email-subscribers, site-editor and the-events-calendar||

bronze frigate
#

Hi, can anyone help with the PASSWORD ATTACKS > Passwd, Shadow & Opasswd module? have stuck on this for days. how to get the root password with user will's access?

granite plover
vital adder
#

yep

vital adder
solar granite
vital adder
vital adder
#

that one is way easier give me a sec

undone belfry
vital adder
#

also dirsearch work for me on that

vital adder
#

i think so

lament tartan
#

this NoMachine setup is literally insane

#

connect to foothold machine and run NMap scan, can't even copy and paste into my notes 😐