#modules

1 messages · Page 18 of 1

ocean night
#

No, that's what the Academy is for

pale stump
#

Ok.. Do U Know Hacking

ocean night
#

🤦‍♂️

#

Ok, go and learn, or don't. I'm going to get lunch

zenith schooner
#

he's pulling your leg. 🙂

solar granite
#

Have you figured this? I'm having the same issue.
I tried ~1500 from rockyou via burp intruder but I didn't get the correct one.

ocean night
#

But whatever, I've been wrong before 🙂

#

Many... many times

zenith schooner
ocean night
#

Could be a language barrier?

#

🤷 Anyway, looks like they went off to Academy, and hope they have fun and learn something in the process 🙂

autumn pilot
zenith schooner
ocean night
#

👃

solar granite
vital adder
solar granite
vital adder
#

the username you will need for this is the answer for question 1 but you don't need a valid password for that user

#

even though for RCE the that section said we need "a valid username and password"

solar granite
vital adder
#

i don't think qwertyuiop is the password for that user

solar granite
#

I'm not sure I understand then. How do I log in?

vital adder
#

all you need is a "valid username" not the password

solar granite
#

Oh

#

Cool, let me try that

vital adder
unreal patio
#

@echo zenith can I dm you?

echo zenith
solar granite
vital adder
#

especially when the section have this

solar granite
#

Exactly. That's what threw me off

hazy grotto
#

Hey Truth, I'm having issues with this as well. Can you DM me the commands you used?

placid quest
#

@hazy grotto what is the problem

ocean night
#

No.

edgy ridge
#

Hey everyone, I'm stuck on SQLmap essentials - Skills Assessment
I found the attack vector and my sqlmap displayed all the tables within the database however, I am unable to get the contents of the table with the flag.

rain drum
#

Give the permission

solar granite
warm sand
#

Hello! for the AD Enumeration skill assessment 1, can i get some help on how to get the cleartext credentials for another domain user? Thank you.

lyric mason
#

I'm stuck on Linux Local Privilege Escalation - Skills Assessment flag5 now and I need some help. I think that I should gain root but I don't how . use the busctl command that sudo -l give me? FeelsBadMan any suggestion guys?

unreal patio
lyric mason
#

I did but I don't get it. busctl --show-machine !/bin/sh right?

slim plover
#

you can use python for it

unreal patio
#

If you can't run sudo yet you'll have to do what 3dc0deR pointed out

jagged arrow
#

Since the last time, i have now tried all given SYSTEM clsid's on the github and tried compiling my own binary as well for juicy potato. Still not getting anywhere. Any help would be much appreciated 🙂 (ref: windows privilege escalation part I)

lament tartan
#

I was unable to use the method described in this section as well, repeated the process a few times in case i missed something but no luck.. I'll try one of the other techniques now

vital adder
#

for that DnsAdmins section i can load and run the dll but not as a rev shell but i can make that dll file run a rev shell
msfvenom -p windows/x64/exec cmd='C:\Users\netadm\reverse.exe' -f dll -o sussy.dll

slim plover
# jagged arrow Since the last time, i have now tried all given SYSTEM clsid's on the github and...

Using the first CLSID from here https://github.com/ohpe/juicy-potato/tree/master/CLSID/Windows_Server_2016_Standard worked fine for me with juicypotato

GitHub

A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT AUTHORITY\SYSTEM. - juicy-potato/CLSID/Windows_Server_...

vital adder
jagged arrow
# vital adder for that you can use the test_clsid.bat script on that tool github with the CLSI...

trying this right now. seems to output 10000, 10001, 10002 and 10003 next to the CLSIDs. trying with one CLSID from each group didn't get me the shell.

Just to rule out the obvious, would it matter if I am using powershell instead of cmd? And does this format of running the payload look correct .\juicypotato.exe -t * -p "C:\users\public\rev.exe" -l 1337 -c "0C3B05FB-3498-40C3-9C03-4B22D735550C"? I have verified that rev.exe works well on it's own to give me a reverse shell.

lament tartan
vital adder
#

yep it did yep it crash for me after 2 sec so the auto migrate didn't have a chance to run

vital adder
#

for the CLSIDs in result.log only a few one doesn't work for me but just for sure i copy and use every one of them but you 100% don't need to do this

jagged arrow
#

it's starting to come together a bit. got result.log and that had the first clsid from the github link as well. switched to cmd, just in case. and now the target timedout. brb.

warm turret
#

yes you can dm

jagged arrow
#

got it! thank you so much @vital adder and @slim plover!

cloud estuary
#

hello, i am working on the academy module, "Laudanum, One Webshell To Rule Them All" and am stuck on questions 2, "Establish a web shell session with the target using the concepts covered in this section. Submit the full path of the directory you land in. (Format: c:\path\you\land\in)". i have followed all the proper directions but when i try to navigate to the imported config file for the webshell, i get a server error. can someone help me figure out what i am doing wrong?

vital adder
#

which module are on?

cloud estuary
#

Shells & Payloads

vital adder
# cloud estuary Shells & Payloads

sorry for the delay my note was kinda F for this so i have to give that a check but what exactly is the issue? if you white list your ip in the payload and upload that payload you should just get RCE

#

also this payload will give you a cmd shell you for the directory use dir

cloud estuary
#

no problem on the delay! and i am at the part where i upload the webshell and get the output url to access the webshell. so when i use that url to get to the cmd shell, i get a runtime error

#

also i did whitelist my ip

vital adder
#

and what url are you trying to access the payload in?

cloud estuary
#

should i blur the url?

vital adder
#

yep

cloud estuary
#

||status.inlanefreight.local\files\demo.aspx||

vital adder
#

and you still don't know why you have that issue? \ is only for windows directory use / on the web

cloud estuary
#

so i did try that as well and i got the same error

unreal patio
#

I used url//files/demo.aspx

cloud estuary
#

tried that as well

unreal patio
#

with double /?

cloud estuary
#

yup

vital adder
#

try with 1 /

cloud estuary
#

ok one moment

vital adder
#

if that still doesn't work restart the target machine

cloud estuary
unreal patio
#

Stupid question, the file you uploaded did you rename it to demo.aspx?

cloud estuary
#

yes, just to be on par with the instructions

#

under section: Move a copy for Modification

unreal patio
#

Can you send a screenshot of the error you're getting + did you add your 10.xx.xx.xx ip?

#

If that doesn't work you can try to upload the file again under a different name

cloud estuary
#

sure thing. one moment while i take screen shot. and yes, i added my ip in the allowedips section

unreal patio
#

And if that doesn't work you should indeed just reset the target

cloud estuary
#

pm'ed you the screenshot @unreal patio

#

and ok i can try to reset the target if it doesnt work

high totem
#

Hi, could you give me a nudge on the Shells&Payloads Skills Assessment Host 1? I got all other tasks done, apart from the host 1. I can upload a war file, but whenever I visit a uploaded java payload, I get 500 error and runtime exception :/

unreal patio
#

@high totem Did you try with an .aspx shell?

high totem
unreal patio
#

Just upload an *.aspx shell directly and browse to it

cloud estuary
#

@high totem i am running into a runtime error as well in that module. i even tried to reset the target with no luck. @unreal patio , i am assuming that module is being a little buggy if others are running into similar issues?

unreal patio
#

I redid both modules as you two ran into the errors and it worked fine for me

cloud estuary
#

hmm odd, must be user errors then..lol

high totem
unreal patio
#

@high totem if you cat /etc/hosts you'll see there is a vhost you can use

high totem
unreal patio
#

(Format: all lower case)

high totem
solar granite
#

Stuck on Attacking Common Applications - Skills Assessment I. I got the first 3 questions, but not the 4th.
I have found a vulnerability that allows RCE, but can't read the flag. I can see it with ||dir+\users\administrator\desktop\flag.txt||, but can't read it with type.

Edit: solved! Thanks a lot to @vital adder

Hint: ||note that this is a BLIND command execution||

Hint2: ||not many common system commands and binaries are available. If what you're trying to do doesn't work, try to use another command/binary||

vital adder
solar granite
#

Can I dm you?

vital adder
#

sure

warm sand
#

can someone help me with the dcsync attack for the AD Enumeration & Attacks - Skills Assessment Part I? thank you

tawny lake
#

Hello,

I am having an issue with my nmap scan on the Starting Point Tier 1 "Responder". My nmap scan does not return the same ports that are shown in the walkthrough; my scan only returns port 80. This is with the same flags used inside the walkthrough "nmap --min-rate 5000 -sV -p- <host> -o <filelocation>. Any help would be greatly appreciated.

waxen barn
#

This last question in the DNS footprinting module is driving me insane. I've found FQNDs all the way out to the ns.dev.inlanefreight.htb. Anyone have any insights into this impossible scenario?

placid quest
#

@waxen barnwhat is the problem

unreal patio
#

@waxen barn Iirc you're supposed to migrate the dev.inlanefreight.htb and it's one of its vhosts..

waxen barn
waxen barn
placid quest
#

@waxen barn try to brute force the subdomain

waxen barn
unreal patio
#

@waxen barn What command did you use to get ns.dev.inlanefreight.htb?

#

Did you bruteforce it? or with a transfer?

waxen barn
unreal patio
#

Then you're on the right track

#

Just the wrong wordlist 😛

#

/opt/useful/SecLists/Discovery/DNS/fierce-hostlist.txt

#

Try with that one

waxen barn
waxen barn
# unreal patio Try with that one

It worked! Holy shit, what a headbanger. I’ll never forget DNS enumeration now though, which I guess is part of the point they’re trying to get us to with exercises like this.

unique valve
shy warren
#

Hello all,

Currently having some trouble with the module Password Attacks - Credential Hunting in Linux. "Examine the target and find out the password of the user Will. Then, submit the password as the answer"

Is the first step to discover Kira's credentials? I have created a mutated list with the LoveYou1 pass included in the hint. I've tried running crackmapexec with the mutated list against Kira's username but receiving no so results. The hint has me a little confused. Should be be making a mutated list out of the hint pass or the password.list included in the resources?

unreal patio
#

Kira with a mut_password of LoveYou1 should get you in

shy warren
shy warren
unreal patio
#

custom.rule from the hashcat rule file in Password Mutations should do it

shy warren
#

Finally found Will's password in Credential Hunting in Linux. That sure was a grind. Not too bad in hindsight. Let me know if anyone needs guidance

zenith schooner
#

anybody working on footprinting module. I am on smb footprinting and I am a bit stuck.

#

I need to findout physical path for particular share. I expect to use rpclient but I cannot access it due NT_STATUS_NOT_FOUND

#

I tried to use enum4linux with debug param to check the calls but no successful to retrieve that information. I almost pretty sure that this tool is the suitable tool. But something is wrong.

#

anybody can help me? I read man page but I don't find what I need and - to be honest - some explanation are beyond my knowledge.

unreal patio
#

@zenith schooner What paths have you tried so far?

#
#

If you're still stuck ping me

thorny wadi
#

hello, anyone that can give some help with Firewall and IDS/IPS Evasion - Medium Lab. its driving me nuts

vital adder
#

pls don't share that also if you need help with anything you can just ask here

vital adder
#

also that email is Pwned in 3 data breaches

#

so if you haven't change your password pls do that and you can check what data breaches your email is in on haveibeenpwned.com

#

also if you can't tell like the last guy that ask how to hack google and also have this issue i'm trying help

supple cape
#

hello i am having challenges answering this question

#

here is it; What is the path to htb-student's home directory?

vital adder
#

if you are having issue need help with anything in the academy pls add which module and section (even question) you are stuck on

vital adder
supple cape
zenith schooner
#

it was not a "read man" situation. I tried pwnbox and rpcclient works as expected. For any unknown reason, my rpcclient on my kali doesn't work (No tcp/ip traffic was detected by tcpdump). Maybe a smb.conf issue. Thanks anyway

vital adder
supple cape
supple cape
placid quest
#

@zenith schooner did u check ur vpn connection

supple cape
vital adder
#

use this

supple cape
hollow thunder
#

Any hints?

supple cape
supple cape
#

and this is the answer i get /home/htb-ac638407

#

What is the path to htb-student's home directory? anyone pls i am stuck

supple cape
#

what happens when some gets stuck and cant answer a question in the modulues

supple cape
#

i need mentorship or help i am new

#

to htb

rustic sage
#

If you are really stuck then take a step back and try to learn some more fundamentals. It's a marathon not a sprint so don't sweat it, everybody gets stuck and everybody started out knowing nothing.

supple cape
rustic sage
supple cape
#

nobody seems to know it

#

and funny enough it has no cubes attached to it the question

high lynx
#

@supple capeAre you on the pwnbox still or have you SSH'd into the given IP address. Just took a look at the question and judging from the output you're getting, you're still in the pwnbox.

supple cape
#

i have figured it out now

supple cape
vital adder
high lynx
#

The last section of the page you're on has info on how to use SSH. Make sure you're connected to the Academy VPN.

vital adder
# supple cape tried google and still dont seem to get the right answer still

also the question need a home directory of a user (in this case for the htb-student user) if you google for that user home directory you will most likely get nothing you have to google something like how to get linux user home directory

edit: i try google that for the first time and the first link show a great article about this: https://www.linuxshelltips.com/find-user-home-directory-linux/

high lynx
#

Also, does anyone know if there's a way to bypass a blacklisted dollar sign character? I'm on a box where I think I need to bypass an underscore, for which I'm using ${LANG:2:1}, but turns out the dollar sign is blacklisted as well.

wheat garden
wheat garden
#

Module- password attacks section- Linux pass the ticket

SSH to <I.P> with user "david@inlanefreight.htb" and password "Password2"

Connect to the target machine using SSH to the port TCP/2222 and the provided credentials. Read the flag in David's home directory.

I cant seem to login with ssh I suspect may just be some command syntax error but the standard ssh format of user@<I.P>:<port> doesnt seem to work. Tried putting the user in quotes and a few other ssh switchers like

#

ssh -l 'david@inlanefreight.htb' -W '10.129.89.17:2222'

#

ssh david@inlanefreight.htb@10.129.89.17:2222

ssh -J david@10.129.89.17:2222

ssh -J "david@inlanefreight.htb"@10.129.89.17:2222

#

none seem to work

forest tapir
#

Footprinting - Medium Lab: There is no "HTB User" in database nor locally. What are they talking about??

forest tapir
chilly nymph
#

One question, if I am connected remotely, how can I go back without disconnecting from the remote connection?

#

/home/nibbler/personal/stuff/monitor.sh: 43: /home/nibbler/personal/stuff/monitor.sh: [[: not found
python3 -c 'import pty; pty.spawn("/bin/bash")'
python3 -c 'import pty; pty.spawn("/bin/bash")'
^[
^[
^C
[us-academy-1]─[10.10.14.113]─[htb-ac630938@htb-qj2d5jsi4f]─[~]
[★]$

#

I press ctrl+z and I disconnect to where I had connected, when what I wanted was to go back

karmic mantle
#

@forest tapir Enumerate the databases. You should see a database with a users table

forest tapir
#

I'm almost certain ive looked. there but I'll look over once more

#

i just started expanding everything at one point in desperation
i cannot find it

karmic mantle
#

@chilly nymph Doing CTR+Z backgrounds the process. You should then do stty raw -echo; fg. The stty raw -echo will send your input raw to the terminal and the -echo will prevent it from showing you double output. The fg then returns the backgrounded process back to the foreground, letting you interact with your shell again

chilly nymph
#

I'll write it down

forest tapir
#

Yeah, there is no "HTB" user:

#

I've expanded everything.

#

I'm not expanding "System Stored Procedures". It's becoming ridiculous.

#

The Select * from master.sys.database_principals was supposed to dump all users anyway, according to microsoft

#

I don't know wtf they're talking about....

#

I've gutted this thing. I'm looking through "schemas" at this point...

#

I've resorted to randomly clicking shit. Idk what else to do.

languid dawn
#

Is it a shared instance and someone removed it blaze

forest tapir
#

a what?

languid dawn
#

Where you dumped that db from

#

If it's from an academy module on a machine that is shared between users

#

And someone did a little joke on you

#

I dunno haven't done that module but I feel like you should easily find it if you have dumped it all

forest tapir
#

I thought the machine changed on restart.

languid dawn
#

I don't know how htb manages these machines.

forest tapir
#

Like, it spins up a new EC2 right?

#

or whatever they use

languid dawn
#

But of it's like boxes on free tier you might be sharing it

#

No clue just a guess

forest tapir
#

I'm not sure that "Footprinting" is free or not. No idea.

#

Would it matter if it was paid?

languid dawn
#

Tier 0 are considered free, but regardless and especially if it is an ec2 instance it might not be a personal one

#

That costs money

#

Again just a guess on my part

#

Since it shouldn't be some dark arts to find a user

forest tapir
#

Nah, it's Tier 2

languid dawn
#

Hmm weird

forest tapir
#

woman, w/e... lol. I'm pissed rn.

languid dawn
#

I dunno if I have the time today but I'll try and look into it if no-one has the answer for you in the meantime

languid dawn
forest tapir
#

Tier 1 boxes and up are private?

#

I...

#

It's THM all over again lul

#

Busted boxes

languid dawn
#

Worst case scenario open a ticket, but as we're Saturday I don't think you'll find a staff though

forest tapir
#

It's okay... I guess I'll have to wait.

#

There is no goddamn Pepe Silvia... Half the people in this office have been made up

digital arrow
#

hello every one

unreal patio
#

@forest tapir What are the credentials for the machine for the medium lab?

#

I solved it some time ago but I forgot the credentials want to see if I can get the htb user out

forest tapir
#

hang on

#

I'll. dm

#

got to spin up my VM first

#

idk why i can't dm you in browser...

unreal patio
#

I dm'd you, can you read me?

forest tapir
#

if you finished it then it can't be broken, can it?

#

I'm waiting for the you're stupid, i found it response

pulsar coral
#

Hey I was wondering if I could get some help with an issue I am having

#

I am not a cyber security expert at all I am a machine learning guy but my professor said if we can hack his fake social media account we get extra credit. My grades are awful right now and can use any assistance.

#

Please dm me if anyone can be of assistance

forest tapir
pulsar coral
#

He is a weird guy literally the dude said it would give us extra credit on our mid term and I was baffled that he’d want us to do that…no like I’ve literally never hacked a day in my life I’m studying data science and this is my class on building neural networks.

#

Sooo yeah this is way out of my ball park

#

He said something about using brute force and I’m so naive to this part of CS.

forest tapir
#

i don't think anyone would do it for you. it's unethical.

pulsar coral
#

I figured and that’s what I thought myself I was like he wants us to break the law for extra credit

forest tapir
#

it's not really breaking the law if he's allowed it (and fake) but solving the riddle for you would be "cheating", therefore unethical

pulsar coral
#

Oh yeah I’m not asking for anyone to do it for me but any pointers on where to start would be helpful like steps or anything everything I’m finding online is fake Instagram hacking apps

unreal patio
#

What kinda blog and login is it?

#

There are just too many ways of approaching it without intel

#

And bruteforce.. is well.. bruteish

pulsar coral
#

It’s just a regular old Instagram account

forest tapir
#

brute forcing is pretty simple

unreal patio
#

So he's asking his class to attack the instagram server?

#

Kinda sus

forest tapir
#

but you would have to learn the tools first

pulsar coral
#

Dude I know I was like this man is getting us all sent to jail for 30 extra points

unreal patio
#

HTB is about ethical hacking, so I doubt you'll find people over here that are going to try to breach servers where we have no permission to pentest on

forest tapir
#

he might have spun up a mock social media page he made himself/snagged from GitHub

#

who knows

unreal patio
#

That'd be a different story

forest tapir
#

you can't brute force insta anyway

pulsar coral
#

I mean I found the page on Instagram

forest tapir
#

they have teams of security experts

#

oh...

pulsar coral
#

Yeah so does he want us to send an email to his personal email pretending to be Instagram and get his login info

#

He said he made a fake email with it as well

#

Would it be easier to get into the gmail account and reset the password

forest tapir
#

maybe

#

would he really be that tenuous?

unreal patio
#

Has he given you an url to attack?

pulsar coral
#

Could I find the password in the elements ?

forest tapir
#

noooo lol

#

you're not going to break into Instagram trust me

#

maybe he does mean "phishing" i dunno

unreal patio
#

It's starting to sound like you have a grudge against someone on instagram and are just spinning a narrative..

forest tapir
#

those are some strong words

pulsar coral
#

I truly wish I had a social life to have a grudge

#

Lol

#

Yeah I’m at a lose with this one so this task is basically impossible right

#

Loss**

forest tapir
#

what kind of class is this?

pulsar coral
#

It’s a machine learning class for basic algos

forest tapir
#

huh...

#

hmm

pulsar coral
#

Yeah I know

forest tapir
#

idk, send him an email

#

try to be crafty

stuck hull
#

This is so sus 🤣

forest tapir
#

if that's his angle

pulsar coral
#

Probably is

#

I know dude I feel like a creep right now asking this lol

unreal patio
#

You're not giving us any info to work with either

#

Maybe you should try another channel seeing this is for academy modules

forest tapir
#

"teacher: hack this thing"

#

okay teech lol

#

wdym

pulsar coral
#

I appreciate it anyways guys have a good night I’ll do some more googling

stuck hull
#

I wouldn't do anything unless you can confirm firstly that the account belongs to the teacher & he wants you to attack via a phish and not trying to 'hack instagram' which, you wouldn't be able to do and would land you in hot water

placid quest
#

@pulsar coral use his email to see if his password was breached

pulsar coral
#

@placid quest what does that mean lol

#

I have never hacked before in my life lol

stuck hull
forest tapir
#

My guess is that he wants you to create a fishing email

#

if I really had to guess

pulsar coral
#

How do I create a fishing email ?

forest tapir
#

because you're not breaking into Instagram. end of story lol, So he must have a different angle

forest tapir
pulsar coral
#

Okay fair

placid quest
#

@pulsar coral it means that sometimes his email and password was breached and he did not change the password which may provide easy win

stuck hull
unreal patio
#

Just steal his laptop and dump all passwords (?)

pulsar coral
#

Yooooooo

placid quest
#

@stuck hull it may work since most people don't know that their password was breached

pulsar coral
#

@unreal patio you are wild man lol

#

@stuck hull it’s an gmail he made to sign up for this account I asked a few of students that had him before if he used the same information but they said he always makes a new Gmail and insta account

forest tapir
#

phishing requires a certain level of creativity/ conniving

placid quest
#

@pulsar coral use dehashed to see if his password was breached first before u go with brute forcing

forest tapir
#

bruteforcing Instagram would get the account locked out

forest tapir
#

maybe, i dunno what this is with "bruteforcing" though or why he said that

stuck hull
#

What's on the instagram account?

#

It sound's either like you need to send a phishing email or this is some kind of puzzle.

north ermine
#

Hi ! I am on AD Enumeration & Attacks - Skills Assessment Part I
Managed to get shell using PS remote with the SQL user but I can't find the user clean text passwords. I tried mimikatz and lazagne but only got the hashes

forest tapir
#

can you submit your own passwords to dehashed/haveibeenpwned??

would they accept that?

#

maybe that's what he did and Crean is on to something...

pulsar coral
#

He literally wants us to get into the account and send him a picture of the only photo on the account it’s private and he won’t accept my friend request

#

I will give all of this a try

forest tapir
#

he either A: doesn't understand how security works. B: is being "obtuse" with his instructions, on purpose or C: this is a lie.

js, those are the possibilities

stuck hull
#

And unless he is just going to email you the password in clear text, you'll have to create a webpage for the phish to be effective - how can he assume ML CS students know how to do that?

#

It just doesn't make sense

forest tapir
#

right. it's a bit complicated for a newbie. it's a bit of a task even for experienced pentesters/hackers

#

unless he just wants you to throw up a quick php page "and just pretend it's pro h4ckzor" and he just wants to see you thinking creatively...

maybe

#

if i was a teacher, that's what i would want

#

but it's still a bit of a task, regardless

sly grotto
#

can i dm someone for Footprinting Lab - Medium?

pulsar coral
#

Well I better get to work this is going to be a longer day than I thought

forest tapir
#

me or @unreal patio

pulsar coral
#

Anyone hiring for ML and data scientist that don’t want to finish school ?

#

Lol

forest tapir
#

heh...

stuck hull
#

bin the idea and focus on your course is my advice

pulsar coral
#

Yeah honestly what I’m going to do this whole project seemed like a waste of time to make I’m just going to ask my roommate in the morning if he figured it out thanks again everyone

stuck hull
#

Oh, they'll be salted won't they? nvm

forest tapir
#

yeh

unreal patio
#

Wouldn't pass the hash work regardless?

#

Unless the cleartxt password is a flag

forest tapir
#

perhaps if it's permitted

#

i do think he mentioned "clear text" which i dunno, I'd have to see what's going on with my eyeballs

#

👀

#

golden ticket softGolden

#

perse deh hersh

#

ermegerd

north ermine
#

Yeah the flag is the clear text password :/

#

I actually finished the lab

#

Only this flag is missing

forest tapir
#

the flag is usually plain text..

unreal patio
#

crackstation is your friend

forest tapir
#

password or flag?? I'm a bit confused

north ermine
#

The cleartext password is the flag

forest tapir
#

oh right

#

sounds like mimikatz

#

Wait you need to be NT in order to dump hashes, right??

north ermine
#

I am

forest tapir
#

hmmm

#

unless it's something dumb like a file laying in the open, i'm not sure

#

i've had katz not elevate correctly as a low-priv user before, so that's also possible.

#

like, sometimes it's finicky at least for me.

#

maybe i'm just a dum-dum idk

unreal patio
#

In module Password Attacks - PTT
I'm not allowed to use xfreerdp with .\Administrator as user

#

Anyone a clue?

charred heath
#

hi

forest tapir
#

administrator as user?

unreal patio
forest tapir
#

what's ur error msg?

unreal patio
forest tapir
#

xfree was goofy for me b4, did u try remmina?

#

idk why

unreal patio
#

remmina also being goofy

#

nvm

#

I'm in

#

gg

forest tapir
#

lol lemme guess

#
  • the .\?
unreal patio
#

I put . as domain in remmina

forest tapir
rustic sage
#

Hii friends

#

Hlo

#

Hi anyone can tell me my answer

#

Anybody is daring to give my answer

#

Weapon of every Hacker

placid quest
#

@rustic sage what is the problem

rustic sage
#

Weapon of every Hacker?
What is Red linux

#

This question

unreal patio
#

🤦‍♂️

stuck hull
#

Hi all, I'm stuck on the "Network Enumeration with Nmap" module, Nmap Scripting Engine section. I've enumerated the ports and ran the 'vuln' script.

It came back with the slow-loris attack, which isn't helpful in this case, the http enum found a robots.txt which looks like it has the flag in it, but won't work when I input it on the site. Any help?

lament tartan
#

Windows Privilege Escalation: Interacting with Users the hint says ||"Look for interesting shares that are writable by our user."|| but there's only 4 shares, 2 of which are "NO ACCESS" and other 2 are "READ ONLY" 🤔

unreal patio
#

@stuck hull
A robots.txt file tells search engine crawlers which URLs the crawler can access on your site.

#

It's a file that is hosted on the webserver

stuck hull
#

This is what I'm seeing

lament tartan
#

that should be the flag i think.. did you try to submit the whole string, with no whitespace?

unreal patio
#

Under Allow you got your flag

stuck hull
#

Yea, I tried that but it didn't work.

unreal patio
#

Just copy the entire thing

#

with HTB

stuck hull
#

Let me make sure

#

Oh ffs

#

thanks all

unreal patio
#

😛

stuck hull
#

I've removed the photo for spoilers

sly grotto
#

where can i find users and passwords in microsoft sql server management

#

i hate this gui things and microsoft also

unreal patio
#

What module are you working on?

sly grotto
unreal patio
#

You have to look for the htb user?

sly grotto
#

i logged in as admin.but i can not find user HTB and pass

sly grotto
unreal patio
#

select * from dbo.devsacc where name = 'htb';

#

Might be too much of a spoiler though

#

😓

sly grotto
unreal patio
#

mssql server management

#

There should be a button for queries

sly grotto
#

let me see

sly grotto
unreal patio
#

select * from accounts where name = 'htb';

#

And that one?

#

Strange because I filled in the previous one earlier today and I got the answer

sly grotto
unreal patio
#

Let me boot up the machine again

#

select * from accounts.dbo.devsacc where name = 'htb';

#

Try like that

#

@sly grotto it worked for me 😐

sly grotto
#

any cheatsheet for mssql?

unreal patio
#

I got the clue that it wasn't part of the default databases

#

select * from sys.databases where name not in ('master', 'tempdb', 'model', 'msdb');

#

So with that command you get the accounts database

#

And then you enumerate that one

sly grotto
#

i can't understand this one?
accounts.dbo.devsacc

unreal patio
#

If you rightclick some files you the option of 'edit top 200' which is a clue in the module

#

So if you enumerate all that you can edit the top 200 with with a query

#

you end up getting a hit for htb

#

In the database accounts there is dbo.devsacc and that is the right file

sly grotto
#

thank you for your help bro

fierce sparrow
#

anyone for web attacks module? XXE Blind Data Exfiltration, just struggling with payload

zenith schooner
placid quest
#

@zenith schooner a u still stuck

brazen apex
#

what channel

#

is for hack talking

#

I need some advice on what tools I should really study

#

and get a firm understanding of

strong adder
#

Hi

#

I'm... new here

#

what to do?

unreal patio
#

Just make an academy account and start doing the fundamental modules

#

It's a good place to start

brazen apex
#

what

#

channel

#

should i ask that in

unreal patio
#

You could start with nmap

brazen apex
#

already know it

#

and its a bit trivial

#

in actual domain hacking

#

especially when you can use metasploit instead

#

this is what im saying i dont wanna learn 10 tools when theres 1 that can do all of them in one

unreal patio
#

Wireshark and burp are also good ones

brazen apex
#

okay it is about time that I look into wireshark

#

you think learning lua is worth for wireshark and NSE scripts

#

ehh

#

ill figure it out

high totem
#

Hey, question regarding metasploit module, sessions section. I cannot get the elevated permissions. Got the shell, dropped it into background, run local_exploit_suggester to find some exploits and found two. Both say they are completed, but no session was created. Any hints on why this might be? lhost is set to tun0 and lport to 4444 (same as in the first exploit, which is now in session)

pliant sage
#

Hi, I'm trying to use Impacket's secretsdump script for the password attacks module but running the script produces no output, has anybody encountered this problem before?

unreal patio
#

@high totem did you specify the right session for the exploits?

high totem
unreal patio
#

You could try to put in your ip by hand instead of tun0

#

I have had cases where specifying tun0 wasnt enough

pliant sage
#

try changing lport, maybe the 2 shells are in conflict since you're trying to run them on the same port

unreal patio
#

@pliant sage which section of password attacks are you in?

pliant sage
#

attacking SAM

#

I've retireved the .save files, but when i run impacket I don"t get any output

#

not even an error message

high totem
high totem
unreal patio
#

@pliant sage I just used cme there

pliant sage
pliant sage
#

I used samdump2, worked like a charm

unreal patio
#

I once ran an exploit twice in a row with no result spend ages breaking my brain just to run it a 3rd time and it to work

#

Your options seem alright

#

I mean you could try to see if with your current shell you can write files to /tmp but I doubt that's it

high totem
#

I mean, the only thing that bothers me here is that I cannot mark the module as finished because of that. And it is needed for the penetration tester path :/

clever fossil
#

anyone hack valo or rblx

high totem
#

I run it many times though, with the same result :/

unreal patio
#

@high totem try to reset the machine and see if the problem persists(?)

#

or kill the session make a 3rd sesion and try with that

high totem
vital adder
# high totem

i didn't use pwnkit for this also i think exploit suggester did give ||CVE-2021-3156|| so try that

high totem
vital adder
#

oh that's weird pretty sure i use exploit suggester for this but right now i'm on the enterprise network module so i'll double check that in a bit

placid quest
#

@brazen apex Wireshark is not used in hacking but it is analysis tool used to inspect packets on the network

vital adder
vital adder
high totem
vital adder
#

yep that's the default

vital adder
high totem
#

Something to be aware for the future then. Thanks

zenith schooner
placid quest
#

@zenith schooner sometimes -N is the problem

stuck hull
#

General Question: I'm working my way through the 'Firewall and IDS/IPS Evasion' section or Network Enumeration with Nmap. It talks about how IDS and IPS are more difficult to detect on a real pen test and we have to use multiple VPS services. Does it mean things like AWS, Azure & Vultr?

Also, a bad actor wouldn't be able to use those services because when a company inquired their names would be attached to the service - so how do they go about using a VPS?

cyan saffron
#

Any help for a noob?

placid quest
#

@cyan saffron what is the problem

cyan saffron
#

im stuck no the question TASK 5

From your scans, what version is FTP running on the target?

#

how can i know if i can't connet on the target machine?

placid quest
#

@cyan saffron did u use nmap to scan the ip address using -v option

cyan saffron
#

no

placid quest
#

So scan the ip address using nmap to get the answer

cyan saffron
#

ok

#

tks

placid quest
#

@cyan saffron u can use nmap -p21 -sV -v ip address

high totem
#

Quick question to Password Attacks module. In the introduction it is stated

could require all three types [of authentication] (A CAC [a card], password, and pin from an authenticator app, for example)
Isn't pin from authenticator app same factor as a card? I.e something you have? Or same as password, i.e. something you know. But I don't get how it should be the third one - something you are

rustic sage
#

Would like to make $500 faster than any other job dm me

stuck hull
#

How do you report spam on discord?

spring tundra
thorn urchin
violet wedge
#

Spent considerable time trying to enable windows subsystem for linux in my Windows 11 VM. I think the problem is that I have to enable virtualization in the bios, but it frustrates me because I can't find any virtualization settings in the bios... Any advice?

thorn urchin
#

if you dont have any virtualization settings in your bios you may literally be running a cpu that doesnt support it

violet wedge
thorn urchin
#

ah virtualization inside of virtualization definitely gets funky, idk how doable it is

violet wedge
#

Windows subsystem for Linux is supposed to be doable, maybe missed a detail somewhere

autumn garnet
#

can someone help me. im doing the attacking common services easy section, but i cant seem to find a user name. i tried the user name list in resources and tried to auth to rdp, ftp, and the mail with no hits

cyan saffron
#

Stop your ACTIVE machine to change access

#

where do i check for my active machines?

#

Error!

You must stop your active machine before spawning another one.

rustic sage
#

Can I have a hint on resolving "The Live Engagement" section on module "Shells & Payloads"? Im finding it non-sense at all...

autumn garnet
#

i think i just found it

placid quest
#

@autumn garnet may enumerate port 25

autumn garnet
placid quest
#

@autumn garnet ok

near night
#

Hi

placid quest
#

@near night hei

unreal patio
#

@rustic sage What is the problem?

warm lichen
#

Anyone able to give me a hand getting the Nginx and Apache Reverse Proxy to work with AJP? I'm following the steps in the Server Side Attacks module but my Nginx/Apache instances always fail to connect 😦

solar zodiac
#

hi everyone! Im doing the Web Servce & API skills assesment. I have DB access, but cant find the admin password. Kinda confused lol

#

if anyone can advise I would be forever in your debt

#

🙂

#

also grepped through all the node js modules and didnt find anything

vital adder
vital adder
vital adder
warm lichen
#

I just don't like using the Pwnbox, it's so laggy for me. Probably cause I'm connecting from Australia :/

vital adder
#

yea the pwnbox is a bit laggy but congratz though

magic valve
#

Sorry for the oh so late reply but thank you for your help @iron basin

hazy grotto
#

I'm working on the footprinting module SNMP. I ran the SNMPwalk and it wouldn't allow me to scroll very far up in the results. Just stops scrolling at a certain point. Is there something i can do for this?

ocean night
#

You could pipe the output via more, e.g. <command> | more, or pipe it out to a file, e.g. <command> | tee -a <file>

#

Treating outputs as data and programs as processors using pipes is a good skill to have - Linux is nice in that respect, distinct commands with very specific purposes. Combining them can help you achieve many things.

hazy grotto
#

snmpwalk -v2c -c public 10.129.112.42

This is the command i need to run so would it be

snmpwalk -v2c -c public 10.129.112.42 | more

ocean night
#

That's right - the command will run and the output shown until it overruns the terminal space.. then you can hit space to continue

solar zodiac
hazy grotto
ocean night
#

You're welcome 🙂

solar zodiac
#

is there anyone I can dm about the skills assesment for webservice and api skill assessment?

kind saddle
#

Does anyone know any hacking courses to do?

solar zodiac
kind saddle
#

thanks

solar zodiac
#

there are learning paths you can follow

#

they will recommend courses to take

kind saddle
#

ok thank you, very much but are the courses in the form of videos and exercises?

solar zodiac
#

I learn better by practicing, so the interactive exercises help me alot

#

some of the exercises are also pretty awesome. I really enjoy the active directory module labs. They simulate a realistic pentest

#

easily one of the best learning resources out there imo

kind saddle
#

I also learn better by practicing, but I'll check here and let you know

solar zodiac
kind saddle
#

is this part of Pwnbox free?

solar zodiac
#

yep

#

it is a network joined parrot os box

#

that you can access through your browser

kind saddle
#

ok , thannks

solar zodiac
#

there are alot of introductory modules I think for free

#

you can try it out and see if it is for you

#

you just have to make an account

kind saddle
#

do you already study hacking or do you only do it in your free time?

solar zodiac
#

I have a few certifications and am working on more before seeking employment

#

got the CRTO OSCP and Pentest+

kind saddle
#

I've already done some things in the courses, but I learn a part better by watching video too

solar zodiac
#

academy has content for everyone

#

from beginner to professional

#

there are pictures in the modules

#

so I dont think video is necessary

#

they have screenshots that walk you through the module

#

and commands issued

kind saddle
#

I understand, I'll follow what you said, thanks

solar zodiac
#

on another note, does anyone know if I can use sqlmap for the web service & api attacks skills assesment? I thought sqlmap fuzzes the parameters of the XML file, but I can't get it to work

kind saddle
#

the problem is that i have to translate, because i don't speak english

solar zodiac
#

maybe you can use it to translte the academy text

kind saddle
#

ok, if you find one let me know

solar zodiac
kind saddle
#

I only have 30 cubes, can I do something?

solar zodiac
#

there are many 10 cube modules

#

on the left, there is a "paths" link

#

cracking into hack the box might be a good place to start

ocean night
#

I believe once you complete a module, you get cubes back as well

spring beacon
#

How can I put another lenguaje in the page?

kind saddle
#

I completed a module and I didn't win, I was with 40 I spent buying the module and I didn't receive it, unless I'm wrong

ocean night
#

I could be wrong regarding earning cubes by completion to be honest, but that's what I recall. Will check..

sturdy igloo
#

anyone can assist on Attacking Common Applications - Skills Assessment I? i have questions 1,2,3. stuck on 4

ocean night
#

Does look like in the code that upon completion of a module, you are rewarded with cubes. If you think something doesn't look right, please do reach out to our support team @kind saddle . They'll be back on Monday 🙂

solar zodiac
#

oops

#

I tried to put a spoiler thing

#

and it sent it to the bot as a report

#

sry ><

#

was not intentional

#

sorry!

ocean night
#

Heh no problem

#

So long as you're not sharing direct solutions with others for active content, it's all good

solar zodiac
#

oh was my previous comment ok?

#

will delete if not

ocean night
#

It's quite direct..

#

A nudge in DM might be a better idea, but mentioning the intended vulnerability is quite the spoiler imho

#

Think how to direct, without pointing to the answer 🙂

solar zodiac
#

ok 🙂

ocean night
#

Cheers!

vital adder
solar zodiac
kind saddle
vital adder
solar zodiac
#

🙂

rustic sage
#

I'm having trouble in Getting Started // Nibbles - Initial Foothold. I have obtained the user.txt flag but the assessment answer box won't accept the answer. Has anyone else come across this issue?

rustic sage
cunning drum
#

<h1>Hello Hi</h1>

timid pollen
#

i think is a normal things that you need to log off a this stage since user setting will need to be loaded again...

rustic sage
frigid summitBOT
#
Vinz | WenLambo/We-NFT#8966 has been warned

Reason: Mass mention

vocal apex
#

Hey guys in the Linux module and I keep getting errors when trying to use the wget or now systemctl commands?

#

Requires authentication and I don't know the password for the HTB user

rustic sage
#

Anyone at zap scanner module?

vocal apex
#

htb[/htb]$ systemctl start ssh - this is the line that requires authentication - can someone help me

unreal patio
#

@vocal apex The desktop should contain a file called credentials

charred heath
#

hi

zenith schooner
vocal apex
#

Thanks @unreal patio

#

Use the "systemctl" command to list all units of services and submit the unit name with the description "Load AppArmor profiles managed internally by snapd" as the answer.

I've used
systemctl list-units --type=service | grep AppArmor

Which returned
apparmor.service
This is the only service with app armor but the answer is wrong?
Is there a better place to ask these questions - I don't want to clog up the adults table - with what I feel are very nooby questions

unreal patio
#

@vocal apex which section and question is this?

vocal apex
#

service and process management in linux basic

unreal patio
#

You are quite close to the answer

#

When you fill in the query you posted above you get two results

#

Try the second one instead of the first one

vocal apex
#

I just have load app armor profiles

#

I don't have a second one

unreal patio
vocal apex
#

Nope don't have the second line

#

mind if I message you what I have privately?

vital adder
unreal patio
#

👍

timid pollen
vocal apex
unreal patio
#

Same for me, it says you have limited whom can message you

kind vessel
#

Hello can someone help me for IDOR ; Bypassing Encoded References

inland coral
#

👍 thank you re drop first 17000, was giving up on that large list given time constraints, was also seeing unverified info that copy/pasting rule from module was it... I was also considering other users and short lists, etc. etc. ... so I had a huge matrix of potentials... dropping first 17000 likely got me past the section before 2050 LoL. Thanks again.

stray wing
#

hy I am new in cyber security and I am in need of help and how to start. I have been able to download kali Linux but I am having some trouble downloading scripts from git hub so if anyone can please walk me through it. thank you.

vital adder
#

if you are new to this i'm not sure if it is a good idea to run random code from github without knowing what you are running also check this video out to see which skill are you missing to start hacking https://www.youtube.com/watch?v=lhz0-qAQlBM

Sponsor: https://go.intigriti.com/thecybermentor
Blog Post: https://tcm-sec.com/so-you-want-to-be-a-hacker-2022-edition/
Academy: https://academy.tcm-sec.com

Timestamps:
0:00 - Introduction
0:53 - Intigriti Sponsorship
1:55 - Building a Foundation
2:10 - Important Notes
5:37 - Basic IT Skills
8:28 - Networking Skills
12:38 - Linux Skills
17:04 ...

▶ Play video
vital adder
vital adder
#

also for github you can use git clone to clone the whole github repository or if you just want to download a single file you can click that file and look for the Download button if the file you are trying to download just have code and you can wget the url

stark ermine
#

Hi there, could someone give me a hint regarding the Broken Authentication Module -> Predictable Reset Token -> question number 2 (request a reset token for htbadmin to force a password change)? I can decode the temporary password and tamper it but not sure how can I use it to access the htbadmin.

vital adder
#

hint use that as ||the password|| ||(after you change the token of course)||

stark ermine
#

Thanks @vital adder , going to try that!

shy warren
#

Anyone having issues with xfreerdp disconnecting the session? It appears my session crashes frequently when doing the Windows modules for password attacks. I know it's not my fiber connection, it seems to disconnect me every 2 min or so

vital adder
#

is your pwnbox on at the same time as your vpn?

stray wing
shy warren
vital adder
#

academy have a free module on this but in the video i send you there is a section of "where to learn linux" or something like

vital adder
shy warren
vital adder
#

lately i also have the disconnect and slow network issue regenerate a new vpn help a bit but not much after a while

shy warren
#

Password Attacks - PTH module - "Connect via RDP and use Mimikatz located in c:\tools to extract the hashes presented in the current session. What is the NTLM/RC4 hash of David's account?"

Are we suppose to use mimikatz to dump the current session hashes? When I use lsadump::lsa or lsadump::sam, the only users returned are admin, guest, default, and wdagutility. I've also used crackmapeec to remotely dump sam and lsa but still can't find David's hash. Any guidance to push me in the right direction?

pastel ginkgo
#

Is there a way to increase the display size of a remote session in reminia, trying to read the output of my cmd window on this remote machine and its a couple hundred lines squished into a million lines

placid quest
#

@shy warren use sekurlsa::logonPasswords full

shy warren
pastel ginkgo
#

You need to pass the debug command first

shy warren
#

oops, just needed to privilege::debug. Thanks @placid quest

pastel ginkgo
#

Is there a way to evil-winrm into a local admin account? I've tried both .\Administrator as well as the -r .\ option

obtuse moth
#

Is the use of the MyWorkstation mandatory or does the VPN Connection also work in the academy?
Otherwise a free user just has one shot a day?

pastel ginkgo
#

Figured out how to make reminina dynamically alter the resolution of the remote machine. It took me far to long to learn this.

pastel ginkgo
#

VPN is free pwnbox is one per day I think for free users, id just spin up your own vpn so you can evaluate if you want to upgrade to a subscription and access the more complicated material

obtuse moth
#

Thanks man 🙂

dusty mulch
#

hello 🙂 one random question i tried looking in the internet but no luck and probably i wont be able to do that but

#

someone knows how to specify a name for the hydra.restore file ?? im trying to do a script and i need different restore files 🙂 thanks<3<3

topaz locust
#

in the ffuf model, where does it tell us which ip and port the webserver is supposed to run? nvm you need to start it in the exercise tab

stray wing
#

does anyone know what ngrok is?

foggy light
rustic sage
#

I'm having issues in this section. Any hint?

rustic sage
balmy radish
foggy light
#

thanks for the explanation

balmy radish
#

yw

sturdy igloo
#

need help attacking common applications skills assessment 2. have all the answers but cant figure out the url to wordpress

vital adder
#

oh this is dumb the answers need to have http://(domain) and without a / at the end

vital adder
pastel ginkgo
#

When we use Rubeus we get a base64 key instead of the aes key is there a way to get the aes key? When I decode it I get garbage that can't be used to pth

#

I've already solved the page, just trying to dig deeper

silver iris
#

Hey guys, maybe i´m stupid, but i´m stuck on "Active Infrastructure Identification" question 2. I don´t get how i can look for vhosts with whatweb.

hazy grotto
#

I entered the passive command and still got the same result.

#

Footprinting Lab - Easy
Having issues using the dir and ls command

#

any suggestions?

sleek patrol
hazy grotto
iron basin
#

Thank y’all for this ^

hazy grotto
hazy grotto
#

i'm mounted to NFS share. I cat the file but it doesn't show anything. What do i need to do?

iron basin
# hazy grotto You were on footprinting easy as well?

Yes I am casually working on it. Managed to ssh in after getting the creds off the ftp server. I uploaded linepeas.sh and gonna try to get privilege escalation based upon the CVE's it showed the box to be vulnerable to. .bash_history shows the flag.txt filed was made and moved to the root directory.

hazy grotto
#

i can help if you dm

#

msaezh helped me but I think he just got off.

thorn urchin
hazy grotto
thorn urchin
#

looks at the file sizes

hazy grotto
#

i had to ls -la to see that. thanks foxyboxy

bleak patrol
#

Hey guys I'm new to ethical hacking and the stuff I'm reading in these modules aren't making any sense

thorn urchin
#

which module and what doesnt make sense

#

you may need to brush up on your computer foundations first

#

esp Linux

iron basin
#

@hazy grotto I currently stopped working on it but would you mind in the future if I dm you?

hazy grotto
hazy grotto
thorn urchin
#

I was mainly referring to Manny Sosa, but yeah wouldnt hurt

#

over half my flags from the hacktheboo ctf came down to just knowing basic linux tools

#

<@&861185840277487616>

balmy radish
#

I would start with the fundamentals modules and the intro to infosec path

hazy grotto
vital adder
#

just a normal scam

thorn urchin
#

scam spammer nothing big

#

happens from time to time on any medium or larger server

worn forge
#

Hey I need help with this Q: "se the user's credentials we found in the previous section and find out the credentials for MySQL. Submit the credentials as the answer. (Format: <username>:<password>)" I found the root creds n' I login into the mysql, I put the root creds as the answer and is incorrect, am I missing something?

hazy grotto
worn forge
#

Ur right, sry is in Password Attacks - Password Reuse / Default Passwords

vital adder
#

oh hint ||the cred is in one of the link||

hazy grotto
thorn urchin
#

not atm, Im about to buckle down doing my own thing here

bleak patrol
#

I'm on Service and Process Management

thorn urchin
#

yeah you should absolutely be following along with the module. Get those muscle memory going

sly tapir
#

why is it that \n = %0a , but when I encode the actual \n it is something else?

ocean night
#

How are you encoding it?

sly tapir
#

with URL through burp

ocean night
#

What is it encoding as with the unexpected result? I guess %5Cn?

sly tapir
#

its giving me %5c%6e

ocean night
#

Yeah.. literal value of the string \n

#

Instead of the interpreted value of the escape \n, which is a newline, aka %0a

sly tapir
#

i see. I was so confused because all the other injection operators matched a URL encoding except that one --- thanks for the help

ocean night
#

No worries 🙂

lapis pivot
#

Hi guys 🤗.. anyone help me with this Q it on fuff mod what filter should I use because am getting alot of results

Try running a VHost fuzzing scan on 'academy.htb', and see what other VHosts you get. What other VHosts did you get?

#

I used this command

ffuf -w /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -u http://academy.htb:PORT/ -H 'Host: FUZZ.academy.htb' -fs 900

sly tapir
lapis pivot
hazy grotto
#

Is this the correct command to connect RDP?

#

I'm trying to RDP into medium lab and having such a hard time. Not sure if it's installed correctly, wrong creds or wrong command

#

footprinting medium lab

sly tapir
hazy grotto
#

no / lol really?

sly tapir
#

i have no idea what your working on bro... i was talking to XO7

#

srry

hazy grotto
lapis pivot
#

@sly tapir
What filter do you think I should to use

sly tapir
lapis pivot
broken saffron
#

Hello everyone! I need help with Brute Forcing Skills Assesment-Web first question (When you try to access the IP shown above, you will not have authorization to access it. Brute force the authentication and retrieve the flag) I have like 3 days traying to find the password my understood here is the user must be b.gates and my commands is the next (hydra -l b.gates -P /usr/share/wordlists/rockyou.txt -f 134.122.106.163 -s 31793 http-post-form "/admin_login.php:username=^USER^&password=^PASS^:F=<form name='log-in'") is not clear how u should solve if someone could give me a hint I will appreciate a lot 😅

pastel ginkgo
#

On Password Attacts PtT, I'm able to get the hash 256 hash for svc_workstations but I can't find the ntlm hash to crack and get the password. Can someone point me in the right direction? I tried forging a ticket but im not sure how to use that to privilege escalate on a linux machine.

#

I figured it out, was easy I was just looking down the wrong rabbit hole

wheat garden
wheat garden
worn forge
#

Hello I need help on section Password Attacks - Password Reuse / Default Passwords, I found the root creds but idk what is the correct answer

vital adder
#

oh wait i didn't realize they also updated that section but previous apply that also you ||can't find the cred on the target machine||

vital adder
rustic sage
#

Is anyone able to help with the CPTS Getting Started - Knowledge Check assessment?

I have gained the initial reverse shell and obtained the user.txt flag but I am having trouble escalating my privileges. I can see that I have sudo access to /usr/bin/php but can't work out how to use that to gain root privileges.

vital adder
#

hint use ||gtfobins||

rustic sage
#

Hello hello and best regards

rustic sage
vital adder
#

hi guy, any tip on getting through no nut november?

wheat garden
marble raft
#

hi guys! can't seem to crack the aes256 hash in the Pass the Ticket Linux section of Passwords Attacks, any help

vital adder
#

i don't think you can crack that hash and ||hint you can crack all crackable hash on crackstation||

marble raft
vital adder
#

also are you on question 5?

marble raft
vital adder
#

so i'm pretty sure i have a typo or something in my note for this one but you can ||basically do the same thing as the last question|| and if you did dump the hash try cracking i think ntlm hash or something like that not aes256 one

marble raft
#

yea that was my first line of thought since it asks to use ssh to login as svc_ but using the keytabextract it doesn't find an RC4/NTLM hash

#

like i have this constant feeling that the answer is very very simple and i'm simply too dumb to see it

vital adder
marble raft
#

Today we have learned a very valuable lesson in life kids

#

Always ls -la the directory

#

and if you feel you're dumb

#

thats because you are

#

thx a bunch man

stone wigeon
#

Would I receive any certificate after completing a module?

marble raft
#

and you can get a Student Transcript via Settings

pliant sage
#

Hi, I'm doing the password attacks, cracking linux passwd shadow and whatnot and I have a problem. I've successfully retrieved the passwd.bak and shadow.bak but when I run them through unshadow, the output file is identical to the shadow file

#

and therefore I can't crack it with haschcat

#

has anyone ever encountered this problem?

placid quest
#

@pliant sage use john

pliant sage
#

i just tried

#

doesn't work

#

i ran this command: john --wordlist /usr/share/wordlists/rockyou.txt unshadowed.hashes

#

oh wait actually I think I made a mistake

late beacon
#

I've officially completed every module on Academy. It's been fun

#

Shoutout to the module creators. Slightly expensive content but high-quality training for the most part

#

And for some reason my dashboard hasn't updated in a while. It should say 100% for everything

pliant sage
#

congrats

frank bridge
#

Hlo

fresh reef
#

o7 HTB I'm stumped for tonight @>@ and I must place this on hold until tomorrow...but i need some guidance on this question with in "Footprinting>Host Based Enum>DNS" with the " What is the FQDN of the host where the last octet ends with "x.x.x.203"? "

I have tried
https://raw.githubusercontent.com/danielmiessler/SecLists/master/Discovery/DNS/sortedcombined-knock-dnsrecon-fierce-reconng.txt
https://raw.githubusercontent.com/danielmiessler/SecLists/master/Discovery/DNS/subdomains-top1million-20000.txt
https://raw.githubusercontent.com/danielmiessler/SecLists/master/Discovery/DNS/subdomains-top1million-110000.txt

And have run these bash scripts & dnsenum against all 3 aswell as have referenced https://forum.hackthebox.com/t/hack-the-box-academy-footprinting-dns-enumeration/250408

unreal patio
#

Use the fierce wordlist

#

on .dev.

fresh reef
#

bet

#

Thankyou

unreal patio
#

Gl

unreal patio
#

Yup

whole robin
#

how to do this and what r u doing can yall teach me?

tiny ledge
#

Can someone help me why is Session Security: Skills Assessment website not opening for me, what am I missing? :

#

I checked and the minilab is there on the list, any idea why is it not working for me?

rustic sage
#

Hi! Does anybody remember about it and is willing to help me with Footprinting module/medium lab?

unreal patio
#

@rustic sage Can you be a bit more specific with your question?

rustic sage
unreal patio
#

@rustic sage Was getting lunch 😛

#

select * from accounts.dbo.devsacc where name = 'htb';

#

Try that query

rustic sage
#

@unreal patio Thank you! This way I learned how to use a query. This is my first experience with SQL. Problem solved!

unreal patio
#

🙂

stuck hull
#

Hi guys, I'm following the Network Enumeration module, host discovery - and I am getting a different terminal output from my Nmap scan then the example. My Nmap seems to not be doing ARP ping scans.

#

Here is the example:

#

And this is my output:

sly grotto
#

can u guys suggest some boxes after complete Information Gathering - Web Edition module in academy?cause academy did not suggest?for footprinting it did

loud sapphire
fierce sparrow
loud sapphire
#

yes

fierce sparrow
#

shouldn't take long

#

show us your command

loud sapphire
#

hydra -l sam -P mut_password.list ssh://x.x.x.x

fierce sparrow
#

try -t 64 and -V, also recommend using your own vm and not pwnbox for this

loud sapphire
#

no vm. hardware. ill try with what you said

foggy light
#

Can need some help with Predictable Reset Token Question 1
This is the script im using

from hashlib import md5
import requests
from sys import exit
from time import time
import datetime

url = "http://138.68.181.31:31259/question1/"

header= {"User-Agent": "Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0", "Accept": "text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,/;q=0.8" , "Content-Type": "application/x-www-form-urlencoded"}
now = int(1667830437)
start_time = now
fail_text = "Wrong token"
user="htbadmin"
endtime=now+1000

for x in range(start_time-1000, endtime):
        raw_data = user+str(x)
        md5_token = md5(str(raw_data).encode()).hexdigest()
        data ="token={md5_token}&submit=check"

print("checking {} {}".format(str(x), md5_token))

res = requests.post(url, data=data,headers=header)

if not fail_text in res.text:
    print(res.text)
    print("[*] Congratulations! raw reply printed before")
    exit()


    exit()
languid dawn
#

also that data is never used and just rewritten until the loop ends

foggy light
#
for x in range(start_time-1000, endtime):
        raw_data = user+str(x)
        md5_token = md5(str(raw_data).encode()).hexdigest()
        data =f"token={md5_token}&submit=check"
#

is it good now?

languid dawn
#

sure but you still never use data outside the loop

brisk ocean
#

need someone who knows keyauth (i need cmd keyauth loader with hwid) DM ME good money to make

foggy light
languid dawn
#

sorry I stoppepd the convo mid way I'm in a meeting

foggy light
#

ok I fixed the code i think

languid dawn
#

but like you probably wanna send a request for each token you create

#

that's the main issue in your code

foggy light
#

Ok After fixing the code it working

#

Also Anyone looking at this in future you have to use milliseconds

lament tartan
#

when I run secretsdump.py, it dumps all hashes including the krbtgt account but when i specify -just-dc-user krbtgt it cant find the account.. any ideas why this would be or how i can just pull down the krbtgt hash without printing the hundreds/thousands of other users?

fierce sparrow
#

anyone for web services/api module? having issues with sqli payload

loud sapphire
fierce sparrow
loud sapphire
lethal atlas
fierce sparrow
lethal atlas
loud sapphire
fierce sparrow
lethal atlas
#

I opened the list in mousepad

loud sapphire
#

ewww

lethal atlas
#

sed is much easier

loud sapphire
#

brb!

fierce sparrow
lethal atlas
#

what a re you stuck on? I have finished that one

loud sapphire
#

hey guess what?
Its DONE.......... it took less than 20 seconds after deleting the first 17000 passwords.

fierce sparrow
#

nice haha

loud sapphire
#

finished that question. it was super easy.......... why 17000 passwords... ahhhhh i been sitting here for hours!!!!!!!

#

thank you @fierce sparrow @lethal atlas

fierce sparrow
#

no worries

lethal atlas
#

17000 was just a number to eliminate the majority. COuld have really been anything

loud sapphire
#

i am just surprised that as its only an example exercise that they set it up that way........ cracking that in 20 mins would have been sufficient imo. teach the method and a small amount of patience.

stuck hull
#

Can someone help me understand why the MAC addresses are not showing up and my Nmap is not doing ARP scans?

#

I have run nmap in sudo

loud sapphire
#

this next one isnt great either lol. mysql creds now lol. here we go

lethal atlas
#

this entire module is a test of patience. Start hydra, walk away for a bit and come back later lol

#

@stuck hull dm me and I will try to help you

loud sapphire
#

ya dont need hydra for the mysql part

vocal vortex
#

Hi there,
Section Web Attacks, Chaining IDOR vulnerabilities.
The question at the end is "Try to change the admin's email to 'flag@idor.htb', and you should get the flag on the 'edit profile page."
So i have changed the admin email to what is mentioned, but requesting the info afterward i don't get any flag as it should. In case i am missing something could you give me a hint? Thanks in advance.

unreal patio
#

Trying to get the password out of the ziphash but John wont even start

thorn urchin
#

idk its saying session completed

unreal patio
thorn urchin
#

maybe rockyou aint the list ya need to use then

unreal patio
#

Tried a mutated list and it also stops at 01 seconds

thorn urchin
#

can try the unmutated list for completionist sake too. I dont recall running into any issues on that module, are you using your kali or the pwnbox?

unreal patio
#

pwnbox

#

I'm rebuilding john to see

#

I downloaded the github but the run folder didnt have zip2john

thorn urchin
#

I used the pwnbox for that too but didnt need to download or build anything

unreal patio
#

Did you edit the hash you got out of zip2john?

thorn urchin
#

I dont believe so

unreal patio
#

😐

#

Why is it all fucky for me then :\

#

Am I supposed to get the zip out of the root folder or is documents fine?

timber hatch
#

Modul Local File Inclusion, Remote File Inclusion (RFI) ...I can't connect to the webpage?

#

but there is only a IP and no port when i spawn the target? Is that supposed to be so?

thorn urchin
thorn urchin
#

in which case the webserver is typically on a default port, or youre supposed to scan the box to find the port

#

the box spawns btw you have to either use the pwnbox or connect to the VPN for, wheras the dockers can sometimes(always?) be reached publicly

timber hatch
#

ok now it works...I generated a new vpn key... 😉

unreal patio
#

I am dumb

pastel ginkgo
#

I'm trying to do the optional exercises of Password Attacks - PtT but when I try to connect from my host I get the following error.

#

Is it because im using a bad ticket? I tried taking the one used that worked from the linux machine as well as from windows through rubeus. I get the same error, did I set up my proxy wrong or am I missing something?

waxen current
#

Today I joined the academy, did the first module and i already feel welcomed, motivated and inspired.

#

Tomorrow we'll make more progress.

thorn urchin
rustic sage
#

@waxen current Welcome to the team!

thorn urchin
waxen current
pastel ginkgo
thorn urchin
#

thats chisel connected but that doesnt mean proxychains is connected

#

chisel doesnt often listen on 9050 for a reverse tunnel like that

#

and also if proxychains did connect, youd have more log stuff from chisel there

unreal patio
#

@thorn urchin Just had to use the full mutated list

pastel ginkgo
unreal patio
#

I thought the wordlist was not working out due to the speed

thorn urchin
# pastel ginkgo

yup so you need to change your proxychains conf to point at localhost 1080

pastel ginkgo
#

I think I see why

#

The socks4 was there already so I left it alone

thorn urchin
thorn urchin
pastel ginkgo
#

Thanks, but now im at a new error lol

#

but thats progress!

#

[proxychains] Strict chain ... 127.0.0.1:1080 ... ms01:445 ... OK
[-] ('unpack requires a buffer of 4 bytes', "When unpacking field 'length | !L=0 | b''[:4]'")

thorn urchin
#

well thats an error alright lol

#

but looks specific to impacket

pastel ginkgo
unreal patio
#

For the zip?

thorn urchin
#

probably used better chunks for that section 😛

pastel ginkgo
# unreal patio For the zip?

Whoops thats the next section for me, I thought you were talking about when it first introduces mutated list and you have some 17000 passwords

unreal patio
#

😛

silver iris
#

Anyone here who can give me a hint on "Active Subdomain Enumeration"?

lofty blade
#

What is the proof text displayed in the Target website you browsed?
in the Introduction to academy module, I try to connect to a docker target but all I get is an error screen that says Error code: SSL_ERROR_RX_RECORD_TOO_LONG

#

I dont know what Im doing wrong

wide path
#

Does anyone know what is the password of our htb instance on the htb academy website ? I tried my account password but it does not work

#

When i try to sudo in the instance it asks me a password

brisk tapir
#

ifaik there should be a text file somewhere with the password in it

wide path
#

Yes, I reset the instance and the credential.txt appeared, thanks !

placid quest
#

@silver iris what is the problem

late beacon
#

Any new modules coming soon? @blissful verge

woven copper
#

Hi everyone from the BloodHound Module - Analyzing bloodhoun data , did anyone face a problem with zip files ? I tried from version 3.0.5 to latest 4.2.0 and all show up message BAD JSON FILES.