#modules

1 messages Β· Page 19 of 1

lethal atlas
#

I think they are updating that module as some of the content is now out of date

#

Has anyone done Linux Priv Esc? I have a question about the skills assessment, flag4.

rustic sage
#

Hello

strange folio
#

Hi

foggy light
#

Can Someone help me with Broken Access Control ;skill assessment ? After trying for hours Im totally lost.

rustic sage
#

i need an advice regarding the Pivoting Skills. reached mlefay, found 172.16.6.35 with the Powershell Ping Sweep but how can i find the creds to login there? Opened a lot of hidden files but nothing πŸ‘€

foggy light
#

I found 1 user and I think I figure out the password pattern

warm sand
#

anyone available for a hint for AD Enumeration & Attacks - Skills Assessment Part II question 5 - what is the user's password? i've enumerated the domain finding all the users but honestly lost on how to get the user credential from here on..thank you

lethal atlas
#

dm me

wide path
#

Does anyone know who I can contact if I have a technical problem about a module ?

lethal atlas
wide path
#

In the Windows Fundamental Module, when i use xfreerdp it keeps disconnect me from the remote Windows machine with error message

wraith pelican
#

Has someone here done the "User interaction" part in the "Windows priv esc " module?

lethal atlas
vital adder
wraith pelican
#

can i pm you?

vital adder
#

sure

foggy light
#

Almost done with Broken Access Skillassessment.. I need a little bit help

#

decoding the cookie

#

@lethal atlas +rep

lethal atlas
wide path
lethal atlas
#

did you execute with sudo?

wide path
#

no is that the problem ? I executed it without sudo during the past sections and didnt disconnect like this

#

I found an alternative by using rdesktop

zealous belfry
#

Could somebody help me with attacking common services smb "whats the password for jason"? I thought you just use crackmap and the provided password list to get the pw but theres no hit? ```sh
crackmapexec smb 10.129.194.196 -u jason -p ~/Desktop/pws.list

vital adder
#

i use metasploit for that but crackmapexec would work just find a the cred for that user is in the given wordlist

zealous belfry
#

oh nvm moved back a section to ftp and found it weired that you dont have to use SMB in the SMB section tho

vital adder
#

oh yea that's is weired 🀣

vital adder
thorn urchin
#

worth trying the local auth or whatever its called for cme

#

Ive had a few fail cause cme trues the domain auth against a box thats not in a domain at all and so it just doesnt work but theres no error, you just either get all hits fail or more bizzarely all hits pass

vital adder
#

i think i got a similar issue on an active directory lab a while back

#

@zealous belfry i just try with metasploit and it seem to be working fine for me use auxiliary/scanner/smb/smb_login

vital adder
#

let me try crackmapexec again on my machine hope this is not a pwnbox issue again

zealous belfry
#

nah i dont use the pwnbox

vital adder
#

oh

zealous belfry
#

prob a CME issue

zealous belfry
#

Nah if im honest that module is weird is af. It's SMB and you retrive the flag with brute-forcing ftp.. i dont get it thinkw

thorn urchin
#

well the ftp is an alt route

#

its still achievable via smb

vital adder
#

most of the section in this module is using the same target machine so if the jason user can login to smb mostly he can login via ftp and the flag is at the place you just can access it with multiple method

zealous belfry
#

oh wait

zealous belfry
vital adder
#

@thorn urchin oh wow nice tip i'll note down thanks

zealous belfry
#

Me too appreciate it ty

thorn urchin
#

np

#

I probably stumbled across it while working on that very module

#

<@&861185840277487616>

zealous belfry
#

Interesting

sterile hawk
#

ty

little whaleBOT
#

SandPlanet has been banned permanently.

pastel ginkgo
#

For the life of me I cant remember how to ssh to a target now that I have their private key

zealous belfry
#

shh user@host -i key

#

make sure it has the correct chmod

pastel ginkgo
#

that was it

#

thanks a ton, was brain farting

zealous belfry
#

no worries πŸ˜„

vital adder
#

over a months late but thanks for the respect on htb (i just learn how to check that 🀣 )

thorn urchin
#

wait thats a thing lol

zinc dew
#

Yep, just gotta visit their profile

pastel ginkgo
#

How do you open a encrypted docx file if you have the password?

thorn urchin
#

open it

#

like in word

#

think open office/libre office is fine too

vital adder
pastel ginkgo
#

Thanks! that worked!

#

Rip this site spit out the pages as jpg so now I have to hand write the flag πŸ˜‚

acoustic dawn
#

Hello all, I am having issues with the last challenge with the HTTP headers section in http fundamentals. The question says to find the flag in the requests when browsing to the target in the network section of the devtools. I’m looking at the flag. Flag_….txt but no matter what format it says it’s wrong. I’ve tried restarting from scratch I’ve tried htb{} flag{} flag_ just the numbers.txt , the entire get request lol. Is this question broken?

timber meadow
#

HI

red obsidianBOT
#

BEEP BEEP! BMW M4

fresh reef
#

Trying to dump the contents of an IMAP Mailbox over SSL, can someone point me in the right direction for the FETCH Cmd

placid quest
#

@fresh reef what is the problem

fresh reef
#

1 FETCH 1:* FLAGS pulls the flag and the all pulls what a response i trly dont understand yet

#

as well as still cant find documentation on why the preceding "1" exist thus further clouding my debugging judgment

#

I'm having an imap command syntax struggle

placid quest
#

@fresh reef maybe use evolution

fresh reef
#

0.0 evolution , looking of a binary cli-tool?

placid quest
#

@fresh reef I am not understanding u

fresh reef
#

@placid quest sent a terminal pic, and thx btw

fast vale
#

Hello

tiny ledge
#

Are people able to connect to Session Security: Skills Assessment, I can't connect to the minilab.htb.net even after vHost has been configured

pliant sage
#

Hi, I'm currently in the Passwords attack: pass the ticket part of academy and I've encountered a problem. I've used keytabextract.py to get a hash from a keytab file. It's only provided me with an aes-256 hash but I can't seem to crack it with hashcat or the online tool suggested by the module. Any suggestions?

#

this is the hash ||0c91040d4d05092a3d545bbf76237b3794c456ac42c8d577753d64283889da6d||

#

nevermind figured it out

autumn pilot
#

no

tiny ledge
#

Can someone nudge me forward in Session Security: Skills Assessment? How am I supposed to figure who the admin is, and what am I supposed to do with this:

blazing solstice
#

hello i wan't anyperson in private

#

because i have a probleme

zealous belfry
tiny ledge
thorny glade
#

Hi,

Is my understanding of LD PRELOAD correct?

If LD_PRELOAD is available and a user can run a SUID file, we can escalate privileges via loading a .so script, that is compiled C program via gcc.

Then overwrite the env with the shell and alongside with the SUID file to spawn a shell that will run as root.

sudo LD_PRELOAD=/tmp/shell.so sky_backup_utility

#

Thanks!

solar granite
#

Hi guys, I need some help with attacking common applications skills assessment 2
What is the admin password to access this application? - I tried the default credentials and also a brute-force attack for the default admin user ||n...admin||, on the application from the question above, but I haven't got any valid password

Edit: solved!

rustic sage
#

hi can someone help me with the Pass the Hash (PtH) section of the password attacks module??

#

i can't figure out how to connect to DC01

dawn bloom
#

any channel to discuss about retired machines or machines in general?

pliant sage
dawn bloom
mellow turtle
#

i think u need to verify your account

rustic sage
mellow turtle
floral jolt
#

hello

dawn bloom
#

until a moderator answers, i can't verufy my account

#

identification error for some reason

pliant sage
mellow turtle
#

So u must wait then

rustic sage
floral jolt
#

hi

mellow turtle
#

hola

little whaleBOT
#

Please see your DMs for instructions on how to verify your HTB account.

pliant sage
#

or you can't get one?

solar granite
#

dm me

rustic sage
mellow turtle
#

@rustic sage send us the command u are using to connect

rustic sage
#

Wait a sec and I’ll send you

pliant sage
rustic sage
pliant sage
#

and it didn't connect back?

rustic sage
#

nope

#

can i dm u?

pliant sage
#

ofc

hollow hinge
#

Can you describe where you stuck at?

rustic sage
#

Question: can i change the letters to white, cuz grey on blue is not readable

dawn bloom
#

idk if it's the version i'm using or because i'm launching firefox with firejail

rustic sage
#

I rather have the text white

#

but its doable

thorny glade
# gusty fulcrum .so is Bash scripting ?

As I remember, it stands for .soname it is similar to Windows DLL it is commonly used for pre loading a program the .soname also include the C runtime library.

rustic sage
#

is there anyone to help with PIVOTING AND TUNNELING SKILLS MODULE?how to transfer mimicatz to mlefay host?AM IN WITH xfreerdp /v:127.0.0.1:3300 /u:mlefay and can't find vfrank password,AM BADLY STUCK

plain coral
#

Anyone else experiencing lag spawning targets?

lament tartan
#

yep

rustic sage
#

yes

blissful glen
#

Are targets down for everyone ?

stuck hull
#

These hosts are up apparently. But when you scan them individually nmap doesn't find any open ports

#

Ignore previous message. Those hosts are up and ports are open on them

lament tartan
#

mine spawned now

carmine quail
gusty fulcrum
lament tartan
storm jackal
#

same

plain coral
warm sand
#

For the AD skills assessment 2, question Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host - can someone give me a hand getting the flag? I've connected with the user/pass that I've found in the config file. Thank you

storm jackal
#

seeing everything operational though 🀨

fierce sparrow
#

it's taking very long

buoyant drum
#

Hi, I'm trying to spawn a machine but it keeps loading. Never happened before. Anyone know why it keeps loading?

blissful glen
#

Welcome to the club

buoyant drum
#

look like I'm not alone xD

lethal atlas
#

Looks like HTB is having some issues today. Be patient, I am sure they are working hard to fix the problem.

shadow tulip
#

hi, I have an issue on academy. I click on spawn target (stack overflow linux x86 module), it says target is spawning but it doesn't spawn. I also tried to spawn targets in other modules but didn't work too. Can anyone help me?

#

never spawns

lethal atlas
shadow tulip
#

oh sorry

#

I noticed now

#

Thanks a lot

#

I will try tomorrow

smoky chasm
#

🀣 typically the day I decide to sit down and get some modules done...ah well

high coral
#

Me: of course...

lament tartan
unique valve
#

Make sure to use the support bubble to report this as well.

lament tartan
solar granite
lament tartan
#

oh sorry, i misread my notes.. that didnt work for me either πŸ˜‚

#

will DM

solar granite
#

Cheers

lament tartan
#

not even trying to spawn now

#

connected!

raven cairn
#

Pwnbox is up for me now

flint helm
# lament tartan not even trying to spawn now

For me the target of shells & payloads assessment is taking an eternity to spawn, I waited a whole hour for it to spawn and then refreshed the page to try again. When I tried again I was getting that same error. Now it's been loading again for about a good 20 minutes... πŸ˜•

loud sapphire
#

i am also having issues spawning servers..........

inland coral
# shadow tulip never spawns

If it helps to know, I'm seeing this as well. I cannot paste a picture in my post yet but it is stuck at "Target is spawning..." with spinning circle. Was working great a little over 7 hours ago when last using it. And generally, it works really really well, never have seen this before.

inland coral
#

FYI, I see this in the support chat window so they are very much aware of it: "We are currently investigating an issue with spawning machines on Academy. If you are affected, please do not open a ticket. We are working on resolving this as soon as possible."

lament tartan
#

could try and refresh and spawn again, did take mine a while though.. servers must be busy. maybe depends on VPN region/server as well.

inland coral
lament tartan
#

yeh mine just started working 20 mins ago

inland coral
lament tartan
#

just in time for me to take a break πŸ˜„

inland coral
inland coral
broken warren
#

Can someone explain the question in broken authentication > session attacks > brute forcing cookies. I was able to convert one token to reveal the user and role. I can change them but Idk what Im supposed to change them too. The question asks for a super user which I tried as a role but no luck.

raven cairn
#

Just to check. Is anybody having issues spawning the target???

#

Is the issue still persisting???

high coral
#

Yup, still occurring for me.

raven cairn
jovial halo
mellow turtle
#

same

raven cairn
#

Hope support can get it fixed soon. We appreciate all that you do. prayge

gentle steeple
#

Right so there is an issue with spawning machines.. I thought something's wrong on my end πŸ˜…

inland coral
#

Hey folks, guess what? I just came back to my system and had pwnbox and target IPs, things were up, so I figured things were back. Since I had been away, I had lost "time" on the systems, so immediately reset both to have a fresh long time period. After that, I see target spawning/spinning circles...

So maybe it works but is very very slow... so maybe just refresh, spawn, and wait and do not refresh... just wait, and you will eventually get a target. This would be consistent with what others have reported, that they eventually get one but it took a *long *while.

This is all a *guess *on my part, but I did have target and when I reset just now it went back to spinning/spawning and no target. I should not have reset for fresh long duration time period, just use whatever I had with whatever time was left.

#

Like right now mine is still "spawning" after 5 minutes ... but I am not refreshing at all, just not touching it, leaving it... I will report back if it eventually has IP.

solar granite
inland coral
stuck hull
solar granite
#

Seems to be fixed now. Everything works fine after ~15 minutes of uptime on the target

inland coral
#

I still have spawning... about 7 to 10mins now.

#

oh just got IP after sending that last message.

silver iris
#

I still have the issue :/
Pwnbox is working, just target is not

sturdy whale
#

I'm having issues logging in to HTB Academy. Not receiving reset password email.

#

Issue resolved.

inland coral
#

I had luck by refreshing, starting pwbbox, starting target, then waiting not refreshing for about 10 minutes and it eventually gave me a target.

#

I am using a target now and it has about 50 minutes left. It is the most productive I've been this morning... to refresh/spawn and wait. When I would keep refreshing, I never would get any target... so waiting after spawn, even for 10 minutes seems better than constantly spawning.

#

(that is what I observed, maybe you are seeing a different issue but sounds the same)

#

I was able to find this out by spawning and taking a coffee break... I came back and had an IP address. When I reset to spawn again, it was waiting for about 10 minutes before getting another IP. So I do not recommend resetting to get fresh "time" on the target, just wait for a target and use it as best you can until you need another.

warm sand
#

hello for AD assessment 2, question Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host - i am on the sql01 machine as administrator, ran mimikatz but did not get anything that might get me to ms01 machine, anyone could get me some help with this? thank you

marble raft
#

Hi guys! Having some trouble with the Web Server Pivoting with Rpivot section.

Everything is working properly yet when i try to use proxychains to request the webserver it just keeps loading.

Running nmap against 172.16.5.135 via Proxychains work btw

Edit: Network was very slow, the request worked without doing anything, just had to wait

pastel ginkgo
#

I'm on the Medium lab for Password Attacks || I know about the "d" user" But not sure how to crack his password, I tried the default passwords to tomcat but im not sure where to go from here ||

rustic sage
#

hello all how long should an smtp enum scan take? using quite a big txt file but seems to be taking a long time??

hardy anchor
#

Hey I'm having problems to solve the "Attacking common services easy lab". I found ||fiona|| creds, the files into ||FTP|| and I was able to upload ||webshell php in mysql (SELECT "<?php echo shell_exec($_GET['cmd']);?>" INTO OUTFILE 'C:\xampp\htdocs\webshell.php';) ||but when I go to the web page where I save it, it return "not found". Any hint please?

placid quest
#

@hardy anchor did u login smtp

wheat garden
pastel ginkgo
#

I got really excited for all of 2 mins when it returned the password as 12345657

#

only to find out its a dead end

wheat garden
#

ya it allows anonymous access need to enumerate what you have access to

pastel ginkgo
wheat garden
#

oh ok

pastel ginkgo
#

I found || d account listed in the passwd file so I've been trying to figure out how to get to him to see if I can find more but i'm now stuck ||

wheat garden
pastel ginkgo
#

You mean the sql db files?

wheat garden
#

always good to look at running services youll see the machine is running mysql database youll need to access the database and see what other information and creds you find on there

pastel ginkgo
#

how do I see running services?

wheat garden
#

theres actually quite a few ways you can do so but I usually use the top command in linux it shows the prcoessses taking up the most memory and processing power

pastel ginkgo
#

I see now

#

hmm

#

now I need to figure out how to open the db files

wheat garden
#

the terminal program you need to use is the same name as the service mysql

#

you could use other programs though too

wheat garden
pastel ginkgo
#

it seems so simple now

#

idk how I missed it

#

well, I do , I was thinking I needed to find the db file. I didnt even think to launch mysql πŸ€¦β€β™‚οΈ

worn forge
#

Hey, I need help in PASSWORD ATTACKS - Attacking sam, I'm trying to dump the sam files with secretsdump but I have an error " 'NoNeType' object is not subscriptable" idk what Im doing wrong

hardy anchor
placid quest
#

@hardy anchor enumerate the smtp

wheat garden
#

keep calm and enumerate

hardy anchor
lethal atlas
#

anyone online that has done linux priv esc?

warm turret
#

hello

#

someone can help me with Attacking Common Applications - Skills Assessment I

hardy anchor
wheat garden
vital adder
vital adder
thorn urchin
vital adder
#

yep

thorn urchin
#

my friend was doing the getting started module and was sidetracked trying to figure that out because linpeas pointed it out

#

I was like lol no I gurantee you thats an unintended path, look elsewhere

#

havnt done the module yet but tbh pwnkit is something important enough that it should probably be a part of that module somewhere

vital adder
#

yep but it's just that the module is kinda old so an update would be good for newer exploit like this

thorn urchin
#

yeah

#

its definitely the hard part about modules, you could get unlucky and as short as a month have the whole thing be outdated

vital adder
vital adder
thorn urchin
#

yeah not shocked

hazy grotto
#

Anyone who's completed the pentesting path? How long did it take you?

thorn urchin
#

not many people have completed it yet so you may not get your answer, but for the record Im 50% of the way through and been at it for roughly a month

#

but your background is going to have a big influence on how quickly you get through

raven cairn
#

Having IT experience will be super helpful

#

it's been taking me a while since I have no college or career experience

#

However it is accessible for n00bies

vital adder
thorn urchin
#

like I have a weird background in that I used to be super active like 10 years ago and then took a big break for a buncha years basically only tuning in to news n stuff but not really practicing or learning new stuff, so like the first 40% of the course was basically just a refresher for me.

#

the AD module is mammoth of one and been taking me the longest. Lots of content that's actually new to me plus a ton of sections, and wrist problems cropping up means taking notes has been difficult, so Ive slowed down a lot, probably been spending the past week and half on that module alone

#

Web stuff always used to be my weak area so im very curious and excited to see how those sections go for me

#

since at least if the hacktheboo ctf was anything to go off of, my intuition for that area has drastically changed since my old days.

raven cairn
#

Cbbh is great for web stuff

#

super in depth

#

have completed all the modules, will complete the exam sometime

thorn urchin
#

yeah I may check it out after I finish the cpts, my post plans for it arent set in stone yet unless I miraculously save up enough for the OSCP, in which case thats definitely going to be my next aim after this.

#

its just so expensive that the few times ive had the money to purchase it Ive been too scared to bite the bullet even though rationally I know I have the capability to do just fine. So part of me is banking on clearing the much more accessible cpts to assuage the non rational emotional part of my brain into agreeing with the money risk.

#

since by all accounts the cpts is newer and harder than the oscp in most areas and the ones that it doesnt cover used to be my strong points anyways lol

raven cairn
#

I think oscp will be a breeze if you do cpts

thorn urchin
#

thats what Im banking on

pastel ginkgo
#

Wait Cpts is harder than oscp?

thorn urchin
#

thats the general consensus so far yeah

#

its more modern and focuses more on TTPs

#

I mean oscp bans the usage of some tools because theyre too powerful and would make their exam lab too easy, cpts says use whatever youve got. Draw your own conclusions

raven cairn
thorn urchin
#

tactics, techniques, and procedures

#

I dont know what that translates to in practical terms, its just what Ive read from people discussing them and staff, but my interpretation is that the OSCP is more likely to be a series of challenge boxes, wheras the CPTS is more likely to be a simulation of a real network and you must transverse it accordingly.

But I could be wrong.

#

hopefully within a couple of months I could answer more clearly πŸ˜‰

marble raft
#

Getting this error while executing chisel on Pivoting Tunneling and Port Forwarding module, in the SOCKS5 Tunneling with Chisel

./chisel: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.32' not found (required by ./chisel)

Any idea how to fix?

warm sand
raven cairn
#

Could I have some help on attacking common applications: Gitlab?

#

I can't get the user enumeration bash script to work

thorn urchin
#

looks like its breaking on something and causing syntax reading errors

#

try running it with sh specifically or bash specifically instead

raven cairn
#

so I changed my default shell to /bin/bash cuz I know pwnbox uses zsh

patent obsidian
#

hello, can you help me I am in the COMMAND INJECTIONS module, exactly in Bypassing Blacklisted Commands and I don't know how to get and read flag.txt

thorn urchin
raven cairn
#

Still not working pepehands

thorn urchin
#

you tried both bash and sh?

raven cairn
#

yes

thorn urchin
#

well thats different error now

#

hey different errors are progress

#

not sure what that one means though, Id have to look at the script

vital adder
#

@raven cairn use 49821.sh (with searchsploit)

raven cairn
#

Yeah, I'm using that script

#

Just renamed it

#

I get frustrated when I do exactly what the module tells me to do and it don't work 😭

vital adder
# raven cairn

oh yea you are using that script not the given script that's weird

#

let me give it a check

raven cairn
#

pls

pastel ginkgo
#
#

What a beast!

#

took me two weeks!

thorn urchin
#

I hated that module lol

#

too much time wasting stuff

vital adder
# raven cairn pls

so... it's working fine for me, try re-copy the script

searchsploit -m ruby/webapps/49821.sh
./49821.sh ```
thorn urchin
#

good job though!

raven cairn
#

Got it to work. The script on exploitdb wasn't working for me for some reason

#

but that should be the same one on searchsploit?

vital adder
#

yep it should be

vital adder
raven cairn
#

Yeah the module gives you a script from exploit db so I just used that one

vital adder
#

oh

thorn urchin
#

weird that they would be different

vital adder
#

want to know something weirder? both script are the same both have 110 word and a text compare show both script are the same but the one on exploitdb don't work

thorn urchin
#

probably encoding shenanigans then

#

hexdump with xxd and compare those πŸ˜›

#

@vital adder yup, the one on pwnbox is just ASCII, the downloaded one from exploitdb is ASCII with CRLF line terminators

vital adder
#

oh yea why didn't i use file for both file

thorn urchin
#
cat 49821.sh | tr -d '\r' | bash
#

works fine

vital adder
#

yea the code are the same so if you just copy the raw code from exploitdb it should just work fine

thorn urchin
#

that sounds like extra steps that tr can do for you

urban valley
#

Hi Can someone help me with the last question (find another user with dsync rights) of enumerate domain acl section for the AD PowerView module?

quasi wave
#

hi can someone give me a hint for this part of the Windows fundamentals module?

#

I'm trying to identify the service that has to do with PDF editing

#

I don't want someone to just give me the answer but if I could have a hint

#

I figured out multiple ways of looking at different services on the windows machine

#

but I don't see one that has to do with PDFs specifically

thorn urchin
#

I dunno if thats what theyre going for in the module though

quasi wave
#

I don't think so

#

there's no PDFs open

#

and I don't think there are any on the system

#

that are saved anyways

#

so its a tough one

#

solved it

#

never mind

rustic sage
#

can anyone help me with an SMTP issue please? πŸ™‚

#

im struggling to change the query time! not quite sure what or where i need to put in my command to change it...

rustic sage
solar granite
# raven cairn

For the record, the reason it doesn't work is because the shebang line (#!/bin/bash) isn't usually put as the very first in most scripts from exploitdb. For errors like this make sure to always check the shebang line, and move/add it

#

Sure, dm me or write here what you've tried so far

autumn pilot
#

no

languid dawn
#

Read the #rules we don't allow illegal activities. EDIT FOR FUTURE STAFF: There was an srs rule break ping, it's not a ghost ping

autumn pilot
#

read the #rules before asking such questions @tired badge

cloud urchin
#

Can anyone help me with this

bitter knoll
#

Can any one help me with hashcat concept

spare condor
#

@woven copper any hint on this one? Found this, if someone has some issue regarding this, DM me.

lament tartan
#

Attacking Enterprise Networks - Lateral Movement says We can do this via Proxychains using GetUserSPNs.py or PowerView but every single combo I try with GetUseSPNs.py returns the same error: [-] Error in bindRequest -> invalidCredentials: 8009030C: LdapErr: DSID-0C090690, comment: AcceptSecurityContext error, data 52e, v4563. Tried it with 4 users, including the Administrator πŸ€” The PowerView method works fine, any ideas??

rustic sage
#

Doing Passwords Mutation section in Password Attacks modules. Is it normal the exercise takes so long to bruteforce the correct password?

solar granite
#

For the Web Service & API Attacks module, did anyone do it the SQL Injection way? I've done it using a different method and was wondering about the sql injection way

marble raft
#

For those who come to face the error "version `GLIBC_2.32' not found" (or similar) on the SOCKS5 Tunneling with Chisel section.

You can do export CGO_ENABLED=0 to disable CGo and get rid of the dependencies, and then use go build and the binary will work.

rustic sage
#

Hi how can i register in HTB ctf 2022

solar granite
#

I am not aware of any HTB CTF running right now.

hardy anchor
#

Hey good morning! I'm having problems to solve the "Attacking common services easy lab". I found ||fiona|| creds, the files into ||FTP|| and I was able to upload ||webshell in mysql (SELECT "<?php echo shell_exec($_GET['cmd']);?>" INTO OUTFILE 'C:\xampp\htdocs\webshell.php';)|| but when I go to the web page where I save it, it return "not found". Any hint please?

loud sapphire
charred heath
#

hi

lament tartan
# lament tartan `Attacking Enterprise Networks - Lateral Movement` says `We can do this via Prox...

Also on this module, when you escalate privs on Win01 the guide says to run mimikatz after adding your user (ilfserveradm) to the administrators group. I did that but mimikatz doesnt have enough privileges. Tried to launch a new cmd.exe as admin but it rejects the creds πŸ˜• edit: I can't read the flag on Administrator desktop either, is some step missing from the section? same issue was mentioned on forum but no response - https://forum.hackthebox.com/t/attacking-enterprise-networks-lateral-movement/266130 - double edit: i just modified privesc to get a reverse shell instead

rustic sage
merry salmon
#

looking for help at the attacking common services - hard lab. I managed to get rdp session with F**** who doesn't really have much privs. ||The problem is I cannot do impersonation with msf cause it tells me none of the users that can be impersonated are sysadmins.||. I found out about the|| linked server|| but I'm unable to access it yet.

carmine quail
#

Or specify DC if available

lament tartan
carmine quail
#

Another thing to check is whether the proxychains dns is interfering. Are you using IP address or host names?

#

By default host names through proxy chains goes to 4.4.2.2

lament tartan
#

using IP, have not had any issues using proxychains with impacket etc until now. i can use the same creds/hashes and IPs with other scripts, e.g. psexec.py, crackmapexec, evil-winrm

lament tartan
hardy anchor
rustic sage
#

Is there no one who can help me with smtp-user-enum??!!

merry salmon
# hardy anchor This is my message

try to write that same command 2 times and you will get an error that the file already exists but you will see then why you cannot access the web shell, there is something in the command that needs to be added so it goes in the directory specified. If you still won't know whats the catch PM me

merry salmon
lament tartan
junior hazel
#

Hi,
I'm stuck on Attacking Active directory module, ACL section
Can someone help me please ? πŸ™‚

hardy anchor
rustic sage
#

I think there are some issues with Password Attacks module... it is being a waste of time as things doesnt work as teached

hardy anchor
#

@merry salmon Thank you!! I just spoted up

rustic sage
#

Can I have help in Attacking Active Directory & NTDS.dit section on Password Attacks module?

west perch
#

hi, I am new, and was wondering if I could start learning a bit of ethical hacking somewhere ?

kind saddle
#

Warning: xx.xx.xxx.xx giving up on port because retransmission cap hit (10).
does anyone know why this problem happens?

#

and how to solve

slim plover
thorn urchin
west perch
#

oh ok thanks you kind sir/lady

crisp remnant
#

Can anyone help a bit with one of the last tasks in intro to assembly module ?

woeful mural
#

Anyone completed ACTIVE DIRECTORY ENUMERATION & ATTACKS ? I am having an issue with uestion 2.

thorn urchin
#

question 2 of what section

woeful mural
#

active directory enumeration and attacks

#

Question 2

#

I found the user and cracked the hash but it seems to be incorrect.

thorn urchin
#

thats the name of the module,theres multiple sections within that module, which section are you on

woeful mural
#

Sorry. Miscellaneous Misconfigurations

rustic sage
woeful mural
#

ACTIVE DIRECTORY ENUMERATION & ATTACKS :Miscellaneous Misconfigurations question # 2

thorn urchin
#

not dont that section of the module yet so idk, good luck

#

<@&861185840277487616>

languid dawn
#

well he's gone

winged hedge
#

scary dude yo

languid dawn
#

but thank you

thorn urchin
#

felt like clear spam so ping seemed warranted, but ill keeo it in mind

languid dawn
#

for a random troll like that you can just dm a mod or two for clean up πŸ™‚

#

or ping if you see one of us active

thorn urchin
#

sounds good

rustic sage
#

anyone help me to change query timeout on SMTP-user-enum? i dont know where I need to place it in the command line

thorn urchin
rustic sage
#

ive tried -t 15 and --timeout-enum 15 which im sure they are both right but ive tried moving all around the query but it doesnt change anything? so not sure...

thorn urchin
#

what problem are you even trying to solve? might be trying the apply the wrong solution

rustic sage
#

my only other option is to metasploit but i should be able to get what im looking for via smtp-user-enum so bit frustrated i cant figure it out

#

footprinting module in the academy

thorn urchin
#

ah yeah that one

#

which mode are you trying to use πŸ˜‰

rustic sage
#

VRFY

slow hawk
#

hah I just finished footprinting today

rustic sage
thorn urchin
#

hint hint hint

slow hawk
#

yes sir

thorn urchin
#

are you sure thats the mode that works with this target

rustic sage
#

not anymore im not

#

xD

slow hawk
#

i believe a nmap default script will tell you what the smtp server accepts

thorn urchin
#

the module covers several different methods, if one doesnt work, try another

rustic sage
#

ok ill be back... thank you πŸ™‚

thorn urchin
slow hawk
#

ye, I'm just saying the nmap default scripts helps you figure out what you need to put for smtp-user-enum

bitter knoll
#

@slow hawk factβœ…

fair belfry
#

hi i'm new

rustic sage
#

so ive changed the mode.. but i still dont know where or how to change the query timeout?

#

i dont know where in the command i need to type it?

thorn urchin
#

why do you need to change it?

rustic sage
#

Remember that some SMTP servers have higher response times.

bitter knoll
#

@rustic sage what tool is that

thorn urchin
#

so -t is for that

#

but Ill tell you, wasnt necessary for that module

slow hawk
#

I had to use -t for that

rustic sage
#

im still drawing blanks... let me revist my query 1 sec

thorn urchin
#

pwnbox or VM?

slow hawk
#

VM

fair belfry
#

how i can learn kali

thorn urchin
thorn urchin
#

try the Linux fundementals module first, then the getting started module

rustic sage
#

pwnbox

thorn urchin
# slow hawk VM

thatd make sense then cause youd have greater latency to the target

#

pwnbox def doesnt need -t for this one

bitter knoll
#

@fair belfry try some books maybe

slow hawk
#

understandable

rustic sage
#

mad can i pm with my query?

slow hawk
#

are you using the right wordlist @rustic sage ?

rustic sage
#

the one from the resouce?

#

resource*

slow hawk
#

yeah

rustic sage
#

yeah got that one...

#

can i pm yourself guns?

slow hawk
#

sure

thorn urchin
#

I dont mind either

rustic sage
#

@slow hawk cheers for the help :). @thorn urchin thanks for the help πŸ™‚

#

all solved now.

slow hawk
#

yay

thorn urchin
#

nice, was it the mode πŸ˜‚

bitter knoll
#

proxychain configuration I have finished but still doesn't work @slow hawk

rustic sage
#

was wait time i needed to use -w

thorn urchin
#

weird, dont even see that as an option

rustic sage
#

me neither until it was pointed out lmfao. anyways its all good just running scan now so

#

my result just came through cheers peoples

desert steeple
#

Is anyone willing to help me or teach me how to hack a ig acc. He is someone from my school idk who he is tho he is posting gossip or secrets from everybody and posting it public and making beauty school competitions please someone help me please dm thanks. I am sorry if this is the wrong channel in advance.

thorn urchin
hardy anchor
#

Hi everyone! I'm doing the attacking common services - medium lab and I have a question: I'm trying to brute force ftp (because ||fiona|| creds from last server didn't work) and I would like to know if it's the correct way to solve the lab because this probably could take a long time

hardy anchor
# thorn urchin try enumerating deeper

Yes, i found this:

||PORT STATE SERVICE REASON
22/tcp open ssh syn-ack
53/tcp open domain syn-ack
110/tcp open pop3 syn-ack
995/tcp open pop3s syn-ack
2121/tcp open ccproxy-ftp syn-ack
30021/tcp open unknown syn-ack||

||fiona|| creds didn't work either for pop3 and ssh so I started with ftp. But probably the correct way is dns?

thorn urchin
#

nope, you should look a bit more closely at what services are running and check for common misconfigurations first

#

Its also worth keeping in mind that much of hacking is finding the overlooked spots. Just cause they've locked down one service correctly doesnt mean theyve locked down that exact same service elsewhere correctly

hardy anchor
#

Hm. Thank you @thorn urchin I will look more closely

thorn urchin
#

my notes on this lab have me being shocked at how quickly the lab is over, that med lab is 80% just thorough enumeration

hardy anchor
#

Lab completed πŸ‘πŸΌ

thorn urchin
#

nice

woeful mural
#

Anyone completed ACTIVE DIRECTORY ENUMERATION & ATTACKS ? Miscellaneous Misconfigurations I am having an issue with uestion 2.

craggy elm
#

hey guys, is there someone who wants to have a look on a simple sqlmap command?

tranquil urchin
#

I probably have the dumbest question ever to be asked here, but I am stuck at Password Attacks module, section Attacking SAM, first question: Where is the SAM database located in the Windows registry? (Format: **). I'm stuck for like an hour, someone please put me out of my misery...

thorn urchin
tranquil urchin
#

..

#

I got it...

craggy elm
#

Nice πŸ™‚

tranquil urchin
craggy elm
#

I am stucked in the sql-injection module. I found some json-data to test with sqlmap, but however I draft the command (using -r flag or --data flag), the output after a long long runtime tells me, the POST parameter JSON does not seem to be injectable. Am I missing something really obvious here...?

thorn urchin
#

I havnt done that module yet, but sounds like the json parameters arent injectable with sqlmap. Have you manually verified that it is indeed the route?

craggy elm
#

yes, I did.
I guess in this case I do have to work with json, because the previous description of the module also dealt with json-injections

#

I got it πŸ˜„

edgy ridge
#

hi everybody, i'm stuck in File Upload Attack module on Limited File Uploads , on question 1 : "The above exercise contains an upload functionality that should be secure against arbitrary file uploads. Try to exploit it using one of the attacks shown in this section to read "/flag.txt"" .... i've tryed all payload but the app don't display anything .... any help??

waxen current
#

Hello, I am doing the windows fundamental module. Could someone guide me on how to get the machine's build number and Os after having access

wide path
#

In the module they talk about this command:

wmic os list brief
cyan oar
#

ls

waxen current
rustic sage
#

Hey guys

#

Is it normal I'm locked from sending messages on most other threads?

#

I was wondering how I gain points with hackthebox. I did the first beginner module called meow.

thorn urchin
#

modules refer to academy modules, not individual boxes

thorn urchin
low mica
#

can someone help me

solar zodiac
#

hi everyone! I was curious if anyone knew if MSSQL saved windows users passwords. I kinda went under the hood of SQLMap, and in queries.xml, tried to see how it requests usernames/password hashes for sqlserver. None of the queries returned the name I logged in with! the only username that showed up that I recognized was sa

dense vine
#

Hi, idk that so thx for info

warm shell
#

Hi everyone.

#

I am a newb and can't figure out a couple of things. Anyone feel like helping?

solar zodiac
#

nevermind just found a great article. apparently windows authentication doesnt store the password in SQL server

tidal mango
#

I have a question with Windows and OpenVPN. When I use any Windows machine (VM) with openVPN and download the academy-regular.ovpn file and use it to connect to the training environment, the VPN constantly disconnects and reconnects making for a very painful experience. I have tried with a VM on ProxMox as well as a local KVM on my Linux machine. Using Linux or any Linux VM I can connect without issues. Does anyone else experience this or have an idea on how to solve the issue? I appreciate any help!

tidal mango
warm shell
#

In Linux Fundamentals Page 5 / System Information. I can't seem to figure out What is the path to the htb-student's mail and Which shell is specified for the htb-student user.

#

Almost certain it's bash but it says no. After digging through all of the directories I don't see any about mail. IDK

#

Feeling real dumb. LOL

tidal mango
warm shell
#

Thank you very much CrazyHorse! I'm out of workstation time for today but that gives me a direction to go in tomorrow when I get back on. I appreciate your help very much!

opaque badger
#

I’m working on the skills assessment for SQL Injections Fundamentals and I am trying to write a file to the web root β€œvar/www/html” through a union injection but I keep getting β€œErrcode: 13 Permissions denied”. I am the root used so I don’t why this is happening any hints or tips would be greatly appreciated!

kind turret
tidal mango
thorn urchin
opaque badger
tidal mango
tidal mango
slim plover
#

Can someone please help me with ACTIVE DIRECTORY ENUMERATION & ATTACKS > ACL Enumeration's last question What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word). I found two using bloodhound but neither of them are being accepted as answer.

pliant sage
#

Hi, I'm doing the passwords attack easy lab, I've tried bruteforcing ssh with hydra but it doesn't get me anywhere. Nmap shows there are very few services I can try to attack on the machine so I'm kind of puzzled. Am I correct in trying a bruteforce attack? Or am I missing something?

gloomy tangle
#

hey! me too. it detects it as a infected dll.

slim plover
#

could you try again by adding the dll folder as exception in windows defender?

#

although disabling defender worked just fine for me

gloomy tangle
woeful mural
#

@slim plover I eventually found it. Took me a while an i had to go through it a few times but finally got it with powershell and following the lesson.

slim plover
woeful mural
#

It takes a few minutes. Send me a DM

loud sapphire
#

Hello,

woeful mural
#

@thorn urchin Thanks. I found the other user.

loud sapphire
#

Wondering if someone can help. I cant seem to copy NTDS.dit to my local linux system... keeps erroring with
C:> cmd.exe /c move C:\Users\jmarston\Desktop\NTDS.dit \10.10.14.xxx\CompData
cmd.exe : The specified server cannot perform the requested operation.
+ CategoryInfo : NotSpecified: (The specified s...sted operation.:String) [], RemoteException
+ FullyQualifiedErrorId : NativeCommandError

#

(one of the backslashes has been omitted in my message on here. so it aint that)

placid quest
#

@loud sapphire use cme

loud sapphire
placid quest
#

@loud sapphire if u are using evil-winrm use download option

loud sapphire
#

i can indeed try other things. thank you for the suggestions. But at this time, i need to know why the intended solution isnt working.

I am supposed to create a share on my local system using smbshare.py. This is operational and receives communications from the DC. It just errors out on the winrm side.

any suggestions as to why its not working would help.

placid quest
#

@loud sapphire switch to cmd.exe or change the share

loud sapphire
#

change the share in what way?

placid quest
#

@loud sapphire from compdata to another name

pliant sage
#

so nobody has a hint about where to start for the pwd attacks easy lab? 😒

loud sapphire
#

i havent got that far yet. sorry dude.

stiff tapir
#

In the Information security foundations path, setting up is above linux fundamentals, but linux fundamentals is pre-requisite for setting up. What should I do first?

carmine quail
#

I’d go with Linux fundamentalists

#

Fundamentals… autocorrect… ugh

fierce sparrow
#

can anyone help me with ACTIVE DIRECTORY ENUMERATION & ATTACKS living off the land? I can't seem to find the disabled user

slim plover
fierce sparrow
thorn urchin
#

@gloomy tangle @slim plover why yall responding to a question I made two weeks ago lol its all taken care of now.

polar widget
#

Its crazy and awesome at the same time, seeing modules improvement over time in #858470491676737536

#

Content remains best and fresh

solar granite
#

I definitely agree with the sentiment. It's cool to see improvements over time

unreal patio
#

I managed to log into the password attack labs - easy

#

But I'm a bit clueless as to how to priv esc

pliant sage
unreal patio
#

Sure

iron basin
#

Any help on Footprinting Lab - Easy? I was able to ssh in with the given account after getting what I needed on the ftp server. However, I am not sure how I should escalate to root. Any hints be appreciated.

lethal atlas
iron basin
#

I am dumb ._.

opaque rampart
#

I don't suppose there's a kind soul willing to help me find the name of the hidden 'history' file in the htb-user's home directory, is there? I've been struggling all day with the fundamentals course asking me to perform tasks which seemingly aren't covered in the content before the question.

lethal atlas
#

hidden files usually begin with .

#

to see them you can use ls -la

opaque rampart
#

Ahh, ty, I had been typing 'ls' and 'ls -a' in the home directory to no avail! It is extremely confusing how I'm supposed to find the solution by myself when it's not discussed in the material leading up to the questions at the end of the section. Am I missing something??

solar granite
opaque rampart
#

i was 'htb-student@nixfund:~$' '~' is his home right? not root home?

fallen osprey
#

Shell & Payloads:Reverse Shells: is it the IP Address on my Pwnbox/Workstation I set as TCPCLIENT adress in the codesnippit ?

lethal atlas
solar granite
#

Adding onto that, you are logged in as htb-student, and ~ stands for /home/htb-student in this case. You should change your directory to the home dir of the other user (likely /home/htb-user) and then try to view the hidden file

lethal atlas
opaque rampart
#

When i typed "cd /home/htb-user" I got the error message, "-bash: cd: /home/htb-user/: No such file or directory" I think they were referring to the htb-student as the htb user but idk?

opaque rampart
opaque rampart
# solar granite I'll dm you

Ty, sorry not trying to fill up the chat but I am SO lost it's not even amusing after 8 straight hours of headache!

lethal atlas
#

googling the answers and googling how to use a tool are different. You have to learn how they work really well to fully utilize them in a RW situation. I have been at this for over a year now and am still learning

thorn urchin
#

learning how to find the relevant information and getting comfortable with that will serve you far more in the long run than any module content

fallen osprey
#

Shell & Payloads:Reverse Shells: when I in Powerhsell try to setup a reverse shell I get a very long errormessage from Powershell I have no clue about:

unique valve
fallen osprey
unique valve
spark monolith
#

hello im new to HTB and wanted to start off with - getting started in cracking into HTB - any tips on if that's a good module to start in or would should do something else to get familiar with HTB

cursive plover
#

@cursive plover

unique valve
spark monolith
#

i have an idea of these ,yes. very basic linux command , less on windows and some understanding of networking without having to look at notes if that makes sense

unique valve
spark monolith
#

if i get stuck while doing this is there videos i can follow or any recommendations you have when getting stuck and or just clueless after readying the whole section

unique valve
#

I recommend. If you are stuck take some time to consider what you are trying to accomplish, review the section reading (read it multiple times), ask for help here in the Discord, rely on video walkthroughs as a last resort. Im sure others in here have some good advice too

spark monolith
#

thank you , i would appreciate all the advice i can get

low vine
#

Hey guys working on Footprinting - DNS
Question #2 identifying if its possible to perform a zone transfer. I've read through the zone transfer notes in the section and something isnt quite clicking. Anyone mind breaking it down a little bit for me?

I'm looking at its explanation on Dig-AXFR Zone transfer and it mentions that if "allow-transfer" option is set to any everyone can query the entire zone file.

I feel like this is gonna be real obvious but I'm not quite understanding it and need a slight ELI5 if possible.

#

i've used ||dig axfr inlanefreight.htb @<IP>|| and I see the information but I guess I dont quite understand how to use this information to determine yes/no on it.

thorn urchin
#

do you get a list of domains or do you get a denied message?

low vine
#

I get a list of domains

thorn urchin
#

then congrats its allowed

pastel ginkgo
#

Ok I am mad confused, Im doing the Attacking Common Services (SMB) module and I stumbled on the user jason password while working on the previous section for ftp. Now that password apparently was correct as I was able to provide it as an answer. But when I try to use it to connect to the SMB server it wont log me in.

thorn urchin
#

it never says to login via smb as jason

pastel ginkgo
#

I cant download the private key as anon though πŸ€”

hardy anchor
#

Hey! I'm having problems to find the linked server on attacking common services - hard lab. I found ||fiona, simon, john, patric and julio ||creds. Also I log via ||rdp with fiona|| creds. I think that's the correct way to found the linked server. Could someone give me a hint please?

thorn urchin
#

read what the question wants you yo do again

thorn urchin
hardy anchor
low vine
#

Still stuck on Footprinting - DNS #2
We have confirmed that zone transfer is possible, I'm not understanding how I would go about reading a txt file that is shown.

lethal atlas
thorn urchin
rustic sage
#

Hi all, got a question on Password Attacks module, Pass the Ticket section: How can I get NTLM hashes with Rubeus? Similar to mimikatz "sekurlsa::logonpasswords"

pastel ginkgo
# thorn urchin read what the question wants you yo do again

Ok i'm at a total loss, || I know that the 2 users on the client are jason and robin neither passwords mentioned in the hint work for smb. I've tried setting up responder but its radio silence. idk what else to do, i've tried everything they've mentioned on the page. ||

thorn urchin
pastel ginkgo
#

login via ssh?

thorn urchin
#

πŸ™‚

pastel ginkgo
#

I can't it wants a private key

thorn urchin
#

hmm maybe my memory is playing with me then

pastel ginkgo
#

frankly im confused how'd you'd get his password at all if I hadn't stumbled on it while working the ftp page.

thorn urchin
#

im at work right now, give me a little bit and ill fire up the instance again and see what my memory has forgotten

#

cause idr a pub key being needed

hardy anchor
thorn urchin
#

try diff users

hardy anchor
# thorn urchin try diff users

I'm using this query ||EXECUTE('select @@servername, @@version, CHANGE_USER, is_srvrolemember(''sysadmin'')') AT [LOCAL.TEST.LINKED.SRV]||

thorn urchin
#

idr off the top of my head if that looks sane or not

hardy anchor
#

idr?

thorn urchin
#

i dont remember

hardy anchor
#

Oh got it

#

No problem. Thank you

low vine
# thorn urchin not txt *file* a txt *field*

Yea idk I have to just be missing the worlds most obvious thing but it doesnt add up to me....
I've confirmed that I can perform a zone transfer for inlanefreight.htb but I'm apparently doing it wrong as i've submitted the 3 TXT records shown (none of which are HTB(FLAG)) format

#

So i must not actually be confirming yes/no on the zone transfer with what I'm trying

thorn urchin
# low vine Yea idk I have to just be missing the worlds most obvious thing but it doesnt ad...

if youre getting domains then that means youve got the axfr, the confirming yes/no has nothing to do with your end.

Idr if its for that one, but at least one of the dns related sections required you to do multiple dns zone transfers with different zones.

so the first zone transfer may have given you a list of domains and some of those could actually be its own zone as well that you need to attempt a transfer on.

placid quest
#

@hardy anchor you need to enable xp_cmdshell to execute commands

low vine
#

Yea idk ive read through this so many times

#

like what the fuck could i be missing lol

#

Getting connection refused / host unreachable for everything

#

😦

placid quest
#

@low vine vpn problem

pastel ginkgo
# thorn urchin cause idr a pub key being needed

|| I found a way to get the private key using smbmap and providing the password I had. That being said I have no idea what the intended way is to get the password. As I wasn't able to bruteforce it at all, if I hadn't found it while brute forcing ftp in the previous section I would still be stuck. Would love to know what the correct route was. ||

low vine
#

@placid quest im tilted now....fuck me

#

LOL

thorn urchin
placid quest
#

@low vine maybe download vpn and connect again

hardy anchor
thorn urchin
placid quest
#

@hardy anchor dm me

thorn urchin
low vine
#

@thorn urchin Ty for the help and all the help you're giving here.

pastel ginkgo
low vine
#

also my own stupidity made me waste way to long on that lol. Glad someone pointed out VPN ><

thorn urchin
thorn urchin
#

time could also be up if you've been at it for awhile and need to reset the target

rustic sage
#

Am experiencing the same issue now, connected to vfrank and nada, tried to restart, tried to connect the drive from mlefay and reconnect. Interesting think that it logged me in as Other user and someting vfrank ...thank you

low vine
thorn urchin
#

nice

rustic sage
#

may I pm anyone regarding the pivoting module?

tepid thicket
#

options

thorn urchin
#

@pastel ginkgo okay just quickly redid that page, its pretty straightforward actually. ||you use the hint for the jason question to get the pw list from the resources section, use that to brute jason to get the pw, then use the pw to login to the GGJ share, and download the id_rsa key||

pastel ginkgo
vital adder
#

wait they update that section?

vital adder
thorn urchin
pastel ginkgo
#

yeah thats what I was trying and it returned auth failure

#

i'll just chock it up to my vm acting up

vital adder
elfin moth
#

heloo

#

alguem brasileiro aqui?

vital adder
#

try ||auxiliary/admin/smb/ms17_010_command|| with the command "dir C:\Users\administrator\Desktop"

rustic sage
#

WEB ATTACKS Page 8 Mass IDOR Enumeration: can some one help me out im having issue with grep in this section.

#

or the curl command rather...

#

i ran curl -s http://SERVER_IP:PORT/documents.php?uid=1 | grep <li class="pure-tree_link"> and got nothing back. I've tried several variations of this but i get nothing back. can someone explain what I'm doing wrong?

granite radish
#

Tf

#

Y'all on some shitty type crosh type shit?

rustic sage
#

huh?

tidal mango
granite radish
#

Dawg, I'm saying tf is y'all tryna damn hack?

mellow turtle
#

?

rustic sage
#

silent tag

tidal mango
rustic sage
#

im tracking

#

sry brain fart

tidal mango
granite radish
#

Tracking what? Fuckin' gollum?

rustic sage
thorn urchin
#

@granite radish you lost bro

granite radish
#

Then were is the better hackers at?

thorn urchin
#

try twitter

granite radish
thorn urchin
#

anyways if youre not here to discuss the academy modules kindly fuck off

thorn urchin
#

hey @spring tundra can you please get this clown outta here. Thanks

wise nimbus
mellow turtle
#

:/

thorn urchin
#

<@&861185840277487616> okay can somebody get rid of this clown then

spring tundra
#

Im here

thorn urchin
#

πŸ‘ thanks

rustic sage
#

Vick is being a Mc DICK

wise nimbus
#

OMEGALUL Solid name.

mellow turtle
#

@thorn urchin where are u from?

thorn urchin
#

Im from thischannelisabouttheacademy

opaque badger
mellow turtle
#

😦

thorn urchin
tidal mango
vital adder
mellow turtle
#

or try to \ "

vital adder
#

yea that too but i do have some issue with bash and multiple "

vital adder
rustic sage
vital adder
#

oh so the uid parameter is in the right place? i really need to update my note on this module

rustic sage
thorn urchin
#

@spring tundra round 2

granite radish
#

πŸ˜‚πŸ˜‚

vital adder
#

about to ping 0xjb

tidal mango
vital adder
spring tundra
#

Sorted πŸ‘

thorn urchin
#

thanks again

vital adder
#

nice thanks

thorn urchin
#

wont be shocked if round 3 on an alt though

rustic sage
#

its pretty exciting though...

#

this is the most active ive seen this server in a bit

thorn urchin
#

idk I always wake up to a billion messages cause the euros come out when Im asleep

rustic sage
#

maybe i just need to login more..

thorn urchin
#

login to these academy modules haha gottem

rustic sage
#

lol

thorn urchin
#

I have a dumb question about AD that I think I already know the answer to. But in the active directory attacks and enumeration module, it has sections about attacking a parent domain from a child domain.

I presume the reason why theres no section about parent to child is either cause if you started in the parent domain and comprmised it you already have perms to affect the child domain or is it the attacks work perfectly fine both ways its just phrased from the child to parent perspective?

snow mirage
#

I'm having a problem in the Active Directory Enumeration & Attacks module. I keep getting this response when I'm trying to enumerate the IP stating none of the hosts are online and so I have no active host to target:

#

i've reset the box, I've reset and redownloaded the vpn. I have tried this one two PCs, I have 0 idea whats causing this

wheat garden
#

maybe theyre up but not accpeting ping request?

#

havent done that module but pretty common for firewalls or hosts to block ping requests

snow mirage
#

waiting for my nmap scan to finish

#

somethings wrong ;/

snow mirage
#

OHH nvm im dumb. I haven't been doing it inside of the ssh'd network

wise nimbus
#

127.0.0.1

wheat garden
#

πŸ˜†

wheat garden
#

this is expert social engineering just ask um for their I.P brilliant!!

fresh reef
#

Stuck on the Footprinting Med Lab like a noob @.@, ive reached the remost host(WINMEDIUM), ive scoured the user's filesystem and registry, currently... I need direction, ssms is a no go for me , i have both sa/alex's creds...maybe another set of creads from the regs but im not sure

fresh reef
wheat garden
fresh reef
#

i have thats where i've been stuck

wheat garden
#

then you need to access a sql database on the machine using the sql server manager program

fresh reef
#

yes there exactly is my issue, non of the creds i have are applicable

#

al,sa, maybe an htb set

wheat garden
#

ya you need to run the program as administrator using "sa" creds

fresh reef
#

i feel like im missing some keey part

#

ok ill try that out

#

thankyou πŸ™‚

wheat garden
fresh reef
#

can i dm you?

wheat garden
wheat garden
indigo furnace
#

:emoji_108:

#

πŸ–₯️

marble raft
#

Idk if im being dense but in the Enumerating & Retrieving Password Policies section of AD Enumeration and Attacks it says:

"We can also obtain the password policy. We can see that the password policy is relatively weak, allowing a minimum password of 7 characters."

Yet the code output shows min_password_length: 8

marble raft
#

Yea i thought of asking here first because i may be wrong, since one of the questions ask this very same thing and the answer isn't 8.

charred heath
turbid lily
#

Hi, I'm currently trapped in "Network Enumeration with Nmap" - Medium Lab. The question is: After the configurations are transferred to the system, our client wants to know if it is possible to find out our target's DNS server version. Submit the DNS server version of the target as the answer.

Could anyone help me? I've tried --source-ports and some NSE scripts, but still does not show the DNS version. Help would be really appreciated

turbid lily
thorn urchin
#

you tried going slower

turbid lily
#

yup, even with -T0

thorn urchin
#

without templates

feral stump
#

Or try maybe connecting with ||nc to port 80 using also source-port and capture the traffic on another tab with tcpdump||

thorn urchin
#

double checked, dont need to go slow or use tcpdump

#

you sure youre scanning the right port πŸ˜‰

turbid lily
#

There are 2 filtered ports from the whole sample of ports. Yup, tried with both. Port 53 opens if I use UDP instead of TCP, and source-port 53 as well. I can read the version of that one, but that's not the answer. So it must be the another one that I've been tracking but nothing. I could send you a DM if you want more specifications as well πŸ˜„

thorn urchin
#

youre probably copying the answer wrong

#

the format is HTB{stuff}

feral stump
#

Yeah if it’s a HTB{} version then you are not copying it right … otherwise since it appears at one time a version that is not HTB{} format then there is something you are missing

thorn urchin
#

I also figured out the manual way grab the banner without nmap at all. A little silly but kinda fun.

turbid lily
#

It's supposed to use ncat -nv to get it, in theory

feral stump
thorn urchin
#

that sounds painful

#

my manual way used dig

#

but just good ole nmap is fine

#

anyways like I said, youve already done the correct thing from what youve said, likely just copied the answer wrong. my visions going blurry so im just gunna go to bed. good luck

low vine
#

Need slight help on Footprinting - SMTP Last question

feral stump
#

The one with the email?

#

Can’t remember exactly

low vine
#

Yea sorry was looking back over it but I'm currently using smtp-user-enum -M < > -U <LIST> -t <IP> -w <longer timeout>

#

and i've not been able to get any sort of confirmed user

#

Unsure of where I might be fucking up or how I can confirm if I'm doing the process wrong etc

feral stump
#

Hold on let me check my notes quickly

#

But you need to connect to the server for sure

#

And then use IMAP commands

low vine
#

wtf are IMAP commands

#

lol

#

So i've used telnet to connect previously

feral stump
#

In the module it explains

low vine
#

oh thats the next section I'm right before IMAP

#

I'm on SMTP

vital adder
#

@low vine if you can get smtp-user-enum to work for this pls shoot me a dm with how you do it but i did noted down i can't get smtp-user-enum so i use ||auxiliary/scanner/smtp/smtp_enum|| in metasploit for that

low vine
#

Yea I had seen mention of using that was trying to figure out how to do it without 😦

feral stump
#

Sorry I confused that one

low vine
#

WAIT

#

IM SO DUMB

#

I GOT IT AND DIDNT REALIZZE LOL

feral stump
#

Can you type your command in a spoiler form pls?

low vine
#

||smtp-user-enum -M VRFY -U footprinting-wordlist.txt -t <IP> -w 15||

feral stump
#

Yup that’s the one that worked for me

low vine
#

I didnt see a spit out so I just didnt realize i had it and thought I had done something wrong

feral stump
#

With ||-w 40 || through

vital adder
#

jesus christ so the tool was going to fast?

feral stump
#

Haha

low vine
#

I wonder if there is a better way to walk through this process

#

That took me way to long to figure out ><

feral stump
#

Maybe if you use some nmap script you can get it directly

#

Haven’t tried though

vital adder
feral stump
#

But you could start using vuln or check the nse files and search for smtp

low vine
#

I tried nmap script and didnt get it to work right 😦

#

Bleh its definitely a process. Many more hours of pounding my head to come

feral stump
#

Anyway as you say it’s a process

low vine
#

Just have to keep learning and growing

pliant sage
#

Hi, could anybody give me a nudge for passwords attacks lab - medium? I think I'm pretty far along but I'm stuck now

#

I've got user d***** but I really don't understand what I'm supposed to do with him

tidal mango
pliant sage
#

can i dm you?

tidal mango
noble aurora
#

Hi, is there anybody I can ask about a question of the Linux privilege escalation module?

#

nvm I misunderstood the question πŸ˜„

buoyant peak
#

how to lsit all the windows partitions using meterpreter?

buoyant peak
#

nvm its show_mount

lapis pivot
#

Hello everyone πŸ€—,,, how to handle GET parameter secure with uid by using sqlmap

#

Should I use --randomize

torn crest
#

hello im new

rapid ember
#

Hello! Anyone can help me with the sqlmap module (Running SQLMap on an HTTP Request) ? I'm stuck at the first exercise: What's the contents of table flag2? (Case #2)

#

but getting only bad requests :(

raven cairn
rapid ember
lapis pivot
rapid ember
lapis pivot
hazy grotto
#

Does anyone else have issues with zap browser and HUD not loading sometimes, freezing?

#

I keep having to shut it down and restart. It's frustrating.

patent kernel
#

wasnt sure where to ask this, and I admit I'm being lazy and not just searching, but what is the policy/rules on doing videos or writeups of any of the acadamy modules? are there ones were its allowed? is it a no for all of them?

naive ravine
#

Hi all I would like a nudge on the LFI skills assessment. Can anyone help out? Thanks

loud sapphire
hazy grotto
loud sapphire
hazy grotto
#

I’ve gotten some things to work but it just fails a lot.

zealous belfry
#

somebody did the password cracking module ? Taking ages for me to crack those passwords

thorn urchin
#

some of them simply do take awhile

#

its probably the most frustrating module for that reason alone

zealous belfry
#

yea...

pastel ginkgo
#

If your stuck on the mutations one the only advice anyone here can give is find some good tv to watch

zealous belfry
#

exactly where im sitting right now πŸ™ƒ

pastel ginkgo
#

lol that one pissed me off I still remember the password for it

zealous belfry
#

i dont get the point in letting someone bruteforce a password for idk been like 30 45 minutes

#

and also why ssh come on ..

pastel ginkgo
#

The one bit of advice i'll give you ||rather than target ssh target other services that reply faster. ||

zealous belfry
#

ya i saw ftp but was like nah cant take that long

#

but gonna try that then ty

zealous belfry
#

jesus finally found it

rustic sage
#

Hey guys

#

im new to HTB

#

should i know any tips befor strating

#

starting

spring tundra
#

good bot

zealous belfry
#

nice try tho

inland coral
# zealous belfry prob a CME issue

ditto... saw the same thing as you and @vital adder...|| cme exhausts list, fails all, msfconsole succeeds w/same list. since lesson touches on cme and not msfconsole||, it might be a nice tweak (erratum) to mention ||msfconsole ||somewhere in the class. Many can search here or know of alternative but some might think cme is fine and try larger/other lists.

zealous belfry
inland coral
zealous belfry
#

πŸ‘ŒπŸΌ

inland coral
zealous belfry
inland coral
#

Thank you both @zealous belfry and @vital adder!! πŸ‘

summer lava
#

Attacking Common Services - Easy
How do i transfer a shell to the web-server ?

sly tapir
pastel ginkgo
#

For the Attacking Common services - Email, do we use their password list? As I didnt get any hits on the user and im now 40k attempts in on rockyou without a hit yet.

summer lava
#

i just uploaded the file but couldn't find it's location on the web

zealous belfry
zealous belfry
pastel ginkgo
zealous belfry
#

oh yea right i remember.. but anyway if you bruteforce it should take more than like 5 minutes. As a tipp || once you find credentials see if you can exploit the latest ftp vuln ||

#

And also dont use rockyou, use the provided resources as a rule of thumb πŸ˜‰

iron basin
#

Any help on the footprinting easy lab? I'm in the root directory but I can't find the flag anywhere on the box .

zealous belfry
pastel ginkgo
zealous belfry
#

I honestly do not remember the lab but check all services most likely you will find something somewhere else thats usefull most of the times

pastel ginkgo
#

Should be in a directory called || flag ||

zealous belfry
#

I only remember that || you can use the ftp vuln to upload a file onto the webserver (e.g reverse shell?) and for that you need basic auth creds||

iron basin
zealous belfry
summer lava
iron basin
summer lava
#

i could only find two accessible web directories but couldn't find any of my uploaded file in them

zealous belfry
#

now the question for you is to find that directory πŸ˜‰

summer lava
#

Thanks, but how can i upload in from ftp to a particular web directory ?

pastel ginkgo
zealous belfry
raven cairn
#

Can I have some help with the attacking common application Skills assesment 1? I have found a vulnerability for the application, but having trouble using it because it requires fuzzing for a .bat file. Don't really know what wordlist I should be using and I would really appreciate some help.

summer lava
shy warren
#

Hey guys, stuck on Linux Pass the Ticket. I was able to import Julio's ccache file and and impersonate him to read files in his remote machine. I can see the flag using smbclient but I'm not sure how to open the file contents. Type command does not work, it seems like I can only list the contents. Any suggestions on how to open the remote file through smbclient?

zealous belfry
raven cairn
summer lava
summer lava
zealous belfry
raven cairn
#

anything for .bat files?

summer lava
#

i'm currently running gobuster using the -x php but havn't find anything yer

zealous belfry
zealous belfry
zealous belfry
#

πŸ‘πŸΌ

vital adder
shy warren
# vital adder use more or get

For some reason whenever I used get <file name> no data was transferred. Of course when I reset the box and started over it worked fine. Thanks πŸ™

low vine
#

Working on POP3/IMAPS module I got the Last answer, but really strugling with What is the customized version of the POP3 server?

#

I can login and am given a version but that seems to not be it

#

I'm not understanding how I would figure out the customized version 😦

#

Would love a small hint

outer mountain
#

Hi

vital adder
#

are you in the Footprinting module IMAP / POP3 section? if so then hint use ||nmap||

outer mountain
#

I am new here

west canopy
#

Hello friends

outer mountain
#

Hi

low vine
vital adder
#

shoot me a dm i'll help you with that

dense vine
#

Hi guys, i have a stupid problem. Getting Started/Public Exploits on HTB Academy and don't know how to read that backup database, i use metasploit but where i can read what is on this backup

vital adder
pine dagger
#

Does anyone have a suggestion on how to pivot onto MS01 in AD Enumeration & Attacks - Skills Assessment Part I? I think I'm missing something obvious. ||I've tried pivoting with metasploit. But when I tried reverse proxying through the web server, the meterpreter session just fails. When I try to run two meterpreter sessions (so I can netcat), the 2nd session dies as its established.||

loud pagoda
#

Hey, I am in the last section of the Using Web Proxies module. I run zap and find that there is a csp vuln, after reading about it I am not finding a way to get an XSS through. Any tips on this one?

vital adder
#

hi @languid dawn sorry for the ping but can you dealt with this? i don't want to use the SERIOUS RULE BREAK thing just for spam like this

vital adder
loud pagoda
tulip coral
#

confession.. i have been on the nmap module hard lab for 6 hours.. do i have a baby brain ?

loud pagoda
#

Is called ZAP Scanner before the skills assessment.

vital adder
loud pagoda
#

Yes that one, well the prompt is "Run ZAP Scanner on the target above to identify directories and potential vulnerabilities. Once you find the high-level vulnerability, try to use it to read the flag at '/flag.txt"

#

I ran the ZAP scanner report and the only high ranked vuln is a CSP

tulip coral
#

@vital adder LUL the truth hurts

loud pagoda
#

for Content Secuirty Policy missing.

vital adder
#

the first time i do that section zap didn't find the vuln i end up have to find and exploit manually now for me zap still only find that vuln like half of the time for me

loud pagoda
#

Well, I have a hunch. There is a comment section where there is a link to a ping function

#

I tried putting js alert in there but is not rendering shit

vital adder
vital adder
#

but it have nothing to do with ||java||

loud pagoda
#

Is this a path traversal vuln?

#

I was able to get to a devtools path with a ping php file

vital adder
vital adder
#

shoot me a dm with the zap scan output of that directory i don't have that save but i think zap will did show which vuln it is