#modules

1 messages Β· Page 20 of 1

loud pagoda
#

I have it on a VM can't copy paste to discord

#

I may just need to get some rest and try tomorrow with a fresh brain.

vital adder
#

sure np and you can just take a screenshot of that

loud pagoda
#

Yeah brother, I had shut the kali VM off

#

Thanks man

vital adder
#

np see you when you don't have brain damage

loud pagoda
#

I'm afraid that won't ever change but will see you around

tulip coral
#

lol

pliant sage
#

Hi, could anyone help me with something for the password attack lab -hard please?

pliant sage
hidden trellis
#

can someone please help with Attacking Common Applications, Application Discovery & Enumeration... aquatone is not working, either timing out or not taking screenshots

rustic sage
#

dm me if u wanna learn how to hack

hidden trellis
vital adder
#

did you do that in the pwnbox or your vm? because it's going to hell with all of that in kali

#

all you need is wget https://dl.google.com/linux/direct/google-chrome-stable_current_amd64.deb;sudo dpkg -i google-chrome-stable_current_amd64.deb

hidden trellis
#

in own kali vm

vital adder
#

it's going to be hell but it should still work

#

so after you run ||cat web_discovery.xml | ./aquatone -nmap|| like in the example show what did you get?

#

also shoot me a dm i'll help you troubleshoot

pliant sage
#

Hi again, I'm trying to download a file using evil win-rm, it says the file was downloaded successfully but when I check the directory it's supposed to be in it's nowhere to be found. Has anybody encountered this problem before?

outer mountain
#

Yooo

#

Imma newbiw

#

Can yall tell me from where do i start learning to do ethical hacking?

vital adder
vital adder
pliant sage
thorn urchin
#

its a common problem with winrm

#

gotta use full path names

pliant sage
#

i did

thorn urchin
#

I think both source and destination

vital adder
pliant sage
#

download c:/whatever/Logins.kbdx /home/whatever

#

didn't work

#

i disconnected and reconnected many times already

vital adder
#

yep it isn't really a "fix"

#

also try updog

pliant sage
#

I'm really not gonna fall for it man

thorn urchin
#

πŸ˜‰

pliant sage
#

loool

vital adder
#

about to send that

pliant sage
#

mb was genuinely thinking you where tryin to prank me

pliant sage
vital adder
#

nope

#

you can just use a browser or curl

#

but i for the command for curl and i don't thing i did save that command but for powershell

rustic sage
#

Yes bro

outer mountain
pliant sage
#

feels like the host can't connect to anything through internet

#

nvm

thin kettle
#

Anyone managed to complete the nmap module - firewall evasion hard part?

pliant sage
#

@vital adder is it normal I can't open the .img files with 7z?

vital adder
#

i have no idea about that

north ermine
#

Hi ! Can someone help me on the Login Brute Forcing - 2nd skill assessment ?

i Created a user list, created a password list with name and surname, numbers, special characters and leet.

Then used the sed commands provided in the module. But after 7 attempts in 3 days, I still have no hits.

charred heath
#

hi

unreal patio
#

Can someone give me a pointer on Password Attacks Medium skill assessment? I got both ssh users but I'm stuck on priv esc

vital adder
north ermine
#

Yeah just resolved it ...

vital adder
#

congratz

north ermine
#

God I am so mad

vital adder
#

yea me too after reading all of that

unreal patio
#

Nani

vital adder
#

yamete kudasai

#

wait i think i copy the wrong thing

unreal patio
#

I checked for ssh keys but found nothing

vital adder
#

shoot me a dm with your user just to double check wait nope i misunderstand my own note you should have found ||all of the user|| but if there is no ||ssh keys|| then i think you should restart the target machine

unreal patio
#

I'm currently exhausting the wordlists on the hash

vital adder
#

if you got the right ||key|| hash it should take like 2 sec (it did for me on the pwnbox)

pliant sage
#

Hi it's me again. I'm still on the password attacks lab - hard. I found the .iso files but I can't for the life of me read them. Most of what I see online says to use 7z but it just doesn't do anything when I try to use it. I've also tried mounting it but that fail as well, telling me something about bitlocker (i did try to run the file through bitlocker2john but that produces nothing)

#

Am I doing smth wrong?

tulip coral
#

ok let me get back on these modules..... lord giv me strength

vital adder
#

there should be only a .vhd file

pliant sage
#

.img sorry

vital adder
#

still no

pliant sage
#

yeah but when i unpack it there are .img files in it no?

vital adder
#

wait they did update the module not sure if they update this last bit or not

pliant sage
#

well I ran the .vhd file through 7z and I found 2 .img files in it

vital adder
#

wait how?

#

that is a F ing ||partition|| how tf did you ran 7z on that?

pliant sage
#

whatchu mean?

vital adder
#

shoot me a dm

undone cypress
#

Hello everyone
One step away from the flag)
module - AD Enumeration & Attacks
Skills Assessment # I
With the help of ||mimikatz, I pulled out the administrator's ntlm hash||, cracked his password, but I can't connect to ||DC01 via PsExec||
Is writing:

Access is denied.
I tried using ||Invoke-Winexec||, but I didn't quite understand what commands you can pull out the flag.
(give a hint please))
And then I doubt that I pulled out the hash of the domain administrator I need)

#

maybe you used other tools to get to the flag when you had the administrator's hash and the password itself in plain text on your hands?πŸ€”

pastel ginkgo
#

So im connecting to an ftp server, but anytime I issue commands it enters extended passive mode. What can I do from here?

#

Hmm wget was able to get the files but can anyone explain what Extended Passive mode from ftp is? Google just left me more confused

tulip coral
#

Just completed Nmap Hard lab... what a humbling experience

pastel ginkgo
#

Could use a hint, Im on Attacking Common Services - Easy, and im in the sql database but I don't know how to escape and escalate from here.

placid quest
#

@pastel ginkgo upload file

pastel ginkgo
#

Tried that I dont think im doing it right

undone cypress
pastel ginkgo
placid quest
#

@pastel ginkgo use mysql to upload the file

pastel ginkgo
placid quest
#

@pastel ginkgo add another /

pastel ginkgo
#

|| I tried putting it into the dashboard directory, but when I try and launch it from my browser it fails ||

placid quest
#

@pastel ginkgo did u try with ?c=

pastel ginkgo
placid quest
#

@pastel ginkgo u need to get a reverse shell using powershell

rustic sage
#

hello

pastel ginkgo
shy warren
#

Hey guys, stuck on Password Attacks - Lab Easy. I understand we are suppose to brute force FTP. Based on the hints I've seen on here, the included password.list should be all you need to crack the credentials correct? I'm using hydra with the uname list and passlist provided in resources. Increased my threads to 48 and still am not getting results. Any suggestions?

pastel ginkgo
#

According to my notes it took me 15 mins to crack it at 64 threads

shy warren
deft plank
#

I'm having trouble connecting to HTB academy VPN, when i run sudo openvpn academy-regular.ovpn i get this error

#

2022-11-12 20:32:09 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2022-11-12 20:32:09 DEPRECATED OPTION: --cipher set to 'AES-128-CBC' but missing in --data-ciphers (AES-256-GCM:AES-128-GCM). Future OpenVPN version will ignore --cipher for cipher negotiations. Add 'AES-128-CBC' to --data-ciphers or change --cipher 'AES-128-CBC' to --data-ciphers-fallback 'AES-128-CBC' to silence this warning.
2022-11-12 20:32:09 OpenVPN 2.5.7 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Jul 5 2022
2022-11-12 20:32:09 library versions: OpenSSL 3.0.5 5 Jul 2022, LZO 2.10
2022-11-12 20:32:09 OpenSSL: error:0A00018E:SSL routines::ca md too weak
2022-11-12 20:32:09 Cannot load inline certificate file
2022-11-12 20:32:09 Exiting due to fatal error

rustic sage
#

hey i would like to build like a team with people that are really new to this domain so we can grind together

loud pagoda
#

I am working on the web proxies zap scanner module. I am unable to find the vulnerability. All I am getting on the scanner is CSP and CSRF vulns.

#

Anyone here has experience with this module?

next remnant
#

πŸ‘

rustic sage
#

Hello! I'm doing (mostly not πŸ˜• ) Footprinting lab hard. I did the enumeration and found the port for snmp. I did the footprinting with onesixtyone tool (with snmp.txt from seclist) and found 3220 communities. What should I do further? I read some of the hard lab related messages from here, but I'm still trying to figure it out. Thanks for any advice/suggestions!

shy warren
#

Hey guys, for password attacks -medium lab, do we use the included resources pass.list and user.list to brute force ssh? I managed to get into an smb share and cracked a pass protected file and was able to discover a password. I've tried using that password with crackmap to bruteforce both smb and ssh with no success. Any pointers?

pastel ginkgo
snow mirage
#

Hey guys for the Internal Password Spraying - from Linux, I had a problem where I could not get the username that started with "s" to show up in my 1 liner bash, and kerbrute had a problem checking jsmith.txt I completed the question but only by looking at the given name in the section which just happened to be the answer

#

the only one that got resolved from bash 1 liner

#

kerbrute failing

shy warren
#

i didnt see a user, i was able to open the file but it was all encrypted. So when I ran that through John, I only found a password @pastel ginkgo . Must be missing something simple, I'll go back and retrace steps

snow mirage
#

anybody got any ideas??? is it a problem with the vm or??? I just dunno if im doing something wrong. interestingly enough when I tried a crackmapexec, I also only got tjohnson

#

I just created a file that contained the correct user and passed it against kerbrute with the same above syntax but it found the user this time, I also checked jsmith.txt to confirm that the user in question IS in the file but alas.....it errors when I try to use jsmith in kerbrute

placid quest
#

@rustic sage try to enumerate using braa

rustic sage
placid quest
#

@rustic sage try to login mail server

rustic sage
placid quest
#

@rustic sage no problem

thorn urchin
#

docx files dont have users πŸ™‚

shy warren
thorn urchin
#

use the password to decrypt the docx file

shy warren
rustic sage
placid quest
#

@rustic sage find useful files

rustic sage
placid quest
#

@rustic sage use ls -la

rustic sage
#

@placid quest I am. And there are a lot of files. Not all of them accessible or useful. Still looking...

placid quest
#

@rustic sage would u dm me with screen shot

raven cairn
#

I don't know what wordlist you mean by this

vital adder
#

i can dm you? this is a a bit too much spoiler

pearl island
#

Hello all, working on the "Active Directory Enumeration & Attacks" module. I keep getting this error when trying the DCSync attack using mimikatz

pine dagger
shy warren
#

Hey guys, stuck on Password attacks - medium lab. How you do you about finding the mysql credentials once you are logged in as J user?

pearl island
tidal mango
pine dagger
shy warren
pearl island
pine dagger
pine dagger
#

I'll have to go back and try after I finish skill assessment 2

pearl island
#

That would be great! Thank you! πŸ™‚

charred heath
#

hi

vital adder
#

hi guy, so let say i want to write a pentest report for the attacking enterprise networks module what type of report should i write? there is a lot of both AD and web app hacking

calm flax
#

Sorry to disturb you, friends. Let me ask a question: Do we have the course details of Java code auditing here?

vital adder
#

not sure if this is what you are looking for the the academy have 3 module about java here is 2 of them and the last one is the Whitebox Pentesting 101: Command Injection module that will "build upon what you learned in the Secure Coding 101 module"

calm flax
#

πŸ™ Thanks a lot sir . Let me see see .

fallen osprey
#

Shell & Payloads Module: The Live Engagement. I'm stuck on HOST-1: I had tried create a WAR file with a Java reverse shell in Msfvenom and uploaded it to Tomcat but I get a HTTP 500 Error when I try to deploy it for a reverse shell. I had also tried used Msfconsole: Tomcat_mgr_upload exploit but it not work there either. Can anyone give me a Hint? I have no clue after working on this many hours

rustic sage
#

hello! is anyone wishing to help me with the footprinting hard lab?

vital adder
rustic sage
#

@vital adder Thank you for your help!

tight mesa
#

hello everyone

#

anyone who has completed API Attacks to discuss a little bit a logical attack vector under LFI section..!!!

knotty summit
#

hello im blocked please

tight mesa
#

I'm stuck under API Attacks LFI section, I found the download folder but can not find the upload, any clue | hint about this?

sleek urchin
#

hello all, i currently doing Footprinting Lab - Medium, i know what is the initial step is, which is to mount the available share and take the information and move on, but the issue is the permission that is given to the share which is "nobody nogroup" , and i can't cd into ther share

#

since i have to be root when mounting the share, which i have done, can someone help please

placid quest
#

@sleek urchin cd TechSupport

sleek urchin
placid quest
#

Use sudo cd

sleek urchin
placid quest
#

@sleek urchin unmount and try again when u are in root privileges

sleek urchin
placid quest
#

@sleek urchin look for file with big numbers

sleek urchin
placid quest
#

Ok

high totem
#

Hey all, question about Password Attacks module. I'm in Password mutations, trying to do a question at the end and I'm not sure if I got it. I created a mutated passwords list, but when using the custom.rule from the resources, it has >90k entries. Using the hashcat's best64, it has >13k. Should these be so big? Because using the smaller one (best64) to brute force sam's password according to hydra will take 3h on my local computer...

#

3h is more than the time allowed for the instance πŸ˜„

unreal patio
#

@high totem You can use egrep to filter out by 10 chars and so on ^.{10,10}$

jovial halo
#

Hello all ! I'm stuck for few hours on the footprinting module at the last question of the DNS section which ask for the IP of the host ending with .203. If someone could juste give me an hint, would be highly appreciate ! Cheers πŸ™‚

high totem
unreal patio
#

@high totem iirc the password has 11 characters

#

I split the mut_password.list into 8 -> 9 -> 10 -> etc

#

And eventually got a hit

high totem
unreal patio
#

Bruteforcing is a pain in the ass

#

@jovial halo it's a vhost of .dev. try enumerating that with the 'fierce' wordlist

#

@high totem egrep '^.{11,11}$' mut_password.list > mut_password2.list

high totem
unreal patio
#

It beats 90k 😐

knotty summit
#

hi im blocked please

placid quest
#

@knotty summit how

knotty summit
#

@placid quest for a challenge which is name "tree"

#

normally it is very easy but here i don't understand

wraith gazelle
#

Hi everyone

I have a doubt in the footprinting module in dns, actually I tried to change in the etc/bind directory and then nano names.conf.local but it does not let me modify anything :((

I've been at this for two days and I don't understand what I'm doing wrong 😦

thorn urchin
heady hazel
#

I got same annoying issue, in the end, I installed BH 3.0.5 on my Windows machine, and finally I was able to import ILF_BH.zip file!

wraith gazelle
spiral isle
#

Greetings everyone I'm actually a beginner. Can someone coach me through?

lyric dome
#

Hi everyone, I've been stuck on the footprinting easy lab for hours. I've done the DNSENUM with the correct wordlist, but I'm not sure how to proceed

pine dagger
#

Hi there! I'm stuck on #8 of AD Enumeration Skill Assessment 2 - The flag.txt on Administrator desktop on MS01. I've got the passwords for the two user accounts, and the NTLM hash of ||mssql_svc|| account. I've tried a bunch of different things, but no success. Any hints on what to do next?

shy warren
#

Hello all, looking for a hint for password attacks hard lab. I cracked the keypass file and found creds for D user but they do not work for remote logons. So far I’ve found the bitlocker file on D’s smb share and I’ve managed to get the registry hives from the mounted drive, and cracked the hashes. I cracked the admins hash but I’m also unable to logon with it. I was unable to crack D’s hash as well. Any suggestions as what direction to head in? Should I be attempting PtH attack?

pine dagger
pine dagger
lyric dome
#

@inland coral ive mainly been doing dns enumeration, ive found like a ftpserver but i cant connect into it

inland coral
lyric dome
#

I think i am super lost

#

Cause i thought the main direction was to start with dns

pine dagger
#

No

#

Its "start with the basics"

shy warren
inland coral
pine dagger
pine dagger
inland coral
lyric dome
#

ohhh i see i see, thank you guys

inland coral
lyric dome
#

Im really new to htb, so im not sure about all the resources. Are there any like walkthroughs anywhere

pine dagger
#

All the skill assessments for the modules generally work by starting at the basics of the module and working up.

lyric dome
#

or do you find out mainly through hints

inland coral
pine dagger
#

It can get very frustrating at times, but when you crack it.... feeeeels goooood

inland coral
# lyric dome or do you find out mainly through hints

I think you mean "hints" generally, not question/answer Hint button hints... but FYI, someone experienced on HTB told me to just click the Hint button because sometimes it has essential information. ||I think for the lab you are on right now, there is one hint button that has required info.||

pine dagger
#

If you get stuck, try using the search function in Discord on this channel, or checking out the HTB forums. You can sometimes pick up hints that trigger you to realise what you're missing.

lyric dome
#

hmm makes sense for sure

#

so i found an ssh hostkey

#

with rsa and ecdsa

#

Im not sure if ive worked with ssh much

#

so idk what those keys mean or do πŸ˜…

inland coral
#

optional hint: ||You should do something with the key.|| Check in if you get lost.

lyric dome
#

so after ssh into the server, i have to enter a password

#

Is that the rsa key or ecdsa key or whats the difference

#

damn, none of them work

inland coral
pine dagger
inland coral
fallen osprey
pine dagger
#

@languid dawn ^^^

fallen osprey
#

@teal mountain

clear saffron
#

Could somebody provide me some assistance with "Attacking Common Applications-Skills Assessment I "?

shy warren
soft scroll
#

Hello, I am working on the footprinting easy lab: I have started with a nmap scan and entered into the ftp

#

ftp> ls -a
200 PORT command successful
150 Opening ASCII mode data connection for file list
drwxr-xr-x 2 root root 4096 Nov 10 2021 .
drwxr-xr-x 2 root root 4096 Nov 10 2021 ..
226 Transfer complete

#

I've entered this command in the FTP but I'm not entirely sure how to proceed

pine dagger
#

Was watching a show with my wife. πŸ™‚
Try using the ||same mutated password list that was used in the Network Services section||

shy warren
pine dagger
shy warren
pine dagger
#

Now if only someone would give me a hint on AD Skill Assessment 2! πŸ™‚

teal mountain
#

@fallen osprey I am not a moderator, it's just my username lol πŸ˜‚

teal mountain
#

@fallen osprey it happens all the time with me, just false pings and I like it

fallen osprey
#

@sterile hawk

sterile hawk
#

Ty, removing

fallen osprey
winter quest
#

Hello, for the Network enumeration with NMAP on Host and Ports scanning this question: Enumerate the hostname of your target and submit it as the answer. (case-sensitive

#

I used sudo nmap -sS -sV

#

and I got For service info

#

Service Info: Host: NIX-NMAP-DEFAULT; OS: Linux; CPE: cpe:/o:linux:linux_kernel

#

I dont know if I am formatting it wrong or whatever

#

I spent an Hour on this, any help would be appreciated

hallow quiver
#

damn feels like i m a newbie here..totally newbie

unique valve
winter quest
#

@sleek urchin

hallow quiver
wraith gazelle
#

hello, I have a question in the smtp footprinting module, I already listed the SMTP to find the username but many appear and I already tried one by one and it doesn't work, any advice? πŸ™πŸ»

placid quest
#

@wraith gazelle use Metasploit

wraith gazelle
thorn urchin
#

finally finished Active Directory Enumeration and Attacks

#

hot damn what a beefy module

sly tapir
#

has anyone done the CBBH file upload module? im very stuck , and whats worse is i have the upload.php file

placid quest
#

@sly tapir Is it allowed to ask for help when doing exams

sly tapir
autumn pilot
#

no hints for exams

sly tapir
#

its a skills assessment, not the actual exam

fallen osprey
#

Using the Metasploit Framework Module: the text talk about 2 versions of Metasploit: Metasploit Pro and Metasploit Framework (Pro is commercial and you need pay for it) and Metasploit Framework is free. But when I try answer Metasploit Framework on the question (see my Screenshot) it give me a Error. I have even tried online enter: Framework. Can anyone give me a hint?

thorn urchin
fallen osprey
low vine
#

Trying to dump hashes for Footprinting - IPMI. Have attempted with msfvenom and not getting the hasehs to dump, how might I go about doing this manually?

placid quest
#

@low vine use msfconsole

low vine
#

err sorry thats what i'm using

#

I think

#

msf6

placid quest
#

Did u search for ipmi

low vine
#

[*] Scanned 1 of 1 hosts (100% complete)
[*] Auxiliary module execution completed
#

Like I guess next step would be ot just use some password list?

#

or maybe hashcat?

placid quest
#

Did u provide the ip address

pine dagger
low vine
#

using something else

#

err sorry no I didnt end up getting it

#

working on trying hashcat but no fucking clue and the examples of use seem to not work

#

Hashfile '/usr/share/wordlists/rockyou.txt' on line 49357 (panda14): Token length exception

#

hashcat -a 0 -m 400 /usr/share/wordlists/rockyou.txt

zealous belfry
low vine
#

I'm trying to disctionary attack

#

dictionary*

zealous belfry
#

it tried to crack hashes inside the word list

low vine
#

So if i wanted to set a username and then use a wordlist to attack.
hashcat -a 0 -m 400 -u admin /rockyou.txt

#

idk its not clear to me after reading like 5 different "beginner walkthroughs"

#

how to use hashcat as a dictionary attack

zealous belfry
#

sry I did not read all the conversation before just replied to the error
so you want to crack a hash right ?

low vine
#

No

#

I dont have a hash (could get the hash with msf)

#

so I'm trying to dictionary attack since I have username

zealous belfry
#

what protocol you trying

low vine
#

what you mean?

zealous belfry
#

like what are you attacking ftp rdp etc

low vine
#

IPMI

zealous belfry
#

oh okay then i have to get back home later and see because out of my head I don't know how to attack that
if you don't get it dm me in the evening and I'll try to help

low vine
#

yea so far i tried metaspoit to try to dump the hash

#

but wastn successful so looking at other ways to do it

placid quest
#

@low vine u can use john to crack the password

low vine
#

I'm not trying to crack the password

#

I'm trying to dump the hash

#

if possible I have to be fucking something up but I dont understand what or why

vital adder
low vine
vital adder
#

under ||Dangerous Settings|| there is a example hashcat command with the right mode for this hash

vital adder
low vine
#

yea idk I dont understand how to use hashcat

#

just keeps erroring

#

And I have no information leading me to believe the password is a certain length

#

so this seems like a bad idea

vital adder
vital adder
low vine
#

okay ill look at john

#

cause fuck this shit

zealous belfry
#

looking at my notes found || hashcat -m 7300 ipmi.txt -a 3 ?1?1?1?1?1?1?1?1 -1 ?d?u || maybe it helps

low vine
#

it doesnt work

vital adder
low vine
zealous belfry
low vine
#

found 1 more tool ill try

zealous belfry
#

you just need to || get the hash via metasploit use auxiliary/scanner/ipmi/ipmi_dumphashes || That should definitely work if you set all the required options

vital adder
#

so i just give it a try and if you use load the hash in hash cat without the username even the example will work

zealous belfry
#

and then || crack the pw w/ hashcat as shown ||

low vine
#

@zealous belfry i tried i got nothing

#

from metasploit

#
[*] Auxiliary module execution completed
zealous belfry
#

hm have you checked with nmap if they use a non default port ?

low vine
#

I did earlier ill rescan

vital adder
#

no i just try that and it should work fine (i use the pwnbox not kali)

low vine
#

Let me walk back through set it up again

zealous belfry
#

does the || version enum work? use auxiliary/scanner/ipmi/ipmi_version ||

vital adder
low vine
#

yea version enum works

#

setting it up again

zealous belfry
#

Verry Strange

low vine
#

I reset it

#

so diff ip

#

Works immediately obviously

#

no clue

#

Ty for the help that was really frustrating I didnt have a clue why i was not able to reproduce.

zealous belfry
#

np sometimes they just stuck

#

Β―_(ツ)_/Β―

fierce sparrow
#

ACTIVE DIRECTORY ENUMERATION & ATTACKS, i'm stuck on privileged access, anyone to give me a helping hand?

fierce sparrow
pine dagger
#

Which question, 1, 2, or 3?

fierce sparrow
#

not a question was just wondering for learning purposes lol

#

it's below under "Choosing enable_xp_cmdshell"

pine dagger
#

Not sure how you're "stuck". That part just involves running the command xp_cmdshell after turning it on.

#

All the stuff after that is covered in Windows Priv Escalation

fierce sparrow
#

ok cool

flint agate
#

Hello I am stuck on SSRF AJP Proxy
sudo docker run -it --rm -p 8009:8009 -v pwd/tomcat-users.xml:/usr/local/tomcat/conf/tomcat-users.xml --name tomcat "tomcat:8.0" this command gives me an error like shortname "tomcat:8.0" did not resolve to an alias and no unqualified-search registries are defined in "/etc/containers/registries.conf"

winter quest
fierce sparrow
#

@pine dagger were you having issues connecting to the machine via mssqlclient?

vital adder
fierce sparrow
winter quest
#

that worked for me

vital adder
#

nice and weird but pls remove that

pine dagger
fierce sparrow
#

all right no worries ty

pliant hamlet
#

I have some order questions, who should I contact.

warm gyro
#

Who can decrypt elf.so file ?

Paid help

sly tapir
#

i just finished closed out that section...the skills assessment had me in a very deep rabbit hole

fierce sparrow
#

do the active directory attacks module, definitely worth the money

sly tapir
pine dagger
sly tapir
pine dagger
#

Ah!

pine dagger
pine dagger
#

Oh Well 😦

#

But congrats on completing File Uploads!

fallen ruin
#

Any one can give me the pdf copy of β€œHands on hacking” by Matthew?

tight mesa
#

anyoen who has finished API Attacks

#

to ask something regarding SSRF section

flint agate
#

Hello

#

did you resolve it ?

#

I am having problems with the login brute forcing module , skill-assesment website section. I've been stuck on this module for some time.

#

As yaoi74 said is my password wrong ?

flint agate
#

I am trying to the second question "Once you access the login page, you are tasked to brute force your way into this page as well. What is the flag hidden inside? "

sudden prism
#

Is anyone else having trouble spawning machines in the modules? I'm back working on some lower level modules in an attempt to clear out every training module but the box for Win Fundamentals will not spawn.

wide viper
lethal atlas
#

anyone having issues spawning targets? I have been waiting almost 20 minutes now

indigo forge
lethal atlas
#

well there is my answer

sudden prism
#

@indigo forge @lethal atlas Glad I'm not the only one.

low vine
#

Footprinting Lab - Easy , I ended up looking at the hint giving me username/password. What was the intended methodology for finding this. Could not for the lift of me figure it out.

wide viper
sudden prism
wide viper
low vine
#

I would assume if all of ours is down that your stuff is likely down too

sudden prism
wide viper
sudden prism
#

Haha, glad you got that relief. There's nothing more frustrating than following directions, trying multiple iterations of the directions, and still not getting the flag.

low vine
#

^^

sudden prism
#

Sounds like it's time for an early lunch. Catch you all later!

wide viper
#

yeah i was really questioning myself if i'm too dumb to open a website

flint agate
wide viper
flint agate
#

i received a bunch of passwords but none of them work

#

i was wondering if the username is wrong

wide viper
flint agate
#

you can put the form name and the fail/succes string in the same command ?

wide viper
flint agate
#

I keep getting passwords but they don't work

#

i even made a wordlist with cupp for ||nas||

wide viper
sly tapir
thorn urchin
# pine dagger Congrats! Would you mind if I dm you for a hint on skill assessment 2 question 8...

one of the privileged sections that covers mssql mentions the technique you need to use. The annoying part though is that none of the practical sections actually covers the method you need to use.

I had some issues trying to run it myself, until I discovered a certain convenient shell implements it natively. So it went from frustrating pulling my hair out trying to sort it all together to a 5 second solution πŸ™‚ definitely imo the hardest part of the whole assessment.

pine dagger
thorn urchin
#

specifically the Priviledged Access section is the one youll want to scrutinize deeper

tight mesa
#

anyone is experiencing some buggy behavior with some modules?

pine dagger
#

Not normally. Only time I had issues with it, it was the VPN related to some platform issues.

true kayak
#

Hi

tight mesa
#

ok., weird

#

when established a reverse shell with the web server under SSRF section/API Attacks the connection is closed

#

@pine dagger do you finished API Attacks?

pine dagger
#

On my to do list.

tight mesa
#

ok.

pine dagger
tight mesa
#

anyone who has finished API Attacks to ask some related to SSRF section..!!!

thorn urchin
hazy grotto
#

Anybody know why this is happening and how to resolve it?

clear saffron
hazy grotto
#

brilliant lol

thorn urchin
#

p expects the very next sequence to be the specified port number

#

so when you're shorthand grouping them together order actually matters

tight mesa
#

anyone knows other way to establish a connection "reverse shell" than the example of SSRF section under API Attacks?

#

because when I establish the reverse shell with curl encoded command as described in the section and ran a command the connection is immediately closed

pine dagger
thorn urchin
#

no

pine stump
#

Hi everyone, I'm thinking of getting a new laptop, should I go for m1 mac or should i stick to Intel/AMD? For hacking purposes

gloomy tangle
#

dude, its not about you. maybe someone else needs a hint πŸ˜‰

sly tapir
#

I have an improvement to one of the CBBH modules.. who can i send this too? might be nothing because we are expected to Google some stuff, but I was hard stuck on this until i tried a certain tool out, and that helped alot, because the magic numbers didnt work like I expected

thorn urchin
placid quest
#

@sly tapir I may be happy to know that tool

placid quest
#

@sly tapir thanks

hazy grotto
#

So i was having issues starting a reverse shell today. I actually went over to Tryhackme to do a couple easy boxes for practice and when i was setting up a reverse shell. I was using my tun0 ip address.

I noticed in my THM VPN it had mentioned tun1 open or something along those lines. After smashing my head for a about 2 hours I used tun1's ipaddress and it worked.
I'm thinking I may need to delete tun1 from my machine but i'm not really sure. Can anyone explain my issue if I have one and a solution? or does THM use tun1 and HTB use tun0.... I don't really even know what the difference is.

loud sapphire
loud sapphire
hazy grotto
hazy grotto
thorn urchin
loud sapphire
#

depends on how you connect to the vpn i guess?
For example, if you are using openvpn to connect then you can just CTRL-C in the terminal you ran the original command to close the connection.

Once all vpn connections are disconnected run ifconfig.

Ifconfig should list nothing for any TUN interface.

#

from there connect to the vpn you need to use and run ifconfig again to see what comes up for TUN.

Default should be tun0. tun1 shouldnt exist unless connected.

loud sapphire
pine dagger
# thorn urchin no

Went round in a circle, back to things I thought I had already tried, and then finally I must have done something differently. Thanks for the pointer! πŸ™‚

loud sapphire
#

anyone help? i want to get this finished please.

loud sapphire
#

...

zealous belfry
#

does anyone know if its possible for firefox_decrypt to recognize newly added profiles instead of overwriting the existing once?

zealous belfry
thorn urchin
#

its the Pass the Ticket part afterall πŸ™‚

loud sapphire
#

so i can ignore that and just pth or ptt

thorn urchin
#

if I remember correctly at least

#

if not go back over how it said to do it

#

ah yeah it even recommends just plugging it into crackstation. Try that if passing it doesnt work

loud sapphire
#

the hash doesnt do anything in crackstation. Its not NTLM or another supported hash.
Its an AES-256 hash.

I cant use rubeus as its a linux box.
I am at a loss... guess i will keep digging.

#

figured out why. 2nd file.

hazy grotto
loud sapphire
#

reboot?

loud pagoda
#

Hey ya'll, I am on the last problem for the web proxies module. I am having trouble getting ZAP to intercept my msfconsole exploit. I have set the proxies, rhost, and rport on msfconsole but it not working. Any pointers?

loud pagoda
#

Wasted a bunch of time trying to get ZAP to work with msfconsole. Used BURPSUITE and it worked immediately. Got the last flag.

zealous belfry
loud pagoda
#

No, and I tested. ZAP did not work.

zealous belfry
#

asking because if you would then zap cant bind to port 8080

thorn urchin
#

zap is just kinda garbage tbh

zealous belfry
#

because its occupied by burp but if it worked with burp guess its fine

#

ja i dont like it neither

loud pagoda
#

Yeah, I made sure. I've been using ZAP only cause its open source but I guess burp is a bit better I just don't want to pay while i'm learning.

thorn urchin
#

shouldnt need to

zealous belfry
#

youre fine without the payment

thorn urchin
#

burp community is still pretty good

zealous belfry
#

community edition is good enough

loud pagoda
#

It's kinda frustrating that the modules are labeled easy but I struggled to get them completed

#

Thought I was decent with computers.

thorn urchin
#

remember the adage

#

HTB easy is medium to hard anywhere else

zealous belfry
#

ya but tbh sometimes the module assignments are kind weired

#

anyone of you guys got a quick tip on how to crack the root hash in password attacks by any chance? Dont want to waste my time with rockyou if its not the right path

thorn urchin
#

generally use the mutated password list or the regular password list first, then brush off rockyou

zealous belfry
#

yea i tried but did not hit on any

thorn urchin
#

which lab was it

zealous belfry
#

found || $6$XePuRx/4eO0WuuPS$a0t5vIuIrBDFx1LyxAozOu.cVaww01u...fqhXg ||

thorn urchin
#

ah I dont have any particular notes on that one

zealous belfry
#

sad :/

wraith gazelle
#

Hi, I don't quite understand what you mean by IMAP/POP3 serviceπŸ€• in module footprinting

thorn urchin
#

what about em

low vine
#

Footprinting Lab - Easy , I looked at the hint giving me username/password. What was the intended methodology for finding this? Could not for the life of me figure it out.

thorn urchin
#

whenever they do a pass over that module next I expect itll get updated

#

cause people complain all the time

low vine
#

Not really a complaint just trying to understand what I might have missed/ not understood

#

But okay makes sense

#

ty

thorn urchin
#

yeah saying that feeling is the valid reason to be complaining though lol, the hint is just simply mandatory information to complete the section

low vine
#

I saw it and I was like what in the fuck did I miss during the 3x I walked through both FTP servers + other open things

#

lol

vast cliff
#

I need a pro hacker

#

me and you are in the same boat. hopefully we can find some help here tho

alpine kindle
#

Hello! I've solved everything for Information Gathering - Web Edition, Active Subdomain Enumeration, but I want to confirm my understanding...
Is the way to identify the number of zones on the target nameserver (Question 2) simply to try to do a zone transfer on each subdomain and if it works, that's a zone? Or did I miss something much simpler?

pine dagger
#

Ohhh yeah! AD Enumeration complete. Damn that was frustrating as hell, but oh so fun. πŸ˜„

thorn urchin
#

nice congrats

nova geyser
#

I need help with login brute forcing Skills Assrssment first question "When you try to access the IP shown above, you will not have authorization to access it. Brute force the authentication and retrieve the flag."

#

I wait an hour without any succes

#

I am ONE YEAR on this room

warm blaze
#

can anyone help me with the footprinting medium lab, Already found the creds but hitting roadblocks on attempted methods

warm lichen
opaque badger
#

I’m interested in learning more about IDORs and business logic errors does anyone know of any good resources on hack the box or other platforms?

nova geyser
#

And doing a 1337 bill

warm lichen
#

Everything you need to answer the question is in the module

#

Read them again and apply what they taught you

#

From my notes I can see that the username is wrong (^:

nova geyser
#

That's not helping...

#

If you don't want to help just don't answer I get enough of these responses one year.

thorn urchin
#

If you dont like the help just because its not the direct answer thats on you

nova geyser
#

I tried all the possible combinations, everything that was said in the forums I've created random dictionaries of usernames and passwords

#

So you are not helping.

thorn urchin
#

its big choosey beggar energy

nova geyser
#

Dude stop sarcasm I have enough of this ONE FCKN YEAR

thorn urchin
#

its the kind of attitude that for me at least makes me definitely not want to help at all

#

Youre being a jerk to people who simply tried to help you

nova geyser
#

You are NOT helping at all

thorn urchin
#

Stop being a jackass

nova geyser
#

It's not the first time I am asking this how the hell do you think I'm passing I'm so fcking happy

#

I was asking for this since one year

#

Forums, reddit discord

thorn urchin
#

you taking a year to work on one module doesnt entitle you to being a jerk

nova geyser
#

Ok so just don't answer if you don't want to help that's all I have a lot of these responses.

thorn urchin
#

Sounds good to me πŸ‘

#

what even is the module youre working on

thorn urchin
#

hey buddy πŸ™‚

#

buddy pal

#

your form name is wrong

#

so is your page name for that matter

#

and your params

#

copy paste less and youd get it. If your command is formatted properly itll find the correct password in about 15 seconds

#

also also the hint tells you what user to use

warm lichen
#

My boy needs to try harder if he's been at it for a year

thorn urchin
#

also your attempted command is closer for the form login page but thats the second question and your initial question is about the first one.

#

which ironically can be solved by a near copy paste from the relevant module page

broken saffron
#

Hello all! Somebody is doing file upload attacks module (blacklist & whitelists section?) I can't get response from the server but I was able to upload the file πŸ˜΅β€πŸ’«πŸ€”

#

@nova geyser if u still need help ping me!

nova geyser
#

I got it now, it is related to the -C flag of hydra and login form attacks tab from room

#

aghhhh so fucking ez to take one year lololol

vital adder
nova geyser
#

the problem was that I didnt know what hydra -C did, just knew -L and -P

broken saffron
#

@nova geyser great to know!

#

@vital adder can't access sorry I explain wrong but I'm sure was upload succesful

rustic sage
#

is Easy Lab in Password attacks module intended to solve with resources files?

rustic sage
# vital adder yep

and is it normal to take longer to bruteforce than the 90 minutes of spawn time? πŸ˜‚

vital adder
flint agate
#

I can't access login bruteforce second skill assesment

#

it could a problem be from HTB

warm turret
#

Hello

#

anyone can hellpme with Attacking Common Applications - Skills Assessment II

vital adder
feral ridge
#

i need a little help for an academy module, where should i ask?

vital adder
#

here

#

but make sure to include the module and section name

feral ridge
#

oo okay, so the problem is for the shells & payloads module's live assessment i was required to rdp into a "foothold" machine, but i cant find a browser on that machine

#

i think i need one to upload war files and stuff..

marble raft
#

Have you tried reseting the VM?

vital adder
#

run firefox on the terminal

feral ridge
#

omg woww....

#

ty so muchh

vital adder
#

also i'm predy sure that "updated" lab was just an old lab re-used

vital adder
feral ridge
#

πŸ˜‚πŸ˜­

marble raft
#

hey @vital adder i was wondering, how long did you take to complete AD module?

vital adder
#

nope still can't stop procrastinating

marble raft
#

rly? I'm kinda near the end but for sure will need to go through it again, too much info

vital adder
#

yea that's one of the thing i'm kinda scared of

flint agate
vital adder
#

i'm doing the attacking enterprise networks with now and still that module have a lot of stuff

vital adder
vital adder
pliant sage
#

yoooo I have a very weird problem

#

I'm doing the attacking common services module, ftp section

#

i bruteforced the ftp serv with hydra and got a login:password and the subsequent flag

#

except those are all for the smb section

placid quest
#

@pliant sage that is what happened to me

vital adder
#

so for that module there is i think only one machine throughout the whole module or something so you can kinda still access smb in the ftp section, if you use the right method you should still be able the get the ftp flag

pliant sage
#

dunno for the rght method but I found another user I'll try to bruteforce that one lol

vital adder
#

shoot me a dm if you need help with that

placid quest
#

@pliant sage u don't need to brute force because the ftp has anonymous login

vital adder
#

yea that's a bit too much spoiler

pliant sage
#

yeah but it only gives me the password and user lists no?

#

i saw that anonymous login was enable

placid quest
#

@pliant sage try to login with anonymous

pliant sage
#

yeah no I got that I just misunderstood smth about the files we were given

#

thanks

warm gyro
#

Hi there who can decrypt (lib.so) decompiled like smali to java.? To be more readable

Paid help

low vine
#

Missing some lack of understanding on using ssh for Footprinting Lab - Easy
I'm using this command ||ssh -i ~/10.129.60.185:2121/.ssh/id_rsa.pub ceil@10.129.42.195|| I've changed permissions to ||chmod 077|| and not quite understanding what I might be doing wrong. Is it because i've reset my box and what I downloaded is for a diff ip?

placid quest
#

@low vine The ssh keys are private not pub

vital adder
#

and you need to set the chmod to 600 not 077 (for ssh private key)

flint agate
vital adder
#

use ||cupp||

flint agate
#

as the exercise says
skill asssesment login bruteforce service login

#

I know about ||cupp|| but how can i find the information necessary about employees ? : ))

vital adder
#

oh wait no that's for the password not the username

flint agate
#

anyway I am at a THM Hydra room and will get back to it after

vital adder
#

for the username use username-anarchy

vital adder
low vine
#

I feel like yall gave me the best possible hint but I'm really clueless on what I'm not understanding

#

and would love a small ELI5

vital adder
low vine
#

yea I did and im still getting the same thing lol

#

thats whats causing me confusion

vital adder
#

oh wait that's weird can you shoot me a dm with a screenshot of that error?

fair mesa
#

Hello ! I need help on Password Attacks Lab - Easy... I get access to the FTP server but once I got the ssh files I can download them and modify them but I can't upload them on the ftp server to make me connect to ssh

vital adder
#

why tf would you upload them back on ftp after getting the ssh key?

#

just use the ssh key to login via ssh

fair mesa
#

Oh

#

so i can use the private key directly?

vital adder
#

yep

#

that's how ssh work

fair mesa
#

Ohhhhh I get it xD thank you mate

fair mesa
vital adder
#

nope you need to get the id_rsa key from the ftp not id_rsa.pub

fair mesa
#

Okey I got it ! ssh -i [id_rsa file] with the correct permissions on the file

#

thank you MRtom !

flint agate
#

I now know about the username

#

but should I use an online tool for the password ?

#

I tried a command like ||hydra -l <username> -P <full path to pass> MACHINE_IP -t 4 ssh|| is this ok ?
I think it is but the problem is how to figure out that passwd list

placid quest
#

@flint agate try to use xhydra maybe it may be easy to use more than hydra

turbid lily
#

Why sometimes the "lifetime" of a spawned machine in any module is way shorter than it says? For example, a machine is supposed to stay as spawned for 90 mins, but some of them do not remain spawned for more than 5 mins (and the time counter decreases really fast). Why is this? D: I mean, sometimes you need that time to scan ports, or crack passwords :c

low vine
#

I was looking but didnt see it can we us Burpsuite Pro on CPTS/CBBH?

#

or community edition only

warm lichen
low vine
#

How did you exam go?

warm lichen
#

I got the points to pass. I'm waiting for feedback on my report to tell me if I pass or not

low vine
#

Awesome congrats! Looking forward to giving it a go here in a couple months

warm lichen
#

Good luck!!

flint agate
#

can someone help me on login bruteforce second skill assesment ?

junior hazel
#

Someone have done the attacking AD module ? I'm stuck :x

warm lichen
flint agate
#

can I send you a dm ?

#

regarding the creating of custom wordlists

wet jolt
#

Why i have this error?

warm lichen
raven urchin
#

Hiya, having some issues on **Information Gathering - Web Edition ** - Active Subdomain Enumeration.
Every time I try to use > nslookup -type=NS inlanefreight.htb
I'm getting the following: ** server can't find inlanefreight.htb: NXDOMAIN
I've tried looking through messages from users who previously have had this issue but haven't found anything, any help is welcome :)

placid quest
#

@raven urchin what is the problem

raven urchin
placid quest
#

@raven urchin use dig tool

rustic sage
#

hi all, im stuck on a lab and really not sure where to go with this. its the footprinting module and im on the easy lab 😳 . I dont want to type to many spoilers in here but proper stuck

#

anyone help please?

placid quest
#

@rustic sage like how are u stuck

rustic sage
#

ive wget on p2121 says 12 files downloaded but when I cd to it and ls theres nothing in the cd?

#

nothing in the directory*

placid quest
#

@rustic sage try to use ls -la

uncut mirage
#

Hi, can anyone give a hint on module "Attacking Common Services", section "Attacking FTP", Question 2: "What username is available for the FTP server?"
Only suggestion during the text is to brute-force it with medusa, I've tried that now with no luck, can't think of anything else, please help

rustic sage
placid quest
#

@rustic sage ok

#

@uncut mirage the ftp allows anonymous login so try that

raven urchin
warm lichen
#

Are you using Windows CMD?

wet jolt
#

yes

warm lichen
#

Yeah ok that would do it πŸ˜„

#

You need to escape your quotes with \

#

Linux has no problem with it

wet jolt
#

can you give me an example?

#

πŸ™‚

warm lichen
#

Ah

wet jolt
#

Like 'password'?

warm lichen
#

I was wrong, sorry. You only need to escape single quotes if it's within double quotes

#

curl -X POST -d "username=admin&password=admin" "http://167.99.204.5:32558/" -v

wet jolt
#

with ?

warm lichen
#

This works

wet jolt
#

sorry idk discord cancel \

warm lichen
#

My advice is to stick with a linux-like terminal, or use WSL if you want to keep using windows

#

Cause funky stuff like that happens in my experience

wet jolt
#

ty

#

❀️

warm lichen
#

No problem πŸ’ͺ

low vine
#

When mounting NFS share what might cause you to not be able to access it?

#

using nmap it shows /<NFSshare>(everyone)

#

which makes me think there shouldnt be limitations to accessing it

#

Wait i think it just hit me

west perch
#

who needs a pro hacker when you yourself are the hacker ?

low vine
#

Not so much module specific but just started using parrot os and I'm receiving !mD: event not found

#

when trying to use xfreerdp

#

Not understanding whats going on so kinda lost on whats happening

carmine cape
#

Hi, can anyone give a hint on module "Attacking Common Services", section "Attacking SMB", Question 2: "What is the password for the username "jason"? "
I can't think of anything to find out the answer. I have tried crackmapexec and ran the ./enum4linux-ng.py without any luck, I have tried to read the file GGJ/id_rsa but it's empty because access denied:/. please help

vital adder
low vine
#

What is set +H?

#

yea just trying parrot for the 1st time

#

and failing miserably

#

lol

vital adder
vital adder
low vine
#

yea was reading that

vital adder
#

the i did get event not found error when using metasploit one liner

vital adder
low vine
#

Im just trying to use xfreerdp

#

and its spitting that out

vital adder
#

oh wait what is your xfreerdp command also try remmia

low vine
#

xfreerdp /u:<user> /p:<password> /v:<ip>

#

trying to login on medium box for footprinting

vital adder
low vine
#

Oh i did miss that

vital adder
#

so did that work?

low vine
#

no

#

well diff error

vital adder
#

oh

low vine
#

command not found ><

#

<

vital adder
#

wait what? 🀣

low vine
#

xrdp = xfreerdp?

vital adder
#

wait nope

#

wait what

low vine
#

guess i failed at installing xfreerdp then

vital adder
#

oh wait this is actual cred that password is kinda dumb so I thought it was just a example command

low vine
#

Yea my bad

#

Idk just having bunch of problems trying to get stuff onto parrot

#

<

vital adder
low vine
#

Wish i worked a little more with linux

#

<

#

I'm like a 5 year old

#

so seems like i just explicitly install one of the 2 packages right

vital adder
#

i can't remember exactly but i think i did have a lot if issue when installing one of the rdp tool into linux and i wasn't able to fix that issue whatever it was, but i can't remember which rdp tool so if you are having issue installing this i think you should try other tool first

vital adder
low vine
#

Is there any like giant package like kali has to just download a ton of extra tools

#

didnt really find one when doing quick google

unreal patio
low vine
#

Must have missed that on initial install ty

#

oh thats kali, yea I know kali has it trying to see if parrot os has it

vital adder
low vine
#

Aight im just nuking this and going bacxk to what I know

#

lol sorry for the spam

vital adder
#

no worries, it's ok to ask for help besides we got way worse scammer that spam a lot here

placid quest
#

@low vine
sudo apt-get install aptitude
sudo aptitude install freerdp2-x11

tight mesa
#

hello anyone who has completed the API Attacks skill assessment?

#

unfortunately I'm not being able to enumerate the API

#

any hint?

vital adder
# tight mesa any hint?

sure shoot me a dm also keep in mind "the service will respond successfully only after submitting the proper SQLi payload"

tight mesa
#

thanks

low vine
#

tdhat might have been the thing i was missing

loud sapphire
#

Quick one please, using Hydra with FTP... what Thread count can i get away with (password attacks lab easy)

unreal patio
#

I used 48 on smb iirc

#

But I read some people used 64

loud sapphire
#

I am using 64 with FTP now. Slow process tho... I also used CrackMapExec but it goes soooo fast i cant see if i got a hit to stop it in time.....

unreal patio
#

cme should stop automatically on success

loud sapphire
#

then..... im doing something wrong. maybe.

mellow turtle
#

anybody knows how to kill a process in the pwnbox? Im trying with "kill PID" but its still there

unreal patio
#

@mellow turtle you can always use xkill

#

But it might kill all your terminals if that's what you're looking to close

mellow turtle
#

@unreal patio I often close python http server processes with ctrl + z instead of ctrl + c so they still running and i cant use that port again

unreal patio
#

Then type jobs

#

and kill %1

#

the number being the job process you want to end

mellow turtle
#

@unreal patio It worked ty :3

fierce sparrow
#

ctrl c

#

or just close the terminal

loud sapphire
#

hint on list for Password Attacks -Lab "Easy" please?

unreal patio
#

@loud sapphire details?

loud sapphire
# unreal patio <@229045797931450368> details?

i have 2 services. FTP and SSH open. default ports.

I need to find username and pass for one of these services to gain a foothold.

I have used the files in resources but am failing to get creds. am i missing a list of a mutation?

unreal patio
#

Have you tried without mutation?

loud sapphire
#

yes.

unreal patio
#

I did this one a week ago and I've forgotten how I solved it

#

But I thought that one was just user.list and password.list for the initial foothold

loud sapphire
#

see i tried that. I will try again.

which is best for FTP? CME or Hydra?

unreal patio
#

ftp with cme

#

Last time I used hydra it skipped over a password

#

😦

loud sapphire
#

ill try again now. its very possible that cme is skipping

mellow turtle
#

@loud sapphire i think u should try nmap with -p-

#

I think there is a port opened > 1000

loud sapphire
mellow turtle
#

i always nmap IP -p- -Pn to collect the active services and then i run the nmap -sC -sV -p{PORTS} -Pn

#

oh sorry then πŸ™‚

barren heath
#

This a lame question but How do I start?
PS: i have less to no knowledge of programming but i really love the idea of coding

mellow turtle
barren heath
mellow turtle
#

I cant tell because when i started on HTB i was full stack developer and sys admin

#

but i dont think so, if you dont know something just google it

unreal patio
#

Can someone give me a nudge about PW Attacks Lab - Hard?

#

I got most of the credentials but I'm stuck

mellow turtle
#

@unreal patio where are u stuck?

unreal patio
#

I can't seem to open the vhd file

mellow turtle
#

import it to your own windows machine

#

and then open it and put the password

barren heath
unreal patio
#

Is there no other way?

#

😦

mellow turtle
#

i do it like that @unreal patio :/

#

if you find another way tell me

unreal patio
#

:p

barren heath
#

Wait last question
Which language should I start with?

mellow turtle
#

@barren heath nice question

#

mr tom always recommends a video to see

#

let me find it

barren heath
mellow turtle
#

@loud sapphire try hydra with -t 64

#

hydra -L username.list -P password.list ftp://{YOUR-IP} -t 64

#

@barren heath NP

pulsar fjord
#

hii

mellow turtle
#

hi

loud sapphire
mellow turtle
#

nice

pulsar fjord
#

can you help me

mellow turtle
#

maybe

pulsar fjord
#

i am new in cyber security

vital adder
barren heath
#

isn't the app too costly ?

mellow turtle
#

hey mrtom thats the video u usually send right?

vital adder
mellow turtle
#

nice

#

@barren heath it depends where u live

barren heath
vital adder
#

which app?

barren heath
#

the website i meant

mellow turtle
#

the academy

vital adder
#

ohh

pulsar fjord
#

hello

vital adder
#

sup

mellow turtle
#

@barren heath its a low price for all it gives

vital adder
#

also check the tcm video out there should be some free stuff in there

vital adder
pulsar fjord
#

hello anyone tell me

vital adder
#

you need emotional support?

mellow turtle
vital adder
#

nice

mellow turtle
#

check that video killer

low vine
#

Okay so trying to clear my head a bit everything shown as an example seems to not work in Parrot

#

is there a particular reason why?

#

Or is there some bigger download I can put to it to download most of the tools and not have to do this tool by tool?

placid quest
#

@low vine what tool

low vine
#

xfreerdp

#

winrm

#

Kali has like an install everything package wasnt sure if parrot had something similar

vital adder
#

so what's the issue with both tool?

#

you can't install or there is an error when using both tool?

placid quest
#

@vital adder maybe he needs a package that can install all tools needed

vital adder
#

or just use kali

low vine
#

cant

#

copy paste doesnt work

#

lol

#

FUCK KALI

#

FUCK THIS

#

FUCK THAT

#

FUCK EVERYTHING

#

I would 100x rather use kali but copy paste does not work in new instance of kali I put up

#

so cant

languid ginkgo
#

Hello all,
Anyone can help me on 'Broken Authentication'->'Brute Forcing Cookies'->'Question 1'.
I can change the role from student to admin, but I have this response:
'Welcome htbadmin.
Your role is admin.
Unfortunately, as admin you dont have any flag.'

How can I found the role name of the super user ?

Thx in advance

vital adder
placid quest
#

@low vine so use Parrot os

low vine
#

I'm using parrot right now

#

but my dumbass just continues running into problems (all my fault)

#

but fuck

vital adder
low vine
#

i still cant get xfreerdp

#

to download

#

which is beyond fucking stupid

#

i have to be the dumbest motherfucker

vital adder
low vine
#

Like I cant figure out what hte package

#

name is called to get it

#

sudo apt install xfreerdp definitely isnt it

#

just beyond frustrated with this bullshit this morning

#

I have to be the dumbest fucking idiot in the world to struggle with the simplest shit

placid quest
low vine
#

Yea im just overly frustrated by small shit this morning

#

sorry

#

Feel like I wasted a good half a day solving dumb shit when i should just be focusing on getting better

languid ginkgo
placid quest
#

@low vine i have used Parrot os for 3 years but i have never got any issues

low vine
#

Yea I mean first morning for me since Copy/paste went to shit on new kali install

#

so im sure its just me

rustic sage
#

Hello there! Is this server currently open for partnerships? <@&817153850845823057>

placid quest
#

@low vine I got into issues when i was using kali so i had to use Parrot os it was hard at first due missing tools

marble raft
#

is anyone having problems spawning pwnbox

low vine
#

Finally got connected via remmia

long frost
#

what was the problem with xfreerdp?

low vine
#

No idea never got it to work

long frost
#

it has been working flawlessly for me for approx 10 years

vital adder
placid quest
#

@low vine sometimes u can use rdesktop

long frost
low vine
#

Hmm okay this is weird I guess I need to find some other user inside this windows thing?

#

No idea how to enumerate some windows system

long frost
#

What does the error say?

marble raft
#

Yea, currently on a computer who doesn't have a dedicated vm, tried spawning the one in the browser under my workstation but it's stuck at starting

#

oh it did work now, weird

manic pilot
#

hi there, is there anyone available for a quick discussion on AD skill assessment I? managed to get the hash for ||tpetty|| but was unable to crack it

low vine
#

Okay at a pretty big loss Medium Lab - Footprintingl. I have just found username/password inside of important.txt. I have tried using this login information accross everythign I know / have seen so far

#

can I get a slight nudge on the though process?

#

have not been able to get in SQL server

warm blaze
#

can anyone help me with the footprinting medium lab, Already found the creds but dont know the next step

#

ca anyone help out ?

low vine
#

^ I'm at same exact spot lol

placid quest
#

@low vine how many ports are open

low vine
#

id have to look aback

warm blaze
#

loading up the vm but if i can remeber correctly it was 135 139 one or two in between then 3389

#

will confirm in a little

manic pilot
low vine
#

111 135 139 445 2049 3389

placid quest
#

Try to login smb with that username and password

low vine
#

Yea I need to get my thought process right

#

Stepping back that seems like an obvious thing to try but was definitely not thinking that

#

Yea was not able to connect

#

via smb

placid quest
#

@low vine what command did u use

low vine
#

like 10

#

lol

#

rpcclient -U "sa" <ip>

placid quest
#

If it is like that connect rpd with Alex after connect to the database to find the password of htb

low vine
#

I've not be able to connect to the database

placid quest
#

@low vine change sa to administrator

low vine
#

still same problem

placid quest
#

How

low vine
#

Oh wait think my vm went down

#

How long should this take us like this has taken me several days to get through footprinting

#

how long does it take people to typically get through this

placid quest
#

@low vine patient and asking pulse hard work

low vine
#

Yea maybe mentally I'm just in a rush to learn it

#

lol

#

okay finally got in

#

Okay so from here I need to find some HTB users info which I'm not seeing. I'm seeing shares to maybe connect to

#

So I would guess i'd try getting to C:\

#

C:\Windows but not sure ill have to think a bit on it

warm blaze
#

try finding a share you are able to login to

low vine
#

Found it through enumerating where you connect for SMB

#

I just see shares/ info but unusre of what do move to next

#

I'm probably looking for some login info into SQL management but not sure

thorn urchin
#

(and im positive theres people who blitzed through it faster than I did)

low vine
#

I was recently let go from webapp pentesting job. So it just kinda freaks me out that I cant fly through this even though this wasnt what I was doing

#

So mentally i'm just worried

thorn urchin
#

ah nerves getting to ya, well web app pentesting is pretty specific so youre probably just not used to this side of things much

#

once the web specific modules start coming up, youll blitz through those ones

placid quest
#

@low vine use Alex to login rpd after use the the password of sa to login mssql

low vine
#

Now i'm more confused I already had the password and tried

#

why would I magically be able to now?

low vine
placid quest
#

@low vine use Administrator as username