#modules

1 messages ยท Page 21 of 1

low vine
#

Oh duh ><

#

Wait i'm pretty sure I already tried that

#

okay lets see

#

yea login failed

placid quest
#

Can u dm me with a screen shot

low vine
placid quest
#

@low vine use small letter maybe

storm jackal
low vine
#

yea tried both ways @placid quest

storm jackal
#

i feel like it should work with 'sa' account but it's not

low vine
#

Okay did I miss something with the SMB connect thing. Like I connected looked around but ddint seem to be shit to find

#

was that just a rabbit hole?

#

Or I guess thats where we logically can make the admin connection

warm blaze
# low vine

okay now im lost i might of missed the section how to use the sql server any tips

low vine
#

No idea

#

cant get connected

warm blaze
#

found on alex desktop = Microsoft SQL Server Management Studio 18.lnk

#

do i need to do anything with that

low vine
#

@storm jackal did you find a way to connect?

#

Having a hard time mapping this out in my head

#

sure once i get through it a couple times it will flow better

warm blaze
#

phew im in using xfreedp

storm jackal
#

no i was at the same step you were...but I just tried something...password reuse is possible Administrator account

#

poking around now

thorn urchin
# low vine

iirc there was one user you could rdp into that couldnt connect to the db even with valid creds but another user that could

low vine
#

wait is this dumb that i have to connect back with like sa

#

or something lol

#

okay let me try

#

yea got it

#

okay lets find some creds

#

No clue how to use this shit time to google

storm jackal
#

so laggy lol

warm blaze
storm jackal
zealous belfry
#

Hey I have a question for PtH password attacks. It was assumed that a user can connect to a share called dc01. I was wondering how you could enumerate that. On the system logged in with the user i looked at the shares but its not listed. Am i missing something (This is not a question to solve the questions i got that already)

#

|| PS C:> net share

Share name Resource Remark


C$ C:\ Default share
IPC$ Remote IPC
ADMIN$ C:\Windows Remote Admin
The command completed successfully.||

warm blaze
#

Im in as Administrator rdp

storm jackal
#

nice!

tight mesa
#

hey I'm stuck with API Attack skill assessment..!!!

#

i'm trying to execute the automate.py script but i've a syntax error

#

reviewing the script code i dont see any differences with the module

#

so, i dont understand why the error

pastel ginkgo
#

Could someone shoot me a hint for Attacking Common Services - Medium? I've been cracking at it for 2 days now and I haven't been able to get a foothold anywhere. || Besides my nmap that shows ftp is on 2121 I got nothing. As you can't login anonymously and Hydra has come up with nothing. ||

slim plover
#

if not, try resetting the box

hidden meadow
#

Hey! So I'm trying to complete a section in the linux fundamental module and the question is "What is the path to the htb-student's mail?" and I genuinely cannot find the path to the students mail. The closest thing i found was in /var which was mail.log. Am I inputting the path wrong or am I in the complete wrong spot?

pastel ginkgo
mellow turtle
#

Hi im having a problem in the PIVOTING, TUNNELING, AND PORT FORWARDING module in the RDP and SOCKS Tunneling with SocksOverRDP section.
I upload the SocksOverRDP-Plugin.dll and tried to load it using regsvr32.exe but Windows delete the file saying that is a virus. The antivirus is disabled by default and i dont know what to do.

placid quest
#

@hidden meadow look in var

thorn urchin
#

If not I think I had given up and just chained through it not using the intended method

mellow turtle
#

So this is for erratum no?

vital adder
thorn urchin
mellow turtle
#

Its down

thorn urchin
#

you minimum have to go through some non listed hoops to fix it, if not ignore it completely and get the flags elseway

vital adder
thorn urchin
#

yeah real time can be on even if AV is off

#

which doesnt make sense, but ya know windows

vital adder
#

after you disable that remove both file that the av flag and upload or extract it again

mellow turtle
#

thats an example

#

it says me to restart in every change i make

vital adder
thorn urchin
#

oh yeah now I remember how I did it

vital adder
# mellow turtle

i got no idea where you found this but check the real time protection in your previous screenshot

thorn urchin
#

instead of just tunneling the rdp, I just opened a rdp client within my session and just rdpd to the next box lol

vital adder
#

me too

mellow turtle
#

yeah but i want to follow the section ๐Ÿ˜ฆ

vital adder
#

but the section is kinda dumb

thorn urchin
#

the section is broken

#

Ive also never heard of anyone ever using that method in the real world

mellow turtle
#

yeah yeah i know

#

if the real time protector catch it is not so good

#

xd

thorn urchin
#

youre never gunna get it as a question in a technical interview and youll ne er do it on an engagement

hidden meadow
#

anyone have any idea why my terminal just stops letting me type sometimes?

thorn urchin
#

in any situation where you NEED to tunnel rdp, youd just use literally any of the other tunneling tools available

#

either from your implant supporting it, or running something far more popular like chisel

mellow turtle
#

Are you working as pentester madยฟ?

thorn urchin
#

chisel is so good I copied my notes for that page into the root of my academy obsidian notes

#

not yet no

#

Im echoing the opinions ive heard and read of those that have though

#

(and maybe from a little bit of teenager blackhat days exp)

mellow turtle
#

dark side teenager xd

#

Okey so ill rdp with another tool ty guys

thorn urchin
#

np

#

Honestly if theres anything that the CPTS course could use as a whole module addition, it would probably be a C2 framework

#

doubled check, academy doesnt have one at all. Would be a great addition. any of the free popular ones would be fine just to get the general principles down of like generating payloads, creating intermediate host beacons, forwarding, loading modules, ect.

glacial isle
#

hello, i am having an issue with the very first module, when you have to guess bob's password i can simply not find it for the life of me

#

the module that covers services i believe

thorn urchin
#

specifically which module, a lot of modules can be the 'first module'

glacial isle
#

the getting started module

#

the service scanning page

#

i need to complete the last excercise and i only need the password to complete the page

thorn urchin
#

did you try the example password they gave in the module?

#

idr the exact answer but id try that one first

glacial isle
#

they dont give one

#

||this is a spoiler ig so the hint is that the password is weak||

thorn urchin
#

they do, read through the module again

ashen orbit
#

Anyone having connectivity issues, connected to the VPN but can't ever ping the target

glacial isle
#

try changing from udp to tcp

ashen orbit
#

Or I try a long Nmap scan it it can't complete

glacial isle
#

yeah

thorn urchin
glacial isle
#

yes

#

oh

#

i see

#

i must be blind

#

thank for the help

thorn urchin
#

np like I said idr if thats even right, it just probably is

rose urchin
#

hello, i got a problem in the Attacking Web Applications with Ffuf module, in the first question of the finbal examn i dont find any sub-domain whit any of the list i try, can anyone give me a hint?

ashen orbit
#

Thanks, looks like I was on UDP and I switched it to TCP and seems to better, hopefully it stays that way

glacial isle
ashen orbit
#

I would think I would get a specail VPN as a paying user haha

thorn urchin
#

you do ๐Ÿ˜›

ashen orbit
#

well more special haha

zealous belfry
raven cairn
#

WE NEED A MODULE ON C2's. Pls hackthebox pls hacktheflag

#

This is an area I am unfamiliar with.

#

On another note. Can I have some help on the attacking common applications part 2?

raven cairn
pastel ginkgo
#

whoops I missread that as attack common services

#

Speaking of Attacking Common services, on the Hard assessment || Im logged in RDP to Fiona but I cant figure out how the hell im supposed to connect to the sql server. None of the credentials I have work. ||

rustic zephyr
#

Hello quick question. I know that the box are shared so what are we allowed to do on a box ? upload file, ? create file ? change $PATH ?

zealous belfry
#

do what ever you want they reset anyway

rustic zephyr
#

ok thx

raven cairn
zealous belfry
#

uhm ._.

#

i mean you can try but its gonna be hard without internet access ๐Ÿ˜„

#

sometimes i feel like a 5yrs old whos not allowed to use a computer when im on a box and want to download something sadglas

rustic zephyr
raven cairn
#

seriously tho. If anybody knows how to do the Attacking Common Applications Skills Assessment 2 let me know. I need help. I am going to cry ๐Ÿ˜ฟ

zealous belfry
#

not done yet sry ยฏ_(ใƒ„)_/ยฏ

thorn urchin
#

im quite a few modules away from that one sadly

#

but most of them seem like pretty short ones though so

#

ยฏ_(ใƒ„)_/ยฏ

raven cairn
#

I wish MrTOm was online. He always helps me out but I don't want to ping him.

#

That dude is awesome

thorn urchin
#

hiding behind that noob rank like a crouching hidden master

balmy radish
raven cairn
balmy radish
rustic sage
#

anyone good with SSH keys? ive got all the info i need i just dont know how/where to store them so when i try to connect via SSH i dont get access denied public key.

zealous belfry
#

well you need to chmod them to 600 and then connect with the priv key aka id_rsa or what ever its called ssh user@ip -i privkey

rustic sage
#

do i need to make them into a file? i already have them saved in a dir, just not sure what to do from there. ill try do some more reading see if i can figure it out. I do remember covering this before i just cant remember where so got nothing to ref back to at the moment

zealous belfry
#

yea the key has to be a file

#

like everything in linux ๐Ÿ™ƒ

pastel ginkgo
#

Could someone shoot me a hint for Attacking Common Services Hard? || Im logged into the remote computer but I cant login to the Db, and theres no users to session hijack idk where to go from here ||

rustic sage
zealous belfry
thorn urchin
zealous belfry
#

yo srsly who though that RDP to 10.129.253.112 with user ".\Administrator" and password "AnotherC0mpl3xP4$$" would be cool credentials to log in? gotta escape so much

thorn urchin
#

scratch that I double checked my notes and thats wrong

long jolt
#

Has anyone here worked on the Wordpress module before?

thorn urchin
#

theres another module thats very similar, but for attacking common services hard, go back and look at your initial scans again ๐Ÿ™‚

long jolt
#

I'm a bit confused on how to use wpscan to scan the target forinstalled plugins

pastel ginkgo
marble raft
#

Hi guys having trouble with the AD Assessment I

Submit the contents of the flag.txt file on the Administrator desktop on MS01

How can i find the IP address of MS01?

thorn urchin
#

my notes even have myself scolding past me for overlooking it

pastel ginkgo
thorn urchin
#

a tad more complicated than smb

#

remember what youre trying to login to in the first place here

warm blaze
#

hello any hints on the footprinting Hard lab ? big_think

thorn urchin
#

||also im presuming you already found the creds, just having difficulty logging into the db||

warm blaze
#

havent been able to enumerate the service

#

what am i missing

thorn urchin
pastel ginkgo
thorn urchin
#

dont worry that was my reaction too

fluid mist
#

In the "Setting Up" Module it says to type "cat tools.list" into the terminal but when I do it says "No such file or directory". What do I do please?

long jolt
#

are you in the correct directory?

#

try using the command: pwd

long jolt
#

then look back at your question and see if you're in the right directory if not you can look around by doing cd <directory> or cd .. , to go back a directory

rustic sage
zealous belfry
#

well i assume you got 2 files right ? a public key and a private key

rustic sage
#

yup got them

zealous belfry
#

then you take the private key to connect to the server sh ssh user@ip -i privKey

#

and that should log you in

pastel ginkgo
zealous belfry
rustic sage
#

nope says identity file privkey not accessible... not sure where its reading the file from

thorn urchin
pastel ginkgo
#

So how do I add commands to execute and return output?

zealous belfry
#

either absolute or relative

thorn urchin
fluid mist
pastel ginkgo
#

Honestly the mysql portion of this module is kinda all over the place and im just so lost.

thorn urchin
#

thats not mysql

pastel ginkgo
#

sql

thorn urchin
#

its mssql

#

the distinction is important

zealous belfry
#

We love windows dont we ๐Ÿ˜„

pastel ginkgo
#

almost same thing except windows made something simple way more confusing

thorn urchin
#

yup, but also has built in command execution, which is super nice of them

#

its a pita to do the same with mysql

zealous belfry
#

the impersonation is also nice tho

thorn urchin
#

the user impersonation or the SeImpersonatePrivilege?

#

both are nice ๐Ÿ˜›

zealous belfry
#

well.. so much stuff to exploit so nice of them ยฏ_(ใƒ„)_/ยฏ

rustic sage
#

hey ify, I think ive got it sorted. cheers

zealous belfry
#

no worries

pastel ginkgo
# thorn urchin both are nice ๐Ÿ˜›

So i've been trying to add more on to the remote command but im not getting the syntax right. || EXECUTE('select @@servername, @@version, system_user, is_srvrolemember(''sysadmin''),EXECUTE sp_configure 'show advanced options', 1') AT [LOCAL.TEST.LINKED.SRV] ||

thorn urchin
#

youre stacking executes

half pawn
#

Hi

#

Can anyone help me with somth.

pastel ginkgo
pastel ginkgo
#

I tried and I get more syntax errors

thorn urchin
#

you were on the right track with your last message, but stacked the executes

thorn urchin
#

no

rustic sage
#

is there a way to view hidden dir's in ssh? ive used ls -la but cant quite locate the file i need...

thorn urchin
#

ls -la is correct

#

if you dont see it, its probably not there

rustic sage
#

that leads me to my problem then.. appears the file i need isnt there

thorn urchin
#

what file?

rustic sage
#

a flag.txt

#

im on footprinting easy lab. done all the bits to get into the SSH

#

but cant find the flag.txt

pastel ginkgo
zealous belfry
#
EXECUTE('select @@servername, @@version, system_user, is_srvrolemember(''sysadmin'')') AT [10.0.0.12\SQLEXPRESS]```
#

just an example

pastel ginkgo
#

Finally got the flag, god damn I hate Mssql I need more practice with it

zealous belfry
#

gz :=)

pearl island
#

Hello all, I keep getting this error when trying the PrintNightmare attack on the Active Directory Enumeration & Attacks module. Any help is greatly appreciated.

thorn urchin
#

youre requesting the call back to be an interface that the DC is not gunna have access to

#

youll want it to be the 172.whatever of the attack host box

pearl island
#

Gotcha! That's my bad

#

Let me try this

thorn urchin
#

make sure to regen your payload, listener, ect

pearl island
#

You were right. I got it!

#

Thanks @thorn urchin. That was a stupid mistake!

thorn urchin
#

its only stupid if you did it on a live engagement ๐Ÿ˜‰

#

nothing's ever stupid in a lab environment

#

thats why youre doing it in a lab environment

zealous belfry
pearl island
#

True! Good practice I guess.

thorn urchin
#

granted youd hope vanilla PrintNightmare would get flagged just as well, but still the principal remains

zealous belfry
#

ja gotcha

thorn urchin
#

I was watching alh4zr3d's stream and once he mentioned that for red team engagements before any command is executed it gets put into slack and double checked by the team and approved. You never want a syntax error or a mistake like that to happen live.

#

*also subnet earlier not subdomain

zealous belfry
#

I mean makes sense for red teaming if your in a atk against blue team. But just normal pentest ๐Ÿค”

#

Like i dont think you gonna send a mail for every command you gonna try ๐Ÿ˜„

thorn urchin
#

ยฏ_(ใƒ„)_/ยฏ

zealous belfry
#

would be funny tho

pastel ginkgo
thorn urchin
#

np youre welcome

zealous belfry
#

will you guys do the cert?

pastel ginkgo
#

yes thats the goal then its on to oscp

#

then working on my Masters at NYU or Georgia Tech

#

they both have good cyber programs

thorn urchin
#

thats the plan as well, minus the college

zealous belfry
thorn urchin
#

oscp gets you jobs though

#

also oscp isnt a renew cert

zealous belfry
#

mostly (at least here) certificates are not important at all

thorn urchin
#

certs are usually more important for the first job

zealous belfry
thorn urchin
#

at least last I checked anyways

pastel ginkgo
#

I already have ccna and Cysa as well as a billion other certs I'm used to having to renew

zealous belfry
#

damn u are going ham

pastel ginkgo
#

I was trying to swap to the cyber team at my work and I got declined because I was just a net tech

thorn urchin
#

nice, I have an expired A+ cert I never renewed ๐Ÿ™‚

zealous belfry
#

Im empty handed ;D

pastel ginkgo
#

ccna isnt that hard

#

the new test seems easier too

zealous belfry
#

how much are these

steel iris
#

hello

pastel ginkgo
#

300 for ccna

zealous belfry
#

I dont know man a more viable option for me is to get it later once i got the job but paying all that money for certs idk

pastel ginkgo
#

ccna will get you an entry networking position

zealous belfry
#

I got B.Sc. in cyber sec next yr then ill go for a junior pentest job

#

def will do the htb one so i got something to show tho

thorn urchin
#

ive been fiddling around as a repair tech after some unfortunate life turns and Im just tired of it. But oscp is so expensive to risk not passing. But CPTS is much more affordable and supposedly harder, so passing that should make me a lot more confident in one shotting the oscp and make the payment palpable. Then with that getting an entry pentest job should be a lot more feasible

pastel ginkgo
#

hearing that cpts is harder worries me lol

thorn urchin
#

more so its more modern and more TTP focused

pastel ginkgo
#

But Im going to finish the pathway and switch to trying the other boxes before attacking the cert

zealous belfry
thorn urchin
#

america for me

#

so I have to cheatcode HR or its no dice

zealous belfry
#

thats a F

pastel ginkgo
#

If you can get a clearance the NSA pays pretty well for "pentesters"

thorn urchin
#

after the CPTS I might play around with some of the other labs and dabble in bug bounties while I save up

thorn urchin
zealous belfry
#

I mean that would be pretty sick xD

thorn urchin
#

and cant afford to get

#

and the only way to bypass the degree req is to have several years of exp on your resume

pastel ginkgo
#

Georgia Techs Masters in Cyber Sec is around 5k which is extremely affordable for a master

raven cairn
#

My masters is 3k : )

thorn urchin
#

I havnt been able to afford an associates lol

raven cairn
#

I dont have assosciates yet

#

Im young

#

๐Ÿ˜ข

pastel ginkgo
#

Take a look at WGU its pretty affordable and you can technically finish the entire degree in 6 months

thorn urchin
#

otherwise Id already have the clearance section checked. My army job had me with secret clearance with top secret eligibility (if required for something)

zealous belfry
pastel ginkgo
#

I finished my Comp Sci degree through them in 8 months

thorn urchin
#

ill keep that in mind

#

but right now my focus is on the oscp plan

pastel ginkgo
#

mind if I dm you?

thorn urchin
#

tired of waiting to do what I want with roundabout methods

#

sure but cant promise ill respond quickly

zealous belfry
#

aight was nice chatting w/ u guys but gtg to sleep ๐Ÿ˜ด cya!

shy warren
#

Attacking Common Service - hey guys any suggestions on the wordlist to use for the attacking FTP module?

pearl island
shy warren
raven cairn
#

Has anybody attempted the Introduction to NoSQL skills assessment yet?

#

It's a fun module, but this skills assessment is killing me

warm blaze
#

anyone able to help with the footprinting Hard lab. Wass able to ssh into tom acount but stuck on finding any other creds

placid quest
#

@warm blaze do u have the ssh keys

warm blaze
placid quest
#

@warm blaze login in ssh with ssh -i ssh keys tom@ip address

warm blaze
placid quest
#

@warm blaze use the password of tom to connect to mysql database

placid quest
#

@warm blaze no just use mysql -u Tom -p

warm blaze
#

oh i see let me try that

warm blaze
placid quest
#

@warm blaze no problem

low vine
#

Working on Footprinting:Hard lab and I believe I have toms information. I'm failing miserably at trying to login via SSH and frankly not quite understanding how I should appropriately do that.

#

i've been trying ||ssh tom@<ip> -p22|| but keep getting Permission Denied (publickey)

#

Very likely i just missing some ssh understanding but trying to get it clear

#

Wait....think I just got it ...

vital adder
#

hint it is

#

but for this to login via ssh you need something else ||key||

low vine
#

yea thats what I was afraid oof, not understanding how I might find/go after that back to reading

vital adder
#

yea this is a bit too much spoiler if you need we can discuss this is dm

#

also this is tom cred so pls remove this

vital adder
#

wait what?

raven cairn
#

Weird...

#

Well I promise I'm not messing with you

low vine
#

looking now....

marble raft
#

Hi there guys, can i have some help on AD Skill Assessment I?

vital adder
low vine
#

I didnt see nosql

vital adder
#

i guess 0xYaoi got early access

marble raft
#

just searched here and dont have the nosql module too

elfin spruce
pliant sage
#

can someone explain to me how to write a proper sqsh query? WHatever I do I don't get an output

vital adder
#

so after you type your command the next line run go (no cap) to execute

pliant sage
#

oh so it's no cap

#

thanks

pearl island
#

Hello all, I'm trying the PetitPotem attack in Active Directory Enumeration & Attacks module. I don't get the base64 encoded certificate. It says Error Obtaining Certificate. Has anyone seen this before?

pliant sage
#

can anybody tell me why i get the access denied error? I manage to add the key manually through the GUI but couldn't do it by running this command

flint agate
#

Can somebody help me at the SSRF module Nginx Reverse Proxy & AJP ?
Can you please send me a picture with the conf file
I think I am doing something wrong that is why I keep getting the "location" error

slim plover
slim plover
marble raft
#

Actually figured it out, but damn took me nearly three hours

pliant sage
#

any idea why this doesn't work? I have added the ip to /etc/hosts

slim plover
jagged zenith
#

Hello who completed module nmap

marble raft
#

hey could i have a nudge on AD Skill Asssessment II?

Obtain a password hash for a domain user account that can be leveraged to gain a foothold in the domain. What is the account name?

turbid lily
jagged zenith
slim plover
jagged zenith
turbid lily
# jagged zenith Firewall IPS Evasion hard lab

ah, I did it a couple of days. You just have to use an example provided with ncat in the Firewall evasion session, using the same "source port" method. Try with the same port as in that example

turbid lily
marble raft
fair mesa
#

Hello everyone ! I am blocked at Password Attacks Lab - Medium ! I found the credentials of d***** & j**** but then on d***** I don't find anything interesting except the ssh private key but I don't have the passphrase for it please help, lot of thanks !

#

Oh also there is the Docs.zip document in which it talks a lot about inlane deployment service using maven, but I can't do a simple manipulation because I don't have root permissions

pliant sage
pliant sage
#

also tried blog and my

slim plover
slim plover
fair mesa
placid quest
#

@fair mesa what is the problem

fair mesa
placid quest
#

@fair mesa if u use ls -la what do u see

fair mesa
placid quest
#

@fair mesa how many uses do u see

fair mesa
#

how many users?

placid quest
#

@fair mesa yes how many uses do u see

fair mesa
#

I see 1 user but I know I feel like I can use this private key for the root user. But I don't find the passphrase

fair mesa
placid quest
#

@fair mesa how did u login with the first user

placid quest
#

@fair mesa dm me

grand fulcrum
#

I have a question There is anyone known Courses teach Web App Pentesting ?
I want learn Web App Pentesting

pliant sage
fair mesa
pliant sage
#

good

#

that's not the key for the root user tho

#

id_rsa I mean

fair mesa
# pliant sage good

Yeah there was hints as if it was the key for root user so it worked now I got into root thanks again

rapid sparrow
#

Need some help on file upload attack module skills assessment

rustic sage
#

is anybody else having trouble with the LFI page 8 (Log Poisoning) exercises? I don't get it to work with the examples from the page or the cheat sheet for that matter

rustic sage
#

pff n/m...typo ๐Ÿ™‚

unreal patio
#

I'm stuck on attacking common services - ftp
I've used hydra and medusa with the wordlists on the ftp but I find no user/password for ssh

placid quest
#

@unreal patio look closely and try to login with anonymous

unreal patio
#

@placid quest I logged in with anonymous and downloaded the two files and then used those with hydra and medusa, how many threads should I be using?

slate dome
#

firewall.wiki

placid quest
#

@unreal patio use xhydra

unreal patio
#

I'll try xhydra again with 12 threads now instead of 16

#

Because I've gone through that already ๐Ÿ˜ฆ

slate dome
#

fine bro

slate dome
#

ok

#

5 star

vital bough
#

did you have to use Ncat or was it just a scan?

placid quest
#

@vital bough it looks like he was trying to connect to a vpn

spring tundra
#

@slate dome could you please read the rules. Asking for illegal activity isnโ€™t welcome here

spare condor
#

I have the same problem. @vital adder I didn't use special character. I used the filename ||shell.phar.jpg||. Could someone help me with this one?

spring tundra
#

Ta

vital adder
vital adder
#

hint ||magic number||

spare condor
vital adder
spare condor
vital adder
#

sure

raven cairn
#

Good morning everybody

#

Going back to my CPTS grind peepoRedbull

sleek urchin
#

hello all, i just finished the the whole Footprinting module except for one question, which for IMAP / POP3: Figure out the exact organization name from the IMAP/POP3 service and submit it as the answer.

#

i have done nmap on the services/ip and found the organization name, but when i submit it, it's always wrong can someone help please, thx

#

what i have is

#

commonName=dev.inlanefreight.htb/organizationName=Inlan*

#

commonName=dev.inlanefreight.htb/organizationName=Inlan******

vital adder
#

hint ||the organization name have a Ltd in it||

sleek urchin
#

you are right, just submitted it

#

thx alot

placid quest
#

@low vine so u are doing cpts

low vine
#

Yea thats what I'm working on currently

#

I plan to take CPTS as a warmup for OSCP and see what happens

crisp remnant
#

Someone up for network enumeration with nmap module ?

placid quest
#

@low vine i am following cpts

low vine
#

I've been really happy so far, have definitely learned some things and will likely learn a ton throughout the course.

hazy grotto
#

Vulnerability Assessement module / OpenVAS skills assessment.
I have ran this scan so many times and I'm not getting the results i need.
In the description it gives a target IP and creds. Below the VM it gives entirely different creds and IP. Which one are we supposed to use? I used the ones at the top and the scan doesn't even start. Just goes from 0% to Done. When i use the creds and ip at the bottom it scans to 100% but I'm missing FTP and it seems like through the scan I'm not getting the results the questions are asking for. Can anyone DM me or help me with what configs I need to set up this scan properly?

ebon agate
#

guys

#

what happens if i say the n word here

placid quest
#

@hazy grotto u don't need run the scan because the ip address is already scanned

hazy grotto
placid quest
#

@hazy grotto yes read the scan

ebon agate
#

ima say it

#

pls dont hack me for this

placid quest
#

@ebon agate what is the problem

rustic sage
#

hackthebox or tryhackme? I've been using tryhackme but want to hear your guys' opinions

hidden meadow
#

they're both good

#

some stuff in tryhackme are locked behind payments, whereas hackthebox has much more free stuff to offer

#

but htb can be a bit confusing (im stuck on a question for like 2 days now lmfao)

#

but thats probably me being dumb though

vital adder
placid quest
#

@rustic sage Hackthebox goes deeper and sometimes u may stuck for 3-4 days without getting any answer so u may use Hackthebox after u have tried out tryhackme

vital adder
hidden meadow
#

^

#

me rn ๐Ÿฅฒ

hidden meadow
#

for tryhackme?

rustic sage
#

yea

hidden meadow
#

THEN DO THAT THEN INNIT

rustic sage
#

cus I needed to access the attackbox ๐Ÿ’€

#

ig

hidden meadow
#

can you not set up a vm?

rustic sage
#

thats what an attack box is

#

right ?

hidden meadow
#

no thats browser based

#

im talking oracle virtual box type vm

#

like actually on your pc

rustic sage
#

oh, yea, but the vpn connection is too slow

hidden meadow
#

ah ok

vital adder
#

if you need help pls just send the question, module and section you need help with also pls remove that (literally almost all right answer is there) and for that hint ||environment||

rustic sage
#

"origin message was deleted"

hidden meadow
rustic sage
#

dam, dirsearch is a very handy tool

hidden meadow
#

ive been using locate this entire time ๐Ÿฅฒ

hidden meadow
#

it isnt ๐Ÿ’€

#

welp

rustic sage
#

what cheat sheet

hidden meadow
#

time to try it one more time

hidden meadow
rustic sage
#

naw, I just happened to be using dirsearch for the first time

rustic sage
hidden meadow
vital adder
#

nope check the cheat sheet

#

or the command in that section

hidden meadow
#

I SEEEEEEE

#

thank you

#

i hope this works

rustic sage
#

bruh, what if Cross-site scripting worked on Discord messages ๐Ÿ˜ณ

#

instant grab everyones tokens ๐Ÿ’€

hidden meadow
rustic sage
#

๐Ÿ’€

#

small typo be like

hidden meadow
#

im so annoyed

hidden meadow
rustic sage
#

prolly had an extra space in there

hidden meadow
#

ive been stuck on a question for literally no reason

hidden meadow
rustic sage
#

lmao

hidden meadow
#

i cant remember what i input

vital adder
# hidden meadow im so annoyed

wait until you got a bug in one of the hard module at that poin you will 100% not sure if it's a bug or you are doing something wrong

hidden meadow
#

i even did ||locate mail|| and input so many of the directories i got from that

#

i wasted like 2 hours today and yesterday ๐Ÿ’€

hidden meadow
#

welp

#

i can finally progress

#

thanks

bronze stream
#

what should i know before starting in hack the box

hidden meadow
#

linux shell

#

basic commands at least

#

but they do teach you that in the linux fundamentals module

bronze stream
#

ill check that thanks

hidden meadow
#

np

#

also learn patience if you get frustrated easily. took me 2 days to answer a damn question cuz of a typo ๐Ÿ’€

vital adder
# bronze stream what should i know before starting in hack the box

Sponsor: https://go.intigriti.com/thecybermentor
Blog Post: https://tcm-sec.com/so-you-want-to-be-a-hacker-2022-edition/
Academy: https://academy.tcm-sec.com

Timestamps:
0:00 - Introduction
0:53 - Intigriti Sponsorship
1:55 - Building a Foundation
2:10 - Important Notes
5:37 - Basic IT Skills
8:28 - Networking Skills
12:38 - Linux Skills
17:04 ...

โ–ถ Play video
hidden meadow
#

what a thumbnail ๐Ÿ’€

bronze stream
hidden meadow
#

i have no idea if this is good or not, but my teacher recommended our class this in case we were interested in learning linux cli so see if you like it

bronze stream
#

yea well i know how to code , networking skills and basic it skills but i lk nothing about linux so i think ill start there

junior shell
#

So I am trying to figure out something in the Windows Privilege Escalation under subsection Communication with Processes. It seems as though I am supposed to use accesschk.exe to check for permissions, but accesschk.exe doesn't exist. Could someone point me in the right direction?

hazy grotto
#

What did you figure out?

marble raft
#

Hi guys having some trouble with the question

Use a common method to obtain weak credentials for another user. Submit the username for the user whose credentials you obtain.

I'm already inside MS01 but whenever i run Import-Module .\DomainPasswordSpray.ps1 i get an error

Figured it out, in the .ps1 script there is a variable called $Message:

Well Powershell doesn't like it that way, so it should be changed to ${Message}:

Awesome explanation here: https://stackoverflow.com/questions/61581718/powershell-variable-reference-is-not-valid-was-not-followed-by-a-valid-va

thorn urchin
#

The question hint will point the right way

broken warren
#

Can some one help me with file inclusion >. File inclusion prevention. I don't understand what they mean by make a webshell and execute using system(). I think I found where the disable functions place is in the ini file but idk if I'm editing that correctly either

marble raft
thorn urchin
#

Awesome, but its still the wrong path ๐Ÿ˜›

#

oh wait I may be thinking of a different question

#

ye nvm

vital adder
junior shell
sly reef
#

hey guys can someone help me out with hashcat final exercice?

#

tried everything

vital bough
#

aaaaannnnnd I got it

ruby ivy
#

hello

raven cairn
vital adder
#

about to say videos showing beginner where and what to learn to get started is always good, mind shamelessly plug your channel? already did

#

oh wait when did they updated the ptf? the last time i check from hackersploit that thing was super outdated

broken warren
#

Has anyone been able to install tplmap? I try from the exersise but I keep getting an error when I do pip install requirements

vital adder
#

it seems so and i may miss remember this also i got 0 idea when is the last time i check but i think the last time i check it wasn't getting any update in years

vital adder
coral ginkgo
#

Hello guys hmmm

#

Im new in the hacking and hackthebox

#

I'm not going to tryhackme because although hackthebox is also paid for some rooms, I can't pay and hackthebox seemed better than tryhackme

#

and I wanted to ask something

raven cairn
#

I have a video that I posted to help out noobies

#

Also wut is your question

coral ginkgo
#

when install to connect OpenVPN, q put tcp or udp

raven cairn
#

I usually do UDP

coral ginkgo
#

Hm okay very thanks

raven cairn
coral ginkgo
coral ginkgo
#

lol hmmm

raven cairn
#

Do they speak SPanish or Portuguese in Argentina?

coral ginkgo
#

Spanish, portuguese? Wtf lol

#

that is spoken in brazil and portugal

raven cairn
#

oh my b. I thought they spoke spanish because online it says Spanish is the official langauge

vital adder
broken warren
coral ginkgo
#

Guys, is there a way to verify me or something like that to be able to send images?

vital adder
raven cairn
vital adder
marble raft
#

hey there, need some help with

Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host.

On AD Skills Assessment II.

Tried logging in both through skills-par01 and my own attack host which is connected via sshuttle to the 172.16.6.0/23 network but the login fails with this error

ERROR(SQL01\SQLEXPRESS): Line 1: Login failed. The login is from an untrusted domain and cannot be used with Integrated authentication.

Any typs?

thorn urchin
#

what are you trying to login with and as?

#

and to what?

pastel ginkgo
#

Working on the into into Bash Scripting, is Bash like python where whitespace matters?

#

For example I found that if my echo statement in my if wasn't tabed it didnt work correctly?

marble raft
#

can i dm you @thorn urchin ? as to avoid pasting creds here

thorn urchin
#

sure, but im at work so may be slow to respond

zenith schooner
#

anybody on footprinting DNS questions? there is something that I don't fully understand: If I make a zone transfer dig axfr <domain> @<DNS SERVER> I can see several DNS entries. I guess all for that domain. But, if I type dig ANY <subdomain>.<domain> some entries return the IP as I expected but others doesn't. It is normal? If anybody can help me,please? DM or directly here. Thanks

pastel ginkgo
sly reef
#

guys can someone help me out with hashcat module?ยฟ

zenith schooner
#

but dig dev.inlanefreight.htb doesn't return the IP but app.inlanefreight.htb return the 10.129.18.15. It looks like weird for me.

placid quest
#

@zenith schooner maybe dev.inlanefreight.htb has a another subdomain

placid quest
#

@zenith schooner i mean if the website has top domain and a subdomain maybe that subdomain has another sub-subdomain

zenith schooner
thorn urchin
#

they do not mean internal

#

subdomains can have more subdomains

#

thats just how subdomains work

placid quest
#

@thorn urchin thanks for more information

thorn urchin
#

whether or not theyre internal is a matter of routing, mot DNS

pastel ginkgo
#

a good example would be say you have 4 different sites with their own sharepoint. So detroit.us.inlanefreight.htb, newyork.us.inlanefreight.htb etc.. They are all members of the us.inlanefreight subdomain which is a member of the inlanefreight domain.

pastel ginkgo
#

Anyone familiar with bash scripting? I'm trying to write something like:
a.length() < x which would work in something like python. But in Bash im writing it like:

[echo var | wc -c ] -gt $x but idk how to make bash to evaluate the enclosed item first before doing the comparison.

warm lichen
#

Use pipes

pastel ginkgo
#

wouldn't || be an or statement?

warm lichen
#

Pipes get evaluated left to right so if you add a second pipe it would just evaluate the output of echo $var | wc -c

#

..I say that without actually testing it on my machine ๐Ÿ˜„

pastel ginkgo
#

hmm the problem is that it dosn't do the greater than operation after what ever wc is returning

#

im getting -gt not found

warm lichen
#

Let me play around with it. I assume it would be because you need to pipe things into a function, -gt looks like a flag for something

pastel ginkgo
#

-gt is supposed to be a int operator

warm lichen
#

what output are you hoping to get? Boolean?

ashen orbit
#

I'm trying to get the flag in the Getting Started Public exploits. I get the exploit to comple for WordPress Simple Backup File Read Vulnerability. I got the file but not sure what to do with it.

pastel ginkgo
#

The issue it appears is that it assumes the -gt is an operator part of wc, but if I put the entire previous statement in a () it gives me echo command not found

warm lichen
#

Yeah I understand now

#

I'm not sure pipe would solve your issue

#

I think you'll need to use in-line bash or something similar, I'm trying to find the syntax for it now

#

Like wc -gt <<evaluate bash here>>

warm lichen
pastel ginkgo
#

I figured I could just do the wc and put the result in another variable then check it

#

not sure if thats working yet since wc isn't returning me a character count for some reason

warm lichen
#

can i see?

#

Oh

pastel ginkgo
warm lichen
#

Btw the -c flag is byte count, not character count. But I guess it would be the same in most cases anyway

pastel ginkgo
#

I did -m and it didnt work either

#

figured that part out, idk why you need to echo it but that what it wants

warm lichen
#

Ahh right lol. Yeah that's weird

#

Why did you have to use bash and not just python? ๐Ÿ˜„

pastel ginkgo
#

im doing the bash module lol

warm lichen
#

Fair enough then

pastel ginkgo
#

I took it because I more or less wanted to figure how to make very basic scripts like, do nmap take xml results into html and open firefox with them

warm lichen
#

Yeah true. I always just stumble through bash when it requires more than just basic piping or for loops

#

I might do that module

thorn urchin
#

the secret to bash one liners is to just excessively pipe things and eyeball the results until you see what you need to add to the change

#

nobody does cat file | awk blah | sed s/blah/bleh | grep 'dub' | ect ect off the top of their head

#

people who do that are psycopaths

zealous belfry
#

yo doing PtH from Linux in password attacks. Just wondering when configuring proxychains the section just said use socks5 and port 1080 but im kinda wondering why we need to use port 1080.

#

just checked its for the socks proxy service well..

pastel ginkgo
#

@warm lichen I figured it out if your interested, just know its the answer to a module

thorn urchin
zealous belfry
#

do they? In the section it looks like its on 8080 ```sh
sudo ./chisel server --reverse

2022/10/10 07:26:15 server: Reverse tunneling enabled
2022/10/10 07:26:15 server: Fingerprint 58EulHjQXAOsBRpxk232323sdLHd0r3r2nrdVYoYeVM=
2022/10/10 07:26:15 server: Listening on http://0.0.0.0:8080```

#

thats why im wondering

warm lichen
thorn urchin
#

if you were say running the server on the target host, and then connected it with the client, the interface the client creates is usually 1080

#

so just depends on how youre using it

raven cairn
zealous belfry
#

aw yea also just browsed through the docs and obv they mention it "R:socks" will listen on the server's default socks port (1080)

drowsy sedge
#

Hello Iโ€™m stuck on cracking the Mr Gates ssh FeelsBadMan I tried many wordlist and spending so much time on this module , any clue to which dictionary choose?

wheat garden
#

what does this tag do and why does the bruteforce fail without it?

#

crack map does not have a man page and the --help is rather minimalist doesnt even mention that tag

lyric dome
#

Hello everyone,

#

Ive been stuck on active subdomain enumeration for awhile

#

I need help on the syntax of zone transfer

#

and how to use dig axfr

graceful mortar
#

what is the easiest way too transfer from xfreeRDP files between windows/linux?

rustic sage
#

Is the bug bounty path worth it?

feral stump
rustic sage
#

ok ive just passed my oscp and was looking to really hone down on my web skills.

#

Looks like i will try that path first and then move onto burp certified, then oswe.

thorn urchin
# graceful mortar someone?

if you dont particularly care about opsec stuff, the +home-drive option will auto mount your linux home dir.

placid quest
#

@graceful mortar using smbserver is the easiest method

thorn urchin
#

no Im about to fo to bed

pearl island
thorn urchin
#

maybe

desert iris
#

I'm working on Linux Fundamental - Find files and directory and I'm encoutering trouble w/ the find command

#

the question is: What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?

#

my command is

#
find / -size +25k -size -28k -newermt 2020-03-03 -exec ls -la {} \; 2>/dev/null
#

but I don't find the right answer

#

what's the prob?

acoustic owl
# desert iris what's the prob?

You want to find a config file.
So you have to declare that in your search as well
|| -name "*.conf" ||

It is not quite clear to me what you intend by this
-exec ls -la {} ;

desert iris
#

oops I do grep config and also -name *.cfg

#

the exec part is just to list all the file the find command found then do a ls -la against it

#

easy to look at

acoustic owl
gray ocean
#

Hello im new

pliant sage
#

is it normal that I can't connect to the mysql db remotely in attacking common services lab easy?

#

telnet can't reach it either

#

nevermind

jagged zenith
#

Any one completed module nmap

#

Firewall Evasion hard lab

rustic sage
#

Academy Dashboard is giving a 502

jaunty halo
#

Yes, it's giving a 502

green pollen
vital adder
#

i'm in a module right now and after a refresh everything is still fine (also the pwnbox)

ripe badge
#

me too

#

but you can't submit the flag in the module ๐Ÿ˜ฆ

rough thunder
#

can anyone help with LLPE? I am at the skills assessment and I'm stuck on flag 4

pliant sage
#

can anyone help me with attacking common services lab easy? I've been at it all afternoon and I'm obviously missing smth but I don't get what

loud sapphire
#

Hey so i found out that i didnt use the intended strategy for Password Attacks - Medium Lab....... Is this something that needs to be patched out so that the intended strat is the only solution or......... are we ok to use other means?

mellow turtle
#

@vital adder Are u on?

vital adder
#

yep

acoustic owl
#

Feel free to DM me

unreal patio
#

I'm currently stuck on attacking common services smb,
xhydra says it's lacking libsmbclient for smb2 which I've downloaded and reconfigured xhydra with but to no avail

#

If I use the normal reconfigured hydra it only gives false positives on smb2 and on smb it doesnt crack the pw

loud sapphire
loud sapphire
unreal patio
#

I just had to add --local-auth to it

loud sapphire
#

oh ok

zenith schooner
#

Hi, I am working on Footprinting DNS module. I already anwered almost all the questions. The first one is not yet solved because I don't understand what they actually ask. Anyone can help me what I am looking for? Any teacher on the room? ๐Ÿ™‚

acoustic owl
# zenith schooner Hi, I am working on Footprinting DNS module. I already anwered almost all the qu...

It asks you for the FQDN of the nameserver
https://en.wikipedia.org/wiki/Fully_qualified_domain_name

A fully qualified domain name (FQDN), sometimes also referred to as an absolute domain name, is a domain name that specifies its exact location in the tree hierarchy of the Domain Name System (DNS). It specifies all domain levels, including the top-level domain and the root zone. A fully qualified domain name is distinguished by its lack of ambi...

zenith schooner
rustic sage
#

Good morning colleagues I have a problem to install apache2 in kali I get this and I do not know what to do.

#

i can't install apache

vital adder
#

i don't know about apache but apache2 is pre-install on kali

rustic sage
#

apavhe2

#

apache2

sly tapir
rustic sage
#

In the console I get this

#

E: Could not get lock /var/lib/apt/lists/lock. It is held by process 47836 (apt)
N: Be aware that removing the lock file is not a solution and may break your system.
E: Unable to lock directory /var/lib/apt/lists/

#

and I cannot connect to localhost

sly tapir
#

Did u try doing a: ps aux, look for PID and then kill it with kill -9 PID

rustic sage
#

ok

sly tapir
#

U can do โ€œps aux | grep aptโ€ and it should filter it to that

rustic sage
#

[sudo] password for kali:
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
apache2 is already the newest version (2.4.54-3).
0 upgraded, 0 newly installed, 0 to remove and 481 not upgraded.

#

But when I connect to the localhost it tells me that I cannot connect.

clear stump
#

you need to start it using
sudo service apache2 start
or
sudo systemctl start apache2

#

or enable it to make it run on startup

thorn goblet
#

Hello, i think there is a problem with the server of the box from the Session Hijacking / XSS. I tried to get a response from every parameter of the form with Burp but i fail to see any connexion on my server acces log. While the same thing worked for the Skill Assessment.

crisp remnant
#

Anyone for network enumeration with nmap module ?

loud sapphire
#

How to mount Bxxxxxp.vhd in linux? its encrypted with bitlocker but i have pass.

pliant sage
# loud sapphire How to mount Bxxxxxp.vhd in linux? its encrypted with bitlocker but i have pass.
Linux Uprising Blog

This is a guide on how to access a BitLocker-encrypted Windows volume from Linux, useful in cases of dual-booting Windows 10, 8 or 7, and a Linux distribution. It covers how to decrypt and mount the BitLocker partition from the command line, as well as how to add it to /etc/fstab, so it's automatically mounted on boot.

loud sapphire
#

thank you

mellow turtle
#

@pliant sage Nice ty

pliant sage
#

np

#

if anybody can answer a question about common services - medium lab btw that'd be great

mellow turtle
#

let me check if i have notes

#

where are u stuck on @pliant sage

pliant sage
#

imma dm u

mellow turtle
#

Okey

rustic sage
#

it is easier

#

ans faster

#

everyone should have a Comando VM hahaha

loud sapphire
rustic sage
#

awesome

loud sapphire
#

@rustic sage Comando VM? whats that?

rustic sage
loud sapphire
lethal shard
#

Hello! i do Skills Assessment part 1 in ACTIVE DIRECTORY ENUMERATION & ATTACKS. Stucked on 4 question. How i can connect to MS01? Tried instances SQL, lsass dumped. Computer SQL01 is not responding. What i need to try?

loud sapphire
#
mellow turtle
#

to build .vhd without taking it to ur windoows

mellow turtle
#

nice if i stuck there ill ask u xD @lethal shard

lethal shard
pliant sage
#

yo

#

common services lab -hard

#

why the hell do I get this when I try to read the flag?

mellow turtle
#

@pliant sage no idea

thorn urchin
wary river
#

Can anyone help me out for a movie with the final knowledge check for getting started? Iโ€™m not sure what Iโ€™m doing wrong, but trying to run the RCE exploit for get simple metasploit keeps saying it canโ€™t make the session

#

"Started reverse TCP handler on <ip>
Exploit complete, but no session was created.

lethal shard
wary river
#

i dont think ive used msfvenom

#

using the search exploit on metasploit

#

i was watching a walkthrough for it and they did the same thing i did, im not sure if its something i did earlier that messed it up or if theres something else i have to configure

#

nevermind i think im just stupid

elfin pulsar
#

is 911 still working

wary river
#

what

#

the emergency service?

wary river
mellow turtle
#

send us a image

#

and let us see how u configured the options

#

@wary river

wary river
#

alright, yeah

#

unless thats exactly what it's supposed to do and im stupid

mellow turtle
#

can u send me a image of "ifconfig" result?

wary river
#

here it is

mellow turtle
#

try with tun0 ip

#

done true?

wary river
#

let me try really quick

#

yes! that worked, thank you!!!

mellow turtle
#

When u are connecting to htb u have to use tun0 ip

#

because thats the "ip that can see" other machines in htb network

wary river
#

okay, that makes sense, tun0 is the ip from the vpn?

#

the tunneled ip?

mellow turtle
#

yep

limber ledge
#

can someone help me with password attacks module

#

"Find the user for the WinRM service and crack their password. Then, when you log in, you will find the flag in a file there. Submit the flag you found as the answer."

#

not sure where to start

placid quest
#

@limber ledge try brute force method

ashen orbit
#

fuck I suck at this shit, always have to look up answers haha

placid quest
#

@ashen orbit That is the best thing and that is what makes learning beautiful thing

ashen orbit
#

lets hope I get better, thinking to much sometimes, i was going to execute dirty pipe exploit when I just had to change to a directory

unique valve
solid quarry
#

Hacking Wordpress - Skills Assesment last question, I can't find any credentials, I found the wordpress location but I can't read php files with the lfi vuln (Found it, banging my head for something easy...)

ashen orbit
unique valve
ashen orbit
#

So when doing privilege escalation, it says you can run scripts, but when I transfer the scripts to the sever, you need root access? How would they help?

placid quest
#

@ashen orbit maybe sudo script name

ashen orbit
pastel ginkgo
#

On Pivoting Tunneling & Port Forwarding, I can see the reverse proxy connection coming in but I don't have a meterpreter connection

#

Any ideas as to why I don't have a console with metasploit? Its clearly coming back to me correctly.

#

check your directory

#

you might of not uploaded it to your current directory

#

or try ./LinEnum.sh

rapid fjord
#

ok thanks, will try tomorrow as i closed the shell by mistake ahahhaha

balmy radish
#

when doing a wget from the victim machine you need to include the LinEnum.sh part in the url, in the response you posted it would have returned index.html

vocal vortex
#

Hi there,
I'm currently doing the web service and api attacks skills assessment.
This is the question Submit the password of the user that has a username of "admin". Answer format: FLAG{string}. Please note that the service will respond successfully only after submitting the proper SQLi payload, otherwise it will hang or throw an error.
I manage to get do the sqli and get the password in md5 format, do i need to crack it ? or i need to interrogate the DB to get it in clear text?

simple merlin
#

Hi someone might help for Skill assessment I - Introduction to deserialization ?

pastel ginkgo
#

Anyone else have issues with the pivoting module? I can't get metasploit to play nice with my socks server for whatever reason. If I try to open one in Metasplot it crashes instantly.

gleaming rapids
#

Anyone good with finding IP address please dm in need of help $$

zealous belfry
#

anyone got an idea why johns not doing what its supposed to do ?

#

used ssh2john id_rsa > id_rsa.hash before to convert

hidden trellis
#

hi can anyone help with Windows Privilege Escalation - Weak Permissions... i have membership of the admin group but cant get access to the admin directory

balmy radish
#

will john unzip the .gz for you? I always just point it at the txt file

zealous belfry
runic moth
#

is having a napalm watergun illegal

paper gust
#
  1. i dont believe john supports running gzipped wordlists inline, though hashcat does these days
#
  1. it is doing exactly what you asked it to
#

the reason it appears to be completing instantly is because that's how long it took to go through the candidates you loaded, especially in the case of the gzipped rockyou since that loaded as a bunch of garbled text, which you see on the right side, so the total number of lines was probably much smaller than the already minimal rockyou

zealous belfry
#

So okay, but when using the txt file it's finishing instantly as well. It cant be that fast checking all the hashes tho

#

(im on the zip one)

green pollen
#

l'm stuck in these question too.
Can i dm you for help? plz.

paper gust
#

there's only 14M passwords in rockyou

#

and its doing 10M/second according to that screenshot

#

so only should take 1.4 seconds

rustic sage
#

Okkkkkkkkkk

balmy radish
#

Some hashes are faster to calculate than others

zealous belfry
zealous belfry
vital adder
zealous belfry
#

used all the mutated and normal once from the course

vital adder
vital adder
zealous belfry
#

Password attacks

#

protected archives

vital adder
vital adder
#

also i'm pretty sure this is not the case but try to unzip that file there could be a another zip file in there and that's the file you're supposed to crack

zealous belfry
#

nah this one is pw protected

#

i tried all of the mutated once .. kinda sux

vital adder
#

so i just give it a try and it's working fine for me

zealous belfry
#

huh

vital adder
#

if you want to double check the hash shoot me a dm if your hash

vital adder
#

or if you can on a different machine

zealous belfry
#

a07a87ddfd01e9e105dfaa540a2ff75b md5 of the hash

vital adder
#

of the zip file?

zealous belfry
#

yes for u to check

#

nah wait doesnt make sense because the name is integrated in the hash ill shoot u a dm

vital adder
zealous belfry
#

461d6bc95b03112697102d13f880ac33

#

the zip is fine

fierce coral
#

Just want to share how I managed to solve RDP and SOCKS Tunneling with SocksOverRDP exercise following the steps in the section.

After configuring Proxifier, I ran mstsc.exe ||(not as administrator)||. The "User name" needs an additional information: ||The hint mentioned that Jason is a local account||.

Initially I used the alternative method of using netsh.exe shared by user 19delta4u in the forum . From 172.16.5.19, I RDP normally into 172.16.6.155 without success. Using the hint, I tried to play around with switching user and saw that it prompted what was the extra information it needed.

graceful mortar
#

im trying to connect with xfreerdp and i got this error [171895:171896] [ERROR][com.freerdp.core] - transport_connect_tls:freerdp_set_last_error_ex ERRCONNECT_TLS_CONNECT_FAILED [0x00020008]

#

i think is my xfreerdp version ๐Ÿ˜”

sturdy igloo
#

Try Rdesktop

hollow thunder
#

Need assistance/nudge. AD Living off the land final question

"Utilizing techniques learned in this section, find the flag hidden in the description field of a disabled account with administrative privileges. Submit the flag as the answer."

RDP keeps crashing so taking a break

stiff tapir
#

Hello, I am using Mac and i want to setup openvpn and want to complete htb challenges locally. I also have Kali Linux in my virtual machine. Can someone tell me what is the process?

rustic sage
#

Hello fellow heqrs... I must say this discord business is making me feel like quite the boomer trying to figiure the tv remote out for the 300th time.. Anyways, brb, gotta get these kids of my lawn again, thanks for having me!

#

(did i already use the wrong chat ๐Ÿซฃ

clear stump
stiff tapir
clear stump
stiff tapir
clear stump
#

the academy require openvpn

stiff tapir
#

Ahh i get it now.

vocal vortex
low vine
#

Dont want an answer but would like to be pointed wher I need to read more. Currently working on Information gathering - web edition ||Submit the FQDN of the nameserver for the "inlanefreight.htb" domain as the answer.||

#

Not sure if i'm just mentally strugling right now as I feel this would be extremely easy to figure out and find nad I'm just mentally lapsing

#

Wait

#

Mental collapse confirmed ><

placid quest
#

@low vine use dig ns

low vine
#

I figured it out literally right after I asked

#

I did try ns but let me try that again

hidden trellis
flat karma
#

hey everybody , i m stuck in privilege escalations exercices in module getting started. I dont understand , how i do read flag.txt in /root/flag.txt , someone want help me ? thanks

little wyvern
#

Hi I am working on footprinting medium and stucked here.. got one username from nfs share with a password but when using it with xfreerdp get an error because password contains !mD... Anybody could help or send me a write up?

placid quest
#

@little wyvern u can use '

little wyvern
little wyvern
#

As I read back the messages an important.txt is needed for sa creds.... Where can I find it? Thanks

placid quest
#

@little wyvern on smb server

little wyvern
#

Ok meanwhile I found it on alex windows..devshare

#

But login failed for user sa with this cred on SQL server...

placid quest
#

@little wyvern try with Administrator

little wyvern
#

Can't believe just finished this finally..... Thanks @placid quest

low vine
#

Btw @placid quest @vital adder and the couple others I see constantly helping / explaining things to people in here. You guys are awesome and hopefully I can give back / spend free time in the same way once I've mastered this a little more.

#

Dont know if theres a way to buy yall like a month of HTB or some gift certificate but would like to if thats possible.

rustic sage
#

am in exact same situation. The provided commands in the section easily give a shell, but it is a shell where you cannot run mimikatz. Need a nudge

unreal patio
#

For some reason my pwnbox doesnt have sqsh install by default

#

It's in the binaries but when I try to run it it says command not found

placid quest
#

@unreal patio use packages to install sqsh

vital adder
vital adder
vital adder
vital adder
vital adder
flat karma
#

@vital adder Thanks , i find the flag after long time of search ^^

vital adder
#

congratz

rustic sage
low vine
#

Yea its just obvious they spend alot of time helping people out.

astral zinc
#

Hello! I just started doing the modules on HTB Academy, and I'm wondering if its possible to connect openvpn and work from my own VM directly instead of using the pwnbox? I do it in HTB, but i can't seem to find that option in the Academy

#

or maybe I just need to connect to my normal htb ovpn file?

vital adder
#

yep that's what you need to do and you can get some more info about this in the Getting Started module Connecting Using VPN section

astral zinc
#

alright, thanks for you help!

rustic sage
#

returning to the question of Attacking Domain Trusts - Child -> Parent Trusts - from Linux, what is the hashcat -m for 'aes256-cts-hmac-sha1-96s' or maybe am on a wrong path hmm

flint birch
#

Hey does anyone know how to trouble shoot commands in modules that are supposed to work that don't work? specifically accesschk.exe for \.\pipe

clear saffron
raven cairn
storm jackal
rustic sage
#

great resource, will bookmark!thank you

frank blaze
raven cairn
#

I have a really stupid question. I'm on the Active Directory Enumeration and Attacks Module - Internal Password Spraying from Windows section. performed a file transfer from my machine and I am trying to get DomainPasswordSpray.ps1 to work.

#

why does this not work. my powershell skills suck haha

twin gulch
#

Hey guys
Iโ€™m at password attacks at module passwd, shadow and opasswd.Any who figured it?

thorn urchin
#

lots of people have figured it out, you should ask your real question of what youre having issue with

thorn urchin
raven cairn
#

YEah. Hackthebox academy recommends weird tools sometimes

thorn urchin
#

if you can launch your attack fron a linux host and/or via a tunnel thats usually better tradecraft anyways

#

which makes me terribly sad that mimikatz can still catch a few things in memory that secretsdump.py cant

#

tripped me up on a skills assessment for that reason

twin gulch
#

Well I got that I need to perform an edit to passwd file to continue finding the password of root user, but I neither can edit the file or the shadow file of that, I can scp it to my main system but cannot scp that inside for edit
I need to find a way to remove that โ€˜xโ€™ from the file

thorn urchin
thorn urchin
#

iirc that section was more about unshadowing it to crack the passwords, but maybe my memory is faulty

thorn urchin
twin gulch
#

It is more about unshadowing, but should I do it when Iโ€™m scp the file to my system or from the ssh by some tools I can place in?

thorn urchin
#

if you can read the necessary files I would pull them down and do it locally

#
  1. less artifacts on the target so better tradecraft and 2. youll be feeding the results into john or hashcat anyways so might as well have it locally
lament tartan
vital adder
thorn urchin
#

if there was one other "complaint" id have about CPTS is that it usually only hints at better tradecraft but doesnt actually teach it. But thats a matter of the scope of it. Including all that stuff would probably double the amount of content and make it 2x as hard. But where you can practice good tradecraft it doesnt hurt to do so.

thorn urchin
lament tartan
#

one sec

raven cairn
raven cairn
#

I know it's pretty easy but I am just really used to unix stuff

lament tartan
#

basically just add a space before the colon in Message:

twin gulch
#

I scp out the passwd.back

#

Shadow file from my local

#

Unshadowed it

#

Well Iโ€™ll make some progress and back

thorn urchin
#

otherwise youll just wind up trying to crack your own passwords lol

twin gulch
#

But I cannot perform any action on it

#

Trying again

thorn urchin
#

sure there isnt a shadow backup either?

lament tartan
twin gulch
#

Omg

#

Just found that shadow.back

#

Bak **

raven cairn
lament tartan
#

sure ๐Ÿ™‚

raven cairn
#

also your channel is cool btw

brazen apex
#

Ayyy

#

It's crypto cat!

#

@lament tartan love watching your videos man

twin gulch
thorn urchin
#

Enumeration is king

#

if I could pick any aspect of hacking to instantly become a god of, itd be enumeration. Because by proxy thatll make you a god of just about everything else too

twin gulch
#

Got the shadow.Bak out, unshadowed it and now hashcating the hashes

thorn urchin
#

nice

raven cairn
#

Imo they should change up this section a bit

#

I don't know how TF I am supposed to know to add a space to somewhere in the script

lament tartan
#

youll run into a lot of scripts/exploits that dont work, quite often they arent even maintained but youll see other people have raised issues and worked out fixes

#

i have to run some random command to fix docker each time i boot Parrot. i found the fix in a git issue comment like 6 months ago and theres just never been a patch i guess xD

thorn urchin
#

seeing functioning pull requests from months or years ago but just never accepted is always heartbreaking

#

esp if the og dev is still active and could just accept it and move on

brazen apex
#

Does anyone have or know of a website/youtuber that has write ups for the academy modules