#modules

1 messages ยท Page 22 of 1

lament tartan
#

yeh even worse is when they turn issues off altogether! even if devs dont have time to fix, other users can post their troubleshooting steps/fixes if they leave them open ๐Ÿ˜ซ

#

i think because the academy is paid content, only the tier 0 modules are allowed public walkthroughs

little wyvern
#

Hi I am doing footprinting hard lab, figured out that snmp server is v3 but cannot find commmunity string..used onesixtyone with snmp seclist but nothing only got ,,linux nixhard 5.4.0_90 generic #101 ubuntu smp but no community string...and I could also interact with imap and pop3 servers but not sure what commands shall I use on Imap..or am I on a wrong track? Donnot know from where can I get the rsa for ssh...

thorn urchin
#

yeah module writeups would be pretty anti-thetical to the purpose of the modules

#

not like challenge boxes where a writeup might teach you about a new technique or attack. The module already does that, you just have to apply it.

charred hedge
#

Is this the right place to post questions about module exercises?

#

I'm super stuck.

thorn urchin
#

I mean looks like ya got it to me

charred hedge
#

It asks for the version for service running on 8080. Looks like Apache Tomcat/9.0.31 is running on 8080 but it says that 9.0.31, 9, 9.0, Apache Tomcat, etc are all wrong

charred hedge
thorn urchin
#

which module/section are you on? I'll review it real quick

charred hedge
thorn urchin
#

ah gotcha, yeah the Apache Tomcat youve tried is correct. If you copy pasted make sure you didnt accidentally include and extra space somewhere

charred hedge
#

9.0.31 gives me an error...

thorn urchin
#

well thats not the one I said was correct so lol

charred hedge
#

rekt. Thanks for confirming I'm not crazy. Must just be a bug on their end.

thorn urchin
#

99/100 times its just an errant space from copy paste

#

its a strict text matching ๐Ÿ™‚

brazen apex
#

Or I find out that I had the answer the whole time I just wasn't pasting the whole thing

thorn urchin
#

Dont take me the wrong way here, but thats a very poor way to approach the material

brazen apex
#

It isn't if you study

thorn urchin
#

itll bite you in the foot come skill assessment or exam time

brazen apex
#

The whole point is to learn how to use the tool

#

So that I can start using it an real engagements

#

That's what I've been doing

thorn urchin
#

not really, the CPTS is focused on TTPs

brazen apex
#

Okay then what should I do

thorn urchin
#

but lets say your way is right, copy pasting things isnt really learning the tools either

brazen apex
#

If studying and applying the material in real scenarios isn't enough

#

Wdym copy pasting?

thorn urchin
#

Im just quoting what youve said my friend

brazen apex
#

I mean once you get a flag

#

Sometimes I don't copy the whole flag

thorn urchin
#

ah gotcha

#

thats very different than what your comment originally sounded like lol

brazen apex
#

Yeah I get that a lot

#

I have a hard time conveying what I say

thorn urchin
#

wdym by not having the time to try every method and option then? before I criticize that specifically and you actually meant something else

brazen apex
#

No I think you understand what I mean by that

#

I try quite a few different methods

#

And then I try what the module is asking in the directions

#

I get stuck

#

And look it up

#

Well

#

I try to look up guides on how to use x tool first

#

Then I start looking for write ups

thorn urchin
#

ah well, part of the whole cpts and teaching TTPs is comprehensive approaches. Enumeration is key in the real world and it applies here too. You should be trying everything because in the real world your job may literally be trying everything. Red teams can be a little different, but standard pentests want a comprehensive approach. They dont want to know just thr one way you got initial access, they want to know the myriad ways of getting initial access for example.

brazen apex
#

Yeah I definitely agree with you but I usually just have so many other factors I'm dealing with

#

I prefer this kind of self education

#

But

thorn urchin
#

its a demanding field

brazen apex
#

I'm also taking 16 credit hours

#

Along with a part time job

#

I just feel like I'm wasting my time when I look at

#

Estimated time:45 min and I've spent like

#

2 hours on it

#

It's discouraging I guess

thorn urchin
#

I feel it, but its not something you can shortcut and do well on later

#

dont worry about the time estimates, theyre all bullshit

#

the 41 days or so overall estimate btw is assuming 1 day = 8 hours of active work for each day

#

the first dude who passed the exam already had half the modules done cause of the CBBH and had full time security job and still took 49 days to complete the rest.

#

Ive had days where I blitzed 3 modules in one day, and then 2 weeks on a module that says 2 days.

brazen apex
#

Damn okay that's a bit relieving lol

thorn urchin
#

I literally do not look at the time estimates at all

brazen apex
#

Alright I appreciate the advice man I'm gonna go back to htb and try my best

thorn urchin
#

good luck

brazen apex
#

I made it a lot farther on tryhackme

#

Only cause they have a write up for every activity

thorn urchin
#

remember the golden rule: HTB easy is THM medium/hard

brazen apex
#

I think you got that backwards

thorn urchin
#

this platform is just objectively more advanced in difficulty than THM

brazen apex
#

I breeze through thm

thorn urchin
#

Yes thats what Im saying

brazen apex
#

Okay

thorn urchin
#

"easy" ranked HTB content is more equivalent to medium or hard ranked THM content and it only goes up from there

#

and cpts is a whole mix of easy and medium modules

brazen apex
#

Sorry had to do something @thorn urchin

#

Do you have any suggestions advice on where to start in Red Teaming

#

On htb

thorn urchin
#

I mean the cpts itself is a good start. Theres also the pro labs that are whole simulated networks so theyre really good. Dante in particular gets heavily recommended as extracurricular exam prep after youre done with the modules.

Difficulty with red teaming specifically is that theres a slight shift of general approaches and goals compared to regular pentesting, and so a lot of educational content is ill suited for it. A lot more of like C2 domain name preps, EDR evasions, phishing, state of the art attacks like ADCS attacks.

brazen apex
#

Dante yeah me and a buddy were planning on doing an engagement on dante

thorn urchin
#

id focus more on nailing general pentesting stuff before worrying about red team content. There is no real jr red teamer that isnt already senior pentester basically lol

brazen apex
#

Ah alright idk I've just heard a lot from friends in the field

#

You don't know who has the best advice on all that but I agree

thorn urchin
#

no worries mostly Im parroting what Ive heard as well

brazen apex
#

I think I should study more tools in pentesting before attacking ADs

thorn urchin
#

CPTS modules have a couple excellent ones dedicated to AD anyways

#

the Active Directory Enumeration and Attacks module is a mammoth, expect to spend a lot of time on that one

#

30+ sections lol

brazen apex
#

Dumb question but what are CPTS

thorn urchin
#

its the HTB certification

brazen apex
#

Sorry if I'm talking your ear off man

#

Oh okay

thorn urchin
#

if youre doing modules youre typically on either the CPTS or the CBBH paths for their certs

#

CPTS is meant as a competitor to the OSCP

brazen apex
#

I wanted to take the oscp down the road

#

But if I can start studying it now that'll definitely help a ton

thorn urchin
#

np, typically in this channel the assumption is that youre going for one of those two

brazen apex
#

The cbbh path is bug bounty I'm guessing?

thorn urchin
#

yeah, greater focus on web app pentesting stuff

brazen apex
#

Is there a equivalent of that cert?

#

Like the oscp

#

Web app pentesting sounds like a nightmare to me

thorn urchin
#

I think portswigger has some certs that are comparable or even more in depth(theyre the burpsuite guys afterall). Other than that the only ones that come to mind are pretty minor stuff

lament tartan
#

but yeh portswiggers web security academy is amazing

#

and they have a cert for it now

vital adder
#

oh yea their cer is going to be $9 on black friday so i'm definitely going to do that cer in a few months

lament tartan
#

they were doing it for free when they released it

#

problem is you need burp pro

#

so its not really free ๐Ÿ˜„

thorn urchin
#

does burp pro still have lifetime licenses?

lament tartan
#

nah like $400 a year i think

#

last i checked

thorn urchin
#

cause tbh if youre gunna get serious about web app stuff, its really not a bad pickup

#

ah yeah oof

brazen apex
#

God mother fuckin damn

#

400

#

How much was a lifetime license when they were around lol

vital adder
#

nope it's $449

thorn urchin
#

I mean the price is still worth it if youre super serious, its pretty clearly the most powerful web app testing tool around

sly reef
#

has anyone done hashcat module?

lament tartan
#

yeh if you doing bug bounty or web app pentesting professionally youd be silly not to get it

thorn urchin
#

I know they used to be pretty chill about cracking it on the basis that if you had the skills to do so youve earned it, but I doubt they still have that unofficial policy anymore.

#

or maybe Im thinking of ida, memory could be fuzzy

brazen apex
#

How do you know if pentesting/red teaming or web app pentesting and that is for you

thorn urchin
#

ยฏ_(ใƒ„)_/ยฏ

#

passion

brazen apex
#

True

#

Hmm I wonder

#

I don't think trying ro learn both is practical

thorn urchin
#

Everything else Ive been doing in life just doesnt feel as fulfilling and feels like I'm wasting my time

#

Learning both IS pretty practical, but specialization helps a lot

sly reef
lament tartan
#

yeh whats the quesiton

#

the assessment?

sly reef
#

last question asks for the password i get 5 times, the problem is i got more than one five times and i've been stuck there for a week lmao

lament tartan
#

oh sorry i havent done the module ๐Ÿ˜‚

#

thought you meant hashcat section of the CPTS track

sly reef
#

RIP

#

na

#

np ๐Ÿ™‚ thanks anyway

thorn urchin
#

if you shot me a giftcard for the cubes id take a look at it and help out in a couple of days ๐Ÿ˜‚

#

jk dont do that

vital adder
#

@sly reef so the skill assessment? (i finishe that module btw)

sly reef
#

yep

#

what did you do?

#

i've tried everything in last question

vital adder
#

after cracking the hash did you use the DPAT tool?

sly reef
#

nope

vital adder
#

yea... use that

sly reef
#

i cracked 60% of the hashes in the file

#

and counted them

placid quest
#

@lament tartan hei, how do u transfer a directory to the attacked machine because scp is not working

vital adder
#

oh you don't need to crack them all

sly reef
#

what do i crack then

#

it is asking for the most common password

#

:/

vital adder
vital adder
sly reef
#

can u tell me which one you got? Idk what i am doing wrong

#

i've been trying for a week now

#

lol

vital adder
#

also i'm not 100% sure about this but i think they did add some uncrackable hash to make this realistic

vital adder
placid quest
#

@lament tartan @vital adder thanks

lament tartan
#

oh rdp as well, if you can enable it then just copy and paste the dir

thorn urchin
#

if youre a renegade that doesnt care about opsec, xfreerdp has the +home-drive option that will mount your home dir for easy file transfer as well.

vital adder
vital adder
thorn urchin
#

theres binary versions as well Ive not examined at all

#

its one of the reasons that I know people who say reversing java is easy you just decompile it have never tried reversing anything other than a trivial java jar

sly reef
#

thanks btw

marble raft
#

Hi there guys having some trouble on Attacking Web Applications with FFUF

Try running a VHost fuzzing scan on 'academy.htb', and see what other VHosts you get. What other VHosts did you get?

I'm using the command:

ffuf -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -u http://178.62.84.158:30146/ -H 'Host: FUZZ.academy.htb' -fs 900

It detects everything ๐Ÿ˜ฆ

thorn urchin
#

your fail condition is probably faulty then

sly reef
thorn urchin
#

see what result you get back with just the academy.htb and one with like a bogusobviouslynotreal.academy.htb and see if you can spot a difference in their response and use that

lament tartan
#

yeh filtering response size 900 there, if the response sizes vary then you can filter by response code or regex

#

the regex option often doesnt work for me on academy though, even when i can see the text in the response

marble raft
#

Yea, just followed what madf0x suggested and it worked, i'm going to try the other filters Crypto, and see how it pans out

#

Do paid tools like Burpsuite Pro have these kind of functionalities ?

thorn urchin
#

an auto calculate fail condition would be a cool feature to add to ffuff(assuming it doesnt have one already built in somewhere deep down)

lament tartan
thorn urchin
#

also gobuster, idr if it auto-detects or not for vhosts though

lament tartan
#

yeh you can use --exclude-length option also with gobuster

zealous belfry
#

Someone got a tipp for the easy lab on password attacks? i got the ftp login and im now logged in as mike in ssh but i dont find anything of interest on the system

placid quest
#

@zealous belfry use ls -la maybe u may see something interesting

zealous belfry
#

already did but did not see anything there

thorn urchin
zealous belfry
#

ya okay got it well i found that earlier but it didnt came to mind to just use the pw for ssh login

#

ยฏ_(ใƒ„)_/ยฏ

thorn urchin
#

dont worry, my notes has me embarrassed on that one that I overlooked it until linpeas pointed it out

zealous belfry
#

damn ๐Ÿ˜„

marble raft
#

Is anyone else having trouble spawning targets?

tiny sail
#

hello, good day...someone has made the web applications module...because the answers of the mini-exercises are not clear to me which url I have to do the tests

thorn urchin
#

gunna need to mention the specific module and section name to get help, lots of web app modules

#

which question youre on will be ideal as well

glass cedar
#

Hello. I am stuck with XSS Phishing...i found the payload and it works, but i don t understand how to get the username and password of the victim. Please someone can helps me?

thorn urchin
#

Ive not done that module yet but my first guess would be to check if theres any cookies or form fields that may store that info and exfil those with your payload

pastel ginkgo
#

Anyone else having issues with interacting with machines?

glass cedar
thorn urchin
#

Usually walkthroughs are frowned upon if not banned for modules

#

the module IS the walkthrough, where the skills assessment is you applying what has been taught

#

might get better help after someone whose gone through that module gets online

thorn urchin
#

no thanks

pastel ginkgo
#

@thorn urchin Did the pivoting module give you any trouble? Yesterday I couldn't get meterpreter to connect at all. Today it seems like I can't even reach the vm on both pwn box and my machine.

thorn urchin
#

nope

#

someone else said they were having issues with machines earlier so something may be funk

#

I havnt had a chance today to spin up and modules to see

pastel ginkgo
#

Werid, when it was working yesterday I couldnt get metasploit to open a socks server either

#

kept opening and closing

thorn urchin
#

that module overall was kinda funky, but I didnt have those kinds of issues

#

also ngl, I cheated like half that module using more chisel n stuff than some of the more imo silly stuff.

twin gulch
thorn urchin
#

oh shoulda lead with that lol

twin gulch
#

Lol well the hashcat takes longer than expected

raven cairn
twin gulch
#

Lol๐Ÿ˜ข

raven cairn
#

Would be super sick to get a hash cracking rig

vital adder
#

i learn this on tryhackme throwback lab a while back but there is something call colabcat that's basically cracking hash using hashcat on google colab but now i think that's against google colab TOS but the tool is still there and you can still use it

pastel ginkgo
#

@thorn urchin Yeah its crashing on me constantly for what ever reason

#

guess im going take a break tonight

ashen orbit
#

there ain't no rest for the wicked

foggy light
#

Can I text anyone regarding WebAttack Skill assesment

raven cairn
#

Makes life so much easier

zealous belfry
#

A hint for the medium pw cracking lab? Logged in as ||john|| already and got the docx file open but i dont find || any databases, scripts, or ways to get root or the user dennis||

glass cedar
#

i am stuck in the section xss phishing...The exercise ask this: Try to find a working XSS payload for the Image URL form found at '/phishing' in the above server, and then use what you learned in this section to prepare a malicious URL that injects a malicious login form. Then visit '/phishing/send.php' to send the URL to the victim, and they will log into the malicious login form. If you did everything correctly, you should receive the victim's login credentials, which you can use to login to '/phishing/login.php' and obtain the flag. I found the payload but i don t understand to who i must send the url to get his username and password

balmy radish
glass cedar
#

aaaah so the payload is wrong good

clear saffron
solar zodiac
#

Hi everyone! I was wondering if anyone could provide a nudge about the cleartext credentials for bob_adm in the windows privilege escalation module

simple zephyr
#

get a nudge on this

What is the ObjectAceType of the first right that the forend user has over the GPO Management group?

i have ran everything in powershell and bloodhound. Powershell just hangs up and I don't get anything back.

thorn urchin
#

and unfortunately I don't believe bloodhound records the answer in the format the question wants, I couldnt find a way to get what it wanted anyways

fallen osprey
#

Password Attacks Module: I have am stuck when I try to install Crackmapexec (I'm on Network Services) I had tried both install it with Apt install and PIP / PIP3 install and I have no clue what I have to do (see my screenshot)

zealous belfry
#

why you trying to pip install it

#

use apt on kali

#

see if you have the libs installed apt-get install -y libssl-dev libffi-dev python-dev-is-python3 build-essential

fallen osprey
zealous belfry
#

im not sure if you can use apt on parrot then. Apt and crackmap is as far as i know is kali only

thorn urchin
zealous belfry
#

yup thats also on the page furhter down if you like python more

thorn urchin
#

cme is written in python, you dont have a choice in the matter ๐Ÿ˜‚

#

just whether apt is handling the package or pip

zealous belfry
#

you can also use poetry

fallen osprey
#

I get same error on Pwnbox

zealous belfry
thorn urchin
#

pwnbox calls crackmapexec cme

simple zephyr
#

@thorn urchin I sent you a DM if you donโ€™t mind

fallen osprey
#

when I run crackmapexec smb -h I get same error on Pwnbox

thorn urchin
#

bout leaving from work, be awhile before I respond

zealous belfry
thorn urchin
fallen osprey
#

okey I try it then

thorn urchin
#

if that doesnt work something may have broke when you tried installing it so reset the instance and then try cme

fallen osprey
ashen orbit
#

am I the only one who likes nano more than vim

fallen osprey
ashen orbit
fallen osprey
#

When I try use sudo cme winrm on Pwnbox I get this Errormessage. Anyone have any idea or hint ?

balmy radish
fallen osprey
#

@zealous belfry @thorn urchin I solved it! Thanks for your help ๐Ÿ™

fallen osprey
#

@sharp cove @languid dawn

urban sage
#

Thanks for the heads up!

low vine
#

Good evening / morning

autumn pilot
#

No

low vine
#

google is your best bet

outer wadi
#

is anyone up for a challenge?

onyx copper
#

hello, i have windows 11 pc and 4 random preson google profiles, all be hacked in two days

#

strong passwords, now i set f2a, but think something is my pc

#

a have some cracked software

#

adaware free scan says all ok

#

but i wanna format system disk a clean windows install withou any cracks

hidden trellis
#

Hi did you have any luck with this? in the same boat....... sorted

onyx copper
#

last software what i istall was wiztree

#

free version

thorn urchin
#

@onyx copper were not tech support, good luck

orchid ingot
#

Can someone help on attacking common services - skill assessment easy. I found the username from SMTP and tried to brute-force it with various services, but I found nothing.

placid quest
#

@orchid ingot anonymous login on ftp may help

onyx copper
#

new info google spoted my pc as malware and logout all 4 person from pc

#

on another devices acounts works normal

#

i remove addblocker from chrome extensions

tribal drift
#

Hello guys if someone have attaque the squashed machine in hackthebox i need a help

#

I can t decrypt the keepass file

#

With an extention .kdbx

wooden mason
#

hello

tribal drift
#

Hey

low vine
#

hi

wooden mason
#

Any advice for getting started on CTF? Any good books? Im stuck and i dont have knowledge to find some flags.

low vine
#

Hack the box academy will be the best place

#

depends abit on what you know but they ahve a great lead up for it

bright ridge
low vine
#

Its such an awesome feeling

bright ridge
#

nibble box

#

its though the getting started module

#

but its a live machine too i think

sharp jasper
low vine
#

Okay, so have run into a problem. I currently use/have used kali for a while and I'm getting 100% different responses with a dig command.
I've just fully updated kali, and I am still getting "communication error / timeout" when attempting to solve a problem in active subdomain enumeration.

example just for reference:

  1. Submit the FQDN of the nameserver for the "inlanefreight.htb" domain as the answer.
    Kali: ||dig ns inlanefreight.htb @<ip>||
    Response: communication error to <ip>#53: timed out

Parrot: ||dig ns inlanefreight.htb @<ip>||
Response: ```; <<>> DiG 9.16.27-Debian <<>> ns inlanefreight.htb @10.129.42.195
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 3105
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 2
;; WARNING: recursion requested but not available

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
; COOKIE: b2dec93a1964fb15010000006378bc6492c78e95d88c46c8 (good)
;; QUESTION SECTION:
;inlanefreight.htb. IN NS

;; ANSWER SECTION:
inlanefreight.htb. 604800 IN NS ns.inlanefreight.htb.

;; ADDITIONAL SECTION:
ns.inlanefreight.htb. 604800 IN A 127.0.0.1

;; Query time: 83 msec
;; SERVER: 10.129.42.195#53(10.129.42.195)
;; WHEN: Sat Nov 19 11:22:12 GMT 2022
;; MSG SIZE rcvd: 107```

I have full disconnected/ reconnected my VPN when testing and I'm really unsure why in Kali I cannot get the same response or what I might have messed up. Would love some help / clarification before future problems arise regarding the same thing.

tribal quail
#

Hi, maybe weird question but are their pdf extracts of the text we can download to print? I am a terrible learner on screen and for example all the AD knowledge is just not getting in my mind by reading it on screen (can't doodle/note next to it as to speak)

kind vessel
#

Hello I have 2 questions for active directory. I try with kerbrute jsmith.txt password list how can i save the result easily. Why on crackmapexec and kerbrute they stop enumeration when they get 1 valid users ?

rustic sage
#

HI

feral stump
#

You can maybe try connecting to another region

low vine
#

I havent ill give that a go

feral stump
#

Let me try

low vine
#

Does PTS cover ADCS abuse?

#

(asking for a friend)

#

CPTS*

feral stump
#

Did you try spawning the ip?

low vine
#

Installing new kali box atm i walked aaway for a bit so trying it now

pastel ginkgo
#

On the Pivoting Module is anyone else unable to get a socks server running via metasploit? I've tried now on both my Kali Box & Pwnbox and I get the same thing

feral stump
#

Shouldnโ€™t you set your SRVHOST to local?

pastel ginkgo
#

in the module page they show 0.0.0.0

#

let me try that real quick

#

Nope tried localhost and 127.0.0.1 as well as swapping to version 5 (and editing proxuchains.conf)

rustic sage
#

BYE

feral stump
pastel ginkgo
feral stump
#

Facing you

#

In the end the server will be listening

#

So the ip of that server has to be you

#

Is like nc -l

#

Similar not the same

pastel ginkgo
#

still fails

feral stump
#

Strange

#

That is the local ip from where you listen right?

pastel ginkgo
#

ah ha I figured it out

#

has to be the ip of the pwnbox machine

feral stump
#

Right

#

The one you are using

#

Your machine

pastel ginkgo
#

im guessing using 127.0.0.0 would fail on my kali because it has to route via the tunnel

feral stump
#

May have not enough clearly explained myself

#

Try your tun0

pastel ginkgo
#

but the pwnbox does not and 127 should work, either way every tutorial I can find seems to have it pointing to 0.0.0.0

vital adder
#

goddamn inside job is good

#

@pastel ginkgo shoot me a dm if you still need help with that i'll help you troubleshoot

pastel ginkgo
feral stump
#

Hey @vital adder can I dm you real quick?

vital adder
#

sure

split bloom
low vine
#

works perfectly on Parrot OS but not working at all on kali ๐Ÿ˜ฆ

#

Have fully reinstalled / updated/ moved to vmware workstation 17 as well just no go for all of it:(

split bloom
#

Yeah I reset the workstation and refreshed the ip a few times and nothing

rustic sage
#

what is this

low vine
#

Active subdomain enumeration might actually be the death of me. I cant be this stupid to not understand and struggle on every question....anyways

1.Find and submit the contents of the TXT record as the answer.

so I used ||dig axfr inlanefreight.htb @<ip>|| to basically enumerate all the subdomains. From here it seems that I should be able to use something like dig txt <subdomain>.inlanefreight.htb @<ip shown from subdomain enumeration>

I cant figure out waht i'm doing wrong i've gone through every single one in this manner and am not getting a TXT response from any of these.

placid quest
#

@low vine try on internal maybe

low vine
#

I guess I missed that

#

So its not the ip thats shown from the transfer?

#

Example the IP i have for HTBA is 10.129.xx.xxx

The enumeration shows ips next to the subdomains of <10.10.34.2>

placid quest
#

@low vine no

low vine
#

My mental is dying in this section lol this seems so fucking easy and I'm having such a hard time lol

#

need to spend a bunch of time here lol

#

Okay other question, question before its talking about zones and identifying the number of zones we have. I basically saw that there is an "A" record and a "NS" record does that mean its only 2 zones or is my understanding wrong

marble raft
#

Hi guys, having some trouble with Parameter Fuzzing - GET section on ATTACKING WEB APPLICATIONS WITH FFUF module.

I'm not sure i'm doing this wrong, but i added the IP 178.62.84.158 and admin.hackthebox.htb to the /etc/hosts/ and i'm trying to run the command

ffuf -w /opt/useful/SecLists/Discovery/Web-Content/burp-parameter-names.txt:FUZZ -u http://admin.178.62.84.158:30633/admin/admin.php?FUZZ=key -fs 341 yet it doesn't return any results

Should i add the 178.62.84.158 and academy.htb since admin is a VHOST?

Got it, needed to add the following input to /etc/hosts: SpawnMachine academy.htb admin.academy.htb

placid quest
#

@low vine u will need to count all zones

low vine
#

Okay thanks for clarification, I got it right but wasnt confident that I actually knew how to correctly do that

rustic sage
#

Hello there, i really stuck with a problem...

Module: PasswordAttacks -> Default Passwords

I know I have to use to Default Cred link provided, but im not sure how to scan using hydra.
The Port i try to Bruteforce is on localhost, so I can't attack this service using its 10.129 IP.

I tried using ssh Dynamic Port Forwarding with Proxychains, but hydra stops after 1sec because of connection error (But nmap works...)

How to brute force this localhost service ?

placid quest
#

@rustic sage u don't need to brute force defualt password

rustic sage
#

now im totaly lost xD any hints ?

low vine
#

Struggling hard on last question for All of the "A" records from all zones.

#

is there a way to recursively output everything?

#

or just manually go find it all

placid quest
#

@low vine do zone transfer on inlanefreight and internal inlanefreight.htb and count all A

low vine
#

Yup it's what I did was more asking if there was a way to set up something to run some transfers from everything

#

And output it

#

Wasn't sure if I was just missing something

placid quest
#

@low vine it is hard to do that since i think u can not do zone transfer on sub domains with bash scripting

silver zenith
#

Wow im rising to new levels of stupidity

#

Im doing the command injection assesment

#

Busy with it all day

#

Try to succesfully inject whoami with different techs

#

But got error unable to move www-data

#

So i thougt fuck what al i doing wrong

#

Spend 2 hours

#

Untill i realised

#

โ€ฆ

#

Www-data

#

Tunnelvision can make you blind

silver zenith
#

Yeey another module completed

rustic sage
#

Hello

#

Can you help me in module Active Directory

#

Skills Assessments 2 I stuck at the 4 question

silver zenith
#

Ik still working on that

#

I am at NTLM auth

blissful verge
#

hey all, new module posted today.

silver zenith
#

Nice

#

Need more cubes

rustic sage
#

Cool

#

Hi all

arctic condor
#

Hi

silver zenith
#

It feels good to see my red ball shrink

#

More brainstuff to consume

raven cairn
#

On the Active Directory Enumeration & Attacks module Kerberoasting -from linux Section, was the password to use for impacket??? Trying to use GetUserSPNS

mint knot
#

Hi everyone

raven cairn
rustic sage
dusty shadow
#

Hey guys evening

silver zenith
#

Spending my saturday evening on htb

#

Nice

void ember
thorn urchin
#

@raven cairn for this module its highly recommended to keep a seperate list of all credentials youve found while progressing through the sections, because they come up again a painful number of times and the module wont always remind you.

rustic sage
#

I use password spray with user list and password basic list but none results

rustic sage
#

hi all, im on the footprinting medium lab and a little stuck ive tried everything (i think) so far on each port but unable to get much further just need a bit of a prod into the right direction... i believe i need to mount? right done that bit. lol

timber hatch
#

sure dm me.

#

i have a question to the modul local file inclusion..in the section automated scanning they use this command:
ffuf -w ./LFI-WordList-Linux:FUZZ -u 'http://<SERVER_IP>:<PORT>/index.php?language=../../../../FUZZ' -fs 2287

this does not give the same output as explained in the modul... when i go to the page there is no button to select language...buit there should be one... otherwise for me it makes totaly sense that the curl command does not work as explained...

there should be the possibility to select the language..no?

silver zenith
#

Well try look for the parameters name

#

If it is not language

#

Try first fuzzing for a parameter bro

#

Reading bro

#

Read before ask

timber hatch
#

lol

#

be quiet bro

silver zenith
#

๐Ÿ˜‰

timber hatch
#

๐Ÿ˜‰

silver zenith
#

Parameter=argument

#

Like not in definition

#

Index.php?parameter=argument

rustic sage
#

Hi all, Footprinting medium lab. Ive done the NFS but cant open the Dir ive made. permission denied. on tree says [error opening dir] what could be the reason?

timber hatch
timber hatch
rustic sage
#

I havent yet found the creds...

timber hatch
#

ah...

rustic sage
#

I believe I'm meant to get them from this Directory ive made but since mounting and that I can no longer access this dir

#

so i cant view the information inside and unsure how to change it

rustic sage
#

password? xD lol

thorn urchin
thorn urchin
rustic sage
#

ill have a look now thanks

#

ok that worked thank you

silver zenith
#

They want you to find a exposed parameter

#

So fuzz the parameter and filter on the right filesize

#

I try to help

pastel ginkgo
#

For the Proxychains module did anyone get Rpiviot to work? I just used sshuttle for the last question because it was ... wayyyyyy easier

timber hatch
silver zenith
#

Damn cannot complete more then 2 section of introduction to ad per day

#

A lot of text

gaunt juniper
#

Hello and help lol. Im stuck at "Firewall and IDS/IPS Evasion - Medium Lab"

#

the question goes like this ```Questions

Answer the question(s) below to complete this Section and earn cubes!

Target: 10.129.130.173

Time Left: 46 minutes

  • 1 After the configurations are transferred to the system, our client wants to know if it is possible to find out our target's DNS server version. Submit the DNS server version of the target as the answer. ```
#

i tried everything yet have nothing

#

most likely i was stuck at the easy lab too. but with some help i got it but 2nd one is deadly idk what to do tbh 2 days or so stuck here

acoustic owl
rustic sage
#

@acoustic owl can i pick your brains with SQL database locating a user?

karmic mantle
#

@gaunt juniper check the DNS Proxying section in the โ€œFirewall and IDS/IPS Evasionโ€ topic

rustic sage
#

how? lmfao

#

footprinting medium lab

#

im right up to the last part now

#

and no idea how to locate the user/pass

acoustic owl
rustic sage
#

yup

#

so im looking for the htb user and pass now

karmic mantle
#

@rustic sage what do you get when you do select name from sys.databases

rustic sage
#

keeps crashing too which is annoying

acoustic owl
rustic sage
#

ok doke... ill see what i can do cheers peoples

#

solved it cheers

gaunt juniper
#

lol

karmic mantle
#

@gaunt juniper I think this one I got it by luck. It wasnโ€™t working and I just did a normal nmap -p- with a โ€”min-rate 5000 and it worked. But I donโ€™t think it was supposed to work

acoustic owl
drifting glacier
#

Anyone around for a question on the medium lab for the footprinting module?

#

I've found credentials from ||nfs port, for what should be rdp, but the xfreerdp keeps returning the following error||

#

Any help on connecting to rdp would be greatly appreciated

balmy radish
#

Put the password in quotes to keep bash happy and hide the screenshot with the credentials to avoid spoilers

#

+clipboard in the xfreerdp command is also helpful

charred heath
#

hi

long jolt
#

Does anyone have an idea on how to check what commands an user can run as root

#

I'm doing the Linux PrivEsc module

#

I've tried doing sudo -l and then submitting the command that says (root) NOPASSWD: /usr/bin/******* and various variations of that command like sudo (command) as the answer

#

Anybody got an idea of what might be the problem

balmy radish
long jolt
#

thank you

balmy radish
#

yw

light fern
#

Hey guys, I'm learning in the HTBA, im wondering if I need to use parrot or is it ok to use Kali? Appreciate the advice, my goal is to get the pentester cert in the coming year so not sure if the OS will matter

light fern
#

@balmy radish Ty sir

balmy radish
#

You'll need to connect to the VPN for the non-docker exercises if you aren't using the ParrotOS pwnbox

#

yw

light fern
#

Ok sure, I think I had been planning to connect to the VPN most of the time moving forward as I feel more comfortable working in my VM instead of pwnbox.

#

@balmy radish Im working through the setting up module, and they have a recommended tool list file, is this just an example of what we should have or should we actually have all these tools in the file? As I see a step to update all tools in a certain file

#

Hopefully that makes sense ๐Ÿ˜ตโ€๐Ÿ’ซ haha

balmy radish
#

You can always install the tools as you need them. I mostly use the pwnbox.

light fern
#

Roger

arctic condor
#

You have finish AD Stills Assessments part 2 ?

#

Okok im stuck at the 4 question but we can see together if i finish it or come in dm

muted drift
#

hey can I reset the progress of the module? I have one that I've started long ago and want to jump with fresh state

simple merlin
#

Hey, I'm stuck on the deserialization - Skill Assessment I. I guess I'm stucked with the last exception to escape for my payload, someone can help me ?

rustic sage
muted drift
#

didnt see such option

rustic sage
rapid sparrow
#

Hi, I have some problem with Blind Data Exfiltration from Web Attacks module

#

I could not get any response from the server

drifting glacier
rustic sage
#

Cancel my message im gonna just try to re-read all my notes n stuff.

tiny dragon
#

help me Find a way to start a simple HTTP server inside the PWNBOX or your local virtual machine using NPM. Send a command that launches a web server on port 8080 (use a short argument to specify the port number).

rustic sage
tiny dragon
raven cairn
rustic sage
#

Im gonna put my ego aside actually for this - seems people have had issues in the past

raven cairn
#

Its a badly worded question tbh

#

I dont think it is unreasonable to find this question confusing if you are a beginner

rustic sage
#

Can I have a hint for Privilege Escalation - Flag 2

I'll give some context, one moment

#

I think I was answering your question before you deleted it.

#

I usually really hate asking for help but

#

I think I really need to just kind of accept it, I don't think im the only one struggling being new to it

#

I don't know the specific module, but have you looked for any interesting files? Are there any SUID, GUID, capabilities? See if you're apart of any interesting groups

#

It's okay to struggle just never give up๐Ÿ˜‰

raven cairn
#

Also take a break when you get flustered : )

rustic sage
#

Im too stubborn for that aha-

#

I haven't been giving up- ill check for files

#

I think I found passwd earlier but it's just nonsense, nothing to decode

#

I haven't done the privilege escalation modules yet so I can't really be of much help besides telling you what to look for๐Ÿคทโ€โ™‚๏ธ I just started the CPTS path, but it'll be a while before I get there

#

This is "Getting Started" ^^;;;

rustic sage
#

What?!?!

#

That quick?!...damn ;-;

#

so there is something you're missing I'm trying to think of how I can word it where it won't give it away

#

I'm going to dm you in case so there is no spoiler

placid quest
#

@rustic sage what is the problem

rustic sage
#

okieokei!

#

It's privilege elevation, im stuck in a loop of not being able to do anything with user2, I've found the file but keep getting asked for a password and can't find anything important, and the SSH keys are going over my head (I think)

#

Check your DMs @rustic sage

feral stump
#

Hey has anyone gone through the file transfer module?

#

Just started โ€ฆ I see I need a bit more familiar with powershell

#

Guess bash too right?
Any advices?
Thx!

silver zenith
#

Bought 1800 cubes๐Ÿคฃ

#

Im sponsoring htb like a mowf*cker

rustic sage
#

I already help them they should be good now๐Ÿ‘

silver zenith
#

Okii

rustic sage
#

now I have to figure out keys backtomycave

rustic sage
#

Hello everyone, in AD skills 2 Q7. I tried this:

#

But: CertUtil: -URLCache command FAILED: 0x80072ee2 (WinHttp: 12002 ERROR_WINHTTP_TIMEOUT)

#

How can i do ?

#

I supposed its a restriction error ?

umbral loom
#

Hey, I'm stuck on the deserialization - Skill Assessment II. I dont really know what i am doing wrong, someone can help me ?

brazen apex
#

Hey guys wat is nmap -D rnd:x for?

#

from my understanding it just creates extra

#

ip addresses

#

that send the same packet you do

#

to create some anon

#

for you

toxic sigil
#

can somerone teach me how to type

bleak heart
#

I got a gift card and redeemed it. But i cant spend it even though my account balance would cover a silver subscrbtion. How can I spend it? xD

placid quest
#

@bleak heart buy silver subscribtion

bleak heart
#

"You need to add a payment method to purchase cubes. " but I dont have paypal or a credit card and therefore can't add any other payment method than the gift card. If I click to subscribe I'm asked to enter my credit card info. Do I miss something or is it not possible to buy anything from the account balance if you dont have any payment method added?

#

and I cant enter the gift card code during checkout because I already redeemed it (the money is stuck in the account balance) ๐Ÿ˜ฆ

placid quest
#

@bleak heart if u cannot buy silver without credit card that is hard maybe u will need to pay cubes only with that gift card

wheat garden
umbral loom
#

Heyo i need some help with last flag of the deserialization attack module, if someone can help pls DM me

magic valve
#

May I have some help with Reverse Shell & Payloads - The Live Engagement? Iโ€™m receiving an exploit failed message when attempting to run the exploit for the blog site.

unique valve
magic valve
unique valve
#

Also confirm that you are using the correct LHOST address. Keep in mind that in this assessment you are connecting to an additional internal network.

quasi wave
#

Once I get past Information Security Foundations, I was thinking of doing bug bounty pathway before doing CPTS. Is that a bad way to go or should I do CPTS first? Iโ€™m a student who wants to bug hunt but I also want to be a pentester someday.

#

I started the InfoSec fundamentals path to get prerequisites to do either

pastel ginkgo
#

Anyone else encounter this error when trying to do the chisel section of the Pivoting module?

woeful mural
#

@rustic sage Did you figure it out?

rustic sage
#

No

rustic sage
# pastel ginkgo

Yes but i relaunched my kali and try in the parrot and it resolve it idont know how

rustic sage
mint flame
#

hi, please when start the competition of Hack the Box ?

magic valve
pastel ginkgo
rustic sage
#

yes maybe a bug ?

pastel ginkgo
#

yeah Im thinking something just wasnt playing nice with my kali box. I've noticed theres a few bugs with this module

rustic sage
#

Yeah i remember i have changed few times kali and parrot for this module and it solve big

#

bug

#

Some box work better with kali and some box with parrot big_think

flat oxide
#

how did you solved it?

silver pagoda
#

Hey guys im trying the Passwords Attack Module from the Junior Path, and I dont understand this question.
Find the user for the WinRM service and crack their password. Then, when you log in, you will find the flag in a file there. Submit the flag you found as the answer.
The module provides a list of both usernames and credentials as Resources, but when i try to use them, im unable to do a sucessful brute-force. Is there anything that Im missing? Is there a way to get the user whitout having to brute-force both user and password?

pastel ginkgo
placid quest
#

@pastel ginkgo are u on pivoting module

pastel ginkgo
#

Yeah the last part before the assement

placid quest
#

@pastel ginkgo have u done rpivot section

pastel ginkgo
#

I couldnt get rpviot to work

#

I ended up solving it using sshuttle

placid quest
#

@pastel ginkgo I have failed to transfer rpivot directory so i have not solved it maybe i will try to use sshuttle

woeful mural
#

@rustic sage I havent gotten there yet. Im stuck on the 5th question in AD assesment 1

wheat garden
#

I could likely help ive finished that module

pastel ginkgo
#

@thorn urchin Were you ever able to do the RDP pivot of the pivot module correctly? For what ever reason traffic isnt running over proxifer ๐Ÿค” I got the flag but that was rdp from one machine to the next not via the fancy proxy

thorn urchin
#

nope I did it your way too

#

fwiw Ive never heard of anyone actually proxying that way IRL

pastel ginkgo
#

rip this module is probably the buggest one yet

#

half the time im not sure if im not doing right or its bugged

thorn urchin
#

yeah its my second least favorite module so far, though the chisel section carries the whole thing on its back because chisel is just that good

pastel ginkgo
#

I had trouble getting chisel to work lol

#

I like sshuttle, its fire and forget

thorn urchin
#

I added notes about cross compiling and smaller bin size and that was helpful

pastel ginkgo
#

the issue I ran into with it is if I compiled it on my linux machine it wouldn't work on the remote machine. If I compiled from pwnbox it worked

thorn urchin
#

yeah that idk

#

downside of sshtuttle is its not as flexible, wheras chisel can just be a pure socks5 proxy

sly tapir
#

has anyone ever used these modules on HTB academy as CEU's when renewing Sec+

wheat garden
#

good question

pastel ginkgo
#

So after downloading my transcripts it dose not list # of hours, so I dont think it would be accepeted

#

its also missing date of completion

wheat garden
wheat garden
sly tapir
#

it tells you on the main page how long a module takes or "should take"

#

i was gonna try it out...i mean i used my college class as hours before...all i did was put the description...

wary parrot
#

Hi guys, I need help with the 'Working with rules' practice section in the hashcat module, please. I believe I'm doing what is being asked but am obviously missing something.

#

It asks you to: "Crack the following SHA1 hash using the techniques taught for generating a custom rule: 46244749d1e8fb99c37ad4f14fccb601ed4ae283. Modify the example rule in the beginning of the section to append 2020 to the end of each password attempt."

#

And I have created the rule, debugged it and confirmed it's doing what it is supposed to do.

#

But when I try to crack the hash with "sudo hashcat -m 100 hash /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou.txt -r rule" command hashcat exhausts all possibilities and quits

#

I'm wondering if I'm supposed to create a custom wordlist using the rockyou.txt list but was hesitant to try that because it would increase the length and processing time significantly

#

Also that is never mentioned, not even on the hint: Create a custom rule and combine it with the rockyou.txt wordlist. This exercise was created in the year 2020.

paper gust
#

Modify the example rule in the beginning of the section to append 2020 to the end of each password attempt.

low vine
#

When you complete a section it typically gives you a list of a copule of boxes to try out the information you have learned, once you leave that page is there any ways to go back and see HTB boxes recommended?

unique valve
low vine
unique valve
twin vine
#

Password Mutations section's exercise need to be addressed. Been banging my head for the past day trying to find the right rule to crack sam's password. Any other hint except "get rid of first 17k" and "faster on ftp"?

placid quest
#

@twin vine brute force ssh

tidal mango
#

In the active directory module, it has a part on bloodhound in the "Credentialed Enumeration - from Linux " section. How would I connect via freeRDP to the linux system? I have only used it to connect to Windows... "Next, we can type bloodhound from our Linux attack host when logged in using freerdp to start the BloodHound GUI application and upload the data. The credentials are pre-populated on the Linux attack host, but if for some reason a credential prompt is shown, use:"

tidal mango
thorn urchin
#

yeah rdp is just rdp, its more common on windows modern day, but its far from windows exclusive

tidal mango
thorn urchin
#

it shouldnt

#

but idr how that one was setup

tidal mango
thorn urchin
#

<@&861185840277487616>

dusty citrus
#

hi

gusty fulcrum
#

Hi

coral mulch
#

Hello, you probably have hundreds of people doing this question, but I will do it again, so I am learning programming by myself, and I am a bit lost in what to choose what path should I choose, and I always wanted to learn more about cybersecurity, I don't have to much time because I work 8 hours per day and I want to dedicate 3 to 5 hours per day to study, my question is, is the academy good for beginners or should I learn somethings first, if so what should I learn first before start with the academy? Thank you for your time in helping me out, I appreciate it very much.

placid quest
#

@coral mulch academy is a good place when u have some experience but if u are new it may be hard on academy

coral mulch
#

Oh OK thanks for helping,

#

I don't want to be disrespectful, but I was thinking in tryhackme first to gain some knowledge and then use hack the box academy

placid quest
#

@coral mulch That is a good plan ๐Ÿ‘Œ

random heart
#

Hey guys, Iโ€™m currently working on the Linux privilege escalation skill assessment, but I got stuck on flag 4. I managed to find the directory for it, the credentials for the tomcat website, but canโ€™t manage to escalate my privileges on the machine. Could someone perhaps give me a tip into the right direction?

pliant sage
#

Hi, I'm trying to do the pivoting tunnelling thing, the part with Rpivot but I can't get to see the webserver home page, connection just times out, any ideas?

#

I mean I guess i could ssh and curl it but that's not really the spirit of the module lol

#

No one? ๐Ÿ˜ฆ

placid quest
#

@pliant sage i would help u but i am still stuck on how to transfer the rpivot directory to the attacked machine

pliant sage
#

scp doesn't work?

#

@placid quest

placid quest
#

@pliant sage yes

pliant sage
#

have you tried: python3 -m http.server 8080 and then from pivot wget http://<IP>:8080/rpivot?

#

@placid quest

fossil wedge
#

what do i start with?

#

ah i looked at pinned

placid quest
#

@pliant sage i did that but still it is not working

pliant sage
placid quest
#

@pliant sage ok i will look for another method

pliant sage
placid quest
#

@pliant sage why not i try to use sshuttle to see what happens

pliant sage
#

what I don't understand is even if I curl the page I only get the apache default page

placid quest
#

@pliant sage maybe try to understand where the flag is

unreal patio
#

What wordlist do I have to use for ||fiona|| on attacking common services easy?

#

The provided one doesnt work and rockyou will take 84 hours

placid quest
#

@unreal patio why not login with anonymous

unreal patio
#

It doesnt work on the ftp

#

Whenever I try to target the ftp it bugs out

#

And when I log in as anonymous it prompts a pw

placid quest
#

@unreal patio disconnect and try again

tepid sand
#

how learn hack

unreal patio
#

@placid quest I reset the target and still can't log in with anonymous

fathom mortar
#

Hey guys

#

can anyone help me with Password attacks with Pass the Ticket from Linux section ?

coral mulch
#

Thank you @placid quest

umbral loom
#

I am stuck with the last flag of the Deserialization Attacks Module, if someone have a tip to help me psyduck

lethal goblet
tepid sand
rocky dock
#

Yoo boi what is this server bois?

#

Tell

#

Fast

#

I wanna know

#

U guys there?

#

Hello?

#

Damn

#

Y u all not responding

#

๐Ÿ˜”

lethal goblet
#

Check that

lethal goblet
unique valve
tepid sand
#

Wlr

rocky dock
#

Oki bois ty

#

๐Ÿ˜€

placid quest
#

@coral mulch no problem

frank blaze
unreal patio
#

Does someone have 1 minute to dm me about attacking common services easy?

random heart
solar granite
#

Hi guys, need some help with the pivoting and tunneling module, RDP and SOCKS Tunneling with SocksOverRDP.
I have done everything as in the lesson, but I can't get the proxifier to work.

  1. Loaded the DLL
  2. Created RDP session victor@172.16.5.19 with mstsc.exe
  3. From the RDP session, ran SocksOverRDP-Server.exe as administrator
  4. Checked the port is listening on the foothold machine, and it is.
  5. Set up proxifier as 127.0.0.1:1080 SOCKS5
  6. Tried to RDP with mstsc.exe as jason@172.16.5.19, but got the login attempt failed
  7. Tried same as 6, but jason@172.16.6.155, and it failed again.
frank blaze
simple zephyr
#

I am having trouble with this can anyone help me.

Leverage SQLAdmin rights to authenticate to the ACADEMY-EA-DB01 host (172.16.5.150). Submit the contents of the flag at C:\Users\damundsen\Desktop\flag.txt.

p3ta@kali ~/Downloads> sudo impacket-mssqlclient INLANEFREIGHT/DAMUNDSEN:SQL1234!@10.129.201.234 -windows-auth
Impacket v0.10.0 - Copyright 2022 SecureAuth Corporation

Traceback (most recent call last):
File "/usr/share/doc/python3-impacket/examples/mssqlclient.py", line 169, in <module>
ms_sql.connect()
File "/usr/lib/python3/dist-packages/impacket/tds.py", line 535, in connect
sock.connect(sa)
ConnectionRefusedError: [Errno 111] Connection refused

placid quest
#

@simple zephyr did u try with python3

rustic sage
#

Hi, is there an issue with LinEnum downloads?

I've got it installed on vmbox but it keeps saying 404 on my remote target when I try to download via Python Server.

#

Unsure if this is an issue anyone else has had?

flat karma
#

hey in module "DNS enumeration Using python" in section "DNS Records and queries" i dont find the correct answer for the first question i try multiple answer but nothing... someone for help me please ?

thorn urchin
rustic sage
flat karma
#

i found the Flag in txt record but nothing it s a bug ?

#

its done sorry ..

placid quest
#

@solar granite section

solar granite
placid quest
#

@solar granite i am not on that section

solar granite
placid quest
#

@solar granite i am still on netsh section

solar granite
#

Oh

graceful parrot
#

Hi there,
I'm currently doing the web service and api attacks skills assessment.
This is the question Submit the password of the user that has a username of "admin". Answer format: FLAG{string}. Please note that the service will respond successfully only after submitting the proper SQLi payload, otherwise it will hang or throw an error.
I use SQLMap but the htb table does not contain the password column.
Can someone help me to know how to approach the problem?

solar granite
#

I never got that to work SQLi

graceful parrot
#

yes @solar granite i found this

`|| import requests

payload = f'<?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:tns="http://tempuri.org/" xmlns:tm="http://microsoft.com/wsdl/mime/textMatching/">soap:Body<LoginRequest xmlns="http://tempuri.org/"><username>onthesauce</username><password>admin</password></LoginRequest></soap:Body></soap:Envelope>'

print(requests.post("http://10.129.84.31:3002/wsdl", data=payload, headers={"SOAPAction":'"Login"'}).content)||`

simple zephyr
raven cairn
#

Can I have help with this question in the "Active Directory Enumeration & Attacks" - "Living Off the Land"

#

I've been googling for a while and I haven't been having luck finding any flags with my dsqueries

rustic sage
#

Hi guys

#

After subscribing to VIP, do we has access to the active machines?

#

to the all*

rustic sage
unique valve
rustic sage
thorn urchin
#

I could be thinking about a different question however

unique valve
rustic sage
unique valve
raven cairn
thorn urchin
#

nvm then

#

but the exact command is still in the section

rustic sage
#

But I subscribed now โœ…

thorn urchin
#

youre allowed to say tryhackme here

#

๐Ÿ˜‰

rustic sage
#

Okay

#

Yeah itโ€™s Tryhackme

thorn urchin
raven cairn
#

Lol

rustic sage
#

Now I will test the machines ๐Ÿ™‚

thorn urchin
#

keep in mind the academy subscriptions are different than the main site subscriptions

rustic sage
#

Yeah

storm jackal
raven cairn
#

Sorry I'm stupid FeelsBadMan

thorn urchin
#

probably, Idr

#

be a moment before I can check

raven cairn
#

nevermind I got it

#

Thank you for the help

#

Trying Smarter Always helps

random parrot
#

Hi all, I'm stuck on the Tier 1 machine "Appointment", the task 4 doesn't take any of the answers I enter! Can someone help me with that?

raven cairn
#

But usually this is for modules

#

can you DM me please?

random parrot
# raven cairn yes

Sorry, my first message on this channel, I just joined so not very familiar with what goes where ๐Ÿ™‚

raven cairn
#

no p

mellow turtle
#

@raven cairn

raven cairn
#

wassup dude

mellow turtle
#

you completed the Initial Enumeration of the Domain true?

raven cairn
mellow turtle
#

I have a problem spawning wireshark there

raven cairn
#

hmmm

#

It's been a while since I've done it

#

You can dm me and I can try to help you out when I have a second

#

We'll get this figured out !!!!!!!

thorn urchin
#

I don't remember using wireshark at all for that section

glad forum
#

Hi all, does anyone have experience with the responder.py through a pivoting host (ssh tunnel)? What is better ssh tunnel or chisel?

thorn urchin
#

im a fan of chisel personally

#

being a socks5 proxy makes things smoother

#

but also, you cant proxy responder like that to my knowledge

#

I could be wrong though

mellow turtle
#

@glad forum this is what you are looking for?

thorn urchin
#

neat, be nicer if there was a guide on using a more modern tool though

rustic sage
#

Hi all, Footprinting hardlab help please. I've tried everything but the right thing of course. I've seen others have found creds but I dont know where to start looking? struggling to connect to the SSH as I think thats where im going to find my next step.. can i connect anonymously?

thorn urchin
#

ssh has no anon feature

rustic sage
#

ok thats sorted that one.

mellow turtle
#

u can use a id_rsa with -i

rustic sage
#

i have a server key....

mellow turtle
#

what u mean with server key

thorn urchin
#

server key is likely to be an id_rsa key

mellow turtle
#

oh

thorn urchin
#

I didnt save notes on that assessment though so idr

mellow turtle
#

i got notes

rustic sage
#

ok cheers mad.

#

so on my nmap scan i found a server key

mellow turtle
#

u can dm me if you want craizi

rustic sage
#

cheers

graceful parrot
#

Hi there,
I'm currently doing the web service and api attacks skills assessment.
This is the question Submit the password of the user that has a username of "admin". Answer format: FLAG{string}. Please note that the service will respond successfully only after submitting the proper SQLi payload, otherwise it will hang or throw an error.
I use SQLMap but the htb table does not contain the password column.
Can someone help me to know how to approach the problem?

glad forum
raven cairn
#

My boi Arrano still needs some help

#

Where is MrTom at?

mellow turtle
#

nah its okey, i just was trying to figure out if i was doing something wrong

ashen orbit
#

when you waited 15 minutes for a port scan and realized you used the wrong ip

rustic sage
#

Fairly stuck on the last part of the knowledge check for Getting Started and all of my notes and web surfing isn't really helping me all too well,

  • I've grabbed the user.txt file
  • I have a reverse shell (low level priv)
  • Target: Root.txt
  • required: Root shell

I'm trying to import LinEnum.sh, but on the remote side it keeps giving me permission denied. I can sudo into bin/sh/PHP, but this just breaks the shell (maybe?)

I've been stuck on this for a bit and backtracked in my notes but could use a judge into the right direction or command?

Thanks!

thorn urchin
#

use GTFOBins to find out how to elevate when you have sudo perms as php

rustic sage
#

I've got one
CMD="/bin/sh" sudo php -r "system($CMD');

#

But it doesn't work either- I think that may be the one though?

autumn pilot
#

the CMD variable and the sudo command must be on different lines

#

e.g. submitted one after another

thorn urchin
#

alao you dont have to do the env variable at all

#

if you think about what its doing you can just run your command directly

graceful parrot
rustic sage
thorn urchin
#

run the scan and find out

rustic sage
#

It worked yaaaay ^^

marble raft
#

Hi guys, need some help on Login Bruteforcing Skill Assessment I , question 2.

My command is

hydra -l user -P /usr/share/wordlists/rockyou.txt 134.209.186.13 -s 30720 http-post-form "/admin_login.php:username=^USER^&password=^PASS^:F=<form name='log-in'"

Been running for a while now, feels wrong. Any tips?

ashen orbit
#

snap, I got a box without looking it up

#

Victory or death

plush steppe
#

Hi there, I'm working on linux fundamentals and I can't figure out how to use the locate command for a question

#

Here's what I have so far

#

||find -user root -newermt 2020-03-03 -name *.conf -size +25k -size -28k||

#

I think the problem is that it's trying to find files you need root for but I added the option for it to not

steady hawk
plush steppe
#

Lmfao I didn't even read that good idea

#

aha might have found it

steady hawk
#

also you need to specify which directory to start your search in

#

awesome! ๐Ÿ˜„

plush steppe
#

Ty lol I haven't found it yet but I'll specify that

vital adder
vital adder
# mellow turtle

so you can answer both of the question in that section with nmap

mellow turtle
#

yeah i know but i wanted to open wireshark @vital adder

vital adder
#

oh the given machine through ssh?

vital adder
mellow turtle
#

@vital adder yeah but i cant use it bcs i cant run wireshark with privileges

#

and when i try to wireshark -i {interface} it says me that i dont have permissions

mellow turtle
drowsy sedge
#

Hello , Iโ€™m stuck on skill assessment login bruteforcing, any clue ?

mellow turtle
#

which one

vital adder
#

sure what's the issue

vital adder
mellow turtle
#

im using pwnbox

vital adder
#

oh i mean the pwnbox have the same issue with wireshark can't run as root or with sudo

mellow turtle
#

ohok

lofty moat
#

hello May I please get some assistance with Getting Started foothold for knowledge check. I believe the exploit is the Arbitrary file upload but I am having issues executing it. I don't know if I am on the correct page or not. Thank you

vital adder
lofty moat
#

Metasploit ?

#

I used metasploit to get in

vital adder
#

nope for me a get a shell through ||theme||

thorn urchin
#

I got in with metasploit

#

didnt take any notes on that module though, it went smoothly

lofty moat
#

yeah I wanted the exploit that I had to work I just don't know where to upload it

#

I am thinking that @vital adder used curl ?

vital adder
#

no idea but it could be a rabbit hole

lofty moat
#

k

#

if I am escalataing privileges how can I use the usr/bin/php to escalate to root ?

#

do I have to edit the php ?

thorn urchin
#

gtfobins

#

rule of thumb if you have sudo rights over a programming language interpreter you can just use it to spawn a shell directly as the shell will inherits the perma of the interpreter.

waxen barn
#

So, how long did it take you guys to crack the Passwords Mutations module? I've grown a beard and mowed my lawn with a pair of nail clippers and this thing still isn't cracked

marble raft
steady hawk
thorn urchin
#

its my least fav module overall

waxen barn
waxen barn
pastel ginkgo
#

For the Piviot skills assessment how in the hell do you get the lsass off the remote windows machine? Im losing my mind trying to get it

vital adder
#

or you can get ||mimikatz|| to that machine

pastel ginkgo
#

the Av wouldn't remove it?

vital adder
#

i think you can just disable it

pastel ginkgo
#

I tried it wont work

#

I tried getting a msfvenom on it but the av is stopping it

#

I tried base64 the lsass dump but that took to long to calculate q.q

steady hawk
vital adder
waxen barn
vital adder
pastel ginkgo
#

||Set-MpPreference -DisableRealtimeMonitoring $true|| does not work, returns an error

waxen barn
vital adder
#

first did you use powershell -ep Bypass before that and i mean in the windows security

thorn urchin
#

I don't remember messing around with AV much in that module.

you can also try secretsdump.py but it can miss things mimikatz doesnt.

lofty moat
vital adder
#

sure

thorn urchin
#

crackmapexec also has an lsass dumping module but Ive not tried it

pastel ginkgo
#

it wont work because smb isnt authenticating

#

i tried that lol

waxen barn
hidden trellis
#

hi can someone please hepl with Pass the Hash (PtH) - Using David's hash, perform a Pass the Hash attack to connect to the shared folder \DC01\david and read the file david.txt.

thorn urchin
#

whats the issue youre having with

drifting glacier
#

Anyone around for a question on the medium lab for the footprinting module? I've found creds for the ||mssql server studio|| from ||smb share||, but they keep erroring out when attempting to log onto the server...

hidden trellis
waxen barn
drifting glacier
#

Here is the error i'm currently receiving

#

Getting that using both 'sa' and Administrator, with the password from the smb share

waxen barn
drifting glacier
#

Hah all good. I've tried it without the "win..." as well, for good measure

#

But keeps erorring out

#

Not sure what I'm missing

waxen barn
drifting glacier
#

yep yep

thorn urchin
waxen barn
# drifting glacier yep yep

That's odd. I just logged in over RDP w/ Administrator and that password and had no problem opening the studio

thorn urchin
#

iirc this is one where the mssql server is publicly facing

drifting glacier
thorn urchin
#

ohhhh that one

#

yeah one user has perms, one doesnt

waxen barn
#

Log in as the Administrator

drifting glacier
#

I'll be damned

#

Appreciate the help @waxen barn * @thorn urchin !

rustic sage
#

Can anyone help with a hint for the final Footprinting - DNS question? I've tried all seclists wordlists and can't find the answer.

thorn urchin
#

like you found blah.inlanefrieght.htb have you also checked for anything under *.blah.inlanefreight.htb

rustic sage
thorn urchin
#

im a fan of gobuster personally, but whatever works really

#

gobuster is more vhosts though

#

idk if it does actual dns queries

#

oh it does, yeah Id go with gobuster

raven cairn
#

Where my FFUF gang at???

rustic sage
#

@thorn urchin not working with gobuster

rustic sage
#

Iโ€™ve always used ffuf for my subdomain enumeration๐Ÿ™‚

polar saffron
#

ๆœ‰ไผšๆธ—้€็š„ๅ—

mossy nexus
#

Anyone want to do boxes together? If a group of us do it together we can discuss how we did it. Could be a nice way to learn

rustic sage
vital adder
raven cairn
#

I think rule 5 is dumb tbh

low mica
#

finally figured out where i fucked up in the password mutations module

mental jacinth
#

IS THERE ONLY TWO TEIRS FOR THE MACHINES

#

@here

graceful mortar
#

someone help me with juicypotato

graceful mortar
#

how do i find CLSID and port from machine to windows escalation?

tidal mango
#

I have a Question on Active Directory --Credentialed Enumeration - from Windows-- There is a section on PowerView, none of the commands listed in the reading seem to work. What step am I missing here? Do I need to do something like Import-Module PowerView (which I tried)? I see powerview.ps1 in the Tools directory and tried importing that as well... Thanks for any insight!!

tidal mango
hollow hinge
#

Can you link that module?

#

Oh, thats skill assessment. Did you find vulnerable parameter?

#

And btw dont try to read passwd file, find other php files on that web app and read them, you will find one path once you decode that

#

I havent tried reading that, but it did not mattered for me, what really matters first for me is to read and find all available files on that web

#

Welcome.

#

Remember to use filters.

mellow bone
#

can I have some help with this question

#

I don't want the answer I just wanna know how to do i t

#

Submit the broadcast address of the following CIDR: 10.200.20.0/27

#

Because I'm not realy sure how the CIDR ip is createtd

#

I may have just figured it out correct me if I'm wrong in binary the subnet mask is 1111.1111|1111.1111|1111.1111|1110.0000| the last 8 bits has a decimal value of 224. Subtracting from the maximum subnet mask value you can have being 255 you get 31

#

so the answer is 10.200.20.31

warm lichen
#

Looks correct to me

hallow oxide
#

Hello. Is there a way to reformat ssh key? Couldnt find a way to google that. I have found an ssh private key in a message in pop mail server. Couldnt figure a way to save it correctly, ssh always says invalid format. it sarts with -----BEGIN OPENSSH PRIVATE KEY----- and ends with ----end etc. so its not like smth if missing, i guess just format of .txt file is wrong, like missed spaces os smth like that. How can i fix it?

rustic sage
#

Hello all,

I'm trying to solve the 'Blacklisted Filters' question from the 'File Upload' module. I managed to find an extension that I could use to run my exploit but my browser displays this error message in the console:
"""
The character encoding of the HTML document was not declared. The document will render with garbled text in some browser configurations if the document contains characters from outside the US-ASCII range. The character encoding of the page must be declared in the document or in the transfer protocol.
"""

Does anyone know how to circumvent this problem ?

Thanks in advance for your help.

warm lichen
rustic sage
# warm lichen If it's a browser-level error, couldn't you go around that by using an intermedi...

Well after attempting the Burp approach, I may think that there is a misconfiguration in the server. As a matter of fact, I'm getting the aforementioned error because the content of my Web Shell script is sent back to my client. Normally it should be executed on the server side. The example given in the section uses .phtml and in the next section (Whitelist filters )it is indicated that Apache accepts to execute a file with this extension:

<FilesMatch ".+.ph(ar|p|tml)">
SetHandler application/x-httpd-php
</FilesMatch>

However the different extensions that could be used to bypass the blacklisted filters are not mentioned.

mystic sphinx
#

hi

warm lichen
rustic sage
warm lichen
solar granite
#

Hi, I need some help with Pivoting, Tunneling and Port Forwarding module skills assessment. I have got access to the foothold machine as ||webadmin||, and pivoted to ||172.16.5.35|| as ||mlefay||. From there I found the credentials for ||vfrank||, and connected to ||172.16.6.35||. My problem is, now I can't find any other host on the ||172.16.6.0/24|| network. Any hints?

Edit: solved. Leaving it up in case anyone has this issue in the future.

Hint: ||make sure to ping sweep multiple times. For some reason, it doesn't respond to the first ping it gets.||

coarse mango
#

Hello everyone, I am doing the Intro to Bash Scripting Module in the Comparison Operators section.

#

I am having trouble getting the answer. I am not sure what is wrong with my script, I have two comparison expressions and get a seemingly expected output although its not correct

#

I'd appreciate any help

solar granite
analog junco
#

Hi, i'm on the Bruteforcing module making the Skill assessment on the website but i'm stuck. We're supposed to bruteforce the login form prompting when going to the IP but we're given no information on what to bruteforce it with ?

solar granite
#

Hey guys, need some help with the Pivoting, Tunneling and Port Forwarding module skills assessment. I have found every host and the DC (||172.16.10.5||), but I can't connect to it from ||vfrank@172.16.10.25||. The DC responds to pings, but when trying mstsc.exe it says the host is down.

marble raft
solar granite
marble raft
#

Sure!

unique valve
#

Just throwing this out there. As you develop skills doing HTB boxes, labs and Academy modules don't forget to update your CV/Resume. These skills are in high demand right now and you'll have some great talking points to discuss in interviews. Make sure to use keywords and not just mention "Finished this module..". Say things like: "Learned and develop methodology in assessing the security of Web applications manually and using tools such as Burp Suite & OWASP Zap". Also be sure to mention Active directory, pivoting and many of the endless variety of topics taught through Academy.

waxen barn
manic pilot
#

finally finished AD enum and attacks after 2 whole months... probably wouldn't have been able to complete the assessments without the hints littered across discord

thorn urchin
mellow turtle
#

@analog junco hydra maybe

raven cairn
#

Itโ€™s a long one for sure FeelsBadMan

mellow turtle
#

better

#

we learn more

rustic sage
#

i'm working on wordpress module