#modules

1 messages · Page 23 of 1

rustic sage
#

Directory Indexing

#

Can't find the flag

#

I cannot understand what I am supposed to do

#

I followed every directory

#

even in the source code

#

same, ho did you figure it out?? I'm still stuck

brazen apex
#

I wish they had it censored out like Try hack me does ***

#

it would be so helpful

#

I cant tell you how many times I had a flag but wasnt pasting it properly

solar granite
cosmic dock
#

What is the answer for this: Active Directory Enum & Attacks
What is the ObjectAceType of the first right that the forend user has over the GPO Management group?

I've been inputting the "answer" over and over, to no avail. I've literally had my fill of this course and its stupid nuances

rustic sage
solar granite
rustic sage
#

the module says "manually"

#

i tried that way

#

headache and nothing else

#

plese a little hint in private

thorn urchin
#

congrats, its definitely a monster of a module

brazen apex
#

Bro why is nmap so inconsistent

#

I swear to god something that works 5 min ago

#

stops working on the same lab with a different ip

#

I already got the answer but now im not even sure

#

how I did it

#

Network Enumeration with Nmap

#

the medium difficulty

rustic sage
#

what section?

brazen apex
#

You mean like the "table of contents"

#

or whatever its called

#

Im on the medium lab

rustic sage
#

yes so "Network Enumeration with Nmap" is the module and within the table of contents are different sections

brazen apex
#

Fire wall and IPS/IDS evasion

#

medium lab

#

I got the answer

#

and I was trying to look at what I did and take note

#

but now it deosnt work

#

im so confused

rustic sage
#

command history?

brazen apex
#

yeah I hit up

#

used the same command

#

Netcat denies it thinking im trying to use my loopback

#

0.0.0.0

#

weirdest thing

#

Im going crazy why did this work like 2 seconds ago

#

but not now

rustic sage
#

I haven't done this module yet so I cannot help besides basic nmap usage. I'll try to complete the module today and if I figure out the answer I'll let you know. I'm not really sure how the lab is setup

brazen apex
#

sure its up to you im gonna keep trying it for now ill let you know if I figure it out as well.

rustic sage
#

might help to just reset the lab and re-execute the command

brazen apex
#

Yeah good idea

cosmic dock
#

Finally got it. Thanks to a list of all of the ObjectACETypes and me brute forcing each and every one until i got it right

rustic sage
# brazen apex Yeah good idea
Firewall rules and IDS/IPS protect the systems, so we need to use the techniques shown to bypass the firewall rules and do this as quiet as possible. Otherwise, we will be blocked by IPS.
mellow turtle
#

@rustic sage that frog looks dangerous 😵‍💫

solid quarry
solid quarry
#

tried in my kali and the box that they provide in the exercise

thorn urchin
#

cause pwnbox definitely had it built in just fine

solid quarry
#

I will try one last thing here and I will tell If It works, If not I will try with pwnbox and port fowarding

raven cairn
#

Can I have some help with this question???

thorn urchin
#

What about it

raven cairn
#

The queries take forever and I am not sure if I am inputting the corrects ones

solid quarry
#

@thorn urchin not even on pwnbox shows to me

thorn urchin
#

dont search for lightweight

solid quarry
thorn urchin
#

I wasnt taking the greatest of notes in the intro modules cause I just blasted past em

solid quarry
#

Is one of this?

thorn urchin
#

nah

#

I have a quick minute let me see if I can search it again

solid quarry
#

ok

raven cairn
#

Also if anybody wants to help me with my issue feel free to DM

thorn urchin
#

Okay yeah didnt find it, but you can use searchsploit with -x to get the full path of of the exploit and then move it to the metasploit modules directory(usr/share/metasploit-framework/modules/exploits/)

then you can use exploits/50064 and itll work

#

it wont pop up in search even after moving it but you can still use it

solid quarry
#

I did in the box they provided, and It worked, I will try again later in my kali don't know why but thanks anyways

thorn urchin
#

You should just go take a dump or make a sandwhich while you wait

raven cairn
#

Was that the correct query tho?

#

My pwnbox died : ( while it was going

thorn urchin
#

its what I have in my notes so I believe so

#

whats annoying is that bloodhound finds it super fast but has a slightly different name for it that isnt accepted by the question

#

I tried to see if I could work backwards from the bloodhound results to find the name it wanted so I could keep in mind for the future but couldnt figure it out within a reasonable time

raven cairn
#

Would it be ok if I DM you afterward if that doesn't work?

thorn urchin
#

Sure but work is shaping up to be a hectic day so I may be going dark here for some hours

raven cairn
pastel ginkgo
#

@thorn urchin What user did you find for the skills assessment for the pivot on the windows machine? || I've dumped the hashes and only got apendragon , but I also see a user named vfrank on the machine||

thorn urchin
#

my notes are light for that one. But it does look like I got some cleartext creds for vfrank that dont look crackable

#

so youre probably on the right track and just missed it in your dump

pastel ginkgo
#

I trippled checked mimikatz isnt dumping them

placid quest
#

@thorn urchin why is the password of melfay not working on pivoting module

thorn urchin
#

you typing it right?

#

its a weird one

pastel ginkgo
#

The password should work make sure you have it in ''

placid quest
#

Thanks i did not use @pastel ginkgo ''

pastel ginkgo
#

issue im having is that the next user isn't part of my dump

#

yeah any time there are spaces use ''

thorn urchin
#

try a different dump method

#

my notes just have ||dumped lsass|| but not what I used

#

note taking is one of things im trying to improve on in this course 😅

mellow turtle
#

i think is not melfay

#

but mlefay

#

@placid quest

thorn urchin
#

could just be discord typo

mellow turtle
#

maybe u need to set "set +H"

#

because of the !

#

@placid quest

pastel ginkgo
placid quest
#

@mellow turtle yes i need to use ''

thorn urchin
pastel ginkgo
thorn urchin
#

yeah idr what Im using im just commenting on the nature of why its good to try different tools, cause even my fav tool can miss things

pastel ginkgo
#

just in time too since I ran out of time and have to refresh it

#

idk how im going to rdp to the next workstation, I was able to ping it but when I tried to rdp to it, it failed

pastel ginkgo
#

I figured || netsh.exe interface portproxy add v4tov4 listenport=8080 listenaddress=172.16.5.35 connectport=3389 connectaddress=172.16.6.25 || would work on the windows machine to direct traffic, I'm just not sure how to get the linux pivot host to direct || 172.15.6.0 || traffic forward towards || 172.16.5.0 ||

#

I wonder if I can add it to the routing table

thorn urchin
#

havnt messed with netsh much so idk

pastel ginkgo
#

I think its possible you just need to direct the traffic on the remote host on how to get back to you

#

The routing is good on the linux machine with the added chisel server

rustic sage
#

Hi

pastel ginkgo
#

I just think the issue is with the far machine, probably have to get that double piviot thing working

#

i'm just nerding out, as I do network engineering as my day job lol

rustic sage
#

I have a problem mit smbmap. When I type the command smbmap -H host it gets execute and list me the shares. But after I add the /share it does not work

#

No error message

pastel ginkgo
#

shoot a screen shot

rustic sage
#

Same problem with smbclient

#

Okay

#

I send you a picture @pastel ginkgo

#

Because I can't upload the image here;

The output is "Finding open SMB ports….."

#

Not more

thorn urchin
#

iirc to upload here you need to verify your discord profile

rustic sage
#

Hi! I'm trying to solve my first machine and I am stuck! I am currently trying to get the flag for the RedPanda machine. I tried a few different injection methods in the search bar but haven't come to any results yet other than getting a 500 Error for using unclosed tags which I inserted in the search form

rustic sage
#

Ah thank you very much!

#

I apologise, I'm a bit new here

raven cairn
#

No prob

brazen apex
#

Anyone done the Metasploit module? I'm not sure how to exactly phrase this but what does it mean by calling us lazy

#

If you aren't going to use tools then what do you use really? build everything from scratch or what? Or am I taking the phrase tools to literally i.e. tools like nmap, metasploit(obv), burpesuite, and etc

#

Are we not supposed to use them the choice of words they use is confusing to me

wise nimbus
#

I have not done the Metasploit module but generally from my experience when someone says "oh I'm lazy" it's right after they just created some crazy tool that will make it so they don't have to waste time doing tedious repetitive work anymore. In that sense tools are lazy I guess. But also just using tools without understanding what it's doing or why you are using it is bad for learning if that's the context instead.

brazen apex
#

Yeah I wholeheartedly agree

#

and believe what you've said

#

but I don't know its odd the way they put it.

#

To me the whole essence of hacking is being a jack of many trades using many different tools while understanding their protocols exploiting them

#

someone else could put it into better words but thats the best i can do

raven cairn
#

I don't think Metasploit is lazy at all. Best to use the easiest thing for the job

#

🤷‍♂️

#

However you should know how to manually use exploits

#

And metasploit is mostly useful for exploits that have already been discovered

waxen barn
#

Password Mutations SUCKED! @steady hawk helped, and also recommend cracking FTP and increasing your thread count to 48. It'll go way faster than SSH.

wise nimbus
#

There is a book on the mindset of hacking that I was reading that said something along the lines that hacking is fundamentally finding unintended uses for something. In cyber security and ethical hacking you can become as jack of all trades or as specialized as you wish from what I've seen. As far as Metasplot being "lazy", it's lazy in the tech sense in which freeing your time to do greater things by automating the things that hold you up is "lazy". I don't know if it's the same everywhere but many of the people I've known in the tech world compliment themselves by calling themselves lazy.

brazen apex
sly tapir
raven cairn
#

Also I hope cryptocat collabs with me

#

🥹

waxen barn
brazen apex
waxen barn
wise nimbus
wise nimbus
raven cairn
#

Some people think you can just use metasploit haha

thorn urchin
#

metasploit is a powerful tool, but its not a substitute for understanding the actual exploits and techniques being used under the hood, but since its so easy a lot of people DO try to use it as a crutch instead if understanding. Those people are whose being called out as lazy.

raven cairn
#

based

thorn urchin
#

You should, have the capability of being able to run an exploit without metasploit.

its basically the iron man speech to spiderman. If youre nothing without the tool you dont deserve the tool.

raven cairn
thorn urchin
silver zenith
#

Im goona try the bug bounty hunter exam soon i think

thorn urchin
#

no

silver zenith
#

AronRICH

raven cairn
#

You could work a bit on your social engineering my guy 😉

#

Yep you’re full of shit lol

thorn urchin
#

this channel is for discussing academy modules, not for begging for cash, so shutup

raven cairn
#

@violet gyro explain a buffer overflow

thorn urchin
#

youre doing it in a pretty shitty way then

#

nobody cares

raven cairn
#

Cool cool

#

If you need any advice just lmk.

#

Skid

elfin nacelle
#

no embed

#

sad

#

💀

raven cairn
#

Yes I can create a buffer overflow 😸

low vine
#

Yea use the right buffer and it will work perfect

silver zenith
#

So he s hacking people to play robin hood?

#

The man with the bow

raven cairn
#

This shit is too funny haha

low vine
#

[x] we believe you dont worry

elfin nacelle
thorn urchin
#

@winged hedge can we get this moron removed or at least shut up please and thankyou

elfin nacelle
#

how old are you may I ask

low vine
#

Amazing how smart 22 year olds can be

silver zenith
#

Go to codecademy

#

Good place to start coding

low vine
#

click the red quick

thorn urchin
elfin nacelle
#

you have no coding knowledge but can “make 100k year black hat hacking”

raven cairn
#

This is soooooooo good 🤣

elfin nacelle
warm lichen
#

Buzzword hustling 101

low vine
#

50k i swear

silver zenith
#

Hahahaha

elfin nacelle
#

me resisting not to bully this 22 year old who has the intellectual capacity of a raccoon

low vine
#

How dare you insult raccoons like that

elfin nacelle
#

I dislike raccoons 🦝

#

unpopular opinion

low vine
#

Those motherfuckers can get into anything, that dude can hardly turn the power on a computer.

#

Definitely a difference

raven cairn
#

Racoons are awesome

#

Very cute

elfin nacelle
#

HTB is so fun

winged hedge
#

Please keep conversations on topic.

low vine
#

^ boo this man

raven cairn
#

🤣🤣🤣

thorn urchin
#

thats not smart

raven cairn
#

Ban speedrun any%

thorn urchin
#

but yes lets get back on topic please, the bozo is gone

low vine
#

Alright fine ill try to keep getting better

raven cairn
#

Ok fine shitposting was funny

#

@winged hedge thank you for banning that user

elfin nacelle
#

how long have you guys been doin htb

tidal mango
#

Greetings, I have another question for the Active Directory Module... In the "Living Off the Land" section. There is a good amount of this section that talks about downgrading PowerShell to 2.0 and some things to try after you do that. When I try to follow the course work I cannot downgrade, I get the error "Version v2.0.50727 of the .NET Framework is not installed." did anyone else encounter this or find a way to downgrade? Many Thanks!

elfin nacelle
raven cairn
elfin nacelle
#

why is there no general chat

raven cairn
#

This channel is much more chill

elfin nacelle
#

prolly need a role

low vine
#

same lol

#

wait nvm found it

#

its under offtopic

elfin nacelle
#

I only see bot-commands

low vine
elfin nacelle
#

weird af doesn’t even look like it’s a private channel

thorn urchin
#

probably do need verified

#

tbh this channel should prob be locked behind verified

elfin nacelle
#

am I not verified?

low vine
#

^

thorn urchin
#

no

elfin nacelle
#

how do I verify then

thorn urchin
elfin nacelle
#

Ty

low vine
#

I've got an 8 hour roadtrip tomorrow...Hopefully can get in some work on the trip

winged hedge
north ermine
#

Hi !

I am stuck on the last part of skills assessment - file inclusion

I managed to poison the log in the admin control panel and execute basic commands : id,pwd,ls

But everytime that I try to ls the / directory to get the flag file, the admin panel crash

#

Any hints ?

thorn urchin
north ermine
#

Yup it doesn't work either

thorn urchin
#

odd, can try cheating and using the newish base64 php filters to get cmd execution that way. might be more stable

north ermine
#

Hoo didn't hear about this one, can you point it to me please ?

thorn urchin
#

keep in mind its almost certainly outside the scope of the module

thorn urchin
#

but its too good to not add to your toolbox if youre doing lfi

#

theres a ton of boxes with LFI segments you can straight up skip with this method:)

north ermine
#

Hmm this method is indeed teached in the module

thorn urchin
#

dope

north ermine
#

But it doesn't work in my case

thorn urchin
#

that was a fast check

winged hedge
north ermine
#

Sure

thorn urchin
#

yeah if your commands are only failing on certain paths and they've neutered php filters I've got nothing off the top of my head, im a few modules away from starting that one, so good luck.

winged hedge
#

something like <?php phpinfo(); ?>

north ermine
#

it seems that the fastcgi is bugging

silver zenith
#

Got 1 more redbull

north ermine
#

ok I found the issue

#

Problem sovled

warm lichen
#

Also I recommend putting that message in spoiler tags haha

south crown
#

hello

raven cairn
#

HACKTHEBOX PLEASE ADD A DEAL FOR BLACK FRIDAY

inner cave
#

Hi, I am stuck at Attacking Common Services - Easy. I got full credential but having trouble executing webshell. I saw my shell uploaded but i was only able to download not execute. Is there an efficient way to FUZZ path to find out execution path or i am overthink this.. Can anyone please give me a nudge?

tidal mango
graceful mortar
#

Helloooo

inner cave
tidal mango
sly tapir
#

Broken Authentication Module - Brute Force Usernames : Find the valid username for the web application based at subdirectory /question2/. I need a bigger hint..i have tried so many different things here, I have also looked at all the source in response...nothing...can anyone assist?

vital adder
tidal mango
vital adder
#

oh yep if you upload a shell from the ||db|| it will run normal php just fine for some reason, wait but i remember the it was ||mysql|| did they change it to MariaDB?

tidal mango
inner cave
sly tapir
vital adder
raven cairn
#

My boi MRtom is alive !!!

#

how you doin?

graceful mortar
#

someone can help me with Windows Privilege Escalation Skills Assessment - Part II ?

vital adder
graceful mortar
#

@vital adder thanks :}

raven cairn
#

somebody get Mrtom a ps5

#

he deserves one lol

river igloo
#

hello

tidal mango
#

In active directory living off the land... the last question, I am not understanding how to setup my DSQuery and LDAP filter.. Can anyone help me out? "Utilizing techniques learned in this section, find the flag hidden in the description field of a disabled account with administrative privileges. Submit the flag as the answer"

rustic sage
#

please help me Directory Indexing Wordpress

#

I'm going crazy as hell

forest tapir
#

Shells & Payloads - Laudanum is the site filtering uploads? It says "uploaded" and yet it's not there.

#

Do I need to change magic-numbers or something?

#

or add a .zip to the end? The module doesn't say anything about filters.

thorn urchin
#

if youre not in the whitelisted ip addresses it'll 404 you 😉

forest tapir
#

ah, i reset the box and forgot to...

#

fuck

#

lmao

thorn urchin
#

happens

forest tapir
#

blaze erry day, ig

#

feels that way...

#

good lord

pliant sage
#

yo has anybody succeeded in using rpivot to get the web server homepage in pivoting tunneling and port forwarding session?

placid quest
#

@pliant sage use sshuttle like sshuttle -r ubuntu@ip the pivot ip and after browser to the ip address

pliant sage
#

nah it's ok actually I figured out the rpivot problem

#

for those interested, running prxychains firefox-esr with another firefox window already opened does not work

sly grotto
#

hey can u give me hint too for
Find the existing exploit in MSF and use it to get a shell on the target. What is the username of the user you obtained a shell with?

sly grotto
#

did you find the solution?

placid quest
#

@sly grotto use id u will get the user

sly grotto
#

my question is what is the exploit

placid quest
#

@sly grotto what is the question

sly grotto
#

which exploit i should use??

placid quest
#

@sly grotto if u have a shell why do u need to make a reverse shell

placid quest
#

@sly grotto use Metasploit

sly grotto
placid quest
#

@sly grotto how will i know the exploit if cannot see the vulnerability

kind vessel
#

Hello frens, can someone help me with the second question of Kerberoasting - from Linux from the Active Directory Enumeration & Attacks i find the response but I think there are a better way to do it

forest tapir
#

responder?

#

what more could you want

sly grotto
idle hazel
#

hi guys

#

im new here

#

new to cybersecurity in general

placid quest
#

@sly grotto maybe the problem is lhost

sly grotto
idle hazel
#

does anyone have any course i can start with?

placid quest
#

@sly grotto can u send me the screen shot

vital adder
vital adder
# idle hazel does anyone have any course i can start with?

both of this video have a lot of great resources to get started so give this is it check to see where you should started
https://www.youtube.com/watch?v=0vu_Hs4N8B8
https://www.youtube.com/watch?v=lhz0-qAQlBM

Introductory video on getting into hacking and cybersecurity.

▶ Play video

Sponsor: https://go.intigriti.com/thecybermentor
Blog Post: https://tcm-sec.com/so-you-want-to-be-a-hacker-2022-edition/
Academy: https://academy.tcm-sec.com

Timestamps:
0:00 - Introduction
0:53 - Intigriti Sponsorship
1:55 - Building a Foundation
2:10 - Important Notes
5:37 - Basic IT Skills
8:28 - Networking Skills
12:38 - Linux Skills
17:04 ...

▶ Play video
placid quest
#

@vital adder Metasploit module

vital adder
#

and he's replying to people need help with Server-Side-Attacks module?

#

@sly grotto search the answer of ||question 1|| in metasploit and try the exploit that metasploit give you if that doesn't work try a different one

sly grotto
#

i do all the things the best
just metasploit problem
after run 10times it worked :/

rustic sage
vital adder
#

check the ||directory|| show one of the ||example||

rustic sage
#

thanks

#

solved

#

was under my nose and i was searching elsewhere

mellow turtle
#

hey, care what enters in your nose! @rustic sage

loud sapphire
pliant sage
loud sapphire
pliant sage
#

does xfreerdp say it or does the window that opens say the user can't use rdp?

loud sapphire
#

Ah. the user cant use RDP.
I cant set that registry entry without admin access tho no?

pliant sage
#

idk man try to add it see what happens

#

and run ps as admin if you want to it in the command line

terse nova
#

hello guys

#

can anyone help me in one HTB challenge?

#

its called ''Weather App''

terse nova
#

there is no channel like this

vital adder
loud sapphire
pliant sage
#

has anybody done the tunneling w/ chisel part of tunneling and port forwarding? If so, how? When i try to run chisel on the pivot an error get thrown

vital adder
pliant sage
vital adder
#

yea just use the pre-compiled one

pliant sage
vital adder
#

the stuff in the tool github releases page

obtuse moth
#

Skills Assessment - SQL Injection Fundamentals

Hello,
I just finished the skill assessment.
The key was to upload the shell payload not directly to the web root but a directory further. I found out by guessing. My question is know, is there a way to find out in which directory I am able to write files?

winged hedge
loud sapphire
#

how long does it take subbrute.py to find all the subdomains in Attacking common services / Attacking dns.

vital adder
#

for this if subbrute is taking too long you can use gobuster but there is a chance gobuster will miss the subdomain with the flag and there is a chance gobuser will find a pornhub subdomain

loud sapphire
vital adder
#

sure

vital adder
light sinew
#

hay, i stuck in html injection question i can't find the answer

rustic sage
#

Hello colleagues, I have a problem connecting to smbclient. What should I do in this case?

#

smbclient -L 10.129.218.228 -U htb-student
do_connect: Connection to 10.129.218.228 failed (Error NT_STATUS_IO_TIMEOUT)

vital sluice
#

is there any discount for black Friday?

obtuse moth
vital adder
#

my way is just to test every directory you can find but usually www-data have write permission in the web root

vital adder
rustic sage
#

thank you.}

thorn urchin
#

Note in that skills assessment you cant actually write to the webroot, you can only write a few directories in, which is where their question is coming from

#

Im not sure either outside of guessing

vital adder
#

i fotgot but i'm pretty sure they did say something about writing permission in that module

thorn urchin
#

they do, but for that one it doesnt return anything specific

rustic sage
#

I'm going to check again in the scenario to see what could have happened.

thorn urchin
#

I happened to have also cleared the sqli assessment last night before bed. It was pretty easy overall, but the writing part without a little guessing is annoying. but thats life

#

the checking writing perms is only if mysql itself is setting a restriction on where writes can be done, but for the assessment that seems to not be the case, so I presume its being limited by the actual user. tempted to go back and double check

vital adder
#

yep the ||mysql|| user don't have write permission in the web root

rustic sage
#

In the module Password Attacks/Protected Files, after finding the RSA Private key, i tried cracking it using John with both rockyou and the mutatedlist but nothing works. Any help would be appreciated 🙂

loud sapphire
#

check the hashcat examples page for what the hash needs to be formatted like

storm jackal
#

Working through the PIVOTING, TUNNELING, AND PORT FORWARDING module... i feel like it's very easy to get lost in the sauce if you're not keeping track of which host your running commands on. Words like "local host" are being used but it really means the pivot server's local host lol

unique valve
obtuse moth
#

So you also don’t know which OS user you use before writing your shell, don’t you?

#

And that’s the point where my question comes from. Where do I know my OS user and which rights my OS user has ?

mellow turtle
#

i think u need a shell for that

#

u can check what user u are in mysql and what rights u have there

#

then if the user of the sql server have write permissions then you can try writing a shell

#

or if u can read with load_data u can poison logs and then read them with load_data

#

@obtuse moth where are u stuck at

rustic sage
#

WEB REQUESTS - crud api

mellow turtle
#

dont use ''

#

@rustic sage

rustic sage
mellow turtle
#

xD

rustic sage
#

how to find flag, im done with this

obtuse moth
thorn urchin
violet gyro
#

How do you fix this?

obtuse moth
thorn urchin
#

Yes, except you can sometimes get the directory IF a specific directory was configured for it.

#

inside mysql

mellow turtle
#

or creating an error log and reading the error.log

chilly slate
#

cd /tmp

violet gyro
#

Can u increase storage in PWNBOX?

ashen orbit
#

I'm doing the Getting Started knowledge check and running an nmap ssh brute script

#

How does that work, if I guess it boots me after 3 guesses, does it know how to work around that?

thorn urchin
#

just reconnects

#

robot faster than human

ashen orbit
#

were boned when quantum computing is here haha

fossil thicket
#

can

#

someone

#

help me

#

with beef-xss

thorn urchin
#

Havnt touched beef-xss since it came out, is it covered in a module somewhere?

west canopy
thorn urchin
#

Possibly, Im just responding to the message above me

west canopy
#

ah gotcha

raven cairn
#

Beef framework is fun to mess around with

#

Not sure how useful it actually is

thorn urchin
#

its basically just a client side xss exploitation framework. It has the contrivances though on needing to convince the user to keep the tab open while youre doing things though. So often youre gunna be better off being a bit more...precise with your payload.

obtuse moth
#

Any suggestions which academy I should do before doing the in the “real” htb boxes

rustic sage
#

Is it possible to send a message to all Windows users?

balmy radish
obtuse moth
#

As a free user I think these boxes aren’t available 😅
Just want to check the basic so I am ready for the boxes

thorn urchin
#

HTB easy boxes are other places medium and hard, tough to pinpoint what constitutes the basics for ya. Background varies

obtuse moth
#

Mhm I understand
And then learning with the walkthrough?

old verge
#

Hello. I was wondering if somebody can give me a hint concerning "What is the admin email address?" on Footprinting IMAP/POP3? I have tried cto.dev@dev.inlanefreight.htb. I have also logged in as robin.. Any recommendations?

stiff bridge
#

Hi, some1 for a nudge on Skill Assessment - Broken Authentication (privesc)?

hardy anchor
#

Hi everyone. I have a problem with Web Server Pivoting with Rpivot.

Moduel question:
*Using the concepts taught in this section, connect to the web server on the internal network. Submit the flag presented on the home page as the answer. *

My problem is: Once I execute server.py (on attacking host) client.py (on pivote host) and proxychains firefox-esr 172.16.5.135:80 on my attacking host to see the webbpage I got an error "The connection has timed out"

Someone faced the same issue?

#

I'm able to see the flag because of curl (proxychains curl 172.16.5.135:80) command but it shouldn't be the way to solve the module

thorn urchin
rustic sage
#

hi guys, Skills Assessment AD pt 1, have run Winpeas and got admin has, got svc_sql but stuck on tpetty as don't know how to transfer tools from 172.16.6.100 to 172.16.6.50

hardy anchor
thorn urchin
raven cairn
#
  • ippsecc
vital adder
vital adder
#

oh 🤣 hint ||cookie||

forest tapir
vital adder
#

you can just use tor browser or if you want to route tools over tor you can use whonix (gateway)

forest tapir
#

Sure.

thorn urchin
#

yeah when I need to use tor its a QubesOS container getting pointed at a whonix gateway qube

raven cairn
#

Teach me the way of qubes prayge

thorn urchin
#

😉

raven cairn
#

Thanks !!

thorn urchin
#

Ill slowly corrupt the whole server into qube fanatics

weak quail
#

Check for errors in the URL.

weak quail
thorn urchin
raven cairn
coral breach
#

I'm in Firefox Dev Tools, trying to follow along with the 'Web Requests' module. In this part, I'm copying the request as Fetch, and pasting it into the console. But I can't figure out how to see this bottom section as shown in the module page

graceful mortar
#

ii'm very stuck in Windows Privilege Escalation Skills Assessment - Part II , may someone help me in dm?

#

i used windows-escalation-suggester but anyone seens works

vital adder
inner cave
#

Attacking Common Services - Easy: for those who still struggling, I used ps encoded base64 payload via ||sql path|| and got the flag. This community has been really friendly and helpful to beginners.🙏

vital adder
#

yeah... that's a bit too much spoiler, maybe you can get away with spoiler tag only and also for that method i didn't have to encode my payload with base64

inner cave
#

I thought regex could cause some error so i encoded it because most of the time my commands somehow failed.

forest tapir
#

where the heck is the "login" button? It's in the source....

#

I'm not strong with cURL but ig I could login that way...

#

but I also can't seem to find that anywhere in any of the directories

#

idk what's happening, man

thorn urchin
#

which module sammy?

forest tapir
#

Live Engagement on Shells n' payloads

#

Host 2

#

I have creds if you want to check it out

thorn urchin
#

nah I definitely didnt have any visual issues like that when I did it

forest tapir
#

Is it a Links2 problem?

#

I don't like this thing to begin with. I want my Firefox

#

But, alas... no firefox.

acoustic slate
#

ey dudes what going on?

thorn urchin
#

I never used Links2

forest tapir
#

That's all the workstation has.

#

other than Tor, but Tor requires "an update" on first run, so it doesn't want to work.

#

Or am I insane?

thorn urchin
#

I just proxied everything across the host

#

so maybe you are insane lol

forest tapir
#

SSH?

thorn urchin
#

idr what I specifically used

#

probably chisel

forest tapir
#

Hopefully it has a static binary, somwhere. Otherwise, I'm lost.

thorn urchin
#

for chisel you can just build the binary

forest tapir
thorn urchin
#

its literally go build

forest tapir
#

ty for the tip.

thorn urchin
#

unless its a windows box

forest tapir
thorn urchin
#

then you gotta do a little env magic to cross build for windows

forest tapir
#

I'll have to install it on Kali and base64 copy/paste it to the wrk-station

forest tapir
#

luckily it's not tho

thorn urchin
#
git clone https://github.com/jpillora/chisel.git
cd chisel
GOOS=windows GOARCH=amd64 go build
#

dropping the goos and goarch if the dest is not windows

forest tapir
thorn urchin
#

yeah I know

forest tapir
#

So base64 -w 0 > dumb.txt then copy-paste lol

#

i don't think that will work tho

#

does that work??

thorn urchin
#

the webshell ought to have pretty easy file upload

forest tapir
#

it's not a webshell. I'm just on the internal testing-host.

#

so it won't be too bad.

#

Remmina

thorn urchin
#

the initial foothold they give you is a webshell I thought?

forest tapir
#

I'm not sure yet. I can't log in to find any vectors lol

#

I'm not explaining myself lol

thorn urchin
#

no I mean literally the foothold they give you as part of the scenario premise

forest tapir
#

foothold is just RDP

#

you start from the inside the network

thorn urchin
#

my memory seems to be almost completely different

forest tapir
#

lol

#

I can tell you're way past this point

#

I have the same memory issues

thorn urchin
#

its been like a month since I did that modulr

#

and I wasn't taking greatest of notes

#

oh you can ssh into the foothold too not just rdp

#

that's why my memory is different, fuck rdp lol

#

scp over any files if need be or just ssh proxy

forest tapir
thorn urchin
#

why would you need it

forest tapir
#

skill issues. I need to "see it"

#

If I could cURL login to the page, I would.

#

maybe I should revise.....

thorn urchin
#

or you could proxy the foothold and then use firefox at your leisure

forest tapir
#

Yeah. I could scp chisel over and do it that way...

thorn urchin
#

host 2 def also doesnt need visibility, you can get all the necessary information with nmap and the the question basically tells you what to do

vital adder
#

so for this they did update the lab not not long ago (more like a downgrade) but everything you need to exploit all 3 target is already on the foothold machine also i remember nothing you can ssh into this machine if you can it will be great because the rdp thing suck

tidal mango
#

in the AD module... Does anyone know how I would determine what groups a user is a member of on the DC using just linux?

vital adder
#

originally for host 2 you have to enum the page and find a exploit from there now for the updated target and the issue with the web server i'm not sure if this is still the intended way

forest tapir
#

just a mysql config file

#

with passwords n all, but not sure how I'm supposed to know what 50064.rb is (clearly, MSF but how was I supposed to discover it?)

#

unless that's not the point of the exercise...

thorn urchin
#

nmap to get version and then searchsploit

forest tapir
#

idk why i make this shit more complicated...

thorn urchin
#

never skip the basics 😉

forest tapir
#

when I could just use metasploit

#

tryhard mode ig

thorn urchin
#

my little notes did warn I had a slight stumbling block with using it but unhelpfully not what the solution for.

good news though the third host is actually the easiest host of them all but youll probably wrack your brain overthinking it if you dont read the scenario hint for it.

#

pssst spoilers

forest tapir
#

"Lightweight facebook-styled blog" though?

#

really?

thorn urchin
#

funny enough I don't believe thats the only time it pops up in the course

vital adder
forest tapir
thorn urchin
#

cause rdp is ass

forest tapir
#

so i can't see anything properly/ too lazy to sift through the source ig

forest tapir
vital adder
#

yeah i'm also checking right now and nothing seem to load for me too

forest tapir
#

Uh oh...

thorn urchin
#

are you using ass rdp or proxying Firefox

forest tapir
#

no fair

#

I've only been doing this for 7 months lol

#

quit flexing on blue chat

thorn urchin
#

youre a hacker, cheat

forest tapir
#

I should still probably report it as a bug though. Honest to god, I could not figure out what was wrong.

vital adder
forest tapir
#

Not everyone knows what "proxying" is.

#

and I've never done it a day in my life, so no fair sire

thorn urchin
#

When I was on the now defunct securityoverride forums my web skills werent good enough to pass all the challenges. So instead I discovered a hidden .git repo that has the source code for the whole forum(no db backup though), and so I dumped all the challenges answers.

Nobody revoked my score.

forest tapir
#

welp, time to go learn how to use chisel lol

thorn urchin
#

or just ssh proxy

forest tapir
#

good point...

#

see what I mean? lol

#

never would have thought twice

thorn urchin
#

or since youve already found what you needed to know, you might not need either

forest tapir
#

yeah but...

#

idk meng...

thorn urchin
#

or maybe you do, idr

#

¯_(ツ)_/¯

forest tapir
#

I guess that's why they straight up give the answer in the question

forest tapir
#

fuck it.

#

this thing is frankensteined.

#

okay, am I just getting flustered or??

#

maybe i should just walk away...

vital adder
#

you need to import the exploit from the rb file

forest tapir
#

i have to manually import it?

vital adder
#

yep

forest tapir
#

why must i work?

thorn urchin
#

manually importing it is just cp over to the right directory

forest tapir
#

guess i had to do it at some point

#

I'm spoiled from being on THM for too long, kek

thorn urchin
#

youve been drinking milk all your life, youre now ready for whiskey

vital adder
forest tapir
#

jk

#

not really though... haha

vital adder
thorn urchin
#

you put sammy in your own screenshot, you dont have room to complain about doxxing lol

forest tapir
#

good luck finding sammy:"Pennsylvania" lol

thorn urchin
#

🙂

forest tapir
#

not my real name, on purpose either wolflaugh

#

goteem

thorn urchin
#

im going to Pennsylvania in January

forest tapir
thorn urchin
#

visiting a friend

#

for a pagan feast

forest tapir
#

oooooh

#

bro...

#

the f...

forest tapir
#

I'm sticking it in the main folder. Fuck this...

#

under "antivirus"...

#

🖕

#

idk why it won't load

rich mulch
#

Hi guys, I am stuck on Assessment of PIVOTING, TUNNELING, AND PORT FORWARDING

I read the file "for-admin-eyes-only", it only shows me the username, how to get the password?

placid quest
#

@rich mulch use the ssh key to connect

rich mulch
#

I mean what is the password of this user?

placid quest
#

@rich mulch the password maybe at the end of maybe like the plaintext

#

@placid quest yes plain human work

rich mulch
placid quest
#

@rich mulch can u dm me

rich mulch
rustic sage
#

a hint for Active Directory , how to transfer tools to the svc_sql account, there's no chisel, no mimikatz, am using the Windows way because meterpreter is like a dumbshell(but probably it is me who is dumb). I have NT/SYSTEM hash and I launched Winpeas either. Not managing to connect the two ip's:the 172.6.6.*0 and the 172.16.6.5..

forest tapir
#

Or is it blocked?

rustic sage
#

will try them immediately,thank you

forest tapir
#

If they're blocked by AMSI/AV then idk heh

rustic sage
#

!!!awesome,thanks

placid quest
#

@forest tapir he can try to use evil-winrm to upload files

forest tapir
#

that too.

rustic sage
#

am such a noob 😐

forest tapir
#

That's why following Career Paths is nice. It steps you thru the basics, first.

#

Everyone's a noob at first

deft lagoon
#

Hey can somebody please help me with a question of a module

placid quest
#

@deft lagoon what question

deft lagoon
#

IN footprinting imap pop3 the admin question

#

if my pc wont lag i can send a screen wait a sec

#

i cant send a screen maybe i dont have the permission

#

can we go private chat for a sec

#

@placid quest

placid quest
#

@deft lagoon yea

deft lagoon
#

@placid quest cool i dm you

placid quest
#

@deft lagoon ok

deft lagoon
#

@placid quest already done

deft lagoon
#

does anybody have another idea

flint agate
#

I am really stuck on the “Broken Authentication Module” page 5 Weak Bruteforce Protections
I changed the ip to the ip of the website, tried the python script but nothing

flint agate
#

I finally got it, but I used hydra

#

you need to brute force credentials, it is not just about bypassing

light fern
#

Hey guys, with OpenVPN, I'm finding nmap is super slow, I'm in Australia but can only connect to US or EU is this causing the slow scan?

loud sapphire
#

Hello,
Doing the medium box on Attacking Common services. Got a user name from an anon connection but cant seem to brute force the pass. What am i missing?

loud sapphire
placid quest
#

@loud sapphire u maybe missing something but hard to know if u are not seeing anything

loud sapphire
light fern
loud sapphire
light fern
#

I fixed this with a nmap t4 instead of -p- which is good. But hoping for future machines I can get a better ms ?

#

Only EU and US

#

If I go VIP do I get an AU?

solar granite
solar granite
rustic sage
#

wonderful everyone is in pc

light fern
#

I am preferring to use OpenVPN over the HTB machine so I can get use to the real thingI guess that's how I would describe it

#

Are you saying if I use HTB (pwnbox) machine it would be fast?

solar granite
#

They are 2 different platforms really

light fern
#

Ahh ok sorry, HTB ATM. But also working through academy

solar granite
#

I don't know if there's a dedicated AU server for VIP (there probably is, but don't take my word for it), but note that it won't speed up your scans 10x

#

If you're doing big scans (like full port scans) it's still going to take a while, even with a closer server

light fern
#

Ok understood thankyou, what is a good nmap scan? Do you recommend -p-? It estimated about 20-30 mins

solar granite
#

That depends on what you're doing

#

The way I approach is I run a fast scan (like nmap -T4 <IP> -sVC), and launch a full scan (like nmap -T4 <IP> -p-) in the background, after

#

I say it depends because you can maybe find all the open ports with just the top 1000, or you might not and then you need to do a full port scan

#

That way you can also poke at the open ports while waiting for the full scan to finish

light fern
#

Ok sounds good I'll use that thanks mate

solar granite
#

You're welcome

rustic sage
#

what is this ? can someone tell me what to do here?

placid quest
#

@rustic sage where

rustic sage
#

my name

#

what happend to my nick name

placid quest
#

@rustic sage delete " and +

rustic sage
#

still wrong

manic hound
#

open console

#

and use console.log() on that flag string

placid quest
#

@rustic sage stop coping and pasting

forest tapir
rustic sage
#

wait

#

online compiler

#

still buffring

#

nah man something wrong with question

#

how to tell them

#

my bad

#

f my bad

drifting knoll
#

@rustic sage pls be careful with spoilers

rustic sage
#

bruh

#

i forgot to run code xdd

#

sorry guys my bad

forest tapir
forest tapir
rustic sage
#

kk

rustic sage
#

Web Requests - crud api last question

forest tapir
#

maybe you should move on to something else, until another time.

there's nothing wrong with that. I've done it.

forest tapir
#

that's normal

#

growing pains

rustic sage
#

pepepray want all complete

#

looks cool

forest tapir
#

you wanna supplement your knowledge as well. Don't just rely on HTB.

if you're just doing htb and trying to "get through the modules" you won't get far

rustic sage
forest tapir
#

it should be an obsession, tbh

#

and "looking cool" should only be a side effect, not the primary purpose

#

everyone gets frustrated. that's when you step away for a while.

manic hound
forest tapir
#

okay, not "obsession" but a very strong drive

deft lagoon
#

hey can someone help me with footprinting snmp

#

the last question

#

Enumerate the custom script that is running on the system and submit its output as the answer.

rich mulch
#

=====
Hello guys,
I am in Skill Assessments of Pivoting, Tunneling, & Portforwarding module.
I am in the machine of user "mlefay" and I found that this machine also have 2 NICs which are

  1. 172.16.5.0, include its machine: 172.16.5.35 and the Linux machine: 172.16.5.15
  2. 172.16.6.0

I try to discovery hosts by running script to ping all IP in range 172.16.6.1-17.16.6.254 in 172.16.6.0 network, but does not found any new machine
→ I think machine in Network 172.16.6.0 was configured to block ICMP ping

What I should do next to find out other machines?

brazen dust
#

Hello everyone, Can someone get me going in the right direction with the skill assessment for Using Web Proxies. I am trying to enable the button on a website but I a may be going about it the wrong way

loud sapphire
#

doing the final assessment Attacking Common Services - Hard.

I am on the DB and can see the linked server. What i cant get my head around is writing code to execute code on that linked server past what was taught in the module. Can someone help me out please?

vital adder
vital adder
vital adder
# loud sapphire doing the final assessment Attacking Common Services - Hard. I am on the DB a...

hi this is pre-write thing so if you don't understand any shoot me a dm

for example the EXECUTE command if you run 1 command like EXECUTE('select @@servername') AT [LOCAL.TEST.LINKED.SRV] you only need to use 1 single quote but if you need to run 2 command (which is how you get the flag) like EXECUTE('xp_cmdshell ''dir''') AT [LOCAL.TEST.LINKED.SRV] you need to use 2 single quote
so EXECUTE('xp_cmdshell ''dir''') instead of EXECUTE('xp_cmdshell 'dir'')

loud sapphire
#

this is what i was doing wrong.........

brazen dust
vital adder
#

same

ashen orbit
#

if I have a brute force attack running(ftp which seems to take forever), and I walk away and am signed out, does it continue to run?

rich mulch
vital adder
#

yeah the powershell ping sweep one doesn't work for me like at all

#

try the cmd one or the wnetwatcher tool

rich mulch
vital adder
#

i forgot but look in the cheat sheet for cmd ping sweep

deft lagoon
rich mulch
vital adder
#

nope it's the name of the tool

vital adder
vital adder
solar granite
#

Hey guys, need a hint for attacking common services - attacking smb: What is the password for the username "jason"?. Where do I find a passwords list to try for it? The hint says it's in the resources, but I can't find it. I have found an interesting file on the shares (||id_rsa||), but can't access it

Edit: if you're blind like me, there's a Resources button at the top right of the page

rich mulch
vital adder
solar granite
#

Never checked that before lol

rich mulch
vital adder
#

oh wait so that's what the name stand for??? i didn't notice that

leaden quail
#

Can someone give me a hint how i can transfer files in the password attacks hard lab module? Copy + Paste not working and connecting to an smbserver is forbidden

brazen apex
#

Hey I was working on The Payloads section of Using the Metasploit Framework

#

and im stuck I can get the exploit to run but I don't think I'm using the correct payload

#

what kind of payload should I be looking for its a Apache Druid server that im running the exploit on

#

I tried running a few payloads related to https but couldn't get them to work either

#

I think by default Metasploit tries using the tcp_reverse shell payload

vital adder
mellow turtle
#

I think you need to start a upload server (python3 -m uploadserver ) and then upload via http with living off the land , curl etc

#

@leaden quail

vital adder
brazen apex
#

okay I was setting some other options thanks for the feedback

#

ill look into what those are

modern drift
#

Can anyone answer please in my account showing unranked in htb I am new to htb just today I completed the all tasks of starting point can anyone tell what I have to do later

forest tapir
#

you can verify if you want, then start doing boxes or Academy

deft lagoon
vital adder
#

i can't remember but there should be a flag in the format HTB{} in the tool output

rustic sage
rustic sage
#

Someone for a sanity check on Attacking Common Services - Medium assessment?

vale geyser
#

sanity check on XSS Session Hijacking

rustic sage
#

I'm really struggling on find and locate it is ridiculous

buoyant peak
#

i lost my 2fa and backup code and i need any help to login

dim wolf
#

working on the last question of the Skills Assessment for Cracking Passwords With Hashcat. i found the hash that appears the most and cracked it, but inputting the password as the answer appears to be wrong. what should i be looking for?

#

oh, the question in the paragraph above is different than the question where you submit the answer

mild grove
#

Hello,
can somebody pls give me some hint on file upload module - blacklist filters ?

wheat garden
#

anyone available to assist with Attacking Common Services - Easy? I figured out how to upload a webshell but now im stuck and don't know how I can execute it.

jovial bronze
#

hi

#

i need help with something

#

import random

data_list = "abcdefghijklmnopqrstuvwxyz0123456789"
chardData = list(data_list)

password = str(input("password"))
myguess = ""
while(myguess != password):
myguess =random.choices(chardData,k=len(password))
print(myguess)
myguess="".join(myguess)
print("your password is" + myguess)

plain coral
#

There is a handy browser extension called Hack Tools with reverse shells, TTY shells, useful Linux/PowerShell commands and one-liners. LFI, XSS, SQL payloads, data encoding, and more that is helpful.

warm turret
#

@mild grove i do not remember the details but just change the extension to .jpg.php or .php.jpg, then you try using different versions of php there

sly tapir
quasi wave
#

is it practical to do bug bounty pathway while doing infosec fundamentals pathway since bug bounty pathway has no prerequisites?

#

also where is the Exercise Script in the introduction of bash scripting conditions module

quasi wave
#
#!/bin/bash
# Count number of characters in a variable:
#     echo $variable | wc -c

# Variable to encode
$var="nef892na9s1p9asn2aJs71nIsm"

for counter in {1..40}
do
        var=$(echo $var | base64)
        if [counter -eq 35]
        then
        echo $var
        fi
done
#

that's my code

#

can someone point me in the right direction with it?

hidden trellis
#

can someone please help with this error using getuserSPNS -- Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great)

quasi wave
#

this variation on my code also doesn't work:

#!/bin/bash
# Count number of characters in a variable:
#     echo $variable | wc -c

# Variable to encode
$var="nef892na9s1p9asn2aJs71nIsm"

for counter in {1..40}
do
        var=$(echo $var | base64)
    if [counter -eq $var | wc -c]
    then
    echo $var | wc -c
        fi
done
rustic sage
#

same here, this module is mindblowing,but I've learned an abnormous quantity of things. Afterall, it wouldn't be interesting if it were too simple. Still have the Skills Assessment part 2 to do 🙂

forest tapir
#

Is there any way to increase my chances of success with the eternalblue module? Or is it just against the wind...

#

i'm trying a generic payload at this point.

#

i'm guessing it's latency but I don't actually know for sure.

#

praying for patience right now...

solar granite
#

For attacking common services - attacking sql, I found the password of the user mssqlsvc, but I can't use it to connect or impersonate someone else to read the flag. Any hints?

placid quest
#

@solar granite where are u stuck

solar granite
forest tapir
#

Edit: SMB user/pass isn't required I don't think. Let me know if i'm stupid/wrong

placid quest
#

@solar granite can u dm me

forest tapir
#

Regardless, this Workstation "Inlanefreight decided to give me" is fucking annoying. I hope this isn't what it's like in real engagements...

#

everything is broken/outdated + no internet connection... fml.

#
  • 644x480 screen resolution.
#

I don't need display at this point, i'm just bitching/complaining

loud sapphire
#

hello,
Pivoting proxy and portforwarding.

proxychains nmap -v -sn 172.16.5.1-200 does nothing but give me host down for everything.

My attack host is listening on the correct port. proxychains.conf is setup....

Whats wrong?

forest tapir
#

it just worked... what the fffffffffffffffff

#

I spent an entire day @ my work trying this lmao... sorry for taking chat hostage, i'll shut up now.

solar granite
dusty citrus
#

Hi guys, I need a 16 GB RAM chip, can you suggest any good one?

amber otter
#

Go with Crucial

loud sapphire
solar granite
vital adder
#

also the ip is in the question so you don't need to look for it

solar granite
#

You also don't need to find hosts, you are given the address of the host in question

loud sapphire
loud sapphire
solar granite
vital adder
#

just for a sanity check try re-try that command but change the range to a few ip before the actual target

solar granite
#

A ping is not a TCP connection

#

Pings are ICMP and they don't go past proxychains

vital adder
#

oh yea i forgot i don't think you can use a ping scan with proxychains

loud sapphire
#

then why is it an example in the module if i cannot replicate it.....

ill just continue.. i guess.

vital adder
#

but just for sure try changing range to something like 172.16.5.18-20

loud sapphire
#

i changed it to 1-20. same result.

vital adder
#

still no hit?

solar granite
solar granite
vital adder
#

i just give it a try and yep without the ping tag the nmap scan work fine

loud sapphire
#

it should be working for me then. i dunno why i cant replicate.. weird.

somber cosmos
#

No blackfriday ? NotLikeThis

loud sapphire
#

@solar granite @vital adder so i figured out why it wasnt working.

proxychains dont like running as root..... or at least not for me. So i ran as my normal user for shits/giggles and it started reporting back info.

#

thank you both for the help though.

zealous belfry
#

Hey could i get a small hint on hard password cracking lab ? I found the encrypted vhd on the share folder but cracking this thing would take ages.. Also I cant mount it in windows because it requires admin privs so instead i mounted it in my VM. John gave me a guess after like 10 minutes of waiting (~1% pw tryed then) with ||123456789! || but that was not correct.

rustic sage
#

Have some issues with
Linux Fundamentals: Filter contents
Task: Use Curl to obtain the source code of www.inlanefreight.com and filter all unique paths of that domain. Submit the number of paths as the answer.

All this stuff is going straight over me now, I've managed to grep the individual links and listed them, but I'm always getting the numbers wrong.

#

I've managed to curl and grep the individual links, but even counting them manually doesn't work.
|| I believe one path is duplicated? I have the answer now ||

zealous belfry
rustic sage
#

Yes

#

I really dislike filtering stuff

zealous belfry
#

pipe it untill u make it 😄

rustic sage
#

I still didn't really understand much of the code, it's just putting in flags and stuff until it works

zealous belfry
#

did not do the module so i dont rly know what to do there

#

¯_(ツ)_/¯

rustic sage
#

I did after the Getting started one, I only did it to get a better grasp but I left more confused ahaha

zealous belfry
#

😄

twin gulch
#

Hey guys!

#

At PTH, connected to the Rdp and opened mimikatz but forgot how to extract hashes, any suggestions?

#

At password attacks

placid quest
#

@twin gulch use sekurlsa::logonPasswords full

twin gulch
#

Thanks

placid quest
#

No problem

rustic sage
#

Could use some help with Live Engagement in shells and payloads module if anyone is free

rich vortex
#

I am stumped at the very start of: AD Enumeration & Attacks - Skills Assessment Part I - I'm given a password-protected web shell to start but I don't know what to do with that. Any hint would be greatly appreciated.

raven cairn
#

Good morning everyone ✨✨✨

#

Good luck on those academy modules 🔥🔥🔥

raven cairn
vital adder
#

jesus christ pls don't

raven cairn
rich vortex
dim wolf
#

working on the last question of the Skills Assessment for Cracking Passwords With Hashcat. i have the hash i need to crack, but i was really tired so i used a big rule and let hashcat run overnight. it wasn't able to crack it... can someone point me in the right direction?

vital adder
dim wolf
dim wolf
#

i'm supposed to submit the password that appears 5 times right?

#

even though i only see one that appears 6 times

vital adder
#

you need to submit the password that repeat the most time, i don't have to number in my note but i'm pretty sure it's not 5 or 6 time

dim wolf
#

i did that but it wasn't the right answer though

vital adder
#

i think the right one repeat something like 20 time maybe but i'm going off memory

dim wolf
#

oh wait

#

maybe using grep the correct way will work

#

holy shit

#

i'm a fucking genius

vital adder
#

nice

dim wolf
#

thanks for the help

mellow turtle
#

genius

solar granite
#

For attacking common services - email attacks, I have found the email and password, but how do I login? I tried ||AUTH LOGIN|| and then supplying ||base64 encoded email and password||, but I get the following error on port 25: 535 Authentication failed. Restarting authentication process.

vital adder
vital adder
solar granite
vital adder
#

hint yep you got the right one but the command for that is completely different

raven cairn
#

Nah. Those channels toxic AF

#

Zero chill there

solar granite
#

I wonder if the people on #general know MRtom

vital adder
#

properly not 🤣

raven cairn
#

Probably not. MrTom too good for #general .

#

Just a bunch of insecure tryhard skids who try to put down others so they feel better

pastel ginkgo
#

Lol It feels like its mostly the same folks + random the random person asking a question in this chat

thorn urchin
#

it is pretty amusing to see entirely different sets of people hang out in certain channels and not others

forest tapir
#

hey...

#

i hang out in general FeelsBadMan

raven cairn
rich vortex
#

Has anyone completed AD Enumeration & Attacks - Skills Assessment Part I and is willing to offer a tip?

raven cairn
forest tapir
#

true

raven cairn
#

Bad apples can ruin the whole bunch

forest tapir
#

I'm of the belief that any political talk should be outlawed but that's just me

raven cairn
#

Agreed

thorn urchin
#

"hey I disagree with your opinion"
"youre stupid and harassing me!"

actual convo from general yesterday

#

<@&861185840277487616>

raven cairn
#

Some of the Mod team have small PPs

pastel ginkgo
#

Lmao gone in less than 5 seconds

raven cairn
#

Dont care if i get banned for that opinion

tough fjord
#

by law of averages you are probably right

solar granite
#

This hint just saved me. I was close to losing my mind over why I can't find the password with the previous wordlist

tough fjord
#

but by same logic there is a 50% chance you do as well

#

🤷

low girder
forest tapir
#

where's my mans Hyena at?

languid dawn
#

ok on a serious note, please keep the discussion relevant to the channel

low girder
#

I was confused, not sure if I had to deal with madfox or yaoi comment

#

lol

languid dawn
#

thanks for signaling that as well prayge

forest tapir
#

signaling??? PepeGa

forest tapir
#

ok I'm done promise

thorn urchin
languid dawn
low girder
forest tapir
low girder
languid dawn
shy warren
#

Hey @hardy anchor, can you give me a hint of what you added to the php reverse shell command in order to in order to get to the flag in the easy lab?

iron basin
#

Hey I once saw that we can save information to a certain directory on the HTB VMs that will persist between different vms instances, is that true?

solar granite
shy warren
#

Hey all, just curious if I could get a hint regarding Easy lab- Attacking Common Services. I'm attempting to upload the php revershell through a mysql command, however, when navigating to the directory, I get this error " Warning: shell_exec(): Cannot execute a blank command in C:\xampp\htdocs\dashboard\webshells.php on line 1"

I'm certain its just me writing to the wrong directory and something is wrong inside my shell_exec(). Should I be passing 'cmd' as the value?

solar granite
#

I can write files and they appear when browsing there, but it doesn't execute

vital adder
#

for that to execute i end up have to use a php payload with powershell code

mellow turtle
#

what code are u using as webshell?

solar granite
solar granite
#

Also tried system but the result is the same

vital adder
#

use system but instead of $_REQUEST['c'] put powershell there (it can only run 1 command at the time so so you can't get a rev shell just with this)

mellow turtle
#

let me check

#

or directly the command

shell gale
#

Hello everyone, i've recently started the password cracking module but it seems I cant get past the first part as crackmapexec doesnt install properly. Does anyone know a fix?

mellow turtle
#

without $_REQUEST

shell gale
#

oh that seems to have started it, thank you!

solar granite
# mellow turtle without $_REQUEST

I just tried multiple payloads and still it doesn't execute.
||<?php echo system('powershell.exe -c whoami');?>||
||<?php echo system('whoami');?>||
Writing it as ||SELECT "<?php echo system('whoami');?>" INTO OUTFILE 'SPOILER\\shell5.php';||

#

I think that's the correct dir since it appears when browsing to https://IP:443/

vital adder
#

oh wait i miss the echo in your payload remove that

solar granite
#

<?php system('whoami');?> still fails

vital adder
#

and hint if you use the ||mysql|| method the target machine will run normal php just fine only the other method needed this

mellow turtle
#

whats the other method

vital adder
mellow turtle
#

i just used mysql

solar granite
mellow turtle
#

oh