#modules

1 messages · Page 25 of 1

vital adder
#

@worn tusk i mean the command for this

solid quarry
#

What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word) Bloodhound shows 2 but none of those are correct

lethal atlas
#

I may be wrong but it has been my experience that people often forget to try the simple steps first. I catch myself overcomplicating problems here frequently. Always try the basic stuff first, work your way into the more complex solutions when those fail.

loud sapphire
#

so like.. who do we ask about things that shouldnt be in modules?
Im doing the Pivoting module. https://academy.hackthebox.com/module/158/section/1439

So i was scratching my brain wondering why i couldnt find the dll file in the unzipped file..........

Windows deletes it as it detects bad code.

You have to go into settings on the box and windows security to restore the dll... which is fine if you know that this is a thing. but if you dont then..... yay?

Is this part of the module as in "expected knowledge"?

unique valve
loud sapphire
unique valve
#

Yep its that way on purpose in this module to help prepare people for what can be experienced in the real world

loud sapphire
#

oh ok. thought i had better check. usually small hints are dropped. this module has no break pedal. lololol

lucid bloom
#

pls any help with windows fundemantals ntfs vs. share permissions first question. tried everything but notthing get accepted

#

pls

loud sapphire
lucid bloom
#

yes

loud sapphire
# lucid bloom yes

i guarantee you you have done this right. it aint you.

fully refresh your page. try entering it again.

lucid bloom
#

uhhhhhm

vital adder
#

yep try a hard refresh

lucid bloom
#

didn´t bring anything

loud sapphire
# lucid bloom uhhhhhm

yah. i guarantee you did this right.

You need to enter it again after a full refresh of this page

lucid bloom
#

i did

loud sapphire
#

dm me

#

@lucid bloom

brazen apex
#

Whoever made the Password attacks module should really cut the list down

#

like a lot

#

taking forever

loud sapphire
brazen apex
#

maybe possibly more lol

#

I did the math

#

on how long it was taking

#

before I made a script

#

that made it a bit faster

#

it would have taken 5 hours

#

each service

#

like god damn

loud sapphire
brazen apex
#

i mean taking off

loud sapphire
#

@brazen apex DM me for assustance

#

you can fix this with a command and then get the answer in roughly 2 minutes.

brazen apex
#

You talking about ||threads||

#

they didnt affect performance

#

for me

vital adder
drifting glacier
#

Got it, thank you!

loud sapphire
loud sapphire
#

so... HTB broke?

I am using the correct creds....... I also tried .\

#

its driving me a little nuts ngl...

#

its the pivoting module. specifically the RDP and SOCKS Tunneling with SocksOverRDP

solar granite
loud sapphire
#

ahhhhhhhhh

placid quest
#

@solar granite me too i am still stuck on that

loud sapphire
#

ffs..... who so we ask? lol

#

im also soooo glad it aint just me.

solar granite
solar granite
#

Yes

#

||From the victor machine|| I believe

loud sapphire
#

i mean.... yeah.... i can try that.. seems like cheese tho.

solar granite
#

It is, but since the intended way doesn't work I'm not sure what to call it

loud sapphire
#

i calls it cheese lol. bit i like a little cheese here and there.

#

nah. no cheese here. i cant connect to anything. 172.16.6.155 is blocked to me for straight rdp and the intended route via 172.16.5.19 is blocked by a password bug.....

solar granite
loud sapphire
#

i see. i have no path to it tho.. but i will re-attempt.

#

nah. i cant get in direct. they must have fixed that cheese.

im at a total loss.

vital adder
#

so i can verify the victor machine cred do work find the but the third jason machine did give me an error

#

and also for the "password bug" i 100% remember that bug when the module first come out i forgot which machine have that bug and i'm pretty sure they did fix that at one point because a while after i done this module i did come back and do this section the intended way

fathom talon
#

guys

#

anybody down to help me with some hacking

#

I am completely new to hacking

#

and yeah

#

I nearly got hacked 2 times in span of few days

vital adder
#

Introductory video on getting into hacking and cybersecurity.

▶ Play video

Sponsor: https://go.intigriti.com/thecybermentor
Blog Post: https://tcm-sec.com/so-you-want-to-be-a-hacker-2022-edition/
Academy: https://academy.tcm-sec.com

Timestamps:
0:00 - Introduction
0:53 - Intigriti Sponsorship
1:55 - Building a Foundation
2:10 - Important Notes
5:37 - Basic IT Skills
8:28 - Networking Skills
12:38 - Linux Skills
17:04 ...

▶ Play video
fathom talon
#

I do have their IP adress

raven cairn
#

I'm not really a huge liveoverflow fan but this video goes over why leaking an IP isn't that bad.

#

If you want to start learning there is hackthebox academy, and starting point 😉

#

||Also my channel|| Shameless plug warning

solar granite
raven cairn
#

I don't want to be annoying at the end of the day

#

just want to help people out

solar granite
#

I know, was just joking

raven cairn
#

yeah but you are pretty much right lmao

#

No.

fathom talon
#

breh

#

lemme DM one of ya guys

raven cairn
#

No problemo. Just not gonna help you with anything that is stupid.

#

💀 Ok bad idea lol

vital adder
raven cairn
vital adder
#

wait crypto miner? intezer show it's ClipBanker and Discord Token Grabber

high zinc
#

dunno, just a guess based on what virustotal says it "drops" in the temp folder

#

but definitely malware 😄

#

so ty ❤️

lucid mirage
#

It would be much great if java based deserialization attacks is included in the "Introduction to Deserialization Attacks" module. CPTS

#

@dense ferry

vital adder
#

so i just give the RDP and SOCKS Tunneling with SocksOverRDP section a try and everything seem to be working fine for me now, Paddon and crean (don't want to ping) but if you guys still need help shoot me a dm

sand yoke
#

Hi guys i'm new to this server

vital adder
sand yoke
#

thx

#

who here knows about github?

vital adder
#

oh wow that's a hard topics to learn the joke come out kinda mean

raven cairn
sand yoke
#

nah i was just asking

raven cairn
upper fiber
#

hello, I'm at the final part of the shoppy machinr

#

where i have to root the machine

#

but i can't find any credentials for the master password

vital adder
upper fiber
#

oh i see

#

thanks

waxen barn
#

Ok, what am I missing on the Password Attacks - Protected Archived module? I’ve followed the instructions to a T, yet no passwords have been extracted from zip.hash.

solar granite
vital adder
#

same i just do it again for helping other people how to do the "right way" if they want to do it like that

solar granite
#

Your help is definitely appreciated

west canopy
#

Anyone who has completed AD E&A Skills Assessment Part II with a good memory available?

pastel ginkgo
vital adder
#

i waited like 5 min after i god the target ip for everything to fully boot up and that seem to fixed some of the issue

thorn urchin
thorn urchin
#

sure

waxen barn
#

Ok, what’s up with the Protected Archived module on Password Attacks?

dry parrot
#

Hi 🙂

#

im going though Server side attacks

#

and when im trying to install tplmap tool i found that This project is no longer maintained

#

someone have any alternatives?

#

is based on tplmap

#

so i think is a good alternative

vital adder
# waxen barn Ok, what’s up with the Protected Archived module on Password Attacks?

so for that i did help one guy with a weird issue but basically he got a ||pkzip|| hash when extract the hash on his kali and i got a different one on the pwnbox and when i try it on my kali sure enough i got the same hash but the different is i can crack it but he can't (we're using the same tool and wordlist) but all he did was wait a day and try again and it work for some reason

#

if you are having issue with that wait a day and try again or shoot me a dm

trim goblet
#

So I'm attempting to connect to a box for my first time. Im connected via Openvpn to the starting point server and I have an online target machine. My task is to telnet in, I'm using (telnet -l root <Ip adress> <port 23>. I continue to get a Connection refused. Also should I be able to ping the server or the target machine(because i cannot)

steady hawk
trim goblet
#

Ok I was able to figure it out. I was not running openvpn as su

inland coral
waxen barn
vital adder
#

oh that's weird first time i heard of re-mutated the wordlist for this module

raven cairn
rustic sage
#

So close to finishing another path : D

#

(one costs 2k)
D :

rustic sage
#

2k cubes ?

#

Enumeration ^^

#

It's the last one, at the bottom

drowsy scaffold
#

Use school email for free modules (from tier0 to tier2)

rustic sage
#

I do not go to school 💀

drowsy scaffold
#

You know no one going?

rustic sage
#

I do but it gives me time to save whilst I'm going over the initial modules again

#

Stuff like OS fundamentals

drowsy scaffold
#

Well it's also a way to do it

thin shuttle
#

pr++join prolabs-dante

#

++join prolabs-dante

little whaleBOT
#

I don't know what role that is. Did you spell it right?

rustic sage
vital adder
waxen barn
pastel ginkgo
#

yeah that module is a slog

#

The AD enumeration and Attacks is also a slog but its just a crap ton of material to go through. So its a happy slog.

brazen apex
#

#module: Password Attacks
#Section: Network Services
Man does Crackmapexec just not work I feel like im gonna go insane its gone through the 2 lists 2 times now with no credentials for ssh I need some advice on how to continue because running it a third time I don't think is gonna make it work

pastel ginkgo
#

What other services are running? Attacking ssh takes a long time, why not try another service

brazen apex
#

I didnt know you could do that

#

I thought that it would stop bopth processes

#

if I tried "attacking" the target with so many

#

at a time

pastel ginkgo
#

I mean you could end up dosing the target if you were going like absolutely ham

brazen apex
#

I have xargs running 20 instances of crackmapexec

#

lmao

pastel ginkgo
#

lmao your fine

#

I think I did it with Hydra and did like 64 threads

brazen apex
#

alright thanks I'm definitely gonna do that then

#

can I use crackmapexec or would I have to use

pastel ginkgo
#

Yeah for that entire module just try other services, rarely should you ever attack ssh directly

brazen apex
#

a different service like hydra

#

just curious

pastel ginkgo
#

If I remember correctly that module has you use hydra and crack map

#

hyrdra wont work with smb if I remember correctly but crackmap will

brazen apex
#

Yeah it does but I guess im asking there wont be any issues

#

if I lets say used crackmap for 3 different services at a time

#

like rdp winrm and smb

pastel ginkgo
#

depends on the device, if it can handle the traffic

brazen apex
#

Okay gotcha

pastel ginkgo
#

a server can obviously handle more traffic than a end device

brazen apex
#

I guess I was wondering if the program would allow it yk

pastel ginkgo
#

I dont see why not

brazen apex
#

It solely depends on the network then

#

thanks man

potent ermine
#

Hey guys, I need some help on the 'File Transfers' Module. I'm in the first section 'Windows File Transfer Methods'. I'm having trouble with the 2nd question in the assessment. It's asking me to RDP to the box and the credentials have been provided. How can I RDP into the box? I have tried ssh and smbclient and I haven't been successful.

pastel ginkgo
#

RDP is a windows protocol so you'd have to access it via port 3389 using a RDP tool. So xfreerdp or my prefered being reminia

raven cairn
#

Dumb question. Why am I not able to authenticate with Impacket.

#

I know I am missing something super obvious

#

but I don't know what

pastel ginkgo
#

I remember that one kinda just working

#

I remember because I was trying to figure out how to leverage some other user then I realized they kinda give it to you

#

which page of the module is that

raven cairn
#

Active Directory Enumeration and Attacks - Privileged Access

#

This is what the module tells me to do

pastel ginkgo
#

yeah that should just work

#

try resetting it

cinder arrow
#

Hiii

#

I'm from Philippines

raven cairn
#

sup

pastel ginkgo
#

yup that should just be a connect and follow instructions one, I remember because they have you look up some user who also has PS access or some crap and I thought we had to leverage our way to his account then do the msql stuff

#

turned out "oh I suck at reading" and was done in 2 mins

thorn urchin
pastel ginkgo
#

yup that'll do it idk why I didnt see that

raven cairn
#

jumpbox??

pastel ginkgo
#

have to remember your on the 10 network

raven cairn
#

never heard that term

thorn urchin
#

pivot host if you prefer

raven cairn
#

Ok

pastel ginkgo
#

ssh to the 10 ip then attack from that host or setup a piviot

thorn urchin
#

A jump server, jump host or jump box is a system on a network used to access and manage devices in a separate security zone. A jump server is a hardened and monitored device that spans two dissimilar security zones and provides a controlled means of access between them. The most common example is managing a host in a DMZ from trusted networks or...

raven cairn
#

stupid me

#

I get tunnel vision sometimes haha

thorn urchin
#

ironically if you 'tunneled' your vision, youd not have a problem 😛

brazen apex
#

I figured out why I've wasted hours on the network services portion of password cracking

#

crackmapexec deosnt always print out Pwn3d on success

#

and thats what ive been greping this whole time 🥲

thorn urchin
#

it only prints Pwn3d if it detects it to be a local admin 🙂

raven cairn
pastel ginkgo
#

So they tell you to ssh to that 10 ip right?

thorn urchin
pastel ginkgo
#

thats the attack box they have setup within the target network

#

you can attack from either that box

thorn urchin
#

usually setup with the tools you already need on there

pastel ginkgo
#

or just use it a a pivot and proxychain your way in

raven cairn
thorn urchin
#

theres usually also a linux host for Linux relevant sections

#

or you create a tunnel

pastel ginkgo
#

good practice to setup a piviot

#

I was able to get a netsh piviot working on the machines in this module too

raven cairn
#

I got it : )

#

I haven't finished the pivoting, tunneling and port forwarding modules yet

thorn urchin
#

are you just yoloing whatever module you feel like at the time lol?

raven cairn
#

That's pretty much what i do

#

I should follow stuff in order haha

thorn urchin
#

¯_(ツ)_/¯

pastel ginkgo
#

Lol The AD enum module is a slog too

#

idk if its just me but for what ever reason my remote vm keep on kicking me out

#

@thorn urchin How far are you in the pathway anyways?

thorn urchin
#

70~%

pastel ginkgo
#

Are you able to solve easy boxes on htb yet? it still seems to be crazy hard for me

thorn urchin
#

Ive solved some in the past, but I havnt tackled any since doing the path, not a priority to me.

#

most boxes are just X random web vuln, chain to Y random web vuln to get user, then random BS go for root.

pastel ginkgo
#

yeah the red pandas (recently retired) the user wasn't to bad but after that it was a nightmare. Watching Ipsec video on it was like how in the hell

thorn urchin
#

Red panda was the most recent one I did, but never got around to root

#

I dont think the cpts pathway has material that woulda been relevant for the root path on that one tbh

swift carbon
#

I am about 24% done. It's taking me a lot longer to go through all the modules than I thought, but the material is very good so I'm not complaining.

sly tapir
#

just finished that broken authentication module...damn that was rough...finishing the skills assessment is a morale booster haha

pastel ginkgo
#

I can create the ticket without issue but I can't psexec with the created golden ticket

#

@thorn urchin Did you have any trouble with Attacking Domain Trusts - Child -> Parent Trusts - from Linux ?

thorn urchin
#

no was a pretty straightforward one for me

pastel ginkgo
#

I figured it out I just said screw it and copied and pasted their commands and it worked. Meaning ive been fat fingering something this entire time

#

How did you get secrets dump.py to use your ticket?

#

I've tried -k and -no-pass but it doesnt work

thorn urchin
#

does kinit see your ticket as loaded?

#

with the ccache file and all that jazz?

pastel ginkgo
#

yup

#

Am I just not doing the command correctly?|| secretsdump.py logistics.inlanefreight.local/paste@172.16.5.5 -just-dc-user INLANEFREIGHT/bross -k ||

thorn urchin
#

looks good to me, noticing my notes for the section doesnt have secretsdump for it though,

pastel ginkgo
#

How did you get the ntlm hash then?

thorn urchin
#

my notes doesn't actually have the end section assessment so idk lol im loading the module back up now

pastel ginkgo
#

im banging my head against this atm lol

thorn urchin
#

that vaguely looks familiar

#

I mightve tried one of the other dumping methods

pastel ginkgo
#

idk how to get it to dump using the method they want us to use

#

im starting to wonder if maybe the ticket i generated isnt good after all

#

Double checked my ticket I can get C drive access I just cant get it to dump

#

not sure what im missing

#

@thorn urchin I got it, was not able to get it via the kerberos ticket though

thorn urchin
#

okay just went through it

#

you need to have your created user @ the FQDN of the dc controller, not just @rustic sage

#

and secretsdump will get it just fine

pastel ginkgo
#

so inlanefreight.local?

thorn urchin
#

nah

#

the full name of the dc controller

#

the academy-blah.inlanefreight.locsl

pastel ginkgo
#

hmm still failing on me

thorn urchin
#

oh its also still logistics.inlanefreight.local/fakeuser

pastel ginkgo
#

still not working for me

#

I was able to get it via the hash method

#

but not via the ticket

thorn urchin
#

yeah it suddenly stopped working for me even running the exact same working command within the same session

#

I think its just temperamental

#

whats the hash method

pastel ginkgo
#

so using || the raisechild.py it spits out the administrator ntlm you can pass that hash and it will work ||

thorn urchin
#

ah gotcha

#

yeah I think it uses a slightly different method for the extraSIDs

pastel ginkgo
#

werid reset it now im getting invalid checksum

thorn urchin
#

the manual method worked for me again after I regenerated a new ccache file

#

also it says you can use a fake user but I cant help but wonder if itd be more stable if you used a real username on the child domain since the error message is about not being able to find the spn

pastel ginkgo
#

annnd it finnaly worked

#

regenerated it and it worked

#

idk Im done for the night this shit drove me batty

#

Going to write this down though as im not doing it again in the skills assessment

thorn urchin
#

no spoilers but I wouldnt stress too much about it

#

but yeah regenning the ccache if its giving you errors is def note worthy

pastel ginkgo
#

im glad cpts is a week long as i'll end up going through the modules to brainstorm

thorn urchin
#

definitely wont hurt I imagine

#

Ive considered doing a blind run of all the skills assessment after I finished but that may be too tedious. gunna do the dante prolab though as extra prep for sure.

pastel ginkgo
#

same that and do a few boxes too

coral breach
#

If someone has an answer to this, please @ me so I don't miss your response when I check back in later. **Has anyone had success proxying Metaspoit through Burp/Zap? ** I tried using msf through proxychains, I tried setting the proxy within metasploit. No matter what I tried it never got intercepted by Burp or Zap.

In previous exercises I did get some things to work through proxychains (like curl), but just never Metasploit. Thanks

thorn urchin
coral breach
thorn urchin
#

yeah

#

its type ip port

waxen barn
# pastel ginkgo same that and do a few boxes too

I’m gonna try and do the boxes they recommend that are also on TJ Null’s OSCP prep list (minus BOF). Figured that would aid in prep for both certs. Dante’s Pro Lab is going to be my graduation event before doing the CPTS too. I’d rather over prepare than have to go through another week of the exam.

waxen barn
wheat garden
#

any one on done attacking common services - medium skill assessment? Im stuck.

I found the 2nd ftp service got username s---- and tried brute forcing both ftp services and pop3 service using the provided pass list and s---- username and am not getting any hits.

If any one can provide more insight.

rustic sage
#

Hey, can anybody help with Information Gathering Web Edition - Active Infrastructure Identification? I think I may have a DNS issue.

thorn urchin
rustic sage
# thorn urchin gotta add the host to your /etc/hosts file

@thorn urchin I've added inlanefreight.local as the IP was provided at the start of the exercise and I can enumerate that host with no issues, I can't work out a way to find the dev.inlanefreight and app.inlanefreight IP addresses though

rustic sage
#

Did you add dev.inlanefreight.local and app.inlanefreight.local to your /etc/hosts? or just inlanefreight.local

#

@rustic sage

#

just inlanefreight.local @rustic sage

#

Can you give a hint on how to enumerate for the IPs of the subdomains? All methods previously taught don't work

thorn urchin
rustic sage
#

^^

#

you’re trying to enter a domain and your computer has no idea how to resolve it. You have to add subdomains to the /etc/hosts file as well before you can ping/reach them

#

@thorn urchin @rustic sage I add them under the same IP? This is a learning for me

#

you can add multiple lines or add them on the same line either works

#

<ip> inlanefreight.local dev.inlanefreight.local app.inlanefreight.local

OR

<ip> inlanefreight.local
<ip> dev.inlanefreight.local
<ip> app.inlanefreight.local

#

I always do multiple lines because I find it easier just to echo ‘ip domain’ | sudo tee -a /etc/hosts

#

and you will need to do that for every subdomain/VHOST you find or else you won’t be able to reach it

sleek citrus
#

not sure if this is needed, but you should install it through pipx

sudo python3 -m pip install pipx
sudo pipx install crackmapexec
loud sapphire
rich vale
#

on the AD Enum course, whats the 'right' way for interacting with the target network?

#

the attacker linux host provided seems to be missing some stuff, like trying to run kerbrute. is the right way for the lab to just try and install tools/dependencies on the box, or should i be trying to tunnel through?

flat karma
#

Hey everyone , i m block in Web Service & API Fundamentals. I dont understand the meaning of the question "If you should think of the operation object in WSDL as a programming concept, which of the following is closer in terms of the provided functionality? " ? someone help me ? I m sorry for my bad english it's not my native language

upper flame
#

bro i like your font color can you tell me the Hex code of your font color

rustic sage
#

On the ZAP scanner question, i could run the scanner but found no high level vulnerability. Any help please:)

rustic sage
#

Having an issue with this too

#

If I can get a prod into the right direction it'd be appreciated!

rustic sage
#

@ocean raft mate unblock me

#

Pls

#

@ocean raft plssss

simple zephyr
#

I am looking for help with the footprinting module for IMAP I am going through the list from hacktricks and not finding any messages.

raven saddle
#

Hello, I'm on the Htb academy. I'm doing the module: Web Request.

#

I'm on the GET section. & I was doing the instance, and I tried to do a search for the flag but the new request didn't pop up. Can someone explain to me what I did wrong?

#

Hi, I'm also on that section. Did you ever find help for that part?

woeful karma
#

okay hackthebox in my opinion so far after purchasing is honestly terrible. When I read a module, I learn a few things. But then the question it's asking is completely different to what I've just read. I'm currently on "Working with web services" and its asking me to use npm, a command I've never even seen before. How am I supposed to know what to do if I'm not taught anything about what the question is asking?

I don't mean to come off as a being rude or anything, I'm genuinely curious as to how other people do it.

low vine
#

Most people google to get an idea and if they struggle they ask further questions in here

rustic sage
# woeful karma okay hackthebox in my opinion so far after purchasing is honestly terrible. When...

you're not always going to be given the answer that goes for anything... You've been taught to read man pages and to do outside research. If you cannot do that this really isn't the field for you. You will need to always be constantly learning and reading new tools, man pages, and new attacks.

The questions for the modules aren't always "repeat what you learned above." Sometimes they are, but they are also there to challenge you and get you in the mindset for what you'll be doing in this field.

woeful karma
low vine
#

Say you're doing a pentest for someone and you see some sort of service that you're unfamiliar with. How are you going to figure out how to move forward and test that?

#

There wont always be a do X. Sometimes we gotta google around and try to figure it out and work from there

vital adder
raven saddle
#

Anyone?

vital adder
rustic sage
#

My advice is instead of saying how the platform is awful and doesn't teach you what you're being asked, try telling us what you tried, what went wrong, where you're struggling so you can get a nudge in the right direction @woeful karma. Not just "I'm never taught this, this module is terrible"

woeful karma
raven saddle
raven saddle
#

Wait, I don't want an answer to the question. I'm in the Network tab of the inspection. But whenever I search "flag" new requests don't pop up. Is there something wrong w my steps? Did I skip something?

rustic sage
vital adder
vital adder
woeful karma
vital adder
rustic sage
#

Had a small typo aha ^^;

#

Also finishing a module isn't the end. You should go back and make sure you understand the tool, what you were taught, and why the command gave you such output in the first place. I can't express enough how important it is to understand the tool you're using and what it is doing behind the scenes to feed you that output

raven saddle
vital adder
#

oh that hint was just pointing you to the thing you missed

rustic sage
#

and if you're doing a job path such as the CBBH or CPTS, it's even more important because you really do need notes and need to understand what the tool is doing before you use it actively

simple zephyr
#

anyone on that knows the IMAP, I found the mail folder that i think i should be in and can see that one email exists but can't open it.

#

never mind got it

rustic sage
#

I always make little notes on flags and stuff a tool can do

#

Then I use the hell out of it

#

And try to test the limits of it

simple zephyr
#

lol i think i found a later flag i wasn't supposed to find yet in this box

vital adder
#

module like that one i think use the same target machine for multiple section so there is a chance that will happen

iron summit
#

Happens quite a lot. Make a note. You'll probably need it in 10 mins time 😉

raven saddle
vital adder
#

||header||

raven saddle
#

I can't see that

#

All I see is a black mark.

vital adder
#

i mean on the section

raven saddle
#

Can I message you what I'm doing?

vital adder
#

sure

brazen apex
#

Why does ssh take so much longer to brute force vs any other network service

iron summit
#

... possibly the question should be 'why don't all the other network services enforce an arbitrary delay on password failure?' 😉

warm moth
#

hello

hasty solar
#

hey in Firewall and IDS/IPS Evasion - Hard Lab you have to find the service in UDP or TCP Scan? and which service do you have to find?

rustic sage
#

the service

#

run both and see what comes up🤷‍♂️ enumerate the services found and see what they give you!

hasty solar
#

I have already done it and when trying tu put the answer got the following message : INcorret answer

rustic sage
#

remove that so no spoilers are leaked

#

you can dm me and I'll tell you if you're submitting the right flag or not

hasty solar
#

ok sorry

cold marsh
#

someone can help me on Web Service & API Attacks - Skills Assessment

#

CBBH Path

rustic sage
cold marsh
#

kk thank you

shrewd wasp
raven saddle
civic nymph
#

hello

#

im here to learn ethical hacking'

#

im in class 8

brazen apex
#

what does class 8 mean

vital adder
# civic nymph im here to learn ethical hacking'

Introductory video on getting into hacking and cybersecurity.

▶ Play video

Sponsor: https://go.intigriti.com/thecybermentor
Blog Post: https://tcm-sec.com/so-you-want-to-be-a-hacker-2022-edition/
Academy: https://academy.tcm-sec.com

Timestamps:
0:00 - Introduction
0:53 - Intigriti Sponsorship
1:55 - Building a Foundation
2:10 - Important Notes
5:37 - Basic IT Skills
8:28 - Networking Skills
12:38 - Linux Skills
17:04 ...

▶ Play video
civic nymph
#

school ?

#

u dont know school

brazen apex
#

ohokay

civic nymph
#

k

brazen apex
#

yeah check out mah boi 0xyaoi

#

His videos can get you started pretty quick

#

does you school have its own email

#

address or whatever

civic nymph
civic nymph
brazen apex
#

becuase you can use that to get a pretty hefty discount on the academy

#

modules 0-2

#

for about 8$ a month

civic nymph
#

i wanted to ask

brazen apex
#

sign up using your schools

#

its what i did anyways

civic nymph
brazen apex
#

on youtube @vital adder just sent a few

civic nymph
#

oh thaks

brazen apex
#

yep goodluck hacking feel free to ask questions here when your stuck theres plenty of people willing to help

#

I can help with a few im not that far in tho

open drum
#

Hello people.... how are you today, God bless you!

vital adder
#

i will be with god soon so thanks

solar granite
vital adder
#

just a little brain damage

loud sapphire
solar granite
#

The server would definitely collapse without the helpful squirrel

raven cairn
raven cairn
sterile temple
#

Can anyone help or give me a little hint. I'm on password attack hard lab. I already have the vhd file but i don't find a way to read it, already have a The password. I try guestmount, i try to Open on My windows host machine (no proud but i read that it was a way but no) almost done with this interesting module hahaha any help would be appreciated.

vital adder
forest tapir
#

Yeah, so wtf is going on here?

#

"Works fine on my machine"

#

But not on target.

solar granite
rustic sage
#

Please find the unique malware in this windows 10 iso file.

hasty temple
#

Hi. I'm trying to finish the footprinting medium lab. I got the sa:password from the txt file. I can't seem to get past the sql login. I tried to log in with sa and Administrator but no luck. I also tried to remote in with sa as user as well as Administrator but no luck with that either. All I can do is remote in with Alex. I'd appreciate any help. Thanks.

pastel ginkgo
mellow turtle
#

@hasty temple dont share users and passwords here

hasty temple
#

Hey thanks for the help

rustic sage
#

I am targeted by a hacker group. They altered the iso file that I downloaded from microsoft's website.
I am %99 sure that this iso file has a unique undetected RAT malware

pastel ginkgo
#

@west rampart @languid dawn @sharp cove I think this falls under your purview?

west rampart
#

@rustic sage We're not downloading any weird iso files

#

@rustic sage Please read the rules of the Server. Thanks

thorn urchin
#

@rustic sage also not the right channel for it even if were allowed. also also unique undetected malware is actually pretty common. Even basic stuff thats written by amateurs automatically become unique and will evade half of AV. Doesnt take a whole lot of effort to make it bypass the rest. Not that special.

lucid bloom
#

Linux Fundemantals Section Working with Web Services, first question - there are multiple http frameworks/servers - which one should i use?

lucid bloom
#

yes but in npm are more than one

pastel ginkgo
#

I think your over thinking this

#

think " I have zero linux knowledge" and go from there

lucid bloom
forest tapir
#

🤷‍♂️

pastel ginkgo
#

what is what is shown on the page?

thorn urchin
#

Id go with the one http-server that calls it a simple http server

#

and cli based

pastel ginkgo
#

answers for 95% of the module questions are listed in the module

#

the other 5% involve smashing your head on the keyboard

hasty temple
#

You’re not kidding

pastel ginkgo
#

just wait till you actually come across a bug in the module its the worst lol

thorn urchin
#

yeah theyre not many but theyre painful

#

but also working around RL bugs and faulty documentation is true to life

pastel ginkgo
#

yup, apparently the bug in the pivot module was fixed or at least was working now according to MrTom

cursive burrow
#

Hello there, I'm currently giving the linux fundamentals a go, and I'm at this point where I get this error and I'm not sure why. I'd love to know what I'm doing wrong.

#
mv: cannot move 'info.txt' to 'Storage/': Not a directory```
#

I thought that the Storage/local/user were directories, do I need to specify the full path to Storage?

pastel ginkgo
#

is storage in your current directory?

cursive burrow
#

I'm further in the tree of it.

pastel ginkgo
#

if your deeper, then you need to move up with ..

#

the way you currently have it you want it to move into a directory called storage within your current directory

cursive burrow
#

got it. So if I wanted to move it, then I should navigate to storage and execute something like, mv /local/user/info.txt /Storage

pastel ginkgo
#

If the info.txt is in your current directory you could just do ./info.txt /storage

#

way easier then specifying the entire directory, but if its not then you need to specify the entire path

#

For example if I wanted user.txt from johns directory and put it in my own home directory id do something like mv /user/john/user.txt ~/

fallow delta
#

Anyone free for a nudge on Command Injection Skills Assessment?

woeful mural
#

Anyone finish with the footprinting module. DNS section. I'm having trouble with the last question

rustic sage
#

could I dm someone about MSSQL?

manic hound
forest tapir
#

PassAttack - PtH I'm a little confused. David doesn't seem to have permissions on the SMB share on the Domain Controller, at least according to this but he can authenticate:

coral breach
thorn urchin
#

cause you can have permission for some shares but not others, authentication is seperate.

forest tapir
#

So, I have to take it upon myself to "give him permission"?

#

Can a local Administrator even do that remotely?

thorn urchin
#

maybe I dont remember that section very well

#

I usually only save notes about the module and the end full skill assessment, I dont often write notes for the section by section tests

placid quest
#

@thorn urchin hei i need ur help

thorn urchin
#

busy atm but ask away and maybe ill have something or someone else can chime in

placid quest
#

Ok no problem

timber hatch
#

hello
at the modul file inclusion in section automated scanning, should this command work as explained in the example with the spawned webpage?
xy@htb[/htb]$ curl http://<SERVER_IP>:<PORT>/index.php?language=../../../../etc/apache2/apache2.conf

...SNIP...
ServerAdmin webmaster@localhost
DocumentRoot /var/www/html

    ErrorLog ${APACHE_LOG_DIR}/error.log
    CustomLog ${APACHE_LOG_DIR}/access.log combined

...SNIP...

stiff moon
#

yo i got root but could u explain to me (in dm if u want) why or how that works

im a bit confused how this priveleg escalation works

coarse mango
#

hey everyone. I am currently doing Bash Scripting, section Flow Control and I am having trouble with my script

#

if anyone could help id appreciate it

iron summit
# coarse mango hey everyone. I am currently doing Bash Scripting, section Flow Control and I am...

Heya. I've gotta dash... but I got bitten on this module last night. If you're pretty sure you've got it right and it should be working... I think there's a problem in this module. If you're using something like: ${#variable} to get the length to set your salt (as you're taught in the Arithmetic section) ... it won't work. If you the earlier method (echo $variable | wc -c)... then it'll appear to work. Technically... the latter method is wrong, as it also counts a newline, so it's off by one.

iron summit
timber hatch
#

somebody knows if there will come azure or aws modules?

#

can i DM you...would appreciate some help with the file inclusion automated scanning stuff....?

patent whale
#

Hi everyone, I need a little nudge for the Password Attacks > Mutations module. I downloaded the resources and created a password list, using the provided rules. Resulting list is 90k+ strings. As expected, bruteforcing SSH is slow (up to 30 tries per minute), which means that either I can have a luck, or wait for tens of hours. Is there anything I might have missed?

thorn urchin
#

it will still take ages however

patent whale
gaunt juniper
#

can someone help me at the nmap scanning module HTB at medium lab i've been stuck over a week

#

it's so hard lool

#

for me *

#

Firewall and IDS/IPS Evasion - Medium Lab

pastel ginkgo
#

@thorn urchin Can you shoot me a tiny nudge for the AD Skills assessment? I got a meterpreter foothold on the webshell machine and I was able to dump the admin hashes but I cant crack the admin password. I've tried getting Domain spray on it but I cant import the module at all

forest tapir
thorn urchin
#

go back to the basics and what every AD testers favorite thing to run once on a AD network.

rustic sage
#

How it feels asking for help here when the answer is a simple oversight

pastel ginkgo
thorn urchin
#

I dont believe so, where ya getting rdp from?

pastel ginkgo
#

ikm so lost on this module the most I can get is the inital foothold from the webshell to a reverse shell

#

cant import active directory

#

on either a nc shell or metasploit

thorn urchin
#

dont really need to, the webshell is already a shell

elfin timber
#

For Getting Started: Privilege Escalation

I have made a copy of the file but I am having trouble getting wget to transfer the file:
user2: python3 -m http.server 8000

attacker: wget http://138.68.191.22:8000/file

rustic sage
#

Helloooo I require some help again, this time I am stuck on Web Information Gathering - Active Subdomain Enumeration. Can anyone please DM?

I have added the host to /etc/hosts and can ping it with it returning the IP address but I can't perform an nslookup on it to complete the first challenge.

thorn urchin
#

otherwise its just gunna go off your system dns which isnt going to know anything about the domain

pastel ginkgo
#

Administrators failed when I tried rockyou against it

thorn urchin
#

you dont need to go after the webhost administrator at all

#

forget it even exists

pastel ginkgo
#

Id just like to get a working version of powershell

#

I figured out what wasnt working with meterpreters for importing modules then it broke when giving output lol

thorn urchin
#

I didnt bother

pastel ginkgo
#

i know im supposed to enumerate the AD but nothing seems to be working for me on that front lol

thorn urchin
#

I did what I needed to get the kerberoast going, and then switched to a chisel pivot once I had network creds

elfin timber
#

anyone please?

thorn urchin
elfin timber
#

it will just keep attempting to connect

thorn urchin
#

any output on your listener side?

elfin timber
#

can you not put screenshots in here?

thorn urchin
#

you can

#

might be blocked for unverified users

elfin timber
#

im using snippet tool and I cant paste it

thorn urchin
#

thats unfortunate

elfin timber
thorn urchin
#

and youre sure thats the right ip

elfin timber
#

so i checked ifconfig and I see its a completely diff ip

#

I changed it and nothing happened still

#

im so lost... why is the IP that spawns completely different internally?

#

this should be an easy transfer, use the key and get root

thorn urchin
#

it shouldnt be, I have no idea what rabbit hole youve gone down

#

could be a firewall block too

sterile temple
elfin timber
#

im just gonna start everything from scratch

balmy radish
elfin timber
balmy radish
#

in your wget command, use that ip

elfin timber
#

Not the ip that you spawn in?

#

When you launch everything?

balmy radish
#

wait never mind I see you are trying to transfer off the victim machine, not to it. Forget what I said

elfin timber
#

Correct

thorn urchin
#

also its just an id_rsa key, Id just cat it and copy paste it

quasi wave
#

What percentage of CBBH path is covered under CPTS path?

tepid thicket
#

Can someone help me out with the Documentation and Reporting lab? Honestly have no clue how to move forward. I found lab_adm hash but haven't been able to crack it and not even sure if I'm on the right path. Thought this was supposed to be an easy module 😩 please help

solid quarry
#

Obtain credentials for a user who has GenericAll rights over the Domain Admins group. What this user's account name? tried with responder but I don't think this is the way

tepid thicket
arctic siren
#

Hi all! I am a mathematician who's always had an interest in computers and after doing cryptography in uni I decided cybersec is the pathway I want to go. Can you recommend the first training course I can do to get my feet wet in hacking and start to figure out which field best suits my talents and interests, thanks guys 😄

solemn fog
rustic sage
forest tapir
#

no clue meng

solemn fog
forest tapir
#

I'll have to check tomorrow but it's likely. Another process (convert.b64) similar returned '0'.

Not sure if 'exit 0' or '0 bytes'

#

I'm still pretty new to Powershell

#

Just saying that made me realize...

#

I must be mentally defective...

#

why would an error 'exit 0 '? Lol

#

nvm

solid quarry
tepid thicket
#

can you help me out with this please? I'm at the same spot and not even sure if it is the correct approach

vivid nova
#

Can anyone help with the hashcat module question? Crack the following hash: 978078e7845f2fb2e20399d9e80475bc1c275e06 using the mask ?d?s. I have been using the command line hashcat -a 7 -m 190 hybridhash -1 01 '?d?s' /usr/share/wordlists/rockyou.txt I have tested the hashcat modes 100,4500,6000,190 and I keep getting an exhausted error.

west canopy
#

My approach was not the correct approach 🙂

tidal mango
#

I might be able to help, whats up?

vital adder
vital adder
sly tapir
quasi wave
tidal mango
tidal mango
sly tapir
#

thanks man

tidal mango
iron plaza
#

Anyone completed the DNS Enumeration Using Python (module 27 section 439)?
It asks me to perform a zone transfer against the target but what I get for dig axfr inlanefreight.htb @10.129.184.188 is "Transfer failed." Any idea how to resolve this?

rich vale
#

so I want to run kerbrute against a network, but i dont want to have to constantly rebuild tools for the attack VM in the AD module. is there any reason why i couldnt create an ssh tunnel from my kali VM to the parrot attack box, and run the tool from my own VM?

rustic sage
#

Good morning from Spain! Ive been struggling with the live engagement (shells and payloads), I have the aspx web shell but cant navigate through the directories 😦 😦 any hint would be appreciated!!

placid quest
#

@rich vale try to use vpn

rich vale
#

semi-related question, but has anyone had issues with kerbrute not actually writing output to a file? creates the file, but file is empty

rich mulch
#

Hi guys,
I am stuck at "RDP and SOCKS Tunneling with SocksOverRDP" task. I cannot apply the technique in this task because the Jason's machine has different IP Network: 172.16.6.155
While the pivot point (htb-student) has 2 IP network: (10.129.42.198 & 172.16.5.155). I also find out there is another machine 172.16.5.19, and I supposed this machine can connect to Jason Machine

But I am get stuck how to get the credential of machine 172.16.5.19?

vital adder
loud sapphire
#

good luck getting it to connect to 5.19 tho. lol. i still havent found success.

rich mulch
rich mulch
loud sapphire
vital adder
rich mulch
waxen barn
loud sapphire
loud sapphire
rich mulch
#

thank you ^^

waxen barn
vital adder
loud sapphire
loud sapphire
gloomy tangle
#

Stuck also two days with it. Solved by using same method in the first question but changing user and using grep for powershell solves it

iron plaza
vital adder
#

just use the target ip for that

#

i didn't have to do that on the pwnbox but just for sure try that

iron plaza
solar granite
#

Hi guys, I need some help with Windows Privilege Escalation - DnsAdmins. I have used the technique to escalate, and I am part of the domain admins group:
Local Group Memberships *DnsAdmins *Remote Desktop Users Global Group memberships *Domain Admins *Domain Users
However, I still get an access denied error when trying to read the flag or access the Administrator directory, even from an administrator powershell console.

Edit: solved. Simply log out and log back in.

vital adder
#

in that section for me i end up making the dll payload run a different rev shell file and that give me authority system but if you want to do the intended way try restart the the target (with shutdown -l)
#modules message

low vine
#

Having a little trouble setting up proxy chains

#

I keep getting error [proxychains] config file found: /etc/proxychains.conf [proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4 error: invalid item in proxylist section: https 127.0.0.1 8080

#

My understanding is that it wants us using that, but just not quite understanding why its not funcitoning correctly

eternal moss
#

delete the line https

#

so:

http 127.0.0.1 8080
low vine
#

Yea works perfect

#

Ty

eternal moss
#

🙂

low vine
#

❤️

#

Guess the module needs to be edited or I just need to read better lol

#

To use proxychains, we first have to edit /etc/proxychains.conf, comment the final line and add the following two lines at the end of it:

eternal moss
#

can anyone that has completed Broken Authentication help me?

vital adder
eternal moss
#

i'm clueless in the skill assesment, but i dont want to spoil it, so can i dm you? @vital adder

vital adder
#

sure

eternal moss
#

thanks 🙂

rustic sage
#

Guys I am new here and I am having trouble connecting to the VPN can anyone help?

lament hollow
#

Anyone around that's finished the AD Enumeration & Attack module? I've been stuck on final assessment I Q4 for about 10 hours now and while the failing has been useful I'm spinning my wheels a bit here and think I could use a hint.

spring sigil
#

How do you actually use searchsploit properly? I just got to it in the "Getting Started" Module and I'm supposed to look for "Simple Backup Plugin 2.7.10 for WordPress". Of course, you can find it on google, but the same search doesn't output any results on searchsploit. The help command wasn't very useful either

loud sapphire
#

i have a result.

#

google ultimately is your best friend tho. exploit-db will likely come up with some code.

lament hollow
spring sigil
loud sapphire
#

copy uRL of the question youre on.

spring sigil
spring sigil
lament hollow
#

try running searchsploit -u to update the local db?

spring sigil
#

As I said, I have arledy solved the question, but not through using searchsploit, because it didn't output the result I needed no matter the input

#

And I kind of wanted to understand if it was a me issue or a serachsploit issue

loud sapphire
spring sigil
#

I see, thank you both then! 😄

rustic sage
#

someone could help me in USING WEB PROXIES module- Skill Assesment?¿

loud sapphire
#

meh, dm me if needed. im gonna continue with other stuff til then.

simple zephyr
#

Foot Printing Easy - can some one DM me how you would have found the creds without the hint and it says not to brute force so stuff like medusa and nscrack would be off the table

mellow turtle
#

AD Enumeration & Attacks - Skills Assessment Part II
Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host.

Can someone help me?

rustic sage
#

Just for my sanity...nobody knows all of the terminology in AD off the bat right? Like I'm not the only person who'll still be searching this in the future??^^;

mellow turtle
rustic sage
#

I'm on it now, but it's a LOT to take on

mellow turtle
#

yeah

#

it is

rustic sage
#

Taking notes but I'm forgetting a lot as I go on

mellow turtle
#

x

#

D

unique valve
rustic sage
#

yeah, I have to rego over it anyway

#

Saving up for the next module gives me time to study

lucid bloom
#

intro to ad section structure last question - what´s the awnser?

rustic sage
#

I have a question about the root indicator I don't understand that part in the first machine.

#

I undestand jejjee

simple zephyr
#

ok for Footprinting Easy i figured out where to get the password from without the hint. it just takes a while the way I did it. I would still love for people to DM me how they found it without the hint so I can add that to my notes.

loud sapphire
lucid mirage
#

anyone could give a nudge for deserialization skill assessment 2? thanks.

lucid bloom
#

can´t connect to intro to ad - ad administration 1

crisp remnant
#

Anyone for footprinting module ?

loud sapphire
#

footprinting is an awful module.

acoustic owl
rustic sage
#

Having this issue too, is there a specific format??

frigid mica
#

can someone help me, i am very new to all of this...... it keeps saying: Firefox is configured to use a proxy server that is refusing connections. so now i cant use firefox and i tried everything already.

rustic sage
#

Try using another browser-

frigid mica
#

i did

#

i tried 4 already

#

same issue

rustic sage
#

Chrome/Brave?

frigid mica
#

yes

rustic sage
#

And which VM are you running?

#

The built in one or your own?

frigid mica
#

no i use the one on the site that runs it for you

rustic sage
#

And when you press start instance it just comes up with an error?

frigid mica
#

( my workstation )

#

yes nothing works

#

been trying things sinds yesterday

rustic sage
#

Find a moderator and send them a recording/screenshot id suggest

loud sapphire
#

suggestion: Dont use your main browser for proxying. Just use the built in browser on burp. easier.

frigid mica
#

how do i do that?

frigid mica
#

i am very very new to all this

rustic sage
#

Are you using a windows computer?

frigid mica
#

no macbook

loud sapphire
#

in your browser (firefox i assume) what are you using to proxy?

#

foxy?

frigid mica
#

i am learning linux from this guy on youtube ( networkchuck ) and he shows that i need to install al kind of stuff so i need to use firefox the browser bud i cant because its keeps saying tge same thing

#

already did...

loud sapphire
#

does your proxy setting look like this?

loud sapphire
rustic sage
#

Macbook screenshot:
Shift + command + 3

(just for future reference 😄 )

mellow turtle
#

there are problems with the academy labs?

loud sapphire
mellow turtle
frigid mica
#

alright i will try thankyou!

mellow turtle
#

AD Enumeration & Attacks - Skills Assessment Part II

loud sapphire
mellow turtle
#

i tried resseting the pwnbox, the targets etc

#

okey but thats just an attack host

rustic sage
#

I usually just fully restart the browser or target when that happens

loud sapphire
mellow turtle
#

more than 5 :/

loud sapphire
#

browser reset also valid.

#

do what peacekeeper suggested.

#

check that you havent left a connection open to a previous box too.

mellow turtle
#

i do that ._.

rustic sage
#

One sec

#

Is that target still up?

mellow turtle
#

yes

#

still up no

#

for me is more like down

#

xD

rustic sage
#

o-o

Hmmmm

loud sapphire
rustic sage
#

I was about to say

#

Yeah aha

mellow turtle
#

._.

#

im not getting any

loud sapphire
frigid mica
loud sapphire
mellow turtle
#

im using pwnbox

#

so yes

rustic sage
loud sapphire
loud sapphire
# mellow turtle im using pwnbox

interesting...... try connecting your physical box to the vpn and send ping. or terminate the pwnbox session and make a new one?

simple zephyr
#

Did any one complete the footprinting Easy lab without the hint? I would like to compare notes to see if we did it the same way

mellow turtle
mellow turtle
#

ill try from my kali laptop

rustic sage
#

Kali my beloved

frigid mica
rustic sage
#

So it should be saved to your desktop, rename it if you'd like.

Press the plus next to your message input, browse to the image and send it here ^^

frigid mica
#

i dont have the option send image

rustic sage
#

In here?

frigid mica
#

yeah

#

i dont know why

tepid thicket
vital adder
rustic sage
#

^^^^^

vital adder
vital adder
rustic sage
#

I got it thanks! I kept putting group at the end ^^;;;

#

Always with the syntax ehehe

vital adder
#

hi @frigid mica mind explaining your issue again?

lucid mirage
simple zephyr
#

I’m curious though how it would be in the exam

vital adder
#

oh wait i did only check if the cred was there i didn't check the cred location so it's that fast

#

also htb always use the ||names.txt|| so a good guess for the username wordlist should be that and of course rock you

simple zephyr
#

Also I’m new to discord how do I black out text

vital adder
simple zephyr
#

Ok sweet ||Test||

simple zephyr
#

p3ta@kali ~/H/A/footprinting> ||hydra -l ceil -P /usr/share/wordlists/seclists/Passwords/darkweb2017-top10.txt 10.129.74.82 -s 2121 ftp -vv||
Hydra v9.4 (c) 2022 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2022-12-01 07:07:58
[DATA] max 11 tasks per 1 server, overall 11 tasks, 11 login tries (l:1/p:11), ~1 try per task
[DATA] attacking ftp://10.129.74.82:2121/
[VERBOSE] Resolving addresses ... [VERBOSE] resolving done
[2121][ftp] host: 10.129.74.82 login: ||ceil password: qwer1234||
[STATUS] attack finished for 10.129.74.82 (waiting for children to complete tests)
1 of 1 target successfully completed, 1 valid password found
Hydra (https://github.com/vanhauser-thc/thc-hydra) finished at 2022-12-01 07:08:11

GitHub

hydra. Contribute to vanhauser-thc/thc-hydra development by creating an account on GitHub.

#

This was how I did it after I found the cred with ||NMAP||

simple zephyr
#

The word list didn’t have it in though I added it to it after I found it in rock you, I forgot to copy my notes and didn’t want to run it again

slim plover
mellow turtle
#

yeah

#

and for mssqlsvc

#

but im not sure if i got the right one

#

can i dm u?=

slim plover
#

sure

lament hollow
#

I'm stuck on the pivot to MS01 in the first skills assessment either of you gents willing to DM me a hint?

vital adder
vital adder
lament hollow
#

AD enum and Attack

vital adder
#

oh i haven't done that so can't help Sad_Squidward_Pepe

lament hollow
#

NP, there was two gents just above talking about the second final assessment so hoping to hop in

solid quarry
#

Enumerate the target and find a vHost that contains flag No. 1. Submit the flag value as your answer (in the format HTB{DATA}). , is the namelist.txt on seclist the right wordlist? No matter how I change de ffuf command I get no results

pastel ginkgo
#

How can you get mimikatz output from a rev shell?

#

I got the ticket I want to extract in memory but I can't get my rev shell to run mimikatz or any powerview module

vital adder
solid quarry
#

Information Gathering - Web Edition - Virtual Hosts

thorn urchin
vital adder
#

you can use log for that

pastel ginkgo
#

ooo thats a good idea how do you do that?

solid quarry
vital adder
#

ffuf should work the same

vital adder
solid quarry
#

I will send to you and try here again, If I got something I send you another message

pastel ginkgo
#

mimikatz.exe privilege::debug; log output.txt; sekurlsa::tickets ?

#

as thats not working for me

rustic sage
vital adder
pastel ginkgo
#

So I got mimikatz to finally work via shell on meterpreter but I guess it droped the ticket from memory as its unable to find it now

#

I got it

#

this has been fustrating as hell but I got it lol

rustic sage
#

I`m with the live engagement and seems the laundanum aspx webshell only allows me to see the actual directory... I have tried cd \ // and multiple things but no luck yet... any hints!

thorn urchin
#

iirc laudanum doesnt support changing directories, just gotta specify full paths

mellow turtle
#

@thorn urchin laudanum uploads a bat file to execute the commands and then delete it true?

thorn urchin
#

idr

mellow turtle
#

it was something like that, thats why u cant change directories

rustic sage
thorn urchin
#

its overall not super uncommon for shells, webshells in particular, to not support directory changing

rustic sage
#

im on lfi skill assessment i found the admin log and the access.log but i cant seem to get rce through &cmd=id i wanna try to change the payload to not needing the &cmd=COMMAND and just executing whatever i put into the php script but idk how to write it out

thorn urchin
rustic sage
#

i dont have burp suite

thorn urchin
#

also just in case, the access.log isnt a real log file, gotta find the real one.

#

yes you do, community edition is free

rustic sage
#

i dont reallly wanna spend time learning burp suite right now i just wanna get the thing done and move on to another module

thorn urchin
#

well good luck then because I tried exhaustively to bypass the intended route of the module and wasnt able to, so log injection was needed and the curl method kept failing outright.

rustic sage
#

oh well

thorn urchin
#

only thing I didnt try was one of the automated tools, so you can try that or you can start learning the basics of burp

#

I imagine zap would work too if youre more familiar with that

frigid monolith
#

Having an issue with AD enumeration and attacks - skills assessment part 1

rustic sage
#

so should the php code <?php system("id"); ?> instead of <?php system($_GET["cmd"]); ?>

thorn urchin
#

either

frigid monolith
#

The web server was working and now it isn't

rustic sage
#

ok i guess ill just learn burp

pastel ginkgo
#

10/10 hacker over here, crack the users passwords but forget to write down their username.

thorn urchin
#

woopsies

frigid monolith
#

I've restarted it several times

mellow turtle
#

@thorn urchin have u completed ACTIVE DIRECTORY ENUMERATION & ATTACKS?

thorn urchin
#

yeah

frigid monolith
#

I'm so close too

thorn urchin
#

took like 8 hours on the part 2 assessment lol

mellow turtle
#

help me with the 2 assessment

thorn urchin
#

what are you stuck on

mellow turtle
#

im trying to figure out what user have generic all priv on domain admins

frigid monolith
#

Could you try to start 1 and see if the web server comes up for you?

thorn urchin
#

you run bloodhound

frigid monolith
#

Blood hound

mellow turtle
#

i dont like bloodhound :S

frigid monolith
#

-c all

thorn urchin
#

Bloodhound is one of the most powerful tools in AD hacking so unfortunately gotta live with it

mellow turtle
#

||Get-ObjectAcl -ResolveGUIDs | ? {$.objectdn -eq "CN=Domain Admins,CN=Users,DC=INLANEFREIGHT,DC=LOCAL"-and ($.ActiveDirectoryRights -Like 'GenericAll')}||

#

i was trying that :S

thorn urchin
#

you could do it manually but takes longer and harder to parse imo

mellow turtle
#

but yes u are right

frigid monolith
#

Next you'll say you don't like burp

#

Lol

mellow turtle
#

i love burp

thorn urchin
#

the three way venn diagram of burp users, web app pentesers, and zap users, are just two circles barely tapping each other.

mellow turtle
#

but bloodhound looks ugly to me

#

i prefer command line

thorn urchin
#

I think you can use bloodhound cmd line if youre really good at cypher queries 😛

mellow turtle
#

no im not xAD

pastel ginkgo
#

lol im on day 2 of the 1st skills assessment in the AD module

thorn urchin
#

graph based attack tools are cool though imo, one of the few things I dont mind having GUIs for, and I imagine theres more untapped potential for graph based tooling.

pastel ginkgo
#

yesterday was killing my moral

frigid monolith
#

Could someone check ad assessment 1?

thorn urchin
pastel ginkgo
#

The provided one got hung up alot for me

frigid monolith
#

Oh yeah I'm on that too

#

Semi colon breaks it

pastel ginkgo
#

but being cursed is a true statement with me and computers

#

they actively break around me

mellow turtle
#

@tranquil carbon ill check ty

pastel ginkgo
#

its why im good at IT because I am constantly fixing my own computer

vital adder
thorn urchin
#

Not at all

frigid monolith
#

Lol

thorn urchin
#

well a little bit about cypher queries, but not running cmdline

pastel ginkgo
#

Do I want to know what a cypher query is or is it come kind of Eldrich truth?

frigid monolith
#

Someone should make a tui for bloodhound

thorn urchin
#

idk if it officially has support for it, but its all neo4j db, so if youre good with cypher queries you could just connect to the db and run the queries manually.

vital adder
#

bloodhound is good but it's so goddamn messy multiple step just for some enum

vital adder
pastel ginkgo
#

the more I lean in this field the more I feel like im going to run into some dark eldrich god

thorn urchin
vital adder
#

ohhh

pastel ginkgo
#

My co workers actively think im crazy for working on this cert lol

thorn urchin
#

or at least I assume thats what they mea

thorn urchin
#

But also ironically his content has been a useful companion in following the cert path.

pastel ginkgo
#

rip my rev shell died while looking up how to setup a netsh piviot lol

thorn urchin
#

embrace chisel

pastel ginkgo
#

I couldnt get it to play nice from my box to theirs

thorn urchin
#

I have a seperate cloned section of my chisel notes in my obsidian root so its easier to swap to for setup, and added a few additional notes about cross compiling

pastel ginkgo
#

if I used their compiled version it would work

#

theirs being from pwnbox

#

if I compiled it on my kali machine it wouldnt run

frigid monolith
#

Who do I talk to about a broken module

pastel ginkgo
#

does chisel even work on windows machines?

thorn urchin
#

yes

#

I used it extensively for this module

#

clone the repo then ```
GOOS=windows GOARCH=amd64 go build -ldflags="-s -w"

all one line
#

itll generate a stripped slightly compact windows executable version of chisel

frigid monolith
#

Can go build to Android?

thorn urchin
#

I doubt it but maybe

#

@frigid monolith also yeah just checked myself, was working yesterday but seems its broken today

frigid monolith
#

Thanks

#

That sucks it literally broke while I was in the middle today

thorn urchin
#

support chat bubble gone too, I think theyre overall having some issues today

frigid monolith
#

And yes, goarch=arm goos=Linux

pastel ginkgo
#

@thorn urchin I need your notes on chisel lol

thorn urchin
pastel ginkgo
#

ill give it another once over once I get passed this module

#

in the mean time Im trying to figure out how to get from my attack host to the msql host

#

i am brain farting on how to jump to it atm

thorn urchin
#

did you kerberoast the one account yet?

pastel ginkgo
#

yeah I got the sql admin password

thorn urchin
#

then next id run the mill of the usuals, smbexec, psexec, wmiexec, winrm, ect.

pastel ginkgo
#

yeah I need to get chisel working then because netsh is just 1 port vrs all of them

#

so for the windows build you just do go build GOOS=windows GOARCH=amd64 go build -ldflags="-s -w ?

thorn urchin
#

minus the first go build there yeah

#

the temp env vars basically say "I want a windows x64 binary" and then the ldflags is "shave off a few extra MB of file size"

frigid monolith
thorn urchin
#

yall are

pastel ginkgo
#

yeah hasnt crashed yet

frigid monolith
#

Better hurry lol

pastel ginkgo
#

lol i'll be lucky if I can get the sql workstation flag in time

#

I am not fast at this at all

frigid monolith
#

I'm not either

#

Got the user and PW though

#

I assume impacket is next

thorn urchin
#

probably

#

I forgot to take notes on the first section

#

much better notes for the significantly lengthier part 2 except I derped and forgot to add any of the host names to the notes, so its more of a catalog of random attacks and creds.

#

Half my goal with this course is improving my note taking skills lol

pastel ginkgo
#

I have decent non pc invloved not taking skills

#

but so much of this is cmd line I dont write it out

frigid monolith
#

I wonder if you could just use the initial shell for that

rustic sage
#

i know how to use burp suite now but now but the burp browser doesnt load the website

#

and also it works when I send a text but it filters out php

frigid monolith
#

There's a query box

pastel ginkgo
#

I wouldnt use the inital shell, I used a msvenom and rev shell for most of it

rustic sage
#

in lfi skill assessment

pastel ginkgo
#

idk fox did it

frigid monolith
#

Duck maybe %00

thorn urchin
#

Just native commands for the initial kerberoast, then chisel and proxy the rest if my attacks.

frigid monolith
#

I used power view

pastel ginkgo
#

you got powerview to work?

frigid monolith
#

Yeah

thorn urchin
pastel ginkgo
#

I couldnt get it to display anytthing

frigid monolith
#

Gotta import and do it all in one shot

pastel ginkgo
#

oh god

#

thats why then

frigid monolith
#

Since it spawns cmds in their own processes

rustic sage
thorn urchin
#

the basic cmd variant you already posted

pastel ginkgo
#

I ended up using a werid mix of a rev shell and msvenom

rustic sage
#

i tried it 1000000 times

#

and it wont work

pastel ginkgo
#

|| my metasploit shell let me run mimikatz in cmd and my rev shell let me load the ticket into memory in powershell ||

thorn urchin
#

now one hiccup I did have was that by the time I got to that section my earlier attempts had flooded the access log so the response with the php was getting truncated, I had to reset the box.

frigid monolith
#

Yeah I just did powerview and cracked the ticket

rustic sage
#

im gonna try to reset the box and try my php payload again

pastel ginkgo
#

that sound so much easier

frigid monolith
#

%00 didn't get it

thorn urchin
frigid monolith
#

Oo

#

Haven't gotten there

rustic sage
#

when i turn on intercept in burp the burp browser wont load website but when i turn it off it loads

#

is it supposed to be like that (i think it is)

thorn urchin
#

yes

#

intercept is for modifying the requests in transit

#

usually I say no, and the send the request I want to play with to repeater and modify it there