#modules

1 messages Β· Page 32 of 1

little whaleBOT
#

Sexual Squid Game Fan Club Owner (926879219655524352) has been banned until 2022-12-21 03:29:16 (UTC).

graceful rampart
#

Rippp

tiny ember
#

Cause you left your caps lock on? 🀣

fathom pendant
#

Ok so this one stumped me because the module teaches you a specific tool which may not be installed on a VM, but is on the pwnbox

tiny ember
fathom pendant
#

I got the flag :D

#

Just figured I'd see if you still needed help with it since I just did it

tiny ember
#

I DMed you

graceful mortar
#

Helllllllloooooo

runic walrus
#

Hello, I the question What is the name of the security regulation for credit card payments a company must adhere to? (Answer Format: acronym) is giving me an error saying it is wrong but i am fairly certain it is right. Can someone help me?

#

Penetration Testing Process: Post Exploitation

fathom pendant
hardy glen
#

Hello, I'm stuck answering the following question in the footprinting

#

What is the FQDN of the host where the last octet ends with "x.x.x.203"?

#

I have tried all the possibilities using the wordlist. But I couldn't get the answer

#

I did > Subdomain Brute Forcing

fathom pendant
#

one sec while I pull it up

hardy glen
#

using dnsenum with SecLists. word list

runic walrus
fathom pendant
#

it's in the Post-Exploitation Page

#

but it's within that page area that you'll find it :)

runic walrus
fathom pendant
#

No Problem! also as just a note: sometimes the labs can be touchy/buggy so if you're having an issue with a box or trying to nab info when you get to it - sometimes refreshing the host is the key :)

fathom pendant
fathom pendant
# runic walrus Oh, i just got it. I tried that before, but i didn't have the hyphon. Thanks for...

It warns you as such; but they do provide you the resources (If your pc can run it) to the parrot VM they use (though it's not required) but good luck in moving forward! if you ever need help you can always field a question in here; to get best results try and phrase things in ways like
"I am stuck at this module, and have tried this - but no luck" the veterans usually will swoop in and push you in the right direction. The reason they won't tell you the direct command to run is that it doesn't help you learn to use resources :)

last cape
#

hey can somebody help me with a question on the wordpress module

#

its this section

#

i got everything except for "Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download"

#

and i am not sure what to do for that one

#

help would be appreciated πŸ˜„

fathom pendant
last cape
#

i found this directory on exploit-db

#

/wp-content/plugins/site-editor/editor/extensions/pagebuilder/includes/ajax_shortcode_pattern.php?ajax_path=/etc/passwd

fathom pendant
#

what happens when that is run?

last cape
#

i get this

#

i sent a ss in dms

normal wind
#

Appreciate it

#

@raven cairn

fierce pond
#

Which version of the FTP server is running on the target system? Submit the entire banner as the answer.
what do thy mean by entering the entire banner ?

i mean i have the version off the scan and its 1.1 so what kind of stuff are they asking for

Please someone help , i even added the option to trace the packet to see if there's something hidden , but nothing showed up , one script showed some nonsense , but i think the answer needs only the version , and it seems i cant type it right πŸ˜„

#

btw module footprinting

proper pagoda
#

When you are trying to connect to the FTP server, it usually sends you a banner.
If this isn’t the case with your scanner application, then you can always try to connect to it with any other tools, and just grab the whole banner it sends you

ripe terrace
#

Has anyone done the hard lab in the footprinting module and is willing to point me in the right direction? I feel as if I have enumerated all possibilities (which clearly isn't the case, otherwise, I wouldn't be stuck), and I'm not sure what else I can/should try.

fierce pond
#

i tried nmap , ftp , netcat , openssl

other than FTP v1.1 nothing really came up

#

so can u please be more specific about what other tools you are talking about ? should i try the telnet ?

ripe terrace
#

@fierce pond , you have the answer in the first screenshot.

fierce pond
#

ah damn

#

i was entering that with the 220 ! that was dumb , sorry to waste your time guys

ripe terrace
#

Yeah, the 220 at the front is just a status code, not part of the banner πŸ™‚

fierce pond
#

anyway , yeah i should have tried to just delete the status code , you are right !

ripe terrace
#

@fierce pond if you have any luck with the next lab (Hard), let me know... I'm stuck there at the moment.

fierce pond
stiff tapir
#

I am trying to connect to openvpn using mac terminal but I am unable to connect. can someone help me?

#

i installed openvpn using homebrew

deep tendon
#

What group type is best utilized for assigning permissions and right to users? I know what group it is but it tells me that it is not

rustic sage
#

Please someone help me with predictable reset token module?

jade gulch
#

my target is spawned and now i dont want it

#

how to disconnect from it

hallow oxide
#

Need help with Password Attacks/Credential Hunting in Linux module. Can i DM someone?

still violet
#

I am stuck on Broken Authentication in Weak Bruteforce Protections section. Question 2. I used|| X-Forwareded-For: TargetIp:Port with deafault-credentials.csv || I've used other lists as well but still can't figure out the correct credentials. Any hints ??

hallow oxide
jade gulch
#

it resets with a different ip

#

but the timer ticks

#

in thm there is a button to terminate

#

but i cant find any here

deep tendon
#

What group type is best utilized for assigning permissions and right to users? I know what group it is but it tells me that it is not

hallow oxide
# jade gulch but the timer ticks

sometimes timer doesnt reset. I fix this my reloading page or just opening a new tab and closing existing one. Looks like there is now way to terminate the target before timer runs out. tho maybe "finishing" the page after u type in all the answers does the trick

deep tendon
#

active directory

#

section active directory groups

hallow oxide
deep tendon
hallow oxide
#

even which GROUP TYPE

#

correct your answer accordingly. You are right, but should answer the question they ask.

deep tendon
#

group type and group scopes is the same?

hallow oxide
#

"What group type" should probably have a one-worded answer

hallow oxide
deep tendon
hallow oxide
#

Your welcome. Just read the questions with care. Mistake in quantity is a mistake.

#

Need help with Password Attacks/Credential Hunting in Linux module. Can i DM someone?

fierce pond
sinful falcon
#

Hello world, I need help, I have a problem with the "Pivoting, Tunneling, and Port Forwarding" module. When I use my kali, the port forwarding reverses do not work and I tried with the workstation, it works perfectly.

#

I have no response on msf

fierce pond
#

as long as you can connect to the ubuntu client and to the windows desktop , then there's no problem , check your the ports and the Ip you providing !

still violet
sinful falcon
#

On the workstations of HTB, it works. And not on my kali. I'm going through exactly the same steps.

fierce pond
#

oh Yeah i remember that well , can you connect to the VPN correctly ?

fierce pond
#

send a screen shot of your configuration

sinful falcon
#

I have never had a problem yet, I am following the CPTS path. I have problems only with this module.

sinful falcon
fierce pond
#

you need to specify the ip of your tun0

sinful falcon
fierce pond
#

so the first thing you need to do , is that you need to be sure that the ubuntu will connect to the tun0

sinful falcon
#

I tried 0.0.0.0 and tun0 ip and differents ports

#

just 1 min

#

I will try

orchid ingot
#

Can someone help me on Skills Assessment of PIVOTING, TUNNELING, AND PORT FORWARDING module? stuck on the last question. I found another host from the last machine which is 172.16.10.5 (I think this is a DC) but cannot move further.

fierce pond
sinful falcon
candid zephyr
#

there's so much going on for ad assessment 2 :-s

final salmon
#

Trying to do the BloodHound assessment, but the BloodHound user//pass is not working. Has anybody experienced this?

fierce pond
vital adder
orchid ingot
#

Howw

vital adder
#

hint click this pc in the file explorer

sinful falcon
orchid ingot
sinful falcon
#

for windows machine ? yes

fierce pond
#

lhost= ubuntu ?

sinful falcon
#

yes 172.16.5.129

#

Does it work on your own kali?

fierce pond
vital adder
#

@sinful falcon i remember helping some guy on this module with a weird issue and the issue end up to be the meterpreter shell is too big to be route through multiple machine but which section are you on?

fierce pond
#

i dont think you are facing that kind since you can connect to the ubuntu and windows freely

sinful falcon
sinful falcon
vital adder
#

i got no note but i'm pretty sure it's this one

#

try with a normal instead of the meterpreter shell

sinful falcon
#

I have not to use this one ; windows/x64/meterpreter/reverse_https ?

vital adder
#

found an old screenshot on this

vital adder
sinful falcon
#

Ok i wil try, thanks

vital adder
#

use windows/x64/shell/reverse_tcp (that work for my babased on the screenshot)

#

or netcat 🀣

sinful falcon
#

I'll keep you informed

hallow oxide
#

Need help with Password Attacks/Credential Hunting in Linux module. Can i DM someone?

vital adder
vital adder
vital adder
#

try with netcat just for a sanity check

sinful falcon
vital adder
#

yep so the issue still is the shell is way too big some how

#

even with the normal shell

fierce pond
sinful falcon
sinful falcon
#

Thank you for your help

candid zephyr
#

after finishing this ad module I am definitely going to figurre out a better, more orderly workflow hahaha

#

so many things open 😭

still violet
candid zephyr
#

Has anyone done AD Module Assessment 2 available for a quick Q?

#

Before I waste a bunch of time...

#

Nvm it was that stupid mimikatz thing.

hallow oxide
#

Still stuck on Password Attacks/Credential Hunting in Linux module. Can i DM anyone?

fierce pond
#

@sinful falcon

#

from my machine

#

you need to set the ip to your ip machine

placid quest
#

@hallow oxide dm

sinful falcon
placid quest
#

@vital adder hei man can i dm u because i am stuck on pivoting module skills assessment

fierce pond
sinful falcon
fierce pond
# sinful falcon I have no response on msf

idk , never looked , but it has nothing to do with the VPN , you are getting connected to the VPN and the connection is actually established as u can see from your screen shot here , it just that the msf doesnt get the connection for somereson , i thought it because of the connection through the VPN that's why i specified the redirection in the SSH -R to the ip of the tun , after i done that restarted the process of the msf , and it worked !

sinful falcon
#

Ok, too bad it doesn't work for me.

fierce pond
sinful falcon
placid quest
#

@fierce pond replacing 0.0.0.0 may not work

sinful falcon
#

I will test too with new kali instance

fierce pond
#

he's getting connected to it , it just the matter of the msf , and idont know if msf has it own routing tables , but it worked for me while having the same problem , are you facing the same problem as well ?

placid quest
#

@fierce pond no i have completed that selection but on skills assessment i have tried to use the msf but i am still stuck since the payload is not showing any errors but i am not getting the shell

fierce pond
#

are you on the last step of that ?

placid quest
#

@fierce pond yes

fierce pond
placid quest
#

@fierce pond i have done everything but i am not understanding where i am making the mistake

fierce pond
autumn badge
#

nnniiggeerrrss nniggeerrrsss

fierce pond
pastel verge
#

Ih

#

Sorry hi

sinful falcon
#

@fierce pond @vital adder I just tried with another kali VM and it's working !

fierce pond
#

your nat was the problem ? damn i hate when that happen !!

sinful falcon
#

I have a new problem with the following section... Meterpreter Tunneling & Port Forwarding. Same problem, no return, even with netcat ...

#

from "Meterpreter Reverse Port Forwarding" it does not work

#

Port forwarding is present though

placid quest
#

@sinful falcon i don't think u need to use nc

fierce pond
#

your port is open on 3389

sinful falcon
sinful falcon
placid quest
#

@sinful falcon if it is a test u are doing it the wrong way

sinful falcon
#

meterpreter don't work too

placid quest
#

@sinful falcon u need to transfer the payload to the windows machine

placid quest
#

@sinful falcon can u dm

sinful falcon
fierce pond
#

he's trying to just ping or use netcat instead which should work .

sinful falcon
#

this module will make me lose my mind

fierce pond
placid quest
#

@sinful falcon it will not work since ur local machine cannot ping the windows machine due to dmz

fierce pond
#

i will go back to that module because of you mate thanks for the motivation

sinful falcon
#

I'll move on to another module I think. I hope the problems will be solved in the meantime.

fierce pond
sinful falcon
#

I follow exactly the steps of the module. If it doesn't work, there is a problem with the explanations given.

placid quest
#

@fierce pond yes but u cannot start the nc on ur local machine u need to start the nc on Ubuntu

fierce pond
candid zephyr
#

AD Attacks and Enumeration Module is great for anyone interested. Windows Priv Esc will help. Pivoting knowledge needs to be up to scratch.

fierce pond
sinful falcon
#

I will see the following sections. Hopefully it works.

fierce pond
placid quest
#

@fierce pond That would be great πŸ‘

pastel ginkgo
candid zephyr
sinful falcon
#

I hope there is no fowarding port on the CPTS exam otherwise I'm in trouble

pastel ginkgo
#

its not that hard

fierce pond
candid zephyr
#

I think the hardest thing to do with pivoting imo is just keeping track of all your shit.

pastel ginkgo
#

Just use chisel for pivioting

#

its gold

fierce pond
candid zephyr
#

Idk how people do this stuff with tmux/terminator or whatever.

pastel ginkgo
pastel ginkgo
#

got to take advantage of that 95 dollars off lol

fierce pond
pastel ginkgo
#

even if I dont get to it for a month im still saving 60 dollars

fierce pond
#

you will be saving the money either way so this is a good offer , specially i have time to do it because of the vacation

pastel ginkgo
#

right

#

people were like what are you doing for the holiday and got crazy looks when I said im trying to finish this hacking course πŸ˜†

sinful falcon
fierce pond
#

same bro same !

fierce pond
pastel ginkgo
#

im sure theres quite a few people in this discord with the same idea

fierce pond
#

but we need to finish the pivoting and the ad section , i guess we can achieve that till 31

pastel ginkgo
#

I loved that module

#

its kinda buggy though

fierce pond
#

cracking Dante in 10 days sunglas

pastel ginkgo
#

lol thats wishful thinking

sinful falcon
pastel ginkgo
#

im expecting to get wrecked lol

fierce pond
#

@sinful falcon @placid quest imma be on VC lets finish this pivoting section

placid quest
#

@fierce pond i have been stuck on skills assessment if u start that selection tell me i will be waiting βœ‹οΈ for u

placid quest
#

@pastel ginkgo on getting a reverse shell with msf

fierce pond
pastel ginkgo
#

I dont think I as able to get that working, the vpn tunnel bandwith isn't large enough to get meterpeter working

#

I kinda got it working from pwnbox

placid quest
#

@pastel ginkgo thanks let me try that

pastel ginkgo
#

You can also make a windows build of chisel

pastel ginkgo
#

For Web Attacks Mass Idor Enum, how did yall write the regix expression? As I couldn't figure out how to write it properly so I ended up || writing a script that did the curl request then I grep it to just the documents then just looked for the flag in my wall of text ||

dusty citrus
#

are you using dehashed?

weak marsh
#

My phone locked how can I unnlock it without losing my data? It's Oppo a83 and I haven't used the phone today. I can't use whatsapp...payment apps etc...

#

Pllz mention me when u reply so tht i can a notification

dry parrot
#

Hi all, what type of decoder did you use to solve Brute Forcing Cookies

rustic sage
#

same

#

i use cyberchef

#

i'm stuck on the secoond answer

dry parrot
#

im using cyberchef

#

but probably i dont know how to use it correctly

fathom pendant
weak marsh
#

lol

#

ik but still...

dim hound
#

I am doing Password Attacks -> Remote Passwords Attacks -> Network Services. I am not able to get the Winrm and SMB password... I am using the user and password list that are present at the resources tab of this module

#

Would someone be willing to provide me a nudge ?

placid quest
#

@dim hound yes

dim hound
#

Can I dm you? @placid quest

placid quest
#

@dim hound yes

heavy dome
#

I need help!!! I am running Network Enumeration with Nmap Hard Lab and ||found the hidden port 50000.|| I have made several attempts but it is always filtered. Can anyone help me?

pastel ginkgo
#

Its been a couple months since I last did that module, but are you changing where your ip is coming from?

fierce pond
pastel ginkgo
#

This web attacks module be like, hope you know how to script in bash xD

pastel ginkgo
#

kinda, just a little you have to modify their scripts. although this one I just got to said write a script to change all users emails as an optional.

#

But that being said the bash module is a kinda ok intro into scripting

#

or you could chatgpt it out big_think

fierce pond
#

chatgpt something is gonna be a new verb soon lol

pastel ginkgo
#

i already used it to help me solve one modules assessment lol

#

i am not super familiar with php so I asked it to explain the code lol

fierce pond
#

though some people say it delivers false information , which i didnt encounter still

pastel ginkgo
#

yup I had it write me a couple non related scripts to fix stuff already

#

I think it might be down atm though

#

im getting a 404 error

pastel gale
#

anyone do the live engagement from shells and payloadds recently

fierce pond
#

i had it once to explain me how routing tables function , i went with my curiosity till the kernel XD

pastel ginkgo
pastel gale
#

i need help with the priv eesc of host 3

pastel ginkgo
#

check the cheat sheet

#

answer is there

pastel gale
#

BRUHHHH

#

never bothered to look there

#

thankss

heavy dome
pastel ginkgo
#

how many decoys are you using?

heavy dome
fierce pond
#

try a source port , with some rate modifications

pastel ginkgo
#

|| I think I used like 15 ||

#

but that should also be enough

pastel gale
#

i am not sure where i am effing up

vocal goblet
#

Hi there. For Module "Getting Started", section "Service Scanning" one needs to grab the version of whatever service is running on port 8080. However nmap doesn't seem to return that:

nmap -sV 10.129.248.35 -p8080
Starting Nmap 7.92 ( https://nmap.org ) at 2022-12-20 19:15 GMT
Nmap scan report for 10.129.248.35
Host is up (0.011s latency).

PORT     STATE SERVICE VERSION
8080/tcp open  http    Apache Tomcat

The hint also does not tell much more than running nmap with option -sV on the target IP

pastel gale
#

use another tag

#

with -sV

#

@vocal goblet

vocal goblet
#

What do you mean with tag?

pastel gale
#

just like -sV

#

there are other tags

#

try using them

vocal goblet
#

OK ill keep looking, thanks πŸ™‚

pastel gale
heavy ferry
#

Hello

#

I need help

vocal goblet
fierce pond
heavy ferry
#

Is there a channel for discussing hacking

#

Or can i just ask for the help here

fierce pond
#

this is the academy channel

heavy ferry
#

Where can i ask for help hacking smth

pastel gale
fathom pendant
heavy ferry
#

I just need to talk to someone that has experience

graceful rampart
pastel ginkgo
#

Well this channel is for talking about Modules from HTB Academy so if its not about that please look in another channel

fathom pendant
#

If you do not receive a flag, you may need to redownload your VPN key as well @heavy dome -- after redownloading and refreshing my VPN connection I got it in a jiffy with the right command

heavy ferry
graceful rampart
fathom pendant
#

What type of device, or devices, you're being obtuse which is making it harder to provide an answer and to redirect

heavy ferry
#

What does a hacker need to steal folders from a device

graceful rampart
#

One does not simply "Steal files" from a device

heavy ferry
#

Like an average hacker

fierce pond
fathom pendant
#

IP, SSH key, Credentials, access

pastel gale
#

hashes

fathom pendant
heavy ferry
thorn urchin
graceful rampart
graceful rampart
#

i thought you wanted to do something illegal

graceful rampart
#

wrong server buddy

heavy ferry
#

Sorry

fathom pendant
pastel gale
#

go to reddit you will find your answers there

heavy ferry
#

Ty guys sorry for interrupting

graceful rampart
# heavy ferry Sorry

Not trying to be mean but if you want to steal files without someones permissin youre in the wrong place.

fierce pond
#

well its possible if that's what you are asking

pastel ginkgo
pastel gale
#

haha lool

graceful rampart
#

Yes it is

fathom pendant
graceful rampart
#

if youre concerned for a buisness then they likely need a pentest

heavy ferry
#

I mean like they don't know how much information they can put out

pastel gale
fathom pendant
#

There is a reason there are people that get paid for this

heavy ferry
#

Like an ip adress can be grabbed from a home line number

heavy ferry
fathom pendant
#

I mean that's just a bandaid solution

fathom pendant
pastel gale
#

AND PLEASEE do not store the passwords to the files in the notes of the same phone @heavy ferry

fathom pendant
#

You yourself cannot hire a pen tester on behalf of a company

graceful rampart
fathom pendant
#

As stated only the relevant leadership for their team can hire someone

heavy ferry
pastel gale
#

good

heavy ferry
#

Ty guys

pastel gale
#

we actually need an off topic channel for sruff like this hmmm

fathom pendant
#

Just because they're your relatives does not mean shit

heavy ferry
#

They asked me for it lmao

pastel gale
fathom pendant
#

Do you work directly for the department? As in, are you on the payroll?

heavy ferry
#

I'm known as the tech guy in the family but I'm not really experienced in that topic

graceful rampart
fathom pendant
#

That too

heavy ferry
#

I asked for help here because i don't really know what to do yk

fierce pond
#

πŸ˜‚

#

DEAD !!

graceful rampart
#

lol

fathom pendant
#

And if you're going to hire someone, you HAVE to use the proper channels within the organization to do so.

heavy ferry
#

And live in a shitty country we don't even have proper cyber security

pastel gale
#

Ahh yes i get that I thought you were pissed as he was working for his fam for free πŸ˜‚

heavy ferry
#

System

#

Like primal shit yk

#

So that's why I'm afraid too

fathom pendant
#

Yes but there are still basic legality and ethics if there aren't strict laws.

heavy ferry
#

I get it

#

Ty

graceful rampart
# heavy ferry System

At the end of the day, what youre looking for is a pentest. There is a lot of legal work that has to be done before any professional will perform said pentest. Now you know what youre looking for, so you can start looking into it

#

Or actually, if said company has never had a pentest done before youll probably want a vulnerability assesment instead

heavy ferry
#

Tysm 🀍

graceful rampart
#

np

fathom pendant
#

Vuln assessment is definitely a lot less risky as well

graceful rampart
#

Pentests are suually done after several vulnerability assments have been conducted and the results of those assesments have been acted upon

fathom pendant
#

Yep

placid quest
#

@graceful rampart vulnerability assessment and pentesting are different things

graceful rampart
#

yes i know

#

hence why i said usually you dont do a pentest until after youve already done several vulnerability assements

fathom pendant
#

The pen test is there to say 'hey there are still x y z flaws in the system'

graceful rampart
#

A pentest is pointless if its going to find 100 critical vulnerabilites that are gonna overwhelm the buisness. Cuz once they get overwhelmed, aint none of em getting fixed

#

so you do several vulnerability assements first to find and fix a mojority of them before hand. Then you do a pentest and see whats left

fathom pendant
#

Your mom is a professional sunglas

placid quest
#

@graceful rampart Using nessus and finding some vulnerability that does not mean that all vulnerability are real some are not vulnerability that is why u need to reconnaissance first

graceful rampart
#

again, I very much understand the difference between a pentest and a vulnerability assesment lmao

fierce pond
rustic sage
#

Hello

placid quest
#

@rustic sage hei

rustic sage
#

@placid quest Any tips ? In h@cking

fierce pond
placid quest
#

@fierce pond thanks for ur help

rustic sage
#

I'm new here

#

@fierce pond i created my htb account 2 years ago

#

Now I'm just logged in

#

And i want to learn

fierce pond
placid quest
#

@fierce pond yeap

#

@rustic sage start on getting started

rustic sage
#

@placid quest Windows

placid quest
#

@rustic sage what

fathom pendant
fading quail
#

Oh, lord.. I promise you I've had enough ||ftp brute forcring||
I won't do it again after this ||Password Attacks easy lab||
1 billion tries, userlists, passwords, mutated, reversed, blablaed...
lead me to this point where I beg you for guidance in my path
or the next bruteforcing will be my lobotomy, followed by the
||cme ftp -u cus_mut_use -p cus_mut pass||... with a Intel3-no graphic card.
I'm crying out my soul to you right now..

fierce pond
fathom pendant
# rustic sage I'm new here

If you're looking to do a specific specialty I would suggest going to http:://academy.hackthebox.com and starting there. Or if you wanna test it out there are a few getting started modules that give you a gentle guide into what to expect.

placid quest
#

@fading quail anonymous login is enabled on ftp

fathom pendant
placid quest
#

@fathom pendant I will try to improve on that thanks 😊

fading quail
#

I tried that already >.< But I'll hard-try then πŸ˜› Thanks!!

fierce pond
#

can someone help me or direct me to talk to someone about something related to VM and stuff like that ?

i notice that im facing a problem with the VM , and everytime its a different shit , sometimes its the NAT sometimes its the routing table , sometimes is VPN is there anyway you guys are getting along with this ?

are you all connecting to HTB behind a NAT ?

candid zephyr
#

don't set your vm network adapter to nat

#

bridged.

fierce pond
#

and do you advice to get it bridged while im connecting to the Academy ? im not monitoring my network all the time im on HTB that's why nat was better choice for me

candid zephyr
#

what do you mean?

#

im not monitoring my network all the time im on HTB that's why nat was better choice for me

#

this doesn't make sense?

fierce pond
# candid zephyr this doesn't make sense?

well i mean we are connecting to a platform to learn how to pentest , but some will take another road and try to hack us instead just for fun , we are all sharing VPN and maybe the instances as well in some cases

#

anyway i will change it to bridge as you advice if that will solve the Issue !

candid zephyr
#

It's highly unlikely. The kinds of people inclined to mess with your Kali VM don't have the ability to do so and the people with the ability have better things to do with their time.

#

unless your threat model is someone compromising your kali vm through the HTB VPN and escaping the VM into your host OS to install a bitcoin miner.

fierce pond
candid zephyr
#

You'll be safe inside your VM :>

fierce pond
#

there is a pro lab channel you can go there and im sure they will help you

candid zephyr
low forge
#

Okay, for some reason i am not able to view the channel #prolabs-dante

#

How do i access it?

low forge
#

Oh alright, thanks for the help!

graceful rampart
#

Preferably do them all

fathom pendant
#

Fundamentally insane

pastel ginkgo
#

I like to compare learning hacking as researching eldritch truths so yes you need to be a little nuts.

wide oak
#

I think in "Pass the Hash (PtH)" (https://academy.hackthebox.com/module/147/section/1638) there is a mistake in the example:

PS c:\tools\Invoke-TheHash> Import-Module .\Invoke-TheHash.psd1
PS c:\tools\Invoke-TheHash> Invoke-SMBExec -Target 172.16.1.10 -Domain inlanefreight.htb -Username julio -Hash 64F12CDDAA88057E06A81B54E73B949B -Command "net user mark Password123 /add && net localgroup administrators mark /add" -Verbose

The Import-Module here seems like it should be on Invoke-SMBExec instead. Otherwise the second command won't execute properly.

raven cairn
#

Could I have some help on the AD skills assessment 1?

#

I am pretty sure I know the way about how to do this, but I just need some clarification on a few things.

#

Been stuck on it for a while and would appreciate a nudge in the right direction

#

I don't think the tool I am supposed to use was touched on enough within the module.

lethal schooner
#

How many threads did you use? It's taking forever to find the password.

frigid summitBOT
pastel ginkgo
raven cairn
pastel ginkgo
#

So for where you are I made a reverse shell because it was just easier to work with, although madF0x insisted he didnt need one and just was ok with that crappy webshell

#

for a hint || These accounts tend to have weak passwords because they are not intended as user accounts ||

raven cairn
pastel ginkgo
#

Sure

wheat garden
#

been having this same issue you find a solution? As soon as I login to the jason machine that has the flag I get this error before the desktop can load up so I cant read the flag.

pastel ginkgo
#

Oh that one is buggy as fuck

#

I never got Proxifier to work

#

I used a different pivoting method to get the flag

#

its a common complaint

#

For Web Attacks - Blind Data Exfiltration, Was anyone able to get the automated tool to work? I got the flag the good old fashioned way but the tool dose not work for me.

fading quail
wheat garden
pastel ginkgo
#

I never got that far, I got stuck trying to get a connection

#

I think the issue is due to bandwith limitations

#

There's a similar problem on getting meterpreter working on the 2nd pivot in that module. Has to be done from pwnbox to work. Over the vpn it shits the bed.

wheat garden
pastel ginkgo
#

lol there you go

hazy grotto
#

Anybody doing the THM advent event?

shut matrix
#

Should I learn some SQL before I take SQL Injection Fundamentals or will that teach me what I need to know

sly tapir
final elm
#

search again, the exploit is a txt file

pastel ginkgo
#

The feeling when you finish a module you started working on at 10 this morning and finished 12 hours later

sly tapir
#

i have definitely been there...thought i was the only one

graceful rampart
#

Bro, this file transfers module is like an encyclopedia lmao. Theres a transfer method for everything. Not that im complaining. 3 pages of different commands so far and theres still more πŸ˜†

raven cairn
#

File Transfer's are super important tho!!!

graceful rampart
#

Agreed

#

And it's awesome how many methods they give

#

Always good to have something ti pull outta your back pocket for that one super obscure situation that you're inevitably gonna run into eventually

raven cairn
#

Loved how the module talked about evading detection

gilded sonnet
#

I completed CBBH modules today, looking forward for the exam

weak kindle
gilded sonnet
woeful oxide
#

Good luck man

#

I recommend you having your notes ready for the exam

brisk geode
#

~~hey can anyone help?

Module:Login Brute Forcing
Section: Service Authentication Brute Forcing

it seems like my container isnt responding i restarted the container multiple times~~

solved

lime frigate
#

I'm a new student. How do I get started?

woeful ermine
#

hello. I think there is a problem with metasploit - module section. Aim is finding an eternalromance exploit and get shell on target machine. I tried it on both vm and parrot instance. In both cases I ve got timed out error.

frozen socket
frozen socket
frozen socket
#

to te port you want and later being listening on thag port with nc

strange vault
#

can someone melt this guys router if i give you guys his ip address? stupid request, but he be creeping on girls on snap and I wanted to do a good deed lol

strange vault
#

i respect your decision

woeful ermine
#

@frozen socketno on 445 , 4444 lport for listening

frozen socket
#

the RPORT should be the same as the one on listening because

#

it is supposed to be open and ready to inject

#

and later you should have in your machine nc waiting on listening mode on that port

fathom pendant
#

the RPORT is the receiving port iirc

#

not to familiar with the msfconsole stuff but that rings a bell on it

fathom pendant
woeful ermine
#

@frozen socketwell no worries. I tried at that in instance

#

here you go

strange vault
#

my apologies, butttt if you have a server for that, plz provide @fathom pendant

tepid thicket
#

you shouldn't change rport for this exploit. 445 is default smb port
and lower ports are reserved. for listening port you shoud probably use a higher port

woeful ermine
#

@tepid thicketyepp I used 4444

fathom pendant
#
4. Keep it legal.
Do not request, suggest, perform, promote or in other way or shape discuss illegal activities. We respect and follow the Discord ToS as well as the HackTheBox ToS, and do not hesitate escalating matters appropriately, if we deem it necessary. If in doubt, ask a Community Administrator before posting or don’t post it at all.```
blazing crow
#

I know that is confusing questions but did you found the commands to get sid of the last two questions you are talking about.
these are the ones I found that gives correct sid.
||getting sid of user:- wmic useraccount get name,sid or whoami /user
getting sid of group:- wmic group get name,sid||

fathom pendant
#

The reason for win10 is most likely because a lot of corporate infrastructure still uses 10 and windows 11 isn't standard in corporations :)

rich vale
#

getting to the end of the AD enumeration module, this thing is -dense-

candid zephyr
#

No. 2 was like a mini htb box.

rich vale
#

good to know, im trying to finish it off before i fly out for vacation thursday lol

#

running out of time

candid zephyr
#

You'll do the assessments quickly but just absorbing and taking notes for each section takes time haha

rich vale
#

can you use the golden ticket with secretsdump to get a specific users hash?

#

nvm, got it

fathom pendant
#

ok the smb module is super buggy x-x i had to try the access command like 5 times before it let me do the thing

candid zephyr
fathom pendant
normal wind
#

What are you guys studying

fathom pendant
#

Penetration testing :)

normal wind
#

Nice

#

How long have u been in this field

fathom pendant
#

N00b time lol but tbh the modules are super simple to learn from

#

Super digestable

normal wind
#

I'm new to cyber security and I'm struggling to choose the path

fathom pendant
#

Well are you interested in finding bugs in programs, or sniffing and poking into networks is the first question

normal wind
#

Yes

#

I'm stuck to choose the path and I hope I can get an idea where to go

candid zephyr
#

Just dabble in everything, you'll find something that fits.

fathom pendant
#

^you can take a look at the general skill paths

#

Or the wider look at the career paths

normal wind
#

Right now I'm working on a pre-security certificate from try hack me

candid zephyr
#

TryHackMe might be better for you for a brief overview. They have a bit better step by step for Blue / Red team beginners.

normal wind
#

What's the difference between blue and red team

candid zephyr
#

Offensive / Defensive security.

normal wind
#

Aight

fathom pendant
#

Red is offensive

#

Blue is defensive

candid zephyr
#

It needn't be so black and white really, but when people refer to red team they refer to pen testing generally.

fathom pendant
#

^

normal wind
#

Thank you for the information

#

Blue team refers to ethical hacker

fathom pendant
#

Both are ethical

normal wind
#

Oh I see

fathom pendant
#

Penetration testing isn't necessarily an unethical thing. The goal of pen testing is just that, testing

normal wind
#

I think I'll just get the basic knowledge from tryhack me then I should come to hack the box

fathom pendant
#

You are testing within the scope defined by a contract,

normal wind
#

What do you say

#

Perfect

fathom pendant
#

Up to you man :)

normal wind
#

Appreciate it

#

What stuff are you doing on hackthebox

#

Are u a student

fathom pendant
#

I'm a student :)

normal wind
#

Thanks for the link

#

I am a math tutor

outer ledge
#

Can somebody nudge me with the blacklist filter of FILE UPLOAD ATTACKS?

kind turret
#

DM me

blazing crow
vital tree
brisk geode
outer ledge
vital adder
vital tree
spare condor
#

Trying to connect to the machine on Password Attacks / Pass the Ticket (PtT) from Windows, with RDP and I get the following:

#

Can anyone help with this?

broken warren
#

In the broken authentication module > predictable reset tokens section. I'm struggling to grasp what's being conveyed. The information just seems all over the place. I get that mt_rand() isn't like secure, but I don't understand what I'm supposed to do with my python script or if I'm even supposed to use it? The question says use the one from the open meeting example, but one link is just a whole php script that doesn't work (I tried serving it up on Apache locally and I get a page but it's wonky) and the other is the python reset token script. Then there's the two POC's.
Am I trying to actually get the flag with that python script or do I need to do something else? Do I need to modify the script beyond just the username? And current date (in milliseconds)? and do I need to change 'from hashlib import md5' to something different?

rustic sage
#

or try it from your own VM

candid zephyr
#

🦐 prawnbox

spare condor
#

I'm reaching the machine..

rustic sage
#

now try xfreerdp...

#

or gnome boxes...

broken warren
candid zephyr
#

'P@ssw0rd' etc

candid zephyr
#

single quotes

#

'

spare condor
#

Worked. Thank you. But why it required ' here? Cause of special characters on password? If it was abc it wouldn't require ', right?

candid zephyr
#

the double quotes mean it'll still try to interpret the $ etc

#

so if you did 0xhai = 1337

#

echo "$ohai" would output 1337

#

and echo '$ohai' would out put $ohai

#

0xhai you know what i mean

spare condor
#

yesss, perfect, thank you!

#

πŸ‘Œ

candid zephyr
#

So single quotes for your passwords basically xD

echo portal
#

hi

#

why i can't see gc in this server πŸ˜”

rustic sage
echo portal
rustic sage
#

hi hi

#

can smeone help me with pivoting tunneling and port forwarding skill assessment?

brisk geode
placid quest
#

@rustic sage where are u stuck maybe we can help each other

rustic sage
#

dm?

placid quest
#

@rustic sage ok

iron ermine
#

Hey there, I was wondering if anyone can help me with the getting started, service scanning module, I am getting the following error: error NT_STATUS_NOT_FOUND when connecting to the target with the following command: smbclient -U bob ////{IP_ADRESS}//users

#

I should add that I am able to see the shares. I just can't seem to log in with the provided user credentials

candid zephyr
#

smbclient is one of those stupid syntaxes i always get wrong first try.

iron ermine
#

Omg, I feel so stupid XD Thanks a ton xd

hybrid plover
#

Can anyone help me out on the pivot & tunnelling assessment?

candid zephyr
iron ermine
#

I will have a look at that, thanks again

candid zephyr
#

because i'll be damned if i can remember the slight dlffereinces with each impacket syntax /o\

iron ermine
#

Yeh, I have that problem myself >.<

outer ledge
#

Can someone help with Type Filters, I had the php file firing up and reflecting but then my pwnbox died. I treid to redo it but now it is just showing me the code when im trying to get the hello world reflecting.

rustic sage
#

Windows Privilege Escalation Skills Assessment - Part I, i got a reverse shell on the box but somehow powershell doesn't let me download Juicypotato.exe with either curl or wget. Any idea?

placid quest
#

@rustic sage what about Invoke-WebRequest

frank blaze
rustic sage
placid quest
#

@rustic sage did u use powershell

rustic sage
#

yes

frank blaze
#

What does the error message say?

formal crest
#

@red obsidian Who can I contact for an issue on one of the academy modules? I do not need help with a module but is more in line with a bug.

outer ledge
#

Anyone nudge for:
FILE UPLOAD ATTACKS
Module: Typer Filter

lethal schooner
#

Did anyone in the password attacks module/password mutation section attack ftp instead of ssh when try to brute the user 'sam'?

crisp remnant
#

Anyone for quick question on login brute forcing module ?

lethal schooner
#

Update: Ok so ftp is faster to attack than ssh. Why didn't they just get us to attack ftp in the module..

abstract orbit
#

Need help to make a bypass system for subway tickets with an NFC card

#

Any assistance?

frank blaze
# abstract orbit Any assistance?

Your question doesn't seem to be related to a Module on the HTB Academy and at first glance appears illegal. You're not going to find any help here is you're not asking for help with educational content held on the HTB Academy.

sinful falcon
#

Hello world, SOCKS5 Tunneling with Chisel module, I have this error on ubuntu server

crisp remnant
sinful falcon
abstract orbit
rustic sage
#

@frozen socket you may be able to get sensitive info from auxiliary one Backup might contain credentials

rustic sage
abstract orbit
#

ah thanks man

#

much appreciated

rustic sage
#

It’s pretty cool tbh

#

I can get cheap ones off Amazon that read and write but none hold a candle to proxmark3

abstract orbit
#

i mean i need to see if someone can do it bc then i can get it to my gov and tell them that this can happen so they can reinforce their system

rustic sage
#

And you likely will need β€œmagic” UID cards

abstract orbit
#

nah i can just jump the fence

rustic sage
#

True lol but it’s an area worth exploring

abstract orbit
#

hacking in general and programming is something worth exploring

#

i would like to get in that endless rabbit hole

rustic sage
#

There are a lot of phsyical access controls that can be bypassed with proxmark3 far more than you realize most likely

abstract orbit
#

idk how to do any of this

#

furthest ive gone is arduino XD

outer ledge
#

Anyone nudge for:
FILE UPLOAD ATTACKS
Module: Typer Filter

rustic sage
abstract orbit
#

:D

rustic sage
#

Even the best of the best

abstract orbit
#

or like the furthest i might have gone is put windows 10 or do some weird things on linux

#

but i would enjoy starting to learn

outer ledge
#

Anyone nudge for:
FILE UPLOAD ATTACKS
Module: Type Filter
Thnx in advance! I had it but since my pwnbox died I can not recreate the thing without failing..

woeful mural
#

Anyone here finish ACTIVE DIRECTORY ENUMERATION & ATTACKS Skills Assessment 1? I am stuck on the last 2 questions?

stuck hull
#

Hello I am struggling with FOOTPRINTING LAB (EASY). Any help greatly appreciated.

I have connected to the ftp server on both the standard and non-standard port. I had to use the hint... but when there I cannot even list the contents of the directory. I see this:

candid zephyr
#

It won't let me review the questions on mobile πŸ˜‚

woeful mural
candid zephyr
#

Oh ya

#

I'm trying to think of a way to give a nudge without a spoiler. Have you enumerated what things the user you've got is able to do?

dim hound
frail thicket
#

Someone knows how to report issue with the target server in a module?
Module: Windows Privilege Escalation
Section: SeImpersonate and SeAssignPrimaryToken
The question ask to execute priv escalation but the user does not have SeImpersonate privilege.

candid zephyr
frail thicket
#

I connected to the box using "htb-student" and ran cmd as sql_dev. But the user does not have the tokens privileges.

graceful rampart
#

Also, someone call me stupdi but where exactly is the vrowser in the shells and payloads skills assement vm? I could very well just be blind but I dont see any bropwsers installed

#

Am i just dumb?

frail thicket
graceful rampart
#

SeImpersonate is one of them

#

iirc you get GUI access for that one right? Just run cmd or powershell as administrator

#

it should be there

frail thicket
#

No, I didn't. The sql_dev account is not in the Remote Desktop group, this is the first issue with the box.

graceful rampart
#

ohhh, right. I just looked back at my notes sorry

frail thicket
#

As workaround, I connected using htb-student and then executed cmd as sql_dev user.

graceful rampart
#

iirc youre supposed to connect usiong mssqlclient like they do in the example

#

you can pretty much just copy commands directly from the example for most of it

frail thicket
#

but I don't see the tokens and I also tried to execute JuicyPotato, RoguePotato and PrintSpoofer.exe - non of them worked

graceful rampart
#

Can you show me the output when you run whoami /priv?

frail thicket
#

humm ok, I didn't try to get access through mysqlclient... I thought we had to RDP to the server

#

thanks for the tip, let me try that

graceful rampart
#

big difference

#

but yea, just follow what they do in the example

outer ledge
#

Anyone nudge for:
FILE UPLOAD ATTACKS
Module: Type Filter
Thnx in advance! I had it but since my pwnbox died I can not recreate the thing without failing..

frail thicket
swift forge
#

Anyone able to help with the SID question on the Window's Security lesson?

graceful rampart
#

ok, so I can run firefox from the commandline, but not from anywhere else on the system

#

fml

rustic sage
swift forge
#

How can I check which 3rd party security app is disabled at startup?

outer ledge
#

Anyone nudge for:
FILE UPLOAD ATTACKS
Module: Type Filter
Thnx in advance! I had it but since my pwnbox died I can not recreate the thing without failing.. Thnx in advance

limpid maple
#

Oussama Ben Laden is the goat

swift forge
candid zephyr
swift forge
candid zephyr
#

Oh idk. I've not done th emodule. 3rd party implies not defender.

swift forge
candid zephyr
#

If you're getting stuck a lot then you need to spend more time parsing the information / taking notes to be honest. the answers are generally in the text above. There's here and the forum but nothing in the questions hasn't been answered in the section already.

outer ledge
#

I have to say the Academy pwnboxes are not stable as well. Still figuring out why my command worked before and now it does not..

candid zephyr
#

i don't understand the pwnbox. they run like shit for me - surely a vm will be better performance for anyone?

#

or even boot kali off a usb

outer ledge
#

Ya true but sometimes its just easier to do stuff on my dual screen setup from browser

#

but ya still, you pay for it.. why isnt it just stable..

#

Also target resetting is more like reset 8x before the target works again

fathom pendant
#

Also if you're having issues with targets sometimes you need to refresh your VPN/VPN key

outer ledge
#

heh?

#

pwnbox is not using vpn

fathom pendant
#

It is

#

Just in the background

outer ledge
#

no as you just use a browser

#

I am using both pwnbox does not require you to set up vpn

fathom pendant
#

You don't need to set up VPN... Because it's already on it

outer ledge
#

pwnbox is casting a VM from HTB to your browser

#

VPN is only for your own attack box to connect to htb servers what are you talking about?

outer ledge
naive aspen
#

Looking some help for the Pivoting, Tunneling, and Port Forwarding skills assessment. I'm on the 2nd box but when I try to do a reverse port forward from the 2nd box to my attack host via the 1st box, I can't get a connection. I've tried all the options outlined in the module. Breaking it down to see where it's not working, I started a python web server on my attacker box and used a ssh -R tunnel to the 1st pivot box but it's opening the listener on it on 127.0.0.1 so it won't accept connections. The I've tried a MSF reverse tunnel and I can see the port listening on the 1st pivot box on 0.0.0.0, and when I try to make a connection from the 2nd pivot box it establishes with the 1st pivot but the connection doesn't get established from the 1st box to my attack machine. Any ideas?

graceful rampart
outer ledge
#

Hahahaha oki so how do I reset the vpn of pwnbox?

fathom pendant
#

^

#

Switch the VPN server

outer ledge
#

talking to a wall here

graceful rampart
#

Bro, Ive done 4 modules in the past day and a half. If I continue at this pace ill be done with CPTS by the end of next week πŸ˜†

graceful rampart
outer ledge
#

congratz

fathom pendant
outer ledge
#

I am just saying

#

What you are showing is for your personal computer vpn connection

#

Has nothing to do with the pwnbox

fathom pendant
#

Brother

#

Read the text

#

Warning: Each time you "Switch", your connection keys are regenerated and you must re-download your VPN connection file.

All VM instances associated with the old VPN Server will be terminated when switching to a new VPN server.
Existing PwnBox instances will automatically switch to the new VPN server.

graceful rampart
outer ledge
#

I understand that I need it for my own comp to connect to academy vpn

#

Pwn box generates a attack vm for me to attack on plus the module requires me to click another thing to spwan a target

fathom pendant
#

Ok

outer ledge
#

spawn*

fathom pendant
#

Let's break this down

outer ledge
#

Everytime I Start an instance a new VM will be generated

#

PWNbox generates a new instance VM every time I click Start Instance. Connected to their servers yes but not through my openvpn file

#

nvrmnd, I dont want to discuss I want to progress

#

All is good

pastel ginkgo
#

Was anyone able to get the Eyewitness.py to work in the Attacking Common Applications Module?

#

it just spits out a massive error for me

outer ledge
#

whats the error?

pastel ginkgo
#

its massive but it looks to be an issue with firefox

outer ledge
#

can you dm me the error

pastel ginkgo
#

I ran an apt update / upgrade but nada

fathom pendant
# outer ledge PWNbox generates a new instance VM every time I click Start Instance. Connected ...

It still connects through the VPN tunnel, that's how it's able to actually connect to the local labs, because the actual local test labs are on an internal network, not connected to the outside world. The VPN tunnel connects us to an interim access point which we use to explore those labs/modules... So yes the VPN is the exact same. The only difference is, the VPN is connected in the background on pwnbox instead of manually on your own system/VM... There is no way to access the (non public) IPs without the VPN so changing servers resets and refreshes that connection

#

While it generates a new instance it's still using the same VPN key

outer ledge
#

Thank you for all the effort

#

Didnt wanna keep you from your projects srry for wasting your time

fathom pendant
#

Phone support job so I got time. not on my personal system ATM to assist with directly doing anything. But yeah if you are having difficulties with a specific module: best practices:
Be specific with your ask:
Provide screenshots:
If it's going to be a spoiler try to avoid it:
Ask yourself what you do know about the attack you are performing, what did the module teach you so far

#

Sometimes the answer is in plain text in the module

#

Aka the steps they show you are EXACTLY what they want you to do :)

#

Also with pwnbox I recommend opening it up in Fullscreen instead of the tiny window they give you

outer ledge
#

Nah my frustration is that I had the script reflecting what I needed then pwnbox died, so all my work gone. I have my notes so I retried from my own attack box but now the same comman does not worj

#

Supeerrrr annoying

fathom pendant
#

What module are you on?

outer ledge
#

FILE UPLOAD ATTACKS: Type Filters

#

The rest Ive completed

#

just that one before i can do skill assessment

fathom pendant
#

Sometimes the error you get can help determine if you need to regen your VPN key

#

I've had it where I copied the attack onto pwnbox and it worked so I just redownload my ovpn key

outer ledge
#

Oki ill try tomorrow

#

Thank you tho

fathom pendant
#

I wish you luck !

twin gulch
#

Anyone online for a question at skill assessment at password attacks?

fathom pendant
#

Sorry haven't done that one

dim hound
#

can I pm you regarding that matter?

warm sail
#

if i have a password encoded as a hash, what tool would i use to crack it?

rustic sage
warm sail
rustic sage
#

I'm on a budget recently and have to get rid of Pwnbox... is VirtualBox working for macOS again? I have an M1 chip

#

I'd also kinda like to have a VM again instead of doing everything in the browser

proud pine
#

You should not use a pentest distro as a daily driver.

rustic sage
#

I want to use macOS as my main OS

#

and have VMs

proud pine
#

What's the problem you're running into with virtualbox?

sly tapir
#

is parrot as mainOS better than Kali?

rustic sage
#

I was told it doesn't work on M1 macs

#

or apple silicon in general

rustic sage
#

people always said it didn't work

#

thats is why I've been using Pwnbox

proud pine
#

I don't know much about mac. Is it ARM or something?

rustic sage
#

it says it mainly uses the ARM architecture yeah

#

Apple silicon is a series of system on a chip (SoC) and system in a package (SiP) processors designed by Apple Inc., mainly using the ARM architecture.

rustic sage
#

Checkout VMware fusions or parallels @rustic sage

#

Pwnbox sucks it should be called painbox cuz it b a pita

proud pine
#

Ah yeah, pretty sure virtualbox would not work. I don't know if there's any other alternative that can run an x86 VM.

rustic sage
#

If you need license code just search for them online

#

VMware Fusion doesn't currently support M1 macs @rustic sage

proud pine
#

Doesn't kali have an ARM version, though?

rustic sage
#

haven't heard too much about Parallels I'll do some research

rustic sage
pastel ginkgo
#

On the Attacking Common Apps - Worpress enum, where in the hell is this mysterious 3rd plugin. Everything ive found isnt the answer and ive found a few plugins.

rustic sage
#

Parallels looks interesting! I'll try that thanks @rustic sage

#

No problem

rustic sage
onyx rapids
#

Can someone explain the "Passwd, Shadow & Opasswd" objective? I SSH in with the username and password from the previous section and then I'm assuming I've got to do something with /etc/shadow. The probablem is that I have no access to this file at all

rustic sage
#

Have u tried ca /etc/passwd

#

Cat*

fathom pendant
# rustic sage VirtualBox works for Mac M1?!

Mac VirtualBox users will be happy to know that VirtualBox now runs natively on Apple Silicon ARM processors, including the M1 and M2. VirtualBox is virtualization software that allows you to run o…

rustic sage
#

I believe passwd is accessible by all users as it’s needed for certain things

onyx rapids
#

Yup, I can see the /etc/passwd

rustic sage
#

So typically you’d take a list of all those users and use that data for password attacks. Shadow contains password hashes and is protected

#

In general

#

I wish I could help more but can’t acces htb or my notes atm

rustic sage
onyx rapids
#

Apparently from doing searches, I see people can access the shadow file, but I don't understand how

rustic sage
#

Need to elevate permissions.

#

Or change permissions on shadow but that typically requires elevated perms anyways

#

So u need to get access to a higher user or one with proper permissions. The passwd file can help you do that

#

To access shadow all you’d do is cat /etc/shadow with right user/perms

onyx rapids
#

Yup, that's the strange thing, everyone who seems to have solved it, just goes straight for the shadow hash and cracks it

rustic sage
#

Copy the entire question you’re trying to solve into here

#

Do a ls -lah on shadow

onyx rapids
#

-rw-r----- 1 root shadow 1.7K Feb 9 2022 /etc/shadow

#

" Examine the target using the credentials from the user Will and find out the password of the "root" user. Then, submit the password as the answer"

rustic sage
#

Hmm looks like users can read the file try audio

#

sudo cat /etc/shadow

#

Actually I think it shows people in group shadow can read it my b

onyx rapids
#

Will isn't in the sudoers file

rustic sage
#

Try doing sudo -l and see if you can run any programs with no password

onyx rapids
#

Sorry, user will may not run sudo on nix01.

#

nervermind I found a hidden folder in will's homedirectory called backups with the shadow file in there

rustic sage
#

Nice there ya go always enumerate dies

vital adder
onyx rapids
#

HTB is just evil

rustic sage
#

Lol

#

It’s truuu

vital adder
#

@rustic sage oh wait you got a mac?

rustic sage
#

No it was just something to check out

onyx rapids
#

It's kind of a dumb because in the module they teach you about how sometimes the shadow file and passwd file can have these little flaws, but then they throw you a curveball and say "We're going to do absolutely nothing of what we just taught you"

rustic sage
#

The vm software I mean

rustic sage
onyx rapids
rustic sage
tepid thicket
#

Can anyone give me a nudge on Windows Privilege Escalation Miscellaneous Techniques? I have shell as nt authority/system, cracked a couple hashes, found a password from lsass dump, and found an additional password using lazagne.exe but none of these are the expected answer. It is asking for cleartext credentials for an "account" but doesn't specify which account ... 😀

vital adder
#

i got 0 note on how to get the answer for some reason all i got in my note is ||Get-LocalUser||

iron basin
#

Anyone mind helping on the web proxies module? It is the Web Proxies - Repeating Requests section. It says to use the repeat function to find the other flag. I use this function and pass the commands however I cannot find the flag due to inability to traverse directories(hint says its in another directory). Do I need to privesc in order to accomplish this? (Solved) Use the find command to help out, not sure why I wasn't allowed to cd out of the directory however.

hazy grotto
#

Anybody ever have issues with my VM not allowing you to change the display resolution anymore? Also can't enable my second monitor anymore.

solid wedge
iron basin
#

Anyone familiar with proxychains? Having some issues with it on Web Proxies module - Proxy tools. Not able to run commands with proxychain

pastel ginkgo
#

So how do you pip install a module for python 2.7 if you have python 3 and 2.7 installed

#

because I already have it installed for python3 sooo pip install click says its good lol

#

but when I try and run this 2.7 script it wants click x)

vital adder
#

you can use pip --version to see which version your pip is using by default pip will using python2.7 but in kali it used python3

#

or if you need to install something from pip but you nee python2.7 you can use pip2 and if that isn't installed you can install it manually

#

@pastel ginkgo also can i dm you about the AD Enumeration & Attacks module?

pastel ginkgo
#

sure

fresh reef
#

Im currently on the Passwd, Shadow & Opasswd, Ive retrieved the hashes and am now solo cracking the root hash per the Question... May I PM someone for a Sanity Check?

vital adder
fresh reef
#

Thankyou~

hazy grotto
#

Is there a HTB rep that can help me with an issue? I was told that if you submit a question wrong 3x. you can ask help from HTB. I do not get this pop up.

pastel ginkgo
#

Thats only if you have the annual sub

#

& its also xmass soooo support is limited

hazy grotto
#

I have silver annual

#

I'm a HTB faithful servant. I pay homage.

#

Finally made it to 40 percent of the pentest path. uffda. Started this journey knowing nothing and never using linux. Been a stressful trip but i've learned alot. Thanks to all the heros in here that help the inferior out.

strange stone
#

alguem br?

#

need help

fathom pendant
pastel ginkgo
rustic sage
#

ngl I thought everyone said CleanMyMac was a scamπŸ˜‚ (only posting here because of the macOS Fundamentals module)

thorn urchin
#

It is, do they seriously have it in the fundementals module??

#

I literally get paid in my day job to remove that shit

#

I did it today in fact

rustic sage
#

yes they recommended it in the "Security Tips" section, CleanMyMac is an excellent tool for any macOS user.

#

also recommended Objective See's products, which I've never heard anything about so I'm looking into these at the moment

#

I need a bit of help on the third question in info gathering web edition subdomain enumeration
so i ran a dig command on the server and i found two zones
||a.root-servers.net. nstld.verisign-grs.com.||
and i ran a dig command on ||a.root-servers.net.||to read the txt record but i cant
how do i find its txt record

rustic sage
#

Wow even as a daily macOS users I still learned some things from macOS Fundamentals. Highly recommended, especially if you want to learn more about the security & privacy benefits that come with Mac and Apple devices in general.

Really only compliant is the suggestion to install CleanMyMacπŸ˜‚ Don't install this... Rather take the time to learn the security & privacy settings you can set, don't install sketchy software, and don't go to sketchy sights. If you do you'll be okayπŸ‘Œ

ripe terrace
fathom pendant
rustic sage
# ripe terrace Out of curiosity, what exactly is wrong with CleanMyMac?

let me start by saying I’m not one of those β€œMacs never get viruses” people…

macOS is very secure in the sense apps only do what you give them explicit permissions to do. Meaning if you configure them properly you’re fine. Yes there are some 0 days and macOS vulnerabilities that bypass these security features, but the chance you encounter one is very rare.

If you properly configure the settings, update the system, update your applications, and remove outdated/unused applications, AVs and auto cleaners are a waste. If you download safe apps and go to safe sites you really don’t need them.

you will also find very few people vouch for CleanMyMac and a lot of people against it. I’ve never personally used CleanMyMac, but the majority of people saying don’t use it turned me away.

rustic sage
brisk geode
fathom pendant
#

Is there a username list that is provided in the Resources button? @brisk geode ? The Footprinting Module I'm doing has a Footprinting-Wordlist that I have yet to use but there may be a resource that you needed to add if it's something you don't have yet?

brisk geode
#

less informative

magic valve
#

Hey everyone! May I message someone for some further assistance regarding AD Enumeration & Attacks Skills Assessment Part 1 question 4. I have attempted to login via evil-winrm with the credentials from previous questions and doesn’t work. I’m lost on what to do and wondering if I am on the right track.

latent sage
#

hello @thorn urchin can you please check your DM ?

thorn urchin
#

checked, I see nothing

#

also like brushing my teeth n shit before bed so

latent sage
#

so can you please check again !

shadow owl
#

What is the hardest module you came across?πŸ€”

rustic sage
fathom pendant
#

Not sure yet but I'm divinginto this rabbit hole; a command that I'm given is using specific numbers and format arguments so I'm researching what those do since they aren't really touched on we're just given the command and told "hey this is a brute force" @shadow owl

#

But I wanna know WHY/How it's a brute force

rustic sage
#

Good morning from Spain! Anyone working with the password attacks medium lab?!?!

rustic sage
vital adder
rustic sage
fathom pendant
# vital adder hello from wakanda, shoot me a dm

Hey tom! I'm doing the smb and the basic code they have to iterate to find users and groups is pretty cool :D! I had to use uncle google to find out why the specific range but hey it's a thing. And I learned how to grab the flag without fully connecting to the server too :D I knew how to get in and pull the flag from last night.... but I forgot to actually pull it LOL

vital adder
#

the password attacks module?

fathom pendant
#

:) still in the baby steps

#

I figured they'll elaborate on the code but they also said "here's some other automated codes as well LOL

vital adder
#

yea i think i do that section manually or something because i got like 0 note on any given code

#

also for the flag if you are too lazy to download and cat the flag when you access the share with smbclient you can use more flag.txt to just view flag

fathom pendant
#

LOL yeah i've done that a bit too in other modules where you pull files forgetting i could you know get the file Ghost_Laugh

shadow owl
#

@rustic sage Thanks for the tip

fathom pendant
#

@vital adder printf() is a neat command :)

rich vale
#

just got to the skills assessment for the AD module and... it feels kind of janky

#

i mean its early, but specifically the web shell you start with

candid zephyr
#

What about it?

#

PowerShell webshells are a thing.

#

The only trip up is it assumes a basic level of competency in general.

rich vale
#

I guess it just feels weird and kind of unstable, after the module focused more on starting from an attack host or one configured for loading necessary tools

candid zephyr
#

I haven't done the CPTS path etc but I can only assume the AD one comes after a bunch of other modules.

#

If your first ever experience with offensive security was this AD module you'd hit a wall fast in the assessment.

#

If you've ever done a CTF box etc then it's somewhat of a trivial step.

rich vale
#

sure, its not that I can't get beyond it, more of a comment on that it feels a bit out of step with the rest of the module

#

the module is pretty focused, dense and solid, then you get to the skills assessment is a janky webshell that you can't tell if its working or not

candid zephyr
#

Sure, but you can get out of the webshell with one quick command. The module already taught you how to do this.

#

Imo the danger with the modules is they make you lazy. SSH into a box with all the tools and privs ready to go - I can only assume the rest of the modules teach you the basics of work flow in general, moving tools about etc.

#

The AD module kinda assumes a level of knowledge is what I mean, it's teaching you to do AD specific things - not to hack.

#

The assessment is you using them in an "actual" environment.

#

I don't think it's "janky" but I do agree it's a significant leap from what you've done in the sections. That's why I can only assume it's meant to be taken as part of a course.

outer ledge
#

Anyone nudge for:
FILE UPLOAD ATTACKS
Module: Type Filter
Thank you in advance!

fathom pendant
#

Not sure what I'm missing for this in the smb module I don't even really know what this is supposed to mean tbh

kind turret
fathom pendant
kind turret
#

Then use netsharegetinfo

fathom pendant
fathom pendant
#

I'm thinking if recording myself doing these blind then record them at a later date once I know what I'm doing just to see progress

kind turret
vital adder
#

hi guys, need a nudge for the last part of AD Enumeration & Attacks - Skills Assessment Part II i already got the cred for question 9-10

vital adder
#

the last 2 so yes

candid zephyr
#

Send a DM

vital adder
#

sure thanks