#modules

1 messages · Page 35 of 1

polar crag
#

you have to start openvpn with the downloaded file
sudo openvpn academy-regular.ovpn

dawn forge
#

Feel free to write me

winged zodiac
dawn forge
winged zodiac
#

Then I why can't ping the box

dawn forge
winged zodiac
#

No its the first section on getting started module its not some medium level box I'm pretty sure it doesn't have that but still I tried -Pn probe scan on nmap but no results

dawn forge
winged zodiac
#

I do have reset the meachine

candid zephyr
#

Why are you running nmap?

#

Visit it in a browser.

winged zodiac
#

I have been simply over complicated things

dawn forge
winged zodiac
dawn forge
polar crag
#

Doing the Attacking Common Services Lab - Hard
cant get a foothold.. tried bruteforcing smb with the given resources and with the user "simon" but nothing works.. null session are not allowed and when trying to bruteforce it with msq/hydra/crackmack i get alot of "success" messages but these passwords dosent work.
A little confused how thats even possible.. even if i choose a complete different userlist + rockyou it gives me a success after the it checked the first row

winged zodiac
#

Bro I have been THM- top 3% its just I'm new to HTB so just chill

winged zodiac
#

Tryhackme bro

dawn forge
midnight patio
#

hey, have anyone finished the command injection Skills Assessment?

#

the output of my flag.txt is wrong

winged zodiac
spare condor
#

@dim hound Did you find the solution on this one? Can I DM you?

candid zephyr
#

Top 3% I thought everyone started at top 1%

echo zenith
#

Linux Local Privilege Escalation - Skills
get the flag5.txt

help!!! I got a reverse shell with NC, but I can see that it is limited, despite that, I can run the command Sudo -l and I get that /usr/bin/busctl can be run as root. I go into GTFobins and it shows me a simple command to escape the limitation or get root, which is what I need, but I don't understand how to do it, it shows me like this in GTF:

sudo busctl --show-machine
!/bin/sh

I execute the commands one after the other and the first one shows me information, and the second one is blank, I can't do it.
What am I doing wrong or what am I missing?

severe dagger
#

Hello. I am doing LINUX PRIVILEGE ESCALATION >> Shared Object Hijacking. I just can't reach the required answer. Can someone please guide me.

#

I am doing exactly what it is asking for. Replicating the steps. I can't figureout.

echo zenith
severe dagger
#

how did you figured out?

echo zenith
celest vault
#

using smbclient everything works fine until I put in the password provided and it times out? Tried this on my VM and on the pwnbox and same issue, anyone experience something similar?

#

also tried it as sudo, and smbclient -U bob \\IP\users to the same effect

candid zephyr
#

Also usual are you connected to vpn etc.

iron plaza
#

Hey all, I am in the Attacking SAM section of the Password Attacks Module. Trying to solve one of the questions but I get this response... Any idea why this is the case?

celest vault
#

[refreshed target IP but same]

graceful rampart
#

You can also use crackmapexec to dump SAM

iron plaza
graceful rampart
#

They're very large files. How did you transfer them? It's very easy fir them to get mangled in transit sometimes

hard knot
#

WHO PINGED ME !!?

vital adder
rustic sage
feral stump
#

couldn't really solve it after trying on VM and PWNBOX editing the shell and not editing (leaving default parameters)... not sure why... found the answer with the help of a kind soul but would be interested in understanding why it did not work for any of the attempts I tried

#

thansk @thorn urchin

thorn urchin
#

hmm did you use the vhost like the question said?

teal stirrup
#

Web Attacks -Bypassing Encoded References challenge if failing to stay up

#

):

thorn urchin
#

double checked the page and yeah the answers pretty close to what you got but not quite. Not totally sure why yours would ve different

#

Yeah just ran through the section again, still got the normal correct answer

teal stirrup
#

fixed with log out && login ):

long saffron
#

should i use Kali or parrot OS?

feral stump
#

and the result i obtained is so close to the one that is correct

teal stirrup
long saffron
#

i cant choose which one i should use daily

teal stirrup
#

I usually use kali but haven't used parrot in some time. However felt like parrot was the closest thing to kali if you have only used kali up to that point.

long saffron
#

Okay thanks!

old verge
#

Hello. Can I get some assistance with Live Engagement from Shells & Payloads first box?

knotty hemlock
#

Hi, I can't SSH as user MTanaka in the "User and Group Management" section of the "Introduction to Windows Command Line" module. It's the third day in a row that it seems not working, although I can ping the machine and see that port 22 is open with nmap... Anyone else having this issue? There is no error message, just a timeout:
❯ ssh mtanaka@10.129.203.105 Connection reset by 10.129.203.105 port 22

pastel ginkgo
feral stump
#

I am at Live Engagement section module Shells & Payloads

#

when I rdp into the foothold machine

#

there is no web browser on it? Or am i getting blind?

#

thx for help

old verge
#

I had the same issue chronosbolt

feral stump
#

no way

#

how did you solve it? can I dm

#

?

old verge
#

you can use burpsuite built in browser

#

I and actually using sshuttle

feral stump
#

that's what I thought yeah with burpsuite

#

wanted to make sure i was not out of my mind

#

thx @old verge

old verge
#

I started ssh on the foothold box and using sshuttle to pivot

rustic sage
#

Hi to all, i have an issue with the mysql login using default creds into the password attacks module, lesson password reuse. In fact the mysql port is closed on the target machine.Did you get the same issue?

old verge
#

that way I can use my kali box

#

if you find a way on box one, please provide what you found. I am stuck

feral stump
old verge
#

yes.. want to do it together in a private chat?

feral stump
#

sure let me DM give me a sec ... got the last question too

#

and the previous one regarding machine 3

graceful rampart
#

theres no shortcut to it for some dumb reason

#

I found it with pure dumb luck

feral stump
#

@old verge suggested to pivot and use kali

#

I am checking if that works

rustic sage
#

Hi all,

I am doing final machine in Getting started module
I am stuck at next things:

I got API KEY
I got admin.xml file with username 'admin' and password that looks like this: 033e22ae348aeb5660fc2140aec3585XXXXXXX

Also, I got admin panel access. But still IDK how I am supposed to get foothold onto server 😅

#

I try to use this password from admin.xml file and to put it into file then ssh with that file that contains that password but it requires me admin password. I don't know how I am supposed to log in with API key (is that possible at all?).

severe dagger
#

@rustic sage possibly that is hashed. Tried running in cyberchef? or anything similar? crackstation?

rustic sage
nimble warren
#

Hello Everyone! Sorry for the off topic (didn't find the right room for it). Do I have to verifciate my discord account with HTB account, or is it fine if I don't do that? Have only HTBA account, but if it's a must, then i'll to a HTB account right now

rustic sage
#

I tried to change admin password in control panel and it said:

"Error: Unable to continue: Unable to write the configuration file. CHMOD 755 or 777 the /data, /backups folders & sub-folders and retry."

rustic sage
candid zephyr
#

Does thou need to verificate to thrust mine shitpost upon thee

rustic sage
#

Means wrong hash type chosen or hash isn’t formatted properly

#

Use this command hashid puthashhere

#

Hello, I need guidance with the password manipulation section under Password Attacks. I have used multiple rules and still am unsuccessful of cracking the password with hydra using the user sam.

#

@rustic sage And then hashcat -h | grep hashtypehere

#

Than put that in the -m for hashcat

#

Also…

#

Make sure the hash in the file you’re cracking doesn’t have any hidden spaces or tabs or hidden double chars or even a newline if it’s only one hash

#

Also can try crackstation.net website always try that for a hash first @rustic sage

rustic sage
#

But it doesnt let me log now with that password lmao

#

Login how?

#

I am getting permission denied

rustic sage
#

directly to that machine

#

Dm me command you’re running

rustic sage
fathom pendant
patent rose
#

Hi! I struggled 2 days on that too. I finally read your comment that helped me out. They definitely need to rewrite the question.
I've tried multiple times without payload, and with the pattern as payload, nothing worked.
I finally used the 'dumb' payload ... and got it ... thank you again.

rustic sage
fathom pendant
#

Maybe there's an admin page

vital adder
#

if it is talking too long cut the first ||17000|| word

rustic sage
#

trojan that does not come out formatting the pc can replace the memory?

graceful rampart
#

Sam is the SMB user right? I had to use the netasplout module to crack that one

#

For the password mutations thing

rustic sage
#

Its an SSH user called "sam"

graceful rampart
#

I couldn't do ssh with hydra

#

Had to use ncrack

vital adder
rustic sage
#

What's ncrack? Because I agree I have used multiple rules and sources such as metasploit scanner.

long saffron
#

hello guys can i ask which one parrot OS edition i should download: Security , Home or the Hack the box edition?

vital adder
#

both is for hacking (use the Security one)

rustic sage
#

Okay I'll try learning about ncrack and using it.

graceful rampart
rustic sage
#

trojan on motherboard

long saffron
graceful rampart
#

The htb version was made and is maintained by htb lol

long saffron
#

i mean in usability

graceful rampart
#

Not thay I know of

#

But I don't use parrot

long saffron
#

Kali?

rustic sage
graceful rampart
rustic sage
#

Okay heres the problem then, I must be running the wrong command because I'm not getting that many.

#

hashcat --force sam.txt -r custom.rule --stdout | sort -u > mut_password.list

#

This is the command I'm running, its not giving out that many passwords.

#

sam.txt just holds "sam"

graceful rampart
#

Well why would you do that? You're given a "password.list" file to use

#

You need to mutate that

rustic sage
#

oh.

#

I assume I was suppose to alter sam because he had a bad password

sage glacier
#

hi everyone

graceful rampart
#

Mutating the username would be useful if you know you have a valid password but don't have a valid username

#

If you have the username, you need to figure out the password

rustic sage
#

Does somebody know how to 'update' meterpreter shell. Because meterpreter shell can't do basic commands like whoami, pwd, sudo -la

graceful rampart
#

It can

#

You need to drop into a shell

#

shell

#

Will get you there

rustic sage
#

Sorry I'm having difficulty understanding this, whats the difference of brute forcing with a password list that has nothing to do with sam, compared to a mutated password list that also has nothing to do with sam.

rustic sage
graceful rampart
rustic sage
#

Ohhhh. I kept getting caught up on the sam part, but that makes complete sense thank you.

graceful rampart
rustic sage
#

This is going to take a long time isnt it.

#

I have an idea, ill split up the mutated file into 3 files, and use ncrack, hydra and metasploit at the same time.

#

tfw when you realize you don't know how to grep for the first 17000 lines.

#

Does somebody know why I am getting permission denied?

#

I set python server to run on local host in order to download .sh file from remote machine

sonic wyvern
#

did you try to run this command with sudo before?

thorn urchin
#

you should run it from a directory you have permissions for such as a home dir, or a web dir in the case of a webserver user, or from /tmp or a dozen other valid locations

#

otherwise you a user could just wget a new passwd file from /etc/ and instantly priv esc on any linux box lol

rustic sage
thorn urchin
#

idr the octal codes, you do chmod +x

rustic sage
#

The thing that is useful and Idk what that means is when I do "sudo -l" I get:

User www-data may run the following commands on gettingstarted:
(ALL : ALL) NOPASSWD: /usr/bin/php

#

This is taking forever, any advice on how I could speed up the process @graceful rampart

graceful rampart
#

what command did you use?

rustic sage
#

hydra -l sam -P ~/Downloads/HTB/Academy/PasswordAttacks/Password-Attacks/mut_password2.list ssh://10.129.68.220

#

ncrack -p 22 --user sam -P ~/Downloads/HTB/Academy/PasswordAttacks/Password-Attacks/mut_password2.list 10.129.68.220

graceful rampart
#

Have you already taken the first 17000 words off of the password list?

rustic sage
#

Yes

#

7 minutes before my ip despawns 😦

thorn urchin
rustic sage
graceful rampart
#

Lmao

gentle swift
#

Hello guys, I must say, in the introduction to cybersecurity path, the "Setting up" module comes before the OS's modules although it requires knowledge in them as prerequisites, doesn't make much sense.

rustic sage
#

Bruh. I just learned the head command to do all that, how would I use grep to remove the first 17000 and cat everything else.

graceful rampart
#

sed '1,17000d' mut_password.list > cut_mut_password.list

rustic sage
#

hmm I have to look into the sed command, but thank you friend.

graceful rampart
#

np

rustic sage
#

Solution attained, thanks for the assistance!

rustic sage
#

But still don't know what I am supposed to do. Any hint?

thorn urchin
#

Yes, and im saying thats the right path, to understand what you need to do you should google sudoers to learn how that works, then google gtfobins to see how that works

#

combining the two bits of information will show you how to use it

rustic sage
thorn urchin
#

I dont believe in telling people the answer but ill tell you how to go find the answer for yourself

rustic sage
#

Thats what I am asking

#

Make sure you understand why though its a really important thing to learn!

#

Im gonna do those things you and @rustic sage mentioned

graceful rampart
thorn urchin
#

yes so start literally googling "sudoers" and read

graceful rampart
#

Only then should you go to GTFObins to find out how to abuse the relationship

rustic sage
#

Yes, take their advice mine might get you the answer but this is a very common tactic in priv esc and so its best to understand how it works.

#

Thank you all!

#

Im still learning it too

#

but you see here :User www-data may run the following commands on gettingstarted:
(ALL : ALL) NOPASSWD: /usr/bin/php

#

right now you are www-data, if you check your id

graceful rampart
#

dont give away the answer

#

hes gotta find it himself to learn

rustic sage
#

Okay you're right

thorn urchin
#

tbf the module in question I believe specifically mentions this attack path, but it also assumes you have a certain amount of linux fundementals under your belt, of which sudoers definitely counts

#

Ill be the first to say you dont actually have to grind fundementals before you get started on the fun offensive stuff because thats what I did back in the day, but it does mean knowing when you have to weave in a bit of fundementals to understand whatever you're currently trying to tackle

rustic sage
#

I believe this is so easy, but I am 1hr stuck on this part where I need to run sh scrip LMAO

thorn urchin
#

the .sh script wont find anything you didnt already find

#

it wont exploit it for you, only tell you its there, and youve already seen its there

#

spend another 30 minutes reading on sudoers and then 30 minutes on gtfobins. Or an hour each. It aint a race.

rustic sage
#

To enumerate possible PrivEsc

#

But I guess I already found it with sudo -l command

#

like madf0x said

fathom pendant
#

You were given the nudge where to look

thorn urchin
#

have you googled sudoers yet?

#

By all means if you have and are struggling with it, share what youve gathered so far and what part youre having issues with.

#

understand how sudoers work and then you can move on to the next step

fathom pendant
#

I think some of this may get to spoilers because tbh the answer is the spoiler

#

Sudoers isn't necessary but a good read

thorn urchin
#

its fundemental to understand what sudo -l is showing you and how to read the format

#

as sudoers is how you configure it in the first place

rustic sage
#

oh

thorn urchin
#

ergo understanding sudoers will show you why thats bad, and the first stage of how to exploit it. The second stage of exploiting it will come from looking into gtfobins. But gotta nail the first stage in understanding before the second makes any sense.

#

cause the gtfobins part wont make any sense to you at all until you know the first part, as it already assumes you understand how dangerous privileges work. Of which sudoers is just one example of a possible permission misconfiguration

rustic sage
graceful rampart
rustic sage
graceful rampart
#

yes and what is sudo?

rustic sage
#

In my case, I was able to run it as Super User or sudo

#

right?

graceful rampart
#

so what does that mean? You can run php as root

rustic sage
#

So I leveraged that and put sh shell into CMD variable

atomic ruin
#

Hey, I think I'm facing some dumb config issue. Trying to finish the "Getting Started" module, "Knowledge check". I can port scan the target, find some folders in it, navigate those, and already found a set of credentials, but can't actually browse to the page at all. In nibbles I managed to solve this by adding the domain in my /etc/hosts but that doesn't seem to be working in this case? Any help?

graceful rampart
rustic sage
graceful rampart
#

Exactly

rustic sage
graceful rampart
#

np

thorn urchin
#

yeah so fun tidbit to rememberany programming language interpreter if you can run as root means you can escalate as root

#

without exception

graceful rampart
#

In the future, regardless of where you may find a command, you should never execute any command unless fully understand what it does

rustic sage
rustic sage
#

in web browser

atomic ruin
#

yep, that's what I was doing. Folders load fine, it's just the main page. I think it's just super suuuuper slow, left it loading in a separate tab and it loaded now, after some 20min

rustic sage
#

so it could load things faster

atomic ruin
#

It's already the closest. Don't think it's anything VPN/network related because everything else is loading fine. I can curl files just fine, it's just when trying to browse to the page

simple zephyr
#

not sure if its just the bind shell module, but anyone else having issues with boxes losing connecting. i literally get not response from the box after its been up for about a minute.

vocal vortex
#

Hello all,
Im currently doing Attacking common services module, section Attacking SQL Databases.
I have reached the last question which basically state to enumerate database flagDB, i have already the credentials for user mssqlsvc but no idea how to actually use.
I have tried to login using that user and password and domain but i just get failed login.
Could anyone who already did the module drop a small hint. Thanks in advance.

Update: Resolved.

atomic ruin
#

Think I got it. It timeouts waiting for ajax.googleapis.com every single request. Sink that in /etc/hosts and it now works just fine

pearl flint
#

Hi. I need a little push for this question here : Getting Started > Web Enumeration > Try running some of the web enumeration techniques you learned in this section on the server above, and use the info you get to get the flag?

#

I've tried multiple things

#

but I cant find the answer

#

I tried gobuster, cURL, whatweb, checked the robots.txt, checked the page source of the index.php, robots.txt and the wordpress page.

heady siren
#

Any god hacker around?

thorn urchin
heady siren
#

Lol

thorn urchin
#

ftr this channel is for HTB Academy discussion. If youre not here to discuss that, find somewhere else.

Also read the server rules, literally everyone that asks something like what you asked winds up breaking the rules and risking a ban.

devout cliff
#

can anyone help me with a question in the footprinting module - easy lab? for some reason it wont let me ||wget the contents to complete the rest of the lab||. i figured out how to get that to work but ||dont understand why it was hiding the files from me after i downloaded them?||

drifting glacier
#

For host 1 on the live engagement in the shells and payloads section, the application returns a server error when attempting to active the war file reverse shell, is this host bugged?

fathom pendant
fathom pendant
#

You're supposed to use the tools from that module to enumerate the information

atomic ruin
fathom pendant
#

Nah

#

I mean yeah sometimes the boxes are buggy

devout cliff
simple zephyr
#

I don't know what I am missing on this question, but in Shells & Payloads - Automating payloads & Delivery with Metasploit, What command language interpreter is used to establish a system shell session with the target?

I tried everything that I thought it could be and I get nothing

hollow thunder
#

DomainPAsswordSpray.ps1 giving me issues

#

i want to punch it

fathom pendant
devout cliff
pearl flint
thorn urchin
#

ssh only accepts keys with correct perms set on it

devout cliff
thorn urchin
#

thats wrong

devout cliff
#

ok whats right

#

does the module tell you

thorn urchin
#

google ssh key perms

#

iirc it does

devout cliff
#

when i did that it told me 644

#

so i set it to 644

#

is it 600 instead?

thorn urchin
#

if you did google youd see people saying they were having errors with 644, not use 644

#

600 yeah

devout cliff
#

also the module in the section talking about ssh does not mention changing permissions to make it work

thorn urchin
#

644 is fine for pub keys, not priv keys

devout cliff
#

i know you need to but thats frustrating

thorn urchin
#

Thought the module did mention it, but even if it doesnt it very frequently by design throws you stuff you need to look up on your own

#

priv keys being 600 perm to work is also something most would consider a linux fundementals

devout cliff
#

i knew about the chmod, but my problem is that even with EITHER 600 or 644 it is not working

thorn urchin
#

you got the right key?

devout cliff
#

id_rsa

#

from the ftp server

thorn urchin
#

and how are you using it?

devout cliff
#

ssh ||-i KEYHERE ceil@IPHERE||

thorn urchin
#

and what does it give?

devout cliff
#

nothing, it hangs and then closes the connection

thorn urchin
#

thats not a sshkey issue then, thats a connection issue

devout cliff
#

ok im resetting the box

thorn urchin
#

if something was wrong with the key itd have given you a permissions error or a login failure

devout cliff
#

i got it

#

my vpn was messing with it

thorn urchin
#

if its any consolation you were going to run into the perm issue regardless, so at least you got that cleared up too

plucky current
severe quarry
#

hello guys,i have a question how can i know exactly if i have connected to the vpn, e.g in windows can i see it but i don't know kali exactly is there an exact command or something?(openvpn)

plucky current
severe quarry
plucky current
#

If you are connected to the HTB servers, then you shouldn't have any issues with SSH, as long as you are trying to SSH into a valid (and active) HTB server (box) and have valid SSH credentials for that server/box.

fathom pendant
#

^

tardy yew
#

Can anyone help with a question on Intro to Networking?

fathom pendant
#

Just ask the question don't need to ask to ask.

#

If someone knows they know, and can nudge you, if not then oh well

#

But it helps to just ask

lethal latch
#

Has anyone completed the skill assessment for using crackmapexec? I'm struggling a bit with question 3.

fathom pendant
#

Ask questions better: what have you done, what is troubling you, what is the error you're getting. Or what is the unexpected results you're seeing. It doesn't help to be kinda vague...

hazy grotto
#

Can anyone tell me how i can grab this file?

#

I used a pass the hash with mimicats to get in here. I'm currently in system 32\ need to connect to the shared drive and grab david.txt

floral bone
#

Have you tried using net share to see if it's connected / mapped? Just my suggestion, if I'm wrong - let me know!

floral bone
hazy grotto
#

──(ruderaph㉿kali)-[~]
└─$ smbclient -U david \\10.129.148.2\david
Password for [WORKGROUP\david]:
session setup failed: NT_STATUS_LOGON_FAILURE

floral bone
rustic sage
# hazy grotto

Just do type Dave.txt no need for extra die info ur already in it

fathom pendant
mortal basin
#

Glad you found the module useful. As for CMM, I've used many MacOS software over the past 15 years, and it truely is a software that deserves to be on the recommended list. It bundles a lot of features of many other applications, so it may be the only software you need for a bunch of things, which is why we recommended it, mainly based on personal experience. Give it a shot and don't go by what others say without trying it.
Another useful application that comes to mind is iStatMenus, but CMM also has a built in system monitor, though not as detailed.

thorn urchin
#

CMM is basically junkware.

#

I literally get paid to remove it at work for customers

mortal basin
thorn urchin
#

you think thats it 😬

#

might wanna check over your launch daemons and other junk that doesnt get removed

wheat garden
#

yes security but not privacy. At least not from apple. They can monitor everything on your device collecting data making profiles.

mortal basin
thorn urchin
#

if you believe so

#

I have some other tools I use as part of my toolbox to make sure I clean out unwanted apps and the likes for customers. Can never trust built in uninstallers. Some can be fine, many arent. Not worth the time to sort out which is which

#

and ftr Ive been in the repair industry for about 8 years now and been pretty involved with the repair community at large. CMM has a terrible reputation

mortal basin
#

Other than the reputation, if there's any evidence of wrong doing or adware etc then we'll remove the recommendation from the module..

#

Also please feel free to suggest macOS apps you find useful.. we wanted to build a list of apps to get users going who are new to macOS

thorn urchin
#

Other people will claim its adware but I dont go that far. Its just junkware. It gives the illusion that its doing helpful things when really, what is actually doing thats a tangible benefit? Its smoke and vapors to talk up a good enough game to sucker people into paying for it when theres no need.

wheat garden
hazy grotto
sonic wyvern
#

When you're doing ffuf / fuzz

  1. is it taking bandwidth from the server?
  2. If I have monitors on the server can I see the actions?
#

Any way to block fuzzing?

#

Another question, why when I run fuzzing on my own server I get nothing?

#

ffuf -w list.txt:FUZZ -u my-domain.com/FUZZ

#

Yes, no results

#

I tried this code

#

also I need to mention that it's an app that running on port 3000

#

mm.. let's say I have the contact keyword

proud pine
sonic wyvern
#

Ok, it's probably something, idk
But if you already here maybe you can help me with the fuzzing params lesson.

I'm trying to run this
ffuf -w params.txt:FUZZ -u http://admin.academy.htb:30421/admin/admin.php?FUZZ=key -ic

lethal schooner
#

@wheat garden that guy seems unhinged

sonic wyvern
#

from this module I'm not sure if I need to put in the -u admin.academy.htb or the ip address

#
  1. I don't know why everytime I'm fuzzing, I'm getting
#

: Progress: [1555/2588] :: Job [1/1] :: 1814 req/sec :: Duration: [0:00:02] :: Progress: [1959/2588] :: Job [1/1] :: 5087 req/sec :: Duration: [0:00:02] :: Progress: [1959/2588] :: Job [1/1] :: 5087 req/sec :: Duration: [0:00:03] :: Progress: [1959/2588] :: Job [1/1] :: 5087 req/sec :: Duration: [0:00:03] :: Progress: [1959/2588] :: Job [1/1] :: 5087 req/sec :: Duration: [0:00:03] :: Progress: [1959/2588] :: Job [1/1] :: 5087 req/sec :: Duration: [0:00:03] :: Progress: [1959/2588] :: Job [1/1] :: 5087 req/sec :: Duration: [0:00:03] :: Progress: [2354/2588] :: Job [1/1] :: 6913 req/sec :: Duration: [0:00:03]

wheat garden
lethal schooner
#

@wheat garden I can't when he's yelling into the microphone

proud pine
wheat garden
sonic wyvern
#

I need help with this Parameter Fuzzing - GET fuzzing, I'm not sure if I need to use this extra location /admin/admin.php

lethal schooner
#

I am beautiful

proud pine
#

Really not useful or appropriate.

wheat garden
lethal schooner
#

As soon as I hear globalist satanic elites I turn it off

wheat garden
lethal schooner
#

@wheat garden let's stick to the module exercises

proud pine
#

This is not the place to push conspiracy theories. This is a chat about modules.

wheat garden
#

only make conditions worse in the long run

lime frigate
#

I found a download interface that does not require authentication, but I only know a certain file name and cannot download other unknown file names. Is blasting the best option

thorn urchin
sonic wyvern
#

@thorn urchin Do you know why when I try to ffuf I get nothing?
I'm on the Value Fuzzing

I'm trying
ffuf -w params.txt:FUZZ -u http://admin.academy.htb:32348/admin/admin.php -X POST -d 'FUZZ=key' -H 'Content-Type: application/x-www-form-urlencoded'

thorn urchin
sonic wyvern
#

Everytime I Fuzz I get many lines like that
:: Progress: [35/2588] :: Job [1/1] :: 0 req/sec :: Duration: [0:00:00] :: Er.....

thorn urchin
#

the many lines is cause the terminal width is too short, maximize your terminal

#

itll make the progress status cleaner to read as well as any results

#

0 req/sec would suggest its not finding a path to the host though

wheat garden
sonic wyvern
#

yes.. but those lines not telling me anything about the result

#

it's not finding any keywords

#

so I assume I'm doing something wrong

thorn urchin
thorn urchin
sonic wyvern
#

What's the location of this log?

thorn urchin
#

idr, google ffuf log location

wheat garden
thorn urchin
#

you're going off topic by a landslide

#

and arguing about it instead of taking the L

wheat garden
thorn urchin
#

I literally have not watched the video and couldnt care less.

#

it just has no basis belonging in this channel whatsoever

#

move on

wheat garden
#

then you disrespected me telling me to shut up

thorn urchin
#

Yes, because you have actively earned less respect

#

Now Im done discussing it further, if you got a module question to ask then ill listen, otherwise ill just start pinging mods.

sonic wyvern
#

I logged a report to HTML, I got html file and in it Showing 0 to 0 of 0 entries

wheat garden
thorn urchin
#

not logging a report, you need to read the error log, its different

wheat garden
#

If you directly reply to me im going to respond most likely.

sonic wyvern
#

@thorn urchin are you talking about debug-log or something else?

#

I have a feeling it's because I need to spawn the server again

#

ok, I just didn't understand the -fs part which is weird

#

for example, I get many results like
adminpwd [Status: 200, Size: 798, Words: 227, Lines: 54, Duration: 0ms]

#

now why do I need to do -fs 798
to get the desired results?

I assume if I filter by this number I should get the same list.. because they all have 798.
So how come it's filtering it, and we're getting only 2 results?

proud pine
sonic wyvern
#

oh it's filtering out?

proud pine
#

Yeah, -fs will stop showing you any entry with a size that matches the value you give it.

sonic wyvern
#

Got it, I thought it's the opposite, I thought it's selecting only the 798

proud pine
#

So they key is to run the fuzz for a second or two, to determine what the 'false' size is.

#

Then cancel it, and start it again with a filter in place.

sonic wyvern
#

the key is just to narrow down the big list

#

so you see bunch of 798.. so you start with that

proud pine
#

Correct.

sonic wyvern
#

Yeah, ok let's see if I can solve the curl thing, the next step

#

Thanks

sonic wyvern
#

Do you know maybe what is the syntax if I want to use ffuf with regex?
I tried to add -mr "\w\.\w"

#

but it's not filtering by that regex

hollow thunder
#

AD assessment 2 nudge?

#

" Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host."

proud pine
tiny parrot
#

Hey how y'all doing? I need a little bit help with a question. The question is Create an "If-Else" condition in the "For"-Loop of the "Exercise Script" that prints you the number of characters of the 35th generated value of the variable "var". Submit the number as the answer. The bash script I wrote is:
#!/bin/bash

Count number of characters in a variable:

echo $variable | wc -c

Variable to encode

var="nef892na9s1p9asn2aJs71nIsm"

printf '=%.0s' {1..35}

var=$(echo "$var" | base64)

if true; then

echo "Given argument is greater than 10."

fi

done

Please let me know. If you can please. Thank you

hollow thunder
#

Can I dm you

proud pine
#

sure

fathom pendant
tiny parrot
#

Yes u can dm me

#

Not sure what you mean

fathom pendant
#

"if true" is just an infinite loop

tiny parrot
#

O okay make sense

gaunt zodiac
#

I have a question related to coding

#

I wanna download a game however I am not sure if its a virus so what should I do?

fathom pendant
fathom pendant
tiny parrot
#

Thank you MarcieLee appreciate it

gaunt zodiac
fathom pendant
gaunt zodiac
#

I did that but It's just totaling the link

#

Can you scan a file you haven't downloaded

#

Sorry if I am confusing

fathom pendant
#

What's the source?

#

... BAHAHA no don't download

gaunt zodiac
#

Whats wrong with it?

fathom pendant
gaunt zodiac
#

Yeah what is wrong with the site?

#

Is it malicious?

fathom pendant
#

"who claim to have scanned them"

gaunt zodiac
#

Hm

candid zephyr
gaunt zodiac
#

Can you virus total it?

gaunt zodiac
fathom pendant
#

Virustotal is free to use bro

candid zephyr
gaunt zodiac
gaunt zodiac
#

Coming back for the nostalgia

fathom pendant
#

Download the exe yourself and submit it

#

It can't do anything unless you run it

gaunt zodiac
#

What if it destroys my pc tho immediatly after downloading it?

#

True

#

I don't wanna mess up my PC

#

Does anyone got a VM?

fathom pendant
#

Also recommended to visit the site thru a vpn

#

VirtualBox is free brother

candid zephyr
#

Oh weird. Just yolo run it. Tell us how it went.

gaunt zodiac
#

I know

#

I'm trying to save PC storage though

#

Aren't VM's large files?

fathom pendant
#

And you're downloading a game

gaunt zodiac
#

Trying to avoid clogging up my PC lol

fathom pendant
#

So

gaunt zodiac
#

I mean true but any space helps-

candid zephyr
#

When I was a kid on the internet everything was a virus.

fathom pendant
#

Listen

#

This isn't even the right place for this anyway;

gaunt zodiac
#

I know

#

Where is the right place?

fathom pendant
#

Not this discord

gaunt zodiac
#

Can you refer me to a server that would help*

fathom pendant
#

Nope

#

Don't know a server that would

gaunt zodiac
#

Hmph okay should I download the EXE?

fathom pendant
#

Without being a complete dick about it to you

gaunt zodiac
#

Ok so basically

#

Can downloading an EXE

#

Destroy your PC?

#

Or you must run it first?

proud pine
#

Wait wait, you're asking if an illegal file that you want to download might be a virus?

gaunt zodiac
#

Are you good with legal stuff

#

Is downloading a game that went bankrupt or well

#

From a company that went bankrupt*

#

illegal

fathom pendant
#

It's still a pirated version

gaunt zodiac
#

True so

#

Is it illegal to play

#

If you just play them for yourself

fathom pendant
#

Eh

gaunt zodiac
#

I wanna make sure

#

I mean TBH I owned it legit a few years ago :/

fathom pendant
#

No one enforces DRM but you're not seeing the point kid. We are not going to do the work for you.

gaunt zodiac
#

I know

#

Kinda thought you would know

#

Just searched up in the server directory

fathom pendant
#

Can't know without actually looking at the file

gaunt zodiac
#

Ok

#

So can I download it without it harming my PC?

#

Because its a .exe

fathom pendant
#

It's a zip file

#

Not an exe

gaunt zodiac
#

Oh yeah

#

Oh so just downloading it could harm your pc...

fathom pendant
#

No

proud pine
#

This discussion doesn't belong here, or anywhere. Take it elsewhere.

gaunt zodiac
#

Sorry just trying to find advice

#

Your the first server I could find

fathom pendant
#

Listen, if windows or any av detects it when you download it then it's bad

gaunt zodiac
#

Came here for advice

#

Yeah true

#

So should I just yolo it?

fathom pendant
#

If it doesn't then you roll the dice

gaunt zodiac
#

Alright so Ill end it here

#

Is it worth the risk?

fathom pendant
#

I advise creating a restore point (Google is your friend)

#

Fucking go do it and stop beating around the bush

gaunt zodiac
#

I know

#

Thats legit my last question

novel matrix
#

Can we please keep this channel on topic

gaunt zodiac
#

Do the risks outweigh the benefits?

novel matrix
#

This can be taken to DM or community help section

fathom pendant
gaunt zodiac
#

Sorry for making it off-topic, this is the only channel I could find

#

Who can I DM for help

novel matrix
gaunt zodiac
#

And ill be on my way

#

Ok Tysm

vocal vortex
#

still need help with that ?

feral willow
#

Hi, i'm trying to solve the section "ZAP Scanner" in the module "Using Web Proxies". Task is to run a ZAP Scanner on a target to identify directories and potential vulnerabilities. "Once you find the high-level vulnerability, try to use it to read the flag at /flag.txt" . Problem is, that ZAP only comes up with medium and low level vulns, when i scan the given target. i dont know what i'm missing out. EDIT: got the flag manually

feral stump
#

anyone can give me nudge on the The Live Engagement of Shells & Payloads? thx

#

related to the blog exploitation question

heady hamlet
#

I am working on the NETWORK ENUMERATION WITH NMAP module The Service Enumeration section I am trying to get all the ports but I have tried about everything but I am still only getting the same 7 ports. Can someone assist me with that?

feral stump
heady hamlet
#

Enumerate all ports and their services. One of the services contains the flag you have to submit as the answer.

feral stump
#

can you dm your command?

heady hamlet
#

from the exercise: sudo nmap 10.129.2.28 -p- -sV -Pn -n --disable-arp-ping --packet-trace and it throws out a ton of info that isn't really needed.

feral stump
#

try ||sudo nmap -sS -sV -Pn -p- <ip>||

heady hamlet
#

copy

potent wyvern
#

I am stuck on the final assessment of the File Upload Attack, anyone can help?

rustic sage
#

Hi there,
I started with the "JobRolePath" Penetration Tester.
There is a section called "ServiceScanning". To perform some nmap scans as shown in the description / or answer the questions at the end /
Which VPN connection is necessary to reach out the host "10.129.42.253" ?

high totem
rustic sage
#

thank you, but it doesn't work. (EU Academy1 & 2)
the VPN connection seems to be ok, but the host does not reachable (10.129.42.253)
what can i do to troubleshoot this issue?

placid quest
#

@rustic sage try to use ping

rustic sage
placid quest
#

@rustic sage change the vpn server

rustic sage
#

already done, is the same

placid quest
#

@rustic sage what vpn server are u using

rustic sage
#

can someone get my fortnite account back i got hacked please😭

#

i got the info of the guy who hacked me plesae

rustic sage
placid quest
#

@rustic sage ok

rustic sage
#

If I'm using the htb original vpn are the boxes (not Academy) available, so I think that could be an Issue of the Academy Network?

placid quest
#

@rustic sage if u are connected to the wrong vpn server it will not work

rustic sage
keen pike
iron plaza
#

Been trying to solve the Attacking LSASS section in Password Attacks and pwnbox rdp keeps crashing and the virtual box show this transfer error:

#

Safe to assume HTB has issues?

oak sequoia
#

Hi! Any tip to solve Skill Assessment nº9 of Introduction to Windows Command Line?

#

"Use the tasklist command to print the started services and then sort them in reverse order by name. The fourth service is the flag for this user."

iron plaza
spare condor
#

@covert vault Can I DM you regarding the last question of Pass the Ticket (PtT) from Linux?

fathom pendant
fathom pendant
sleek elbow
pastel gale
placid quest
#

@sleek elbow what is the problem

pastel gale
#

@sleek elbow what wordlist are you using with gobuster also what output are you getting please share a ss

sleek elbow
devout cliff
#

can anyone help me with the footprinting medium lab? i am hardstuck after i get access via RDP

placid quest
#

@devout cliff ok how are u stuck

devout cliff
placid quest
#

@devout cliff maybe try administrator has the username

devout cliff
#

isnt working

#

ive tried ||sa, alex, admin, administrator, Administrator, Admin|| for the usernames

lethal schooner
#

@devout cliff Maybe you have the right info for the user/pass, but you're missing a flag with the command

devout cliff
#

@lethal schooner im using the program MSSQL SMS not a terminal

lethal schooner
#

Everything that you need is in the module if I recall correctly

rustic sage
#

In Attacking Common Services // Attacking SQL Databases, i got the password of the mssqlsvc user but login doesn't work with mssqlclient.py. Any idea what i should do?

pearl flint
lethal schooner
#

Try using sqsh

devout cliff
lethal schooner
#

@devout cliff What exercise are you on

devout cliff
#

footprinting

lethal schooner
#

Have you checked all the services like nfs?

fathom pendant
# devout cliff isnt working

The medium one is a bit of a pain: but here's a hint. You have the credentials you need. And take a look at the protocols being used

#

Unless you didn't read the medium fully

graceful parrot
#

#Module: Attacking Common Services
#Sections: Attacking SQL Databases

I need help, I find the hash, decode it and get the password.
Then I use ||rdesktop -u mssqlsvc -p mypassXXXXX 10.129.177.184|| and it appears that remote access has been removed.

Someone tell me if I'm on the right track or am I missing something?

fathom pendant
#

It tells you something that isn't obvious on a scan

graceful parrot
rustic sage
vital adder
#

hint the first user isn't a domain user (i think)

graceful parrot
placid quest
#

@fathom pendant not rdp but mssql

vital adder
vital adder
graceful parrot
stuck hull
devout cliff
spare condor
#

Can I DM someone regarding the last question of the Password Attacks / Pass the Ticket (PtT) from Linux??

stuck hull
#

So you have access to the RDP with alexs' credentials? Enumerate his windows machine a bit.

graceful parrot
vital adder
#

yes but i don't know what's the domain syntax for that tool i only got the syntax save for sqsh in my note

devout cliff
stuck hull
lethal schooner
#

@vital adder The domain syntax is documented in the module

vital adder
#

oh nice good to know

devout cliff
#

i hated every second of that LOL

hearty oak
#

hi guys whats up?

graceful parrot
vital adder
#

that doesn't look like the right domain but sure give me a sec let me give that a check

vital adder
graceful parrot
#

thank you, now i managed to connect, you are the best 👏

vital adder
hearty oak
#

hey guys!
I have a question...: is it possible to hack the administrator in win10?
Thanks in advance!
(sorry for the spelling mistake! 😐 google is just like that!)

spare condor
# fathom pendant just ask the question here

The question says "Use the LINUX01$ Kerberos ticket to read the flag found in \\DC01\linux01. [..]". The LINUX01$ Kerberos ticket is the ||/etc/krb5.keytab||, right? I used this to export it in the KRB5CCNAME variable and then tried to read the contents in \\DC01\linux01 but can't access it..

fathom pendant
#

I don't know that one I just meant don't ask to ask; just ASK lol and someone may be able to nudge in the right direction

hearty oak
#

hey guys!
I have a question...: is it possible to hack the administrator in win10?
Thanks in advance!
(sorry for the spelling mistake! 😐 google is just like that!)

spare condor
vital adder
#

nope you can't use the root username for this

rustic sage
#

I'm having difficulty understand the Default Password section under the Password attacks module. I have the credentials from the user in the last section and I know how to brute force the MySQL service. I made a file called user_pass.list where I separated the credentials by a colon. Am I suppose to manipulate this file with rules? What does this have to do with default credentials.

vital adder
#

hint the cred ||is in one of the link||

rustic sage
#

I don't understand? What link?

vital adder
#

the link show in that section

spare condor
vital adder
#

oh you can do that? i didn't even know that

#

but i think this is a domain user on a another domain or something that's why you can't use root for this

rustic sage
#

So all I have to do is use MySQL default credentials? What does that have to do with the user from the last section in password manipulation? I'm confused.

vital adder
#

yep and nope you don't need that user at all

rustic sage
#

Why does it say than to use those credentials? Okay well I have the default user for MySQL I suppose now I have to add root:password, and somehow just manipulate the password part?

vital adder
#

oh wait the question did ask that 🤣 i think this is just another case of thb being evil

rustic sage
#

lol... am I on the right track? Do you know how I would just manipulate the password part of root:password

vital adder
rustic sage
#

Okay sounds good.

spare condor
vital adder
#

yep

rustic sage
# vital adder yep

I used all the default credentials for MySQL, they did not work? Am I overthinking this?

#

The wording of the question has confused me. I can't understand what it wants me to do.

#

Nevermind solution solved, I was actually trying to login to MySQL which did not work but the answer did for HTB.

graceful rampart
#

You should be able to log in to MySQL

#

How were you trying to log it?

#

(Take the username and password out if the command. Don't want to spoil it for others in here)

spare condor
tired wyvern
#

Hi guys new to this discord… I have a question… In the Windows Fundamentals Mod do you have to do the mods all in one sitting? Because when I go back to it like “File System “ #3 the xfreerdp from Parrot to windows isn’t working. I’m starting to bang my head.

vital adder
minor pelican
vital adder
minor pelican
#

i cant say for sure since im still taking notes for the beginning but i assume the boxes are reset if youre gone for too long

spare condor
minor pelican
#

But no you do not need to spend your time completing a whole module in one sitting

vital adder
vital adder
graceful rampart
minor pelican
spare condor
tired wyvern
graceful rampart
spare condor
#

I tried and got the same error (don't want to spam with screenshots)

tired wyvern
vital adder
vital adder
tired wyvern
vital adder
#

so linux?

stuck hull
#

Have you tried Reminna?

tired wyvern
stuck hull
#

Yup

tired wyvern
stuck hull
#

I was struggling with xfreerdp on the footprinting module but Reminna worked

#

It comes pre-installed on ParrotOS

tired wyvern
#

I just thought that maybe I didn’t do the mod all in one sitting was the prob.

tired wyvern
hearty oak
#

Hi guys! I have a question: how to hack a win10 administrator?

thorn urchin
#

cause youre in the modules channel so surely this is about s module youre doing

hearty oak
#

I'm sorry, I didn't know, I'm right there... I just thought this was a simple joke

pastel gale
#

??

gaunt wren
#

any one know how to reach ... HTB support to stop a machine , because i am not able to connect by vpn suddenly... please help

broken warren
#

What list are we supposed to use for the Footprinting module > DNS section. I'm on the last question asking for FQDN of xx.xx.xx.203 Ive tried all three subdomain-top1million lists and the namelist in SecLists DNS section.

raw compass
#

i want to learn hacking ( professional ) and i am intermediate level rn in this field, i want to learn it (not just scripting) but actual technical stuff of hacking, can you guys suggest me some course online (FREE)

devout cliff
#

because a couple of them should work

#

oh i see what is happening actually, expand your lists a bit

#

you are on the right track but try a different list outside of the ones you tried in that section

broken warren
# devout cliff what command are you running

Ive run both shown in the exercise u(dnsenum and the bash one liner) using the subdomain-top1million-5000.txt and only got three entries I'm currently doing the subdomain-top1million-110000.txt but I'm assuming it won't work since the hint says to try another wordlist.

devout cliff
#

yeah try some of the others that are in Seclists DNS section

broken warren
graceful rampart
#

God i hate this password attacks module so much. Every exercise feels like a full lab lmao

#

At least the labs will hopefully be fun

dawn forge
#

Hello guys just finished Command Injection, and met some strange behavior with file manager(skills assessment), at first visiting the web app it was not fully rendered. Is it ok for htb labs or it was a part of task?

vital adder
vital adder
#

also it's docker container so it's going to took like 2 sec

dawn forge
pastel gale
#

Using David's hash, perform a Pass the Hash attack to connect to the shared folder \DC01\david and read the file david.txt.

#

Module pass the hash
i have the ntlm hash but all the tools cme smbclient etc throw some error

#

am i missing something

#

||tree connect failed: NT_STATUS_BAD_NETWORK_NAME||

gentle swift
#

Yello, someone got a coupon code for academy and cares to share? fingerguns

vital adder
vital adder
pastel gale
#

AHH I ran privilege::debug

#

not token :: elevate

#

it wasnt there in the tutorial

vital adder
graceful rampart
vital adder
vital adder
graceful rampart
pastel gale
#

but i need to access an smb share

vital adder
graceful rampart
#

Yea but the SMB share isnt on your machine. Running as system gives you full control over the current machine, not a remote machine

pastel gale
#

cant i directly use a tool to pth from my linux machine to access the share rather than using mimikatz

#

||smbclient -U David \\10.129.229.59\DC01\david --pw-nt-hash <hash> -W inlanefreight.htb||

#

i am using this

graceful rampart
pastel gale
#

yep

graceful rampart
#

which question?

pastel gale
#

tree connect failed: NT_STATUS_BAD_NETWORK_NAME

#

getting this error

#

Using David's hash, perform a Pass the Hash attack to connect to the shared folder \DC01\david and read the file david.txt.

graceful rampart
#

oh thats cuz you cant interact with the DC from your kali machine

#

its on a different network'

#

you have to rdp into the windows machine and do it form there

pastel gale
#

oh makes sense now

gentle swift
#

You're learning through academy and having hard time? Or through the main HTB site?

graceful rampart
#

easiest way is with mimikatz or rubeus

pastel gale
#

i got a cmd.exe running with mimikatz but how do i access a share from there

graceful rampart
pastel gale
#

yes

vital adder
#

if you are new and want something easy to started with go for tryhackme

graceful rampart
# pastel gale yes

|| type \\dc01\david\david.txt || or you can mount the smb share with something like || net use n: \\dc01\david ||. Then you could do || cd n: || and access the share that way

pastel gale
graceful rampart
graceful rampart
#

np

vital adder
#

if you still got 1 year until your exam voucher expired but you are still new to this i would recommend give tryhackme a try learn the basic for a few week or even months if you need to then come back to the academy and continued the pentester path for the exam

graceful rampart
#

Because you dont have access to the entire host. You only have access to one single port. nmap will attempt host discover (yes even if yopu supply the -Pn flag, it just does it without ICMP packets)

#

yea. You have to specify the specifc port. Nice

#

What module are you working on?

#

There you go. Do you know why -A works? Do you understand what it does?

#

no

#

-A includes the options for -sC -sV and -O

#

I like to remember -A as 'All'

#

Cuz it just runs everything

#

np

normal lagoon
#

Anybody complete the CrackMapExec module. Currently stuck on the skills assessment. Very difficult to get the first flag. I'm probably missing one little detail.

pastel gale
graceful rampart
thorn urchin
#

-A is just shorthand for a bunch of different aggressive flags

onyx pelican
#

I'm on Module 88, Section 934. The question is asking.

# Question2

x_coordinate = (42,)

# What type is `x_coordinate`?

This answer should be ||tuple||, but the UI is saying that is incorrect.

pastel gale
#

i had a general doubt at what point in the pentesters path should i be able to tackle atleast a few easy or medium boxes?

fathom pendant
#

Once you get your footing with the tools, you should be good. The only real thing is reading the box description to see if it's stuff you know/just learned so that way you're not diving into uncharted territory. But Uncle Google is always a friend if you know how to ask

thorn urchin
#

the pentester path and doing boxes is not like a 1 to 1 match, its tough to really compare em

broken warren
#

Something is wrong with the timer for the target spawn at least for me on the Footprinting lab > DNS section. I'm running dnsenum and have the questions open in that background so I can see the target through my terminal. And I literally have watched it count down 3 minutes but on my watch it's only been a minute. I respawned one like 15 minutes ago it said I had 90 minutes left I'm already at 32. Also Ive organized seclists DNS wordlists smallest to largest and have tried 6 of the 14 and still haven't come up with anything, and the box is just timing out before I can even finish the larger lists. It's now saying I have 11 minutes lefts so 32 to 11 in 6 minutes

thorn urchin
#

the course is structured and has sequences of stuff to learn. Doing a box needs some specific domains and runs the whole gamut from enumeration to priv escalation. Theres also some common box attacks that arent covered by the course at all, but you need to be prepared to get yourself up to speed quickly on if you wanna do that box.

#

basically its too much of a case by case basis to say any broad strokes of if youre X% done you should be able to tackle Y ranked boxes

#

after all look at this very channel, youve got light green peeps struggling in some sections getting advice from blue and green names. It doesn't translate like that lol

onyx pelican
fathom pendant
graceful rampart
#

Anyone around for a sanity check on the password attacks labs? Not looking for the answer, just wanna make sure im not about to waste my time trying the wrong thing

onyx pelican
# fathom pendant This is considered spoiling

I apologize for spoiling any of the content. This particular question I have issues with though. Is there a more appropriate place to submit such feedback? The website basically points me to the Discord server.

graceful rampart
#

Bro this la is gonna make me cry lol. 1410 out of 21122 attempts. F me

fathom pendant
#

^

lethal schooner
#

I think It took me around 69 mins

graceful rampart
#

I hate this module so much

lethal schooner
#

Yeah it's the worst one

#

so far anyway

graceful rampart
#

😭

lethal schooner
#

I would run my attacks, then leave for a bit. Maybe run some errands or something .

lethal schooner
#

You don't have to ask to dm lol

fathom pendant
#

You can substitute things like <my answer> and <their answer> just in case someone that's stuck on the same thing clicks your spoiler tag and then just gets the answer

graceful rampart
proud pine
lethal schooner
#

I guessed I missed that one

thorn urchin
#

yeah its a rule lol

simple zephyr
#

i am on Shells and Payloads doing the live Engagement. Is it just me or is the box that we RDP into stuck at a resolution that is a pain to work in.

feral stump
#

It worked for me yesterday and today

#

it is a bit of a pain

#

you can also try pivoting as somebody suggested me

#

and use Kali

#

or Parrot VMs

#

whatever you have installed

warm dagger
#

in the "Linux Local Privilege Escalation - Skills Assessment" anyone find the shell w/o ssh with the creds provided?

pastel gale
#

It's literally pathetic

simple zephyr
#

i was able to resize it with /size: 1920x1080 and its much more usable

pastel gale
#

For me it was the speed that was slow asf

#

Like dragging a firefox from one end to another was like moving a window in a windows Vista with 2gb Ram 💀

simple zephyr
#

yeah, lol i am stuck on host 1 and i have done this exploit 1000 times before too.

#

i think i figured it out.... lol

pastel gale
#

I was stuck on this module for so long...
Just to realize i fucked up something so simple

simple zephyr
#

probably the same thing I did too lol stupid simple

pastel gale
#

Was it related to host?

simple zephyr
#

if you mean the host as in the machine I am accessing then yes.

drifting path
#

hello i need help from someone proficient in computers.

granite estuary
#

hi

crude wharf
#

Hi guys

dull moth
#

anyone facing slow issues on pwnbox academy?

fathom pendant
olive bramble
#

I'm working on the final Nmap section (Firewall and IDS/IPS Evasion - Hard Lab). I tried specifying various source ports to bypass the firewall (21, 137, 445, 53). I also tried specifying a different ethernet interface to approach it from an "external" view. Does anyone have any tips or nudges?

#

I did find 137 available via UDP

#

I tried the ACK scan. I didn't see any benefits from it.

fervent crane
#

Hi all, so I'm stuck on the XSS module, Phishing section. I'm getting the dreaded "Issue in sending URL!" message when submitting my URL. When I test the URL, it works perfectly from credential capture to getting picked up by the PHP server and forwarding back to the original page...and yet the "send.php" page keeps kicking it back. I've been at this one issue all day and my brain has officially melted. So any assistance would be super appreciated.

proud pine
#

So you can just resize as necessary, on the fly.

sly tapir
graceful rampart
#

Password Attacks

harsh badger
#

I'm almost done with the Metasploit module and I got to say I never took MSF seriously until I read through it here, very interesting and useful for organizing data
Is it going to be part of the exam or more of a general must-know?

hazy grotto
graceful rampart
#

Nice. I'm in the middle of the hard lab. Stopped to eat some food

#

The easy lab was a load of bs. Half an hour of waiting to bruteforce a pssword

hazy grotto
#

How many hours a day do you spend? I've been putting in about 4.. Still takes me a long time.

#

No judgement... Just curious

graceful rampart
#

The medium one was a ton of fun

#

Hard too so far

graceful rampart
hazy grotto
#

Ahh nice.

graceful rampart
#

This module has by far taken me the longest tho

hazy grotto
#

Did that work for you

graceful rampart
#

I've been on it for a week. There were parts that pissed me off so much I just quit for the say

graceful rampart
hazy grotto
#

Really? everytime i tried to visit the site to generate the revshell it wouldn't work but i found a way around it.

graceful rampart
#

Weird

#

I've used that site for a long time

#

Also, the hacktools Firefox extension is amazing

hazy grotto
#

Yeah idk. couldn't use the Invoke method with that ps rev shell generator.

#

What i did was took the hash into hashcat.

#

Cracked it, then brought up RDP on the MS01 system.

#

RDP'd with those creds into DS01

#

I'm pretty sure you could get the rest of the flags from that but I just took that one.

graceful rampart
#

I just passed the hash lmao

#

No cracking required

hazy grotto
#

PtT was fun

graceful rampart
graceful rampart
hazy grotto
#

Take it back@

graceful rampart
#

Lol

fathom pendant
devout cliff
rustic sage
#

can someone teach me the basics from the ground up

#

i will pay

devout cliff
#

join and start going through modules

#

enjoy

graceful rampart
#

Youre joking right?

devout cliff
graceful rampart
devout cliff
#

are you running it in a VM?

graceful rampart
#

Phew, k. I got it. Tried a different wordlist lmao

#

got it instantly

devout cliff
#

did you try the cutdown rockyou?

#

like the 10 or 15?

graceful rampart
#

no. Remembered I have another wordlist from earlier in this lab

devout cliff
#

ah

#

still thats interesting, does the bitlocker hash usually take that long to run through a wordlist?

graceful rampart
#

I mean, I know bitlocker has pretty strong encryption, so cracking the password is expected to be intense on your system

devout cliff
#

i suppose if its an strong encryption it takes more time to do the encryption process. so yeah makes sense

graceful rampart
#

Yea exactly

thorn urchin
#

should be noted thats a bitlocker encrypted volume

graceful rampart
#

Well, no. Its the hash of the bitlocker password

thorn urchin
#

slightly different than a bitlocker encrypted drive, which is going to have a pregenned password thats like 48 characters long

graceful rampart
#

nope. Youre thinking about the recovery key

thorn urchin
#

Yes, exactly

graceful rampart
#

Yea, i cant imagine brute forcing that lol

thorn urchin
#

Thats my entire point lol

graceful rampart
#

ah

devout cliff
#

if its 48 characters and uses upper/lower/numbers/symbols then it would take longer than the universe has been around i think

thorn urchin
#

this is a bitlocker encrypted volume, and thus is the most feasible scenario for cracking. Dont expect this for 99% of the common bitlocker use cases

fathom pendant
devout cliff
#

only numbers?

thorn urchin
#

hex digits iirc

fathom pendant
#

not hex digits

#

BitLocker recovery keys consist of 48 numbers which is why you're unable to type characters - recovery keys themselves don't contain characters. BitLocker recovery keys are numbers only.

graceful rampart
#

looking back at my notes, the module says its a string of 48 numbers

thorn urchin
#

there ya go then

devout cliff
#

Your BitLocker recovery key is a unique 48-digit numerical password

fathom pendant
#

the recovery key ID is alphanumeric (maybe hex)

devout cliff
#

ok 48 numbers

#

thats possible actually

thorn urchin
#

no lol

devout cliff
#

im not saying FEASIBLE

#

im saying POSSIBLE

thorn urchin
#

each additional digit is exponential

#

no

fathom pendant
#

It is technically possible

#

reasonable to do? no

devout cliff
#

According to a password-security estimator, cracking a 48 character key, guessing at 17.5 million keys per second would take almost infinity to crack.

#

ez

#

just be batman

#

and guess first try

fathom pendant
#

"almost infinity" is basically saying, it would take so long that we don't bother to give you a reasonable estimate

thorn urchin
#

just be the NSA and be able to ring up Microsoft and ask for their copy of the recovery key

graceful rampart
#

lmao

devout cliff
#

ayyyy

fathom pendant
#

AFAIK Microsoft doesn't keep a copy of the key

thorn urchin
#

if my customers can do it, the nsa can

#

They do

fathom pendant
#

it's attached solely to your account

thorn urchin
#

Yeah exactly

#

Ive had to walk customers through it for data recovery jobs

fathom pendant
#

that's not the same as asking microsoft directly for the key; it's signing into their microsoft account to get the key

thorn urchin
#

Semantics

#

I dont believe for a second that theyre encrypting that info to the per account password

#

even if they were, tons of other ways the nsa could go about getting the password for the account with Microsofts cooperation. But were starting to veer off topic

fathom pendant
#

They are; or at the very least, Microsoft refuses to even acknowledge bitlocker keys aside from assisting with getting to the recovery key page

devout cliff
#

in other news im on track to complete 3 modules today

fathom pendant
#

Nice

thorn urchin
#

I miss when I could knock out three modules a day

devout cliff
#

1 of the modules doesnt count really, was a fundamental macos module

#

i dunno if im going to ever use that but good to know

#

another was finishing the footprinting module, and now the metasploit module

fathom pendant
#

The Medium Footprinting was tougher than the hard one, change my mind

devout cliff
#

no i agree

#

i was able to do the hard one without any assistance

minor pelican
#

the cornerstone of password cracking. Asking politely

devout cliff
#

just needed to refer back to notes

dull moth
simple zephyr
#

I am stuck on Shells & Payloads. I have a foothold onto Host 3, but stuck on the last question.

solid wedge
#

?

#

wait never mind got it

simple zephyr
#

nm, i tried this for an hour and it finally works. I still have some questions about Host 3 though

atomic ruin
#

Any one up for some help with my setup? Trying to finish the Nmap module, everytime I try to scan with different source IP I get: setup_target: failed to determine route to ip
I'm using the -e tun0 to use the vpn interface.
Any suggestions on what I'm doing wrong?

graceful rampart
#

Alright, I just want to say, While i wasnt a fan of a lot of the excersizes int he password attacks module, the medium and hard labs were amazing. I still doing think it shou8ld take 30 minutes to get the foothold on the easy lab, but hte medium and hard ones were an absolute ton of fun

devout cliff
#

does anyone know after you run the shell command in meterpreter how to go back to a meterpreter shell instead of the native shell on the box?

atomic ruin
#

exit

devout cliff
#

thanks

rustic sage
#

Was there a off topic section here??

devout cliff
#

one other question - is there a way to background a meterpreter session without using ctrl+z?

#

because tmux shares that hotkey to bg the whole msf process

devout cliff
#

ok fair

atomic ruin
#

type background

graceful rampart
devout cliff
#

that works

graceful rampart
atomic ruin
#

think bg also works but dont quote me on that