#modules

1 messages · Page 36 of 1

fathom pendant
#

if fg is a thing, surely bg must be

devout cliff
#

it did work as well

rustic sage
#

i need a little help on info gathering web edition active subdomain enum, the third question

#

I managed to do the first and second

#

ping or dm me if u wanna help me

graceful rampart
# rustic sage i need a little help on info gathering web edition active subdomain enum, the th...

This question isnt very helpful. You havent actually asked your question yet which means when someone offers to help, they then have to wait for you to ask a second question. You havent said what youve tried either.

If you want an answer to a question, start by first actually asking the question. Share as much info as you can (while avoiding spoilers obviously). You want to make it as easy as possible for someone to help you that way when they see the message, if they know the answer, they can just say it

#

That being said, if you provide the information i just mentioned ill be happy to try to help you

rustic sage
#

k

#

so I try to dig or nslookup the ip given by the section it returns nxdomain

#

which i looked up what nxdomain means and it means non existant domain

graceful rampart
#

Well, theres more you can do than just a dns lookup

rustic sage
#

i put the ip into the zone transfer website thingey and it still returns an error

graceful rampart
#

maybe try running a command from your terminal to do a zone trnasfer

rustic sage
#

ok

#

i think it could be because u need to connect to the website through the openvpn proxy htb academy gives me and nslookup or dig or whatever is connecting through their server so they cant connect but im not too sure how to resolve this

languid remnant
#

Hola alguien sabe co o puedo hacer si pedí mi código 2FA

#

Perdón alguien sabe cómo puedo hacer si perdí mi código 2FA

novel matrix
languid remnant
#

Sorry, does anyone know what I can do if I lost my 2FA code?

novel matrix
languid remnant
#

Sorry, does anyone know what I can do if I lost my 2FA code?

#

how can i contact support

#

?

novel matrix
languid remnant
#

Tanks

#

Gracias

harsh badger
#

Hm, so not all modules return cubes?

toxic oracle
#

really?

fallen osprey
#

I try use John the ripper for crack a id_rsa ssh key-file but I get a errormessage when I try run ssh2john to get a hash. What I'm doing wrong?

karmic mantle
#

@fallen osprey did you first run ssh2john to get the hash that John can crack?

#

Oh sorry I read that wrong

harsh badger
#

Try an earlier version or python2

fallen osprey
#

PASSWOR ATTACK-Pass the Thicket (PrT) from Linux I used smbclient to download the flag.txt from //dc01/linux01 and read the content from that flag.txt to answer the question. But it said it´s Incorrent Answer. Anyone have any hint/clue/idea ?

ivory hollow
#

Hi all

May anybody assist in Footprinting module. section DNS in last question please. as i already dig all the links and also did the brute force of those link but no luck. Any assistance will be appreciated.

Thanks

harsh badger
fallen osprey
harsh badger
#

You can try lol maybe there's a new compatible version of it for 3.9

#

Hm so in the File Transfers module in the PowerShell Web Uploads section it says
"PowerShell doesn't have a built-in function for upload operations, but we can use Invoke-WebRequest or Invoke-RestMethod to build our upload function."

But in the Net.Webclient docs there's a table of methods that can be used to upload files and data
https://learn.microsoft.com/en-us/dotnet/api/system.net.webclient?view=net-6.0

Mistake?

fallen osprey
#

@harsh badger do you have any idea/hint for my Pass the Ticket ((PrT) issue too?

harsh badger
#

Sadly no(t yet) lol

graceful rampart
#

Need to confirm you actually found the correct one

fallen osprey
midnight burrow
#

why

#

i mean i could

#

nut this is not hacking service

graceful rampart
#

Wrong server

midnight burrow
#

This is not hacking service server

#

sorry

umbral river
#

I finally got the content in table flag5 for SQLMAP ESSENTIALS module and it says its not the correct answer...... any help here would be greatly appreciated. I do not have a space character at the end or begining of this key.. just for clarification.

#

ok what gives.... one of the characters was a _ instead of a number?!

#

I submitted it successfully but the above doesn't make any sense if anyone would care to explain it to me.

wheat garden
#

😆

#

Any one complete Introduction to Windows Command Line ? Need help with question 5 of the skill assessment

"User4 has a lot of files and folders in their Documents folder. The flag can be found within one of them. "

wheat garden
umbral river
#

Thanks with the help from @proud pine seems like the type of sqli can miss some data so multiple passes can be beneficial

hardy hare
#

Anyone been able to complete the last question of the skill assessment for Intro to Windows Command Line? I've been able to view the event log entries and the usernames, but none of them work for the answer...

fallen osprey
#

@sterile hawk

sterile hawk
#

Please don't ask for help with illegal activity in future

ivory hollow
#

Hi all

May anybody assist in Footprinting module. section DNS in last question please. as i already dig all the links and also did the brute force of those link but no luck. Any assistance will be appreciated.

Thanks

fathom pendant
proud pine
#

Man, I spent 20 minutes trying to figure out why the bash script I was writing for this module wasn't working, and ChatGPT goes and finds the error in 2 seconds.

sly tapir
cunning yew
#

@sly tapir

rich vale
#

can anyone help me with the skills assessment on the AD module

proud pine
#

That sorta depends on what your goal is. The modules are just there to teach you a concept, or how to use a tool. If you know what you are doing already, or know a better way to do something, that's up to you.

wheat garden
#

only if you want to be

sonic wyvern
#

CROSS-SITE SCRIPTING (XSS), the first question there is
To get the flag, use the same payload we used above, but change its JavaScript code to show the cookie instead of showing the url.

#

So i tried to put inside of the input <script>console.log(window.cookie)</script>

#

But in the console I get error message
Cookie “cookie” will be soon rejected because it has the “SameSite"...

proud pine
sonic wyvern
#

yep.. i meant document.cookie.. but still the same issue

#

the page is also refreshing when I submit the form

#

and it's the first question on this module so I assume they don'y want me to go too deep with JS and use e.preventDefault()

proud pine
#

I'd go back through the module, and try to use the methods they show.

#

Also, you should avoid putting outright spoilers in any of your messages here.

sonic wyvern
#

Ok

midnight burrow
#

l

lucid wyvern
#

Pivoting, Tunneling, and Port Forwarding module. I can't move forward as the instance is up and down, not fun.

peak hamlet
#

Hi Guys anyone have any idea what is the answer for "What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word) " in Active Directory Modue? stuck there for a while, powershell is stuck and the 2 answers from Bloodhound not working 😄

sonic wyvern
#

@proud pine but the page should refresh on that question? in the example they provided I should be able to add a "word" and it will submit the form and show the word below

#

honestly, I don't understand this question, I can just go to the dev tools, run the command there and get the flag..

#

so I'm good for now, until the next one

candid zephyr
peak hamlet
candid zephyr
peak hamlet
candid zephyr
wheat garden
#

Any one finish introduction to windows command line module? On the final question of the skill asessment. Ran

Get-WinEvent -FilterHashTable @{LogName='Security';ID='4625 '} | select-object -ExpandProperty message

non of the displayed usernames haave been accepted im stumped

ripe terrace
sterile goblet
#

Hi

#

I'm new in this, any hint to solve my module

stuck hull
echo zenith
#

Linux Local Privilege Escalation - Skill Assessment
flag 5
Can someone help me to obtain the reverse shell? I have tried with msfconsole and there is no way, I have the username and password

fathom pendant
#

Hint: what does it tell you it serves as

ripe terrace
#

Thanks, @stuck hull / @fathom pendant - I got some help over DM, and I'm making progress again.

brisk geode
#

hey can anyone help me with the Nmap module hard and medium labs, i have completed this module like 4-5 months ago currently taking notes so would really appreciate if someone helps

fathom pendant
ripe terrace
plain coral
#

@brisk geode Feel free to message me directly if you are still stuck after those hints.

silver zenith
#

When i get home from work gonna pick op academy again. Been to pang…

storm jackal
sweet island
#

hi everyone!
i'm doing the skill assessment for the file inclusion module and i'm kinda lost.
i've already tried somethings like LFI and RCI with PHP Wrappers and nothing yet.
i also look on web for tips and i saw a lot of people saying about source code disclosure but everything i tried lead me to a dead end somehow, i know maybe i'm doing anything wrong or missing something basic but if anyone has some way to point me or any useful tip i'll appreciate it 🙂
**Btw english is not my native language so if i said anything weird please tell me 🙂 **

gleaming cosmos
#

is someone available for DM about my findings related to Broken Authentication - Skill Assessment ?

polar crag
#

doing the reverse port forwarding section in the pivot module and im stuck at creating a reverse shell.
I tried the meterpreter way and it always clses the session, then i tried the nc way and something strange happend xD
im not sure what im doing wrong haha

placid quest
#

@polar crag check the payload option

polar crag
#

@placid quest thanks! but im still confused because the payload created was a reverse_https and was shown in the module "windows/x64/meterpreter/reverse_https" and this didnt worked.
Now i created a new payload but a windows/x64/meterpreter/reverse_tcp changed it in the multi/handler to reverse_tcp and now it worked.

#

I have to write down all the steps because there were so many...
-Create payload
-Remote forwarding so you can login via rdp

  • Copy payload to Pivothost
    -Login to ssh and start the http server
  • Download payload
  • Reverse port forward
    -Start Multi/Handler
    -Execute payload
placid quest
#

@polar crag That thing that to happen to me when i was doing pivoting module so to solve it i had to change the payload and it worked

polar crag
#

It confused me hard but now i understood the concept of reverse port forwarding. Its a really interesting module.

quiet oxide
#

Hello all I am new here but have no idea about anything can anyone help me?

polar crag
#

its the place to learn if youre interested

quiet oxide
#

Thank you

#

Well i have no idea abt hacking too can anyone guide me i am interested but don't know wat to do

minor pelican
#

Thats a very very broad question thats impossible to sum up in one message. Theres so many areas of hacking

pastel gale
#

google and youtube is your friend

radiant verge
minor pelican
#

yes

#

XSS for example

#

But i would say if you overall want to do more pentesting/cybersec. One language you know isnt going to do much for you

#

there a giant amount of different areas within the term "hacking" term

pastel gale
#

you should be well versed with any scripting language and you must have a little coding experience so that you can atleast read code for vulnerabilities and exploits IMO

torn blade
#

finally coming back to try to finish the fuzz module

#

i have ran fuzz and dirb for this question and i cannot find the page. "Try to use what you learned in this section to fuzz the '/blog' directory and find all pages. One of them should contain a flag. What is the flag?" its in page fuzzing

#

ATTACKING WEB APPLICATIONS WITH FFUF

#

i need help, like fuzz finds the index.php page that has no information but cant find the page with the flag

hybrid plover
#

Can anyone explain dns zone transferring to me? I understand that your basically doing a download of the records stored on that dns server, but what I don’t understand is how do you know you that you can do a zone transfer? When using dig what differentiates a normal dns record to a server that can do transfers?

severe dagger
#

Helo, I am doing

LINUX PRIVILEGE ESCALATION - Skill Assessment

I believe I am pretty close to get flag5.txt or root flag. I am stuck at one place. Can someone help me? can I DM someone??

pastel gale
#

why is the target server so buggy today it keeps dropping the connection

topaz locust
#

anybody else having issues with starting instances?

pastel gale
#

i guess its a server issue from htb

topaz locust
#

i would point my finger at aws

#

just shoddy infrastructuring

#

😛

pastel gale
#

lmao

#

ill come back later i guess no point doing this with this connection

topaz locust
#

mine just worked

#

mwhaaha

pastel gale
#

go on

#

and wait till you loose connection in the middle of an exploit

#

mwahahahahah

#

anyone has a solution to increasing the resolution of a windows rdp

feral stump
topaz locust
torn blade
#

instances be going dowwwwn

#

got it

shadow canopy
#

can someone help me with this please

  • Basic Bypasses - LFI - module/23 section/1491
  • web application employs more than one filter to avoid LFI exploitation
  • ?language=languages/en.php

i tried with cheat sheet and tried all methods but not getting /etc/passwd

rustic sage
#

The answers aren’t given. If you need help you should state what module and section you are on and where you are stuck.

autumn tundra
#

i am working on Public Exploits and the target Web Server can not be reached. The website was working at first. I am guessing I tried the wrong exploit in Metasploit and now nothing is reachable. I wanted to try the wp_plugin_backup_guard_rce for remote code execution but I am having no luck

autumn tundra
#

sorry I found it out. took a lot of struggling when all i needed to do was read the advanced options -_-

proud surge
#

hey guys, i have an error, somebody help -me
I config the resolv.conf with ip and status.inlanefreight.local

but the page doesnt load
Laudanum, One Webshell To Rule Them All

autumn tundra
#

I just did that one!

#

happy to help i am building my notes now

#

send the path of the exploit you are using

fathom pendant
#

The lesson itself walks you through how to do so

autumn tundra
#

ok the main step is going to the web server

#

your next step will be searching for the exploit on Metasploit. From there it is key to look at how it is configured befcore launching it

#

that is not it

stuck hull
#

How do we report minor errors in the material?

autumn tundra
#

be more specific in your exploit search

lethal schooner
#

Just so I'm clear on this, the purpose of static/dynamic port forwarding is to get around a firewall?

hallow tendon
#

hey guys im stuck on Firewall and IDS/IPS Evasion - Easy Lab (cpts path) i cant get the answer "Our client wants to know if we can identify which operating system their provided machine is running on. Submit the OS name as the answer. " any help will be appreciate.

stuck hull
hallow tendon
#

i think i did let me check again thx

shell fox
#

Hi all, I have managed to fail at the first hurdle. I am progressing through Starting-Point. I have a target machine started. I can ping it. But I cannot ssh/rdp/web to it.
The last question in the module is to "Submit root flag" but I cannot get onto the target.
I am obviously missing something fundamental.

hallow tendon
stuck hull
#

Just the name of the OS

#

Go have a look at the actual website

hallow tendon
#

Apache2 Ubuntu

graceful rampart
#

Apache2 is not an OS

stuck hull
#

One of those is an OS the other is a Web Server

hallow tendon
#

i tried before text on this chat

hallow tendon
autumn tundra
#

send your msf > exploit search

#

I PM'd you @rustic sage

hallow tendon
rustic sage
#

Could anyone learn me coding 1 on 1

stuck hull
craggy wing
#

Hi, for the Precious HTB machine I had created my own webserver in order to input the URL in the Precious.htb webpage since it requests a valid url. However, it continues to ask for a valid url. Can someone help me out with this. I've been inputting http://127.0.0.1 and it doesn't work. Also for the image below, I got a response when I opened the IP address in a separate tab not from the Precious.htb page.

fathom pendant
craggy wing
#

How do I fix a loopback address?

shell fox
stuck hull
#

*python is useful if your intending on getting into infosec. The course itself is just a generic python course. But it will introduce you to the basics of programming too

rustic sage
#

Oke thanks

#

If anyones got some time to help me out with SQLMap Essentials -> Building attacks, please DM me, i'd be really appreciative ^^

rustic sage
#

uhhh put your tun0 address with the port

#

tun0 is your actual IP

#

you can check with ifconfig

candid zephyr
rustic sage
#

to be fair - when i get really tired i forget the basic stuff too

rustic sage
#

like typing print instead of printf for C

#

(pain)

pastel gale
#

bro

#

java

#

c

#

c++

#

python

#

javascript

#

all syntax gets messed

rustic sage
#

python, my beloved

pastel gale
#

FUCK JAVA

rustic sage
#

fuck java, me and my homies hate java

We all about simple, efficient and easy to understand design

pastel gale
#

imagine needing to type

candid zephyr
pastel gale
#

system.out.println just for print()

candid zephyr
#

And when reminded ask how to fix "loopback address"

pastel gale
#

if you want to take input

#

CALL A NEW SCANNER FUNCTION wtffff

#

why would people use this shit

rustic sage
#

what are you talking about cack you're speaking in moon runes now

#

i haven't slept for two days lmao.

pastel gale
#

i was stuck on shells and payloads for 3 days just because i was using my rdp ip as the lhost -___-

candid zephyr
#

The guy who's probably failing at following a writeup is what I'm talking about.

rustic sage
#

I got stuck on some machines for a while because i was using "starting point" PWNBOX :' )

pastel gale
rustic sage
#

anyways - can anyone help me with SQLMap - Attack Tuning

#

i just wanna get this module done for today so i can crack one with coding too

pastel gale
#

Does regular hackthebox have any kind of students discount?

muted comet
#

can anyone help me set up my vsFTPd.conf file to be anonymous

#

dont understand how to set it ip

#

up

stone igloo
#

Just uncomment the anonymous access line

rustic sage
#

Does anyone anything about remote acces dm me please

stone igloo
#

Elaborate please

stone igloo
#

^

fathom pendant
#

This channel is also for the modules found on academy; if you have an unrelated question #1024429874246590575 is the place to ask/search if your question has already been asked and answered

graceful rampart
#

Bruh. Im on Attacking Common Services > Attacking ftp
The ftp port refuses to open

#

Anyone else have this issue?

graceful rampart
pastel gale
#

how are you posting pics?

graceful rampart
#

Ive tried swapping vpn servers too 😭

graceful rampart
pastel gale
#

are u sure its not on 21?

graceful rampart
#

yep

#

positive

pastel gale
#

sometimes there is port forwardiung

graceful rampart
#

no. theres no port forwarding. I know its supposed to be there cuz when i started the machine the first time it was there. Then i crashed the machine trying bruteforce something. Then when i restarted it ftp wont open

pastel gale
#

L

#

btw how do you verify?

#

i dont see a channe;l

thorn urchin
pastel gale
#

yes yes

#

got it

#

thanks

stuck hull
rustic sage
#

I have a remote acces tool

rustic sage
graceful rampart
rustic sage
#

Idk why it dindt work on him

rustic sage
#

I know

#

How to use it

#

Little

pastel gale
#

does academy not have any account identifier

graceful rampart
#

clearly you dont

rustic sage
#

Actually

#

No

#

I don’t

graceful rampart
rustic sage
#

But I want to learn

graceful rampart
rustic sage
#

Why

pastel gale
#

go back to the shady server full of skids from where you came from

graceful rampart
#

Cuz we dont do illegal things here

rustic sage
#

So u hack legal

stuck hull
#

Brother, you don't hack at all

rustic sage
#

I know

#

I’m learning

graceful rampart
rustic sage
#

How

graceful rampart
#

Thats litteraly the entire point of this server

rustic sage
#

Okay

#

Learn

#

Me

graceful rampart
pastel gale
#

🤣

stuck hull
rustic sage
#

Pleasee

devout cliff
#

is this really what we are doing

#

right now

#

i come back from changing my tire and i find this

bright ridge
#

hm

devout cliff
#

i am disappointed

pastel gale
#

tire

graceful rampart
devout cliff
stuck hull
devout cliff
#

i touched grass yes

stuck hull
#

ewww

#

why?

pastel gale
#

touching grass is so overrated

devout cliff
#

for the sensation

stuck hull
pastel gale
#

and get scarred by the things he searches?

pastel gale
#

POV : How to humble my child?

#

i am really shelling out 2k$ for oscp !! i am so fucking scared regarding the ifs

rustic sage
#

Do u guys also learn here how to program a cheat for a game

devout cliff
rustic sage
#

Ow

#

And where can I find that

devout cliff
#

not here

rustic sage
#

Where

devout cliff
#

the opposite of here

rustic sage
#

And that is?

#

Where

devout cliff
#

somewhere else

thorn urchin
#

This discussion is for academy module stuff

rustic sage
#

And who are u

thorn urchin
#

If academy adds a game hacking module then sure itll be relevant

#

otherwise too bad

rustic sage
#

Okay

muted comet
#

getting this when trying to get the version of FTP my target is running

rustic sage
#

Use (y:,

muted comet
#

but it says my answer is wrong

rustic sage
devout cliff
#

that is the right answer, you just gotta little too much there 😉

muted comet
#

omg

#

lmfao

#

is the correct answer

#

hahahaha

devout cliff
#

and then delete the answers in the channel pls 😄

#

220 is a response code

muted comet
#

lol rfr

#

alright well that was enough learning for today this footprinting module long as hell lol

#

but learned a lot

devout cliff
#

its a decent module

thorn urchin
#

definitely one of the fun early ones

thorn urchin
#

eh not that much

#

Id put it at high medium in length

#

AD module is a mammoth though

devout cliff
#

its just so dense

pastel gale
#

i am so bored to attempt passtheticket

#

anything elkated to rdp is boring

#

related

thorn urchin
#

PtT isnt related to rdp, rdp is just one such means to potentially abuse a PtT scenario

pastel gale
#

i meant any excercise where i have to use an rdp is boring

#

btw the rdp keeps dropping connection anyone else facing the same issue

#

?

graceful rampart
#

PtH and PtT are really fun

#

especially if you understand whats happening under the hood

pastel gale
#

These servers are acting funny

#

the targets are dropping connection for me

graceful rampart
#

yea. theyre doin some weird stuff for me as well

topaz locust
#

mine are lacking jquery and as a result all the javascript functions don't work 😄

#

it's great

topaz locust
#

I have to read the source and manually recreate the requests

graceful rampart
#

Im doing the 'Attacking ftp' section of Attacking common services and theres no FTP running lmao

pastel gale
#

In ptt the rdp connection resolution is so small i tried to increase it but apparently i cant change it from a remote session is there any workaround

topaz locust
buoyant escarp
#

im stuck in the assessment for XSS module
the hint says: i can see you but you cant see me.

characters like <>" gets converted to < >
can someone give me a rough direction?

pastel gale
graceful rampart
# pastel gale

with xfreerdp i know you can give the /dynamic-resolution flag

#

idk how to do it with remmina

pastel gale
#

ill try

#

thanks

stuck hull
topaz locust
stuck hull
#

see above...

pastel gale
#

ok

#

Thanks man i feel so dumb for not trying that

#

ugh

buoyant escarp
low vine
#

Okay I have to be extremely dense but I'm failing ot connect to MYSQL database in SQL section
||mysql -u root -h <ip> -p|| this is what i'm doing to try to connect and I'm not understanding why I cannot connect

rustic sage
#

Specify port?

low vine
#

^

#

i just realized that

#

facepalm.jpg ><

devout cliff
low vine
#

I'm crying inside

#

-P 😦

fathom pendant
#

-P is password

#

Iirc

#

I forget the syntax

#

When I go on break I'll double check that section

low vine
#

-p is password -P is port

#

So much great info !

rustic sage
#

We all have those moments aha

#

since you guys are good at hacking does anyone know how to get unban for fivem

#

don't use cheats

buoyant escarp
#

finished the XSS, its such a cool module, worth every penny

tiny ember
#

For the Footprinting Module test boxes, when they say "forbidden to attack the services aggressively using exploits" does that mean no wordlist enumerations or more like no metasploit?

devout cliff
tiny ember
#

kk

fathom pendant
#

Yea

#

The information is easily available if you know where you're looking :) the lab tells you what services you should be looking for

tiny ember
#

see you say that and then the box time expires and one then has to avoid questioning their decisions in life 🤣

fathom pendant
#

Everything you need is within the module, so I hope you took notes!

waxen barn
#

In the Active Directory Skill Assessment I, how do I get to the MS01 computer?

graceful rampart
#

Lmao yea

#

It finally decided ti start working

#

After like 3 hours

devout cliff
#

ok because im on the same module and i didnt have that issue 😄

#

but it didnt use ||port 21|| as well

#

most likely on purpose

graceful rampart
#

Yea ik

#

It worked initially, but then the machine crashed. So i reset it and there was no ftp

devout cliff
#

rip

graceful rampart
#

Yea

fathom pendant
#

F

gentle swift
fathom pendant
#

Including potential flags you'd need

#

It does a good job of telling you the thing and giving an example. In some cases the section covers what it's asking for you to walk through

#

The labs usually are designed to be done as an INDIVIDUAL module regardless if you're doing a path or not. So very much self contained

clear haven
#

I'm wondering if anyone could provide some insight to completing the footprinting hard lab? I've goen through SNMP with the correct community string. I've logged into the IMAP service and retried the one email with private key. I've been able to connect over ssh with that key and I've looked at the history. I think I've found additional credentials but when I try the two I think I've found to log into the mysql service I keep getting access denied. I think it's a typo on my part or I'm completely off base.

stuck hull
#

I'd say you're pretty close

fathom pendant
#

Hint: you are thinking about the right tool;

stuck hull
#

The credentials you need you would have found when enumerating the SNMP service.

broken warren
#

For anyone who completed the Footprinting module > host based enumeration> SMTP section.
I got the answer to question 2 but I didn't take notes so I'm redoing it, and I don't really remember how I got the answer. I tried using smtp-user-enum and the Footprinting-wordlist given by HTB but I got 0 results. Which I know can't be true because I can see the correct name in the wordlist. So I'm just curious how anyone else approached this

feral stump
fathom pendant
stuck hull
#

Well remembered!

fathom pendant
#

I forget the flag for it

#

Ik it can be done within msfconsole, but that is a sanity check for sure

stuck hull
#

MrTom had the answer for the flag: -w

devout cliff
#

ill be honest guys, i did that part manually 🙂

#

im a masochist i guess

rustic sage
#

Well boys we did it

#

my very first

#

machine by myself

#

yippee

devout cliff
stuck hull
devout cliff
#

the former

stuck hull
devout cliff
#

i am quite the enigma i suppose

simple zephyr
#

https://malicious.link/post/2011/2011-05-16-dumping-hashes-on-win2k8-r2-x64-with-metasploit/

||you have to migrate to a PID that support x64|| (answering for future searches)

clear haven
#

@stuck hull I have that…or I think I do. It’s the one that errored out in the script? If it is, so I need (). I’ve tried a few different ways and can’t get it to work.

wintry gorge
#

Anyone else on the Active Directory Bloodhound module? I think the module is broken, when importing the files it says "File created from incompatible Collector" Any workarounds?

rustic sage
#

i am doing file upload labs. when i put my php code in to the website why does it get commented out... for example: tyhis is what happens when i view page source. <!--?php echo shell_exec('ls /'); ? -->

dim hemlock
#

Hi all I hope you are well

#

Im stuck a bit on the footprinting Module

#

I was wondering if someone would be able to point me in the right direction

fathom pendant
graceful rampart
#

Lmao. It's in my bio

#

Easier than telling them to just ask their question myself

#

Maybe in the future they'll actually just ask the question lol

fathom pendant
#

Yeah I need to edit my bio for here

ripe terrace
#

@dim hemlock I've just completed it. Feel free to DM if you still need a hand.

fathom pendant
graceful rampart
#

Nice

dim hemlock
#

Hi thank you but I improved a step

#

I will continue until I get stuck again

#

hghaha

dim hemlock
#

Hi guys, I have ssh-d to the server on the footprinting easy module lab
but I am unable to find flag.txt with ceil user
do I need to get root user?

#

opokay I got ittt

pearl island
#

Hey all, can anyone help me with Attacking Common Applications Skills Assessment I? I've got the answer but I still have some questions.

sonic wyvern
#

What's the question

fathom pendant
simple zephyr
#

For Password Attacks - Password Mutations can someone just tell me the first digit of the password.

fathom pendant
#

The first digit is [0-9a-zA-Z]

#

:^)

simple zephyr
fathom pendant
#

I had to do the regex, just a bit of trolling

simple zephyr
#

Went back to my office for it to be done. I want to build a cracking server for this reason

warm dagger
#

how did you solve this?

simple zephyr
#

What’s the max threads you all run on hydra?

graceful rampart
#

depends on the service and the target server

#

and whether you care about being detected or not

simple zephyr
#

What’s a good threshold for being silent and not caring for FTP

floral sandal
#

I am working on attacking active directory module, but when I RDP into machine it disconnects me after couple of minutes
I cannot continue my learning, how to fix that ?
thanks

simple zephyr
floral sandal
#

I only connect my kali to VPN

simple zephyr
#

Did you open the pwnbox though? I only run mine off VPN but I guess I bumped it and that caused it

floral sandal
#

I will try open pwnbox without connecting to vpn

graceful rampart
warm dagger
#

same issue, same question in pivoting section, how did you solve, if you don't mind sharing?

wheat garden
prisma knot
#

Anyone free to assist with the footprinting IMAP/POP3 module?

fathom pendant
#

It's best to just ask the question, if someone has the answer they'll assist and help nudge you

rancid finch
#

hello

#

like my dog

#

he be doin hole pack

#

krlgkrg,fmlmblmbl;fg ,kldbdklfldsrdr;d;lfsnbsl lsblsdfnbdfkbkdnfbndsflkbndklnbithbekngknbls b d,f dkfn lksdnfksdvb

#

dont copy link hehe

#

it tells p

#

sike

fathom pendant
#

You good?

rancid finch
#

you

#

hey you

#

let me dm you

fathom pendant
#

No

rancid finch
#

fine

#

join hacking dark

#

its private

#

i am real hacker

#

i learned how to hack by this server

fathom pendant
#

Cool story bro

rancid finch
#

then then theeee

#

dang

#

just join it

fathom pendant
rancid finch
#

nah

#

your ip

#

is

#

your mom sonic boy

#

poopy oppsi

#

nah thats mine

#

wanna come to my house

#

play date

graceful rampart
#

Please stop spamming in this channel. If you want to mess around go do it in #general

rancid finch
#

what

rancid finch
#

i you using mom gif meme

#

what's your real name

#

i can tell you your id if you tell me

graceful rampart
#

HOnestly, you could prolly figure that out if you were a half decent hacker

thorn urchin
#

ids are easy

#

1057858724670210098 is yours

graceful rampart
#

I have a very public linkedIn profile lol

thorn urchin
#

236600482750005248 is Man'

rancid finch
#

how about ip

graceful rampart
rancid finch
#

my private one

thorn urchin
#

277851449147392000 is mine

thorn urchin
rancid finch
#

wrong let me look

#

wrong

#

L

graceful rampart
#

prove it

#

Wow. Amazing. Congrats. Youre just like every other skid in the world

rancid finch
#

i am joking

#

#staff

#

#STAFF

dim hemlock
#

Hi guys

#

anyone finished the Medium footprinting module?

#

Im stuck trying to RDP with a privilged user which should be the last part

#

I think I got the credentials

ripe terrace
#

You can DM me if you want; happy to help.

dim hemlock
#

awesomeee

rancid finch
#

click

#

gen z belikehttps://youtu.be/BGiSjpKujNg

#

click link

sonic wyvern
#

CROSS-SITE SCRIPTING (XSS)
the Phishing part, I didn't understand why adding a parameter in the link of the website (for example: URL=image.jpg) would render it on the page

#

Can someone explain?

sly tapir
sonic wyvern
#

why when you put ?url=image.png it's adding image to the website?

#

I didn't see explanation for that

#

is it because of this line? <input type="text" placeholder="Image URL" name="url">

ripe terrace
sonic wyvern
#

so what do you mean.. that there is a php code that accept this url param and echo a <img> tag because of this param?

ripe terrace
#

Yup, basically.

#

Or the img tag is always there, but it's src attribute is being set to the url query parameter.

sonic wyvern
#

Weird.. I don't see why anyone do that as a web developer

#

and the question is how would you know as a hacker that it's available, that's what I'm asking

ripe terrace
#

You'd be surprised 🙂

fathom pendant
#

view source; enumeration tools; trial and error

sly tapir
#

i think its more because that form of image viewers are found in online forums and other similar web applications

sonic wyvern
#

but is there a way to see this vulnerability? or you have to guess with just typing url=...?

ripe terrace
#

You'd usually find a URL with existing query parameters and fuzz that or a combination of parameters/values to discover which ones are available. It takes time and patience.

fathom pendant
#

^

#

hacking isn't like what most movies make it out to be

#

Mr.Robot does a decent job of showing some things can take several days to actually pull off, but that's also a mix of external AND internal penetration of assets

sonic wyvern
#

@ripe terrace Thanks for the reply, I'll see you in the next question

#

btw, I saw here some people asking for 1vs1?
is that like a game that someone is trying to hack and someone is trying to defend?

fathom pendant
sonic wyvern
#

no, not this guy

#

I'm talking about battlefrounds

#

is it what I think it is?

#

I can join to this anytime with a friend.. and basically someone trying to attack and the other one trying to defend?

fathom pendant
#

basically a mix of both actually you are trying to attack while the other person is trying to defend

sonic wyvern
#

yes, that's what I said

#

Do you mean.. like both attacking and defending?

proud pine
sonic wyvern
#

cool, I'll try it

#

hey @proud pine, good to see you again

proud pine
sonic wyvern
#

I'm on the Phising question now, in the CROSS-SITE SCRIPTING (XSS)
It's talking about to do what I learned from this page.. and I tried to go to /phishing/send.php

#

Any hint if I'm doing something wrong?

#

also /phishing/index.php isn't available

proud pine
#

You use send.php once you have placed the malicious code.

#

Then it simulates a person checking the page

sonic wyvern
#

I can't think of a way to add something to the page because I have a blank page

#

I assume I'm in the wrong page

proud pine
#

At /phishing ?

sonic wyvern
#

yes

#

no, phishing is saying Not found

#

Maybe it's a restart machine issue?

proud pine
#

If you refresh the module page, does it still show the VM IP?

sonic wyvern
#

to spawn again

proud pine
#

I've had weird situations where machines are dying after a few minutes lately.

sonic wyvern
#

Yeah.. but I spawned it again bunch of times, let me try again

#

Yes, /phising/ or /phising/index.php

#

isn't working

#

I guess I'm doing something wrong

fathom pendant
#

I had to redo part of my notes from Getting started since I'm migrating my notes over to obsidian; got bored, decided to test my working knowledge in the Starting Point Labs on the regular HTB site... and wow I am zooming through this; some of the ports and names I already knew having gone through a course for it and receiving a CompTIA network+ cert but holyyy

#

i'm riding downhill with the wind at my back through starting point lol

candid zephyr
fathom pendant
#

and taking a look at the next set that it's recommending modules for; I'm not even going to attempt yet - but hey! At least I could do it without really needing to reference my notes too much either :) the annoying part at the start was waiting for the machine to spawn so I can answer the trivial questions

candid zephyr
fathom pendant
#

That is fair since they're rated "very easy" But I'd rather tackle them with pre-existing knowledge for the most part

candid zephyr
#

I personally find I absorb more just doing boxes than academy modules but some of them are really good to take lots of notes from.

fathom pendant
#

yeah I learned about a linux db service called redis... which is neat... and the commands are fairly straightforward which is also nice lol

proud pine
fathom pendant
#

(zoomed out because spoilers) but I'm liking the canvas feature a lot tbh of obsidian; and the fact I can link/use documents from the working vault to sort of keep things together without needing for additional copy/pasting

worldly pagoda
#

In the module on "windows command line " there is this question "What command can display the contents of a file and redirect the contents of the file into another file or to the console? "

#

what is expected out here? which file name should I enter which will make it happy

fathom pendant
#

What command
That's the question

worldly pagoda
#

This command does what is asked in the question

fathom pendant
#

is it the one given in the module?

#

that's basically how to answer your question

#

refrain from putting the hints here; as it can still be considered spoiling

worldly pagoda
#

my apologies

#

got the answer finally.

#

it was just the command name ..NotLikeThis

fathom pendant
#

^spoilers

#

sometimes it really is that easy :)

#

the fundamentals are generally going to walk you through things and mostly hold your hand throughout, the easy modules presume you have some working knowledge, medium builds off of the easy knowledge, and hard is basically you have advanced knowledge and are looking to dive deeper if that makes any sense

candid zephyr
fathom pendant
#

you can either join it to an existing box, or to a blankspace and create/import a new note

#

you can also color/label the arrows

candid zephyr
#

Ooh. I played with it briefly and it seemed to only want to link things that had backlinks.

fathom pendant
#

you can either add note from vault or add card

#

this is why you'd want color coding if you have to point things back to each other i.e. enumerate a step; get a result that lets you go back to another step

turbid lily
#

Hi, I'm currently in Pivoting Module. I have a question in the second section "Remote/Reverse Port Forwarding with SSH". Not about the section questions, it's about how to implement the reverse shell in pivoting. Anyone that could help?

fair spear
#

to whom or how can i communicate to solve this issue:
Identification error: please contact an online Moderator or Administrator for help

dire eagle
#

Anyone else having issues with File Inclusion? I do what the lesson tells me too, even look up other people doing it on youtube, and they don't work. php://filter/read=convert.base64-encode/resource=config.php shows a blank box. fuzzed it to find en, es, index, and configure but none of them show anything more than a blank box. curl also shows blank

#

had same problem with earlier lessons in this but found the right answers elsewhere.

vital adder
vital adder
vital adder
dire eagle
#

Not configure, en, es either. Probably flag. Sigh, I’ll have to wait until tomorrow for the pwn box to resets

#

Thanks

vital adder
#

also you don't need the pwnbox for this

dire eagle
#

?

vital adder
#

oh wait i forgot you will need tool like ffuf for this but if you have kali you can just do it on there

dire eagle
#

I’ve got Ubuntu, I can install gif

#

Fuff

vital adder
dire eagle
#

Thanks

#

Me dumb

solid pivot
#

morning guys! Is anyone available to assist me with the last step of the AD SKills assessment? I am losing my mind hahahaha

#

preferable not with the "chain" route 😉

vital adder
#

sure which assessment are you on?

solid pivot
#

the Active Directory Skills assessment I

#

the very last step

#

is it ok if I DM you @vital adder , to prevent any spoilers 😄

vital adder
#

sure

thorny solstice
#

At module Password Attacks>protected files. I have try to run ssh2john with rockyou and with a mut password list from the resources but i can not crack. Do anyone have a hint?

turbid lily
turbid lily
thorny solstice
#

I've try all 3 and it will not cracked.

uncut meadow
#

Hello team, Im stucked in the Footprinting DNS last question, I tried to bruteforce with dnsenum with all Seclist/Discovery/DNS/files and dont find any *.*.*.203 IP. Am I doing something wrong?

feral stump
#

Your command should work fine

turbid lily
# uncut meadow Hello team, Im stucked in the Footprinting DNS last question, I tried to brutefo...

as far as I remember you should first try to do a transfer zone "axfr" to every domain you get from previous scans. Some of them will fail, some of them will not. With those that don't fail, you could try the DNSenum command provided in the section. || A good hint is that in dns enum you can also try subdomains inside subdomains, so, in the example provided in the section, instead of 'inlanefreight.htb' you could also try 'example.inlanefreight.htb'. Which subdomains should you use? Well, read the first thing I told you to do. Which dictionary should you use? Be fierce ||

thorny solstice
uncut meadow
#

Got it thanks guys

turbid lily
#

yep, I suffered with that one too

stuck hull
#

Yeah the last one got me too

gleaming cosmos
shell cloud
#

For module Active Directory Enumeration and Attacks / LLMNR/NBT-NS Poisoning - from Windows, I can't seem to connect using xfreerdp to the Windows host. I get a black screen on the remote window and get the below error on my VM terminal:

stuck hull
proud pine
naive aspen
#

Anyone having connectivity issues into the AD skills 2 lab?

broken warren
#

For the Footprinting lab > host enumeration> IMAP/POP3. I got the answers to questions 1-4 and 6 but I can't find the admin email. The obvious one didn't work or I'm entering it in wrong? and I didn't see one in the message containing the flag for question 6 either.

stuck hull
broken warren
broken warren
stuck hull
feral stump
#

Im on password attacks network services and Im no getting results for smb

#

have tried both hydra and msf

#

any clues?

feral stump
#

I'll try again

graceful rampart
#

Show options and dm me the output

feral stump
#

ok

high totem
#

Hey everyone, question regarding Attacking Common Services - Attacking SMB section. I try getting password for user jason. Hint says to use the password list provided in the resources, but running it checking all passes for jason using CME returns no matches. Am I missing something, or misunderstand question/hint?

graceful rampart
lyric inlet
#

Hi , I have a problem with the question9 on cmdline module (skills assessment)

lyric inlet
#

I can PM anyone ?

graceful rampart
#

Np

high totem
wide path
#

Hey guys, I am doing the Cracking passwords with hashcat module and I'm stuck at the last question of the assessment witht the NTDS.dit file with all the hashes inside it, I tried to crack using MD4 and NTLM but I think hashcat gives me random passwords because it cracks all the passwords and I see people cracking a average of 80% of the password. So I really dont know what is the hash format, can someone help me ?

tiny ember
#

if you leave the hash format blank it will try to auto detect it

wide path
#

If i leave it blank I get this error

Failed to parse hashes using the 'pwdump' format.
gray pike
#

Hello, I am currently working on the Skills Assessment on the CrackMapExec module and I have been stuck for a few days on the 3rd question. Is there someone that I could talk to about where to go next ?
Thx !

graceful rampart
wide path
#

nevermind, I figured it out by finding that the hashcat.potfile displays only once the password even with the --username flag, I used the --show directly to the command and it shows me the repeated passwords

lyric inlet
#

on introduction to windows commandline question , tasklist give me some strange result :/

graceful rampart
graceful rampart
lyric inlet
graceful rampart
#

You're unlikely to get an answer from anyone unless you actually ask a question

graceful rampart
lyric inlet
#

I will not spoil 🙂

#

I pm you ?

#

tasklist /v show me only unknown status for services

#

Get-Services is ok , I can see if service is running ok stopped etc

#
Running  wscsvc             Security Center
Running  WSearch            Windows Search
Running  wuauserv           Windows Update```
#

Maybe I misunderstand the question

vernal reef
#

Hi bros excuse me someone could help me with this error un de openvpn to connect

vernal reef
stuck hull
# vernal reef

Click on 'switch' and select one of the free labs. Then download a new connection file and try again

warm dagger
#

need help with pivoting, tunnel - ah you understand :). setup proxychains, able to RDP to the windows box. see a different network that seems to map back to the original box. used mimikatz to get the PW of a different user, but don't see how to use it. tried ssh and rdp to the other 2 ips found from the windows box. Can someone help, pls?

vernal reef
#

ok bro thats

#

i am trying

vital adder
warm dagger
#

thanks @vital adder

warm dagger
#

@vital adder can i dm you?

vital adder
#

sure

tiny ember
#

Question about the Footprinting Hard box. ||Given that it states: Subsequently, this server has the function of a backup server for the internal accounts in the domain.
does that mean that previous users from the easy and medium box are relevant for this box? ||

fathom pendant
tulip pollen
#

In the module Public exploit I have a problem with the filepath i guess, someone can help me?

wheat belfry
#

Bro you are in the wrong directory
Try download in /dev/shm or /tmp

stuck hull
tulip pollen
#

I am using WordPress Simple Backup File Read Vulnerability y set the rhost good but I really can’t find the pathfile. I don’t know if I have a problem with the sploit or the path

rustic sage
#

Anyone which I can discuss about Responder in Attacking Active Directory module? It is not an issue, just a misunderstanding I think. DM me

stuck hull
placid quest
#

@rustic sage yes

tiny ember
fathom pendant
#

Enumeration itself just means gathering Intel

rustic sage
fathom pendant
#

^

placid quest
#

@rustic sage yes

fathom pendant
#

Nmap is an enumeration tool, so is gobuster, netcat, etc. Anything that can be used to establish/verify the presence of something is an enumeration tool

thorn urchin
#

Enumeration is King

vital adder
stuck hull
#

@tulip pollen You DMd me but I wasn't expecting it so it was just by luck I saw it. Copy your msfconsole options here, maybe someone can help

thorn urchin
stuck hull
#

I swear it's a rule as well.

thorn urchin
#

It is

#

if you cant enumerate server rules or a discord profile to deduce the best way to contact someone for help, how can you ever be able to enumerate a box for the best way to exploit it?

#

Enumeration is King

solar hound
#

Hey everyone. New here and I'm running into an issue with the unified box. Been stuck for about 2 hours now. Anyone have time to help, give advice?

stuck hull
thorn urchin
solar hound
#

Oh! Sorry about that, didn't see the academy tag. I'll give a better writeup in #boxes

granite patio
#

Could someone give me a bit of direction on Ambassador?

stuck hull
fathom pendant
granite patio
buoyant escarp
#

im currently in the assessment for command injection module.

the hint says: It is always easier to inject our command in an input going at the end of the command, rather than in the middle of it, though both are possible.

so i think i need to break the search/find command then || to my injection?

simple zephyr
#

in password attacks - attacking sam I completed the module but was getting access denied when attempting to run reg.exe save hklm\sam C:\sam.save

my question is, is there two ways to accomplish this take and I just didn't explore far enough doing it on the local machine or is doing it remote with a ||secret ||tool, the only way to do it.

thorn urchin
#

Someone can correct me if im wrong, but iirc reg.exe wont operate on the sensitive hives while they are in active use in memory. Hence you have to do a couple different workarounds to dump the hive.

#

theres more than one way, but reg.exe alone isnt one of em

muted comet
#

Confused on this question. "What is the full system path of that specific share?"

simple zephyr
#

ok cool just wanted to make sure when following the module i didn't do anything wrong

rustic sage
#

I need help

muted comet
#

I got this information but it says its not suposed to be a C:// but this is the only path i find for the share.

#

dont understand how its supose to be linux when it is windows destination...

#

can someone help

#

this is the SMB section of the foothold module

rustic sage
#

Can u guys find people

#

Off anonymous profiles

uncut meadow
muted comet
#

i got the answer

#

literally right infront of my face only had to delete the c:

#

lmfao

#

Yo is there ever any study sessions for people in the acaedmy

tiny ember
#

by study session do you mean a bunch of peeps quietly clicking on links and occasionally saying..."hmmm...."

stuck hull
tiny ember
#

Soooo looking for a hint for the Footprinting Hard box. ||Nothing to fancy, but something like which of the services is the jumping off point, 22, 110, 143, 993, 995... or none of these||

high totem
stuck hull
#

So the key is that the server is used as a managment server.

#

and remember Nmap scans TCP by default

high totem
tiny ember
#

thanks

#

always something simple 🤦‍♂️

simple zephyr
#

anyone see this with pypykatz

╰─ pypykatz -h ─╯
Traceback (most recent call last):
File "/usr/bin/pypykatz", line 33, in <module>
sys.exit(load_entry_point('pypykatz==0.4.9', 'console_scripts', 'pypykatz')())
File "/usr/lib/python3/dist-packages/pypykatz/main.py", line 16, in main
from pypykatz.kerberos.cmdhelper import KerberosCMDHelper
File "/usr/lib/python3/dist-packages/pypykatz/kerberos/cmdhelper.py", line 17, in <module>
from pypykatz.kerberos.kerberos import get_TGS, get_TGT, generate_targets,
File "/usr/lib/python3/dist-packages/pypykatz/kerberos/kerberos.py", line 11, in <module>
from msldap.commons.url import MSLDAPURLDecoder
ModuleNotFoundError: No module named 'msldap.commons.url'

fathom pendant
simple zephyr
#

nope

fathom pendant
#

There's an easy way; what can you do as user2

#

How do you check what user 2 can do

#

Because that's not what you're meant to do :)

fathom pendant
stuck hull
#

Currently working through Active Infrastructure Identification. The tool Aquatone errors out on installation, there is a github issue - however the project seems dead. Does anyone know of a replacement tool or a decent fork?

graceful rampart
#

The command given in the module wont work due to some changes in GO

graceful rampart
#

oh

#

that should work

#

What error are you getting?

stuck hull
#

the error is: invalid operation: cannot call non-function xurls.Relaxed (variable of type *regexp.Regexp)

graceful rampart
#

You installed the chromium-driver? And set you path to include $HOME/go/bin?

stuck hull
#

Yes. I've done both of those 😦

#

thank you

graceful rampart
#

lemme make sure it still works. I did that about 2 weeks ago but ive since ahd to revert to a previous snapshot

stuck hull
graceful rampart
#

Yea its not working for me now either

#

so something broke recently

stuck hull
graceful rampart
#

unfortunate

thorn urchin
#

Yeah Aquatone was dead in the water for me too

#

took a little fiddling to get Eyewitness working too

graceful rampart
#

Eyewitness has its own issues lol

rose gate
#

Hi guys, can anybody help me pls with ACTIVE DIRECTORY ENUMERATION & ATTACKS skill assessment part II at the question: "Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host."?, I found the credentials net***:D@ta*** but I can't connect to SQL01 host via mssqlclient.py, always I recive the same Error message: "error(sql01\sqlexpress): line 1: login failed. the login is from an untrusted domain and cannot be used with integrated authentication"; I have tried all possible methods (ssh htb_student@<spawned ip> -X, xfreerdp <spawned ip>, adding SQL01 IP to /etc/resolv.conf of the VM gived) but nothing works. Regards

stuck hull
graceful rampart
#

use something like sqsh and youll be fine

thorn urchin
stuck hull
graceful rampart
#

could be, but they specifically refuse to give instructions for that lol

obsidian prairie
#

Hi

thorn urchin
#

Sounds like someone needs to do a new rust replacement version of the tool 😉

obsidian prairie
#

hru guys?

#

@west rampart hey i have a question

uncut meadow
#

can somebody give me a hint for the footprinting smtp last question. I tried to bruteforce with a lot of username wordlists, with 3 tools but still stucked

fathom pendant
fathom pendant
stuck hull
autumn pilot
fathom pendant
#

Lol 3 people jumped on that xD

uncut meadow
#

wow hahaha

#

I didnt saw this wordlist hahahah

#

It can help

graceful rampart
#

Thats a common problem if you cant tell lol

thorn urchin
fathom pendant
#

Hey I have a question...
{20 minutes later}
So my question is...

tiny ember
#

what does the fox say?

stuck hull
graceful rampart
vital adder
west rampart
fathom pendant
#

Hi raccoon person

vital adder
#

isn't that a red panda?

fathom pendant
#

Listen I'm looking at it on mobile with bad eyesight

vital adder
fathom pendant
#

Upon further review; red panda indeed. Remediation steps: get glasses

rose gate
simple zephyr
#

I was able to get the password using Mimikatz locally on the box for Attacking LSASS but still cant figure out how to get pypykatz to work.

uncut meadow
#

thanks for the hint

thorn urchin
stuck hull
#

@graceful rampart Could I DM you about Aquatone?

graceful rampart
#

sure

red obsidianBOT
#

There is no need to use a VPN to connect for any of the CA Challenges, they are all accessible via the public IP's given when started. Not all challenges have an HTTP server however, some you need to connect via nc.

trim bramble
#

I'm pretty much a newby to this, currently im having trouble with this question:
Module: Linux fundementals.
chapter: system information
What is the path to htb-student's home directory?
I tried cd /home/username
$home
this did not work, anyone got some ideas, also please let me know in case this is the wrong channel.

thorn urchin
#

its a module so its the right channel

trim bramble
#

ah, thats good I did read the rules channel 3 times so I guess that paid off😂

gentle verge
#

@trim bramble the cd /home/username

#

is a command

#

to change the directory

#

and you need to send just the path of the directory

naive aspen
#

Anyone free to answer a question for the AD Enumeration & Attacks - Skills Assessment Part II? I've got the hash for CTXXX but I can't find a wordlist to crack it. I've tried rockyou and all seclist lists. Any help?

thorn urchin
fathom pendant
naive aspen
# thorn urchin rockyou should definitely be able to

Nope...

Session..........: hashcat
Status...........: Exhausted
Hash.Mode........: 5600 (NetNTLMv2)
Hash.Target......: CT059::INLANEFREIGHT:896549794fb4b8b5:79e7552af3b4b...000000
Time.Started.....: Fri Dec 30 21:55:30 2022 (23 secs)
Time.Estimated...: Fri Dec 30 21:55:53 2022 (0 secs)
Kernel.Feature...: Pure Kernel
Guess.Base.......: File (/usr/share/wordlists/rockyou.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#1.........: 639.7 kH/s (0.62ms) @ Accel:256 Loops:1 Thr:1 Vec:8
Recovered........: 0/1 (0.00%) Digests (total), 0/1 (0.00%) Digests (new)
Progress.........: 14344385/14344385 (100.00%)

thorn urchin
#

so

#

¯_(ツ)_/¯

naive aspen
thorn urchin
#

yeah I grepped the password to confirm it was indeed in that list

naive aspen
fathom pendant
#

It happens

rancid finch
#

this happens bozo

trim bramble
stuck hull
#

Such good input you have, so clever you are:

fathom pendant
rancid finch
#

that was my 13 year old little brother

rancid finch
#

why are you people want to learn to hack

fathom pendant
rancid finch
#

forkarth and marcie lee why do you want to learn how to hack

obsidian prairie
#

I will be a black hat hacker

rancid finch
#

i got someone that can help

obsidian prairie
#

And trolling

rancid finch
#

your not going to be a real hacker

fathom pendant
#

This isn't the place for Blackhat so if you're gonna do that, don't advertise it

rancid finch
#

shhhh

stuck hull
fathom pendant
#

🍿

rancid finch
#

poiuytrerw

#

[pokjhgfcdx

#

,mnbvcxz

#

no way i found out how to hack moonshynes account wow

#

he was rude

#

fgbnm,.

#

asdfvg

#

\\\\\\\\\\\\

#

sike

#

bozo

stuck hull
#

On the Active Infrastructure Identification module, do I need to do some setting up in the etc/hosts file to get the vHosts to work?

The question states Vhosts needed for these questions: app.inlanefreight.local and dev.inlanefreight.local

thorn urchin
#

@winged hedge hey can you deal with this person? they were trolling and spamming last night when mods were all asleep too.

rich vale
#

can anyone help me with the Skill Assessment for the AD module? specifically looking for advice on how to run tools like cme

thorn urchin
#

Recall lessons from pivoting module and set one up. I used chisel for most of both assessments

rich vale
vital adder
fathom pendant
rich vale
thorn urchin
#

ah oof

#

AD is about the biggest of a doozy first module you could do lol

#

its affectionately called the mid-boss of the CPTS course lol

rich vale
#

oh god lol

fathom pendant
#

yep

thorn urchin
#

either way, its a lot easier if you setup a pivot

fathom pendant
#

many people have spent DAYS in AD

rich vale
#

is it easier to use the parrot box provided by HTB?

thorn urchin
#

there will be a couple bits where pivot isnt enough, but most of the assessments can be done via pure pivots

fathom pendant
#

the pwnbox comes preloaded with all the tools from the modules basically; the downside is that the files don't save so if you want to reference anything from a previous module/day when you used the vm - what documents/downloads aren't there

#

but if you don't have the resources to set up a VM

#

¯_(ツ)_/¯

#

but afaik all the modules can be completed with the pwnbox as that's what they were tested on

thorn urchin
#

In fact I can only think of two instances in the AD 2 assessment where just using linux tools via a pivot wasnt enough to get the job done.

#

I did those assessments in the pwnbox at the time

simple zephyr
#

anyone around to talk through Attacking Active Directory & NTDS.dit, I am stuck on a part

rich vale
#

@thorn urchin does chisel work on the windows box? im gonna take a quick look at the pivot module, but trying to get a quick grasp on what would be executed from the windows machine nvm got my answer

stuck hull
solar zodiac
#

has anyone had any success with CME's rdp protocol?

#

it just gives me false negatives

#

not quite sure why

tiny ember
rich vale
#

hmm got my connection established on chisel, but not sure how to confirm that it works. just throw cme at it maybe?

winged hedge
thorn urchin
rich vale
#

err actually, dumber question, how do you quit chisel without killing the shell?

#

ctrl+c wants to kill the shell

fathom pendant
#

Quit;exit?

#

Either of those?

broken warren
#

For the Footprinting module, first lab skill assessment. Am I supposed to edit MY configuration files? Or the servers? I'm not sure where to start to be honest 😅

stuck hull
stuck hull
#

Treat it like a machine that you're trying to access

atomic ruin
simple zephyr
#

I got pypykatz to work. I had to remove it and then reinstall it with their setup.py and not use the pip installer.

fathom pendant
#

Nope

#

If it works, it works

#

That's part of thinking outside the box

broken warren
fathom pendant
#

Regarding the service you're referring to

atomic ruin
#

Or have you jumped straight into the Skill Assessment without reading anything before? Because that wouldn't have any bullet points, but it would also explain why you're so confused about what to do

thorn urchin
#

copy and pasting b64 encoded binary blobs as data transfer has been a thing since the 90s. So def just as valid as what youre doing.

broken warren
rich vale
#

@fathom pendant i did try other ways to quit btw, but no luck. ended up just ctrl+c and starting a new session