#modules

1 messages ยท Page 37 of 1

atomic ruin
#

Fair enough, so I got confused about what you were talking about, ignore all that I've just said, and think about what you can do and where to get access to it, and what access you would need for it

fathom pendant
#

Remove the credentials in your message, that is considered a spoiler

broken warren
#

It's given in the hint

fathom pendant
#

the hint is just a hint but isn't needed afaik to get that info

#

But is still a spoiler

#

As it's not in plaintext directly on the page without interaction

broken warren
broken warren
fathom pendant
#

But it's not required to hit the hint button

frigid summitBOT
#
0860#5349 has been warned

Reason: Bad word usage

thorn urchin
#

cross compile

#

youre not who the bot tagged

#

if you have access, you can always upload

#

it may be a pita though

#

million other ways to file transfer

#

depends on the situation

#

the File Transfer module goes over a bunch of common ways

#

id suggest doing that

#

the getting started module shouldnt require any uploading of exploits

#

if youre trying something like pwnkit, that was discovered after the creation of the box and is an unintended path

#

you dont have to compile code for that one

#

searchsploit will tell you unintended paths too

#

idr the exact path cause its been a few months, I distinctly remember not needing any code compilation though

#

and even if code compilation was required, HTB would definitely provide gcc and the likes for a beginner module

#

also that one is ssh, you should be able to scp if you really wanted to

#

yeah definitely an unintended route

#

the intended path is much simpler

#

idk what you mean by ssh method lol

#

ssh is given to you by default lol

#

ah, you mean searching for ssh keys

#

yeah, always a good thing to look for, esp with multiple users on a box

#

well, dont always think you have to aim for root right away

#

the section objective is to settle for user2

fathom pendant
#

But look at what user2 can (su)do

thorn urchin
#

ah thought you were still working on that part

#

gotcha

fathom pendant
#

That's my biggest hint iirc that pushed me in the right direction

thorn urchin
#

honestly might be too much of a hint imo lol

fathom pendant
#

I mean it still took me an hour after getting that hint I think

thorn urchin
#

but its also a basic thing to always check so meh

fathom pendant
#

You shouldn't be denied sudo -l as user2 I don't think unless I'm thinking wrong

#

I'll have to revisit that

thorn urchin
#

just checked

fathom pendant
#

Ohhhh I remember now with this one

#

You're right

thorn urchin
#

okay yeah confirmed the route was the one I was originally think

#

google sudoers

#

it depends entirely on how that file is configured

fathom pendant
#

Anyway some exploring may help :)

thorn urchin
#

sudoers is the config file that dictates the results of sudo -l

#

<@&861185840277487616>

little whaleBOT
#

@rustic sage (803120787711066153) has been muted for 2h.

urban sage
thorn urchin
#

ofc

minor pelican
#

keep it up! Its a great feeling to feel your progress!

tepid thicket
#

Are there issues with windows privesc skills assessment currently? I've restarted the machine multiple times and switched vpn server/redownloaded vpn file and still can't connect to the target machine from my vm

minor pelican
#

Are you a student?

#

thats good then! Its such a life saver with the student subscription!

fathom pendant
tepid thicket
fathom pendant
#

Yes and ok. You'd be surprised how often that's the answer lol

tepid thicket
#

lol ๐Ÿคฃ

fathom pendant
tepid thicket
fathom pendant
#

Are you able to ping it?

thorn urchin
#

personally im sus of anyone these days offerring to be a tutor

fathom pendant
#

Also after resetting the VPN key, reset the box

thorn urchin
#

either someone likes to help so they just help when they can, or theyre trying to grift something from ya. Imo at least

ripe terrace
#

The HTB Academy is your tutor ๐Ÿ˜‰

mental nova
#

Can anybody gift me nitro i really really want it

mental nova
buoyant escarp
#

finally

mental nova
#

can you buy me nitro please

buoyant escarp
#

wtf

#

i dont even have it

mental nova
#

oh sorry

ripe terrace
# mental nova Hey

Why not use some of your millions?

๐ˆ'๐ฆ ๐ฌ๐ฆ๐จ๐ค๐ข๐ง' ๐ฅ๐จ๐ฎ๐ ๐ฉ๐š๐œ๐ค ๐ฐ๐ก๐ข๐ฅ๐ž ๐ˆ ๐ฌ๐ฉ๐ž๐ง๐ ๐ฆ๐ฒ ๐ฆ๐ข๐ฅ๐ฅ๐ข๐จ๐ง๐ฌ๐Ÿšฌ

tepid thicket
tepid thicket
thorn urchin
fathom pendant
rich vale
#

okay so, for AD skills assessment, trying to use metasploit autoroute now and not having any luck

thorn urchin
#

I used chisel and life was a breeze

rich vale
#

i was trying that as well, but i think im having a different issue

#

i dont think i have the right IP of the target

#

or at least, im not seeing the correct machine from my shell

#

i know i have creds for a sql admin that i can see in bloodhound, but not seeing the ip of the machine to target

sonic wyvern
#

CROSS-SITE SCRIPTING (XSS) - Phishing
I'm still stuck on that
How can I inject HTML to the page, I still didn't find an exploit

iron basin
#

Can anyone help me understand this net stat output on a raspberry pi I am running?

rustic sage
#

Is anyone good with hydra and can help me with the Password Attacks - Password Mutations Challenge?

#

My box keeps timing out (after 90 mins) before the password is cracked. I've set it to -t 48 but still no luck. I can't see in the documentation how to set a minimum password length without also having to state exactly which characters to include (i.e. /!@# etc.).

#

I can't use the -R function as the IP is different each time the box times out. Is there a way to get it to resume a previous attempt but with a different IP address?

rich vale
#

for the AD skills assessment, I know the next box i need to touch, but didnt see it in my ping sweep... can anyone tell me if its outside the /24? wondering if i need to sweep a full /16 for it

sonic wyvern
#

Dm me also if you know XSS, haha

#

helppp

reef knot
#

Any nudges? I'm on Password Attacks -> Password Mutations. I'm using the VM. I made the mutations list, cut the first 17k entries like suggested above. The VM STILL says it will take hours to complete. I've tinkered with the threads to get it down to two hours, which potentially will have the VM time out first...

I've done the theory/work part of it and can make/use combined lists. But is there anything to do to speed it up? (ncrack was even slower)

#

Heh, and the VM just died again.

fathom pendant
reef knot
#

I keep using it and keeps terminating

fathom pendant
#

if you can; cut that smaller list into even more cut up lists if it's really taking forever;

#

huh i looked up how the example in the getting started/public exploit works and managed to actually do it manually without needing msfconsole... neat

reef knot
#

yeah - might need to do that - I might just try from a kali box tomorrow and see if that goes faster.

fathom pendant
#

also was it 17000 or first 1700

#

I honestly forgot lol

crimson patio
#

(ISC)ยฒ certified in cybersecurity certification is worth its 50$ ?
Will it make any difference in my resume or will the HR notice it ?

fathom pendant
whole sigil
#

After gaining access to Windows PC from Kali, I want to transfer some files (for example output of winpeas) back to kali. How to do so?

sonic wyvern
#

Can someone help me to fix ffuf: command not found ?

#

How do I add that to the variables on my machine

bronze shell
#

good evening so im in the web enumeration of th egetting started module and im havinf an issue with getting the flag. how do i get the Robots.txt file?

rich vale
candid zephyr
#

The ad module assumes you're comfortable with pivoting.

rich vale
#

right yeah, thats what I mean, from the box with the internal network that can hit ms01 and the dc

#

learning the hard way on the pivoting, but i assumed that id see the box on the internal, but i also only checked /24

dire eagle
#

Clearly I'm stupid. File Inclusion "Fuzz the web application for other php scripts, and then read one of the configuration files and submit the database password as the answer" curl ip:port/index.php?language=php://filter/read=convert.base64-encode/resource=configure.php, en.php, es.php, index.php, flag.php, and config.php do nothing.

#

blank box

#

if I change the first index in index.php? it's all blank.

candid zephyr
rich vale
candid zephyr
rich vale
#

@candid zephyr thanks, that helps, thought i was going insane comparing what i found in bloodhound vs what i saw on the network

#

ill pick it up tomorrow

fair spear
#

@Pwning#6898

feral stump
#

Hey! Iโ€™m totally desperate with mutated passwords

Have run everythingโ€ฆ hydra, medusa, Crackmapexec, ncrack

Have removed thousands of lines based on attempts and nothing!!!!!

#

Any help pls?!

proud pine
#

Isn't that the one where you need to remove like 90k lines?

feral stump
#

The mutated list has 92400 aprox

heavy dome
#

Hi everyone! in the Footprinting - Medium Lab module|| i found alex's credentials and sa knows by connecting in rdp, unfortunately i can't with these credentials access the MSSQL database and i'm in a dead end||...help! Thanks!

stuck hull
heavy dome
stuck hull
heavy dome
velvet galleon
#

Hi
im busy with theJavaScript Deobfuscation module, (cracking into HTB)

on the decoding section, where ive sent the server a POST request, its given me an obfuscated text.
ive confirmed its Base64, and decrypted
it with the base64 -d command, which gives me the below flag:
7h15_15_a_s3cr37_m3554g3

but the module wont accept this as the answer, am i doing something wrong?

grim zenith
#

What does one do if their academy account got so messed up to the point that they cant contact support there?

velvet galleon
#

... you reach out to the support in discord.

grim zenith
#

What channel

velvet galleon
glass tapir
#

Hi everyone. Can anyone direct me to the PROLABS APT HTB GROUP?

velvet galleon
high totem
#

Hey everyone, I have a question regarding the Attacking Common Services, SQL part. I've stolen and cracked the hash for mssqlsvc, but cannot figure out how to enumerate the flagDB. I tried using the credentials for mssqlsvc to login to the db and rpd, but login fails for both. I can log in as htbdbuser, but this user cannot impersonate :/
Any nudge?

proud pine
novel matrix
wintry gorge
#

can anyone help me with the Bloodhound module skill assessment?

rustic sage
#

sudoooo

stuck hull
#

I'm doing the Virtual Hosts module, and I think I have a conceptual misunderstanding about IP-Based Virtual hosting.

The question says that different servers can be addressed under different IP addresses, but if you have a separate IP address, would you not also have a server for that? And therefore it wouldn't be a virtual host...

#

The name based virtual hosting makes sense intuitively but I am struggling with understanding the IP based virtual hosting.

floral sandal
#

I ran sharphound on windows domain controller and collected data, but how to transfer it to my kali attack box to view it in bloodhound ?

graceful rampart
#

With whatever file transfer method you choose?

floral sandal
#

Any method

#

I just want download it from the DC

graceful rampart
#

Well I mean, assume you're doing the modules in order you shiuld have already done the file transfer module

#

You should have a bunch of file transfer methods in your back pocket

#

Pick one and transfer the file lol

glass tapir
wintry gorge
candid zephyr
#

You need to verify

graceful rampart
candid zephyr
#

How do I call the bot? Can I?

floral sandal
glass tapir
#

Ok thanks. Let me verify now

glass tapir
#

But still cant find PROLABS APTLabs

autumn pilot
glass tapir
#

Ok thanks. Got it now. Will have to do it from HTB website

hazy grotto
#

Happy New Years everyone!

candid zephyr
#

wow wtf sliver creates 16mb payloads HYPERLUL

graceful rampart
#

Lol

opal prairie
#

guys im new to programming which language should i learn first

candid zephyr
#

srsly tho what do you want to even do?

opal prairie
plain coral
candid zephyr
stuck hull
opal prairie
#

just tryna learn the basics

candid zephyr
opal prairie
#

ok thank u

graceful rampart
# opal prairie ok thank u

You can by all means start off by learning programming. Lots of people in cyber security start off studying computer science. But Luke cack said, it's very very important to have an end goal. Cyber Security is an absolutley massive, and ever growing and changing field. It's is absolutley impossible for one person to learn all of it and thus it's very important to define your end goal before you really start studying

#

Otherwise it'll feel like you're running in circles and constantly not making any progress

opal prairie
#

ok thank u this is very helpful

graceful rampart
#

Np

candid zephyr
fierce rivet
#

What are your favourite attacks in hacking?

#

My fav is MITM

graceful rampart
candid zephyr
graceful rampart
graceful rampart
fierce rivet
polar widget
fierce rivet
#

Hey guys please suggest me a C|EH V11 course which is not too expensive. i know a lot about hacking but not that much

#

I'll send you my course outline where i have taken the course

#

So you can suggest

#

I can't attach file

stuck hull
candid zephyr
brisk geode
#

hey can anyone help me with the What is the admin email address? IMAP/POP23 in foot-printing module? i have no clue how to get that i have completed all other qustions

high totem
#

Hey everyone, I'll repeat my question regarding the Attacking Common Services, SQL part, because I still cannot solve it. I have cracked the hash for mssqlsvc, but cannot figure out how to enumerate the flagDB. I tried using the credentials for mssqlsvc to login to the db and rdp, but login fails for both. I can log in as htbdbuser, but this user cannot impersonate :/
Any nudge?

sweet citrus
#

So I just need help , I learn cause of mony , on the other hand I don't know what I need to learn so I start with learn some network and programming language Java, the I go to tryhackme and do solve the machines

#

But I feel like script kiddy

#

And I don't know how to out of that

#

Also is problem solving skill is important in this field or not

#

Hope some gave me answer

high totem
#

OK, I was able to connect, but only with sqsh. Now however I get no output. Like I type a query, type GO and it's giving me 3> and 4> and so on :/

EDIT: ok, for some reason GO was not accepted, but go (lowercase) was -.-

sweet citrus
#

It's just programming

stuck hull
#

It's been eye opening as to how little that knowledge has helped me as I learn more through the modules.

sweet citrus
feral stump
#

hey there is something i am not gettin right in Password Reuse and Default Passwords

#

so I log in with the ||previous credentials found for sam||

#

I create a list for the users i find when i connect to ssh and add ||root and admin with the previous credential and without password for each of them||

#

next step is ||running hydra against mysql with that list||?

#

I am confused appreciate some help

graceful rampart
graceful rampart
graceful rampart
feral stump
#

yeah ๐Ÿ™‚ I am going through it to see if i am missing any default creds

stuck hull
#

How did you get those boxes behind the individual notes?

wary stump
#

is there any way around to install crackmapexec without troubleshooting 1 day?

#

its not possible to install this tool on parrot

#

ok solved. uninstall parrot and use hl-livecd from compass (for me the best) and crackmapexec is working without issue

shadow verge
wary stump
#

unfortunately not working. i got 20 python error messages

#

tried also with pip and pip3

#

but in kali no problem

#

but thanks for the help

shadow verge
#

Did you use instructions from crackmapexec module?

wary stump
#

yes tried everything i found

#

my vm crashed today ๐Ÿ˜ฆ

shadow verge
#

did you try poetry?

wary stump
#

yes and after starting the poetry shell i got the same python errors

#

tried to fix it but no step helped

shadow verge
#

it works fine for me

#

just installed it

lethal latch
#

Super awesome module, had a blast going through this one.

tiny ember
#

Can someone give me a hint on the Footprinting Hard box. ||I've got the ssh key and got into the box but can't find the mysql password for tom anywhere. Based on bash_history it looks like it should be in an email in the Important folder but nothing there. Nothing else in the mailbox folders. Email headers referred to a missing mailbox and domain, but no other users on the box have a mail directory. what am I missing here?||

stuck hull
#

Have you found the sa credentials?

tiny ember
#

only tom's creds

#

or bob

stuck hull
tiny ember
#

yeah, that was the medium ๐Ÿ™‚

stuck hull
#

I'm sorry my memory is woeful and apparently my note-taking while doing that box, have you tried his credentials on the sql server?

tiny ember
#

yeah they are a no go

#

omfg

#

it worked when i hand typed it

#

FML!!!!

#

fucking HHHHOOOOURRRRS!

stuck hull
bleak escarp
#

Hi, this where we ask for help? ๐Ÿ˜…
I'm running the blue machine for eternalblue but it's buggy as hell, the exploit sometimes work and sometimes don't and meterpreter commands doesn't work

tiny ember
#

annnnnnd box done

graceful rampart
rustic sage
#

has anyone done the sqlmap module? Need a bit of help on Case#10

forest shoal
rustic sage
#

yeah, but I've probably got it wrong. Can I dm?

forest shoal
#

sure

vocal vortex
#

trying with the exe version of proxifier seams to be working

dim hemlock
#

Hi all. I hope you are well... Im currently stuck on a question from: Active Infrastructure identification

#

Which CMS is used on app.inlanefreight.local?

#

I got all the other quesions but I cannot figure this out

dim hemlock
#

I was trying with WhatWeb

stuck hull
#

What was the output?

dim hemlock
#

Can I PM so I dont spoil?

stuck hull
#

sure

ruby elbow
#

Hi everyone! how you doing? Happy new year!

I am stuck in the assessment of the file upload attacks module.
I cannot find the files I upload.

I believe I am constructing the path and the filename right, dunno whats happenin

Thanks in advance!

viscid furnace
#

Hi, I need a little nudge on 'Attacking Common Services' - Easy skills assessment - I found a username via SMTP brute forcing but thats about it

candid sandal
#

Guys, I'm a bit confused : what is the address that I'm supposed to give to metasploit so that it gets back to me with a reverse shell when I'm listening with nc

#

What is my 'public' address

fathom pendant
candid sandal
#

I am, if I use ipconfig on windows I am given an IP address and I am connected. But I'm working with the WSL2 and Kali, and I believe the problem may come from here

fathom pendant
#

no

#

In Linux do ip a

candid sandal
fathom pendant
#

In metasploit the reverse IP is going to be LHOST option and if you're using nc you wanna specify the LPORT

candid sandal
#

I know, but my question was : what is the IP address that I should give as LHOST

#

I believe it is the 10.10.14.116 that I've been given by the VPN right ?

#

But why doesn't it appear when I do a ifconfig in kali ?

fathom pendant
#

Again are you connected to the VPN in Kali?

#

Also in Linux you've done the ip a command yeah?

candid sandal
fathom pendant
#

No, the boxes are meant to be accessed through the VPN as they are "offline" boxes

#

With the only access being the VPN tunnel

#

Because the box you're using does not register you're routing through the VPN if you're doing it on your host machine

candid sandal
#

I see, so that means I need to connect to the VPN not on windows but within kali itself

fathom pendant
#

Yes

#

The only reason to do it through windows would be if you were attempting to run these exploits as a windows user i.e. using the command prompt... Which that is not fun

#

Terminal is nicer

graceful rampart
#

Or if you're doing some advanced red teaming or evasion and need to blend in to the environment

#

Also there are some things that just generally interact with windows better than linux

candid sandal
#

I understand, thank you very much for all of your responses

woeful mural
#

Anyone here finished shells and payloads module?

hazy grotto
#

Should have went to Jared

#

LOL You are everywhere my friend. I love you

unique valve
#

A portrait of @west canopy

thorn urchin
#

Im pretty sure part of his actual job is academy community liaison or something like that lol

rustic sage
#

anyone here done file upload whitelist filters?

graceful rampart
#

It's called an educated guess

vital adder
#

oh wait miss remember the cred was nip*

vital adder
tiny ember
#

I'm on the Information Gathering - Web Edition module (144) Active Infrastructure Identification Section (1255). What is this vHosts tool they are referring to? I see a lot of different referernces online for this. Its mentioned passive section that "Bing virtual hosts search." Is that the correct tool? seems odd for an domain that is local

thorn urchin
#

yeah unfortunately it just hinges on guessing the password. Not a fan either myself, but somehow thats just how it is

tiny ember
vital adder
fathom pendant
thorn urchin
tiny ember
#

ahh, never done that, i'll look it up

fathom pendant
#

ye

#

it's a useful thing due to how often it's used

thorn urchin
#

think of a vhost as just being another domain an IP address can have. A webserver checks the vhost when receiving queries and may serve up entirely different webpages and applications based on the vhost. This is how shared hosting servers work.

vital adder
tiny ember
#

ahh

#

kk

fathom pendant
thorn urchin
#

adding a provided vhost to /etc/hosts is a common thing for ctf boxes, because often ip addresses are internal so a public dns server couldnt resolve it, and spinning up a whole extra dns resolver box for a ctf lab environment is a ton of extra unnecessary work

vital adder
tiny ember
#

cool

#

thanks all

fathom pendant
#

imagine blocking out localhost :^)

tiny ember
#

well... its literally a chat group of hackers so.... never can be too careful

fathom pendant
#

bruh

#

127.0.0.1 is localhost/loopback 127.0.1.1 is also a localhost

tiny ember
#

one of them is my host name for my computer ๐Ÿคท

#

127.0.1.1

#

anyway

fathom pendant
#

either way neither are public IPs

tiny ember
#

aware ๐Ÿ™‚

atomic ruin
#

can I get any nudge on footprinting labs - easy? Got the Username, but can't get the password out of it ||trying to crack it but tried all the password lists in the folder with no luck, and bruteforcing would take days||

#

I can do it with the hint, just trying to figure out where that info comes from

fathom pendant
#

yeah that's something i need to spend time on when I revisit it

tiny ember
#

I would love this information as well

fathom pendant
#

not sure if the footprinting provided list is just usernames or not

atomic ruin
#

just usernames yes

#

But I already have the username, and "know" the password. But not sure on the intended method to get it

#

oooor if I just fucked up my commands somehow ๐Ÿ˜…

zealous swallow
#

A question can be made a brute force attack on a hack machine the box?

crude carbon
#

hi everyone!

rustic sage
uncut meadow
#

@atomic ruin how did you find the username??

atomic ruin
#

PM to avoid posting spoilers here

uncut meadow
#

ok

stuck hull
atomic ruin
#

Hum, I might have fucked up the comand then. tried literally ALL lists, no hits

stuck hull
#

There was an argument being made that the 'hint' should just be moved up into the the question prompt

#

I never confirmed that for myself, it was just mentioned in the discussion.

hazy grotto
#

Anyone give me help on PW attacks medium lab? I've cracked to docx..... Im not sure where to go from here. I've smb'd into IPC$ but can't figure out what to do.

fathom pendant
#

you're not giving much info for what you're asking

zealous swallow
#

opss sorry

atomic ruin
#

and it's also on rockyou, was just checking that with @uncut meadow

#

so I messed up somewhere

fathom pendant
#

i'd say this is spoiler but it's also a headscratcher lol

zealous swallow
#

A question can be made a brute force attack on a hack machine the box?รง

atomic ruin
#

because I'm not picking it up

stuck hull
fathom pendant
#

because the hint needs to be interacted with; i'd still say spoiler -

fathom pendant
dim hemlock
#

Hiiii

#

Happy new yearrr

#

Stuck on my first question for the new year haha

#

Perform subdomain enumeration against the target githubapp.com. Which subdomain has the word 'triage' in the name?

fathom pendant
dim hemlock
#

Do you know what im doing wong

#

Im trying to use NSLOOKUP

stuck hull
dim hemlock
#

Hmm havent tried it

#

Let me seee

hazy grotto
#

How does someone decrypt a docx file if they have the password?

atomic ruin
#

Running out of ideas of where I messed up, if someone can get the pasword somehow please let me know

stuck hull
vital adder
vital adder
atomic ruin
hazy grotto
vital adder
#

with microsoft word?

vital adder
stuck hull
atomic ruin
#

Yeah that was the point. We know how to get the username, just trying to figure out the intended way for the password

vital adder
#

i think with stuff like this that's unintended because if the intended way is brute force the section didn't give you any thing (not even a hint for the wordlist)

#

so without the hint you have to blindly brute force with random wordlist until you get a hit

hazy grotto
#

all i have is subl vim and gedit.

Tried downloading openoffice but i cant seem to get it to work.

vital adder
#

how tf can you open a docx file with vim or gedit ๐Ÿคฃ

hazy grotto
#

cuz i'm an idiot

vital adder
#

but try with firefox it worked on my main host

hazy grotto
vital adder
#

yep

#

oh wait i don't think i did try with docx

#

it work fine with pdf

stuck hull
vital adder
vital adder
#

@atomic ruin shoot me a dm i'll recommend the wordlist (for the both username and password)

#

also because this is htb you can still kinda make an educated guess (based on htb pass stuff) for the wordlist

atomic ruin
#

I already got the wordlist, but the software I'm using is not picking it up

stuck hull
atomic ruin
#

still didn't try hydra, was trying with hashcat first, but yes please

hazy grotto
#

For the life of me i can't get libreoffice to work.

wheat garden
hazy grotto
#

kali

#

I think i messed something up. I tried getting openoffice to install. that iddn't work. installed libre.. it installed but would never load. Tried uninstalling openoffice and trtying to install libre one more time.

rustic sage
#

Could someone help with the last very part of SQLMap ? Flag 11. Just think i might have gotten a bit mixed up with syntax or calling a wrong script.

||sqlmap -u http://167.172.55.94:32207/case11.php?id=1 --tamper=space2comment --batch --union-cols=9 --dump -T flag11 -D testdb --level=5 --risk=3 -v 3||

Returns: ||[ERROR] unable to retrieve the number of columns for table 'flag11' in database 'testdb'||

hazy grotto
#

Who knew install a word program could be harder than the password attacks module itself

#

RIP

wheat garden
#

sudoย apt-getย installย libreoffice

vital adder
hazy grotto
vital adder
#

maybe but i'm note sure

hearty nova
#

Hey i know this is a random and dumb question but how do i change my pfp on hack the box academy

sly tapir
#

@vital adder what program/app do you use to take notes?

vital adder
sly tapir
graceful rampart
hearty nova
hearty nova
#

i kinda like having a physical copy

vital adder
rustic sage
vital adder
#

sure shoot me a dm

hazy grotto
graceful rampart
# deft mango Notion

I used to use notion. Decided I'm not a huge fan of all my notes being in the cloud. Now I use obsidian with everything stored on an encrypted external harddrive

vital adder
graceful rampart
#

How'd you mess that up???

#

Then you can open the word files with Libre office writer

hazy grotto
#

So i first installed open office

hazy grotto
hazy grotto
#

Then tried removing open. reinstall libre

#

nothing is working but i got the file to open via a free online editer. I'm going to have to get some help later to fix this libre/office problem I think im going to call it a night and hit the bar up... Happy new years yall

graceful rampart
#

^^^

hazy grotto
#

Boys ive told you before. I'm an idiot. My only experience with linux was HTB. When it comes to installing things. I'm special needs. Theres something definetly wrong. I followed the offical instructions. Got it to load. I tried opening it with libre, tried opening libre write gui style. Just wont load. it's like something is broken in the settings and i couldn't really figure out how to uninstall. I've been working on this module for 12 hours day. Made some good progress but my brain is shot and i don't think i'm able to think clearly anymore so i'll call it a day. Thanks for the help everyone.

#

HAPPY NEW YEAR! Hope all of you get laid or crack a box! Peace!

graceful rampart
hazy grotto
#

I could have. but im stubborn and despite it being a headache... It's a learning experience.

graceful rampart
#

True

hearty nova
#

basic linux commands and stuff

hearty nova
hollow hazel
hazy grotto
hazy grotto
stuck hull
hazy grotto
hollow hazel
#

Ez dubs bro

wheat garden
hollow hazel
#

The kernel team is currently working on it.

wheat garden
atomic ruin
wheat garden
#

lol dont actually do this for the noobs. This will wipe your whole linux system

hollow hazel
#

Lies

#

Gives you more ram

#

๐Ÿ˜ƒ

little whaleBOT
#

Please see your DMs for instructions on how to verify your HTB account.

hollow hazel
#

I am trying to crack a hash on pwnbox but it looks like I don't have enough memory on my machine

novel matrix
hollow hazel
#

Got it.

hazy grotto
#

You said i can ask you anything.

hollow hazel
#

Yes. I'll help for reals instead of trolling

hazy grotto
#

Who hurt you?

#

That's my question?

hollow hazel
#

Oh shit. Did you actually do it

hazy grotto
#

Was it your dad? Your grandpa? Your uncle? Because you should see someone about the trauma you experienced as a child.

#

No i googled it first....

hazy grotto
#

But seriously please go seek help.

hollow hazel
#

Ok good. That would make me feel bad haha

hazy grotto
#

That kind of abuse will catch up to you in the end.

hollow hazel
hazy grotto
#

@novel matrix Why wouldn't you ban this guy right away?

hollow hazel
wheat garden
hollow hazel
#

Will just shitpost. not troll.

#

promise I will abide by rules. Am sorry for pushing the envelope.

novel matrix
#

Keep this on topic please and this can be taken to DM's.

hollow hazel
#

Gotcha

hazy grotto
novel matrix
novel matrix
#

Tun0 is your VPN ip

#

Then you want to setup a listener
nc -lnvp 8443

#

You

#

Yeah

#

Go back over the section of the module

rustic sage
#

Well guys tell me smth i dont want to be banned

#

If i ask someone to hack someone roblox account i Will be banned?

#

Okey ty

#

I want to learn but idk how to start

#

Ty

novel matrix
thorn urchin
#

it looks like your actual script is busted

#

hard to say for sure

#

also is this a cronjob thats being executed or do you just have sudo perms to it

#

cause if youve got sudo perms, no need to reverse shell, you can just drop directly into a shell

#

You need to focus more on understanding why, and less on rote repetition

balmy radish
#

Did you create a copy before you appended? Check the script and make sure it just has the one line you want to add at the end as the difference

thorn urchin
#

The lab says revshell but thats utterly unnecessary in this scenario

#

Well I point it out cause dropping into a regular shell would be easier than getting a full working revshell

#

but a revshell would be more appropriate for say a cron job

#

just a simple

echo "/bin/sh" >> monitor.sh

ought to do the trick off the top of my head

thorn urchin
#

cause with a cron job you dont have control over it starting, so you wouldnt be able to interact with it unless you did a revshell. Though, theres other payloads you can do too.

As for why not revshell everything youve kinda already stumbled into why. Sometimes theyre not stable or they can be finicky. Its also an extra network connection going out over the wire, which can have opsec and detection considerations.

#

I just personally dont like creating unnecessary extra connections.

hazy grotto
#

Can anyone give me a a hint on medium lab on PW attacks?

I ssh'd as the J user. Can't seem to find anything of value. The i tried oing to the urls in the docx and nothing showed up .

graceful rampart
hazy grotto
#

systemctl?

graceful rampart
#

No

#

Some ports are only open locally

hazy grotto
#

Thanks boss

graceful rampart
#

Np

hazy grotto
raven cairn
#

What module are you on?

violet axle
#

The last question from the "Password Spraying" section in the CrackMapExec module wasn't responding as expected. I'd only get errors. Is it possible for someone to confirm the mssql query can be done?

#

It error's with confirmed credentials, NULL session and failed credentials.

hazy grotto
hazy grotto
#

I should say PW attacks has been the most enjoyable module ive done but the hardest thing i've ever done in my life.

raven cairn
#

Oh bro I havent done that one yet

hazy grotto
#

What are you working on?

raven cairn
#

I was doing AD enumeration and attacks but I think I am going to take a break from it

#

Itโ€™s lots of information to absorb

hazy grotto
#

lol

fathom pendant
#

I'm using redoing my notes as a "break" from progressing in the path as it lets me kinda walk back and refresh/strengthen my knowledge

raven cairn
#

I think they should split it up into 2 or 3 modules

hazy grotto
#

Well I heard its tough. I'm surprised you skipped over PW attacks

flint depot
#

hi

#

im new, how are you guys doing?

fathom pendant
#

studying is just a mix of the words 'students dying'

flint depot
#

oh

#

never though of that

fathom pendant
raven cairn
#

Mods will get mad if you go off topic for 2 seconds

hazy grotto
raven cairn
#

Damn dude!!!

#

Thatโ€™s some dedication

#

Take some healthy breaks bro

fathom pendant
#

sometimes the answer comes after you step away for a bit and refresh yourself

hazy grotto
#

Well actaully. I did two sections starting easy lab, halfway throught this lab. Total 17 hours today

raven cairn
#

Holy shiiiiiiii

vital adder
hazy grotto
fathom pendant
#

I asked the manager at my local Dollar General to order an additional case for me :) easiest $60 ever (24 to a case)

candid zephyr
rich vale
#

after hours of mistakes, i managed to get Enter-PSSession to work in the AD skills assessment

#

is the powershell session when using Enter-PSSession any different from normal? the regular commands dont seem to work the same way but sounds like they should

fathom pendant
#

wow after redoing the nibbles test box my notes made things super easy p =p

tiny ember
#

So figured out how to get the initial foothold on the easy box for Footprinting after going back. ||There is a password list that has the creds (which i'm guessing there are quite a few lists that have it given what it looks like) so my guess is a brute force attack is needed. The picture is an example method of how it would have been done. I put in the proper creds, but the user would have been gathered from the port 2121 enumeration via nmap which showed the possible user name for the server name (Ceil's FTP). The tool accepts a list as well for both user and pass. https://salsa.debian.org/pkg-security-team/patator||
||```
โ””โ”€$ patator ftp_login user=ceil
password=qwer1234 host=10.129.42.195 -x ignore:mesg='Login incorrect.' -x ignore,reset,retry:code=500 --timeout 120
01:08:43 patator INFO - Starting Patator 0.9 (https://github.com/lanjelot/patator) with python-3.10.9 at 2023-01-01 01:08 PST
01:08:43 patator INFO -
01:08:43 patator INFO - code size time | candidate | num | mesg
01:08:43 patator INFO - -----------------------------------------------------------------------------
01:08:51 patator INFO - 230 19 0.168 | | 1 | User ceil logged in
01:08:51 patator INFO - Hits/Done/Skip/Fail/Size: 1/1/0/0/1, Avg: 0 r/s, Time: 0h 0m 8s

plucky falcon
#

does HTTP Proxy Post Request Relaying vulnerability comes under VRT Server Security Misconfiguration > Web application Firewall (WAF) bypass > direct server access category?

quasi moth
#

Hello, can somebody help me in file upload => skills assessment. I have found the right payload, but I can't find the upload directory and can't see the answer for my payload. There are only base 64 encoded code

feral stump
#

hey cant help you with your question @quasi moth but have you completed pwd attacks by any chance?

feral stump
#

ok thx

thorn urchin
#

cause you may be accidentally trying to do the second half while missing out vital info on the first half

quasi moth
#

I have searched in forum and find out hint to XXE, and I could look for /etc/passwd

#

But now i don't really know where are path to upload.php

thorn urchin
#

occams razor says its likely to be in the same directory or one close. Dont need full path.

feral stump
#

hey @thorn urchin I have a question on password attacks default credentials? By any chance can I get some help from you? Thx!

little whaleBOT
#

I don't know what role that is. Did you spell it right?

thorn urchin
#

not the channel for this

thorn urchin
thorn urchin
#

but you can always just ask your question anyways, lot easier to get an answer from someone that way

feral stump
#

sure

#

so basically i can ssh with the creds that i need into the target... it asks then to find the MySQL user and creds and in the section there is a githug repo link for default credentials.

#

now when I am connected in ssh and I try to connect to ||mysql with the 3-4 default credentials it says it's unsafe to write the credentials in clear text||

#

I have also tried to use ||hydra not being connected through ssh but port 3306 is not opened||

#

so im kind of stuck

#

have tried a couple of different things too with ||smb and ftp and get a zip file though is password protected and can't unzip it||

#

and the user with whom I log in to ssh is ||not root||

#

and not included in ||sudoers||

stiff flax
#

Does anyone has a clue why on windows privelege escalation does accesschk does not work any longer on target machine?

little wyvern
#

Hi, can anybody help me? Doing lfi skill assesment module 23 section 253, and done log poisoning, || ....ilf_admin/index.php?log=../../../../../../../var/log/nginx/access log&cmd=ls || works now but cmd=cat/flag.txt gives no flag, what am I doing wrong??? Thanks Ok I found it finally

ripe terrace
#

Hey folks, has anyone here completed The Live Engagement on the Shells & Payloads module? I'm having a hard time getting the ||50064.rb|| payload related to ||blog.inlanefreight.htb|| to run in MSF. Keep getting the following error...

Edit: Ignore that. was the lack of the VHOST parameter (even though it was marked optional facepalm )

jovial halo
#

Hi guys, I'm kind of stuck on the 2nd host on The live Engagement from the Shells & Payload module, I found the exploit mentioned in the blog in msf but have an error when running it. Anyone could give me an hint ? ๐Ÿ˜„

ripe terrace
jovial halo
#

@ripe terrace Already specified the vhost unfortunatly

ripe terrace
#

What's the error you're getting?

jovial halo
#

@ripe terrace "unexpected reply: Unexpected json response"

vague rock
#

Hello am a beginner here
Where do I start

stuck hull
ripe terrace
final cosmos
#

Hi All.. I am currently trying to get through the Using Web Proxies module on HTB academy, but am having difficulties with the ZAP Scanner sub module... It seems to me like there is no High level vulnerability when i use my own virtual machine. When i use the pwnbox instead i cannot seems to get the site i am visiting within scope, which hinders me in commencing with the scan. Has anyone else encountered this issue ?

worldly scaffold
#

Currently having loads of issues with the shells and payloads module, disconnects and machine timeouts, etc. Are there any known issues with the environment currently?

woeful ermine
#

hello everyone, I am stuck at the last question footprinting - IMAP/pop3 . There is only 1 e-mail I found on the IMAP server and there is no flag in it. It asks "Try to access the emails on the IMAP server and submit the flag as the answer.". Do I need to bruteforce admin password or sth from here. I am totally lost. Any help pls?

fathom stump
hazy grotto
#

Alright anyone able to help with password attacks medium lab? I've got creds for J and D. Unsure where to go now.

stuck hull
hazy grotto
#

@graceful rampart I'm looking for you bud lol

graceful rampart
#

For me it just clicked after I looked there

hazy grotto
graceful rampart
#

Dm me

pliant sage
#

yoooo I have a question about the sudo -l command. If I run it and get this: User jaeger may run the following commands on shoppy:
(deploy) /home/deploy/password-manager

#

what does (deploy) indicate? because whatever I try I can't run the command it says I can run

graceful rampart
#

It means you can run that command as the user deploy not as root

pliant sage
#

how would I run that command as that user? su deploy /home/deploy/password-manager ?

graceful rampart
#

So you'll need to do something like sudo -u deploy /home/deploy/password-manager the -u is for user

#

Also, this is the modules section. You shouldn't be asking questions about HTB Boxes here

warped bay
#

Guys, is there a way to pay hack the box subscription without PayPal and those things?

graceful rampart
#

Wrong channel lol

pliant sage
#

thanks

warped bay
graceful rampart
graceful rampart
# warped bay What

This channel is for HTB Academy modules. Your question dosent relate to that and thus you're in the wrong channel

warped bay
#

What is the correct channel

graceful rampart
warped bay
#

Ok thx

feral stump
#

On attacking lsass did you guys get the dmp file using the rundll32 method?

#

got the answer already but wanted to check if rundll worked for you guys? Thx

heavy dome
#

Hi all! in the Footprinting - Hard Lab module|| I found tom's credentials and reading his mail in imap I found a private ssh key but using it gives me error "Permission denied (publickey)." Obviously I have given permissions 400 to the key but I don't understand if it is my ssh setting problem.|| Thanks for the help

placid quest
#

@heavy dome use 600

graceful rampart
umbral ruin
#

i have issue with academy machine its not working . its responding for 2 mins and not working until reset where should i report this issue

#

Please SomeOne Help me out

light plank
#

I am trying to set up hack the box and I am very new to everything! do I need to set up a VM with Kali Linux to run hack the box or can I do it on my normal web browser?

steep thunder
#

You can just run through the "pwn-box"

light plank
cunning drum
#

pwn box is also giving error

steep thunder
#

Oh??

cunning drum
#

dont confuse i am @umbral ruin with another account

#

actually target machine is having issues

steep thunder
#

I'm having issues answering the questions in system information in shell module for the intro to Linux. I'm also super new

light plank
#

@umbral ruin I am having the same problem when I download it, it doesn't open giving me a believe a zip file

cunning drum
#

same here i have issues with module Shells & Payloads and cli windows room

#

i am changing rooms if there are issues are you guys doing somting other than me

steep thunder
#

I know my answers are correct .. like "which kernel versions installed in the system?"... I know I'm putting this in correctly and yet still receive 'incorrect answer' message

cunning drum
#

yahh

#

same in Shells & Payloads module

#

who are going to help us out ๐Ÿ˜ฉ

steep thunder
#

The first question was right and then the rest of my answers aren't working for the rest of the questions in the module...

#

Like..."what is the path to htb-students home directory?"... Super simple answer right?? Well it's not working lol

light plank
#

@queen hatch & @cunning drum are you guys opposed to hopping in a call I dont even know what i am doing wrong Ive looked up youtube videos and I am doing everything i have been told and I am still not able to get into fricken meow!

steep thunder
#

I can't jump into a call right now unfortunately ๐Ÿ˜‘

light plank
#

its okay

cunning drum
#

i can help you dude

light plank
#

It looks straight forward

#

but i dont know if i am just an idiot

cunning drum
#

msg me private

light plank
cunning drum
#

yah

steep thunder
#

I'll try this module again after a little break... I know my answers in the questions I can answer are correct. I nailed the first one and some of the other ones are just as easy lol ๐Ÿคฆ

heavy dome
stuck hull
#

HackTheBox - Hacker, forgets sudo. You have given me home sir.

#

*hope

#

f*ck

fathom pendant
#

Local hacker needs a home, will you support them:^)

slim night
#

idk which channel to ask this question but, where can I learn about how data passes through ports and network and learn how it all functions in the grassroot level so that I can start writing my own exploits and auxillaries rather than relying on the existing ones?

low vine
#

For anyone whos taken CBBH is there any recommended material to try once CBBH modules are complete?

#

I would assume the web focused stuff on HTB? challenges?

fathom pendant
# slim night idk which channel to ask this question but, where can I learn about how data pas...

There are networking modules on http://academy.hackthebox.com if you click on the module tab and type in the search bar you'll be able to find stuff. Also a quick ask to Uncle Google provided me this: https://www.practicalnetworking.net/index/networking-fundamentals-how-data-moves-through-the-internet/

#

It's been a minute since I brushed up on my network stuff

atomic ruin
#

Footprinting done feelsamazingman

sage jackal
#

Hey guys Iโ€™m at the last question of Windows Command Line module. Canโ€™t get the username right Iโ€™ve literally tried all from event Id 4625

#

Any help please ?

vital adder
sage jackal
graceful rampart
low vine
hazy grotto
#

I'm trying to mount the .vhd in password attacks hard lab. Ive been trying tons of guides. I keep getting stuck at figuring out the windows partition

#

Step 3: Get the partition info which needs to be decrypted

#

I can't figure out how to mount this baby. Spent almost two hours on this. Anyone have any nudges? I was going to use my windows host but I have home edition and bitlocker doesn't come installed.

vital adder
#

if you got the vhd file onto your windows host then all you need to do is a bit of research for the a tool that can open bitlocker on windows (i found multiple in 1 google search) or if you want to mount it in linux there also a lot of gui tool or you can just use losetup with dislocker
#modules message

#

hint wrong cred

hazy grotto
#

I deleted that i forget their was creds in there

vital adder
#

yeah but the cred are still wrong though

hazy grotto
#

Right

#

you are right

stuck hull
#

This might be a spoiler

hazy grotto
hazy grotto
#

i snapped my vm before this incase of something bad. but is this concerning?

graceful rampart
#

Nothing is concerning if you have a good snapshot ๐Ÿ˜‚

hazy grotto
#

This look good MRtom?

vital adder
#

i never got that error so i got no idea but in this case you are just making a partition from the vhd and mount that partition as a directory so what is the worst that can happen

#

yep (i think)

hazy grotto
#

or do i need to add the .vhd file at the end of /bitlocker

stuck hull
vital adder
hazy grotto
#

my .vhd file is located inside that dir

hazy grotto
vital adder
#

just move the vhd to a different directory

stuck hull
hazy grotto
#

i had to system restor

hazy grotto
#

Wouldn't it need to be in the directory before i run this?

vital adder
#

nope also for the name thing i think i copy the command from some blog or article so i got no idea about that

hazy grotto
#

hmm

#

not sure what to run then

vital adder
hazy grotto
#

ok..

#

did that.

vital adder
#

and the 4 file at the end should be your next and last step for this assessment

hazy grotto
#

wow thanks what a nightmare

hazy grotto
vital adder
#

you can just use umount for that

hazy grotto
#

โ””โ”€$ sudo umount /media/bitlockermount /media/bitlocker
umount: /media/bitlockermount: target is busy.
umount: /media/bitlocker: target is busy.

vital adder
#

just make sure one of your terminal isn't in that directory

hazy grotto
#

lol

#

there we go

#

โ”Œโ”€โ”€(ruderaphใ‰ฟkali)-[~/Downloads]
โ””โ”€$ losetup -d /dev/loop0
losetup: /dev/loop0: detach failed: Permission denied

vital adder
#

hint ||sudo||

hazy grotto
#

exit

ivory dock
#

I'm having some trouble in dns footprinting questions

#

The first question is "Interact with the target DNS using its IP address and enumerate the FQDN of it for the "inlanefreight.htb" domain." I don't understand what the question is asking for

stuck hull
#

It wants the fully qualified domain name for the name server I believe.

#

have a dig through the notes

ivory dock
#

right I'm running dig as:

dig any inlanefreight.htb @TARGET_IP

#

Which gets any records related to inlanefreight from the specified DNS server if I understand correctly

stuck hull
#

You can return just name servers with dig also.

ivory dock
#

But none of the fqdns that show up are the answer

stuck hull
#

DM me what you have submitted.

ivory dock
#

For the final question in DNS footprinting, I had to use the dnsenum script. However, I didn't expect it to work because I wasn't able to ||zone transfer the correct subdomain||. I looked in the source code but I'm not familiar with Perl, so I'm having trouble understanding how dnsenum was able to find the FQDN that we're looking for but I cannot with zone transfers and dig queries.

fathom pendant
ivory dock
#

As would any of the other hints/suggestions regarding the same topic

fathom pendant
#

hints are to nudge forward; giving a zone transfer domain is flat out telling people where to go

#

there's a difference between "have you tried this tool" versus "I got the answer and it was under this domain"

ivory dock
#

Hmm

#

There

#

Any idea regarding my question though?

fathom pendant
#

not sure; have an idea, but I'll test it out once I actually get to that point

#

redoing notes

lyric echo
#

Hey! Could someone help me understand the Linux Privilege Escalation LXC/LDD? Do I need to install lxd onto my system or alpine? im confused lol

magic valve
#

Module: Active Directory Enumeration & Attacks

Section: AD Enumeration & Attacks - Skills Assessment Part I

Question: Hey everyone, Iโ€™m currently on question 5 and am on the MS01 host and I can see other users but unsure of the direction to go to receive the clear credentials for another domain user. May I dm someone regarding this? I donโ€™t want to accidentally provide a spoiler regarding my finding.

fathom pendant
hazy grotto
#

Finally finished PW ATTACKS. phew.... Talk about difficultly but also so much fun. Best module so far. Thanks for everyone's help.

magic valve
fathom pendant
#

Remember pentesting isn't linear :) sometimes you have to go horizontal to go vertical

- What can we see?
- What reasons can we have for seeing it?
- What image does what we see create for us?
- What do we gain from it?
- How can we use it?
- What can we not see?
- What reasons can there be that we do not see?
- What image results for us from what we do not see?
magic valve
#

Understood. Thank you for reminding me. ๐Ÿ˜ƒ

graceful rampart
#

Yea, amazing way to think about it

fathom pendant
#

In my obsidian notes where I'm doing practice/lab my arrow directions go horizontal for lateral access, and vertical for priv-esc

#

And color coded for the type of access I have

#

And if a particular access point gets me nowhere I drop that line by deleting it.

#

That way if I revisit it I know I can just follow the flow reliably

graceful rampart
#

nice

#

I just started looking at the canvas

#

thats gonna change how i take notes completely

#

Absolute Game changer

fathom pendant
#

Instead of just "run this command" it is "credentials" -> login via (whatever access portal is my opening) -> what can I (su)do /access

#

Keeping the actual path succinct and followable, while my notes for the section are verbose. Commands have their own section as well where I include the options and their explanation

#

Especially if I had to do some mild research into things

lyric echo
#

Hey! Could someone help me understand the Linux Privilege Escalation LXC/LDD? Not sure what to do for this section. Thanks

fathom pendant
#

most of what to do should be explained by the module/lesson.

lyric echo
fathom pendant
#

dm me with the question it is asking you

graceful rampart
fathom pendant
graceful rampart
woeful ermine
#

any help with footprinting hard lab // I have nothing and no ideas. Right now I am trying to bruteforce pop3 with meta. Not to mention it is painfully slow, I also think I am going to wrong direction here. There are 5 open ports with syn scan and looks like 1 snmp with UDP. Well, I cant do anything with snmp because the only feedback I am getting is timeout response. syn ports are ssh and IMAP/pop3.

atomic ruin
#

think about how an admin could use snmp to interact with the server

woeful ermine
fathom pendant
atomic ruin
rustic sage
#

Hello, I need assistance in the Credential Hunting in Linux section under Password Attacks Module. I am instructed to fine the password for will, and I have no initial foothold, I'm unsure on how I should proceed.

fathom pendant
#

Have you tried everything the module has shown you?

#

so far*

rustic sage
#

I'm unable to actually try anything in the module itself without having some sort of credentials to access the host.

fathom pendant
#

then attempt to enumerate the host

#

what can you find out

#

you have a username; has the module so far talked about trying to find a password with just the uname?

rustic sage
#

The module is about dumping credentials while you are on a linux host, I do have a user but no way to access the host. I have tried brute forcing with the user, but to no avail.

rustic sage
graceful rampart
rustic sage
graceful rampart
#

i think

#

actually, you can do it cuz the user is in the provided username list.

#

but it would take a very long time

rustic sage
#

Okay a small hint here would help save me time now that I know what I need to do. Is SSH the service I'm trying to bruteforce?

graceful rampart
#

You should always enumerate before trying any attacks

rustic sage
#

Sounds good, I will enumerate the host just weird I did not expect all this when it comes to this specific section...

fathom pendant
#

i mean enumeration is always the first step of any attack

rustic sage
#

Generally the sections have been made so that you are trying to do what the section taught about. I have tried bruteforcing ssh, ftp and smb. SMB is giving me a strange response, its saying everything is a correct password but I will attempt to run nmap scripts against the service to see if its vulnerable to anything.

steep thunder
#

What do I do if a question is not accepting my answer but I'm 100% certain I'm correct??

#

Lol

umbral river
#

check to make sure there isn't a space character at the end of your input

steep thunder
#

Done. Still is incorrect?

umbral river
#

what module are you doing?

steep thunder
#

Now I know I'm a total noob because I'm just getting involved, but I know I'm right.

#

I'm on...

#

System information in the Linux Fundamentals

#

Finally answering some questions...

rustic sage
steep thunder
#

Hint is useful only for the first question

rustic sage
#

I have tried manipulating the hinted user.

steep thunder
#

Are we talking the same module?

umbral river
steep thunder
#

I mean the answer is almost literally in the question... Even the 3rd question....

#

I'll dm you thank you

woeful ermine
#

On footprinting - hard lab . I ve found a ssh key. made a file and paste the key. set permission to 600. and use command 'ssh -i id_rsa t**@10.129..' I am getting connection closed. Am I doing sth wrong. I ve checked the file triple times.

dim hemlock
#

I think the permission I gave it was 644

#

Try that?

rustic sage
#

Are you running the command as root?

graceful rampart
woeful ermine
rustic sage
#

I'm gonna mutated the password also that says the user was using. Hopefully this works.

#

Oh. Okay that worked haha.

fathom pendant
dim hemlock
fathom pendant
#

I believe the module tells you

rustic sage
#

I have found the solution, thanks for the help @graceful rampart

dim hemlock
#

can you help me with this section?:
Mounting a Linux Folder Using xfreerdp
I didnt really understand it.
/v:10.10.10.132
the /v: = Target yea?

woeful ermine
# fathom pendant rsa needs to be 600

That what I was doing but I started to try everything when it didnt worked. hahaha. Well, weirdly enough ssh still giving error and I connect with remmina no problem

fathom pendant
#

I don't think ssh port was open on that, which is probably why, or you did something wonky

woeful ermine
fathom pendant
woeful ermine
fathom pendant
#

I can dm you in a moment to explain why Remmina actually worked

woeful ermine
slim night
fathom pendant
#

but the modules exist within the job role and their own mini paths

slim night
#

the normal path is where i should start with ig. i have a lot of time with me before next semester starts

earnest pelican
#

I have a question

#

I just joined this server because my server with a lot of people got hacked and im scared that I will lose it

#

And it took me very long to get to my spot

fathom pendant
earnest pelican
#

Ah ok fair enough thanks

median crescent
#

hello guys

#

i am so sick of hackers

#

i want to get them back

#

can someone teach me the step to step guide to finding their addresses?

modest kindle
#

???

median crescent
#

i will pay you back in gratitude and positive attitude

modest kindle
#

first install DN

fathom pendant
median crescent
#

what's DN

modest kindle
#

deez nuts

fathom pendant
median crescent
#

i won't snitch

fathom pendant
#

well your friend lied LOL

modest kindle
#

Bro?

median crescent
#

my friend is @modest kindle

modest kindle
#

I don't know this guy

#

He added me and I added him back but idk him

#

I'm just here to see what cyber security is like ygm

#

nothin malicious

median crescent
#

lol

#

he added me

#

told me exactly what you guys are

#

and do

modest kindle
#

inspect element

#

that's literally not me

#

Idk you

median crescent
#

you're all disgusting he said but he will put up with it to bully kids on roblox

modest kindle
#

Ok

fathom pendant
#

what you do with the information you learn from http://academy.hackthebox.com is on you. The services are only for learning ethical hacking; which does not generally dive into retrieving an IP from any target - but rather being hired by a company to test their security in place ยฏ_(ใƒ„)_/ยฏ

median crescent
#

damn

fathom pendant
#

with an understood Rules of Engagement and boundaries

modest kindle
#

fair

earnest pelican
#

I'm legit crying rn lol

modest kindle
#

Why?

median crescent
#

so if i bullied a child on minecraft and found out his ip address and scared him shitless

earnest pelican
#

my server got hacked

median crescent
#

it's not on you?

modest kindle
earnest pelican
#

fr

#

I wanna learn to hack

modest kindle
#

bro?

earnest pelican
#

What??

modest kindle
#

this is not the one

#

Go about it thru discord man

earnest pelican
#

isn't this where you learn to hack

modest kindle
#

It's a cs hub man

fathom pendant
modest kindle
#

for stuff like ctf

earnest pelican
#

oh I don't know what that means

fathom pendant
#

If you are caught doing malicious activity using hackthebox vpns then you will get banned from their services :)

earnest pelican
#

Pfft

modest kindle
#

You passive aggressive as hell

earnest pelican
#

Marcie if you wanted to hack a discord user could you do it if you wanted to I'm not asking you to do it

fathom pendant
#

but if you are using your own vpn and services not much they can do; but advertising illegal things is also against the #rules and against discord ToS

fathom pendant
#

just google the shit dude; plenty of PoC (proof of concept) code out there

earnest pelican
#

to*

#

wait

#

Do you have a link for it

#

I have no idea wtf to do ๐Ÿ˜ญ

fathom pendant
#

Google is a free resource bro

earnest pelican
#

yes yes I know but what do I search up

fathom pendant
#

figure it out yourself; if you don't know how to search google that's kinda on you and a skill diff tbh

earnest pelican
#

Damn this server got some smart asses here

#

fair play

#

I'm not even gonna argue cuz you could probably hack my ass in a thanos snap

fathom pendant
#

only for people that are asking us to provide info on illegal activities

earnest pelican
#

is hacking a server with robux illegal?

#

cuz apparently that's what happened to me

fathom pendant
#

yes; your issue is with discord; go to their support and shit dude.

earnest pelican
#

Alright

fathom pendant
#

at the very least they'll shut it down

#

ยฏ_(ใƒ„)_/ยฏ

#

but not our fault if you or an admin of your server got caught lackin with clicking sus links

novel matrix
#

@earnest pelican Any more chats or discussions on this, I will remove you from the server.

earnest pelican
#

alright my fault

fathom pendant
#

hi pwning

earnest pelican
#

Wait can u ban me say merry Christmas cuz I'm just gonna leave anyway

novel matrix
#

Please keep this chat on topic of being academy modules related.

If I see any other discussions not being on topic, I will hand out mutes.

rustic sage
fathom pendant
#

lol i feel so dumb... I forgot the most important thing in the Firewall - Medium... After regoing over and over and over... I realized I am the DUMB xD the reason is so obvious

brisk geode
#

Hey can anyone help me with the footprinting easy lab?
i did a basic scan and got into the ftp server and dowloaded both of the private and public keys but whenever i try to login using the private key it asks for password and yeah i changed the ssh key chown value

fathom pendant
#

lemme check my notes rq

wheat garden
fathom pendant
brisk geode
fathom pendant
#

or I should say; clicking hint is not required

brisk geode
#

lol

#

its required for the ftp tho

fathom pendant
#

you should be able to enumerate the uname and pass without the hint it just takes time

brisk geode
#

i see

wheat garden
#

or might need to enumerate vstpd service on port 2121

fathom pendant
#

I'm just stating it's possible; but if you want to get through quicker then yeah - just use the provided hint ยฏ_(ใƒ„)_/ยฏ

brisk geode
fathom pendant
#

I didn't take great notes on this one tbh; part of why I'm redoing my notes for these sections

wheat garden
#

maybe get rid of the .txt extension

#

just name it id_rsa and chmod 600 it

#

and it ceil not celi

brisk geode
fathom pendant
#

Technically username is a spoiler

wheat garden
wheat garden
brisk geode
fathom pendant
brisk geode
#

how do yall take notes?

#

i just keep it like attack chain commands

fathom pendant
#

it's in the hint; and 99% of the time - you don't need to use the hint button to actually get the information it supplies

#

but it's not directly in the question/information given to you

wheat garden
#

Think hints are given information. Not spoiling anything if the module gives you info in the hint.

fathom pendant
#

Not everyone is going to hit the hint button

#

it is supplementary information, that you should be able to get yourself is the point. You don't need to rely on the hint to get the user:pass. It just takes time to actually get that info. The module provides information on how to acquire/use the tools provided to get info

fathom pendant
high totem
fathom pendant
brisk geode
high totem
fathom pendant
wheat garden
brisk geode
brisk geode
fathom pendant
high totem