#modules

1 messages Β· Page 45 of 1

solar zodiac
#

maybe instagram customer service

graceful rampart
#

No. sorry. You should go through Instagram Support if you need an account taken down. It would be extremely unethical for anyone to help you even if you had a valid reason. If theres valid reason to need an account taken down Instagram Support is the place to go

hollow thunder
#

nvm

brisk geode
#

hey im sorry, i was sleeping

sharp siren
#

Hi everyone, I'm stuck on broken authentication module skills assesment, I was able to enumerate 2 users through the message board, I know how to decode the cookie and I know what the password policy is. I tried to brute force to find the credentials of some user but this one blocks me on the 5th attempt. Any hints or recommendations please?

ivory hollow
#

Hi all

i am in MSSQL section and struck in 2nd question. Actually i know the way and open it but struck with sql commands . So please let me know.

Thanks

fathom pendant
#

The module teaches you all the commands you'll need to figure it out

rustic sage
#

hello everyone !!!!

#

i have recently joined htb nd discord hope we will make great discussions on htb

#

Expect your support guys!!!!!

ivory hollow
#

@fathom pendant i get the commands but not working. so that's why i am not sure is my commands wrong or some problem with in the box

graceful rampart
#

90% of the time you're doing something wrong. There's very rarely a problem with the box

ivory hollow
#

may someone bit help me please.

high sentinel
low vine
#

Login Brute Forcing - Login Forms Attack
I should be using this hydra payload from my understanding in order to attack the /login.php form with admin user
||hydra -l admin -P /usr/share/payloads/SecLists/Passwords/Leaked-Databases/rockyou.txt -f <IP>-s <PORT>
http-post-form "/login.php:username=^USER^&password=^PASS^:F=<form name='login' "|| Why would this payload not be working for this?

high sentinel
#

what's the F=<form about? that doesn't look correct

ripe terrace
#

That seems right, it's the syntax for Hydra's http-post-form module.

@low vine are you sure you have the right username/password field names? And does the form name match what you see in the HTML source code?

low vine
#

let me triple check that might be where i messsed up

high sentinel
low vine
high sentinel
#

<form is not a valid html tag <form> is

#

you probably just want to use the actual name of the form or so

low vine
#

Maybe i need to read back but not quite understanding what it should be

high sentinel
#

probably the name='...'?

low vine
#

just gonna keep playing around with it ty for the tips

#

Gonna go read back on that section as well and take good notes so I can have this down

ripe terrace
#

@high sentinel it needs the actual HTML snippet, so <form name='xyz' is correct.

high sentinel
#

really? well i was wrong then

ripe terrace
dim wolf
#

this is new

sly tapir
#

I wish they had a junior pentest cert for beginners

dim wolf
#

wouldn't that be htb cpts?

sly tapir
#

i thought it said, "intermediate"

dim wolf
#

it says intermediate but the course content is geared towards beginners (or anyone of any skill level really)

sly tapir
#

true; I guess your right.

low vine
#

CBBH feels pretty good towards junior lvl

viral trail
#

Hi I’m new here

jaunty mortar
#

Anyone can help with the Password Attacks Lab - HARD I have been stuck for couple days with bruteforcing user johanna. I have tried mutated list using custom rules from resources as well as best64 rules, also tried the unmodfied password.list. I have used both hydra and crackmapexec targeting rdp.

acoustic owl
jaunty mortar
turbid kraken
#

Hey guys! So I'm working through the OSINT: Corporate recon module and stuck on the first questions x_x

It askes for the GPS coords for cities where the company HQ is, I found the cities no problem, but the issue is that I can't get the answer to validate.
I'm supposing the GPS coords are off by a few 1 meters which makes it really hard to get. Also the hint dosn't seem to show the same results as my google :/

Has anyone else dones this module and struggled with it? Would love to know!

low vine
#

Login Brute Forcing - Question #1

Driving me absolutely fucking insane. I'm there I'm in the spot and its giving me the same as the #2 flag? So confused.....

turbid kraken
low vine
#

I reset the box and it was right there

#

not sure what happened but who knows

turbid kraken
#

πŸ‘Œ

turbid lily
#

Thank you, this is the best tip for this question in this Discord. I'm serious, it was pain

candid zephyr
acoustic owl
arctic sentinel
#

Hello everyone! Anyone working on the Attacking FTP module! A little help would be appreciate it!

arctic sentinel
#

The module is attacking common services and I`m in the ftp section!

brisk geode
arctic sentinel
#

the last question... Im trying medusa, hydra, crackmap againts ftp and ssh but I cant get the password of the user r.....

#

I`m using the pwd list provided but no luck so far!

brisk geode
#

how are you trying to attack the ftp server?

#

dont forget theres a ftp proxy server available

arctic sentinel
#

medusa is running now...

#

ftp proxy server?!?! meaning that it`s not port 21?!?!

brisk geode
#

you'll know it

#

and kindly reply back with a ping if you need further help

sly nebula
#

Will there be a course on C2 usage and extension? I never was into C2s, but I can appreciate their usefulness in large and complex networks. Havoc looks like a promising, free alternative. Any thoughts on this?

arctic sentinel
# brisk geode enum the host

Thanks!! I gotta go now 😦 😦 Ive been stuck for a couple of hours... when I come back I will keep trying!! thanks!!!

brisk geode
ripe terrace
#

I'm dying here. What's the best way to do host discovery from a windows box over a double-pivot? I have a meterpreter session, socks proxy, and autoroute configured. I've tried a ping sweep, which took forever and returned nothing, and my arp_ping doesn't return anything but the compromised machine itself... If it helps, this is for the Pivoting, Tunneling, and Port Forwarding skills assessment.

Clearly, all I needed to do was type out that message/vent. Nmap finally came through with the goods. I've found the other host.

karmic helm
#

Guys Should I choose ejpt or CEH? Which one more better?

languid dawn
karmic helm
autumn pilot
#

red team != pentester

karmic helm
languid dawn
# karmic helm I want to become like a (Red team)penetration tester

hmm ok, I'll try my best to make it short,
firstly red team != penstester even if (arguably) pentesting is under the red team umbrella
secondly, none of these certs will help for that, maybe ejpt a little.
and finally, look at job offers and see what certifications are often asked for, for entry level jobs and more advanced roles.
Personally I don't think you should pay for certifications though, your employer should. But I'm aware that it's not that easy and a famous cert will open lots of doors.

karmic helm
#

Ahhhh thank you

#

And I want to ask if cyber security and computer science majors are the same?

languid dawn
#

is there many infosec majors? from my understanding unis mainly do CS and you can get a master geared towards infosec

#

also I do suggest you identify with our bot and come to #careers-and-certs to ask all your questions πŸ˜„

#

you'll get more answers, and also we don't want to go off topic in our channels

karmic helm
#

Ah ok 😁 thanks

graceful rampart
#

I'm an infosec major and I can tell you it's absolutley a waste a of time. At least as a CS major you'll learn some somewhat practical things. Infosec degrees are very very very theory heavy. There's a good chance that most of your professors don't actually know what they're talking about. I'm half way through my second year and I've had a grand total of 1 good professor.

#

Infosec is 100% self study. The stuff you learn in college is very rarely practical or useful

languid dawn
#

if it's a good college you basically learn the oscp and how to do secure architecture πŸ’€

#

why am I encouraging off topic convos hide

graceful rampart
#

πŸ˜† yea basically. It's all stuff you can learn on your own for a lot less than what college will cost you

graceful rampart
#

Np. That being said, this is definetly the wrong channel for this conversation. If you ask the same thing in #careers-and-certs there's a good chance you'll get several replies. You'll be able to hear more than a few different perspectives which will likely be very beneficial

dim cosmos
#

$(rev<<<'imaohw') is the coolest thing ive seen in my entire life. how good is the command injection module lol

graceful rampart
#

Bruh that's genius lol. I'll get to the command injection module eventually

dim cosmos
#

it's cool πŸ™‚

broken warren
languid dawn
#

hmmm ||wholesome||

broken warren
#

For anyone that has been having trouble with predictable reset token, question 2, shoot me a message. I felt like such a noodle when i figured out how simple it is.

sinful falcon
#

Hello world, in** AD Enumeration & Attacks - Skills Assessment Part I** To connect to MS01, do I need use web01 as Pivot ?

#

I tried Enter-PSSession but no success

graceful rampart
turbid kraken
graceful rampart
#

I haven't done that module. Sorry

turbid kraken
sinful falcon
graceful rampart
#

Remember that you can't send ICMP packets through a socks tunnel. You need the -Pn flag with nmap. You also can't do syn scans so you'll likely need the -sT flag too

crisp remnant
#

Anyone for small assistance for Attacking Common Services module ?

autumn pilot
#

which section

crisp remnant
autumn pilot
#

you are taking into consideration the files you have previously discovered

crisp remnant
#

Yes

autumn pilot
#

once you know that there isn't only one service/server, you will have to tweak a bit the settings to execute commands

#

the command is not enabled by default

simple zephyr
#

Attacking Common Services- easy I know what to do just ran out of time, but I got to thinking, could you create a php script for file upload with a web interface for the sql file upload. Then just edit the script with credentials and file location. Also could you use sqlmap to execute your payload as an alternative for this challenge. I’m just brainstorming other ways to do things and trying to make scripts for the exam.

autumn pilot
#

As you already know the service and supposedly how to include something from yourself, trying crafting a something that will allow you to execute commands

rustic sage
#

Hi! I'm honestly not sure what I'm doing wrong, I'm trying to solve flag8(Case #8) from the SQLMAP ESSENTIALS. This is the command I'm using:

||sqlmap -u "http://161.35.169.118:30557/case8.php" --data="id=1&t0ken=wZfhGHZouwbPBukWrbI06G6yH25Me1ASxQzjBHyC2qA" --csrf-token="t0ken" --batch||

The only thing I get returned is 4 injection points, no flag. Appreciate it πŸ˜„

arctic sentinel
arctic sentinel
#

Anyone working in the attacking common services module?!?!

autumn pilot
#

What's your question

quiet night
#

Hi, sorry if this is the wrong channel to ask this but does anyone know how i can link my academy account to discord? im supposed to be able to find the option here: https://academy.hackthebox.com/settings but I can't seem to find it anywhere. is this a bug or am i doing something wrong? (Trying to get the Academy User role)

arctic sentinel
#

How do you use the ftp command if tou want to connect to a different port other than 21

#

Im trying and searching but I cant find how to connect to an especific port different than 21

proud pine
weak ibex
#

Howdy

arctic sentinel
#

Have you done the attacking ftp section?

arctic sentinel
#

I tried but get no valid password for user r....

#

In the forum they mention that you can access anonymously... but can`t find it how!

brisk geode
arctic sentinel
#

yeah... I`m using the password list from the resources...

#

just finished HYDRA and got 0 valid passwords...

arctic sentinel
brisk geode
#

u need to grab it from the ftp server

brisk geode
#

||anonymous:slfksfsfs||

arctic sentinel
#

I get login incorrect

brisk geode
#

send ss

arctic sentinel
#

I`m trying to copy my screen!

#

how do you make a cut of whta`s being shown in your screen?!?! hahaha

brisk geode
#

windows?

#

or linux?

cunning drum
#

if windows use win+swift+s

brisk geode
#

try screen and snip

cunning drum
#

if linux use (right swift + printscreen)

arctic sentinel
#

yeah yeah! I`m on it

fathom pendant
arctic sentinel
brisk geode
arctic sentinel
#

How did you figure it out? that it was allowed?!?!

brisk geode
#

i did that target using anonymous user

fathom pendant
#

^

rustic sage
#

Finally solved the Phishing XSS question... i just had to URL encode it
But the weird thing is when I tried to URLencode through JS with encodeURIComponent("string...") it didn't work, but when i copied it from the url it auto URL encoded it and it worked
Does anyone know what might have caused the issue?

brisk geode
fathom pendant
#

Or any pass

arctic sentinel
#

That`s what I did... in the screenshot I sent... it says login failed... maybe I should use another command

brisk geode
#

your command is right

#

what youre inputting as pass?

arctic sentinel
#

ramdom keys

brisk geode
#

should work

arctic sentinel
#

now it works... I shouldn`t write the user=

brisk geode
#

that target is kinda buggy

#

ftp proxy server needs some time to run

#

so try enum to check if the proxy server is up or down

arctic sentinel
#

it`s running πŸ™‚

brisk geode
#

then the command should work

arctic sentinel
#

should I try to connect through ssh?!?!

#

that`s what the question says...

weak ibex
#

Hey people. Quick question

brisk geode
#

did you get the password.list from the ftp server?

#

u need that file to bruteforce

weak ibex
#

Is there any way of knowing whether a site was hacked (along with all the services)?

fathom pendant
brisk geode
arctic sentinel
brisk geode
#

if the website is popular enough

weak ibex
#

It's Payoneer

brisk geode
weak ibex
rustic sage
#

I want to report a bug that's present in ALL tebex based minecraft server stores, this is a high severity problem. The problem is that I want to get a reward for my work, but tebex closed its public bug bounty program some time ago, and the server owners wont even listen to me, they just dont care, or in one case, I told them the bug, then they blocked me and stole the bug from me 😦 What should I do?

fathom pendant
#

It's been a minute since I attacked ftp

brisk geode
#

ftp {ip} {port}

#

then {user}

#

then {pass}

#

it worked for me

arctic sentinel
#

thanks a lot!!!!

#

how did you find out it was allowed the anonymous login in the ftp server?!?!?!?!

brisk geode
#

just trying out by using the username anonymous or you can check that by inspecting config files if you have access to the whole machine

fathom pendant
brisk geode
fathom pendant
#

Because -sC for nmap tells it to run scripts for the services it finds

arctic sentinel
brisk geode
arctic sentinel
#

How do you know the anonymous login is enable... ?!?!?

brisk geode
graceful rampart
arctic sentinel
#

ohhh ok...since in this lab in 2121 it wont show it...

#

ohhhhhhhhhh!!! ok ok!!!

#

I should do that everytime!

brisk geode
#

depends on the situation

#

waf could pop up

arctic sentinel
#

ohhhh i see!!

brisk geode
#

yeah

#

lmao

graceful rampart
#

Min rate 10000 could crash older machines if you aren't careful

arctic sentinel
#

Thanks to everyone!!! I keep learning!!

wispy pebble
#

Hello mates! 🀝🏻

ivory dock
#

anybody else stuck on the vulnerability module? the machine for the nessus exercise keeps crashing every time I access the nessus ui

#

I say crashing because I can't ping it at all and I get a "trying to reconnect" pop up

#

I tried with 4 different machines, all the same results

graceful rampart
#

Do not dm people wiothout asking first

#

Server rule

rustic sage
#

oh sorry

azure cloak
#

Hi there! Can somebody help me with dns fuzzing module? I can’t find the fqdn of x.x.x.203. I try multiple wordlists

graceful rampart
desert zinc
#

Hi

#

How are you guys

#

I need to ask you about app

#

If i install it in my phone it's give the access to my phone and i can open microphone using another phone

fathom pendant
#

Read #welcome it'll help you understand what this server is

graceful rampart
#

The amount of people who dont read server rules will never cease to amaze me

pliant flame
#

hi guys. im at the footprinting hard lab. i ve logged in to ssh. ive found a mysql server (?) on there. Since i cant connect regularily to the mysql server (its local) am i right to assume that I have to somehow tunnel the connection through SSH? and if thats the case, how the hell am i doing that. i tried with googling but i cant get a connection to work.
Can someone give me a little nudge?

buoyant escarp
#

WordPress Hacking Module, Skills Assessment.
which Plugin should i throw an eye on for an unauthenticated file download?

#

looked through wpscan but im not sure

fathom pendant
buoyant escarp
#

i just find vulns like LFI, SQLI and so on, but not 'Unauthenticated File Download'

fathom pendant
#

Can't you use sql to download a file?

buoyant escarp
#

um via file write to create a webshell?

low vine
#

Command Injection - Bypassing Blacklisted commands
This is what i've come to that still works and bypasses what seems to be a block on ||cat||
||ip=127.0.0.1${LS_COLORS:10:1}%0ac'a't${IFS}${PATH:0:1}home${PATH:0:1}flag.txt||

I dont want the answer but would like a small nudge in what I might be missing and understanding. I've attempted to use the single and double quotes through the command but it seems that cat is the only 1 thats blocked from what I see.

#

It runs but it doesnt execute as intended I guess?

azure cloak
thorn urchin
# low vine

have you tried echoing it in a terminal to confirm that the resulting output is what you intended?

fathom pendant
low vine
azure cloak
low vine
#

echo "${LS_COLORS:10:1}%0ac$@at${IFS}${PATH:0:1}home${PATH:0:1}flag.txt"

thorn urchin
#

echo 'YOUR PAYLOAD HERE'

low vine
#

yea doesnt work for me

thorn urchin
#

what output do you get

low vine
fathom pendant
thorn urchin
# low vine

try with double quotes and without anyquotes, theres one of em idr that parses it properly and another that doesnt

low vine
#

Yea not valid in my terminal

#

😦

thorn urchin
#

what shell are you using?

low vine
#

fish

thorn urchin
#

then dont use fish

#

try in bash

fathom pendant
low vine
#

Thats odd there shouldnt be a new line between cat and /home/flag.txt

low vine
#

New line is before "cat" now im more confused lol

thorn urchin
low vine
#

Yea I understand that but looking at the payload it should be

cat(space)/home/flag.txt```
#

I dont understand why its showing different

placid wharf
thorn urchin
low vine
#

Thats the sad part i have for 30 minutes and I cant figure it out ><

#

let me read throug hagain

#

and might come cry in 20 minutes

buoyant escarp
#

Try cat instead of cat

#

Tac*

#

If cat is blacklisted

thorn urchin
low vine
#

Well the bypass works for cat

#

if i use c'a't or c"a"t both work

low vine
#

ty

thorn urchin
#

also I could totally be misremembering wrong but I didnt think the flag location was /home/flag.txt

#

but memory could be faulty, just make sure youre confident on that

low vine
#

I also just reread the question and its of a previous user lol

#

so that could also be a problem

rustic sage
#

Need some help here: https://academy.hackthebox.com/module/163/section/1551
Struggling with the reverse shell over the forwarded port 1234 on dmz01: dc01 -> dmz01 1234 <-portfwrd (msf) -> 10.10.14.19 (my attacker machine)

root@dmz01:~# tcpdump -i ens192 dst port 1234
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on ens192, link-type EN10MB (Ethernet), capture size 262144 bytes
20:59:41.186007 IP 172.16.8.3.64889 > 172.16.8.120.1234: Flags [R.], seq 3696198686, ack 2750044908, win 0, length 0
20:59:41.186109 IP 172.16.8.3.64902 > 172.16.8.120.1234: Flags [R.], seq 3586340546, ack 2592359372, win 0, length 0
20:59:41.186123 IP 172.16.8.3.64928 > 172.16.8.120.1234: Flags [R.], seq 478348283, ack 262965734, win 0, length 0
20:59:41.186136 IP 172.16.8.3.64914 > 172.16.8.120.1234: Flags [R.], seq 2264802788, ack 1072586443, win 0, length 0
20:59:41.186157 IP 172.16.8.3.64940 > 172.16.8.120.1234: Flags [R.], seq 2265080408, ack 3020844998, win 0, length 0
21:00:27.796403 IP 172.16.8.3.64946 > 172.16.8.120.1234: Flags [SEW], seq 3203670305, win 64240, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
21:00:27.796828 IP 172.16.8.3.64946 > 172.16.8.120.1234: Flags [.], ack 4081947409, win 8212, length 0

#

Is my monitoring wrong?

#
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on ens160, link-type EN10MB (Ethernet), capture size 262144 bytes
20:59:41.186230 IP 10.129.203.114.56830 > 10.10.14.19.https: Flags [P.], seq 2012863926:2012864054, ack 3152730324, win 4721, options [nop,nop,TS val 1279633583 ecr 1367410628], length 128
20:59:41.213762 IP 10.129.203.114.56830 > 10.10.14.19.https: Flags [P.], seq 128:640, ack 1, win 4721, options [nop,nop,TS val 1279633611 ecr 1367436449], length 512
20:59:41.306868 IP 10.129.203.114.56830 > 10.10.14.19.https: Flags [P.], seq 640:800, ack 129, win 4721, options [nop,nop,TS val 1279633704 ecr 1367436541], length 160
20:59:41.431617 IP 10.129.203.114.56830 > 10.10.14.19.https: Flags [P.], seq 800:960, ack 257, win 4721, options [nop,nop,TS val 1279633829 ecr 1367436666], length 160
20:59:41.603322 IP 10.129.203.114.56830 > 10.10.14.19.https: Flags [P.], seq 960:1120, ack 385, win 4721, options [nop,nop,TS val 1279634000 ecr 1367436838], length 160
20:59:41.706566 IP 10.129.203.114.56830 > 10.10.14.19.https: Flags [P.], seq 1120:1280, ack 513, win 4721, options [nop,nop,TS val 1279634103 ecr 1367436941], length 160
20:59:41.813586 IP 10.129.203.114.56830 > 10.10.14.19.https: Flags [P.], seq 1280:1440, ack 641, win 4721, options [nop,nop,TS val 1279634211 ecr 1367437048], length 160
21:00:27.797014 IP 10.129.203.114.56830 > 10.10.14.19.https: Flags [P.], seq 1440:1664, ack 641, win 4721, options [nop,nop,TS val 1279680194 ecr 1367437079], length 224
21:01:27.962619 IP 10.129.203.114.56830 > 10.10.14.19.https: Flags [P.], seq 1664:1808, ack 769, win 4721, options [nop,nop,TS val 1279740360 ecr 1367543248], length 144
#

The portforward is setup like this:
Revshell from dmz01 to kali on port 443

#

Updated first tcpdump, copypaste fail

#

Updated again, you can see the timestamps that the packages arriving on 1234 go out to 443 (https) to my machine

#

But metasploit doesn't catch the shell

fathom pendant
#

Have you tried not using metasploit? I've heard people have had issues with metasploit on this one

rustic sage
#

aaand it died cause the 2h were over

#

No, haven't, it's quite a bit of portbending etc going on, so I tried to go as easy as possible

#

Guess I'll try again another day

low vine
#

@thorn urchin I've read back through the 3 sections and I'm just not understanding where the error is with it

#

could i pm you?

thorn urchin
#

Not atm, im at work so dont have time to spin up an instance and test things/verify.

low vine
#

np appreciate the help either way. I'm not far off just maybe need to walk away and look at it in 30 minute

rapid sparrow
#

Anyone like me stuck in the Windows Privilege Escalation Print Operation Module, I cannot compile it

woeful ermine
#

hello everyone, attacking common services module - Attacking DNS. I added machine to /etc/hosts with inlanefreight.htb. Also added ns1.inlanefreight.htb to resolvers.txt. But I am getting this error from subbrute

#

any ideas why? Hint suggests to use subbrute

fathom pendant
main ridge
#

Hi everyone. I'm doing the Intro to AD module and had to create a GPO using the following command

Copy-GPO -SourceName "Logon Banner" -TargetName "Security Analysts Control"

To later link it to the OU "Security Analysts"

Set-GPLink -Name "Security Analysts Control" -Target "ou=Security Analysts,ou=IT,OU=HQ-NYC,OU=Employees,OU=Corp,dc=INLANEFREIGHT,dc=LOCAL" -LinkEnabled Yes

The problem is that I'm having this error

woeful ermine
frigid osprey
#

Hey All!
I am working or rather stuck on "Password Attacks: Password Reuse/Default Passwords"

I am on the machine with the creds obtained from the previous task, and the question asks to discover the credentials for MySQL.

I scrolled through some of the previous posts here, and it seems like I went in the same direction as everyone else, with a particular online list of default creds.

However, none of them seem to work. Tried all the passwords related to MySQL and even put the previously discovered password in the list with some variations, with all the users on the machine, and nothing.

Any nudges would be greatly appreciated.

woeful ermine
frigid osprey
# woeful ermine which part spesifically // sorry I bit tired I guess

I could be wrong entirely but testing for the default or reused password in Password Attacks: Password Reuse / Default Passwords

Q: Use the user's credentials we found in the previous section and find out the credentials for MySQL. Submit the credentials as the answer. (Format: <username>:<password>)

#

I am logged in and attempted to discover creds for mysql

woeful ermine
#

every port I mean

frigid osprey
woeful ermine
#

I assumed you use ssh or sth right? check other services

frigid osprey
#

yeah i ssh'd into the box

woeful ermine
#

yeah its not there as you know πŸ˜„

frigid osprey
#

yup hahah

#

just trying to figure out the mysql part, i figured it would be a default, but yeah ha

woeful ermine
#

it is default actually

#

but the list on the module doesnt have that one πŸ˜„

#

you still need to find it I guess πŸ˜„

frigid osprey
#

got ya, google to the rescue hopefully lol

graceful rampart
frigid osprey
#

Ive been trying from there but still havent found the right one. Doesn't like me i guess

graceful rampart
#

Yes. The one they give you a link for

frigid osprey
#

I will def. keep poking at it

graceful rampart
frigid osprey
#

yeah for sure. I did lol. they just didnt work. Used good old ctrl +f, found the 4 you are referring to. Ill try and reset this machine again.

rustic sage
#

Greetings everyone, might anyone assist me with some confusion I'm having with "credential hunting in linux" from the "Password attacks" module? I've read the community forum but using and mutating the password from the hint does not grant me a successful authentication (either with CME or Hydra). I understand the idea of mutating passwords, even discovered passwords, but this lab has left me confused πŸ˜…

graceful rampart
frigid osprey
#

Tried them all again after resetting, got it! Thanks, everyone. You all are awesome.

graceful rampart
rustic sage
graceful rampart
rustic sage
graceful rampart
#

np. Feel free to dm me if you need more help with it

fluid maple
#

Shameless bost - After three days of researching, reviewing past sections in the Footprinting Module, and without querying this thread, I finally got the Footprinting - Hard Lab! πŸŽ‰

rustic sage
#

hi guys! you look like smart people so im going to ask a question

#

nevermind have a good life

rustic sage
fluid maple
graceful rampart
fluid maple
graceful rampart
#

This path is amazing

fluid maple
#

Sorry - this = the Penetration Tester path, to be specific.

Yes! It is.

unreal grail
#

Can someone help me to find the right value of the --kdcHost of the domain which correspond to the DC FQDN? I tried nmap as suggested by @solid python , but no success. connecting to the domain.

Module: Crackmapexec
Section: Working with Modules

coral escarp
#

Is anyone whos good at subdomain brute force able to tell me why the tool subbrute and gobuster are consistently returning different subdomains? I spent way too many hours because gobuster didnt return whats required...

woeful ermine
coral escarp
unreal grail
graceful rampart
rustic sage
#

@graceful rampart Finished that section I was working on, wanted to say thanks for taking the time to help out. πŸ‘

raven cairn
#

Am I crazy or did the mods delete the discussion about making this channel verified only?

graceful rampart
#

Dosent really matter since we got vetoed on that

raven cairn
#

Sure but mods shouldn't delete the discussion lol

#

πŸ™„

thorn urchin
#

which discussion? I still see my complaints in erratum

raven cairn
#

I thought it was this channel haha

graceful rampart
fathom pendant
#

This just in: yaoi can't read

raven cairn
#

Lol. This is true

#

Do you need help with a module/section?

#

Yeah np!

#

What do you need help with?

thorn urchin
#

which module?

#

cause surely youve read the server rules and understand what this chat is for

thorn urchin
feral elbow
#

where do I ask for specific retired machine assistance

fathom pendant
high sentinel
thorn urchin
#

Ima start screen shotting all these

feral elbow
fathom pendant
high sentinel
#

^

fathom pendant
#

Huge NPC energy

feral elbow
feral elbow
#

never seen this

high sentinel
#

what kind of error are you getting?

feral elbow
#

Access denied

thorn urchin
#

off topic

#

please use the correct channel youve already been told so

fathom pendant
#

^

#

You've been told how to access the correct channel for this

still raft
#

Hi! I want to ask about Skills Assessment - Broken Authentication i have found 10 usernames in the websites and then i tried to create a password list based on the password policy using this command ||grep -E '^[A-Z]' /usr/share/wordlists/rockyou.txt | grep '[0-9]$' | grep '[^A-Za-z0-9]' | awk 'length >= 20 && length <= 29'|| but until today i can't find correct password for each user. Is my password list is wrong?

graceful rampart
#

Time based SQL Injections are the worst lmao

fathom pendant
#

That just sounds painful

graceful rampart
#

Even with sqlmap, its so slowwww

#

This is almost as bad as some of the bruteforce in password attacks

raven cairn
#

Im terrified to do that module

woeful ermine
graceful rampart
#

fair, but i mean, im just sitting and waiting only to find out i need another flag in my command. Repeat that 5 times and its a pretty long and annoying wait

wheat garden
#

Module - active directory enumeration and attacks

section - bleeding edge vulnerabilities

question 2 - "Apply what was taught in this section to gain a shell on DC01. Submit the contents of flag.txt located in the DailyTasks directory on the Administrator's desktop. "

Not sure how to even start the exercise seems you cant ssh or rdp as the forend user. Can ssh as the htb-user but cant find nopac tool on that box and cant gitclone tools into the box cause it doesn't seem to have internet access. If anyone done this section

graceful rampart
graceful rampart
#

Sure. I don't have notes on that exercise which means I found it to be very straight forward.

fathom pendant
#

Can we help you with a module?

#

<@&861185840277487616>

fathom pendant
#

Sip ez

raven cairn
#

They said the F word 🀬

#

Absolutely Haram

fathom pendant
#

Your PFP encapsulates the true level of disgust

urban sage
raven cairn
#

So many crazy unverified people here haha

fathom pendant
#

Because it's the landing space

graceful rampart
#

bruh

#

why is this chanel availible to unvarified but #general isnt???

urban sage
thorn urchin
rustic sage
#

can someone plz help me to hack a snapchat acc

brisk geode
#

πŸ’€

rustic sage
#

sorry

brisk geode
#

this is not the place

rustic sage
#

ohk sorry

#

what is that?

brisk geode
#

and hacking someone is acc depends on how dumb the victim is

rustic sage
#

ohk

raven cairn
#

It’s not like you can do an account takeover willy-nilly

brisk geode
#

lmao

novel matrix
#

This convo is over. @rustic sage This is a verbal warning.

#

Please read and follow the rules

rustic sage
#

okk sorry

#

lol

woeful ermine
#

which part

#

sure sleep tight, most likely you are missing very small step

#

sure

turbid kraken
#

Hey guys, sorry for the repost but still struggling for the location questions (1st ones) of the OSINT: Corporate Recon module. Has anyone done it?

swift dune
#

Hey all,
I am trying to perform ADCS Relay + PetitPotam attack but I am getting error "[-] Error obtaining certificate!"
Did anyone else faced this error and why is happening ?
Thanks in advance

sinful falcon
#

Hi i'm stuck with Active Directory - Skill assesment 1 to find ||tpetty|| credentials I tried lazagne and mimikatz but nothing

rustic sage
sinful falcon
sinful falcon
#

Yeah I tried to crack with rockyou but no success

feral stump
#

Try with resources provided in the module

mortal basin
#

πŸ”₯

leaden quail
#

Hello, Im doing the Remote/Reverse Port Forwarding with SSH and the Meterpreter Tunneling & Port Forwarding Module, but im not able to run a function reverse shell in msfconsole if im follow the steps describe in the sections. I got some errors messages:

dim cosmos
#

man Bill Gates had a pretty good password going in the brute forcing module kek

leaden quail
#

or Segmentation fault (core dumped)

acoustic owl
placid quest
#

@leaden quail the payload is causing that problem

dim cosmos
#

i just finished the login brute forcing module and i now need a very stiff drink....

rustic sage
#

i am facing ngrok context deadline exceeded error... anyone knows how to fix?

torn blade
#

after running an ssh command i never get promoted for a password?

#

yeah, its not reaching it, but every time i try restating the target i get the same resulkts

#

it was working fine 5 minutes ago

#

wtf

#

couldnt ping it or connect to ssh

#

ran an nmap again on it and it detected it

#

and now i can ssh again

#

wtf HTB servers

rustic sage
#

Can somebody help me out with information gathering web editionI am stuck on question 3
Q. find and submit the contents of the txt record as answer?
I am using dig and its giving error

sly kelp
tidal kelp
#

module: Password Attacks Lab - Hard can I DM you Mr.Tom? or anyone. I try hydra rdp, wordlist is mut_password.list with user john but it's not working. Thanks

twilit cipher
#

nevermid... πŸ™„

#

Still getting:

#

This module sucks, or I am exhausted. Or both. Circling back later.

#

If anyone has any useful tips for RDP and SOCKS Tunneling with SocksOverRDP, I'm all ears though. Otherwise, backing away slowly...

graceful rampart
main basin
#

Im wondering, can soemnoe make safe exam browser bypass?

raven cairn
#

Sorry

main basin
graceful rampart
raven cairn
#

They want to bypass exam proctoring software i tthink

graceful rampart
#

Also please don't spam every channel with the same question

graceful rampart
raven cairn
#

Yeah, but they aren’t asking about CpTS or CBBH

graceful rampart
#

Well the. They're asking in the wrong server lol.

#

Why would ask about an exam that has nothing to do with HTB in the HTB server?

raven cairn
graceful rampart
#

I know

#

But like, asking about a specific exam? I feel like people should have a little common sense lmao

raven cairn
#

Ngl a lot of the time its easier to just study than cheat lol

#

I’m sure if you put the time and effort you could probably find some sort of bypass, but it seems easier to me to just study haha

graceful rampart
#

Lol. Most of these things are like invasive malware. Very hard to bypass usually, especially if they've been around for a while

#

(Also were getting off topic)

unreal grail
#

Module: CrackMapExec
Section: MSSQL Enumeration and Attacks.

Wondering why I am able to fetch the database name, but no result is displayed when fetching the table name from the core_app database. Any idea?

tidal kelp
#

can i dm you too? i need help on Password Attacks Lab - Hard

surreal marsh
#

Hello I got an issue with a simple instruction: "Navigate to the web interface at the end of this section and log in with the provided credentials." This is regarding Nessus Skills Assessment. I've started the instance it provided me with an IP but when I'm trying to go to the web panel via pwnbox it's "Unable to connect Firefox can’t establish a connection to the server at IP." There are no additional instructions did someone experienced something similar?

lethal atlas
surreal marsh
#

well I can ping the target

lethal atlas
#

what module is that

surreal marsh
#

VULNERABILITY ASSESSMENT

#

πŸ™‚

#

either its something really simple or I don't know wtf

#

I've tried via vpn first with no result so I thought I'll use a pwnbox as it should see the thing

surreal marsh
#

i just did

tender viper
#

Hey, I've been stuck on the module firewall and ids/ips evasion hard lab for a while now and I was wondering if anyone could guide me in the right direction?

fathom pendant
#

Or at least start you in the right direction

#

Oh wait wrong thing

#

Sorry

tender viper
fathom pendant
#

What has the module taught you about that then?

twilit cipher
# twilit cipher Still getting:

If anyone else runs into this on this module. After turning off "real-time" protections, make sure you are running regsvr32.exe in an elevated powershell session. that should have been obvious, which is why I guess it wasn't covered in the course material...

tender viper
fathom pendant
#

Check your notes and try.

tender viper
fathom pendant
#

If you have notes/things to try, try them :)

surreal marsh
tender viper
fathom pendant
tender viper
fathom pendant
#

Yes

#

Those steps specifically, from the syn scan forward, are what will help you

tender viper
fathom pendant
#

Yep resetting sometimes kicks the gears on

tender viper
fathom pendant
#

When you did the -sS -p- it should have revealed that port

tender viper
fathom pendant
#

I'm trying to remember the syntax but basically that port is discoverable

tender viper
fathom pendant
#

I've had this conversation with someone recently; went over chat logs , you added the suppress ping yeah?

#

-Pn

tender viper
fathom pendant
#

Sometimes though you have to manipulate the commands provided to get info

tender viper
torn blade
#

Could someone explain to me what exactly this command does (this will be 2 posts of single lines)

#

CMD="bin/sh"

#

php -r "system('$CMD');

fathom pendant
#

So

#

CMD sets a variable named "CMD" to be "bin/sh"

#

Also that looks incorrect? Shouldn't it be /bin/sh?

torn blade
#

yeyeyey /bin my bad

fathom pendant
#

The $CMD indicates to PHP that you want to run the variable, not the text "CMD"

#

For the php portion look up PHP documentation for what 'system()' is

#

php -r is just the syntax to run the following using php

torn blade
#

thx u

fathom pendant
#

Much like python -m

torn blade
#

this entire conversation i am copying and pasting and sending in my notes xD

tender viper
fathom pendant
#

Hmm

raven echo
#

Hello all... Just started a module and I'm at the question portion. How do I use my own Kali instance? I've downloaded the academy VPN file and connected. However, the only option that I have is to start their virtual instance.

fathom pendant
#

So for the starting point modules you are expected to answer those using their pwnbox

red obsidianBOT
#

There is no need to use a VPN to connect for any of the CA Challenges, they are all accessible via the public IP's given when started. Not all challenges have an HTTP server however, some you need to connect via nc.

raven echo
#

Nm... I just refreshed the webpage and the option to spawn the target just appeared

fathom pendant
#

sometimes it's weird Β―_(ツ)_/Β―

rustic sage
#

I really need help from support doing the DCSync section in AD module, impacket-secretsdump does not work and I cannot complete the exercises with other tools... Please, just a hand on it

#

I am stuck here for a while

thorn urchin
#

secretsdump worked for me when I last did it

#

just saw your picture in erratum, your domain is wrong

#

its not inlanefreight.local/adunn

#

its INLANEFREIGHT/adunn

fathom pendant
#

^

thorn urchin
#

@rustic sage respond in here to not clutter erratum channel.

whats the screenshot of your command and output when using the right domain?

simple zephyr
#

can I DM anyone fo attacking common services easy, I am stuck on the SQL part and i must be just missing one little thing.

marble raft
#

Hi guys! I'm on the Brute Forcing Passwords on the Broken Auth module.

Stuck on this question

Using rockyou-50.txt as password wordlist and htbuser as the username, find the policy and filter out strings that don't respect it. What is the valid password for the htbuser account?

Need help because some of the concepts aren't really clear

dim hemlock
#

Hi guys, Im also stuck on a question and my question is related to using the correct User.list or Pass.list on:
Network Services
Find the user for the WinRM service and crack their password. Then, when you log in, you will find the flag in a file there. Submit the flag you found as the answer.

#

I cannot find the correct list to crack it

storm jackal
#

The username and password lists given in the resources section of the module are the correct ones to use

#

The credentials for winrm should still work for listing smb shares which is a capability of crackmapexec

rustic sage
thorn urchin
#

why are you at 10.129.217.89? that doesnt look like the DC to me

dim hemlock
upper lake
#

hi there, I am at the nmap hardlab, I found the missing port and I am trying to get the version, but had no luck so far. I also tried with netcat, but could not connect. Someone any more hints on this one?

tiny ledge
#

Hello, could someone DM me the answers for the Session Security - Skills Assessment. I completed it in the past, but for some reason it shows incompleted, I remember it being pain in the ass and don't feel like redoing it hahah

thorn urchin
#

against the rules for obvious reasons

simple zephyr
#

Additionally, I uploaded php reverse shells through FTP and moved them to the proper directory and I have the ability to download the files, but not execute them.

raven cairn
#

Stupid question. Attacking Common Services - Attacking SQL Databases , What am I doing wrong with my sqsh command?

dim wolf
#

enjoyed this path

raven cairn
#

I've been trying to connect and I am a little confused what's going wrong

west canopy
#

i'm getting the same error with the sqsh tool.

raven cairn
#

Interesting.

#

Does that mean one of my commands was correct?

west canopy
rustic sage
#

Can anyone help me take down child p server

west canopy
rustic sage
#

Sorry I could not find any other channel

acoustic owl
raven cairn
#

Damn. I'm not crazy

#

Usually I just make really simple mistakes.

acoustic owl
#

Maybe a problem with sqsh 3.0?

#

I had the version 2.5.1.6.1 at that time

raven cairn
#

Can I at least have a bit of assistant connecting with impacket mssqclient.py then . The module doesn't talk about the command usage, there aren't many resources online, and impacket doesn't have manpages.

fathom pendant
#

I thought one of the early modules talked about mssqlclient

west canopy
#

mssqlclient.py -p 1433 htbdbuser@10.129.203.7

fathom pendant
#

But I'm also bad at remembering rn as it feels like my head is in a vice grip

raven cairn
#

I triple checked the Ip.

#

Gonna try restarting machine and box. Hope that works

fathom pendant
#

The good ole "reset it and it just works" technique

thorn urchin
raven cairn
#

Update Jared Dm'd me about some stuff. Issue is resolved for now.

#

I have been banging my head for so many hours lmao 🀣

thorn urchin
#

peopleve been saying sqsh has had issues for awhile now

thorn urchin
#

so? they work internationally and will accept reports from anyone

fathom pendant
#

^

rustic sage
#

Didn't know that ty

raven cairn
turbid salmon
#

Hi! I have some difficulties with the module ο»ΏACTIVE DIRECTORY ENUMERATION & ATTACKS (Especially for the section AD Enumeration & Attacks - Skills Assessment Part I)
Someone for a PM?

simple zephyr
#

For Attacking Common Servicer -medium is there a wrong and right box? I have reset the box a few times and have gotten different NMAP results

rustic sage
simple zephyr
#

I feel like for Attacking Common Services half the box is missing. I found his SSH key in his inbox but don't know a way to retrieve them from pop, but I got the flag another way.

thorn urchin
#

thats the foothold of the Network, unless that IP is running the DC services it is not the DC and wont connect to the controller that is on the 172. network

#

Its not gunna magically forward the requests for you

rustic sage
thorn urchin
#

are you sure .5.25 is the DC though?

rustic sage
thorn urchin
#

np! itd certainly be nice if impacket gave some clearer errors in these scenarios

#

even a "so and so IP address doesnt appear to be a DC" message would be nice

thorn urchin
# rustic sage i am totally idiot... thanks anyway, solved πŸ˜„

also Id recommend taking the time to setup a tunnel on the foothold host and trying again from your own machine routing through the tunnel.

The module doesnt tell you to do this, but itll be extremely useful for the assessment, and this section is one of the perfect labs to practice it and verify you have it working.

merry arrow
#

sorry my english is bad.. but I need help with privilege escalation (the final part of getting started) I'm stuck.... thanks

thorn urchin
merry arrow
thorn urchin
#

yes, so you need to become root. What have you tried when it comes to looking for ways to become root.

merry arrow
#

try using sudo /usr/bin/php system("bin/sh"); since I can run the bin/php as root but it didn't work for me

#

Loading the LinEnum.sh file and adding a php line to it to run a rever shell as root but it didn't work

thorn urchin
#

I recommend searching for php on the gtfobins site

merry arrow
sly tapir
merry arrow
thorn urchin
#

congrats

spring lily
#

is the server down? I can't connect to the website

ripe terrace
#

Yup, it's down.

spring lily
thorn urchin
#

yup main and academy. time to go outside and touch grass

rustic sage
#

noooooooooooooooooo

#

why gawd whyyyyy

ripe terrace
#

I went outside once, the graphics are good, but the gameplay is sh*t.

rustic sage
#

i was on a roll lol

rustic sage
#

guys i'm 96 percent done. took 150-160 hours

solar zodiac
#

hey guys is academy down?

#

oh wait

rustic sage
#

yep

solar zodiac
#

just read chat

#

😦

#

im kinda stuck on the blind sql module

#

I don't know the query to extract the length of a column entry

rustic sage
#

i'll help

solar zodiac
#

thx πŸ˜„

rustic sage
#

sent a dm

solar zodiac
#

ok )

#

πŸ™‚

thorn urchin
#

well youre on mandatory break mode now sooo

spring lily
#

It would be ironic if HTB got hacked,,, I want my server back

ripe terrace
#

The HTB central server holds the golden flag. The one flag to rule them all.

rustic sage
#

i was thinking that would suck if they got hacked

#

guys what does the label top 25, 50 etc mean is that just for htb or htb academy or both

solar zodiac
#

I think just HTB

rustic sage
#

yay sites back up!

solar zodiac
#

but im not sure

#

aww I just turned off my computer lol

rustic sage
#

kk

#

lol

solar zodiac
#

ehh how do I get in touch with a tutor

#

i thought i would be prompted after answe4ring a question wrong 3 times

#

hehe

fathom pendant
#

Bottom right should be a chat bubble thing

solar zodiac
#

hehe πŸ™‚

#

thx

dim wolf
#

whoever is making the module artwork is doing a really good job

#

i can't stop looking at it

robust prism
#

Hey folks, awhile back I went through a module that demonstrated some of the basics of enumerating web sites and then exploiting them with metasploit, but now I can't find it. I suspect it was retired. Does anyone have a suggestion for a current module I can reference for website enumeration, lateral movement, exploits, etc? I want to put on a demo for my university cybersecurity club.

#

alternatively, is there somewhere I can reference retired content for HTB Academy?

iron totem
#

is this supposed to be general

dim wolf
#

this channel is for discussing the modules on HTB Academy

#

i think you need to verify your htb account if you want to get access to the other channels including #general

dim wolf
rustic sage
#

I'm trying to do Enter-PSSession -ComputerName ||MSSQLSvc/SQL01.inlanefreight.local:1433 -Credential INLANEFREIGHT\svc_sql|| however when i hit enter it prints a blank new line and nothing happens am i entering this command wrong?

olive crow
#

Hey yall is this where general discussion occurs?

rustic sage
#

Hi, can anyone help me with the "Type Filters" section in File Upload Attacks, I am stuck. Let's DM.

west canopy
olive crow
#

oh

thorn urchin
fathom pendant
rustic sage
#

no it just does that auotmatically on discord haha let me double check tho and thanks for replying

#

ya it doesn't work i've tried the command literally prob 50 times in different ways 😦 i apprecciate you trying to help tho

#

@fathom pendant

solar zodiac
#

hi everyone πŸ˜„ has anyone done the blindsql injection module?

#

It asks for the admin password, but there is no non-default database to dump

#

was wondering if this was intended

#

I would love to use this tutor feature I heard about in the announcements πŸ™‚

ripe terrace
#

I haven't done the blind SQL injection module yet, so I can't help you there. But as for the HTB tutor feature, I believe you can only use it if you're on the silver annual plan. Are you on that?

solar zodiac
#

I have gold

#

but not annual

#

😦

ripe terrace
#

Yeah. it's limited right now to silver annual

solar zodiac
#

oh I see

#

thanks for the info!

ripe terrace
#

I'm sure someone else here can help you who's also done that module, this channel gets more active later in the day.

solar zodiac
#

πŸ™‚ ok awesome πŸ˜„

#

I will get silver annual once I get my finances in order

#

saving up for a move hehe

#

kinda broke atm lol

ripe terrace
#

Good luck with the move!

warm spade
#

++verify

little whaleBOT
#

Please see your DMs for instructions on how to verify your HTB account.

simple barn
#

Hi everyone, I'm stuck on the Nmap module IDS/IPS Evasion - Hard Lab. I tried to use different options like decoys, source IP address etc... but couldn't find the right service and its version. Can you guys please give me some idea ? I'm definitely missing something.

sleek sentinel
#

Hello, I'm new to Hack The Box and I'm very bad at hacking and would like to get started. only I did not manage to pass the "appointment" challenges of the easy level. Can you help me please ? thanks in advance for the answer.

devout torrent
#

Should probably start at academy to learn the basics of penetration

mild sky
#

hey guys i have a question maybe you could help me out, so here it goes; not wanting to pay for any subscriptions until just yet after signing up, does htb offer a lot of free rooms/modules ect like thm or more subscription based?

dim cosmos
balmy radish
#

If you’re a college student, the student sub is hard to beat. The modules are more difficult than the THM rooms, but they go more in depth and have great exercises.

mild sky
#

thanks

dim cosmos
#

it's worth it ! peepocowboylove

#

be prepared for late nights and ramen noodles

mild sky
#

yup, thanks

warped scarab
#

@gusty hornet

rustic sage
#

Hi

ember jewel
#

Hello everyone, I am in need of assistance with the LFI module on hackthebox. Specifically, I am currently stuck on the task of automating the scanning process for exposed parameters and attempting to exploit them using LFI wordlists to read the /flag.txt file. I have already attempted to fuzz the web application and find the parameter, as well as the webroot, but have not been successful in finding the flag.txt file. I have also attempted to view the /var/log/apache2/error|access.log using path traversal techniques in order to poison the logs, but have not been able to access them, suggesting that Apache logs are only readable by users with high privileges such as the root or adm groups. Can anyone provide guidance or assistance in this matter?

flint helm
#

how can I contact support if the support chat is not responding?

uncut meadow
#

yo Team, can somebody help me on Attacking Common Services : Attacking SQL Databases

autumn pilot
flint helm
autumn pilot
#

Β―_(ツ)_/Β―

acoustic owl
buoyant escarp
#
    require_once $_REQUEST['ajax_path'];
}````
when trying to load /etc/passwd, it works, but when i try /var/log/apache2/access.log it throws an error, is a .log not a regular file defined in is_file ?
acoustic owl
buoyant escarp
acoustic owl
buoyant escarp
#

trying to poison log and make an web shell

#

there are many vulnerable plugins tho, i personally like LFI most of them all listed

acoustic owl
buoyant escarp
uncut meadow
#

yo Team, can somebody help me on Attacking Common Services : Attacking SQL Databases. Im stuck at the begining

woeful ermine
#

where exactly, what did you do?

uncut meadow
#

I connect to the mssql service with htdbuser, but nothing interesting, only that another user exists ||sa||, but cannot do anything with it, im trying to bruteforce this user creds but nothing and also trying to bruteforce creds for the user of question one for mssql and rdp but nothing

#

stuck here hahaha

#

can I DM?

woeful ermine
#

well I dont remeber and my notes are empty at that part

#

to mssql

#

my notes start from there lol

#

haha

#

you should connect somewhere with given creds

#

maybe restart the machine

woeful ermine
rustic sage
#

Does the latest version of cURL (now installed on the new pwnbox) require user confirmation before finishing? Is there a flag to suppress that behavior?

Edit: nvm - user error (put your URL in quotes πŸ˜…)

stone zenith
#

Can anybody help me out please. I am doing the footprinting module, and I am stuck on the last question of the DNS section. The question is β€œwhat is the fqdn of the host where the last octet ends with .203?” I can’t find it it’s driving me up the wall

stone zenith
rustic sage
stone zenith
#

Transfer failed

leaden quail
#

hey Guys, am doing the RDP and SOCKS Tunneling with SocksOverRDP. But im stuck to running the listener 127.0.0.1:1080 On the Pivot Host. When im executing SocksOverRDP-Server.exe on 172.16.5.19 with Admin privileges and im looking at "netstat -antp" on the Pivot Host There are no active Connections. Any Hints?

dense charm
#

how to elevate the privileges user so you can do what ever to the system but you have to get the authorization code it's like a API Keys but its more encrypted and powerfull and it can only use once ?

buoyant escarp
#

can someone check, if you get the same blank page when loading assessment 1 from nosql?

steel flume
sly tapir
#

yup

buoyant escarp
steel flume
#

Name of the box .htb

buoyant escarp
#

i cant ping it

#

packet loss

#

100$

#

%

steel flume
buoyant escarp
urban anvil
#

Hi guys I m trying to use the command "nc -lnvp 4444" in the parrot os provided by HTB but it always listens on 0.0.0.0 and I am unable to get a reverse shell. Can anyone help me?

buoyant escarp
steel flume
buoyant escarp
#

just assessment 1 doesnt

#

no proxy, no burp is running

steel flume
buoyant escarp
leaden quail
steel flume
# buoyant escarp yes

Maybe change the location as some days is very slow in some regions, do you have VIP ?

buoyant escarp
steel flume
dim hemlock
#

Hi all anyone knows why crackmapexec is giving me like this?

#

SMB 10.129.202.136 5985 WINSRV [] Windows 10.0 Build 17763 (name:WINSRV) (domain:WINSRV)
HTTP 10.129.202.136 5985 WINSRV [
] http://10.129.202.136:5985/wsman
WINRM 10.129.202.136 5985 WINSRV [-] WINSRV\username.list:password.list

#

im using the list from the resources module

tidal kelp
robust prism
urban anvil
dim hemlock
#

Im doing the password attack module and I cannot crack any of the users

#

Can someone point me in the right direction please? I am using the credentials that the resources have on the module

autumn pilot
dim hemlock
#

But it does not seem to work either

woeful ermine
#

Hello everyone - on hard lab // attacking common services. I ve got the flag but there is a question " Once logged in, what other user can we compromise to gain admin privileges? " which I cant figure out

#

I dont understand which users - there are 2 users I can impersonate when I enter the db as f* user. But I tried those with every combination. I also tried other users I found with possible combinations

#

never mind how on earth I was reading the question. It is asking for the user. only one and only one of them works indeed

dim hemlock
#

writing here sometimes you will realize whats wrong hahh

#

too bad mine no

#

I did crack the SSH though hehe

woeful ermine
#

by the way my cme wasnt working last time I used

#

I did whatever I needed to do with meta

dim hemlock
#

Hmm I will check meta I never used it

#

but thanks for the tip!!!

woeful ermine
#

msfconsole

#

then choose what you want with

#

use

#

you can use it like

#

search "service name"

#

ur welcome

dim hemlock
#

was trying to avoid metsploit but if cme wont work than yeaaa

woeful ermine
#

well mine doesnt. tried to fix it without any luck 😦

fathom pendant
#

Meta is a shortcut usually, but if you can't find a good POC then it works

dim hemlock
#

cracking ssh i managed to get the users so it should be easier to enumerate now

torn crest
#

hi anyone rooted new Stocker machine?

west canopy
fathom pendant
#

At least privesc

torn crest
#

ok bro

#

i have a problem in privsec

fathom pendant
#

Which module?

livid bluff
#

Hello
In the file upload attacks module in the whitelist filters section.
I find several payloads that work to send my file, I have a code 200 with the mention 'File successfully uploaded' but when I go to the page where I uploaded the file I have an error 404.

raven cairn
#

Last time I checked they were doing maintenance so if you are able to complete this section lmk

dim hemlock
#

Hi all Im having issues trying to connect to an SMB

#

I have got the credentials but not sure about the sharename

#

how can I confirm the sharename of the smb

#

tree connect failed: NT_STATUS_BAD_NETWORK_NAME

woeful ermine
#

smbclient -N -L ///ip/

#

to check available shares

#

smbclient //ip/sharename

#

to check share and if you have priv to read

dim hemlock
#

I see let mee seee

#

How can I add credentials too :
smbclient -N -L ///ip/
I got this error message:
session setup failed: NT_STATUS_ACCESS_DENIED

#

i think i know how

fathom pendant
#

-N I believe doesn't ask for the sign in

#

So remove that

#

I also believe -U is the user flag

dim hemlock
#

still didnt work 😦

leaden quail
#

Hello, im doing the Pivoting, Tunneling, and Port Forwarding Skill Assessment im trying to ssh with mlefay. Just get "Permission denied". Any hint?

woeful ermine
dim hemlock
#

I gottt ittt

#

└──╼ $smbclient -L //10.129.212.99/ -U cassie -W WINSRV

#

ChatGPT got me the answer πŸ˜›

fathom pendant
dim hemlock
#

πŸ˜‚

fathom pendant
#

There's probably something in the module that told you to do that

dim hemlock
#

ask chatgpt haha?

vital adder
#

i wonder if you could ask ChatGPT how to pwn offshore?

fathom pendant
dim hemlock
#

ohh yea it did say how to connect too hahah

#

wohoo got all 4 flags !!

#

only took me 1 day kek

unreal grail
#

Hi! I am using CrackMapExec in a Docker container, but my proxychains is on my localhost machine. Can someone know how I can use crackmapexec running in a container through proxychains?

rustic sage
#

I have the same issue. Any solution?

scarlet sapphire
#

Hi i have problem with crackmapexec when i try to install it poetry install
Traceback (most recent call last):
File "/usr/bin/poetry", line 5, in <module>
from poetry.console.application import main
File "/usr/lib/python3/dist-packages/poetry/console/application.py", line 15, in <module>
from cleo.exceptions import CleoError
ImportError: cannot import name 'CleoError' from 'cleo.exceptions' (/usr/lib/python3/dist-packages/cleo/exceptions/init.py)

acoustic owl
dim hemlock
acoustic owl
vital adder
#

yep it kinda did but offshore is just so ficking long NotLikeThis

acoustic owl
#

I have only made 1/4 so far

vital adder
#

also because the discount on december was so big i can't resist but buy 2 pro lab so now i still for the aptlabs 😭

vital adder
#

my enum is just super slow also just have to note everything down is driving me crazy

acoustic owl
#

Oh, you have a lot planned
I have now completed CPTS, waiting for the result.
Doing Offshore and all the new modules in the Academy. They are killing me. They're throwing out new content faster than I can learn it 🀣

#

I also write everything down. That helps me to understand things better

vital adder
#

same with the academy also congratz on completing CPTS

acoustic owl
#

Thanks

vital adder
acoustic owl
#

Did you also take the exam?

vital adder
#

not yet i need to finished offshore 🀣

thorn urchin
#

I have two modules left to do

vital adder
#

i may take the exam after offshore then the aptlabs

thorn urchin
#

then gunna do dante

vital adder
#

but there go my first half of 2023

acoustic owl
thorn urchin
#

after dante yeah

acoustic owl
vital adder
#

yes but not worth the money

thorn urchin
#

ye, plan is to write up a mock report as if it were a real assessment for extra report writing practice

#

I got it on the discount as well

vital adder
#

on nice then it's worth it

acoustic owl
thorn urchin
#

I think hes just saying prolabs are pricey lol

acoustic owl
#

Yes, they're expensive, but there's also a lot of work that goes into a lab like this.

vital adder
thorn urchin
#

Side note Im pleased to find that learning tmux is part of the documentation module because its been on my to-learn list. Very convenient that its in the module for me.

vital adder
#

i did talk to some one who done dante in like a few day and it's 122$

acoustic owl
#

Well, it's certainly not for everyone. But for me it was a good lab to practice again things that I will probably need in CPTS.

#

It definitely helped me prepare and feel better for the exam.

vital adder
#

for the exam then yep and looking back i should just go for dante and the exam because offshore is kicking me in the nut right now also mrb3n did say offshore it's over kill just for the exam so there is a chance that most of the thing i learn so far isn't even in the exam 🀣

acoustic owl
#

In a video, mrb3n mentioned that the exam is between Dante and Offshore.

thorn urchin
#

offshore has seemed more like the lab you do when you wanna start practicing some c2 stuff

vital adder
vital adder
#

i did see some mod talk about us lab get reset daily but so far i got the same on eu

acoustic owl
#

Also check out the videos from bmdyy and CryptoCat. They contain good tips.

thorn urchin
#

yeah watched those already

vital adder
#

same and the 90+ page report scared me PepeProtecc

acoustic owl
#

I think all labs are reset every day.
They let you and me into one of those labs. Something can get broken there πŸ˜‚

acoustic owl
vital adder
#

yeah i know but still 90+ page

acoustic owl
#

This sounds like more than it actually is

vital adder
#

at one point i see there is like 100+ people in dante so it make sense for that lab to be reset daily and offshore is a more advanced lab so people of course are going to test stuff that may break the lab but still can't use c2 is kinda suck

acoustic owl
#

Yes, I know what you mean. Nevertheless, I think it is necessary. Things break when you try things and that's what this lab is for.

Of course, it would be cool if everyone got their own lab. So he can restart it when something is broken.

thorn urchin
#

I wouldn't mind if there was a price increased option to have private instances for the lab

graceful rampart
#

Yea. Thats would be pretty cool

#

Dante is gonna be my practice run as well

acoustic owl
ember jewel
#

Hello everyone, i posted this earlier, I am in need of assistance with the LFI module on hackthebox. Specifically, I am currently stuck on the task of automating the scanning process for exposed parameters and attempting to exploit them using LFI wordlists to read the /flag.txt file. I have already attempted to fuzz the web application and find the parameter, as well as the webroot, but have not been successful in finding the flag.txt file. I have also attempted to view the /var/log/apache2/error|access.log using path traversal techniques in order to poison the logs, but have not been able to access them, suggesting that Apache logs are only readable by users with high privileges such as the root or adm groups. Can anyone provide guidance or assistance in this matter?

ember jewel
acoustic owl
thorn urchin
ember jewel
# ember jewel Automated scanning

i have spent considerable amount of time on the question, i have made progress on finding the parameter, and the exploits from the wordlist to find the webroot, but i still cant find the flag.txt

ember jewel
thorn urchin
acoustic owl
acoustic owl
#

But everything else you can train in it. I would definitely recommend Dante as an exam preparation.

thorn urchin
#

Personally the AD module clicked pretty well with me so Im not too worried about that section. 90% of the issues I had was just me being stubborn about my preferred tools and methods.

#

Otherwise Id say pretty confidently I nailed the assessments.

acoustic owl
#

Haha, yes I know what you mean

graceful rampart
#

Any AD practice I can do In my lab

#

Its everything else I need to practice πŸ˜†

thorn urchin
#

setting up a private AD lab is on my todo list

acoustic owl
#

Then practice Dante

graceful rampart
acoustic owl
#

Maybe I should also build an AD Lab

graceful rampart
#

If you enjoy AD it's a lot of fun

acoustic owl
#

But first I'm doing Offshore now and all the new modules here at the Academy. They're killing me. They're putting out modules faster than I can learn them. πŸ€£πŸ™ˆ

graceful rampart
#

Lmao. Yea. There's so much to learn

#

I had a massive todo list before I started academy. Now it just keeps growing

west canopy
#

@mild mango eats me for breakfast

fair saffron
#

i can't open myd files how can i open this file

thorn urchin
#

There are definitely some modules I have on my list I wanna do after CPTS, but gotta save up for OSCP after first.

thorn urchin
dim wolf
#

is there anything else i need to learn outside of the penetration tester path to complete dante

#

i was looking at the reviews and some say that they did buffer overflow exploits

acoustic owl
dim wolf
#

alright good to know. will probably do dante before cpts then

thorn urchin
#

yeah usually Dante is recommended as prep for CPTS not the other way around. We were actually just discussing it for exactly that reason a little earlier lol

acoustic owl
#

So I spend my money for further education πŸ˜‰

old hound
#

Anyone have done the "WINDOWS PRIVILEGE ESCALATION - Pillaging" ?
I may need a hint

acoustic owl
old hound
#

"Restore the directory containing the files needed to obtain the password hashes for local users. Submit the Administrator hash as the answer."

#

I restored a backup containing SAM and SYSTEM Files
I retrieved the hashes with samdump2 but it wont accept the answer

thorn urchin
#

I think its the nt hash part but Idr

acoustic owl
old hound
#

I tried every combinations

acoustic owl
#

Are you sure you don't have any spaces at the end?

old hound
#

after a second look on the hashes from all accounts - they are mostly the same.
Never use samdump2, use secretsdump

graceful rampart
#

Funnily enough I just told that to someone else who was struggling with the password attacks module

old hound
# dim wolf nvm

sorry, I guess I was a little bit late. You can message it in private if you want

dim wolf
#

did you get the hash?

old hound
#

yea

dim wolf
#

then everything's good

graceful rampart
hot merlin
#

Ehi guys anyone for help me on Module AD Enumeration & Attacks - Skills Assessment Part I and 3 answer Crack the account's password. Submit the cleartext value.?? I'm stuck :(... i have login in MS01 and WEB01 and found a flag.txt but not found a password svc_sql

wanton sapphire
#

Hey guys i need help

#

How yo install the von

#

Vpn

#

I have problems to install the ovpn

raw elbow
wanton sapphire
#

Have problems with the terminal install

thorn urchin
#

you need to supply more information than that or else nobody can help you

hot merlin
#

ok found hash and crack

graceful rampart
#

πŸ‘

raven cairn
devout flint
#

can someone tell if you have connection to this machine

fathom pendant
#

Yep

fathom pendant
devout flint
#

no i just didnt have connection to it

fathom pendant
#

Not sure then

devout flint
#

it seems it working know

#

thank you

fathom pendant
#

Good luck with your answers

marble raft
#

Hi guys! Any help on Predictable Reset Token? Kinda lost to be honest, script doesn't seem to work and i idk why

drifting canopy
#

Hi!
New Member to the Academy. I'm working on Public Exploits (Page 9) of the Pentesting Basics. I'm trying to answer the question, but the instance nor my Kali with an active VPN tunnel can hit the box. Trying to do a Nmap to find out what services are running. They both get the same error: it can't reach the machine's IP. Any help is appreciated. I've reset the target and instance multiple times. Current target is: 178.128.37.153:30664

graceful rampart
#

That's a docker machine. You can't ping it. Usually your not supposed to nmap them either. Don't remember that module but it's likely hosting a website (or some other service that your told about in the exercise description)

drifting canopy
#

@graceful rampart Thanks for the quick reply. The lesson is an introduction to Metasploit. The question is "Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start)" So was thinking enumeration with nmap to find out software versions. Will poke further. Thanks!

graceful rampart
#

Np

drifting canopy
#

@graceful rampart Yep you were right. Website.