#modules

1 messages · Page 51 of 1

vital adder
#

but other tools should work just fine

fathom pendant
#

I'm not seeing a question that's asking or requiring that tbh

acoustic owl
#

I have already sent him the answer. This question should not stop him from taking the exam.

fathom pendant
#

But if you're having issues: is it by chance with paydiant.com

peak hamlet
#

exactly 😛 , will try what you recommended 👍🏻

fathom pendant
#

Oh wait

#

I'm dumb

#

Read as the info gathering not attacking services

peak hamlet
#

@fathom pendant Maybe you thought its the footprinting module 😛

fathom pendant
#

I need a longer nap

peak hamlet
fathom pendant
#

Coffee doesn't have an effect on me

#

Aside from bathroom

vital adder
peak hamlet
#

2x of dark roast > energy drinks

fathom pendant
#

My body literally is unaffected by caffeine

#

I can down a can of monster and still sleep

vital adder
#

that is both a blessing and a curse

acoustic owl
vital adder
#

or from a caffeine addicted guy named networkchuck

acoustic owl
#

Have you ever ordered coffee from him? Is it good?

peak hamlet
vital adder
#

i think i did but it's been a while ago and it's i would say medium not that good but not bad like at all

nimble warren
#

Hi, Currently im doing the Public exploits section (in getting started module) where I have to use msfconsole with the /windows/smb/ms17_010_psexec exploit.
When I do only the things what the site tell me to do (set RHOSTS and LHOST) I get an error, and when I set the port number as well, i get a different error (both can be seen in the ss). What am I missing here?

devout cliff
#

alright my workaround to make crackmapexec work is to install poetry and use it through that 😛

#

idk what happened with the install that comes with parrotos sec

fathom pendant
# nimble warren

That's because I don't think eternalblue (msf017_010) is the exploit here, did you enumerate the target spawned to verify that's what you should be using?

nimble warren
fathom pendant
#

Hint: this is a web server; not a host machine

#

The eternal blue sploit is just an example

#

Perhaps you should visit that IP in a browser ;) that will help you find the actual exploit

#

Step 1 of any attack: enumerate/find info

nimble warren
fathom pendant
#

You can't

nimble warren
#

good to know... 😄

#

thanks

fathom pendant
#

Eternalblue is specifically an exploit targeting SMB (port 445)

dim wolf
#

you can use info to get a description of the module you currently have selected

fathom pendant
#

^

rustic sage
#

I'm stuck at the SSRF Exploitation Example module. When I try to follow the SSRF exploit I get no response back even though I have my nc listener on port 8080:

fathom pendant
#

Is that the IP of the spawned target?

rustic sage
#

the first ip, yes

fathom pendant
#

Are you able to ping it to verify its up?

rustic sage
#

let me check

storm cargo
#

hello guys, someone already did the Login brute forcing module ?

fathom pendant
rustic sage
fathom pendant
#

Are you able to visit the page?

#

The IP*

storm cargo
#

oh ok, i used hydra for username and password and idk why but it's doesn't work

barren dirge
#

If I generate a public key from open SSH private key with "ssh-keygen -y -f <file> > whatever.pub" and when I try to use it with ssh login and I get: Load key "whatever.pub": error in libcrypto. Whats wrong with my public key? I added 600 permissions to it.

rustic sage
rustic sage
unreal granite
#

iam stck again somebody help ? What user account on the Domain Controller has many Event ID (4625) logon failures generated in rapid succession, which is indicative of a password brute forcing attack? Flag is the name of the user account.

#

i tryed everything

#

someone help

#

this is the last thing i tried

#

wevtutil qe Security /c:30 /rd:true /f:text /q:"Event[System[(EventID=4625)]]" | findstr /i "time provider status code user"

unreal granite
#

sry

dim wolf
unreal granite
#

INTRODUCTION TO WINDOWS COMMAND LINE

barren dirge
fathom pendant
#

You can't just arbitrarily use your own key to ssh into something

#

Hint: look at the type of server it is and start there

barren dirge
fathom pendant
#

If it's about what the "public string" is remember there's a tool to help find that

#

onesixtyone

barren dirge
#

Nooo, I think Im past that already

unreal granite
barren dirge
fathom pendant
barren dirge
fathom pendant
#

Why do you need the private key????

#

Like ask why first

#

But also maybe a look at some history may serve you well

barren dirge
#

FFFFFFF, sorry., sorry, sorry.

storm cargo
fathom pendant
#

Maybe a list of all the files you land in can help

rustic sage
#

hi

#

im kinda new in hack the box

barren dirge
#

Yeah, Im just blind / confused. Nvm. I have everything I need for next step. Sorry about that

fathom pendant
#

Lol all good, that's why I was like "why are you overcomplicated this lmfao"

#

/starthere

devout cliff
#

anyone that has completed the attacking common services module, im on the smb section atm and can't find jason's pw. tried using crackmapexec to bruteforce it with the list provided and didnt find anything. anyone can give me a nudge?

fathom pendant
#

Reee bot autofill commands not working

#

Anyway

fathom pendant
storm cargo
#

who knows why i have this results ?

fathom pendant
#

Haven't done that yet, be patient and someone may have the answer, in the meantime try and look for other things i.e. is there a hint it gives you that may narrow your results

dim wolf
fathom pendant
storm cargo
#

ok thanks

unreal granite
acoustic owl
dim wolf
#

read what marcie told you

devout cliff
unreal granite
devout cliff
acoustic owl
jaunty vigil
#

shells & payloads skill assessment freerdp dies instantly

#

pretty much 30s -1m after logging in i can't use it anymore

cedar whale
#

this is not the server name? big_think

#

^^ skill assessment of information gathering - web edition

topaz lantern
#

save the request with Burp and use it along with -T (searching for the flag)

acoustic owl
cedar whale
jaunty vigil
#

"The Live engagement is literally unusable... xfreerdp on the jump box dies instantly

#

by the time i launch msfvenom it dies

#

and i have to wait like 5 minutes for it to respanw

#

and try again

#

any admins can takea look

#

and the bottom right help thing completely invisible to me i have not clue why, this is so frustrating

#

soo frustrating..

feral stump
#

Try Remmina

jaunty vigil
fathom pendant
#

Try removing the \ before the !

raw field
#

I am working on the Responder box where I have to use the Responder utility, but I get an error when I try to run it. Installing the 'missing package' hasn't been successful so far

fathom pendant
deft escarp
#

finished a box... but had to use a hint for the first time :(, doesn't feel like I Really earned it even though I spent like 3-4 hours trying to figure out what to exploit

tall notch
#

hello

hazy grotto
#

Pivoting Remote/Reverse Port Forwarding with SSH

#

This was the given code.

#

ssh -R <InternalIPofPivotHost>:8080:0.0.0.0:8000 ubuntu@<ipAddressofTarget> -vN

#

Would the internalIPofPivothost be the ip given to us here?

#

Or is it the IP address that connects to the windows target? the one thats the answer for Question one....

IPADDRESSofTARGET? Same...

I'm confused so i want to make sure i am doing this right.

graceful rampart
graceful rampart
hazy grotto
#

oh

#

Soooo the ip that it gives me?

graceful rampart
#

Idk what the questions are. I'm in the car stuck in traffic lol

hazy grotto
#

in the picture above. That's the linux pivot ip

graceful rampart
#

Well, in order to understand you need to break down the command. -R specifies to create a reverse port forward. You specify that with the format <Internal IP>:<PORT>:<External IP>:<PORT>. The internal IP is the IP that's on the internal network that you want to access. The port can be whatever. The external IP is the IP of the machine that you can ALREADY access. In this case it's 0.0.0.0 which means all interfaces on the target will be used.

Then you need to specify your ssh login. The format for that is the same as any ssh command. <user>@<External IP>. The external IP is the one you can access from your attack machine (here you need the actual ip not 0.0.0.0)

#

I hope that makes sense

#

@hazy grotto

zinc trench
#

can someone please send me an RDP link

hazy grotto
hazy grotto
trim canopy
#

Hello am new gere

graceful rampart
#

Internal IP

trim canopy
#

Hope am welcome

hazy grotto
trim canopy
#

You have nothing to do with my profile okay

hazy grotto
#

00000?

#

or the 129?

rustic sage
#

I have just finished the file upload skills assessment and am now looking into the web servers configurations.
Can someone point me ||to the file were the (reverse) double extension (e.g., .php.jpg) misconfiguration|| may appear?

solid wedge
trim canopy
#

Yes

solid wedge
#

Oh I am in the Pentester job role path

solid wedge
trim canopy
#

Please who can teach me here

trim canopy
solid wedge
trim canopy
#

Don that no one replied am tried

graceful rampart
#

Read the rules. We don't do malicious things here and that sounds very malicious. Stop asking

solid wedge
#

What is the name of the accessible share on the target? can someone hint me in the right direction

fathom pendant
#

@novel matrix

solid wedge
#

I am stuck in SMB Module

livid zephyr
#

module -> footprinting/DNS. For "What is the FQDN of the host where the last octect ends with "x.x.x.203"? question , I used dnsenum with all the txt pages on the SecList/Discovery/DNS directory and still didn't see any IP with the "203" octect. Any ideas?

solid wedge
fathom pendant
#

No the ping wasn't about you

solid wedge
novel matrix
solid wedge
#

What is the name of the accessible share on the target? can someone hint this in the SMB module

pine dagger
#

Anyone done "Pass The Ticket in Windows" in Password Attacks? I'm trying to RDP to the host with the provided credentials, and it keeps coming back with Logon Failure.

#

Ah nevermind, enclose the password in single quotes.

rotund junco
#

Hi! I’m in Linux Fundamentals in Page 10 “Navigator” at second question for index number on sudoers

#

With comand ls -i sudoers i see number 964110

#

But it’s wrong

#

By htb

hazy grotto
#

@sharp cove

#

Is someone going to boot this loser?

jaunty vigil
#

can anyone dm me about password mutaliations in the password cracking module?

jaunty vigil
#

nvm got it

#

i found some hints that will lower the time

#

idk how it hasn't gotten an update

hazy grotto
#

@novel matrix You going to kick that obvious scammer?

past grove
#

Hi!

I'm having a bit of a problem with the public exploits part of the "getting started" module. I don't understand how I can exploit the server, I can't find any vulnerabilities that I can use on the Apache server and I am just completely lost on what I should do. Could someone help me? Thanks

hollow bramble
#

In Attacking Common Services - Lab Hard I've got some questions about my bruteforcing results if anyone has a minute?

faint rampart
fathom pendant
faint rampart
fathom pendant
#

No I'm not at my computer to check anything

faint rampart
#

Alright then...

analog tendon
#

hey would anyone be able to assist in Information Gathering - Web Edition Active Infrastructure Identification. im having issues reaching the 2 addresses listed

honest ridge
#

you added the vhosts?

analog tendon
#

added?

#

to my host file?

fathom pendant
#

yes

honest ridge
#

IP app.inlanefreight.local
IP dev.inlanefreight.local to /etc/hosts

analog tendon
#

no i didnt. but ill do that. thanks

fathom pendant
prime basalt
#

please i need help in C programming

fathom pendant
#

For the target

honest ridge
analog tendon
#

right i understand that

#

just didnt say in the module that those needed added. my B

fathom pendant
analog tendon
#

thanks @fathom pendant and @honest ridge

vale salmon
#

So I am working on File Upload Attacks (Client-Side Validation). When I inspect the page and take out the validation, it still tells me I can only upload images. Even if I take out the file types, or add .php, I still get the same message. I am not sure what I am doing wrong, but I can't get it to let me upload a shell I can access.

graceful mortar
#

someone finish linux buffer overflow could hep me?

analog tendon
#

could use assistance in the active subdomain enumeration. is there something im supposed to add when searching for the given name server? anytime i use the nslookup or tools and using the given ip i get a communication error and then server cant find <address>

#

or dig tools*

honest ridge
#

^^ im having issues aswell.

#

if someone could dm me or jump in a disc channel to help explain some things would be super helpful

analog tendon
honest ridge
#

I get the gist of it but not enough to do much. just waiting for help while reading through it. ill message you later if i figure it

analog tendon
#

sure same here. and yea i get it too but when there is nothing but communication errors im not sure what i can do at this time.

full echo
#

Use the plaintext switch to encrypt the forge cookie

quasi wave
#

hi I need help with the second to last section of AD module

#

its not giving me permission to add the user which doesn't make any sense

novel matrix
#

Please read the rules.

quasi wave
#

hi nevermind I am figuring it out fine

#

I'm having trouble with the second to last module but a different section

fathom pendant
analog tendon
#

same with nslookup -type=ns

fathom pendant
#

And you're on the VPN?

analog tendon
#

yes. using the udp connection

#

when i went to the next section i was able to start grabbing flags

fathom pendant
#

Give me an hour I'll be back at my computer to sanity check

analog tendon
#

sure

#

thanks

versed frost
#

hey guys, in Passwd, Shadow & Opasswd section of Password Attack module, are we suppose to complete the question as we learned from the section? becuase whenever, I try to get the /etc/shadow, it needs a root permission in order to copy it, but the files could be found else where on the sys (not saying where to not become a spoiler)?

fathom pendant
#

And you've tried the nslookup with both the IP and the domain name? nslookup -type=NS {IP}

analog tendon
#

yes

#

no matter which command i used in whatever way i just got a communication error. thought it was a vpn issue too but i can grab header flags in the next section with no problem

fathom pendant
#

Ok ThumbsUpCat

honest ridge
#

@analog tendon im on "Find and submit the contents of the TXT record as the answer." you sus that one?

#

figured it be easy with just dig txt @ url/ip

#

gues not. lol

analog tendon
fathom pendant
analog tendon
quasi wave
#

almost finished with Active Directory Module

#

lol this is great

#

I love this stuff

#

on very last section of module and still haven't figured it out

#

once I finish AD I'm gonna go onto the next thing which probably is bash scripting and windows command line

#

lol

#

I like how HTB Modules can be used as prerequisites to get to HTB Main Platform boxes

#

and how there is a system to match HTB Modules with HTB Main Platform boxes

#

that's what I'm gonna spend my time on

#

lol

versed frost
quasi wave
kindred loom
#

Sorry for OffTopic, Is it possible for us to have a white mode theme of Academy instead of always black one...

fathom pendant
#

wanting white mode

#

but in all seriousness that's more of something you may squeak by asking in #1024429874246590575 or something

kindred loom
#

I'll ask there, sorry for disturb. I'm here to ask because that I guess there might not be official ones in #1024429874246590575

fathom pendant
fathom pendant
analog tendon
#

thats funny that you messaged. i did all that bout 10 seconds ago and got it

fathom pendant
#

@honest ridge also it's not on the main domain; the txt record is on a subdomain :)

honest ridge
fathom pendant
#

doable with the nslookup as well

#

though if you're searching for txt records you'd do -query=txt

honest ridge
#

isnt it the same thing with dig? ive done dif axfr inlanefreight.htb ip then does its thing. then im blank on next step. been at it for hours still noidea

fathom pendant
#

so if you've done the dig; you should see a list of the different subdomains yeah?

honest ridge
#

yeah

#

then try query txt against them. altho it was manly not sure how to put all in file then run dig txt agaisnt each

#

manual*

fathom pendant
#

you'd need to first basically strip the dig to JUST the sudomains

#

that requires some extra knowledge of commands ; but you can start with dig ... | grep -v ";" | cut -f1 | sort -u

#

each pipe basically ripping out different parts

#

from that you may be able to do a for loop

#

if you know how to use sed you can further cut that list down

honest ridge
#

i really dont know much about txt manipulation

fathom pendant
#

grep -v does an inverse search for what you input (the ";" is used as a comment character), cut takes the out put and -f says in the first field only show that, sort -u just sorts by unique so it takes care of any weird dupes

analog tendon
#

do they really want us to count all these subdomains up? there is alot

honest ridge
#

mmmm confusing. might have to find a tutorial on it

fathom pendant
analog tendon
#

yea. after getting that one thing straightened out i was able to fly through getting zone transfer records. i was able to get the TXT file. did @honest ridge figure that out or is that what you all are working on?

honest ridge
#

stil trying 😂

fathom pendant
analog tendon
#

i got the number. i just copy pasted all the records into a numbered text editor and then divided by 2

fathom pendant
#

i mean

#

that works ig

#

¯_(ツ)_/¯

analog tendon
#

lol

fathom pendant
#

if you know how to filter results it's super easy

#

grep, cut, sed are all powerful tools

analog tendon
#

yea but im tired and i didnt want to play with the syntax. but perhaps next time

honest ridge
#

maybe im just so spent and cant think. is there any site you recommend to learn?

fathom pendant
#

just look up the man pages or google "how to do x"

#

for instance how do I show the opposite result of a grep command

#

first result on google

#

you can get pretty far if you google

#

because 9 times out of 10 your question has been asked

#

:)

honest ridge
#

been googling all day but think im just whacked out for today. i got the answer after manually doing it, which would get pretty shit after a while. really do need to get better and grep/cut etc

fathom pendant
#

if you're wondering the pipe | just says "take the standard output of this command, and use it as the standard input of the next command"

honest ridge
#

yeah, thats about the only thing i know lol

fathom pendant
#

regex is a useful thing to keep in mind

#

as it can substitute a LOT

honest ridge
#

yeah, its overwhelming

fathom pendant
#

that's why i posted the cheatsheet for regex :)

honest ridge
#

cheers, completed this module, altho ima have to go back over it at some stage as i clearly have alot to learn and be more proficient at

#

cheers @fathom pendant

fathom pendant
#

run this :) it will tell you all your loopback, eth0,tun0, etc. ip a | grep "[0-9]*\.[0-9]*\.[0-9]*\.[0-9]*/[0-9]*"

past grove
#

@faint rampart @fathom pendant Thank you for your help!

novel matrix
#

Not the appropriate question for this channel unless it is module related.

rose gate
#

hi guys, can someone help me please with the module: ATTACKING COMMON SERVICES-Attacking DNS?, I tried all kind enumeration (fierce, subfinder, subbrute) but there is nothing, even I tried gobuster and found 4 subdomains (ns, control, helpdesk, NS) but none have the flag. Edit (Solved): finally I got it, for whoever that is stuck in this section, my hint is: Don't add the target ip spawned to the /etc/hosts, use subbrute and any query with dig, do it with @<Target ip spawned>. Regards

rugged veldt
#

Hi there, for the IMAP/POP3 section of the Footprinting module. I am trying to obtain the admin email address, I have gotten it from one of the commands they used within the resource but it wont accept it?

rugged veldt
#

got it

weary shoal
#

any hint for module 57 section 516?..
been trying for hours with no success... 😦

digital zodiac
#

<?php
if(!isset($_GET['page'])) {
include "main.php";
}
else {
$page = $_GET['page'];
if (strpos($page, "..") !== false) {
include "error.php";
}
else {
include $page . ".php";
}
}
?>

Hello everyone, I'm stuck here, I tried to bypass the extension using empty bytes but I couldn't. Is there anyone who can help?

past grove
#

Is one supposed to use the LinPEAS script to do the privilege escalation part of "Getting Started"?

#

I have gotten access to user2 but I'm not sure how to get root

#

I can't write to root's SSH keys, I have not been able to run a kernel exploit (although I found one), I'm not sure what else I can do

digital zodiac
#

What is kernel version ?

past grove
#

5.10.0

digital zodiac
#

Unlucky

past grove
#

It is vulnerable to DirtyPipe but I haven't been able to get any of the scripts I found to run successfully

digital zodiac
#

İf be 4.15 you can use PwnKit

past grove
#

And Metasploit seems to need a meterpreter session first to run its script but I don't have it

digital zodiac
#

i can't remember bro

#

i don't remember how i solved it

past grove
#

Thank you for being willing to help

scenic plank
#

Hello, it is possible to make all modules as free user? Or i must buy cubes?

past grove
#

You get cubes for completing modules so those are probably enough

scenic plank
#

Yes, but i must spend some to buy module. Example module is for 500 and i can earn 200 if completed

#

So im -300

past grove
#

Oh I see

#

Well, I'm very new to this, so I can't answer that

#

And in fact I'm kind of lost right now as well

scenic plank
autumn pilot
#

no

sonic thunder
#

Keep it legal yea 😬

#

Ok I will try to find difrend server

past grove
#

Is there any kind of walkthrough for people who are lost? The hint just tells me to not forget to chmod but I assume it's talking about SSH keys, I can't use the keys, I can't write to root's keys file

placid quest
#

@past grove what is the problem

devout torrent
#

Did you download the key @past grove but can’t open it ?

past grove
#

I am in the privilege escalation part of "getting started", I have gained access to user2 but I am not sure how to get the root user, the hint and the stuff in the computer lead me to believe I should plant an SSH key but I can't modify root's authorized_keys so I am not sure what to do

#

I have found that the computer's kernel (5.10.0) is vulnerable to the dirty pipe exploit, but I haven't been able to run a script for it

devout torrent
#

I am not sure if I remember correct, but I think thats the module where you log as user2, and there there is a file id_rsa you can download

#

I think thats the whole case of that module, that you can use other options to authenticate via ssh

past grove
#

Oh my yes I can read that

#

Thank you!

#

Wow that worked

#

Damn

#

Thank you!

rustic sage
#

Module Password-Attacks, section Protected-Archives: i am unable to crack Kira's file Notes.zip. I tried Hashcat (all zip formats), John with the provided password list, rockyou, etc. Nothing works. Any hint?
Edit: got it (use custom.rule)

supple jackal
#

hey all, im trying to understand some code i just wrote lol i dont want to be a script kitty.. so pretty much i need to obtain the source code of this website and filter all unique paths of that domain.. i have done that but i do not understand the hole code, i get most of it but some is still a little hard for me to understand.

autumn pilot
#

the output is not a code

#

and what you are executing is a set of commands in certain order

rustic sage
#

I have just finished the file upload skills assessment and am now looking into the web servers configurations and trying to find were it would be fixed.
Can someone point me ||to the file were the (reverse) double extension (e.g., .php.jpg) misconfiguration|| may appear?

tight void
#

For the "shells and payloads" final skills assessment (pen tester path), how are we supposed to get a browser to reach the targets? The foothold PC doesn't have firefox and the other browsers dont seem to work. Haven't figured out how to get the pwnbox browser to reach the target ip's either

rustic sage
#

I am new, please help me*

#

i literally just joined hackthebox

#

idk how to hack

#

and idk any codes

#

or coding languages

winged zodiac
novel matrix
silver zenith
rustic sage
#

Any tips for the easy lab in Password Attacks? I tried to brute force both ssh and ftp, with the provided username, password list, the mutated version with the custom rule, rockyou, etc. Nada, nothing. Ugh.

devout cliff
#

hey everyone, im on the MSSQL section of attacking common services. i just need a nudge on the first question Nevermind i got the next step

stiff flume
fossil sierra
#

Should I buy VIP on hackthebox.com or is there other websites I can learn hacking and programming?

calm abyss
#

Hello i am stuck at Automated Scanning

https://academy.hackthebox.com/module/23/section/1494

I managed to scan for a parameter and i am able to read the /etc/password

But nothing else seams to work, no log poisoning, there is no session cookie
PHP wrappers are not working
There is no image upload so i can remote hack it

I am stuck, stuck, stuck

vague lotus
#

Hello, I'm currently unable to successfully run the loader.py script from module 85 section 905:

#!/usr/bin/python3

import sys
from pwn import *

context(os="linux", arch="amd64", log_level="error")

run_shellcode(unhex(sys.argv[1])).interactive()

When executing the command:
python3 loader.py '4831db66bb79215348bb422041636164656d5348bb48656c6c6f204854534889e64831c0b0014831ff40b7014831d2b2120f054831c0043c4030ff0f05'

I get the following error:

pwnlib.exception.PwnlibException: There was an error running ['/usr/bin/x86_64-linux-gnu-ld', '--oformat=elf64-x86-64', '-EL', '-z', 'execstack', '-o', '/tmp/pwn-asm-d5l4ohgp/step3-elf', '/tmp/pwn-asm-d5l4ohgp/step2-obj']:
It had this on stdout:
/usr/bin/x86_64-linux-gnu-ld: warning: /tmp/pwn-asm-d5l4ohgp/step3-elf has a LOAD segment with RWX permissions

Anybody know what to do from here?

cedar whale
#

the fuzzing of the ffuf section suddenly seems to go really slow 😦

calm abyss
fathom pendant
fathom pendant
vague lotus
#

@fathom pendant - Shellcodes

tight void
cinder mortar
#

Anyone i can dm for "information gathering - web edition, active subdomain enumeration section" question 2?

fathom pendant
#

Just ask the question

cinder mortar
#

i did dig axfr

#

is the number of zones not the number shown at the btm?

#

so 22

dim wolf
#

records are not zones.

fathom pendant
#

No; hint, what type of record holds the number of zones and zone information
Also your screenshot shows IPS which are used to answer other questions

analog tendon
#

so close.

fathom pendant
#

Either way, your output has the answer if you look closely.

#

(not the ss you shared)

cinder mortar
#

oh got it

#

just had to re read the module

#

thanks

fathom pendant
#

Yeah that tends to help answer questions:)

storm cargo
#

someone desn't have connection too right now ?

#

or i am alone?

fathom pendant
#

?

drowsy ingot
#

PS C:\htb> Get-Service | ? {$_.Status -eq "Running"} | select -First 2 |fl

#

sorry what is {$_.Status -eq

#

Is it the same grep ?

analog tendon
storm cargo
#

connection is down with all target

#

for me

analog tendon
#

did you reset the vpn connection?

storm cargo
#

i am on the pwnbox

#

i have

#

"the connection was reset"

analog tendon
#

ok. what are you trying to do to reach it? how much time is left on target?

storm cargo
#

that

#

83 min

dim wolf
#

actually, when i was doing the log poisoning section of the file inclusion module, whenever i put <?php system($_GET["cmd"]); ?> as the user agent header, the target machine completely died and resetting the machine didn't help... i needed to reset the machine until i got an entirely different IP for the site to display on my browser

sturdy pelican
#

can someone help me with the module network enumeration with nmap on the section Firewall and ids/ips evasion - medium lab, i was able to scan the network using the evasion techniques and scanned on the dns port and i got a version but its not correct am i just looking at the wrong port?
edit: the problem was that i was using the tcp vpn option, switching it to udp worked and now i got the flag

rustic sage
#

Hello, I can't start openvpn, it says "Unrecognized option or missing extra parameters(s) in (name file.ovpn):12: data-ciphers-fallback"
I am using VirtualBox Ubuntu 20.04.5

analog tendon
rustic sage
nocturne flicker
#

.

analog tendon
#

see if they both give you an error or if only one connects

balmy radish
#

Kali or parrot will have a lot of the tools you’ll need already installed for you and make things a lot easier if you are a beginner

uncut meadow
#

Hi team, I dont realy understand the question of the Skills Assessment - Web Fuzzing module : Before you run your page fuzzing scan, you should first run an extension fuzzing scan. What are the different extensions accepted by the domains? I know how to add extensions with -e or add wordlists with -w but not really how to run extension fuzzing. Can somebody help me?

analog tendon
#

unfortunately no

#

there will be some of the HTB machines that you use to learn with in the academy though

rustic sage
fathom pendant
analog tendon
#

well yea they are retired. but still htb machines available if you have the VIP which i may grab here in the next month or so

fathom pendant
#

Rank is earned on active machines/challenges; if your rank increases on completing academy content it's basically pay to win at that point, gating people that don't have the means to pay

#

Lol that's the student discount: not everyone has a student email

analog tendon
#

if your a student sure

rustic sage
fathom pendant
#

Yes : and completing courses does not equate to actually learning a skill

analog tendon
fathom pendant
#

You can put the cert on your resume once you obtain it. The htb rank gating is mostly to filter out people who are inactive

#

If you can afford it

#

vip gives you access to a bunch of retired boxes; and retired boxes tend to have writeups and walk-throughs ¯_(ツ)_/¯

#

Well writeups are a good tool to learn too; how readable is the write-up , how can you use some of the formatting in your own writeup as cpts requires a write-up alongside pwning the systems

#

Also it doesn't hurt to see if there's a way to do it faster

#

Improve your own methodology and such

dim wolf
uncut meadow
dim wolf
#

there is a part where it explains how to do extension fuzzing.

mossy marsh
#

hey there, Im looking for pen testers for the new project, if some one interested dm me

thorn urchin
#

or how about a mod like @winged hedge removes both yall

brave palm
#

hi guys, need some tips on the DOCUMENTATION & REPORTING - Skills Assessment module

#

im kinda stuck on that 1st question

#

theres a lot of stuff in there and i tried something but with no great results so far

echo roost
#

Firewall and IDS/IPS Evasion - Medium Lab - I keep getting ||TXT CHAOS? version.bind.in tcpdump|| and version ||NLnet Labs NSD|| but my version isn't accepted as the answer. Anyone feel like helping? I am stuck. I also get this (||Probe DNSVersionBindReq matched with DNSVersionBindReq line 12571): 10.129.37.80:53 is domain. Version: |NLnet Labs NSD|||||

thorn urchin
#

You're expected to rely on skills from the whole entire coursework for it

brave palm
winged hedge
#

@sly mantle I removed your message.

gritty peak
#

hey guys, I am 100% stuck, can anyone help me?

I am on the footprinting easy challange lab in Htb academy. I have spend 2 days on this and I am just completely stuck. I talked with someone who have solved it and he ran this command using hashcat:
hashcat -m 7300 crackme.txt SecLists\Passwords\Leaked-Databases\rockyou.txt -a 3

  1. Using -a 3 without any pattern, makes no sense(?)
  2. I used: hashcat -m 7300 crackme.txt SecLists\Passwords\Leaked-Databases\rockyouv2.txt -a 0 and the hash is not cracked.
  3. I also tried the hashcat -m 7300 crackme.txt SecLists\Passwords\Leaked-Databases\rockyouv2.txt -a 3 -o cracked.txt and that did not work either (I ran it for a long time and got no cracked hash into cracked.txt)

I ran the -a 3 attack, for about 40min on a 3080

can someone help me fix this so I can go on to the next challange? I have also tried this command:
hashcat -m 7300 crackme.txt -a 3 ?1?1?1?1?1?1?1?1 -1 ?d?u no sucess

sly mantle
limpid void
#

If user input is not handled carefully, it could be interpreted as a comment. Use a comment to login as admin without knowing the password. What is the first word on the webpage returned?

isnt the answer should be like administrator'--?

thorn urchin
limpid void
brave palm
thorn urchin
#

Yeah this one definitely strikes me as a longer assessment, especially if youre actually making the report like youre supposed to, it warns about needing to reset the lab and saving your work. Def dont expect yourself to clear it one day.

gritty peak
brave palm
limpid void
thorn urchin
thorn urchin
limpid void
#

really sorry new to this platform working on appointment level1

thorn urchin
#

never heard of that module

limpid void
#

on the starting point TIER 1 machines : machine name 'appointment'

gritty peak
limpid void
#

but doesn't ring any bells thats why

#

at that labs its like union select then command follows

#

and to enter as admin we simply modify the request by administrator'--

pine dagger
#

Shouldn't the question be in boxes rather than modules?

gritty peak
pine dagger
#

or in starting-point?

gritty peak
#

Maybe you need to do # instead of -- depending on what DBMS they use

limpid void
#

but its not working

#

i tried i know the flag that i passed using the admin'#

gritty peak
#

Use a comment to login as **admin** without knowing the password.

#

maybe try admin?

limpid void
#

not even administrator fits on it

#

if you dont mind can i dm you?

gritty peak
#

I am confused, are you guessing the flag?

#

the flag is: What is the first word on the webpage returned? so, the first word returend after you login as admin

#

Try using Admin as the username, instead of administaror

#

admin*

limpid void
#

can i dm you ':)

gritty peak
#

sure

leaden quail
#

Hello, im struggeling with the "Attacking Gitlab" Module. I downloaded the GitLab User Enumeration Script but get always different errors when running the Script (locally and pwnbox)

#

any Hints?

thorn urchin
raven cairn
#

Gimme a sec to think what I did

#

I remember the script was acting weird

#

Which is stupid.

#

I think I used 49821.sh from searchsploit

supple jackal
# autumn pilot the output is not a code

hey sorry had to work.. so what i really wanted to know was why this is happening, so for cut my -d is " ' " so on file 2 and again for ' " ' on file 2 why does that need to be put in.. why can i not just do something like //// cat hacker.txt | grep "http link " and forget tr and cut

echo roost
supple jackal
#

]

gritty peak
#

ey madf0x, can you take a look at my question about hashcat? I don't understand why It does not work and I have been stuck for 2 days because I can't crack the hash using rockyou, which other people have done to solve the task

echo roost
supple jackal
#

sorry

#

i thought i was in my terminal

#

lol

leaden quail
#

but thanks

echo roost
#

I am stuck

supple jackal
#

on what

wind gust
#

anyone did web attacks skill assessment?

thorn urchin
#

iirc that easy lab was actually the hardest of the three labs

supple jackal
#

why does this happen

gritty peak
thorn urchin
#

I dont actually remember a hash needing to be cracked for that lab, but that could just be how little I remember it

timber hatch
#

has anyone done the modul pivot, tunneling and port forwarding and can remember, if in the sectionDynamic Port Forwarding with SSH and SOCKS Tunneling, whether we should be able to follow this step at the screenshot? Because no Password is provided for the ssh login

placid quest
#

@timber hatch the password was provided at the end

timber hatch
#

ah shit. my bad. thanks!

echo roost
#

So far my command sudo nmap 10.129.37.80 -Pn -sS --disable-arp-ping --packet-trace --source-port 53 -sV -e tun0 and is also run the same command with -sU and I get a version and some sort of flag but it it's not accepted as an answer. Firewall and IDS/IPS Evasion - Medium Lab - I keep getting ||TXT CHAOS? version.bind.in tcpdump ||and version|| NLnet Labs NSD|| but my version isn't accepted as the answer. Anyone feel like helping? I am stuck. I also get this ||(Probe DNSVersionBindReq matched with DNSVersionBindReq line 12571): 10.129.37.80:53 is domain. Version: |NLnet Labs NSD|||||

supple jackal
#

that way to advance for me but sometimes when i put in answers there is a space and it mess everything up

thorn urchin
#

iirc I had to use a non-nmap way to get the version properly

echo roost
thorn urchin
#

At work atm and I dont have notes on that section so wouldnt be very useful to you

echo roost
#

ok no worries

thorn urchin
#

other than knowing theres other ways to research doing it

echo roost
#

tried ncat, and nc

supple jackal
#

can anyone explain to me why this would happen

#

what is the importance of the cut and the tr... what does \n do to the space and why remove ' " ' " ' "

thorn urchin
echo roost
#

Evertime you run the command it add a newline with

supple jackal
#

no its counting

echo roost
#

hmmm

supple jackal
#

im trying to get the number of unique paths from a source code

echo roost
thorn urchin
thorn urchin
echo roost
#

I did it won't accept the answer

thorn urchin
#

you can DM the flag and I can at least say if it looks right or not

echo roost
echo roost
#

Nm - I got it - had to run the -sU option

thorn urchin
#

nice

devout cliff
#

quick question on the dns section of attacking common services module - for the question what method would you normally use to find the subdomain of the dns server?

devout cliff
thorn urchin
#

to find out

devout cliff
#

can you do subbrute without adding a resolver?

thorn urchin
#

its not magic

acoustic owl
devout cliff
#

so you just use inlanefreight.htb as the resolver?

acoustic owl
#

No, inlanefreight.htb as Domain and the Target IP as resolver

devout cliff
#

ok i get it

#

big click in my brain

#

gotcha

acoustic owl
#

$cat resolvers.txt
10.129.203.6

devout cliff
#

how long does it usually take for it to run?

unreal grail
#

Does HiveMind pop up for you? I can't join the chat support.

spark shadow
#

is there an off topic channel for chatting?

woeful ermine
#

channels under HTB:offtopic I guess

hazy grotto
#

Sometimes after doing something 200x over and over again trying to get something to work. You wonder..... Is this worth it?

mellow turtle
#

Hey whats the pwnbox bloodhound neo4j server user and password?

thorn urchin
hazy grotto
#

I read his profile.

thorn urchin
#

¯_(ツ)_/¯

slender kelp
#

I'm at the end of the windows fundamentals module. Not sure how the page would know the answer to the last two questions (SIDs for an account and a group)

hazy grotto
#

I'm just kidding. idk but it appeared so.

slender kelp
#

oh. time to reset the machine then, haha

hazy grotto
#

PLEASE SOMEONE HELP ME

#

Pivoting

#

question two

#

I cna't get metasploit to catch the shell

slender kelp
#

cheers madf0x, I'm through the module now 🥳

hazy grotto
#

@vital adder Are you available? I feel like you have delt with my problem already.

manic hornet
#

how is this not right

slender kelp
#

I believe you need to start your answer with 41

fathom pendant
manic hornet
#

still keep getting it wrong

fathom pendant
#

What module is it?

#

Also leading/trailing spaces can fuck it up

manic hornet
#

Crackmapexec

manic hornet
#

sone of

fathom pendant
#

:)

#

It happens

manic hornet
dim wolf
#

why can't i get rce on any of these webshells on file upload attacks - whitelist filters

kind turret
#

Please remove the spoilers.

unborn cave
#

That's spoil. Sorry.

dim wolf
#

ignore the fact that i screwed up the php

fathom pendant
#

...

#

Does it work now

dim wolf
#

no.

#

i'm trying it with every php extension in PayloadsAllTheThings with different payloads

#

using the bash script to generate each payload

#

there's no way a reverse shell is going to work but let's just try anyway

thorn urchin
#

Did you actually confirm any valid extensions yet

#

Personally I used a script generated list of extensions and then used ffuf to brute upload all of them, and then used ffuf again to call ID on each of them and filtered out for ones that returned data

#

was like 2-3~ of em that worked

dim wolf
#

looking in burp suite and there are successful file uploads which i run into repeater and navigate to in the browser

#

but the php is always commented out

thorn urchin
#

not all successful uploads are good payloads

#

well your posted example has you commenting then out so

#

how about you roll over and die useless parasite

dim wolf
#

hmm..

graceful rampart
# dim wolf

I mean, your payload is just a comment. Im not really sure what you were expecting

dim wolf
#

yeah but i'm not commenting the payload

thorn urchin
#

whats your raw payload youre uploading

graceful rampart
#

What payload are you usint?

dim wolf
#

||<?php system($_REQUEST['cmd']); ?>||

graceful rampart
#

Then your looking in the wrong place

#

Cuz the image you uploaded is co oletely different

#

Not just the comments. This payload uses $REQUEST the one in the image dosent

dim wolf
#

i ask you ignore the typo

thorn urchin
#

looks sane, might just be looking at uploads that simply dont work

stuck hull
#

On the Intro To Windows Command Line - Skills Assessment, can someone help me with the 5th question. Where there are lots of directories and files and the flag is one of them.

dim wolf
#

if the file name is ||shell.pgif%0a.jpg|| or something similar how do i ... type?? it in the browser

thorn urchin
#

just like that

#

also that doesnt look like one of the valid extensions I remember fwiw

dim wolf
#

ok just making sure.. the target timed out so i have to wait 30 minutes again

thorn urchin
#

if your list is good, ffuf makes this like a 10minute challenge to pass

dim wolf
#

oh yeah ffuf's a thing i forg.t.

#

tunnelvision is real

slender kelp
drifting light
#

yo wsg yall

iron minnow
#

hello all 🙂 Requesting help for that challenge please After the configurations are transferred to the system, our client wants to know if it is possible to find out our target's DNS server version. Submit the DNS server version of the target as the answer. Went trough reading the forum already. Tried many Firewall bypass combination but no luck. Tried to go slower, same, tried to spoof, tried proxying, tried ncat... Thx for your help.

thorn urchin
#

Have you tried simple dns enumeration methods

#

and why would you try to bypass AV on a network enumeration issue?

iron minnow
#

I meant "Firewall" bypass (tired ;)) Yes, I did try simple enumeration methods. -sS, sV, sC, n, Pn, f .... I tried decoys also and using different source IP and proxying

thorn urchin
#

well if you used decoys and diff source IP youre never gunna get a response back

#

not sure what in the environment you could use to proxy either

#

The section info does tell you what method to use

iron minnow
#

the hint does not talks to me ||During the meeting, the administrators talked about the host we tested as a publicly accessible server that was not mentioned before.||

thorn urchin
#

yeah that hint is nonesense that means nothing

iron minnow
#

so do you mind directing me to the correct flag? spend hours on that one, loosing a lot of time I think...

fathom pendant
#

Try combining flags

#

Also this flag is tricky

sturdy pelican
fathom pendant
#

Sometimes it's best to just do it from pwnbox

#

For some reason it works better there

sturdy pelican
#

Yea i had a problem using the tcp vpn

iron minnow
#

it would be a lot of wasted time if it was the case 😉 I'd go for -n -sS -Pn

sturdy pelican
#

But using the udp one it did work

fathom pendant
iron minnow
#

yeah that one of course 😉

fathom pendant
#

But tbh this is one of the few that is just a pain even with the right answer

sturdy pelican
#

Also think about what things an ids might not look at when a server needs to be publicly accessible

fathom pendant
sturdy pelican
#

Wel you have to bypass it to avoid it shutting you down right? Or am i thinking of the wrong section

fathom pendant
#

It's the hard lab that focuses on it more

sturdy pelican
#

Oh wel i might have just gotten lucky with the options i tried to avoid the ids

fathom pendant
#

It'll still work lol

#

Just not necessary

iron minnow
#

doing it from pwnbox.... suspens....

#

nope, still not

fathom pendant
#

Reset target repeat command

iron minnow
#

did it 😦

fathom pendant
#

This is the footprinting module yes? Firewall IDS/IPS evasion medium?

iron minnow
#

yes

#

the medium one

fathom pendant
#

Try a UDP scan

fathom pendant
#

Nice

iron minnow
#

yep, did that, was just expecting a VERSION (as the prompt says), not a flag.........

#

thx for your quick responses 🙂

fathom pendant
#

Again if it looks like a duck...

#

The hard lab though focuses a lot more on the IDS/IPS deployment

livid zephyr
#

the hint for Footprint/SMTP- for the enumerating username says "use the Footprinting-wordlist provided as resource". Where is that file? I tried running the ones from seclists unsuscesfully.

jaunty lodge
#

hi guys how are u?

#

i have a problem but i don't understand the cuestion on the module introduction to window

#

this one: What is the Build Number of the target workstation?

#

where can i found that?

dim wolf
#

what a pain.. here we go again (type filters - file upload attacks)

#

well it was a lot quicker than the last section

fathom pendant
spark shadow
spark shadow
thorn urchin
#

its that or start chatting about academy modulea

dim wolf
#

oh boy it's skills assessment time. on the academy module file uploads

full echo
#

DM me so I can help you out 🙂

hexed forge
#

The purpose of running the following commands in nmap: -Pn -n --disable-arp-ping are to reduce the noise of our scans correct? Or can they help obtain information we might not have been able to get without them?

thorn urchin
#

noise and startup time when you already know the box is up

hexed forge
#

ahh. so if I know the link is active there is no point in doing the scans that those cut out?

#

Can you restart a lab? Or once you submitted the correct answer will it not let you start again?

inner talon
raven cairn
#

Does anybody know how long it takes to crack the password on Password attacks - Passwd, Shadow & Opasswd ??

thorn urchin
#

moron

bright hazel
#

What's actually your business with me?

thorn urchin
#

read the server rules

bright hazel
#

Alright

thorn urchin
#

you dont even know where you are

#

useless trash

#

this channel is for discussing HTB Academy modules not your useless waste of oxygen

raven cairn
#

Lol i love how salty you get @thorn urchin kek

thorn urchin
#

This is my low level

raven cairn
#

it's a good reason tho. these dip shits wont shut up

hexed forge
#

-A includes the scans that would be performed in -sV plus more correct?

dim wolf
#

i can't find the file i am uploading on file attacks - skill assessment

#

i have the source code in front of me why can't i find it

graceful rampart
dim wolf
#

bro what is happening

bleak root
#

I have the same problem… Anyone can help with this?

graceful rampart
#

This. Sorry. Replied tot he worng message

graceful rampart
#

Lmao

inner talon
#

Has anyone done, or is doing, the "Firewall and IDS/IPS Evasion - Medium Lab" module? I got the version of dns but I don't think is right

novel matrix
#

👢

thorn urchin
#

I like how of you squint that dude was technically offering to sell passing module sections lol

graceful rampart
#

np!

inner talon
bronze sequoia
#

hi

inner talon
hexed forge
#

thats the answer

inner talon
hexed forge
#

IE HTB{XXXXXXXXXXXXXXXXXXXXXX}

#

I am actually going back through this one. I stumbled in to the answer yesterday, but have no idea how I did it

fathom pendant
inner talon
fathom pendant
hexed forge
#

do you have an extra space?

inner talon
#

nope

fathom pendant
#

Double check, go to the first character and hit backspace a few times

raven cairn
fathom pendant
#

Mhm

#

That one was more of a pain to me than the PtH and PtT

inner talon
#

actually, I'm in the medium module, not hard hahahahahha

#

so I got hard flag but not the medium hahahhahah

fathom pendant
#

Medium footprinting lab has you looking for the DNS server version

inner talon
#

yep

fathom pendant
#

Which is super simple

inner talon
fathom pendant
#

Nope

#

Reset target

#

The server version should come up as a HTB{..}

inner talon
hexed forge
#

If I am getting the state as filtered, it means I need to get around that to get to the answer?

hexed forge
#

No, I didnt mean, how do you do it. I mean if I see that, then it should tell me that I have to get around it

fathom pendant
#

hint: there's a scan that checks Versions

#

also fun fact so you don't have to do -sA -sS -sV... you can combine them like so -sSV, -sSCV, etc

#

makes life easier

hexed forge
#

really? that is great to know! thankyou

fathom pendant
#

yep

#

it's similar to if you're using netcat ; nc -lvnp you can do -l -n -v -p {port} if you want

hexed forge
#

can you combine -Pn -n --disable-arp-ping?

fathom pendant
#

no

#

the reason that those are able to be combined is because one; it's coded that way - and two they share the prefix -s

hexed forge
#

ahh. that makes sense.

#

You are better than chatgpt

fathom pendant
#

it's just something you pick up ¯_(ツ)_/¯

#

it's good to have in your notes a bit of info regarding whatever is your most common scan options

#

also with nmap you can put the IP at the very end

#

so you can have nmap {options} IP where the nmap {options} part is a copy paste

#

if you're familiar with creating variables you can take it a step further and export target={targetIP};

#

nmap {options} $target

#

lots of neat things really

hexed forge
#

oh I get it. baically have a notepad of all my different searches. And then when I went to use them, i just copy them and plant the ip at the end so I dont have to backspace to the front?

dim wolf
#

sanity check for file uploads - skills assessment?

fathom pendant
#

but you should keep a list of commands in your notes; alongside just general notes of the course

#

:)

hexed forge
#

I will start doing that. Thanks again!

fathom pendant
#

I suggest a notetaking application such as Obsidian; some people use cherry tree

#

but it makes it a lot easier to go back and check a specific section if you're like "oh god how do I upload files again, Oh yeah"

static roost
#

Currently getting rekt on File Inclusion skills assessment. Fuzzing for hours. So many word lists. help.

#

omg...nevermind...i swear

regal idol
#

Hi guys
am new hear......how to start on hackthebox.....

red obsidianBOT
dim wolf
#

i'm so done with this module...

hexed forge
#

I think the key is the type of scan you do

dim wolf
#

i got the flag

hexed forge
#

still wont take it?

dim wolf
#

no it took it

#

i'm just really pissed

hexed forge
#

ahh. gotcha.

dim wolf
#

obviously the key takeaway from this experience is to not do this during US nightly hours because you will never get the flag that way

hexed forge
#

the machines definitely seem to slow down at night.

dim wolf
#

it's not that

#

hackthebox is based in EU

#

i'm over in US which screwed everything up because of the timezone difference

hexed forge
#

ahh gotcha.

graceful mortar
#

hello, could any good soul help me with the bufferflow linux module? I've been stuck for 3 days. I get eip x66666666, I delete the characters but I don't get the reverse shell. please

thick dove
#

I am having such a hard time with the getting started | knowledge check privilege escalation. Anyone mind pointing me in the right direction? I know I have a no passwd for /usr/bin/php. I am just not sure how to exploit that

thorn urchin
#

but in general if you have root access to a programming language interpreter its gg

thick dove
#

essentially I have to figure out how to run a reverse shell command with the php interpreter?

#

This probably wouldn't take so long if these shells wouldn't work like garbage

thorn urchin
#

yes except why run a reverse shell when you already have shell

#

dont need to reverse anything

fathom pendant
#

^

#

just need to gtfobins to escalate privilege

young lance
#

yea these target spawns don't work half the time...

#

hard to know if it's my own incompetence or their issue..

fathom pendant
fathom pendant
young lance
#

AD?

#

well so far i've had a target spawn and not return anything from any enumerations

fathom pendant
#

Active Directory

young lance
#

then i have a friend spawn one and it works just fine

fathom pendant
#

have you tried resetting your vpn connection/regenning your vpn key? sometimes that can be an issue

vital adder
young lance
#

the getting started one. I've done bit of the linux fundementals but decided to try this one.

#

Yeah, i've done all that. Changed the tcp/udp as well

fathom pendant
#

if it's giving you the IP in the form of IP:PORT then it's a web server/docker container and standard enumeration techniques will not apply

young lance
#

weird thing is webservers will load in browser

#

gobuster seems to work to find the robot.txt

fathom pendant
#

yes

young lance
#

it taught on webserver

fathom pendant
#

but nmap and ping tend to not

#

:)

#

they are designed that way

young lance
#

weird...would think you could scan a webserver

fathom pendant
#

nope

#

gobuster/ffuf/etc. work because they do directory enumeration not scanning

#

they actively try and visit ip:port/page to see if it responds or not

young lance
#

yea issue is sometimes the provided webservers won't even be reached. They just give an error.

fathom pendant
#

it's all relative usually

young lance
#

I've had the issue where I literally used the same enumeration on my target with no success, then used a friends and easily found the flag

fathom pendant
#

¯_(ツ)_/¯

young lance
#

my target just did no work

fathom pendant
#

i take it you're using the pwnbox?

#

not your own vm?

young lance
#

nah, vm

fathom pendant
#

ah

young lance
#

succesfully connected to the vpn

#

and it works sometimes

#

annoying as hell

#

thought dude up there was maybe having my same issue

fathom pendant
#

¯_(ツ)_/¯

young lance
#

so guess i should stop this 8 intensity nmap sV scan that's got 5 hours remaining then huh lmao

fathom pendant
#

yeah

young lance
#

i did get some info from a webserver with a nmap scan before though

fathom pendant
#

because it's not going to yield anything

#

if the ip is not 10.x.x.x you're generally not gonna get anything out of the nmap scan

thick dove
#

This makes me feel very stupid 😡

fathom pendant
#

:)

young lance
#

See I just literally tried doing a gob on friends provided and it worked. Then i used it on my own and no ...

thick dove
#

So, I have a unprivileged shell on the system. I see that I need to use php somehow. I went to gtfobins and am looking at the php stuff. I am using sudo php -a to start the interpreted, but none of the commands do anything

high sentinel
#

what's sudo php -a? 😄

fathom pendant
#

i'm not seeing anything about sudo php -a on this page

thick dove
fathom pendant
thorn urchin
#

not the kind of shell you're wanting @thick dove

fathom pendant
#

literally just read the gtfobins php page

high sentinel
#

what do you mean by start a shell?

fathom pendant
#

you also don't need to start a shell

#

since you're IN a shell

#

you just need to break out

#

in fact there's a section on the gtfobins page that tells you exactly what to do with SUDO

high sentinel
#

sudo make me a sandwich 👀

fathom pendant
vital adder
high sentinel
thorn urchin
fathom pendant
vital adder
#

oh wait nope i remember this wrong it's was sudo-hax-me-a-sandwich

thick dove
#

Gah it does turn out that I am an idiot

#

just type in the commands as they were and forget about the php interpreter

fathom pendant
#

bingo

thick dove
#

Thanks for you help

hybrid nymph
#

Hello. all. In Attacking Common Services - Attacking FTP, the port that is the correct answer to the first question is closed, is that suppose to be the case? How am I suppose to get into it for the purpose of the example?

thick dove
#

My shell kept crapping out every 30 seconds. That made it harder

fathom pendant
#

php -r "{command}" is the php syntax for running a command; much like python3 -m runs the module you tell it to

thick dove
#

Yeah that makes sense to me now

#

I don't know why I got it in my head to run the interpreter

fathom pendant
#

all good; part of the learning process :D

thick dove
#

Now I can go take a nap. Catch you all tomorrow

fathom pendant
#

here's the takeaway; are you likely to make that same mistake again?

vital adder
hybrid nymph
#

Alrighty. After the 7th time ill ask support what to do.

full echo
#

Can you tell me what you have done so far?

thorn urchin
#

oh neat, documentation and reporting has at least one thing that ought to be a finding thats not listed.

winged zodiac
#

Hey I have caught up in footprinting-easy lab I have logged in as ceil via ssh but can't find the flag.txt I have seen viminfo file for searching vim history and details regarding flag.txt file

fathom pendant
#

maybe {user} isn't who has access to the flag ;)

#

dig around to see

#

lateral movement may be required

thorn urchin
#

So like for documentation and reporting, if the first thing you do pops a domain admin, like is that just what you put down for your attack path 🤔

fathom pendant
#

you mean got domain admin from the pops/pop3?

#

or

thorn urchin
#

no, I mean literally the first thing I sat down to do popped two domain admins for the skill assessment

#

I suppose still need to test that they actually work and that some tooling is not lying to me

#

popped == I have cleartext password for

fathom pendant
#

ah

#

the attack path would be
using tool: x - i was able to retrieve y, and verified manually that y is indeed correct

cinder mortar
#

can anyone help me with INFORMATION GATHERING - WEB EDITION virtual hosts question 3 onwards?

#

am i suppose to use another wordlist to fuzz for more vhosts?

fathom pendant
cinder mortar
#

which one?

thorn urchin
cinder mortar
#

i used the one they provided for qn2

fathom pendant
#

yes

#

it should all be the same list

cinder mortar
#

i only found app tho

fathom pendant
#

/opt/useful/SecLists/Discovery/DNS/namelist.txt

cinder mortar
#

how do u know to use this list

fathom pendant
#

you may also have luck with the list provided in the part "vHosts" List; it is talked about in the module - under "Name-Based Virtual Hosting"

cinder mortar
tidal kelp
#

Needs some help. Am stuck on the ZoneTransfer Module.
after running 'dig axfr inlanefreight.htb @10.129.87.233' .

  1. how do you figure out what the 2nd zone is?
#
  1. how the hell do you query it?
tidal kelp
#

Ok så SOA record is the second zone?

#

but how to query it. both the root/ns . inlanefreight.htb give transfer failed

fathom pendant
#

but it contains all the info you'll need

fathom pendant
#

i just redid this for the sanity check

cinder mortar
fathom pendant
#

read this section over again; it tells you this list

cinder mortar
#

ah ok

#

thanks

fathom pendant
#

if you do not have a namelist.txt in that opt/useful then it's the path of wherever you downloaded the SecLists repo

cinder mortar
#

thanks!

dim wolf
#

4 modules left. let's finish this off this week

tidal kelp
tidal kelp
fathom pendant
hexed forge
#

For the hard Firewall and IDS/IPS lab. I got the key. But I cheated a little using port 50000. No matter what nmap search I do, I cant come up with port 50000 in the results. Unless I search specifically for that port. Any ideas?

cinder mortar
hexed forge
#

yeah, I cant seem to come up with a search that has port 50000 as one of the results

fathom pendant
#

:)

#

that's what infintesky is meaning

#

I've revisited this several times to help people sanity check

hexed forge
#

I did get the flag. now I am just making sure I actually understood what I did

fathom pendant
#

DM me and I'll show you the differences

hexed forge
#

So the idea is, I do the nmap scan from an outside ip, and the IDS/IPS prevents me from seeing all the ports. Then I do it from a "trusted" port, and I am able to see more ports?

fathom pendant
#

and can explain more in-case the IDS/IPS section wasn't clear on exactly WHY it works :) as explaining in more detail may lead to spoilers

fathom pendant
inner talon
fathom pendant
#

<3

pliant sage
#

ok so I know there's an easier way to do this but I wrote the script so now I'd like it to work

#

In broken authentication, bruteforcing cookies, i wrote a script to encode several payloads and pass them to curl to try to get the superuser account

#

the thing is, when I encode payloads using burp decoder with payload ->ASCII hex -> base64 I get a different output than when I use echo 'payload' | xxd -p | base64and I'd like to know why

#

the burp encoded payload works fine but the command line one doesn't get recognized

fathom pendant
cedar whale
#

Hey,
I'm dong the javascript deobfuscation module and doing the source code lab

#

I also did the post request and decoded it, added htb around it but also is not correct 🤔

fathom pendant
cedar whale
fathom pendant
#

i'm saying at the end of the question does it say "format HTB{..}"

#

oh wait

#

the screenshot is just huge

#

didn't realize it scrolled right

#

LOL

cedar whale
#

np 🙂 haha

#

nvm, apparently there are other flags as well

fathom pendant
#

:)

gray blade
#

Hello everybody, im stuck on the last question or PTH Linux ^^* Someone to help me? :))

fathom pendant
#

be more descriptive of what you're having trouble with

gray blade
#

I try to access to Linux01 with kerberos ticket, //DC01/linux01

fathom pendant
#

did you find the actual ticket?

gray blade
#

Is it krb5.keytab ?

fathom pendant
#

nope but you may be close to finding it

#

hint: the linux01 is a ccache; maybe it's stored in a database of some kind

#

that's what tripped me up

winged zodiac
gray blade
#

I understand, but i have try to find inside /tmp and i have try all user

fathom pendant
#

it's not in /tmp where is the krb5.keytab

gray blade
#

Yes i have found a the .ker…./kerbe…ah

#

Sh

fathom pendant
#

hiding in plain sight

gray blade
fathom pendant
#

look around there has to be a db of some sort

gray blade
supple jackal
#

hey im a little stuck im trying to the flag for the module web requests but im hitting a wall.. im unable to find the flag.. i am tasked in using curl to download a file returned by /download.php but i do not know how to ID the flag

fathom pendant
fathom pendant
#

Don't need to add to DM me

gray blade
cedar whale
#

It seems like the final assesment of the XSS module always uses the same ip for the box but the problem is that it appears to be highly unstable for me. I get time out's the whole time 😦

supple jackal
#

nvm i got her