#modules

1 messages · Page 52 of 1

fathom pendant
#

setting on your end only accepting DMs from friends

#

reset the target

cedar whale
supple jackal
#

hey stupid question but how do i know what the flag is.. is it alway something like HTB{examlpe_flag} like HTB{64$!c_cURL_u$3r}

fathom pendant
#

it will usually either be told to you that the format is HTB{..} or when you get the flag it's that

#

however there are occasions where the flag is just a string of alphanumerics or l337 speak pertaining to how you obtained the flag

supple jackal
#

lol so i have to sometimes really read the question to make sure i know if its telling me what the flag may be or i will just see that and know its a flag

#

srry i just did a lab and i had no idea what the flag was with out a little google... and the question never even told me what to look for just to get the flag

fathom pendant
#

yep

#

9 times outta 10 it's in the form of HTB{..}

supple jackal
#

Yosh, but sometimes it can be different but the question will dictate

#

thanks ❤️

fathom pendant
#

yep and USUALLY they tell you explicitly that there is a /path/to/flag.txt or /path/to/${user}.txt file you're looking for

hazy grotto
#

What payload would you suggest I try? I tried reverse_tcp I think and it just keep auto closing over and over.

cloud skiff
#
Password for htb-student@//10.129.231.212/Share: 
mount error(115): Operation now in progress
Refer to the mount.cifs(8) manual page (e.g. man mount.cifs) and kernel log messages (dmesg)``` how to resolve this error?
unkempt steppe
cloud skiff
#

I try to mount a folder which is on windows 10 to linux.

fathom pendant
cloud skiff
#

Any other solution for this?

fathom pendant
#

If you're using your own VM do sudo apt upgrade && sudo apt update

cloud skiff
#

I already do this.

fathom pendant
#

Also

#

It says it's in progress doesn't necessarily say it failed

#

See if you can visit that directory

#

Is that the command they are telling you to do? Is that the IP of the spawned target

cloud skiff
#

yes, I checked twice everything correct.

fathom pendant
#

Is that the name of the share file

cloud skiff
#

yes.

pliant sage
#

could anyone give me a nudge on broken authenttication - bruteforcing cookies?

#

I'm struggling to find the right role for the first question

fathom pendant
mild dome
#

how do i get html codes

cloud skiff
mild dome
#

how do i get html codes

fathom pendant
gusty fulcrum
fathom pendant
gusty fulcrum
#

So it is a bit like Samba

fathom pendant
mild dome
#

wrong server

fathom pendant
#

NTFS is used in Windows

gusty fulcrum
#

And the Active Directory is part of the NTFS since it is a kind of phonebook

fathom pendant
#

sighs

gusty fulcrum
#

I am trying to learn but I keep forgetting the basics

fathom pendant
#

Write the basics down somewhere then

light fern
#

Is HTB actively working on growing the academy with new content? I assume so and if that is the case is there a suggestion area?

brave palm
#

did you find that || admin hash || in the || notes folder || ?

vital adder
brave palm
#

dude, i've been trying everything I've found in those ||notes folders || via ||evil-winrm|| but i cant do shit with it, any tip pls?

fathom pendant
#

the user you're trying to reach is attempting to sleep

dim wolf
#

it's been a wild and fun experience

#

even though i've been through 2.5 years of college i got some really great fundamental knowledge from Information Security Foundations

#

and a lot of stuff i've learned is immediately applicable to my classes

#

there's always something to learn

graceful rampart
#

I'm almost 2 years into college and I've learned next to nothing from my classes

#

Nearly everything I know I've learned on my own

dim wolf
#

it really kinda sucks doesn't it

#

if you go out of your way to seek what you want, you'll retain that information much longer

#

and the way academy modules are structured helps

rustic sage
#

nice

soft cloud
#

can someone help me with the following question: Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer.

#

but the answer is wron

dim cosmos
#

the file upload attack skill assessment was not easy....!

#

not helped by the little green button i didnt take any notice of for a while...

vital adder
soft cloud
#

Linux Fundamental - filter contents

vital adder
#

yeah i'll go and check that section because i think my note is custom (i use 11 thing after the curl coomand )

soft cloud
#

ok. thanks

vital adder
#
  • 5 cut command 🤣
ivory dock
#

Regarding the Shells and Payloads module skills assessment, is it possible to get a webshell on host 1 without the creds in the hint?

#

And, is Links the only browser installed? Pain in the ass to use pepehands

vital adder
#

yes but it's 90% unintended and i'm not sure it's still work but there isn't only 1 application on that host

ivory dock
#

interesting

mortal basin
vital adder
#

this channel is for htb academy modules

dim wolf
#

i need to get that platinum subscription

turbid kraken
#

Hey guys, I'm having some trouble with the footprinting module, dns sub-section.

I think I understand the theory behind dns zone transfers (tho I'm still kinda confused on what zones are specificaly).

I'm having trouble doing the last question where I need to find the x.x.x.203 IP using the dnsenum tool.
If I understood the course well I need to trick the main dns (root.inlanefreight.htb) to give me it's gold by pretending to be internal.inlanefreight.htb but how do I practically do that? what is the flag in dnsenum to do so?

Thanks for any help!

tight basin
#

What tool is best used for this one? AD Enumeration module

What powerful local group on the Domain Controller is the SAPService user a member of?

dim wolf
#

PowerView

#

or

#

well it's a localgroup

vital adder
#

@soft cloud yeah i'm not sure what's the intended way to solve this because this a beginner module and even google give me mostly complex stuff

dim wolf
#

if you're on the domain controller that's a default windows command

tight basin
vital adder
#

which section are you on?

tight basin
vital adder
#

||GetUserSPNs||

tight basin
#

It's only utilizing ||GetUserSPNs.py|| in that section

tight basin
obtuse oriole
#

HELLO

fathom pendant
vital adder
fathom pendant
#

Subdomains of subdomains of...

vital adder
tight basin
vital adder
#

i think that's call level (somehthing) subdomains but no idea

novel matrix
dim wolf
#

any plans for these?

graceful rampart
pliant sage
#

I have a question concerning broken authentication - skill assessment, could I dm someone?

vital adder
# mortal basin 🔥

i got 80 cube so for the love of god pls release a tier 2 module so i can have even number cube NotLikeThis

fathom pendant
dim light
#

"SQL INJECTION FUNDAMENTALS " is so looooooooooooooong

fathom pendant
#

The fundamentals tend to be long if there's a bit to go through

dim light
odd gorge
#

I’m using AttackBox to do the Intro to Assembly module. What’s the best way to get the zip files you’re supposed to download onto the AttackBox?

turbid kraken
dim light
vital adder
#

also you can just use wget

odd gorge
#

I knew I was going to cop it for the wrong name - didn’t know the right one 😂

dim light
#

guys
what is cpe ?

vital adder
#

Continuing professional education

fathom pendant
#

^

#

Some certifications expire after x amount of years, CPE allows you to renew without retaking exam

dim wolf
red obsidianBOT
devout cliff
#

hello everyone, im on the attacking common services module on the email services section talking about pop3, imap, smtp. i have found the username for the domain but unsure of how to start going about finding the rest of the credentials required to access the account. i have tried hydra but no luck with the password list provided in resources. should i try a different password list (rockyou - one of the smaller ones maybe?).

#

one thing i havent tried yet is using o365spray or similar cloud based attacks due to the fact that the server provided doesnt seem to be one, so i dont think its the intended method

Figured it out - wasnt using the correct username kek

acoustic owl
# mortal basin 🔥

When will the new Job Role Path be available?
All the new modules are guaranteed to do that. Right? Please say yes

acoustic owl
flat oxide
#

Can I DM you about this?

acoustic owl
rustic sage
#

guys, does cubes currency become much of a problem later on? I've just the intro the academy and not sure where to go to next

#

like is it worth spending cubes on linux fundamentals as I am a newbie

#

ayuda, por favor

devout cliff
vital adder
# rustic sage guys, does cubes currency become much of a problem later on? I've just the intro...

if you are new to this give both of those video a check
https://www.youtube.com/watch?v=0vu_Hs4N8B8
https://www.youtube.com/watch?v=4JZjj_H4ei4

Introductory video on getting into hacking and cybersecurity.

▶ Play video

Sponsor: https://go.intigriti.com/thecybermentor
Blog Post: https://tcm-sec.com/so-you-want-to-be-a-hacker-2023-edition/
Academy: https://academy.tcm-sec.com

Timestamps:
0:00 - Introduction
0:41 - Intigriti Sponsorship
2:01 - Important Notes
4:12 - Building a Foundation
5:14 - Basic IT Skills
8:22 - Networking Skills
12:35 - Linux Skills
15:07 ...

▶ Play video
rustic sage
rustic sage
waxen barn
#

Learn the basics of networking, computers, and coding before hacking

graceful rampart
#

If you wanna go into something more advanced like redteaming tho then youll need to be able to code

waxen barn
#

Still something you want to know, particularly for web apps. Learning to write it helps you learn to read it. You don't need to be on the level of a developer, but you need to know what the code is doing.

graceful rampart
#

True

gray blade
#

Hey! Someone have solve Password Attacks Lab Medium ? Im stuck for priv esc? 🙂

raven cairn
graceful rampart
#

Yes. That is very important. While you can be a pentester without being a developer, very very often people dont actually understand how the applications theyre attacking are built.

#

And that causes problems

hazy grotto
#

Would you have any other suggestions for a shell? When I tried@that one it@just kept auto closing the shell over and over again.
When I googled the section someone has the same@issue

raven cairn
hazy grotto
odd gorge
#

Doing Intro to Windows Command Line Skills Assessment. The pattern is that the answer to previous question is password for next user but I can’t work out what it would be for user4. The previous answer was a number and the files were all empty so there was no flag either that could be used as a password

thorn urchin
#

no one wants to have to search and scroll back to find your problem again

pliant sage
#

hi, does this: ||af6172da1f353a9b9bbbaac3ac1ed4c4:434990c8a25d2be94863561ae98bd682||look like anything anybody knows? a type of hash or something?

#

kinda banging my head against the wall with the broken auth skill assessment lol

pliant sage
#

my bad

vital adder
#

hint decode it separately

rustic sage
#

Stuck on the Password Attacks hard lab. I have cracked the Backup.vhd. But how on earth am I able to mount or open the vhd file? I tried all the online instructions, but keep getting weird errors.

vital adder
pliant sage
devout cliff
#

im currently on the easy lab for attacking common services - was able to find the credentials to log into the ftp server but everytime i try to use the ls command im getting a '229 entering extended passive mode'. is there something im doing wrong?

rustic sage
vital adder
thorn urchin
vital adder
#

oh sorry 🤣

vital adder
#

and i think there should be something about this in the module (forgot the section though)

odd gorge
vital adder
pliant sage
vital adder
#

try the second one first

devout cliff
#

maybe itll turn something up

vital adder
vital adder
dim wolf
#

you can remove the first 17000 passwords or the first 150000 passwords

livid bluff
#

HI !
On the web service & api attacks in Information Disclosure (with a twist of SQLi) section :
Is a simple question about sqli
But in the second question I don't understand, we are asked for the username that has a position 736373 .
In the section we are told to try the users with IDs from 1 to 10000.
I have tried up to 100,000 but I only have IDs 1, 2 and 3.
And none of them have position 736373.
The response like this :
[{"id":"2","username":"HTB-User-John","position":"2"}]

devout cliff
vital adder
dim wolf
#

yes it is only usable for one section

vital adder
#

only 1? i didn't even know that 🤣

vital adder
#

and also you can do this with sqlmap

devout cliff
dim wolf
#

for the other sections just sort -u the mutated list and you should be good to go

vital adder
devout cliff
vital adder
gray blade
#

Hey! Someone have solve Password Attacks Lab Medium ? Im stuck for priv esc? 🙂

vital adder
rustic sage
vital adder
#

oh no quotes or space

devout cliff
#

@vital adder to be honest though i feel like im chasing my tail a bit with this. i dont see useful info in the files i dont think

#

oh wait

#

i think i see something

vital adder
# dim wolf i was able to do it using this

but how cloud you do it with only those link? also the only article i didn't find from the other post was the one from itsfoss, in this case the vhd file isn't a disk it's partition

#

so before you can mount it you have to use losetup to convert it into something that's mountable which none of the blog show

#

and that's kinda suck for beginner

dim wolf
devout cliff
#

nope nvm i dont get what im supposed to do with this info

#

im sure its useful. but i just am not sure

pliant sage
#

finished broken authentication

#

the more i do them the more I hate bruteforcing modules

vital adder
late prawn
#

Hello guys, i need help

rustic sage
late prawn
#

Hashfile '7z.hash' on line 1 (hashca...c3063744d081db1492ea1cdef7a9b983): Signature unmatched

vital adder
pliant sage
late prawn
#

also try it in pwnbox

vital adder
#

and yes try with john

devout cliff
vital adder
#

yeah no idea about that user

#

also no note about that use

devout cliff
#

are you looking at the same assessment as me? attacking common services - easy lab?

late prawn
#

ok i will try john, because in Tutorials is using hashcat

vital adder
devout cliff
vital adder
late prawn
#

\

vital adder
#

for the hashcat (and john) mode you can try hashid -jm (hash or hash file)

#

why would you think sending a screenshot the password is a good idea ??

vital adder
devout cliff
vital adder
#

ah nothing wake you up more than an helping spree

#

*except red bull

devout cliff
vital adder
#

sure

chilly forge
#

Quick question (hopefully): In the password cracking module I just learned about crackmapexec. The examples use the switch "-u user.list -p password.list". I cannot use "user.list" can I? Do I need to supply my own user/pass lists? Cause if so, how do I generate user/password lists for a target I have no info on?

devout cliff
chilly forge
#

The module is called "Password attacks", the page is 'network services' (about WINRM, SSH, RDP, SMB, etc)

devout cliff
chilly forge
#

That makes sense, I did look through those. Only found password lists, not username lists? I'll try looking again 🙂

devout cliff
#

they are there

chilly forge
#

Ah its a completely different directory! Found it, thank you!!

#

I"ll give that a try

tidal mango
iron bough
#

Hi

uncut mirage
#

Hi all,
I'm in the Password Attacks module, Credential Hunting in Linux section. I don't think i understand the question. I've tried brute forcing the password for user Will and Kira using the provided password.list, both FTP, SSH and SMB has been tried - no luck. Can i get a hint?

outer smelt
#

hi

fathom pendant
#

Also lowercase usernames @uncut mirage

sinful olive
#

Hi, in Password Attacks module - medium lab.. I am trying to open the Doc file, and it just not working.. tried John with the mutated list and with rockyou now.. Which list should I try?

fathom pendant
#

Did you doc2john?

sinful olive
#

office2john..

#

is it someting else?

chilly forge
fathom pendant
#

Generally though if you're supplied a user.list though it's correct

woeful mural
#

Anyone online finished the shells and payloads section? I am having an issue on the live engagement.

fathom pendant
uncut mirage
fathom pendant
#

it's following the same lines of thought

#

each section is building on each other

#

by the way; the credentials do not change

#

:) so I would definitely keep note of them

thorn urchin
#

yeah I had a list of em for that module as well

knotty blade
#

Hey fellow hacker. i am stuck on the same problem. it seems there has been some missing information. i used the curl method and got back some injection points by now what? Is the question looking fofr a flag or a command?

tender acorn
#

ping don't work Getting started / Privilege Escalation. Reset target dosen't work.

uncut meadow
#

yo Im stucked on the login brute forcing - Service Authentication Brute Forcing... seams that the vm is not reachable... the vm commes with a port x.x.x.x:12345, but first exercise ask to hydra the ssh (22) service... Is it normal? did you also have problems connecting victim IPs or is it only related to this module??

vital adder
uncut mirage
# fathom pendant it's following the same lines of thought

My thinking now is that i need to brute force the kira account using a mutated list created with passwords.list and custom.rule like you told me. Then, when i get access to the system i need to hunt for user will's credentials in the Linux machine, correct?

knotty blade
#

on sql essential flag 2 case2

fathom pendant
#

I'm planning on redoing this module once Finished to really soak it in

#

and make better notes

knotty blade
vital adder
uncut mirage
fathom pendant
#

that's for you to find out :)

#

the section IS called Credential Hunting in Linux :^)

tender acorn
vital adder
#

for this flag i save the request in to a file and run sqlmap with that file

vital adder
#

there is a port tag

uncut mirage
knotty blade
fathom pendant
vital adder
fathom pendant
#

fuckin hate discord sometimes

vital adder
fathom pendant
#

he probably has notifications off for this or had his account hacked and it's just a botted account at this point

tender acorn
devout cliff
#

F for ip

vital adder
devout cliff
#

btw tom i pm'd you again if you got a minute

fathom pendant
#

Tom: relevant thing in gen-images

vital adder
#

jk don't forget to sleep

vital adder
vital adder
vital adder
#

of course only the hard lab is

devout cliff
#

im just starting the hard lab now so just get back to me when you are free

#

LOL

vital adder
#

@raven cairn i will use that dancing squirrel (hopefully) when i pass cpts

#

spoiler alert offshore is still not finished twisting my D and the APTlabs is waiting for it turn on my D

graceful rampart
#

Lmao

vital adder
#

yeah that's not a joke my nut is hurting really bad right now

simple merlin
#

Hi, may I DM someone about "Skill Assessment - Service Login" (Login Bruteforce) ?

vital adder
#

sure shoot me a dm

shadow pawn
#

Hi there all, having an odd issue on the "Bind Shells" module with the 2nd practical question. Nc is giving me a "Cannot Assign Requested Address Error" . Tried a few different VPN servers, no luck. Anyone perhaps have an idea?

#

Ignore, figured it out 🙂

rocky citrus
#

Hey everyone, I'm new to HTB and Discord. Can anyone help me understand how to get my VPN going? I download the VPN Connection file, but what am I supposed to do with it? All it does is download a Word file.

golden island
iron basin
#

Anyone mind helping on Password Attacks - Credential Hunting in Windows? I found the answer(what I believe to be) for the last question but its not accepting it.

red obsidianBOT
fathom pendant
#

@rocky citrus ^

iron basin
#

Also anyone have any experience with laZagne?

iron basin
iron basin
rocky citrus
dim cosmos
#

hi everyone

jaunty vigil
#

i dont really like that some challenges are literally impossible unless the hint is read because it provides vital information like "login with blablacreds"...

graceful rampart
#

iirc the hint system is being reevaluated exactly fir that reason

jaunty vigil
#

yeah cause i come from an offensive security background and i try to never look at hints

#

and this is getting annoying cause im wasting so much time lol

devout cliff
#

im on the file transfers module on the first question for the section 'linux file transfer methods'. the phrasing for the question makes it seem that i should be using python to download the file from the target machine. is it that or is it that the target machine is hosting the file using python http server and i can just use any of the simple methods to grab it?

fathom pendant
#

The file transfer section has you remote in to do the file transfers iirc

#

For linux

devout cliff
#

first question: Download the file flag.txt from the web root using Python from the Pwnbox. Submit the contents of the file as your answer.

#

im assuming you just use the same method as you can do with the windows section

#

because i did it...and it worked

#

but the phrasing for the question seems just a little weird

native bridge
#

Hey all, looking for some help with the skills assessment for Pivoting and tunnelling section. Up to the last two questions but can't seem to pivot to the new box. Anyone able to DM me to chat or anyone have any hints here?

shadow canopy
#

Reverse Port Forward :
https://academy.hackthebox.com/module/158/section/1427
Problem :
i get response in msfconsole but "Command Shell Closed"
payload :

  • windows/x64/meterpreter_reverse_https
  • windows/x64/meterpreter/reverse_https

ok (set payload payload/windows/x64/meterpreter_reverse_tcp) works

dim wolf
devout cliff
fathom pendant
#

gunzip?

#

i think is what's installed

devout cliff
#

ok how do i know thats installed

#

for future reference

#

not gunzip specifically

#

but in general, application listing via ssh

#

bc i thought about looking in /usr/share might show something but i didnt see it there

#

oh its in bin

#

not share

#

F

fathom pendant
#

ye

#

gunzip is a binary but it's also just good to know in general what common zip/archive tools are

devout cliff
#

are you sure gunzip works for .zip files?

dim wolf
#

judging by the name... i'd say yea

devout cliff
#

its not though

#

im stupid then

dim wolf
#

to be fair i have no idea if it does

#

it does

devout cliff
#

wait i think i got it

#

needed -S flag

native bridge
# dim wolf there's something on the box to clue you in on your next step

I've been over the box, I have creds for user v***** and ssh key for m*****
I've tried to netsh ports from/to each box over common remote solutions.
Everytime I try ssh I get connection terminated for v***** and the ssh session just goes back to the same box pivot-srv01
Everytime I RDP it doesn't connect to the other internal network.
Any other clue without giving too much away?

dim wolf
#

you are overthinking it. the box gives you the clue you need to get to the next box, and the hop to it is very simple.

#

friendly reminder that if you're using mstsc.exe to RDP to a box, fill out all the information before attempting to connect

deft escarp
#

When doing web exploitation with metasploit, I can't figure out what the TARGETUI is supposed to be. for the current exploit im running, metasploit says it needs to the full URI path to getsimplecsm. I've tried inputting all the base directories

deft escarp
#

figured it out @fathom pendant ty! btw, you know if the upload feature for the knowledge check machine in the getting started module is supposed to be broken?

fathom pendant
#

Don't know what you mean by broken?

deft escarp
fathom pendant
#

It shouldn't be broken

#

how are you trying to upload?

deft escarp
#

hmmm, hold up, may have figured it out

native bridge
neon ermine
#

Hello

#

Am not new but I have no idea what we do here

dim wolf
#

i don't understand. you RDP'd into the new host and... it's a host you already RDP'd from??

dim wolf
neon ermine
#

Alright I will do if I find a reason ig

native bridge
dim wolf
#

you ||did a ping sweep|| and ||verified that the host to hop to is on another network you haven't seen before||?

hexed forge
#

Iam doing the brute force login module. But everytime I try to load the log in page they give us, it says proxy server is refusing connections. I dont think thatis suppose to be part of the scenario or is it?

dim wolf
hexed forge
#

cool

hazy grotto
#

Module Pivoting

#

Section

#

Meterpreter Tunneling & Port Forwarding

#

This worked last night but tonight it doesn't.

dim wolf
hazy grotto
#

ahh i think you are right

dim wolf
#

same thing happened to me

hazy grotto
#

I never udnerstood if that was a requirement but a previous lesson they ran that command.

dim wolf
#

msfconsole is for setting up the proxy, so you don't need to run it as proxychains msfconsole

#

you only use proxychains if you're trying to run your command through your proxy onto the separate network

fathom pendant
deft escarp
hazy grotto
#

It kept closing over and over. Someone said the shell was too big... So i tried another and that was to no avail.

#

What did you do for that one?

#

Would you DM?

dim wolf
#

sure just brushing my teeth rn

deft escarp
fathom pendant
#

if you ctrl+z just do fg once you're back i think for this one i gave up on trying to get a working pty

rustic sage
#

this is killing me

#

im not sure why

#

but im unable to get the flag

#

ive already entered everything

#

and executed every command

#

and then deleted the city

#

i renamed france to flag

#

then deleted flag

#

and then went to the IP and Port and searched flag and it just says []

#

Am i missing something?

void gate
#

Module: Attacking Common Services
Section: Attacking SQL Databases

I've extracted the service user hash and am attempting to crack. I've tried hashcat and john for a || netNTLMv2 || hash type using the provided password list without success, I've also tried the rockyou wordlist with no luck, I've tried the best64 ruleset with both wordlists suspecting it may be a password mutation but I'm a bit lost. I suspect I've got the wrong hash type or may need to edit it for the tools to work property, can I get a sanity check that I'm on the right track?

honest ridge
#

Information Gathering - Web - Skills Assessment-Last question. am using hint provided using sublist3r and it starts running against target then just stops after this error - Error: Virustotal probably now is blocking our requests. not sure what to do as screenshots of other people running it does this but also gets passed and runs the script

fathom pendant
#

try using a different tool?

hexed forge
#

Any particular reason why the connection keeps timing out when I try to ssh into Bill Gates ssh for the login cracking lab?

hazy grotto
#

pivoting
section Meterpreter Tunneling & Port Forwarding

#

I've tried this for the SRVHOST as well 127.0.0.1

#

same result. anyone know why this is happening?

cloud skiff
#

Since Yesterday I try to resolve this error.
do_connect: Connection to 10.129.218.38 failed (Error NT_STATUS_IO_TIMEOUT)

#

This command gives me error - "smbclient -L 10.129.218.38 -U htb-student
"

#

I try to off the firewall and now everything is fine.

hexed forge
#

Is there any particular reason why the hosts keep timing out?

fathom pendant
#

no idea

hexed forge
#

I cant even ping the ip from mypwnbox

glossy cipher
#

question for DCSync in Active Directory Enumeration & Attacks
i understand they want me to use secretsdump.py which is on the linux
but the system they enable for me was the windows

fathom pendant
#

Yes

thorn urchin
#

and

glossy cipher
fathom pendant
#

Windows can run python

glossy cipher
#

do i need to revert it because i do not see secretsdump.py in the tools 😅
or do i neeed to copy and paste it over

peak hamlet
peak hamlet
#

@glossy cipher You can do DCSnyc with ||Mimikatz ||on Windows

#

Or ||Invoke-DCSync ||

glossy cipher
#

ohh i will try with ||invoke-DCSync||
||mimikatz|| keeps giving me an error when i follow the attack

peak hamlet
#

What kind of error?

glossy cipher
#

ERROR kuhl_m_lsadump_dcsync ; GetNCChanges: 0x000020f7 (8439)

#

i even did the debug and the token elevate

#

still same issue

thorn urchin
#

irrelevant, get lost

peak hamlet
glossy cipher
#

||lsadump::lsa /patch|| seem to work only in local
the domain it just gives me an error

hexed forge
#

Is there anyway to find out if its my problem or the machines problem why its not responding? when I run nmap it says its filtered.

rustic sage
#

Can someone help me out with command injection skills assessment its been hour
I am getting error like
file doesn't exist
Malicious command
And whole payload printed with file not found
File not found
Can someone tell hint me how to find the injectable parameters, is it GET OR POST request.
I have tried all the filters bypass but getting nothing.

woven copper
#

Hi someone could help me with skiils assessment on Secure Coding 101:Javascript , last two questions , thanks

woven copper
rustic sage
#

@woven copper I have tried using & | ; in encode form with and without space it just print my whole payload with fill not found error

native bridge
#

Big thanks to calculac0re today for their help. Just wondering if the Pivoting Skills assessment requires us to scan a full /16 for additional hosts?

woven copper
woven copper
native bridge
wraith spoke
#

pivoting looks so cool on my screen

pliant sage
#

yo

#

I have a (probably stupid) problem with web attacks - bypassing security filters

#

whatever HTTP method I use, the request gets flagged by the filter as malicious

#

am I missing smth?

graceful mortar
#

In password attacks - Network services i'm doing the right way? it's take too much time... i think at least 1h30

rustic sage
#

Once I completed a module and If module is upgraded or if the subscription ends do I need to pay to do the module again. Or it will be unlocked forever

acoustic owl
hallow swift
#

Hello! I need help with the "information gathering - web edition" module in the section "Active infrastructure identification" in the question 2

turbid kraken
#

Hey bud, did you ever get that working?

cedar whale
#

I'm stuck on the final assessment of the file upload attacks. I'm trying an XXE attack but I keep getting 500 internal server error 🤔

#

I'm really not sure why the XXE is not working mmmh

cedar whale
vital adder
hallow swift
#

Hello! I need help with the "information gathering - web edition" module in the section "Active infrastructure identification" in the question 2, please!

vital adder
vital adder
#

and if the default mode scan doesn't work for some reason try use -a 3 (most likely you don't need to use this mode)

brave palm
#

can somebody pls explain me the meaning of these buttons in this page? i mean I completed these modules but why some of them have 'unlock' button and others 'start' ?

hallow swift
#

I continue and now I need help with the "information gathering - web edition" module in the section "Virtual hosts" in the first question, please!

placid quest
#

@hallow swift use gobuster to enumerate the vhost

vital adder
# brave palm

i don't have any unfinished module but if you got one it should say continue or something like that and if you finished a module it should say view or if you own a module but didn't do it it will say start

#

so in your case if you done all 3 of the module that have the full task bar then that's a bug

brave palm
vital adder
# brave palm

also how can you view module like this? i never see module put in this format before just path

#

if you are in a beta thing then it's 100% a bug

hallow swift
brave palm
brave palm
placid quest
#

@hallow swift yes

nimble warren
#

Can someone confirm the following for me pls? (basically YES or NO would be enough as I'm not stuck just confused a little bit)

Getting Started Module, privilege escalation section.
According to the description in the beginning of the section, there's a part where ./linpeas.sh has to be used after cloning PEASS from GitHub. Apparently linpeas.sh is now called linpeas_base.sh

vital adder
brave palm
vital adder
#

but yeah my show the same all module is set as start

brave palm
#

do i get some award after discovering this bug? lol

vital adder
#

i mean if you help out a lot a find some good bug (like in module content) i think yeah, you can maybe ask some stuff for some stuff

#

or if you some bug that are related to hacking then you can get bounty but i'm not sure if htb have one i just know thm have one

brave palm
#

hahaha yeah i was jk, dont have time for that, still at 47% for the pentesting certification, this stuff is endless

vital adder
cloud skiff
#

Hey guys, does anyone how to find the answer to this question?
Identify one of the non-standard update services running on the host. Submit the full name of the service executable (not the DisplayName) as your answer.

#

It's on windows fundamentals

#

section - Windows Services & Processes

vital adder
#

for finding the services you can use the given powershell command but instead of select -First 2 use select * to get everything and you don't need to touch the rest

#

but to find non-standard update services you'll have to google around a bit to find which is standard and which is not

cloud skiff
#

oh, okay

frail thicket
#

Hello!
AD Enumeration & Attacks - Skills Assessment Part I
Can someone give me a hint on how to take control over the Domain Controller?

vital adder
#

first did you take over the MS01 machine?

frail thicket
#

Yes, I have completed the previous 6 questions

#

I have access to MS01 as S*****c and have done the DC attack using the user t****y

vital adder
#

to you pwn the DC 🤣 ???

#

then what's the issue?

frail thicket
#

I don't know how I can access the DC

vital adder
#

did you get the Administrator hash?

frail thicket
#

I think so, I used secretsdump from kali to get the hashes using the -just-dc argument against the DC

vital adder
hallow swift
vital adder
#

also you can use -just-dc-user administrator to just get the administrator hash after that you can just connect in and get the flag

placid quest
#

@hallow swift the url which u are using to access the website

hallow swift
placid quest
#

@hallow swift yes

hallow swift
frail thicket
vital adder
#

if you got a meterpreter shell on MS01 you can just use autoroute and use proxychains(4) to access the DC

hallow swift
placid quest
#

@hallow swift use just need to brute force the vhost using gobuster or ffuf

vital adder
# frail thicket I established a reverse port forwarding tunnel using chisel between my kali and ...

also on "that" privileges section they also show you how to exploit it with mimikatz and if you rdp in with xfreerdp and use the /drive: tag to mount one of your directory as a shared drive on the target machine you can just open a cmd shell on the target machine and use mimikatz from that shared drive so from your machine without having to copy it over with something like this \\TSCLIENT\home\x64\mimikatz.exe

turbid lily
hallow swift
frail thicket
hallow swift
#

@placid quest I found the first flag, thanks!

frail thicket
#

but thanks @vital adder , I will try to access the DC using the admin hash using a PTH attack such as evil-winrm or psexec.

vital adder
#

yeah i don't think i did a silver ticket attack for this assessment

vital adder
placid quest
#

@hallow swift no problem

tropic turret
#

Hello

#

LOGIN BRUTE FORCING
Skills Assessment - Website

#

someone can give me a hint ? 😇

woven copper
#

Secure Coding 101 : Javascript , skills assessment, anyone with a hint on the /Reverse endpoint ?

pliant sage
#

If you can ps remote you can create a remote session to the computer and use Copy-Item

grand harbor
#

can anyone explain me how to find the hostname becouse its turining me crazy

#

this is the folder

#

i already have

#

i am root aswell

#

yes it autocompleted

dim wolf
#

is your attack box a linux box?

#

try port forwarding with meterpreter

cedar whale
#

hey, for the skill assesment of server-side attacks I'm having a bit of troubles locating the flag file...

#

I would think it would be under /app/flag.txt

grand harbor
#

dont wanna talk ab it

dim wolf
#

wget http://<pivot host IP>:<port>/mimikatz.exe -o mimikatz.exe

#

yeah it'll still work

#

start the web server on your attack host

#

if you've got a socks proxy running on msfconsole and you've ran autoroute on your meterpreter session, you can do a reverse port forward on the meterpreter session so that you can download files off your attack box to the host on the internal network

cedar whale
#

but it doesn't seem the case and also not /flag.txt. Do we need to get rce or so?

dim wolf
#

i'm not sure what you mean by that

dim wolf
#

yeah so the attack box can access the internal host but the internal host can't access the attack box

#

so you do a reverse port forward with meterpreter so that the internal host has a route to your attack box

formal turret
#

Well I did eternal blue CTF on htb

#

What's pivots https server

#

A particular website hosted on this server

cedar whale
#

okay ... wow hehe

steady light
#

hey guys, i'm doing the metasploit module rn and can't find the answer to the " Which version of Metasploit is free and can be used only through a CLI?" 😅 I've tried entering like metasploit framework and stuff but it doesn't work

devout cliff
dim wolf
#

are you sure you're setting it up correctly

#

what does your port forward look like on meterpreter

#

is your attack box on the 172.16.6.0 network?

#

then change that IP address to the tun0 IP address

#

-L is your attack box

#

so traffic coming to the pivot host on port 1234 gets forwarded to your attack box on port 8081

#

there is an easy way

#

you can base64 encode mimikatz and decode the string on the other host

#

but that kinda sucks

#

that reverse port forward should work, i don't know why it doesn't

#

you could set up a share on the windows box

#

me neither but google may help you here

#

all is well that ends well

foggy sierra
#

anyone did the HTB module Linux Local Privilege Escalation , i need a hint for gaining foothold on the machine without using ssh creds

midnight tusk
#

Thanks for this hint. I was doing zone transfers until my fingers bled. Thanks for the syntax correction!

rustic sage
#

we really need a button to extend time on labs🫠

raven cairn
rustic sage
#

it's usually the labs that kill me... especially on this pivot skill assessment. I guess it's good I'm practicing the commands, but it's annoying going through all the hosts again

placid quest
#

@rustic sage Do u need help

devout cliff
# raven cairn I know there is an extend button for pwnbox

i think in general i agree that there needs to be an extension like pwnbox for the target host. even if it is similar to a 1 time extension. sometimes you just need a bit more time to finish what you started and you really don't want to redo a bunch of work to just get back to where you were

rustic sage
placid quest
#

@rustic sage no problem 😊

grand harbor
#

how im i supposed to acces websites??

#

im doing the The Live Engagement

dim wolf
grand harbor
#

i am

#

i never use parrot btw

vital adder
grand harbor
vital adder
#

open a terminal and run firefox

grand harbor
#

ye got it cheers

wheat adder
#

why arent they the same if someone can clarify what are the signals and how to apply them with the kill command it would be great!!

#

linux fundamentals module btw

devout cliff
wheat adder
#

service and process management

#

and am using my own vm not the instance built in htb

modest isle
#

Am still in that module too! 🤧

devout cliff
#

about halfway down the page

wheat adder
#

yep but when I try em in my vm it just doesn't work

devout cliff
#

is the ping command running constantly while you are trying to kill it?

wheat adder
#

yeh

devout cliff
#

try another process

#

see if you can kill it

wheat adder
#

okay

#

nope

devout cliff
#

try stopping it and then killing it

wheat adder
#

ctrl c or z

#

XXDD

devout cliff
#

sudo kill 20 PID

wheat adder
#

lol

devout cliff
#

try pkill

wheat adder
#

yep worked

#

so why wasnt kill cmd workin

devout cliff
#

might be bc it had a parent process

wheat adder
#

oh

#

gotcha

#

okay thx bro

devout cliff
#

np

flat oxide
#

Guys I'm stuck in Whitelist Filters section of file upload module, I've tried the given script and the classic php extension wordlist but nothing

#

Can anyone help me?

hoary mist
#

hi guys i cant open sites of any machines

#

i can ping the sites but cant open in my browser

#

getting dns error/ nx_domain error

#

can anyone help?

dim wolf
steep loom
#

What is the password for the account logistics.inlanefreight.local/htb-student_adm so you can do module Attacking Domain Trusts - Child -> Parent Trusts - from Linux from ACTIVE DIRECTORY ENUMERATION & ATTACKS . I can not find it anywhere.

dim wolf
steep loom
#

every other exercise has provided the passwrod within the module

#

for the user account

dim wolf
#

i don't have my notes rn so i am unsure

steep loom
#

fair enough!

dim wolf
steep loom
#

yes to ssh to the pivot host, you need the password for the account shown in all the examples from the domain to run the assoicadted commands

#

htb-student is not the same as the other account, the other account is a domain account, and from what I have seen one that has not come up before.

steep loom
sturdy igloo
#

anyone experiencing issues today? i am on ACL enumeration and the powerview commands just hangs. i have reset teh machine like 3 times already

dim wolf
thorn urchin
#

yeah it should come with a warning but I know which one youre talking about too, I thought it was also hanging.

#

its seriously like 15-20 mins to finish

dim wolf
#

it takes way too long

#

you might as well watch an episode of kitchen nightmares while you're waiting

rustic sage
#

Hello, I'm stuck at the SSTI assessment. i can't seem to solve it without registering, there is no attack vector that is not sanitized. can anyone give me a hint where the unsanitized field should be? I also followed the scheme, but it was not vulnerable even if registering and creating a post

hallow swift
#

Hello, I need help with the "information gathering -web edition" module, in the "Skill assessment" section, question 3. Please!

sturdy pelican
#

could someone help me with the module footprinting on the section dns, i am at the last step to find the fqdn for a specific host but i cant seem to find it. could someone maybe point me in the right direction

timber hatch
#

try it...when it doesnt work DM me... I also needed help in that..I would never have solved it on my own😂

devout cliff
#

im on the vulnerability assessment module and trying to get the nessus service to start on the machine provided and its not working. says that nessusd.service not found

#

i am trying to start it with sudo systemctl start nessusd.service as the module instructs

dim wolf
#

um, shouldn't it already be started?

devout cliff
#

didnt seem like it. i tried to access it at the ip provided and it wasnt working

#

going to try another box real quick

#

see if maybe its just a bug

#

the module says the following:

The VM provided at the Nessus Skills Assessment section has Nessus pre-installed and the targets running. You can go to that section and start the VM and use Nessus throughout the module, which can be accessed at https:// < IP >:8834. The Nessus credentials are: htb-student:HTB_@cademy_student!. You may also use these credentials to SSH into the target VM to configure Nessus.

#

ok NOW it works

#

mustve been the box

sturdy pelican
#

can some help me with the footprinting dns module i tried the hint but it didn´t realy help

light bobcat
#

Lol learning about burpsuite and realizing how I could’ve used it to make so many of my projects easier. Instead of manually verifying web requests through inspect tool and other methods

chilly forge
#

During the password cracking module i have to use credential lists (crackmapexec -u user.list -p password.list). Some are password-only lists, some are user only lists. How do I use credential lists? (username:password) and how do I use CSV files (pass1, pass2, pass3 \n pass4, pass5, etc.)

inner talon
#

someone can help with the Firewall and IDS/IPS Evasion - Hard Lab ?

chilly forge
#

Yes I think I can D0lf, what's your question?

inner talon
#

I have run many types of scans, in many different ways. I've run them from a virtual machine and from the HTB instance, but I can't get through.NotLikeThis

chilly forge
#

Can you send me the Q again? I forgot what the Q was about 😛

inner talon
#

With our second test's help, our client was able to gain new insights and sent one of its administrators to a training course for IDS/IPS systems. As our client told us, the training would last one week. Now the administrator has taken all the necessary precautions and wants us to test this again because specific services must be changed, and the communication for the provided software had to be modified. AND THEN:

#

Now our client wants to know if it is possible to find out the version of the running services. Identify the version of service our client was talking about and submit the flag as the answer.

chilly forge
#

Ah right, I can give you some hints on that (its the Nmap module right?) Mind if I DM you?

inner talon
#

Of course, thank uprayge

hexed forge
#

why is my connection keep timing out?

#

would an adware blocker cause that?

graceful mortar
#

@vital adder i apreciate any hint

timber hatch
#

pivot, tunenling and port forwarding, section remote/reverse port forwarind:
ssh -R <InternalIPofPivotHost>:8080:0.0.0.0:8000 ubuntu@<ipAddressofTarget> -vN ==> this command do i have to execute from the ubuntu server right?

#

and the internalIPofPivotHost is the ubuntu servers IP right?

chilly forge
#

Can someone give me a hint (privately if possible) on the Password crack module - Network Services? (question: Find the user for the WinRM service and crack their password. Then, when you log in, you will find the flag in a file there. Submit the flag you found as the answer.) - I can't find the username, I tried using usernamelists and passwordlists but none of the combinations seem to work. How do I find the username for the WINRM service?

rugged stag
iron basin
#

Anyone mind providing a nudge on Credential hunting in linux? ||I have been able to ssh with kira mutated creds and found the notes.zip file. But need guidance on how to crack the password protected file.||

cerulean crow
#

Module name: Shells & Payloads

Section name: PHP Web Shells

I'm having trouble getting the webshell to correctly upload like in the module example. I'm changing the content-type in burp but it doesn't seem to be uploading. Anyone else had trouble with this module?

supple jackal
#

hey im on web requests and im stuck trying to do the tutorial on a GET request for using curl to search for a city name. i get all that but they also say i can go on the devtools and right-click on the request and select copy curl but i see no result when i put in my search

devout cliff
rustic sage
#

If it can help anybody with the IDS/IPS medium challenge i just spent 2h desperately trying from my vpn access to send the command. Sending the same command from the PwnBox got me the answer in 2sec...frustrating as it can get. Everything you need is in the "Firewall and IDS/IPS evasion" section

devout cliff
#

can anyone help me real quick with this bash script in the intro to bash scriping module? i just started and feel like im missing something obvious

steady totem
chilly cosmos
#

Hello, Can't access the root shell in the local privilege escalation Kernel Exploits

fathom pendant
#

@novel matrix

primal sundial
#

💀💀💀 funniest shit I've seen in a while

#

<@&861185840277487616> wake up sleepy heads

low girder
#

thanks for report

novel matrix
#

❤️

supple jackal
#

no

devout cliff
#

ok and this is on the GET section?

supple jackal
#

its the tutorial not the question

devout cliff
#

uhm did you read the question?

supple jackal
#

im trying to copy>curl the request in te devtools and use

#

the

#

welllll lol i just searched for flag and i got it

#

i understand the http get request syntax for searching and i know where i would find it

#

but for the life of me i cant get it to appear

#

i know its goingto be somthing stupid lol

#

but im just not seeing it

devout cliff
#

so you entered the search term right

supple jackal
#

correct

devout cliff
#

and while dev tools is open, you hit enter right?

supple jackal
#

yes

devout cliff
#

ok standby let me see if i can replicate this

supple jackal
#

ok thank you

dim cosmos
#

advanced xxe is a mind bender!

dim wolf
#

so many common applications..

devout cliff
#

working as intended

dim wolf
#

did you try reloading the page

supple jackal
devout cliff
#

could also empty any previous requests like the module says to do

supple jackal
#

with trash can

#

i did that

#

ill try to load again wait one

#

lol target is down

#

one sec

supple jackal
supple jackal
devout cliff
#

np

supple jackal
#

ya just need to reload the page and i was good to go

dim wolf
#

if nothing's showing up and the dev tools say to Reload the page, you should probably do that

devout cliff
#

^ based

supple jackal
#

Yosh

#

ahhh beautiful

supple jackal
#

why is that happening

#

i gtg if you could DM if you dont mind that be great

devout cliff
#

should be all lowercase

dim cosmos
#

from memory i think change the user agent to curl also

#

i remember the user agent making a difference for some of those exercises

uncut crest
#

Can someone who has finished the sql injection skill assessment dm me? I have a question about why something worked when everything I can think of tells me it shouldn't.

hazy grotto
#

Pretend HTB isn't watching..

#

KALI or PWN distro?

waxen kayak
#

In the modules, will they set up decoy flag.txt files???
doing one.. says very specifically "find the flag.txt file. Submit the contents of it as the answer. "... I have the flag.txt file and the contents I guess, are incorrect.

thorn urchin
#

some boxes have multiple flags for different sections

#

but chances are youre just copying the answer wrong.

waxen kayak
#

Aye I got the first flag, second one is the .txt file, maybe I'm crazy 😄

hard dew
#

has anyone run into mysql-server having no RC in parrot metapackages, im working on Footprinting -> mysql

#

default-mysql-server is available but not mysql-server

Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
Package mysql-server is not available, but is referred to by another package.
This may mean that the package is missing, has been obsoleted, or
is only available from another source

E: Package 'mysql-server' has no installation candidate

dim wolf
#

academy servers are slow?

#

can't seem to spawn a VM

manic pilot
#

yup same thing here, page loading is slow and spawning of VMs fail

plucky current
#

Just tried to get in to the main site and was redirected to CloudFlare. Perhaps a DDOS attack.

dim wolf
#

a, a vm just spawned

manic pilot
deft escarp
#

I just realized how important programming is for hackers/pentesters

hexed forge
#

If I run my hydra on the Brute Force Skill Assessment - Website, and it says it found a successful un/pw, shouldnt i be able to log in with it?

fathom pendant
#

I'd think so

final salmon
#

For the Password Attacks module, network services. Are we just supposed to use whatever username list and password we want?

fathom pendant
#

I think the lists we're given are fine

#

In resources

brave sinew
#

ls

final salmon
fathom pendant
hexed forge
#

user=user that part is wrong

lunar nimbus
#

hello, newbie here. Working my way through the Getting Start module knowledge check and I've made it to the file upload page on the admin portal but the link to upload the file isnt working... any tips?

hexed forge
#

should be user=^USER^

main ridge
#

Hi, anyone knows how am I supposed to access the vHosts in this question?


Time Left: 87 minutes
vHosts needed for these questions:

    app.inlanefreight.local
    dev.inlanefreight.local

Tried adding inlanefreight.local to /etc/hosts, but it didn't work

hexed forge
#

Is it failing or just not finding the password?

main ridge
fathom pendant
#

add in
<IP> app.inlanefreight.local dev.inlanefreight.local

pliant sage
#

can anyone help me with web attacks - advanced file disclosure?

#

I'm trying to use the CDATA method but it doesn't work

fathom pendant
#

it's because /etc/hosts is basically a local dns if you just put "app.inlanefreight.local dev.inlanefreight.local" it doesn't know what you're trying to do

hexed forge
#

I keep getting passwords but they are never correct

#

:F=<input name='pass' placeholder='Password' type='password'"

dim wolf
#

does the ||html use single quotes around log-in||?

#

well, i gues that owuldn't affec tit

turbid kraken
dim wolf
opaque marlin
#

has anyone made or have a link for the machines to do for the HTB pentest certification

#

to do before exam

fathom pendant
# opaque marlin has anyone made or have a link for the machines to do for the HTB pentest certif...

on-record the only thing is the pro-labs dante and I think Offshore though I think it's been discussed in #cpts ; even if someone has completed the CPTS exam - they cannot really say which labs do or do not correlate to completing the exam as that is equivalent to saying what is on the exam. :) But afaik as well there are no other labs or anything that are actually required to complete or anything, the module content should be enough

main ridge
fathom pendant
main ridge
fathom pendant
#

yeah I feel like that should come earlier

main ridge
#

Maybe this section should be before the other (or unless a note)

#

: )

fathom pendant
#

but they are at least expecting you to know the basics of
<IP> example.com

#

for /etc/hosts

vital adder
vital adder
fathom pendant
vital adder
vital adder
fathom pendant
#

^

#

but yes that file comes into play 8 sections later LOL

#

so you saved your time of ssh into the target to begin with xD

arctic marlin
#

Did anybody completed 'Introduction to NoSQL' In-band data extraction and could tell me what do I do wrong?

fathom pendant
#

hey @vital adder you've done Password Attack yeah? I'm meant to mut the resource provided list with the resource provided rule as that's the ONLY info I have yeah? (And of course bruteforce the Service with it

#

if so I'm gonna go watch this paint dry rq

cedar whale
#

this can't be right for the bruteforcing module ... can it?

#

oh wait it finished 😄

hollow frigate
#

can some one bump me in the right direction on "AD Enumeration & Attacks - Skills Assessment Part II" Q:"Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host" I have the creds for the SQL and have enabled xp_cmdshell. Tried to upload a "shell_reverse_tcp" that i created in msvenom. Tried to copy it with the following "EXEC xp_cmdshell 'xcopy "\172.16.7.240\compdata\help" "c:\users\public\downloads\help.txt" /y' and getting "Invalid drive specification" there is a smbserver and i can see it is connecting when downloading the file. am i going at this the wrong way or is there a diffrent appoach the get an interactive session on this machine

devout torrent
#

I am just wondering in general when doing sqlmap injections, is there any way to know which tamper script you should use or do you just go blindly 😄

fathom pendant
chilly forge
modern sundial
#

Just a quick question, would I by any means be able to learn hacking in 3 days,, and be able to get my exam questions from someone’s laptop, or is that far fetched

fathom pendant
cedar whale
#

F in chat

fathom pendant
modern sundial
#

So.. I have to study.. yeah..?

fathom pendant
#

Yeah

fathom pendant
flint adder
fathom pendant
modern sundial
#

What if I ask someone to do it for me.. I’m certain my university’s security level is the weakest out there

cedar whale
#

oh weak credentials ones

fathom pendant
# modern sundial What if I ask someone to do it for me.. I’m certain my university’s security lev...

If you are looking for someone to hack for you, that'll be a no, and against the #rules :) you're more than welcome to give https://academy.hackthebox.com a try if you're really needing to

modern sundial
#

Tsk… just.. joking.. haha.. but if there’s a real good hacker here without ethics hmu

#

I’ll check that thing out too

fathom pendant
#

Just study and you won't need to waste money/time/effort on cheating

modern sundial
#

Thing is, I studied, I just know my professors don’t like passing students

fathom pendant
#

Because if you get caught you'll most assuredly get kicked out if caught

modern sundial
#

That’s a point, yeah

fathom pendant
#

Not our problem

#

tfw I get to the end and the lab just dies on me PepeHands

vital adder
fathom pendant
#

But I'm meant to brute it with the user they're asking for, not lateral movement?

vital adder
fathom pendant
#

because if so Sipaggressively

vital adder
fathom pendant
vital adder
#

i mean that will give you a way bigger chance of getting a hit but longer brute force time

#

this is better for brute force hash

fathom pendant
#

ty I'll try bruting the ftp with hydra again but the first time I didn't get any cred with the provided lists

#

if you wanna DM me any other tip or trick that i'm just not thinking of because i don't want to lose my sanity over this

#

:)

vital adder
vital adder
fathom pendant
fathom pendant
#

easy

#

🙃

#

the majority of pw attack was simple just do the thing and it be happy

vital adder
#

oh hint this is the only assessment that you don't need to use the mutated wordlist

fathom pendant
vital adder
#

but i guess that will work too just will take a good while

fathom pendant
#

but I can attack using root? or is this a lateral movement one?

vital adder
#

no idea what you mean by lateral movement but for the root user nope this machine have a different set of cred

fathom pendant
#

ThumbsUpCat get access then find root; was just making sure that if it was REALLY necessary attempting to just attack via the pwnbox

#

also that would probably explain why I didn't get creds :^)

vital adder
hollow frigate
vital adder
# fathom pendant also that would probably explain why I didn't get creds :^)

oh yeah i did help a few guy that misunderstand the same thing and i think they should add a note for this for change the question to get a foothold and PrivEsc to root or something like that but nope you have to get a foothold from mainly brute force and PrivEsc (sorry for the delay i forgot i was typing)

fathom pendant
cedar whale
#

Hey MarcieLee,
For the second part of the brute force web assement. Is it correct that you should use rockyou-10?

static glacier
#

I'm doing the metasploit module in the HTB academy however I cannot seem to find an exploit to obtain a meterpreter session I have no idea if I'm just missing something any assistance will be greatly appreciated 🙂

vital adder
static glacier
vital adder
#

i mean the name

static glacier
#

oh lol sorry using the metasploit framework > meterpreter

vital adder
#

like always i just note down what to use not where to how to find that to give me a sec

vital adder
#

and find an exploit for that in metasploit

static glacier
#

thanks tom peepocowboylove

fathom pendant
#

@vital adder 15 minutes left; let's gooooo

#

I ended up lowering my threadcount because I believe that to be the issue; it's attempting too much at once

sinful olive
#

Hi everyone.. In sqlmap essentials - Skills Assessment: I found the flag but when I write in HTB it says this is wrong.. so weird. What am I missing?

fathom pendant
#

dmed @vital adder because it was indeed what I was thinking in terms of why the password wasn't found i was trying with 64 threads... but it was saying "x did not connect to host" dropped to 32 and woo

devout torrent
fathom pendant
#

but waiting to see if it finds more users

sinful olive
cedar whale
fathom pendant
#

actually they're super useful idk what you mean by not useful?

devout torrent
fathom pendant
#

it teaches you how to brute passwords and utilities to adapt a list to match password policies... using tools to actually crack them

#

also teaching on the patience part of hacking

#

also adaptation

#

"hey this method did not work; let me try this"

cedar whale
fathom pendant
cedar whale
#

true that the hydra commands etc are useful, but bc of time constraints irl I don't think these modules are extremely useful

fathom pendant
#

but in most instances where a list isn't given; it's in rockyou

#

can you not do these modules outside of work?

#

or I'm not understanding what you mean by time constraints with work?

cedar whale
devout torrent
#

The only time i was on time contraint or the output taking long, was when you need to bruteforce passwords, but Ive learned that if i just remove some inputs from rockyou, or if ftp is enabled you use that instead of ssh, it speeds up password cracking from 50minutes to less than a minute

sinful olive
devout torrent
#

oh your in the skill assessment

cedar whale
#

maybe I fucked something up with the hydra command. Because I would think it would finish rather quickly normally

graceful mortar
#

i'm trying the Password Mutations module but when i run hydra i get this error. What that means? Someone help me?

fathom pendant
#

"Error" all processes were disabled due to too many connection errors; it's basically saying that you're not able to connect to the host

#

so next questions are: are you connected to the VPN (do you have a tun0) and is that the correct IP

graceful mortar
#

yes i'm

#

i found the password using pwnbox

#

that is stranger

dim cosmos
#

hi everyone

devout torrent
brave palm
#

yoh is it normal for the spawn targets to be laggy in the SQL inj fundamentals module?

#

always have to reset the vm and refresh targets ip, mysql is not connecting even after a minute of wait lol

fathom pendant
#

ugh Password Attacks Medium Lab is killing me; i made it to the second user but not sure where to go from there...

molten cairn
#

I have a problem and I cant find the solution. So im in the Getting Started module at the Web Enum part and in the question we need to try web enum techniques on the "server above" to get the flag. So I tried the domain mention http://10.10.10.121/ but with the pwnbox and the vpn conf im not in the right network so i tried to change the network but I couldnt reach the domain so im a bit lost to what server is mention to do the task.

fathom pendant
#

give me a moment sorry i was doing a practice lab

fathom pendant
#

that's the server they are referring to

#

the target system you spawn

molten cairn
#

I already try to spawn the target but with or wihout the vpn conf I cant ping it

fathom pendant
#

it spawns a target such as x.x.x.x:port correct?

molten cairn
#

Yes

fathom pendant
#

that means it is a docker container; purely a webserver that is not meant to be pinged

#

:)

#

visit the page in a web browser to confirm it is up in these instances

#

or use the other tools such as whatweb

#

or curl

timber hatch
#

Modul Pivot, Tunnleing and Port Forwarding, section Remote/Reverse Port Forwarding with SSH.

anybody an idea why this error occurs?

fathom pendant
#

as talked about in the section

#

-UseBasicParsing

molten cairn
#

Thanks i copy paste the ip:port in the browser and it works

fathom pendant
#

ThumbsUpCat then everything in this section should work as intended just replacing the 10.10.10.21 with the ip:port

silk dagger
#

Can someone help me with Initial Enumeration of the Domain
(in AD enumeration and attacks)
and the scan question for MS SQL?

Only 2 machines answer in my scan from the 9 IPs... Even when I enter the IPs in the answer (kind of cheating) all are wrong... ?!

frigid vector
#

Hey guys! Need a hint on Broken Authentication module

fathom pendant
fathom pendant
static glacier
#

@vital adder I managed to get it done thank you for your help i really appreciate it peepocowboylove

frigid vector
static glacier
#

Marcie thank you for your help too peepocowboylove

fathom pendant
frigid vector
fathom pendant
#

ah then idk i haven't done it

#

but perhaps you have an extra space or the copy added some weird characters

frigid vector
#

actually the task is pretty clear...I can't understand what's the problem:)
Usually modules from the academy took me less then a few hours to solve... BUT I've spent already more then a hour for this section

frigid vector
fathom pendant
#

Maybe take a break 😅

uncut mirage
#

Hi all,
I'm in the Password Attacks module, Pass the Ticket (PtT) from Linux section trying to to get the credentials for the user svc_workstations and use them to authenticate via SSH. In the crontab I found the svc_workstations.kt file and managed to extract a AES-256 hash from it. Now I'm stuck trying to crack it. I've tried CrackStation but they do not support AES-hashes, then various hashcat modes (17010, 19700, 19900, 1400 and 26403) but it doesn't even let me run most of the time. Usually stating the error "Separator unmatched, No hashes loaded". Can i get a hint please?

frigid vector
dim cosmos
#

what happens if you let hashcat auto detect?

#

might need to clean up what you're feeding

uncut mirage
# dim cosmos what happens if you let hashcat auto detect?
┌──(kali㉿kali)-[~]
└─$ hashcat --quiet "0c91040d4d05092a3d545bbf76237b3794c456ac42c8d577753d64283889da6d" 
The following 8 hash-modes match the structure of your input hash:

      # | Name                                                       | Category
  ======+============================================================+======================================
   1400 | SHA2-256                                                   | Raw Hash
  17400 | SHA3-256                                                   | Raw Hash
  11700 | GOST R 34.11-2012 (Streebog) 256-bit, big-endian           | Raw Hash
   6900 | GOST R 34.11-94                                            | Raw Hash
  17800 | Keccak-256                                                 | Raw Hash
   1470 | sha256(utf16le($pass))                                     | Raw Hash
  20800 | sha256(md5($pass))                                         | Raw Hash salted and/or iterated
  21400 | sha256(sha256_bin($pass))                                  | Raw Hash salted and/or iterated
autumn pilot
#

careful with spoilers

uncut mirage
#

Sorry, will hide next time 🙂

brittle berry
#

Can someone give me a hint with Attacking Common Services - Hard I'm kinda stuck on it for a while, I was able to impersonate then find a DB which has user that is supposed to be an admin, but not quite sure how to move urther than this.

timber hatch
#

PIVOTING, TUNNELING, AND PORT FORWARDING, section Remote/Reverse Port Forwarding with SSH:
my multi handler is not able to make a connection...anybody an idea why...?

timber hatch
#

why?

placid quest
#

@timber hatch try with sudo

timber hatch
#

tried. but did not work

#

I mean I can go on I have answered the questions.... but somehow I still want to manage that...

autumn pilot
#

are you sure that you can reach the 172.16.x.x subnet address?

timber hatch
#

thanks 😉

#

that whole forwarding is confusing me

brittle berry
timber hatch
#

i have a feeling why...

#

once to twice a week such a requestkek

fathom pendant
#

@autumn pilot banhammer

timber hatch
autumn pilot
#

the exercise is based on what you have learned in the section of the module

#

if you have your payload already uploaded to the target ubuntu machine, then you first must make it an executable there and secondly you must ensure that the listening IP is the appropriate one as well as the port that you have specified in msfvenom's command

woven sparrow
#

Is there a way to close a target ip in academy? It says I have 60 minuts left.

devout cliff
timber hatch
# autumn pilot the exercise is based on what you have learned in the section of the module

at the windows host i have to add .exe to the backup file, right?
at the ubuntu server the file does not ineterest me, right? but there it lays also with the ending .exe. but that was only for the transfer to the windows host, right?

are the ip set right in these commands:
msfvenom -p windows/x64/meterpreter/reverse_https lhost=172.16.5.129 -f exe -o backupscript.exe LPORT=8080

ssh -R 172.16.5.129:8080:0.0.0.0:8000 ubuntu@10.129.68.157 -vN

?

autumn pilot
#

no idea

timber hatch
woven sparrow
devout cliff
#

for academy?