#modules

1 messages Β· Page 60 of 1

north ermine
#

Hi ! I need some guidance om Documentation & Reporting Practice Lab

I managed to find a user that can log on the DC but I am failing to get RCE on the DC

sinful olive
#

Module:ACTIVE DIRECTORY ENUMERATION & ATTACKS - Credentialed Enumeration - from Linux

I have a weird problem.. Found the user for the first question - but it doesn't accept his name / username as an naswer..

low vine
#

Ned some help with WEB ATTACKS - Advance File Disclosure. I've read through everyone elses complaints as well as reading some that apparently work and I'm not getting any sort of traction with this one.

I'm set up / its communicating but I just have the wrong info getting pulled in a I guess?

#

(CDAT BASED ONE )

autumn pilot
#

if have converted the rid to a user, just get the username

#

and Axiom, please stop deleting your messages with the intent of posting another one only to be the most recent

low vine
#

I delete them because i think I found them

#

thanks for your input though

#

err think I found the answer and then realize im a dumbass and still cant do it

#

so i put it back up

sinful olive
autumn pilot
#

sure

austere osprey
#

Just finished Linux Privilege Escalation module, if got stuck feel free for an hint

#

Or if have suggestions for challenging modules you got stuck at, feel free to mention them and I will take a look πŸ˜‰

low vine
#

@austere osprey Web Attacks - Advanced File Disclosure using CDATA

brittle berry
#

Yo what up channel? I'm doing RDP and SOCKS Tunneling with SocksOverRDP from Pivoting, Tunneling, and Port Forwarding module and I have done all the steps but when I try to connect to 172.16.6.155 as Jason RDP never loads.. I have changed the RDP settings to 56 kbps Modem and it's now 20 minutes waiting for it to load.. any ideas how much should I wait for it to load?

low vine
#

I'm absolutely dumb....I got it.....im dumb

north ermine
austere osprey
#

Starting with windows privilege escalation now, see how it goes xD

weak stirrup
#

I am still having problems with "Packet Inception, Dissecting Network Traffic With Wireshark" I am looking for an image of a 'transformer' the only image I find after capture is a image of a dog. the dog comes down as ftp-data I have tried to filter on image-jfif and image-gif and looked through the http for any inline images in the data. I cant see any http traffic that contains images. i am not sure what i am supposed to be seeing. i am left to assume i am not even capturing the correct data. can someone help?

tidal lark
#

Hey

#

can anyone help me with what flags mean?

#

I'm having problems resolving HTTP and cUrl exercise

autumn pilot
#

HTB{this_IS_a_fl4g}

tidal lark
#

but do they have any other definition i might dont know?

autumn pilot
#

nope

#

apart from a md5sum, nothing else

tidal lark
#

I mean i've downloaded with curl a file from an url and now i have tofind the flag inside the file but i canΒ΄t

wind sparrow
#

?w

echo sparrow
#

Hey

#

I'm trying to figure out the solution to the windows fundamentals but it seems none of the answers I find is correct

hoary palm
#

Hi, I've finished the tutorial Getting Started. Can someone check my walkthrought document for the last module step and provide me some corrections ? πŸ™‚

gray blade
#

Hello everybody ! Someone could help me? I’m on Active Directory skill assessment II and I’m trying to find solutions solutions to connect myself on ms01 with mssql user (psexec) :))

placid quest
#

@gray blade maybe try with mssqlclient

tidal lark
dim wolf
autumn pilot
#

hint - you don't need to actually download it

versed lichen
#

Hi, I am doing a medium lab of the Password Attacks module. I have password from users j***n and d****s (and its ssh key along with password). When enumerating the machine, I also found user n****y, but I don't have his password. I have been trying to find something interesting and useful using user d****s for a few days. Could I ask for some tips on what to do next?

wind sparrow
#

can someone pls give me nitro

#

i never got it

autumn pilot
#

no and don't ask for such stuff @wind sparrow

wind sparrow
dim wolf
#

???

hasty solar
#

In RDP and SOCKS Tunneling with SocksOverRDP from PIVOTING, TUNNELING, AND PORT FORWARDING when trying to execute this command C:\Users\htb-student\Desktop\SocksOverRDP-x64> regsvr32.exe SocksOverRDP-Plugin.dll im getting the following error

#

The module SocksOverRDP-Plugin.dll failed to load, why I'm getting this ?

acoustic owl
autumn pilot
#

make sure you are running the terminal as an administrator

hasty solar
#

gonna try that thanks for the help

hollow hinge
#

Hey, do you still need help regarding FI module? if yes, you can DM, if you want

autumn pilot
acoustic owl
# versed lichen bump

If everything is configured correctly, a user does not have admin rights. But if he needs some, he often has another account, with which he can then get admin rights.
On a Linux machine, depending on the configuration, a key is needed for root πŸ˜‰

versed lichen
acoustic owl
autumn pilot
#

there is no need to run enumeration scripts or anything else

versed lichen
hasty solar
#

IN Skills Assessment from PIVOTING, TUNNELING, AND PORT FORWARDING once you discover that user mlefay exists you have to pivot to a windows host, what dictionary did you use to bruteoforce the following services ssh,msrpc,smb and rdp

placid quest
#

@hasty solar why do you need to brute force some services

hasty solar
#

cause I tried with null sessions and anonymous authentication and didnt found nothing on this host 172.16.5.35

placid quest
#

@hasty solar but you need to dump the lsass to get the password and username

dim wolf
#

lsass is a windows process

autumn pilot
#

TTL

hasty solar
#

ok

ripe grove
#

I'm working on AD Enum and Attacks:ACL Abuse Tactics. one of the examples mentions using Get-ADGroup from PowerView, but it doesn't look like Get_ADGroup is in PowerView. Thoughts?

thorn urchin
#

are you sure you imported it correctly first?

#

actually looks like its a builtin, no powerview

ripe grove
#

so I guess that still leaves the question, how do I do this?

thorn urchin
#

theres some other ways you could get the group information

#

idk off the top of my head for powershell but could always just do like bloodhound

weak stirrup
#

In the new Linux fundamentals does anyone understand what is intended by the question What is the type of the service of the "syslog.service"? i tried systemd: system log, system logging, logging. etc.. I am not sure why is meant by the word type

ripe grove
thorn urchin
#

I dont remember it not working for me, but its been hot minute

#

Β―_(ツ)_/Β―

tardy beacon
#

im working on the "Initial Enumeration" section in the the windows privesc module, im stuck on the What non-default privilege does the htb-student user have? , i ran whoami /all and everything seems standard, what am i missing? the hint says to run cmd as administrator and for some reason I actually can but why?!

acoustic owl
tardy beacon
#

what command can i run to see those rights?

ripe grove
acoustic owl
rustic sage
#

Hi all, could I have a sanity check on this? this is my second day stuck here... Module: Attacking Common Applications, Section: Skill Assessment Part I

thorn urchin
#

I dont actually like running powershell on the target if I can avoid it. so I didnt use that methof

tardy beacon
tardy beacon
#

lol im so confused, anything i try to submit to the questing answer place it says wrong

#

oh nevermind i just wrote it wrong the first time

#

works now

elfin nacelle
#

Hello can someone assist with the File Upload Attacks Module. The question hint is "Try to find an extension that is not blacklisted and can execute PHP code on the web server, and use it to read "/flag.txt" I fuzzed for php extensions using seclists and payloadsallthings and get a bunch of 200s back. However, none of the extensions will read a simple hello world script or shell. Can someone give me a nudge?

safe leaf
#

If you want to DM me, I can try and help, are you using burp intruder? If so, can you show me your payload? and the part you are fuzzing and your script? I will say I got maybe 15-20 things that made it through as a file, but only one of them executes the php script when you call it

arctic sentinel
#

Hello, anyone could help me with the bash scripting module! I`ve been stuck in the flow control-loops sections for many days.

low mica
#

could i have some help. im working on the "password attack" module. i have copied the NTDS.dit file from the target machine and now trying to share it back to my attack machine. im getting an error even though i am using the right share ip. any suggestions?

lethal atlas
fathom pendant
#

nah

#

it's the sudo part

#

that actually breaks it

#

because they are remoted into a POWERSHELL

#

but also yes

#

try putting quotes around the command portion aftrer /c

magic valve
#

Hello, may I get a hint with Attacking common services -Easy? I’ve attempted to get conmand execution with uploading php cmd file on FTP. Receiving a 404 not found error when attempting to navigate to it through the web browser.

fathom pendant
#

is the ftp port linked to the web service?

thorn urchin
#

but I had a light chuckle at that too

fathom pendant
#

i can't read

magic valve
fathom pendant
#

in the ftp server isn't there an additional file that may be worthwhile to look at carefully

thorn urchin
fathom pendant
#

@hollow dagger check what realm the linux user is part of; then look for a folder that may contain that realm information; it has to be saved somewhere locally right?

#

you are looking for a ccache

magic valve
fathom pendant
#

basically if you are uploading it to the ftp server; where is it going?

hollow dagger
#

Could someone help me with the Pass the Ticket section, please? Particularly the last question, "Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_)."

I think I understand that I ||need to use a ccache file in /tmp (the ones starting with krb5cc)||, but none seem to let me smb into //dc01/linux01.

I then thought I needed to generate the ccache by running|| kinit linux01@INLANEFREIGHT.HTB -k -t /etc/krb5.keytab||, but that just says there are no suitable keys...

Have I missed something??

@fathom pendant , thanks for your quick response. I had posted it prematurely and have added more detail. Any more advice?

fathom pendant
#

and you are unable to use that keytab

#

but there is a place where information about the realm is stored in some sort of variable library

hallow remnant
#

AD Enumeration & Attacks - Skills Assessment Part II:

I'm having trouble with Question 8, wherein I need to obtain the flag.txt from the Administrator's Desktop on machine MS01.

At this point, I've tried running LaZagne.exe, Snaffler.exe, Mimikatz.exe, and Rubeus.exe to unearth assorted credentials from the SQL01 host. I've obtained a cleartext credential for mssqlsvc, but it hasn't seemed applicable. I've likewise pulled a number of hashes, including one for the local Administrator account for SQL01.

I've attempted to Pass-the-Hash with the aforementioned hash using impacket-psexec, crackmapexec, and evil-winrm to no avail. I've also tried various iterations on the password that was discovered. It's unclear to me what my next step is intended to be at this point.

thorn urchin
#

hint:its not a red herring

fathom pendant
#

hint: what does mssql stand for

fathom pendant
fathom pendant
#

local*

hallow remnant
fathom pendant
#

i'll have to redo to doublecheck but iirc it's fairly straightforward

#

are you able to run commands in the sql server?

hallow remnant
fathom pendant
#

including xp_cmdshell yeah?

sleek pulsar
hallow remnant
fathom pendant
#

so why can't you get Administrator desktop?

hallow remnant
#

Admin desktop for MS01

#

Not SQL01

#

I'm having trouble with Question 8, wherein I need to obtain the flag.txt from the Administrator's Desktop on machine MS01.

fathom pendant
#

mmm my bad

hallow remnant
#

It's what follows getting Admin on SQL01

fathom pendant
#

misread

#

is admin reusable?

hallow remnant
#

Tried performing some pass-the-hash using the admin NTLM I dumped, but no dice

#

And I haven't been able to crack it yet

#

*crack the hash

#

thrown it at SMB and WinRM

fathom pendant
#

that's not what I asked :)

#

have you tried reusing admin password

hallow remnant
#

Not sure I follow; I have the SQL01 Admin's NTLM hash, but not their plaintext. Or was that not the "admin" you were referring to?

rustic sage
#

Hello friends

hollow dagger
#

Thank you so much. That was such a good hint. Didn't give too much away and helped me realise where the gap in my knowledge was.

thorn ingot
#

I wanted to reset the progress for modules that aren't completed, but thank you

fathom pendant
fathom pendant
hallow remnant
fathom pendant
#

F

#

i misread the module you were doing; i haven't yet completed this one yet; i was thinking of a diff module mb but i'd say take a step back and take a break especially if you've been working 1-2+ hours on it

hallow remnant
#

sad trombone

fathom pendant
#

i've heard tho doing windows priv-esc first before ad enum helps a lot

thorn urchin
#

my hint is still relevant

#

Why do you think that clear text password isnt relevant?

#

Its very relevent, yes FOR MS01

#

Admin hash for SQL01 would only be useful if local admin pass was same across multiple machines(which sometimes is the case, especially if LAPS isnt used, but that doesnt apply here)

serene holly
#

How can someone see their one?

fathom pendant
thorn urchin
rustic sage
#

.

surreal harbor
#

Hi Family!

magic valve
#

Greetings

fathom pendant
thorn urchin
magic valve
zinc hemlock
deft escarp
#

Would you say labs in medium difficulty modules are equivalent to medium HTB machines?

fathom pendant
#

they're really not 1-1 comparable; as the module teaches a specific thing where machines use a handful of things at times

#

medium modules just refer to the previous level of knowledge required to work through it smoothly

deft escarp
#

Ahhh

fathom pendant
#

for instance there's a web https module that's tier4/5 i think that you'd be completely lost on if you don;t know basics of sqli/xss/xsrf/nosqli

deft escarp
#

Got ya, thanks for the info

dim wolf
#

no tier 5 modules

fathom pendant
#

listen I couldn't remember what tier it was

#

I just remember it was a higher tier than 3

void echo
#

Hi guys

calm gull
#

Can someone explain the magic that is wildcard abuse (in linux priv esc)? In the example, commands are written to filenames, which are executed by by the cron job, it seems. Is this because the cron job ends with a wildcard *, and the filenames are listed sequentially after the cron job in the directory?

faint rampart
rustic sage
#

hello everyone

faint rampart
# calm gull Can someone explain the magic that is wildcard abuse (in linux priv esc)? In the...

here's something I saved in my notes that could help :

* * * * *  command to execute
 ┬ ┬ ┬ ┬ ┬
 β”‚ β”‚ β”‚ β”‚ β”‚
 β”‚ β”‚ β”‚ β”‚ β”‚
 β”‚ β”‚ β”‚ β”‚ └───── day of week (0 - 7) (0 to 6 are Sunday to Saturday, or use names; 7 is Sunday, the same as 0)
 β”‚ β”‚ β”‚ └────────── month (1 - 12)
 β”‚ β”‚ └─────────────── day of month (1 - 31)
 β”‚ └──────────────────── hour (0 - 23)
 └───────────────────────── min (0 - 59)
rustic sage
#

anyone here looking forward, for a hacking partner?

thorn urchin
faint rampart
fading coyote
#

hello is anyone available for a simple question that i have?

#

its about ncat

#

when i am trying to open a server on port 80 using the pwnbox

#

it says the port is already in use

#

i am following the modules instructions so i am unsure how to fix it

autumn pilot
#

Use a different port number

fading coyote
#

i amm supposed to listen on port 80 i think

#

since its a HTTP

#

for context

#

its the XSS module

#

phishing part

gray blade
#

Hello everyone! Someone could help on Active Directory skill assessment ? I try to find solutions to connect myself to the dc01 :))

acoustic owl
acoustic owl
gray blade
# acoustic owl and what exactly is not working? Some info would be helpful

Sure! Im actually on ms01 with CT*** rights and im try to find solutions to connect myself on the dc01. I saw than someone talk about port forwarding but I don’t understand why because we are on the same network 172.16.7.0/23. Maybe I need to find other credentials on ms01 with CT*** rights (with snaffler) and know which tool I can use to be connected on dc

fading coyote
#

tyty

#

just curious what's using port 80 on the pwnbox

#

is it the box itself?

fathom pendant
#

Probably

#

Or some other thing like nginx

fading coyote
fathom pendant
#

You can always take a look yourself

fading coyote
#

could probably do a scan

#

eh

#

getting late

#

need sleep

fathom pendant
#

Don't even need to scan lol

fading coyote
#

i am still new to this

#

learning

#

gotta google it tmrw

#

XD

fathom pendant
#

Lol or just use a simple command

fading coyote
#

will do

fathom pendant
#

That will tell you what process is listening on any ports

fading coyote
#

tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN 14344/python2.7

#

huh

fathom pendant
#

Python http.server?

fading coyote
#

dunno

#

i didn't run a python server

fathom pendant
#

That's what it looks like

#

Β―_(ツ)_/Β―

fading coyote
#

i just lunched the box as it is

#

ya

fathom pendant
#

I use my own vm so dunno

fading coyote
#

i dont like using the boxes

#

i use my own vm too

#

but i just do it here and there to avoid lunching

#

just wanted to get a module out for today

fathom pendant
#

whatever boats your float Β―_(ツ)_/Β―

fading coyote
#

caffeine

#

a lot of it

fathom pendant
#

Mood

simple zephyr
#

File Upload Attacks final challenge was really fun. I encourage everyone to give that one a try.

calm gull
faint rampart
burnt sluice
#

hello guys

#

i've been having a problem with the Linux Fundamentals module, the task scheduling section.

#

i can't seem to find the answer for this question

What is the type of the service of the "syslog.service"?

#

i searched the internet for an answer, read the official linux wiki, tried multiple answers but nothing seems to work

#

if anyone knows any tips regarding this please tell me

scarlet jewel
scarlet jewel
autumn pilot
#

if you don't have one, you can't join them

scarlet jewel
#

How can I get them

sinful falcon
#

You can join public CTF

#

Like cyber apocalypse by HTB

autumn pilot
#

if you are part of the entity that has requested the ctf you will have the key, otherwise you can't

scarlet jewel
#

Also anyone have vacancy in their team for a noob

grand harbor
#

can someone help me with answering this question : What is the admin email address? in the imap/pop3 module.

#

i have already got the flag

#

i have got this already ||* 1 FETCH (ENVELOPE ("Wed, 03 Nov 2021 16:13:27 +0200" "Flag" (("CTO" NIL "devadmin" "inlanefreight.htb")) (("CTO" NIL "devadmin" "inlanefreight.htb")) (("CTO" NIL "devadmin" "inlanefreight.htb")) (("Robin" NIL "robin" "inlanefreight.htb")) NIL NIL NIL NIL))||

autumn pilot
#

you already have the email, you just need to piece together the information you already have

#

think about the format of the answer that is being expected

grand harbor
autumn pilot
#

because it is incorrect

grand harbor
#

ok got it

#

lol

#

thanks

burnt sluice
torn blade
#

struggling on a php module

#

when a staf is free plz halp, like ik what payload to use i think im just missing something basic

torn blade
#

Can I get a different discord admin member for assistance, I got MitcoSC and every time he has been the one to help me he does not provide good assistance and ghosts me. Like ive only have gotten help from him twice but so far 100% of the time he is not helpful where every other discord admin member who assists me is very helpful.

lethal atlas
prisma knot
#

Anyone potentially see any errors with this python3 file transfer command? I continuously get "name resolution" errors, even though I can browse to the URL I pass in perfectly fine. python3 -c 'import urllib.request;urllib.request.urlretrieve("https://raw.githubusercontent.com/rebootuser/LinEnum/master/LinEnum.sh", "LinEnum.sh")'

lethal atlas
#

@prisma knot has to be something in your settings. The command works perfectly

torn blade
fathom pendant
#

I take it you're using the Perk of being a Silver Annual Sub; in which staff will indeed help you

prisma knot
lethal atlas
#

been there done that

subtle glen
#

information gathering, virtual hosts, ||ffuf -w /usr/share/seclists/Discovery/DNS/namelist.txt -u http://10.129.42.195 -H "HOST: FUZZ.inlanefreight.htb" || needs around 18 hours to complete, isnt there any way i can do it faster?

||i added 10.129.42.195 inlanefreight.htb to my /etc/hosts but i cannot curl -s 10.129.42.195 -H "inlanefreight.htb" it there is no output at all||

deft escarp
#

anytime I run xfreerdp in any capacity, even if its just --help, I get this error: ```
No protocol specified
[15:23:30:279] [4324:4324] [ERROR][com.freerdp.client.x11] - failed to open display: :0.0
[15:23:30:279] [4324:4324] [ERROR][com.freerdp.client.x11] - Please check that the $DISPLAY environment variable is properly set.

#

even with the default display set, which is 1, i get the same error

#

using pwnbox

#

the issue was pwnbox, works on my vm

analog tendon
#

if anyone is available i could used some assistance on the medium lab in password attacks. I was able to get the J account and from the cool document i got i know there is a mysql database but i cant seem to access it. ive searched through just about any file i could find and open but nothing is pointing to it. am i going down a rabbit hole here or is this the right way to go? any nudges?

proud pine
deft escarp
#

yeah

proud pine
#

Try as the normal user.

#

I think the issue is just because you're only running commands in a shell as root, but it doesn't have an X session.

#

So if you still have the problem when not running as root, then I'm not sure.

lethal atlas
analog tendon
#

but now for some reason it froze. so theres that

analog tendon
#

ah i have to restart the machine. yay

lethal atlas
analog tendon
#

usually after restarting the machine and the terminal that was connected to it i can continue on

tidal kelp
#

Hello everyone, i'm on Windows Privilege Escalation Skills Assessment - Part II can anyone help me? i tried 16 explit from windows-exploit-suggester

#

helo bro, can i dm you about Windows Privilege Escalation Skills Assessment - Part II ?

brazen apex
#

Has anyone thats online dealt with the FTP section of Footprinting

#

I got the flag but I hate how unspecific questions are

#

submit the entire banner

#

well the banner is pretty fuckin big

#

and doesnt fit

#

Does anyone know what part i should copy and paste. It's no longer printing "try being more creative" so I assume I got the answer

autumn pilot
#

the part that the is basically the banner

brazen apex
autumn pilot
#

I mean you need to make the differentiation what is the banner

#

for example when you visit a page that is non existent it will spit out 404

brazen apex
#

the banner is this portion yeah
| service blah
|
|

autumn pilot
#

improve your method

brazen apex
#

wdym improve my method clearly a banner is something that can be dynamic

#

so i have to try every command till I get the order of the banner that works for the question

autumn pilot
#

its not about that you have tried every command, but it is about how you consume the information that every command spits out

brazen apex
#

bro I got the flag already clearly im not bashing my brain at the terminal

#

i got no clue what this question ants me

autumn pilot
#

it asks you to grab the banner of the service

#

nothing more nothing less

#

it is also shown in the section, e.g. in the material

brazen apex
#

could you please help me define which part the banner is

autumn pilot
#

and there is an example

brazen apex
#

I guess but the examples arent always perfect man I mean I havent seen a single example in HTB that shows how to correctly use the NSE

autumn pilot
#

it would be much more rewarding if you try it by yourself

brazen apex
#

I have been 100% i already have the answer

autumn pilot
#

there was a module that explained NSE

#

and if you literally search on the page in the section the word "banner" you will go to the example and the text that explains it

ripe grove
#

It's training, it should explain concepts and processes to students more clearly

brazen apex
#

omg

autumn pilot
#

it is explained cretan

brazen apex
#

this is painful bro my bad

#

when i think of banner

#

I think of enumeration with nmap or netcat

ripe grove
#

I've often found many sections kind of lacking

autumn pilot
#

and they are?

ripe grove
#

I've been documenting them in the erratum as I've been going through. Also through our facilitator

#

but the response should never be "do better"

brazen apex
#

I dont expect answers to be given but I agree theres been a few times where the syntax isnt explained well for commands

#

and why that orders used etc

#

but its not a huge deal

#

to me

autumn pilot
#

all I can see is that you have two messages there cretan

pseudo ledge
#

it might be a pretty stupid question but how do I upload an exploit from exploit-db to msfconsole?

brazen apex
#

No dumb questions here

autumn pilot
potent epoch
#

hi

#

i am new to this community

#

can you guys tell what is this server about

pine bough
brazen apex
autumn pilot
pseudo ledge
autumn pilot
#

not necessarily needed

potent epoch
autumn pilot
#

if you are working on the live engagement, the exploit is already there

brazen apex
potent epoch
autumn pilot
brazen apex
#

pretty sure theres a command that walks you thorugh it

#

yk it @autumn pilot ?

pseudo ledge
autumn pilot
#

can't recall the exact name, but it was in the Downloads folder if I'm not mistaken

#

and it started with numbers

pseudo ledge
#

so how can I run it using msfconsole?

autumn pilot
#

use <exploit>

pseudo ledge
#

but the downloads folder isnt connected to the msfconsole

potent epoch
autumn pilot
#

if you have actually read it you will know what to do as it is explained step by step

potent epoch
#

is it free to learn

autumn pilot
#

yes

#

and to some extent as well on academy

pseudo ledge
#

@autumn pilot can you help me find the exploit pls? I've been stuck on this for hours

#

I know what is the ruby file

autumn pilot
#

ls Downloads/ or use the find command

pseudo ledge
#

I found the file

autumn pilot
#

use <exploit>

pseudo ledge
#

I get failed to load module error

autumn pilot
#

copy the error and paste in google

pseudo ledge
#

I cant find the problem

#

can someone pls help me

rustic sage
#

How did you figured it out?

fair spindle
#

hello

pseudo ledge
acoustic owl
lethal atlas
pseudo ledge
#

im working on shells&payloads the live engagement

#

I got to the second host and I can't seem to find the exploit in the msfconsole even though the file clearly exists in the system

lethal atlas
pseudo ledge
#

yeah

lethal atlas
#

copies the file. then once you have msfconsole loaded you have to reload_all

#

after that you should be able to search for it in msf

pseudo ledge
#

thank you so much, it worked!!

lethal atlas
#

πŸ˜„

worthy briar
#

On the module Meterpreter Tunneling & Port Forwarding, i was able to complete it on the hackthebox instance but on my main attack box i canΒ΄t. Pretty sure something wrong with proxychains or even the auxiliary/server/socks_proxy module. When i try proxychains nmap 172.16.5.19 -p3389 -sT -v -Pn nothing happens. Just wondering if somenone had the same problem and was able to solve it. Thanks

autumn pilot
#

double check your proxychains configuration and etc

worthy briar
#

everything is ok on the .conf

#

pretty odd because i was able to do it on the academy instance

versed lichen
#

Hi, do you have any tutorial/hints how to mount Bitlocker vhd disk on linux (kali/parrot)? [Password Attacks - Hard Lab]

lethal atlas
rustic sage
#

Can I DM someone about Active Directory Enumeration & Attacks - External Recon and Enumeration Principles? I feel like I'm missing something so simple but I can't find the flag

thorn urchin
#

just ask your question

rustic sage
#

I just don't know how to find the flag... the hint says ||check DNS records|| but I don't see anything besides the nameservers, mail server, and www no flags. Tried looking at the site and couldn't find anything either. The module used bgp.he.net and I tried that but for some reason the site doesn't load on PwnBox

shadow canopy
autumn pilot
thorn urchin
#

external checks wont see an internal vpn lab environment

thorn urchin
#

its just on the VPN

#

so you cant use public services with it

#

you gotta use local tools

autumn pilot
#

in this exercise the real domain is used

rustic sage
#

I've been mainly using dig and viewdns.info but I couldn't find any flag

mellow turtle
#

@versed lichen If u are trying to mount bitlocker use this use bitlocker with losetup
sudo apt-get update; sudo apt-get install dislocker -y
sudo mkdir -p /media/bitlocker
sudo mkdir -p /media/bitlockermount
sudo losetup -f -P Backup.vhd
sudo dislocker /dev/loop0p2 -u(password) -- /media/bitlocker
sudo mount -o loop /media/bitlocker/dislocker-file /media/bitlockermount

also here is the unmount command if you are doing this on your machine
umount /media/bitlockermount /media/bitlocker
losetup -d /dev/loop0

autumn pilot
#

the flag is in the mentioned record

versed lichen
mellow turtle
#

yes

versed lichen
#

it asking me for some user pass, it'll be pass of user whose created this disk?

rustic sage
autumn pilot
#

try using the tool that I shared

rustic sage
autumn pilot
#

don't know, maybe dns?

hazy grotto
#

Can anyone help me with Bypassing other blacklisted characters section in comannd injections?

#

I'm almost there but i can't seem to get it to work.

#

DM?

thorn urchin
#

Have you tried the ffuf fuzzing method?

quasi wave
#

hi InfoSec fundamentals is getting a lot of updates lately. How much is it gonna be expanded? I had completed 78% two days ago but now 2 modules have been expanded extensively. I'm fine with this but just so I can plan my goals a little better, how many sections are getting major updates that will be released soon and how long will it take for these major updates to be completed?

#

so now I've only completed 70% lol

thorn urchin
#

Theres no released update plans

#

Β―_(ツ)_/Β―

#

but updates tens to be excellent so I welcome them even when briefly inconvenient

uncut mirage
#

Hi all,
I'm in the Active Directory Enumeration & Attacks module, ACL Enumeration section, stuck on the last question regarding the forned users rights over the GPO Management group. I've tried everything demonstrated in the section, tried my best with Google Dorks and asked ChatGPT for help too, all without luck... Can i get a little help please?

simple zephyr
#

Command Injection Module is a hair puller

autumn pilot
hazy grotto
autumn pilot
#

and you have tried the same method from the whoami example?

hazy grotto
#

πŸ™‚

autumn pilot
#

nice

hazy grotto
#

I was forgetting the url encoded new line in the beginging.

#

I didn't realize i needed that to separate the command from the ip

hazy grotto
#

echo -n 'cat /etc/passwd | grep 33' | base64

#

This command.... the | grep 33'

autumn pilot
#

it will find a string let's say that has 33' and then it will base64 encode it

hazy grotto
#

Is telling the base 65 something?

Or is it apart of the etc command

hazy grotto
#

So its saying get me a code that is 33 characters

autumn pilot
#

not 33 characters, but whatever line or string that has 33' in it

hazy grotto
#

Why the 33?

autumn pilot
#

no idea, maybe somewhere in the file there is that piece of string

#

you can remove the last part of the command, e.g. | base64 and see what exactly is being printed to stdout

fathom pendant
thorn urchin
hazy grotto
thorn urchin
hazy grotto
#

and the 33 part of that?

thorn urchin
#

root's uid is always 0 for example

hazy grotto
#

that's a common ID number?

thorn urchin
#

and most regular users are 1000 and up

#

yeah

#

1-999 are often uids for different services

#

*often but not always

#

if you look at an /etc/passwd file you can see all the associated uids for each user

hazy grotto
#

Can i dm someone for the next question? I don't want to give a spoiler. I believe im close

#

I'm getting the ip to ping back and no invalid input. But the command is not running.

hazy grotto
#

NVM got it.

#

I forgot to take out the grep 33 in the new command

frigid osprey
#

same I didnt write down all the passwords. Missing kira's too LOLOL

timber hatch
#

at the moment my target goes all the time down...any body else facing problems?

tardy beacon
#

im having trouble logging into the rdp as svc_backup from the windows privesc module: Leverage SeBackupPrivilege rights and obtain the flag located at... i enter the credentials and it just says incorect username or password, i used user "svc_backup" and password "HTB_@cademy_stdnt!"

thorn urchin
timber hatch
#

WTF....attacking common services after each attack my tagret goes down...

tardy beacon
thorn urchin
#

also if youre passing the password via cmd line is worth trying not to and entering it for the prompt, sometimes bash will interpret the @ or ! weirdly

tardy beacon
#

i escaped the ! with a backslashh

#

also tried entering from the login screen

#

idk what to do

thorn urchin
#

escaping it can also mess it up

#

what client are you using

tardy beacon
#

rdesktop

thorn urchin
#

try xfreerdp

tardy beacon
#

used it before on htb academy and worked fine

#

ok ill try it

thorn urchin
#

its password prompt is text based

tardy beacon
#

oh wow it actually worked!

#

thanks

brave sail
#

Hello, I'm at the CROSS-SITE SCRIPTING (XSS), Session Hijacking. When the web page reads the src=IP/script injected code it does a Null request instead of GET. Is this an important factor or it doesn't affect the exercises?

magic valve
#

May I dm someone to confirm I am barking up the right tree regarding creds and services for Attacking common services - Hard? Been stuck on this for a day.

fallow delta
#

Anyone happen to finish the Web Attacks assessment? I found an IDOR but currently trying to change a password| Edit: Figured it out

unborn ocean
#

Having issues with Skills Assessment - Using Web Proxies "The /lucky.php page has a button that appears to be disabled. Try to enable the button, and then click it to get the flag. " I have the button enable and sent it through repeater and hit about 30 times still don't see the flag.

lyric echo
#

Hey yall! Im running into this xfreerdp error while trying to access the Password Attacks: Pass the Ticket labs. Anyone have advice on how to correct this?

][com.freerdp.crypto] - Certificate verification failure 'self-signed certificate

red current
#

Anyone else having issues getting pypykatz to work in the attack passwords / attacking lsass section?

#

I reinstalled pypykatz and I'm getting an error of ModuleNotFoundError: No module named 'msldap.commons.url' when I try running it. I've looked through the forum and through the chat here and I don't see any good answer for it.

tidal kelp
# autumn pilot mashed potatoes

i don't know where to put the creds iamtheadministrator? section Windows Privilege Escalation Skills Assessment - Part II . potato needs SeImpersonatePrivilege. Can anyone help me out?

simple zephyr
#

I must be blind because I can not find the answer to this question. for Linux Priv Escalation.

Find a file with the setuid bit set that was not shown in the section command output (full path to the binary). I can't find anything that isn't shown in the example. I found the setgid no problem.

tidal kelp
simple zephyr
#

I tried that, let new try again after dinner

fading hound
#

Hello everyone, I have a query, I am making the LFI module and I got to this part where I have to get to the root but I found this code that does not let me go through the routes ../../
Is something going over my head or maybe I should make the deposit in another way?

<?php
if(!isset($_GET['page'])) {
include "main.php";
}
else {
$page = $_GET['page'];
if (strpos($page, "..") !== false) {
include "error.php";
}
else {
include $page . ".php";
}
}
?>

hazy grotto
#

Want to show some love to @light current @safe leaf and @west canopy for the huge help on Command Injections Skills Assessment.

#

GOD DAMN.

#

Really puts in perspective... How terrible I am at this. πŸ™‚

potent epoch
#

i need to ask a thing
what programing language should i learn for hacking
like java or python or c++

tribal plume
#

People are going to say it sort of depends on what you want to do.

tribal plume
#

Well, if you know nothing about programming you can't really do too bad learning python. There's a million free courses for it and there's a module for everything.

modest isle
#

I need help please!

I can't access my Academy account with my email

What can I do to get back my academy account? πŸ₯ΊπŸ₯ΊπŸ₯Ί

thorn urchin
#

contact support

modest isle
#

Can't get through to them

thorn urchin
#

then you wait

modest isle
#

Don't have access to my account

thorn urchin
#

you can access support without an account

modest isle
modest isle
thorn urchin
#

By clicking the green chat bubble for support

#

so what youre saying is, you did not attempt to contact support yet

novel matrix
#

This is the incorrect channel to reach out for support @modest isle

modest isle
#

What's the support channel here?

thorn urchin
#

you also dont need to spam your request to three different channels

#

there is none

#

click the green bubble

modest isle
thorn urchin
#

you lack reading comprehension

#

Good luck πŸ‘

modest isle
clear moss
#

you're really bad at reading comprehension, wow

novel matrix
# modest isle Buh I really need to get through to my account

If you can't sign in, you will need to make an account on the CTF platform as all accounts do not sync and aren't cross-platform. Again, this is the wrong channel to be discussing this as well.

If you are stuck, sign in to your HTB account and click the green chat bubble

thorn urchin
#

been said like three times. 1. Go to the website. 2. click the green chat bubble.

modest isle
#

The support team ain't responding

novel matrix
#

This convo stops here unless it is module related topic.

modest isle
#

Thanks @novel matrix

novel matrix
subtle escarp
#

hey, is this a place where i can learn how to hack

red obsidianBOT
novel matrix
#

@subtle escarp ^

next ledge
#

I have a question about the Firewall and IDS/IPS Evasion - Medium Lab. Anyone around?

#

I solved it but I am not sure if I did it the right way.

subtle escarp
#

what defines something as malicious, as in does that just mean hacking to get money and/or hacking to hurt someone in some way

arctic mango
#

Hello, I am struggling with Windows Exploitation. Can anyone please suggest me great resources to master Windows Exploitation. Thank you

quiet ember
cloud skiff
autumn pilot
crisp remnant
#

Can anyone that is good at windows help me a bit to understand why something is not working as expected

livid bluff
#

Hi,
I'm stuck in password attacks module in Pass the Ticket (PtT) from Linux section at the question :
Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_).

The clue is the following There is a file containing the identification information of Linux machines in Active Directory.

I tried everything in the course with the /etc/krb5.keytab but nothing work ...

When i try Abusing KeyTab Files i have an error :
keytabs contain no suitable key

With keytabextract.py i dump the hash but i can't login with it.

balmy lion
#

hello, can somebody give me a nudge towards the answer for the following:

Module: Password attacks
Section: Password mutations
Question: Create a mutated wordlist using the files in the ZIP file under "Resources" in the top right corner of this section. Use this wordlist to brute force the SSH password for the user "sam"

I've tried several methods, but I cannot brute the password before the expiration of the target machine.
Currently trying: hydra -l sam -P cut_mut_password.list ftp://10.129.186.213 -t 64 (I've cut the first 17k lines from the wordlist as suggested here, and also opted for ftp brute forcing rather than ssh with no luck)

livid bluff
livid bluff
hallow swift
#

hello, can somebody give me a nudge towards the answer for the following:

Module: Usig web proxies
Section: Zap Scanner
Question: Find vuln and get /flag.txt

I tried some command injections but I can't get it..

vital adder
balmy lion
vital adder
#

my zap on this section for some reason was only able to detect the vuln like half of the time

livid bluff
hallow swift
vital adder
hallow swift
vital adder
#

so did you get RCE?

hallow swift
#

yes

#

I can't get to cat the flag.txt

vital adder
#

because of to spoiler shoot me a dm with what you have try because if you got RCE the flag should just be at /

vital adder
#

i forgot about this common mistake, for this user only you can use @inlanefreight.htb

#

a quick ls at /home will show you all of the user that have @inlanefreight.htb at the end

livid bluff
vital adder
#

the linux01 user is a domain user and (i think) not a local user on this linux machine

livid bluff
vital adder
#

yea i do remember don't have to use like half of the example showed but goddamn it's be come useful af for offshore

livid bluff
#

I've been on it since two days, I don't know what can i do for access to this folder

analog tendon
analog tendon
livid bluff
analog tendon
wild oar
#

hello, i need a hint for the session security skill assessment πŸ™‚

turbid tartan
#

i need a hint at the password attacks easy lab im bruteforcing ssh and ftp but it needs ages. Is there anythin that can speed up that process

opaque niche
analog tendon
turbid tartan
#

yes but its just using 16 threads

#

im using normal an mutated

analog tendon
#

i used the -t 50 and it went pretty fast. also ssh takes too long

turbid tartan
#

yeah im trying ftp

analog tendon
#

and im assuming youre using user list in hydra too correct?

turbid tartan
#

yes

opaque niche
#

Hello, in attacking common services hard , I'm having problems to find the flag (||I've already activated xp_cmdshell and show advanced options )||, I'm making the following query: ||EXECUTE('SELECT *
FROM OPENROWSET(BULK ''C:\Users\Administrator\Desktop\flag.txt'', SINGLE_CLOB) AS Contents')
AT [LOCAL.TEST.LINKED.SRV]|| , and the error is dsp_desc_bind: memory allocation failure for column #1, any ideas?

woeful ermine
opaque niche
opaque niche
woeful ermine
#

ohh ok nice

#

your welcome

analog tendon
#

im on the hard lab for the password attacks and i cant seem to find a way to get that inital hold. i tried bruteforcing johannas password and have been through the whole mutated list. no hits. both local-auth and normal. any nudges?

vital adder
vital adder
opaque niche
vital adder
#

i guess that would work too but i'm not sure also if you make the mutated wordlist right (with a sort command) the cred for that user isn't going to be that deep

opaque niche
wild oar
# vital adder sure what's the issue?

i used my payload to change thins/ steal cookies etc. and this works for other users but this payloads doesn't work the the admin. is used the right submit endpoint.

turbid tartan
#

im already done with the lab but thanks

analog tendon
opaque niche
vital adder
wild oar
#

but the api shows success

vital adder
#

shoot me a dm if the API request that you use to send your payload to the admin user

#

if you have confirmed that the payload worked but only the sending it to the admin user doesn't work then this is the only issue i can think of right now

brave palm
#

hi peeps, so i was doing the module **Password Attacks ** but the 3rd question in the "Attacking Active Directory & NTDS.dit" section is not accepting the answer, am i going nuts or what? pretty sure i have the answer..

valid nest
#

Any module recommendations for Cloud pen testing?

brave palm
#

oh fuck, solved it

#

i didnt read well enough the output from the || ntds.dit file || which had the username in lowercase lol

turbid tartan
#

password attacks medium labs i cant escalate privilege or find a pw for ||dennis||

#

what am i missing

livid bluff
meager pike
#

Hi someone can help me pls with BROKEN AUTHENTICATION - Predictable Reset Token ?

analog tendon
turbid tartan
#

yeas

analog tendon
#

examine the document where you got that info. notice anything you could also use that info for?

turbid tartan
#

im connected trough ||ssh||

#

and i searched everything on that machine

#

but i cant get what am i not getting

#

i cant get what am i not getting ~~ Me 2023

analog tendon
#

official quote of the HTB Academy if ive ever seen one lol. ok go back to the .docx file. and read through to the bottom. what services does it mention?

turbid tartan
#

ive been trough the ||mysql configs ||

analog tendon
#

idk how to do seperate spoilers. so its not the configs

#

||try the database itself||

turbid tartan
#

youre my hero man

analog tendon
#

no problem, if you need help on the hard one well im stuck on it so itll be a minute before im ready to help anyone with it

turbid tartan
#

bruh now im stuck again

lethal atlas
analog tendon
#

what have you found so far?

turbid tartan
#

now im logged in as ||dennis|| but cant find credentials for root

analog tendon
#

oh yea this one is tricky unless you play around a bit.

#

what can you find on dennis home page?

turbid tartan
#

i looked trough bash history etc. and all that and ssh key is encrypted but why would i crack that im already in dennis account

analog tendon
#

i mean sometimes the password on an ssh key is different then what the password for the account is

#

would be a reason to crack it i mean...

cloud skiff
#

Any solution for this openvas error

[>]
[>] You might need to refresh your browser once it opens.
[>]
[>]  Web UI (Greenbone Security Assistant): https://127.0.0.1:9392

Job for ospd-openvas.service failed because the control process exited with error code.
See "systemctl status ospd-openvas.service" and "journalctl -xeu ospd-openvas.service" for details.
Job for gvmd.service failed because the control process exited with error code.
See "systemctl status gvmd.service" and "journalctl -xeu gvmd.service" for details.```
turbid tartan
analog tendon
turbid tartan
#

yes

#

my mindset should be just crack everything thats encrypted even if it doesnt make sense

analog tendon
#

thats the spirit

#

35k password attempts into the hard password lab. nothing. lol

desert stump
#

Hey I am having some trouble with the CrackMapExec Module.
Question 4 in password spraying section

Is there any other local MSSQL account created with the same username and password as the corresponding Active Directory account?`

I am getting:

MSSQL       10.129.204.177  1433   DC01             [-] DC01\jorge:Inlanefreight01! [('SSL routines', '', 'legacy sigalg disallowed or unsupported')]
MSSQL       10.129.204.177  1433   DC01             [-] DC01\jorge:Inlanefreight02! [('SSL routines', '', 'legacy sigalg disallowed or unsupported')]
MSSQL       10.129.204.177  1433   DC01             [-] DC01\jorge:Inlanefreight03! [('SSL routines', '', 'legacy sigalg disallowed or unsupported')]
MSSQL       10.129.204.177  1433   DC01             [-] DC01\jorge:Password@123 [('SSL routines', '', 'legacy sigalg disallowed or unsupported')]

for every user

#

hmmm, maybe its to do with my cme install

fathom bone
#

someone here for helping me out on attacking common services easy lab?

lethal atlas
analog tendon
#

i rebuilt my mut-passwords

lethal atlas
#

the mut list is the correct one

opaque niche
lethal atlas
#

not sure if it matters but is Johanna capitalized?

analog tendon
#

i know. i was told it shouldnt be that far into the list. but im now 46k in

#

she is not

lethal atlas
#

because @opaque niche is correct, it should not take that long

analog tendon
#

let me reset target

lethal atlas
analog tendon
#

restarting with Johanna on RDP --local-auth

opaque niche
#

dont use rdp

#

try with winrm

lethal atlas
#

I used ||hydra -l Johanna -P mut_password.list rdp://10.129.202.222||

analog tendon
#

yea rdp was running faster

#

but ill try winrm

opaque niche
#

||crackmapexec + winrm + --local-auth||

desert stump
#

If anyone can help with my crackmapexec module question above. it would be appreciated.

lethal atlas
analog tendon
#

would you say johannas password is supposed to be within 10k of the mut-password list

lethal atlas
#

for sure

analog tendon
#

ok then let me try hydra because CME just past it

lethal atlas
#

how many passwords are in your mut list?

analog tendon
#

let me check

lethal atlas
#

just curious if you maybe missed something

#

I have 94359

analog tendon
#

187775 after deleting it and rebuilding it from the resources

lethal atlas
#

this list was made from the provided password list correct?

#

using ||hashcat --force password.list -r custom.rule --stdout | sort -u > mut_password.list||

analog tendon
#

yes. thats the exact command i used

#

i can try rebuilding it again

#

ok after rebuilding 94045

lethal atlas
#

thats closer. try running hydra now on rdp

#

the password in my list is between 9500 - 10000

analog tendon
#

running now with rdp

wispy sphinx
#

@tough fjord can i ask some?

analog tendon
#

ok cool. yea rdp works for it. CME just blasted right through it

#

hydra*

livid bluff
#

It's not my day ...
There is a special wordlist for Protected Archives in password attacks ?
I have the hash in good format but when i put the hash file in john there is no password.
I tried with rockyou and many list and the password.list in the ressource but not working.

analog tendon
livid bluff
vague rock
#

hi

rough trail
#

in metasploit module , in sessions and jobs section i am not getting the correct exploit for the older version of sudo please help

quaint gate
#

Anyone know the working version to ingest files to Bloodhound for the Bloodhound module on ParrotOS ?

steep flame
#

hello. I am trying to pass the password attack module. the Password Mutations section. But i have a really big problem. We have a lot of variants password even after deleting duplicate ones. And it's take around 6 hours. I sopose it's wrong dirrection. Maybe somebody make hint me, because other password in past section was realy fast founded.

autumn pilot
lethal atlas
lethal atlas
simple zephyr
#

for LINUX PRIVILEGE ESCALATION, I am finding that we maynot have permissions to run some of the privesc that they demonstrate and the flag is just searching directories. For example in Shared Object HiJacking, I have the flag and completed the module, but I get a permission denied on the exploit and same thing for Miscl Techniques.

Am I just completely missing something?

polar widget
#

someone has resetted the whole progress on BloodHound module

#

apparently I can't see what's updated, since everything stands new in that module (as of now), but I had already done it last year

acoustic owl
polar widget
#

there's the proof

#

I checked what's updated and saw that BloodHound was updated too

acoustic owl
#

Since all areas have been replaced, the status is now 0% again.

polar widget
#

makes sense

#

lmfao

acoustic owl
#

I only skimmed it quickly, but I'm really happy about the update

polar widget
#

I am excited about AzureHound

calm abyss
#

hello guys i got a question

What is the type of the service of the "syslog.service"?

I cant guess this one

thorn urchin
#

You shouldnt be guessing any of the questions

#

also which module and section

rustic sage
#

on the topic of Bloodhound... I have enough cubes to purchase a Tier III module. Would y'all recommend Bloodhound or CrackMapExec? I do plan on taking both, but I'm curious what y'all recommend

dapper fable
#

hey im doing "Information Gathering - Web Edition" and the DNS section asks "Which subdomain is returned when querying the PTR record for 173.0.87.51?"

#

wondering if the answer changed recently :/

#

ugh nevermind

modest token
#

Can someone share how they did the Double Pivot in ATTACKING ENTERPRISE NETWORKS Post-Exploitation? because the instructions provided in the module don't appear to work... πŸ˜₯ --Edit --- Anyone who has this question in the future check out this post https://forum.hackthebox.com/t/attacking-enterprise-networks-double-pivot-using-chisel/267043/4 it will solve your problem. ^_^

quaint gate
sonic arch
foggy light
#

Module: Attacking Common Services
Section: Attacking FTP
I have logged in ftp and used then used the username and password list to brute force to bruteforce ssh, When try logging in its giving me a error Permission denied publickey.
then i brute forced smb, and couldnt download the id_rsa, so i mounted it and tried again but same error.

cursive pawn
#

Similar problem as @polar aspen and @viscid furnace and @hazy grotto - I can get the meterpreter, run it in the bg, and run what I believe is the correct cve exploit, but I always get "Exploit completed, but no session was created" on thie metasploit - sessions - last question. Any hints?

timber hatch
timber hatch
#

sure

polar widget
hazy grotto
thorn urchin
#

Unfortunately I dont take notes on section specific assignments so I couldnt help much either other than just redoing it again.

graceful rampart
cursive pawn
tardy moth
#

Hello guys, In the cbbh -> ATTACKING WEB APPLICATIONS WITH FFUF -> Recursive Fuzzing
I got the flag but it tells me that it is wrong. Can someone verify that the flag I have is the right one?

tardy moth
modest isle
#

Hello guys

#

I just noticed that the Linux Fundamentals module has been updated with some newer sections added

#

I feel that kind of cool

fathom pendant
#

but in short; are you having the payload call back to the right IP

cursive pawn
tranquil lichen
#

Hello guys, I'm having a bit of trouble on the Getting Started module, Service Scanning section

Specifically this question
Perform a Nmap scan of the target. What is the version of the service from the Nmap scan running on port 8080?

I've identified it to be Apache Tomcat via nmap, but I'm stuck on what flags I need to set to pull up the version number

#

Tried things like
-A
--version-all
--script=http-apache-server-status

#

Also visited the site directly on the browser, got the version on the 404 page as 9.0.31, but that doesn't seem to be the correct answer

calm gull
#

What does % mean in

Rpcclient -U’%’ 10.10.110.17

?

tranquil lichen
low mica
# lethal atlas are you working on `Capture the NTDS.dit file and dump the hashes. Use the tec...

im working on the part" On an engagement you have gone on several social media sites and found the Inlanefreight employee names: John Marston IT Director, Carol Johnson Financial Controller and Jennifer Stapleton Logistics Manager. You decide to use these names to conduct your password attacks against the target domain controller. Submit John Marston's credentials as the answer. (Format: username:password, Case-Sensitive)" "attacking the active directory and NTDS.dit" of the "password attacks " modules

low mica
fathom pendant
#

probably :) username-anarchy will generate a list of usernames based off of what you give it; that is what can be used to get the info :)

low mica
fathom pendant
thorn urchin
low mica
#

were you the one who helped with a previous module?

thorn urchin
#

maybe?

#

I just clicked back to find your original question only to discover I had already answered it and you never replied lol

low mica
#

still didnt work

thorn urchin
#

winrm builtin upload?

low mica
#

yes

#

evil-winrm command

#

from the man

thorn urchin
#
  1. need to use download 2. did you specify full paths for both the source file AND destination?
#

or no, maybe upload is still correct idr

#

either way the path thing is key

#

Ive seen pro pentesters trip on that cause its dumb

low mica
#

this is how i used it

thorn urchin
#

yeah thats not correct

simple zephyr
#

before i recreate the wheel does anyone know a way to automate the section for bypasspassing blacklisted commands? can this be done in burp at all? If not I am thinking of writing a pythonscript to do it for me.

thorn urchin
#

for winrm you dont need to use a share

#

you just specify the full local path

#

also stop trying to run sudo on a windows computer lol

low mica
thorn urchin
#

Thats why I mention it

low mica
#

this is why i tried to use it

thorn urchin
#

you use the share for using the cmd.exe move command, not for the winrm builtin in, it works differently

low mica
#

so i straight up fileshare and not use this command on the attack machine?

thorn urchin
#

Youd use that command if you wanted to use the cmd route

#

evil-winrm's upload functionality does file transfer using just the winrm protocol.

#

the cmd.exe is using windows UNC path handling feature to treat shares as file system objects instead.

#

totally different mechanisms

#

either can be viable. but mixing is gunna be a bad time lol

low mica
#

like this

thorn urchin
#

no, you should read your error messages closer

#

'upload' is not a valid command. And also like I said you DONT use the share at all when using the win rm file transfer method

#

which is admittedly weird cause it should exist

#

what output do you get if you enter in just 'menu'

low mica
#

you get this

thorn urchin
#

okay so it does have upload and download properly

#

and yes you need to use download, not upload

#

so something like

download C:\NTDS\ntds.dit /home/htb-user-blah-whatever/
low mica
#

it worked this way it seems

thorn urchin
#

hardway but hey if you got the file you got the file

low mica
#

it worked!

#

i appreciate the help man. i really do.

#

i been on this for a week

thorn urchin
#

don't trust winrm saying its successful until youve verified the files actually there

#

Ive seen numerous times where it says successful and its just lied lol

#

Google your specific errors and the tools/commands youre trying to run more and itll take less time in the future

low mica
fathom pendant
# low mica it worked!

The reason the upload portion failed is because there is no c: on Linux, the upload is expecting
upload /path/to/Linux/file c:\windows\path

#

Upload is to upload a file from your attack system to the victim computer

buoyant void
#

Hey guys I'm currently stuck trying to answer the questions in the footprinting module specifically the part about DNS. Anyone in here able to help a brother figure this out

low mica
thorn urchin
#

Good idea πŸ‘

night hawk
thorn urchin
night hawk
#

[-] [('SSL routines', '', 'legacy sigalg disallowed or unsupported')] any ideas?

buoyant void
faint oxide
#

Anymore subdomains to those subdomains…/

buoyant void
#

Thanks that helped me knock out two of the four questions. Still stuck on how to get the FQDN for the inlanefreight.htb domain and for another subdomain

uncut ocean
#

Is there anyone I need to ask something

buoyant void
# thorn urchin https://dontasktoask.com

Just wanted to say this really opened my eyes to way I tend to ask questions and how they may be perceived. So I apologize for all the times I've ever done this in any server and will definitely consider this going forward

thorn urchin
iron plaza
#

Guys I am the last question of the Linux Privilege Escalation Module and I am trying to find FLAG5 but what I understood is I need to upgrade my reverse shell for the user ||tomcat||, however using|| python -c β€˜import pty;pty.spawn(β€œ/bin/bash”)’|| does not do anything. Any hint on how to solve it?

fathom pendant
fathom pendant
# low mica like that?

Yes, just read the error and you'll see why it failed, not that you did anything fully incorrect

fathom pendant
buoyant void
#

Yeah I figured it out a few minutes ago, the answer was simple I had it all along just didn't know I was looking at it

thorn urchin
#

happens to the best of us

buoyant void
#

Yeah it's frustrating but on the bright side I was on the right track the whole time so gives me confidence that I understood the module

weary pasture
#

honestly i need a mentor...

iron plaza
pale galleon
#

Did you end up cracking this hash?

fresh reef
#

Module:AD Enumeration & Attacks - Skills Assessment Part I
Im stuck due to this error

New-Object : Cannot find type [System.IdentityModel.Tokens.KerberosRequestorSecurityToken]: verify that the assembly 
containing this type is loaded.
At line:1 char:1
+ New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken ...

    + CategoryInfo          : InvalidType: (:) [New-Object], PSArgumentException
    + FullyQualifiedErrorId : TypeNotFound,Microsoft.PowerShell.Commands.NewObjectCommand

Any insight?

#

Prior to this i did add the relevant type via PS> Add-Type -AssemblyName System.IdentityModel

fathom pendant
fresh reef
#

I tried, but MEE6 hates me

#

lol

fathom pendant
#

Ah

#

Probably BC you're not verified

#

It likes doing that

#

As it can be seen as "spammy" behavior

fresh reef
#

Ahh i see

fathom pendant
fresh reef
#

and ive spend a couple hours trying to remidiate it

#

I get no error when adding the System.IdentityModel assembly

#

but still get the error that subsequent object cant be created due to it been invalid...but it shouldn't be

#

lol and powerview throws errors as well

#

And ...not gonna lie compiling Rubeus flew over my head(tbh)

fathom pendant
#

haven't finished ad enum yet, sorry

fresh reef
#

Npnp , I think i've got an idea :3

#

Rip nvm Sharpview wont run either @.@

buoyant escarp
#

Dm me if you wanna hear more

shadow canopy
#

Check proxy history

#

try browsing and clicking stuff on the website then see if any api requests happen in the background. They will be in history. If you stuck dm

fresh reef
fresh reef
low vine
#

question more on note taking / keeping. When keeping track of potential injection points when walking a web application is there any sort of tool we might user or do we just have to write them all down?

dim hound
tropic radish
#

Someone can help me to understand something on Server-Side Attack in SSRF exploitation example?

tropic radish
# tribal plume What's the question.

I don't really understand why I'm not able to reach file local file's through the port 80 and I am able using the internal.app.local. I mean, isn't the webserv running on the local machine? I'm not sure if my question is clear

tribal plume
vale crescent
#

Hey I'm new to hack the box is there any tutorials about networking and Linux before doing any ctf

tribal plume
tropic radish
vale crescent
tribal plume
modest chasm
#

hi guys

still edge
#

Hi guys i'm wondering if someone can help me. i'm in the module about network enumeration with nmap.

sudo nmap 10.129.2.0/24 -sn -oA tnet | grep for | cut -d" " -f5 this command should show the host that is up. so i tried it in my kali on my network(i use my subnet address). ( Kali is in a vm in nat mode) when i do it i receive all the range has host is up when there might be 4 or 5 host that exist

#

i'm trying in bridge mode just to see if it make a difference

tropic radish
still edge
#

i'm guessing it's my firewall that send reset-ttl

sick warren
#

im in AD Enumeration & Attacks - Skills Assessment Part I
Can someone tell me how to pivot from an interface to another manually or using tool away from metasploit? i tried chisel socks + proxychains but seems there's somthing broken

autumn pilot
#

ligolo

analog urchin
#

Hey Guys! When you enroll to a job-path, is it the way the modules are organized on the dashboard the recommended way to study them? Or should I read them before hand to know which one is better to follow up next? (Because maybe there's a module that's related to another one... etc)

hasty solar
#

Hi, Im stuck in Password Reuse / Default Passwords from PASSWORD ATTACKS, I ssh in utilizing ||sam||, then I proceed with port forwarding the port ||3306||, and start bruteforce in ||localhost:3306||, I tried 12252 combinations and found nothing, what should I try next? Thanks for the help

autumn pilot
#

please remove the password

hasty solar
#

ok

balmy lion
#

hey all, any hints for the following question, please?

Module: Password attacks
Section: Cred hunting in Linux
Question: Examine the target and find out the password of the user Will..

I've used the hint and mutated the password found in there, tried bruting it with hydra through ssh with the provided custom rule mutated list, but no luck, also tried other hashcat rules

autumn pilot
#

usually you are on the right track, however, you must check if your mutated password is anything around the one given in the hint

torpid crest
#

Attack Common Applications - Other Notable Applications

Somewhat stuck and looking for a little nudge.
I have the application we need to exploit and an RCE Exploit from ExploitDB. Was able to get it to run but my connection keeps closing after launching the exploit not sure if I am missing something or not. Thanks!

autumn pilot
#

I guess you have found the app on the unusual port?

torpid crest
autumn pilot
#

try using some verbosity to see why is that

#

double-check your lhost and lport and etc

quasi tree
#

could someone hack someone for me, he is a pedo that posted a link to chld prn and i want all his online shto be taken down meaning his gmail logins everything. here is his user Jetbump67890#9696

autumn pilot
#

reach out to discord themselves

#

we cannot do anything

quasi tree
#

please help, this pedo deservses to go to prison

#

how could discord hack their googleaccount all they can do is ban their discord

autumn pilot
#

out of the scope of this server

quasi tree
#

what?

autumn pilot
#

again, reach out to the appropriate authorities

torpid crest
# autumn pilot double-check your lhost and lport and etc

Lhost and Lport are good, and same with remote host. When running the exploit I see it context to the first listener but then it goes to sending return with payload then all I get is closing connection. This is ran outside Metasploit

autumn pilot
#

not sure, double check if that is the exploit you have to use

vital adder
#

@quasi tree everyone can say everyone is a pedo plus this discord is for a cyber security learning platforms not a hacker forum so if you keep asking for thing like that you will get the πŸ‘’ from pwning and if that guy is a pedo just report it and if it's valid they will report it to the right authorities

autumn pilot
#

the exploit I used worked from the first try

torpid crest
tiny ledge
#

Holy shit, finally beat Session Security - Skills assessment, that was a real tough one, had to do it twice too lol

pseudo ledge
#

LOGIN BRUTE FORCING -Skills Assessment website
been stuck on the second question, pretty sure I wrote the right command but it's taking too long, can anyone help please?
||hydra -l user -P /usr/share/wordlists/rockyou.txt 161.35.33.20 -s 30764 http-post-form "/admin_login.php:user=^USER^&pass=^PASS^:F=<title>Admin Panel - Login"|| - this is the command I'm using

autumn pilot
#

what makes you sure that this is the user

pseudo ledge
#

the hint

autumn pilot
#

also what makes you be sure that the field, e.g. string will change upon log in

pseudo ledge
#

well I'm not sure about that

autumn pilot
#

if you are not, try something else that could stick out even more

pseudo ledge
#

you think I should change it?

#

ok

jaunty vigil
#

hey! need some help with a module

#

im local admin

#

not the administrator

#

but part of the administrators group

#

and trying to access C:\Users\Administrator

#

but getting access denied

#

am i missing something here?

autumn pilot
#

maybe log out and log back in?

jaunty vigil
#

I am netadm

#

logged out and back in

#

nothing sadly

#

I lied, I was "disconnecting" and reconnecting

low vine
jaunty vigil
#

manually clicking the sign out button is what i needed to do

#

figured disconnecting did the same

jaunty vigil
#

Ok then side question, does the same apply for domain admin?

dim hound
jaunty vigil
#

if a user is a domain admin do they get to access any machines administrator directory and function essentially as a local administrator

autumn pilot
#

DA is better than local admin, it is like the cherry on the top

low vine
#

is all just trying to figure it out

jaunty vigil
#

second question: the module was the dll loading through the dns service. I loaded a cmd that added me to local admin and domain admin. that worked like a charm. However, I tried to run reverse shell dll and that failed, any reason why?

autumn pilot
#

any DA has administrative control over the domain, e.g. everything in it if there isn't any configuration/policies that can limit it

jaunty vigil
#

makes sense!

autumn pilot
#

the process is not stable

jaunty vigil
#

ok great! thanks!

#

nearly done with this ctps path

#

getting nervous lol

autumn pilot
#

use john

#

you might need to specify an additional option(flag) to tell john what this block of data is

deft escarp
#

Per the instructions for the footprinting module labs, am I allows to exploit the hard box? The following snippet is from the description of the easy box and the same idea of not exploitating isn't in the description of the medium or hard boxes. I'm confused if the same no exploitation rule applies:

||We were commissioned by the company Inlanefreight Ltd to test three different servers in their internal network. The company uses many different services, and the IT security department felt that a penetration test was necessary to gain insight into their overall security posture.

The first server is an internal DNS server that needs to be investigated. In particular, our client wants to know what information we can get out of these services and how this information could be used against its infrastructure. Our goal is to gather as much information as possible about the server and find ways to use that information against the company. However, our client has made it clear that it is forbidden to attack the services aggressively using exploits, as these services are in production.||

jaunty vigil
zenith gazelle
#

Hi guys, i have one question, when using the command ffuf how i filtered to just show me request size <some number?

#

@jaunty vigil nice photo profile

autumn pilot
#

-fs

jaunty vigil
zenith gazelle
silk glade
#

Hi guys,i can not do last exercise on Footprinting IMAP/POP3 section. I have accessed email on DEV.DEPARTMENT.INT but do not see any flag there. Can someone give me hint? I used robin account. I am thinking maybe i need to find devadmin pass?

grand prairie
#

#Introduction to Windows Command Line
#Skills Assessement
#Question 10
hey, i'am a little lost. Question 10 asks me to connect to the domain controller. How do I connect to the so that I can read the log file? Can anyone help me pls with this question?

slim fern
#

How can i become a hacker

silver zenith
#

I guess hack something

acoustic owl
acoustic owl
grand prairie
silk glade
#

pls someone help me too for IMAP/POP3

acoustic owl
analog tendon
#

if anyone is available i need some assistance in the passwords hard lab. i got the backup file and was able to grab the password for it. but i dont know how to mount it properly to take a look through it

#

wait hold up. i may have a way. i didnt realize i can do a gpart scan on it maybe i can dislocker it too

#

nvm gpart didnt give me any useful info

thorn urchin
analog tendon
#

yes

#

the share is mounted. i have a copy of the vhd of course and i used john to crack the bitlocker

thorn urchin
#

the module recommends just transferring to a windows machine to natively mount it. Otherwise youre kinda on your own for figuring out how to mount it. Theres some mount extensions you can install to get it working in linux but that's gunna require googling and old fashioned computer know-how problem solving.