#modules

1 messages · Page 62 of 1

obtuse summit
#

can someone help me

hallow trail
#

what happens when u type the address in?

tiny ledge
#

Can someone assist with: WEB SERVICE & API ATTACKS - Question: Identify the username of the user that has a position of 736373 through SQLi. | I have located the vulnerable parameter and SQLi using SQLmap, but I don't understand how to get the info for the position with this knowledge.

frigid ingot
#

Anyone available for a nudge on metasploit module?

rustic sage
#

Hello
Please am new to crypto
I wanna invest but don't know how and where
I think I need assistance
am I in the right place to find a good crypto trader??

autumn pilot
#

No

native hound
#

hi anyone knows how to encode the decoded cookie?

autumn pilot
#

depends if you know how it was encoded

#

you can reverse it and decode it

native hound
native hound
#

how do you recode back?

#

and send to request?

tidal kelp
#

section Documentation & Reporting Skills Assessment, I have creds of user ||dhawkins||, ping sweep i have 4 hosts. Using crackmapexe for checking but get nothing, can anyone help me out? thanks

verbal galleon
#

Try —local-auth

tidal kelp
autumn pilot
#

it's more simpler than you think

#

don't unnecessarily over complicate things, use what you have and build on top of it

verbal galleon
tidal kelp
verbal galleon
#

sure np

void gate
#

I just hit this same problem, This post was very helpful with finding a solution #modules message

tidal kelp
verbal galleon
#

you're welcome

turbid tartan
#

attack common services easy lab i dont get how to execute webshell

rustic sage
#

hellou

#

im trying to install hcxtools but doesnt work

#

somebody can help?

native hound
#

anyone knows how after decoding and modifying?

solar granite
#

Yes, if you still need help

low vine
#

Need a nudge on SQLMap - Bypassing Web App Protections - Case #10

#

[CRITICAL] an error occurred while evaluating provided code ('TypeError: Strings must be encoded before hashing')

#

Tried a couple of other things and its not quite clear if this is the path forward, missing some understanding and would like a nudge if possible

sacred ermine
#

did you manage to solve? I am stuck also exactly where you are

autumn pilot
#

show me your command

#

the command that you have typed into your shell

fading ridge
#

Anybody that did the module server attacks?

autumn pilot
#

try adding single quotes around the password

#

or remove it and type it in once you are asked

opaque niche
opaque niche
low vine
#

Any understanding on why this does not run or work I'm so confused

storm jackal
low vine
#

yup just reset it

storm jackal
#

hmm

low vine
#

and redid all the steps to recreate new file etc

verbal galleon
#

Try sudo

sacred ermine
#

guys I need help for skills assesment port forwarding
I stuck here: Use the information you gathered to pivot to the discovered host. Submit the contents of C:\Flag.txt as the answer.
I have no clue what to do next
feels like stuck for eternity

#

I found creds have access to w*** the pivot is 172.*

opaque niche
sacred ermine
#

I am about to try it with chisel I guess that one will work, cuz in of the sections I have done it using chisel

sacred ermine
north creek
#

hey, actually stuck in Navigator (linux fundamentals), with the question about inode number of sudoers. tried cd /etc, ls -i sudoers it gave me 964110 but that's wrong. Any help? This is not the first time the question was asked, but there's no answer

autumn pilot
#

make sure you have connected to the target

north creek
#

I am

#

i restarted the vpn + the box, still '964110'

proud pine
#

I haven't done the module, but your prompt looks like the pwnbox prompt. Are you supposed to connect to a box first?

autumn pilot
#

you are not connected

#

to the target

#

target != pwnbox

north creek
north creek
#

i'll try by ssh

opaque niche
#

Hello, I'm stuck in Skils assessments on pivoting, tunneling and port forwarding, I found the credentials of v--- as well as the ip address 172.16.6.*, the point is that when I connect remotely from m---, I have the same folders as m--- as well as the network settings, any idea how to proceed?

sacred ermine
opaque niche
sacred ermine
#

thanks

#

I thought I have to transfer the file .dat and it appears that it "does not" exist when I try dir in cmd

livid bluff
#

Hi,
I'm stuck on Attacking Common Services - Easy
I am connected to the database. I try to launch a reverse shell but it does not work.

I don't understand, especially if I write a test file and I want to open it on my browser I can't find it.
If I make a request to read the file from the DB it finds the file.

I write it in C:\xampp\htdocs\ which is normally the right place.

low vine
#

Still having the same problems with SQLMap

#

Any help would be appreciated

north creek
opaque niche
hazy grotto
grand spoke
#

mhm

rustic sage
brave palm
#

Password Attacks - Hard Lab : hi guys, does anyone know how to move the || logins.kdbx || to attacker machine? tried via ||smbserver|| but windows blocks the connection

lone pendant
#

I can not seem to connect to this IP

#

I can not connect with SSH

rustic sage
rustic sage
rustic sage
lone pendant
rustic sage
brave palm
lone pendant
rustic sage
analog tendon
#

wow. the medium lab for the attacking common services is WAY easier than the "easy" lab. lol geez

brave palm
low vine
low vine
rustic sage
brave palm
# rustic sage try ||impacket-smbserver ||

||You can't access this shared folder because your organization's security policies block unauthenticated guest access. These policies help protect your PC from unsafe or malicious devices on the network.||

#

this is from my windows cmd

sonic ferry
#

I keep getting stuck on pretty much every module at least a few times because the target IP stops responding. I've taken up a habit of just resetting the target a few times whenever I feel like I'm not progressing (and usually that was the problem). It's getting a bit irritated to not know whether I'm doing something wrong or if the target is down. Is there a fix for this?

brave palm
# rustic sage okay yes

tried looking around if there was something to turn off but can't do much without admin rights

rustic sage
brave palm
#

😮

#

thanks, will try it rn

rustic sage
#

if you haven't done the File Transfer module, I'd highly recommend it

brave palm
#

i did that

#

but forgot this part hahah damn too much stuff

rustic sage
#

good notes are important!

#

not only will it help you with the CPTS exam (which I'm assuming you're on), but once you're done you basically have a cheatsheet/playbook for future assessments

brave palm
#

ty

rustic sage
#

imo I'd build you own notes and use the cheatsheets as a secondary resource

brave palm
rustic sage
lone pendant
#

nevermind now it is working

#

so odd

livid bluff
analog tendon
brave palm
#

(btw yeah, file transfer worked, ty again)

low vine
wintry lark
#

Hey, i am trying "Nibbles - Initial Foothold". Everytime i try to upload a file with the plugin My Image it ends with this The connection was reset

The connection to the server was reset while the page was loading.

The site could be temporarily unavailable or too busy. Try again in a few moments.
If you are unable to load any pages, check your computer’s network connection.
If your computer or network is protected by a firewall or proxy, make sure that Firefox is permitted to access the Web.. The VPN is still running.
livid bluff
devout torrent
#

Anybody tried Credential Hunting in Linux lately, my box crashes after like 2 minutes of hydra which is mighty annoying

analog tendon
livid bluff
rustic sage
# low vine

weird... I haven't done the SQLMap module yet, but I just tested the command and it works for me. Valid HTTP request in the file (which would be a different error, but worth a try)?

low vine
#

yea I can copy as curl and send

#

and it works

#

but I cannot save to file then call it its so weird

rustic sage
#

try copy and pasting it to a different file and try that

analog tendon
low vine
#

Yea just did

rustic sage
#

mhmmm I'm not sure then

low vine
#

Yea its been stumping me, + question has stumped me for like 4 hours now

#

lol

#

hurting my brain

#

Need to get this figured out before I take the test 😦

unborn finch
#

I need help in Web Proxies module > Skill assessment > Intercepting Response question
I'm doing what exactly need to do but didn’t get the flag !! Changed disabled to enable and forward the request from Burp > turn interception off in burp and click get the flag button
This is the page source after modifying HTML code

It does says enable but not showing me flag
what am I missing ?

#

I'm sorry I'm sharing in multiple channel but I see more people are active here

rustic sage
low vine
#

Yea ill switch to pwn box , prob works perfect there lol

rustic sage
livid bluff
low vine
#

Yea I full updated , its an arch repo

#

I thought maybe i fucked up something and went clean install as wsell

#

Ill get it figured out eventually or keep crying lol

analog tendon
#

i cant remember if i did http or https

proud pine
low vine
#

@proud pine yes i've done fujll path as well

analog tendon
#

lol way to put a damper on my hopes that the hard lab would be the easiest one because they got them backwards

livid bluff
rustic sage
analog tendon
proud pine
analog tendon
rustic sage
analog tendon
#

well im not gonna look at your spoilers just yet. im gonna start the enumeration stuff pretty soon though

low vine
#

Full path worked this time...waht ....I dont care

#

it worked LOL ty

worldly jewel
#

So I'm lost on Attacking Common Services - Easy. I've got the full username and after exhausting other paths it seems I need to brute-force the password which goes against what you should do in real life but it's what everyone is saying to do. However, I keep getting locked out from multiple services due to too many password attempts. I'm using the provided password file as well. I could wait for the lockout to end and pick up on the next set of passwords but that seems silly. Any thoughts?

analog tendon
#

also try other popular wordlists as well

worldly jewel
#

cool will give that a try

livid bluff
analog tendon
runic rampart
#

Good evening! Who can give a hint?
Active Directory BloodHound:BloodHound for BlueTeams:Which relationship (edge) do we need to remove to break the path between David and Domain Admins?

worldly jewel
rustic sage
analog tendon
worldly jewel
analog tendon
radiant marten
#

I need some help with SQL map essentials OS exploitation, once I get to the os-shell I can't go anywhere, I've uploaded shell.php to the target but don't "hear" anything on netcat... any help into the right direction of finding the 2nd flag would be greatly appreciated.

tidal lark
#

Hey, i'm stuck here I don't know what else to do with that code the terminal gave me, or maybe im taking the wrong path.

thorn urchin
#

need to deobfuscate the js in api.min.js

tidal lark
thorn urchin
#

personally Id replace the eval with a js print and then run it in a sandbox

tidal lark
#

nothing

#

imma try to look for more ways to get this

thorn urchin
#

sounds like you should read through the section materials again

tidal lark
#

yeah maybe is just because im having a bit of a headache now

#

thanks madf0x

ashen fog
#

Ok. Cant read SRY

fathom pendant
#

I did the same thing don't worry

autumn pilot
#

careful with spoilers pls

desert stump
#

Can someone please help me with the CrackMapExec Module : Skill Assesment
I cannot get a single hit for the correct password during spraying

rustic sage
#

Is there anybody that can help with the hard lab attacking common services?

rustic sage
desert stump
#

Can someone please help me with the CrackMapExec Module : Skill Assesment
I cannot get a single hit for the correct password during spraying

As I have been having so much trouble trying to get a password hit i basically bruteforced the answer to the question first; "What's the password of the account you found? " I've used the correct answer I have for the question to password spray against all accounts I found using --rid-bruteenumeration action.

Ive password sprayed against all hosts within the network without success:
Using these commands:

proxychains4 -q crackmapexec winrm 172.16.15.3 -u users.txt -p Password1
proxychains4 -q crackmapexec ldap dc01.inlanefreight.local -u users.txt -p Password1 // hosts updated
proxychains4 -q crackmapexec smb 172.16.15.3 -u users.txt -p Password1

proxychains4 -q crackmapexec mssql 172.16.15.15 -u users.txt -p Password1 --local-auth
proxychains4 -q crackmapexec mssql 172.16.15.15 -u users.txt -p Password1 -d .
proxychains4 -q crackmapexec mssql 172.16.15.15 -u users.txt -p Password1
proxychains4 -q crackmapexec smb 172.16.15.15 -u users.txt -p Password1
proxychains4 -q crackmapexec winrm 172.16.15.15 -u users.txt -p Password1
proxychains4 -q crackmapexec winrm 172.16.15.15 -u users.txt -p Password1 --local-auth

proxychains4 -q crackmapexec winrm 172.16.15.20 -u users.txt -p Password1 --local-auth
proxychains4 -q crackmapexec winrm 172.16.15.20 -u users.txt -p Password1
proxychains4 -q crackmapexec smb 172.16.15.20 -u users.txt -p Password1
proxychains4 -q crackmapexec smb 172.16.15.20 -u users.txt -p Password1 --local-auth
hazy grotto
#

How did you get the token?

valid nest
#

Can anyone help me on AD Enumeration & Attacks - Skills Assessment Part II Q4. - Use a common method to obtain weak credentials for another user. Submit the username for the user whose credentials you obtain.

I created a username list with two letters and numbers and combined that with valid users on jsmith. I created a small password dictionary file. Sprayed many times but no luck.

thorn urchin
#

try one of the ones they use for examples

valid nest
#

thanks

uncut mirage
#

Hi all,
I'm in the AD Enumeration & Attacks - Skills Assessment Part I, Question 2 Kerberoast an account with the SPN MSSQLSvc/SQL01.inlanefreight.local:1433.
I'm trying to follow section Kerberoasting - from Windows, targeting a single user.
||First adding the System.IdentityModel.

PS> Add-Type -AssemblyName System.IdentityModel

Then perform the Kerberroasting attack:

PS> New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList "MSSQLSvc/SQL01.inlanefreight.local:1433"
New-Object : Cannot find type [System.IdentityModel.Tokens.KerberosRequestorSecurityToken]: verify that the assembly 
containing this type is loaded.
At line:1 char:1
+ New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : InvalidType: (:) [New-Object], PSArgumentException
    + FullyQualifiedErrorId : TypeNotFound,Microsoft.PowerShell.Commands.NewObjectCommand

Problem is I get the error Cannot find type [System.IdentityModel.Tokens.KerberosRequestorSecurityToken]. But shouldn't that have been added by the Add-Type -AssemblyName System.IdentityModel command?

Any suggestions on how to proceed?||

valid nest
uncut mirage
valid nest
#

ahh i missed your question.

hazy grotto
#

Can someone give me a nudge on web attacks skills assessment.Ive got the UID, PHPSESSID, and the token.

steady hawk
hazy grotto
steady hawk
carmine cape
dull thunder
#

is there a trick to reading a file in a smb share that is "read only"

#

ive tried !cat file.txt

#

it says file not found

topaz zenith
#

So im in the Attacking Web Applications with ffuf - Filtering Results. I have added the academy.htb to /etc/hosts/ but when I try to actually access the website nothing. When I run the ffuf -w /SecLists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -u http://academy.htp:30771/ -H 'Host: FUZZ.academy.htb' -fs 900 to even see if admin is a subdomain I get back nothing. Is there something i'm doing wrong?

grim gust
#

can someone help me with question 119 ?

valid nest
rustic sage
#

time for the AD Skill Assessment 😅

valid nest
thorn urchin
#

its the midboss of CPTS for good reason. Easily my fav skill assessment in the course

echo roost
#

Anyone else have this issue when trying to start Nessus?

thorn urchin
#

looks like you dont have the service file on that machine

echo roost
#

I'll reset it see if the next machine has it

#

same issue.... -

#

Something is broken

#

nm, I guess you don't need to start the service it was already started

thorn urchin
#

looks like its lookong for nessus.service but yours is nessusd.service

echo roost
#

oh Duh - still didn't allow me to run start|status|stop commands lol but http://IP:8834 works anyways

faint rampart
#

Please I have a question from the Password Attacks module -

Forging tickets through overpass the hash or pass the key is relevant only when a user's ticket has expired yes? Because I cant really understand why else there would be a need to request a ticket with rubeus using the rc4 hash when you could dump tickets. clearifications would be helpful thank you!

faint rampart
# faint rampart Please I have a question from the Password Attacks module - Forging tickets t...

Also Please, Is it possible to use Rubeus entirely for a Pass the ticket attack? I understand the only way to present a ticket to Rubeus is through Rubeus.exe ptt /ticket:B64_TICKET but the ticket here in question requires you converting a mimikatz exported ticket kirbi file into base64 and using here OR Using Rubeus.exe asktgt /domain:$DOMAIN /user:$USER /rc4:$RC4_HMAC /ptt but then the only way showed in the module to get the RC4_HMAC hash is thru mimikatz. The exercise asks to try practicing with both mimikatz alone and rubeus alone thats why I have these questions, thank you anybody

EDIT : I understand now loool

velvet lily
#

Hello all. I was going through Active Directory LDAP module and i don't know why it doesn't work the answer i am providing to the question **"What is the domain functional level?" ** I am using the tool that basically gives me the response, but then when i am pasting it, it says it is wrong. Can anyone provide some help?

static roost
#

@faint rampart Noob take here. If you can crack the users hash and retrieve a cleartext password, I believe Rubeus can generate RC4 + AES keys.

#

In regards to you previous question, I believe you're using the users hash to acquire a terminal session with that users TGT? It's been a while since I did that module or played around with mimi/rubeus.

faint rampart
faint rampart
static roost
#

Good quetion. I'd say it's because perhaps the user you are looking for doesn't have any tickets stored in memory on that host.

#

So you use rubeus to interact with the KDC, supplying a properly encrypted password in order to get a ticket.

#

Again, I'm super new to this stuff, so don't take my responses as absolute lol

#

But yea, your reasoning makes sense too. I'm not sure how to restore an expired ticket; gotta get a new one.

faint rampart
faint rampart
#

Thank you very much!

static roost
#

@faint rampart sure thing bud

primal silo
thorn urchin
#

not the server for this, get lost

old tangle
#

hello

#

where can i ask a noobish question about gaming hacking?

valid nest
# thorn urchin try one of the ones they use for examples

Thanks for the heads up. My issue was I did not create a comprehensive username dictionary. I simply created a file by changing the numbers without touching the letters. ha!!
This was very interesting because the windows tool does the work for you, which was a great lesson for me.

thorn urchin
#

interesting, thats not the part of it I thought you were doing wrong lol but hey if it works it works

old tangle
#

guys no one answers me?

thorn urchin
#

or rather at least not the channel

old tangle
#

in fact i was asking where could i found someone to ask

thorn urchin
#

this channel is for module discussion and module discussion only

old tangle
#

bro i can't write in that channels

thorn urchin
#

...

old tangle
#

i ve written on this for a reason lol

thorn urchin
#

youre dense

old tangle
#

i'm a newbiewìe

opaque niche
#

just read the rules and welcome

#

lol

thorn urchin
#

if you cant read simple discord channel instructions youre not gunna fair well in your pursuits

#

its not supposed to be this difficult

#

youll get your answers if you do

tight mesa
#

how do I run an exploit that I found using searchsploit? I copied the exploit to my machine, but when I try to use it by typing the file name, it says command not found

thorn urchin
#

often you have to make sure its executable and make sure youre specifying the path, but you absolutely need to read the instructions for it first. Many exploits wont work or worse unless you do what they say which may involve minor modifications

#

sometimes the exploit is just a text file that tells you how to manually do it

tight mesa
thorn urchin
#

you read it

tight mesa
#

the exploit is python code

#

there's no instructions inside of it

thorn urchin
#

read it first, then chmod +x ./47887.py to mark it as executable and then can run it with ./47887.py

tight mesa
#

I did that, but it still says command not found

thorn urchin
#

did you include the path

#

./ if youre in the current working directory

tight mesa
#

same command not found when i did ./

thorn urchin
#

thats more specific here, its having an issue with a line in the code itself

#

youll need to run the appropriate python interpreter for it

#

likely python3 or python2.7

analog tendon
#

so just throwing it out there. they should attempt to explain the syntax a little more for the common services hard lab on abusing the mssql

tight mesa
#

adding python to the beginning worked! thanks @thorn urchin

analog tendon
#

even with research that was a brain exploder

crude vessel
#

Hello, I'm stuck in the skills assessments module (pivoting, tunneling and port forwarding) I currently have the v and m credentials, I have did portforwarded between both machines to access the workstation, but I couldn't due to I have access or timeout problems. Any help please? (I'm stuck on question number 5 btw). Can anyone help me with this please?

glad dock
#

How did you get access because I am dumb as well 😄

sharp steppe
#

sorry

fathom pendant
#

Explore with root

naive sky
#

You are using the 'auxiliary/scanner/http/coldfusion_locale_traversal' tool within Metasploit, but it is not working properly for you. You decide to capture the request sent by Metasploit so you can manually verify it and repeat it. Once you capture the request, what is the 'XXXXX' directory being called in '/XXXXX/administrator/..'?

#

i have done in msfconsole

#

how to find XXXXX and what to do next?

fathom pendant
#

If only there's a way to print the working directory

red current
#

I have a question about the Pass the Hash section in Password Attacks. It shows how julio can access the \dc01\julio directory, but it says nothing about how to access the files within it. I can't find that information anywhere in the lesson. It's like it just skips over that. Does anyone know how that is accomplished?

tardy beacon
#

can someone give a hint on where to find the ldapadmin password for the windows privesc skills assessment task part 1?

red current
#

I figured it out. It helps if you specify the whole path when you use the "more" command.

tardy beacon
red current
#

Sorry, that wasn't meant as a response to your question. I was saying that I answered my own previous question.

tardy beacon
#

ah oh, been stuck on this for a long time, thought that finally someone answered 😆

uncut mirage
#

Hi all,
I'm in the AD Enumeration & Attacks - Skills Assessment Part I, Question 2 Kerberoast an account with the SPN MSSQLSvc/SQL01.inlanefreight.local:1433.
I'm trying to follow section Kerberoasting - from Windows, targeting a single user.
||First adding the System.IdentityModel.

PS> Add-Type -AssemblyName System.IdentityModel

Then perform the Kerberroasting attack:

PS> New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList "MSSQLSvc/SQL01.inlanefreight.local:1433"
New-Object : Cannot find type [System.IdentityModel.Tokens.KerberosRequestorSecurityToken]: verify that the assembly 
containing this type is loaded.
At line:1 char:1
+ New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : InvalidType: (:) [New-Object], PSArgumentException
    + FullyQualifiedErrorId : TypeNotFound,Microsoft.PowerShell.Commands.NewObjectCommand

Problem is I get the error Cannot find type [System.IdentityModel.Tokens.KerberosRequestorSecurityToken]. But shouldn't that have been added by the Add-Type -AssemblyName System.IdentityModel command?

Any suggestions on how to proceed?||

naive sky
uncut mirage
verbal galleon
#

if you have a webshell, you can upload/download files right?

strong heron
#

Hi guys

verbal galleon
#

hello

strong heron
#

How are yall doing?

rustic sage
#

Can someone help me out with broken authentication skill assessment and here is what I know
I know how the cookie works.
|| I know how to find valid users and something to do with country code. ||

verbal galleon
#

fine 🙂 and you

strong heron
#

Good

#

Where are you guys from?

rustic sage
#

I have tried || alpha 2 and 3 code
Ex support.AF and support.AFG and replace . With some other char || but no luck.

uncut mirage
#

And no file appears in the directory

steady light
#

Hey guys, I'm doing password attacks - easy lab and I'm trying to bruteforce ftp with username.list and password.list. It's taking quite a time and I'm scared I'm doing something wrong, but I don't see any other options

acoustic owl
outer jolt
#

Ayy, I am not permitted to send messages #HTB:serious discussions channels, wy tho

#

Do i need to cross a certain level

desert stump
#

Anyone available to help with the CrackMapExec module Skill Assesment?

#

I've tried everything from the course content now and I've had no success

valid nest
# uncut mirage Whenever i upload i get:

So …. There are many files or scripts that you can use to have a reverse shell. I used a powershell script by nishang. Also the web application has some sort of WAF or rules (or it may just dont like certain file extensions) that doesnt allow certain format.

uncut mirage
valid nest
#

That is very interesting. I will try that! Thanks for the info!

wintry lark
rustic sage
#

I just finished Introduction to Academy and Learning Process. Does anyone recommend any tier 0 modules to start off?

desert stump
#

I am having constant trouble with the academy labs. I can't finish a single attack before the target drops offline and i lose access.

glossy cipher
#

Eh question
If I buy the yearly plan
Do I get cubes too?

#

The one with the cpts

rustic sage
#

but if you buy the Silver Annual, you will have access to the entire CPTS path and earn cubes from completing the modules within it.

wintry crown
#

Hello guys, can someone help me about a error i get in the "Soccer" (easy) machine? im following a writeup step for step but im still getting an error i dont know how to debug. please DM me!

rustic sage
glossy cipher
rustic sage
glossy cipher
#

Oh wait if I have a silver monthly sub and I buy the silver annual
Do I keep the silver monthly sub?

#

If that’s the case I can just pay that and slowly do and save up for the tier 3 stuff

rustic sage
glossy cipher
#

Ah
I will buy and test it out kek

#

Thanks man

rustic sage
#

npnpn I will say if you need cubes always buy the monthly plans over the cubes themselves (unless you want/need a module in the moment).

glossy cipher
#

Tbh i was considering the gold monthly for like 2 months and buy the course
But is like cheaper by only abit

rustic sage
#

the student plan is always the best if it's available for you. once I finish though I'll probably get the platinum monthly to knock out some Tier III modules

glossy cipher
#

I can’t get student plan pepehands

#

Welp thx for your help
Time to buy it kek

rustic sage
#

np good luck on whatever you decide!

raw sierra
#

&Xd*Gz5d

wanton sonnet
desert stump
#

Are you on the skill assessment ?

wanton sonnet
#

Yes

desert stump
#

PM'd

turbid tartan
#

attack common services easy lab how do i execute my payload

opaque niche
turbid tartan
#

from https it just downloads the file from http nothing 404

analog tendon
torn blade
#

if anyone has any knowlde on the brocken authetntication wfuzz module please let me know. all responses show 200 and im unsure how to distinguish

autumn pilot
#

djikstra please mask the username since it is a part of a question

worldly jewel
#

That time it takes you hours to do the "easy" module and 5 min to do the "medium" one 🙃

proud pine
#

DM me

simple zephyr
#

Is anyone around that understands Web Attacks - Advanced File Disclosure. I was able to get the flag using CDATA but struggling to get it with Error Based XXE. I want to ensure I understand both methods and not doing something dump.

rustic sage
#

Can someone help me with question 2 of AD Enumeration & Attacks - Skills Assessment Part I? I've tried a few things but haven't made any progress...

valid nest
#

Lol I suffered on this problem as well. Restart worked for me. If you find out why it didn't work at the first time, please let me know.

worldly spire
#

#prolabs-aptlabs

dapper temple
#

Anyone working on FIle Upload Typefilter?

thorny wadi
#

Hey need some help on the Page Fuzzing of Attacking Web Applications with Ffuf. I dont know if the server is broken or im doing something wrong

iron minnow
#

Hello fellows, quick question please ^^ We often face the following situation: Initial windows Host obtained with a reverse shell -> autoroute + socks + proxychains to a 2nd windows host. The question is -> what is your "best" method to upload stuffs (like mimikatz) on the 2nd windows host? I can easily transfer stuff to the first host (dozens of ways), but I struggle to send over to the second host. Oftentimes, there is no python on the first host or ftp server. I can upload nc64.exe on the first host... but no nc on the second 😦 THANKS for your ideas ^^

iron minnow
#

(the transfer module does not precise that that much; often all the tools are available in c:Tools)

thorny wadi
#

with Ctrl+C Ctrl+V 😄

#

or with meterpreter

#

upload fuction

iron minnow
#

so both msfconsole or CTRLC / V can't help

fathom pendant
iron minnow
#

but to wget, you need a webserver on the first host ; which we don't have 😉

fathom pendant
#

But also using the windows remote access tool, in advanced options you can select it to share the files from the system you're using

thorny wadi
#

you can always check the cheat sheet in the file tranfer module

fathom pendant
worldly jewel
#

hey any ideas why I always have to use -Pn with nmap when scanning boxes now? I didn't used to have to do that. I can connect to the boxes and do the exercises just fine.

iron minnow
#

how to transfer files easily between both

fathom pendant
#

Clure

fathom pendant
#

It also helps if you tell us what module you're doing

#

And the section

#

Rather than just saying you are having an issue

iron minnow
#

Maybe my question was not at the right place. it's more "a general matter". But to answer you, I'm doing the first skill assessment in the AD-Enumeration-and-Attacks

fathom pendant
#

You can also mount your files to the Windows system with xfreerdp, try looking at the man page to find that option

fathom pendant
iron minnow
#

So I'm at the question Find cleartext credentials for another domain user. Submit the username as your answer. ; trying to upload pillaging tools on the host I have a shell on through proxychains xfreedp; if someone can help ^^ Thx

thorny wadi
dapper temple
#

For FIle upload Type filters, I can successfully upload the file File successfully uploaded But I'm getting The requested URL was not found on this server. when I try to browse the file after I upload it.

rancid mulch
#

Hi I'm stuck at network enumeration with nmap
Now our client wants to know if it is possible to find out the version of the running services. Identify the version of service our client was talking about and submit the flag as the answer.

Can someone help me with this question please? I'm trying sudo nmap $IP -p50000 -sS -Pn -n --disable-arp-ping --packet-trace --source-port 53 -sV but I don't get back the version

rancid mulch
#

@dapper temple I don't get back anything useful shouldn't it give a flag or something? Not sure which service they are talking about

dapper temple
#

maybe its running on a weird port. so you'd need to run that same command for all ports

flint helm
#

Anyone for Data Movement in Intro To Assembly Language? I add mov rax, [rsp] at the end of the attached code but I get a segmentation fault.

elfin nacelle
#

Hello, currently stuck on the Server-Side Attacks Module, Nginx Reverse Proxy & AJP.

Each time I try to set up the enviroment I got this message:
nginx: [emerg] "location" directive is not allowed here in /etc/nginx/conf/nginx.conf:65
I assume im not setting up the nginx.conf file correctly?

distant tinsel
#

i dont understand how on AD enum and attacks acl primer the answer to "Which ACE entry can be leveraged to perform a targeted Kerberoasting attack?" isnt generic write when in thew same lesson it says. "GenericWrite - gives us the right to write to any non-protected attribute on an object. If we have this access over a user, we could assign them an SPN and perform a Kerberoasting attack (which relies on the target account having a weak password set). Over a group means we could add ourselves or another security principal to a given group. Finally, if we have this access over a computer object, we could perform a resource-based constrained delegation attack which is outside the scope of this module."

thorn urchin
distant tinsel
thorn urchin
distant tinsel
thorn urchin
#

yeah, they use the line of the question verbatim

distant tinsel
#

damn i must be really be blind today ty

thorn urchin
#

np

primal silo
distant tinsel
# thorn urchin np

i give up i reread it 3 times the answer isnt GenericWrite WriteSPN or WriteOwner i then proceeded to try every ace on the page lol

thorn urchin
#

when I say verbatim I mean verbatim

#

you can ctrl-f it

distant tinsel
#

i did it didnt show up lmfao

thorn urchin
#

what exactly did you search for

#

the word targeted only appears twice in the section. Once in the question and once in the answer lol

distant tinsel
#

i tried kerb

thorn urchin
#

well youre not looking for kerb

#

youre looking for targeted kerberoasting

valid nest
thorn urchin
#

its very literal

#

you def dont need bloodhound for this question

#

not even a lab environment for this Q

valid nest
#

Oopps sorry

distant tinsel
#

i didnt capitalize generic all ffs

valid nest
#

I thought it was about the lab.

distant tinsel
#

didnt know the g needed to be capital rip

thorn urchin
#

lol

distant tinsel
#

and i assumed it needed to be more specifically about kerberoasting not less

dapper temple
#

Anyone know where I'm going wrong with this output? (File upload exercises)
||The image “http://1$IP:$PORT/profile_images/text..phar.jpg” cannot be displayed because it contains errors.||

thorn urchin
#

whats your payload

quick cairn
#

Hi, I'm in Password Attacks Lab - Medium, and I got the d** user information and the ssh file. What do I do next?

dapper temple
dim hound
#

I use that, inside burp Intruder

thorn urchin
dapper temple
#

the content is getting more obscure. I mean I knew something was funky with that filename because it was returning that error. I had to loop through running curl trying to find a commonality. It got my brain going in circles either doing nearly the same thing, expecting a different result

thorn urchin
#

I used ffuf and just fuzzed everything in that module

#

made it 10x easier

thorny wadi
#

anyone that has done Login Brute Forcing that i can DM with some doubts?

#

this web modules are driving me completly nuts, the machines are very unstable to me. totally slowing me down. Am I the only one? This did not happen at all with the previous ones

simple zephyr
#

Web Attacks Skill Assessment - was a fun one and wasn't as bad as I thought it would be. Almost got stuck and had to ask but pulled through.

primal silo
hazy grotto
#

You get this?

atomic ruin
#

that moment when you waste 90min trying shit before you realise you just skipped the bit of text that hints at where to get the foothold so that you don't have to do that 🥲

simple zephyr
lost gyro
#

Module: Attack Common Service / SQL

I can login to BD with the htbdbuser credentials but I can’t do anything inside the DB. Please give me some ideas! Thanks!

summer flame
#

Hi, how do I scan 172.16.6.x?

fathom pendant
#

you either need to be on the first host; or use the first host as a proxy-host

summer flame
#

@fathom pendant Thanks. Should I be expecting to scan a Workstation and DC from that? because I was not able to scan anything from 172.16.6.x, not sure if there is anything I miss out

fathom pendant
#

Google what a Ping sweep is and how to do it within Powershell or CMD if your first host is Windows, terminal if Linux

frosty dock
#

hey guys I am a beginner here, having a bit of trouble on the very last section of the Getting Started module. Its called 'knowledge check' and I've been at it for a while now. I've taken detailed notes of the info gained on the target box, and tried to follow the procedures taught throughout the module, and have managed to gain access to the website on port 80 as admin. I think I'm supposed to be able to gain reverse shell access to the webserver with my admin privileges, but I'm having trouble. ): there are 2 plugins installed but I don't think I can reconfigure them. Am I supposed to download a 3rd plugin that would give me reverse shell access? Or am I going down the wrong rabbit hole..? I'm lost!

#

hope I posted this question in the right place. thanks in advance

fathom pendant
#

no need to download a plugin. See what you can do with your current access

frosty dock
grand harbor
#

Who is willing me to help with active subdomain enumeration? Becouse i cant figure it out

raven swallow
#

Ok so I just wanted to checkout the academy and see what was there. I just opened linux fundamentals. And they want me to give the command to start a http server using php

#

Now I know how to do that.

#

And I even verified it on my own box for a sanity check.

grand harbor
#

lmfao

#

bro my sanity has already dropped with 60% with doing this stupid task

raven swallow
#

@grand harbor Yeah what about sub?

#

Yeah pisses me off

grand harbor
#

well so i have to find sub domains

raven swallow
#

ENDLESSLY

#

Ok

grand harbor
#

so i use the commands i learned in the modules

#

and i just doesnt work

raven swallow
#

what tool are they using?

grand harbor
#

nslookup

#

🤮

raven swallow
#

wait

#

what

grand harbor
raven swallow
#

You can use dig

#

That an option if you dont wanna fuzz

raven swallow
#

So this is your box?

#

Right

#

The kali

grand harbor
#

ye

raven swallow
#

hosts

grand harbor
#

i found the nameserver with dig

raven swallow
#

Add to your host file

grand harbor
#

the name server?

acoustic owl
# grand harbor

I think you are asking the wrong resolver.
You have to specify the resolver 😉
Take the IP of your target

grand harbor
#

yes thats what i did with dig

#

i did dig ns <target> @rustic sage

acoustic owl
#

htb is not a valid top level domain.
It can only be used internally.

raven swallow
#

add it to /etc/hosts

grand harbor
#

The name server?

raven swallow
#

ip and server

grand harbor
#

becouse it says that the namserver is 127.0.0.1

#

ant thats me

raven swallow
#

It will ask you

#

Since htb is not a toplevel domain as bunny pointed out

#

But it will resolve if you add it to the hostfile

grand harbor
#

yes its internal right

grand harbor
#

becouse theyy mention it in the previous tasks

raven swallow
#

Either way, it's too buggy

#
Press Ctrl-C to quit.
#

Just started the frakking http server

#

Still the answer is wron

#

fun

grand harbor
#

hahaha

#

your sanity is getting hard checked in the academy

verbal galleon
grand harbor
raven swallow
#

wow, I feel the rage

#

I mean you could normally argue that I dont know what I'm doing

grand harbor
#

btw

#

i completed the questions

raven swallow
#

and?

#

You just had to add it to the host and dig?

#

When it comes to subdomain enum further down the line. Use amass, learn it from the start

#

ffuf is also good since it's written in GO and thats some nice network speed

grand harbor
#

not even

#

just zone transferd a internal dns

raven swallow
#

ohh

#

kek

grand harbor
#

was so ez but nothing to do

#

with the instructions i red

raven swallow
#

So wait. They wanted you to make a zonetransfear

#

How far are you in this module that I assume is called DNS

#

You have several types of transfears as well.

grand harbor
#

where the hell do i find vhost list in seclists

raven swallow
#

Yeah I'm going back to my box

turbid tartan
#

how do i make a space in a url webshell

raven swallow
#

%25 i think

#

%20

#

sorry

#

non braking space is %C2%A0

coarse lichen
#

Hello, I have a question about something in the Introduction to Active Directory module,
in the AD Administration: Guided Lab Part I section, and in the Task 3: Manage Group Policy Objects.

We are asked to duplicate a GPO, modify some user and computer settings, and then link it to an OU which only contains user objects.
I know this task might have for goal only to practice and navigate in the GPOs settings, but isn't it strange to modify and enable computer settings even though there is no computer objects in the OU ? Since because of that the computer settings won't be applied.
Wouldn't it confuse people ? Or am I completly mistaken about how GPOs work ?
Thanks for the answer.

grand harbor
cinder mortar
#

Need help on attacking lsass under password attacks, im unable to transfer the file to my attack machine

subtle glen
grand harbor
#

Ye got it thanks

spiral pelican
#

Hi
I need help on the module Stack-Based Buffer Overflows on Windows x86 -> skill assessment part.
i found the offset 4**, check for bad char (found 3 chars), and get a jmp esp addr in funcs.dll (0x62******).
But its not working, the program crash but nothing happen... i am completly stuck and can't find what i missing out.
Please help 🙂 thanks

#

*offset : 4xx

lament gull
#

Hey all. I have a scope question:

Going through the Server-Side attacks module. NOT LOOKING FOR SPOILERS. I'm on the final assessment and for the target, they give you a url in the format of <IP>:<PORT> to attack. Is it safe to assume that the scope of this engagement is limited to that port for initial recon or would we be allowed to run an NMAP scan on all the ports for that IP?

UPDATE 50 minutes later:
Figured it out. I was totally overthinking it. This was an easy one if you just walk the app manually looking at everything in Burp and go from there.

devout torrent
chilly forge
#

Hello, for the module Cross Side Scripting (XSS) - Session Hijacking: The module itself sets a php listener on 0.0.0.0:80, which is already in use for my pwnbox. Let's say I wanted to change the listener to 8080 for instance, which is free, how would the XSS command change?|| <script src="http://myIP:PORT/username"></script>|| for instance? Can someone give me a hint?

fossil thicket
primal silo
#

i need help with broken authentication skill assessment

#

lmk if can dm some1

fossil thicket
#

Just say it here

primal silo
#

i couldn't find any admin users

#

and I don't know if admin user exists..

#

what to do next

#

i narrowed it down from rockyou using grep and regex

fossil thicket
primal silo
#

yep i got many correct user names

#

like admin, finance, support

fossil thicket
primal silo
#

with .cn .gr. .it .us .uk

#

i tried to brute force them with wordslist

#

i narrowed it down from rockyou using grep and regex

#

but i can only find passwords for 2 users

#

i narrowed down passwords words list to 40 lines

#

and sprayed those passwords with valid users

#

only got 2 users with valid credentials

#

im doing something wrong here but i don't know what

fossil thicket
brazen apex
#

I'm going crazy could I get some advice on Module Footprinting section FTP what should I try when I recieve "try being more creative"

fossil thicket
brazen apex
#

I'm using some serious scans here and still getting nothing

primal silo
primal silo
#

came down to md5 hashes

fossil thicket
primal silo
#

i changed support to admin and used that cookie but it says user cant have requested role

brazen apex
# fossil thicket Like what

OSCP automated scan gives

  • All cve vulns
  • UDP & TCP
  • Services and version
  • Directories
  • Service users and suggested logins
#

still cant enumerate the FTP banner

#

I got the flag for the FTP user already

fossil thicket
#

That should be more than enough

brazen apex
#

Still isn't :/

brazen apex
#

Yeah

#

But the question is " Submit the entire banner as the answer."

#

I dont have the whole banner

#

I might move on this seems like a waste o time

fossil thicket
primal silo
#

you solved the skill assessment right

#

point me in the right direction

#

i dont mind spoilers

fossil thicket
#

I’m just helping you based on my knowledge

primal silo
#

oh okay

fossil thicket
#

Did you find any cves on the website

brazen apex
fossil thicket
brazen apex
#

theres a cve scripts on nse

fossil thicket
brazen apex
#

I just like to finish the modules as I go instead of going back to them

brazen apex
#

I prefer to anyways

fossil thicket
#

@primal silo

fossil thicket
#

But I can’t remember what rn

leaden quail
#

Hey Guys, will I still have access to the modules I have completed after I cancel my membership?

brazen apex
#

Module Footprinting Section SMB: Hey is CIFS only for Samba or can it be used on all SMB servers?

brazen apex
past garden
#

Hi, I need a hint on how to phrase the answer in Command Injection " Try all other injection operators to see if any of them is not blacklisted. Which of (new-line, &, |) is not blacklisted by the web application?". I tried all injection operators url encoded and not encode and found a few working ones. If I just put them without any separator in the answer, it doesn't work

primal silo
#

can 1 dm sm1 i need help with broken authentication module

uncut mirage
#

I've been hard stuck on module Active Directory Enumeration & Attacks, AD Enumeration & Attacks - Skills Assessment Part I, Question 6 Submit this user's cleartext password for hours.
||I also posted about this problem yesterday and was hinted to use Mimikatz.exe. Problem is I still can't find the password. The forums also point in the direction of using Mimikatz.exe. I even opened my first ever ticket with HTB because I believed there where a bug in the lab, but they confirmed there are no bug and I need to do something else.
Please help, at this point I just want to know how to find it so I can find out what I keep doing wrong.||

grand harbor
#

Anyone that can help me with this Nessus excersise

#

nessus*

brazen apex
#

Is there a specific place that shares/files go once you "get" them from an SMB share?

#

it was a directory my bad

tight mesa
#

I'm stuck on the linux privilege escalation module- credential hunting. I've obtained root user, yet I still can't find the wp-config.php file. I've used the command find, but it says no file or directory found. Can I have a pointer in the right direction on how I can find wp-config.php?

grand harbor
tight mesa
spiral pelican
#

Hi
I need help on the module Stack-Based Buffer Overflows on Windows x86 -> skill assessment part.
i found the offset 4XX, check for bad char (found 3 chars), and get a jmp esp addr in funcs.dll (0x62XXXXXX).
But its not working, the program crash but nothing happen... i am completly stuck and can't find what i missing out.
Please help 🙂 thanks

vital adder
grand harbor
red current
#

I'm running into an issue on the last question in the Pass the Hash (PtH) section of Password Attacks. I've followed the hints provided in the forum for this section and I still can't seem to get the reverse shell to work. I've got my listener running and I'm using the correct IP address of 172.16.1.10 in the revshells.com site to build the reverse shell. I get the response of command executed with process ID 3084 on DC01 but nothing appears in my listener. Any ideas what I'm doing wrong here?

arctic acorn
red current
#

I figured out my mistake with some help. The revshell should have the IP as your listener. Also, make sure to copy and paste the result from the revshell site instead of copying and pasting the example in the lesson. It turns out that they're different.

undone narwhal
#

Can any one help me with pivoting module assessment im stuck at loggin into dc

red current
#

I'm on the next session now. Pass the Ticket (PtT) for Windows and I'm not able to remote into the target using the provided credentials? Has anyone else seen that before?

#

I tried xfreerdp, evil-winrm and impacket. Nothing works to gain access to the target with the credentials provided.

analog urchin
#

Hey team @carmine kiln @winged hedge - Currently doing the 'getting started' module of pentesting, on the 'Public Exploits' session. And the exercise I have to do with the target machine says "(server may take a few seconds to start)". But I have started two of them so far and still cant get it

The first step of the exercise is that I have to identify the services running on the server (and on their ports) - but I can't even get a ping response from the IP, nor my nmaps are working against it because the server "seems down". I don't know if I am doing something wrong or if it has to do completely with the disclaimer shown before.

(I tagged the mods cause I thought that's the way to go, but if anybody else reading this has some input I would appreciate it)

thorny wadi
analog urchin
thorny wadi
#

restart the target machine and try again

#

wait 3 minutes after it starts befora interacting with it

#

how go it get the"Academy User" role here 😄 ?

#

how do i get *

dusty timber
thorny wadi
#

look like i did

#

but i dont know why xD

#

just appeared xD

dusty timber
#

I think its if you get a paid subscription

#

I only got cubes so I dont have it

red current
#

I had some help figuring out my issue with RDP'ing into the windows box in the pass the ticket for windows section. When you use xfreerdp, don't put in /p: and the password. Let it ask for the password and you'll be able to then get in.

#

I really think that should probably be mentioned.

young whale
tight mesa
#

i need help with linux privilege escalation skills assessment. It says for flag1 i must enumerate all the files of the user, but i went through every folder of htb-student and can't find flag1. Any tips?

tribal plume
#

Hidden directories/files too?

tight mesa
tribal plume
#

I haven't done that one, I suppose it might be worth trying a 'find' with the username htb-student. Assuming htb-student owns the file with the flag.

analog urchin
tight mesa
#

I'm struggling with finding every single one of these flags except flag 2

bright rune
elfin loom
#

hi. I finished web requests module. in the command line everything was smooth, but in the browser, after authenticating with the proper cookie by replacing in a storage section of devtools, and getting to a search page (in POST section), after search attempt I had completely different results, and no okeyed POST with search.php showed up at all, but many others. my page reloaded instead of showing a result. what happened? the app works properly cause I could do all requests I wanted through cli.

austere sandal
#

hajao mizki

north kestrel
#

Hello guys

lyric bolt
#

this may be a silly question but some of the modules in the Penetration Tester path have a publicIP:port and on those certain boxes I have a hard time using nmap or wget is there an option that I am missing?

analog tendon
sly tapir
#

that PtT Linux question 8 was rough

split parcel
#

anyone got issues with the module?
PIVOTING, TUNNELING, AND PORT FORWARDING - SOCKS5 Tunneling with Chisel

#

when i tried to run chisel on the ubuntu (pivot host) it gave me this error:
./chisel: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.32' not found (required by ./chisel) ./chisel: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.34' not found (required by ./chisel)

dim hound
split parcel
fossil crescent
#

Were you ever able to solve this? I'm stuck on it myself... Can't figure out the proper query. Feel free to DM

versed frost
#

can someone give me a nodge on Footprinting lab medium, I am stuck at the begining

split parcel
#

anyone managed to install "SocksOverRDP-Plugin.dll" in RDP and SOCKS Tunneling with SocksOverRDP module?

#

the dll keep disappearing after i extracted it out

undone narwhal
sinful olive
#

MODULE: ACTIVE DIRECTORY ENUMERATION & ATTACKS

In Attacking Domain Trusts - Child -> Parent Trusts - from Windows - Q3:
Perform the ExtraSids attack to compromise the parent domain. Submit the contents of the flag.txt file located in the c:\ExtraSids folder on the ACADEMY-EA-DC01.INLANEFREIGHT.LOCAL domain controller in the parent domain.

I am able to see the content of the C drive, but cannot move forward to see other folders and files in it.. any help?
When I try to get sub-directory - it says cannot find path.. dir \\academy-ea-dc01.inlanefreight.local\Users

split parcel
winged zodiac
#

Hey I need help for Attacking Common Services > Attacking Email Services I have found m**** user but coulnd't find the password I'm thinking of hydra cannot be used as they said in the module. Need help its been too long I'm stuck in this

rustic sage
silver mesa
#

In nmap "module/19/section/103" there is a question asking for a flag by checking on services, i got the flag (robots.txt) but it says wrong answer?

#

I tried reset the machine also, but the flag doesn't accepting
Can anyone help me with this.

dusty timber
#

Linux privilege escalation -> Shared libraries
I don't understand why this isnt working. Doing just like the academy says and yet I get errors?

grand harbor
#

Welcome to the htb academy😂

dusty timber
#

I did manage to solve it by just ignoring the errors apparently they were fine as they were, just annoying that they didnt show up in the academy output so would have known they were supposed to be there lol

royal wren
#

Hey 👋 guys I am just getting started into this HTB course. Can anyone help me with this error
ssh: connect to host [ip] port 22 : connection refused

vague hedge
#

Why it's give me wrong it's in into to network traffic analysis

grand harbor
#

without the .

vague hedge
grand harbor
#

or 443, 56282

wise slate
#

refresh the page

hasty solar
#

hi I'm in Attacking DNS section from ATTACKING COMMON SERVICES module, I'm bruteforcing utilizing this command gobuster dns --domain "inlanefreight.htb" -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt and only found ```Found: ns.inlanefreight.htb

Found: helpdesk.inlanefreight.htb

Found: control.inlanefreight.htb``` but any of them contain the flag what wordlist should I try next?

rustic sage
timber hatch
#

attacking common servcies, attacking sql database
i could connect to the database and see the flagDB database, but have no acces.
can anybody give me a push in the right direcrtion for the two questions there?
What is the password for the "mssqlsvc" user?
Enumerate the "flagDB" database and submit a flag as your answer.

remote field
#

So, I'm doing Interactive Section with Target. I spawned my machine, and tried to access firefox so I can view http://157.245.40.149:30655. I can't. I get a timed out error. seems like my machine doesn't have access to the internet , in fact I can't even access the bookmarked taps.

#

Is there a reason for that?

warm flint
#

does anybody know a way to automatically check Payloads for LFI. I'm in module File Inclusion, Automated Scanning section, I tried with burp suite, and tools I could find on the web but none of them works.

vague hedge
warm flint
remote field
warm flint
#

im not sure but i i think that for some machine ip's to have access you need to add the ip to the etc/hosts file on your machine

grand harbor
remote field
warm flint
#

maybe try to restart it if you can i haven't used it till now

remote field
#

Restating doesn't work sadly , I tried it. maybe I need to connect it to openvpn

#

but again, how do I get the .opn file in this target machine

warm flint
#

i think its enough to have the vpn open and working on your machine

remote field
#

which I do

warm flint
#

try to restart the vpn maybe

remote field
#

maybe this challenge is bugged ?

remote field
winged zodiac
autumn pilot
#

free users on academy don't have internet in their workstations

#

the target can be reached over the internet, if it doesn't work in the workstation for whatever reason, feel free to open it in your browser

remote field
#

So, this is a subscription issue, makes sense.

rustic sage
autumn pilot
#

reset the target

remote field
wise slate
north kestrel
#

What are you talking about friends?

wise slate
#

there was a confusion with other module from my part

winged zodiac
north kestrel
winged zodiac
ashen wolf
#

attacking common services easy i know u can ||upload webshell with mysql & ftp|| but it doesnt seem like it does that at all.

ashen wolf
#

at least as i remember

winged zodiac
ashen wolf
#

i did that just now. both with rockyou.txt & password list provided in resources. they work. maybe a typo?

ashen wolf
north kestrel
#

What machine do they make?

#

you can use wfuzz

#

In what sense do you mean?

winged zodiac
ashen wolf
#

ezz

north kestrel
warm mountain
#

Which modules on HTB Academy do you think it helped for OSWE prep? I'm currently doing CBBH path in order to prepare for OSWE exam and also bought the Blind SQLi module, but I would like some advices on which modules from the tiers III and IV would help me most.

glad dock
#

Guys need some help 👀 🚨 🔥

So I have connected to the RDP and I have found the users then I have found the important.txt file but when I try to connect to the SQL is giving me error. I have tried the whole string and also have tried the string without the "sa:" but still no access.... I have tried all accounts with that password and plus "admin:admin" and so on.... I have tried with the sa account as well.

warm mountain
warm mountain
#

And assure you have the correct credentials

frigid osprey
#

Have you been able to figure it out yet? I have been stuck at the privesc piece for a while now. Haven't found anything that I don't already have for the initial user login.

vestal nacelle
frigid osprey
# vestal nacelle The privesc one in the getting started module?

The Password Attacks module, Lab Easy. Question is asking for us to provide the root password. I scanned the host, found my way in. I went through all the items in Linux Credential Hunting. Looked for weak configurations "/etc/shadow", but haven't been able to find anything.

Nvm:

I reset the machine, ran an enum script I made a while back and found it. hahaha

glad dock
steel scarab
#

the Industrial Revolution and its consequences have been a disaster for the human race. They have greatly increased the life-expectancy of those of us who live in “advanced” countries, but they have destabilized society, have made life unfulfilling, have subjected human beings to indignities, have led to widespread psychological suffering (in the Third World to physical suffering as well) and have inflicted severe damage on the natural world. The continued development of technology will worsen the situation. It will certainly subject human beings to greater indignities and inflict greater damage on the natural world, it will probably lead to greater social disruption and psychological suffering, and it may lead to increased physical suffering even in “advanced” countries

cobalt pine
#

Hey guys. I have a question regarding filetransfer module -
I have created a script (bash - through time) -asking 3 questions. Normally Manual done with wget FILE - chmod - execute. using read to collect the manual input.
Then Trying to do it with curl FILE | bash - like fileless attacks - It do not ask the 3 question (can see the txt output is asking) - but the script just continues- and fails carse the missing user input.
Is it because of the read command in bash is not working
EDIT --> solution is read -p ANSWER < /dev/tty

magic valve
#

May I get some help with Pivoting, Tunneling, and Port Forwarding - Skills Assessment Question 3?

I attempted to utilize ssh to dynamic port forward with the found id_rsa file as found user on the webshell but receiving the following error. As the ssh_config file is owned by root I am unable to edit the file to try to make it work.

Am I on the wrong path?

glass locust
#

Guys, any tip on Password Attacks -> Credential Hunting in Linux? I logged in as Kira, but can not find Will pass. I cracked the archive but there is only the HTB flag, not the pass. For FireFox I need the master key and in Kira home directory there is only ssh keys for same user.

opaque niche
north kestrel
#

Has anyone here used SET?

#

Congratulations

steady totem
#

@austere osprey dm me I just did that one

uncut mirage
magic valve
hasty solar
#

hi anyone can help me with ZAP Fuzzer section from USING WEB PROXIES stuck in this question The directory we found above sets the cookie to the md5 hash of the username, as we can see the md5 cookie in the request for the (guest) user. Visit '/skills/' to get a request with a cookie, then try to use ZAP Fuzzer to fuzz the cookie for different md5 hashed usernames to get the flag. Use the "top-usernames-shortlist.txt" wordlist from Seclists. Tried generating md5 cookies utilizing the provided wordlist then used burp intruder and repeater as I dont know how to use properly ZAP proxy, but got nothing, what should I try next?

low tusk
#

Hey, a newbie here and im struggling with finding my VM IP in XSS module for /phishing section. Im not using a vpn so it means when i use ip a command i should copy the ip under eth0 and not tun0. But when i paste it into the required place within the code it doesnt happen what its supposed to happen. Pls help

steady totem
low tusk
#

Under tun0 or under eth0

#

?

hasty solar
#

I dont know but I think under tun0

low tusk
#

The support told me under eth0 if im not using vpn

#

And im not

#

But i tried both and it didnt work

steady totem
#

do you have ens224 or something like that?

#

Do you have any interfaces with an ip like the one I listed

low tusk
#

Uhh i dont really know whats that bc my VM got terminated now i wasted so much time waiting for the support and they didnt answer me in time so

#

Ill see tomorrow

autumn pilot
#

your vpn IP is assigned to the tun0 interface

warm kernel
#

if anyone has time, I need a nudge on a question from the 'pass the ticket from linux' module

low tusk
autumn pilot
#

i don't know what you have configured and what you are trying to do

low tusk
#

I am trying to inject a login form

#

But i need the ip of vm

#

And it isnt working

#

Can you check it up pls if you have XSS module

fathom pendant
red current
#

I'm having an issue using the ccache files to gain access to DC01 in the pass the ticket for linux section of the Password Attacks module. I've tried using both files for Julio and I keep getting no credentials cache found. I'm not seeing what I'm missing here.

north kestrel
#

Oh sorry, I can't find the channel for the questions

fathom pendant
untold ore
#

literally just started, but anyone know the point of beautiful soup if you can just curl?
is it because it's python?

fathom pendant
#

there's probably more options and stuff that make beautiful soup useful or more intuitive than curl

#

¯_(ツ)_/¯

rustic sage
#

hey

balmy radish
#

Beautiful Soup parses the response in to an object that is easy to pull data from. It’s handy when writing a Python script that needs to use data scraped from a site.

red current
#

Still having an issue gaining access to DC01 in the pass the ticket for linux section. I tried using both ccache files for Julio. One keeps changing and the other is static. Neither work. I get No credentials cache found after exporting it to root and running klist. Any ideas what I'm doing wrong? I've tried restarting the instance as well and get the same error each time.

#

I've tried with my own VM and using the pwnbox. I keep having the same issue. Neither ccache file works. Could there be something wrong with this module?

sly tapir
thorny wadi
#

this is great 🙂

rustic sage
#

Hack the box

#

Mdr

#

Lol

red current
sly tapir
red current
ivory dock
#

anyone have a hint for the Passwd, Shadow, Opasswd section where we have to find the root password? I tried running hashcat on the unshadowed file with a bunch of different wordlists and haven't gotten a hit

rustic sage
#

if i don't achieve a passing score or complete the exam how many days do i have to schedule a retake. when i went to register for exam only thing i could find about an exam retake is this:
If Participant completes the exam and uploads the answer but does not achieve a passing score for Certification, Participant shall have the option of retaking the exam one more time with the original voucher within 20 days from the date he is notified by HackTheBox of the result.

If a Participant does not achieve a passing score the second time, the Participant must acquire a new Exam Voucher.

It makes it sound like only retakes are available if you complete the exam(sdolve everything) but still don't pass.

mint hound
#

Hey, I was wondering if someone could give me a small pointer on Skill Assessment - Broken Authentication. Id greatly appreciate it 🙂

mint hound
#

@shrewd cradle Could I DM and Ill send a print screen at my current step if thats okay?

mint hound
magic valve
#

May I get some help with Pivoting, Tunneling, and Port Forwarding - Skills Assessment Question 4?

I received a meterpreter session, ran autoroute, attempted proxychains xfreerdp with the found credentials in the webshell pointing to the found IP address for question 3 but getting a failed to connect error

wise slate
#

hi peole im trying to import a exploit module on metasploit but i cant get it . someone has had problems with modules import ?

sly tapir
wise slate
#

b3r4 i just execute reload_all and its works fine

#

thank you

rustic sage
#

hey all im trying to user scanner/http/joomla_bruteforce_login in msf for a subdomain: test123.inlanefreight.local however when i use it it only shows this as the site its attacking: http://10.129.230.222:80/administrator/index.php - Failed to find Joomla Login Response as an error. how can i get it to go against the subdomain i've tried changing rhosts and vhosts to the subdomain but it still onjly goes against the ip

steady hawk
rustic sage
verbal galleon
#

Do you have the subdomain pointed to the ip address in /etc/hosts ?

verbal galleon
#

Then use intruder 😉

rustic sage
#

mercy meee lol ok i'll try

#

but intruder is slow as shit wish i ahd practiced more with zap

modest coyote
#

I'm trying out the ffuf module and am having an issue. Using the built-in pwnbox, I am doing the first interactive section. I can see ffuf working and running through the wordlist, but no matches are displayed at the end of the fuzzing.

opaque niche
magic valve
opaque niche
magic valve
opaque niche
magic valve
brisk geode
opaque niche
magic valve
opaque niche
#

This is what comes to my mind right now

magic valve
rustic sage
#

...

velvet pawn
#

I am on the skill assessment for the pivoting, tunneling module, and im getting some odd results when running nmap through proxychains, or when running a for loop to do a ping sweep from the pivot host.

Proxychains: roxychains nmap -v -sn 172.16.5.1-200 wont find the host I know is there, and outputs "Host is up" on all entries

and

running "for i in {1..200} ;do (ping -c 1 172.16.5.$i ) ;done)" on the pivot host, also failes to find the live host.

but if I manually ping just the one IP I already know is there, I get a response. Anyone that could help me understand why this could be happening?

rich light
#

To solve this issue you would want to start your ping sweep on whatever the machine is that has access to the internal network

#

The module has an example for doing ping sweeps using meterpreter I believe

velvet pawn
#

I see, thanks @rich light ill do some looking around to get a better grasp on it

warm sail
warm sail
#

Tried various types of scans, and intercepting using netcat/tcpdump. Still don't see any flag?

carmine hill
#

Hi there! Is someone here doing the HTTP Misconfiguration module? I’m stuck in the web cache poisoning/host header combined attack.

#

The lab is not working at all

#

I already added the needed vhosts and gave some minutes to the lab to start, refreshed the target several times too, yet it’s not working

rich light
ancient spire
#

I am unable to RDP to the machine in the 'Introduction to Active Directory' module

#

Im trying to paste the xfreerdp log into the chat, but the bot keeps deleting it

iron rune
#

try restarting the machine

silver mesa
#

Hey, Im working Firewall and IDS/IPS Evasion - Medium Lab . I got the port 53 version NLnet Labs NSD . need some help. Anyone?

winged zodiac
wet narwhal
#

can i learn how to hack

red obsidianBOT
novel matrix
#

@wet narwhal ^

wet narwhal
#

yea

rustic sage
rustic sage
silver mesa
#

Actually the question is to find the DNS server version

rustic sage
silver mesa
#

sure

low vine
#

Using Web Proxies - Skills Assessment - Q3
I have the 31 character thing I'm supposed to have that appears to be an md5 according to the question. How am I supposed to fuzz with intruder. I'm having a hard time understanding how I would set this up to attempt this question and would love a little help. It says clearly what to do but I'm not quite understanding how I would go about this and would love a little help if possible.

#

Is this saying that I should basically fuzz a-z 0-9 until I can put this into some md5 converter?

#

Step 1. fuzz for the last character unti lit returns correct?
Step 2. encode md5 with previous methods used to decode.

rustic sage
#

you could create a bash script that'll do that for you and take the md5sum after each attempt and search through those results to find the correct flag

low vine
#

I cant code (i'm sure i could just chat gpt it).

rustic sage
#

I believe there is a way to do it in Burp

#

it's been a while since I've done that module and my notes are at home soooo

low vine
#

Mind if I pm?

#

Yea I'm finishing the last couple of questions and having a much harder time than I should so its worrying me lol

rustic sage
#

I don't know how much help I'll be😅 I did the Burp module back when I wasn't taking good notes. I know how to use the tool and whatnot but I still have to go back through that module and update my notes

low vine
#

Haha thats fair thats exactly what i'm doing now

#

Finishing up the last couple ones that havent been answered / done. My notes are horrible and I hate it

rustic sage
#

I was pretty good except for the ffuf and burp module. I'm already confident in the tools, but I'm going to redo them once I finish the CPTS path to actually get notes for my cheatsheet/playbook

naive sky
#

really sucks

#

css module at phising part

#

what to do actually

#

not make sense

#

at phising part

#

any help please?

brave flax
#

Hi, I'm having trouble listing the total packages installed in Linux. I've tried dpkg -list| wc -l

#

and apt list --installed | wc -l

#

both give different answers and both wrong

winged roost
#

Hey all. Could do with a nudge if possible: On Skills assessment part 1 - Windows Priv esc task ** Escalate privileges and submit the contents of the flag.txt file on the Administrator Desktop.** - ive got juicypotato and nc.exe on the windows box - but cannot seem to get NT Authority shell - im using the default BITs as CLSID and using cmd.exe as the program launch.

brave flax
#

has anyone got any other ideas I could try?

winged roost
brave flax
#

Cheers Doozy, It's Linux fundamentals - File Descriptors and Redirections

fathom pendant
brave flax
#

I was ssh into it but can use it

turbid tartan
#

how do i compromise ||john|| hard lab common services ? i tried ||rdp mssql ||

rustic sage
#

maybe you should try MSSQL again

brave flax
#

@fathom pendant using pwnbox yields the same results. I'm clearly using the wrong commands but can't for the life of me work out what the correct one is. I've tried dpkg --list and apt list --installed. one gives 738 and the other gives 748. This is for the Linux fundamentals - File Descriptors and Redirections. Has anyone got any other pointers I could try?

tribal linden
#

can anyone do a sanity check on "Attacking common Services" - "Attacking SMB"? Im struggling to find jasons password.

autumn pilot
#

are you using the password list that was provided in the resources?

tribal linden
#

The password list from the ftp .

autumn pilot
#

the password can be found in the password list from the resources

turbid tartan
#

on the easy lab attack common services how do i put a whole command in the ||webshell url||

autumn pilot
#

depends on the web shell you are using, if its a simple php request cmd or whatever, you can issue commands simply by http://example.com/shell.php?cmd=<command>

turbid tartan
#

yes im using the second one

#

but how do i use spaces

autumn pilot
#

most browsers can do url encoding automatically

turbid tartan
#

bc if i type c=cd C:/ for example it doesnt go trough completely

#

it just says illegal url

autumn pilot
#

url encode it then

bright rune
#

I need some help with Service Enumeration:

The challenge is asking me to: "Enumerate all ports and their services. One of the services contains the flag you have to submit as the answer."
I am assuming it's a banner. I have pulled all of the banners of the target and don't find anything

#

||and 31337 is empty||

autumn pilot
#

try to use another method to grab the banner

bright rune
#

tried using nmap and nc, just havent tried tcpdump. Let me give that a shot

turbid tartan
#

encoding doenst work too

bright rune
wise slate
rustic sage
wise slate
#

thank you! 🙂

rancid mulch
#

can someone help me with answering this question : What is the admin email address? in the imap/pop3 module please? I can't figure out the command to view email addresses

low vine
#

Web Attacks - Skills Assessment---I've logged into the Admin account and I'm full stuck on waht I'm supposed to do here. Googling around seems to point to the events XML thing and I cannot post to it.

golden vortex
#

Im currently doing the attacking joomla in attacking common applications module and i have the flag but it wont let me submit ive tried to reset box but it didnt work

low vine
autumn pilot
#

explore the application, capture every action/request you do on the app with burp

#

once you see something, poke it

low vine
#

@autumn pilot from asking around I know that this is the point where i'm supposed to have access to the /createevent thing

#

but I do not have access?

autumn pilot
#

all I can say is to explore, if you think the target could be borked reset it

low vine
#

Think it has to be at this point i've looked at everything else I think

#

ill give it a go thanks

versed lichen
#

Hi, I just did the Attacking Common Services Medium Lab. It took me less than 2 minutes to find the flag. Can you tell me if, according to the assignment, I should be messing around with dns/mail service, and the fact that the flag is available after a 10-second bruteforce is a simple mistake, but did someone not think the assignment through very well?

marsh coral
#

Hi, im currently working on the web enumeration module. I apologize if this question sounds dumb but, when I try to use gobuster I keep getting this error https://prnt.sc/EgfXYstFCZSL Is this part of the module or a general error? Thanks in advance.

versed lichen
neat cape
#

Hi! Im currently working on the Password Attacks Lab - Medium Assessment, I was able to get into a share, obtain a file to be cracked and extracted a Document. This was encrypted too so I found the password and tried to decrypt it and it turns out that the file has been corrupted

#

I later checked the actual zip file too and it was corrupted as well

#

Any idea how I would fix this or get around this?

marsh coral
versed lichen
marsh coral
rustic sage
#

I'm not really a gobuster user, but the error says can't connect to site

marsh coral
rustic sage
#

well that's your problem then. If you can't reach the site neither can gobuster

#

if you're sure that's the right IP try resetting the lab

marsh coral
#

I understand that, what im asking is it something that I need to try to work around because its part of the training or is it an actual problem. I already have reset the IP

rustic sage
#

I would say it's a problem with your connection/lab instance

marsh coral
marsh coral
fathom pendant
fathom pendant
#

Also: if it's a spawned ip then you'll need to include the port it gives you

naive field
#

if i get a student subscription on htb academy will i have access to penetration tester job path?

thorn urchin
#

yes, but you dont get an exam voucher with it

naive field
#

does it count for high schoolers too?

#

like the student sub

thorn urchin
#

Im not sure, they have an internal list of schools where an email is automatically valid from, but you can try with a school email that isnt accepted and then contact support to verify it and theyve been known to add exceptions.

#

I haven't heard much about highschool school emails though.

marsh coral
naive field
#

yeah, but my hs email blocks third party so i cant like register or log in with it

thorn urchin
#

You can try hashing it out with support but I think chances sound slim

naive field
analog tendon
#

has anyone gotten this while using hydra even for a simple dictionary attack? [ERROR] waittime must be larger than 0

#

nvm i see where i went wrong

#

just a fat finger

timber hatch
#

attacking common servcies, sql attack, i try to steal the hash, i logged in to the database, i see there flagdb, than in execute EXEC master..xp_dirtree '\IP\flagDB', but i can^t see anything at my responder...any hint?

fathom pendant
thorn urchin
timber hatch
#

just like this EXEC master..xp_dirtree '\IP\share'?

timber hatch
static roost
#

Anyone able to perform CVE-2014-3704 manually via "Attacking Drupal" Section in module "Attacking Common Applications"? Can't seem to get the SQLi syntax right.

thorn urchin
#

that or my notes are wrong

timber hatch
#

yeah...thank u. impacket did work...responder not...

thorn urchin
#

nope, shoulda saved em 😦

low vine
#

Skills Assessment File Include
I was able to confirm that User-Agent would show up in logs.....I'm no longer able to?
||```GET /ilf_admin/index.php?log=../../../../../var/log/nginx/access.log HTTP/1.1

Host: 144.126.200.173:32767

Cache-Control: max-age=0

Upgrade-Insecure-Requests: 1

User-Agent: Plzfuckingwork

Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.7

Accept-Encoding: gzip, deflate

Accept-Language: en-US,en;q=0.9

Connection: close```||

#

This is the last response I'm getting and it will not update for any newer time / request sent

#

||144.126.200.173 - - [13/Mar/2023:22:18:40 +0000] "GET /ilf_admin/index.php?log=../../../../../var/log/nginx/access.log HTTP/1.1" 200 1283 "-" "||

thorn urchin
#

did you already attempt to poison the log

#

if you tried but the payload was no good it could be bricking and so you dont see anything new after that point(and also any nee payloads wont work either. you gotta reset the box).

you can check by loading the error log