#modules

1 messages · Page 69 of 1

halcyon grove
#

What is the FQDN of the host where the last octet ends with "x.x.x.203"? anyone know how i can solve it i tried brutefroceing and file transfers

halcyon grove
#

so if a zone fails i need to brute force it ?

#

for example:

#

dig axfr @10.129.42.195 mail1.inlanefreight.htb

; <<>> DiG 9.18.12-1-Debian <<>> axfr @10.129.42.195 mail1.inlanefreight.htb
; (1 server found)
;; global options: +cmd
; Transfer failed.

#

@acoustic owl

acoustic owl
#

Not every zone allows a zone transfer, that is correct

halcyon grove
#

yeah ive tried that ive tried bruteforcing no luck what wordlist u prefer?

acoustic owl
#

Take the smallest one from SecLists
If you can't find the host with this, then use the next larger list.
The list with 5000 entries is too big

halcyon grove
#

keeps giving me app.inlanefreight.htb NS record query failed: NOERROR

#

thanks for the help anyway

acoustic owl
#

A DNS zone is a specific portion of the DNS namespace in the Domain Name System (DNS), which is managed by a specific organization or administrator. A DNS zone is an administrative space that allows for more granular control of the DNS components, such as authoritative nameserver. The DNS is broken up into many different zones, which are distinc...

halcyon grove
#

no i got that still bruteforcing no luck

tepid elk
#

Hi, any advice to module "AD Enumeration & Attacks - Skills Assessment Part II", I have some trouble with the next questions "Obtain credentials for a user who has GenericAll rights over the Domain Admins group. What this user's account name?"

#

I think i have to spoof, but im not sure

acoustic owl
halcyon grove
#

thats the output i got

#

i have no clue were i should go next

acoustic owl
acoustic owl
agile rapids
#

anybody have tips on public exploit section of getting started

halcyon grove
#

to find the exploit

#

if your doing the lab

agile rapids
#

@halcyon grove i tryed

halcyon grove
agile rapids
#

trying to find the service or plugin

#

nmap is blocking pings

halcyon grove
#

are you doing nibbles ?

agile rapids
#

go buster isn't showing anyhting

#

no public exploits

#

its the metasploit primer

#

only thing that shows stuff is curl -IL

#

and whatweb

halcyon grove
#

hit: look at the wordpress verssion

agile rapids
#

wordpress version is 5.6.1

halcyon grove
#

now think of possible exploits

agile rapids
#

then i do search exploit on msfconsole

#

theres lke 80 expoits

#

how do i know wich one

halcyon grove
#

narrow it down what functions does the website have

#

hint: its the title

agile rapids
#

i wish it would explain this stuff

halcyon grove
#

once you find the plugin the website is useing searchsploit it

#

good luck

agile rapids
#

yeh it says 2.7.10

#

searchploit does nothing

#

i just use it then it gives a list

halcyon grove
#

yes

#

a list of ?

agile rapids
#

exploits

#

that i can't use

halcyon grove
#

there you go

#

you can think about it

#

what is that plugin version vanrable to

agile rapids
#

how do i find that?

halcyon grove
#

whats the plugin name lets start of with that

agile rapids
#

2.7.1 or 5.6.1???

halcyon grove
#

read again what's the name of the plugin it gives you the name in the wordpess website

#

starts with an s

agile rapids
#

simple backup

#

i do searchploit and it says mutiple vunerablities, whats that mean?

#

i wish i could post screen shots but this sub is restricted

halcyon grove
#

simple backup _______

#

ur missing sumthing

#

after u find the missing part if searchsploit gives you no resualt goole it

#

Hint: exploit ends with read

#

@agile rapids

hardy void
#

Hi
And who is the site administrator here, who can I talk to about paying for a subscription?

agile rapids
#

hmmm

#

just a min

hardy void
#

I'm just asked to pay for my subscription with a card or PayPal, and I don't have it in the USA

halcyon grove
hardy void
#

Khaotic#5059 He can help, can't he?

#

If it's not difficult for anyone to tell him, let him answer me in PM

fathom pendant
agile rapids
#

@halcyon grove should i use ncat for listener

halcyon grove
#

yes

#

but its your choice at this point if you found the correct exploit

hardy void
halcyon grove
fathom pendant
#

^

hardy void
#

Well, if I don't have paypal and USA card

fathom pendant
#

are you in the US?

hardy void
#

Maybe you can pay for crypto

fathom pendant
#

US shouldn't matter anyway since HTB is based in UK

hardy void
fathom pendant
#

The only currently known payment processing issue is if you're in India

#

but you don't need a US card...

#

just a card

hardy void
#

Well, I want to pay, but I don't know how to do it

#

I can't even pay with a European card

fathom pendant
#

sounds like a skill issue

red current
#

I'm working on the Pivoting, Tunneling and Port Forwarding module and there appears to be a step or instructions missing for the Meterpreter Tunneling and Port Forwarding section. It mentions configuring and starting the multi/handler after creating your payload, but there is absolutely no mention of how to copy that payload over to the ubuntu pivot target. Is that something you're just supposed to know or is there something missing from this section of the module?

hardy void
placid quest
#

@red current Nothing that is missing in the module

red current
placid quest
#

@red current what problem are you facing

steady hawk
gentle root
#

Clarification on mimikatz / passtheticket -- ||When I use "mimikatz # kerberos::ptt "C:\tools[0;53834]-2-0-40e10000-john@krbtgt-INLANEFREIGHT.HTB.kirbi"

  • File: 'C:\tools[0;53834]-2-0-40e10000-john@krbtgt-INLANEFREIGHT.HTB.kirbi': OK

mimikatz # exit
Bye!

C:\tools>dir \DC01.inlanefreight.htb\john" --------- Am I being granted the rights of John for the next command I type ||

halcyon grove
#

anyone have the solution foe this i am about to rip my head out:

#

What is the FQDN of the host where the last octet ends with "x.x.x.203"?

red current
halcyon grove
gentle root
halcyon grove
#

bruteforceing and everything

#

tried all word lists

#

can you give me a hint

placid quest
#

@red current use wget and python server

gentle root
#

Oh shoot that's right. Yeah there's a brute force on a subdomain IIRC

red current
fathom pendant
gentle root
#

1 sec

gentle root
#

Which question module is thsi on?

halcyon grove
#

DNS

#

Footprinting

gentle root
#

PMing

fathom pendant
#

subdomains of subdomains. first get a list of all subdomains > then try and bruteforce those subdomains i.e. a.b.inlanefreight.htb

gentle root
#

^^

agile rapids
#

@halcyon grove auxiliary/scanner/http/wp_simple_backup_file_read still doesn't help

fathom pendant
#

don't know what to tell you brother you can make a post in #1024429874246590575 and you may get assistance from a mod there ¯_(ツ)_/¯

fathom pendant
#

wink

red current
placid quest
#

@red current you are welcome

agile rapids
#

@fathom pendant filepath is correct i think it has something to do with my ports and lhost

fathom pendant
#

fun fact if you do lhost tun0 it will automatically configure it to your vpn IP

agile rapids
#

i did tun0 says did you mean vhost?

fathom pendant
#

vhost would be the website

#

that may be required

#

i forget

halcyon grove
#

use tun0

#

ur useing openvpn

agile rapids
#

this module doesn't use openvpn its on clear net

fathom pendant
#

also always pay attention to errors when things fail; they tend to give you a clue as to where you fucked up

#

so the first octets aren't 10.129.x.x or 10.x.x.x?

fathom pendant
agile rapids
#

@fathom pendant getting started public exploits section

fathom pendant
#

oh yeah this one is on the docker container

#

your lhost should be your IP though just to be sure

agile rapids
#

@fathom pendant you mean i should put my exteranl iP or lan ip?

#

i use both instance and vm for different results

fathom pendant
#

when you do ip a whatever that IP is

rustic sage
#

I am working on "Password mutations" lab from "Password attacks" module and I am stuck on bruteforcing SSH. I have created a mutated password list and I tried using hydra and crackmapexec for cracking but the process is very slow. The time usually runs out before I finish the list, any tips to improve?

small sage
#

I’m very stuck on the last part of the LFI skills assessment, anyone available to talk to?

fathom pendant
#

@agile rapids make sure you set the RHOST and RPORT properly; the only options needed to change are FILEPATH; RHOST; RPORT that's it

fathom pendant
rustic sage
fathom pendant
rustic sage
# fathom pendant give me a moment to sanity check this

So I was thinking that my first scan with hydra worked on 8k passwords, I could split the wordlist into chunks of 8k each and run it from there but I think there should be another easier solution. Each scan can do 8k password attempts before machine dies.

fathom pendant
#

shouldn't be necessary

rustic sage
#

Okay, what do you have in mind?

fathom pendant
#

like I said I'm sanity checking on my VM

rustic sage
#

alrighty

agile rapids
#

@fathom pendant filepath should be my filepath?

fathom pendant
agile rapids
#

@fathom pendant thanks finally... sorry for bugging you guys just really wanted to solve this one

fathom pendant
fathom pendant
fathom pendant
#

also in hydra you can increase the threads with -t (though if you use too many threads you can miss the password too, it's a delicate balance)

#

don't forget there is an "extend instance liftime" button under the refresh instance button

#

so if it's gonna take a bit of time :)

rustic sage
#

thanks

fathom pendant
#

it's a relatively new button

willow bluff
#

Howdy! I am rather new, and am in the Getting Started module, specifically am in Knowledge Check. Amidst my logging into the admin website management site, I can't upload any files into the Upload Files section. I also tried searching for exploits with SearchSploit for the HTTP version, and the listed exploit scripts unfortunately don't work.

If I may ask, may someone please help me amidst my predicament? Link to the module/section below. Thanks for reading, and I hope y'all have a grand day!

https://academy.hackthebox.com/module/77/section/859

fathom pendant
#

Yeah that one's a bit tricky. It's easier to just run the metasploit exploit for it

#

Rather than try and do the uploads

fathom pendant
#

that's for a different section wolfiej

foggy light
#

Module : Active Directory Enumeration & Attacks
Section: Kerberoasting - from Linux
I logged in using ssh but Im getting this error when i used this password "HTB_@cademy_stdnt!" , Same password i used to ssh in

manic magnet
#

Any idee why crackmapexec does not start bruteforcing the username/password here? Its from the Password Attacks module

pine dagger
fathom pendant
#

yeah most shouldn't it's just an option just in case it's necessary

pine dagger
foggy light
pine dagger
#

I think you need capital u and p

fathom pendant
#

nah

#

cme only uses -u and -p

#

no capitals

foggy light
#

so weird.. why would it do it lol

pine dagger
#

Hrm

fathom pendant
#

it errors if you try and do -P

#

try absolute filepaths

pine dagger
#

My one note isn’t opening to check my notes. Sigh

manic magnet
fathom pendant
#

CME/crackmap is a bit finicky tbh

pine dagger
#

Ah. I had the command pulling them from downloads so never hit that issue. 🙂

foggy light
manic magnet
#

Maybe also try copying the password then pasting it when prompted

#

maybe a char is somehow broken

foggy light
#

hm

#

HTB_@cademy_stdnt!

#

the password is hidden so not sure what i should do

manic magnet
#

just when you are prompted press ctrl+shift+v

#

it will paste the password then if it is copied

foggy light
#

it did copied it.. but not working

#

I see someone had the same issue as me.. not sure how they solved it

pine dagger
#

From my notes on kerb for Linux, I didn’t use that account

foggy light
#

I mean I can ssh in.. so it should be the same password

pine dagger
#

Try using ||dbranch|| login

foggy light
#

can i dm you @pine dagger

pine dagger
#

Sorry, not atm. Tomorrow morning. Am in bed 🙂

foggy light
#

its all good man. Thanks for trying

pine dagger
#

The account I referred to you should have the password for from the earlier chapter Internal Password Spraying from Windows

foggy light
#

you mean using that in impacket?
inlanefreight.local/adunn ?

pine dagger
#

Click the black block in my earlier answer to see the name of the account

foggy light
#

I just looked for password for that user.. I didnt found any from pervious section.. going blind maybe lol

pine dagger
#

The username is the answer to question 2 of that section. You spray the password to get the username

#

So you must have the password 🙂

foggy light
#

bro thanks

#

lmao

#

+rep @pine dagger

pine dagger
#

Getspn working now?

foggy light
#

Anyone in future having problem with logging in Kerberoasting - from Linux , Use the user Internal Password Spraying - from Windows

foggy light
pine dagger
#

Glad I could help. That module is a beast

#

/goes back to reading macOS fundamentals

rustic sage
#

cracking takes forever

pine dagger
#

Which chapter is it?

fathom pendant
rustic sage
#

this is password mutations from password attacks but anyways, I am trying to run this again

#

thanks

honest hazel
#

can anyone give me a hint on the command injection skills assessment? I've tried several approaches, I know where I need to inject, I just can't seem to bypass the thing

glass quarry
#

@surreal rain

summer flame
#

Hi, for AD Enumeration & Attacks - Skills Assessment Part II Qn 11, I am trying dcsync method but it does not seems to work? Can advise if I am on the right path?

rustic sage
#

Are there any options that let me connect to rdp

#

Rather than remmina

autumn pilot
#

xfreerdp

placid quest
#

@rustic sage rdesktop

rustic sage
placid quest
#

@rustic sage did you install it

rustic sage
pine dagger
empty condor
#

Hello, i'm a noob a I need help (The course is https://academy.hackthebox.com/module/35/section/224)

#

When I type curl -X POST -d '{"search":"london"}' -b 'PHPSESSID=brlcb2hci2588m60fs1id1ofs5' -H 'Content-Type: application/json' http://144.126.192.55:30392/search.php
This return Received content contained invalid JSON!

#

I can't pass this exercice 😭

livid quest
#

hmm do the task by copy and pasting from the example code and replacing the ip and Sessioncookie with your's it's propably something stupid-simple you are missing, which is totally normal, i still have the same problems with other modules today

lost rivet
#

hey guy can some help me with the the metasploit framework modules

placid quest
#

@lost rivet where are you stuck

lost rivet
#

Meterpreter

#

i cant steal the token

placid quest
#

Use post modules

lost rivet
#

sorry but can u explain more

placid quest
#

@lost rivet if you are trying to steal passwords or dump passwords you can use post modules

lost rivet
#

i tried

#

but when checking method for exploit

placid quest
#

@lost rivet can you dm

hot merlin
#

anyone nudge for module "Attaching Common Applications" ?

#

i have done 1,2,3 assessment

#

but I'm stuck on Thick Client app

lost rivet
#

Yes

#

I’ll be back

hot merlin
#

I'm stuck here

rustic sage
#

Can I get a nudge for default password section in password attacks module?
I have|| logged into ssh|| and I am stuck

slender kelp
#

in the skills assessment section of the module "shells & payload" you're given access to a foothold box and ip addresses and ports of 3 more boxes. one of these is accessed at port 8080 but the foothold box seems to be missing a browser and it can't connect to the internet to fetch one either. is this intentional?

rustic sage
#

Had the same problem myself

slender kelp
#

thanks @rustic sage, that worked 🙂

rustic sage
#

happy hunting

bold canopy
#

@everyone Hello Guys , I would like to ask for help from anyone who is quite confortable with reverse engineering. That would be very helpful

hybrid kraken
#

hello guys, I do reverse shell and I get an error: WARNING: Failed to daemonise. This is quite common and not fatal. No route to host (113) . Can some help me ?

rare topaz
#

What rev shell r u using

hybrid kraken
rare topaz
#

in what box or module

#

and whats the rev shell ur using

hybrid kraken
#

i also get error on other platform like tryhackme

rare topaz
hybrid kraken
#

yes

rare topaz
hybrid kraken
#

three in tier 1 and pentestmonkey/php-reverse-shell

red current
#

I'm on the Pivoting, Tunneling and Port Forwarding module and having an issue with the Web Server Pivoting with Rpivot section. When starting server.py from my VM or from the Pwnbox I get an error of can't open file server.py: [Errno 2] No such file or directory. Has anyone else come across this?

light atlas
#

Currently doing the medium lab for Password Attacks. Have ssh access and found that there is a second user starting with d. Tried everything from the Linux Credential Hunting segment. Anyone open for a chat on how to proceed?

red current
#

Never mind. I figured out my issue with rpivot. It helps to be in the correct directory. However, when I try running proxychains (yes, I configured it properly) the web page times out, so I'm not able to get the flag. I tried using the option of connecting via Web Server using HTTP-Proxy & NTLM Auth as mentioned in the section and I get a strange syntax error. Has anyone else run into this?

red current
red current
balmy lion
#

hi all, hit a wall with:

Module: ACTIVE DIRECTORY ENUMERATION & ATTACKS
Section: AD Enumeration & Attacks - Skills Assessment Part I
Q:6 ||tpetty's|| cleartext password

I've tried Mimikatz and Lazagne (and impacket-secretsdump) both with admin privileges, I'm only getting a SHA and NTLM hash for ||tpetty||, no passwords at all, but I cannot crack that hash, I've tried multiple wordlists (rockyou as well).
Any idea / nudges on this?

halcyon grove
#

Oracle TNS hack the box i need help cant get the password

#

./odat.py all -s 10.129.205.19
[+] Checking if target 10.129.205.19:1521 is well configured for a connection...
[-] Impossible to establish a TCP connection to 10.129.205.19:1521. This target is SKIPPED

verbal kraken
#

hi everyone

#

i need help with active subdomain enumeration

#

i dont understand this room and i cant solve the questions

#

i tried looking up hints and nothing was helpful

quick cloud
#

footprinting What is the FQDN of the host where the last octet ends with "x.x.x.203"? I made a script that went through all the wordlist but didnt find any x.x.x.203 ip address what am I missing?

surreal harbor
#

The answer

verbal kraken
quick cloud
#

was that aimed at me tcp?

quick cloud
#

ok will try that out

surreal harbor
#

DM me if you get stuck. Just finished it like 2 minutes ago

fathom pendant
honest hazel
#

Can anyone lend a nudge on command injection skills assessment? I'm leading out with || or %27%27, and I've tried b64 encoding and double url encoding, and using rev and all kinds of stuff and I've been stuck for a while

steady hawk
honest hazel
#

I've caught an error with everything I've tried it just says malicious request denied

honest hazel
steady hawk
#

Hashes you've previously cracked are stored in hashcat.potfile

red current
#

I'm running into an issue in the Port Forwarding with Windows Netsh section of the Pivoting, Tunneling and Port Forwarding module. I can't seem to get the RDP session to start using the provided username and password, even though I confirmed that the listener is running on the Windows pivot host. Has anyone else run into that?

steady hawk
#

Try adding the --show option

steady hawk
#

<@&861185840277487616>

novel matrix
steady hawk
twilit cipher
#

@warped cape Did you ever find the right answer to that last question in the Bloodhound module? I know how many users and how many have a path to GLOBAL ADMINISTRATOR, but the math doesn't seem to work out.

#

@fossil crescent Did you ever find the answer to my above query?

#

I mean, are you supposed to count service accounts, adn the one duplicate "extension" account?

halcyon grove
#

ayone know how i can get into the ssh serber footprinting lab 1

#

ome/kali/FootPrint_LAB1/10.129.42.195:2121/key.txt' ceil@10.129.42.195
Load key "/home/kali/FootPrint_LAB1/10.129.42.195:2121/key.txt": error in libcrypto
ceil@10.129.42.195: Permission denied (publickey).

rustic sage
#

sup

fossil crescent
#

Yes -- I have some notes stored away but feel free to dm if needed

halcyon grove
#

whoever is doing the footprinting lab i figgured it out

#

find the ssh keys on port 2121

#

its hiden with a firewall

#

hint:decoy method

#

use msfconsole to determine the password of the ftp user

#

download ssh keys

#

login with the ssh key

#

you will find flag .txt

#

your welcome

wispy tree
#

Can someone help me with Login Brute Forcing - Skills Assessment - Website? dm me pls

foggy light
#

Steve is learning about the tool that can make logging a session easier. He messages you for help mentioning that he would like to try to split the panes vertically. What do you tell him? (Answer format: [key] + [key] + [key], i.e., fill in the values for "key" and leave the brackets and + signs.)
It doesnt take this as answer
|| [Ctrl] + [B] + [Shift] + ["] ||

torpid knoll
#

is that tmux

#

the keybind for vertical split is ctrl + b + %

runic rampart
#

Good evening! Have you managed to unwind Advanced sqli:Common Character Bypasses:union-based SQL injection?('//union//select/**/$$1$$,$$2$$,$$3$$--)

acoustic owl
copper haven
#

Hey people,

I have a question on MACOS FUNDAMENTALS -> https://academy.hackthebox.com/module/details/157
They say ( To complete this module, you must have access to a macOS machine ) but when I start the instance it's not MACOS, what can I do and how connect to MACOS?

placid quest
#

@copper haven I had to finish the module without connecting to macos

autumn pilot
#

"To complete this module, you must have access to a macOS machine"

summer lava
#

Please Guys
How do i get HTTP headers, in JSON format ?

placid quest
#

@summer lava use jq

placid quest
#

@copper haven You are welcome

summer lava
native bridge
#

Hey All, Just wondering if they Skill Assessment for "File Inclusion" is broken or breaks? I can read via LFI and write into the user-agent field. When I use a basic PHP webshell the log stops being written to and webshell commands don't work. Anyone else experience the same? Restarted the box multiple times

acoustic owl
bright hemlock
#

hey guys...another one stuck on command injection skills assessment... i've managed to get this error message..can anyone give me any pointers at all?

flat silo
#

Ok I'm on the command injection assessment I figured out what connection command bypasses the filter but now everything I put in after bypasses the filter, or I think it is, I just get the same output as if I had only searched for the file. I guess I'm just a little lost on where I'm going wrong I've tried different obfuscation methods and just writing the command to the server, its the same output

native bridge
south glen
#

can anyone help me with getting started "privilege esc " portion .

turbid lily
flat silo
#

Ok I guess my only question is am I just continuing to stab in the dark or are there indicators I'm not noticing bc as I said I've tried different things and I'm just getting the same results at least a failed attempt on the request would tell me something

sullen dragon
#

hi please I want to know about this offer,

#

I can get all modules from tier 0 to tier 2 with it ?

prisma silo
#

to winsrv

sullen dragon
#

any support for htb academic here ?

acoustic owl
sullen dragon
#

okay but what if my mail is not accepted ? do you know the list of accepted mails domains ?

sullen dragon
#

thankss

spiral pelican
#

hi all,
i try to complete the module File Upload Attacks but im stuck on the skill assessment section.
I guess we have to use an XXE on the image in the contact page but impossible to trigger anything.
i tried to fuzz black/white list extenstion but i always get a success and nothing happen...
I cant find what i missing out. If someone can help me it will be very apreciated.
Thanks all have a good day

foggy light
#

The Answer format: [key] + [key] + [key]
While I need 4 key according to the section?

torpid knoll
#

try caps lock :")

#

the session tool is tmux though right?

foggy light
#

yea

foggy light
torpid knoll
#

try both

foggy light
#

bro.. its crazy sometimes how forgetful I can be. using tmux this whole time but answering the question wrong -.-

#

Also for someone in future the format is
[key] + [key] + [key] + [key]

torpid knoll
#

it happens

placid quest
#

@foggy light So you mean the answer is the format

foggy light
placid quest
#

@foggy light Thanks

spiral pelican
#

pleas no one can help me ?🙏

misty cedar
#

So I just finished Network Enumeration with Nmap

#

Here’s my fucking problem… why the labs have answers and no answers at the same time XD
Maybe I’m just dumb because if forgot to do the <target>/status.php but holy shit XD that was a lot.

#

Like one lab I had use —script=dns-nsid… WHERE DOES THAT SAY THAT

#

I READ EVERYTHING AND STILL AINT FIND IT XD

empty condor
#

Hello, i'm on starting point and i'm stuck in Tier 1 - Machine called Three. I'm stuck at the step Then, we can upload this PHP shell to the thetoppers.htb S3 bucket using the following command.

#

I managed to do all the actions, my cmd tells me that the file has been uploaded but I am left with a 404 Not Found

The requested URL was not found on this server.

#

Also, when you do this command aws --endpoint=http://s3.thetoppers.htb s3 ls s3://thetoppers.htb it returns 2 files (In walkthrough) while I see 15

empty condor
empty condor
ashen wolf
#

AD Skills Assessment II 'get flag.txt on MS01 host as Admin'. I ran mimikatz, have hashes, successfully logged in with a password. waht next?

spare condor
#

Did you resolve this? Can I DM you? I have issues on this topic too

empty condor
#

Someone can help me ?

When I type nc -nvlp 1337, my terminal returs listennig on [any] 1337 Instead of listennig on 0.0.0.0:1337

red current
#

@spare condor I still need help with it myself.

still spear
#

i Think it fails on the Success/FAIL string but im not sure

rustic sage
#

fy

placid quest
#

@red current where are you stuck

red current
#

@placid quest I'm actually at work right now. I'll try to message you back when I get off in about 4 hours if you're still available.

placid quest
#

@red current no problem

willow sigil
#

Hello! I'm having trouble with the Linux Fundamentals System Information questions "What is the path to the heb-student's mail?" & "Which shell is specified for the htb-student user?" I thought the mail path would be "/var/mail/" and the shell is either "unprivileged" or "bash" but none of those are being accepted

#

So now I'm not sure if I'm understanding the questions correctly

rugged lintel
#

Just a question regarding netcat, when connecting to a service and waiting for a reply is there any reason the response takes so long to come back? for example Firewall IDS/IPS Hard lab. when I test netcat on x port connection succeeds but response 200 takes 30 seconds to come back (using the HTB vnc web browser client no vpn)

empty condor
#

I think you're not allowed to post this

fathom pendant
#

<@&861185840277487616>

autumn pilot
#

thanks

languid dawn
#

💀

empty condor
#

I don't know if i can @mention, thanks ! I do it next time..

spark night
#

Anyone else having issues with spawned targets right now?

foggy light
#

Module: Documentation & Reporting Practice Lab
can someone help with the assessment? not sure what im doing here. collected all the password I can and logged into rdp but none of them have domain admin level access

thorn urchin
#

you can get DA creds in the first 5 minutes of doing the lab

#

just cause the partial pentest says the former guy did something, doesnt mean they were properly thorough

thorn urchin
#

sure

zenith gazelle
#

Hello everyone, I have a very big doubt regarding a topic: How to study hacking, more specifically the modules for CPTS etc? What should I focus on to understand and remember the material?

In my experience I read the module count and take notes, and I try to use flash cards, but I feel that I am not being very efficient and effective.

I want to hear your study techniques on how to study hacking better!

thorn urchin
#

write good notes, dont skip out on practicing whats taught

#

not much more than that. everything else is just experience and aptitude

zenith gazelle
thorn urchin
#

if you have a weak background thatll be difficult

thorn urchin
zenith gazelle
thorn urchin
#

thats pretty much next to nothing

zenith gazelle
thorn urchin
#

lot of experience with fundementals, knowing Linux and windows pretty well, understanding of networking, some coding/scripting knowledge helpful as well

zenith gazelle
#

Can you show me one of your notes ?

thorn urchin
#

no

zenith gazelle
#

Okay

pine dagger
#

Good evening, could anyone give me a hint on the Active Directory BloodHound -> Analyzing BloodHound Data question 3? Its " Find what attack the Enterprise Admins group can execute over the Domain object.". I can see what level of control they have, but I can't seem to figure out what the correct answer is.

lucid marsh
#

hey guys

#

does anyone use chirpy-theme on github pages? got a little doubt

pine dagger
simple zephyr
#

anyone complete the Attacking Applications Connecting to Services yet? When I am running this command to set the break points its not really working like its shown in the module.

gdb-peda$ set disassembly-flavor intel
gdb-peda$ disas main
   0x00000000000015fa <+420>:    mov    ecx,0xfffffffd
   0x00000000000015ff <+425>:    mov    esi,0x0
   0x0000000000001604 <+430>:    mov    rdi,rax
   0x0000000000001607 <+433>:    call   0x11b0 <SQLDriverConnect@plt>
   0x000000000000160c <+438>:    add    rsp,0x10
   0x0000000000001610 <+442>:    mov    WORD PTR [rbp-0x4b4],ax
gdb-peda$ b *0x11b0
Breakpoint 1 at 0x11b0
gdb-peda$ run
Starting program: /home/htb-student/octopus_checker 
Warning:
Cannot insert breakpoint 1.
Cannot access memory at address 0x11b0
pine dagger
#

run it first

simple zephyr
#

thanks that worked

pine dagger
#

np, that one irritated me as well.

simple zephyr
#

have you done the exploiting web vulnerbilities in thick-client applications yet?

pine dagger
#

Yes.

simple zephyr
pine dagger
#

Its pretty much a case of following the steps. You just need to modify a different Java file, and then copy that in instead of the ClientGUI. The modified code is detailed towards the end of the instructions.

#

They just don't provide the steps for importing it.

simple zephyr
pine dagger
#

Huh?

simple zephyr
#

for the fat client one

pine dagger
#

You would run it on the Windows box. But you dont need to do that, because the notes in the folder detail the port

simple zephyr
#

ok, thats where i gave up on that one, was because the wireshark wasn't working.

pine dagger
#

I just jumped straight into modifying, heh

#

Its the same port as in the reading

simple zephyr
#

ok cool going to work it now

versed frost
#

hey all, in Password Attack module, and Attacking SAM section, I copied the three hives from the target, and when I tried to dump the hashes using secretsdump.py, I recieve this message, Can someone help?

pine dagger
#

I'd check the size of your .save files

versed frost
thorn urchin
#

that seems too small for a good transfer

pine dagger
#

them all being identical is also suspicious

versed frost
#

I got it, Thanks all, I'll try another way to transfer them

halcyon grove
#

Footprinting Lab - Hard
any hints i found all ports just don't know were to start from

#

snmpwalk -v2c -c public 10.129.202.20 i tried this,but no response from target. i enumerated what should be next step?

simple zephyr
#

@pine dagger on the fat client one, I made the changes to the port, deleted the 1.RSA, 1.SF, and all of the hashes in manifest.mf, ran

jar -cmf .\META-INF\MANIFEST.MF ..\fatty-client-new.jar *

and still getting connection error

NEVERMIND....

I am a dumb dumb... realized it creates a new .jar in the directory outside of the one i am working in 🙂

dapper star
#

Anything I can do to fix this? Need it for the MSSQL chapter in the footprinting module.

versed frost
halcyon grove
#

no luck with onesixyone

#

any hint ?

#

@versed frost

versed frost
last cape
#

anyone familiar with turing machines wanna dm me $$$

versed frost
umbral mist
#

I'm working through the Windows Command Line Basics module, and are currently on scheduling tasks under cmd.txt

I've tried setting up the following on the target it gives me:

schtasks /create /sc minute /tn "Task" /tr "echo test > C:\Users\htb-student\Desktop\testing.txt"

however the task never runs, nor does it run if I manually do schtasks /run /tn "Task"

if I manually copy and paste the task command it works so i know the command is valid

does anyone have any ideas how to fix this?

umbral mist
#

after 10+ minutes there still isnt the testing.txt file

west parrot
#

anybody here to help

pine dagger
umbral mist
#

it doesnt work if i do it on my local machine either

#

so its not just vm-centred

simple zephyr
#

@pine dagger mind DMin me I am stuck on the Fat Client one trying to get it to create the file on my desktop right now

pine dagger
simple zephyr
#

ok no problem

pine dagger
# umbral mist so its not just vm-centred

Try writing the echo command to a batch file, and running the batch file instead. I think if you check task scheduler, you'll find that it will say something like "cannot find the specified resource". Most likely because "echo" isn't an executable that can be run outside of command prompt/powershell.

simple zephyr
#

this module is a nightmare lol

umbral mist
pine dagger
umbral mist
#

How weird, all the same commands?

#

I guess I’ll just move on and know my notes are correct, just can’t test it out for whatever reason

#

I’m logging off for the night now anyway but I’ll play around tomorrow to see if I can debug it at all

pine dagger
#

You don’t have the /mo to identify how many minutes

umbral mist
ebon chasm
#

Hello not sure where I should ask this question so I’m typing it here

#

I am having issues trying to set up my kali Linux vm while connecting it to hack the box through the vpn

#

If anyone could help me out it would be much appreciated

modern yew
rustic sage
#

Hi there!!

rugged veldt
#

In the Attacking DNS section of the Attacking Common Services module, I am having troubles getting the flag as a DNS record. Using subbrute and the IP in the resolvers file, I have yet been able to find a name server allowing me to find the flag when using dig axfr

foggy light
#

this was unlread

rustic sage
#

@foggy light can u help me with LFI

rugged veldt
#

Nvm got it

quartz quest
#

Can anyone help me lfi final assessment, I got lfi but I'm not able to get an rce. I think I'm missing something.

misty aurora
#

can someone help me with Footprinting Lab - Medium i can't connect with the database despite have a right cred.

plain coral
misty aurora
jolly dagger
#

Did anyone answer this? I have the same question. The instructions aren't very clear what state you want to find the address of the base pointer.

jolly dagger
# jolly dagger Did anyone answer this? I have the same question. The instructions aren't very c...

Got it. You're suppose to use the python input from the previous example. Wish they specified that, but if anyone has this issue, add the python input. I think it's not intuitive to do this, because the program segfaults on itself, and doesn't even provide input before it breaks. On my own, I would have used my input of AAAABBBB..., and would have been wrong. Maybe add what input will get the correct address on EBP after it faults.

rugged veldt
#

Attacking Common Services Easy, I need help uploading my reverse shell. Have uploaded using ftp but not able to access it via the browser?

#

Nvm using sql I got it :)

brave sail
#

I'm using sql however

summer prism
#

Q) Enumerate the custom script that is running on the system and submit its output as the answer.

snmpwalk -v2c -c $IP 10.129.14.128, nothing seems like a custom script am i missing anything?

brave sail
#

I0m getting sql syntax error

#

I'm*

rugged veldt
# brave sail How did you find the right reverse shell?

Revisit the sql section in the module, make sure u change the path to that of Windows, look in the config file of the web page to find the default location, this is where u save the shell. Make sure its a webshell, then u can run a command to get urself a Rev shell

eager torrent
#

g

ashen wolf
#

AD Skills Assessment II 'get flag.txt on MS01 host as Admin'. I ran mimikatz, have hashes, logged in with a password as a m...svc user. what next?

junior hazel
#

Someone finish the Crackmapexec module ? I need help plz

south glen
#

can anyone guide me in knowledge check portion of "getting started" module .

#

I am stuck and not able to figure out how to upload the payload on GetSimple csm

autumn pilot
#

have you checked if there is a module about the vulnerability you are poking within metasploit?

south glen
#

yes

#

but i want to do it manually

autumn pilot
#

then search for blog posts of the vulnerability

#

usually, people explain how they go to X, Y and Z

south glen
#

okay thanks for responding @autumn pilot

storm matrix
#

Hello guys, I need a bit help in HTB Academy, in Network Enumeration with Nmap

#

But its not working

#

Any ideas why?

weak stirrup
#

I am working on 'Active Directory Enumeration & Attacks' and cannot get some of the examples to work. How do I use the 'net' command. the 'accounts' option net accounts does not appear to be a option in net. I get the message:

PS /home/htb-student> net accounts
Invalid command: net accounts
Usage:
...

in the usage list accounts is not a valid option

storm matrix
#

net users?

weak stirrup
#

i am really unclear what is it asking me to do. it gave me an ip for a linux machine for which too ssh to... then it asks for information on windows policies but i don't know what windows machine i am supposed to be looking at.

Questions

Answer the question(s) below to complete this Section and earn cubes!

Target: 10.129.155.176

Life Left: 79 minutes

SSH to 10.129.155.176 with user "htb-student" and password "HTB_@cademy_stdnt!"
+ 0 What is the default Minimum password length when a new domain is created? (One number) 
#

so the net command i can get to is the linux one...

#

the linux based query command require a windows computer to 'look at'

#

for what new domain?

gusty fulcrum
glass pecan
#

attacking common services - DNS, I got the flag but for some reason says is wrong, no space at beginning or end, flag-format HTB{s3c3r3t}

pliant flame
#

Attacking Thick Client Applications Dumping the File to Memory.
in the Module it says "The specific map's size is 0000000000003000, and if we double-click on it, we will see the magic bytes MZ in the ASCII .." if i double click on the one with that size, the magic byte MZ is not there.

the only way i get that Magic Byte is on the "...401000" Adress.

my problem now is no matter which of those i dump to memory and run strings on, neither gives me an output.

i only get "no matching files were found" when i use strings.

if someone could lend me a hand that would be greatly appreciated.

honest hazel
#

have you tried strings -el?

summer lava
rustic sage
rustic sage
#

please remove that screenshot you're spoiling the lab.

1) Check for leading/trailing whitespaces.
2) If there is none, and you're sure you're copying/pasting right, you most likely found a flag for a previous/future question
weak stirrup
storm matrix
#

And.. yea.. I will try to restart it, but not sure about that, there are no previous boxes

rustic sage
summer lava
storm matrix
pliant flame
rustic sage
#

you need to dump the correct memory address. you cannot just dump any memory address

pliant flame
rustic sage
pliant flame
#

yes ive read the instructions and i know what it tells me to dump. The problem is no matter if dump the map with the file size 0000003000 or the one were i see the magic byte MZ is giving me either the correct output if i use strings, nor is containing a .net executable.

i mean either im completly blind rn or i need to restart the instance. but ill take a short break. Thanks for your help

calm jetty
#

Hi, Im looking for help with the password attacks - pass the hash - final question. Please let me know if you can help and ill provide more details. Thanks ❤️

heady tusk
#

sure, dm me

cold yoke
#

How do people go about unlocking modules? I’m seeing some for 500-1000 cubes. Unless I’m dropping 100s of dollars how do I get access to these modules?

autumn pilot
#

By winning either a CTF that HTB has sponsored or a giveaway

sacred ermine
#

anyone who did AD enum&Attack skills assesment 1 ??
I am unable to Import the PowerView, I've had enough I need a phocologist....

heady tusk
velvet atlas
river token
#

I'm using Pwnbox in the file transfer lab and am seeing the RDP is unstable. I've reset the target but continually get a dropped connection and can't work through the exercise. Any suggestions? Honestly I just need the quick answer and am happy to move on. I know what to do the machine is just unstable

velvet atlas
#

sometimes I have had to rest boxes like 15 times to get the proper ports/results even after waiting multiple mins on each reset. I pretty much only use ovpn now as pwnbox kept messing up

river token
#

ive reset the pwn box several times and the labs 😦

#

and am now getting incorrect password after trying rdesktop instead of remmina or xfree

topaz zenith
#

So I am on the last question of the Active Subdomain Enumeration module and I feel like I am in the right place to get the answer for the, Submit the number of all "A" records from all zones as the answer. But it is coming back incorrect. I have used the dig AXFR inlanefreight.htb @rustic sageIP to bring up all A records. Am I missing something?

#

Do I need to do this for all of the zones that appear on this list? A little confusing probably haven't quite grasped it yet.

pulsar spade
#

Hello everyone, I am a new member, it is nice to meet all of you and I hope to become friends with you.

placid quest
#

@pulsar spade welcome to the club

pulsar spade
drowsy ingot
#

in Using the Metasploit Framework
Which version of Metasploit is free and can be used only through a CLI?
Can anyone give me a hint how to find which version?

heady tusk
heady tusk
calm jetty
#

Hi, Im looking for help with the password attacks - pass the hash - final question. Please let me know if you can help and ill provide more details. Thanks ❤️

zinc marsh
#

someone can give me a hand with dns enumeration im a bit lost

obtuse kayak
#

hi everyone

#

someone for a hint with a question in bug bounty process please?

topaz zenith
topaz zenith
heady tusk
#

I believe there was one where dig should work. The others indeed don't work because they aren't zones.

harsh sun
#

Working on the XSS module and having trouble with the Phishing section. Whenever I try to set up a listener - either netcat or PHP - it comes back complaining that 0.0.0.0:80 is already in use on my PwnBox instance. Any ideas?

#

Also tried using the tun0 address with port 80 and it too comes back that it's in use.

autumn pilot
#

you can use a different port

harsh sun
placid quest
#

@idle cargo where are you stuck

heady tusk
#

Anyone able to give me a hint for AD Enum & Attacks skill assessment part two? feel free to dm me, I'll share more details where I currently am

strange zenith
#

how can i lern to hack

rustic sage
#

Anybody has discount code for the prolabs?

strange zenith
#

how can i learn to hack

fathom pendant
sleek urchin
#

hello all I am about to finish the whole Bug Bounty Hunter path but a i have 2-3 sections/questions to finish, any help will appreciated 😉

#

Broken Authentication: Predictable Reset Token and Server-side Attacks: Nginx Reverse Proxy & AJP

red current
#

I'm in the SOCKS5 Tunneling with Chisel section in Pivoting, Tunneling and Port Forwarding and I'm running into an issue with the final command. I've been able to get everything else to work and confirm that it's working up to this point. However, when I run the $ proxychains xfreerdp /v:172.16.5.19 /u:victor /p:pass@123 I get a failed to connect to 172.16.5.19. Has anyone else come across this? Everything up to this has connected and I'm getting the successfully completed messages and my listeners are running. Never mind. It helps to have your proxychains4.conf file properly configured!

dim cosmos
#

gez the new attacking thick client applications exercise is madness....

dim cosmos
#

my f8 key is worn out lol

rustic sage
versed frost
#

Hey all, in Password Attacks Module, Attacking Active Directory & NTDS.dit Section, when I got through the target and obtained the ntds.dit file, moved it to my machine, how can I dump the hashes of it? I solved the question with the cme method, however, I did not know how to get a valuable info out of this file. Though I tried secretsdump.py but it needs SYSTEM hive or bootkey which I don't have

sleek urchin
zinc marsh
#

someone can give me a hand with imap/pop3 part

#

in the module footprinting?

rustic sage
rugged veldt
#

For attacking common services medium I have found the 2nd ftp server but unable to run an Nmap scan with ftp-* scripts to enum it further. What am I missing?

zinc marsh
#

someone who completed footprinting please

rugged veldt
#

Nvm had to restart vm and reset instsnce 3 times

rustic sage
#

Can I dm someone about skills assesment - medium lab in password attacks module?

strange zenith
#

Ok thanks

quiet ember
sleek urchin
#

can i dm someone about **Broken Authentication: Predictable Reset Token **(only question1)

#

?

agile rapids
#

hi im having trouble doing ssh keys on the getting started module

sleek urchin
agile rapids
#

@sleek urchin i tryed chmod 600 , i thought that was the lowest

fathom pendant
#

600 is technically fine

#

as that just translates to rw-;---;--- access to the file

#

400 is r--;--;---

#

aka readonly

#

*tho if you have control of the file it will always be rw to you

agile rapids
#

i figured what i should do is cp the key file to user 2 then do shh root@10.10.10.10 -i keyfile

fathom pendant
#

or are root

agile rapids
#

@fathom pendant or am i missing something with the pubkeys

fathom pendant
#

what error (if any) are you getting when you do it

#

pubkey won't do anything you need the private key

#

aka the id_rsa

agile rapids
#

no error just hanging terminal

#

yeh the id_rsa

sleek urchin
fathom pendant
#

if it's hanging try resetting the excersize

#

and trying again

agile rapids
#

hmmm ok

fathom pendant
#

wait

#

nevermind

#

I found your error

#

you said root@10.10.10.10

#

is that the actual ip of the target?

agile rapids
#

10.10.10.10 is just example

fathom pendant
#

or did you do 10.10.10.10 as an example

#

ok

rugged veldt
#

Anyone able to help with Attacking Common Services Hard? Able to RDP with user f.. from there am trying to use sqlcmd with no luck

agile rapids
#

weird though i do it over and over all i get is hanging terminal

#

il try couple more times

#

reset docker etc..

charred canopy
#

anyone wanna do binexp/RE challenges w me

fathom pendant
charred canopy
#

pls do point me in the right direction oh gracious discord mod

fathom pendant
#

I'm not a mod and learn to read

#

i pointed you to the rules and welcome pages

sleek urchin
agile rapids
#

@sleek urchin yeh thats what i did

rugged veldt
#

😭

agile rapids
#

i just did ''' cp /root/.ssh/id_rsa .ssh/id_rsa '''

fathom pendant
#

your copying it to where though?

#

:)

#

if you don't copy it to YOUR machine how can you use it?

#

the reason it's hanging is because it's trying to ssh to itself

#

if you're user2@system and attempting to do this then yeah

#

that's why it's hanging

sleek urchin
fathom pendant
#

also that's not how you code block you use ` and ```

sleek urchin
#

you can

agile rapids
#

@fathom pendant hmmm yeh thats the case im user2... so your saying i should copy it to user1 or directlly to my machine?

fathom pendant
#

directly to your system

agile rapids
#

@fathom pendant ok i understand, thats just strange to me i can't just do it from user2

fathom pendant
#

either by doing python -m http.server then on your system in a different terminal window wget http://ip/id_rsa

#

because of what ssh is

fathom pendant
#

ssh is a secure shell protocol to remote into a system... but you're already interacting with that system through ssh

#

meaning it's trying to call that protocol on itself while it's already in use

#

ssh is NOT meant to be a privilege escalation technique from within the shell

agile rapids
#

@fathom pendant i guess its just an ssh thing, cause ive done this lots with netcat

fathom pendant
#

netcat is a different protocol/tool entirely

#

netcat is generally used with reverse shells

#

ssh is it's own dedicated service

#

netcat reverse/bind shells are temporary they are not the same

agile rapids
#

@fathom pendant interesting thanks, i try the otherway then

#

@fathom pendant ohh now i remmber the problem

#

i did this before

#

it keeps asking me for keyfile

#

sorry not keyfile password to login as root

#

on my system

fathom pendant
#

yes because it didn't recognize the keyfile you're using as a privatekey

#

so it defaults to the next auth system

agile rapids
#

@fathom pendant ok i guess i nned to the exact file through wget

fathom pendant
#

yes

#

the PRIVATE key is unique to that individual user

#

it cannot be YOUR private key

agile rapids
#

so now im trying to do wget problem is i can't becuase i have no access to user2

#

so im wondering how do i download a file i have no ssh access to because user 2 was only accomplish through lateral movement?

fathom pendant
#

ssh user1; lateral to user2

#

start the http server as user2

#

you use wget from YOUR system

#

to the target IP

gentle root
#

I keep getting a error trying to "Use the cracked password of the user Kira and log in to the host and crack the "id_rsa" SSH key. Then, submit the password for the SSH key as the answer." ---- ──╼ [★]$ ssh2john.py id_rsa > hashes.txt
Traceback (most recent call last):
File "/usr/share/john/ssh2john.py", line 193, in <module>
read_private_key(filename)
File "/usr/share/john/ssh2john.py", line 103, in read_private_key
data = base64.decodestring(data)
AttributeError: module 'base64' has no attribute 'decodestring'

#

I thought this was exactly what I was supposed to be doing, am I doing something wrong here?

fathom pendant
#

it's because base64.decodestring() is deprecated in python3, you'd need to install an older version of python (2.7) for it to work

#

or more accurately; the function was renamed/changed

gentle root
#

You're a wizard

fathom pendant
#

i ran into that issue too

#

the only other way would be to edit that line to the new call function in python 3.x

#

I forget what it is though

gentle root
#

You taking CPTS ?

fathom pendant
#

I'm doing the path yeah

gentle root
#

How's progress?

fathom pendant
#

had to take a break on progress life stuff happening

gentle root
#

Sounds awesome, you're going to kill it 🙂

rugged veldt
#

Anyone able to help with Attacking Common Services Hard? Able to RDP with user f.. from there am trying to use sqlcmd with no luck

#

Have also attempted sqsh from my kali VM with no success

void gate
#

AD Enumeration & Attacks - Skills Assessment Part I
Q3 Crack the account's password. Submit the cleartext value.

Hoping for a nudge. I've tried to upload PowerView but can't Import Module [Error - doesn't exist]. I can't get Rubeus to work and Mimikatz is hanging when I try to run it. any direction would be appreciated

SOLVED: || I used https://www.revshells.com/ to generate a PowerShell #3 (Base64) Reverse Shell and connected to my Kali netcat listener. This gave me a more stable shell than the webshell. From here I used PowerView that I had previously uploaded and it worked without issue. ||

sleek urchin
odd notch
#

So enumerating over a box I managed to figure the username from a file... But I would have never thought about using the email as a password. I'm kinda afraid I should have known better?

fathom pendant
sleek urchin
#

plus I really want to see the full path complete

fathom pendant
#

then you're rushing yourself and probably overlooking something simple. Take a break like an hour or two, let your mind reset and reapproach the question

fathom pendant
#

(Predictable Reset Token) I'd assume means that it's probably something simple in the section/module that you've overlooked

sleek urchin
rugged veldt
#

Ok all my sql login attempts are failing

fathom pendant
rugged veldt
#

I figured it out, I didn't even need to use a login

#

Because when u think abt it u are already windows authenticated when u RDP in

dim cosmos
#

ive underestimated the difficulty level of hte documentation and reporting lab LUL

frigid summitBOT
#
slapman#3353 has been warned

Reason: Mass mention

light fern
#

any1 had to crack a md5 joomla hash before struggling

calm jetty
#

Looking for help with pass the hash, been stuck on it for days, any help guidance would be massively helpful

autumn pilot
#

which step

turbid tartan
#

Perform the ExtraSids attack to compromise the parent domain from the Linux attack host. After compromising the parent domain obtain the NTLM hash for the Domain Admin user bross. Submit this hash as your answer. Im struggling here. How do i search for the user bross

autumn pilot
#

if you have answered the previous two questions, you can combine the answers into the command for the 3rd question

turbid tartan
#

i cant find the user bross

autumn pilot
#

what if you don't need that user, but something else

turbid tartan
#

i got the ticket but im not able to secretdump the dc01 for credentials/ntml hashes

autumn pilot
#

Submit this hash as your answer.

turbid tartan
#

yeah i know but i cant find the hash of said user bross

autumn pilot
#

my bad, was looking at the wrong exercise

#

so, basically what I did is to use some of the "ACL Abuse Tactics", and then since I already control a users password I can simply dump hashes and grep for the username, since there quite the number of users in the environment

paper crag
#

This doesn't work for me...it then complains that it can't get the certificate from the server...

turbid tartan
rustic sage
#

Hi all

#

I am working on password attack hard lab and I am stuck at cracking the ||encrypted VHD file||. Can I dm anyone?
I don't know what I am supposed to do with this file at all, cracking was the first thing that came to mind after playing with it but still don't know.

autumn pilot
rustic sage
#

@autumn pilot you saved my life

#

I just noticed that john has it

#

thanks mate

#

One more sanity check @autumn pilot
Is the file supposed to be corrupted or my file was corrupted somewhere between transfers?

autumn pilot
#

it could be between transfer

rustic sage
#

Right, cause the file command has thrown errors

autumn pilot
#

The file is rather big, which affects the transfer, e.g. it might not transfer the whole file but a portion which won't work

rustic sage
#

I will work around it

rustic sage
#

ZUP HUD working unstable. Any similar experiences?

dim cosmos
#

anyone around who has done the Thick Client Web Vuln assessment? I've managed to download fatty-server but it isnt running. I can extract contents and all looks ok, but would be good to discuss with someone who has done it

fair hill
#

guys if i subscribe in the Platinum Subscription do i get tier 2 modules or just the cubs ?

dim cosmos
#

woohoo!

#

that last thick client one was absolutely awful

zinc marsh
#

cannot find 1 answer in the SNMP part in Footprinting

#

i found the flag and the dev mail

dim cosmos
zinc marsh
#

but the version idk why is the wrong answer

zinc marsh
#

i must have been using a space or something

dim cosmos
#

been there many times

cyan ginkgo
#

stuck at medium passwd attack i got user jason and ssh into him but i cant seem to find out where to go from there

rustic sage
#

I been working on password attack hard lab for a few hours now, ||I finally managed to mount the disk only to find out there is nothing inside||. I need to dm someone about this, is anyone available?

rustic sage
rustic sage
#

let me know if that's correct so I delete it

elfin nacelle
#

Can someone please help me with Module: Web Attacks. Section: Bypassing Encoded References?

rustic sage
#

yes that's right you can delete it. let me look into this article you used

rustic sage
rustic sage
#

I am so close to admin

rustic sage
#

ty, I will probably look for other linux based solutions around here

fierce island
#

I am seriously struggling with and feeling like I am burning out with Attacking common services - easy. Anyone care to toss me a lifeline in DMs?

rustic sage
#

btw @rustic sage, does the file system show corrupted to you?

weak stirrup
#

i am working on Active Directory Enumeration & Attacks : Kerberoasting - from Linux and when i try to run the example command GetUserSPNs.py -dc-ip 172.16.5.5 INLANEFREIGHT.LOCAL/forend it requires a password which i can not find given to me. is this something i am supposed to get by other means or did i miss it in the text of the lesson?

rustic sage
#

that module was so long ago I honestly can't remember.

#

no worries, I have left it out for now, I will do it later

rustic sage
hot merlin
#

good days .. i have a problem
'Exploiting Web Vulnerabilities in Thick-Client Applications'
After I edit the xml file and manifest I compile the app again but it gives me error at startup, anyone for nudges?

hot merlin
rustic sage
hot merlin
#

ok sorry but I didn't mess up the lab because the lab tells it what to do step by step, but unfortunately recompiling and running it gives me error

#

I'm stuck 😦

#

I've already done the three assessments as well

rustic sage
hot merlin
#

in the instructions it says exactly how to change it, but I don't want to do spoilers

#

nothing much just a different tcp port

hot merlin
#

soory

#

sorry

rustic sage
#

it looks like they've updated the lab and I've not completed the updated version so I won't be able to help you

broken warren
#

in the dns enumeration with python module i tried running the script and none of my imports are recognized but when i do pip install dnspython it says its already satisified. Im cornfused as to what im missing

fierce island
silver veldt
#

im stuck in the last question of SMB that says "What is the full system path of that specific share?"
I found the path, but it doesn't say correct. Somebody mentioned this question has a format issue with the answer. can somebody help?

simple zephyr
#

anyone complete the Exploiting Web Vulnerabilities in Thick-Client Applications yet, i have been stuck on this for days

silver veldt
#

footprinting module SMB section

atomic ruin
#

oh boy, finally getting to the AD modules, feel like there are going to put up a fight

fathom pendant
silver veldt
#

thanks, got it

fathom pendant
#

<@&861185840277487616> ^

autumn pilot
#

thanks

rustic sage
simple zephyr
rustic sage
north tulip
#

WHAT IS fatty-client.jar

zinc marsh
#

someone who completed the module footprinting can help me with oracle?

simple zephyr
#

right now I am at the part where you edit the code and rebuild the jar

rustic sage
north tulip
#

WHAT IS fatty-client.jar

zinc marsh
rustic sage
simple zephyr
#

not that i can see 😦

fathom pendant
north tulip
fathom pendant
rustic sage
simple zephyr
#

ok thanks

weak stirrup
#

how long should Get-DomainObjectACL -ResolveGUIDs -Identity * | ? {$_.SecurityIdentifier -eq $sid} take to run... i have been waiting more then a few minutes for it to return ...

rustic sage
shadow shard
#

what apps do I need to start hacking

rustic sage
zinc marsh
shadow shard
#

ik a little python

zinc marsh
#

i would go to tryhackme first and omplete all the paths there

shadow shard
#

thx

#

can u send an invite

#

?

zinc marsh
#

then move to hackthebox academy and app.hackthebox when u are done

shadow shard
#

ok i joined

zinc marsh
zinc marsh
#

then

weak stirrup
rustic sage
weak stirrup
# weak stirrup interesting ok thanks

i am actually trying to do the second to last question is there a faster way to acquire the ActiveDirectoryRights that the user forend has over the user dpayne i thought that one command was going to spam out the answer to both and my task was digging through the output. i dont really see an alternative given ... the bloodhound solution seems equally long-returning

manic perch
#

I'm on the first box for Attacking Enterprise Networks and noticed some services seem to be failing, after getting a shell I saw this:

df -h
Filesystem                         Size  Used Avail Use% Mounted on
/dev/mapper/ubuntu--vg-ubuntu--lv   14G   14G     0 100% /

That's not intended right?

weak stirrup
zinc marsh
#

is there anyway to get ipmi credentials without using msfconsole

rustic sage
#

guys

#

i need help

#

please

fathom pendant
#

if it's related to an academy module just ask; if it's about an account being hacked and looking for someone to help with that - please read the #rules

rustic sage
#

wait a sec i will send what's my problem

hollow spade
#

Module: attacking web applications with ffuf
Skills Assessment last question.

Could someone please help me with the wordlist selection to get the value of the parameter?

You can DM me too

native comet
#

@rustic sage Were you able to find the parameters?

#

If you did there should be a wordlist in the SecList try them

hollow spade
#

@native comet I think your comment was meant for me. I've tried MANY lists in there. None are returning any results

weak stirrup
#

i am trying to send a msg it is not showing up on my screen and when i tried to send it again i got a warning about duplication. is this normal?

weak stirrup
#

can someone answer some questions about secretsdump.py getting a reset by peer issue for the dsync module

native comet
#

Use mimikatz

weak stirrup
# native comet Use mimikatz

the mimikatz example from the module does not work on the administstrator account as it is suggested it should i get the following error ERROR kuhl_m_lsadump_dcsync ; GetNCChanges: 0x000020f7 (8439) when i google this error i get limited information .. from what i gather user being used is not privileged enough to execute... i am still just trying to follow the examples given on the page did i miss a step?

heady tusk
weak stirrup
native comet
hazy grotto
#

@vital adder Are you available by chance? I see you helped a few people on a question that i am currently on. XSS Phishing

zinc marsh
#

need help with public keys

native comet
#

?

acoustic owl
weak stirrup
zinc marsh
#

someone who completed footprinting

#

can help me with the first lab

heady tusk
broken crystal
#

is someone here know lua?

zinc marsh
#

dont askk to ask just ask

#

just ask ur question about lua

thorn urchin
zinc marsh
#

instead of looking for someone who know lua

thorn urchin
#

as well as channels you should read as I strongly suspect your question has nothing to do with modules channel

rustic sage
#

The attacks used to generate the example files used in this section will be covered in a wireless attacks module in HTB Academy.🤔 🤔

bitter zenith
#

Hey ! Can someone give me a hint about the XSS Skill Assessment (or at least, confirming me that I do wrong) pls ? ^^
It's about choosing the good payload cause I tried a lot but nothing looks promising

acoustic owl
bitter zenith
#

Getting a request back at my webserver ^^'

#

I found the vulnerable form, tried a lot of payload, my webserver is OK and the scripts are too (tested them with an other window), but I can't seem to find a working payload to get a request to my webserver since my PHP webserv show nothing

acoustic owl
acoustic owl
stiff moon
#

anyone that have done Exploiting Web Vulnerabilities in Thick-Client Applications? im stuck on the very last part and need help

dapper star
#

Anyone here that finished the footprinting easy lab and did not use the hint? I want to see how you got the credentials... I used a method that was not discussed in the modules yet, so I want to know if there is any other way that I missed. Dm's are open. (I got the flag)

thorn urchin
#

what?

zinc marsh
#

can u dm please. I completed it but with the hint

elfin nacelle
#

Can someone please help me with Module: Web Attacks. Section: Bypassing Encoded References. Can someone please dm me?

hollow thunder
#

can i dm someone about the file inclusion (LFI) assessment

#

Trying to poison the panel.

zinc marsh
#

dm

alpine kindle
#

Hello, I got the answer for the skills assessment for the module Web Service & API Attacks by using SOAPAction spoofing, not SQLi as instructed. I'd really like to know how to do it using SQLi if anyone solved it using that method

late creek
#

I need help with root on Busqueda

zinc marsh
#

and dm if u want

twin gulch
#

Hey guys, I’m at password attack hard lab skill assessment. I’ve tried the mut and normal password file to attack Johannas password, with crackmapexec, hydra and crowbar, but there seems to be something wrong, any clue to go further?

manic magnet
#

I have question:

When I use kerberos on a linux system, why do I need to append the realm after each username? E.g.
carlos@inlanefreight.htb
or svc_workstations@inlanefreight.htb ?

thorn urchin
#

because kerberos

#

kerberos looooooves proper domain names

manic magnet
#

ok haha

manic magnet
#

I am currently on the password attacks module (PtT from Linux) I am stuck on the optional exercises.
I don't know how I can figure out the ip of the DC01 to add it to the hosts file. Everything else is working just that one piece missing

#

I installed proxychains. Configured it. I downloaded chisel and started it. I used the correct ccname file export. I edit the hosts file for ms01 but don't know what to add for dc01. I also installed the kerberos authentication package and configured it. At last I started chisel on ms01

#

I might have figured it out though it was a bit of a hacky solution imo

jolly dagger
#

Working on x86 buffer overflow for linux. I sent my exploit through gdb, but there's a bunch of 0xc2 or what I believe are RET instructions between each NOP. I'm unsure why this is happening. And the rest of my shellcode isn't appearing next my NOP slide. Any resources would be appreciated. Thanks

rustic sage
#

Hi folks

#

I am stuck at "attacking sql databases" from attacking common services module.
||I have tried everything mentioned on the module including dumping databases, impersonation, file load, command execution. Nothing works||, any help will be highly appreciated.

manic magnet
#

yes I think so

#

I think the ports are wrong. Try out the ports given in the Linux Pass The TIcket section of the module

#

this might fix it

#

also did you setup your hosts file ?

gritty lagoon
#

Hello, I am trying to pass one of the initial htb machines, and I am using john but it tells me no such file or directory, and I did it as the guide, any help pls?

manic magnet
#

dm me

thorn urchin
#

not module relevant. read #rules and #welcome you can verify your account and access the other channels and ask on a more appropriate channel.

quasi wave
#

Would doing the CRT path prepare me for OSCP?

thorn urchin
quasi wave
#

Ok

quartz quest
#

hi,
I think there is some issue with LFI module. Its giving me errors

#

and sometimes its giving 500 sc

#

500 SC

#

resetted twice

thorn urchin
#

that's pretty normal if your payload is bad

placid quest
#

@quartz quest change the apache2 to nginx

frank vine
#

Hey everyone, I need a bit of direction with footprinting lab medium if anyone could help? ||I have found a nfs share which I mounted and got alex creds, then found what appears to be creds in smb share devshare for user sa. I have tried to use both creds to remote connect to the machine but its not going anywhere. When I have tried using xfreerdp on the pwnbox it is giving an error of DISPLAY not being set properly. I found on the internet that this env variable should be set to host:0.0 but im still getting the error. Does anyone know if this is the correct setting for x11 DISPLAY env variable on the in-browser pwnbox? || Thanks in advance.

frank vine
# rustic sage Hey

I do yes, I have also tried to connect to it with a kali vm but it hasn't worked either on rdp?

rustic sage
#

Let me check my notes real quick...

fathom pendant
frank vine
fathom pendant
#

glad you were able to solve it :)

zinc marsh
#

somenone can help me with this error

#

Please check that the $DISPLAY environment variable is properly set.

#

when i try to use xfreerdp

rustic sage
turbid tartan
#

im stuck on ad skill assesment 2 first question how do i get the hash or user ? i just need a tip from there im good

rustic sage
fathom pendant
smoky viper
#

Does anyone know how to get the FQDN of the host where the last octet ends with "x.x.x.203" DNS question on htb academy.

I've used the axfr zone transfer internal and also brute forced using the feirce list, but nothing

rustic sage
#

hello

rustic sage
rustic sage
zinc marsh
#

and try different wordlists

thorn shale
#

can you support me with:
module: Password attacks
section: Protected files
i registered under kira, found id_rsa, but... this is a stupid question.. i can't figure out how to work with this file, because john is not on kira, the locate command gives a warning 8 days error, and ssh2john.py just won't run
i tried to transfer rs_id via ssh, i tried to transfer ssh2john from my machine, but i always get permission denied

rustic sage
thorn shale
rustic sage
#

maybe you should install it 🙂

thorn shale
#

i tried

#

but kira no sudo

rustic sage
fathom pendant
thorn shale
#

when I tried to do something i got "kira is not in the sudoers file"

fathom pendant
#

why don't you transfer the file to your system to work with it

thorn shale
#

via ssh?

#

permission denied

fathom pendant
#

why not through something like python -m http.server or along those lines

#

I would definitely go over file transfer module before continuing

#

because this module requires a lot of back and forth

placid quest
#

@thorn shale download the file to your attacking machine

thorn shale
placid quest
#

@thorn shale use pwncat-cs

round gale
#

hi, in HTB academy, MASS IDOR Enumeration. I put some echo commands in the second for loop but those echo commands dont get executed. doesnt the second for loop get executed?

zinc marsh
#

dm if someone need help

thorn shale
placid quest
#

@thorn shale no problem

undone fern
#

Dear, It is there. Use the FETCH command. As per the question, this must be in the body of the email.

#

Dear, It is there. Use the FETCH command. As per the question, this must be in the body of the email.

smoky snow
inner talon
#

Hi everyone, do you have any hints for the last question for the POP3/IMAP module?

fathom pendant
gentle root
mellow ember
#

Has anyone done the TE.TE section in HTTP attacks? I'm having trouble. I can't even get a 405. I've tried all of the payloads mentioned inthe section (spaces, vertical, horizontal tabs) as well as the payloads from payloadallthethings. Nothing

gentle root
#

Thanks Marcie 🙂

fathom pendant
gentle root
#

Yeah, I mean... with how quickly this chat fills up if you have to scroll back that far over 2 weeks they've definitely figured it out

inner talon
fathom pendant
#

Not sure how you're confused, the module explains how to connect to the IMAP server

inner talon
#

I actually already logged into the server with the credentials of a minimal account(the one beginning with "r"). I am not sure if I understand the question correctly because I think it is related to the previous question where I found the admin's email

fathom pendant
#

then it's just finding the email

#

might be best to use an email client like evolution to access emails