#modules

1 messages Β· Page 70 of 1

fathom pendant
#

it makes email enum a lot better

turbid tartan
#

im stuck on ad skill assesment 2 i found the first user but at the scond user i tried password spraying and it seems its the right approach but cme doenst work and i cant import the DomainSpray.ps1

inner talon
heady tusk
fathom pendant
heady tusk
fathom pendant
small steppe
#

Request for Help. Module: Nessus Skills Assessment
Q: Navigate to the web interface at the end of this section and log in with the provided credentials. Once logged in, perform a BASIC NETWORK SCAN (modify the scan template to scan ALL ports, leave all other options the same) against the target: 172.16.16.100. Additionally, set up the scan to be authenticated using administrator:Academy_VA_adm1! as the credentials.

The scan will take up to 60 minutes to finish. Note: It may take 1-2 minutes for your target instance to spawn. Additionally, it may take up to an hour for the scan to run

Alternatively, use the pre-populated scan data to answer the questions below without having to wait for the scan to finish but feel free to practice configuring and running it.


Nessus doesnt start on the pwnbox. I get an error "Failed to start nessusd.service: Unit nessusd.service not found."

That aside -- I'm not waiting 60 minutes to run a scan when there's a sample scan provided. However, I cant seem to locate where the pre-populated scan data is. I spooled up the pwnbox and dont see it in the home directory of the pwnbox. Any help would be very welcomed.

zinc marsh
#

dm if someone need help

fathom pendant
fathom pendant
#

I believe the module also informs you of that

inner talon
turbid tartan
heady tusk
small steppe
# fathom pendant it's in the box that you spawn you can rdp in and open firefox and navigate to t...

So I tried both xfreerdp and rdesktop to authenticate into the spawned host but Im getting the following errors respectively.

xfreerdp
└─$ xfreerdp /u:'htb-student' /p:'HTB_@cademy_student!' /v:10.129.46.86
[10:57:05:891] [18588:18589] [ERROR][com.freerdp.core] - freerdp_tcp_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_FAILED [0x00020006]
[10:57:05:893] [18588:18589] [ERROR][com.freerdp.core] - failed to connect to 10.129.46.86

rdesktop
└─$ rdesktop -u 'htb-student' -p 'HTB_@cademy_student!' 10.129.46.86
Autoselecting keyboard map 'en-us' from locale
Core(error): tcp_connect(), unable to connect to 10.129.46.86

rustic sage
#

Hey guys, qq: Can we ask questions related to modules here? For example if we are stuck with a task etc? Thanks

fathom pendant
small steppe
fathom pendant
#

one moment

rustic sage
# inner talon yep

Thanks for confirming. I am struggling with the Attacking my first box - Nibbles and I am at step "Nibbles - Initial Foothold". I am uploading the image.php file with the reverse shell, but when I start listening to port 9443 it doesn't say 'listening to any" but rather "0.0.0.0::9443". I have checked if I have uploaded the php file correctly few times + checking if there are any typos and all looks good. Do you have a clue what I have done wrong here? Thanks

fathom pendant
autumn pilot
#

you can use the --username flag in hashcat

inner talon
inner talon
#

just try

autumn pilot
#

without backupagent

small steppe
fathom pendant
rustic sage
fathom pendant
#

what module is this?

#

section?

#

I'll have to double check later but that looks correct not sure what's giving you the error then

#

try copying and pasting it in different text editors

#

hmm

inner talon
inner talon
rustic sage
fathom pendant
#

yeah john tends to be more friendly

#

hashcat likes to break a lot

#

this shouldn't be your first impression with hashcat if you're following the cpts path

#

ah

#

your school has you doing htb as the curriculum? interesting

#

password attacks has a better overview of hashcat

#

and there is a hashcat module iirc

#

not in cpts but in the academy itself

misty cedar
#

Sometimes the questions don't align with the lesson but it is teaching a lot

#

BUT THERE"S SO MUCH FREAKING READING...

#

Not when you're dyslexic xD

sterile cove
#

Is it possible to do this on moblie by chance?

small steppe
#

Request for Help. Module: OpenVAS Skills Assessment
Q: What type of FTP vulnerability is on the Linux host? (Case Sensitive, four words)

Reading the results -- its obvious what the issue is with FTP. But I guess HTB is looking for four hyper specific words? Ive tried copying and pasting a number of options from the scan results with no success.

Edit: Disregard. Solved.

torpid knoll
#

reading works fine but doing the exercises on mobile not so much

zinc marsh
#

dm if someone need help

fathom pendant
zinc marsh
#

unless is just reading in that case where u want

quartz quest
#

Can anyone help me in LFI final assessment?
I got LFI but not able to get flag or cmd execution?
Can anyone help me a bit !!
I'm missing something in between !!

heady tusk
#

I believe that's the intended way, yes. I definitely did it that way too

vivid marsh
#

Noob question, I want to use the parrotOS system in the academy but it's telling me to SSH into another machine, where to find the IP for that machine in the module?

fathom pendant
#

It's going to be the target machine from the "spawn target" button

#

The space where the IP will be is blank if you haven't spawned it yet

vivid marsh
#

aaaah I see, sneaky

#

Thanks MarcieLee, you tha real mvp

fathom pendant
#

The modules/sections generally tell you the method they want you to connect with. Skill assessments will be a bit tougher but will use the tools/techniques discussed to achieve results

fathom pendant
#

<@&861185840277487616>

thorn urchin
#

<@&861185840277487616>

urban sage
#

We got it.

thorn urchin
#

ty

acoustic owl
#

Thanks NightWolf

cursive lily
#

what is <@&861185840277487616>

#

?

sharp spoke
#

lol

acoustic owl
cursive lily
#

I am sorry !

#

What does this mean

#

Greetings! It has been determined by a member of the staff team that your nickname was breaking the rules. As a result your nickname has been randomized. Please verify your HTB account (see #welcome for how) to have your name reset to your HTB username.

#

@teal mountain

thorn urchin
#

maybe read it

languid dawn
#

We only allow usernames with ascii chars

cursive lily
#

what is ascii cahrs?

languid dawn
#

also you just pinged a random user

thorn urchin
#

means what it says it means lol

sharp spoke
#

lmfao

cursive lily
#

no

thorn urchin
#

@teal mountain knew what they were doing

cursive lily
#

@teal mountain pings a moderator

thorn urchin
#

lmao

stiff spoke
#

hi

cursive lily
#

hello

thorn urchin
cursive lily
stiff spoke
#

i need something from u ...

cursive lily
thorn urchin
sharp spoke
#

this has to be someone's alt

cursive lily
thorn urchin
cursive lily
#

asked?

languid dawn
thorn urchin
#

100% an alt

stiff spoke
#

i need usb to reset windows pasword with out formatting (not hacking or craking)

sharp spoke
#

bruh

cursive lily
#

Very new to HTB and ethical hacking. Thank you in advance.

sharp spoke
#

wrong channel

stiff spoke
#

wrong ???

urban sage
sharp spoke
#

friendly reminder to encrypt your drives

stiff spoke
#

wat how

#

alo

thorn urchin
winged hedge
thorn urchin
#

πŸ‘

frigid summitBOT
#

Here you go! :WIZARD6:

cursive lily
#

why did mute?

#

admin no reply

cursive lily
zenith crow
#

Hello

thorn urchin
cursive lily
south glen
#

is any one on "network enumeration with Nmap" module - service enumeration section

fathom pendant
#

It's better to just ask the question

#

A good read on how to ask better questions in this field

zinc marsh
#

someone can help scripting one thing in bash i dont really know how to do it

south glen
#

i had just got the flag from the robots.txt but it seems not to be the correct flag

#

and i can not find a flag any where else

fathom pendant
#

Make sure there's no weird spaces in front or behind your copy/paste

south glen
#

already checked everything properly

fathom pendant
#

Even if it "looks" right sometimes it's weird and adds in Unicode characters that are 0space

south glen
#

can i dm you the flag

fathom pendant
#

Yeah

simple zephyr
#

just curious is Attacking Common Applications - Skills Assessment III a newly added assessment?

zinc marsh
zinc marsh
#

the name.txt strings here STRING.inlanefreight.htb

fathom pendant
#

What are you trying to achieve with this in clear words not just commands

simple zephyr
fathom pendant
#

If you break your command/goal down then you might be able to get it better

autumn mirage
#

guys, i just finished PIVOTING, TUNNELING, AND PORT FORWARDING module and have some question on final step, because i have some suspicions that i solved it unintended way

fierce minnow
#

@surreal rain, I know a way how to bypass the chat filter (aka Automod) and say the N-word and other (racial) slurs.
I can tell you how I did that and how to fix it, but I want some "gold" in return.

autumn mirage
#

can i pm someone or maybe discuss right here if it not prohibited

fierce minnow
fathom pendant
fathom pendant
#

this isn't the way nor the right place

autumn mirage
fierce minnow
fathom pendant
#

What you're doing now is an easy way to get yourself banned

fathom pendant
#

i don't recall if I asked jared about it

fierce minnow
fathom pendant
#

cool story bro they can just ban/mute people manually still

#

Β―_(ツ)_/Β―

thorn urchin
fierce minnow
thorn urchin
#

weve already known of the bypass

fierce minnow
#

Then why they havenΒ΄t fixed it yet?

#

Lmao

sterile hawk
#

Automod bots are best effort, we'll just ban anyone we see saying slurs tipsfedora

fierce minnow
#

Bruh, then it means no gold for me apensive

sterile hawk
#

If you'd like to share that would be nice

fathom pendant
#

there's no real incentive for them to reward you for it tho

thorn urchin
#

theres no gold to even give out

ocean night
#

You can get a solid high five if you like?

#

Sharing is cool.

sterile hawk
sterile hawk
ocean night
#

πŸ˜„

thorn urchin
#

what 1860s prospector is trying to get paid in gold over a naughty word filter anyways

ocean night
#

Nervous Nancy never knew noisily nibbling on nachos near Niagara Falls could result in a nasty nosebleed.

#

πŸ™ˆ

#

So many N words used

#

But seriously, if you know something, be a good person and share it. Sharing is caring

flat zodiac
rustic sage
#

I thought the n word was nuclear

man trump lied to me

zinc marsh
ocean night
#

If you're reading from a file named please yeah

#

Otherwise it's cat name.txt

#

Right?

zinc marsh
#

the file is please

#

but it doesnt work

#

:/

cursive lily
thorn urchin
ocean night
#

Mmhm

zinc marsh
cursive lily
zinc marsh
ocean night
#

Like if you do something simple, like replace the curl command with an echo ${please}, do you get the contents of the file?

surreal rain
#

πŸ‘€

ocean night
#

You're sure the file is called please? You originally said it was called name.txt?

#

(sorry for stupid question, but sometimes we derp πŸ˜‰ )

zinc marsh
#

yea

#

i changed the name because it couldnt read name.txt

tribal plume
#

Are you trying to make it do sub in the lines of please?

zinc marsh
#

if i do cat ./please i get the strings

zinc marsh
tribal plume
#

like: for i in cat blab.txt; do echo $i;done?

zinc marsh
#

grepping 'htb'

#

cat please | while read please; do curl -s http://10.129.122.65 -H "HOST: ${please}.inlanefreight.htb" | grep -i "htb";done

ocean night
#

"for i in `cat blab.txt`; do echo $i; done"

#

How the hell do you escape lol

#

There we go haha, discord being discord

tribal plume
#

I think something like for i in cat please; do curl curl -s http://10.129.122.65 -H "HOST: ${i}.inlanefreight.htb" | grep -i "htb";done

ocean night
#

Gotta wrap that cat please in "`" characters

#

Otherwise you just get cat please πŸ˜…

#

If you're still struggling hop on screen share here if you like

zinc marsh
#

am doing the information gathering web edition module

#

in the virtual hosts part

autumn pilot
#

There is already a command in the examples that mimicks the one you want to create

#

Additionally, using ffuf will make your life easier, since you have the ability to use filters to filter out any false positives

tribal plume
#

Yeah you want to use ffuf

zinc marsh
#

yea i took that one as example

#

i used ffuf already and got that list that i saved in please

#

and i wanted to use curl in all of them grepping 'htb' to get the flags

autumn pilot
#

Why do you want to grep on the domain?

zinc marsh
#

the flags are in the domains

ocean night
#

They're not greping the domain, but the result from curl?

zinc marsh
#

i did inlanefreight.htb | grep -i 'htb'

#

to get the first flag

zinc marsh
#

give error all time

ocean night
#

@zinc marsh want to jump on a screen share quickly, it'd be so much easier

zinc marsh
#

400 bad request i get

ocean night
#

Oh

autumn pilot
#

Not 100%, but this might be a good start for a script

#!/bin/bash

while read -r hostname; do
  result=$(curl -s "http://10.129.122.65" -H "HOST: ${hostname}" | grep -i "htb")
  echo "Results for ${hostname}:"
  echo "${result}"
done < name.txt```
ocean night
#

Could be an issue with the host?

zinc marsh
#

no

#

when i use curl manually it works

ocean night
#

Ok, well I guess give @autumn pilot example a go, if that fails still then something very odd is going on with the list of subdomains you have πŸ˜‰

zinc marsh
autumn pilot
#

capture it with wireshark or burp and inspect the request

zinc marsh
#

if that is important for the please list

ocean night
#

That command should work @zinc marsh - it does here anyway. Something else is screwy

#

My offer stands, otherwise good luck

zinc marsh
#

i just tried with a new file i created

#

with 1 string and my script works

#

so yea must be something wrong in the please file

ocean night
#

So.. file permissions or for some reason odd characters at end of line 🀷

#

Could be using CRLF as line end for some reason?

#

Having that passed in to the HOST header would certainly cause a bad request response

#

(the CR part of it, that is)

zinc marsh
#

yea i tried this list i did with 3 strings and the command works

#

so i will check the please file

ocean night
#

Nice

zinc marsh
#

i know why is wrong

#

this idk why

#

^[[2K

ocean night
#

Weird

#

How did you cut it?

autumn pilot
#

I'd suggest taking a break for a moment

zinc marsh
#

cut -d " " -f 1

autumn pilot
#

On top of that, if you are using the example "vHost List" you will only get one flag

zinc marsh
#

i got ittttttt

#

no how i wanted but well

#

i used the whole dns enumeration list

#

doing curl in the domain and grepping htb

unique flame
#

what do i do if I cant afford any modules and I can't afford to buy cubes

tacit lava
#

just joined can someone tech me how to hack

unique flame
#

trolling?

tacit lava
#

nope

tribal plume
unique flame
#

go on youtube and look up how to get started

tacit lava
#

kk

zinc marsh
#

go tryhackme do all the paths

#

the come to academy.hackthebox

#

and app.hackthebox and do the introduction

#

then start looking for certifications like ejpt-oscp-cpts

zinc marsh
#

there are some free modules

tacit lava
#

hoiyah

fair slate
#

HELLO

#

I'm still here

thorn urchin
#

@tacit lava and stop spamming

zinc marsh
#

dm me if someone need help

wispy marsh
#

Hey Hackers,
iam in the Getting Started module section public exploits. iam connected via VPN (the academy vpn) but the target host has a public ip from digital ocean. i have assumed that it is a private 10.x.x.x ip ?!
i belive that the target hosts are droplets at digi ocean but iam a bit suspicious

zinc marsh
#

what is the question?

#

which is the target?

#

u should have an option of spawn target when u go to the questions

thorn urchin
zinc marsh
wispy marsh
zinc marsh
#

@wispy marsh

#

if there is any target u will have this option before start the questions

#

it will create an ip to attack

wispy marsh
#

@zinc marsh i have a target thank you, i just was concerned it was an public ip from digital ocean rather a private ip in the academy ip spce.

ocean night
#

Rare exception but I believe required due to the nature of the target @wispy marsh - expected behaviour πŸ™‚

wispy marsh
#

and iam just guessing because of the pub ip

ocean night
#

Honestly I can't remember all the reasons for it being on a public droplet, but.. I know there are reasons hehe

#

Have fun!

#

We've a good relationship with them, so don't worry about hitting up the target, it's all good πŸ˜‰

solid wedge
#

First, try to update any city's name to be 'flag'. Then, delete any city. Once done, search for a city named 'flag' to get the flag. can anyone help with this

#

Its ok got it

wispy marsh
solid wedge
#

Hello is there a channel for the Bug Bounty

zinc marsh
fathom pendant
#

Questions related to the modules in the path can be asked here

fathom pendant
#

#cwes is more for questions and info on the exam Itself

sleek urchin
fathom pendant
#

Congrats

smoky snow
#

This question qsk for port 5500 but nothing is using port 5500 ever, is that a bug ? If so what answer is expected ?

sleek urchin
#

a big thanks to @acoustic owl for the help and the motivation

sleek urchin
fathom pendant
#

Read the section carefully

ocean night
#

Google ColdFusion and the services behind it πŸ˜‰

#

And yeah, read the section again

smoky snow
#

Wow, I actually entered 50 different variant of this, pretty weird that actually no 5500 port is opened

#

thanks anyway πŸ™‚

ocean night
#

Everything you need is in the section πŸ™‚

zinc marsh
#

just saw u are htb staff, u all doing an amazing job in hackthebox

ocean night
#

❀️ thank you

#

Big team effort from everyone, and the community is what has helped us to grow what we are today, so thank you too for being here!

smoky snow
ocean night
#

Started with 3 people, and we are now over 200, it's crazy!

smoky snow
#

and yeah congrats on founding HTB πŸ™‚

#

pretty awesome

#

happy 6th anniversary

ocean night
#

Some academy questions help to assess reading comprehension I believe, but if you think content can be improved or adjusted, there is the #858470491676737536 channel πŸ™‚

#

Thank you! hugthebox

zinc marsh
#

@ocean night maybe htb can create content for people that start from zero knowledge like they have in tryhackme

#

that would bring much more newbies in this world to htb

thorn urchin
ocean night
#

Exactly that πŸ™‚

thorn urchin
#

esp recommend the infosec fundementals skill path for newbs

#

except for like two modules, its all tier 0 stuff

ocean night
#

Always open to feedback if you think the tier 0 modules and starting point are still too high of an entry point, but yeah.. we've tried to tailor the content to be approachable for anyone entering the field, whether they have been active for some time and are looking to sharpen their skills, or if they're completely new and looking to get in to infosec

sleek urchin
#

if you have an injection point you can use sqlmap with --os-shell , I did this trick with SQL Injection Fundamentals and saved time

ocean night
#

More content always under development πŸ™‚

zinc marsh
hidden trellis
ocean night
#

imho, if we were to introduce paths relating to introducing people to IT in general, it might digress from the main focus of HTB which is infosec. Get where you're coming from, and yeah the more we can get people engaged and learning the better.. Just not sure if this would be a focus for our content team right now

#

2023 got a lot on its plate already πŸ˜…

zinc marsh
#

i started around 4 months ago and first came to hackthebox but didnt understand too much, then i moved to tryhackme did all the paths and returned to hackthebox.

#

just from my point of view from 0 knowledge

ocean night
#

So, was it knowledge around systems in general, e.g. interacting with a console, definition of what for example a service is, that kind of thing you think you couldn't get from us?

zinc marsh
#

i just knew coding in python, c# and c++

ocean night
#

Honest question, always open to feedback

rustic sage
smoky snow
#

I missed the challenge to sign up honestly, does it still exist somewhere ?

ocean night
#

Heh no, that went away a long time ago

#

We opened up the flood gates πŸ™ˆ

zinc marsh
#

but well now im able to help people and pwn easy and medium machies πŸ™‚

rustic sage
zinc marsh
#

yea true

#

very competitive prices

#

in hackthebox

rustic sage
#

when I get my CPTS I'm going to push to get the cert recognized as a managerial cert at where I work

ocean night
#

yaaaas

thorn urchin
ocean night
#

We're new to the cert game, but we hope that the quality of our content and assessment will show value, above what value employers already see in HTB on a CV πŸ˜‰

#

Also.. more to come

#

Watch this space πŸ˜„

thorn urchin
#

Im completely convinced that HTB is staged to become a dominant force in the infosec cert scene

rustic sage
#

well your competition will bankrupt anyone who doesn't have a company to pay for it

rustic sage
#

8000 dollar sans class lmaooooo

zinc marsh
#

for what i heard cpts is harder than oscp

ocean night
#

Pricing people out of being certified, that's just crap. Knowledge and education should be accessible to all.

zinc marsh
#

since oscp just covered exploits

thorn urchin
#

thats been the consensus

zinc marsh
#

and cpts cover all exploits and misconfigurations

rustic sage
ocean night
#

I still don't think holding a cert is a golden ticket, but if it teaches you the skills you need to hit the ground running, hell yeah

thorn urchin
#

I have yet to hear anyone say that oscp is tougher than cpts. Its solely been cpts harder than oscp so far

rustic sage
#

OSCP finally removed buffer overflow as necessary to learn

thorn urchin
#

on the otherside, the number of cpts holders are quite low. so small sample size

rustic sage
#

it's now shifted that focus to ad

thorn urchin
#

and CPTS blows them out the water in AD

rustic sage
#

I belive it

zinc marsh
#

he has the cbbh and cpts

thorn urchin
#

if youve completed the AD attacks and enumeration module for CPTS relatively comfortably, the OSCP's ad section should be free points for you(from what Ive heard about the AD sets)

ocean night
#

They removed buffer overflow? The exam module that hasn't been updated in probably nearly 10 years?

thorn urchin
#

yup

#

gone completely

ocean night
#

I think there's value in that knowledge tbh

#

I'm not shitting on offsec, I got great value from osco

#

Oscp

#

It taught me how to research, document and apply knowledge

#

But you gotta keep current

rustic sage
#

offsec has just really poor business practice imo

I shouldn't have to invest so much money for their content when other platforms offer it for a fraction of the price or free

thorn urchin
#

im sure once I tackle it ill learn some good stuff too and itll bring me value, but Im bummed at the prospect of how its almost mandatory these days if youre not already established in the field

rustic sage
#

at the point you are paying for the LinkedIn search bar

zinc marsh
rustic sage
#

because recruiters just search oscp and dm enmasse

zinc marsh
#

yea all the jobs i have seen ask for oscp

thorn urchin
rustic sage
ocean night
#

mm true

rustic sage
thorn urchin
#

id rather go for CRTO in you position then

#

after cpts πŸ˜‰

rustic sage
#

Ye I was looking at that too

ocean night
#

One thing I'm extremely proud of with HTB, is the number of people (and employers) have fed back saying they got positions in the field thanks to HTB. I just find that amazing, that we are actually achieving our goal of getting more people in to the game

rustic sage
#

our red team is brand spanking new, building a program from scratch is so hard

#

and it's just me and two others plus our director

but the really cringe part is we are in charge of pci compliance for the company

ocean night
#

ew

rustic sage
#

why that is? I don't know

ocean night
#

that was not fun

#

That surely doesn't belong with red team?

rustic sage
#

it does not.

ocean night
#

I mean yeah, advisory role perhaps, but in charge of? nah

#

policy

rustic sage
#

but we are the only people who know about penetration testing

but we contract out 90% of it to a third party but we manage that process

zinc marsh
rustic sage
#

we are working to rely less on the third party either by building a pentest team or this tool we are trialing right now makes pentesting so easy, 3 people can pentest an entire global enterprise and still have time for red team stuff

#

it's definitely been rough 😦

zinc marsh
#

well thanks for all i will go to sleep

rustic sage
#

gn, good luck tomorrow

ocean night
#

nn πŸ™‚

rugged veldt
#

I'm doing blacklist filters in file upload attacks. I used intruder to find extensions that are able to be uploaded, once checking all php related extensions no code was executed. Any ideas?

unborn ocean
opal jewel
rugged veldt
#

Whitelist filter for file uploads,

#

Do I really have to test 20+ paths..??

ocean night
#

Huh? Why reinvent the wheel?

#

Sure, adopt and improve, but you're suggesting that using other peoples tools and software is wrong?

#

lol

#

Yeah ok, you do you

#

Irrrony

#

This is a channel for discussing Academy modules. Take this in to #general if you really want to continue this

novel matrix
#

Please take this to #general or so as this has nothing related to academy.

sharp cove
#

you've been asked to move to another channel

low girder
rustic sage
#

jesus

novel matrix
#

he is banned. just gonna cause grief in the end

tidal mango
#

πŸ˜‚

rugged veldt
#

Whitelist filter for file upload attacks, can anyone help me pls?

#

I've made a custom wordlist, ran intruder on it, for those where it's been uploaded I have created another list of all the extensions, then used a curl script on each one and tried to view the response where ?cmd=id is called

#

No response on any of the extensions that were successful

hidden trellis
#

Hi can anyone please help me with a nudge for Advanced SQL injection: Skills assessment final question? I have the injection point but having trouble getting cmd execution

steady hawk
steady hawk
#

From what I can remember you're able to upload some extensions, but only a few of them will work

rugged veldt
#

😭

steady hawk
#

I just reviewed my notes, try ||double extensions||

rugged veldt
#

Yea I'm doing that atm

#

I'm trying a bigger wordlist

steady hawk
#

One of them should work, dm if you get stuck

thorn urchin
#

also use ffuf

#

faster than burp intruder

rare violet
#

Anyone here complete the Intro to Python?

rare violet
#

Python gurus, anyone point me in the direction to find this answer in the python intro module? I've tried every answer I can think of. x_coordinate = (42,) The type of foo from question 1 is <class 'set'>. What is the type of x_coordinate?

final python
ocean night
#

Maybe give a nudge rather than just the answer @final python πŸ™‚

#

All the questions within the Academy modules have the answers within the content provided. Sometimes you need to go over it a few times, either in practice or simply by re-reading

final python
ocean night
#

Cool beans

#

Thanks πŸ™‚

final python
#

Perhaps I didn't explain myself well. See you later.

ocean night
#

It's all good πŸ™‚

pine dagger
#

If its the one I think it is... just do a google for something like ||"determine type of variable python"|| and you should be able to figure it out.

ocean night
#

@rare violet Check out some information on Google about Python variable types. I'm fairly sure the information you need is within the module section you're on, but it never hurts to research yourself

pine dagger
#

Huh?

#

I was responding to a question....

ocean night
#

Whoops, sorry pinged the wrong person

pine dagger
#

πŸ™‚

ocean night
#

It's as if it never happened πŸ₯·

pine dagger
#

As if what happened?!

thorn shale
#

i have a general question
How was I supposed to guess that you need to use the python2.7, instead of the installed 3?

barren jewel
#

Anyone here who is able to give me a hint to ADEnumeratrion Assessment Part 2 question 3?

undone cypress
#

πŸ‘‹
Modul - File Inclusion
[File Inclusion Prevention]
Help me, please.
In no way can my mind figure out what else to add to the ini file so that I can get an error in the logs.

I would be grateful for help in this exercise.
File Inclusion Prevention
I understood it, so I need to insert the code:
while(substr_count($input, '../', 0)) {
$input = str_replace('../', '', $input); };
and set the parameters:
allow_url_fopen - Off allow_url_include - Off
But I'm not sure that's what they want me to do

turbid tartan
#

ad skills assessment part 2 Q7 cant access the flag ist there a way to privesc? or is there another way?

barren jewel
heady tusk
fiery berry
heady tusk
kind holly
#

can anyone help me with answers of linux fundamental module ? here is the question --- Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer.

glossy marsh
#

Hello,
Im new to cybersecurity training and learning the fundamentals right now.
I have an issue with logging in via ssh to a target where i believe that i typed all correctly but the response from the terminal is unclear.
Can anyone help?

barren jewel
heady tusk
#

I was replying to voldemort404. As for question 3, yes those credentials do work

glossy marsh
tribal plume
tribal plume
#

You're probably on the right track, just need to build a regex to filter. Let me know if you need more help.

glossy marsh
manic magnet
#

Hey. Can someone help me to understand this stuff the correct way? I have a hard time understanding it and I am not sure if I got it now:
Active Directory is a way (mostly Windows) to share resources and to authenticate. AD uses a Domain Controller with LDAP for resource sharing and either NTLM or Kerberos for authenticating users. A domain is all PC's that are connected under the same DC. If that is correct I still have some questions:

What is a workgroup?
For some stuff I need to know the domain name of the network domain. How do I find out the domain if I only have something like the domain controller IP. Is it even possible to find the network domain name?

sacred ermine
#

anyone who can help with skills assesment part 2 ? AD ENUM & ATTACK third question

#

I am not able to do anything, how can I access MS01?

zinc marsh
#

u not explaining too much about ur issue

sacred ermine
#

so yeah, basically I have no idea how I have access to MS01, any advice or little hints? what am I supposed to use?

latent sage
undone cypress
#

"Edit the php.ini file to block system(), then try to execute PHP Code that uses system. Read the /var/log/apache2/error.log file and fill in the blank: system() has been disabled for ________ reasons. "

honest iron
#

Hello

latent sage
honest iron
#

Any can help me

fathom pendant
torn blade
#

anyone know what do do when hydra is saying every password provided in a list is valid

heady tusk
torn blade
#

owo once sec

zinc marsh
#

someone can help me with nessus i dont understand this

#

Once logged in, perform a BASIC NETWORK SCAN (modify the scan template to scan ALL ports, leave all other options the same) against the target: 172.16.16.100.

#

but i have a spawned target as well

#

which should i use to respond the questions because the scan can take up to 1-2 hours and i dont want to waste the time

fierce island
#

Hey all, hope someone can get me out this pickle.
I am doing** Attacking common services - hard**. I have creds for f*** and I am trying to authenticate to the MSSQL server using mssqlclient.py without success. Am I supposed to get access with that user?

autumn mirage
#

can someone get a hint what exactly wordlist from seclists need to be use on the last step of the ffuf assessment ?

barren jewel
heady tusk
heady tusk
heady tusk
heady tusk
autumn mirage
fiery berry
autumn mirage
heady tusk
#

might wanna go deeper πŸ˜‰

autumn mirage
#

hate fuzzing guessing

heady tusk
#

well trying different wordlists is part of it. you won't have one that always works

autumn mirage
heady tusk
#

ugh yeah wordlist you're looking for has like 800 ish I think

elder ibex
#

hi, is there anyone who can give me some pointers on the webfuzzers section of burp intruder and zap?
-burp intruder your supposed to scan for files under admin, my scan doesn't complete before the vm's time runs out.
-zap fuzzer - i used zap to convert the username shortlist and matched it against the cookie. i didn't know how to do it through zap. after manually matching the cookie to a username. i'm not sure what to do next. i tried using the decode as a file name "decoded_username.html". that didn't work.

autumn mirage
autumn mirage
zinc marsh
#

u missing the last question?

autumn mirage
#

why i should complete this task only with ffuf

#

and why they can just accept different tools

#

they have maybe some check on UA or maybe something like this

#

why with burp it didn't worked

#

so you should put disclaimer to use ONLY FFUF not other tools

#

why i should guess which tool should i use to complete this if from technical point of view this is exactly the same

#

and fuzzing tasks is so dumb and not so realistic

#

this is like much guessing or who has the more powerful wordlists

heady tusk
#

well it's teaching basics. hard to make it realistic while keeping it that simple

#

a disclaimer might be an idea, that'd be something for #858470491676737536 then. but word it as a nice suggestion

zinc marsh
#

ATTACKING WEB APPLICATIONS WITH FFUF

rare violet
autumn mirage
# zinc marsh ``ATTACKING WEB APPLICATIONS WITH FFUF``

so, after investigating what the difference between burp request and ffuf + curl, i spot that i just add line in the end of the request that is breaks all NotLikeThis NotLikeThis

sorry for blaming this section and i think this will be helpful for others

smoky snow
rare violet
elfin nacelle
#

Module: Web Attacks. Section: Bypassing Encoded References.

"Try to download the contracts of the first 20 employee, one of which should contain the flag, which you can read with 'cat'. You can either calculate the 'contract' parameter value, or calculate the '.pdf' file name directly."

Im hard stuck on the question above for two days now, I assume that the script provided for mass enumeration needs to be modified. I tried to modify numerous ways but don't know what I'm doing wrong. Can I DM someone please?

rare violet
zinc marsh
#

or the .pdf file

#

so i assume that the others 19 are empty or with the same size

#

anyway u can just cat all while read and grep the htb flag

heady tusk
fathom pendant
#

What's the name of the module?

heady tusk
#

Login Brute Forcing

#

I have a feeling my fail condition for hydra isn't quite right but don't wanna cancel too early either. that's why I'm asking

sleek urchin
#

hello I am doing Shells & Payloads: The Live Engagement via xfreerdp, i need to use msvenom to produce a shell, what ip should i use ??

ember pike
#

Hello I found the exploit for Wordpress N-media Website Contact Form Upload Vulnerability for the Getting Started Module; Public Exploits Sections. I tried setting the RHOST to the IP of the target, IP:port (even though I know that was silly). I also tried changing the default RPORT to the port of the docker. Yet no matter what I can't run the exploit on the docker instance, even after using my openvpn connection. Its probably something stupid, point me in the right direction please and thank you

fathom pendant
#

Generally it'll be your IP (tun0) but if you're using a primary host it will be the one that matches the subnet

fathom pendant
ember pike
#

Good lord I didn't notice the TARGETURI option. layer 8 issue haha. @fathom pendant Thank you I was in my head too much!

fathom pendant
#

I don't recall needing to change that option

#

Filepath maybe

ember pike
#

I just didn't notice is before so I was thinking that coulde be it but it already has the / symbol. Everything else is set like the RHOSTS and RPORT

#

I only changed the RHOST right now after resetting the docker

fathom pendant
#

If anything else: reset msfconsole by exiting and restarting it

#

And do the same steps

#

Sometimes it's dumb

heady tusk
sharp plover
#

hi

ember pike
#

I think I might have the wrong file upload vulnerability there are a lot to pick from, put nothing seems to correlate directly to the version 5.1.6 I'll check this out before continuing. @fathom pendant thank you for the advice

fathom pendant
#

It's been a minute since I've done it

smoky snow
#

everywhere I look the answer is something like GLIBC_2.X.Y but no matter how many times or variation i tried, htb won't accept the answer

#

well, I ended up kinda bruteforcing it, if someone has the real answer please let me know

sharp plover
#

hmmm

violet prairie
#

Looking for hints for Protected Files module. I have extracted hashes for kira's private ssh key and the zip file. trying to crack with john using the password.list file provided in the resources, I have a mutated version of passwords generated using hashcat custom.rules provided in resources, I also used best64 hashcat rules to create additional variations + tried simple rockyou and other password lists in seclists. Nothing has worked on eithe the notes file hash or the ssh key hash.

deep schooner
#

guys Server-Side Attacks Example 1, how do you find the flag. I tried printenv, env, and set, basically everything but still no clues

elfin nacelle
#

Module: Web Attacks. Section: Bypassing Encoded References.

"Try to download the contracts of the first 20 employee, one of which should contain the flag, which you can read with 'cat'. You can either calculate the 'contract' parameter value, or calculate the '.pdf' file name directly."

Im hard stuck on the question above for two days now, I assume that the script provided for mass enumeration needs to be modified. I tried to modify numerous ways but don't know what I'm going wrong. Can I DM someone please?

heady tusk
violet prairie
heady tusk
#

found it. dm me with the commands you used and I'll see where the error is

fiery berry
elfin nacelle
shadow canopy
#

can anyone help me with "Attacking Thick Client Applications" first section

  • i followed the steps and F8 until it hit the banner
  • i dumped that file
  • when i drag and drop onto de4dot.exe it says
    The file isn't a .NET PE
grizzled hearth
#

Hello, I am new to this, how do you recommend me to start?

tribal plume
zinc marsh
zinc marsh
#

Downloading/uploading files using bitsadmin, is the protocol encrypted

#

like with openssl or is plain text

thorn urchin
#

not relevant to this channel

exotic hound
#

okay okay

sleek urchin
radiant escarp
#

Hi, I'm doing the module "Web Requests" under "Cracking into Hack the Box"
I'm at the "GET" section and i need help with obtaining a flag, I'm pretty sure my command is all correct and i don't understand what's wrong and why it wont output anything.
Is there anybody that can DM me that could also help me?

tribal plume
#

Sure, I'm happy to try and help. DM me your question.

radiant escarp
#

Thank you

spare plaza
#

I am doing Linux Fundimentals, and I am trying to connect to a remote host but it keeps timing out

#

is this because i am using my own vm instead of pwnbox?

#

and if so how can i set it up so i can do this on my own vm

steady hawk
#

Make sure you don't have pwnbox and openvpn running at the same time

autumn pilot
#

are you connected to the vpn?

spare plaza
autumn pilot
#

what is the output of your openvpn command initialization?

spare plaza
#

it was something along the lines of "successfully initialized"

#

but then when i tried to ping my target it still timed out

autumn pilot
#

take a screenshot of the openvpn command and its output

spare plaza
#

where it says initialization sequence complete

#

2:19

autumn pilot
#

not helpful to be fair

spare plaza
#

sorry I am very new to all this

autumn pilot
#

np, if you run ifconfig and you see that you have multiple tun interfaces, e.g. tun0, tun1 or more either kill the openvpn process or restart your vm

agile rapids
#

anybody remmember nibbles on getting started module?

#

seams like theres a big hole between gobuster and getting admin access

#

i suppose i could just cheat and watch the walkthroughs online

burnt sluice
#

Module: Password Attacks, Section Cred Hunting Linux
guys im stuck with the username kira, i have the password from the hint, i tried making a mutated password list, but it didn't work, i tried it against FTP, SSH, SMB is configured to allow all logins.

#

if anyone could drop a hint that would be appreciated, i've been stuck on it for a couple hours now

#

i've went through the forums but with no use, i couldn't get a grasp on what i should do, i tried bruteforcing all the services, i've obtained access to the Mysql server but couldn't find anything useful

#

one thing i didn't try is to check the user i've got against the smb service...one sec

brittle sierra
#

i want hacking tools for windows

fathom pendant
sharp plover
#

what

zinc marsh
brittle sierra
fathom pendant
#

you should have these 3 files from the resources @burnt sluice

agile rapids
#

cleanup of 'image.php' on the target any body ever get that on metasploit module?

burnt sluice
burnt sluice
#

i read around that i need to remove the last number from the password, i did that and im trying one last time, after that im going to try the original mutated password list.

fathom pendant
#

Just as a note your mutated Kira list should have around 459 lines

burnt sluice
#

yes, it does

#

406 exactly, eliminating the 2-3 numbers passwords

fathom pendant
#

I mean to give you a hint: you shouldnt eliminate any

burnt sluice
#

oh, okay, i'll put back the one's i removed in a sperate list if the one i'm using didn't work

#

ty ty

mild laurel
#

Hello

fathom pendant
#

The only time it's been advised to cut a list is the full list just because it's enormous

sleek urchin
#

Password Attacks: Pass the Ticket (PtT) from Linux: I am trying to impersonate LINUX01$ via Kerberos ticket

#

export KRB5CCNAME=/root/krb***

#

klist

#

klist: Bad format in credentials cache (filename: /root/krb**)

#

any help ?

burnt sluice
#

im still on that section

#

if you can help me im still stuck on the Cred hunting Lab, here is what i did
I took the given password in the hint "LoveYou1"
generated a custom wordlist based on the rules given
made a 542 word wordlist.
launched crackmapexec and tried hydra against "kira" and "Kira" on ssh
nothing turned out
i'm now trying it against ftp

sleek urchin
#

as kira, using hrdya

#

if you wish dm

sleek urchin
fathom pendant
fathom pendant
twin gulch
#

Hey guys, I’m at skill assessment hard lab at password attacks. Trying to get johannas password with a few tries at cracmapexec hydra and crpwbar but with no real results. Tried mut passwords file also. Any clue?

sleek urchin
twin gulch
#

Thanks

sleek urchin
twin gulch
#

Johanna

#

Of course

umbral ether
#

Find a baby who is playing Angry Birds on their phone or tablet. Approach the baby and take their device without their consent. Locate and download hacking software from the internet. Install the software on the baby's device without their knowledge. Use the hacking software to gain access to the game's code. Manipulate the code to give yourself an unfair advantage in the game. Save the modified code and close the software. Return the device to the baby, without them noticing any changes. Watch as the baby struggles to play the game, while you easily beat their high score. Laugh as the baby becomes frustrated and eventually gives up, feeling defeated and helpless.

thorn urchin
sleek urchin
twin gulch
#

Ohhh I did winrm

#

Well a little mistake

#

Trying again

thorn urchin
#

winrm is usually only enabled for administrators so unless you know youre going for an admin account its usually best to test the other methods first before winrm

twin gulch
#

πŸ™πŸ»

torn cedar
#

hello

#

i like coding

thorn urchin
dapper star
#

anyone here willing to give a tip for this one?

Enumerate the target and find a vHost that contains flag No. 3. Submit the flag value as your answer (in the format HTB{DATA}).

It's in information gathering - web edition (Active information gathering: virtual hosts)

#

I tried the vhost file that they provide and tried every thing I could, but using other files is giving status code 200 for every entry :/

cunning nimbus
#

hi, I am currently doing the fundamentals of getting started on offensive, and I am currently doing the nmap section, where I need to go into the users shares and download the file password flag.txt and when I use either vim, cat, or nano, the terminal says command is not found, so how else am I supposed to open the file

karmic dagger
dapper star
#

How do you mean?

#

Like just take the same file?

karmic dagger
#

Same method as the previous questions. Find the Vhost name using ffuf and add it to your hosts file. Then use curl.

#

Curl on the name you found.

dapper star
#

I did it now, because I know how many lines it contains πŸ™‚ but this isn't the right way I think

#

Can I dm you @karmic dagger

karmic dagger
#

That's fine

tribal plume
cunning nimbus
#

I am on a linuc machine

#

linux machine

deep owl
#

Hello All, this is my first message in this community, i am hoping to find help with this question .... password attacks module network services section

fathom pendant
#

Because if you're using SMB to connect, you only have the availability to download the file

#

Not read it

cunning nimbus
#

@fathom pendant so what should I use instead of SMB?

fathom pendant
#

You're using the right tool

#

Think of how you can get the file

deep owl
fathom pendant
#

How to ask questions in a tech forum

#

:)

deep owl
#

thanks

fathom pendant
#

That's not just "is there any experts"

#

Worst case scenario with academy content is you get redirected to this channel

rustic sage
#

I got a new ssd but i have no way to download or install windows to the usb drive since I only have one laptop currently and it has no os
But i have windows on a external hdd
Is there any possible way i can display the content of the external hard drive and copy the windows file to the usb using cmd ?

deep owl
fathom pendant
cunning nimbus
#

ya I think I found it, I had to use ftp

fathom pendant
cunning nimbus
#

or how to open it since I cant use vim, nano or cat

fathom pendant
#

Are you sure that's the password. Also be careful when asking for assistance try to avoid spoiling things by just typing password in your question

fathom pendant
cunning nimbus
#

bruh

deep owl
cunning nimbus
#

thank you so much for that

#

I was going insane from that

fathom pendant
#

Because those commands aren't smb commands ;)

#

Simple mistake/issue it happens often

fathom pendant
#

What's the section again?

deep owl
#

am getting confused by the smb one, because i used crackmapexec and it showed me that it found the credentials but when i use them to connect i don't get connected

#

password attacks module

#

network services section

fathom pendant
#

Sec

#

Sanity checking for you

thorn urchin
#

if anonymous logins are enabled for smb, any cred combo is gunna pop as valid

#

idr if that applies to that section or not though

fathom pendant
#

It doesn't

#

They're hung up on a set of valid credentials but for a different service

fathom pendant
deep owl
torn cedar
thorn urchin
torn cedar
fathom pendant
fathom pendant
torn cedar
#

also where do i find the api indentification thing?

thorn urchin
#

snarky but actually useful is my entire personality

torn cedar
fathom pendant
#

If youre talking about for verification ATM I think it's only on the main site not academy (iirc it used to be or there's some weird thing)

fathom pendant
#

They are two separate things/logins

torn cedar
#

well this is going to be fun lol

fathom pendant
#

Huh upon revisiting footprinting module I realized there's more to IMAP that I just didn't care to learn at the time... Neat

torn cedar
#

uh

fathom pendant
#

But now I have a handy link to provide people when they get stuck on that module

torn cedar
#

what module whould i start with?

#

im kinda lost

fathom pendant
#

If you're extremely new: fundamentals

#

Any of the tier 0 content; getting started as well

#

Those are decent introductions to how courses and everything are laid out

torn cedar
fathom pendant
#

As in you kinda know Linux but mostly use windows as a daily driver so commands in Linux get lost on you

deep owl
torn cedar
#

ive never used linux

#

only windows and macos

fathom pendant
tribal plume
torn cedar
#

should i download the parrot software???

fathom pendant
#

Parrot is a Linux os

torn cedar
torn cedar
fathom pendant
#

Not necessarily software... I mean all OS are software

#

smbclient --user c* //ip/sharename

torn cedar
fathom pendant
#

Then either copy/paste or type in the user password

deep owl
torn cedar
#

im on a windows machine

fathom pendant
#

Sorry I replied wrong

torn cedar
#

oh

fathom pendant
# torn cedar oh

Anyway Parrot has documentation on how to install on a virtual machine

fathom pendant
fathom pendant
#

Np gl, hh(happy hacking)

torn cedar
#

so i do need to download parrot as a vm?

fathom pendant
#

Parrot is downloaded as an iso

#

Again there is documentation on the site

#

And I believe getting started module kinda walks through it

deep owl
fathom pendant
quasi wave
#

I'm doing the skills assessment for Windows Command Line module. I'm trying to figure out using PowerShell how to view hidden contents of files within a folder

#

don't give me the answer but if you could help me figure it out that would be great

#

I keep trying Get-Content, Get-ChildItem, etc.

#

is it not a powershell thing?

torn cedar
fathom pendant
#

No there is literally a module called "getting started"

deep owl
torn cedar
quasi wave
#

hi can anyone help me? I am about to go out to dinner. Should I come back later?

#

thanks btw

deep owl
fathom pendant
#

Not the username but the sharename

#

Usernames in Windows specifically are case-agnostic meaning you can have any letter be a capital and windows will be like 'eh close enough'

deep owl
deep owl
fathom pendant
#

Eh sometimes it just be buggy

quasi wave
#

so no one wants to help me?

#

I will come back later then

smoky charm
#

Hi, everyone!
I'm starting on cybersecurity, and I'm doing the getting started module. I'm on the public exploits page, and trying to complete the lab.
But for the life of me, I don't know how to get the list of services.
I tried to use nmap to get the list of open ports on the target VM, but I keep getting a message saying that the "Host seems down. If it is really up, but blocking our ping probes, try -Pn"
my command is nmap 139.59.181.223
I also tried using nmap 139.59.181.223 30656
I tried using -Pn to try to get something else, but I get the following

Nmap scan report for 139.59.181.223 Host is up (0.084s latency). Not shown: 995 filtered tcp ports (no-response) PORT STATE SERVICE 30000/tcp closed ndmps 30718/tcp closed unknown 30951/tcp closed unknown 31038/tcp closed unknown 31337/tcp closed Elite

I believe this is not the correct information I should be looking for, because these ports are closed, and I can't interact with them

Am I doing something wrong? Or missing something?

Thank you!

thorn urchin
fathom pendant
fathom pendant
#

Even still public IP is going to usually be a webpage (not always guaranteed) so try visiting that ip:port combination in firefox

smoky charm
#

I believe I should be using this command
nmap -p 32327 139.59.181.223
(I had to respawn the target, so the IP changed)

But this still gets this result:

Starting Nmap 7.92 ( https://nmap.org ) at 2023-04-15 01:56 BST
Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in 3.08 seconds

#

And address on Firefox shows a Wordpress site

#

But I understand the lab wants me to scan the available services and identify public exploits

#

So I want to undestand if I'm doing something on the nmap wrong

torn cedar
#

How does the course work

#

i still cant figure it out

#

😭

fathom pendant
smoky charm
#

Ohhh

#

I see

fathom pendant
fathom pendant
# smoky charm Ohhh

Nmap will literally not get you the results (this is done on purpose) another tool is curl

#

Iirc that section talks about those tools

#

And some other ones

rustic sage
#

I am working on attacking email services and ||evolution has hung up on me. It's not even asking for the password to authenticate||, can I dm someone?

smoky charm
#

Thanks a lot for the help!

agile rapids
#

hey ive been trying to do enumerattion on getsimple

#

i found some directories with gobuster

#

i tryed a get simple metasploit attack but so far i can't see anything

rustic sage
agile rapids
#

@rustic sage getting started final section

#

knowlege check

fathom pendant
rustic sage
agile rapids
#

i found quite a bit in the /data

fathom pendant
#

It's legit as simple as checking all options. Then hitting run (rhosts rport)

#

In the msf module

agile rapids
#

seems like my target uri is off

fathom pendant
#

And lport

agile rapids
#

maybe ill just try a few others

fathom pendant
#

Target uri doesn't need to be changed

#

Also using the correct exploit helps

agile rapids
#

port is 80 by default

#

hmmm makes sense

#

ive also been wondering about searchsploit

fathom pendant
#

Only 2 things technically need to be set properly: RHOST and LHOST

agile rapids
#

thought i don't need to use it yet

fathom pendant
#

Well here's the thing

agile rapids
#

it seems useless to me because i can't use any of the exploits i just search them

fathom pendant
#

In order to find the correct exploit you need to know the version of get simple you're working with

agile rapids
#

@fathom pendant im pretty sure i know i found it in the cache

fathom pendant
#

Either way that's your first step. Second step is using that version to find a correct exploit

agile rapids
#

@fathom pendant sounds good ill give it a second try

fathom pendant
#

Also for an easier way to set the LHOST without needing to remember your IP, you can just type 'tun0' and it will grab it for you

agile rapids
#

@fathom pendant yeh did the trick iwas caught up on target uri and it through me off before

fathom pendant
#

Basically most options you change are going to be RHOST, rport, LHOST. There are a few instances where you need to change filepath in the options... But that's when it's literally grabbing the file for you

#

Usually those filepath are default /etc/passwd in the exploit

dim trellis
#

Anyobody has hacking friend group that grinds if so send invite

naive sky
#

**Excuse me its weird and suck chall i got answer but it doesnt work **

  • 0 Observe the web application based at subdirectory /question1/ and infer rate limiting. What is the wait time imposed after an attacker hits the limit? (round to a 10-second timeframe, e.g., 10 or 20)
#

i got 19,26

#

its guessy

agile rapids
#

so im the meterpreter, haven't used this thing much, seems like theres alot of commands i can't do, reverse shells are much better if you can get into them

naive sky
#

if yes i couldnt understand what do you mean?

agile rapids
#

@naive sky no sorry im a noob myself

fathom pendant
agile rapids
#

@fathom pendant wow never knew that thanks!!

fathom pendant
#

Iirc if you type in help in msfconsole it gives you all the msfconsole commands ;)

waxen kayak
#

Has anyone been able to get the ping_sweep module to work in msfconsole? I always end up with a ton of errors.

gentle root
#

Having a bit of trouble with Password Attacks Medium -- From the nmap I am assuming ||THat it was going to be something involving SMB considering ports 139,445 are open --- I am trying to brute force with smb using hydra and it is just not accepting me attempt to brute force -- I tried smb brute force in MSF and it just says everything is a valid password - Am I missing something here?||

waxen kayak
naive sky
#

i cant understand

fathom pendant
#

You said your rough number was 19ish

#

It's asking for the closest in a 10 second interval (10, 20, 30, 40...)

#

It's not asking for the exact number

naive sky
#

so it should be how?

#

sorry for confused

fathom pendant
#

What's the closest number divisible by 10 to what you have

naive sky
#

i got 19 and 26

gentle root
#

me installing libreoffice on the attackbox

odd notch
#

Question about the window fundemantals section "Service Permissions",

sc config wuauserv binPath=C:\Winbows\Perfectlylegitprogram.exe

is there some kind of privEsc going on in that line? it wasn't clearly stated in the section but I got a feeling there is somethign going on there.

novel tendon
#

Are the boxes really slow for anyone? It doesn't seem like my SSH session can stay alive for more than 30 seconds

fathom pendant
odd notch
#

Oh ok. I thought it was some how confusing the permissions with the ones the new .exe has. thanks πŸ™‚

fathom pendant
#

I mean kind of

#

It's like running "definitely not a virus.exe" as admin

#

It only is doing what you tell it

#

It doesn't necessarily know it's valid or not

odd notch
#
Path   : Microsoft.PowerShell.Core\Registry::HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuauserv
Owner  : NT AUTHORITY\SYSTEM
Group  : NT AUTHORITY\SYSTEM
Access : BUILTIN\Users Allow  ReadKey
         BUILTIN\Users Allow  -2147483648
         BUILTIN\Administrators Allow  FullControl
         BUILTIN\Administrators Allow  268435456
         NT AUTHORITY\SYSTEM Allow  FullControl
         NT AUTHORITY\SYSTEM Allow  268435456
         CREATOR OWNER Allow  268435456
         APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES Allow  ReadKey
         APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES Allow  -2147483648
         S-1-15-3-1024-1065365936-1281604716-3511738428-1654721687-432734479-3232135806-4053264122-3456934681 Allow
         ReadKey
         S-1-15-3-1024-1065365936-1281604716-3511738428-1654721687-432734479-3232135806-4053264122-3456934681 Allow
         -2147483648

what do the numbers mean next to the user names? like what does 268435456 mean for Administrators? how do i check?

fathom pendant
#

Yooo I just found the secret with bruteforcing for footprinting easy... It definitely helps to enumerate everything... To think way back when I first did it I was so confused xD

fathom pendant
#

Can I help you?

fathom pendant
south glen
#

can any one help me with the nmap enumeration module on the last exercise im doing the scan with the following :

#

sudo nmap 10.129.29.154 -p 50000 -sS -Pn -n -A --packet-trace --source-port 53

#

and still cant able to find the version of ibm-db2

#

nor was able to connect to it with nc

fiery berry
severe hollow
#

Hi, I'm having a problem opening the crocodile IP adress in the browser . I can ping it, I can nmap it , ftp works fine also , gobuster worked fine also. Is that a known problem or am I doing something wrong? I have found someone with the same issue, and he fixed that with changing the protocol. That didn't work for me tho

patent blaze
#

Someone that I could DM about Command Injection: Identifying Filters ??

I'm pretty sure I've found the right operator, but it's not being accepted.

I've seen a couple of similar problems here, with this particular section, so I don't think I'm missing something.

Thanks in advance!

shadow agate
#

Hey guys i Just Hacked Tesla Cloud

#

How do i contact Elon Musk

round dune
#

Hi guys, I'm getting a 'There are no available instances' error on the 'Internal Password Spraying - from Windows' topic in AD enumeration module (paid subscription) when trying to launch a box. Have been the same for about 30 mins now. When trying to use the VPN to RDP into the target, then I get a black screen. Anyone else has the same issue currently or know the solution?

south glen
autumn pilot
#

have you tried hitting either "Space" or "ESC" when you see the black screen?

round dune
autumn pilot
#

Even after a reset of the target?

round dune
#

yes and getting the mentioned error when trying to launch pwnbox as well. So not sure if it's a bigger issue with the servers?

autumn pilot
#

The instances of the workstation are separated from the target, e.g. only connected via VPN

#

However, have you tried with remmina rather than only with xfreerdp?

round dune
#

I've got a windows attack machine on my side so only tried mstsc.exe essentially

#

with the vpn file ofc

autumn pilot
#

well, if that's your host OS, I'd highly recommend using a VM

round dune
fiery berry
autumn pilot
#

No idea

round dune
#

haha no worries

south glen
south glen
fiery berry
#

can you paste the command?

#

again between spoiler tags

south glen
fiery berry
south glen
fiery berry
#

did you read carefully the output?

south glen
#

Yeah it gave me permission denied and other times netcat time out alert

fiery berry
#

dm me

dusty citrus
#

guys i have a CTF, can anyone help me?

fringe dew
#

The question is Enumerate the server carefully and find the username β€œHTB” and it’s password. Then, submit HTB’s password as the answer.

#

When I scan the network I found IMAP/POP3 and SSH in TCP and SNMP v3 in UDP. Then, I am stuck! Idk how to find credentials from SNMP v3

#

Can anyone help me with this? I just only want a hint

#

The lab is footprint - hard

frigid vector
#

Guys, I have few questions on Stuck-Based Buffer overflow(linux) module, can someone help me a bit?:)

heady tusk
odd notch
#

Hi I'm a little confused. some help?

vestal nacelle
#

yeah because i tried it and its not working on my machine

odd notch
#

Also the alias property is not set in the help command...

vestal nacelle
#

but mine at least gives me the ps commands relaated to it

odd notch
#

ok this is dumb.

vestal nacelle
#

lol

#

I remember feeling similar, I honestly think I just guessed the answer if I remember correctly

odd notch
#

Microsoft please...

vestal nacelle
#

what module is it

#

drove home

vestal nacelle
#

never mind it is windows fundamentals, I actually haven't done this one

shadow canopy
#

Exploiting Web Vulnerabilities in Thick-Client Applications

Section (SQL)

Rebuild the JAR file by following the same steps and log in again to the application. Then, navigate to FileBrowser -> Config, add the fatty-server.jar name in the input field, and click the Open button

i'm lost and have no clue how to rebuild the JAR

odd notch
#

It says following the same steps... what ware the previous steps?

shadow canopy
#

yes thanks it worked. i tied previous commands and found it. all good

viral shoal
#

Hello, I would like to ask for help. They banned me from an online game. My account was stolen. How can I get it back? Does anyone know?

quick crane
odd notch
#

πŸ™‚

rustic sage
#

Hello friends

rustic sage
misty cedar
#

I have a bit of a problem connecting to the SMB Client in Footprint SMB. "Connect to the discovered share and find the flag.txt file. Submit the contents as the answer."
I don't know the password and I'm looking through the point to find out if I was able to log in anonymously or if they just gave the password but I'm out of luck. can someone help me out a bit?

sleek urchin
autumn pilot
#

Are you sure that the Kioptrix VM that you have downloaded and started has the IP you mentioned?

sleek urchin
#

make sure that you are connected to vpn

autumn pilot
#

he doesn't need a VPN if he is using a vulnerable VM image in his local environment

sleek urchin
#

what are you trying to achieve from the nmap scan ?

autumn pilot
#

Additionally, the machine might not be in the specified subnet

patent blaze
#

Sup folks!

Anyone that I could DM regarding Command Injection: Identifying Filters’ section??

autumn pilot
#

you will have to figure out the IP of the machine first, then you can check what ports are usually open on that machine that you can target with your nmap scan

sleek urchin
#

I am doing Password Attacks Lab - Hard and found valid smb creds. and when i try to list any possible share via smbclient i get "*NT_STATUS_NO_SUCH_FILE listing *
"

#

any help ?

odd notch
#

Ok I am having problems wraping my head around these part of the windows fundamentals

Security Accounts Manager (SAM) and Access Control Entries (ACE)

SAM grants rights to a network to execute specific processes.

The access rights themselves are managed by Access Control Entries (ACE) in Access Control Lists (ACL). The ACLs contain ACEs that define which users, groups, or processes have access to a file or to execute a process, for example.

The permissions to access a securable object are given by the security descriptor, classified into two types of ACLs: the Discretionary Access Control List (DACL) or System Access Control List (SACL). Every thread and process started or initiated by a user goes through an authorization process. An integral part of this process is access tokens, validated by the Local Security Authority (LSA). In addition to the SID, these access tokens contain other security-relevant information. Understanding these functionalities is an essential part of learning how to use and work around these security mechanisms during the privilege escalation phase.
#

who against who and what includes what?

#

Specificly on the Securable objects part