#modules

1 messages · Page 71 of 1

timid osprey
#

I’m really stuck on Attacking Common Services - Attacking DNS.
I have found lol the subdomain and everything. But I tried Dig AXFR command on all but nothing is working. Im not sure what I am missing exactly but nothing seems to work.
I also have edited the /etc/hosts.

slender kelp
#

in passwords attacks / AD, the following command is listed || *Evil-WinRM* PS C:\NTDS> cmd.exe /c copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy2\Windows\NTDS\NTDS.dit c:\NTDS\NTDS.dit ||. looks to me like it's simply overwriting the original file rather than putting it elsewhere before exfiltration?

timid osprey
slender kelp
#

that's what I thought, it's just that that path is standard as is explained in the same section, so I'm not sure what the point would be

ancient spire
#

anyone else experience issues with the machine for the virtual hosts section of the information gathering module? One minute the machine works the next it doesn't even respond to a curl request

river token
#

Shells & Payloads >> Anatomy Of A Shell >>. In Pwnbox issue the $PSversiontable variable using PowerShell. Submit the edition of PowerShell that is running as the answer. I give the correct answer and am told that it is wrong. Can I get some help?

slender kelp
odd notch
#

I'm confused... int he Windows Security section in the Windows fundementals module they say to find the user SID using Get-WmiObject, but up to this point I don't recall (and I looked though my notes too) any such cmdlet that includes SID of users other then the one already logged in. I tried runAs but it requires the password of the user.

river token
slender kelp
odd notch
#

halp

#

I'm honestly lost

slender kelp
# odd notch halp

well it's there, but I'm not sure how to explain it without downright spoiling the solution

odd notch
#

point me to the section

#

Wait.. they mean the SID from the page itself?

#

that sounds like cheating..

#

ok good it is't it

slender kelp
#

no, it's not displayed on the page. I've searched microsoft's KB but can't find the argument for some reason and I wasn't keeping notes back when I did that module

odd notch
#

is the command in the module?

slender kelp
#

it's in the hint

odd notch
#

? Get-WmiObject isn't really helpful if I don't know what object to query

#

there are tons

slender kelp
#

if you google ||get-wmiobject sid|| you'll find something useful on ||likely the first result, on tenforums||

odd notch
#

Ok so it isn't in the module... that kinda mean after all that info dump

#

thanks n4p ❤️

kind holly
#

can anyone help me to solve this questions --- Find a way to start a simple HTTP server inside Pwnbox or your local VM using "php". Submit the command that starts the web server on the localhost (127.0.0.1) on port 8080.

odd notch
#

Ok so I can see the answer... || nordVPN|| for the second question, but how do I know it's disabled on startup? do I really need to go to ||task Manager|| ?is there a way to check that from the command line?

slender kelp
# odd notch thanks n4p ❤️

no problem. it happens sometimes that you need to find some info outside the modules. also I just noticed that you can do something like ||get-wmiobject -list | select-string user|| to look for classes related to users. I wish I could remember what my thought process was when I solved it but I'm drawing complete blanks

odd notch
#

oki

#

thanks 🙂

slender kelp
lusty imp
#

Hi everyone, hope you are well
Quick question, i juste finished the getting started module and "hacked" the box at the end of the modules.
My problem is that i was working on the HTB workstation and lost the connection after submitting the root flag.
I didn't had the time to export the information do you know if i can find the walkthrough somewhere ?

Thanks in advance for your response

cyan ginkgo
#

Could someone help me with Password Attacks Hard Lab? I tried brute forcing Johanna's password, but cannot get anything. I used mut.lists from the resources .

slender kelp
red current
#

I'm on the third question of the skills assessment for Pivoting, Tunneling and Port Forwarding. I've tried several things to either get a meterpreter reverse tcp shell or to try and get the ssh password and move forward with enumerating the network. So far, nothing has worked. Can someone give me a hint as to how to move forward?

red current
proper wagon
#

hi ! i am stuck in HTB academy live engagement module

#

need a little help in exploiting the HOST 1

#

but it says unauthorized to upload

#

by logging in to manager through gui the credentials work

#

now thinking that there must be something wrong

#

need a direction

misty cedar
#

found the way. ❤️

desert lark
#

first time in hack the box and no experience! could someone tell me how to use openvpn? I've already download the files, unfortunately, when I open kali linux, the files is not abled to drag over. how can i figure it out?

placid quest
#

@desert lark use sudo openvpn file name

misty cedar
#

$ sudo openvpn <FILENAME>

desert lark
#

I GOT IT! first time try~

misty cedar
#

niceee

quick cairn
#

In active directory living off the land... the last question, I am not understanding how to setup my DSQuery and LDAP filter.. Can anyone help me out? "Utilizing techniques learned in this section, find the flag hidden in the description field of a disabled account with administrative privileges. Submit the flag as the answer"

cunning nimbus
#

hi, I am doing the getting started fundamentals and on the gobuster module, I am running the vpn, and when I try to use gobuster and the ipaddress that I was given, I am getting a timeout error, can someone pls give me some pointers

proper wagon
#

hi anyone who can help me with tomcat manager upload issue ... i am facing in Shells & payloads - The live engagement - host #1

nocturne bough
#

Hey, I got stuck on Q7 from AD Enumeration Module Skills Assessment II. I got revshell with the user, but how can I get additional info from here? any hints? thank you 🥲

tidal mango
nocturne bough
nocturne bough
tidal mango
#

ahh ok, you need to work on getting a more stable shell at this point. See if you can figure out how to get a stable shell back to your attack machine

nocturne bough
nocturne bough
tidal mango
static roost
#

Module: Linux Privilege Escalation
Section: Wildcard Abuse
I'm reasonably comfortable with cronjobs. But what does NOT make sense is how the escalation vector is supposed to work if that command is executed from within the root folder? I've tried this on my VM with no success. I'm sure I'm doing something wrong. Can anyone explain this?

quasi wave
#

Hi I could have sworn I was doing this last exercise right for PowerShell in Windows Command Line Module

proven peak
#

who work with sql

normal gyro
#

I must be stupid! In the introduction to academy the very first question? What is the name of the first section of this module? I have tried til I'm blue can someone point me in the right direction. I am new to the p c stuff so please go easy on me. Thanks

cunning nimbus
#

hi guys, I am trying to do an nmap on a ip address, and I am connected to the vpn, but when I try nmap, it says the host is down, any tips/ suggestions?

fathom pendant
quasi wave
#

Hi guys, I put user10, user10@greenhorn.corp, etc in for the answer to the Windows Command Line Module's final question. Can you please help me figure this out? I tried this tutorial but for Event 4625

fathom pendant
cunning nimbus
#

ahh ok

quasi wave
#

What user account on the Domain Controller has many Event ID (4625) logon failures generated in rapid succession, which is indicative of a password brute forcing attack? Flag is the name of the user account.

#

could someone help me out?

#

I know Advapi is not the answer

#

could someone help me out?

#

I don't get it

cunning nimbus
#

when I am trying to exploit a target and it says that the target is not exploitable, does that mean that the exploit I am trying to use wont work? or the method that I am trying to use should be different?

umbral cliff
#

it looks like (from other discussions) that due to some security patch (possibly), it only works with a separate CA that is not a DC. Perhaps the lab should be updated, as without a certificate we cannot proceed with the following sections of the module

cunning nimbus
#

maybe I should ask a better question, when I search on the searchsploit for an exploit and a ton of different exploits show up, can I just choose any one of them or is there someway I should know which one to pick?

fathom pendant
#

Generally to narrow down choices you should be clarifying version number

cunning nimbus
#

so I would say "search exploit "name" "version" ?

fathom pendant
#

Yes

cunning nimbus
#

ok

#

when I do that, i getting no search results

fathom pendant
#

What's the module you're doing?

cunning nimbus
#

fundamentals of hacking attack public exploits

fathom pendant
#

Ah then I would definitely make sure you keep it Simple ;)

quasi wave
#

hi how to I find waldo.txt?

#

I'm struggling

cunning nimbus
#

if I use the searchsploit and the name with file, i get results, but I am not really sure how to use the exploits

fathom pendant
cunning nimbus
#

ok

fathom pendant
#

When I get home later I may be able to provide better hints of you still don't have it

cunning nimbus
#

that would be greatly appreciated

sleek urchin
#

I am doing Password Attacks Lab - Hard and i found valid creds. and logged into RDP and evil_winrm, but i can't progress any further

#

can dm someone ?

fathom pendant
sleek urchin
#

i have tried dumping sam lsass, but couldn't

#

there is ***.kdbx but i don't know what to do with it

fathom pendant
#

Crack it :)

#

Look at what programs the user has access to

waxen kayak
#

^ there are a few files in that lab that are rather interesting, and in some cases might need exfiltration.

fathom pendant
#

One of those is a password manager. Perhaps that matches the .kbdx format

#

There is a k*2john as your other hint

sleek urchin
#

i have found a fat passwords file, but i can't do anything with it (**/1/password.txt)

fathom pendant
#

These are some of the baseline hints I can give

#

Not home so can't check notes

coarse frost
#

this is gonna sound rlly dumb but

#

what does the bash terminal icon look like 😭

sleek urchin
fathom pendant
#

Hint it's a character

#

Iirc

coarse frost
fathom pendant
#

Terminal = command line

coarse frost
#

oh

#

omg im dumb ok thanks

fathom pendant
#

Ywyw

coarse frost
#

sorry idk anything abt like this stuff at all

fathom pendant
#

Also welcome to hacking

#

Nah you're good

#

The only time any of the active people will be really pedantic/sassy is when someone is showing a clear lack of reading comprehension

coarse frost
#

i think im still dumb

#

can i send you a ss of what it looks like

fathom pendant
#

Not at home

coarse frost
#

screenshot

fathom pendant
#

If you're using pwnbox it's the green box

#

You do need to be using a Linux VM or pwnbox

#

Hint though: look carefully at the command line iirc

coarse frost
#

omg ok i did it

#

it was called like MATE terminal and not bash terminal 😭

#

thank you

fathom pendant
#

MATE is the terminal: bash is the actual command line interpreter

coarse frost
#

oh okay thank you

#

i jus thought the website looked cool as you can tell im going into this w absolutely no idea what im doing

#

thanksfor ypur help and patience :)

quasi wave
#

Hi guys, a few months ago I tried to do the finding files and directories section of Windows Command Line Module. I asked for help when the file Waldo.txt, containing the flag, could not be found. The HTB Academy community said I should come back to it later so I completed other modules as well as the rest of windows cmd line module later on, and after I did that I got back to this module finding files and directories. I will look again for Waldo.txt but I don’t want to waste my time because the HTB Academy community said the flag is not stored on that server and that the HTB Academy devs made a mistake when writing that section initially. Should I try this module again or should I just get the flag online or something? In other words, has the exercise been fixed yet?

#

And if not how am I supposed to get the flag if the file is not there

mystic light
quasi wave
agile rapids
#

so im looking for the proper NSE script on the nmap module

#

im having trouble with what port or what script

#

ive tried both --banner and -vuln on both 31337 and 80

mystic light
wanton mica
#

Hello all…having a hell of a time with the command injection skills assessment. I’ve found the injection point, and can tell I’m close since I’m getting the ‘Malicious request denied!’ message….but can’t seem to get anywhere. I’ve literally tried every injection operator…as well as o’bfus’ca’ti’on if you know what I mean….but no dice. Any nudges?

agile rapids
#

@mystic light had some random luck picking the right script in the NSE but thanks!

waxen kayak
#

Active Directory Enumeration & Attacks <<< this module is like 100 miles long. sheesh 😄

wanton mica
rustic sage
#

Module: Shells and Payloads

#

Section: Live Engagement

fathom pendant
#

because that's the custom version but not the actual version; do an nmap scan and check for the version to get it

#

that answers a different question in that section

rustic sage
#

Hello. I'm working through the live engagement for the shells and payloads module and cant figure out how to access host 1. It seems like there should be a web browser or something on the footprinting machine but I can't seem to find one installed. Can someone help out?

rustic sage
fathom pendant
#

eh if you haven't really run firefox from your vm's terminal before you don't immediately think about it

#

also for smb section you will use pretty much each of the tools discussed

brazen hinge
#

Hello, anyone was solved the Skills Assessment - Service Login? i'm stuck trying guess credentials, i am using cupp and only setting name, surname and birthday, also pet name, but nothing, i should use other data to generate password? for user i am trying with username-anarchy.

red current
#

I'm on the Pivot, Tunneling and Port Forwarding skills assessment and I'm having a problem with the 4th question. I can get chisel to work up to the point where you're supposed to rdp into the live host that you found on the adjacent network with the user name and password you found. However, I'm getting a very strange error of Failed at index 1 [v:ip address of the pivot target]: Invalid sigil. Has anyone seen that before or know how to resolve it?

#

I've tried using an ssh tunnel instead, but that fails without the password for the linux host, which I don't have.

#

proxychains xfreerdp /v:ip address of pivot target /u:username /p:password

#

Thank you!

#

What should it be then?

#

I copied and pasted it directly from the 3rd answer and I still get the same error. Could it be that my config file might be incorrect?

#

add proxy here ...

socks4 127.0.0.1 9050

socks5 127.0.0.1 1080 (is how my config file looks)

#

Wow, that copied and pasted strangely.

#

LOL!

tidal mango
#

In the Attacking Common Applications Module, there are some new sections that were recently added. Has anyone done the Attacking Think Client Applications section? I finished it but it won't take my answer, so I was hoping I could verify my findings with someone else who has completed that section. https://academy.hackthebox.com/module/113/section/2139

quasi wave
#

I completed windows command line module

#

Lmao

fathom pendant
tidal mango
fathom pendant
#

no

#

on the academy site on the bottom right you should see a green chat bubble

tidal mango
#

ok thanks! will do

fathom pendant
#

if you don't see it: Disable ad-block; disable any vpn you may be using

tidal mango
fathom pendant
#

oof; also to get credit just provide the POC/attack chain you used to get what you assume is the correct answer and they'll be able to sort it out for you

quick crane
#

can you help me

fathom pendant
#

Why don't you ask your question here to see if someone can help you instead of replying to someone randomly who's message was a few weeks to a month ago

final python
#

I finished the Log Poisoning section of the FILE INCLUSION module. If anyone has any questions, maybe I can help with something. I had some trouble doing it, which is why I offer my help.

kind holly
#

can anyone help me to find the answer of ----- What is the size in GiB of the "/dev/vda" disk in our Pwnbox? (Format: 000)

rustic sage
#

I am stuck on what to do for NMAP module, hard lab challenge

#

Would love some help

#

the hint is cryptic as hell and ive been at it for a few hours (really just waiting for -sS -D scan to finish, no avail)

rustic sage
#

I didnt even discover it myself.

mild gyro
#

Hello

final python
#

I have finished these modules, if anyone needs help I can explain a little.

autumn pilot
agile rapids
#

need some help with the nmap module, the whole ids thing, i can't seem to see how to stop ids

rustic sage
#

you dont stop it, you circumvent it

agile rapids
#

@rustic sage yeh i get that, but so far, ive done spoofing the ips and redirecting the ports as well as fragmenting the packets

rustic sage
#

which lab?

agile rapids
#

hard lab

rustic sage
#

welcome to the club

#

its a shit lab in that module

#

i spent 4-5 hours on it

#

bad hints, bad explanation

#

try netcatting to port 50k like it did in the primer

agile rapids
#

i netcatted a bunch of ports already, haven't not 50k yet

#

must say thats a random one

rustic sage
#

because it doesnt enumerate

#

HTB needs to fix it

#

my scan took 3 and a half hours and didnt detect it

agile rapids
#

kk ill give it a go then

#

@rustic sage got it , so do you think theres any differnce between ncat and nc?

rustic sage
#

they are different

#

ncat is basically an extension of functionality

#

its "modern"

#

the syntax is compatible

agile rapids
#

@rustic sage so ncat is better would you say then?

rustic sage
#

yes

acoustic owl
bright hemlock
#

bashing my head against a wall for broken authentication module brute force attack against htbuser. you have to identify the password policy which i have..but keep getting too many login failures. have added x-forwarded-for but no joy. this module is the least fun 😦 any tips?
wfuzz -b "PHPSESSID=bcpma2pk6deoig3h587itscvt8" -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:102.0) Gecko/20100101 Firefox/102.0" -H "X-Forwarded-For: 127.0.0.1" -c -w output.txt -d "userid=htbuser&passwd=FUZZ&submit=submit" --hs "Invalid credentials." http://139.59.181.223:31707/

rustic sage
acoustic owl
#

So if you understood the way, it should be possible without problems to detect another port and adjust your payload accordingly.

rustic sage
#

My guy, i even resorted to chatgpt to help with the payload

#

me and another had the same issue

#

this ones on HTB

pine dagger
#

I don’t recall have any issues with it. But sadly didn’t record any notes on it.

rustic sage
#

Nmap, hard lab 3, We both used fragmentation, decoys, syn scan, etc

#

Port didnt show at all, not even filtered

#

I got the flag on a fluke, guessing

pine dagger
#

I remember finding medium being harder

rustic sage
#

Medium and easy took me 5 minutes each

#

Hard is poorly presented

#

it consumed 5 hours of my day doing painstaking scans

pine dagger
#

So have you actually understood why the guess worked?

acoustic owl
rustic sage
#

Not at all

karmic dagger
#

For the second question on the Dynamic Port Forwarding lesson, when I attempt to enable dynamic port forwarding with ssh, I log in as the ubuntu user instead. Any hints on what could be the issue? Here is my command: ssh -D 9050 ubuntu@10.129.49.53

fluid quartz
#

Hey I’m sorry I can’t find which channel they talk about the pro labs , how do I find this?

autumn pilot
fluid quartz
grand harbor
#

can anyone explain me why this query is not working for this question: In the 'titles' table, what is the number of records WHERE the employee number is greater than 10000 OR their title does NOT contain 'engineer'?

My query: ||SELECT * FROM titles WHERE emp_no > 10000 OR title NOT LIKE '%Engineer%';||

woeful ermine
#

which question are you taling about

heady tusk
heady tusk
karmic dagger
heady tusk
pine dagger
#

Would anyone be able to provide some guidance?
Module: HTTPS/TLS Attacks
Chapter: POODLE & BEAST
Question: Construct a valid SSL 3.0 padding of the plaintext bytes "AABBCCDDEEFF". Use the byte 00 for any byte that can be an arbitrary value. Provide the padded plaintext without spaces. Assume the cipher suite TLS_RSA_WITH_AES_128_CBC_SHA is used.

I'm just a little bit lost on what the actual quesiton is wanting you to do. I've tried following the examples, but I'm not getting the vulnerable and not-vulnerable responses. Is there a specific host I'm meant to be testing against?

karmic dagger
heady tusk
#

You're welcome 🙂

pine dagger
final python
#

I finished the FILE INCLUSION module, so if anyone has any doubts, maybe I can help.

grand harbor
#

anyone able to help me with sql injection with comments im trying to figure out how it works

grand harbor
#

anyone able to help me with this question? We see in the above PHP code that '$conn' is not defined, so it must be imported using the PHP include command. Check the imported page to obtain the database password.

#

nvm got it

fluid quartz
#

hi can an admin or moderator please DM me

fathom pendant
#

Why do you need to be dmed

pine dagger
rustic sage
#

hello guys i didnt kow where to ask this but here i am

#

so if im brutefroing a ssh port and the brute force attack is a sucsess wold i have to be on the same network as the server to gain root access to it?

naive sky
#

@fathom pendant

#

24 seconds

#

Observe the web application based at subdirectory /question1/ and infer rate limiting. What is the wait time imposed after an attacker hits the limit? (round to a 10-second timeframe, e.g., 10 or 20)

fathom pendant
#

So round up to 30

naive sky
#

still wrong

#

invalid answer

#

its really guessy 😢

fathom pendant
#

i haven't done the module ¯_(ツ)_/¯

#

It shouldn't be guess based you should have enough clues within the module and section to get you the answer

naive sky
#

Hint

Try to generate some failed login attempts.

#

the HINT its guessy lol

burnt sluice
#

Module Attacking Common Services - Lab Easy
hello, I have been able to enumerate the host and get to the file upload part.
ty in advance
supposedly I have been able to upload a php shell, the simple one where you supply the "cmd=<command>" part in the url.
but I haven't been able to launch it, I also tried to upload wwwolf php shell and launch it but with no avail.
here are the commands I used
file upload
||curl -k -X PUT -H "Host: 10.129.99.210" --basic -u <user>:<password> -F 'fileX=@/home/user/shell.php' 'https://10.129.99.210/../../../../../..\xampp\htdocs\myshell.php' ||
but when it comes to running them im uncertain tbh
i have tried the url method where i supply the cmd param at the end (?cmd="whoami")
i have also tried invoking a rev shell with curl, but it keeps giving me a (No Header Colon Error)
||curl -k -X GET -H "HOST: localhost" -u <user>:<pass> 'https://10.129.99.210/shell.php?cmd="whoami"' ||

#

and the upload command gave me a 200 response code

#

i have been able to access the files on the server originally, other than it won't work

uneven shard
#

Hi there, can anyone nudge me on Q6 AD Enumeration Module Skills Assessment II? It's kicking my ass

rustic sage
#

Trying to finish up the live engagement part of the shells and payloads module. Have tried running the eternalblue metasploit module on host 3 but but can't seem to get a shell (Exploit completed, but no session was created). can anyone help my out?

burnt sluice
sterile cove
#

So im new to this thing. Where should I start?

torpid knoll
burnt sluice
# burnt sluice Module Attacking Common Services - Lab Easy hello, I have been able to enumerate...

im officially stuck, i uploaded the shell using MySQL, but i haven't been able to run it, and when i try to load it with MySQL to view it's contents, it gives me NULL.
the cur command i use to try to invoke the shell:
||curl -k -u <user>:<pass> "https://10.129.203.7/webshell.php" ||
and the SQL commands
||SELECT "<?php echo shell_exec($_GET['whoami']);?>" INTO OUTFILE 'C:\xampp\htdocs\webshell.php'||
||select load_file("C:\xampp\htdocs\webshell.php");||

#

if anyone could lend a hand, please do

pine dagger
burnt sluice
#

wait, i did the first two notes, but the last one, that's where im lost

#

the ||select load_file|| i used it to check if my files r uploaded correctly or not, i used the ||double slashes|| when i noticed that the file names r messed up, but i still can't access the file xD

mystic light
brazen hinge
#

Hello, anyone was solved, the Skills Assessment - Service Login? I'm stuck trying guess credentials, I am using cap and only setting name, surname and birthday, also pet name, but nothing, I should use other data to generate password? For user I am trying with username-anarchy.

burnt sluice
heady tusk
rustic sage
#

hey guys quick question for the nibbles box module in getting started, for my priv esc from the normal user nibble, the only way i could get root through my reverse shell was having to specify the full path of where the shell script was that the user had root permission to run as opposed to just doing ./script.sh why is that?

#

e.g sudo /home/user/nibble/script.sh as opposed to sudo script.sh

fathom pendant
#

Just one of those weird things with sudo iirc

rustic sage
#

is it bad I just used SOCKS and proxy chains for the payloads assessment because the foothold box annoyed me?

#

theres many ways to skin a squirel

umbral swallow
#

Salam

rustic sage
#

Hello i need some help on the Windows Priv Esc PILLAGING last question "Restore the directory containing the files needed to obtain the password hashes for local users. Submit the Administrator hash as the answer", i restored all 3 but there is nothing containing SAM or SYSTEM

dim crag
#

Hi! i am trying to complete "using web proxies" and i am stuck on the ZAP fuzzer lab. I am fuzzing the cookie with the md5 hash of the usernames in the file "top-usernames-shortlist.txt" but i am still unable to find the flag. can someone point out what i am doing wrong please.

golden vortex
#

Im working on Kerberoasting - from Linux and I'm stuck on the question What powerful local group on the Domain Controller is the SAPService user a member of?

dim crag
#

here is a screen shot of the thing i am trying to do .

pine dagger
quiet ember
#

For Password Attacks > Credential Hunting in Linux, does anyone know the intended way without using the hint?

#

It feels like the hint is almost required

tidal mango
#

In the Attacking Common Applications module, Exploiting Web Vulnerabilities in Thick-Client Applications, section. I am wondering if there is anyone who can help me? I got as far as the part where I should be able to use the .jar file to download fatty-server.jar to the desktop. When I try this nothing downloads and the .jar file I am running tries to open the fatty-server.jar inside the traverse.jar app. There is a part where it has me edit Invoker.java then rebuild the jar. I am guessing this is where I messed something up (either editing or building the jar). anyway I was hoping someone could shed some light on it. Thanks!

pine dagger
sage jackal
pine dagger
#

My suggestion to you both would be to not mess with the invoker.java. Instead ||look at the later part of the chapter text. There's another java file that they modify in their example.||

tidal mango
pine dagger
#

It had my going down the rabbit hole as well. 😉

tidal mango
# pine dagger It had my going down the rabbit hole as well. 😉

There is a part right before SQL injection where it tells me to modify it, that is why I went that route ```We can modify the open function in fatty-client-new.jar.src/htb/fatty/client/methods/Invoker.java to download the file fatty-server.jar as follows.
Code: java

import java.io.FileOutputStream;
<SNIP>
public String open(String foldername, String filename) throws MessageParseException, MessageBuildExcept
ion, IOException {
String methodName = (new Object() { }).getClass().getEnclosingMethod().getName();
logger.logInfo("[+] Method '" + methodName + "' was called by user '" + this.user.getUsername() + "'.");
if (AccessCheck.checkAccess(methodName, this.user)) {
return "Error: Method '" + methodName + "' is not allowed for this user account";
}
this.action = new ActionMessage(this.sessionID, "open");
this.action.addArgument(foldername);
this.action.addArgument(filename);
sendAndRecv();
FileOutputStream fos;
String desktopPath = System.getProperty("user.home") + "\Desktop\fatty-server.jar";
fos = new FileOutputStream(desktopPath);
if (this.response.hasError()) {
return "Error: Your action caused an error on the application server!";
}
String response = "";
try {
response = this.response.getContentAsString();
} catch (Exception e) {
response = "Unable to convert byte[] to String. Did you read in a binary file?";
}
fos.write(this.response.getContent());
fos.close();
return response;
}
<SNIP>

pine dagger
#

Yep, same. I did loads of screwing around before I realised my mistake.

tidal mango
sage jackal
pine dagger
#

Modifying ||the wrong java file.||

sage jackal
#

I’m so confused and exhausted been trying this for hours so I fun

#

So unfun

grand sable
#

Hello everyone Does anyone know where I can ask Linux questions

pine dagger
#

It does, but that's an example. Stop focussing on that section, and look at the rest of the text.

#

Your ultimate goal is to get the IP address. Not to follow the example. 🙂

sage jackal
rustic sage
#

I've been working on the Live Engagement portion of the Shells and Payloads module for WAY too long and I am struggling to get a session on Host 3. I've tried all of the eternalblue metasploit modules and scanners and for some reason cannot find a way to get a shell. Is there a parameter or options that I could be overlooking when configuring the exploit?

pine dagger
zinc marsh
#

in shells and payloads which browser do i have too use

#

for the engagement

heady tusk
odd notch
#

Hi on the windows fundemental aseesemtn I don't have access to create new users in powershell. is tha intentional? do I really have to go through all the menues?

primal aurora
#

hey anybody help me with aws fortress

heady tusk
primal aurora
#

stuck on ad attack
no clue how to exploit it
nothing works here

krbrute not working no smb blah blah balh☹️

zinc marsh
#

someone who completed sheels and payloads i need help with the browser

rustic sage
zinc marsh
#

was using links 2 and is so fucking slow

sage jackal
rustic sage
#

anyone else struggling with the metasploit modules trying to exploit Host 3 in the Live Engagement section of the Shells and Payloads modules? ive tried all of the modules and configuring them with different options and cant seem to grab a shell....

prisma wedge
#

Hello everybody, is there anyone completed Busqueda machine?

fathom pendant
fathom pendant
#

yes and you can ask for hints in those channels

zinc marsh
#

not sure if for the cpts is allowed

fathom pendant
#

any tools talked about in the modules are allowed in cpts

#

it would be kinda silly if they said "hey here's a tool... but you can't use it"

rustic sage
#

Still good advice—best to know what a script is doing

slow ice
#

Guys, does anyone here speak Portuguese?

pine dagger
vital bough
#

I too have fallen victim to the the last question in the footprinting section on DNS...I can't find all the zones...any hints please

fathom pendant
#

the second uses a list from SecLists

#

your answer will be x.y.inlanefreight.htb

vital bough
#

I got it but how do I know that subdomain was a zone vs all the other ones??

fathom pendant
#

just bruteforce/trial and error

vital bough
#

You can't do a zone transfer but you can bruteforce it. I can't understand that unless you just do it for all of them, I think that's the point...

fathom pendant
#

i mean yeah

#

cause there's 2 ways to go about the bruteforcing is you can individual replace OR create a list and do the bruteforce using the list

final python
#

I completed the NETWORK ENUMERATION WITH NMAP module, maybe i can help someone who is having issues.

fathom pendant
final python
fathom pendant
#

I mean I don't generally read everything either just the last handful of messages when I first hop on and while I'm just active

#

but giving the blanket "send me a DM" can be loaded, it definitely doesn't let you filter out people that just refuse to read

final python
#

Yeah, but many people could search info about any module using the Discord search engine and find helpful messages, including my message

fathom pendant
#

(here's a hint, they generally don't)

acoustic zinc
#

Does anyone have any clues to solve Firewall and IDS/IPS Evasion - Hard Lab?

#

from nmap module

rustic gyro
#

Anyobe did the CCT or Crest module and took the exam?

#

how well does it prepare you?

#

i wonder do you still need extra thing for the exam or just the module will be enough

still merlin
#

hello guys

placid quest
#

@rustic gyro you will need to do some prolabs to be confident to take the exam

rustic gyro
still merlin
#

i dont go for participate in youre plattform i go search people for collaborate with my bussines of cybersecurity and my certifications OSCP

#

im founder of OSC Offensive Security & Consultancy

placid quest
#

@rustic gyro You will choose prolab according to your choice

still merlin
#

getings

#

i want colaborate with me certifications and the practice my profesionals and the plattform

#

& HackTheBox

rustic gyro
still merlin
#

thats youre opinion of certificate OSCP

#

🙂

placid quest
#

@rustic gyro Since I haven't done most of prolabs I think donte is good

still merlin
#

im founder of this busines OSC Offensive Security & Consultancy

#

theyre like see me url web ??

rustic gyro
placid quest
#

@rustic gyro I don't think that is the person who created donte

rustic gyro
#

the person in the link on teh right no?

#

but i remember his name on the cert

placid quest
#

@rustic gyro maybe

rustic gyro
#

but maybe i am wrong

placid quest
#

@rustic gyro Just try the Dante prolab you may like it

novel matrix
#

Can we please keep this channel on topic to academy

rustic gyro
placid quest
#

@rustic gyro If you have the experience with the environment you can just do cpts

quick cloud
#

Just solved my first easy lab without any help GG

placid quest
#

@quick cloud congratulations 🎊 👏 💐 🥳

faint trellis
#

Hi, everyone!

Can someone help me with "Intro to Assembly Language" - (Skill Assessment Task 1)?

Should my binary ./loaded_shellcode to return either "Segmentation fault" or the decoded shellcode?

I will thankful for any hint

spiral pelican
#

Hi all. I tried to complete the module common app attacks but I'm stuck on the skill assessment 1. I found de Wxx-xxx/cxx but impossible to find something interesting in it. I tried to fuzz multiple extension but nothing.. If someone can give me a hint it will be very appreciated 🙂

quick cloud
bright osprey
#

Hello, this is kind of off topic and i don't know where to ask this... But i am planning to buy new machine (laptop ) considering intel 12 gen hybrid architecture.
Is there any problem in running vms on hybrid architecture?
Should i go for it?

placid quest
#

@rustic sage <@&861185840277487616>

west rampart
fathom pendant
cinder mortar
#

Need some hints on Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host. for assessment 2 on AD enum and attack, i found the password dumping the lsa, but i cant seem to get the username for that password

fathom pendant
#

Please remove the image as it is actually a spoiler. (Spoiler tagging doesn't really do much) but also is there any other accounts found? Perhaps the actual password itself may be a clue. Think, you're on a windows device

cinder mortar
#

sry

#

hmm ok ill try agn

flint laurel
#

Hello, in attacking common services hard , I'm having problems to find the flag (I can't activate xp_cmdshell.

I get a 0 when trying to impersonate John.
Will appreciate hints and nudges please dm

fathom pendant
#

Iirc there is another sql server you can access through the current one, it's DEFINITELY something I had to do a lot of looking up to get the answer to I can't remember if it's somewhat gone over or not in the sql section

#

But it does require some abstracting

flint laurel
#

I think I found the testadmin

#

On Local.test.linked...

sleek urchin
#

i am still doing Password Attacks Lab - Hard and i reached to somefile.vhd
i have bitlocker2john , produced some hashes, but only cracked one of 2 with the same password
and when i try to mount the vdh file with the pass i found, this what i get

#

Enter key or passphrase ("/dev/sda2"): guestmount: no operating system was found on this disk

#

any help ?

cinder mortar
#

Active Directory skill assessment #2: + 1 Crack this user's password hash and submit the cleartext password as your answer.
I have gotten the user account name via bloodhound but im stuck on how to get his hash, ive tried kerberoasting dumping lsass/sam but got nothing

cinder mortar
#

Ok so i got the password by password spraying but im wondering whats the way to get the users hash

tall saffron
#

in a chapter they told you nmap miss stuff and it is better to connect directly to the service to know more like version of the software used

turbid tartan
#

ad skills assesment 2 : i dont get how to get printspoofer on target system

cinder mortar
#

but how do u get responder to work if u arent logged into ct059 to make the request

cinder mortar
#

Wow just finished AD module, good stuff

spiral pelican
#

hi all
i tried to complete the module Attacking Common Applications but i am stuck on the
Exploiting Web Vulnerabilities in Thick-Client Applications section since several days..
I get an error when i use the cmd : javac -cp fatty-client-new.jar fatty-client-new.jar.src/htb/fatty/client/gui/ClientGuiTest.java
(error: cannot find symbol (for all classes in the file))
and the new class are not created so i cant move to the next step... I cant figure out what i missing out
and i have to say java and me is cleary not a love story xD
If some one can help me on this it will be very apprecitated
tkanks all

queen gazelle
#

Am I missing something obvious?

**"Authenticate to 10.129.159.194 with user "htbdbuser" and password "MSSQLAccess01!" **

On the Attacking Common Services >> Attacking SQL Databases section:

  1. I have attempted to authenticate with mssqlclient.py
  2. I have attempted to authenticate with sqsh -- both normal and windows-auth

Regardless, both methods fail. I am doing this directly from the HTB-supplied machine. I have restarted the target machine twice.

glass locust
#

Worked for me

queen gazelle
fathom pendant
#

Also sqsh seems to be broken in general

queen gazelle
fathom pendant
#

It's broken specifically for parrot, pwnbox is a fork of parrot

#

Iirc people had no issues with sqsh on Kali or Ubuntu systems

queen gazelle
#

Oh, that makes sense. Usually I use my own Kali VM for the labs, but have run into issues which require the Pwnbox specifically -- so for this one, it requires NOT using the pwnbox specifically 😂

fathom pendant
#

I mean no labs really require the pwnbox

#

I've managed pretty fine without it

#

I only really hop on the pwnbox if I think that what I'm doing should get results but isn't for some reason

small steppe
#

#module name: Shells & Payloads
#section name: Reverse Shells
#question: Connect to the target via RDP and establish a reverse shell session with your attack box then submit the hostname of the target box.

I'm using a personal VM with a VPN connection. I've setup up nc listener on my attack box. RDP'd into the target box, no issues. When I run any attempt to establish a reverse shell on the target, powershell either dumps a list of erorrs or powershell just closes out and no connection is established. I've tried using the PS one-liner that's provided in the lesson (adjusting the IP and port accordingly) and I've tried using one-liners from both PayloadAllTheThings and revshells.com. Issue persists. Any help would be appreciated.

Edit: Resolved.

twilit cipher
#

😅

raw gulch
#

Same issue, the module is likely broken and the server ignores every verb it doesn't handle (OPTIONS included)

rustic sage
#

Hi

mystic light
# sleek urchin any help ?

I couldnt get mounting to work on linux in any reasonable timeframe. Instead i pulled it off and mounted on a windows box.

fathom pendant
#

That's been the general move to do

mystic light
fathom pendant
#

I don't recall if anyone was able to mount it

#

On a linux

sleek urchin
mystic light
fathom pendant
#

It's possible but probably something stupid simple that's overlooked

#

Whereas open windows system, do thing is easier

#

¯_(ツ)_/¯

sleek urchin
worthy pagoda
#

did u solve it?

onyx rapids
worthy pagoda
onyx rapids
worthy pagoda
kind turret
#

The question is not about bypassing filters @worthy pagoda

#

So you need to adjust your approach. See the pop-up notification you get when visiting the website and you shall find the way

worthy pagoda
kind turret
#

Absolutely not.

#

Just abuse the form fields

cursive gull
#

Hello, is there someone that I can message to help me better understand why something works on the "AD Skills Assessment 2" please? It has to do with capturing credentials, but I don't want to spoil it.

heady tusk
cursive gull
kind turret
#

It's not misleading: the section does not tell you at all to assume that the last line before the exercise has to do anything with the section's question, it's your own whims.

#

Also, delete the parts of your message that spoil the question. You are giving away the answer as you can guess.

onyx rapids
kind turret
#

I am not arguing, just responding to your messages.

onyx rapids
worthy pagoda
kind turret
kind turret
worthy pagoda
#

its not this module problem, some of modules exactly saying to u, what need to do, but another don't say that and sometimes just get confuse to you, sometimes it's not so obvious) btw this module really good and more like real life lemonthink_hd

onyx rapids
unreal grail
#

Trying to mount the NFSSHARE from NFS - Foothold module. I got this error. Anyone has an hint? It works well when I try to mount the "nfs" share, but I have issue for the second question with "nfsshare"

kind turret
#

No pain No gain 😉

mystic light
#

thats the name of the share, not the share type

unreal grail
mystic light
unreal grail
sterile cove
#

Any languages I should know before starting?

mystic light
tidal mango
# pine dagger ||And the teensy bit before||

I am still battling this, I thought I had it figured out, but it has me edit the htb/fatty/shared/resources/User.java down towards the end of the section. It says to modify the code and shows what to modify. My question is I see two places in the User.java file that look like is where I should modify it. I am a bit confused if I should delete everything in that file and replace it with the code it shows, or just modify one to both places that have the public User(int uid, String username, String password <snip-->) etc? Hopefully my question makes some sense.. Thanks!

#

If anyone else has some insight on Exploiting Web Vulnerabilities in Thick-Client Applications in the Attacking Common Application module for the above question I would love some help. Thanks!

pine dagger
#

Yeah, that was annoying to follow in an example. I believe ||its the one that has less in it. I think that's the second one||, but I'd need to look at the Java to be sure.

#

I mean.. you could literally try changing both, and see what happens 🙂

tidal mango
fallow dagger
#

In the Linux Fundamentals course, in the File Descriptors and Redirections section, the question asks "How many total packages are installed on the target system?". Could someone please explain what exactly I am meant to be looking for please? Is it a specific type of file extension?

mystic light
# fallow dagger In the Linux Fundamentals course, in the File Descriptors and Redirections secti...

at the risk of overexplaining, every "program" you install within linux consists of one or more packages. this could be application functionality or base-OS functionality. there is a command you can run that lists out the currently installed packages. remember that there is more than one package manager in linux world, so make sure youre using the command for the right one for the target OS. This command may or may not display the number right there; cant remember, but there is another command that you could redirect output to somehow that can count the output.

fallow dagger
# mystic light at the risk of overexplaining, every "program" you install within linux consists...

I finally found out how to answer the question, basically I was using the wrong command (||apt instead of dpkg||) and wasn't using the correct filters but after watching a video I was able to understand what I was being asked to do in the question better... Thank you for attempting to help me but in all honesty it was a video that helped by spoon feeding me the way to do it that helped, which I didn't really want to do

fossil crescent
#

As your post is almost a month-old, really hopeful you solved it... but if you haven't, feel free to DM.

tidal mango
pine dagger
#

Are you using their example username?

tidal mango
manic magnet
#

Hey
I am stuck at the Attacking Common Services Module at the SQL section. Enumerate the "flagDB" database and submit a flag as your answer. I already tried things like ||impersonation (but there is no one to impersonate). I also tried just using the the flagDB database but I have no rights. I cracked the password in the task before but I don't know how to use it. I also tried searching for remote databases but also no luck.|| Can someone give me a little push into the right direction ?

pine dagger
manic magnet
#

weird also tried that. I will try again

#

Yeah it says login failed

pine dagger
pine dagger
# manic magnet Yeah it says login failed

Only thing else I can think of without looking at the question again is that you are using ||the wrong username. You're meant to be using the service account. You may need to explicitly identify it with .\\ at the beginning.||

tidal mango
manic magnet
#

@pine dagger
always getting the same error with the other account as well. IDK why that happens. Maybe you know

#

(Thats the default account given in the exercise)

pine dagger
#

Thats not the account that you cracked the password for.

manic magnet
#

yeah I know

#

But I wanted to post the command I used. I just replaced it with the default account so I don't spoil stuff

#

The other one gives the same error

pine dagger
#

Well, I'd have to redo it to confirm, but that's what I have in my notes.

manic magnet
#

weird maybe sqsh is broken ?

lofty saddle
#

vi

#

ls

manic magnet
#

@pine dagger Got it. It wanted ||-windows-auth||. Though sqsh still isn't working. At least I got the task with mssqlclient.py now

unreal grail
#

Hi @plucky rover ! I'm blocked at the same question. Could you provide me some help?

honest ridge
#

is vpn shit today? ive tried us1 and us2 also pwnbox going so slow its unusable

unreal grail
#

In the FOOTPRINTING Module (DNS), I have issue with this question. I tried many combination of "dig" and never found the correct answer. From my understanding the FQDN is [hostname].[domain].[TLD], so I'm looking for an answer of that format, but could not find the answer.

wanton mica
#

For the AD enum & Attacks assessment pt 1, I’m unable to answer question 2….I was able to get a reverse shell, but for some reason can’t upload any tools and use them….whenever I try to upload them via the feature in the web shell, it doesn’t actually work. Anyone else have this problem?

manic magnet
#

Can you send me what you tried via DM ?

#

Because if you played around with dig you should have found it by now and I guess you just have some minor mistake

quiet ember
#

For Password Attacks > Credential Hunting in Linux, does anyone know the intended way without using the hint? I don't see how I was supposed to get it without the pass from the hint.

rugged veldt
#

Unable to find the upload path for file upload skill assessment. Anyone able to help?

jolly dagger
#

Is there a way to press the windows key to get a powershell prompt while in xfreerdp? Using macOS > to the parrotOS instance > windows box.

jolly dagger
fathom pendant
nova ocean
#

hello guys i am stuck on linux fundamental ,file system, What is the size in GiB of the "/dev/vda" disk in our Pwnbox? (Format: 000)
can anybody help? please?

fathom pendant
#

I believe the command is lsblk

nova ocean
#

wait let me try

#

boom

#

ur a king man

#

thank u

#

i was suffering for 2 days lol i finish all only this one stuck

fathom pendant
quiet ember
lilac halo
#

hi , i am doing Kerberoasting - from Linux section from ACTIVE DIRECTORY ENUMERATION & ATTACKS module and i have issue with GetUserSPNs.py script is askingo for password

analog urchin
#

If anybody experiences difficulties with the US VPN's, always try switching to EU. For some reason US rarely works for me.

rustic sage
#

can I ask question regarding SQLMap Essential Attack Tune module?

#

I found a flag but seems like it doesn't work 😦

fathom pendant
hoary mauve
#

can i get a nudge for the CBBH session hijacking part of the XSS module? i cannot get any payloads to work (i don't see any traffic being made to my local server from the target), and i'm at a loss for what i'm doing wrong

near quartz
#

Starting point 1 is not avalible at the moment?

#

will starting point 2 work the same

#

@ me pls

#

if answer

fathom pendant
fossil crescent
#

Hoping you already solved this, but if you're still stuck on it, DM me.

nova magnet
#

Hi guys, I am stuck on SeTakeOwnershipPrivilege section from WINDOWS PRIVILEGE ESCALATION module.
My issue is that whoami /priv does not include either enabled or disabled SeTakeOwnershipPrivilege with the htb_student rdp account.
Did I miss some steps to access the privileges? The post mentioned SharpGPOAbuse but there seems no instructions with it.

languid hollow
carmine hill
burnt sluice
languid hollow
#

@burnt sluice thanks, i was just a dumby and didnt realize I was looking at the answer 💀

nova ocean
#

Anw i got my answer thank u

rustic sage
#

hey guys quick question

#

for nmap enumerating, the module mentions that the nmap connect scan is the most stealthy way of determining the state of a port

#

but on nmap documentation nmap says that the most stealthy way isn't -sT (connect) but -sS (TCP-SYN)?

#

This is the most basic form of TCP scanning. The connect() system call provided by your operating system is used to open a connection to every interesting port on the machine. If the port is listening, connect() will succeed, oth erwise the port isn’t reachable. One strong advantage to this technique is that you don’t need any special privileges. Any user on most UNIX boxes is free to use this call.

This sort of scan is easily detectable as target host logs will show a bunch of connection and error messages for the services which accept() the connection just to have it immediately shut- down. This is the default scan type for unprivileged users.``` <- from nmap docs
#

The Connect scan is useful because it is the most accurate way to determine the state of a port, and it is also the most stealthy. Unlike other types of scans, such as the SYN scan, the Connect scan does not leave any unfinished connections or unsent packets on the target host, which makes it less likely to be detected by intrusion detection systems (IDS) or intrusion prevention systems (IPS). <<-- from HTB

#

anybody able to provide any clarity on that?

#

from what i've read, with -sS the TCP packet flow is SYN-SYN/ACK - RST which means the handshake never completes

#

however with -sT it performs a proper handshake (SYN - SYN/ACK - ACK) which actually establishes a connection

#

so surely the server would notice the connect scan as opposed to the TCP-SYN scan?

summer prism
#

Footprinitng SNMP
Q) Enumerate the custom script that is running on the system and submit its output as the answer.

Any hints?

heady tusk
lament tiger
#

hello i need help

#

i cant connect hackthebox vpn with kalilinux

summer prism
summer prism
lament tiger
#

?

#

how do i connect ut

summer prism
#

sudo openvpn <directory to .ovpn file>

small raptor
#

did you solve the challenge ? if not, I can give you some hints

buoyant prawn
#

Hello everyone?
Are HTB writeups prohibited? For example if you write a walk through without revealing the the flags, is that prohibited?

buoyant prawn
#

Thanks mate

torpid knoll
crimson walrus
#

Hello everyone.
I need help with the Port Forwarding with Windows Netsh part of the Port forwarding and pivoting module.
I can rdp to the pivot but I don't have admin rights to run netsh.exe. Can someone give me a tip on how to do the privilege escalation here?

rustic sage
#

hey, am in Windows Priv Esc PILLAGING, i got the SAM and SYSTEM files, i used samdump and impacket-secretdump and got the hashes and but nothing seems to be working for the Admin hash as the correct answer, can someone give me a heads up on what i might be doing wrong?

autumn pilot
#

There are a few snapshots, you will have to find the one that will work

#

Hint: Take into consideration the time and the paths

rustic sage
autumn pilot
#

¯_(ツ)_/¯

rustic sage
#

fair thanks for the info

#

give me a sec, because i retrieved them and dumping them offline

fiery berry
rustic sage
crimson walrus
untold parcel
#

I need help with the Active directory enumeration & attacks skill assessment II

rough anvil
#

hey, stuck on this as well, would you be able to give me a nudge?

quaint wing
#

can we earn cubes without passing by modules ?

autumn pilot
dim hound
rustic sage
quaint wing
dim hound
versed spear
#

Any experts of John here or at least know it well enough to mentor?

lament tiger
#

hey

#

is it legal to hack one of my own emails?

manic magnet
#

depends what you mean with hack and email I guess

lament tiger
#

like if i send a phising attack to one of my other emails

primal sundial
#

<@&861185840277487616>

burnt sluice
#

....

#

check the description of this bot

#

PYTHON AI DEVELOPER

manic magnet
wintry river
lament tiger
#

oh okey thanks

manic magnet
lament tiger
#

haha yes

burnt sluice
slate shell
#

Can someone help me with the nessus assessment, the 172.16.16.100 ip doesn't seem to work

manic magnet
#

Which module is it ? @slate shell If its Vulnerability Assessment you can DM me

fossil crescent
cedar gull
#

hello guy, how is it going? I'm so stuck on the first brute force Skills Assessment. I easily succeeded with the first flag but for the second am going mental. Can anyone help?

manic magnet
cedar gull
craggy wing
#

Hello, I need help completing the Blind SSRF module in hack the box

fathom pendant
#

If you read you'll see that in order to access other channels you need to verify your HTB account here.

#

Second: it's rude to just randomly @ or reply to people

lethal atlas
#

gm everyone

small steppe
#

Module: Shells & Payloads
Section: The Live Engagement
Question: Connectivity Issues

Description: I'm having issues connecting to the foothold host for the Live Engagement. Attempts to SSH or RDP into the host with the provided credentials result in connection time out errors, connection failed, or connection refused.

Im using a VM with the VPN key. Ive tried redownloading the VPN file. No success with a refreshed key. Same results from the pwnbox. Any help is muchly appreciated.

scarlet sapphire
#

Module:Cracking Passwords with Hashcat
Question:Cracking Common Hashes
hi i have tried most of rules but i cant find it can u give me a hint

small sage
small steppe
queen gazelle
#

Possible suggestion for the HTB Team --

I am working through the "Attacking Common Services - Easy Lab" -- in the "Resources" there is a user list and a password list. These lists are used throughout the module for attacks require a bruteforce. In addition, the user list is used in the lab to discover the correct username.

Nevertheless, to find the password, you then have to switch to the "rockyou.txt" wordlist (which I learned after too much experimentation to figure out what I am missing). If the module provides a user/password list --- but there is a part that requires a different list --- please provide this information. The constant experimentation with random wordlists does not help the student learn the bruteforcing process. In the real world, pentesters generally have standard wordlists they use (or wordlists that are discovered through enumeration on the target domain) and bruteforcing is done via high-end "cracking" machines or renting cloud machines.

Randomly experimenting with wordlists, especially when it's unclear at best, leads to frustration -- not learning.

Of course, all in my opinion so take it with a grant of salt 🙂 always a good chance I am missing something HTB team is trying to accomplish!

small sage
small steppe
small sage
small steppe
#

Yeah, I reset the target host a couple times, redownloaded the VPN file, tried accessing from the pwnbox...nada.

dim hound
small steppe
# dim hound use `'HTB_@cademy_stdnt!'` in quotes

Just tried.

──(kali㉿kali)-[~/Kali_Host]
└─$ xfreerdp /v:10.129.126.213 /u:htb-student /p:'HTB_@cademy_stdnt!'
[10:59:30:523] [74259:74260] [ERROR][com.freerdp.core] - freerdp_tcp_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_FAILED [0x00020006]
[10:59:30:523] [74259:74260] [ERROR][com.freerdp.core] - failed to connect to 10.129.126.213

dim hound
#

hmm, can you ping that ip ? @small steppe

small steppe
#

Yup.

dim hound
#

hmmm that's weird. I would reset the machine

small steppe
#

Ive done that. Atleast twice.

dim hound
#

Which module is this, I can try it myself in 5-10 mins ; )

small sage
#

Are you using tcp or udp vpn key?

dim hound
#

udp

small steppe
#

Module: Shells and Payloads
Section: The Live Engagement

#

udp

dim hound
#

try to switch to TCP

dim hound
small sage
small steppe
dim hound
small steppe
#

Muchly appreciated -- I was throwing myself at the wall over this.

dim hound
small sage
dim hound
#

hmmm that's a weird erorr.. well pm me after work 😁

mystic light
silent knoll
#

Hello! Can anybode give me the Payload for the Cross-site scripting / session hijacking part? Ranning out of ideas ..

autumn pilot
#

The payload of which stage?

#

The exercise is based on the material, so if you have understood the material you can use it in your advantage

silent knoll
autumn pilot
#

I can assure you it works

silent knoll
#

i used every input field

autumn pilot
#

Take a break, and rethink

silent knoll
#

getting no response in my php server

silent knoll
silent knoll
autumn pilot
#

All that you need to solve it is within the material of the section

silent knoll
autumn pilot
#

can't be more precise on that mate

silent knoll
#

Bro your tip is not more than "check your material" :/

autumn pilot
#

Yes, because everything you need to solve it is in it

silent knoll
#

then for what is this academy-chat, everything is solvable with the knowledge from htb

#

its about getting stuck and helping others out, nvmd

autumn pilot
#

Agree, however, you are asking for the payload directly and not a specific question

#

which makes me think, that you don't want to bother much on troubleshooting it why it is not working, but rather just to have a working one from someone else

lament tiger
#

hey guys how do i start solving a challenge?

silent knoll
dim hound
silent knoll
#

The ip i entered is also correct, checked that several times

autumn pilot
#

break the things in to multiple pieces, pick one and try if it works and if it does move onto the next one

dim hound
#

You can't simply copy + paste stuff.. each websites filters the XSS payload slightly differently. By advise; open inspect element, and verify how your payload is being filtered on the webpage.

silent knoll
lament tiger
#

guys

#

do i have to connect hackthebox vpn everytime i am opening it again?

silent knoll
dim hound
silent knoll
mystic light
# silent knoll How can i see how the backend is processing it? I cant find any frontend process...

with php the backend code is abstracted away and processed on the sever only. it then returns to you html or files that have been processed.
the whole point of the module youre on is to throw stuff at the inputs methodically.
if your server isnt getting responses, maybe youre trying the wrong input. maybe your server command is incorrect.

"can i get the answer" isnt a good way to learn. explain what you did, explain whats wrong, and ask for a hint. users are are much more apt to respond to someone who shows that they tried.

silent knoll
mystic light
rugged stag
#

Did you solve this by any chance?

zinc sentinel
wanton mica
#

Hey guys, having a tough time with question 7 of the AD Enumeration & Attacks - Skills Assessment Pt 2….I was able to get a mssql session going….but xp_cmdshell doesn’t give much other than a headache lol.
Any nudges?

dim hound
#

@wanton mica Are you able to execute xp_cmdshell?

queen gazelle
queen gazelle
#

Another suggestion to HTB staff (and other students who might be stuck) -- The "Attacking Common Services - Medium" lab is supposed to have 6 services come up (based on the forums). I have restarted the target twice so far, waited 5+ minutes for my scan, and nmap -p- scan is still only returning 4 services. No way I would know that I am missing the main services without reading the forum. It may be helpful to add a note on the number of services that SHOULD be exposed, and that some students have reported issues seeing all the services.

I am on to rebooting the target for the 3rd time to see if I can finally get the services to start.

autumn pilot
#

yeah, it takes a few resets and a couple of minutes of waiting for that port and service to work

queen gazelle
queen gazelle
broken warren
#

Session Security skills assessment. How do we even start that? Like are we supposed to guess the admin email? should it be obvious? is it necessary? I've done every other exercise in the module but don't get how im supposed to approach this one. It seems like every other exercise i had known victim and attacker credentials.

balmy lion
#

hello, can somebody provide me with a bit of a sanity check pls?

module: ACTIVE DIRECTORY ENUMERATION & ATTACKS
section: AD Enumeration & Attacks - Skills Assessment Part II

Q: I have system priv on ||SQL01|| and know that i need to get the pass for ||mssqlsvc|| but i cant crack the ntlm hash and the password i get from tools seems to still be partially encrypted? i know it has something to do with ||Sup3rS3cur3...|| but im not getting its cleartext version only something similar to this (but with the actual password inside)||;.6.b.u.^.u.r.;.m.J.&.E.S.&.#.I.u.).C.Q.Z.e.c.k.||
How should I figure out what the actual, full pass is?

steady hawk
balmy lion
small steppe
#

Module: Shells & Payloads
Section: The Live Engagement
Question: Host 2 - Exploit the blog site and establish a shell session with the target OS. Submit the contents of /customscripts/flag.txt.

So, I have my exploit in MSF and I set the options. Exploit returns an error (see image). I did some searching on the Discord and it looks like I'm doing everything appropriately -- unclear why I'm getting this error. Any ideas?

Edit: Resolved.

wanton mica
wanton mica
dim hound
#

Then enumerate from there

wanton mica
dim hound
#

hahah no worries 😁 get a full-interactive shell. It's windows, I would use: ||rlwrap nc -lnvp <port>||

rustic sage
#

Hello am generating a reverse_tcp on dll file, am running the dll and i am geting a connection on my machine but no reverse shell. Is something that i need to be careful of?
Nevermind :}

onyx rapids
#

I have finally completed HTTP Attacks module, it was painful and I contemplated my existence many times, but it's done now. If anyone ever stumbles upon this, you can message me for hints, so you don't have to lose your mind like I did

dim light
#

hey guys
i have a problem to solve skill assessment the "File upload" module
any body can help me?

#

i understand all of step and solve them but have a problem in last step (get the flag)

hollow jay
#

Hey there ! I have a question :
The exams : " HTB Certified Penetration Testing Specialist " if i buy a ticket. i dont give me access to all modules ? they just give me two tickets to take an exam?

#

(sry idk if its the right channel)

honest hazel
#

can anyone help with a nudge on file uploads skills assessment?

#

i'm pretty close

hollow jay
crimson crown
#

hmmm

fathom pendant
fathom pendant
crimson crown
#

has anyone successfully installed BIND9 on their local parrot os VM?

#

fpr the footprinting module

#

*for

fathom pendant
#

You don't really need to install bind for it

fathom pendant
crimson crown
#

wanna follow alongf

#

and do the same

#

to test

#

there is a dependency conflict however when I try to install it

fathom pendant
#

Then install the dependency

#

¯_(ツ)_/¯

dim hound
#

atm I am doing Footprinting -> Oracle TNS -> I receive the following error. Does someone has a solution for it? bash ┌──[🛡️ f0rk] └──╼[🔥]/opt/blackbuntu/odat $ sqlplus scott/tiger@10.129.205.19/XE; sqlplus: error while loading shared libraries: libsqlplus.so: cannot open shared object file: No such file or directory ┌──[🛡️ f0rk] └──╼[🔥]/opt/blackbuntu/odat $ sudo sh -c "echo /usr/lib/oracle/12.2/client64/lib > /etc/ld.so.conf.d/oracle-instantclient.conf";sudo ldconfig

crimson crown
#

Some packages could not be installed. This may mean that you have
requested an impossible situation or if you are using the unstable
distribution that some required packages have not yet been created
or been moved out of Incoming.
The following information may help to resolve the situation:

The following packages have unmet dependencies:
bind9 : Depends: bind9-libs (= 1:9.16.37-1~deb11u1) but 1:9.18.12-1~bpo11+1 is to be installed
E: Unable to correct problems, you have held broken packages.

fathom pendant
#

it's prob a weird edge case sorta thing but like I said. It's not needed and a lot of the 'follow along' isn't too important. ¯_(ツ)_/¯

bright hemlock
#

hi guys, any pointers on the username injection task in broken auth module? just getting passwords don't match? - nevermind. for some reason the server bugged. reset and tried again and it worked, love wasting time !!

fathom pendant
dim hound
#

Nope.. I following the troubleshoot step

#

But it's not working

fathom pendant
#

I'd also suggest adding the odat to your $PATH

#

For some reason it doesn't like to add it to path

#

But I didn't really have any issues with it not working (fully up-to-date parrotOS)

dim hound
#

hmm

#
┌──[🛡️ f0rk]
└──╼[🔥]/opt/blackbuntu/odat $ export LD_LIBRARY_PATH=/usr/bin/sqlplus:$LD_LIBRARY_PATH
┌──[🛡️ f0rk]
└──╼[🔥]/opt/blackbuntu/odat $ sqlplus scott/tiger@10.129.205.19/XE;
sqlplus: error while loading shared libraries: libsqlplus.so: cannot open shared object file: No such file or directory
fathom pendant
#

¯_(ツ)_/¯

dim hound
#

got it

#

I had to add this: export LD_LIBRARY_PATH=/usr/lib/oracle/21/client64/lib:$LD_LIBRARY_PATH

#

Thanks to chatGPT ❤️

fathom pendant
#

¯_(ツ)_/¯

#

If it works it works

dim hound
#

yUP HAHA

fathom pendant
#

I just followed the script they provided

dim hound
#

I did too..

#

I am using Blackbuntu tho

fathom pendant
#

as in copy pasted to a file then chmod +x ¯_(ツ)_/¯

dim hound
#

I did that too

fathom pendant
#

Weird then

dim hound
#

well I did: sudo bash <script>.sh

#

it's the same tho

fathom pendant
#

Only issue I had was the predic

dim hound
hollow jay
#

I've got troubles in my File Upload module ^^'

#

If someone already finished this module ^^'

rotund urchin
#

Can I chat with someone about the answer for the SMB module and what the full path of the share is? Its not accepting my answers and I am not sure why.

fathom pendant
#

Iirc

wanton mica
#

I have a question related to AD enum & attacks skills assessment 2…

How the hell is everyone able to use ||PrintSpoofer||? I’ve tried compiling it on both windows and Linux and it just won’t work…and for some reason I can’t install winegcc

half inlet
#

Can anyone help me with the DNS section on the Footprinting lesson? I have no idea what to do. I tried using Dig and DNSEnum, but I couldn’t get the answer for any of the questions, I don’t really understand what to do

wanton mica
half inlet
#

I tried that by using dig with AXFR, I saw a few text entries but I didn’t know what to do with that

#

I tried digging the subdomains I got but I couldn’t get anything else either

wanton mica
half inlet
#

Don’t really understand

fathom pendant
#

Read your axfr results

#

Any further hints would basically spoil it

wanton mica
#

Yes…what Master Marcie said

fathom pendant
#

As far as the octet of x.x.x.203, subdomains of subdomains

rustic sage
#

Hi i m new here

half inlet
#

Wait which problem are you guys talking about?

rustic sage
#

Don't know anything

#

Pls help

half inlet
#

I was looking at the second one with txt

rustic sage
#

Feom where i have to atart

#

Start

fathom pendant
half inlet
#

Yeah but which problem on that section

fathom pendant
#

Doing a zone transfer to one of the subdomains gives you the text record

half inlet
#

So I would use dig to get AXFR on one of the subdomains?

fathom pendant
#

Yes

half inlet
#

Ah I see I got it

#

I really don’t understand DNS I have such trouble understanding it 😭

fathom pendant
#

The section kinda goes over it a fair bit

half inlet
fathom pendant
#

Nope

half inlet
#

Oh I guess not because it’s not a web server huh

fathom pendant
#

Well... Not necessarily

#

Inlanefreight.htb is just the domain name

half inlet
#

Are website FQDN’s and DNS FQDN’s two different things?

thorn urchin
#

no

fathom pendant
thorn urchin
#

so a FQDN specifies the full domain name for a specific instance, the domain name is just like the root of it

#

fqdn = hostname + domain name

fathom pendant
honest hazel
#

i'm on my last module and i've made it most of the way through. I'm stuck at the user.java part in the fatty client. i've overwritten the two sections the chapter discusses, but I'm still not able to get qtc' or the sql string to bypass auth for me. anybody have any pointers?

half inlet
fathom pendant
#

Read the question carefully

half inlet
#

Because I got several such as mail1, ns, app, dev, internal, root

fathom pendant
#

It's asking you the fqdn of a specific thing

half inlet
#

Ah, I’ll check again in a bit I have to go to a different class now

dreamy forge
#

hey guys
does anyone know how to rub commands like osintgram and aircrack-ng or hydra
because most of the people put these contents on youtube but they don’t explain it with more details

#

most of the videos on social media also doesn’t tell you exactly how

#

they just tell you what is used for but they don’t tell you exactly how to do it or they don’t explain much about

honest hazel
#

man tool

thorn urchin
fathom pendant
#

There is a module related to aircrack iirc

#

But yeah their phrasing indicates they're just watching a video

dreamy forge
#

guys i know man or help commands but i some places u have to specify a file or it should be done through root
most of the youtubers don’t tell you that

honest hazel
#

i've recompiled the fatty.server and gone through all the source code with jd-gui

fathom pendant
thorn urchin
dreamy forge
#

thx guys i think i was just a noob to ask here

thorn urchin
#

its not about being a noob or not, this just isnt the correct place.

honest hazel
#

but for some reason when I move user.java over to the raw folder and recompile the java app, launch traverse.jar it fails to log me in with qtc'

fathom pendant
#

And you're being pointed to the correct place

#

If you fucking read

languid hollow
fathom pendant
honest hazel
#

this is my last mod in the whole cpts deallyo

fathom pendant
#

Lol you got this

honest hazel
#

and I'm like....allllmost there

#

lol

fathom pendant
#

It's not on the exam at least

dreamy forge
thorn urchin
# dreamy forge i think u should also read the rules for being disrespectful

The alternative is we start pinging mods about ya being offtopic till you get the boot. You can either take the genuine advice and eventually get the help you're looking for or you can bitch at the people pointing you in the correct direction and go nowhere like the 6521 other unverified users before you.

fathom pendant
#

^

thorn urchin
#

This occurrence plays out daily here.

fathom pendant
#

It gets tiring explaining the same thing every other hour

thorn urchin
#

Youd pick crying over reading, amazing

dreamy forge
#

😂 as long as u guys get angry

thorn urchin
#

Not angry, just disappointed

dreamy forge
#

about urself?

languid hollow
#

Idk man these people are pretty active an helpful to peeps. I wouldn't be pissing off the peeps that will likely be the ones you want help from in the future.

thorn urchin
#

This is off topic enough as is. Lets stop it now or we shall just get mods invovled

fathom pendant
#

Ugh I need to get back to rewriting my notes

dreamy forge
languid hollow
#

What? lol

fathom pendant
#

Imagine thinking this is a job

#

That we're doing

languid hollow
#

Look at their roles

thorn urchin
#

@carmine kiln can you please get @dreamy forge on topic please 🙏

dreamy forge
#

ok then u guys can choose to not answering me

fathom pendant
#

Hey f0x can I pay you in a highfive to redo my modules and write my notes

dreamy forge
#

theres a lot of people here to answer

languid hollow
#

Oh snap, should I be taking notes?

fathom pendant
#

Yeah probably

thorn urchin
#

moron

fathom pendant
dreamy forge
#

thank you

#

finally i am reaching a point

thorn urchin
#

Reading hard

dreamy forge
#

was it so hard to say that from the beginning

thorn urchin
#

We did

#

holy fuck

mystic light
fathom pendant
#

Dude it's in the rules that you failed to comprehend

dreamy forge
#

say whaaaaaaat

thorn urchin
#

If you cant read maybe pick a different field to learn

dreamy forge
#

i am peaking cyber security to just write commands

#

lul

#

yo what is reading i just got here

languid hollow
thorn urchin
#

@sterile hawk since woodenk seems busy can you get our dear friend @dreamy forge on topic please

dreamy forge
#

ok ok don’t f me just stop it i got bored of this

#

u are write and i am wrong
ok ?

#

right*

#

sorry

#

close this topic

#

ok so how was the weather today?

thorn urchin
#

also off topic

#

moron

dreamy forge
#

😂

#

ay yooooo

thorn urchin
#

@coral sundial can you get @dreamy forge on topic please? I dont want to ping serious rule break.

dreamy forge
#

guys

#

just chillout

#

don’t get mad

#

just talk about somthing else

coral sundial
fathom pendant
#

this channel is about academy modules

thorn urchin
#

its not about something else, this channel is for academy module discussion

#

its not a general chat

dreamy forge
#

dude i am new here and also for ethical hacking

thorn urchin
#

I dont care

dreamy forge
#

ok so what should i do now

thorn urchin
honest hazel
dreamy forge
#

can i just skip that please

coral sundial
dreamy forge
#

i hate reading

#

well

acoustic owl
#

Maybe it would be helpful to unlock this channel for verified users only

thorn urchin
dreamy forge
#

ethical hacking and cyber security
because i am a junior student in university (department of computer engineering)

coral sundial
thorn urchin
dreamy forge
#

i don’t have access

thorn urchin
#

no shit

dreamy forge
#

yup i need a husband

acoustic owl
coral sundial
dreamy forge
#

after that what ?

thorn urchin
#

read it

#

christ how stupid are you

coral sundial
#

Read, understand and you will see the other channels

fathom pendant
#

They are trolling at this point

thorn urchin
#

already been told 50 times to read the channel and literally too stupid or too trolling to do so

#

just boot em already

dreamy forge
#

can i put photos to show you

#

which channel i have access

thorn urchin
#

No

thorn urchin
#

we already know what ones you dont have access

fathom pendant
#

the oracle tns section of footprinting was interesting ¯_(ツ)_/¯

thorn urchin
#

were telling you how to get access

#

but youre too stupid

coral sundial
#

Time out 1 hr

fathom pendant
#

Also, cannot post images without being verified

knotty cosmos
#

Hello

thorn urchin
thorn urchin
fathom pendant
knotty cosmos
#

Please I have started my introduction to academy

#

And I have gotten to the interactive section with terminal

#

And the question is based on the command "name -a" that I executed, what's likely to be the operating system flavor of the instance?

#

Please how do I analyse this question?

thorn urchin
#

What part of the question gives you trouble

acoustic owl
half inlet
#

Hmmm. Still very stuck on this; it wants me to enumerate the FQDN for the target dns but how do I get that?

#

Whoops

#

Mean to replay

#

Reply*

half inlet
knotty cosmos
#

@acoustic owl Yes please

fathom pendant
half inlet
#

A ptr record right?

coral sundial
half inlet
#

I tried doing ‘dig ANY inlanefreight.htb @(the ip it gave me)’

#

And dig PTR

fathom pendant
#

You're looking for a specific type of record

#

After all a DNS is this type of server

half inlet
#

NS record? 🤔