#modules

1 messages ยท Page 74 of 1

pine dagger
#

haha

acoustic owl
#

Python is very cool. It has saved my ass at the CBBH

pine dagger
#

Yeah. I am a big fan of Python, although I was listening to a podcast (I think it was Luke from LTT WAN Show), and a comment that was made was that Python is one of the worst languages to start learning programming. Not because its hard, but because it teaches so many bad behaviours that other programming languages don't allow, i.e. adding Integers to strings.

livid pier
#

Good morning everyone! Im trying to do the Pass the Ticket from Linux section on PASSWORD ATTACKS and david's provided password isnt working? Anyone experience this?

ashen fog
#
ACTIVE DIRECTORY ENUMERATION & ATTACKS  
Privileged Access

The Hint says i need to use mssqlclient.py but from the VPN i cant access 172.16.5.150 do i need to perform Port Forwarding

Leverage SQLAdmin rights to authenticate to the ACADEMY-EA-DB01 host (172.16.5.150). Submit the contents of the flag at C:\Users\damundsen\Desktop\flag.txt.

acoustic owl
mystic light
# pine dagger Yeah. I am a big fan of Python, although I was listening to a podcast (I think i...

i come from a bunch of years of software dev. i can understand that argument, but i think the basic skills are super important. loops, functions, conditionals.. that stuff transfers to most other languages really well, and once you learn it, its mostly just a matter of syntax and keywords. it does play fast and loose with types which, if youre unprepared for, can be a challenge if you move to say C++. also python has what id call an imperfect implementation of OOP, and its not the language id recommend for learning that paradigm ๐Ÿ˜› but for scripting? fantastic.

livid pier
#

Password2

#

Ive moved back a couple sections to the gneral pth, i need to do this too. The object is to crack davids hash, maybe it will be different

fathom pendant
#

Yes it may be different

pine dagger
acoustic owl
#

Try using a different VPN. Just change the region to US or EU, depending on what you are using now. I had this problem once with another module with a Windows client.

fathom pendant
#

It's been a moment since I did this module

livid pier
mystic light
autumn pilot
#

ssh david@inlanefreight.htb@TARGET_IP -p 2222

pine dagger
#

Its very fast.

pine dagger
acoustic owl
naive field
#

Hey guys please help on shells and payload s metasploit module

#

i can not scan the machine

#

at all

#

but i can ping it

#

so i know its online

#

please hel

#

p

#

"Exploit the target using what you've learned in this section, then submit the name of the file located in htb-student's Documents folder. (Format: filename.extension) "

#

i tried -Pn also but nope

#

i got it, i was scanning with scripts

fathom pendant
pine dagger
#

They already solved it ๐Ÿ™‚

naive field
#

not do anything on my own

#

lol

#

i was trying ot fingerprint it etc...

fathom pendant
#

Lol yeah the shells/payloads section is very much follow the steps

naive field
#

for infiltrating windows

#

but i get this error when i try to exploit

#

in metasploit

#

and it says exploit completed but no session

fathom pendant
#

Ah I forget what I did fully I think it was a case where I just had to restart msfconsole because dumb

fathom pendant
#

No problem, not entirely sure what causes it to be fucky wucky but turning it off and on, age old solutions

bleak coral
#

hey how i can connect to my hackthebox profile?

autumn pilot
naive field
#

creds

#

how do i log in?

autumn pilot
#

php webshells?

naive field
golden vortex
#

im doing the footprinting module section dns and im stuck on the question Identify if its possible to perform a zone transfer and submit the TXT record as the answer.

#

ive found one zone but wasnt there

surreal marsh
#

Hi guys is there anyone by any chance that tried to set up a Windows11 VM on Virtualbox on Linux as a host operating system? And installed wsl2 on it and was able to run let's say Ubuntu?

jaunty vigil
#

anyone able to figure this out?

#

Exploit the Heartbleed bug to obtain the server's private key. Submit the first 10 digits of d

#

in https attacks

#

the .jar heartbleed exploit in tls-breaker doesn't work..

golden vortex
#

use metaploit

jaunty vigil
#

which 1?

fathom pendant
naive field
autumn pilot
#

I don't know neither the module nor the section

naive field
#

haahah

#

its shells and payloads module

#

php webshell section

autumn pilot
#

admin:admin ?

near bay
#

hello, I have a little problem I can't get a return from "ping (ip address)" on the getting started module: public exploits, is that normal? i have restart target lot of time and download a new vpn file and test on the interactive instance , same problem

autumn pilot
#

does the target have a port

near bay
#

yes

autumn pilot
#

how can you ping a target with a port

near bay
#

I ping without the port and so far I've had feedback!

autumn pilot
#

have you tried to use the target with the port in a web browser

naive field
#

can anyone help me with the sells and payloads live engagement. im still at the beggining just connected to the rdp

#

cant seem even to answer the 1st question lol

#

thanks

autumn pilot
#

the first question can be solved with knowledge from a previous module

near bay
#

I had tried without return, I have just restarted the instance and I finally have something by typing the address thank you!

jaunty vigil
#

anyone can give me a nudge on https/tls attacks skill assessment

deft bison
#

Anyone working on the "Attacking Domain Trusts - Child -> Parent Trusts - from Windows" section in the Active Directory Enumeration & Attack module? If yes, are you able to rdp to the htb-student_adm?

autumn pilot
#

yes?

soft vortex
#

my friend who is a hacker says he can explode boilers and set a fire in houses with hacking. is that true?

fathom pendant
#

I mean. Theoretically yes, though setting a fire in a house is less likely

soft vortex
#

he says he set 3 houses on fire

fathom pendant
#

Boiler just requires the fail-safes to also be electronic

fathom pendant
soft vortex
#

i sound stupid for saying this but what?

autumn pilot
#

please keep the channel on topic

fathom pendant
#

Sorry

#

I'm just prodding at bullshit

soft vortex
fathom pendant
#

This is getting off-topic and Google is free, Google what a failsafe is

digital pewter
#

@Staff - Any plans on adding some type of Offensive C# module to the academy?

royal current
#

Almost a year after you still help man ๐Ÿ˜‰ Tnx

sly parcel
#

I cannot connect to RDP -.-

thorn urchin
fathom pendant
sly parcel
fathom pendant
#

Have you tried using Remmina? To see if it's just something up with xfreerdp

sly parcel
sly parcel
#

will investigate remmina

soft vortex
# sly parcel

can you please tell me how this thing works does it just boot people or something?

thorn urchin
#

ive noticed sometimes that the rdp services take a hot minute to actually spin up too

thorn urchin
soft vortex
#

oh alr

#

i got banned in a rando server for being toxic to a toxic person ๐Ÿ˜‚ i did go a bit too far tho

thorn urchin
#

this isnt a generic chat or learning channel. if you want those you have to verify your account

sly parcel
thorn urchin
#

do you have pwnbox and vpn active at same time?

sly parcel
#

Yes

thorn urchin
#

thats your problem

#

one or the other

#

never both

sly parcel
#

Oh I thought I needed the VPN

#

oops

thorn urchin
#

causes problems

sly parcel
#

ggs xD

thorn urchin
#

if you disable vpn your vpn and xfreerdp will magically work again

#

the vpn is if you want to use your own machine/vm for the labs instead of pwnbox.

sly parcel
#

Aaaaaaaaah

#

oh wait, so I didnt need to spend the $18 to have unlimited pwnboxes? I could have just used my local? .-.

fathom pendant
#

Yes

#

Though pwnbox is useful for ts

sly parcel
#

I mean, I do just want to get more familiar with Linux so its whatever ig ๐Ÿ˜›

fathom pendant
#

I mean you want to use a Linux vm

#

Not your host system

#

In case you do a fucky wucky

sly parcel
#

Ah yeah

sly parcel
#

Stealing

fathom pendant
#

Also Linux VM because the commands in modules won't line up with windows cli/PowerShell

jaunty vigil
#

did anyone do this?

#

i think i got it figured it out, but its not taking my answer

#

i even tried different combinations but its not budging :/

quasi wave
#

hi is anyone able to help me with the Intro to BASH module's for-loops section?

#

anyone I can DM to get help with my code?

jaunty vigil
quasi wave
#

thanks

jaunty vigil
#

just say it here ๐Ÿ˜„

#

no need to ask to ask

acoustic owl
jaunty vigil
#

yeah

#

this new azure stuff is interesting

halcyon pond
#

Hey can Someone give me a nudge on transferring files to MS01 on ad enum and attacks skill assessment im pretty stuck

acoustic owl
jaunty vigil
acoustic owl
quasi wave
#

Please don't just give me the answer I want to be guided to the answer so I can figure it out.

Instructions:
Create a "For" loop that encodes the variable "var" 28 times in "base64". The number of characters in the 28th hash is the value that must be assigned to the "salt" variable.
My code:

#!/bin/bash

# Decrypt function
function decrypt {
    MzSaas7k=$(echo $hash | sed 's/988sn1/83unasa/g')
    Mzns7293sk=$(echo $MzSaas7k | sed 's/4d298d/9999/g')
    MzSaas7k=$(echo $Mzns7293sk | sed 's/3i8dqos82/873h4d/g')
    Mzns7293sk=$(echo $MzSaas7k | sed 's/4n9Ls/20X/g')
    MzSaas7k=$(echo $Mzns7293sk | sed 's/912oijs01/i7gg/g')
    Mzns7293sk=$(echo $MzSaas7k | sed 's/k32jx0aa/n391s/g')
    MzSaas7k=$(echo $Mzns7293sk | sed 's/nI72n/YzF1/g')
    Mzns7293sk=$(echo $MzSaas7k | sed 's/82ns71n/2d49/g')
    MzSaas7k=$(echo $Mzns7293sk | sed 's/JGcms1a/zIm12/g')
    Mzns7293sk=$(echo $MzSaas7k | sed 's/MS9/4SIs/g')
    MzSaas7k=$(echo $Mzns7293sk | sed 's/Ymxj00Ims/Uso18/g')
    Mzns7293sk=$(echo $MzSaas7k | sed 's/sSi8Lm/Mit/g')
    MzSaas7k=$(echo $Mzns7293sk | sed 's/9su2n/43n92ka/g')
    Mzns7293sk=$(echo $MzSaas7k | sed 's/ggf3iunds/dn3i8/g')
    MzSaas7k=$(echo $Mzns7293sk | sed 's/uBz/TT0K/g')

    flag=$(echo $MzSaas7k | base64 -d | openssl enc -aes-128-cbc -a -d -salt -pass pass:$salt)
}

# Variables
var="9M"
salt=""
hash="VTJGc2RHVmtYMTl2ZnYyNTdUeERVRnBtQWVGNmFWWVUySG1wTXNmRi9rQT0K"

# Base64 Encoding Example:
#        $ echo "Some Text" | base64

for i in {1..28}
do
    $var=$(echo $var | base64)
    $salt=${#var}
done

# <- For-Loop here

# Check if $salt is empty
if [[ ! -z "$salt" ]]
then
    decrypt
    echo $flag
else
    exit 1
fi

Errors in terminal:

greg@greg-IdeaPad-5-15ARE05:~/Documents/htb bash$ ./for-loops 
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 35: =2: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 35: =2: command not found
<SNIP>
#

can someone help me figure out what's causing the error?

#

and help me correct my code?

jaunty vigil
#

do 
  var=$(echo $var | base64)
done
salt=$(echo -n $var | wc -c)
#

@quasi wave

#

might not need the -n tho

#

in the second echo

quasi wave
#

that's all I was doing wrong? hold on

jaunty vigil
#

sorry i just updated it

quasi wave
#

ok

jaunty vigil
#

you need to put the salt after tht for loop so that it can be the lattest

halcyon pond
quasi wave
#

I did that

#

I am getting same error.

#
greg@greg-IdeaPad-5-15ARE05:~/Documents/htb bash$ ./for-loops 
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 34: 9M=OU0K: command not found
./for-loops: line 36: =3: command not found
#

not same error

#

similar error

#

can someone help me out further?

jaunty vigil
#

var=

#

not $var

#

u missed what i wrote

quasi wave
#

wait that just solved it

#

ok so syntax at that point

#

thanks man I really appreciate it

#

I can't believe I was that close

#

not exactly me being led to answer but since I was so close I guess I can forgive that

#

thank you

static roost
jaunty vigil
#

dont worry about asking for help

#

professionals ask for help forever

fathom pendant
#

It's why stackoverflow exists

#

And forums like superuser

sly parcel
#

Not sure what I am doing wrong

#

Made sure cifs was installed already

onyx rapids
#

Pass the Ticket (PtT) from Linux - Question : Try to get the credentials of the user svc_workstations

The hash is SHA-256 and I don't feel like it's crackable despite the text clearly stating
"Carlos has a cronjob that uses a keytab file named svc_workstations.kt. We can repeat the process, crack the password, and log in as svc_workstations."

zinc sentinel
leaden yew
next ledge
#

Can anyone help me with the Password Attacks > Pass the Ticket from Linux > Optional Exercises > From Windows (MS01), export Julio's ticket using Mimikatz or Rubeus. Convert the ticket to ccache and use it from Linux to connect to the C disk?

I am trying to see if its possible to get the ticket exported with Rubeus that I can then take to a Linux box. I tried the /outfile:file.kirbi but it doesn't create the file.

cinder mortar
#

Anyone can help verify my flag for sqlmap essentials skills assement? I think i got it but it says its wrong

acoustic owl
#

No, this is not necessary

acoustic owl
cinder mortar
#

Ye i checked that alrd

acoustic owl
tribal linden
#

Can I DM anyone to help me out with "File Upload Attacks Skills Assessment"?
I cant figure out where the uploaded files are going?

cold scaffold
#

Has anyone completed "FILE INCLUSION - LOG POISONING" ?

#

I poisoned access.log and error.log with CURL setting the User Agent to :<?php system($_GET["cmd"]); ?>

#

But still executing any command doesn't work

acoustic owl
cold scaffold
#

@acoustic owl Thanks, i will try again with single quotation

acoustic owl
#

Double quotes are used in the log file. Your payload is thus torn apart

acoustic owl
tribal linden
#

So, I could read the php source code with one of the attacks mentioned in the module, but I would need to know where the uploaded images are being stored. ( I think) I have treid to find the upload directory with dirb but no luck.

acoustic owl
hollow frigate
#

Hi, i am struggling with: Exploiting Web Vulnerabilities in Thick-Client Applications. Been at it now for to days now, i am just before the SQL injection part of the module but can't get the java code correct (every time i try to compile the java code I get a bunch of errors) If any one just can give me a hint at what i am doing wrong

tribal linden
#

@acoustic owl Looking carefully at the traffic, I cant even see the request that contains the image that im uploading.

acoustic owl
#

You need to read the PHP code.

rustic sage
#

Hi, can you please tell me, what variable i should write out in "Tcpdump Fundamentals", question "Were absolute or relative sequence numbers used during the capture?"
"yes" and "no" doesn't apply

autumn pilot
#

because it is not an yes or no quesiton

#

Were absolute or relative sequence numbers used during the capture?

rustic sage
#

I type in the absolute sequence number and neither

cold scaffold
#

FILE INCLUSION - LOG POISONIG:

#

Still not working

#

Have been trying this for 4 hours now

autumn pilot
#

Use the repeater and send a few requests

cold scaffold
#

Finally got it ๐Ÿฅต ๐Ÿฅณ

brave sail
#

Hello, I'm trying to --data-urlencode a curl GET request, but I'm unsure on how to do it since the flag is mainly for Post requests.

#

The exercise is about a bash script, but I didn't find any options to url encode data in the terminal either

rustic sage
#

This module hard

autumn pilot
rustic sage
#

relative answer

odd notch
#

Ok I'm hacing issues finding the domain in the SMB section in footprinting module. I tried dig, nothing... I tried smbclient -L... nothing. I tried domain.glass. no results... I just need the answer and how to get it.

acoustic owl
odd notch
#

I figured a domain naming service will give me the domain if I give it an IP? I'm probably wrong obv...

acoustic owl
#

try || enum4linux-ng ||

odd notch
#

Isn't that a || script ||

#

I rather do things || manually || the first time

glacial hazel
#

You can use verbosity to see. What commands enum4linux is running

#

and then just run those commands manually u_serious

#

to get that hacker feeling

acoustic owl
odd notch
#

ok I'll try rpc, thanks!

#

found it. THANKS!

brave sail
hazy minnow
#

Stuck on Active Directory Enumeration Skills Assessment II - need a nudge.|| I am Admin on SQL01 but can't figure out how to get back to MS01 as Admin to submit the flag||

heady tusk
rustic sage
#

Hello everyone.
I'm on Footprinting Module, and I have a problem with FTP servers.
I am on tethering on my laptop, using a Kali VM. I can connect on FTP servers, but I can't get any data. I know that FTP uses port 20 to send data.
I tried shutting down my Firewall on my host, and to use passive command, nothing works.
When I do a ls or dir, I got a 226 Transfer complete, but nothing appear.
Does someone already have this issue and/or know how to fix it please ?

mental bolt
#

Stuck on SqlMap essentials Case 5. I got what looks like the flag, but it keeps telling me it's the wrong answer. Any ideas?

rustic sage
#

somebody can help me with skills assesment with lfi?

fiery berry
fiery berry
rustic sage
#

yes a little hard

fiery berry
weak stirrup
#

working on active directory enumeration and attacks / privileged access walkign through example on page should the establishing WinRm Session from Windows example for on the target when connected via rdp? i get a connection failure and it looks like the example password given of "Klmcargo2" might be wrong

grizzled hatch
#

I am working on the Burp intruder section of the using web proxies module, and the machine that spawns is not functional no matter how many times I restart it. Can someone help me?

heady tusk
golden vortex
#

Im doing module password attacks section network services stuck on the questionFind the user for the SMB service and crack their password. Then, when you log in, you will find the flag in a file there. Submit the flag you found as the answer. I have the credentials but when i connect i get this error ```_samba_cmd_set_machine_account_s3: failed to open secrets.tdb to obtain our trust credentials for WORKGROUP

left axle
#

hello! everybody.

#

Hi ruck33! Are you like dancing?

cold scaffold
#

Hello, Im trying to Fuzz web app in FIle inclusion - Automated Scanning lesson but, i get response code 200 fot everything

heady tusk
#

looks like you're missing a filter

rustic sage
#

guys

#

if anyone is interested in turkish data etc

#

dm

heady tusk
rustic sage
#

hack the box innit ๐Ÿฅฐ

heady tusk
#

read #rules please. looks like you haven't

cold scaffold
#

And also the page show the main page no matter what the parameter is

#

So no matter what, the code is 200

#

I think ๐Ÿ˜…

heady tusk
#

well I'd assume you get different response sizes if you found a parameter that exists

cold scaffold
#

Yes, good idea

#

@heady tusk Got it, Thanks

rotund urchin
#

Can I DM someone about the Footprinting - Medium Lab? Not sure where to go next.

cold scaffold
#

For FIle inclusion - Automated Scanning, Is this even the right place to search for exposed parameters ?

#

Cause i found something, but after searching for LFI in that directory didn't show too much

cold scaffold
#

Ok, i got it, it was kind of confusing

heady tusk
#

great ๐Ÿ™‚

rustic sage
#

guys

#

Apple MacBook Pro M1 Pro 10C CPU 14C GPU for this device

#

is 1.6k euro good ?

heady tusk
#

wrong channel

rustic sage
#

ok

#

Hello friends. can someone help me with Skill assessment task please

#

I;ve exploited and found the answers except for host 2

#

I stuck

#

Exploit the blog site and establish a shell session with the target OS. Submit the contents of /customscripts/flag.txt

fathom pendant
#

what module

rustic sage
#

Shell & Payload

#

Shell & Payload's skill assessment

ember wing
#

The Windows Attacks & Defense Lab has to be the most unstable, temperamental lab environment I've ever used, it defies troubleshooting, whether or not I can connect to a machine seems to depend on which way the wind is blowing..

rustic sage
#

almost 2 days I cant exploi it

rustic sage
fathom pendant
#

I saw what you typed no need to reply to me

#

I don't recall what I did and don't have my notes on me

rustic sage
fathom pendant
#

I was asking to clarify the module so other people may be able to help

#

Also you don't need to reply

#

That feature pings the user you replied to

rustic sage
#

Guys, who can guide me, to exploit the host-2 Module: Shel & Payload, thanks in advance

small steppe
#

Module: PASSWORD ATTACKS
Section: Pass the Hash (PtH)
Question: Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt.

Okay. So, I'm able to RDP in, launch a PowerShell session using Julios NTLM hash. I push my reverse shell to the DC and it says "[+] Command executed with process ID xxx on DC01" but my NC listener isn't catching the shell. I have no idea what's going on here. Ive triple checked the callback IP and port. Any ideas?

rustic sage
#

hey guys

heady tusk
heady tusk
rustic sage
heady tusk
rustic sage
#

are any of you guys good at data analysis

#

and data science

#

oh

#

wait

#

forgot I was in the wrong channel

small steppe
woven canopy
#

Footprinting - DNS Hi Im quite stuck with the last question: "What is the FQDN of the host where the last octet ends with x.x.x.203?"

I've done the following:

  • Zone transfer of inlanefreight.htb and internal.inlanefreight.htb and think I have all the subdomains listed and the zones
  • I've tried to dnsenum the subdomains, and the SOAs but keep getting a "NX failed: REFUSED" error when it comes to try and brute the domains under each one.
  • The hints I've received I have an idea of what wordlist to use but I feel like I'm running my commands incorrectly.
    Can anyone provide some direct assistance? I'm confused what how I'm supposed to execute the next step? Thanks in advance!
fathom pendant
forest hollow
#

Has anyone done the "Windows Privilege Escalation" Module section "SeDebugPrivilege" and can help me on the exercise ?

rustic sage
#

lol

next ledge
#

Can anyone help me with the Password Attacks > Pass the Ticket from Linux > Optional Exercises > From Windows (MS01), export Julio's ticket using Mimikatz or Rubeus. Convert the ticket to ccache and use it from Linux to connect to the C disk?

I am trying to see if its possible to get the ticket exported with Rubeus that I can then take to a Linux box. I tried the /outfile:file.kirbi but it doesn't create the file.

onyx rapids
halcyon pond
#

Can anyone give me a nudge for this question Take over the domain and submit the contents of the flag.txt file on the Administrator Desktop on DC01 i cant rdp or get a shell as tXX and secretsdump.py isnt working

heady tusk
onyx rapids
heady tusk
upbeat dragon
#

Hi Guys, i'm stuck at Active Subdomain Enumeration, is there someone available to help me?

fathom pendant
heady tusk
dark rampart
#

guys how do i find a home path in an other linux computer(im using ssh)

autumn pilot
#

on the current user or other user?

fathom pendant
#

in general most Linux systems use /home/<user>/ if I'm remembering right

upbeat dragon
#

How do I find the FQDN from an IP Address?

fathom pendant
#

Not sure if I'm following. Generally if you ping or visit a site via IP it redirects you to the website

#

Fqdn is in the form generally a.b.c

halcyon pond
#

im pretty sure

dark rampart
#

thanks anyway

fathom pendant
#

That's a command

dark rampart
#

ah okay

halcyon pond
#

command

#

np

autumn pilot
heady tusk
upbeat dragon
# autumn pilot You can use dig or dnsenum

yeah im still checking.. On other hand, im also stuck with the following question: "Find and submit the contents of the TXT record as the answer." --- My guess is to run the following command: nslookup -type=any -query=AXFR inlanefreight.htb ns.inlanefreight.htb as I've seen in the course that it provides the .txt, but i'm not getting that info.. Im i missing sth?

autumn pilot
#

try with dig

daring steeple
#

Hi, I'm working in File Inclusion module, section Log poisoning second question, I don't understand why after sending my request with curl I can't access /access.log and I have access to /etc/passwd, the file is inaccessible with ?cmd=id and even without the parameter, I don't know if it's clear sorry for my English!
Ty for you response

acoustic owl
upbeat dragon
#

Thanks

iron canopy
#

Hi, I am on the module Attack Common Applications, and I'm stuck on the section on thick clients, on the restart oracle application.

I dumped the address so I have this MZ magic byte. However, the file appears to not be a .NET app. So I'm stuck with a dump and nowhere to go.

#

Any nudge would be appreciated

north kite
#

hello

#

can someone simplify this to me ?

#

We can see from the SENT line that we (10.10.14.2) sent a TCP packet with the SYN flag (S) to our target (10.129.2.28). In the next RCVD line, we can see that the target responds with a TCP packet containing the RST and ACK flags (RA). RST and ACK flags are used to acknowledge receipt of the TCP packet (ACK) and to end the TCP session (RST).

tribal plume
# north kite can someone simplify this to me ?

What don't you understand? It's just describing the conversation that happened between your computer and the target. In that case, the target computer acknowledges the SYN packet and then ends the interaction.

woeful ermine
rustic sage
#

guys

open violet
#

Hello

#

I am new user on HTB

#

I just want to know

#

about HTB academy for cubes

#

how can I get cubes free

#

Can I do somethings to get cubes free in HTB academy?

iron canopy
#

And therefore, trying to use the tool to convert it won't work as intended and will fail with an error message indicating that the file does not appear to be a .NET app

solar drift
#

does htb offer university apprenticeship degrees in the uk?

#

just curious to know

quasi wave
#

hi I'm having issues with this one question in network traffic analysis module

#

in the TCPDump Fundamentals section

#

I did all the other questions in section and got it right so without giving away the answer, here is the instructions:

Given the capture file at /tmp/capture.pcap, what tcpdump command will enable you to read from the capture and show the output contents in Hex and ASCII? (Please use best practices when using switches)

My answer tends to be something like:

tcpdump -rX /tmp/capture.pcap

or

sudo tcpdump-rX /tmp/capture.pcap

or

tcpdump -r /tmp/capture.pcap -X
#

I don't see what it is I'm doing wrong here

#

could someone give me a hint

#

thanks

quasi wave
#

I got it I had them in the wrong order but thank you

#

I solved it

thorn urchin
# open violet Can I do somethings to get cubes free in HTB academy?

no, you get a certain number of cubes for free to start with to let you have a taste of academy. Tier 0 modules notably will award you cubes equal to their cost if you complete them so theyre free so long as you finish the module.

But the academy at large is a paid training center.

There is the HTB seasons going on right now where you can win a small amount of cubes but not a whole lot.

elfin granite
#

I have a technical question related to nmap. If I send a packet to a server with a spoofed IP address, the server is technically supposed to reply back to that spoofed IP address(like in a ddos smurf attack) . However, in practice, the server ends up sending the response back to my actual IP address instead. So how does it really work?

fossil crescent
thorn urchin
#

yes on local net its because its responding to the mac address not the IP address. Otherwise you didnt actually spoof it or you sent along your real packets with the spoofed ones. You can check with wireshark to confirm the behavior

woeful ermine
#

but you are saying you have MZ for magic bytes

#

did you check your dump file start with MZ

fossil crescent
#

Anyone do the HTTP ATTACKS - HTTP Response Splitting? I get the concept, but can't get the XSS to work locally (yet alone attempt to get admin cookie). In Firefox, it states it won't resolve and therefore done, and in Chrome & Chromium, just displays the text... I've got a suspicion on what the issue is, but tried unsuccessfully thus-far to get it to work.... would love to chat with someone whose done it to see if I'm on the right track or not.

EDIT: Got reflected XSS, but now struggling to figure out how the heck to get the cookie...

EDIT2: Solved. As a small hint/nudge, break it apart into steps... and then it all comes together (relatively) easily AND beautifully.

red current
#

I'm in the Active Directory Enumeration and Attacks module in the Attacking Domain Trusts - Cross-Forest Trust Abuse - from Linux section and confused by how to get the second question. I followed the steps and I don't see where I'm supposed to get a TGS to crack. I can't seem to get bloodhound to run either. Any ideas on what the issue might be? Everything ran pretty smoothly up to this point.

mystic light
tidal mango
#

Going to ask this again here, hopefully someone can give my a push in the right direction....Hello, I am working on the Active Directory BloodHound Module, on the NODES section the last question is stumping me. Which non-default Group Policy affects all users? In this section they just give me the BH.zip file to look at in Bloodhound. Well I may well be not understanding the question correctly, I cannot figure out how to List the GPO or non-default GPO for all users. Could someone help clarify what they are asking and how to go about finding it please? Thank you!!

tidal mango
deep mason
#

hi i have a question, im going through the beginning and i refreshed my page, and my pwnbox disappeared, so do i have to wait a day to finish the module?

latent sage
#

hello are you on the free plan ?

deep mason
#

yes

#

i just joined so i wanted to try it

fathom pendant
#

Unfortunately yes then, unless you set up your own vm

deep mason
#

how can i do that

fathom pendant
#

I believe the getting started talks about how

honest ridge
#

Module =Pivoting, Tunneling, and Port Forwarding
section= Skill assessment

have initial credentials and see the id_rsa, but cant connect to ssh ? prob missing something basic here but dont know why i cant connect to ssh?

deep mason
#

thank you very much

mystic light
honest ridge
#

@mystic light mlefay?

mystic light
honest ridge
#

kk ty

winged glen
#

Can someone help me with the Live Engagement Host 1 in the Shells and Payloads module? I am able to upload the file using the ||tomcat_mgr_upload|| exploit in ||metasploit||, but it says the payload was unable to execute. I am sure I'm just missing something, but I'm not sure what and have been stuck on this for the last couple of days. I have also tried creating a payload via ||msfvenom|| using the payload ||java/jsp_shell_reverse_tcp|| and configuring the file as a ||war file||. When manually uploaded into tomcat and clicking on the uploaded file (with nc listening) it just opens a blank page and doesn't return a shell. Any help would be appreciated!

shadow canopy
winged glen
winged glen
shadow canopy
#

on the vuln-website its the same syntax. Maybe you trying file.war instead of file

winged glen
tender shuttle
#

In the Footprinting module, In 'Footprinting Lab Easy' exercise, the login credentials were provided in the hint. However, I am interested in learning if there is an alternative method to obtain the credentials without relying on the hint. I attempted to use brute force by running a Medusa attack on the FTP service using the rockyou.txt wordlist, but it is taking a significant amount of time. I am wondering if anyone knows of any other methods to obtain the credentials ------ ( Nevermind ,Hydra got the job done!๐Ÿ‘)----------

brazen hinge
#

Has anyone solved BROKEN AUTHENTICATION - Brute Forcing Passwords (Using rockyou-50.txt as password wordlist and htbuser as the username, find the policy and filter out strings that don't respect it. What is the valid password for the htbuser account?)? I'm stuck in this module,

daring steeple
rustic sage
# fiery berry I suppose you need to get the flag.txt, right? Better say, do you need help with...

Hello Autom4il, thanks for your return.

I'm on Easy Lab, I did manage to get the ssh private key, but I don't know if it is a normal behavior. I got to do some stranges moves to get the key, but it means that the problem isn't from port 20 being blocked.
Even in SSH, none of ls or dir commands show me results.
Is it normal to do all the stuff blindly ? Or do I have some technical problem ? Is the DNS server of Footprinting module secured that way ?

fiery berry
rustic sage
fiery berry
rustic sage
inner talon
#

ls

strange aspen
#

can someone give me a hint im at file inclusion skill assessment and try to log poison but i cant write in access.log..

acoustic owl
#

Haha, no table, big problem ๐Ÿคฃ
One dot? Really, one dot?!?
This module almost drove me crazy.
The thing with the dot was really nasty ๐Ÿคช

But it was really great! Thanks @dense ferry for this module.
I am looking forward to your other modules

quick crane
#

After the injection test is completed using sqlmap, the flag in the obtained form is submitted

wise bramble
#

Hi, is there anyone that can help for "Attacking LSASS" module ? I got errors while trying to dump the lsass.dmp file

#

I used pypykatz, lsassy, SAM dump but nothing work

misty cedar
#

SERIOUS QUESTION: I'm on CPTS Path - Footprinting -IPMI and its asking me what the Username of the Host and Clear Text Password.

Username was found off First Guess and Reading....
However the question "What is the account's cleartext password?" bothers me. Because the only example of how to use metasploit gave me a large hash that was not what everyone else got when they looked at the forums. A lot of people are talking about the Hashcat function and I'm wondering am I supposed to learn password cracking with hashcat to understand this? and if so... WHY THE HELL ISNT IT IN THE DAMN CPTS PATH

acoustic owl
acoustic owl
#

In the Dangerous Settings section

misty cedar
#

I see it

#

I'm just so confused xD

rocky pier
#

Anybody can help a bit? I am doing footprinting academy and stuck in Oracle TNS. pwnbox seems not to have odat installed and my one that I tried to get to work will fail to open with errors on missing files.

misty cedar
humble bobcat
#

Hey guys, did anyone use softether vpn ?

acoustic owl
weak stirrup
#

i am working on the Vulnerability Assessment - openvas section and when I start the target server for the assessment. i can log in via ssh but not through https :8080 .. when i log into the system and do a systemctl status | grep reen . I do not see the Greenbone Security Assistant (gsad) running nor can i find a valid .service file. i am under the understanding it should be already installed and running on the target and using a find / and some greping i can find some gvm data files so it looks like it the reports "exist" . am i misunderstanding something?

quick crane
#

What is the command can you help me

#

thanks

quick crane
#

you can test and see the meesage

weak stirrup
quick crane
#

can you need help?

normal sierra
#

how can i verify myself if i'm from hack the box academy if i dont have a unique account identifier?

dim hound
#

I am doing the Dcsync module. I am receiving the following error: ```powershell
mimikatz # lsadump::dcsync /domain:INLANEFREIGHT.LOCAL /user:INLANEFREIGHT\administrator
[DC] 'INLANEFREIGHT.LOCAL' will be the domain
[DC] 'ACADEMY-EA-DC01.INLANEFREIGHT.LOCAL' will be the DC server
[DC] 'INLANEFREIGHT\administrator' will be the user account
[rpc] Service : ldap
[rpc] AuthnSvc : GSS_NEGOTIATE (9)
ERROR kuhl_m_lsadump_dcsync ; GetNCChanges: 0x000020f7 (8439)

surreal perch
#

Hi ALL , I AM ALSO stuck on the "PIVOTING, TUNNELING, AND PORT FORWARDING" Skills Assessment, final question. I hav hopped liked rabbit on one other with alot of duin RnD & finally standing now on PIVOTWIN10 (not disclosing IP), just one step before DC -INLANEFREIGHT.LOCAL (not disclosing IP) ,where seems RDP is not enabled on it so Any assistance how to grab last DC flag??? thanks

rustic sage
#

Hi there fellows I am stuck with this question I am doing the possible combinations to use the best practices of switches but I have no answer .
The question is as follows

Given the capture file in /tmp/capture.pcap, what tcpdump command will allow you to read from the capture and display the output content in Hex and ASCII (Use best practices when using switches)?

#

These are my combinations

#

sudo tcpdump /tmp/capture.pcap -rX

#

tcpdump -rX /tmp/capture.pcap

#

sudo tcpdump -rX /tmp/capture.pcap

#

module:INTRO TO NETWORK TRAFFIC ANALYSIS

#

sudo tcpdump -XX -r /tmp/capture.pcap

#

But I can't find an answer to this question

surreal perch
brave sail
#

What is a method for selecting only the content of the token? I was thinking grep

rustic sage
#

According to the documentation for tcpdump which causes it to save the packet data to a file for later analysis, and/or with the -r flag, -XX When parsing and printing, in addition to printing the headers of each packet, print the data of each packet, including its link level header, in hex and ASCII.

#

sudo tcpdump -rXX /tmp/capture.pcap

#

But I haven't got the answer to this flag either

mystic light
misty cedar
#

On the Easy Lab of Footprinting, I'm lost after accessing the FTP files and looking in the hidden files and finding the flag.txt... or the history of the damn flag.txt and Im still like confused as to how to actually grab the flag

brave sail
mystic light
quiet ember
misty cedar
acoustic owl
misty cedar
misty cedar
#

unless thats the default because I thought 21 was

acoustic owl
misty cedar
#

cant post a picture

acoustic owl
misty cedar
sweet roost
#

h

naive field
#

hey can someone help me with shells and payloads last live engagement section

#

im on the last host host 3

#

and i know the vuln is

#

||eternalblue||

#

my rhosts is 172.16.1.3 and lhost is the attack box ip

#

๐Ÿคทโ€โ™‚๏ธ

#

pls help im stuck on this for hours

#

idk whats wrong...

sweet roost
#

h

heady tusk
sweet roost
#

ih

#

my phone just got switch off and i am trying to hack it can anyone help me?

woeful ermine
sweet roost
fathom pendant
sweet roost
#

That's I am hearprayge AngryPing

fathom pendant
#

"Google website" more than likely a paid malvertisement either way still off-topic for this chat

sweet roost
sweet roost
fathom pendant
#

Read my sentence, this is off-topic for this channel.

#

Aka not relevant

sweet roost
#

Ok๐Ÿ˜’

#

Aka means?

fathom pendant
#

Aka = also known as

#

Not for helping people hack things

sweet roost
#

I just freacking to hack my phone not my neighbours phone

#

I did the cmd thing also

fathom pendant
sweet roost
fathom pendant
#

Either way still off-topic, idk if you own the phone or not

fathom pendant
sweet roost
fathom pendant
#

And I don't care

#

My brother in Christ read the words

sweet roost
#

O I just hacked my phone troll troll

fathom pendant
#

We do not care about your phone

thorn urchin
#

or continue talking about off topic shit nobody cares about until you get kicked. your call.

sweet roost
#

Y you are getting rude & angry

thorn urchin
#

Because this is a daily occurrence and you lack reading comprehension skills

#

Its the rules, stay on topic or get the boot, your choice

sweet roost
#

Y everyone getting angry to me when I am in a big problemFeelsBadMan ๐Ÿ˜ข o sorry no one care about me

fathom pendant
#

We've explained how you're being annoying. Learn how to read (specifically #rules and #welcome )

sweet roost
#

Ok i am sorry

thorn urchin
sweet roost
#

I am sorry

flint wing
#

Hi everyone I am doing the linux fundamentals module, did you guys really finished it in 6 hours ?

#

I spend at least 10 hours on it and i'm still at 18h section !

fathom pendant
fathom pendant
fathom pendant
#

Different levels of experience will net different times than estimated

flint wing
#

Haha i know linux but it's still longer than estimated

#

maybe it's underestimated

#

or maybe I am very very slow

fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

#

Some people can probably breeze through in 5 minutes

flint wing
thorn urchin
#

Ive had some modules Ive knocked out the whole thing in 10 minutes flat, and others taken me a month

#

the time estimates should be ignored entirely

dark rampart
#

till 2020*

dim hound
#

lol ๐Ÿ˜‚

dark rampart
#

Hey guys, i need help with this question as i dont know what am i looking for:
"What is the index number of the "sudoers" file in the "/etc" directory?"

can someone help me pls?

dark rampart
#

yea, its a gold well for programmers and the IT sector

#

but it might suck at other more "real" things

subtle wing
#

Hello

dim hound
#

Make sure you understand it .. I would recommend to use chatGPT not that much if you are a starter. Since it would take away the learning curve.

subtle wing
#

Can someone help

#

Me

dim hound
#

Your opinion ; )

opaque phoenix
#

I am a beginner who is diving in ethical hacking I have learned python css html and will soon finish learning numpy pandas and javascript and within 1 month I will master all of them. I am hardworking person who works all day and sleep and I need a proper roadmap about the courses I need to learn and practice to master ethical hacking and start doing bug bounty from experienced pro ethical hacker.

subtle wing
#

Anybody please help me

subtle wing
#

Well can anybody help me hack an acc in a game I play

onyx rapids
acoustic owl
sand glade
#

Hello

fathom pendant
sand glade
#

Can you teach me php html css js jqury and laravel

dim hound
fathom pendant
#

Spanish

sand glade
#

Php and laravel

#

For hindi and english

fathom pendant
#

Existing, middle school, living with a Spanish speaker and visiting their parents every now and then

dark rampart
#

u can try apps such as Mimo or go straight to Youtube and learn it with utubers

rare marsh
#

XD

fathom pendant
#

My Spanish is awful however

rare marsh
rare marsh
fathom pendant
#

But hopefully you got what I was meaning

#

You need to verify your HTB following #welcome

#

Then you should be able to post

#

In the appropriate channel

rare marsh
#

Understand

#

My English si very bad

#

Thanks

acoustic owl
rare marsh
#

I like

#

I use deepl for traductor PDFd of English to spanish

#

XD

#

Is cool, mex, yes i need verify My account

fathom pendant
#

You overestimate my ability to care

#

Either way we are straying far off-topic

rare marsh
#

Ok sorry

quartz fox
#

hi guys, i joined this server because i need a favour

#

its hacking related

#

@everyone

#

pls help me

#

anyone knows how to hack?

fathom pendant
quartz fox
#

but i need a person's help

acoustic owl
onyx rapids
#

It's a good thing I'm not a moderator of this chat. I would be banning people left and right. Heck, I would have probably banned myself with some of the posts I've made here

quartz fox
#

guys my account got hacked and the person isnt giving it back

thorn urchin
#

@quartz fox hey how about you read the #rules and then get fucked?

quartz fox
#

what did i do๐Ÿ˜ญ

thorn urchin
#

Not read the rules

quartz fox
#

sorry im new idk anything

thorn urchin
#

this channel is for module discussion only

quartz fox
#

okok

#

sorry

thorn urchin
#

I dont care

quartz fox
#

i apologise

thorn urchin
#

I hope you never get your account back ๐Ÿ‘

thorn urchin
#

That would just be heaven. I suggest/request server validation for these channels very often for this exact reason.

coral sundial
#

@rustic sage Now would be a good time to move on.

#

Just to highlight that this channel is related to "questions" about the HTB Academy. Please keep it respectful and if someone makes a mistake and asks the wrong type of question, then please guide them to the correct channels.

rotund urchin
#

Can someone hlep with initial foothold on the footprinting hard module?

thorn urchin
#

what have you tried so far

rotund urchin
#

Just namp scan really. I tried to do some enumeration on the IMAP/POP3 ports but not finding much.

thorn urchin
#

well it is the footprinting module after all. Just go service by service and refer to your section notes

rotund urchin
#

All i see are pop3/imap

#

I did the enumeration ports, the rest of the section refers to having creds

thorn urchin
#

did you check udp as well(I dont remember the specific lab)?

#

and full port scan or nah?

rotund urchin
#

yeah I did full port, let me see if I can add other switches to find more ports

thorn urchin
#

snmp especially can be a gold mine if thats running

sleek urchin
#

doing AD-LLMNR/NBT-NS Poisoning - from Linux and it's not clear how do capture the hashes, any help ?

thorn urchin
#

ideally that ought to be in their notes already

sleek urchin
rotund urchin
#

yeah, found the missing port. Will make sure to scan UDP as part of my normal process

thorn urchin
sleek urchin
bitter tree
#

hola

thorn urchin
sleek urchin
#

and logged into ssh

thorn urchin
#

so the attack machine?

sleek urchin
#

yes

thorn urchin
#

did you verify thats the right interface its got two of em(idr which one it needs)?

and assuming its the right one what output are you getting and how long have you waited? hashes dont always come in instantly.

#

make sure tun0 is the internal 172 network

opal creek
#

is anybody able to help me with a few of the basics.. like i mean literal basic basics

thorn urchin
opal creek
#

bet ty

thorn urchin
#

np

sleek urchin
acoustic owl
sleek urchin
thorn urchin
#

sweet

#

probably just had to wait. the stuff sending the hashes are on a periodic timer

#

theres a later module where you can skip 90% of the lab if you wait an extra 10 minutes or so collecting hashes.

#

I wont spoil which one though.

sleek urchin
fathom pendant
rustic sage
#

According to the documentation for tcpdump which causes it to save the packet data to a file for later analysis, and/or with the -r flag, -XX When parsing and printing, in addition to printing the headers of each packet, print the data of each packet, including its link level header, in hex and ASCII.

#

sudo tcpdump -rXX /tmp/capture.pcap

#

ร‘But I haven't got the answer to this flag either

fathom pendant
#

You may need to separate the -r and -XX

red current
#

Having an issue with the first skills assessment for Active Directory Enumeration and Attacks. The 2nd question asks to kerberoast an account, but I can't seem to get any of the commands needed for this to run in PowerShell. I've even tried to downgrade it and it fails. Anyone else run into this?

rotund urchin
#

any hint after getting SSH access?

fathom pendant
#

Look around for what you can find

keen compass
#

hi, I have a question about Footprinting lab - Easy. After spending hours not able to progress, I finally gave up and clicked on the Hint button ๐Ÿ˜ฆ I was very dissapointed with I discovered that the password could be bruteforced... Could one of you tell me how I could have find it myself please ? When trying hydra, according to the bruteforce rate and the location of the "good" password in rockyou, it should be found in about 20 minutes ... (I am not very used to having to brute during so much time... ) were there other ways to do it please ?

rotund urchin
#

yeah this part was bogus. Apearantly there is a wordlist (not rockyou or the one provided) that you can brute force the password with. I have not went back and tested this. I used about 4-5 different wordlists from the built in image but nothing worked for me.

keen compass
rotund urchin
#

well, other wordlists are not as big as rockyou

#

I usually start with the SecLists optoins

thorn urchin
#

Ive complained about that question as well

#

one of the only questions where the hint is mandatory information

#

if its any consolation that doesnt really come up often

rotund urchin
#

facts

thorn urchin
#

by all means make an erratum post complaining about it. If people consistently complain it may get changed eventually

fathom pendant
#

To get the username there's a specific port you can see, and when you connect to it it says <user>'s server

#

Then from there it's hydra

keen compass
thorn urchin
#

yup the answer is you dont

keen compass
#

I also tried rockyou using the gathered hashed from ipmi

#

but it seems that the password was not the same (or maybe I did something wrongly with jtr / hashcat (in fact, I don't know much about hashcat and am impatient to deep dive into it in a next module

thorn urchin
#

its just a bad question

#

dont sweat it too much. Make a complaint about it and move on

fathom pendant
keen compass
keen compass
#

I mean, rock you as it and perhaps a lot of other ones but the ftp service is quite slow

thorn urchin
#

unless were all talking about different questions here

fathom pendant
#

But idk if we're referencing the same question

#

The one with the hint c*:<password>?

thorn urchin
#

im talking about the one where literally the hint contains the password and there was no list or any way to find the password and htb staff has confirmed checking the hint is the intended routem

keen compass
#

but how did you used rock you ? with nmap nse script ? with hydra ? some other tool ?

fathom pendant
#

Hydra

#

Because one of the services you can scan for has the users name plastered on the banner when you connect

#

So you don't need to guess a name

keen compass
#

umm, my hydra scan has just finished after about 30 minutes... this is definatly the way to go... I am just not (at all) used to having to wait so much time before getting a positive result ! another lesson learned today

fathom pendant
#

Also you can adjust the threads hydra uses

keen compass
#

oh ...

fathom pendant
#

I've found 48 to be reliable for ftp

#

64 drops too many

keen compass
#

many thanks for the share

fathom pendant
#

Np because I redid this module recently and decided to try and figure out how to brute it

#

But yeah make sure you check all ports for a double number of a common port

balmy radish
#

What ip address does the dns server give for inlanefreight

thorn urchin
weak charm
#

Can someone message me. I'm currently working on the windows exploitation module and I'm struggling to get the ntds.dit onto my attack host. I've gone through the file transfer module and tried the different windows upload techniques but none are working.

thorn urchin
#

which section are you on?

#

also I could be wrong but im pretty sure ntds.dit is a protected system file. you could only really copy it if you had like a shadow volume copy of it, did you try that?

autumn veldt
#

Hi anyone needing an editor

fathom pendant
weak charm
fathom pendant
#

Huh ntds.dit is (NT directory System).(Directory Information Tree)

thorn urchin
#

then if youre having issue copying the shadow version of the file over its likely an issue with your system, have you tried copying it over in the pwnbox?

weak charm
#

I haven't tried it with pwnbox. Do you think it's just a connection issue

shadow canopy
weak charm
shadow canopy
#

with xfreerdp yes you can drag and drop. if you open windows explorer > Networks > tsclient > your-attack-box
but you can do it if you add this flag
/drive:<any-name>,.

weak charm
mystic light
regal barn
#

Can someone please help me with Bypassing Encoded References exercise?

fossil crescent
#

If still stuck on the HTTP Response Splitting, feel free to DM me -- just solved it. In working it over last few days, realized I over-complicated it / need to break it apart into steps and then once you think it'll work (based on the steps) -- odds are it will -- vs. my original approach of #YOLO (and failing miserably).

lucid mirage
#

did you fix the errors?

rustic sage
#

According to the documentation for tcpdump which causes it to save the packet data to a file for later analysis, and/or with the -r flag, -XX When parsing and printing, in addition to printing the headers of each packet, print the data of each packet, including its link level header, in hex and ASCII. But I haven't got the answer to this flag either

autumn pilot
#

In this one you don't have a lab to spawn, instead you can use the name of the given website

spring osprey
#

i am a newbie to hacking stuff but i wanna learn it but dont know where to start
can anyone guide?

spring osprey
#

i like know nothing

#

no programming languages

glacial hazel
acoustic owl
cursive gull
#

???? RE and programming are just tools, just as much as ping and nmap are. You use them when, and if, needed.

acoustic owl
#

Start Powershell as Administrator

gusty gate
#

Module: Cross Site Scripting/Session hijacking

Try to repeat what you learned in this section to identify the vulnerable input field and find a working XSS payload, and then use the 'Session Hijacking' scripts to grab the Admin's cookie and use it in 'login.php' to get the flag.

I have followed everything mentioned on the page but I am not getting a request back on my php server. I have even reverted the machine a couple of times.

autumn pilot
#

make sure you are using the proper IP address and port

gusty gate
#

@autumn pilot I am

autumn pilot
#

then check the payload you are using

gusty gate
#

it's the second payload from the tutorial

#

and changed the ip to my ip

#

tun0 ip

weak charm
# weak charm Okay I'm gonna try this tomorrow. Thank you!

So I figured it out. Using the /drive command allowed me to copy the file. Also in order to Crack it you need the system file as well. But.. apparently none of that mattered because all I was supposed to do is copy the flag directly with copy-filebackupprivelege. ๐Ÿคฃ๐Ÿคฃ

sweet roost
#

h

#

h

#

h

deep mason
#

Hey so I have a dumb question, I felt maybe I didnt read it well enough but, I was in the first interactive section with target. I felt pretty confused because I would type in the ip address as is and run it in firefox and it kept telling me it timed out and etc. So I didnt know what to do. am I missing something?

acoustic owl
rustic sage
#

Hi all, I am currently struggling with the DNS section of the Footprinting module. The last question where I need to find the fqdn of the host ending in .203. I have tried both the 5000 and the 110000 wordlist. I have also been trying the subdomains of subdomains and I am not really sure where else to go with this.

glacial hazel
#

Do u have the IP address of it

rustic sage
#

of the subdomain?

glacial hazel
#

No of the host ending in .203

#

Do u have the full IP address

deep mason
#

module/15/section/453

rustic sage
glacial hazel
#

Do you know what subnet itโ€™s on?

fathom pendant
fathom pendant
glacial hazel
#

and if you find the host ending in .203 then u can do a reverse dns lookup

#

I think nmap actually does reverse dns lookup automatically for active hosts

sly nebula
#

I need a sanity check on the "Error-based SQL Injection" section of the "Advanced SQL Injections" module. Is anyone available? @dense ferry ?

fathom pendant
rustic sage
#

I am still stuck...

fathom pendant
#

And the right word list is a little more fierce

rustic sage
#

I have the fierce word list running now

#

I am going through all the subdomains again

fathom pendant
#

You can ignore NS and internal since you could already see those

rustic sage
#

Am I supposed to be changing the IP in the dnsenum command? The subnet suggestion has me a bit confused now.

deep mason
fathom pendant
#

Getting Started module

fathom pendant
#

Ignore their subnet suggestion

#

The intended way is to use dnsenum or some dig command syntax I'm not aware of at this time

rustic sage
#

I just got it. The new wordlist showed me that last domain

#

Thank you!

fathom pendant
#

Their suggestion is more for if you know the specific subnet it would be under

#

Which you don't

fathom pendant
fathom pendant
acoustic owl
fathom pendant
#

Oh yeah that one is a docker

onyx rapids
deep mason
acoustic owl
#

IP and Port

deep mason
#

Oh I see. Haha maybe I should of read deeper. I must of missed it because it's obvious

#

but i see its not on firefox

#

is that the pwnbox

acoustic owl
#

No, the PwnBox does not have Internet access as far as I know.
You can access it on your PC with your browser

iron canopy
#

No clue what I am doing wrong as other addresses won't give me a proper DOS MZ executable

river token
#

Stupid Question - Shells and payloads - live engagement - I RDP to the foothold box and do not see a web browser installed. Am I missing something ? the tor browser will not install saying im not connected to the internet.

autumn pilot
#

you can call the web browser from your terminal

river token
autumn pilot
#

hint: the browser is not tor

river token
wary magnet
#

hi! is anyone here doing the dante pro labs? i'm a bit stuck and would like some nudge in the right direction. i have completed about 53% of the lab already and am stuck in what steps to take next.

please dm me so that i can explain further and avoid any spoilers

fathom pendant
karmic knoll
#

Find a file with the setuid bit set that was not shown in the section command output (full path to the binary).

Can anyone help give a nudge on these two questions in the Linux Priv Esc? I have finished everything but this and I feel like I'm overcomplicating it. I'm running both commands to find the binaries with both setuid and setgid set and know how to read the permissions but I'm not sure what file I should be looking for? Any help, thank you!!

autumn pilot
#

search for the file

limber widget
#

for the password attacks module, starting off the first section with a VM has me enumerate winrm service. Currently using crackmapexec using the recourse lists provided, im guessing this will work. But crackmap is fairly slow. Are there any other tools recommended for this situation?

karmic knoll
# autumn pilot search for the file

Is it a blatant obvious file? I just got a bit confused when the question says "not show in the section command output." Thanks if you're able to clarify, I've tried pasting what I thought was the full path but I'm just stuck tbh

autumn pilot
#

ยฏ_(ใƒ„)_/ยฏ

fathom pendant
#

It's something to do with new-object and not being able to identify what you're doing, you sure you don't need to put the kerberos request inside parentheses? ()

fathom pendant
#

im not familiar with ps error messages, only other thing is that it's stating "verify the assembly containing this is loaded" ยฏ_(ใƒ„)_/ยฏ

#

For the kerberos request

silk minnow
#

Can I get help with SQLmap essentials bypassing web application protections, case 8?

misty cedar
#

Footprint Lab Medium: am I supposed to be seeing an error after mounting the dir?

fathom pendant
#

Error like can't cd to the directory

ashen fog
#

Its an Antak Webshell

#

Im not logged in thats the problem i think

fathom pendant
#

Webshells suck try upgrading to a reverse shell first

naive field
#

is it possible to change profile picture on htb academy?

fathom pendant
#

Afaik, no

ashen fog
fathom pendant
#

Whatever works for you

misty cedar
fathom pendant
#

Try running as sudo and I think there's a flag -o no_root_squash I think

misty cedar
#

this what when I did the tree . command

timid pollen
#

hi guys anyone has got problem with with machine in windows priv escalation... the rdp always crashes after a couple of mins

fathom pendant
#

Because of how it's mounted try sudo chmod o+xr on the share

#

So sudo chmod o+xr /sharefolderyounamed

#

I'm just looking google

#

Lol

#

Or switch to root and you can navigate

cinder mortar
#

hi need a nudge for Skills Assessment - File Inclusion, i've tried fuzzing params, lfi wordlists, fuzzing for server files, but still cant seem to find any direction of where to proceed

fathom pendant
cinder mortar
#

yes

#

all i see is invalid input

#

like i ran ffuf on it

cinder mortar
fathom pendant
#

havent done that module so not sure. Maybe need more ../ ยฏ_(ใƒ„)_/ยฏ

cinder mortar
#

:/

steady hawk
cinder mortar
steady hawk
#

You're in the File Inclusion module right? There's a section called File Disclosure in there.

cinder mortar
#

oh

#

ok

#

was blind xd

steady hawk
#

๐Ÿ‘

cinder mortar
# steady hawk ๐Ÿ‘

ive gotten to the point where i can see the php code for index, but from my understanding: only .. is being filtered but url encoding does not work

fathom pendant
#

Add an additional '../' such that ....//

cinder mortar
fathom pendant
#

That works too lol

obsidian kettle
#

does anyone know the Username file and Password file we are suppose to use for the Skill assessment -website first question within Login Brute Forcing module? I keep trying the different files that are mention in the learning section but either nothing comes up or it takes for ever and time out (or seems to times out)

autumn pilot
#

the first assessment or the last?

obsidian kettle
#

the first

#

this is the question: When you try to access the IP shown above, you will not have authorization to access it. Brute force the authentication and retrieve the flag.

autumn pilot
#

there is a wordlist that will help you

#

it was mentioned in the cheatsheet

obsidian kettle
#

I have been using them

iron basin
#

Hey, this is for anyone who doesn't know, but you can make you RDP windows bigger if you use xfreerdp to rdp in. Just use /size:WxH. For example, /size:1920x1080

fathom pendant
#

Iirc you can do like /dynamicresolution as well

iron basin
#

ah, not aware, Ill have to try that out!

naive field
#

im on password attacks and im doing the password mutaation module, its been 15 minutes of me trying to crack the password for the user sam

autumn pilot
naive field
#

:/

autumn pilot
#

use the info that I have given you to modify the wordlist in order to speed up the process

naive field
#

before that i had to mutate it with the rules and i used this cmd

#

||hashcat --force password.list -r custom.rule --stdout | sort -u > mut_password.list||

autumn pilot
#

lower and upper

naive field
#

ik how to modify for lowercase and upper

#

but not letter

autumn pilot
#

this is a good exercise to test and use your researching skills

naive field
#

requires hella researching lol

thorny wadi
#

Web Service & API Attacks - Skills Assessment, someone to give me help with the SQLi payload?

fathom pendant
#

Also a good thing to know, hydra and cme lets you adjust the threads used to speed things up

naive field
#

47min now

#

xd

#

i think something is not good

fathom pendant
naive field
#

can i dm u with the cmd i used and a screenshot

#

so i dont spoil here?

fathom pendant
#

There's another service you can crack that will be faster

#

The question is worded stupid

naive field
#

" Use this wordlist to brute force the SSH"

fathom pendant
#

Like I said

#

It's stupid

naive field
#

which service then

#

?

fathom pendant
#

Lol ssh takes forever to crack because it's slow connect disconnect

fathom pendant
naive field
fathom pendant
#

Yep

#

I recommend (if using hydra) -t 48

#

That's the fastest/most reliable threading I've seen for these labs

naive field
#

im using this command to mutate the passwords with hashcat rules

#

||hashcat --force password.list -r custom.rule --stdout | sort -u > mut_password.list||

fathom pendant
#

That's fibe

#

Fine the mut list is fine

naive field
#

lets see now ...

fathom pendant
#

Why are you spinning it back up?

#

Once you've created the list from the resources you don't need to recreate it

naive field
#

to crack

#

its still cracking

#

usually when i cracked on htb labs it didnt take longer than a minute

#

now its been 5min alr

fathom pendant
#

You realize that is just creating a password list right?

#

And outputting it to a file

naive field
#

nono ikik

#

i alr did that

#

now im here

fathom pendant
#

Now I'm confused

naive field
#

i used the cmd above just to mutate the password

fathom pendant
#

Yes

naive field
#

and now i used hydra

#

to crack it

fathom pendant
#

Ok

naive field
fathom pendant
#

Like I said though you don't need to recreate the mutated password list

#

Anyway as long as you used the password.list and custom.rule from the resource files you'll be fine

naive field
#

yeah i did

#

even for ssh i did but it took like over an hour

#

and it still didnt find anything

#

so yeah now im trying on ftp just as u said

fathom pendant
#

Give it like 10-15 min, if that, on ftp

naive field
#

okay

thorny wadi
#

Web Service & API Attacks - anyone completed this ? i think i have the answer and maybe only failing in the formating

naive field
sick mural
#

Hi everyone, I need little clue on Footprinting-Hard lab. I am able to get the required ssh private key but not able to successfully login with discovered user account via ssh. I get permission denied publickey error. Can anyone guide what must i be looking for to move forward?.

#

private key has required permisions set as needed to be used in ssh command.

woeful ermine
#

Ohh you already changed it. Sorry. I dont have much in my notes. Post the error please

magic lotus
#

Hello.
I'm not really getting what is expected as an answer for this question.
"Enumerate all ports and their services. One of the services contains the flag you have to submit as the answer."
module/19/section/103

#

can somebody help me understanding?

fathom pendant
#

What's the module name?

magic lotus
#

Service Enumeration

#

Nmap

fathom pendant
#

So it's asking you to run nmap against the target: potentially use netcat to connect to a specific port (or use --script banner I believe) to get the flag

magic lotus
#

ok, so these are not the flags of the tcpdump?

#

in this module is stated that Nmap some times doesn't show everything

fathom pendant
#

Yes and it stated you may need to connect directly to the port

#

And that module/section demonstrates different methods

magic lotus
#

I thought it was this kind of flags -> Flags [P.]
nc can show banners and I don't see any kind of similar value/flag like above

rustic sage
#

I just figured out to use the tool for finding the username in the smtp footprinting module, but I never saw it in the module itself. Is is not there, or am I just somehow missing it?

naive field
#

on attacking sam module, when i try to move the sam file i get access is denis

#

denied*

sick mural
fathom pendant
naive field
# naive field

i checked if there is any pw on my smb server running etc

#

but nope

#

idk whats up.... :/

fathom pendant
naive field
#

i alr made copies of the sam files

#

but i cant move them

#

its working now

#

i hate when im stuck for long time and then when i ask i find the answer

#

i feel like an asshole xd

fathom pendant
#

Yeah that happens

fathom pendant
timid osprey
#

Hi
Iโ€™m stuck in Attacking common services- Easy skill assessment lab. I have done everything and I have uploaded multiple shells through MySQL but none work. When I open them through browser they open as text webpage no Shell and no reverse shell connection obtained. Any suggestion?

magic lotus
sick mural
#

With -v see server is imposting publickey as authentication and not the password for use tom

#

But dont have the public key its private key

#

Found it in email

#

Imposing*

fathom pendant
naive field
#

to connect?

sick mural
#

No i have private key

naive field
#

yeah mb

#

where did u get it?

sick mural
#

It was in email

naive field
#

okay

#

then make sure u copy it good

#

maybe u deleted some part of it or added a space etc..

sick mural
#

Yes i am coping it with full text including start of open ssh private key and the end of it as same

#

Oh let me check this again

fathom pendant
#

Try pasting it in different text editors I've had copy paste swap letters sometimes