#modules

1 messages · Page 80 of 1

fathom pendant
#

You don't need to reuse (for this one) I don't believe

#

Usually the question will tell you if you need previously gained creds

#

You don't need to do any exploits. Just brute force, mostly following the techniques in the section

keen compass
#

ok, thanks, I got traped by the fact that the Openssh service is in v7.7. Does any of you have manages to run a user enum exploit against it ?

autumn pilot
#

you can use crackmapexec

#

plus this ^

keen compass
#

for SSH ?

autumn pilot
#

yes

keen compass
#

oh...

#

thanks

fathom pendant
#

It's easy to overcomplicate things: general rule of thumb , if it's not covered by the module - it's generally a rabbit hole

frigid osprey
#

Have you figured it out yet?

silk minnow
spare condor
#

Can anyone help me with the double pivoting in the Pivoting, Tunneling, and Port Forwarding Skills Assessment? I have successfully pivot from 10.129.201.127 to ||172.16.5.35||. I have found ||vfrank||'s credentials and I'm trying to find and enumerate the next machine.

keen compass
lament lance
#

Hi! I'm trying to enumerate Firewall and IDS/IPS Evasion - Medium Lab, I'm using the command:

sudo nmap 10.129.113.199 -sA -sV -Pn -F --packet-trace --version-trace -n --disable-arp-ping -T 2 -D RND:5 --source-port 53

And the question is:
After the configurations are transferred to the system, our client wants to know if it is possible to find out our target's DNS server version. Submit the DNS server version of the target as the answer.
Could someone point me in the right direction? I'm quite lost.

naive field
#

yeah it was actually good even tho it was hard

indigo belfry
#

You generated a kerberos ticket. You can authenticate with the same ticket using another tool apart from psexec.py. Check the help for the other tool. The parameters are almost the same as psexec.py...

frigid osprey
onyx rapids
#

Has anyone finished "Skills Assessment - Hard" of the HTTP Misconfigurations Module? I'm stuck on a section and it's driving me crazy. Payload works, but don't understand why admin isn't hitting the page

fathom pendant
keen compass
# autumn pilot you can use crackmapexec

for this module, now, I have used cme for all protocols and it worked nicely, but crackmapexec didn't worked on RDP (it just return with no output at all) whild Hydra succeed. Has some of you be faced to the same behaviour please ?

lament lance
#

The first lab was easy and I don't get banned on this one but the issue is that all the ports appear as filtered

#

I got SOMETHING, but no versions of the services, let me try the version script.

autumn pilot
lament lance
vocal sentinel
#

The best way is contacting the support ? And saying that I can’t create account

uncut crest
#

Is anyone willing to help me figure out what I am doing wrong trying to run bloodhound-python through a pivot from outside the internal network?

lament lance
hollow veldt
#

Ok.

acoustic owl
autumn pilot
green birch
#

This I have found on the site Common Pitfalls:

_Working on Two Devices
The HTB VPN cannot be connected to more than one device simultaneously. If we are connected on one device and try to connect from another device, the second connection attempt will fail.

For example, this can happen when our VPN connection is connected in our PwnBox, and then we try to connect to it from our Parrot VM at the same time. Alternatively, perhaps we are connected on our Parrot VM, and then we want to switch to a Windows VM to test something._

Normally, I was with one device logged in on the HTB-Website in two windows, because in one I have the language german in the other english. There I make the Academy Path Cracking into HTB. At the other device I'm logged into the target via a Parrot VM, when I want to do the exercises.

If I understand the text correctly, is there only a problem when I'm logged into the target with two devices or are there already problems when it's like I described above?

fathom pendant
#

Only if you have two devices using the VPN. Like the pwnbox (interactive VM in the browser) AND your VM

#

If you are logged into the site twice I don't believe there are many issues

proud cloak
#

Hello everyone, I ask for some help if you can, could someone show me how to edit the user.java file correctly? I'm stuck on module Attacking Common Applications section Exploiting Web Vulnerabilities in Thick-Client Applications plese help me !! 🙂

sterile wharf
noble hazel
#

Need help in File Upload Attacks > Type Filters. I have modified the magic bytes for the jpg + php code and the file uploads successfully. But, when i visit the url saids "cannot be displayed because it contains errors". Using phar.jpg as the extension. Any help greatly appreciated it.

autumn pilot
#

You are close, don't forget what the app is expecting to be uploaded

#

also, start by running a simple php echo command to verify if php is getting executed

noble hazel
#

Ok. Thanks.

wanton mica
#

Hello all, need some help on the File Upload Attacks Skills Assessment. I know the first step is reading the source code and I know how to do it (considering I have…”limited” 😉 options) but for some reason the damn ||.svg|| file won’t upload no matter how I manipulate burp suite…any guidance?

rustic sage
#

Hello! Stuck on the last question of the Skills Assessment for the Login Brute Forcing module. I'm on the box, I have the correct user. I'm running hydra on the machine using the provided wordlist. I'm 95% sure I have the right command syntax. But it's been running for quite awhile. The box has about 60 minutes left. Am I being impatient, or does it really take this long, compared to the previous similar excercise?

fathom pendant
#

Sometimes it can take up to like 20 minutes

#

¯_(ツ)_/¯

rustic sage
#

OK, that's cool then.

#

I'd really like to get this done, and move on to the next module. I don't have a lot of time today.

#

Thank you!

fathom pendant
#

When you rush you can make mistakes

rustic sage
#

True. I spent about an hour on it last night. I circled back this afternoon and double checked, and I think it's right.

fathom pendant
proud cloak
#

mo wrong IP

#

no

proud cloak
#

echo xx.xx.xx.xxx server.fatty.htb >> C:\Windows\System32\drivers\etc\hosts

#

don't work well.. edit via notepad

fathom pendant
proud cloak
#

3 days man 🙂

fathom pendant
#

Take it it was escaping all the \

#

This is why quotes are important too

rustic sage
#

Just had to let it sit for awhile.

#

Which is weird, because I used the same syntax last night, and got 0 results.

#

All's well that ends well.

drowsy yacht
#

Any idea as to why I’m getting this?

dim hound
#

and send the output in the chat

cold scaffold
#

first line should be "-----BEGIN RSA PRIVATE KEY-----"

#

and also the last line respectively

#

END RSA.....

drowsy yacht
cold scaffold
#

@drowsy yacht I did the same mistake 2 days ago 😅

drowsy yacht
#

Lol

#

That worked

golden vortex
#

Hello, working on Password Attacks Lab - Hard I cannot mount vhd. Ive tried guestmount and doesnt work

fathom pendant
tidal mango
fathom pendant
#

There's a useful link someone sent earlier

thorn urchin
#

I just googled around how to mount in Linux until I got it working

simple zephyr
#

anyone complete the ATTACKING ENTERPRISE NETWORKS module yet? I just completed the Active Directory Compromise section and I have a few questions to see if we did things that same.

-Mainly how you authenticated to the DC.
-If you used the Admin account or were able to do it with the user that was found.
-How did you get $group = = Convert-NameToSid "Server Admins" to work (I got it to take, but not sure if it was the most elegant way)

#

Feel free to DM me

golden vortex
fathom pendant
#

Then you may need to use a x2john to decrypt

fathom pendant
#

You need to click a partition then it gives you the option to mount a vhd

tidal mango
simple zephyr
tidal mango
simple zephyr
#

Yea I did proxy chains with impacket and evil might have been the box, going to reset it and try a few other things. How many hashes did you crack at the very end?

simple zephyr
little bear
#

Also once again, RIP kirbi2john.py. I ended up manually formatting the crack_me file so it would work with Hashcat. That, and ParrotOS has the .py file to use instead of the one hyperlinked within "this"...

#

ONly cost me Four hours. Lesson Learned: Manually do it for now. Learn Python asap later.

wraith mason
#

may i ask question abount nmap here? I meet a problem. When i scan a machine on htb by nmap , why i get different result when i spawn new machine.

cinder tinsel
#

trying to complet the password module . on protected file and protected archive asks to use the cracked kira password's. there is no cracked password ,tho

raw belfry
#

A bit out of nowhere and old asf but W advice king 👑

simple zephyr
leaden stag
#

does anyone have any input on this? I've tried running it first but i'm getting the same error as well. Can't add the breakpoint.

vital adder
#

Sir this is a Wendy's

simple zephyr
simple zephyr
kind pike
#

Can someone infiltrate the website database

tough prawn
#

still stuck ):

#

I think the problem is from the lab

glad orbit
#

Someone can help me for: (AD Enumeration & Attacks - Skills Assessment Part II) - Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host.

autumn pilot
weary shoal
#

Hi guys, im stuck on "Attacking Common Services - Easy" lab for days now... I can't figure out what am i doing wrong.
I found the f*** username and im trying to brute the password on FTP like so:

hydra -l <username> -P <pws.list> -s 21 -v -V -t 1 -u <HOST_IP> ftp

and it finds nothing... I also tries it on SMTP but again - nothing. How do go on from here? Please Help!!!

Thank you ❤️

autumn pilot
#

maybe ftp is not the path

weary shoal
autumn pilot
#

perhaps you can use a different more common wordlist

weary shoal
#

like r***? hydra says its gonna take 48 hours to complete 😦

weary shoal
#

nvm, looks like smtp can proccess a lot more threads then i thought...

autumn pilot
#

careful with spoilers

real summit
#

Good morning, in Module "Active Directory Enumeration & Attacks" Privileged Access part there's question: "What host can this user access via WinRM? (just the computer name)". I have found user, how can I find his possibilities to access computers without BloodHound?

weary shoal
autumn pilot
#

don't worry it was something not related to your question

weary shoal
#

oh ok

#

🙂

real summit
cold scaffold
#

Trying to get this logic work

#

if i try to run it says: syntax error in line 10

fathom pendant
#

-eq is a numerical evaluator

#

And you're trying to compare strings

cold scaffold
#

Ok, Thanks

fathom pendant
#

sip knew that paste wasn't lasting long

cold scaffold
#

Still the same error

#

i put the variables in quotation marks also

fathom pendant
cold scaffold
fathom pendant
#

Also your tail command is missing var

glad orbit
#

Test with insert space between 450" and ]

fathom pendant
#

That could also be an issue

cold scaffold
fathom pendant
#

Also syntax could be interpreting 113,450 as the literal string

#

Which is a whole other issue

cold scaffold
#

No error, but something is wrong

#

But the logic seems good

fathom pendant
#

Read what I typed above :)

cold scaffold
fathom pendant
#

You may need to do something like && $(wc -c $var)

#

Iirc wc -c counts characters

cold scaffold
#

ohhhh, ok

fathom pendant
#

But doing man wc would be more helpful

#

Also

#

You're not going to get an answer

#

Just an fyi

cold scaffold
#

i want to learn not get the answer

fathom pendant
#

Ik

#

Look at your comparator

cold scaffold
#

The exercise seems like to much for the start imho

#

But i will try

fathom pendant
#

It's probably explained in the module

proud pine
#

You have a comma.

fathom pendant
#

But you need to find a way to look for the $value inside of $var as well

#

Unless that does work @proud pine

azure barn
#

What is the name of the security standard for credit card payments that a company must adhere to? (Answer Format: acronym)
Payment card Industry security standard
Please why do i still get incorrect answers

#

i try PCI still incorrect, can someone please help

#

Payment Card Industry didn't work also

naive wadi
azure barn
naive wadi
#

some of the questions are worded very strangely so I understand, I have the same issue sometimes.

blazing light
#

hey I am starting the bug bounty hunter path, anyone wants to do it in sync? would be good to have people to discuss and a little bit competition never hurt anyone.

fathom pendant
#

It's gonna be hard to get people that are on the same page as you tbh

tribal plume
#

Attacking Common Services, Attacking Thick Client Applications: When I try and compile after changing the ClientGuiTest.java file with: C:\> javac -cp fatty-client-new.jar fatty-client-new.jar.src/htb/fatty/client/gui/ClientGuiTest.java I get the error: Error: Could not find or load main class fatty-client-new.jar.src.htb.fatty.client.gui.ClientGuiTest.java Any ideas? I'm executing the command from the parent directory of fatty-client-new.jar.src, and I've tried going into that directory and executing too.

obsidian kettle
#

to use username-anarchy are we suppose to place anything before ./username-anarchy and the name we want to use to get the username for? I keep trying to use figure out username-anarchy but there doesnt seem to be clear instructions on how to use it to get the username file. thank you for any assistance someone can provide

tribal plume
tribal plume
obsidian kettle
#

I didnt see it but I will look again. thank you

#

I think I am typing the examples but i get ./username-anarchy: command not found so I think I am missing something that I am not seeing in the examples

tribal plume
#

The ./ tells the computer to look in the current directory.

obsidian kettle
#

Ok I think I got it thank you

iron basin
#

Linux Fundamentals - File System Management:

Question: What is the size in GiB of the "/dev/sda" disk in our Pwnbox? (Format: 000)

I have found the /dev/sda, its /dev/sda1 and /dev/sda2. SDA1 shows || 75.8 GB || and SDA2 || 3.7GB || . How do I put these in the format it wants(000)? Also do I add them together or do I just take SDA1?

tribal plume
#

It's asking for the total size of sda, I think. But I don't think it's asking for the two to be added together.

#

What was your command and what was the output?

iron basin
#

|| sudo fdisk -l
Disk /dev/sda: 160 GiB, 171798691840 bytes, 335544320 sectors
Disk model: QEMU HARDDISK
Units: sectors of 1 * 512 = 512 bytes
Sector size (logical/physical): 512 bytes / 512 bytes
I/O size (minimum/optimal): 512 bytes / 512 bytes
Disklabel type: dos
Disk identifier: 0x5224b35f

Device Boot Start End Sectors Size Id Type
/dev/sda1 * 2048 158974027 158971980 75.8G 83 Linux
/dev/sda2 158974028 166796875 7822848 3.7G 82 Linux swap / Solaris ||

#

Thinking its sda1, since the bottom is swap. But either way, entering the ||75.8 || I get wrong answer and same for when I add. So I think its a formatting error. I just dont get what it means by 000 as format. Cause ive also entered this to try bytes || 75800000000 ||

tribal plume
#

Read the output carefully and see if there's a number in the format requested. ###

#

/dev/sda is the drive /dev/sda1 and /dev/sda2 are what's called partitions on the drive.

iron basin
tribal plume
#

It's a little clearer with lsblk, yeah.

celest light
#

hi guys, im doing the windows pe module, and im in the pillaging section, the question is : Restore the directory containing the files needed to obtain the password hashes for local users. Submit the Administrator hash as the answer.
i got all of the hashes tried to submit only the nt part and the whole ntlm hashes but it wont accept it, someone can help?

iron basin
#

@celest light You can dm me it and I can compare it to the answer I have to see if you got the right one.

cold scaffold
#

Modified the script for bashscripting module. Still doesn't give the answer

sinful nexus
#

hey, If i buy student pack monthly for 5 pounds, than it says free tier 0 to tier 2 but do this reward cubes for module completion?

#

are you sure? if I buy that pack and access CPTS - and when ever I need to unlock above tier 2 start other skill paths to collect and unlock for CPTS?

viscid bridge
#

Hi i have a quick question. I have this string “be?ikta?”(Utf-8) and i have to convert it to besiktas.

vital adder
#

for that section i found a vuln that doesn't require to be login via rdp so i didn't but you can try something like powershell -ep bypass or powershell –ExecutionPolicy bypass before you import a ps1 script

#

if you still need help shoot me a dm with exactly what you run because if you just import a script there will be no error or output the script will just be imported

flint helm
#

prompt injection module when

dull vortex
#

I am doing the shells and payloads live engagement and I have been struggling for while and keep getting an error when trying to upload my shell but I am not sure why. Anyone around to give me a nudge?

dull vortex
#

Not sure if I am not supposed to be able to upload a war file and need to go with the other shell?

zinc sentinel
somber gorge
#

Can the exams be done without doing their relative paths rn?

acoustic owl
cold scaffold
fathom pendant
cold scaffold
#

so it should be something like this: "$var == $*value"

#

?

#

or should i try to play with tools like "uniq"

fathom pendant
#

If you're going to throw a wildcard in you need to do it like this *$value

cold scaffold
#

i surrender for now 😵‍💫 , i will try to do something else

rustic sage
#

hi yall

hardy swallow
steady totem
hardy swallow
#

I just did the lab and it would not work

steady totem
#

Interesting... I will spin it up rn to check

#

Yes works for me

hardy swallow
#

When I do it I get NLnet Lab not the flag, same command I get the flag using the HTB attack host

steady totem
#

That's odd... DM please, I'd like to understand what the difference is here

fathom pendant
lament lance
steady totem
barren robin
fathom pendant
#

It can be gotten over VPN it can just be tricky

hardy swallow
#

I think its broken over the tcp vpn

scenic yacht
#

I resumed a lab after a year, but seems like the machine is broken

#

Can't find any option to contact support to revert the lab, any idea how to do it?

barren robin
cunning prairie
#

Module=AD Enumeration & Attacks, Section=Skills Assessment Part II. I'm on the mssql server. I looked into using JuicyPotato but noticed that I should be using RoguePotato. I tried to Google on how to use RoguePotato but am unable to get through. Any recommendations on which source to review on how to use RoguePotato or other suggestions beside using RoguePotato/JuicyPotato? Thanks!

steady totem
cunning prairie
steady totem
#

dm

weak charm
supple patio
#

hello guys, I am on shells & payloads the live engagement. I need someone to dm

#

hi

#

no idea

#

try to mention them idk

#

no idea

glad orbit
#

Someone can help me for “Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host” question?

acoustic owl
acoustic owl
glad orbit
#

Sorry Module=AD Enumeration & Attacks, Section=Skills Assessment Part II.

acoustic owl
glad orbit
acoustic owl
glad orbit
#

I have not permission to read this file. I try with user A* and B* from MS01 host

acoustic owl
eternal rover
#

I need a slight hint for "attacking common services" module easy lab, got the user and their pass and can access the sql database and ftp server and reading the forums I see I'm supposed to gain a shell, however whenever I try anything it downloads the payload rather than running it, a little stuck probably me being dense

glad orbit
acoustic owl
acoustic owl
#

Try it with a mail client like Thunderbird/Evolution

glad orbit
acoustic owl
#

sure

tidal kelp
#

hello, can i dm for help with the Using CrackMapExec Skills Assessment? Thanks

sacred ermine
#

I tried python code, it download all the 20 files, but there is no any flag

balmy lion
#

hello, anybody with some help for the following, please?

Module: Attacking common apps
Section: Web vulns in Thick Client apps

I've got to the SQL injection part, I have modified the User.java file by ||modifying the first public User definition with the code that was given in the lecture, as well as deleting all the SHA encoding blocks and replacing it with the public void setPassword definition. ||, and rebuilt the JAR file as it was done earlier in the lecture. The JAR file runs properly, however I am getting a login failed error when I try to login with the SQL injection. (logging in with a valid user works however, but no elevated privileges of course)

balmy lion
twin gulch
#

Hey guys, I’m at attacking common services - SQL part, stuck at logging in the user, somehow my network getting bugged when I’m trying, any help?

twin gulch
#

Looks like I need to install SQLcmd , is it available on kali?

fathom pendant
#

If I'm recalling correctly*

tardy aurora
#

Hello

candid ocean
#

Module: Using metasploit frameowrk
Section: Sessions and Jobs
Priv esc question
I have gotten the user shell.
Tried using the post exploitation tools however kept getting "Exploit completed, but no session was created." with every variation I tried
moved onto uploading linpeas and while I got linpeas uploaded. I cannot get a TTY shell, or when attempting to exe from the meterpreter shell it doesnt escalate the user.
Need some help please

fathom pendant
#

To do the post-exploit

#

You also do need to ctrl-z/background not fully exit/close session

candid ocean
#

I was able to get that far, found the 3 post exploitation modules
-seems vulnerable but could not verify
-is vulnerable
and -service is running but could not verify

#

tried running all 3

fathom pendant
#

Iirc it's the one that is shown

#

In the module

#

But make sure you set the post exploit exactly the same

candid ocean
#

There is no post exploit mentioned in the module - it makes quick reference to that it is possible to use sessioned exploited machines in a post exploit way.
But no actual examples - I'll keep digging i guess

thin harbor
#

Hello everyone
Please help with the possibility of ROTATION, TUNNELING AND PORT FORWARDING.
I'm stuck on one of the tasks and can't go any further.
I will be very grateful if someone can help me in private messages.

fathom pendant
thin harbor
#

I probably haven't gotten to that yet)))

fathom pendant
#

Also just ask your question

#

What section is it?

thin harbor
#

I have a one-step question: What two IP addresses can be discovered when attempting a ping sweep from the Ubuntu pivot host? (Format: x.x.x.x,x.x.x.x)
This refers to the topic of Meterpreter Tunneling & Port Forwarding.
I use the communication verification methods that were specified in this thread and get two hosts: 172.16.5.19 and 172.16.5.129, but they are not suitable for the answer

fathom pendant
#

And you provided it in the same format?

#

Provide it in the same format it tells you

#

With a comma between the IP

thin harbor
#

Oh, I was wrong
Yes, I provide the answer in the same form as required, but it doesn't help

candid ocean
#

@fathom pendant I appreciate your help but wanted to let you know what happened.
So running the "post/multi/recon/local_exploit_suggester" gave different results the 3 times I ran it - on my most recent run it made reference to the boxes sudo version (which was obviously hinted at in the question)
However that was still not the end becuase that post exploitation payload does not execute a shell - I then had to search for similar shells to that suggested payload and there was another with a similar name which was able to provide a shell as root.
Thought I'd let you know incase you get this question again 🙂

thin harbor
fathom pendant
#

Idk then I'm not at my computer to help

#

Just wait and someone else may be able to assist

autumn pilot
#

you need to specify just one IP address

#

not both

fathom pendant
#

Ahhh right

#

BC one is the system's ip

#

The answer format implies 2

#

Unless they copied wrong

thin harbor
#

I don't understand)
Do I need to find out 2 addresses on the question, or am I confusing something?

fathom pendant
#

Just one

autumn pilot
#

the answer is one IP

fathom pendant
#

One of those IPs is the Ubuntu host that you're sweeping from

#

The other is the answer

thin harbor
#

That's why I decided that these 2 addresses should be suitable 🙂

autumn pilot
#

please delete the spoiler

thin harbor
#

So this is the wrong decision (
I don't understand what to do(

raven saddle
#

I have a question. Before you guys do the modules did yall do the academy first or go back & forth?

fathom pendant
#

The modules are academy

fathom pendant
shy star
#

Hello! Is this the place to report issues with content on htb academy?

silk minnow
#

Linux Privilege Escalation - Special Permissions
I ran the command to find files with the setuid bit set and got /tmp/r*. I put that in as the answer but it tells me its incorrect. Can I get help on this?

Edit: So there were 2 files that were not shown in the example output. I got the answer!

shy star
fathom pendant
shy star
#

Makes sense! I guess I should expand my vocabulary - wasn't sure what erratum meant 😅

fathom pendant
rare topaz
#

My god i have 380 ping on Xfreerdp sessions

#

Does anybody know how to uhhh make it more stable?

misty current
#

I'm not able to see the A record for the host

west dune
#

What is this sever about ?

rare topaz
rare topaz
misty current
#

Footprinting - DNS

#

I need the get the IPv4 address of the DC1 host

fathom pendant
acoustic owl
misty current
#

I did the zone transfer, But I don't see the DC1 host

#

@fathom pendant

fathom pendant
misty current
#

Noted, let me check.

somber gorge
#

Is there somewhere where htb points are explained? why do I get 5 pts for a 50 pts box for example

autumn pilot
rare topaz
#

If i got the student plan and completed the modules, will i still have access to them after i cancel the student plan?

And what about the cubes i get for completing each module, do i still get/keep them?

tribal plume
#

I'm pretty sure you keep access to modules you complete even if you don't have an active subscription.

#

Same for the cubes you earn.

rare topaz
#

under the student plan, there's a disclaimer saying you'd have to pay again to continue having access, hence my need for clarification.

tribal plume
#

I suppose you should take this to support then.

rare topaz
#

Aight

fathom pendant
rare topaz
#

Ah ok, ty

#

There's still the cubes question, but i'd assume you get to keep the cubes?

quick cloud
#

I keep timing out from the rdp session to the foothold machine on Shells and Payloads - The Live Engagement. Is this intended?

misty current
#

subdomains-top1million-110000.txt from seclists is sufficient for the last question in Footprinting-DNS?

fathom pendant
misty current
#

Yup!

fathom pendant
#

Need a more fierce hostlist. Your answer will be a.b.inlanefreight.htb

misty current
#

Ah, so that's what the hint was about huh?

fathom pendant
#

Subdomains of subdomains woooo

misty current
#

oh well, gotta do what you gotta do lol. Thanks for clarification

fathom pendant
#

Np

formal pike
#

A

quick cloud
#

I keep timing out from the rdp session to the foothold machine on Shells and Payloads - The Live Engagement. Is this intended?

misty current
sonic moon
#

ATTACKING COMMON APPLICATIONS - Attacking Thick Client Applications
Hi,
I'm trying to solve the exercice but I don't understand which memory address I need to dump. I did uncheck all option except Exit Breakpoint. Each time I launch the program, It stops at this address : 00007FFD994E250D | EB 00 | jmp ntdll.7FFD994E250F

Then, when I follow it in Memory Map, I don't have anything like the exemple in the course (USER, MAP -RW)

I'm pretty sure that I need to analyze the restart-service .exe in the c:\programdata folder but it isn't there.

I know that I need to run that program to generate it. It crashed all the time. I changed all the permissions has mentionned.

.\Restart-OracleService.exe
Windows PowerShell terminated with the following error:
The type initializer for 'System.Management.Automation.Runspaces.InitialSessionState' threw an exception.
'c:\programdata\restart-service.exe' is not recognized as an internal or external command,
operable program or batch file.
Could Not Find c:\programdata\restart-service.exe

Can someone give me a clue on this one please?

Nevermind I got it. Dump mistake. I was skipping an important step. All details matter.

pulsar swift
#

can anyone ping me, I need small clue/help regarding Snoopy? Sorry if this is against the rules Im really stuck for long time 🙂

pulsar swift
#

Thanks, just read it 🙂

#

I see I should not ask in private, so I asked here if someone can hint me in private 🙂

fathom pendant
pulsar swift
#

ok, let me verify first

#

I just verified

#

Let me check the chann

plucky temple
#

question: Where can I find the list of valid academic domains from hack the box? I am a student from the Netherlands but I'm not sure if my school is on the hack the box list. (I want to buy a student subscription in HTB academy:))

little bear
#

One will talk to the DNS/DHCP or DC server, the other over the WAN I believe

plucky temple
quasi wave
#

is it worth it to do CBBH and pentesterlab at the same time?

#

to get really good at web app pentesting?

cunning prairie
#

Module=AD Enumeration & Attacks , Section=Skills Assessment Part II. I am able to get the pw to CT***. My thinking is to do a dcsync attack based on the BH result. I port forwarded and logged via RDP into MS01 but obviously running into limited privileges. I did consider using secretsdump.py but getting errors. Can someone offer a suggestion on what I may not be considering?

steady hawk
cunning prairie
red steppe
#

Hey all

#

Would like some nudge on priv escalation

#

If anybody could have a chat about it? cheers

quasi wave
#

quick question. at what point doing HTB Academy should I start HTB Main Platform if I'm a beginner?

#

would you say when I complete CBBH/CPTS? earlier?

#

what's your take?

#

or later when I have CBBH, CPTS, CREST CRT, and CREST APP?

steady totem
#

You can get on there and do the starting point anytime. They come with walkthroughs to show you through it. After that, if you buy the VIP, you can use community walkthroughs to do some retired boxes just for reps and exposure.

Figuring out an active box on your own is pretty tough though usually

quasi wave
#

Ok. What if my long term goal is to be able to do advanced boxes on my own and my medium term goal is to be able to do easy and intermediate boxes on my own?

#

is that doable if I go through Academy and get all certs?

#

and practice?

#

and do advanced boxes also have web component?

steady totem
#

practicing boxes on the main platform will get you there faster than the certs imo

quasi wave
#

Ok. No I really meant what about practicing on Academy?

#

not so much about taking certs

#

at what point should I add in HTB Main Platform if I already am doing Academy?

#

I am on last module of Information Security Foundations Path on Academy

#

I want to do CBBH next

#

and maybe do HTB boxes that go with CBBH?

#

so ya

#

then once I am good with web I want to do boxes that go with CPTS stuff and OSCP

#

so your saying Academy won't get me there?

rose furnace
#

Hello, i am currently stuck on this question.
Use the Metasploit-framework to exploit the target with EternalRomance. Find the flag.txt file on Administrator’s Desktop and submit the contents as an answer.
I was able to access the desktop and i opened flag.txt and copied the answer but it says its the incorrect answer

#

The answer i got is || MSF-W1nD0w5-3xPL01t4t10n ||

#

Sorry i am new to hack the box

steady totem
rose furnace
#

Okay

#

I got it. I forgot to copy the HTB bit. Sorry for wasting your time

fathom pendant
willow sonnet
#

Currently doing the password attacks module. idk if its just me but should the pass the hash section really be included there instead of at the pivoting module? It is explained pretty well already but i feel that specific section has a fair share of parts that asks you to read a module that come after the current one in the current track for more info

quasi wave
#

I found that the entire CBBH path on Academy maps to a fortress. If I wanted to do Akerva fortress on HTB Main Platform, would that best be done while I'm doing CBBH or after? Is Akerva material more advanced than all of CBBH?

#

or is it same difficulty level?

fathom pendant
sacred ermine
#

does anyone have difficulties with academy ? I mean it doesnt work at all

#

seems smbdy is having fun

rose furnace
#

Hello, I’ve been using hackthebox for about 2 days and for some reason the workstation is quite laggy

#

Is that normal?

vital adder
vital adder
sacred ermine
#

it loads barely, sometimes it logs me out

vital adder
#

the log out thing i sometime get and the loading issue may because of adblock extension or your internet speed or most likely the HTB academy server are having a stroke

sacred ermine
#

but yeah, maybe u will be ensured in it later

vital adder
cinder edge
#

Hi

#

am new to HTB academy

#

i just started in File Transfers

#

can any one help me on it

spiral pelican
#

hi all
Module : Windows Attack & Defense
Section : Credential in Object Properties
i am stuck in the last question of the section. i got the cred for bonni and try to connect to the DC
Then go for check the log as htb-student but i only have 4625 event no 4771 id event as the hint says to check.
I dont know what to do for this question. the targetUserSid on the event 4625 is not the correct answer. (i check with the UI and PS)
anyone had the same probleme ?

blazing socket
cold scaffold
#

for "Running SQLMap on an HTTP Request" in sqlMap essentials module. I run this command

#

Now i have to use sql injection based on the results ?

#

So i have to learn SQL first 🤔

light hearth
#

Is never a Bad idea, but why not try --os-shell or --os-pwn as sqlmap params

cold scaffold
#

in "hint" it says to use --data and --batch parameters

fallow delta
#

anyone recently finish the Password Attacks module? I am currently on Credential Hunting Linux and could use an assist as far as what wordlist to use for a shadow file. Tried rockyou but it exhausted

brazen hinge
#

FOOTPRINTING - SMTP (Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer.) what am I supposed to do?

cinder edge
#

iam stuck in file transfer :Windows File Transfer Methods no 1 question how can i get flag.txt

misty current
#

Also, the module provides you a username wordlist under "Resources"

#

You can make use of that

cinder edge
#

i didn't have a proper guide to do on my first question Download the file flag.txt from the web root using wget from the Pwnbox. Submit the contents of the file as your answer.

#

can any one give me hint to do

#

iam stuck for 1 week on this

acoustic owl
rustic sage
#

@edgy trellis

willow sonnet
#

i managed to solve the password attack medium lab but i'm unsure how the privilege escalation even works. Could someone explain it to me?

celest latch
#

Hey I am new to cybersecurity, Can anyone help me to grow?

acoustic owl
cinder edge
#

@acoustic owltq for it

plain coral
fathom pendant
lilac halo
#

ACTIVE DIRECTORY ENUMERATION & ATTACKS : ACL Abuse Tactics
module I'm trying to run this command, but I'm getting back this error what can be a reason

fathom pendant
#

It looks like within the script it didn't load properly

fathom pendant
lilac halo
odd knot
#

Can someone help me with the footprinting lab- hard? I get the account data for ssh but I need the public key so I login in IMAP and try to Fetch with “1 UID FETCH <ID> RFC822, but the message is that “Fetch is complete” but I don’t get any message. So what can I do to become the key to login?

lilac halo
#

its showing like INLANEFREIGHT does not exist

fathom pendant
#

Interesting

#

If you were able to just interact with it that's weird

rotund urchin
#

I am working on the shells and payloads assessment and i can figure out how to gain access to host 2. I found the exploit, but im not sure how to use it.

#

i would love to chat about it with someone

rustic sage
#

bro

#

why earning cube's is hard

#

i only got 30

#

i need buy a easy something for grind

#

but which stuff's are easy (modules and etc)

fathom pendant
#

Fundamentals

#

Also you won't earn more cubes than you spend

#

Fundamentals will refund the 10 cube cost each tier up only refunds some not all

stone glen
#

there is no earning of cubes, for the tier 0 modules, you get back what you spend, for higher, you just get some cubes back. No additional cubes are given.

dim hound
blazing socket
rustic sage
rustic sage
storm skiff
#

Hey guys, I'm trying to solve the File Upload Attacks Whitelist Filters section. I used the bash script and added ||php5, php7, phtm|| to the ||for ext in|| line. After generating that list, I pasted it into Intruder and made sure to uncheck url encode these characters. Whenever I navigate to ||SITE:PORT/profile-images/PAYLOAD|| I get a ||Not Found|| error. Is anyone able to help?

rustic sage
#

you must upload a something for see your file in "PAYLOAD"

#

are you here

storm skiff
rustic sage
#

that's a php code

#

you know probaly

#

you should upload "php" file extansion but probaly there is a only accepts "png and etc photo extansions"

#

did you tried upload your php file extansion?

vital adder
#

also ||one of|| the extensions you added to your script should work

sullen sandal
#

Hi guys I'm currently on the "AD Enumeration & Attacks - Skills Assessment Part II" and I'm stuck on the question 6 : Locate a configuration file containing an MSSQL connection string. What is the password for the user listed in this file?

#

Does someone have an idea please ?

storm skiff
vital adder
rotund urchin
#

Can someone chat about Shells and Payloads skills assesmnet? I cannot figure out this one and I have been stuck for a while:

vital adder
rotund urchin
#

It is the 5th on on the Live Engagement part

naive wadi
#

I'm on the last question of the SMB footprinting section & I have done all the work, found the flag etc & I am currently looking at the path and it still won't accept my answer, unsure of what syntactically I am doing wrong? Question is "What is the full system path of that specific share?"

vital adder
vital adder
rotund urchin
#

so idk what I am missing

vital adder
naive wadi
vital adder
#

without a / at the end?

naive wadi
#

yeah

#

even tried tilde ~ as well

vital adder
#

oh that's weird shoot me a dm with your answer

naive wadi
vital adder
#

hint take a step back and enum ||other service||

sullen sandal
#

thanks

storm skiff
rotund urchin
vital adder
#

nope and got 0 idea about that error

#

and did you use the .rb exploit in the exploitdb directory on the foothold machine?

vital adder
#

you still on question 6?

sullen sandal
#

Yes

#

The hint for this question is : "Remember that not all users can read all files in an AD environment."

#

So I think I need to find a file on ms01

vital adder
plucky temple
#

On the /billing page it says the following:
" Access to Academy modules requires an active student subscription."

Does that mean that if I buy a student subscription and I complete several modules. I won't be able to access those completed modules after my subscription is ended?

fathom pendant
#

After you complete a module you retain access

#

If you lose your subscription while in the middle you either need to buy a new sub or just buy cubes

plucky temple
#

That's good to hear! Thank you for your quick reaction:)

rustic sage
#

how youtuber's get hacked by only clicking fake pfp file

#

by mail

fathom pendant
fathom pendant
#

I'm informing you :) there are other channels to ask in if you read #welcome it explains it

rustic sage
fathom pendant
rustic sage
#

hep

#

help*

#

bro i cant even send smth because of mee6

brazen hinge
manic magnet
#

Does anyone know why this happens:

#

Like to be specific: Why is my ticket removed from the cache ?

#

(I am on the active directory enumeration module)

#

nvm I used the wrong domain

primal crag
#

Hey everyone is anyone able to help with the Web attacks/API module, I'm somewhat stuck on the Information disclosure through SQL injection question. I've tried all the basic payloads from the SQL module and can't get a positive response.

brazen hinge
#

Anyone could help me in Footprinting - SMTP? (Enumerate the SMTP service even further and find the username that exists on the system.) , i was trying using the command: ||smtp-user-enum -M VRFY -U footprinting-wordlist.txt -D inlanefreight.htb -t 10.129.198.120 -w 7||, playing with|| -M and -w parameters||, but i can't find the username, what am I doing wrong?

lilac halo
rose furnace
#

hello, for some reason whenever i open a workstation my internet keeps cutting off. It is always when i open the workstation because my internet is working just fine before opening it. Everytime my internet turns off and it says wifi is disabled. i am using arco linux

#

it was working completely fine yesterday

#

but yesterday i was using a different internet network

fathom pendant
#

<@&861185840277487616>

burnt stone
thorn urchin
#

do you have pwnbox + vpn connected at the same time

primal crag
#

Hey Everyone, I'm at 95% completion on the CBBH path and have run into three recurring issues that I'm stuck on.

Php file inclusion filters on the LFI and uploadattacks moduule. I seem to be missing something that across both. I've been fuzzing extensions, adding magic bytes, etc and I don't know what is causing my issues.

Time Code generation for the cookie brute forcing and login brute forcing. Need to discuss this a bit.

SQLi - Where it is used in the web attacks/API module.

If anyone is able to help/discuss these I would greatly appreciate it.

vital adder
plucky temple
# fathom pendant After you complete a module you retain access

Support says this:

Make sure to renew your plan monthly to not lose access to the learning material you've acquired so far.

So that means you have to renew your plan in order to have access to the material you have acquired so far, even if you have completed it right? (I'm strictly talking about the student subscription, I don't know about other subscriptions)

fathom pendant
#

Just message support chat

#

I'm not an all knowing wizard, I just know what others have said

#

And iirc I've seen staff say it as well

plucky temple
#

Ah okey thank you

iron plaza
#

Need a bit of clarification on something related to Web Attacks - Mass IDOR Enumeration:

If I am unsure of the format of the files in the folder then how do I go about using curl to get the links?

I tried: ||url -s -X POST http://178.62.74.235:31244/documents.php -d uid=15 | grep -oP "\/documents.*?"|| but this does not work ... FYI the files in question are pdf and txt files

autumn pilot
#

grep -oE "/documents/[^']+\.(pdf|txt)" this?

#

or this grep -oP "\/documents/.*?.(pdf|txt)"

hardy socket
#

hey guys and gals, can anyone help me with the shells & payloads Live engagement assessment please? I've been stuck on the second question since yesterday 🥺

autumn pilot
rustic sage
#

oh my god!

low echo
#

Has anyone completed this module? Exploiting Web Vulnerabilities in Thick-Client Applications

rustic sage
#

they keep muting me!

#

IM NOT JOKING

rustic sage
low echo
#

i figured it out, thanks anyway

#

it is punishing

autumn pilot
#

if you continue to be naughty you will get the boot, keep up with the topic of the channel and its intended purpose

rustic sage
#

he has a roman pfp those were racist christian nationalists who persecuted africans and arabs purely for their appearance and religion

#

maybe you need to check your white privelege

autumn pilot
#

what?

rustic sage
#

you heard me

#

black lives matter it may not be 2020 anymore but its a movement not a trend

analog dock
#

Wtf did I walk into

rotund urchin
hardy socket
rotund urchin
#

sure, DM if you would like

hardy socket
rustic sage
#

Anyone else got this error while doing "RDP and SOCKS tunneling with SocksOverRDP" section in "Pivoting, tunneling and port forwarding" module?

acoustic owl
rustic sage
tulip cipher
#

hey did you solve it ? i got the same problem

brisk geode
summer flame
#

Hi, can someone give me some hints for Windows Priv Esc - Miscellaneous Techniques?

autumn pilot
#

think where an admin could potentially store sensitive information

glossy ore
#

||the Deleted Items folder in Outlook||

dull vortex
#

How long should I expect to wait for the password attacks module exercises to complete? Like in terms of hydra brute forcing things, is it a very long time that I should let it run or did I do something wrong if it is running forever?

thorn urchin
#

unfortunately its long enough that often by the time you can reasonably say something was wrong, you have to reset the lab

brazen hinge
# fathom pendant -w 25

I just tried it, but it shows me that all the emails in the list are valid.I am trying with the VRFY mode, the EXPN does not return anything, and the RCPT mode also returns that all the emails are valid.I am trying with the VRFY mode, the EXPN does not return anything, and the RCPT mode also returns that all the emails are valid.

dull vortex
thorn urchin
#

sometimes yeah

fathom pendant
brazen hinge
#

yes i am usiging it and the domain ||inlanefreight.htb with the argument -D||

fathom pendant
#

Iirc you shouldn't need to specify -D

#

But it has been a moment

wispy aspen
#

Yes, use VRFY and skip the -D and domain

#

with -w 25

fathom pendant
#

Thanks

#

My brain is a bit fogged since just waking up so syntax in brain go brrr

wispy aspen
#

No worries, I only had it in mind since I just did that one on like Friday

fathom pendant
#

Lol fair

brazen hinge
#

Great! that was, the domain was not necessary, thanks!

fathom pendant
#

It's the same password list for 99% of the module the one from resources. Iirc though after it has you create a mutated list you need that as well

#

If I'm recalling correctly

#

Otherwise there's an open port you can pull the list from

#

Iirc there's only one that may require that

glossy ore
#

i think i'm having issues reading/parsing again. working on the skills assessment for the module "information gathering - web edition" and am confused about what this question is looking for: Perform active infrastructure identification against the host <snip>. What server name is returned for the host? it feels like "server name" can mean a million different things, and i'm not sure what it's looking for

fathom pendant
glossy ore
#

the hostname of the server the site is running on? or the value of the Host header?

fathom pendant
#

Hostname as in when you log into the server via ssh you get user@system

#

Iirc

#

Again it's been a hot minute

#

Just do the active enum and usually the answer is fairly obvious

#

Overthinking tends to lead to wrong answers

glossy ore
#

yeah and the obvious answer isn't being accepted, so now i'm not sure what i'm supposed to do

#

oh. it works now. weird. must have had some extra spaces or NPCs

#

module complete, thanks 🙂

fathom pendant
#

Ye

fathom pendant
rustic sage
#

I was working on skills assessment of pivoting and port forwarding, from what I see here, it seems like this lab doesn't involve any password cracking. (it doesn't have resources)

fathom pendant
rustic sage
#

I am on the part where you dump ||lsass||, I tried previous tactics and failed so will work on it later.

fathom pendant
#

Ah

naive field
#

hey guys any idea why its not working? they provided this cmd in the module

autumn pilot
#

Are you sure the path is correct

#

Also you have an >

fathom pendant
#

^

naive field
#

thanks a lot mb

fathom pendant
#

❤️

naive field
#

haha

naive field
#

okay so I am doing pivoting module, web server pivoting with rpivot section and i've got ssh and attack host connected, but when i run proxychains with firefox its not working

#

it just fires up mozila and loads foreveerr

zinc marsh
#

someone who completed macos fundamentals?

#

not sure if is bugged

#

i have this question Find the numeric version running on your machine and submit it as the answer.

#

but there is no machine to connect and the machine i spawn is a parrot

acoustic owl
naive field
zinc marsh
# acoustic owl

even with that if i create a virtualbox with macos i cannot respond that answer no?

naive field
#

u could then

#

u just need something with macos on :D

zinc marsh
acoustic owl
naive field
#

u can do that

zinc marsh
#

unless i can answer with any version

naive field
#

the same

#

🤷‍♂️

thorn urchin
#

not even having taken that module before and Ive had several complaints with it lol

acoustic owl
#

The module is cool. But it requires a Mac. But that's what it says in the description.

acoustic owl
#

<@&861185840277487616>

autumn pilot
#

thanks

languid dawn
reef sundial
#

Same issue like I had!

rustic sage
#

Just finished Pivoting, tunneling and port forwarding module, if anyone needs assistance, DM me.

naive field
naive field
rustic sage
#

Sure, looking forward to it.

polar widget
#

Folks

rustic sage
#

Thanks, one step closer to the big bad AD module 😄

quick cloud
#

I need help with Shells and Payloads - The live engagement - Exploit the target and gain a shell session. Submit the name of the folder located in C:\Shares\ (Format: all lower case)

zinc marsh
#

someone who finished macos fundamentals am just missing 1 question but i cannot finish it because i havent mac

#

i know how to solve it but i cannot do it because i havent mac if someone could help me

ocean beacon
#

can any tell how can I find cms info

zinc marsh
#

Search 'homebrew' for 'tmux', and one of the results ends in 'nator'. What is the full name of this package?

flint chasm
#

Hi i have a slightly different topic. is there anyone who could give me tips on how to properly make a test report using the CVSS calculator? Thanks in advanced!

zinc marsh
#

cvss is to know the risk of the vulnerability

#

following the CIA triangle

#

condifentiality integrity and availability if im right

zinc marsh
ocean beacon
#

content management systems (CMS)

zinc marsh
ocean beacon
#

recon (information gathering)

red current
#

I'm really struggling with the Intro to SQL Injections module. Is anyone able to provide clarification on how this all works? I just can't seem to wrap my head around it.

zinc marsh
ocean beacon
#

Active Infrastructure Identification

rotund urchin
#

Has anyone done the password mutation module? I did the walkthrough from the course to write a password list, but nothing is cracking when attacking SSH.

zinc marsh
trail leaf
#

Quick question on Session Security - Exploiting Weak CSRF tokens: The text says

When assessing how robust a CSRF token generation mechanism is, make sure you spend a small amount of time trying to come up with the CSRF token generation mechanism. It can be as easy as md5(username), sha1(username), md5(current date + username) etc. Please note that you should not spend much time on this, but it is worth a shot.

I know that these are suggestions, but if you were to use current date + username, would it be more common to have an actual date (e.g. 05152023) or use something similar to a Unix timestamp rounded up or something or something else entirely?

zinc marsh
#

did u added the vhosts?

trail leaf
#

Basically just asking what the most common ways to do it would be, because I can think of many 🙃

thorn urchin
ocean beacon
zinc marsh
ocean beacon
#

how

#

?

zinc marsh
#

read the section

zinc marsh
thorn urchin
#

often just using your eyes and looking for the cms version number works

zinc marsh
#

but cant find the answer lol

thorn urchin
zinc marsh
#

i must be just to tired then

#

completed 3 modules today

thorn urchin
#

its the same backend as using the cmdline so if you couldnt spot it with the website you wouldnt spot it from the terminal either 😛

#

might have fat fingered spelling tmux

ocean beacon
zinc marsh
#

yea was easier than i thought lol thanks

zinc marsh
#

there are different tools to enumerate the infrastructure of a website

ocean beacon
#

that I am not able find the cms

zinc marsh
#

what command did u try

ocean beacon
#

I used whatweb

#

how can I add vhosts

thorn urchin
#

add it to /etc/hosts

ocean beacon
#

same thing I did

zinc marsh
ocean beacon
#

how?

thorn urchin
#

worked for me too

#

check the output carefully

zinc marsh
#

just use wappalyzer if u not able to see it

#

i think is more visual for new people

thorn urchin
#

You can also just look at the web page and read it

ocean beacon
#

I got it

#

thanx man

zinc marsh
#

well im going to sleep

#

gn

ocean beacon
#

gn

rotund urchin
#

Would someone be able to at least give me a nudge of what letter the password starts with for the mutations module? I have been bruteforcing SSH/FTP for over 2 hours now.

#

I unerstand the concepts and mutations, I feel like this is just dragging out for no reason lol

fathom pendant
#

Those are given in the resources tab

#

If it's dragging out then you're probably just using the wrong lists

rotund urchin
#

i am, i ran the same command as in the module against the resources provided. I first tried SSH but was too slow. Switched to FTP, it’s still slow and haven’t got anything yet

fathom pendant
#

Try using -t 32

steady hawk
#

^
Also, if you can get the password policy you can reduce the list size

fathom pendant
#

Pw policy isn't needed if it's the pw attacks module

#

From the sounds it's just the pw attack module being sloooow

fathom pendant
#

If that's the module I'm thinking

steady hawk
rotund urchin
#

nah it’s the one for ‘sam’

fathom pendant
rotund urchin
#

yeah i was thinking about trying to cut down the list, it’s huge. I know it probably hits toward the beginning or middle, but just not having luck

fathom pendant
#

it's there ¯_(ツ)_/¯

#

Iirc some of them I've had to wait like 10 minutes before

rotund urchin
#

yeah idk, just slow as balls. sucks.

#

i’ll try again with higher threads

fathom pendant
#

32/48 seems to work on average

rotund urchin
#

well i thought SSH had a cap on threads due to the nature of the service but i could be wrong

fathom pendant
#

Don't use ssh

#

There are other services running

rotund urchin
#

yeah tried ftp first, didnt notice that big of a jump

#

but i’ll try again

thorn urchin
#

if you didnt notice a big jump you did something wrong

#

plaintext protocol vs encrypted protocol designed to be slow to brute

pine dagger
#

If it’s the question I think it is, ||cut the first 17,000 lines||

rotund urchin
#

thanks for the tip 😄

plain gazelle
#

Crackmapexec - Skills Assessment - Question 3 - I've pwned the SQL server and have ||stolen the james hash and cracked it.|| I have no idea where to go from here. Any nudges?

rotund urchin
#

That seemed to work @pine dagger , much appreciated

fringe shell
#

Anyone done the Attacking FTP section in Attacking Common Services module? I've restarted and waited a few minutes and the FTP still isn't coming up. I can read the proftpd.conf and read what port it should be on to answer the question, but I can't hydra the robin login without the service up 🫠

rotund urchin
#

also side note: seems like ncrack is much better to use, at least for me

buoyant plover
#

Does anyone ever finish the modules in the time it states? For Example, File Transfers show an estimated time of 3 hours to complete and it has a lot of material. Is anyone getting through the modules at the time listed?
Note: I am not racing against the clock, I am taking my time... I just wanted to know I'm not the only one.

plain gazelle
fathom pendant
#

Some people only spend at most an hour on some modules that take others 4+

#

Also when a module states 'days' it is considering 8 hours as a day

buoyant plover
#

Thank you both for the quick responses, that really helps. I can tell "Active Directory Enumeration & Attacks" will take a least 2 weeks for me even though it states 7 Days. I'm going through the Pentester path as well, so it's good to set my expectations early in the game.

plain gazelle
#

No worries. The Active Directory module is epic. In fact, I might redo it just to cement some concepts and enumeration tactics. The crackmapexec module is also good for A.D. stuff.

#

I think the A.D. module took me 3 weeks or so.

buoyant plover
#

Thank you for the insight. I will make sure to take detailed notes during that module.

fathom pendant
#

I think so far I've spent maybe ~8-9 hours on it but I've been busy and not been touching it a few days at a time

buoyant plover
#

I can definitely see myself going through the module again after missing days. Some skill assessments are rough if some days have passed in reviewing the material.

#

Later mates.

dull vortex
#

I have been working on the password attacks/password reuse and default creds section for about an hour now. I have the list that was linked in the module, and I have been trying all the password/user combinations over and over again both in the lab and in the answer box and nothing is working... I feel like I am going crazy, is there something I am missing here?

fathom pendant
#

And user list

rotund aspen
#

Hello, I am having issues with the Attacking Common Services - Attacking SMB questions. I am using the password list provided but all passwords fail when using crackmap. Am I missing something?

dull vortex
fathom pendant
#

Ah

#

Yeah iirc you just need to look closely at the history

#

When ssh in

rotund aspen
#

nevermind, found the answer when the question was asked previously. Need to use the --local-auth option which isn't mentioned in the module

fringe shell
fathom pendant
rustic snow
#

OKOK

#

Sorry

fathom pendant
#

Also don't just spam every channel you have access to

#

Makes you look like a jackass

unique valve
# rustic snow Sorry

No worries. Limit cross posting. Know that youll get quicker responses in the relevant channels 😁

fathom pendant
#

And people more willing to give a response

glacial hazel
#

inb4 I get a warning NotLikeThis ban

foggy light
#

Module - Game Hacking Fundamentals
Section - Skill Assessment
Question - What flag is displayed when you successfully modify the HiddenScore counter to a value greater than 200'000'000?

I found 2 values 1 float and 1 double , tried matching the value.. not working. Anyone solved it yet?

acoustic owl
plain coral
#

Given the increasing number of defensive-based modules being released, I believe it would be fantastic if HTB Academy expanded on the Introduction to Networking Module. It would be great to have an advanced networking module that delves into setting up networks with VLANs and other components, while building upon the theoretical knowledge. Acquiring thse skills would be incredibly valuable.

crude turret
#

Yandex translator.
Can you help with the introduction to the academy? I do not know the answer in the Interactive section, I have already tried everything I knew. Thanks for the help

#

Thank you, this is the answer I was looking for. I didn't find it in the text, most likely not attentive

quick cloud
#

I have been struggling with Shells and Payloads - The live engagement question 2 for hours now if someone can point me in the right direction it would be very helpful

#

Even went and did shells and payloads a second time just to see if I missed something

quick cloud
#

never mind it was so simple haha pm me if anyone needs a hint with this

fathom pendant
quick cloud
#

I hope not lmao im trying to uplaod a war payload rn

fathom pendant
#

Ohhh the tomcat one

quick cloud
#

yep

fathom pendant
#

Yeah that one was fun I didn't take good notes on it so it'll be fun to revisit lol

quick cloud
#

haha im taking very detailed notes this one hurts my brain

#

I never wanna revisit again

fathom pendant
#

I remember Google being a good friend xD

wraith delta
#

How do I get cubes for the modules without paying i got the 200 cubes a month but it aint enough

fathom pendant
#

You can't. You get some refunded whenever you complete a module but it's not going to be a net positive

wraith delta
#

So the only way is to subscribe to the more cubes plans

#

right?

fathom pendant
#

Or just purchase the cubes outright

wraith delta
#

I dont see an option to buy cubes alone

#

Oh nevermind

#

i didnt know u could scroll

quick cloud
#

]

#

\

fathom pendant
fathom pendant
#

Reminder that some things can only be accessed internally

#

Don't speak in emoji

#

You could access via proxychain or just by signing into the foothold

#

¯_(ツ)_/¯

#

Pw attacks labs are lot about back and forth with files

#

Iirc

#

You shouldn't need to specify -h

#

But yes

languid grove
#

hi

fathom pendant
#

Or you know just do it from your foothold machine

#

Not at my computer to assist

#

But just a reminder: if you're trying to overcomplicate it, then you're probably doing it wrong

#

The module can be completed without proxychain

#

Iirc

#

IP may be a red herring if I'm remembering

#

Like I said I'm not at my computer and I've got work in a few hours so if after work you're still stuck. Lmk. Iirc it's fairly straightforward for the most part

#

Someone is probably gonna come by and reveal like the obvious answer xD

rustic sage
#

hello

smoky chasm
#

Stuck on Password Attacks Lab - Medium initial foothold, I tried Hydra but get "target smb://10.129.202.221:445/ does not support SMBv1" and recompiled Hydra to no help. I defaulted to the Metasploit module and it gives me all false positives

autumn pilot
#

what about crackmapexec?

smoky chasm
#

it stops on the very first user/pw combo as successful

#

@autumn pilot

autumn pilot
#

well, can you reproduce the same issue using the workstation in academy

snow coyote
#

hi, i have issues with the file inclusion module. The problem is in the very first LFI exercise. As seen in the explanation of the module something like "...language=/etc/passwd" should at least (depending on if the Basic inclusion is possible) give me an error code in the "history" box. However, i end up with something like this:

#

nvm i can't post pictures

#

But the history box is completely empty

#

I'm using firefox, tried chrome too, tried reseting the target, tried a few bypasses but it just won't show me anything

smoky chasm
#

just tried and same issues using workstation, I must be doing something wrong but can't work it out

fathom pendant
smoky chasm
#

ok will try ty

fathom pendant
#

I mean anonymous do go brr

#

If that's the hint you're given

#

...

smoky chasm
#

😂 fml

ocean beacon
#

can any one help me to solve the Active Subdomain Enumeration part

#

I am stuck there

snow coyote
zinc marsh
placid quest
#

@snow coyote dm me

tough prawn
#

Skills Assessment - File Upload Attacks I do Everything Right bypass the extension & i found the Path

#

But when I try access the file it's not exist

thorn cosmos
#

Hey GUYS, I'm on Shells & Payloads Laudanum and the module don't accept my answer. the absolute path with or without the filename of the shell don't work.... It's the same path on my Kali and in the PWNBOX... any advice? ||Even if I put the path of the symlink...||

autumn pilot
#

have you checked the hint?

thorn cosmos
autumn pilot
#

and you have specified the filename as well in the path?

thorn cosmos
wraith delta
#

Guys whats the best amount of tasks and timeout for ssh bruteforce with hydra

rustic sage
#

Hi, I'm stuck at the same point, depending on the way I launch sqlmap I get a HTB non valid flag or a blank table, any help? thanks

#

Hi same for me... any help?

proud pine
#

Alternatively, you could use a longer manual delay.

slender steppe
#

Command Injection Skills Assessment need hint?

naive wadi
#

Just found your message, after doing the same.

weak stirrup
#

i am doing the Login Brute Forcing website assessment i got a few passwords for the second 'admin' login php page from a hydra run. None of them seem to work. I always get a 404 return when i try to log in. what might i be doing wrong? i find it weird that i have found multiple username/password combos...

weak stirrup
ocean beacon
#

I need some help with the Active Subdomain Enumeration

tropic galleon
#

Hey folks! I’m stuck on the Htb academy hacking wordpress “submit the contents of the flag file in the directory with directory listing enabled” trouble is I can’t actually get in to the website when trying to run wpscan it doesn’t work and I’ve tried so much stuff I just can’t make any breakthroughs. Any help or tips would be greatly appreciated. Thanks should of said I’m on the skills assessment - final part.

storm ice
#

Hello Would you mind sharing more hints, I am stuck in this lab, I tried Hydra with username.list + password.list / mut_password list for ssh, smbv2, cme and metaesploit and nothing, not able to get a valid username or password. Thanks in advance for the help. CME shows a shared folder /john, metasploit smb plugin shows false possitives ; (

tough prawn
#

Im stuck on the Skills Assessment - File Upload Attacks
I got everything except when I try access the file

#

also I got the endpoint for uploads file

lethal shard
#

Hello!
I'm stuck on Introduction to deserialization attacks skills assessment II. I know how to recreate the cookie object value, but i can not forge the sign value. I think that i found the right salt in the web page source code, but don't know how to use it and where i need put it. Any hint like $salt.$value how to recreate the sign value please?

naive wadi
#

Im doing the SMTP footprinting section and have used the supplied wordlist with smtp-user-enum but either get a bunch of false positives or 0 results command is as follows ||smtp-user-enum -M VRFY -U footprinting-wordlist.txt -D inlanefreight.htb -t 10.129.66.126 -m 20 -w 3|| note the -w flag option varies hence the false positives etc

#

looking for a nudge

naive wadi
#

is anyone here....

glacial timber
#

no

naive wadi
glacial timber
naive wadi
#

I'm good, just smashing my head against a wall due to false positives, you?

sonic seal
#

Hi everyone, anyone have a hint or tip for me please? I can't find the flag4.txt on Linux Local Privilege Escalation:Skills Assessment. I found some credentials but I can't use it in any place... I already use LinEnum and LinPeas but I can't see the path. Moreover, I already check the services but I can't as well.

naive wadi
glacial timber
sonic seal
sonic seal
naive field
#

hey im trynna transfer chisel with scp and i get this

#

and i get not a regular file everytime?

autumn pilot
#

you are trying to transfer a directory

naive field
#

yeah

autumn pilot
#

instead of a file

naive field
#

oh okay

naive field
autumn pilot
#

If you want to transfer directories, you should check the manual, there is a specific switch you can use

naive field
naive wadi
#

@autumn pilot please sir, can I have a hint......

autumn pilot
naive field
#

hey so when im using chisel, in the module they get this in output when connecting with server:


2022/05/05 14:21:18 client: Connecting to ws://10.129.202.64:1234
2022/05/05 14:21:18 client: tun: proxy#127.0.0.1:1080=>socks: Listening```
#

this last line

#

but i dont get that

#

how can i know what ip and port for proxychains to config?

#

🤷‍♂️

autumn pilot
#

check your proxychains config file

naive wadi
autumn pilot
#

nothing prevents you from using it

#

be curious

naive field
#

"2022/05/05 14:21:18 client: tun: proxy#127.0.0.1:1080=>socks: Listening"

#

but i dont have that so idk what to set in config

#

what ip and port

willow breach
#

Hello all, someone can help me, i'm stuck on DNS footprinting

naive wadi
willow breach
naive wadi
#

yeah this one got to me too.

autumn pilot
#

don't forget special characters when using cupp

willow breach
#

What the hell is that... 😂
I found 2 transferable zone, but no one gave me the good FQDN

naive wadi
acoustic owl
willow breach
#

I try one by one 😂

blazing crypt
wraith delta
#

guys if i buy one of the monthly plans for cubes do i get the cubes immediately

#

like 200 today then 200 in a month

autumn pilot
#

yup

wraith delta
#

alr

autumn pilot
wraith delta
#

I enrolled the penetration tester path, should i complete it in order from top to bottom as it shbows the modules or does it not show by order?

#

Or should i complete all easy modules then move up to the medium ones?

naive wadi
#

Have reset box to ensure it's not the box

#

Think I may just be dense in this one

#

still not working

#

with a box reboot

#

FIXED! Dodgy VPN connection

#

still cannot get an answer with the supplied wordlist and recommended module in metasploit

#

there are no other switches that can be used so have no idea

smoky chasm
#

Password Attacks hard - I am trying to crack the ||vhd|| hash but have tried the mut_password list to no avail, i'm trying the other well known list but that seems like it will take forever

thorn urchin
naive field
#

do i have to have sudo privileges to run ptunnel-ng

#

?

vital adder
smoky chasm
vital adder
vital adder
zinc marsh
#

any useful text editor to make scripts in bash and python?

#

which do u recommend

vital adder
#

sublime text

#

you can both run and edit code right in the gui

zinc marsh
#

but in the new one is asking me to pay the license all time

naive field
#

but was just wondering since i needed to use sudo on ssh too

#

and if i dont have sudo priv on real engagement i couldnt use it

#

right?

vital adder
vital adder
zinc marsh
#

i need the license unless i cannot use it lol

vital adder
#

oh wait which version of sublime text are you using? the main one is free the licence pop up is just a bit annoying

zinc marsh
#

sublime3

vital adder
#

if you are on linux follow this and install the Stable version and you should get sublime text 4 with i think the latest build and it's free with the license pop up thing https://www.sublimetext.com/docs/linux_repositories.html

edit: nope this isn't the case for sublime text 4 not sure how tf i can still use it in my kali

zinc marsh
#

am uninstalling ans installing it again

#

@vital adder now i can use it without license ty

vital adder
#

i mean i can in my kali vm

heady geyser
#

module 147, section 120. If someone could help. I have used the usernames and passwords list in the resources tab to try to bruteforce ssh and ftp creds with hydra. I have used Will as user and the passwords list and no luck. I have used Kira and the passwords list, no luck. I have used Kira and LoveYou1 and still cant get any access via ftp, ssh, or smb. What am i missing?

vital adder
#

you can just say the module and section name not the number in the url

heady geyser
#

Password Attacks - Credential Hunting in Linux

zinc marsh
#

@vital adder can i ask u when i finish the script if it can be optimized?

vital adder
#

yes but i'm 100% way too dumb to answer that question

vital adder
heady geyser
#

thanks, will try again

storm ice
#

Thanks a lot my friend, it worked like a charm 😉

cyan ginkgo
#

can someone help me on the AD module living off the hand the last question " Utilizing techniques learned in this section, find the flag hidden in the description field of a disabled account with administrative privileges. Submit the flag as the answer. "

heady geyser
zinc marsh
#

someone can explain me why it tells Syntax error: "(" unexpected in this code:

import re
from bs4 import BeautifoulSoup

PAGE_URL = 'http://143.110.162.231:31880'

def get_html_of(url):
    resp = requests.get(url)

    if resp.status_code != 200:
        print(f'HTTP status code of {resp.status_code}, but 200 was expected.')
        exit(1)

    return resp.content.decode()

html = get_html_of(PAGE_URL)
soup = BeautifoulSoup(html, 'html.parser')
raw_text = soup.get_text()
all_words = re.findall(r'\w+', raw_text)

word_count = {}

for word in all_words:
    if word not in word_count:
        word_count[word] = 1
    else:
        current_count = word_count.get(word)
        word_count[word] = current_count + 1

top_words = sorted(word_count.items(), key=lambda item: item[1], reverse=True)

for i in range(10):
    print(top_words[i][0])```
heady geyser
zinc marsh
#

and i was missing the #!/usr/bin/env python3

#

now it worked lol

heady geyser
#

nice

frosty mason
#

hello im really struggling with this question on pregnition ,When using gobuster to dir bust, what switch do we add to make sure it finds PHP pages? for the love of god i have tried everything that comes to mind help me please

#

tier 0 starting page

acoustic owl
naive wadi
humble hemlock
#

I got a question, should i share my academy transcript ? Or is it personal information

#

I own a good amount of modules and paths

#

I feel like this would be a bonus ok my resume, but am not sure