#modules

1 messages · Page 81 of 1

humble hemlock
#

Any suggestions?

frosty mason
#

thank you

thorn urchin
#

idk I didn't use metasploit

naive wadi
#

I tried smtp-user-enum same deal

#

will try again

thorn urchin
naive wadi
#

tried EXPN & VRFY

thorn urchin
#

sounds like out of three different options youve tried two that hasnt worked

naive wadi
#

haha, will try some more

#

thanks

dire abyss
#

this maybe the wrong place to ask but do the cubes roll over?

zinc marsh
#

someone can create a new repository in github?

#

or is just me who is bugged

leaden abyss
#

**** Originally posted in pwnbox channel since it's related to pwnbox but, it's also very specific to HTB Academy so, I'm posting it here for help. ****

Hi everyone! Does anyone know how to copy something from the HTB module and paste it into a module instance of pwnbox?

I'm doing a Ffuf module and am trying to copy/paste the wordlist path but, can't figure out how to do it.

I would use the copy/paste feature for more than just this. This is just 1 example.

#

I know about the small clipboard button in the individual instances of pwnbox.

This same button doesn't seem to exist in the per-module instances of pwnbox.

zinc marsh
#

where can we share ideas for modules?

#

i would like they add more advanced scripting 🙂

fossil crescent
#

Has anyone done Data Extraction under the module Blind SQL Injection -- MANUALLY? I used sqlmap to solve this one, but at a loss on how to do it manually...

glacial hazel
#

You can also inspect the entire request with wireshark

#

or you can increase verbosity level, check the manual

fossil crescent
glacial hazel
fossil crescent
glacial hazel
#

yes doing sqlmap manually is a good practice to understand what it’s doing

iron spear
#

Can I get some help with working on dante? I cant get the ball rolling unfortunately. Not sure what I can say without spoilers

fossil crescent
hardy socket
#

can anyone help me with the meterpreter question in the Metasploit module please?

hardy socket
fathom pendant
red current
#

I'm in the SQLMap Essentials module and I keep having issues with the connection timing out to the target URL. Anyone else seen that or know what I might be able to do to fix it? I can't get past the first question because of this issue.

red current
hardy socket
fringe shell
#

Can anyone help with the Attacking Common Services module? Specifically Attacking SQL Databases and the question "Enumerate the "flagDB" database and submit a flag as your answer."

red current
finite seal
#

Can I ask someone for help on Attacking Applications Connecting to Services please? Part of Attacking Common Applications

red current
#

Does anyone have any hints or tops for the 3rd question in Running SQLMap on an HTTP Request of the SQLMap Essentials module?

fringe shell
iron spear
steady hawk
red current
steady hawk
fathom pendant
fresh vector
#

Hello I'm having issues with the Nmap network enumeration service enumeration module

red current
steady hawk
#

Didn't work in my vm either lol

fresh vector
#

is there a way to hide my commands? I dont want to accidently reveal anything

fathom pendant
#

Screenshot, go into mspainy

#

Mspaint*

#

And gg

fresh vector
#

I think i found the flag on the webserver, but its spitting out that its not the correct flag. I found it in the robots.txt directory

glacial hazel
#

Is it a long string of alpha numeric characters?

fathom pendant
fresh vector
#

Ahh okay, ill keep enumerating

red current
#

Does anyone have any hints or tips for the 3rd question in Running SQLMap on an HTTP Request of the SQLMap Essentials module?

#

I've copied the request header and pasted it into a txt doc. I then ran sqlmap against it with the -r switch and I get nothing. Even when I add --craw=2 to it, I get nothing.

#

If there's something I'm supposed to ad to the txt file, I can't find where to add or what needs to be added. Does anyone have any hints?

steady hawk
red current
steady hawk
#

Yea, you should include the post data. then just sqlmap -r req.txt

red current
steady hawk
#

Yea, copy the whole request in the the file

red current
steady hawk
#

you can right-click on burp > copy to file

red current
fringe shell
red current
solar zodiac
#

hi eveyone! has anyone done the game hacking module? I was wondering if it covered game client/server data transfers, or if all the game hacking was local

steady hawk
red current
steady hawk
#

Cookie: id=1*

red current
#

Wait, this is for the 3rd question, right?

steady hawk
#

Yes, i believe that's the one you asked about

red current
steady hawk
red current
steady hawk
red current
heady geyser
#

need help in password attacks module "credential hunting in linux". download all resources. mutated password list. used the new mutated password list to hydra FTP. hydra -l Kira -P mut_password.list ftp://10.129.232.48 -t 64. 2 hour scan later and still no hit. I got a "hint" from someone saying to use the mutated password list but that didnt work. Could use some help.

swift forge
#

Is there a fix with web enumeration in the pwnbox? Everytime I try to run it with the generated target, I get an error that it is unable to connect

#

HTB Staff any help with this?

fringe timber
#

Can someone help me with Information Gathering - Web Edition - Active Subdomain Enumeration. "Find and submit the contents of the TXT record". I have no idea what's going on

fringe shell
heady geyser
#

ok, will give it a go. thanks

fringe timber
#

Sweet. Found it

fringe shell
heady geyser
fringe shell
heady geyser
#

no worries, thanks again

#

meh. so i bruteforce using crackmapexec. Get successful creds. Still cannot access the SMB share with those creds. Tried using those creds to SSH and FTP in and still no luck. Rabbit hole?

#

@fringe shell

heady geyser
crimson crown
#

has anyone completed pop3/imap on footprinting?

fringe shell
crimson crown
#

nvm just finished

#

gotta be the hardest section on that module

tired marten
#

im starting new need help with netcat on first module

#

forward host lookup failed: unknown host

faint rampart
#

its not broken
I actually find it more efficient lol

steady hawk
faint rampart
#

alrighty
Its easier to execute batch queries with it or at least for me

steady hawk
faint rampart
#

alrighty thank you

rustic sage
#

Hey!!

zinc sentinel
sick mural
#

Hi all, Did someone come across any mind map made just for CPTS track?

#

Or any idea how to revise all the studies again? Its a huge course to learn in one go. Just my thoughts

zinc sentinel
dreamy solar
#

Hello I would like to learn attack of active directory and I would like to have a certification for confirm my formation? Can you help me plz?

autumn pilot
#

there are a few modules covering AD in Academy

dreamy solar
#

yes I see but a certifcation? Is there ?

autumn pilot
#

well, if you want a certification you can go for CPTS

dreamy solar
#

Thanks !

candid zephyr
#

If you want to specifically learn about attacking AD etc do CRTP / RTO etc.

#

CPTS if you want a more rounded approach, some of the labs are fun, some are fucking awful.

rustic sage
#

I am currently doing the the skill assessment for LFI, I'm trying to get LFI and read /etc/hosts.

||So far, I've read the source code and found <?php if(!isset($_GET['page'])) { include "main.php"; } else { $page = $_GET['page']; if (strpos($page, "..") !== false) { include "error.php"; } else { include $page . ".php"; } } ?>

I can see that any string with ".." is sanitized so i use payloads without it or I double URL encode my string. Whenever I try to read the /etc/passwd file I recieve a blank output, I assume that its because ".php" is appended to the end of the string, however I can't seem to be able to bypass it, I've tried using filter wrappers, path truncation, null byte injection but nothing seem to work. I've also tried all of these with various different prompts but can't seem to get LFI. Is there something I am missing or doing completely wrong?||

any help with be much appreciated sadbob

#

Ok, I was checking source code and found:
||ilf_admin/index.php||

#

Success hi

fathom pendant
fathom pendant
fathom pendant
#

While it wasn't their actual password don't want people falling down incidental rabbit holes

fathom pendant
# heady geyser Done

If you're still working on pw attacks. I recommend keeping all the passwords you come across

fathom jasper
#

can anyone tell me if cubes roll over into the next month if you don't use them all? I'm assuming they do, but I can't find anything that states it

rugged veldt
#

hey for password attacks lab medium, i have found a zip file, got the hash, cracked the hash but getting errors when i open the file. any ideas?

fathom pendant
fathom pendant
fathom jasper
rugged veldt
#

nvm think i got it XD

fathom pendant
#

XD

rugged veldt
#

wait nvm

#

LOL

#

i need to unencrypt it

fathom pendant
#

Yeah no shit that's why you got the password

#

XD

rugged veldt
#

yea i got the pass

#

but incorrect password?

fathom pendant
#

Rip

#

Copy the password into a text editor and make sure there's no weird spaces or anything at the start or end

#

Or just copy/paste lol

rugged veldt
#

yea im just typing it

zinc marsh
fathom pendant
#

|| before and after

rugged veldt
#

2 of ea

zinc marsh
#

ty

fathom pendant
#

Basic discord things

#

That gets explained at least once a month

manic magnet
#

~~Hey, I am at the last skill assessment of the AD enum module and when I try to LLMNR poison I get this:

Why does it says that it captured the hash but does not print it. (I used sudo responder -I ens224 -wF)~~

Solved it with -v

fathom pendant
vivid igloo
#

need hel p

#

i got the flag of this question : Enumerate all ports and their services. One of the services contains the flag you have to submit as the answer.

#

but it's still saying incorrect ans ??

rustic sage
#

check for spaces

spark iris
#

Hey guys i just started the linux fundamentals module and i wanna ask

fathom pendant
#

I wanna answer

vivid igloo
spark iris
#

regarding the VPn connection file and SSH connection, can i do it on windows too? or exusively on linux?

vivid igloo
#

it's still saying incorrect ans ??

#

but i got the flag

fathom pendant
fathom pendant
#

No idea what that is

spark iris
#

if u have kali linux try that command

fathom pendant
#

don't care enough to ¯_(ツ)_/¯

vivid igloo
#

wth is this error ?

#

@rustic sage ??

fathom pendant
vivid igloo
#

ok

#

can u check ur dm @fathom pendant

rare gorge
#

Greetings to you 👋🏽

rustic sage
#

I'm trying to get RCE on the LFI skill assessment:

||Im using burp suite to log poison, but the logs dont seem to show up? I'm getting 0 matches||

sonic ferry
#

For the past few days I've had major problems with the targets in htb academy. The targets keep freezing. I usually get to do a few minutes of work on the target, and then I have to restart it. Is it just me? Even when using the pwnbox I keep having this problem. Yesterday whenever RDP kicked me out, I just kept swapping between my VM and the Pwnbox since I couldn't connect back with the same machine for the next few minutes.

If I just try to wait out the problem, it takes 3-5 minutes for the target to start responding once again...

rare gorge
#

Please can I discuss with someone in PV for my research?

fathom pendant
harsh hill
#

Hi, I have a problema with the first question of the section "Attacking SQL Databases" of the module Attacking Common Service, you can help me ?

autumn pilot
#

what is the problema

viscid epoch
#

me too please

autumn pilot
#

take a look at the plugins

dull vortex
#

I am working on Password Attacks, Credential Hunting in Linux. I am unable to get lazagne running on linux(I don't have python2.7). What is the recommended method of setting it up on my VM?

acoustic owl
vapid isle
#

Hey everyone

#

I have problem with footprin hard leb

#

I got the key from toms mail box and then I tried to login over ssh.

#

But it show me an error. “Load key “id_rsa”: invalid format
tom@10.129.202.20: Permission denied (publickey).”

#

I change permission with 600

fathom pendant
#

change RSA perms
The rsa key needs the begin and end lines

vapid isle
#

Thanks

#

Now it’s working

#

🫡

storm ice
#

Thanks for the follow up, I got it already, thanks a lot for the hint!

analog tendon
#

I could use some help on the broken authentication module. section predictable reset token question 1 so far. I can get the epoch time and they give the username for the token we need to find. but i dont know what script they want us to make. i tried modifying the php script and get parsing errors. im not sure how the username and time are connected to render it a md5sum because ive tried the "username . time" as shown but they keep ending up incorrect. im unable to recreate the original token hash because i dont know how its supposed to be formatted prior to the hashing

naive field
#

im doing pivoting module and socksoverrdp section and when i try using mstsc i get this

spark iris
#

is trhere any kind on how the VPN thing should work on llinux?

analog tendon
naive wadi
proud cloak
#

Hi all, need a litle help with restic the password I found seems to be incorrect i can't chack repository... (module windows privilege escalation)

#

*check

acoustic owl
proud cloak
acoustic owl
rustic sage
# naive field

This is common, happened to me and a few other fellas, I can help out though. Dm me.

analog tendon
subtle glen
#

using web proxies skills assessment 3rd question i know i need to find a result with a different result, i cannot, here's what i have done so far:
||i sent the request captured from http://[target ip]/admin.php i set the payload to alphanum-case.txt i set the payload processors to the decoded cookie, base 64 and ascii hex.
then i tried to run it, mostly 200s some had different lengths but there was no one different from the others.
i tried to include admin.php in these: §§ but it was giving me a different original cookie so i deleted them off admin.php|| may i please have some help?

rustic sage
rustic sage
#

Sure.

misty current
#

Going through the CREST CRT path modules,prepares a person to take the exam. I heard that you need other pre-requisites to be eligible for the exam? Is that the case?

crimson walrus
#

hey guys, I need help with the AD enum and attacks module.
I am currently doing the DCSync exercises and I need to use both the Linux and Windows attacker machines. In the module it says to ssh from the Windows machine to the Linux one and the IP and creds are given. However, when I try to do it, it says permission is denied (it doesn't accept the password). Any help?prayge

spark iris
analog tendon
misty current
outer steeple
#

Anybody around that could answer a question on the IDS/IPS Evasion Medium lab?

outer steeple
analog tendon
#

are you using the tcp or udp connection when using your vm?

fathom pendant
#

Eh sometimes it's an issue with UDP/TCP connection

#

^

outer steeple
#

udp

analog tendon
#

what Marcie said. if your using the TCP vpn connection. for some reason it doesnt work correctly. but the UDP does

#

youre sure? because thats the issue i had when going through that. switching to a new config file for UDP fixed it

outer steeple
#

nevermind.. just opened my vpn connection. The website showed udp selected but my file is tcp

#

/doh

analog tendon
#

happens ¯_(ツ)_/¯

terse igloo
#

I am stuck at the beginning of the hashcat module for the path of basic toolset

#

😅😊

acoustic owl
terse igloo
#

Creating a xor Cypher, I am stuck at where to begin tbh

#

I'm also utilizing Google to research it on my own as well but I figured I'd ask you just in case somebody has like a hint of what I can do I don't want the answer

#

So I guess the answer would be I have only tried researching, I have not put in effort yet with what I've gathered so I'll come back when I've exhausted if I haven't gotten it on my own

#

Thank u

acoustic owl
#

This question?

Create the XOR ciphertext of the password 'opens3same' using the key 'academy'. (Answer format: \x00\x00\x00....)

zealous spruce
#

Hi there! I am new to the academy 🙂

acoustic owl
analog tendon
#

Can anyone help me with the question im on?

zinc marsh
#

someone who completed the module siem fundamentals

#

am trying to find the logon type but it does not show it

terse igloo
acoustic owl
earnest ginkgo
#

Hi, i am doing the module, Active Directory and windows Security. But i can't access the VMs in RPD since a couple of days. You guys have the same issue ?

halcyon pond
#

hey how do i make win32bof.exe accept data in the Stack-Based Buffer Overflows on Windows x86 skill assessment ive just been trying with a basic python script at port 21449 but nothing seems to happen

terse igloo
#

Oh I always do 😂 its just I'm a freshling

acoustic owl
#

No problem. Everyone here started from 0

vast ginkgo
#

hello everyone, I am new to this website and is going to try out the Penetration Tester on hack the box, excited to see how much i learn from this.

spark iris
analog tendon
spark iris
analog tendon
spark iris
#

is the System Information by Linux Fundementals supposed to be done from the VM or an private laptop?

analog tendon
spark iris
analog tendon
spark iris
#

ye just the parrotOS realy hangs hard on the console for me currently idk why

glacial hazel
#

VM is de wey

analog tendon
#

Is anyone going to help me with the question im on. i just need someone to explain what i need to do Broken Authentication. Predictable reset token question 1. ive already got question 2 but im not sure what script they want me to make and the script provided gives me traceback errors

storm skiff
#

I'm stuck on the File Upload Attacks Skills Assessment. I found the ||upload.php|| location. Tried to POST a ||SVG file|| for ||XXE|| and I get an error: ||only images are allowed||. Can anyone assist?

analog tendon
odd notch
#

I'm confused

#

"The Oracle Transparent Network Substrate (TNS) server is a communication protocol that facilitates communication between Oracle databases and applications over networks."

#

how is it a server and a protocol?

storm skiff
analog tendon
#

did you bruteforce the acceptable extensions?

plucky temple
#

Question: If I buy the student subscription (it says unlimited pwnbox access) would I also be able to use the pwnbox when I’m not doing a module on academy HTB? (for example to use for an active machine on the main HTB platform)

storm skiff
analog tendon
#

ok. so using the known good extensions. do you know of any of those that will work with the XXE inside a SVG file? i know in the module they gave a few lists and in one of them it should have a file extension that allows for it. then after that just need to work on the magic number

fringe shell
#

man its frustrating when a module gives you a specific password list in the resources, the password isn't in the list and it sends you down a rabbit hole for an hour until you just try rockyou and get the creds 🫠

manic magnet
#

Just saying but the AD enum and attack module was insane. Like the Skill assessment took me overall probably 8h. But coming from "I don't know anything about AD" to "I actually can solve the skill assessment" is awesome now 😄

mellow sundial
#

hello

#

I speak english an spanish, pls speak in spanish

red current
#

Got a question on the first question in the SQLMap Essentials module. The Attack Tuning section's first question says "What's the contents of table flag5? (Case #5)" and the hint says to use the -T flag5 option and the --no-cast option as well. I have run this multiple times and I still get to the end of the run with no flag found. Any ideas what I might b doing wrong?

mellow sundial
#

aa

#

esto es preguntas xd

red current
mellow sundial
#

hola

red current
mellow sundial
red current
#

Is anyone else available to assist with the SQLMap Essentials module?

red current
# zinc sentinel hit me

The Attack Tuning section's first question says "What's the contents of table flag5? (Case #5)" and the hint says to use the -T flag5 option and the --no-cast option as well. I have run this multiple times and I still get to the end of the run with no flag found. Any ideas what I might b doing wrong?

fathom pendant
zinc sentinel
red current
#

I've even added --dbms=mysql and set the --level and --risk as high as possible. Still no result.

zinc sentinel
#

-T?

red current
#

It runs for about 5 to 10 minutes and then ends with nothing found.

zinc sentinel
#

are you dumping ur finding?

red current
#

I'm dumping.

#

Wait a minute. Never mind. I'm not sure what happened, but it suddenly coughed up the flag. Thanks for the help, though!

red current
#

Uh, it says it's wrong.

zinc sentinel
#

didnt wanna say it... but yeh i had to run it 4-5 times

#

Recommend save flags each time and compare

red current
hard dew
#

I can't seem to complete the File Transfers - Detection module

red current
#

It just keeps giving the same flag. Is there something I'm missing? I'm even changing the level and risk. Still getting the same flag each time.

zinc sentinel
red current
mellow sundial
mellow sundial
#

srry

zinc hemlock
#

In the Login Brute Forcing Module, on the first question in the "Service Login" skill assessment, I need some help. I have used username anarchy to create a username list which is 15 line long, because i dont know what "usernameGenerator" is. Also i used cupp -i to create a wordlist multiple times, first i used <firstname> and <lastname>. and then i used that with the birthdate. I got fully through the first list and most of the way through the second list, but even in 90 minutes the second list didn't fully finish, because the machine shut down. I have been brute forcing for hours and gotten nothing. Can i get a hint?

red current
zinc hemlock
#

@red current yes and it is 15 lines long

red current
prisma knot
#

How can I identify group membership of a specific AD user from a linux attack box?

zinc hemlock
#

@red current the username list is 15 lines long, not 15 characters name. is that still too long?

prisma knot
red current
zinc hemlock
#

@red current yeah that is what i've been using though and unless it is meant to take this long, something must be going wrong

#

idk what it is though

red current
zinc hemlock
#

yeah sure

fringe shell
#

Just did the easy assessment for "Attacking Common Services" and the flag mentioned there were 2 ways to get it. I'm interested to know if anyone else has done it and if they did it differently

naive field
#

how do i transfer a file using xfreerdp? in the command line

#

im trynna figure out for hour lol

#

i cant find anything good online

zinc sentinel
#

/drive:/home

naive field
#

just in the command?

zinc sentinel
#

add ur path to end of the xfreerdp command

naive field
#

xfreerdp /drive:/home /v:ip /u: usr like this?

zinc sentinel
#

xfreerdp /v:IP /u:username /p:password /drive:/home

naive field
#

okee thanks!

zinc sentinel
#

😄

naive field
#

okay im kinda stuck on pivoting skills assesment, im onto the first pivot user mlefay and im stuck there the whole day

zinc sentinel
#

im am stuck many hours on command injection bypass black listed commands trying to cat file from users home

naive field
#

i just used mimikatz for lssas since thats what it says in the hint, but am i supposed to crack the passwords or what?

naive field
#

i did a ctf that they said at the end was made by that module lab

#

ughh im trynna remember give me a min xd

zinc sentinel
naive field
#

ohh wow

#

i didnt expect that i had to exploit this lab

#

i thought its just gonna be pivoting n portforwarding lol

zinc sentinel
#

should be called pivoting/portfwding and file transfers XD

#

any advise on the command injection

little bear
#

Anyone notice that the powerview cmdlets in powershell provided in the examples (WinAD A&E)--some yield no ldap results and also STDERR out silently (2 arg; .ctor)?
The exact query is Get-DomainObjectAcl -Identity * |?{$_.SecurityIdentifier -eq $namesid}. This command example should technically work. When appended with -Verbose, no output is provided UNLESS is in Get-DomainObjectAcl -Identity * -Verbose which then you can see the LDAP query service.

The task was to find the specific ActiveDirectoryRights/ExtendedRights to a particular group over a user. Anything helps. I've tried different queries, with one yielding the answer I feel like inefficiently

barren robin
#

are you putting the verbose after the $namesid}

little bear
#

uhm, so the example states after {} -Verbose in the comment above

barren robin
#

I dont think that would work, since your telling Where-Object to run verbose and I dont think it has that option

#

It would only make sense to me, to put it after the -Identity * since that would tell Get-DomainObjectAcl to fun Verbose

#

Although I havent made it to that section yet so I don't know what exactly its telling you to do

little bear
#

(See comment about task)

barren robin
#

But running verbose gives you the answer?

#

in that second command?

little bear
#

It doesn't. The beginning of OP states that some of the powerview powershell cmdlets that some yield no ldap results and also STDERR out silently (2 arg; .ctor)

rotund urchin
#

Cna someone provide a nudge finding Will's password in the Linux Credential Hunting module? I have ran a few tools and attempted to run others, but no luck on finding it.

heady geyser
#

need some help, password attacks/credential hunting in linux. able to ssh in as k*** but cannot find any credentials for Will. i transferred over firefox_decrypt.py. chmod +x, then tried running it and get this error. ./firefox_decrypt.py
Traceback (most recent call last):
File "./firefox_decrypt.py", line 46, in <module>
PWStore = list[dict[str, str]]
TypeError: 'type' object is not subscriptable

#

Am i even going down the right track?

barren robin
fringe shell
heady geyser
#

so i did that a few min ago and got the same traceback error

fringe shell
#

are you using it on the target machine as the k user?

heady geyser
#

transferring "tasty dish" to k user. chmod +x. try to run it and get the traceback error

#

you think i should run this in pwnbox?

fringe shell
#

did you transfer the whole folder?

#

'tasty dish' in python needs the whole linux folder

heady geyser
#

hmm

#

can you wget a whole folder?

fringe shell
#

just zip the whole folder and transfer that over

heady geyser
#

gotcha

#

now i feel dumb, thanks. going to try it now

fringe shell
rotund urchin
#

I tried using that. I tried copying the repo and the compiled version over to the target, but neither version would run

#

says it was missing dependencies

fringe shell
fringe timber
#

anyone know why my module sections aren't being marked as complete?

acoustic owl
#

There is a button "Mark complete & Next".
You have to click on it. Only then the section will be marked as complete

fringe timber
#

lol

#

I understand that much. It's just not marking as complete when I click "Mark Complete & Next". I've tried logging out/in, deleting cookies and multiple browsers

acoustic owl
#

Have you answered all the questions on the page?

fathom pendant
#

<@&861185840277487616> ??

fringe timber
#

just going to move on for now, but leaving that module incomplete is really bothering me

acoustic owl
#

Open a Supportticket (Green Bubble)

fringe timber
#

i did

jaunty mortar
#

<@&486603600085123073> Can someone give me a nudge on Blind SQL Injection module; Assessment Q1. I have tried manual injection and sqlmap on login.php and index.php. Tried injecting user agent, referer and cookie fields but no luck. Also reset target a couple times

fringe shell
#

anyone able to give me a pointer on initial enumeration for the Attacking Common Services - Medium Assessment. I've pulled out a few domain names, but apart from straight brute forcing pop3 and ssh, i'm lost

autumn pilot
#

if you are not seeing a specific high port, then you will have to reset the target until it comes up

frigid ingot
#

is anyone available to assist with the Web Attacks module, just looking for a nudge using burp

autumn pilot
#

which section, or what is the exact question that you have

jaunty mortar
autumn pilot
#

nope to Skillet37

#

haven't done the blind sql injection module, therefore I won't be able to help you much

fringe shell
#

the magical port has appeared prayge

vivid igloo
#

After the configurations are transferred to the system, our client wants to know if it is possible to find out our target's DNS server version. Submit the DNS server version of the target as the answer.

#

hey am kind a stuck here

#

i got the nc connection but its not responding

#

module :NETWORK ENUMERATION WITH NMAP

#

contents :Firewall and IDS/IPS Evasion - Medium Lab

#

@everyone

fringe shell
fringe shell
vivid igloo
#

sudo nmap -sSU -p 53 --script dns-nsid 10.129.2.48

#

this was the command for the scan

#

i've spent hours but it was worth it lol

fringe shell
#

mine was similar, but i just did -sV instead of the exact script

vivid igloo
#

this one looks hard : Now our client wants to know if it is possible to find out the version of the running services. Identify the version of service our client was talking about and submit the flag as the answer.

#

got it \

eternal zephyr
#

Anyone there who can give me some advice on htb academy?

#

for someone who's just starting should there be any pre requisites before doing any of the modules?

#

or are the modules already fundamental enough?

vivid igloo
#

some bts would be great ig and also some knowledge of networking and also some basic knowledge of Linux

eternal zephyr
#

im currently enrolled in the bug bounty hunter programme but I plan to do both paths

#

Im doing some tryhackme and when I feel ready Ill hop on htb academy

#

everyone tells me htb is quite hard

vivid igloo
#

u should go slow u should make ur basic strong first

#

it'll only puzzle u by hoping one thing to another

#

go for the basic and make sure u have a good grip of burp networking and linux

eternal zephyr
#

when should you know youre ready for ctfs?

vivid igloo
#

i mean u can go for it anytime but what woud u do if u don't know non ?

#

u will google it and then get the ans that is non but wasting ur time

eternal zephyr
#

but what is the basic knowledge required to attempt them

vivid igloo
#

learn tools like burp gidra hydra etc ..

#

there are a lot it all depends on what kind of ctf ur playing it could be web crypto pwn

#

those are just tools

#

there are tons of em

eternal zephyr
#

okay thank you

vivid igloo
#

ayo am stuck again

#

Now our client wants to know if it is possible to find out the version of the running services. Identify the version of service our client was talking about and submit the flag as the answer.

#

module :NETWORK ENUMERATION WITH NMAP

#

content :Firewall and IDS/IPS Evasion - Hard Lab

#

nvm got it (sudo nc -nvv -p 53 10.129.57.209 50000
)

rustic sage
#

Hello everyone i want to buy cpts job path can someone help me to explain me which plan should I buy

acoustic owl
#

Or you are a student. Then check out the student subscription

rustic sage
#

No i want only cpts

rustic sage
acoustic owl
rustic sage
#

Yes I'm student

#

But does it matter which university?

acoustic owl
#

Then register with your university email address and you can sign up for the student subscription.

acoustic owl
rustic sage
#

So i have account yet with different email now i should create new with my university email?

#

I'm sorry for the dump questions but i don't want to do mistakes

acoustic owl
#

No, you can simply change the mail address in your HTB Academy Account

rustic sage
#

I see only one plan for students that's for 7 euro on month

acoustic owl
rustic sage
#

Nice

acoustic owl
#

Once you have completed the path, you can buy a voucher for the exam.

rustic sage
#

So thr voucher is buying separated

acoustic owl
#

yes

rustic sage
#

Thank you so much

rustic sage
acoustic owl
#

Yes, you can complete all modules in the CPTS and CBBH path

rustic sage
#

Thank you so much for the answers

rustic sage
acoustic owl
unreal narwhal
#

Is anyone else having issues spawning an AttackBox instance?

mystic lance
#

hello, i am new, you can call me pika or colress

sterile wharf
fathom pendant
#

contact support

open pelican
#

cant spawn pwnbox at all

fathom pendant
#

Message support on the website

low girder
#

Hello all. US ACADEMY 3 VPN is going down for maintenance. Please switch to different VPN servers for the time being.
Thank you hugthebox

naive field
#

??

#

anyone else has problems with pwnbox?

low girder
naive field
#

i cant run it

low girder
#

Please allow a few minutes.

naive field
open pelican
naive field
open pelican
#

support not answering either 😄

sterile wharf
low girder
heady geyser
#

question on password cracking section Passwd, Shadow & Opasswd. i found the .bak files and unshadowed them. i then deleted everything but root and then ran hashcat. hashcat is showing a 3+hour estimated time to crack with the rockyou list. Am i going down the correct path and just need to be patient?

autumn pilot
#

what about the mutated password list?

uneven comet
#

guys who can help me with DANTE?

green birch
#

snmpwalk -v 2c -c public 10.129.42.253 1.3.6.1.2.1.1.5.0
Can someone explain me the command and the flags? Because explainshell.com don't have an answer.

acoustic owl
green birch
naive field
#

hey guys im doing pivoting module skill assesment

#

i got creds for vfrank but i can not access it

#

i try to connect via mstsc.exe and it says creds are inncorrect

#

even tho they should be fine

#

do i maybe need to input a domain also or no? thanks

#

i alr checked with someone else and they say the creds are fine, what can the error be?

heady tusk
#

just checked my notes. don't have anything special regarding that step. maybe mistyped or something broke when copying?

simple zephyr
#

anyone around that has completed the Documentation & Reporting Practice Lab final lab?

I also set the resolution to dynamic but it doesn't look like I can change it. Am i stuck with this crappy resolution? I was trying xrandr but nothing was working

acoustic owl
simple zephyr
acoustic owl
#

If I remember correctly, you need the graphical interface

autumn pilot
#

you can create a tunnel

#

plus you can download the obsidian notes

true nacelle
#

Can the language of the website be changed to Spanish?

autumn pilot
#

no

true nacelle
#

ok

#

thx

simple zephyr
# autumn pilot you can create a tunnel

with this module, they do a password spray to get asmiths user name, when i ran enum4linux to pull all the users that list was much smaller then theirs. Am i missing something or just assume that asmith is a user and trust their results.

autumn pilot
#

well, go over the notes, and make some assumptions

#

based on them try to think what would be the next step

simple zephyr
#

ok i was trying to conduct the test blind and was trying to figure out where they found this user

naive field
zinc marsh
#

i have 1 question about defensive security

#

when should i Consult with IT Operations or Escalate to a Tier 2/3 analyst?

fickle nacelle
#

Pwnbox still down ;//////

heady geyser
#

asking again, question on password cracking section Passwd, Shadow & Opasswd. i found the .bak files and unshadowed them. i then deleted everything but root and then ran hashcat. hashcat is showing a 3+hour estimated time to crack with the rockyou list. Am i going down the correct path and just need to be patient?

fathom pendant
heady geyser
#

i dont think that's right. if you have notes could you take a look?

#

i already did the mutated password stuff for "will" and got in, now it wants me to find password for root. section is all about /etc/passwd /etc/shadow. so i dont think it has anything to do with mutations

fathom pendant
#

It's still cracking passwords

#

It's entirely possible it's in rockyou

#

Also a lot of this module regards patience

naive field
#

try changing vpn

naive field
#

if not make sure u use good wordlists

#

u have a lot of crackers online 🤷‍♂️

heady geyser
#

will do, thanks guys

wicked crescent
#

when i use gobuster the percentages interupt the results

#

how do i fix that

#

its a bit hard to explain wihtout an image

acoustic owl
open pelican
#

hi all, im stuck on the question "Obtain credentials for a user who has GenericAll rights over the Domain Admins group. What this user's account name? " on the AD Enumeration & Attacks - Skills Assessment Part II section, does anyone have a tip?

simple zephyr
# autumn pilot you can create a tunnel

SSH was defiantly the way to do it for the documentation and reporting. It made it very simple and I didn't have worry about proxychains. But it is still bugging me why i can not enumerate and find asmith without using the obsidian notes. I wanted to do this 100% blind to practice and that is the only part that I wasn't able to figure out.

running

enum4linux -U 172.16.5.5  | grep "user:" | cut -f2 -d"[" | cut -f1 -d"

Gets me a solid list but asmith is missing from it.

#

nm I just found asmith running this

crackmapexec smb 172.16.5.5 --users
open pelican
#

how did u? 😄

fathom pendant
open pelican
#

gotta do what you gotta do

raw belfry
#

^

rustic sage
fathom pendant
#

Instead just ask your question here

#

Like including " I tried doing x thing for this but I didn't get answers" or
"I'm stuck trying to do thing"

simple zephyr
#

for anyone that wants to test password spraying on the documentation module this will create you a user list.

||```
crackmapexec smb 172.16.5.5 --users | awk -F' ' '{print $5}' | awk -F'\\' '{print $2}' > users.txt
``||`

fathom pendant
#

Asking someone from something greater than a week ago is less likely to get you an answr

#

It's probably something simple that was overlooked

#

Is usually the case

#

Or a simple command switch missing

raw belfry
#

I'm on Linux Fundamentals Module in the Containerization section, and I'm attempting to "Configure the network settings for your LXC container.", I'm using the command "sudo lxc network create lixcon1" but I get this result:

#

Any ideas? I've tried to go through the options of lxc itself and google but I haven't found anything to lead me in the right direction

fathom pendant
#

Looks like there's no unix.socket file

#

At least that's what I read

fathom pendant
# raw belfry I'm on Linux Fundamentals Module in the Containerization section, and I'm attemp...
GitHub

Required information $ uname -a Linux nephele 4.18.0-041800-generic #201808122131 SMP Sun Aug 12 21:33:20 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux $ sudo lsb_release -a Distributor ID: Ubuntu Descri...

#

Two articles I found within 5 seconds of googling the error

raw belfry
#

Weird, when I looked it up it lead to only three results that didn't help at all, but thank you! Looks like I didn't have lxd installed (didn't know that lxc/lxd are different)

fathom pendant
#

They are codependent

#

Hopefully this fixes and works :D

zinc marsh
#

someone can help me with this question i dont know what to do: Search for "WordPress xmlrpc attacks" and find out how to use it to execute all method calls. Enter the number of possible method calls of your target as the answer.

#

hacking wordpress login section

#

this is the hint: ||Look at the "system.listMethods" method. You can filter and count the number of results with the help of "grep" and "wc".||

fathom pendant
#

Probably grep for method and piping it to wc just counts for you

zinc marsh
#

i am trying this: ||curl -X POST -d "<methodCall><methodName>system.listMethods</methodName><params></params></methodCall>" http://178.62.74.235:32534/xmlrpc.php | grep -i '<value><string>' | wc||

fathom pendant
#

grp

velvet pawn
#

anyone having issues spawning their pwnbox instance?

#

I am getting no instances available
"Error
There are no available instances. Please try again later.

fathom pendant
velvet pawn
#

thanks

zinc marsh
#

yea i got it

#

was reading wrong the wc lol

misty current
#

You can complete the Penetration Tester path within 100$ right?

fathom pendant
#

Between $100-200

#

The raw cubes is $200 I didn't do the math for refund cost

#

For the easy/medium modules that refund a portion of cubes on completion

misty current
#

But, a Gold+Platinum would give 1500 cubes which is around 110$

#

that should be enough to complete the path right?

fathom pendant
#

Click on the path: it will tell you (an estimated) cube cost

acoustic owl
misty current
#

It does say 1500, so the Reward cubes are the little cubes you collect overall from completing the modules right?

fathom pendant
#

Yes

misty current
#

Thanks guys

acoustic owl
#

You've already done a few modules. Therefore you need less cubes now

misty current
deep owl
#

hello all, i need some help please .... password attacks module ... credential hunting in linux section ..... i cannot connect to ssh using the username and password declared in the quiz hint

deep owl
#

yes

fathom pendant
#

You need to mutate the password given

raw belfry
#

I'll keep looking

autumn pilot
#

check for the hint

candid sail
raw belfry
velvet pawn
candid sail
dense shale
#

erm question

#

if i had lets say a blocked cromebook (totally not school) and they blocked extensions and being able to enable developer mode is there another way to download extensions ?

#

like a script

#

that will download them 4 u

#

or what

deep owl
#

password attacks module, ......... section: Passwd, Shadow & Opasswd............ quiz: how can i find the root password hash if the user will is not in the sudors file to access etc shadow

zinc marsh
#

someone who completed hacking wordpress, skill assesment section for sanity check please

#

am not sure if im doing what i have to do

little bear
# barren robin Right but you said this command Get-DomainObjectAcl -Identity * -Verbose yeilded...

No, that errored with "~2 arg..... .ctor--".

Basically, I modified the cmdlet query and achieved the results in what felt like an inefficient way when the example provided should have been the intended. Get-DomainObjectACL -ResolveGUIDs -Identity * | ?{$_.SecurityIdentifier -eq $groupnamesid} -Verbose resulted in a silent loop error that becomes apparent when you instead place -Verbose after Identity *. I tried something similar that I included in my notes (but I'm not logged into to view them).

proper needle
#

What uniquely identifies a Service instance?

little bear
# eternal zephyr okay thank you

I recommend learning your standard port numbers and try understanding simple protocol misconfigurations (i.g. the "beginner boxes"). Things like SMB, FTP, etc were all good but I highly recommend learning your port numbers and the services involved. That way, misconfigurations pique your interest and allow you to understand how one may leverage that misconfiguration.

barren robin
little bear
little bear
barren robin
# little bear The sound of Silence my friend

Hmm well the verbose at the very end shouldn't work, because Where-Object shouldn't have a verbose option I would think. So it makes sense that putting it after identity would work, but if thats what the example shows, I would think that would be wrong.

little bear
#

Still, if I can solve it, I can proceed.

#

Thank you shockp

zinc marsh
#

<@&861185840277487616>

barren robin
little bear
zinc marsh
#

someone for sanity check in wordpress - skill assesment

little bear
zinc marsh
#

||the flag is in the plugins directories?||

#

because i have enumerated all and couldnt find it

#

i already finished pwning the box by the way but still missing 1 questions lol

#

- Submit the contents of the flag file in the directory with directory listing enabled.

#

if it is 500k im down lol

red current
#

I'm in the SQLMap Essentials and running into an issue with the Attack Tuning section. I found how to do the second question, but it repeatedly times out before completely giving up the flag. Is there something I'm missing?

little bear
#

And do you have perms when searching?

little bear
zinc marsh
#

u didnt complete the module i think

barren robin
green birch
#

I am on this side: https://academy.hackthebox.com/module/77/section/728
Under the title Install SecLists stand: Next, add a DNS Server such as 1.1.1.1 to the /etc/resolv.conf file. We will target the domain inlanefreight.com, the website for a fictional freight and logistics company.

I don't understand what I have to do with the file resolv.conf, because in the page we don't make anything with this file. Or?

little bear
#

vim?

#

@green birch

zinc marsh
rustic sage
#

When I spawn a target, is it normal for 20 minutes to pass in real life and according to the target it's already been 50 minutes?

zinc marsh
#

but there is no flag lol i even got root to check the plugins where i needed admin

#

but nothing

barren robin
rustic sage
#

I mean that 20 minutes should be subtracted, not 50 minutes.

zinc marsh
#

it wasnt the intended way but well i was creative lol

barren robin
green birch
barren robin
green birch
# little bear vim?

Well, I can change the file, but I don't know for what I need this. Because the next command is

gobuster dns -d inlanefreight.com -w /usr/share/SecLists/Discovery/DNS/namelist.txt

But we don't use the file resolv.conf. I think so.

green birch
weak charm
#

Cam anyone PM me. I'm stuck on the final assessment for OS command injection and I feel like I've tried hundreds of payloads

grim mural
#

大家好哇

little bear
#

AD Enumeration
Setting a Fake SPN.
Cmdlet input leads to a Constraint error?

fathom pendant
glacial hazel
#

@grim mural 你会说英语吗 😄

fathom pendant
#

@glacial hazel this is an English Only Server especially in these channels regarding academy

glacial hazel
#

ik I said "we don't speak Chinese", and "Do you speak English?"

fathom pendant
#

I know what you said

#

I know some basic Chinese

#

But that's not the point

little bear
#

So committing changes is the issue. Just need to navigate around that I suppose

fringe shell
#

Just finished the Hard assessment for Attacking Common Services module and just got the flag through a file read. Just wondering if anyone else did it and got a full admin login?

fringe shell
fathom pendant
#

It's logical that someone joining a discord server would read the #rules as well

#

But we know that doesn't happen

fringe shell
#

i guess you could have the same expectation that people would read the terms and conditions for any service they use... 0.

fathom pendant
#

Nah it's pretty commonplace to parse the rules

#

Even if you don't fully read them

fringe shell
#

agree to disagree fingerguns

little bear
#

I figured it out... and I don't wanna talk about it, Lol

#

Kawabunga time

surreal hazel
#

I’m having difficulty with the System Information section of Linux Fundamentals where I’m instructed to connect to a server via VPN, to then “SSH to with user ‘htb-student’ and password ‘HTB_@cademy_stdnt!’ but am not giving an IP address and when I try either localhost or the IP address of the VPN, the password is rejected

surreal hazel
#

I’ve already spawned the server and connected to it via VPN

fathom pendant
#

That's... That's not how the VPN works my guy

#

The VPN connects you to the HTB academy network

surreal hazel
#

I’m not provided with an IP address for ssh

fathom pendant
#

The 'spawn target' button on the page should spawn it

#

It's under the launch pwnbox instance

#

Above the questions

#

That would be the IP you ssh to

#

Syntax : ssh username@ip

surreal hazel
fathom pendant
#

That's your pwnbox instance

#

Not the target

#

Look at the page for Linux Fundamentals you're on. Above where the question is that contains credentials should be green text

surreal hazel
#

That is unclear. I see now.

fathom pendant
#

That is either an IP, or says 'spawn target'

#

How is it unclear? Please explain what is unclear?

surreal hazel
#

Your explanation is clear

fathom pendant
#

I meant getting to the point we're at now without assistance

surreal hazel
#

The HTB explanation neglects a few key points

fathom pendant
#

It... It really doesn't

#

Spawn interactive instance and spawn target seem very different of a thing to me

#

I would suggest the Getting Started Module

#

To get you familiar with the platform if it was really that unclear

wild oar
#

hello i need a hint for the last nmap skill assessment 🙂

faint bobcat
#

@distant turret

heady tusk
heady tusk
silk minnow
#

Module: Windows Privilege Escalation
Section: Interacting with users

Question: Using the techniques in this section obtain the cleartext credentials for the SCCM_SVC user.

I've set up responder with the scf file placed in the open smb share but I am only able to get hashes from htb-student. I am not getting any hashes from SCCM_SVC

fringe shell
faint trellis
#

Hi!
What have I missed?
It returns the floowing:
`(gdb) b *0x5555555551b0
Note: breakpoint 22 also set at pc 0x5555555551b0.
Breakpoint 23 at 0x5555555551b0
(gdb) run
The program being debugged has been started already.
Start it from the beginning? (y or n) y
Starting program: /home/htb-student/octopus_checker
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".
Program had started..
Attempting Connection

Breakpoint 22, 0x00005555555551b0 in SQLDriverConnect@plt ()`

nocturne geyser
#

hi to everyone
can someone help me with a htb machine?
im so stucked on the scanning
i found someone vulnerabilities but i cant do nothing because i didnt find a exploit for they
thanks
(Sorry for my english level)

fringe shell
#

@nocturne geyser hello Gabriel, this is the thread for HTB academy, you might want to try the #boxes one for help with machines

flat minnow
#

Hello at https://academy.hackthebox.com/module/147/section/1639, I can't connect with RDP to the target machine. I get:
[13:27:11:307] [2170:2171] [ERROR][com.freerdp.core] - nla_recv_pdu:freerdp_set_last_error_ex ERRCONNECT_LOGON_FAILURE [0x00020014]
[13:27:11:307] [2170:2171] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail
[13:27:11:307] [2170:2171] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1

crimson walrus
#

I have a question about Active directory enum and attacks - Privileged access
The first 2 questions ask about another user who has the CanPSRemote right. However, the Cypher queries only show the user forend. The PS command Get-NetLocalGroupMember also only returns this user. I am sure there is something here that I am not getting. Maybe some default account who can PSRemote but I cant find it in the module itself. Can someone pls point me in the right direction?

iron coyote
#

@flat minnow did u put the password in single quotes?

fair hamlet
flat minnow
rustic sage
brisk tiger
#

I have a doubt in the module "WHITEBOX PENTESTING 101: COMMAND INJECTION"(https://academy.hackthebox.com/module/48/section/434) I completed all the exercises, they were very calm in the penultimate exercise, but it did not evolve because I passed something wrong in the body of the request, which must be the issue. The application in Node has two endpoints that receive JSON. Here are a few ways I've tried to pass code injection: curl http://localhost:21440/ifconfig -X POST -d '{"iface":"eth0\;ls"}' -H 'Content-Type: application/json'
curl http://localhost:21440/ifconfig -X POST -d '{"iface":"eth0\;ls"}' -H 'Content-Type: application/json'
curl http://localhost:21440/ifconfig -X POST -d '{"iface":"eth0%3Bls"}' -H 'Content-Type: application/json'

placid scaffold
#

Hello, if I subscribe to the Platinium offer for 1 month, I receive 1000 cubes from the first day of the subscription? Thank you.

worthy briar
#

Hello, anyone who finished the Attacking Thick Client Applications from Attacking Common Applications module could help me please. I followed every step. When i run strings64.exe on the dumped file the output its very different from the exercise:

||`PS C:\TOOLS\Strings> .\strings.exe C:\restart-service_00007FFBA2EE0000.bin

Strings v2.54 - Search for ANSI and Unicode strings in binary images.
Copyright (C) 1999-2021 Mark Russinovich
Sysinternals - www.sysinternals.com

wzW
L/Z
$I)B9
oleaut32.dll
advapi32.dll
ole32.dll`||

And running de4dot.exe:

||`PS C:> TOOLS\de4dot\de4dot.exe .\restart-service_00007FFBA2EE0000.bin

de4dot v3.1.41592.3405

WARNING: The file isn't a .NET PE file: C:\restart-service_00007FFBA2EE0000.bin`||

PS: I have no idea what i doing in this exercise, just following the steps. Open to DM!

placid scaffold
# acoustic owl Yes

Ok thanks, these subscriptions only give cubes right? No free access to any module?

slender steppe
#

Remote Code Execution (RCE) via the Theme Editor
Attacking the WordPress Backend

#

while adding php code its getting error

acoustic owl
acoustic owl
slender steppe
#

ohh

#

still there is error

placid scaffold
acoustic owl
deep owl
#

hello all, password attacks module, ......... section: Passwd, Shadow & Opasswd............ when trying to find the root password hash in rtc shadow i face will is not in the sudoers file

iron coyote
#

check wills directory more

spark iris
#

what is the diffrent betwee nthe blue and green collor in Ls -la?

silk minnow
#

help please 😦
Module: Windows Privilege Escalation
Section: Interacting with users

Question: Using the techniques in this section obtain the cleartext credentials for the SCCM_SVC user.

I've set up responder with the scf file placed in the open smb share but I am only able to get hashes from htb-student. I am not getting any hashes from SCCM_SVC

zinc marsh
#

If someone have any doubt about any module dm me 🙂

pseudo ledge
#

hey, I just did the Web Service & API Attacks - Skills Assessment and I managed to get a shell and then get the flag inside the shell but without using sqli, can someone pls help me understand what is the intended way to do this skills assessment?

rustic sage
summer lava
#

Please how do i solve this?

################################################################################
#                                  EyeWitness                                  #
################################################################################
#           FortyNorth Security - https://www.fortynorthsecurity.com           #
################################################################################

Starting Web Requests (7 Hosts)
Message: Can not connect to the Service geckodriver

Message: Can not connect to the Service geckodriver
serene spoke
#

Guys, I am working AD Enumeration and Attacks module on the Academy. The task is to do Kerberoasting attack and find hash of SAPService, crack it, then find what group in AD this user belongs to.

I confirmed cracked creds are valid with psexec. So, for the second part, I tried using rpcclient with anonymous login, and cannot find a way to see which group (and there's like 100 of them) contains user SAPService or his RID. I have used querygroup hex_id, querygroupmem hex_id and few groups pop up but they are not valid flag. Can anyone give me a nudge on this?

EDIT: Found it, || tool you use to request all tickets will show MemberOf column for each user. ||

zinc marsh
alpine crow
#

I can't able to get the answer, can anyone share what's wrong here

#

I did not get an error

#

Not getting the answer as well

naive wadi
#

is all the information to complete the question in the Oracle section contained within that module or do I have to look further afield?

alpine crow
#

Are you asking me?

rotund urchin
summer lava
#

Nah

summer lava
rotund urchin
#

eyewitness is hit or miss for me

naive wadi
proud cloak
#

Hi all, can you give me a little hint on this flag please... Find left behind cleartext credentials for the iamtheadministrator domain admin account (windows privilege escalation first flag)

#

it doesn't matter i found it

alpine crow
#

did anyone, completed the command injection module from HTB-Academy

rustic sage
#

hi noob's

vocal coral
#

@solemn slate hey can you check dm from me?

naive wadi
#

I can't figure out the oracle TNS section in footprinting, I am running the commands outlined with the tools but getting very little back. The other information online is pretty slim too, that I can find.

#

Does anyone have a hint?

#

Okay so worked now

#

odat is temperamental it seems

rustic sage
low tusk
#

Hey guys

fathom pendant
#

Nvm didn't see you got it. Discord split your messages

lethal shard
#

Could anyone help with HTTP Attacks Module?

Try to use what you learned in this section to steal the admin user's cookie via XSS. CRLF Section Http Response Splitting

Trying to document.location to the /?admin page to read log with cookie

rustic sage
#

hi, so with the Student monthly subscription plan I can access all modules up to tier 2 for 7$ if I'm a student so all the 28 modules for CPTS path will be accessible right?

fathom pendant
#

Yes

rustic sage
#

so normally I'd have to pay 116$ for 1000 cubes to be able to unlock all the 28 modules which in total cost 1970 cubes for the pentester job role path?

fathom pendant
#

The cost is estimated and doesn't calculate the cube refunds of completing modules

rustic sage
#

Yes

#

but still it's estimatedly 13x cheaper for students to purchase modules compared to not students LOL

fathom pendant
#

Well yeah

#

Most students are in crippling debt already for their studies

rustic geyser
#

doing module 54 fuzzing with ffuf, and it requires you to fuff the public htb site for the store, but twice now it has blacklisted my connection very early in the scan.

solar zodiac
thorn urchin
rustic geyser
#

ffuf -w /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -u http://FUZZ.hackthebox.eu <<< thats not the command i was supposed to use?

thorn urchin
#

yeah that looks reasonable (though should be https), not sure why youd be blacklisted then

#

try it from the pwnbox if you havnt, might be more trusted

rustic geyser
#

yeah strangely it just did the exact same thing for skills assessment box, connected via vpn runs ffuf fine for enumerating directories and php params but i try to check for subdomains and it crashed the scan 40 words in.

thorn urchin
#

that suggests it may be a different issue

rustic geyser
#

tried again, got back into the VPN and refreshed the assessment box to a new one. basic command ffuf -w wordlist:FUZZ -u FUZZ.academy.htb:PORT , and it get exactly 40 words in before it starts counting the errors and get to around 700 words and it drops down to a crawl. Try to open the machines webpage no route, and no outside access till i disconnect from vpn.

#

exact same command works fine via pwnbox, which is very annoying i dont have vip so limited uses and i prefer to use my VM.

dull vortex
#

Can I dm someone about the Password Attacks, Reuse/Default Passwords section? I have all the potential users and the passwords that were possible, and it is still not working? I am at the point where I am wondering if something is wrong with my browser.

barren robin
#

I have noticed that when it comes to DNS stuff. The pwnbox will work when a VPN connection just fails or gives the worng results

fathom pendant
#

But the one directly in the repo

dull vortex
#

ahh I was looking at the updated one I think... I was losing my mind lol

fathom pendant
#

I did the same

dull vortex
#

how do I find the not updated version, all I see is the "update default creds cheat sheet.csv"

rustic geyser
#

meh i got excited over nothing, the pwnbox doesnt get disconnected during the scan like my VM, but it still only gets 40 words into DNS/Vhost Fuzzing before it starts catching errors on all words. looks like i wont be able to finish this module.

fathom pendant
#

Sec

dull vortex
#

thank god... I have been stuck on that for days...

#

thanks

fathom pendant
#

Remember it's just MySQL creds you're looking for

#

So there's only like 4

dull vortex
#

I had the wrong usernames the whole time

fathom pendant
#

:)

dull vortex
#

Some of this module is fun, and then other parts... meh

dapper star
#

Hey guys, I'm at this question right now in PasswordAttacks:
Examine the target and find out the password of the user Will. Then, submit the password as the answer.

And I can't get further... Tried using a mutated list of passwords from the one in the tip (both custom_rule from the zip and best64), normall password list, both users,... tried SSH, FTP, SMB,... Anyone that can help?

rustic sage
#

hi, I have a question about hackthebox academy subscriptions, once I buy the subscription plan does it expire 30 days after the purchase or does it work differently?

fathom pendant
fathom pendant
thorn urchin
#

its a bummer to not be able to complete it the proper way cause of infra changes but you can still finish the module anyways

#

you clearly understand the concept and what to do, just being cockblocked by htb site

rustic sage
#

That was my exact question

dapper star
fathom pendant
#

Iirc it's roughly 4 weeks or 30 days (looking at you February for fucking shit up)

simple zephyr
fathom pendant
fathom pendant
rustic sage
#

"Next, add a DNS Server such as 1.1.1.1 to the /etc/resolv.conf file. We will target the domain inlanefreight.com, the website for a fictional freight and logistics company."
How would an example of this look like in the resolve file?

fathom pendant
rustic sage
#

but in order to fuzz the subdomain i have to add it somewhere? like in the etc/hosts?

fathom pendant
rustic sage
#

ohhh

fathom pendant
#

It doesn't need to go in your etc hosts file

#

The hosts file is just for resolving internal domains

rustic sage
#

but then how do i run a subdomain fuzz for a ip

#

adding it in the etc/hosts file, right?

fathom pendant
#

No

autumn pilot
#

for this exercise you are not required to do subdomain fuzz

fathom pendant
#

^

rustic sage
#

oh

autumn pilot
#

just visit the IP address, and go from there

rustic sage
#

i reviewed the source code, fuzzed dirs, whatwebbed, robots.txt but cant find the flag

autumn pilot
#

well, you are on a good track, however, read carefully

rustic sage
#

hmmmm

#

could you maybe give a hint? i tried everything the module learned me so far

autumn pilot
#

the hint is to read carefully

rustic sage
#

what am i missing? 🙂 i read everything twice but i tried everything

#

ohh

#

...

#

but the head was empty? doesn't the robots.txt have to be in there?

rustic sage
heady geyser
#

have a question on password attacks/PTH section. I solved the final question where it was asking us to reverse shell with julio. i started to wonder if i could use davids hash to do the same reverse shell but it didnt work. So i'm thinking that David doesnt have access to DC01. My question is, how do i quickly determine which accounts do or dont have access to DC01. Is there something in the mimikatz hash dump that would have clued me into knowing that Julio has access but David doesnt? Thanks.

fathom pendant
#

Iirc something with mimikatz should tell you, can't recall what though

tender lake
#

I've just completed the Footprinting Labs, and I feel that the Hard and Medium should swap places. Medium kicked my but

#

but I did learn a bunch.

lunar wing
#

Working on using ffuf for parameter fuzzing and am getting only errors from ffuf. I added the Ip address without port to /etc/hosts but ffuf just tells me there's errors for every scan.

Any and all help appreciated.

fathom pendant
hidden spruce
#

is there a specific place i should go with help or questions for the labs?

lunar wing
#

Ok, so no errors this time but absolutely no results or output.

fathom pendant
fathom pendant
lunar wing
#

I actually don't know what size to filter for. I was using numbers from 0-1000 there and getting the same results.

#

I just noticed that apparently I shouldn't have the admin/admin.php at the end of the ip address, which is EXTREMELY confusing since the first thing that particular page says is "we discover an admin/admin.php page" and I logically assume that needs to be part of what I'm fuzzing for.

either way, I got the scan to work, but the size for everything is 986

hidden spruce
#

I'm doing the documenation and reporting practice lab for the pentesting path, it is asking me to get the contents of flag.txt on the DC01 desktop. I was able to connect to an administrator desktop at 172.16.5.130 and another user at 172.16.5.200 but am not finding what i need. Ive also tried to run the Get-ADUser command and it just won't work. Am i going in the right direction?

#

I've also had problems attempting to crack the hashes supplied in the obsidian notes. Every time I attempt to crack it with hashcat, it tells me that my seperator is unmatched. It is a NTLMv2 hash so my command looks as follows: hashcat -m 5600 /home/htb-student/plaintext.txt /usr/share/wordlists/rockyou.txt

lunar wing
#

so in the previous example, I had to use the ip address..

#

In THIS one, I have to use admin.academy.htb.

I feel like what I'm supposed to be doing in these modules is never ever clear.

#

like, what am I missing that indicates whether I should be using an IP or URL in these. Also, shouldn't the results be the same???

unique valve
#

@lunar wing Sometimes a webserver can be hosting multiple websites on the same IP address but utilizing different domain names for each website. This is why sometimes you must use different domain names (admin.academy.htb is a sub domain) to reach different target websites. I recommend you continue studying DNS basics and DNS enumeration.

lunar wing
# unique valve <@1086284318248284160> Sometimes a webserver can be hosting multiple websites on...

Thanks for the reply. I am on HTB Academy to try and learn these, but I constantly feel like I'm lacking something I can't get from these modules: background information on networks, protocol, etc. I'm in the basic toolset path, which I thought was the place to start, but I guess I'm in the wrong one?

I've done codecademy modules about networks, hacking, and network essentials, but I still don't have the knowledge I need. Any and all resources to go and learn (I already have HTB Academy, HTB Labs, and Codecademy) would really be appreciated.

unique valve
# lunar wing Thanks for the reply. I am on HTB Academy to try and learn these, but I constant...

No worries this is a process. The challenges you run into in the modules are most certainly going to help you spot areas for growth. None of us know everything and we all have room to learn. If you consider yourself an absolute beginner I recommend you start with the Information Security Foundations path on HTB Academy but keep doing what you are doing by reaching out here in the Discord. https://academy.hackthebox.com/path/preview/information-security-foundations

#

What module are you stuck on now?

iron coyote
#

its sort of a whole different skillset doing things practically and learning the theory of it

#

also is there a fix for this or do I reset lol

#

C:\tools>Rubeus.exe ptt /ticket:julio.kirbi
[*] Action: Import Ticket
[X] Error 1398 running LsaLookupAuthenticationPackage (ProtocalStatus): There is a time and/or date difference between the client and server

fathom pendant
#

Reset maybe

lunar wing
#

Thanks so much for the help and guidance.

unique valve
simple zephyr
unique valve
red current
#

Anyone have any tips or suggestions for the last question in the Attack Tuning section of SQLMap Essentials? I've been stuck on this for a couple of days and none of my attempts result in the flag.

obtuse verge
#

Hi!! Im having problems connecting to an Hack the Box machine, in 'LLMNR/NBT-NS Poisoning - from Windows' from the Active Directory Enumeration & Attacks. Either xfreerdp(xfreerdp /v:IP/u:htb-student /p:Academy_student_AD!) or rdesktop(rdesktop -u 'htb-student' IP -p 'Academy_student_AD!') is not working(im connected to the VPN)... Can someone help me?

storm skiff
#

I'm trying to figure out the foothold for the File Upload Attacks Skills Assessment. I'm completely lost. Anyone available for a DM?

wooden rapids
#

hey team, im currently on the pivoting and tunneling skills assessment and trying to ping sweep on the pivot host with msf and im getting spammed out with this error, does anyone know a way round this?

warm dagger
#

Can I get some help on AD Enumeration & Attacks - Skills Assessment Part II?
Question 6 : Locate a configuration file containing an MSSQL connection string. What is the password for the user listed in this file? - can't seem to locate it i've enumerated M*** and S**** and even the DC, but no love... onionthink

red current
wooden rapids
red current
fathom pendant
#

What module are you doing?

swift forge
#

Beginner question: when I am trying to setup a reverse shell, is the IP address that I'm entering in the bash commands my IP or the target IP?

small sage
#

Hello, stuck on Attacking Common Services - hard lab
on the final question, I'm logged into MSSQL as Fiona, impersonating John and trying to send commands to the linked server but unable to make much progress from here, any tips?

figured it out, I'm dumb

fathom pendant
swift forge
fathom pendant
fathom pendant
swift forge
# fathom pendant What module are you doing?

I'm on the Privilege Escalation lesson of Getting Started. I think I just realized the problem, I'm trying to send the reverse shell from myself to myself, I need to use an exploit to gain control of the target first right?

fathom pendant
#

And what does your revshell command look like {put the command between backticks `}

rustic sage
#

türk varmı

steady matrix
#

Hi everyone, I'm on the "AD Enumeration & Attacks - Skills Assessment Part I" and trying to use BloodHound, without success. I have tried using the sharphound.exe injestor from the Parrot box, occasionally the .ps1, tried using the latest sharphound.exe from github, tried using the version installed on my machine, still getting "bloodhound file created from incompatible collector". What am I doing wrong?

#

Also tried using the v4.0.3 as suggested here in a few channels, no success either.

steady hawk
steady matrix
#

I did try, I'm probably doing something wrong but I didn't have any issue during the course itself with the provided BH and SH

steady matrix
#

Alright, if that can help anyone else, turns out the zip archive was the webshell and not the file, submitting just the filename and clicking the download button downloads the HTML page instead, so it needs the full path.

surreal hazel
#

Ty. It’s been a while since I finished setting things up, but I’m finding helpful posts here that answer my questions. Things have been going smoother since I started SSHing directly from my computer (while on HTB’s VPN) instead of from the virtual instance

glacial hazel
#

VM is de wey

mellow sundial
#

a

surreal hazel
#

Sometimes the wording of the submitted questions throws me for a loop.

There was one about finding “listening services” but the wording of the task included the confusing phrase “Not on localhost and IPv4 only.” Is “not” modifying the phrase “on localhost and IPv4”?” Or should it be read as “include IPv4 and exclude localhost?” If the latter, Why not just phrase the task as “How many services are listening on the target system on all interfaces? (only IPv4)?” This implies that all non-IPv4 are excluded (including localhost and IPv6)

#

I just spent a semester symbolizing English sentences into first and second order predicate calculus, so I’m fairly rigorous in my parsing of the logical structure of sentences

red current
#

I'm working on the SQLMap Essentials module and running into an issue with the Advanced Database Enumeration section. The first question regarding getting the column containing "style". I've run every possible iteration of the --schema switch in the command and it either times out due to the 89 minutes running out, or it just gives an error that nothing injectable was found. Anyone have any hints on this one?

#

My current command looks like this sqlmap -u "http://IP_Address:PORT/?id=1" --schema --dbms=mysql --level=5 --risk=3 --random-agent

little bear
#

are you SQL querying? What does the tool you're using do?

#

(g2g, but read your stderr, if any, or use --verbose or equivilent)

#

I ran into a Constraint violation due to a \ instead of a / in WinAD Enum

red current
little bear
#

I duno, I'm just a guy. Try modifying your command w/ args. or man sqlmap if avail

zinc sentinel
#

Command 💉 defeated ✅️
Quiet the adventure..
Could spend days finding the right command string to use

cinder edge
#

wh[ Error writing /etc/hosts: Permission denied ]

#

when am trying to save my nano file iam getting error

#

[ Error writing /etc/hosts: Permission denied ]

green birch
#

I have seen that I have different accounts for academy and app. Was it better when I have only one Account?

little bear
#

Permission Denied. Are you root?

#

@cinder edge

cinder edge
#

No that time I am not in root after I tryed in sodu

thorn ingot
#

I’m facing a problem with the burp intruder question in “using web proxies” module

#

I’ve found the flag in /admin/*.html but It’s somehow wrong

#

nvm it was just a stupid space at the beginning of the answer

warm dagger
wicked crescent
#

Im at the final section of the getting started module for the red teaming. But I can’t figure out the privilege exclamation. I don’t want to solution just a slight hint, Ive used the scripts but they Dont rly help me, I found the sudo -l thing but that points to a symlink which I can’t seem to modify in any way

rotund sphinx
#

hi, is anyone able to give a hint for Footprinting Lab - Hard

there are a couple of services that i cant get any response out of but then all the main ones that i can interact with seem to require credentials which i dont have

should i be trying to bruteforce one of the known services? digging deeper into the mystery UDP ports, or have i just missed something 😦

been banging my head against this for hours

quick rain
#

||hey wsp yall||

sonic seal
#

Hello! How can I privilege escalation if the user is on sudo group but I don't have password? Any tip?

wicked crescent
#

NVM I GOT IT MYSELF

zinc sentinel
lunar harness
#

im currently stuck at linux privilege escalation skill assessment, if someone done it recently and can give me a hint will be appretiated. im on fourth flag,

near hinge
#

hi, i'm currently learning Containerization module on Linux Fundamentals, and i'm trying to run this script but why did i get this result?

pine dagger
#

Because you're not meant to use "bash" to run the dockerfile

#

You use docker run to use a dockerfile

native osprey
#

helolo

native osprey
pine dagger
#

Yeah I was replying to peepsqueak

acoustic owl
#

<@&861185840277487616>

silver seal
#

fr totally non-suspicious link.

#

Ah! I forgot what to ask ..

#

lemme THINK

#

yeah found it ..

#

what are some basic things for me to get into hacking?

#

I already know coding in some languages.

#

Anyone? ||UwU||

acoustic owl
silver seal
near hinge
odd notch
#

Hi, when using hashcat I get driver erros for opencl (I don't have it installed) but when I use the opencl-mesa I get a warning it's unstable, and when I --force, well,, computer kinda hangs. I got a 7700 with 16g ddr5 if that helps. any ideas?

#

scrap that

#

I used the pocl package and it works flawlessly

#

open source ftw

pine dagger
outer steeple
#

When doing the "Try to access the emails on the IMAP server and submit the flag", without using ||an email client like evolution|| what would the appropriate command be using ||openssl||? I listed out the directory contents, but unsure how I would have connected to the folder ||dev.department.int||. I got the flag but only by utilizing a ||gui mail client||

odd notch
#

So I'm doing the hashcat part in the IPMI foorprinting module. it says it will take 1 day to go over everything... I am willing to wait, but I doubt that was the intention. did I missosmething?

slender steppe
#

Skills Assessment - WordPress Obtain a shell on the system and submit the contents of the flag in the /home/erika directory.

#

i found the etc/passwd file through LFI

#

but not able to make other cmd

odd notch
#

afaik you must do all the modules in order to do the test

#

it's written with the sub

#

check for yourself I don't fully remember

#

any suggestions to my question?

proud pine
# odd notch any suggestions to my question?

Most of the password-cracking in the academy has the password near the beginning of rockyou.txt. If it takes longer than 5 minutes, you probably have something wrong. This is only really not true in the password mutation section of the password attacks module.

odd notch
#

So I should use a list with hashcat?

#

is that a thing?

rustic sage
#

hi, can I connect to the hackthebox academy VPN and pwn the boxes through a VM or do I have to use the browser instance in module Getting Started and section Public exploits? there's no vpn file to download.

proud pine
queen hatch
# odd notch So I should use a list with hashcat?

Yes. I'm not sure what OS / VM you're using. But as @proud pine stated, most HTB crackable content can be done with the rockyou.txt list.

If you're using a distro like Parrot or Kali, you can probably find rockyou.txt with locate rockyou.txt.

If not, its in this repo https://github.com/danielmiessler/SecLists

Specially here (you'll have to unzip it): https://github.com/danielmiessler/SecLists/blob/master/Passwords/Leaked-Databases/rockyou.txt.tar.gz

odd notch
#

So the hashcat mention is purly... academic?

rustic sage
fathom pendant
#

Public exploit is like that on purpose

rustic sage
#

I tried with tcp vpn connection file too

fathom pendant
#

You're meant to enumerate it a different way than nmap

vagrant gust
#

how would i find out what ip to connect to my ftp server

#

is it eth0

rustic sage
#

I couldn't connect to web enumeration section too

fathom pendant
rustic sage
#

y

fathom pendant
#

And using other web enum techniques> your format would include the port

fathom jasper
#

i just started academy, and I'm working on the kerberos module... what is up with all of the disconnects from the web terminal to the rdp session? I continually lose connections to it for the constrained delegation module, and it feels like something htb is aware of because there's a note of "If you lose connection to the machine, try again in 2 or 3 minutes." I keep a connection for around 45 seconds and then it disconnects...

swift forge
#

Quick question regarding the Public Exploit lesson on Getting Started: I'm practicing the process and am trying to connect the page of the target to identify plug-in, but everyway that I can think of viewing the page I get a connection time out. Any thoughts on what I may be doing wrong/

fathom pendant
fathom pendant
#

It should give you a (public) ip along with a port

swift forge
boreal topaz
#

ye

fathom jasper
fathom pendant
#

Yes and you WILL encounter errors if you have both pwnbox and VM connected to VPN

rustic sage