#modules

1 messages · Page 82 of 1

rustic sage
#

But I get connection timed out when I try to nmap scan or ping it

fathom pendant
rustic sage
fathom pendant
#

You're not meant to be able to ping or nmap the target in "public exploits" from Getting Started

#

You're meant to use the web enumeration techniques

rustic sage
#

I need to pwn the box and submit the flag and I need to access the machine so you want me to do it without being able to connect to the vpn?

dim light
#

hey guys
in "Service Authentication Brute Forcing" part of "LOGIN BRUTE FORCING" module i can't gain the flag
i brute force with user "b.gates" and Password list "William.txt" that made by "cupp" script but it doesn't work
anybody can help me :_) ?

fathom pendant
#

Use the techniques referenced in the section to enumerate

dim light
#
 Using what you learned in this section, try to brute force the SSH login of the user "b.gates" in the target server shown above. Then try to SSH into the server. You should find a flag in the home dir. What is the content of the flag?
red current
dim light
#

i used hydra for get password

#

the question say username for ssh login is "b.gates"

red current
# dim light can i DM you?

Sure, I'm actually at work right now but I have my notes with me on this module. You really should just need to follow the steps outlined in this section.

wraith delta
dim light
wraith delta
#

ok

swift forge
#

I'm trying to do an enumeration for the "Privilege Escalation" lesson of Getting Started and whenever I try to run an enumeration I'm getting an error

#

Anyone can help?

#

I'm basically trying to find the exploit that would allow me to create a reverse shell but I can't figure it out

swift forge
fathom pendant
#

Sir you haven't even gotten the foothold

#

That sudo -l is on your own machine

swift forge
fathom pendant
#

So you did an nmap scan on the target IP?

#

That is the 10.x.x.x IP?

swift forge
#

No that IP is my own, the target is 134.x.x.x

fathom pendant
#

Oh

#

Then nmap isn't going to help you

#

It's a public ip

fathom pendant
#

Familiarize yourself with the private range prefixes so you can easily determine things :)

limber wasp
#

Ive got a question. Im doing the Responder box in tier 1 starting point, You have to add the ip address to ur /etc/hosts file for it load unika.htb. yesterday i got it to work. but then i got stuck trying to get responder to pick up anything. today everytime i go to the ip address it cant find page. on this particular one they give you an IP address instead of <target ip> Am i supposed to use the ip adress givven or the one i get when i spawn the box?

fathom pendant
swift forge
fathom pendant
#

You may be able to run exploits if you search hard enough for certain plugins that are on the webserver

#

You are on the Nibbles - PrivEsc part or the Knowledge check?

vagrant gust
#

getting command not found this is for the file transfer module and the windows file transfer section

swift forge
fathom pendant
#

You're on your own pwnbox

vagrant gust
#

it says the rdp to the box

#

which i assume is the pwnbox

fathom pendant
vagrant gust
#

ive unzipped it on that

fathom pendant
fickle nacelle
#

HI.....im having trouble with two questions on the footprinting dns portion What is the FQDN of the host where the last octet ends with "x.x.x.203"? and Interact with the target DNS using its IP address and enumerate the FQDN of it for the "inlanefreight.htb" domain I have tried using different wordlists like Jhaddix, fierce and using smalling wordlists. still no luck what am i missing?

fathom pendant
#

Whenever it talks about RDP/ssh into anything it's referring to the target

swift forge
fathom pendant
#

Pwnbox is an attack machine that's an alternative to setting up your own vm

vagrant gust
#

and upload the file

fathom pendant
vagrant gust
#

then it says to rdp to the box

#

i assumed thats another box

fathom pendant
vagrant gust
#

ohhhhh

#

ffs

fathom pendant
#

Pwnbox is never actually needed

#

Always assume it's referring to target

#

If it doesn't give an IP then you may need to spawn target.

#

They'll generally use the terms; server,box,target

#

To refer to the target or initial jump host (for pivoting)

vagrant gust
#

fair

swift forge
fathom pendant
#

Nope

#

Ssh is a tool that's already installed

rustic sage
#

openssh is the package for ssh

fathom pendant
#

Syntax: ssh <username>@IP

#

Note * remove the brackets

fathom pendant
#

As most tier1+ modules assume a previous working knowledge of Linux

#

And basic tools/commands

storm skiff
#

Hey guys, I'm doing the Login Brute Forcing Skills Assessment and on the very last question. I ran ||netstat ||and don't see|| ftp open just port 80||, which was the case when I was doing the Service Authentication Brute Forcing section. I checked the ||other home directory|| and have that ||username|| part of the puzzle. The hint says to|| use the wordlist on your home directory||, which is the second piece of the puzzle. What am I missing?

red current
storm skiff
red current
storm skiff
vagrant gust
#

the file i got was 0 length for the windows file transfer

red current
acoustic sparrow
#

finished the windows file transfer yesterday

storm skiff
# red current Yes, that's possible. I had a similar issue if I recall when I was doing this as...

Figured this out...for anyone stuck on this question, the hint gives you the answer, but the brute forcing process takes a very long time even with the -t 4 switch. It took well over 30 minutes for me and timed out a few times in earlier attempts. I think this section of the module needs to be edited so it doesn't take so long. That was disappointing. Other than that it was a good module.

rustic sage
#

anyone stuck at ACL Abuse Tactics? I always get 'unable to find user damundsen' when trying to execute Set-DomainUserPassword command

zinc marsh
#

what can i do if my vm crashed lol

fathom pendant
#

Cry

zinc marsh
#

i restarted the machine and i cannot even log in now

fathom pendant
#

Oof

zinc marsh
#

fuck ffuf 😢

fathom pendant
#

What happened with your VM?

zinc marsh
#

idk

#

was using ffuf to complete the module

#

i couldnt desactivate the proxy and restarted the machine

fathom pendant
#

F

zinc marsh
#

with this video

fathom pendant
#

Ohhh it broke the gui

#

Which you just have to reinitialize

sweet roost
#

fu** this men fu** this😭 😩

dull vortex
#

Trying to get Lazagne.py working on linux, and I keep getting errors as such:

red current
#

I know I've asked this before, but so far I haven't been able to get any help. I'm in the Advanced Database Enumeration section in SQLMap Essentials and having an issue getting the first answer. It's asking what's the name of the column containing "style" in it's name? (Case #1) Does anyone have any hints or clues for this?

dull vortex
#

I am not sure if I have done something wrong during installation, but I am at a dead end rn and would appreciate any help

#

I directly copied the source code

red current
zinc marsh
#

isnt that finished?

fathom pendant
#

Most of the boxes use and have python 2.7

zinc marsh
#

but i dont remember which

fathom pendant
#

And some of the tools haven't been update to work with 3.x

dull vortex
#

I have tried to update python and also install 2.7

fathom pendant
#

Probably the password attacks module with the <filetype>2john

dull vortex
#

the Password attacks module shows both 2.7 and 3 being used

zinc marsh
#

How long is it till the sunset date? The sunset date has now passed; it was January 1st, 2020. What happens now? As of January 1st, 2020 no new bug reports, fixes, or changes will be made to Python 2, and Python 2 is no longer supported.

fathom pendant
#

Some of the 2johns are in 2.7

dull vortex
#

its the Credential Hunting in linux section

zinc marsh
dull vortex
#

is the tool absolutely neccessary?

fathom pendant
#

¯_(ツ)_/¯

red current
fathom pendant
zinc marsh
dull vortex
#

Password Attacks, Credential Hunting in Linux, with lazagne.py

zinc marsh
#

oh i remember that

dull vortex
#

I am trying to run it on my own VM currently, is that even neccessary?

fathom pendant
#

No

#

It's like linpeas

zinc marsh
#

i couldnt run it with python2.7 the lazagne.py i think

fathom pendant
#

You should be running it on the system that you're exploiting

#

It's possible yeah I just never cared enough to try harder xD

dull vortex
#

I was just doing it to test it out prior the exercises

zinc marsh
#

at least when i did it

dull vortex
#

spinning up the target now

fathom pendant
#

I was gonna say there's no harm

#

Iirc it's just an enum tool

zinc marsh
#

i was using Ubuntu when i did it

#

the last version

dull vortex
#

I have been having a lot of issues with the PW Attacks module... I am also trying to work out pypykatz, but I am going to circle back to that one at the end

zinc marsh
#

@fathom pendant is there any command to empty a file

#

without deleting it?

fathom pendant
#

You can maybe do echo "" > file.extension

zinc marsh
#

make sense lol

#

i did truncate 0 /path

fathom pendant
#

Or

#

Iirc you can echo file > file

#

Er cat file > file

#

Iirc that breaks

#

And voids it

red current
#

I know I've asked this before, but so far I haven't been able to get any help. I'm in the Advanced Database Enumeration section in SQLMap Essentials and having an issue getting the first answer. It's asking what's the name of the column containing "style" in it's name? (Case #1) Does anyone have any hints or clues for this? I also for some reason keep getting HTTP error codes detected during run 400 (Bad Request). I'm using the --schema switch and so many others like --risk, --level, --random-agent, --no-cast, --batch --dump, --dbms=mysql ... etc. I just can't seem to get this one no matter what I try.

zinc kettle
#

who here is good at hacking

#

i need help hacking into my old account

#

?

#

?

red current
zinc kettle
#

where is general

fathom pendant
dense shale
#

is their a way to uncap googles 60 fps cap useing a script preferably javascript ?

zinc kettle
#

where fo i contact support

fathom pendant
fathom pendant
fathom pendant
dense shale
#

ugg i just need help ;-;

fathom pendant
#

Well if you look at welcome it shows you other channels you'll have access to once you verify your htb account following the instructions there

dense shale
#

i am verified :/

fathom pendant
red current
#

Never mind about my sqlmap question. I think there was an issue with the instance. I got it, finally.

fathom pendant
#

That happens on occasion

limber river
#

any hint for SQLMap skill assessment , I found a db but it seems like empty

weak charm
#

Is the file inclusion final assessment broken

#

@limber river make sure to tamper

limber river
weak charm
#

Let me know! You can PM me

thorn urchin
#

had to restart like 30 times debugging some payloads

limber river
#

thanks a lot

odd notch
#

So I'm at the east lab of the footprinting, they ask for flag.txt but I don't see no DNS TXT records of it. there are serveral IP's but all are unreachable. I don't know if it's a problem on the machine part... or maybe I just don't know what to look for.

rapid ember
#

Hey! Someone can give a me a tip on the sql essentials module, more specific on the case 9 ?

#

When i try to run it, it gives a bunch of random URI that doesnt work

weak charm
weak charm
rapid ember
weak charm
zinc marsh
#

is there any option to show only the results with ffuf

#

i get too much trash in the screen

wicked crescent
#

im in the Widnows fundamental thing but i get "do_connect: Connection to 10.129.203.195 failed (Error NT_STATUS_IO_TIMEOUT)" when trying to use smbclient

im on NTFS vs. Share Permissions

rustic sage
#

do you know some the most recent/up to date blogs related to: retired HTB boxes, write-ups on recent exploits/attacks, Active Directory exploitation techniques, CTF event write-ups, bug bounty report write-ups sites etc.

thorn urchin
wicked crescent
#

Online Ive read stuff about the firewall but the section doesn’t mention that at all

tough kindle
#

Hello. Im stuck on the footprinting lab Medium. I would appreciate any help. Please DM me if you can offer any help. Currently, I mounted the NFS and logged in as alex in the RDP port but I can't access the database and I can't log in using the user sa.

acoustic owl
zinc marsh
#

@acoustic owl can i ask u about the ffuf module?

zinc marsh
#

i know that the value i have to do is ||id=FUZZ||

#

i created a list with 1000 of them but no luck, now i created one with 100000 and nothing either

acoustic owl
#

A list with 1000 entries should be enough

surreal hazel
#

I can’t spawn an instance of pwnbox. Can all the submitted exercises be completed using the Parrot OS HTB pwnbox in a VM?

acoustic owl
red current
#

Is there anyone available to assist with the Bypassing Web Application Protections section in SQLMap Essentials? None of this makes any sense and I can't even get the first question answered.

thorn urchin
acoustic owl
#

Did you specify the CSRF token name?

red current
green birch
#

Have I asked this in another Channel?

red current
odd notch
fickle nacelle
#

can anyone here help me real quick with the dns section in footprinting? SO If i cannot perform a zone transfer I a assuming I have to brute force the sub domain but every time I try to brute force it with fierce it takes forever to load then times out. What should I do?

acoustic owl
acoustic owl
fickle nacelle
# acoustic owl You have to find all the zones first. Once you have found all the zones, you can...

SO I did a dig axfr with the target ip and I see the same sub domains as when I brute forced it. I cannot dig all the sub domains as it says transfer denied or connection timed out. Can I get a hint please what am I missing. I am trying to answer these two questions What is the FQDN of the host where the last octet ends with "x.x.x.203"? and Interact with the target DNS using its IP address and enumerate the FQDN of it for the "inlanefreight.htb" domain.

green birch
acoustic owl
acoustic owl
fathom pendant
#

It's a subdomain of a subdomain though

#

a.b.inlanefreight.htb

fickle nacelle
fathom pendant
#

For instance the command will have b.inlanefreight.htb using the automated tool

#

I've seen some people's subdomain list missing the proper subdomain to brute into

acoustic owl
fickle nacelle
fathom pendant
#

Hey payload I have an idea how the automated tool works but can I dm you to see if I'm right (not at my computer to actually look at it)

acoustic owl
#

I am currently not at the computer either. But yeah sure, send me a DM

#

I like to look at it this afternoon

odd notch
#

I'm in the middle of doing the easy lab of the footprinting module. I did the nmap scan and discovered || ftp.int.inlanefreight.htb || but I don't have any credentials and || anonymous login seems to be disabled ||, however, I did not discover it with || dig axfr inlanefreight.htb @rustic sage || which leads me to think the || DNS server is hiding some domains||, but no mutter what list I used it doesn't seem to work. any ideas?

odd notch
#

yes

red current
odd notch
#

|| -sS -sV -sC ||

#

🙃

#

Oh and || -Pn ||

odd notch
#

OMFG

#

I don't care... the Hint has credentials in it. that's dumb af.

red current
# odd notch Anything?

Oh, right. Yeah, I thought that was kind of dumb as well. you really can't get anywhere without the hint.

odd notch
#

weird. maybe there is but very few has found it? still

#

I fucking can't with this unstable boxes.. either they block you way too early or they are just borked. I rather download them and do this offline if I can.

fringe shell
fathom pendant
fathom pendant
# odd notch Ye

Guess what happens when you connect to the alternative port. (It's in the banner)

odd notch
#

I dunno... But one bad login attempt and I'm locked out

#

Dude I just can't with this... the box is fucked. I even restarted the box it still gives me || permission denied public key || but it let me the first time I try. and then bamm, donezo.

#

is there any techsupport regrading these? this can't be expected behavior

autumn pilot
#

well, if you are not giving the proper permission on the file it will always throw out the permission denied publickey error

odd notch
#

I don't have a file. I tried enumerating for hosts to get it from but every single host returns "out of reach". I just tried to login with the credentials.

autumn pilot
#

also there is a service running on non-default port

odd notch
#

Yes.

odd notch
autumn pilot
#

play around and you will find out

odd notch
#

I have

#

That's what i found

autumn pilot
#

and feel free to check the hint for the exercise

odd notch
#

I did

#

That's the credentials we talked about earlier

misty current
#

In the Password Attacks - Hard Lab, I can see there's a .vhd file. I can only run as the dav** user with runas and can't take any other session. Should we download this to the local and mount it? It's a big file and trying to download it failed just now and I'm wondering if It's my network issue and I should try again

autumn pilot
#

nothing stops you from following that logic

#

it might be helpful

odd notch
#

I tried using the credentials in the hint to login to the ftp server || both 21 and 2121 || to no success, i noticed the.url does shows a subdomain || ftp.int.inlanerfreight.htb || but enumerating that gave nothing. As well as all hosts discoveres in || dig axfr inlanefreight.htb @{IP} || . I exaustes my attack serfuce.

#

I have no idea what else to do

autumn pilot
#

the credentials are not an issue, all I'm going to say is that they are valid

#

and there is no need to enumerate any kind of subdomains or domains

odd notch
#

That's weird... Because the "story" here is that we are asked to enumerate the DNS server. So i figured it's part of the exercise

#

I dunno... Am i supposed to get a file somewhere?

autumn pilot
#

yes

dapper star
#

Can I DM someone about Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt. it's in Password Attacks Pass the Hash

misty current
autumn pilot
#

well, I have given you a hint, so there is no need open a thread

misty current
autumn pilot
#

yup, so go for it

misty current
dapper star
misty current
#

Like, why I wasn't able to explore the share when I logged in as Julio user but I was able to when I opened a cmd with pth for julio

misty current
# autumn pilot yup, so go for it

I got the full file downloaded, I tried using a different file transfer method this time rather than winrm download. Not sure if the issue was with my network or winrm.

#

Thanks tho

odd notch
# autumn pilot yes

Do i get the file before using the credentials? Do i get it from the same host?

autumn pilot
#

🤷‍♂️

odd notch
#

I tried going over all the services... All give access denied

#

I'm not learning anything new or excercising something I learned a tthis point. I'm looking for solutions online...

autumn pilot
#

taking breaks usually helps

odd notch
#

I took 3 breaks at this point.

#

there... fixed

willow sonnet
#

is there something wrong with the instances lately. Im doing attacking common services and it takes me 3-5 restarts of the instance for it to even work properly

rustic sage
#

Module Introduction to Windows command line Command to start Windows Defender Service is Start-Service -Name WinDefend and hackthebox refuses it

odd notch
# autumn pilot taking breaks usually helps

there is NO WAY I would have thought of doing that without outside help... there are too many possiblities and the fact you || can't login striaght up with the credentials || is a huge throwoff.

odd notch
#

Ok now what does a proxy FTP server intail? I searched online I couldn't find any good explanation

fervent owl
#

Hey guys is there a way to make an android game play on itself using any script

#

Like it farms on itslef

#

No use of fingers

odd notch
#

Maybe there will be something in the new game hacking module, either way that sounds illegal.

prisma knot
#

I have a question on the Pivoting, Tunneling, and Port Forwarding module, in the "Remote/Reverse Port Forwarding with SSH" section.

I see that first we create a windows payload with msfvenom, then we get the listener set up in msfconsole, then we transfer the payload to the pivot host and start a web server on the pivot host with python in order to download the payload to the windows machine from the pivot host, but this is where my confusion starts. The next step says to use the PowerShell cmdlet Invoke-WebRequest from the windows target, but wouldn't that mean we already have a shell on the target windows machine if we have powershell access in order to run this cmdlet?

If we have shell access on the windows host, why do we need to download this msfvenom payload at all?

mystic perch
#

I'm stuck in the skills assessment part of the web service and api module. can you give me a hint?

viscid epoch
#

any hints please ?

#

module/17/section/88 too much time wasted any hints on the f

acoustic owl
misty current
# prisma knot I have a question on the Pivoting, Tunneling, and Port Forwarding module, in the...

I believe the whole point is to get a meterpreter shell (any kind of shell) on the windows machine directly in the attacker machine, so that you have more flexibility and can do more such as using direct exploits from the meterpreter session.

The line the module that starts with "There are several times during a penetration testing engagement.." would give a detailed answer to your doubts.

acoustic owl
viscid epoch
iron coyote
#

anyone done this question? been stuck for 3 days now cx
Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_).

leaden abyss
#

Skill Assessment- Web Fuzzing- Anyone experience ffuf not passing arguments you give it? I've used it "okay" thus far but, now it's being all wonky and won't filter any results I tell it to filter.

For instance- It won't filter out any 403 codes when I use the "-fc 403" and also won't output to any files anymore.

It's way too much data to just parse through, hence the filters.

Anyone know how to keep it from being all janky? 🥴

cinder mortar
#

Anyone else having issues with Windows Privilege Escalation Skills Assessment - Part I, I cant ping the target with my own attack box or the htb pwn box, tried resetting the vpn multiple times but still cant ping the target. I tried other modules and it works just fine.

sick mural
#

Hi Admins, I have made a mindmap for Pass the ticket section and I needed to confirm, Can i share mindmap( self made )here for ease of others?.

vagrant gust
#

how can i unzip in ssh

#

cant install unzip and i cant see any other way after googling it

tender shuttle
#

I have a question. If I successfully complete a module, will I still have access to the learning materials and their respective lab after my subscription ends?

misty current
proud pine
#

Don't you have jason's password? No need for rsa file.

#

Even if you drop the -i flag?

#

Restart the machine.

#

VPN or pwnbox?

#

I'll load it up. DM me.

rustic sage
#

Can I get some help with Login bruteforcing section's skill assessment - service login?
I have been stuck on this for quite sometime, I have tried multiple methods to create the wordlist but I am not getting any hits whether my wordlist is 5k, 8k or 15k.

vagrant gust
#

im getting virus detected every time i try to download a cheat sheet from a module

dull vortex
#

In "Password Attacks - Credential Hunting in Linux" I am on the target as Kira, and I have been searching for two hours now for wills password/a way to login as will. Any nudges? I am pretty lost with this now

misty current
dull vortex
native pagoda
#

guys im totally new to coding and im planning to study hacking

#

what coding language should i use?

#

python?

glacial hazel
#

depends what you want to do

#

also this is not the appropriate channel for programming questions, better to ask in #programming

fervent vigil
#

Hi, in the footprinting module, in the easy lab i don't know what to do.
I found the ftp and the ipmi (which i tried to access using cipher zero, but it didn't work). Looking at the hint I can access at the ftp with the credentials and get the flag but without the hint I would have no clue in how to find this credentials

#

to exploit IPMI I tried doing
||ipmitool -I lanplus -C 0 -N 15 -H 10.129.X.X -U USERNAME -P randomPass ||
with USERNAME as admin, root, administrator
I always get in return ||Error: Unable to establish IPMI v2 / RMCP+ session||

native pagoda
glacial hazel
odd notch
#

And I'm stuck again... man these labs are kinda the worst. the meduim footprinting lab hint is talking about || sql server and that systems have administrators || but I got nothing.

acoustic owl
#

You need to verify your account

rustic sage
#

Which employee is suspected of performing potentially malicious actions in the live environment? == Bob

odd notch
#

godamit bob...

rustic sage
#

Intro to Network Traffic Analysis 🙂

haughty blade
#

Hlw

fathom pendant
fathom pendant
odd notch
#

I just went on the internet for help. I'm done doing these "blind". I learned more from just looking up the answer tbh

fathom pendant
#

Eh

#

If you use the answer as a crawl back space of 'how did I get here'

rustic sage
#

Can somebody help me on sqlmap Attack Tuning Case6? I've wasted days of my life and I just don't get what they want me to do. 😫

  • I get that case 6 it's about changing the prefix. I did that.
  • I already tried a gazillion possibilities, including raising level and risk, randomizing user agent, focusing on the right table, ...
    I'm not able to figure out what I'm missing...
    I'm using this flags --batch -T flag6 --prefix='`)' --technique=U -t outuput.txt -p col ...
    I know that there is something I'm missing. Any nudge in the right direction is greatly appreciated before I throw the computer out the window. Thanks.
odd notch
fathom pendant
#

You got this

storm skiff
#

Hey guys, I have a question about the File Upload Attacks Skills Assessment. When I go to upload an actual jpeg file and hit the submit button I just see a GET request with 4 parameters (name, email, message, and uploadfile). I don't see any data from the jpeg file. I tried intercepting the request and changing it from GET to POST, also tried change body encoding, but I don't see any data in Burp. Is that by design? or is my pwnbox having issues?

storm skiff
pine dagger
#

Why would you use the Firefox install rather than the built in Burp Suite browser?

odd notch
#

So in medium lab footprinting || I was able to login with xfreerdp to alex with his password, but when trying to connect with sql management I get a weird error that says there is no service at the other hand of the pipe || ideas?

weak charm
full dragon
#

On Active Directory Enumeration and Attacks Module - Privileged Access section. The second question “What host can this user access via WinRM? (just the computer name)”. Does anyone know an effective way to find this information manually using PowerView rather than Bloodhound?

storm skiff
storm skiff
rustic sage
storm skiff
karmic dagger
#

Did anyone else have issues with the Password Attacks - Password Mutations module? Haschcat has been running for almost two hours and still hasn't cracked the password.

pine dagger
karmic dagger
#

Does it matter if you're using the pwnbox or not?

#

I tried downloading the file on to pwnbox to work on it that way, but it crashes when I try to log on to the website.

#

Got it. Thank you very much.

rugged vapor
#

happend to me on local file inclusion too so I am probbly the problem lol

#

I learned so much before going to hack the box and now I feel like I know nothing everytime they challange me to death lol

heady tusk
deep owl
#

hello all please give me a hint on this question .... am not able to spawn a reverse shell although i followed the steps in the module

#

section: password attacks

#

module: pass the hash

#

Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt.

#

appreciate any help 🙂

autumn garnet
#

anyone complete the Documentation & Reporting practice lab?

little bear
#

Not yet, but will be excited to start.

balmy saffron
#

Hello, I am in the "linux password attacks/credential hunting" section. I am supposed to find Will's password. I tried to ssh the machine using
"Kira:LoveYou1" as stated by the hint. Didn't work.
kira:LoveYou1 didn't work either
I tried then
hydra -l Kira -P password.list ssh://IP
hydra -L kira -P password.list ssh://IP
Nothing worked.
Is this expected? Did I miss something?

#

sorry hydra -l kira ...

acoustic owl
#

You have to create your own password list with the given password

glacial hazel
#

incidentally, that's what I'm doing right now 😮

#

but for something unrelated

wooden rapids
#

im doing the active directory enum and attacks module and the rdp connection to the parrot host is painfully slow, is there anything i can do to imprive it?

glacial hazel
#

Are you using pwnbox or your own VM

#

Wait you’re RDP’d into a parrot host?

#

Or you’re using an RDP client on a parrot host to remote into a windows host?

wooden rapids
#

im on my own vm, rdp'd into a linux host, "Scroll to the bottom, spawn the target, connect to the Linux attack host using xfreerdp and fire up Wireshark to begin capturing traffic."

glacial hazel
#

Ohh okay, I was curious what the purpose of RDP into Linux host would be, but I assume it’s because Wireshark is generally taught through GUI. If the RDP connection is too slow to the point of being unusable, you can alternatively SSH into the machine and use tcpdump and apply the same rules and you should get the same PCAP file which you can analyze on your own VM with wire shark

#

Because both wireshark and tcpdump use the libpcap packet capture library to produce the PCAP file

wooden rapids
#

thanks, ill try it that way 👍

glacial hazel
tulip coral
#

can someone help me rectify the following

raw venture
#

Hi, I'm currently in DNS footprinting and stuck in the last question "What is the FQDN of the host where the last octet ends with "x.x.x.203"?". Just want to ask if the dev subdomain is the right path? Thank you.

spark vector
fringe shell
tulip coral
#

@spark vector on the password and username fields ? no i have not.... i can try though

#

@spark vector so it kinda worked.... this was the result with double quotes

#

but then with single quotes .. i got the same error but the session opened

#

is this lost magic ?

fringe shell
glacial hazel
#

For example if you enter the following command you will get the PPID of the shell:

echo $$
#

So your first command is really using that number^

#

When you use single quotes, it’s called literal string, and there is no parameter expansion

misty drift
#

GETTING STARTED-Public Exploits
My question is “Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the ‘/flag.txt’ file. (note: the web server may take a few seconds to start)”, i used nmap -Pn -cV -cS -p[port] [host] then gain:
"└─$ nmap -Pn -sC -sV -p31770 46.101.2.67
Starting Nmap 7.93 ( https://nmap.org ) at 2023-05-22 00:02 EDT
Nmap scan report for 46.101.2.67
Host is up (0.22s latency).

PORT STATE SERVICE VERSION
31770/tcp open http Apache httpd 2.4.41 ((Ubuntu))
|_http-title: Getting Started – Just another WordPress site
|_http-generator: WordPress 5.6.1
|_http-server-header: Apache/2.4.41 (Ubuntu)

Service detection performed. Please report any incorrect results at Nmap OS/Service Fingerprint and Correction Submission Page .
Nmap done: 1 IP address (1 host up) scanned in 31.80 seconds"
I tried searching on Google with ‘WordPress 5.6.1 exploit,’ but I couldn’t find any public exploits to use for ‘msf>search exploit [plugin_name].’ Can anyone help me with this step?

fathom pendant
spark vector
#

Module:ATTACKING COMMON SERVICES
Section: Attacking DNS
Question: Find all available DNS records for the "inlanefreight.htb" domain on the target name server and submit the flag found as a DNS record as the answer.
Results:
Stuck on this one. Any hints would be appreciated.

  1. I located all three subdomains h*******.inlanefreight.htb, c******.inlanefreight.htb and n*.inlanefreight.htb.
  2. Performed dig on all subdomains (dig any @ip subdomains).
  3. Used subbrute on domain and all subdomains.
misty drift
fathom pendant
#

Perhaps there's a vulnerable plugin

fathom pendant
#

Iirc

#

But you also shouldn't need to subbrute for the text record

#

If you can axfr

rugged vapor
#

I am losing my mind over how to crack WINRM when theres no password or username I used about 5 wordlists and no luck

fathom pendant
rugged vapor
fathom pendant
rugged vapor
#

OMG

#

and thats 8 hours on nothing folks

#

Thank you so much!

spark vector
fathom pendant
fathom pendant
rugged vapor
fathom pendant
#

It's not the name of the subdomain

rugged vapor
#

as long as I am not the problem lol

fathom pendant
rugged vapor
misty drift
#

Module: Getting Started
Section: Public Exploits
Question: Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start)

Can anyone who has solved this question help me with the steps to solve it? Thank you very much in advanceprayge

fathom pendant
#

Lol

#

It's not something crazy

spark vector
misty drift
# fathom pendant Lol

I have tried, but I didn't get good results and I'm not sure what to do next, Can you help me with the specific steps I need to take

fathom pendant
#

Which it's nice enough to tell you

snow coyote
#

hey so i just wanted to ask if it's possible to download for example the wordlists that are on the vm from the academy. I mean ik that i could copy-paste etc, but yh just wanted to ask if there is like an easier download from the files that are in there

autumn pilot
#

The are mostly from seclists

snow coyote
#

thank you :)

rustic sage
#

I might be dumb but i am on the Learning process Module and i cant answer the last question

fathom pendant
#

What's the question?

rustic sage
fathom pendant
rustic sage
#

ah damn

#

got it

naive shell
#

50064.rb

dense elk
#

Hi

odd notch
#

Greatings toast's haver's. I have come to ask a question. if a host have 2 ports used for nfs? will it follow I should somehow scan both for diff shares?

odd notch
heady tusk
#

have you selected a database before trying to log in?

odd notch
#

default?

heady tusk
#

I didn't change anything and ran into the same issue that you're having right now. check through the available databases and see which one would be interesting. you'll have access to that one

odd notch
#

ok, I'll check it thanks!

heady tusk
#

sure thing 🙂

odd notch
#

I can't seem to even get available databases.

#

I think user || sa is not configured to login... I'm getting login failed for sa after the first attempt, which fails with "no service on the other end" error || @heady tusk

heady tusk
#

alright my notes on this one are pretty bad so gimme a couple of minutes to run through it again

odd notch
#

thank you 🙏

young trellis
heady tusk
odd notch
heady tusk
#

||Think about what 'sa' means||

odd notch
#

oop

#

got it

#

😄

heady tusk
heady tusk
odd notch
#

def adding that to my notes

heady tusk
#

definitely a good idea to check that 🙂

odd notch
#

well the || HTB user isn't on the DB. which sucks. but maybe I need access to somwhere else with these accounts? big_think ||

#

nvm

#

found it

#

😄

heady tusk
#

great 🙂

thorn cosmos
#

Hello everybody. I'm in "Reverse Shell & Payloads - The live engagement" and I've some trouble to add the payload in metasploit. The file is in the correct directory with correct permission, but it never show in metasploit. Any advice?

shadow current
#

any program on htb recos for people who are just starting on a entry level job as infosec analyst

worn violet
odd notch
#

daim the hard footprinting is tough...

heady tusk
#

Has a bunch of steps for sure. But it's doable, just keep methodically running through everything you've learned

odd notch
#

Am I supposed to use previous credentials?

heady tusk
#

No

odd notch
#

Ok, so || I only see ssh, 2 imaps and 2 pop3's ports. all of which require credentials...||

heady tusk
#

Then you're missing a service

odd notch
#

huh...

#

it's -sT for steath (full handshake) right?

#

my notes are kinda off on that

heady tusk
#

No need to worry about stealth in this case

#

But yes, -sT is full handshake

odd notch
#

Well I did -sS I got || only 5 ports open... 2 pop 2 imap 1 ssh ||

heady tusk
#

Well yes. And that's the correct result for that scan

odd notch
#

oh,

#

ok

#

I'll play around with it

heady tusk
#

Good luck 🙂

odd notch
#

-p- (I'mma go make me coffee ig...)

devout osprey
#

Did anyone have the same problem with vaccine tier and vi program? Because when I tried to type the command :set shell=/bin/sh and then I have typed :shell it showed me an error Not an editor command: shell

odd notch
heady tusk
#

100%

odd notch
#

|| so 6 ports should be open? right? ||

heady tusk
#

Well for which protocol?

devout osprey
odd notch
heady tusk
#

Nmap is the tool for the job here. Look into different scan types

odd notch
#

aight thanks! don't tell me more 🙂 unless I'm really going off the path..

#

|| My slow UDP scan seems to found 50+ ports wtf ||

heady tusk
#

Ugh that shouldn't happen

odd notch
#

most probably are false positives

#

the command || sudo nmap -sU -sV -sC 10.129.202.20 -oA nmap_scan_udp ||

heady tusk
#

I'd probably omit the -sC cause it's really slow

odd notch
#

butbutbut

#

it's almost done anyway but oki

heady tusk
#

Well if it's fast enough sure keep it

odd notch
#

I just figured while I'm doing other stuff I'll let it run. so didn't mind adding some stuff

heady tusk
#

Fair point

thorn cosmos
odd notch
#

I FUCKING KNEW IT! || it's snmp on 161 I was missing right? ||

heady tusk
thorn cosmos
heady tusk
#

And on pwnbox it doesn't?

thorn cosmos
thorn cosmos
heady tusk
#

Even if the module doesn't show up in search, can you load it using it's full path?

odd notch
# heady tusk Yes

|| how come it responds to v2c when it says it's snmp version 3? is that the miss configuration? backward compatibility? ||

final basin
#

hey guys, would anyone be willing to help me / give me hint with one question form Attacking Domain Trusts - Cross-Forest Trust Abuse - from Linux module?

#

sorry, the module is ACTIVE DIRECTORY ENUMERATION & ATTACKS

#

that was a section

autumn pilot
#

which question

thorn cosmos
final basin
#

logging in the DC.

autumn pilot
#

psexec

odd notch
#

boxes are so unstable 😦

#

I'mma cry

odd notch
#

ok I get hang every like3 minutes... is it just me?

final basin
# autumn pilot psexec

Thank you! I've tried playing around with psexec.py but it didnt work for me the first time. ||I was not supposed to use -k flag.. since well, its not a Kerberos login. ||

#

do you have a forum acc? i will tag you and answer me my question.

autumn pilot
odd notch
#

how do I fix 😦

autumn pilot
#

check your tun interface, if there are multiple kill the process and reinitiate it

odd notch
#

nope. only 1

#

anything else?

autumn pilot
#

reach out to support for further checks

odd notch
#

I think I figured it out

#

I am using a vm. and on my host I also started the vpn connection.

#

so I closed the one on the host and now it's stable.

fathom pendant
#

Yeah that'll do it

shell mantle
#

as you can see, nothing happens

autumn pilot
#

well, you are in the home directory which most probably doesn't contain any of the specified files you are looking for

odd notch
#

footprinting hard || I got tom's pirvate key and password, logged in. now I now he has a file in /opt/ that should change his password.. it seems bad, but tom also doesn't have root. I see mysql evidence but I don't really know how to proceed.|| any tips?

shell mantle
#

damn i feel like such a spoiled little kid for asking these questions

autumn pilot
#

think about the filesystem, how it is structured and you will be one step closer

fickle thicket
#

hi, anyone knows to take the htb cpts, if i am a beginner, do i have to complete all the tier 0 module first before embarking on the htb cpts path?

autumn pilot
#

nope kikirikikokos

shell mantle
#

probably me

odd notch
#

ok

#

wait

#

don't tell me I think I found something

#

BAM.

#

done.

#

finished footprinting! yaay!

shell mantle
#

isn't that where im supposed to be?

#

idk all this "ssh" thingy confuses me so much

fathom pendant
#

Don't you bring that here buffet

fathom pendant
#

Think of ssh as just being on a system

autumn pilot
#

@rustic sage not the place

fickle thicket
shell mantle
#

well, to be precise -> I don't understand how do I get to that system

#

like htb-student

#

ssh htb-student@white rock address

shell mantle
#

what is "htb-student"

fathom pendant
#

The user

shell mantle
#

their email address?xd

fickle thicket
#

the username

#

?

shell mantle
#

username of what

fathom pendant
#

Yes

#

The user on the remote IP

shell mantle
#

do you type your username and password when starting up linux?

fathom pendant
#

God this feels like a "the door to the microwave" moment

fickle thicket
#

you can specify a specific port number when you ssh too.
with a -p option if i remember correctly

fathom pendant
fickle thicket
#

thanks. i find htb academy more comprehensive than other website. is pretty good.

shell mantle
#

so if i have your username, pass and ip, i can look through your pc and all of it's files?

fickle thicket
#

the port number is like a door number.
the ip address and the port forms the socket.
the socket is an interface between the application and transport layer.

shell mantle
#

like i understand it only enough for the module, so i can finish the questions

fickle thicket
#

i am not sure if i am correct though😅

#

but that's what i read from books

fickle thicket
fathom pendant
fickle thicket
#

there are generally 3 kind of permission.
r - read
w - write
x - execute

then there are 3 kinds of user based permission group
owner, group, others
each one of them has their own set of permission which is mainly rwx

fathom pendant
fickle thicket
shell mantle
#

wait

fickle thicket
shell mantle
#

i think im having issues with either my internet connection or htb

#

because i wasnt able to do basically anything

fickle thicket
#

can you access google🤣

shell mantle
#

i was like typing and nothing executed

fathom pendant
#

Probably your connection

#

Or box timed out

#

:p

naive wadi
#

Question: Is the information in the "Hint" of footprinting Easy possible to find by enumeration alone?

fathom pendant
fathom pendant
#

I did it the brute way on my second go of it to fix notes

rustic sage
#

@edgy trellis

fickle thicket
#

i cannot remember so many stuff.
guess taking down notes is impt for cpts 😅

fickle thicket
fathom pendant
#

some of those things are learning by repetition ¯_(ツ)_/¯

fickle thicket
#

since there are so many information in a single module. how do you choose which part to include in your notes?

#

isnt http port 80?

fathom pendant
#

Don't lie

fickle thicket
#

🤣🤣🤣🤣🤣🤣

wraith delta
#

What is the 2021 OWASP Top 10 classification for this vulnerability?

#

for starting point

fickle thicket
#

sometimes i feel i started learning too late.

fathom pendant
#

Stop spreading disinformation

wraith delta
#

What is the 2021 OWASP Top 10 classification for this vulnerability? I cant answer this question on "Appointment Bot" in starting point.

fickle thicket
#

don't believe everything you see on the internet - abraham lincoln

fathom pendant
wraith delta
#

I cant chat on pwnbox

#

where tf am i supposed to ask then

fathom pendant
#

There are instructions on how in #welcome also pwnbox isn't the right chat, there is a starting-point chat you'll be able to access once you follow instructions from welcome

visual dagger
#

@spring tundra it's Suit, message me pal

fathom pendant
#

Which makes me highly doubt you actually read

wraith delta
fathom pendant
#

Don't know wtf you said

wraith delta
fathom pendant
#

I don't care enough

wraith delta
#

Ok then smd

fathom pendant
#

No need to be hostile my guy I'm pointing you in the right direction

wraith delta
#

you said i cant read ur trying to be a asmartass

fathom pendant
#

Do you realize how many people come into this server daily on some dumb shit?

ivory cipher
#

Hello smart people! I'm doing File Upload attacks - Blacklist filters. I've found some extensions that give me a good response. But when I run any php code it ends at the first ">". Is this because the extension can't properly run php code and I have to find another one or am I doing something else wrong?

fathom pendant
#

You act like I murdered your father just because the verify may not have gone through yet to prove you read and did it

fickle thicket
wraith delta
fathom pendant
wraith delta
#

Ok then stop licking the tip

fathom pendant
#

Chill bro

shell mantle
#

dude stop being toxic

wraith delta
#

hahaa

fathom pendant
#

With an attitude like that I'm surprised if you get any actual help

#

And I was actually going to be willing to help you in that channel too

shell mantle
#

debate about hacking related stuff, not some random bullshit

wraith delta
fathom pendant
#

Either way we're straying off topic of this channel

fathom pendant
shell mantle
#

gonna do it later

#

i have to touch some grass broski

fathom pendant
#

🌳

#

Nice

odd notch
#

in the information gathering - web edition they recommend signing for hackerone and reproducing something? I didn't quite understand what they mean.

fathom pendant
#

That's just if you wanna try bug bounty

#

There's no need to however

odd notch
#

OH, ok. seems to pay very little anyway

dull vortex
#

I have a question on the Password Attacks module but a picture would spoil it. I am trying to crack a hash but I am not sure if I have this in the correct format, I keep exhausting the wordlists.

novel matrix
#

yooo can we please keep this chat on topic

odd notch
#

it's not?

novel matrix
#

it's not a channel for chit chat unless it is module related.

fathom pendant
mortal canyon
odd notch
#

can you point out where? I'm confused. just for future referance

novel matrix
fathom pendant
#

Also hashcat will straight up tell you if it's an incorrect hash most of the time

dull vortex
#

Its the Passwd, Shadow & Opasswd section. I am exhausting both the password.list and mut_password.list

mortal canyon
#

Maybe I'm crazy but isnt the supposed hash missing a character? Iirc you have to use a charlist do add the last char and then dehash...

fathom pendant
#

It should be in the mut_passwd

dull vortex
#

I am going to re mutate the list to ensure it is working properly

fathom pendant
dull vortex
#

got it, I may have the wrong thing in there

fathom pendant
dull vortex
#

cracked... thanks

deep owl
#

hello all please give me a hint on this question .... am not able to spawn a reverse shell although i followed the steps in the module
section: password attacks
module: pass the hash
Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt.
appreciate any help

#

.

#

any help plz

vocal coral
#

hi, i'm stuck with imap command. i need do command 1 FETCH 1 all but did not show

vocal coral
#

solved. thank you)

acoustic owl
fallow delta
#

@sonic moon I am having the same issue, mind if I ping ya for a nudge?

snow coyote
#

hey, i need a hint at the file inclusion module, to be more precise with php wrappers. So i was able to create a cmd shell and can use cmd commands at the end of the url (i use the data wrapper to complete the exercise.) However if i type something like "cmd=dir" at the end of the url, it doesn't showed me a flag file. I also tried to add (idk if that works) more cmd commands by adding them with "&cmd=cd .." for example because i thought i might need to go a directory above, but it won't

sacred ermine
#

WTF IS HAPPENNING WITH ACADEMY SITE????

sacred ermine
#

I am also stuck there

#

idk what to do

#

that's weird

deep owl
heady tusk
ivory cipher
heady tusk
#

awesome 🙂

little bear
heady tusk
fathom pendant
#

The pivoting module is by far the worst on repetition

#

Different tools same results

heady tusk
#

agreed

acoustic owl
sacred ermine
acoustic owl
sacred ermine
#

yeap, even I changed it

fathom pendant
#

Sip are you running the pwnbox and VPN at the same time?

#

Also when you changed it did you redownload and restart the ovpn service?

sacred ermine
#

nope

fathom pendant
#

Are you using the in-browser pwnbox

sacred ermine
#

that's strange

sacred ermine
fathom pendant
#

Ok so VM > you downloaded the new config file to your VM and are running it there yes?

sacred ermine
fathom pendant
#

That's not the question

fathom pendant
#

It's a yes/no question... Not a 'sure'

sacred ermine
#

yes

#

I mean, "sure" == "yes"

fathom pendant
#

Ok so if you do ip a do you have a tun0 interface?

sacred ermine
#

yep

fathom pendant
#

The command would look like this then:
ssh htb-student@<ip>
Note, replace <IP> with the "spawn target" IP

#

You aren't also running the VPN on your host machine, are you?

sacred ermine
#

could it be bc of some "broken" packages?

As far as I know Parrot OS likes these type of errors, as I am using Parrot.

so I dont know, maybe smth wrong with my OS, let me try on pwnbox

fathom pendant
#

No

#

I use parrot myself and haven't had issues

#

*aside from sqsh

sacred ermine
fathom pendant
#

No route to host indicates most likely a DNS/network issue

karmic wren
#

Hey academy password attack ?????

fathom pendant
#

After changing VPN region did you hit the refresh button next to the target IP to respawn it?

fathom pendant
karmic wren
#

I am stuck in rdp username enumeration.

sacred ermine
dusty citrus
#

Guys anyone done DNS takeover?

fathom pendant
fathom pendant
dusty citrus
sacred ermine
#

I dont have such problem on pwnbox

fathom pendant
fathom pendant
vital bough
#

on the footprinting medium lab, did anyone have issues with the password throwing a bash error all the time?

karmic wren
#

And sometimes distinction is unreachable ????? Why.

thorn urchin
#

idk about that one specifically but if youre supplying a password as a cmd line argument its special characters can sometimes get interpreted as bash special chars, so you have to wrap it in quotes

fathom pendant
#

It's reading $$ as a variable

fathom pendant
vital bough
sacred ermine
#

Module: Linux Privilege Escalation
Section: Kernel Exploits

Although I had a problem with Attacking common apps
Section:Attacking Thick Client Applications

then I jumped on the next module, just hoping that I wouldn't have a problem, that's basically it.

fathom pendant
sacred ermine
#

now its strange

karmic wren
#

Winrm services to find username. ???

fathom pendant
#

I forget what services are running on that lab

sacred ermine
# karmic wren Network services

just look around, u will find it I am sure, only if you look closely for which service to look at, and which wordlist to use

sacred ermine
zinc marsh
#

dm if someone need help

sacred ermine
glossy ore
#

out of curiosity, is there a module for c2 servers/tools in general?

karmic wren
sacred ermine
sacred ermine
thorn urchin
glossy ore
#

it'd be cool if it included how to write your own basic C2. i know there are lots of examples out there, but htb content is great

wide oak
#

Hello there 🙂 Could someone give me a hint for Windows Privilege Escalation Skills Assessment - Part II - 2nd Question? monkaS

fallow delta
#

You end up figuring it out? I'm not seeing the memory address they reference // MAP -RW-

fathom pendant
naive wadi
fathom pendant
#

It's an attack that does not cause a denial of service

#

That's more of fluff to say don't remove or delete files on the accessed server

naive wadi
#

actually will use crackmap to see

zinc marsh
#

someone who completed login bruteforce - login form attacks

#

i got the flag but it doesnt work lol

fathom pendant
naive wadi
#

so that makes sense

zinc marsh
#

no? if i remember well

fathom pendant
fathom pendant
fallow delta
acoustic owl
fathom pendant
whole grotto
#

Hi everyone, I'm in the nmap module, in the hard lab, and I'm a bit stuck, I found some ports open with their versions, and others filtered but after being banned several times while trying I didn't succeed. Can I dm someone who can help me pls?

fathom pendant
naive wadi
#

also winrm is not running

whole grotto
fathom pendant
fathom pendant
#

If you run the scan without the specified port but with the (source) port of DNS then all will be revealed

#

The examples are definitely helpful

naive wadi
shell mantle
#

yo im back

#

and i got the same issue again...

#

it's not returning absolutely anything

fathom pendant
shell mantle
#

Linux Basics - Find Files and Directories

#

if I knew how to search it up on google, i wouldnt be bothering you bro

fathom pendant
shell mantle
#

nope, nothing again

wispy aspen
#

Should there be a space between -name and *.conf

fathom pendant
#

Probably

wispy aspen
#

and should there be a . or / between find and -type f

lavish needle
#

Hey! Can anyone give me a nudge for File Upload Attack - Skill Assessment? I've made some progress but I can't get any of my payloads to run properly : (

shell mantle
#

it's working now

wispy aspen
#

You changed literally nothing and it began working?

shell mantle
#

so spaces are really important in linux i guess

shell mantle
wispy aspen
#

there ya go

shell mantle
#

and also "cd /"

#

idk if that helped

wispy aspen
#

if it worked now, didn't before, and that's what you changed, then there's a good chance

shell mantle
#

well i had this same issue before with correct command so im guessing "cd /" is the important one

#

why tho?

fathom pendant
#

Most of the time there should be a space after a flag especially if the flag is a full word and not a letter

pulsar mural
#

Is there no bug report channel on this discord for the academy modules?

fathom pendant
#

What does cd / do and that'll tell you

fathom pendant
#

If it's the Linux one where it's not telling you that it's parrot that's being worked on

wispy aspen
shell mantle
#

ohhh

fathom pendant
#

It could also be a user error issue. There are some modules however whose boxes are a little touchy

shell mantle
fathom pendant
#

Yes

shell mantle
#

if i just wrote "ssh.." im not in a folder right?

fathom pendant
#

No

#

Ssh is a service/tool

#

We went over this yesterday

#

When you ssh you're going to that user's home directory

shell mantle
#

okay so im in his /home/htb-student directory -> "cd /" is the beginning? like no directory?

autumn pilot
#

the / is the root directory of linux

shell mantle
#

thats what i was trying to say 😅

#

thanks guys

#

to all of you ❤️

zinc marsh
#

i need help with the wordlists in skill assesment - service login

#

login bruteforce

limber widget
#

On the attacking SQL Databases module, Question 2: "Enumerate the "flagDB" database and submit a flag as your answer." - the user and cracked hash does not seem to want to login to enumerate. Any tips? Ive tried sqsh and mssqlclient

wooden palm
#

pkilled all openvpn instances and reset it.

#

reset the box

#

still isn't showing up for some reason.

autumn pilot
#

there is no need to use a vpn for this target

#

you have an IP and a port, think how can you combine them in your ssh command alongside with the username

wooden palm
#

I can't ping the box.

autumn pilot
#

Of course you can't

#

Because that is not a pingable box, but rather banner grabbing

#

if you want to check that the machine is alive

wooden palm
#

ohhh

#

I guess I've just been so used to pinging it.

#

Thanks!

rustic sage
#

Can I get a nudge for sqlmap essentials attack tunning section?
sqlmap gets stuck on case 7

odd notch
#

Hi I'm at the information gathering -web edition, passive subdomain enumeration, I'm a bit worried about the automated use of havester and the modules... will I need to go indepth by myself into each of them? or do I take that solution as is?

misty current
deep owl
#

hello all, password attacks module .... section: pass the ticket ...... i cannot connect via RDP

#

anyone else facing this issue i believe something wrong with the vulnerable vm

misty current
deep owl
#

worked with the single quote

#

thanks

heady geyser
#

could use some help. Password attack/ Pass the ticket with linux section. I have logged in as Carlos and its asking me to find the creds for svc_workstation and login via ssh. I have found the crontab associated with svc_workstation. i have extracted an aes-256 hash but no luck with an NTLM. I cannot crack the aes256hash with either online website or hashcat. i was able to use "klist" to impersonate svc_workstations and see the share in the DC but i dont this is the intended route since the question specifically says to use SSH. Thanks

lavish needle
#

@limber widget Send me a dm - I can help you out : )

limber widget
misty current
heady geyser
#

i've looked everywhere, and other then the crontab, i found 2 krb5cc files for julio, and 2 for carlos

fathom pendant
lament lance
#

Hi, I'm doing the hashcat module.
The following question:

"Crack the following MD5 hash using a mask attack: 50a742905949102c961929823a2e8ca0. Use the following mask: -1 02 'HASHCAT?l?l?l?l?l20?1?d'"

This is my command, but hashcat gets exhausted and doesn't crack it. Any idea what I'm doing wrong?
||hashcat.exe -a 3 -m 0 50a742905949102c961929823a2e8ca0 -1 02 'HASHCAT?l?l?l?l?l20?1?d'||

lethal atlas
misty current
lethal atlas
lament lance
#

Yes, I downloaded it as it's much faster on my GPU. It worked with all other attacks but this time it just exhausts.

heady geyser
lethal atlas
lament lance
#

tried, doesnt work

lethal atlas
#

works for me

lament lance
lethal atlas
lament lance
lethal atlas
#

one set of single quotes

lament lance
lament lance
#

and that happens

lament lance
#

@lethal atlas Any idea what I could be doing wrong?

#

Oh huh

#

I think it was just windows hashcat being high because I tried it in pwnbox and it did it

#

weird

lethal atlas
#

yeah I ran it from a vm. I havent used the windows version

lament lance
#

weird

#

it worked for all past hashes

fathom pendant
#

Did you try with double quotes only?

lament lance
#

No, tried single and double

lethal atlas
#

that is interesting. Just out of curiosity try saving the hash in a file then running hashcat with the file name instead of the hash

lament lance
#

Sure.

lethal atlas
#

hashcat -a 3 -m 0 hash.txt -1 02 'HASHCAT?l?l?l?l?l20?1?d'

#

my first run thru this module I used that method

lament lance
#

Exhausted

#

Although

#

what I noticed is that it's using a weird mask as well

lethal atlas
#

hmmm well I tried it several ways but they all work in linux.

lament lance
#

Worked for me too

#

I'm using the binary of hashcat

limber widget
#

Out of curiosity I gave it a shot as well in windows, no go

lament lance
#

exhausted?

limber widget
#

yupp

lament lance
#

that is strange

limber widget
#

with same strange mask

lament lance
#

what is your hashcat version?

limber widget
#

6.2.6

lament lance
#

same

#

the only thing i can think of is linux using a different one??

lethal atlas
#

6.2.6 on my vm

lament lance
#

well

#

that is very weird

#

also when brute forcing, waht do MHs actually mean?

limber widget
#

megahash per sec I believe

lament lance
#

yeah but what does that actually do?

wooden palm
misty current
#

can you try once without wrapping the mask with single quotes

#

and run it

wooden palm
#

You have kh/s too

#

Kilohashes

misty current
#

hashcat.exe -a 3 -m 0 50a742905949102c961929823a2e8ca0 -1 02 HASHCAT?l?l?l?l?l20?1?d

#

like this @lament lance

lament lance
#

gimme a sec ill try

limber widget
#

that worked

lethal atlas
#

this worked in windows for me hashcat.exe -a 3 -m 0 "50a742905949102c961929823a2e8ca0" -1 02 "HASHCAT?l?l?l?l?l20?1?d"

misty current
#

I guess the thing with windows, is that, it wraps the hash and mask value with single quotes automatically.

#

so you can go either no quotes or double quotes for those two.

lethal atlas
#

looks like it

lament lance
# lethal atlas looks like it

One more thing,
Crack the following hash: 978078e7845f2fb2e20399d9e80475bc1c275e06 using the mask ?d?s.
Exhausted in a few seconds on windows, currently trying in PWNBOX. Do you see any issues in my command?

||hashcat.exe -a 6 -m 100 978078e7845f2fb2e20399d9e80475bc1c275e06 wordlists/rockyou.txt '?d?s'||

#

Hybrid hash section

#

but pwnbox is not looking very successful either

limber widget
#

Read @misty current comment above

#

about single quotes

lament lance
#

I figured, that's why I'm trying in pwnbox.

limber widget
#

issue is single quotes '?d?s'

lament lance
#

Oh you were right

#

cracked in pwnbox

#

why's windows gotta be so stupid

fathom pendant
#

Single quotes reads it as literal instead of as wildcard as well

lament lance
#

i love how pwnbox took 2 minutes and my pc took less than 1 second

lethal atlas
lament lance
#

well mainly between cpu and gpu

zinc marsh
#

someone who completed login bruteforce - skill assessment service login?

small sage
#

hello, working on the pivoting module, SocksOverRDP section, I have the dll successfully loaded onto the first target, when I RDP onto the second target and try to start the server I get an error that the plugin is not loaded client side. Any tips?

karmic dagger
#

Is anyone having issues with the connection on the Password Attacks - Attacking SAM module? The connection to the RDP drops repeatedly even if I reset the machine and any access when trying to transfer files is denied.

zinc marsh
#

30 modules completed 😄

small sage
lavish needle
#

can anyone give me a nudge on how to find the flag for File Upload - Skill Assessment?

rustic sage
#

@acoustic owl Can I dm you about login bruteforcing skill assessment?

oak sequoia
#

hi, what does this mean in Silver Annual plan? ✅ No waiting to unlock modules

thorn urchin
#

theyre unlocked while you have the sub, dont need to pay cubes for em

fathom pendant
#

^

thorn urchin
#

but you lose access if you lose the sub UNLESS youve completely finished a module, then you retain access to it.

fathom pendant
#

Instead of waiting the next month to get cubes all modules (up to and including tier 2) are unlocked

oak sequoia
#

huh perfect thanks @thorn urchin

thorn urchin
#

on a per module basis ofc

oak sequoia
#

thank you everyone

spark vector
#

Module:ATTACKING COMMON SERVICES
Section: Attacking DNS
Question: Find all available DNS records for the "inlanefreight.htb" domain on the target name server and submit the flag found as a DNS record as the answer.
Results:
Stuck on this one. Any hints would be appreciated.

  1. I located all three subdomains h**.inlanefreight.htb, c**.inlanefreight.htb and n.inlanefreight.htb. I might be missing one?
  2. Performed dig on all subdomains (dig any @white rock subdomains).
  3. Used subbrute on inlanefreight.htb.
rustic sage