#modules

1 messages ยท Page 89 of 1

low girder
#

Which VPN server?

limber river
low girder
#

Oh that one

#

Okay

tranquil quail
modest ingot
#

Guys idk why i cant download my prolab vpn anymore, it say to turn off active machine before, but i dont have any ON machine

acoustic owl
modest ingot
#

any way to fix my problem ?

low girder
modest ingot
#

issue resolved thx prayge

low girder
#

Slowly users will now be able to spawn the academy targets and pwnbox.

analog dock
#

Saw some people that did it with gui, but I managed to do it in terminal

analog dock
naive wadi
#

and have been beating my head against the wall

#

this might be it

analog dock
heady tusk
zinc marsh
#

is the academy working already?

heady tusk
#

it should be

cursive zinc
#

Hi everyone, just to know, is there a module specially dedicated to python programming?

zinc marsh
#

and search python

zinc marsh
#

or literally just google python htb

pliant flower
#

Hi guys, I've just joined this server. I'm stuck with something while doing Oopsie in Starting Point. Can I ask the question here?

cursive zinc
#

Thanks

pliant flower
#

Thank you guys

zinc marsh
#

u also have the write-ups to check it

pliant flower
#

I don't have access to the server you've posted

#

Or channel

#

It says No Access

heady tusk
naive field
#

ok so for attacking domain trusts, extrasids attack

#

i need to have DCSync ACL enabled ?

#

or i did not understand it good

#

it says compromising child domain, what do they mean by compromising? having local admin or?

#

just wanna make sure i understand it ๐Ÿ˜„

tacit bay
#

Anyone able to help me out with password mutations exercise for "sam" user ? tried ftp instead of ssh with hydra, also filtered my list down to 8 character + passwords - still this mutated list is not coming back with anything after 30 mins..

foggy light
#

Module Using CrackMapExec
Section Command Execution
Q. Copy the file named julio_keys from the target Administrator's desktop and authenticate using the file with SSH. Submit the flag in Julio's desktop.

im using this command to download the file

crackmapexec smb 10.129.204.178 -u administrator -p 'AnotherC0mpl3xP4$$' --local-auth --get-file "c:\Users\administrator\Desktop\julio_keys" /tmp/julio_keys

getting error

[-] Error reading file C$: SMB SessionError: STATUS_OBJECT_NAME_INVALID(The object name is invalid.)

Why it didnt work?

Also which ip im going to ssh into?
I have looked into the content of the key and made a id_rsa but cant login via ssh

autumn pilot
#

You need to escape the slash, e.g. double slashes will work

foggy light
autumn pilot
#

removal of the c: is necessary as well

foggy light
#

I can look into the file like this

autumn pilot
#

it will drop you in the C: directory, from there you can navigate to the key without specifying (C:)

foggy light
#

I almost press send to this

now for the stupid question.. how do I login via ssh :skull: 

Almost xD

silent scarab
#

can anyone give me a hint please ๐Ÿฅฒ

graceful mortar
#

someone could help me with Documentation & Reporting Practice Lab ?

graceful mortar
heady tusk
tacit bay
heady tusk
#

don't have notes on it but from what I remember it does indeed take a bit. so increasing threads may be helpful and choosing the fastest service

tacit bay
heady tusk
#

ugh it should be doable within 20min for sure. Feel free to dm me, I can run through it later and try to help with debugging

wild smelt
foggy light
#

No

snow lion
#

Hello. What are you talking about?

#

I AM NEW HERE.

snow lion
foggy light
#

this is a NSA level tool. used for various things. you can brute force , type in other peoples computer and get peoples password

tepid hemlock
#

Hey dudes, I am interested in doing the Academy content, any suggestions on how to get started? I have some background knowledge on many topics. Would you recommend Penetration Tester path on Academy?

foggy light
#

Both Penetration testing path and bug bounty path is good.
I have some knowledge about a lot the topic hackthebox covered. But the moment I started studying the modules I understand how little I know. HTB goes in debt in everything they teach. @tepid hemlock

snow lion
#

Can save a message here?

tepid hemlock
#

I am currently doing it and I dunno, I feel like it has a bit too much hand holding which gives a bit of a false sense of success

snow lion
#

@foggy light Why do you using this NSA? Are coding for something? What were that software?

foggy light
# tepid hemlock Have you by any chance done THM content? How would you compare the two?

I did a lot of THM, last december i was around rank 9000.
Both of them have different flavor. While THM helps you a lot , HTB wants you to try hard. You can use discord to discuss if you have issues but mods here still will motivate you to solve it by yourself by giving you hint first. So again different flavor.

IMO if you are want in dept knowledge htb is the way to go

tepid hemlock
#

yea, a little bit of sweating is what I believe promotes learning and makes it interesting

#

You say both paths are good, have you done from both or maybe completed both?

#

and as a last question. If I want to the Pentest path, which pricing model should I go with? I do wish HTB Academy had similar pricing to THM (one price, access to all) but maybe this way it is easier to be dedicated to one path

foggy light
#

IMO bug bounty path is relatively easier than Pentest path.
But both focus on different things. I have both of the certification , if you like web app pentesting start with bug bounty path

tepid hemlock
#

I was thinking bug bounty was "easier" to use on Freelancer type gigs, like Hacker1 where as pentester seems more suited if you want a fulltime job

#

I mean, easier to practice in real life with bug bounty programs

foggy light
foggy light
zenith mango
#

Both paths look very interesting

snow lion
#

The Try hack me is not free?

#

How can i learn how to crypto and hack?

heady tusk
tepid hemlock
snow lion
tepid hemlock
#

But yea, just start googling/reading for the topics you are interested in

#

Maybe check Academy for modules related to your learning needs

snow lion
tepid hemlock
#

Check the link Lieke sent

snow lion
tepid hemlock
snow lion
#

And how about Hack the Box?

tepid hemlock
#

I think Active machines are free to hack

#

retired content and academy is paid I believe

heady tusk
tall birch
#

hii, I am doing the WINDOWS PRIVILEGE ESCALATION module.

Whenever I add my user to the admin group, I can see I added it succesffuly but I can't read the flags. Then I redo all and get a shell back to read it.

So just out of curiosity is this normal?

snow lion
heady tusk
#

I have no idea what's free there. just sign up and look around a bit

#

the fundamental stuff is free pretty sure

naive shell
#

Which module and question?

#

What have you tried so far?

#

You may also DM me so you don't spoil anything.

zinc marsh
#

@snow lion I know u are surely a kid, but this is not the right server to troll. (just for ur safety and ur family)

naive shell
#

I dm'd you.

zinc marsh
#

u have to enumerate subdomains of subdomains

naive field
#

ok guys idk why this is not working. im on AD enum and attacks, Attacking domain trusts cross forest abuse from linux

#

i got user and password of domain admin

#

but can not connect to it

zinc marsh
#

yea same to me

naive field
zinc marsh
#

i went to do machines in app.hackthebox

#

waiting for support

naive field
#

๐Ÿ˜ญ

#

its the last question

#

"Log in to the ACADEMY-EA-DC03.FREIGHTLOGISTICS.LOCAL Domain Controller using the Domain Admin account password submitted for question #2 and submit the contents of the flag.txt file on the Administrator desktop. "

#

im was finna leave the office after this

#

but got stuck on this for the last 30mins xd

#

myb even less but...

naive field
naive field
#

did u find the ip of the dc03?

#

cuz we have to

#

but idk how to lol

zinc marsh
#

ah no im stuck here

#

it doesnt let me ssh to 172.16.5.225 with that creds

#

u got this? @naive field

naive field
#

chect /etc/hosts

#

its ||172.16.5.238||

#

but still not working for me

naive field
naive field
#

lmao

zinc marsh
#

yea lol

naive field
#

are u sshing from the powershell/cmd?

zinc marsh
#

wait what module are u

naive field
#

aka windows host

zinc marsh
naive field
zinc marsh
#

permission denied

naive field
naive field
#

u need to type in the password

#

pasting wont work

zinc marsh
#

bruh

#

i didnt try that lol

naive field
#

yeah

#

now im stuck af on thissssss

naive field
#

i also tried with IP of the DC03

#

but nah

zinc marsh
#

oh u are 3 sections above me

naive field
#

but yeah idk why this is not workingg

naive field
# naive field

got it, was supposed to use user without the INLANEFREIGHT.LOCAL domain

rustic sage
#

bro help

#

i cant install linenum

#

for privilage escalation

graceful mortar
#

someone help me with documentation and reporting practice lab :{

rustic sage
blazing crypt
#

Active Directory Enumeration & Attacks

AD Enumeration & Attacks - Skills Assessment Part I

๐Ÿ”— https://academy.hackthebox.com/module/143/section/1278

Have been stuck at question 4 all day.

Submit the contents of the flag.txt file on the Administrator desktop on MS01

So:

  • || I've tried to use the gathered credentials everywhere. I know this svc_sql user has SQLAdmin rights over SQL01, but I couldn't seem to get anything out of it. ||
  • || I believe this domain is also vulnerable to PetitPotam, but with the port forwarding, I wasn't able to get a connection back to my relay. ||

Those are my main 2 ways of thinking right now. I seem to have exhausted all the rest I had in mind. Any help is greatly appreciated!

golden vortex
#

I'm in AD Enumeration & Attacks - Skills Assessment Part I
I got a Windows reverse shell , but I'm having issues while running mimikatz can anyone help?

zinc marsh
zinc marsh
#

we all doing the same module lol

golden vortex
#

did you use mimikatz for question 3?

blazing crypt
#

Oh, let me help you then! I didn't use mimikatz

rustic sage
#

and also in root directory i need do that

rustic sage
zinc marsh
rustic sage
zinc marsh
rustic sage
#

like mysql, ssh etc

zinc marsh
#

u can use linpeas or just enumerate what u learnt in the section manually

rustic sage
fathom pendant
#

File transfer methods

#

You have shell, you can transfer

rustic sage
#

should i use scp

fathom pendant
#

Whatever method you want

#

Python http

rustic sage
#

python http

#

how

#

wdym

zinc marsh
fathom pendant
#

Brother

#

Did you not do the file transfers module?

zinc marsh
#

u should do other modules first i guess

#

learn the basics first

rustic sage
zinc marsh
#

before start looking for privesc modules

zinc marsh
rustic sage
fathom pendant
#

It's called a path for a reason lol

fathom pendant
#

That's dumb

#

Never trust school

zinc marsh
zinc marsh
#

in the school they teach hacking now?

#

that is good

#

oh im spanish

#

here they still dont even know what is hacking -.-

fathom pendant
#

Ahh that looks more along the Cbbh path

zinc marsh
#

yea

#

that is enfocated in web hacking

blazing crypt
#

Active Directory Enumeration & Attacks

AD Enumeration & Attacks - Skills Assessment Part I

๐Ÿ”— https://academy.hackthebox.com/module/143/section/1278

Submit the contents of the flag.txt file on the Administrator desktop on MS01

Does anyone know why BloodHound does not show this access? It seems like something that should totally be shown... ๐Ÿค”
I missed this, but not sure what to add to my methodology not to miss this in the future...

zinc marsh
#

and uploaded it to bloodhound

blazing crypt
zinc marsh
#

but i didnt check if ms01 was there

blazing crypt
#

Because for me it doesn't

zinc marsh
#

but i used sharphound with bloodhound to complete 2 sections

golden vortex
zinc marsh
#

@blazing crypt try .\sharphound.exe -c all --zipfilename whatever

#

and check if it appears

blazing crypt
#

It's not getting the data in BloodHound that's the problem. That all worked fine.
It's that a specific edge is not in there that should be there and I don't know why. Seems to be the case for everyone

blazing crypt
zinc marsh
#

i think i can arrive to the skill assessment by tomorrow

#

is harder i think

#

cpts

#

the cpts include exploits and missconfigurations

#

the oscp had just exploits

#

but they updated the exam and i dont know if now they have included missconfigurations as well

blazing crypt
#

I used to work with CryptoCat and he told me that if you can pass CPTS, then you can just take the OSCP with ease

zinc marsh
#

he is guru

#

he knows too much kek

blazing crypt
zinc marsh
analog dock
#

In the footprinting medium lab, Iโ€™m in the server management studio as admin, but where do I find the HTB user and pass? Iโ€™ve checked security-users in every database but i canโ€™t seem to find it

tepid hemlock
#

I heard that if you can do medium boxes without the biggest hassle then you should be able to pass OSCP too

gentle root
fathom pendant
pine dagger
#

Anyone able to give some hints on Advanced SQL Injection Skill Assssment? I've got the ||email|| but its not working ||to reset the password||.

analog dock
fathom pendant
#

Read the names of them. There's one that will certainly help you

analog dock
fathom pendant
#

So starting at the top. There's some standard DBs but I believe one of them sticks out a bit more

analog dock
fathom pendant
analog dock
#

Well in the tables that is

fathom pendant
#

Give me one moment

#

Lol

analog dock
#

I only see master model msdb and tempdb

fathom pendant
#

It is accounts

#

Sorry

#

I was thinking of a different module

#

But yes you're close.
SQL GUI is just trash

#

And I wish they taught you basic enumeration with CLI in footprinting

analog dock
#

In accounts the only thing left to open is columns

fathom pendant
#

You haven't checked tables?

analog dock
#

Dbo.accounts is in tables

fathom pendant
#

Like I said

#

Start at DATABASES

analog dock
#

Yeah, master seems most logical to me

fathom pendant
#

Literally found it in 3 seconds (knowing where to look in GUI)

analog dock
#

๐Ÿฅฒ

fathom pendant
analog dock
fathom pendant
#

Ok

analog dock
#

Those + and - are gonna make me cry

fathom pendant
#

DM me a screenshot because you seem wildly lost

#

Lol

#

Because it sounds like you're digging down a rabbit hole

#

When the answer is right in front of you

golden vortex
#

Active Directory Enumeration & Attacks AD Enumeration & Attacks - Skills Assessment Part I on question 4 Submit the contents of the flag.txt file on the Administrator desktop on MS01. Im using chisel to tunnel and then rdp. im not sure what im doing wrong. I think im doing something wrong in proxychains.conf

fathom pendant
#

Again I'm not telling you System databases

#

Just DATABASES

deep owl
#

module: ACTIVE DIRECTORY ENUMERATION & ATTACKS section:Kerberoasting - from Linux
when trying to run the attackitt requests a password .... am confused what password do i need to enter

#

appreciate any help ๐Ÿ™‚

analog dock
#

Tip, do not filter your databases on accident

lone hemlock
#

Hello, i need support about buying cubes in htb academy...

fathom pendant
#

Contact support on the site using the green bubble on the bottom corner of the screen

zinc marsh
#

someone more in the AD enumeration and attacks with poblems with the xfreerdp?

#

i always need to retry multiple times to be able to use it

paper rivet
#

Hi, i need help please... In the module "File Transfers" --> Windows File Transfer Methods --> Second question. I have submit the content of the file and give me an error

#

So i have submit the md5 hash of the file as well

#

And error

#

๐Ÿ˜ฆ

naive field
#

what error

analog dock
#

Footprinting module finished! Had a much better time on the hard lab compared to the medium lab

#

Now I can sleep in peace

pine dagger
#

Yeah I found the medium lab much harder than hard. heh

paper rivet
naive field
#

at the beggining or at the end

#

of the flag

naive wadi
keen compass
#

Have you used the Footprinting-Wordlist provided in the resources ?

zinc marsh
#

i need to try it multiple times all time

red current
#

Anyone here able to give some help with the WordPress - Discovery & Enumeration section in Attacking Common Applications? I can't seem to find any of the answers at all for this section.

paper rivet
pine dagger
#

Can I DM you for some hints on the skill assessment? ๐Ÿ™‚

pine dagger
#

@modern epoch sent you a friend request so I can dm.

zinc marsh
#

@blazing crypt i found this website

#

it tells how to abuse each ObjectAceType

opal storm
#

Im kinda confused on the next steps for the Active Directory Enumeration and Attacks module, section "Privileged Access". We can't use a linux host to run mssqlclient.py since we are rdp'ed in and there seems to be an issue changing the settings using PowerUpSQL. Any recommendations around this?

opal storm
zinc marsh
#

i havent could even log in with rdp yet

opal storm
red current
#

Okay, still stuck on WordPress Discovery & Enumeration, but I have the last two answers and just need to find out how to get the flag for the first answer. I can't find it anywhere. Does anyone have a hint?

zinc marsh
red current
opal storm
red current
graceful mortar
#

what to do when target machine is going down?

pine dagger
red current
zinc marsh
#

but yea chisel should work

zinc marsh
red current
opal storm
zinc marsh
#

and one of them has the flag

red current
pine dagger
red current
zinc marsh
#

annoying it takes me 20 minute to be able to rdp

#

and am still getting black screen with rdp

west night
#
  1. Have you used the wordlist in the resources page?
red current
#

Okay, I'm stumped. Is the flag enrcrypted? I've tried decrypting the different cyphers that I've found but so far, nothing has the flag.

zinc marsh
opal storm
#

no i did them manually

west night
#
  1. There is a command shown in smtp module that allows you verify users. please look through module to find this. Once you have these two hints it is just a matter of enumerating through the usernames on the wordlist until find a name that matches.
zinc marsh
#

with mssqlclient and evil-winrm

opal storm
#

i used different tools within the rdp session to find the other user

#

powershell, aduc, etc

zinc marsh
opal storm
#

did i look over that section?

zinc marsh
#

it is at the beginning of the section

opal storm
#

LOL

#

maybe i should read then

zinc marsh
#

send the link

graceful mortar
#

damn, that was hard

red current
#

Is there some special tool that I should be using to get the flag for the WordPress Discovery & Enumeration section, or just the ones it shows you how to use?

plain sleet
opal storm
#

is the ssh this really slow for everyone else?

#

for active directory enumeration and attacks - privilege access

#

lol

#

ive tried resetting the machine

#

i might end up doing that if this doesnt load in a few minutes

zinc marsh
#

and worked fine

#

it was slow as well like 1h ago

opal storm
#

i just reset mine and its still slow

#

maybe i need a new vpn file again

zinc marsh
#

i downloaded us 3 vpn

#

and it works better than eu

opal storm
#

when you ran the ssh command, did you have to use "-tt" at the end?

#

and im already us 2

zinc marsh
#

no

opal storm
#

hm

zinc marsh
#

u mean for 172.16.5.225?

opal storm
#

you didnt get that pseudo terminal error?

#

yes

zinc marsh
#

u have to write the password manually

#

htb-student:HTB_@cademy_stdnt!

#

and dont use clear in the ssh lol

opal storm
#

i dont even get a prompt for a password

#

it just dies immediately

#

im just doing ssh htb-student@172.16.5.225

zinc marsh
#

weird then

#

u doing it from ms01?

opal storm
#

yes

zinc marsh
#

i dont know then

#

they need to upgrade the servers i guess

opal storm
#

no worries, thank you for the help tho

zinc marsh
#

they are too slow since the kids finished the school

opal storm
#

lol

#

and they stay up later now even during the work week

zinc marsh
#

well gn is 4am here

quiet ember
#

For Attacking Common Services Hard, is the ||Home share supposed to be empty||?

patent blaze
#

Is there anyone that I could discuss about Broken Authentication module Predictable Reset Token section?

fathom pendant
patent blaze
#

I was taking a look at the source code the provide on the section (not the python one) and it seems the app do not concatenate ||user+time||

limber river
#

but the Apache OpenMeeting: was about it

patent blaze
#

Yeah, that make sense, but I really tried hundreds of hundreds of tokens all being user+time and/or time+user.

limber river
#

but it dosen't work for me

#

it give me errors on $time

patent blaze
#

Worked on that yesterday. Pretty easy/simple to run it locally php -a. Define the vars and echo them

#

Came to the conclusion that itโ€™s possible to achieve the same md5 token with python. So now Iโ€™m working with python.

What I tried so far:
user+timestamp
user+timestamp_in_miliseconds
timestamp+user
timestamp_in_miliseconds+user

Iโ€™ve implemented the for loop in the timestamp, as HTB showed on their script.

At the beginning I thought that I had to find a way to recreate the token, we generate on the app, locally. But after reading all questions regarding this section, it seems that we just have to guess (brute force) the admin one. One of the reasons is because the exercise says that after +-1 second the admin token is generated. It doesnโ€™t says that is gonna be invalidated after N seconds, so it seems we have to guess it.

limber river
#

eeem that's intersting I am gonna give it a try later

patent blaze
#

Sure! Lemme know if you get any news

acoustic owl
#

You have to calculate the tokens based on the displayed time. Each token you have to check against the website

patent blaze
patent blaze
loud yacht
#

user+displaytime ?

acoustic owl
loud yacht
#

timestamp has 13 digits right?

patent blaze
acoustic owl
loud yacht
#

still can't get any answer๐Ÿฅฒ

autumn pilot
#

flag5 is easier than you think, don't over complicate things and you will get it

#

you are on the right path

#

ยฏ_(ใƒ„)_/ยฏ

#

poke around and find out

summer lava
#

Morning Guys
i need a little bit of help here.. i've been stuck on this for weeks
ATTACKING COMMON APPLICATIONS ==> Exploiting Web Vulnerabilities in Thick-Client Applications

rustic sage
pine dagger
#

Could I please DM you for some guidance on the Advanced SQL Injection module?

limber river
acoustic owl
limber river
acoustic owl
limber river
#

Ik GMT

#

i got this but ther's no flag

acoustic owl
scarlet cipher
#

i am not able to unlock any model, can someone help me

#

if i click unlock it just changes. the size

acoustic owl
scarlet cipher
scarlet cipher
acoustic owl
#

Which module do you want to unlock?

idle root
#

any module unlock or not yet?

scarlet cipher
scarlet cipher
idle root
#

in the dashboardgo modules -> all modules -> then click unlock button

scarlet cipher
#

nothing is happing

analog dock
#

Is target spawn down again?

idle root
scarlet cipher
#

nope

analog dock
#

Been trying in openvas skills assessment but itโ€™s been going for 5-10 mins now

idle root
#

try to logout and login again

scarlet cipher
#

also created different acc too

#

still

idle root
#

try to unlock "learning process" module

idle root
scarlet cipher
#

tried different browser too

idle root
#

mmm i'm sorry, but i don't know what is the problem

analog dock
#

Might be a problem with academy

#

Working again now

fathom pendant
#

Try contacting support if issues are persistent

#

easiest way to find out if shit is borked is contact support ยฏ_(ใƒ„)_/ยฏ

limber river
limber river
#

tbh I use chatgpt cuz , I 'am awful at py

acoustic owl
acoustic owl
limber river
#

ig I must go finish it

pine dagger
limber river
acoustic owl
pine dagger
#

I don't see why. Its just another tool

#

Do you feel bad for using dirbuster, or wfuzz?

winter copper
#

hi, I really could use an explanation as I'm banging my head against a wall here.
The last question in the Active Directory Enumeration is baffling to me: "Find the name of an account with a ServicePrincipalName set that is also a member of the Protected Users group".
have tried several times using:
Get-ADUser -Filter "adminCount -eq '1'" -Properties * | where servicePrincipalName -ne $null | select SamAccountName,MemberOf,ServicePrincipalName | fl

#

and it provides me w/ two accounts which definitely can't be those

#

the only search I was able to ask ChatGPT to come up with was:

#

Get-ADGroupMember -Identity "Protected Users"

#

I thought I needed to see ServicePrincipalName also, so I modified it to:

#

Get-ADGroupMember -Identity "Protected Users" | select SamAccountName,SID,ServicePrincipalName,

#

but ServicePrincipalName is empty

#

can someone pls elighten me? ๐Ÿ˜ฆ Thanks!

patent blaze
solar plinth
#

Hello please some one can tell me how to clear command line history

fathom pendant
#

Elaborate. You mean the terminal screen?

#

clear - Linux
cls - Windows

winter copper
ashen viper
#

Footprinting -IMAP/POP3. I am struck at getting (1).what is the customized version of the POP3 server (2).what is the admin email address (3).Try to access the emails on the IMAP server and submit the flag as tge answer. I need the commands to get answers to this questions. I have been struck for days on these.

fathom pendant
#
  1. connect to the POP3 server
    2/3) you can get both by reading the email. This section contains some useful commands but I googled and found more: #modules message
    The other email option is using a client like evolution
fathom pendant
tall birch
#

I am doing the WINDOWS PRIVILEGE ESCALATION module.
Whenever I add my user to the admin group, I can see that I have added my self successfully but I can't read the flags.

So just out of curiosity is this normal?

acoustic owl
plain coral
solar plinth
naive field
#

im doing ad enum and attacks assement part 1 and i have the web shell, when trying to kerberos for single user i get this

#

kerberoast*

#

but in the above command you can see i added the .Net framework class to poweshell session

naive field
# naive field

is it maybe because i need to get a more stable shell than webshell?

naive field
#

i cant even get a more stable sheeelll

#

:(

#

im always getting errors, i tried like 10 diff payloads

#

lol i see this is not gonna be very fun :D

rustic sage
blazing crypt
#

Windows Privilege Escalation

SeDebugPrivilege

Leverage SeDebugPrivilege rights and obtain the NTLM password hash for the sccm_svc account.

Eeuhm, the user we get given doesn't have that privilege? What kind of a weird lab is this? Is that intentional!

rustic sage
#

correct .NET framework

naive field
rustic sage
#
Get-ItemProperty -name Version -EA 0 |
Where-Object { $_.PSChildName -match '^(?!S)\p{L}'} |
Select-Object -Property PSChildName, Version
#

on powershell

#

unless you are on MacOS lol

naive field
#

no, its a powershell web shell xd

rustic sage
#

one moment

#

System.IdentityModel is inNET Framework versions 3.0 and above.... soooo since you have the required versions installed its not that

#

try run this

#

on powershell now

#

this confirms. that theSystem.IdentityModelassembly is available in GAC

#

@naive field

naive field
rustic sage
#

this will see if the assembly is successfully loaded and thefore ou should be able to use the New-Object cmdlet for instances of types from the System.IdentityModel namespace, such as KerberosRequestorSecurityToken etc etc

naive field
naive field
rustic sage
#

maybe create an instance

#

to check

#

run some token

#

umm

#

lemme try create one

#

its been a while

#

? try this perhaps

rustic sage
#

oh

#

see this

rustic sage
#

Replace MSSQLSvc/SQLO1.inlanefreight.local:1433 with SPN for your SQL Server instance. Make sure the SPN is correctly formatted with the correct host and port information of what you have

#

does it work?

#

@naive field

#

sorry for ping lol

naive field
rustic sage
#

still no luck?

naive field
#

i will try to get a more stable shell

rustic sage
#

oh okay lol

naive field
#

this is a webshell and i've been told by my friend that every command run in webshell is executed in its own process

rustic sage
#

try RDP or VNC

#

oh bet

naive field
#

so when i loaded the .net framework above it did ran but not in my session...

rustic sage
#

oof

#

yeah probably just a shell issue

#

no worries. dm me if you still need help

#

cya

naive field
narrow solar
#

hey friends, at RDP and SOCKS Tunneling with SocksOverRDP, at the last step when i want to connect to jason at 172.16.6.155 it tells me at the login screen that domain isnt available

#

and proxifier give me this error (Microsoft.SharePoint.exe (8688) *64 - 127.8.0.1:443 error: Cannot connect to placeholder (fake) IP address. It's recommended to restart the client application.)

narrow solar
#
  • Proxy server cannot establish a connection with the target - general SOCKS server failure
#

it was a local account ๐Ÿ˜‘

rustic sage
#

why hacking is too mixed

rustic sage
#

"9328/tcp open ftp syn-ack ttl 63 vsftpd 3.0.3
9999/tcp open abyss? syn-ack ttl 63"

i know how do connect ftp but how do we can connect to "unknown" service's and also like "abyss?" something's

marble kraken
#
[20:17:10:226] [1119287:1119288] [ERROR][com.freerdp.core] - freerdp_tcp_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_FAILED [0x00020006]
[20:17:10:227] [1119287:1119288] [ERROR][com.freerdp.core] - failed to connect to 10.129.91.118

Have a problem connecting with xfreerdp from my VMware fusion kali VM. I must state that i run kali on an M1 (ARM64 but little_endian) machine. Could be the problem, but could also be something trivial ... Ideas?

#

Module: Windows Fundamentals

steady hawk
marble kraken
#

Did all that - enclosing /u:'' and /p'' in single quotes. Must state that there seems to be a problem with the certificate. First time connecting I used quotes on all, and i got asked if I want to trust the Server certificate -> Answer Y . Now its like this

steady hawk
#

Try Remmina?

marble kraken
#

Ill try get a different IP Address maybe?
yeah ill check out the other client options, too. Gotta be on my way. Back later. Tnx 4 now

limber river
acoustic owl
dull vortex
#

Can i get a nudge in the right direction on password attacks medium? I am on the target with the first user and I found the service I am looking for but am now stuck. I don't want to say anything else and spoil, can I dm someone to see if I am in the right direction?

dapper star
#

Hey guys, I'm at the phishing part in the XSS module and I got the flag but not the way I was supposed to get it. (In fact I did, but I skipped a step because it didn't work) Can I DM someone to see what I did wrong? (the URL is +- the answer to this question so I want to do it in DM)

silent flax
#

hi

#

i cant solve question

#

can snybody help me ?

fathom pendant
#

It helps if you ask your question

silent flax
#

The exercise above seems to be broken, as it returns incorrect results. Use the browser devtools to see what is the request it is sending when we search, and use cURL to search for 'flag' and obtain the flag.

#

this is my question

#

i meen exercise

#

in รผeb requests

#

get method

#

web requests

pine dagger
#

Provide module and chapter name, and which question

ashen viper
#

Please help with the command. I have been struggling on this.

silent flax
#

Cracking into Hack the Box

#

HTTP Methods

#

GET

#

The exercise above seems to be broken, as it returns incorrect results. Use the browser devtools to see what is the request it is sending when we search, and use cURL to search for 'flag' and obtain the flag.

faint hull
#

is there a general chat

pine dagger
#

Cracking into Hack the Box isn't a module....

silent flax
#

sorry

#

web requests

faint hull
#

where do i start hacking and stuff im into the basics first

rustic sage
faint hull
# rustic sage learn basic's first

Knowledge of coding in relevant programming languages.
An understanding of computer networks, both wired and wireless.
Basic hardware knowledge.
Creative and analytical thinking abilities.
Database proficiency.
A solid foundation in information security principles.

deep owl
#

hello alll

#

module ACTIVE DIRECTORY ENUMERATION & ATTACKS

#

section Kerberoasting - from Linux

#

which password do i have to use ...

faint hull
deep owl
#

just tried it .... saying invalid credentials

autumn pilot
#

because thats not the credentials..

autumn pilot
faint hull
#

im not going to mess with you guys

deep owl
#

hahah no worries, seriously though what credentials am i supposed to give it

faint hull
deep owl
#

bro you sure as hell can't be scared of me ... am asking about the credentials of a basic tool in the industry

silent flax
faint hull
fathom pendant
#

Don't be a dick period

faint hull
fathom pendant
rustic sage
#

can't RDP into my password attacks module target after multiple restarts. any idea why?

fathom pendant
deep owl
#

try ' password '

rustic sage
#

ohhhhhh

#

thanks guys

fathom pendant
#

Also if you're curious what's going on, echo $$

deep owl
faint hull
deep owl
fathom pendant
dull vortex
#

Why does lazagne.exe close right after running on a windows target? I dont have any time to look at the results.

deep owl
fathom pendant
#

I don't remember

#

Kinda put academy progress on pause

misty current
fathom pendant
#

๐Ÿ™„

deep owl
fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

misty current
deep owl
#

is it the password of that user

misty current
#

First question to ask yourself is

#

is that user a domain user?

#

How do you find out if a user is a domain user?

modest ingot
#

i think i break the lab

misty current
#

validate if your user is a domain user and then proceed.

deep owl
#

that is some great questions

thorn urchin
deep owl
#

i hope so

opal storm
#

still no luck with ssh in the privileged access section on active directory enumeration and attacks

opal storm
#

ssh just wont connect

zinc marsh
#

to what ip

#

are u trying to connect

opal storm
#

the .5.225 from MS01

zinc marsh
#

with powershell/cmd?

opal storm
#

powershell

#

ssh htb-student@172.16.5.225 -tt

zinc marsh
#

why u use tt

opal storm
#

i get this error without it:
Pseudo-terminal will not be allocated because stdin is not a terminal.

#

and then just hangs

zinc marsh
#

weird

#

i just spawn the target

#

connect with xfreerdp and i open powershell and i ssh to 172.16.5.225

opal storm
#

no issue?

zinc marsh
#

no

opal storm
#

...

#

what vpn are you again?

zinc marsh
#

us 3

opal storm
#

im gonna reset the vpn and reset the machine again

deep owl
jagged hazel
#

New machine came?

zinc marsh
fathom pendant
opal storm
#

no luck again :/

prisma spruce
#

Has a module ever changed tiers?

#

I'm looking at a few old tweets, and I'm under the impression that they have.

zinc marsh
#

u must be doing something wrong

opal storm
#

i rdp as htb-student, i then psremote onto ms01 as forend, then i try ssh as htb-student on .5.225

#

ssh htb-student@172.16.5.225

zinc marsh
#

i dont get what i have to do

zinc marsh
#

RDP to with user "htb-student" and password "Academy_student_AD!"

opal storm
#

right thats for initial access

#

once im on the machine, i psremote into ms01 as forend

#

ill just come back to it i guess, kinda frustrating but whatever

zinc marsh
#

just xfreerdp and then ssh

opal storm
#

i gotta be an idiot

#

no way

#

LOL

#

welp

#

scratch that i should pay attention more

opal storm
# zinc marsh ?

ty for the help, i should read the notes much more carefully

patent blaze
#

Just to help others whoโ€™s going or will go through Predictable Reset Tokens. Question 1 is not the kinda thing you get one shot one hit. Iโ€™ve been running the same script the whole day, the script that I first use to get the flag and is not working. Conclusion: you gotta keep running until you get it.

Well, thatโ€™s at least what Iโ€™ve been experiencing.

gentle root
#

Can't see to get the correct brute-force on Skills Assessment - Website - Once you access the login page, you are tasked to brute force your way into this page as well. What is the flag hidden inside? - Brute-forcing module

#

If someone could sanity check here or dm, would be lovely

gentle root
zinc marsh
gentle root
#

Um, || hydra -L harry_username.txt -P harry.txt -u -f 144.126.230.162 -s 31679 http-post-form "/admin_login.php:username=^USER^&password=^PASS^:F=<title>Admin Panel - Login" -t 4 -I
||

#

Idek if this is right I was trying for like an hour or so and then just got back and trying again and read forums

zinc marsh
#

are u stuck in the first or second question

gentle root
#

second

limber river
#

is wrong

gentle root
#

I had it different earlier and wans't working, I can give that a change. I mean the whole point is it shouldn't show up on the actual page so

hardy socket
#

hello ppl, I'm struggling with the Password Attacks Lab - Medium. I've cracked the docx, got j**** creds for (i guess?) mysql service but it doesn't work and I'm not sure what to do next. Can somebody guide me a bit, please?

gentle root
#

||:F=<form name='log-in'" ||

zinc marsh
gentle root
#

Yeah I haha I dunno

fathom pendant
gentle root
#

I'll give this like 10min and see what happens

zinc marsh
#

not too much sense to bruteforce the title lol

gentle root
#

iT's not bruteforcing the title, its seeing if the title changes based on the next page that loads

#

which I figured it should

fathom pendant
limber river
hardy socket
gentle root
zinc marsh
#

i did it with rockyou.txt

gentle root
#

oh word?

fathom pendant
vagrant gust
#

on the password mutation section of password attacks im only get ~1500 words and other people are geting 60k plus

fathom pendant
vagrant gust
#

is there any reason for this?

fathom pendant
vagrant gust
#

yeah i did that

zinc marsh
fathom pendant
#

^

zinc marsh
#

or ur wordlists are wrong

fathom pendant
#

The wordlist should be like 90k+ iirc

zinc marsh
#

and yea i did it with rockyou.txt

fathom pendant
zinc marsh
#

ad module is taking forever

#

i think i can finish it tomorrow

vagrant gust
#

thanks for the help @fathom pendant @zinc marsh

hardy socket
zinc marsh
#

hide files maybe?

#

i havent checked the module

hardy socket
fathom pendant
#

you have the info to log into mysql

#

Just saying.

zinc marsh
fathom pendant
#

pika_sip you just have to access it from your foothold user

hardy socket
fathom pendant
#

You have the user. Think of how you log in

#

-u

hardy socket
#

ok, I'm an idiot, i got through

#

thank you @fathom pendant and @zinc marsh

gentle root
#

Okay, back to the web server brute force login, maybe I'm misunderstanding -- || Created username list using Harry and Potter. Created password list using cupp -i using First, Last, l33t, Numbers, and Special, then grepped out any missing those. Ran hydra -L harry_username.txt -P harry.txt -u -f 134.209.176.83 -s 32461 http-post-form "/admin_login.php:username=^USER^&password=^PASS^:F=<form name='log-in'" -t 4 ---- From attack box and no luck. What am I missing here?||

gentle root
limber river
#

use rockyou with what u found earlier "read hint"

gentle root
#

restart everything and trying again

gentle root
#

Okay, just to clarify this is on the Brute Forcing Logins - Skills Assessment - Website, I've been running rockyou and the cupp -i didn't work either, if someone could dm to clarify I would give you +1 Respect

limber river
#

but which module is dedicated to cryptography ?

#

there's no module with this name

#

eeem maybe they will release it later

limber river
gentle root
#

This is the Skills Assessment of Login Brute Forcing, there is no resources.

#

I have a username of like 15 users generated from username anarchy

#

I followed like these exact steps as well as trying rockyou,

#

Sorry for ping friend ๐Ÿ˜‰

#

It's a completely separate module

#

There's not.

#

It's self-generated ones

#

Not exactly what this one's about it's differnet

#

Yup

ebon root
#

Hello everyone. I have a question about STACK-BASED BUFFER OVERFLOWS ON WINDOWS X86. The fuzzing Parameters to be specific. I have a payload of length x , and I get the desired 41414141 at the eip
and when i generate payload x-1, I Get have 0D414141 in eip. I cant seem to find the right format for the answer. Any help will be appreciated. Thank you.

iron plaza
#

need a bit of a nudge in the File Upload Attach (module/136/section/1290). In the Type Filters question I managed to successfully upload a web shell file with the following extension: ||testshell.phtml.gif%20 || with the following content:
||GIF8
<?php system($_REQUEST['cmd']); ?>||
but when I try to curl it or send a request through repeater I get nothing ... any suggestion/tips as to why?

grave creek
#

i have problems RDPing to the remote machine 10.129.x.x for the AD enumeration and attacks module-specifically for the box at Internal Password Spraying -from Windows.
tried xfreerdp,remmina,rdesktop, evil-winrm, downloading the different vpn etc. and nothing works. i suspect it might be something that is at the end of HTB side. anyone faced this problem and have a solution please?
edit: I have also tried single quotes for password. When using evil-winrm as the last resort but failed, i have also include the -N flag in that attempt

broken tendon
#

any staff that could look into my module reset?

vital adder
vital adder
vital adder
grave creek
grave creek
vital adder
grave creek
misty current
#

Attacking Common Application's - Exploiting Web Vulnerabilities in Thick-Client Applications
Performed the path traversal, and I see the .jar files which I need to download to the system and in the module, it says to use thick-client's open button to download the .jar file, but I don't think it's downloading and just viewing the jar in it's console.
Was anybody able to download this?

acoustic willow
#

Could any one help me how to find flag in the accessible directory in module Attacking Common Applicationโ€™s
Enumerate the host and find a flag.txt flag in an accessible directory.

misty current
#

run a directory a bruteforcing and see what directories you can move around in.

acoustic willow
#

But check for all plugins i can not find anything

misty current
#

use tools like gobuster, ffuf

acoustic willow
#

Hmm

#

It sounds strangely

ocean flume
#

Can any one help with login brute force website assessment Iโ€™ve gotten four diff passwords ๐Ÿ˜“๐Ÿ˜“๐Ÿ˜“

#

N non work

acoustic willow
iron plaza
lost cave
#

have you got any hint for my i log in with ssh but i couldn't find the password for mysql

quick cloud
#

obsidian has made learning a lot easier I suggest obsidian or something similar to everyone

#

I tried One Note but its very overwhelming to have a bunch of notes on one page

eager hatch
quick cloud
#

I wish I would have knew about it earlier though haha I have to go back to everything before password attacks and take notes

eager hatch
#

Saaaaame. Guess it will be a good review ๐Ÿ˜‚

quick cloud
#

๐Ÿ˜‚

zinc marsh
gentle root
#

I obviously read the hint what do you mean

zinc marsh
#

then why are u using a wordlist for the users

gentle root
#

Which part of this says "Don't use a wordlist"

rustic sage
gentle root
#

export it* to like a file and use that is a input for SSH

#

or just try to su

rustic sage
#

i tried ๐Ÿ˜ฆ but it wants the password which i have to crack from the hash

acoustic willow
rustic sage
# acoustic willow What question did you stuck with ?

"Check Carlos' crontab, and look for keytabs to which Carlos has access. Try to get the credentials of the user svc_workstations and use them to authenticate via SSH. Submit the flag.txt in svc_workstations' home directory.
"

autumn pilot
rustic sage
#

why? i did put it around as spoiler

fathom pendant
#

It's still existing as anyone can look at it

rustic sage
#

oh alright, sorry

wispy aspen
#

Schrodinger's Hash

fathom pendant
#

A spoiler tag really doesn't do anything

autumn pilot
#

thanks

fathom pendant
#

It generally makes it stick out more for people looking to do the least work

rustic sage
#

yeah

#

my bad

autumn pilot
#

and a hint, there is a hash that can be cracked using one of the two things you mentioned

acoustic willow
#

you should find NTLM hash

rustic sage
autumn pilot
#

check the file(s) you are giving to the tool

acoustic willow
rustic sage
autumn pilot
#

whats the point of giving him a tool that mostly works on windows for a linux pass the hash?

#

there are more

rustic sage
#

ill look for more files

acoustic willow
#

Look for more files

rustic sage
#

found it thanks guys

craggy iris
#

Hello everyone, I'm working on the "limited file uploads" lab for the file upload attack module. I have a question: When I attempt to retrieve the SVG file that contains the XML at /images/xxe.svg , I receive an error message stating, "This XML file does not seem to contain any style information." Could someone provide me with a hint? Have a great day!

rustic sage
torn blade
#

no clue why the shell wont connect

#

like its a simple XML lab

acoustic willow
rustic sage
#

yes

acoustic willow
#

and in the victim's host ?

acoustic willow
acoustic willow
torn blade
#

are you saying i need to add the address to the etc/hosts?

acoustic willow
#

You just go the your http:<IP>:<PORT>/home/shell.php?cmd=? ?

rustic sage
acoustic willow
#

No I meant if you have uploaded you shell into the victim's host. You just run by http://<IP>:<PORT>/home/shell.php?cmd=id

torn blade
#

i mean the commadn you put looks like ewhat i put, am i missing something?

#

like ik im obvi missing something very simple i just dont know what

acoustic willow
#

http://<IP>:<PORT>/home/shell.php?cmd=id trythis

#

file:///flag.txt

#

/// not //

torn blade
#

do you mean liek this? I still get same result :(

acoustic willow
#

Nooo

torn blade
#

i dumbbbb i sorrrry

acoustic willow
#

Your command is right. But you need to go to the your browser and try http://<IP_Victim>:<PORT>/shell.php?cmd=id

torn blade
#

ah

acoustic willow
#

Try this

#

You hit the button "Send" and see the result

#

in the request in Burp Suite

torn blade
#

no dice

acoustic willow
torn blade
#

dont think so

acoustic willow
#

You need to upload again

torn blade
#

the module is on a contact page, its supposed to be via altering the xml it seems

acoustic willow
rustic sage
#

nope

acoustic willow
rustic sage
#

same error

misty current
#

check your proxychains file

rustic sage
#

socks5 127.0.0.1 1080

misty current
#

and where did you initiate the port forwarding?

rustic sage
#

on the attack machine

misty current
#

can you show me what you did

rustic sage
acoustic willow
rustic sage
#

yes

#

on the compromised RDP machine i ran c:\tools\chisel.exe client <myip>:8080 R:socks

acoustic willow
#

If this SVG has been uploaded into server, you can check it in photo ))) and you'll see the flag

torn blade
#

could it maybe be because the text in burp isnt green so its not technicaly doing what i want

misty current
# rustic sage yes

The thing is, I don't see you explicitly initiating/mentioning the traffic for which port socks needs to use

acoustic willow
misty current
#

can you send me the module link @rustic sage

torn blade
#

yeah, i get the same result if i try using just filtering like it recommends in the hint tho, so im jsut lie kstuck

rustic sage
#

currently trying the things ive tried again

rustic sage
#

"Setting the KRB5CCNAME Environment Variable"

acoustic willow
rustic sage
#

i tried. i have to set the variable in my root@linux01 machine right?

acoustic willow
rustic sage
#

now the server froze up again.........

acoustic willow
#

good luck to u ))

misty current
#

you have to set variable on the machine where you're going to run impacket

rustic sage
#

ok

misty current
#

But, regardless, there's an issue with your proxychains not finding valid proxies in your config

rustic sage
#

yeah

vital adder
rustic sage
#

yes

#

"Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_).
"

vital adder
# rustic sage im at this point

also no idea why tf there is a windows machine involved when the name of this section clearly say from linux but what is your main issue? (there isn't a third to pivot so you won't need chisel ) forgot about the Optional Exercises but still you don't need chisel for this

#

you can do 100% of this section on the given target machine

rustic sage
#

oh

#

well in that case im on root on the target machine

#

but i can't seem to find a kerberos ticket which should be used to connect to DC01\linux

misty current
#

I've not used chisel before tbh, I see in the module that they're inegrating both chisel and proxychains for your attack host to reach ms01. I'm just wondering, how they both work with each other hmm

vital adder
rustic sage
#

to be honest im quite confused about the different tools

blazing crypt
#

Active Directory Enumeration & Attacks

AD Enumeration & Attacks - Skills Assessment Part II

Use a common method to obtain weak credentials for another user. Submit the username for the user whose credentials you obtain.

I feel like I've tried every common method I know. Any hint here?

rustic sage
vital adder
vital adder
#

no idea if this is an issue for an old default chisel thing

blazing crypt
#

"Guess the password"

vital adder
#

even for ctf that suck ass

torn blade
#

nvm for me

misty current
#

when you get the chance @rustic sage can you try giving
on attack mapchine chisel server --socks5 --reverse
on victim machine: chisel client <snip> R:1080:socks
then try proxychains

acoustic willow
#

This belongs to root ?

#

if this to yes ))

rustic sage
vital adder
#

yep and maybe too much spoiler even with the spoiler tag (for mod)

acoustic willow
#

try it

vital adder
#

you can just remove the spoiler part but that work i guess ๐Ÿคฃ

misty current
#

the machines keytab is usually present in that location. They mention it in the module itself

misty current
rustic sage
rustic sage
#

the one i talked about before does not work :/

onyx rapids
#

Has anyone sucessfully solved Remote Code Execution from the Blind SQL Injection module?

I know most of the payload works because I get callbacks to download nc.exe

Not sure why my reverse shell is doing nothing though

vital adder
rustic sage
vital adder
#

yeah the question clearly say LINUX01$ not with that domain like the reset of the user (on that linux machine)

rustic sage
#

oh

surreal beacon
#

anyone can help in the footprinting module?

rustic sage
#

i do have the right keytab file right?

#

ohhh wait

#

think i got it

vital adder
surreal beacon
#

haha ok

#

im really confused with the system , i entered sqlplus using scott and tiger

#

and this is the question : Enumerate the target Oracle database and submit the password hash of the user DBSNMP as the answer.

vital adder
surreal beacon
#

i just cant find my way to the right table

#

im really confused

#

i know its simple but its stuck

vital adder
# misty current ๐Ÿคง

funny enough this section is the only section that i loss my note for that wholie module so a bit layter if i can re-do that from scratch i'll send you a dm?

torn blade
#

naw i got it for that one

rustic sage
torn blade
#

i sent a message to staff about another thing im stuck on and im just gunan wait to ehare back for that one

vital adder
surreal beacon
#

oracle Tns @vital adder

surreal beacon
#

if u could hint me or give me the steps i would really appreciate it @vital adder

vital adder
#

sure sorry for the wait i was double checking some stuff but hint if you have login check the example show under ||Oracle RDBMS - Extract Password Hashes|| and following something like that

acoustic willow
vital adder
vital adder
rustic sage
vital adder
#

and there is no flag?

surreal beacon
#

thanks guys forreal much appreciate what ur doing

vital adder
# rustic sage yes

also just to make sure you access \\DC01\linux01 like in the question said right?

vital adder
#

try without -no-pass